From f10dcdbb3b56390daa08a80c37b3dbaa7f732787 Mon Sep 17 00:00:00 2001 From: Dave McCloskey Date: Tue, 1 Feb 2022 00:33:39 +0000 Subject: [PATCH] Revert "Changes to support adding CTS Test TrustTestCases." Revert "Add TrustTestCases CTS test with first test for onUserRe..." Revert submission 16640606-au-cts1 Reason for revert: Test case does not work on CTS. b/217203979 Reverted Changes: I43bffe76c:Changes to support adding CTS Test TrustTestCases.... Ia0008dd81:Add TrustTestCases CTS test with first test for on... Change-Id: I9161003d217e624f22d2d212197a365d92aba3c3 --- core/api/test-current.txt | 22 +----- .../java/android/app/trust/ITrustManager.aidl | 2 - core/java/android/app/trust/TrustManager.java | 73 ++----------------- .../service/trust/TrustAgentService.java | 4 +- core/res/AndroidManifest.xml | 2 +- .../server/trust/TrustManagerService.java | 32 +------- 6 files changed, 11 insertions(+), 124 deletions(-) diff --git a/core/api/test-current.txt b/core/api/test-current.txt index 1ebf9192bc99e..ff26ae8d09fcc 100644 --- a/core/api/test-current.txt +++ b/core/api/test-current.txt @@ -2,7 +2,6 @@ package android { public static final class Manifest.permission { - field public static final String ACCESS_KEYGUARD_SECURE_STORAGE = "android.permission.ACCESS_KEYGUARD_SECURE_STORAGE"; field public static final String ACCESS_NOTIFICATIONS = "android.permission.ACCESS_NOTIFICATIONS"; field public static final String ACTIVITY_EMBEDDING = "android.permission.ACTIVITY_EMBEDDING"; field public static final String APPROVE_INCIDENT_REPORTS = "android.permission.APPROVE_INCIDENT_REPORTS"; @@ -281,8 +280,8 @@ package android.app { } public class KeyguardManager { - method @RequiresPermission(anyOf={android.Manifest.permission.SET_AND_VERIFY_LOCKSCREEN_CREDENTIALS, android.Manifest.permission.ACCESS_KEYGUARD_SECURE_STORAGE}) public boolean checkLock(int, @Nullable byte[]); - method @RequiresPermission(anyOf={android.Manifest.permission.SET_AND_VERIFY_LOCKSCREEN_CREDENTIALS, android.Manifest.permission.ACCESS_KEYGUARD_SECURE_STORAGE}) public boolean setLock(int, @Nullable byte[], int, @Nullable byte[]); + method @RequiresPermission(anyOf={android.Manifest.permission.SET_AND_VERIFY_LOCKSCREEN_CREDENTIALS, "android.permission.ACCESS_KEYGUARD_SECURE_STORAGE"}) public boolean checkLock(int, @Nullable byte[]); + method @RequiresPermission(anyOf={android.Manifest.permission.SET_AND_VERIFY_LOCKSCREEN_CREDENTIALS, "android.permission.ACCESS_KEYGUARD_SECURE_STORAGE"}) public boolean setLock(int, @Nullable byte[], int, @Nullable byte[]); } public class LocaleManager { @@ -576,15 +575,6 @@ package android.app.prediction { } -package android.app.trust { - - public class TrustManager { - method @RequiresPermission(android.Manifest.permission.ACCESS_KEYGUARD_SECURE_STORAGE) public void enableTrustAgentForUserForTest(@NonNull android.content.ComponentName, int); - method @RequiresPermission(android.Manifest.permission.ACCESS_KEYGUARD_SECURE_STORAGE) public void reportUserRequestedUnlock(int); - } - -} - package android.app.usage { public class NetworkStatsManager { @@ -2386,14 +2376,6 @@ package android.service.quicksettings { } -package android.service.trust { - - public class TrustAgentService extends android.app.Service { - method public void onUserRequestedUnlock(); - } - -} - package android.service.voice { public class AlwaysOnHotwordDetector implements android.service.voice.HotwordDetector { diff --git a/core/java/android/app/trust/ITrustManager.aidl b/core/java/android/app/trust/ITrustManager.aidl index 7956a35c7b3d1..edabccf23c2cb 100644 --- a/core/java/android/app/trust/ITrustManager.aidl +++ b/core/java/android/app/trust/ITrustManager.aidl @@ -17,7 +17,6 @@ package android.app.trust; import android.app.trust.ITrustListener; -import android.content.ComponentName; import android.hardware.biometrics.BiometricSourceType; /** @@ -30,7 +29,6 @@ interface ITrustManager { void reportUserRequestedUnlock(int userId); void reportUnlockLockout(int timeoutMs, int userId); void reportEnabledTrustAgentsChanged(int userId); - void enableTrustAgentForUserForTest(in ComponentName componentName, int userId); void registerTrustListener(in ITrustListener trustListener); void unregisterTrustListener(in ITrustListener trustListener); void reportKeyguardShowingChanged(); diff --git a/core/java/android/app/trust/TrustManager.java b/core/java/android/app/trust/TrustManager.java index fba2d3e037692..70b7de0767e47 100644 --- a/core/java/android/app/trust/TrustManager.java +++ b/core/java/android/app/trust/TrustManager.java @@ -16,14 +16,10 @@ package android.app.trust; -import static android.Manifest.permission.ACCESS_KEYGUARD_SECURE_STORAGE; - -import android.annotation.NonNull; +import android.Manifest; import android.annotation.RequiresPermission; import android.annotation.SystemService; -import android.annotation.TestApi; import android.compat.annotation.UnsupportedAppUsage; -import android.content.ComponentName; import android.content.Context; import android.hardware.biometrics.BiometricSourceType; import android.os.Handler; @@ -37,17 +33,9 @@ import java.util.ArrayList; import java.util.List; /** - * Interface to the system service managing trust. - * - *

This class is for internal use only. This class is marked {@code @TestApi} to - * enable testing the trust system including {@link android.service.trust.TrustAgentService}. - * Methods which are currently not used in tests are marked @hide. - * - * @see com.android.server.trust.TrustManagerService - * + * See {@link com.android.server.trust.TrustManagerService} * @hide */ -@TestApi @SystemService(Context.TRUST_SERVICE) public class TrustManager { @@ -63,8 +51,7 @@ public class TrustManager { private final ITrustManager mService; private final ArrayMap mTrustListeners; - /** @hide */ - public TrustManager(@NonNull IBinder b) { + public TrustManager(IBinder b) { mService = ITrustManager.Stub.asInterface(b); mTrustListeners = new ArrayMap(); } @@ -75,10 +62,8 @@ public class TrustManager { * * @param userId The id for the user to be locked/unlocked. * @param locked The value for that user's locked state. - * - * @hide */ - @RequiresPermission(ACCESS_KEYGUARD_SECURE_STORAGE) + @RequiresPermission(Manifest.permission.ACCESS_KEYGUARD_SECURE_STORAGE) public void setDeviceLockedForUser(int userId, boolean locked) { try { mService.setDeviceLockedForUser(userId, locked); @@ -93,11 +78,8 @@ public class TrustManager { * @param successful if true, the unlock attempt was successful. * * Requires the {@link android.Manifest.permission#ACCESS_KEYGUARD_SECURE_STORAGE} permission. - * - * @hide */ @UnsupportedAppUsage - @RequiresPermission(ACCESS_KEYGUARD_SECURE_STORAGE) public void reportUnlockAttempt(boolean successful, int userId) { try { mService.reportUnlockAttempt(successful, userId); @@ -111,7 +93,6 @@ public class TrustManager { * * Requires the {@link android.Manifest.permission#ACCESS_KEYGUARD_SECURE_STORAGE} permission. */ - @RequiresPermission(ACCESS_KEYGUARD_SECURE_STORAGE) public void reportUserRequestedUnlock(int userId) { try { mService.reportUserRequestedUnlock(userId); @@ -131,10 +112,7 @@ public class TrustManager { * attempt to unlock the device again. * * Requires the {@link android.Manifest.permission#ACCESS_KEYGUARD_SECURE_STORAGE} permission. - * - * @hide */ - @RequiresPermission(ACCESS_KEYGUARD_SECURE_STORAGE) public void reportUnlockLockout(int timeoutMs, int userId) { try { mService.reportUnlockLockout(timeoutMs, userId); @@ -147,10 +125,7 @@ public class TrustManager { * Reports that the list of enabled trust agents changed for user {@param userId}. * * Requires the {@link android.Manifest.permission#ACCESS_KEYGUARD_SECURE_STORAGE} permission. - * - * @hide */ - @RequiresPermission(ACCESS_KEYGUARD_SECURE_STORAGE) public void reportEnabledTrustAgentsChanged(int userId) { try { mService.reportEnabledTrustAgentsChanged(userId); @@ -159,34 +134,11 @@ public class TrustManager { } } - /** - * Enables a trust agent. - * - *

The agent is specified by {@code componentName} and must be a subclass of - * {@link android.service.trust.TrustAgentService} and otherwise meet the requirements - * to be a trust agent. - * - *

This method can only be used in tests. - * - * @param componentName the trust agent to enable - */ - @RequiresPermission(ACCESS_KEYGUARD_SECURE_STORAGE) - public void enableTrustAgentForUserForTest(@NonNull ComponentName componentName, int userId) { - try { - mService.enableTrustAgentForUserForTest(componentName, userId); - } catch (RemoteException e) { - throw e.rethrowFromSystemServer(); - } - } - /** * Reports that the visibility of the keyguard has changed. * * Requires the {@link android.Manifest.permission#ACCESS_KEYGUARD_SECURE_STORAGE} permission. - * - * @hide */ - @RequiresPermission(ACCESS_KEYGUARD_SECURE_STORAGE) public void reportKeyguardShowingChanged() { try { mService.reportKeyguardShowingChanged(); @@ -199,10 +151,7 @@ public class TrustManager { * Registers a listener for trust events. * * Requires the {@link android.Manifest.permission#TRUST_LISTENER} permission. - * - * @hide */ - @RequiresPermission(android.Manifest.permission.TRUST_LISTENER) public void registerTrustListener(final TrustListener trustListener) { try { ITrustListener.Stub iTrustListener = new ITrustListener.Stub() { @@ -243,10 +192,7 @@ public class TrustManager { * Unregisters a listener for trust events. * * Requires the {@link android.Manifest.permission#TRUST_LISTENER} permission. - * - * @hide */ - @RequiresPermission(android.Manifest.permission.TRUST_LISTENER) public void unregisterTrustListener(final TrustListener trustListener) { ITrustListener iTrustListener = mTrustListeners.remove(trustListener); if (iTrustListener != null) { @@ -261,8 +207,6 @@ public class TrustManager { /** * @return whether {@param userId} has enabled and configured trust agents. Ignores short-term * unavailability of trust due to {@link LockPatternUtils.StrongAuthTracker}. - * - * @hide */ @RequiresPermission(android.Manifest.permission.TRUST_LISTENER) public boolean isTrustUsuallyManaged(int userId) { @@ -279,10 +223,8 @@ public class TrustManager { * can be skipped. * * @param userId - * - * @hide */ - @RequiresPermission(ACCESS_KEYGUARD_SECURE_STORAGE) + @RequiresPermission(Manifest.permission.ACCESS_KEYGUARD_SECURE_STORAGE) public void unlockedByBiometricForUser(int userId, BiometricSourceType source) { try { mService.unlockedByBiometricForUser(userId, source); @@ -293,10 +235,8 @@ public class TrustManager { /** * Clears authentication by the specified biometric type for all users. - * - * @hide */ - @RequiresPermission(ACCESS_KEYGUARD_SECURE_STORAGE) + @RequiresPermission(Manifest.permission.ACCESS_KEYGUARD_SECURE_STORAGE) public void clearAllBiometricRecognized(BiometricSourceType source, int unlockedUser) { try { mService.clearAllBiometricRecognized(source, unlockedUser); @@ -324,7 +264,6 @@ public class TrustManager { } }; - /** @hide */ public interface TrustListener { /** diff --git a/core/java/android/service/trust/TrustAgentService.java b/core/java/android/service/trust/TrustAgentService.java index 5bd423599f5d1..fba61cfd801ec 100644 --- a/core/java/android/service/trust/TrustAgentService.java +++ b/core/java/android/service/trust/TrustAgentService.java @@ -21,7 +21,6 @@ import android.annotation.IntDef; import android.annotation.NonNull; import android.annotation.SdkConstant; import android.annotation.SystemApi; -import android.annotation.TestApi; import android.app.Service; import android.app.admin.DevicePolicyManager; import android.content.ComponentName; @@ -311,10 +310,9 @@ public class TrustAgentService extends Service { * * @see #FLAG_GRANT_TRUST_TEMPORARY_AND_RENEWABLE * - * TODO(b/213631672): Remove @hide and @TestApi + * TODO(b/213631672): Add CTS tests * @hide */ - @TestApi public void onUserRequestedUnlock() { } diff --git a/core/res/AndroidManifest.xml b/core/res/AndroidManifest.xml index 33bc90e078b81..3a842ee6e7f3f 100644 --- a/core/res/AndroidManifest.xml +++ b/core/res/AndroidManifest.xml @@ -5316,7 +5316,7 @@ android:protectionLevel="signature|setup|role" /> + @hide --> diff --git a/services/core/java/com/android/server/trust/TrustManagerService.java b/services/core/java/com/android/server/trust/TrustManagerService.java index 52f7d101ce993..9bed24d05f3d8 100644 --- a/services/core/java/com/android/server/trust/TrustManagerService.java +++ b/services/core/java/com/android/server/trust/TrustManagerService.java @@ -122,8 +122,7 @@ public class TrustManagerService extends SystemService { private static final int MSG_DISPATCH_UNLOCK_LOCKOUT = 13; private static final int MSG_REFRESH_DEVICE_LOCKED_FOR_USER = 14; private static final int MSG_SCHEDULE_TRUST_TIMEOUT = 15; - private static final int MSG_USER_REQUESTED_UNLOCK = 16; - private static final int MSG_ENABLE_TRUST_AGENT = 17; + public static final int MSG_USER_REQUESTED_UNLOCK = 16; private static final String REFRESH_DEVICE_LOCKED_EXCEPT_USER = "except"; @@ -632,24 +631,6 @@ public class TrustManagerService extends SystemService { } } - - /** - * Uses {@link LockPatternUtils} to enable the setting for trust agent in the specified - * component name. This should only be used for testing. - */ - private void enableTrustAgentForUserForTest(@NonNull ComponentName componentName, int userId) { - Log.i(TAG, - "Enabling trust agent " + componentName.flattenToString() + " for user " + userId); - List agents = - new ArrayList<>(mLockPatternUtils.getEnabledTrustAgents(userId)); - if (!agents.contains(componentName)) { - agents.add(componentName); - } - // Even if the agent was already there, we still call setEnabledTrustAgents to trigger a - // refresh of installed agents. - mLockPatternUtils.setEnabledTrustAgents(agents, userId); - } - boolean isDeviceLockedInner(int userId) { synchronized (mDeviceLockedForUser) { return mDeviceLockedForUser.get(userId, true); @@ -948,7 +929,6 @@ public class TrustManagerService extends SystemService { continue; } allowedAgents.add(resolveInfo); - if (DEBUG) Slog.d(TAG, "Adding agent " + getComponentName(resolveInfo)); } return allowedAgents; } @@ -1177,13 +1157,6 @@ public class TrustManagerService extends SystemService { mHandler.sendEmptyMessage(MSG_ENABLED_AGENTS_CHANGED); } - @Override - public void enableTrustAgentForUserForTest(ComponentName componentName, int userId) - throws RemoteException { - enforceReportPermission(); - mHandler.obtainMessage(MSG_ENABLE_TRUST_AGENT, userId, 0, componentName).sendToTarget(); - } - @Override public void reportKeyguardShowingChanged() throws RemoteException { enforceReportPermission(); @@ -1460,9 +1433,6 @@ public class TrustManagerService extends SystemService { // This is also called when the security mode of a user changes. refreshDeviceLockedForUser(UserHandle.USER_ALL); break; - case MSG_ENABLE_TRUST_AGENT: - enableTrustAgentForUserForTest((ComponentName) msg.obj, msg.arg1); - break; case MSG_KEYGUARD_SHOWING_CHANGED: refreshDeviceLockedForUser(mCurrentUser); break;