tree 9b6aee0872c275bef68dbfa7ecef9c323993d61e
parent f9d1bbb566371312987e15737f669e9f582d241a
author Treehugger Robot <treehugger-gerrit@google.com> 1621564979 +0000
committer Chiachang Wang <chiachangwang@google.com> 1621584097 +0000

Use CS identity to update setting while performing factory reset

When apps try to call factoryReset to do networking reset, it
will result in updating the setting in SettingsProvider.
ContentProvider will verify if the package name of the caller
that initiated the request being processed on the current thread.
The package should belong to the calling UID. The setting update
started from the ConnectivityService context, so the package will
be android but the calling UID will be the calling app. It will
cause a SecurityException. The behavior is fine previously as its
known caller(Settings) shares system UID. But it will be a
problem for other callers, such as CTS. Thus, clear the identity
since the necessary permission check should be examined at the
top of the method. The following actions should be fine to be
proceed from the system itself. Also replace the user restriction
check via hasUserRestrictionForUser with the UserHandle created
from the calling uid to ensure it's verified with correct user.

Bug: 186061922
Test: Factory reset from Settings
Merged-In: If2dd69f702a1eafff331f9e71f6b92aeadfb715d
Change-Id: If2dd69f702a1eafff331f9e71f6b92aeadfb715d
(cherry picked from commit 10ba4b773bb66811be4a6a2f5e0c6735e3a5e5d2)
