Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 660f2327 authored by Janis Danisevskis's avatar Janis Danisevskis
Browse files

Clear WIFI namspace on primary user keystore reset.

This patch makes LocksettingsService clear the WIFI namspace when
Keystore is reset for the primary user.

Test: Using Settings, install a WIFI certificate, tap clear credentials,
      and check that the certificate was removed from the stored
      credentials.
Bug: 189601008
Change-Id: I9364c860250653e50fa8c92c11c510c864f3c3d8
parent 52109a93
Loading
Loading
Loading
Loading
+8 −3
Original line number Diff line number Diff line
@@ -105,6 +105,7 @@ import android.security.keystore2.AndroidKeyStoreLoadStoreParameter;
import android.security.keystore2.AndroidKeyStoreProvider;
import android.service.gatekeeper.GateKeeperResponse;
import android.service.gatekeeper.IGateKeeperService;
import android.system.keystore2.Domain;
import android.text.TextUtils;
import android.util.ArrayMap;
import android.util.ArraySet;
@@ -254,8 +255,7 @@ public class LockSettingsService extends ILockSettings.Stub {
     * The UIDs that are used for system credential storage in keystore.
     */
    private static final int[] SYSTEM_CREDENTIAL_UIDS = {
            Process.WIFI_UID, Process.VPN_UID,
            Process.ROOT_UID, Process.SYSTEM_UID };
            Process.VPN_UID, Process.ROOT_UID, Process.SYSTEM_UID};

    // This class manages life cycle events for encrypted users on File Based Encryption (FBE)
    // devices. The most basic of these is to show/hide notifications about missing features until
@@ -2123,9 +2123,14 @@ public class LockSettingsService extends ILockSettings.Stub {
            // Clear all the users credentials could have been installed in for this user.
            for (int profileId : mUserManager.getProfileIdsWithDisabled(userId)) {
                for (int uid : SYSTEM_CREDENTIAL_UIDS) {
                    mKeyStore.clearUid(UserHandle.getUid(profileId, uid));
                    AndroidKeyStoreMaintenance.clearNamespace(Domain.APP,
                            UserHandle.getUid(profileId, uid));
                }
            }
            if (mUserManager.getUserInfo(userId).isPrimary()) {
                AndroidKeyStoreMaintenance.clearNamespace(Domain.SELINUX,
                        KeyProperties.NAMESPACE_WIFI);
            }
        } finally {
            if (managedUserId != -1 && managedUserDecryptedPassword != null) {
                if (DEBUG) Slog.v(TAG, "Restore tied profile lock");