blob: 7fde68f55b76bfddd7f145d86863364320d54d1c [file] [log] [blame]
Svet Ganovadc1cf42015-06-15 16:36:24 -07001/*
2 * Copyright (C) 2015 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
17package com.android.server.pm;
18
19import android.Manifest;
Dianne Hackbornca8e6da2015-06-24 15:19:17 -070020import android.app.DownloadManager;
Dianne Hackborn388cd2c2015-06-26 17:32:36 -070021import android.app.admin.DevicePolicyManager;
Svet Ganovadc1cf42015-06-15 16:36:24 -070022import android.content.Intent;
23import android.content.pm.ApplicationInfo;
24import android.content.pm.PackageManager;
25import android.content.pm.PackageManagerInternal.PackagesProvider;
Svetoslav0010b702015-06-30 18:05:26 -070026import android.content.pm.PackageManagerInternal.SyncAdapterPackagesProvider;
Svet Ganovadc1cf42015-06-15 16:36:24 -070027import android.content.pm.PackageParser;
Dianne Hackbornca8e6da2015-06-24 15:19:17 -070028import android.content.pm.ProviderInfo;
Svet Ganovadc1cf42015-06-15 16:36:24 -070029import android.content.pm.ResolveInfo;
30import android.net.Uri;
31import android.os.Build;
32import android.os.UserHandle;
Dianne Hackborn388cd2c2015-06-26 17:32:36 -070033import android.provider.CalendarContract;
34import android.provider.ContactsContract;
Svet Ganovadc1cf42015-06-15 16:36:24 -070035import android.provider.MediaStore;
Jack Yued79bf52015-07-06 17:23:52 -070036import android.provider.Telephony.Sms.Intents;
Svet Ganovadc1cf42015-06-15 16:36:24 -070037import android.util.ArraySet;
38import android.util.Log;
39
40import java.io.File;
41import java.util.ArrayList;
42import java.util.List;
43import java.util.Set;
44
45import static android.os.Process.FIRST_APPLICATION_UID;
46
47/**
48 * This class is the policy for granting runtime permissions to
49 * platform components and default handlers in the system such
50 * that the device is usable out-of-the-box. For example, the
51 * shell UID is a part of the system and the Phone app should
52 * have phone related permission by default.
53 */
54final class DefaultPermissionGrantPolicy {
Jeff Davidson2a880312015-06-22 16:54:34 -070055 private static final String TAG = "DefaultPermGrantPolicy"; // must be <= 23 chars
Svet Ganovadc1cf42015-06-15 16:36:24 -070056 private static final boolean DEBUG = false;
57
Jeff Sharkey7186dd32015-06-30 17:32:45 -070058 private static final String AUDIO_MIME_TYPE = "audio/mpeg";
Svet Ganovadc1cf42015-06-15 16:36:24 -070059
60 private static final Set<String> PHONE_PERMISSIONS = new ArraySet<>();
61 static {
62 PHONE_PERMISSIONS.add(Manifest.permission.READ_PHONE_STATE);
63 PHONE_PERMISSIONS.add(Manifest.permission.CALL_PHONE);
Dianne Hackborn388cd2c2015-06-26 17:32:36 -070064 PHONE_PERMISSIONS.add(Manifest.permission.READ_CALL_LOG);
Svet Ganovadc1cf42015-06-15 16:36:24 -070065 PHONE_PERMISSIONS.add(Manifest.permission.WRITE_CALL_LOG);
66 PHONE_PERMISSIONS.add(Manifest.permission.ADD_VOICEMAIL);
67 PHONE_PERMISSIONS.add(Manifest.permission.USE_SIP);
68 PHONE_PERMISSIONS.add(Manifest.permission.PROCESS_OUTGOING_CALLS);
69 }
70
71 private static final Set<String> CONTACTS_PERMISSIONS = new ArraySet<>();
72 static {
73 CONTACTS_PERMISSIONS.add(Manifest.permission.READ_CONTACTS);
74 CONTACTS_PERMISSIONS.add(Manifest.permission.WRITE_CONTACTS);
75 }
76
77 private static final Set<String> LOCATION_PERMISSIONS = new ArraySet<>();
78 static {
79 LOCATION_PERMISSIONS.add(Manifest.permission.ACCESS_FINE_LOCATION);
80 LOCATION_PERMISSIONS.add(Manifest.permission.ACCESS_COARSE_LOCATION);
81 }
82
83 private static final Set<String> CALENDAR_PERMISSIONS = new ArraySet<>();
84 static {
85 CALENDAR_PERMISSIONS.add(Manifest.permission.READ_CALENDAR);
86 CALENDAR_PERMISSIONS.add(Manifest.permission.WRITE_CALENDAR);
87 }
88
89 private static final Set<String> SMS_PERMISSIONS = new ArraySet<>();
90 static {
91 SMS_PERMISSIONS.add(Manifest.permission.SEND_SMS);
92 SMS_PERMISSIONS.add(Manifest.permission.RECEIVE_SMS);
93 SMS_PERMISSIONS.add(Manifest.permission.READ_SMS);
94 SMS_PERMISSIONS.add(Manifest.permission.RECEIVE_WAP_PUSH);
95 SMS_PERMISSIONS.add(Manifest.permission.RECEIVE_MMS);
96 SMS_PERMISSIONS.add(Manifest.permission.READ_CELL_BROADCASTS);
97 }
98
99 private static final Set<String> MICROPHONE_PERMISSIONS = new ArraySet<>();
100 static {
101 MICROPHONE_PERMISSIONS.add(Manifest.permission.RECORD_AUDIO);
102 }
103
104 private static final Set<String> CAMERA_PERMISSIONS = new ArraySet<>();
105 static {
106 CAMERA_PERMISSIONS.add(Manifest.permission.CAMERA);
107 }
108
109 private static final Set<String> SENSORS_PERMISSIONS = new ArraySet<>();
110 static {
111 SENSORS_PERMISSIONS.add(Manifest.permission.BODY_SENSORS);
112 }
113
114 private static final Set<String> STORAGE_PERMISSIONS = new ArraySet<>();
115 static {
Svet Ganov975fa472015-06-22 20:45:31 -0700116 STORAGE_PERMISSIONS.add(Manifest.permission.READ_EXTERNAL_STORAGE);
Svet Ganovadc1cf42015-06-15 16:36:24 -0700117 STORAGE_PERMISSIONS.add(Manifest.permission.WRITE_EXTERNAL_STORAGE);
118 }
119
Dianne Hackborn388cd2c2015-06-26 17:32:36 -0700120 private static final Set<String> ACCOUNTS_PERMISSIONS = new ArraySet<>();
121 static {
Svet Ganov50a8bf42015-07-15 11:04:18 -0700122 ACCOUNTS_PERMISSIONS.add(Manifest.permission.GET_ACCOUNTS);
Svet Ganovadc1cf42015-06-15 16:36:24 -0700123 }
124
Svet Ganovadc1cf42015-06-15 16:36:24 -0700125 private final PackageManagerService mService;
126
127 private PackagesProvider mImePackagesProvider;
128 private PackagesProvider mLocationPackagesProvider;
129 private PackagesProvider mVoiceInteractionPackagesProvider;
Svetoslavcdfd2302015-06-25 19:07:31 -0700130 private PackagesProvider mSmsAppPackagesProvider;
131 private PackagesProvider mDialerAppPackagesProvider;
Svetoslav0010b702015-06-30 18:05:26 -0700132 private SyncAdapterPackagesProvider mSyncAdapterPackagesProvider;
Svet Ganovadc1cf42015-06-15 16:36:24 -0700133
134 public DefaultPermissionGrantPolicy(PackageManagerService service) {
135 mService = service;
136 }
137
138 public void setImePackagesProviderLPr(PackagesProvider provider) {
139 mImePackagesProvider = provider;
140 }
141
142 public void setLocationPackagesProviderLPw(PackagesProvider provider) {
143 mLocationPackagesProvider = provider;
144 }
145
146 public void setVoiceInteractionPackagesProviderLPw(PackagesProvider provider) {
147 mVoiceInteractionPackagesProvider = provider;
148 }
149
Svetoslavcdfd2302015-06-25 19:07:31 -0700150 public void setSmsAppPackagesProviderLPw(PackagesProvider provider) {
151 mSmsAppPackagesProvider = provider;
152 }
153
154 public void setDialerAppPackagesProviderLPw(PackagesProvider provider) {
155 mDialerAppPackagesProvider = provider;
Jeff Davidson2a880312015-06-22 16:54:34 -0700156 }
157
Svet Ganov50a8bf42015-07-15 11:04:18 -0700158 public void setSyncAdapterPackagesProviderLPw(SyncAdapterPackagesProvider provider) {
Svetoslav0010b702015-06-30 18:05:26 -0700159 mSyncAdapterPackagesProvider = provider;
160 }
161
Svet Ganovadc1cf42015-06-15 16:36:24 -0700162 public void grantDefaultPermissions(int userId) {
163 grantPermissionsToSysComponentsAndPrivApps(userId);
164 grantDefaultSystemHandlerPermissions(userId);
165 }
166
167 private void grantPermissionsToSysComponentsAndPrivApps(int userId) {
Jeff Sharkey7186dd32015-06-30 17:32:45 -0700168 Log.i(TAG, "Granting permissions to platform components for user " + userId);
Svet Ganovadc1cf42015-06-15 16:36:24 -0700169
170 synchronized (mService.mPackages) {
171 for (PackageParser.Package pkg : mService.mPackages.values()) {
Svet Ganov824d4532015-07-10 18:25:48 -0700172 if (!isSysComponentOrPersistentPlatformSignedPrivApp(pkg)
Svet Ganovadc1cf42015-06-15 16:36:24 -0700173 || !doesPackageSupportRuntimePermissions(pkg)) {
174 continue;
175 }
176 final int permissionCount = pkg.requestedPermissions.size();
177 for (int i = 0; i < permissionCount; i++) {
178 String permission = pkg.requestedPermissions.get(i);
179 BasePermission bp = mService.mSettings.mPermissions.get(permission);
180 if (bp != null && bp.isRuntime()) {
181 final int flags = mService.getPermissionFlags(permission,
182 pkg.packageName, userId);
183 if ((flags & PackageManager.FLAG_PERMISSION_SYSTEM_FIXED) == 0) {
184 mService.grantRuntimePermission(pkg.packageName, permission, userId);
185 mService.updatePermissionFlags(permission, pkg.packageName,
186 PackageManager.MASK_PERMISSION_FLAGS,
Svet Ganov77ab6a82015-07-03 12:03:02 -0700187 PackageManager.FLAG_PERMISSION_SYSTEM_FIXED
188 | PackageManager.FLAG_PERMISSION_GRANTED_BY_DEFAULT, userId);
Svet Ganovadc1cf42015-06-15 16:36:24 -0700189 if (DEBUG) {
190 Log.i(TAG, "Granted " + permission + " to system component "
191 + pkg.packageName);
192 }
193 }
194 }
195 }
196 }
197 }
198 }
199
200 private void grantDefaultSystemHandlerPermissions(int userId) {
Jeff Sharkey7186dd32015-06-30 17:32:45 -0700201 Log.i(TAG, "Granting permissions to default platform handlers for user " + userId);
Svet Ganovadc1cf42015-06-15 16:36:24 -0700202
203 final PackagesProvider imePackagesProvider;
204 final PackagesProvider locationPackagesProvider;
205 final PackagesProvider voiceInteractionPackagesProvider;
Svetoslavcdfd2302015-06-25 19:07:31 -0700206 final PackagesProvider smsAppPackagesProvider;
207 final PackagesProvider dialerAppPackagesProvider;
Svetoslav0010b702015-06-30 18:05:26 -0700208 final SyncAdapterPackagesProvider syncAdapterPackagesProvider;
Svet Ganovadc1cf42015-06-15 16:36:24 -0700209
210 synchronized (mService.mPackages) {
211 imePackagesProvider = mImePackagesProvider;
212 locationPackagesProvider = mLocationPackagesProvider;
213 voiceInteractionPackagesProvider = mVoiceInteractionPackagesProvider;
Svetoslavcdfd2302015-06-25 19:07:31 -0700214 smsAppPackagesProvider = mSmsAppPackagesProvider;
215 dialerAppPackagesProvider = mDialerAppPackagesProvider;
Svetoslav0010b702015-06-30 18:05:26 -0700216 syncAdapterPackagesProvider = mSyncAdapterPackagesProvider;
Svet Ganovadc1cf42015-06-15 16:36:24 -0700217 }
218
219 String[] imePackageNames = (imePackagesProvider != null)
220 ? imePackagesProvider.getPackages(userId) : null;
221 String[] voiceInteractPackageNames = (voiceInteractionPackagesProvider != null)
222 ? voiceInteractionPackagesProvider.getPackages(userId) : null;
223 String[] locationPackageNames = (locationPackagesProvider != null)
224 ? locationPackagesProvider.getPackages(userId) : null;
Svetoslavcdfd2302015-06-25 19:07:31 -0700225 String[] smsAppPackageNames = (smsAppPackagesProvider != null)
226 ? smsAppPackagesProvider.getPackages(userId) : null;
227 String[] dialerAppPackageNames = (dialerAppPackagesProvider != null)
228 ? dialerAppPackagesProvider.getPackages(userId) : null;
Svetoslav0010b702015-06-30 18:05:26 -0700229 String[] contactsSyncAdapterPackages = (syncAdapterPackagesProvider != null) ?
230 syncAdapterPackagesProvider.getPackages(ContactsContract.AUTHORITY, userId) : null;
231 String[] calendarSyncAdapterPackages = (syncAdapterPackagesProvider != null) ?
232 syncAdapterPackagesProvider.getPackages(CalendarContract.AUTHORITY, userId) : null;
Svet Ganovadc1cf42015-06-15 16:36:24 -0700233
234 synchronized (mService.mPackages) {
Svetoslav3e7d9772015-07-06 18:31:23 -0700235 // Installer
236 PackageParser.Package installerPackage = getSystemPackageLPr(
237 mService.mRequiredInstallerPackage);
238 if (installerPackage != null
239 && doesPackageSupportRuntimePermissions(installerPackage)) {
240 grantRuntimePermissionsLPw(installerPackage, STORAGE_PERMISSIONS, true, userId);
Svet Ganovadc1cf42015-06-15 16:36:24 -0700241 }
242
Svetoslav3e7d9772015-07-06 18:31:23 -0700243 // Verifier
244 PackageParser.Package verifierPackage = getSystemPackageLPr(
245 mService.mRequiredVerifierPackage);
246 if (verifierPackage != null
247 && doesPackageSupportRuntimePermissions(verifierPackage)) {
248 grantRuntimePermissionsLPw(verifierPackage, STORAGE_PERMISSIONS, true, userId);
Svet Ganovadc1cf42015-06-15 16:36:24 -0700249 }
250
251 // SetupWizard
252 Intent setupIntent = new Intent(Intent.ACTION_MAIN);
Svet Ganov50a8bf42015-07-15 11:04:18 -0700253 setupIntent.addCategory(Intent.CATEGORY_SETUP_WIZARD);
Svetoslavcdfd2302015-06-25 19:07:31 -0700254 PackageParser.Package setupPackage = getDefaultSystemHandlerActivityPackageLPr(
Svet Ganovadc1cf42015-06-15 16:36:24 -0700255 setupIntent, userId);
256 if (setupPackage != null
257 && doesPackageSupportRuntimePermissions(setupPackage)) {
258 grantRuntimePermissionsLPw(setupPackage, PHONE_PERMISSIONS, userId);
259 grantRuntimePermissionsLPw(setupPackage, CONTACTS_PERMISSIONS, userId);
Svet Ganovadc1cf42015-06-15 16:36:24 -0700260 }
261
Svet Ganovadc1cf42015-06-15 16:36:24 -0700262 // Camera
263 Intent cameraIntent = new Intent(MediaStore.ACTION_IMAGE_CAPTURE);
Svetoslavcdfd2302015-06-25 19:07:31 -0700264 PackageParser.Package cameraPackage = getDefaultSystemHandlerActivityPackageLPr(
Svet Ganovadc1cf42015-06-15 16:36:24 -0700265 cameraIntent, userId);
266 if (cameraPackage != null
267 && doesPackageSupportRuntimePermissions(cameraPackage)) {
268 grantRuntimePermissionsLPw(cameraPackage, CAMERA_PERMISSIONS, userId);
269 grantRuntimePermissionsLPw(cameraPackage, MICROPHONE_PERMISSIONS, userId);
Dianne Hackbornca8e6da2015-06-24 15:19:17 -0700270 grantRuntimePermissionsLPw(cameraPackage, STORAGE_PERMISSIONS, userId);
271 }
272
273 // Media provider
274 PackageParser.Package mediaStorePackage = getDefaultProviderAuthorityPackageLPr(
275 MediaStore.AUTHORITY, userId);
276 if (mediaStorePackage != null) {
Svetoslav0010b702015-06-30 18:05:26 -0700277 grantRuntimePermissionsLPw(mediaStorePackage, STORAGE_PERMISSIONS, true, userId);
Dianne Hackbornca8e6da2015-06-24 15:19:17 -0700278 }
279
280 // Downloads provider
281 PackageParser.Package downloadsPackage = getDefaultProviderAuthorityPackageLPr(
282 "downloads", userId);
283 if (downloadsPackage != null) {
Svetoslav0010b702015-06-30 18:05:26 -0700284 grantRuntimePermissionsLPw(downloadsPackage, STORAGE_PERMISSIONS, true, userId);
Dianne Hackbornca8e6da2015-06-24 15:19:17 -0700285 }
286
287 // Downloads UI
288 Intent downloadsUiIntent = new Intent(DownloadManager.ACTION_VIEW_DOWNLOADS);
Svetoslavcdfd2302015-06-25 19:07:31 -0700289 PackageParser.Package downloadsUiPackage = getDefaultSystemHandlerActivityPackageLPr(
Dianne Hackbornca8e6da2015-06-24 15:19:17 -0700290 downloadsUiIntent, userId);
291 if (downloadsUiPackage != null
292 && doesPackageSupportRuntimePermissions(downloadsUiPackage)) {
Svetoslav0010b702015-06-30 18:05:26 -0700293 grantRuntimePermissionsLPw(downloadsUiPackage, STORAGE_PERMISSIONS, true, userId);
Svet Ganovadc1cf42015-06-15 16:36:24 -0700294 }
295
Jeff Sharkey7186dd32015-06-30 17:32:45 -0700296 // Storage provider
297 PackageParser.Package storagePackage = getDefaultProviderAuthorityPackageLPr(
298 "com.android.externalstorage.documents", userId);
299 if (storagePackage != null) {
300 grantRuntimePermissionsLPw(storagePackage, STORAGE_PERMISSIONS, userId);
301 }
302
Svetoslava5a0d942015-07-01 19:49:58 -0700303 // Dialer
304 if (dialerAppPackageNames == null) {
305 Intent dialerIntent = new Intent(Intent.ACTION_DIAL);
306 PackageParser.Package dialerPackage = getDefaultSystemHandlerActivityPackageLPr(
307 dialerIntent, userId);
308 if (dialerPackage != null) {
309 grantDefaultPermissionsToDefaultSystemDialerAppLPr(dialerPackage, userId);
310 }
311 } else {
312 for (String dialerAppPackageName : dialerAppPackageNames) {
313 PackageParser.Package dialerPackage = getSystemPackageLPr(dialerAppPackageName);
314 if (dialerPackage != null) {
315 grantDefaultPermissionsToDefaultSystemDialerAppLPr(dialerPackage, userId);
316 }
317 }
318 }
319
Svetoslavcdfd2302015-06-25 19:07:31 -0700320 // SMS
Svetoslava5a0d942015-07-01 19:49:58 -0700321 if (smsAppPackageNames == null) {
322 Intent smsIntent = new Intent(Intent.ACTION_MAIN);
323 smsIntent.addCategory(Intent.CATEGORY_APP_MESSAGING);
324 PackageParser.Package smsPackage = getDefaultSystemHandlerActivityPackageLPr(
325 smsIntent, userId);
326 if (smsPackage != null) {
327 grantDefaultPermissionsToDefaultSystemSmsAppLPr(smsPackage, userId);
328 }
329 } else {
Svetoslavcdfd2302015-06-25 19:07:31 -0700330 for (String smsPackageName : smsAppPackageNames) {
Svetoslava5a0d942015-07-01 19:49:58 -0700331 PackageParser.Package smsPackage = getSystemPackageLPr(smsPackageName);
332 if (smsPackage != null) {
333 grantDefaultPermissionsToDefaultSystemSmsAppLPr(smsPackage, userId);
Svetoslavcdfd2302015-06-25 19:07:31 -0700334 }
335 }
Svet Ganovadc1cf42015-06-15 16:36:24 -0700336 }
337
Jack Yued79bf52015-07-06 17:23:52 -0700338 // Cell Broadcast Receiver
339 Intent cbrIntent = new Intent(Intents.SMS_CB_RECEIVED_ACTION);
340 PackageParser.Package cbrPackage =
341 getDefaultSystemHandlerActivityPackageLPr(cbrIntent, userId);
Jack Yued79bf52015-07-06 17:23:52 -0700342 if (cbrPackage != null && doesPackageSupportRuntimePermissions(cbrPackage)) {
343 grantRuntimePermissionsLPw(cbrPackage, SMS_PERMISSIONS, false, userId);
344 }
345
Svet Ganovadc1cf42015-06-15 16:36:24 -0700346 // Calendar
347 Intent calendarIntent = new Intent(Intent.ACTION_MAIN);
348 calendarIntent.addCategory(Intent.CATEGORY_APP_CALENDAR);
Svetoslavcdfd2302015-06-25 19:07:31 -0700349 PackageParser.Package calendarPackage = getDefaultSystemHandlerActivityPackageLPr(
Svet Ganovadc1cf42015-06-15 16:36:24 -0700350 calendarIntent, userId);
351 if (calendarPackage != null
352 && doesPackageSupportRuntimePermissions(calendarPackage)) {
353 grantRuntimePermissionsLPw(calendarPackage, CALENDAR_PERMISSIONS, userId);
354 grantRuntimePermissionsLPw(calendarPackage, CONTACTS_PERMISSIONS, userId);
Dianne Hackborn388cd2c2015-06-26 17:32:36 -0700355 grantRuntimePermissionsLPw(calendarPackage, ACCOUNTS_PERMISSIONS, userId);
356 }
357
358 // Calendar provider
359 PackageParser.Package calendarProviderPackage = getDefaultProviderAuthorityPackageLPr(
360 CalendarContract.AUTHORITY, userId);
361 if (calendarProviderPackage != null) {
362 grantRuntimePermissionsLPw(calendarProviderPackage, CONTACTS_PERMISSIONS, userId);
Svetoslav0010b702015-06-30 18:05:26 -0700363 grantRuntimePermissionsLPw(calendarProviderPackage, CALENDAR_PERMISSIONS,
364 true, userId);
Dianne Hackborn388cd2c2015-06-26 17:32:36 -0700365 grantRuntimePermissionsLPw(calendarProviderPackage, ACCOUNTS_PERMISSIONS, userId);
366 grantRuntimePermissionsLPw(calendarProviderPackage, STORAGE_PERMISSIONS, userId);
Svet Ganovadc1cf42015-06-15 16:36:24 -0700367 }
368
Svetoslav0010b702015-06-30 18:05:26 -0700369 // Calendar provider sync adapters
Svetoslava5a0d942015-07-01 19:49:58 -0700370 List<PackageParser.Package> calendarSyncAdapters = getHeadlessSyncAdapterPackagesLPr(
Svet Ganov50a8bf42015-07-15 11:04:18 -0700371 calendarSyncAdapterPackages, userId);
Svetoslav0010b702015-06-30 18:05:26 -0700372 final int calendarSyncAdapterCount = calendarSyncAdapters.size();
373 for (int i = 0; i < calendarSyncAdapterCount; i++) {
374 PackageParser.Package calendarSyncAdapter = calendarSyncAdapters.get(i);
375 if (doesPackageSupportRuntimePermissions(calendarSyncAdapter)) {
376 grantRuntimePermissionsLPw(calendarSyncAdapter, CALENDAR_PERMISSIONS, userId);
377 }
378 }
379
Svet Ganovadc1cf42015-06-15 16:36:24 -0700380 // Contacts
381 Intent contactsIntent = new Intent(Intent.ACTION_MAIN);
382 contactsIntent.addCategory(Intent.CATEGORY_APP_CONTACTS);
Svetoslavcdfd2302015-06-25 19:07:31 -0700383 PackageParser.Package contactsPackage = getDefaultSystemHandlerActivityPackageLPr(
Svet Ganovadc1cf42015-06-15 16:36:24 -0700384 contactsIntent, userId);
385 if (contactsPackage != null
386 && doesPackageSupportRuntimePermissions(contactsPackage)) {
387 grantRuntimePermissionsLPw(contactsPackage, CONTACTS_PERMISSIONS, userId);
388 grantRuntimePermissionsLPw(contactsPackage, PHONE_PERMISSIONS, userId);
Dianne Hackborn388cd2c2015-06-26 17:32:36 -0700389 grantRuntimePermissionsLPw(contactsPackage, ACCOUNTS_PERMISSIONS, userId);
390 }
391
Svetoslav0010b702015-06-30 18:05:26 -0700392 // Contacts provider sync adapters
Svetoslava5a0d942015-07-01 19:49:58 -0700393 List<PackageParser.Package> contactsSyncAdapters = getHeadlessSyncAdapterPackagesLPr(
Svet Ganov50a8bf42015-07-15 11:04:18 -0700394 contactsSyncAdapterPackages, userId);
Svetoslav0010b702015-06-30 18:05:26 -0700395 final int contactsSyncAdapterCount = contactsSyncAdapters.size();
396 for (int i = 0; i < contactsSyncAdapterCount; i++) {
397 PackageParser.Package contactsSyncAdapter = contactsSyncAdapters.get(i);
398 if (doesPackageSupportRuntimePermissions(contactsSyncAdapter)) {
399 grantRuntimePermissionsLPw(contactsSyncAdapter, CONTACTS_PERMISSIONS, userId);
400 }
401 }
402
Dianne Hackborn388cd2c2015-06-26 17:32:36 -0700403 // Contacts provider
404 PackageParser.Package contactsProviderPackage = getDefaultProviderAuthorityPackageLPr(
405 ContactsContract.AUTHORITY, userId);
406 if (contactsProviderPackage != null) {
Svetoslav0010b702015-06-30 18:05:26 -0700407 grantRuntimePermissionsLPw(contactsProviderPackage, CONTACTS_PERMISSIONS,
408 true, userId);
Makoto Onuki7a4082e2015-07-06 16:59:36 -0700409 grantRuntimePermissionsLPw(contactsProviderPackage, PHONE_PERMISSIONS,
410 true, userId);
Dianne Hackborn388cd2c2015-06-26 17:32:36 -0700411 grantRuntimePermissionsLPw(contactsProviderPackage, ACCOUNTS_PERMISSIONS, userId);
412 grantRuntimePermissionsLPw(contactsProviderPackage, STORAGE_PERMISSIONS, userId);
413 }
414
415 // Device provisioning
416 Intent deviceProvisionIntent = new Intent(
417 DevicePolicyManager.ACTION_PROVISION_MANAGED_DEVICE);
Svet Ganovb6e00132015-06-29 20:19:25 -0700418 PackageParser.Package deviceProvisionPackage =
419 getDefaultSystemHandlerActivityPackageLPr(deviceProvisionIntent, userId);
Dianne Hackborn388cd2c2015-06-26 17:32:36 -0700420 if (deviceProvisionPackage != null
421 && doesPackageSupportRuntimePermissions(deviceProvisionPackage)) {
Amith Yamasania72eac62015-07-06 09:24:08 -0700422 grantRuntimePermissionsLPw(deviceProvisionPackage, ACCOUNTS_PERMISSIONS, userId);
Svet Ganovadc1cf42015-06-15 16:36:24 -0700423 }
424
425 // Maps
426 Intent mapsIntent = new Intent(Intent.ACTION_MAIN);
427 mapsIntent.addCategory(Intent.CATEGORY_APP_MAPS);
Svetoslavcdfd2302015-06-25 19:07:31 -0700428 PackageParser.Package mapsPackage = getDefaultSystemHandlerActivityPackageLPr(
Svet Ganovadc1cf42015-06-15 16:36:24 -0700429 mapsIntent, userId);
430 if (mapsPackage != null
431 && doesPackageSupportRuntimePermissions(mapsPackage)) {
432 grantRuntimePermissionsLPw(mapsPackage, LOCATION_PERMISSIONS, userId);
433 }
434
Svet Ganov200d4942015-07-01 20:46:02 -0700435 // Gallery
436 Intent galleryIntent = new Intent(Intent.ACTION_MAIN);
437 galleryIntent.addCategory(Intent.CATEGORY_APP_GALLERY);
438 PackageParser.Package galleryPackage = getDefaultSystemHandlerActivityPackageLPr(
439 galleryIntent, userId);
440 if (galleryPackage != null
441 && doesPackageSupportRuntimePermissions(galleryPackage)) {
442 grantRuntimePermissionsLPw(galleryPackage, STORAGE_PERMISSIONS, userId);
443 }
444
Svet Ganovadc1cf42015-06-15 16:36:24 -0700445 // Email
446 Intent emailIntent = new Intent(Intent.ACTION_MAIN);
447 emailIntent.addCategory(Intent.CATEGORY_APP_EMAIL);
Svetoslavcdfd2302015-06-25 19:07:31 -0700448 PackageParser.Package emailPackage = getDefaultSystemHandlerActivityPackageLPr(
Svet Ganovadc1cf42015-06-15 16:36:24 -0700449 emailIntent, userId);
450 if (emailPackage != null
451 && doesPackageSupportRuntimePermissions(emailPackage)) {
452 grantRuntimePermissionsLPw(emailPackage, CONTACTS_PERMISSIONS, userId);
453 }
454
455 // Browser
Svetoslavcdfd2302015-06-25 19:07:31 -0700456 PackageParser.Package browserPackage = null;
457 String defaultBrowserPackage = mService.getDefaultBrowserPackageName(userId);
458 if (defaultBrowserPackage != null) {
459 browserPackage = getPackageLPr(defaultBrowserPackage);
460 }
461 if (browserPackage == null) {
462 Intent browserIntent = new Intent(Intent.ACTION_MAIN);
463 browserIntent.addCategory(Intent.CATEGORY_APP_BROWSER);
464 browserPackage = getDefaultSystemHandlerActivityPackageLPr(
465 browserIntent, userId);
466 }
Svet Ganovadc1cf42015-06-15 16:36:24 -0700467 if (browserPackage != null
468 && doesPackageSupportRuntimePermissions(browserPackage)) {
469 grantRuntimePermissionsLPw(browserPackage, LOCATION_PERMISSIONS, userId);
470 }
471
472 // IME
473 if (imePackageNames != null) {
474 for (String imePackageName : imePackageNames) {
475 PackageParser.Package imePackage = getSystemPackageLPr(imePackageName);
476 if (imePackage != null
477 && doesPackageSupportRuntimePermissions(imePackage)) {
478 grantRuntimePermissionsLPw(imePackage, CONTACTS_PERMISSIONS, userId);
479 }
480 }
481 }
482
483 // Voice interaction
484 if (voiceInteractPackageNames != null) {
485 for (String voiceInteractPackageName : voiceInteractPackageNames) {
486 PackageParser.Package voiceInteractPackage = getSystemPackageLPr(
487 voiceInteractPackageName);
488 if (voiceInteractPackage != null
489 && doesPackageSupportRuntimePermissions(voiceInteractPackage)) {
490 grantRuntimePermissionsLPw(voiceInteractPackage,
491 CONTACTS_PERMISSIONS, userId);
492 grantRuntimePermissionsLPw(voiceInteractPackage,
493 CALENDAR_PERMISSIONS, userId);
494 grantRuntimePermissionsLPw(voiceInteractPackage,
495 MICROPHONE_PERMISSIONS, userId);
496 grantRuntimePermissionsLPw(voiceInteractPackage,
497 PHONE_PERMISSIONS, userId);
498 grantRuntimePermissionsLPw(voiceInteractPackage,
499 SMS_PERMISSIONS, userId);
500 grantRuntimePermissionsLPw(voiceInteractPackage,
501 LOCATION_PERMISSIONS, userId);
502 }
503 }
504 }
505
506 // Location
507 if (locationPackageNames != null) {
508 for (String packageName : locationPackageNames) {
509 PackageParser.Package locationPackage = getSystemPackageLPr(packageName);
510 if (locationPackage != null
511 && doesPackageSupportRuntimePermissions(locationPackage)) {
512 grantRuntimePermissionsLPw(locationPackage, CONTACTS_PERMISSIONS, userId);
513 grantRuntimePermissionsLPw(locationPackage, CALENDAR_PERMISSIONS, userId);
514 grantRuntimePermissionsLPw(locationPackage, MICROPHONE_PERMISSIONS, userId);
515 grantRuntimePermissionsLPw(locationPackage, PHONE_PERMISSIONS, userId);
516 grantRuntimePermissionsLPw(locationPackage, SMS_PERMISSIONS, userId);
Svetoslav0010b702015-06-30 18:05:26 -0700517 grantRuntimePermissionsLPw(locationPackage, LOCATION_PERMISSIONS,
518 true, userId);
Svet Ganovadc1cf42015-06-15 16:36:24 -0700519 grantRuntimePermissionsLPw(locationPackage, CAMERA_PERMISSIONS, userId);
520 grantRuntimePermissionsLPw(locationPackage, SENSORS_PERMISSIONS, userId);
521 grantRuntimePermissionsLPw(locationPackage, STORAGE_PERMISSIONS, userId);
522 }
523 }
524 }
Jeff Davidson2a880312015-06-22 16:54:34 -0700525
Jeff Sharkey7186dd32015-06-30 17:32:45 -0700526 // Music
527 Intent musicIntent = new Intent(Intent.ACTION_VIEW);
528 musicIntent.addCategory(Intent.CATEGORY_DEFAULT);
529 musicIntent.setDataAndType(Uri.fromFile(new File("foo.mp3")),
530 AUDIO_MIME_TYPE);
531 PackageParser.Package musicPackage = getDefaultSystemHandlerActivityPackageLPr(
532 musicIntent, userId);
533 if (musicPackage != null
534 && doesPackageSupportRuntimePermissions(musicPackage)) {
535 grantRuntimePermissionsLPw(musicPackage, STORAGE_PERMISSIONS, userId);
536 }
537
Svet Ganovba3ba812015-06-26 10:54:06 -0700538 mService.mSettings.onDefaultRuntimePermissionsGrantedLPr(userId);
Svet Ganovadc1cf42015-06-15 16:36:24 -0700539 }
540 }
541
Svetoslava5a0d942015-07-01 19:49:58 -0700542 private void grantDefaultPermissionsToDefaultSystemDialerAppLPr(
543 PackageParser.Package dialerPackage, int userId) {
544 if (doesPackageSupportRuntimePermissions(dialerPackage)) {
545 grantRuntimePermissionsLPw(dialerPackage, PHONE_PERMISSIONS, userId);
546 grantRuntimePermissionsLPw(dialerPackage, CONTACTS_PERMISSIONS, userId);
547 grantRuntimePermissionsLPw(dialerPackage, SMS_PERMISSIONS, userId);
548 grantRuntimePermissionsLPw(dialerPackage, MICROPHONE_PERMISSIONS, userId);
549 }
550 }
551
552
553 private void grantDefaultPermissionsToDefaultSystemSmsAppLPr(
554 PackageParser.Package smsPackage, int userId) {
555 if (doesPackageSupportRuntimePermissions(smsPackage)) {
556 grantRuntimePermissionsLPw(smsPackage, PHONE_PERMISSIONS, userId);
557 grantRuntimePermissionsLPw(smsPackage, CONTACTS_PERMISSIONS, userId);
558 grantRuntimePermissionsLPw(smsPackage, SMS_PERMISSIONS, userId);
559 }
560 }
561
562
Svetoslavcdfd2302015-06-25 19:07:31 -0700563 public void grantDefaultPermissionsToDefaultSmsAppLPr(String packageName, int userId) {
564 Log.i(TAG, "Granting permissions to default sms app for user:" + userId);
565 if (packageName == null) {
566 return;
567 }
568 PackageParser.Package smsPackage = getPackageLPr(packageName);
569 if (smsPackage != null && doesPackageSupportRuntimePermissions(smsPackage)) {
570 grantRuntimePermissionsLPw(smsPackage, PHONE_PERMISSIONS, userId);
571 grantRuntimePermissionsLPw(smsPackage, CONTACTS_PERMISSIONS, userId);
572 grantRuntimePermissionsLPw(smsPackage, SMS_PERMISSIONS, userId);
573 }
574 }
575
576 public void grantDefaultPermissionsToDefaultDialerAppLPr(String packageName, int userId) {
577 Log.i(TAG, "Granting permissions to default dialer app for user:" + userId);
578 if (packageName == null) {
579 return;
580 }
581 PackageParser.Package dialerPackage = getPackageLPr(packageName);
582 if (dialerPackage != null
583 && doesPackageSupportRuntimePermissions(dialerPackage)) {
584 grantRuntimePermissionsLPw(dialerPackage, PHONE_PERMISSIONS, userId);
585 grantRuntimePermissionsLPw(dialerPackage, CONTACTS_PERMISSIONS, userId);
586 grantRuntimePermissionsLPw(dialerPackage, SMS_PERMISSIONS, userId);
587 grantRuntimePermissionsLPw(dialerPackage, MICROPHONE_PERMISSIONS, userId);
588 }
589 }
590
591 public void grantDefaultPermissionsToEnabledCarrierAppsLPr(String[] packageNames, int userId) {
592 Log.i(TAG, "Granting permissions to enabled carrier apps for user:" + userId);
593 if (packageNames == null) {
594 return;
595 }
596 for (String packageName : packageNames) {
597 PackageParser.Package carrierPackage = getSystemPackageLPr(packageName);
598 if (carrierPackage != null
599 && doesPackageSupportRuntimePermissions(carrierPackage)) {
600 grantRuntimePermissionsLPw(carrierPackage, PHONE_PERMISSIONS, userId);
601 grantRuntimePermissionsLPw(carrierPackage, LOCATION_PERMISSIONS, userId);
602 }
603 }
604 }
605
606 public void grantDefaultPermissionsToDefaultBrowserLPr(String packageName, int userId) {
607 Log.i(TAG, "Granting permissions to default browser for user:" + userId);
608 if (packageName == null) {
609 return;
610 }
611 PackageParser.Package browserPackage = getSystemPackageLPr(packageName);
612 if (browserPackage != null
613 && doesPackageSupportRuntimePermissions(browserPackage)) {
614 grantRuntimePermissionsLPw(browserPackage, LOCATION_PERMISSIONS, userId);
615 }
616 }
617
Svetoslavcdfd2302015-06-25 19:07:31 -0700618 private PackageParser.Package getDefaultSystemHandlerActivityPackageLPr(
Svet Ganovadc1cf42015-06-15 16:36:24 -0700619 Intent intent, int userId) {
Svetoslav8b24a1d2015-07-13 17:37:32 -0700620 List<ResolveInfo> handlers = mService.mActivities.queryIntent(intent,
621 intent.resolveType(mService.mContext.getContentResolver()),
622 PackageManager.GET_DISABLED_COMPONENTS, userId);
Svet Ganov50a8bf42015-07-15 11:04:18 -0700623 if (handlers == null) {
624 return null;
625 }
Svet Ganovadc1cf42015-06-15 16:36:24 -0700626 final int handlerCount = handlers.size();
627 for (int i = 0; i < handlerCount; i++) {
628 ResolveInfo handler = handlers.get(i);
Svet Ganovadc1cf42015-06-15 16:36:24 -0700629 PackageParser.Package handlerPackage = getSystemPackageLPr(
630 handler.activityInfo.packageName);
631 if (handlerPackage != null) {
632 return handlerPackage;
633 }
634 }
635 return null;
636 }
637
Svetoslav0010b702015-06-30 18:05:26 -0700638 private List<PackageParser.Package> getHeadlessSyncAdapterPackagesLPr(
639 String[] syncAdapterPackageNames, int userId) {
640 List<PackageParser.Package> syncAdapterPackages = new ArrayList<>();
641
642 Intent homeIntent = new Intent(Intent.ACTION_MAIN);
643 homeIntent.addCategory(Intent.CATEGORY_HOME);
644
645 for (String syncAdapterPackageName : syncAdapterPackageNames) {
646 homeIntent.setPackage(syncAdapterPackageName);
647
Svetoslav8b24a1d2015-07-13 17:37:32 -0700648 List<ResolveInfo> homeActivities = mService.mActivities.queryIntent(homeIntent,
649 homeIntent.resolveType(mService.mContext.getContentResolver()),
650 PackageManager.GET_DISABLED_COMPONENTS, userId);
Svetoslav0010b702015-06-30 18:05:26 -0700651 if (!homeActivities.isEmpty()) {
652 continue;
653 }
654
655 PackageParser.Package syncAdapterPackage = getSystemPackageLPr(syncAdapterPackageName);
656 if (syncAdapterPackage != null) {
657 syncAdapterPackages.add(syncAdapterPackage);
658 }
659 }
660
661 return syncAdapterPackages;
662 }
663
Dianne Hackbornca8e6da2015-06-24 15:19:17 -0700664 private PackageParser.Package getDefaultProviderAuthorityPackageLPr(
665 String authority, int userId) {
666 ProviderInfo provider = mService.resolveContentProvider(authority, 0, userId);
667 if (provider != null) {
668 return getSystemPackageLPr(provider.packageName);
669 }
670 return null;
671 }
672
Svetoslavcdfd2302015-06-25 19:07:31 -0700673 private PackageParser.Package getPackageLPr(String packageName) {
674 return mService.mPackages.get(packageName);
675 }
676
Svet Ganovadc1cf42015-06-15 16:36:24 -0700677 private PackageParser.Package getSystemPackageLPr(String packageName) {
Svetoslavcdfd2302015-06-25 19:07:31 -0700678 PackageParser.Package pkg = getPackageLPr(packageName);
Svet Ganovadc1cf42015-06-15 16:36:24 -0700679 if (pkg != null && pkg.isSystemApp()) {
Svet Ganov824d4532015-07-10 18:25:48 -0700680 return !isSysComponentOrPersistentPlatformSignedPrivApp(pkg) ? pkg : null;
Svet Ganovadc1cf42015-06-15 16:36:24 -0700681 }
682 return null;
683 }
684
Svet Ganovadc1cf42015-06-15 16:36:24 -0700685 private void grantRuntimePermissionsLPw(PackageParser.Package pkg, Set<String> permissions,
686 int userId) {
Svet Ganov6a166af2015-06-30 10:15:44 -0700687 grantRuntimePermissionsLPw(pkg, permissions, false, userId);
Svet Ganov6a166af2015-06-30 10:15:44 -0700688 }
689
690 private void grantRuntimePermissionsLPw(PackageParser.Package pkg, Set<String> permissions,
691 boolean systemFixed, int userId) {
Svet Ganovadc1cf42015-06-15 16:36:24 -0700692 List<String> requestedPermissions = pkg.requestedPermissions;
693
694 if (pkg.isUpdatedSystemApp()) {
695 PackageSetting sysPs = mService.mSettings.getDisabledSystemPkgLPr(pkg.packageName);
696 if (sysPs != null) {
697 requestedPermissions = sysPs.pkg.requestedPermissions;
698 }
699 }
700
701 final int permissionCount = requestedPermissions.size();
702 for (int i = 0; i < permissionCount; i++) {
703 String permission = requestedPermissions.get(i);
704 if (permissions.contains(permission)) {
705 final int flags = mService.getPermissionFlags(permission, pkg.packageName, userId);
706
707 // If any flags are set to the permission, then it is either set in
708 // its current state by the system or device/profile owner or the user.
709 // In all these cases we do not want to clobber the current state.
710 if (flags == 0) {
711 mService.grantRuntimePermission(pkg.packageName, permission, userId);
712 if (DEBUG) {
713 Log.i(TAG, "Granted " + permission + " to default handler "
714 + pkg.packageName);
715 }
Svet Ganov6a166af2015-06-30 10:15:44 -0700716
Svet Ganov77ab6a82015-07-03 12:03:02 -0700717 int newFlags = PackageManager.FLAG_PERMISSION_GRANTED_BY_DEFAULT;
Svet Ganov6a166af2015-06-30 10:15:44 -0700718 if (systemFixed) {
Svet Ganov77ab6a82015-07-03 12:03:02 -0700719 newFlags |= PackageManager.FLAG_PERMISSION_SYSTEM_FIXED;
Svet Ganov6a166af2015-06-30 10:15:44 -0700720 }
Svet Ganov77ab6a82015-07-03 12:03:02 -0700721
722 mService.updatePermissionFlags(permission, pkg.packageName,
723 newFlags, newFlags, userId);
Svet Ganovadc1cf42015-06-15 16:36:24 -0700724 }
725 }
726 }
727 }
728
Svet Ganov824d4532015-07-10 18:25:48 -0700729 private boolean isSysComponentOrPersistentPlatformSignedPrivApp(PackageParser.Package pkg) {
730 if (UserHandle.getAppId(pkg.applicationInfo.uid) < FIRST_APPLICATION_UID) {
731 return true;
732 }
733 if ((pkg.applicationInfo.privateFlags & ApplicationInfo.PRIVATE_FLAG_PRIVILEGED) == 0
734 || (pkg.applicationInfo.flags & ApplicationInfo.FLAG_PERSISTENT) == 0) {
735 return false;
736 }
737 return PackageManagerService.compareSignatures(mService.mPlatformPackage.mSignatures,
738 pkg.mSignatures) == PackageManager.SIGNATURE_MATCH;
Svet Ganovadc1cf42015-06-15 16:36:24 -0700739 }
740
741 private static boolean doesPackageSupportRuntimePermissions(PackageParser.Package pkg) {
742 return pkg.applicationInfo.targetSdkVersion > Build.VERSION_CODES.LOLLIPOP_MR1;
743 }
744}