Commit Graph

16688 Commits

Author SHA1 Message Date
Andrei-Valentin Onea
a22612eb94 Merge changes from topic "ignore-vendor-apex-allowlists"
* changes:
  Ignore vendor apex priv-app permission allowlists
  Add test for parsing apex allowlists
  Ignore prebuilt shared library if it doesn't exist on device
  Rename updatable-library to apex-library
  Parse new xml attributes used for updatable shared libraries
  Create XML parser only once.
2022-03-01 15:15:56 +00:00
Treehugger Robot
990ac01f71 Merge "Add a runtime check to ensure that system server jars are prefetched." 2022-02-25 13:44:34 +00:00
Jiakai Zhang
8db9757f08 Add a runtime check to ensure that system server jars are prefetched.
We prefetch standalone system server jars in ZygoteInit based on the
STANDALONE_SYSTEMSERVER_JARS environment variable, so that they can take
the advantage of AOT compilation. This CL adds a check to disallow jars
that are not prefetched, which reminds developers to make appropriate
changes so that their jars will be in the environment variable.

Bug: 203198541
Test: 1. Build a system image.
  2. The device boots.
Test: 1. Remove an entry from PRODUCT_APEX_STANDALONE_SYSTEM_SERVER_JARS
  2. Build a system image.
  3. The device does not boot and encounters the following error:
     java.lang.RuntimeException: Creating a ClassLoader from /apex/com.android.wifi/javalib/service-wifi.jar is not allowed. Please make sure that the jar is listed in `PRODUCT_APEX_STANDALONE_SYSTEM_SERVER_JARS` in the Makefile and added as a `standalone_contents` of a `systemserverclasspath_fragment` in `Android.bp`.
Change-Id: I275d75ac37194a4d8fd491529b7cdb697dc04e37
Merged-In: I275d75ac37194a4d8fd491529b7cdb697dc04e37
(cherry picked from commit 418ab8212c)
2022-02-24 16:21:28 +00:00
Bernardo Rufino
cccb1b78d9 Add safer Bundle APIs and deprecated old ones
Add safer Bundle APIs that take an extra Class<T> argument that checks
that the type about to be deserialized is a child of the type passed in
parameter *before* actually deserializing it, while also deprecating old
APIs.

This allows use to reap the benefits of the new typed Parcel APIs and
enhances security.

Only the APIs that could involve custom object injection are modified.
So, besides the obvious ones that have that design (eg.
readParcelableList()), subtler cases such as readIntegerArrayList()
could result in custom object deserialization, and since it's all
generics, even the casting inside Bundle wouldn't fail, only after the
client unpacked the list items would it blow up. Now those are checked
beforehand.

Since Bundle always calls Parcel.readValue() under the hood (instead of
specialized APIs such as readParcelable() etc), we had to augment that
method (that's used by LazyValue when retrieving the item) to accept
item types now for containers, which I implemented as a vararg of
Class<?> parameters (this is all private/@hide). This way we could
retrieve a list of intents like readValue(.., List.class, Intent.class),
or a map of string to intents like readValue(.., Map.class,
String.class, Intent.class). For non-container items, we can just pass
no arguments for the vararg. This is explained in internal javadocs.

Inside readValue() now, we also check the container types before
calling the internal methods for deserialization. So, if the thing on
the wire is a VAL_MAP and we know the method we're about to call will
return a HashMap, we verify that the type passed in parameter is a super
type of that (if it's non-null, if it's null it means "perform no
check").

Now, LazyValue became a BiFunction<Class<?>, Class<?>[], Object> to
receive those extra "item types" for containers. The reason for
separating the first from the rest is that the first defines the return
type in the new APIs and inside Parcel, so we need the T from Class<T>
to ensure type-safety.

(I was torn here between using BiFunction or just exposing LazyValue as
@hide for Bundle since it feels like we're missing meaning/abstraction,
but end up leaving this way, advise if you'd prefer the other way)

There was a bit of a refactor in Parcel so readValue() could call
internal methods that accepted nullable Class<?> parameters with the
meaning that null = "no verification"  and non-null = "check against
type provided" (because the external APIs all require non-null
parameters).

Now we can return null in all cases when there is a type mismatch. Note
that the Bundle APIs catch ClassCastException to return null, but that
only works for non-generic types (eg. getSizeF()). For generic types
wrapping "return (T) o" with try-catch doesn't work because the type
gets erased to its bound at runtime, so the type mismatch escapes that
try-catch to the caller, potentially causing a crash. Now they happen
inside the getters, as the non-generic ones.

Test: Boots for now
Test: Working on CTS
Test: atest -d android.os.cts.ParcelTest android.os.cts.BundleTest android.os.BundleTest android.os.ParcelTest
CTS-Coverage-Bug: 219980813
Change-Id: Ifcbeb34b4684d7de105756b9d414162a9205ffaa
2022-02-19 14:10:29 +00:00
Treehugger Robot
8bbb5be10e Merge "[MS70] Have BatteryStatsImpl use the public NetworkStats API" 2022-02-10 18:04:39 +00:00
Junyu Lai
571e216af5 [MS70] Have BatteryStatsImpl use the public NetworkStats API
Test: BatteryStatsManagerTest
Bug: 204830222
  (cherry-picked from ag/16713581)
Change-Id: I35dd909b5da563cea27d8a81a81fe472c59e9b17
Merged-In: I35dd909b5da563cea27d8a81a81fe472c59e9b17
2022-02-09 22:04:45 +08:00
Ken Chen
f584f880ab Merge "Add system_server to net_admin group" 2022-02-09 09:42:29 +00:00
Jean Chalard
cbb2fa2f00 Merge "Allow VPN apps to ask for running the validation checks" 2022-02-09 06:03:45 +00:00
Ken Chen
5c5b682b6d Add system_server to net_admin group
This allows system_server to search/read skfilter BPF programs. Skfilter
BPF programs status were previously dumped by Netd. In Android T, the
related code are mainlined and dumped by system_server process.
system_server needs to be in net_admin group so that it can read program
status.

$ adb root; adb shell ls -l /sys/fs/bpf/
-r--r----- 1 root net_admin ... prog_netd_skfilter_allowlist_xtbpf
-r--r----- 1 root net_admin ... prog_netd_skfilter_denylist_xtbpf
-r--r----- 1 root net_admin ... prog_netd_skfilter_egress_xtbpf
-r--r----- 1 root net_admin ... prog_netd_skfilter_ingress_xtbpf

Bug: 202086915
Test: test in Ib0e935ee2b714ac61daceba6d13fa7a20f97f68f
Change-Id: I8c48230a5da6873eee7d0ba183cb83e1d92cd8f6
2022-02-09 03:47:18 +00:00
Felipe Leme
0b6e3a959b Merge "Adds OWNERS to com.androd.internal.util.Dump*" 2022-02-08 18:14:23 +00:00
Chiachang Wang
3fc98d5ebd Allow VPN apps to ask for running the validation checks
Expose an API to allow VPNs app to ask for running the validation
check on the VPN network built from Ikev2VpnProfile.

Bug: 184750836
Test: New test in Ikev2VpnTest
      Also FrameworksNetTests
Change-Id: I385bb887b6c697d8f5d87af750dbd2aab44afca6
CTS-Coverage-Bug: 184750836
 (but CTS is in the same topic, just not detected by the tool)
2022-02-09 02:19:15 +09:00
Felipe Leme
3c5dea3fe4 Adds OWNERS to com.androd.internal.util.Dump*
Test: no, thanks
Bug: 149254050

Change-Id: I1dbb8a4c04817f39de147927c26c14e461eb564b
2022-02-08 08:50:43 -08:00
Treehugger Robot
81568fa22f Merge "Delete legacy fs-verity support" 2022-02-08 00:48:19 +00:00
Felipe Leme
5f09bb49f0 Merge "Adds OWNERS to com.androd.internal.util.dump" 2022-02-08 00:24:38 +00:00
Felipe Leme
16c1aedbf3 Adds OWNERS to com.androd.internal.util.dump
Test: no, thanks
Bug: 149254050

Change-Id: I7af006ffdfa768b887ff2c7bde970efbc1b1f297
2022-02-07 09:42:26 -08:00
Victor Hsieh
e97a8700b0 Delete legacy fs-verity support
The "legacy" fs-verity was introduced in P in Pixel 3 kernel. During
fs-verity upstream to Linux, the API has changed. During Pixel 4 / Q
development, fs-verity was upstreamed to Linux kernel. By setting
ro.apk_verity.mode = 2, device vendors such as Pixel 4 can opt in to
enable the support. The feature has become mandatory for new devices
shipped with R.

Since Pixel 3 family is no longer supported, it's time to remove the
dead code.

Bug: 120629632
Test: m
Test: TH
Change-Id: I6dacd9bbd38b502ee510ff12970e76342d7b72dd
Merged-In: I6dacd9bbd38b502ee510ff12970e76342d7b72dd
2022-02-01 23:09:43 +00:00
Treehugger Robot
25d96f8d4d Merge "Have BatteryStatsImpl use the public NetworkStats API" 2022-01-25 07:58:21 +00:00
Chalard Jean
bda5db8cb8 Have BatteryStatsImpl use the public NetworkStats API
Test: BatteryStatsManagerTest
Change-Id: I0bfb4df45e373aa3907b07a382ba8edd07c73895
Merged-In: I0bfb4df45e373aa3907b07a382ba8edd07c73895
2022-01-25 06:39:29 +00:00
Junyu Lai
513d8dd2ac Merge "[MS61] Remove NetworkManagementSocketTagger#install dependency" 2022-01-25 00:48:23 +00:00
Siim Sammul
3af0c6a106 Merge "Move binder latency data logging to a background thread to improve performance of the main thread." 2022-01-24 13:40:33 +00:00
Junyu Lai
5262c0eb82 [MS61] Remove NetworkManagementSocketTagger#install dependency
Expose TrafficStats#attachSocketTagger and use it instead.

Test: atest TrafficStatsTest
Bug: 204830222
CTS-Coverage-Bug: 214979748
Change-Id: I1748d349b499053ad08bd62202325fa759ad8da5
2022-01-22 13:51:55 +08:00
Dmitri Plotnikov
c4b9de7d95 Include saved battery history chunks into BatteryUsageStats parcel
Bug: 209297031
Test: Test: atest FrameworksCoreTests:BatteryUsageStatsTest FrameworksCoreTests:BatteryUsageStatsProviderTest
Merged-In: I369d863b6f6fd488030aa031cc465bef6ce99ab8
Change-Id: Ifc70a49b731b5510e7bcd049e0c12d9ac7f68f44
2022-01-21 22:44:46 +00:00
Dmitri Plotnikov
587eef25c9 Merge "Fix concurrency issue with BatteryUsageStats" 2022-01-21 22:44:28 +00:00
Phil Burk
f5bf153f13 Merge "Include MIDI service OWNERS for internal/midi" 2022-01-21 14:58:34 +00:00
Siim Sammul
42e84a4cc4 Move binder latency data logging to a background thread to improve performance of the main thread.
Bug: 213435093
Test: existing tests apply
Change-Id: Ic7a3a413d8e23c0405b4dd16f0b8c919a214eb32
2022-01-21 11:30:26 +00:00
Frank Li
a078c73c47 Merge "[DU07]Remove BatteryStatsImpl NetworkStats.subtract dependences" 2022-01-21 09:19:34 +00:00
lifr
20689682e5 [DU03-1]Remove INetworkStatsService from BatteryStatsImpl
Expose systemapi NetworkStats.getDetailedUidStats for use by
BatteryStats.

BatteryStatsImpl is using INetworkStatsService APIs, which
cannot be accessed after moving into the mainline module. So, replace
and remove those hidden API usages.

Bug: 210066922
Test: atest BatteryStatsImplTest WifiPowerCalculatorTest
            MobileRadioPowerCalculatorTest NetworkStatsServiceTest
CTS-Coverage-Bug: 213437796
Change-Id: I40d713923278f4654d67bb4d12155cea85c10447
2022-01-21 13:52:41 +08:00
Phil Burk
a4cc251eb8 Include MIDI service OWNERS for internal/midi
Change-Id: Icabeeab73b3106e87041a0a9149560ad691640f4
2022-01-20 23:34:39 +00:00
Dmitri Plotnikov
0856f76846 Fix concurrency issue with BatteryUsageStats
BatteryUsageStats is created under a BatteryStatsImpl lock.  One of
the elements of BatteryUsageStats is the battery history buffer Parcel.
Once the BatteryUsageStats object is created, the BatteryStatsImpl lock
is released and the history buffer parcel continues to be appended
by BatteryStatsImpl.  The Parcel may even be reset altogether if the
battery stats session is reset.  The BatteryUsageStats object is parceled
during the getBatteryUsageStats binder call. Any modification of the
history buffer concurrent with parceling causes a crash.

Bug: 194256984
Test: atest FrameworksCoreTests:BatteryUsageStatsTest FrameworksCoreTests:BatteryUsageStatsProviderTest
Change-Id: I262c4608cd02943f926e8daaf3e782c6fe6eaee7
Merged-In: Ifb03a32275dfbea172cd28309a42349d6dd4bcd5
2022-01-20 23:04:22 +00:00
Frank
77fb00ddde [DU07]Remove BatteryStatsImpl NetworkStats.subtract dependences
BatteryStatsImpl is using INetworkStatsService APIs, which
cannot be accessed after moving into the mainline module. So, replace
and remove those hidden API usages.

Bug: 213523117
Test: atest BatteryStatsImplTest WifiPowerCalculatorTest
            MobileRadioPowerCalculatorTest
Change-Id: I9e8d94259ad9845d94bfd78d971ff1a2cd7bb38e
2022-01-20 20:08:19 +08:00
Andrei Onea
64a27bd856 Ignore vendor apex priv-app permission allowlists
Apexes contain the allowlists for privileged permissions used by their
respective apk's, however vendor (partner) apexes should be forbidden from
using this mechanism.

Test: atest FrameworksServicesTests:SystemConfigTest
Bug: 190375768
Change-Id: I34bf2a80fb66f2b2a732234111a338e3af1e919b
2022-01-19 13:11:32 +00:00
Andrei Onea
5765fa9fb8 Add test for parsing apex allowlists
Test: atest FrameworksServicesTests:SystemConfigTest
Bug: 190375768
Change-Id: Ia530a7b5b62774660c410ca8a9f49b18ff9b9b57
2022-01-19 13:11:32 +00:00
Rhed Jao
791eb6934d Ignore prebuilt shared library if it doesn't exist on device
Bug: 191232777
Test: atest PackageManagerTest
Test: atest SystemConfigTest
Change-Id: I756e2c909af6ad0dcf8f1857ba398cfe07862b29
Merged-In: I756e2c909af6ad0dcf8f1857ba398cfe07862b29
2022-01-19 13:11:32 +00:00
Pedro Loureiro
1df9a1e8f5 Rename updatable-library to apex-library
Mostly for consistency with the names used in related changes.

Test: atest com.android.server.pm.parsing.library.ApexSharedLibraryUpdaterTest com.android.server.systemconfig.SystemConfigTest

Bug: 191978330
Change-Id: Ic4ccc0fdca100b576e28bc0918d378cabae9ce61
Merged-In: Ic4ccc0fdca100b576e28bc0918d378cabae9ce61
2022-01-19 13:11:13 +00:00
Pedro Loureiro
5c228ca3e9 Parse new xml attributes used for updatable shared libraries
Attributes added to the `library` tag used in AndroidManifest.xml.
They allow to easily and transparently include/exclude a library from
apps for compatibility purposes.

Bug: 191978330
Test: atest com.android.server.pm.parsing.library.ApexSharedLibraryUpdaterTest com.android.server.systemconfig.SystemConfigTest
Change-Id: Ibdde742a05fd670a9aaee5ee77ae25b9c0801f53
Merged-In: Ibdde742a05fd670a9aaee5ee77ae25b9c0801f53
2022-01-19 11:59:35 +00:00
Alex Buynytskyy
66fc1f1941 Create XML parser only once.
This greatly cuts memory usage: 2.5M -> 0.5M (see bug for traces).

Bug: 200995209
Test: atest SystemConfigTest SystemConfigNamedActorTest
Change-Id: I0b76dc2610afaad3e418ef3115c5e54a05ab334e
Merged-In: I0b76dc2610afaad3e418ef3115c5e54a05ab334e
2022-01-19 11:59:34 +00:00
Junyu Lai
57c59fba4c [MS24] Remove FileUtils.sync dependencies
FileRotator will be built with Connectivity mainline module
while the file location will be kept inside platform.
Thus, hidden api usage needs to be addressed.

This change removes some dependencies by inlining the content
of FileUtils.sync to remove the dependency, and change the
Slog to Log.

Test: TH
Bug: 204830222
Change-Id: I6105850dd8311072fd8de2e2864d11fdb052f061
2022-01-19 07:07:34 +00:00
Treehugger Robot
296fbccd6e Merge "[DU03]Remove INetworkStatsService from BatteryStatsImpl" 2022-01-12 19:33:52 +00:00
Taras Antoshchuk
bc8f256721 Merge "Revert "Revert "Revert "Revert "Add APIs that allow to exclude r..."" 2022-01-12 15:27:30 +00:00
lifr
ca904a8ea8 [DU03]Remove INetworkStatsService from BatteryStatsImpl
BatteryStatsImpl is using INetworkStatsService APIs, which
cannot be accessed after moving into the mainline module. So, replace
and remove those hidden API usages.

Bug: 210066922
Test: atest BatteryStatsImplTest WifiPowerCalculatorTest
            MobileRadioPowerCalculatorTest
CTS-Coverage-Bug: 213437796

  (cherry-picked from ag/16548638)

Change-Id: I584897ff8ba303c717a9df3756c9f6778c1cfb10
Merged-In: I584897ff8ba303c717a9df3756c9f6778c1cfb10
2022-01-12 07:28:55 +00:00
Artur Satayev
c89ed260a2 Add PACKAGE_MANAGER_OWNERS as owners of SystemConfig.java
Merged-In: Iabd1ee367d8234425c5770455a20a413cc37c6a7
Change-Id: Iabd1ee367d8234425c5770455a20a413cc37c6a7
2022-01-10 18:23:21 +00:00
Taras Antoshchuk
fe5a57e8c4 Revert "Revert "Revert "Revert "Add APIs that allow to exclude r..."
Revert "Revert "Revert "Revert "Add VpnServiceBuilderShim for Vp..."

Revert submission 1941195-revert-1931760-reland-vpn-impl-part-2-WGARECSJEM

Reason for revert: fixed merge conflict with aosp/1938197
Reverted Changes:
Ic25e5e4ea:Revert^2 "Revert "Add CTS tests for exclude VPN ro...
Ic72cafcf5:Revert "Revert "Revert "Add APIs that allow to exc...
I53802190a:Revert "Revert "Revert "Add VpnServiceBuilderShim ...

Change-Id: Id3e5f698cf8965fa8386a98bed1fd0170a9e0344
2022-01-10 10:20:29 +00:00
Matt Buckley
f7a327e8d5 Merge "Revert "Revert "Revert "Add APIs that allow to exclude routes fr..."" 2022-01-07 17:48:45 +00:00
Matt Buckley
7153b105e7 Revert "Revert "Revert "Add APIs that allow to exclude routes fr..."
Revert "Revert "Revert "Add VpnServiceBuilderShim for VpnService..."

Revert submission 1931760-reland-vpn-impl-part-2

Reason for revert: DroidMonitor-triggered revert due to breakage https://android-build.googleplex.com/builds/quarterdeck?branch=aosp-master&target=test_suites_x86_64&lkgb=8053795&lkbb=8053908&fkbb=8053828, bug b/213588956.
BUG: b/213588956
Reverted Changes:
Ic8ed8fce7:Revert "Revert "Add CTS tests for exclude VPN rout...
I07104340a:Revert "Revert "Add VpnServiceBuilderShim for VpnS...
I7c69b7244:Revert "Revert "Add APIs that allow to exclude rou...

Change-Id: Ic72cafcf5c7e2c62236f1cef61b0764882bacaad
2022-01-07 17:44:52 +00:00
Taras Antoshchuk
f4177e94ee Merge "Revert "Revert "Add APIs that allow to exclude routes from VPN""" 2022-01-07 16:27:12 +00:00
Junyu Lai
b7d0199763 [MS22] Move NetworkManagementSocketTagger into the module
This is heavily used by TrafficStats, and no other modules
are using it. Hence it should be moved to the module as well.

Test: TH
Bug: 204830222

Change-Id: I7ea1ccb916e796c786c29d53e4ecf3970a8af6dd
2022-01-07 09:57:15 +00:00
Taras Antoshchuk
5b1d7c2ead Revert "Revert "Add APIs that allow to exclude routes from VPN""
This reverts commit 487b2e645a.

Reason for revert: failing build target configuration is fixed

Change-Id: I7c69b7244b4262336e427e4c671aaebb70ddc6ed
2022-01-06 14:49:02 +00:00
Junyu Lai
0cf9e87c79 [MS27] Expose noteUntaggedSocket SystemApi
While Data usage related codes are moving to mainline module,
StrictMode#vmUntaggedSocketEnabled() and onUntaggedSocket()
can no longer be accessed from NetworkManagementSocketTagger.

Thus, expose alternative SystemApi to allow invocations from
the module.

Test: TH
Bug: 204830222
Exempt-From-Owner-Approval: 1. Owner approved the change with
  explicitly granted submission after adderessing the
  straight-forward comment. 2. Owner is OOO for 3 months.
Change-Id: Ib54ff54ce3617ae0d04080a1740e78b086bbb039
2022-01-06 08:49:46 +00:00
Chiachang Wang
de8c621832 Add configuration whether to exclude local traffic in the VPN
Add a extra variable to store whether the local traffic is
exempted from the VPN.

Bug: 184750836
Test: atest FrameworksNetTests
Change-Id: I70301901c2374ded9fdf179d0ce64e7bb2d7b1ab
2021-12-28 11:14:01 +08:00
Junyu Lai
6ff6240694 Merge "[MS10.1] Move multiplySafeByRational to NetworkStatsUtils" 2021-12-21 01:22:14 +00:00