summaryrefslogtreecommitdiffstats
path: root/src
diff options
context:
space:
mode:
authorJeff Sharkey <jsharkey@android.com>2016-08-09 19:38:50 +0000
committerandroid-build-merger <android-build-merger@google.com>2016-08-09 19:38:50 +0000
commitec19fe64858d6f702a01d094ce9c5b449baab7a1 (patch)
tree01afee3060dc7406cbc8680e40e7e8de78b48c21 /src
parent47784d61cf756509e5002b0938af03ce009fd854 (diff)
parent8be3a92eb0b4105a9ed748be5a937ce79145f565 (diff)
downloadandroid_packages_providers_DownloadProvider-ec19fe64858d6f702a01d094ce9c5b449baab7a1.tar.gz
android_packages_providers_DownloadProvider-ec19fe64858d6f702a01d094ce9c5b449baab7a1.tar.bz2
android_packages_providers_DownloadProvider-ec19fe64858d6f702a01d094ce9c5b449baab7a1.zip
Enforce calling identity before clearing.
am: 8be3a92eb0 Change-Id: I0b339abd106680e44a7e900e3eae514cf0f630c1
Diffstat (limited to 'src')
-rw-r--r--src/com/android/providers/downloads/DownloadProvider.java13
1 files changed, 13 insertions, 0 deletions
diff --git a/src/com/android/providers/downloads/DownloadProvider.java b/src/com/android/providers/downloads/DownloadProvider.java
index 2d914c41..d2a9d847 100644
--- a/src/com/android/providers/downloads/DownloadProvider.java
+++ b/src/com/android/providers/downloads/DownloadProvider.java
@@ -1192,6 +1192,19 @@ public final class DownloadProvider extends ContentProvider {
logVerboseOpenFileInfo(uri, mode);
}
+ // Perform normal query to enforce caller identity access before
+ // clearing it to reach internal-only columns
+ final Cursor probeCursor = query(uri, new String[] {
+ Downloads.Impl._DATA }, null, null, null);
+ try {
+ if ((probeCursor == null) || (probeCursor.getCount() == 0)) {
+ throw new FileNotFoundException(
+ "No file found for " + uri + " as UID " + Binder.getCallingUid());
+ }
+ } finally {
+ IoUtils.closeQuietly(probeCursor);
+ }
+
final Cursor cursor = queryCleared(uri, new String[] {
Downloads.Impl._DATA, Downloads.Impl.COLUMN_STATUS,
Downloads.Impl.COLUMN_DESTINATION, Downloads.Impl.COLUMN_MEDIA_SCANNED }, null,