Commit Graph

187 Commits

Author SHA1 Message Date
Nate Myren
f882feeabc Remove R QPR attribution hacks
Bug: 172868375
Test: manual
Change-Id: I5e731bb821e879f6c314604912f13800ca668aa4
2021-03-16 15:10:36 -07:00
Nate Myren
1023e07f85 Show all system apps to hub teamfood, remove location indicator
Location indicator has its own flag, so it is being removed from the hub
teamfood. Also, showing all system usages (except the system app) for
the hub teamfood.

Bug: 172868375
Test: atest PrivacyDialogControllerTest, PrivacyItemControllerFlagsTest
Change-Id: Iad5b141f600a0bf830d5b2ef5169ed90533914cb
2021-03-12 12:36:27 -08:00
Eugene Susla
9076840750 Merge "Address API council feedback" into sc-dev 2021-03-04 19:09:23 +00:00
Evan Severson
33792c94ea Merge "Update permissions OWNERS files" am: 391145ab85 am: d35d84c8fc am: 69abbcb203
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1611821

MUST ONLY BE SUBMITTED BY AUTOMERGER

Change-Id: I7d0c9e41b15a62c547df2ca1fb2bca37c5ab7d43
2021-03-02 22:32:49 +00:00
Eugene Susla
206e26a294 Address API council feedback
Fixes: 181681395
Fixes: 181562406
Test: presubmit
Change-Id: I51fc6e1568a8fadf82c8c1c5b52c1356a94ce36d
2021-03-02 12:46:51 -08:00
Evan Severson
13fd14252b Update permissions OWNERS files
Test: None
Change-Id: I039bf12c65b0cd509a6772d89b96821b98ff318c
2021-03-02 10:37:41 -08:00
Nate Myren
066f1bce6e Merge "Show usage by default speech recognizer" into sc-dev 2021-02-26 23:51:30 +00:00
Nate Myren
4ee433cc90 Show usage by default speech recognizer
Test: manual
Fixes: 181067845
Change-Id: I9be50bf4bbafcedbc1c52adc0780b9821c865c8d
2021-02-26 11:22:58 -08:00
Evan Severson
c5d33bfde2 Remove role exempt flag
There is no use for this currently.

Bug: 158311343
Test: atest CtsPermission{1,3}TestCases
Change-Id: I102b30ccb3354e248e4e6be304c6dfe6135ba2a6
2021-02-25 14:04:41 -08:00
Eran Messeri
003453b354 Restrict Admin grant of sensors-related permissions
Restrict the admin of a fully-managed device or managed profile from
granting sensors-related permissions.

The admin of a managed profile cannot control permission grants for
sensors-related permissions at all.

The admin of a  fully-managed device can opt-out of having said control
by providing a provisioning extra.

This change passes the boolean flag in ActiveAdmin indicating whether
the admin has control over sensor permission grants into the permission
controller.

Manual testing:
* Install TestDPC
* Create a work profile using TestDPC.
* Get the BasicLocation app by checking out
  https://github.com/android/location-samples and building it from there.
* Install the app onto the device but do not start it.
* In TestDPC, Find "Manage app permissions", choose "Basic Location Sample"
  from the drop-down menu.
* Toggle each of the "ACCESS_COARSE_LOCATION" and
  "ACCESS_BACKGROUND_LOCATION" to "Allow".
* Observe that no notification appears.
* Start the BasicLocation app and observe the runtime permission prompt
  shows up.

Bug: 158735247
Test: Manual (more to be added).
Test: cts (see topic)
Change-Id: I12d9f7e24ad4bc09651a5e5f60b864298506c2c4
2021-02-16 19:03:57 +00:00
TreeHugger Robot
bbeeeefc70 Merge "Fix double adding of special attribution usage" into sc-dev 2021-02-11 23:18:37 +00:00
Philip P. Moltmann
8d6a0cb6af Merge "Remove me from OWNERS files" am: 25ee5a7fb7 am: bf8de269cb am: 39198ddd84
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1573324

MUST ONLY BE SUBMITTED BY AUTOMERGER

Change-Id: I429557a8537fb6417fcb9539978964ade75c8dee
2021-02-11 23:15:42 +00:00
Philip P. Moltmann
a8eb3d3e69 Remove me from OWNERS files
Test: n/a
Change-Id: I6113011e6ab0997285d5b7a86303fc60a3b98a2b
Exempt-From-Owner-Approval: Previously approved
2021-02-11 22:28:43 +00:00
Nate Myren
f187670270 Fix double adding of special attribution usage
Fixes: 180019623
Test: manual
Change-Id: I6e0681e0126bc563d8af4cd11c7db0785e47c912
2021-02-11 12:40:48 -08:00
Hai Zhang
bdd7a8e8a3 Add documentation about role permission protection in Permissions.md.
Change-Id: Ibb645d33554a05965ac344c4a4a4b7b9f004dec7
Test: presubmit
(cherry picked from commit dcbaef9481)
2021-02-02 19:06:24 +00:00
Nate Myren
2779eb839e Change recent threshold to 15 seconds
Change default recent threshold to 15 seconds

Test: build
Bug: 172868375
Change-Id: Ib716cc68744aa563fcf8988be6da56c9f95b9ab9
2021-01-29 09:50:26 -08:00
Nate Myren
f78406820e Add wifi call special case, fix phone, predictor, filter system
Add the wifi call special case, where if a call is ongoing while a
carrier privileged app is using microphone, the phone call usage is
removed. Ensure the phone mic op is listened for, add code to find the
predictor app, and show it, if the user is in a teamfood. Filter the
system app out, since the system app can be a location provider

Fixes: 178701757
Test: Manual
Change-Id: Ic1bf7f28c99bc0f596492332f7b4656c3bd7d25e
2021-01-28 14:28:31 -08:00
Nate Myren
a2cd99a805 Make sure user context map is ArrayMap, not Map
Ensure the user context map is editable, and remove hardcoded enable.

Fixes: 178616169
Test: manual
Change-Id: I54d721be7712a2efcc3695bae5ae7e44920a40ed
2021-01-27 11:44:21 -08:00
Nate Myren
6fa6a807a5 Do not look at self when comparing for duplicate usage
When looking for duplicate usages, do not compare to self

Fixes: 178088373
Test: manual
Change-Id: I5e7316caff5ff33017cd868324c066a3f3e99bd6
2021-01-21 10:44:07 -08:00
Nate Myren
281f981a56 Fix proxy attribution in PermissionUsageHelper
Test: manual
Fixes: 177677430
Change-Id: I98e65447ee33e2c15785e7f1ef0c003bbc4d9540
2021-01-15 12:14:36 -08:00
Nate Myren
85bcae5eff Merge "Add special attribution cases to PermissionUsageHelper" 2021-01-14 17:07:10 +00:00
Nate Myren
1099641699 Add special attribution cases to PermissionUsageHelper
Porting the proxy usage and mic special attribution cases from the
PermissionController to the PermissionManager

Bug: 172868375
Test: manual
Change-Id: I2af850c9cd709541abf862377b67153a1c477c94
2021-01-13 09:10:23 -08:00
Eugene Susla
0da6fe5759 Replace CDM profiles hardcoded strings with real values
Test: manual
Bug: 165951651
Change-Id: Ie3771df49dca43b9c91f64b32a6b56b211e754ad
2021-01-12 11:30:24 -08:00
Nate Myren
f0243ed0ee Merge "Add lastAccessTime to PermGroupUsage" 2021-01-11 22:52:37 +00:00
Nate Myren
2dfe8025c5 Add lastAccessTime to PermGroupUsage
Bug: 172868375
Test: Build
Change-Id: Ib23ef6459f709a2743e9e662619cb785a1ce54c7
2021-01-11 12:52:54 -08:00
TreeHugger Robot
5e96902fb1 Merge "Check for running app op when checking recent" 2021-01-09 00:25:56 +00:00
Nate Myren
caf1078e52 Check for running app op when checking recent
Ensure that it is checked if an app op is running before filtering it
due to an old "lastAccessTime".

Fixes: 177089983
Test: manual
Change-Id: Ibeb344ad691994a93bde1a93794093d7d4fc920c
2021-01-08 13:35:00 -08:00
TreeHugger Robot
a4c1faff5b Merge "Create copy of op list, return empty if indicators disabled" 2021-01-07 23:21:46 +00:00
Nate Myren
0767818077 Create copy of op list, return empty if indicators disabled
When assembling the op list, create a copy, do not use the existing
camera op list, as that list is final. Also return an empty list when
indicators are disabled, not null.

Fixes: 177005228
Test: Manual
Change-Id: I281085c12f0706836098fc2f16d196887596170e
2021-01-07 13:12:19 -08:00
Eugene Susla
b0de403aa9 Merge "Introduce API to get CDM profile permissions description string" 2021-01-07 17:21:27 +00:00
Hai Zhang
d96a064ded Finish swapping packageName and permissionName.
Package is the subject and permission is the attribute, so naturally
package should come first. However, some APIs in the early days
weren't declared this way. Now that our new APIs are designed
properly, clean up our ordering internally as well.

Bug: 158736025
Test: presubmit
Change-Id: I47cab14bb80afcdb7e868fe75a375a4705606d9d
2021-01-06 17:29:59 -08:00
TreeHugger Robot
97c6f3c0c0 Merge "Remove IPermissionManager usage inside PackageManagerService." 2021-01-07 00:18:54 +00:00
Eugene Susla
2959fa471a Introduce API to get CDM profile permissions description string
Bug: 165951651
Test: presubmit
Change-Id: Ic59f7a70f0a1b8b53510fc313e0e3e2155cd3b31
2021-01-06 11:59:41 -08:00
Nate Myren
f88fbe5128 Merge "Add most basic aspects of permission usage to PermissionManager" 2021-01-06 19:58:25 +00:00
Hai Zhang
a0d2826aa8 Remove IPermissionManager usage inside PackageManagerService.
Because we are moving permission into mainline and AIDL can't be an
API.

Most usages are replaced with calling through PermissionManager
instead.

For checkPermission() and checkUidPermission(), they are not intended
to be exposed as cross-process APIs because people should use
Context.check*Permission() instead. So they are made in-process APIs.

resetRuntimePermissions() is moved to IPackageManager because it is
only used by PackageManagerShellCommand and is implemented by calling
resetRuntimePermissions() in a loop.

Bug: 158736025
Test: presubmit
Change-Id: I8285abddbfb3c4011a8acbc2e2ebfc30715c6f9a
2020-12-21 15:55:10 -08:00
Hai Zhang
226c6ccb96 Use allowlist in permission internally.
Now that our new APIs are named properly, clean up our naming
internally as well.

Bug: 158736025
Test: presubmit
Change-Id: If70f8b012dec2d4f80e7fa1d36c47f6fbe370e81
2020-12-17 19:13:24 -08:00
Nate Myren
32c2514a9d Add most basic aspects of permission usage to PermissionManager
Add the basic API for getting permission usage for mic, camera, and
location. Does not use special attribution yet. Mostly untested

Bug: 172868375
Test: Basic manual tests
Change-Id: Icb268b820557d62125e9307d6ffcf7046ab9b490
2020-12-16 08:40:09 -08:00
Hai Zhang
65404d6c66 Move permission methods in PackageManager to PermissionManager.
A number of permission-related methods were implemented in
ApplicationPackageManager by calling the IPermissionManager AIDL
interface. However since we are moving permission into module, the
AIDL inteface can't be an API and the implementions must be moved.

This change moves these methods into PermissionManager, with the
javadoc and interface from PackageManager and the implementation from
AppliationManager. The javadoc remains mostly the same except for
style and typo fixes. The API interface also remains the same except
for inclusive language changes since we are defining new one and have
a chance to fix them now.

We have to lazily get the PermissionManager instance because the
context passed in may be null for an instrumentation use case.

Bug: 158736025
Test: presubmit
Change-Id: I1c28433ca6200679a41e3518354fe03b866621b5
2020-12-10 16:19:05 -08:00
Hai Zhang
e7d707ceb0 Move a subset of PermissionManager APIs into LegacyPermissionManager.
And move their implementation from PermissionManagerService to
LegacyPermissionService.

The DefaultPermissionGrantPolicy related methods are not APIs, and
are thus moved to LegacyPermissionManager and their usages are updated
to use LegacyPermissionManager.

The checkDeviceIdentifierAccess() method is also moved into
LegacyPermissionManager, because it's merely an application of
permission checking, not the permission management infra itself, and
there isn't great benefit in updating it. However since it is an API,
we still have to keep a delegate for it on PermissionManager, and make
the delegated method @SystemApi.

Bug: 158736025
Test: presubmit
Test: LegacyPermissionManagerServiceTest
Change-Id: Ic838f3685427217c8e0477551c3373258408983f
2020-12-10 16:19:01 -08:00
Jeff Sharkey
0ab7007631 resolve merge conflicts of 358f0d4fc8 to master
Bug: 174932174
Test: I solemnly swear I tested this conflict resolution.
Exempt-From-Owner-Approval: refactoring with team leads buy-in
Change-Id: I9262a08ffc1ccede8e519d0eed90ed2bfcf0232c
2020-12-08 11:01:05 -07:00
Jeff Sharkey
c7c4a74a78 Improve OWNERS coverage across frameworks/base/. am: fab0ab3c9c
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1519383

MUST ONLY BE SUBMITTED BY AUTOMERGER

Change-Id: I0211462ecbcd9ad66f66af87e31cf12e1582fc65
2020-12-08 16:01:16 +00:00
Jeff Sharkey
fab0ab3c9c Improve OWNERS coverage across frameworks/base/.
As general background, OWNERS files expedite code reviews by helping
code authors quickly find relevant reviewers, and they also ensure
that stakeholders are involved in code changes in their areas.

Some teams under frameworks/base/ have been using OWNERS files
successfully for many years, and we're ready to expand them to cover
more areas.  Here's the historical coverage statistics for the last
two years of changes before these new OWNERS changes land:

-- 56% of changes are fully covered by OWNERS
-- 17% of changes are partially covered by OWNERS
-- 25% of changes have no OWNERS coverage

Working closely with team leads, we've now identified clear OWNERS on
a per-package basis, and we're using "include" directives whenever
possible to to simplify future maintenance.  With this extensive
effort, we've now improved our coverage as follows:

-- 98% of changes are fully covered by OWNERS
-- 1% of changes are partially covered by OWNERS
-- 1% of changes have no OWNERS coverage

This specific change is automatically generated by a script from
detailed ownership information confirmed by team leads.

Bug: 174932174
Test: manual
Exempt-From-Owner-Approval: refactoring with team leads buy-in
Merged-In: I9789c97c1de8e5d962b48c29c57d82fe83729eba
Change-Id: I9789c97c1de8e5d962b48c29c57d82fe83729eba
2020-12-08 08:36:27 -07:00
Hai Zhang
a23b25cd1a Remove obsolete is/setPermissionEnforced().
isPermissionEnforced() always returns true and is only exposed on AIDL
and there is actually no API, so it is directly removed.
setPermissionEnforced() currently doesn't affect anything so its
remaining implementation is removed as well, and we consider all
permissions enforced when needed for compatibility of dumping.

Bug: 158736025
Test: presubmit
Change-Id: I0584553ac0171147b6f131b5359ddb2964113a1d
2020-12-04 23:06:02 -08:00
Hai Zhang
93e38c9566 Move or refactor PermissionManagerInternal APIs.
Make the three backup related methods in PermissionManagerInternal
ready for system API. PermissionManagerInternal is currently used in
framework so it can't be removed without other changes yet. The other
listener methods are only used by PermissionPolicyService and will
become module internal.

Finally turn PermissionManagerInternal and
PermissionManagerServiceInternal into an interface from an abstract
class, and remove redundant modifiers after this.

Also refactors onUserCreated/Removed() to be system API ready.

Bug: 158736025
Test: presubmit
Change-Id: I335a7a37b737f6fa0faf0a2c34634d44199aee97
2020-12-04 23:05:59 -08:00
Hai Zhang
1ca9409dbc Move CheckPermissionDelegate API into PermissionManagerServiceInternal.
Expose only start/stopShellPermissionIdentityDelegation() as API,
because there won't be a use case for UIDs other than the shell UID.

The caller checking is left in ActivityManagerService because only it
knows info about the ongoing intrumentations. So this new system
server API only delegates the permission identity of Shell to someone
else, but checking who can start the delegation to whom is the
responsibility of other parts of the system.

For now the API only delegates permissions checks since app ops won't
be updatable in this release, and it is a platform implementation
detail that ActivityManagerService also delegates app op checks via
the in platform AppOpsService interface at the same time. Once we
complete moving AppOpsService, this API will start delegating for app
ops (or whatever it will become) as well, and then the platform code
can just drop the app op related code and call this API only. Platform
code will have to drop those app op related code by then anyway since
the internal app op interface will no longer be available after the
move.

Bug: 158736025
Test: presubmit
Change-Id: I42839dacdf06e4d94682a46a0e692119de0bfdc0
2020-12-03 17:28:33 -08:00
Hai Zhang
9c0907c3b5 Move default app related methods to role manager.
Default apps (browser, dialer and home) are by no means a concept of
permission, so they should not be exposed as permission
manager API. Instead, they should be accessed via role manager API.

This change moves getDefaultBrowser() and setDefaultBrowser()'s AIDL
interface and implementation into RoleManagerService. Package manager
has a number of special behaviors regarding these default apps, so we
can not pretend that package manager doesn't know about these
roles. After all, we can say permission and role are at the same level
in the system after recent refactoring that split permission and
package. So package manager is reusing the public role API now.

The new methods moved to RoleManagerService needs to be system APIs on
RoleManager, because IRoleManager cannot be a system API and we need
to delegate method calls to it from ApplicationPackageManager.

The other methods directly calling into DefaultPermissionGrantPolicy
should be moved/refactored as well, depending on whether we want to
mainline it, in a later change.

Bug: 158736025
Test: presubmit
Change-Id: I84b9519a084e410875a3c3e88b33e9a612e7de98
2020-12-03 17:28:27 -08:00
Xin Li
d31ee38811 Merge rvc-qpr-dev-plus-aosp-without-vendor@6881855
Bug: 172690556
Merged-In: I78222391b83a4add8e964340ec08bb8a1306e1c6
Change-Id: I28bbf40820674675ccf765c912aa8140d3f74ab2
2020-12-02 00:38:58 -08:00
Hai Zhang
65d46e9b05 Refactor getAppOpPermissionPackages() as API.
- Remove IPermissionManager.getAppOpPermissionPackages() and its usage
  because we are not going to expose it as a new API on
  PermissionManager.

- Make PermissionManagerServiceInternal.getAppOpPermissionPackages()
  unchecked because it's an internal API. Internal APIs should be by
  default unchecked and checks should be done manually when
  necessary.

- The parameters and return value of
  PermissionManagerServiceInternal.getAppOpPermissionPackages() are
  also made non-null to be a good API, and EmptyArray.STRING is
  returned in the empty case so there won't be a performance penalty.
  IPackageManager.getAppOpPermissionPackages() will return an empty
  array for null permissionName before calling
  PermissionManagerServiceInternal.getAppOpPermissionPackages() for
  compatibility, and clients should handle returned empty arrays as
  good as null.

- Use PermissionManagerServiceInternal.getAppOpPermissionPackages()
  only to support the @UnsupportedAppUsage of
  IPackageManager.getAppOpPermissionPackages() and perform checks
  there.

Bug: 158736025
Test: presubmit
Change-Id: I0f96e898daa4cf40706430f1b7fbd5737a1f97f8
2020-11-12 17:07:26 -08:00
TreeHugger Robot
05e768ced6 Merge "Do not allow to install S+ apps with cross cert permissions" 2020-10-22 00:14:32 +00:00
Philip P. Moltmann
22d2486c1f Do not allow to install S+ apps with cross cert permissions
I.e. permissions and permission groups should stay inside a cert-group
so that there cannot be accidential security bugs in apps.

Test: atest CtsPermissionTestCases
            CtsPermission2TestCases
	    CtsAppSecurityHostTestCases
Fixes: 146211400 (No backport possible, all changes are for S+ apps
only)
Change-Id: I19c2f3e216ea57a9e25c65e276f87425aeb1c038
2020-10-21 18:58:16 +00:00