Commit Graph

1851 Commits

Author SHA1 Message Date
Jeff Sharkey
dd5a4f39c8 Long-tail of AttributionSource plumbing.
Wires up AttributionSource across the remaining long-tail of
Bluetooth AIDL interfaces, ensuring that developers can accurately
make calls chained back to a specific Context.

Moves "for data delivery" permission checks to happen in a single
location on each interface to ensure they're performed consistently
with the new AttributionSource arguments.  Note that "for data
delivery" isn't the best name; it's designed to represent that the
requested action was performed and should result in the relevant
appop being noted for the caller.

This change has the positive side effect of ensuring that all
interfaces are consistently enforcing the BLUETOOTH_CONNECT
permission, even in the case where BLUETOOTH_PRIVILEGED is also
required; this is what ensures that revoking the "Nearby devices"
permission takes effect for all callers.

Additionally, standardizing on enforcing permissions closer to the
AIDL entry point reduces the need for @RequiresPermission annotations
to be carried around inside the Bluetooth stack.

Bug: 183626112
Test: atest BluetoothInstrumentationTests
Change-Id: I8023dda654e325b8bfa2f0cdb994ad63a2b429d4
2021-04-24 08:31:43 -06:00
Jeff Sharkey
efe1110be8 More AttributionSource plumbing.
To prepare for future work which will plumb AttributionSource values
through all remaining AIDLs, we need profiles to interact directly
with the specific BluetoothAdapter they were created from.  This is
how we'll ensure that the relevant AttributionSource can be chained
down from the original Context they're obtained from.

This change also marks getDefaultAdapter() as deprecated to clearly
communicate that BluetoothManager.getAdapter() is the best-practice
path to obtaining a correctly scoped BluetoothAdapter instance.

Bug: 183626112
Test: atest BluetoothInstrumentationTests
Change-Id: I1e15170d7679019bbb6e396279d6e633e3dad4d6
2021-04-23 08:51:49 -06:00
Oli Lan
52f8d4c9c3 Pass attribution source to BT APIs.
This adds attribution source to BT method calls. This is now
required to allow the app ops for the new BT permissions
(BLUETOOTH_CONNECT, BLUETOOTH_ADVERTISE, and BLUETOOTH_SCAN)
to be noted.

Bug: 183626112
Test: atest BluetoothInstrumentationTests
Change-Id: I81598553b762e491d6364064a2e1ef41dec89bf9
2021-04-22 14:47:39 -06:00
Jeff Sharkey
67d4e1e079 Refinement of AttributionSource handling.
Previous CLs had started passing AttributionSource values across
Binder calls inside BluetoothDevice instances, but this can cause
confuse the permission check logic in the future; we should instead
always aim to use the AttributionSource closest to the app making
the call, instead of parceling it.

This change also improves logging to highlight when we're quietly
treating a permission as denied, and when a UID is mismatched.

Bug: 186106084
Test: atest BluetoothInstrumentationTests
Change-Id: I5d3fdb3c573cb9e77474952d8680caa4c4c464eb
2021-04-22 12:46:06 -06:00
Jeff Sharkey
c1b024d280 Merge "Pass AttributionSource to AdapterService methods." into sc-dev 2021-04-21 22:40:20 +00:00
Jeff Sharkey
d4b3fcac16 Merge "Annotations for Bluetooth broadcast intents." into sc-dev 2021-04-21 22:23:48 +00:00
Jeff Sharkey
f459828358 Annotations for Bluetooth broadcast intents.
Recent work has been using Error Prone rules and annotations to
reflect the current state of permission enforcement across the
Bluetooth stack, and we're now in a position were we can add new
permission enforcement that had been missing.

We've currently standardized on saying that APIs that return device
or Bluetooth state information (without sharing details about any
particular remote Bluetooth device) do not need to be permission
protected.

Bug: 183626724
Test: ./build/soong/soong_ui.bash --make-mode Bluetooth RUN_ERROR_PRONE=true
Change-Id: I53ac7a4fe1dea57316048c3cac4fa237b6ba3d38
2021-04-21 12:59:38 -06:00
Oli Lan
141edf9ef6 Pass AttributionSource to AdapterService methods.
This adds attribution source to AdapterService bluetooth method
calls. This is now required to allow the app ops for the new
bluetooth permissions (BLUETOOTH_CONNECT, BLUETOOTH_ADVERTISE,
and BLUETOOTH_SCAN) to be noted.

Bug: 183626112
Test: atest AdapterServiceTest
Test: atest CtsPermissionTestCases:android.permission.cts.NearbyDevicesPermissionTest
Change-Id: I8d1fe41ca9945a3baab584f248a17b3a1eb255f7
2021-04-21 17:59:06 +01:00
Rahul Sabnis
edad7c7c60 Update docs to reflect LE batch scan report delay floor
Tag: #feature
Bug: 167340030
Test: Manual
Change-Id: Ieeb0e6bccfc316fd4c8cdc40f6865b4185d6d9e8
2021-04-20 16:40:15 -07:00
Nataniel Borges
0cd1de2226 Merge "Revert "Set a floor value for BLE Batch Scan report delay of 5000ms"" am: 6528da5667 am: 3ed5afa516 am: 81583909a9
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1681445

Change-Id: Ia2a73845fb92c457b37bacef7542aa47535560d4
2021-04-20 17:14:48 +00:00
Nataniel Borges
5aa369359e Revert "Set a floor value for BLE Batch Scan report delay of 5000ms"
This reverts commit ea303904fd.

Reason for revert: b/185890964

Change-Id: I270dc16de0e24728c694830fbe920786b6d90174
2021-04-20 15:50:03 +00:00
Treehugger Robot
0bf5efaeab Merge "Set a floor value for BLE Batch Scan report delay of 5000ms" am: ce2a2c80dd am: da5eb08ae3 am: 2b8dce1db1
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1676810

Change-Id: I2aafeceb53a673e0172e5873c7354a6d59acc530
2021-04-20 04:00:37 +00:00
Rahul Sabnis
ea303904fd Set a floor value for BLE Batch Scan report delay of 5000ms
Tag: #feature
Bug: 167340030
Test: Manual
Change-Id: I4ef99a9562f1447a2ccee42a344384a38a487c19
2021-04-19 17:29:02 -07:00
Jeff Sharkey
655d691d65 Add missing Bluetooth API permission enforcement.
Recent work has been using Error Prone rules and annotations to
reflect the current state of permission enforcement across the
Bluetooth stack, and we're now in a position were we can add new
permission enforcement that had been missing.

We've currently standardized on saying that APIs that return device
or Bluetooth state information (without sharing details about any
particular remote Bluetooth device) do not need to be permission
protected.

Bug: 183626724
Test: ./build/soong/soong_ui.bash --make-mode Bluetooth RUN_ERROR_PRONE=true
Change-Id: I37a9e03ecdca6f7a6eb9d7f094e2f95a97036612
2021-04-18 07:58:11 -06:00
Jeff Sharkey
6eed56ddd3 More Bluetooth API annotation updates.
This change adds a "BluetoothPermissionChecker" that ensures that
all Bluetooth permission annotations are consistent.  In addition, it
verifies that all Bluetooth public APIs have been audited to be
permission protected where relevant.

We've currently standardized on saying that APIs that return device
or Bluetooth state information (without sharing details about any
particular remote Bluetooth device) do not need to be permission
protected.

This change is only annotations and has no behavior changes.

Bug: 183626724
Test: ./build/soong/soong_ui.bash --make-mode Bluetooth RUN_ERROR_PRONE=true
Change-Id: Ie80b15b058359bf1e9a6ee881b89cb3e5b584ca1
2021-04-16 13:31:22 -06:00
Jeff Sharkey
938e329b77 Refine BluetoothLeAdvertiser permissions.
Technically these APIs required both ADVERTISE and CONNECT, since
internally it would attempt getting the device name as part of
calculating packet lengths.  These methods shouldn't require the
CONNECT permission, so we add a getNameLengthForAdvertise() method
internally to remove this dependency.

Bug: 183626724
Test: ./build/soong/soong_ui.bash --make-mode Bluetooth RUN_ERROR_PRONE=true
Change-Id: I245417bfc26d6d3a4f8be14077c7f1d271b5959e
2021-04-15 14:58:02 -06:00
Martin Brabham
76a512f958 OOB generateLocalOobData
unhide @SystemApi callback methods

Bug: 178007935
Tag: #feature
Test: compiles
Change-Id: I2d4167a6c92ee0cc24da12df206838161c8f3318
Merged-In: I2d4167a6c92ee0cc24da12df206838161c8f3318
2021-04-15 18:36:06 +00:00
Jeff Sharkey
cd5c179783 Merge changes from topic "apr10" into sc-dev
* changes:
  Update Bluetooth API annotations.
  Error Prone for RequiresPermission across AIDL.
2021-04-15 13:43:03 +00:00
Jeff Sharkey
4acdb1beff Update Bluetooth API annotations.
Recent work has introduced a new "Nearby devices" runtime permission
which protects all existing Bluetooth APIs; we've done this by
defining a <split-permission> to convert the old BLUETOOTH and
BLUETOOTH_ADMIN permissions into one of three new permissions:

* BLUETOOTH_ADVERTISE: Required to be able to advertise to nearby
                       Bluetooth devices.
* BLUETOOTH_CONNECT:   Allows applications to connect to paired
                       bluetooth devices.
* BLUETOOTH_SCAN:      Required to be able to discover and pair
                       nearby Bluetooth devices.

At its core, this change begins updating the Bluetooth APIs to have
correct @RequiresPermission indicating which permission is actually
enforced internally.  To ensure alignment across Binder, the newly
added "RequiresPermissionChecker" Error Prone checker was used to
discover any inconsistencies, ensuring correctness from server-side
enforcement up through to the public APIs.

In addition, since developers will continue building apps for both
modern and legacy platforms, this change introduces new auto-doc
annotations which will emit helpful consistent documentation
describing the behavior of older devices that are still using the
old permission model.

Bug: 183626724
Test: ./build/soong/soong_ui.bash --make-mode Bluetooth RUN_ERROR_PRONE=true
Change-Id: I02aa127e8e07f239561f4f2a3bbdfc6fccb82f7f
2021-04-14 21:13:24 -06:00
Treehugger Robot
b2e2624e8b Merge "Bluetooth OOB: Fix getLeAppearance" am: ef0304a087 am: 2988998bd3 am: 6745daf3c2
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1673875

Change-Id: I8d2d9d4ea7bfa3b9a3a4bfe358da4275688b6f19
2021-04-15 03:11:10 +00:00
Martin Brabham
ba2c904f8d OOB generateLocalOobData
unhide @SystemApi callback methods

CTS-Coverage-Bug: 184395281
Bug: 178007935
Tag: #feature
Test: compiles
Change-Id: I2d4167a6c92ee0cc24da12df206838161c8f3318
2021-04-14 18:53:04 +00:00
Hansong Zhang
a77bdb5161 Bluetooth OOB: Fix getLeAppearance
Bug: 185196125
Test: Use OOB pairing
Change-Id: I1cb1c33b0b17f2fd242f6579844996c2ccf09e62
2021-04-13 11:55:28 -07:00
Martin Brabham
6d4100e433 OOB: Implement getLocalOutOfBand API
CTS-Coverage-Bug: 184395281
Bug: 178007935
Tag: #feature
Test: manual
Change-Id: I5bc11ac13d9cbb8f76f422aa4aea8295ebec95b4
Merged-In: I5bc11ac13d9cbb8f76f422aa4aea8295ebec95b4
2021-04-07 14:08:39 -07:00
TreeHugger Robot
dcc1a906cf Merge "OOB: Implement generateLocalOutOfBand API" into sc-dev 2021-04-07 19:32:23 +00:00
Martin Brabham
2093f69721 OOB: Implement generateLocalOutOfBand API
CTS-Coverage-Bug: 184395281
Bug: 178007935
Tag: #feature
Test: manual
Change-Id: I5bc11ac13d9cbb8f76f422aa4aea8295ebec95b4
2021-04-06 18:13:29 +00:00
Oli Lan
ec2ca2d83e Pass AttributionSource to bluetooth scanning methods.
This passes the AttributionSource to AdapterService and GattService
methods that perform scanning or discovery.

Bug: 183203469
Test: atest GattServiceTest
Test: atest AdapterServiceTest
Test: atest CtsPermissionTestCases:android.permission.cts.NearbyDevicesPermissionTest

Change-Id: Id68558624fbae69eac3a8613b9536eb6e0df75bf
2021-04-01 15:51:40 +01:00
Svet Ganov
8d2ed50604 Runtime permission attribution improvements
When an app is proxying access to runtime permission protected
data it needs to check whether the calling app has a permission
to the data it is about to proxy which leaves a trace in app ops
that the requesting app perofmed a data access. However, then the
app doing the work needs to get the protected data itself from the
OS which access gets attributed only to itself. As a result there
are two data accesses in app ops where only the first one is a
proxy one that app A got access to Foo through app B - that is the
one we want to show in the permission tracking UIs - and one
for the data access - that is the one we would want to blame on
the calling app, and in fact, these two accesses should be one -
that app A accessed Foo though B. This limitation requires fragile
one off workarounds where both accesses use the same attribution
tag and sys UI has hardcoded rules to dedupe. Since this is not
documented we cannot expect that the ecosystem would reliably
do this workaround in apps that that the workaround in the OS
would be respected by every OEM.

This change adds a mechaism to resolve this issue. It allows for
an app to create an attribution context for another app and then
any private data access thorugh this context would result in a
single app op blame that A accessed Foo though B, i.e. we no longer
have double accounting. Also this can be nested through apps, e.g.
app A asks app B which asks app C for contacts. In this case app
B creates an attribution context for app A and calls into app C
which creates an attribution context for app B. When app C gets
contacts the entire attribution chain would get a porper, single
blame: that C accessed the data, that B got the data from C, and
that A got the data form B. Furthermore, this mechanism ensures
that apps cannot forget to check permissions for the caller
before proxying private data. In our example B and C don't need
to check the permisisons for A and B, respectively, since the
permisisons for the entire attribution chain are checked before
data delivery. Attribution chains are not forgeable preventing
a bad actor to create an arbitrary one - each attribution is
created by the app it refers to and points to a chain of
attributions created by their corresponding apps.

This change also fixes a bug where all content provider accesses
were double counted in app ops due to double noting. While at
this it also fixes that apps can now access their own last ops.
There was a bug where one could not pass null getting the attributed
ops from a historical package ops while this is a valid use case
since if there is no attribution everything is mapped to the null
tag. There were some app op APIs not being piped thorough the app
ops delegate and by extension through the app ops policy. Also
now that we have nice way to express the permission chain in a
call we no longer need the special casing in activity manager to
handle content provider accesses through the OS. Fixed a bug
where we don't properly handle the android.os.shell calls with
an invlaid tag which was failing while the shell can do any tag.

Finally, to ensure the mechanims is validated and works end-to-end
we are adding support for a voice recognizer to blame the client
app for the mic access. The recognition service can create a blaming
context when opening the mic and if the mic is open, which would
do all permission checks, we would not do so again. Since changes
to PermissionChercker for handling attribution sources were made
the CL also hooks up renounced permissoins in the request permission
flow and in the permission checks.

bug:158792096
bug:180647319

Test:atest CtsPermissionsTestCases
     atest CtsPermissions2TestCases
     atest CtsPermissions3TestCases
     atest CtsPermissions4TestCases
     atest CtsPermissions5TestCases
     atest CtsAppOpsTestCases
     atest CtsAppOps2TestCases

Change-Id: Ib04585515d3dc3956966005ae9d94955b2f3ee08
2021-03-29 16:49:33 +00:00
Treehugger Robot
d2cc19e8f1 Merge "Remove BluetoothHeadset#setPriority which was deprecated in Android 11" am: cdf9e7ef43 am: 283653d4b1 am: c93442cac9
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1650990

Change-Id: I40ae55301eb6b33e596e7c7976dda4caa837e70c
2021-03-25 04:31:19 +00:00
Rahul Sabnis
2b735a548f Remove BluetoothHeadset#setPriority which was deprecated in Android 11
Tag: #feature
Bug: 183551808
Test: Manual
Change-Id: I88745589ec66d3060d24b530fe49fea8926726c6
2021-03-24 14:01:52 -07:00
Jack He
4acab1d9ae Merge "ScanFilter.setDeviceAddress: Should send deviceAddress instead of mDeviceAddress to the next level" am: b4d4127efb am: c1d92b8ddd am: 7617088bd9
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1649650

Change-Id: I1d0ba23462d69dbae4cde8eb6d6d271afd39797c
2021-03-23 19:35:34 +00:00
Rahul Sabnis
7030bd354f Merge "Makes BluetoothDevice#setAlias a public API" into sc-dev 2021-03-23 19:07:24 +00:00
Chen Chen
feab55912c ScanFilter.setDeviceAddress: Should send deviceAddress instead of mDeviceAddress to the next level
Bug: 183409081
Test: build and run

Change-Id: I2d25d21b0f143fc7362679e0094455c9132fda9d
2021-03-23 17:43:36 +00:00
Rahul Sabnis
c7635a46e7 Makes BluetoothDevice#setAlias a public API
Tag: #feature
Bug: 181093329
Test: atest BluetoothDeviceTest
Change-Id: Ib94bedab5d6d4c63a19096f61187f58dd8937b55
2021-03-22 16:07:37 -07:00
Treehugger Robot
db77ba6c0e Merge "Add new @SystemApi for specifying AddressType and IRK" am: bf516b9e11 am: 6ec4bd694b am: 48107ad1a3
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1641559

Change-Id: Id8342097bc9fa720151a621342eab4d4813e0644
2021-03-22 12:30:16 +00:00
Chienyuan Huang
50421a5c83 Merge "Le Scan: Add ambient discovery mode (1/2)" am: 4a47532570 am: c1b4ca0ef5 am: fedc9228f3
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1629277

Change-Id: I14fe563d36d9f63e2a39cb33599a8587a3dba73c
2021-03-22 10:55:14 +00:00
Treehugger Robot
bf516b9e11 Merge "Add new @SystemApi for specifying AddressType and IRK" 2021-03-21 20:15:38 +00:00
Martin Brabham
045fe260e1 Add new @SystemApi for specifying AddressType and IRK
Bug: 178234318
Test: compiles and runs
Tag: #feature
Change-Id: Ib67e681af01260df98602003b2aca47963494c6f
2021-03-20 15:13:24 -07:00
Chienyuan Huang
4a47532570 Merge "Le Scan: Add ambient discovery mode (1/2)" 2021-03-20 00:26:04 +00:00
Jeff Sharkey
e6e4c05291 Implement per-field matching of ScanRecord.
As part of building out support for robustly matching Bluetooth LE
devices in the wild, this change checks all "fields" contained in a
ScanRecord against a given BytesMatcher.

To support matching variable-length Eddystone beacons, this change
also expands BytesMatcher to support both exact length and prefix
based rules, which are then used with rules that verify that example
Eddystone and iBeacon values can be detected with these rules:

    Eddystone: ⊆0016AAFE/00FFFFFF
    iBeacon: ⊆00FF4C0002/00FFFFFFFF

Expands testing to confirm all newly added capabilities are working.

Bug: 181812624
Test: atest BluetoothTests:android.bluetooth.le
Test: atest FrameworksCoreTests:android.os.BytesMatcherTest
Change-Id: I1cff8e08604436f4bba6f55aad64c3ce5969bf56
2021-03-18 14:17:28 -06:00
Martin Brabham
3af765a863 Fix CTS Failure
Bug: 182849735
Test: atest CtsSystemApiAnnotationTestCases:android.signature.cts.api.AnnotationTest#testAnnotation -- --abi x86_64
Change-Id: I1b9e77b05cd23299bf179c854e136fa341c81566
2021-03-16 20:11:05 -07:00
Martin Brabham
96e6e4a0b3 Bluetooth: Modify and append to the Out-of-Band API
- Modify createOutOfBand to be a SystemApi, and accept p192 and p256 data objects.
 - Modify OobData to become a SystemApi and to provide a Builder pattern for creation.

CTS-Coverage-Bug: 182420103
Bug: 178007935
Test: compiles and runs
Tag: #feature
Change-Id: I46aec8c2cb64a8da8957d01d32b879d60df7a31c
Merged-In: I46aec8c2cb64a8da8957d01d32b879d60df7a31c
2021-03-16 20:10:56 -07:00
Martin Brabham
a45008561e Fix CTS Failure
Bug: 182849735
Test: atest CtsSystemApiAnnotationTestCases:android.signature.cts.api.AnnotationTest#testAnnotation -- --abi x86_64
Change-Id: I1b9e77b05cd23299bf179c854e136fa341c81566
2021-03-16 16:22:56 -07:00
Chienyuan
f757d2fa69 Le Scan: Add ambient discovery mode (1/2)
Bug: 177466875
Test: manual
Change-Id: I4a5c8a0768903ef0838dcf55cf5cfba9a0a18eef
2021-03-16 17:53:19 +08:00
Martin Brabham
6ab241ca6a Bluetooth: Modify and append to the Out-of-Band API
- Modify createOutOfBand to be a SystemApi, and accept p192 and p256 data objects.
 - Modify OobData to become a SystemApi and to provide a Builder pattern for creation.

CTS-Coverage-Bug: 182420103
Bug: 178007935
Test: compiles and runs
Tag: #feature
Change-Id: I46aec8c2cb64a8da8957d01d32b879d60df7a31c
2021-03-10 16:39:56 -08:00
Rahul Sabnis
d65ce8e59f Merge "Derestrict some APIs." am: 8e97fea3c2 am: 4651bc7b96 am: 6b93271842
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1623840

MUST ONLY BE SUBMITTED BY AUTOMERGER

Change-Id: I467147251bf2f581bc3c5bbb823324660bd935fe
2021-03-09 23:10:06 +00:00
Rahul Sabnis
8e97fea3c2 Merge "Derestrict some APIs." 2021-03-09 21:29:12 +00:00
Mathew Inwood
cbc3132096 Derestrict some APIs.
They were retricted because we thought they were unused, but it turns out
that they are needed afterall.

NoNonSdkCheck: 170729553

Bug: 181103983
Test: N/A
Change-Id: Iddf7916456be27d60d2a7520d7cadcda1d04cac6
2021-03-09 21:24:00 +00:00
Xin Li
1af6a12e98 Merge "Merge RQ2A.210305.007" 2021-03-03 21:41:39 +00:00
Jakub Pawlowski
cce8e9ec91 Merge "Fix comment typo in PeriodicAdvertisingParameters" am: d806639032 am: 5b746422d6 am: 81c2336e23
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1614522

MUST ONLY BE SUBMITTED BY AUTOMERGER

Change-Id: I1452acbb0e4ad1c72633a849441619cf82002c65
2021-03-03 20:24:46 +00:00
Jakub Pawlowski
5b746422d6 Merge "Fix comment typo in PeriodicAdvertisingParameters" am: d806639032
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1614522

MUST ONLY BE SUBMITTED BY AUTOMERGER

Change-Id: I20348933b26ae9dc07b20370832ea52187362c17
2021-03-03 19:09:20 +00:00