Merge "Replace COMMON_CRITERIA_MODE setting with getter API" into rvc-dev

This commit is contained in:
Rubin Xu
2020-03-18 18:42:28 +00:00
committed by Android (Google) Code Review
7 changed files with 54 additions and 43 deletions

View File

@@ -6942,7 +6942,7 @@ package android.app.admin {
method public boolean isApplicationHidden(@NonNull android.content.ComponentName, String);
method public boolean isBackupServiceEnabled(@NonNull android.content.ComponentName);
method @Deprecated public boolean isCallerApplicationRestrictionsManagingPackage();
method public boolean isCommonCriteriaModeEnabled(@NonNull android.content.ComponentName);
method public boolean isCommonCriteriaModeEnabled(@Nullable android.content.ComponentName);
method public boolean isDeviceIdAttestationSupported();
method public boolean isDeviceOwnerApp(String);
method public boolean isEphemeralUser(@NonNull android.content.ComponentName);

View File

@@ -9289,7 +9289,6 @@ package android.provider {
field public static final String AUTOFILL_COMPAT_MODE_ALLOWED_PACKAGES = "autofill_compat_mode_allowed_packages";
field public static final String CARRIER_APP_NAMES = "carrier_app_names";
field public static final String CARRIER_APP_WHITELIST = "carrier_app_whitelist";
field public static final String COMMON_CRITERIA_MODE = "common_criteria_mode";
field public static final String DEFAULT_SM_DP_PLUS = "default_sm_dp_plus";
field public static final String DEVICE_DEMO_MODE = "device_demo_mode";
field public static final String DEVICE_PROVISIONING_MOBILE_DATA_ENABLED = "device_provisioning_mobile_data";

View File

@@ -11919,13 +11919,17 @@ public class DevicePolicyManager {
}
/**
* Called by device owner or profile owner of an organization-owned managed profile to return
* whether Common Criteria mode is currently enabled for the device.
* Returns whether Common Criteria mode is currently enabled. Device owner and profile owner of
* an organization-owned managed profile can query its own Common Criteria mode setting by
* calling this method with its admin {@link ComponentName}. Any caller can obtain the
* aggregated device-wide Common Criteria mode state by passing {@code null} as the
* {@code admin} argument.
*
* @param admin which {@link DeviceAdminReceiver} this request is associated with.
* @param admin which {@link DeviceAdminReceiver} this request is associated with, or
* {@code null} if the caller is not a device admin.
* @return {@code true} if Common Criteria mode is enabled, {@code false} otherwise.
*/
public boolean isCommonCriteriaModeEnabled(@NonNull ComponentName admin) {
public boolean isCommonCriteriaModeEnabled(@Nullable ComponentName admin) {
throwIfParentInstance("isCommonCriteriaModeEnabled");
if (mService != null) {
try {

View File

@@ -14191,19 +14191,6 @@ public final class Settings {
public static final String POWER_BUTTON_SUPPRESSION_DELAY_AFTER_GESTURE_WAKE =
"power_button_suppression_delay_after_gesture_wake";
/**
* An integer indicating whether the device is in Common Criteria mode. When enabled,
* certain device functionalities are tuned to meet the higher security level required
* by Common Criteria certification. Examples include:
* Bluetooth long term key material is additionally integrity-protected with AES-GCM.
* WiFi configuration store is additionally integrity-protected with AES-GCM.
* A value of 0 means Common Criteria mode is not enabled (default), a value of non-zero
* means Common Criteria mode is enabled.
* @hide
*/
@SystemApi
public static final String COMMON_CRITERIA_MODE = "common_criteria_mode";
/**
* The usage amount of advanced battery. The value is 0~100.
*

View File

@@ -199,7 +199,6 @@ public class SettingsBackupTest {
Settings.Global.CERT_PIN_UPDATE_CONTENT_URL,
Settings.Global.CERT_PIN_UPDATE_METADATA_URL,
Settings.Global.COMPATIBILITY_MODE,
Settings.Global.COMMON_CRITERIA_MODE,
Settings.Global.CONNECTIVITY_CHANGE_DELAY,
Settings.Global.CONNECTIVITY_METRICS_BUFFER_SIZE,
Settings.Global.CONNECTIVITY_SAMPLING_INTERVAL_IN_SECONDS,

View File

@@ -1076,6 +1076,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
private static final String TAG_PROFILE_OFF_DEADLINE = "profile-off-deadline";
private static final String TAG_ALWAYS_ON_VPN_PACKAGE = "vpn-package";
private static final String TAG_ALWAYS_ON_VPN_LOCKDOWN = "vpn-lockdown";
private static final String TAG_COMMON_CRITERIA_MODE = "common-criteria-mode";
DeviceAdminInfo info;
@@ -1206,7 +1207,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
public String mAlwaysOnVpnPackage;
public boolean mAlwaysOnVpnLockdown;
boolean mCommonCriteriaMode;
ActiveAdmin(DeviceAdminInfo _info, boolean parent) {
info = _info;
@@ -1454,6 +1455,9 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
if (mAlwaysOnVpnLockdown) {
writeAttributeValueToXml(out, TAG_ALWAYS_ON_VPN_LOCKDOWN, mAlwaysOnVpnLockdown);
}
if (mCommonCriteriaMode) {
writeAttributeValueToXml(out, TAG_COMMON_CRITERIA_MODE, mCommonCriteriaMode);
}
}
void writeTextToXml(XmlSerializer out, String tag, String text) throws IOException {
@@ -1704,6 +1708,9 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
} else if (TAG_ALWAYS_ON_VPN_LOCKDOWN.equals(tag)) {
mAlwaysOnVpnLockdown = Boolean.parseBoolean(
parser.getAttributeValue(null, ATTR_VALUE));
} else if (TAG_COMMON_CRITERIA_MODE.equals(tag)) {
mCommonCriteriaMode = Boolean.parseBoolean(
parser.getAttributeValue(null, ATTR_VALUE));
} else {
Slog.w(LOG_TAG, "Unknown admin tag: " + tag);
XmlUtils.skipCurrentTag(parser);
@@ -1940,6 +1947,8 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
pw.println(mAlwaysOnVpnPackage);
pw.print("mAlwaysOnVpnLockdown=");
pw.println(mAlwaysOnVpnLockdown);
pw.print("mCommonCriteriaMode=");
pw.println(mCommonCriteriaMode);
}
}
@@ -15606,28 +15615,38 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
}
@Override
public void setCommonCriteriaModeEnabled(ComponentName admin, boolean enabled) {
public void setCommonCriteriaModeEnabled(ComponentName who, boolean enabled) {
final int userId = mInjector.userHandleGetCallingUserId();
synchronized (getLockObject()) {
getActiveAdminForCallerLocked(admin,
final ActiveAdmin admin = getActiveAdminForCallerLocked(who,
DeviceAdminInfo.USES_POLICY_ORGANIZATION_OWNED_PROFILE_OWNER);
admin.mCommonCriteriaMode = enabled;
saveSettingsLocked(userId);
}
mInjector.binderWithCleanCallingIdentity(
() -> mInjector.settingsGlobalPutInt(Settings.Global.COMMON_CRITERIA_MODE,
enabled ? 1 : 0));
DevicePolicyEventLogger
.createEvent(DevicePolicyEnums.SET_COMMON_CRITERIA_MODE)
.setAdmin(admin)
.setAdmin(who)
.setBoolean(enabled)
.write();
}
@Override
public boolean isCommonCriteriaModeEnabled(ComponentName admin) {
synchronized (getLockObject()) {
getActiveAdminForCallerLocked(admin,
DeviceAdminInfo.USES_POLICY_ORGANIZATION_OWNED_PROFILE_OWNER);
public boolean isCommonCriteriaModeEnabled(ComponentName who) {
if (who != null) {
synchronized (getLockObject()) {
final ActiveAdmin admin = getActiveAdminForCallerLocked(who,
DeviceAdminInfo.USES_POLICY_ORGANIZATION_OWNED_PROFILE_OWNER);
return admin.mCommonCriteriaMode;
}
}
// Return aggregated state if caller is not admin (who == null).
synchronized (getLockObject()) {
// Only DO or COPE PO can turn on CC mode, so take a shortcut here and only look at
// their ActiveAdmin, instead of iterating through all admins.
final ActiveAdmin admin = getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceLocked(
UserHandle.USER_SYSTEM);
return admin != null ? admin.mCommonCriteriaMode : false;
}
return mInjector.settingsGlobalGetInt(Settings.Global.COMMON_CRITERIA_MODE, 0) != 0;
}
@Override

View File

@@ -5990,26 +5990,29 @@ public class DevicePolicyManagerTest extends DpmTestBase {
public void testSetCommonCriteriaMode_asDeviceOwner() throws Exception {
setDeviceOwner();
dpm.setCommonCriteriaModeEnabled(admin1, true);
verify(getServices().settings).settingsGlobalPutInt(
Settings.Global.COMMON_CRITERIA_MODE, 1);
assertFalse(dpm.isCommonCriteriaModeEnabled(admin1));
assertFalse(dpm.isCommonCriteriaModeEnabled(null));
dpm.setCommonCriteriaModeEnabled(admin1, true);
when(getServices().settings.settingsGlobalGetInt(Settings.Global.COMMON_CRITERIA_MODE, 0))
.thenReturn(1);
assertTrue(dpm.isCommonCriteriaModeEnabled(admin1));
assertTrue(dpm.isCommonCriteriaModeEnabled(null));
}
public void testSetCommonCriteriaMode_asPoOfOrgOwnedDevice() throws Exception {
setupProfileOwner();
configureProfileOwnerOfOrgOwnedDevice(admin1, DpmMockContext.CALLER_USER_HANDLE);
final int managedProfileUserId = 15;
final int managedProfileAdminUid = UserHandle.getUid(managedProfileUserId, 19436);
addManagedProfile(admin1, managedProfileAdminUid, admin1);
configureProfileOwnerOfOrgOwnedDevice(admin1, managedProfileUserId);
mContext.binder.callingUid = managedProfileAdminUid;
assertFalse(dpm.isCommonCriteriaModeEnabled(admin1));
assertFalse(dpm.isCommonCriteriaModeEnabled(null));
dpm.setCommonCriteriaModeEnabled(admin1, true);
verify(getServices().settings).settingsGlobalPutInt(
Settings.Global.COMMON_CRITERIA_MODE, 1);
when(getServices().settings.settingsGlobalGetInt(Settings.Global.COMMON_CRITERIA_MODE, 0))
.thenReturn(1);
assertTrue(dpm.isCommonCriteriaModeEnabled(admin1));
assertTrue(dpm.isCommonCriteriaModeEnabled(null));
}
public void testCanProfileOwnerResetPasswordWhenLocked_nonDirectBootAwarePo()