Merge changes from topic "presubmit-am-1ab3ffc180ef400a970f85dbe14238c7-sc-dev" into sc-qpr1-dev

* changes:
  [automerge] [Ongoing Call] Don't call #getIntent to avoid a security vulnerability. 2p: b029b005d8
  [Ongoing Call] Don't call #getIntent to avoid a security vulnerability.
This commit is contained in:
TreeHugger Robot
2022-03-08 18:57:57 +00:00
committed by Android (Google) Code Review
2 changed files with 16 additions and 6 deletions

View File

@@ -21,7 +21,7 @@ import android.app.IActivityManager
import android.app.IUidObserver import android.app.IUidObserver
import android.app.Notification import android.app.Notification
import android.app.Notification.CallStyle.CALL_TYPE_ONGOING import android.app.Notification.CallStyle.CALL_TYPE_ONGOING
import android.content.Intent import android.app.PendingIntent
import android.util.Log import android.util.Log
import android.view.View import android.view.View
import android.widget.Chronometer import android.widget.Chronometer
@@ -86,7 +86,7 @@ class OngoingCallController @Inject constructor(
val newOngoingCallInfo = CallNotificationInfo( val newOngoingCallInfo = CallNotificationInfo(
entry.sbn.key, entry.sbn.key,
entry.sbn.notification.`when`, entry.sbn.notification.`when`,
entry.sbn.notification.contentIntent?.intent, entry.sbn.notification.contentIntent,
entry.sbn.uid, entry.sbn.uid,
entry.sbn.notification.extras.getInt( entry.sbn.notification.extras.getInt(
Notification.EXTRA_CALL_TYPE, -1) == CALL_TYPE_ONGOING Notification.EXTRA_CALL_TYPE, -1) == CALL_TYPE_ONGOING
@@ -197,7 +197,6 @@ class OngoingCallController @Inject constructor(
logger.logChipClicked() logger.logChipClicked()
activityStarter.postStartActivityDismissingKeyguard( activityStarter.postStartActivityDismissingKeyguard(
intent, intent,
0,
ActivityLaunchAnimator.Controller.fromView( ActivityLaunchAnimator.Controller.fromView(
backgroundView, backgroundView,
InteractionJankMonitor.CUJ_STATUS_BAR_APP_LAUNCH_FROM_CALL_CHIP) InteractionJankMonitor.CUJ_STATUS_BAR_APP_LAUNCH_FROM_CALL_CHIP)
@@ -286,7 +285,7 @@ class OngoingCallController @Inject constructor(
private data class CallNotificationInfo( private data class CallNotificationInfo(
val key: String, val key: String,
val callStartTime: Long, val callStartTime: Long,
val intent: Intent?, val intent: PendingIntent?,
val uid: Int, val uid: Int,
/** True if the call is currently ongoing (as opposed to incoming, screening, etc.). */ /** True if the call is currently ongoing (as opposed to incoming, screening, etc.). */
val isOngoing: Boolean val isOngoing: Boolean

View File

@@ -22,7 +22,6 @@ import android.app.IUidObserver
import android.app.Notification import android.app.Notification
import android.app.PendingIntent import android.app.PendingIntent
import android.app.Person import android.app.Person
import android.content.Intent
import android.service.notification.NotificationListenerService.REASON_USER_STOPPED import android.service.notification.NotificationListenerService.REASON_USER_STOPPED
import android.testing.AndroidTestingRunner import android.testing.AndroidTestingRunner
import android.testing.TestableLooper import android.testing.TestableLooper
@@ -413,6 +412,19 @@ class OngoingCallControllerTest : SysuiTestCase() {
.isEqualTo(OngoingCallLogger.OngoingCallEvents.ONGOING_CALL_CLICKED.id) .isEqualTo(OngoingCallLogger.OngoingCallEvents.ONGOING_CALL_CLICKED.id)
} }
/** Regression test for b/212467440. */
@Test
fun chipClicked_activityStarterTriggeredWithUnmodifiedIntent() {
val notifEntry = createOngoingCallNotifEntry()
val pendingIntent = notifEntry.sbn.notification.contentIntent
notifCollectionListener.onEntryUpdated(notifEntry)
chipView.performClick()
// Ensure that the sysui didn't modify the notification's intent -- see b/212467440.
verify(mockActivityStarter).postStartActivityDismissingKeyguard(eq(pendingIntent), any())
}
@Test @Test
fun notifyChipVisibilityChanged_visibleEventLogged() { fun notifyChipVisibilityChanged_visibleEventLogged() {
controller.notifyChipVisibilityChanged(true) controller.notifyChipVisibilityChanged(true)
@@ -440,7 +452,6 @@ class OngoingCallControllerTest : SysuiTestCase() {
notificationEntryBuilder.modifyNotification(context).setContentIntent(null) notificationEntryBuilder.modifyNotification(context).setContentIntent(null)
} else { } else {
val contentIntent = mock(PendingIntent::class.java) val contentIntent = mock(PendingIntent::class.java)
`when`(contentIntent.intent).thenReturn(mock(Intent::class.java))
notificationEntryBuilder.modifyNotification(context).setContentIntent(contentIntent) notificationEntryBuilder.modifyNotification(context).setContentIntent(contentIntent)
} }