specialCrossUserGrant should not be false by default for

secondary users.

bug: 120913988
Test: adb shell am switch-user 0
cts-tradefed run cts-dev -a arm64-v8a -m CtsAppSecurityHostTestCases -t android.appsecurity.cts.AppSsts#testPermissionDiffCert
adb shell am switch-user 10
cts-tradefed run cts-dev -a arm64-v8a -m CtsAppSecurityHostTestCases -t android.appsecurity.cts.AppSsts#testPermissionDiffCert

Verified continued functionality (See b/120913988#comment4):
open a document in quickOffice
In the menu, tap share
in the disambig dialog, tap Android for work



Change-Id: I94960bc91276a2a797df97fa84aa67890582b046
This commit is contained in:
Nicholas Sauer
2018-12-20 19:31:03 -08:00
parent 03e04e83db
commit faa877f797

View File

@@ -1129,7 +1129,8 @@ public class UriGrantsManagerService extends IUriGrantsManager.Stub {
* In this case, we grant a uri permission, even if the ContentProvider does not normally
* grant uri permissions.
*/
boolean specialCrossUserGrant = UserHandle.getUserId(targetUid) != grantUri.sourceUserId
boolean specialCrossUserGrant = targetUid >= 0
&& UserHandle.getUserId(targetUid) != grantUri.sourceUserId
&& checkHoldingPermissionsInternal(pm, pi, grantUri, callingUid,
modeFlags, false /*without considering the uid permissions*/);