Add unaudited exported flag to exposed runtime receivers
Android T allows apps to declare a runtime receiver as not exported by invoking registerReceiver with a new RECEIVER_NOT_EXPORTED flag; receivers registered with this flag will only receive broadcasts from the platform and the app itself. However to ensure developers can properly protect their receivers, all apps targeting T or later registering a receiver for non-system broadcasts must specify either the exported or not exported flag when invoking #registerReceiver; if one of these flags is not provided, the platform will throw a SecurityException. This commit updates all the exposed receivers with a new RECEIVER_EXPORTED_UNAUDITED flag to maintain the existing behavior of exporting the receiver while also flagging the receiver for audit before the T release. Bug: 161145287 Test: Build Change-Id: I165dbff34a03180a770d7cd621464f3d832b8095
This commit is contained in:
@@ -264,7 +264,8 @@ public class PackageInstallerImpl {
|
||||
String action = ACTION_INSTALL_COMMIT + "." + packageName;
|
||||
IntentFilter intentFilter = new IntentFilter();
|
||||
intentFilter.addAction(action);
|
||||
mContext.registerReceiver(broadcastReceiver, intentFilter);
|
||||
mContext.registerReceiver(broadcastReceiver, intentFilter,
|
||||
Context.RECEIVER_EXPORTED_UNAUDITED);
|
||||
|
||||
// Create a matching PendingIntent and use it to generate the IntentSender
|
||||
Intent broadcastIntent = new Intent(action);
|
||||
|
||||
Reference in New Issue
Block a user