Merge "Prevent memory corruption from use-after-free" into lmp-mr1-dev

This commit is contained in:
John Reck
2015-01-23 20:24:56 +00:00
committed by Android (Google) Code Review

View File

@@ -304,7 +304,7 @@ public final class Bitmap implements Parcelable {
* there are no more references to this bitmap. * there are no more references to this bitmap.
*/ */
public void recycle() { public void recycle() {
if (!mRecycled) { if (!mRecycled && mFinalizer.mNativeBitmap != 0) {
if (nativeRecycle(mNativeBitmap)) { if (nativeRecycle(mNativeBitmap)) {
// return value indicates whether native pixel object was actually recycled. // return value indicates whether native pixel object was actually recycled.
// false indicates that it is still in use at the native level and these // false indicates that it is still in use at the native level and these
@@ -1571,7 +1571,7 @@ public final class Bitmap implements Parcelable {
} }
private static class BitmapFinalizer { private static class BitmapFinalizer {
private final long mNativeBitmap; private long mNativeBitmap;
// Native memory allocated for the duration of the Bitmap, // Native memory allocated for the duration of the Bitmap,
// if pixel data allocated into native memory, instead of java byte[] // if pixel data allocated into native memory, instead of java byte[]
@@ -1597,6 +1597,7 @@ public final class Bitmap implements Parcelable {
VMRuntime.getRuntime().registerNativeFree(mNativeAllocationByteCount); VMRuntime.getRuntime().registerNativeFree(mNativeAllocationByteCount);
} }
nativeDestructor(mNativeBitmap); nativeDestructor(mNativeBitmap);
mNativeBitmap = 0;
} }
} }
} }