Commit Graph

10807 Commits

Author SHA1 Message Date
Alex Buynytskyy
36b0e9e94c Always restart apps if base.apk gets updated.
Bug: 219044664
Fixes: 219044664
Test: atest PackageManagerShellCommandTest
Change-Id: I27a0c5009b2d5f1ea51618b9acfa1e6ccee71296
Merged-In: I27a0c5009b2d5f1ea51618b9acfa1e6ccee71296
2022-03-09 00:47:24 +00:00
Michael Groover
115740d022 Merge "Revert "[DO NOT MERGE]Revert "Relax minimum signature scheme ver..."" into sc-v2-dev 2022-03-08 00:42:19 +00:00
Michael Groover
01c3d11b83 Revert "[DO NOT MERGE]Revert "Relax minimum signature scheme ver..."
Revert submission 16943318-presubmit-am-bc566b73c1674298b82a1153c03313a1

Reason for revert: This change breaks Better Bug.
Reverted Changes:
I32a2db8c7:[automerge] [DO NOT MERGE]Revert "Relax minimum si...
Ic53d2a361:[DO NOT MERGE]Revert "Relax minimum signature sche...

Bug: 223079119

Change-Id: I987bda9df92543f082700936c20aad06f992bdb0
2022-03-08 00:05:17 +00:00
Michael Groover
7026055322 Merge "[DO NOT MERGE]Revert "Relax minimum signature scheme version for apps on system partition"" into sc-v2-dev 2022-03-05 00:02:48 +00:00
Michael Groover
3c36fd5fee [DO NOT MERGE]Revert "Relax minimum signature scheme version for apps on system partition"
This reverts commit b71e398935.

Revert reason: System apps should now have uncompressed dex / library
files in their APKs and should be able to satisfy the minimum V2
signature requirement when targeting API level 30+.

Fixes: 215046612
Test: Manually verified V1 only signed APK targeting API level 30
      on the system image failed to verify.
Change-Id: Ic53d2a3614e7dff4e4bfe18561d3dfbb665bbcb2
2022-02-22 18:17:11 +00:00
TreeHugger Robot
6e59db1952 Merge changes from topic "presubmit-am-0d13c95295c446889fc51032ba336d89" into sc-qpr1-dev am: 459761c7a3
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/16778744

Change-Id: I930db864b7bb7e90996cb54e8e92a0422e5f3a2c
2022-02-09 18:10:54 +00:00
Presubmit Automerger Backend
167749b462 [automerge] Security fixes for PendingIntent related apis in LauncherApps 2p: e41e04bb8c
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/16778744

Bug: 209607104
Change-Id: Ie671aa785fd13e9389b2fec0a02318e7b5e05861
Merged-In: Id262b9a0de58d8834c85d925cf84bb44b8b99742
2022-02-09 03:12:23 +00:00
Pinyao Ting
e41e04bb8c Security fixes for PendingIntent related apis in LauncherApps
Allowing arbitrary activityOptions during the creation of PendingIntent
is a source of security vulnerability. This CL removes activityOptions
from the call-site.

Bug: 209607104
Test: manual
Change-Id: Id262b9a0de58d8834c85d925cf84bb44b8b99742
Merged-In: Id262b9a0de58d8834c85d925cf84bb44b8b99742
2022-02-09 03:12:10 +00:00
Ganesh Olekar
e38b4d59cf Merge "Validate pid can be trusted" into sc-dev am: 45312b8382 am: b14e524ffd
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/16461958

Change-Id: I55bd837724c745078138cdbd8afc4213768dcdb1
2022-02-05 04:31:21 +00:00
Ganesh Olekar
b14e524ffd Merge "Validate pid can be trusted" into sc-dev am: 45312b8382
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/16461958

Change-Id: I47da71211e30902d5f489f0dec109056b9503707
2022-02-05 04:14:22 +00:00
Ganesh Olekar
45312b8382 Merge "Validate pid can be trusted" into sc-dev 2022-02-05 03:56:26 +00:00
TreeHugger Robot
5150b2b56c Merge "Move CtsContentTestCases to group presubmit-large" into sc-dev am: a9a177e057 am: dd9121aaf6
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/16709491

Change-Id: I24513de281029178f2cdd9360ce87ed4d8eb210c
2022-01-27 18:47:46 +00:00
TreeHugger Robot
dd9121aaf6 Merge "Move CtsContentTestCases to group presubmit-large" into sc-dev am: a9a177e057
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/16709491

Change-Id: I23f8aac37dde7a9390d8ff478122b13eb99275a2
2022-01-27 18:29:12 +00:00
Jackal Guo
7172238add Move CtsContentTestCases to group presubmit-large
The test config takes longer than 900 seconds to run. Move it to a
dedicated group for running slow presubmit Test Mapping test.

Some more context is in the referenced bug, e.g, b/174495337
The group will work exactly the same as presubmit for now.

Bug: 174654670
Bug: 174495337
Fix: 215431363
Fix: 215549069
Test: treehugger
Change-Id: Id9769bbc625b42257af603d69098ae69c0fabb80
Merged-In: Id9769bbc625b42257af603d69098ae69c0fabb80
(cherry picked from commit ccc91c4fa9)
2022-01-24 23:45:31 +08:00
Ganesh Olekar
f29223746d Validate pid can be trusted
Bug: 200288596
Test: Manual
Test: atest android.security.cts.AttributionSourceTest#testPidCheck
Change-Id: I07f86ba220bedb1393f4d7ed23175e92d4576601
2022-01-13 00:30:12 +00:00
Naomi Musgrave
f5284f89be Merge "Introduce WindowManagerState field for sandboxing" into sc-v2-dev 2021-12-08 21:52:51 +00:00
Naomi Musgrave
5acb031f31 Introduce WindowManagerState field for sandboxing
New field indicates if ActivityRecord#providesMaxBounds has
calculated that sandboxing of max bounds to match app bounds
should be applied.

Test: manual
Bug: 193514437
Change-Id: I91587ce1e1ded7435038e2d1a7d038be57ff0f2f
2021-12-08 17:36:03 +00:00
tomnatan
303e76b80e Remove EnabledSince from OVERRIDE_MIN_ASPECT_RATIO_PORTRAIT_ONLY
We want this change to be enabled regardless of the app's target sdk
version.

Fix: 202842551
Test: N/A
Change-Id: Ia08afdeff276d132d6a5c619427017de3e1fba22
2021-12-06 16:42:36 +00:00
TreeHugger Robot
23039de620 Merge "Add feature flag for Android automotive OS templates host" into sc-v2-dev 2021-11-13 00:09:56 +00:00
tomnatan
36d7acbaaf Change OVERRIDE_MIN_ASPECT_RATIO_PORTRAIT_ONLY to be enabled since Sv2
Bug: 203647190
Test: N/A
Change-Id: Ie4c47d58c678082d37f8afb7cfde35e85e92ae77
2021-11-11 17:57:04 +00:00
Calvin Huang
17525b616d Add feature flag for Android automotive OS templates host
Bug: 204165454
Fix: 204165454
Test: Build gcar_emu_x86_64-userdebug then run \
android.app.cts.SystemFeaturesTest#testFeatureNamespaces

Change-Id: I77f817ae02e581e010cdd7eb3ee9e4d1c1bb8e37
2021-11-09 00:54:59 +00:00
tomnatan
5a676f6f15 Introduce an OVERRIDE_MIN_ASPECT_RATIO_PORTRAIT_ONLY change ID
This change ID will determine whether the OVERRIDE_MIN_ASPECT_RATIO override will be applied for portrait only activities (if enabled), and for all orientations (if disable).

Note that this change is enabled by default because it will need to be
enabled for most use cases.

Fix: 203647190
Test: atest WmTests:SizeCompatTests
Change-Id: I0fccbdc22ff387d33695fbf432cf96cd517de095
2021-11-08 16:47:49 +00:00
Chris Li
8e47bf7a9f Check app targetSdkVersion when check minWidth/Height for multi window
Bug: 197654537
Test: manually with app target S- with large min width/height
Change-Id: I2dd0902cb255cbe111ebab86dbf59be1a32e0cfc
2021-11-03 17:26:22 +08:00
Tom Natan
59f0a73009 Merge "Apply min aspect ratio override only for portrait only activities" into sc-v2-dev 2021-10-25 09:16:38 +00:00
tomnatan
4674792ad6 Apply min aspect ratio override only for portrait only activities
This only affects the min aspect ratio override, developers can still set min aspect ratio in the manifest regadless of whether the app is fixed to portrait. This change is needed since applying the override on activities that aren't fixed to portrait results in unintended behavior (see bug for more context).

Fix: 202842551
Test: atest WmTests:SizeCompatTests
Change-Id: Iebd8edf1fc43ee892aea78715c9b217950df5a3b
2021-10-20 22:58:13 +00:00
Makoto Onuki
f61a9d76e1 Fix javadoc on Context.startForegroundService
Bug: 203664384
Bug: 142968927
Test: treehugger
Change-Id: Ie3ba7d9fd5cda034f2ef8fab79630cfb15d6bb13
2021-10-20 21:45:06 +00:00
Varun Shah
991929b9fb Merge "Dismiss the suspend dialog if conditions have been modified." into sc-qpr1-dev am: 912d89451a
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/15853562

Change-Id: Id9539465fac375a4c2953aff19d6b3e5a880375a
2021-09-27 16:10:57 +00:00
TreeHugger Robot
875c6c5c13 Merge "Add warning for a known issue in a newly added API" into sc-qpr1-dev am: 697c7a819c
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/15583141

Change-Id: I9a73685647124772452cf16983ba48245ad70bdc
2021-09-25 02:12:46 +00:00
Varun Shah
912d89451a Merge "Dismiss the suspend dialog if conditions have been modified." into sc-qpr1-dev 2021-09-24 17:54:45 +00:00
TreeHugger Robot
697c7a819c Merge "Add warning for a known issue in a newly added API" into sc-qpr1-dev 2021-09-20 06:28:17 +00:00
Varun Shah
777d87f91b Dismiss the suspend dialog if conditions have been modified.
Whenever suspension conditions change, if there is a user-visible
suspension-related dialog, dismiss it to ensure the user is never
looking at stale information.

Bug: 169137795
Test: atest SuspendPackagesBroadcastTest#sendPackagesSuspendModifiedForUser
Test: manual (steps below)
-enable EBS, tap on suspended app to see dialog
-enable Focus mode, ensure dialog is dismissed
-tap on suspended app again to see relevent dialog,
 disable Focus mode, ensure dialog is dismissed
-tap on suspended app again to see relevant dialog,
 disable EBS, ensure dialog is dismissed correctly
-can permute enable/disable steps to further verify

Change-Id: Ib1650f910f7441498424ab4bc92185ce432ac405
(cherry picked from commit 25e73a8b9e)
2021-09-17 22:35:26 +00:00
Abhijeet Kaur
6fa7ca47ab Add warning for a known issue in a newly added API
checkUriPermissions is a new API added in Android S to check multiple
uri permissions via single API call.
However, checkUriPermissions is not working as intended for secondary
users. The root cause has been found and the fix is merged for later
releases.

Bug: 194700183
Test: atest --user-type secondary_user CtsScopedStorageDeviceOnlyTest:android.scopedstorage.cts.device.RedactUriDeviceTest#testSharedRedactedUri_openFileForRead
Change-Id: I72db7f0b4ddf97dce14880b6341799106d711c5c
2021-09-10 11:38:43 +00:00
Kevin Hufnagle
ef5e6685d7 docs: Fix links to narrative guides am: a1796499fe am: 522d5e32de
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/15738642

Change-Id: Ic51fe5f2fef7ba3a9e80b530a05ff2c6fa2a1e2b
2021-09-01 17:46:32 +00:00
Kevin Hufnagle
a1796499fe docs: Fix links to narrative guides
Cannot use both `{@docRoot}` and leading `/` when specifying URLs

Bug: 197663210
Change-Id: If6762b95a3d6991b4732684853d974a06da032bc
Test: make ds-docs
Exempt-from-Owner-Approval: Docs-only change
2021-09-01 15:43:02 +00:00
Rhed Jao
baf1f463f0 DO NOT MERGE Apply a maximum char count to the load label api
The system is overwhelmed by an enormous label string returned by
the load label api. This cl truncates the label string if it exceeds
the maximum safe length.

Bug: 67013844
Test: atest PackageManagerTest
Change-Id: Ia4d768cc93a47cfb8b6f7c4b6dc73abd801809bd
2021-08-31 06:05:27 +00:00
Winson Chung
1acaeb5b66 Add logging for app drag and drop
- Allow source to specify an instance id for the drag instance
  (we'll create one otherwise if not specified)
- Log start/drop/end as per go/dragdrop_splitscreen_logging

Bug: 191686897
Test: statsd_testdrive -terse 90
Change-Id: I215208777e3627859079abac90520b1772478c5e
2021-08-13 14:56:06 -07:00
Ray Essick
8100a960b9 Merge "Rename android.media.MediaTranscodeManager -> MediaTranscodingManager" into sc-dev am: 9d0e91c7b6 am: e1906a6dc8
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/15521772

Change-Id: I740ee3aba3ebfb1cff6e78c367cfc00e94659aca
2021-08-12 18:41:53 +00:00
Ray Essick
e1906a6dc8 Merge "Rename android.media.MediaTranscodeManager -> MediaTranscodingManager" into sc-dev am: 9d0e91c7b6
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/15521772

Change-Id: I02cccd46608894c908ccbcf8e1d0fe3bf4a5af6a
2021-08-12 18:27:55 +00:00
Ray Essick
1168d9d014 Rename android.media.MediaTranscodeManager -> MediaTranscodingManager
renamed to avoid conflict with existing copy in the R framework.jar.
The framework.jar copy was removed during S development

Bug: 195608856
Test: build
Test: cts-tradefed run cts -m CtsMediaTranscodingTestCases
Change-Id: I40ab066cd61be8d278f21cc788016f2edd6bb86e
2021-08-12 07:42:56 +00:00
Rhed Jao
97ff8e3eed Merge "DO NOT MERGE Apply a maximum char count to the load label api" into sc-dev 2021-08-09 10:48:39 +00:00
Nate Myren
dcd809e7cd Merge "Remove calling UID check from ContentProvider" into sc-dev am: c2c1c0341b
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/15463733

Change-Id: I44bc8d19e6877cbfbf5cf54b9cb9dbcd8db35cd9
2021-08-05 16:59:04 +00:00
Nate Myren
e758539f02 Remove calling UID check from ContentProvider
AttributionSource checks calling UID on unparcel (so the check is not
necessary), and some ContentProviders may clear calling identity.

Test: Manual
Fixes: 188755312
Change-Id: If629eea3ba8c1a57fd4b7aff0fec2c0acb5f69be
2021-08-04 20:25:21 +00:00
Rhed Jao
cd8558a253 DO NOT MERGE Apply a maximum char count to the load label api
The system is overwhelmed by an enormous label string returned by
the load label api. This cl truncates the label string if it exceeds
the maximum safe length.

Bug: 67013844
Test: atest PackageManagerTest
Change-Id: Ia4d768cc93a47cfb8b6f7c4b6dc73abd801809bd
Merged-in: Ia4d768cc93a47cfb8b6f7c4b6dc73abd801809bd
2021-08-03 04:15:21 +00:00
Alex Buynytskyy
dcbf05475e Merge "Check for invalid (negative) string pool pos." into sc-dev am: 59bad728e2
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/15390628

Change-Id: Ie08ac7e816b906c224e0ee4ac573286535fa1ec6
2021-07-29 19:03:50 +00:00
Tom Natan
3c3deaed91 Merge "Add an 'android.software.app_compat_overrides' feature" into sc-v2-dev 2021-07-27 07:32:45 +00:00
Alex Buynytskyy
b2a831ac3c Check for invalid (negative) string pool pos.
Parcel implementation would crash the system server otherwise.
Any exception is OK as it'll cause the cache to be invalidated.
Crash is not OK.

Bug: 194632313
Fixes: 194632313
Test: atest PackageParserCacheHelperTest
Change-Id: I58a4496b4646e172e6c3aee9ea17854a7ef55eaa
2021-07-26 18:51:02 +00:00
tomnatan
ee126f0404 Add an 'android.software.app_compat_overrides' feature
This feature will allow OEMs to opt-in specific devices/builds to per-app compat overrides.

Bug: 188500456
Test: N/A
Change-Id: I00108d163f752d23c380496ccac971cf0fcfe0f6
2021-07-19 14:00:26 +00:00
Jeff Sharkey
38ffbde17e Root UID can synthesize AttributionSource values.
We trust any incoming value from the system UID, so we should also
trust values coming from the root UID, which includes many shell
commands such as "svc".

Bug: 193659633
Test: atest BluetoothInstrumentationTests:com.android.bluetooth.btservice.AdapterServiceTest --rerun-until-failure 100
Change-Id: Ied07731345f08fc3c4df465a3773e35c8df7c59a
2021-07-14 14:35:17 -06:00
TreeHugger Robot
fee338118c Merge "Validate AttributionSource during unparceling." into sc-dev 2021-07-13 20:57:17 +00:00
Jeff Sharkey
4025c6e7ae Validate AttributionSource during unparceling.
The Bluetooth stack is just one example of an application that makes
self-calls through public APIs, which makes it very difficult to
unconditionally validate AttributionSource arguments.

(The AttributionSource is correctly defined the first time a remote
caller enters the Bluetooth stack, but we've found many cases where
Bluetooth stack calls back into itself without clearing the Binder
identity, causing validation chaos.)

This change is an attempt at gracefully solving this by performing
validation automatically as part of unparceling an AttributionSource
the first time it enters a process.  This strategy isn't perfect,
since transporting an instance inside a Bundle would risk
unparceling much later, possibly long after the calling UID
information has been discarded.  We're rationalizing that this risk
doesn't exist since AttributionSource was only added a few months
ago, and isn't being used in this way.

We still intend to circle back and provide a better strategy in a
future release for transporting AttributionSource across AIDL which
will handle the nuances of self-calls.

Bug: 188391719
Test: atest BluetoothInstrumentationTests
Change-Id: I10b198cfcd8f361e19d52f86deb7f10f05fec891
2021-07-13 12:34:14 -06:00