ServiceConnector does not call unbindService when requested to unbind if
the service isn't currently connected. This causes issues like leaving
zombie Trusted Hotword processes bound forever if the process is stopped
('restarted') immediately after being created (say if audio server
crashes twice in quick succession).
Fix: 223845998
Test: manual - locally comment out code that immediately connects the
service, then `for i in {1..10}; do adb shell cmd voiceinteraction\
restart-detection; done` - without fix results in an extra process
Change-Id: I6a8c01390130bcec9aff1460004343ca2b207031
Merged-in: I6a8c01390130bcec9aff1460004343ca2b207031
(cherry picked from commit 52e0dafcb3)
IVold.ENCRYPTION_STATE_* and IVold.PASSWORD_TYPE_* are values returned
by or accepted by FDE-specific vold methods, which are no longer used.
Stop using these constants so that we can remove them from IVold.aidl.
Notes on specific constants:
- Some constants have @UnsupportedAppUsage. There is no reason why a
non-system app should have been using these. However, to avoid
possibly breaking apps I just left these with hardcoded values.
- StorageManager.CRYPT_TYPE_* are used by
LockscreenCredential.getStorageCryptType(). However, the caller of
this method was removed by an earlier CL, so just remove this method.
- StorageManager.CRYPT_TYPE_* also have a user in
packages/apps/Settings, but it is obsolete code that I'm removing in
another CL.
Bug: 208476087
Change-Id: I41c684b69a97dbafac65d8f55db2c284d7a8dd70
Bug: 207717787
Test: build & boot pass.
Test: manual. Both trust and no-trust still work.
Test: manual. In nornal case, log with expected values, see bug for
details. Log expected value for some error cases (not all are tested)
by local changes.
Android Metrics Design Review : eldar/276723226
Merged-in: Iaa778616eca4cfad83a94297d9cd6116bb9577e7
Change-Id: I98fde2467e09564569cdbf10b20e9defece65cbf
(cherry picked from commit e4b76fc200)
Now that FDE is no longer supported, checking the FDE password cache
will never accomplish anything. Remove this check from Keyguard, and
remove the supporting code from LockSettingsService.
Bug: 208476087
Change-Id: If1bb80dfcc015aeea19916a88c89a4067e6ada32
(cherry picked from commit e9b69111b2)
Merged-In: If1bb80dfcc015aeea19916a88c89a4067e6ada32
There is a "race condition" where a MessagingGroup is recycled while the
contents of that group are being used elsewhere in the
ConversationLayout, namely in the "image message container" used to show
the most recent image message in the collapsed state.
This state isn't cleared until later in the bind() process, which
unfortunately depends on the groups being updated. For that reason, we
defer all synchronous calls to recycle() until the end of bind(), which
will ensure that the old groups are still around as long as necessary.
Fixes: 216202070
Test: manual
Change-Id: Idef815d54690544615512bd2bd1006f172403e18
(cherry picked from commit 2a68270c76)
When switching users and attempting to lock the device, the sysui main
thread becomes overwhelmed with events, creating a significant lag
between the time a message is posted and processed on the main
thread. This can be dangerous when these events are critical for
security, such as calls coming from PhoneWindowManager#lockNow() that
call KeyguardViewMediator#doKeyguardTimeout(). On older devices with
slower CPUs and less memory, the delay in processing can be
significant (15 - 30s).
The result of not prioritizing these events leads to a window of time
where a guest user can switch back to the owner, and gain access to
the owner's homescreen without needing to unlock the device with the
owner's credentials.
As a mitigation, prioritize two events originating in two specific
methods to make sure the device locks as soon as possible as well as
have the system server preemptively update its local cache.
Bug: 151095871
Test: Very manual race condition - follow steps listed in bug
Change-Id: I7585a0a5eeb308e0e32a4f77f581556d883b5cda
Merged-In: I7585a0a5eeb308e0e32a4f77f581556d883b5cda
(cherry picked from commit 28c53ab8bc)
(cherry picked from commit f8023c9829)
Since FDE is no longer supported, updating the FDE password never does
anything. Stop trying to do so. Remove updateEncryptionPassword() from
ILockSettings, since its only caller outside of LockSettingsService
itself was in LockPatternUtils, and the previous CL removed that caller.
Bug: 208476087
Change-Id: I46c2a472177836f0c9084e4c3b4ed2e6c0ab61d5
(cherry picked from commit 3762ada110)
Merged-In: I46c2a472177836f0c9084e4c3b4ed2e6c0ab61d5
Remove this method which cleared the FDE password, since is no longer
used. It was only being used by the accessibility settings in the
Settings app, and that caller was removed by http://ag/16624515.
Bug: 208476087
Change-Id: If0c75774555d3503f21857e66cce527c5edfa586
(cherry picked from commit 8e265a9fd3)
Merged-In: If0c75774555d3503f21857e66cce527c5edfa586
Now that FDE is no longer supported, getting/setting FDE fields is
always a no-op, so there is no need to do so.
Bug: 208476087
Change-Id: Iab7ba8d36890daa0645b2cedf33e4bd177a86b63
(cherry picked from commit c6ce767e59)
Merged-In: Iab7ba8d36890daa0645b2cedf33e4bd177a86b63
Add a field in the VpnConfig to store local route exclusion
bit from VpnProfile, and set the value into the networkAgent
of VPN network.
Bug: 184750836
Test: atest FrameworksNetTests HostsideVpnTests
Change-Id: I22b9a5990a3dab0418b44ec19d2996ead6529231
* changes:
Ignore vendor apex priv-app permission allowlists
Add test for parsing apex allowlists
Ignore prebuilt shared library if it doesn't exist on device
Rename updatable-library to apex-library
Parse new xml attributes used for updatable shared libraries
Create XML parser only once.
We prefetch standalone system server jars in ZygoteInit based on the
STANDALONE_SYSTEMSERVER_JARS environment variable, so that they can take
the advantage of AOT compilation. This CL adds a check to disallow jars
that are not prefetched, which reminds developers to make appropriate
changes so that their jars will be in the environment variable.
Bug: 203198541
Test: 1. Build a system image.
2. The device boots.
Test: 1. Remove an entry from PRODUCT_APEX_STANDALONE_SYSTEM_SERVER_JARS
2. Build a system image.
3. The device does not boot and encounters the following error:
java.lang.RuntimeException: Creating a ClassLoader from /apex/com.android.wifi/javalib/service-wifi.jar is not allowed. Please make sure that the jar is listed in `PRODUCT_APEX_STANDALONE_SYSTEM_SERVER_JARS` in the Makefile and added as a `standalone_contents` of a `systemserverclasspath_fragment` in `Android.bp`.
Change-Id: I275d75ac37194a4d8fd491529b7cdb697dc04e37
Merged-In: I275d75ac37194a4d8fd491529b7cdb697dc04e37
(cherry picked from commit 418ab8212c)
Add safer Bundle APIs that take an extra Class<T> argument that checks
that the type about to be deserialized is a child of the type passed in
parameter *before* actually deserializing it, while also deprecating old
APIs.
This allows use to reap the benefits of the new typed Parcel APIs and
enhances security.
Only the APIs that could involve custom object injection are modified.
So, besides the obvious ones that have that design (eg.
readParcelableList()), subtler cases such as readIntegerArrayList()
could result in custom object deserialization, and since it's all
generics, even the casting inside Bundle wouldn't fail, only after the
client unpacked the list items would it blow up. Now those are checked
beforehand.
Since Bundle always calls Parcel.readValue() under the hood (instead of
specialized APIs such as readParcelable() etc), we had to augment that
method (that's used by LazyValue when retrieving the item) to accept
item types now for containers, which I implemented as a vararg of
Class<?> parameters (this is all private/@hide). This way we could
retrieve a list of intents like readValue(.., List.class, Intent.class),
or a map of string to intents like readValue(.., Map.class,
String.class, Intent.class). For non-container items, we can just pass
no arguments for the vararg. This is explained in internal javadocs.
Inside readValue() now, we also check the container types before
calling the internal methods for deserialization. So, if the thing on
the wire is a VAL_MAP and we know the method we're about to call will
return a HashMap, we verify that the type passed in parameter is a super
type of that (if it's non-null, if it's null it means "perform no
check").
Now, LazyValue became a BiFunction<Class<?>, Class<?>[], Object> to
receive those extra "item types" for containers. The reason for
separating the first from the rest is that the first defines the return
type in the new APIs and inside Parcel, so we need the T from Class<T>
to ensure type-safety.
(I was torn here between using BiFunction or just exposing LazyValue as
@hide for Bundle since it feels like we're missing meaning/abstraction,
but end up leaving this way, advise if you'd prefer the other way)
There was a bit of a refactor in Parcel so readValue() could call
internal methods that accepted nullable Class<?> parameters with the
meaning that null = "no verification" and non-null = "check against
type provided" (because the external APIs all require non-null
parameters).
Now we can return null in all cases when there is a type mismatch. Note
that the Bundle APIs catch ClassCastException to return null, but that
only works for non-generic types (eg. getSizeF()). For generic types
wrapping "return (T) o" with try-catch doesn't work because the type
gets erased to its bound at runtime, so the type mismatch escapes that
try-catch to the caller, potentially causing a crash. Now they happen
inside the getters, as the non-generic ones.
Test: Boots for now
Test: Working on CTS
Test: atest -d android.os.cts.ParcelTest android.os.cts.BundleTest android.os.BundleTest android.os.ParcelTest
CTS-Coverage-Bug: 219980813
Change-Id: Ifcbeb34b4684d7de105756b9d414162a9205ffaa