Commit Graph

245 Commits

Author SHA1 Message Date
Thomas Vannet
af615e7baf Add self revocation public API
Test: Manual test using a non-privileged app, atest
android.permission.cts.SelfRevokeRuntimePermissionTest

When calling the API, the permission (along with any other permissions
from the same group) for the current package is downgraded to a one-time
permission, and a one-time permission session is started.

Bug: 210387494

Change-Id: I9f061cbc8c3db720127c96200fe94a644246b6d7
2022-01-11 16:32:40 -08:00
Nate Myren
2c54f50da6 Allow shell to revoke notification permission without kill
Add the revokePostNotificationPermissionWithoutKillForTest API, which
will allow the shell to revoke the POST_NOTIFICATIONS permission without
killing this app. Gate this permission behind the
REVOKE_POST_NOTIFICATIONS_WITHOUT_KILL permission, which is
signature|privileged, accessible only to the shell.

Ignore-AOSP-First: Contains information about unreleased features
Test: manual
Bug: 194833441
Change-Id: I3177d1aeb338591c1d736aa6b4f073b6db6227e7
2022-01-10 11:58:45 -08:00
Lee Shombert
9a686c07ba Merge "Prepare PropertyInvalidatedCache for SystemApi" 2022-01-06 23:14:05 +00:00
Kevin Han
8c7b307f03 Merge "Add unused count API" 2022-01-06 01:24:26 +00:00
Jordan Jozwiak
a5ca465453 Merge "Intent action to review permission decisions" 2022-01-05 17:25:01 +00:00
Nate Myren
96f8c9fd10 Merge "Ensure only microphone attribution chains are recorded" 2022-01-04 17:04:27 +00:00
Lee Shombert
0cece3898b Prepare PropertyInvalidatedCache for SystemApi
Bug: 152453213
Tag: #refactor

This commit prepares PropertyInvalidatedCache to function as a system
api.  Specifically, the methods recompute() and bypass() which may be
overridden by clients are now public (instead of protected).  This
forces an update to all existing clients, to accommodate the change in
method visibility.

Two small changes have been made as cleanup:

 1. The awkwardly named debugCompareQueryResults() is now
    resultEquals(), which is more or less consistent with how other
    equality tests are named in Android.  This name change affects two
    clients.

 2. PackageManager has changed to use resultEquals() instead of
    maybeCheckConsistency().  This provides a simpler and more
    consistent use of the APIs.  maybeCheckConsistency() has been made
    private.

Test: atest PropertyInvalidatedCacheTests

Change-Id: I4110f8e887a4fd8c784141e8892557a9d1b80a94
2022-01-04 08:13:59 -08:00
William Escande
6b436464d2 Javadoc on Method from api review
Add some specific info on checkPermissionForDataDeliveryFromDataSource
javadoc.
Fix: 204179567
Bug: 195144968
Test: build (it's only javadoc)

Change-Id: I6d4e5b9e06bf990b5e40eb727259dc79753d5eef
2022-01-03 12:08:51 +01:00
Nate Myren
33c3c1a629 Ensure only microphone attribution chains are recorded
Also ensure each chain is attributed to only one op

Test: manual
Fixes: 212434116
Change-Id: I50efc2b305627f8e37eb28842487b911dce5d925
2021-12-29 11:36:49 -08:00
Jordan Jozwiak
70b59c872d Intent action to review permission decisions
Action will open the PermissionController screen to review recent
permission decisions. Currently only supported on Auto.

Bug: 194240664
Test: adb shell am start -a android.permission.action.REVIEW_PERMISSION_DECISIONS
Change-Id: Ic37e0b69632d38596b707cd7b1a17fbb89bfa547
2021-12-22 13:13:46 -08:00
Kevin Han
f23347642c Add unused count API
Add unused count API to PermissionControllerManager to allow Settings to
pull the number of unused apps from PermissionController.

Bug: 200087723
Bug: 187465752
Test: CTS test in topic
Change-Id: I197b07af0e7a40bb5daececd8ef7d053a2895016
2021-12-16 18:11:14 -08:00
Nate Myren
8fb048aede Lock mAttributionChains in PermissionUsageHelper
Test: manual
Fixes: 201451838
Change-Id: I4b17ed0e65fae45f393665f7f9d617a2acc1cbdd
2021-12-08 13:51:09 -08:00
Hai Zhang
124f68b2f2 Merge "Unify owners for default permission grant policy." am: bff35de778 am: 74906bb45b am: b78ad5e8db am: a176c9efb2 am: 2d8f698bd7
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1878788

Change-Id: Ife128e50b161df46d3116acbbaf5472c36aa60c3
2021-11-05 21:11:43 +00:00
Hai Zhang
7ea5048947 Unify owners for default permission grant policy.
The list of owners is taken from:
- frameworks/base/services/core/java/com/android/server/pm/permission/OWNERS
- cts/common/device-side/util-axt/src/com/android/compatibility/common/util/OWNERS
- vendor/xts/gts-tests/tests/permission/src/com/google/android/permission/gts/OWNERS

Test: presubmit
Change-Id: I3cc073d4890a4295caba8b04752a02f1e00db03c
2021-11-03 03:41:45 +00:00
Nate Myren
533d486d60 Merge "Only initialize PermissionUsageHelper lazily or when requested" 2021-11-02 22:07:52 +00:00
Nate Myren
338cafab6c Only initialize PermissionUsageHelper lazily or when requested
This fixes a memory leak caused by automatically registering a
PermissionUsageHelper on PermissionManager instantiation.

Bug: 204222680
Test: manual
Change-Id: I94c6da3dd89e8b158552e94c94e4d0fb3f5d6f0d
2021-11-02 21:03:04 +00:00
William Escande
57bc716432 Add checkPermissionForDataDeliveryFromDataSource
Api is used by Bluetooth and we need to stop using the hidden call to
permissionChecker
Add associated CTS test

Bug: 195144968
Tag: #refactor
Test: Build
Change-Id: I854b7b5e3d95589bf0d3df307829e3f85e31aee1
2021-10-07 20:11:01 +02:00
Treehugger Robot
d335f26f60 Merge "Update permissions OWNERS" am: dbbb827a79 am: 799b63acc2 am: 3c213db1f8 am: 31e6117eb0 am: 3dfc16e7da
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1838051

Change-Id: Ib5be74f5815d966db35d5c74ea9c2de445c33144
2021-09-28 05:12:34 +00:00
Treehugger Robot
799b63acc2 Merge "Update permissions OWNERS" am: dbbb827a79
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1838051

Change-Id: Ic4d3da57e701c0da40c55bd44d73df0edce9a911
2021-09-28 04:19:01 +00:00
Evan Severson
73ebf86c32 Update permissions OWNERS
Bug: 201319595
Test: None
Change-Id: Iebb9cd731b592df2dfb79bd088e917635c21b6b1
2021-09-28 01:03:32 +00:00
Hai Zhang
4c8ff26e9f Expose PermissionChecker as system API.
Only the most basic two APIs are exposed here, which happens to be the
ones required by USB module so that we can unblock them before IC. The
other overloads and variants can be exposed later when we have a
proper decision on how to expose this entire class as an API.

The constant values are hard-coded because they have to be compile
constants to be included in API, while referencing the PermissionChecker
fields doesn't count as such.

More details are available in Buganizer comments.

Bug: 195353742
Test: atest android.permission5.cts.PermissionCheckerTest
Change-Id: I156c3be0e4c45c95a65bfa9117fb6b850b95238d
2021-09-14 11:51:56 -07:00
Nate Myren
aad177261c Merge "Add attribution info to start callbacks" into sc-dev am: 5d97f29218 am: d1a82a7de8
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/15446590

Change-Id: Ic800a8e11e6d8513629ec8e9b1f64ffef0c85645
2021-08-03 20:18:08 +00:00
Nate Myren
06d07d54db Add attribution info to start callbacks
Add attribution flags and chain IDs to start callbacks, and have the
PermissionUsageHelper listen for starts. This ensures that, if another
start happens while an op is already running, and has chain information,
then this chain information will be recorded.

Test: manual
Bug: 194198234
Change-Id: I0ab1aa0969b70e18001f4a814ea5689f9329a019
2021-08-03 08:25:31 -07:00
Lee Shombert
e2405233d9 Do not cache wildcard users (PermissionManager)
Bug: 186778818

PropertyInvalidatedCache queries that contain wildcard user IDs are no
longer cached.  Some simple multi-user tests show that no current
caches use wildcard user IDs, so the change has no effect on
performance.  The bypass() mechanism is used to avoid the cache when
necessary.

The change is preemptive - there are no known uses of these caches
with wildcard user IDs.

Test: atest
 * FrameworksServicesTests:UserManagerServiceCreateProfileTest

Change-Id: I60be14ae33fcd6e2e8df30c279311f6ffdf7711c
2021-08-02 17:03:41 +00:00
Jeff Sharkey
75d4f93a4e Pass metadata as AttributionSourceSource.
These two PermissionManager methods are using AttributionSource as
metadata only, and aren't interested in the remote caller enforcing
that the claimed UID matches the caller, since they're not actually
being used for permission enforcement.

Thus we pass the metadata using the AttributionSourceState holder
object and reconstruct on the remote side, entirely avoiding the
enforceCallingUid() check.

Bug: 193842956
Test: atest CtsPermission5TestCases
Change-Id: I576b6feb8cc2b0586b4341268866d8027689293f
2021-07-27 09:45:54 -06:00
Svet Ganov
1babd5bf51 Optimize AttributionSource tokens - base
For cases where the attribution soruce doesn't need to be
registered as trusted we are now using a shares static
token since the only purpose of the token in these cases
is for watching the source process dying as opposed to that
and security for registered cases.

bug: 192415943

Test: CtsPermissionTestCases
      CtsPermission2TestCases
      CtsPermission3TestCases
      CtsPermission4TestCases
      CtsPermission5TestCases

Change-Id: I93fde9ca1cacada7929761533dcae11b2736ce1e
2021-07-10 00:24:30 +00:00
Nate Myren
4c426c4d03 Create "trusted chain" mechanism for AttributionSource
Add and populate a "trusted" attribution flag, that verifies the
attribution sources used to create it were trusted.

Fixes: 192270935
Test: atest RuntimePermissionsAppOpTrackingTest
Change-Id: Ifd8f825151bec55aa795da7bee0a3069509f5abe
2021-06-30 16:06:59 -07:00
Nate Myren
fd49debdc0 Create Attribution Chains in HistoricalOps
Add a historical flag to signify that attribution chains should be
assembled. Assemble the chains, filter out middle nodes, and attach the
last visible node to the start as a proxy info

Bug: 158792096
Test: manual
Change-Id: I8fbd8f438c62b28fd90039440e86224c624dea79
2021-06-23 12:12:15 -07:00
Nate Myren
5cd62ee5f7 Support AttributionSource chains in PermissionUsageHelper
Test: manual
Bug: 184963112
Change-Id: Idca4ccdaab1f243b754ef15888ea679788bfdd9b
2021-06-04 12:55:50 -07:00
Svet Ganov
2eebf92965 Switch media fw permissions checks to AttributionSource
Attribution source is the abstraction to capture the data
flows for private data across apps. Checking permissions
for an attribution source does this for all apps in the
chain that would receive the data as well as the relevant
app ops are checked/noted/started as needed.

Teach speech recognition service about attribution
chains. If an implementation does nothing the OS
would enforce permisisons and do blame as always.
This apporach leads to double blaming and doesn't
support attribition chains where app calls into
the default recognizer which calls into the on
device recognizer (this nests recursively). If the
implementer takes advantage of the attribution chain
mechanims the permissions for the entire chain are
checked at mic access time and all apps are blamed
only once.

Fixed a few bugs around finishing ops for attribution
chains. Also ensured that any app death in a started
attribution chain would lead to finishing the op for
this app

bug: 158792096

Test: (added tests for speech reco)
      atest CtsMediaTestCases
      atest CtsPermissionTestCases
      atest CtsPermission2TestCases
      atest CtsPermission3TestCases
      atest CtsPermission4TestCases
      atest CtsPermission5TestCases
      atest CtsAppOpsTestCases
      atest CtsAppOps2TestCases

Merged-In: Ic92c7adc14bd2d135ac13b96f17a1b393dd562e4

Change-Id: Ic92c7adc14bd2d135ac13b96f17a1b393dd562e4
2021-06-01 23:43:29 +00:00
TreeHugger Robot
78896f98c0 Merge "Add missing permission enforcement." into sc-dev 2021-06-01 21:50:44 +00:00
Hai Zhang
a4015ce67a Add missing permission enforcement.
Since, we are opening PermissionControllerService to instant apps for
the permission group mapping API, I'm reviewing the permission checks
and this is the only missing one. However, this API is just a trigger
to update our state so calling it some more times shouldn't pose a
security risk, so this fix is just a nice-to-have.

Bug: 189836392
Test: presubmit
Change-Id: I6e9159ce090acaad2ecf522bd04c613169e03252
2021-06-01 12:45:00 -07:00
Hai Zhang
032d5f1fd5 Fix wrong permission check in
setRuntimePermissionGrantStateByDeviceAdminFromParams().

This is nice to have, but not necessarily a security fix because we are
already always enforcing ADJUST_RUNTIME_PERMISSIONS_POLICY.

Bug: 158735247
Test: presubmit
Change-Id: I629969e04e1d5e7e3ef47c8833780f19d83b9e0b
2021-06-01 18:55:01 +00:00
Hai Zhang
8bda34c493 Expose platform permission group mapping as public API.
The API is moved from PermissionControllerManager (only a System API)
to PackageManager to expose it as public API.

Bug: 182094776
Test: atest GetPermissionGroupInfoTest
Change-Id: I175afb2e37bf2651b91765029645f7940f58f39c
2021-05-21 03:03:56 +00:00
Hai Zhang
8f6290db77 Fix nullability of the group name parameter in queryPermissionsByGroup().
Change-Id: Id503da0fe4f16a92997634089fc052d58e78f9df
Fixes: 141452667
Test: presubmit
2021-04-30 21:43:05 +00:00
Nate Myren
2af054a29f Merge "Add Executor to Permission Group methods in PermissionControllerManager" into sc-dev 2021-04-27 15:18:06 +00:00
Nate Myren
599d4db0bd Add Executor to Permission Group methods in PermissionControllerManager
Test: atest GetPermissionGroupInfoTest
Fixes: 185177089
Change-Id: I6b3ff9c02d013ee48dc2f7f39d556cc6da0edac4
2021-04-26 17:51:11 -07:00
Adam Bookatz
33e17a9933 Revert "Prepare AttributionSource to expose to native"
Revert "Prepare AttributionSource to expose to native - native"

Revert submission 14225527-bug-158792096-04/16/21-1

Reason for revert: b/186467053
Reverted Changes:
I16740cc2d:Prepare AttributionSource to expose to native - na...
I4e050e78b:Prepare AttributionSource to expose to native

Change-Id: I83e4091231241c2211edf5745735f4ee993c6680
2021-04-26 23:20:46 +00:00
Svet Ganov
7b7ea938f5 Prepare AttributionSource to expose to native
Separate the internal state of AttributionSource from the
class to make it a simple AIDL we can translate automatically
to native - keeping Java and native parts in sync. This
would allow writing a thin native lib for checking attribution
source permissions which would be used to teach camera and
audio about attributions.

Deinfe an AIDL interface for passing around an attribution
source and opr performing permission checker oprations allowing
native and Java permission checks on attribution chains to be
handled. The Java side permission checker functions are in a dedicated
permisison checker service on top of which sits the PermissionChecker.
We expose similar PermissionChecker native APIs sitting on top
of the same remote interface. The nice thing is that we have
native and Java permisison checkers in sync sharing remoting
code and being close in shape.

For now the PermissionChecker in Java is divorced from the
PermissionManager but in T we will consider how to unify them,
either by an extension object on the PermmissionManager or
APIs on the PermissionManager, or another approach, and then
migrate clients off the PermissionChecker APIs.

bug: 158792096

Test: atest CtsPermission5TestCases

Change-Id: I4e050e78b2361cbf524cc213802e0fef5b487f67
2021-04-25 19:00:30 +00:00
Nate Myren
f7c1b2721e Merge "Change Permission Group methods to be callback, gate behind perm" into sc-dev 2021-04-21 21:01:05 +00:00
TreeHugger Robot
a212d74f3e Merge "Refactor Telephony phone number access checks to LegacyPermissionMgr" into sc-dev 2021-04-21 04:37:41 +00:00
Michael Groover
2947561500 Refactor Telephony phone number access checks to LegacyPermissionMgr
The TelephonyPermissions phone number access check can require several
interactions with the system_server to obtain the targetSdkVersion
and check the required permissions / appops for the requesting
package. This commit refactors all of these checks into the
LegacyPermissionManager (similar to what was previously done for the
device identifier access checks), requiring only a single request
to the system_server to check all non-subscriber access requirements.

Fixes: 159662444
Test: atest TelephonyPermissionsTest
Test: atest LegacyPermissionManagerServiceTest
Test: atest SmsManagerTest
Test: atest PhoneNumberTest
Test: atest SubscriptionControllerTest
Test: atest TelephonyManagerTest
Change-Id: I6c5cdbeecc2c4a2e200dcc33eedcb9213376f1ad
2021-04-20 17:15:59 -07:00
Nate Myren
7590ff96f0 Change Permission Group methods to be callback, gate behind perm
Create a GET_RUNTIME_PERMISSION_GROUP_MAPPING permission to gate the
permission group methods behind, and changes the methods to have
callbacks.

Test: atest GetPermissionGroupInfoTest
Fixes: 185177089
Change-Id: Ifd2ebc74f16e51b62068bdc6c8748f69bc63e923
2021-04-19 16:44:33 -07:00
Fabian Kozynski
60864b944e Do not hold indicators for apps that become paused
If an app op becomes "paused" (microphone muted or disabled by toggle),
remove the indicator immediately as opposed to holding for 5s.

Also, pass the value that we are using for mic muted to
PermissionManager, so they are in sync.

Test: atest SystemUITests
Test: manual
Fixes: 184891081
Change-Id: I4d46fc6e1cefa45c0d718cc01f40c8f060dafee7
2021-04-15 14:22:39 -04:00
Eran Messeri
9ac9fe53bf Merge "Address API review for admin-granted permissions" into sc-dev 2021-04-11 11:44:26 +00:00
Nate Myren
2d400b8737 Exclude only system and device intelligence roles from indicators
Converts both the AppOpsControllerImpl and the PermissionUsageHelper to
use the same static method when filtering which packages to show. The
only packages which are filtered are 6 device intelligence roles, and
the system package. These values are updated at most every 15 seconds

Fixes: 184141707
Test: manual
Change-Id: I9dc44197a2ff3df7783b37f450ada4ef2fb1ca6f
2021-04-07 12:48:30 -07:00
Eran Messeri
1663624e5d Address API review for admin-granted permissions
Address API review for changes related to admin-granted permissions:
* Change the provisioning extra to indicate it only affects
  sensors-related permissions.
* Add an IntDef for the AdminPermissionControlParams grant state.

Bug: 184204476
Bug: 184204334
Test: atest ManagedProvisioningTests
Change-Id: I75c8b6de1e897e02916b17f0ae3a521f8384c242
2021-04-07 19:03:44 +01:00
TreeHugger Robot
086a0be6b2 Merge "Assemble proxy chain based on package/uid, not attribution tag" into sc-dev 2021-04-07 03:08:20 +00:00
Nate Myren
1eda90e312 Assemble proxy chain based on package/uid, not attribution tag
Some proxy usages, in future, may not have matching attribution tags.
Match on package name and uid instead.

Bug: 183402046
Test: Manual
Change-Id: If122f13fb1d20bfe0bad415235f2143d41339650
2021-04-02 14:41:57 -07:00
Svet Ganov
48801b0bbd Hookup renounced permissions
Propagate renounced permissions from context params
to the context attribution source. Throw if one
tries to request at runtime a renounced permission.

Also make the AttributionSource take null for the
setters to ease usage, otherwise folks should always
check for null before calling a builder method.

Additionally, we allow apps that have UPDATE_APP_OPS_STATS
to register arbitrary trusted AttributionSource for
testing. Note that this permission allows abritrary app
op operations, thus we are not relaxing the security
model.

bug: 158792096

Test: atest CtsPermission5TestCases

Change-Id: I4330684bb8695fb998cf31e9363b94ad981ba2cc
2021-04-02 17:30:10 +00:00