App can set a android.internal.PROPERTY_NO_APP_DATA_STORAGE property in it's
AndroidManifest.xml which will tell platform to avoid creating data
directories for it.
This property is intentionally not exposed as public API because not
having private app storage is a very niche requirement.
This change also logic to prevent app updates from changing value of the
property, i.e.: if an installed app doesn't specify value of the
PROPERTY_NO_APP_DATA_STORAGE property (or has it set to false), then any
update to this app shouldn't have this property specified (or explicitly
set it to false). If an app has PROPERTY_NO_APP_DATA_STORAGE set to
true, then all updates should keep that property set to true.
Note: this change only takes into account internal storage. Removing
app's external storage will be done in the follow up cl.
Bug: 211761016
Test: atest PackageManagerShellTest
Change-Id: I3e541d947a77f5c050bf706f64009f21c24dcbc9
Bug: 152453213
Tag: #refactor
This commit prepares PropertyInvalidatedCache to function as a system
api. Specifically, the methods recompute() and bypass() which may be
overridden by clients are now public (instead of protected). This
forces an update to all existing clients, to accommodate the change in
method visibility.
Two small changes have been made as cleanup:
1. The awkwardly named debugCompareQueryResults() is now
resultEquals(), which is more or less consistent with how other
equality tests are named in Android. This name change affects two
clients.
2. PackageManager has changed to use resultEquals() instead of
maybeCheckConsistency(). This provides a simpler and more
consistent use of the APIs. maybeCheckConsistency() has been made
private.
Test: atest PropertyInvalidatedCacheTests
Change-Id: I4110f8e887a4fd8c784141e8892557a9d1b80a94
Similar to bindService(), even if bindServiceAsUser() returns false,
unbindService() must still be called to allow the service to shut down.
The documentation is updated to reflect this.
Bug: 212663289
Test: m ds-docs-java
Change-Id: I780d307f4a0ebf8bef508932181e580f168b5578
Declaring duplicate permissions with different protection levels is
not allowed. Add the scheme enforcement for manifest during parsing.
Bug: 211934395
Test: atest AppSecurityTests
Change-Id: Ieb006ab4abf19baf949e9b5bfd3e3fea16237527
Android T allows apps to declare a runtime receiver as not exported
by invoking registerReceiver with a new RECEIVER_NOT_EXPORTED flag;
receivers registered with this flag will only receive broadcasts from
the platform and the app itself. However to ensure developers can
properly protect their receivers, all apps targeting T or later
registering a receiver for non-system broadcasts must specify either
the exported or not exported flag when invoking #registerReceiver;
if one of these flags is not provided, the platform will throw a
SecurityException. The platform and system apps have several locations
where a receiver is registered for non-system broadcasts that have
not yet been audited to determine if they should be exported. This
commit introduces a temporary flag that can be used to meet the
new requirement that a flag be specified while also marking the
receiver as needing an audit before the T release to determine
whether the receiver should be exported or not.
Bug: 161145287
Test: atest ContextTest
Change-Id: Ie9d1e2ad6e2d831c374437ed65d085711b7dc3b7
Unless we are looking at stack traces (e.g. from strict mode) it's not
possible to identify which type of object is not being closed (most
methods are 'close' or 'release). Change the logged text to clarify.
Change-Id: Ib90eac716f43c2c2caf8d8c6fb64a7bd90562da9
Test: manual
This is a preliminary change to apply READY/FAILED/APPLIED to
non-staged sessions.
* Move mSession* fields to PackageInstallerSession as they
will be useful to both staged and non-staged sessions.
* Rename some members as they will be applicable to both staged
and non-staged sessions.
Bug: 210359798
Test: atest StagingManagerTest \
PackageInstallerSessionTest \
CtsStagedInstallHostTestCases
Change-Id: Ie1b09aa4c7cbc843712c731a1b903d26684b2e30
Whenever a package's app ID has changed, the system broadcasts should
behave as if the package is fully uninstalled and then re-installed
subsequently. Additional extras are added to indicate the app ID change
to allow components to handle this case specifically.
Test: atest SharedUserMigrationTest#testDataMigration
Bug: 179284822
Change-Id: Ie00eaed1f0a704876ea76aa0e5ae2a1b21f199df
The initial selection toolbar related architecture. Render service
part and the implementation will be revised in the follow up changes.
Bug: 190030331
Bug: 205822301
Test: manual. Can boot to home and get manager successfully.
Ignore-AOSP-First: new file for T
Change-Id: Iab5d5f2e5e48e6258a63fb0c479194c958ea61e8
Modified myAttributionSource() to check for global AS for
process in ActivityThread and fallback to building new AS
with PackageManager#getPackageForUid(myUid()) if null.
Tag: #feature
Bug: 210467846
Bug: 210468546
Test: build
Change-Id: I7aa75395469bf0bb806100420faaf98c52057355
CTS-Coverage-Bug: 210906055
This reverts commit a822ccd755.
Reason for revert: Broke a shell-transition CTS test (b/210902428)
Change-Id: I479a6152f94cc6aff30caa8f49932c53d420db1e
Migrate the following unsafe parcel APIs in framework-minus-apex:
* Parcel.readSerializable()
* Parcel.readArrayList()
* Parcel.readList()
* Parcel.readParcelable()
* Parcel.readParcelableList()
* Parcel.readSparseArray()
This CL was generated by applying lint fixes that infer the expected
type from the caller code and provide that as the type parameter
(ag/16365240).
A few observations:
* In some classes we couldn't migrate because the class also belonged to
another build module whose min SDK wasn't current (as is the case for
framework-minus-apex), hence I suppressed the lint check
(since I'll eventually submit the lint check to the tree).
* In some cases, I needed to do the cast in
https://stackoverflow.com/a/1080525/5765705 to make the compiler happy
since there isn't another way of providing a class of type
Class<MyClassWithGenerics<T>>.
* In the readSerializable() case, the new API also requires the class
loader, that was inferred to by InferredClass.class.getClassLoader().
* Note that automatic formatting and import rely on running hooked up
to the IDE, which wasn't the case here.
Bug: 195622897
Test: TH passes
Change-Id: I11a27b9bdab7959ee86e90aa1e1cbebd7aaf883c
mPendingResult is not guaranteed to have been initialized at this point.
Test: Manual.
Bug: 210266601
Change-Id: I84287a068d03dd3aac2b046d1b8fdd8e6e52803f
- getShortcutIntent and startShortcut now additionally checks AppSearch
if specifed shortcuts cannot be found in memory.
- getShortcutIconFd and getShortcutIconUri now additionally checks
AppSearch if specified shortcuts cannot be found in memory.
- getShortcutIconResId is unchanged since the api is deprecated.
- Introduced ShortcutQuery.FLAG_GET_PERSISTED_DATA, when used in
getShortcuts, it additionally performs the check in AppSearch.
Bug: 151359749
Test: atest CtsShortcutManagerTestCases
Change-Id: I0e56e3d0261fc0a3cf0ab4c5decbbd59ac3d7d29
* changes:
Support per-process Application class (AM and client side)
Support per-process Application class (package parser)
Support per-process Application class in <process> tag
It isn't enough to only dump the theme id and name because there is
no whole theme inheritance map. Developers need the map to figure out
why the attribute value is so strange.
A theme is a kind of style. This patch creates an API to retrieve the
parent id for any style. And, it dumps the whole inheritance between
themes until it can't find the parent style.
Test: manual test described in b/209708201#comment5
Bug: 209708201
Change-Id: I9de0e6e9aaeff7cb9fc89dc9b8a04925e84f975c
Now the <process> tag supports `android:name`, which takes a custom
Application class name. If omitted, the system defaults to the
class set in the <application> tag, or the default class which is
`android.app.Application`.
Bug: 197264681
Test: atest CtsProcessTest
Test: atest PackageManagerServiceUnitTests
Change-Id: Iaf336cc34fe950c4b3d8887de557857f8c23dc83