Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 794e9022 authored by Zach Jang's avatar Zach Jang Committed by android-build-merger
Browse files

Revert "Catch KeyStoreException for setting profile lock" am: e61672ab am:...

Revert "Catch KeyStoreException for setting profile lock" am: e61672ab am: fe3b0b2c am: f516131a
am: af98d20d

Change-Id: Ib443a1fea735b8aa240d724fc7a24c91102440ef
parents 94c1ead8 af98d20d
Loading
Loading
Loading
Loading
+4 −12
Original line number Diff line number Diff line
@@ -249,16 +249,13 @@ public class LockSettingsService extends ILockSettings.Stub {
        try {
            randomLockSeed = SecureRandom.getInstance("SHA1PRNG").generateSeed(40);
            String newPassword = String.valueOf(HexEncoding.encode(randomLockSeed));
            tieProfileLockToParent(managedUserId, newPassword);
            setLockPasswordInternal(newPassword, managedUserPassword, managedUserId);
            // We store a private credential for the managed user that's unlocked by the primary
            // account holder's credential. As such, the user will never be prompted to enter this
            // password directly, so we always store a password.
            setLong(LockPatternUtils.PASSWORD_TYPE_KEY,
                    DevicePolicyManager.PASSWORD_QUALITY_ALPHANUMERIC, managedUserId);
        } catch (KeyStoreException e) {
            // Bug: 32490092
            Slog.e(TAG, "Not able to set keys to keystore", e);
            tieProfileLockToParent(managedUserId, newPassword);
        } catch (NoSuchAlgorithmException | RemoteException e) {
            Slog.e(TAG, "Fail to tie managed profile", e);
            // Nothing client can do to fix this issue, so we do not throw exception out
@@ -779,7 +776,6 @@ public class LockSettingsService extends ILockSettings.Stub {
    }

    private void unlockChildProfile(int profileHandle) throws RemoteException {
        if (DEBUG) Slog.v(TAG, "Unlock child profile");
        try {
            doVerifyPassword(getDecryptedPasswordForTiedProfile(profileHandle), false,
                    0 /* no challenge */, profileHandle, null /* progressCallback */);
@@ -1039,7 +1035,7 @@ public class LockSettingsService extends ILockSettings.Stub {
        }
    }

    private void tieProfileLockToParent(int userId, String password) throws KeyStoreException {
    private void tieProfileLockToParent(int userId, String password) {
        if (DEBUG) Slog.v(TAG, "tieProfileLockToParent for user: " + userId);
        byte[] randomLockSeed = password.getBytes(StandardCharsets.UTF_8);
        byte[] encryptionResult;
@@ -1081,7 +1077,7 @@ public class LockSettingsService extends ILockSettings.Stub {
                keyStore.deleteEntry(LockPatternUtils.PROFILE_KEY_NAME_ENCRYPT + userId);
            }
        } catch (CertificateException | UnrecoverableKeyException
                | IOException | BadPaddingException | IllegalBlockSizeException
                | IOException | BadPaddingException | IllegalBlockSizeException | KeyStoreException
                | NoSuchPaddingException | NoSuchAlgorithmException | InvalidKeyException e) {
            throw new RuntimeException("Failed to encrypt key", e);
        }
@@ -1223,11 +1219,7 @@ public class LockSettingsService extends ILockSettings.Stub {
        } finally {
            if (managedUserId != -1 && managedUserDecryptedPassword != null) {
                if (DEBUG) Slog.v(TAG, "Restore tied profile lock");
                try {
                tieProfileLockToParent(managedUserId, managedUserDecryptedPassword);
                } catch (KeyStoreException e) {
                    throw new RuntimeException("Failed to tie profile lock", e);
                }
            }
        }
    }