/*
 * Copyright (C) 2024 The Android Open Source Project
 *
 * Licensed under the Apache License, Version 2.0 (the "License");
 * you may not use this file except in compliance with the License.
 * You may obtain a copy of the License at
 *
 *      http://www.apache.org/licenses/LICENSE-2.0
 *
 * Unless required by applicable law or agreed to in writing, software
 * distributed under the License is distributed on an "AS IS" BASIS,
 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 * See the License for the specific language governing permissions and
 * limitations under the License.
 */

syntax = "proto2";

package android.os.statsd.uprobestats;

import "frameworks/proto_logging/stats/atoms.proto";
import "frameworks/proto_logging/stats/atom_field_options.proto";

option java_package = "com.android.os.uprobestats";
option java_multiple_files = true;

extend Atom {
  optional TestUprobeStatsAtomReported test_uprobestats_atom_reported = 915;
  optional SetComponentEnabledSettingReported set_component_enabled_setting_reported = 1018 [(module) = "uprobestats"];
  optional BalProcessControllerAddBoundClientUidReported bal_process_controller_add_bound_client_uid_reported = 1019 [deprecated = true];
  optional BindServiceLockedWithBalFlagsReported bind_service_locked_with_bal_flags_reported = 1045 [(module) = "uprobestats"];
  optional AndroidGraphicsBitmapAllocated android_graphics_bitmap_allocated =
          1039 [(module) = "uprobestats"];
  optional AndroidGraphicsBitmapAllocationSnapshot
      android_graphics_bitmap_allocation_snapshot = 1118 [(module) = "uprobestats"];
  optional DisabledLauncherActivityUidsReported disabled_launcher_activity_uids_reported = 1185 [(module) = "uprobestats"];
  optional BindServiceLockedWithBalFlagsUidsReported bind_service_locked_with_bal_flags_uids_reported = 1186 [(module) = "uprobestats"];
}

/* Test atom, specifically for UprobeStats tests, not logged anywhere */
message TestUprobeStatsAtomReported {
    optional int64 first_field = 1;
    optional int64 second_field = 2;
    optional int64 third_field = 3;
}

/**
  * Logged by uprobestats on sampled devices, when
  * components have been enabled/disabled.
  *
  * This event happens quite frequently (multiple times per second) on boot,
  * and rarely thereafter. Implementation filters out packages in the
  * android and com.android namespaces, and states lower than
  * COMPONENT_ENABLED_STATE_DISABLED, which suppresses
  * nearly all of those early boot events.
  *
  * Given the above, expected logging rate is on the order of tens
  * in a day.
  */
message SetComponentEnabledSettingReported {
    optional string package_name = 1;
    optional string class_name = 2;
    optional int32 new_state = 3;
    optional string calling_package_name = 4;
    optional bool is_launcher_activity = 5;
}

/**
  * DEPRECATED - this message was never usesd and is replaced by
  * BindServiceLockedWithBalFlagsReported.
  *
  * Logged by uprobestats on sampled devices, when
  * unprivileged apps bind to privileged apps that
  * are allowed to do BAL (e.g. apps managing companion devices).
  *
  * Expected logging rate is on the order of tens in a day.
  */
message BalProcessControllerAddBoundClientUidReported {
    optional int32 client_uid = 1 [(is_uid) = true];
    optional string client_package_name = 2;
    optional int32 bind_flags = 3;
}

/**
  * Flags that can be passed to Context.bindService.
  *
  * This should be kept in sync with the `BIND_` flags in
  * frameworks/base/core/java/android/content/Context.java.
  */
enum BindServiceFlags {
    UNSPECIFIED = 0;
    BIND_AUTO_CREATE = 0x0001;
    BIND_DEBUG_UNBIND = 0x0002;
    BIND_NOT_FOREGROUND = 0x0004;
    BIND_ABOVE_CLIENT = 0x0008;
    BIND_ALLOW_OOM_MANAGEMENT = 0x0010;
    BIND_WAIVE_PRIORITY = 0x0020;
    BIND_IMPORTANT = 0x0040;
    BIND_ADJUST_WITH_ACTIVITY = 0x0080;
    BIND_NOT_PERCEPTIBLE = 0x00000100;
    BIND_ALLOW_ACTIVITY_STARTS = 0X000000200;
    BIND_INCLUDE_CAPABILITIES = 0x000001000;
    BIND_SHARED_ISOLATED_PROCESS = 0x00002000;
    BIND_PACKAGE_ISOLATED_PROCESS = 0x4000; // 1 << 14
    BIND_NOT_APP_COMPONENT_USAGE = 0x00008000;
    BIND_ALMOST_PERCEPTIBLE = 0x000010000;
    BIND_BYPASS_POWER_NETWORK_RESTRICTIONS = 0x00020000;
    BIND_ALLOW_FOREGROUND_SERVICE_STARTS_FROM_BACKGROUND = 0x00040000;
    BIND_SCHEDULE_LIKE_TOP_APP = 0x00080000;
    BIND_ALLOW_BACKGROUND_ACTIVITY_STARTS = 0x00100000;
    BIND_RESTRICT_ASSOCIATIONS = 0x00200000;
    BIND_ALLOW_INSTANT = 0x00400000;
    BIND_IMPORTANT_BACKGROUND = 0x00800000;
    BIND_ALLOW_WHITELIST_MANAGEMENT = 0x01000000;
    BIND_FOREGROUND_SERVICE_WHILE_AWAKE = 0x02000000;
    BIND_FOREGROUND_SERVICE = 0x04000000;
    BIND_TREAT_LIKE_ACTIVITY = 0x08000000;
    // @deprecated Repurposed to {@link #BIND_TREAT_LIKE_VISIBLE_FOREGROUND_SERVICE}.
    // BIND_VISIBLE = 0x10000000;
    BIND_TREAT_LIKE_VISIBLE_FOREGROUND_SERVICE = 0x10000000;
    BIND_SHOWING_UI = 0x20000000;
    BIND_NOT_VISIBLE = 0x40000000;
    // java.lang.Long flags that are not supported by proto enum.
    // BIND_EXTERNAL_SERVICE = 0x80000000;
    // BIND_EXTERNAL_SERVICE_LONG = 0x4000000000000000; // 1L << 62
    // BIND_BYPASS_USER_NETWORK_RESTRICTIONS = 0x100000000; // 0x1_0000_0000L
    // BIND_MATCH_QUARANTINED_COMPONENTS = 0x200000000 // 0x2_0000_0000L
    // BIND_ALLOW_FREEZE = 0x400000000; // 0x4_0000_0000L
}

/**
  * Logged by uprobestats on sampled devices, when
  * unprivileged apps bind to privileged apps that
  * are allowed to do BAL (e.g. apps managing companion devices).
  *
  * Expected logging rate is on the order of tens in a day.
  */
message BindServiceLockedWithBalFlagsReported {
    // The package name of the intent passed to bindServiceLocked.
    optional string intent_package_name = 1;
    // The flags passed to the bindServiceLocked call.
    // Must be one or a combination of the types in BindServiceFlags enum above.
    optional int64 flags = 2;
    // The package name of the app that called bindServiceLocked.
    optional string calling_package_name = 3;
    // The action of the intent passed to bindServiceLocked.
    optional string intent_action = 4;
    // The package name of the component passed to bindServiceLocked.
    // This package may gain the BAL capabilities of the calling_package_name.
    optional string intent_component_name_package = 5;
    // The class name of the component passed to bindServiceLocked.
    optional string intent_component_name_class = 6;
}

/**
 * Records Bitmap allocation events.
 *
 * Logged via Hummingbird for probes at android.graphics.Bitmap constructor.
 *
 * Estimated Logging Rate:
 *   Peak: 100 times in a minute | Avg: O(hundreds) per device per day
 */
message AndroidGraphicsBitmapAllocated {
    optional int32 uid = 1 [(is_uid) = true];
    optional int32 width = 2;
    optional int32 height = 3;
}

/**
 * Records snapshot of Bitmap allocations resident in memory.
 *
 * Logged via Hummingbird for probes at android.graphics.Bitmap constructor.
 *
 * Estimated Logging Rate:
 *   Peak: 100 times in a second | Avg: O(hundreds) per device per day
 */
message AndroidGraphicsBitmapAllocationSnapshot {
    optional int32 uid = 1 [(is_uid) = true];
    optional int32 width = 2;
    optional int32 height = 3;

    enum PixelStorageType {
      PIXEL_STORAGE_TYPE_UNSPECIFIED = 0;
      PIXEL_STORAGE_TYPE_HEAP = 1;
      PIXEL_STORAGE_TYPE_ASHMEM = 2;
      PIXEL_STORAGE_TYPE_HARDWARE = 3;
      PIXEL_STORAGE_TYPE_WRAPPED_PIXEL_REF = 4;
    };

    optional PixelStorageType pixel_storage_type = 4;

    // Unique identifier for the snapshot, generated randomly on the device
    // every time a snapshot is taken. Bitmaps in the same snapshot will have
    // the same snapshot_id.
    optional int64 snapshot_id = 5;
    enum SnapshotType {
        SNAPSHOT_TYPE_UNSPECIFIED = 0;
        SNAPSHOT_TYPE_RANDOM_SAMPLE = 1;
        SNAPSHOT_TYPE_MAX_ALLOCATION_SIZE = 2;
    }
    optional SnapshotType snapshot_type = 6;

    optional string activity_name = 7;
}

/**
  * Logged by uprobestats when launcher activities are disabled.
  * Disabling the launcher activity is a common abuse technique to
  * hide the malicious app's icon from the launcher.
  *
  * Logging rate is on the order of tens in a day.
  */
message DisabledLauncherActivityUidsReported {
    optional int32 calling_uid = 1 [(is_uid) = true];
    optional int32 disabled_activity_uid = 2 [(is_uid) = true];
}

/**
  * Logged by uprobestats on when apps bind to other apps while
  * passing along their BAL privileges (using the BAL flags).
  * Only privileged apps are allowed to do BAL
  * (e.g. apps managing companion devices), and vulnerabilities in those
  * apps can lead to unwanted BAL by malicious apps. This metric is used
  * to detect such vulnerabilities.
  *
  * Expected logging rate is on the order of tens in a day.
  */
message BindServiceLockedWithBalFlagsUidsReported {
    optional int32 binder_uid = 1 [(is_uid) = true];
    optional int32 bindee_uid = 2 [(is_uid) = true];
}