Commit Graph

10651 Commits

Author SHA1 Message Date
Svetoslav Ganov
720add59c7 Merge "Prepare AttributionSource to expose to native" into sc-dev 2021-05-05 23:23:54 +00:00
Corina Grigoras
df2e7b8839 Merge "Revert "Restore file truncation where expected."" into sc-dev 2021-05-04 19:53:57 +00:00
Sahana Rao
8f28e57780 Merge "Change hasRequestRawExternalStorageAccess() to return integer" into sc-dev 2021-05-04 19:19:17 +00:00
Corina Grigoras
3fcb12e221 Revert "Restore file truncation where expected."
Revert "Restore file truncation where expected."

Revert submission 14173486-rwt

Reason for revert: b/186862362 - breaks ContentResolverWrapTest
Reverted Changes:
I41bc298af:Restore file truncation where expected.
Iacec49164:Restore file truncation where expected.

Bug: 186862362
Change-Id: I2afe5e2334cff60c4e7220267095042a60909185
2021-05-04 15:39:40 +00:00
Alex Buynytskyy
1e5cf8f1ff Customer API feedback.
Use two separate interfaces for flags and single value. This produces
correct API documentation.

Bug: 160605420
Test: atest PackageManagerShellCommandTest PackageManagerShellCommandIncrementalTest IncrementalServiceTest PackageManagerServiceTest ChecksumsTest
Change-Id: I9a7eaf86af558d8dcfd1636a4baf6a28e2ee79b1
2021-05-04 15:24:02 +00:00
Svet Ganov
4bf102ae26 Prepare AttributionSource to expose to native
Separate the internal state of AttributionSource from the
class to make it a simple AIDL we can translate automatically
to native - keeping Java and native parts in sync. This
would allow writing a thin native lib for checking attribution
source permissions which would be used to teach camera and
audio about attributions.

Deinfe an AIDL interface for passing around an attribution
source and opr performing permission checker oprations allowing
native and Java permission checks on attribution chains to be
handled. The Java side permission checker functions are in a dedicated
permisison checker service on top of which sits the PermissionChecker.
We expose similar PermissionChecker native APIs sitting on top
of the same remote interface. The nice thing is that we have
native and Java permisison checkers in sync sharing remoting
code and being close in shape.

For now the PermissionChecker in Java is divorced from the
PermissionManager but in T we will consider how to unify them,
either by an extension object on the PermmissionManager or
APIs on the PermissionManager, or another approach, and then
migrate clients off the PermissionChecker APIs.

Sync app ops were not tracked across multiple binder calls which
prevents moving the permission checks in the system server as
this adds one more hop. Now sync ops are propagated backed the
call stack and only the ops for the package are dispatched to
it and the rest are propagated back to the caller, recursively.

bug: 158792096

Test: atest CtsPermission5TestCases
      atest CtsAppOps2TestCases
      atest CtsPermissionTestCases
      atest CtsPermission2TestCases
      atest CtsPermission3TestCases
      atest CtsPermission4TestCases
      atest CtsPermission5TestCases

Change-Id: Ia5cbd2eb20a2da172a5960afdddd7e467f4bcb0d
2021-05-04 07:42:45 +00:00
Jackal Guo
e3e92e26c5 Merge "Migrate the usage of sCompatibilityModeEnabled" into sc-dev 2021-05-04 01:18:58 +00:00
Sahana Rao
d559e78253 Change hasRequestRawExternalStorageAccess() to return integer
Previously, hasRequestRawExternalStorageAccess would return null if the
app doesn't have requestRawExternalStorageAccess attribute in the
manifest. And, return true/false based on the value specified in
manifest.

Based on API review comments, changed the method to
getRequestRawExternalStorageAccess which returns
* RAW_EXTERNAL_STORAGE_ACCESS_DEFAULT if app didn't specify
requestRawExternalStorageAccess attribute in the manifest.
* RAW_EXTERNAL_STORAGE_ACCESS_REQUESTED if the app requested raw
external storage access.
* RAW_EXTERNAL_STORAGE_ACCESS_NOT_REQUESTED if the app requests to
disable raw external storage access

The API is not guarded with any system level API permissions, hence
changing the API to public API instead of system API. Also added
documentation to ensure apps don't misunderstand this API

Bug: 185484514
Test: atest packages/providers/MediaProvider
Change-Id: Ib7e41ab8ee38389bf44a360e4288d03e58ef44cf
2021-05-03 22:16:56 +01:00
Jackal Guo
0a98d27b04 Migrate the usage of sCompatibilityModeEnabled
PackageManagerService still set global compatibility mode to the
Deprecated PackageParser. We should migrate the usage to the new
ParingPackageUtils.

Also replacing the usage of PackageParser#generateApplicationInfo
in PackageManagerService since we no longer set the compatibility
mode to PackageParser.

Bug: 186592266
Bug: 174723245
Test: atest -p core/java/android/content/pm \
        core/java/com/android/internal/content \
	services/core/java/com/android/server/pm \
	services/tests/servicestests/src/com/android/server/pm
Change-Id: I3f377273e06bd4adbd9311dd3bdc584af0028c77
2021-05-03 14:30:52 +08:00
Hai Zhang
8f6290db77 Fix nullability of the group name parameter in queryPermissionsByGroup().
Change-Id: Id503da0fe4f16a92997634089fc052d58e78f9df
Fixes: 141452667
Test: presubmit
2021-04-30 21:43:05 +00:00
Florian Mayer
748c3a8040 Merge changes from topic "playprofileable" into sc-dev
* changes:
  Add packageInstaller to packages.list.
  Add profileable opt-out to packages.list.
2021-04-30 20:42:16 +00:00
Oli Lan
b74c7adf8e Merge "Call OnPrimaryClipChanged when classification status changes." into sc-dev 2021-04-30 17:20:04 +00:00
Winson Chiu
1b8610d9a9 Merge "Implement domain verification backup and restore" into sc-dev 2021-04-30 16:17:30 +00:00
Florian Mayer
6ea939f3bf Add profileable opt-out to packages.list.
We now have two notions of profileable:
 * profileable from shell: the user can profile the app using ADB-based
   tools (e.g. Android Studio or shell) . This is off unless the app
   opts in.
 * profileable from platform services: trusted platform services can,
   in accordance to the app installer's Terms Of Service profile the
   app. This is the default unless the app opts out. This is enforced
   by the profilers with information provided by the framework.

A new flag <profileable android:enable="false"/> can be used to opt out
of profiling in general. If this is not given, the app is considered
profilable by the platform, but the data will *not* be exposed to the
user via shell or adb. If profiles of the app should be given to the
user (e.g. for using Android Studio), <profileable
android:shell="true"/> can can still be used.

We write whether the app opted out or not to packages.list, to be
consumed by the profilers.

CTS-Coverage-Bug: 186720347

Test: m
Test: on userdebug: /data/system/packages.list for preinstalled, Play
      Store installed app and sideloaded app.
Test: on user: atest CtsPerfettoTestCases.
Bug: 170284829

Change-Id: I8d4bbedc043976fd11a95a511bd95a05c7ced7b9
2021-04-30 11:52:31 +00:00
Jay Sullivan
a26bf49927 Merge "Make REVOKE_WHEN_REQUESTED a SystemApi field" into sc-dev 2021-04-29 19:52:33 +00:00
Jeff Sharkey
02b741f883 Merge "Restore file truncation where expected." into sc-dev 2021-04-29 15:31:16 +00:00
TreeHugger Robot
51cac482f5 Merge "Update documentation for activity flags." into sc-dev 2021-04-29 08:48:15 +00:00
Jay Thomas Sullivan
7a7834230e Make REVOKE_WHEN_REQUESTED a SystemApi field
We have a reason to reference this flag from the base framework.  Mark
the flag as @SystemApi so it can be referenced.

Bug: 184962595
Test: atest AutoRevokeTest
Change-Id: Id9cb5d32b4afc9c49b8f97996fdfde2d4c239ca4
2021-04-28 20:33:48 -04:00
Todd Kennedy
229773b648 Merge "PackageParser OWNERS noparent" am: 26a5186ab1 am: 159886625a am: 2678377c4b
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1688565

Change-Id: Iacc17024700bdb7ac9c7d044288bd35b0dfb0054
2021-04-28 22:41:50 +00:00
Jeff Sharkey
fe738fbd0d Restore file truncation where expected.
Several years ago ParcelFileDescriptor.parseMode() was fixed to match
the behavior of fopen(), since developers expect consistent behavior
between managed and native code.  FileUtilsTest.testTranslateMode()
verifies that all these modes are correctly translated.

However, this unintentionally changed the behavior of
ContentResolver.openOutputStream(), which only sends the 'w' mode
to the remote process.  Developers expect this API to behave like
the FileOutputStream constructor, which always truncates the file
unless opened with the append mode.

Since some remote providers may not be prepared to handle the 't'
mode, this change carefully uses Os.ftruncate() to restore this
expected behavior in all cases.

For other APIs that return opened files, this strategy is applied
to restore the original behavior, but only when the target SDK of
the app is expecting this truncation to take place.  The reason for
this is that moving forward our goal should always enable
ContentInterface APIs to be a transparent conversation between apps
without attempting to alter the behavior.  Apps talking with older
providers can apply the Os.ftruncate() logic themselves, if
desired, once they target Android Q or higher.

Bug: 157888856, 180680924
Test: atest CtsContentTestCases:ContentResolverTest
Change-Id: Iacec49164c4ce3891db0270635e9f458dea7becd
2021-04-28 14:25:46 -06:00
TreeHugger Robot
9ccd991dac Merge "Move new changes to ParsingPackageUtils" into sc-dev 2021-04-28 07:36:36 +00:00
Jackal Guo
ed537a2acf Move new changes to ParsingPackageUtils
PackageParsers is marked as Deprecated so any new change should be
in the alternative. Moving the new activity launch mode definition
to ParsingPackageUtils.

Bug: 174723245
Test: atest IntentTests
Change-Id: I841f9d9d5d5555a78902cc3c126ed811dd2ccfc6
2021-04-28 09:30:14 +08:00
Winson Chiu
7edfb41f13 PackageParser OWNERS noparent
Remove other OWNERS from PackageParser.java to disallow future changes.
No new code should go into PackageParser.java except in extreme outlier
circumstances.

Change-Id: I2f663d2ae527beccbd47402492aa51d0cc6f6c13
2021-04-27 16:14:50 +00:00
Oli Lan
7461b08f9f Call OnPrimaryClipChanged when classification status changes.
To allow apps to know when text classification has been completed
on clipboard clips, ClipboardService will now call any
OnPrimaryClipChangedListeners when the classification status
of the primary clip changes.

This change is made as per API council suggestion.

This CL also ensures that the classification status is set on
any related profiles.

Bug: 185177537
Test: atest ClipboardManagerListenerTest
Test: atest ClipDescriptionTest
Test: atest atest ManagedProfileCrossProfileTest#testCrossProfileCopyPaste

Change-Id: I63c44a051d1e8029b6d56b9af5d1e506355a8466
2021-04-27 17:08:06 +01:00
Svetoslav Ganov
b9b8524f38 Merge "Revert "Prepare AttributionSource to expose to native"" into sc-dev 2021-04-27 02:12:30 +00:00
Adam Bookatz
33e17a9933 Revert "Prepare AttributionSource to expose to native"
Revert "Prepare AttributionSource to expose to native - native"

Revert submission 14225527-bug-158792096-04/16/21-1

Reason for revert: b/186467053
Reverted Changes:
I16740cc2d:Prepare AttributionSource to expose to native - na...
I4e050e78b:Prepare AttributionSource to expose to native

Change-Id: I83e4091231241c2211edf5745735f4ee993c6680
2021-04-26 23:20:46 +00:00
TreeHugger Robot
de1232b368 Merge "Add examples for EXTRA_PERMISSION_GROUP_NAME and EXTRA_ATTRIBUTION_TAGS" into sc-dev 2021-04-26 22:39:10 +00:00
Vadim Caen
8773bbe881 Merge "API to override the splashscreen theme" into sc-dev 2021-04-26 19:20:04 +00:00
Guojing Yuan
9e703b97e6 Add examples for EXTRA_PERMISSION_GROUP_NAME and EXTRA_ATTRIBUTION_TAGS
Fix: 184890546

Test: N/A
Change-Id: I900995fc9d78da87a17013aaa56c86453eef7fb8
2021-04-26 18:22:29 +00:00
Jeff Chang
911123acdd Update documentation for activity flags.
1. LAUNCHED_FROM_HISTORY, remove the out of date sentence.
2. NEW_DOCUMENT,add information about documentLaunchMode="never"
3. SINGLE_TOP, refer to launch modes for more information.

Bug: 123083574
Test: build
Change-Id: Id4da7be9993aaf1140c1c709a23ae7ed6d1718f5
2021-04-26 17:39:47 +08:00
Svet Ganov
7b7ea938f5 Prepare AttributionSource to expose to native
Separate the internal state of AttributionSource from the
class to make it a simple AIDL we can translate automatically
to native - keeping Java and native parts in sync. This
would allow writing a thin native lib for checking attribution
source permissions which would be used to teach camera and
audio about attributions.

Deinfe an AIDL interface for passing around an attribution
source and opr performing permission checker oprations allowing
native and Java permission checks on attribution chains to be
handled. The Java side permission checker functions are in a dedicated
permisison checker service on top of which sits the PermissionChecker.
We expose similar PermissionChecker native APIs sitting on top
of the same remote interface. The nice thing is that we have
native and Java permisison checkers in sync sharing remoting
code and being close in shape.

For now the PermissionChecker in Java is divorced from the
PermissionManager but in T we will consider how to unify them,
either by an extension object on the PermmissionManager or
APIs on the PermissionManager, or another approach, and then
migrate clients off the PermissionChecker APIs.

bug: 158792096

Test: atest CtsPermission5TestCases

Change-Id: I4e050e78b2361cbf524cc213802e0fef5b487f67
2021-04-25 19:00:30 +00:00
Vadim Caen
7817164210 API to override the splashscreen theme
By default, the SplashScreen uses the manifest theme.
This API allows user to change the theme used for the splashcreen for
the whole application.

Test: atest CtsWindowManagerDeviceTestCases:SplashscreenTests#testOverrideSplashscreenTheme
Bug: 185109768

Change-Id: I64e24910f6529a0ea2867b67d7e5963b971164b4
2021-04-23 10:53:59 +02:00
Varun Shah
62696eb689 Merge "Update OWNERS for Content* framework." am: 81f00f0198 am: 44b972b1f7 am: 49548d9faf
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1665999

Change-Id: I920018f2654eee3bcccc865c37fa44f0c265b995
2021-04-23 01:01:17 +00:00
Varun Shah
81f00f0198 Merge "Update OWNERS for Content* framework." 2021-04-22 23:59:17 +00:00
Hui Yu
9757955874 Merge "Temp allowlist bluetooth broadcast to start FGS for 10 seconds." into sc-dev 2021-04-22 23:41:30 +00:00
Evan Severson
171fe09c3c Merge "Remove package manager feature for toggles" into sc-dev 2021-04-22 16:38:36 +00:00
Jackal Guo
011805bf48 Merge "Apply package visibility to LauncherApps.Callback" into sc-dev 2021-04-22 08:54:29 +00:00
Hui Yu
8c23d658c7 Temp allowlist bluetooth broadcast to start FGS for 10 seconds.
Add an overloaded version of Context.sendBroadcastMultiplePermissions() that can
specify BroadcastOptions, it is called by com.android.bluetooth package.

Bug: 182816627
Test: atest AdapterServiceTest
Test: atest AvrcpControllerStateMachineTest
Test: atest BondStateMachineTest
Test: atest MapClientStateMachineTest
Test: atest RemoteDevicesTest

Change-Id: I8bb2d2ed98ece70ebbe9d3a1b549b966d690de4f
2021-04-21 16:48:04 -07:00
Alexander Dorokhine
5681f7c05f Merge "Update framework from jetpack." into sc-dev 2021-04-21 23:17:21 +00:00
Lucas Dupin
2a8031d889 Merge "Fix typos in documentation" into sc-dev 2021-04-21 22:17:42 +00:00
TreeHugger Robot
0b99af47c5 Merge "Addresses setRequireUserAction API feedback" into sc-dev 2021-04-21 22:11:23 +00:00
Pinyao Ting
a51996aa48 Merge "Replace oneway shortcut api with AndroidFuture" into sc-dev 2021-04-21 22:10:19 +00:00
Nate Myren
f7c1b2721e Merge "Change Permission Group methods to be callback, gate behind perm" into sc-dev 2021-04-21 21:01:05 +00:00
TreeHugger Robot
5e8994981d Merge "Refine setRenouncedPermissions() docs." into sc-dev 2021-04-21 20:49:59 +00:00
Alexander Dorokhine
ca083d96de Update framework from jetpack.
Included changes:
* b7122be: Update Builders to comply with API council requirements.
* 60b34cd: Changes to AppSearchSchema builders to comply with API requirements.
* c6f7eee: Support property paths in GenericDocument.
* cbee331: Update documentation to distinguish between AppSearchSession and GlobalSearchSession
* cbdd3b9: Rename ReportUsage#usageTimeMillis to #usageTimestampMillis.
* cc09d3a: Implement value indices in GenericDocument.
* e7faa03: Rename isIndexNestedProperties to shouldIndexNestedProperties.
* aaa6e81: Support @CurrentTimeMillisLong in export.
* 388c2b4: Rename GenericDocument's "uri" to "id" everywhere.

Bug: 184576792
Bug: 184576806
Bug: 184174844
Bug: 180481315
Bug: 179797058
Bug: 175146044
Bug: 184175636
Bug: 185492298
Test: Presubmit
Change-Id: I81e396c1d4770479654a3a69ea598e23de88ac9a
2021-04-21 11:23:09 -07:00
Jeff Sharkey
4047486998 Refine setRenouncedPermissions() docs.
Bug: 182423603
Test: none
Change-Id: I3c92a3150d3f22b4ed072a66d6b080e00a7ddabe
2021-04-21 12:08:48 -06:00
Pinyao Ting
480d532c96 Replace oneway shortcut api with AndroidFuture
Oneway calls to the system process can cause more trouble along those
lines than they solve.

Asynchronous incall pressure to the system process is worse than
synchronous incall pressure: it causes catastrophic failure modes
and is also much harder to diagnose when problems happen.
It's also much harder to guarantee transactionality when the caller
side is asynchronous.

Bug: 184878227
Test: atest ShortcutManagerTest1 ShortcutManagerTest2
ShortcutManagerTest3 ShortcutManagerTest4 ShortcutManagerTest5
ShortcutManagerTest6 ShortcutManagerTest7 ShortcutManagerTest8
ShortcutManagerTest9 ShortcutManagerTest10 ShortcutManagerTest11
Test: atest CtsShortcutManagerTestCases
Change-Id: I4ec6b188f079c018902bedf32198c04e9c45a60d

Change-Id: I854de382ee6bdc5ae32b6874b7d875dfe6c03c40
2021-04-21 11:02:28 -07:00
Ashwini Oruganti
991791446c Merge "Make ActivityInfo#attributionTags public." into sc-dev 2021-04-21 17:27:41 +00:00
Patrick Baumann
2491ee93bb Addresses setRequireUserAction API feedback
This change modifies the signature of SessionParams#setRequireUserAction
to take an int instead of a bool to match the return of
SessionInfo#getRequireUserAction.

Fixes: 184890429
Test: atest CtsSilentUpdateHostTestCases
Change-Id: I5868f9dadaf10bda1524446d3ad755cb69be73a5
2021-04-21 09:16:36 -07:00
Kholoud Mohamed
3846f7b552 Merge "Expose setInstallFlagAllowTest testAPI" into sc-dev 2021-04-21 11:07:50 +00:00