From c0ebaea33a14df3a1112e83fe67a31bce62e7e12 Mon Sep 17 00:00:00 2001 From: Catherine Liu Date: Fri, 13 Apr 2012 15:16:07 -0500 Subject: [PATCH] Fix Force Close when enable airplane mode In GSMPhone handler for message EVENT_RADIO_OFF_OR_NOT_AVAILABLE, the for loop was trying to remove all pending MMI code starting from the index 0 of the ArrayList mPendingMMIs. When mPendingMMIs has more than 1 item in the list, after the 1st one in the list was removed, the rest in the list were shifted. The 2nd one became 1st. Assume the list size is 2, if now the for loop goes to index 1, access to mPendingMMIs.get(1) will result a null pointer access, and cause a Force Close. To fix it, make the for loop to begin with the last one in the ArrayList mPendingMMIs. Change-Id: I3e60086186851b1d6c10fefdb086aa0ae3e16048 --- telephony/java/com/android/internal/telephony/gsm/GSMPhone.java | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/telephony/java/com/android/internal/telephony/gsm/GSMPhone.java b/telephony/java/com/android/internal/telephony/gsm/GSMPhone.java index e1f4c4bd28b01..5c95e7d163c07 100644 --- a/telephony/java/com/android/internal/telephony/gsm/GSMPhone.java +++ b/telephony/java/com/android/internal/telephony/gsm/GSMPhone.java @@ -1240,7 +1240,7 @@ public class GSMPhone extends PhoneBase { // If the radio shuts off or resets while one of these // is pending, we need to clean up. - for (int i = 0, s = mPendingMMIs.size() ; i < s; i++) { + for (int i = mPendingMMIs.size() - 1; i >= 0; i--) { if (mPendingMMIs.get(i).isPendingUSSD()) { mPendingMMIs.get(i).onUssdFinishedError(); }