The refactoring in S unintendedly introduced a change that allowed
signature|privileged to be granted to platform-signed privileged apps
without being in the allowlist XML, so we should revert to the old
behavior.
The refactoring was done in the hope that we can have one step that
handles privileged permission granting. However upon retrospection, we
have to do this in two separate steps because the privapp permission
allowlist should always be enforced first.
This change reverts to the old behavior by looking at both the current
code and the R source code, then extracts the privapp permission
enforcement as a separate step that happens first, to be used by both
signature and the new internal permission protection.
Also simplified the check about privileged permission, because vendor
privileged permission is always a privileged permission, as made sure
in PermissionInfo.fixProtectionLevel().
In the mean time, added the missing privapp permission allowlist entry
for Settings and RESTART_WIFI_SUBSYSTEM for device to boot.
Fixes: 179309876
Test: manual
Change-Id: I93cfe7a4621fc5ac65229d42c7a8ebd825ae8ae5
Add a statsd puller to record CPU usage of system server threads: all
and binder.
Bug: 173227907
Test: cmd stats pull-source 10098
Test: atest CpuStatsTests
Change-Id: I0d5c6e1e8d772bae6efdcbe62767932cc2fefe02
The system server inherits the ELF note from the Zygote, but should also
be able to be overwritten by the system property. This needs to be
manually parsed.
Bug: 172365548
Test: 'adb shell setprop arm64.memtag.process.system_server 123' \
Test: ... kill the system_server, and and look in logcat for
Test ... "Unknown memory tag level for the system server".
Test: 'adb shell setprop arm64.memtag.process.system_server sync' \
Test: ... kill the system_server, and look in logcat for
Test: ... "SetHeapTaggingLevel: tag level set to 3".
Change-Id: Icda4ff141646086ae85d751b8af9b1fe94bfd7b5
This CL make UpdatableFontDir support multi font update in transaction.
The public / shell API is TBD.
Bug: 179103383
Test: atest CtsGraphicsTestCases:FontManagerTest
Test: atest FrameworksServicesTests:PersistentSystemFontConfigTest
Test: atest FrameworksServicesTests:UpdatableFontDirTest
Test: atest UpdatableSystemFontTest
Change-Id: If9474a8ab81fe194b2d76080a4b066131fcd9e44
Completely deletes all the code for v1 of domain verification,
delegating everything to the new DomainVerificationService.
Exempt-From-Owner-Approval: Already approved by owners on main branch
Bug: 171251883
Test: none, removal of effectively dead code
Change-Id: Ib222ccd46019c1c28b402c0f68466077b62871c1
Includes the request class sent to the verification agent and the 2
data classes returned by the to-be-added DomainVerificationManager.
Exempt-From-Owner-Approval: Already approved by owners on main branch
Bug: 163565712
CTS-Coverage-Bug: 179382047
Test: atest DomainVerificationCoreApiTest
Change-Id: If9f1b987f0d06c930f6c44b58af101b83947acb9
Moves everything to com.android.server.pm.intent.verify.legacy, in
preparation for replacement with new classes.
No functional changes were made, although the code may be slightly
slower since lambdas are now passed around to do locking.
Eventually the entire legacy package will be deleted. Any attempts at
backwards compatbility will involve a brand new wrapper of the v1 APIs
which delegate into the v2 methods.
Exempt-From-Owner-Approval: Already approved by owners on main branch
Bug: 163565078
Test: atest IntentFilterVerificationTest
Test: manual, verify with `dumpsys package d` that an app auto verifies
Change-Id: Id7d428b939cab6dd887567abcc7ba0e8f3fb7638
The flow has been replaced by @ChangeId ALLOW_TEST_API_ACCESS, making
old approach obsolete.
Bug: 147113465
Test: atest CameraEvictionTest#testBasicCamera2ActivityEviction
Merged-In: I0bf109fa78212d6d71ba85d25f80e27e8e7cd900
Merged-In: I0e58b6924744590afaadec6a6230aa9d552b2f6f
Change-Id: I9cf8f80abb0165d4aefbf943bade57f5e031904b
Exempt-From-Owner-Approval: cp
Bug: 178391911,147113465
(cherry picked from commit a27cd30535)