Merge commit 'ea8eafad4f5438ec1291d45376959a996d36e15e' * commit 'ea8eafad4f5438ec1291d45376959a996d36e15e': Make bad notifications crash their application.
This commit is contained in:
@@ -1293,6 +1293,17 @@ public abstract class ActivityManagerNative extends Binder implements IActivityM
|
||||
return true;
|
||||
}
|
||||
|
||||
case CRASH_APPLICATION_TRANSACTION: {
|
||||
data.enforceInterface(IActivityManager.descriptor);
|
||||
int uid = data.readInt();
|
||||
int initialPid = data.readInt();
|
||||
String packageName = data.readString();
|
||||
String message = data.readString();
|
||||
crashApplication(uid, initialPid, packageName, message);
|
||||
reply.writeNoException();
|
||||
return true;
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
return super.onTransact(code, data, reply, flags);
|
||||
@@ -2867,5 +2878,20 @@ class ActivityManagerProxy implements IActivityManager
|
||||
return res;
|
||||
}
|
||||
|
||||
public void crashApplication(int uid, int initialPid, String packageName,
|
||||
String message) throws RemoteException {
|
||||
Parcel data = Parcel.obtain();
|
||||
Parcel reply = Parcel.obtain();
|
||||
data.writeInterfaceToken(IActivityManager.descriptor);
|
||||
data.writeInt(uid);
|
||||
data.writeInt(initialPid);
|
||||
data.writeString(packageName);
|
||||
data.writeString(message);
|
||||
mRemote.transact(CRASH_APPLICATION_TRANSACTION, data, reply, 0);
|
||||
reply.readException();
|
||||
data.recycle();
|
||||
reply.recycle();
|
||||
}
|
||||
|
||||
private IBinder mRemote;
|
||||
}
|
||||
|
||||
@@ -100,6 +100,12 @@ final class SuperNotCalledException extends AndroidRuntimeException {
|
||||
}
|
||||
}
|
||||
|
||||
final class RemoteServiceException extends AndroidRuntimeException {
|
||||
public RemoteServiceException(String msg) {
|
||||
super(msg);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* This manages the execution of the main thread in an
|
||||
* application process, scheduling and executing activities,
|
||||
@@ -644,6 +650,10 @@ public final class ActivityThread {
|
||||
public void dispatchPackageBroadcast(int cmd, String[] packages) {
|
||||
queueOrSendMessage(H.DISPATCH_PACKAGE_BROADCAST, packages, cmd);
|
||||
}
|
||||
|
||||
public void scheduleCrash(String msg) {
|
||||
queueOrSendMessage(H.SCHEDULE_CRASH, msg);
|
||||
}
|
||||
|
||||
@Override
|
||||
protected void dump(FileDescriptor fd, PrintWriter pw, String[] args) {
|
||||
@@ -871,6 +881,7 @@ public final class ActivityThread {
|
||||
public static final int REMOVE_PROVIDER = 131;
|
||||
public static final int ENABLE_JIT = 132;
|
||||
public static final int DISPATCH_PACKAGE_BROADCAST = 133;
|
||||
public static final int SCHEDULE_CRASH = 134;
|
||||
String codeToString(int code) {
|
||||
if (localLOGV) {
|
||||
switch (code) {
|
||||
@@ -908,6 +919,7 @@ public final class ActivityThread {
|
||||
case REMOVE_PROVIDER: return "REMOVE_PROVIDER";
|
||||
case ENABLE_JIT: return "ENABLE_JIT";
|
||||
case DISPATCH_PACKAGE_BROADCAST: return "DISPATCH_PACKAGE_BROADCAST";
|
||||
case SCHEDULE_CRASH: return "SCHEDULE_CRASH";
|
||||
}
|
||||
}
|
||||
return "(unknown)";
|
||||
@@ -1031,6 +1043,8 @@ public final class ActivityThread {
|
||||
case DISPATCH_PACKAGE_BROADCAST:
|
||||
handleDispatchPackageBroadcast(msg.arg1, (String[])msg.obj);
|
||||
break;
|
||||
case SCHEDULE_CRASH:
|
||||
throw new RemoteServiceException((String)msg.obj);
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -402,6 +402,14 @@ public abstract class ApplicationThreadNative extends Binder
|
||||
dispatchPackageBroadcast(cmd, packages);
|
||||
return true;
|
||||
}
|
||||
|
||||
case SCHEDULE_CRASH_TRANSACTION:
|
||||
{
|
||||
data.enforceInterface(IApplicationThread.descriptor);
|
||||
String msg = data.readString();
|
||||
scheduleCrash(msg);
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
return super.onTransact(code, data, reply, flags);
|
||||
@@ -826,5 +834,15 @@ class ApplicationThreadProxy implements IApplicationThread {
|
||||
data.recycle();
|
||||
|
||||
}
|
||||
|
||||
public void scheduleCrash(String msg) throws RemoteException {
|
||||
Parcel data = Parcel.obtain();
|
||||
data.writeInterfaceToken(IApplicationThread.descriptor);
|
||||
data.writeString(msg);
|
||||
mRemote.transact(SCHEDULE_CRASH_TRANSACTION, data, null,
|
||||
IBinder.FLAG_ONEWAY);
|
||||
data.recycle();
|
||||
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -316,6 +316,9 @@ public interface IActivityManager extends IInterface {
|
||||
public boolean isImmersive(IBinder token) throws RemoteException;
|
||||
public boolean isTopActivityImmersive() throws RemoteException;
|
||||
|
||||
public void crashApplication(int uid, int initialPid, String packageName,
|
||||
String message) throws RemoteException;
|
||||
|
||||
/*
|
||||
* Private non-Binder interfaces
|
||||
*/
|
||||
@@ -531,4 +534,5 @@ public interface IActivityManager extends IInterface {
|
||||
int IS_IMMERSIVE_TRANSACTION = IBinder.FIRST_CALL_TRANSACTION+110;
|
||||
int SET_IMMERSIVE_TRANSACTION = IBinder.FIRST_CALL_TRANSACTION+111;
|
||||
int IS_TOP_ACTIVITY_IMMERSIVE_TRANSACTION = IBinder.FIRST_CALL_TRANSACTION+112;
|
||||
int CRASH_APPLICATION_TRANSACTION = IBinder.FIRST_CALL_TRANSACTION+113;
|
||||
}
|
||||
|
||||
@@ -103,6 +103,7 @@ public interface IApplicationThread extends IInterface {
|
||||
static final int PACKAGE_REMOVED = 0;
|
||||
static final int EXTERNAL_STORAGE_UNAVAILABLE = 1;
|
||||
void dispatchPackageBroadcast(int cmd, String[] packages) throws RemoteException;
|
||||
void scheduleCrash(String msg) throws RemoteException;
|
||||
|
||||
String descriptor = "android.app.IApplicationThread";
|
||||
|
||||
@@ -139,4 +140,5 @@ public interface IApplicationThread extends IInterface {
|
||||
int GET_MEMORY_INFO_TRANSACTION = IBinder.FIRST_CALL_TRANSACTION+31;
|
||||
int SCHEDULE_SUICIDE_TRANSACTION = IBinder.FIRST_CALL_TRANSACTION+32;
|
||||
int DISPATCH_PACKAGE_BROADCAST_TRANSACTION = IBinder.FIRST_CALL_TRANSACTION+33;
|
||||
int SCHEDULE_CRASH_TRANSACTION = IBinder.FIRST_CALL_TRANSACTION+34;
|
||||
}
|
||||
|
||||
@@ -37,6 +37,7 @@ interface IStatusBarService
|
||||
out List<IBinder> notificationKeys, out List<StatusBarNotification> notifications);
|
||||
void onPanelRevealed();
|
||||
void onNotificationClick(String pkg, String tag, int id);
|
||||
void onNotificationError(String pkg, String tag, int id, String message);
|
||||
void onNotificationError(String pkg, String tag, int id,
|
||||
int uid, int initialPid, String message);
|
||||
void onClearAllNotifications();
|
||||
}
|
||||
|
||||
@@ -38,18 +38,23 @@ public class StatusBarNotification implements Parcelable {
|
||||
public String pkg;
|
||||
public int id;
|
||||
public String tag;
|
||||
public int uid;
|
||||
public int initialPid;
|
||||
public Notification notification;
|
||||
|
||||
public StatusBarNotification() {
|
||||
}
|
||||
|
||||
public StatusBarNotification(String pkg, int id, String tag, Notification notification) {
|
||||
public StatusBarNotification(String pkg, int id, String tag,
|
||||
int uid, int initialPid, Notification notification) {
|
||||
if (pkg == null) throw new NullPointerException();
|
||||
if (notification == null) throw new NullPointerException();
|
||||
|
||||
this.pkg = pkg;
|
||||
this.id = id;
|
||||
this.tag = tag;
|
||||
this.uid = uid;
|
||||
this.initialPid = initialPid;
|
||||
this.notification = notification;
|
||||
}
|
||||
|
||||
@@ -65,6 +70,8 @@ public class StatusBarNotification implements Parcelable {
|
||||
} else {
|
||||
this.tag = null;
|
||||
}
|
||||
this.uid = in.readInt();
|
||||
this.initialPid = in.readInt();
|
||||
this.notification = new Notification(in);
|
||||
}
|
||||
|
||||
@@ -77,6 +84,8 @@ public class StatusBarNotification implements Parcelable {
|
||||
} else {
|
||||
out.writeInt(0);
|
||||
}
|
||||
out.writeInt(this.uid);
|
||||
out.writeInt(this.initialPid);
|
||||
this.notification.writeToParcel(out, flags);
|
||||
}
|
||||
|
||||
@@ -99,7 +108,8 @@ public class StatusBarNotification implements Parcelable {
|
||||
};
|
||||
|
||||
public StatusBarNotification clone() {
|
||||
return new StatusBarNotification(this.pkg, this.id, this.tag, this.notification.clone());
|
||||
return new StatusBarNotification(this.pkg, this.id, this.tag,
|
||||
this.uid, this.initialPid, this.notification.clone());
|
||||
}
|
||||
|
||||
public String toString() {
|
||||
|
||||
Reference in New Issue
Block a user