From 98980cdfff34d1cace1ab60fa54e248c0ee8bc8e Mon Sep 17 00:00:00 2001 From: Doris Liu Date: Tue, 12 Jul 2016 18:48:52 -0700 Subject: [PATCH] Fix use-after-free in vector drawable animation Added a strong pointer to hold reference to VD in the animation, so that VD will not be released before animation is finished/destroyed. BUG: 29438210 Change-Id: I311cd83043f988640de44f637cb474baada9b5ca --- libs/hwui/PropertyValuesAnimatorSet.h | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/libs/hwui/PropertyValuesAnimatorSet.h b/libs/hwui/PropertyValuesAnimatorSet.h index 49021bc828251..f9274e1735367 100644 --- a/libs/hwui/PropertyValuesAnimatorSet.h +++ b/libs/hwui/PropertyValuesAnimatorSet.h @@ -60,7 +60,7 @@ public: virtual uint32_t dirtyMask(); bool isInfinite() { return mIsInfinite; } void setVectorDrawable(VectorDrawableRoot* vd) { mVectorDrawable = vd; } - VectorDrawableRoot* getVectorDrawable() const { return mVectorDrawable; } + VectorDrawableRoot* getVectorDrawable() const { return mVectorDrawable.get(); } AnimationListener* getOneShotListener() { return mOneShotListener.get(); } void clearOneShotListener() { mOneShotListener = nullptr; } uint32_t getRequestId() const { return mRequestId; } @@ -78,7 +78,7 @@ private: std::vector< std::unique_ptr > mAnimators; float mLastFraction = 0.0f; bool mInitialized = false; - VectorDrawableRoot* mVectorDrawable = nullptr; + sp mVectorDrawable; bool mIsInfinite = false; // This request id gets incremented (on UI thread only) when a new request to modfiy the // lifecycle of an animation happens, namely when start/end/reset/reverse is called.