Commit Graph

138 Commits

Author SHA1 Message Date
Hai Zhang
65d46e9b05 Refactor getAppOpPermissionPackages() as API.
- Remove IPermissionManager.getAppOpPermissionPackages() and its usage
  because we are not going to expose it as a new API on
  PermissionManager.

- Make PermissionManagerServiceInternal.getAppOpPermissionPackages()
  unchecked because it's an internal API. Internal APIs should be by
  default unchecked and checks should be done manually when
  necessary.

- The parameters and return value of
  PermissionManagerServiceInternal.getAppOpPermissionPackages() are
  also made non-null to be a good API, and EmptyArray.STRING is
  returned in the empty case so there won't be a performance penalty.
  IPackageManager.getAppOpPermissionPackages() will return an empty
  array for null permissionName before calling
  PermissionManagerServiceInternal.getAppOpPermissionPackages() for
  compatibility, and clients should handle returned empty arrays as
  good as null.

- Use PermissionManagerServiceInternal.getAppOpPermissionPackages()
  only to support the @UnsupportedAppUsage of
  IPackageManager.getAppOpPermissionPackages() and perform checks
  there.

Bug: 158736025
Test: presubmit
Change-Id: I0f96e898daa4cf40706430f1b7fbd5737a1f97f8
2020-11-12 17:07:26 -08:00
TreeHugger Robot
05e768ced6 Merge "Do not allow to install S+ apps with cross cert permissions" 2020-10-22 00:14:32 +00:00
Philip P. Moltmann
22d2486c1f Do not allow to install S+ apps with cross cert permissions
I.e. permissions and permission groups should stay inside a cert-group
so that there cannot be accidential security bugs in apps.

Test: atest CtsPermissionTestCases
            CtsPermission2TestCases
	    CtsAppSecurityHostTestCases
Fixes: 146211400 (No backport possible, all changes are for S+ apps
only)
Change-Id: I19c2f3e216ea57a9e25c65e276f87425aeb1c038
2020-10-21 18:58:16 +00:00
Anton Hansson
586a3cf229 Remove @TestApi from @SystemApi symbols
I ran these commands:
    cd frameworks/base
    grep -rl '@TestApi' --include '*.java' | xargs perl -i -p0e \
        's/\@SystemApi[\s\n]+(\@\w+[\s\n]+)?\@TestApi/\@SystemApi\1/gs'
    grep -rl '@TestApi' --include '*.java' | xargs perl -i -p0e \
        's/\@TestApi[\s\n]+(\@\w+[\s\n]+)?\@SystemApi/\1\@SystemApi/gs'

Bug: 171179806
Test: m checkapi
Change-Id: I772790b783b0a8730b8bf680c9e569a886b8d789
2020-10-20 09:04:03 +01:00
Roman Kalukiewicz
24403f7ef2 Add @Nullable annotation to the parameter of Object.equals() methods.
Those annotations could be inferred by some tools (like Kotlin), but the
https://checkerframework.org/ doesn't check inherited annotations
complaining about all equals() invocations that get nullable argument.

The change was generated by running

find . -name \*.java | xargs sed -i 's/public boolean equals(Object /public boolean equals(@Nullable Object /'

in the frameworks/base directory and by automatically adding and
formatting required imports if needed. No manual edits.

Bug: 170883422
Test: Annotation change only. Should have not impact.
Exempt-From-Owner-Approval: Mechanical change not specific to any component.
Change-Id: I5eedb571c9d78862115dfdc5dae1cf2a35343580
2020-10-15 10:48:01 -07:00
Lee Shombert
626323eb27 Merge "Enable in-process permission caches for system_server" 2020-10-15 15:37:03 +00:00
Alexander Dorokhine
2588dcb34d Merge "Migrate away from deprecated Truth APIs." 2020-10-12 23:18:52 +00:00
Lee Shombert
642aab2c50 Enable in-process permission caches for system_server
Bug: 170472470

Do not disable the permission caches inside the system server.  This
is beneficial because permission checks require many binder calls, and
the cache, even though it is in-process, eliminates those calls.
1. Make the PermissionManager cache more effective by increasing the
   maximum size to 2048.  Experiments show that the high-water mark is
   about 600.
2. Suppress cache content in the 'dumpsys cacheinfo' output.  dumpsys
   fails if the output is too large in a single process, and the new
   caches push the system server cacheinfo over the limit.  The
   content can be added to the output by setting the new DETAILED
   boolean in PropertyInvalidatedCache to true, but this flag should
   never be committed with a value of true.

Test: two atest runs
 * atest FrameworksServicesTests:com.android.server.devicepolicy.DevicePolicyManagerTest#testGetPermissionGrantState
 * atest FrameworksServicesTests:NetworkPolicyManagerServiceTest

Change-Id: I7d3c1f34b44216bb510319ca5b6aced1cc53e05d
2020-10-12 19:26:49 +00:00
TreeHugger Robot
23606d44e8 Merge "Improve the documentation of the paramters passed to noteOp" 2020-10-09 03:12:56 +00:00
Philip P. Moltmann
8c22ae2a0c Improve the documentation of the paramters passed to noteOp
Test: Docs only changes
Change-Id: I10bac140182db2de43399b45da683c45435ed828
2020-10-08 17:48:10 -07:00
Jeff Sharkey
2d2e07e2ff Tighten up Binder.clearCallingIdentity() usage.
The recently added AndroidFrameworkBinderIdentity Error Prone checker
examines code to ensure that any cleared identities are restored to
avoid obscure security vulnerabilities.

This change is a purely mechanical refactoring that adds the "final"
keyword to the cleared identity to ensure that it's not accidentally
modified before eventually being cleared.  Here's the exact command
used to generate this CL:

$ find . -name "*.java" -exec sed -Ei \
    's/    (long \w+ = .+?clearCallingIdentity)/    final \1/' \
    {} \;

Bug: 155703208
Test: make
Exempt-From-Owner-Approval: trivial refactoring
Change-Id: I832c9d70c3dfcd8d669cf71939d97837becc973a
2020-10-06 11:18:09 -06:00
Alexander Dorokhine
4697f76edd Migrate away from deprecated Truth APIs.
This is a transitional step towards truth 1.0.1, where these APIs have
been completely removed.

Bug: 168765701
Test: m checkbuild
Change-Id: I26ab5ab82bb939bbd9553c05387ac8641eb468b4
2020-10-02 23:42:38 -07:00
Philip P. Moltmann
faeec12c7d Merge changes from topic "revert-12439864-PermAppOpsCrossUserCheck-Fixed-DGFFMARPXU"
* changes:
  Revert "Give all non-package services the power to interact accr..."
  Revert "Check cross-user interactions for permissions and app-op..."
  Revert "Invalidate package/permission cache if cross-profile app..."
2020-09-22 15:20:22 +00:00
Philip P. Moltmann
bbeed895f5 Revert "Check cross-user interactions for permissions and app-op..."
Revert "Add dedicated host side tests for permissions and appops"

Revert submission 12439864-PermAppOpsCrossUserCheck-Fixed

Reason for revert: Bug 169044600
Reverted Changes:
I95d015e01:Invalidate package/permission cache if cross-profi...
I2a8a84f57:Check cross-user interactions for permissions and ...
Ie8f0db231:Give all non-package services the power to interac...
I11af434a8:Test package/permission cache invalidation when IN...
Ib6d609a4d:Add dedicated host side tests for permissions and ...

Change-Id: Iea5eeded0ee5caf5383bb0e749133d4fef18d392
2020-09-21 22:26:18 +00:00
Philip P. Moltmann
fa24a327ab Merge changes from topic "PermAppOpsCrossUserCheck-Fixed"
* changes:
  Invalidate package/permission cache if cross-profile app is is changed
  Check cross-user interactions for permissions and app-ops operations
  Give all non-package services the power to interact accross users
2020-09-20 03:22:25 +00:00
Jeff Sharkey
4b5b0174d0 Merge changes from topic "sep11" am: c0b288133a am: 69e6f07347 am: 741c0a78cc am: da7478b570 am: 487d394296
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1426195

Change-Id: Id01f468b43fd5b2aada78608010625b392c1b647
2020-09-15 21:01:48 +00:00
Jeff Sharkey
487d394296 Merge changes from topic "sep11" am: c0b288133a am: 69e6f07347 am: 741c0a78cc am: da7478b570
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1426195

Change-Id: I79488866c538bf9e76d0a6429e30262978f6fdab
2020-09-15 00:13:08 +00:00
Jeff Sharkey
a8cec413b6 Update language to comply with Android's inclusive language guidance
See https://source.android.com/setup/contribute/respectful-code for reference

Test: none
Bug: 168334533
Exempt-From-Owner-Approval: docs updates
Change-Id: I245b8d9cac722da76ea67983738a3cbb9deb68df
2020-09-14 10:00:07 -06:00
Philip P. Moltmann
bca4796525 Check cross-user interactions for permissions and app-ops operations
1.
We want to be quite permissive here as without being able to check
permissions or appops nothing else works. Hence allow cross-user
interactions if any cross-user permission is granted.

2.
Also we need to prevent infinite recursion as we are checking permission
and appops inside of permission and app-op checks.

2.
Clear Binder.callingUid when checking permission inside system server

Makeing the binder call "checkPermission" usually sets
Binder.callingUid to the calling processes UID. Hence clearing the
calling UID is superflous. If the call is inside the system server
though "checkPermission" is not a binder all, it is only a method call.
Hence Binder.callingUid might still be set to the app that called the
system server. This can lead to problems as not every app can check the
same permission the system server can check.

E.g. the system server can check permission accross user boundaries,
most regular apps can't

Test: atest CtsPermissionHostTestCases CtsAppOpHostTestCases // execute the new paths for both full users and profiles
      atest ManagedProfileTest#testCameraPolicy              // a previous version of the patch caused a regression in this test
      atest AccountManagerXUserTest                          // a previous version of the patch caused a regression in this test
      Accessed clipboard from chrome in work profile
Fixes: 153996875
Change-Id: I2a8a84f574fbf07ab88ed991445830fa85aa4450
2020-09-11 19:23:07 -07:00
TreeHugger Robot
fab755105a Merge "PackageNamePermissionQuery uid->userId" 2020-08-12 20:59:23 +00:00
Adam Bookatz
833fe586e6 PackageNamePermissionQuery uid->userId
PackageNamePermissionQuery (and all that uses it) speaks
of uid, but it actually stores/queries a userId. We therefore
rename the variable/parameter from uid to userId, as appropriate.

Bug: 163651060
Test: still compiles (no functional changes were made)
Change-Id: I3db2263a3f960d7eda35466a2e9058fe6f27e49a
2020-08-12 01:37:51 +00:00
Nate Myren
070b491882 Add changeId to gate R-QPR tests behind
Bug: 162551686
Test: none
Change-Id: I6df669785db4d4684b8207fa7234d4793d652cb3
2020-08-12 00:21:40 +00:00
Nate Myren
dae94b50fa Add changeId to gate R-QPR tests behind
Bug: 162551686
Test: none
Change-Id: I6df669785db4d4684b8207fa7234d4793d652cb3
2020-08-11 15:56:21 -07:00
Lee Shombert
f168f2737e Enhance PropertyInvalidatedCache debugging
Bug: 162103383

Update 'dumpsys cacheinfo': add the number times a cache is cleared,
rename misses due to cache disabled/unset/corked to "skips", and fix the
logic counting cache invalidates.

Make the cache name distinct from the property.  There is no change to
legacy caches (which continue to use the property as the name) but
caches that share the cache_key.package_info property now have distinct
names.

Add the property name to auto-corker debug messages.

Test: Boot and run 'dumpsys cacheinfo' to verify the output.
Change-Id: I3e3e500dc9a1559fd7ccdc49fb00292ab5f712c1
2020-08-05 15:52:25 -07:00
Eugene Susla
aaa8d9fe67 Run Binder.dump away from main thread
Fixes: 158212653
Test: ensure .dump() is no longer run on main thread
Change-Id: I7c6e1c9f54c65c21e411813ffda636377a1c2bbe
2020-07-15 19:12:05 +00:00
felipeal
389a7260fc Improved logging when PermissionController package is missing.
For example, if it's not enabled for managed profiles, the message would now be:

7-13 20:46:38.308 16176 16205 E PermissionControllerManager: No PermissionController package (com.google.android.permissioncontroller) for user 11
07-13 20:46:38.311 22224 22224 E AndroidRuntime: FATAL EXCEPTION: main
07-13 20:46:38.311 22224 22224 E AndroidRuntime: Process: com.afwsamples.testdpc, PID: 22224
07-13 20:46:38.311 22224 22224 E AndroidRuntime: java.lang.RuntimeException: Unable to start receiver com.afwsamples.testdpc.DeviceAdminReceiver: java.lang.IllegalStateException: No PermissionController package (com.google.android.permissioncontroller) for user 11

Instead of:

07-13 18:07:19.887 26168 26168 E AndroidRuntime: FATAL EXCEPTION: main
07-13 18:07:19.887 26168 26168 E AndroidRuntime: Process: com.afwsamples.testdpc, PID: 26168
07-13 18:07:19.887 26168 26168 E AndroidRuntime: java.lang.RuntimeException: Unable to start receiver com.afwsamples.testdpc.DeviceAdminReceiver: java.lang.NullPointerException: Attempt to invoke virtual method 'android.content.pm.ComponentInfo android.content.pm.ResolveInfo.getComponentInfo()' on a null object reference

Bug: 161135695
Test: adb shell setprop persist.debug.user.package_whitelist_mode 1
Test: # then install the TestDPC
Change-Id: I8d27b59cd5b96735e1d5e22a341bf869158e278f
2020-07-13 14:30:09 -07:00
Evan Severson
80a13bce0d Merge "Implement permission revoke with reason" into rvc-dev am: cee666eba9 am: 8ce472840e am: ebd42f9dd3 am: df1adc879d
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/11959996

Change-Id: I352500452191b1a012ec486a8474c1210fbc9ea1
2020-06-24 23:55:19 +00:00
Evan Severson
aacd48b0bc Implement permission revoke with reason
The reason is passed to app exit info so a given app can get more
information about why their app was killed in the event of permission
revoke.

Test: atest RevokePermissionTest ActivityManagerAppExitInfoTest#testPermissionChangeWithReason
Fixes: 159659620
Change-Id: Id711667eb2c1579ecb2a1b83a62af3cc7862d5f6
2020-06-24 10:03:54 -07:00
Adam Bookatz
36bacceee5 Clarify doc for users, clarifying profiles
Test: N/A
Bug: 159173436
Change-Id: I3c105559801a72ef1d91d9db2d42a816e27e24f6
Merged-In: I3c105559801a72ef1d91d9db2d42a816e27e24f6
2020-06-18 00:08:51 +00:00
Adam Bookatz
ffffe91132 Clarify doc for users, clarifying profiles
Test: N/A
Bug: 159173436
Change-Id: I3c105559801a72ef1d91d9db2d42a816e27e24f6
2020-06-17 17:07:11 -07:00
Eugene Susla
5a291acd8e Merge "Correct javadoc for an auto-revoke API" into rvc-dev am: 3f24b9cf64 am: f611c94d72 am: 84a545a34b am: c2050acf06
Change-Id: I2c6ee08bcf015596cad1463cb4a13692c891d8fc
2020-05-21 22:19:54 +00:00
Eugene Susla
44753b4c8f Correct javadoc for an auto-revoke API
Test: presubmit
Bug: 153607914
Change-Id: Ie271ecfbb3e9356080c28103df658b411ebd61ec
2020-05-21 11:03:37 -07:00
Eugene Susla
a4cc1cd4d6 Merge "No need for copying dump state for PC" into rvc-dev am: 0728a4fe50 am: 3cb0fb2e07 am: ee924b06eb am: 08c93a2973
Change-Id: I1951fffcd1ff07eddadbe02fd7725befb03b77e8
2020-05-12 01:31:46 +00:00
Philip P. Moltmann
1a4467816a No need for copying dump state for PC
Also
- enforce permission when dumping PC data

Bug: 155680199
Test: dumpsys permissionmgr
Change-Id: I2cacd6f9d8db0ea329de1d15c96bea9f2ae15dd1
2020-05-11 14:32:17 -07:00
Philip P. Moltmann
65de8f996e Merge "Forward dumps from PermissionControllerManager to permissionmgr" into rvc-dev am: f7d1f1a40c am: 2ed0952744 am: 09fd12d9bf am: 7dc20cffc2
Change-Id: I1e22754721fb15ba1f20fa05881dec202dd44b1b
2020-05-07 06:11:34 +00:00
Philip P. Moltmann
5ab27fca5c Forward dumps from PermissionControllerManager to permissionmgr
Test: adb shell dumpsys permissionmgr
Bug: 155680199
Change-Id: Iab5da24277eb6333ef047ab84dfcb65b7c4c2ff2
2020-05-06 17:24:40 -07:00
Philip P. Moltmann
497f2a3291 Merge "Fix typos in permissions.md" into rvc-dev am: fa658e0206 am: 41677ef61d am: 6d828fdf7d am: 2ef567606a
Change-Id: I1a792a73156e6789cbf1b0678f41f6403e9de8f1
2020-04-27 22:18:00 +00:00
Philip P. Moltmann
fa658e0206 Merge "Fix typos in permissions.md" into rvc-dev 2020-04-27 21:18:40 +00:00
TreeHugger Robot
89b334ec8d Merge "Allow tests for more PermissionControllerManager methods" into rvc-dev am: bac5755dad am: 3dc3e75e95 am: d219925fd6 am: 63581abaac
Change-Id: If55785f96ebd3727480cb3626e60ff3a962c78d9
2020-04-27 17:20:58 +00:00
Philip P. Moltmann
14be93f59a Fix typos in permissions.md
Bug: 151379035
Change-Id: I1335ca5a0ed22b8a39a57adc22c6b3b0b5d6e06d
2020-04-27 16:10:39 +00:00
Philip P. Moltmann
18247c1a8c Allow tests for more PermissionControllerManager methods
Test: atest RuntimePermissionPresentationInfoTest PermissionControllerTest
Bug: 155019930
Change-Id: I4baca0f35e7218fbf127d56fcdf1fe1855d64929
2020-04-26 17:52:41 -07:00
Michael Groover
7e66441c4e Merge "Refactor device ID access SystemAPI to PermissionManager" into rvc-dev am: ffd92af9a5 am: 5cca1f94a0 am: 20b4078f1c am: 2b8113443f
Change-Id: I08d9d09d133ff30833346a843f7bdd927a070c15
2020-03-21 16:34:48 +00:00
Michael Groover
56a84b26f4 Refactor device ID access SystemAPI to PermissionManager
Based on feedback during the API review of the new SystemAPI for
telephony to check device identifier access the method was moved
from DevicePolicyManager to a more generic location to perform
the non-subscriber portions of the check.

Bug: 147761267
Test: atest TelephonyPermissionsTest
Test: atest PermissionManagerServiceTest
Test: atest DeviceIdentifierTest
Test: atest DeviceOwnerTest#testDeviceOwnerCanGetDeviceIdentifiers
Test: atest TelephonyManagerTest
Test: atest DeviceOwnerTest#testDeviceOwnerCannotGetDeviceIdentifiersWithoutPermission
Test: atest ManagedProfileTest#testProfileOwnerOnPersonalDeviceCannotGetDeviceIdentifiers
Test: atest CtsDevicePolicyManagerTestCases:com.android.cts.devicepolicy.OrgOwnedProfileOwnerTest#testProfileOwnerCannotGetDeviceIdentifiersWithoutPermission
Test: atest CtsDevicePolicyManagerTestCases:com.android.cts.devicepolicy.OrgOwnedProfileOwnerTest#testProfileOwnerCanGetDeviceIdentifiers
Change-Id: Ic1867dad0b2369f2dc1a7d31facb65f89131376f
2020-03-19 20:42:47 +00:00
Peter Wang
8ec9a3e3f9 Merge "[Telephony Mainline] Hide all PermissionManager APIs for R" into rvc-dev am: f4885bf28f am: a010ea5e1e am: f9318598b6 am: b4d1c0331d
Change-Id: I0c8b81dc1e95e5853620a47303281627c36fc50d
2020-03-19 20:18:54 +00:00
Peter Wang
f4885bf28f Merge "[Telephony Mainline] Hide all PermissionManager APIs for R" into rvc-dev 2020-03-19 19:21:21 +00:00
Peter Wang
256683e3a8 [Telephony Mainline] Hide all PermissionManager APIs for R
Bug: 142019744
Fix: 142019744
Test: Build
Change-Id: Ic1e08757ccba510fac3636c5bae33e8da23b7e6b
2020-03-18 22:07:22 -07:00
TreeHugger Robot
6f2b9c21f0 Merge "Add executor to onUpdateUserSensitiveFlags" into rvc-dev am: 045181d7f8 am: 8bba99961b am: 408fcf17c9 am: 9be98374f4
Change-Id: Ia7e66f082aaffe5a38fcf888ac7cc2fcbafc6ba7
2020-03-19 01:22:08 +00:00
TreeHugger Robot
045181d7f8 Merge "Add executor to onUpdateUserSensitiveFlags" into rvc-dev 2020-03-19 00:11:03 +00:00
Philip P. Moltmann
e3d8a33f1f resolve merge conflicts of ec3e1e68cf to master
Change-Id: I9fd3852b402b363907df501ff4705d7683269664
2020-03-17 23:46:27 +00:00
Philip P. Moltmann
379322f066 Merge "Suggested additions to permissions docs" into rvc-dev 2020-03-17 22:19:32 +00:00