Final token from Binder.clearCallingIdentity()

The result from Binder.clearCallingIdentity() should be final in order
to prevent it from being overwritten before calling
Binder.restoreCallingIdentity(), which can cause security problems when
restoring the identity.

Bug: 157626959
Test: m checkbuild
Change-Id: I45e0e29fcefc35afa70d50dabfb79ada1579eae8
This commit is contained in:
Azhara Assanova
2021-05-21 13:03:24 +00:00
parent f9b2ab02dc
commit 340f6d4d52
10 changed files with 24 additions and 24 deletions

View File

@@ -4369,7 +4369,7 @@ public class UserBackupManagerService {
return OperationType.BACKUP;
}
long oldCallingId = Binder.clearCallingIdentity();
final long oldCallingId = Binder.clearCallingIdentity();
try {
IBackupTransport transport = transportClient.connectOrThrow(
/* caller */ "BMS.getOperationTypeFromTransport");

View File

@@ -787,7 +787,7 @@ public class CompanionDeviceManagerService extends SystemService implements Bind
+ " for " + association
+ " - profile still present in " + otherAssociationWithDeviceProfile);
} else {
long identity = Binder.clearCallingIdentity();
final long identity = Binder.clearCallingIdentity();
try {
mRoleManager.removeRoleHolderAsUser(
association.getDeviceProfile(),
@@ -1001,7 +1001,7 @@ public class CompanionDeviceManagerService extends SystemService implements Bind
}
private List<UserInfo> getAllUsers() {
long identity = Binder.clearCallingIdentity();
final long identity = Binder.clearCallingIdentity();
try {
return mUserManager.getUsers();
} finally {
@@ -1017,7 +1017,7 @@ public class CompanionDeviceManagerService extends SystemService implements Bind
}
private Set<Association> getAllAssociations() {
long identity = Binder.clearCallingIdentity();
final long identity = Binder.clearCallingIdentity();
try {
ArraySet<Association> result = new ArraySet<>();
for (UserInfo user : mUserManager.getAliveUsers()) {

View File

@@ -265,7 +265,7 @@ public final class SensorPrivacyService extends SystemService {
sensor = CAMERA;
}
long token = Binder.clearCallingIdentity();
final long token = Binder.clearCallingIdentity();
try {
onSensorUseStarted(uid, packageName, sensor);
} finally {
@@ -484,7 +484,7 @@ public final class SensorPrivacyService extends SystemService {
mIndividualEnabled.put(userId, userIndividualEnabled);
if (!enable) {
long token = Binder.clearCallingIdentity();
final long token = Binder.clearCallingIdentity();
try {
// Remove any notifications prompting the user to disable sensory privacy
NotificationManager notificationManager =

View File

@@ -3459,7 +3459,7 @@ class StorageManagerService extends IStorageManager.Stub
// We want to call the manageSpaceActivity as a SystemService and clear identity
// of the calling App
int originalUid = Binder.getCallingUidOrThrow();
long token = Binder.clearCallingIdentity();
final long token = Binder.clearCallingIdentity();
try {
ApplicationInfo appInfo = mIPackageManager.getApplicationInfo(packageName, 0,

View File

@@ -262,7 +262,7 @@ public class FingerprintService extends SystemService {
final boolean isKeyguard = Utils.isKeyguard(getContext(), opPackageName);
// Clear calling identity when checking LockPatternUtils for StrongAuth flags.
long identity = Binder.clearCallingIdentity();
final long identity1 = Binder.clearCallingIdentity();
try {
if (isKeyguard && Utils.isUserEncryptedOrLockdown(mLockPatternUtils, userId)) {
// If this happens, something in KeyguardUpdateMonitor is wrong.
@@ -272,7 +272,7 @@ public class FingerprintService extends SystemService {
return;
}
} finally {
Binder.restoreCallingIdentity(identity);
Binder.restoreCallingIdentity(identity1);
}
final boolean restricted = getContext().checkCallingPermission(MANAGE_FINGERPRINT)
@@ -296,11 +296,11 @@ public class FingerprintService extends SystemService {
provider.second.getSensorProperties(sensorId);
if (!isKeyguard && !Utils.isSettings(getContext(), opPackageName)
&& sensorProps != null && sensorProps.isAnyUdfpsType()) {
identity = Binder.clearCallingIdentity();
final long identity2 = Binder.clearCallingIdentity();
try {
authenticateWithPrompt(operationId, sensorProps, userId, receiver);
} finally {
Binder.restoreCallingIdentity(identity);
Binder.restoreCallingIdentity(identity2);
}
} else {
provider.second.scheduleAuthenticate(provider.first, token, operationId, userId,

View File

@@ -2292,7 +2292,7 @@ public class HdmiControlService extends SystemService {
@Override
public List<String> getUserCecSettings() {
initBinderCall();
long token = Binder.clearCallingIdentity();
final long token = Binder.clearCallingIdentity();
try {
return HdmiControlService.this.getHdmiCecConfig().getUserSettings();
} finally {
@@ -2303,7 +2303,7 @@ public class HdmiControlService extends SystemService {
@Override
public List<String> getAllowedCecSettingStringValues(String name) {
initBinderCall();
long token = Binder.clearCallingIdentity();
final long token = Binder.clearCallingIdentity();
try {
return HdmiControlService.this.getHdmiCecConfig().getAllowedStringValues(name);
} finally {
@@ -2314,7 +2314,7 @@ public class HdmiControlService extends SystemService {
@Override
public int[] getAllowedCecSettingIntValues(String name) {
initBinderCall();
long token = Binder.clearCallingIdentity();
final long token = Binder.clearCallingIdentity();
try {
List<Integer> allowedValues =
HdmiControlService.this.getHdmiCecConfig().getAllowedIntValues(name);
@@ -2327,7 +2327,7 @@ public class HdmiControlService extends SystemService {
@Override
public String getCecSettingStringValue(String name) {
initBinderCall();
long token = Binder.clearCallingIdentity();
final long token = Binder.clearCallingIdentity();
try {
return HdmiControlService.this.getHdmiCecConfig().getStringValue(name);
} finally {
@@ -2338,7 +2338,7 @@ public class HdmiControlService extends SystemService {
@Override
public void setCecSettingStringValue(String name, String value) {
initBinderCall();
long token = Binder.clearCallingIdentity();
final long token = Binder.clearCallingIdentity();
try {
HdmiControlService.this.getHdmiCecConfig().setStringValue(name, value);
} finally {
@@ -2349,7 +2349,7 @@ public class HdmiControlService extends SystemService {
@Override
public int getCecSettingIntValue(String name) {
initBinderCall();
long token = Binder.clearCallingIdentity();
final long token = Binder.clearCallingIdentity();
try {
return HdmiControlService.this.getHdmiCecConfig().getIntValue(name);
} finally {
@@ -2360,7 +2360,7 @@ public class HdmiControlService extends SystemService {
@Override
public void setCecSettingIntValue(String name, int value) {
initBinderCall();
long token = Binder.clearCallingIdentity();
final long token = Binder.clearCallingIdentity();
try {
HdmiControlService.this.getHdmiCecConfig().setIntValue(name, value);
} finally {

View File

@@ -82,7 +82,7 @@ public class GnssAntennaInfoProvider extends
}
public void addListener(CallerIdentity callerIdentity, IGnssAntennaInfoListener listener) {
long identity = Binder.clearCallingIdentity();
final long identity = Binder.clearCallingIdentity();
try {
putRegistration(listener.asBinder(),
new AntennaInfoListenerRegistration(callerIdentity, listener));
@@ -92,7 +92,7 @@ public class GnssAntennaInfoProvider extends
}
public void removeListener(IGnssAntennaInfoListener listener) {
long identity = Binder.clearCallingIdentity();
final long identity = Binder.clearCallingIdentity();
try {
removeRegistration(listener.asBinder());
} finally {

View File

@@ -331,7 +331,7 @@ public class GnssManagerService {
@Override
public void onCapabilitiesChanged(GnssCapabilities oldCapabilities,
GnssCapabilities newCapabilities) {
long ident = Binder.clearCallingIdentity();
final long ident = Binder.clearCallingIdentity();
try {
Intent intent = new Intent(LocationManager.ACTION_GNSS_CAPABILITIES_CHANGED)
.putExtra(LocationManager.EXTRA_GNSS_CAPABILITIES, newCapabilities)

View File

@@ -41,7 +41,7 @@ public class SystemDeviceStationaryHelper extends DeviceStationaryHelper {
public void addListener(DeviceIdleInternal.StationaryListener listener) {
Preconditions.checkState(mDeviceIdle != null);
long identity = Binder.clearCallingIdentity();
final long identity = Binder.clearCallingIdentity();
try {
mDeviceIdle.registerStationaryListener(listener);
} finally {
@@ -53,7 +53,7 @@ public class SystemDeviceStationaryHelper extends DeviceStationaryHelper {
public void removeListener(DeviceIdleInternal.StationaryListener listener) {
Preconditions.checkState(mDeviceIdle != null);
long identity = Binder.clearCallingIdentity();
final long identity = Binder.clearCallingIdentity();
try {
mDeviceIdle.unregisterStationaryListener(listener);
} finally {

View File

@@ -1620,7 +1620,7 @@ public class LockSettingsService extends ILockSettings.Stub {
+ PERMISSION);
}
long identity = Binder.clearCallingIdentity();
final long identity = Binder.clearCallingIdentity();
try {
enforceFrpResolved();
// When changing credential for profiles with unified challenge, some callers