Commit Graph

220 Commits

Author SHA1 Message Date
Svet Ganov
1babd5bf51 Optimize AttributionSource tokens - base
For cases where the attribution soruce doesn't need to be
registered as trusted we are now using a shares static
token since the only purpose of the token in these cases
is for watching the source process dying as opposed to that
and security for registered cases.

bug: 192415943

Test: CtsPermissionTestCases
      CtsPermission2TestCases
      CtsPermission3TestCases
      CtsPermission4TestCases
      CtsPermission5TestCases

Change-Id: I93fde9ca1cacada7929761533dcae11b2736ce1e
2021-07-10 00:24:30 +00:00
Nate Myren
4c426c4d03 Create "trusted chain" mechanism for AttributionSource
Add and populate a "trusted" attribution flag, that verifies the
attribution sources used to create it were trusted.

Fixes: 192270935
Test: atest RuntimePermissionsAppOpTrackingTest
Change-Id: Ifd8f825151bec55aa795da7bee0a3069509f5abe
2021-06-30 16:06:59 -07:00
Nate Myren
fd49debdc0 Create Attribution Chains in HistoricalOps
Add a historical flag to signify that attribution chains should be
assembled. Assemble the chains, filter out middle nodes, and attach the
last visible node to the start as a proxy info

Bug: 158792096
Test: manual
Change-Id: I8fbd8f438c62b28fd90039440e86224c624dea79
2021-06-23 12:12:15 -07:00
Nate Myren
5cd62ee5f7 Support AttributionSource chains in PermissionUsageHelper
Test: manual
Bug: 184963112
Change-Id: Idca4ccdaab1f243b754ef15888ea679788bfdd9b
2021-06-04 12:55:50 -07:00
Svet Ganov
2eebf92965 Switch media fw permissions checks to AttributionSource
Attribution source is the abstraction to capture the data
flows for private data across apps. Checking permissions
for an attribution source does this for all apps in the
chain that would receive the data as well as the relevant
app ops are checked/noted/started as needed.

Teach speech recognition service about attribution
chains. If an implementation does nothing the OS
would enforce permisisons and do blame as always.
This apporach leads to double blaming and doesn't
support attribition chains where app calls into
the default recognizer which calls into the on
device recognizer (this nests recursively). If the
implementer takes advantage of the attribution chain
mechanims the permissions for the entire chain are
checked at mic access time and all apps are blamed
only once.

Fixed a few bugs around finishing ops for attribution
chains. Also ensured that any app death in a started
attribution chain would lead to finishing the op for
this app

bug: 158792096

Test: (added tests for speech reco)
      atest CtsMediaTestCases
      atest CtsPermissionTestCases
      atest CtsPermission2TestCases
      atest CtsPermission3TestCases
      atest CtsPermission4TestCases
      atest CtsPermission5TestCases
      atest CtsAppOpsTestCases
      atest CtsAppOps2TestCases

Merged-In: Ic92c7adc14bd2d135ac13b96f17a1b393dd562e4

Change-Id: Ic92c7adc14bd2d135ac13b96f17a1b393dd562e4
2021-06-01 23:43:29 +00:00
TreeHugger Robot
78896f98c0 Merge "Add missing permission enforcement." into sc-dev 2021-06-01 21:50:44 +00:00
Hai Zhang
a4015ce67a Add missing permission enforcement.
Since, we are opening PermissionControllerService to instant apps for
the permission group mapping API, I'm reviewing the permission checks
and this is the only missing one. However, this API is just a trigger
to update our state so calling it some more times shouldn't pose a
security risk, so this fix is just a nice-to-have.

Bug: 189836392
Test: presubmit
Change-Id: I6e9159ce090acaad2ecf522bd04c613169e03252
2021-06-01 12:45:00 -07:00
Hai Zhang
032d5f1fd5 Fix wrong permission check in
setRuntimePermissionGrantStateByDeviceAdminFromParams().

This is nice to have, but not necessarily a security fix because we are
already always enforcing ADJUST_RUNTIME_PERMISSIONS_POLICY.

Bug: 158735247
Test: presubmit
Change-Id: I629969e04e1d5e7e3ef47c8833780f19d83b9e0b
2021-06-01 18:55:01 +00:00
Hai Zhang
8bda34c493 Expose platform permission group mapping as public API.
The API is moved from PermissionControllerManager (only a System API)
to PackageManager to expose it as public API.

Bug: 182094776
Test: atest GetPermissionGroupInfoTest
Change-Id: I175afb2e37bf2651b91765029645f7940f58f39c
2021-05-21 03:03:56 +00:00
Hai Zhang
8f6290db77 Fix nullability of the group name parameter in queryPermissionsByGroup().
Change-Id: Id503da0fe4f16a92997634089fc052d58e78f9df
Fixes: 141452667
Test: presubmit
2021-04-30 21:43:05 +00:00
Nate Myren
2af054a29f Merge "Add Executor to Permission Group methods in PermissionControllerManager" into sc-dev 2021-04-27 15:18:06 +00:00
Nate Myren
599d4db0bd Add Executor to Permission Group methods in PermissionControllerManager
Test: atest GetPermissionGroupInfoTest
Fixes: 185177089
Change-Id: I6b3ff9c02d013ee48dc2f7f39d556cc6da0edac4
2021-04-26 17:51:11 -07:00
Adam Bookatz
33e17a9933 Revert "Prepare AttributionSource to expose to native"
Revert "Prepare AttributionSource to expose to native - native"

Revert submission 14225527-bug-158792096-04/16/21-1

Reason for revert: b/186467053
Reverted Changes:
I16740cc2d:Prepare AttributionSource to expose to native - na...
I4e050e78b:Prepare AttributionSource to expose to native

Change-Id: I83e4091231241c2211edf5745735f4ee993c6680
2021-04-26 23:20:46 +00:00
Svet Ganov
7b7ea938f5 Prepare AttributionSource to expose to native
Separate the internal state of AttributionSource from the
class to make it a simple AIDL we can translate automatically
to native - keeping Java and native parts in sync. This
would allow writing a thin native lib for checking attribution
source permissions which would be used to teach camera and
audio about attributions.

Deinfe an AIDL interface for passing around an attribution
source and opr performing permission checker oprations allowing
native and Java permission checks on attribution chains to be
handled. The Java side permission checker functions are in a dedicated
permisison checker service on top of which sits the PermissionChecker.
We expose similar PermissionChecker native APIs sitting on top
of the same remote interface. The nice thing is that we have
native and Java permisison checkers in sync sharing remoting
code and being close in shape.

For now the PermissionChecker in Java is divorced from the
PermissionManager but in T we will consider how to unify them,
either by an extension object on the PermmissionManager or
APIs on the PermissionManager, or another approach, and then
migrate clients off the PermissionChecker APIs.

bug: 158792096

Test: atest CtsPermission5TestCases

Change-Id: I4e050e78b2361cbf524cc213802e0fef5b487f67
2021-04-25 19:00:30 +00:00
Nate Myren
f7c1b2721e Merge "Change Permission Group methods to be callback, gate behind perm" into sc-dev 2021-04-21 21:01:05 +00:00
TreeHugger Robot
a212d74f3e Merge "Refactor Telephony phone number access checks to LegacyPermissionMgr" into sc-dev 2021-04-21 04:37:41 +00:00
Michael Groover
2947561500 Refactor Telephony phone number access checks to LegacyPermissionMgr
The TelephonyPermissions phone number access check can require several
interactions with the system_server to obtain the targetSdkVersion
and check the required permissions / appops for the requesting
package. This commit refactors all of these checks into the
LegacyPermissionManager (similar to what was previously done for the
device identifier access checks), requiring only a single request
to the system_server to check all non-subscriber access requirements.

Fixes: 159662444
Test: atest TelephonyPermissionsTest
Test: atest LegacyPermissionManagerServiceTest
Test: atest SmsManagerTest
Test: atest PhoneNumberTest
Test: atest SubscriptionControllerTest
Test: atest TelephonyManagerTest
Change-Id: I6c5cdbeecc2c4a2e200dcc33eedcb9213376f1ad
2021-04-20 17:15:59 -07:00
Nate Myren
7590ff96f0 Change Permission Group methods to be callback, gate behind perm
Create a GET_RUNTIME_PERMISSION_GROUP_MAPPING permission to gate the
permission group methods behind, and changes the methods to have
callbacks.

Test: atest GetPermissionGroupInfoTest
Fixes: 185177089
Change-Id: Ifd2ebc74f16e51b62068bdc6c8748f69bc63e923
2021-04-19 16:44:33 -07:00
Fabian Kozynski
60864b944e Do not hold indicators for apps that become paused
If an app op becomes "paused" (microphone muted or disabled by toggle),
remove the indicator immediately as opposed to holding for 5s.

Also, pass the value that we are using for mic muted to
PermissionManager, so they are in sync.

Test: atest SystemUITests
Test: manual
Fixes: 184891081
Change-Id: I4d46fc6e1cefa45c0d718cc01f40c8f060dafee7
2021-04-15 14:22:39 -04:00
Eran Messeri
9ac9fe53bf Merge "Address API review for admin-granted permissions" into sc-dev 2021-04-11 11:44:26 +00:00
Nate Myren
2d400b8737 Exclude only system and device intelligence roles from indicators
Converts both the AppOpsControllerImpl and the PermissionUsageHelper to
use the same static method when filtering which packages to show. The
only packages which are filtered are 6 device intelligence roles, and
the system package. These values are updated at most every 15 seconds

Fixes: 184141707
Test: manual
Change-Id: I9dc44197a2ff3df7783b37f450ada4ef2fb1ca6f
2021-04-07 12:48:30 -07:00
Eran Messeri
1663624e5d Address API review for admin-granted permissions
Address API review for changes related to admin-granted permissions:
* Change the provisioning extra to indicate it only affects
  sensors-related permissions.
* Add an IntDef for the AdminPermissionControlParams grant state.

Bug: 184204476
Bug: 184204334
Test: atest ManagedProvisioningTests
Change-Id: I75c8b6de1e897e02916b17f0ae3a521f8384c242
2021-04-07 19:03:44 +01:00
TreeHugger Robot
086a0be6b2 Merge "Assemble proxy chain based on package/uid, not attribution tag" into sc-dev 2021-04-07 03:08:20 +00:00
Nate Myren
1eda90e312 Assemble proxy chain based on package/uid, not attribution tag
Some proxy usages, in future, may not have matching attribution tags.
Match on package name and uid instead.

Bug: 183402046
Test: Manual
Change-Id: If122f13fb1d20bfe0bad415235f2143d41339650
2021-04-02 14:41:57 -07:00
Svet Ganov
48801b0bbd Hookup renounced permissions
Propagate renounced permissions from context params
to the context attribution source. Throw if one
tries to request at runtime a renounced permission.

Also make the AttributionSource take null for the
setters to ease usage, otherwise folks should always
check for null before calling a builder method.

Additionally, we allow apps that have UPDATE_APP_OPS_STATS
to register arbitrary trusted AttributionSource for
testing. Note that this permission allows abritrary app
op operations, thus we are not relaxing the security
model.

bug: 158792096

Test: atest CtsPermission5TestCases

Change-Id: I4330684bb8695fb998cf31e9363b94ad981ba2cc
2021-04-02 17:30:10 +00:00
Nate Myren
41886ea17c Merge "Add Api to get permission group info from PermissionController" into sc-dev 2021-04-01 15:21:09 +00:00
Nate Myren
6d7cbf74f6 Add Api to get permission group info from PermissionController
Bug: 182094776
Test: atest GetPermissionGroupInfoTest
Change-Id: I872b0658ea0d8a5aca80a83cff1e29f25b7d6d3d
2021-03-31 09:31:47 -07:00
Svet Ganov
8d2ed50604 Runtime permission attribution improvements
When an app is proxying access to runtime permission protected
data it needs to check whether the calling app has a permission
to the data it is about to proxy which leaves a trace in app ops
that the requesting app perofmed a data access. However, then the
app doing the work needs to get the protected data itself from the
OS which access gets attributed only to itself. As a result there
are two data accesses in app ops where only the first one is a
proxy one that app A got access to Foo through app B - that is the
one we want to show in the permission tracking UIs - and one
for the data access - that is the one we would want to blame on
the calling app, and in fact, these two accesses should be one -
that app A accessed Foo though B. This limitation requires fragile
one off workarounds where both accesses use the same attribution
tag and sys UI has hardcoded rules to dedupe. Since this is not
documented we cannot expect that the ecosystem would reliably
do this workaround in apps that that the workaround in the OS
would be respected by every OEM.

This change adds a mechaism to resolve this issue. It allows for
an app to create an attribution context for another app and then
any private data access thorugh this context would result in a
single app op blame that A accessed Foo though B, i.e. we no longer
have double accounting. Also this can be nested through apps, e.g.
app A asks app B which asks app C for contacts. In this case app
B creates an attribution context for app A and calls into app C
which creates an attribution context for app B. When app C gets
contacts the entire attribution chain would get a porper, single
blame: that C accessed the data, that B got the data from C, and
that A got the data form B. Furthermore, this mechanism ensures
that apps cannot forget to check permissions for the caller
before proxying private data. In our example B and C don't need
to check the permisisons for A and B, respectively, since the
permisisons for the entire attribution chain are checked before
data delivery. Attribution chains are not forgeable preventing
a bad actor to create an arbitrary one - each attribution is
created by the app it refers to and points to a chain of
attributions created by their corresponding apps.

This change also fixes a bug where all content provider accesses
were double counted in app ops due to double noting. While at
this it also fixes that apps can now access their own last ops.
There was a bug where one could not pass null getting the attributed
ops from a historical package ops while this is a valid use case
since if there is no attribution everything is mapped to the null
tag. There were some app op APIs not being piped thorough the app
ops delegate and by extension through the app ops policy. Also
now that we have nice way to express the permission chain in a
call we no longer need the special casing in activity manager to
handle content provider accesses through the OS. Fixed a bug
where we don't properly handle the android.os.shell calls with
an invlaid tag which was failing while the shell can do any tag.

Finally, to ensure the mechanims is validated and works end-to-end
we are adding support for a voice recognizer to blame the client
app for the mic access. The recognition service can create a blaming
context when opening the mic and if the mic is open, which would
do all permission checks, we would not do so again. Since changes
to PermissionChercker for handling attribution sources were made
the CL also hooks up renounced permissoins in the request permission
flow and in the permission checks.

bug:158792096
bug:180647319

Test:atest CtsPermissionsTestCases
     atest CtsPermissions2TestCases
     atest CtsPermissions3TestCases
     atest CtsPermissions4TestCases
     atest CtsPermissions5TestCases
     atest CtsAppOpsTestCases
     atest CtsAppOps2TestCases

Change-Id: Ib04585515d3dc3956966005ae9d94955b2f3ee08
2021-03-29 16:49:33 +00:00
Eugene Susla
14c9afbe6f Merge "Extend permission pregrant tracing utility" into sc-dev 2021-03-24 20:58:07 +00:00
Nate Myren
4cbdb452de Merge "Add Permission Indicator methods/classes to Test Api" into sc-dev 2021-03-24 16:27:22 +00:00
Nate Myren
9ca6298114 Add Permission Indicator methods/classes to Test Api
Also sets lastAccessTime = now for running ops

Test: atest PermissionIndicatorAppOpUsageTest
Bug: 172868375
Change-Id: I2a616f624640e0f219e33d6fa8ebf55559e24e1a
2021-03-23 13:04:47 -07:00
Eugene Susla
2055002199 Extend permission pregrant tracing utility
Bug: 182579819
Test: manual

Change-Id: I142d1c4470fe4f4b7c9ef52c23cf8dfc86fec792
2021-03-23 10:54:14 -07:00
Nate Myren
5e85167c22 Handle proxy chains including the system package
Ensure that usages with the system package are not filtered entirely.
Instead, they should not be shown on their own, and the "system" label
should not be included in proxy label chains

Bug: 172868375
Test: manual
Change-Id: If9812ce915de0ca1ac47d93d96f199a8bb768bce
2021-03-22 14:47:55 -07:00
Nate Myren
f882feeabc Remove R QPR attribution hacks
Bug: 172868375
Test: manual
Change-Id: I5e731bb821e879f6c314604912f13800ca668aa4
2021-03-16 15:10:36 -07:00
Nate Myren
1023e07f85 Show all system apps to hub teamfood, remove location indicator
Location indicator has its own flag, so it is being removed from the hub
teamfood. Also, showing all system usages (except the system app) for
the hub teamfood.

Bug: 172868375
Test: atest PrivacyDialogControllerTest, PrivacyItemControllerFlagsTest
Change-Id: Iad5b141f600a0bf830d5b2ef5169ed90533914cb
2021-03-12 12:36:27 -08:00
Eugene Susla
9076840750 Merge "Address API council feedback" into sc-dev 2021-03-04 19:09:23 +00:00
Evan Severson
33792c94ea Merge "Update permissions OWNERS files" am: 391145ab85 am: d35d84c8fc am: 69abbcb203
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1611821

MUST ONLY BE SUBMITTED BY AUTOMERGER

Change-Id: I7d0c9e41b15a62c547df2ca1fb2bca37c5ab7d43
2021-03-02 22:32:49 +00:00
Eugene Susla
206e26a294 Address API council feedback
Fixes: 181681395
Fixes: 181562406
Test: presubmit
Change-Id: I51fc6e1568a8fadf82c8c1c5b52c1356a94ce36d
2021-03-02 12:46:51 -08:00
Evan Severson
13fd14252b Update permissions OWNERS files
Test: None
Change-Id: I039bf12c65b0cd509a6772d89b96821b98ff318c
2021-03-02 10:37:41 -08:00
Nate Myren
066f1bce6e Merge "Show usage by default speech recognizer" into sc-dev 2021-02-26 23:51:30 +00:00
Nate Myren
4ee433cc90 Show usage by default speech recognizer
Test: manual
Fixes: 181067845
Change-Id: I9be50bf4bbafcedbc1c52adc0780b9821c865c8d
2021-02-26 11:22:58 -08:00
Evan Severson
c5d33bfde2 Remove role exempt flag
There is no use for this currently.

Bug: 158311343
Test: atest CtsPermission{1,3}TestCases
Change-Id: I102b30ccb3354e248e4e6be304c6dfe6135ba2a6
2021-02-25 14:04:41 -08:00
Eran Messeri
003453b354 Restrict Admin grant of sensors-related permissions
Restrict the admin of a fully-managed device or managed profile from
granting sensors-related permissions.

The admin of a managed profile cannot control permission grants for
sensors-related permissions at all.

The admin of a  fully-managed device can opt-out of having said control
by providing a provisioning extra.

This change passes the boolean flag in ActiveAdmin indicating whether
the admin has control over sensor permission grants into the permission
controller.

Manual testing:
* Install TestDPC
* Create a work profile using TestDPC.
* Get the BasicLocation app by checking out
  https://github.com/android/location-samples and building it from there.
* Install the app onto the device but do not start it.
* In TestDPC, Find "Manage app permissions", choose "Basic Location Sample"
  from the drop-down menu.
* Toggle each of the "ACCESS_COARSE_LOCATION" and
  "ACCESS_BACKGROUND_LOCATION" to "Allow".
* Observe that no notification appears.
* Start the BasicLocation app and observe the runtime permission prompt
  shows up.

Bug: 158735247
Test: Manual (more to be added).
Test: cts (see topic)
Change-Id: I12d9f7e24ad4bc09651a5e5f60b864298506c2c4
2021-02-16 19:03:57 +00:00
TreeHugger Robot
bbeeeefc70 Merge "Fix double adding of special attribution usage" into sc-dev 2021-02-11 23:18:37 +00:00
Philip P. Moltmann
8d6a0cb6af Merge "Remove me from OWNERS files" am: 25ee5a7fb7 am: bf8de269cb am: 39198ddd84
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1573324

MUST ONLY BE SUBMITTED BY AUTOMERGER

Change-Id: I429557a8537fb6417fcb9539978964ade75c8dee
2021-02-11 23:15:42 +00:00
Philip P. Moltmann
a8eb3d3e69 Remove me from OWNERS files
Test: n/a
Change-Id: I6113011e6ab0997285d5b7a86303fc60a3b98a2b
Exempt-From-Owner-Approval: Previously approved
2021-02-11 22:28:43 +00:00
Nate Myren
f187670270 Fix double adding of special attribution usage
Fixes: 180019623
Test: manual
Change-Id: I6e0681e0126bc563d8af4cd11c7db0785e47c912
2021-02-11 12:40:48 -08:00
Hai Zhang
bdd7a8e8a3 Add documentation about role permission protection in Permissions.md.
Change-Id: Ibb645d33554a05965ac344c4a4a4b7b9f004dec7
Test: presubmit
(cherry picked from commit dcbaef9481)
2021-02-02 19:06:24 +00:00
Nate Myren
2779eb839e Change recent threshold to 15 seconds
Change default recent threshold to 15 seconds

Test: build
Bug: 172868375
Change-Id: Ib716cc68744aa563fcf8988be6da56c9f95b9ab9
2021-01-29 09:50:26 -08:00
Nate Myren
f78406820e Add wifi call special case, fix phone, predictor, filter system
Add the wifi call special case, where if a call is ongoing while a
carrier privileged app is using microphone, the phone call usage is
removed. Ensure the phone mic op is listened for, add code to find the
predictor app, and show it, if the user is in a teamfood. Filter the
system app out, since the system app can be a location provider

Fixes: 178701757
Test: Manual
Change-Id: Ic1bf7f28c99bc0f596492332f7b4656c3bd7d25e
2021-01-28 14:28:31 -08:00