Xiaomi Pocophone F1 128Gb+6Gb Dual LTE [106/118] Multi user support

Xiaomi Pocophone F1 128Gb+6Gb Dual LTE [106/118] Multi user support
[C-0-4] Alternate runtimes MUST abide by the Android sandbox model and installed
applications using an alternate runtime MUST NOT reuse the sandbox of any other app
installed on the device, except through the standard Android mechanisms of shared user
ID and signing certificate.
[C-0-5] Alternate runtimes MUST NOT launch with, grant, or be granted access to the
sandboxes corresponding to other Android applications.
[C-0-6] Alternate runtimes MUST NOT be launched with, be granted, or grant to other
applications any privileges of the superuser (root), or of any other user ID.
[C-0-7] When the .apk files of alternate runtimes are included in the system image of
device implementations, it MUST be signed with a key distinct from the key used to sign
other applications included with the device implementations.
[C-0-8] When installing applications, alternate runtimes MUST obtain user consent for the
Android permissions used by the application.
[C-0-9] When an application needs to make use of a device resource for which there is a
corresponding Android permission (such as Camera, GPS, etc.), the alternate runtime
MUST inform the user that the application will be able to access that resource.
[C-0-10] When the runtime environment does not record application capabilities in this
manner, the runtime environment MUST list all permissions held by the runtime itself
when installing any application using that runtime.
Alternate runtimes SHOULD install apps via the PackageManager into separate Android
sandboxes (Linux user IDs, etc.).
Alternate runtimes MAY provide a single Android sandbox shared by all applications using
the alternate runtime.
9.5. Multi-User Support
Android includes support for multiple users and provides support for full user isolation.
Device implementations MAY but SHOULD NOT enable multi-user if they use removable
media for primary external storage.
If device implementations include multiple users, they:
[C-1-1] MUST meet the following requirements related to multi-user support .
[C-1-2] MUST, for each user, implement a security model consistent with the Android
platform security model as defined in Security and Permissions reference document in
the APIs.
[C-1-3] MUST have separate and isolated shared application storage (a.k.a. /sdcard )
directories for each user instance.
[C-1-4] MUST ensure that applications owned by and running on behalf a given user
cannot list, read, or write to the files owned by any other user, even if the data of both
users are stored on the same volume or filesystem.
[C-1-5] MUST encrypt the contents of the SD card when multiuser is enabled using a key
stored only on non-removable media accessible only to the system if device
implementations use removable media for the external storage APIs. As this will make the
media unreadable by a host PC, device implementations will be required to switch to MTP
or a similar system to provide host PCs with access to the current user’s data.
If device implementations include multiple users and do not declare the android.hardware.telephony
feature flag, they:
Page 106 of 118

Содержание

Похожие устройства

Скачать