Because Bluetooth is going mainline, we need to remove call to hidden
API.
Intent.ACTION_SETTING_RESTORED and extra are currently hidden.
There is no known alternative, so this CL make them SystemApi.
Bug: 211851706
Test: Build + start bt
Tag: #refactor
Change-Id: I7a105946f075819f21b91a39bc37c6e167439bf4
This allows holders of START_CROSS_PROFILE_ACTIVITIES permission to start an activity of the caller package in the other profile.
Test: atest CrossProfileAppsHostSideTest (with new tests in change I661d4b7132291950c8bcb4690d90154a78751b1e)
Ignore-AOSP-First: seeking internal review on WIP change prior to merging in AOSP
Bug: 207117478
Change-Id: I5afa2e458b2eda4f53cfceabe3af950c0df63ad7
Rename the error codes as they will be used by
non-staged sessions as well.
Bug: 210359798
Test: atest StagingManagerTest \
PackageInstallerSessionTest \
CtsStagedInstallHostTestCases
Change-Id: Iec572d7a85f2615204ac069a42edb569ecadb294
This commit fixes a typo in the RegisteredServicesCache when
registering for the ACTION_USER_REMOVED broadcast; previously this
action was added to the sdFilter that was defined for the previous
call to registerReceiver, but then the last call to registerReceiver
used the empty userFilter.
Fixes: 214122859
Test: Manually verified receiver was successfully registered with action
Change-Id: I72b49fa02845844fe7788817430f289f2aad7bc4
Test: Manual test using a non-privileged app, atest
android.permission.cts.SelfRevokeRuntimePermissionTest
When calling the API, the permission (along with any other permissions
from the same group) for the current package is downgraded to a one-time
permission, and a one-time permission session is started.
Bug: 210387494
Change-Id: I9f061cbc8c3db720127c96200fe94a644246b6d7
The queries tag in the manifest that declares intent's visibility
with the uri data without the host name should only match browsers'
intent filters. This CL fixes intent filters with a wildcard prefix
in the host name are matched incorrectly by the queries of browsers.
Bug: 210405218
Test: atest AppEnumerationTests
Test: atest IntentFilterTest
Change-Id: Ib4e968c1f9e6e543c1d3dece230579def10ee306
`processes` is initialized as an empty map, so we're currently always
hitting the loop case. We should avoid it.
Bug: 213021110
Test: atest PackageManagerPerfTest#testGetApplicationInfoWithFiltering
Test: atest CtsProcessTest
Test: atest PackageManagerServiceUnitTests
Change-Id: I49fa8adb0cf10e405b2251e7de78caea1bbd8fa1
Manually migrate the few cases of:
* readArray()
* readParcelableArray()
To the new parcel APIs that take the expected type as the last
parameter. This enhances security because it prevents unexpected types
*before* running unparcelling code. More details at go/safer-parcel.
Owners, please check that the type of the objects expected is always a
subtype of the type provided as the 3rd parameter. This is usually easy
to verify due to casts that happen shortly after.
These changes often allowed further transformations but I decided to
avoid them to keep this change small and targeted.
This was manual since it's tricky to get lint to infer the type in
those cases and it was only a few.
Bug: 195622897
Test: TH passes
Change-Id: I262ed7cd6d3bc15b32e9296e88a8a67fdb59e880
App can set a android.internal.PROPERTY_NO_APP_DATA_STORAGE property in it's
AndroidManifest.xml which will tell platform to avoid creating data
directories for it.
This property is intentionally not exposed as public API because not
having private app storage is a very niche requirement.
This change also logic to prevent app updates from changing value of the
property, i.e.: if an installed app doesn't specify value of the
PROPERTY_NO_APP_DATA_STORAGE property (or has it set to false), then any
update to this app shouldn't have this property specified (or explicitly
set it to false). If an app has PROPERTY_NO_APP_DATA_STORAGE set to
true, then all updates should keep that property set to true.
Note: this change only takes into account internal storage. Removing
app's external storage will be done in the follow up cl.
Bug: 211761016
Test: atest PackageManagerShellTest
Change-Id: I3e541d947a77f5c050bf706f64009f21c24dcbc9
Currently, BaseParceledListSlice will hold a reference to the List<>
until the Binder object is destroyed. However, this requires that the
receiver run GC before the sender's global Binder reference can be
removed, causing the List to be retained until both receiver and
sender perform GC. Since the List is usually the large part of the
object, instead clear the reference to the List once the transfer to
the receiver completes, allowing the List to be GC'd before the
receiver GC's its reference to the sender's Binder object.
Test: boots
Bug: 213236807
Change-Id: I22d6e56c953db3c85179911b909d5b6e7c8ba784
The dialog is shown if the app is not a signature app, the system is
ready, and the app has created at least one notification channel.
Also applies the SHOULD_SHOW_REQUEST flag to all packages with implicit
POST_NOTIFICATIONS permissions
Bug: 194833441
Test: atest NotificationPermissionTest
Change-Id: I4cb8cc7bcc3635f55e291f176f722dd420a4a1bb
Bug: 152453213
Tag: #refactor
This commit prepares PropertyInvalidatedCache to function as a system
api. Specifically, the methods recompute() and bypass() which may be
overridden by clients are now public (instead of protected). This
forces an update to all existing clients, to accommodate the change in
method visibility.
Two small changes have been made as cleanup:
1. The awkwardly named debugCompareQueryResults() is now
resultEquals(), which is more or less consistent with how other
equality tests are named in Android. This name change affects two
clients.
2. PackageManager has changed to use resultEquals() instead of
maybeCheckConsistency(). This provides a simpler and more
consistent use of the APIs. maybeCheckConsistency() has been made
private.
Test: atest PropertyInvalidatedCacheTests
Change-Id: I4110f8e887a4fd8c784141e8892557a9d1b80a94
Similar to bindService(), even if bindServiceAsUser() returns false,
unbindService() must still be called to allow the service to shut down.
The documentation is updated to reflect this.
Bug: 212663289
Test: m ds-docs-java
Change-Id: I780d307f4a0ebf8bef508932181e580f168b5578
In order to registerContentObserver as other user, callers need to hold
the INTERACT_ACROSS_USERS_FULL permission.
Bug: 206743591
Test: CtsContentTestCases
Change-Id: I2f373a3f064718cc87bdda35a5854b6a6fd2e7aa
Declaring duplicate permissions with different protection levels is
not allowed. Add the scheme enforcement for manifest during parsing.
Bug: 211934395
Test: atest AppSecurityTests
Change-Id: Ieb006ab4abf19baf949e9b5bfd3e3fea16237527