Merge "Add more checks for bad values to protect from corrupt files." into gingerbread
This commit is contained in:
committed by
Android (Google) Code Review
commit
42a23783aa
@@ -3077,13 +3077,18 @@ public final class BatteryStatsImpl extends BatteryStats {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
void readExcessivePowerFromParcelLocked(Parcel in) {
|
boolean readExcessivePowerFromParcelLocked(Parcel in) {
|
||||||
final int N = in.readInt();
|
final int N = in.readInt();
|
||||||
if (N == 0) {
|
if (N == 0) {
|
||||||
mExcessivePower = null;
|
mExcessivePower = null;
|
||||||
return;
|
return true;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (N > 10000) {
|
||||||
|
Slog.w(TAG, "File corrupt: too many excessive power entries " + N);
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
mExcessivePower = new ArrayList<ExcessivePower>();
|
mExcessivePower = new ArrayList<ExcessivePower>();
|
||||||
for (int i=0; i<N; i++) {
|
for (int i=0; i<N; i++) {
|
||||||
ExcessivePower ew = new ExcessivePower();
|
ExcessivePower ew = new ExcessivePower();
|
||||||
@@ -3092,6 +3097,7 @@ public final class BatteryStatsImpl extends BatteryStats {
|
|||||||
ew.usedTime = in.readLong();
|
ew.usedTime = in.readLong();
|
||||||
mExcessivePower.add(ew);
|
mExcessivePower.add(ew);
|
||||||
}
|
}
|
||||||
|
return true;
|
||||||
}
|
}
|
||||||
|
|
||||||
void writeToParcelLocked(Parcel out) {
|
void writeToParcelLocked(Parcel out) {
|
||||||
@@ -4687,7 +4693,7 @@ public final class BatteryStatsImpl extends BatteryStats {
|
|||||||
}
|
}
|
||||||
|
|
||||||
int NW = in.readInt();
|
int NW = in.readInt();
|
||||||
if (NW > 10000) {
|
if (NW > 100) {
|
||||||
Slog.w(TAG, "File corrupt: too many wake locks " + NW);
|
Slog.w(TAG, "File corrupt: too many wake locks " + NW);
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
@@ -4705,7 +4711,7 @@ public final class BatteryStatsImpl extends BatteryStats {
|
|||||||
}
|
}
|
||||||
|
|
||||||
int NP = in.readInt();
|
int NP = in.readInt();
|
||||||
if (NP > 10000) {
|
if (NP > 1000) {
|
||||||
Slog.w(TAG, "File corrupt: too many sensors " + NP);
|
Slog.w(TAG, "File corrupt: too many sensors " + NP);
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
@@ -4718,7 +4724,7 @@ public final class BatteryStatsImpl extends BatteryStats {
|
|||||||
}
|
}
|
||||||
|
|
||||||
NP = in.readInt();
|
NP = in.readInt();
|
||||||
if (NP > 10000) {
|
if (NP > 1000) {
|
||||||
Slog.w(TAG, "File corrupt: too many processes " + NP);
|
Slog.w(TAG, "File corrupt: too many processes " + NP);
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
@@ -4729,6 +4735,10 @@ public final class BatteryStatsImpl extends BatteryStats {
|
|||||||
p.mSystemTime = p.mLoadedSystemTime = in.readLong();
|
p.mSystemTime = p.mLoadedSystemTime = in.readLong();
|
||||||
p.mStarts = p.mLoadedStarts = in.readInt();
|
p.mStarts = p.mLoadedStarts = in.readInt();
|
||||||
int NSB = in.readInt();
|
int NSB = in.readInt();
|
||||||
|
if (NSB > 100) {
|
||||||
|
Slog.w(TAG, "File corrupt: too many speed bins " + NSB);
|
||||||
|
return;
|
||||||
|
}
|
||||||
p.mSpeedBins = new SamplingCounter[NSB];
|
p.mSpeedBins = new SamplingCounter[NSB];
|
||||||
for (int i=0; i<NSB; i++) {
|
for (int i=0; i<NSB; i++) {
|
||||||
if (in.readInt() != 0) {
|
if (in.readInt() != 0) {
|
||||||
@@ -4736,7 +4746,9 @@ public final class BatteryStatsImpl extends BatteryStats {
|
|||||||
p.mSpeedBins[i].readSummaryFromParcelLocked(in);
|
p.mSpeedBins[i].readSummaryFromParcelLocked(in);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
p.readExcessivePowerFromParcelLocked(in);
|
if (!p.readExcessivePowerFromParcelLocked(in)) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
NP = in.readInt();
|
NP = in.readInt();
|
||||||
@@ -4749,6 +4761,10 @@ public final class BatteryStatsImpl extends BatteryStats {
|
|||||||
Uid.Pkg p = u.getPackageStatsLocked(pkgName);
|
Uid.Pkg p = u.getPackageStatsLocked(pkgName);
|
||||||
p.mWakeups = p.mLoadedWakeups = in.readInt();
|
p.mWakeups = p.mLoadedWakeups = in.readInt();
|
||||||
final int NS = in.readInt();
|
final int NS = in.readInt();
|
||||||
|
if (NS > 1000) {
|
||||||
|
Slog.w(TAG, "File corrupt: too many services " + NS);
|
||||||
|
return;
|
||||||
|
}
|
||||||
for (int is = 0; is < NS; is++) {
|
for (int is = 0; is < NS; is++) {
|
||||||
String servName = in.readString();
|
String servName = in.readString();
|
||||||
Uid.Pkg.Serv s = u.getServiceStatsLocked(pkgName, servName);
|
Uid.Pkg.Serv s = u.getServiceStatsLocked(pkgName, servName);
|
||||||
|
|||||||
Reference in New Issue
Block a user