From 05412c37c727dca117006627c3ba47c95d775b49 Mon Sep 17 00:00:00 2001 From: Tsung-Mao Fang Date: Tue, 27 Sep 2022 07:34:27 +0000 Subject: [PATCH 1/2] Make preference unselectable Because Encrypt phone is not an entry which can launch to next page, let's make it unselectable now. Change-Id: I860c76c501fccc488b2e120a4702c652f1bee134 Test: Manual test Fix: 249193859 --- res/xml/encryption_and_credential.xml | 1 + .../security/EncryptionAndCredentialTest.java | 25 +++++++++++++++++++ 2 files changed, 26 insertions(+) diff --git a/res/xml/encryption_and_credential.xml b/res/xml/encryption_and_credential.xml index cc8210af0e3..5663df1581d 100644 --- a/res/xml/encryption_and_credential.xml +++ b/res/xml/encryption_and_credential.xml @@ -27,6 +27,7 @@ android:key="encryption_and_credentials_encryption_status" android:title="@string/encrypt_title" android:summary="@string/summary_placeholder" + android:selectable="false" settings:controller="com.android.settings.security.EncryptionStatusPreferenceController"/> diff --git a/tests/robotests/src/com/android/settings/security/EncryptionAndCredentialTest.java b/tests/robotests/src/com/android/settings/security/EncryptionAndCredentialTest.java index 1d7a4a74547..446fd6cc04c 100644 --- a/tests/robotests/src/com/android/settings/security/EncryptionAndCredentialTest.java +++ b/tests/robotests/src/com/android/settings/security/EncryptionAndCredentialTest.java @@ -20,8 +20,12 @@ import static com.google.common.truth.Truth.assertThat; import android.app.admin.DevicePolicyManager; import android.content.Context; +import android.os.Bundle; import android.os.UserManager; +import androidx.preference.Preference; +import androidx.preference.PreferenceFragmentCompat; + import com.android.internal.logging.nano.MetricsProto.MetricsEvent; import org.junit.Before; @@ -32,6 +36,7 @@ import org.mockito.MockitoAnnotations; import org.robolectric.RobolectricTestRunner; import org.robolectric.RuntimeEnvironment; import org.robolectric.shadows.ShadowApplication; +import org.robolectric.shadows.androidx.fragment.FragmentController; @RunWith(RobolectricTestRunner.class) public class EncryptionAndCredentialTest { @@ -58,4 +63,24 @@ public class EncryptionAndCredentialTest { assertThat(fragment.getMetricsCategory()).isEqualTo(MetricsEvent.ENCRYPTION_AND_CREDENTIAL); } + @Test + public void isSelectable_encryptionPreferenceStatus_isNotSelectable() { + final PreferenceFragmentCompat fragment = + FragmentController.of(new TestFragment(), new Bundle()) + .create() + .start() + .resume() + .get(); + final Preference preference = + fragment.findPreference("encryption_and_credentials_encryption_status"); + + assertThat(preference.isSelectable()).isFalse(); + } + + public static class TestFragment extends PreferenceFragmentCompat { + @Override + public void onCreatePreferences(Bundle savedInstanceState, String rootKey) { + addPreferencesFromResource(com.android.settings.R.xml.encryption_and_credential); + } + } } From f5062c2df86bc1f1034e780c7b19c29f8acecab5 Mon Sep 17 00:00:00 2001 From: Tsung-Mao Fang Date: Fri, 30 Sep 2022 15:27:06 +0800 Subject: [PATCH 2/2] Guard FallbackHome activity behind permission An attacker can launch FallbackHome of the Settings app to reset unlock time. This would prevent the device from sleeping because it runs the following code: PowerManager#userActivity(). However, running PowerManager.userActivity() requires android.permission.DEVICE_POWER or android.permission.USER_ACTIVITY. So, let's add a permission to guard this activity. Test: Rebuilt a rom and see no side effect. Bug: 246543238 Change-Id: I23a1e352f76cbec3e8c07a1b58b94615f2779121 --- AndroidManifest.xml | 1 + 1 file changed, 1 insertion(+) diff --git a/AndroidManifest.xml b/AndroidManifest.xml index 0be2e2efbac..ebfbe6f5e41 100644 --- a/AndroidManifest.xml +++ b/AndroidManifest.xml @@ -3013,6 +3013,7 @@ android:taskAffinity="com.android.settings.FallbackHome" android:exported="true" android:theme="@style/FallbackHome" + android:permission="android.permission.DEVICE_POWER" android:configChanges="keyboardHidden">