From 0191bba17cf78285aa38e0a91acbce112774d348 Mon Sep 17 00:00:00 2001 From: Jim Miller Date: Sun, 21 Aug 2011 14:47:59 -0700 Subject: [PATCH] Fix 4993068: Don't check password history when dpm sets the password This fixes a crash caused by permission problems when we try to update the password history and discover there's no password salt. The code attempts to create the salt, which triggers the exception. This could be fixed by wrapping the call with a clearCallingIdentity()/ restoreCallingIdentity(ident). However, while looking at it, it occurred to me that this can cause unexpected failures if the DPM tries to set the password twice or happens to set it to something in the password history. Instead, we should *always* allow the DPM to reset the password to whatever it wants, provided it passes the minimum password criteria. Change-Id: I1505b24f9c097ee5c2c44e4bf378ba90095b113b --- .../com/android/server/DevicePolicyManagerService.java | 7 ------- 1 file changed, 7 deletions(-) diff --git a/services/java/com/android/server/DevicePolicyManagerService.java b/services/java/com/android/server/DevicePolicyManagerService.java index d549308705649..f1b8bae47fcbd 100644 --- a/services/java/com/android/server/DevicePolicyManagerService.java +++ b/services/java/com/android/server/DevicePolicyManagerService.java @@ -1556,13 +1556,6 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub { return false; } } - - LockPatternUtils utils = new LockPatternUtils(mContext); - if(utils.checkPasswordHistory(password)) { - Slog.w(TAG, "resetPassword: password is the same as one of the last " - + getPasswordHistoryLength(null) + " passwords"); - return false; - } } int callingUid = Binder.getCallingUid();