From cc051fe9cfb890030b2972ec369d6115d35ba360 Mon Sep 17 00:00:00 2001 From: Patrick Baumann Date: Wed, 22 Jul 2020 11:48:57 -0700 Subject: [PATCH 1/3] Grant visibility even when not granting URI perm This change modifies the flow of uri permission grants to ensure that even when we're not granting URI permissions, we still take the opportunity to grant app visibility. This change also re-grants visibility based on any persisted URI grants at boot time. Bug: 161912313 Bug: 161721834 Change-Id: I077b263fc3dc01f3505c39fc0e36d3419bab3c5f (cherry picked from commit 9406f1dea8be7f1a72738990f536480bdf488a7c) --- .../server/uri/UriGrantsManagerService.java | 9 +++++++++ .../uri/UriGrantsManagerServiceTest.java | 19 +++++++++++++++++++ 2 files changed, 28 insertions(+) diff --git a/services/core/java/com/android/server/uri/UriGrantsManagerService.java b/services/core/java/com/android/server/uri/UriGrantsManagerService.java index 4b3ddd856c615..f14c3a53940d4 100644 --- a/services/core/java/com/android/server/uri/UriGrantsManagerService.java +++ b/services/core/java/com/android/server/uri/UriGrantsManagerService.java @@ -51,6 +51,7 @@ import android.app.AppGlobals; import android.app.GrantedUriPermission; import android.app.IUriGrantsManager; import android.content.ClipData; +import android.content.ComponentName; import android.content.ContentProvider; import android.content.ContentResolver; import android.content.Context; @@ -698,6 +699,11 @@ public class UriGrantsManagerService extends IUriGrantsManager.Stub { final UriPermission perm = findOrCreateUriPermissionLocked( sourcePkg, targetPkg, targetUid, grantUri); perm.initPersistedModes(modeFlags, createdTime); + mPmInternal.grantImplicitAccess( + targetUserId, null, + UserHandle.getAppId(targetUid), + pi.applicationInfo.uid, + false /* direct */); } } else { Slog.w(TAG, "Persisted grant for " + uri + " had source " + sourcePkg @@ -1171,6 +1177,9 @@ public class UriGrantsManagerService extends IUriGrantsManager.Stub { // grant, we can skip generating any bookkeeping; when any advanced // features have been requested, we proceed below to make sure the // provider supports granting permissions + mPmInternal.grantImplicitAccess( + UserHandle.getUserId(targetUid), null, + UserHandle.getAppId(targetUid), pi.applicationInfo.uid, false); return -1; } diff --git a/services/tests/servicestests/src/com/android/server/uri/UriGrantsManagerServiceTest.java b/services/tests/servicestests/src/com/android/server/uri/UriGrantsManagerServiceTest.java index 62b6a65cc6cbf..614949c91b9a8 100644 --- a/services/tests/servicestests/src/com/android/server/uri/UriGrantsManagerServiceTest.java +++ b/services/tests/servicestests/src/com/android/server/uri/UriGrantsManagerServiceTest.java @@ -43,11 +43,19 @@ import static org.junit.Assert.assertFalse; import static org.junit.Assert.assertNull; import static org.junit.Assert.assertTrue; import static org.junit.Assert.fail; +import static org.mockito.ArgumentMatchers.any; +import static org.mockito.ArgumentMatchers.anyBoolean; +import static org.mockito.ArgumentMatchers.anyInt; +import static org.mockito.ArgumentMatchers.eq; +import static org.mockito.ArgumentMatchers.isNull; +import static org.mockito.Mockito.never; +import static org.mockito.Mockito.verify; import android.content.ClipData; import android.content.Intent; import android.content.pm.ProviderInfo; import android.net.Uri; +import android.os.UserHandle; import android.util.ArraySet; import androidx.test.InstrumentationRegistry; @@ -62,6 +70,12 @@ public class UriGrantsManagerServiceTest { private UriGrantsMockContext mContext; private UriGrantsManagerInternal mService; + // we expect the following only during grant if a grant is expected + private void verifyNoVisibilityGrant() { + verify(mContext.mPmInternal, never()) + .grantImplicitAccess(anyInt(), any(), anyInt(), anyInt(), anyBoolean()); + } + @Before public void setUp() throws Exception { mContext = new UriGrantsMockContext(InstrumentationRegistry.getContext()); @@ -83,6 +97,7 @@ public class UriGrantsManagerServiceTest { assertEquals(UID_PRIMARY_SOCIAL, needed.targetUid); assertEquals(FLAG_READ, needed.flags); assertEquals(asSet(expectedGrant), needed.uris); + verifyNoVisibilityGrant(); } /** @@ -100,6 +115,7 @@ public class UriGrantsManagerServiceTest { assertEquals(UID_SECONDARY_SOCIAL, needed.targetUid); assertEquals(FLAG_READ, needed.flags); assertEquals(asSet(expectedGrant), needed.uris); + verifyNoVisibilityGrant(); } /** @@ -111,6 +127,8 @@ public class UriGrantsManagerServiceTest { final NeededUriGrants needed = mService.checkGrantUriPermissionFromIntent( intent, UID_PRIMARY_PUBLIC, PKG_SOCIAL, USER_PRIMARY); assertNull(needed); + verify(mContext.mPmInternal).grantImplicitAccess(eq(USER_PRIMARY), isNull(), eq( + UserHandle.getAppId(UID_PRIMARY_SOCIAL)), eq(UID_PRIMARY_PUBLIC), eq(false)); } /** @@ -128,6 +146,7 @@ public class UriGrantsManagerServiceTest { assertEquals(UID_SECONDARY_SOCIAL, needed.targetUid); assertEquals(FLAG_READ, needed.flags); assertEquals(asSet(expectedGrant), needed.uris); + verifyNoVisibilityGrant(); } /** From ed2c898865272fecf90a53ab5cbfaf81b1b5b5e5 Mon Sep 17 00:00:00 2001 From: Jing Ji Date: Tue, 21 Jul 2020 11:52:07 -0700 Subject: [PATCH 2/3] Java docs update: Advise not to include PII in setProcessStateSummary Bug: 161812603 Test: m -j offline-sdk-docs & manual verify the javadoc Change-Id: I741bbf7b83badcd7f1610f31bbd41a49b8b975fb (cherry picked from commit 3bda3bf8c6e06b910df1f219d983c803bcf49da6) --- core/java/android/app/ActivityManager.java | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/core/java/android/app/ActivityManager.java b/core/java/android/app/ActivityManager.java index acf6315ddc5df..1059a6f2e8685 100644 --- a/core/java/android/app/ActivityManager.java +++ b/core/java/android/app/ActivityManager.java @@ -3728,7 +3728,8 @@ public class ActivityManager { * manner, excessive calls to this API could result a {@link java.lang.RuntimeException}. *

* - * @param state The state data + * @param state The state data. To be advised, DO NOT include sensitive information/data + * (PII, SPII, or other sensitive user data) here. Maximum length is 128 bytes. */ public void setProcessStateSummary(@Nullable byte[] state) { try { From 61b6c2988821d6055a2d3b23eefddfd711f5c529 Mon Sep 17 00:00:00 2001 From: Yohei Yukawa Date: Fri, 17 Jul 2020 16:10:13 -0700 Subject: [PATCH 3/3] Fix missing IME switcher icon (w/ a hardware keyboard) This is a follow up CL to our previous CL [1], which aimed to adjust the timing to change navbar icons that depend on the IME window visibility. One thing we overlooked is that only InputMethodService#IME_VISIBLE needed to be cleared to keep the back button icon to behave as if the IME window was invisible. For the IME switcher icon to work as intended, the current protocol requires InputMethodService.IME_ACTIVE to remain to be set even when an IME window is invisible as long as there is an active session between the app and the IME. [1]: I4dc9d6513d0559156f7da39244f3fc5ebc952ed4 c22eec9d35e797417b8630fff178ec53e7c29b65 Fix: 160283619 Test: Manually done as follows: 1. Build aosp_coral-userdebug and flash it 2. make -j SoftKeyboard 3. adb install -r $OUT/system/app/SoftKeyboard/SoftKeyboard.apk 4. adb shell ime enable com.example.android.softkeyboard/.SoftKeyboard 5. adb shell ime set com.example.android.softkeyboard/.SoftKeyboard 6. Open any app that has an EditText 7. Focus in to the EditText. Make sure the IME shows up and the IME switcher icon is visible on the navbar. 8. Attach a hardware keyboard. Make sure that the IME becomes hidden while the IME switcher icon remains to be visible on the navbar. 9. Detach the hardware keyboard. Make sure that the IME switcher icon remains to be visible on the navbar. Change-Id: I4a9ddf514a32a221c2372be0ca166fbdac555932 Merged-In: I4a9ddf514a32a221c2372be0ca166fbdac555932 (cherry picked from commit 5749b51f8c739f8fa82760a8a7868e9b05aa9dd2) --- .../android/server/inputmethod/InputMethodManagerService.java | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/services/core/java/com/android/server/inputmethod/InputMethodManagerService.java b/services/core/java/com/android/server/inputmethod/InputMethodManagerService.java index 0154fe07a418f..254285dfbd415 100644 --- a/services/core/java/com/android/server/inputmethod/InputMethodManagerService.java +++ b/services/core/java/com/android/server/inputmethod/InputMethodManagerService.java @@ -2942,7 +2942,7 @@ public class InputMethodManagerService extends IInputMethodManager.Stub vis = 0; } if (!mCurPerceptible) { - vis = 0; + vis &= ~InputMethodService.IME_VISIBLE; } // mImeWindowVis should be updated before calling shouldShowImeSwitcherLocked(). final boolean needsToShowImeSwitcher = shouldShowImeSwitcherLocked(vis);