From 9a3cf7c7ec4569f57997fa810219c7fb9b4e2463 Mon Sep 17 00:00:00 2001 From: Eric Biggers Date: Tue, 17 May 2022 00:17:56 +0000 Subject: [PATCH] Revert deprecation of DevicePolicyManager FDE constants The API council doesn't want these constants to be deprecated. This is a partial revert of http://ag/18171342, which keeps and revises the text that was added to the documentation. Bug: 208476087 Bug: 232310299 Change-Id: Ia5112416bcccf4dac2fa8f17ebe39dab0a8177f3 --- core/api/current.txt | 8 +-- .../app/admin/DevicePolicyManager.java | 57 +++++++++---------- 2 files changed, 31 insertions(+), 34 deletions(-) diff --git a/core/api/current.txt b/core/api/current.txt index 12c2b899093c2..103afee60db51 100644 --- a/core/api/current.txt +++ b/core/api/current.txt @@ -7673,11 +7673,11 @@ package android.app.admin { field public static final String DELEGATION_PACKAGE_ACCESS = "delegation-package-access"; field public static final String DELEGATION_PERMISSION_GRANT = "delegation-permission-grant"; field public static final String DELEGATION_SECURITY_LOGGING = "delegation-security-logging"; - field @Deprecated public static final int ENCRYPTION_STATUS_ACTIVATING = 2; // 0x2 - field @Deprecated public static final int ENCRYPTION_STATUS_ACTIVE = 3; // 0x3 - field @Deprecated public static final int ENCRYPTION_STATUS_ACTIVE_DEFAULT_KEY = 4; // 0x4 + field public static final int ENCRYPTION_STATUS_ACTIVATING = 2; // 0x2 + field public static final int ENCRYPTION_STATUS_ACTIVE = 3; // 0x3 + field public static final int ENCRYPTION_STATUS_ACTIVE_DEFAULT_KEY = 4; // 0x4 field public static final int ENCRYPTION_STATUS_ACTIVE_PER_USER = 5; // 0x5 - field @Deprecated public static final int ENCRYPTION_STATUS_INACTIVE = 1; // 0x1 + field public static final int ENCRYPTION_STATUS_INACTIVE = 1; // 0x1 field public static final int ENCRYPTION_STATUS_UNSUPPORTED = 0; // 0x0 field public static final String EXTRA_ADD_EXPLANATION = "android.app.extra.ADD_EXPLANATION"; field public static final String EXTRA_DELEGATION_SCOPES = "android.app.extra.DELEGATION_SCOPES"; diff --git a/core/java/android/app/admin/DevicePolicyManager.java b/core/java/android/app/admin/DevicePolicyManager.java index e23c1d24c6fcb..829bdee289721 100644 --- a/core/java/android/app/admin/DevicePolicyManager.java +++ b/core/java/android/app/admin/DevicePolicyManager.java @@ -6472,53 +6472,50 @@ public class DevicePolicyManager { public static final int ENCRYPTION_STATUS_UNSUPPORTED = 0; /** - * @deprecated {@link #getStorageEncryptionStatus} could only return this value on devices that - * use Full Disk Encryption. However, support for Full Disk Encryption was entirely removed in - * API level 33, being replaced by File Based Encryption. {@link #setStorageEncryption} can - * return this value for an unrelated reason, but {@link #setStorageEncryption} is deprecated - * since it doesn't do anything useful. - * * Result code for {@link #setStorageEncryption} and {@link #getStorageEncryptionStatus}: * indicating that encryption is supported, but is not currently active. + *

+ * {@link #getStorageEncryptionStatus} can only return this value on devices that use Full Disk + * Encryption. Support for Full Disk Encryption was entirely removed in API level 33, having + * been replaced by File Based Encryption. Devices that use File Based Encryption always + * automatically activate their encryption on first boot. + *

+ * {@link #setStorageEncryption} can still return this value for an unrelated reason, but {@link + * #setStorageEncryption} is deprecated since it doesn't do anything useful. */ public static final int ENCRYPTION_STATUS_INACTIVE = 1; /** - * @deprecated {@link #getStorageEncryptionStatus} could only return this value on devices that - * use Full Disk Encryption. However, support for Full Disk Encryption was entirely removed in - * API level 33, being replaced by File Based Encryption. - * - * Result code for {@link #getStorageEncryptionStatus}: - * indicating that encryption is not currently active, but is currently - * being activated. This is only reported by devices that support - * encryption of data and only when the storage is currently - * undergoing a process of becoming encrypted. A device that must reboot and/or wipe data - * to become encrypted will never return this value. + * Result code for {@link #getStorageEncryptionStatus}: indicating that encryption is not + * currently active, but is currently being activated. + *

+ * This result code has never actually been used. */ public static final int ENCRYPTION_STATUS_ACTIVATING = 2; /** - * @deprecated {@link #getStorageEncryptionStatus} could only return this value for apps - * targeting API level 23 or lower, or on devices that use Full Disk Encryption. However, - * support for Full Disk Encryption was entirely removed in API level 33, being replaced by File - * Based Encryption. {@link #setStorageEncryption} can return this value for an unrelated - * reason, but {@link #setStorageEncryption} is deprecated since it doesn't do anything useful. - * * Result code for {@link #setStorageEncryption} and {@link #getStorageEncryptionStatus}: * indicating that encryption is active. *

- * Also see {@link #ENCRYPTION_STATUS_ACTIVE_PER_USER}. + * {@link #getStorageEncryptionStatus} can only return this value for apps targeting API level + * 23 or lower, or on devices that use Full Disk Encryption. Support for Full Disk Encryption + * was entirely removed in API level 33, having been replaced by File Based Encryption. The + * result code {@link #ENCRYPTION_STATUS_ACTIVE_PER_USER} is used on devices that use File Based + * Encryption, except when the app targets API level 23 or lower. + *

+ * {@link #setStorageEncryption} can still return this value for an unrelated reason, but {@link + * #setStorageEncryption} is deprecated since it doesn't do anything useful. */ public static final int ENCRYPTION_STATUS_ACTIVE = 3; /** - * @deprecated {@link #getStorageEncryptionStatus} could only return this value on devices that - * use Full Disk Encryption. However, support for Full Disk Encryption was entirely removed in - * API level 33, being replaced by File Based Encryption. - * - * Result code for {@link #getStorageEncryptionStatus}: - * indicating that encryption is active, but an encryption key has not - * been set by the user. + * Result code for {@link #getStorageEncryptionStatus}: indicating that encryption is active, + * but the encryption key is not cryptographically protected by the user's credentials. + *

+ * This value can only be returned on devices that use Full Disk Encryption. Support for Full + * Disk Encryption was entirely removed in API level 33, having been replaced by File Based + * Encryption. With File Based Encryption, each user's credential-encrypted storage is always + * cryptographically protected by the user's credentials. */ public static final int ENCRYPTION_STATUS_ACTIVE_DEFAULT_KEY = 4;