From d323c922ffa8af5438eed31ef61f0ae930a197b5 Mon Sep 17 00:00:00 2001 From: ryanlwlin Date: Thu, 3 Mar 2022 23:50:11 +0800 Subject: [PATCH] Revert "Adds install source checks for accessibility service" This reverts commit f1f2c847560e7ebb741909bd398c7d220d5078dc. The stragery is chaged, we don't need to check the installer nor if it is sytem app. We also delete the tests that are obsolete. Bug: 221318082 Test: AccessibilitySecurityPolicyTest, PolicyWarningUIControllerTest Change-Id: Ide89213dbf90cdb57001e5b05a2eeefc35f6adee --- core/res/res/values/symbols.xml | 2 - .../AccessibilitySecurityPolicy.java | 72 +---------- .../PolicyWarningUIController.java | 2 +- .../AccessibilitySecurityPolicyTest.java | 115 +----------------- .../PolicyWarningUIControllerTest.java | 3 +- 5 files changed, 9 insertions(+), 185 deletions(-) diff --git a/core/res/res/values/symbols.xml b/core/res/res/values/symbols.xml index df3cbf34c8f01..68ab39ccdc5b6 100644 --- a/core/res/res/values/symbols.xml +++ b/core/res/res/values/symbols.xml @@ -4644,8 +4644,6 @@ - - diff --git a/services/accessibility/java/com/android/server/accessibility/AccessibilitySecurityPolicy.java b/services/accessibility/java/com/android/server/accessibility/AccessibilitySecurityPolicy.java index e251bcc39f325..c637045589e7b 100644 --- a/services/accessibility/java/com/android/server/accessibility/AccessibilitySecurityPolicy.java +++ b/services/accessibility/java/com/android/server/accessibility/AccessibilitySecurityPolicy.java @@ -18,7 +18,6 @@ package com.android.server.accessibility; import static android.accessibilityservice.AccessibilityService.SoftKeyboardController.ENABLE_IME_FAIL_BY_ADMIN; import static android.accessibilityservice.AccessibilityService.SoftKeyboardController.ENABLE_IME_SUCCESS; -import static android.content.pm.PackageManagerInternal.PACKAGE_INSTALLER; import android.Manifest; import android.accessibilityservice.AccessibilityService; @@ -31,9 +30,7 @@ import android.app.admin.DevicePolicyManager; import android.appwidget.AppWidgetManagerInternal; import android.content.ComponentName; import android.content.Context; -import android.content.pm.InstallSourceInfo; import android.content.pm.PackageManager; -import android.content.pm.PackageManagerInternal; import android.content.pm.ResolveInfo; import android.content.pm.ServiceInfo; import android.content.pm.UserInfo; @@ -42,14 +39,12 @@ import android.os.IBinder; import android.os.Process; import android.os.UserHandle; import android.os.UserManager; -import android.text.TextUtils; import android.util.ArraySet; import android.util.Slog; import android.view.accessibility.AccessibilityEvent; import android.view.inputmethod.InputMethodInfo; import com.android.internal.util.ArrayUtils; -import com.android.server.LocalServices; import com.android.server.inputmethod.InputMethodManagerInternal; import com.android.settingslib.RestrictedLockUtils; @@ -734,7 +729,7 @@ public class AccessibilitySecurityPolicy { final AccessibilityServiceInfo a11yServiceInfo = boundServices.get( i).getServiceInfo(); final ComponentName service = a11yServiceInfo.getComponentName().clone(); - if (!isA11yCategoryService(a11yServiceInfo)) { + if (!a11yServiceInfo.isAccessibilityTool()) { tempNonA11yCategoryServices.add(service); if (mNonA11yCategoryServices.contains(service)) { mNonA11yCategoryServices.remove(service); @@ -794,69 +789,4 @@ public class AccessibilitySecurityPolicy { mPolicyWarningUIController.onEnabledServicesChangedLocked(userId, enabledServices); } - - /** - * Identifies whether the accessibility service is true and designed for accessibility. An - * accessibility service is considered as accessibility category if meets all conditions below: - *
    - *
  • {@link AccessibilityServiceInfo#isAccessibilityTool} is true
  • - *
  • is installed from the trusted install source
  • - *
- * - * @param serviceInfo The accessibility service's serviceInfo. - * @return Returns true if it is a true accessibility service. - */ - public boolean isA11yCategoryService(AccessibilityServiceInfo serviceInfo) { - if (!serviceInfo.isAccessibilityTool()) { - return false; - } - if (!serviceInfo.getResolveInfo().serviceInfo.applicationInfo.isSystemApp()) { - return hasTrustedSystemInstallSource( - serviceInfo.getResolveInfo().serviceInfo.packageName); - } - return true; - } - - /** Returns true if the {@code installedPackage} is installed from the trusted install source. - */ - private boolean hasTrustedSystemInstallSource(String installedPackage) { - try { - InstallSourceInfo installSourceInfo = mPackageManager.getInstallSourceInfo( - installedPackage); - if (installSourceInfo == null) { - return false; - } - final String installSourcePackageName = installSourceInfo.getInitiatingPackageName(); - if (installSourcePackageName == null || !mPackageManager.getPackageInfo( - installSourcePackageName, - 0).applicationInfo.isSystemApp()) { - return false; - } - return isTrustedInstallSource(installSourcePackageName); - } catch (PackageManager.NameNotFoundException e) { - Slog.w(LOG_TAG, "can't find the package's install source:" + installedPackage); - } - return false; - } - - /** Returns true if the {@code installerPackage} is a trusted install source. */ - private boolean isTrustedInstallSource(String installerPackage) { - final String[] allowedInstallingSources = mContext.getResources().getStringArray( - com.android.internal.R.array - .config_accessibility_allowed_install_source); - - if (allowedInstallingSources.length == 0) { - //Filters unwanted default installers if no allowed install sources. - String defaultInstaller = ArrayUtils.firstOrNull(LocalServices.getService( - PackageManagerInternal.class).getKnownPackageNames(PACKAGE_INSTALLER, - mCurrentUserId)); - return !TextUtils.equals(defaultInstaller, installerPackage); - } - for (int i = 0; i < allowedInstallingSources.length; i++) { - if (TextUtils.equals(allowedInstallingSources[i], installerPackage)) { - return true; - } - } - return false; - } } diff --git a/services/accessibility/java/com/android/server/accessibility/PolicyWarningUIController.java b/services/accessibility/java/com/android/server/accessibility/PolicyWarningUIController.java index 5080ca277445e..7c12ece472c2c 100644 --- a/services/accessibility/java/com/android/server/accessibility/PolicyWarningUIController.java +++ b/services/accessibility/java/com/android/server/accessibility/PolicyWarningUIController.java @@ -270,7 +270,7 @@ public class PolicyWarningUIController { final AccessibilityServiceInfo a11yServiceInfo = enabledServiceInfos.get(i); if (componentName.flattenToShortString().equals( a11yServiceInfo.getComponentName().flattenToShortString())) { - if (!mAccessibilitySecurityPolicy.isA11yCategoryService(a11yServiceInfo) + if (!a11yServiceInfo.isAccessibilityTool() && !mNotifiedA11yServices.contains(componentName)) { final CharSequence displayName = a11yServiceInfo.getResolveInfo().serviceInfo.loadLabel( diff --git a/services/tests/servicestests/src/com/android/server/accessibility/AccessibilitySecurityPolicyTest.java b/services/tests/servicestests/src/com/android/server/accessibility/AccessibilitySecurityPolicyTest.java index 46515468489d1..edacc165016f1 100644 --- a/services/tests/servicestests/src/com/android/server/accessibility/AccessibilitySecurityPolicyTest.java +++ b/services/tests/servicestests/src/com/android/server/accessibility/AccessibilitySecurityPolicyTest.java @@ -16,8 +16,6 @@ package com.android.server.accessibility; -import static android.content.pm.PackageManagerInternal.PACKAGE_INSTALLER; - import static androidx.test.platform.app.InstrumentationRegistry.getInstrumentation; import static junit.framework.Assert.assertFalse; @@ -45,14 +43,10 @@ import android.appwidget.AppWidgetManagerInternal; import android.content.ComponentName; import android.content.Context; import android.content.pm.ApplicationInfo; -import android.content.pm.InstallSourceInfo; -import android.content.pm.PackageInfo; -import android.content.pm.PackageInstaller; import android.content.pm.PackageManager; import android.content.pm.PackageManagerInternal; import android.content.pm.ResolveInfo; import android.content.pm.ServiceInfo; -import android.content.pm.SigningInfo; import android.os.Process; import android.os.UserHandle; import android.os.UserManager; @@ -63,7 +57,6 @@ import android.view.accessibility.AccessibilityEvent; import android.view.accessibility.AccessibilityWindowInfo; import com.android.internal.R; -import com.android.server.LocalServices; import org.junit.Before; import org.junit.Rule; @@ -150,22 +143,12 @@ public class AccessibilitySecurityPolicyTest { @Mock private AccessibilityServiceInfo mMockA11yServiceInfo; @Mock - private ResolveInfo mMockResolveInfo; - @Mock - private ServiceInfo mMockServiceInfo; - @Mock - private ApplicationInfo mMockApplicationInfo; - @Mock - private ApplicationInfo mMockSourceApplicationInfo; - @Mock - private PackageInfo mMockSourcePackageInfo; - @Mock private PolicyWarningUIController mPolicyWarningUIController; @Mock private PackageManagerInternal mPackageManagerInternal; @Before - public void setUp() throws PackageManager.NameNotFoundException { + public void setUp() { MockitoAnnotations.initMocks(this); mContext.setMockPackageManager(mMockPackageManager); mContext.addMockSystemService(Context.USER_SERVICE, mMockUserManager); @@ -612,8 +595,7 @@ public class AccessibilitySecurityPolicyTest { } @Test - public void onBoundServicesChanged_nonA11yTool_invokeAction() - throws PackageManager.NameNotFoundException { + public void onBoundServicesChanged_nonA11yTool_invokeAction() { final ArrayList boundServices = new ArrayList<>(); boundServices.add(mMockA11yServiceConnection); initServiceInfoAndConnection(TEST_COMPONENT_NAME, @@ -630,14 +612,11 @@ public class AccessibilitySecurityPolicyTest { } @Test - public void onBoundServicesChanged_sysA11yTool_noAction() - throws PackageManager.NameNotFoundException { + public void onBoundServicesChanged_isA11yTool_noAction() { final ArrayList boundServices = new ArrayList<>(); initServiceInfoAndConnection(TEST_COMPONENT_NAME, mMockA11yServiceConnection, - /* isAccessibilityTool= */ true, - /* isSystemApp= */true, - /* installSourceInfo= */ null); + /* isAccessibilityTool= */ true); boundServices.add(mMockA11yServiceConnection); mA11ySecurityPolicy.onBoundServicesChangedLocked(TEST_USER_ID, boundServices); @@ -649,63 +628,7 @@ public class AccessibilitySecurityPolicyTest { } @Test - public void onBoundServicesChanged_nonSysA11yToolFromAllowedInstallerInAllowedList_noAction() - throws PackageManager.NameNotFoundException { - final ArrayList boundServices = new ArrayList<>(); - final String allowedSourcePackageName = "com.allowed.install.package"; - mContext.getOrCreateTestableResources().addOverride(R.array - .config_accessibility_allowed_install_source, - new String[]{allowedSourcePackageName}); - // The allowed Installer should be system app in the allowed list. - InstallSourceInfo allowedSource = initInstallSourceInfo( - allowedSourcePackageName, /* isSystemApp= */ true); - initServiceInfoAndConnection(TEST_COMPONENT_NAME, - mMockA11yServiceConnection, - /* isAccessibilityTool= */ true, - /* isSystemApp= */ false, - allowedSource); - boundServices.add(mMockA11yServiceConnection); - - mA11ySecurityPolicy.onBoundServicesChangedLocked(TEST_USER_ID, boundServices); - verify(mPolicyWarningUIController, never()).onNonA11yCategoryServiceBound(anyInt(), any()); - - mA11ySecurityPolicy.onBoundServicesChangedLocked(TEST_USER_ID, new ArrayList<>()); - verify(mPolicyWarningUIController, never()).onNonA11yCategoryServiceUnbound(anyInt(), - any()); - } - - @Test - public void onBoundServicesChanged_nonSysA11yToolFromValidInstallerWithoutAllowedList_noAction() - throws PackageManager.NameNotFoundException { - final ArrayList boundServices = new ArrayList<>(); - final String validInstallerPackageName = "com.valid.install.package"; - final String defaultInstallerPackageName = "com.default.install.package"; - LocalServices.addService(PackageManagerInternal.class, mPackageManagerInternal); - when(mPackageManagerInternal.getKnownPackageNames(PACKAGE_INSTALLER, - TEST_USER_ID)).thenReturn(new String[]{defaultInstallerPackageName}); - mContext.getOrCreateTestableResources().addOverride(R.array - .config_accessibility_allowed_install_source, - new String[]{}); - // The valid Installer should be system app and not the default installer. - InstallSourceInfo validSource = initInstallSourceInfo( - validInstallerPackageName, /* isSystemApp= */ true); - initServiceInfoAndConnection(TEST_COMPONENT_NAME, - mMockA11yServiceConnection, /* isAccessibilityTool= */ true, - /* isSystemApp= */ false, - validSource); - boundServices.add(mMockA11yServiceConnection); - - mA11ySecurityPolicy.onBoundServicesChangedLocked(TEST_USER_ID, boundServices); - verify(mPolicyWarningUIController, never()).onNonA11yCategoryServiceBound(anyInt(), any()); - - mA11ySecurityPolicy.onBoundServicesChangedLocked(TEST_USER_ID, new ArrayList<>()); - verify(mPolicyWarningUIController, never()).onNonA11yCategoryServiceUnbound(anyInt(), - any()); - } - - @Test - public void onSwitchUser_oldUserHadAction_invokeActionForOldUser() - throws PackageManager.NameNotFoundException { + public void onSwitchUser_oldUserHadAction_invokeActionForOldUser() { final int newUserId = 2; final ArrayList boundServices = new ArrayList<>(); initServiceInfoAndConnection(TEST_COMPONENT_NAME, @@ -725,35 +648,9 @@ public class AccessibilitySecurityPolicyTest { private void initServiceInfoAndConnection(ComponentName componentName, AccessibilityServiceConnection connection, - boolean isAccessibilityTool) throws PackageManager.NameNotFoundException { - initServiceInfoAndConnection(componentName, connection, isAccessibilityTool, false, null); - } - - private void initServiceInfoAndConnection(ComponentName componentName, - AccessibilityServiceConnection connection, - boolean isAccessibilityTool, boolean isSystemApp, InstallSourceInfo installSourceInfo) - throws PackageManager.NameNotFoundException { + boolean isAccessibilityTool) { when(connection.getServiceInfo()).thenReturn(mMockA11yServiceInfo); when(mMockA11yServiceInfo.getComponentName()).thenReturn(componentName); when(mMockA11yServiceInfo.isAccessibilityTool()).thenReturn(isAccessibilityTool); - when(mMockA11yServiceInfo.getResolveInfo()).thenReturn(mMockResolveInfo); - mMockResolveInfo.serviceInfo = mMockServiceInfo; - mMockServiceInfo.applicationInfo = mMockApplicationInfo; - mMockServiceInfo.packageName = componentName.getPackageName(); - when(mMockApplicationInfo.isSystemApp()).thenReturn(isSystemApp); - when(mMockPackageManager.getInstallSourceInfo(componentName.getPackageName())).thenReturn( - installSourceInfo); - } - - private InstallSourceInfo initInstallSourceInfo(String packageName, boolean isSystemApp) - throws PackageManager.NameNotFoundException { - final InstallSourceInfo installSourceInfo = new InstallSourceInfo( - packageName, new SigningInfo(), null, - packageName, PackageInstaller.PACKAGE_SOURCE_UNSPECIFIED); - when(mMockPackageManager.getPackageInfo(packageName, 0)).thenReturn( - mMockSourcePackageInfo); - mMockSourcePackageInfo.applicationInfo = mMockSourceApplicationInfo; - when(mMockSourceApplicationInfo.isSystemApp()).thenReturn(isSystemApp); - return installSourceInfo; } } diff --git a/services/tests/servicestests/src/com/android/server/accessibility/PolicyWarningUIControllerTest.java b/services/tests/servicestests/src/com/android/server/accessibility/PolicyWarningUIControllerTest.java index b8535c22451fc..3cd967db3d917 100644 --- a/services/tests/servicestests/src/com/android/server/accessibility/PolicyWarningUIControllerTest.java +++ b/services/tests/servicestests/src/com/android/server/accessibility/PolicyWarningUIControllerTest.java @@ -116,8 +116,7 @@ public class PolicyWarningUIControllerTest { mMockResolveInfo.serviceInfo = mMockServiceInfo; when(mMockA11yServiceInfo.getResolveInfo()).thenReturn(mMockResolveInfo); when(mMockA11yServiceInfo.getComponentName()).thenReturn(TEST_COMPONENT_NAME); - when(mAccessibilitySecurityPolicy.isA11yCategoryService( - mMockA11yServiceInfo)).thenReturn(false); + when(mMockA11yServiceInfo.isAccessibilityTool()).thenReturn(false); mFakeNotificationController.onReceive(mContext, PolicyWarningUIController.createIntent(mContext, TEST_USER_ID,