Binder.getCallingUidOrThrow throws if the caller is NOT:
1) Called from within a binder transaction OR
2) Called from within a
Binder.clearCallingIdentity/restoreCallingIdentity block
Number 2 was added in I162db933f9e52cd6f9f46796bda11ad6216d3d66
to allow us to migrate from Binder.getCallingUid to it. There are
many use cases where callers are not in a Binder transaction, but
have set the calling UID "explicitly" by calling clearCallingIdentity.
In order to further ease the migration from Binder.getCallingUid to
Binder.getCallingUidOrThrow, this hidden API behaves similarly,
but logs at WTF level instead of throwing IllegalStateException.
The motivation is to first migrate to the WTF version, so that
system_server will log and continue. The goal is to only use this
in the system (hence @hide). It will provide early signals as to the
feasibility of a given migration.
For example, its desirable to migrate the permission checking in code
generated by the @EnforcePermission annotation (via the AIDL compiler).
This call site is widely used, and itself subject to mass migrations to
@EnforcePermission instead of manual permission enforcement.
Bug: 252975769
Test: TH
Change-Id: I11ea3fdf889689d76211506e81420e694238ee68
This CL improves the documentation and semantic behaviour of asyncTraceForTrackBegin
to match how these methods were expected to be used. [1] misuses
the event as previously written because it provides overlapping
events with the same cookie: however, it also nests the events and due
to how Perfetto UI/trace_processor are implemented, this just ends up
*happening* to work out.
I will send some follow up CLs cleaning up usages in the broadcast code
where we should nest events instead of overlapping them.
Bug: 259535570
Change-Id: Idcf10bed7ed1228b0ba9aa62ef3f47169030cc6a
This is initially thought of in
go/vibration-effects-for-notifications-dd, and can be used whenever a
vibration pattern is needed to be extracted from a VibrationEffect. See
also: go/vibration-changes-for-notification-channels
Bug: 241732519
Test: unit tests
Change-Id: Ieccbe95d40e638dec23014cc18ba11c0b5754fd8
This adds a system API to retrieve the user that was last in the
foreground, apart from the current user.
This may be used for example when the current user is removed,
to switch to the previous current user.
Bug: 259373662
Test: atest UserManagerHostTest
Change-Id: Ie21fe2f47a90633d2e2a9cb36f03d7d1bca1f9d5
This adds a system API to get the designated main user on the device.
The documentation for the existing isMainUser API is updated to make
clear that a main user might not exist on the device, particular for
non-phone/tablet form factors, but there will always be at most one
main user.
The CTS tests for isMainUser are updated to reflect that documentation,
and to no longer enforce that the main user is the first user on the
device
Bug: 259476886
Bug: 256624031
Test: atest UserManagerTest
Change-Id: Id1739b188d7c1c0f9006bc473de35a88d09cad95
These APIs are "similar" to AM.getCurrentUser() which is also
@SystemApi. Besides, regular apps shouldn't care about users.
Test: m update-api
Test: atest CtsMultiUserTestCases:android.multiuser.cts.UserManagerTest MultipleUsersOnMultipleDisplaysTest
Fixes: 259423113
Change-Id: I71a5bcefdb719cee632936faf8bdf87386356452
The new method hasExplicitIdentity will track whether the caller is
within a Binder.clearCallingIdentity/restoreCallingIdentity block based
on packing this state information into the token returned by clearCallingIdentity.
Bug: b/252975769
Test: android.os.cts.BinderTest
Change-Id: I162db933f9e52cd6f9f46796bda11ad6216d3d66
This reverts commit ee13e8d435.
Reason for revert: As discussed in b/233915142, an API that can obtain an arbitrary binder should not be exposed, and mainline modules should generally follow go/android-api-guidelines#the-moduleservicemanager-pattern.
Bug: 233915142
Test: Presubmit
Change-Id: I67e6e177d48ed213306aa0c10f83fe3b670daf1d
With ag/19901205 the permissions for this API were increased,
and calling users required 'MANAGE_EXTERNAL_STORAGE' permissions.
There is now a way to add the same functionality without
adding any additional permissions.
Bug: 235321217
Test: atest android.appsecurity.cts.StorageHostTest
Change-Id: I6b166ac191a80c600b527266f53107b8d9c78177
This is to replace ServiceManager, which the ART module is currently
using to get the "artd" service.
Only the ART mainline module will be able to access an instance of this
class.
Bug: 233915142
Test: Presubmit
Change-Id: I94953bc7fbf471e142b1ab375fe1624bebd2a4ea
This adds an API to determine if the context user is the designated
main user on the device. This user may have access to features which
are limited to a single user on the device.
In Android U, this will be the first user to go through setup.
On regular devices, this will be the system user, but on devices in
No Primary User / Headless System User Mode, it will be a different
user.
The isPrimaryUser System API is confusing because it actually always
returns the system user, even in headless mode. That API is deprecated
in this change.
On devices that are upgrading, if they are non-headless, the system user
will be the main user. If they are headless, the full user with the
earliest creation date will be given the flag.
Bug: 256624031
Test: atest UserManagerTest
Change-Id: Ib36f3b372f9bf33cbb097c4af63eb43515ac835b
artificially limited.
We may limit charging when battery is overheating, or due to dock defend
or other battery defend mechanisms. In these cases, the battery is
expected to drain while dreaming since charging is limited. Therefore,
do not exit dreams in this case.
Test: atest PowerManagerServiceTest
Fixes: 258027228
Change-Id: I10ce0c848892b42267d819d07a284d17a97899d1