[automerge] DO NOT MERGE: SurfaceControlViewHost: Restrict disclosure of input token 2p: 0cfda55b95

Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/17562439

Bug: 215912712
Change-Id: I3ba5c200fb3266a21b98909b5faa288a75c9fda6
This commit is contained in:
Presubmit Automerger Backend
2022-04-05 19:22:04 +00:00
6 changed files with 57 additions and 18 deletions

View File

@@ -306,7 +306,7 @@ interface IWindowSession {
*/ */
void grantInputChannel(int displayId, in SurfaceControl surface, in IWindow window, void grantInputChannel(int displayId, in SurfaceControl surface, in IWindow window,
in IBinder hostInputToken, int flags, int privateFlags, int type, in IBinder hostInputToken, int flags, int privateFlags, int type,
out InputChannel outInputChannel); in IBinder focusGrantToken, out InputChannel outInputChannel);
/** /**
* Update the flags on an input channel associated with a particular surface. * Update the flags on an input channel associated with a particular surface.

View File

@@ -231,7 +231,7 @@ public class SurfaceControlViewHost {
public @Nullable SurfacePackage getSurfacePackage() { public @Nullable SurfacePackage getSurfacePackage() {
if (mSurfaceControl != null && mAccessibilityEmbeddedConnection != null) { if (mSurfaceControl != null && mAccessibilityEmbeddedConnection != null) {
return new SurfacePackage(mSurfaceControl, mAccessibilityEmbeddedConnection, return new SurfacePackage(mSurfaceControl, mAccessibilityEmbeddedConnection,
mViewRoot.getInputToken()); mWm.getFocusGrantToken());
} else { } else {
return null; return null;
} }

View File

@@ -22,6 +22,7 @@ import android.graphics.PixelFormat;
import android.graphics.Point; import android.graphics.Point;
import android.graphics.Rect; import android.graphics.Rect;
import android.graphics.Region; import android.graphics.Region;
import android.os.Binder;
import android.os.IBinder; import android.os.IBinder;
import android.os.RemoteCallback; import android.os.RemoteCallback;
import android.os.RemoteException; import android.os.RemoteException;
@@ -75,6 +76,7 @@ public class WindowlessWindowManager implements IWindowSession {
private final Configuration mConfiguration; private final Configuration mConfiguration;
private final IWindowSession mRealWm; private final IWindowSession mRealWm;
private final IBinder mHostInputToken; private final IBinder mHostInputToken;
private final IBinder mFocusGrantToken = new Binder();
private int mForceHeight = -1; private int mForceHeight = -1;
private int mForceWidth = -1; private int mForceWidth = -1;
@@ -91,6 +93,10 @@ public class WindowlessWindowManager implements IWindowSession {
mConfiguration.setTo(configuration); mConfiguration.setTo(configuration);
} }
IBinder getFocusGrantToken() {
return mFocusGrantToken;
}
/** /**
* Utility API. * Utility API.
*/ */
@@ -153,10 +159,10 @@ public class WindowlessWindowManager implements IWindowSession {
mRealWm.grantInputChannel(displayId, mRealWm.grantInputChannel(displayId,
new SurfaceControl(sc, "WindowlessWindowManager.addToDisplay"), new SurfaceControl(sc, "WindowlessWindowManager.addToDisplay"),
window, mHostInputToken, attrs.flags, attrs.privateFlags, attrs.type, window, mHostInputToken, attrs.flags, attrs.privateFlags, attrs.type,
outInputChannel); mFocusGrantToken, outInputChannel);
} else { } else {
mRealWm.grantInputChannel(displayId, sc, window, mHostInputToken, attrs.flags, mRealWm.grantInputChannel(displayId, sc, window, mHostInputToken, attrs.flags,
attrs.privateFlags, attrs.type, outInputChannel); attrs.privateFlags, attrs.type, mFocusGrantToken, outInputChannel);
} }
} catch (RemoteException e) { } catch (RemoteException e) {
Log.e(TAG, "Failed to grant input to surface: ", e); Log.e(TAG, "Failed to grant input to surface: ", e);
@@ -464,7 +470,7 @@ public class WindowlessWindowManager implements IWindowSession {
@Override @Override
public void grantInputChannel(int displayId, SurfaceControl surface, IWindow window, public void grantInputChannel(int displayId, SurfaceControl surface, IWindow window,
IBinder hostInputToken, int flags, int privateFlags, int type, IBinder hostInputToken, int flags, int privateFlags, int type, IBinder focusGrantToken,
InputChannel outInputChannel) { InputChannel outInputChannel) {
} }

View File

@@ -41,6 +41,8 @@ class EmbeddedWindowController {
private static final String TAG = TAG_WITH_CLASS_NAME ? "EmbeddedWindowController" : TAG_WM; private static final String TAG = TAG_WITH_CLASS_NAME ? "EmbeddedWindowController" : TAG_WM;
/* maps input token to an embedded window */ /* maps input token to an embedded window */
private ArrayMap<IBinder /*input token */, EmbeddedWindow> mWindows = new ArrayMap<>(); private ArrayMap<IBinder /*input token */, EmbeddedWindow> mWindows = new ArrayMap<>();
private ArrayMap<IBinder /*focus grant token */, EmbeddedWindow> mWindowsByFocusToken =
new ArrayMap<>();
private final Object mGlobalLock; private final Object mGlobalLock;
private final ActivityTaskManagerService mAtmService; private final ActivityTaskManagerService mAtmService;
@@ -59,10 +61,13 @@ class EmbeddedWindowController {
void add(IBinder inputToken, EmbeddedWindow window) { void add(IBinder inputToken, EmbeddedWindow window) {
try { try {
mWindows.put(inputToken, window); mWindows.put(inputToken, window);
final IBinder focusToken = window.getFocusGrantToken();
mWindowsByFocusToken.put(focusToken, window);
updateProcessController(window); updateProcessController(window);
window.mClient.asBinder().linkToDeath(()-> { window.mClient.asBinder().linkToDeath(()-> {
synchronized (mGlobalLock) { synchronized (mGlobalLock) {
mWindows.remove(inputToken); mWindows.remove(inputToken);
mWindowsByFocusToken.remove(focusToken);
} }
}, 0); }, 0);
} catch (RemoteException e) { } catch (RemoteException e) {
@@ -95,8 +100,10 @@ class EmbeddedWindowController {
void remove(IWindow client) { void remove(IWindow client) {
for (int i = mWindows.size() - 1; i >= 0; i--) { for (int i = mWindows.size() - 1; i >= 0; i--) {
if (mWindows.valueAt(i).mClient.asBinder() == client.asBinder()) { EmbeddedWindow ew = mWindows.valueAt(i);
if (ew.mClient.asBinder() == client.asBinder()) {
mWindows.removeAt(i).onRemoved(); mWindows.removeAt(i).onRemoved();
mWindowsByFocusToken.remove(ew.getFocusGrantToken());
return; return;
} }
} }
@@ -104,8 +111,10 @@ class EmbeddedWindowController {
void onWindowRemoved(WindowState host) { void onWindowRemoved(WindowState host) {
for (int i = mWindows.size() - 1; i >= 0; i--) { for (int i = mWindows.size() - 1; i >= 0; i--) {
if (mWindows.valueAt(i).mHostWindowState == host) { EmbeddedWindow ew = mWindows.valueAt(i);
if (ew.mHostWindowState == host) {
mWindows.removeAt(i).onRemoved(); mWindows.removeAt(i).onRemoved();
mWindowsByFocusToken.remove(ew.getFocusGrantToken());
} }
} }
} }
@@ -114,6 +123,10 @@ class EmbeddedWindowController {
return mWindows.get(inputToken); return mWindows.get(inputToken);
} }
EmbeddedWindow getByFocusToken(IBinder focusGrantToken) {
return mWindowsByFocusToken.get(focusGrantToken);
}
void onActivityRemoved(ActivityRecord activityRecord) { void onActivityRemoved(ActivityRecord activityRecord) {
for (int i = mWindows.size() - 1; i >= 0; i--) { for (int i = mWindows.size() - 1; i >= 0; i--) {
final EmbeddedWindow window = mWindows.valueAt(i); final EmbeddedWindow window = mWindows.valueAt(i);
@@ -139,6 +152,8 @@ class EmbeddedWindowController {
InputChannel mInputChannel; InputChannel mInputChannel;
final int mWindowType; final int mWindowType;
private IBinder mFocusGrantToken;
/** /**
* @param session calling session to check ownership of the window * @param session calling session to check ownership of the window
* @param clientToken client token used to clean up the map if the embedding process dies * @param clientToken client token used to clean up the map if the embedding process dies
@@ -153,7 +168,7 @@ class EmbeddedWindowController {
*/ */
EmbeddedWindow(Session session, WindowManagerService service, IWindow clientToken, EmbeddedWindow(Session session, WindowManagerService service, IWindow clientToken,
WindowState hostWindowState, int ownerUid, int ownerPid, int windowType, WindowState hostWindowState, int ownerUid, int ownerPid, int windowType,
int displayId) { int displayId, IBinder focusGrantToken) {
mSession = session; mSession = session;
mWmService = service; mWmService = service;
mClient = clientToken; mClient = clientToken;
@@ -164,6 +179,7 @@ class EmbeddedWindowController {
mOwnerPid = ownerPid; mOwnerPid = ownerPid;
mWindowType = windowType; mWindowType = windowType;
mDisplayId = displayId; mDisplayId = displayId;
mFocusGrantToken = focusGrantToken;
} }
@Override @Override
@@ -216,5 +232,16 @@ class EmbeddedWindowController {
public int getPid() { public int getPid() {
return mOwnerPid; return mOwnerPid;
} }
IBinder getFocusGrantToken() {
return mFocusGrantToken;
}
IBinder getInputChannelToken() {
if (mInputChannel != null) {
return mInputChannel.getToken();
}
return null;
}
} }
} }

View File

@@ -807,7 +807,7 @@ class Session extends IWindowSession.Stub implements IBinder.DeathRecipient {
@Override @Override
public void grantInputChannel(int displayId, SurfaceControl surface, public void grantInputChannel(int displayId, SurfaceControl surface,
IWindow window, IBinder hostInputToken, int flags, int privateFlags, int type, IWindow window, IBinder hostInputToken, int flags, int privateFlags, int type,
InputChannel outInputChannel) { IBinder focusGrantToken, InputChannel outInputChannel) {
if (hostInputToken == null && !mCanAddInternalSystemWindow) { if (hostInputToken == null && !mCanAddInternalSystemWindow) {
// Callers without INTERNAL_SYSTEM_WINDOW permission cannot grant input channel to // Callers without INTERNAL_SYSTEM_WINDOW permission cannot grant input channel to
// embedded windows without providing a host window input token // embedded windows without providing a host window input token
@@ -823,7 +823,7 @@ class Session extends IWindowSession.Stub implements IBinder.DeathRecipient {
try { try {
mService.grantInputChannel(this, mUid, mPid, displayId, surface, window, hostInputToken, mService.grantInputChannel(this, mUid, mPid, displayId, surface, window, hostInputToken,
flags, mCanAddInternalSystemWindow ? privateFlags : 0, flags, mCanAddInternalSystemWindow ? privateFlags : 0,
mCanAddInternalSystemWindow ? type : 0, outInputChannel); mCanAddInternalSystemWindow ? type : 0, focusGrantToken, outInputChannel);
} finally { } finally {
Binder.restoreCallingIdentity(identity); Binder.restoreCallingIdentity(identity);
} }

View File

@@ -8374,7 +8374,8 @@ public class WindowManagerService extends IWindowManager.Stub
*/ */
void grantInputChannel(Session session, int callingUid, int callingPid, int displayId, void grantInputChannel(Session session, int callingUid, int callingPid, int displayId,
SurfaceControl surface, IWindow window, IBinder hostInputToken, SurfaceControl surface, IWindow window, IBinder hostInputToken,
int flags, int privateFlags, int type, InputChannel outInputChannel) { int flags, int privateFlags, int type, IBinder focusGrantToken,
InputChannel outInputChannel) {
final InputApplicationHandle applicationHandle; final InputApplicationHandle applicationHandle;
final String name; final String name;
final InputChannel clientChannel; final InputChannel clientChannel;
@@ -8382,7 +8383,7 @@ public class WindowManagerService extends IWindowManager.Stub
EmbeddedWindowController.EmbeddedWindow win = EmbeddedWindowController.EmbeddedWindow win =
new EmbeddedWindowController.EmbeddedWindow(session, this, window, new EmbeddedWindowController.EmbeddedWindow(session, this, window,
mInputToWindowMap.get(hostInputToken), callingUid, callingPid, type, mInputToWindowMap.get(hostInputToken), callingUid, callingPid, type,
displayId); displayId, focusGrantToken);
clientChannel = win.openInputChannel(); clientChannel = win.openInputChannel();
mEmbeddedWindowController.add(clientChannel.getToken(), win); mEmbeddedWindowController.add(clientChannel.getToken(), win);
applicationHandle = win.getApplicationHandle(); applicationHandle = win.getApplicationHandle();
@@ -8602,10 +8603,10 @@ public class WindowManagerService extends IWindowManager.Stub
} }
} }
void grantEmbeddedWindowFocus(Session session, IBinder inputToken, boolean grantFocus) { void grantEmbeddedWindowFocus(Session session, IBinder focusToken, boolean grantFocus) {
synchronized (mGlobalLock) { synchronized (mGlobalLock) {
final EmbeddedWindowController.EmbeddedWindow embeddedWindow = final EmbeddedWindowController.EmbeddedWindow embeddedWindow =
mEmbeddedWindowController.get(inputToken); mEmbeddedWindowController.getByFocusToken(focusToken);
if (embeddedWindow == null) { if (embeddedWindow == null) {
Slog.e(TAG, "Embedded window not found"); Slog.e(TAG, "Embedded window not found");
return; return;
@@ -8614,6 +8615,11 @@ public class WindowManagerService extends IWindowManager.Stub
Slog.e(TAG, "Window not in session:" + session); Slog.e(TAG, "Window not in session:" + session);
return; return;
} }
IBinder inputToken = embeddedWindow.getInputChannelToken();
if (inputToken == null) {
Slog.e(TAG, "Focus token found but input channel token not found");
return;
}
SurfaceControl.Transaction t = mTransactionFactory.get(); SurfaceControl.Transaction t = mTransactionFactory.get();
final int displayId = embeddedWindow.mDisplayId; final int displayId = embeddedWindow.mDisplayId;
if (grantFocus) { if (grantFocus) {
@@ -8643,7 +8649,7 @@ public class WindowManagerService extends IWindowManager.Stub
} }
} }
void grantEmbeddedWindowFocus(Session session, IWindow callingWindow, IBinder targetInputToken, void grantEmbeddedWindowFocus(Session session, IWindow callingWindow, IBinder targetFocusToken,
boolean grantFocus) { boolean grantFocus) {
synchronized (mGlobalLock) { synchronized (mGlobalLock) {
final WindowState hostWindow = final WindowState hostWindow =
@@ -8657,7 +8663,7 @@ public class WindowManagerService extends IWindowManager.Stub
return; return;
} }
final EmbeddedWindowController.EmbeddedWindow embeddedWindow = final EmbeddedWindowController.EmbeddedWindow embeddedWindow =
mEmbeddedWindowController.get(targetInputToken); mEmbeddedWindowController.getByFocusToken(targetFocusToken);
if (embeddedWindow == null) { if (embeddedWindow == null) {
Slog.e(TAG, "Embedded window not found"); Slog.e(TAG, "Embedded window not found");
return; return;
@@ -8668,7 +8674,7 @@ public class WindowManagerService extends IWindowManager.Stub
} }
SurfaceControl.Transaction t = mTransactionFactory.get(); SurfaceControl.Transaction t = mTransactionFactory.get();
if (grantFocus) { if (grantFocus) {
t.requestFocusTransfer(targetInputToken, embeddedWindow.toString(), t.requestFocusTransfer(embeddedWindow.getInputChannelToken(), embeddedWindow.toString(),
hostWindow.mInputChannel.getToken(), hostWindow.mInputChannel.getToken(),
hostWindow.getName(), hostWindow.getName(),
hostWindow.getDisplayId()).apply(); hostWindow.getDisplayId()).apply();
@@ -8677,7 +8683,7 @@ public class WindowManagerService extends IWindowManager.Stub
"reason=grantEmbeddedWindowFocus(true)"); "reason=grantEmbeddedWindowFocus(true)");
} else { } else {
t.requestFocusTransfer(hostWindow.mInputChannel.getToken(), hostWindow.getName(), t.requestFocusTransfer(hostWindow.mInputChannel.getToken(), hostWindow.getName(),
targetInputToken, embeddedWindow.getInputChannelToken(),
embeddedWindow.toString(), embeddedWindow.toString(),
hostWindow.getDisplayId()).apply(); hostWindow.getDisplayId()).apply();
EventLog.writeEvent(LOGTAG_INPUT_FOCUS, EventLog.writeEvent(LOGTAG_INPUT_FOCUS,