This method is no longer needed as b/225435110 has
addressed the cache issues.
Bug: 238591450
Test: StagedInstallInternalTest#testApkInApexPruneCache
Change-Id: I7829b3ce95ce6723d8166e30ffc73a0b3b60e0f0
Bug: 235635119
Test: atest FrameworksCoreTests:BatteryStatsTests
Test: atest FrameworksServicesTests:BatteryStatsTests
Test: atest BatteryUsageStatsProtoTests:BatteryUsageStatsPulledTest
NoNonSdkCheck: BatteryStatsImpl is being permanently moved to a different package. All data available via these hidden API is also available in dumpsys.
Change-Id: I39be1c66c23f43d339f9076c6b87902f6ef35967
- To fix apis which invoke the #filterAppAccess leak the package
existence information of other users, this CL returns true if
the target package is not installed under the given user id.
- Add an extra boolean parameter to the #filterAppAccess API for
the LauncherApp module to not filter the uninstalled package
when monitoring package changes events.
- Correct wrong user id usages of the filterAppAccess API in
some modules.
Bug: 229684723
Test: atest android.content.pm.cts.PackageManagerTest
Test: atest android.appenumeration.cts.AppEnumerationTests
Test: atest android.appwidget.cts.AppWidgetTest
Test: atest com.android.cts.devicepolicy.ManagedProfileCrossProfileTest
Test: atest com.android.cts.devicepolicy.LauncherAppsProfileTest
Test: atest android.devicepolicy.cts.LauncherAppsTests
Change-Id: I3cced4668d1cc4488665c928e4cbe4e194c249cf
* changes:
Using isUidPrivileged instead of getPrivateFlagsForUid API
Add package manager internal api checkUidSignaturesForAllUsers
Fix cross user package visibility leakage for PackageManager (6/n)
Sending broadcasts are not restricted by the package visibility of the
calling package. This is achieved by clearing the Binder calling
identity in several top-level broadcast sending APIs.
ag/15315839 introduced intent filter matching enforcement, which
requires the real calling UID to be used for evaluation. This caused
regression in broadcast package visibility.
Test: manual
Bug: 230363029
Change-Id: I6bf34fe22aa9396786e3bbbfe64094474c34b6df
Changed how protected packages are stored in package manager:
* previously they were stored in a map from DO package into
a list of protected packages. This isn't expressive enough
to allow POs: the same PO package on different users may
protect different packages.
* now they are stored in a map from userId into a list of
protected packages. In case when the DO sets the policy
the userId will be UserHandle.USER_ALL, otherwise it will
be the calling user.
Bug: 218639412
Test: atest UserControlDisabledPackagesTest
Change-Id: I2d1d33acad035610c8db365f69b7a15faa03a2d5
Merged-In: I2d1d33acad035610c8db365f69b7a15faa03a2d5
Changed how protected packages are stored in package manager:
* previously they were stored in a map from DO package into
a list of protected packages. This isn't expressive enough
to allow POs: the same PO package on different users may
protect different packages.
* now they are stored in a map from userId into a list of
protected packages. In case when the DO sets the policy
the userId will be UserHandle.USER_ALL, otherwise it will
be the calling user.
Bug: 218639412
Test: atest UserControlDisabledPackagesTest
Change-Id: I2d1d33acad035610c8db365f69b7a15faa03a2d5
Starting from U, the PackageManager#checkUidSignatures does not
support to check package signatures for different users. It
returns false if packages cannot be found in the calling user.
This cl adds an internal api checkUidSignaturesForAllUsers for
system modules that need to check package signatures installed
in any users.
Bug: 229684723
Test: atest BlobStoreMultiUserTest
Change-Id: Ib5b3c25dcafe664b31bd737bdb2718c045f845b4
Now the check is in PackageSessionVerifier for both staged and
non-staged APEX. This ensures a consistent behavior between
staged and non-staged APEX when it comes to signature checking.
* Remove the dependency on ApexPackageInfo from ApexManager
which helps us migrate from ApexPackageInfo.
* Performance slightly improved (measured on Pixel4a) for
APEX signature checking:
shim APEX: 13-16ms -> 10-13ms
com.android.art: 340-355ms -> 160-180ms
com.android.cellbroadcast: 165-180ms -> 79-85ms
This is because the SigningDetails of the install session is
reused without re-calculation.
Bug: 225756739
Test: atest CtsStagedInstallHostTestCases \
StagedInstallInternalTest \
GtsStagedInstallHostTestCases \
com.android.server.pm.ApexManagerTest
Change-Id: I6e3adf0f3f80764dcdb9cc26ef281f25566e854e
Due to the removal of support for Full Disk Encryption,
the "core apps only" mode of system_server is no longer used, and
onlyCore is hard-coded to false. For details, see http://ag/17685636.
Remove the corresponding obsolete code from PackageManagerService and
the related classes InitAppsHelper, UserDataPreparer, PackageParser2,
and ParsingPackageUtils.
Bug: 208476087
Change-Id: I48289d1f74414f831504b38ac5c1bde719b07fb2
Apps targeting T will not get SCHEDULE_EXACT_ALARM permission by
default, except in a few privileged special cases.
Test: atest FrameworksMockingServicesTests:AlarmManagerServiceTest
atest CtsAlarmManagerTestCases:ExactAlarmsTest
Bug: 226439802
Change-Id: Ie81a9c3bd8b863c3fd64aaf413209ff8862de74b
The iteration n updates some PackageUserState instances for the
specified user. Once OverlayManagerService(OMS) changes some
PackageUserState instance, it triggers a snapshot rebuild in the
next iteration.
OMS has prepared all changes in switching users. PackageManagerService
compute all changes of PackageUserStates and then use the mutator to
modified all changes of PackageUserStates in one
commitPackageStateMutation.
Test: run perfetto.ui and follow the commands on perfetto.
b/174206591#comment14
Test: TC="PtsConfigTestCases:com.google.android.config.pts"; \
atest ${TC}.PixelSetupWizardOverlayTest ${TC}.ConfigTestCase
Bug: 174206591
Change-Id: I2b58b5e6164a72008c284adf05f6ff0240a5a33a
This reverts commit 35ef88f4cc.
Reason for revert: re-introduce change after disabling test in
Ia4303f6ba0160c24ac8949c359dfe3e28a544cc6
Change-Id: I14402335736559c4997439425d2ab49ac172d9ca
This reverts commit 2fd993fd6c.
Reason for revert: test monitor, was identified as culprit for b/223768516
Change-Id: I871e5ab1c9cbe083a4aea4e916eb45a820725155
Effectively removes the lock and trampoline Computer wrappers as
we enforce that snapshots are always available now.
Also isolates IPackageManager and PackageManagerInternal from
PackageManagerService to prevent misuse of the APIs. The separated
base classes have access to a snapshot method which is then proxied
to, or used to call into PMS.
This makes it impossible for a caller using PMS directly to
accidentally call into one of these other API surfaces that won't
use the caller's provided snapshot, causing inconsistency problems.
Also removes live locking annotations and the related infrastructure
since we just assume that doesn't matter anymore.
Also migrates some _Helper logic to take/pass snapshots to match the
PMS methods, but not all of the helper logic migated to consistent
snapshots. That will be done in a follow up.
With this, all known extra overhead has been removed and metrics
should return to normal.
Bug: 215403184
Test: presubmit
Change-Id: I7e977f600f49b070c3a539901cc06d523fb7517a
To avoid leaking IPackageManager methods directly into
PackageManagerService, moves the IPM implementation into an inner
class similar to PackageManagerInternal.
This will help enforce snapshot consistency by ensuring that all
non-IPM PMS methods can always take in a Computer instance to re-use.
Bug: 217961172
Test: presubmit
Change-Id: Ibf7bd3d1d90a40786279763ba8d62eb9348bb760
Adds a new method to PackageManagerInternal that checks
if a given package belongs to the calling uid. This logic also
accounts for calling uids in the sdk sandbox range.
Deduplicates two methods in NotificationManager and ActivityTaskManager
which have implemented this logic.
Bug: 219750831
Test: atest NotificationManagerServiceTest
Test: Manual test using Sdk Sandbox test app
Change-Id: I1c566f75c81112dfeeb664827dcb27768959c377
When handling post-install during the installation process, some
tasks are posted to PackageHandler and be executed after notifying
the install observer (install initiator). The task includes force-
stopping the package. If the install observer starts the app right
after being notified, the ongoing force-stop will kill the process.
The race happens. To mitigate the potential race, We should defer
the notification until these tasks are done.
Bug: 165012101
Test: atest -p services/core/java/com/android/server/pm
Change-Id: Ia6b32f72f3d75b8a40c42e11d21f21c459db5299
Merged-In: Ia6b32f72f3d75b8a40c42e11d21f21c459db5299
(cherry picked from commit bad03aa3c9)
Lambdas were used to ensure consistent locking around the snapshot,
but since it's impossible to lock the snapshot now, this is no longer
necessary, and all methods should just store a reference.
Also migrates DomainVerificationService off PackageSetting lambdas,
which cleans up a lot of extra emthods.
Bug: 215403184
Test: atest com.android.server.pm.verify.domain
Test: atest SuspendPackageHelperTest
Change-Id: Ib4e3442e5c16e935b14b8421fbc33adff65dcf68
Migrates ComponentResolver and ResolveIntentHelper away from calling
PM directly in favor of using a consistent Computer snapshot. This
saves on snapshot rebuild and ensures data consistency within a single
method call.
Bug: 215403184
Change-Id: Id017db704493f38d94fd498f77d2264fe008ef45
Removes the ability to disable PackageManagerService snapshots. The
new PackageState and related APIs rely on never taking PMS#mLock, so
a snapshot Computer must always be available.
To keep changes small, this does not migrate existing
executeWithConsistentComputer calls, but that can be done in a simple
follow-up to save on lambda allocation costs.
Bug: 202291547
Change-Id: I243988b0c48938a8701842a9de5cfc465c1d38d8
On detecting excessive battery usage of a background uid, we may
move the background restriction of the apps running in this uid to
more restrictive levels.
Bug: 200326767
Test: atest FrameworksMockingServicesTests:BackgroundRestrictionTest
Change-Id: I6c2d41e44367a283d8aa9491be683018a80a810c
Client apps need the ACCESS_AMBIENT_CONTEXT_EVENT permission to use the service. The permission protection level is internal|role.
API overview: http://go/ambient-framework-api
PRD: http://go/ambient-attribution-prd
Design doc: http://go/ambient-service-api
Test: CTS test
Bug: 192476579
Change-Id: I9daede83af34f215c278cb0530238faba1be5c70
Ignore-AOSP-First: to prevent new feature leak.
This facilitates exposing the Parsed_ classes as
@SystemApi(client = SYSTEM_SERVER) while keeping everything inside
services.jar rather than having it split across both jars.
This reverts getPackageArchiveInfo to use legacy PackageParser, since
framework.jar can no longer access the moved classes.
Bug: 214038417
Test: presubmit, no logic changes
Change-Id: I152d70fb4f643d32efb012cfb20b0fbc5f88f2d8
Adds APIs to record a state at some time and use that state to commit
changes to package state. Which allows reconcilation and retry of
competing changes without needing to take the data model lock unless
absolutely necessary.
Also copies over data model/settings changes to make it compile.
Split from actual usage to make review easier.
Bug: 202291547
Test: presubmit, no usages yet
Change-Id: I6738829185022efef4add1805b5a52b3de3d173a
+ Use explicit flag types in PackageManager.
+ Distinguish AllocationFlags from StorageFlags.
BUG: 207030431
Test: Builds
Change-Id: I641c76859d3a16f70acad17507695ddd161f339a
We are running out of int flags for public API methods such as
PackageManager.getPackageInfo(String packageName, int flags). As a
solution, we will change the flags param to Flags objects. At the
same time, we deprecate the old methods that directly use int flags.
The new flags classes are: ApplicationInfoFlags, PackageInfoFlags,
ComponentInfoFlags and ResolveInfoFlags. Because there are already
annotations of the same names, we renamed the annotations to *FlagsBits.
Old API usage example:
getPackageInfo(pkgName, MATCH_UNINSTALLED_PACKAGES)
New API usage example:
getPackageInfo(pkgName, PackageInfoFlags.of(MATCH_UNINSTALLED_PACKAGES))
See b/204433742 for discussions.
CTS-Coverage-Bug: 206147270
BUG: 204432643
BUG: 204433659
Test: manual
Change-Id: I8ab2adad6907670c5879c043d170c950afefe46c
Changes IPackageManager.aidl methods to use long flags instead of int.
Public API change to be followed.
BUG: 204432643
BUG: 204433659
Test: manual
Change-Id: Ib5c42fef998f0116e312c71d620e1a15329e26e0
In most non-install, non-mutate areas, migrates away from locking
PackageManagerService directly in favor of the Computer snapshot.
This will relieve more lock contention and allow scoping
PackageSetting to mutate-only scenarios, such as install.
Bug: 202291449
Change-Id: Ie92ebfeacdc4a00484373f11739fdfe3c3897a7f
Moves to a read-only interface inside Computer and all of its
dependencies. This is the next step towards true data model
immutability and mutation time snapshots.
Bug: 202291449
Test: atest PackageManagerServiceUnitTests \
PackageManagerSettingsTests \
PackageUserStateTest \
PackageParserTest \
PackageManagerTest \
ScanTests \
PackageInfoUserFieldsTest \
DexoptUtilsTest \
PackageManagerComponentLabelIconOverrideTest
Change-Id: If5afb44e20b50a15b2b99057b0797c9b88e6e60b
We estimate the next app launch time by looking at the past 7 days of
usage history and assuming that the user opens the app like clockwork.
If there is at least 24 hours of usage events, then we take the earliest
ACTIVITY_RESUMED event and estimate that the app will be launched
exactly 7 days after that event. If there is less than 24 hours of
history (which would be the case for a new app), then we take the
earliest ACTIVITY_RESUMED and add 24 hours. If we don't see any launch
event in the past 7 days, then we just say the app should be launched
within a year. If we have a long estimate for an app and it is launched,
then we re-evaluate our estimate because we can now estimate a launch
within the next 7 days.
Bug: 194532703
Test: atest FrameworksMockingServicesTests:PrefetchControllerTest
Test: manually launch apps and check dumpsys for expected launch time changes
Change-Id: I9ef5fc3e3df3c2d029243b1fb8949a4bf21900db