Files
Meshtastic-Android/androidApp/src/main/AndroidManifest.xml
T

411 lines
20 KiB
XML

<?xml version="1.0" encoding="utf-8"?>
<!--
~ Copyright (c) 2025 Meshtastic LLC
~
~ This program is free software: you can redistribute it and/or modify
~ it under the terms of the GNU General Public License as published by
~ the Free Software Foundation, either version 3 of the License, or
~ (at your option) any later version.
~
~ This program is distributed in the hope that it will be useful,
~ but WITHOUT ANY WARRANTY; without even the implied warranty of
~ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
~ GNU General Public License for more details.
~
~ You should have received a copy of the GNU General Public License
~ along with this program. If not, see <https://www.gnu.org/licenses/>.
-->
<manifest xmlns:android="http://schemas.android.com/apk/res/android"
xmlns:tools="http://schemas.android.com/tools"
tools:ignore="GoogleAppIndexingWarning">
<!-- If a device is missing a GPS - we will still be able to work though , must be before uses-permission-->
<uses-feature
android:name="android.hardware.location"
android:required="false" />
<uses-feature
android:name="android.hardware.location.gps"
android:required="false" />
<!-- Request legacy Bluetooth permissions on older devices -->
<uses-permission android:name="android.permission.BLUETOOTH"
android:maxSdkVersion="30" />
<uses-permission android:name="android.permission.BLUETOOTH_ADMIN"
android:maxSdkVersion="30" />
<!-- API 31+ Bluetooth permissions -->
<uses-permission android:name="android.permission.BLUETOOTH_CONNECT" />
<uses-permission android:name="android.permission.BLUETOOTH_SCAN"
android:usesPermissionFlags="neverForLocation"
tools:targetApi="s" />
<!-- API 33+ Notification runtime permissions -->
<uses-permission android:name="android.permission.POST_NOTIFICATIONS" />
<!-- Permissions required for providing location (from phone GPS) to mesh -->
<uses-permission android:name="android.permission.ACCESS_FINE_LOCATION" />
<uses-permission android:name="android.permission.ACCESS_COARSE_LOCATION" />
<!-- This permission is required for analytics - and soon the MQTT gateway -->
<uses-permission android:name="android.permission.INTERNET" />
<uses-permission android:name="android.permission.WAKE_LOCK" />
<!--
Android 17 (API 37) Local Network Protection: targetSdk=37 apps are blocked
from local-network access by default. Required for both NSD/mDNS device
discovery on the Connections screen and the built-in TAK Server's localhost
loopback binding. Requested at runtime via rememberLocalNetworkPermissionState.
See: https://developer.android.com/privacy-and-security/local-network-permission
-->
<uses-permission android:name="android.permission.ACCESS_LOCAL_NETWORK" />
<!--
This permission is optional but recommended so we can be smart
about when to send data.
-->
<uses-permission android:name="android.permission.ACCESS_NETWORK_STATE" />
<uses-permission android:name="android.permission.FOREGROUND_SERVICE" />
<uses-permission android:name="android.permission.FOREGROUND_SERVICE_CONNECTED_DEVICE" />
<uses-permission android:name="android.permission.FOREGROUND_SERVICE_LOCATION" />
<uses-permission android:name="android.permission.CHANGE_WIFI_MULTICAST_STATE" />
<!-- Needed to open our bluetooth connection to our paired device (after reboot) -->
<uses-permission android:name="android.permission.RECEIVE_BOOT_COMPLETED" />
<!-- Camera permission for QR Code scanning -->
<uses-permission android:name="android.permission.CAMERA" />
<!-- NFC permission for sharing channels and contacts -->
<uses-permission android:name="android.permission.NFC" />
<uses-feature
android:name="android.hardware.camera"
android:required="false" />
<uses-feature
android:name="android.hardware.bluetooth_le"
android:required="false" />
<uses-feature
android:name="android.hardware.nfc"
android:required="false" />
<uses-feature
android:name="android.hardware.nfc.hce"
android:required="false" />
<!-- for USB serial access -->
<uses-feature
android:name="android.hardware.usb.host"
android:required="false" />
<!-- Declare geo: intent visibility for Android 11+ (needed for resolveActivity with map apps) -->
<queries>
<intent>
<action android:name="android.intent.action.VIEW" />
<data android:scheme="geo" />
</intent>
</queries>
<application
android:name="org.meshtastic.app.MeshUtilApplication"
android:allowBackup="false"
android:dataExtractionRules="@xml/data_extraction_rules"
android:fullBackupContent="false"
android:icon="@mipmap/ic_launcher"
android:label="@string/app_name"
android:supportsRtl="true"
android:hardwareAccelerated="true"
android:theme="@style/SplashTheme"
android:localeConfig="@xml/locales_config"
android:networkSecurityConfig="@xml/network_security_config"
android:enableOnBackInvokedCallback="true"
android:largeHeap="true">
<!--
Reproduced live via adversarial mesh-fuzz testing: a 2000-node NodeDB (push_fake_nodedb's own
largest fixture; large public-event meshes like MeshCon/DEF CON/Burning Man are a supported
scenario, not just an adversarial edge case) combined with sustained hostile traffic (chaos fuzz)
and repeated reconnects in one long-lived process drove the default ~256MB Dalvik heap to
exhaustion: OutOfMemoryError at
androidx.datastore.core.DataStoreImpl.readAndInitOrPropagateAndThrowFailure, on an otherwise
unrelated settings read; any allocation would have thrown at that point, the heap was simply
full. largeHeap raises the ceiling (device dependent, commonly 2 to 4x) rather than reducing
footprint; it buys headroom for legitimately large meshes while the real fix (bounding/streaming
the in-memory log + node caches; see DebugViewModel and MeshMessageProcessorImpl) remains the
long-term mitigation.
TREAT THIS AS A TEMPORARY STOPGAP, not a permanent setting. It is a global,
whole-app flag with a global cost: a larger heap increases the working set the GC scans
each cycle, which can raise GC pause times / jank for ALL sessions, including typical
small-mesh use on low-RAM devices, which never come near the OOM this guards against. That
tradeoff (a tail-scenario safety net paid for by every user) is why Android's own docs
caution against relying on largeHeap alone. Remove it once the cache-bounding/streaming work
in DebugViewModel + MeshMessageProcessorImpl fully bounds footprint; validate that removal
on a low-RAM device AND under the large-mesh + chaos-fuzz soak that motivated this, not just
the flagship test device.
-->
<uses-library
android:name="org.apache.http.legacy"
android:required="false" />
<!-- Default crash collection and analytics off until we (possibly) turn it on in application.onCreate -->
<meta-data
android:name="firebase_crashlytics_collection_enabled"
android:value="false" />
<meta-data
android:name="firebase_analytics_collection_enabled"
android:value="false" />
<!-- Disable AdID collection for privacy -->
<meta-data
android:name="google_analytics_adid_collection_enabled"
android:value="false" />
<meta-data
android:name="google_analytics_default_allow_ad_personalization_signals"
android:value="false" />
<!-- Disable SSAID collection to reduce PII footprint -->
<meta-data
android:name="google_analytics_ssaid_collection_enabled"
android:value="false" />
<!-- Disable automatic screen reporting to reduce background noise -->
<meta-data
android:name="google_analytics_automatic_screen_reporting_enabled"
android:value="false" />
<!-- Set default analytics storage consent to denied for Advanced Consent Mode -->
<meta-data
android:name="google_analytics_default_allow_analytics_storage"
android:value="false" />
<!--
Presents the armed share URL as an NFC Forum Type 4 Tag, so another phone can take a
contact or channel by tapping this one. Serves nothing unless a share dialog has armed
it. BIND_NFC_SERVICE is the system-only permission that makes exported="true" safe.
-->
<service
android:name="org.meshtastic.core.nfc.MeshtasticHostApduService"
android:exported="true"
android:permission="android.permission.BIND_NFC_SERVICE">
<intent-filter>
<action android:name="android.nfc.cardemulation.action.HOST_APDU_SERVICE" />
<category android:name="android.intent.category.DEFAULT" />
</intent-filter>
<meta-data
android:name="android.nfc.cardemulation.host_apdu_service"
android:resource="@xml/nfc_apduservice" />
</service>
<!-- In-app mesh foreground service -->
<service
android:name="org.meshtastic.core.service.MeshService"
android:enabled="true"
android:foregroundServiceType="connectedDevice|location"
android:exported="false" />
<service
android:name="androidx.appcompat.app.AppLocalesMetadataHolderService"
android:enabled="false"
android:exported="false">
<meta-data
android:name="autoStoreLocales"
android:value="true" />
</service>
<activity
android:name="org.meshtastic.app.BubbleActivity"
android:allowEmbedded="true"
android:documentLaunchMode="always"
android:resizeableActivity="true"
android:windowSoftInputMode="adjustResize"
android:theme="@style/Theme.AppCompat.DayNight.NoActionBar"
android:exported="false" />
<activity
android:name="org.meshtastic.app.MainActivity"
android:launchMode="singleTop"
android:windowSoftInputMode="adjustResize"
android:exported="true">
<intent-filter>
<action android:name="android.intent.action.MAIN" />
<category android:name="android.intent.category.LAUNCHER" />
</intent-filter>
<intent-filter>
<action android:name="android.intent.action.SEND" />
<category android:name="android.intent.category.DEFAULT" />
<data android:mimeType="text/plain" />
</intent-filter>
<intent-filter>
<action android:name="android.intent.action.VIEW" />
<category android:name="android.intent.category.DEFAULT" />
<category android:name="android.intent.category.BROWSABLE" />
<data android:scheme="meshtastic" android:host="meshtastic" />
</intent-filter>
<intent-filter android:autoVerify="true">
<!--
The QR codes to share channel settings and contacts are shared as meshtastic URLS.
We also support NFC NDEF Discovery for the same URLS.
An approximate example:
https://meshtastic.org/e/YXNkZnF3ZXJhc2RmcXdlcmFzZGZxd2Vy
https://meshtastic.org/v/#CNar9vwDEi0KCSEzZjgyOTVkNhIPV2F0ZXJmYWxsIDIg4piGGgPimaciBu2eP4KV1igJOAI
-->
<action android:name="android.intent.action.VIEW" />
<action android:name="android.nfc.action.NDEF_DISCOVERED" />
<category android:name="android.intent.category.DEFAULT" />
<category android:name="android.intent.category.BROWSABLE" />
<data android:scheme="https" />
<data android:host="meshtastic.org" />
<data android:pathPrefix="/e/" />
<data android:pathPrefix="/E/" />
<data android:pathPrefix="/v/" />
<data android:pathPrefix="/V/" />
</intent-filter>
<!-- App Links for modern RESTful navigation paths -->
<intent-filter android:autoVerify="true">
<action android:name="android.intent.action.VIEW" />
<category android:name="android.intent.category.DEFAULT" />
<category android:name="android.intent.category.BROWSABLE" />
<data android:scheme="http" />
<data android:scheme="https" />
<data android:host="meshtastic.org" />
<data android:pathPrefix="/share" />
<data android:pathPrefix="/connections" />
<data android:pathPrefix="/map" />
<data android:pathPrefix="/messages" />
<data android:pathPrefix="/quickchat" />
<data android:pathPrefix="/nodes" />
<data android:pathPrefix="/settings" />
<data android:pathPrefix="/channels" />
<data android:pathPrefix="/firmware" />
<data android:pathPrefix="/wifi-provision" />
<data android:pathPrefix="/discovery" />
</intent-filter>
<intent-filter>
<action android:name="android.hardware.usb.action.USB_DEVICE_ATTACHED" />
</intent-filter>
<!-- The USB devices we want to be informed about -->
<meta-data
android:name="android.hardware.usb.action.USB_DEVICE_ATTACHED"
android:resource="@xml/device_filter" />
</activity>
<receiver android:name="org.meshtastic.core.service.BootCompleteReceiver"
android:exported="false">
<!-- handle boot events -->
<intent-filter>
<category android:name="android.intent.category.DEFAULT" />
<action android:name="android.intent.action.BOOT_COMPLETED" />
<action android:name="android.intent.action.QUICKBOOT_POWERON" />
<!--For HTC devices per https://stackoverflow.com/questions/20441308/boot-completed-not-working-android/46294732#46294732 -->
<action android:name="com.htc.intent.action.QUICKBOOT_POWERON" />
<!-- for testing -->
<action android:name="org.meshtastic.app.SIM_BOOT" />
</intent-filter>
<!-- Also restart our service if the app gets upgraded -->
<intent-filter>
<action android:name="android.intent.action.MY_PACKAGE_REPLACED" />
<!-- I was using PACKAGE_REPLACED, but MY_PACKAGE_REPLACED is newer and seems cleaner
<data
android:scheme="package"
android:path="com.geeksville.mesh" /> -->
</intent-filter>
</receiver>
<receiver android:name="org.meshtastic.core.service.ReplyReceiver" android:exported="false" />
<receiver android:name="org.meshtastic.core.service.MarkAsReadReceiver" android:exported="false" />
<receiver android:name="org.meshtastic.core.service.ReactionReceiver" android:exported="false" />
<receiver
android:name="org.meshtastic.feature.widget.LocalStatsWidgetReceiver"
android:exported="false">
<intent-filter>
<action android:name="android.appwidget.action.APPWIDGET_UPDATE" />
</intent-filter>
<meta-data
android:name="android.appwidget.provider"
android:resource="@xml/widget_local_stats_info" />
</receiver>
<!--
glance-appwidget declares ActionTrampolineActivity, but nothing in Glance ever targets it. Its onCreate
calls launchTrampolineAction(intent), which require()s an "ACTION_INTENT" Intent extra, so ANY launch that
does not carry that extra is a guaranteed FATAL IllegalArgumentException ("List adapter activity trampoline
invoked without specifying target intent") before a single line of our code runs.
Nothing can supply that extra, because nothing creates the intent. Verified against the Glance sources for
our pinned 1.2.0-rc01 (and 1.3.0-alpha02): applyTrampolineIntent() picks ActionTrampolineActivity only for
ActionTrampolineType.ACTIVITY, and no call site ever passes ACTIVITY. The four call sites all live in
getFillInIntentForAction() - i.e. only inside a lazy collection - and pass BROADCAST / SERVICE /
FOREGROUND_SERVICE, which all route to InvisibleActionTrampolineActivity instead. StartActivityAction is
special-cased there to skip the trampoline entirely and ride the collection's pending-intent template. The
non-lazy path never trampolines at all: actionStartActivity() becomes a direct PendingIntent.getActivity()
and actionRunCallback() a direct PendingIntent.getBroadcast() to ActionCallbackBroadcastReceiver.
So this is dead-but-launchable library code: an exported=false activity that crashes the process on every
launch and that our widget can never legitimately reach (LocalStatsWidget has no lazy collection, and a tap
on it dispatches its own PendingIntent directly). Same defect class as the ATAK marker below. Removing the
node is the whole fix - it takes the component out of the merged manifest so it cannot be started.
If glance is ever bumped, re-verify that ActionTrampolineType.ACTIVITY still has no producer before
trusting this removal; GlanceTrampolineManifestTest guards the removal itself.
-->
<activity
android:name="androidx.glance.appwidget.action.ActionTrampolineActivity"
tools:node="remove" />
<!--
ATAK plugin-discovery marker. The action is what ATAK looks for, so the filter stays exported; it now
resolves to a real no-op activity because the name used to be com.atakmap.app.component, a class not
present in this APK, so anything that launched it crashed the app on instantiation.
NOT VERIFIED AGAINST A REAL ATAK INSTALL: if any ATAK version keys discovery off the activity's class name
rather than off the action, this rename silently breaks it. Confirm on-device before relying on TAK
interop. Nothing else in this repo depends on the class name.
-->
<activity
android:name=".AtakPluginDiscoveryActivity"
android:excludeFromRecents="true"
android:exported="true"
android:noHistory="true"
android:theme="@android:style/Theme.NoDisplay">
<intent-filter android:label="@string/app_name">
<action android:name="com.atakmap.app.component" />
</intent-filter>
</activity>
<provider
android:name="androidx.startup.InitializationProvider"
android:authorities="${applicationId}.androidx-startup"
android:exported="false"
tools:node="merge">
<meta-data
android:name="androidx.work.WorkManagerInitializer"
android:value="androidx.startup"
tools:node="remove" />
</provider>
</application>
</manifest>