Merge "Allow DO to access DevicePolicyManager.isDeviceManaged()"

This commit is contained in:
TreeHugger Robot
2016-11-30 13:35:33 +00:00
committed by Android (Google) Code Review
6 changed files with 46 additions and 3 deletions

View File

@@ -6250,6 +6250,7 @@ package android.app.admin {
method public boolean isAdminActive(android.content.ComponentName);
method public boolean isApplicationHidden(android.content.ComponentName, java.lang.String);
method public boolean isCallerApplicationRestrictionsManagingPackage();
method public boolean isDeviceManaged();
method public boolean isDeviceOwnerApp(java.lang.String);
method public boolean isLockTaskPermitted(java.lang.String);
method public boolean isManagedProfile(android.content.ComponentName);

View File

@@ -6089,6 +6089,7 @@ package android.app.admin {
method public boolean isAdminActive(android.content.ComponentName);
method public boolean isApplicationHidden(android.content.ComponentName, java.lang.String);
method public boolean isCallerApplicationRestrictionsManagingPackage();
method public boolean isDeviceManaged();
method public boolean isDeviceOwnerApp(java.lang.String);
method public boolean isLockTaskPermitted(java.lang.String);
method public boolean isManagedProfile(android.content.ComponentName);

View File

@@ -3844,14 +3844,22 @@ public class DevicePolicyManager {
}
/**
* @return true if the device is managed by any device owner.
* Called by the system to find out whether the device is managed by a Device Owner.
*
* <p>Requires the MANAGE_USERS permission.
* @return whether the device is managed by a Device Owner.
* @throws SecurityException if the caller is not the device owner, does not hold the
* MANAGE_USERS permission and is not the system.
*
* @hide
*/
@SystemApi
@TestApi
public boolean isDeviceManaged() {
return getDeviceOwnerComponentOnAnyUser() != null;
try {
return mService.hasDeviceOwner();
} catch (RemoteException re) {
throw re.rethrowFromSystemServer();
}
}
/**

View File

@@ -132,6 +132,7 @@ interface IDevicePolicyManager {
boolean setDeviceOwner(in ComponentName who, String ownerName, int userId);
ComponentName getDeviceOwnerComponent(boolean callingUserOnly);
boolean hasDeviceOwner();
String getDeviceOwnerName();
void clearDeviceOwner(String packageName);
int getDeviceOwnerUserId();

View File

@@ -5979,6 +5979,12 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub {
}
}
@Override
public boolean hasDeviceOwner() {
enforceDeviceOwnerOrManageUsers();
return mOwners.hasDeviceOwner();
}
boolean isDeviceOwner(ActiveAdmin admin) {
return isDeviceOwner(admin.info.getComponent(), admin.getUserHandle().getIdentifier());
}

View File

@@ -2506,6 +2506,32 @@ public class DevicePolicyManagerTest extends DpmTestBase {
MoreAsserts.assertEmpty(targetUsers);
}
public void testIsDeviceManaged() throws Exception {
mContext.binder.callingUid = DpmMockContext.CALLER_SYSTEM_USER_UID;
setupDeviceOwner();
// The device owner itself, any uid holding MANAGE_USERS permission and the system can
// find out that the device has a device owner.
assertTrue(dpm.isDeviceManaged());
mContext.binder.callingUid = 1234567;
mContext.callerPermissions.add(permission.MANAGE_USERS);
assertTrue(dpm.isDeviceManaged());
mContext.callerPermissions.remove(permission.MANAGE_USERS);
mContext.binder.clearCallingIdentity();
assertTrue(dpm.isDeviceManaged());
clearDeviceOwner();
// Any uid holding MANAGE_USERS permission and the system can find out that the device does
// not have a device owner.
mContext.binder.callingUid = 1234567;
mContext.callerPermissions.add(permission.MANAGE_USERS);
assertFalse(dpm.isDeviceManaged());
mContext.callerPermissions.remove(permission.MANAGE_USERS);
mContext.binder.clearCallingIdentity();
assertFalse(dpm.isDeviceManaged());
}
private void setUserSetupCompleteForUser(boolean isUserSetupComplete, int userhandle) {
when(mContext.settings.settingsSecureGetIntForUser(Settings.Secure.USER_SETUP_COMPLETE, 0,
userhandle)).thenReturn(isUserSetupComplete ? 1 : 0);