Commit Graph

2136 Commits

Author SHA1 Message Date
Ayush Sharma
554e19a375 Enforce QUERY_ADMIN_POLICY for getGlobalProxyAdmin
Bug: 206127671
Test: NA
Change-Id: Id4bce828bc69867c9c4d20b991e9e53e8ae385f2
2021-12-21 12:37:54 +00:00
Pavel Grafov
2732b61030 Merge "Ensure no stale data is cached after policy upgrade" 2021-12-20 15:59:48 +00:00
Pavel Grafov
fe8e6b1b95 Merge "Check caller owns admin for per-admin getters." 2021-12-20 15:57:56 +00:00
Pavel Grafov
43622051ca Ensure no stale data is cached after policy upgrade
Bug: 198768109
Test: atest PolicyVersionUpgraderTest#testUpgradePerformedInDpmsCtor
Change-Id: I250dcc030e909e2c22620b5943abbdc7f44e81c8
2021-12-14 19:28:20 +00:00
Pavel Grafov
50f0f94b75 Check caller owns admin for per-admin getters.
Currently some functions allow the caller to check policy
enforced by a particular admin by passing a non-null "who"
argument. This circumvents package visibility rules. There is no
legitimate reason for an 3rd party app to query policies for
arbitrary admins. With this change whenever "who" is not null,
the code will ensure that the admin referenced by "who" is owned
by the caller.

Exception to the above are methods that are also called by
Setting to query policy for a particular admin for policy
transparency. For those methods callers with QUERY_ADMIN_POLICY
permission are allowed to query per-admin policy:
 * getMaximumFailedPasswordsForWipe
 * getMaximumTimeToLock
 * getPasswordQuality

There is no legitimate reason for an 3rd party app to query
policies for arbitrary admins. Code search for
getPasswordHistoryLength and getPasswordMinimum* methods doesn't
return any priviledged usage of these methods inside Android.
getPasswordQuality is used by Settings, hence the system uid is
exempt.

+ removed redundant system or root UID checks when querying
permission.

Bug: 204995407
Test: atest android.devicepolicy.cts.NoAdminLeakingTest
Test: atest android.devicepolicy.cts.ResetPasswordWithTokenTest
Test: atest com.android.cts.devicepolicy.MixedDeviceOwnerTest#testPasswordRequirementsApi
Change-Id: I443ed1f6dcd5e5b161c99dd09a4b2aef9f8ef0a7
2021-12-14 17:18:44 +00:00
Aleks Todorov
0a332deb7d Rename broadcast ACTION_MANAGED_USER_CREATED to ACTION_PROVISIONING_COMPLETED
Also started using it for DPM#provisionFullyManagedDevice and
DPM#createAndProvisionManagedProfile

Bug: 188410712
Bug: 206083853
Test: atest android.devicepolicy.cts.DevicePolicyManagerTest
Change-Id: Ic5bdb2bec16c83671a7e2cc955522b2d8c82ea70
2021-12-14 16:44:46 +00:00
Aleks Todorov
4d001dfc90 Expose DevicePolicyManager provisioning APIs as SystemAPIs
Exposed provisionFullyManagedDevice and createAndProvisionManagedProfile
as SystemAPIs

Bug: 188410712
Bug: 206083853
CTS-Coverage-Bug: 175380793
Test: N/A
Change-Id: I3a035e4d0e20028cbb7a5f175e64395682b1f3b6
2021-12-14 16:44:33 +00:00
kholoud mohamed
8b100eb307 Expose some hidden APIs in DevicePolicyManager as SystemAPIs
Exposed setUserProvisioningState and checkProvisioningPreCondition as
SystemAPIs

Bug: 208634589
Bug: 188410712
Test: atest android.devicepolicy.cts.DevicePolicyManagerTest
Change-Id: I0b186a36793a1fca6066905892131f06454acc71
2021-12-06 22:05:47 +00:00
Pavel Grafov
9ad78eae2e Move policy upgrade to DPMS ctor
Currently upgrade happens on lock settings ready, but by that time
WifiService alredy calls to isCommonCriteriaModeEnabled and this
results in obsolete values left in cache. Moving upgrade to ctor
avoids this issue.

Both old and new upgrade invocations happen during
SystemServer.startOtherServices, while all services on which the upgrade
depends, namely UserManager and PackageManager are started earlier in
SystemServer.startBootstrapServices.

Bug: 198768109
Test: upgrade from Android 11 and check device policy cache
Change-Id: Ie4c17a617bbed176bc87fc598f56ccbc49569009
2021-12-02 15:54:36 +00:00
kholoud mohamed
2f2bf87a6e Add QUERY_ADMIN_POLICY to some DevicePolicyManaged APIs
Allowed holders of QUERY_ADMIN_POLICY to access the following APIs:
* getPermittedAccessibilityServices
* getPermittedInputMethodsForCurrentUser

Test: manual testing
Bug: 188410712
Bug: 205707885
Bug: 206107027
Change-Id: I76b86313cadd23b51d486f76a3e8b52196d23c5f
2021-11-30 17:06:43 +00:00
Wilson Wu
5eb038836a Merge "Add user aware getPermittedInputMethods in DPM" 2021-11-26 01:35:51 +00:00
Wilson Wu
0f8da178c8 Add user aware getPermittedInputMethods in DPM
In order to make on-screen keyboard settings
support tab layout. It's needed to get the
permitted input method list as work profile
user.

Add this @hide API in DevicePolicyManager which
should only be used in system.

This change only add the API first for further
usage, there is no user-facing changes.

Bug: 197707782
Test: atest com.android.server.devicepolicy.DevicePolicyManagerTest
      atest com.android.cts.devicepolicy.OrgOwnedProfileOwnerTest#testPermittedInputMethods
      atest com.android.cts.devicepolicy.OrgOwnedProfileOwnerTest#testPermittedInputMethodsLogged
Change-Id: I8ee9f523d2b25af7bfea2a138dba601f9678b8aa
2021-11-25 14:31:55 +08:00
Adam Bookatz
67639c67e1 Merge "UM.canAddMoreUsers(userType)" 2021-11-24 18:51:14 +00:00
Adam Bookatz
ac0a1235ee UM.canAddMoreUsers(userType)
Introduces an API for whether more users can be added of the given user
type.

Bug: 192577100
Bug: 175795666
Bug: 189937255
Bug: 205100630
Test: atest com.android.server.pm.UserManagerTest#testAddTooManyUsers
Change-Id: I1c705d65d1c083a60fd4e058456dcdc4ffa0fffb
2021-11-23 10:14:29 -08:00
kholoud mohamed
af7fc7b675 Add MANAGE_PROFILE_AND_DEVICE_OWNERS permission to some APIs
Allowed holders of MANAGE_PROFILE_AND_DEVICE_OWNERS to call the following DPM APIs
* isDeviceManaged
* getUserProvisioningState
* isManagedKiosk
* isUnattendedManagedKiosk
* getDeviceOwnerNameOnAnyUser
* getProfileOwnerNameAsUser

Test: N/A
Bug: 188410712
Bug: 205707885
Bug: 206107027
Change-Id: I12cf55bf58004ecd4adb57129f2ac4f9e5e82b42
2021-11-21 14:47:27 +00:00
Jay Wang
8eccfdce16 Revert "Require QUERY_ALL_PACKAGES getDeviceOwnerComponent"
Revert "Add test for isDeviceOwnerApp"

Revert submission 15660377-ayushsha_185896465

Reason for revert: DroidMonitor-triggered revert due to breakage bug http://b/207143396
BUG: 207143396
Reverted Changes:
I774ec2a09:Add test for isDeviceOwnerApp
Ibd611bfe2:Require QUERY_ALL_PACKAGES getDeviceOwnerComponent...

Change-Id: I30a701efefed6eeaf232497019282a7a96ff0424
2021-11-19 23:50:08 +00:00
Ayush Sharma
11b08fc14b Require QUERY_ALL_PACKAGES getDeviceOwnerComponent
Add permission check QUERY_ALL_PACKAGES in API
getDeviceOwnerComponent.

Bug: 185896465
Test: atest DevicePolicyManagerTest#testDeviceOwnerMigration
      atest DevicePolicyManagerTest#testGetDeviceOwnerAdminLocked

Change-Id: Ibd611bfe2b96227a09df81a60c6e2109851c1938
2021-11-19 12:29:55 +00:00
TreeHugger Robot
fbeb7661a5 Merge "Make SAME_MANAGED_ACCOUNT the default policy" 2021-11-16 22:12:50 +00:00
TreeHugger Robot
0b93c3b8d2 Merge "Send the network logging enabled notification to the current user." into sc-v2-dev am: b5827095ca am: e8ae1c959b
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/16244061

Change-Id: I7cad7d419389e1254a36a9008d39e70a313e66d0
2021-11-13 16:59:28 +00:00
TreeHugger Robot
e8ae1c959b Merge "Send the network logging enabled notification to the current user." into sc-v2-dev am: b5827095ca
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/16244061

Change-Id: Icf5498eb7d2ebb89663eec8fa913895066922652
2021-11-13 16:48:06 +00:00
TreeHugger Robot
b5827095ca Merge "Send the network logging enabled notification to the current user." into sc-v2-dev 2021-11-13 16:34:10 +00:00
TreeHugger Robot
0216e279ef Merge "New hidden DPM methods: getLogoutUserId() and clearLogoutUser()." into sc-v2-dev am: b3137b3b86 am: 3740f52ea4
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/16245093

Change-Id: I5e5355fbde455ba76b8c98f64f6414fac3947822
2021-11-13 01:49:54 +00:00
TreeHugger Robot
3740f52ea4 Merge "New hidden DPM methods: getLogoutUserId() and clearLogoutUser()." into sc-v2-dev am: b3137b3b86
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/16245093

Change-Id: I73aded8d5b2f1bd38adba570d2eab4c6d84cdea8
2021-11-13 01:33:32 +00:00
Maurice Lam
231cd85dda Make SAME_MANAGED_ACCOUNT the default policy
Bug: 205850201
Test: Manual
Change-Id: I7e8eebd0305274436cf986535ea96c1d9eb89507
2021-11-12 15:10:26 -08:00
Felipe Leme
3106ae05e2 Send the network logging enabled notification to the current user.
It was sending it to the system user, which wouldn't work on systems
with headless system user.

Test: atest FrameworksServicesTests:DevicePolicyManagerTest
Test: manual verification with TestDpc and CtsVerifier on phone and automotive
Test: adb shell dumpsys device_policy | grep mNetworkLoggingNotificationUserId

Bug: 205190291

Change-Id: I0c060a9d9f1c41f63f9bcebd3c1848963ff12764
2021-11-12 12:11:05 -08:00
Felipe Leme
670c8895be New hidden DPM methods: getLogoutUserId() and clearLogoutUser().
Also fixed how the logout user was cleared after a successful switch.

They will be used by CarSystemUi to end a session.

Test: Manual verification with CtsVerifier and TestDpc on automotive

Bug: 205185521
Bug: 204483021

Change-Id: Ieda0a22625ef705fcd705aedfc2dbf2cf570bf81
2021-11-11 18:14:28 -08:00
Varun Shah
0912451704 Merge "Update deletion conditions for a package's UsageStats." into sc-dev am: 2a14be36ff am: 837f58f7fa am: 41e23753cc
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/16222839

Change-Id: I9a3965fccb3e1b48b0f5ae3b1a46557731a5bd72
2021-11-11 01:54:22 +00:00
Varun Shah
0b0b81f505 Merge "Update deletion conditions for a package's UsageStats." into sc-dev am: 2a14be36ff am: e1a38189da
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/16222839

Change-Id: I10b4e4a641752585cc23ef4a08f25517aa4be791
2021-11-11 01:37:54 +00:00
Varun Shah
41e23753cc Merge "Update deletion conditions for a package's UsageStats." into sc-dev am: 2a14be36ff am: 837f58f7fa
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/16222839

Change-Id: I483fcba4ada48dcb8be415063f101d523def3a8b
2021-11-11 01:37:09 +00:00
Varun Shah
e1a38189da Merge "Update deletion conditions for a package's UsageStats." into sc-dev am: 2a14be36ff
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/16222839

Change-Id: Ic05768dc4213e00f93829ace282fd847dc2e5fed
2021-11-11 01:19:38 +00:00
Varun Shah
837f58f7fa Merge "Update deletion conditions for a package's UsageStats." into sc-dev am: 2a14be36ff
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/16222839

Change-Id: I4eabd7f3cafc5e95399e7265c56c937c04d5992d
2021-11-11 01:18:16 +00:00
Varun Shah
157fbcfbe4 Update deletion conditions for a package's UsageStats.
If a profile owner is defined for a specific user, do not delete usage
stats for a package on package deletion.

Bug: 197399948
Test: atest UserUsageStatsServiceTest
Test: atest UsageStatsTest [all]
Change-Id: I94a8e3dfca8ef4c7616f77944d61726e06043b85
Merged-In: I94a8e3dfca8ef4c7616f77944d61726e06043b85
2021-11-10 17:11:32 +00:00
Varun Shah
9af940970d Update deletion conditions for a package's UsageStats.
If a profile owner is defined for a specific user, do not delete usage
stats for a package on package deletion.

Bug: 197399948
Test: atest UserUsageStatsServiceTest
Test: atest UsageStatsTest [all]
Change-Id: I94a8e3dfca8ef4c7616f77944d61726e06043b85
2021-11-08 17:55:31 -08:00
Michael Groover
4537809559 Merge "Add required flag to registerReceiver call in RemoteBugreportManager" 2021-11-06 00:06:48 +00:00
Michael Groover
f1df584560 Add required flag to registerReceiver call in RemoteBugreportManager
Android T adds support to allow a runtime receiver to be registered as
not exported, but to ensure apps can take advantage of this, calls to
registerReceiver must specify a flag indicating whether the receiver
should be exported for apps targeting T+ that are registering for
unprotected broadcasts. This commit adds the RECEIVER_EXPORTED flag
to the call to registerReceiver in RemoteBugreportManager when
registering for the REMOTE_BUGREPORT_DISPATCH action as this is
broadcast from shell.

Bug: 161145287
Test: Manually verified logcat warning was not reported
Change-Id: I51ef7b5c275c70edd4eaa98132b98315c1e04256
2021-11-05 15:43:37 -07:00
Felipe Leme
75e2021aaf Merge "Disabled some password-related APIs on automotive." into sc-v2-dev am: ef61167cf4 am: 32fb93eaed
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/16150886

Change-Id: I37fd93c9f37569c7ea06ce67c1d4bcb88fb09017
2021-11-05 16:42:32 +00:00
Felipe Leme
32fb93eaed Merge "Disabled some password-related APIs on automotive." into sc-v2-dev am: ef61167cf4
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/16150886

Change-Id: I22ec02083d41e21e65ca851dff509544684b3436
2021-11-05 16:25:50 +00:00
Felipe Leme
087aad751c Merge "Fixed DPM.logoutUser() for headless system user mode." into sc-v2-dev am: f1f95597f0 am: 3ff4835584
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/16145450

Change-Id: I4701554c2145a53d2a6fdd2438462ebf0df48710
2021-11-05 16:17:23 +00:00
Felipe Leme
ef61167cf4 Merge "Disabled some password-related APIs on automotive." into sc-v2-dev 2021-11-05 16:06:13 +00:00
Felipe Leme
3ff4835584 Merge "Fixed DPM.logoutUser() for headless system user mode." into sc-v2-dev am: f1f95597f0
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/16145450

Change-Id: I8a327d7bb4659b67d2ed3365b3640d88d9aee103
2021-11-05 15:59:15 +00:00
Felipe Leme
bc671b859a Fixed DPM.logoutUser() for headless system user mode.
On "traditional" devices, this method switches back to the "primary"
user, which is the system user. But on devices running with headless
system user mode, it should switch to the previous user instead.

Test: manual verification (TestDpc/CtsVerifier) on car and phone
Test: atest com.android.cts.devicepolicy.DeviceOwnerTest#testCreateAndManageUser_LogoutUser
Bug: 204483021

Change-Id: I3ccbc1f31f8bcc4dae8fcb71cf5de7a7ad8882fe
2021-11-04 10:54:40 -07:00
Felipe Leme
97e42e2785 Disabled some password-related APIs on automotive.
The APIs are deprecated (in favor of setRequiredPasswordComplexity())
and some automotive OEMs might not even provide the option to
set passwords (just PINs and patterns).

Fixes: 204252236

Test: atest CtsDevicePolicyTestCases:android.devicepolicy.cts.DeprecatedPasswordAPIsTest # on automotive and phone

Change-Id: I6272bdd0e893f6fd8f1d126d384d1b332e61bac2
2021-10-29 16:18:04 -07:00
Felipe Leme
3c134b582a Merge "Expose ACTION_SHOW_NEW_USER_DISCLAIMER and acknowledgeNewUserDisclaimer()" 2021-10-12 22:04:23 +00:00
Felipe Leme
1e7e2ecee0 Expose ACTION_SHOW_NEW_USER_DISCLAIMER and acknowledgeNewUserDisclaimer()
They're used by CarService, which is being main-lined.

Test: m update-api
Fixes: 202420426

Change-Id: I5670b1cb1206ad0a361bbd91b0a785a6b8075fdf
2021-10-08 10:59:33 -07:00
TreeHugger Robot
be55d5dd48 Merge "Do not set profile owner on guest users on headless system user." into sc-v2-dev am: 356b103c6f am: d5ad334e9c
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/15999410

Change-Id: Iae64b806f539e23e18cb468f274a0927b1b1d883
2021-10-07 17:22:50 +00:00
TreeHugger Robot
d5ad334e9c Merge "Do not set profile owner on guest users on headless system user." into sc-v2-dev am: 356b103c6f
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/15999410

Change-Id: I1072d4ef2ff398fc833a1e22c21e2e1e5687c73c
2021-10-07 17:16:26 +00:00
Felipe Leme
ec902a9694 Do not set profile owner on guest users on headless system user.
The guest user cannot have extra apps, hence the DPC app is not
installed. We could try to bypass that restriction, but it could
cause other issues down the road; besides, on phones the guest
user is not managed neither and DPM doesn't provide an API to
created managed guests.

Test: manual verification using TestDpc
Fixes: 202327386

Change-Id: I02f963bc84325dd73a18abb7103fc34d4960005d
2021-10-06 16:47:24 -07:00
TreeHugger Robot
1414abeca7 Merge "Proper fix for setDeviceOwner() permission check." into sc-v2-dev am: f70489f2d0 am: 5b905266dd
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/15953790

Change-Id: I89c4e841cfc1e9116d7579ac30cb2215ccaecc2f
2021-10-05 12:37:15 +00:00
TreeHugger Robot
5b905266dd Merge "Proper fix for setDeviceOwner() permission check." into sc-v2-dev am: f70489f2d0
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/15953790

Change-Id: I64e728a54e89c7151e80eecb75c89b77f53c889e
2021-10-05 12:22:50 +00:00
TreeHugger Robot
f70489f2d0 Merge "Proper fix for setDeviceOwner() permission check." into sc-v2-dev 2021-10-05 12:04:37 +00:00