Parcel implementation would crash the system server otherwise.
Any exception is OK as it'll cause the cache to be invalidated.
Crash is not OK.
Bug: 194632313
Fixes: 194632313
Test: atest PackageParserCacheHelperTest
Change-Id: I58a4496b4646e172e6c3aee9ea17854a7ef55eaa
This feature will allow OEMs to opt-in specific devices/builds to per-app compat overrides.
Bug: 188500456
Test: N/A
Change-Id: I00108d163f752d23c380496ccac971cf0fcfe0f6
We trust any incoming value from the system UID, so we should also
trust values coming from the root UID, which includes many shell
commands such as "svc".
Bug: 193659633
Test: atest BluetoothInstrumentationTests:com.android.bluetooth.btservice.AdapterServiceTest --rerun-until-failure 100
Change-Id: Ied07731345f08fc3c4df465a3773e35c8df7c59a
The Bluetooth stack is just one example of an application that makes
self-calls through public APIs, which makes it very difficult to
unconditionally validate AttributionSource arguments.
(The AttributionSource is correctly defined the first time a remote
caller enters the Bluetooth stack, but we've found many cases where
Bluetooth stack calls back into itself without clearing the Binder
identity, causing validation chaos.)
This change is an attempt at gracefully solving this by performing
validation automatically as part of unparceling an AttributionSource
the first time it enters a process. This strategy isn't perfect,
since transporting an instance inside a Bundle would risk
unparceling much later, possibly long after the calling UID
information has been discarded. We're rationalizing that this risk
doesn't exist since AttributionSource was only added a few months
ago, and isn't being used in this way.
We still intend to circle back and provide a better strategy in a
future release for transporting AttributionSource across AIDL which
will handle the nuances of self-calls.
Bug: 188391719
Test: atest BluetoothInstrumentationTests
Change-Id: I10b198cfcd8f361e19d52f86deb7f10f05fec891
For cases where the attribution soruce doesn't need to be
registered as trusted we are now using a shares static
token since the only purpose of the token in these cases
is for watching the source process dying as opposed to that
and security for registered cases.
bug: 192415943
Test: CtsPermissionTestCases
CtsPermission2TestCases
CtsPermission3TestCases
CtsPermission4TestCases
CtsPermission5TestCases
Change-Id: I93fde9ca1cacada7929761533dcae11b2736ce1e
We've seen evidence of a Binder leak, and our hunch is that it's
caused by one of these anonymous "new Binder()" sites. Adding
descriptors will help us identify the leak cause.
Bug: 192415943
Test: atest BluetoothInstrumentationTests
Change-Id: I30cd15f084cf50f67edd833b27b853c4b22e1db1
- Previously we were adding the activity info to the ClipData, but
that data is provided to non-intercept windows when the drop happens
and can be retrieved using reflection. The intention was only to
provide this activity info to the shell global intercept window
for invoking split.
Instead of baking the info into the ClipData, we pass the resolved
info along side the data and only construct a ClipData with the
additional info for the intercept window.
Fixes: 191057499
Test: atest DragDropControllerTests
Change-Id: I2ccc9f1f666ff2a388f22b6e6a7b5eea3102964c
This reverts commit cb5a80ea57.
Reason for revert: Was not the cause of the test failure
Fixes: 186622527
Test: atest FrameworksCoreTests:ContextTest
Change-Id: I705854f080200f0465d94a7754e710f05a3ec92c
Specifically, mentioning that the alarm count can only be included with
the alarm if the supplied pending intent is mutable.
Test: make offline-sdk-docs
Fixes: 178413211
Change-Id: I2914bceebeed8b52b0de11d70960aa33e6837b13
Add a test to ensure that system could boot without exception after
a package is uninstalled with keeping data.
Bug: 188635265
Test: atest PackageManagerServiceHostTests
Change-Id: I190db789ecd8c0ca1ddd87fc1c6ef79593b35492
This change cleans up a couple of links in the new setRequireUserAction
javadocs to avoid listing the entire permission namespace in the text.
Fixes: 190535637
Test: Builds
Change-Id: I80fff983309963e0a2485510e793f30fcfbec28e
Its existence allows implicit readParcelable calls to invoke a Parcel
operation with mismatched read/write data sizes, allowing someone to
swap out the data on a reparcel.
Internal classes will use writeIntentInfoToParcel, so this is safe to
remove.
Bug: 191055353
Test: atest com.android.server.pm.test.parsing.parcelling
Change-Id: I44faa635faf8a77894a3dda8adf89c10064e53f1
Unlike staged installer check, we can't check if given APEX package is
allowed to be updated at session creation time, since we don't have
knowledge of the package being installed yet. Instead, the check is
implemented in PackageInstallerSession#handleInstall.
Like staged install check, allowed apex update check has similar
exemptions (adb is allowed to update any APEX,
`adb shell pm --bypass-allowed-apex-update-check` makes next install
session bypass the check).
In order to implement these exemptions, a new
INSTALL_DISABLE_ALLOWED_APEX_UPDATE_CHECK flag that can only be set by
system is added. PackageInstallerSession will skip the APEX update
checks if INSTALL_DISABLE_ALLOWED_APEX_UPDATE_CHECK is set.
Bug: 189274479
Test: atest CtsStagedInstallHostTestCases
Test: atest GtsStagedInstallHostTestCases
Test: atest FrameworksServicesTests:SystemConfigTest
Change-Id: I22921a3ac4d43011b565733d7a7183e5cdb4fe80
Merged-In: I22921a3ac4d43011b565733d7a7183e5cdb4fe80
(cherry picked from commit aafaaec0d5)
Get rid of the unused method to mitigate the potential information
leakage.
Bug: 185124942
Test: atest view-compiler-tests
Test: atest android.view.cts.LayoutInflaterTest
Test: atest -p core/java/android/content/pm
Test: atest -p services/core/java/com/android/server/pm
Test: manually using the PoC in the buganizer to ensure the symptom
no longer exists.
Change-Id: I5ee7381728a93535849fcf61a1373a5ed9036aa4
Tests failed due to wrong targetSdkVersion returned by the apk lite
parser. The result of targetSdkVersion was overwritten by the
ParsingPackageUtils#computeMinSdkVersion.
Bug: 191063347
Test: atest SilentUpdateTests
Change-Id: If24d2c0eac10922903c5ca86d1b8ec8360d92e12
To improve the performance of SilentUpdateHostsideTests in the Cts,
this cl adds support to update the throttle time of silent updates
using the pm command. The `pm set-silent-updates-policy
--throttle-time TIME` could be invoked to shorten the testing waiting
time for the repeated silent updates.
Bug: 189506896
Test: atest SilentUpdateHostsideTests
Change-Id: I2f9ab58d16b7f1173f1ee45b6b842ad1f18136a4
Some devices may not have certain partitions available and the
OverlayConfigTests use hardcoded paths to test OverlayConfig
functionality. This change ensures that the temporary directory
created to test OverlayConfig has all of the partitions defined in
PackagePartitions#SYSTEM_PARTITIONS within it.
Bug: 190469357
Bug: 187020117
Bug: 187020675
Test: atest OverlayConfigTest
Change-Id: I511e24b7ccfe82e6e89ceea7107457439793ef77
Merged-In: I511e24b7ccfe82e6e89ceea7107457439793ef77
Native allocations that hold theme data can be several KBs. Registering
the native allocation using NativeAllocationRegistry helps induce the GC
to free the malloced memory sooner and alleviate memory pressure.
Bug: 187883085
Bug: 141198925
Test: atest ResourcesPerfWorkloads
Change-Id: I2710cfea19565ea8aaf2b5fbd7b2c05d9cb17182
Memory churn is high when swapping the ResourcesImpl of a Resources
object. Each time Resources#setImpl is invoked, all themes based on
that Resources object are assigned new ThemeImpl objects that are
created using the new ResourcesImpl.
ThemeImpls can only belong to one Theme object, so the old
implementation is discarded and the theme takes ownership of the new
ThemeImp.
This creates performance problems when framework overlays are toggled.
Toggling overlays targeting the framework causes all themes across all
processes to recreate and reallocate all of their themes. By rebasing
the ThemeImpl on the new ResourcesImpl without deallocating the native
theme memory, we reduce churn and produce less garbage that needs to
be garbage collected.
Bug: 141198925
Test: atest libandroidfw_tests
Test: atest ResourcesPerfWorkloads
Change-Id: I03fb31ee09c9cfdbd3c41bcf0b605607dab54ed7
It'll help to debug content provider related performance issues.
Bug: 190416935
Test: Manual - Record perfetto trace & verify auth name is logged.
Test: CtsContentTestCases:android.content.cts
Test: FrameworksCoreTests:android.content
Change-Id: Ifaa1c58135e6aa2a46ecbba92a9266e7d29d5421