Merge "Forbid granting access to NLSes with too-long component names" into tm-dev am: b70ba506ef am: 5002b7bd7b am: 29f8115755
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/23733070 Change-Id: I44c967e947ea34fe68590f0fde09321f88f91ed5 Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
This commit is contained in:
@@ -571,6 +571,12 @@ public class NotificationManager {
|
|||||||
*/
|
*/
|
||||||
public static final int BUBBLE_PREFERENCE_SELECTED = 2;
|
public static final int BUBBLE_PREFERENCE_SELECTED = 2;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Maximum length of the component name of a registered NotificationListenerService.
|
||||||
|
* @hide
|
||||||
|
*/
|
||||||
|
public static int MAX_SERVICE_COMPONENT_NAME_LENGTH = 500;
|
||||||
|
|
||||||
@UnsupportedAppUsage
|
@UnsupportedAppUsage
|
||||||
private static INotificationManager sService;
|
private static INotificationManager sService;
|
||||||
|
|
||||||
|
|||||||
@@ -243,7 +243,9 @@ public class RestrictedSwitchPreference extends SwitchPreference {
|
|||||||
return mHelper != null ? mHelper.packageName : null;
|
return mHelper != null ? mHelper.packageName : null;
|
||||||
}
|
}
|
||||||
|
|
||||||
public void updateState(@NonNull String packageName, int uid, boolean isEnabled) {
|
/** Updates enabled state based on associated package. */
|
||||||
|
public void updateState(
|
||||||
|
@NonNull String packageName, int uid, boolean isEnableAllowed, boolean isEnabled) {
|
||||||
mHelper.updatePackageDetails(packageName, uid);
|
mHelper.updatePackageDetails(packageName, uid);
|
||||||
if (mAppOpsManager == null) {
|
if (mAppOpsManager == null) {
|
||||||
mAppOpsManager = getContext().getSystemService(AppOpsManager.class);
|
mAppOpsManager = getContext().getSystemService(AppOpsManager.class);
|
||||||
@@ -254,7 +256,9 @@ public class RestrictedSwitchPreference extends SwitchPreference {
|
|||||||
final boolean ecmEnabled = getContext().getResources().getBoolean(
|
final boolean ecmEnabled = getContext().getResources().getBoolean(
|
||||||
com.android.internal.R.bool.config_enhancedConfirmationModeEnabled);
|
com.android.internal.R.bool.config_enhancedConfirmationModeEnabled);
|
||||||
final boolean appOpsAllowed = !ecmEnabled || mode == AppOpsManager.MODE_ALLOWED;
|
final boolean appOpsAllowed = !ecmEnabled || mode == AppOpsManager.MODE_ALLOWED;
|
||||||
if (isEnabled) {
|
if (!isEnableAllowed && !isEnabled) {
|
||||||
|
setEnabled(false);
|
||||||
|
} else if (isEnabled) {
|
||||||
setEnabled(true);
|
setEnabled(true);
|
||||||
} else if (appOpsAllowed && isDisabledByAppOps()) {
|
} else if (appOpsAllowed && isDisabledByAppOps()) {
|
||||||
setEnabled(true);
|
setEnabled(true);
|
||||||
|
|||||||
@@ -5486,6 +5486,11 @@ public class NotificationManagerService extends SystemService {
|
|||||||
boolean granted, boolean userSet) {
|
boolean granted, boolean userSet) {
|
||||||
Objects.requireNonNull(listener);
|
Objects.requireNonNull(listener);
|
||||||
checkNotificationListenerAccess();
|
checkNotificationListenerAccess();
|
||||||
|
if (granted && listener.flattenToString().length()
|
||||||
|
> NotificationManager.MAX_SERVICE_COMPONENT_NAME_LENGTH) {
|
||||||
|
throw new IllegalArgumentException(
|
||||||
|
"Component name too long: " + listener.flattenToString());
|
||||||
|
}
|
||||||
if (!userSet && isNotificationListenerAccessUserSet(listener)) {
|
if (!userSet && isNotificationListenerAccessUserSet(listener)) {
|
||||||
// Don't override user's choice
|
// Don't override user's choice
|
||||||
return;
|
return;
|
||||||
|
|||||||
@@ -1049,7 +1049,11 @@ public class VrManagerService extends SystemService
|
|||||||
|
|
||||||
for (ComponentName c : possibleServices) {
|
for (ComponentName c : possibleServices) {
|
||||||
if (Objects.equals(c.getPackageName(), pkg)) {
|
if (Objects.equals(c.getPackageName(), pkg)) {
|
||||||
nm.setNotificationListenerAccessGrantedForUser(c, userId, true);
|
try {
|
||||||
|
nm.setNotificationListenerAccessGrantedForUser(c, userId, true);
|
||||||
|
} catch (Exception e) {
|
||||||
|
Slog.w(TAG, "Could not grant NLS access to package " + pkg, e);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -84,6 +84,7 @@ import static junit.framework.Assert.assertNull;
|
|||||||
import static junit.framework.Assert.assertTrue;
|
import static junit.framework.Assert.assertTrue;
|
||||||
import static junit.framework.Assert.fail;
|
import static junit.framework.Assert.fail;
|
||||||
|
|
||||||
|
import static org.junit.Assert.assertThrows;
|
||||||
import static org.mockito.ArgumentMatchers.isNull;
|
import static org.mockito.ArgumentMatchers.isNull;
|
||||||
import static org.mockito.Matchers.anyBoolean;
|
import static org.mockito.Matchers.anyBoolean;
|
||||||
import static org.mockito.Matchers.anyLong;
|
import static org.mockito.Matchers.anyLong;
|
||||||
@@ -3847,6 +3848,30 @@ public class NotificationManagerServiceTest extends UiServiceTestCase {
|
|||||||
any(), anyInt(), anyBoolean(), anyBoolean(), anyBoolean());
|
any(), anyInt(), anyBoolean(), anyBoolean(), anyBoolean());
|
||||||
}
|
}
|
||||||
|
|
||||||
|
@Test
|
||||||
|
public void testSetListenerAccessForUser_grantWithNameTooLong_throws() {
|
||||||
|
UserHandle user = UserHandle.of(mContext.getUserId() + 10);
|
||||||
|
ComponentName c = new ComponentName("com.example.package",
|
||||||
|
com.google.common.base.Strings.repeat("Blah", 150));
|
||||||
|
|
||||||
|
assertThrows(IllegalArgumentException.class,
|
||||||
|
() -> mBinderService.setNotificationListenerAccessGrantedForUser(
|
||||||
|
c, user.getIdentifier(), /* enabled= */ true, true));
|
||||||
|
}
|
||||||
|
|
||||||
|
@Test
|
||||||
|
public void testSetListenerAccessForUser_revokeWithNameTooLong_okay() throws Exception {
|
||||||
|
UserHandle user = UserHandle.of(mContext.getUserId() + 10);
|
||||||
|
ComponentName c = new ComponentName("com.example.package",
|
||||||
|
com.google.common.base.Strings.repeat("Blah", 150));
|
||||||
|
|
||||||
|
mBinderService.setNotificationListenerAccessGrantedForUser(
|
||||||
|
c, user.getIdentifier(), /* enabled= */ false, true);
|
||||||
|
|
||||||
|
verify(mListeners).setPackageOrComponentEnabled(
|
||||||
|
c.flattenToString(), user.getIdentifier(), true, /* enabled= */ false, true);
|
||||||
|
}
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
public void testSetAssistantAccessForUser() throws Exception {
|
public void testSetAssistantAccessForUser() throws Exception {
|
||||||
UserInfo ui = new UserInfo();
|
UserInfo ui = new UserInfo();
|
||||||
|
|||||||
Reference in New Issue
Block a user