From 00455bf0fea9f879518a63bdc8210bda0cebd65c Mon Sep 17 00:00:00 2001 From: Jeff Sharkey Date: Fri, 4 Nov 2016 14:45:24 -0600 Subject: [PATCH] Give easy flag to disable Direct Boot emulation. Direct Boot emulation is encouraged to help developers test their apps, but it's not required. Test: cts-tradefed run cts-dev --module CtsAppSecurityHostTestCases --test android.appsecurity.cts.DirectBootHostTest#testDirectBootEmulated Bug: 30686636 Change-Id: I3bb2dd42c0f71e52d8b7cf8da7e50568f41aafb7 --- .../java/com/android/server/MountService.java | 15 ++++++++++++++- 1 file changed, 14 insertions(+), 1 deletion(-) diff --git a/services/core/java/com/android/server/MountService.java b/services/core/java/com/android/server/MountService.java index 8bb93263d9390..8b7b6a0f80162 100644 --- a/services/core/java/com/android/server/MountService.java +++ b/services/core/java/com/android/server/MountService.java @@ -201,6 +201,15 @@ class MountService extends IMountService.Stub // Disable this since it messes up long-running cryptfs operations. private static final boolean WATCHDOG_ENABLE = false; + /** + * Our goal is for all Android devices to be usable as development devices, + * which includes the new Direct Boot mode added in N. For devices that + * don't have native FBE support, we offer an emulation mode for developer + * testing purposes, but if it's prohibitively difficult to support this + * mode, it can be disabled for specific products using this flag. + */ + private static final boolean EMULATE_FBE_SUPPORTED = true; + private static final String TAG = "MountService"; private static final String TAG_STORAGE_BENCHMARK = "storage_benchmark"; @@ -1978,9 +1987,13 @@ class MountService extends IMountService.Stub waitForReady(); if ((mask & StorageManager.DEBUG_EMULATE_FBE) != 0) { + if (!EMULATE_FBE_SUPPORTED) { + throw new IllegalStateException( + "Emulation not supported on this device"); + } if (StorageManager.isFileEncryptedNativeOnly()) { throw new IllegalStateException( - "Emulation not available on device with native FBE"); + "Emulation not supported on device with native FBE"); } if (mLockPatternUtils.isCredentialRequiredToDecrypt(false)) { throw new IllegalStateException(