Android 17 प्लैटफ़ॉर्म में, ऐप्लिकेशन के काम करने के तरीके से जुड़े कुछ बदलाव किए गए हैं. इनका असर आपके ऐप्लिकेशन पर पड़ सकता है.
ऐप्लिकेशन के काम करने के तरीके से जुड़े ये बदलाव, Android 17 पर चलने वाले सभी ऐप्लिकेशन पर लागू होते हैं. भले ही, targetSdkVersion कुछ भी हो. आपको अपने ऐप्लिकेशन की जांच करनी चाहिए. इसके बाद, ज़रूरत के मुताबिक उसमें बदलाव करना चाहिए, ताकि इन बदलावों को लागू किया जा सके.
Android 17 को टारगेट करने वाले ऐप्लिकेशन पर असर डालने वाले बदलावों की सूची भी ज़रूर देखें.
मुख्य फ़ंक्शन
Android 17 (एपीआई लेवल 37) में ये बदलाव शामिल हैं. इनसे Android सिस्टम की कई मुख्य क्षमताओं में बदलाव होता है या उन्हें बढ़ाया जाता है.
ऐप्लिकेशन के लिए मेमोरी की सीमाएं
Android 17 में, डिवाइस की कुल रैम के आधार पर ऐप्लिकेशन की मेमोरी की सीमाएं तय की गई हैं. इससे आपके ऐप्लिकेशन और Android उपयोगकर्ताओं के लिए, ज़्यादा स्थिर और भरोसेमंद एनवायरमेंट तैयार किया जा सकेगा. ये सीमाएं, मेमोरी लीक और अन्य गड़बड़ियों पर फ़ोकस करती हैं. ऐसा इसलिए, ताकि ये गड़बड़ियां पूरे सिस्टम को अस्थिर न कर दें. इनकी वजह से, यूज़र इंटरफ़ेस (यूआई) में रुकावटें आती हैं, बैटरी ज़्यादा खर्च होती है, और ऐप्लिकेशन बंद हो जाते हैं. हमें उम्मीद है कि इस बदलाव का असर ज़्यादातर ऐप्लिकेशन सेशन पर नहीं पड़ेगा. हालांकि, हमारा सुझाव है कि आप मेमोरी के इस्तेमाल से जुड़े इन सबसे सही तरीकों को अपनाएं. इनमें मेमोरी के इस्तेमाल के लिए एक बेसलाइन तय करना भी शामिल है.
यह पता लगाया जा सकता है कि आपके ऐप्लिकेशन के सेशन पर असर पड़ा है या नहीं. इसके लिए, ApplicationExitInfo में getDescription को कॉल करें. अगर आपके ऐप्लिकेशन पर असर पड़ा है, तो बंद होने की वजह REASON_OTHER होगी. साथ ही, ब्यौरे में "MemoryLimiter:AnonSwap" स्ट्रिंग के साथ-साथ अन्य जानकारी भी शामिल होगी. मेमोरी की सीमा पूरी होने पर इकट्ठा किए गए हीप डंप पाने के लिए, TRIGGER_TYPE_ANOMALY के साथ ट्रिगर पर आधारित प्रोफ़ाइलिंग का भी इस्तेमाल किया जा सकता है.
अपने ऐप्लिकेशन की मेमोरी मैनेज करना दस्तावेज़ में, आपके ऐप्लिकेशन की मेमोरी से जुड़ी समस्याओं का पता लगाने और उसके संसाधन इस्तेमाल को ऑप्टिमाइज़ करने के बारे में जानकारी दी गई है.
मेमोरी की सीमाओं के तहत, अपने ऐप्लिकेशन के व्यवहार की जांच करना
Android डीबग ब्रिज (adb) का इस्तेमाल करके, मेमोरी की सीमाओं को लागू करने वाले किसी भी डिवाइस पर, मेमोरी की सीमाओं में बदलाव किया जा सकता है या उन्हें बंद किया जा सकता है. शेल कमांड am
में मेमोरी की सीमाएं अडजस्ट करने के लिए, तीन सब-कमांड होती हैं. (ये कमांड, उस डिवाइस पर लागू नहीं होती हैं जिस पर मेमोरी की सीमाएं लागू नहीं होती हैं.)
am memory-limiter ignore <uid>|none|allam memory-limiter manual <pid> <limit>|max|noneam memory-limiter status
ignoreयह विकल्प, मेमोरी लिमिट तय करने वाले टूल को कुछ या सभी प्रोसेस को अनदेखा करने का निर्देश देता है. यूआईडी (Android उपयोगकर्ता आईडी) पास करने पर, मेमोरी लिमिटर को उस यूआईडी से जुड़ी सभी प्रोसेस पर मेमोरी लिमिट लागू न करने का निर्देश मिलता है. इसके अलावा,
all(सभी ऐप्लिकेशन को अनदेखा करें) याnone(किसी भी ऐप्लिकेशन को अनदेखा न करें) भी पास किया जा सकता है.noneको पास करने से,am memory-limiter ignoreको किए गए पिछले सभी कॉल रद्द हो जाते हैं.अगर आपने मेमोरी लिमिटर को किसी यूआईडी को अनदेखा करने का निर्देश दिया है, तो भी ऐप्लिकेशन में किसी प्रोसेस के लिए मैन्युअल तरीके से मेमोरी की सीमा लागू की जा सकती है. इसके लिए,
am memory-limiter manualको कॉल करें.manualयह सिस्टम को निर्देश देता है कि वह प्रोसेस पर मेमोरी की सीमा लागू करे. इसके लिए, दिए गए PID (प्रोसेस आईडी) का इस्तेमाल किया जाता है. मेमोरी की सीमा को पूर्णांक के तौर पर बताया जाता है. यह सीमा एमबी में होती है. उदाहरण के लिए,
30पास करने का मतलब है कि प्रोसेस के लिए मेमोरी की सीमा 30 एमबी है.maxको पास करने से, उस प्रोसेस पर मेमोरी की सभी सीमाएं हट जाती हैं.noneपास करने पर, प्रोसेस के लिए मैन्युअल तरीके से सेट की गई सभी सीमाएं हट जाती हैं. साथ ही, सिस्टम की डिफ़ॉल्ट सीमा (अगर कोई है) वापस आ जाती है.statusमेमोरी लिमिटर की मौजूदा स्थिति की रिपोर्ट करता है. इस स्टेटस में, दिखने वाली और न दिखने वाली प्रोसेस पर लगाई गई मेमोरी की सीमाएं शामिल होती हैं.
निजता
Android 17 में, उपयोगकर्ता की निजता को बेहतर बनाने के लिए ये बदलाव किए गए हैं.
एसएमएस से मिलने वाले ओटीपी की सुरक्षा
Beginning with Android 17, Android is expanding its protection for SMS messages containing one-time passwords (OTP).
In previous versions of Android, this protection was primarily focused on the SMS Retriever format. Delivery of messages containing an SMS retriever hash was delayed for most apps for three hours. However, certain apps (like the default SMS handler) were exempt from the delay, and the app that owned the hash was also exempted.
Beginning with Android 17, the protection is also applied to WebOTP format messages. If an app has permission to read SMS messages but is not the intended recipient of a WebOTP message (as determined by domain verification), the message is not accessible to the app until three hours after the message's receipt. This change is intended to improve user security by ensuring that only apps associated with the domain mentioned in the message can programmatically read the verification code.
During this three hour delay, the SMS_RECEIVED_ACTION broadcast is
withheld and SMS provider database queries are filtered. The
SMS message is available to these apps after the delay. This change applies to
all apps, regardless of their target API level.
Certain apps such as the default SMS assistant app, connected device companion apps, etc., are exempted from this delay. All apps that rely on reading SMS messages for OTP extraction should transition to using SMS Retriever or SMS User Consent APIs to ensure continued functionality.
सुरक्षा
Android 17 में, डिवाइस और ऐप्लिकेशन की सुरक्षा को बेहतर बनाने के लिए ये बदलाव किए गए हैं.
usesClearTraffic के बंद होने का प्लान
In a future release, we plan to deprecate the usesCleartextTraffic element.
Apps that need to make unencrypted (HTTP) connections should migrate to
using a network security configuration file, which lets you
specify which domains your app needs to make cleartext connections to.
Be aware that network security configuration files are only supported on API levels 24 and higher. If your app has a minimum API level lower than 24, you should do both of the following:
- Set the
usesCleartextTrafficattribute totrue - Use a network configuration file
If your app's minimum API level is 24 or higher, you can use a network
configuration file and you don't need to set usesCleartextTraffic.
यूआरआई के लिए, इंप्लिसिट ग्रांट को प्रतिबंधित करना
फ़िलहाल, अगर कोई ऐप्लिकेशन, ऐक्शन ACTION_SEND, ACTION_SEND_MULTIPLE या ACTION_IMAGE_CAPTURE वाले यूआरआई के साथ कोई इंटेंट लॉन्च करता है, तो सिस्टम टारगेट ऐप्लिकेशन को यूआरआई को पढ़ने और लिखने की अनुमतियां अपने-आप दे देता है. Android 18 से, सिस्टम इन अनुमतियों को अपने-आप नहीं देगा. इस वजह से, हमारा सुझाव है कि ऐप्लिकेशन, सिस्टम पर भरोसा करने के बजाय यूआरआई की ज़रूरी अनुमतियां साफ़ तौर पर दें.
अपने ऐप्लिकेशन में इन इंटेंट के इस्तेमाल का पता लगाने के लिए, उल्लंघन ट्रिगर करने के लिए StrictMode के साथ detectImplicitUriPermissionGrant() का इस्तेमाल करें:
Kotlin
val policy = StrictMode.VmPolicy.Builder() .detectImplicitUriPermissionGrant() .penaltyLog() .build() StrictMode.setVmPolicy(policy)
Java
StrictMode.VmPolicy policy = new StrictMode.VmPolicy.Builder() .detectImplicitUriPermissionGrant() .penaltyLog() .build(); StrictMode.setVmPolicy(policy);
इसके अलावा, लॉग किए गए उन अपवादों को मॉनिटर किया जा सकता है जिनमें यह मैसेज
Please set the grant explicitly in the app शामिल हो. यह मैसेज तब दिखता है, जब सिस्टम अनुमति को
अपने-आप सेट करता है. इन लॉग की निगरानी करने के लिए, यहां दी गई adb कमांड का इस्तेमाल करें:
adb logcat | grep "Please set the grant explicitly in the app"
ज़रूरी अनुमतियां देने के लिए, ACTION_SEND और ACTION_SEND_MULTIPLE इंटेंट में FLAG_GRANT_READ_URI_PERMISSION फ़्लैग जोड़ें:
Kotlin
intent.addFlags(Intent.FLAG_GRANT_READ_URI_PERMISSION)
Java
intent.addFlags(Intent.FLAG_GRANT_READ_URI_PERMISSION);
ACTION_IMAGE_CAPTURE इंटेंट के लिए, FLAG_GRANT_READ_URI_PERMISSION और FLAG_GRANT_WRITE_URI_PERMISSION, दोनों फ़्लैग शामिल करें:
Kotlin
intent.addFlags(Intent.FLAG_GRANT_READ_URI_PERMISSION or Intent.FLAG_GRANT_WRITE_URI_PERMISSION)
Java
intent.addFlags(Intent.FLAG_GRANT_READ_URI_PERMISSION | Intent.FLAG_GRANT_WRITE_URI_PERMISSION);
हर ऐप्लिकेशन के लिए कीस्टोर की सीमाएं
ऐप्लिकेशन को Android Keystore में बहुत ज़्यादा कुंजियां नहीं बनानी चाहिए, क्योंकि यह डिवाइस पर मौजूद सभी ऐप्लिकेशन के लिए शेयर किया गया संसाधन है. Android 17 से, सिस्टम यह तय करता है कि कोई ऐप्लिकेशन कितनी कुंजियों का मालिकाना हक रख सकता है. Android 17 (एपीआई लेवल 37) या उसके बाद के वर्शन को टारगेट करने वाले नॉन-सिस्टम ऐप्लिकेशन के लिए, 50,000 कुंजियों की सीमा तय की गई है. वहीं, अन्य सभी ऐप्लिकेशन के लिए, 2,00,000 कुंजियों की सीमा तय की गई है. सिस्टम ऐप्लिकेशन के लिए, 2,00,000 कुंजियों की सीमा तय की गई है. इससे कोई फ़र्क़ नहीं पड़ता कि वे किस एपीआई लेवल को टारगेट करते हैं.
अगर कोई ऐप्लिकेशन तय सीमा से ज़्यादा कुंजियां बनाने की कोशिश करता है, तो कुंजियां नहीं बन पाएंगी. साथ ही, KeyStoreException गड़बड़ी का मैसेज दिखेगा. अपवाद के मैसेज स्ट्रिंग में, कुंजी की सीमा के बारे में जानकारी होती है. अगर ऐप्लिकेशन, अपवाद पर getNumericErrorCode() को कॉल करता है, तो रिटर्न वैल्यू इस बात पर निर्भर करती है कि ऐप्लिकेशन किस एपीआई लेवल को टारगेट करता है:
- Android 17 (एपीआई लेवल 37) या इसके बाद के वर्शन को टारगेट करने वाले ऐप्लिकेशन के लिए:
getNumericErrorCode()नईERROR_TOO_MANY_KEYSवैल्यू दिखाता है. - अन्य सभी ऐप्लिकेशन:
getNumericErrorCode(),ERROR_INCORRECT_USAGEदिखाता है.
क्रॉस प्रोफ़ाइल के लूपबैक ट्रैफ़िक को ब्लॉक करना
Android 17 से, क्रॉस-प्रोफ़ाइल लूपबैक ट्रैफ़िक को डिफ़ॉल्ट रूप से अनुमति नहीं दी जाएगी. एक ही प्रोफ़ाइल में लूपबैक ट्रैफ़िक पर कोई असर नहीं पड़ता. यह बदलाव, Android 17 या इसके बाद के वर्शन पर चलने वाले सभी ऐप्लिकेशन पर लागू होता है. भले ही, ऐप्लिकेशन किसी भी एपीआई लेवल को टारगेट करता हो.
उपयोगकर्ता अनुभव और सिस्टम यूज़र इंटरफ़ेस (यूआई)
Android 17 में ये बदलाव किए गए हैं. इनका मकसद, लोगों को बेहतर और एक जैसा अनुभव देना है.
रोटेशन के बाद, IME की डिफ़ॉल्ट दृश्यता को वापस लाना
Android 17 से, डिवाइस के कॉन्फ़िगरेशन में बदलाव होने पर (उदाहरण के लिए, रोटेशन के ज़रिए) और ऐप्लिकेशन के ज़रिए इसे मैनेज न किए जाने पर, IME की पिछली सेटिंग वापस नहीं लाई जाती.
अगर आपके ऐप्लिकेशन के कॉन्फ़िगरेशन में ऐसा बदलाव होता है जिसे वह हैंडल नहीं कर पाता है और बदलाव के बाद ऐप्लिकेशन को कीबोर्ड की ज़रूरत होती है, तो आपको इसके लिए साफ़ तौर पर अनुरोध करना होगा. यह अनुरोध इनमें से किसी एक तरीके से किया जा सकता है:
android:windowSoftInputModeएट्रिब्यूट कोstateAlwaysVisibleपर सेट करें.- अपनी गतिविधि के
onCreate()तरीके में, प्रोग्राम के हिसाब से सॉफ़्ट कीबोर्ड का अनुरोध करें याonConfigurationChanged()तरीका जोड़ें.
लोगों से मिले इनपुट
Android 17 में ये बदलाव किए गए हैं. इनसे, ऐप्लिकेशन के कीबोर्ड और टचपैड जैसे ह्यूमन इनपुट डिवाइसों के साथ इंटरैक्ट करने के तरीके पर असर पड़ता है.
पॉइंटर कैप्चर करने के दौरान, टचपैड डिफ़ॉल्ट रूप से रिलेटिव इवेंट डिलीवर करते हैं
Beginning with Android 17, if an app requests pointer capture using
View.requestPointerCapture() and the user uses a touchpad, the system
recognizes pointer movement and scrolling gestures from the user's touches and
reports them to the app in the same way as pointer and scroll wheel movements
from a captured mouse. In most cases, this removes the need for apps that
support captured mice to add special handling logic for touchpads. For more
details, see the documentation for View.POINTER_CAPTURE_MODE_RELATIVE.
Previously, the system did not attempt to recognize gestures from the touchpad,
and instead delivered the raw, absolute finger locations to the app in a similar
format to touchscreen touches. If an app still requires this absolute data, it
should call the new View.requestPointerCapture(int) method with
View.POINTER_CAPTURE_MODE_ABSOLUTE instead.
मीडिया
Android 17 में, मीडिया के व्यवहार में ये बदलाव किए गए हैं.
बैकग्राउंड ऑडियो सुरक्षा कड़ी करना
Android 17 से, ऑडियो फ़्रेमवर्क बैकग्राउंड में ऑडियो इंटरैक्शन पर पाबंदियाँ लागू करता है. इनमें ऑडियो चलाना, ऑडियो फ़ोकस के अनुरोध, और वॉल्यूम बदलने वाले एपीआई शामिल हैं. ऐसा यह पक्का करने के लिए किया जाता है कि ये बदलाव उपयोगकर्ता ने जान-बूझकर शुरू किए हों.
अगर ऐप्लिकेशन, ऑडियो एपीआई को कॉल करने की कोशिश करता है, जबकि ऐप्लिकेशन मान्य लाइफ़साइकल में नहीं है, तो ऑडियो चलाने और वॉल्यूम बदलने वाले एपीआई बिना किसी अपवाद या गड़बड़ी का मैसेज दिए चुपचाप काम नहीं करते. ऑडियो फ़ोकस एपीआई, AUDIOFOCUS_REQUEST_FAILED नतीजे वाले कोड के साथ काम नहीं करता.
ज़्यादा जानकारी और इससे बचने के तरीकों के लिए, बैकग्राउंड में चलने वाले ऑडियो को सुरक्षित बनाना लेख पढ़ें.
कनेक्टिविटी
Android 17 में, डिवाइस की कनेक्टिविटी को बेहतर बनाने के लिए ये बदलाव किए गए हैं.
ब्लूटूथ कनेक्शन के बंद होने पर, अपने-आप फिर से कनेक्ट होने की सुविधा
Android 17 introduces autonomous re-pairing, a system-level enhancement designed to automatically resolve Bluetooth bond loss.
Previously, if a bond was lost, users had to manually navigate to Settings to unpair and then re-pair the peripheral. This feature builds upon the security improvement of Android 16 by allowing the system to re-establish bonds in the background without requiring users to manually navigate to Settings to unpair and re-pair peripherals.
While most apps will not require code changes, developers should be aware of the following behavior changes in Bluetooth stack:
- New pairing context: The
ACTION_PAIRING_REQUESTnow includes theEXTRA_PAIRING_CONTEXTextra which allows apps to distinguish between a standard pairing request and an autonomous system-initiated re-pairing attempt. - Conditional key updates: Existing security keys will only be replaced if the re-pairing is successful and new connection meets or exceeds the security level of the previous bond.
- Modified intent timing: The
ACTION_KEY_MISSINGintent is now broadcast only if the autonomous re-pairing attempt fails. This reduces unnecessary error handling in the app if the system successfully recovers the bond in the background. - User notification: The system manages re-pairing via new UI notifications and dialogs. Users will be prompted to confirm the re-pairing attempt to ensure they are aware of the reconnection.
Peripheral device manufacturers and companion app developers should verify that hardware and app gracefully handle bond transitions. To test this behavior, simulate a remote bond loss using either of the following methods:
- Manually remove the bond information from the peripheral device
- Manually unpair the device in: Settings > Connected devices