diff options
| -rw-r--r-- | services/core/java/com/android/server/pm/ShortcutService.java | 22 | 
1 files changed, 22 insertions, 0 deletions
diff --git a/services/core/java/com/android/server/pm/ShortcutService.java b/services/core/java/com/android/server/pm/ShortcutService.java index 2f3056e89614..937f0d900c01 100644 --- a/services/core/java/com/android/server/pm/ShortcutService.java +++ b/services/core/java/com/android/server/pm/ShortcutService.java @@ -34,6 +34,7 @@ import android.app.usage.UsageStatsManagerInternal;  import android.appwidget.AppWidgetProviderInfo;  import android.content.BroadcastReceiver;  import android.content.ComponentName; +import android.content.ContentProvider;  import android.content.Context;  import android.content.Intent;  import android.content.IntentFilter; @@ -1913,11 +1914,32 @@ public class ShortcutService extends IShortcutService.Stub {          }          if (shortcut.getIcon() != null) {              ShortcutInfo.validateIcon(shortcut.getIcon()); +            validateIconURI(shortcut);          }          shortcut.replaceFlags(shortcut.getFlags() & ShortcutInfo.FLAG_LONG_LIVED);      } +    // Validates the calling process has permission to access shortcut icon's image uri +    private void validateIconURI(@NonNull final ShortcutInfo si) { +        final int callingUid = injectBinderCallingUid(); +        final Icon icon = si.getIcon(); +        if (icon == null) { +            // There's no icon in this shortcut, nothing to validate here. +            return; +        } +        int iconType = icon.getType(); +        if (iconType != Icon.TYPE_URI && iconType != Icon.TYPE_URI_ADAPTIVE_BITMAP) { +            // The icon is not URI-based, nothing to validate. +            return; +        } +        final Uri uri = icon.getUri(); +        mUriGrantsManagerInternal.checkGrantUriPermission(callingUid, si.getPackage(), +                ContentProvider.getUriWithoutUserId(uri), +                Intent.FLAG_GRANT_READ_URI_PERMISSION, +                ContentProvider.getUserIdFromUri(uri, UserHandle.getUserId(callingUid))); +    } +      private void fixUpIncomingShortcutInfo(@NonNull ShortcutInfo shortcut, boolean forUpdate) {          fixUpIncomingShortcutInfo(shortcut, forUpdate, /*forPinRequest=*/ false);      }  |