Commit Graph

1528 Commits

Author SHA1 Message Date
Alex Johnston
bb1d2a931b Fix testScreenCaptureDisabled
* A SecurityException was being thrown because getProfiles
  in UserManager cannot be called by the COPE PO for user 0
  without permission MANAGE_USERS or CREATE_USERS.
* Added binderWithCleanCallingIdentity to this method.

Bug: 149941985
Test: atest com.android.cts.devicepolicy.OrgOwnedProfileOwnerTest#testScreenCaptureDisabled
Change-Id: Iccc60233baaeaa732f197d7aaf31acc9d75a247b
Merged-In: Iccc60233baaeaa732f197d7aaf31acc9d75a247b
(cherry picked from commit 2797594914)
2020-02-28 14:00:16 +00:00
Suprabh Shukla
1b6ce9ec76 Merge "Let admin block suspend in some cases" 2020-02-21 10:02:06 +00:00
Joshua Duong
10d71243b2 Merge changes from topic "adbwifi-aosp"
* changes:
  Add Settings.Global.ADB_WIFI_ENABLED.
  [adbwifi] SysUI: Add WifiDebuggingActivity.
2020-02-21 02:22:08 +00:00
Joshua Duong
2076c04333 Add Settings.Global.ADB_WIFI_ENABLED.
ADB_ENABLED historically meant the state for USB debugging. Since
wireless debugging can be enabled separately, define another setting
for it.

BUG: b/111434128

Test: make
Exempt-From-Owner-Approval: approved in aosp_master
Change-Id: If3abca8e77381d6832f55d55a43c52ee1a1267d1
2020-02-21 02:21:08 +00:00
Rubin Xu
cb40b9881d Merge "Support security logging on org-owned managed profile devices" 2020-02-21 00:00:03 +00:00
Soonil Nagarkar
a6149521d3 Merge "Revert requestSetProviderEnabled API" 2020-02-20 16:34:37 +00:00
Rubin Xu
1480ce7b87 Support security logging on org-owned managed profile devices
When security logging is enabled on org-owned profile devices,
Security events will be redacted to preserve privacy on the personal
profile as follows:

* TAG_ADB_SHELL_CMD
  Shell command will be redacted.

* TAG_MEDIA_MOUNT
* TAG_MEDIA_UNMOUNT
  The media's volume name will be redacted.

* TAG_APP_PROCESS_START
* TAG_CERT_AUTHORITY_INSTALLED
* TAG_CERT_AUTHORITY_REMOVED
* TAG_KEY_GENERATED
* TAG_KEY_IMPORT
* TAG_KEY_DESTRUCTION
* TAG_KEY_INTEGRITY_VIOLATION
  Only events happening inside the managed profile will be returned
  to the admin.

Bug: 148437300
Test: atest FrameworksServicesTests:DevicePolicyManagerTest
Test: atest FrameworksServicesTests:SecurityEventTest
Test: atest FrameworksCoreTests:EventLogTest
Test: atest com.android.cts.devicepolicy.MixedDeviceOwnerTest#testSecurityLoggingWithSingleUser
Test: atest com.android.cts.devicepolicy.MixedDeviceOwnerTest#testSecurityLoggingWithTwoUsers
Test: atest com.android.cts.devicepolicy.MixedDeviceOwnerTest#testSecurityLoggingEnabledLogged
Test: atest com.android.cts.devicepolicy.OrgOwnedProfileOwnerTest#testSecurityLogging

Change-Id: I2e52229a3163b3e0dc3d80d71700023394d84587
2020-02-20 15:47:29 +00:00
TreeHugger Robot
1ef019d3e0 Merge "Disable Settings toggle if admin has set always-on VPN" 2020-02-20 10:09:34 +00:00
Suprabh Shukla
f0f84c8f92 Let admin block suspend in some cases
There may be policy critical apps that must not be suspended by the
user in a managed profile. The owner can now use either of the following
to block suspension of apps:
 - DISALLOW_APPS_CONTROL: Blocks suspension of all apps in the user
 - DISALLOW_UNINSTALL_APPS: Blocks suspension of all apps in the user
 - setUninstallBlocked: Blocks suspension of a given package.

The same also block any of the DistractionRestriction to be set via
PackageManager#setDistractingPackageRestrictions. This is to make sure
the apps can still show notifications.

Since the owner should have the final call, these do not block the owner
from adding app suspensions itself. Whenever either of these are set,
any app suspensions that were not originally added by the owner are
lifted immediately and any distraction restrictions that were added are
removed.

Also, clearing restrictions and suspensions if an app with SUSPEND_APPS
permission is disabled. Even though it is expected that UI not allow
such an app to be disabled, it is hard to enforce across all device
implementations. And a missed edge case would lead to permanently
unusable apps on the device.

This change also fixes a bug where any DistractionRestrictions set
weren't cleared on suspending app data clear.

Test: atest GtsSuspendAppsTestCases

Bug: 144826981
Bug: 145735990
Change-Id: I81a492e1d07a8cc9aeb0acd7e5142826824a42ae
2020-02-19 15:56:17 -08:00
Automerger Merge Worker
3979a56060 Merge "Rename ro.device_owner system property" am: 075c6b9db7 am: 3cf8f19dc4 am: 4b8545b3fb
Change-Id: Iad0b91c0b37e1e4c22ea3b2754b96e21b3fa427b
2020-02-19 23:14:24 +00:00
Soonil Nagarkar
3819f972df Revert requestSetProviderEnabled API
Bug: 144955780
Test: presubmits
Change-Id: Iec8520acfd98b9d9d92a4876ebfa899ac2a0731e
2020-02-19 14:39:58 -08:00
Winson Chiu
633cd037f7 Merge changes from topics "package-parsing-v2.1", "parsing-parsed-package-split"
* changes:
  Remove AndroidPackageWrite
  Migrate to new ParsedComponents and ParseResult
  Split ParsedComponents
  Add ParseResult infrastructure
  ParsingPackage/ParsedPackage test code migration
  ParsingPackage/ParsedPackage split source migration
  Important migration for new ParsingPackage/ParsedPackage split
  Separate ParsingPackage into core and ParsedPackage into server
2020-02-19 22:16:15 +00:00
TreeHugger Robot
cb7f6ffe03 Merge "Add COMP->COPE migration test into presubmit." 2020-02-19 19:21:39 +00:00
Pavel Grafov
fba650eaed Merge "Add "Forgot my password" to start profile in locked state." 2020-02-19 19:09:20 +00:00
Alex Johnston
5263c11a4c Merge "Add permission to ACTION_RESET_PROTECTION_POLICY_CHANGED" 2020-02-19 18:54:35 +00:00
Automerger Merge Worker
4b8545b3fb Merge "Rename ro.device_owner system property" am: 075c6b9db7 am: 3cf8f19dc4
Change-Id: I9e22996ed4f03dab423953db57c49bb27be7d903
2020-02-19 17:49:37 +00:00
Pavel Grafov
cd38eba7a6 Add COMP->COPE migration test into presubmit.
Bug: 149075700
Test: atest com.android.server.devicepolicy.DevicePolicyManagerServiceMigrationTest
Change-Id: I64473696e8e4c68afe49495aab4bded47f4d61fd
2020-02-19 16:33:41 +00:00
Pavel Grafov
4513e24323 Add "Forgot my password" to start profile in locked state.
Feature is disabled on non-FBE devices since the profile user will
end up in RUNNING_UNLOCKED state.

Bug: 143516540
Test: atest com.android.server.devicepolicy.DevicePolicyManagerTest
Test: manual
Change-Id: Ib87492577b4e5153a8108036af89c547e4bb76ee
2020-02-19 12:44:12 +00:00
Rubin Xu
e4b77b8bf2 Rename ro.device_owner system property
Bug: 148437300
Test: atest FrameworksServicesTests:DevicePolicyManagerTest
Change-Id: I3986de71c3f0f737419702799099ac08bfc48139
2020-02-19 10:40:07 +00:00
Rubin Xu
2108f19b49 Disable Settings toggle if admin has set always-on VPN
If the admin has turned on always-on VPN, do not allow the user
to modify it. In order to distinguish between a user-initiated
always-on request and an admin-initiated one, DevicePolicyManager
needs to track what the admin has set, and provide getter to be
consumed by Settings code.

Bug: 137938969
Test: manually set always-on VPN and check Settings is disabled
Change-Id: Ief7454a2b66c487c23d06c2b4486a7107f8a385a
2020-02-19 10:11:23 +00:00
Winson
5e0a1d5ce2 ParsingPackage/ParsedPackage split source migration
Part of the Parsing/ParsedPackage split into core/server.

This migrates any core/services source with trivially reviewable
changes. Import changes, moving files around, or generally
small single line changes scattered throughout all code that
depended on the old state of the package code.

Bug: 135203078

Test: enumerated in first commit of change ID
		Ib4fe51d729a56bfb0ea1316e577358ba0dfceccf

Change-Id: If091641a81be2d943d1d3e4a3d654e200d0ce59d
2020-02-19 00:29:05 -08:00
TreeHugger Robot
37266b681a Merge "Modified getActiveAdminsForAffectedUser" 2020-02-17 19:07:25 +00:00
Alex Johnston
a875e43280 Modified getActiveAdminsForAffectedUser
* Removed parent parameter from method.
* If user is a managed profile, return active admins for that user.
* If user is not a managed profile, then add all the active admins
  for that user and the parent active admins of managed profiles
  associated with it.

Bug: 149461308
Test: atest com.android.server.devicepolicy.DevicePolicyManagerTest
      atest com.android.cts.devicepolicy.MixedDeviceOwnerTest#testAdminConfiguredNetworks
      atest com.android.cts.devicepolicy.MixedDeviceOwnerTest#testSetCameraDisabledLogged
      atest com.android.cts.devicepolicy.OrgOwnedProfileOwnerTest#testAdminConfiguredNetworks
      atest com.android.cts.devicepolicy.OrgOwnedProfileOwnerTest#testCameraDisabledOnParentLogged

Change-Id: I3a4f9dd9f43c1acd7115aede6d26bb288b110c80
2020-02-17 17:29:31 +00:00
Pavel Grafov
50495dd81c Merge "Allow control over account management of parent profile" 2020-02-17 13:48:20 +00:00
Alex Kershaw
7f7195bf2c Log cross-profile metrics
Log metrics for the new app-op permission INTERACT_ACROSS_PROFILES and
each of the new app-facing and DPC-facing APIs where possible.

Simple getters do not have logging. Setters have logging but only when
the value has changed.

I always moved the logging into a separate private method. This is done
to keep the logging code from overpowering the actual logic in the
corresponding methods, particularly when there are conditions attached
to when we want to log.

There are also a few minor clean-ups in CrossProfileAppsServiceImpl.

Bug: 136249261
Bug: 149370554
Bug: 149318411
Bug: 149370875
Bug: 149370515
Test: atest com.android.cts.devicepolicy.CrossProfileAppsHostSideTest
Test: atest
com.android.cts.devicepolicy.CrossProfileAppsPermissionHostSideTest
Test: atest com.android.cts.devicepolicy.ManagedProfileCrossProfileTest
Test: atest com.android.cts.devicepolicy.ManagedProfileTest
Change-Id: Ibf2899f9b9974387ed1ba62fd02ece54a4c1564b
2020-02-14 18:32:32 +00:00
Eran Messeri
65d94931f3 Allow control over account management of parent profile
Let the owner of a managed profile on an organization-owned device set
accounts for which management is disabled in the primary profile, via
the parent profile's DevicePolicyManager instance.

Test: atest CtsDevicePolicyManagerTestCases:com.android.cts.devicepolicy.OrgOwnedProfileOwnerTest#testCanRestrictAccountManagementOnParentProfile
Test: atest FrameworksServicesTests:DevicePolicyManagerTest
Bug: 148438071
Change-Id: I45eaf5e8e403e0c23dad2df106fefd1a1f3c6f4b
2020-02-14 12:44:41 +00:00
Alex Johnston
c39e9b2e25 Merge "Modify DPM KEYGUARD_DISABLE_SECURE_CAMERA restriction" 2020-02-13 17:50:29 +00:00
Alex Johnston
af0aa258a1 Modify DPM KEYGUARD_DISABLE_SECURE_CAMERA restriction
* Introduced new logic that allows the profile owner of an
  organization-owned device (COPE PO) to set the restriction
  KEYGUARD_DISABLE_SECURE_CAMERA on the parent profile.
* Modified the API setKeyguardDisabledFeatures to be callable
  on the parent profile for restriction KEYGUARD_DISABLE_SECURE_CAMERA.

Bug: 148656201
Test: Manual testing with TestDPC
      atest com.android.cts.devicepolicy.OrgOwnedProfileOwnerTest#testSetKeyguardDisabledFeatures
      atest com.android.cts.devicepolicy.MixedDeviceOwnerTest#testSetKeyguardDisabledFeatures
      atest com.android.cts.devicepolicy.MixedManagedProfileOwnerTest#testSetKeyguardDisabledFeatures
      atest com.android.cts.devicepolicy.MixedDeviceOwnerTest#testSetKeyguardDisabledFeaturesLogged

Change-Id: I13984193e24b8745686e48c9c58ebee40a204fc7
2020-02-13 16:08:06 +00:00
Alex Johnston
090fa3c637 Add permission to ACTION_RESET_PROTECTION_POLICY_CHANGED
* Introduced new permission MANAGE_FACTORY_RESET_PROTECTION
  which allows an application to set a factory reset
  protection (FRP) policy.
* Added the new permission as the receiver permission when sending
  a broadcast in setFactoryResetProtectionPolicy.

Bug: 148596703
Test: atest com.android.cts.devicepolicy.OrgOwnedProfileOwnerTest#testFactoryResetProtectionPolicy
      atest com.android.cts.devicepolicy.MixedDeviceOwnerTest#testFactoryResetProtectionPolicy

Change-Id: I2a9c859c2304c12b58d7f16e6bae6dac15d3f8eb
2020-02-13 14:31:15 +00:00
Pavel Grafov
a210870598 Merge "Add COPE related metric." 2020-02-13 13:42:06 +00:00
Alex Johnston
7ab8a28306 Merge "Rename lockdown admin configured networks API" 2020-02-13 09:51:00 +00:00
Pavel Grafov
e878706d71 Add COPE related metric.
* setManagedProfileMaximumTimeOff
* setPersonalAppsSuspended
* COMP -> COPE migration

Test: OrgOwnedProfileOwnerTest#testSetManagedProfileMaximumTimeOffLogged
Test: OrgOwnedProfileOwnerTest#testSetPersonalAppsSuspendedLogged
Test: manual, via "adb shell cmd stats print-logs" + "adb logcat | grep statsd" during boot
Bug: 148788010
Change-Id: Iaf09b536328bdb6623a2d4f6c92f73cd7f94f28c
2020-02-12 18:59:10 +00:00
Alex Johnston
12a4461733 Merge "Modify Screen Capture Disabled APIs" 2020-02-12 16:55:36 +00:00
Alex Johnston
8e935f7737 Modify Screen Capture Disabled APIs
* Previously, setScreenCapturedDisabled and getScreenCaptureDisabled
  did not support explicitly querying the parent profile.
* This CL allows the COPE profile owner call these APIs on the parent
  profile to disable screen capture device-wide.

Bug: 149006854
Test: atest com.android.cts.devicepolicy.OrgOwnedProfileOwnerTest#testScreenCaptureDisabled
      atest com.android.cts.devicepolicy.MixedDeviceOwnerTest#testScreenCaptureDisabled
      atest com.android.cts.devicepolicy.MixedDeviceOwnerTest#testScreenCaptureDisabled_assist
      atest com.android.cts.devicepolicy.MixedManagedProfileOwnerTest#testScreenCaptureDisabled_allowedPrimaryUser
      atest com.android.cts.devicepolicy.MixedDeviceOwnerTest#testCreateAdminSupportIntent

Change-Id: I64469af190577f66f48052c7f0df20067101aac4
2020-02-12 11:52:59 +00:00
TreeHugger Robot
c228e1d88a Merge "Add manifest broadcasts for profile (un-)available." 2020-02-12 11:39:12 +00:00
Alex Johnston
3e7916ef18 Merge "Update COPE metrics" 2020-02-12 09:11:15 +00:00
Pierre Barbier de Reuille
1858482e49 Add manifest broadcasts for profile (un-)available.
This mean both switch on/off and add/remove profiles.

The broadcasts already exists for registered receivers, this adds them
for manifest receivers with INTERACT_ACROSS_PROFILES permission and
crossProfile attribute.

The MANAGED_PROFILE_REMOVED broadcast is sent to all application with
android:crossProfile="true". Any cross profile app may be impacted, and
there is no possible transfer of information as the account is already
deleted at the time the signal is emitted.

Change-Id: I17fb9a01b70b28845c5d6aacdcdd497a82391474
Fix: 145135525, 145598120
Test: Demo-app using Digital Wellbeing (automated test underway).
Test: atest com.android.cts.devicepolicy.CrossProfileAppsPermissionHostSideTest
Test: atest 'com.android.cts.devicepolicy.QuietModeHostsideTest#testBroadcastManagedProfileAvailable_withCrossProfileAppsOp'
Test: atest 'com.android.cts.devicepolicy.QuietModeHostsideTest#testBroadcastManagedProfileAvailable_withoutCrossProfileAppsOp'
2020-02-12 07:44:23 +00:00
Automerger Merge Worker
03cebe3202 Merge "Re-activate backup service after cleaning a profile owner" into qt-qpr1-dev am: c1e78426b5
Change-Id: Ia7277711125ed3be7cf9914483601488f66e94ca
2020-02-11 23:24:38 +00:00
Alex Johnston
57ec80939f Rename lockdown admin configured networks API
* Renamed 'isLockdownAdminConfiguredNetworks'
  to 'hasLockdownAdminConfiguredNetworks'
* Renamed 'setLockdownAdminConfiguredNetworks'
  to 'setConfiguredNetworksLockdownState'

Bug: 148853269
Test: atest com.android.server.devicepolicy.DevicePolicyManagerTest
      atest com.android.cts.devicepolicy.MixedDeviceOwnerTest#testAdminConfiguredNetworks
      atest com.android.cts.devicepolicy.OrgOwnedProfileOwnerTest#testAdminConfiguredNetworks

Change-Id: I6bef862b4ef7e5a7997378efcff08477da9de6dc
2020-02-11 12:43:21 +00:00
Fiona Campbell
d4eb295196 Add support for brightness as a float
Change the framework to handle brightness as a float rather than an int.

Test: AutomaticBrightnessControllerTest
BrightnessConfigurationTest
BrightnessMappingStrategyTest
BrightnessUtilsTest
DevicePolicyManagerTest
DisplayManagerServiceTest
DisplayTest
DozeScreenBrightnessTest
PowerManagerTest
PowerManagerVrTest
SettingsProviderTest

Exempt-From-Owner-Approval: Changing param from int to float

Change-Id: I413641cd987c5ec8f82753c0388a33f85a9682de
2020-02-10 23:44:40 +00:00
Soonil Nagarkar
ad1c960744 Merge "Add location notification and target sdk checks" 2020-02-10 19:43:06 +00:00
TreeHugger Robot
2669b7f6ff Merge "Check for FEATURE_TELEPHONY before clearing APNs" 2020-02-10 16:35:11 +00:00
Alex Johnston
d9283a79ef Update COPE metrics
* Add the parent flag to the existing metrics for:
	- setUserRestriction
	- getPasswordComplexity
	- wipeData
	- setCameraDisabled

Bug: 148841428
Test: atest com.android.cts.devicepolicy.DeviceOwnerPlusProfileOwnerTest#testWipeData_secondaryUserLogged
      atest com.android.cts.devicepolicy.ManagedProfileWipeTest#testWipeDataLogged
      atest com.android.cts.devicepolicy.PasswordComplexityTest#testGetPasswordComplexity
      atest com.android.cts.devicepolicy.MixedDeviceOwnerTest#testSetCameraDisabledLogged
      atest com.android.cts.devicepolicy.MixedDeviceOwnerTest#testSetKeyguardDisabledFeaturesLogged
      atest com.android.cts.devicepolicy.MixedDeviceOwnerTest#testApplicationHidden
      atest com.android.cts.devicepolicy.MixedDeviceOwnerTest#testPasswordMethodsLogged
      atest com.android.cts.devicepolicy.MixedDeviceOwnerTest#testSetUserRestrictionLogged
      atest com.android.cts.devicepolicy.OrgOwnedProfileOwnerTest#testCameraDisabledOnParentLogged
      atest com.android.cts.devicepolicy.OrgOwnedProfileOwnerTest#testUserRestrictionSetOnParentLogged

Change-Id: Ia3bf5aa1149aded6d2effab938881669b2e23c45
2020-02-10 15:28:33 +00:00
Eran Messeri
83235861a5 Merge "Revert: Prevent auto-granting of location permission via DPM" 2020-02-10 13:52:35 +00:00
Eran Messeri
9b132e135a Revert: Prevent auto-granting of location permission via DPM
Revert the change where the DPC could no longer set location permissions
by calling DevicePolicyManager.setPermissionGrantState.

Bug: 148631522
Bug: 147650798
Test: manual
Test: see cts tests in associated CL.
Change-Id: Ic6ebb7c8001a8e356296bc6459fc3530e0531070
2020-02-07 13:20:44 +00:00
Soonil Nagarkar
a8717feb6b Add location notification and target sdk checks
Check target SDKs to disallow using setSecureSetting with LOCATION_MODE
and point clients to setLocationEnabled() instead. Show notifications to
users when location settings are changed by the admin.

Bug: 136219903
Test: manual - triggered setLocationEnabled and observed notification
Change-Id: I07c150e62230b06f76ec7bd5197a23e703ffb918
2020-02-06 15:57:46 -08:00
Alex Johnston
3ec4f57333 Merge "Add metrics logging for setTime and setTimeZone" 2020-02-06 18:28:43 +00:00
Alex Johnston
feff951d37 Add metrics logging for setTime and setTimeZone
Bug: 148841428
Test: atest com.android.cts.devicepolicy.MixedDeviceOwnerTest#testSetTime
      atest com.android.cts.devicepolicy.MixedDeviceOwnerTest#testSetTimeZone

Change-Id: I9588d1259026f7a4c655a10407fbc90dbef309ca
2020-02-06 13:39:06 +00:00
Valentin Iftime
c89c3b8216 Check for FEATURE_TELEPHONY before clearing APNs
Do not clear override APNs for devices without FEATURE_TELEPHONY

Test: atest DeviceOwnerTest
Bug: 148928926
Change-Id: I2b6c426c4a88ea7260910b48327a408ab9ee0466
2020-02-06 12:55:55 +01:00
Andrei-Valentin Onea
374ba3fcff Merge "Clear caller identity before calls to PlatformCompat" 2020-02-05 15:33:36 +00:00