Add a test to ensure that system could boot without exception after
a package is uninstalled with keeping data.
Bug: 188635265
Test: atest PackageManagerServiceHostTests
Change-Id: I190db789ecd8c0ca1ddd87fc1c6ef79593b35492
A previous fix was introduced to re-enable compressed packages if any
user on the device had the package installed + enabled, but this
introduced a regression if there was only 1 user on device.
It treated an uninstall updates command as if it was disabling for
the primary user, whereas those should actually be handled
independently, allowing an app to remain installed and enabled even
after uninstalling updates.
This was caught in the initial change, but ignored as an unimportant
quirk of the uninstall updates system. This was in error and thus the
tests for this feature were also broken and needed to be fixed to match
the preserving behavior.
This tacks onto a previous change that records the user state for a
package before deletePackageX actually runs, and resets the state
objects afterwards. This informs whether any user has the package
installed + enabled to re-uncompress the stub to /data.
Bug: 191988668
Test: atest SystemStubMultiUserDisableUninstallTest
Change-Id: I670163e01d13ee5fdd2ebc6a046fa55a5398b290
Merged-In: I670163e01d13ee5fdd2ebc6a046fa55a5398b290
A security fix to enforce package visibility filter to the
api IPackageManager#querySyncProviders.
Bug: 188802680
Test: atest AppEnumerationInternalTests
Change-Id: Idca4b1bf739b6113ac3922af63ebc9d15fd5fe69
Previously, async writes were posted to a Handler but not throttled,
so it was possible to do redundant writes when the latest state had
already been saved.
To avoid that, a counter is stored that serves as a request ID that
can be checked against to see if the latest state has already been
saved, skipping the write request if it has.
This is preferred to calling Handler#hasCallbacks or
Handler#removeCallbacks because those will lock the Handler. And taking
the lock twice is perhaps worse than locking once to schedule a no-op
Runnable, although this was not benchmarked.
This also introduces a retry mechanism in case the write fails.
Bug: 168086110
Test: atest PackageSessionTests
Test: atest RequestThrottleTest
Change-Id: I604dc433c77cf1d9d743c8437674576ad087d62c
If a package is ever updated as part of an OTA, it have may removed
domains that were included in the original set, and so that state
should be evicted when it's re-attached.
Bug: 184562304
Test: atest DomainVerificationPackageTest
Change-Id: Ie90dc390afa89b0c26f73de64b1e513c6fa272a3
For consumers who don't care about blocking package data updates and
only need data at a specific snapshot in time, these methods would
avoid locking PMS during the iteration process.
Bug: 183643808
Test: atest com.android.server.pm.test.verify.domain
Change-Id: Ia951381798d75f77c4ad5fc010a469b69992f074
This was preventing the domain verifier from being printed as part of
dumpsys, since PMS checks this to see if the proxy exists.
To avoid future issues, also removs the default interface methods in
favor of just overriding them in the unavailable variant.
Bug: 186665132
Test: manual, dumpsys package dv
Test: atest DomainVerificationProxyTest#nonNullComponentName
Change-Id: Ib8fb5e07b1650a46a9ebb735f9c640877e58cb22
Only apps that are preloaded on the system are allowed to be auto
approved. This prevents package name takeover for optional packages
that are still configured in the XML.
Bug: 166697328
Test: atest DomainVerificationPackageTest
Test: manual verify pm get-app-links on a device
Change-Id: Ic055db3c07ff876600402c3ed0fe66b30cebe09e
The collection logic for exposing HTTP domains only accepts those
that match Patterns#DOMAIN_NAME, roughly "domain.tld".
This updates the Intent resolution logic to match so that link approval
is not required if the URI host doesn't match that pattern.
Bug: 184963244
Test: atest DomainVerificationValidIntentTest
Test: atest CtsDomainVerificationDeviceTestCases
Change-Id: Ieb4ca01089785246b61d6b1710d76bffceefcbf7
Change get -> valueAt and get the actual base.apk ApkAssets for the
package. Also fixes overlay reference visibilty, which was broken with
the AppsFilter cache.
Bug: 184834206
Test: atest OverlayReferenceMapperTests
Test: atest OverlayActorVisibilityTest
Test: atest AppsFilterTest
Change-Id: I01e6a39b36a0e03c2cb9d48e705fe02c1a63c169
Forgot the docs update part of the feedback. Also enforces the param
non-nullablility.
Bug: 184891031
Test: atest DomainVerificationManagerApiTest
Change-Id: I4c90f69bc38c9760a76555ee8c8ad121cac997b6
Hooks up PreferredActivityBackupHelper to the domain verification XML,
replacing the old intent filter verification backup.
Also fixes a leftover bug where linkHandlingAllowed state was not
being deserialized properly.
Bug: 170746586
Bug: 182206123
Test: atest DomainVerificationPackageTest
Test: atest DomainVerificationPersistenceTest
Change-Id: I418c62866da4f82bf387a3b95d0139c2236ea62c
Kept the lowest to highest ordering priority, under the assumption
that less has to change in the UI/consumer if the highest priority
is popped, since it will just take it off the end without shifting
any elements. The ordering is documented.
Bug: 184891031
Test: atest DomainVerificationManagerApiTest
Change-Id: I6ea5908e356ee96aa440650f3d5025319c195266
* changes:
Fix domain verify restore and add signature check
Support serializing package signatures for domain verification state
Add domain verification CTS to TEST_MAPPING
Fix DomainVerificationService deadlock
Check installed and enabled state for package domain approval
Revoke domain user selection when approved through shell
With domain verification changes and UX changes for app links v2,
none of these tests are valid anymore.
Bug: 184476155
Test: none, still need to fix SdCardEjectionTests
Change-Id: I4b6c00406631b39d222bb34d89aa708eaf1ac889
Verifies that all signatures of the package being restored matches by
SHA256 hash. And fixes a bug where the restored packages weren't being
added to the internal structures.
Bug: 170746586
Test: atest DomainVerificationPackageTest
Change-Id: I2cf2e739a88396475599bc4c1ff27c36e09a8d45
To prepare for backup/restore changes which need to verify that the
package signatures match.
Bug: 182207215
Test: atest DomainVerificationPersistenceTest
Change-Id: I9e4bd24256604b649acf2c925cce2ac65331fa2c
Enforces the PackageManagerService lock to be taken before the DVS lock,
when neccessary, so that the locking is always one-way and cannot
deadlock when Settings attempts to serialize state.
Bug: 183643808
Test: manual run CTS which previously reproduced this issue
Change-Id: Ibccde458df16238755f3a67080321cb3ebdf7233
If the package isn't installed or isn't enabled for a user, it cannot
be approved for that user.
Also hooks into package uninstall for a single user to remove the
domain state for that package for that user.
Bug: 183226822
Test: atest DomainVerificationManagerApiTest#getOwnersForDomain
Test: atest com.android.server.pm.test.verify.domain
Change-Id: I04942e1491d470fdd41e99f207bbf85baae87d4c
Settings shouldn't need this information as it's all provided as part
of the user state object.
Bug: 183537875
Test: DomainVerificationEnforcerTest
Change-Id: Ib84b92d1d43c098ea2c2a89471c0cd1deacc9661
Uses the isChangeEnabledInternalNoLogging variant, which skips the
caller permission check, which improves performance. Also removes
the need to clear calling identity.
This uses a mocked ApplicationInfo as it can be called during package
update, which means the PM lock cannot be taken. This, and in all other
cases, the method is being called as part of a service side check, post
feature/permission app visibility enforcement, so it should be safe to
skip permission checks.
This isn't enforced, but since DomainVerificationUtils#isChangeEnabled
is only visible inside the DVS package, it should be fine.
Bug: 159952358
Test: atest com.android.server.pm.verify.domain
Change-Id: I9c54e8653d843cfb67fb9d6e12349cf06de90fce
Validates the calling/target user IDs still exist, to handle race
conditions.
Since the data structures are not locked during the user check, also
adds a call during user creation to wipe the user data if there's any
stale values left. This should never practically happen, but it's a
fairly fast call just to make sure.
Bug: 182416431
Test: atest com.android.server.pm.test.verify.domain
Change-Id: I6cc270fb0e85f0c920b3b71a52e059e818066fac
Removes the InvalidDomainSetException and exposes the reasons as API
error codes. Implementers can check for a non-0 error code to tell if
the failure is meant to indicate a cancelled request.
Bug: 180991102
Test: atest com.android.server.pm.test.verify.domain
Test: atest DomainVerificationManagerApiTest
Change-Id: I19b88fb582fc7f633497d036a0590350ec463f3e
Hides the internal values and exposes a smaller set of defined values
for each specific case the domain verification agent might be
interested in.
These values are only for the public API output and all other classes
should continue to use the internal DomainVerificationState.
Bug: 181100856
Test: atest com.android.server.pm.test.verify.domain
Change-Id: I2b16d14bbf3a70e4c2e3f4b358af8671aed71490
Allows shell configured values to persist across package updates and
validates the behavior with new unit tests.
Also fixes a bug with failing to recalculate hasAutoVerifyDomains
during an update.
Bug: 180535047
Test: atest DomainVerificationPackageTest
Change-Id: I793171491c8373ad67a38b5a02a57f46e4d5828a
Removes the endDocument call so the serializer can be used as a child
of a larger group. Instead calls flush and assumes all usages will
close tags appropriately.
This usage is incorrect regardless, but endDocument itself is broken
and does not behave the same depending on which XmlSerialier
implementation is being used. Which is why this bug never appeared
during testing/development.
Bug: 180838875
Bug: 181813200
Test: manual, debug linked Bug
Test: atest DomainVerificationPersistenceTest
Change-Id: I50e27817e526d2cbcc0efbcc3ffdfffa53886f0f
Better reflects the fact that the map no longer contains only the
selection state, but the domain state in general for the user.
Bug: 181637637
Test: none, naming refactor
Change-Id: I28bc73906f764d83c258fa10e23f2821e9482419
In anticipation of renaming the public API class, rename the internal
one to something that doesn't conflict, so that explicit imports or
aliases don't have to be used.
Bug: 181637637
Test: none, naming refactor
Change-Id: I2b2487265ba783a97697d1aff48568572e96ac3d
This is now visible to all apps to get the verified status of domains
which they declare. Because this is already restricted by app
visibility, opening up the API with no changes should be sufficient.
The permission requirement was also removed, since normals apps will
not have it.
This will only expose a relevant status when used with the changes at
Ib14049e397154616f84a2264167ac30659cd81c9.
Bug: 180955393
CTS-Coverage-Bug: 179382047
Change-Id: Ia7b7acffe41ac435f9bda98cd4e0ee422c8df328
Makes testing a little more difficult, but mirrors the other system
service classes.
Bug: 181101101
Test: atest com.android.server.pm.test.verify.domain
Change-Id: I39a3c2160943a0a6c77fe792446ed2f1407fb0e0
To make debugging v1 collection easier, print out the invalidly
configured domains, so that ideally a developer can remove them from
their HTTP intent-filter declarations.
Bug: 181050655
Test: manual, print out an app with invalid domains
Change-Id: Idc06d34301bde42e14f9c12449486ee8f3b6f918
Adjusts the logic for selecting a domain, removing the selection for
other applications once a domain is verified or overridden by another
application being selected.
To this end, exposes a new Domain class with verified/selected booleans
to encapsulate the state, returned in the initial response for the
Settings screen API. This avoids the usage of the
getDomainVerificationSet API, so that can be restricted to only the
domain verification agent in a future change.
Also introduces the concept of a DomainOwner, which represents a single
package who has been granted any positive level of approval to open
a domain.
Bug: 177923646
CTS-Coverage-Bug: 179382047
Test: atest com.android.server.pm.verify.domain
Test: TODO with Settings changes
Change-Id: Ib14049e397154616f84a2264167ac30659cd81c9
If the domains in each data class exceed 32 KB, serializes them using
writeBlob so that they get passed through shared memory rather than
the Binder transaction.
Bug: 177553185
Test: atest DomainVerificationCoreApiTest
Change-Id: I0dd4bd140c8b847eb604d8e42272ca5be5690731
This toggle is actually used to toggle whether or not the app can open
app links at all, not just verified app links.
Updates the persistence/data classes to be in line with the new default
behavior.
Also makes it so that unverified apps cannot be enabled if another
approved package already exists.
Bug: 178525735
Test: atest DomainVerificationPersistenceTest
Change-Id: I5e258e230e6d6b5de79aab32838496f2126f8451
Cleans up the permission logic and introduces app filtering.
This will require non-user targeted APIs that hit a package name
to hold QUERY_ALL_PACKAGES. This ensures the caller can see the packages
without needing to check instant app state by passing a userId.
Currently it's not clear how to handle instant app visibility, but it's
assumed that the verification agent and settings have visibility.
Bug: 171251883
Test: atest DomainVerificationEnforcerTest
Change-Id: I3ffe2cc0307c9efa97dfcf8474a620622e7cfcfe