Commit Graph

1859 Commits

Author SHA1 Message Date
Jeff Sharkey
9a9fa815f1 Merge "Ensure privileged APIs require runtime permission." into sc-dev 2021-04-29 22:22:25 +00:00
Martin Brabham
329a11f7c6 Merge changes from topic "bluetooth_oob_api" am: 2e67798711 am: 8411b5d7b3 am: 50e294ad9b
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1686315

Change-Id: I00dc7f393edb9b562c97147d053302159c12fcdb
2021-04-29 21:33:10 +00:00
Martin Brabham
d50c8e0703 OOB: Remove static creator methods in favor of public constructors am: 1cd46165dd am: e897917de7 am: 2d3dbcab8f
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1684129

Change-Id: Ia4d99bf5f2dcee3d688796dfa3e11c1d104132a1
2021-04-29 21:32:57 +00:00
Jeff Sharkey
b8e4b883ae Ensure privileged APIs require runtime permission.
When users revoke a runtime permission, they expect all interactions
to be blocked, including those protected by the BLUETOOTH_PRIVILEGED
permission.

This change finishes applying that policy to any remaining Bluetooth
APIs which didn't already implement it.  To keep the implementation
straightforward, this change does "data delivery" checks when
registering for callbacks; the ideal behavior would be to wait
until data is actually delivered through the callbacks, but
RemoteCallbackList doesn't have support for AttributionSource yet.

Bug: 186405452
Test: atest BluetoothInstrumentationTests
Change-Id: Idd7be143eb8baff020a0718065293baae708041b
2021-04-29 13:55:07 -06:00
Jeff Sharkey
0cab9b7480 Preserve legacy permission check behavior.
As part of the new "Nearby devices" permission work, the
registerStateChangeCallback() API has been relaxed to no longer
require permissions.  However, we've discovered that some apps were
depending on that SecurityException being thrown, so this change
restores throwing behavior for those legacy apps.

Bug: 186176507
Test: atest BluetoothInstrumentationTests
Change-Id: Ife536dee246b300ffb3dd78aef0b059a230f3835
2021-04-28 09:25:38 -06:00
Martin Brabham
b0d691b3a1 Convert onOobData parameter for OobData from @Nullable to @NonNull
Bug: 185603183
Test: Compiles, test app works
Tag: #feature
Change-Id: I52636769f50f50b5ad2d135f54472bdeb1c25ee5
2021-04-27 09:36:41 -07:00
Martin Brabham
1cd46165dd OOB: Remove static creator methods in favor of public constructors
Bug: 184370881
Tag: #feature
Test: Manual compile
Change-Id: I502cdf5adde324b7a41cfb6974f0b43b0064a911
2021-04-26 09:35:54 -07:00
Jeff Sharkey
dd5a4f39c8 Long-tail of AttributionSource plumbing.
Wires up AttributionSource across the remaining long-tail of
Bluetooth AIDL interfaces, ensuring that developers can accurately
make calls chained back to a specific Context.

Moves "for data delivery" permission checks to happen in a single
location on each interface to ensure they're performed consistently
with the new AttributionSource arguments.  Note that "for data
delivery" isn't the best name; it's designed to represent that the
requested action was performed and should result in the relevant
appop being noted for the caller.

This change has the positive side effect of ensuring that all
interfaces are consistently enforcing the BLUETOOTH_CONNECT
permission, even in the case where BLUETOOTH_PRIVILEGED is also
required; this is what ensures that revoking the "Nearby devices"
permission takes effect for all callers.

Additionally, standardizing on enforcing permissions closer to the
AIDL entry point reduces the need for @RequiresPermission annotations
to be carried around inside the Bluetooth stack.

Bug: 183626112
Test: atest BluetoothInstrumentationTests
Change-Id: I8023dda654e325b8bfa2f0cdb994ad63a2b429d4
2021-04-24 08:31:43 -06:00
Jeff Sharkey
efe1110be8 More AttributionSource plumbing.
To prepare for future work which will plumb AttributionSource values
through all remaining AIDLs, we need profiles to interact directly
with the specific BluetoothAdapter they were created from.  This is
how we'll ensure that the relevant AttributionSource can be chained
down from the original Context they're obtained from.

This change also marks getDefaultAdapter() as deprecated to clearly
communicate that BluetoothManager.getAdapter() is the best-practice
path to obtaining a correctly scoped BluetoothAdapter instance.

Bug: 183626112
Test: atest BluetoothInstrumentationTests
Change-Id: I1e15170d7679019bbb6e396279d6e633e3dad4d6
2021-04-23 08:51:49 -06:00
Oli Lan
52f8d4c9c3 Pass attribution source to BT APIs.
This adds attribution source to BT method calls. This is now
required to allow the app ops for the new BT permissions
(BLUETOOTH_CONNECT, BLUETOOTH_ADVERTISE, and BLUETOOTH_SCAN)
to be noted.

Bug: 183626112
Test: atest BluetoothInstrumentationTests
Change-Id: I81598553b762e491d6364064a2e1ef41dec89bf9
2021-04-22 14:47:39 -06:00
Jeff Sharkey
67d4e1e079 Refinement of AttributionSource handling.
Previous CLs had started passing AttributionSource values across
Binder calls inside BluetoothDevice instances, but this can cause
confuse the permission check logic in the future; we should instead
always aim to use the AttributionSource closest to the app making
the call, instead of parceling it.

This change also improves logging to highlight when we're quietly
treating a permission as denied, and when a UID is mismatched.

Bug: 186106084
Test: atest BluetoothInstrumentationTests
Change-Id: I5d3fdb3c573cb9e77474952d8680caa4c4c464eb
2021-04-22 12:46:06 -06:00
Jeff Sharkey
c1b024d280 Merge "Pass AttributionSource to AdapterService methods." into sc-dev 2021-04-21 22:40:20 +00:00
Jeff Sharkey
d4b3fcac16 Merge "Annotations for Bluetooth broadcast intents." into sc-dev 2021-04-21 22:23:48 +00:00
Jeff Sharkey
f459828358 Annotations for Bluetooth broadcast intents.
Recent work has been using Error Prone rules and annotations to
reflect the current state of permission enforcement across the
Bluetooth stack, and we're now in a position were we can add new
permission enforcement that had been missing.

We've currently standardized on saying that APIs that return device
or Bluetooth state information (without sharing details about any
particular remote Bluetooth device) do not need to be permission
protected.

Bug: 183626724
Test: ./build/soong/soong_ui.bash --make-mode Bluetooth RUN_ERROR_PRONE=true
Change-Id: I53ac7a4fe1dea57316048c3cac4fa237b6ba3d38
2021-04-21 12:59:38 -06:00
Oli Lan
141edf9ef6 Pass AttributionSource to AdapterService methods.
This adds attribution source to AdapterService bluetooth method
calls. This is now required to allow the app ops for the new
bluetooth permissions (BLUETOOTH_CONNECT, BLUETOOTH_ADVERTISE,
and BLUETOOTH_SCAN) to be noted.

Bug: 183626112
Test: atest AdapterServiceTest
Test: atest CtsPermissionTestCases:android.permission.cts.NearbyDevicesPermissionTest
Change-Id: I8d1fe41ca9945a3baab584f248a17b3a1eb255f7
2021-04-21 17:59:06 +01:00
Rahul Sabnis
edad7c7c60 Update docs to reflect LE batch scan report delay floor
Tag: #feature
Bug: 167340030
Test: Manual
Change-Id: Ieeb0e6bccfc316fd4c8cdc40f6865b4185d6d9e8
2021-04-20 16:40:15 -07:00
Rahul Sabnis
93404b4883 Update docs to reflect LE batch scan report delay floor
Tag: #feature
Bug: 167340030
Test: Manual
Change-Id: Ieeb0e6bccfc316fd4c8cdc40f6865b4185d6d9e8
2021-04-20 14:22:16 -07:00
Nataniel Borges
0cd1de2226 Merge "Revert "Set a floor value for BLE Batch Scan report delay of 5000ms"" am: 6528da5667 am: 3ed5afa516 am: 81583909a9
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1681445

Change-Id: Ia2a73845fb92c457b37bacef7542aa47535560d4
2021-04-20 17:14:48 +00:00
Nataniel Borges
5aa369359e Revert "Set a floor value for BLE Batch Scan report delay of 5000ms"
This reverts commit ea303904fd.

Reason for revert: b/185890964

Change-Id: I270dc16de0e24728c694830fbe920786b6d90174
2021-04-20 15:50:03 +00:00
Treehugger Robot
0bf5efaeab Merge "Set a floor value for BLE Batch Scan report delay of 5000ms" am: ce2a2c80dd am: da5eb08ae3 am: 2b8dce1db1
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1676810

Change-Id: I2aafeceb53a673e0172e5873c7354a6d59acc530
2021-04-20 04:00:37 +00:00
Rahul Sabnis
ea303904fd Set a floor value for BLE Batch Scan report delay of 5000ms
Tag: #feature
Bug: 167340030
Test: Manual
Change-Id: I4ef99a9562f1447a2ccee42a344384a38a487c19
2021-04-19 17:29:02 -07:00
Jeff Sharkey
655d691d65 Add missing Bluetooth API permission enforcement.
Recent work has been using Error Prone rules and annotations to
reflect the current state of permission enforcement across the
Bluetooth stack, and we're now in a position were we can add new
permission enforcement that had been missing.

We've currently standardized on saying that APIs that return device
or Bluetooth state information (without sharing details about any
particular remote Bluetooth device) do not need to be permission
protected.

Bug: 183626724
Test: ./build/soong/soong_ui.bash --make-mode Bluetooth RUN_ERROR_PRONE=true
Change-Id: I37a9e03ecdca6f7a6eb9d7f094e2f95a97036612
2021-04-18 07:58:11 -06:00
Jeff Sharkey
6eed56ddd3 More Bluetooth API annotation updates.
This change adds a "BluetoothPermissionChecker" that ensures that
all Bluetooth permission annotations are consistent.  In addition, it
verifies that all Bluetooth public APIs have been audited to be
permission protected where relevant.

We've currently standardized on saying that APIs that return device
or Bluetooth state information (without sharing details about any
particular remote Bluetooth device) do not need to be permission
protected.

This change is only annotations and has no behavior changes.

Bug: 183626724
Test: ./build/soong/soong_ui.bash --make-mode Bluetooth RUN_ERROR_PRONE=true
Change-Id: Ie80b15b058359bf1e9a6ee881b89cb3e5b584ca1
2021-04-16 13:31:22 -06:00
Jeff Sharkey
938e329b77 Refine BluetoothLeAdvertiser permissions.
Technically these APIs required both ADVERTISE and CONNECT, since
internally it would attempt getting the device name as part of
calculating packet lengths.  These methods shouldn't require the
CONNECT permission, so we add a getNameLengthForAdvertise() method
internally to remove this dependency.

Bug: 183626724
Test: ./build/soong/soong_ui.bash --make-mode Bluetooth RUN_ERROR_PRONE=true
Change-Id: I245417bfc26d6d3a4f8be14077c7f1d271b5959e
2021-04-15 14:58:02 -06:00
Martin Brabham
76a512f958 OOB generateLocalOobData
unhide @SystemApi callback methods

Bug: 178007935
Tag: #feature
Test: compiles
Change-Id: I2d4167a6c92ee0cc24da12df206838161c8f3318
Merged-In: I2d4167a6c92ee0cc24da12df206838161c8f3318
2021-04-15 18:36:06 +00:00
Jeff Sharkey
cd5c179783 Merge changes from topic "apr10" into sc-dev
* changes:
  Update Bluetooth API annotations.
  Error Prone for RequiresPermission across AIDL.
2021-04-15 13:43:03 +00:00
Jeff Sharkey
4acdb1beff Update Bluetooth API annotations.
Recent work has introduced a new "Nearby devices" runtime permission
which protects all existing Bluetooth APIs; we've done this by
defining a <split-permission> to convert the old BLUETOOTH and
BLUETOOTH_ADMIN permissions into one of three new permissions:

* BLUETOOTH_ADVERTISE: Required to be able to advertise to nearby
                       Bluetooth devices.
* BLUETOOTH_CONNECT:   Allows applications to connect to paired
                       bluetooth devices.
* BLUETOOTH_SCAN:      Required to be able to discover and pair
                       nearby Bluetooth devices.

At its core, this change begins updating the Bluetooth APIs to have
correct @RequiresPermission indicating which permission is actually
enforced internally.  To ensure alignment across Binder, the newly
added "RequiresPermissionChecker" Error Prone checker was used to
discover any inconsistencies, ensuring correctness from server-side
enforcement up through to the public APIs.

In addition, since developers will continue building apps for both
modern and legacy platforms, this change introduces new auto-doc
annotations which will emit helpful consistent documentation
describing the behavior of older devices that are still using the
old permission model.

Bug: 183626724
Test: ./build/soong/soong_ui.bash --make-mode Bluetooth RUN_ERROR_PRONE=true
Change-Id: I02aa127e8e07f239561f4f2a3bbdfc6fccb82f7f
2021-04-14 21:13:24 -06:00
Treehugger Robot
b2e2624e8b Merge "Bluetooth OOB: Fix getLeAppearance" am: ef0304a087 am: 2988998bd3 am: 6745daf3c2
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1673875

Change-Id: I8d2d9d4ea7bfa3b9a3a4bfe358da4275688b6f19
2021-04-15 03:11:10 +00:00
Martin Brabham
ba2c904f8d OOB generateLocalOobData
unhide @SystemApi callback methods

CTS-Coverage-Bug: 184395281
Bug: 178007935
Tag: #feature
Test: compiles
Change-Id: I2d4167a6c92ee0cc24da12df206838161c8f3318
2021-04-14 18:53:04 +00:00
Hansong Zhang
a77bdb5161 Bluetooth OOB: Fix getLeAppearance
Bug: 185196125
Test: Use OOB pairing
Change-Id: I1cb1c33b0b17f2fd242f6579844996c2ccf09e62
2021-04-13 11:55:28 -07:00
Martin Brabham
6d4100e433 OOB: Implement getLocalOutOfBand API
CTS-Coverage-Bug: 184395281
Bug: 178007935
Tag: #feature
Test: manual
Change-Id: I5bc11ac13d9cbb8f76f422aa4aea8295ebec95b4
Merged-In: I5bc11ac13d9cbb8f76f422aa4aea8295ebec95b4
2021-04-07 14:08:39 -07:00
TreeHugger Robot
dcc1a906cf Merge "OOB: Implement generateLocalOutOfBand API" into sc-dev 2021-04-07 19:32:23 +00:00
Martin Brabham
2093f69721 OOB: Implement generateLocalOutOfBand API
CTS-Coverage-Bug: 184395281
Bug: 178007935
Tag: #feature
Test: manual
Change-Id: I5bc11ac13d9cbb8f76f422aa4aea8295ebec95b4
2021-04-06 18:13:29 +00:00
Oli Lan
ec2ca2d83e Pass AttributionSource to bluetooth scanning methods.
This passes the AttributionSource to AdapterService and GattService
methods that perform scanning or discovery.

Bug: 183203469
Test: atest GattServiceTest
Test: atest AdapterServiceTest
Test: atest CtsPermissionTestCases:android.permission.cts.NearbyDevicesPermissionTest

Change-Id: Id68558624fbae69eac3a8613b9536eb6e0df75bf
2021-04-01 15:51:40 +01:00
Svet Ganov
8d2ed50604 Runtime permission attribution improvements
When an app is proxying access to runtime permission protected
data it needs to check whether the calling app has a permission
to the data it is about to proxy which leaves a trace in app ops
that the requesting app perofmed a data access. However, then the
app doing the work needs to get the protected data itself from the
OS which access gets attributed only to itself. As a result there
are two data accesses in app ops where only the first one is a
proxy one that app A got access to Foo through app B - that is the
one we want to show in the permission tracking UIs - and one
for the data access - that is the one we would want to blame on
the calling app, and in fact, these two accesses should be one -
that app A accessed Foo though B. This limitation requires fragile
one off workarounds where both accesses use the same attribution
tag and sys UI has hardcoded rules to dedupe. Since this is not
documented we cannot expect that the ecosystem would reliably
do this workaround in apps that that the workaround in the OS
would be respected by every OEM.

This change adds a mechaism to resolve this issue. It allows for
an app to create an attribution context for another app and then
any private data access thorugh this context would result in a
single app op blame that A accessed Foo though B, i.e. we no longer
have double accounting. Also this can be nested through apps, e.g.
app A asks app B which asks app C for contacts. In this case app
B creates an attribution context for app A and calls into app C
which creates an attribution context for app B. When app C gets
contacts the entire attribution chain would get a porper, single
blame: that C accessed the data, that B got the data from C, and
that A got the data form B. Furthermore, this mechanism ensures
that apps cannot forget to check permissions for the caller
before proxying private data. In our example B and C don't need
to check the permisisons for A and B, respectively, since the
permisisons for the entire attribution chain are checked before
data delivery. Attribution chains are not forgeable preventing
a bad actor to create an arbitrary one - each attribution is
created by the app it refers to and points to a chain of
attributions created by their corresponding apps.

This change also fixes a bug where all content provider accesses
were double counted in app ops due to double noting. While at
this it also fixes that apps can now access their own last ops.
There was a bug where one could not pass null getting the attributed
ops from a historical package ops while this is a valid use case
since if there is no attribution everything is mapped to the null
tag. There were some app op APIs not being piped thorough the app
ops delegate and by extension through the app ops policy. Also
now that we have nice way to express the permission chain in a
call we no longer need the special casing in activity manager to
handle content provider accesses through the OS. Fixed a bug
where we don't properly handle the android.os.shell calls with
an invlaid tag which was failing while the shell can do any tag.

Finally, to ensure the mechanims is validated and works end-to-end
we are adding support for a voice recognizer to blame the client
app for the mic access. The recognition service can create a blaming
context when opening the mic and if the mic is open, which would
do all permission checks, we would not do so again. Since changes
to PermissionChercker for handling attribution sources were made
the CL also hooks up renounced permissoins in the request permission
flow and in the permission checks.

bug:158792096
bug:180647319

Test:atest CtsPermissionsTestCases
     atest CtsPermissions2TestCases
     atest CtsPermissions3TestCases
     atest CtsPermissions4TestCases
     atest CtsPermissions5TestCases
     atest CtsAppOpsTestCases
     atest CtsAppOps2TestCases

Change-Id: Ib04585515d3dc3956966005ae9d94955b2f3ee08
2021-03-29 16:49:33 +00:00
Treehugger Robot
d2cc19e8f1 Merge "Remove BluetoothHeadset#setPriority which was deprecated in Android 11" am: cdf9e7ef43 am: 283653d4b1 am: c93442cac9
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1650990

Change-Id: I40ae55301eb6b33e596e7c7976dda4caa837e70c
2021-03-25 04:31:19 +00:00
Rahul Sabnis
2b735a548f Remove BluetoothHeadset#setPriority which was deprecated in Android 11
Tag: #feature
Bug: 183551808
Test: Manual
Change-Id: I88745589ec66d3060d24b530fe49fea8926726c6
2021-03-24 14:01:52 -07:00
Jack He
4acab1d9ae Merge "ScanFilter.setDeviceAddress: Should send deviceAddress instead of mDeviceAddress to the next level" am: b4d4127efb am: c1d92b8ddd am: 7617088bd9
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1649650

Change-Id: I1d0ba23462d69dbae4cde8eb6d6d271afd39797c
2021-03-23 19:35:34 +00:00
Rahul Sabnis
7030bd354f Merge "Makes BluetoothDevice#setAlias a public API" into sc-dev 2021-03-23 19:07:24 +00:00
Chen Chen
feab55912c ScanFilter.setDeviceAddress: Should send deviceAddress instead of mDeviceAddress to the next level
Bug: 183409081
Test: build and run

Change-Id: I2d25d21b0f143fc7362679e0094455c9132fda9d
2021-03-23 17:43:36 +00:00
Rahul Sabnis
c7635a46e7 Makes BluetoothDevice#setAlias a public API
Tag: #feature
Bug: 181093329
Test: atest BluetoothDeviceTest
Change-Id: Ib94bedab5d6d4c63a19096f61187f58dd8937b55
2021-03-22 16:07:37 -07:00
Treehugger Robot
db77ba6c0e Merge "Add new @SystemApi for specifying AddressType and IRK" am: bf516b9e11 am: 6ec4bd694b am: 48107ad1a3
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1641559

Change-Id: Id8342097bc9fa720151a621342eab4d4813e0644
2021-03-22 12:30:16 +00:00
Chienyuan Huang
50421a5c83 Merge "Le Scan: Add ambient discovery mode (1/2)" am: 4a47532570 am: c1b4ca0ef5 am: fedc9228f3
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1629277

Change-Id: I14fe563d36d9f63e2a39cb33599a8587a3dba73c
2021-03-22 10:55:14 +00:00
Treehugger Robot
bf516b9e11 Merge "Add new @SystemApi for specifying AddressType and IRK" 2021-03-21 20:15:38 +00:00
Martin Brabham
045fe260e1 Add new @SystemApi for specifying AddressType and IRK
Bug: 178234318
Test: compiles and runs
Tag: #feature
Change-Id: Ib67e681af01260df98602003b2aca47963494c6f
2021-03-20 15:13:24 -07:00
Chienyuan Huang
4a47532570 Merge "Le Scan: Add ambient discovery mode (1/2)" 2021-03-20 00:26:04 +00:00
Jeff Sharkey
e6e4c05291 Implement per-field matching of ScanRecord.
As part of building out support for robustly matching Bluetooth LE
devices in the wild, this change checks all "fields" contained in a
ScanRecord against a given BytesMatcher.

To support matching variable-length Eddystone beacons, this change
also expands BytesMatcher to support both exact length and prefix
based rules, which are then used with rules that verify that example
Eddystone and iBeacon values can be detected with these rules:

    Eddystone: ⊆0016AAFE/00FFFFFF
    iBeacon: ⊆00FF4C0002/00FFFFFFFF

Expands testing to confirm all newly added capabilities are working.

Bug: 181812624
Test: atest BluetoothTests:android.bluetooth.le
Test: atest FrameworksCoreTests:android.os.BytesMatcherTest
Change-Id: I1cff8e08604436f4bba6f55aad64c3ce5969bf56
2021-03-18 14:17:28 -06:00
Martin Brabham
3af765a863 Fix CTS Failure
Bug: 182849735
Test: atest CtsSystemApiAnnotationTestCases:android.signature.cts.api.AnnotationTest#testAnnotation -- --abi x86_64
Change-Id: I1b9e77b05cd23299bf179c854e136fa341c81566
2021-03-16 20:11:05 -07:00
Martin Brabham
96e6e4a0b3 Bluetooth: Modify and append to the Out-of-Band API
- Modify createOutOfBand to be a SystemApi, and accept p192 and p256 data objects.
 - Modify OobData to become a SystemApi and to provide a Builder pattern for creation.

CTS-Coverage-Bug: 182420103
Bug: 178007935
Test: compiles and runs
Tag: #feature
Change-Id: I46aec8c2cb64a8da8957d01d32b879d60df7a31c
Merged-In: I46aec8c2cb64a8da8957d01d32b879d60df7a31c
2021-03-16 20:10:56 -07:00
Martin Brabham
a45008561e Fix CTS Failure
Bug: 182849735
Test: atest CtsSystemApiAnnotationTestCases:android.signature.cts.api.AnnotationTest#testAnnotation -- --abi x86_64
Change-Id: I1b9e77b05cd23299bf179c854e136fa341c81566
2021-03-16 16:22:56 -07:00