Merge changes from topics "WPT_279560135", "WPT_DPM_ROLE_HOLDER" into udc-dev
* changes: Remove flag, switch to work profile for sms dialog Throw exception if can't set default sms app on profile DPM role holder to control access managed sub api
This commit is contained in:
@@ -9862,6 +9862,9 @@ public class DevicePolicyManager {
|
|||||||
* profile owner of an organization-owned managed profile.
|
* profile owner of an organization-owned managed profile.
|
||||||
* @throws IllegalArgumentException if called on the parent profile and the package
|
* @throws IllegalArgumentException if called on the parent profile and the package
|
||||||
* provided is not a pre-installed system package.
|
* provided is not a pre-installed system package.
|
||||||
|
* @throws IllegalStateException while trying to set default sms app on the profile and
|
||||||
|
* {@link ManagedSubscriptionsPolicy#TYPE_ALL_MANAGED_SUBSCRIPTIONS}
|
||||||
|
* policy is not set.
|
||||||
*/
|
*/
|
||||||
@RequiresPermission(value = MANAGE_DEVICE_POLICY_DEFAULT_SMS, conditional = true)
|
@RequiresPermission(value = MANAGE_DEVICE_POLICY_DEFAULT_SMS, conditional = true)
|
||||||
public void setDefaultSmsApplication(@Nullable ComponentName admin,
|
public void setDefaultSmsApplication(@Nullable ComponentName admin,
|
||||||
|
|||||||
@@ -12445,6 +12445,17 @@ public final class Settings {
|
|||||||
public static final String BYPASS_DEVICE_POLICY_MANAGEMENT_ROLE_QUALIFICATIONS =
|
public static final String BYPASS_DEVICE_POLICY_MANAGEMENT_ROLE_QUALIFICATIONS =
|
||||||
"bypass_device_policy_management_role_qualifications";
|
"bypass_device_policy_management_role_qualifications";
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Whether work profile telephony feature is enabled for non
|
||||||
|
* {@link android.app.role.RoleManager#ROLE_DEVICE_POLICY_MANAGEMENT} holders.
|
||||||
|
* ("0" = false, "1" = true).
|
||||||
|
*
|
||||||
|
* @hide
|
||||||
|
*/
|
||||||
|
@Readable
|
||||||
|
public static final String ALLOW_WORK_PROFILE_TELEPHONY_FOR_NON_DPM_ROLE_HOLDERS =
|
||||||
|
"allow_work_profile_telephony_for_non_dpm_role_holders";
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Indicates whether mobile data should be allowed while the device is being provisioned.
|
* Indicates whether mobile data should be allowed while the device is being provisioned.
|
||||||
* This allows the provisioning process to turn off mobile data before the user
|
* This allows the provisioning process to turn off mobile data before the user
|
||||||
|
|||||||
@@ -116,6 +116,7 @@ public class SettingsBackupTest {
|
|||||||
Settings.Global.ADD_USERS_WHEN_LOCKED,
|
Settings.Global.ADD_USERS_WHEN_LOCKED,
|
||||||
Settings.Global.AIRPLANE_MODE_ON,
|
Settings.Global.AIRPLANE_MODE_ON,
|
||||||
Settings.Global.AIRPLANE_MODE_RADIOS,
|
Settings.Global.AIRPLANE_MODE_RADIOS,
|
||||||
|
Settings.Global.ALLOW_WORK_PROFILE_TELEPHONY_FOR_NON_DPM_ROLE_HOLDERS,
|
||||||
Settings.Global.SATELLITE_MODE_RADIOS,
|
Settings.Global.SATELLITE_MODE_RADIOS,
|
||||||
Settings.Global.SATELLITE_MODE_ENABLED,
|
Settings.Global.SATELLITE_MODE_ENABLED,
|
||||||
Settings.Global.AIRPLANE_MODE_TOGGLEABLE_RADIOS,
|
Settings.Global.AIRPLANE_MODE_TOGGLEABLE_RADIOS,
|
||||||
|
|||||||
@@ -232,7 +232,6 @@ import static android.net.ConnectivityManager.PROFILE_NETWORK_PREFERENCE_ENTERPR
|
|||||||
import static android.net.ConnectivityManager.PROFILE_NETWORK_PREFERENCE_ENTERPRISE_NO_FALLBACK;
|
import static android.net.ConnectivityManager.PROFILE_NETWORK_PREFERENCE_ENTERPRISE_NO_FALLBACK;
|
||||||
import static android.net.NetworkStack.PERMISSION_MAINLINE_NETWORK_STACK;
|
import static android.net.NetworkStack.PERMISSION_MAINLINE_NETWORK_STACK;
|
||||||
import static android.provider.DeviceConfig.NAMESPACE_DEVICE_POLICY_MANAGER;
|
import static android.provider.DeviceConfig.NAMESPACE_DEVICE_POLICY_MANAGER;
|
||||||
import static android.provider.DeviceConfig.NAMESPACE_TELEPHONY;
|
|
||||||
import static android.provider.Settings.Global.PRIVATE_DNS_SPECIFIER;
|
import static android.provider.Settings.Global.PRIVATE_DNS_SPECIFIER;
|
||||||
import static android.provider.Settings.Secure.MANAGED_PROVISIONING_DPC_DOWNLOADED;
|
import static android.provider.Settings.Secure.MANAGED_PROVISIONING_DPC_DOWNLOADED;
|
||||||
import static android.provider.Settings.Secure.USER_SETUP_COMPLETE;
|
import static android.provider.Settings.Secure.USER_SETUP_COMPLETE;
|
||||||
@@ -876,10 +875,6 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
|
|||||||
private static final String KEEP_PROFILES_RUNNING_FLAG = "enable_keep_profiles_running";
|
private static final String KEEP_PROFILES_RUNNING_FLAG = "enable_keep_profiles_running";
|
||||||
public static final boolean DEFAULT_KEEP_PROFILES_RUNNING_FLAG = true;
|
public static final boolean DEFAULT_KEEP_PROFILES_RUNNING_FLAG = true;
|
||||||
|
|
||||||
private static final String ENABLE_WORK_PROFILE_TELEPHONY_FLAG =
|
|
||||||
"enable_work_profile_telephony";
|
|
||||||
private static final boolean DEFAULT_WORK_PROFILE_TELEPHONY_FLAG = false;
|
|
||||||
|
|
||||||
// TODO(b/261999445) remove the flag after rollout.
|
// TODO(b/261999445) remove the flag after rollout.
|
||||||
private static final String HEADLESS_FLAG = "headless";
|
private static final String HEADLESS_FLAG = "headless";
|
||||||
private static final boolean DEFAULT_HEADLESS_FLAG = true;
|
private static final boolean DEFAULT_HEADLESS_FLAG = true;
|
||||||
@@ -3376,9 +3371,7 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
|
|||||||
onLockSettingsReady();
|
onLockSettingsReady();
|
||||||
loadAdminDataAsync();
|
loadAdminDataAsync();
|
||||||
mOwners.systemReady();
|
mOwners.systemReady();
|
||||||
if (isWorkProfileTelephonyEnabled()) {
|
|
||||||
applyManagedSubscriptionsPolicyIfRequired();
|
applyManagedSubscriptionsPolicyIfRequired();
|
||||||
}
|
|
||||||
break;
|
break;
|
||||||
case SystemService.PHASE_ACTIVITY_MANAGER_READY:
|
case SystemService.PHASE_ACTIVITY_MANAGER_READY:
|
||||||
synchronized (getLockObject()) {
|
synchronized (getLockObject()) {
|
||||||
@@ -3409,9 +3402,7 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
|
|||||||
unregisterOnSubscriptionsChangedListener();
|
unregisterOnSubscriptionsChangedListener();
|
||||||
int policyType = getManagedSubscriptionsPolicy().getPolicyType();
|
int policyType = getManagedSubscriptionsPolicy().getPolicyType();
|
||||||
if (policyType == ManagedSubscriptionsPolicy.TYPE_ALL_PERSONAL_SUBSCRIPTIONS) {
|
if (policyType == ManagedSubscriptionsPolicy.TYPE_ALL_PERSONAL_SUBSCRIPTIONS) {
|
||||||
final int parentUserId = getProfileParentId(copeProfileUserId);
|
clearManagedSubscriptionsPolicy();
|
||||||
// By default, assign all current and future subs to system user on COPE devices.
|
|
||||||
registerListenerToAssignSubscriptionsToUser(parentUserId);
|
|
||||||
} else if (policyType == ManagedSubscriptionsPolicy.TYPE_ALL_MANAGED_SUBSCRIPTIONS) {
|
} else if (policyType == ManagedSubscriptionsPolicy.TYPE_ALL_MANAGED_SUBSCRIPTIONS) {
|
||||||
// Add listener to assign all current and future subs to managed profile.
|
// Add listener to assign all current and future subs to managed profile.
|
||||||
registerListenerToAssignSubscriptionsToUser(copeProfileUserId);
|
registerListenerToAssignSubscriptionsToUser(copeProfileUserId);
|
||||||
@@ -7718,11 +7709,10 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
|
|||||||
}
|
}
|
||||||
mLockSettingsInternal.refreshStrongAuthTimeout(parentId);
|
mLockSettingsInternal.refreshStrongAuthTimeout(parentId);
|
||||||
|
|
||||||
if (isWorkProfileTelephonyEnabled()) {
|
|
||||||
clearManagedSubscriptionsPolicy();
|
clearManagedSubscriptionsPolicy();
|
||||||
clearLauncherShortcutOverrides();
|
clearLauncherShortcutOverrides();
|
||||||
updateTelephonyCrossProfileIntentFilters(parentId, UserHandle.USER_NULL, false);
|
updateTelephonyCrossProfileIntentFilters(parentId, UserHandle.USER_NULL, false);
|
||||||
}
|
|
||||||
Slogf.i(LOG_TAG, "Cleaning up device-wide policies done.");
|
Slogf.i(LOG_TAG, "Cleaning up device-wide policies done.");
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -11334,11 +11324,10 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
|
|||||||
synchronized (mSubscriptionsChangedListenerLock) {
|
synchronized (mSubscriptionsChangedListenerLock) {
|
||||||
pw.println("Subscription changed listener : " + mSubscriptionsChangedListener);
|
pw.println("Subscription changed listener : " + mSubscriptionsChangedListener);
|
||||||
}
|
}
|
||||||
pw.println("DPM Flag enable_work_profile_telephony : "
|
|
||||||
+ isWorkProfileTelephonyDevicePolicyManagerFlagEnabled());
|
|
||||||
pw.println("Telephony Flag enable_work_profile_telephony : "
|
|
||||||
+ isWorkProfileTelephonySubscriptionManagerFlagEnabled());
|
|
||||||
|
|
||||||
|
pw.println("DPM global setting ALLOW_WORK_PROFILE_TELEPHONY_FOR_NON_DPM_ROLE_HOLDERS : "
|
||||||
|
+ mInjector.settingsGlobalGetString(
|
||||||
|
Global.ALLOW_WORK_PROFILE_TELEPHONY_FOR_NON_DPM_ROLE_HOLDERS));
|
||||||
mHandler.post(() -> handleDump(pw));
|
mHandler.post(() -> handleDump(pw));
|
||||||
dumpResources(pw);
|
dumpResources(pw);
|
||||||
}
|
}
|
||||||
@@ -11580,6 +11569,15 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
|
|||||||
Preconditions.checkCallAuthorization(isDefaultDeviceOwner(caller)
|
Preconditions.checkCallAuthorization(isDefaultDeviceOwner(caller)
|
||||||
|| isProfileOwnerOfOrganizationOwnedDevice(caller));
|
|| isProfileOwnerOfOrganizationOwnedDevice(caller));
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (!parent && isManagedProfile(caller.getUserId())
|
||||||
|
&& getManagedSubscriptionsPolicy().getPolicyType()
|
||||||
|
!= ManagedSubscriptionsPolicy.TYPE_ALL_MANAGED_SUBSCRIPTIONS) {
|
||||||
|
throw new IllegalStateException(
|
||||||
|
"Default sms application can only be set on the profile, when "
|
||||||
|
+ "ManagedSubscriptions policy is set");
|
||||||
|
}
|
||||||
|
|
||||||
if (parent) {
|
if (parent) {
|
||||||
userId = getProfileParentId(mInjector.userHandleGetCallingUserId());
|
userId = getProfileParentId(mInjector.userHandleGetCallingUserId());
|
||||||
mInjector.binderWithCleanCallingIdentity(() -> enforcePackageIsSystemPackage(
|
mInjector.binderWithCleanCallingIdentity(() -> enforcePackageIsSystemPackage(
|
||||||
@@ -15197,8 +15195,14 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
|
|||||||
|
|
||||||
@Override
|
@Override
|
||||||
public void setGlobalSetting(ComponentName who, String setting, String value) {
|
public void setGlobalSetting(ComponentName who, String setting, String value) {
|
||||||
Objects.requireNonNull(who, "ComponentName is null");
|
|
||||||
final CallerIdentity caller = getCallerIdentity(who);
|
final CallerIdentity caller = getCallerIdentity(who);
|
||||||
|
if (Global.ALLOW_WORK_PROFILE_TELEPHONY_FOR_NON_DPM_ROLE_HOLDERS.equals(setting)) {
|
||||||
|
Preconditions.checkCallAuthorization(isCallerDevicePolicyManagementRoleHolder(caller));
|
||||||
|
mInjector.binderWithCleanCallingIdentity(
|
||||||
|
() -> mInjector.settingsGlobalPutString(setting, value));
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
Objects.requireNonNull(who, "ComponentName is null");
|
||||||
Preconditions.checkCallAuthorization(isDefaultDeviceOwner(caller));
|
Preconditions.checkCallAuthorization(isDefaultDeviceOwner(caller));
|
||||||
|
|
||||||
DevicePolicyEventLogger
|
DevicePolicyEventLogger
|
||||||
@@ -23791,26 +23795,6 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
|
|||||||
suspendAppsForQuietProfiles(keepProfileRunning);
|
suspendAppsForQuietProfiles(keepProfileRunning);
|
||||||
}
|
}
|
||||||
|
|
||||||
private boolean isWorkProfileTelephonyEnabled() {
|
|
||||||
return isWorkProfileTelephonyDevicePolicyManagerFlagEnabled()
|
|
||||||
&& isWorkProfileTelephonySubscriptionManagerFlagEnabled();
|
|
||||||
}
|
|
||||||
|
|
||||||
private boolean isWorkProfileTelephonyDevicePolicyManagerFlagEnabled() {
|
|
||||||
return DeviceConfig.getBoolean(NAMESPACE_DEVICE_POLICY_MANAGER,
|
|
||||||
ENABLE_WORK_PROFILE_TELEPHONY_FLAG, DEFAULT_WORK_PROFILE_TELEPHONY_FLAG);
|
|
||||||
}
|
|
||||||
|
|
||||||
private boolean isWorkProfileTelephonySubscriptionManagerFlagEnabled() {
|
|
||||||
final long ident = mInjector.binderClearCallingIdentity();
|
|
||||||
try {
|
|
||||||
return DeviceConfig.getBoolean(NAMESPACE_TELEPHONY, ENABLE_WORK_PROFILE_TELEPHONY_FLAG,
|
|
||||||
false);
|
|
||||||
} finally {
|
|
||||||
mInjector.binderRestoreCallingIdentity(ident);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
@Override
|
@Override
|
||||||
public void setOverrideKeepProfilesRunning(boolean enabled) {
|
public void setOverrideKeepProfilesRunning(boolean enabled) {
|
||||||
Preconditions.checkCallAuthorization(
|
Preconditions.checkCallAuthorization(
|
||||||
@@ -23921,24 +23905,26 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
|
|||||||
|
|
||||||
@Override
|
@Override
|
||||||
public ManagedSubscriptionsPolicy getManagedSubscriptionsPolicy() {
|
public ManagedSubscriptionsPolicy getManagedSubscriptionsPolicy() {
|
||||||
if (isWorkProfileTelephonyEnabled()) {
|
|
||||||
synchronized (getLockObject()) {
|
synchronized (getLockObject()) {
|
||||||
ActiveAdmin admin = getProfileOwnerOfOrganizationOwnedDeviceLocked();
|
ActiveAdmin admin = getProfileOwnerOfOrganizationOwnedDeviceLocked();
|
||||||
if (admin != null && admin.mManagedSubscriptionsPolicy != null) {
|
if (admin != null && admin.mManagedSubscriptionsPolicy != null) {
|
||||||
return admin.mManagedSubscriptionsPolicy;
|
return admin.mManagedSubscriptionsPolicy;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
|
||||||
return new ManagedSubscriptionsPolicy(
|
return new ManagedSubscriptionsPolicy(
|
||||||
ManagedSubscriptionsPolicy.TYPE_ALL_PERSONAL_SUBSCRIPTIONS);
|
ManagedSubscriptionsPolicy.TYPE_ALL_PERSONAL_SUBSCRIPTIONS);
|
||||||
}
|
}
|
||||||
|
|
||||||
@Override
|
@Override
|
||||||
public void setManagedSubscriptionsPolicy(ManagedSubscriptionsPolicy policy) {
|
public void setManagedSubscriptionsPolicy(ManagedSubscriptionsPolicy policy) {
|
||||||
if (!isWorkProfileTelephonyEnabled()) {
|
CallerIdentity caller = getCallerIdentity();
|
||||||
|
|
||||||
|
if (!isCallerDevicePolicyManagementRoleHolder(caller)
|
||||||
|
&& !Objects.equals(mInjector.settingsGlobalGetString(
|
||||||
|
Global.ALLOW_WORK_PROFILE_TELEPHONY_FOR_NON_DPM_ROLE_HOLDERS), "1")) {
|
||||||
throw new UnsupportedOperationException("This api is not enabled");
|
throw new UnsupportedOperationException("This api is not enabled");
|
||||||
}
|
}
|
||||||
CallerIdentity caller = getCallerIdentity();
|
|
||||||
Preconditions.checkCallAuthorization(isProfileOwnerOfOrganizationOwnedDevice(caller),
|
Preconditions.checkCallAuthorization(isProfileOwnerOfOrganizationOwnedDevice(caller),
|
||||||
"This policy can only be set by a profile owner on an organization-owned "
|
"This policy can only be set by a profile owner on an organization-owned "
|
||||||
+ "device.");
|
+ "device.");
|
||||||
|
|||||||
@@ -32,7 +32,6 @@ import android.os.RemoteException;
|
|||||||
import android.os.SystemProperties;
|
import android.os.SystemProperties;
|
||||||
import android.os.UserHandle;
|
import android.os.UserHandle;
|
||||||
import android.os.UserManager;
|
import android.os.UserManager;
|
||||||
import android.provider.DeviceConfig;
|
|
||||||
import android.telephony.SubscriptionManager;
|
import android.telephony.SubscriptionManager;
|
||||||
import android.telephony.TelephonyFrameworkInitializer;
|
import android.telephony.TelephonyFrameworkInitializer;
|
||||||
import android.telephony.TelephonyManager;
|
import android.telephony.TelephonyManager;
|
||||||
@@ -262,9 +261,6 @@ public final class TelephonyUtils {
|
|||||||
*/
|
*/
|
||||||
public static void showSwitchToManagedProfileDialogIfAppropriate(Context context,
|
public static void showSwitchToManagedProfileDialogIfAppropriate(Context context,
|
||||||
int subId, int callingUid, String callingPackage) {
|
int subId, int callingUid, String callingPackage) {
|
||||||
if (!isSwitchToManagedProfileDialogFlagEnabled()) {
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
final long token = Binder.clearCallingIdentity();
|
final long token = Binder.clearCallingIdentity();
|
||||||
try {
|
try {
|
||||||
UserHandle callingUserHandle = UserHandle.getUserHandleForUid(callingUid);
|
UserHandle callingUserHandle = UserHandle.getUserHandleForUid(callingUid);
|
||||||
@@ -302,11 +298,6 @@ public final class TelephonyUtils {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
public static boolean isSwitchToManagedProfileDialogFlagEnabled() {
|
|
||||||
return DeviceConfig.getBoolean(DeviceConfig.NAMESPACE_DEVICE_POLICY_MANAGER,
|
|
||||||
"enable_switch_to_managed_profile_dialog", false);
|
|
||||||
}
|
|
||||||
|
|
||||||
private static boolean isUidForeground(Context context, int uid) {
|
private static boolean isUidForeground(Context context, int uid) {
|
||||||
ActivityManager am = context.getSystemService(ActivityManager.class);
|
ActivityManager am = context.getSystemService(ActivityManager.class);
|
||||||
boolean result = am != null && am.getUidImportance(uid)
|
boolean result = am != null && am.getUidImportance(uid)
|
||||||
|
|||||||
Reference in New Issue
Block a user