- Added Context.getUser() to system API, to allow module framework
classes to also implement multi-user support in manager classes.
- Added PackageManager.getPermissionControllerPackageName() to system
API for RoleControllerManager to know which package to bind to.
Bug: 158736025
Test: build
Change-Id: If69a97573eb1e676145e0accdfa73fef320aabe7
This was broken in the original migration, causing this field to be
dropped on reboot.
Bug: 178209505
Test: TODO, separate change will include comprehensive parceling test
Change-Id: I67219fe00c7b92677391fd46305bf0424d74e5f3
Adding a new public system feature constant that must be expressed by
devices that support Android's security model as documented in
the CDD.
Test: Build
Bug: 173540259
Change-Id: Ib651ab31cba065fc9b2a28d8ac16eaa85357f252
Exported components that are not guarded by a signature permission
can receive Intents from any other app on a device. If an app unparcels
and launches an Intent from the Intent delivered to this unprotected
component then a malicious actor can potentially craft an Intent that
could launch hidden components, grant URI permissions, etc. This
commit adds a StrictMode check to report if a component launches an
Intent unparceled from the delivered Intent.
Bug: 160796858
Test: atest StrictModeTest
Change-Id: I763b8a965f91f5b433ce2f4b619e10ef12f5c296
Created AppSearchShortcutInfo and AppSearchPerson to handle data
transformation for AppSearch interops.
Bug: 151359749
Test: AppSearchShortcutInfoTest, AppSearchPersonTest
Change-Id: Ia3641982360a0a877172cb1ed21f36c0e70296f9
The initial APIs for ui translation. There is no implementation in
this change, we will implement it in the next CL.
Bug: 172969740
Bug: 176871912
Test: manual. build pass and build success.
Change-Id: I4ae0bc7a695076a87bed73e458396312d87f48c5
This permission model is only allowed for BUGREPORT_MODE_TELEPHONY to
let carrier apps (even from the Play Store / not pre-loaded) access
BugreportManager to trigger connectivity bugreports.
This also requires SELinux policy changes to allow non-system apps to
get an instance through Context#getSystemService, and then dumpstate
also needs permissions to write public apps' files.
Minor documentation and formatting fixes as well.
BYPASS_INCLUSIVE_LANGUAGE_REASON=leaving variable name derived from
"bugreport-whitelisted" sysconfig alone for now
Bug: 161393541
Test: atest CtsCarrierApiTestCases:BugreportManagerTest
Change-Id: I5a38e7a040fa23146fa6c1e785db102b066ad167
Merged-In: I5a38e7a040fa23146fa6c1e785db102b066ad167
(cherry picked from commit 57fd3440be)
ec6ebc3a1e
Also made the APIs test API instead of system API, to be turned into
system API later during the actual move into module.
Bug: 158736025
Test: atest RcsProvisioningMonitorTest
Change-Id: I74ce1b8352b6e3afc595d8d0f08db28b8c2f29c3
* changes:
Provide IndividualSensorPrivacyController instead of bind it
Add mic sensor privacy QS tile
Hook up camera toggle QS tile to SensorPrivacyManager
Create camera toggle tile
This permission model is only allowed for BUGREPORT_MODE_TELEPHONY to
let carrier apps (even from the Play Store / not pre-loaded) access
BugreportManager to trigger connectivity bugreports.
This also requires SELinux policy changes to allow non-system apps to
get an instance through Context#getSystemService, and then dumpstate
also needs permissions to write public apps' files.
Minor documentation and formatting fixes as well.
BYPASS_INCLUSIVE_LANGUAGE_REASON=leaving variable name derived from
"bugreport-whitelisted" sysconfig alone for now
Bug: 161393541
Test: atest CtsCarrierApiTestCases:BugreportManagerTest
Change-Id: I5a38e7a040fa23146fa6c1e785db102b066ad167
The PackageParser is deprecated, but two inner classes PackageLite
and ApkLite are still used widely. To move away from PackageParser,
the first step is having alternatives of these inner classes.
Besides, some constants in the PackageParser are also used. This CL
also moves them into the individual class.
Bug: 174723245
Test: make
Change-Id: Ice151dc4daf7e342e9f77cfdae69682c1d5ba56f
The intent can be used to prevent the user from accessing critical
notifications (b/137274359) and system dialogs in general (eg. the
long-press power menu, assistant UIs, etc.). For these security reasons,
in S, the intent is severely limited to only a few use-cases/callers
after investigation (go/close-system-dialogs-usage), these are:
1. Permission holders of BROADCAST_CLOSE_SYSTEM_DIALOGS (includes
platform, sysUI and recents).
2. Non-activity notification trampolines: Apps send the intent before
starting an activity in trampolines.
3. Tests: Tests that interact with the UI send the intent to dismiss
random dialogs.
4. Windows above the notification shade: Apps with windows above the
shade that want to start activity send the intent to collapse the
shade in order to show the activity to the user.
For apps w/ targetSdk < S: The intent will be dropped with the exception
of the cases above.
For apps w/ targetSdk S+: Sending the intent will result in a
SecurityException except for cases 1 and 3. For cases 2 and 4:
2. Non-activity notification trampolines: These activity starts are
blocked (go/notification-trampolines), so the app has no reason to
send the intent anymore.
4. Windows above the notification shade: The platform will automatically
collapse the shade on activity starts in this case.
In all other use-cases, the user and the system is in control of closing
system dialogs, not third-party applications. Hence, marking
Intent.ACSD as deprecated for third-party applications.
Test: Builds
Bug: 159105552
Change-Id: Id82415ab4cfe09f7582da06ee20adb1e1cf447e0