From 35c2c13bd5c2e91892d731f37d39fd3463a7bf3c Mon Sep 17 00:00:00 2001 From: Charles Chen Date: Sun, 5 Feb 2023 00:14:14 +0000 Subject: [PATCH] Verify SandboxedDetectionServices for sharedIsolatedProcess Add checking of shared isolated tag for HotwordDetectionService and VisualQueryDetectionService. Bug: 265535257 Test: atest CtsVoiceInteractionTestCases Change-Id: I6e4933bb315f63ee2c7376c527cc0113321eac6a --- .../HotwordDetectionConnection.java | 7 ++++++- .../VoiceInteractionManagerServiceImpl.java | 20 +++++++++++++++++++ 2 files changed, 26 insertions(+), 1 deletion(-) diff --git a/services/voiceinteraction/java/com/android/server/voiceinteraction/HotwordDetectionConnection.java b/services/voiceinteraction/java/com/android/server/voiceinteraction/HotwordDetectionConnection.java index 3eabea67e8906..48a39e682340f 100644 --- a/services/voiceinteraction/java/com/android/server/voiceinteraction/HotwordDetectionConnection.java +++ b/services/voiceinteraction/java/com/android/server/voiceinteraction/HotwordDetectionConnection.java @@ -621,8 +621,13 @@ final class HotwordDetectionConnection { ServiceConnectionFactory(@NonNull Intent intent, boolean bindInstantServiceAllowed, int detectionServiceType) { mIntent = intent; - mBindingFlags = bindInstantServiceAllowed ? Context.BIND_ALLOW_INSTANT : 0; mDetectionServiceType = detectionServiceType; + int flags = bindInstantServiceAllowed ? Context.BIND_ALLOW_INSTANT : 0; + if (mVisualQueryDetectionComponentName != null + && mHotwordDetectionComponentName != null) { + flags |= Context.BIND_SHARED_ISOLATED_PROCESS; + } + mBindingFlags = flags; } ServiceConnection createLocked() { diff --git a/services/voiceinteraction/java/com/android/server/voiceinteraction/VoiceInteractionManagerServiceImpl.java b/services/voiceinteraction/java/com/android/server/voiceinteraction/VoiceInteractionManagerServiceImpl.java index 929e033315f78..62be2a555bc44 100644 --- a/services/voiceinteraction/java/com/android/server/voiceinteraction/VoiceInteractionManagerServiceImpl.java +++ b/services/voiceinteraction/java/com/android/server/voiceinteraction/VoiceInteractionManagerServiceImpl.java @@ -738,6 +738,13 @@ class VoiceInteractionManagerServiceImpl implements VoiceInteractionSessionConne } else { verifyDetectorForVisualQueryDetectionLocked(sharedMemory); } + if (!verifyProcessSharingLocked()) { + Slog.w(TAG, "Sandboxed detection service not in shared isolated process"); + throw new IllegalStateException("VisualQueryDetectionService or HotworDetectionService " + + "not in a shared isolated process. Please make sure to set " + + "android:allowSharedIsolatedProcess and android:isolatedProcess to be true " + + "and android:externalService to be false in the manifest file"); + } if (mHotwordDetectionConnection == null) { mHotwordDetectionConnection = new HotwordDetectionConnection(mServiceStub, mContext, @@ -931,6 +938,19 @@ class VoiceInteractionManagerServiceImpl implements VoiceInteractionSessionConne return (serviceInfo.flags & ServiceInfo.FLAG_ISOLATED_PROCESS) != 0 && (serviceInfo.flags & ServiceInfo.FLAG_EXTERNAL_SERVICE) == 0; } + @GuardedBy("this") + boolean verifyProcessSharingLocked() { + // only check this if both VQDS and HDS are declared in the app + ServiceInfo hotwordInfo = getServiceInfoLocked(mHotwordDetectionComponentName, mUser); + ServiceInfo visualQueryInfo = + getServiceInfoLocked(mVisualQueryDetectionComponentName, mUser); + if (hotwordInfo == null || visualQueryInfo == null) { + return true; + } + return (hotwordInfo.flags & ServiceInfo.FLAG_ALLOW_SHARED_ISOLATED_PROCESS) != 0 + && (visualQueryInfo.flags & ServiceInfo.FLAG_ALLOW_SHARED_ISOLATED_PROCESS) != 0; + } + void forceRestartHotwordDetector() { if (mHotwordDetectionConnection == null) {