Merge "migrate keyguard disabled features" into udc-dev

This commit is contained in:
Kholoud Mohamed
2023-04-03 12:42:03 +00:00
committed by Android (Google) Code Review
2 changed files with 90 additions and 27 deletions

View File

@@ -9193,34 +9193,53 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
Objects.requireNonNull(who, "ComponentName is null"); Objects.requireNonNull(who, "ComponentName is null");
} }
final int userHandle = caller.getUserId(); final int userHandle = caller.getUserId();
int affectedUserId = parent ? getProfileParentId(userHandle) : userHandle; int affectedUserId = parent ? getProfileParentId(userHandle) : userHandle;
synchronized (getLockObject()) { synchronized (getLockObject()) {
ActiveAdmin ap; if (useDevicePolicyEngine(caller, /* delegateScope= */ null)) {
if (isPermissionCheckFlagEnabled()) {
// SUPPORT USES_POLICY_DISABLE_KEYGUARD_FEATURES // SUPPORT USES_POLICY_DISABLE_KEYGUARD_FEATURES
ap = enforcePermissionAndGetEnforcingAdmin( EnforcingAdmin admin = enforcePermissionAndGetEnforcingAdmin(
who, MANAGE_DEVICE_POLICY_KEYGUARD, caller.getPackageName(), who, MANAGE_DEVICE_POLICY_KEYGUARD, caller.getPackageName(),
affectedUserId).getActiveAdmin(); affectedUserId);
} else { if (which == 0) {
ap = getActiveAdminForCallerLocked( mDevicePolicyEngine.removeLocalPolicy(
who, DeviceAdminInfo.USES_POLICY_DISABLE_KEYGUARD_FEATURES, parent); PolicyDefinition.KEYGUARD_DISABLED_FEATURES, admin, affectedUserId);
}
if (isManagedProfile(userHandle)) {
if (parent) {
if (isProfileOwnerOfOrganizationOwnedDevice(caller)) {
which = which & PROFILE_KEYGUARD_FEATURES_AFFECT_OWNER;
} else {
which = which & NON_ORG_OWNED_PROFILE_KEYGUARD_FEATURES_AFFECT_OWNER;
}
} else { } else {
which = which & PROFILE_KEYGUARD_FEATURES; // TODO(b/273723433): revisit silent masking of features
if (isManagedProfile(userHandle)) {
if (parent) {
if (isProfileOwnerOfOrganizationOwnedDevice(caller)) {
which = which & PROFILE_KEYGUARD_FEATURES_AFFECT_OWNER;
} else {
which = which
& NON_ORG_OWNED_PROFILE_KEYGUARD_FEATURES_AFFECT_OWNER;
}
} else {
which = which & PROFILE_KEYGUARD_FEATURES;
}
}
mDevicePolicyEngine.setLocalPolicy(PolicyDefinition.KEYGUARD_DISABLED_FEATURES,
admin, new IntegerPolicyValue(which), affectedUserId);
}
invalidateBinderCaches();
} else {
ActiveAdmin ap = getActiveAdminForCallerLocked(
who, DeviceAdminInfo.USES_POLICY_DISABLE_KEYGUARD_FEATURES, parent);
if (isManagedProfile(userHandle)) {
if (parent) {
if (isProfileOwnerOfOrganizationOwnedDevice(caller)) {
which = which & PROFILE_KEYGUARD_FEATURES_AFFECT_OWNER;
} else {
which = which & NON_ORG_OWNED_PROFILE_KEYGUARD_FEATURES_AFFECT_OWNER;
}
} else {
which = which & PROFILE_KEYGUARD_FEATURES;
}
}
if (ap.disabledKeyguardFeatures != which) {
ap.disabledKeyguardFeatures = which;
saveSettingsLocked(userHandle);
} }
}
if (ap.disabledKeyguardFeatures != which) {
ap.disabledKeyguardFeatures = which;
saveSettingsLocked(userHandle);
} }
} }
if (SecurityLog.isLoggingEnabled()) { if (SecurityLog.isLoggingEnabled()) {
@@ -9252,15 +9271,51 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
Preconditions.checkCallAuthorization( Preconditions.checkCallAuthorization(
who == null || isCallingFromPackage(who.getPackageName(), caller.getUid()) who == null || isCallingFromPackage(who.getPackageName(), caller.getUid())
|| isSystemUid(caller)); || isSystemUid(caller));
int affectedUserId = parent ? getProfileParentId(userHandle) : userHandle;
final long ident = mInjector.binderClearCallingIdentity(); synchronized (getLockObject()) {
try { if (who != null) {
synchronized (getLockObject()) { if (useDevicePolicyEngine(caller, /* delegateScope= */ null)) {
if (who != null) { EnforcingAdmin admin = getEnforcingAdminForCaller(
who, who.getPackageName());
Integer features = mDevicePolicyEngine.getLocalPolicySetByAdmin(
PolicyDefinition.KEYGUARD_DISABLED_FEATURES,
admin,
affectedUserId);
return features == null ? 0 : features;
} else {
ActiveAdmin admin = getActiveAdminUncheckedLocked(who, userHandle, parent); ActiveAdmin admin = getActiveAdminUncheckedLocked(who, userHandle, parent);
return (admin != null) ? admin.disabledKeyguardFeatures : 0; return (admin != null) ? admin.disabledKeyguardFeatures : 0;
} }
}
if (useDevicePolicyEngine(caller, /* delegateScope= */ null)) {
Integer features = mDevicePolicyEngine.getResolvedPolicy(
PolicyDefinition.KEYGUARD_DISABLED_FEATURES,
affectedUserId);
return Binder.withCleanCallingIdentity(() -> {
int combinedFeatures = features == null ? 0 : features;
List<UserInfo> profiles = mUserManager.getProfiles(affectedUserId);
for (UserInfo profile : profiles) {
int profileId = profile.id;
if (profileId == affectedUserId) {
continue;
}
Integer profileFeatures = mDevicePolicyEngine.getResolvedPolicy(
PolicyDefinition.KEYGUARD_DISABLED_FEATURES,
profileId);
if (profileFeatures != null) {
combinedFeatures |= (profileFeatures
& PROFILE_KEYGUARD_FEATURES_AFFECT_OWNER);
}
}
return combinedFeatures;
});
}
final long ident = mInjector.binderClearCallingIdentity();
try {
final List<ActiveAdmin> admins; final List<ActiveAdmin> admins;
if (!parent && isManagedProfile(userHandle)) { if (!parent && isManagedProfile(userHandle)) {
// If we are being asked about a managed profile, just return keyguard features // If we are being asked about a managed profile, just return keyguard features
@@ -9290,9 +9345,9 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
} }
} }
return which; return which;
} finally {
mInjector.binderRestoreCallingIdentity(ident);
} }
} finally {
mInjector.binderRestoreCallingIdentity(ident);
} }
} }

View File

@@ -246,6 +246,14 @@ final class PolicyDefinition<V> {
(Long value, Context context, Integer userId, PolicyKey policyKey) -> true, (Long value, Context context, Integer userId, PolicyKey policyKey) -> true,
new LongPolicySerializer()); new LongPolicySerializer());
static PolicyDefinition<Integer> KEYGUARD_DISABLED_FEATURES = new PolicyDefinition<>(
new NoArgsPolicyKey(DevicePolicyIdentifiers.KEYGUARD_DISABLED_FEATURES_POLICY),
new FlagUnion(),
POLICY_FLAG_LOCAL_ONLY_POLICY,
// Nothing is enforced for keyguard features, we just need to store it
(Integer value, Context context, Integer userId, PolicyKey policyKey) -> true,
new IntegerPolicySerializer());
private static final Map<String, PolicyDefinition<?>> POLICY_DEFINITIONS = new HashMap<>(); private static final Map<String, PolicyDefinition<?>> POLICY_DEFINITIONS = new HashMap<>();
private static Map<String, Integer> USER_RESTRICTION_FLAGS = new HashMap<>(); private static Map<String, Integer> USER_RESTRICTION_FLAGS = new HashMap<>();