Merge changes I9e940e5b,Iaa27f34a,I2291984c,I95d8ec76

* changes:
  Correctly identify the COPE user for screenshot policy.
  Stop silently eating exceptions in DPMS. This can result in really hard to debug issues.
  Don't supress failures in adopting shell permission identity.
  Remove assumption that COPE profile owner is on profile of system user
This commit is contained in:
TreeHugger Robot
2022-12-16 13:54:30 +00:00
committed by Android (Google) Code Review
2 changed files with 141 additions and 31 deletions

View File

@@ -76,7 +76,6 @@ import java.io.IOException;
import java.lang.annotation.Retention;
import java.lang.annotation.RetentionPolicy;
import java.util.ArrayList;
import java.util.Collections;
import java.util.List;
import java.util.Set;
import java.util.concurrent.TimeoutException;
@@ -484,7 +483,7 @@ public final class UiAutomation {
// Calling out without a lock held.
mUiAutomationConnection.adoptShellPermissionIdentity(Process.myUid(), null);
} catch (RemoteException re) {
Log.e(LOG_TAG, "Error executing adopting shell permission identity!", re);
throw re.rethrowFromSystemServer();
}
}
@@ -509,7 +508,7 @@ public final class UiAutomation {
// Calling out without a lock held.
mUiAutomationConnection.adoptShellPermissionIdentity(Process.myUid(), permissions);
} catch (RemoteException re) {
Log.e(LOG_TAG, "Error executing adopting shell permission identity!", re);
throw re.rethrowFromSystemServer();
}
}
@@ -525,7 +524,7 @@ public final class UiAutomation {
// Calling out without a lock held.
mUiAutomationConnection.dropShellPermissionIdentity();
} catch (RemoteException re) {
Log.e(LOG_TAG, "Error executing dropping shell permission identity!", re);
throw re.rethrowFromSystemServer();
}
}
@@ -543,8 +542,7 @@ public final class UiAutomation {
final List<String> permissions = mUiAutomationConnection.getAdoptedShellPermissions();
return permissions == null ? ALL_PERMISSIONS : new ArraySet<>(permissions);
} catch (RemoteException re) {
Log.e(LOG_TAG, "Error getting adopted shell permissions", re);
return Collections.emptySet();
throw re.rethrowFromSystemServer();
}
}

View File

@@ -721,6 +721,10 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
private static final String KEEP_PROFILES_RUNNING_FLAG = "enable_keep_profiles_running";
private static final boolean DEFAULT_KEEP_PROFILES_RUNNING_FLAG = false;
// TODO(b/261999445) remove the flag after rollout.
private static final String HEADLESS_FLAG = "headless";
private static final boolean DEFAULT_HEADLESS_FLAG = true;
/**
* This feature flag is checked once after boot and this value us used until the next reboot to
* avoid needing to handle the flag changing on the fly.
@@ -1231,6 +1235,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
}
} catch (RemoteException re) {
// Shouldn't happen.
Slogf.wtf(LOG_TAG, "Error handling package changes", re);
}
}
if (removedAdmin) {
@@ -1288,6 +1293,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
&& mIPackageManager.getPackageInfo(targetPackage, 0, userHandle) == null;
} catch (RemoteException e) {
// Shouldn't happen
Slogf.wtf(LOG_TAG, "Error checking isRemovedPackage", e);
}
return false;
@@ -1310,6 +1316,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
null, null, null, PLATFORM_PACKAGE_NAME, userHandle);
} catch (RemoteException ignored) {
// shouldn't happen.
Slogf.wtf(LOG_TAG, "Error handling new package installed", ignored);
}
}
@@ -2228,6 +2235,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
packageName, MATCH_DIRECT_BOOT_AWARE | MATCH_DIRECT_BOOT_UNAWARE, userId);
} catch (RemoteException e) {
// Shouldn't happen.
Slogf.wtf(LOG_TAG, "Error getting application info", e);
return;
}
if (appInfo == null) {
@@ -2580,7 +2588,6 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
ensureLocked();
// Try to find an admin which can use reqPolicy
final ComponentName poAdminComponent = mOwners.getProfileOwnerComponent(userId);
final ComponentName doAdminComponent = mOwners.getDeviceOwnerComponent();
if (poAdminComponent != null) {
return getProfileOwnerLocked(userId);
@@ -2862,6 +2869,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
| PackageManager.MATCH_DIRECT_BOOT_UNAWARE, userHandle);
} catch (RemoteException e) {
// shouldn't happen.
Slogf.wtf(LOG_TAG, "Error getting receiver info", e);
return null;
}
});
@@ -6769,6 +6777,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
}
} catch (RemoteException re) {
// Shouldn't happen
Slogf.wtf(LOG_TAG, "Error forcing wipe user", re);
} finally {
if (!success) SecurityLog.writeEvent(SecurityLog.TAG_WIPE_FAILURE);
}
@@ -7063,8 +7072,13 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
Preconditions.checkCallAuthorization(frpManagementAgentUid == caller.getUid()
|| hasCallingPermission(permission.MASTER_CLEAR),
"Must be called by the FRP management agent on device");
admin = getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceLocked(
UserHandle.getUserId(frpManagementAgentUid));
// TODO(b/261999445): Remove
if (isHeadlessFlagEnabled()) {
admin = getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceLocked();
} else {
admin = getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceLocked(
UserHandle.getUserId(frpManagementAgentUid));
}
} else {
Preconditions.checkCallAuthorization(
isDefaultDeviceOwner(caller)
@@ -7105,8 +7119,14 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
hasCallingOrSelfPermission(permission.TRIGGER_LOST_MODE));
synchronized (getLockObject()) {
final ActiveAdmin admin = getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceLocked(
UserHandle.USER_SYSTEM);
// TODO(b/261999445): Remove
ActiveAdmin admin;
if (isHeadlessFlagEnabled()) {
admin = getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceLocked();
} else {
admin = getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceLocked(
UserHandle.USER_SYSTEM);
}
Preconditions.checkState(admin != null,
"Lost mode location updates can only be sent on an organization-owned device.");
mInjector.binderWithCleanCallingIdentity(() -> {
@@ -7741,9 +7761,15 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
// be disabled device-wide.
private void pushScreenCapturePolicy(int adminUserId) {
// Update screen capture device-wide if disabled by the DO or COPE PO on the parent profile.
ActiveAdmin admin =
getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceParentLocked(
UserHandle.USER_SYSTEM);
// TODO(b/261999445): remove
ActiveAdmin admin;
if (isHeadlessFlagEnabled()) {
admin = getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceParentLocked(
mUserManagerInternal.getProfileParentId(adminUserId));
} else {
admin = getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceParentLocked(
UserHandle.USER_SYSTEM);
}
if (admin != null && admin.disableScreenCapture) {
setScreenCaptureDisabled(UserHandle.USER_ALL);
} else {
@@ -8774,6 +8800,10 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
return null;
}
/**
* @deprecated Use the version which does not take a user id.
*/
@Deprecated
ActiveAdmin getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceLocked(int userId) {
ensureLocked();
ActiveAdmin admin = getDeviceOwnerAdminLocked();
@@ -8783,6 +8813,15 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
return admin;
}
ActiveAdmin getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceLocked() {
ensureLocked();
ActiveAdmin admin = getDeviceOwnerAdminLocked();
if (admin == null) {
admin = getProfileOwnerOfOrganizationOwnedDeviceLocked();
}
return admin;
}
ActiveAdmin getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceParentLocked(int userId) {
ensureLocked();
ActiveAdmin admin = getDeviceOwnerAdminLocked();
@@ -9078,6 +9117,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
pushUserRestrictions(userId);
} catch (RemoteException re) {
// Shouldn't happen.
Slogf.wtf(LOG_TAG, "Failing in updatePermissionFlagsForAllApps", re);
}
}
@@ -9341,6 +9381,22 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
});
}
@GuardedBy("getLockObject()")
ActiveAdmin getProfileOwnerOfOrganizationOwnedDeviceLocked() {
return mInjector.binderWithCleanCallingIdentity(() -> {
for (UserInfo userInfo : mUserManager.getUsers()) {
if (userInfo.isManagedProfile()) {
if (getProfileOwnerAsUser(userInfo.id) != null
&& isProfileOwnerOfOrganizationOwnedDevice(userInfo.id)) {
ComponentName who = getProfileOwnerAsUser(userInfo.id);
return getActiveAdminUncheckedLocked(who, userInfo.id);
}
}
}
return null;
});
}
/**
* This API is cached: invalidate with invalidateBinderCaches().
*/
@@ -9797,7 +9853,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
}
return currentUser.id;
} catch (RemoteException e) {
Slogf.wtf(LOG_TAG, "cannot get current user");
Slogf.wtf(LOG_TAG, "cannot get current user", e);
}
return UserHandle.USER_NULL;
}
@@ -10027,6 +10083,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
mIPackageManager.flushPackageRestrictionsAsUser(userHandle);
} catch (RemoteException re) {
// Shouldn't happen
Slog.wtf(LOG_TAG, "Error adding persistent preferred activity", re);
} finally {
mInjector.binderRestoreCallingIdentity(id);
}
@@ -10055,6 +10112,8 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
mIPackageManager.flushPackageRestrictionsAsUser(userHandle);
} catch (RemoteException re) {
// Shouldn't happen
Slogf.wtf(
LOG_TAG, "Error when clearing package persistent preferred activities", re);
} finally {
mInjector.binderRestoreCallingIdentity(id);
}
@@ -10252,6 +10311,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
}
} catch (RemoteException re) {
// Shouldn't happen
Slogf.wtf(LOG_TAG, "Error adding cross profile intent filter", re);
} finally {
mInjector.binderRestoreCallingIdentity(id);
}
@@ -10302,6 +10362,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
mIPackageManager.clearCrossProfileIntentFilters(parent.id, who.getPackageName());
} catch (RemoteException re) {
// Shouldn't happen
Slogf.wtf(LOG_TAG, "Error clearing cross profile intent filters", re);
} finally {
mInjector.binderRestoreCallingIdentity(id);
}
@@ -11826,7 +11887,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
}
} catch (RemoteException e) {
// shouldn't happen
Slogf.wtf(LOG_TAG, "Failed to resolve intent for: " + intent);
Slogf.wtf(LOG_TAG, "Failed to resolve intent for: " + intent, e);
return 0;
} finally {
mInjector.binderRestoreCallingIdentity(id);
@@ -11880,6 +11941,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
== PackageManager.INSTALL_SUCCEEDED;
} catch (RemoteException re) {
// shouldn't happen
Slogf.wtf(LOG_TAG, "Error installing package", re);
return false;
} finally {
mInjector.binderRestoreCallingIdentity(id);
@@ -14523,6 +14585,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
return ai == null ? 0 : ai.targetSdkVersion;
} catch (RemoteException e) {
// Shouldn't happen
Slogf.wtf(LOG_TAG, "Error getting application info", e);
return 0;
}
}
@@ -17415,8 +17478,14 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
synchronized (getLockObject()) {
// Only DO or COPE PO can turn on CC mode, so take a shortcut here and only look at
// their ActiveAdmin, instead of iterating through all admins.
final ActiveAdmin admin = getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceLocked(
UserHandle.USER_SYSTEM);
ActiveAdmin admin;
// TODO(b/261999445): remove
if (isHeadlessFlagEnabled()) {
admin = getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceLocked();
} else {
admin = getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceLocked(
UserHandle.USER_SYSTEM);
}
return admin != null ? admin.mCommonCriteriaMode : false;
}
}
@@ -18233,6 +18302,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
}
} catch (RemoteException e) {
// Shouldn't happen.
Slogf.wtf(LOG_TAG, "Error setting application enabled", e);
}
}
@@ -18268,6 +18338,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
callerPackage);
} catch (RemoteException e) {
// Shouldn't happen.
Slogf.wtf(LOG_TAG, "Error starting user", e);
} finally {
mContext.unregisterReceiver(unlockedReceiver);
}
@@ -18590,6 +18661,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
}
} catch (RemoteException e) {
// Shouldn't happen.
Slogf.wtf(LOG_TAG, "Error resetting default cross profile intent filters", e);
}
});
}
@@ -18819,8 +18891,14 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
}
private boolean isUsbDataSignalingEnabledInternalLocked() {
final ActiveAdmin admin = getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceLocked(
UserHandle.USER_SYSTEM);
// TODO(b/261999445): remove
ActiveAdmin admin;
if (isHeadlessFlagEnabled()) {
admin = getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceLocked();
} else {
admin = getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceLocked(
UserHandle.USER_SYSTEM);
}
return admin == null || admin.mUsbDataSignalingEnabled;
}
@@ -18870,8 +18948,14 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
@Override
public int getMinimumRequiredWifiSecurityLevel() {
synchronized (getLockObject()) {
final ActiveAdmin admin = getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceLocked(
UserHandle.USER_SYSTEM);
ActiveAdmin admin;
// TODO(b/261999445): remove
if (isHeadlessFlagEnabled()) {
admin = getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceLocked();
} else {
admin = getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceLocked(
UserHandle.USER_SYSTEM);
}
return (admin == null) ? DevicePolicyManager.WIFI_SECURITY_OPEN
: admin.mWifiMinimumSecurityLevel;
}
@@ -18887,8 +18971,14 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
+ "a profile owner on an organization-owned device or "
+ "an app with the QUERY_ADMIN_POLICY permission.");
synchronized (getLockObject()) {
final ActiveAdmin admin = getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceLocked(
UserHandle.USER_SYSTEM);
ActiveAdmin admin;
// TODO(b/261999445): remove
if (isHeadlessFlagEnabled()) {
admin = getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceLocked();
} else {
admin = getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceLocked(
UserHandle.USER_SYSTEM);
}
return admin != null ? admin.mWifiSsidPolicy : null;
}
}
@@ -19260,9 +19350,17 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
|| isProfileOwnerOfOrganizationOwnedDevice(caller));
}
synchronized (getLockObject()) {
ActiveAdmin admin =
getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceLocked(
UserHandle.USER_SYSTEM);
// TODO(b/261999445): Remove
ActiveAdmin admin;
if (isHeadlessFlagEnabled()) {
admin =
getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceLocked();
} else {
admin =
getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceLocked(
UserHandle.USER_SYSTEM);
}
if (admin != null) {
final String memtagProperty = "arm64.memtag.bootctl";
if (flags == DevicePolicyManager.MTE_ENABLED) {
@@ -19284,12 +19382,26 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
|| isProfileOwnerOfOrganizationOwnedDevice(caller)
|| isSystemUid(caller));
synchronized (getLockObject()) {
ActiveAdmin admin =
getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceLocked(
UserHandle.USER_SYSTEM);
// TODO(b/261999445): Remove
ActiveAdmin admin;
if (isHeadlessFlagEnabled()) {
admin =
getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceLocked();
} else {
admin =
getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceLocked(
UserHandle.USER_SYSTEM);
}
return admin != null
? admin.mtePolicy
: DevicePolicyManager.MTE_NOT_CONTROLLED_BY_POLICY;
}
}
}
private boolean isHeadlessFlagEnabled() {
return DeviceConfig.getBoolean(
NAMESPACE_DEVICE_POLICY_MANAGER,
HEADLESS_FLAG,
DEFAULT_HEADLESS_FLAG);
}
}