Notify caller onError when aborting operation.

Bug: 169323687
Test: atest com.android.server.biometrics.AuthServiceTest
Test: manual launch work app and verify biometric prompt (i.e. adb shell am start --user 10 -n com.google.android.apps.dynamite/.activity.main.MainActivity)
Change-Id: Ib62a70bfbdbde60f9ed9b7f161afdceef03a1482
This commit is contained in:
Joe Bolinger
2021-06-09 09:58:53 -07:00
parent 466698f9af
commit 9fecaf5a2c
2 changed files with 44 additions and 10 deletions

View File

@@ -27,6 +27,8 @@ import static android.Manifest.permission.USE_FINGERPRINT;
import static android.hardware.biometrics.BiometricAuthenticator.TYPE_FACE;
import static android.hardware.biometrics.BiometricAuthenticator.TYPE_FINGERPRINT;
import static android.hardware.biometrics.BiometricAuthenticator.TYPE_IRIS;
import static android.hardware.biometrics.BiometricAuthenticator.TYPE_NONE;
import static android.hardware.biometrics.BiometricConstants.BIOMETRIC_ERROR_CANCELED;
import static android.hardware.biometrics.BiometricManager.Authenticators;
import android.annotation.NonNull;
@@ -76,7 +78,6 @@ import java.util.List;
*/
public class AuthService extends SystemService {
private static final String TAG = "AuthService";
private static final boolean DEBUG = false;
private static final String SETTING_HIDL_DISABLED =
"com.android.server.biometrics.AuthService.hidlDisabled";
private static final int DEFAULT_HIDL_DISABLED = 0;
@@ -208,7 +209,6 @@ public class AuthService extends SystemService {
public void authenticate(IBinder token, long sessionId, int userId,
IBiometricServiceReceiver receiver, String opPackageName, PromptInfo promptInfo)
throws RemoteException {
// Only allow internal clients to authenticate with a different userId.
final int callingUserId = UserHandle.getCallingUserId();
final int callingUid = Binder.getCallingUid();
@@ -222,17 +222,18 @@ public class AuthService extends SystemService {
}
if (!checkAppOps(callingUid, opPackageName, "authenticate()")) {
Slog.e(TAG, "Denied by app ops: " + opPackageName);
return;
}
if (!Utils.isForeground(callingUid, callingPid)) {
Slog.e(TAG, "Caller is not foreground: " + opPackageName);
authenticateFastFail("Denied by app ops: " + opPackageName, receiver);
return;
}
if (token == null || receiver == null || opPackageName == null || promptInfo == null) {
Slog.e(TAG, "Unable to authenticate, one or more null arguments");
authenticateFastFail(
"Unable to authenticate, one or more null arguments", receiver);
return;
}
if (!Utils.isForeground(callingUid, callingPid)) {
authenticateFastFail("Caller is not foreground: " + opPackageName, receiver);
return;
}
@@ -257,6 +258,17 @@ public class AuthService extends SystemService {
}
}
private void authenticateFastFail(String message, IBiometricServiceReceiver receiver) {
// notify caller in cases where authentication is aborted before calling into
// IBiometricService without raising an exception
Slog.e(TAG, message);
try {
receiver.onError(TYPE_NONE, BIOMETRIC_ERROR_CANCELED, 0 /*vendorCode */);
} catch (RemoteException e) {
Slog.e(TAG, "authenticateFastFail failed to notify caller", e);
}
}
@Override
public void cancelAuthentication(IBinder token, String opPackageName)
throws RemoteException {

View File

@@ -16,6 +16,8 @@
package com.android.server.biometrics;
import static android.hardware.biometrics.BiometricAuthenticator.TYPE_NONE;
import static android.hardware.biometrics.BiometricConstants.BIOMETRIC_ERROR_CANCELED;
import static android.hardware.biometrics.BiometricConstants.BIOMETRIC_SUCCESS;
import static junit.framework.Assert.assertEquals;
@@ -234,6 +236,27 @@ public class AuthServiceTest {
eq(mReceiver),
eq(TEST_OP_PACKAGE_NAME),
eq(promptInfo));
verify(mReceiver).onError(eq(TYPE_NONE), eq(BIOMETRIC_ERROR_CANCELED), anyInt());
}
@Test
public void testAuthenticate_missingRequiredParam() throws Exception {
mAuthService = new AuthService(mContext, mInjector);
mAuthService.onStart();
final PromptInfo promptInfo = new PromptInfo();
final long sessionId = 0;
final int userId = 0;
mAuthService.mImpl.authenticate(
null /* token */,
sessionId,
userId,
mReceiver,
TEST_OP_PACKAGE_NAME,
promptInfo);
waitForIdle();
verify(mReceiver).onError(eq(TYPE_NONE), eq(BIOMETRIC_ERROR_CANCELED), anyInt());
}
@Test
@@ -259,7 +282,6 @@ public class AuthServiceTest {
eq(authenticators));
}
@Test
public void testHasEnrolledBiometrics_callsBiometricServiceHasEnrolledBiometrics() throws
Exception {