diff --git a/api/current.txt b/api/current.txt index ce43f21e78cd7..3d734276d52de 100644 --- a/api/current.txt +++ b/api/current.txt @@ -6942,7 +6942,7 @@ package android.app.admin { method public boolean isApplicationHidden(@NonNull android.content.ComponentName, String); method public boolean isBackupServiceEnabled(@NonNull android.content.ComponentName); method @Deprecated public boolean isCallerApplicationRestrictionsManagingPackage(); - method public boolean isCommonCriteriaModeEnabled(@NonNull android.content.ComponentName); + method public boolean isCommonCriteriaModeEnabled(@Nullable android.content.ComponentName); method public boolean isDeviceIdAttestationSupported(); method public boolean isDeviceOwnerApp(String); method public boolean isEphemeralUser(@NonNull android.content.ComponentName); diff --git a/api/system-current.txt b/api/system-current.txt index 0fb80a205248f..1d7d468b7ffef 100755 --- a/api/system-current.txt +++ b/api/system-current.txt @@ -9289,7 +9289,6 @@ package android.provider { field public static final String AUTOFILL_COMPAT_MODE_ALLOWED_PACKAGES = "autofill_compat_mode_allowed_packages"; field public static final String CARRIER_APP_NAMES = "carrier_app_names"; field public static final String CARRIER_APP_WHITELIST = "carrier_app_whitelist"; - field public static final String COMMON_CRITERIA_MODE = "common_criteria_mode"; field public static final String DEFAULT_SM_DP_PLUS = "default_sm_dp_plus"; field public static final String DEVICE_DEMO_MODE = "device_demo_mode"; field public static final String DEVICE_PROVISIONING_MOBILE_DATA_ENABLED = "device_provisioning_mobile_data"; diff --git a/core/java/android/app/admin/DevicePolicyManager.java b/core/java/android/app/admin/DevicePolicyManager.java index 5b8ee71c8ba30..32e815e5b170e 100644 --- a/core/java/android/app/admin/DevicePolicyManager.java +++ b/core/java/android/app/admin/DevicePolicyManager.java @@ -11919,13 +11919,17 @@ public class DevicePolicyManager { } /** - * Called by device owner or profile owner of an organization-owned managed profile to return - * whether Common Criteria mode is currently enabled for the device. + * Returns whether Common Criteria mode is currently enabled. Device owner and profile owner of + * an organization-owned managed profile can query its own Common Criteria mode setting by + * calling this method with its admin {@link ComponentName}. Any caller can obtain the + * aggregated device-wide Common Criteria mode state by passing {@code null} as the + * {@code admin} argument. * - * @param admin which {@link DeviceAdminReceiver} this request is associated with. + * @param admin which {@link DeviceAdminReceiver} this request is associated with, or + * {@code null} if the caller is not a device admin. * @return {@code true} if Common Criteria mode is enabled, {@code false} otherwise. */ - public boolean isCommonCriteriaModeEnabled(@NonNull ComponentName admin) { + public boolean isCommonCriteriaModeEnabled(@Nullable ComponentName admin) { throwIfParentInstance("isCommonCriteriaModeEnabled"); if (mService != null) { try { diff --git a/core/java/android/provider/Settings.java b/core/java/android/provider/Settings.java index d8679b20e6dcc..ff34055b70858 100644 --- a/core/java/android/provider/Settings.java +++ b/core/java/android/provider/Settings.java @@ -14191,19 +14191,6 @@ public final class Settings { public static final String POWER_BUTTON_SUPPRESSION_DELAY_AFTER_GESTURE_WAKE = "power_button_suppression_delay_after_gesture_wake"; - /** - * An integer indicating whether the device is in Common Criteria mode. When enabled, - * certain device functionalities are tuned to meet the higher security level required - * by Common Criteria certification. Examples include: - * Bluetooth long term key material is additionally integrity-protected with AES-GCM. - * WiFi configuration store is additionally integrity-protected with AES-GCM. - * A value of 0 means Common Criteria mode is not enabled (default), a value of non-zero - * means Common Criteria mode is enabled. - * @hide - */ - @SystemApi - public static final String COMMON_CRITERIA_MODE = "common_criteria_mode"; - /** * The usage amount of advanced battery. The value is 0~100. * diff --git a/packages/SettingsProvider/test/src/android/provider/SettingsBackupTest.java b/packages/SettingsProvider/test/src/android/provider/SettingsBackupTest.java index 610165a44626e..dab050533ecbc 100644 --- a/packages/SettingsProvider/test/src/android/provider/SettingsBackupTest.java +++ b/packages/SettingsProvider/test/src/android/provider/SettingsBackupTest.java @@ -199,7 +199,6 @@ public class SettingsBackupTest { Settings.Global.CERT_PIN_UPDATE_CONTENT_URL, Settings.Global.CERT_PIN_UPDATE_METADATA_URL, Settings.Global.COMPATIBILITY_MODE, - Settings.Global.COMMON_CRITERIA_MODE, Settings.Global.CONNECTIVITY_CHANGE_DELAY, Settings.Global.CONNECTIVITY_METRICS_BUFFER_SIZE, Settings.Global.CONNECTIVITY_SAMPLING_INTERVAL_IN_SECONDS, diff --git a/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java b/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java index fc9044a8cfa16..6ab5303b41e4f 100644 --- a/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java +++ b/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java @@ -1076,6 +1076,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager { private static final String TAG_PROFILE_OFF_DEADLINE = "profile-off-deadline"; private static final String TAG_ALWAYS_ON_VPN_PACKAGE = "vpn-package"; private static final String TAG_ALWAYS_ON_VPN_LOCKDOWN = "vpn-lockdown"; + private static final String TAG_COMMON_CRITERIA_MODE = "common-criteria-mode"; DeviceAdminInfo info; @@ -1206,7 +1207,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager { public String mAlwaysOnVpnPackage; public boolean mAlwaysOnVpnLockdown; - + boolean mCommonCriteriaMode; ActiveAdmin(DeviceAdminInfo _info, boolean parent) { info = _info; @@ -1454,6 +1455,9 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager { if (mAlwaysOnVpnLockdown) { writeAttributeValueToXml(out, TAG_ALWAYS_ON_VPN_LOCKDOWN, mAlwaysOnVpnLockdown); } + if (mCommonCriteriaMode) { + writeAttributeValueToXml(out, TAG_COMMON_CRITERIA_MODE, mCommonCriteriaMode); + } } void writeTextToXml(XmlSerializer out, String tag, String text) throws IOException { @@ -1704,6 +1708,9 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager { } else if (TAG_ALWAYS_ON_VPN_LOCKDOWN.equals(tag)) { mAlwaysOnVpnLockdown = Boolean.parseBoolean( parser.getAttributeValue(null, ATTR_VALUE)); + } else if (TAG_COMMON_CRITERIA_MODE.equals(tag)) { + mCommonCriteriaMode = Boolean.parseBoolean( + parser.getAttributeValue(null, ATTR_VALUE)); } else { Slog.w(LOG_TAG, "Unknown admin tag: " + tag); XmlUtils.skipCurrentTag(parser); @@ -1940,6 +1947,8 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager { pw.println(mAlwaysOnVpnPackage); pw.print("mAlwaysOnVpnLockdown="); pw.println(mAlwaysOnVpnLockdown); + pw.print("mCommonCriteriaMode="); + pw.println(mCommonCriteriaMode); } } @@ -15606,28 +15615,38 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager { } @Override - public void setCommonCriteriaModeEnabled(ComponentName admin, boolean enabled) { + public void setCommonCriteriaModeEnabled(ComponentName who, boolean enabled) { + final int userId = mInjector.userHandleGetCallingUserId(); synchronized (getLockObject()) { - getActiveAdminForCallerLocked(admin, + final ActiveAdmin admin = getActiveAdminForCallerLocked(who, DeviceAdminInfo.USES_POLICY_ORGANIZATION_OWNED_PROFILE_OWNER); + admin.mCommonCriteriaMode = enabled; + saveSettingsLocked(userId); } - mInjector.binderWithCleanCallingIdentity( - () -> mInjector.settingsGlobalPutInt(Settings.Global.COMMON_CRITERIA_MODE, - enabled ? 1 : 0)); DevicePolicyEventLogger .createEvent(DevicePolicyEnums.SET_COMMON_CRITERIA_MODE) - .setAdmin(admin) + .setAdmin(who) .setBoolean(enabled) .write(); } @Override - public boolean isCommonCriteriaModeEnabled(ComponentName admin) { - synchronized (getLockObject()) { - getActiveAdminForCallerLocked(admin, - DeviceAdminInfo.USES_POLICY_ORGANIZATION_OWNED_PROFILE_OWNER); + public boolean isCommonCriteriaModeEnabled(ComponentName who) { + if (who != null) { + synchronized (getLockObject()) { + final ActiveAdmin admin = getActiveAdminForCallerLocked(who, + DeviceAdminInfo.USES_POLICY_ORGANIZATION_OWNED_PROFILE_OWNER); + return admin.mCommonCriteriaMode; + } + } + // Return aggregated state if caller is not admin (who == null). + synchronized (getLockObject()) { + // Only DO or COPE PO can turn on CC mode, so take a shortcut here and only look at + // their ActiveAdmin, instead of iterating through all admins. + final ActiveAdmin admin = getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceLocked( + UserHandle.USER_SYSTEM); + return admin != null ? admin.mCommonCriteriaMode : false; } - return mInjector.settingsGlobalGetInt(Settings.Global.COMMON_CRITERIA_MODE, 0) != 0; } @Override diff --git a/services/tests/servicestests/src/com/android/server/devicepolicy/DevicePolicyManagerTest.java b/services/tests/servicestests/src/com/android/server/devicepolicy/DevicePolicyManagerTest.java index d038d6c1ca7ff..f57b5f246978e 100644 --- a/services/tests/servicestests/src/com/android/server/devicepolicy/DevicePolicyManagerTest.java +++ b/services/tests/servicestests/src/com/android/server/devicepolicy/DevicePolicyManagerTest.java @@ -5990,26 +5990,29 @@ public class DevicePolicyManagerTest extends DpmTestBase { public void testSetCommonCriteriaMode_asDeviceOwner() throws Exception { setDeviceOwner(); - dpm.setCommonCriteriaModeEnabled(admin1, true); - verify(getServices().settings).settingsGlobalPutInt( - Settings.Global.COMMON_CRITERIA_MODE, 1); + assertFalse(dpm.isCommonCriteriaModeEnabled(admin1)); + assertFalse(dpm.isCommonCriteriaModeEnabled(null)); + + dpm.setCommonCriteriaModeEnabled(admin1, true); - when(getServices().settings.settingsGlobalGetInt(Settings.Global.COMMON_CRITERIA_MODE, 0)) - .thenReturn(1); assertTrue(dpm.isCommonCriteriaModeEnabled(admin1)); + assertTrue(dpm.isCommonCriteriaModeEnabled(null)); } public void testSetCommonCriteriaMode_asPoOfOrgOwnedDevice() throws Exception { - setupProfileOwner(); - configureProfileOwnerOfOrgOwnedDevice(admin1, DpmMockContext.CALLER_USER_HANDLE); + final int managedProfileUserId = 15; + final int managedProfileAdminUid = UserHandle.getUid(managedProfileUserId, 19436); + addManagedProfile(admin1, managedProfileAdminUid, admin1); + configureProfileOwnerOfOrgOwnedDevice(admin1, managedProfileUserId); + mContext.binder.callingUid = managedProfileAdminUid; + + assertFalse(dpm.isCommonCriteriaModeEnabled(admin1)); + assertFalse(dpm.isCommonCriteriaModeEnabled(null)); dpm.setCommonCriteriaModeEnabled(admin1, true); - verify(getServices().settings).settingsGlobalPutInt( - Settings.Global.COMMON_CRITERIA_MODE, 1); - when(getServices().settings.settingsGlobalGetInt(Settings.Global.COMMON_CRITERIA_MODE, 0)) - .thenReturn(1); assertTrue(dpm.isCommonCriteriaModeEnabled(admin1)); + assertTrue(dpm.isCommonCriteriaModeEnabled(null)); } public void testCanProfileOwnerResetPasswordWhenLocked_nonDirectBootAwarePo()