[RESTRICT AUTOMERGE] Do not resume activity if behind a translucent task
The top-focusable activity resides in the RESUMED state while the app process is newly created and attached. The behavior may enable UI hijacking attacks against apps implementing authentication. This CL disallows the system to resume the activity for the case if it is not visible or is occluded by other translucent tasks. Bug: 211481342 Test: atest CtsWindowManagerDeviceTestCases:ActivityLifecycleTests Change-Id: I7903494cf928b5b5613700262b7c5fff10f3c5a0
This commit is contained in:
@@ -97,7 +97,7 @@ class EnsureActivitiesVisibleHelper {
|
||||
// activities are actually behind other fullscreen activities, but still required
|
||||
// to be visible (such as performing Recents animation).
|
||||
final boolean resumeTopActivity = mTop != null && !mTop.mLaunchTaskBehind
|
||||
&& mTaskFragment.isTopActivityFocusable()
|
||||
&& mTaskFragment.canBeResumed(starting)
|
||||
&& (starting == null || !starting.isDescendantOf(mTaskFragment));
|
||||
|
||||
ArrayList<TaskFragment> adjacentTaskFragments = null;
|
||||
|
||||
@@ -1979,7 +1979,8 @@ class RootWindowContainer extends WindowContainer<DisplayContent>
|
||||
|
||||
try {
|
||||
if (mTaskSupervisor.realStartActivityLocked(r, app,
|
||||
top == r && r.isFocusable() /*andResume*/, true /*checkConfig*/)) {
|
||||
top == r && r.getTask().canBeResumed(r) /*andResume*/,
|
||||
true /*checkConfig*/)) {
|
||||
mTmpBoolean = true;
|
||||
}
|
||||
} catch (RemoteException e) {
|
||||
|
||||
Reference in New Issue
Block a user