IInputMethodManager#isInputMethodPickerShownForTest() was introduced
in Android P (API 28) to verify IME picker visibility in CTS [1].
To make it clear that that IPC method must be available only for
special testing purpose, this CL introduces an @hide permission
android.permission.TEST_INPUT_METHOD
and requires it in
InputMethodManagerService#isInputMethodPickerShownForTest().
This CL grants that permission to the shell process hence CTS tests
can still access to the corresponding test API by using
UiAutomation#adoptShellPermissionIdentity().
[1]: I4e21625c32a0ca1abc740229efb3c7fcd97141cc
eb5706183f
Bug: 237317525
Test: atest CtsInputMethodTestCases
Test: Manually verified as follows.
1. adb logcat -b events | grep 237317525
2. atest CtsInputMethodTestCases:InputMethodManagerTest#testIsInputMethodPickerShownProtection
Ignore-AOSP-First: For a security fix
Change-Id: Ie79a3e9d41ce22605ae083594d639c37d08b7def
Add a Y2038 check into the time_detector and add infrastructure to allow
command-line testing to confirm it works.
This is before removing a Y2038 check from NITZ parsing code in the
telephony process. After this change, Androdi will consistently block
>= Y2038 suggestions, not just time signals that come in via telephony.
The initial checks attempt to limit the restriction to devices with
32-bit ABIs, since the main issue we're aware of is that time_t is a
32-bit signed int under bionic, hence there could be issues with that
type in 32-bit processes on 32-bit / mixed 32/64-bit devices.
Bug: 204193177
Test: adb shell cmd time_detector suggest_network_time --reference_time 2480587 --unix_epoch_time 1646473966056
Test: Run with 32-bit + 64-bit only builds, inspect adb shell dumpsys time_detector
Merged-In: Ib9d6472f5ca7a62d59b3224f1845846f99a0b52d
Change-Id: Ib9d6472f5ca7a62d59b3224f1845846f99a0b52d
Add a Y2038 check into the time_detector and add infrastructure to allow
command-line testing to confirm it works.
This is before removing a Y2038 check from NITZ parsing code in the
telephony process. After this change, Androdi will consistently block
>= Y2038 suggestions, not just time signals that come in via telephony.
The initial checks attempt to limit the restriction to devices with
32-bit ABIs, since the main issue we're aware of is that time_t is a
32-bit signed int under bionic, hence there could be issues with that
type in 32-bit processes on 32-bit / mixed 32/64-bit devices.
Bug: 204193177
Test: adb shell cmd time_detector suggest_network_time --reference_time 2480587 --unix_epoch_time 1646473966056
Test: Run with 32-bit + 64-bit only builds, inspect adb shell dumpsys time_detector
Ignore-AOSP-First: The change will be cherry-picked upstream
Change-Id: Ib9d6472f5ca7a62d59b3224f1845846f99a0b52d
The permission allows a package to create a protected VM with custom
config. It's used by MicrodroidHostTestCases.
Bug: 207769805
Test: atest MicrodroidHostTestCases
Change-Id: If049d26c0ef97695098979c4a36fe1f7f607af5a
This permission will eventually replace the sepolicy that we have now,
making it possible to test unique id attestation, which is no longer
possible due to the deprecation of shared uids.
Skipping automerger because the framework manifest has diverged too
much across aosp and tm-dev to allow for clean auto merges, and
presubmits block.
Test: KeyAttestationTest
Bug: 216778747
Ignore-AOSP-First: "do not merge" blocked automerging -- pick to master
Merged-In: Iecde35b9a79456b293118d8089dd2a3b0905f5f3
Change-Id: Iecde35b9a79456b293118d8089dd2a3b0905f5f3
Bug: 217224856
Test: atest android.devicepolicy.cts.NearbyAppStreamingPolicyTest && atest android.devicepolicy.cts.NearbyNotificationStreamingPolicyTest
Ignore-AOSP-First: This new permission is part of a T-targeting feature
Change-Id: I303549d4f9fcf639da3d4981a8887c3ba55434fc
This permission will eventually replace the sepolicy that we have now,
making it possible to test unique id attestation, which is no longer
possible due to the deprecation of shared uids.
Skipping automerger because the framework manifest has diverged too
much across aosp and tm-dev to allow for clean auto merges, and
presubmits block.
Test: KeyAttestationTest
Bug: 216778747
Merged-In: Iecde35b9a79456b293118d8089dd2a3b0905f5f3
Change-Id: Iecde35b9a79456b293118d8089dd2a3b0905f5f3
Add ACCESS_FPS_COUNTER to Shell in order to run CTS properly.
Ignore-AOSP-First: permission doesn't exist in AOSP yet.
Bug: b/220029298
Test: atest TaskFpsCallbackCtsTest
Test: atest TaskFpsCallbackCtsTest --instant
Change-Id: Ica37bafff368f4a0027f9549de6a31ce3254c986
Add android.permission.SUGGEST_TELEPHONY_TIME_AND_ZONE to the shell
process to enable command-line injection of time zone suggestions to the
time_zone_detector service.
Shell already has permissions like SET_TIME_ZONE that allow the time
zone to be set directly, so this is not a security regression.
Bug: 227337462
Test: adb shell cmd time_zone_detector suggest_telephony_time_zone --slot_index 0 --zone_id Europe/London --quality single --match_type country
Merged-In: I377cab85a1b39ef2887b452d1ffcdc5b00a8d5ab
Change-Id: I377cab85a1b39ef2887b452d1ffcdc5b00a8d5ab
Add android.permission.SUGGEST_TELEPHONY_TIME_AND_ZONE to the shell
process to enable command-line injection of time zone suggestions to the
time_zone_detector service.
Shell already has permissions like SET_TIME_ZONE that allow the time
zone to be set directly, so this is not a security regression.
Bug: 227337462
Test: adb shell cmd time_zone_detector suggest_telephony_time_zone --slot_index 0 --zone_id Europe/London --quality single --match_type country
Ignore-AOSP-First: Merge conflict, AOSP cherry-pick will land after
Change-Id: I377cab85a1b39ef2887b452d1ffcdc5b00a8d5ab
This permission will eventually replace the sepolicy that we have now,
making it possible to test unique id attestation, which is no longer
possible due to the deprecation of shared uids.
Skipping automerger because the framework manifest has diverged too
much across aosp and tm-dev to allow for clean auto merges, and
presubmits block.
Test: KeyAttestationTest
Bug: 216778747
Change-Id: Iecde35b9a79456b293118d8089dd2a3b0905f5f3
In remote bugreport collection, Shell sends REMOTE_BUGREPORT_DISPATCH to
DevicePolicyManagerService which in turn notifies Device Owners that a
bug report is ready for collection. There existed a threat where a
malicous user could spoof the REMOTE_BUGREPORT_DISPATCH broadcast via
ADB to send a crafted bugreport to the Device Owner. Securing
REMOTE_BUGREPORT_DISPATCH is not as easy as it appears: putting a
permission on REMOTE_BUGREPORT_DISPATCH does not work since both the
legitimate sender and the malicious user are UID_SHELL. Instead, we
introduces a nonce which was sent from DPMS to Shell when bugreport is
triggered, and DPM will only accept REMOTE_BUGREPORT_DISPATCH when
a matching nonce is seen.
Ignore-AOSP-First: security fix
Bug: 171495100
Test: atest DeviceOwnerTest#testRemoteBugreportWithTwoUsers
Test: atest DeviceOwnerTest#testAdminActionBookkeeping
Test: atest BugreportManagerTest
Change-Id: I7649b4f22b74647d152d76bb46d5ca70bfa3617d
Merged-In: I7649b4f22b74647d152d76bb46d5ca70bfa3617d
(cherry picked from commit a4131c50d0)
Changes:
* Use TRIGGER_LOST_MODE permission to gate the
DevicePolicyManager API sendLostModeLocationUpdate
Bug: 223148704
Test: atest android.devicepolicy.cts.LostModeLocationTest
Change-Id: If15388a377c75b7581c9c2a35b3d9828f78e13fc
Merged-In: If15388a377c75b7581c9c2a35b3d9828f78e13fc