Commit Graph

1877 Commits

Author SHA1 Message Date
Jeff Sharkey
79b834d47c Tag some "new Binder()" instances to detect leaks.
We've seen evidence of a Binder leak, and our hunch is that it's
caused by one of these anonymous "new Binder()" sites.  Adding
descriptors will help us identify the leak cause.

Bug: 192415943
Test: atest BluetoothInstrumentationTests
Change-Id: I30cd15f084cf50f67edd833b27b853c4b22e1db1
2021-07-07 17:17:07 -06:00
Etienne Ruffieux
5e3a79e1d6 Update BluetoothAdapter and BluetoothDevice documentation
Update BluetoothAdapter#startDiscovery and
BluetoothDevice#fetchUuidsWithSdp documentation to
indicate that it queues the request if a device is
currently bonding

Tag: #feature
Bug: 187165224
Test: Manual
Merged-In: I3dbcdacff062f6c33c2fdc8d64170bf60b2fbf6f
Change-Id: I7e598417ba96a5acc9f13fb6d29a0612740f31b4
2021-07-01 22:39:36 +00:00
Rahul Sabnis
a8d3435cfd Add BluetoothLeAudio to BluetoothAdapter#getProfileProxy and
BluetoothAdapter#closeProfileProxy

Tag: #feature
Bug: 15083918
Test: Manual
Merged-In: Ia46dc4e50d42dbd574588b531045cb680aa09d94
Change-Id: Ia46dc4e50d42dbd574588b531045cb680aa09d94
2021-06-23 23:46:43 +00:00
Rahul Sabnis
4571f15931 Adds rahulsabnis@ as an owner for all Bluetooth files in frameworks/base
Tag: #feature
Bug: 191481598
Test: Manual
Merged-In: I6c8606c8e4802b74e80555e8ebf78932863d3f5b
Change-Id: I6c8606c8e4802b74e80555e8ebf78932863d3f5b
2021-06-18 12:27:11 -07:00
Rahul Sabnis
710f462a5f Update nullability checks to use Objects#requireNonNull
instead of deprecated method in Preconditions class

Tag: #feature
Bug: 190767948
Test: Manual
Change-Id: Ie7f7282b89c13f587fdfe1bf3288eb4a3c7dcc6e
2021-06-14 14:57:21 -07:00
Jeff Sharkey
fde28483d7 Merge "More Binder call AttributionSource assignment." into sc-dev 2021-06-04 04:07:17 +00:00
Jeff Sharkey
17bb873156 CloseGuard for more Bluetooth components.
We've seen evidence of IBluetoothProfileServiceConnection and
IBluetoothStateChangeCallback references being leaked, so attempt to
unregister them when an object is finalized without closing.

Bug: 189091551
Test: manual
Change-Id: I23792d48d94578acd7fc7a5164a95171801ee721
2021-06-03 15:38:17 -06:00
Jeff Sharkey
22ca72a675 More Binder call AttributionSource assignment.
Since developers can use a BluetoothDevice object can make remote
calls, it needs to have an accurate AttributionSource.  Previous CLs
had updated many places where these BluetoothDevice instances were
passed across Binder interfaces, but this change updates several
remaining locations which had been missed.

Introduces new "Attributable" marker interface to offer consistent
tooling when applying AttributionSource updates.

Bug: 187097694
Test: atest BluetoothInstrumentationTests
Change-Id: Icad3b9726591f0fbad58a493cefa5a0af7648280
2021-06-03 12:14:17 -06:00
Jeff Sharkey
6e8cafb843 Merge "Relax ACTION_TETHERING_STATE_CHANGED permissions." into sc-dev 2021-05-20 23:47:30 +00:00
Jeff Sharkey
263d880cf9 Relax ACTION_TETHERING_STATE_CHANGED permissions.
This broadcast doesn't contain any sensitive BluetoothDevice extras;
it only contains a single boolean indicating tethering state, so
relax it to no longer require the BLUETOOTH_CONNECT permission.

Bug: 188706031
Test: atest BluetoothInstrumentationTests
Change-Id: I2ff5c501844186a5813b2347246bbc83c190222d
2021-05-20 08:20:53 -06:00
Rahul Sabnis
b8cfbebbec Merge "Update BluetoothDevice#setAlias based on API council feedback: now accepts null input and returns an int (with error codes). Update CompanionDeviceManager#canPairWithoutPrompt to take a UserHandle instead of an int. Adds BluetoothStatusCodes class for all new Bluetooth error / success codes. Moved OOB and hci disconnect constants to the new BluetoothStatusCodes class." into sc-dev 2021-05-19 16:00:04 +00:00
Rahul Sabnis
d6b43bb520 Update BluetoothDevice#setAlias based on API council feedback: now
accepts null input and returns an int (with error codes).
Update CompanionDeviceManager#canPairWithoutPrompt to take a
UserHandle instead of an int. Adds BluetoothStatusCodes class for all
new Bluetooth error / success codes. Moved OOB and hci disconnect
constants to the new BluetoothStatusCodes class.

Tag: #feature
Bug: 184714087
Test: atest BluetoothDeviceTest#test_setAlias_getAlias
Change-Id: Ife03506f2cf68800f5824cb5fa94fec8aa34a39c
2021-05-17 16:47:55 -07:00
Jeff Sharkey
dd6dd3b1fb Apply AttributionSource during Intent delivery.
There are some Parcelables which offer to perform Binder calls, and
when these are delivered via Intent extras they fallback to
ActivityThread.currentAttributionSource(), instead of being tagged
based on the relevant app component.

This change begins using Intent.prepareToEnterProcess() as a hook to
fix-up AttributionSource when those extras finally land in the
destination process.  It uses the relevant AttributionSource based
on the Activity or Service the Intent is delivered to, which
developers have control over via AppComponentFactory.

In the case of <receiver> manifest elements, this change applies the
first android:attributionTags value to the Context used for that
BroadcastReceiver.

Bug: 187097694
Test: atest AttributionTest
Change-Id: I8f5197db7e8d7277d34f0ef2bb90bfdf1871186a
2021-05-15 09:48:14 -06:00
Treehugger Robot
ff3c817ba8 Merge "Bluetooth ScanFilter: Allow null in setDeviceAddress" am: 561b4c8aad am: 05c6b40a84 am: 32712787a0
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1702025

Change-Id: I48df730d65443e2417acf24d563ef7d7ad780340
2021-05-12 00:37:15 +00:00
Rahul Sabnis
30002e7cd3 Merge "Update docs for BluetoothDevice#fetchUuidsWithSdp to reflect that if the device is bonding, we either broadcast cached UUIDs or wait for SDP to be performed after the device is bonded." am: d8c539d8b8 am: 27918f0cf2 am: 634cd45795
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1698769

Change-Id: I0b4ae79183c1b6e72c75369a25ca375acd4e5331
2021-05-10 21:21:20 +00:00
Myles Watson
025714ff33 Bluetooth ScanFilter: Allow null in setDeviceAddress
Bug: 187076761
Test: manual scan filter test
Change-Id: I6456be4baab4b2a2b6d4607619ff92370b8b457d
2021-05-10 13:52:32 -07:00
Rahul Sabnis
d8c539d8b8 Merge "Update docs for BluetoothDevice#fetchUuidsWithSdp to reflect that if the device is bonding, we either broadcast cached UUIDs or wait for SDP to be performed after the device is bonded." 2021-05-10 17:41:36 +00:00
Rahul Sabnis
6f92ae94ab Update docs for BluetoothDevice#fetchUuidsWithSdp to reflect that if the
device is bonding, we either broadcast cached UUIDs or wait for SDP to
be performed after the device is bonded.

Tag: #feature
Bug: 187157597
Test: Manual
Change-Id: I1bd694195c4e974b7cd72f81848a6343b45c98fd
2021-05-07 19:13:25 -07:00
Jeff Sharkey
9a9fa815f1 Merge "Ensure privileged APIs require runtime permission." into sc-dev 2021-04-29 22:22:25 +00:00
Martin Brabham
329a11f7c6 Merge changes from topic "bluetooth_oob_api" am: 2e67798711 am: 8411b5d7b3 am: 50e294ad9b
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1686315

Change-Id: I00dc7f393edb9b562c97147d053302159c12fcdb
2021-04-29 21:33:10 +00:00
Martin Brabham
d50c8e0703 OOB: Remove static creator methods in favor of public constructors am: 1cd46165dd am: e897917de7 am: 2d3dbcab8f
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1684129

Change-Id: Ia4d99bf5f2dcee3d688796dfa3e11c1d104132a1
2021-04-29 21:32:57 +00:00
Jeff Sharkey
b8e4b883ae Ensure privileged APIs require runtime permission.
When users revoke a runtime permission, they expect all interactions
to be blocked, including those protected by the BLUETOOTH_PRIVILEGED
permission.

This change finishes applying that policy to any remaining Bluetooth
APIs which didn't already implement it.  To keep the implementation
straightforward, this change does "data delivery" checks when
registering for callbacks; the ideal behavior would be to wait
until data is actually delivered through the callbacks, but
RemoteCallbackList doesn't have support for AttributionSource yet.

Bug: 186405452
Test: atest BluetoothInstrumentationTests
Change-Id: Idd7be143eb8baff020a0718065293baae708041b
2021-04-29 13:55:07 -06:00
Jeff Sharkey
0cab9b7480 Preserve legacy permission check behavior.
As part of the new "Nearby devices" permission work, the
registerStateChangeCallback() API has been relaxed to no longer
require permissions.  However, we've discovered that some apps were
depending on that SecurityException being thrown, so this change
restores throwing behavior for those legacy apps.

Bug: 186176507
Test: atest BluetoothInstrumentationTests
Change-Id: Ife536dee246b300ffb3dd78aef0b059a230f3835
2021-04-28 09:25:38 -06:00
Martin Brabham
b0d691b3a1 Convert onOobData parameter for OobData from @Nullable to @NonNull
Bug: 185603183
Test: Compiles, test app works
Tag: #feature
Change-Id: I52636769f50f50b5ad2d135f54472bdeb1c25ee5
2021-04-27 09:36:41 -07:00
Martin Brabham
1cd46165dd OOB: Remove static creator methods in favor of public constructors
Bug: 184370881
Tag: #feature
Test: Manual compile
Change-Id: I502cdf5adde324b7a41cfb6974f0b43b0064a911
2021-04-26 09:35:54 -07:00
Jeff Sharkey
dd5a4f39c8 Long-tail of AttributionSource plumbing.
Wires up AttributionSource across the remaining long-tail of
Bluetooth AIDL interfaces, ensuring that developers can accurately
make calls chained back to a specific Context.

Moves "for data delivery" permission checks to happen in a single
location on each interface to ensure they're performed consistently
with the new AttributionSource arguments.  Note that "for data
delivery" isn't the best name; it's designed to represent that the
requested action was performed and should result in the relevant
appop being noted for the caller.

This change has the positive side effect of ensuring that all
interfaces are consistently enforcing the BLUETOOTH_CONNECT
permission, even in the case where BLUETOOTH_PRIVILEGED is also
required; this is what ensures that revoking the "Nearby devices"
permission takes effect for all callers.

Additionally, standardizing on enforcing permissions closer to the
AIDL entry point reduces the need for @RequiresPermission annotations
to be carried around inside the Bluetooth stack.

Bug: 183626112
Test: atest BluetoothInstrumentationTests
Change-Id: I8023dda654e325b8bfa2f0cdb994ad63a2b429d4
2021-04-24 08:31:43 -06:00
Jeff Sharkey
efe1110be8 More AttributionSource plumbing.
To prepare for future work which will plumb AttributionSource values
through all remaining AIDLs, we need profiles to interact directly
with the specific BluetoothAdapter they were created from.  This is
how we'll ensure that the relevant AttributionSource can be chained
down from the original Context they're obtained from.

This change also marks getDefaultAdapter() as deprecated to clearly
communicate that BluetoothManager.getAdapter() is the best-practice
path to obtaining a correctly scoped BluetoothAdapter instance.

Bug: 183626112
Test: atest BluetoothInstrumentationTests
Change-Id: I1e15170d7679019bbb6e396279d6e633e3dad4d6
2021-04-23 08:51:49 -06:00
Oli Lan
52f8d4c9c3 Pass attribution source to BT APIs.
This adds attribution source to BT method calls. This is now
required to allow the app ops for the new BT permissions
(BLUETOOTH_CONNECT, BLUETOOTH_ADVERTISE, and BLUETOOTH_SCAN)
to be noted.

Bug: 183626112
Test: atest BluetoothInstrumentationTests
Change-Id: I81598553b762e491d6364064a2e1ef41dec89bf9
2021-04-22 14:47:39 -06:00
Jeff Sharkey
67d4e1e079 Refinement of AttributionSource handling.
Previous CLs had started passing AttributionSource values across
Binder calls inside BluetoothDevice instances, but this can cause
confuse the permission check logic in the future; we should instead
always aim to use the AttributionSource closest to the app making
the call, instead of parceling it.

This change also improves logging to highlight when we're quietly
treating a permission as denied, and when a UID is mismatched.

Bug: 186106084
Test: atest BluetoothInstrumentationTests
Change-Id: I5d3fdb3c573cb9e77474952d8680caa4c4c464eb
2021-04-22 12:46:06 -06:00
Jeff Sharkey
c1b024d280 Merge "Pass AttributionSource to AdapterService methods." into sc-dev 2021-04-21 22:40:20 +00:00
Jeff Sharkey
d4b3fcac16 Merge "Annotations for Bluetooth broadcast intents." into sc-dev 2021-04-21 22:23:48 +00:00
Jeff Sharkey
f459828358 Annotations for Bluetooth broadcast intents.
Recent work has been using Error Prone rules and annotations to
reflect the current state of permission enforcement across the
Bluetooth stack, and we're now in a position were we can add new
permission enforcement that had been missing.

We've currently standardized on saying that APIs that return device
or Bluetooth state information (without sharing details about any
particular remote Bluetooth device) do not need to be permission
protected.

Bug: 183626724
Test: ./build/soong/soong_ui.bash --make-mode Bluetooth RUN_ERROR_PRONE=true
Change-Id: I53ac7a4fe1dea57316048c3cac4fa237b6ba3d38
2021-04-21 12:59:38 -06:00
Oli Lan
141edf9ef6 Pass AttributionSource to AdapterService methods.
This adds attribution source to AdapterService bluetooth method
calls. This is now required to allow the app ops for the new
bluetooth permissions (BLUETOOTH_CONNECT, BLUETOOTH_ADVERTISE,
and BLUETOOTH_SCAN) to be noted.

Bug: 183626112
Test: atest AdapterServiceTest
Test: atest CtsPermissionTestCases:android.permission.cts.NearbyDevicesPermissionTest
Change-Id: I8d1fe41ca9945a3baab584f248a17b3a1eb255f7
2021-04-21 17:59:06 +01:00
Rahul Sabnis
edad7c7c60 Update docs to reflect LE batch scan report delay floor
Tag: #feature
Bug: 167340030
Test: Manual
Change-Id: Ieeb0e6bccfc316fd4c8cdc40f6865b4185d6d9e8
2021-04-20 16:40:15 -07:00
Rahul Sabnis
93404b4883 Update docs to reflect LE batch scan report delay floor
Tag: #feature
Bug: 167340030
Test: Manual
Change-Id: Ieeb0e6bccfc316fd4c8cdc40f6865b4185d6d9e8
2021-04-20 14:22:16 -07:00
Nataniel Borges
0cd1de2226 Merge "Revert "Set a floor value for BLE Batch Scan report delay of 5000ms"" am: 6528da5667 am: 3ed5afa516 am: 81583909a9
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1681445

Change-Id: Ia2a73845fb92c457b37bacef7542aa47535560d4
2021-04-20 17:14:48 +00:00
Nataniel Borges
5aa369359e Revert "Set a floor value for BLE Batch Scan report delay of 5000ms"
This reverts commit ea303904fd.

Reason for revert: b/185890964

Change-Id: I270dc16de0e24728c694830fbe920786b6d90174
2021-04-20 15:50:03 +00:00
Treehugger Robot
0bf5efaeab Merge "Set a floor value for BLE Batch Scan report delay of 5000ms" am: ce2a2c80dd am: da5eb08ae3 am: 2b8dce1db1
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1676810

Change-Id: I2aafeceb53a673e0172e5873c7354a6d59acc530
2021-04-20 04:00:37 +00:00
Rahul Sabnis
ea303904fd Set a floor value for BLE Batch Scan report delay of 5000ms
Tag: #feature
Bug: 167340030
Test: Manual
Change-Id: I4ef99a9562f1447a2ccee42a344384a38a487c19
2021-04-19 17:29:02 -07:00
Jeff Sharkey
655d691d65 Add missing Bluetooth API permission enforcement.
Recent work has been using Error Prone rules and annotations to
reflect the current state of permission enforcement across the
Bluetooth stack, and we're now in a position were we can add new
permission enforcement that had been missing.

We've currently standardized on saying that APIs that return device
or Bluetooth state information (without sharing details about any
particular remote Bluetooth device) do not need to be permission
protected.

Bug: 183626724
Test: ./build/soong/soong_ui.bash --make-mode Bluetooth RUN_ERROR_PRONE=true
Change-Id: I37a9e03ecdca6f7a6eb9d7f094e2f95a97036612
2021-04-18 07:58:11 -06:00
Jeff Sharkey
6eed56ddd3 More Bluetooth API annotation updates.
This change adds a "BluetoothPermissionChecker" that ensures that
all Bluetooth permission annotations are consistent.  In addition, it
verifies that all Bluetooth public APIs have been audited to be
permission protected where relevant.

We've currently standardized on saying that APIs that return device
or Bluetooth state information (without sharing details about any
particular remote Bluetooth device) do not need to be permission
protected.

This change is only annotations and has no behavior changes.

Bug: 183626724
Test: ./build/soong/soong_ui.bash --make-mode Bluetooth RUN_ERROR_PRONE=true
Change-Id: Ie80b15b058359bf1e9a6ee881b89cb3e5b584ca1
2021-04-16 13:31:22 -06:00
Jeff Sharkey
938e329b77 Refine BluetoothLeAdvertiser permissions.
Technically these APIs required both ADVERTISE and CONNECT, since
internally it would attempt getting the device name as part of
calculating packet lengths.  These methods shouldn't require the
CONNECT permission, so we add a getNameLengthForAdvertise() method
internally to remove this dependency.

Bug: 183626724
Test: ./build/soong/soong_ui.bash --make-mode Bluetooth RUN_ERROR_PRONE=true
Change-Id: I245417bfc26d6d3a4f8be14077c7f1d271b5959e
2021-04-15 14:58:02 -06:00
Martin Brabham
76a512f958 OOB generateLocalOobData
unhide @SystemApi callback methods

Bug: 178007935
Tag: #feature
Test: compiles
Change-Id: I2d4167a6c92ee0cc24da12df206838161c8f3318
Merged-In: I2d4167a6c92ee0cc24da12df206838161c8f3318
2021-04-15 18:36:06 +00:00
Jeff Sharkey
cd5c179783 Merge changes from topic "apr10" into sc-dev
* changes:
  Update Bluetooth API annotations.
  Error Prone for RequiresPermission across AIDL.
2021-04-15 13:43:03 +00:00
Jeff Sharkey
4acdb1beff Update Bluetooth API annotations.
Recent work has introduced a new "Nearby devices" runtime permission
which protects all existing Bluetooth APIs; we've done this by
defining a <split-permission> to convert the old BLUETOOTH and
BLUETOOTH_ADMIN permissions into one of three new permissions:

* BLUETOOTH_ADVERTISE: Required to be able to advertise to nearby
                       Bluetooth devices.
* BLUETOOTH_CONNECT:   Allows applications to connect to paired
                       bluetooth devices.
* BLUETOOTH_SCAN:      Required to be able to discover and pair
                       nearby Bluetooth devices.

At its core, this change begins updating the Bluetooth APIs to have
correct @RequiresPermission indicating which permission is actually
enforced internally.  To ensure alignment across Binder, the newly
added "RequiresPermissionChecker" Error Prone checker was used to
discover any inconsistencies, ensuring correctness from server-side
enforcement up through to the public APIs.

In addition, since developers will continue building apps for both
modern and legacy platforms, this change introduces new auto-doc
annotations which will emit helpful consistent documentation
describing the behavior of older devices that are still using the
old permission model.

Bug: 183626724
Test: ./build/soong/soong_ui.bash --make-mode Bluetooth RUN_ERROR_PRONE=true
Change-Id: I02aa127e8e07f239561f4f2a3bbdfc6fccb82f7f
2021-04-14 21:13:24 -06:00
Treehugger Robot
b2e2624e8b Merge "Bluetooth OOB: Fix getLeAppearance" am: ef0304a087 am: 2988998bd3 am: 6745daf3c2
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1673875

Change-Id: I8d2d9d4ea7bfa3b9a3a4bfe358da4275688b6f19
2021-04-15 03:11:10 +00:00
Martin Brabham
ba2c904f8d OOB generateLocalOobData
unhide @SystemApi callback methods

CTS-Coverage-Bug: 184395281
Bug: 178007935
Tag: #feature
Test: compiles
Change-Id: I2d4167a6c92ee0cc24da12df206838161c8f3318
2021-04-14 18:53:04 +00:00
Hansong Zhang
a77bdb5161 Bluetooth OOB: Fix getLeAppearance
Bug: 185196125
Test: Use OOB pairing
Change-Id: I1cb1c33b0b17f2fd242f6579844996c2ccf09e62
2021-04-13 11:55:28 -07:00
Martin Brabham
6d4100e433 OOB: Implement getLocalOutOfBand API
CTS-Coverage-Bug: 184395281
Bug: 178007935
Tag: #feature
Test: manual
Change-Id: I5bc11ac13d9cbb8f76f422aa4aea8295ebec95b4
Merged-In: I5bc11ac13d9cbb8f76f422aa4aea8295ebec95b4
2021-04-07 14:08:39 -07:00
TreeHugger Robot
dcc1a906cf Merge "OOB: Implement generateLocalOutOfBand API" into sc-dev 2021-04-07 19:32:23 +00:00