Commit Graph

10775 Commits

Author SHA1 Message Date
Kevin Hufnagle
ef5e6685d7 docs: Fix links to narrative guides am: a1796499fe am: 522d5e32de
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/15738642

Change-Id: Ic51fe5f2fef7ba3a9e80b530a05ff2c6fa2a1e2b
2021-09-01 17:46:32 +00:00
Kevin Hufnagle
a1796499fe docs: Fix links to narrative guides
Cannot use both `{@docRoot}` and leading `/` when specifying URLs

Bug: 197663210
Change-Id: If6762b95a3d6991b4732684853d974a06da032bc
Test: make ds-docs
Exempt-from-Owner-Approval: Docs-only change
2021-09-01 15:43:02 +00:00
Rhed Jao
baf1f463f0 DO NOT MERGE Apply a maximum char count to the load label api
The system is overwhelmed by an enormous label string returned by
the load label api. This cl truncates the label string if it exceeds
the maximum safe length.

Bug: 67013844
Test: atest PackageManagerTest
Change-Id: Ia4d768cc93a47cfb8b6f7c4b6dc73abd801809bd
2021-08-31 06:05:27 +00:00
Winson Chung
1acaeb5b66 Add logging for app drag and drop
- Allow source to specify an instance id for the drag instance
  (we'll create one otherwise if not specified)
- Log start/drop/end as per go/dragdrop_splitscreen_logging

Bug: 191686897
Test: statsd_testdrive -terse 90
Change-Id: I215208777e3627859079abac90520b1772478c5e
2021-08-13 14:56:06 -07:00
Ray Essick
8100a960b9 Merge "Rename android.media.MediaTranscodeManager -> MediaTranscodingManager" into sc-dev am: 9d0e91c7b6 am: e1906a6dc8
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/15521772

Change-Id: I740ee3aba3ebfb1cff6e78c367cfc00e94659aca
2021-08-12 18:41:53 +00:00
Ray Essick
e1906a6dc8 Merge "Rename android.media.MediaTranscodeManager -> MediaTranscodingManager" into sc-dev am: 9d0e91c7b6
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/15521772

Change-Id: I02cccd46608894c908ccbcf8e1d0fe3bf4a5af6a
2021-08-12 18:27:55 +00:00
Ray Essick
1168d9d014 Rename android.media.MediaTranscodeManager -> MediaTranscodingManager
renamed to avoid conflict with existing copy in the R framework.jar.
The framework.jar copy was removed during S development

Bug: 195608856
Test: build
Test: cts-tradefed run cts -m CtsMediaTranscodingTestCases
Change-Id: I40ab066cd61be8d278f21cc788016f2edd6bb86e
2021-08-12 07:42:56 +00:00
Rhed Jao
97ff8e3eed Merge "DO NOT MERGE Apply a maximum char count to the load label api" into sc-dev 2021-08-09 10:48:39 +00:00
Nate Myren
dcd809e7cd Merge "Remove calling UID check from ContentProvider" into sc-dev am: c2c1c0341b
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/15463733

Change-Id: I44bc8d19e6877cbfbf5cf54b9cb9dbcd8db35cd9
2021-08-05 16:59:04 +00:00
Nate Myren
e758539f02 Remove calling UID check from ContentProvider
AttributionSource checks calling UID on unparcel (so the check is not
necessary), and some ContentProviders may clear calling identity.

Test: Manual
Fixes: 188755312
Change-Id: If629eea3ba8c1a57fd4b7aff0fec2c0acb5f69be
2021-08-04 20:25:21 +00:00
Rhed Jao
cd8558a253 DO NOT MERGE Apply a maximum char count to the load label api
The system is overwhelmed by an enormous label string returned by
the load label api. This cl truncates the label string if it exceeds
the maximum safe length.

Bug: 67013844
Test: atest PackageManagerTest
Change-Id: Ia4d768cc93a47cfb8b6f7c4b6dc73abd801809bd
Merged-in: Ia4d768cc93a47cfb8b6f7c4b6dc73abd801809bd
2021-08-03 04:15:21 +00:00
Alex Buynytskyy
dcbf05475e Merge "Check for invalid (negative) string pool pos." into sc-dev am: 59bad728e2
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/15390628

Change-Id: Ie08ac7e816b906c224e0ee4ac573286535fa1ec6
2021-07-29 19:03:50 +00:00
Tom Natan
3c3deaed91 Merge "Add an 'android.software.app_compat_overrides' feature" into sc-v2-dev 2021-07-27 07:32:45 +00:00
Alex Buynytskyy
b2a831ac3c Check for invalid (negative) string pool pos.
Parcel implementation would crash the system server otherwise.
Any exception is OK as it'll cause the cache to be invalidated.
Crash is not OK.

Bug: 194632313
Fixes: 194632313
Test: atest PackageParserCacheHelperTest
Change-Id: I58a4496b4646e172e6c3aee9ea17854a7ef55eaa
2021-07-26 18:51:02 +00:00
tomnatan
ee126f0404 Add an 'android.software.app_compat_overrides' feature
This feature will allow OEMs to opt-in specific devices/builds to per-app compat overrides.

Bug: 188500456
Test: N/A
Change-Id: I00108d163f752d23c380496ccac971cf0fcfe0f6
2021-07-19 14:00:26 +00:00
Jeff Sharkey
38ffbde17e Root UID can synthesize AttributionSource values.
We trust any incoming value from the system UID, so we should also
trust values coming from the root UID, which includes many shell
commands such as "svc".

Bug: 193659633
Test: atest BluetoothInstrumentationTests:com.android.bluetooth.btservice.AdapterServiceTest --rerun-until-failure 100
Change-Id: Ied07731345f08fc3c4df465a3773e35c8df7c59a
2021-07-14 14:35:17 -06:00
TreeHugger Robot
fee338118c Merge "Validate AttributionSource during unparceling." into sc-dev 2021-07-13 20:57:17 +00:00
Jeff Sharkey
4025c6e7ae Validate AttributionSource during unparceling.
The Bluetooth stack is just one example of an application that makes
self-calls through public APIs, which makes it very difficult to
unconditionally validate AttributionSource arguments.

(The AttributionSource is correctly defined the first time a remote
caller enters the Bluetooth stack, but we've found many cases where
Bluetooth stack calls back into itself without clearing the Binder
identity, causing validation chaos.)

This change is an attempt at gracefully solving this by performing
validation automatically as part of unparceling an AttributionSource
the first time it enters a process.  This strategy isn't perfect,
since transporting an instance inside a Bundle would risk
unparceling much later, possibly long after the calling UID
information has been discarded.  We're rationalizing that this risk
doesn't exist since AttributionSource was only added a few months
ago, and isn't being used in this way.

We still intend to circle back and provide a better strategy in a
future release for transporting AttributionSource across AIDL which
will handle the nuances of self-calls.

Bug: 188391719
Test: atest BluetoothInstrumentationTests
Change-Id: I10b198cfcd8f361e19d52f86deb7f10f05fec891
2021-07-13 12:34:14 -06:00
Svet Ganov
1babd5bf51 Optimize AttributionSource tokens - base
For cases where the attribution soruce doesn't need to be
registered as trusted we are now using a shares static
token since the only purpose of the token in these cases
is for watching the source process dying as opposed to that
and security for registered cases.

bug: 192415943

Test: CtsPermissionTestCases
      CtsPermission2TestCases
      CtsPermission3TestCases
      CtsPermission4TestCases
      CtsPermission5TestCases

Change-Id: I93fde9ca1cacada7929761533dcae11b2736ce1e
2021-07-10 00:24:30 +00:00
Tom Natan
28a6e9f973 Merge "Add support for always_constrain_display_apis flag" into sc-dev 2021-07-08 10:25:09 +00:00
Jeff Sharkey
79b834d47c Tag some "new Binder()" instances to detect leaks.
We've seen evidence of a Binder leak, and our hunch is that it's
caused by one of these anonymous "new Binder()" sites.  Adding
descriptors will help us identify the leak cause.

Bug: 192415943
Test: atest BluetoothInstrumentationTests
Change-Id: I30cd15f084cf50f67edd833b27b853c4b22e1db1
2021-07-07 17:17:07 -06:00
tomnatan
f332106222 Add support for always_constrain_display_apis flag
Bug: 191184114
Test: atest WmTests:SizeCompatTests
Test: atest FrameworksCoreTests:ConstrainDisplayApisConfigTest
Change-Id: Ifc0d48c838216603c00f4cc09d0df2fd145a53a6
2021-07-06 15:18:50 +00:00
Winson Chung
b827a8ac83 Merge "Only provide the resolved activity info to the global intercept window" into sc-dev 2021-07-01 17:33:27 +00:00
Winson Chung
d07dca11ab Only provide the resolved activity info to the global intercept window
- Previously we were adding the activity info to the ClipData, but
  that data is provided to non-intercept windows when the drop happens
  and can be retrieved using reflection. The intention was only to
  provide this activity info to the shell global intercept window
  for invoking split.

  Instead of baking the info into the ClipData, we pass the resolved
  info along side the data and only construct a ClipData with the
  additional info for the intercept window.

Fixes: 191057499
Test: atest DragDropControllerTests
Change-Id: I2ccc9f1f666ff2a388f22b6e6a7b5eea3102964c
2021-07-01 17:32:18 +00:00
Ryan Mitchell
b3659d36b0 Merge changes from topic "revert-15058002-SNQUARIDWJ" into sc-dev
* changes:
  Revert^2 "Apply overlay changes with config change"
  Revert^3 "Deprecate Context#createApplicationContext"
2021-06-30 20:58:43 +00:00
Ryan Mitchell
350c2669d6 Revert^3 "Deprecate Context#createApplicationContext"
This reverts commit cb5a80ea57.

Reason for revert: Was not the cause of the test failure

Fixes: 186622527
Test: atest FrameworksCoreTests:ContextTest
Change-Id: I705854f080200f0465d94a7754e710f05a3ec92c
2021-06-30 15:53:45 +00:00
Jackal Guo
04a45607c1 Merge "Move BootTest to internal test" into sc-dev 2021-06-30 05:39:37 +00:00
TreeHugger Robot
4260ce4100 Merge "Improve javadocs for repeating alarms" into sc-dev 2021-06-30 00:55:07 +00:00
Suprabh Shukla
94f5840bed Improve javadocs for repeating alarms
Specifically, mentioning that the alarm count can only be included with
the alarm if the supplied pending intent is mutable.

Test: make offline-sdk-docs

Fixes: 178413211
Change-Id: I2914bceebeed8b52b0de11d70960aa33e6837b13
2021-06-29 17:34:14 -07:00
TreeHugger Robot
a46f524537 Merge "Double DEFAULT_MAX_LABEL_SIZE_PX to 1000px" into sc-dev 2021-06-29 23:36:33 +00:00
Paul Hobbs
8d440c0566 Merge changes from topic "revert-15058002-SNQUARIDWJ" into sc-dev
* changes:
  Revert^2 "Deprecate Context#createApplicationContext"
  Revert "Version LoadedApk cache using base code path"
  Revert "Apply overlay changes with config change"
2021-06-29 20:36:15 +00:00
Paul Hobbs
cb5a80ea57 Revert^2 "Deprecate Context#createApplicationContext"
Bug: 192242649

5a41b45a85

Change-Id: Idcebd68e0079e7e87de04ae25069b3a9ff72093c
2021-06-29 20:06:45 +00:00
Erik Wolsheimer
48af5ac794 Double DEFAULT_MAX_LABEL_SIZE_PX to 1000px
Fixes: 185869616
Test: Manual
Change-Id: I717d1e7fb7b912a0330ac08742206314c23b32c8
2021-06-29 17:51:07 +00:00
Jackal Guo
c9b3bd434e Move BootTest to internal test
Add a test to ensure that system could boot without exception after
a package is uninstalled with keeping data.

Bug: 188635265
Test: atest PackageManagerServiceHostTests
Change-Id: I190db789ecd8c0ca1ddd87fc1c6ef79593b35492
2021-06-29 12:04:41 +08:00
Patrick Baumann
c6bce70bc2 Fix links in setRequireUserAction docs
This change cleans up a couple of links in the new setRequireUserAction
javadocs to avoid listing the entire permission namespace in the text.

Fixes: 190535637
Test: Builds
Change-Id: I80fff983309963e0a2485510e793f30fcfbec28e
2021-06-29 02:29:53 +00:00
Ryan Mitchell
5a532f6eed Merge changes Icf81845d,Iea54abf3,I98656314 into sc-dev
* changes:
  Apply overlay changes with config change
  Version LoadedApk cache using base code path
  Revert "Deprecate Context#createApplicationContext"
2021-06-27 06:27:58 +00:00
Winson
2d96f8ab31 Remove ParsedIntentInfo CREATOR am: 75214cc510 am: f416e7b485
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/15080916

Change-Id: I8376c9667aa64953551961c3346447ad06c93f10
2021-06-24 22:01:29 +00:00
Winson
f416e7b485 Remove ParsedIntentInfo CREATOR am: 75214cc510
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/15080916

Change-Id: I4210bdd97953331cfe9e7cfbe30422fec91a2eac
2021-06-24 21:45:37 +00:00
Winson
75214cc510 Remove ParsedIntentInfo CREATOR
Its existence allows implicit readParcelable calls to invoke a Parcel
operation with mismatched read/write data sizes, allowing someone to
swap out the data on a reparcel.

Internal classes will use writeIntentInfoToParcel, so this is safe to
remove.

Bug: 191055353

Test: atest com.android.server.pm.test.parsing.parcelling

Change-Id: I44faa635faf8a77894a3dda8adf89c10064e53f1
2021-06-23 18:04:15 +00:00
Ryan Mitchell
5a41b45a85 Revert "Deprecate Context#createApplicationContext"
This reverts commit c54ebba25b.

Bug: 188059515
Test: atest FrameworksCoreTests:ContextTest
Change-Id: I986563142dac135281889e811e6e5219d728d5d1
2021-06-22 22:30:38 -07:00
Winson Chiu
343684b523 Merge "Fix parsing code parcelling errors" into sc-dev 2021-06-22 18:10:43 +00:00
Nikita Ioffe
637be99afd Add sys config to handle apexes that are allowed to be updated
Unlike staged installer check, we can't check if given APEX package is
allowed to be updated at session creation time, since we don't have
knowledge of the package being installed yet. Instead, the check is
implemented in PackageInstallerSession#handleInstall.

Like staged install check, allowed apex update check has similar
exemptions (adb is allowed to update any APEX,
`adb shell pm --bypass-allowed-apex-update-check` makes next install
session bypass the check).

In order to implement these exemptions, a new
INSTALL_DISABLE_ALLOWED_APEX_UPDATE_CHECK flag that can only be set by
system is added. PackageInstallerSession will skip the APEX update
checks if INSTALL_DISABLE_ALLOWED_APEX_UPDATE_CHECK is set.

Bug: 189274479
Test: atest CtsStagedInstallHostTestCases
Test: atest GtsStagedInstallHostTestCases
Test: atest FrameworksServicesTests:SystemConfigTest
Change-Id: I22921a3ac4d43011b565733d7a7183e5cdb4fe80
Merged-In: I22921a3ac4d43011b565733d7a7183e5cdb4fe80
(cherry picked from commit aafaaec0d5)
2021-06-22 13:39:41 +01:00
Jackal Guo
cc057784c1 Merge "Remove unused interface and implementation" into sc-dev 2021-06-22 04:58:58 +00:00
TreeHugger Robot
890daeb051 Merge "Do not canonicalize overlay config test paths" into sc-dev 2021-06-21 23:07:21 +00:00
Makoto Onuki
d97f509923 Merge "Update the javadoc around FGS" into sc-dev 2021-06-21 18:04:37 +00:00
Jackal Guo
9440df9105 Remove unused interface and implementation
Get rid of the unused method to mitigate the potential information
leakage.

Bug: 185124942
Test: atest view-compiler-tests
Test: atest android.view.cts.LayoutInflaterTest
Test: atest -p core/java/android/content/pm
Test: atest -p services/core/java/com/android/server/pm
Test: manually using the PoC in the buganizer to ensure the symptom
      no longer exists.
Change-Id: I5ee7381728a93535849fcf61a1373a5ed9036aa4
2021-06-21 13:08:56 +08:00
TreeHugger Robot
dc86e26f54 Merge "Removing remaining references of ActivityView in fw/base" into sc-dev 2021-06-19 01:23:12 +00:00
Winson
f93af7ef7e Fix parsing code parcelling errors
Address problems reading/writing:
- ParsedComponent mProperties
- ParsingPackageImpl mKeySetMapping
- ParsingPackageImpl mQueriesIntent

Bug: 187043377

Test: atest com.android.server.pm.test.parsing.parcelling

Change-Id: I5b33315f8248d5fcbdef2cc04ecf77cc18dbd7b6
2021-06-18 11:32:51 -07:00
Issei Suzuki
41e7f367ed Merge "Persist Theme name instead of ID for ShortcutInfo" into sc-dev 2021-06-16 14:57:36 +00:00
Rhed Jao
b55a5da715 Merge "Add support to update the throttle time of silent updates" into sc-dev 2021-06-16 07:28:58 +00:00