Clear the Parcel before writing an exception during a transaction
This prevents any object data from being accidentally overwritten by the
exception, which could cause unexpected malformed objects to be sent
across the transaction.
Test: atest CtsOsTestCases:ParcelTest#testExceptionOverwritesObject
Bug: 34175893
Change-Id: Iaf80a0ad711762992b8ae60f76d861c97a403013
Merged-In: Iaf80a0ad711762992b8ae60f76d861c97a403013
(cherry picked from commit f8ef5bcf21)
This commit is contained in:
committed by
android-build-team Robot
parent
205e540a64
commit
1924f6d94d
@@ -740,6 +740,8 @@ public class Binder implements IBinder {
|
||||
Log.w(TAG, "Caught a RuntimeException from the binder stub implementation.", e);
|
||||
}
|
||||
} else {
|
||||
// Clear the parcel before writing the exception
|
||||
reply.setDataSize(0);
|
||||
reply.setDataPosition(0);
|
||||
reply.writeException(e);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user