mirror of
https://github.com/Divested-Mobile/DivestOS-Build.git
synced 2025-01-11 15:39:28 -05:00
134 lines
5.7 KiB
Diff
134 lines
5.7 KiB
Diff
|
From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
|
||
|
From: Oli Lan <olilan@google.com>
|
||
|
Date: Fri, 25 Feb 2022 15:22:27 +0000
|
||
|
Subject: [PATCH] Prevent exfiltration of system files via user image settings.
|
||
|
|
||
|
This is a backport of ag/17005706.
|
||
|
|
||
|
This adds mitigations to prevent system files being exfiltrated
|
||
|
via the settings content provider when a content URI is provided
|
||
|
as a chosen user image.
|
||
|
|
||
|
The mitigations are:
|
||
|
|
||
|
1) Copy the image to a new URI rather than the existing takePictureUri
|
||
|
prior to cropping.
|
||
|
|
||
|
2) Only allow a system handler to respond to the CROP intent.
|
||
|
|
||
|
Bug: 187702830
|
||
|
Test: build and check functionality
|
||
|
Change-Id: Ia6314b6810afb5efa0329f3eeaee9ccfff791966
|
||
|
Merged-In: I15e15ad88b768a5b679de32c5429d921d850a3cb
|
||
|
(cherry picked from commit 8950a9002402de6e1218bab3da52868a51104a95)
|
||
|
Merged-In: Ia6314b6810afb5efa0329f3eeaee9ccfff791966
|
||
|
---
|
||
|
.../users/EditUserPhotoController.java | 42 +++++++++++++------
|
||
|
1 file changed, 29 insertions(+), 13 deletions(-)
|
||
|
|
||
|
diff --git a/src/com/android/settings/users/EditUserPhotoController.java b/src/com/android/settings/users/EditUserPhotoController.java
|
||
|
index 0f67b181de3..cdf392b9df0 100644
|
||
|
--- a/src/com/android/settings/users/EditUserPhotoController.java
|
||
|
+++ b/src/com/android/settings/users/EditUserPhotoController.java
|
||
|
@@ -22,6 +22,7 @@ import android.content.ClipData;
|
||
|
import android.content.ContentResolver;
|
||
|
import android.content.Context;
|
||
|
import android.content.Intent;
|
||
|
+import android.content.pm.ActivityInfo;
|
||
|
import android.content.pm.PackageManager;
|
||
|
import android.database.Cursor;
|
||
|
import android.graphics.Bitmap;
|
||
|
@@ -75,6 +76,7 @@ public class EditUserPhotoController {
|
||
|
private static final int REQUEST_CODE_TAKE_PHOTO = 1002;
|
||
|
private static final int REQUEST_CODE_CROP_PHOTO = 1003;
|
||
|
|
||
|
+ private static final String PRE_CROP_PICTURE_FILE_NAME = "PreCropEditUserPhoto.jpg";
|
||
|
private static final String CROP_PICTURE_FILE_NAME = "CropEditUserPhoto.jpg";
|
||
|
private static final String TAKE_PICTURE_FILE_NAME = "TakeEditUserPhoto2.jpg";
|
||
|
private static final String NEW_USER_PHOTO_FILE_NAME = "NewUserPhoto.png";
|
||
|
@@ -85,6 +87,7 @@ public class EditUserPhotoController {
|
||
|
private final Fragment mFragment;
|
||
|
private final ImageView mImageView;
|
||
|
|
||
|
+ private final Uri mPreCropPictureUri;
|
||
|
private final Uri mCropPictureUri;
|
||
|
private final Uri mTakePictureUri;
|
||
|
|
||
|
@@ -96,6 +99,8 @@ public class EditUserPhotoController {
|
||
|
mContext = view.getContext();
|
||
|
mFragment = fragment;
|
||
|
mImageView = view;
|
||
|
+
|
||
|
+ mPreCropPictureUri = createTempImageUri(mContext, PRE_CROP_PICTURE_FILE_NAME, !waiting);
|
||
|
mCropPictureUri = createTempImageUri(mContext, CROP_PICTURE_FILE_NAME, !waiting);
|
||
|
mTakePictureUri = createTempImageUri(mContext, TAKE_PICTURE_FILE_NAME, !waiting);
|
||
|
mPhotoSize = getPhotoSize(mContext);
|
||
|
@@ -130,7 +135,7 @@ public class EditUserPhotoController {
|
||
|
case REQUEST_CODE_TAKE_PHOTO:
|
||
|
case REQUEST_CODE_CHOOSE_PHOTO:
|
||
|
if (mTakePictureUri.equals(pictureUri)) {
|
||
|
- cropPhoto();
|
||
|
+ cropPhoto(pictureUri);
|
||
|
} else {
|
||
|
copyAndCropPhoto(pictureUri);
|
||
|
}
|
||
|
@@ -239,7 +244,7 @@ public class EditUserPhotoController {
|
||
|
protected Void doInBackground(Void... params) {
|
||
|
final ContentResolver cr = mContext.getContentResolver();
|
||
|
try (InputStream in = cr.openInputStream(pictureUri);
|
||
|
- OutputStream out = cr.openOutputStream(mTakePictureUri)) {
|
||
|
+ OutputStream out = cr.openOutputStream(mPreCropPictureUri)) {
|
||
|
Streams.copy(in, out);
|
||
|
} catch (IOException e) {
|
||
|
Log.w(TAG, "Failed to copy photo", e);
|
||
|
@@ -250,27 +255,38 @@ public class EditUserPhotoController {
|
||
|
@Override
|
||
|
protected void onPostExecute(Void result) {
|
||
|
if (!mFragment.isAdded()) return;
|
||
|
- cropPhoto();
|
||
|
+ cropPhoto(mPreCropPictureUri);
|
||
|
}
|
||
|
}.execute();
|
||
|
}
|
||
|
|
||
|
- private void cropPhoto() {
|
||
|
+ private void cropPhoto(final Uri pictureUri) {
|
||
|
// TODO: Use a public intent, when there is one.
|
||
|
Intent intent = new Intent("com.android.camera.action.CROP");
|
||
|
- intent.setDataAndType(mTakePictureUri, "image/*");
|
||
|
+ intent.setDataAndType(pictureUri, "image/*");
|
||
|
appendOutputExtra(intent, mCropPictureUri);
|
||
|
appendCropExtras(intent);
|
||
|
- if (intent.resolveActivity(mContext.getPackageManager()) != null) {
|
||
|
- try {
|
||
|
- StrictMode.disableDeathOnFileUriExposure();
|
||
|
- mFragment.startActivityForResult(intent, REQUEST_CODE_CROP_PHOTO);
|
||
|
- } finally {
|
||
|
- StrictMode.enableDeathOnFileUriExposure();
|
||
|
+ try {
|
||
|
+ StrictMode.disableDeathOnFileUriExposure();
|
||
|
+ if (startSystemActivityForResult(intent, REQUEST_CODE_CROP_PHOTO)) {
|
||
|
+ return;
|
||
|
}
|
||
|
- } else {
|
||
|
- onPhotoCropped(mTakePictureUri, false);
|
||
|
+ } finally {
|
||
|
+ StrictMode.enableDeathOnFileUriExposure();
|
||
|
+ }
|
||
|
+ onPhotoCropped(mTakePictureUri, false);
|
||
|
+ }
|
||
|
+
|
||
|
+ private boolean startSystemActivityForResult(Intent intent, int code) {
|
||
|
+ ActivityInfo info = intent.resolveActivityInfo(mContext.getPackageManager(),
|
||
|
+ PackageManager.MATCH_SYSTEM_ONLY);
|
||
|
+ if (info == null) {
|
||
|
+ Log.w(TAG, "No system package activity could be found for code " + code);
|
||
|
+ return false;
|
||
|
}
|
||
|
+ intent.setPackage(info.packageName);
|
||
|
+ mFragment.startActivityForResult(intent, code);
|
||
|
+ return true;
|
||
|
}
|
||
|
|
||
|
private void appendOutputExtra(Intent intent, Uri pictureUri) {
|