Harden provisioning and add per-app cross-profile access - #13
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Validation
./gradlew --no-daemon testDebugUnitTest lintDebug assembleRelease generateSbomscripts/verify-manifest.shagainst the release APKscripts/verify-deterministic-build.shgit diff --check154a39b4edffc20496f9c0ee64eddfba3a3248dbf3fc9df9698e839f14a3e97fverifyanddeterministicchecks pass for74e05197b5c057d3ee7ea3ff4bd445c6cd3881aaPhysical and disposable-environment checks
Samsung Galaxy S24 (completed separately)
This run intentionally did not repeat the completed Cross-profile validation.
Provisioning
sdk_gphone64_arm64, Android 16/API 36). From a clean owner user with no device/profile owner, Harbor displayedCreate Work space; tapping it passed Harbor's public-API preflight and launched Android's normalcom.android.managedprovisioning/.preprovisioning.PreProvisioningActivityflow. Android then stopped at its nativeCan't set up devicescreen because the Google managed-provisioning role-holder update failed offline (Update failed and offline provisioning is not allowed); no Harbor exception or policy mutation was observed.no owners,Device managed: false, andCan have profile: true. Harbor returned to its normal setup screen and still offeredCreate Work space.google_apis;arm64-v8aon the arm64 host; onlyemulatorand that API 36 system image were added, with the already-presentandroid-sdk-licenseandandroid-sdk-arm-dbt-licenseaccepted. The physical S24 was not touched during this run.Issue readiness