Merge "Revert "Changes to support adding CTS Test TrustTestCases.""
This commit is contained in:
committed by
Android (Google) Code Review
commit
84e5767fdf
@@ -2,7 +2,6 @@
|
||||
package android {
|
||||
|
||||
public static final class Manifest.permission {
|
||||
field public static final String ACCESS_KEYGUARD_SECURE_STORAGE = "android.permission.ACCESS_KEYGUARD_SECURE_STORAGE";
|
||||
field public static final String ACCESS_NOTIFICATIONS = "android.permission.ACCESS_NOTIFICATIONS";
|
||||
field public static final String ACTIVITY_EMBEDDING = "android.permission.ACTIVITY_EMBEDDING";
|
||||
field public static final String APPROVE_INCIDENT_REPORTS = "android.permission.APPROVE_INCIDENT_REPORTS";
|
||||
@@ -288,8 +287,8 @@ package android.app {
|
||||
}
|
||||
|
||||
public class KeyguardManager {
|
||||
method @RequiresPermission(anyOf={android.Manifest.permission.SET_AND_VERIFY_LOCKSCREEN_CREDENTIALS, android.Manifest.permission.ACCESS_KEYGUARD_SECURE_STORAGE}) public boolean checkLock(int, @Nullable byte[]);
|
||||
method @RequiresPermission(anyOf={android.Manifest.permission.SET_AND_VERIFY_LOCKSCREEN_CREDENTIALS, android.Manifest.permission.ACCESS_KEYGUARD_SECURE_STORAGE}) public boolean setLock(int, @Nullable byte[], int, @Nullable byte[]);
|
||||
method @RequiresPermission(anyOf={android.Manifest.permission.SET_AND_VERIFY_LOCKSCREEN_CREDENTIALS, "android.permission.ACCESS_KEYGUARD_SECURE_STORAGE"}) public boolean checkLock(int, @Nullable byte[]);
|
||||
method @RequiresPermission(anyOf={android.Manifest.permission.SET_AND_VERIFY_LOCKSCREEN_CREDENTIALS, "android.permission.ACCESS_KEYGUARD_SECURE_STORAGE"}) public boolean setLock(int, @Nullable byte[], int, @Nullable byte[]);
|
||||
}
|
||||
|
||||
public class LocaleManager {
|
||||
@@ -585,15 +584,6 @@ package android.app.prediction {
|
||||
|
||||
}
|
||||
|
||||
package android.app.trust {
|
||||
|
||||
public class TrustManager {
|
||||
method @RequiresPermission(android.Manifest.permission.ACCESS_KEYGUARD_SECURE_STORAGE) public void enableTrustAgentForUserForTest(@NonNull android.content.ComponentName, int);
|
||||
method @RequiresPermission(android.Manifest.permission.ACCESS_KEYGUARD_SECURE_STORAGE) public void reportUserRequestedUnlock(int);
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
package android.app.usage {
|
||||
|
||||
public class NetworkStatsManager {
|
||||
@@ -2374,14 +2364,6 @@ package android.service.quicksettings {
|
||||
|
||||
}
|
||||
|
||||
package android.service.trust {
|
||||
|
||||
public class TrustAgentService extends android.app.Service {
|
||||
method public void onUserRequestedUnlock();
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
package android.service.voice {
|
||||
|
||||
public class AlwaysOnHotwordDetector implements android.service.voice.HotwordDetector {
|
||||
|
||||
@@ -17,7 +17,6 @@
|
||||
package android.app.trust;
|
||||
|
||||
import android.app.trust.ITrustListener;
|
||||
import android.content.ComponentName;
|
||||
import android.hardware.biometrics.BiometricSourceType;
|
||||
|
||||
/**
|
||||
@@ -30,7 +29,6 @@ interface ITrustManager {
|
||||
void reportUserRequestedUnlock(int userId);
|
||||
void reportUnlockLockout(int timeoutMs, int userId);
|
||||
void reportEnabledTrustAgentsChanged(int userId);
|
||||
void enableTrustAgentForUserForTest(in ComponentName componentName, int userId);
|
||||
void registerTrustListener(in ITrustListener trustListener);
|
||||
void unregisterTrustListener(in ITrustListener trustListener);
|
||||
void reportKeyguardShowingChanged();
|
||||
|
||||
@@ -16,14 +16,10 @@
|
||||
|
||||
package android.app.trust;
|
||||
|
||||
import static android.Manifest.permission.ACCESS_KEYGUARD_SECURE_STORAGE;
|
||||
|
||||
import android.annotation.NonNull;
|
||||
import android.Manifest;
|
||||
import android.annotation.RequiresPermission;
|
||||
import android.annotation.SystemService;
|
||||
import android.annotation.TestApi;
|
||||
import android.compat.annotation.UnsupportedAppUsage;
|
||||
import android.content.ComponentName;
|
||||
import android.content.Context;
|
||||
import android.hardware.biometrics.BiometricSourceType;
|
||||
import android.os.Handler;
|
||||
@@ -37,17 +33,9 @@ import java.util.ArrayList;
|
||||
import java.util.List;
|
||||
|
||||
/**
|
||||
* Interface to the system service managing trust.
|
||||
*
|
||||
* <p>This class is for internal use only. This class is marked {@code @TestApi} to
|
||||
* enable testing the trust system including {@link android.service.trust.TrustAgentService}.
|
||||
* Methods which are currently not used in tests are marked @hide.
|
||||
*
|
||||
* @see com.android.server.trust.TrustManagerService
|
||||
*
|
||||
* See {@link com.android.server.trust.TrustManagerService}
|
||||
* @hide
|
||||
*/
|
||||
@TestApi
|
||||
@SystemService(Context.TRUST_SERVICE)
|
||||
public class TrustManager {
|
||||
|
||||
@@ -63,8 +51,7 @@ public class TrustManager {
|
||||
private final ITrustManager mService;
|
||||
private final ArrayMap<TrustListener, ITrustListener> mTrustListeners;
|
||||
|
||||
/** @hide */
|
||||
public TrustManager(@NonNull IBinder b) {
|
||||
public TrustManager(IBinder b) {
|
||||
mService = ITrustManager.Stub.asInterface(b);
|
||||
mTrustListeners = new ArrayMap<TrustListener, ITrustListener>();
|
||||
}
|
||||
@@ -75,10 +62,8 @@ public class TrustManager {
|
||||
*
|
||||
* @param userId The id for the user to be locked/unlocked.
|
||||
* @param locked The value for that user's locked state.
|
||||
*
|
||||
* @hide
|
||||
*/
|
||||
@RequiresPermission(ACCESS_KEYGUARD_SECURE_STORAGE)
|
||||
@RequiresPermission(Manifest.permission.ACCESS_KEYGUARD_SECURE_STORAGE)
|
||||
public void setDeviceLockedForUser(int userId, boolean locked) {
|
||||
try {
|
||||
mService.setDeviceLockedForUser(userId, locked);
|
||||
@@ -93,11 +78,8 @@ public class TrustManager {
|
||||
* @param successful if true, the unlock attempt was successful.
|
||||
*
|
||||
* Requires the {@link android.Manifest.permission#ACCESS_KEYGUARD_SECURE_STORAGE} permission.
|
||||
*
|
||||
* @hide
|
||||
*/
|
||||
@UnsupportedAppUsage
|
||||
@RequiresPermission(ACCESS_KEYGUARD_SECURE_STORAGE)
|
||||
public void reportUnlockAttempt(boolean successful, int userId) {
|
||||
try {
|
||||
mService.reportUnlockAttempt(successful, userId);
|
||||
@@ -111,7 +93,6 @@ public class TrustManager {
|
||||
*
|
||||
* Requires the {@link android.Manifest.permission#ACCESS_KEYGUARD_SECURE_STORAGE} permission.
|
||||
*/
|
||||
@RequiresPermission(ACCESS_KEYGUARD_SECURE_STORAGE)
|
||||
public void reportUserRequestedUnlock(int userId) {
|
||||
try {
|
||||
mService.reportUserRequestedUnlock(userId);
|
||||
@@ -131,10 +112,7 @@ public class TrustManager {
|
||||
* attempt to unlock the device again.
|
||||
*
|
||||
* Requires the {@link android.Manifest.permission#ACCESS_KEYGUARD_SECURE_STORAGE} permission.
|
||||
*
|
||||
* @hide
|
||||
*/
|
||||
@RequiresPermission(ACCESS_KEYGUARD_SECURE_STORAGE)
|
||||
public void reportUnlockLockout(int timeoutMs, int userId) {
|
||||
try {
|
||||
mService.reportUnlockLockout(timeoutMs, userId);
|
||||
@@ -147,10 +125,7 @@ public class TrustManager {
|
||||
* Reports that the list of enabled trust agents changed for user {@param userId}.
|
||||
*
|
||||
* Requires the {@link android.Manifest.permission#ACCESS_KEYGUARD_SECURE_STORAGE} permission.
|
||||
*
|
||||
* @hide
|
||||
*/
|
||||
@RequiresPermission(ACCESS_KEYGUARD_SECURE_STORAGE)
|
||||
public void reportEnabledTrustAgentsChanged(int userId) {
|
||||
try {
|
||||
mService.reportEnabledTrustAgentsChanged(userId);
|
||||
@@ -159,34 +134,11 @@ public class TrustManager {
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Enables a trust agent.
|
||||
*
|
||||
* <p>The agent is specified by {@code componentName} and must be a subclass of
|
||||
* {@link android.service.trust.TrustAgentService} and otherwise meet the requirements
|
||||
* to be a trust agent.
|
||||
*
|
||||
* <p>This method can only be used in tests.
|
||||
*
|
||||
* @param componentName the trust agent to enable
|
||||
*/
|
||||
@RequiresPermission(ACCESS_KEYGUARD_SECURE_STORAGE)
|
||||
public void enableTrustAgentForUserForTest(@NonNull ComponentName componentName, int userId) {
|
||||
try {
|
||||
mService.enableTrustAgentForUserForTest(componentName, userId);
|
||||
} catch (RemoteException e) {
|
||||
throw e.rethrowFromSystemServer();
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Reports that the visibility of the keyguard has changed.
|
||||
*
|
||||
* Requires the {@link android.Manifest.permission#ACCESS_KEYGUARD_SECURE_STORAGE} permission.
|
||||
*
|
||||
* @hide
|
||||
*/
|
||||
@RequiresPermission(ACCESS_KEYGUARD_SECURE_STORAGE)
|
||||
public void reportKeyguardShowingChanged() {
|
||||
try {
|
||||
mService.reportKeyguardShowingChanged();
|
||||
@@ -199,10 +151,7 @@ public class TrustManager {
|
||||
* Registers a listener for trust events.
|
||||
*
|
||||
* Requires the {@link android.Manifest.permission#TRUST_LISTENER} permission.
|
||||
*
|
||||
* @hide
|
||||
*/
|
||||
@RequiresPermission(android.Manifest.permission.TRUST_LISTENER)
|
||||
public void registerTrustListener(final TrustListener trustListener) {
|
||||
try {
|
||||
ITrustListener.Stub iTrustListener = new ITrustListener.Stub() {
|
||||
@@ -243,10 +192,7 @@ public class TrustManager {
|
||||
* Unregisters a listener for trust events.
|
||||
*
|
||||
* Requires the {@link android.Manifest.permission#TRUST_LISTENER} permission.
|
||||
*
|
||||
* @hide
|
||||
*/
|
||||
@RequiresPermission(android.Manifest.permission.TRUST_LISTENER)
|
||||
public void unregisterTrustListener(final TrustListener trustListener) {
|
||||
ITrustListener iTrustListener = mTrustListeners.remove(trustListener);
|
||||
if (iTrustListener != null) {
|
||||
@@ -261,8 +207,6 @@ public class TrustManager {
|
||||
/**
|
||||
* @return whether {@param userId} has enabled and configured trust agents. Ignores short-term
|
||||
* unavailability of trust due to {@link LockPatternUtils.StrongAuthTracker}.
|
||||
*
|
||||
* @hide
|
||||
*/
|
||||
@RequiresPermission(android.Manifest.permission.TRUST_LISTENER)
|
||||
public boolean isTrustUsuallyManaged(int userId) {
|
||||
@@ -279,10 +223,8 @@ public class TrustManager {
|
||||
* can be skipped.
|
||||
*
|
||||
* @param userId
|
||||
*
|
||||
* @hide
|
||||
*/
|
||||
@RequiresPermission(ACCESS_KEYGUARD_SECURE_STORAGE)
|
||||
@RequiresPermission(Manifest.permission.ACCESS_KEYGUARD_SECURE_STORAGE)
|
||||
public void unlockedByBiometricForUser(int userId, BiometricSourceType source) {
|
||||
try {
|
||||
mService.unlockedByBiometricForUser(userId, source);
|
||||
@@ -293,10 +235,8 @@ public class TrustManager {
|
||||
|
||||
/**
|
||||
* Clears authentication by the specified biometric type for all users.
|
||||
*
|
||||
* @hide
|
||||
*/
|
||||
@RequiresPermission(ACCESS_KEYGUARD_SECURE_STORAGE)
|
||||
@RequiresPermission(Manifest.permission.ACCESS_KEYGUARD_SECURE_STORAGE)
|
||||
public void clearAllBiometricRecognized(BiometricSourceType source, int unlockedUser) {
|
||||
try {
|
||||
mService.clearAllBiometricRecognized(source, unlockedUser);
|
||||
@@ -324,7 +264,6 @@ public class TrustManager {
|
||||
}
|
||||
};
|
||||
|
||||
/** @hide */
|
||||
public interface TrustListener {
|
||||
|
||||
/**
|
||||
|
||||
@@ -21,7 +21,6 @@ import android.annotation.IntDef;
|
||||
import android.annotation.NonNull;
|
||||
import android.annotation.SdkConstant;
|
||||
import android.annotation.SystemApi;
|
||||
import android.annotation.TestApi;
|
||||
import android.app.Service;
|
||||
import android.app.admin.DevicePolicyManager;
|
||||
import android.content.ComponentName;
|
||||
@@ -311,10 +310,9 @@ public class TrustAgentService extends Service {
|
||||
*
|
||||
* @see #FLAG_GRANT_TRUST_TEMPORARY_AND_RENEWABLE
|
||||
*
|
||||
* TODO(b/213631672): Remove @hide and @TestApi
|
||||
* TODO(b/213631672): Add CTS tests
|
||||
* @hide
|
||||
*/
|
||||
@TestApi
|
||||
public void onUserRequestedUnlock() {
|
||||
}
|
||||
|
||||
|
||||
@@ -5378,7 +5378,7 @@
|
||||
android:protectionLevel="signature|setup|role" />
|
||||
|
||||
<!-- Allows access to keyguard secure storage. Only allowed for system processes.
|
||||
@hide @TestApi -->
|
||||
@hide -->
|
||||
<permission android:name="android.permission.ACCESS_KEYGUARD_SECURE_STORAGE"
|
||||
android:protectionLevel="signature|setup" />
|
||||
|
||||
|
||||
@@ -122,8 +122,7 @@ public class TrustManagerService extends SystemService {
|
||||
private static final int MSG_DISPATCH_UNLOCK_LOCKOUT = 13;
|
||||
private static final int MSG_REFRESH_DEVICE_LOCKED_FOR_USER = 14;
|
||||
private static final int MSG_SCHEDULE_TRUST_TIMEOUT = 15;
|
||||
private static final int MSG_USER_REQUESTED_UNLOCK = 16;
|
||||
private static final int MSG_ENABLE_TRUST_AGENT = 17;
|
||||
public static final int MSG_USER_REQUESTED_UNLOCK = 16;
|
||||
|
||||
private static final String REFRESH_DEVICE_LOCKED_EXCEPT_USER = "except";
|
||||
|
||||
@@ -632,24 +631,6 @@ public class TrustManagerService extends SystemService {
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
/**
|
||||
* Uses {@link LockPatternUtils} to enable the setting for trust agent in the specified
|
||||
* component name. This should only be used for testing.
|
||||
*/
|
||||
private void enableTrustAgentForUserForTest(@NonNull ComponentName componentName, int userId) {
|
||||
Log.i(TAG,
|
||||
"Enabling trust agent " + componentName.flattenToString() + " for user " + userId);
|
||||
List<ComponentName> agents =
|
||||
new ArrayList<>(mLockPatternUtils.getEnabledTrustAgents(userId));
|
||||
if (!agents.contains(componentName)) {
|
||||
agents.add(componentName);
|
||||
}
|
||||
// Even if the agent was already there, we still call setEnabledTrustAgents to trigger a
|
||||
// refresh of installed agents.
|
||||
mLockPatternUtils.setEnabledTrustAgents(agents, userId);
|
||||
}
|
||||
|
||||
boolean isDeviceLockedInner(int userId) {
|
||||
synchronized (mDeviceLockedForUser) {
|
||||
return mDeviceLockedForUser.get(userId, true);
|
||||
@@ -948,7 +929,6 @@ public class TrustManagerService extends SystemService {
|
||||
continue;
|
||||
}
|
||||
allowedAgents.add(resolveInfo);
|
||||
if (DEBUG) Slog.d(TAG, "Adding agent " + getComponentName(resolveInfo));
|
||||
}
|
||||
return allowedAgents;
|
||||
}
|
||||
@@ -1177,13 +1157,6 @@ public class TrustManagerService extends SystemService {
|
||||
mHandler.sendEmptyMessage(MSG_ENABLED_AGENTS_CHANGED);
|
||||
}
|
||||
|
||||
@Override
|
||||
public void enableTrustAgentForUserForTest(ComponentName componentName, int userId)
|
||||
throws RemoteException {
|
||||
enforceReportPermission();
|
||||
mHandler.obtainMessage(MSG_ENABLE_TRUST_AGENT, userId, 0, componentName).sendToTarget();
|
||||
}
|
||||
|
||||
@Override
|
||||
public void reportKeyguardShowingChanged() throws RemoteException {
|
||||
enforceReportPermission();
|
||||
@@ -1460,9 +1433,6 @@ public class TrustManagerService extends SystemService {
|
||||
// This is also called when the security mode of a user changes.
|
||||
refreshDeviceLockedForUser(UserHandle.USER_ALL);
|
||||
break;
|
||||
case MSG_ENABLE_TRUST_AGENT:
|
||||
enableTrustAgentForUserForTest((ComponentName) msg.obj, msg.arg1);
|
||||
break;
|
||||
case MSG_KEYGUARD_SHOWING_CHANGED:
|
||||
refreshDeviceLockedForUser(mCurrentUser);
|
||||
break;
|
||||
|
||||
Reference in New Issue
Block a user