Its existence allows implicit readParcelable calls to invoke a Parcel
operation with mismatched read/write data sizes, allowing someone to
swap out the data on a reparcel.
Internal classes will use writeIntentInfoToParcel, so this is safe to
remove.
Bug: 191055353
Test: atest com.android.server.pm.test.parsing.parcelling
Change-Id: I44faa635faf8a77894a3dda8adf89c10064e53f1
Unlike staged installer check, we can't check if given APEX package is
allowed to be updated at session creation time, since we don't have
knowledge of the package being installed yet. Instead, the check is
implemented in PackageInstallerSession#handleInstall.
Like staged install check, allowed apex update check has similar
exemptions (adb is allowed to update any APEX,
`adb shell pm --bypass-allowed-apex-update-check` makes next install
session bypass the check).
In order to implement these exemptions, a new
INSTALL_DISABLE_ALLOWED_APEX_UPDATE_CHECK flag that can only be set by
system is added. PackageInstallerSession will skip the APEX update
checks if INSTALL_DISABLE_ALLOWED_APEX_UPDATE_CHECK is set.
Bug: 189274479
Test: atest CtsStagedInstallHostTestCases
Test: atest GtsStagedInstallHostTestCases
Test: atest FrameworksServicesTests:SystemConfigTest
Change-Id: I22921a3ac4d43011b565733d7a7183e5cdb4fe80
Merged-In: I22921a3ac4d43011b565733d7a7183e5cdb4fe80
(cherry picked from commit aafaaec0d5)
Get rid of the unused method to mitigate the potential information
leakage.
Bug: 185124942
Test: atest view-compiler-tests
Test: atest android.view.cts.LayoutInflaterTest
Test: atest -p core/java/android/content/pm
Test: atest -p services/core/java/com/android/server/pm
Test: manually using the PoC in the buganizer to ensure the symptom
no longer exists.
Change-Id: I5ee7381728a93535849fcf61a1373a5ed9036aa4
Tests failed due to wrong targetSdkVersion returned by the apk lite
parser. The result of targetSdkVersion was overwritten by the
ParsingPackageUtils#computeMinSdkVersion.
Bug: 191063347
Test: atest SilentUpdateTests
Change-Id: If24d2c0eac10922903c5ca86d1b8ec8360d92e12
To improve the performance of SilentUpdateHostsideTests in the Cts,
this cl adds support to update the throttle time of silent updates
using the pm command. The `pm set-silent-updates-policy
--throttle-time TIME` could be invoked to shorten the testing waiting
time for the repeated silent updates.
Bug: 189506896
Test: atest SilentUpdateHostsideTests
Change-Id: I2f9ab58d16b7f1173f1ee45b6b842ad1f18136a4
Some devices may not have certain partitions available and the
OverlayConfigTests use hardcoded paths to test OverlayConfig
functionality. This change ensures that the temporary directory
created to test OverlayConfig has all of the partitions defined in
PackagePartitions#SYSTEM_PARTITIONS within it.
Bug: 190469357
Bug: 187020117
Bug: 187020675
Test: atest OverlayConfigTest
Change-Id: I511e24b7ccfe82e6e89ceea7107457439793ef77
Merged-In: I511e24b7ccfe82e6e89ceea7107457439793ef77
Native allocations that hold theme data can be several KBs. Registering
the native allocation using NativeAllocationRegistry helps induce the GC
to free the malloced memory sooner and alleviate memory pressure.
Bug: 187883085
Bug: 141198925
Test: atest ResourcesPerfWorkloads
Change-Id: I2710cfea19565ea8aaf2b5fbd7b2c05d9cb17182
Memory churn is high when swapping the ResourcesImpl of a Resources
object. Each time Resources#setImpl is invoked, all themes based on
that Resources object are assigned new ThemeImpl objects that are
created using the new ResourcesImpl.
ThemeImpls can only belong to one Theme object, so the old
implementation is discarded and the theme takes ownership of the new
ThemeImp.
This creates performance problems when framework overlays are toggled.
Toggling overlays targeting the framework causes all themes across all
processes to recreate and reallocate all of their themes. By rebasing
the ThemeImpl on the new ResourcesImpl without deallocating the native
theme memory, we reduce churn and produce less garbage that needs to
be garbage collected.
Bug: 141198925
Test: atest libandroidfw_tests
Test: atest ResourcesPerfWorkloads
Change-Id: I03fb31ee09c9cfdbd3c41bcf0b605607dab54ed7
It'll help to debug content provider related performance issues.
Bug: 190416935
Test: Manual - Record perfetto trace & verify auth name is logged.
Test: CtsContentTestCases:android.content.cts
Test: FrameworksCoreTests:android.content
Change-Id: Ifaa1c58135e6aa2a46ecbba92a9266e7d29d5421
An empty string doesn't work, needs to be null.
And configForSplit is not android namespaced.
Bug: 189988327
Test: atest android.appsecurity.cts.IsolatedSplitsTests
Change-Id: I9599c609d69ff1d8bd281975126b81fb35d06247
Since developers can use a BluetoothDevice object can make remote
calls, it needs to have an accurate AttributionSource. Previous CLs
had updated many places where these BluetoothDevice instances were
passed across Binder interfaces, but this change updates several
remaining locations which had been missed.
Introduces new "Attributable" marker interface to offer consistent
tooling when applying AttributionSource updates.
Bug: 187097694
Test: atest BluetoothInstrumentationTests
Change-Id: Icad3b9726591f0fbad58a493cefa5a0af7648280
The method is used in ClasspathDeviceTest to filter out native .so
files, as it only cares about java classes.
Bug: 189347015
Bug: 187823488
Test: m
Change-Id: Id4d41ddef1cddbecd7f7028e28da4040cdfd5c26
Attribution source is the abstraction to capture the data
flows for private data across apps. Checking permissions
for an attribution source does this for all apps in the
chain that would receive the data as well as the relevant
app ops are checked/noted/started as needed.
Teach speech recognition service about attribution
chains. If an implementation does nothing the OS
would enforce permisisons and do blame as always.
This apporach leads to double blaming and doesn't
support attribition chains where app calls into
the default recognizer which calls into the on
device recognizer (this nests recursively). If the
implementer takes advantage of the attribution chain
mechanims the permissions for the entire chain are
checked at mic access time and all apps are blamed
only once.
Fixed a few bugs around finishing ops for attribution
chains. Also ensured that any app death in a started
attribution chain would lead to finishing the op for
this app
bug: 158792096
Test: (added tests for speech reco)
atest CtsMediaTestCases
atest CtsPermissionTestCases
atest CtsPermission2TestCases
atest CtsPermission3TestCases
atest CtsPermission4TestCases
atest CtsPermission5TestCases
atest CtsAppOpsTestCases
atest CtsAppOps2TestCases
Merged-In: Ic92c7adc14bd2d135ac13b96f17a1b393dd562e4
Change-Id: Ic92c7adc14bd2d135ac13b96f17a1b393dd562e4
When an application is incrementally installed, and a resources
operation fails due to the resources not being fully present,
the app should crash instead of swallowing the error and
returning default values to not alter the experience of
using the application.
Disable IncFsFileMap protections on ApkAssets that are a part of the
application that is running (base and splits).
Bug: 187220960
Test: atest ResourcesHardeningTest
Change-Id: Ibc67aca688720f983c7c656f404593285a54999b
Previous resolve had a weird behavior where a specific IntentFilter
configured cross profile filter configuration (as opposed to a general
configuration requiring allow_parent_profile_app_linking to be toggled)
would be added into the candidate set, which the code assumed was only
for the user ID being queried.
Instead, this specific cross profile resolution needs to be kept
separate as a different user, and applied if when the general
resolution is unavailable.
This makes both specific and general branchs assign the same
CrossProfileDomainInfo that domain verification was already checking,
and so should allow the logic to work in cases where the specific info
was previously dropped.
Bug: 189222753
Test: CtsDomainVerificationDeviceMultiUserTestCases
Change-Id: I0ac12d7125a7c5a9d4b9b35692d13928cbeb84e3
When a string cannot be retrieved from a StringBlock due to pages of
the StringPool missing, rather than throwing an
IndexOutOfBoundsException, compute a default value rather that
abides by the API contacts of the functions that use the StringBlock.
IndexOutOfBoundsExceptions are not really documented as a possible
exception that can be thrown from APIs that use StringBlock because
it indicates that the binary resource table was built incorrectly.
Returning default values is much less likely to break applications
that fetch the resources of incrementally installed applications than
throwing IndexOutOfBoundsExceptions where they would normally not be
expected.
Bug: 188174746
Test: atest ResourcesHardeningTest
Change-Id: I58fe754fb446fefc031ddba19e290830fdd6d015
We ended up defaulting to this behavior, so we no longer need this flag.
Bug: 189235490
Bug: 188057823
Test: Build
Change-Id: I62e383978d9b168657f2eac2e6bf4337a91b909b