Merge "add a new telephony protection level" am: cd953e939f
am: 2d98a66b18
Change-Id: Ie07cbd4d8c8350668a5d534fef9f1bd4863e43ab
This commit is contained in:
@@ -1746,6 +1746,7 @@ package android.content.pm {
|
|||||||
field public static final int PROTECTION_FLAG_INCIDENT_REPORT_APPROVER = 1048576; // 0x100000
|
field public static final int PROTECTION_FLAG_INCIDENT_REPORT_APPROVER = 1048576; // 0x100000
|
||||||
field public static final int PROTECTION_FLAG_OEM = 16384; // 0x4000
|
field public static final int PROTECTION_FLAG_OEM = 16384; // 0x4000
|
||||||
field public static final int PROTECTION_FLAG_SYSTEM_TEXT_CLASSIFIER = 65536; // 0x10000
|
field public static final int PROTECTION_FLAG_SYSTEM_TEXT_CLASSIFIER = 65536; // 0x10000
|
||||||
|
field public static final int PROTECTION_FLAG_TELEPHONY = 4194304; // 0x400000
|
||||||
field public static final int PROTECTION_FLAG_WELLBEING = 131072; // 0x20000
|
field public static final int PROTECTION_FLAG_WELLBEING = 131072; // 0x20000
|
||||||
field @Nullable public final String backgroundPermission;
|
field @Nullable public final String backgroundPermission;
|
||||||
field @StringRes public int requestRes;
|
field @StringRes public int requestRes;
|
||||||
|
|||||||
@@ -707,6 +707,7 @@ package android.content.pm {
|
|||||||
method @RequiresPermission(anyOf={"android.permission.GRANT_RUNTIME_PERMISSIONS", "android.permission.REVOKE_RUNTIME_PERMISSIONS", "android.permission.GET_RUNTIME_PERMISSIONS"}) public abstract int getPermissionFlags(@NonNull String, @NonNull String, @NonNull android.os.UserHandle);
|
method @RequiresPermission(anyOf={"android.permission.GRANT_RUNTIME_PERMISSIONS", "android.permission.REVOKE_RUNTIME_PERMISSIONS", "android.permission.GET_RUNTIME_PERMISSIONS"}) public abstract int getPermissionFlags(@NonNull String, @NonNull String, @NonNull android.os.UserHandle);
|
||||||
method @NonNull public abstract String getServicesSystemSharedLibraryPackageName();
|
method @NonNull public abstract String getServicesSystemSharedLibraryPackageName();
|
||||||
method @NonNull public abstract String getSharedSystemSharedLibraryPackageName();
|
method @NonNull public abstract String getSharedSystemSharedLibraryPackageName();
|
||||||
|
method @Nullable public String[] getTelephonyPackageNames();
|
||||||
method @Nullable public String getWellbeingPackageName();
|
method @Nullable public String getWellbeingPackageName();
|
||||||
method @RequiresPermission("android.permission.GRANT_RUNTIME_PERMISSIONS") public abstract void grantRuntimePermission(@NonNull String, @NonNull String, @NonNull android.os.UserHandle);
|
method @RequiresPermission("android.permission.GRANT_RUNTIME_PERMISSIONS") public abstract void grantRuntimePermission(@NonNull String, @NonNull String, @NonNull android.os.UserHandle);
|
||||||
method @RequiresPermission("android.permission.REVOKE_RUNTIME_PERMISSIONS") public abstract void revokeRuntimePermission(@NonNull String, @NonNull String, @NonNull android.os.UserHandle);
|
method @RequiresPermission("android.permission.REVOKE_RUNTIME_PERMISSIONS") public abstract void revokeRuntimePermission(@NonNull String, @NonNull String, @NonNull android.os.UserHandle);
|
||||||
@@ -739,6 +740,7 @@ package android.content.pm {
|
|||||||
field public static final int PROTECTION_FLAG_INCIDENT_REPORT_APPROVER = 1048576; // 0x100000
|
field public static final int PROTECTION_FLAG_INCIDENT_REPORT_APPROVER = 1048576; // 0x100000
|
||||||
field public static final int PROTECTION_FLAG_OEM = 16384; // 0x4000
|
field public static final int PROTECTION_FLAG_OEM = 16384; // 0x4000
|
||||||
field public static final int PROTECTION_FLAG_SYSTEM_TEXT_CLASSIFIER = 65536; // 0x10000
|
field public static final int PROTECTION_FLAG_SYSTEM_TEXT_CLASSIFIER = 65536; // 0x10000
|
||||||
|
field public static final int PROTECTION_FLAG_TELEPHONY = 4194304; // 0x400000
|
||||||
field public static final int PROTECTION_FLAG_VENDOR_PRIVILEGED = 32768; // 0x8000
|
field public static final int PROTECTION_FLAG_VENDOR_PRIVILEGED = 32768; // 0x8000
|
||||||
field public static final int PROTECTION_FLAG_WELLBEING = 131072; // 0x20000
|
field public static final int PROTECTION_FLAG_WELLBEING = 131072; // 0x20000
|
||||||
field @Nullable public final String backgroundPermission;
|
field @Nullable public final String backgroundPermission;
|
||||||
|
|||||||
@@ -3120,6 +3120,15 @@ public class ApplicationPackageManager extends PackageManager {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
@Override
|
||||||
|
public String[] getTelephonyPackageNames() {
|
||||||
|
try {
|
||||||
|
return mPM.getTelephonyPackageNames();
|
||||||
|
} catch (RemoteException e) {
|
||||||
|
throw e.rethrowAsRuntimeException();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
@Override
|
@Override
|
||||||
public String getSystemCaptionsServicePackageName() {
|
public String getSystemCaptionsServicePackageName() {
|
||||||
try {
|
try {
|
||||||
|
|||||||
@@ -754,6 +754,8 @@ interface IPackageManager {
|
|||||||
|
|
||||||
String getWellbeingPackageName();
|
String getWellbeingPackageName();
|
||||||
|
|
||||||
|
String[] getTelephonyPackageNames();
|
||||||
|
|
||||||
String getAppPredictionServicePackageName();
|
String getAppPredictionServicePackageName();
|
||||||
|
|
||||||
String getSystemCaptionsServicePackageName();
|
String getSystemCaptionsServicePackageName();
|
||||||
|
|||||||
@@ -7367,6 +7367,18 @@ public abstract class PackageManager {
|
|||||||
"getAppPredictionServicePackageName not implemented in subclass");
|
"getAppPredictionServicePackageName not implemented in subclass");
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return the system defined telephony package names, or null if there's none.
|
||||||
|
*
|
||||||
|
* @hide
|
||||||
|
*/
|
||||||
|
@Nullable
|
||||||
|
@TestApi
|
||||||
|
public String[] getTelephonyPackageNames() {
|
||||||
|
throw new UnsupportedOperationException(
|
||||||
|
"getTelephonyPackageNames not implemented in subclass");
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @return the system defined content capture service package name, or null if there's none.
|
* @return the system defined content capture service package name, or null if there's none.
|
||||||
*
|
*
|
||||||
|
|||||||
@@ -59,6 +59,7 @@ public abstract class PackageManagerInternal {
|
|||||||
public static final int PACKAGE_CONFIGURATOR = 9;
|
public static final int PACKAGE_CONFIGURATOR = 9;
|
||||||
public static final int PACKAGE_INCIDENT_REPORT_APPROVER = 10;
|
public static final int PACKAGE_INCIDENT_REPORT_APPROVER = 10;
|
||||||
public static final int PACKAGE_APP_PREDICTOR = 11;
|
public static final int PACKAGE_APP_PREDICTOR = 11;
|
||||||
|
public static final int PACKAGE_TELEPHONY = 12;
|
||||||
@IntDef(value = {
|
@IntDef(value = {
|
||||||
PACKAGE_SYSTEM,
|
PACKAGE_SYSTEM,
|
||||||
PACKAGE_SETUP_WIZARD,
|
PACKAGE_SETUP_WIZARD,
|
||||||
@@ -72,6 +73,7 @@ public abstract class PackageManagerInternal {
|
|||||||
PACKAGE_CONFIGURATOR,
|
PACKAGE_CONFIGURATOR,
|
||||||
PACKAGE_INCIDENT_REPORT_APPROVER,
|
PACKAGE_INCIDENT_REPORT_APPROVER,
|
||||||
PACKAGE_APP_PREDICTOR,
|
PACKAGE_APP_PREDICTOR,
|
||||||
|
PACKAGE_TELEPHONY,
|
||||||
})
|
})
|
||||||
@Retention(RetentionPolicy.SOURCE)
|
@Retention(RetentionPolicy.SOURCE)
|
||||||
public @interface KnownPackage {}
|
public @interface KnownPackage {}
|
||||||
@@ -715,10 +717,11 @@ public abstract class PackageManagerInternal {
|
|||||||
*/
|
*/
|
||||||
public abstract boolean isResolveActivityComponent(@NonNull ComponentInfo component);
|
public abstract boolean isResolveActivityComponent(@NonNull ComponentInfo component);
|
||||||
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Returns the package name for a known package.
|
* Returns a list of package names for a known package
|
||||||
*/
|
*/
|
||||||
public abstract @Nullable String getKnownPackageName(
|
public abstract @NonNull String[] getKnownPackageNames(
|
||||||
@KnownPackage int knownPackage, int userId);
|
@KnownPackage int knownPackage, int userId);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
|||||||
@@ -237,6 +237,17 @@ public class PermissionInfo extends PackageItemInfo implements Parcelable {
|
|||||||
@TestApi
|
@TestApi
|
||||||
public static final int PROTECTION_FLAG_APP_PREDICTOR = 0x200000;
|
public static final int PROTECTION_FLAG_APP_PREDICTOR = 0x200000;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Additional flag for {@link #protectionLevel}, corresponding
|
||||||
|
* to the <code>telephony</code> value of
|
||||||
|
* {@link android.R.attr#protectionLevel}.
|
||||||
|
*
|
||||||
|
* @hide
|
||||||
|
*/
|
||||||
|
@SystemApi
|
||||||
|
@TestApi
|
||||||
|
public static final int PROTECTION_FLAG_TELEPHONY = 0x400000;
|
||||||
|
|
||||||
/** @hide */
|
/** @hide */
|
||||||
@IntDef(flag = true, prefix = { "PROTECTION_FLAG_" }, value = {
|
@IntDef(flag = true, prefix = { "PROTECTION_FLAG_" }, value = {
|
||||||
PROTECTION_FLAG_PRIVILEGED,
|
PROTECTION_FLAG_PRIVILEGED,
|
||||||
@@ -258,6 +269,7 @@ public class PermissionInfo extends PackageItemInfo implements Parcelable {
|
|||||||
PROTECTION_FLAG_CONFIGURATOR,
|
PROTECTION_FLAG_CONFIGURATOR,
|
||||||
PROTECTION_FLAG_INCIDENT_REPORT_APPROVER,
|
PROTECTION_FLAG_INCIDENT_REPORT_APPROVER,
|
||||||
PROTECTION_FLAG_APP_PREDICTOR,
|
PROTECTION_FLAG_APP_PREDICTOR,
|
||||||
|
PROTECTION_FLAG_TELEPHONY,
|
||||||
})
|
})
|
||||||
@Retention(RetentionPolicy.SOURCE)
|
@Retention(RetentionPolicy.SOURCE)
|
||||||
public @interface ProtectionFlags {}
|
public @interface ProtectionFlags {}
|
||||||
@@ -501,6 +513,9 @@ public class PermissionInfo extends PackageItemInfo implements Parcelable {
|
|||||||
if ((level & PermissionInfo.PROTECTION_FLAG_APP_PREDICTOR) != 0) {
|
if ((level & PermissionInfo.PROTECTION_FLAG_APP_PREDICTOR) != 0) {
|
||||||
protLevel += "|appPredictor";
|
protLevel += "|appPredictor";
|
||||||
}
|
}
|
||||||
|
if ((level & PermissionInfo.PROTECTION_FLAG_TELEPHONY) != 0) {
|
||||||
|
protLevel += "|telephony";
|
||||||
|
}
|
||||||
return protLevel;
|
return protLevel;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -1626,7 +1626,7 @@
|
|||||||
@hide This should only be used by Settings and SystemUI.
|
@hide This should only be used by Settings and SystemUI.
|
||||||
-->
|
-->
|
||||||
<permission android:name="android.permission.NETWORK_SETTINGS"
|
<permission android:name="android.permission.NETWORK_SETTINGS"
|
||||||
android:protectionLevel="signature" />
|
android:protectionLevel="signature|telephony" />
|
||||||
|
|
||||||
<!-- Allows SetupWizard to call methods in Networking services
|
<!-- Allows SetupWizard to call methods in Networking services
|
||||||
<p>Not for use by any other third-party or privileged applications.
|
<p>Not for use by any other third-party or privileged applications.
|
||||||
@@ -2146,12 +2146,12 @@
|
|||||||
|
|
||||||
<!-- Must be required by a telephony data service to ensure that only the
|
<!-- Must be required by a telephony data service to ensure that only the
|
||||||
system can bind to it.
|
system can bind to it.
|
||||||
<p>Protection level: signature
|
<p>Protection level: signature|telephony
|
||||||
@SystemApi
|
@SystemApi
|
||||||
@hide
|
@hide
|
||||||
-->
|
-->
|
||||||
<permission android:name="android.permission.BIND_TELEPHONY_DATA_SERVICE"
|
<permission android:name="android.permission.BIND_TELEPHONY_DATA_SERVICE"
|
||||||
android:protectionLevel="signature" />
|
android:protectionLevel="signature|telephony" />
|
||||||
|
|
||||||
<!-- Must be required by a NetworkService to ensure that only the
|
<!-- Must be required by a NetworkService to ensure that only the
|
||||||
system can bind to it.
|
system can bind to it.
|
||||||
@@ -2172,11 +2172,11 @@
|
|||||||
|
|
||||||
<!-- @SystemApi Must be required by an EuiccService to ensure that only the system can bind to
|
<!-- @SystemApi Must be required by an EuiccService to ensure that only the system can bind to
|
||||||
it.
|
it.
|
||||||
<p>Protection level: signature
|
<p>Protection level: signature|telephony
|
||||||
@hide
|
@hide
|
||||||
-->
|
-->
|
||||||
<permission android:name="android.permission.BIND_EUICC_SERVICE"
|
<permission android:name="android.permission.BIND_EUICC_SERVICE"
|
||||||
android:protectionLevel="signature" />
|
android:protectionLevel="signature|telephony" />
|
||||||
|
|
||||||
<!-- ================================== -->
|
<!-- ================================== -->
|
||||||
<!-- Permissions for sdcard interaction -->
|
<!-- Permissions for sdcard interaction -->
|
||||||
@@ -2956,7 +2956,7 @@
|
|||||||
@hide
|
@hide
|
||||||
-->
|
-->
|
||||||
<permission android:name="android.permission.INTERNAL_SYSTEM_WINDOW"
|
<permission android:name="android.permission.INTERNAL_SYSTEM_WINDOW"
|
||||||
android:protectionLevel="signature" />
|
android:protectionLevel="signature|telephony" />
|
||||||
|
|
||||||
<!-- @SystemApi Allows an application to use
|
<!-- @SystemApi Allows an application to use
|
||||||
{@link android.view.WindowManager.LayoutsParams#SYSTEM_FLAG_HIDE_NON_SYSTEM_OVERLAY_WINDOWS}
|
{@link android.view.WindowManager.LayoutsParams#SYSTEM_FLAG_HIDE_NON_SYSTEM_OVERLAY_WINDOWS}
|
||||||
@@ -3736,7 +3736,7 @@
|
|||||||
@hide
|
@hide
|
||||||
-->
|
-->
|
||||||
<permission android:name="android.permission.DEVICE_POWER"
|
<permission android:name="android.permission.DEVICE_POWER"
|
||||||
android:protectionLevel="signature" />
|
android:protectionLevel="signature|telephony" />
|
||||||
|
|
||||||
<!-- Allows toggling battery saver on the system.
|
<!-- Allows toggling battery saver on the system.
|
||||||
Superseded by DEVICE_POWER permission. @hide @SystemApi
|
Superseded by DEVICE_POWER permission. @hide @SystemApi
|
||||||
@@ -3771,13 +3771,13 @@
|
|||||||
<p>Not for use by third-party applications.
|
<p>Not for use by third-party applications.
|
||||||
-->
|
-->
|
||||||
<permission android:name="android.permission.BROADCAST_SMS"
|
<permission android:name="android.permission.BROADCAST_SMS"
|
||||||
android:protectionLevel="signature" />
|
android:protectionLevel="signature|telephony" />
|
||||||
|
|
||||||
<!-- Allows an application to broadcast a WAP PUSH receipt notification.
|
<!-- Allows an application to broadcast a WAP PUSH receipt notification.
|
||||||
<p>Not for use by third-party applications.
|
<p>Not for use by third-party applications.
|
||||||
-->
|
-->
|
||||||
<permission android:name="android.permission.BROADCAST_WAP_PUSH"
|
<permission android:name="android.permission.BROADCAST_WAP_PUSH"
|
||||||
android:protectionLevel="signature" />
|
android:protectionLevel="signature|telephony" />
|
||||||
|
|
||||||
<!-- @SystemApi Allows an application to broadcast privileged networking requests.
|
<!-- @SystemApi Allows an application to broadcast privileged networking requests.
|
||||||
<p>Not for use by third-party applications.
|
<p>Not for use by third-party applications.
|
||||||
@@ -4392,13 +4392,13 @@
|
|||||||
{@link android.provider.BlockedNumberContract}.
|
{@link android.provider.BlockedNumberContract}.
|
||||||
@hide -->
|
@hide -->
|
||||||
<permission android:name="android.permission.READ_BLOCKED_NUMBERS"
|
<permission android:name="android.permission.READ_BLOCKED_NUMBERS"
|
||||||
android:protectionLevel="signature" />
|
android:protectionLevel="signature|telephony" />
|
||||||
|
|
||||||
<!-- Allows the holder to write blocked numbers. See
|
<!-- Allows the holder to write blocked numbers. See
|
||||||
{@link android.provider.BlockedNumberContract}.
|
{@link android.provider.BlockedNumberContract}.
|
||||||
@hide -->
|
@hide -->
|
||||||
<permission android:name="android.permission.WRITE_BLOCKED_NUMBERS"
|
<permission android:name="android.permission.WRITE_BLOCKED_NUMBERS"
|
||||||
android:protectionLevel="signature" />
|
android:protectionLevel="signature|telephony" />
|
||||||
|
|
||||||
<!-- Must be required by an {@link android.service.vr.VrListenerService}, to ensure that only
|
<!-- Must be required by an {@link android.service.vr.VrListenerService}, to ensure that only
|
||||||
the system can bind to it.
|
the system can bind to it.
|
||||||
|
|||||||
@@ -295,6 +295,9 @@
|
|||||||
<!-- Additional flag from base permission type: this permission can be automatically
|
<!-- Additional flag from base permission type: this permission can be automatically
|
||||||
granted to the system app predictor -->
|
granted to the system app predictor -->
|
||||||
<flag name="appPredictor" value="0x200000" />
|
<flag name="appPredictor" value="0x200000" />
|
||||||
|
<!-- Additional flag from base permission type: this permission can be automatically
|
||||||
|
granted to the system telephony apps -->
|
||||||
|
<flag name="telephony" value="0x400000" />
|
||||||
</attr>
|
</attr>
|
||||||
|
|
||||||
<!-- Flags indicating more context for a permission group. -->
|
<!-- Flags indicating more context for a permission group. -->
|
||||||
|
|||||||
@@ -3677,6 +3677,15 @@
|
|||||||
-->
|
-->
|
||||||
<string name="config_defaultWellbeingPackage" translatable="false"></string>
|
<string name="config_defaultWellbeingPackage" translatable="false"></string>
|
||||||
|
|
||||||
|
|
||||||
|
<!-- The package name for the system telephony apps.
|
||||||
|
This package must be trusted, as it will be granted with permissions with special telephony
|
||||||
|
protection level. Note, framework by default support multiple telephony apps, each package
|
||||||
|
name is separated by comma.
|
||||||
|
Example: "com.android.phone,com.android.stk,com.android.providers.telephony"
|
||||||
|
-->
|
||||||
|
<string name="config_telephonyPackages" translatable="false">"com.android.phone,com.android.stk,com.android.providers.telephony,com.android.ons"</string>
|
||||||
|
|
||||||
<!-- The component name for the default system attention service.
|
<!-- The component name for the default system attention service.
|
||||||
This service must be trusted, as it can be activated without explicit consent of the user.
|
This service must be trusted, as it can be activated without explicit consent of the user.
|
||||||
See android.attention.AttentionManagerService.
|
See android.attention.AttentionManagerService.
|
||||||
|
|||||||
@@ -3464,6 +3464,7 @@
|
|||||||
<java-symbol type="string" name="config_defaultAutofillService" />
|
<java-symbol type="string" name="config_defaultAutofillService" />
|
||||||
<java-symbol type="string" name="config_defaultTextClassifierPackage" />
|
<java-symbol type="string" name="config_defaultTextClassifierPackage" />
|
||||||
<java-symbol type="string" name="config_defaultWellbeingPackage" />
|
<java-symbol type="string" name="config_defaultWellbeingPackage" />
|
||||||
|
<java-symbol type="string" name="config_telephonyPackages" />
|
||||||
<java-symbol type="string" name="config_defaultContentCaptureService" />
|
<java-symbol type="string" name="config_defaultContentCaptureService" />
|
||||||
<java-symbol type="string" name="config_defaultAugmentedAutofillService" />
|
<java-symbol type="string" name="config_defaultAugmentedAutofillService" />
|
||||||
<java-symbol type="string" name="config_defaultAppPredictionService" />
|
<java-symbol type="string" name="config_defaultAppPredictionService" />
|
||||||
|
|||||||
@@ -49,6 +49,7 @@ import android.util.Pair;
|
|||||||
import android.util.Slog;
|
import android.util.Slog;
|
||||||
|
|
||||||
import com.android.internal.annotations.GuardedBy;
|
import com.android.internal.annotations.GuardedBy;
|
||||||
|
import com.android.internal.util.ArrayUtils;
|
||||||
import com.android.server.IntentResolver;
|
import com.android.server.IntentResolver;
|
||||||
|
|
||||||
import java.io.PrintWriter;
|
import java.io.PrintWriter;
|
||||||
@@ -375,8 +376,11 @@ public class ComponentResolver {
|
|||||||
addProvidersLocked(pkg, chatty);
|
addProvidersLocked(pkg, chatty);
|
||||||
addServicesLocked(pkg, chatty);
|
addServicesLocked(pkg, chatty);
|
||||||
}
|
}
|
||||||
final String setupWizardPackage = sPackageManagerInternal.getKnownPackageName(
|
// expect single setupwizard package
|
||||||
PACKAGE_SETUP_WIZARD, UserHandle.USER_SYSTEM);
|
final String setupWizardPackage = ArrayUtils.firstOrNull(
|
||||||
|
sPackageManagerInternal.getKnownPackageNames(
|
||||||
|
PACKAGE_SETUP_WIZARD, UserHandle.USER_SYSTEM));
|
||||||
|
|
||||||
for (int i = newIntents.size() - 1; i >= 0; --i) {
|
for (int i = newIntents.size() - 1; i >= 0; --i) {
|
||||||
final PackageParser.ActivityIntentInfo intentInfo = newIntents.get(i);
|
final PackageParser.ActivityIntentInfo intentInfo = newIntents.get(i);
|
||||||
final PackageParser.Package disabledPkg = sPackageManagerInternal
|
final PackageParser.Package disabledPkg = sPackageManagerInternal
|
||||||
@@ -410,8 +414,11 @@ public class ComponentResolver {
|
|||||||
final List<ActivityIntentInfo> protectedFilters = mProtectedFilters;
|
final List<ActivityIntentInfo> protectedFilters = mProtectedFilters;
|
||||||
mProtectedFilters = null;
|
mProtectedFilters = null;
|
||||||
|
|
||||||
final String setupWizardPackage = sPackageManagerInternal.getKnownPackageName(
|
// expect single setupwizard package
|
||||||
PACKAGE_SETUP_WIZARD, UserHandle.USER_SYSTEM);
|
final String setupWizardPackage = ArrayUtils.firstOrNull(
|
||||||
|
sPackageManagerInternal.getKnownPackageNames(
|
||||||
|
PACKAGE_SETUP_WIZARD, UserHandle.USER_SYSTEM));
|
||||||
|
|
||||||
if (DEBUG_FILTERS && setupWizardPackage == null) {
|
if (DEBUG_FILTERS && setupWizardPackage == null) {
|
||||||
Slog.i(TAG, "No setup wizard;"
|
Slog.i(TAG, "No setup wizard;"
|
||||||
+ " All protected intents capped to priority 0");
|
+ " All protected intents capped to priority 0");
|
||||||
|
|||||||
@@ -1408,6 +1408,7 @@ public class PackageManagerService extends IPackageManager.Stub
|
|||||||
final @Nullable String mConfiguratorPackage;
|
final @Nullable String mConfiguratorPackage;
|
||||||
final @Nullable String mAppPredictionServicePackage;
|
final @Nullable String mAppPredictionServicePackage;
|
||||||
final @Nullable String mIncidentReportApproverPackage;
|
final @Nullable String mIncidentReportApproverPackage;
|
||||||
|
final @Nullable String[] mTelephonyPackages;
|
||||||
final @NonNull String mServicesSystemSharedLibraryPackageName;
|
final @NonNull String mServicesSystemSharedLibraryPackageName;
|
||||||
final @NonNull String mSharedSystemSharedLibraryPackageName;
|
final @NonNull String mSharedSystemSharedLibraryPackageName;
|
||||||
|
|
||||||
@@ -3132,6 +3133,7 @@ public class PackageManagerService extends IPackageManager.Stub
|
|||||||
mContext.getString(R.string.config_deviceConfiguratorPackageName);
|
mContext.getString(R.string.config_deviceConfiguratorPackageName);
|
||||||
mAppPredictionServicePackage = getAppPredictionServicePackageName();
|
mAppPredictionServicePackage = getAppPredictionServicePackageName();
|
||||||
mIncidentReportApproverPackage = getIncidentReportApproverPackageName();
|
mIncidentReportApproverPackage = getIncidentReportApproverPackageName();
|
||||||
|
mTelephonyPackages = getTelephonyPackageNames();
|
||||||
|
|
||||||
// Now that we know all of the shared libraries, update all clients to have
|
// Now that we know all of the shared libraries, update all clients to have
|
||||||
// the correct library paths.
|
// the correct library paths.
|
||||||
@@ -21206,6 +21208,16 @@ public class PackageManagerService extends IPackageManager.Stub
|
|||||||
return mContext.getString(R.string.config_incidentReportApproverPackage);
|
return mContext.getString(R.string.config_incidentReportApproverPackage);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
@Override
|
||||||
|
public String[] getTelephonyPackageNames() {
|
||||||
|
String names = mContext.getString(R.string.config_telephonyPackages);
|
||||||
|
String[] telephonyPackageNames = null;
|
||||||
|
if (!TextUtils.isEmpty(names)) {
|
||||||
|
telephonyPackageNames = names.trim().split(",");
|
||||||
|
}
|
||||||
|
return telephonyPackageNames;
|
||||||
|
}
|
||||||
|
|
||||||
@Override
|
@Override
|
||||||
public void setApplicationEnabledSetting(String appPackageName,
|
public void setApplicationEnabledSetting(String appPackageName,
|
||||||
int newState, int flags, int userId, String callingPackage) {
|
int newState, int flags, int userId, String callingPackage) {
|
||||||
@@ -24363,34 +24375,36 @@ public class PackageManagerService extends IPackageManager.Stub
|
|||||||
}
|
}
|
||||||
|
|
||||||
@Override
|
@Override
|
||||||
public String getKnownPackageName(int knownPackage, int userId) {
|
public @NonNull String[] getKnownPackageNames(int knownPackage, int userId) {
|
||||||
switch(knownPackage) {
|
switch(knownPackage) {
|
||||||
case PackageManagerInternal.PACKAGE_BROWSER:
|
case PackageManagerInternal.PACKAGE_BROWSER:
|
||||||
return getDefaultBrowserPackageName(userId);
|
return new String[]{getDefaultBrowserPackageName(userId)};
|
||||||
case PackageManagerInternal.PACKAGE_INSTALLER:
|
case PackageManagerInternal.PACKAGE_INSTALLER:
|
||||||
return mRequiredInstallerPackage;
|
return new String[]{mRequiredInstallerPackage};
|
||||||
case PackageManagerInternal.PACKAGE_SETUP_WIZARD:
|
case PackageManagerInternal.PACKAGE_SETUP_WIZARD:
|
||||||
return mSetupWizardPackage;
|
return new String[]{mSetupWizardPackage};
|
||||||
case PackageManagerInternal.PACKAGE_SYSTEM:
|
case PackageManagerInternal.PACKAGE_SYSTEM:
|
||||||
return "android";
|
return new String[]{"android"};
|
||||||
case PackageManagerInternal.PACKAGE_VERIFIER:
|
case PackageManagerInternal.PACKAGE_VERIFIER:
|
||||||
return mRequiredVerifierPackage;
|
return new String[]{mRequiredVerifierPackage};
|
||||||
case PackageManagerInternal.PACKAGE_SYSTEM_TEXT_CLASSIFIER:
|
case PackageManagerInternal.PACKAGE_SYSTEM_TEXT_CLASSIFIER:
|
||||||
return mSystemTextClassifierPackage;
|
return new String[]{mSystemTextClassifierPackage};
|
||||||
case PackageManagerInternal.PACKAGE_PERMISSION_CONTROLLER:
|
case PackageManagerInternal.PACKAGE_PERMISSION_CONTROLLER:
|
||||||
return mRequiredPermissionControllerPackage;
|
return new String[]{mRequiredPermissionControllerPackage};
|
||||||
case PackageManagerInternal.PACKAGE_WELLBEING:
|
case PackageManagerInternal.PACKAGE_WELLBEING:
|
||||||
return mWellbeingPackage;
|
return new String[]{mWellbeingPackage};
|
||||||
case PackageManagerInternal.PACKAGE_DOCUMENTER:
|
case PackageManagerInternal.PACKAGE_DOCUMENTER:
|
||||||
return mDocumenterPackage;
|
return new String[]{mDocumenterPackage};
|
||||||
case PackageManagerInternal.PACKAGE_CONFIGURATOR:
|
case PackageManagerInternal.PACKAGE_CONFIGURATOR:
|
||||||
return mConfiguratorPackage;
|
return new String[]{mConfiguratorPackage};
|
||||||
case PackageManagerInternal.PACKAGE_INCIDENT_REPORT_APPROVER:
|
case PackageManagerInternal.PACKAGE_INCIDENT_REPORT_APPROVER:
|
||||||
return mIncidentReportApproverPackage;
|
return new String[]{mIncidentReportApproverPackage};
|
||||||
case PackageManagerInternal.PACKAGE_APP_PREDICTOR:
|
case PackageManagerInternal.PACKAGE_APP_PREDICTOR:
|
||||||
return mAppPredictionServicePackage;
|
return new String[]{mAppPredictionServicePackage};
|
||||||
|
case PackageManagerInternal.PACKAGE_TELEPHONY:
|
||||||
|
return mTelephonyPackages;
|
||||||
}
|
}
|
||||||
return null;
|
return ArrayUtils.emptyArray(String.class);
|
||||||
}
|
}
|
||||||
|
|
||||||
@Override
|
@Override
|
||||||
|
|||||||
@@ -276,6 +276,9 @@ public final class BasePermission {
|
|||||||
public boolean isAppPredictor() {
|
public boolean isAppPredictor() {
|
||||||
return (protectionLevel & PermissionInfo.PROTECTION_FLAG_APP_PREDICTOR) != 0;
|
return (protectionLevel & PermissionInfo.PROTECTION_FLAG_APP_PREDICTOR) != 0;
|
||||||
}
|
}
|
||||||
|
public boolean isTelephony() {
|
||||||
|
return (protectionLevel & PermissionInfo.PROTECTION_FLAG_TELEPHONY) != 0;
|
||||||
|
}
|
||||||
|
|
||||||
public void transfer(@NonNull String origPackageName, @NonNull String newPackageName) {
|
public void transfer(@NonNull String origPackageName, @NonNull String newPackageName) {
|
||||||
if (!origPackageName.equals(sourcePackageName)) {
|
if (!origPackageName.equals(sourcePackageName)) {
|
||||||
|
|||||||
@@ -437,17 +437,20 @@ public final class DefaultPermissionGrantPolicy {
|
|||||||
|
|
||||||
// Installer
|
// Installer
|
||||||
grantSystemFixedPermissionsToSystemPackage(
|
grantSystemFixedPermissionsToSystemPackage(
|
||||||
getKnownPackage(PackageManagerInternal.PACKAGE_INSTALLER, userId),
|
ArrayUtils.firstOrNull(getKnownPackages(
|
||||||
|
PackageManagerInternal.PACKAGE_INSTALLER, userId)),
|
||||||
userId, STORAGE_PERMISSIONS);
|
userId, STORAGE_PERMISSIONS);
|
||||||
|
|
||||||
// Verifier
|
// Verifier
|
||||||
final String verifier = getKnownPackage(PackageManagerInternal.PACKAGE_VERIFIER, userId);
|
final String verifier = ArrayUtils.firstOrNull(getKnownPackages(
|
||||||
|
PackageManagerInternal.PACKAGE_VERIFIER, userId));
|
||||||
grantSystemFixedPermissionsToSystemPackage(verifier, userId, STORAGE_PERMISSIONS);
|
grantSystemFixedPermissionsToSystemPackage(verifier, userId, STORAGE_PERMISSIONS);
|
||||||
grantPermissionsToSystemPackage(verifier, userId, PHONE_PERMISSIONS, SMS_PERMISSIONS);
|
grantPermissionsToSystemPackage(verifier, userId, PHONE_PERMISSIONS, SMS_PERMISSIONS);
|
||||||
|
|
||||||
// SetupWizard
|
// SetupWizard
|
||||||
grantPermissionsToSystemPackage(
|
grantPermissionsToSystemPackage(
|
||||||
getKnownPackage(PackageManagerInternal.PACKAGE_SETUP_WIZARD, userId), userId,
|
ArrayUtils.firstOrNull(getKnownPackages(
|
||||||
|
PackageManagerInternal.PACKAGE_SETUP_WIZARD, userId)), userId,
|
||||||
PHONE_PERMISSIONS, CONTACTS_PERMISSIONS, ALWAYS_LOCATION_PERMISSIONS,
|
PHONE_PERMISSIONS, CONTACTS_PERMISSIONS, ALWAYS_LOCATION_PERMISSIONS,
|
||||||
CAMERA_PERMISSIONS);
|
CAMERA_PERMISSIONS);
|
||||||
|
|
||||||
@@ -596,7 +599,8 @@ public final class DefaultPermissionGrantPolicy {
|
|||||||
userId, CONTACTS_PERMISSIONS, CALENDAR_PERMISSIONS);
|
userId, CONTACTS_PERMISSIONS, CALENDAR_PERMISSIONS);
|
||||||
|
|
||||||
// Browser
|
// Browser
|
||||||
String browserPackage = getKnownPackage(PackageManagerInternal.PACKAGE_BROWSER, userId);
|
String browserPackage = ArrayUtils.firstOrNull(getKnownPackages(
|
||||||
|
PackageManagerInternal.PACKAGE_BROWSER, userId));
|
||||||
if (browserPackage == null) {
|
if (browserPackage == null) {
|
||||||
browserPackage = getDefaultSystemHandlerActivityPackageForCategory(
|
browserPackage = getDefaultSystemHandlerActivityPackageForCategory(
|
||||||
Intent.CATEGORY_APP_BROWSER, userId);
|
Intent.CATEGORY_APP_BROWSER, userId);
|
||||||
@@ -761,8 +765,8 @@ public final class DefaultPermissionGrantPolicy {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
private String getKnownPackage(int knownPkgId, int userId) {
|
private @NonNull String[] getKnownPackages(int knownPkgId, int userId) {
|
||||||
return mServiceInternal.getKnownPackageName(knownPkgId, userId);
|
return mServiceInternal.getKnownPackageNames(knownPkgId, userId);
|
||||||
}
|
}
|
||||||
|
|
||||||
private void grantDefaultPermissionsToDefaultSystemDialerApp(
|
private void grantDefaultPermissionsToDefaultSystemDialerApp(
|
||||||
|
|||||||
@@ -1710,8 +1710,9 @@ public class PermissionManagerService {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
final String systemPackageName = mPackageManagerInt.getKnownPackageName(
|
// expect single system package
|
||||||
PackageManagerInternal.PACKAGE_SYSTEM, UserHandle.USER_SYSTEM);
|
String systemPackageName = ArrayUtils.firstOrNull(mPackageManagerInt.getKnownPackageNames(
|
||||||
|
PackageManagerInternal.PACKAGE_SYSTEM, UserHandle.USER_SYSTEM));
|
||||||
final PackageParser.Package systemPackage =
|
final PackageParser.Package systemPackage =
|
||||||
mPackageManagerInt.getPackage(systemPackageName);
|
mPackageManagerInt.getPackage(systemPackageName);
|
||||||
|
|
||||||
@@ -1827,18 +1828,19 @@ public class PermissionManagerService {
|
|||||||
// need a separate flag anymore. Hence we need to check which
|
// need a separate flag anymore. Hence we need to check which
|
||||||
// permissions are needed by the permission controller
|
// permissions are needed by the permission controller
|
||||||
if (!allowed && bp.isInstaller()
|
if (!allowed && bp.isInstaller()
|
||||||
&& (pkg.packageName.equals(mPackageManagerInt.getKnownPackageName(
|
&& ArrayUtils.contains(mPackageManagerInt.getKnownPackageNames(
|
||||||
PackageManagerInternal.PACKAGE_INSTALLER, UserHandle.USER_SYSTEM))
|
PackageManagerInternal.PACKAGE_INSTALLER, UserHandle.USER_SYSTEM),
|
||||||
|| pkg.packageName.equals(mPackageManagerInt.getKnownPackageName(
|
pkg.packageName) || ArrayUtils.contains(mPackageManagerInt.getKnownPackageNames(
|
||||||
PackageManagerInternal.PACKAGE_PERMISSION_CONTROLLER,
|
PackageManagerInternal.PACKAGE_PERMISSION_CONTROLLER,
|
||||||
UserHandle.USER_SYSTEM)))) {
|
UserHandle.USER_SYSTEM), pkg.packageName)) {
|
||||||
// If this permission is to be granted to the system installer and
|
// If this permission is to be granted to the system installer and
|
||||||
// this app is an installer, then it gets the permission.
|
// this app is an installer, then it gets the permission.
|
||||||
allowed = true;
|
allowed = true;
|
||||||
}
|
}
|
||||||
if (!allowed && bp.isVerifier()
|
if (!allowed && bp.isVerifier()
|
||||||
&& pkg.packageName.equals(mPackageManagerInt.getKnownPackageName(
|
&& ArrayUtils.contains(mPackageManagerInt.getKnownPackageNames(
|
||||||
PackageManagerInternal.PACKAGE_VERIFIER, UserHandle.USER_SYSTEM))) {
|
PackageManagerInternal.PACKAGE_VERIFIER, UserHandle.USER_SYSTEM),
|
||||||
|
pkg.packageName)) {
|
||||||
// If this permission is to be granted to the system verifier and
|
// If this permission is to be granted to the system verifier and
|
||||||
// this app is a verifier, then it gets the permission.
|
// this app is a verifier, then it gets the permission.
|
||||||
allowed = true;
|
allowed = true;
|
||||||
@@ -1854,53 +1856,64 @@ public class PermissionManagerService {
|
|||||||
allowed = origPermissions.hasInstallPermission(perm);
|
allowed = origPermissions.hasInstallPermission(perm);
|
||||||
}
|
}
|
||||||
if (!allowed && bp.isSetup()
|
if (!allowed && bp.isSetup()
|
||||||
&& pkg.packageName.equals(mPackageManagerInt.getKnownPackageName(
|
&& ArrayUtils.contains(mPackageManagerInt.getKnownPackageNames(
|
||||||
PackageManagerInternal.PACKAGE_SETUP_WIZARD, UserHandle.USER_SYSTEM))) {
|
PackageManagerInternal.PACKAGE_SETUP_WIZARD, UserHandle.USER_SYSTEM),
|
||||||
|
pkg.packageName)) {
|
||||||
// If this permission is to be granted to the system setup wizard and
|
// If this permission is to be granted to the system setup wizard and
|
||||||
// this app is a setup wizard, then it gets the permission.
|
// this app is a setup wizard, then it gets the permission.
|
||||||
allowed = true;
|
allowed = true;
|
||||||
}
|
}
|
||||||
if (!allowed && bp.isSystemTextClassifier()
|
if (!allowed && bp.isSystemTextClassifier()
|
||||||
&& pkg.packageName.equals(mPackageManagerInt.getKnownPackageName(
|
&& ArrayUtils.contains(mPackageManagerInt.getKnownPackageNames(
|
||||||
PackageManagerInternal.PACKAGE_SYSTEM_TEXT_CLASSIFIER,
|
PackageManagerInternal.PACKAGE_SYSTEM_TEXT_CLASSIFIER,
|
||||||
UserHandle.USER_SYSTEM))) {
|
UserHandle.USER_SYSTEM), pkg.packageName)) {
|
||||||
// Special permissions for the system default text classifier.
|
// Special permissions for the system default text classifier.
|
||||||
allowed = true;
|
allowed = true;
|
||||||
}
|
}
|
||||||
if (!allowed && bp.isConfigurator()
|
if (!allowed && bp.isConfigurator()
|
||||||
&& pkg.packageName.equals(mPackageManagerInt.getKnownPackageName(
|
&& ArrayUtils.contains(mPackageManagerInt.getKnownPackageNames(
|
||||||
PackageManagerInternal.PACKAGE_CONFIGURATOR,
|
PackageManagerInternal.PACKAGE_CONFIGURATOR,
|
||||||
UserHandle.USER_SYSTEM))) {
|
UserHandle.USER_SYSTEM), pkg.packageName)) {
|
||||||
// Special permissions for the device configurator.
|
// Special permissions for the device configurator.
|
||||||
allowed = true;
|
allowed = true;
|
||||||
}
|
}
|
||||||
if (!allowed && bp.isWellbeing()
|
if (!allowed && bp.isWellbeing()
|
||||||
&& pkg.packageName.equals(mPackageManagerInt.getKnownPackageName(
|
&& ArrayUtils.contains(mPackageManagerInt.getKnownPackageNames(
|
||||||
PackageManagerInternal.PACKAGE_WELLBEING, UserHandle.USER_SYSTEM))) {
|
PackageManagerInternal.PACKAGE_WELLBEING, UserHandle.USER_SYSTEM),
|
||||||
|
pkg.packageName)) {
|
||||||
// Special permission granted only to the OEM specified wellbeing app
|
// Special permission granted only to the OEM specified wellbeing app
|
||||||
allowed = true;
|
allowed = true;
|
||||||
}
|
}
|
||||||
if (!allowed && bp.isDocumenter()
|
if (!allowed && bp.isDocumenter()
|
||||||
&& pkg.packageName.equals(mPackageManagerInt.getKnownPackageName(
|
&& ArrayUtils.contains(mPackageManagerInt.getKnownPackageNames(
|
||||||
PackageManagerInternal.PACKAGE_DOCUMENTER, UserHandle.USER_SYSTEM))) {
|
PackageManagerInternal.PACKAGE_DOCUMENTER, UserHandle.USER_SYSTEM),
|
||||||
|
pkg.packageName)) {
|
||||||
// If this permission is to be granted to the documenter and
|
// If this permission is to be granted to the documenter and
|
||||||
// this app is the documenter, then it gets the permission.
|
// this app is the documenter, then it gets the permission.
|
||||||
allowed = true;
|
allowed = true;
|
||||||
}
|
}
|
||||||
if (!allowed && bp.isIncidentReportApprover()
|
if (!allowed && bp.isIncidentReportApprover()
|
||||||
&& pkg.packageName.equals(mPackageManagerInt.getKnownPackageName(
|
&& ArrayUtils.contains(mPackageManagerInt.getKnownPackageNames(
|
||||||
PackageManagerInternal.PACKAGE_INCIDENT_REPORT_APPROVER,
|
PackageManagerInternal.PACKAGE_INCIDENT_REPORT_APPROVER,
|
||||||
UserHandle.USER_SYSTEM))) {
|
UserHandle.USER_SYSTEM), pkg.packageName)) {
|
||||||
// If this permission is to be granted to the incident report approver and
|
// If this permission is to be granted to the incident report approver and
|
||||||
// this app is the incident report approver, then it gets the permission.
|
// this app is the incident report approver, then it gets the permission.
|
||||||
allowed = true;
|
allowed = true;
|
||||||
}
|
}
|
||||||
if (!allowed && bp.isAppPredictor()
|
if (!allowed && bp.isAppPredictor()
|
||||||
&& pkg.packageName.equals(mPackageManagerInt.getKnownPackageName(
|
&& ArrayUtils.contains(mPackageManagerInt.getKnownPackageNames(
|
||||||
PackageManagerInternal.PACKAGE_APP_PREDICTOR, UserHandle.USER_SYSTEM))) {
|
PackageManagerInternal.PACKAGE_APP_PREDICTOR, UserHandle.USER_SYSTEM),
|
||||||
|
pkg.packageName)) {
|
||||||
// Special permissions for the system app predictor.
|
// Special permissions for the system app predictor.
|
||||||
allowed = true;
|
allowed = true;
|
||||||
}
|
}
|
||||||
|
if (!allowed && bp.isTelephony()
|
||||||
|
&& ArrayUtils.contains(mPackageManagerInt.getKnownPackageNames(
|
||||||
|
PackageManagerInternal.PACKAGE_TELEPHONY, UserHandle.USER_SYSTEM),
|
||||||
|
pkg.packageName)) {
|
||||||
|
// Special permissions for the system telephony apps.
|
||||||
|
allowed = true;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
return allowed;
|
return allowed;
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user