Defuse Bundles parsed by the system process.
It's easy for apps to throw custom Parcelables into Bundles, but if the system tries peeking inside one of these Bundles, it triggers a BadParcelableException. If that Bundle was passed away from the Binder thread that delivered it into the system, we end up with a nasty runtime restart. This change mitigates this trouble by "defusing" any Bundles parsed by the system server. That is, if it encounters BadParcelableException while unpacking a Bundle, it logs and delivers an empty Bundle as the result. Simultaneously, to help catch the system process sticking its fingers into Bundles that are destined for other processes, a Bundle now tracks if it's "defusable." For example, any Intents delivered through ActivityThread are marked as being defusable, since they've arrived at their final destination. Any other Bundles are considered to be "in transit" and we log if the system tries unparceling them. Merges several Parcel boolean fields into a flags int. Add better docs to several classes. Bug: 27581063 Change-Id: I28cf3e7439503b5dc9a429bafae5eb48f21f0d93
This commit is contained in:
@@ -28,6 +28,7 @@ import android.content.Intent;
|
||||
import android.content.pm.PackageManager;
|
||||
import android.content.res.Configuration;
|
||||
import android.content.res.Resources.Theme;
|
||||
import android.os.BaseBundle;
|
||||
import android.os.Build;
|
||||
import android.os.Environment;
|
||||
import android.os.FactoryTest;
|
||||
@@ -35,7 +36,6 @@ import android.os.FileUtils;
|
||||
import android.os.IPowerManager;
|
||||
import android.os.Looper;
|
||||
import android.os.PowerManager;
|
||||
import android.os.RecoverySystem;
|
||||
import android.os.RemoteException;
|
||||
import android.os.ServiceManager;
|
||||
import android.os.StrictMode;
|
||||
@@ -53,6 +53,7 @@ import com.android.internal.R;
|
||||
import com.android.internal.os.BinderInternal;
|
||||
import com.android.internal.os.SamplingProfilerIntegration;
|
||||
import com.android.internal.os.ZygoteInit;
|
||||
import com.android.internal.widget.ILockSettings;
|
||||
import com.android.server.accessibility.AccessibilityManagerService;
|
||||
import com.android.server.accounts.AccountManagerService;
|
||||
import com.android.server.am.ActivityManagerService;
|
||||
@@ -69,10 +70,9 @@ import com.android.server.hdmi.HdmiControlService;
|
||||
import com.android.server.input.InputManagerService;
|
||||
import com.android.server.job.JobSchedulerService;
|
||||
import com.android.server.lights.LightsService;
|
||||
import com.android.internal.widget.ILockSettings;
|
||||
import com.android.server.media.MediaResourceMonitorService;
|
||||
import com.android.server.media.MediaRouterService;
|
||||
import com.android.server.media.MediaSessionService;
|
||||
import com.android.server.media.MediaResourceMonitorService;
|
||||
import com.android.server.media.projection.MediaProjectionManagerService;
|
||||
import com.android.server.net.NetworkPolicyManagerService;
|
||||
import com.android.server.net.NetworkStatsService;
|
||||
@@ -271,6 +271,10 @@ public final class SystemServer {
|
||||
// explicitly specifying a user.
|
||||
Environment.setUserRequired(true);
|
||||
|
||||
// Within the system server, any incoming Bundles should be defused
|
||||
// to avoid throwing BadParcelableException.
|
||||
BaseBundle.setShouldDefuse(true);
|
||||
|
||||
// Ensure binder calls into the system always run at foreground priority.
|
||||
BinderInternal.disableBackgroundScheduling(true);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user