The NetworkStackPermissionStub package is used to enforce that permissions used by the NetworkStack are only used in packages sharing signature with NetworkStackPermissionStub. Permissions defined in this package are intended to be used only by the NetworkStack: both NetworkStack and the stub APK will be signed with a dedicated certificate to ensure that, with permissions being signature permissions. This APK *must* be installed, even if the NetworkStack app is not installed, because otherwise, any application will be able to define this permission and the system will give that application full access to the network stack. Test: flashed, booted Bug: 112869080 Change-Id: Ia13a9e6a703cb7b4403697a7f7bfff0f6f3b813e
46 lines
2.1 KiB
XML
46 lines
2.1 KiB
XML
<?xml version="1.0" encoding="utf-8"?>
|
|
<!--
|
|
/*
|
|
* Copyright (C) 2014 The Android Open Source Project
|
|
*
|
|
* Licensed under the Apache License, Version 2.0 (the "License");
|
|
* you may not use this file except in compliance with the License.
|
|
* You may obtain a copy of the License at
|
|
*
|
|
* http://www.apache.org/licenses/LICENSE-2.0
|
|
*
|
|
* Unless required by applicable law or agreed to in writing, software
|
|
* distributed under the License is distributed on an "AS IS" BASIS,
|
|
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
* See the License for the specific language governing permissions and
|
|
* limitations under the License.
|
|
*/
|
|
-->
|
|
<manifest xmlns:android="http://schemas.android.com/apk/res/android"
|
|
package="com.android.mainline.networkstack"
|
|
android:sharedUserId="android.uid.networkstack">
|
|
<uses-permission android:name="android.permission.INTERNET" />
|
|
<uses-permission android:name="android.permission.ACCESS_COARSE_LOCATION" />
|
|
<uses-permission android:name="android.permission.ACCESS_NETWORK_STATE" />
|
|
<uses-permission android:name="android.permission.ACCESS_WIFI_STATE" />
|
|
<uses-permission android:name="android.permission.CONNECTIVITY_INTERNAL" />
|
|
<uses-permission android:name="android.permission.NETWORK_SETTINGS" />
|
|
<!-- Signature permission defined in NetworkStackStub -->
|
|
<uses-permission android:name="android.permission.MAINLINE_NETWORK_STACK" />
|
|
<!-- Launch captive portal app as specific user -->
|
|
<uses-permission android:name="android.permission.INTERACT_ACROSS_USERS_FULL" />
|
|
<uses-permission android:name="android.permission.NETWORK_STACK" />
|
|
<uses-permission android:name="android.permission.WAKE_LOCK" />
|
|
<application
|
|
android:label="NetworkStack"
|
|
android:defaultToDeviceProtectedStorage="true"
|
|
android:directBootAware="true"
|
|
android:usesCleartextTraffic="true">
|
|
<service android:name="com.android.server.NetworkStackService">
|
|
<intent-filter>
|
|
<action android:name="android.net.INetworkStackConnector"/>
|
|
</intent-filter>
|
|
</service>
|
|
</application>
|
|
</manifest>
|