Commit Graph

241 Commits

Author SHA1 Message Date
Suprabh Shukla
097087fe4b Tweaking the irq pattern regex for wakeup reasons
Fixing to match only at the start of the line, so that invalid reasons
like "adb1 adb2" or negative ids don't get matched.

Also, removing a spurious newline introduced in the previous change.

Test: atest FrameworksServicesTests:CpuWakeupStatsTest

Bug: 195684213
Change-Id: Iab70f1a665a71a846a0bf8c186942f96b7e7ae95
2022-10-31 17:57:00 +00:00
Suprabh Shukla
774a7e61c4 Adding uid attribution mechanism for kernel wakeups
BatteryStats currently only stores the reason it receives from the
suspend control service. Starting with this change, batterystats will
now try to attribute these wakeups in more detail.

IRQ style wakeups where there has been an IRQ from a device get a
well structured reason string from the kernel. CpuWakeupStats will parse
it to get irq devices and then use irq_device_map xml to map the wakeup
to possible pre-defined subsystems that may have caused it.

Different parts of the system can use these subsystems to report any
associated activity (not to be confused with the class
android.app.Activity) tha could have caused a wakeup. CpuWakeupStats
will then attempt to associate this information with any wakeup that
may have occurred due to an IRQ from the relevant device.

This change defines the "Alarm" subsystem, and relies on the device
overlay to map this subsystem to the rtc device that ultimately enables
waking up the CPU when needed to process a wakeup alarm. Whenever there
is a batch of wakeup alarms that is dispatched, alarm manager notifies
batterystats (and hence cpuwakeupstats) of this "activity", which will
then try to associate it with any temporally proximal wakeups that have
happened due to the rtc device.

Currently, the information supported is only the uids that have
requested or initiated the activity from the subsystem that should be
blamed for the wakeup. But this can be extended to include more enum
style codes to represent other information.

Test: atest FrameworksServicesTests:IrqDeviceMapTest
Test: atest FrameworksServicesTests:CpuWakeupStatsTest

Bug: 249370357
Bug: 195684213
Change-Id: Idfbba82e9c007b5c9f15b9fd785b9a96cb202572
2022-10-11 15:10:37 -07:00
Christophe Pinelli
8378ff9423 Merge "Revert^2 "Verify that the component is exported"" 2022-09-16 15:00:46 +00:00
Christophe Pinelli
f3ef712a28 Revert^2 "Verify that the component is exported"
d84de83dcd

Change-Id: Ie9bf69a7549205b36924e1bb2c450e0961579ecd
2022-09-15 19:53:35 +00:00
Sam Saccone
ae74c8cc34 Merge "Revert "Verify that the component is exported"" 2022-09-14 23:11:10 +00:00
Domen Su
d84de83dcd Revert "Verify that the component is exported"
Revert submission 19776394-safer-implicit-intents

Reason for revert: DroidMonitor: Potential culprit for Bug b/246818637 - verifying through ABTD before revert submission. This is part of the standard investigation process, and does not mean your CL will be reverted.
Reverted Changes:
I66227a4fa:Update PackageManager test in Car to adapt to safe...
I779f3d6ee:CTS tests for safer implicit intents
I41c48a412:Verify that the component is exported

Change-Id: I8484d317afc9a1d845b3394828062615b5fd2066
2022-09-14 22:49:12 +00:00
Christophe Pinelli
44c0ac96b9 Merge "Verify that the component is exported" 2022-09-14 17:03:56 +00:00
Winson Chiu
ee11a9ceb3 Rename AndroidPackageApi to AndroidPackage
Makes it so that the non-suffixed name is the to-be system API,
renaming the internal class with an _Internal suffix.

This will also happen to all other exposed internal package data
types in future changes.

Test: presubmit, just a naming change

Change-Id: I8695e7f1644ff5af9303bb32ddec3480bd155bf8
2022-09-12 21:03:43 +00:00
Jeff Sharkey
2ef69945af Internalize setPackageStoppedState() call.
Several places across the OS internals were invoking this method
via AppGlobals, which is a poor strategy for testing.  Moving the
call to PackageManagerInternal supports easier mocking.

Bug: 243656033
Test: atest CtsContentTestCases:BroadcastReceiverTest
Test: atest FrameworksMockingServicesTests:BroadcastQueueTest
Change-Id: Ie29f60ac379eac8137af1301ac5cded4c9f37fc8
2022-08-30 17:38:31 -06:00
Christophe Pinelli
80a78df01e Verify that the component is exported
CL for tests: ag/19776394

Bug: 229362273
Test: atest
This reverts commit 24a489a25a.

Change-Id: I41c48a4127f66d81085c5f58140d640ae30cd949
2022-08-29 23:28:51 +00:00
Allen Xu
24a489a25a Revert "Verify that the component is exported"
Revert submission 18335517-safer-implicit-intents

Reason for revert: DroidMonitor-triggered revert due to many breakages in Quarterdeck, bug b/243844000
BUG: b/243844000
Reverted Changes:
Ida701f445:Update PackageManager test in Car to adapt to safe...
Ibd29e145a:CTS tests for safer implicit intents
I84e5d20f5:Verify that the component is exported

Change-Id: If4ac0c5e743f78417c4caa7d92a34f5027b34ec3
2022-08-25 23:02:12 +00:00
Christophe Pinelli
c000456edd Verify that the component is exported
CL for tests: ag/18698797

Bug: 229362273
Test: atest CtsContentTestCases:PackageManagerTest + manual tests
Change-Id: I84e5d20f575a77ece1459e79f288f1f5867449d1
2022-08-24 16:52:22 +00:00
Jackal Guo
51fdab007e Remove unused compile command --compile-layouts
The 'pm compile --compile-layouts' is deprecated, and it leaves the
possibility that malicious apps could do a side channel attack. Re-
move related entry to mitigate this.

Bug: 241233589
Test: atest dex-builder-test
Test: manually using the PoC in the buganizer to ensure the symptom
      no longer exists.
Change-Id: Ibd11425e6ee1468149fabe201983f95bfd69349c
2022-08-16 11:14:12 +08:00
Himanshu Gupta
acadbebb20 Fix Typos
Bug: 238632408
Test: NA

Change-Id: I20085577ef1aa451d9085f9ad1a62afdf1124dc1
2022-07-22 15:40:26 +05:30
JW Wang
00053b2456 Remove PackageManagerInternal#pruneCachedApksInApex
This method is no longer needed as b/225435110 has
addressed the cache issues.

Bug: 238591450
Test: StagedInstallInternalTest#testApkInApexPruneCache
Change-Id: I7829b3ce95ce6723d8166e30ffc73a0b3b60e0f0
2022-07-15 08:31:55 +08:00
Dmitri Plotnikov
842b134e2c Move BatteryStatsImpl to com.android.server.power.stats
Bug: 235635119
Test: atest FrameworksCoreTests:BatteryStatsTests
Test: atest FrameworksServicesTests:BatteryStatsTests
Test: atest BatteryUsageStatsProtoTests:BatteryUsageStatsPulledTest
NoNonSdkCheck: BatteryStatsImpl is being permanently moved to a different package. All data available via these hidden API is also available in dumpsys.
Change-Id: I39be1c66c23f43d339f9076c6b87902f6ef35967
2022-06-16 17:06:59 -07:00
Rhed Jao
376af6ff4a Fix cross user package visibility leakage for filterAppAccess API
- To fix apis which invoke the #filterAppAccess leak the package
  existence information of other users, this CL returns true if
  the target package is not installed under the given user id.

- Add an extra boolean parameter to the #filterAppAccess API for
  the LauncherApp module to not filter the uninstalled package
  when monitoring package changes events.

- Correct wrong user id usages of the filterAppAccess API in
  some modules.

Bug: 229684723
Test: atest android.content.pm.cts.PackageManagerTest
Test: atest android.appenumeration.cts.AppEnumerationTests
Test: atest android.appwidget.cts.AppWidgetTest
Test: atest com.android.cts.devicepolicy.ManagedProfileCrossProfileTest
Test: atest com.android.cts.devicepolicy.LauncherAppsProfileTest
Test: atest android.devicepolicy.cts.LauncherAppsTests
Change-Id: I3cced4668d1cc4488665c928e4cbe4e194c249cf
2022-06-10 12:43:34 +08:00
Rhed Jao
6282dc527c Merge changes from topic "pm_cross_user_package_visibility_6"
* changes:
  Using isUidPrivileged instead of getPrivateFlagsForUid API
  Add package manager internal api checkUidSignaturesForAllUsers
  Fix cross user package visibility leakage for PackageManager (6/n)
2022-05-16 04:21:48 +00:00
John Wu
7b21aedde0 Merge "Fix package visibility broadcast regression" into tm-dev am: e825776dce am: 252365bafa
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/18171369

Change-Id: Iaea163d2630a4f7ce5f36c8f3269df551efe47a9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-05-12 01:20:58 +00:00
John Wu
e825776dce Merge "Fix package visibility broadcast regression" into tm-dev 2022-05-12 00:44:52 +00:00
John Wu
8b1f96741c Fix package visibility broadcast regression
Sending broadcasts are not restricted by the package visibility of the
calling package. This is achieved by clearing the Binder calling
identity in several top-level broadcast sending APIs.

ag/15315839 introduced intent filter matching enforcement, which
requires the real calling UID to be used for evaluation. This caused
regression in broadcast package visibility.

Test: manual
Bug: 230363029
Change-Id: I6bf34fe22aa9396786e3bbbfe64094474c34b6df
2022-05-10 22:19:42 +00:00
Pavel Grafov
91edfc163b Allow profile owners to protect packages.
Changed how protected packages are stored in package manager:
* previously they were stored in a map from DO package into
  a list of protected packages. This isn't expressive enough
  to allow POs: the same PO package on different users may
  protect different packages.
* now they are stored in a map from userId into a list of
  protected packages. In case when the DO sets the policy
  the userId will be UserHandle.USER_ALL, otherwise it will
  be the calling user.

Bug: 218639412
Test: atest UserControlDisabledPackagesTest
Change-Id: I2d1d33acad035610c8db365f69b7a15faa03a2d5
Merged-In: I2d1d33acad035610c8db365f69b7a15faa03a2d5
2022-05-10 10:09:13 +00:00
Pavel Grafov
2e356b37ad Allow profile owners to protect packages.
Changed how protected packages are stored in package manager:
* previously they were stored in a map from DO package into
  a list of protected packages. This isn't expressive enough
  to allow POs: the same PO package on different users may
  protect different packages.
* now they are stored in a map from userId into a list of
  protected packages. In case when the DO sets the policy
  the userId will be UserHandle.USER_ALL, otherwise it will
  be the calling user.

Bug: 218639412
Test: atest UserControlDisabledPackagesTest
Change-Id: I2d1d33acad035610c8db365f69b7a15faa03a2d5
2022-05-10 09:56:17 +00:00
Rhed Jao
83e91711f2 Add package manager internal api checkUidSignaturesForAllUsers
Starting from U, the PackageManager#checkUidSignatures does not
support to check package signatures for different users. It
returns false if packages cannot be found in the calling user.

This cl adds an internal api checkUidSignaturesForAllUsers for
system modules that need to check package signatures installed
in any users.

Bug: 229684723
Test: atest BlobStoreMultiUserTest
Change-Id: Ib5b3c25dcafe664b31bd737bdb2718c045f845b4
2022-05-10 11:57:56 +08:00
JW Wang
6b6d653cee Move signature checking out of ApexManager
Now the check is in PackageSessionVerifier for both staged and
non-staged APEX. This ensures a consistent behavior between
staged and non-staged APEX when it comes to signature checking.

* Remove the dependency on ApexPackageInfo from ApexManager
  which helps us migrate from ApexPackageInfo.

* Performance slightly improved (measured on Pixel4a) for
  APEX signature checking:

  shim APEX: 13-16ms -> 10-13ms
  com.android.art: 340-355ms -> 160-180ms
  com.android.cellbroadcast: 165-180ms -> 79-85ms

  This is because the SigningDetails of the install session is
  reused without re-calculation.

Bug: 225756739
Test: atest CtsStagedInstallHostTestCases \
            StagedInstallInternalTest \
	    GtsStagedInstallHostTestCases \
	    com.android.server.pm.ApexManagerTest

Change-Id: I6e3adf0f3f80764dcdb9cc26ef281f25566e854e
2022-04-29 13:19:57 +08:00
Eric Biggers
6efca75753 PackageManagerService: remove unused support for onlyCore mode
Due to the removal of support for Full Disk Encryption,
the "core apps only" mode of system_server is no longer used, and
onlyCore is hard-coded to false.  For details, see http://ag/17685636.

Remove the corresponding obsolete code from PackageManagerService and
the related classes InitAppsHelper, UserDataPreparer, PackageParser2,
and ParsingPackageUtils.

Bug: 208476087
Change-Id: I48289d1f74414f831504b38ac5c1bde719b07fb2
2022-04-20 05:36:06 +00:00
Presubmit Automerger Backend
eaa49ae05e [automerge] Deny SCHEDULE_EXACT_ALARM by default to newer apps 2p: a1adc26c84 2p: cc26719f99
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/17601963

Bug: 226439802
Change-Id: I7f5aac204419d152996762497b57caac3b522cc2
2022-04-06 23:45:02 +00:00
Suprabh Shukla
a1adc26c84 Deny SCHEDULE_EXACT_ALARM by default to newer apps
Apps targeting T will not get SCHEDULE_EXACT_ALARM permission by
default, except in a few privileged special cases.

Test: atest FrameworksMockingServicesTests:AlarmManagerServiceTest
atest CtsAlarmManagerTestCases:ExactAlarmsTest

Bug: 226439802
Change-Id: Ie81a9c3bd8b863c3fd64aaf413209ff8862de74b
2022-04-06 23:44:36 +00:00
Felka Chang
633a8c6d29 Merge "Remove snapshot flood by update all overlays in one commitment" 2022-04-01 07:32:08 +00:00
Felka Chang
655a3f42a5 Remove snapshot flood by update all overlays in one commitment
The iteration n updates some PackageUserState instances for the
specified user. Once OverlayManagerService(OMS) changes some
PackageUserState instance, it triggers a snapshot rebuild in the
next iteration.

OMS has prepared all changes in switching users. PackageManagerService
compute all changes of PackageUserStates and then use the mutator to
modified all changes of PackageUserStates in one
commitPackageStateMutation.

Test: run perfetto.ui and follow the commands on perfetto.
    b/174206591#comment14
Test: TC="PtsConfigTestCases:com.google.android.config.pts"; \
    atest ${TC}.PixelSetupWizardOverlayTest ${TC}.ConfigTestCase

Bug: 174206591
Change-Id: I2b58b5e6164a72008c284adf05f6ff0240a5a33a
2022-04-01 01:52:45 +08:00
Songchun Fan
b85f36f1a6 [pm] remove mPm reference from DumpHelper
BUG: 215749969
BUG: 221896353
Test: builds and manual dump
Change-Id: I4360423c70fd6f589c0d5b682662d81d0d4fb362
2022-03-30 15:30:17 +00:00
Winson Chiu
85ba4b57e6 Revert "Revert "Remove ComputerTracker and fix consistency in PackageManagerService""
This reverts commit 35ef88f4cc.

Reason for revert: re-introduce change after disabling test in
Ia4303f6ba0160c24ac8949c359dfe3e28a544cc6

Change-Id: I14402335736559c4997439425d2ab49ac172d9ca
2022-03-10 13:11:27 -08:00
Sam Gilbert
35ef88f4cc Revert "Remove ComputerTracker and fix consistency in PackageManagerService"
This reverts commit 2fd993fd6c.

Reason for revert: test monitor, was identified as culprit for b/223768516

Change-Id: I871e5ab1c9cbe083a4aea4e916eb45a820725155
2022-03-10 18:13:17 +00:00
Winson
2fd993fd6c Remove ComputerTracker and fix consistency in PackageManagerService
Effectively removes the lock and trampoline Computer wrappers as
we enforce that snapshots are always available now.

Also isolates IPackageManager and PackageManagerInternal from
PackageManagerService to prevent misuse of the APIs. The separated
base classes have access to a snapshot method which is then proxied
to, or used to call into PMS.

This makes it impossible for a caller using PMS directly to
accidentally call into one of these other API surfaces that won't
use the caller's provided snapshot, causing inconsistency problems.

Also removes live locking annotations and the related infrastructure
since we just assume that doesn't matter anymore.

Also migrates some _Helper logic to take/pass snapshots to match the
PMS methods, but not all of the helper logic migated to consistent
snapshots. That will be done in a follow up.

With this, all known extra overhead has been removed and metrics
should return to normal.

Bug: 215403184

Test: presubmit

Change-Id: I7e977f600f49b070c3a539901cc06d523fb7517a
2022-03-09 13:07:34 -08:00
Winson
eb403e7d37 Isolate IPackageManager implementation
To avoid leaking IPackageManager methods directly into
PackageManagerService, moves the IPM implementation into an inner
class similar to PackageManagerInternal.

This will help enforce snapshot consistency by ensuring that all
non-IPM PMS methods can always take in a Computer instance to re-use.

Bug: 217961172

Test: presubmit

Change-Id: Ibf7bd3d1d90a40786279763ba8d62eb9348bb760
2022-03-07 23:10:41 -08:00
Gavin Corkery
4682aac632 Merge "Add isSameApp to PackageManagerInternal" into tm-dev 2022-03-03 13:49:14 +00:00
Gavin Corkery
7044722391 Add isSameApp to PackageManagerInternal
Adds a new method to PackageManagerInternal that checks
if a given package belongs to the calling uid. This logic also
accounts for calling uids in the sdk sandbox range.
Deduplicates two methods in NotificationManager and ActivityTaskManager
which have implemented this logic.

Bug: 219750831
Test: atest NotificationManagerServiceTest
Test: Manual test using Sdk Sandbox test app
Change-Id: I1c566f75c81112dfeeb664827dcb27768959c377
2022-03-01 18:27:08 +00:00
Jackal Guo
65067cb36d Mitigate the races during installation
When handling post-install during the installation process, some
tasks are posted to PackageHandler and be executed after notifying
the install observer (install initiator). The task includes force-
stopping the package. If the install observer starts the app right
after being notified, the ongoing force-stop will kill the process.
The race happens. To mitigate the potential race, We should defer
the notification until these tasks are done.

Bug: 165012101
Test: atest -p services/core/java/com/android/server/pm
Change-Id: Ia6b32f72f3d75b8a40c42e11d21f21c459db5299
Merged-In: Ia6b32f72f3d75b8a40c42e11d21f21c459db5299
(cherry picked from commit bad03aa3c9)
2022-02-21 09:20:06 +00:00
Winson
664792c231 Remove PMS snapshot lambdas
Lambdas were used to ensure consistent locking around the snapshot,
but since it's impossible to lock the snapshot now, this is no longer
necessary, and all methods should just store a reference.

Also migrates DomainVerificationService off PackageSetting lambdas,
which cleans up a lot of extra emthods.

Bug: 215403184

Test: atest com.android.server.pm.verify.domain
Test: atest SuspendPackageHelperTest

Change-Id: Ib4e3442e5c16e935b14b8421fbc33adff65dcf68
2022-02-18 11:47:36 -08:00
Winson
668fd62267 Fix ComponentResolver Computer consistency
Migrates ComponentResolver and ResolveIntentHelper away from calling
PM directly in favor of using a consistent Computer snapshot. This
saves on snapshot rebuild and ensures data consistency within a single
method call.

Bug: 215403184

Change-Id: Id017db704493f38d94fd498f77d2264fe008ef45
2022-02-16 23:04:06 -08:00
Songchun Fan
c7c5ed7080 [pm] remove SharedUserSetting from PackageSetting
Test: atest com.android.server.pm.AppsFilterTest
Test: atest com.android.server.pm.PackageManagerSettingsTests
Test: atest com.android.server.pm.SharedLibrariesImplTest
Test: atest com.android.server.pm.PackageManagerTests
BUG: 216207402
Change-Id: I7e321ee25f35e46ec0e21672e5b932e749de52e9
2022-02-11 09:32:25 -08:00
Sudheer Shanka
d1e5fabaa9 Track broadcast dispatched event only when the app is in the bg.
Bug: 206518114
Test: atest tests/tests/app.usage/src/android/app/usage/cts/UsageStatsTest.java
Change-Id: Ic017fff35d800a1ea9b4288421e021859f443b30
2022-01-28 16:27:57 -08:00
Winson Chiu
42e1d4b40a Merge changes I243988b0,I096b9019,Icf20dc74
* changes:
  Force PMS snapshots
  Remove more mLock usages
  Remove some mutation mLock usages
2022-01-27 22:52:58 +00:00
Winson
ae7cf39152 Force PMS snapshots
Removes the ability to disable PackageManagerService snapshots. The
new PackageState and related APIs rely on never taking PMS#mLock, so
a snapshot Computer must always be available.

To keep changes small, this does not migrate existing
executeWithConsistentComputer calls, but that can be done in a simple
follow-up to save on lambda allocation costs.

Bug: 202291547

Change-Id: I243988b0c48938a8701842a9de5cfc465c1d38d8
2022-01-27 02:39:41 -08:00
Jing Ji
627bbedd40 Add a tracker on background current drains for each uid
On detecting excessive battery usage of a background uid, we may
move the background restriction of the apps running in this uid to
more restrictive levels.

Bug: 200326767
Test: atest FrameworksMockingServicesTests:BackgroundRestrictionTest
Change-Id: I6c2d41e44367a283d8aa9491be683018a80a810c
2022-01-25 14:33:12 -08:00
Sudheer Shanka
eb2e42c49b Merge "Add OWNERS for UsageStats related classes." am: e9f11554d6 am: 08b23493b5 am: 0c3e7453a2 am: cef13c69d9
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1959074

Change-Id: I364ab78d87380a496b9a2e4992a4f1ed5705a1fc
2022-01-24 23:19:01 +00:00
Sudheer Shanka
5373a2e698 Merge changes Idde09e4c,I0337b400
* changes:
  Inform UsageStatsManager about notification related events.
  Allow reporting certain events to UsageStatsManager.
2022-01-24 22:13:30 +00:00
Sudheer Shanka
f1ade4643d Add OWNERS for UsageStats related classes.
Test: n/a
Change-Id: I86bfb95be2c5a8c560c6270ac876bf4eced3ab5a
2022-01-24 11:06:26 -08:00
Sudheer Shanka
4e50889197 Allow reporting certain events to UsageStatsManager.
Add methods to allow reporting broadcast-dispatched,
notification-posted, notification-updated,
notification-removed events to UsageStatsManager.

Bug: 206518114
Test: atest --test-mapping apex/jobscheduler/service/java/com/android/server/usage/TEST_MAPPING
Change-Id: I0337b4004505930d21f4ef669e79ba4512b9792b
2022-01-24 09:22:43 -08:00
Kathy Xiaoming Chen
5d568eda62 AmbientContext (aka Ambient PCC) Framework API, with a client API for apps to subscribe for AmbientContextEvents, and a provider API for AiAi to implement and provide the detected events.
Client apps need the ACCESS_AMBIENT_CONTEXT_EVENT permission to use the service. The permission protection level is internal|role.

API overview: http://go/ambient-framework-api
PRD: http://go/ambient-attribution-prd
Design doc: http://go/ambient-service-api

Test: CTS test
Bug: 192476579
Change-Id: I9daede83af34f215c278cb0530238faba1be5c70
Ignore-AOSP-First: to prevent new feature leak.
2022-01-22 22:07:22 +00:00