Fix BAL bypass via getAppMarketActivityIntent LauncherAppsService.getAppMarketActivityIntent created a PendingIntent on behalf of the system server (UID 1000) due to cleared identity. An unprivileged app could request this IntentSender and use it as a deleteIntent in a notification, allowing it to launch activities from the background when the notification is dismissed, bypassing BAL restrictions. This fix sets the PendingIntentCreatorBackgroundActivityStartMode to ALLOW_IF_VISIBLE when creating the PendingIntent. This ensures that the PendingIntent carries restrictions that prevent background activity launches unless the app is visible, while still allowing the system server to create the PendingIntent (preserving cross-profile functionality). Bug: 492867206 Test: atest CtsPackageManagerTestCases:android.content.pm.cts.LauncherAppsForHiddenProfilesTest Flag: EXEMPT CVE_FIX Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:0c7caef3e68dc331a45cad0b6bbee69e7cf928ba Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:927fb5e35c9d7b1808d72c9ac6ba3b049fd73428 Merged-In: Ida112cd1f289089c4dba4c81d5cd43496daeeb62 Change-Id: Ida112cd1f289089c4dba4c81d5cd43496daeeb62