Crash app on foreground service notification error.
On any notification error, the NMS silently cancels the notification, including foreground service notifications. Thus, an app could pass in a garbage notification deliberately and start a foreground service silently. This patch resolved this issue by judging the notification's flag, and if it is a foreground notification, still crash the app as previous platforms, and if it is a normal notification, don't crash the app. Background: In3ad4cdd1, which was merged into Android 9 release, the crash behaviour is removed. But it is an important rule that foreground services guaranteed to show an ongoing notification. Test: Run the sample apk provided in the issue, it's main thread received a RemoteServiceException: Bad notification posted from package... as intended behaviour. Fixes: 118612296 Merged-In: I36ea0137ca6978ff401f64dccacb6f2edcadd7db Change-Id: I36ea0137ca6978ff401f64dccacb6f2edcadd7db Signed-off-by: Da Xing <qiyueliuhuo813@gmail.com> (cherry picked from commitb740ed72b9)
This commit is contained in:
@@ -901,8 +901,22 @@ public class NotificationManagerService extends SystemService {
|
||||
@Override
|
||||
public void onNotificationError(int callingUid, int callingPid, String pkg, String tag,
|
||||
int id, int uid, int initialPid, String message, int userId) {
|
||||
final boolean fgService;
|
||||
synchronized (mNotificationLock) {
|
||||
NotificationRecord r = findNotificationLocked(pkg, tag, id, userId);
|
||||
fgService = r != null && (r.getNotification().flags & FLAG_FOREGROUND_SERVICE) != 0;
|
||||
}
|
||||
cancelNotification(callingUid, callingPid, pkg, tag, id, 0, 0, false, userId,
|
||||
REASON_ERROR, null);
|
||||
if (fgService) {
|
||||
// Still crash for foreground services, preventing the not-crash behaviour abused
|
||||
// by apps to give us a garbage notification and silently start a fg service.
|
||||
Binder.withCleanCallingIdentity(
|
||||
() -> mAm.crashApplication(uid, initialPid, pkg, -1,
|
||||
"Bad notification(tag=" + tag + ", id=" + id + ") posted from package "
|
||||
+ pkg + ", crashing app(uid=" + uid + ", pid=" + initialPid + "): "
|
||||
+ message));
|
||||
}
|
||||
}
|
||||
|
||||
@Override
|
||||
|
||||
Reference in New Issue
Block a user