* changes:
locksettings: miscellaneous logging cleanups
locksettings: improve logging of SP and protector changes
locksettings: improve logging of LSKF verification
locksettings: clean up logging of cached GK password expiration
locksettings: clean up logging of password history updates
locksettings: clean up logging of escrow token operations
locksettings: only log profile key removal when actually done
locksettings: only log FRP migration when actually done
locksettings: move credentialTypeToString to LockPatternUtils
locksettings: zero-pad IDs when shown as hex
The TODO in the doc comment was ending up in the published docs. Moved it to a separate, non-doc comment (// instead of /** */) so the doc engine will ignore it.
NO_TEST , fixes a doc bug (no code edits).
Change-Id: Ifbefc2cccef8fac5887184c017fbe6bc6a4a8e30
Fixes: 270366001
Test: [go/abtd docs build]
Clean up a few log messages that didn't fit into any of the previous
changes. This includes removing the last uses of the DEBUG field.
Bug: 268526331
Change-Id: Iee462825434c5a5042e1ddc4dfbb95579d339d40
Merged-In: Iee462825434c5a5042e1ddc4dfbb95579d339d40
(cherry picked from commit 50e8789519)
Improve the logging for synthetic password protectors being created and
deleted, and the synthetic password itself being created. This includes
the case where a user's LSKF is being changed.
These are infrequent and important operations, so generally we should
error on the side of being verbose for them.
Bug: 268526331
Change-Id: I9cd91ecd3bb80b59fb367072d7f30dc90a5ee332
Merged-In: I9cd91ecd3bb80b59fb367072d7f30dc90a5ee332
(cherry picked from commit 72ba837864)
Improve the logging related to verifying the LSKF.
We generally don't want to be super verbose here, but it does make sense
to have an INFO message at the beginning and end. There was already a
DEBUG message at the beginning and an INFO message near the end, but
they were unclear, so replace them with clearer INFO messages.
Bug: 268526331
Change-Id: Iaccbbd0d5a297bf97ff6ef31630eeec19fe3277b
Merged-In: Iaccbbd0d5a297bf97ff6ef31630eeec19fe3277b
(cherry picked from commit 18045f36e8)
When a cached GK password expires, use a much clearer log message.
Also, don't log anything if the GK password was already explicitly
removed by LockSettingsService.removeGatekeeperPasswordHandle().
Bug: 268526331
Change-Id: I734c9115bd8ea0a44ed6c03754e87341848a00f5
Merged-In: I734c9115bd8ea0a44ed6c03754e87341848a00f5
(cherry picked from commit 070e3d6ce3)
Currently the logging for password history updates consists only of the
message "Initialized lock password salt for user". But that's only
logged on the first update, and it's unclear that it's related to the
password history. Let's replace it with a clearer message that is
logged whenever a password is added to the password history.
This doesn't change anything for the case where password history is
disabled, which is the default setting.
Bug: 268526331
Change-Id: Ibe6f679a17b887261711e0fd7da1b62a114ce7e6
Merged-In: Ibe6f679a17b887261711e0fd7da1b62a114ce7e6
(cherry picked from commit 61729d86ba)
Currently "Disabling escrow token on user" is logged *every time* a
user's lockscreen credential is verified, if the user is not eligible
for escrow tokens. Let's instead make
disableEscrowTokenOnNonManagedDevicesIfNeeded() return early if the user
has no escrow data, so it will only log if it does something.
At the same time, be more verbose when something is actually done
related to escrow tokens, as these are generally exceptional events.
Bug: 268526331
Change-Id: I83cd783572d33954b95c9d7bb58916e75459809e
Merged-In: I83cd783572d33954b95c9d7bb58916e75459809e
(cherry picked from commit 57688444a0)
The message "Remove keystore profile key for user" is always being
logged at INFO level when a user's locksettings state is removed.
However, that step is only applicable for profiles, so usually it's
irrelevant and is a no-op.
It could serve as a hint that the user's locksettings state is being
removed. However, there's already a proper log message for that.
So, let's first check whether the user actually has a profile key,
before attempting to remove it and logging that removal.
Bug: 268526331
Change-Id: I90f46bc4cf5bfe096b0b037c5b88a9a9be2dcdd6
Merged-In: I90f46bc4cf5bfe096b0b037c5b88a9a9be2dcdd6
(cherry picked from commit deb0af0095)
Instead of logging "Migrated migrated_frp" when the FRP credential
migration is considered, which effectively means whenever the device
boots up for the first time (regardless of whether the migration
actually needed to be done or not), let's only log if the FRP credential
migration is actually being done. Also make the message clearer.
Bug: 268526331
Change-Id: I8a46c90902da982eb684e49fb4afee19387621c3
Merged-In: I8a46c90902da982eb684e49fb4afee19387621c3
(cherry picked from commit 0b76af4d82)
In preparation for using credentialTypeToString() from more places, move
it to LockPatternUtils. Also change the strings returned to all
upper-case, as this looks better in the contexts where it will be used.
Bug: 268526331
Change-Id: Ic9ef28321bca793161182730d11a818378f8ab19
Merged-In: Ic9ef28321bca793161182730d11a818378f8ab19
(cherry picked from commit cacb0f37f6)
When printing a 'long' ID as hex, use %016x instead of %x so that the
width is always consistent, not shorter 1/16 of the time. This also
matches the way the synthetic password state files are named.
Bug: 268526331
Change-Id: I999606ff0d6a19641f32c4f4826476b4a839ad59
Merged-In: I999606ff0d6a19641f32c4f4826476b4a839ad59
(cherry picked from commit cec56be0ad)
Remove scaling with DisplayMetrics obtain from system context, which can
be outdated. Also added check to guarantee that
default_minimal_size_resizable_task is in dp unit.
Bug: 270393438
Test: passes local atest
Change-Id: I1ad4cb7d2d44cce8de9a3d9acb074671549f777a
Before, the surface1 color was only applied to the top card which left
the bottom corner color incorrect.
Bug: 271168041
Test: manual (see bug for screenshot)
Change-Id: Ic2b7f3b13563955e39b00611ba1a4b04aeac721c