Fix BAL bypass via getAppMarketActivityIntent

LauncherAppsService.getAppMarketActivityIntent created a PendingIntent
on behalf of the system server (UID 1000) due to cleared identity.
An unprivileged app could request this IntentSender and use it as
a deleteIntent in a notification, allowing it to launch activities
from the background when the notification is dismissed, bypassing
BAL restrictions.

This fix sets the PendingIntentCreatorBackgroundActivityStartMode to
ALLOW_IF_VISIBLE when creating the PendingIntent. This ensures that
the PendingIntent carries restrictions that prevent background activity
launches unless the app is visible, while still allowing the system
server to create the PendingIntent (preserving cross-profile functionality).

Bug: 492867206
Test: atest CtsPackageManagerTestCases:android.content.pm.cts.LauncherAppsForHiddenProfilesTest
Flag: EXEMPT CVE_FIX
Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:0c7caef3e68dc331a45cad0b6bbee69e7cf928ba
Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:927fb5e35c9d7b1808d72c9ac6ba3b049fd73428
Merged-In: Ida112cd1f289089c4dba4c81d5cd43496daeeb62
Change-Id: Ida112cd1f289089c4dba4c81d5cd43496daeeb62
1 file changed