`processes` is initialized as an empty map, so we're currently always
hitting the loop case. We should avoid it.
Bug: 213021110
Test: atest PackageManagerPerfTest#testGetApplicationInfoWithFiltering
Test: atest CtsProcessTest
Test: atest PackageManagerServiceUnitTests
Change-Id: I49fa8adb0cf10e405b2251e7de78caea1bbd8fa1
Manually migrate the few cases of:
* readArray()
* readParcelableArray()
To the new parcel APIs that take the expected type as the last
parameter. This enhances security because it prevents unexpected types
*before* running unparcelling code. More details at go/safer-parcel.
Owners, please check that the type of the objects expected is always a
subtype of the type provided as the 3rd parameter. This is usually easy
to verify due to casts that happen shortly after.
These changes often allowed further transformations but I decided to
avoid them to keep this change small and targeted.
This was manual since it's tricky to get lint to infer the type in
those cases and it was only a few.
Bug: 195622897
Test: TH passes
Change-Id: I262ed7cd6d3bc15b32e9296e88a8a67fdb59e880
App can set a android.internal.PROPERTY_NO_APP_DATA_STORAGE property in it's
AndroidManifest.xml which will tell platform to avoid creating data
directories for it.
This property is intentionally not exposed as public API because not
having private app storage is a very niche requirement.
This change also logic to prevent app updates from changing value of the
property, i.e.: if an installed app doesn't specify value of the
PROPERTY_NO_APP_DATA_STORAGE property (or has it set to false), then any
update to this app shouldn't have this property specified (or explicitly
set it to false). If an app has PROPERTY_NO_APP_DATA_STORAGE set to
true, then all updates should keep that property set to true.
Note: this change only takes into account internal storage. Removing
app's external storage will be done in the follow up cl.
Bug: 211761016
Test: atest PackageManagerShellTest
Change-Id: I3e541d947a77f5c050bf706f64009f21c24dcbc9
The dialog is shown if the app is not a signature app, the system is
ready, and the app has created at least one notification channel.
Also applies the SHOULD_SHOW_REQUEST flag to all packages with implicit
POST_NOTIFICATIONS permissions
Bug: 194833441
Test: atest NotificationPermissionTest
Change-Id: I4cb8cc7bcc3635f55e291f176f722dd420a4a1bb
Bug: 152453213
Tag: #refactor
This commit prepares PropertyInvalidatedCache to function as a system
api. Specifically, the methods recompute() and bypass() which may be
overridden by clients are now public (instead of protected). This
forces an update to all existing clients, to accommodate the change in
method visibility.
Two small changes have been made as cleanup:
1. The awkwardly named debugCompareQueryResults() is now
resultEquals(), which is more or less consistent with how other
equality tests are named in Android. This name change affects two
clients.
2. PackageManager has changed to use resultEquals() instead of
maybeCheckConsistency(). This provides a simpler and more
consistent use of the APIs. maybeCheckConsistency() has been made
private.
Test: atest PropertyInvalidatedCacheTests
Change-Id: I4110f8e887a4fd8c784141e8892557a9d1b80a94
Similar to bindService(), even if bindServiceAsUser() returns false,
unbindService() must still be called to allow the service to shut down.
The documentation is updated to reflect this.
Bug: 212663289
Test: m ds-docs-java
Change-Id: I780d307f4a0ebf8bef508932181e580f168b5578
In order to registerContentObserver as other user, callers need to hold
the INTERACT_ACROSS_USERS_FULL permission.
Bug: 206743591
Test: CtsContentTestCases
Change-Id: I2f373a3f064718cc87bdda35a5854b6a6fd2e7aa
Declaring duplicate permissions with different protection levels is
not allowed. Add the scheme enforcement for manifest during parsing.
Bug: 211934395
Test: atest AppSecurityTests
Change-Id: Ieb006ab4abf19baf949e9b5bfd3e3fea16237527
Android T allows apps to declare a runtime receiver as not exported
by invoking registerReceiver with a new RECEIVER_NOT_EXPORTED flag;
receivers registered with this flag will only receive broadcasts from
the platform and the app itself. However to ensure developers can
properly protect their receivers, all apps targeting T or later
registering a receiver for non-system broadcasts must specify either
the exported or not exported flag when invoking #registerReceiver;
if one of these flags is not provided, the platform will throw a
SecurityException. The platform and system apps have several locations
where a receiver is registered for non-system broadcasts that have
not yet been audited to determine if they should be exported. This
commit introduces a temporary flag that can be used to meet the
new requirement that a flag be specified while also marking the
receiver as needing an audit before the T release to determine
whether the receiver should be exported or not.
Bug: 161145287
Test: atest ContextTest
Change-Id: Ie9d1e2ad6e2d831c374437ed65d085711b7dc3b7
Unless we are looking at stack traces (e.g. from strict mode) it's not
possible to identify which type of object is not being closed (most
methods are 'close' or 'release). Change the logged text to clarify.
Change-Id: Ib90eac716f43c2c2caf8d8c6fb64a7bd90562da9
Test: manual
This is a preliminary change to apply READY/FAILED/APPLIED to
non-staged sessions.
* Move mSession* fields to PackageInstallerSession as they
will be useful to both staged and non-staged sessions.
* Rename some members as they will be applicable to both staged
and non-staged sessions.
Bug: 210359798
Test: atest StagingManagerTest \
PackageInstallerSessionTest \
CtsStagedInstallHostTestCases
Change-Id: Ie1b09aa4c7cbc843712c731a1b903d26684b2e30
Whenever a package's app ID has changed, the system broadcasts should
behave as if the package is fully uninstalled and then re-installed
subsequently. Additional extras are added to indicate the app ID change
to allow components to handle this case specifically.
Test: atest SharedUserMigrationTest#testDataMigration
Bug: 179284822
Change-Id: Ie00eaed1f0a704876ea76aa0e5ae2a1b21f199df
The initial selection toolbar related architecture. Render service
part and the implementation will be revised in the follow up changes.
Bug: 190030331
Bug: 205822301
Test: manual. Can boot to home and get manager successfully.
Ignore-AOSP-First: new file for T
Change-Id: Iab5d5f2e5e48e6258a63fb0c479194c958ea61e8