Commit Graph

185 Commits

Author SHA1 Message Date
Nate Myren
5660b698eb Add READ_MEDIA_VISUAL_USER_SELECTED to apps automatically
If an app requests READ_MEDIA_VIDEO/IMAGES, we should add
READ_MEDIA_VISUAL_USER_SELECTED automatically.

Also updates documentation

Bug: 256921561
Bug: 251783841
Test: atest PhotoPickerPermissionTest
Change-Id: I2ddb2caeeacd8c1d65b7892ea7fc22c024f69325
2022-11-08 15:52:05 -08:00
Kunal Malhotra
c69aa1be70 Restrict readability of uid state changes so that uid states of other users uids are not exposed to those that do not have permission.
Test: manual test
Bug: 217934898
Change-Id: I3f52d4ca32c22c54fa9b1663954a43b44d9000a0
2022-07-29 22:20:20 +00:00
Treehugger Robot
63283e7450 Merge "Update security_log_writer group name" am: 5a66f41fa4 am: 5327a51e5a
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/2108084

Change-Id: I06beb1a61be0620176466061cf86b3a7b37e8a51
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-26 16:07:57 +00:00
Rubin Xu
4486314be6 Update security_log_writer group name
group name was changed during review but not updated
in the permission mapping.

Bug: 232283779
Test: manual
Change-Id: Ib7df61fa4fd49c8419f0543fd6c54186a33ebeb6
2022-05-26 12:44:55 +01:00
Rubin Xu
c8c601c335 Merge "Map WRITE_SECURITY_LOG permission to gid" am: 2b2b455884 am: 356f81b957
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/2105065

Change-Id: Ic70701d437bc15b73b8ff85004c0329059499d64
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-25 12:20:46 +00:00
Rubin Xu
2b2b455884 Merge "Map WRITE_SECURITY_LOG permission to gid" 2022-05-25 11:43:50 +00:00
Rubin Xu
e806776e54 Map WRITE_SECURITY_LOG permission to gid
Map WRITE_SECURITY_LOG to AID_SECURITY_LOG_WRITE which is how logd
controls access to security log buffer.

Bug: 232283779
Test: manual
Change-Id: Ifde2e5192326f0811807dcb05563b1b5b63077ce
2022-05-24 23:27:10 +01:00
Jay Thomas Sullivan
5b9f6a592c Add perm split W_E_S to A_M_L and sort
Add a permission split:

    WRITE_EXTERNAL_STORAGE to ACCESS_MEDIA_LOCATION

...and sort split permissions.

The reason adding this is that the split-permission handling code
doesn't handle recursive split-permission mappings, but only direct
mappings.

The reason for sorting is that, given a tree of permission splits,
the entries in platform.xml must be sorted topologically, due to
current permission split code.

Bug: 227240947
Test: atest CtsPermissionTestCases CtsPermission3TestCases SplitPermissionsSystemTest
Change-Id: I62c2ab8687af2e8325fcc370a74af0f589d8e9f2
2022-03-29 17:46:18 -07:00
Jay Thomas Sullivan
9b78af4292 Add split perms from W_E_S to media
Add split permissions from WRITE_EXTERNAL_STORAGE to media permissions.

The reason for doing this is that the split-permission handling code
doesn't handle recursive split-permission mappings, but only direct
mappings.

This resulted in a problem with WRITE_EXTERNAL_STORAGE because:

1) WRITE_EXTERNAL_STORAGE splits into READ_EXTERNAL_STORAGE, and
2) Recently, we added split permissions from READ_EXTERNAL_STORAGE
to READ_MEDIA_AUDIO, READ_MEDIA_IMAGES, READ_MEDIA_VIDEO, and
ACCESS_MEDIA_LOCATION

The effect is that apps which request WRITE_EXTERNAL_STORAGE are not
being granted media storage permissions properly.

(Note that, for now, we've not yet added the split to
ACCESS_MEDIA_LOCATION, because this scenario has not yet been
thoroughly tested.)

Bug: 222238273
Test: atest CtsPermissionTestCases CtsPermission3TestCases SplitPermissionsSystemTest
Change-Id: I94694b37189ea8ad89edc4f478391ccfe1ccd5b8
2022-03-28 19:51:38 +00:00
Jay Thomas Sullivan
90f8bc6f9d Rename READ_MEDIA_IMAGE to READ_MEDIA_IMAGES
This permission was only created very recently, and it is unlikely that
any apps are using it yet.

After its creation, it was decided that it should be renamed.

Bug: 223691971
Test: atest CtsPermissionTestCases CtsPermission3TestCases
Change-Id: I9c171161e2c60d38c14e167ea7b7b87bf1235e1b
2022-03-09 23:38:06 -08:00
Jay Thomas Sullivan
7fd9adf992 Define splits for AUDIO/VIDEO/IMAGE permissions
Define three permission splits:

- READ_EXTERNAL_STORAGE to READ_MEDIA_AUDIO (targetSdk<T)
- READ_EXTERNAL_STORAGE to READ_MEDIA_VIDEO (targetSdk<T)
- READ_EXTERNAL_STORAGE to READ_MEDIA_IMAGE (targetSdk<T)

This results in the following behavior: any time any legacy application
(i.e., targetSdk<TIRAMISU) is granted READ_EXTERNAL_STORAGE, it will
also automatically be granted READ_MEDIA_AUDIO, READ_MEDIA_VIDEO, and
READ_MEDIA_IMAGE.

The motivation for this change is to support the "Media Permission
Update for Android T" project.

Bug: 201318587
Test: atest CtsPermissionTestCases CtsPermission3TestCases
Change-Id: I79171cbda6a3d6d1d4bb87994c8b02f7174ea4db
2022-02-01 20:24:58 -08:00
Jay Sullivan
ff9f7176ac Revert "Define new AUDIO/VIDEO/IMAGE permissions"
Revert "Fix PermissionPolicyTest and SplitPermissionsSystemTest"

Revert submission 15933906-t-define-media-permissions

Reason for revert: caused b/216588046 and b/216453842
Reverted Changes:
I79afe120d:Update DefaultPermissionGrantPolicyTest for new pe...
I321282b1f:Fix PermissionPolicyTest and SplitPermissionsSyste...
If3d357bae:Define new AUDIO/VIDEO/IMAGE permissions

Change-Id: I0d4f0eaefc5c29063f517755b4c9b61417a15fd0
2022-01-29 03:11:22 +00:00
Jay Thomas Sullivan
811fb71ae2 Define new AUDIO/VIDEO/IMAGE permissions
Define three new permissions:

- READ_MEDIA_AUDIO: read audio files from external storage
- READ_MEDIA_VIDEO: read video files from external storage
- READ_MEDIA_IMAGE: read image files from external storage

Also, define two new permission groups:

- READ_MEDIA_AURAL
- READ_MEDIA_VISUAL

The permissions are assigned to permission groups as follows:

  READ_MEDIA_AURAL {
      READ_MEDIA_AUDIO
  }
  READ_MEDIA_VISUAL {
      READ_MEDIA_VIDEO
      READ_MEDIA_IMAGE
  }

The motivation for this change is to support the "Media Permission
Update for Android T" project.

Bug: 201318587
Test: manual
Change-Id: If3d357baed15b66319a6c2308416622e5e57fe28
2022-01-18 10:44:14 -08:00
Varun Bansal
02853cf179 Merge "Add tristate permission support for body sensor permission" 2021-12-22 17:09:55 +00:00
varun
4379a4cb56 Add tristate permission support for body sensor permission
Currently only states supported for body sensor permissions are allow
and deny. This change adds support for allowing the permission only
while the app is in foreground by adding a new permission only for
background. This structure is similar to the current state for location
permissions.

BYPASS_INCLUSIVE_LANGUAGE_REASON=Referring to an existing method failing
the inclusive language check.

Test: Manual atest
Change-Id: I8fcab6c0c884b79291586f64fd221e40982bc4c5
Bug: 208305481
2021-12-22 05:16:40 +00:00
Emilian Peev
baeaad66d0 CameraServiceProxy: Query recent tasks for top activity data
Certain top activities will not trigger the "onTaskMovedToFront"
callback which can result in incorrect resizeability
queries. This can happen when a new activity is launched in the top
task.
To avoid this, retrieve the necessary information via the reported
recent tasks by activity manager for a given user id.

Bug: 203044281
Test: Manual using camera application

Change-Id: I61efd4282a2231e6354e5514fc25d7d27005335b
2021-12-09 10:16:04 -08:00
Meng Wang
0c1b382ace Merge "Allow ImsServiceEntitlement app to schedule jobs" into sc-dev 2021-06-08 23:50:09 +00:00
samalin
cc01a8a656 Allow ImsServiceEntitlement app to schedule jobs
ImsServiceEntitlement is a headless app for certain carriers requiring
background IMS provisioning only. So the app needs to be allowed to
schedule jobs.

Bug: 189397221
Test: make
Change-Id: Ib910681ef81a417aaa4a13514260cfa26098a048
2021-06-03 16:38:16 +00:00
Suprabh Shukla
a1812e90a3 Add emergency app to power-save allowlist
Test: Manually run:
adb shell dumpsys alarm
Should show 'com.android.emergency' under 'Exempted bucket packages'.

Bug: 189866352
Change-Id: I485dd3e4d9026e576b670a1a4439ea62eec987f3
2021-06-02 14:08:32 -07:00
Treehugger Robot
88d1911f16 Merge "Grant keystore permission to register pull stats" am: 63788ff48a am: e2d58f3789 am: f42a439274
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1683905

Change-Id: I06580e0443e78eb4ea23e7aa0278b14ae9e8da3c
2021-04-22 03:29:20 +00:00
Seth Moore
226b32669c Grant keystore permission to register pull stats
Test: statsd_testdrive 10103
Bug: 172013262
Change-Id: I4d3ad2172b522b79454f5232b6d89c16178593d5
2021-04-21 23:13:43 +00:00
Hall Liu
f4562b5cee Remove fixed grant of READ_PHONE_STATE and cleanup
No longer grant READ_PHONE_STATE as a fixed permission to all apps
holding READ_PRIVILEGED_PHONE_STATE. Also clean up the previous grants
by un-fixing the permission if the app requests it in the manifest, and
removing it altogether if the app only requests READ_PRIV.

Bug: 183537857
Test: manual -- prepare two system apps, one with READ_PRIV and
READ_PHONE and one with only READ_PRIV, then go through the upgrade flow
with this CL.

Change-Id: Id1fac0f9f4391857f46c7109eadafd60420b279d
2021-04-19 15:00:01 -07:00
TreeHugger Robot
c74ea74939 Merge "Upgrading allowlist for calendar provider" into sc-dev 2021-04-12 19:56:32 +00:00
Suprabh Shukla
cd83b1fac7 Upgrading allowlist for calendar provider
This allows it to schedule alarms while the device is in doze without
needing SCHEDULE_EXACT_ALARM permission, which is user visible.

Test: adb logcat -s AndroidRuntime
should show no crashes for "com.android.providers.calendar" due to
missing SCHEDULE_EXACT_ALARM.

Bug: 171306433
Change-Id: I3dc358f0de0f6d869c3c6e7d6c2c243dc2348096
2021-04-09 14:52:46 -07:00
Jeff Sharkey
6dcac06a84 New BLUETOOTH_ADVERTISE manifest permission.
This change is part of defining a distinct BLUETOOTH_ADVERTISE
permission to guard the BluetoothLeAdvertiser APIs, since that's a
distinct enough of an operation from SCAN and CONNECT.  It'll
continue to be covered under the general "Nearby devices" runtime
permission group.

Bug: 181813006
Test: atest CtsPermission2TestCases
Test: atest CtsPermission3TestCases
Change-Id: I8b62e4d625df1e201f12a73025cd29c431feea79
2021-04-08 20:15:02 -06:00
Christine Franks
592b9daa1c Merge "Create VIRTUAL_INPUT_DEVICE signature permission" into sc-dev 2021-03-23 20:25:06 +00:00
Jay Thomas Sullivan
4452bbd065 Split new NEARBY_DEVICES permissions
This creates a "split permission" from:
- BLUETOOTH to BLUETOOTH_SCAN and BLUETOOTH_CONNECT, and
- BLUETOOTH_ADMIN to BLUETOOTH_SCAN and BLUETOOTH_CONNECT
...for apps targetting SDK<31.

What this means is that any apps that use either the BLUETOOTH or the
BLUETOOTH_ADMIN permission, and target SDK<31, will automatically be
be granted the BLUETOOTH_SCAN and BLUETOOTH_CONNECT permissions.

Bug: 181813006
Test: manual
Change-Id: I92a974203fd51e87747e740273a21ba399a81cd0
2021-03-22 13:23:29 -06:00
Christine Franks
3dfad4132e Create VIRTUAL_INPUT_DEVICE signature permission
This is used to convey the AID_UHID supplemental gid

Bug: 182854143
Test: n/a
Change-Id: Iaba2db19100ad0cbc43da09e4ba0102e336a704c
2021-03-22 11:59:54 -07:00
Zimuzo Ezeozue
b3705153db Merge "Fix MANAGE_EXTERNAL_STORAGE permission gid mapping" into sc-dev 2021-03-18 15:02:17 +00:00
Zim
782dc19e95 Fix MANAGE_EXTERNAL_STORAGE permission gid mapping
In Android R, we introduced a platform.xml based
mapping. Unfortunately, it only worked for signature|preinstalled
apps.

To support apps granted the appop (via special app access
permissions), we now check the permission and appop grant state
explicitly and grant the app the external_storage gid appropriately

Test: Manual
Bug: 165515144

Change-Id: Ib91e1b3a7e54ac2c83fb1d94446bed06fd44bcf6
2021-03-17 19:42:18 +00:00
Oscar Azucena
4537327187 Added interact accross user permission to media uid
Added interact accross user permission to media uid so that it can query
packages for UID in cases where media service is running for user 0 and
applications runs for different user id (i.e. 10) as is the case in car.

Bug: 181574201
Test: build seahawk (car target)
Test: run media recorder application with RECORD_AUDIO permission
Test: run media recorder application without RECORD_AUDIO permission
Change-Id: I5052c92831978a7e6c8277d3c5a4e6cb5ed8a78b
2021-03-12 10:50:54 -08:00
Robert Shih
7562087ee0 Give uid media REGISTER_STATS_PULL_ATOM permission
Bug: 141714243
Bug: 159337195
Test: statsd_testdrive 10099
Change-Id: I08d4f4aef3dcd7c94e9a120b0d4fa1d1e267a2b0
2021-03-12 16:58:23 +00:00
Evan Severson
e47b4eafe3 Give camera/audio the OBSERVE_SENSOR_PRIAVY permisison
This permission is needed to check if they should mute the feed.

Test: Manual
Fixes: 181724488
Change-Id: I5ffa01b29b4deff72238688e06e0f0dd9a2b351f
2021-03-02 19:45:07 -08:00
Yuncheol Heo
5f3f9ce6eb Give INTERACT_ACROSS_USERS permission to audioserver
- gcar_emu_x86_64 starts to crash after commit 1dafc38 is merged.

Bug: 179455284
Test: Build gcar_emu_x86_64 and check if it boots successfully.
Change-Id: I59dad57c846e3a83d71abb58fdd5e57019d99e75
2021-02-05 23:34:26 +00:00
Evan Severson
7ce41c1082 Remove mic/camera permission split
Apps can't request this permission anyways so some apps started
misbehaving when forcing users to grant all permissions without caring
what they are.

Test: Boot
Fixes: 172844303
Bug: 158311343
Change-Id: Ia83ad5433ff3cdae57d901b3a9d781725124c6b9
2021-02-01 18:11:04 -08:00
Steven Moreland
1d09a22ec4 Merge "Remove declaration of hidl manager -> base dep" am: 4ff4b2ee17 am: 742771fdd7 am: e798d05a73 am: d53ccbc7bf
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1467918

Change-Id: If382fe51b02209c72089b7c0965f63c52fe1614f
2020-10-22 06:11:13 +00:00
Steven Moreland
fb52599e8a Remove declaration of hidl manager -> base dep
This dependency is fictitious: hidl manager actually contains a static
copy of hidl base for convenience. Separate libraries were created
later (e.g. android.hidl.manager-java-shallow) in order for users of
these libraries to specify the exact deps they need.

Fixes: 170710203
Test: boot and check logs

:) adb logcat | grep android.hidl.manager-V1.0-java.jar
10-21 00:42:53.173   328   328 D ApplicationLoaders: Created zygote-cached class loader: /system/framework/android.hidl.manager-V1.0-java.jar
10-21 00:43:17.322   329   329 D ApplicationLoaders: Created zygote-cached class loader: /system/framework/android.hidl.manager-V1.0-java.jar
10-21 00:43:31.920  2250  2250 D ApplicationLoaders: Returning zygote-cached class loader: /system/framework/android.hidl.manager-V1.0-java.jar
10-21 00:43:38.884  2847  2847 D ApplicationLoaders: Returning zygote-cached class loader: /system/framework/android.hidl.manager-V1.0-java.jar
10-21 00:43:41.010  2923  2923 D ApplicationLoaders: Returning zygote-cached class loader: /system/framework/android.hidl.manager-V1.0-java.jar
10-21 00:43:42.146  3044  3044 D ApplicationLoaders: Returning zygote-cached class loader: /system/framework/android.hidl.manager-V1.0-java.jar

Change-Id: I024a1b16570bdceb7bef5b2e718c65155c675b4a
2020-10-21 00:52:13 +00:00
TreeHugger Robot
dfd56946f8 Merge "Guard IResourceObserver::registerObserver with permission" 2020-09-30 18:43:45 +00:00
Chong Zhang
95ad2ceac8 Guard IResourceObserver::registerObserver with permission
bug: 154733526
bug: 168307955
test: mediatranscodingservice unit testing.
Change-Id: Ie210f704eb0982fcc50b8e7de7e84a7b96280e81
2020-09-25 23:56:38 +00:00
Evan Severson
4f30e0baeb Split camera and microphone for background modes
Test: adb shell dumpsys package [package targeting < 31]>
Bug: 158311343
Change-Id: Ia5d0c40551163772e7cc10fdaf067360c6885f5b
2020-09-23 14:06:05 -07:00
Ulyana Trafimovich
4719733d49 Merge "Drop dependency of android.test.mock -> android.test.base." am: f08e8871d4 am: 72003fb685 am: 10e02f55c0 am: 2dc7803823 am: 51f2298687
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1434135

Change-Id: I3a9f55e09d4dd452445bee3b834f23ce2e98fbbd
2020-09-23 17:08:34 +00:00
Ulya Trafimovich
c578ab0ada Drop dependency of android.test.mock -> android.test.base.
There should be no such dependency.

Test: lunch aosp_cf_x86_phone-userdebug && m
Bug: 169137403
Bug: 132357300
Change-Id: Iaa7414be66581c01c6acbf367dc165cd8af78615
2020-09-23 11:08:01 +01:00
Philip P. Moltmann
aba996799d Revert "Give all non-package services the power to interact accr..."
Revert "Add dedicated host side tests for permissions and appops"

Revert submission 12439864-PermAppOpsCrossUserCheck-Fixed

Reason for revert: Bug 169044600
Reverted Changes:
I95d015e01:Invalidate package/permission cache if cross-profi...
I2a8a84f57:Check cross-user interactions for permissions and ...
Ie8f0db231:Give all non-package services the power to interac...
I11af434a8:Test package/permission cache invalidation when IN...
Ib6d609a4d:Add dedicated host side tests for permissions and ...

Change-Id: I47d371832c119fe4ce4890e10c1ac87aba92acbc
2020-09-21 22:26:51 +00:00
Philip P. Moltmann
5f9b30a11a Give all non-package services the power to interact accross users
Test: ManagedProfileTest#testCameraPolicy
Bug: 153996875
Change-Id: Ie8f0db231a29abc8f478cd519fc661c8fccaa1b7
2020-09-11 19:21:47 -07:00
Adam Bookatz
dc33904acb Remove references to system-user-whitelisted-app
The two SysConfig xml tags
system-user-whitelisted-app
system-user-blacklisted-app
are deprecated and were never used.

Bug: 139547572
Bug: 137101239
Test: compiles
Change-Id: I0a5a8cb9b178a3742ddc1fe70b9ee1e2737abdba
2020-07-21 23:35:04 +00:00
Chen Xu
1d4939fff2 support cellbroadcast data migration by dafault
As part of mainline effort, cellbroadcastreceiver package name has been
renamed. Now its a completely new apk with different uid. That said all
user data e.g, cellbroadcast history and user preference from legacy app
com.android.cellbroadcastreceiver are gone. This change is to support
preserve user data when devices upgrate to R and take cellbraodcast.
mainline module.
1. create legacy cellbroadcast app with old pakcage name
com.android.cellbroadcastreceiver. this app only surface the old data
and should not contains any activities/services to handle emergecy apert
2. legacy cellbroadcast app will be included to the system image by
default. OEMs are free to remove it if they don't care data loss or
after R data migration is done. leagcy app will not be part of
com.android.cellbroadcast apex.
3. the real mainline module rename to com.android.cellbroadcast.module

Bug: 155844209

Change-Id: I5e61c7e777526e038cd8d9971a2c5b87c00eaacb
Merged-in: I5e61c7e777526e038cd8d9971a2c5b87c00eaacb
2020-05-27 20:25:10 +00:00
Chen Xu
bb4b28e805 support cellbroadcast data migration by dafault
As part of mainline effort, cellbroadcastreceiver package name has been
renamed. Now its a completely new apk with different uid. That said all
user data e.g, cellbroadcast history and user preference from legacy app
com.android.cellbroadcastreceiver are gone. This change is to support
preserve user data when devices upgrate to R and take cellbraodcast.
mainline module.
1. create legacy cellbroadcast app with old pakcage name
com.android.cellbroadcastreceiver. this app only surface the old data
and should not contains any activities/services to handle emergecy apert
2. legacy cellbroadcast app will be included to the system image by
default. OEMs are free to remove it if they don't care data loss or
after R data migration is done. leagcy app will not be part of
com.android.cellbroadcast apex.
3. the real mainline module rename to com.android.cellbroadcast.module

Bug: 155844209

Change-Id: I5e61c7e777526e038cd8d9971a2c5b87c00eaacb
2020-05-23 21:26:30 -07:00
Hall Liu
594a7cb577 Merge "Convert Telephony broadcasts to be non-sticky" into rvc-dev am: ee1249911a am: 276f44d2ba am: 558b7f1af4 am: e6fa6c55b0
Change-Id: Ic5183c50e7932e9d3f4c985de8783aa4579854f3
2020-05-10 06:02:57 +00:00
Hall Liu
45066127b3 Convert Telephony broadcasts to be non-sticky
Convert ACTION_SERVICE_STATE_CHANGED and
ACTION_ANY_DATA_CONNECTION_CHANGED to be non-sticky broadcasts that
require the READ_PHONE_STATE permission to receive. As part of this,
declare READ_PHONE_STATE to be split from READ_PRIVILEGED_PHONE_STATE,
so that system apps holding READ_PRIVILEGED_PHONE_STATE can also receive
these broadcasts.

Also modify affected users to fetch the current value of the broadcast
upon registration instead of relying on the sticky nature of the
broadcast.

Bug: 150155839
Test: manual
Test: atest KeyguardUpdateMonitorTest
Change-Id: I020b1554c4fc59c138d015e787526b4a66c74853
2020-05-06 18:11:50 -07:00
Chong Zhang
9248b26375 Grant PACKAGE_USAGE_STATS permission to media uid
Allow media service to register UidObserver to get uid
state changes. Media transcoding uses uid states for
transcoding job scheduling purposes.

bug: 154734285
bug: 145233472

Change-Id: I20c7b33798ff5ede6620cccf65143da5ad77cba5
2020-04-29 10:55:37 -07:00