package: "android.security" container: "system" flag { name: "extend_ecm_to_all_settings" namespace: "responsible_apis" description: "Allow all app settings to be restrictable via configuration" bug: "297372999" } flag { name: "asm_restrictions_enabled" is_exported: true namespace: "responsible_apis" description: "Enables APIs for ASM" bug: "230590090" } flag { name: "asm_restrictions_v2" namespace: "responsible_apis" description: "Enables ASM restrictions for activity starts and finishes" bug: "416033243" } flag { name: "asm_toasts_enabled" namespace: "responsible_apis" description: "Enables toasts when ASM restrictions are triggered" bug: "230590090" } flag { name: "asm_ignore_grace_period_exemption" namespace: "responsible_apis" description: "Ignore grace period exemption for ASM apps" bug: "367702727" } flag { name: "content_uri_permission_apis" is_exported: true namespace: "responsible_apis" description: "Enables the content URI permission APIs" bug: "293467489" } flag { name: "enforce_intent_filter_match" is_exported: true namespace: "responsible_apis" description: "Make delivered intents match components' intent filters" bug: "293560872" } flag { name: "block_null_action_intents" namespace: "responsible_apis" description: "Do not allow intents without an action to match any intent filters" bug: "293560872" } flag { name: "asm_opt_system_into_enforcement" namespace: "responsible_apis" description: "Opt the system into enforcement of BAL" bug: "339403750" } flag { name: "aapm_api" namespace: "responsible_apis" description: "Android Advanced Protection Mode Service and Manager" is_exported: true bug: "352420507" is_fixed_read_only: true } flag { name: "prevent_intent_redirect" namespace: "responsible_apis" description: "Prevent intent redirect attacks" bug: "361143368" is_fixed_read_only: true is_exported: true } flag { name: "prevent_intent_redirect_abort_or_throw_exception" namespace: "responsible_apis" description: "Prevent intent redirect attacks by aborting or throwing security exception" bug: "361143368" } flag { name: "prevent_intent_redirect_show_toast" namespace: "responsible_apis" description: "Prevent intent redirect attacks by showing a toast when activity start is blocked" bug: "361143368" is_fixed_read_only: true } flag { name: "prevent_intent_redirect_show_toast_if_nested_keys_not_collected_r_w" namespace: "responsible_apis" description: "Prevent intent redirect attacks by showing a toast if not yet collected" bug: "361143368" } flag { name: "prevent_intent_redirect_throw_exception_if_nested_keys_not_collected" namespace: "responsible_apis" description: "Prevent intent redirect attacks by throwing exception if the intent does not collect nested keys" bug: "361143368" } flag { name: "prevent_intent_redirect_collect_nested_keys_on_server_if_not_collected" namespace: "responsible_apis" description: "Prevent intent redirect attacks by collecting nested keys on server if not yet collected" bug: "361143368" is_fixed_read_only: true } flag { name: "enable_intent_matching_flags" is_exported: true namespace: "permissions" is_fixed_read_only: true description: "Applies intentMatchingFlags while matching intents to application components" bug: "364354494" } flag { name: "aapm_feature_disable_install_unknown_sources" namespace: "responsible_apis" description: "Android Advanced Protection Mode Feature: Disable Install Unknown Sources" bug: "369361373" } flag { name: "aapm_feature_disable_cellular_2g" namespace: "responsible_apis" description: "Android Advanced Protection Mode Feature: Disable Cellular 2G" bug: "377748286" } flag { name: "aapm_feature_usb_data_protection" namespace: "preload_safety" description: "Android Advanced Protection Mode Feature: Usb Data Protection" bug: "389958463" } flag { name: "aapm_feature_usb_data_protection_delay_disable_auto_only" namespace: "preload_safety" description: "Limiting the delay disable for USB upon unplug only to auto connections" bug: "444044714" } flag { name: "aapm_feature_usb_data_protection_disable_data_for_charger_upon_lock" namespace: "preload_safety" description: "Disable USB data upon lock if existing connection is power brick" bug: "444044714" } flag { name: "implicit_uri_grants_restricted_for_sendmultiple_imagecapture_actions" namespace: "permissions" description: "Flag for restricting implicit URI grants on SendMultiple and ImageCapture intents" bug: "295238578" } flag { name: "implicit_uri_grants_restricted_for_send_action" namespace: "permissions" description: "Flag for restricting implicit URI grants on Send action intents" bug: "295238578" } flag { name: "enable_intent_firewall_extra_key_value_filter" namespace: "responsible_apis" description: "Flag for enable ExtraKeyValueFilter in IntentFirewall" bug: "428733109" } flag { name: "enable_intent_firewall_component_class_filter" namespace: "responsible_apis" description: "Flag for enabling component-class-filter in IntentFirewall" bug: "428733109" } flag { name: "fail_on_parcel_size_mismatch" namespace: "responsible_apis" description: "Flag for failing instead of logging in case of parcel size mismatches" bug: "416031865" } flag { name: "wtf_bundle_defuse" namespace: "responsible_apis" description: "Flag for wtf logging when defuse is enabled." bug: "254848919" metadata { purpose: PURPOSE_BUGFIX } } flag { name: "deprecate_bundle_defuse" namespace: "responsible_apis" description: "Flag for failing instead of logging when defuse is enabled." bug: "254848919" metadata { purpose: PURPOSE_BUGFIX } } flag { name: "service_uprobestats" namespace: "responsible_apis" description: "Flag that enables the uprobestats system service" bug: "408041227" } flag { name: "check_application_thread_called_by_system" namespace: "responsible_apis" description: "Allow only the system to call methods on ApplicationThread." bug: "317346668" metadata { purpose: PURPOSE_BUGFIX } }