When an app is proxying access to runtime permission protected
data it needs to check whether the calling app has a permission
to the data it is about to proxy which leaves a trace in app ops
that the requesting app perofmed a data access. However, then the
app doing the work needs to get the protected data itself from the
OS which access gets attributed only to itself. As a result there
are two data accesses in app ops where only the first one is a
proxy one that app A got access to Foo through app B - that is the
one we want to show in the permission tracking UIs - and one
for the data access - that is the one we would want to blame on
the calling app, and in fact, these two accesses should be one -
that app A accessed Foo though B. This limitation requires fragile
one off workarounds where both accesses use the same attribution
tag and sys UI has hardcoded rules to dedupe. Since this is not
documented we cannot expect that the ecosystem would reliably
do this workaround in apps that that the workaround in the OS
would be respected by every OEM.
This change adds a mechaism to resolve this issue. It allows for
an app to create an attribution context for another app and then
any private data access thorugh this context would result in a
single app op blame that A accessed Foo though B, i.e. we no longer
have double accounting. Also this can be nested through apps, e.g.
app A asks app B which asks app C for contacts. In this case app
B creates an attribution context for app A and calls into app C
which creates an attribution context for app B. When app C gets
contacts the entire attribution chain would get a porper, single
blame: that C accessed the data, that B got the data from C, and
that A got the data form B. Furthermore, this mechanism ensures
that apps cannot forget to check permissions for the caller
before proxying private data. In our example B and C don't need
to check the permisisons for A and B, respectively, since the
permisisons for the entire attribution chain are checked before
data delivery. Attribution chains are not forgeable preventing
a bad actor to create an arbitrary one - each attribution is
created by the app it refers to and points to a chain of
attributions created by their corresponding apps.
This change also fixes a bug where all content provider accesses
were double counted in app ops due to double noting. While at
this it also fixes that apps can now access their own last ops.
There was a bug where one could not pass null getting the attributed
ops from a historical package ops while this is a valid use case
since if there is no attribution everything is mapped to the null
tag. There were some app op APIs not being piped thorough the app
ops delegate and by extension through the app ops policy. Also
now that we have nice way to express the permission chain in a
call we no longer need the special casing in activity manager to
handle content provider accesses through the OS. Fixed a bug
where we don't properly handle the android.os.shell calls with
an invlaid tag which was failing while the shell can do any tag.
Finally, to ensure the mechanims is validated and works end-to-end
we are adding support for a voice recognizer to blame the client
app for the mic access. The recognition service can create a blaming
context when opening the mic and if the mic is open, which would
do all permission checks, we would not do so again. Since changes
to PermissionChercker for handling attribution sources were made
the CL also hooks up renounced permissoins in the request permission
flow and in the permission checks.
bug:158792096
bug:180647319
Test:atest CtsPermissionsTestCases
atest CtsPermissions2TestCases
atest CtsPermissions3TestCases
atest CtsPermissions4TestCases
atest CtsPermissions5TestCases
atest CtsAppOpsTestCases
atest CtsAppOps2TestCases
Change-Id: Ib04585515d3dc3956966005ae9d94955b2f3ee08
Also, standardize the implementations of getConsumedPower()
to consistently return the total power consumed, not the
power unattributed to apps.
Bug: 183235836
Test: atest FrameworksCoreTests:com.android.internal.os.BatteryStatsTests
Change-Id: Iaedb29b9d7afd9843b0ab871e9b8656963db11ea
With this change we allow system packages with the new permission to
override ChangeIds specifically annotated as Overridable to set
overrides even on non-debuggable builds.
Bug: 174043039
Bug: 175874108
CTS-Coverage-Bug: 180396382
Test: atest FrameworksServicesTests:CompatConfigTest
Test: atest FrameworksServicesTests:PlatformCompatTest
Change-Id: Ib8d5d83b5fd62acb5808d10f5c413616f29ee65c
Allowing passing raw texts offers more flexibility to callers in some
cases. However, in this case, the callers must handle locale changes on
their own.
Test: atest FrameworksServicesTests:SuspendDialogInfoTest
atest FrameworksServicesTests:PackageManagerSettingsTest
atest CtsSuspendAppsTestCases:DialogTests
Fixes: 170653551
Bug: 170653208
Change-Id: Iaa51e1d3f260ad553db8b33fddc935c478a40c9c
This changes stores a brightness value per display.
Add brightness value item to persistent data store.
Add BrightnessSettingController to save and retrieve brightnesses.
It is indexed by primary display device of the concerned logical display.
Add method in DisplayManager to expose this.
Bug: 176985835
Bug: 147415200
Bug: 175286226
Test: manual, check "adb shell dumpsys display | grep -A10 Persistent" shows brightness values for each display attached.
Change-Id: Ib8557f8a0f45a5bfb0810967f678015d3f121bb9
We also changed API from setHotwordDetectionServiceConfig
to updateState.
Bug: 182951186
CTS-Coverage-Bug: 183425641
Test: Test: atest CtsVoiceInteractionTestCases
Test: atest CtsVoiceInteractionTestCases --instant
Change-Id: I29ed0736f9502d3ac5a29ea26a8386bce7113e54
Uses the atom MagnificationModeWithImeOnReported in westworld to log
the activated mode when the IME window is shown on the screen.
Adding a new callback API in the MagnificationCallback to monitor the
IME window visibility changes. The A11y framework registers the
callback when the magnification is enabled. It logs the related
data when it receives the IME window visibility changes through
this callback and the magnification is in the activation.
Bug: 154021596
Test: a11y CTS & unit tests
Test: make statsd_testdrive && ./out/host/linux-x86/bin/statsd_testdrive 346
Merged-In: I49b02e00d5a1131b388eeb923440f59a2b4f81a6
Change-Id: I49b02e00d5a1131b388eeb923440f59a2b4f81a6
(cherry picked from commit 1aa113d8dd)
Enabled querying and processing Mobile Radio and Gnss energy consumption
in BatteryStatsExternal.
Attribute and accumulate their power deltas in BatteryStatsImpl
Utilize measured power data in MobileRadioPowerCalculator and
GnssPowerCaluclulator.
Bug: 174818228
Test: atest GnssPowerCalculatorTest
Test: atest MobileRadioPowerCalculatorTest
Test: BatteryStatsExternalWorkerTest
Change-Id: If062033ff3c8cff20842be2cd92b04f6cb981366
When the frame size and the frame position of the window are changed at
the same time, setPosition to the surface will be applied first, and
the client will draw on the new-size buffer later, which makes the
window flicker.
This CL uses applyWithNextDraw to make the new surface position can be
applied while the new frame is drawn. applyWithNextDraw is applied only
when
- the window doesn't have a move animation. So if a window needs to make
resizing stable, it may need PRIVATE_FLAG_NO_MOVE_ANIMATION.
- it is visible, e.g., the surface is shown, and the window is OK to
display -- for better performance.
If applyWithNextDraw is used while the window frame is changed to an
empty rectangle, e.g., Rect(10, 10 - 1000, 10), mNextDrawUseBlastSync
will stay true forever, because we don't draw while the dirty area is
empty, and ViewRootImpl would lose the only chance to clear the flag.
performTraversals will never be executed.
This CL makes mNextDrawUseBlastSync can be cleared in that case.
Bug: 182729646
Fix: 176874720
Test: steps in the bug
Change-Id: I81b0574ee8db7e4d9053639f56e04858d9feae90
The implementation is now based on BatteryStats.getStartClockTime
Bug: 183434301
Test: atest FrameworksCoreTests:com.android.internal.os.BatteryUsageStatsTest
Change-Id: I55184f981b2583b184d859788837443e58eccb6c
It will be more secure to use PersistableBundle
instead of Bundle for passing the configrations
data from VoiceInteractor to HotwordDetectionService.
Bug: 176938300
Test: Test: atest CtsVoiceInteractionTestCases
Test: atest CtsVoiceInteractionTestCases --instant
Change-Id: I19a412cca5e2cd5f9f79a112a9d7da8fd3a00a38
This is simply passed through the system to the AlwaysOnHotwordDetector.
Bug: 182788844
Bug: 168305377
CTS-Coverage-Bug: 183425641
Test: builds
Change-Id: I2b7147b330051d870bfe970e9b5e16aaab52e9bc
Route the sharesheet user interaction from PeopleService to Remote Prediction Service, while PeopleService is making inference for sharesheet.
It is guarded by the flag "adb shell device_config put systemui dark_launch_remote_prediction_service_enabled true"
Test: test on local device
Bug: 180933488
Change-Id: I7db52c69224e69ad3125362185e2ffd1a474bb78
Merged-In: I7db52c69224e69ad3125362185e2ffd1a474bb78
(cherry picked from commit 51daca2ea3)
* Remove all media-specific color extraction and colorization logic
* Remove all 'large icon' gradienting logic
* Simplify base (headerless) style to use a LinearLayout instead of tweaking margins
* Make compact media layout a tweak of the base (headerless) layout
* Make big_media layout a tweak of the big_base layout
* Fix an unnecessary swooping animation that happened on expand
* Ensure RTL layout also works
Fixes: 172652345
Test: manual testing w/ updated notify2
Change-Id: I11c1494c0ac32aaf3e9d2010560cc8f1d8c50037
This is guarded by the flag "apply_sharing_app_limits_in_sysui".
Bug: 182146792
Test: verify on local phone
Test: atest ChooserActivityTest
Change-Id: Ic03395343432015400f37299e5748932d2bd9eaa
Merged-In: Ic03395343432015400f37299e5748932d2bd9eaa
(cherry picked from commit d001e08b92)
It's been default true for a while but some users seem to have a false
value on their phones. We intend for everyone to have it right now.
Bug: 183277962
Test: Builds, long screenshot functionality shows up.
Change-Id: I1a7bb3eddc2f613943b8c1c78a2ac43aa07466a6
Introduces a SparseDoubleArray class.
It is based on a SparseLongArray, storing the double values
in the bits of the long in the SparseLongArray.
This is a hidden class.
Not all long-term desired features of SparseDoubleArray
have necessarily been implemented here; only the ones needed
right now have been written.
Bug: 182845832
Test: atest BatteryStatsTests
Test: atest FrameworksCoreTests:android.util.SparseDoubleArrayTest
Change-Id: Id68b22328f2660839e2005990766d99140b00c16