Delay unlock attempts for managed profiles.

Managed profiles may not have a credential challenge, so we need to
make sure we don't unlock them until their parent user has been
unlocked.  Otherwise the managed profile will get into all sorts of
trouble trying to reach into its still-locked parent.

Bug: 28051109, 27457806
Change-Id: If2ca59834024e5ad039f659d611ef708ed751fad
This commit is contained in:
Jeff Sharkey
2016-04-07 01:20:58 -06:00
parent 74cd3de6f4
commit 5dab713ff0

View File

@@ -237,7 +237,13 @@ final class UserController {
AppOpsManager.OP_NONE, null, true, false, MY_PID, SYSTEM_UID, userId);
}
maybeUnlockUser(userId);
// We only attempt to unlock real users here; we delay unlocking
// profiles until after the parent user is unlocked.
if (getUserManager().isManagedProfile(userId)) {
Slog.d(TAG, "User " + userId + " is managed profile; delaying unlock attempt");
} else {
maybeUnlockUser(userId);
}
}
}
@@ -905,6 +911,20 @@ final class UserController {
finishUserUnlocking(uss, progress);
}
// We just unlocked a user, so let's now attempt to unlock any managed
// profiles under that user.
synchronized (mService) {
for (int i = 0; i < mStartedUsers.size(); i++) {
final int testUserId = mStartedUsers.keyAt(i);
final UserInfo parent = getUserManager().getProfileParent(testUserId);
if (parent != null && parent.id == userId && testUserId != userId) {
Slog.d(TAG, "Found user " + testUserId + " with parent " + userId
+ "; attempting unlock");
maybeUnlockUser(testUserId);
}
}
}
return true;
}