Commit Graph

261 Commits

Author SHA1 Message Date
Manjeet Rulhania
efdf00bff9 Fix printing duplicate logs to save on battery
Adding state to remember if a log for missing activity manager
is already printed or not.

Bug: 202092164
Test: Manual
Change-Id: Ia945a7396d06f7e8a3fc12359583970faed06a72
2022-03-26 12:05:34 +00:00
Nate Myren
e0ae12756c Add conditional permission check annotation to checkPermission methods
Per API council feedback, reflect that the first app in an
AttributionSource chain must have UPDATE_APP_OPS_STATS to do a trusted
blame

Fixes: 222094627
Test: build
Change-Id: I63513ca70ddebe0fd5a05d4414f88985bc3fcad4
2022-03-21 21:16:15 +00:00
Ganesh Olekar
6f73905cf6 Merge "Location provider check for subattribution" into tm-dev 2022-03-17 23:40:32 +00:00
Ganesh Olekar
7f13dcaadf Location provider check for subattribution
Bug: 200280741
Test: atest com.android.systemui.privacy.PrivacyDialogTest
Change-Id: I7240db08025d801eb537234ca95aeb17c3f302f2
Merged-In: I7240db08025d801eb537234ca95aeb17c3f302f2
2022-03-17 20:32:19 +00:00
Thomas Vannet
c418be3814 Rename revokeOwnPermissionsOnKill to revokeSelfPermissionsOnKill
Bug: 215555831
Test: atest android.permission.cts.RevokeSelfPermissionTest
Change-Id: I887e2b8a86868352e772537addd8cd20ef305d7b
2022-03-16 16:39:59 -07:00
Thomas Vannet
a24e244560 Self-revocation: Call PermissionControllerManager directly from Context
This fixes a bug where self-revocation didn't work in multi-user
settings. Now the correct context is used throughout the call stack and
the permission for the calling user will be revoked.

Also added a checked IllegalArgumentException (previously unchecked
SecurityException) when trying to revoke a permission that is not
currently granted.

Test: manual using two users and
atest android.permission.cts.RevokeOwnPermissionTest
Bug: 218788609

Change-Id: I3dce34b8b956b4d1eb0ac1e34b6fdbf1795aa269
2022-03-16 16:35:59 -07:00
Ganesh Olekar
bc545518e2 Merge "Add attribution to PermGroupUsage and indicators" 2022-02-17 18:20:39 +00:00
Ganesh Olekar
b5ccbc33ed Add attribution to PermGroupUsage and indicators
Bug: 200280741
Test: atest com.android.systemui.privacy.PrivacyDialogTest
Change-Id: I1dcd7bea997605f3caaac742419476f4e0ac2fdf
CTS-Coverage-Bug: 220157796
2022-02-17 18:17:18 +00:00
Nate Myren
86d226366a Add information to grant permissions intent for continue messages
After first launch, remember T+ apps which had the review required flag
cleared on launch, until a grant permission request comes in.

Also modifies some behavior of the upgrade code grants.

Bug: 194833441
Test: atest NotificationPermissionTest
Change-Id: Iafef8348e6cdb05fb214382b945cc7886beaff4b
2022-02-09 10:01:26 -08:00
Thomas Vannet
8b2f6ecf8a Update self-revocation doc: revoke by permission, not group
Test: None, this is just a doc update
Bug: 210387494
Change-Id: Ib6555c9c419e2f5b890d31c249f09207632d7724
2022-02-03 15:46:12 -08:00
Thomas Vannet
9346e5338a Add killed delay param to startOneTimePermissionSession
This param controls how long to wait before revoking permission after
every process has been killed.
Deprecate previous API and update all known uses of the deprecated API.
Use updated API for self-revocation feature.
If multiple one-time permission sessions are started for the same
package with different parameters, always use the shortest parameters.

Test: atest android.permission.cts.RevokeOwnPermissionTest,
atest android.permission.cts.OneTimePermissionTest
Bug: 210387494

Change-Id: I0c0e21b3b48dd31f0c267d5c8b89336714835289
2022-02-03 15:46:12 -08:00
Nate Myren
e5d2351829 Merge "create systemApi checkPermissionForStartDataDelivery in PermissionManager" 2022-01-25 18:09:06 +00:00
Kevin Han
19166cb1fc Add API to get hibernation eligibility
Add an API to get a package's eligibility for hibernation for a given
user. A package is either eligible, exempt by the system, or exempt by
the user.

This information can be used to show more accurate UI for hibernation
controls (e.g. disabling the user-controlled exemption toggle if the app
is already exempt by the system)

Bug: 200087723
Test: CTS test in topic
Change-Id: Iea844477184fadb55ea14485dff172ed7be2b715
2022-01-21 13:31:06 -08:00
Thomas Vannet
f331c8f585 Immediately revoke permission on process kill after a self-revocation
Test: atest android.permission.cts.RevokeOwnPermissionTest
Bug: 210387494
Change-Id: Iaa3a4c00847d5411c5b829d190eba8231d046d8c
2022-01-21 05:51:05 +00:00
Thomas Vannet
395f8deeff Rename selfRevokePermissions to revokeOwnPermissionsOnKill
Test: atest android.permission.cts.RevokeOwnPermissionTest
Bug: 215555831
Bug: 210575642
Bug: 210387494
Change-Id: I94e29f66d13ac76669fab2ccc08879c30c26b7ea
2022-01-21 05:50:22 +00:00
Thomas Vannet
af615e7baf Add self revocation public API
Test: Manual test using a non-privileged app, atest
android.permission.cts.SelfRevokeRuntimePermissionTest

When calling the API, the permission (along with any other permissions
from the same group) for the current package is downgraded to a one-time
permission, and a one-time permission session is started.

Bug: 210387494

Change-Id: I9f061cbc8c3db720127c96200fe94a644246b6d7
2022-01-11 16:32:40 -08:00
Nate Myren
7d095bbc0b create systemApi checkPermissionForStartDataDelivery in PermissionManager
This allows us to check attribution for started ops in tests, and support
starting in system apps

Test: atest CameraMicIndicatorsPermissionTest
Bug: 212434116
Change-Id: Iacdf1d339588cd680c20b3fb55ada9cedb2e70b0
2022-01-10 22:01:34 +00:00
Nate Myren
2c54f50da6 Allow shell to revoke notification permission without kill
Add the revokePostNotificationPermissionWithoutKillForTest API, which
will allow the shell to revoke the POST_NOTIFICATIONS permission without
killing this app. Gate this permission behind the
REVOKE_POST_NOTIFICATIONS_WITHOUT_KILL permission, which is
signature|privileged, accessible only to the shell.

Ignore-AOSP-First: Contains information about unreleased features
Test: manual
Bug: 194833441
Change-Id: I3177d1aeb338591c1d736aa6b4f073b6db6227e7
2022-01-10 11:58:45 -08:00
Lee Shombert
9a686c07ba Merge "Prepare PropertyInvalidatedCache for SystemApi" 2022-01-06 23:14:05 +00:00
Kevin Han
8c7b307f03 Merge "Add unused count API" 2022-01-06 01:24:26 +00:00
Jordan Jozwiak
a5ca465453 Merge "Intent action to review permission decisions" 2022-01-05 17:25:01 +00:00
Nate Myren
96f8c9fd10 Merge "Ensure only microphone attribution chains are recorded" 2022-01-04 17:04:27 +00:00
Lee Shombert
0cece3898b Prepare PropertyInvalidatedCache for SystemApi
Bug: 152453213
Tag: #refactor

This commit prepares PropertyInvalidatedCache to function as a system
api.  Specifically, the methods recompute() and bypass() which may be
overridden by clients are now public (instead of protected).  This
forces an update to all existing clients, to accommodate the change in
method visibility.

Two small changes have been made as cleanup:

 1. The awkwardly named debugCompareQueryResults() is now
    resultEquals(), which is more or less consistent with how other
    equality tests are named in Android.  This name change affects two
    clients.

 2. PackageManager has changed to use resultEquals() instead of
    maybeCheckConsistency().  This provides a simpler and more
    consistent use of the APIs.  maybeCheckConsistency() has been made
    private.

Test: atest PropertyInvalidatedCacheTests

Change-Id: I4110f8e887a4fd8c784141e8892557a9d1b80a94
2022-01-04 08:13:59 -08:00
William Escande
6b436464d2 Javadoc on Method from api review
Add some specific info on checkPermissionForDataDeliveryFromDataSource
javadoc.
Fix: 204179567
Bug: 195144968
Test: build (it's only javadoc)

Change-Id: I6d4e5b9e06bf990b5e40eb727259dc79753d5eef
2022-01-03 12:08:51 +01:00
Nate Myren
33c3c1a629 Ensure only microphone attribution chains are recorded
Also ensure each chain is attributed to only one op

Test: manual
Fixes: 212434116
Change-Id: I50efc2b305627f8e37eb28842487b911dce5d925
2021-12-29 11:36:49 -08:00
Jordan Jozwiak
70b59c872d Intent action to review permission decisions
Action will open the PermissionController screen to review recent
permission decisions. Currently only supported on Auto.

Bug: 194240664
Test: adb shell am start -a android.permission.action.REVIEW_PERMISSION_DECISIONS
Change-Id: Ic37e0b69632d38596b707cd7b1a17fbb89bfa547
2021-12-22 13:13:46 -08:00
Kevin Han
f23347642c Add unused count API
Add unused count API to PermissionControllerManager to allow Settings to
pull the number of unused apps from PermissionController.

Bug: 200087723
Bug: 187465752
Test: CTS test in topic
Change-Id: I197b07af0e7a40bb5daececd8ef7d053a2895016
2021-12-16 18:11:14 -08:00
Nate Myren
8fb048aede Lock mAttributionChains in PermissionUsageHelper
Test: manual
Fixes: 201451838
Change-Id: I4b17ed0e65fae45f393665f7f9d617a2acc1cbdd
2021-12-08 13:51:09 -08:00
Hai Zhang
124f68b2f2 Merge "Unify owners for default permission grant policy." am: bff35de778 am: 74906bb45b am: b78ad5e8db am: a176c9efb2 am: 2d8f698bd7
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1878788

Change-Id: Ife128e50b161df46d3116acbbaf5472c36aa60c3
2021-11-05 21:11:43 +00:00
Hai Zhang
7ea5048947 Unify owners for default permission grant policy.
The list of owners is taken from:
- frameworks/base/services/core/java/com/android/server/pm/permission/OWNERS
- cts/common/device-side/util-axt/src/com/android/compatibility/common/util/OWNERS
- vendor/xts/gts-tests/tests/permission/src/com/google/android/permission/gts/OWNERS

Test: presubmit
Change-Id: I3cc073d4890a4295caba8b04752a02f1e00db03c
2021-11-03 03:41:45 +00:00
Nate Myren
533d486d60 Merge "Only initialize PermissionUsageHelper lazily or when requested" 2021-11-02 22:07:52 +00:00
Nate Myren
338cafab6c Only initialize PermissionUsageHelper lazily or when requested
This fixes a memory leak caused by automatically registering a
PermissionUsageHelper on PermissionManager instantiation.

Bug: 204222680
Test: manual
Change-Id: I94c6da3dd89e8b158552e94c94e4d0fb3f5d6f0d
2021-11-02 21:03:04 +00:00
William Escande
57bc716432 Add checkPermissionForDataDeliveryFromDataSource
Api is used by Bluetooth and we need to stop using the hidden call to
permissionChecker
Add associated CTS test

Bug: 195144968
Tag: #refactor
Test: Build
Change-Id: I854b7b5e3d95589bf0d3df307829e3f85e31aee1
2021-10-07 20:11:01 +02:00
Treehugger Robot
d335f26f60 Merge "Update permissions OWNERS" am: dbbb827a79 am: 799b63acc2 am: 3c213db1f8 am: 31e6117eb0 am: 3dfc16e7da
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1838051

Change-Id: Ib5be74f5815d966db35d5c74ea9c2de445c33144
2021-09-28 05:12:34 +00:00
Treehugger Robot
799b63acc2 Merge "Update permissions OWNERS" am: dbbb827a79
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1838051

Change-Id: Ic4d3da57e701c0da40c55bd44d73df0edce9a911
2021-09-28 04:19:01 +00:00
Evan Severson
73ebf86c32 Update permissions OWNERS
Bug: 201319595
Test: None
Change-Id: Iebb9cd731b592df2dfb79bd088e917635c21b6b1
2021-09-28 01:03:32 +00:00
Hai Zhang
4c8ff26e9f Expose PermissionChecker as system API.
Only the most basic two APIs are exposed here, which happens to be the
ones required by USB module so that we can unblock them before IC. The
other overloads and variants can be exposed later when we have a
proper decision on how to expose this entire class as an API.

The constant values are hard-coded because they have to be compile
constants to be included in API, while referencing the PermissionChecker
fields doesn't count as such.

More details are available in Buganizer comments.

Bug: 195353742
Test: atest android.permission5.cts.PermissionCheckerTest
Change-Id: I156c3be0e4c45c95a65bfa9117fb6b850b95238d
2021-09-14 11:51:56 -07:00
Nate Myren
aad177261c Merge "Add attribution info to start callbacks" into sc-dev am: 5d97f29218 am: d1a82a7de8
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/15446590

Change-Id: Ic800a8e11e6d8513629ec8e9b1f64ffef0c85645
2021-08-03 20:18:08 +00:00
Nate Myren
06d07d54db Add attribution info to start callbacks
Add attribution flags and chain IDs to start callbacks, and have the
PermissionUsageHelper listen for starts. This ensures that, if another
start happens while an op is already running, and has chain information,
then this chain information will be recorded.

Test: manual
Bug: 194198234
Change-Id: I0ab1aa0969b70e18001f4a814ea5689f9329a019
2021-08-03 08:25:31 -07:00
Lee Shombert
e2405233d9 Do not cache wildcard users (PermissionManager)
Bug: 186778818

PropertyInvalidatedCache queries that contain wildcard user IDs are no
longer cached.  Some simple multi-user tests show that no current
caches use wildcard user IDs, so the change has no effect on
performance.  The bypass() mechanism is used to avoid the cache when
necessary.

The change is preemptive - there are no known uses of these caches
with wildcard user IDs.

Test: atest
 * FrameworksServicesTests:UserManagerServiceCreateProfileTest

Change-Id: I60be14ae33fcd6e2e8df30c279311f6ffdf7711c
2021-08-02 17:03:41 +00:00
Jeff Sharkey
75d4f93a4e Pass metadata as AttributionSourceSource.
These two PermissionManager methods are using AttributionSource as
metadata only, and aren't interested in the remote caller enforcing
that the claimed UID matches the caller, since they're not actually
being used for permission enforcement.

Thus we pass the metadata using the AttributionSourceState holder
object and reconstruct on the remote side, entirely avoiding the
enforceCallingUid() check.

Bug: 193842956
Test: atest CtsPermission5TestCases
Change-Id: I576b6feb8cc2b0586b4341268866d8027689293f
2021-07-27 09:45:54 -06:00
Svet Ganov
1babd5bf51 Optimize AttributionSource tokens - base
For cases where the attribution soruce doesn't need to be
registered as trusted we are now using a shares static
token since the only purpose of the token in these cases
is for watching the source process dying as opposed to that
and security for registered cases.

bug: 192415943

Test: CtsPermissionTestCases
      CtsPermission2TestCases
      CtsPermission3TestCases
      CtsPermission4TestCases
      CtsPermission5TestCases

Change-Id: I93fde9ca1cacada7929761533dcae11b2736ce1e
2021-07-10 00:24:30 +00:00
Nate Myren
4c426c4d03 Create "trusted chain" mechanism for AttributionSource
Add and populate a "trusted" attribution flag, that verifies the
attribution sources used to create it were trusted.

Fixes: 192270935
Test: atest RuntimePermissionsAppOpTrackingTest
Change-Id: Ifd8f825151bec55aa795da7bee0a3069509f5abe
2021-06-30 16:06:59 -07:00
Nate Myren
fd49debdc0 Create Attribution Chains in HistoricalOps
Add a historical flag to signify that attribution chains should be
assembled. Assemble the chains, filter out middle nodes, and attach the
last visible node to the start as a proxy info

Bug: 158792096
Test: manual
Change-Id: I8fbd8f438c62b28fd90039440e86224c624dea79
2021-06-23 12:12:15 -07:00
Nate Myren
5cd62ee5f7 Support AttributionSource chains in PermissionUsageHelper
Test: manual
Bug: 184963112
Change-Id: Idca4ccdaab1f243b754ef15888ea679788bfdd9b
2021-06-04 12:55:50 -07:00
Svet Ganov
2eebf92965 Switch media fw permissions checks to AttributionSource
Attribution source is the abstraction to capture the data
flows for private data across apps. Checking permissions
for an attribution source does this for all apps in the
chain that would receive the data as well as the relevant
app ops are checked/noted/started as needed.

Teach speech recognition service about attribution
chains. If an implementation does nothing the OS
would enforce permisisons and do blame as always.
This apporach leads to double blaming and doesn't
support attribition chains where app calls into
the default recognizer which calls into the on
device recognizer (this nests recursively). If the
implementer takes advantage of the attribution chain
mechanims the permissions for the entire chain are
checked at mic access time and all apps are blamed
only once.

Fixed a few bugs around finishing ops for attribution
chains. Also ensured that any app death in a started
attribution chain would lead to finishing the op for
this app

bug: 158792096

Test: (added tests for speech reco)
      atest CtsMediaTestCases
      atest CtsPermissionTestCases
      atest CtsPermission2TestCases
      atest CtsPermission3TestCases
      atest CtsPermission4TestCases
      atest CtsPermission5TestCases
      atest CtsAppOpsTestCases
      atest CtsAppOps2TestCases

Merged-In: Ic92c7adc14bd2d135ac13b96f17a1b393dd562e4

Change-Id: Ic92c7adc14bd2d135ac13b96f17a1b393dd562e4
2021-06-01 23:43:29 +00:00
TreeHugger Robot
78896f98c0 Merge "Add missing permission enforcement." into sc-dev 2021-06-01 21:50:44 +00:00
Hai Zhang
a4015ce67a Add missing permission enforcement.
Since, we are opening PermissionControllerService to instant apps for
the permission group mapping API, I'm reviewing the permission checks
and this is the only missing one. However, this API is just a trigger
to update our state so calling it some more times shouldn't pose a
security risk, so this fix is just a nice-to-have.

Bug: 189836392
Test: presubmit
Change-Id: I6e9159ce090acaad2ecf522bd04c613169e03252
2021-06-01 12:45:00 -07:00
Hai Zhang
032d5f1fd5 Fix wrong permission check in
setRuntimePermissionGrantStateByDeviceAdminFromParams().

This is nice to have, but not necessarily a security fix because we are
already always enforcing ADJUST_RUNTIME_PERMISSIONS_POLICY.

Bug: 158735247
Test: presubmit
Change-Id: I629969e04e1d5e7e3ef47c8833780f19d83b9e0b
2021-06-01 18:55:01 +00:00
Hai Zhang
8bda34c493 Expose platform permission group mapping as public API.
The API is moved from PermissionControllerManager (only a System API)
to PackageManager to expose it as public API.

Bug: 182094776
Test: atest GetPermissionGroupInfoTest
Change-Id: I175afb2e37bf2651b91765029645f7940f58f39c
2021-05-21 03:03:56 +00:00