Merge "Reset fingerprint lockout timer when strong auth is used." into mnc-dr-dev

This commit is contained in:
Jim Miller
2015-08-18 23:12:18 +00:00
committed by Android (Google) Code Review
6 changed files with 42 additions and 0 deletions

View File

@@ -668,6 +668,25 @@ public class FingerprintManager {
return 0; return 0;
} }
/**
* Reset the lockout timer when asked to do so by keyguard.
*
* @param token an opaque token returned by password confirmation.
*
* @hide
*/
public void resetTimeout(byte[] token) {
if (mService != null) {
try {
mService.resetTimeout(token);
} catch (RemoteException e) {
Log.v(TAG, "Remote exception in getAuthenticatorId(): ", e);
}
} else {
Log.w(TAG, "getAuthenticatorId(): Service not connected!");
}
}
private class MyHandler extends Handler { private class MyHandler extends Handler {
private MyHandler(Context context) { private MyHandler(Context context) {
super(context.getMainLooper()); super(context.getMainLooper());
@@ -677,6 +696,7 @@ public class FingerprintManager {
super(looper); super(looper);
} }
@Override
public void handleMessage(android.os.Message msg) { public void handleMessage(android.os.Message msg) {
switch(msg.what) { switch(msg.what) {
case MSG_ENROLL_RESULT: case MSG_ENROLL_RESULT:

View File

@@ -68,4 +68,7 @@ interface IFingerprintService {
// Gets the authenticator ID for fingerprint // Gets the authenticator ID for fingerprint
long getAuthenticatorId(String opPackageName); long getAuthenticatorId(String opPackageName);
// Reset the timeout when user authenticates with strong auth (e.g. PIN, pattern or password)
void resetTimeout(in byte [] cryptoToken);
} }

View File

@@ -2465,6 +2465,10 @@
<permission android:name="android.permission.MANAGE_FINGERPRINT" <permission android:name="android.permission.MANAGE_FINGERPRINT"
android:protectionLevel="system|signature" /> android:protectionLevel="system|signature" />
<!-- Allows an app to reset fingerprint attempt counter. Reserved for the system. @hide -->
<permission android:name="android.permission.RESET_FINGERPRINT_LOCKOUT"
android:protectionLevel="signature" />
<!-- Allows an application to control keyguard. Only allowed for system processes. <!-- Allows an application to control keyguard. Only allowed for system processes.
@hide --> @hide -->
<permission android:name="android.permission.CONTROL_KEYGUARD" <permission android:name="android.permission.CONTROL_KEYGUARD"

View File

@@ -578,6 +578,10 @@ public class KeyguardUpdateMonitor implements TrustManager.TrustListener {
public void reportSuccessfulStrongAuthUnlockAttempt() { public void reportSuccessfulStrongAuthUnlockAttempt() {
mStrongAuthTimedOut.remove(sCurrentUser); mStrongAuthTimedOut.remove(sCurrentUser);
scheduleStrongAuthTimeout(); scheduleStrongAuthTimeout();
if (mFpm != null) {
byte[] token = null; /* TODO: pass real auth token once fp HAL supports it */
mFpm.resetTimeout(token);
}
} }
private void scheduleStrongAuthTimeout() { private void scheduleStrongAuthTimeout() {

View File

@@ -108,6 +108,7 @@
<uses-permission android:name="android.permission.ACCESS_KEYGUARD_SECURE_STORAGE" /> <uses-permission android:name="android.permission.ACCESS_KEYGUARD_SECURE_STORAGE" />
<uses-permission android:name="android.permission.TRUST_LISTENER" /> <uses-permission android:name="android.permission.TRUST_LISTENER" />
<uses-permission android:name="android.permission.USE_FINGERPRINT" /> <uses-permission android:name="android.permission.USE_FINGERPRINT" />
<uses-permission android:name="android.permission.RESET_FINGERPRINT_LOCKOUT" />
<!-- Needed for WallpaperManager.clear in ImageWallpaper.updateWallpaperLocked --> <!-- Needed for WallpaperManager.clear in ImageWallpaper.updateWallpaperLocked -->
<uses-permission android:name="android.permission.SET_WALLPAPER"/> <uses-permission android:name="android.permission.SET_WALLPAPER"/>

View File

@@ -54,6 +54,7 @@ import android.hardware.fingerprint.IFingerprintServiceReceiver;
import android.view.Display; import android.view.Display;
import static android.Manifest.permission.MANAGE_FINGERPRINT; import static android.Manifest.permission.MANAGE_FINGERPRINT;
import static android.Manifest.permission.RESET_FINGERPRINT_LOCKOUT;
import static android.Manifest.permission.USE_FINGERPRINT; import static android.Manifest.permission.USE_FINGERPRINT;
import java.io.File; import java.io.File;
@@ -255,6 +256,9 @@ public class FingerprintService extends SystemService implements IBinder.DeathRe
Slog.v(TAG, "Reset fingerprint lockout"); Slog.v(TAG, "Reset fingerprint lockout");
} }
mFailedAttempts = 0; mFailedAttempts = 0;
// If we're asked to reset failed attempts externally (i.e. from Keyguard), the runnable
// may still be in the queue; remove it.
mHandler.removeCallbacks(mLockoutReset);
} }
private boolean handleFailedAttempt(ClientMonitor clientMonitor) { private boolean handleFailedAttempt(ClientMonitor clientMonitor) {
@@ -878,6 +882,12 @@ public class FingerprintService extends SystemService implements IBinder.DeathRe
Binder.restoreCallingIdentity(ident); Binder.restoreCallingIdentity(ident);
} }
} }
@Override // Binder call
public void resetTimeout(byte [] token) {
checkPermission(RESET_FINGERPRINT_LOCKOUT);
// TODO: confirm security token when we move timeout management into the HAL layer.
mLockoutReset.run();
}
} }
private void dumpInternal(PrintWriter pw) { private void dumpInternal(PrintWriter pw) {