Commit Graph

2020 Commits

Author SHA1 Message Date
Rubin Xu
80f1f86f7a Clear binder identity during network logging notification processing
A regression was introduced by Iab009978c472f843000c1b193de571863fc185bb
which moved some external calls outside a binderClearCallingIdentity block.
Fix it by moving them back.

Bug: 193206826
Test: atest DeviceOwnerTest#testAdminActionBookkeeping
Test: atest DeviceOwnerTest#testNetworkLoggingWithSingleUser
Test: atest DeviceOwnerTest#testNetworkLogging_multipleBatches
Test: atest DeviceOwnerTest#testNetworkLoggingWithTwoUsers
Test: atest DeviceOwnerTest#testNetworkLogging_rebootResetsId
Test: atest OrgOwnedProfileOwnerTest#testNetworkLoggingLogged
Test: atest OrgOwnedProfileOwnerTest#testNetworkLoggingDelegate
Test: atest OrgOwnedProfileOwnerTest#testNetworkLogging
Test: atest DeviceOwnerPlusProfileOwnerTest#testNetworkAndSecurityLoggingAvailableIfAffiliated
Test: atest MixedDeviceOwnerTest#testDelegation
Test: CTSVerifier: Device Owner Tests -> Network Logging U
Change-Id: I6c6420f39f671082137adcf498914dd5ee1374fa
2021-07-13 13:53:19 +01:00
Jimmy Hu
810915add5 Update USB HAL version early
USB API could be used before USB HAL version is updated.
Update USB HAL version early and log it.

Bug: 180711938
Test: USB HAL version updated normally
Signed-off-by: Jimmy Hu <hhhuuu@google.com>
Change-Id: If63c848e9643e9144662f031c981fad16d0a0fd6
2021-07-12 15:54:12 +08:00
TreeHugger Robot
250e7a7dff Merge "Do not hold lock when calling into NotificationManager" into sc-dev 2021-07-05 10:10:04 +00:00
Rubin Xu
9d6ac996ff Do not hold lock when calling into NotificationManager
Small refactor of DevicePolicyManagerService.setNetworkLoggingActiveInternal
to make it call NotificationManager without holding its lock.

Bug: 192435507
Test: enable network logging, check notification is shown.
Change-Id: Iab009978c472f843000c1b193de571863fc185bb
2021-07-01 23:22:59 +01:00
TreeHugger Robot
b8a739355f Merge "Enforce profile password quality policy on unified device lock" into sc-dev 2021-07-01 10:30:59 +00:00
Rubin Xu
f04e1ae05c Enforce profile password quality policy on unified device lock
Effectively revert I59354066dafb02fe1d464fd1ddabf3969a4d0f1b to
allow password quality policy set on the profile DPM instance to
be enforced on device lockscreen provided the device has no
separate work challenge.

Bug: 182561862
Test: atest FrameworksServicesTests:DevicePolicyManagerTest
Test: atest ManagedProfilePasswordTest
Test: atest MixedManagedProfileOwnerTest#testResetPasswordWithToken
Test: Create work profile, set profile password quality policy,
      update device password via Settings and verify policy is applied.

Change-Id: I160997822f57c1da9327fe1a5482f445df8e1094
2021-06-30 13:58:22 +01:00
Rubin Xu
3c0f63ab97 Merge "DPM.isUsbDataSignalingEnabled() callable on unmanaged device" into sc-dev 2021-06-21 15:19:40 +00:00
Rubin Xu
b4fe247823 DPM.isUsbDataSignalingEnabled() callable on unmanaged device
Fix an issue in existing implementation where the API will
throw exception when called on a device without DO or PO: a
slight tweak of semantics such that when the API is called by
a regular app, return the device-wide policy regardless which
user the caller is from.

Bug: 190024751
Test: manual with modifed TestDPC on unmanaged device.
Change-Id: I227d01ec275bc0a074a3789bab194c76fc72b5b8
2021-06-21 13:39:11 +01:00
TreeHugger Robot
9ce47a5ab2 Merge "Revert "More debug for security loggin broadcast"" into sc-dev 2021-06-21 11:23:45 +00:00
Rubin Xu
b372f5062b Revert "More debug for security loggin broadcast"
This reverts commit 25f228087f.

Reason for revert: was temporary logging to investigate 185004808 and caused 191563556

Bug: 191563556
Change-Id: I0939a8e95f096c03fa157354630a9cba1edb59a9
2021-06-21 10:08:07 +00:00
Yan Zhu
38b64a51a5 Merge "Improve restriction for BugreportManagerService for multi-user" into sc-dev 2021-06-19 17:17:08 +00:00
Pavel Grafov
6f5fe9271d Merge "More debug for security loggin broadcast" into sc-dev 2021-06-17 11:04:37 +00:00
Felipe Leme
60ec24eb1e Merge "Split DevicePolicyManagerInternal into DevicePolicyManagerLiteInternal." into sc-dev 2021-06-17 00:03:24 +00:00
Pavel Grafov
25f228087f More debug for security loggin broadcast
Bug: 185004808
Test: atest MixedDeviceOwnerTest#testSecurityLoggingDelegate
Change-Id: I1a56a6384f5cb4e2dcab633f7e3819e4713a4dff
2021-06-16 19:30:48 +01:00
Felipe Leme
43dc489afd Split DevicePolicyManagerInternal into DevicePolicyManagerLiteInternal.
DevicePolicyManagerInternal is not set when the device doesn't have
the device_admin feature, but some methods are still needed in that
scenario (like notifyUnsafeOperationStateChanged() on automotive).

Fixes: 190395562

Test: manual verification
Test: atest FrameworksServicesTests:DevicePolicyManagerTest FrameworksServicesTests:DevicePolicyManagerServiceMigrationTest

Change-Id: I48271b828ff01c4e4f3e0365410a7a745f1b0a1d
2021-06-16 08:57:50 -07:00
Felipe Leme
73471b7634 Fixed wipeData() so it doesn't depend on device_admin.
That method can be called by apps that have the MASTER_CLEAR
permission, even if the device doesn't support device_admin

Test: manual verification using automotive's KitchenSink app
Fixes: 190861794

Change-Id: I97ddb18580593e7b23f8fb55b3346049a2261144
2021-06-15 11:32:22 -07:00
Yan Zhu
421dcbaca5 Improve restriction for BugreportManagerService for multi-user
For provisioned device
- Remove the check for the current user is the same as the primary user
- Check for whether the caller is device owner and the current user is
affiliated with the device

Bug: 185426804
Test: manual test with AAOS build with device owner setup and request
bugreport from TestDPC

Change-Id: I78066979fd54b480433ef9ba5144ca666c601591
2021-06-15 10:21:55 -07:00
arangelov
0ba9c3c5cc Don't remove mainline modules if they declare support in manifest
meta-data

Test: atest OverlayPackagesProviderTest
Fixes: 179653892
Change-Id: Idd324fc04542a9be055c1144e4473c6a716a2e6f
2021-06-14 14:00:07 +00:00
Kholoud Mohamed
58d0a17836 Merge "Fix security vulnerability in DPMS" into sc-dev 2021-06-14 09:11:57 +00:00
Pavel Grafov
c0115519f6 Merge "Don't reset user VPN without reason" into sc-dev 2021-06-10 15:31:04 +00:00
Pavel Grafov
1142e5e8cb Merge "Don't leak AccessibilityManager binder proxy." into sc-dev 2021-06-10 15:16:34 +00:00
kholoud mohamed
342fd83483 Fix security vulnerability in DPMS
Changed DPMS#isPackageAllowedToAccessCalendarForUser to always require
INTERACT_ACROSS_USERS/_FULL permission if called for a different uid
than the calling uid.

Test: atest com.android.server.devicepolicy.DevicePolicyManagerTest
Bug: 187043716
Change-Id: I230bbffbdf97c251c8a40add097b3b4254d39452
2021-06-10 13:49:25 +00:00
Rubin Xu
b9be267361 Merge "Allow any apps to call DPM.isUsbDataSignalingEnabled()" into sc-dev 2021-06-09 15:54:21 +00:00
Pavel Grafov
a3c06bc6bb Don't leak AccessibilityManager binder proxy.
Bug: 190412311
Test: atest MixedDeviceOwnerTest#testPermittedAccessibilityServices
Test: com.android.cts.devicepolicy.OrgOwnedProfileOwnerTest#testPersonalAppsSuspensionNormalApp
Change-Id: I34b0ff5cbf52786e0f0c10f787e2ceddfca1e4e1
2021-06-09 16:31:11 +01:00
Pavel Grafov
d406212ac2 Don't reset user VPN without reason
When DPM.setAlwaysOnVpn is called with package=null, it resets
any VPN configured by the user. With this change it won't happen
anymore: it will only reset VPN configuration if it was previously
configured by the admin.

If an admin actually wants to remove any user configured VPN, they
can enforce DISALLOW_CONFIG_VPN restriction which will remove any
user VPNs and will prevent the user from configuring a new one.

+ Also make sure that when the DPC removes an always-on VPN
configuration, the package loses ability to start VPN until the
user authorizes it again.

Bug: 139823667
Test: atest com.android.server.devicepolicy.DevicePolicyManagerTest
Change-Id: Ia703015b4e8d7eaf156358d7eb000d6f58d32238
2021-06-09 14:22:01 +01:00
Rubin Xu
4d68ae240b Allow any apps to call DPM.isUsbDataSignalingEnabled()
This is to allow 3p apps to query the state of the policy so they
can show appropriate UX to the user in case the app's interaction
with the plugged-in USB devices is  disrupted by the admin policy.

Bug: 190024751
Test: atest FrameworksServicesTests:DevicePolicyManagerTest
Change-Id: I829ff84256e0288b88c11add53da312ee2bc2558
2021-06-09 10:13:21 +01:00
TreeHugger Robot
b6c1884785 Merge "Added missing space on error message." into sc-dev 2021-06-09 03:50:24 +00:00
kholoud mohamed
54dc06ab99 Fix security vulnerability in DPMS
Changed DPMS#getCrossProfileCalendarPackagesForUser to always require
INTERACT_ACROSS_USERS or INTERACT_ACROSS_USERS_FULL.

Bug: 187043444
Test: N/A
Change-Id: I53300bfe2e0481df0d473cc73a85857b5603a45e
2021-06-07 16:05:20 +01:00
Felipe Leme
d58a21f6e0 Added missing space on error message.
Test: manual verification
Bug: 189264297

Change-Id: I4a85e6921f60cb69989d3e0badb0c72b94486f02
2021-06-03 12:44:05 -07:00
Alex Johnston
c65974f14e Merge "Remove requireAutoTime on upgrade" into sc-dev 2021-06-01 08:17:27 +00:00
TreeHugger Robot
0c2d1458f2 Merge "Clear calling identity when accessing isProfileOwner and listAllOwners" into sc-dev 2021-05-27 19:35:49 +00:00
Alex Johnston
a9c51e7fb8 Remove requireAutoTime on upgrade
* In Android 11, setRequireAutoTime was deprecated.
  The user restriction DISALLOW_CONFIG_DATE_TIME
  should be used instead to enforce time policies.
* When removing the DO, requireAutoTime needs to
  be set to false
* When transferring policies from the DO to the
  COPE PO, the user restriction should be used instead
  of requireAutoTime. This is because requireAutoTime
  can never be turned false for the COPE PO

Manual testing steps - Scenario 1
* Flash device with Android Q build and set up
  device in DO mode
* Apply some policies using TestDPC, including requireAutoTime
* Flash device with Android R build and do not wipe
* Replicate issue by checking date time cannot be removed
* Flash device with Android S build and do not wipe
* Verify date time restriction can be removed

Manual testing steps - Scenario 2
* Flash device with Android Q build and set up
  device in DO mode
* Apply some policies using TestDPC, including requireAutoTime
* Flash device with Android S build and do not wipe
* Verify DO restriction has been set on parent admin
* Verify date time restriction can be removed

Bug: 165026695
Test: atest com.android.server.devicepolicy.DevicePolicyManagerTest
      Manual testing
Change-Id: I76344fe2df7475b6411362b4aff806a5cbf053a7
2021-05-27 09:30:07 +01:00
arangelov
522076dec3 Clear calling identity when accessing isProfileOwner and listAllOwners
Last year we added a security fix ag/12968597 to address
b/153995973. Now, some DPM methods require the interact
across users permission, unlike in R. This CL aims to
prevent potential security exceptions in these methods
by clearing their calling identity.

Bug: 182279073
Test: atest DevicePolicyManagerTest
Change-Id: Ie861a7880160563f9613db72e3283edac294a7a1
2021-05-26 14:15:23 +01:00
Rubin Xu
0a551e8a9a Merge "Clear policy cache during DO removal" into sc-dev 2021-05-25 10:47:24 +00:00
Shuo Qian
5fcdcebfd2 Merge "Change default value from true to false for preferential network service enabling" into sc-dev 2021-05-24 17:57:56 +00:00
Rubin Xu
0e9bbf8aae Clear policy cache during DO removal
Remove left-over polices (such as mCanGrantSensorsPermissions)
from the cache so it's not interfering with subsequent test runs

Bug: 187862351
Bug: 184079462
Bug: 183162232
Bug: 183162329
Test: 1. atest MixedDeviceOwnerTest#testGrantOfSensorsRelatedPermissions
      2. atest MixedProfileOwnerTest#testGrantOfSensorsRelatedPermissions
Change-Id: I8551fca161c7df39228587a024f468a496dcdb58
2021-05-24 15:36:53 +01:00
Alex Johnston
68d3b19012 Merge "Add DPMS reset password metrics" into sc-dev 2021-05-24 08:41:13 +00:00
Shuo Qian
63c9e34ae9 Change default value from true to false for preferential network service enabling
Test: atest DevicePolicyManagerTest#testSetGetPreferentialNetworkServiceEnabled;
      atest DevicePolicyManagerTest#testUpdateNetworkPreferenceOnStartUser;
      atest DevicePolicyManagerTest#testUpdateNetworkPreferenceOnStopUser;
      atest MixedManagedProfileOwnerTest#testSetPreferentialNetworkServiceStatusLogged;
      atest MixedManagedProfileOwnerTest#testSetGetPreferentialNetworkServiceStatus

Bug: 187771747
Change-Id: I3c7af4de7fb2c8ed284a27ada9092450e32aeb89
2021-05-21 22:49:43 +00:00
Alex Johnston
e011ffe22a Add DPMS reset password metrics
PDD: https://eldar.corp.google.com/assessments/875507949

RESET_PASSWORD
We log this when the admin forces a new password for the
device or the managed profile.
There is no log data (only the event).

RESET_PASSWORD_WITH_TOKEN
We log this when the admin forces a new password for the
device or the managed profile. The admin can change the
password even before the device is unlocked, as long as the
password reset token was previously provisioned.
There is no log data (only the event).

Bug: 186740337
Test: atest com.android.server.devicepolicy.DevicePolicyManagerTest
      atest com.android.cts.devicepolicy.MixedDeviceOwnerTest#testResetPasswordWithToken
Change-Id: I07b66904e423bc6e1f4bdd4ae44aad0cae6d537b
2021-05-20 08:56:36 +00:00
Alex Johnston
e9614f06c4 Merge "Security logging broadcast work profile" into sc-dev 2021-05-19 16:17:24 +00:00
Rubin Xu
68aa35b03d Merge "Send network & security logging callbacks in foreground" into sc-dev 2021-05-19 15:34:31 +00:00
TreeHugger Robot
cf5b205e9a Merge "Extend set user protected packages for multi-user" into sc-dev 2021-05-19 15:14:39 +00:00
Rubin Xu
372ab606e7 Send network & security logging callbacks in foreground
Send ACTION_NETWORK_LOGS_AVAILABLE and ACTION_SECURITY_LOGS_AVAILABLE
as foreground broadcasts to reduce test time. Updated javadoc on
callbacks in DeviceAdminReceiver and DelegatedAdminReceiver.

Remove obsolete special handling of the two broadcasts above in
sendDeviceOwnerCommand(), now that they are only sent through
sendDeviceOwnerOrProfileOwnerCommand().

Bug: 183066771
Test: atest MixedManagedProfileOwnerTest#testNetworkLogging
Change-Id: I0758c0eb98be43b24cd08105a2449c349cfd4e6d
2021-05-17 15:13:39 +01:00
Alex Johnston
25b2533630 Security logging broadcast work profile
Changes
On an org-owned device with a managed
profile, the security logs available broadcast
should be sent to the work profile user

Manual testing steps
* Set up org-owned device
  with a managed profile
* Enable security logging in
  the work profile
* Force logs using adb
  adb shell dpm force-security-logs
* Verify DeviceAdminReceiver
  receives broadcast

Bug: 170293810
Test: manual testing
      atest com.android.server.devicepolicy.DevicePolicyManagerTest
      atest com.android.cts.devicepolicy.MixedDeviceOwnerTest#testSecurityLoggingWithSingleUser
      atest com.android.cts.devicepolicy.MixedDeviceOwnerTest#testSecurityLoggingEnabledLogged
      atest com.android.cts.devicepolicy.MixedDeviceOwnerTest#testSecurityLoggingWithTwoUsers
      atest com.android.cts.devicepolicy.MixedDeviceOwnerTest#testSecurityLoggingDelegate
      atest com.android.cts.devicepolicy.OrgOwnedProfileOwnerTest#testSecurityLogging
      atest com.android.cts.devicepolicy.OrgOwnedProfileOwnerTest#testSecurityLoggingDelegate
Change-Id: Ia955d6ef6b983fb1ff05dff9e68f8cb8e9b6e9f9
2021-05-14 13:00:57 +00:00
Salud Lemus
46a1dcefb0 Extend set user protected packages for multi-user
The current implementation does not work when the multi-user feature is
enabled because it clears the "globally" protected packages set by the
device owner whenever a new user is created.

Bug: 178500150
Test: atest FrameworksServicesTests:com.android.server.devicepolicy.OwnersTest
Test: atest FrameworksServicesTests:com.android.server.devicepolicy.DevicePolicyManagerTest
Test: Ran the CTS tests that were added

Change-Id: Id04cb9b5b2357b0a0b5090442a39d97405287dbe
2021-05-13 12:02:22 -07:00
Felipe Leme
2deff36974 Changed behavior of DPMS.setLocationEnabled() for automotive.
It should only be ignored when it's called to disable location.

Test: atest com.android.cts.devicepolicy.DeviceOwnerTest#testSetLocationEnabled
Fixes: 186263875

Change-Id: I71a4d91196f15b6e13bc0e87290bc0a9418ef87d
2021-05-12 18:34:12 -07:00
Pavel Grafov
9eb3f1e986 Merge "Clean device-wide policies on COPE PO relinquish" into sc-dev 2021-05-11 15:55:54 +00:00
Pavel Grafov
ea96577017 Clean device-wide policies on COPE PO relinquish
Policies that should be now cleaned up properly:
* setRequiredStrongAuthTimeout
* setScreenCaptureDisabled
* setPersonalAppsSuspended
* setFactoryResetProtectionPolicy
* setSecurityLoggingEnabled
* setConfiguredNetworksLockdownState
* setSystemUpdatePolicy

The cleanup is performed upon receiving ACTION_USER_REMOVED
after policy data is removed.

Bug: 162815601
Test: atest DevicePolicyManagerTest#testWipeDataManagedProfileOnOrganizationOwnedDevice
Test: atest OrgOwnedProfileOwnerTest#testCanRelinquishControlOverDevice
Change-Id: I23434c6e103a558304b6b83b86f9ea2cca5ed36c
2021-05-11 15:29:40 +01:00
kholoud mohamed
158dd8fc09 Allow forceUpdateUserSetupComplete for non system users
Test: atest android.devicepolicy.cts.DevicePolicyManagerTest
Test: atest com.android.server.devicepolicy.DevicePolicyManagerTest
Bug: 183716601
Change-Id: Id2340ac1c6404ac41ca7b5a31c6fbb1577804595
2021-05-11 09:25:20 +01:00
Rubin Xu
f7a6c02cc8 Remove unused isProfileActivePasswordSufficientForParent()
Bug: 182561862
Test: builds
Change-Id: I26d18113862c64c51333f62b81db65e335ccd18c
2021-05-07 11:22:35 +01:00