From 9ed66da8dfd15001cebe8f7ef453718f41f9904d Mon Sep 17 00:00:00 2001 From: Julia Reynolds Date: Tue, 26 Aug 2014 15:42:03 -0400 Subject: [PATCH] Limit the settings profile/device owners can update. Bug: 16351901 Change-Id: Id33a57ad651b5b7b58de0549eb90d5a1fe5c19c5 --- .../app/admin/DevicePolicyManager.java | 20 +++++++++++- .../DevicePolicyManagerService.java | 31 +++++++++++++++++++ 2 files changed, 50 insertions(+), 1 deletion(-) diff --git a/core/java/android/app/admin/DevicePolicyManager.java b/core/java/android/app/admin/DevicePolicyManager.java index 5c24540f5ead3..243e233c767f3 100644 --- a/core/java/android/app/admin/DevicePolicyManager.java +++ b/core/java/android/app/admin/DevicePolicyManager.java @@ -3157,6 +3157,20 @@ public class DevicePolicyManager { /** * Called by device owners to update {@link Settings.Global} settings. Validation that the value * of the setting is in the correct form for the setting type should be performed by the caller. + *

The settings that can be updated with this method are: + *

* * @param admin Which {@link DeviceAdminReceiver} this request is associated with. * @param setting The name of the setting to update. @@ -3176,7 +3190,11 @@ public class DevicePolicyManager { * Called by profile or device owners to update {@link Settings.Secure} settings. Validation * that the value of the setting is in the correct form for the setting type should be performed * by the caller. - * + *

The settings that can be updated with this method are: + *

* @param admin Which {@link DeviceAdminReceiver} this request is associated with. * @param setting The name of the setting to update. * @param value The value to update the setting to. diff --git a/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java b/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java index 7baa258845ae6..55ef53e0ab34e 100644 --- a/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java +++ b/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java @@ -167,6 +167,27 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub { DEVICE_OWNER_USER_RESTRICTIONS.add(UserManager.DISALLOW_SMS); } + private static final Set SECURE_SETTINGS_WHITELIST; + private static final Set GLOBAL_SETTINGS_WHITELIST; + static { + SECURE_SETTINGS_WHITELIST = new HashSet(); + SECURE_SETTINGS_WHITELIST.add(Settings.Secure.DEFAULT_INPUT_METHOD); + SECURE_SETTINGS_WHITELIST.add(Settings.Secure.SKIP_FIRST_USE_HINTS); + + GLOBAL_SETTINGS_WHITELIST = new HashSet(); + GLOBAL_SETTINGS_WHITELIST.add(Settings.Global.ADB_ENABLED); + GLOBAL_SETTINGS_WHITELIST.add(Settings.Global.AUTO_TIME); + GLOBAL_SETTINGS_WHITELIST.add(Settings.Global.AUTO_TIME_ZONE); + GLOBAL_SETTINGS_WHITELIST.add(Settings.Global.BLUETOOTH_ON); + GLOBAL_SETTINGS_WHITELIST.add(Settings.Global.DATA_ROAMING); + GLOBAL_SETTINGS_WHITELIST.add(Settings.Global.DEVELOPMENT_SETTINGS_ENABLED); + GLOBAL_SETTINGS_WHITELIST.add(Settings.Global.MODE_RINGER); + GLOBAL_SETTINGS_WHITELIST.add(Settings.Global.NETWORK_PREFERENCE); + GLOBAL_SETTINGS_WHITELIST.add(Settings.Global.USB_MASS_STORAGE_ENABLED); + GLOBAL_SETTINGS_WHITELIST.add(Settings.Global.WIFI_ON); + GLOBAL_SETTINGS_WHITELIST.add(Settings.Global.WIFI_SLEEP_POLICY); + } + final Context mContext; final UserManager mUserManager; final PowerManager.WakeLock mWakeLock; @@ -4964,6 +4985,11 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub { } getActiveAdminForCallerLocked(who, DeviceAdminInfo.USES_POLICY_DEVICE_OWNER); + if (!GLOBAL_SETTINGS_WHITELIST.contains(setting)) { + throw new SecurityException(String.format( + "Permission denial: device owners cannot update %1$s", setting)); + } + long id = Binder.clearCallingIdentity(); try { Settings.Global.putString(contentResolver, setting, value); @@ -4984,6 +5010,11 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub { } getActiveAdminForCallerLocked(who, DeviceAdminInfo.USES_POLICY_PROFILE_OWNER); + if (!SECURE_SETTINGS_WHITELIST.contains(setting)) { + throw new SecurityException(String.format( + "Permission denial: profile/device owners cannot update %1$s", setting)); + } + long id = Binder.clearCallingIdentity(); try { Settings.Secure.putStringForUser(contentResolver, setting, value, callingUserId);