From 63a1446971b20f7f1cc96e34142b680f322eeba1 Mon Sep 17 00:00:00 2001 From: Martijn Coenen Date: Tue, 28 Jan 2020 10:08:18 +0100 Subject: [PATCH] Don't leak local reference to BinderProxy. The local reference created by javaObjectForIBinder() in the death handling path is never freed, because it's not part of a regular JNI call. Use a ScopedLocalRef<> to make sure it gets freed when we no longer need it. Bug: 148181449 Test: adb shell dumpsys activity binder-proxies shows low dead nodes Change-Id: I031a46a310a06826bfadd77de7478b4342cf09ab --- core/jni/android_util_Binder.cpp | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/core/jni/android_util_Binder.cpp b/core/jni/android_util_Binder.cpp index fb8e633fec12f..e77c25efb1d4e 100644 --- a/core/jni/android_util_Binder.cpp +++ b/core/jni/android_util_Binder.cpp @@ -537,9 +537,10 @@ public: LOGDEATH("Receiving binderDied() on JavaDeathRecipient %p\n", this); if (mObject != NULL) { JNIEnv* env = javavm_to_jnienv(mVM); - jobject jBinderProxy = javaObjectForIBinder(env, who.promote()); + ScopedLocalRef jBinderProxy(env, javaObjectForIBinder(env, who.promote())); env->CallStaticVoidMethod(gBinderProxyOffsets.mClass, - gBinderProxyOffsets.mSendDeathNotice, mObject, jBinderProxy); + gBinderProxyOffsets.mSendDeathNotice, mObject, + jBinderProxy.get()); if (env->ExceptionCheck()) { jthrowable excep = env->ExceptionOccurred(); report_exception(env, excep,