This reverts commit b71e398935.
Revert reason: System apps should now have uncompressed dex / library
files in their APKs and should be able to satisfy the minimum V2
signature requirement when targeting API level 30+.
Fixes: 215046612
Test: Manually verified V1 only signed APK targeting API level 30
on the system image failed to verify.
Change-Id: Ic53d2a3614e7dff4e4bfe18561d3dfbb665bbcb2
Allowing arbitrary activityOptions during the creation of PendingIntent
is a source of security vulnerability. This CL removes activityOptions
from the call-site.
Bug: 209607104
Test: manual
Change-Id: Id262b9a0de58d8834c85d925cf84bb44b8b99742
Merged-In: Id262b9a0de58d8834c85d925cf84bb44b8b99742
The test config takes longer than 900 seconds to run. Move it to a
dedicated group for running slow presubmit Test Mapping test.
Some more context is in the referenced bug, e.g, b/174495337
The group will work exactly the same as presubmit for now.
Bug: 174654670
Bug: 174495337
Fix: 215431363
Fix: 215549069
Test: treehugger
Change-Id: Id9769bbc625b42257af603d69098ae69c0fabb80
Merged-In: Id9769bbc625b42257af603d69098ae69c0fabb80
(cherry picked from commit ccc91c4fa9)
New field indicates if ActivityRecord#providesMaxBounds has
calculated that sandboxing of max bounds to match app bounds
should be applied.
Test: manual
Bug: 193514437
Change-Id: I91587ce1e1ded7435038e2d1a7d038be57ff0f2f
We want this change to be enabled regardless of the app's target sdk
version.
Fix: 202842551
Test: N/A
Change-Id: Ia08afdeff276d132d6a5c619427017de3e1fba22
This change ID will determine whether the OVERRIDE_MIN_ASPECT_RATIO override will be applied for portrait only activities (if enabled), and for all orientations (if disable).
Note that this change is enabled by default because it will need to be
enabled for most use cases.
Fix: 203647190
Test: atest WmTests:SizeCompatTests
Change-Id: I0fccbdc22ff387d33695fbf432cf96cd517de095
This only affects the min aspect ratio override, developers can still set min aspect ratio in the manifest regadless of whether the app is fixed to portrait. This change is needed since applying the override on activities that aren't fixed to portrait results in unintended behavior (see bug for more context).
Fix: 202842551
Test: atest WmTests:SizeCompatTests
Change-Id: Iebd8edf1fc43ee892aea78715c9b217950df5a3b
Whenever suspension conditions change, if there is a user-visible
suspension-related dialog, dismiss it to ensure the user is never
looking at stale information.
Bug: 169137795
Test: atest SuspendPackagesBroadcastTest#sendPackagesSuspendModifiedForUser
Test: manual (steps below)
-enable EBS, tap on suspended app to see dialog
-enable Focus mode, ensure dialog is dismissed
-tap on suspended app again to see relevent dialog,
disable Focus mode, ensure dialog is dismissed
-tap on suspended app again to see relevant dialog,
disable EBS, ensure dialog is dismissed correctly
-can permute enable/disable steps to further verify
Change-Id: Ib1650f910f7441498424ab4bc92185ce432ac405
(cherry picked from commit 25e73a8b9e)
checkUriPermissions is a new API added in Android S to check multiple
uri permissions via single API call.
However, checkUriPermissions is not working as intended for secondary
users. The root cause has been found and the fix is merged for later
releases.
Bug: 194700183
Test: atest --user-type secondary_user CtsScopedStorageDeviceOnlyTest:android.scopedstorage.cts.device.RedactUriDeviceTest#testSharedRedactedUri_openFileForRead
Change-Id: I72db7f0b4ddf97dce14880b6341799106d711c5c
Cannot use both `{@docRoot}` and leading `/` when specifying URLs
Bug: 197663210
Change-Id: If6762b95a3d6991b4732684853d974a06da032bc
Test: make ds-docs
Exempt-from-Owner-Approval: Docs-only change
The system is overwhelmed by an enormous label string returned by
the load label api. This cl truncates the label string if it exceeds
the maximum safe length.
Bug: 67013844
Test: atest PackageManagerTest
Change-Id: Ia4d768cc93a47cfb8b6f7c4b6dc73abd801809bd
- Allow source to specify an instance id for the drag instance
(we'll create one otherwise if not specified)
- Log start/drop/end as per go/dragdrop_splitscreen_logging
Bug: 191686897
Test: statsd_testdrive -terse 90
Change-Id: I215208777e3627859079abac90520b1772478c5e
renamed to avoid conflict with existing copy in the R framework.jar.
The framework.jar copy was removed during S development
Bug: 195608856
Test: build
Test: cts-tradefed run cts -m CtsMediaTranscodingTestCases
Change-Id: I40ab066cd61be8d278f21cc788016f2edd6bb86e
AttributionSource checks calling UID on unparcel (so the check is not
necessary), and some ContentProviders may clear calling identity.
Test: Manual
Fixes: 188755312
Change-Id: If629eea3ba8c1a57fd4b7aff0fec2c0acb5f69be
The system is overwhelmed by an enormous label string returned by
the load label api. This cl truncates the label string if it exceeds
the maximum safe length.
Bug: 67013844
Test: atest PackageManagerTest
Change-Id: Ia4d768cc93a47cfb8b6f7c4b6dc73abd801809bd
Merged-in: Ia4d768cc93a47cfb8b6f7c4b6dc73abd801809bd
Parcel implementation would crash the system server otherwise.
Any exception is OK as it'll cause the cache to be invalidated.
Crash is not OK.
Bug: 194632313
Fixes: 194632313
Test: atest PackageParserCacheHelperTest
Change-Id: I58a4496b4646e172e6c3aee9ea17854a7ef55eaa
This feature will allow OEMs to opt-in specific devices/builds to per-app compat overrides.
Bug: 188500456
Test: N/A
Change-Id: I00108d163f752d23c380496ccac971cf0fcfe0f6
We trust any incoming value from the system UID, so we should also
trust values coming from the root UID, which includes many shell
commands such as "svc".
Bug: 193659633
Test: atest BluetoothInstrumentationTests:com.android.bluetooth.btservice.AdapterServiceTest --rerun-until-failure 100
Change-Id: Ied07731345f08fc3c4df465a3773e35c8df7c59a
The Bluetooth stack is just one example of an application that makes
self-calls through public APIs, which makes it very difficult to
unconditionally validate AttributionSource arguments.
(The AttributionSource is correctly defined the first time a remote
caller enters the Bluetooth stack, but we've found many cases where
Bluetooth stack calls back into itself without clearing the Binder
identity, causing validation chaos.)
This change is an attempt at gracefully solving this by performing
validation automatically as part of unparceling an AttributionSource
the first time it enters a process. This strategy isn't perfect,
since transporting an instance inside a Bundle would risk
unparceling much later, possibly long after the calling UID
information has been discarded. We're rationalizing that this risk
doesn't exist since AttributionSource was only added a few months
ago, and isn't being used in this way.
We still intend to circle back and provide a better strategy in a
future release for transporting AttributionSource across AIDL which
will handle the nuances of self-calls.
Bug: 188391719
Test: atest BluetoothInstrumentationTests
Change-Id: I10b198cfcd8f361e19d52f86deb7f10f05fec891