Commit Graph

6512 Commits

Author SHA1 Message Date
Svetoslav Ganov
77591d9942 Merge "Runtime permission attribution improvements" into sc-dev am: a6c3d6ad39
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/13692058

Change-Id: Ibad155ee212f6e71800e288a44bbed6012d32838
2021-03-29 21:05:00 +00:00
Svet Ganov
8d2ed50604 Runtime permission attribution improvements
When an app is proxying access to runtime permission protected
data it needs to check whether the calling app has a permission
to the data it is about to proxy which leaves a trace in app ops
that the requesting app perofmed a data access. However, then the
app doing the work needs to get the protected data itself from the
OS which access gets attributed only to itself. As a result there
are two data accesses in app ops where only the first one is a
proxy one that app A got access to Foo through app B - that is the
one we want to show in the permission tracking UIs - and one
for the data access - that is the one we would want to blame on
the calling app, and in fact, these two accesses should be one -
that app A accessed Foo though B. This limitation requires fragile
one off workarounds where both accesses use the same attribution
tag and sys UI has hardcoded rules to dedupe. Since this is not
documented we cannot expect that the ecosystem would reliably
do this workaround in apps that that the workaround in the OS
would be respected by every OEM.

This change adds a mechaism to resolve this issue. It allows for
an app to create an attribution context for another app and then
any private data access thorugh this context would result in a
single app op blame that A accessed Foo though B, i.e. we no longer
have double accounting. Also this can be nested through apps, e.g.
app A asks app B which asks app C for contacts. In this case app
B creates an attribution context for app A and calls into app C
which creates an attribution context for app B. When app C gets
contacts the entire attribution chain would get a porper, single
blame: that C accessed the data, that B got the data from C, and
that A got the data form B. Furthermore, this mechanism ensures
that apps cannot forget to check permissions for the caller
before proxying private data. In our example B and C don't need
to check the permisisons for A and B, respectively, since the
permisisons for the entire attribution chain are checked before
data delivery. Attribution chains are not forgeable preventing
a bad actor to create an arbitrary one - each attribution is
created by the app it refers to and points to a chain of
attributions created by their corresponding apps.

This change also fixes a bug where all content provider accesses
were double counted in app ops due to double noting. While at
this it also fixes that apps can now access their own last ops.
There was a bug where one could not pass null getting the attributed
ops from a historical package ops while this is a valid use case
since if there is no attribution everything is mapped to the null
tag. There were some app op APIs not being piped thorough the app
ops delegate and by extension through the app ops policy. Also
now that we have nice way to express the permission chain in a
call we no longer need the special casing in activity manager to
handle content provider accesses through the OS. Fixed a bug
where we don't properly handle the android.os.shell calls with
an invlaid tag which was failing while the shell can do any tag.

Finally, to ensure the mechanims is validated and works end-to-end
we are adding support for a voice recognizer to blame the client
app for the mic access. The recognition service can create a blaming
context when opening the mic and if the mic is open, which would
do all permission checks, we would not do so again. Since changes
to PermissionChercker for handling attribution sources were made
the CL also hooks up renounced permissoins in the request permission
flow and in the permission checks.

bug:158792096
bug:180647319

Test:atest CtsPermissionsTestCases
     atest CtsPermissions2TestCases
     atest CtsPermissions3TestCases
     atest CtsPermissions4TestCases
     atest CtsPermissions5TestCases
     atest CtsAppOpsTestCases
     atest CtsAppOps2TestCases

Change-Id: Ib04585515d3dc3956966005ae9d94955b2f3ee08
2021-03-29 16:49:33 +00:00
TreeHugger Robot
86f1dd7048 Merge "[Settings] add readable tests to presubmit" into sc-dev am: 894cde1030
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/13988647

Change-Id: Ibf61eb518156934815b1518b7da04ca4e9d2166e
2021-03-29 12:04:53 +00:00
TreeHugger Robot
894cde1030 Merge "[Settings] add readable tests to presubmit" into sc-dev 2021-03-29 11:52:22 +00:00
Kriti Dang
e713ee6c60 Merge changes from topic "cherrypick-Display settings HDR formats-mumvl547ah" into sc-dev
* changes:
  Handling Number Format Exception in DiscreteValueIntegerListValidator
  Hdr format settings [Backend]
2021-03-28 12:25:32 +00:00
Matt Casey
b1f83230d2 Merge "Revert "Add setting for touch gesture and long-press home assist..."" into sc-dev am: 304bd59b3e
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/13998375

Change-Id: I6ad23bd8cab8c7ebf861d9dd479b7dd4c28dcfc4
2021-03-25 21:39:32 +00:00
Matt Casey
304bd59b3e Merge "Revert "Add setting for touch gesture and long-press home assist..."" into sc-dev 2021-03-25 21:28:34 +00:00
Matt Casey
fabc9f6f27 Revert "Add setting for touch gesture and long-press home assist..."
Revert "Hide long-press home animation when disabled by setting"

Revert submission 13958909-mrcasey-lph

Reason for revert: Possible test breakage b/183684181
Reverted Changes:
Iaaf39e76a:Hide long-press home animation when disabled by se...
I24ee67cf1:Add setting for touch gesture and long-press home ...

Change-Id: Ieb43607a8010b843fc643979953a266cbb84788f
2021-03-25 21:19:00 +00:00
Songchun Fan
d32eb9de2c Merge "[Settings] keys with @TestApi need to have @Readable" into sc-dev am: 1d70937fe7
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/13985782

Change-Id: I184d505dd850e299c8c16b7b27195637ffd40f3a
2021-03-25 15:45:27 +00:00
Songchun Fan
1d70937fe7 Merge "[Settings] keys with @TestApi need to have @Readable" into sc-dev 2021-03-25 15:44:33 +00:00
Kriti Dang
b4775b02a7 Hdr format settings [Backend]
Added new APIs to DisplayManager to set the user disabled HDR formats,
and get/set if user disabled formats should be ignored or not.
These new settings are stored in Settings.Global.
Modified the implementation of Display#getHdrCapabilities to not return
the formats disabled by user.

Bug: 172905874
Test: atest CtsDisplayTestCases
Change-Id: I4841af251ee0e4938614b154d0c5239814ea7cd9
Merged-In: I4841af251ee0e4938614b154d0c5239814ea7cd9
2021-03-25 12:41:35 +00:00
Matt Casey
5c255ac169 Merge "Add setting for touch gesture and long-press home assistant invocations" into sc-dev am: af29800df0
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/13958909

Change-Id: I98f7432728516ff0df432747d3fc2bd97a3bae9b
2021-03-25 12:21:27 +00:00
Matt Casey
af29800df0 Merge "Add setting for touch gesture and long-press home assistant invocations" into sc-dev 2021-03-25 12:15:09 +00:00
Sudheer Shanka
5586cb3965 Merge "Add DeviceConfig namespace for media." into sc-dev am: d2cd698106
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/13969015

Change-Id: I5c4eb8dc3156ef295bf566c394974f13433f54bd
2021-03-25 07:07:48 +00:00
Sudheer Shanka
d2cd698106 Merge "Add DeviceConfig namespace for media." into sc-dev 2021-03-25 06:56:08 +00:00
Ahaan Ugale
fb7b11b313 Merge "Introduce a default Voice IME concept." into sc-dev am: dadfd22e74
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/13944370

Change-Id: I756c008620895b4d2593a8a1d7726c3cfb724754
2021-03-25 03:04:57 +00:00
Ahaan Ugale
dadfd22e74 Merge "Introduce a default Voice IME concept." into sc-dev 2021-03-25 02:59:41 +00:00
Winson Chiu
667e32a346 Merge "Expose the open by default settings screen to apps" into sc-dev am: 5ae11b4a58
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/13986993

Change-Id: Ib16bab6355c4a5be2efd053438f1841e509d50a8
2021-03-25 02:36:01 +00:00
Winson Chiu
5ae11b4a58 Merge "Expose the open by default settings screen to apps" into sc-dev 2021-03-25 02:20:37 +00:00
Ahaan Ugale
9672b2e58c Introduce a default Voice IME concept.
This is configured by the system config resource,
config_systemSpeechRecognizer, which also provides the default
VoiceRecognitionService and the holder for the SYSTEM_SPEECH_RECOGNIZER
role.

InputMethodManagerService updates the new DEFAULT_VOICE_INPUT_METHOD
setting and handles changes to the config_systemSpeechRecognizer value.

No updates are made through the Settings UpgradeController because any
updates that would be needed are already handled by the logic for config
value changes.

Testing:
1. Enable DEBUG logging in InputMethodManagerService.
2. $ m -j && adb remount && adb shell stop && adb sync && adb shell start
3. $ adb shell settings get secure enabled_input_methods; \
 adb shell settings get secure default_input_method; \
 adb shell settings get secure disabled_system_input_methods; \
 adb shell settings get secure default_voice_input_method
4. Check logcat to make sure nothing looks suspect.

Cases tested:
- IME wasn't already in the enabled IME list
- IME was already enabled
- no value for config_systemSpeechRecognizer
- new user added
- locale changed
- config package doesn't have an IME
- update without config value, then set a config value
- config value updated (when both values had valid IMEs)
- combinations of the above cases, as appropriate

Bug: 175480456
Test: manual - see above
Test: atest InputMethodUtilsTest
Test: atest CtsInputMethodTestCases --retry-any-failure
Change-Id: I1abdc145e3d5969fbb69811df2ca2e35c7a177e1
2021-03-24 23:07:21 +00:00
Songchun Fan
3f08960272 [Settings] add readable tests to presubmit
This will enforce the readable tests for changes made to Settings.java.

Test: atest
BUG: 183530680
Change-Id: Ie91350b29c10868cecd2c2fe4eba378278b3cb23
2021-03-24 22:37:44 +00:00
Winson
b5ba585b39 Expose the open by default settings screen to apps
With the changes for app links v2, apps need a way to link users into
the domain selection screen if the app relies on opening web links
for some functionality.

To achieve that, this exposes the existing action,
ACTION_APP_OPEN_BY_DEFAULT_SETTINGS, from android.provider.Settings
and removes the permission needed to launch the relevant Activity,
since it's no longer required.

Note that this will also require a change to remove the enforcement
from the Activity declaration, which will be a follow up.

Bug: 178648367

Test: none, unhide API

Change-Id: I73231b9b4686ee67490ffe1526542b2f59c8089b
2021-03-24 12:43:06 -07:00
Songchun Fan
da9e388d20 [Settings] keys with @TestApi need to have @Readable
This allows them to be accessed by test apps.

BUG: 183223092
Test: atest CtsAppSecurityHostTestCases:android.appsecurity.cts.ReadableSettingsFieldsTest#testSecurePublicSettingsKeysAreReadable
Change-Id: I2bdcab2d9279f5ef944b17896c7b31b84ca8dc81
2021-03-24 18:15:53 +00:00
Kriti Dang
9abafa09f6 Merge "Hdr format settings [Backend]" 2021-03-24 15:54:18 +00:00
Matt Casey
662f32ddc2 Add setting for touch gesture and long-press home assistant invocations
No UI, just setting storage and the code to honor that setting.

Bug: 182216673
Bug: 182220287
Test: manual + atest NavigationBarTest
Change-Id: I24ee67cf196d7ae698a731e00a9eb5a726eddb24
2021-03-24 11:49:38 -04:00
Sudheer Shanka
36cf320611 Add DeviceConfig namespace for media.
Bug: 174699413
Test: manual
Change-Id: I9c749f34931f9197e428ae9d5044062d705efed6
2021-03-24 06:59:23 -07:00
Abhijeet Kaur
7591e2d06a Make getExternalStorageMountMode as SystemApi
Secondary volumes are FUSE mounted, whereas Android/data and Android/obb
on primary volumes are not FUSE mounted. Access to these private app
directories on primary volumes is restricted using the mount modes, but
access for these on secondary volumes need to be regulated by
MediaProvider.

Make getExternalStorageMountMode as SystemApi so that MediaProvider
can leverage the same mount logic for Secondary volumes.
Expose relevant mount modes as SystemApi as well.

This change saves us the maintenance overhead for Secondary volumes for
Android S+. Otherwise we would have to check if an app is a signature
app through APIs which would basically be the duplication for the
logic in StorageManagerService.java.

Expose ExternalStorageProvider and downloads Authority for MediaProvider
to rely only on APIs. This is also required for CDD modifications that
these 2 providers are given exceptional access to private app dirs.

Bug: 175796984
Bug: 173505864
Bug: 173505864
Test: atest DownloadProviderTest
Test: atest CtsScopedStorageHostTest
Test: atest android.scopedstorage.cts.host.PublicVolumeHostTest#testCheckInstallerAppAccessToObbDirs
Test: atest android.scopedstorage.cts.host.PublicVolumeHostTest#testCantAccessOtherAppsExternalDirs
Change-Id: I51bc7bd3f355fadd9de56ac267469c2352eb0ffa
Merged-In: I51bc7bd3f355fadd9de56ac267469c2352eb0ffa
2021-03-24 09:28:27 +00:00
Xiaoyu Jin
c85389acdd Merge "Add DeviceConfig namespace for AppSearch" into sc-dev am: d988ccfa8e
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/13959213

Change-Id: I7f60d86e559c8ae46e976d23c1533c61e30d9841
2021-03-24 06:19:46 +00:00
Peter Wang
e8a9d666b9 Merge "[API Review] Change ACTION_MANAGE_ALL_SIM_PROFILE_SETTINGS API" into sc-dev am: 3c8304207b
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/13807440

Change-Id: Ief71b115a7ff011f60e11e1923cb3d3c8a06d40c
2021-03-24 06:10:27 +00:00
Rambo Wang
f226b0762e Merge changes from topics "ServiceState#dataRegState", "ServiceState#duplexMode" am: c289c9b0a2 am: 506d5c92c3 am: 507e3b9dcd am: 6d768fb7d6
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1636779

Change-Id: Ic1b0f034772ec1c7f38571684b8675727a0b03c5
2021-03-24 06:07:35 +00:00
Rambo Wang
16750636fd Public ServiceState#duplexMode in telephony provider am: 4481b5181e am: b336d92aa7 am: 57456a7152 am: de0c5fa090
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1638159

Change-Id: Ic886e9ad3620344cf96afb62ecd7242b26157ab3
2021-03-24 06:07:29 +00:00
Xiaoyu Jin
d988ccfa8e Merge "Add DeviceConfig namespace for AppSearch" into sc-dev 2021-03-24 05:29:12 +00:00
Jacky Kao
c9f94813f9 Merge "Logs magnification feature behavior. (2/2)." 2021-03-24 05:08:59 +00:00
Peter Wang
3c8304207b Merge "[API Review] Change ACTION_MANAGE_ALL_SIM_PROFILE_SETTINGS API" into sc-dev 2021-03-24 03:24:20 +00:00
Rambo Wang
6d768fb7d6 Merge changes from topics "ServiceState#dataRegState", "ServiceState#duplexMode" am: c289c9b0a2 am: 506d5c92c3 am: 507e3b9dcd
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1636779

Change-Id: Ic8faff9d023b492da5eb7e31e281ddfbf49c8d1d
2021-03-24 03:01:54 +00:00
Rambo Wang
de0c5fa090 Public ServiceState#duplexMode in telephony provider am: 4481b5181e am: b336d92aa7 am: 57456a7152
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1638159

Change-Id: I2f53c2305075011904718ba5a81279875dc07235
2021-03-24 03:01:39 +00:00
John Li
bb9e119844 Merge "Add Settings flag for Transform." into sc-dev 2021-03-24 02:21:00 +00:00
TreeHugger Robot
c19c8d77ff Merge "Enable RESTRICTED bucket." into sc-dev am: 77cbe77beb
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/13520216

Change-Id: I9c7fbe6587c58663918d1f7eb0b460ce946fe367
2021-03-24 01:03:09 +00:00
TreeHugger Robot
074666c5a0 Merge "Add support for selected contacts device to device sharing." into sc-dev 2021-03-23 22:11:22 +00:00
Xiaoyu Jin
eefbf02162 Add DeviceConfig namespace for AppSearch
Adds a new namespace to DeviceConfig for features
relating to AppSearch.

Bug: 173532925
Test: build
Change-Id: I5887899d9292bf88ea5007d94c20b8690ee73872
2021-03-23 13:08:43 -07:00
TreeHugger Robot
77cbe77beb Merge "Enable RESTRICTED bucket." into sc-dev 2021-03-23 18:58:14 +00:00
Kriti Dang
4f7df5b8aa Hdr format settings [Backend]
Added new APIs to DisplayManager to set the user disabled HDR formats,
and get/set if user disabled formats should be ignored or not.
These new settings are stored in Settings.Global.
Modified the implementation of Display#getHdrCapabilities to not return
the formats disabled by user.

Bug: 172905874
Test: atest CtsDisplayTestCases
Change-Id: I4841af251ee0e4938614b154d0c5239814ea7cd9
2021-03-23 18:10:34 +01:00
Rambo Wang
cff9760e07 Export ServiceState#DataRegState into telephony provider
Keep ServiceState#getDataRegState hide. Apps can get the same
info from telephony provider without loation permission.

Bug: 182601774
Test: atest com.android.phone.ServiceStateProviderTest
Change-Id: I1ba72a5b767761d2f7bd1b52459a0c9d101061a2
2021-03-23 09:33:21 -07:00
Rambo Wang
4481b5181e Public ServiceState#duplexMode in telephony provider
ServiceState#getDuplexMode is a public API. Expose the same
info through telephony provider to let applications retreive
it without location permission.

Bug: 182601774
Test: atest com.android.phone.ServiceStateProviderTest
Change-Id: I19128c938993f351533aca9a8e1a1356e21eb30e
2021-03-23 09:27:42 -07:00
Rambo Wang
9e92686d87 Merge "Expose ServiceState#getDataNetworkType in telephony provider" am: 9446a5239f am: 11264381a4 am: ff97f102cc am: 8fadaef00c
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1639370

Change-Id: I819cc7cc59391113747b338bbce740fdb9c0bdfd
2021-03-23 16:11:37 +00:00
Rambo Wang
8fadaef00c Merge "Expose ServiceState#getDataNetworkType in telephony provider" am: 9446a5239f am: 11264381a4 am: ff97f102cc
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1639370

Change-Id: Ib2c5d3ec7b28e37d1fa7426aa9e0a1bc7730b9e8
2021-03-23 15:57:25 +00:00
Grace Jia
2bd23cfbcc Add support for selected contacts device to device sharing.
Bug: 163085177
Test: CTS tests
Change-Id: I4f6da463a29ba9cf067d36941a9b4e584012c817
Merged-In: I4f6da463a29ba9cf067d36941a9b4e584012c817
2021-03-23 15:51:24 +00:00
Grace Jia
7fd18ac469 Merge "Add support for selected contacts device to device sharing." 2021-03-23 15:50:52 +00:00
Abhijeet Kaur
839aa85298 Make getExternalStorageMountMode as SystemApi
Secondary volumes are FUSE mounted, whereas Android/data and Android/obb
on primary volumes are not FUSE mounted. Access to these private app
directories on primary volumes is restricted using the mount modes, but
access for these on secondary volumes need to be regulated by
MediaProvider.

Make getExternalStorageMountMode as SystemApi so that MediaProvider
can leverage the same mount logic for Secondary volumes.
Expose relevant mount modes as SystemApi as well.

This change saves us the maintenance overhead for Secondary volumes for
Android S+. Otherwise we would have to check if an app is a signature
app through APIs which would basically be the duplication for the
logic in StorageManagerService.java.

Expose ExternalStorageProvider and downloads Authority for MediaProvider
to rely only on APIs. This is also required for CDD modifications that
these 2 providers are given exceptional access to private app dirs.

Bug: 175796984
Bug: 173505864
Bug: 173505864
Test: atest DownloadProviderTest
Test: atest CtsScopedStorageHostTest
Test: atest android.scopedstorage.cts.host.PublicVolumeHostTest#testCheckInstallerAppAccessToObbDirs
Test: atest android.scopedstorage.cts.host.PublicVolumeHostTest#testCantAccessOtherAppsExternalDirs
Change-Id: I51bc7bd3f355fadd9de56ac267469c2352eb0ffa
2021-03-23 11:18:17 +00:00
John Li
8929a2e804 Add Settings flag for Transform.
Bug: 177299699
Test: manual
Change-Id: I4947117b6bb11678e3ad761204d720354b9e73ae
Merged-In: I4947117b6bb11678e3ad761204d720354b9e73ae
2021-03-23 07:50:22 +00:00