From 45c183d201c99e06d5bff6a0077acedf8dd94109 Mon Sep 17 00:00:00 2001 From: Chen Xu Date: Mon, 7 Oct 2019 00:24:41 -0700 Subject: [PATCH] add a new telephony protection level for oems which take telephony mainline module, all telephony related apks will be signed with non-platform certificate. that said apks won't be able to grant platform signature permission. Solution is to add a new telephony protection level. Bug: 141479803 Test: cts & manual Change-Id: Ib3be016080d42fd76e7c131f4e44d815ce431e6e --- api/system-current.txt | 1 + api/test-current.txt | 2 + .../app/ApplicationPackageManager.java | 9 +++ .../android/content/pm/IPackageManager.aidl | 2 + .../android/content/pm/PackageManager.java | 12 ++++ .../android/content/pm/PermissionInfo.java | 15 +++++ core/res/AndroidManifest.xml | 22 +++---- core/res/res/values/attrs_manifest.xml | 3 + core/res/res/values/config.xml | 9 +++ core/res/res/values/symbols.xml | 1 + .../content/pm/PackageManagerInternal.java | 7 ++- .../android/server/pm/ComponentResolver.java | 15 +++-- .../server/pm/PackageManagerService.java | 42 ++++++++----- .../server/pm/permission/BasePermission.java | 3 + .../DefaultPermissionGrantPolicy.java | 16 +++-- .../permission/PermissionManagerService.java | 59 +++++++++++-------- 16 files changed, 158 insertions(+), 60 deletions(-) diff --git a/api/system-current.txt b/api/system-current.txt index 8ed79a3f23386..2b4b2fc08de62 100644 --- a/api/system-current.txt +++ b/api/system-current.txt @@ -1752,6 +1752,7 @@ package android.content.pm { field public static final int PROTECTION_FLAG_INCIDENT_REPORT_APPROVER = 1048576; // 0x100000 field public static final int PROTECTION_FLAG_OEM = 16384; // 0x4000 field public static final int PROTECTION_FLAG_SYSTEM_TEXT_CLASSIFIER = 65536; // 0x10000 + field public static final int PROTECTION_FLAG_TELEPHONY = 4194304; // 0x400000 field public static final int PROTECTION_FLAG_WELLBEING = 131072; // 0x20000 field @Nullable public final String backgroundPermission; field @StringRes public int requestRes; diff --git a/api/test-current.txt b/api/test-current.txt index 70837a84adfdb..482f36cf0c4a8 100644 --- a/api/test-current.txt +++ b/api/test-current.txt @@ -730,6 +730,7 @@ package android.content.pm { method @RequiresPermission(anyOf={"android.permission.GRANT_RUNTIME_PERMISSIONS", "android.permission.REVOKE_RUNTIME_PERMISSIONS", "android.permission.GET_RUNTIME_PERMISSIONS"}) public abstract int getPermissionFlags(@NonNull String, @NonNull String, @NonNull android.os.UserHandle); method @NonNull public abstract String getServicesSystemSharedLibraryPackageName(); method @NonNull public abstract String getSharedSystemSharedLibraryPackageName(); + method @Nullable public String[] getTelephonyPackageNames(); method @Nullable public String getWellbeingPackageName(); method @RequiresPermission("android.permission.GRANT_RUNTIME_PERMISSIONS") public abstract void grantRuntimePermission(@NonNull String, @NonNull String, @NonNull android.os.UserHandle); method @RequiresPermission("android.permission.OBSERVE_GRANT_REVOKE_PERMISSIONS") public abstract void removeOnPermissionsChangeListener(@NonNull android.content.pm.PackageManager.OnPermissionsChangedListener); @@ -768,6 +769,7 @@ package android.content.pm { field public static final int PROTECTION_FLAG_INCIDENT_REPORT_APPROVER = 1048576; // 0x100000 field public static final int PROTECTION_FLAG_OEM = 16384; // 0x4000 field public static final int PROTECTION_FLAG_SYSTEM_TEXT_CLASSIFIER = 65536; // 0x10000 + field public static final int PROTECTION_FLAG_TELEPHONY = 4194304; // 0x400000 field public static final int PROTECTION_FLAG_VENDOR_PRIVILEGED = 32768; // 0x8000 field public static final int PROTECTION_FLAG_WELLBEING = 131072; // 0x20000 field @Nullable public final String backgroundPermission; diff --git a/core/java/android/app/ApplicationPackageManager.java b/core/java/android/app/ApplicationPackageManager.java index 86bf20a57eeca..03ef286c48c13 100644 --- a/core/java/android/app/ApplicationPackageManager.java +++ b/core/java/android/app/ApplicationPackageManager.java @@ -3159,6 +3159,15 @@ public class ApplicationPackageManager extends PackageManager { } } + @Override + public String[] getTelephonyPackageNames() { + try { + return mPM.getTelephonyPackageNames(); + } catch (RemoteException e) { + throw e.rethrowAsRuntimeException(); + } + } + @Override public String getSystemCaptionsServicePackageName() { try { diff --git a/core/java/android/content/pm/IPackageManager.aidl b/core/java/android/content/pm/IPackageManager.aidl index 19d8edfa38848..1d78e2c36cd3d 100644 --- a/core/java/android/content/pm/IPackageManager.aidl +++ b/core/java/android/content/pm/IPackageManager.aidl @@ -682,6 +682,8 @@ interface IPackageManager { String getWellbeingPackageName(); + String[] getTelephonyPackageNames(); + String getAppPredictionServicePackageName(); String getSystemCaptionsServicePackageName(); diff --git a/core/java/android/content/pm/PackageManager.java b/core/java/android/content/pm/PackageManager.java index 9513ce802813f..f302d5949feb4 100644 --- a/core/java/android/content/pm/PackageManager.java +++ b/core/java/android/content/pm/PackageManager.java @@ -7415,6 +7415,18 @@ public abstract class PackageManager { "getAppPredictionServicePackageName not implemented in subclass"); } + /** + * @return the system defined telephony package names, or null if there's none. + * + * @hide + */ + @Nullable + @TestApi + public String[] getTelephonyPackageNames() { + throw new UnsupportedOperationException( + "getTelephonyPackageNames not implemented in subclass"); + } + /** * @return the system defined content capture service package name, or null if there's none. * diff --git a/core/java/android/content/pm/PermissionInfo.java b/core/java/android/content/pm/PermissionInfo.java index dd5c6a53cc20f..c77c53f387e22 100644 --- a/core/java/android/content/pm/PermissionInfo.java +++ b/core/java/android/content/pm/PermissionInfo.java @@ -237,6 +237,17 @@ public class PermissionInfo extends PackageItemInfo implements Parcelable { @TestApi public static final int PROTECTION_FLAG_APP_PREDICTOR = 0x200000; + /** + * Additional flag for {@link #protectionLevel}, corresponding + * to the telephony value of + * {@link android.R.attr#protectionLevel}. + * + * @hide + */ + @SystemApi + @TestApi + public static final int PROTECTION_FLAG_TELEPHONY = 0x400000; + /** @hide */ @IntDef(flag = true, prefix = { "PROTECTION_FLAG_" }, value = { PROTECTION_FLAG_PRIVILEGED, @@ -258,6 +269,7 @@ public class PermissionInfo extends PackageItemInfo implements Parcelable { PROTECTION_FLAG_CONFIGURATOR, PROTECTION_FLAG_INCIDENT_REPORT_APPROVER, PROTECTION_FLAG_APP_PREDICTOR, + PROTECTION_FLAG_TELEPHONY, }) @Retention(RetentionPolicy.SOURCE) public @interface ProtectionFlags {} @@ -501,6 +513,9 @@ public class PermissionInfo extends PackageItemInfo implements Parcelable { if ((level & PermissionInfo.PROTECTION_FLAG_APP_PREDICTOR) != 0) { protLevel += "|appPredictor"; } + if ((level & PermissionInfo.PROTECTION_FLAG_TELEPHONY) != 0) { + protLevel += "|telephony"; + } return protLevel; } diff --git a/core/res/AndroidManifest.xml b/core/res/AndroidManifest.xml index b030b33daf5e3..b3372a6eea068 100644 --- a/core/res/AndroidManifest.xml +++ b/core/res/AndroidManifest.xml @@ -1624,7 +1624,7 @@ @hide This should only be used by Settings and SystemUI. --> + android:protectionLevel="signature|telephony" /> + android:protectionLevel="signature|telephony" /> + android:protectionLevel="signature|telephony" /> @@ -2955,7 +2955,7 @@ @hide --> + android:protectionLevel="signature|telephony" /> + android:protectionLevel="signature|telephony" /> + android:protectionLevel="signature|telephony" /> + android:protectionLevel="signature|telephony" /> + android:protectionLevel="signature|telephony" /> + android:protectionLevel="signature|telephony" /> + + diff --git a/core/res/res/values/config.xml b/core/res/res/values/config.xml index 3fef7a2dffae1..531023fb41bf1 100644 --- a/core/res/res/values/config.xml +++ b/core/res/res/values/config.xml @@ -3687,6 +3687,15 @@ --> + + + "com.android.phone,com.android.stk,com.android.providers.telephony,com.android.ons" +