Commit Graph

169 Commits

Author SHA1 Message Date
Meng Wang
0c1b382ace Merge "Allow ImsServiceEntitlement app to schedule jobs" into sc-dev 2021-06-08 23:50:09 +00:00
samalin
cc01a8a656 Allow ImsServiceEntitlement app to schedule jobs
ImsServiceEntitlement is a headless app for certain carriers requiring
background IMS provisioning only. So the app needs to be allowed to
schedule jobs.

Bug: 189397221
Test: make
Change-Id: Ib910681ef81a417aaa4a13514260cfa26098a048
2021-06-03 16:38:16 +00:00
Suprabh Shukla
a1812e90a3 Add emergency app to power-save allowlist
Test: Manually run:
adb shell dumpsys alarm
Should show 'com.android.emergency' under 'Exempted bucket packages'.

Bug: 189866352
Change-Id: I485dd3e4d9026e576b670a1a4439ea62eec987f3
2021-06-02 14:08:32 -07:00
Treehugger Robot
88d1911f16 Merge "Grant keystore permission to register pull stats" am: 63788ff48a am: e2d58f3789 am: f42a439274
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1683905

Change-Id: I06580e0443e78eb4ea23e7aa0278b14ae9e8da3c
2021-04-22 03:29:20 +00:00
Seth Moore
226b32669c Grant keystore permission to register pull stats
Test: statsd_testdrive 10103
Bug: 172013262
Change-Id: I4d3ad2172b522b79454f5232b6d89c16178593d5
2021-04-21 23:13:43 +00:00
Hall Liu
f4562b5cee Remove fixed grant of READ_PHONE_STATE and cleanup
No longer grant READ_PHONE_STATE as a fixed permission to all apps
holding READ_PRIVILEGED_PHONE_STATE. Also clean up the previous grants
by un-fixing the permission if the app requests it in the manifest, and
removing it altogether if the app only requests READ_PRIV.

Bug: 183537857
Test: manual -- prepare two system apps, one with READ_PRIV and
READ_PHONE and one with only READ_PRIV, then go through the upgrade flow
with this CL.

Change-Id: Id1fac0f9f4391857f46c7109eadafd60420b279d
2021-04-19 15:00:01 -07:00
TreeHugger Robot
c74ea74939 Merge "Upgrading allowlist for calendar provider" into sc-dev 2021-04-12 19:56:32 +00:00
Suprabh Shukla
cd83b1fac7 Upgrading allowlist for calendar provider
This allows it to schedule alarms while the device is in doze without
needing SCHEDULE_EXACT_ALARM permission, which is user visible.

Test: adb logcat -s AndroidRuntime
should show no crashes for "com.android.providers.calendar" due to
missing SCHEDULE_EXACT_ALARM.

Bug: 171306433
Change-Id: I3dc358f0de0f6d869c3c6e7d6c2c243dc2348096
2021-04-09 14:52:46 -07:00
Jeff Sharkey
6dcac06a84 New BLUETOOTH_ADVERTISE manifest permission.
This change is part of defining a distinct BLUETOOTH_ADVERTISE
permission to guard the BluetoothLeAdvertiser APIs, since that's a
distinct enough of an operation from SCAN and CONNECT.  It'll
continue to be covered under the general "Nearby devices" runtime
permission group.

Bug: 181813006
Test: atest CtsPermission2TestCases
Test: atest CtsPermission3TestCases
Change-Id: I8b62e4d625df1e201f12a73025cd29c431feea79
2021-04-08 20:15:02 -06:00
Christine Franks
592b9daa1c Merge "Create VIRTUAL_INPUT_DEVICE signature permission" into sc-dev 2021-03-23 20:25:06 +00:00
Jay Thomas Sullivan
4452bbd065 Split new NEARBY_DEVICES permissions
This creates a "split permission" from:
- BLUETOOTH to BLUETOOTH_SCAN and BLUETOOTH_CONNECT, and
- BLUETOOTH_ADMIN to BLUETOOTH_SCAN and BLUETOOTH_CONNECT
...for apps targetting SDK<31.

What this means is that any apps that use either the BLUETOOTH or the
BLUETOOTH_ADMIN permission, and target SDK<31, will automatically be
be granted the BLUETOOTH_SCAN and BLUETOOTH_CONNECT permissions.

Bug: 181813006
Test: manual
Change-Id: I92a974203fd51e87747e740273a21ba399a81cd0
2021-03-22 13:23:29 -06:00
Christine Franks
3dfad4132e Create VIRTUAL_INPUT_DEVICE signature permission
This is used to convey the AID_UHID supplemental gid

Bug: 182854143
Test: n/a
Change-Id: Iaba2db19100ad0cbc43da09e4ba0102e336a704c
2021-03-22 11:59:54 -07:00
Zimuzo Ezeozue
b3705153db Merge "Fix MANAGE_EXTERNAL_STORAGE permission gid mapping" into sc-dev 2021-03-18 15:02:17 +00:00
Zim
782dc19e95 Fix MANAGE_EXTERNAL_STORAGE permission gid mapping
In Android R, we introduced a platform.xml based
mapping. Unfortunately, it only worked for signature|preinstalled
apps.

To support apps granted the appop (via special app access
permissions), we now check the permission and appop grant state
explicitly and grant the app the external_storage gid appropriately

Test: Manual
Bug: 165515144

Change-Id: Ib91e1b3a7e54ac2c83fb1d94446bed06fd44bcf6
2021-03-17 19:42:18 +00:00
Oscar Azucena
4537327187 Added interact accross user permission to media uid
Added interact accross user permission to media uid so that it can query
packages for UID in cases where media service is running for user 0 and
applications runs for different user id (i.e. 10) as is the case in car.

Bug: 181574201
Test: build seahawk (car target)
Test: run media recorder application with RECORD_AUDIO permission
Test: run media recorder application without RECORD_AUDIO permission
Change-Id: I5052c92831978a7e6c8277d3c5a4e6cb5ed8a78b
2021-03-12 10:50:54 -08:00
Robert Shih
7562087ee0 Give uid media REGISTER_STATS_PULL_ATOM permission
Bug: 141714243
Bug: 159337195
Test: statsd_testdrive 10099
Change-Id: I08d4f4aef3dcd7c94e9a120b0d4fa1d1e267a2b0
2021-03-12 16:58:23 +00:00
Evan Severson
e47b4eafe3 Give camera/audio the OBSERVE_SENSOR_PRIAVY permisison
This permission is needed to check if they should mute the feed.

Test: Manual
Fixes: 181724488
Change-Id: I5ffa01b29b4deff72238688e06e0f0dd9a2b351f
2021-03-02 19:45:07 -08:00
Yuncheol Heo
5f3f9ce6eb Give INTERACT_ACROSS_USERS permission to audioserver
- gcar_emu_x86_64 starts to crash after commit 1dafc38 is merged.

Bug: 179455284
Test: Build gcar_emu_x86_64 and check if it boots successfully.
Change-Id: I59dad57c846e3a83d71abb58fdd5e57019d99e75
2021-02-05 23:34:26 +00:00
Evan Severson
7ce41c1082 Remove mic/camera permission split
Apps can't request this permission anyways so some apps started
misbehaving when forcing users to grant all permissions without caring
what they are.

Test: Boot
Fixes: 172844303
Bug: 158311343
Change-Id: Ia83ad5433ff3cdae57d901b3a9d781725124c6b9
2021-02-01 18:11:04 -08:00
Steven Moreland
1d09a22ec4 Merge "Remove declaration of hidl manager -> base dep" am: 4ff4b2ee17 am: 742771fdd7 am: e798d05a73 am: d53ccbc7bf
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1467918

Change-Id: If382fe51b02209c72089b7c0965f63c52fe1614f
2020-10-22 06:11:13 +00:00
Steven Moreland
fb52599e8a Remove declaration of hidl manager -> base dep
This dependency is fictitious: hidl manager actually contains a static
copy of hidl base for convenience. Separate libraries were created
later (e.g. android.hidl.manager-java-shallow) in order for users of
these libraries to specify the exact deps they need.

Fixes: 170710203
Test: boot and check logs

:) adb logcat | grep android.hidl.manager-V1.0-java.jar
10-21 00:42:53.173   328   328 D ApplicationLoaders: Created zygote-cached class loader: /system/framework/android.hidl.manager-V1.0-java.jar
10-21 00:43:17.322   329   329 D ApplicationLoaders: Created zygote-cached class loader: /system/framework/android.hidl.manager-V1.0-java.jar
10-21 00:43:31.920  2250  2250 D ApplicationLoaders: Returning zygote-cached class loader: /system/framework/android.hidl.manager-V1.0-java.jar
10-21 00:43:38.884  2847  2847 D ApplicationLoaders: Returning zygote-cached class loader: /system/framework/android.hidl.manager-V1.0-java.jar
10-21 00:43:41.010  2923  2923 D ApplicationLoaders: Returning zygote-cached class loader: /system/framework/android.hidl.manager-V1.0-java.jar
10-21 00:43:42.146  3044  3044 D ApplicationLoaders: Returning zygote-cached class loader: /system/framework/android.hidl.manager-V1.0-java.jar

Change-Id: I024a1b16570bdceb7bef5b2e718c65155c675b4a
2020-10-21 00:52:13 +00:00
TreeHugger Robot
dfd56946f8 Merge "Guard IResourceObserver::registerObserver with permission" 2020-09-30 18:43:45 +00:00
Chong Zhang
95ad2ceac8 Guard IResourceObserver::registerObserver with permission
bug: 154733526
bug: 168307955
test: mediatranscodingservice unit testing.
Change-Id: Ie210f704eb0982fcc50b8e7de7e84a7b96280e81
2020-09-25 23:56:38 +00:00
Evan Severson
4f30e0baeb Split camera and microphone for background modes
Test: adb shell dumpsys package [package targeting < 31]>
Bug: 158311343
Change-Id: Ia5d0c40551163772e7cc10fdaf067360c6885f5b
2020-09-23 14:06:05 -07:00
Ulyana Trafimovich
4719733d49 Merge "Drop dependency of android.test.mock -> android.test.base." am: f08e8871d4 am: 72003fb685 am: 10e02f55c0 am: 2dc7803823 am: 51f2298687
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1434135

Change-Id: I3a9f55e09d4dd452445bee3b834f23ce2e98fbbd
2020-09-23 17:08:34 +00:00
Ulya Trafimovich
c578ab0ada Drop dependency of android.test.mock -> android.test.base.
There should be no such dependency.

Test: lunch aosp_cf_x86_phone-userdebug && m
Bug: 169137403
Bug: 132357300
Change-Id: Iaa7414be66581c01c6acbf367dc165cd8af78615
2020-09-23 11:08:01 +01:00
Philip P. Moltmann
aba996799d Revert "Give all non-package services the power to interact accr..."
Revert "Add dedicated host side tests for permissions and appops"

Revert submission 12439864-PermAppOpsCrossUserCheck-Fixed

Reason for revert: Bug 169044600
Reverted Changes:
I95d015e01:Invalidate package/permission cache if cross-profi...
I2a8a84f57:Check cross-user interactions for permissions and ...
Ie8f0db231:Give all non-package services the power to interac...
I11af434a8:Test package/permission cache invalidation when IN...
Ib6d609a4d:Add dedicated host side tests for permissions and ...

Change-Id: I47d371832c119fe4ce4890e10c1ac87aba92acbc
2020-09-21 22:26:51 +00:00
Philip P. Moltmann
5f9b30a11a Give all non-package services the power to interact accross users
Test: ManagedProfileTest#testCameraPolicy
Bug: 153996875
Change-Id: Ie8f0db231a29abc8f478cd519fc661c8fccaa1b7
2020-09-11 19:21:47 -07:00
Adam Bookatz
dc33904acb Remove references to system-user-whitelisted-app
The two SysConfig xml tags
system-user-whitelisted-app
system-user-blacklisted-app
are deprecated and were never used.

Bug: 139547572
Bug: 137101239
Test: compiles
Change-Id: I0a5a8cb9b178a3742ddc1fe70b9ee1e2737abdba
2020-07-21 23:35:04 +00:00
Chen Xu
1d4939fff2 support cellbroadcast data migration by dafault
As part of mainline effort, cellbroadcastreceiver package name has been
renamed. Now its a completely new apk with different uid. That said all
user data e.g, cellbroadcast history and user preference from legacy app
com.android.cellbroadcastreceiver are gone. This change is to support
preserve user data when devices upgrate to R and take cellbraodcast.
mainline module.
1. create legacy cellbroadcast app with old pakcage name
com.android.cellbroadcastreceiver. this app only surface the old data
and should not contains any activities/services to handle emergecy apert
2. legacy cellbroadcast app will be included to the system image by
default. OEMs are free to remove it if they don't care data loss or
after R data migration is done. leagcy app will not be part of
com.android.cellbroadcast apex.
3. the real mainline module rename to com.android.cellbroadcast.module

Bug: 155844209

Change-Id: I5e61c7e777526e038cd8d9971a2c5b87c00eaacb
Merged-in: I5e61c7e777526e038cd8d9971a2c5b87c00eaacb
2020-05-27 20:25:10 +00:00
Chen Xu
bb4b28e805 support cellbroadcast data migration by dafault
As part of mainline effort, cellbroadcastreceiver package name has been
renamed. Now its a completely new apk with different uid. That said all
user data e.g, cellbroadcast history and user preference from legacy app
com.android.cellbroadcastreceiver are gone. This change is to support
preserve user data when devices upgrate to R and take cellbraodcast.
mainline module.
1. create legacy cellbroadcast app with old pakcage name
com.android.cellbroadcastreceiver. this app only surface the old data
and should not contains any activities/services to handle emergecy apert
2. legacy cellbroadcast app will be included to the system image by
default. OEMs are free to remove it if they don't care data loss or
after R data migration is done. leagcy app will not be part of
com.android.cellbroadcast apex.
3. the real mainline module rename to com.android.cellbroadcast.module

Bug: 155844209

Change-Id: I5e61c7e777526e038cd8d9971a2c5b87c00eaacb
2020-05-23 21:26:30 -07:00
Hall Liu
594a7cb577 Merge "Convert Telephony broadcasts to be non-sticky" into rvc-dev am: ee1249911a am: 276f44d2ba am: 558b7f1af4 am: e6fa6c55b0
Change-Id: Ic5183c50e7932e9d3f4c985de8783aa4579854f3
2020-05-10 06:02:57 +00:00
Hall Liu
45066127b3 Convert Telephony broadcasts to be non-sticky
Convert ACTION_SERVICE_STATE_CHANGED and
ACTION_ANY_DATA_CONNECTION_CHANGED to be non-sticky broadcasts that
require the READ_PHONE_STATE permission to receive. As part of this,
declare READ_PHONE_STATE to be split from READ_PRIVILEGED_PHONE_STATE,
so that system apps holding READ_PRIVILEGED_PHONE_STATE can also receive
these broadcasts.

Also modify affected users to fetch the current value of the broadcast
upon registration instead of relying on the sticky nature of the
broadcast.

Bug: 150155839
Test: manual
Test: atest KeyguardUpdateMonitorTest
Change-Id: I020b1554c4fc59c138d015e787526b4a66c74853
2020-05-06 18:11:50 -07:00
Chong Zhang
9248b26375 Grant PACKAGE_USAGE_STATS permission to media uid
Allow media service to register UidObserver to get uid
state changes. Media transcoding uses uid states for
transcoding job scheduling purposes.

bug: 154734285
bug: 145233472

Change-Id: I20c7b33798ff5ede6620cccf65143da5ad77cba5
2020-04-29 10:55:37 -07:00
Ytai Ben-Tsvi
152e25b804 Remove obsolete permission
Bug: 146157104
Merged-In: I95aafe0e41977ca2656163fce9796abc6127c202
Change-Id: Ia528e3017d25625931a84249872f699659ae6b9a
2020-04-01 10:00:25 -07:00
Ytai Ben-Tsvi
25ca2f5327 Remove obsolete permission
Bug: 146157104
Change-Id: I95aafe0e41977ca2656163fce9796abc6127c202
2020-03-31 15:00:28 -07:00
Tej Singh
10458eca11 Enforce permission on native puller API
Test: m
Test: no security exceptions on boot
Test: atest LibStatsPullTests
Bug: 148955001
Change-Id: I4b06bfc41be2925270eaddd717f1499d98739dae
2020-03-19 11:54:11 -07:00
Automerger Merge Worker
3a8f7de209 Merge "Associate MAINLINE_NETWORK_STACK with net_raw and net_admin gid" am: ee6679031e am: 9ebb8455fa am: 246a2e1f72
Change-Id: I4a71ae683ff443e1f7867b3f83d4de80aa5cc785
2020-02-06 03:48:55 +00:00
Hungming Chen
14858acba5 Associate MAINLINE_NETWORK_STACK with net_raw and net_admin gid
Provide network stack the permission to access eBPF maps for tethering
offload

Test: m
Test: cat /proc/<pid>/status of network_stack has net_raw (3004) and
      net_admin (3005)

$ adb shell cat /proc/<pid>/status | egrep "Name|Uid|Gid|Groups"
Name:   rkstack.process
Uid:    1073    1073    1073    1073
Gid:    1073    1073    1073    1073
Groups:	1073 3001 3002 3003 3004 3005 3006 3007 9997

Change-Id: Ib3f6094e4c846832e44497466e3fed7dcd125593
2020-02-05 11:55:30 +00:00
Zim
7a5050b95a Associate MANAGE_EXTERNAL_STORAGE with external_storage gid
Test: m
Bug: 144914977
Change-Id: I3966701af00e07842a474e7e7fceb7db0fe62273
2020-01-27 16:03:39 +00:00
Zim
7da9f80d6a Deprecate WRITE_MEDIA_STORAGE permission
Previously, this permission would give the holder the media_rw gid
thereby granting access to the following file paths on disk:
1. /data/media
2. /mnt/media_rw
3. /mnt/expand/<uuid>/data/media

With the introduction of a stacked FUSE filesystem on external
storage, modifying any files directly on the lower filesystem (the
paths listed above) could lead to VFS cache inconsistencies and file
corruption.

To mitigate this risk, this cl blocks unneeded access to the lower
filesystem. Apps relying on this permission should instead use
android.permission.MANAGE_EXTERNAL_STORAGE.

Test: cat /proc/<pid>/status of mediaprovider doesn't have media_rw
Bug: 144914977

Change-Id: I8335d18067231657ac9793f7b1dcf6adb617ecfc
2020-01-22 19:29:29 +00:00
Ruchir Rastogi
5ea3163325 Migrate DeviceCalculcatedPower pullers to new API
As part of migrating the pullers to the new API, we modify
permission checks within BatteryStatsService. Previously, a Binder
thread within StatsCompanionService (with statsd's calling identity)
called BatteryStatsService functions, which was why statsd was assigned
the BATTERY_STATS permission. Now, that call is being made from the
system process Background thread. Because enforceCallingPermission
outside of Binder threads, we switched to enforceCallingOrSelfPermission.

Test: m -j
Test: adb shell cmd stats pull-source 10039
Test: adb shell cmd stats pull-source 10040
Test: adb shell cmd stats pull-source 10041
Test: atest CtsStatsdHostTestCases:UidAtomTests#testDeviceCalculatedPowerUse
Test: atest
CtsStatsdHostTestCases:UidAtomTests#testDeviceCalculatedPowerBlameUid
Test: atest CtsStatsdHostTestCases:BatteryStatsValidationTests#testPowerUse
Bug: 145565211
Change-Id: Ie009e6eead3e48ecee6b40d9a38c9d571d4d4117
2020-01-15 15:39:56 -08:00
Ytai Ben-Tsvi
0b0441d16c Add a permission for preempting sound trigger sessions
Previously, the power to preempt sound trigger recognition sessions
for the sake of being able to capture audio on platforms that don't
support doing both concurrently, was implicitly granted based on
process (audio_server) co-location with the sound trigger service.
Since this service is now being migrated out of audio_server, a new
permission is introduced and granted to the audio server.

Change-Id: Ifcdfc2a5543d814fb0630a45cdd9bcdba4d92107
Bug: 142070343
2019-12-13 10:45:42 -08:00
Joe Onorato
8e566f33ee Add new permission that lets incidentd call dropbox
Bug: 139375147
Test: treehugger
Change-Id: I4eaf167ff9157d9168358ed050e7f8b8ce136097
2019-10-23 17:58:00 -07:00
Chen Xu
8dcf873d9a Merge "Revert "remove symbols from greylist"" 2019-09-26 03:45:27 +00:00
Chen Xu
6155eb9663 Revert "remove symbols from greylist"
This reverts commit 27c4e658b3.

Reason for revert: <potential performance regression. revert for now and looking for possible optimization from ART team>

Change-Id: I5bf728e4f6789d7e6398cf90f22fbf3a24d481c2
2019-09-23 18:51:02 -07:00
Philip P. Moltmann
89b044ffb8 Split access-media-storage from read-external-storage
And also pre-grant it to all apps that currently get any storage
permission pre-granted

cherry-pick for qt-qpr1-dev Ib9f50d25c002036f13cf2d42fc4d1b214f20920c

Test: - straight cherry-pick
      - atest SplitPermissionTest
Bug: 141048840,140961754
Change-Id: Ia2219639a2104965a382ffef647e5ebaa0f9d540
2019-09-20 10:31:19 -07:00
Philip P. Moltmann
ac7b10c135 [DO NOT MERGE] Split access-media-storage from read-external-storage
And also pre-grant it to all apps that currently get any storage
permission pre-granted

Test: atest SplitPermissionTest
      m -j gts && gts-tradefed run commandAndExit gts-dev -m GtsPermissionTestCases --test=com.google.android.permission.gts.DefaultPermissionGrantPolicyTest#testDefaultGrantsWithRemoteExceptions
      Manual testing:
         All combinations of
           - App targetSdk = 28 and 29 (and 22 for extra credit)
           - App having the <uses-permission> tag for
             ACCESS_MEDIA_LOCATION or not
           - Upgrade from P->Q-QPR and from vanilla Q->Q-QPR
         Further upgrade of targetSdk from 28->29 while on Q-QPR
         ==> All permission behavior should make sense. Sometimes there
             are weird, but expected behaviors. Hence we need to
             collect the results and then look at the unexpected ones.
             See SplitPermissionTest for some tests I added for the
             location-background permission which was split from
             the fine/coarse-location permissions
Fixes: 141048840,140961754
Change-Id: Ib9f50d25c002036f13cf2d42fc4d1b214f20920c
2019-09-20 16:45:58 +00:00
Chen Xu
c1f208cd69 Merge "remove symbols from greylist" 2019-09-04 23:31:25 +00:00
Chen Xu
27c4e658b3 remove symbols from greylist
telephony-common is not intended to used by any apps and
being in boot class is not updatability friendly.
We are removing telephony-common from bootclass and apply
<uses-library> in manifest instead.
for apps targeting < R will auto load telephony-common lib
for app compatibility. For apos >=R, only allow usage for
phone UID.

Bug: 135955937
Test: Build
Change-Id: Ia318661546df6d8516328886e5cc0c54d5cfafe6
2019-09-04 11:42:14 -07:00