Commit Graph

6459 Commits

Author SHA1 Message Date
Songchun Fan
3a4059f759 [SettingsProvider] allow test_only apps access @hide keys w/o @Readable
+ Also improve error message

BUG: 183436286
BUG: 183709745
Test: atest android.appsecurity.cts.ReadableSettingsFieldsTest
Change-Id: I17224d213d707f6f359aa17f1b745bf508208de8
2021-04-09 19:03:51 +00:00
Kriti Dang
7e6abece7d Merge "Adding unknown constant to AudioManager ENCODED_SURROUND_OUTPUT mode constants" into sc-dev 2021-04-09 12:51:31 +00:00
Kriti Dang
98fdb2616e Adding unknown constant to AudioManager ENCODED_SURROUND_OUTPUT mode constants
Bug: 184044740
Test: atest AudioManagerTest
Change-Id: I806df4aac6fbab5f32f66a7deac67ae8f71e3fdd
2021-04-08 15:01:55 +02:00
Jordan Liu
145e5e211b Merge "Update doc for getDefaultSmsPackage" into sc-dev 2021-04-07 18:51:31 +00:00
Marcus Hagerott
d05767a0af Merge "Improve SimPhonebookContract javadocs and qualifiers" am: e738f2f211 am: 77c1d68aa4 am: 38ff81afb3
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1649647

Change-Id: Ie046dd362b2b0c91ce7dfa6faa02e0c6d1741bdc
2021-04-07 17:08:07 +00:00
Marcus Hagerott
e738f2f211 Merge "Improve SimPhonebookContract javadocs and qualifiers" 2021-04-07 15:43:33 +00:00
Jordan Liu
192cfc6ea0 Update doc for getDefaultSmsPackage
Bug: 174445979
Test: no change to behavior
Change-Id: Ied4b7f5bcc2ff78f4c6f04e4c11b5a10cf463fcd
2021-04-06 22:05:27 +00:00
Winson
0bcdb9897c Change ACTION_APP_OPEN_BY_DEFAULT_SETTINGS to standard format
This was originally introduced as an @hide API, but was exposed as part
of changes to app links. The old constant value was maintained, but it
can be migrated to the standard format and Settings can just catch
both.

Bug: 184370492

Test: manual, test app that launches using action

Change-Id: I904bd816da6c20a1dfdb207f8d4d486bb7be5cd5
2021-04-02 12:47:43 -07:00
Neil Fuller
93a0dca3df Merge "Track API changes TimeZoneDetector -> TimeManager" into sc-dev 2021-04-01 11:01:41 +00:00
Neil Fuller
fddcb999c0 Track API changes TimeZoneDetector -> TimeManager
Methods were moved from TimeZoneDetector to TimeManager in commit
02d943f44d. This commit updates comments
to track.

Bug: 159891384
Test: None - comment change
Change-Id: I96c4c248f98041f88ff3372b575114c277b80620
2021-04-01 10:00:14 +01:00
Forrest Dunlap
f9063fb1ff Clarify resetToDefaults documentation.
Bug: 170157200

Change-Id: I4cf791795132d02289bf49b3a038990a5adbceb3
2021-03-31 17:03:41 +00:00
Matt Casey
4dddebe4b8 Merge "Revert "Revert "Add setting for touch gesture and long-press hom..."" into sc-dev 2021-03-30 14:23:10 +00:00
Jacky Kao
b599784e05 Merge "Logs magnification feature behavior. (2/2)." into sc-dev 2021-03-29 23:56:22 +00:00
Svet Ganov
8d2ed50604 Runtime permission attribution improvements
When an app is proxying access to runtime permission protected
data it needs to check whether the calling app has a permission
to the data it is about to proxy which leaves a trace in app ops
that the requesting app perofmed a data access. However, then the
app doing the work needs to get the protected data itself from the
OS which access gets attributed only to itself. As a result there
are two data accesses in app ops where only the first one is a
proxy one that app A got access to Foo through app B - that is the
one we want to show in the permission tracking UIs - and one
for the data access - that is the one we would want to blame on
the calling app, and in fact, these two accesses should be one -
that app A accessed Foo though B. This limitation requires fragile
one off workarounds where both accesses use the same attribution
tag and sys UI has hardcoded rules to dedupe. Since this is not
documented we cannot expect that the ecosystem would reliably
do this workaround in apps that that the workaround in the OS
would be respected by every OEM.

This change adds a mechaism to resolve this issue. It allows for
an app to create an attribution context for another app and then
any private data access thorugh this context would result in a
single app op blame that A accessed Foo though B, i.e. we no longer
have double accounting. Also this can be nested through apps, e.g.
app A asks app B which asks app C for contacts. In this case app
B creates an attribution context for app A and calls into app C
which creates an attribution context for app B. When app C gets
contacts the entire attribution chain would get a porper, single
blame: that C accessed the data, that B got the data from C, and
that A got the data form B. Furthermore, this mechanism ensures
that apps cannot forget to check permissions for the caller
before proxying private data. In our example B and C don't need
to check the permisisons for A and B, respectively, since the
permisisons for the entire attribution chain are checked before
data delivery. Attribution chains are not forgeable preventing
a bad actor to create an arbitrary one - each attribution is
created by the app it refers to and points to a chain of
attributions created by their corresponding apps.

This change also fixes a bug where all content provider accesses
were double counted in app ops due to double noting. While at
this it also fixes that apps can now access their own last ops.
There was a bug where one could not pass null getting the attributed
ops from a historical package ops while this is a valid use case
since if there is no attribution everything is mapped to the null
tag. There were some app op APIs not being piped thorough the app
ops delegate and by extension through the app ops policy. Also
now that we have nice way to express the permission chain in a
call we no longer need the special casing in activity manager to
handle content provider accesses through the OS. Fixed a bug
where we don't properly handle the android.os.shell calls with
an invlaid tag which was failing while the shell can do any tag.

Finally, to ensure the mechanims is validated and works end-to-end
we are adding support for a voice recognizer to blame the client
app for the mic access. The recognition service can create a blaming
context when opening the mic and if the mic is open, which would
do all permission checks, we would not do so again. Since changes
to PermissionChercker for handling attribution sources were made
the CL also hooks up renounced permissoins in the request permission
flow and in the permission checks.

bug:158792096
bug:180647319

Test:atest CtsPermissionsTestCases
     atest CtsPermissions2TestCases
     atest CtsPermissions3TestCases
     atest CtsPermissions4TestCases
     atest CtsPermissions5TestCases
     atest CtsAppOpsTestCases
     atest CtsAppOps2TestCases

Change-Id: Ib04585515d3dc3956966005ae9d94955b2f3ee08
2021-03-29 16:49:33 +00:00
Matt Casey
38ced457e0 Revert "Revert "Add setting for touch gesture and long-press hom..."
Revert "Revert "Hide long-press home animation when disabled by ..."

Revert submission 13998375-revert-13958909-mrcasey-lph-GNUFFHLQXH

Reason for revert: Reverting these CLs did not fix the test b/183684181
Reverted Changes:
Iac13fc450:Revert "Hide long-press home animation when disabl...
Ieb43607a8:Revert "Add setting for touch gesture and long-pre...

Change-Id: Ia92b0a1f19dc7423fe1b3796e14582169e58d203
2021-03-29 13:42:09 +00:00
TreeHugger Robot
894cde1030 Merge "[Settings] add readable tests to presubmit" into sc-dev 2021-03-29 11:52:22 +00:00
Kriti Dang
e713ee6c60 Merge changes from topic "cherrypick-Display settings HDR formats-mumvl547ah" into sc-dev
* changes:
  Handling Number Format Exception in DiscreteValueIntegerListValidator
  Hdr format settings [Backend]
2021-03-28 12:25:32 +00:00
Matt Casey
304bd59b3e Merge "Revert "Add setting for touch gesture and long-press home assist..."" into sc-dev 2021-03-25 21:28:34 +00:00
Matt Casey
fabc9f6f27 Revert "Add setting for touch gesture and long-press home assist..."
Revert "Hide long-press home animation when disabled by setting"

Revert submission 13958909-mrcasey-lph

Reason for revert: Possible test breakage b/183684181
Reverted Changes:
Iaaf39e76a:Hide long-press home animation when disabled by se...
I24ee67cf1:Add setting for touch gesture and long-press home ...

Change-Id: Ieb43607a8010b843fc643979953a266cbb84788f
2021-03-25 21:19:00 +00:00
Songchun Fan
1d70937fe7 Merge "[Settings] keys with @TestApi need to have @Readable" into sc-dev 2021-03-25 15:44:33 +00:00
Kriti Dang
b4775b02a7 Hdr format settings [Backend]
Added new APIs to DisplayManager to set the user disabled HDR formats,
and get/set if user disabled formats should be ignored or not.
These new settings are stored in Settings.Global.
Modified the implementation of Display#getHdrCapabilities to not return
the formats disabled by user.

Bug: 172905874
Test: atest CtsDisplayTestCases
Change-Id: I4841af251ee0e4938614b154d0c5239814ea7cd9
Merged-In: I4841af251ee0e4938614b154d0c5239814ea7cd9
2021-03-25 12:41:35 +00:00
Matt Casey
af29800df0 Merge "Add setting for touch gesture and long-press home assistant invocations" into sc-dev 2021-03-25 12:15:09 +00:00
Sudheer Shanka
d2cd698106 Merge "Add DeviceConfig namespace for media." into sc-dev 2021-03-25 06:56:08 +00:00
Ahaan Ugale
dadfd22e74 Merge "Introduce a default Voice IME concept." into sc-dev 2021-03-25 02:59:41 +00:00
Winson Chiu
5ae11b4a58 Merge "Expose the open by default settings screen to apps" into sc-dev 2021-03-25 02:20:37 +00:00
Ahaan Ugale
9672b2e58c Introduce a default Voice IME concept.
This is configured by the system config resource,
config_systemSpeechRecognizer, which also provides the default
VoiceRecognitionService and the holder for the SYSTEM_SPEECH_RECOGNIZER
role.

InputMethodManagerService updates the new DEFAULT_VOICE_INPUT_METHOD
setting and handles changes to the config_systemSpeechRecognizer value.

No updates are made through the Settings UpgradeController because any
updates that would be needed are already handled by the logic for config
value changes.

Testing:
1. Enable DEBUG logging in InputMethodManagerService.
2. $ m -j && adb remount && adb shell stop && adb sync && adb shell start
3. $ adb shell settings get secure enabled_input_methods; \
 adb shell settings get secure default_input_method; \
 adb shell settings get secure disabled_system_input_methods; \
 adb shell settings get secure default_voice_input_method
4. Check logcat to make sure nothing looks suspect.

Cases tested:
- IME wasn't already in the enabled IME list
- IME was already enabled
- no value for config_systemSpeechRecognizer
- new user added
- locale changed
- config package doesn't have an IME
- update without config value, then set a config value
- config value updated (when both values had valid IMEs)
- combinations of the above cases, as appropriate

Bug: 175480456
Test: manual - see above
Test: atest InputMethodUtilsTest
Test: atest CtsInputMethodTestCases --retry-any-failure
Change-Id: I1abdc145e3d5969fbb69811df2ca2e35c7a177e1
2021-03-24 23:07:21 +00:00
Songchun Fan
3f08960272 [Settings] add readable tests to presubmit
This will enforce the readable tests for changes made to Settings.java.

Test: atest
BUG: 183530680
Change-Id: Ie91350b29c10868cecd2c2fe4eba378278b3cb23
2021-03-24 22:37:44 +00:00
Marcus Hagerott
a6c9cd2fb7 Improve SimPhonebookContract javadocs and qualifiers
Test: atest CtsSimPhonebookProviderTestCases
Bug: 183395170
Change-Id: Id160092078f26908787b4b9a4fbe525825496875
2021-03-24 14:16:31 -07:00
Winson
b5ba585b39 Expose the open by default settings screen to apps
With the changes for app links v2, apps need a way to link users into
the domain selection screen if the app relies on opening web links
for some functionality.

To achieve that, this exposes the existing action,
ACTION_APP_OPEN_BY_DEFAULT_SETTINGS, from android.provider.Settings
and removes the permission needed to launch the relevant Activity,
since it's no longer required.

Note that this will also require a change to remove the enforcement
from the Activity declaration, which will be a follow up.

Bug: 178648367

Test: none, unhide API

Change-Id: I73231b9b4686ee67490ffe1526542b2f59c8089b
2021-03-24 12:43:06 -07:00
Peter Wang
e0dcbf7c3f [API Review] Change ACTION_MANAGE_ALL_SIM_PROFILE_SETTINGS API
Bug: 182165190
Bug: 170507492
Test: Local
Change-Id: I21bd95bfc746f2d11dc569b9ea990bb7a3726ba5
Merged-In: I21bd95bfc746f2d11dc569b9ea990bb7a3726ba5
2021-03-24 11:18:37 -07:00
Songchun Fan
da9e388d20 [Settings] keys with @TestApi need to have @Readable
This allows them to be accessed by test apps.

BUG: 183223092
Test: atest CtsAppSecurityHostTestCases:android.appsecurity.cts.ReadableSettingsFieldsTest#testSecurePublicSettingsKeysAreReadable
Change-Id: I2bdcab2d9279f5ef944b17896c7b31b84ca8dc81
2021-03-24 18:15:53 +00:00
Matt Casey
662f32ddc2 Add setting for touch gesture and long-press home assistant invocations
No UI, just setting storage and the code to honor that setting.

Bug: 182216673
Bug: 182220287
Test: manual + atest NavigationBarTest
Change-Id: I24ee67cf196d7ae698a731e00a9eb5a726eddb24
2021-03-24 11:49:38 -04:00
Sudheer Shanka
36cf320611 Add DeviceConfig namespace for media.
Bug: 174699413
Test: manual
Change-Id: I9c749f34931f9197e428ae9d5044062d705efed6
2021-03-24 06:59:23 -07:00
Abhijeet Kaur
7591e2d06a Make getExternalStorageMountMode as SystemApi
Secondary volumes are FUSE mounted, whereas Android/data and Android/obb
on primary volumes are not FUSE mounted. Access to these private app
directories on primary volumes is restricted using the mount modes, but
access for these on secondary volumes need to be regulated by
MediaProvider.

Make getExternalStorageMountMode as SystemApi so that MediaProvider
can leverage the same mount logic for Secondary volumes.
Expose relevant mount modes as SystemApi as well.

This change saves us the maintenance overhead for Secondary volumes for
Android S+. Otherwise we would have to check if an app is a signature
app through APIs which would basically be the duplication for the
logic in StorageManagerService.java.

Expose ExternalStorageProvider and downloads Authority for MediaProvider
to rely only on APIs. This is also required for CDD modifications that
these 2 providers are given exceptional access to private app dirs.

Bug: 175796984
Bug: 173505864
Bug: 173505864
Test: atest DownloadProviderTest
Test: atest CtsScopedStorageHostTest
Test: atest android.scopedstorage.cts.host.PublicVolumeHostTest#testCheckInstallerAppAccessToObbDirs
Test: atest android.scopedstorage.cts.host.PublicVolumeHostTest#testCantAccessOtherAppsExternalDirs
Change-Id: I51bc7bd3f355fadd9de56ac267469c2352eb0ffa
Merged-In: I51bc7bd3f355fadd9de56ac267469c2352eb0ffa
2021-03-24 09:28:27 +00:00
Xiaoyu Jin
d988ccfa8e Merge "Add DeviceConfig namespace for AppSearch" into sc-dev 2021-03-24 05:29:12 +00:00
Jacky Kao
f8fb7b24bc Logs magnification feature behavior. (2/2).
Uses the atom MagnificationModeWithImeOnReported in westworld to log
the activated mode when the IME window is shown on the screen.

Adding a new callback API in the MagnificationCallback to monitor the
IME window visibility changes. The A11y framework registers the
callback when the magnification is enabled. It logs the related
data when it receives the IME window visibility changes through
this callback and the magnification is in the activation.

Bug: 154021596
Test: a11y CTS & unit tests
Test: make statsd_testdrive && ./out/host/linux-x86/bin/statsd_testdrive 346
Merged-In: I49b02e00d5a1131b388eeb923440f59a2b4f81a6
Change-Id: I49b02e00d5a1131b388eeb923440f59a2b4f81a6
(cherry picked from commit 1aa113d8dd)
2021-03-24 05:10:57 +00:00
Peter Wang
3c8304207b Merge "[API Review] Change ACTION_MANAGE_ALL_SIM_PROFILE_SETTINGS API" into sc-dev 2021-03-24 03:24:20 +00:00
Rambo Wang
6d768fb7d6 Merge changes from topics "ServiceState#dataRegState", "ServiceState#duplexMode" am: c289c9b0a2 am: 506d5c92c3 am: 507e3b9dcd
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1636779

Change-Id: Ic8faff9d023b492da5eb7e31e281ddfbf49c8d1d
2021-03-24 03:01:54 +00:00
Rambo Wang
de0c5fa090 Public ServiceState#duplexMode in telephony provider am: 4481b5181e am: b336d92aa7 am: 57456a7152
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1638159

Change-Id: I2f53c2305075011904718ba5a81279875dc07235
2021-03-24 03:01:39 +00:00
John Li
bb9e119844 Merge "Add Settings flag for Transform." into sc-dev 2021-03-24 02:21:00 +00:00
TreeHugger Robot
074666c5a0 Merge "Add support for selected contacts device to device sharing." into sc-dev 2021-03-23 22:11:22 +00:00
Xiaoyu Jin
eefbf02162 Add DeviceConfig namespace for AppSearch
Adds a new namespace to DeviceConfig for features
relating to AppSearch.

Bug: 173532925
Test: build
Change-Id: I5887899d9292bf88ea5007d94c20b8690ee73872
2021-03-23 13:08:43 -07:00
TreeHugger Robot
77cbe77beb Merge "Enable RESTRICTED bucket." into sc-dev 2021-03-23 18:58:14 +00:00
Rambo Wang
cff9760e07 Export ServiceState#DataRegState into telephony provider
Keep ServiceState#getDataRegState hide. Apps can get the same
info from telephony provider without loation permission.

Bug: 182601774
Test: atest com.android.phone.ServiceStateProviderTest
Change-Id: I1ba72a5b767761d2f7bd1b52459a0c9d101061a2
2021-03-23 09:33:21 -07:00
Rambo Wang
4481b5181e Public ServiceState#duplexMode in telephony provider
ServiceState#getDuplexMode is a public API. Expose the same
info through telephony provider to let applications retreive
it without location permission.

Bug: 182601774
Test: atest com.android.phone.ServiceStateProviderTest
Change-Id: I19128c938993f351533aca9a8e1a1356e21eb30e
2021-03-23 09:27:42 -07:00
Rambo Wang
8fadaef00c Merge "Expose ServiceState#getDataNetworkType in telephony provider" am: 9446a5239f am: 11264381a4 am: ff97f102cc
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1639370

Change-Id: Ib2c5d3ec7b28e37d1fa7426aa9e0a1bc7730b9e8
2021-03-23 15:57:25 +00:00
Grace Jia
2bd23cfbcc Add support for selected contacts device to device sharing.
Bug: 163085177
Test: CTS tests
Change-Id: I4f6da463a29ba9cf067d36941a9b4e584012c817
Merged-In: I4f6da463a29ba9cf067d36941a9b4e584012c817
2021-03-23 15:51:24 +00:00
John Li
8929a2e804 Add Settings flag for Transform.
Bug: 177299699
Test: manual
Change-Id: I4947117b6bb11678e3ad761204d720354b9e73ae
Merged-In: I4947117b6bb11678e3ad761204d720354b9e73ae
2021-03-23 07:50:22 +00:00
Rambo Wang
6a7df3f4e8 Expose ServiceState#getDataNetworkType in telephony provider
Data network type is key information to make the switching
decision. Exporting to telephony provider can let application
get the information without location permission.

Bug: 182601774
Test: atest com.android.phone.ServiceStateProviderTest
Change-Id: I9753eee2619baf6b1627835624444c0e4f0cd410
2021-03-22 12:24:19 -07:00
Tej Singh
f6561f6c82 Merge "Add statsd flags to public namespaces" into sc-dev 2021-03-22 18:22:48 +00:00