The only significant missing piece of functionality is the handling of credential encrypted data in the case where one or more users haven't unlocked their device. This will be handled in a follow-up change. Bug: 112431924 Test: atest RollbackTest Change-Id: I4582018337ce0344379f6f73d6fd6c9ce31c58a0