Commit Graph

2302 Commits

Author SHA1 Message Date
Les Lee
0d6266ee6c Merge "wifi: Fix the Security Report for pending intent" into sc-dev 2021-07-02 02:39:38 +00:00
Les Lee
90a78649f2 wifi: Fix the Security Report for pending intent
Bug: 170644642
Test: Manual Test, it work normally.
Change-Id: If24e7232f0740c8b43cedd56be7d54fcb3cba5a3
2021-06-30 23:56:05 +08:00
Songchun Fan
e25c0341fe [SettingsProvider] move getCallingPackage() outside of lock
getCallingPackage() now involves locking inside AppOpsService. Avoid
calling it inside SettingsProvider locks.

BUG: 192003928
Test: builds
Change-Id: I34fa3e382fe62bdf9497a6066d007963221fbe1a
2021-06-29 15:40:57 -07:00
Matt Pietal
745deffa8f Backup POWER_BUTTON_LONG_PRESS
Starting with Android 12, start backing up this setting to restore the
user's pref across devices. For users upgrading to a 2021+ device,
they will get the new default (assistant on long-press). If this user
then restores to an older device, they will then get this new behavior
on that device as well, even though it isn't the device default.

Fixes: 189874533
Test: atest SettingsBackupTest
Change-Id: I4b9864045bf12f30da03e3715f5e368bdf48a198
2021-06-11 07:58:21 -04:00
Songchun Fan
8b54307ce6 [SettingsProvider] add maxTargetSdk in @Readable
New annotation field that allows Settings key owners to specify the
maximum target sdk level of the caller app allowed to read the
hidden settings key.

Test: atest android.appsecurity.cts.ReadableSettingsFieldsTest
BUG: 187314081
Change-Id: Ibb603df4c8bca75e3788258e69862595c22e5154
2021-05-27 15:00:41 -07:00
Beth Thibodeau
8beb8407ec Merge "Add recommendation setting and remove app settings" into sc-dev 2021-05-27 16:19:17 +00:00
Beth Thibodeau
18c36e88a8 Add recommendation setting and remove app settings
- Add a new setting to control whether smartspace recommendations are
enabled
- Remove setting to block individual apps from resumption

Bug: 187925818
Test: atest MediaDataManagerTest
Change-Id: If1d5f4c5a204e655a90dd2cca6687acdfcd12fec
2021-05-26 14:27:54 -04:00
Patrick Baumann
dff37ee6d2 Merge "Updates OWNERS files" into sc-dev 2021-05-24 18:30:19 +00:00
Patrick Baumann
43628ca24c Updates OWNERS files
Bug: 186864416
Test: Builds
Change-Id: I04dfc5c2c7143825334ebc62742e335b8c889492
2021-05-21 14:13:18 -07:00
Soonil Nagarkar
1ea818347e Update location bypass allowlist
Create a new DeviceConfig entry to replace the prior Settings entry on
which the location ignore settings allowlist is based. This allows us to
allowlist based on attribution tag, and eliminate holes for large
applications.

Test: manual + CTS + GTS
Bug: 187421886
Change-Id: I31e61db79b93e202bd8c66efae1bb5aaf0c88ff5
2021-05-21 09:25:47 -07:00
Matt Pietal
abc6e0c51b Controls - Use new privacy setting
Wallet/controls privacy setting has been moved and split into
two. Migrate the old setting if the user had previously used
controls. From the QS tile, launch the activity differently when on
the lock screen.

Fixes: 188175341
Test: atest DeviceControlsTileTest
Change-Id: If38ae1c3f0bcc8e0e75146dda09276c13a0604e9
2021-05-18 10:14:32 -04:00
Neil Fuller
9f47ce098b Merge "Add device_config cmds for disabling syncs" into sc-dev 2021-05-17 16:17:12 +00:00
Neil Fuller
ad3d45a642 Add device_config cmds for disabling syncs
This adds a "sync disabled" mode which disables bulk updates to
device_config (AKA server flags). This is intended for use during
automated and manual tests that use device_config settings to set the
device into specific states for tests. Without this, devices can sync at
an arbitrary point during a test which can undo device_config changes
the tests have made and cause them to fail / flake.

This mechanism is independent of the mechanism used to sync, thereby
making it suitable for use in CTS or other AOSP tests, i.e. to disable
sync regardless of whether GMS core or an alternative is handling the
sync.

Test: atest core/tests/coretests/src/android/provider/DeviceConfigTest.java
Bug: 185786624
Change-Id: Icd0ce798642eb136dc8b9b1a58a4ecbc6212fdba
2021-05-14 11:26:13 +01:00
Chris Li
da4381222a Merge "Determine whether to support activities in multi window (7/n)" into sc-dev 2021-05-14 06:10:40 +00:00
PETER LIANG
74a435858a Merge changes from topic "a11y_floating_menu_migration_tooltip" into sc-dev
* changes:
  Add the new migration tooltip for accessibility floating menu.(2/n)
  Add the new migration tooltip for accessibility floating menu.(1/n)
  Add key ACCESSIBILITY_FLOATING_MENU_MIGRATION_TOOLTIP_PROMPT.
2021-05-12 02:59:10 +00:00
Chen Xu
9c4f884ed0 Merge "missing permission check to access multi_sim_data_call settings" into sc-dev 2021-05-11 15:56:20 +00:00
Chris Li
8550c3dd47 Determine whether to support activities in multi window (7/n)
Remove the default true development option.

Device should now use the default behavior from
config_supportsNonResizableMultiWindow.

Bug: 176061101
Test: manual
Change-Id: I5a3c31fc9100a3b6031244b5d6fb66b3c9597da6
2021-05-11 04:21:21 +00:00
Peter_Liang
610c0142d3 Add the new migration tooltip for accessibility floating menu.(1/n)
Goal:
If users have been using the accessibility button in android R, after the device is upgraded from android R to S, the system will pop up the tooltip at the first boot to show the information about the Accessibility button was replaced with the floating menu.

Patch Action:
1. Create the tooltip view
2. Create new secure settings  key for migration tooltip

Bug: 175365399
Test: atest AccessibilityFloatingMenuViewTest AccessibilityFloatingMenuTest AccessibilityFloatingMenuTooltipViewTest
Change-Id: I50b792efcbb631778a668e967fd727806a3f3df4
2021-05-11 08:12:18 +08:00
Chen Xu
38663c6a6c missing permission check to access multi_sim_data_call settings
this private settings can be accessed from alternative API
SubscriptionManager.getPreferredDataSubscriptionId which requires
READ_PRIVILEGED_PHONE_STATE permission. Add additional permission
check for settings access to avoid any potential security holes.
note: the alernative API from SubscriptionManager is also a hidden
one, without the public alertnative API we have to handle app-compat
properly to avoid breaking apks targeting previous SDKs.

Bug: 172670679
Test: Manual
Change-Id: If527f375da33cc6c30c6513c82bf529209da277a
2021-05-07 04:57:47 +00:00
Songchun Fan
7610e4b9e7 [SettingsProvider] better debug messages for invalid write arguments
Previously the debug messages were misleading. It showed "[PERSISTED]"
even if the write was skipped.

BUG: 185786624
Test: manual
Change-Id: Ibe8f23f3fa193a2a32f94f8abdd8db03bf9d513f
2021-05-06 11:52:19 -07:00
Peter_Liang
0c6aa86ea7 Add key ACCESSIBILITY_FLOATING_MENU_MIGRATION_TOOLTIP_PROMPT.
The key used to show the migration information related to
the accessibility floating menu.

Bug: 175365399
Test: atest SettingsProviderTest
Change-Id: Ifabc412b990c72ad345bab2d5d8539a57bd6ca5d
2021-05-05 19:24:30 +08:00
Bill Lin
9df0e2bdb3 Merge "1/ Add ONE_HANDED_MODE_ACTIVATED secure settings for shortcut" into sc-dev 2021-04-29 04:49:42 +00:00
Bill Lin
6b7167d88a 1/ Add ONE_HANDED_MODE_ACTIVATED secure settings for shortcut
A new requirement to add A11y shortcut for One Handed Mode feature

- The shortcut action is enter or exit one handed mode
- ONE_HANDED_MODE_ACTIVATED = 0 /* false */ : STATE_NONE
- ONE_HANDED_MODE_ACTIVATED = 1 /* true */  : STATE_ACTIVE

Compare to enabled or disabled (ONE_HANDED_MODE_ENABLED)
- ONE_HANDED_MODE_ENABLED = 0 /* false */ : Disable function
- ONE_HANDED_MODE_ENABLED = 1 /* true */  : Enabled function

Test: manual
Test: make
Bug: 182425480
Change-Id: Iee911631a6734af7eb742e1206d2b9b75b694969
2021-04-28 00:44:45 +00:00
Galia Peycheva
57ef720249 Merge "Use global setting instead of forceWindowBlurDisabled" into sc-dev 2021-04-26 11:42:49 +00:00
Galia Peycheva
85bb3e4da0 Use global setting instead of forceWindowBlurDisabled
This CL removes the existing TestApi
WindowManager#setForceCrossWindowBlurDisabled and replaces it
with Settings.Global#ENABLE_WINDOW_BLURS.

Bug: 14186649
Test: m && atest BlurTests
Change-Id: Ia15b7932ea973a9ed195c507558cdc71f194b366
2021-04-23 11:13:43 +02:00
Neil Fuller
e1aaa7f9d1 Merge "Update settings for Date / Time / Zone" into sc-dev 2021-04-22 09:31:08 +00:00
Neil Fuller
f41708d93d Merge "Remove Settings.System.DATE_FORMAT" into sc-dev 2021-04-21 20:09:40 +00:00
Neil Fuller
d571ec3fc7 Add location_time_zone_detection_enabled setting
Add location_time_zone_detection_enabled setting to backup list. This
setting was added in S.

Bug: 151304765
Bug: 185884644
Test: build / treehugger
Change-Id: I7ca034028fdf21451e12627ef0bbff6c8fb6c8be
2021-04-21 14:58:13 +01:00
Neil Fuller
8b8d4f8684 Remove Settings.System.DATE_FORMAT
Remove references to Settings.System.DATE_FORMAT and mark it as clearly
deprecated.

It was probably made obsolete some time before kitkat. There were still
some references in view code up to lollipop (removed in change
Ib77a8e7727d027cae39d5e6f431cac1d1ff8a121). During marshmallow / nougat
there were no references, then references were added in backup code in
oreo. This change is intended to make it more obvious that this setting
is obsolete.

Bug: 185884644
Test: build only
Change-Id: I12441541bc3ca0e012cee64d4c784a0ce8233715
2021-04-20 20:22:41 +01:00
Neil Fuller
dfa685c683 Update settings for Date / Time / Zone
Update SettingsProtoDumpUtil / secure.proto to reference the new (user
scoped) location_time_zone_detection_enabled setting that has been added
for S.  This has been added in a "DateTime" message to reflect the
SettingsUI structure.

For consistency with secure.proto and the settings strings, global.proto
and the associated SettingsProtoDumpUtil code has updated to rename the
"Auto.time" and "Auto.time_zone" proto fields to "DateTime.auto_time"
and "DateTime.auto_time_zone". This is a binary compatible change as
the field IDs have not been changed.

Note: The "time_12_24" and "date_format" settings, which are user-scoped
settings from "Settings.System" have been left for a future release
besides some minor docs improvements. See bug 185884644.

This change also improve the docs for settings that are associated with
date and time.

Bug: 151304765
Bug: 185884644
Test: build / treehugger
Change-Id: If2daf3f530bd1add7a0a5cc3260221ea3ad8952d
2021-04-20 18:46:56 +01:00
Mady Mellor
b5a783d611 Move bubble setting to secure table & support multiuser
* Move bubbles setting from the global table to the secure
  table, this should be a per-user setting
* Update step in SettingsProvider that adds the secure
  setting based on the value of the previous global, or if
  the user is managed, it checks if the owner of the managed
  user has a secure setting & uses the value from that to
  insert the new setting.
* Adds the secure setting to the "cloned to profile"
  group since it should follow the setting of the profile
  owner.
* PreferencesHelper tracks this value per-user.

Bug: 173408780
Test: atest PreferencesHelperTest NotificationManagerServiceTest BubbleExtractorTest
Change-Id: I261364890fcc54fb2791e628b41c07aeddde3974
2021-04-19 18:51:01 -07:00
Bill Yi
1a578ba040 Import translations. DO NOT MERGE ANYWHERE
Auto-generated-cl: translation import
Change-Id: Ie26ee18f818e24dcf9e9448683e72fd2996e304f
2021-04-17 21:07:45 -07:00
Songchun Fan
82ded9e0cb Merge "Revert "Revert "[SettingsProvider] remove in-lock calls to PackageManager.getPackageUid()""" into sc-dev 2021-04-13 21:21:31 +00:00
John Li
235c16235a Merge "Add @SystemApi for Secure.UI_TRANSLATION_ENABLED" into sc-dev 2021-04-13 15:55:15 +00:00
Daniel Sandler
f34519a523 Merge "Power + Volume up key chord can now be configured." into sc-dev 2021-04-13 04:56:27 +00:00
John Li
221de3457b Add @SystemApi for Secure.UI_TRANSLATION_ENABLED
Bug: 177299699
Test: manual
Change-Id: I711d078281ae9cc17ebb21e6c3f857caad31016a
2021-04-13 02:57:45 +00:00
Songchun Fan
6443454d68 Revert "Revert "[SettingsProvider] remove in-lock calls to PackageManager.getPackageUid()""
This reverts commit 7a659fca89.

Reason for revert: Fixing ag/14096109 to clear callingUid before retrieving applicationInfo

BUG: 183007597
Test: atest android.appsecurity.cts.ExternalStorageHostTest#testExternalStorageReadDefaultUris
Change-Id: I6b1e7f156e8e62e6d463a5986a0ef90bf2ef61ff
2021-04-12 22:50:27 +00:00
Songchun Fan
c05712b927 Merge "Revert "[SettingsProvider] remove in-lock calls to PackageManager.getPackageUid()"" into sc-dev 2021-04-12 18:18:27 +00:00
Songchun Fan
7a659fca89 Revert "[SettingsProvider] remove in-lock calls to PackageManager.getPackageUid()"
This reverts commit 25728b15e4.

Reason for revert: b/185085629

Change-Id: I2af49e3cb79af5bd80a0f69a2c09be5bbb45aeee
2021-04-12 16:39:20 +00:00
Dan Sandler
069278cdb7 Power + Volume up key chord can now be configured.
Device default value set in config_keyChordPowerVolumeUp in
config.xml; can be overridden for all users with
Settings.Global.KEY_CHORD_POWER_VOLUME_UP.

Value may be one of:

    0 - no-op
    1 - vibrate mode (current AOSP default behavior)
    2 - launch assistant

Bug: 179673796
Test: adb shell settings put global key_chord_volume_up <0, 1, or 2>
      adb shell dumpsys window | grep mPowerVolUpBehavior
      adb shell input keycombination POWER VOLUME_UP
Change-Id: I0e03155bdbe61d9fdd6838fe2c860749cf360907
2021-04-12 12:05:52 -04:00
Songchun Fan
88b6eb6af8 Merge "[SettingsProvider] remove in-lock calls to PackageManager.getPackageUid()" into sc-dev 2021-04-09 22:11:53 +00:00
Songchun Fan
25728b15e4 [SettingsProvider] remove in-lock calls to PackageManager.getPackageUid()
Cache a list of package names of system packages, so we don't have to
check with package manager everytime if a package is system package or
not. This removes the deadlock between SettingsProvider and
PackageManagerService caused by getPackageUid().

BUG: 183007597
Test: run "atest NeneTest" and see there is no deadlock caused by
SettingsProvider

Change-Id: Ia98d47f12d218a7b98ef9003b786ba60e9212e20
2021-04-09 13:21:32 -07:00
Songchun Fan
3a4059f759 [SettingsProvider] allow test_only apps access @hide keys w/o @Readable
+ Also improve error message

BUG: 183436286
BUG: 183709745
Test: atest android.appsecurity.cts.ReadableSettingsFieldsTest
Change-Id: I17224d213d707f6f359aa17f1b745bf508208de8
2021-04-09 19:03:51 +00:00
Matt Casey
4dddebe4b8 Merge "Revert "Revert "Add setting for touch gesture and long-press hom..."" into sc-dev 2021-03-30 14:23:10 +00:00
Svet Ganov
8d2ed50604 Runtime permission attribution improvements
When an app is proxying access to runtime permission protected
data it needs to check whether the calling app has a permission
to the data it is about to proxy which leaves a trace in app ops
that the requesting app perofmed a data access. However, then the
app doing the work needs to get the protected data itself from the
OS which access gets attributed only to itself. As a result there
are two data accesses in app ops where only the first one is a
proxy one that app A got access to Foo through app B - that is the
one we want to show in the permission tracking UIs - and one
for the data access - that is the one we would want to blame on
the calling app, and in fact, these two accesses should be one -
that app A accessed Foo though B. This limitation requires fragile
one off workarounds where both accesses use the same attribution
tag and sys UI has hardcoded rules to dedupe. Since this is not
documented we cannot expect that the ecosystem would reliably
do this workaround in apps that that the workaround in the OS
would be respected by every OEM.

This change adds a mechaism to resolve this issue. It allows for
an app to create an attribution context for another app and then
any private data access thorugh this context would result in a
single app op blame that A accessed Foo though B, i.e. we no longer
have double accounting. Also this can be nested through apps, e.g.
app A asks app B which asks app C for contacts. In this case app
B creates an attribution context for app A and calls into app C
which creates an attribution context for app B. When app C gets
contacts the entire attribution chain would get a porper, single
blame: that C accessed the data, that B got the data from C, and
that A got the data form B. Furthermore, this mechanism ensures
that apps cannot forget to check permissions for the caller
before proxying private data. In our example B and C don't need
to check the permisisons for A and B, respectively, since the
permisisons for the entire attribution chain are checked before
data delivery. Attribution chains are not forgeable preventing
a bad actor to create an arbitrary one - each attribution is
created by the app it refers to and points to a chain of
attributions created by their corresponding apps.

This change also fixes a bug where all content provider accesses
were double counted in app ops due to double noting. While at
this it also fixes that apps can now access their own last ops.
There was a bug where one could not pass null getting the attributed
ops from a historical package ops while this is a valid use case
since if there is no attribution everything is mapped to the null
tag. There were some app op APIs not being piped thorough the app
ops delegate and by extension through the app ops policy. Also
now that we have nice way to express the permission chain in a
call we no longer need the special casing in activity manager to
handle content provider accesses through the OS. Fixed a bug
where we don't properly handle the android.os.shell calls with
an invlaid tag which was failing while the shell can do any tag.

Finally, to ensure the mechanims is validated and works end-to-end
we are adding support for a voice recognizer to blame the client
app for the mic access. The recognition service can create a blaming
context when opening the mic and if the mic is open, which would
do all permission checks, we would not do so again. Since changes
to PermissionChercker for handling attribution sources were made
the CL also hooks up renounced permissoins in the request permission
flow and in the permission checks.

bug:158792096
bug:180647319

Test:atest CtsPermissionsTestCases
     atest CtsPermissions2TestCases
     atest CtsPermissions3TestCases
     atest CtsPermissions4TestCases
     atest CtsPermissions5TestCases
     atest CtsAppOpsTestCases
     atest CtsAppOps2TestCases

Change-Id: Ib04585515d3dc3956966005ae9d94955b2f3ee08
2021-03-29 16:49:33 +00:00
Matt Casey
38ced457e0 Revert "Revert "Add setting for touch gesture and long-press hom..."
Revert "Revert "Hide long-press home animation when disabled by ..."

Revert submission 13998375-revert-13958909-mrcasey-lph-GNUFFHLQXH

Reason for revert: Reverting these CLs did not fix the test b/183684181
Reverted Changes:
Iac13fc450:Revert "Hide long-press home animation when disabl...
Ieb43607a8:Revert "Add setting for touch gesture and long-pre...

Change-Id: Ia92b0a1f19dc7423fe1b3796e14582169e58d203
2021-03-29 13:42:09 +00:00
Kriti Dang
e713ee6c60 Merge changes from topic "cherrypick-Display settings HDR formats-mumvl547ah" into sc-dev
* changes:
  Handling Number Format Exception in DiscreteValueIntegerListValidator
  Hdr format settings [Backend]
2021-03-28 12:25:32 +00:00
Matt Casey
304bd59b3e Merge "Revert "Add setting for touch gesture and long-press home assist..."" into sc-dev 2021-03-25 21:28:34 +00:00
Matt Casey
fabc9f6f27 Revert "Add setting for touch gesture and long-press home assist..."
Revert "Hide long-press home animation when disabled by setting"

Revert submission 13958909-mrcasey-lph

Reason for revert: Possible test breakage b/183684181
Reverted Changes:
Iaaf39e76a:Hide long-press home animation when disabled by se...
I24ee67cf1:Add setting for touch gesture and long-press home ...

Change-Id: Ieb43607a8010b843fc643979953a266cbb84788f
2021-03-25 21:19:00 +00:00
Kriti Dang
72de55e19c Handling Number Format Exception in DiscreteValueIntegerListValidator
Bug: 183690593
Test: Tested via forrest
Change-Id: I0a99675bf316c1e8ccd3408ec3239dd04159916c
Merged-In: I0a99675bf316c1e8ccd3408ec3239dd04159916c
2021-03-25 18:58:37 +00:00