From b98050fc043122a5f92addb22a7a702b539d1045 Mon Sep 17 00:00:00 2001 From: Mike Ma Date: Mon, 30 Mar 2020 13:37:31 -0700 Subject: [PATCH] Fix a race condition on ReportHandler::mBatch Hold mLock when accessing mBatch and mHandlerLooper in ReportHandler. Fixes: 147326028 Test: Take an incident report. Verify no race condition. Change-Id: I9d6da0067731f253532f60e5abb12dfb238b5411 --- cmds/incidentd/src/IncidentService.cpp | 2 ++ cmds/incidentd/src/Section.cpp | 2 +- 2 files changed, 3 insertions(+), 1 deletion(-) diff --git a/cmds/incidentd/src/IncidentService.cpp b/cmds/incidentd/src/IncidentService.cpp index 6c2b8551bf739..9e6d0a23de10f 100644 --- a/cmds/incidentd/src/IncidentService.cpp +++ b/cmds/incidentd/src/IncidentService.cpp @@ -152,6 +152,7 @@ void ReportHandler::handleMessage(const Message& message) { } void ReportHandler::schedulePersistedReport(const IncidentReportArgs& args) { + unique_lock lock(mLock); mBatch->addPersistedReport(args); mHandlerLooper->removeMessages(this, WHAT_TAKE_REPORT); mHandlerLooper->sendMessage(this, Message(WHAT_TAKE_REPORT)); @@ -159,6 +160,7 @@ void ReportHandler::schedulePersistedReport(const IncidentReportArgs& args) { void ReportHandler::scheduleStreamingReport(const IncidentReportArgs& args, const sp& listener, int streamFd) { + unique_lock lock(mLock); mBatch->addStreamingReport(args, listener, streamFd); mHandlerLooper->removeMessages(this, WHAT_TAKE_REPORT); mHandlerLooper->sendMessage(this, Message(WHAT_TAKE_REPORT)); diff --git a/cmds/incidentd/src/Section.cpp b/cmds/incidentd/src/Section.cpp index dec9cb0ad4ff6..114cbb8d64609 100644 --- a/cmds/incidentd/src/Section.cpp +++ b/cmds/incidentd/src/Section.cpp @@ -755,7 +755,7 @@ status_t TombstoneSection::BlockingCall(unique_fd& pipeWriteFd) const { if (stat(link_name, &fileStat) != OK) { continue; } - size_t exe_name_len = readlink(link_name, exe_name, EXE_NAME_LEN); + ssize_t exe_name_len = readlink(link_name, exe_name, EXE_NAME_LEN); if (exe_name_len < 0 || exe_name_len >= EXE_NAME_LEN) { ALOGE("[%s] Can't read '%s': %s", name.string(), link_name, strerror(errno)); continue;