When an app is proxying access to runtime permission protected
data it needs to check whether the calling app has a permission
to the data it is about to proxy which leaves a trace in app ops
that the requesting app perofmed a data access. However, then the
app doing the work needs to get the protected data itself from the
OS which access gets attributed only to itself. As a result there
are two data accesses in app ops where only the first one is a
proxy one that app A got access to Foo through app B - that is the
one we want to show in the permission tracking UIs - and one
for the data access - that is the one we would want to blame on
the calling app, and in fact, these two accesses should be one -
that app A accessed Foo though B. This limitation requires fragile
one off workarounds where both accesses use the same attribution
tag and sys UI has hardcoded rules to dedupe. Since this is not
documented we cannot expect that the ecosystem would reliably
do this workaround in apps that that the workaround in the OS
would be respected by every OEM.
This change adds a mechaism to resolve this issue. It allows for
an app to create an attribution context for another app and then
any private data access thorugh this context would result in a
single app op blame that A accessed Foo though B, i.e. we no longer
have double accounting. Also this can be nested through apps, e.g.
app A asks app B which asks app C for contacts. In this case app
B creates an attribution context for app A and calls into app C
which creates an attribution context for app B. When app C gets
contacts the entire attribution chain would get a porper, single
blame: that C accessed the data, that B got the data from C, and
that A got the data form B. Furthermore, this mechanism ensures
that apps cannot forget to check permissions for the caller
before proxying private data. In our example B and C don't need
to check the permisisons for A and B, respectively, since the
permisisons for the entire attribution chain are checked before
data delivery. Attribution chains are not forgeable preventing
a bad actor to create an arbitrary one - each attribution is
created by the app it refers to and points to a chain of
attributions created by their corresponding apps.
This change also fixes a bug where all content provider accesses
were double counted in app ops due to double noting. While at
this it also fixes that apps can now access their own last ops.
There was a bug where one could not pass null getting the attributed
ops from a historical package ops while this is a valid use case
since if there is no attribution everything is mapped to the null
tag. There were some app op APIs not being piped thorough the app
ops delegate and by extension through the app ops policy. Also
now that we have nice way to express the permission chain in a
call we no longer need the special casing in activity manager to
handle content provider accesses through the OS. Fixed a bug
where we don't properly handle the android.os.shell calls with
an invlaid tag which was failing while the shell can do any tag.
Finally, to ensure the mechanims is validated and works end-to-end
we are adding support for a voice recognizer to blame the client
app for the mic access. The recognition service can create a blaming
context when opening the mic and if the mic is open, which would
do all permission checks, we would not do so again. Since changes
to PermissionChercker for handling attribution sources were made
the CL also hooks up renounced permissoins in the request permission
flow and in the permission checks.
bug:158792096
bug:180647319
Test:atest CtsPermissionsTestCases
atest CtsPermissions2TestCases
atest CtsPermissions3TestCases
atest CtsPermissions4TestCases
atest CtsPermissions5TestCases
atest CtsAppOpsTestCases
atest CtsAppOps2TestCases
Change-Id: Ib04585515d3dc3956966005ae9d94955b2f3ee08
PackageParser is deprecated, but system still references its
sUseRoundIcon. We should move that to PackageParserUtils.
Bug: 180603085
Test: manually check if the icon has the white border
Change-Id: Idb2ccc2be9006237244aabfe9c45814e9c7c27b5
Something was left behind when we opened the installation API.
Bug: 152310230
Test: atest PackageManagerShellCommandTest PackageManagerShellCommandIncrementalTest IncrementalServiceTest PackageManagerServiceTest ChecksumsTest
Change-Id: Ia2d4c3f3e97c8432fcca094d6e0f4e97dcc048d4
It's now possible to define an lStar attribute.
This attribute will modify the base color in a way that its chroma will
be conserved, but perceptive luminance will change.
Fixes: 183609373
Test: atest ColorStateListTest
Change-Id: I341a0a532bd9c030e8f52185bacda0db55486216
These feature flags will hold the KeyMint version for the default and
StrongBox HALs. They can be used by apps to convey that they'll only
work on devices which have a recent enough version of KeyMint.
For example, if an application requires ECDH to be implemented in
Secure Hardware it can convey this requirement by indicated that it
needs FEATURE_HARDWARE_KEYSTORE >= 100. Or if it needs this in the
StrongBox it can use FEATURE_STRONGBOX_KEYSTORE >= 100. As with other
feature flags, this can be used to only show the app on devices which
satisfy such requirements.
Test: Compiles
Bug: 160616951
Change-Id: I582e50fba92de0d598d7e86fcc3b1b2b4a91b103
Add new api to retrieve pending intents from specified shortcut.
Bug: 151359749
CTS-Coverage-Bug: 13975407
Test: atest ShortcutManagerTest12
Change-Id: I6c413615d1392805f601561550dcb85bfe242b37
These methods were only available for dogfooder transition.
None of these methods shipped in a stable SDK.
Bug: 181887768
Bug: 183395357
Test: Build, presubmit
Change-Id: I74feebd2721208c97475df9b74f734a17a41d5e2
* Rename nativeHeapZeroInit to nativeHeapZeroInitialized.
* nativeHeapZeroInitialized is a tri-state, so make it an @IntDef.
* Add documentation to some accessor methods, and missing @type
annotations.
* Add attrs_manifest.xml document for the new attributes.
Bug: 182165383
Bug: 182370211
Test: com.android.cts.tagging
Change-Id: Iad46a1da9bc040baf4c438afbc5fd8cd128e99f1
Allowing passing raw texts offers more flexibility to callers in some
cases. However, in this case, the callers must handle locale changes on
their own.
Test: atest FrameworksServicesTests:SuspendDialogInfoTest
atest FrameworksServicesTests:PackageManagerSettingsTest
atest CtsSuspendAppsTestCases:DialogTests
Fixes: 170653551
Bug: 170653208
Change-Id: Iaa51e1d3f260ad553db8b33fddc935c478a40c9c
In this way, we can clarify the owners and it is easier to maintain.
Also refactor to move WindowContext creation logic to ContextImpl.
Test: atest WindowContext WindowContextTests WindowContextPolicyTests
Bug: 159767464
Bug: 152193787
Change-Id: I78432aa18aa97e001f5a9a04321109e456fd137b
Settings shouldn't need this information as it's all provided as part
of the user state object.
Bug: 183537875
Test: DomainVerificationEnforcerTest
Change-Id: Ib84b92d1d43c098ea2c2a89471c0cd1deacc9661
This change adds a new hidden user type "android.os.usertype.profile.CLONE"
and two new system APIs "isCloneProfile" and "hasSharedMedia". To support App cloning, we need to support sharing media between the owner user and the clone user. Adding this as a property in UserTypeDetails.
Bug: 182396009
Test: atest android.multiuser.cts.UserManagerTest#testCloneUser, atest com.android.server.pm.UserManagerTest#testCloneUser and manually ran shell commands on the clone user.
Change-Id: I49ddcbd499944ca9ec05ef4dc10d2e2b231d8b88
(cherry picked from commit db930667a21dac9f0de7cb2fe99175b3b4545bf4)
Add new manifest attribute requestOptmizedExternalStorageAccess.
When the flag is set, app requests for performance optimisations for
file path operations. Apps get this performance optimisation by
bypassing database operations as part of file path operations. Hence,
when the flag is set, app will be resposible to keep MediaStore database
consistent for its file path operations.
App should hold android.Manifest.permission#MANAGE_EXTERNAL_STORAGE
permission or SYSTEM_GALLERY role, otherwise the flag will be ignored.
The default values is
- True if
* if app has android.Manifest.permission#MANAGE_EXTERNAL_STORAGE
permission and targets targetSDK<=30.
* app has SYSTEM_GALLERY role and targetSDK<=29.
- False otherwise.
Bug: 178209446
Test: atest
android.scopedstorage.cts.device.BypassDatabaseOperationsTest
Change-Id: I951c3001c2b7dbe163b3bfecef4ee8ad350230ae
Following changes are implemented in this CL:
1. Persist shortcuts to icing whenever a shortcut is created/updated.
2. Delete shortcuts from icing only when publisher explicitly removes
the shortcut. i.e. deletion due to exceeding shortcut limit / disabling
shortcut do not lead to shortcut deletion from icing.
3. Call AppSearchSession#reportUsage when
ShortcutManger#pushDynamicShortcuts is invoked.
4. Add StrictMode warning for calling async method on mainthread.
Bug: 151359749
Test: atest ShortcutManagerTest1 ShortcutManagerTest2 ShortcutManagerTest3 ShortcutManagerTest4 ShortcutManagerTest5 ShortcutManagerTest6 ShortcutManagerTest7 ShortcutManagerTest8 ShortcutManagerTest9 ShortcutManagerTest10 ShortcutManagerTest11
Test: atest CtsShortcutManagerTestCases
Change-Id: I7ae7ec50a7e49f8de819d8239d429fc494017f96
Since developers can declare the "neverForLocation" flag in their
manifest as public API, we should also offer a way to inspect the
value that we parsed from the manifest. We do this by surfacing it
through the existing PackageInfo.requestedPermissionsFlags field.
This also means we can remove the PackageManagerInternal API, since
interested parties can now check PackageInfo directly.
Fix a potential security issue by only accepting flags from manifest
when the application is targeting a modern enough SDK.
Bug: 181812281
Test: atest CtsContentTestCases:PackageManagerTest
Test: atest FrameworksServicesTests:PackageParserTest
Test: atest com.android.server.pm.parsing
Change-Id: I877768c06ee15281f3334794034f4af563e74569
- Race condition between Theme.setImpl() cnd Theme.applyStyle() can
happen when creating Window and Configuration-change occur together.
- To maintain the integrity, the whole process of creating new ThemeImpl
and setting it in Resources.setImpl() should be guarded by the lock.
- Moves the lock of ThemeImpl.mKey to Theme.mLock.
Bug: 173558667
Test: manual test in the bug
Change-Id: I9ebdc48333b188c0b26b1b7490a5cbb34bbe6e0f
Clarifies that it's the Context's user being queried and updates for
the selection -> state rename.
Bug: 182345452
Test: none, docs change
Change-Id: Iaefc82b5e1c25292db1f694bf4f05d9f82b81958
TestNetworkManager is being unbundled; the TEST_NETWORK_SERVICE constant
is necessary for the module to register the manager with
registerContextAwareService.
Bug: 171540887
Test: m
Change-Id: I0690251ddfcdaa8a34830e110b75869a370de389
Merged-In: I0690251ddfcdaa8a34830e110b75869a370de389