Merge "Add setProfileOwnerOnOrganizationOwnedDevice COPE API." into tm-dev

This commit is contained in:
Jonathan Scott
2022-03-18 17:50:42 +00:00
committed by Android (Google) Code Review
7 changed files with 40 additions and 34 deletions

View File

@@ -512,7 +512,6 @@ package android.app.admin {
method public boolean isFactoryResetProtectionPolicySupported();
method @RequiresPermission(anyOf={android.Manifest.permission.MANAGE_USERS, android.Manifest.permission.INTERACT_ACROSS_USERS}) public boolean isNewUserDisclaimerAcknowledged();
method public boolean isRemovingAdmin(@NonNull android.content.ComponentName, int);
method @RequiresPermission(anyOf={android.Manifest.permission.MARK_DEVICE_ORGANIZATION_OWNED, android.Manifest.permission.MANAGE_PROFILE_AND_DEVICE_OWNERS}, conditional=true) public void markProfileOwnerOnOrganizationOwnedDevice(@NonNull android.content.ComponentName);
method @NonNull public static String operationSafetyReasonToString(int);
method @NonNull public static String operationToString(int);
method @RequiresPermission(android.Manifest.permission.MANAGE_PROFILE_AND_DEVICE_OWNERS) public void resetDefaultCrossProfileIntentFilters(int);
@@ -521,6 +520,7 @@ package android.app.admin {
method @RequiresPermission(android.Manifest.permission.MANAGE_PROFILE_AND_DEVICE_OWNERS) public boolean setDeviceOwnerOnly(@NonNull android.content.ComponentName, @Nullable String, int);
method public void setDeviceOwnerType(@NonNull android.content.ComponentName, int);
method @RequiresPermission(android.Manifest.permission.MANAGE_DEVICE_ADMINS) public void setNextOperationSafety(int, int);
method @RequiresPermission(anyOf={android.Manifest.permission.MARK_DEVICE_ORGANIZATION_OWNED, android.Manifest.permission.MANAGE_PROFILE_AND_DEVICE_OWNERS}, conditional=true) public void setProfileOwnerOnOrganizationOwnedDevice(@NonNull android.content.ComponentName, boolean);
field public static final String ACTION_DATA_SHARING_RESTRICTION_APPLIED = "android.app.action.DATA_SHARING_RESTRICTION_APPLIED";
field public static final String ACTION_DEVICE_POLICY_CONSTANTS_CHANGED = "android.app.action.DEVICE_POLICY_CONSTANTS_CHANGED";
field public static final int DEVICE_OWNER_TYPE_DEFAULT = 0; // 0x0

View File

@@ -14073,12 +14073,12 @@ public class DevicePolicyManager {
/**
* Deprecated. Use {@code markProfileOwnerOnOrganizationOwnedDevice} instead.
* When called by an app targeting SDK level {@link android.os.Build.VERSION_CODES#Q} or
* below, will behave the same as {@link #markProfileOwnerOnOrganizationOwnedDevice}.
* below, will behave the same as {@link #setProfileOwnerOnOrganizationOwnedDevice}.
*
* When called by an app targeting SDK level {@link android.os.Build.VERSION_CODES#R}
* or above, will throw an UnsupportedOperationException when called.
*
* @deprecated Use {@link #markProfileOwnerOnOrganizationOwnedDevice} instead.
* @deprecated Use {@link #setProfileOwnerOnOrganizationOwnedDevice} instead.
*
* @hide
*/
@@ -14093,14 +14093,14 @@ public class DevicePolicyManager {
"This method is deprecated. use markProfileOwnerOnOrganizationOwnedDevice"
+ " instead.");
} else {
markProfileOwnerOnOrganizationOwnedDevice(who);
setProfileOwnerOnOrganizationOwnedDevice(who, true);
}
}
/**
* Marks the profile owner of the given user as managing an organization-owned device.
* That will give it access to device identifiers (such as serial number, IMEI and MEID)
* as well as other privileges.
* Sets whether the profile owner of the given user as managing an organization-owned device.
* Managing an organization-owned device will give it access to device identifiers (such as
* serial number, IMEI and MEID) as well as other privileges.
*
* @hide
*/
@@ -14108,13 +14108,15 @@ public class DevicePolicyManager {
@RequiresPermission(anyOf = {
android.Manifest.permission.MARK_DEVICE_ORGANIZATION_OWNED,
android.Manifest.permission.MANAGE_PROFILE_AND_DEVICE_OWNERS
}, conditional = true)
public void markProfileOwnerOnOrganizationOwnedDevice(@NonNull ComponentName who) {
}, conditional = true)
public void setProfileOwnerOnOrganizationOwnedDevice(@NonNull ComponentName who,
boolean isProfileOwnerOnOrganizationOwnedDevice) {
if (mService == null) {
return;
}
try {
mService.markProfileOwnerOnOrganizationOwnedDevice(who, myUserId());
mService.setProfileOwnerOnOrganizationOwnedDevice(who, myUserId(),
isProfileOwnerOnOrganizationOwnedDevice);
} catch (RemoteException re) {
throw re.rethrowFromSystemServer();
}

View File

@@ -477,7 +477,7 @@ interface IDevicePolicyManager {
int getGlobalPrivateDnsMode(in ComponentName admin);
String getGlobalPrivateDnsHost(in ComponentName admin);
void markProfileOwnerOnOrganizationOwnedDevice(in ComponentName who, int userId);
void setProfileOwnerOnOrganizationOwnedDevice(in ComponentName who, int userId, boolean isProfileOwnerOnOrganizationOwnedDevice);
void installUpdateFromFile(in ComponentName admin, in ParcelFileDescriptor updateFileDescriptor, in StartInstallingUpdateCallback listener);

View File

@@ -2124,7 +2124,7 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
+ "profile: %d", doUserId, poUserId);
Slogf.i(LOG_TAG, "Giving the PO additional power...");
markProfileOwnerOnOrganizationOwnedDeviceUncheckedLocked(poAdminComponent, poUserId);
setProfileOwnerOnOrganizationOwnedDeviceUncheckedLocked(poAdminComponent, poUserId, true);
Slogf.i(LOG_TAG, "Migrating DO policies to PO...");
moveDoPoliciesToProfileParentAdminLocked(doAdmin, poAdmin.getParentActiveAdmin());
migratePersonalAppSuspensionLocked(doUserId, poUserId, poAdmin);
@@ -14774,7 +14774,8 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
}
@Override
public void markProfileOwnerOnOrganizationOwnedDevice(ComponentName who, int userId) {
public void setProfileOwnerOnOrganizationOwnedDevice(ComponentName who, int userId,
boolean isProfileOwnerOnOrganizationOwnedDevice) {
if (!mHasFeature) {
return;
}
@@ -14806,13 +14807,14 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
// Grant access under lock.
synchronized (getLockObject()) {
markProfileOwnerOnOrganizationOwnedDeviceUncheckedLocked(who, userId);
setProfileOwnerOnOrganizationOwnedDeviceUncheckedLocked(who, userId,
isProfileOwnerOnOrganizationOwnedDevice);
}
}
@GuardedBy("getLockObject()")
private void markProfileOwnerOnOrganizationOwnedDeviceUncheckedLocked(
ComponentName who, int userId) {
private void setProfileOwnerOnOrganizationOwnedDeviceUncheckedLocked(
ComponentName who, int userId, boolean isProfileOwnerOnOrganizationOwnedDevice) {
// Make sure that the user has a profile owner and that the specified
// component is the profile owner of that user.
if (!isProfileOwner(who, userId)) {
@@ -14821,7 +14823,8 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
who.flattenToString(), userId));
}
Slogf.i(LOG_TAG, "Marking %s as profile owner on organization-owned device for user %d",
Slogf.i(LOG_TAG, "%s %s as profile owner on organization-owned device for user %d",
isProfileOwnerOnOrganizationOwnedDevice ? "Marking" : "Unmarking",
who.flattenToString(), userId);
// First, set restriction on removing the profile.
@@ -14838,15 +14841,18 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
+ " on user %d", parentUser.getIdentifier()));
}
mUserManager.setUserRestriction(UserManager.DISALLOW_REMOVE_MANAGED_PROFILE, true,
mUserManager.setUserRestriction(UserManager.DISALLOW_REMOVE_MANAGED_PROFILE,
isProfileOwnerOnOrganizationOwnedDevice,
parentUser);
mUserManager.setUserRestriction(UserManager.DISALLOW_ADD_USER, true,
mUserManager.setUserRestriction(UserManager.DISALLOW_ADD_USER,
isProfileOwnerOnOrganizationOwnedDevice,
parentUser);
});
// markProfileOwnerOfOrganizationOwnedDevice will trigger writing of the profile owner
// setProfileOwnerOfOrganizationOwnedDevice will trigger writing of the profile owner
// data, no need to do it manually.
mOwners.markProfileOwnerOfOrganizationOwnedDevice(userId);
mOwners.setProfileOwnerOfOrganizationOwnedDevice(userId,
isProfileOwnerOnOrganizationOwnedDevice);
}
private void pushMeteredDisabledPackagesLocked(int userId) {
@@ -17783,7 +17789,8 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
if (provisioningParams.isOrganizationOwnedProvisioning()) {
synchronized (getLockObject()) {
markProfileOwnerOnOrganizationOwnedDeviceUncheckedLocked(admin, userInfo.id);
setProfileOwnerOnOrganizationOwnedDeviceUncheckedLocked(admin, userInfo.id,
true);
}
}

View File

@@ -340,7 +340,7 @@ final class DevicePolicyManagerServiceShellCommand extends ShellCommand {
private int runMarkProfileOwnerOnOrganizationOwnedDevice(PrintWriter pw) {
parseArgs(/* canHaveName= */ false);
mService.markProfileOwnerOnOrganizationOwnedDevice(mComponent, mUserId);
mService.setProfileOwnerOnOrganizationOwnedDevice(mComponent, mUserId, true);
pw.printf("Success\n");
return 0;
}

View File

@@ -620,18 +620,15 @@ class Owners {
}
}
/**
* Sets the indicator that the profile owner manages an organization-owned device,
* then write to file.
*/
void markProfileOwnerOfOrganizationOwnedDevice(int userId) {
/** Set whether the profile owner manages an organization-owned device, then write to file. */
void setProfileOwnerOfOrganizationOwnedDevice(int userId, boolean isOrganizationOwnedDevice) {
synchronized (mLock) {
OwnerInfo profileOwner = mProfileOwners.get(userId);
if (profileOwner != null) {
profileOwner.isOrganizationOwnedDevice = true;
profileOwner.isOrganizationOwnedDevice = isOrganizationOwnedDevice;
} else {
Slog.e(TAG, String.format(
"No profile owner for user %d to set as org-owned.", userId));
"No profile owner for user %d to set org-owned flag.", userId));
}
writeProfileOwner(userId);
}

View File

@@ -6665,7 +6665,7 @@ public class DevicePolicyManagerTest extends DpmTestBase {
configureContextForAccess(mContext, false);
assertExpectException(SecurityException.class, /* messageRegex= */ null,
() -> dpm.markProfileOwnerOnOrganizationOwnedDevice(admin2));
() -> dpm.setProfileOwnerOnOrganizationOwnedDevice(admin2, true));
}
@Test
@@ -6674,7 +6674,7 @@ public class DevicePolicyManagerTest extends DpmTestBase {
configureContextForAccess(mContext, false);
assertExpectException(SecurityException.class, /* messageRegex= */ null,
() -> dpm.markProfileOwnerOnOrganizationOwnedDevice(admin1));
() -> dpm.setProfileOwnerOnOrganizationOwnedDevice(admin1, true));
}
@Test
@@ -6709,7 +6709,7 @@ public class DevicePolicyManagerTest extends DpmTestBase {
DpmMockContext.CALLER_MANAGED_PROVISIONING_UID);
try {
runAsCaller(mServiceContext, dpms, dpm -> {
dpm.markProfileOwnerOnOrganizationOwnedDevice(admin1);
dpm.setProfileOwnerOnOrganizationOwnedDevice(admin1, true);
});
} finally {
mServiceContext.binder.restoreCallingIdentity(ident);
@@ -7044,7 +7044,7 @@ public class DevicePolicyManagerTest extends DpmTestBase {
configureContextForAccess(mServiceContext, true);
runAsCaller(mServiceContext, dpms, dpm -> {
dpm.markProfileOwnerOnOrganizationOwnedDevice(who);
dpm.setProfileOwnerOnOrganizationOwnedDevice(who, true);
});
mServiceContext.binder.restoreCallingIdentity(ident);
}