diff options
author | Christopher Tate <ctate@google.com> | 2012-08-13 17:36:14 -0700 |
---|---|---|
committer | Christopher Tate <ctate@google.com> | 2012-08-13 17:36:14 -0700 |
commit | aac71ff465399251fa8e830407f2917b986988d9 (patch) | |
tree | 12178251368dfef76d9d23ed8a493358e7ab514c /services/java/com/android/server/BackupManagerService.java | |
parent | 38cc2a5a3ad076fbbb0824a91f49730a4297549b (diff) | |
download | frameworks_base-aac71ff465399251fa8e830407f2917b986988d9.zip frameworks_base-aac71ff465399251fa8e830407f2917b986988d9.tar.gz frameworks_base-aac71ff465399251fa8e830407f2917b986988d9.tar.bz2 |
Don't back up / restore non-primary users' data
For now only the device owner "user" gets cloud backups. Also, only the
device owner account has access to local backup/restore.
Bug 6956438
Change-Id: I87d7ba5969e606c23f4214469f9bf2fd47a6c61b
Diffstat (limited to 'services/java/com/android/server/BackupManagerService.java')
-rw-r--r-- | services/java/com/android/server/BackupManagerService.java | 23 |
1 files changed, 23 insertions, 0 deletions
diff --git a/services/java/com/android/server/BackupManagerService.java b/services/java/com/android/server/BackupManagerService.java index 2167c49..4542840 100644 --- a/services/java/com/android/server/BackupManagerService.java +++ b/services/java/com/android/server/BackupManagerService.java @@ -65,6 +65,7 @@ import android.os.Process; import android.os.RemoteException; import android.os.ServiceManager; import android.os.SystemClock; +import android.os.UserId; import android.os.WorkSource; import android.os.storage.IMountService; import android.provider.Settings; @@ -4845,6 +4846,18 @@ class BackupManagerService extends IBackupManager.Stub { // ----- IBackupManager binder interface ----- public void dataChanged(final String packageName) { + final int callingUserHandle = UserId.getCallingUserId(); + if (callingUserHandle != UserId.USER_OWNER) { + // App is running under a non-owner user profile. For now, we do not back + // up data from secondary user profiles. + // TODO: backups for all user profiles. + if (MORE_DEBUG) { + Slog.v(TAG, "dataChanged(" + packageName + ") ignored because it's user " + + callingUserHandle); + } + return; + } + final HashSet<String> targets = dataChangedTargets(packageName); if (targets == null) { Slog.w(TAG, "dataChanged but no participant pkg='" + packageName + "'" @@ -4937,6 +4950,11 @@ class BackupManagerService extends IBackupManager.Stub { boolean doAllApps, boolean includeSystem, String[] pkgList) { mContext.enforceCallingPermission(android.Manifest.permission.BACKUP, "fullBackup"); + final int callingUserHandle = UserId.getCallingUserId(); + if (callingUserHandle != UserId.USER_OWNER) { + throw new IllegalStateException("Backup supported only for the device owner"); + } + // Validate if (!doAllApps) { if (!includeShared) { @@ -5001,6 +5019,11 @@ class BackupManagerService extends IBackupManager.Stub { public void fullRestore(ParcelFileDescriptor fd) { mContext.enforceCallingPermission(android.Manifest.permission.BACKUP, "fullRestore"); + final int callingUserHandle = UserId.getCallingUserId(); + if (callingUserHandle != UserId.USER_OWNER) { + throw new IllegalStateException("Restore supported only for the device owner"); + } + long oldId = Binder.clearCallingIdentity(); try { |