EXTRA_CLIENT_AUTHORIZATION_STATE currently wouldn't have its docs
generated correctly (if they ever need to be). Modify the doc comment to
properly link to the authorization state constants.
Fixes: 181350428
Test: presubmits
Change-Id: Ieee8ecbc4af153e4f42bb47c734c4f042361b332
Add a new parameter to DisplayManager.registDisplayListener
which clients can use to specify in which events
they are interested.
Test: atest DisplayManagerServiceTest
atest DisplayManagerGlobalTest
Bug: 171240622
Change-Id: Icc71bdd9ddb390bc5406b298a557c84194a53c00
By default, auth via BiometricPrompt is not allowed unless the
caller is foreground. However, for cases like CTS, which may request
auth from the test itself (and not a test activity, which has no
way of getting access to protected TestApis), auth is requested
from background.
This would also allow us to easily add regression tests for the
security bug b/159249069
Bug: 163058911
Test: atest CtsBiometricsTestCases
Test: atest com.android.server.biometrics
Change-Id: I74bfdcd7989aa9256d1bf10eefae354983b42e6c
On devices with multiple sensors, lockout should be reset whenever
any strong sensor authenticates.
Bug: 163058911
Test: atest CtsBiometricsTestCases
Change-Id: I4bcdc0279cdaa444e59cf0fac6645d9a67e7d11d
The onStatusChangedLocked removes entries from the ArrayMap. Needs to
iterate in the reverse order.
Test: Vendor testing
Bug: 182876702
Change-Id: I5891f24a25c83f096d23ca5675126889a7d2a61c
To mesh with how other parts of the framework handle apps using APIs
when they are denied, ContextHubClientBroker should throw a security
exception when clients are in the denied authorization state rather than
returning a new error code. This is only enabled for clients targeting
S+. All other clients will receive an error code present before S
denoting an unknown error occurs so that they don't have to handle a new
exception.
Fixes: 181350407
Test: Run PTS
Change-Id: Icf828bb1c34797cf2c65a8adeb92eb83db3aaea6
IFace and IFingerprint AIDL interfaces do not require challenge
for resetLockout. Rather, they are time-based. See the HAL interface
for more details.
Bug: 182327296
Test: reset lockout on Pixel4
Test: atest com.android.systemui
Test: atest com.android.server.biometrics
Change-Id: Ibf1130d77e714d15fb9eccd3175027a28de08f7b
1) resetLockoutRequiresHardwareAuthToken is moved to the base
SensorPropertiesinternal class, despite face always requiring
it. This will be clearer, since we are further splitting
resetLockout logic into "challenge-required" (IBiometricsFace@1.0)
and "challenge-less" (IFace@1.0) It would be weird to have
a "resetLockoutRequiresChallenge" property without a
"resetLockoutRequiresHardwareAuthToken" property.
2) Will be adding a resetLockoutRequiresChallenge to
SensorPropertiesInternal in the next CL.
Bug: 182327296
Test: reset lockout on Pixel4
Change-Id: Ifa4b36dc42d91e967506a59d2880f47f61ec6cdf
BrightnessTracker is now global.
Pass in the physicaldisplayid of the primary display device of the
logical display that the display power controller is associated with.
This is so that we can determine the brightness changes for each
physical screen.
Bug: 181767734
Test: manual
Change-Id: Iaebb12ec5fe7785545374cc639d7a345ca469db8
This adds calls that are easier to use for services and providers which
may multiuser aware.
Bug: 162549680
Test: Added callback to another service
Change-Id: Ie8c5c046cd31ae82b89206849a8983d60f0d66c5
- Indicates which int values can be sent via the
EXTRA_CLIENT_AUTHORIZATION_STATE extra
- Explicitly mentions how much time clients have to clean up their state
with a nanoapp so there's no ambiguity.
Fixes: 181350428
Test: presubmits
Change-Id: Id39c233b8678450e3c7687ed2bcb1c1f4516f8d7