Merge "Only disable trust agents after lockout" into nyc-mr1-dev
This commit is contained in:
committed by
Android (Google) Code Review
commit
f6487b63a1
@@ -288,7 +288,6 @@ public class LockPatternUtils {
|
|||||||
public void reportFailedPasswordAttempt(int userId) {
|
public void reportFailedPasswordAttempt(int userId) {
|
||||||
getDevicePolicyManager().reportFailedPasswordAttempt(userId);
|
getDevicePolicyManager().reportFailedPasswordAttempt(userId);
|
||||||
getTrustManager().reportUnlockAttempt(false /* authenticated */, userId);
|
getTrustManager().reportUnlockAttempt(false /* authenticated */, userId);
|
||||||
requireStrongAuth(StrongAuthTracker.SOME_AUTH_REQUIRED_AFTER_WRONG_CREDENTIAL, userId);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
public void reportSuccessfulPasswordAttempt(int userId) {
|
public void reportSuccessfulPasswordAttempt(int userId) {
|
||||||
@@ -1544,7 +1543,8 @@ public class LockPatternUtils {
|
|||||||
value = { STRONG_AUTH_NOT_REQUIRED,
|
value = { STRONG_AUTH_NOT_REQUIRED,
|
||||||
STRONG_AUTH_REQUIRED_AFTER_BOOT,
|
STRONG_AUTH_REQUIRED_AFTER_BOOT,
|
||||||
STRONG_AUTH_REQUIRED_AFTER_DPM_LOCK_NOW,
|
STRONG_AUTH_REQUIRED_AFTER_DPM_LOCK_NOW,
|
||||||
SOME_AUTH_REQUIRED_AFTER_USER_REQUEST})
|
SOME_AUTH_REQUIRED_AFTER_USER_REQUEST,
|
||||||
|
STRONG_AUTH_REQUIRED_AFTER_LOCKOUT})
|
||||||
@Retention(RetentionPolicy.SOURCE)
|
@Retention(RetentionPolicy.SOURCE)
|
||||||
public @interface StrongAuthFlags {}
|
public @interface StrongAuthFlags {}
|
||||||
|
|
||||||
@@ -1575,13 +1575,12 @@ public class LockPatternUtils {
|
|||||||
public static final int STRONG_AUTH_REQUIRED_AFTER_LOCKOUT = 0x8;
|
public static final int STRONG_AUTH_REQUIRED_AFTER_LOCKOUT = 0x8;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Some authentication is required because the user has entered a wrong credential.
|
* Strong auth flags that do not prevent fingerprint from being accepted as auth.
|
||||||
|
*
|
||||||
|
* If any other flags are set, fingerprint is disabled.
|
||||||
*/
|
*/
|
||||||
public static final int SOME_AUTH_REQUIRED_AFTER_WRONG_CREDENTIAL = 0x10;
|
|
||||||
|
|
||||||
private static final int ALLOWING_FINGERPRINT = STRONG_AUTH_NOT_REQUIRED
|
private static final int ALLOWING_FINGERPRINT = STRONG_AUTH_NOT_REQUIRED
|
||||||
| SOME_AUTH_REQUIRED_AFTER_USER_REQUEST
|
| SOME_AUTH_REQUIRED_AFTER_USER_REQUEST;
|
||||||
| SOME_AUTH_REQUIRED_AFTER_WRONG_CREDENTIAL;
|
|
||||||
|
|
||||||
private final SparseIntArray mStrongAuthRequiredForUser = new SparseIntArray();
|
private final SparseIntArray mStrongAuthRequiredForUser = new SparseIntArray();
|
||||||
private final H mHandler;
|
private final H mHandler;
|
||||||
|
|||||||
@@ -48,11 +48,6 @@ public interface KeyguardSecurityView {
|
|||||||
*/
|
*/
|
||||||
int PROMPT_REASON_AFTER_LOCKOUT = 5;
|
int PROMPT_REASON_AFTER_LOCKOUT = 5;
|
||||||
|
|
||||||
/**
|
|
||||||
* Some auth is required because a single wrong credential has been tried.
|
|
||||||
*/
|
|
||||||
int PROMPT_REASON_WRONG_CREDENTIAL = 6;
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Interface back to keyguard to tell it when security
|
* Interface back to keyguard to tell it when security
|
||||||
* @param callback
|
* @param callback
|
||||||
|
|||||||
@@ -86,7 +86,6 @@ import java.util.List;
|
|||||||
|
|
||||||
import static android.provider.Settings.System.SCREEN_OFF_TIMEOUT;
|
import static android.provider.Settings.System.SCREEN_OFF_TIMEOUT;
|
||||||
import static com.android.internal.widget.LockPatternUtils.StrongAuthTracker.SOME_AUTH_REQUIRED_AFTER_USER_REQUEST;
|
import static com.android.internal.widget.LockPatternUtils.StrongAuthTracker.SOME_AUTH_REQUIRED_AFTER_USER_REQUEST;
|
||||||
import static com.android.internal.widget.LockPatternUtils.StrongAuthTracker.SOME_AUTH_REQUIRED_AFTER_WRONG_CREDENTIAL;
|
|
||||||
import static com.android.internal.widget.LockPatternUtils.StrongAuthTracker.STRONG_AUTH_REQUIRED_AFTER_DPM_LOCK_NOW;
|
import static com.android.internal.widget.LockPatternUtils.StrongAuthTracker.STRONG_AUTH_REQUIRED_AFTER_DPM_LOCK_NOW;
|
||||||
import static com.android.internal.widget.LockPatternUtils.StrongAuthTracker.STRONG_AUTH_REQUIRED_AFTER_LOCKOUT;
|
import static com.android.internal.widget.LockPatternUtils.StrongAuthTracker.STRONG_AUTH_REQUIRED_AFTER_LOCKOUT;
|
||||||
|
|
||||||
@@ -614,10 +613,7 @@ public class KeyguardViewMediator extends SystemUI {
|
|||||||
return KeyguardSecurityView.PROMPT_REASON_USER_REQUEST;
|
return KeyguardSecurityView.PROMPT_REASON_USER_REQUEST;
|
||||||
} else if (any && (strongAuth & STRONG_AUTH_REQUIRED_AFTER_LOCKOUT) != 0) {
|
} else if (any && (strongAuth & STRONG_AUTH_REQUIRED_AFTER_LOCKOUT) != 0) {
|
||||||
return KeyguardSecurityView.PROMPT_REASON_AFTER_LOCKOUT;
|
return KeyguardSecurityView.PROMPT_REASON_AFTER_LOCKOUT;
|
||||||
} else if (trust && (strongAuth & SOME_AUTH_REQUIRED_AFTER_WRONG_CREDENTIAL) != 0) {
|
|
||||||
return KeyguardSecurityView.PROMPT_REASON_WRONG_CREDENTIAL;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
return KeyguardSecurityView.PROMPT_REASON_NONE;
|
return KeyguardSecurityView.PROMPT_REASON_NONE;
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -37,6 +37,7 @@ public class TrustArchive {
|
|||||||
private static final int TYPE_AGENT_CONNECTED = 4;
|
private static final int TYPE_AGENT_CONNECTED = 4;
|
||||||
private static final int TYPE_AGENT_STOPPED = 5;
|
private static final int TYPE_AGENT_STOPPED = 5;
|
||||||
private static final int TYPE_MANAGING_TRUST = 6;
|
private static final int TYPE_MANAGING_TRUST = 6;
|
||||||
|
private static final int TYPE_POLICY_CHANGED = 7;
|
||||||
|
|
||||||
private static final int HISTORY_LIMIT = 200;
|
private static final int HISTORY_LIMIT = 200;
|
||||||
|
|
||||||
@@ -99,6 +100,10 @@ public class TrustArchive {
|
|||||||
addEvent(new Event(TYPE_MANAGING_TRUST, userId, agent, null, 0, 0, managing));
|
addEvent(new Event(TYPE_MANAGING_TRUST, userId, agent, null, 0, 0, managing));
|
||||||
}
|
}
|
||||||
|
|
||||||
|
public void logDevicePolicyChanged() {
|
||||||
|
addEvent(new Event(TYPE_POLICY_CHANGED, UserHandle.USER_ALL, null, null, 0, 0, false));
|
||||||
|
}
|
||||||
|
|
||||||
private void addEvent(Event e) {
|
private void addEvent(Event e) {
|
||||||
if (mEvents.size() >= HISTORY_LIMIT) {
|
if (mEvents.size() >= HISTORY_LIMIT) {
|
||||||
mEvents.removeFirst();
|
mEvents.removeFirst();
|
||||||
@@ -112,7 +117,8 @@ public class TrustArchive {
|
|||||||
Iterator<Event> iter = mEvents.descendingIterator();
|
Iterator<Event> iter = mEvents.descendingIterator();
|
||||||
while (iter.hasNext() && count < limit) {
|
while (iter.hasNext() && count < limit) {
|
||||||
Event ev = iter.next();
|
Event ev = iter.next();
|
||||||
if (userId != UserHandle.USER_ALL && userId != ev.userId) {
|
if (userId != UserHandle.USER_ALL && userId != ev.userId
|
||||||
|
&& ev.userId != UserHandle.USER_ALL) {
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -122,11 +128,13 @@ public class TrustArchive {
|
|||||||
if (userId == UserHandle.USER_ALL) {
|
if (userId == UserHandle.USER_ALL) {
|
||||||
writer.print("user="); writer.print(ev.userId); writer.print(", ");
|
writer.print("user="); writer.print(ev.userId); writer.print(", ");
|
||||||
}
|
}
|
||||||
writer.print("agent=");
|
if (ev.agent != null) {
|
||||||
if (duplicateSimpleNames) {
|
writer.print("agent=");
|
||||||
writer.print(ev.agent.flattenToShortString());
|
if (duplicateSimpleNames) {
|
||||||
} else {
|
writer.print(ev.agent.flattenToShortString());
|
||||||
writer.print(getSimpleName(ev.agent));
|
} else {
|
||||||
|
writer.print(getSimpleName(ev.agent));
|
||||||
|
}
|
||||||
}
|
}
|
||||||
switch (ev.type) {
|
switch (ev.type) {
|
||||||
case TYPE_GRANT_TRUST:
|
case TYPE_GRANT_TRUST:
|
||||||
@@ -181,6 +189,8 @@ public class TrustArchive {
|
|||||||
return "AgentStopped";
|
return "AgentStopped";
|
||||||
case TYPE_MANAGING_TRUST:
|
case TYPE_MANAGING_TRUST:
|
||||||
return "ManagingTrust";
|
return "ManagingTrust";
|
||||||
|
case TYPE_POLICY_CHANGED:
|
||||||
|
return "DevicePolicyChanged";
|
||||||
default:
|
default:
|
||||||
return "Unknown(" + type + ")";
|
return "Unknown(" + type + ")";
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -399,12 +399,17 @@ public class TrustManagerService extends SystemService {
|
|||||||
}
|
}
|
||||||
|
|
||||||
void updateDevicePolicyFeatures() {
|
void updateDevicePolicyFeatures() {
|
||||||
|
boolean changed = false;
|
||||||
for (int i = 0; i < mActiveAgents.size(); i++) {
|
for (int i = 0; i < mActiveAgents.size(); i++) {
|
||||||
AgentInfo info = mActiveAgents.valueAt(i);
|
AgentInfo info = mActiveAgents.valueAt(i);
|
||||||
if (info.agent.isConnected()) {
|
if (info.agent.isConnected()) {
|
||||||
info.agent.updateDevicePolicyFeatures();
|
info.agent.updateDevicePolicyFeatures();
|
||||||
|
changed = true;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
if (changed) {
|
||||||
|
mArchive.logDevicePolicyChanged();
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
private void removeAgentsOfPackage(String packageName) {
|
private void removeAgentsOfPackage(String packageName) {
|
||||||
|
|||||||
Reference in New Issue
Block a user