package: "android.security" container: "system" flag { name: "certificate_transparency_configuration" is_exported: true namespace: "network_security" description: "Enable certificate transparency setting in the network security config" bug: "28746284" } flag { name: "conscrypt_network_security_config" is_exported: true namespace: "network_security" description: "Enable the frameworks APIs required by the NSC implementation in Conscrypt" bug: "404518910" } flag { name: "fsverity_api" is_exported: true namespace: "hardware_backed_security" description: "Feature flag for fs-verity API" bug: "285185747" } flag { name: "mgf1_digest_setter_v2" is_exported: true namespace: "hardware_backed_security" description: "Feature flag for mgf1 digest setter in key generation and import parameters." bug: "308378912" is_fixed_read_only: true } flag { name: "keyinfo_unlocked_device_required" is_exported: true namespace: "hardware_backed_security" description: "Add the API android.security.keystore.KeyInfo#isUnlockedDeviceRequired()" bug: "296475382" } flag { name: "unlocked_storage_api" namespace: "hardware_backed_security" description: "Feature flag for unlocked-only storage API" bug: "325129836" } flag { name: "reset_auth_flags_and_metrics_in_lock_user" namespace: "security" description: "Make LockSettingsService#lockUser() always handle resetting strong auth flags and removing user password metrics" bug: "319142556" } flag { name: "scrypt_parameter_change" namespace: "security" description: "Use n=9 instead of n=11 for scrypt for lock screen knowledge factors" bug: "416772194" metadata { purpose: PURPOSE_BUGFIX } } flag { name: "software_ratelimiter" namespace: "security" description: "Enable support for SoftwareRateLimiter in LockSettingsService" bug: "395976735" } flag { name: "stop_recognizing_legacy_password_hashes" namespace: "security" description: "Make LockSettingsService stop recognizing legacy password hashes" bug: "442877927" } flag { name: "frp_enforcement" is_exported: true namespace: "hardware_backed_security" description: "This flag controls whether PDB enforces FRP" bug: "290312729" is_fixed_read_only: true } flag { name: "should_trust_manager_listen_for_primary_auth" namespace: "biometrics" description: "Causes TrustManagerService to listen for credential attempts and ignore reports from upstream" bug: "323086607" } flag { name: "afl_api" namespace: "hardware_backed_security" description: "AFL feature" bug: "365994454" is_exported: true } flag { name: "internal_log_event_listener" namespace: "hardware_backed_security" description: "Use internal callback to gather SecurityMonitor logs." bug: "389732143" metadata { purpose: PURPOSE_BUGFIX } } flag { name: "protect_device_config_flags" namespace: "psap_ai" description: "Feature flag to limit adb shell to allowlisted flags" bug: "364083026" is_fixed_read_only: true } flag { name: "keystore_grant_api" namespace: "hardware_backed_security" description: "Feature flag for exposing KeyStore grant APIs" bug: "351158708" is_exported: true } flag { name: "secure_lockdown" namespace: "biometrics" description: "Feature flag for Secure Lockdown feature" bug: "373422357" is_exported: true } flag { name: "secure_lock_device" namespace: "biometrics" description: "Feature flag for Secure Lock Device feature" bug: "401645997" is_exported: true } flag { name: "subscribe_to_keyguard_locked_state_perm_priv_flag" namespace: "psap_ai" description: "Feature flag to add the privileged flag to the SUBSCRIBE_TO_KEYGUARD_LOCKED_STATE permission" bug: "380120712" is_fixed_read_only: true } flag { name: "disable_adaptive_auth_counter_lock" namespace: "biometrics" description: "Flag to allow an adb secure setting to disable the adaptive auth lock" bug: "371057865" } flag { name: "failed_auth_lock_toggle" namespace: "biometrics" description: "Feature flag to enable the toggle for failed authentication lock" bug: "414605464" } flag { name: "deprecate_uses_cleartext_traffic" namespace: "network_security" description: "If enabled, the XML application flag usesCleartextTraffic is ignored for targetSdk version C+." bug: "415007211" is_fixed_read_only: true } flag { name: "enable_talisman_service" namespace: "cross_device_authentication" description: "Enable the Talisman service." bug: "433283951" } flag { name: "manage_lockout_end_time_in_service" namespace: "security" description: "Manage lockout end time in LockSettingsService rather than LockPatternUtils" bug: "322014085" metadata { purpose: PURPOSE_BUGFIX } }