diff options
author | Andrii Kulian <akulian@google.com> | 2019-07-16 11:24:45 -0700 |
---|---|---|
committer | Andrii Kulian <akulian@google.com> | 2019-07-16 19:30:42 +0000 |
commit | fbc35b907a9b635bd149386ef63e89c96965343b (patch) | |
tree | 73d3ac878190bd5fbc2c733cefc9f19b72b44bd2 /startop/scripts/lib/cmd_utils.py | |
parent | 41c4da37ed9fc69eb53787f2d458d6d0a51225a9 (diff) |
Add calling package verification for ATM binder calls
In some methods in ActivityTaskManagerService and AppTaskImpl we were
not validating if the callingPackage parameter that's passed in from
binder actually belongs to the calling uid. But some of our security
checks involve retrieving properties of the callingPackage, e.g.
ActivityStackSupervisor.getActionRestrictionForCallingPackage(),
and apps were able to circumvent these checks.
This CL adds checks that provided package name belongs to the calling
UID in ATM binder calls, and throws an exception if it doesn't.
Bug: 137395936
Test: Build & flash
Change-Id: I28608fd31bdbc56b758696a5e3b042c20d59c071
Diffstat (limited to 'startop/scripts/lib/cmd_utils.py')
0 files changed, 0 insertions, 0 deletions