diff --git a/services/core/java/com/android/server/notification/NotificationManagerService.java b/services/core/java/com/android/server/notification/NotificationManagerService.java index 2cad829261f06..0897b8a52ad6a 100644 --- a/services/core/java/com/android/server/notification/NotificationManagerService.java +++ b/services/core/java/com/android/server/notification/NotificationManagerService.java @@ -617,7 +617,7 @@ public class NotificationManagerService extends SystemService { { final int pid; final String pkg; - ITransientNotification callback; + final ITransientNotification callback; int duration; Binder token; @@ -634,10 +634,6 @@ public class NotificationManagerService extends SystemService { this.duration = duration; } - void update(ITransientNotification callback) { - this.callback = callback; - } - void dump(PrintWriter pw, String prefix, DumpFilter filter) { if (filter != null && !filter.matches(pkg)) return; pw.println(prefix + this); @@ -1993,32 +1989,38 @@ public class NotificationManagerService extends SystemService { long callingId = Binder.clearCallingIdentity(); try { ToastRecord record; - int index; - // All packages aside from the android package can enqueue one toast at a time - if (!isSystemToast) { - index = indexOfToastPackageLocked(pkg); - } else { - index = indexOfToastLocked(pkg, callback); - } - - // If the package already has a toast, we update its toast - // in the queue, we don't move it to the end of the queue. + int index = indexOfToastLocked(pkg, callback); + // If it's already in the queue, we update it in place, we don't + // move it to the end of the queue. if (index >= 0) { record = mToastQueue.get(index); record.update(duration); - try { - record.callback.hide(); - } catch (RemoteException e) { - } - record.update(callback); } else { + // Limit the number of toasts that any given package except the android + // package can enqueue. Prevents DOS attacks and deals with leaks. + if (!isSystemToast) { + int count = 0; + final int N = mToastQueue.size(); + for (int i=0; i= MAX_PACKAGE_NOTIFICATIONS) { + Slog.e(TAG, "Package has already posted " + count + + " toasts. Not showing more. Package=" + pkg); + return; + } + } + } + } + Binder token = new Binder(); mWindowManagerInternal.addWindowToken(token, TYPE_TOAST, DEFAULT_DISPLAY); record = new ToastRecord(callingPid, pkg, callback, duration, token); mToastQueue.add(record); index = mToastQueue.size() - 1; + keepProcessAliveIfNeededLocked(callingPid); } - keepProcessAliveIfNeededLocked(callingPid); // If it's at index 0, it's the current toast. It doesn't matter if it's // new or just been updated. Call back and tell it to show itself. // If the callback fails, this will remove it from the list, so don't @@ -5098,21 +5100,7 @@ public class NotificationManagerService extends SystemService { int len = list.size(); for (int i=0; i list = mToastQueue; - int len = list.size(); - for (int i=0; i