diff --git a/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java b/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java index 8a7134e24cf86..7f466f38e96a5 100644 --- a/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java +++ b/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java @@ -8513,6 +8513,13 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager { } } + private boolean isDeviceOwnerUserId(int userId) { + synchronized (getLockObject()) { + return mOwners.getDeviceOwnerComponent() != null + && mOwners.getDeviceOwnerUserId() == userId; + } + } + private boolean isDeviceOwnerPackage(String packageName, int userId) { synchronized (getLockObject()) { return mOwners.hasDeviceOwner() @@ -12117,10 +12124,11 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager { return; } final CallerIdentity caller = getCallerIdentity(); - Preconditions.checkCallAuthorization(isProfileOwner(caller) + Preconditions.checkCallAuthorization((isProfileOwner(caller) + && isManagedProfile(caller.getUserId())) || isDefaultDeviceOwner(caller), - "Caller is not profile owner or device owner;" - + " only profile owner or device owner may control the preferential" + "Caller is not managed profile owner or device owner;" + + " only managed profile owner or device owner may control the preferential" + " network service"); synchronized (getLockObject()) { final ActiveAdmin requiredAdmin = getDeviceOrProfileOwnerAdminLocked( @@ -12147,11 +12155,12 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager { } final CallerIdentity caller = getCallerIdentity(); - Preconditions.checkCallAuthorization(isProfileOwner(caller) + Preconditions.checkCallAuthorization((isProfileOwner(caller) + && isManagedProfile(caller.getUserId())) || isDefaultDeviceOwner(caller), - "Caller is not profile owner or device owner;" - + " only profile owner or device owner may retrieve the preferential" - + " network service configurations"); + "Caller is not managed profile owner or device owner;" + + " only managed profile owner or device owner may retrieve the " + + "preferential network service configurations"); synchronized (getLockObject()) { final ActiveAdmin requiredAdmin = getDeviceOrProfileOwnerAdminLocked( caller.getUserId()); @@ -18266,7 +18275,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager { private void updateNetworkPreferenceForUser(int userId, List preferentialNetworkServiceConfigs) { - if (!isManagedProfile(userId)) { + if (!isManagedProfile(userId) && !isDeviceOwnerUserId(userId)) { return; } List preferences = new ArrayList<>();