Merge "Add a new wifi protection level"
This commit is contained in:
@@ -1756,6 +1756,7 @@ package android.content.pm {
|
||||
field public static final int PROTECTION_FLAG_SYSTEM_TEXT_CLASSIFIER = 65536; // 0x10000
|
||||
field public static final int PROTECTION_FLAG_TELEPHONY = 4194304; // 0x400000
|
||||
field public static final int PROTECTION_FLAG_WELLBEING = 131072; // 0x20000
|
||||
field public static final int PROTECTION_FLAG_WIFI = 8388608; // 0x800000
|
||||
field @Nullable public final String backgroundPermission;
|
||||
field @StringRes public int requestRes;
|
||||
}
|
||||
|
||||
@@ -773,6 +773,7 @@ package android.content.pm {
|
||||
field public static final int PROTECTION_FLAG_TELEPHONY = 4194304; // 0x400000
|
||||
field public static final int PROTECTION_FLAG_VENDOR_PRIVILEGED = 32768; // 0x8000
|
||||
field public static final int PROTECTION_FLAG_WELLBEING = 131072; // 0x20000
|
||||
field public static final int PROTECTION_FLAG_WIFI = 8388608; // 0x800000
|
||||
field @Nullable public final String backgroundPermission;
|
||||
}
|
||||
|
||||
|
||||
@@ -248,6 +248,17 @@ public class PermissionInfo extends PackageItemInfo implements Parcelable {
|
||||
@TestApi
|
||||
public static final int PROTECTION_FLAG_TELEPHONY = 0x400000;
|
||||
|
||||
/**
|
||||
* Additional flag for {@link #protectionLevel}, corresponding
|
||||
* to the <code>wifi</code> value of
|
||||
* {@link android.R.attr#protectionLevel}.
|
||||
*
|
||||
* @hide
|
||||
*/
|
||||
@SystemApi
|
||||
@TestApi
|
||||
public static final int PROTECTION_FLAG_WIFI = 0x800000;
|
||||
|
||||
/** @hide */
|
||||
@IntDef(flag = true, prefix = { "PROTECTION_FLAG_" }, value = {
|
||||
PROTECTION_FLAG_PRIVILEGED,
|
||||
@@ -270,6 +281,7 @@ public class PermissionInfo extends PackageItemInfo implements Parcelable {
|
||||
PROTECTION_FLAG_INCIDENT_REPORT_APPROVER,
|
||||
PROTECTION_FLAG_APP_PREDICTOR,
|
||||
PROTECTION_FLAG_TELEPHONY,
|
||||
PROTECTION_FLAG_WIFI,
|
||||
})
|
||||
@Retention(RetentionPolicy.SOURCE)
|
||||
public @interface ProtectionFlags {}
|
||||
@@ -516,6 +528,9 @@ public class PermissionInfo extends PackageItemInfo implements Parcelable {
|
||||
if ((level & PermissionInfo.PROTECTION_FLAG_TELEPHONY) != 0) {
|
||||
protLevel += "|telephony";
|
||||
}
|
||||
if ((level & PermissionInfo.PROTECTION_FLAG_WIFI) != 0) {
|
||||
protLevel += "|wifi";
|
||||
}
|
||||
return protLevel;
|
||||
}
|
||||
|
||||
|
||||
@@ -2955,7 +2955,7 @@
|
||||
@hide
|
||||
-->
|
||||
<permission android:name="android.permission.INTERNAL_SYSTEM_WINDOW"
|
||||
android:protectionLevel="signature|telephony" />
|
||||
android:protectionLevel="signature|telephony|wifi" />
|
||||
|
||||
<!-- @SystemApi Allows an application to use
|
||||
{@link android.view.WindowManager.LayoutsParams#SYSTEM_FLAG_HIDE_NON_SYSTEM_OVERLAY_WINDOWS}
|
||||
|
||||
@@ -298,6 +298,9 @@
|
||||
<!-- Additional flag from base permission type: this permission can be automatically
|
||||
granted to the system telephony apps -->
|
||||
<flag name="telephony" value="0x400000" />
|
||||
<!-- Additional flag from base permission type: this permission can be automatically
|
||||
granted to the system wifi app-->
|
||||
<flag name="wifi" value="0x800000" />
|
||||
</attr>
|
||||
|
||||
<!-- Flags indicating more context for a permission group. -->
|
||||
|
||||
@@ -3687,7 +3687,6 @@
|
||||
-->
|
||||
<string name="config_defaultWellbeingPackage" translatable="false"></string>
|
||||
|
||||
|
||||
<!-- The package name for the system telephony apps.
|
||||
This package must be trusted, as it will be granted with permissions with special telephony
|
||||
protection level. Note, framework by default support multiple telephony apps, each package
|
||||
@@ -3696,6 +3695,13 @@
|
||||
-->
|
||||
<string name="config_telephonyPackages" translatable="false">"com.android.phone,com.android.stk,com.android.providers.telephony,com.android.ons"</string>
|
||||
|
||||
<!-- The package name for the default system wifi app.
|
||||
This package must be trusted, as it has the permissions to control wifi
|
||||
connectivity on the device.
|
||||
Example: "com.android.wifi"
|
||||
-->
|
||||
<string name="config_wifiPackage" translatable="false">"com.android.wifi"</string>
|
||||
|
||||
<!-- The component name for the default system attention service.
|
||||
This service must be trusted, as it can be activated without explicit consent of the user.
|
||||
See android.attention.AttentionManagerService.
|
||||
|
||||
@@ -3468,6 +3468,7 @@
|
||||
<java-symbol type="string" name="config_defaultTextClassifierPackage" />
|
||||
<java-symbol type="string" name="config_defaultWellbeingPackage" />
|
||||
<java-symbol type="string" name="config_telephonyPackages" />
|
||||
<java-symbol type="string" name="config_wifiPackage" />
|
||||
<java-symbol type="string" name="config_defaultContentCaptureService" />
|
||||
<java-symbol type="string" name="config_defaultAugmentedAutofillService" />
|
||||
<java-symbol type="string" name="config_defaultAppPredictionService" />
|
||||
|
||||
@@ -359,6 +359,7 @@ applications that come with the platform
|
||||
<permission name="android.permission.CONNECTIVITY_INTERNAL"/>
|
||||
<permission name="android.permission.DUMP"/>
|
||||
<permission name="android.permission.INTERACT_ACROSS_USERS"/>
|
||||
<permission name="android.permission.INTERNAL_SYSTEM_WINDOW"/>
|
||||
<permission name="android.permission.LOCAL_MAC_ADDRESS"/>
|
||||
<permission name="android.permission.MANAGE_USERS"/>
|
||||
<permission name="android.permission.PACKAGE_USAGE_STATS"/>
|
||||
|
||||
@@ -60,6 +60,7 @@ public abstract class PackageManagerInternal {
|
||||
public static final int PACKAGE_INCIDENT_REPORT_APPROVER = 10;
|
||||
public static final int PACKAGE_APP_PREDICTOR = 11;
|
||||
public static final int PACKAGE_TELEPHONY = 12;
|
||||
public static final int PACKAGE_WIFI = 13;
|
||||
@IntDef(value = {
|
||||
PACKAGE_SYSTEM,
|
||||
PACKAGE_SETUP_WIZARD,
|
||||
@@ -74,6 +75,7 @@ public abstract class PackageManagerInternal {
|
||||
PACKAGE_INCIDENT_REPORT_APPROVER,
|
||||
PACKAGE_APP_PREDICTOR,
|
||||
PACKAGE_TELEPHONY,
|
||||
PACKAGE_WIFI,
|
||||
})
|
||||
@Retention(RetentionPolicy.SOURCE)
|
||||
public @interface KnownPackage {}
|
||||
|
||||
@@ -1604,6 +1604,7 @@ public class PackageManagerService extends IPackageManager.Stub
|
||||
final @Nullable String mAppPredictionServicePackage;
|
||||
final @Nullable String mIncidentReportApproverPackage;
|
||||
final @Nullable String[] mTelephonyPackages;
|
||||
final @Nullable String mWifiPackage;
|
||||
final @NonNull String mServicesSystemSharedLibraryPackageName;
|
||||
final @NonNull String mSharedSystemSharedLibraryPackageName;
|
||||
|
||||
@@ -3061,6 +3062,7 @@ public class PackageManagerService extends IPackageManager.Stub
|
||||
mAppPredictionServicePackage = getAppPredictionServicePackageName();
|
||||
mIncidentReportApproverPackage = getIncidentReportApproverPackageName();
|
||||
mTelephonyPackages = getTelephonyPackageNames();
|
||||
mWifiPackage = mContext.getString(R.string.config_wifiPackage);
|
||||
|
||||
// Now that we know all of the shared libraries, update all clients to have
|
||||
// the correct library paths.
|
||||
@@ -22990,6 +22992,8 @@ public class PackageManagerService extends IPackageManager.Stub
|
||||
return new String[]{mAppPredictionServicePackage};
|
||||
case PackageManagerInternal.PACKAGE_TELEPHONY:
|
||||
return mTelephonyPackages;
|
||||
case PackageManagerInternal.PACKAGE_WIFI:
|
||||
return new String[]{mWifiPackage};
|
||||
}
|
||||
return ArrayUtils.emptyArray(String.class);
|
||||
}
|
||||
|
||||
@@ -279,6 +279,9 @@ public final class BasePermission {
|
||||
public boolean isTelephony() {
|
||||
return (protectionLevel & PermissionInfo.PROTECTION_FLAG_TELEPHONY) != 0;
|
||||
}
|
||||
public boolean isWifi() {
|
||||
return (protectionLevel & PermissionInfo.PROTECTION_FLAG_WIFI) != 0;
|
||||
}
|
||||
|
||||
public void transfer(@NonNull String origPackageName, @NonNull String newPackageName) {
|
||||
if (!origPackageName.equals(sourcePackageName)) {
|
||||
|
||||
@@ -3282,6 +3282,13 @@ public class PermissionManagerService extends IPermissionManager.Stub {
|
||||
// Special permissions for the system telephony apps.
|
||||
allowed = true;
|
||||
}
|
||||
if (!allowed && bp.isWifi()
|
||||
&& ArrayUtils.contains(mPackageManagerInt.getKnownPackageNames(
|
||||
PackageManagerInternal.PACKAGE_WIFI, UserHandle.USER_SYSTEM),
|
||||
pkg.packageName)) {
|
||||
// Special permissions for the system wifi.
|
||||
allowed = true;
|
||||
}
|
||||
}
|
||||
return allowed;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user