1*ec779b8eSAndroid Build Coastguard Worker /*
2*ec779b8eSAndroid Build Coastguard Worker * Copyright (C) 2024 The Android Open Source Project
3*ec779b8eSAndroid Build Coastguard Worker *
4*ec779b8eSAndroid Build Coastguard Worker * Licensed under the Apache License, Version 2.0 (the "License");
5*ec779b8eSAndroid Build Coastguard Worker * you may not use this file except in compliance with the License.
6*ec779b8eSAndroid Build Coastguard Worker * You may obtain a copy of the License at
7*ec779b8eSAndroid Build Coastguard Worker *
8*ec779b8eSAndroid Build Coastguard Worker * http://www.apache.org/licenses/LICENSE-2.0
9*ec779b8eSAndroid Build Coastguard Worker *
10*ec779b8eSAndroid Build Coastguard Worker * Unless required by applicable law or agreed to in writing, software
11*ec779b8eSAndroid Build Coastguard Worker * distributed under the License is distributed on an "AS IS" BASIS,
12*ec779b8eSAndroid Build Coastguard Worker * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13*ec779b8eSAndroid Build Coastguard Worker * See the License for the specific language governing permissions and
14*ec779b8eSAndroid Build Coastguard Worker * limitations under the License.
15*ec779b8eSAndroid Build Coastguard Worker */
16*ec779b8eSAndroid Build Coastguard Worker
17*ec779b8eSAndroid Build Coastguard Worker #include <media/ValidatedAttributionSourceState.h>
18*ec779b8eSAndroid Build Coastguard Worker
19*ec779b8eSAndroid Build Coastguard Worker #include <binder/IPCThreadState.h>
20*ec779b8eSAndroid Build Coastguard Worker #include <error/expected_utils.h>
21*ec779b8eSAndroid Build Coastguard Worker #include <utils/Log.h>
22*ec779b8eSAndroid Build Coastguard Worker
23*ec779b8eSAndroid Build Coastguard Worker using ::android::binder::Status;
24*ec779b8eSAndroid Build Coastguard Worker using ::android::error::BinderResult;
25*ec779b8eSAndroid Build Coastguard Worker using ::android::error::unexpectedExceptionCode;
26*ec779b8eSAndroid Build Coastguard Worker
27*ec779b8eSAndroid Build Coastguard Worker namespace com::android::media::permission {
28*ec779b8eSAndroid Build Coastguard Worker
29*ec779b8eSAndroid Build Coastguard Worker BinderResult<ValidatedAttributionSourceState>
createFromBinderContext(AttributionSourceState attr,const IPermissionProvider & provider)30*ec779b8eSAndroid Build Coastguard Worker ValidatedAttributionSourceState::createFromBinderContext(AttributionSourceState attr,
31*ec779b8eSAndroid Build Coastguard Worker const IPermissionProvider& provider) {
32*ec779b8eSAndroid Build Coastguard Worker attr.pid = ::android::IPCThreadState::self()->getCallingPid();
33*ec779b8eSAndroid Build Coastguard Worker attr.uid = ::android::IPCThreadState::self()->getCallingUid();
34*ec779b8eSAndroid Build Coastguard Worker return createFromTrustedUidNoPackage(std::move(attr), provider);
35*ec779b8eSAndroid Build Coastguard Worker }
36*ec779b8eSAndroid Build Coastguard Worker
37*ec779b8eSAndroid Build Coastguard Worker BinderResult<ValidatedAttributionSourceState>
createFromTrustedUidNoPackage(AttributionSourceState attr,const IPermissionProvider & provider)38*ec779b8eSAndroid Build Coastguard Worker ValidatedAttributionSourceState::createFromTrustedUidNoPackage(
39*ec779b8eSAndroid Build Coastguard Worker AttributionSourceState attr, const IPermissionProvider& provider) {
40*ec779b8eSAndroid Build Coastguard Worker if (attr.packageName.has_value() && attr.packageName->size() != 0) {
41*ec779b8eSAndroid Build Coastguard Worker if (VALUE_OR_RETURN(provider.validateUidPackagePair(attr.uid, attr.packageName.value()))) {
42*ec779b8eSAndroid Build Coastguard Worker return ValidatedAttributionSourceState{std::move(attr)};
43*ec779b8eSAndroid Build Coastguard Worker } else {
44*ec779b8eSAndroid Build Coastguard Worker return unexpectedExceptionCode(Status::EX_SECURITY,
45*ec779b8eSAndroid Build Coastguard Worker attr.toString()
46*ec779b8eSAndroid Build Coastguard Worker .insert(0, ": invalid attr ")
47*ec779b8eSAndroid Build Coastguard Worker .insert(0, __PRETTY_FUNCTION__)
48*ec779b8eSAndroid Build Coastguard Worker .c_str());
49*ec779b8eSAndroid Build Coastguard Worker }
50*ec779b8eSAndroid Build Coastguard Worker } else {
51*ec779b8eSAndroid Build Coastguard Worker // For APIs which don't appropriately pass attribution sources or packages, we need
52*ec779b8eSAndroid Build Coastguard Worker // to populate the package name with our best guess.
53*ec779b8eSAndroid Build Coastguard Worker const auto packageNames = VALUE_OR_RETURN(provider.getPackagesForUid(attr.uid));
54*ec779b8eSAndroid Build Coastguard Worker LOG_ALWAYS_FATAL_IF(packageNames.empty(), "%s BUG: empty package list from controller",
55*ec779b8eSAndroid Build Coastguard Worker __PRETTY_FUNCTION__);
56*ec779b8eSAndroid Build Coastguard Worker attr.packageName = std::move(packageNames[0]);
57*ec779b8eSAndroid Build Coastguard Worker return ValidatedAttributionSourceState{std::move(attr)};
58*ec779b8eSAndroid Build Coastguard Worker }
59*ec779b8eSAndroid Build Coastguard Worker }
60*ec779b8eSAndroid Build Coastguard Worker
61*ec779b8eSAndroid Build Coastguard Worker } // namespace com::android::media::permission
62