Merge "Allow affiliated profile owner to grant sensor permissions." into sc-v2-dev am: 959324fe84
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/15677665 Change-Id: I2315e4710f6123d8155be54fba6b3eb6838f3c8c
This commit is contained in:
@@ -46,6 +46,12 @@ public class DevicePolicyCacheImpl extends DevicePolicyCache {
|
|||||||
@GuardedBy("mLock")
|
@GuardedBy("mLock")
|
||||||
private final SparseIntArray mPermissionPolicy = new SparseIntArray();
|
private final SparseIntArray mPermissionPolicy = new SparseIntArray();
|
||||||
|
|
||||||
|
/** Maps to {@code ActiveAdmin.mAdminCanGrantSensorsPermissions}.
|
||||||
|
*
|
||||||
|
* <p>For users affiliated with the device, they inherit the policy from {@code DO} so
|
||||||
|
* it will map to the {@code DO}'s policy. Otherwise it will map to the admin of the requesting
|
||||||
|
* user.
|
||||||
|
*/
|
||||||
@GuardedBy("mLock")
|
@GuardedBy("mLock")
|
||||||
private final SparseBooleanArray mCanGrantSensorsPermissions = new SparseBooleanArray();
|
private final SparseBooleanArray mCanGrantSensorsPermissions = new SparseBooleanArray();
|
||||||
|
|
||||||
@@ -102,17 +108,16 @@ public class DevicePolicyCacheImpl extends DevicePolicyCache {
|
|||||||
}
|
}
|
||||||
|
|
||||||
@Override
|
@Override
|
||||||
public boolean canAdminGrantSensorsPermissionsForUser(@UserIdInt int userHandle) {
|
public boolean canAdminGrantSensorsPermissionsForUser(@UserIdInt int userId) {
|
||||||
synchronized (mLock) {
|
synchronized (mLock) {
|
||||||
return mCanGrantSensorsPermissions.get(userHandle, false);
|
return mCanGrantSensorsPermissions.get(userId, false);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
/** Sets ahmin control over permission grants for user. */
|
/** Sets ahmin control over permission grants for user. */
|
||||||
public void setAdminCanGrantSensorsPermissions(@UserIdInt int userHandle,
|
public void setAdminCanGrantSensorsPermissions(@UserIdInt int userId, boolean canGrant) {
|
||||||
boolean canGrant) {
|
|
||||||
synchronized (mLock) {
|
synchronized (mLock) {
|
||||||
mCanGrantSensorsPermissions.put(userHandle, canGrant);
|
mCanGrantSensorsPermissions.put(userId, canGrant);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -9144,9 +9144,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
|
|||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Returns the ActiveAdmin associated wit the PO or DO on the given user.
|
* Returns the ActiveAdmin associated with the PO or DO on the given user.
|
||||||
* @param userHandle
|
|
||||||
* @return
|
|
||||||
*/
|
*/
|
||||||
private @Nullable ActiveAdmin getDeviceOrProfileOwnerAdminLocked(int userHandle) {
|
private @Nullable ActiveAdmin getDeviceOrProfileOwnerAdminLocked(int userHandle) {
|
||||||
ActiveAdmin admin = getProfileOwnerAdminLocked(userHandle);
|
ActiveAdmin admin = getProfileOwnerAdminLocked(userHandle);
|
||||||
@@ -14306,6 +14304,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
|
|||||||
maybePauseDeviceWideLoggingLocked();
|
maybePauseDeviceWideLoggingLocked();
|
||||||
maybeResumeDeviceWideLoggingLocked();
|
maybeResumeDeviceWideLoggingLocked();
|
||||||
maybeClearLockTaskPolicyLocked();
|
maybeClearLockTaskPolicyLocked();
|
||||||
|
updateAdminCanGrantSensorsPermissionCache(callingUserId);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -17483,7 +17482,10 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
private void setAdminCanGrantSensorsPermissionForUserUnchecked(int userId, boolean canGrant) {
|
private void setAdminCanGrantSensorsPermissionForUserUnchecked(@UserIdInt int userId,
|
||||||
|
boolean canGrant) {
|
||||||
|
Slogf.d(LOG_TAG, "setAdminCanGrantSensorsPermissionForUserUnchecked(%d, %b)",
|
||||||
|
userId, canGrant);
|
||||||
synchronized (getLockObject()) {
|
synchronized (getLockObject()) {
|
||||||
ActiveAdmin owner = getDeviceOrProfileOwnerAdminLocked(userId);
|
ActiveAdmin owner = getDeviceOrProfileOwnerAdminLocked(userId);
|
||||||
|
|
||||||
@@ -17497,10 +17499,18 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
private void updateAdminCanGrantSensorsPermissionCache(int userId) {
|
private void updateAdminCanGrantSensorsPermissionCache(@UserIdInt int userId) {
|
||||||
synchronized (getLockObject()) {
|
synchronized (getLockObject()) {
|
||||||
ActiveAdmin owner = getDeviceOrProfileOwnerAdminLocked(userId);
|
|
||||||
final boolean canGrant = owner != null ? owner.mAdminCanGrantSensorsPermissions : false;
|
ActiveAdmin owner;
|
||||||
|
// If the user is affiliated the device (either a DO itself, or an affiliated PO),
|
||||||
|
// use mAdminCanGrantSensorsPermissions from the DO
|
||||||
|
if (isUserAffiliatedWithDeviceLocked(userId)) {
|
||||||
|
owner = getDeviceOwnerAdminLocked();
|
||||||
|
} else {
|
||||||
|
owner = getDeviceOrProfileOwnerAdminLocked(userId);
|
||||||
|
}
|
||||||
|
boolean canGrant = owner != null ? owner.mAdminCanGrantSensorsPermissions : false;
|
||||||
mPolicyCache.setAdminCanGrantSensorsPermissions(userId, canGrant);
|
mPolicyCache.setAdminCanGrantSensorsPermissions(userId, canGrant);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user