Commit Graph

419707 Commits

Author SHA1 Message Date
Nate Myren
d38c2bc0ce Merge "RESTRICT AUTOMERGE Revoke SYSTEM_ALERT_WINDOW on upgrade past api 23" into qt-dev 2022-10-28 21:27:28 +00:00
TreeHugger Robot
191036a989 Merge "[RESTRICT AUTOMERGE] Trim the activity info of another uid if no privilege" into qt-dev 2022-10-28 01:03:25 +00:00
TreeHugger Robot
14a5113c31 Merge "[RESTRICT AUTOMERGE][SettingsProvider] key size limit for mutating settings" into qt-dev 2022-10-27 17:05:59 +00:00
TreeHugger Robot
88a76a8cfc Merge "RESTRICT AUTOMERGE Revert "Revert "RESTRICT AUTOMERGE Validate permission tree size..."" into qt-dev 2022-10-27 02:09:34 +00:00
David Saff
b4ac90f433 Merge "Disable broken NotificationStackScrollLayoutTest on qt-dev" into qt-dev 2022-10-26 20:40:59 +00:00
Nate Myren
4e83e59b27 RESTRICT AUTOMERGE Revert "Revert "RESTRICT AUTOMERGE Validate permission tree size..."
Revert submission 20285709-revert-20103164-permTree-qt-dev-QWIEBZIWEA

Reason for revert: resubmission
Reverted Changes:
I0a3b68aff:Revert "RESTRICT AUTOMERGE Add PermissionMemoryFoo...
I4e8ec8b1a:Revert "RESTRICT AUTOMERGE Validate permission tre...

Change-Id: I3cd1aa270373bb32f95dfbe8422faa783ee49dca
2022-10-26 17:58:58 +00:00
Chris Sabotta
f661f5e669 Merge "Revert "RESTRICT AUTOMERGE Validate permission tree size on perm..."" into qt-dev 2022-10-26 00:52:51 +00:00
Chris Sabotta
b3fea7d1a8 Revert "RESTRICT AUTOMERGE Validate permission tree size on perm..."
Revert submission 20103164-permTree-qt-dev

Reason for revert: build breakage b/255661858
Reverted Changes:
I15343e84c:RESTRICT AUTOMERGE Validate permission tree size o...
If16ecb7be:RESTRICT AUTOMERGE Add PermissionMemoryFootprintTe...

Change-Id: I4e8ec8b1a609d0e7a6bb379579014c82a9825101
2022-10-26 00:49:58 +00:00
Nate Myren
2d9de7b6ef Merge "RESTRICT AUTOMERGE Validate permission tree size on permission update" into qt-dev 2022-10-25 19:24:24 +00:00
Nate Myren
ce6ae95066 RESTRICT AUTOMERGE Validate permission tree size on permission update
Bug: 242537498
Test: manual
Change-Id: I15343e84c1802d6b89249106263319a6539fa73b
Merged-In: I15343e84c1802d6b89249106263319a6539fa73b
2022-10-25 16:28:12 +00:00
David Saff
b23782141b Disable broken NotificationStackScrollLayoutTest on qt-dev
Test: presubmit & abtd
Bug: 255552856
Bug: 255368934
Change-Id: Ibc2edc99f99e02edc5dd75486dda64b945223569
2022-10-25 16:16:20 +00:00
Songchun Fan
f1831c8712 [RESTRICT AUTOMERGE][SettingsProvider] key size limit for mutating settings
Prior to targetSdk 22, apps could add random system settings keys which
opens an opportunity for OOM attacks. This CL adds a key size limit.

BUG: 239415997
Test: manual; will add cts test
Merged-In: Ic9e88c0cc3d7206c64ba5b5c7d15b50d1ffc9adc
Change-Id: Ic9e88c0cc3d7206c64ba5b5c7d15b50d1ffc9adc
(cherry picked from commit 783bcba343)
2022-10-24 17:29:19 +00:00
Louis Chang
9c19841384 [RESTRICT AUTOMERGE] Trim the activity info of another uid if no privilege
The activity info could be from another uid which is different
from the app that hosts the task. The information should be
trimmed if the caller app doesn't have the privilege.

Bug: 243130512
Test: verified locally
Test: atest RecentTasksTest
Change-Id: Ia343ac70e5bb9aeae718fca6674e1ca491a14512
(cherry picked from commit 401e782b24)
2022-10-20 13:54:23 +00:00
Songchun Fan
d85a428210 [SettingsProvider] mem limit should be checked before settings are updated
Previously, a setting is updated before the memory usage limit
check, which can be exploited by malicious apps and cause OoM DoS.

This CL changes the logic to checkMemLimit -> update -> updateMemUsage.

BUG: 239415861
Test: atest com.android.providers.settings.SettingsStateTest

(cherry picked from commit 8eeb92950f)
Merged-In: I20551a2dba9aa79efa0c064824f349f551c2c2e4
Change-Id: I20551a2dba9aa79efa0c064824f349f551c2c2e4
2022-10-19 08:43:07 -07:00
Yuri Lin
600ecb01d0 Merge "[DO NOT MERGE] Fix conditionId string trimming in AutomaticZenRule" into qt-dev 2022-10-18 21:06:37 +00:00
Nate Myren
f6ba142a84 RESTRICT AUTOMERGE Revoke SYSTEM_ALERT_WINDOW on upgrade past api 23
Bug: 221040577
Test: atest PermissionTest23#testPre23AppsWithSystemAlertWindowGetDeniedOnUpgrade
Change-Id: I4b4605aaae107875811070dea6d031c5d9f25c96
2022-10-18 20:49:46 +00:00
Yuri Lin
303f6bde89 [DO NOT MERGE] Fix conditionId string trimming in AutomaticZenRule
This change only applies to S branches and earlier.

Bug: 253085433
Bug: 242703460
Bug: 242703505
Bug: 242703780
Bug: 242704043
Bug: 243794204
Test: AutomaticZenRuleTest
Change-Id: Iae423d93b777df8946ecf1c3baf640fcf74990ec
Merged-In: Iae423d93b777df8946ecf1c3baf640fcf74990ec
2022-10-18 15:30:15 +00:00
Daniel Norman
dc0095e9e4 Merge "RESTRICT AUTOMERGE Disable all A11yServices from an uninstalled package." into qt-dev 2022-10-17 19:44:36 +00:00
TreeHugger Robot
62044e5099 Merge "Stop managed profile owner granting READ_SMS" into qt-dev 2022-10-08 11:41:10 +00:00
Daniel Norman
3796629985 RESTRICT AUTOMERGE Disable all A11yServices from an uninstalled package.
Previous logic would exit the loop after removing the first service
matching the uninstalled package.

Bug: 243378132
Test: atest AccessibilityEndToEndTest
Test: m sts;
      sts-tradefed run sts-dynamic-develop -m \
        CtsAccessibilityServiceTestCases
Change-Id: I4ba30345d8600674ee8a9ea3ff411aecbf3655a3
2022-10-07 19:20:53 +00:00
Hao Ke
459808b2c0 Merge "Add safety checks on KEY_INTENT mismatch." into qt-dev 2022-10-05 18:40:44 +00:00
Rhed Jao
4727daddff Merge "[DO NOT MERGE] Fix permanent denial of service via setComponentEnabledSetting" into qt-dev 2022-10-05 00:12:20 +00:00
Hao Ke
eb9a0566a5 Add safety checks on KEY_INTENT mismatch.
For many years, Parcel mismatch typed exploits has been using the
AccoungManagerService's passing of KEY_INTENT workflow, as a foothold of
launching arbitrary intents. We are adding an extra check on the service
side to simulate the final deserialization of the KEY_INTENT value, to
make sure the client side won't get a mismatched KEY_INTENT value.

Bug: 250588548
Bug: 240138294
Test: atest CtsAccountManagerTestCases
Test: local test, also see b/250588548
Change-Id: I433e34f6e21ce15c89825044a15b1dec46bb25cc
2022-10-04 22:07:34 +00:00
TreeHugger Robot
8a2baf4e16 Merge "[Do Not Merge] Ignore malformed shortcuts" into qt-dev 2022-10-03 20:23:07 +00:00
Matt Pietal
2663e8aa43 Merge "[DO NOT MERGE] Update window with FLAG_SECURE when bouncer is showing" into qt-dev 2022-09-27 19:25:13 +00:00
Rhed Jao
4d13148a3f [DO NOT MERGE] Fix permanent denial of service via setComponentEnabledSetting
Do not update invalid component enabled settings to prevent the
malicious apps from exhausting system server memory.

Bug: 240936919
Test: atest android.security.cts.PackageManagerTest
Change-Id: I08165337895e89f13a2b9fcce1201cba9ad13d7d
2022-09-27 03:33:09 +00:00
Pinyao Ting
5a292b8bf4 Merge "Fix a security issue in app widget service." into qt-dev 2022-09-23 19:57:23 +00:00
Julia Reynolds
261b601d25 Merge "Fix NPE" into qt-dev 2022-09-22 18:37:39 +00:00
Pinyao Ting
0ee21ef3e6 Fix a security issue in app widget service.
Bug: 234013191
Test: atest RemoteViewsAdapterTest
Change-Id: Icd2eccb7a90124aca18a3dd463c3f79e3a595c20
Merged-In: Icd2eccb7a90124aca18a3dd463c3f79e3a595c20
(cherry picked from commit 263d7d0ba8)
2022-09-22 18:01:28 +00:00
Yuri Lin
da63d3e028 Merge "Limit lengths of fields in Condition to a max length." into qt-dev 2022-09-22 15:21:17 +00:00
Pinyao Ting
9b0dd514d2 [Do Not Merge] Ignore malformed shortcuts
After an app publishes a shortcut that contains malformed intent, the
system can be stuck in boot-loop due to uncaught exception caused by
parsing the malformed intent.

This CL ignores that particular malformed entry. Since shortcuts are
constantly writes back into the xml from system memory, the malformed
entry will be removed from the xml the next time system persists
shortcuts from memory to file system.

Bug: 246540168
Change-Id: Ie1e39005a5f9d8038bd703a5bc845779c2f46e94
Test: manual
2022-09-21 23:03:20 +00:00
Songchun Fan
b625b562c4 Merge "[pm] forbid deletion of protected packages" into qt-dev 2022-09-15 20:58:34 +00:00
Yuri Lin
5cb217fff3 Limit lengths of fields in Condition to a max length.
This app-generated input needs to not be too long to avoid errors in the process of writing to disk.

Bug: 242846316
Test: cts ConditionTest; atest ConditionTest; manually verified exploit apk is OK

Change-Id: Ic2fa8f06cc7a4c1f262115764fbd1be2a226b4b9
Merged-In: Ic2fa8f06cc7a4c1f262115764fbd1be2a226b4b9
(cherry picked from commit 81352c3775)
2022-09-15 18:06:30 +00:00
Matt Pietal
c561831af7 [DO NOT MERGE] Update window with FLAG_SECURE when bouncer is showing
This will prevent bouncer interactions from showing up in
screenrecords or screenshots.

Fixes: 215005011
Test: atest StatusBarWindowControllerTest && take screenshot
with bouncer up

Merged-In: I3f59df865dc2dd13d4b9ac54bb2dacb7b23f0aa1
Change-Id: I8df2258863b8cede5ba112331e0446f534267ba2
2022-09-15 17:52:28 +00:00
Daniel Norman
6505ed1695 Merge "Include all enabled services when FEEDBACK_ALL_MASK." into qt-dev 2022-09-15 16:43:41 +00:00
TreeHugger Robot
c184d7b721 Merge "[DO NOT MERGE] Do not dismiss keyguard after SIM PUK unlock" into qt-dev 2022-09-15 16:39:42 +00:00
Matt Pietal
a30148b8a4 [DO NOT MERGE] Do not dismiss keyguard after SIM PUK unlock
After PUK unlock, multiple calls to
KeyguardSecurityContainerController#dismiss() were being called from
the KeyguardSimPukViewController, which begins the transition to the
next security screen, if any. At the same time, other parts of the
system, also listening to SIM events, recognize the PUK unlock and
call KeyguardSecurityContainer#showSecurityScreen, which updates which
security method comes next. After boot, this should be one of PIN,
Password, Pattern, assuming they have a security method. If one of the
first dismiss() calls comes AFTER the security method changes, this is
incorrectly recognized by the code as a successful
PIN/pattern/password unlock. This causes the keyguard to be marked as
done, causing screen flickers and incorrect system state.

The solution: every call to dismiss() should include a new parameter
for the security method used. If there is a difference between this
parameter and the current value in KeyguardSecurityContainerCallback,
ignore the request, as the system state has changed.

Bug: 218500036
Test: atest KeyguardSecurityContainerTest

Merged-In: I7c8714a177bc85fbce92f6e8fe911f74ca2ac243
Change-Id: I30226bc7b5eda9480d471b35fe81e106b0491ff8
2022-09-14 14:49:28 +00:00
Songchun Fan
2e42c393f2 [pm] forbid deletion of protected packages
BUG: 242996180
Test: adb shell pm uninstall --user 0 com.google.android.apps.work.oobconfig
Test: Verified with the command above. Before this CL, the package can
be deleted. After this CL, the deletion will fail.

Change-Id: Iba408e536b340ea5d66ab499442c0c4f828fa36f
(cherry picked from commit 15f85c7fa9)
Merged-In: Iba408e536b340ea5d66ab499442c0c4f828fa36f
2022-09-12 17:26:02 -07:00
Julia Reynolds
a375542897 Fix NPE
Test: NotificationChannelGroupTest
Test: view notification settings for an app that doesn't use groups
Fixes: 244574602
Bug: 241764350
Bug: 241764340
Bug: 241764135
Bug: 242702935
Bug: 242703118
Bug: 242703202
Bug: 242702851
Bug: 242703217
Bug: 242703556
Change-Id: I9c681106f6d645e62b0e44903d40aa523fee0e95
(cherry picked from commit 6f02c07176)
2022-09-08 14:05:01 +00:00
Yuri Lin
3fe8fdc4dc Merge "Fix system zen rules by using owner package name if caller is system" into qt-dev 2022-09-07 18:09:40 +00:00
TreeHugger Robot
cef7f19369 Merge "[RESTRICT AUTOMERGE] Check permission for VoiceInteraction" into qt-dev 2022-09-07 03:10:24 +00:00
Yuri Lin
380ec03dee Merge "Trim any long string inputs that come in to AutomaticZenRule" into qt-dev 2022-09-06 23:01:44 +00:00
Yuri Lin
dbfe869c30 Fix system zen rules by using owner package name if caller is system
Previously were unable to add new zen rules because rules added via the settings pages were getting registered under package "com.android.settings", which then were not considered "system rules". These rules should have package android, so when we can trust the caller (via checking that the caller is system) we should be taking the package name from the owner of the rule.

Bug: 245236706
Bug: 242537431
Test: NMSTest; manual

Change-Id: Id69b671592396ac3304862dadbe73de328a8e27a
Merged-In: Id69b671592396ac3304862dadbe73de328a8e27a
2022-09-06 21:20:11 +00:00
TreeHugger Robot
0b5ceb8cd2 Merge "Validate package name passed to setApplicationRestrictions." into qt-dev 2022-09-06 15:05:26 +00:00
Daniel Norman
2bc4d49c2b Include all enabled services when FEEDBACK_ALL_MASK.
Bug: 243849844
Test: m sts;
      sts-tradefed run sts-dynamic-develop -m CtsAccessibilityTestCases
Change-Id: I4f93e06d1066085bd64e8f09882de2f4a72a0633
2022-09-01 20:17:54 +00:00
Yuri Lin
c4b2c877ec Trim any long string inputs that come in to AutomaticZenRule
This change both prevents any rules from being unable to be written to disk and also avoids risk of running out of memory while handling all the zen rules.

Bug: 242703460
Bug: 242703505
Bug: 242703780
Bug: 242704043
Bug: 243794204
Test: cts AutomaticZenRuleTest; atest android.app.AutomaticZenRuleTest; manually confirmed each exploit example either saves the rule successfully with a truncated string (in the case of name & conditionId) or may fail to save the rule at all (if the owner/configactivity is invalid). Additionally ran the memory-exhausting PoC without device crashes.

Change-Id: I110172a43f28528dd274b3b346eb29c3796ff2c6
Merged-In: I110172a43f28528dd274b3b346eb29c3796ff2c6
(cherry picked from commit de172ba0d4)
2022-09-01 18:54:21 +00:00
Oli Lan
cfcfe6ca8c Validate package name passed to setApplicationRestrictions.
This adds validation that the package name passed to
setApplicationRestrictions is in the correct format. This will avoid
an issue where a path could be entered resulting in a file being
written to an unexpected place.

Bug: 239701237
Test: atest UserManagerServiceTest
Change-Id: I1ab2b7228470f10ec26fe3a608ae540cfc9e9a96
(cherry picked from commit 31a582490d)
Merged-In: I1ab2b7228470f10ec26fe3a608ae540cfc9e9a96
2022-08-30 16:10:28 +01:00
Yuri Lin
fcc640c578 Check rule package name in ZenModeHelper.addAutomaticRule
instead of checking that of the configuration activity, which is potentially spoofable. The package name is verified to be the same app as the caller by NMS.

This change removes isSystemRule (called only once) in favor of checking the provided package name directly.

Bug: 242537431
Test: ZenModeHelperTest, manual by verifying via provided exploit apk
Change-Id: Ic7f350618c26a613df455a4128c9195f4b424a4d
Merged-In: Ic7f350618c26a613df455a4128c9195f4b424a4d
2022-08-25 21:17:32 +00:00
Oli Lan
adafc9cb0f Merge "RESTRICT AUTOMERGE Prevent non-admin users from deleting system apps." into qt-dev 2022-08-24 13:37:04 +00:00
Julia Reynolds
c2d264989a Limit the size of NotificationChannel and NotificationChannelGroup
Test: android.app.NotificationChannelGroupTest
Test: android.app.NotificationChannelTest
Test: cts NotificationChannelTest
Test: cts NotificationChannelGroupTest
Bug: 241764350
Bug: 241764340
Bug: 241764135
Bug: 242702935
Bug: 242703118
Bug: 242703202
Bug: 242702851
Bug: 242703217
Bug: 242703556
Change-Id: I0925583ab54d6c81c415859618f6b907ab7baada
Merged-In: I0925583ab54d6c81c415859618f6b907ab7baada
(cherry picked from commit 3850857cb0)
2022-08-23 13:22:33 +00:00