Merge "LockSettingsService: clear gatekeeper state when removing user" into tm-dev

This commit is contained in:
Alain Vongsouvanh
2022-03-28 15:19:06 +00:00
committed by Android (Google) Code Review
2 changed files with 9 additions and 2 deletions

View File

@@ -2473,7 +2473,7 @@ public class LockSettingsService extends ILockSettings.Stub {
private void removeUser(int userId, boolean unknownUser) {
Slog.i(TAG, "RemoveUser: " + userId);
removeBiometricsForUser(userId);
mSpManager.removeUser(userId);
mSpManager.removeUser(getGateKeeperService(), userId);
mStrongAuth.removeUser(userId);
AndroidKeyStoreMaintenance.onUserRemoved(userId);

View File

@@ -565,11 +565,18 @@ public class SyntheticPasswordManager {
return response[0];
}
public void removeUser(int userId) {
public void removeUser(IGateKeeperService gatekeeper, int userId) {
for (long handle : mStorage.listSyntheticPasswordHandlesForUser(SP_BLOB_NAME, userId)) {
destroyWeaverSlot(handle, userId);
destroySPBlobKey(getKeyName(handle));
}
// Remove potential persistent state (in RPMB), to prevent them from accumulating and
// causing problems.
try {
gatekeeper.clearSecureUserId(fakeUid(userId));
} catch (RemoteException ignore) {
Slog.w(TAG, "Failed to clear SID from gatekeeper");
}
}
int getCredentialType(long handle, int userId) {