Merge changes I64307527,Id230f8b1 into udc-dev
* changes: Headless fixes for cross profile apps. Throw SecurityException when an admin uses the setUserRestrictionGlobally method.
This commit is contained in:
committed by
Android (Google) Code Review
commit
53026af587
@@ -9599,6 +9599,7 @@ public class DevicePolicyManager {
|
||||
} catch (RemoteException e) {
|
||||
throw e.rethrowFromSystemServer();
|
||||
} catch (IllegalArgumentException ex) {
|
||||
Log.e(TAG, "IllegalArgumentException checking isPackageSuspended", ex);
|
||||
throw new NameNotFoundException(packageName);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -7515,6 +7515,7 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
|
||||
boolean success = false;
|
||||
try {
|
||||
if (getCurrentForegroundUserId() == userId) {
|
||||
// TODO: We need to special case headless here as we can't switch to the system user
|
||||
mInjector.getIActivityManager().switchUser(UserHandle.USER_SYSTEM);
|
||||
}
|
||||
|
||||
@@ -7522,7 +7523,8 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
|
||||
if (!success) {
|
||||
Slogf.w(LOG_TAG, "Couldn't remove user " + userId);
|
||||
} else if (isManagedProfile(userId) && !wipeSilently) {
|
||||
sendWipeProfileNotification(wipeReasonForUser);
|
||||
sendWipeProfileNotification(wipeReasonForUser,
|
||||
UserHandle.of(getProfileParentId(userId)));
|
||||
}
|
||||
} catch (RemoteException re) {
|
||||
// Shouldn't happen
|
||||
@@ -7870,7 +7872,7 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
|
||||
});
|
||||
}
|
||||
|
||||
private void sendWipeProfileNotification(String wipeReasonForUser) {
|
||||
private void sendWipeProfileNotification(String wipeReasonForUser, UserHandle user) {
|
||||
Notification notification =
|
||||
new Notification.Builder(mContext, SystemNotificationChannels.DEVICE_ADMIN)
|
||||
.setSmallIcon(android.R.drawable.stat_sys_warning)
|
||||
@@ -7879,7 +7881,8 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
|
||||
.setColor(mContext.getColor(R.color.system_notification_accent_color))
|
||||
.setStyle(new Notification.BigTextStyle().bigText(wipeReasonForUser))
|
||||
.build();
|
||||
mInjector.getNotificationManager().notify(SystemMessage.NOTE_PROFILE_WIPED, notification);
|
||||
mInjector.getNotificationManager().notifyAsUser(
|
||||
/* tag= */ null, SystemMessage.NOTE_PROFILE_WIPED, notification, user);
|
||||
}
|
||||
|
||||
private String getWorkProfileDeletedTitle() {
|
||||
@@ -13380,7 +13383,7 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
|
||||
throw new IllegalStateException("Feature flag is not enabled.");
|
||||
}
|
||||
if (isDeviceOwner(caller) || isProfileOwner(caller)) {
|
||||
throw new IllegalStateException("Admins are not allowed to call this API.");
|
||||
throw new SecurityException("Admins are not allowed to call this API.");
|
||||
}
|
||||
if (!mInjector.isChangeEnabled(
|
||||
ENABLE_COEXISTENCE_CHANGE, callerPackage, caller.getUserId())) {
|
||||
@@ -16946,6 +16949,7 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
|
||||
} else {
|
||||
granted = PackageManager.PERMISSION_GRANTED;
|
||||
}
|
||||
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -20049,6 +20053,7 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
|
||||
if (!mHasFeature) {
|
||||
return;
|
||||
}
|
||||
|
||||
Objects.requireNonNull(who, "ComponentName is null");
|
||||
Objects.requireNonNull(packageNames, "Package names is null");
|
||||
final CallerIdentity caller = getCallerIdentity(who);
|
||||
@@ -20065,9 +20070,12 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
|
||||
saveSettingsLocked(caller.getUserId());
|
||||
}
|
||||
logSetCrossProfilePackages(who, packageNames);
|
||||
final CrossProfileApps crossProfileApps = mContext.getSystemService(CrossProfileApps.class);
|
||||
final CrossProfileApps crossProfileApps =
|
||||
mContext.createContextAsUser(
|
||||
caller.getUserHandle(), /* flags= */ 0)
|
||||
.getSystemService(CrossProfileApps.class);
|
||||
mInjector.binderWithCleanCallingIdentity(
|
||||
() -> crossProfileApps.resetInteractAcrossProfilesAppOps(
|
||||
() -> crossProfileApps.resetInteractAcrossProfilesAppOps(
|
||||
previousCrossProfilePackages, new HashSet<>(packageNames)));
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user