From 26c93c94c90f1f84fa607bdec40e6aff7555cf83 Mon Sep 17 00:00:00 2001 From: Tetsutoki Shiozawa Date: Fri, 23 Feb 2018 13:16:56 +0900 Subject: [PATCH] Fix: Double-free error on RemoteFillService Symptom: RemoteFillService was crashed due to IllegalArgumentException "Service not registered:" at onServiceConnected. Root cause: RemoteFillService#onServiceConnected tries to unbind the connection if mDestroyed is flagged or mBinding is not flagged. It always fails with IllegalArgumentException. Both mDestroyed and !mBinding mean the connection was unbound. You can't unbind the unbound connection. It's not allowed. Fixes: 73864601 Fixes: 69905688 Change-Id: If5481468ddac7be41accad63e9d5382bc6c029fd --- .../java/com/android/server/autofill/RemoteFillService.java | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/services/autofill/java/com/android/server/autofill/RemoteFillService.java b/services/autofill/java/com/android/server/autofill/RemoteFillService.java index af55807ff1f04..93df507477237 100644 --- a/services/autofill/java/com/android/server/autofill/RemoteFillService.java +++ b/services/autofill/java/com/android/server/autofill/RemoteFillService.java @@ -342,7 +342,8 @@ final class RemoteFillService implements DeathRecipient { @Override public void onServiceConnected(ComponentName name, IBinder service) { if (mDestroyed || !mBinding) { - mContext.unbindService(mServiceConnection); + // This is abnormal. Unbinding the connection has been requested already. + Slog.wtf(LOG_TAG, "onServiceConnected was dispatched after unbindService."); return; } mBinding = false;