From 7592825084cd316af7c12423d1d8484eb31f4a85 Mon Sep 17 00:00:00 2001 From: Amith Yamasani Date: Mon, 22 May 2017 15:10:47 -0700 Subject: [PATCH] Don't keep a reference to Service object This is a potential fix for a global reference leak in the system process by a JobService in an app. Bug: 38467796 Test: manual Change-Id: I8756c39ac77bead068c88fce750c4024f9ac1c03 --- core/java/android/app/ActivityThread.java | 1 + core/java/android/app/Service.java | 10 +++++++++- core/java/android/app/job/JobServiceEngine.java | 12 +----------- 3 files changed, 11 insertions(+), 12 deletions(-) diff --git a/core/java/android/app/ActivityThread.java b/core/java/android/app/ActivityThread.java index 928ef7e3863d1..01e4ccebe82f6 100644 --- a/core/java/android/app/ActivityThread.java +++ b/core/java/android/app/ActivityThread.java @@ -3567,6 +3567,7 @@ public final class ActivityThread { try { if (localLOGV) Slog.v(TAG, "Destroying service " + s); s.onDestroy(); + s.detachAndCleanUp(); Context context = s.getBaseContext(); if (context instanceof ContextImpl) { final String who = s.getClassName(); diff --git a/core/java/android/app/Service.java b/core/java/android/app/Service.java index 10d6a7b02377a..256c47934dc54 100644 --- a/core/java/android/app/Service.java +++ b/core/java/android/app/Service.java @@ -767,7 +767,15 @@ public abstract class Service extends ContextWrapper implements ComponentCallbac mStartCompatibility = getApplicationInfo().targetSdkVersion < Build.VERSION_CODES.ECLAIR; } - + + /** + * @hide + * Clean up any references to avoid leaks. + */ + public final void detachAndCleanUp() { + mToken = null; + } + final String getClassName() { return mClassName; } diff --git a/core/java/android/app/job/JobServiceEngine.java b/core/java/android/app/job/JobServiceEngine.java index b7d759b27c017..b0ec6502c4b1b 100644 --- a/core/java/android/app/job/JobServiceEngine.java +++ b/core/java/android/app/job/JobServiceEngine.java @@ -55,21 +55,12 @@ public abstract class JobServiceEngine { */ private static final int MSG_JOB_FINISHED = 2; - /** - * Context we are running in. - */ - private final Service mService; - private final IJobService mBinder; - /** Lock object for {@link #mHandler}. */ - private final Object mHandlerLock = new Object(); - /** * Handler we post jobs to. Responsible for calling into the client logic, and handling the * callback to the system. */ - @GuardedBy("mHandlerLock") JobHandler mHandler; static final class JobInterface extends IJobService.Stub { @@ -189,9 +180,8 @@ public abstract class JobServiceEngine { * @param service The {@link Service} that is creating this engine and in which it will run. */ public JobServiceEngine(Service service) { - mService = service; mBinder = new JobInterface(this); - mHandler = new JobHandler(mService.getMainLooper()); + mHandler = new JobHandler(service.getMainLooper()); } /**