Commit Graph

20442 Commits

Author SHA1 Message Date
Makoto Onuki
d0b0f4ce83 Merge "Add TEMPORARY_ALLOW_LIST_TYPE_NONE." into sc-dev 2021-03-29 21:32:40 +00:00
Svetoslav Ganov
a6c3d6ad39 Merge "Runtime permission attribution improvements" into sc-dev 2021-03-29 21:03:06 +00:00
Yuri Lin
e0d692833e Merge "Delete deleteConversationNotificationChannels from NotificationManagerService." into sc-dev 2021-03-29 19:39:25 +00:00
Mustafa Emre Acer
7c4f635b3b Merge "Expose TimeManager.suggestExternalTime()" into sc-dev 2021-03-29 18:46:59 +00:00
Yuri Lin
c5f668e141 Delete deleteConversationNotificationChannels from NotificationManagerService.
This method isn't used anywhere and its functionality is superseded by onConversationRemoved, which handles deleted conversations.

Test: atest NotificationManagerServiceTest
Bug: 169349809

Change-Id: Iad7f592e71ecf425930e31873088a02e298380b3
2021-03-29 17:20:36 +00:00
Richard Ho
2335acd9a2 Merge changes from topic "nearby-streaming-policy" into sc-dev
* changes:
  Add policy for nearby app streaming
  Add policy for nearby notification streaming
2021-03-29 17:12:03 +00:00
Svet Ganov
8d2ed50604 Runtime permission attribution improvements
When an app is proxying access to runtime permission protected
data it needs to check whether the calling app has a permission
to the data it is about to proxy which leaves a trace in app ops
that the requesting app perofmed a data access. However, then the
app doing the work needs to get the protected data itself from the
OS which access gets attributed only to itself. As a result there
are two data accesses in app ops where only the first one is a
proxy one that app A got access to Foo through app B - that is the
one we want to show in the permission tracking UIs - and one
for the data access - that is the one we would want to blame on
the calling app, and in fact, these two accesses should be one -
that app A accessed Foo though B. This limitation requires fragile
one off workarounds where both accesses use the same attribution
tag and sys UI has hardcoded rules to dedupe. Since this is not
documented we cannot expect that the ecosystem would reliably
do this workaround in apps that that the workaround in the OS
would be respected by every OEM.

This change adds a mechaism to resolve this issue. It allows for
an app to create an attribution context for another app and then
any private data access thorugh this context would result in a
single app op blame that A accessed Foo though B, i.e. we no longer
have double accounting. Also this can be nested through apps, e.g.
app A asks app B which asks app C for contacts. In this case app
B creates an attribution context for app A and calls into app C
which creates an attribution context for app B. When app C gets
contacts the entire attribution chain would get a porper, single
blame: that C accessed the data, that B got the data from C, and
that A got the data form B. Furthermore, this mechanism ensures
that apps cannot forget to check permissions for the caller
before proxying private data. In our example B and C don't need
to check the permisisons for A and B, respectively, since the
permisisons for the entire attribution chain are checked before
data delivery. Attribution chains are not forgeable preventing
a bad actor to create an arbitrary one - each attribution is
created by the app it refers to and points to a chain of
attributions created by their corresponding apps.

This change also fixes a bug where all content provider accesses
were double counted in app ops due to double noting. While at
this it also fixes that apps can now access their own last ops.
There was a bug where one could not pass null getting the attributed
ops from a historical package ops while this is a valid use case
since if there is no attribution everything is mapped to the null
tag. There were some app op APIs not being piped thorough the app
ops delegate and by extension through the app ops policy. Also
now that we have nice way to express the permission chain in a
call we no longer need the special casing in activity manager to
handle content provider accesses through the OS. Fixed a bug
where we don't properly handle the android.os.shell calls with
an invlaid tag which was failing while the shell can do any tag.

Finally, to ensure the mechanims is validated and works end-to-end
we are adding support for a voice recognizer to blame the client
app for the mic access. The recognition service can create a blaming
context when opening the mic and if the mic is open, which would
do all permission checks, we would not do so again. Since changes
to PermissionChercker for handling attribution sources were made
the CL also hooks up renounced permissoins in the request permission
flow and in the permission checks.

bug:158792096
bug:180647319

Test:atest CtsPermissionsTestCases
     atest CtsPermissions2TestCases
     atest CtsPermissions3TestCases
     atest CtsPermissions4TestCases
     atest CtsPermissions5TestCases
     atest CtsAppOpsTestCases
     atest CtsAppOps2TestCases

Change-Id: Ib04585515d3dc3956966005ae9d94955b2f3ee08
2021-03-29 16:49:33 +00:00
Jeff Chang
d4a142719e Merge "Update saving persistent state documentation" into sc-dev 2021-03-29 10:57:28 +00:00
Jeff DeCew
d1cc1421df Merge "Fix regressions with DecoratedCustomViewStyle" into sc-dev 2021-03-26 02:11:02 +00:00
Chris Tate
d8022c3d5b Merge "Make FGS notification deferral control tri-state" into sc-dev 2021-03-25 23:50:36 +00:00
Mustafa Acer
5265da19f9 Expose TimeManager.suggestExternalTime()
This CL exposes an API that allows system clock time suggestions from an
external clock / time source to be made. The nature of "external" could
be highly form-factor specific. Example, times obtained via the VHAL for
Android Auto OS.

Bug: 157504928
Bug: 177079827
Test: atest android.app.time
CTS-Coverage-Bug: 182275086
Change-Id: I3527e3827a03c1df73fdc1e00c815ad5971a92ca
2021-03-25 21:17:19 +00:00
Jeff DeCew
987cfcc885 Fix regressions with DecoratedCustomViewStyle
Fixes: 183641274
Test: atest NotificationTemplateTest
Change-Id: I3201e8cde339fb64412c298958786cfdd7f3303b
2021-03-25 15:23:39 -04:00
Richard Ho
2e1428bdc5 Add policy for nearby app streaming
App streaming is when the device starts an app on a virtual display and sends a video stream of the app to nearby devices. The policy specifies options in which app streaming is supported. The default policy is streaming only to devices with the same managed account.

Bug: 179910177
Test: Builds successfully
Change-Id: I1a9424d0de524a0cdfcc00b2bc39196e7f231480
2021-03-25 12:22:14 -07:00
Richard Ho
f15e43f250 Add policy for nearby notification streaming
Notification streaming is sending notification data from pre-installed apps to nearby devices. The policy specifies options in which notification streaming is supported. The default policy is streaming notifications only to devices with the same managed account.

Bug: 179910174
Test: Builds successfully
Change-Id: I96a9c67aab1d27eb0527add51adc019bd98b64b4
2021-03-25 12:22:13 -07:00
Varun Shah
d6494b1cce Add TEMPORARY_ALLOW_LIST_TYPE_NONE.
Also replace all usages of TempAllowListType defined in
PowerWhitelistManager with the newly added reference in
PowerExemptionManager.

Fixes: 183053095
Test: atest ActivityManagerFgsBgStartTest#testTempAllowListType
Test: atest PowerExemptionTest
Test: atest BroadcastOptionsTest
Change-Id: I2f47ca99d4dfa8f267bb029d2934f0f765b0c594
2021-03-25 11:15:56 -07:00
Benjamin Franz
8ee7f9a4c3 Create a new permission to override Overridable change ids
With this change we allow system packages with the new permission to
override ChangeIds specifically annotated as Overridable to set
overrides even on non-debuggable builds.

Bug: 174043039
Bug: 175874108
CTS-Coverage-Bug: 180396382
Test: atest FrameworksServicesTests:CompatConfigTest
Test: atest FrameworksServicesTests:PlatformCompatTest
Change-Id: Ib8d5d83b5fd62acb5808d10f5c413616f29ee65c
2021-03-25 09:45:50 +00:00
Pavel Grafov
46ad0cd297 Merge "Allow COPE DPC to confirm compliance explicitly" into sc-dev 2021-03-25 05:43:56 +00:00
Peiyong Lin
9116887121 Merge "Integrate DeviceConfig with GameManagerService" into sc-dev 2021-03-25 01:09:41 +00:00
Antoan Angelov
25ba2e7f98 Merge "Add API constants for metadata for mainline modules" into sc-dev 2021-03-24 23:46:00 +00:00
Pavel Grafov
bca12f4774 Allow COPE DPC to confirm compliance explicitly
Currently when COPE PO sets a maximum managed profile time off
policy, it is sufficient for the user to turn the profile on
briefly to reset the timer, which technically allows the user
to circumvent the policy, doing so repeatedly.

With this change DPC can control when the timer gets reset by
acknowledging compliance explicitly.
By default, the behavior is the same as before unless the DPC
overrides DAR#onComplianceAcknowledgementRequired in which case
it will have to call DPM.acknowledgeDeviceCompliant when the
timer can be safely reset, e.g. after a successful policy sync.

Bug: 181943978
Test: atest OrgOwnedProfileOwnerTest#testWorkProfileMaximumTimeOff_complianceRequiredBroadcastDefault
Test: atest OrgOwnedProfileOwnerTest#testWorkProfileMaximumTimeOff_complianceRequiredBroadcastOverride
Test: atest OrgOwnedProfileOwnerTest#testWorkProfileMaximumTimeOff
Test: atest com.android.server.devicepolicy.DevicePolicyManagerTest
Change-Id: I6efea53aad8097c047f1e3ebf62b421dc32214e6
2021-03-24 23:16:09 +00:00
arangelov
e798933b83 Add API constants for metadata for mainline modules
The constants will allow mainline modules to declare whether
they should be uninstalled or not during the provisioning
process.

Bug: 179653892
Test: compiled
Change-Id: Id7de12204b2e9481935cc5a56831ab4899b3dfb6
2021-03-24 18:22:33 +00:00
Antoan Angelov
680b4223b9 Merge "Update javadoc for EXTRA_PROVISIONING_ORGANIZATION_NAME" into sc-dev 2021-03-24 17:11:10 +00:00
Nate Myren
4cbdb452de Merge "Add Permission Indicator methods/classes to Test Api" into sc-dev 2021-03-24 16:27:22 +00:00
Charles Chen
1e76f995bf Merge "Move WindowContext module to window package" into sc-dev 2021-03-24 07:45:41 +00:00
Soonil Nagarkar
1419d29d30 Merge "Update Nullability per API review" into sc-dev 2021-03-24 04:09:06 +00:00
Charles Chen
f48ece4875 Move WindowContext module to window package
In this way, we can clarify the owners and it is easier to maintain.
Also refactor to move WindowContext creation logic to ContextImpl.

Test: atest WindowContext WindowContextTests WindowContextPolicyTests
Bug: 159767464
Bug: 152193787

Change-Id: I78432aa18aa97e001f5a9a04321109e456fd137b
2021-03-24 11:26:50 +08:00
TreeHugger Robot
314d760ccf Merge "Fix typo in strict mode violation message" into sc-dev 2021-03-24 03:06:18 +00:00
Lucas Dupin
76ae4090e1 Merge "Change color of expand button on notif groups" into sc-dev 2021-03-24 00:49:53 +00:00
Adam Bodnar
4e421c394c Integrate DeviceConfig with GameManagerService
Bug: 180439000

Test: adb shell device_config put game_overlay <PACKAGE NAME> <VALUES>

Change-Id: If201b36e6f223e42dbefba52bbf86c9d760d3d26
2021-03-23 16:18:45 -07:00
Lucas Dupin
b904a2e608 Change color of expand button on notif groups
They should use the tertiary accent color.

Fixes: 183454454
Test: visual
Change-Id: Ieb1fdfb15a9b74c77880ae7bfad19549e23f9396
2021-03-23 15:49:21 -07:00
Lucas Dupin
98da38aba0 Merge "Do not call WM until we have a window token" into sc-dev 2021-03-23 22:45:32 +00:00
Nate Myren
9ca6298114 Add Permission Indicator methods/classes to Test Api
Also sets lastAccessTime = now for running ops

Test: atest PermissionIndicatorAppOpUsageTest
Bug: 172868375
Change-Id: I2a616f624640e0f219e33d6fa8ebf55559e24e1a
2021-03-23 13:04:47 -07:00
Jeff DeCew
e2d38c5ac5 Merge "Remove Notification.DevFlags" into sc-dev 2021-03-23 19:50:27 +00:00
Soonil Nagarkar
93b6057ebe Update Nullability per API review
Bug: 181707891
Test: presubmits
Change-Id: I515aaad49d3115f872f031978073f4e219b03cff
2021-03-23 11:43:26 -07:00
Cole Faust
3be43d218e Fix typo in strict mode violation message
Change-Id: Ic3c41621dcd8af1c0c60a5f3ef26b80fdab45c19
Fixes: 183513884
Test: Presubmits
2021-03-23 18:04:28 +00:00
Christopher Tate
c02fc88615 Make FGS notification deferral control tri-state
Apps can now request either immediate visibility or deferral explicitly,
versus the previous iteration's immediate-or-default only.

Bug: 179290175
Test: ApiDemos foreground service exercise
Test: atest CtsAppTestCases:ServiceTest
Test: atest CtsAppTestCases:NotificationManagerTest
Change-Id: I0b4d11a7483d2407758c810cf4a77a2e45bb737f
2021-03-23 17:52:07 +00:00
Flavio Fiszman
5785c5c68f Merge "Show messages count in People Tile" into sc-dev 2021-03-23 16:42:53 +00:00
Mustafa Acer
6cebc2f2ac Add a new permission for external time sources
This CL adds a new permission called SUGGEST_EXTERNAL_TIME that
gates TimeManager.suggestExternalTime calls.

The new permission is marked as 'privileged' as protection level. This
could result in third party apps preinstalled on the system image to
potentially get this permission. This is OK for the following reasons:
 - OEM coordination is needed to grant 3P apps this permission, so
 adding "privileged" doesn't introduce significant risk.
 - This permission/API doesn't guarantee that the suggested timestamp
 will immediately be used as the new system timestamp. The system must
 be configured so that the external time source has a higher priority
 than other time sources (e.g. GNSS) for the external time suggestion to
 be used. This configuration is also done by the OEM. That introduces
 significant roadblock for a malicious app to do anything useful with
 this permission.
- More importantly, apps can set system time directly using
TimeManager.setTime() which requires SET_TIME permission. This
permission is also signature|privileged, so this change is consistent
with it.

Bug: 157504928, 177079827
CTS-Coverage-Bug: 182275086
Test: atest android.app.time
Change-Id: I0098ab7565b647fb220d39575f0616d2a47bdc89
2021-03-23 16:24:41 +00:00
Jeff DeCew
8548f343e2 Remove Notification.DevFlags
Fixes: 176239013
Test: manual
Change-Id: I1aeed1c79e4a829d8829eb08224f9b21fafc50fe
2021-03-23 13:28:55 +00:00
Jeff Sharkey
9f5392e8b7 Merge changes from topic "nearby-bluetooth-permission-group" into sc-dev
* changes:
  Request new Bluetooth runtime permissions.
  Default grants for "Nearby devices" permission.
  Add BLUETOOTH_SCAN and BLUETOOTH_CONNECT app ops
  Split new NEARBY_DEVICES permissions
  Define new NEARBY_DEVICES permission group
2021-03-23 12:56:30 +00:00
Flavio Fiszman
87eec50482 Show messages count in People Tile
Change-Id: I85b262dda92227cbea2672d9725bda163a5bb42a
Test: manual
Bug: 183382000
2021-03-23 11:25:29 +00:00
Kholoud Mohamed
e7e5563e96 Merge "Properly expose LockTypes constants as systemAPIs" into sc-dev 2021-03-23 10:17:03 +00:00
TreeHugger Robot
baf818032a Merge "Rename "Network slicing" to "Enterprise network preference" in the 5G Slicing API" into sc-dev 2021-03-23 07:49:10 +00:00
TreeHugger Robot
59a8366541 Merge "Improve the documentation of getLastTimeComponentUsed() API" into sc-dev 2021-03-23 06:57:05 +00:00
Jeff DeCew
2a12cfadb4 Merge "New MediaStyle template:" into sc-dev 2021-03-23 02:14:06 +00:00
TreeHugger Robot
358a76f7e4 Merge "Reduce number of maximum clusters" into sc-dev 2021-03-23 02:04:10 +00:00
Jon Spivack
37a7c0aa58 Merge "Support getting AssistContent for recents in Launcher" into sc-dev 2021-03-22 23:57:55 +00:00
Ruslan Tkhakokhov
5db986d793 Merge "Add a field for transport properties to RestoreSet object" into sc-dev 2021-03-22 23:43:24 +00:00
Ruslan Tkhakokhov
3762670bb7 Add a field for transport properties to RestoreSet object
Android Framework needs to know for each RestoreSet provided by
BackupTransport the properties of the transport (e.g. device-to-device
transport, encryption) that was used to obtain the data in the restore
set in question.

Bug: 182986784
CTS-Coverage-Bug: 183441953
Test: atest FullBackupRulesHostSideTest
Change-Id: I07bc2d4eb3837390ea3b0aee769d143ab153335d
2021-03-22 23:42:47 +00:00
Lucas Dupin
1291155196 Reduce number of maximum clusters
Bug: 183392558
Test: manual
Change-Id: I7a28c319e44700f4fc6367cfe6aac615b13b977d
2021-03-22 23:36:44 +00:00