Merge "Define targetSandboxVersion"
This commit is contained in:
committed by
Android (Google) Code Review
commit
efdc663569
@@ -1269,6 +1269,7 @@ package android {
|
||||
field public static final int targetId = 16843740; // 0x10103dc
|
||||
field public static final int targetName = 16843853; // 0x101044d
|
||||
field public static final int targetPackage = 16842785; // 0x1010021
|
||||
field public static final int targetSandboxVersion = 16844110; // 0x101054e
|
||||
field public static final int targetSdkVersion = 16843376; // 0x1010270
|
||||
field public static final int taskAffinity = 16842770; // 0x1010012
|
||||
field public static final int taskCloseEnterAnimation = 16842942; // 0x10100be
|
||||
|
||||
@@ -1385,6 +1385,7 @@ package android {
|
||||
field public static final int targetId = 16843740; // 0x10103dc
|
||||
field public static final int targetName = 16843853; // 0x101044d
|
||||
field public static final int targetPackage = 16842785; // 0x1010021
|
||||
field public static final int targetSandboxVersion = 16844110; // 0x101054e
|
||||
field public static final int targetSdkVersion = 16843376; // 0x1010270
|
||||
field public static final int taskAffinity = 16842770; // 0x1010012
|
||||
field public static final int taskCloseEnterAnimation = 16842942; // 0x10100be
|
||||
|
||||
@@ -1269,6 +1269,7 @@ package android {
|
||||
field public static final int targetId = 16843740; // 0x10103dc
|
||||
field public static final int targetName = 16843853; // 0x101044d
|
||||
field public static final int targetPackage = 16842785; // 0x1010021
|
||||
field public static final int targetSandboxVersion = 16844110; // 0x101054e
|
||||
field public static final int targetSdkVersion = 16843376; // 0x1010270
|
||||
field public static final int taskAffinity = 16842770; // 0x1010012
|
||||
field public static final int taskCloseEnterAnimation = 16842942; // 0x10100be
|
||||
|
||||
@@ -831,6 +831,12 @@ public class ApplicationInfo extends PackageItemInfo implements Parcelable {
|
||||
*/
|
||||
public int networkSecurityConfigRes;
|
||||
|
||||
/**
|
||||
* Version of the sandbox the application wants to run in.
|
||||
* @hide
|
||||
*/
|
||||
public int targetSandboxVersion;
|
||||
|
||||
/**
|
||||
* The category of this app. Categories are used to cluster multiple apps
|
||||
* together into meaningful groups, such as when summarizing battery,
|
||||
@@ -1012,7 +1018,8 @@ public class ApplicationInfo extends PackageItemInfo implements Parcelable {
|
||||
pw.println(prefix + "enabled=" + enabled
|
||||
+ " minSdkVersion=" + minSdkVersion
|
||||
+ " targetSdkVersion=" + targetSdkVersion
|
||||
+ " versionCode=" + versionCode);
|
||||
+ " versionCode=" + versionCode
|
||||
+ " targetSandboxVersion=" + targetSandboxVersion);
|
||||
if ((flags&DUMP_FLAG_DETAILS) != 0) {
|
||||
if (manageSpaceActivityName != null) {
|
||||
pw.println(prefix + "manageSpaceActivityName=" + manageSpaceActivityName);
|
||||
@@ -1127,6 +1134,7 @@ public class ApplicationInfo extends PackageItemInfo implements Parcelable {
|
||||
fullBackupContent = orig.fullBackupContent;
|
||||
networkSecurityConfigRes = orig.networkSecurityConfigRes;
|
||||
category = orig.category;
|
||||
targetSandboxVersion = orig.targetSandboxVersion;
|
||||
}
|
||||
|
||||
public String toString() {
|
||||
@@ -1187,6 +1195,7 @@ public class ApplicationInfo extends PackageItemInfo implements Parcelable {
|
||||
dest.writeInt(fullBackupContent);
|
||||
dest.writeInt(networkSecurityConfigRes);
|
||||
dest.writeInt(category);
|
||||
dest.writeInt(targetSandboxVersion);
|
||||
}
|
||||
|
||||
public static final Parcelable.Creator<ApplicationInfo> CREATOR
|
||||
@@ -1247,6 +1256,7 @@ public class ApplicationInfo extends PackageItemInfo implements Parcelable {
|
||||
fullBackupContent = source.readInt();
|
||||
networkSecurityConfigRes = source.readInt();
|
||||
category = source.readInt();
|
||||
targetSandboxVersion = source.readInt();
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -1315,6 +1325,7 @@ public class ApplicationInfo extends PackageItemInfo implements Parcelable {
|
||||
} else {
|
||||
dataDir = credentialProtectedDataDir;
|
||||
}
|
||||
// TODO: modify per-user ephemerality
|
||||
}
|
||||
|
||||
/**
|
||||
|
||||
@@ -296,6 +296,7 @@ public class PackageParser {
|
||||
private static boolean sCompatibilityModeEnabled = true;
|
||||
private static final int PARSE_DEFAULT_INSTALL_LOCATION =
|
||||
PackageInfo.INSTALL_LOCATION_UNSPECIFIED;
|
||||
private static final int PARSE_DEFAULT_TARGET_SANDBOX = 1;
|
||||
|
||||
static class ParsePackageItemArgs {
|
||||
final Package owner;
|
||||
@@ -1996,6 +1997,10 @@ public class PackageParser {
|
||||
PARSE_DEFAULT_INSTALL_LOCATION);
|
||||
pkg.applicationInfo.installLocation = pkg.installLocation;
|
||||
|
||||
final int targetSandboxVersion = sa.getInteger(
|
||||
com.android.internal.R.styleable.AndroidManifest_targetSandboxVersion,
|
||||
PARSE_DEFAULT_TARGET_SANDBOX);
|
||||
pkg.applicationInfo.targetSandboxVersion = targetSandboxVersion;
|
||||
|
||||
/* Set the global "forward lock" flag */
|
||||
if ((flags & PARSE_FORWARD_LOCK) != 0) {
|
||||
|
||||
@@ -32,7 +32,7 @@ public class ManifestConfigSource implements ConfigSource {
|
||||
private final int mApplicationInfoFlags;
|
||||
private final int mTargetSdkVersion;
|
||||
private final int mConfigResourceId;
|
||||
private final boolean mEphemeralApp;
|
||||
private final int mTargetSandboxVesrsion;
|
||||
|
||||
private ConfigSource mConfigSource;
|
||||
|
||||
@@ -43,7 +43,7 @@ public class ManifestConfigSource implements ConfigSource {
|
||||
mApplicationInfoFlags = info.flags;
|
||||
mTargetSdkVersion = info.targetSdkVersion;
|
||||
mConfigResourceId = info.networkSecurityConfigRes;
|
||||
mEphemeralApp = info.isEphemeralApp();
|
||||
mTargetSandboxVesrsion = info.targetSandboxVersion;
|
||||
}
|
||||
|
||||
@Override
|
||||
@@ -71,7 +71,7 @@ public class ManifestConfigSource implements ConfigSource {
|
||||
+ " debugBuild: " + debugBuild);
|
||||
}
|
||||
source = new XmlConfigSource(mContext, mConfigResourceId, debugBuild,
|
||||
mTargetSdkVersion, mEphemeralApp);
|
||||
mTargetSdkVersion, mTargetSandboxVesrsion);
|
||||
} else {
|
||||
if (DBG) {
|
||||
Log.d(LOG_TAG, "No Network Security Config specified, using platform default");
|
||||
@@ -80,9 +80,9 @@ public class ManifestConfigSource implements ConfigSource {
|
||||
// should use the network security config.
|
||||
boolean usesCleartextTraffic =
|
||||
(mApplicationInfoFlags & ApplicationInfo.FLAG_USES_CLEARTEXT_TRAFFIC) != 0
|
||||
&& !mEphemeralApp;
|
||||
&& mTargetSandboxVesrsion < 2;
|
||||
source = new DefaultConfigSource(usesCleartextTraffic, mTargetSdkVersion,
|
||||
mEphemeralApp);
|
||||
mTargetSandboxVesrsion);
|
||||
}
|
||||
mConfigSource = source;
|
||||
return mConfigSource;
|
||||
@@ -94,9 +94,9 @@ public class ManifestConfigSource implements ConfigSource {
|
||||
private final NetworkSecurityConfig mDefaultConfig;
|
||||
|
||||
public DefaultConfigSource(boolean usesCleartextTraffic, int targetSdkVersion,
|
||||
boolean ephemeralApp) {
|
||||
int targetSandboxVesrsion) {
|
||||
mDefaultConfig = NetworkSecurityConfig.getDefaultBuilder(targetSdkVersion,
|
||||
ephemeralApp)
|
||||
targetSandboxVesrsion)
|
||||
.setCleartextTrafficPermitted(usesCleartextTraffic)
|
||||
.build();
|
||||
}
|
||||
|
||||
@@ -175,13 +175,14 @@ public final class NetworkSecurityConfig {
|
||||
*
|
||||
* @hide
|
||||
*/
|
||||
public static final Builder getDefaultBuilder(int targetSdkVersion, boolean ephemeralApp) {
|
||||
public static final Builder getDefaultBuilder(int targetSdkVersion, int targetSandboxVesrsion) {
|
||||
Builder builder = new Builder()
|
||||
.setCleartextTrafficPermitted(!ephemeralApp)
|
||||
.setHstsEnforced(DEFAULT_HSTS_ENFORCED)
|
||||
// System certificate store, does not bypass static pins.
|
||||
.addCertificatesEntryRef(
|
||||
new CertificatesEntryRef(SystemCertificateSource.getInstance(), false));
|
||||
final boolean cleartextTrafficPermitted = targetSandboxVesrsion < 2;
|
||||
builder.setCleartextTrafficPermitted(cleartextTrafficPermitted);
|
||||
// Applications targeting N and above must opt in into trusting the user added certificate
|
||||
// store.
|
||||
if (targetSdkVersion <= Build.VERSION_CODES.M) {
|
||||
|
||||
@@ -37,7 +37,7 @@ public class XmlConfigSource implements ConfigSource {
|
||||
private final int mResourceId;
|
||||
private final boolean mDebugBuild;
|
||||
private final int mTargetSdkVersion;
|
||||
private final boolean mEphemeralApp;
|
||||
private final int mTargetSandboxVesrsion;
|
||||
|
||||
private boolean mInitialized;
|
||||
private NetworkSecurityConfig mDefaultConfig;
|
||||
@@ -57,16 +57,16 @@ public class XmlConfigSource implements ConfigSource {
|
||||
@VisibleForTesting
|
||||
public XmlConfigSource(Context context, int resourceId, boolean debugBuild,
|
||||
int targetSdkVersion) {
|
||||
this(context, resourceId, debugBuild, targetSdkVersion, false);
|
||||
this(context, resourceId, debugBuild, targetSdkVersion, 1 /*targetSandboxVersion*/);
|
||||
}
|
||||
|
||||
public XmlConfigSource(Context context, int resourceId, boolean debugBuild,
|
||||
int targetSdkVersion, boolean ephemeralApp) {
|
||||
int targetSdkVersion, int targetSandboxVesrsion) {
|
||||
mResourceId = resourceId;
|
||||
mContext = context;
|
||||
mDebugBuild = debugBuild;
|
||||
mTargetSdkVersion = targetSdkVersion;
|
||||
mEphemeralApp = ephemeralApp;
|
||||
mTargetSandboxVesrsion = targetSandboxVesrsion;
|
||||
}
|
||||
|
||||
public Set<Pair<Domain, NetworkSecurityConfig>> getPerDomainConfigs() {
|
||||
@@ -365,7 +365,7 @@ public class XmlConfigSource implements ConfigSource {
|
||||
// Use the platform default as the parent of the base config for any values not provided
|
||||
// there. If there is no base config use the platform default.
|
||||
NetworkSecurityConfig.Builder platformDefaultBuilder =
|
||||
NetworkSecurityConfig.getDefaultBuilder(mTargetSdkVersion, mEphemeralApp);
|
||||
NetworkSecurityConfig.getDefaultBuilder(mTargetSdkVersion, mTargetSandboxVesrsion);
|
||||
addDebugAnchorsIfNeeded(debugConfigBuilder, platformDefaultBuilder);
|
||||
if (baseConfigBuilder != null) {
|
||||
baseConfigBuilder.setParent(platformDefaultBuilder);
|
||||
|
||||
@@ -1247,6 +1247,12 @@
|
||||
split that contains the defined component. -->
|
||||
<attr name="splitName" format="string" />
|
||||
|
||||
<!-- Specifies the target sandbox this app wants to use. Higher sanbox versions
|
||||
will have increasing levels of security.
|
||||
|
||||
<p>The default value of this attribute is <code>1</code>. -->
|
||||
<attr name="targetSandboxVersion" format="integer" />
|
||||
|
||||
<!-- The <code>manifest</code> tag is the root of an
|
||||
<code>AndroidManifest.xml</code> file,
|
||||
describing the contents of an Android package (.apk) file. One
|
||||
@@ -1274,6 +1280,7 @@
|
||||
<attr name="sharedUserLabel" />
|
||||
<attr name="installLocation" />
|
||||
<attr name="isolatedSplits" />
|
||||
<attr name="targetSandboxVersion" />
|
||||
</declare-styleable>
|
||||
|
||||
<!-- The <code>application</code> tag describes application-level components
|
||||
|
||||
@@ -2790,6 +2790,7 @@
|
||||
<public name="splitName" />
|
||||
<public name="colorMode" />
|
||||
<public name="isolatedSplits" />
|
||||
<public name="targetSandboxVersion" />
|
||||
</public-group>
|
||||
|
||||
<public-group type="style" first-id="0x010302e0">
|
||||
|
||||
@@ -66,6 +66,9 @@ public final class SELinuxMMAC {
|
||||
// Append privapp to existing seinfo label
|
||||
private static final String PRIVILEGED_APP_STR = ":privapp";
|
||||
|
||||
// Append v2 to existing seinfo label
|
||||
private static final String SANDBOX_V2_STR = ":v2";
|
||||
|
||||
// Append ephemeral to existing seinfo label
|
||||
private static final String EPHEMERAL_APP_STR = ":ephemeralapp";
|
||||
|
||||
@@ -287,6 +290,9 @@ public final class SELinuxMMAC {
|
||||
if (pkg.applicationInfo.isEphemeralApp())
|
||||
pkg.applicationInfo.seinfo += EPHEMERAL_APP_STR;
|
||||
|
||||
if (pkg.applicationInfo.targetSandboxVersion == 2)
|
||||
pkg.applicationInfo.seinfo += SANDBOX_V2_STR;
|
||||
|
||||
if (pkg.applicationInfo.isPrivilegedApp())
|
||||
pkg.applicationInfo.seinfo += PRIVILEGED_APP_STR;
|
||||
|
||||
|
||||
@@ -227,7 +227,7 @@ public class NetworkSecurityConfigTests extends ActivityUnitTestCase<Activity> {
|
||||
public void testConfigBuilderUsesParents() throws Exception {
|
||||
// Check that a builder with a parent uses the parent's values when non is set.
|
||||
NetworkSecurityConfig config = new NetworkSecurityConfig.Builder()
|
||||
.setParent(NetworkSecurityConfig.getDefaultBuilder(Build.VERSION_CODES.N, false))
|
||||
.setParent(NetworkSecurityConfig.getDefaultBuilder(Build.VERSION_CODES.N, 1))
|
||||
.build();
|
||||
assert(!config.getTrustAnchors().isEmpty());
|
||||
}
|
||||
@@ -268,9 +268,9 @@ public class NetworkSecurityConfigTests extends ActivityUnitTestCase<Activity> {
|
||||
// Install the test CA.
|
||||
store.installCertificate(TEST_CA_CERT);
|
||||
NetworkSecurityConfig preNConfig =
|
||||
NetworkSecurityConfig.getDefaultBuilder(Build.VERSION_CODES.M, false).build();
|
||||
NetworkSecurityConfig.getDefaultBuilder(Build.VERSION_CODES.M, 1).build();
|
||||
NetworkSecurityConfig nConfig =
|
||||
NetworkSecurityConfig.getDefaultBuilder(Build.VERSION_CODES.N, false).build();
|
||||
NetworkSecurityConfig.getDefaultBuilder(Build.VERSION_CODES.N, 1).build();
|
||||
Set<TrustAnchor> preNAnchors = preNConfig.getTrustAnchors();
|
||||
Set<TrustAnchor> nAnchors = nConfig.getTrustAnchors();
|
||||
Set<X509Certificate> preNCerts = new HashSet<X509Certificate>();
|
||||
|
||||
Reference in New Issue
Block a user