Commit Graph

10760 Commits

Author SHA1 Message Date
Jeff Sharkey
38ffbde17e Root UID can synthesize AttributionSource values.
We trust any incoming value from the system UID, so we should also
trust values coming from the root UID, which includes many shell
commands such as "svc".

Bug: 193659633
Test: atest BluetoothInstrumentationTests:com.android.bluetooth.btservice.AdapterServiceTest --rerun-until-failure 100
Change-Id: Ied07731345f08fc3c4df465a3773e35c8df7c59a
2021-07-14 14:35:17 -06:00
TreeHugger Robot
fee338118c Merge "Validate AttributionSource during unparceling." into sc-dev 2021-07-13 20:57:17 +00:00
Jeff Sharkey
4025c6e7ae Validate AttributionSource during unparceling.
The Bluetooth stack is just one example of an application that makes
self-calls through public APIs, which makes it very difficult to
unconditionally validate AttributionSource arguments.

(The AttributionSource is correctly defined the first time a remote
caller enters the Bluetooth stack, but we've found many cases where
Bluetooth stack calls back into itself without clearing the Binder
identity, causing validation chaos.)

This change is an attempt at gracefully solving this by performing
validation automatically as part of unparceling an AttributionSource
the first time it enters a process.  This strategy isn't perfect,
since transporting an instance inside a Bundle would risk
unparceling much later, possibly long after the calling UID
information has been discarded.  We're rationalizing that this risk
doesn't exist since AttributionSource was only added a few months
ago, and isn't being used in this way.

We still intend to circle back and provide a better strategy in a
future release for transporting AttributionSource across AIDL which
will handle the nuances of self-calls.

Bug: 188391719
Test: atest BluetoothInstrumentationTests
Change-Id: I10b198cfcd8f361e19d52f86deb7f10f05fec891
2021-07-13 12:34:14 -06:00
Svet Ganov
1babd5bf51 Optimize AttributionSource tokens - base
For cases where the attribution soruce doesn't need to be
registered as trusted we are now using a shares static
token since the only purpose of the token in these cases
is for watching the source process dying as opposed to that
and security for registered cases.

bug: 192415943

Test: CtsPermissionTestCases
      CtsPermission2TestCases
      CtsPermission3TestCases
      CtsPermission4TestCases
      CtsPermission5TestCases

Change-Id: I93fde9ca1cacada7929761533dcae11b2736ce1e
2021-07-10 00:24:30 +00:00
Tom Natan
28a6e9f973 Merge "Add support for always_constrain_display_apis flag" into sc-dev 2021-07-08 10:25:09 +00:00
Jeff Sharkey
79b834d47c Tag some "new Binder()" instances to detect leaks.
We've seen evidence of a Binder leak, and our hunch is that it's
caused by one of these anonymous "new Binder()" sites.  Adding
descriptors will help us identify the leak cause.

Bug: 192415943
Test: atest BluetoothInstrumentationTests
Change-Id: I30cd15f084cf50f67edd833b27b853c4b22e1db1
2021-07-07 17:17:07 -06:00
tomnatan
f332106222 Add support for always_constrain_display_apis flag
Bug: 191184114
Test: atest WmTests:SizeCompatTests
Test: atest FrameworksCoreTests:ConstrainDisplayApisConfigTest
Change-Id: Ifc0d48c838216603c00f4cc09d0df2fd145a53a6
2021-07-06 15:18:50 +00:00
Winson Chung
b827a8ac83 Merge "Only provide the resolved activity info to the global intercept window" into sc-dev 2021-07-01 17:33:27 +00:00
Winson Chung
d07dca11ab Only provide the resolved activity info to the global intercept window
- Previously we were adding the activity info to the ClipData, but
  that data is provided to non-intercept windows when the drop happens
  and can be retrieved using reflection. The intention was only to
  provide this activity info to the shell global intercept window
  for invoking split.

  Instead of baking the info into the ClipData, we pass the resolved
  info along side the data and only construct a ClipData with the
  additional info for the intercept window.

Fixes: 191057499
Test: atest DragDropControllerTests
Change-Id: I2ccc9f1f666ff2a388f22b6e6a7b5eea3102964c
2021-07-01 17:32:18 +00:00
Ryan Mitchell
b3659d36b0 Merge changes from topic "revert-15058002-SNQUARIDWJ" into sc-dev
* changes:
  Revert^2 "Apply overlay changes with config change"
  Revert^3 "Deprecate Context#createApplicationContext"
2021-06-30 20:58:43 +00:00
Ryan Mitchell
350c2669d6 Revert^3 "Deprecate Context#createApplicationContext"
This reverts commit cb5a80ea57.

Reason for revert: Was not the cause of the test failure

Fixes: 186622527
Test: atest FrameworksCoreTests:ContextTest
Change-Id: I705854f080200f0465d94a7754e710f05a3ec92c
2021-06-30 15:53:45 +00:00
Jackal Guo
04a45607c1 Merge "Move BootTest to internal test" into sc-dev 2021-06-30 05:39:37 +00:00
TreeHugger Robot
4260ce4100 Merge "Improve javadocs for repeating alarms" into sc-dev 2021-06-30 00:55:07 +00:00
Suprabh Shukla
94f5840bed Improve javadocs for repeating alarms
Specifically, mentioning that the alarm count can only be included with
the alarm if the supplied pending intent is mutable.

Test: make offline-sdk-docs

Fixes: 178413211
Change-Id: I2914bceebeed8b52b0de11d70960aa33e6837b13
2021-06-29 17:34:14 -07:00
TreeHugger Robot
a46f524537 Merge "Double DEFAULT_MAX_LABEL_SIZE_PX to 1000px" into sc-dev 2021-06-29 23:36:33 +00:00
Paul Hobbs
8d440c0566 Merge changes from topic "revert-15058002-SNQUARIDWJ" into sc-dev
* changes:
  Revert^2 "Deprecate Context#createApplicationContext"
  Revert "Version LoadedApk cache using base code path"
  Revert "Apply overlay changes with config change"
2021-06-29 20:36:15 +00:00
Paul Hobbs
cb5a80ea57 Revert^2 "Deprecate Context#createApplicationContext"
Bug: 192242649

5a41b45a85

Change-Id: Idcebd68e0079e7e87de04ae25069b3a9ff72093c
2021-06-29 20:06:45 +00:00
Erik Wolsheimer
48af5ac794 Double DEFAULT_MAX_LABEL_SIZE_PX to 1000px
Fixes: 185869616
Test: Manual
Change-Id: I717d1e7fb7b912a0330ac08742206314c23b32c8
2021-06-29 17:51:07 +00:00
Jackal Guo
c9b3bd434e Move BootTest to internal test
Add a test to ensure that system could boot without exception after
a package is uninstalled with keeping data.

Bug: 188635265
Test: atest PackageManagerServiceHostTests
Change-Id: I190db789ecd8c0ca1ddd87fc1c6ef79593b35492
2021-06-29 12:04:41 +08:00
Patrick Baumann
c6bce70bc2 Fix links in setRequireUserAction docs
This change cleans up a couple of links in the new setRequireUserAction
javadocs to avoid listing the entire permission namespace in the text.

Fixes: 190535637
Test: Builds
Change-Id: I80fff983309963e0a2485510e793f30fcfbec28e
2021-06-29 02:29:53 +00:00
Ryan Mitchell
5a532f6eed Merge changes Icf81845d,Iea54abf3,I98656314 into sc-dev
* changes:
  Apply overlay changes with config change
  Version LoadedApk cache using base code path
  Revert "Deprecate Context#createApplicationContext"
2021-06-27 06:27:58 +00:00
Winson
2d96f8ab31 Remove ParsedIntentInfo CREATOR am: 75214cc510 am: f416e7b485
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/15080916

Change-Id: I8376c9667aa64953551961c3346447ad06c93f10
2021-06-24 22:01:29 +00:00
Winson
f416e7b485 Remove ParsedIntentInfo CREATOR am: 75214cc510
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/15080916

Change-Id: I4210bdd97953331cfe9e7cfbe30422fec91a2eac
2021-06-24 21:45:37 +00:00
Winson
75214cc510 Remove ParsedIntentInfo CREATOR
Its existence allows implicit readParcelable calls to invoke a Parcel
operation with mismatched read/write data sizes, allowing someone to
swap out the data on a reparcel.

Internal classes will use writeIntentInfoToParcel, so this is safe to
remove.

Bug: 191055353

Test: atest com.android.server.pm.test.parsing.parcelling

Change-Id: I44faa635faf8a77894a3dda8adf89c10064e53f1
2021-06-23 18:04:15 +00:00
Ryan Mitchell
5a41b45a85 Revert "Deprecate Context#createApplicationContext"
This reverts commit c54ebba25b.

Bug: 188059515
Test: atest FrameworksCoreTests:ContextTest
Change-Id: I986563142dac135281889e811e6e5219d728d5d1
2021-06-22 22:30:38 -07:00
Winson Chiu
343684b523 Merge "Fix parsing code parcelling errors" into sc-dev 2021-06-22 18:10:43 +00:00
Nikita Ioffe
637be99afd Add sys config to handle apexes that are allowed to be updated
Unlike staged installer check, we can't check if given APEX package is
allowed to be updated at session creation time, since we don't have
knowledge of the package being installed yet. Instead, the check is
implemented in PackageInstallerSession#handleInstall.

Like staged install check, allowed apex update check has similar
exemptions (adb is allowed to update any APEX,
`adb shell pm --bypass-allowed-apex-update-check` makes next install
session bypass the check).

In order to implement these exemptions, a new
INSTALL_DISABLE_ALLOWED_APEX_UPDATE_CHECK flag that can only be set by
system is added. PackageInstallerSession will skip the APEX update
checks if INSTALL_DISABLE_ALLOWED_APEX_UPDATE_CHECK is set.

Bug: 189274479
Test: atest CtsStagedInstallHostTestCases
Test: atest GtsStagedInstallHostTestCases
Test: atest FrameworksServicesTests:SystemConfigTest
Change-Id: I22921a3ac4d43011b565733d7a7183e5cdb4fe80
Merged-In: I22921a3ac4d43011b565733d7a7183e5cdb4fe80
(cherry picked from commit aafaaec0d5)
2021-06-22 13:39:41 +01:00
Jackal Guo
cc057784c1 Merge "Remove unused interface and implementation" into sc-dev 2021-06-22 04:58:58 +00:00
TreeHugger Robot
890daeb051 Merge "Do not canonicalize overlay config test paths" into sc-dev 2021-06-21 23:07:21 +00:00
Makoto Onuki
d97f509923 Merge "Update the javadoc around FGS" into sc-dev 2021-06-21 18:04:37 +00:00
Jackal Guo
9440df9105 Remove unused interface and implementation
Get rid of the unused method to mitigate the potential information
leakage.

Bug: 185124942
Test: atest view-compiler-tests
Test: atest android.view.cts.LayoutInflaterTest
Test: atest -p core/java/android/content/pm
Test: atest -p services/core/java/com/android/server/pm
Test: manually using the PoC in the buganizer to ensure the symptom
      no longer exists.
Change-Id: I5ee7381728a93535849fcf61a1373a5ed9036aa4
2021-06-21 13:08:56 +08:00
TreeHugger Robot
dc86e26f54 Merge "Removing remaining references of ActivityView in fw/base" into sc-dev 2021-06-19 01:23:12 +00:00
Winson
f93af7ef7e Fix parsing code parcelling errors
Address problems reading/writing:
- ParsedComponent mProperties
- ParsingPackageImpl mKeySetMapping
- ParsingPackageImpl mQueriesIntent

Bug: 187043377

Test: atest com.android.server.pm.test.parsing.parcelling

Change-Id: I5b33315f8248d5fcbdef2cc04ecf77cc18dbd7b6
2021-06-18 11:32:51 -07:00
Issei Suzuki
41e7f367ed Merge "Persist Theme name instead of ID for ShortcutInfo" into sc-dev 2021-06-16 14:57:36 +00:00
Rhed Jao
b55a5da715 Merge "Add support to update the throttle time of silent updates" into sc-dev 2021-06-16 07:28:58 +00:00
Antonio Kantek
ec6b2bbd6e Removing remaining references of ActivityView in fw/base
Bug: 179161778
Bug: 191165536
Test: atest CarServiceTest
Change-Id: Ic45091d565e1654c9177183f065e605b0ab0b56d
2021-06-15 11:23:12 -07:00
Makoto Onuki
226923465c Update the javadoc around FGS
Fix: 182901904
Test: build
Test: m offline-sdk-docs && \
  cd /android/sc-dev/out/target/common/docs/offline-sdk/ && \
  python3 -m http.server 8000 && \
  google-chrome http://localhost:8000/
  and check the content

Change-Id: Ic9964c929c8b7d4caf1706d2398d0eb8eaddc70a
2021-06-15 11:17:57 -07:00
Rhed Jao
5294b6b745 Fix wrong targetSdkVersion returned by the ApkLiteParseUtils
Tests failed due to wrong targetSdkVersion returned by the apk lite
parser. The result of targetSdkVersion was overwritten by the
ParsingPackageUtils#computeMinSdkVersion.

Bug: 191063347
Test: atest SilentUpdateTests
Change-Id: If24d2c0eac10922903c5ca86d1b8ec8360d92e12
2021-06-15 07:55:00 +00:00
Ryan Mitchell
015bca79f4 Merge changes I2710cfea,I03fb31ee,Iec512b31 into sc-dev
* changes:
  ResourcesImpl.ThemeImpl NativeAllocationRegistry
  Rebase ThemeImpl rather than reallocate memory
  Sparse native theme representation
2021-06-09 16:35:35 +00:00
Rhed Jao
ab61f0cbdb Add support to update the throttle time of silent updates
To improve the performance of SilentUpdateHostsideTests in the Cts,
this cl adds support to update the throttle time of silent updates
using the pm command. The `pm set-silent-updates-policy
--throttle-time TIME` could be invoked to shorten the testing waiting
time for the repeated silent updates.

Bug: 189506896
Test: atest SilentUpdateHostsideTests
Change-Id: I2f9ab58d16b7f1173f1ee45b6b842ad1f18136a4
2021-06-09 18:55:25 +08:00
Issei Suzuki
42d42335e2 Persist Theme name instead of ID for ShortcutInfo
Change-Id: Iee1e9c1568973f8354e781fcd3de160b8d494921
Bug: 185200798
Test: atest ShortcutManagerTest2 SplashscreenTests
2021-06-09 11:19:41 +02:00
Ryan Mitchell
b063594188 Do not canonicalize overlay config test paths
Some devices may not have certain partitions available and the
OverlayConfigTests use hardcoded paths to test OverlayConfig
functionality. This change ensures that the temporary directory
created to test OverlayConfig has all of the partitions defined in
PackagePartitions#SYSTEM_PARTITIONS within it.

Bug: 190469357
Bug: 187020117
Bug: 187020675
Test: atest OverlayConfigTest
Change-Id: I511e24b7ccfe82e6e89ceea7107457439793ef77
Merged-In: I511e24b7ccfe82e6e89ceea7107457439793ef77
2021-06-08 15:33:03 -07:00
Jing Ji
57532ac939 Merge "Log content provider authority name in traces" into sc-dev 2021-06-08 22:24:04 +00:00
Ryan Mitchell
7b8091ad7c ResourcesImpl.ThemeImpl NativeAllocationRegistry
Native allocations that hold theme data can be several KBs. Registering
the native allocation using NativeAllocationRegistry helps induce the GC
to free the malloced memory sooner and alleviate memory pressure.

Bug: 187883085
Bug: 141198925
Test: atest ResourcesPerfWorkloads
Change-Id: I2710cfea19565ea8aaf2b5fbd7b2c05d9cb17182
2021-06-08 14:25:20 -07:00
Ryan Mitchell
767e34fb17 Rebase ThemeImpl rather than reallocate memory
Memory churn is high when swapping the ResourcesImpl of a Resources
object. Each time Resources#setImpl is invoked, all themes based on
that Resources object are assigned new ThemeImpl objects that are
created using the new ResourcesImpl.

ThemeImpls can only belong to one Theme object, so the old
implementation is discarded and the theme takes ownership of the new
ThemeImp.

This creates performance problems when framework overlays are toggled.
Toggling overlays targeting the framework causes all themes across all
processes to recreate and reallocate all of their themes. By rebasing
the ThemeImpl on the new ResourcesImpl without deallocating the native
theme memory, we reduce churn and produce less garbage that needs to
be garbage collected.

Bug: 141198925
Test: atest libandroidfw_tests
Test: atest ResourcesPerfWorkloads
Change-Id: I03fb31ee09c9cfdbd3c41bcf0b605607dab54ed7
2021-06-08 14:25:18 -07:00
Jing Ji
b8ecbae648 Log content provider authority name in traces
It'll help to debug content provider related performance issues.

Bug: 190416935
Test: Manual - Record perfetto trace & verify auth name is logged.
Test: CtsContentTestCases:android.content.cts
Test: FrameworksCoreTests:android.content
Change-Id: Ifaa1c58135e6aa2a46ecbba92a9266e7d29d5421
2021-06-08 11:00:55 -07:00
TreeHugger Robot
e054e5445b Merge "Fix ApkLite parsing namespace" into sc-dev 2021-06-08 15:48:20 +00:00
Winson
a1e9e63342 Fix ApkLite parsing namespace
An empty string doesn't work, needs to be null.

And configForSplit is not android namespaced.

Bug: 189988327

Test: atest android.appsecurity.cts.IsolatedSplitsTests

Change-Id: I9599c609d69ff1d8bd281975126b81fb35d06247
2021-06-07 18:25:01 -07:00
Winson Chiu
119b05e461 Merge "Handle general and specific cross profile logic" into sc-dev 2021-06-07 23:38:27 +00:00
TreeHugger Robot
4662093318 Merge "Fix ApkLite attribute parsing" into sc-dev 2021-06-07 21:42:17 +00:00