* changes:
Fix domain verify restore and add signature check
Support serializing package signatures for domain verification state
Add domain verification CTS to TEST_MAPPING
Fix DomainVerificationService deadlock
Check installed and enabled state for package domain approval
Revoke domain user selection when approved through shell
For targetSdk < S. For S, they can use the new
GLOBAL_ACTION_DISMISS_NOTIFICATION_SHADE action to dismiss the
notification shade.
Bug: 159334261
Test: Send Intent.ACSD from an a11y service and verify shade is
collapsed when targetSdk < S, and exception thrown when targetSdk
S+.
Change-Id: I0e4be3faef8efa53a0b8a08263e842e0c4b1553e
Besides UI contexts, the context created via
Context#createConfigurationContext with a proper configuration
should be allowed to inflate views or obtain ViewConfiguration.
An example is that a wear device inflate views into bitmap and pass
the bitmap to the Wear OS Companion app on the phone.
Bug: 177847640
Test: atest StrictModeTest
Change-Id: Iab232a80a973f54bf0484262d45af3e4c2f0e5dc
Codegen is a tool that generates parcelable classes from
field declarations. Hence, the @SystemApi annotations are
placed on the field and the tool propagetes them to the
generated APIs. We need to update the AnnotationTest to
either ingore these generated classes or ignore private
fields annotated with @SystemApi as they are not API in
practice. This CL removes the annotations to fix the test.
bug: 184086213
Test: atest android.signature.cts.api.AnnotationTest
Change-Id: Ibe9059f20d95d4cda4eb402704e3c4c002ff0e47
If the datasource is not in a trusted platform component then in would not
have UPDATE_APP_OPS_STATS. The problem is that an app is exposing runtime
permission protected data but cannot blame others in a trusted way which
would not properly show in permission usage UIs. As a fallback we are
adding a proxy op handling blaming the datasource and the caller.
bug: 183960997
Test: Assustant on auto projection works
Change-Id: I8a341a6c46c75eff86bac7a79c4219ebb7991071
When apps use requestOptimizedExternalStorageAccess flag, they get
additional performance benefit by bypassing database operations. They
still have to scan the file to update MediaStore collection otherwise
MediaStore collection can go inconsistent with lower file system.
Current flag name could lead to apps making wrong assumptions hence
changing the name to more precise name.
Bug: 178209446
Test: atest packages/providers/MediaProvider
Change-Id: I00747da9ea53566cbcdd8aa8b2195e536b397b67
We were writing the map as a generic Map, but reading it as an
ArrayMap. There's a subtle difference between the two methods.
The generic Map creator reads the map's key using readValue(),
which first reads an integer datatype and then the data. Whereas
the ArrayMap creator knows the keys are Strings and thus calls
readString() directly without consuming the datatype. This
throws the parcel reading logic out of whack.
Fixes: 176295431
Test: manual
Change-Id: I2d32488e3339e2d838e680be1ed9476b9e15cd69
If the package isn't installed or isn't enabled for a user, it cannot
be approved for that user.
Also hooks into package uninstall for a single user to remove the
domain state for that package for that user.
Bug: 183226822
Test: atest DomainVerificationManagerApiTest#getOwnersForDomain
Test: atest com.android.server.pm.test.verify.domain
Change-Id: I04942e1491d470fdd41e99f207bbf85baae87d4c
Propagate renounced permissions from context params
to the context attribution source. Throw if one
tries to request at runtime a renounced permission.
Also make the AttributionSource take null for the
setters to ease usage, otherwise folks should always
check for null before calling a builder method.
Additionally, we allow apps that have UPDATE_APP_OPS_STATS
to register arbitrary trusted AttributionSource for
testing. Note that this permission allows abritrary app
op operations, thus we are not relaxing the security
model.
bug: 158792096
Test: atest CtsPermission5TestCases
Change-Id: I4330684bb8695fb998cf31e9363b94ad981ba2cc
To make S finalization easier, this changes the framework SDK so that
apps linking against it will be able to continue working as expected
after the first phase of SDK finalization.
During the first phase of SDK finalization, the resource ids of
resources that have not been removed are finalized.
staging-public-group tags are converted to staging-public-group-final
tags in order to encode into the framework what the staged resource id
of a finalized resource was. When an app recompiles, it will use the
finalized resource id. Then after all apps recompile, phase 2 of
finalization begins, in which the staging-public-group-final tags are
removed so apps can no longer use the staged resource ids.
Apps that link against the SDK (provided they are using a recent
version of aapt) will encode references to staged resources as
TYPE_DYNAMIC_REFERENCE and TYPE_DYNAMIC_ATTRIBUTE. The values of R
fields for staged resources are defined out-of-line to prevent them
from being inlined into apps linking agsint the SDK. This allows the
resource ids to change during phase 1 of API finalization.
Bug: 183413192
Test: `aapt2 diff` and resource ids stayed the same
Test: `aapt2 dump` of framework-res.apk and observe staged resources
Change-Id: Ie2275c608297a5f63dde8b1cf795415112cbcc24
ResourcesProvider#finalize called ApkAssets#close. ApkAssets#close is
called during ApkAssets#finalize. If a ResourcesProvider and its
corresponding ApkAssets are finalized concurrently, there may be a
chance that the ApkAsset could be finalized first and then
ResourcesProvider calls ApkAssets#close on the object that has already
been finalized.
This may not fix the bug, but there is no reason to close the ApkAsset
during finalization of the ResourcesProvider.
Bug: 159041693
Test: none
Change-Id: I317ca982df2e11a18ccd6c95c74565dbac417bd6
Previous work implemented getRequestedPermissions() by dynamically
constructing the legacy list of requested permissions, along with a
deprecation message to migrate to ParsedUsesPermission, but there
are too many callers to migrate at this stage of the release.
For now, to mitigate performance issues that arose, this change
builds a parallel list of requested permissions to avoid the
overhead of dynamically building the legacy list.
Bug: 183223056
Test: atest FrameworksServicesTests:PackageParserTest
Test: atest com.android.server.pm.parsing
Test: atest -p core/java/android/content/pm \
core/java/com/android/internal/content \
services/core/java/com/android/server/pm \
services/tests/servicestests/src/com/android/server/pm
Change-Id: I538fbc12a9fd34f5ad5d63177ac5a2cb9a1ff3ce
Per b/150347230#comment18, remove the API since
RollbackManager will not be a module in S.
Bug: 150347230
Test: m
Change-Id: I1f356d0f5097da340986182314e47e3b6b6d9223
Also added some logging for runtime permissions with no app op
bug: 184093962
Test: Setting up device with work account
Change-Id: I85787367b11d57ed1240fcf484ad7d2efa13d406
As we allow non-resizable app in multi-windowing mode, the previous
comment can be confusing.
Bug: 176061101
Test: udpate comment
Change-Id: Iba51ca4158940bbda761fe3b7977d338ee1f3327