Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Unverified Commit a3c7cc79 authored by Kevin F. Haggerty's avatar Kevin F. Haggerty
Browse files

Merge tag 'android-security-10.0.0_r73' of...

Merge tag 'android-security-10.0.0_r73' of https://android.googlesource.com/platform/frameworks/base into lineage-17.1_REBASE_android-security-10.0.0_r73

Android Security 10.0.0 Release 73 (9269285)

* tag 'android-security-10.0.0_r73' of https://android.googlesource.com/platform/frameworks/base:
  [DO NOT MERGE] Revert "Fix system zen rules by using owner package name if caller is system"
  [DO NOT MERGE] Revert "Check rule package name in ZenModeHelper.addAutomaticRule"
  Add safety checks on KEY_INTENT mismatch.
  [DO NOT MERGE] Fix permanent denial of service via setComponentEnabledSetting
  [Do Not Merge] Ignore malformed shortcuts
  [DO NOT MERGE] Update window with FLAG_SECURE when bouncer is showing
  Fix a security issue in app widget service.
  Fix NPE
  [pm] forbid deletion of protected packages
  Include all enabled services when FEEDBACK_ALL_MASK.
  Validate package name passed to setApplicationRestrictions.
  RESTRICT AUTOMERGE Prevent non-admin users from deleting system apps.
  Limit the size of NotificationChannel and NotificationChannelGroup
  Revert "RESTRICT AUTOMERGE Prevent non-admin users from deleting system apps."

Conflicts:
	packages/SystemUI/src/com/android/systemui/statusbar/phone/StatusBarWindowController.java
	packages/SystemUI/tests/src/com/android/systemui/statusbar/phone/StatusBarWindowControllerTest.java

Change-Id: Ic298cddb36a4ed43e9c75de4a50b073cd051f1e7
parents 5a07c6e5 b02406e6
Loading
Loading
Loading
Loading
+14 −5
Original line number Diff line number Diff line
@@ -61,8 +61,13 @@ public final class NotificationChannel implements Parcelable {
    /**
     * The maximum length for text fields in a NotificationChannel. Fields will be truncated at this
     * limit.
     * @hide
     */
    private static final int MAX_TEXT_LENGTH = 1000;
    public static final int MAX_TEXT_LENGTH = 1000;
    /**
     * @hide
     */
    public static final int MAX_VIBRATION_LENGTH = 1000;

    private static final String TAG_CHANNEL = "channel";
    private static final String ATT_NAME = "name";
@@ -195,17 +200,17 @@ public final class NotificationChannel implements Parcelable {
     */
    protected NotificationChannel(Parcel in) {
        if (in.readByte() != 0) {
            mId = in.readString();
            mId = getTrimmedString(in.readString());
        } else {
            mId = null;
        }
        if (in.readByte() != 0) {
            mName = in.readString();
            mName = getTrimmedString(in.readString());
        } else {
            mName = null;
        }
        if (in.readByte() != 0) {
            mDesc = in.readString();
            mDesc = getTrimmedString(in.readString());
        } else {
            mDesc = null;
        }
@@ -214,18 +219,22 @@ public final class NotificationChannel implements Parcelable {
        mLockscreenVisibility = in.readInt();
        if (in.readByte() != 0) {
            mSound = Uri.CREATOR.createFromParcel(in);
            mSound = Uri.parse(getTrimmedString(mSound.toString()));
        } else {
            mSound = null;
        }
        mLights = in.readByte() != 0;
        mVibration = in.createLongArray();
        if (mVibration != null && mVibration.length > MAX_VIBRATION_LENGTH) {
            mVibration = Arrays.copyOf(mVibration, MAX_VIBRATION_LENGTH);
        }
        mUserLockedFields = in.readInt();
        mFgServiceShown = in.readByte() != 0;
        mVibrationEnabled = in.readByte() != 0;
        mShowBadge = in.readByte() != 0;
        mDeleted = in.readByte() != 0;
        if (in.readByte() != 0) {
            mGroup = in.readString();
            mGroup = getTrimmedString(in.readString());
        } else {
            mGroup = null;
        }
+15 −5
Original line number Diff line number Diff line
@@ -42,8 +42,9 @@ public final class NotificationChannelGroup implements Parcelable {
    /**
     * The maximum length for text fields in a NotificationChannelGroup. Fields will be truncated at
     * this limit.
     * @hide
     */
    private static final int MAX_TEXT_LENGTH = 1000;
    public static final int MAX_TEXT_LENGTH = 1000;

    private static final String TAG_GROUP = "channelGroup";
    private static final String ATT_NAME = "name";
@@ -89,13 +90,17 @@ public final class NotificationChannelGroup implements Parcelable {
     */
    protected NotificationChannelGroup(Parcel in) {
        if (in.readByte() != 0) {
            mId = in.readString();
            mId = getTrimmedString(in.readString());
        } else {
            mId = null;
        }
        mName = TextUtils.CHAR_SEQUENCE_CREATOR.createFromParcel(in);
        if (in.readByte() != 0) {
            mDescription = in.readString();
            mName = getTrimmedString(in.readString());
        } else {
            mName = "";
        }
        if (in.readByte() != 0) {
            mDescription = getTrimmedString(in.readString());
        } else {
            mDescription = null;
        }
@@ -119,7 +124,12 @@ public final class NotificationChannelGroup implements Parcelable {
        } else {
            dest.writeByte((byte) 0);
        }
        TextUtils.writeToParcel(mName, dest, flags);
        if (mName != null) {
            dest.writeByte((byte) 1);
            dest.writeString(mName.toString());
        } else {
            dest.writeByte((byte) 0);
        }
        if (mDescription != null) {
            dest.writeByte((byte) 1);
            dest.writeString(mDescription);
+3 −1
Original line number Diff line number Diff line
@@ -1095,7 +1095,9 @@ public class AppWidgetManager {
     * @param intent        The intent of the service which will be providing the data to the
     *                      RemoteViewsAdapter.
     * @param connection    The callback interface to be notified when a connection is made or lost.
     * @param flags         Flags used for binding to the service
     * @param flags         Flags used for binding to the service. Currently only
     *                     {@link Context#BIND_AUTO_CREATE} and
     *                     {@link Context#BIND_FOREGROUND_SERVICE_WHILE_AWAKE} are supported.
     *
     * @see Context#getServiceDispatcher(ServiceConnection, Handler, int)
     * @hide
+89 −0
Original line number Diff line number Diff line
/*
 * Copyright (C) 2022 The Android Open Source Project
 *
 * Licensed under the Apache License, Version 2.0 (the "License");
 * you may not use this file except in compliance with the License.
 * You may obtain a copy of the License at
 *
 *      http://www.apache.org/licenses/LICENSE-2.0
 *
 * Unless required by applicable law or agreed to in writing, software
 * distributed under the License is distributed on an "AS IS" BASIS,
 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 * See the License for the specific language governing permissions and
 * limitations under the License.
 */

package android.app;

import static junit.framework.TestCase.assertEquals;
import static junit.framework.TestCase.assertTrue;

import android.os.Parcel;
import android.test.AndroidTestCase;
import android.text.TextUtils;

import androidx.test.filters.SmallTest;
import androidx.test.runner.AndroidJUnit4;

import com.google.common.base.Strings;

import org.junit.Test;
import org.junit.runner.RunWith;

import java.lang.reflect.Field;

@RunWith(AndroidJUnit4.class)
@SmallTest
public class NotificationChannelGroupTest {
    private final String CLASS = "android.app.NotificationChannelGroup";

    @Test
    public void testLongStringFields() {
        NotificationChannelGroup group = new NotificationChannelGroup("my_group_01", "groupName");

        try {
            String longString = Strings.repeat("A", 65536);
            Field mName = Class.forName(CLASS).getDeclaredField("mName");
            mName.setAccessible(true);
            mName.set(group, longString);
            Field mId = Class.forName(CLASS).getDeclaredField("mId");
            mId.setAccessible(true);
            mId.set(group, longString);
            Field mDescription = Class.forName(CLASS).getDeclaredField("mDescription");
            mDescription.setAccessible(true);
            mDescription.set(group, longString);
        } catch (NoSuchFieldException e) {
            e.printStackTrace();
        } catch (ClassNotFoundException e) {
            e.printStackTrace();
        } catch (IllegalAccessException e) {
            e.printStackTrace();
        }

        Parcel parcel = Parcel.obtain();
        group.writeToParcel(parcel, 0);
        parcel.setDataPosition(0);

        NotificationChannelGroup fromParcel =
                NotificationChannelGroup.CREATOR.createFromParcel(parcel);
        assertEquals(NotificationChannelGroup.MAX_TEXT_LENGTH, fromParcel.getId().length());
        assertEquals(NotificationChannelGroup.MAX_TEXT_LENGTH, fromParcel.getName().length());
        assertEquals(NotificationChannelGroup.MAX_TEXT_LENGTH,
                fromParcel.getDescription().length());
    }

    @Test
    public void testNullableFields() {
        NotificationChannelGroup group = new NotificationChannelGroup("my_group_01", null);

        Parcel parcel = Parcel.obtain();
        group.writeToParcel(parcel, 0);
        parcel.setDataPosition(0);

        NotificationChannelGroup fromParcel =
                NotificationChannelGroup.CREATOR.createFromParcel(parcel);
        assertEquals(group.getId(), fromParcel.getId());
        assertTrue(TextUtils.isEmpty(fromParcel.getName()));
    }
}
+102 −0
Original line number Diff line number Diff line
/*
 * Copyright (C) 2022 The Android Open Source Project
 *
 * Licensed under the Apache License, Version 2.0 (the "License");
 * you may not use this file except in compliance with the License.
 * You may obtain a copy of the License at
 *
 *      http://www.apache.org/licenses/LICENSE-2.0
 *
 * Unless required by applicable law or agreed to in writing, software
 * distributed under the License is distributed on an "AS IS" BASIS,
 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 * See the License for the specific language governing permissions and
 * limitations under the License.
 */

package android.app;

import static junit.framework.TestCase.assertEquals;

import android.net.Uri;
import android.os.Parcel;

import androidx.test.filters.SmallTest;
import androidx.test.runner.AndroidJUnit4;

import com.google.common.base.Strings;

import org.junit.Test;
import org.junit.runner.RunWith;

import java.lang.reflect.Field;

@RunWith(AndroidJUnit4.class)
@SmallTest
public class NotificationChannelTest {
    private final String CLASS = "android.app.NotificationChannel";

    @Test
    public void testLongStringFields() {
        NotificationChannel channel = new NotificationChannel("id", "name", 3);

        try {
            String longString = Strings.repeat("A", 65536);
            Field mName = Class.forName(CLASS).getDeclaredField("mName");
            mName.setAccessible(true);
            mName.set(channel, longString);
            Field mId = Class.forName(CLASS).getDeclaredField("mId");
            mId.setAccessible(true);
            mId.set(channel, longString);
            Field mDesc = Class.forName(CLASS).getDeclaredField("mDesc");
            mDesc.setAccessible(true);
            mDesc.set(channel, longString);
            Field mParentId = Class.forName(CLASS).getDeclaredField("mParentId");
            mParentId.setAccessible(true);
            mParentId.set(channel, longString);
            Field mGroup = Class.forName(CLASS).getDeclaredField("mGroup");
            mGroup.setAccessible(true);
            mGroup.set(channel, longString);
            Field mConversationId = Class.forName(CLASS).getDeclaredField("mConversationId");
            mConversationId.setAccessible(true);
            mConversationId.set(channel, longString);
        } catch (NoSuchFieldException e) {
            e.printStackTrace();
        } catch (ClassNotFoundException e) {
            e.printStackTrace();
        } catch (IllegalAccessException e) {
            e.printStackTrace();
        }

        Parcel parcel = Parcel.obtain();
        channel.writeToParcel(parcel, 0);
        parcel.setDataPosition(0);

        NotificationChannel fromParcel = NotificationChannel.CREATOR.createFromParcel(parcel);
        assertEquals(NotificationChannel.MAX_TEXT_LENGTH, fromParcel.getId().length());
        assertEquals(NotificationChannel.MAX_TEXT_LENGTH, fromParcel.getName().length());
        assertEquals(NotificationChannel.MAX_TEXT_LENGTH,
                fromParcel.getDescription().length());
        assertEquals(NotificationChannel.MAX_TEXT_LENGTH,
                fromParcel.getGroup().length());
    }

    @Test
    public void testLongAlertFields() {
        NotificationChannel channel = new NotificationChannel("id", "name", 3);

        channel.setSound(Uri.parse("content://" + Strings.repeat("A",65536)),
                Notification.AUDIO_ATTRIBUTES_DEFAULT);
        channel.setVibrationPattern(new long[65550/2]);

        Parcel parcel = Parcel.obtain();
        channel.writeToParcel(parcel, 0);
        parcel.setDataPosition(0);

        NotificationChannel fromParcel = NotificationChannel.CREATOR.createFromParcel(parcel);
        assertEquals(NotificationChannel.MAX_VIBRATION_LENGTH,
                fromParcel.getVibrationPattern().length);
        assertEquals(NotificationChannel.MAX_TEXT_LENGTH,
                fromParcel.getSound().toString().length());
    }
}
Loading