Commit Graph

383 Commits

Author SHA1 Message Date
Andrea Ambu
515bbcf6aa speech: Connect on model check/download trigger
Bug: 204189031
Test: atest
Change-Id: I9a3a0aa1b9a955dcb5f7fc365c2f0511a7bba7a0
2022-02-09 14:30:24 +00:00
Andrea Ambu
5230f95d5f Revert^2 "speech: Allow long speech sessions"
cd49383e17

Test: atest
Change-Id: I8b743e39172e307480d4f4ba6ec21769135c9da8
2022-02-08 16:11:04 +00:00
Shubham Dubey
cd49383e17 Revert "speech: Allow long speech sessions"
Revert "speech: Allow long speech sessions"

Revert submission 16691164-os-long-form

Reason for revert: Breaking OnDeviceRecognitionServiceTest
BUG:218303318

Reverted Changes:
I348fbcd70:speech: Allow long speech sessions
I62adfa7ac:speech: Allow long speech sessions

Change-Id: Ice4435288adb4472538c7426a4b68e9f75a2a2bc
2022-02-07 18:30:27 +00:00
Andrea Ambu
950a0f3e78 speech: Allow long speech sessions
See go/one-speech-long-form

Bug: 204189031
Cts-Coverage-Bug: 204189031
Test: atest
Change-Id: I62adfa7aca5e8df32253c141bd4dd7bc7e4fad3c
2022-02-04 11:15:50 +00:00
TreeHugger Robot
ce65b04d56 Merge "Revert "Revert "Migrate unsafe parcel APIs in framework-minus-apex""" 2022-01-20 11:33:39 +00:00
Bernardo Rufino
1a5cb387d6 Revert "Revert "Migrate unsafe parcel APIs in framework-minus-apex""
This reverts commit 331be9a643.

Reintroducing ag/16366278 since it seems unrelated to b/214053959 (more details on b/214053959#comment55).

Original commit message:

Migrate unsafe parcel APIs in framework-minus-apex

Migrate the following unsafe parcel APIs in framework-minus-apex:
* Parcel.readSerializable()
* Parcel.readArrayList()
* Parcel.readList()
* Parcel.readParcelable()
* Parcel.readParcelableList()
* Parcel.readSparseArray()

This CL was generated by applying lint fixes that infer the expected
type from the caller code and provide that as the type parameter
(ag/16365240).

A few observations:
* In some classes we couldn't migrate because the class also belonged to
another build module whose min SDK wasn't current (as is the case for
framework-minus-apex), hence I suppressed the lint check
(since I'll eventually submit the lint check to the tree).
* In some cases, I needed to do the cast in
https://stackoverflow.com/a/1080525/5765705 to make the compiler happy
since there isn't another way of providing a class of type
Class<MyClassWithGenerics<T>>.
* In the readSerializable() case, the new API also requires the class
loader, that was inferred to by InferredClass.class.getClassLoader().
* Note that automatic formatting and import rely on running hooked up
to the IDE, which wasn't the case here.

Bug: 195622897
Change-Id: I272432e6e082a973f7a50492ec35d79c2b577c93
Test: TH passes
2022-01-19 11:13:18 +00:00
Andrea Ambu
60aab5f1fa Merge "speech: Add api to check request is supported" 2022-01-19 09:34:02 +00:00
Andrea Ambu
d15616a547 speech: Add api to check request is supported
Bug: 204189031
CTS-Coverage-Bug: 208776893
Test: atest, new tests TBD
Change-Id: Id3d7df47f52efc31227edb577db44b9e4ca04265
2022-01-18 14:30:17 +00:00
Bernardo Rufino
331be9a643 Revert "Migrate unsafe parcel APIs in framework-minus-apex"
This reverts commit 90bb3709dc.

Reason for revert: b/214053959

Change-Id: Ic271bab1d3eaf677a5989dda9deb944ee2ad6850
2022-01-12 17:44:44 +00:00
Bernardo Rufino
90bb3709dc Migrate unsafe parcel APIs in framework-minus-apex
Migrate the following unsafe parcel APIs in framework-minus-apex:
* Parcel.readSerializable()
* Parcel.readArrayList()
* Parcel.readList()
* Parcel.readParcelable()
* Parcel.readParcelableList()
* Parcel.readSparseArray()

This CL was generated by applying lint fixes that infer the expected
type from the caller code and provide that as the type parameter
(ag/16365240).

A few observations:
* In some classes we couldn't migrate because the class also belonged to
another build module whose min SDK wasn't current (as is the case for
framework-minus-apex), hence I suppressed the lint check
(since I'll eventually submit the lint check to the tree).
* In some cases, I needed to do the cast in
https://stackoverflow.com/a/1080525/5765705 to make the compiler happy
since there isn't another way of providing a class of type
Class<MyClassWithGenerics<T>>.
* In the readSerializable() case, the new API also requires the class
loader, that was inferred to by InferredClass.class.getClassLoader().
* Note that automatic formatting and import rely on running hooked up
to the IDE, which wasn't the case here.

Bug: 195622897
Test: TH passes
Change-Id: I11a27b9bdab7959ee86e90aa1e1cbebd7aaf883c
2021-12-15 18:21:38 +00:00
Nate Myren
b1be18a806 Do not fail Recognition on MODE_IGNORED for preflight
Recognition will fail upon attempting to open the microphone, if it is
accessed.

Bug: 197465285
Test: manual
Change-Id: I83f1ae30295caf576eb7a6f0191313cb789f1d52
2021-09-10 13:36:22 -07:00
TreeHugger Robot
3a2373352f Merge "Only check downstream permissions in preflight in RecognitionService" into sc-dev 2021-07-15 17:44:56 +00:00
Nate Myren
861ee7a8b7 Only check downstream permissions in preflight in RecognitionService
Ensure that, in the preflight permission check, RecognitionService does
not check the service's own permissions. These will be checked if the
RecognitionService tries to access the mic

Fixes: 193111794
Test: manual
Change-Id: I172849f2e0368f9601dc298e6cf96d7a52219e5a
2021-07-12 16:17:17 -07:00
Andrea Ambu
cc204c7e2e Merge "speech: Add lenient SpeechRecognizer instantiation" into sc-dev 2021-07-08 17:40:10 +00:00
Andrea Ambu
6a630f8e00 speech: Add lenient SpeechRecognizer instantiation
This change allows to test on-device listening via a temporary
recognizer even in devices that do no support on device recognition.

It moves the failure from the static
SpeechRecognizer#createOnDeviceSpeechRecognizer to the instance #startListening.

fail-on-listening

Bug: 192586674
Test: atest CtsVoiceRecognitionTestCases with both config and no config
Change-Id: Id722f4e5167132b76b4fbd5ea0c2ef7d19f15909
2021-07-08 17:29:12 +00:00
Nate Myren
6c7dac39d5 Avoid creating Recognition Callback if preflight fails
Only create the callback (and call onCancel) if the preflight permission
check succeeds.

Bug: 190848702
Test: manual
Change-Id: Ie7155348213e86dea0a9080a9c4ed53144f91c6f
2021-07-02 13:32:34 -07:00
Nate Myren
bae80e0db8 Merge "Cancel RecognitionService if permission check fails" into sc-dev 2021-07-02 16:06:15 +00:00
Nate Myren
6978614aeb Cancel RecognitionService if permission check fails
This ensures that, when platform checks fail, the RecognitionService is
notified that it should cancel recognition

Fixes: 190848702
Test: manual
Change-Id: I5073728e544a47f386824ca0a034e149661d864a
2021-07-01 17:24:21 -07:00
Nate Myren
0b234cf922 Try to finish data delivery in onDestroy for RecognitionService
Test: manual
Fixes: 192275399
Change-Id: I56b2e59f80da3e4c6f59236637ec32c1aff1a50a
2021-07-01 23:21:51 +00:00
Nate Myren
050f400b3f Properly check for SDK before nullifying attribution tag
Also adds @SuppressLint to RecognitionService#createContext

Fixes: 190759697
Test: manual
Change-Id: I8ad14f93f86285127d5d2674b0f9a4963b03c933
2021-06-15 17:04:34 +00:00
TreeHugger Robot
c3467536bb Merge "speech: Update createSpeechRecognizer javadoc" into sc-dev 2021-06-14 14:13:23 +00:00
Svet Ganov
97bf4e0083 Don don't blame if attr ctx created
Test: manual

bug: 190657833

Change-Id: Id7c65999baa294a53765f5d17f77a7903611e85a
2021-06-12 04:49:50 +00:00
Andrea Ambu
df709e0d1b speech: Update createSpeechRecognizer javadoc
SpeechRecognizer#createSpeechRecognizer(Context, ComponentName) should
be called only with ComponentNames that are actually mapped in the
running environment.

This update documents how to check the ComponentName is acutally mapped
to RecognitionService.

Bug: 187176179
Test: n/a javadoc change only
Change-Id: Icbf1595f613d6f341b84879122e5eefce6c0fb4a
2021-06-07 14:05:48 +01:00
Svet Ganov
2eebf92965 Switch media fw permissions checks to AttributionSource
Attribution source is the abstraction to capture the data
flows for private data across apps. Checking permissions
for an attribution source does this for all apps in the
chain that would receive the data as well as the relevant
app ops are checked/noted/started as needed.

Teach speech recognition service about attribution
chains. If an implementation does nothing the OS
would enforce permisisons and do blame as always.
This apporach leads to double blaming and doesn't
support attribition chains where app calls into
the default recognizer which calls into the on
device recognizer (this nests recursively). If the
implementer takes advantage of the attribution chain
mechanims the permissions for the entire chain are
checked at mic access time and all apps are blamed
only once.

Fixed a few bugs around finishing ops for attribution
chains. Also ensured that any app death in a started
attribution chain would lead to finishing the op for
this app

bug: 158792096

Test: (added tests for speech reco)
      atest CtsMediaTestCases
      atest CtsPermissionTestCases
      atest CtsPermission2TestCases
      atest CtsPermission3TestCases
      atest CtsPermission4TestCases
      atest CtsPermission5TestCases
      atest CtsAppOpsTestCases
      atest CtsAppOps2TestCases

Merged-In: Ic92c7adc14bd2d135ac13b96f17a1b393dd562e4

Change-Id: Ic92c7adc14bd2d135ac13b96f17a1b393dd562e4
2021-06-01 23:43:29 +00:00
Andrea Ambu
feb478eae5 speech: TEST_MAPPING CtsVoiceRecognitionTestCases
ag/14530956 broke presubmit (b/188784537) because
CtsVoiceRecognitionTestCases did not run.

This makes them run for any change to core/java/android/speech

Bug: 188784537
Test: presubmitting this CL
Change-Id: I9e65abad8d242e5bb87fabc3523909bb14eed3c1
2021-05-21 11:47:07 +01:00
Andrea Ambu
40ef504bc8 speech: Add #isOnDeviceRecognitionAvailable
Bug: 188055926
Test: CtsVoiceRecognitionTestCases
Change-Id: I6ba1d083005782beedb28313077af041af2ae975
2021-05-18 19:04:46 +00:00
Nate Myren
dc0bd5b516 Add information to EXTRA_AUDIO_INJECT_SOURCE
indicate the data for injection should be a URI to an audio resource.

Fixes: 186411622
Test: none
Change-Id: I70b650c8fb8fa6de648c03df3c5464a570222fee
2021-04-26 11:47:37 -07:00
Sergey Volnov
04fa253482 Change attribution integration points for SpeechRecognizer.
I've deleted the extra attribution for now just to fix the bug asap, but
we need a long-term sync to make sure attribution works properly. For
both cases when the RS app decides to integrate with the new attribution
framework OR decides to ignore it.

Bug: 184963112
Test: atest CtsVoiceRecognitionTestCases
Change-Id: I20bd8174c1a188da6c5af55cdd3bebee8a638d2d
2021-04-23 16:16:39 +01:00
Nate Myren
e5a10560c8 Merge "Add EXTRA_AUDIO_INJECT_SOURCE to RecognizerIntent" into sc-dev 2021-04-21 15:30:07 +00:00
Nate Myren
1fde398f7f Add EXTRA_AUDIO_INJECT_SOURCE to RecognizerIntent
Add a constant to signify that the caller of a RecognitionService has
opened an audio stream for the service

Bug: 185936177
Test: build
Change-Id: Id8da84714fef547d2143457c2ad1c0b631e40741
2021-04-20 22:12:58 +00:00
Sergey Volnov
818ace5fe7 Add a comment mentioning that errors might be unbundled, to improve
backwards compatibility story.

Bug: 183427999
Test: N/A, comment change.
Change-Id: I1f583fe31c9edccada510f9a0ab2e333cc62df08
2021-04-19 16:57:10 +01:00
Sergey Volnov
8aeb16cd18 Introduce additional error codes for better language handling.
Additionally, address minor feedback from API council regarding errors
and documentation.

Test: N/A, adding constants
Bug: 176578753
Bug: 183427999
Change-Id: I46358373e8d562cb829ff44232252d26bb5acda4
2021-04-09 11:31:23 +01:00
Alex Agranovich
a95fc29ec6 Fix TextToSpeech system connection error handling
This CL fixes client listener notification upon engine binding error.
In addition fixes logs verbosity for errors caused by calls on dead client.

Bug: 183085464
Test: atest CtsSpeechTestCases
Change-Id: Ic67e97befd87f841430a53993ae5c79d81a0f6ba
2021-04-07 12:13:48 +00:00
Sergey Volnov
d9c6b16308 Merge "Add a comment to speech recognition service requiring clients targeting Android 11 to specify a <queries> tag." am: 8c6820048d am: 507ca766ac am: 9a4b4693f6
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1660358

Change-Id: I4fb577b783a1fcc7b4817fc6fba9d8c56e14e5b5
2021-04-01 11:35:08 +00:00
Sergey Volnov
8c6820048d Merge "Add a comment to speech recognition service requiring clients targeting Android 11 to specify a <queries> tag." 2021-04-01 09:26:27 +00:00
Sergey Volnov
f16e2b1d07 Add a comment to speech recognition service requiring clients targeting
Android 11 to specify a <queries> tag.

Bug: 173748514
Test: N/A
Change-Id: If70dde1bff5d79e258e3759a1f9027d51de6b441
2021-03-31 21:20:21 +01:00
Treehugger Robot
75fd2f1785 Merge "Set up owners for SpeechRecognition packages in frameworks/base." am: 320c3cff41 am: b80973e8d9 am: f614e62c52
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1566278

Change-Id: I52e99051d1ad161d42a128227474e9f052308794
2021-03-31 18:02:23 +00:00
Svet Ganov
8d2ed50604 Runtime permission attribution improvements
When an app is proxying access to runtime permission protected
data it needs to check whether the calling app has a permission
to the data it is about to proxy which leaves a trace in app ops
that the requesting app perofmed a data access. However, then the
app doing the work needs to get the protected data itself from the
OS which access gets attributed only to itself. As a result there
are two data accesses in app ops where only the first one is a
proxy one that app A got access to Foo through app B - that is the
one we want to show in the permission tracking UIs - and one
for the data access - that is the one we would want to blame on
the calling app, and in fact, these two accesses should be one -
that app A accessed Foo though B. This limitation requires fragile
one off workarounds where both accesses use the same attribution
tag and sys UI has hardcoded rules to dedupe. Since this is not
documented we cannot expect that the ecosystem would reliably
do this workaround in apps that that the workaround in the OS
would be respected by every OEM.

This change adds a mechaism to resolve this issue. It allows for
an app to create an attribution context for another app and then
any private data access thorugh this context would result in a
single app op blame that A accessed Foo though B, i.e. we no longer
have double accounting. Also this can be nested through apps, e.g.
app A asks app B which asks app C for contacts. In this case app
B creates an attribution context for app A and calls into app C
which creates an attribution context for app B. When app C gets
contacts the entire attribution chain would get a porper, single
blame: that C accessed the data, that B got the data from C, and
that A got the data form B. Furthermore, this mechanism ensures
that apps cannot forget to check permissions for the caller
before proxying private data. In our example B and C don't need
to check the permisisons for A and B, respectively, since the
permisisons for the entire attribution chain are checked before
data delivery. Attribution chains are not forgeable preventing
a bad actor to create an arbitrary one - each attribution is
created by the app it refers to and points to a chain of
attributions created by their corresponding apps.

This change also fixes a bug where all content provider accesses
were double counted in app ops due to double noting. While at
this it also fixes that apps can now access their own last ops.
There was a bug where one could not pass null getting the attributed
ops from a historical package ops while this is a valid use case
since if there is no attribution everything is mapped to the null
tag. There were some app op APIs not being piped thorough the app
ops delegate and by extension through the app ops policy. Also
now that we have nice way to express the permission chain in a
call we no longer need the special casing in activity manager to
handle content provider accesses through the OS. Fixed a bug
where we don't properly handle the android.os.shell calls with
an invlaid tag which was failing while the shell can do any tag.

Finally, to ensure the mechanims is validated and works end-to-end
we are adding support for a voice recognizer to blame the client
app for the mic access. The recognition service can create a blaming
context when opening the mic and if the mic is open, which would
do all permission checks, we would not do so again. Since changes
to PermissionChercker for handling attribution sources were made
the CL also hooks up renounced permissoins in the request permission
flow and in the permission checks.

bug:158792096
bug:180647319

Test:atest CtsPermissionsTestCases
     atest CtsPermissions2TestCases
     atest CtsPermissions3TestCases
     atest CtsPermissions4TestCases
     atest CtsPermissions5TestCases
     atest CtsAppOpsTestCases
     atest CtsAppOps2TestCases

Change-Id: Ib04585515d3dc3956966005ae9d94955b2f3ee08
2021-03-29 16:49:33 +00:00
Sergey Volnov
f6fa43b753 Add utility for to allow to overwrite on-device speech recognition
temporarily.

I had to define a new permission in order for it to work (which makes
sense, since we only want to allow shell to overwrite the temp service).

Test: adding CTS
Bug: 177915986
Change-Id: I3ac8f2366595f502b42c9ad93b331d0c0039d16c
2021-03-10 00:38:53 +00:00
Nadav Bar
e8d124dc20 Merge "Add a system TextToSpeech implementation that initiates the connection through the system server." into sc-dev 2021-02-20 06:21:18 +00:00
Alex Agranovich
50c987fbb8 Add a system TextToSpeech implementation that initiates the connection through the system server.
This change includes the new System Service that allows the supervised binding to the TextToSpeech service provider.
    It proxies the binding process from the client instead of the direct client -> texttospeech connection.

Bug: 178112052
Test: atest CtsSpeechTestCases
Test: forest apct/device_boot_health_check
Change-Id: I0709e71460fa01ab025c92753a20bce38f562845
2021-02-18 14:31:36 +02:00
Greg Kaiser
c09430c189 Revert "Add a system TextToSpeech implementation that initiates ..."
Revert "Add CTS tests for TextToSpeech connection related functi..."

Revert submission 13547465-ttsproxy

Reason for revert: Setup wizard crashes due to "Service not registered: android.speech.tts.TextToSpeech$SystemConnection"
Reverted Changes:
Id4059e460:Add CTS tests for TextToSpeech connection related ...
Ie17800bae:Add a system TextToSpeech implementation that init...

Bug: 180519958
Change-Id: Ie43c485bd4d0f76f8bb0a1dc77d6d85d46ff8377
Test: Locally reverted this change and no longer see the exception in SUW we saw before.
2021-02-18 00:29:01 +00:00
Sergey Volnov
bf2e94deab Redirect all speech recognition traffic through system server.
Test: atest CtsVoiceRecognitionTestCases
Bug: 176578753
Change-Id: I5783257b76fa21c2a6f1d2e589fb843b93753350
2021-02-17 15:12:12 +00:00
Alex Agranovich
290d1119ee Add a system TextToSpeech implementation that initiates the connection through the system server.
This change includes the new System Service that allows the supervised binding to the TextToSpeech service provider. It proxies the binding process from the client instead of the direct client -> texttospeech connection.

Bug: 178112052
Test: atest CtsSpeechTestCases
Change-Id: Ie17800bae7a84bfd6e63633f5c914ddbe2c29e9d
2021-02-08 17:25:40 +02:00
Sergey Volnov
c06c6f3686 Set up owners for SpeechRecognition packages in frameworks/base.
Bug: 176578753
Test: config change
Change-Id: I4dc2241d166bbdb4d0eb7d903a6bc9f0da78f612
2021-01-29 14:24:34 +00:00
Eugenio Marchiori
c3c0a1ee7e Add System speech recognition service.
Bug: 176578753
Test: local demo, CTS will follow
Change-Id: Ia7766c506bf43a5db5b9719363da66aab263fd8d
2021-01-27 09:40:27 +00:00
Xin Li
d31ee38811 Merge rvc-qpr-dev-plus-aosp-without-vendor@6881855
Bug: 172690556
Merged-In: I78222391b83a4add8e964340ec08bb8a1306e1c6
Change-Id: I28bbf40820674675ccf765c912aa8140d3f74ab2
2020-12-02 00:38:58 -08:00
Mathew Inwood
5d123b6775 Add maxTargetSdk restriction to unused APIs.
These are APIs that have @UnsupportedAppUsage but for which we don't
have any evidence of them currently being used, so should be safe to
remove from the unsupported list.

Bug: 170729553
Test: Treehugger
Merged-In: I626caf7c1fe46c5ab1f39c2895b42a34319f771a
Change-Id: I54e5ecd11e76ca1de3c5893e3a98b0108e735413
2020-11-04 09:45:53 +00:00
Mathew Inwood
8e742f928e Add maxTargetSdk restriction to unused APIs.
These are APIs that have @UnsupportedAppUsage but for which we don't
have any evidence of them currently being used, so should be safe to
remove from the unsupported list.

This is a resubmit of ag/12929664 with some APIs excluded that caused
test failures; see bugs 171886397, 171888296, 171864568.

APIs excluded:
Landroid/bluetooth/le/ScanRecord;->parseFromBytes([B)Landroid/bluetooth/le/ScanRecord;
Landroid/os/Process;->myPpid()I
Landroid/os/SharedMemory;->getFd()I
Landroid/hardware/input/InputManager;->INJECT_INPUT_EVENT_MODE_WAIT_FOR_FINISH:I

Bug: 170729553
Test: Treehugger
Change-Id: I8285daa8530260251ecad6f3f38f98e263629ca7
2020-10-29 11:51:12 +00:00
Hongwei Wang
050275cd83 Revert "Add maxTargetSdk restriction to unused APIs."
This reverts commit 72f07d6a8a.

Reason for revert: Droidcop-triggered revert due to breakage https://android-build.googleplex.com/builds/quarterdeck?testMethod=testAppZygotePreload&testClass=android.app.cts.ServiceTest&atpConfigName=suite%2Ftest-mapping-presubmit-retry_cloud-tf&testModule=CtsAppTestCases&fkbb=6936597&lkbb=6936969&lkgb=6936551&testResults=true&branch=git_master&target=cf_x86_phone-userdebug>, bug b/171886397

Bug: 171886397
Change-Id: Ibe0f0430a3451477c1ee8ef56a596e91ea1e7672
2020-10-28 20:16:22 +00:00