From 62dbf2533080e2332f71757a7e3a55227946835f Mon Sep 17 00:00:00 2001 From: Eric Biggers Date: Mon, 26 Jun 2023 23:11:07 +0000 Subject: [PATCH] DPMS: allow getPasswordMinimumMetrics() to anyone who can set LSKF Everyone who sets a new LSKF is supposed to first validate it against the minimum password metrics. Yet, the SET_AND_VERIFY_LOCKSCREEN_CREDENTIALS or ACCESS_KEYGUARD_SECURE_STORAGE permission is sufficient to set a new LSKF but isn't necessarily sufficient to get the minimum password metrics. This is preventing 'KeyguardManager#setLock(int, byte[], int, byte[])' from being fixed to properly validate the new LSKF. To fix this, make DevicePolicyManagerService#getPasswordMinimumMetrics() accept these permissions. Bug: 219511761 Bug: 232900169 Bug: 243881358 Test: see I46d8bf920526a00d6e6d2145d06c8e39f8047ea8 Change-Id: Ic69fd01dadf95ab49b025295711fa020180690ff --- .../server/devicepolicy/DevicePolicyManagerService.java | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java b/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java index 6ea71e382a716..d8b30be03e601 100644 --- a/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java +++ b/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java @@ -5130,8 +5130,11 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub { boolean deviceWideOnly) { final CallerIdentity caller = getCallerIdentity(); Preconditions.checkCallAuthorization(hasFullCrossUsersPermission(caller, userHandle) - && (isSystemUid(caller) || hasCallingOrSelfPermission( - permission.SET_INITIAL_LOCK))); + && (isSystemUid(caller) + // Accept any permission that ILockSettings#setLockCredential() accepts. + || hasCallingOrSelfPermission(permission.SET_INITIAL_LOCK) + || hasCallingOrSelfPermission(permission.SET_AND_VERIFY_LOCKSCREEN_CREDENTIALS) + || hasCallingOrSelfPermission(permission.ACCESS_KEYGUARD_SECURE_STORAGE))); return getPasswordMinimumMetricsUnchecked(userHandle, deviceWideOnly); }