Adding state to remember if a log for missing activity manager
is already printed or not.
Bug: 202092164
Test: Manual
Change-Id: Ia945a7396d06f7e8a3fc12359583970faed06a72
Per API council feedback, reflect that the first app in an
AttributionSource chain must have UPDATE_APP_OPS_STATS to do a trusted
blame
Fixes: 222094627
Test: build
Change-Id: I63513ca70ddebe0fd5a05d4414f88985bc3fcad4
This fixes a bug where self-revocation didn't work in multi-user
settings. Now the correct context is used throughout the call stack and
the permission for the calling user will be revoked.
Also added a checked IllegalArgumentException (previously unchecked
SecurityException) when trying to revoke a permission that is not
currently granted.
Test: manual using two users and
atest android.permission.cts.RevokeOwnPermissionTest
Bug: 218788609
Change-Id: I3dce34b8b956b4d1eb0ac1e34b6fdbf1795aa269
After first launch, remember T+ apps which had the review required flag
cleared on launch, until a grant permission request comes in.
Also modifies some behavior of the upgrade code grants.
Bug: 194833441
Test: atest NotificationPermissionTest
Change-Id: Iafef8348e6cdb05fb214382b945cc7886beaff4b
This param controls how long to wait before revoking permission after
every process has been killed.
Deprecate previous API and update all known uses of the deprecated API.
Use updated API for self-revocation feature.
If multiple one-time permission sessions are started for the same
package with different parameters, always use the shortest parameters.
Test: atest android.permission.cts.RevokeOwnPermissionTest,
atest android.permission.cts.OneTimePermissionTest
Bug: 210387494
Change-Id: I0c0e21b3b48dd31f0c267d5c8b89336714835289
Add an API to get a package's eligibility for hibernation for a given
user. A package is either eligible, exempt by the system, or exempt by
the user.
This information can be used to show more accurate UI for hibernation
controls (e.g. disabling the user-controlled exemption toggle if the app
is already exempt by the system)
Bug: 200087723
Test: CTS test in topic
Change-Id: Iea844477184fadb55ea14485dff172ed7be2b715
Test: Manual test using a non-privileged app, atest
android.permission.cts.SelfRevokeRuntimePermissionTest
When calling the API, the permission (along with any other permissions
from the same group) for the current package is downgraded to a one-time
permission, and a one-time permission session is started.
Bug: 210387494
Change-Id: I9f061cbc8c3db720127c96200fe94a644246b6d7
This allows us to check attribution for started ops in tests, and support
starting in system apps
Test: atest CameraMicIndicatorsPermissionTest
Bug: 212434116
Change-Id: Iacdf1d339588cd680c20b3fb55ada9cedb2e70b0
Add the revokePostNotificationPermissionWithoutKillForTest API, which
will allow the shell to revoke the POST_NOTIFICATIONS permission without
killing this app. Gate this permission behind the
REVOKE_POST_NOTIFICATIONS_WITHOUT_KILL permission, which is
signature|privileged, accessible only to the shell.
Ignore-AOSP-First: Contains information about unreleased features
Test: manual
Bug: 194833441
Change-Id: I3177d1aeb338591c1d736aa6b4f073b6db6227e7
Bug: 152453213
Tag: #refactor
This commit prepares PropertyInvalidatedCache to function as a system
api. Specifically, the methods recompute() and bypass() which may be
overridden by clients are now public (instead of protected). This
forces an update to all existing clients, to accommodate the change in
method visibility.
Two small changes have been made as cleanup:
1. The awkwardly named debugCompareQueryResults() is now
resultEquals(), which is more or less consistent with how other
equality tests are named in Android. This name change affects two
clients.
2. PackageManager has changed to use resultEquals() instead of
maybeCheckConsistency(). This provides a simpler and more
consistent use of the APIs. maybeCheckConsistency() has been made
private.
Test: atest PropertyInvalidatedCacheTests
Change-Id: I4110f8e887a4fd8c784141e8892557a9d1b80a94
Add some specific info on checkPermissionForDataDeliveryFromDataSource
javadoc.
Fix: 204179567
Bug: 195144968
Test: build (it's only javadoc)
Change-Id: I6d4e5b9e06bf990b5e40eb727259dc79753d5eef
Action will open the PermissionController screen to review recent
permission decisions. Currently only supported on Auto.
Bug: 194240664
Test: adb shell am start -a android.permission.action.REVIEW_PERMISSION_DECISIONS
Change-Id: Ic37e0b69632d38596b707cd7b1a17fbb89bfa547
Add unused count API to PermissionControllerManager to allow Settings to
pull the number of unused apps from PermissionController.
Bug: 200087723
Bug: 187465752
Test: CTS test in topic
Change-Id: I197b07af0e7a40bb5daececd8ef7d053a2895016
The list of owners is taken from:
- frameworks/base/services/core/java/com/android/server/pm/permission/OWNERS
- cts/common/device-side/util-axt/src/com/android/compatibility/common/util/OWNERS
- vendor/xts/gts-tests/tests/permission/src/com/google/android/permission/gts/OWNERS
Test: presubmit
Change-Id: I3cc073d4890a4295caba8b04752a02f1e00db03c
This fixes a memory leak caused by automatically registering a
PermissionUsageHelper on PermissionManager instantiation.
Bug: 204222680
Test: manual
Change-Id: I94c6da3dd89e8b158552e94c94e4d0fb3f5d6f0d
Api is used by Bluetooth and we need to stop using the hidden call to
permissionChecker
Add associated CTS test
Bug: 195144968
Tag: #refactor
Test: Build
Change-Id: I854b7b5e3d95589bf0d3df307829e3f85e31aee1
Only the most basic two APIs are exposed here, which happens to be the
ones required by USB module so that we can unblock them before IC. The
other overloads and variants can be exposed later when we have a
proper decision on how to expose this entire class as an API.
The constant values are hard-coded because they have to be compile
constants to be included in API, while referencing the PermissionChecker
fields doesn't count as such.
More details are available in Buganizer comments.
Bug: 195353742
Test: atest android.permission5.cts.PermissionCheckerTest
Change-Id: I156c3be0e4c45c95a65bfa9117fb6b850b95238d
Add attribution flags and chain IDs to start callbacks, and have the
PermissionUsageHelper listen for starts. This ensures that, if another
start happens while an op is already running, and has chain information,
then this chain information will be recorded.
Test: manual
Bug: 194198234
Change-Id: I0ab1aa0969b70e18001f4a814ea5689f9329a019
Bug: 186778818
PropertyInvalidatedCache queries that contain wildcard user IDs are no
longer cached. Some simple multi-user tests show that no current
caches use wildcard user IDs, so the change has no effect on
performance. The bypass() mechanism is used to avoid the cache when
necessary.
The change is preemptive - there are no known uses of these caches
with wildcard user IDs.
Test: atest
* FrameworksServicesTests:UserManagerServiceCreateProfileTest
Change-Id: I60be14ae33fcd6e2e8df30c279311f6ffdf7711c
These two PermissionManager methods are using AttributionSource as
metadata only, and aren't interested in the remote caller enforcing
that the claimed UID matches the caller, since they're not actually
being used for permission enforcement.
Thus we pass the metadata using the AttributionSourceState holder
object and reconstruct on the remote side, entirely avoiding the
enforceCallingUid() check.
Bug: 193842956
Test: atest CtsPermission5TestCases
Change-Id: I576b6feb8cc2b0586b4341268866d8027689293f
For cases where the attribution soruce doesn't need to be
registered as trusted we are now using a shares static
token since the only purpose of the token in these cases
is for watching the source process dying as opposed to that
and security for registered cases.
bug: 192415943
Test: CtsPermissionTestCases
CtsPermission2TestCases
CtsPermission3TestCases
CtsPermission4TestCases
CtsPermission5TestCases
Change-Id: I93fde9ca1cacada7929761533dcae11b2736ce1e
Add and populate a "trusted" attribution flag, that verifies the
attribution sources used to create it were trusted.
Fixes: 192270935
Test: atest RuntimePermissionsAppOpTrackingTest
Change-Id: Ifd8f825151bec55aa795da7bee0a3069509f5abe
Add a historical flag to signify that attribution chains should be
assembled. Assemble the chains, filter out middle nodes, and attach the
last visible node to the start as a proxy info
Bug: 158792096
Test: manual
Change-Id: I8fbd8f438c62b28fd90039440e86224c624dea79
Attribution source is the abstraction to capture the data
flows for private data across apps. Checking permissions
for an attribution source does this for all apps in the
chain that would receive the data as well as the relevant
app ops are checked/noted/started as needed.
Teach speech recognition service about attribution
chains. If an implementation does nothing the OS
would enforce permisisons and do blame as always.
This apporach leads to double blaming and doesn't
support attribition chains where app calls into
the default recognizer which calls into the on
device recognizer (this nests recursively). If the
implementer takes advantage of the attribution chain
mechanims the permissions for the entire chain are
checked at mic access time and all apps are blamed
only once.
Fixed a few bugs around finishing ops for attribution
chains. Also ensured that any app death in a started
attribution chain would lead to finishing the op for
this app
bug: 158792096
Test: (added tests for speech reco)
atest CtsMediaTestCases
atest CtsPermissionTestCases
atest CtsPermission2TestCases
atest CtsPermission3TestCases
atest CtsPermission4TestCases
atest CtsPermission5TestCases
atest CtsAppOpsTestCases
atest CtsAppOps2TestCases
Merged-In: Ic92c7adc14bd2d135ac13b96f17a1b393dd562e4
Change-Id: Ic92c7adc14bd2d135ac13b96f17a1b393dd562e4
Since, we are opening PermissionControllerService to instant apps for
the permission group mapping API, I'm reviewing the permission checks
and this is the only missing one. However, this API is just a trigger
to update our state so calling it some more times shouldn't pose a
security risk, so this fix is just a nice-to-have.
Bug: 189836392
Test: presubmit
Change-Id: I6e9159ce090acaad2ecf522bd04c613169e03252
setRuntimePermissionGrantStateByDeviceAdminFromParams().
This is nice to have, but not necessarily a security fix because we are
already always enforcing ADJUST_RUNTIME_PERMISSIONS_POLICY.
Bug: 158735247
Test: presubmit
Change-Id: I629969e04e1d5e7e3ef47c8833780f19d83b9e0b
The API is moved from PermissionControllerManager (only a System API)
to PackageManager to expose it as public API.
Bug: 182094776
Test: atest GetPermissionGroupInfoTest
Change-Id: I175afb2e37bf2651b91765029645f7940f58f39c