Merge changes Idc218e5f,I26c3fafc am: 7e3c5382cc am: fb4c1822a8 am: 4d4ababae0 am: 256a0b563f

Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/2052056

Change-Id: Iea3e69f060b492b0973f9726951527709d840193
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
This commit is contained in:
Eric Biggers
2022-04-08 02:20:14 +00:00
committed by Automerger Merge Worker
5 changed files with 10 additions and 120 deletions

View File

@@ -1681,18 +1681,13 @@ public class StorageManager {
} }
/** {@hide} /** {@hide}
* Is this device encryptable or already encrypted? * Is this device encrypted?
* @return true for encryptable or encrypted * <p>
* false not encrypted and not encryptable * Note: all devices launching with Android 10 (API level 29) or later are
*/ * required to be encrypted. This should only ever return false for
public static boolean isEncryptable() { * in-development devices on which encryption has not yet been configured.
return RoSystemProperties.CRYPTO_ENCRYPTABLE; *
} * @return true if encrypted, false if not encrypted
/** {@hide}
* Is this device already encrypted?
* @return true for encrypted. (Implies isEncryptable() == true)
* false not encrypted
*/ */
public static boolean isEncrypted() { public static boolean isEncrypted() {
return RoSystemProperties.CRYPTO_ENCRYPTED; return RoSystemProperties.CRYPTO_ENCRYPTED;
@@ -1701,7 +1696,7 @@ public class StorageManager {
/** {@hide} /** {@hide}
* Is this device file encrypted? * Is this device file encrypted?
* @return true for file encrypted. (Implies isEncrypted() == true) * @return true for file encrypted. (Implies isEncrypted() == true)
* false not encrypted or block encrypted * false not encrypted or using "managed" encryption
*/ */
@UnsupportedAppUsage(maxTargetSdk = Build.VERSION_CODES.R, trackingBug = 170729553) @UnsupportedAppUsage(maxTargetSdk = Build.VERSION_CODES.R, trackingBug = 170729553)
public static boolean isFileEncryptedNativeOnly() { public static boolean isFileEncryptedNativeOnly() {
@@ -1711,54 +1706,6 @@ public class StorageManager {
return RoSystemProperties.CRYPTO_FILE_ENCRYPTED; return RoSystemProperties.CRYPTO_FILE_ENCRYPTED;
} }
/** {@hide}
* Is this device block encrypted?
* @return true for block encrypted. (Implies isEncrypted() == true)
* false not encrypted or file encrypted
*/
public static boolean isBlockEncrypted() {
return false;
}
/** {@hide}
* Is this device block encrypted with credentials?
* @return true for crediential block encrypted.
* (Implies isBlockEncrypted() == true)
* false not encrypted, file encrypted or default block encrypted
*/
public static boolean isNonDefaultBlockEncrypted() {
return false;
}
/** {@hide}
* Is this device in the process of being block encrypted?
* @return true for encrypting.
* false otherwise
* Whether device isEncrypted at this point is undefined
* Note that only system services and CryptKeeper will ever see this return
* true - no app will ever be launched in this state.
* Also note that this state will not change without a teardown of the
* framework, so no service needs to check for changes during their lifespan
*/
public static boolean isBlockEncrypting() {
return false;
}
/** {@hide}
* Is this device non default block encrypted and in the process of
* prompting for credentials?
* @return true for prompting for credentials.
* (Implies isNonDefaultBlockEncrypted() == true)
* false otherwise
* Note that only system services and CryptKeeper will ever see this return
* true - no app will ever be launched in this state.
* Also note that this state will not change without a teardown of the
* framework, so no service needs to check for changes during their lifespan
*/
public static boolean inCryptKeeperBounce() {
return false;
}
/** {@hide} */ /** {@hide} */
public static boolean isFileEncryptedEmulatedOnly() { public static boolean isFileEncryptedEmulatedOnly() {
return SystemProperties.getBoolean(StorageManager.PROP_EMULATE_FBE, false); return SystemProperties.getBoolean(StorageManager.PROP_EMULATE_FBE, false);

View File

@@ -60,14 +60,10 @@ public class RoSystemProperties {
public static final CryptoProperties.type_values CRYPTO_TYPE = public static final CryptoProperties.type_values CRYPTO_TYPE =
CryptoProperties.type().orElse(CryptoProperties.type_values.NONE); CryptoProperties.type().orElse(CryptoProperties.type_values.NONE);
// These are pseudo-properties // These are pseudo-properties
public static final boolean CRYPTO_ENCRYPTABLE =
CRYPTO_STATE != CryptoProperties.state_values.UNSUPPORTED;
public static final boolean CRYPTO_ENCRYPTED = public static final boolean CRYPTO_ENCRYPTED =
CRYPTO_STATE == CryptoProperties.state_values.ENCRYPTED; CRYPTO_STATE == CryptoProperties.state_values.ENCRYPTED;
public static final boolean CRYPTO_FILE_ENCRYPTED = public static final boolean CRYPTO_FILE_ENCRYPTED =
CRYPTO_TYPE == CryptoProperties.type_values.FILE; CRYPTO_TYPE == CryptoProperties.type_values.FILE;
public static final boolean CRYPTO_BLOCK_ENCRYPTED =
CRYPTO_TYPE == CryptoProperties.type_values.BLOCK;
public static final boolean CONTROL_PRIVAPP_PERMISSIONS_LOG = public static final boolean CONTROL_PRIVAPP_PERMISSIONS_LOG =
"log".equalsIgnoreCase(CONTROL_PRIVAPP_PERMISSIONS); "log".equalsIgnoreCase(CONTROL_PRIVAPP_PERMISSIONS);

View File

@@ -1544,23 +1544,6 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
return StorageManager.isFileEncryptedNativeOnly(); return StorageManager.isFileEncryptedNativeOnly();
} }
boolean storageManagerIsNonDefaultBlockEncrypted() {
final long identity = Binder.clearCallingIdentity();
try {
return StorageManager.isNonDefaultBlockEncrypted();
} finally {
Binder.restoreCallingIdentity(identity);
}
}
boolean storageManagerIsEncrypted() {
return StorageManager.isEncrypted();
}
boolean storageManagerIsEncryptable() {
return StorageManager.isEncryptable();
}
Looper getMyLooper() { Looper getMyLooper() {
return Looper.myLooper(); return Looper.myLooper();
} }
@@ -7823,21 +7806,12 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
/** /**
* Hook to low-levels: Reporting the current status of encryption. * Hook to low-levels: Reporting the current status of encryption.
* @return A value such as {@link DevicePolicyManager#ENCRYPTION_STATUS_UNSUPPORTED}, * @return Either {@link DevicePolicyManager#ENCRYPTION_STATUS_UNSUPPORTED}
* {@link DevicePolicyManager#ENCRYPTION_STATUS_INACTIVE}, * or {@link DevicePolicyManager#ENCRYPTION_STATUS_ACTIVE_PER_USER}.
* {@link DevicePolicyManager#ENCRYPTION_STATUS_ACTIVE_DEFAULT_KEY},
* {@link DevicePolicyManager#ENCRYPTION_STATUS_ACTIVE_PER_USER}, or
* {@link DevicePolicyManager#ENCRYPTION_STATUS_ACTIVE}.
*/ */
private int getEncryptionStatus() { private int getEncryptionStatus() {
if (mInjector.storageManagerIsFileBasedEncryptionEnabled()) { if (mInjector.storageManagerIsFileBasedEncryptionEnabled()) {
return DevicePolicyManager.ENCRYPTION_STATUS_ACTIVE_PER_USER; return DevicePolicyManager.ENCRYPTION_STATUS_ACTIVE_PER_USER;
} else if (mInjector.storageManagerIsNonDefaultBlockEncrypted()) {
return DevicePolicyManager.ENCRYPTION_STATUS_ACTIVE;
} else if (mInjector.storageManagerIsEncrypted()) {
return DevicePolicyManager.ENCRYPTION_STATUS_ACTIVE_DEFAULT_KEY;
} else if (mInjector.storageManagerIsEncryptable()) {
return DevicePolicyManager.ENCRYPTION_STATUS_INACTIVE;
} else { } else {
return DevicePolicyManager.ENCRYPTION_STATUS_UNSUPPORTED; return DevicePolicyManager.ENCRYPTION_STATUS_UNSUPPORTED;
} }

View File

@@ -254,21 +254,6 @@ public class DevicePolicyManagerServiceTestable extends DevicePolicyManagerServi
return services.storageManager.isFileBasedEncryptionEnabled(); return services.storageManager.isFileBasedEncryptionEnabled();
} }
@Override
boolean storageManagerIsNonDefaultBlockEncrypted() {
return services.storageManager.isNonDefaultBlockEncrypted();
}
@Override
boolean storageManagerIsEncrypted() {
return services.storageManager.isEncrypted();
}
@Override
boolean storageManagerIsEncryptable() {
return services.storageManager.isEncryptable();
}
@Override @Override
String getDevicePolicyFilePathForSystemUser() { String getDevicePolicyFilePathForSystemUser() {
return services.systemUserDataDir.getAbsolutePath() + "/"; return services.systemUserDataDir.getAbsolutePath() + "/";

View File

@@ -501,18 +501,6 @@ public class MockSystemServices {
public boolean isFileBasedEncryptionEnabled() { public boolean isFileBasedEncryptionEnabled() {
return false; return false;
} }
public boolean isNonDefaultBlockEncrypted() {
return false;
}
public boolean isEncrypted() {
return false;
}
public boolean isEncryptable() {
return false;
}
} }
// We have to keep track of broadcast receivers registered for a given intent ourselves as the // We have to keep track of broadcast receivers registered for a given intent ourselves as the