Migrate existing policies to the policy engine

Migrated policies that are stored in DPMS only

Fixes: 258811766
Bug: 273494642
Test: btest a.d.c.UserControlDisabledPackagesTest#setUserControlDisabledPackages_policyMigration_works*
Test: btest a.d.c.PermitInputMethodsTest#setPermittedInputMethods_policyMigration_works*
Test: btest a.d.c.AccountManagementTest#setAccountManagementDisabled_policyMigration_works*
Test: btest a.d.c.ScreenCaptureDisabledTest#setScreenCaptureDisabled_policyMigration_works*
Change-Id: I320ba9a56e66ce2bf1833ff6e33b1c3d9e36013e
Merged-In: I320ba9a56e66ce2bf1833ff6e33b1c3d9e36013e
This commit is contained in:
Kholoud Mohamed
2023-05-09 16:30:18 +00:00
parent d38421d06e
commit a42e8e4bc7

View File

@@ -12294,13 +12294,18 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
EnforcingAdmin admin = enforcePermissionAndGetEnforcingAdmin( EnforcingAdmin admin = enforcePermissionAndGetEnforcingAdmin(
who, MANAGE_DEVICE_POLICY_INPUT_METHODS, who, MANAGE_DEVICE_POLICY_INPUT_METHODS,
caller.getPackageName(), userId); caller.getPackageName(), userId);
if (packageList == null) {
mDevicePolicyEngine.removeLocalPolicy(
PolicyDefinition.PERMITTED_INPUT_METHODS,
admin,
userId);
} else {
mDevicePolicyEngine.setLocalPolicy( mDevicePolicyEngine.setLocalPolicy(
PolicyDefinition.PERMITTED_INPUT_METHODS, PolicyDefinition.PERMITTED_INPUT_METHODS,
admin, admin,
packageList == null new StringSetPolicyValue(new HashSet<>(packageList)),
? null
: new StringSetPolicyValue(new HashSet<>(packageList)),
userId); userId);
}
} else { } else {
ActiveAdmin admin = getParentOfAdminIfRequired( ActiveAdmin admin = getParentOfAdminIfRequired(
getProfileOwnerOrDeviceOwnerLocked(caller.getUserId()), getProfileOwnerOrDeviceOwnerLocked(caller.getUserId()),
@@ -12337,14 +12342,14 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
} }
CallerIdentity caller; CallerIdentity caller;
if (isPermissionCheckFlagEnabled()) { if (isPolicyEngineForFinanceFlagEnabled()) {
caller = getCallerIdentity(who, callerPackageName); caller = getCallerIdentity(who, callerPackageName);
} else { } else {
caller = getCallerIdentity(who); caller = getCallerIdentity(who);
Objects.requireNonNull(who, "ComponentName is null"); Objects.requireNonNull(who, "ComponentName is null");
} }
if (!isPermissionCheckFlagEnabled()) { if (!isPolicyEngineForFinanceFlagEnabled()) {
if (calledOnParentInstance) { if (calledOnParentInstance) {
Preconditions.checkCallAuthorization( Preconditions.checkCallAuthorization(
isProfileOwnerOfOrganizationOwnedDevice(caller)); isProfileOwnerOfOrganizationOwnedDevice(caller));
@@ -14268,7 +14273,6 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
resultSet.add(accountType); resultSet.add(accountType);
} }
} }
} else { } else {
caller = getCallerIdentity(); caller = getCallerIdentity();
Preconditions.checkCallAuthorization(hasFullCrossUsersPermission(caller, userId)); Preconditions.checkCallAuthorization(hasFullCrossUsersPermission(caller, userId));
@@ -24065,6 +24069,7 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
private boolean hasNonTestOnlyActiveAdmins() { private boolean hasNonTestOnlyActiveAdmins() {
return mInjector.binderWithCleanCallingIdentity(() -> { return mInjector.binderWithCleanCallingIdentity(() -> {
for (UserInfo userInfo : mUserManager.getUsers()) { for (UserInfo userInfo : mUserManager.getUsers()) {
synchronized (getLockObject()) {
List<ComponentName> activeAdmins = getActiveAdmins(userInfo.id); List<ComponentName> activeAdmins = getActiveAdmins(userInfo.id);
if (activeAdmins == null) { if (activeAdmins == null) {
continue; continue;
@@ -24075,13 +24080,15 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
} }
} }
} }
}
return false; return false;
}); });
} }
private boolean shouldMigrateToDevicePolicyEngine() { private boolean shouldMigrateToDevicePolicyEngine() {
return mInjector.binderWithCleanCallingIdentity(() -> return mInjector.binderWithCleanCallingIdentity(() ->
isPermissionCheckFlagEnabled() && !mOwners.isMigratedToPolicyEngine()); (isPermissionCheckFlagEnabled() || isPolicyEngineForFinanceFlagEnabled())
&& !mOwners.isMigratedToPolicyEngine());
} }
/** /**
@@ -24090,13 +24097,21 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
private boolean migratePoliciesToDevicePolicyEngine() { private boolean migratePoliciesToDevicePolicyEngine() {
return mInjector.binderWithCleanCallingIdentity(() -> { return mInjector.binderWithCleanCallingIdentity(() -> {
try { try {
Slogf.i(LOG_TAG, "Started device policies migration to the device policy engine."); synchronized (getLockObject()) {
Slogf.i(LOG_TAG,
"Started device policies migration to the device policy engine.");
if (isUnicornFlagEnabled()) {
migrateAutoTimezonePolicy(); migrateAutoTimezonePolicy();
migratePermissionGrantStatePolicies(); migratePermissionGrantStatePolicies();
// TODO(b/258811766): add migration logic for all policies }
migrateScreenCapturePolicyLocked();
migratePermittedInputMethodsPolicyLocked();
migrateAccountManagementDisabledPolicyLocked();
migrateUserControlDisabledPackagesLocked();
mOwners.markMigrationToPolicyEngine(); mOwners.markMigrationToPolicyEngine();
return true; return true;
}
} catch (Exception e) { } catch (Exception e) {
mDevicePolicyEngine.clearAllPolicies(); mDevicePolicyEngine.clearAllPolicies();
Slogf.e(LOG_TAG, e, "Error occurred during device policy migration, will " Slogf.e(LOG_TAG, e, "Error occurred during device policy migration, will "
@@ -24160,6 +24175,136 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
} }
} }
private void migrateScreenCapturePolicyLocked() {
Binder.withCleanCallingIdentity(() -> {
if (mPolicyCache.getScreenCaptureDisallowedUser() == UserHandle.USER_NULL) {
return;
}
ActiveAdmin admin = getDeviceOwnerOrProfileOwnerOfOrganizationOwnedDeviceLocked();
if (admin != null
&& ((isDeviceOwner(admin) && admin.disableScreenCapture)
|| (admin.getParentActiveAdmin() != null
&& admin.getParentActiveAdmin().disableScreenCapture))) {
EnforcingAdmin enforcingAdmin = EnforcingAdmin.createEnterpriseEnforcingAdmin(
admin.info.getComponent(),
admin.getUserHandle().getIdentifier(),
admin);
mDevicePolicyEngine.setGlobalPolicy(
PolicyDefinition.SCREEN_CAPTURE_DISABLED,
enforcingAdmin,
new BooleanPolicyValue(true));
}
List<UserInfo> users = mUserManager.getUsers();
for (UserInfo userInfo : users) {
ActiveAdmin profileOwner = getProfileOwnerLocked(userInfo.id);
if (profileOwner != null && profileOwner.disableScreenCapture) {
EnforcingAdmin enforcingAdmin = EnforcingAdmin.createEnterpriseEnforcingAdmin(
profileOwner.info.getComponent(),
profileOwner.getUserHandle().getIdentifier(),
profileOwner);
mDevicePolicyEngine.setLocalPolicy(
PolicyDefinition.SCREEN_CAPTURE_DISABLED,
enforcingAdmin,
new BooleanPolicyValue(true),
profileOwner.getUserHandle().getIdentifier());
}
}
});
}
private void migratePermittedInputMethodsPolicyLocked() {
Binder.withCleanCallingIdentity(() -> {
List<UserInfo> users = mUserManager.getUsers();
for (UserInfo userInfo : users) {
ActiveAdmin admin = getProfileOwnerOrDeviceOwnerLocked(userInfo.id);
if (admin != null) {
EnforcingAdmin enforcingAdmin = EnforcingAdmin.createEnterpriseEnforcingAdmin(
admin.info.getComponent(),
admin.getUserHandle().getIdentifier(),
admin);
if (admin.permittedInputMethods != null) {
mDevicePolicyEngine.setLocalPolicy(
PolicyDefinition.PERMITTED_INPUT_METHODS,
enforcingAdmin,
new StringSetPolicyValue(
new HashSet<>(admin.permittedInputMethods)),
admin.getUserHandle().getIdentifier());
}
if (admin.getParentActiveAdmin() != null
&& admin.getParentActiveAdmin().permittedInputMethods != null) {
mDevicePolicyEngine.setLocalPolicy(
PolicyDefinition.PERMITTED_INPUT_METHODS,
enforcingAdmin,
new StringSetPolicyValue(
new HashSet<>(admin.getParentActiveAdmin()
.permittedInputMethods)),
getProfileParentId(admin.getUserHandle().getIdentifier()));
}
}
}
});
}
private void migrateAccountManagementDisabledPolicyLocked() {
Binder.withCleanCallingIdentity(() -> {
List<UserInfo> users = mUserManager.getUsers();
for (UserInfo userInfo : users) {
ActiveAdmin admin = getProfileOwnerOrDeviceOwnerLocked(userInfo.id);
if (admin != null) {
EnforcingAdmin enforcingAdmin = EnforcingAdmin.createEnterpriseEnforcingAdmin(
admin.info.getComponent(),
admin.getUserHandle().getIdentifier(),
admin);
for (String accountType : admin.accountTypesWithManagementDisabled) {
mDevicePolicyEngine.setLocalPolicy(
PolicyDefinition.ACCOUNT_MANAGEMENT_DISABLED(accountType),
enforcingAdmin,
new BooleanPolicyValue(true),
admin.getUserHandle().getIdentifier());
}
if (admin.getParentActiveAdmin() != null) {
for (String accountType : admin.getParentActiveAdmin()
.accountTypesWithManagementDisabled) {
mDevicePolicyEngine.setLocalPolicy(
PolicyDefinition.ACCOUNT_MANAGEMENT_DISABLED(accountType),
enforcingAdmin,
new BooleanPolicyValue(true),
getProfileParentId(admin.getUserHandle().getIdentifier()));
}
}
}
}
});
}
private void migrateUserControlDisabledPackagesLocked() {
Binder.withCleanCallingIdentity(() -> {
List<UserInfo> users = mUserManager.getUsers();
for (UserInfo userInfo : users) {
ActiveAdmin admin = getProfileOwnerOrDeviceOwnerLocked(userInfo.id);
if (admin != null && admin.protectedPackages != null) {
EnforcingAdmin enforcingAdmin = EnforcingAdmin.createEnterpriseEnforcingAdmin(
admin.info.getComponent(),
admin.getUserHandle().getIdentifier(),
admin);
if (isDeviceOwner(admin)) {
mDevicePolicyEngine.setGlobalPolicy(
PolicyDefinition.USER_CONTROLLED_DISABLED_PACKAGES,
enforcingAdmin,
new StringSetPolicyValue(new HashSet<>(admin.protectedPackages)));
} else {
mDevicePolicyEngine.setLocalPolicy(
PolicyDefinition.USER_CONTROLLED_DISABLED_PACKAGES,
enforcingAdmin,
new StringSetPolicyValue(new HashSet<>(admin.protectedPackages)),
admin.getUserHandle().getIdentifier());
}
}
}
});
}
private List<PackageInfo> getInstalledPackagesOnUser(int userId) { private List<PackageInfo> getInstalledPackagesOnUser(int userId) {
return mInjector.binderWithCleanCallingIdentity(() -> return mInjector.binderWithCleanCallingIdentity(() ->
mContext.getPackageManager().getInstalledPackagesAsUser( mContext.getPackageManager().getInstalledPackagesAsUser(