/*
 * Copyright (C) 2023 The Android Open Source Project
 *
 * Licensed under the Apache License, Version 2.0 (the "License");
 * you may not use this file except in compliance with the License.
 * You may obtain a copy of the License at
 *
 *      http://www.apache.org/licenses/LICENSE-2.0
 *
 * Unless required by applicable law or agreed to in writing, software
 * distributed under the License is distributed on an "AS IS" BASIS,
 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 * See the License for the specific language governing permissions and
 * limitations under the License.
 */

syntax = "proto2";

package android.os.statsd.devicelock;

import "frameworks/proto_logging/stats/atom_field_options.proto";
import "frameworks/proto_logging/stats/atoms.proto";

option java_package = "com.android.os.devicelock";
option java_multiple_files = true;

extend Atom {
  optional DeviceLockCheckInRequestReported device_lock_check_in_request_reported = 726
          [(module) = "devicelock"];
  optional DeviceLockProvisioningCompleteReported device_lock_provisioning_complete_reported = 727
          [(module) = "devicelock"];
  optional DeviceLockKioskAppRequestReported device_lock_kiosk_app_request_reported = 728
          [(module) = "devicelock"];
  optional CheckInRetryReported device_lock_check_in_retry_reported = 789
          [(module) = "devicelock"];
  optional ProvisionFailureReported device_lock_provision_failure_reported = 790
          [(module) = "devicelock"];
  optional LockUnlockDeviceFailureReported device_lock_lock_unlock_device_failure_reported = 791
          [(module) = "devicelock"];
  optional DeviceLockKioskAppInstallationFailed device_lock_kiosk_app_installation_failed = 1087
          [(module) = "devicelock"];
  optional DeviceLockFcmMessageReceived device_lock_fcm_message_received = 1091
          [(module) = "devicelock"];
  optional DeviceLockProvisionStateEvent device_lock_provision_state_event = 1093
          [(module) = "devicelock"];
  optional DeviceLockDeviceStateEvent device_lock_device_state_event = 1094
          [(module) = "devicelock"];
  optional DeviceLockPotentialBypassSnapshot device_lock_potential_bypass_snapshot = 10244
          [(module) = "devicelock"];
}

message DeviceLockCheckInRequestReported {
  enum RequestType {
    // Default value for the request type
    UNKNOWN = 0;
    // The Check-in request is getDeviceCheckInStatus
    GET_DEVICE_CHECK_IN_STATUS = 1;
    // The Check-in request is pauseDeviceProvisioning
    PAUSE_DEVICE_PROVISIONING = 2;
    // The Check-in request is reportDeviceProvisioningComplete
    // DEPRECATED, because the gRPC call for this log type is removed
    REPORT_DEVICE_PROVISIONING_COMPLETE = 3 [deprecated = true];
    // The Check-in request is reportDeviceProvisionState
    REPORT_DEVICE_PROVISION_STATE = 4;
    // The Check-in request is isDeviceInApprovedCountry
    IS_DEVICE_IN_APPROVED_COUNTRY = 5;
  }

  optional RequestType type = 1;
}

message DeviceLockProvisioningCompleteReported {
  optional int64 time_spent_on_provisioning_seconds = 1;
}

message DeviceLockKioskAppRequestReported {
  optional int32 kiosk_app_uid = 1 [(is_uid) = true];
}

message CheckInRetryReported {
  enum RetryReason {
    // Check-in retry happens because server did not specify next step.
    RESPONSE_UNSPECIFIED = 0;
    // Check-in retry happens due to provisioning configuration unavailable
    COUNFIGURATION_UNAVAILABLE = 1;
    // Check-in retry happens due to network time being unavailable
    NETWORK_TIME_UNAVAILABLE = 2;
    // Check-in retry happens due to an failure in the previous RPC
    RPC_FAILURE = 3;
    // Check-in retry happens due to a failure generating key attestation leaf certificate
    KEY_ATTESTATION_GENERATION_FAILURE = 4;
  }

  optional RetryReason reason= 1;
}

message ProvisionFailureReported {
  enum FailureReason {
    // Reason is unknown
    UNKNOWN = 0;
    // Failed due to play task unavailable
    PLAY_TASK_UNAVAILABLE = 1;
    // Failed due to installation from play unsuccessful
    PLAY_INSTALLATION_FAILED = 2;
    // Failed due to country eligibility unknown
    COUNTRY_INFO_UNAVAILABLE = 3;
    // Failed due to country not eligible
    NOT_IN_ELIGIBLE_COUNTRY = 4;
    // Failed due to unable to enforce policies
    POLICY_ENFORCEMENT_FAILED = 5;
  }

  optional FailureReason reason = 1;
}

message LockUnlockDeviceFailureReported {
  enum DeviceState {
    // Device state is undefined.
    UNDEFINED = 0;
    // Device state is unlocked.
    UNLOCKED = 1;
    // Device state is locked.
    LOCKED = 2;
    // Device state is cleared.
    CLEARED = 3;
  }

  // True if the command is lock; false if it is unlock.
  optional bool is_lock = 1;
  optional DeviceState state_post_command = 2;
}

message DeviceLockKioskAppInstallationFailed {
  // The version of the devicelock apex package on the device.
  optional int64 apex_version = 1;
}

/*
 * The DeviceLockController received an FCM message from the server.
 * Logged from: vendor/google/modules/DeviceLockGoogle/DeviceLockControllerGoogle/src/com/android/devicelockcontroller/services/DeviceLockFirebaseMessagingService.java
 * Estimated Logging Rate:
 * Peak: 1 time in 4 weeks | Avg: 1 per device in 4 weeks
 */
message DeviceLockFcmMessageReceived {
  // The version of the devicelock apex package on the device.
  optional int64 apex_version = 1;
}

/*
 * Pulled atom that is logged when the device is found to be in a Locked state but lock task mode is not active.
 * Logged from: packages/modules/DeviceLock/service/java/com/android/server/devicelock/DeviceLockService.java
 * Estimated Logging Rate:
 * Only expected to log in a bypass scenario in which case it will be 1 time per day
 */
message DeviceLockPotentialBypassSnapshot {
  // The version of the devicelock apex package on the device.
  optional int64 apex_version = 1;
}

 /* Events pertaining to provision state.
 * Logged from:
 *      (mostly) packages/modules/DeviceLock/DeviceLockController/src/com/android/devicelockcontroller/provision/
 * Expected logging rate:
 *      Peak: 1 time in 3 minutes | Avg: 1 per device per day
 */
message DeviceLockProvisionStateEvent {
  enum Event {
    EVENT_UNKNOWN = 0;
    // The client was unable to perform a check-in request.
    EVENT_UNSUCCESSFUL_CHECKIN_REQUEST = 1;
    // The kiosk app has successfully changed the device state after provisioning.
    EVENT_SUCCESSFUL_PROVISIONING = 2;
    // The device has been reset due to a provisioning failure.
    EVENT_DEVICE_RESET = 3;
    // The kiosk app cleared all restrictions and the device was finalized.
    EVENT_FINALIZATION = 4;
    // The kiosk app attempted to clear all restrictions but it did not end in a successful finalization.
    EVENT_FINALIZATION_FAILURE = 5;
    // DLC was unable to send a report about finalization due to KA generation failure
    EVENT_KA_GEN_FAILURE_REPORT_FINALIZATION = 6;
  }

  optional Event event = 1;
  // The version of the apex package on the device.
  optional int64 apex_version = 2;
}

/*
 * Events pertaining to device state.
 * Logged from:
 *      packages/modules/DeviceLock/DeviceLockController/src/com/android/devicelockcontroller/DeviceLockControllerService.java
 * Expected logging rate:
 *      Peak: 1 time per day | Avg: 1 per device per week
 */
message DeviceLockDeviceStateEvent {
  enum Event {
    EVENT_UNKNOWN = 0;
    // The kiosk app successfully locked the device.
    EVENT_LOCK = 1;
    // The kiosk app successfully unlocked the device.
    EVENT_UNLOCK = 2;
  }

  optional Event event = 1;
  // The version of the apex package on the device.
  optional int64 apex_version = 2;
}
