Seperti rilis sebelumnya, Android 17 menyertakan perubahan perilaku yang mungkin memengaruhi aplikasi Anda. Perubahan perilaku berikut ini berlaku khusus bagi aplikasi yang menargetkan Android 17 atau yang lebih tinggi. Jika aplikasi Anda menargetkan Android 17 atau yang lebih tinggi, Anda harus memodifikasi aplikasi untuk mendukung perilaku ini, jika berlaku.
Pastikan Anda juga meninjau daftar perubahan perilaku yang memengaruhi semua aplikasi
yang berjalan di Android 17, terlepas dari targetSdkVersion aplikasi Anda.
Fungsi inti
Android 17 menyertakan perubahan berikut yang mengubah atau memperluas berbagai kemampuan inti sistem Android.
Implementasi MessageQueue baru tanpa kunci
从 Android 17 开始,以 Android 17(API 级别 37)
或更高版本为目标平台的应用会收到
android.os.MessageQueue 的新无锁实现。新实现可提升性能并减少丢帧,但可能会破坏反映 MessageQueue 私有字段和方法的客户端。
如需了解详情(包括缓解措施),请参阅 MessageQueue 行为变更指南。
Kolom final statis kini tidak dapat diubah
Aplikasi yang berjalan di Android 17 atau yang lebih tinggi yang menargetkan
Android 17 (level API 37) atau yang lebih tinggi tidak dapat mengubah kolom static final. Jika
aplikasi mencoba mengubah kolom static final menggunakan refleksi, aplikasi tersebut akan
menyebabkan IllegalAccessException. Mencoba mengubah salah satu kolom ini
melalui API JNI (seperti SetStaticLongField()) akan menyebabkan aplikasi error.
Aksesibilitas
Android 17 membuat perubahan berikut untuk meningkatkan aksesibilitas.
Dukungan aksesibilitas untuk pengetikan keyboard fisik IME yang kompleks
This feature introduces new AccessibilityEvent and TextAttribute
APIs to enhance screen reader spoken feedback for CJKV language input. CJKV IME
apps can now signal whether a text conversion candidate has been selected during
text composition. Apps with edit fields can specify text change types when
sending text changed accessibility events.
For example, apps can specify that a text change occurred during text
composition, or that a text change resulted from a commit.
Doing this enables accessibility
services such as screen readers to deliver more precise feedback based on the
nature of the text modification.
App adoption
IME Apps: When setting composing text in edit fields, IMEs can use
TextAttribute.Builder.setTextSuggestionSelected()to indicate whether a specific conversion candidate was selected.Apps with Edit Fields: Apps that maintain a custom
InputConnectioncan retrieve candidate selection data by callingTextAttribute.isTextSuggestionSelected(). These apps should then callAccessibilityEvent.setTextChangeTypes()when dispatchingTYPE_VIEW_TEXT_CHANGEDevents. Apps targeting Android 17 (API level 37) that use the standardTextViewwill have this feature enabled by default. (That is,TextViewwill handle retrieving data from the IME and setting text change types when sending events to accessibility services).Accessibility Services: Accessibility services that process
TYPE_VIEW_TEXT_CHANGEDevents can callAccessibilityEvent.getTextChangeTypes()to identify the nature of the modification and adjust their feedback strategies accordingly.
Privasi
Android 17 menyertakan perubahan berikut untuk meningkatkan privasi pengguna.
ECH (Encrypted Client Hello) diaktifkan
Android 17 introduces platform support for Encrypted Client Hello (ECH), a TLS extension that enhances user privacy by encrypting the Server Name Indication (SNI) in the TLS handshake. This encryption helps prevent network observers from easily identifying the specific domain your app is connecting to.
For apps targeting Android 17 (API level 37) or higher, ECH is used for TLS connections. ECH is active only if the networking library used by the app (for example, HttpEngine, WebView, or OkHttp) has integrated ECH support and the remote server also supports the ECH protocol. If ECH cannot be negotiated, the client sends an ECH extension with randomized contents (a mechanism called ECH GREASE). See RFC 9849 for more details on how ECH GREASE works.
To allow apps to customize this behavior, Android 17 adds a new
<domainEncryption> element to the Network Security Configuration file.
Developers can use <domainEncryption> within <base-config> or
<domain-config> tags to select an ECH mode (for example,
"enabled" or "disabled") on a global or per-domain basis.
For more information, see the Encrypted Client Hello documentation.
Izin jaringan lokal diperlukan untuk aplikasi yang menargetkan Android 17
Android 17 introduces the ACCESS_LOCAL_NETWORK runtime permission
to protect users from unauthorized local network access. Because this falls
under the existing NEARBY_DEVICES permission group, users who have already
granted other NEARBY_DEVICES permissions aren't prompted again. This new
requirement prevents malicious apps from exploiting unrestricted local network
access for covert user tracking and fingerprinting. By declaring and requesting
this permission, your app can discover and connect to devices on the local area
network (LAN), such as smart home devices or casting receivers.
Apps targeting Android 17 (API level 37) or higher now have two paths to maintain communication with LAN devices: Adopt system-mediated, privacy-preserving device pickers to skip the permission prompt, or explicitly request this new permission at runtime to maintain local network communication.
For more information, see the Local network permission documentation.
Menyembunyikan sandi dari perangkat fisik
If an app targets Android 17 (API level 37) or higher and the user is using
a physical input device (for example, an external keyboard), the Android
operating system applies the new show_passwords_physical setting to all
characters in the password field. By default, that setting hides all password
characters.
The Android system shows the last-typed password character to help the user see if they mistyped the password. However, this is much less necessary with larger external keyboards. In addition, devices with external keyboards often have larger displays, which increases the danger of someone seeing the typed password.
If the user is using the device's touchscreen, the system applies the new
show_passwords_touch setting.
Perlindungan OTP untuk pesan SMS standar
从 Android 17 开始,Android 将扩展其短信验证码保护功能,以适用于标准短信(包含验证码但不使用 WebOTP 或 SMS Retriever 格式的短信)。对于以 Android 17(API 级别 37)或更高版本为目标平台的应用,这些短信在收到后三小时内不会提供。此延迟旨在帮助防止动态密码劫持。在这三小时的延迟期间,系统会保留
SMS_RECEIVED_ACTION广播,并过滤
短信提供商数据库查询。延迟结束后,这些应用即可使用短信。
某些应用(例如默认短信助理应用、已连接的设备配套应用等)不受此延迟限制。所有依赖于读取短信 来提取动态密码的应用都应改用 SMS Retriever 或 SMS User Consent API,以确保功能持续可用。
Keamanan
Android 17 membuat peningkatan berikut pada keamanan perangkat dan aplikasi.
Keamanan Aktivitas
在 Android 17 中,平台继续向“默认安全”架构转变,引入了一系列旨在缓解网络钓鱼、互动劫持和混淆代理攻击等高严重性漏洞的增强功能。此更新要求开发者明确选择启用新的安全标准,以保持应用兼容性和用户保护。
对开发者的主要影响包括:
- BAL 安全加固和改进的选择启用: 我们正在优化后台活动启动 (BAL) 限制,方法是将保护范围扩展到
IntentSender。开发者必须从旧版MODE_BACKGROUND_ACTIVITY_START_ALLOWED常量迁移。相反,您应 采用精细控制,例如MODE_BACKGROUND_ACTIVITY_START_ALLOW_IF_VISIBLE,它将 活动启动限制为调用应用可见的场景,从而显著 缩小攻击面。 - 采用工具: 开发者应利用严格模式和更新后的 lint 检查来识别旧版模式,并确保为未来的目标 SDK 要求做好准备。
Mengaktifkan CT secara default
If an app targets Android 17 (API level 37) or higher, certificate transparency (CT) is enabled by default. (On Android 16, CT is available but apps had to opt in.)
DCL—C Native yang Lebih Aman
Jika aplikasi Anda menargetkan Android 17 (API level 37) atau yang lebih tinggi, perlindungan Pemuatan Kode Dinamis (DCL) yang Lebih Aman yang diperkenalkan di Android 14 untuk file DEX dan JAR kini diperluas ke library native.
Semua file native yang dimuat menggunakan System.load() harus ditandai sebagai hanya baca.
Jika tidak, sistem akan menampilkan UnsatisfiedLinkError.
Sebaiknya aplikasi menghindari pemuatan kode secara dinamis jika memungkinkan, karena hal itu akan sangat meningkatkan risiko aplikasi disusupi oleh injeksi kode atau modifikasi kode.
Membatasi kolom PII dalam tampilan data CP2
对于以 Android 17(API 级别 Android 17(API 级别 37))及更高版本为目标平台的应用,联系人提供程序 2 (CP2) 会限制数据视图中包含某些个人身份信息 (PII) 的列。启用此变更后,这些列将从数据视图中移除,以增强用户隐私保护。 受限列包括:
如果应用正在使用 ContactsContract.Data
中的这些列,则可以通过与 RAW_CONTACT_ID 联接,改为从 ContactsContract.RawContacts
中提取这些列。
Menerapkan pemeriksaan SQL yang ketat di CP2
For apps targeting Android 17 (API level Android 17 (API level 37)) and
higher, Contacts Provider 2 (CP2) enforces strict SQL query validation when
the ContactsContract.Data table is accessed without
READ_CONTACTS permission.
With this change, if an app doesn't have READ_CONTACTS
permission, StrictColumns and
StrictGrammar options are set when querying
the ContactsContract.Data table. If a query
uses a pattern that isn't compatible with these, it will be
rejected and cause an exception to be thrown.
Media
Android 17 menyertakan perubahan berikut pada perilaku media.
Penguatan audio latar belakang
Beginning with Android 17, the audio framework enforces restrictions on background audio interactions including audio playback, audio focus requests, and volume change APIs to ensure that these changes are started intentionally by the user.
Some audio restrictions apply to all apps. However, the restrictions are more stringent if an app targets Android 17 (API level 37). If one of these apps interacts with audio while it is in the background, it must have a foreground service running. In addition, the app must meet one or both of these requirements:
- The foreground service must have while-in-use (WIU) capabilities.
- The app must have the exact alarm permission and be interacting with
USAGE_ALARMaudio streams.
For more information, including mitigation strategies, see Background audio hardening.
Faktor bentuk perangkat
Android 17 menyertakan perubahan berikut untuk meningkatkan pengalaman pengguna di berbagai ukuran dan faktor bentuk perangkat.
Perubahan API platform untuk mengabaikan batasan orientasi, perubahan ukuran, dan rasio aspek pada layar besar (sw>=600dp)
Kami memperkenalkan perubahan Platform API di Android 16 untuk mengabaikan orientasi, rasio aspek, dan batasan perubahan ukuran pada layar besar (sw >= 600dp) untuk aplikasi yang menargetkan API level 36 atau yang lebih tinggi. Developer memiliki opsi untuk tidak ikut serta dalam perubahan ini dengan SDK 36, tetapi opsi tidak ikut serta ini tidak akan lagi tersedia untuk aplikasi yang menargetkan Android 17 (API level 37) atau yang lebih tinggi.
Untuk mengetahui informasi selengkapnya, lihat Batasan pada orientasi dan perubahan ukuran di abaikan.
Konektivitas
Android 17 memperkenalkan perubahan berikut untuk meningkatkan konsistensi dan menyelaraskan dengan perilaku InputStream Java standar untuk soket RFCOMM Bluetooth.
Perilaku BluetoothSocket read() yang konsisten untuk RFCOMM
Untuk aplikasi yang menargetkan Android 17 (API level 37), metode
read() dari InputStream yang diperoleh dari
BluetoothSocket berbasis RFCOMM kini menampilkan -1 saat
soket ditutup atau koneksi terputus.
Perubahan ini membuat perilaku soket RFCOMM konsisten dengan soket LE CoC dan
selaras dengan dokumentasi standar InputStream.read(), yang menyatakan bahwa -1 ditampilkan saat akhir streaming
tercapai.
Aplikasi yang hanya mengandalkan penangkapan IOException untuk keluar dari loop baca mungkin terpengaruh oleh perubahan ini dan harus memperbarui loop baca BluetoothSocket untuk memeriksa nilai yang ditampilkan secara eksplisit sebesar -1. Hal ini memastikan loop berakhir dengan benar saat perangkat jarak jauh terputus atau soket ditutup. Untuk contoh penerapan yang direkomendasikan, lihat
cuplikan kode dalam panduan Mentransfer data Bluetooth.