Reverted ContentCapture kill-switch mechanism.

Fixes: 121153631
Fixes: 121144410

Test: atest CtsContentCaptureServiceTestCases

Change-Id: Ic0e3fe6e93a8c2aff12eebcf9872f0082a361589
This commit is contained in:
Felipe Leme
2019-02-07 12:24:38 -08:00
parent 5e1e709992
commit 14ef461fc2
6 changed files with 62 additions and 70 deletions

View File

@@ -5709,6 +5709,7 @@ package android.provider {
method @RequiresPermission(android.Manifest.permission.WRITE_DEVICE_CONFIG) public static void resetToDefaults(int, @Nullable String);
method @RequiresPermission(android.Manifest.permission.WRITE_DEVICE_CONFIG) public static boolean setProperty(String, String, String, boolean);
field public static final String NAMESPACE_AUTOFILL = "autofill";
field public static final String NAMESPACE_CONTENT_CAPTURE = "content_capture";
field public static final String NAMESPACE_GAME_DRIVER = "game_driver";
field public static final String NAMESPACE_INPUT_NATIVE_BOOT = "input_native_boot";
field public static final String NAMESPACE_NETD_NATIVE = "netd_native";
@@ -5738,10 +5739,6 @@ package android.provider {
field public static final String SERVICE_ENABLED = "service_enabled";
}
public static interface DeviceConfig.ContentCapture {
field public static final String NAMESPACE = "content_capture";
}
public static interface DeviceConfig.DexBoot {
field public static final String NAMESPACE = "dex_boot";
field public static final String PRIV_APPS_OOB_ENABLED = "priv_apps_oob_enabled";

View File

@@ -1787,11 +1787,7 @@ package android.provider {
method @RequiresPermission("android.permission.READ_DEVICE_CONFIG") public static String getProperty(String, String);
method @RequiresPermission("android.permission.WRITE_DEVICE_CONFIG") public static void resetToDefaults(int, @Nullable String);
method @RequiresPermission("android.permission.WRITE_DEVICE_CONFIG") public static boolean setProperty(String, String, String, boolean);
}
public static interface DeviceConfig.ContentCapture {
field public static final String NAMESPACE = "content_capture";
field public static final String PROPERTY_CONTENTCAPTURE_ENABLED = "enable_contentcapture";
field public static final String NAMESPACE_CONTENT_CAPTURE = "content_capture";
}
public static interface DeviceConfig.Privacy {
@@ -2723,6 +2719,7 @@ package android.view.contentcapture {
public final class ContentCaptureManager {
method public boolean isContentCaptureFeatureEnabled();
method public void setContentCaptureFeatureEnabled(boolean);
field public static final String DEVICE_CONFIG_PROPERTY_SERVICE_EXPLICITLY_ENABLED = "service_explicitly_enabled";
}
public final class ViewNode extends android.app.assist.AssistStructure.ViewNode {

View File

@@ -72,39 +72,14 @@ public final class DeviceConfig {
public static final String NAMESPACE_AUTOFILL = "autofill";
/**
* ContentCapture-related properties definitions.
* Namespace for content capture feature used by on-device machine intelligence
* to provide suggestions in a privacy-safe manner.
*
* @hide
*/
@SystemApi
@TestApi
public interface ContentCapture {
String NAMESPACE = "content_capture";
/**
* Property used by {@code com.android.server.SystemServer} on start to decide whether
* the Content Capture service should be created or not.
*
* <p>Possible values are:
*
* <ul>
* <li>If set to {@code default}, it will only be set if the OEM provides and defines the
* service name by overlaying {@code config_defaultContentCaptureService} (this is the
* "default" mode)
* <li>If set to {@code always}, it will always be enabled, even when the resource is not
* overlaid (this is useful during development and to run the CTS tests on AOSP builds).
* <li>Otherwise, it's explicitly disabled (this could work as a "kill switch" so OEMs
* can disable it remotely in case of emergency by setting to something else (like
* {@code "false"}); notice that it's also disabled if the OEM doesn't explicitly set one
* of the values above).
* </ul>
*
* @hide
*/
// TODO(b/121153631): revert back to SERVICE_EXPLICITLY_ENABLED approach
@TestApi
String PROPERTY_CONTENTCAPTURE_ENABLED = "enable_contentcapture";
}
public static final String NAMESPACE_CONTENT_CAPTURE = "content_capture";
/**
* Namespace for all input-related features that are used at the native level.

View File

@@ -66,6 +66,25 @@ public final class ContentCaptureManager {
*/
private static final int SYNC_CALLS_TIMEOUT_MS = 5000;
/**
* DeviceConfig property used by {@code com.android.server.SystemServer} on start to decide
* whether the Content Capture service should be created or not
*
* <p>By default it should *NOT* be set (or set to {@code "default"}, so the decision is based
* on whether the OEM provides an implementation for the service), but it can be overridden to:
*
* <ul>
* <li>Provide a "kill switch" so OEMs can disable it remotely in case of emergency (when
* it's set to {@code "false"}).
* <li>Enable the CTS tests to be run on AOSP builds (when it's set to {@code "true"}).
* </ul>
*
* @hide
*/
@TestApi
public static final String DEVICE_CONFIG_PROPERTY_SERVICE_EXPLICITLY_ENABLED =
"service_explicitly_enabled";
private final Object mLock = new Object();
@NonNull

View File

@@ -93,7 +93,7 @@ public final class ContentCaptureManagerService extends
/**
* Global kill-switch based on value defined by
* {@link android.provider.DeviceConfig.ContentCapture#PROPERTY_CONTENTCAPTURE_ENABLED}.
* {@link ContentCaptureManager#DEVICE_CONFIG_PROPERTY_SERVICE_EXPLICITLY_ENABLED}.
*/
@GuardedBy("mLock")
@Nullable
@@ -103,9 +103,16 @@ public final class ContentCaptureManagerService extends
super(context, new FrameworkResourcesServiceNameResolver(context,
com.android.internal.R.string.config_defaultContentCaptureService),
UserManager.DISALLOW_CONTENT_CAPTURE);
DeviceConfig.addOnPropertyChangedListener(DeviceConfig.ContentCapture.NAMESPACE,
DeviceConfig.addOnPropertyChangedListener(DeviceConfig.NAMESPACE_CONTENT_CAPTURE,
ActivityThread.currentApplication().getMainExecutor(),
(namespace, name, value) -> setDisabledByDeviceConfig(value));
(namespace, key, value) -> {
if (!ContentCaptureManager.DEVICE_CONFIG_PROPERTY_SERVICE_EXPLICITLY_ENABLED
.equals(key)) {
Slog.i(mTag, "Ignoring change on " + key);
return;
}
setDisabledByDeviceConfig(value);
});
setDisabledByDeviceConfig();
// Sets which services are disabled
@@ -207,8 +214,8 @@ public final class ContentCaptureManagerService extends
}
private void setDisabledByDeviceConfig() {
final String value = DeviceConfig.getProperty(DeviceConfig.ContentCapture.NAMESPACE,
DeviceConfig.ContentCapture.PROPERTY_CONTENTCAPTURE_ENABLED);
final String value = DeviceConfig.getProperty(DeviceConfig.NAMESPACE_CONTENT_CAPTURE,
ContentCaptureManager.DEVICE_CONFIG_PROPERTY_SERVICE_EXPLICITLY_ENABLED);
setDisabledByDeviceConfig(value);
}
@@ -219,11 +226,10 @@ public final class ContentCaptureManagerService extends
final boolean newDisabledValue;
if (value != null && (value.equals("default") || value.equals("always"))) {
newDisabledValue = false;
if (debug) Slog.d(mTag, "setDisabledByDeviceConfig(): set to false on '" + value + "'");
} else {
if (value != null && value.equalsIgnoreCase("false")) {
newDisabledValue = true;
} else {
newDisabledValue = false;
}
synchronized (mLock) {

View File

@@ -64,6 +64,7 @@ import android.util.EventLog;
import android.util.Slog;
import android.util.TimingsTraceLog;
import android.view.WindowManager;
import android.view.contentcapture.ContentCaptureManager;
import android.view.inputmethod.InputMethodSystemProperty;
import com.android.internal.R;
@@ -2214,33 +2215,30 @@ public final class SystemServer {
}
private void startContentCaptureService(@NonNull Context context) {
// Check if it was explicitly enabled by DeviceConfig
final String settings = DeviceConfig.getProperty(DeviceConfig.ContentCapture.NAMESPACE,
DeviceConfig.ContentCapture.PROPERTY_CONTENTCAPTURE_ENABLED);
if (settings == null) {
// Better be safe than sorry...
Slog.d(TAG, "ContentCaptureService disabled because its not set by OEM");
return;
}
switch (settings) {
case "always":
// Should be used only during development
// First check if it was explicitly enabled by DeviceConfig
boolean explicitlySupported = false;
String settings = DeviceConfig.getProperty(DeviceConfig.NAMESPACE_CONTENT_CAPTURE,
ContentCaptureManager.DEVICE_CONFIG_PROPERTY_SERVICE_EXPLICITLY_ENABLED);
if (settings != null && !settings.equalsIgnoreCase("default")) {
explicitlySupported = Boolean.parseBoolean(settings);
if (explicitlySupported) {
Slog.d(TAG, "ContentCaptureService explicitly enabled by DeviceConfig");
break;
case "default":
// Default case: check if OEM overlaid the resource that defines the service.
final String serviceName = context.getString(
com.android.internal.R.string.config_defaultContentCaptureService);
if (TextUtils.isEmpty(serviceName)) {
Slog.d(TAG, "ContentCaptureService disabled because resource is not overlaid");
return;
}
break;
default:
// Kill switch for OEMs
Slog.d(TAG, "ContentCaptureService disabled because its set to: " + settings);
} else {
Slog.d(TAG, "ContentCaptureService explicitly disabled by DeviceConfig");
return;
}
}
// Then check if OEM overlaid the resource that defines the service.
if (!explicitlySupported) {
final String serviceName = context
.getString(com.android.internal.R.string.config_defaultContentCaptureService);
if (TextUtils.isEmpty(serviceName)) {
Slog.d(TAG, "ContentCaptureService disabled because resource is not overlaid");
return;
}
}
traceBeginAndSlog("StartContentCaptureService");
mSystemServiceManager.startService(CONTENT_CAPTURE_MANAGER_SERVICE_CLASS);
traceEnd();