Merge changes from topic "testDelegatedCertInstallerDeviceIdAttestation" into sc-v2-dev-plus-aosp
* changes:
[automerge] Allows DPM.generateKeyPair() to be called from PO of affiliated user. 2p: e8caa07e9f
Allows DPM.generateKeyPair() to be called from PO of affiliated user.
This commit is contained in:
@@ -6388,10 +6388,10 @@ public class DevicePolicyManager {
|
|||||||
* management app can use {@link #ID_TYPE_BASE_INFO} to request inclusion of the general device
|
* management app can use {@link #ID_TYPE_BASE_INFO} to request inclusion of the general device
|
||||||
* information including manufacturer, model, brand, device and product in the attestation
|
* information including manufacturer, model, brand, device and product in the attestation
|
||||||
* record.
|
* record.
|
||||||
* Only device owner, profile owner on an organization-owned device and their delegated
|
* Only device owner, profile owner on an organization-owned device or affiliated user, and
|
||||||
* certificate installers can use {@link #ID_TYPE_SERIAL}, {@link #ID_TYPE_IMEI} and
|
* their delegated certificate installers can use {@link #ID_TYPE_SERIAL}, {@link #ID_TYPE_IMEI}
|
||||||
* {@link #ID_TYPE_MEID} to request unique device identifiers to be attested (the serial number,
|
* and {@link #ID_TYPE_MEID} to request unique device identifiers to be attested (the serial
|
||||||
* IMEI and MEID correspondingly), if supported by the device
|
* number, IMEI and MEID correspondingly), if supported by the device
|
||||||
* (see {@link #isDeviceIdAttestationSupported()}).
|
* (see {@link #isDeviceIdAttestationSupported()}).
|
||||||
* Additionally, device owner, profile owner on an organization-owned device and their delegated
|
* Additionally, device owner, profile owner on an organization-owned device and their delegated
|
||||||
* certificate installers can also request the attestation record to be signed using an
|
* certificate installers can also request the attestation record to be signed using an
|
||||||
|
|||||||
@@ -5898,6 +5898,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
|
|||||||
* (1.1) The caller is the Device Owner
|
* (1.1) The caller is the Device Owner
|
||||||
* (1.2) The caller is another app in the same user as the device owner, AND
|
* (1.2) The caller is another app in the same user as the device owner, AND
|
||||||
* The caller is the delegated certificate installer.
|
* The caller is the delegated certificate installer.
|
||||||
|
* (1.3) The caller is a Profile Owner and the calling user is affiliated.
|
||||||
* (2) The user has a profile owner, AND:
|
* (2) The user has a profile owner, AND:
|
||||||
* (2.1) The profile owner has been granted access to Device IDs and one of the following
|
* (2.1) The profile owner has been granted access to Device IDs and one of the following
|
||||||
* holds:
|
* holds:
|
||||||
@@ -5923,12 +5924,14 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
|
|||||||
* If the caller is from the work profile, then it must be the PO or the delegate, and
|
* If the caller is from the work profile, then it must be the PO or the delegate, and
|
||||||
* it must have the right permission to access device identifiers.
|
* it must have the right permission to access device identifiers.
|
||||||
*/
|
*/
|
||||||
if (hasProfileOwner(caller.getUserId())) {
|
int callerUserId = caller.getUserId();
|
||||||
|
if (hasProfileOwner(callerUserId)) {
|
||||||
// Make sure that the caller is the profile owner or delegate.
|
// Make sure that the caller is the profile owner or delegate.
|
||||||
Preconditions.checkCallAuthorization(canInstallCertificates(caller));
|
Preconditions.checkCallAuthorization(canInstallCertificates(caller));
|
||||||
// Verify that the managed profile is on an organization-owned device and as such
|
// Verify that the managed profile is on an organization-owned device (or is affiliated
|
||||||
// the profile owner can access Device IDs.
|
// with the device owner user) and as such the profile owner can access Device IDs.
|
||||||
if (isProfileOwnerOfOrganizationOwnedDevice(caller.getUserId())) {
|
if (isProfileOwnerOfOrganizationOwnedDevice(callerUserId)
|
||||||
|
|| isUserAffiliatedWithDevice(callerUserId)) {
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
throw new SecurityException(
|
throw new SecurityException(
|
||||||
@@ -9309,10 +9312,11 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
|
|||||||
return false;
|
return false;
|
||||||
}
|
}
|
||||||
|
|
||||||
// Allow access to the device owner or delegate cert installer.
|
// Allow access to the device owner or delegate cert installer or profile owner of an
|
||||||
|
// affiliated user
|
||||||
ComponentName deviceOwner = getDeviceOwnerComponent(true);
|
ComponentName deviceOwner = getDeviceOwnerComponent(true);
|
||||||
if (deviceOwner != null && (deviceOwner.getPackageName().equals(packageName)
|
if (deviceOwner != null && (deviceOwner.getPackageName().equals(packageName)
|
||||||
|| isCallerDelegate(packageName, uid, DELEGATION_CERT_INSTALL))) {
|
|| isCallerDelegate(packageName, uid, DELEGATION_CERT_INSTALL))) {
|
||||||
return true;
|
return true;
|
||||||
}
|
}
|
||||||
final int userId = UserHandle.getUserId(uid);
|
final int userId = UserHandle.getUserId(uid);
|
||||||
@@ -9322,7 +9326,8 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
|
|||||||
final boolean isCallerProfileOwnerOrDelegate = profileOwner != null
|
final boolean isCallerProfileOwnerOrDelegate = profileOwner != null
|
||||||
&& (profileOwner.getPackageName().equals(packageName)
|
&& (profileOwner.getPackageName().equals(packageName)
|
||||||
|| isCallerDelegate(packageName, uid, DELEGATION_CERT_INSTALL));
|
|| isCallerDelegate(packageName, uid, DELEGATION_CERT_INSTALL));
|
||||||
if (isCallerProfileOwnerOrDelegate && isProfileOwnerOfOrganizationOwnedDevice(userId)) {
|
if (isCallerProfileOwnerOrDelegate && (isProfileOwnerOfOrganizationOwnedDevice(userId)
|
||||||
|
|| isUserAffiliatedWithDevice(userId))) {
|
||||||
return true;
|
return true;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -14648,7 +14653,13 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
|
|||||||
final CallerIdentity caller = getCallerIdentity();
|
final CallerIdentity caller = getCallerIdentity();
|
||||||
Preconditions.checkCallAuthorization(hasCrossUsersPermission(caller, userId));
|
Preconditions.checkCallAuthorization(hasCrossUsersPermission(caller, userId));
|
||||||
|
|
||||||
return isUserAffiliatedWithDeviceLocked(userId);
|
return isUserAffiliatedWithDevice(userId);
|
||||||
|
}
|
||||||
|
|
||||||
|
private boolean isUserAffiliatedWithDevice(@UserIdInt int userId) {
|
||||||
|
synchronized (getLockObject()) {
|
||||||
|
return isUserAffiliatedWithDeviceLocked(userId);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
private boolean isUserAffiliatedWithDeviceLocked(@UserIdInt int userId) {
|
private boolean isUserAffiliatedWithDeviceLocked(@UserIdInt int userId) {
|
||||||
|
|||||||
Reference in New Issue
Block a user