From 3e1e24afdef4188c8362b03622a0f0f32e520a48 Mon Sep 17 00:00:00 2001 From: Michael Wachenschwanz Date: Thu, 25 Apr 2019 15:49:55 -0700 Subject: [PATCH] Add a resource config to define a default supervision component. Bug: 124066840 Test: manual (overlay resource with component name and confirm only that component can be set as profile owner after setup is complete) Change-Id: If67ca69f03fda35ee8a2d5a43e96a9f1e64d8886 --- core/res/res/values/config.xml | 4 +++ core/res/res/values/symbols.xml | 2 ++ .../DevicePolicyManagerService.java | 28 +++++++++++++++++-- 3 files changed, 31 insertions(+), 3 deletions(-) diff --git a/core/res/res/values/config.xml b/core/res/res/values/config.xml index ccf8509c2f8f3..bca0e937cb70d 100644 --- a/core/res/res/values/config.xml +++ b/core/res/res/values/config.xml @@ -4087,4 +4087,8 @@ + + diff --git a/core/res/res/values/symbols.xml b/core/res/res/values/symbols.xml index 35113edbfccef..32bd58e20efa7 100644 --- a/core/res/res/values/symbols.xml +++ b/core/res/res/values/symbols.xml @@ -3781,4 +3781,6 @@ + + diff --git a/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java b/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java index c5a2068826951..22231c0ab09be 100644 --- a/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java +++ b/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java @@ -8034,6 +8034,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager { throw new IllegalArgumentException("Component " + who + " not installed for userId:" + userHandle); } + final boolean hasIncompatibleAccountsOrNonAdb = hasIncompatibleAccountsOrNonAdbNoLock(userHandle, who); synchronized (getLockObject()) { @@ -8539,9 +8540,30 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager { return; } enforceCanManageProfileAndDeviceOwners(); - if ((mIsWatch || hasUserSetupCompleted(userHandle)) && !isCallerWithSystemUid()) { - throw new IllegalStateException("Cannot set the profile owner on a user which is " - + "already set-up"); + + if ((mIsWatch || hasUserSetupCompleted(userHandle))) { + if (!isCallerWithSystemUid()) { + throw new IllegalStateException("Cannot set the profile owner on a user which is " + + "already set-up"); + } + + if (!mIsWatch) { + // Only the default supervision profile owner can be set as profile owner after SUW + final String supervisor = mContext.getResources().getString( + com.android.internal.R.string + .config_defaultSupervisionProfileOwnerComponent); + if (supervisor == null) { + throw new IllegalStateException("Unable to set profile owner post-setup, no" + + "default supervisor profile owner defined"); + } + + final ComponentName supervisorComponent = ComponentName.unflattenFromString( + supervisor); + if (!owner.equals(supervisorComponent)) { + throw new IllegalStateException("Unable to set non-default profile owner" + + " post-setup " + owner); + } + } } }