Currently some functions allow the caller to check policy
enforced by a particular admin by passing a non-null "who"
argument. This circumvents package visibility rules. There is no
legitimate reason for an 3rd party app to query policies for
arbitrary admins. With this change whenever "who" is not null,
the code will ensure that the admin referenced by "who" is owned
by the caller.
Exception to the above are methods that are also called by
Setting to query policy for a particular admin for policy
transparency. For those methods callers with QUERY_ADMIN_POLICY
permission are allowed to query per-admin policy:
* getMaximumFailedPasswordsForWipe
* getMaximumTimeToLock
* getPasswordQuality
There is no legitimate reason for an 3rd party app to query
policies for arbitrary admins. Code search for
getPasswordHistoryLength and getPasswordMinimum* methods doesn't
return any priviledged usage of these methods inside Android.
getPasswordQuality is used by Settings, hence the system uid is
exempt.
+ removed redundant system or root UID checks when querying
permission.
Bug: 204995407
Test: atest android.devicepolicy.cts.NoAdminLeakingTest
Test: atest android.devicepolicy.cts.ResetPasswordWithTokenTest
Test: atest com.android.cts.devicepolicy.MixedDeviceOwnerTest#testPasswordRequirementsApi
Change-Id: I443ed1f6dcd5e5b161c99dd09a4b2aef9f8ef0a7
Also started using it for DPM#provisionFullyManagedDevice and
DPM#createAndProvisionManagedProfile
Bug: 188410712
Bug: 206083853
Test: atest android.devicepolicy.cts.DevicePolicyManagerTest
Change-Id: Ic5bdb2bec16c83671a7e2cc955522b2d8c82ea70
Currently upgrade happens on lock settings ready, but by that time
WifiService alredy calls to isCommonCriteriaModeEnabled and this
results in obsolete values left in cache. Moving upgrade to ctor
avoids this issue.
Both old and new upgrade invocations happen during
SystemServer.startOtherServices, while all services on which the upgrade
depends, namely UserManager and PackageManager are started earlier in
SystemServer.startBootstrapServices.
Bug: 198768109
Test: upgrade from Android 11 and check device policy cache
Change-Id: Ie4c17a617bbed176bc87fc598f56ccbc49569009
In order to make on-screen keyboard settings
support tab layout. It's needed to get the
permitted input method list as work profile
user.
Add this @hide API in DevicePolicyManager which
should only be used in system.
This change only add the API first for further
usage, there is no user-facing changes.
Bug: 197707782
Test: atest com.android.server.devicepolicy.DevicePolicyManagerTest
atest com.android.cts.devicepolicy.OrgOwnedProfileOwnerTest#testPermittedInputMethods
atest com.android.cts.devicepolicy.OrgOwnedProfileOwnerTest#testPermittedInputMethodsLogged
Change-Id: I8ee9f523d2b25af7bfea2a138dba601f9678b8aa
Introduces an API for whether more users can be added of the given user
type.
Bug: 192577100
Bug: 175795666
Bug: 189937255
Bug: 205100630
Test: atest com.android.server.pm.UserManagerTest#testAddTooManyUsers
Change-Id: I1c705d65d1c083a60fd4e058456dcdc4ffa0fffb
Revert "Add test for isDeviceOwnerApp"
Revert submission 15660377-ayushsha_185896465
Reason for revert: DroidMonitor-triggered revert due to breakage bug http://b/207143396
BUG: 207143396
Reverted Changes:
I774ec2a09:Add test for isDeviceOwnerApp
Ibd611bfe2:Require QUERY_ALL_PACKAGES getDeviceOwnerComponent...
Change-Id: I30a701efefed6eeaf232497019282a7a96ff0424
It was sending it to the system user, which wouldn't work on systems
with headless system user.
Test: atest FrameworksServicesTests:DevicePolicyManagerTest
Test: manual verification with TestDpc and CtsVerifier on phone and automotive
Test: adb shell dumpsys device_policy | grep mNetworkLoggingNotificationUserId
Bug: 205190291
Change-Id: I0c060a9d9f1c41f63f9bcebd3c1848963ff12764
Also fixed how the logout user was cleared after a successful switch.
They will be used by CarSystemUi to end a session.
Test: Manual verification with CtsVerifier and TestDpc on automotive
Bug: 205185521
Bug: 204483021
Change-Id: Ieda0a22625ef705fcd705aedfc2dbf2cf570bf81
If a profile owner is defined for a specific user, do not delete usage
stats for a package on package deletion.
Bug: 197399948
Test: atest UserUsageStatsServiceTest
Test: atest UsageStatsTest [all]
Change-Id: I94a8e3dfca8ef4c7616f77944d61726e06043b85
Merged-In: I94a8e3dfca8ef4c7616f77944d61726e06043b85
If a profile owner is defined for a specific user, do not delete usage
stats for a package on package deletion.
Bug: 197399948
Test: atest UserUsageStatsServiceTest
Test: atest UsageStatsTest [all]
Change-Id: I94a8e3dfca8ef4c7616f77944d61726e06043b85
Android T adds support to allow a runtime receiver to be registered as
not exported, but to ensure apps can take advantage of this, calls to
registerReceiver must specify a flag indicating whether the receiver
should be exported for apps targeting T+ that are registering for
unprotected broadcasts. This commit adds the RECEIVER_EXPORTED flag
to the call to registerReceiver in RemoteBugreportManager when
registering for the REMOTE_BUGREPORT_DISPATCH action as this is
broadcast from shell.
Bug: 161145287
Test: Manually verified logcat warning was not reported
Change-Id: I51ef7b5c275c70edd4eaa98132b98315c1e04256
On "traditional" devices, this method switches back to the "primary"
user, which is the system user. But on devices running with headless
system user mode, it should switch to the previous user instead.
Test: manual verification (TestDpc/CtsVerifier) on car and phone
Test: atest com.android.cts.devicepolicy.DeviceOwnerTest#testCreateAndManageUser_LogoutUser
Bug: 204483021
Change-Id: I3ccbc1f31f8bcc4dae8fcb71cf5de7a7ad8882fe
The APIs are deprecated (in favor of setRequiredPasswordComplexity())
and some automotive OEMs might not even provide the option to
set passwords (just PINs and patterns).
Fixes: 204252236
Test: atest CtsDevicePolicyTestCases:android.devicepolicy.cts.DeprecatedPasswordAPIsTest # on automotive and phone
Change-Id: I6272bdd0e893f6fd8f1d126d384d1b332e61bac2
The guest user cannot have extra apps, hence the DPC app is not
installed. We could try to bypass that restriction, but it could
cause other issues down the road; besides, on phones the guest
user is not managed neither and DPM doesn't provide an API to
created managed guests.
Test: manual verification using TestDpc
Fixes: 202327386
Change-Id: I02f963bc84325dd73a18abb7103fc34d4960005d