RESTRICT AUTOMERGE Fix DownloadProvider completed download security bypass
Fix a vulnerability where unprivileged apps can read arbitrary files
in /sdcard/Download/ via addCompletedDownload().
This fix strengthens path validation in checkDownloadedFilePath() and
checkWhetherCallingAppHasAccess():
- Skip check if the file is in the caller's app-specific directory.
- For public directories, if the file is not in MediaStore (or has
no owner), allow only if the caller has MANAGE_EXTERNAL_STORAGE
or is a legacy app with READ_EXTERNAL_STORAGE.
- Otherwise, throw SecurityException.
- Fall back to synchronous MediaStore scan if file is not immediately
found in MediaStore, resolving race conditions with FUSE.
Additionally, checkInsertPermissions() is refactored to resolve a
parameter shadowing warning by using a local copy 'check' for
validation, ensuring that original values are not stripped.
Bug: 498162425
Test: atest CtsDownloadManagerTestCases
FLAG: EXEMPT BUGFIX
TAG=agy
CONV=59df8c5e-7bbb-4ca7-876b-5f226dd2c84c
Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:f788c90f69a0eee97c120eb399e5bb4ee841d43c
Merged-In: I159a2a9be7da21b2738be8dc8362dc3fb463d638
Change-Id: I159a2a9be7da21b2738be8dc8362dc3fb463d638
2 files changed