Commit Graph

113 Commits

Author SHA1 Message Date
Kweku Adams
f177a8df86 Create a UsageEventListener.
Creating the UsageEventListener to generalize conveying new usage events
so that multiple components can be notified.

Bug: 142281756
Bug: 171305774
Test: atest AppIdleHostTest
Test: atest CtsUsageStatsTestCases:UsageStatsTest
Test: atest FrameworksMockingServicesTests:UsageStatsServiceTest
Test: atest FrameworksServicesTests:AppIdleHistoryTests
Test: atest FrameworksServicesTests:AppStandbyControllerTests
Change-Id: I176c476257600f0f4299a10f02b5c61332007b1c
2020-11-23 10:56:43 -08:00
Bernardo Rufino
9aee235f28 Merge "Create recents protectionLevel" 2020-11-23 09:30:38 +00:00
Bernardo Rufino
0dec6c042c Create recents protectionLevel
In preparation for permission BROADCAST_CLOSE_SYSTEM_DIALOGS
(go/close-system-dialogs), which will be signature|recents in order to
lock down Intent.ACTION_CLOSE_SYSTEM_DIALOGS. That intent is used by
recents when it's invoked.

Currently, recents is configured via existing config
config_recentsComponentName, so using that to determine the recents
package in PM.

It's my understanding that the package defined in such config will be
responsible for recents no matter which launcher is active. It's also my
understanding that the package being explicit in the system config means
that package has to come from the system image, hence it's fine to use
ensureSystemPackageName() in PM. Please advise if any of
this is wrong.

Test: Will work on CTS once we agree on the proposal here.
Bug: 159105552
Change-Id: I9f73e1f05d8df26666da156b672e370dce5030de
2020-11-19 14:39:51 +00:00
Adam Bookatz
961f737505 Merge "Move UserManagerInternal out of android.os" 2020-11-18 17:38:06 +00:00
Adam Bookatz
e5140cc83b Move UserManagerInternal out of android.os
Moving this class out of android.os will reportedly
greatly reduce ART overhead.

Test: compiles
Test: atest FrameworksServicesTests FrameworksCoreTests
Bug: 165817914
Exempt-From-Owner-Approval: no-op refactoring
Change-Id: I1f3e77120979e2f336e5f42e4ec6e459d6492083
2020-11-17 20:43:46 +00:00
Alex Buynytskyy
6ede83e600 Fix for security logging of missing packages.
Better error cases handling.
Using internal handler to process digests to not overcommit
PackageManager's.

Fixes: 170777013
Test: atest OrgOwnedProfileOwnerTest#testSecurityLogging
Change-Id: I741c10ef3ceeec01e5436f92caa6a52d0c6b6003
2020-11-15 05:34:38 +00:00
TreeHugger Robot
1086c93f77 Merge "Removing taking unrelated locks from holdLock" 2020-10-27 17:46:12 +00:00
vadimt
22676d6118 Removing taking unrelated locks from holdLock
Test: running tests with the lock contention stress mode
Bug: 168630376
Change-Id: I5665eb7100d2fcbb93c7ade6cc30b0d8519246bb
2020-10-26 18:44:08 -07:00
Songchun Fan
d9d9dbae1e Merge "[am/incremental] make package unstartable if it crashes/ANRs while loading" 2020-10-26 17:35:06 +00:00
Songchun Fan
8c7bfcd5ab Merge "Revert "Revert "[incremental/pm] LauncherApps APIs for loading state and progress""" 2020-10-23 17:44:53 +00:00
Songchun Fan
dfd4162711 [am/incremental] make package unstartable if it crashes/ANRs while loading
BUG: 171252552
Test: atest CtsWindowManagerDeviceTestCases:AnrTests
Test: atest FrameworksServicesTests:AnrHelperTest
Test: atest FrameworksServicesTests:ActivityManagerServiceTest
Test: atest IncrementalStatesTest
Change-Id: I30c9aafc52ef1b6939bb724c11794b5a60661740
2020-10-22 13:43:11 -07:00
Songchun Fan
56838fba12 Revert "Revert "[incremental/pm] LauncherApps APIs for loading state and progress""
This reverts commit 69475be847.
Also reverts commit Iaf8e2c075f188df95c68824b71362629c6adabfc.

Reason for revert: Trying again but will submit with new tests

BUG: 165841645
Test: atest NexusLauncherOutOfProcTests
Test: atest LauncherAppsSingleUserTest
Test: atest LauncherAppsMultiUserTest
Test: atest LauncherAppsProfileTest
Test: atest LimitAppIconHidingTest
Change-Id: I5ed5871ccddefbd922b3aa3ee4c1ad53cc0bfa9b
2020-10-21 14:20:20 -07:00
Jackal Guo
7e7c256b3d Compress the known package IDs
The numbers of KnownPackage should be continuous and the string
representation should not be unknown.

Fix: 170356374
Test: atest PackageManagerServiceTest
Change-Id: I2d96ca74a49b8f24ff87f8e21981d8cc0d43a469
2020-10-21 18:14:06 +08:00
Greg Kaiser
69475be847 Revert "[incremental/pm] LauncherApps APIs for loading state and progress"
This reverts commit 0173a44f3d.

Bug: 170959052
Test: Locally confirmed two reverts together fix app tray
Change-Id: I2f7b198f77b54be671c7f02bc2b67838bf99d28b
2020-10-16 07:34:43 -07:00
Songchun Fan
0173a44f3d [incremental/pm] LauncherApps APIs for loading state and progress
Exposing package state changes and progress changes via LauncherApps
and LauncherActivityInfo as public APIs.

BUG: 165841645
Test: builds (will add CTS tests)
CTS-Coverage-Bug: 168925573
Change-Id: I2b5ea698799f9a762b7d9c79d62636d3db187c1f
2020-10-13 13:12:08 -07:00
Jackal Guo
d9f98db1ac Merge "Dump known packages" 2020-10-07 02:14:13 +00:00
Jackal Guo
fa0837d8dc Dump known packages
Add helpful known-packages section in bugreport.

Fix: 121374459
Test: Using 'adb shell dumpsys package (known-packages)' to check
      whether these known packages are dumped.
Change-Id: Ie43871d7ba8adca01bc17761dd9137129f47c58e
2020-10-06 03:27:10 +00:00
TreeHugger Robot
80cede3d78 Merge "Fix keeping track of binder native thread IDs" 2020-09-22 19:33:30 +00:00
Dmitri Plotnikov
9801ed118c Fix keeping track of binder native thread IDs
Test: atest FrameworksCoreTests:com.android.internal.os.BatteryStatsBinderCallStatsTest
Bug: 169094825

Change-Id: If503327bd6f7fa022a1d261edb0746f710b1410c
2020-09-22 10:35:20 -07:00
Felipe Leme
d9414beda1 Fixed PackageManager.readLPw() call.
It wasn't including pre-created users; as such, apps that were not
installed on pre-created users got installed on reboot.

To test it:

adb shell pm create-user --pre-create-only
m ApiDemos
adb install --user current ~/Downloads/apk/ApiDemos.apk
adb shell dumpsys package com.example.android.apis |egrep ".*User .*:"|grep installed
adb shell stop && adb shell start
adb shell dumpsys package com.example.android.apis |egrep ".*User .*:"|grep installed

Without this fix, the second dumpsys would show the app installed
for the pre-created user.

Test: manual test (see above)
Test: atest CtsMultiUserHostTestCases:android.host.multiuser.PreCreateUsersTest
Bug: 160252062

Change-Id: I46c2ec94a3ab422e3e39b66239c21fb6cbff5a8e
2020-09-16 11:13:06 -07:00
Songchun Fan
a70985945b [incremental/pm] register progress listener
Incremental Serivce periodically polls loading progress and sends to
Package Manager Service. Package Manager provides APIs for other
interested parties to listen to the loading progress.

BUG: 165841827
Test: unit test
Change-Id: I44b9e17c2240b9efe53bc09fc728b6671f1f7dfe
2020-09-15 17:39:41 -07:00
Jackal Guo
7141894709 Merge "Rename pmInternal#getPackageUidInternal (1/4)" 2020-08-21 04:51:31 +00:00
Jackal Guo
a478dfcc38 Rename pmInternal#getPackageUidInternal (1/4)
This method was added to operate as an internal variant of the
public getPackageUid method since pmInternal#getPackageUid already
exist. However, pmInternal#getPackageUid method just called to the
public interface, and enforcing permissions and visibility checks.

Since we don't expect any UID/permission checks in a local service,
any callers to this method requiring permission checks should be
migrated onto the PackageManager public method. Remove the original
pmInternal#getPackageUid and rename #getPackageUidInternal to take
its place.

Bug: 148235092
Test: Build pass and boot
Change-Id: Ibd4aa8a6a7743ff378a23e21c68efc52692580c7
2020-08-21 09:26:31 +08:00
Felipe Leme
7a907dbe46 Refactored user switch workflow to decouple UserInfo from TargetUser.
UserController calls SystemServiceManager on some stages of the user
switch lifecycle, and SystemServiceManager calls the respective
callbacks in the SystemService objects it manage.

Prior to Android 11, these callbacks would take a @UserIdInt userid,
but now they take a TargetUser (which in turns contains a Userinfo).
So, currently, UserController calls SystemServiceManager passing the
userid, and SystemServiceManager gets the UserInfo from
UserManagerService. That works fine most of the time, but there might
be some race conditions when a user is removed that can crash the
system when such user is stopped (because UserManagerService doesn't
have its UserInfo anymore).

This CL fixes this issue by refactoring the user switch workflow so:

- TargetUser doesn't hold a reference to the UserInfo anymore, but
  offer the methods needed by SystemService implementations.
- SystemServiceManager keeps track of the TargetUser objects used in
  the callbacks.

Test: manual verification

Fixes: 159831354

Change-Id: If68ab1b5e247c7389c8cac16432d8b8809507e86
2020-08-13 16:56:34 -07:00
Dmitri Plotnikov
6c3defc282 Implement a PowerCalculator to attribute system service power to apps
Test: atest FrameworksCoreTests:com.android.internal.os.SystemServicePowerCalculatorTest
Test: atest FrameworksCoreTests:com.android.internal.os.SystemServerCpuThreadReaderTest
Test: atest FrameworksCoreTests:com.android.internal.os.BatteryStatsBinderCallStatsTest
Bug: 158232997

Change-Id: I14f6527524d6c32de460d80b33dfa0d6c0ad863c
2020-08-04 18:01:58 +00:00
Zoran Jovanovic
9336d9e13b OMS: Add config_signature policy handling
Alongside SIGNATURE and ACTOR_SIGNATURE policies, add CONFIG_SIGNATURE
policy to overlayable that overlay fulfills if it is signed with the
same certificate as the reference package whose package name is
declared in 'config-signature' tag of SystemConfig and is vetted by
OMS that it's a system pre-installed package.

BUG: 158726924
TEST: regular aapt2, idmap2, OMS tests

Change-Id: I645ee72271496008742886274be0d63a2985201b
2020-07-28 18:30:53 +00:00
Automerger Merge Worker
1ba13c827c Merge "Merge "Adding internal version of getUsers without permission check." into rvc-dev am: 467891337c am: 7ddd948a17 am: 558bc4b338" into rvc-qpr-dev-plus-aosp am: 1570ef20cd
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/11909341

Change-Id: I9bd3360b9baa4671ecaf5f437a53796dc9ee27ce
2020-06-19 16:32:46 +00:00
Dmitri Plotnikov
d2e374b671 Include binder stats in battery stats
Bug: 158232997

Test: atest FrameworksCoreTests:com.android.internal.os.BatteryStatsBinderCallStatsTest
Change-Id: I2234776d710adf73c363bdfa6a334f3a6f36d986
2020-06-18 17:31:37 -07:00
Alex Buynytskyy
6eba5bb73b Adding internal version of getUsers without permission check.
It's up to system-server to make sure it's doing the right thing.
-50ms create time for PM

Bug: 157191740
Test: adb reboot; adb logcat | grep -e PackageManagerTiming
Change-Id: I8b64164464fcc6447871cfb94475af7379b72c16
2020-06-18 14:56:28 -07:00
TreeHugger Robot
8ea5fd15dd Merge "Convert personal app suspension on COMP->COPE migration" into rvc-dev am: b14310b5ef am: 50c1b54d3c am: 008693d402 am: bdaf5b1c42
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/11744198

Change-Id: I6e32fb0874f64d801a5fde010101598e122e70c8
2020-06-11 01:44:07 +00:00
Pavel Grafov
80b763830e Convert personal app suspension on COMP->COPE migration
* if no apps are suspended by the DO prior to migration, nothing
  changes
* if some apps were suspended by the DO and the DPC targets R+
  via DPM.setPackagesSuspended(), this will result in personal
  apps suspended explicitly by the PO DPC as if it called
  DPM.setPersonalAppsSuspended(). The apps will stay suspended.
* if the DPC target SDK is below R, the apps will be unsuspended
  because the DPC won't have a way to unsuspend them. And the
  user will be stuck with suspended apps.

+ when unsuspending apps, don't collect the list of apps subject
  to suspension, but rather unsuspend all that is suspended. It
  is more robust, e.g. when some app stops meeting the
  conditions, e.g. not SMS app anymore.

Bug: 157270093
Test: com.android.server.devicepolicy.DevicePolicyManagerServiceMigrationTest
Test: Manual, with TestDPC, also patching it to target R

Change-Id: I1eba7216dd557c94bef822b77d25b484dfcd6f63
2020-06-10 23:11:01 +01:00
Dmitri Plotnikov
305ee3e98e Add plumbing to collect Binder stats for battery attribution
Bug: 158232997
Test: atest FrameworksCoreTests:com.android.internal.os.BinderCallsStatsTest

Change-Id: Icbccd26e20bc4ead13ffeac76b851af39269ca89
2020-06-10 12:09:41 -07:00
Varun Shah
a7f9c762cb Delay updating of usage stats package mappings.
Do not update package mappings for the system user when the user is
first unlocked. Instead, schedule a job to be executed after 24 to 48
hours from when the system user is unlocked. This makes the service
initialization phase for the system user a little quicker since their
data is not likely to be stale. Additionally, this also ensures that
restored data is not pruned by mistake if there is a device restart
before restore is completed. The updating of the mappings occurs
normally for other users, on user service initialization.

Bug: 155209652
Test: manually ensure job is skipped for system user
Test: atest android.app.usage.cts.UsageStatsTest
Change-Id: I2c03a1a05246d6b454569c4569813e90bede3693
2020-05-12 16:45:58 +00:00
TreeHugger Robot
faf1d06d45 Merge changes I9be69af5,Ib85ee393 into rvc-dev
* changes:
  Clear uninstall block when removing DO.
  Clean up app restrictions when removing DO or PO
2020-04-21 13:25:30 +00:00
Pavel Grafov
9798973c01 Clear uninstall block when removing DO.
Another way was to clear it using existing APIs for each package
but each call would cause Package Manager to re-serialize the
package-restrictions.xml, so I added a separate API to do it in
one go.

Bug: 149075700
Test: manual, set TestDPC as a DO, block uninstall, remove DO.
Test: manual, set TestDPC in COMP, block uninstall, migrate to COPE.
Change-Id: I9be69af5d7ae9e0ddda087d3e01e35f3429f25f4
2020-04-21 12:24:49 +01:00
Jackal Guo
63aa98db6d Invalidate the cache for APK-in-APEX
PackageCacher uses file name and modified time to determine if the
parsed cache is still valid. However, all APK-in-APEX would have
the same name and modified time. This results in the out-of-date
cache would be treated as valid.

We need to invlidate the cache for the APK-in-APEX when that APEX
is going to be installed.

Bug: 152352677
Test: atest -p frameworks/base/core/java/android/content/pm
Test: atest -p frameworks/base/services/core/java/android/content/pm
Test: Update/rollback an APK-in-APEX, and check its version code

Change-Id: I2a722036d8b1e9c5121d385f8d0667fb908cc7a1
2020-04-17 10:48:08 +08:00
Alex Johnston
bb5e6b49a7 Merge "Changed how user restrictions are pushed to UM" into rvc-dev 2020-04-05 21:15:26 +00:00
Alex Johnston
ec6c3d35db Changed how user restrictions are pushed to UM
* Sort the user restrictions to local restriction
  set and global bundle in DPMS instead of User
  Manager.
* Simplify pushUserRestrictions.
* Split the list of user restrictions the profile
  owner of an organization-owned device can set into
  a global and local list. The user restrictions in
  the local list will only be applied to the personal
  profile as opposed to the whole device.

Bug: 149743941
     148453838
Test: atest com.android.cts.devicepolicy.UserRestrictionsTest
      atest com.android.server.devicepolicy.DevicePolicyManagerTest
      atest com.android.server.pm.UserRestrictionsUtilsTest
      atest com.android.cts.devicepolicy.OrgOwnedProfileOwnerTest#testUserRestrictionSetOnParentLogged
      atest com.android.cts.devicepolicy.OrgOwnedProfileOwnerTest#testUserRestrictionsSetOnParentAreNotPersisted
Change-Id: I1faa1f4776deb98e38595a358c01c3fbabfb1840
2020-03-30 20:39:30 +01:00
Adam Bookatz
1efd27cde3 UserSystemPackageInstaller only (un)installs when appropriate
The UserSystemPackageInstaller (USPI) uninstalls system
packages that are not needed, depending on the user type.
When that determination changes (or the feature is disabled)
it can also re-install those packages.
This cl specifies when it is appropriate for USPI to actually
perform the (un)installation.

1.
Introduces uninstallReason: records the reason why a package
was uninstalled from a given user. Right now, the only values
are UNKNOWN and USER_TYPE. The latter indicates that the USPI
system uninstalled the package. If the USPI whitelist changes
(or the USPI feature is disabled), uninstalled packages will
only be installed by USPI if the uninstallReason was USER_TYPE.
Any further uninstalls (e.g. by ManagedProvisioning) will reset
the uninstallReason to UNKNOWN, so USPI will no longer install
such packages in the future.
This prevents USPI from reinstalling system packages that other
mechanisms (such as ManagedProvisioning) uninstalled.

2.
USPI will uninstall a system package if it is blacklisted, but
only if that system package is new, i.e in two circumstances:
a. on first boot
b. on an OTA where the package was not present prior to the OTA

Bug: 143200798
Test: atest UserSystemPackageInstallerTest
Test: Confirmed (un)installations during manually simulated OTAs
Change-Id: Ia0714d1faa8f7c79082f2cc93a92ae36b9a4c918
Merged-In: Ia0714d1faa8f7c79082f2cc93a92ae36b9a4c918
2020-03-28 00:19:37 +00:00
Amit Mahajan
0ed16d7b4b Merge changes from topic "Remove telephony protection level" into rvc-dev
* changes:
  Remove telephony protection level.
  Revert "Allowed telephony to bind network service"
  Revert "add telephony role to some permissions needed by telephony module"
2020-03-18 19:22:36 +00:00
Mariia Sandrikova
04cb4adffb Add a broadcast to manifest-register receivers for power save mode changes.
The android.os.action.POWER_SAVE_MODE_CHANGED broadcast already exists for context-registered receivers, this additionally sends the broadcast to a manifest-registered receiver specified in config_powerSaveModeChangedListenerPackage string.

Bug: 149978380
Test: manual using demo apk
Change-Id: I6a363650da7aee11f8f820a0ff78e7a2ec434fad
2020-03-12 20:51:57 +00:00
Amit Mahajan
7931b2efff Remove telephony protection level.
Test: manual sanity & TH
Bug: 148482594
Change-Id: Iae57fddd400ca7549f32d755d478ee225a5375c5
2020-03-11 16:09:35 -07:00
Evan Severson
2a129f696a Merge "Upgrade permissions on PermissionController version change" into rvc-dev 2020-03-05 17:40:08 +00:00
Evan Severson
0dc24cba2b Upgrade permissions on PermissionController version change
If the version of the permsision controller is different than what was
persisted then call the upgrade controller defined in the permission
controller.

Exempt-From-Owner-Approval: Got verbal approval from an OWNER

Bug: 148595539
Test: Manual; verify the version is persisted in runtime-permissions.xml
              verify the upgrade is run when changing the version number
	      move runtime-permissions.xml to old location, verify works
Change-Id: I873ea4d5a0f1f66fed121e38cc6be62fa046a210
2020-03-04 18:44:56 -08:00
Patrick Baumann
4b4918782c Logs for test & debug blocks
This change adds logging for debuggable and test-only apps when they are
the caller and visibility of another app is blocked due to app
enumeration.

It also adds an adb command to turn logging on and off for other apps to
help developers while debugging issues.

Test: atest AppsFilterTest AppEnumerationTests PackageManagerPerfTest
Bug: 145623959
Change-Id: I1fa930ef40bf08b00c41f51aa25c50b2189395bf
2020-03-04 13:47:33 -08:00
JW Wang
298239b59e Remove unused code (3/n)
(Cherry-picked from 2f777b39b7)

Bug: 149663536
Test: m
Merged-In: Ia233ca642d58b7b6a0984359ea11958f8d9a8ff8
Change-Id: Ia233ca642d58b7b6a0984359ea11958f8d9a8ff8
2020-02-27 14:37:05 +08:00
JW Wang
0757179ff8 Include session id when sending broadcasts (1/n)
The session id will be used by RollbackManager to simplify the code in
searching for rollbacks and sessions.

(Cherry-picked from 503c1aca53)

Bug: 149663536
Test: m

Merged-In: I94003873f4f244fd6543f22bdbe7b6d4a31aceaf
Change-Id: I94003873f4f244fd6543f22bdbe7b6d4a31aceaf
2020-02-27 14:35:56 +08:00
Patrick Baumann
710d720db7 Grants visibility on uri permission grant
When permission is granted to another app via URI, we implicitly grant
visibility to that app of the app ID that that URI resolves to.

Test: atest AppSecurityTests
Fixes: 149781706
Fixes: 145677500
Exempt-From-Owner-Approval: Owner approved prior to cherry-pick
Change-Id: I7c8967a4464fd821e4f95d8eb6c0bcfadadb912e
2020-02-25 15:48:30 +00:00
Julius D'souza
5745b057ec Add background thread notes for package restriction serialisation.
Serialising package restrictions uses synchronous disk access; callers
of these methods should probably use background threads for this.

Bug: 149216360
Test: TreeHugger
Change-Id: I6607a7225bf7daaad8a78e4d1e4c585ba5ac3efc
Signed-off-by: Julius D'souza <jdsouza@google.com>
2020-02-21 12:49:40 -08:00
Suprabh Shukla
1b6ce9ec76 Merge "Let admin block suspend in some cases" 2020-02-21 10:02:06 +00:00