Merge "Allow affiliated profile owner to grant sensor permissions." into sc-v2-dev am: 959324fe84

Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/15677665

Change-Id: I2315e4710f6123d8155be54fba6b3eb6838f3c8c
This commit is contained in:
TreeHugger Robot
2021-09-14 15:28:52 +00:00
committed by Automerger Merge Worker
2 changed files with 27 additions and 12 deletions

View File

@@ -46,6 +46,12 @@ public class DevicePolicyCacheImpl extends DevicePolicyCache {
@GuardedBy("mLock") @GuardedBy("mLock")
private final SparseIntArray mPermissionPolicy = new SparseIntArray(); private final SparseIntArray mPermissionPolicy = new SparseIntArray();
/** Maps to {@code ActiveAdmin.mAdminCanGrantSensorsPermissions}.
*
* <p>For users affiliated with the device, they inherit the policy from {@code DO} so
* it will map to the {@code DO}'s policy. Otherwise it will map to the admin of the requesting
* user.
*/
@GuardedBy("mLock") @GuardedBy("mLock")
private final SparseBooleanArray mCanGrantSensorsPermissions = new SparseBooleanArray(); private final SparseBooleanArray mCanGrantSensorsPermissions = new SparseBooleanArray();
@@ -102,17 +108,16 @@ public class DevicePolicyCacheImpl extends DevicePolicyCache {
} }
@Override @Override
public boolean canAdminGrantSensorsPermissionsForUser(@UserIdInt int userHandle) { public boolean canAdminGrantSensorsPermissionsForUser(@UserIdInt int userId) {
synchronized (mLock) { synchronized (mLock) {
return mCanGrantSensorsPermissions.get(userHandle, false); return mCanGrantSensorsPermissions.get(userId, false);
} }
} }
/** Sets ahmin control over permission grants for user. */ /** Sets ahmin control over permission grants for user. */
public void setAdminCanGrantSensorsPermissions(@UserIdInt int userHandle, public void setAdminCanGrantSensorsPermissions(@UserIdInt int userId, boolean canGrant) {
boolean canGrant) {
synchronized (mLock) { synchronized (mLock) {
mCanGrantSensorsPermissions.put(userHandle, canGrant); mCanGrantSensorsPermissions.put(userId, canGrant);
} }
} }

View File

@@ -9144,9 +9144,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
} }
/** /**
* Returns the ActiveAdmin associated wit the PO or DO on the given user. * Returns the ActiveAdmin associated with the PO or DO on the given user.
* @param userHandle
* @return
*/ */
private @Nullable ActiveAdmin getDeviceOrProfileOwnerAdminLocked(int userHandle) { private @Nullable ActiveAdmin getDeviceOrProfileOwnerAdminLocked(int userHandle) {
ActiveAdmin admin = getProfileOwnerAdminLocked(userHandle); ActiveAdmin admin = getProfileOwnerAdminLocked(userHandle);
@@ -14306,6 +14304,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
maybePauseDeviceWideLoggingLocked(); maybePauseDeviceWideLoggingLocked();
maybeResumeDeviceWideLoggingLocked(); maybeResumeDeviceWideLoggingLocked();
maybeClearLockTaskPolicyLocked(); maybeClearLockTaskPolicyLocked();
updateAdminCanGrantSensorsPermissionCache(callingUserId);
} }
} }
@@ -17483,7 +17482,10 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
}); });
} }
private void setAdminCanGrantSensorsPermissionForUserUnchecked(int userId, boolean canGrant) { private void setAdminCanGrantSensorsPermissionForUserUnchecked(@UserIdInt int userId,
boolean canGrant) {
Slogf.d(LOG_TAG, "setAdminCanGrantSensorsPermissionForUserUnchecked(%d, %b)",
userId, canGrant);
synchronized (getLockObject()) { synchronized (getLockObject()) {
ActiveAdmin owner = getDeviceOrProfileOwnerAdminLocked(userId); ActiveAdmin owner = getDeviceOrProfileOwnerAdminLocked(userId);
@@ -17497,10 +17499,18 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
} }
} }
private void updateAdminCanGrantSensorsPermissionCache(int userId) { private void updateAdminCanGrantSensorsPermissionCache(@UserIdInt int userId) {
synchronized (getLockObject()) { synchronized (getLockObject()) {
ActiveAdmin owner = getDeviceOrProfileOwnerAdminLocked(userId);
final boolean canGrant = owner != null ? owner.mAdminCanGrantSensorsPermissions : false; ActiveAdmin owner;
// If the user is affiliated the device (either a DO itself, or an affiliated PO),
// use mAdminCanGrantSensorsPermissions from the DO
if (isUserAffiliatedWithDeviceLocked(userId)) {
owner = getDeviceOwnerAdminLocked();
} else {
owner = getDeviceOrProfileOwnerAdminLocked(userId);
}
boolean canGrant = owner != null ? owner.mAdminCanGrantSensorsPermissions : false;
mPolicyCache.setAdminCanGrantSensorsPermissions(userId, canGrant); mPolicyCache.setAdminCanGrantSensorsPermissions(userId, canGrant);
} }
} }