If an app requests READ_MEDIA_VIDEO/IMAGES, we should add
READ_MEDIA_VISUAL_USER_SELECTED automatically.
Also updates documentation
Bug: 256921561
Bug: 251783841
Test: atest PhotoPickerPermissionTest
Change-Id: I2ddb2caeeacd8c1d65b7892ea7fc22c024f69325
group name was changed during review but not updated
in the permission mapping.
Bug: 232283779
Test: manual
Change-Id: Ib7df61fa4fd49c8419f0543fd6c54186a33ebeb6
Map WRITE_SECURITY_LOG to AID_SECURITY_LOG_WRITE which is how logd
controls access to security log buffer.
Bug: 232283779
Test: manual
Change-Id: Ifde2e5192326f0811807dcb05563b1b5b63077ce
Add a permission split:
WRITE_EXTERNAL_STORAGE to ACCESS_MEDIA_LOCATION
...and sort split permissions.
The reason adding this is that the split-permission handling code
doesn't handle recursive split-permission mappings, but only direct
mappings.
The reason for sorting is that, given a tree of permission splits,
the entries in platform.xml must be sorted topologically, due to
current permission split code.
Bug: 227240947
Test: atest CtsPermissionTestCases CtsPermission3TestCases SplitPermissionsSystemTest
Change-Id: I62c2ab8687af2e8325fcc370a74af0f589d8e9f2
Add split permissions from WRITE_EXTERNAL_STORAGE to media permissions.
The reason for doing this is that the split-permission handling code
doesn't handle recursive split-permission mappings, but only direct
mappings.
This resulted in a problem with WRITE_EXTERNAL_STORAGE because:
1) WRITE_EXTERNAL_STORAGE splits into READ_EXTERNAL_STORAGE, and
2) Recently, we added split permissions from READ_EXTERNAL_STORAGE
to READ_MEDIA_AUDIO, READ_MEDIA_IMAGES, READ_MEDIA_VIDEO, and
ACCESS_MEDIA_LOCATION
The effect is that apps which request WRITE_EXTERNAL_STORAGE are not
being granted media storage permissions properly.
(Note that, for now, we've not yet added the split to
ACCESS_MEDIA_LOCATION, because this scenario has not yet been
thoroughly tested.)
Bug: 222238273
Test: atest CtsPermissionTestCases CtsPermission3TestCases SplitPermissionsSystemTest
Change-Id: I94694b37189ea8ad89edc4f478391ccfe1ccd5b8
This permission was only created very recently, and it is unlikely that
any apps are using it yet.
After its creation, it was decided that it should be renamed.
Bug: 223691971
Test: atest CtsPermissionTestCases CtsPermission3TestCases
Change-Id: I9c171161e2c60d38c14e167ea7b7b87bf1235e1b
Define three permission splits:
- READ_EXTERNAL_STORAGE to READ_MEDIA_AUDIO (targetSdk<T)
- READ_EXTERNAL_STORAGE to READ_MEDIA_VIDEO (targetSdk<T)
- READ_EXTERNAL_STORAGE to READ_MEDIA_IMAGE (targetSdk<T)
This results in the following behavior: any time any legacy application
(i.e., targetSdk<TIRAMISU) is granted READ_EXTERNAL_STORAGE, it will
also automatically be granted READ_MEDIA_AUDIO, READ_MEDIA_VIDEO, and
READ_MEDIA_IMAGE.
The motivation for this change is to support the "Media Permission
Update for Android T" project.
Bug: 201318587
Test: atest CtsPermissionTestCases CtsPermission3TestCases
Change-Id: I79171cbda6a3d6d1d4bb87994c8b02f7174ea4db
Revert "Fix PermissionPolicyTest and SplitPermissionsSystemTest"
Revert submission 15933906-t-define-media-permissions
Reason for revert: caused b/216588046 and b/216453842
Reverted Changes:
I79afe120d:Update DefaultPermissionGrantPolicyTest for new pe...
I321282b1f:Fix PermissionPolicyTest and SplitPermissionsSyste...
If3d357bae:Define new AUDIO/VIDEO/IMAGE permissions
Change-Id: I0d4f0eaefc5c29063f517755b4c9b61417a15fd0
Define three new permissions:
- READ_MEDIA_AUDIO: read audio files from external storage
- READ_MEDIA_VIDEO: read video files from external storage
- READ_MEDIA_IMAGE: read image files from external storage
Also, define two new permission groups:
- READ_MEDIA_AURAL
- READ_MEDIA_VISUAL
The permissions are assigned to permission groups as follows:
READ_MEDIA_AURAL {
READ_MEDIA_AUDIO
}
READ_MEDIA_VISUAL {
READ_MEDIA_VIDEO
READ_MEDIA_IMAGE
}
The motivation for this change is to support the "Media Permission
Update for Android T" project.
Bug: 201318587
Test: manual
Change-Id: If3d357baed15b66319a6c2308416622e5e57fe28
Currently only states supported for body sensor permissions are allow
and deny. This change adds support for allowing the permission only
while the app is in foreground by adding a new permission only for
background. This structure is similar to the current state for location
permissions.
BYPASS_INCLUSIVE_LANGUAGE_REASON=Referring to an existing method failing
the inclusive language check.
Test: Manual atest
Change-Id: I8fcab6c0c884b79291586f64fd221e40982bc4c5
Bug: 208305481
Certain top activities will not trigger the "onTaskMovedToFront"
callback which can result in incorrect resizeability
queries. This can happen when a new activity is launched in the top
task.
To avoid this, retrieve the necessary information via the reported
recent tasks by activity manager for a given user id.
Bug: 203044281
Test: Manual using camera application
Change-Id: I61efd4282a2231e6354e5514fc25d7d27005335b
ImsServiceEntitlement is a headless app for certain carriers requiring
background IMS provisioning only. So the app needs to be allowed to
schedule jobs.
Bug: 189397221
Test: make
Change-Id: Ib910681ef81a417aaa4a13514260cfa26098a048
No longer grant READ_PHONE_STATE as a fixed permission to all apps
holding READ_PRIVILEGED_PHONE_STATE. Also clean up the previous grants
by un-fixing the permission if the app requests it in the manifest, and
removing it altogether if the app only requests READ_PRIV.
Bug: 183537857
Test: manual -- prepare two system apps, one with READ_PRIV and
READ_PHONE and one with only READ_PRIV, then go through the upgrade flow
with this CL.
Change-Id: Id1fac0f9f4391857f46c7109eadafd60420b279d
This allows it to schedule alarms while the device is in doze without
needing SCHEDULE_EXACT_ALARM permission, which is user visible.
Test: adb logcat -s AndroidRuntime
should show no crashes for "com.android.providers.calendar" due to
missing SCHEDULE_EXACT_ALARM.
Bug: 171306433
Change-Id: I3dc358f0de0f6d869c3c6e7d6c2c243dc2348096
This change is part of defining a distinct BLUETOOTH_ADVERTISE
permission to guard the BluetoothLeAdvertiser APIs, since that's a
distinct enough of an operation from SCAN and CONNECT. It'll
continue to be covered under the general "Nearby devices" runtime
permission group.
Bug: 181813006
Test: atest CtsPermission2TestCases
Test: atest CtsPermission3TestCases
Change-Id: I8b62e4d625df1e201f12a73025cd29c431feea79
This creates a "split permission" from:
- BLUETOOTH to BLUETOOTH_SCAN and BLUETOOTH_CONNECT, and
- BLUETOOTH_ADMIN to BLUETOOTH_SCAN and BLUETOOTH_CONNECT
...for apps targetting SDK<31.
What this means is that any apps that use either the BLUETOOTH or the
BLUETOOTH_ADMIN permission, and target SDK<31, will automatically be
be granted the BLUETOOTH_SCAN and BLUETOOTH_CONNECT permissions.
Bug: 181813006
Test: manual
Change-Id: I92a974203fd51e87747e740273a21ba399a81cd0
In Android R, we introduced a platform.xml based
mapping. Unfortunately, it only worked for signature|preinstalled
apps.
To support apps granted the appop (via special app access
permissions), we now check the permission and appop grant state
explicitly and grant the app the external_storage gid appropriately
Test: Manual
Bug: 165515144
Change-Id: Ib91e1b3a7e54ac2c83fb1d94446bed06fd44bcf6
Added interact accross user permission to media uid so that it can query
packages for UID in cases where media service is running for user 0 and
applications runs for different user id (i.e. 10) as is the case in car.
Bug: 181574201
Test: build seahawk (car target)
Test: run media recorder application with RECORD_AUDIO permission
Test: run media recorder application without RECORD_AUDIO permission
Change-Id: I5052c92831978a7e6c8277d3c5a4e6cb5ed8a78b
- gcar_emu_x86_64 starts to crash after commit 1dafc38 is merged.
Bug: 179455284
Test: Build gcar_emu_x86_64 and check if it boots successfully.
Change-Id: I59dad57c846e3a83d71abb58fdd5e57019d99e75
Apps can't request this permission anyways so some apps started
misbehaving when forcing users to grant all permissions without caring
what they are.
Test: Boot
Fixes: 172844303
Bug: 158311343
Change-Id: Ia83ad5433ff3cdae57d901b3a9d781725124c6b9
This dependency is fictitious: hidl manager actually contains a static
copy of hidl base for convenience. Separate libraries were created
later (e.g. android.hidl.manager-java-shallow) in order for users of
these libraries to specify the exact deps they need.
Fixes: 170710203
Test: boot and check logs
:) adb logcat | grep android.hidl.manager-V1.0-java.jar
10-21 00:42:53.173 328 328 D ApplicationLoaders: Created zygote-cached class loader: /system/framework/android.hidl.manager-V1.0-java.jar
10-21 00:43:17.322 329 329 D ApplicationLoaders: Created zygote-cached class loader: /system/framework/android.hidl.manager-V1.0-java.jar
10-21 00:43:31.920 2250 2250 D ApplicationLoaders: Returning zygote-cached class loader: /system/framework/android.hidl.manager-V1.0-java.jar
10-21 00:43:38.884 2847 2847 D ApplicationLoaders: Returning zygote-cached class loader: /system/framework/android.hidl.manager-V1.0-java.jar
10-21 00:43:41.010 2923 2923 D ApplicationLoaders: Returning zygote-cached class loader: /system/framework/android.hidl.manager-V1.0-java.jar
10-21 00:43:42.146 3044 3044 D ApplicationLoaders: Returning zygote-cached class loader: /system/framework/android.hidl.manager-V1.0-java.jar
Change-Id: I024a1b16570bdceb7bef5b2e718c65155c675b4a
There should be no such dependency.
Test: lunch aosp_cf_x86_phone-userdebug && m
Bug: 169137403
Bug: 132357300
Change-Id: Iaa7414be66581c01c6acbf367dc165cd8af78615
Revert "Add dedicated host side tests for permissions and appops"
Revert submission 12439864-PermAppOpsCrossUserCheck-Fixed
Reason for revert: Bug 169044600
Reverted Changes:
I95d015e01:Invalidate package/permission cache if cross-profi...
I2a8a84f57:Check cross-user interactions for permissions and ...
Ie8f0db231:Give all non-package services the power to interac...
I11af434a8:Test package/permission cache invalidation when IN...
Ib6d609a4d:Add dedicated host side tests for permissions and ...
Change-Id: I47d371832c119fe4ce4890e10c1ac87aba92acbc
The two SysConfig xml tags
system-user-whitelisted-app
system-user-blacklisted-app
are deprecated and were never used.
Bug: 139547572
Bug: 137101239
Test: compiles
Change-Id: I0a5a8cb9b178a3742ddc1fe70b9ee1e2737abdba
As part of mainline effort, cellbroadcastreceiver package name has been
renamed. Now its a completely new apk with different uid. That said all
user data e.g, cellbroadcast history and user preference from legacy app
com.android.cellbroadcastreceiver are gone. This change is to support
preserve user data when devices upgrate to R and take cellbraodcast.
mainline module.
1. create legacy cellbroadcast app with old pakcage name
com.android.cellbroadcastreceiver. this app only surface the old data
and should not contains any activities/services to handle emergecy apert
2. legacy cellbroadcast app will be included to the system image by
default. OEMs are free to remove it if they don't care data loss or
after R data migration is done. leagcy app will not be part of
com.android.cellbroadcast apex.
3. the real mainline module rename to com.android.cellbroadcast.module
Bug: 155844209
Change-Id: I5e61c7e777526e038cd8d9971a2c5b87c00eaacb
Merged-in: I5e61c7e777526e038cd8d9971a2c5b87c00eaacb
As part of mainline effort, cellbroadcastreceiver package name has been
renamed. Now its a completely new apk with different uid. That said all
user data e.g, cellbroadcast history and user preference from legacy app
com.android.cellbroadcastreceiver are gone. This change is to support
preserve user data when devices upgrate to R and take cellbraodcast.
mainline module.
1. create legacy cellbroadcast app with old pakcage name
com.android.cellbroadcastreceiver. this app only surface the old data
and should not contains any activities/services to handle emergecy apert
2. legacy cellbroadcast app will be included to the system image by
default. OEMs are free to remove it if they don't care data loss or
after R data migration is done. leagcy app will not be part of
com.android.cellbroadcast apex.
3. the real mainline module rename to com.android.cellbroadcast.module
Bug: 155844209
Change-Id: I5e61c7e777526e038cd8d9971a2c5b87c00eaacb
Convert ACTION_SERVICE_STATE_CHANGED and
ACTION_ANY_DATA_CONNECTION_CHANGED to be non-sticky broadcasts that
require the READ_PHONE_STATE permission to receive. As part of this,
declare READ_PHONE_STATE to be split from READ_PRIVILEGED_PHONE_STATE,
so that system apps holding READ_PRIVILEGED_PHONE_STATE can also receive
these broadcasts.
Also modify affected users to fetch the current value of the broadcast
upon registration instead of relying on the sticky nature of the
broadcast.
Bug: 150155839
Test: manual
Test: atest KeyguardUpdateMonitorTest
Change-Id: I020b1554c4fc59c138d015e787526b4a66c74853
Allow media service to register UidObserver to get uid
state changes. Media transcoding uses uid states for
transcoding job scheduling purposes.
bug: 154734285
bug: 145233472
Change-Id: I20c7b33798ff5ede6620cccf65143da5ad77cba5