Carry the accessibility service count the dump states

Most builds never print the `installed services: {...}` block. They state
installedServiceCount=N in the user's attributes line and list nothing, so the
parser recorded no service at all and MVT logged "Identified a total of 0
accessibility services" — an artifact that says "no accessibility services"
about a dump that said there are five. The dump pasted in #744 is itself an
example: it states installedServiceCount=6 and names none.

Parse the count per user and, for a user whose services the dump did not list,
keep one record carrying it, raised as LOW: a count is a coverage statement,
not a running service.

Name the service state in the alert and split its severity, as asked on #744:
a service the dump states is switched off is LOW, enabled or bound is MEDIUM,
and a dump that does not state the enabled state stays MEDIUM, because "not
stated" is not "not enabled". A state section the dump never printed now reads
None rather than False. IOC matching is unaffected by the state: a disabled
service still returns CRITICAL on a match.

Measured over 163 bug reports carrying an accessibility section: MEDIUM alerts
305 -> 4, LOW 0 -> 407. The four that stay MEDIUM are the only records in the
set with enabled=True.

Fixes #744
This commit is contained in:
va-resident committed 2026-09-22 18:13:57 +03:00
1 parent 777db67291
commit bdbc07a3b3
5 files changed
+351 -21

No files matched your search

@@ -10,8 +10,37 @@ from .artifact import AndroidArtifact
class DumpsysAccessibilityArtifact(AndroidArtifact):
# One list for both record shapes — a service record and a count-only
# record must stay the same shape.
_FIELDS = (
"user_id",
"component",
"package_name",
"service_name",
"installed",
"enabled",
"binding",
"bound",
"crashed",
"accessibility_tool",
"installed_service_count",
)
def check_indicators(self) -> None:
for result in self.results:
# A stated count with no component names is a coverage statement,
# not a service: low, but not silent.
if not result.get("component"):
self.alertstore.low(
f"The accessibility dump states "
f"{result['installed_service_count']} installed "
f"service(s) for user {result['user_id']} but does not "
f"list their component names",
"",
result,
)
continue
if self.indicators:
ioc_match = self.indicators.check_app_id(result["package_name"])
if ioc_match:
@@ -20,11 +49,22 @@ class DumpsysAccessibilityArtifact(AndroidArtifact):
)
continue
self.alertstore.medium(
f'Found accessibility service: "{result["component"]}"',
"",
result,
# Installed is not enabled. A service can sit installed for years
# without ever being switched on, and that is the difference this
# channel is read for — an alert that says only "found" makes every
# device look equally exposed. A service the dump says is switched
# OFF is reported LOW, so it still reaches the analyst without
# competing with one that is actually running; a dump that does not
# state the enabled state stays MEDIUM, because "not stated" is not
# "not enabled".
message = (
f'Found accessibility service: "{result["component"]}" '
f"({self._describe_state(result)})"
)
if result.get("enabled") is False and not result.get("bound"):
self.alertstore.low(message, "", result)
else:
self.alertstore.medium(message, "", result)
def parse(self, content: str) -> None:
"""
@@ -36,6 +76,11 @@ class DumpsysAccessibilityArtifact(AndroidArtifact):
self.results: list[dict[str, Any]] = []
services: dict[tuple[int | None, str], dict] = {}
seen_states: set[str] = set()
# `installedServiceCount=N` from the user's `attributes:{…}` line is on
# most builds the only statement about installed services in the dump:
# few print the `installed services: {…}` block.
installed_counts: dict[int | None, int] = {}
user_id: int | None = None
state: str | None = None
@@ -44,6 +89,10 @@ class DumpsysAccessibilityArtifact(AndroidArtifact):
if user_match:
user_id = int(user_match.group(1))
count_match = re.search(r"installedServiceCount=(\d+)", line)
if count_match:
installed_counts[user_id] = int(count_match.group(1))
stripped = line.strip()
state_match = re.match(
r"(?i)(installed|enabled|binding|bound|crashed) services\s*:\s*\{(.*)",
@@ -51,6 +100,7 @@ class DumpsysAccessibilityArtifact(AndroidArtifact):
)
if state_match:
state = state_match.group(1).lower()
seen_states.add(self._state_field(state))
inline = state_match.group(2)
for component in re.findall(
r"\{?([\w.$-]+/[\w.$-]+)(?:\s+\(A11yTool\))?\}?", inline
@@ -79,24 +129,59 @@ class DumpsysAccessibilityArtifact(AndroidArtifact):
service[self._state_field(state)] = True
service["accessibility_tool"] = "(A11yTool)" in stripped
# A section that was never printed is NOT the same as one printed
# empty: the first says nothing, the second says nothing is enabled.
# Defaulting every flag to False would turn "not stated" into "not
# enabled". Flags for sections this dump never printed stay None.
for (service_user, _component), service in services.items():
for state in ("installed", "enabled", "binding", "bound", "crashed"):
if self._state_field(state) not in seen_states:
service[self._state_field(state)] = None
service["installed_service_count"] = installed_counts.get(service_user)
self.results.extend(services.values())
# A stated count whose services were never listed would leave no trace:
# the module would log "a total of 0" about a dump that said five.
listed_users = {service_user for service_user, _component in services}
for count_user, count in installed_counts.items():
if count_user in listed_users or count == 0:
continue
self.results.append(self._new_unlisted(count_user, count))
@staticmethod
def _describe_state(result: dict) -> str:
if result.get("bound"):
return "enabled and bound"
if result.get("enabled"):
return "enabled"
if result.get("enabled") is None:
return "installed, enabled state not stated"
return "installed, not enabled"
@staticmethod
def _state_field(state: str) -> str:
return {"binding": "binding", "bound": "bound"}.get(state, state)
@staticmethod
def _new_unlisted(user_id: int | None, count: int) -> dict:
"""The dump's own count for a user whose services it did not list.
Every other field stays unknown: the dump named no service to carry it.
"""
record: dict[str, Any] = dict.fromkeys(DumpsysAccessibilityArtifact._FIELDS)
record["user_id"] = user_id
record["installed_service_count"] = count
return record
@staticmethod
def _new_service(component: str, user_id: int | None) -> dict:
package_name, service_name = component.split("/", 1)
return {
"user_id": user_id,
"component": component,
"package_name": package_name,
"service_name": service_name,
"installed": False,
"enabled": False,
"binding": False,
"bound": False,
"crashed": False,
"accessibility_tool": False,
}
record: dict[str, Any] = dict.fromkeys(
DumpsysAccessibilityArtifact._FIELDS, False
)
record["user_id"] = user_id
record["component"] = component
record["package_name"], record["service_name"] = component.split("/", 1)
# Filled in after parsing: the count is per user.
record["installed_service_count"] = None
return record
@@ -48,9 +48,22 @@ class DumpsysAccessibility(DumpsysAccessibilityArtifact, BugReportModule):
)
self.parse(content)
listed = stated = 0
for result in self.results:
self.log.info('Found accessibility service "%s"', result.get("component"))
if result.get("component"):
listed += 1
self.log.info(
'Found accessibility service "%s"', result.get("component")
)
continue
# The operator gets this per user as a LOW alert from
# check_indicators(); here it only has to survive into the summary,
# so that a stated count never reads as "a total of 0".
stated += result.get("installed_service_count") or 0
self.log.info(
"Identified a total of %d accessibility services", len(self.results)
"Identified a total of %d accessibility services (%d more stated by "
"the dump without a component name)",
listed,
stated,
)
@@ -39,7 +39,10 @@ class TestDumpsysAccessibilityArtifact:
assert da.results[0]["package_name"] == "com.malware.accessibility"
assert da.results[0]["service_name"] == "com.malware.service.malwareservice"
assert da.results[0]["enabled"] is True
assert da.results[0]["installed"] is False
# This fixture never prints an `installed services:` section, so the
# dump does not state the installed status. Reporting False would turn
# "not stated" into "not installed", so it reads None here.
assert da.results[0]["installed"] is None
def test_accessibility_service_alert(self):
da = DumpsysAccessibilityArtifact()
@@ -84,7 +87,11 @@ User state[attributes:{id=10
assert len(da.alertstore.alerts) == 0
da.check_indicators()
assert len(da.alertstore.alerts) == len(da.results)
assert da.alertstore.count(AlertLevel.MEDIUM) == 3
# Every service in this fixture is installed and switched off
# (`enabled services:{}` is printed and empty), so the three non-IOC
# findings are LOW, not MEDIUM. The IOC match is unaffected by the
# state.
assert da.alertstore.count(AlertLevel.LOW) == 3
assert da.alertstore.count(AlertLevel.CRITICAL) == 1
critical_alert = next(
alert
@@ -0,0 +1,100 @@
# Mobile Verification Toolkit (MVT)
# Copyright (c) 2021-2026 The MVT Authors.
# Use of this software is governed by the MVT License 1.1 that can be found at
# https://license.mvt.re/1.1/
"""The dump's own installed-service count must survive into the artifact.
Most builds never print the `installed services: {…}` block; they state `installedServiceCount=N` in the user's `attributes:{…}` line and
list nothing. Dropping that number makes an artifact that says "no
accessibility services" about a dump that said there are five.
"""
from mvt.android.artifacts.dumpsys_accessibility import DumpsysAccessibilityArtifact
from mvt.common.alerts import AlertLevel
AOSP_NO_LIST = """\
ACCESSIBILITY MANAGER (dumpsys accessibility)
User state[
attributes:{id=0, touchExplorationEnabled=false, installedServiceCount=5}
Bound services:{}
Enabled services:{}
Binding services:{}
Crashed services:{}
"""
ONE_UI_WITH_LIST = """\
ACCESSIBILITY MANAGER (dumpsys accessibility)
User state[attributes:{id=0, installedServiceCount=2}
installed services: {
0 : com.example.app/com.example.app.Service
1 : com.other.app/.Helper
}
enabled services: {
}
"""
TWO_USERS = """\
ACCESSIBILITY MANAGER (dumpsys accessibility)
User state[attributes:{id=0, installedServiceCount=1}
installed services: {
0 : com.example.app/com.example.app.Service
}
User state[attributes:{id=95, installedServiceCount=3}
Enabled services:{}
"""
ZERO_COUNT = """\
ACCESSIBILITY MANAGER (dumpsys accessibility)
User state[attributes:{id=0, installedServiceCount=0}
Enabled services:{}
"""
def _parse(content):
artifact = DumpsysAccessibilityArtifact()
artifact.results = []
artifact.parse(content)
return artifact
class TestAccessibilityInstalledServiceCount:
def test_stated_count_without_a_list_is_kept(self):
artifact = _parse(AOSP_NO_LIST)
assert len(artifact.results) == 1
record = artifact.results[0]
assert record["installed_service_count"] == 5
assert record["component"] is None
# Every state flag stays unknown: the dump named no service to which a
# state could belong.
assert record["installed"] is None
assert record["enabled"] is None
def test_a_stated_count_is_reported_as_low(self):
artifact = _parse(AOSP_NO_LIST)
artifact.check_indicators()
alerts = artifact.alertstore.alerts
assert len(alerts) == 1
# A count is a coverage statement, not a running service: it must not
# compete with a service the dump says is enabled.
assert alerts[0].level == AlertLevel.LOW
assert "does not list their component names" in alerts[0].message
assert "5 installed" in alerts[0].message
def test_a_listed_user_carries_the_count_on_each_service(self):
artifact = _parse(ONE_UI_WITH_LIST)
assert len(artifact.results) == 2
assert {record["installed_service_count"] for record in artifact.results} == {2}
assert all(record["component"] for record in artifact.results)
def test_only_the_unlisted_user_gets_a_count_record(self):
artifact = _parse(TWO_USERS)
listed = [record for record in artifact.results if record["component"]]
unlisted = [record for record in artifact.results if not record["component"]]
assert [record["user_id"] for record in listed] == [0]
assert [record["user_id"] for record in unlisted] == [95]
assert unlisted[0]["installed_service_count"] == 3
def test_a_zero_count_adds_nothing(self):
# "Zero installed" is a negative result the empty section already
# states; a record for it would be noise.
assert _parse(ZERO_COUNT).results == []
@@ -0,0 +1,125 @@
# Mobile Verification Toolkit (MVT)
# Copyright (c) 2021-2026 The MVT Authors.
# Use of this software is governed by the MVT License 1.1 that can be found at
# https://license.mvt.re/1.1/
"""Installed is not the same as enabled, and the dump says which.
Two things this guards:
* a section the dump never printed must read as None ("not stated"), not as
False ("not enabled");
* the alert must name the state, instead of firing identically on a device
where nothing is switched on and one where something is bound.
"""
from types import SimpleNamespace
from mvt.android.artifacts.dumpsys_accessibility import DumpsysAccessibilityArtifact
from mvt.common.alerts import AlertLevel
from ..utils import get_artifact
NO_STATE_SECTIONS = """\
ACCESSIBILITY MANAGER (dumpsys accessibility)
User state[attributes:{id=0, currentUser=true}
installed services: {
0 : com.example.app/com.example.app.Service
}
"""
ENABLED_BLOCK = """\
ACCESSIBILITY MANAGER (dumpsys accessibility)
User state[attributes:{id=0, currentUser=true}
installed services: {
0 : com.example.app/com.example.app.Service
1 : com.other.app/.Helper
}
enabled services: {
0 : com.other.app/.Helper
}
bound services:{
0 : com.other.app/.Helper
}
"""
class _IndicatorsMatching:
"""Minimal stand-in: matches one package id, like the STIX2 loader would."""
def __init__(self, package_name: str) -> None:
self.package_name = package_name
def check_app_id(self, app_id):
if app_id != self.package_name:
return None
return SimpleNamespace(
message=f"Found a known suspicious app: {app_id}", ioc={"value": app_id}
)
class TestAccessibilityServiceState:
def _parse(self, content):
artifact = DumpsysAccessibilityArtifact()
artifact.results = []
artifact.parse(content)
return {r["component"]: r for r in artifact.results}
def test_absent_sections_leave_the_state_unknown(self):
# None, not False: a build that does not print the sections says
# nothing about what is enabled, and that must not read as "nothing".
state = self._parse(NO_STATE_SECTIONS)[
"com.example.app/com.example.app.Service"
]
assert state["installed"] is True
assert state["enabled"] is None
assert state["bound"] is None
def test_enabled_and_bound_are_attributed_per_service(self):
results = self._parse(ENABLED_BLOCK)
installed_only = results["com.example.app/com.example.app.Service"]
active = results["com.other.app/.Helper"]
assert (installed_only["enabled"], installed_only["bound"]) == (False, False)
assert (active["enabled"], active["bound"]) == (True, True)
def test_alert_message_carries_the_state(self):
artifact = DumpsysAccessibilityArtifact()
artifact.results = []
with open(get_artifact("android_data/dumpsys_accessibility.txt")) as handle:
artifact.parse(handle.read())
artifact.check_indicators()
assert artifact.alertstore.alerts
assert all("installed" in alert.message for alert in artifact.alertstore.alerts)
def test_a_switched_off_service_is_low_and_a_running_one_medium(self):
# A service the dump says is OFF still reaches the analyst, but must not
# compete with one that is actually bound. "Not stated" is not "off".
artifact = DumpsysAccessibilityArtifact()
artifact.results = []
artifact.parse(ENABLED_BLOCK)
artifact.check_indicators()
by_level = {}
for alert in artifact.alertstore.alerts:
by_level.setdefault(alert.level, []).append(alert.message)
assert artifact.alertstore.count(AlertLevel.LOW) == 1
assert artifact.alertstore.count(AlertLevel.MEDIUM) == 1
assert "com.example.app" in by_level[AlertLevel.LOW][0]
assert "com.other.app" in by_level[AlertLevel.MEDIUM][0]
def test_an_unstated_enabled_state_stays_medium(self):
artifact = DumpsysAccessibilityArtifact()
artifact.results = []
artifact.parse(NO_STATE_SECTIONS)
artifact.check_indicators()
assert artifact.alertstore.count(AlertLevel.MEDIUM) == 1
assert artifact.alertstore.count(AlertLevel.LOW) == 0
def test_a_disabled_service_is_still_matched_against_indicators(self):
# The state decides the severity of an ordinary finding, never whether
# the package is compared with the IOC feeds.
artifact = DumpsysAccessibilityArtifact()
artifact.results = []
artifact.parse(ENABLED_BLOCK)
artifact.indicators = _IndicatorsMatching("com.example.app")
artifact.check_indicators()
assert artifact.alertstore.count(AlertLevel.CRITICAL) == 1
assert artifact.alertstore.count(AlertLevel.LOW) == 0