Merge "Migrate the setUsbDataSignalingEnabled api to the device policy engine"

This commit is contained in:
Kholoud Mohamed
2023-06-27 15:57:11 +00:00
committed by Android (Google) Code Review
11 changed files with 104 additions and 72 deletions

View File

@@ -540,6 +540,7 @@ package android.app.admin {
field public static final String PERMITTED_INPUT_METHODS_POLICY = "permittedInputMethods";
field public static final String PERSONAL_APPS_SUSPENDED_POLICY = "personalAppsSuspended";
field public static final String SCREEN_CAPTURE_DISABLED_POLICY = "screenCaptureDisabled";
field public static final String USB_DATA_SIGNALING_POLICY = "usbDataSignaling";
}
public class DevicePolicyManager {

View File

@@ -159,6 +159,14 @@ public final class DevicePolicyIdentifiers {
*/
public static final String CROSS_PROFILE_WIDGET_PROVIDER_POLICY = "crossProfileWidgetProvider";
/**
* String identifier for {@link DevicePolicyManager#setUsbDataSignalingEnabled}.
*
* @hide
*/
@TestApi
public static final String USB_DATA_SIGNALING_POLICY = "usbDataSignaling";
/**
* @hide
*/

View File

@@ -16585,10 +16585,28 @@ public class DevicePolicyManager {
* {@link #canUsbDataSignalingBeDisabled()} to check whether enabling or disabling USB data
* signaling is supported on the device.
*
* Starting from {@link Build.VERSION_CODES#VANILLA_ICE_CREAM}, after the USB data signaling
* policy has been set, {@link PolicyUpdateReceiver#onPolicySetResult(Context, String,
* Bundle, TargetUser, PolicyUpdateResult)} will notify the admin on whether the policy was
* successfully set or not. This callback will contain:
* <ul>
* li> The policy identifier {@link DevicePolicyIdentifiers#USB_DATA_SIGNALING_POLICY}
* <li> The {@link TargetUser} that this policy relates to
* <li> The {@link PolicyUpdateResult}, which will be
* {@link PolicyUpdateResult#RESULT_POLICY_SET} if the policy was successfully set or the
* reason the policy failed to be set
* e.g. {@link PolicyUpdateResult#RESULT_FAILURE_CONFLICTING_ADMIN_POLICY})
* </ul>
* If there has been a change to the policy,
* {@link PolicyUpdateReceiver#onPolicyChanged(Context, String, Bundle, TargetUser,
* PolicyUpdateResult)} will notify the admin of this change. This callback will contain the
* same parameters as PolicyUpdateReceiver#onPolicySetResult and the {@link PolicyUpdateResult}
* will contain the reason why the policy changed.
*
* @param enabled whether USB data signaling should be enabled or not.
* @throws SecurityException if the caller is not permitted to set this policy
* @throws IllegalStateException if disabling USB data signaling is not supported or
* if USB data signaling fails to be enabled/disabled.
* if USB data signaling fails to be enabled/disabled.
*/
@RequiresPermission(value = MANAGE_DEVICE_POLICY_USB_DATA_SIGNALLING, conditional = true)
public void setUsbDataSignalingEnabled(boolean enabled) {
@@ -16623,25 +16641,6 @@ public class DevicePolicyManager {
return true;
}
/**
* Called by the system to check whether USB data signaling is currently enabled for this user.
*
* @param userId which user to check for.
* @return {@code true} if USB data signaling is enabled, {@code false} otherwise.
* @hide
*/
public boolean isUsbDataSignalingEnabledForUser(@UserIdInt int userId) {
throwIfParentInstance("isUsbDataSignalingEnabledForUser");
if (mService != null) {
try {
return mService.isUsbDataSignalingEnabledForUser(userId);
} catch (RemoteException e) {
throw e.rethrowFromSystemServer();
}
}
return true;
}
/**
* Returns whether enabling or disabling USB data signaling is supported on the device.
*

View File

@@ -565,7 +565,6 @@ interface IDevicePolicyManager {
void setUsbDataSignalingEnabled(String callerPackage, boolean enabled);
boolean isUsbDataSignalingEnabled(String callerPackage);
boolean isUsbDataSignalingEnabledForUser(int userId);
boolean canUsbDataSignalingBeDisabled();
void setMinimumRequiredWifiSecurityLevel(String callerPackageName, int level);

View File

@@ -409,7 +409,7 @@ public class RestrictedLockUtilsInternal extends RestrictedLockUtils {
*/
public static EnforcedAdmin checkIfUsbDataSignalingIsDisabled(Context context, int userId) {
DevicePolicyManager dpm = context.getSystemService(DevicePolicyManager.class);
if (dpm == null || dpm.isUsbDataSignalingEnabledForUser(userId)) {
if (dpm == null || dpm.isUsbDataSignalingEnabled()) {
return null;
} else {
EnforcedAdmin admin = getProfileOrDeviceOwner(context, getUserHandleOf(userId));

View File

@@ -140,8 +140,8 @@ public class EnableAdbPreferenceControllerTest {
public void updateState_settingsOn_shouldCheck() {
when(mUserManager.isAdminUser()).thenReturn(true);
when(mDevicePolicyManager.getProfileOwner()).thenReturn(TEST_COMPONENT_NAME);
when(mDevicePolicyManager.isUsbDataSignalingEnabledForUser(
UserHandle.myUserId())).thenReturn(true);
when(mDevicePolicyManager.isUsbDataSignalingEnabled(
)).thenReturn(true);
Settings.Global.putInt(mContext.getContentResolver(),
Settings.Global.ADB_ENABLED, 1);
mPreference.setChecked(false);
@@ -156,8 +156,8 @@ public class EnableAdbPreferenceControllerTest {
public void updateState_settingsOff_shouldUncheck() {
when(mUserManager.isAdminUser()).thenReturn(true);
when(mDevicePolicyManager.getProfileOwner()).thenReturn(TEST_COMPONENT_NAME);
when(mDevicePolicyManager.isUsbDataSignalingEnabledForUser(
UserHandle.myUserId())).thenReturn(true);
when(mDevicePolicyManager.isUsbDataSignalingEnabled(
)).thenReturn(true);
Settings.Global.putInt(mContext.getContentResolver(),
Settings.Global.ADB_ENABLED, 0);
mPreference.setChecked(true);

View File

@@ -3469,8 +3469,10 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
}
revertTransferOwnershipIfNecessaryLocked();
if (!isPolicyEngineForFinanceFlagEnabled()) {
updateUsbDataSignal(mContext, isUsbDataSignalingEnabledInternalLocked());
}
}
updateUsbDataSignal();
// In case flag value has changed, we apply it during boot to avoid doing it concurrently
// with user toggling quiet mode.
@@ -22355,7 +22357,7 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
public void setUsbDataSignalingEnabled(String packageName, boolean enabled) {
Objects.requireNonNull(packageName, "Admin package name must be provided");
final CallerIdentity caller = getCallerIdentity(packageName);
if (!isPermissionCheckFlagEnabled()) {
if (!isPolicyEngineForFinanceFlagEnabled()) {
Preconditions.checkCallAuthorization(
isDefaultDeviceOwner(caller) || isProfileOwnerOfOrganizationOwnedDevice(caller),
"USB data signaling can only be controlled by a device owner or "
@@ -22364,22 +22366,25 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
"USB data signaling cannot be disabled.");
}
synchronized (getLockObject()) {
ActiveAdmin admin;
if (isPermissionCheckFlagEnabled()) {
admin = enforcePermissionAndGetEnforcingAdmin(
if (isPolicyEngineForFinanceFlagEnabled()) {
EnforcingAdmin enforcingAdmin = enforcePermissionAndGetEnforcingAdmin(
/* admin= */ null, MANAGE_DEVICE_POLICY_USB_DATA_SIGNALLING,
caller.getPackageName(),
caller.getUserId()).getActiveAdmin();
caller.getUserId());
Preconditions.checkState(canUsbDataSignalingBeDisabled(),
"USB data signaling cannot be disabled.");
mDevicePolicyEngine.setGlobalPolicy(
PolicyDefinition.USB_DATA_SIGNALING,
enforcingAdmin,
new BooleanPolicyValue(enabled));
} else {
admin = getProfileOwnerOrDeviceOwnerLocked(caller.getUserId());
}
if (admin.mUsbDataSignalingEnabled != enabled) {
admin.mUsbDataSignalingEnabled = enabled;
saveSettingsLocked(caller.getUserId());
updateUsbDataSignal();
ActiveAdmin admin = getProfileOwnerOrDeviceOwnerLocked(caller.getUserId());
if (admin.mUsbDataSignalingEnabled != enabled) {
admin.mUsbDataSignalingEnabled = enabled;
saveSettingsLocked(caller.getUserId());
updateUsbDataSignal(mContext, isUsbDataSignalingEnabledInternalLocked());
}
}
}
DevicePolicyEventLogger
@@ -22389,16 +22394,12 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
.write();
}
private void updateUsbDataSignal() {
if (!canUsbDataSignalingBeDisabled()) {
static void updateUsbDataSignal(Context context, boolean value) {
if (!canUsbDataSignalingBeDisabledInternal(context)) {
return;
}
final boolean usbEnabled;
synchronized (getLockObject()) {
usbEnabled = isUsbDataSignalingEnabledInternalLocked();
}
if (!mInjector.binderWithCleanCallingIdentity(
() -> mInjector.getUsbManager().enableUsbDataSignal(usbEnabled))) {
if (!Binder.withCleanCallingIdentity(
() -> context.getSystemService(UsbManager.class).enableUsbDataSignal(value))) {
Slogf.w(LOG_TAG, "Failed to set usb data signaling state");
}
}
@@ -22406,28 +22407,26 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
@Override
public boolean isUsbDataSignalingEnabled(String packageName) {
final CallerIdentity caller = getCallerIdentity(packageName);
synchronized (getLockObject()) {
// If the caller is an admin, return the policy set by itself. Otherwise
// return the device-wide policy.
if (isDefaultDeviceOwner(caller) || isProfileOwnerOfOrganizationOwnedDevice(caller)) {
return getProfileOwnerOrDeviceOwnerLocked(
caller.getUserId()).mUsbDataSignalingEnabled;
} else {
return isUsbDataSignalingEnabledInternalLocked();
if (isPolicyEngineForFinanceFlagEnabled()) {
Boolean enabled = mDevicePolicyEngine.getResolvedPolicy(
PolicyDefinition.USB_DATA_SIGNALING,
caller.getUserId());
return enabled == null || enabled;
} else {
synchronized (getLockObject()) {
// If the caller is an admin, return the policy set by itself. Otherwise
// return the device-wide policy.
if (isDefaultDeviceOwner(caller) || isProfileOwnerOfOrganizationOwnedDevice(
caller)) {
return getProfileOwnerOrDeviceOwnerLocked(
caller.getUserId()).mUsbDataSignalingEnabled;
} else {
return isUsbDataSignalingEnabledInternalLocked();
}
}
}
}
@Override
public boolean isUsbDataSignalingEnabledForUser(int userId) {
final CallerIdentity caller = getCallerIdentity();
Preconditions.checkCallAuthorization(isSystemUid(caller));
synchronized (getLockObject()) {
return isUsbDataSignalingEnabledInternalLocked();
}
}
private boolean isUsbDataSignalingEnabledInternalLocked() {
// TODO(b/261999445): remove
ActiveAdmin admin;
@@ -22442,9 +22441,14 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
@Override
public boolean canUsbDataSignalingBeDisabled() {
return mInjector.binderWithCleanCallingIdentity(() ->
mInjector.getUsbManager() != null
&& mInjector.getUsbManager().getUsbHalVersion() >= UsbManager.USB_HAL_V1_3
return canUsbDataSignalingBeDisabledInternal(mContext);
}
private static boolean canUsbDataSignalingBeDisabledInternal(Context context) {
return Binder.withCleanCallingIdentity(() ->
context.getSystemService(UsbManager.class) != null
&& context.getSystemService(UsbManager.class).getUsbHalVersion()
>= UsbManager.USB_HAL_V1_3
);
}

View File

@@ -332,6 +332,14 @@ final class PolicyDefinition<V> {
PolicyEnforcerCallbacks::setPersonalAppsSuspended,
new BooleanPolicySerializer());
static PolicyDefinition<Boolean> USB_DATA_SIGNALING = new PolicyDefinition<>(
new NoArgsPolicyKey(DevicePolicyIdentifiers.USB_DATA_SIGNALING_POLICY),
// usb data signaling is enabled by default, hence disabling it is more restrictive.
FALSE_MORE_RESTRICTIVE,
POLICY_FLAG_GLOBAL_ONLY_POLICY,
(Boolean value, Context context, Integer userId, PolicyKey policyKey) ->
PolicyEnforcerCallbacks.setUsbDataSignalingEnabled(value, context),
new BooleanPolicySerializer());
private static final Map<String, PolicyDefinition<?>> POLICY_DEFINITIONS = new HashMap<>();
private static Map<String, Integer> USER_RESTRICTION_FLAGS = new HashMap<>();
@@ -364,6 +372,8 @@ final class PolicyDefinition<V> {
SCREEN_CAPTURE_DISABLED);
POLICY_DEFINITIONS.put(DevicePolicyIdentifiers.PERSONAL_APPS_SUSPENDED_POLICY,
PERSONAL_APPS_SUSPENDED);
POLICY_DEFINITIONS.put(DevicePolicyIdentifiers.USB_DATA_SIGNALING_POLICY,
USB_DATA_SIGNALING);
// User Restriction Policies
USER_RESTRICTION_FLAGS.put(UserManager.DISALLOW_MODIFY_ACCOUNTS, /* flags= */ 0);

View File

@@ -302,4 +302,14 @@ final class PolicyEnforcerCallbacks {
Slogf.wtf(LOG_TAG, "Failed to suspend apps: " + String.join(",", failedApps));
}
}
static boolean setUsbDataSignalingEnabled(@Nullable Boolean value, @NonNull Context context) {
return Binder.withCleanCallingIdentity(() -> {
Objects.requireNonNull(context);
boolean enabled = value == null || value;
DevicePolicyManagerService.updateUsbDataSignal(context, enabled);
return true;
});
}
}

View File

@@ -8125,14 +8125,13 @@ public class DevicePolicyManagerTest extends DpmTestBase {
}
@Test
public void testIsUsbDataSignalingEnabledForUser_systemUser() throws Exception {
public void testIsUsbDataSignalingEnabledForUser() throws Exception {
when(getServices().usbManager.enableUsbDataSignal(false)).thenReturn(true);
when(getServices().usbManager.getUsbHalVersion()).thenReturn(UsbManager.USB_HAL_V1_3);
setDeviceOwner();
dpm.setUsbDataSignalingEnabled(false);
mContext.binder.callingUid = DpmMockContext.SYSTEM_UID;
assertThat(dpm.isUsbDataSignalingEnabledForUser(UserHandle.myUserId())).isFalse();
assertThat(dpm.isUsbDataSignalingEnabled()).isFalse();
}
@Test

View File

@@ -251,6 +251,8 @@ public class DpmMockContext extends MockContext {
return mMockSystemServices.roleManager;
case Context.TELEPHONY_SUBSCRIPTION_SERVICE:
return mMockSystemServices.subscriptionManager;
case Context.USB_SERVICE:
return mMockSystemServices.usbManager;
}
throw new UnsupportedOperationException();
}