Commit Graph

10483 Commits

Author SHA1 Message Date
Svet Ganov
8d2ed50604 Runtime permission attribution improvements
When an app is proxying access to runtime permission protected
data it needs to check whether the calling app has a permission
to the data it is about to proxy which leaves a trace in app ops
that the requesting app perofmed a data access. However, then the
app doing the work needs to get the protected data itself from the
OS which access gets attributed only to itself. As a result there
are two data accesses in app ops where only the first one is a
proxy one that app A got access to Foo through app B - that is the
one we want to show in the permission tracking UIs - and one
for the data access - that is the one we would want to blame on
the calling app, and in fact, these two accesses should be one -
that app A accessed Foo though B. This limitation requires fragile
one off workarounds where both accesses use the same attribution
tag and sys UI has hardcoded rules to dedupe. Since this is not
documented we cannot expect that the ecosystem would reliably
do this workaround in apps that that the workaround in the OS
would be respected by every OEM.

This change adds a mechaism to resolve this issue. It allows for
an app to create an attribution context for another app and then
any private data access thorugh this context would result in a
single app op blame that A accessed Foo though B, i.e. we no longer
have double accounting. Also this can be nested through apps, e.g.
app A asks app B which asks app C for contacts. In this case app
B creates an attribution context for app A and calls into app C
which creates an attribution context for app B. When app C gets
contacts the entire attribution chain would get a porper, single
blame: that C accessed the data, that B got the data from C, and
that A got the data form B. Furthermore, this mechanism ensures
that apps cannot forget to check permissions for the caller
before proxying private data. In our example B and C don't need
to check the permisisons for A and B, respectively, since the
permisisons for the entire attribution chain are checked before
data delivery. Attribution chains are not forgeable preventing
a bad actor to create an arbitrary one - each attribution is
created by the app it refers to and points to a chain of
attributions created by their corresponding apps.

This change also fixes a bug where all content provider accesses
were double counted in app ops due to double noting. While at
this it also fixes that apps can now access their own last ops.
There was a bug where one could not pass null getting the attributed
ops from a historical package ops while this is a valid use case
since if there is no attribution everything is mapped to the null
tag. There were some app op APIs not being piped thorough the app
ops delegate and by extension through the app ops policy. Also
now that we have nice way to express the permission chain in a
call we no longer need the special casing in activity manager to
handle content provider accesses through the OS. Fixed a bug
where we don't properly handle the android.os.shell calls with
an invlaid tag which was failing while the shell can do any tag.

Finally, to ensure the mechanims is validated and works end-to-end
we are adding support for a voice recognizer to blame the client
app for the mic access. The recognition service can create a blaming
context when opening the mic and if the mic is open, which would
do all permission checks, we would not do so again. Since changes
to PermissionChercker for handling attribution sources were made
the CL also hooks up renounced permissoins in the request permission
flow and in the permission checks.

bug:158792096
bug:180647319

Test:atest CtsPermissionsTestCases
     atest CtsPermissions2TestCases
     atest CtsPermissions3TestCases
     atest CtsPermissions4TestCases
     atest CtsPermissions5TestCases
     atest CtsAppOpsTestCases
     atest CtsAppOps2TestCases

Change-Id: Ib04585515d3dc3956966005ae9d94955b2f3ee08
2021-03-29 16:49:33 +00:00
Lucas Dupin
10c1b4f3f9 Merge "Add luma capabilities to ColorStateList" into sc-dev 2021-03-29 15:47:05 +00:00
Jackal Guo
a62a68dba7 Merge "Migrate the usage of sUseRoundIcon to PackageParserUtils" into sc-dev 2021-03-26 08:01:07 +00:00
Sudheer Shanka
ef688bbdf5 Merge "Rename Context.BIND_ALLOW_NETWORK_ACCESS." into sc-dev 2021-03-26 07:56:19 +00:00
Jackal Guo
755cecda8d Migrate the usage of sUseRoundIcon to PackageParserUtils
PackageParser is deprecated, but system still references its
sUseRoundIcon. We should move that to PackageParserUtils.

Bug: 180603085
Test: manually check if the icon has the white border
Change-Id: Idb2ccc2be9006237244aabfe9c45814e9c7c27b5
2021-03-26 08:31:02 +08:00
Alex Buynytskyy
f8d0c5584e Merge "Making the rest of Streaming installation API public." into sc-dev 2021-03-25 23:58:06 +00:00
Sudheer Shanka
53cea237e4 Rename Context.BIND_ALLOW_NETWORK_ACCESS.
Bug: 177641226
Test: treehugger
Change-Id: I12796e19e3d18450f332a410ec04bc1486727709
2021-03-25 15:02:39 -07:00
Alex Buynytskyy
8e3eeb507a Making the rest of Streaming installation API public.
Something was left behind when we opened the installation API.

Bug: 152310230
Test: atest PackageManagerShellCommandTest PackageManagerShellCommandIncrementalTest IncrementalServiceTest PackageManagerServiceTest ChecksumsTest
Change-Id: Ia2d4c3f3e97c8432fcca094d6e0f4e97dcc048d4
2021-03-25 14:52:33 -07:00
Patrick Baumann
47c338bf1c Merge "Exposes way to bypass user action on update" into sc-dev 2021-03-25 20:00:53 +00:00
Lucas Dupin
7a597bb5a0 Add luma capabilities to ColorStateList
It's now possible to define an lStar attribute.
This attribute will modify the base color in a way that its chroma will
be conserved, but perceptive luminance will change.

Fixes: 183609373
Test: atest ColorStateListTest
Change-Id: I341a0a532bd9c030e8f52185bacda0db55486216
2021-03-25 12:55:51 -07:00
David Zeuthen
0b2f572eda Merge "PackageManager: Add FEATURE_HARDWARE_KEYSTORE, modify FEATURE_STRONGBOX_KEYSTORE." am: b0a08c82bc am: a911b5da56 am: d91def89c0
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1626660

Change-Id: I15a899ef7ddb405a953203e38337d2e7674f4429
2021-03-25 19:45:13 +00:00
TreeHugger Robot
cf4b4e4d3c Merge "Include LauncherApps#getShortcutIntents" into sc-dev 2021-03-25 17:28:26 +00:00
David Zeuthen
d9cbeba041 PackageManager: Add FEATURE_HARDWARE_KEYSTORE, modify FEATURE_STRONGBOX_KEYSTORE.
These feature flags will hold the KeyMint version for the default and
StrongBox HALs. They can be used by apps to convey that they'll only
work on devices which have a recent enough version of KeyMint.

For example, if an application requires ECDH to be implemented in
Secure Hardware it can convey this requirement by indicated that it
needs FEATURE_HARDWARE_KEYSTORE >= 100. Or if it needs this in the
StrongBox it can use FEATURE_STRONGBOX_KEYSTORE >= 100. As with other
feature flags, this can be used to only show the app on devices which
satisfy such requirements.

Test: Compiles
Bug: 160616951
Change-Id: I582e50fba92de0d598d7e86fcc3b1b2b4a91b103
2021-03-25 09:38:42 -04:00
TreeHugger Robot
230fac1c9c Merge "Make TypedArray implement AutoCloseable" into sc-dev 2021-03-25 07:10:52 +00:00
Pinyao Ting
4750fe5036 Include LauncherApps#getShortcutIntents
Add new api to retrieve pending intents from specified shortcut.

Bug: 151359749
CTS-Coverage-Bug: 13975407
Test: atest ShortcutManagerTest12
Change-Id: I6c413615d1392805f601561550dcb85bfe242b37
2021-03-25 06:30:42 +00:00
Alexander Dorokhine
30ccdcd621 Merge "Remove deprecated methods from AppSearch APIs." into sc-dev 2021-03-25 05:34:38 +00:00
Alexander Dorokhine
65c4fd881e Remove deprecated methods from AppSearch APIs.
These methods were only available for dogfooder transition.
None of these methods shipped in a stable SDK.

Bug: 181887768
Bug: 183395357
Test: Build, presubmit
Change-Id: I74feebd2721208c97475df9b74f734a17a41d5e2
2021-03-24 22:14:38 -07:00
Evgenii Stepanov
9c1d00870e Merge "Cleanup nativeHeapZeroInit and memtagMode implementation." into sc-dev 2021-03-25 05:02:08 +00:00
TreeHugger Robot
aeb2ba8da6 Merge "Accept strings for more parameters in Suspend Dialog" into sc-dev 2021-03-25 04:38:58 +00:00
Jeff DeCew
d4d3b821be Make TypedArray implement AutoCloseable
Fixes: 170316676
Test: atest TypedArrayTest
Change-Id: If3af1c1402156e43f29b166bfcaabc16ee0c0330
2021-03-24 19:51:47 -04:00
Evgenii Stepanov
0aa606cc5a Cleanup nativeHeapZeroInit and memtagMode implementation.
* Rename nativeHeapZeroInit to nativeHeapZeroInitialized.
* nativeHeapZeroInitialized is a tri-state, so make it an @IntDef.
* Add documentation to some accessor methods, and missing @type
  annotations.
* Add attrs_manifest.xml document for the new attributes.

Bug: 182165383
Bug: 182370211
Test: com.android.cts.tagging
Change-Id: Iad46a1da9bc040baf4c438afbc5fd8cd128e99f1
2021-03-24 16:16:56 -07:00
Suprabh Shukla
241955129a Accept strings for more parameters in Suspend Dialog
Allowing passing raw texts offers more flexibility to callers in some
cases. However, in this case, the callers must handle locale changes on
their own.

Test: atest FrameworksServicesTests:SuspendDialogInfoTest
atest FrameworksServicesTests:PackageManagerSettingsTest
atest CtsSuspendAppsTestCases:DialogTests

Fixes: 170653551
Bug: 170653208
Change-Id: Iaa51e1d3f260ad553db8b33fddc935c478a40c9c
2021-03-24 16:14:47 -07:00
TreeHugger Robot
ddd5bd8318 Merge "Disallow domain user selector from querying autoVerify domains" into sc-dev 2021-03-24 21:15:41 +00:00
Philip Junker
2e998fc497 Merge changes from topic "home_sound_exceptions" into sc-dev
* changes:
  Check if package matches home package and allow exceptions.
  Define private manifest flag for home sound exception and add permission
2021-03-24 16:11:32 +00:00
Yuncheol Heo
fef662cdcc Merge "Add Theme.setNewResourcesImpl() method." into sc-dev 2021-03-24 15:36:17 +00:00
Charles Chen
b26733e23a Merge "Add OWNERS for ComponentCallbacksController" am: 4eca6d0c5c am: 06b102a70d am: 0d35481d52
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1642179

Change-Id: Ie69644a729f2f535366f5e9997bff2c9d58ec782
2021-03-24 11:55:37 +00:00
Philip Junker
0b6eaf12b1 Define private manifest flag for home sound exception and add permission
Test: manual
Test: atest HomeSoundEffectControllerTest
Bug: 167946828
Bug: 157407957
Change-Id: If8278013a7b558e837f3e831fabe8ca3a737aa6e
2021-03-24 11:38:00 +01:00
Charles Chen
4eca6d0c5c Merge "Add OWNERS for ComponentCallbacksController" 2021-03-24 10:05:52 +00:00
Charles Chen
1e76f995bf Merge "Move WindowContext module to window package" into sc-dev 2021-03-24 07:45:41 +00:00
Charles Chen
f48ece4875 Move WindowContext module to window package
In this way, we can clarify the owners and it is easier to maintain.
Also refactor to move WindowContext creation logic to ContextImpl.

Test: atest WindowContext WindowContextTests WindowContextPolicyTests
Bug: 159767464
Bug: 152193787

Change-Id: I78432aa18aa97e001f5a9a04321109e456fd137b
2021-03-24 11:26:50 +08:00
Sahana Rao
98ffa1355d Merge "Add manifest attribute requestOptmizedExternalStorageAccess" into sc-dev 2021-03-24 01:31:55 +00:00
Patrick Baumann
9458370ec9 Exposes way to bypass user action on update
Bug: 182487678
Test: atest CtsSilentUpdateHostTestCases
Change-Id: Idb56472544da378c95346329ddc2664400db37a6
Merged-In: Idb56472544da378c95346329ddc2664400db37a6
2021-03-24 01:31:06 +00:00
Winson
4ef9a38396 Disallow domain user selector from querying autoVerify domains
Settings shouldn't need this information as it's all provided as part
of the user state object.

Bug: 183537875

Test: DomainVerificationEnforcerTest

Change-Id: Ib84b92d1d43c098ea2c2a89471c0cd1deacc9661
2021-03-23 14:42:53 -07:00
Winson
522b9a8b3a Convert domain verify dev errors to IllegalArg
Also adds @CheckResult.

Bug: 180991102

Test: atest DomainVerificationManagerApiTest

Change-Id: I3aad2f920ad07889c4debca1415236699a1845d7
2021-03-23 11:27:09 -07:00
Saumya Pathak
cbe66b17b9 Merge "Add app clone profile and APIs." into sc-dev 2021-03-23 11:15:59 +00:00
Saumya Pathak
5a4fc52fc7 Add app clone profile and APIs.
This change adds a new hidden user type "android.os.usertype.profile.CLONE"
and two new system APIs "isCloneProfile" and "hasSharedMedia". To support App cloning, we need to support sharing media between the owner user and the clone user. Adding this as a property in UserTypeDetails.

Bug: 182396009
Test: atest android.multiuser.cts.UserManagerTest#testCloneUser, atest com.android.server.pm.UserManagerTest#testCloneUser and manually ran shell commands on the clone user.

Change-Id: I49ddcbd499944ca9ec05ef4dc10d2e2b231d8b88
(cherry picked from commit db930667a21dac9f0de7cb2fe99175b3b4545bf4)
2021-03-23 11:15:09 +00:00
Sahana Rao
24734440c0 Add manifest attribute requestOptmizedExternalStorageAccess
Add new manifest attribute requestOptmizedExternalStorageAccess.
When the flag is set, app requests for performance optimisations for
file path operations. Apps get this performance optimisation by
bypassing database operations as part of file path operations. Hence,
when the flag is set, app will be resposible to keep MediaStore database
consistent for its file path operations.

App should hold android.Manifest.permission#MANAGE_EXTERNAL_STORAGE
permission or SYSTEM_GALLERY role, otherwise the flag will be ignored.

The default values is
- True if
* if app has android.Manifest.permission#MANAGE_EXTERNAL_STORAGE
permission and targets targetSDK<=30.
* app has SYSTEM_GALLERY role and targetSDK<=29.
- False otherwise.

Bug: 178209446
Test: atest
android.scopedstorage.cts.device.BypassDatabaseOperationsTest

Change-Id: I951c3001c2b7dbe163b3bfecef4ee8ad350230ae
2021-03-23 09:03:27 +00:00
TreeHugger Robot
9081a441dc Merge "Shortcut integration with AppSearch (Part 5)" into sc-dev 2021-03-23 06:19:01 +00:00
Pinyao Ting
b41bc495ec Shortcut integration with AppSearch (Part 5)
Following changes are implemented in this CL:
1. Persist shortcuts to icing whenever a shortcut is created/updated.
2. Delete shortcuts from icing only when publisher explicitly removes
the shortcut. i.e. deletion due to exceeding shortcut limit / disabling
shortcut do not lead to shortcut deletion from icing.
3. Call AppSearchSession#reportUsage when
ShortcutManger#pushDynamicShortcuts is invoked.
4. Add StrictMode warning for calling async method on mainthread.

Bug: 151359749
Test: atest ShortcutManagerTest1 ShortcutManagerTest2 ShortcutManagerTest3 ShortcutManagerTest4 ShortcutManagerTest5 ShortcutManagerTest6 ShortcutManagerTest7 ShortcutManagerTest8 ShortcutManagerTest9 ShortcutManagerTest10 ShortcutManagerTest11
Test: atest CtsShortcutManagerTestCases
Change-Id: I7ae7ec50a7e49f8de819d8239d429fc494017f96
2021-03-22 12:08:24 -07:00
Winson Chiu
e446e84be3 Merge "Correct getDomainVerificationUserState docs" into sc-dev 2021-03-22 16:58:33 +00:00
Charles Chen
b661dcbda6 Merge "Enable to listen to WindowContext's config changes" into sc-dev 2021-03-22 12:28:02 +00:00
Jeff Sharkey
a57db58f24 Surface "neverForLocation" through public API.
Since developers can declare the "neverForLocation" flag in their
manifest as public API, we should also offer a way to inspect the
value that we parsed from the manifest.  We do this by surfacing it
through the existing PackageInfo.requestedPermissionsFlags field.

This also means we can remove the PackageManagerInternal API, since
interested parties can now check PackageInfo directly.

Fix a potential security issue by only accepting flags from manifest
when the application is targeting a modern enough SDK.

Bug: 181812281
Test: atest CtsContentTestCases:PackageManagerTest
Test: atest FrameworksServicesTests:PackageParserTest
Test: atest com.android.server.pm.parsing
Change-Id: I877768c06ee15281f3334794034f4af563e74569
2021-03-19 17:51:16 -06:00
Yuncheol Heo
7ff59f8556 Add Theme.setNewResourcesImpl() method.
- Race condition between Theme.setImpl() cnd Theme.applyStyle() can
  happen when creating Window and Configuration-change occur together.
- To maintain the integrity, the whole process of creating new ThemeImpl
  and setting it in Resources.setImpl() should be guarded by the lock.
- Moves the lock of ThemeImpl.mKey to Theme.mLock.

Bug: 173558667
Test: manual test in the bug
Change-Id: I9ebdc48333b188c0b26b1b7490a5cbb34bbe6e0f
2021-03-19 12:34:51 -07:00
Charles Chen
0783811428 Enable to listen to WindowContext's config changes
This CL overrides registerComponentCallbacks for
WindowContext. Users can use below code snippet
to listen to Configuration changes.
```
Context windowContext = context.createWindowContext(
        display, ...);
windowContext.registerComponentCallbacks(
        new ComponentCallbacks() {
            @Override
            public void onConfigurationChanged(
                    Configuration newConfig) {
                    // Do Something
                }
        });
```

Bug: 181134729
Test: atest WindowContextTests
Test: atest ComponentCallbacksControllerTest

Change-Id: Iff46607bae3c942a96b64dcc97708f3a8c33f23a
2021-03-19 21:56:35 +08:00
Remi NGUYEN VAN
7e26e33269 Merge "Add TEST_NETWORK_SERVICE to module API" 2021-03-19 02:32:00 +00:00
Winson
492e6558d1 Correct getDomainVerificationUserState docs
Clarifies that it's the Context's user being queried and updates for
the selection -> state rename.

Bug: 182345452

Test: none, docs change

Change-Id: Iaefc82b5e1c25292db1f694bf4f05d9f82b81958
2021-03-18 18:28:17 -07:00
Jeff Sharkey
d8a9a21a84 Merge "Add flags to <uses-permission> manifest tags." into sc-dev 2021-03-19 00:06:12 +00:00
Remi NGUYEN VAN
2bf4c58ceb Add TEST_NETWORK_SERVICE to module API
TestNetworkManager is being unbundled; the TEST_NETWORK_SERVICE constant
is necessary for the module to register the manager with
registerContextAwareService.

Bug: 171540887
Test: m
Change-Id: I0690251ddfcdaa8a34830e110b75869a370de389
Merged-In: I0690251ddfcdaa8a34830e110b75869a370de389
2021-03-19 00:04:24 +00:00
Tiger Huang
1c7a274367 Merge "Let insets can still be controlled if its window bounds is moved" into sc-dev 2021-03-18 15:27:57 +00:00
TreeHugger Robot
043d71394c Merge "Add TEST_NETWORK_SERVICE to module API" into sc-dev 2021-03-18 10:33:54 +00:00