)]}'
{
  "commit": "91d787c2cb512cf896138ccb6956dc689e9b7d81",
  "tree": "e4f29b69f9744cc48f949525e67d5a489ebcaa11",
  "parents": [
    "0f3cf41c8ea88878800eb9a8cb468f610eba8798"
  ],
  "author": {
    "name": "Pinyao Ting",
    "email": "pinyaoting@google.com",
    "time": "Thu Mar 03 18:24:37 2022 +0000"
  },
  "committer": {
    "name": "Android Build Coastguard Worker",
    "email": "android-build-coastguard-worker@google.com",
    "time": "Fri Mar 11 01:39:39 2022 +0000"
  },
  "message": "Verify caller before auto granting slice permission\n\nCurrently SliceManagerService#checkSlicePermission does not verify the\ncaller\u0027s identity. This leads to a security vulnerability because\ncheckSlicePermission does more than checking the permission as opposed\nto simply return a boolean value -- it additionally grants slice access\nunder a certain condition. A malicious app can spoof the calling package\nto acquire slice access.\n\nThis CL verifies the caller before granting slice access.\n\nBug: 208232850, 179699767\nTest: manual\nChange-Id: I2539c9ff5ea977c91bb58185c95280b4d533a520\nMerged-In: I2539c9ff5ea977c91bb58185c95280b4d533a520\n(cherry picked from commit 5bd2196c537ae42a5c1626bdc23c3c6db41fb97f)\n(cherry picked from commit 3c92d74d7d74e1d781ae1b071da97b3b2cbc6be9)\nMerged-In: I2539c9ff5ea977c91bb58185c95280b4d533a520\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "ee0e5ba916b9c0fbe0a0a0dca671575366e03257",
      "old_mode": 33188,
      "old_path": "services/core/java/com/android/server/slice/SliceManagerService.java",
      "new_id": "e3dcfd0c89c06601ace935d1b05618ef32a10d8c",
      "new_mode": 33188,
      "new_path": "services/core/java/com/android/server/slice/SliceManagerService.java"
    }
  ]
}
