Don't expose raw IBinder APIs.

APIs should not expose raw IBinder objects.

Fix: 184735751
Test: builds, boots
Test: atest CtsNetTestCases:android.net.cts.ConnectivityManagerTest
Test: atest CtsNetTestCases:android.net.cts.DnsResolverTest
Change-Id: Ia0c4170def31123f0b79318fec2cfe02e4fcd3bf
This commit is contained in:
Lorenzo Colitti
2021-04-15 18:03:54 +09:00
parent fb7f36b3cb
commit 103e78ed48
5 changed files with 54 additions and 68 deletions

View File

@@ -6092,10 +6092,6 @@ package android.metrics {
package android.net {
public class DnsResolverServiceManager {
method @NonNull @RequiresPermission(android.net.NetworkStack.PERMISSION_MAINLINE_NETWORK_STACK) public static android.os.IBinder getService(@NonNull android.content.Context);
}
public class EthernetManager {
method @NonNull @RequiresPermission(anyOf={android.Manifest.permission.NETWORK_STACK, android.net.NetworkStack.PERMISSION_MAINLINE_NETWORK_STACK}) public android.net.EthernetManager.TetheredInterfaceRequest requestTetheredInterface(@NonNull java.util.concurrent.Executor, @NonNull android.net.EthernetManager.TetheredInterfaceCallback);
}

View File

@@ -1,63 +0,0 @@
/*
* Copyright (C) 2020 The Android Open Source Project
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package android.net;
import android.annotation.NonNull;
import android.annotation.RequiresPermission;
import android.annotation.SystemApi;
import android.content.Context;
import android.os.IBinder;
import android.os.ServiceManager;
import java.util.Objects;
/**
* Provides a way to obtain the DnsResolver binder objects.
*
* @hide
*/
@SystemApi
public class DnsResolverServiceManager {
/**
* Name to retrieve a {@link android.net.IDnsResolver} IBinder.
*/
private static final String DNS_RESOLVER_SERVICE = "dnsresolver";
private DnsResolverServiceManager() {}
/**
* Get an {@link IBinder} representing the DnsResolver stable AIDL interface
*
* @param context the context for permission check.
* @return {@link android.net.IDnsResolver} IBinder.
*/
@NonNull
@RequiresPermission(NetworkStack.PERMISSION_MAINLINE_NETWORK_STACK)
public static IBinder getService(@NonNull final Context context) {
Objects.requireNonNull(context);
context.enforceCallingOrSelfPermission(NetworkStack.PERMISSION_MAINLINE_NETWORK_STACK,
"DnsResolverServiceManager");
try {
return ServiceManager.getServiceOrThrow(DNS_RESOLVER_SERVICE);
} catch (ServiceManager.ServiceNotFoundException e) {
// Catch ServiceManager#ServiceNotFoundException and rethrow IllegalStateException
// because ServiceManager#ServiceNotFoundException is @hide so that it can't be listed
// on the system api. Thus, rethrow IllegalStateException if dns resolver service cannot
// be found.
throw new IllegalStateException("Cannot find dns resolver service.");
}
}
}

View File

@@ -68,5 +68,11 @@ public final class ConnectivityFrameworkInitializer {
return cm.startOrGetTestNetworkManager();
}
);
SystemServiceRegistry.registerContextAwareService(
DnsResolverServiceManager.DNS_RESOLVER_SERVICE,
DnsResolverServiceManager.class,
(context, serviceBinder) -> new DnsResolverServiceManager(serviceBinder)
);
}
}

View File

@@ -0,0 +1,45 @@
/*
* Copyright (C) 2020 The Android Open Source Project
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package android.net;
import android.annotation.NonNull;
import android.os.IBinder;
/**
* Provides a way to obtain the DnsResolver binder objects.
*
* @hide
*/
public class DnsResolverServiceManager {
/** Service name for the DNS resolver. Keep in sync with DnsResolverService.h */
public static final String DNS_RESOLVER_SERVICE = "dnsresolver";
private final IBinder mResolver;
DnsResolverServiceManager(IBinder resolver) {
mResolver = resolver;
}
/**
* Get an {@link IBinder} representing the DnsResolver stable AIDL interface
*
* @return {@link android.net.IDnsResolver} IBinder.
*/
@NonNull
public IBinder getService() {
return mResolver;
}
}

View File

@@ -616,7 +616,9 @@ public class ConnectivityService extends IConnectivityManager.Stub
}
private static IDnsResolver getDnsResolver(Context context) {
return IDnsResolver.Stub.asInterface(DnsResolverServiceManager.getService(context));
final DnsResolverServiceManager dsm = context.getSystemService(
DnsResolverServiceManager.class);
return IDnsResolver.Stub.asInterface(dsm.getService());
}
/** Handler thread used for all of the handlers below. */