Harden startNextMatchingActivity() caller identity propagation.

Currently, startNextMatchingActivity propagates the original caller's identity to the next resolved activity. This enables an "identity  squashing" vulnerability where a malicious intermediary can trampoline an implicit intent from a privileged app to a victim app, bypassing permission checks (e.g. REQUEST_INSTALL_PACKAGES).

This change restricts identity forwarding to prevent caller ID spoofing. The original caller's identity (launchedFromPackage/launchedFromUid) is now only propagated if:
1. The intermediary activity shares the same App ID as the original caller.
2. The intermediary activity is a privileged system component (e.g. SYSTEM_UID), preserving expected behavior for system trampolines like ChooserActivity.

If these conditions are not met, the caller identity is safely reset to the intermediary's own UID and package name.

Bug: 471797575
Test: atest WmTests:ActivityTaskManagerServiceTests
Test: Verified via test app
Flag: EXEMPT CVE_FIX
Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:995f95376eb373d9e8d584883a87ebb90db609d0
Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:a24b74da128da7cf45973c35154eb47876c3acf3
Merged-In: I3df4b731bfae6ce6f8896c69ecdd118819057b36
Change-Id: I3df4b731bfae6ce6f8896c69ecdd118819057b36
4 files changed