CheckSkillPermission previously only verified system-app status when
callerTokenId was 0, leaving the CliToolMgr-proxied path (non-zero
callerTokenId) without any verification. Add two layers of checks:
- Direct IPC caller must be a system ability (IsSACall)
- Indirect caller must hold every permission declared by the skill
(AccessTokenKit::VerifyAccessToken)
Also drop the callerTokenId=0 default and thread callerTokenId through
the ExecuteInAppSkill path so the direct-call variant is also covered.
Co-Authored-By: Agent
Signed-off-by: RuiChen_01 <chenrui193@huawei.com>
🤖 AI[100%] 👌 AI Adopted[100%] 🧑 Human[0%]
Co-authored-by: claude (glm-5.2) <ai@local>
When launching target ServiceExtension or UIAbility through skill
execution, use the real caller's tokenId for permission verification
instead of aimgr's SA identity. This avoids bypassing all permission
checks and eliminates the need to grant extra permissions to aimgr.
- Add SKILL_EXECUTE_PARAM_CALLER_TOKEN_ID Want parameter key
- Pass callerTokenId via Want from ExecuteInAppSkill(withTokenId)
- CheckStaticCfgPermission: detect skill path, skip SA shortcut,
verify permissions using caller's tokenId
- Derive callerUid from callerTokenId inside launch functions
via GetHapTokenInfo, no extra function parameters needed
Change-Id: I0f871ce89953afc3cf69548b75d125cee3ede5d1
Signed-off-by: RuiChen_01 <chenrui193@huawei.com>
Co-Authored-By: Agent
Signed-off-by: RuiChen_01 <chenrui193@huawei.com>
Reuse AMS EventHandler timeout framework to protect SkillExecuteManager
from stale EXECUTING records. When the target app never calls
completeArkTSScriptInApp, the record is automatically cleaned up after
timeout and the caller receives ERR_TIMED_OUT via callback.
Timeout = GetAppStartTimeoutTime() * SKILL_EXECUTE_TIMEOUT_MULTIPLE
(10s in production, 150s under ASAN), aligned with InsightIntent.
Also fix VerifyContext property name: ServiceExtension context uses
"extensionAbilityInfo" not "extensionInfo", which caused
completeArkTSScriptInApp to silently fail for ServiceExtension targets.
Co-Authored-By: Agent
Change-Id: I4e02afc0a75c069b1c5cb677fa81b469ef566f34
Signed-off-by: RuiChen_01 <chenrui193@huawei.com>