Commit Graph

438 Commits

Author SHA1 Message Date
Treehugger Robot
5bdd02628d Merge "Keystore 2.0: Android Protected Confirmation" am: 30841f177c am: 3443d2b671 am: ca6272cf1e
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1508897

MUST ONLY BE SUBMITTED BY AUTOMERGER

Change-Id: I9bb924273fb712efb270e8afbe194604ce1f90ce
2021-01-06 01:52:47 +00:00
Janis Danisevskis
976991edea Merge "Add owners for Protected Confirmation implementation." am: 9bb6231bd2 am: 2fb83e12c7 am: 0d2b2dd166
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1532298

MUST ONLY BE SUBMITTED BY AUTOMERGER

Change-Id: I5cdda7f97b5bcaf111acba6143ae24ab0bf7e107
2020-12-16 23:06:28 +00:00
Janis Danisevskis
81d75b4c52 Keystore 2.0: Android Protected Confirmation
Bug: 160930927
Test: CtsVerifier
Change-Id: I9cc325eafbee2aa4257a3ccbe525091a1cae806d
2020-12-16 10:47:56 -08:00
Janis Danisevskis
fb68656a99 Add owners for Protected Confirmation implementation.
Test: N/A
Change-Id: Ib10884acd284a243d2898fc5a1eeedca5e8c4551
2020-12-16 09:57:11 -08:00
Treehugger Robot
30f8a371b7 Merge "Revert "Revert "Keystore 2.0 SPI: Move keymint spec to security ..."" am: dd8891acbe am: 4ac4916c8d am: cf7203f5d3
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1525189

MUST ONLY BE SUBMITTED BY AUTOMERGER

Change-Id: I024a2f38dfd2432ae77d6a032c27fc8389cf62dc
2020-12-12 01:07:05 +00:00
Shawn Willden
f5a002c222 Revert "Revert "Keystore 2.0 SPI: Move keymint spec to security ..."
Revert "Revert "Keystore 2.0: Move keymint spec to security name..."

Revert "Revert "Keystore 2.0: Move keymint spec to security name..."

Revert^2 "Remove references to keymint1"

34536a352803a08776cc4f373d93a94e1fcbf98e

Bug: 175345910
Bug: 171429297
Change-Id: I694e677e4e20419440f12cb7981f0c0c4ca29e08
2020-12-11 20:36:10 +00:00
Orion Hodson
525a22a777 Merge "Revert "Keystore 2.0 SPI: Move keymint spec to security namespace."" am: bc641a41d8 am: 9e21ecbcb4 am: 1de159412b
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1525805

MUST ONLY BE SUBMITTED BY AUTOMERGER

Change-Id: Ie45400513bc12278a68c8af1b5a12ba754f048c5
2020-12-11 14:02:26 +00:00
Shawn Willden
577c22a23e Merge "Keystore 2.0 SPI: Move keymint spec to security namespace." am: f0c3865132 am: 50df7a46cf am: ce6b4c47e2
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1521879

MUST ONLY BE SUBMITTED BY AUTOMERGER

Change-Id: I085ddcc310b6189ae313959c9a0f349404faa178
2020-12-11 11:01:03 +00:00
Orion Hodson
6acd9c63e7 Revert "Keystore 2.0 SPI: Move keymint spec to security namespace."
Revert "Keystore 2.0: Move keymint spec to security namespace."

Revert "Keystore 2.0: Move keymint spec to security namespace."

Revert "Move keymint to android.hardware.security."

Revert "Configure CF to start KeyMint service by default."

Revert "Move keymint to android.hardware.security."

Revert "Move keymint to android.hardware.security."

Revert submission 1522123-move_keymint

Reason for revert: Build breakage
Bug: 175345910
Bug: 171429297
Reverted Changes:
Ief0e9884a:Keystore 2.0: Move keymint spec to security namesp...
Idb54e8846:Keystore 2.0: Move keymint spec to security namesp...
I9f70db0e4:Remove references to keymint1
I2b4ce3349:Keystore 2.0 SPI: Move keymint spec to security na...
I2498073aa:Move keymint to android.hardware.security.
I098711e7d:Move keymint to android.hardware.security.
I3ec8d70fe:Configure CF to start KeyMint service by default.
Icbb373c50:Move keymint to android.hardware.security.
I86bccf40e:Move keymint to android.hardware.security.

Change-Id: Icd279f358db2387bf2bf232b0548762fab51e67d
2020-12-11 10:45:43 +00:00
Janis Danisevskis
8954dfa092 Keystore 2.0 SPI: Move keymint spec to security namespace.
Test: N/A
Change-Id: I2b4ce3349baf29eb67a31f0c436b964d69d70b02
2020-12-09 13:53:32 -08:00
Jeff Sharkey
0ab7007631 resolve merge conflicts of 358f0d4fc8 to master
Bug: 174932174
Test: I solemnly swear I tested this conflict resolution.
Exempt-From-Owner-Approval: refactoring with team leads buy-in
Change-Id: I9262a08ffc1ccede8e519d0eed90ed2bfcf0232c
2020-12-08 11:01:05 -07:00
Jeff Sharkey
fab0ab3c9c Improve OWNERS coverage across frameworks/base/.
As general background, OWNERS files expedite code reviews by helping
code authors quickly find relevant reviewers, and they also ensure
that stakeholders are involved in code changes in their areas.

Some teams under frameworks/base/ have been using OWNERS files
successfully for many years, and we're ready to expand them to cover
more areas.  Here's the historical coverage statistics for the last
two years of changes before these new OWNERS changes land:

-- 56% of changes are fully covered by OWNERS
-- 17% of changes are partially covered by OWNERS
-- 25% of changes have no OWNERS coverage

Working closely with team leads, we've now identified clear OWNERS on
a per-package basis, and we're using "include" directives whenever
possible to to simplify future maintenance.  With this extensive
effort, we've now improved our coverage as follows:

-- 98% of changes are fully covered by OWNERS
-- 1% of changes are partially covered by OWNERS
-- 1% of changes have no OWNERS coverage

This specific change is automatically generated by a script from
detailed ownership information confirmed by team leads.

Bug: 174932174
Test: manual
Exempt-From-Owner-Approval: refactoring with team leads buy-in
Merged-In: I9789c97c1de8e5d962b48c29c57d82fe83729eba
Change-Id: I9789c97c1de8e5d962b48c29c57d82fe83729eba
2020-12-08 08:36:27 -07:00
Treehugger Robot
84839730c1 Merge "Revert "Revert "Keystore SPI: Initialize KeymasterDefs contants with AIDL generated enums""" am: c565f2bd57 am: 563c167f73 am: f1d47c7b00
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1512902

Change-Id: Iaae86ff91e2faee4340a37ec34fd76798247f8d4
2020-12-01 02:42:11 +00:00
Janis Danisevskis
96a0716a8a Revert "Revert "Keystore SPI: Initialize KeymasterDefs contants with AIDL generated enums""
This reverts commit efec091bcb.

Reason for revert: aosp/1513473 fixed the underlying issue That make this revert necessary.

Change-Id: Ic99a6d080b4b1140924cb89d44b1f650f283a28d
2020-11-30 16:30:02 +00:00
Louis Chang
4429864202 Merge "Revert "Keystore SPI: Initialize KeymasterDefs contants with AIDL generated enums"" am: 9233cb2be8 am: 2399198f26 am: bb1d23d071
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1512878

Change-Id: Ic0aaef95b8a9dd09161ed346982c8b3947418f96
2020-11-30 15:58:43 +00:00
Louis Chang
efec091bcb Revert "Keystore SPI: Initialize KeymasterDefs contants with AIDL generated enums"
This reverts commit 2a66fc6144.

Reason for revert: b/174445211

Change-Id: I286327d8db19d50d3dd9602a2d0bd368d331c0c4
2020-11-30 07:36:55 +00:00
Janis Danisevskis
95290b2266 Merge "Keystore SPI: Initialize KeymasterDefs contants with AIDL generated enums" am: 136fcd2a56 am: 1a59bf1dc2 am: 6dd168558e
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1475677

Change-Id: I919b08cd59919c32bc6f94d1c61c25c9a7931f57
2020-11-27 21:58:40 +00:00
Janis Danisevskis
2a66fc6144 Keystore SPI: Initialize KeymasterDefs contants with AIDL generated enums
Test: None
Change-Id: Ic6b776a3bc0b7eea7a84ef9ec54258eb0a160864
2020-11-23 22:02:45 -08:00
Bram Bonné
420816da1f Merge "Adds two missing Keymaster definitions." am: 6d7e4c43d6 am: faefa76349 am: d914fc3925
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1505232

Change-Id: I4a8d625c0af0229daf0daa65f81159a4f56a0245
2020-11-23 14:42:51 +00:00
Bram Bonné
b60861b281 Adds two missing Keymaster definitions.
Adds KM_TAG_BOOT_PATCHLEVEL and KM_TAG_VENDOR_PATCHLEVEL.

Bug: 173681969
Test: atest KeyAttestationTest
Change-Id: I4e94376241b37fd57c183e7865ae99a4770658c9
2020-11-19 10:15:02 +01:00
Mathew Inwood
f8abe13db4 Merge "Add maxTargetSdk restriction to unused APIs." 2020-11-09 14:41:20 +00:00
Treehugger Robot
9ad8254a96 Merge changes Ib3c9affb,I1dbe3d02,I88681f21 am: 1f65c6b62e am: f2abffe107 am: df8410e677 am: 15e1f8f5eb
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1451015

Change-Id: Ia0c6195e820a04d5ac0a330a0813d308d0eb0c08
2020-11-06 02:32:52 +00:00
Treehugger Robot
15e1f8f5eb Merge changes Ib3c9affb,I1dbe3d02,I88681f21 am: 1f65c6b62e am: f2abffe107 am: df8410e677
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1451015

Change-Id: I654b14fb0386d5bea6d22e37a394b00c1f66a87c
2020-11-06 02:14:41 +00:00
Janis Danisevskis
d2c944bc4d Keystore SPI: Add SecurityLevelEnum to KeyProperties
This patch adds the SecurityLevelEnum to KeyProperties. This enum can be
used by the public API surface to express levels of enforcements of key
properties. And to select a designated residence for a newly generated
or imported key.

The values UNKNOWN and UNKNOWN_SECURE are used to convey to older target
APIs API levels that have not been defined when they where published.

Test: None
Change-Id: I88681f21b8a8ea9a383d32ba99f3ab7d7c8909c3
2020-11-05 13:11:12 -08:00
Mathew Inwood
5d123b6775 Add maxTargetSdk restriction to unused APIs.
These are APIs that have @UnsupportedAppUsage but for which we don't
have any evidence of them currently being used, so should be safe to
remove from the unsupported list.

Bug: 170729553
Test: Treehugger
Merged-In: I626caf7c1fe46c5ab1f39c2895b42a34319f771a
Change-Id: I54e5ecd11e76ca1de3c5893e3a98b0108e735413
2020-11-04 09:45:53 +00:00
Janis Danisevskis
a18b2db113 Merge changes I7c17ab51,I5bd4acb4,I93270f00 am: 18bbac10c1 am: 68acc834d4 am: c04b6004a3 am: 9060b67f0f
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1470088

Change-Id: Iaca7385d86f44b1c1cb8625340c8e5a6033d10c7
2020-11-02 21:28:34 +00:00
Janis Danisevskis
9060b67f0f Merge changes I7c17ab51,I5bd4acb4,I93270f00 am: 18bbac10c1 am: 68acc834d4 am: c04b6004a3
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1470088

Change-Id: I59184b7d4a01b1478599b53b6f7dd1fc3b3c5465
2020-11-02 21:14:04 +00:00
Mathew Inwood
5f0edaaaf5 Add maxTargetSdk restriction to unused APIs.
These are APIs that have @UnsupportedAppUsage but for which we don't
have any evidence of them currently being used, so should be safe to
remove from the unsupported list.

Bug: 170729553
Test: Treehugger
Merged-In: I8285daa8530260251ecad6f3f38f98e263629ca7
Change-Id: I626caf7c1fe46c5ab1f39c2895b42a34319f771a
2020-11-02 10:30:09 +00:00
Mathew Inwood
8e742f928e Add maxTargetSdk restriction to unused APIs.
These are APIs that have @UnsupportedAppUsage but for which we don't
have any evidence of them currently being used, so should be safe to
remove from the unsupported list.

This is a resubmit of ag/12929664 with some APIs excluded that caused
test failures; see bugs 171886397, 171888296, 171864568.

APIs excluded:
Landroid/bluetooth/le/ScanRecord;->parseFromBytes([B)Landroid/bluetooth/le/ScanRecord;
Landroid/os/Process;->myPpid()I
Landroid/os/SharedMemory;->getFd()I
Landroid/hardware/input/InputManager;->INJECT_INPUT_EVENT_MODE_WAIT_FOR_FINISH:I

Bug: 170729553
Test: Treehugger
Change-Id: I8285daa8530260251ecad6f3f38f98e263629ca7
2020-10-29 11:51:12 +00:00
Hongwei Wang
286c33a5c5 Merge "Revert "Add maxTargetSdk restriction to unused APIs."" 2020-10-28 23:58:21 +00:00
Hongwei Wang
050275cd83 Revert "Add maxTargetSdk restriction to unused APIs."
This reverts commit 72f07d6a8a.

Reason for revert: Droidcop-triggered revert due to breakage https://android-build.googleplex.com/builds/quarterdeck?testMethod=testAppZygotePreload&testClass=android.app.cts.ServiceTest&atpConfigName=suite%2Ftest-mapping-presubmit-retry_cloud-tf&testModule=CtsAppTestCases&fkbb=6936597&lkbb=6936969&lkgb=6936551&testResults=true&branch=git_master&target=cf_x86_phone-userdebug>, bug b/171886397

Bug: 171886397
Change-Id: Ibe0f0430a3451477c1ee8ef56a596e91ea1e7672
2020-10-28 20:16:22 +00:00
Dmitry Dementyev
c3addd34cd Merge "Include cause in exceptions thrown by RecoveryController." 2020-10-28 18:29:28 +00:00
Dmitry Dementyev
2b9438ec1f Include cause in exceptions thrown by RecoveryController.
Test: none
Bug: 168995299
Change-Id: I59d5b0eecfc634d2a86f400dae14bc9a367bbeb9
2020-10-27 14:55:04 -07:00
Janis Danisevskis
8232c585ec Add KM_ERROR_HARDWARE_TYPE_UNAVAILABLE to KeymasterDefs
This flag was missing from KeymasterDefs.

Test: None
Change-Id: I7c17ab513df695f510ec1ba41b7c1b059902b040
2020-10-27 12:09:38 -07:00
Mathew Inwood
72f07d6a8a Add maxTargetSdk restriction to unused APIs.
These are APIs that have @UnsupportedAppUsage but for which we don't
have any evidence of them currently being used, so should be safe to
remove from the unsupported list.

Bug: 170729553
Test: Treehugger
Change-Id: I4c8fd0006f950de9955242e93968fb0996ceb372
2020-10-27 15:46:07 +00:00
Roman Kalukiewicz
24403f7ef2 Add @Nullable annotation to the parameter of Object.equals() methods.
Those annotations could be inferred by some tools (like Kotlin), but the
https://checkerframework.org/ doesn't check inherited annotations
complaining about all equals() invocations that get nullable argument.

The change was generated by running

find . -name \*.java | xargs sed -i 's/public boolean equals(Object /public boolean equals(@Nullable Object /'

in the frameworks/base directory and by automatically adding and
formatting required imports if needed. No manual edits.

Bug: 170883422
Test: Annotation change only. Should have not impact.
Exempt-From-Owner-Approval: Mechanical change not specific to any component.
Change-Id: I5eedb571c9d78862115dfdc5dae1cf2a35343580
2020-10-15 10:48:01 -07:00
Xin Li
628590d7ec Merge Android R (rvc-dev-plus-aosp-without-vendor@6692709)
Bug: 166295507
Merged-In: I3d92a6de21a938f6b352ec26dc23420c0fe02b27
Change-Id: Ifdb80563ef042738778ebb8a7581a97c4e3d96e2
2020-08-31 21:21:38 -07:00
Treehugger Robot
cb45db0650 Merge "Update comment to use inclusive language" am: 3b7913607b am: 03e5841ec1
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1373954

Change-Id: Ia7b2e14787dd716af3150fa24a8accff05a8ebc8
2020-07-29 00:27:06 +00:00
Joel Galenson
4143080a6d Update comment to use inclusive language
See https://source.android.com/setup/contribute/respectful-code for reference.

#inclusivefixit

Bug: 161896447
Test: None
Change-Id: I1b24350f4e4528ff40ef8d9065a2c5c4251c5059
2020-07-28 17:02:22 +00:00
Victor Hsieh
b07f4854b5 Respect app-ops permission in FileIntegrityService
Previous permission doesn't consider REQUEST_INSTALL_PACKAGES permission
as an app-ops permission.

Bug: 152009905
Test: atest GtsPlayFsiTestCases
Test: remove appops setup from AndroidTest.xml, the same test failed
Change-Id: Icdbf6bb35fe146c5be8a97e29c4c554b3ce91b5d
2020-03-27 09:23:41 -07:00
Ashwini Oruganti
9330d5e32b Resolve conflicting values of usesCleartextTraffic for shared processes
Bug: 148240416
Test: Manually tested by installing two apps running in a shared process
and starting their shared process activities in various orders. The
value of usesCleartextTraffic gets set as expected.
Change-Id: Ib350c09c42d5524734fb259a2ab787790f2d8e30
2020-02-21 09:52:58 -08:00
David Su
1ac48fd8d6 Merge "Move cacerts_wfa from system to Wifi APEX" 2020-01-28 18:54:29 +00:00
Janis Danisevskis
f2dd2fbd4c Merge "ConfirmationPrompt: Use default values for UIOptions" 2020-01-23 19:10:49 +00:00
Janis Danisevskis
227dddf910 ConfirmationPrompt: Use default values for UIOptions
ConfirmationPrompt passes magnified and inverted options to the keystore
service. While gathering the accessibility_display_inversion_enabled
setting, the implementation would throw an exception if this setting was
never set by the user. This causes the font scaling property to be
ignored. This patch uses default values in case the system setting is
not set.

Test: Run CTSVerifier Protected Confirmation test with increased font
      size.

Merged-In: I03a3ef56209c73ca7d2b2527a5f145f744148e38
Change-Id: I03a3ef56209c73ca7d2b2527a5f145f744148e38
2020-01-23 08:17:39 -08:00
Janis Danisevskis
4ff0964128 ConfirmationPrompt: Use default values for UIOptions
ConfirmationPrompt passes magnified and inverted options to the keystore
service. While gathering the accessibility_display_inversion_enabled
setting, the implementation would throw an exception if this setting was
never set by the user. This causes the font scaling property to be
ignored. This patch uses default values in case the system setting is
not set.

Test: Run CTSVerifier Protected Confirmation test with increased font
      size.

Change-Id: I03a3ef56209c73ca7d2b2527a5f145f744148e38
2020-01-22 16:03:09 -08:00
David Su
4a08a1d37e Move cacerts_wfa from system to Wifi APEX
Bug: 145199837
Test: atest android.security.cts.CertificateTest
Change-Id: I16a6376a01491455f3a2ce69ab57763c99353952
2020-01-22 14:04:04 -08:00
Artur Satayev
2d330f6fa8 Use new UnsupportedAppUsage annotation.
Existing annotations in libcore/ and frameworks/ will deleted after the migration. This also means that any java library that compiles @UnsupportedAppUsage requires a direct dependency on "unsupportedappusage" java_library.

Bug: 145132366
Test: m && diff unsupportedappusage_index.csv
Change-Id: I288969b0c22fa3a63bc2e71bb5009fe4a927e154
Merged-In: I288969b0c22fa3a63bc2e71bb5009fe4a927e154
2020-01-09 15:08:18 +00:00
Artur Satayev
df4395991f Use new UnsupportedAppUsage annotation.
Existing annotations in libcore/ and frameworks/ will deleted after the migration. This also means that any java library that compiles @UnsupportedAppUsage requires a direct dependency on "unsupportedappusage" java_library.

Bug: 145132366
Test: m && diff unsupportedappusage_index.csv
Change-Id: I288969b0c22fa3a63bc2e71bb5009fe4a927e154
2020-01-07 13:29:50 +00:00
TreeHugger Robot
3f7ef32b9f Merge "New API for query trust of a fs-verity certificate" 2019-12-23 20:18:40 +00:00
Victor Hsieh
20fe1f6f22 New API for query trust of a fs-verity certificate
The corresponding service is also added.

The API can be used by a store to know whether their certificate is
trusted on the device. As optimization, they only need to download
.fsv_sig signature file if it will be used.

The API can also be used to gradually switch to stronger key. The store
can query with their certificates in priority order and download the best
signature.

Test: Passed new GTS working in progress
Bug: 142573505
Change-Id: Ic788cd04aeaed35ad62113fe9e7535b8fa63b5ee
2019-12-23 09:21:19 -08:00