Commit Graph

287 Commits

Author SHA1 Message Date
Treehugger Robot
60483bba5f Merge "Update permission OWNERS." am: 97f0cbd96f am: 100a1fe7ac am: 29eef47cb1 am: 9ffc872ad2 am: aa232f8cfd
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/2144379

Change-Id: I28bed132f8fa4ec63090e2edf84a98454fb30a70
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-12 23:18:48 +00:00
Treehugger Robot
100a1fe7ac Merge "Update permission OWNERS." am: 97f0cbd96f
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/2144379

Change-Id: Ic8fde8feea7530b2316d2b3c10aff4d9eddce9e9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-07-12 21:38:32 +00:00
mattgilbride
f48d794e01 @EnforcePermission migrations - services.core
Immediate calls to Context.enforceCallingPermission.  Fixes
applied by Android Lint (ag/18432857).

Bug: 232058525
Test: N/A
Change-Id: Id9bdeb71e84962d55fd1657e91856d84e1c3d11b
2022-07-11 20:01:27 +00:00
Hai Zhang
d60bbb6481 Update permission OWNERS.
Change-Id: I3bf638ecff9b59c27ad3dc1acce1e187230886f4
Test: presubmit
2022-07-06 18:17:41 +00:00
Nate Myren
4d8c0a4a21 Merge "Note RECEIVE_AMBIENT_TRIGGER_AUDIO in the SoundTrigger" into tm-dev am: 7a9cf44cfe am: 3cd4e021a7
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/18175784

Change-Id: Iee8e7495087825443c60f79834ea3b248a1dc983
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-12 00:37:11 +00:00
Nate Myren
454a68f49f Merge "Note RECEIVE_AMBIENT_TRIGGER_AUDIO in the SoundTrigger" into tm-dev am: 7a9cf44cfe
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/18175784

Change-Id: I85128605c9a6caebd207076e0fd1c9037eba8747
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-11 23:03:49 +00:00
Nate Myren
7a9cf44cfe Merge "Note RECEIVE_AMBIENT_TRIGGER_AUDIO in the SoundTrigger" into tm-dev 2022-05-11 22:00:35 +00:00
Kevin Han
c627ac5d24 Merge "Actually use the passed-in executor for unused count" into tm-dev am: 869e4d4fff am: dcf1841747
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/18283296

Change-Id: I911ae565f3a7c63512691bd3b2ec6f1a7cfdd18d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-11 04:08:25 +00:00
Kevin Han
590c8092e1 Merge "Actually use the passed-in executor for unused count" into tm-dev am: 869e4d4fff
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/18283296

Change-Id: I091af7269d6e68d635abdeb06f7b8e97276b0467
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-11 03:26:08 +00:00
Kevin Han
3ac4fac928 Actually use the passed-in executor for unused count
Use the passed in executor for getUnusedCount so that the work is
actually handled on the main executor.

Bug: 231931350
Test: bug repro steps
Change-Id: I7c97e1e6d55457662920a3a15a5605324dd7963f
2022-05-10 10:42:52 -07:00
Nate Myren
bd934eba0f Note RECEIVE_AMBIENT_TRIGGER_AUDIO in the SoundTrigger
This op gets around the background restrictions on RECORD_AUDIO, when
used for SoundTrigger detection
In addition, moves the precise logic for soundtrigger RECORD_AUDIO
checks out of the soundtrigger system

Fixes: 230430779
Test: manual
Change-Id: I6d63c99e2d31e3f668070ac82afed71ff6672c9e
Merged-In: I6d63c99e2d31e3f668070ac82afed71ff6672c9e
2022-05-09 23:35:37 +00:00
Ganesh Olekar
2543ef01eb Merge "Update owners for Permissions & Privacy" am: bde2853623 am: 92b54153a6 am: f151113776 am: 583b36eece am: 0db84223cd
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/2078300

Change-Id: I726cf44790d59cadc82172c7f46cdaa2a70bc6cc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-02 11:23:09 +00:00
Ganesh Olekar
f151113776 Merge "Update owners for Permissions & Privacy" am: bde2853623 am: 92b54153a6
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/2078300

Change-Id: Ie759ae2f328a94a921ed29732d026b9c67359ee5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-29 19:48:00 +00:00
Nate Myren
1521f4d558 Merge "Grant Notifications to Carrier Provisioning App" into tm-dev am: 0a6c6f8d01 am: 0bd0e4e8c8
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/17697690

Change-Id: I18967deac726a95e68875f1fb139767f57e7214c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-04-29 18:33:11 +00:00
Ganesh Olekar
4925ac514e Update owners for Permissions & Privacy
Change-Id: I6969331309fa9908c2fd9bfc4762c58d7dcc9a2a
2022-04-27 23:14:42 +00:00
Nate Myren
a805c6f522 Grant Notifications to Carrier Provisioning App
When the set of carrier privileged apps changes on the device, grant the
Carrier Provisioning app POST_NOTIFICATIONS

Fixes: 226201376
Test: atest DefaultPermissionGrantPolicyTest
Change-Id: I5ff732823404bd48eed076c32485331cf6efd797
2022-04-27 16:58:52 +00:00
Presubmit Automerger Backend
e8abd68613 [automerge] Fix printing duplicate logs to save on battery 2p: efdf00bff9 2p: 70916e87f9
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/17411804

Bug: 202092164
Change-Id: I56243e9400b3b244489b24ab6cde09c6e3b6243f
2022-03-26 12:06:34 +00:00
Manjeet Rulhania
efdf00bff9 Fix printing duplicate logs to save on battery
Adding state to remember if a log for missing activity manager
is already printed or not.

Bug: 202092164
Test: Manual
Change-Id: Ia945a7396d06f7e8a3fc12359583970faed06a72
2022-03-26 12:05:34 +00:00
TreeHugger Robot
0f009b5e69 Merge "Add conditional permission check annotation to checkPermission methods" into tm-dev am: 97d6cf4abe
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/17299168

Change-Id: I566c2c735e645f3ac0ef2de1de2cafbc92d246be
2022-03-22 00:16:53 +00:00
Nate Myren
e0ae12756c Add conditional permission check annotation to checkPermission methods
Per API council feedback, reflect that the first app in an
AttributionSource chain must have UPDATE_APP_OPS_STATS to do a trusted
blame

Fixes: 222094627
Test: build
Change-Id: I63513ca70ddebe0fd5a05d4414f88985bc3fcad4
2022-03-21 21:16:15 +00:00
Ganesh Olekar
6f73905cf6 Merge "Location provider check for subattribution" into tm-dev 2022-03-17 23:40:32 +00:00
Ganesh Olekar
7f13dcaadf Location provider check for subattribution
Bug: 200280741
Test: atest com.android.systemui.privacy.PrivacyDialogTest
Change-Id: I7240db08025d801eb537234ca95aeb17c3f302f2
Merged-In: I7240db08025d801eb537234ca95aeb17c3f302f2
2022-03-17 20:32:19 +00:00
Thomas Vannet
cede13a039 Merge changes from topics "cherrypick-selfrevokemultiuser-emqfc1tlui", "cherrypick-selfrevokerenameself-lcm1yyzp8i", "presubmit-am-8a6e07e400554464bf71e06db20e4f32", "presubmit-am-d66e407983c84f0f90928a76de0d3ef2" into tm-dev am: ac4406b453
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/17226523

Change-Id: Iff3d9cbd726a2558b0de06b9bd00f7f77c9de5fe
2022-03-17 14:54:27 +00:00
Thomas Vannet
c418be3814 Rename revokeOwnPermissionsOnKill to revokeSelfPermissionsOnKill
Bug: 215555831
Test: atest android.permission.cts.RevokeSelfPermissionTest
Change-Id: I887e2b8a86868352e772537addd8cd20ef305d7b
2022-03-16 16:39:59 -07:00
Thomas Vannet
a24e244560 Self-revocation: Call PermissionControllerManager directly from Context
This fixes a bug where self-revocation didn't work in multi-user
settings. Now the correct context is used throughout the call stack and
the permission for the calling user will be revoked.

Also added a checked IllegalArgumentException (previously unchecked
SecurityException) when trying to revoke a permission that is not
currently granted.

Test: manual using two users and
atest android.permission.cts.RevokeOwnPermissionTest
Bug: 218788609

Change-Id: I3dce34b8b956b4d1eb0ac1e34b6fdbf1795aa269
2022-03-16 16:35:59 -07:00
Ganesh Olekar
66314d5073 Merge "Location provider check for subattribution" 2022-03-15 17:34:14 +00:00
Hai Zhang
72c75135b2 Add documentation for permission protection level.
Clarify the difference between protection and protection flags, which
has been a source of confusion for multiple teams. Also added
documentation about the `internal` protection.

Test: presubmit
Change-Id: I72d1a9b5030eabdabecff3983cf299d469dd9910
2022-03-07 22:34:24 +00:00
Ganesh Olekar
578b661b34 Location provider check for subattribution
Bug: 200280741
Test: atest com.android.systemui.privacy.PrivacyDialogTest
Change-Id: I7240db08025d801eb537234ca95aeb17c3f302f2
2022-02-19 16:59:42 +00:00
Ganesh Olekar
bc545518e2 Merge "Add attribution to PermGroupUsage and indicators" 2022-02-17 18:20:39 +00:00
Ganesh Olekar
b5ccbc33ed Add attribution to PermGroupUsage and indicators
Bug: 200280741
Test: atest com.android.systemui.privacy.PrivacyDialogTest
Change-Id: I1dcd7bea997605f3caaac742419476f4e0ac2fdf
CTS-Coverage-Bug: 220157796
2022-02-17 18:17:18 +00:00
Nate Myren
86d226366a Add information to grant permissions intent for continue messages
After first launch, remember T+ apps which had the review required flag
cleared on launch, until a grant permission request comes in.

Also modifies some behavior of the upgrade code grants.

Bug: 194833441
Test: atest NotificationPermissionTest
Change-Id: Iafef8348e6cdb05fb214382b945cc7886beaff4b
2022-02-09 10:01:26 -08:00
Thomas Vannet
8b2f6ecf8a Update self-revocation doc: revoke by permission, not group
Test: None, this is just a doc update
Bug: 210387494
Change-Id: Ib6555c9c419e2f5b890d31c249f09207632d7724
2022-02-03 15:46:12 -08:00
Thomas Vannet
9346e5338a Add killed delay param to startOneTimePermissionSession
This param controls how long to wait before revoking permission after
every process has been killed.
Deprecate previous API and update all known uses of the deprecated API.
Use updated API for self-revocation feature.
If multiple one-time permission sessions are started for the same
package with different parameters, always use the shortest parameters.

Test: atest android.permission.cts.RevokeOwnPermissionTest,
atest android.permission.cts.OneTimePermissionTest
Bug: 210387494

Change-Id: I0c0e21b3b48dd31f0c267d5c8b89336714835289
2022-02-03 15:46:12 -08:00
Nate Myren
e5d2351829 Merge "create systemApi checkPermissionForStartDataDelivery in PermissionManager" 2022-01-25 18:09:06 +00:00
Kevin Han
19166cb1fc Add API to get hibernation eligibility
Add an API to get a package's eligibility for hibernation for a given
user. A package is either eligible, exempt by the system, or exempt by
the user.

This information can be used to show more accurate UI for hibernation
controls (e.g. disabling the user-controlled exemption toggle if the app
is already exempt by the system)

Bug: 200087723
Test: CTS test in topic
Change-Id: Iea844477184fadb55ea14485dff172ed7be2b715
2022-01-21 13:31:06 -08:00
Thomas Vannet
f331c8f585 Immediately revoke permission on process kill after a self-revocation
Test: atest android.permission.cts.RevokeOwnPermissionTest
Bug: 210387494
Change-Id: Iaa3a4c00847d5411c5b829d190eba8231d046d8c
2022-01-21 05:51:05 +00:00
Thomas Vannet
395f8deeff Rename selfRevokePermissions to revokeOwnPermissionsOnKill
Test: atest android.permission.cts.RevokeOwnPermissionTest
Bug: 215555831
Bug: 210575642
Bug: 210387494
Change-Id: I94e29f66d13ac76669fab2ccc08879c30c26b7ea
2022-01-21 05:50:22 +00:00
Thomas Vannet
af615e7baf Add self revocation public API
Test: Manual test using a non-privileged app, atest
android.permission.cts.SelfRevokeRuntimePermissionTest

When calling the API, the permission (along with any other permissions
from the same group) for the current package is downgraded to a one-time
permission, and a one-time permission session is started.

Bug: 210387494

Change-Id: I9f061cbc8c3db720127c96200fe94a644246b6d7
2022-01-11 16:32:40 -08:00
Nate Myren
7d095bbc0b create systemApi checkPermissionForStartDataDelivery in PermissionManager
This allows us to check attribution for started ops in tests, and support
starting in system apps

Test: atest CameraMicIndicatorsPermissionTest
Bug: 212434116
Change-Id: Iacdf1d339588cd680c20b3fb55ada9cedb2e70b0
2022-01-10 22:01:34 +00:00
Nate Myren
2c54f50da6 Allow shell to revoke notification permission without kill
Add the revokePostNotificationPermissionWithoutKillForTest API, which
will allow the shell to revoke the POST_NOTIFICATIONS permission without
killing this app. Gate this permission behind the
REVOKE_POST_NOTIFICATIONS_WITHOUT_KILL permission, which is
signature|privileged, accessible only to the shell.

Ignore-AOSP-First: Contains information about unreleased features
Test: manual
Bug: 194833441
Change-Id: I3177d1aeb338591c1d736aa6b4f073b6db6227e7
2022-01-10 11:58:45 -08:00
Lee Shombert
9a686c07ba Merge "Prepare PropertyInvalidatedCache for SystemApi" 2022-01-06 23:14:05 +00:00
Kevin Han
8c7b307f03 Merge "Add unused count API" 2022-01-06 01:24:26 +00:00
Jordan Jozwiak
a5ca465453 Merge "Intent action to review permission decisions" 2022-01-05 17:25:01 +00:00
Nate Myren
590d4a4e13 Merge "Ensure only microphone attribution chains are recorded" into sc-v2-dev am: 5a1d0103e4
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/16562077

Change-Id: I9ee7979039e38a3b63c9d9a835542a7a291797eb
2022-01-05 00:03:17 +00:00
Nate Myren
91abbb1669 Ensure only microphone attribution chains are recorded
Also ensure each chain is attributed to only one op

Test: manual
Fixes: 212434116
Change-Id: I50efc2b305627f8e37eb28842487b911dce5d925
(cherry picked from commit 33c3c1a629)
Merged-In: I50efc2b305627f8e37eb28842487b911dce5d925
2022-01-04 21:11:19 +00:00
Nate Myren
96f8c9fd10 Merge "Ensure only microphone attribution chains are recorded" 2022-01-04 17:04:27 +00:00
Lee Shombert
0cece3898b Prepare PropertyInvalidatedCache for SystemApi
Bug: 152453213
Tag: #refactor

This commit prepares PropertyInvalidatedCache to function as a system
api.  Specifically, the methods recompute() and bypass() which may be
overridden by clients are now public (instead of protected).  This
forces an update to all existing clients, to accommodate the change in
method visibility.

Two small changes have been made as cleanup:

 1. The awkwardly named debugCompareQueryResults() is now
    resultEquals(), which is more or less consistent with how other
    equality tests are named in Android.  This name change affects two
    clients.

 2. PackageManager has changed to use resultEquals() instead of
    maybeCheckConsistency().  This provides a simpler and more
    consistent use of the APIs.  maybeCheckConsistency() has been made
    private.

Test: atest PropertyInvalidatedCacheTests

Change-Id: I4110f8e887a4fd8c784141e8892557a9d1b80a94
2022-01-04 08:13:59 -08:00
William Escande
6b436464d2 Javadoc on Method from api review
Add some specific info on checkPermissionForDataDeliveryFromDataSource
javadoc.
Fix: 204179567
Bug: 195144968
Test: build (it's only javadoc)

Change-Id: I6d4e5b9e06bf990b5e40eb727259dc79753d5eef
2022-01-03 12:08:51 +01:00
Nate Myren
33c3c1a629 Ensure only microphone attribution chains are recorded
Also ensure each chain is attributed to only one op

Test: manual
Fixes: 212434116
Change-Id: I50efc2b305627f8e37eb28842487b911dce5d925
2021-12-29 11:36:49 -08:00
Jordan Jozwiak
70b59c872d Intent action to review permission decisions
Action will open the PermissionController screen to review recent
permission decisions. Currently only supported on Auto.

Bug: 194240664
Test: adb shell am start -a android.permission.action.REVIEW_PERMISSION_DECISIONS
Change-Id: Ic37e0b69632d38596b707cd7b1a17fbb89bfa547
2021-12-22 13:13:46 -08:00