summaryrefslogtreecommitdiff
path: root/api/api.go
diff options
context:
space:
mode:
author Jackal Guo <jackalguo@google.com> 2022-01-17 16:47:16 +0800
committer Jackal Guo <jackalguo@google.com> 2022-01-18 16:45:33 +0800
commit8423dd15ff7b12687d6726ce555f7a0717ae7f14 (patch)
tree18f40d5ffec7ad409d7f13ce6150b3aa6ea45f91 /api/api.go
parent35eef324464aee9d46301815ddad3d65578bf1a8 (diff)
Verify the incoming package first.
The callingPackage is a parameter from the Binder, and the caller could forge any name they want. We should verify if it's trusted. Bug: 194105935 Bug: 194106074 Bug: 214894893 Test: atest -p core/java/android/app/ Test: atest -p services/tests/servicestests/src/com/android/server/am Test: manually using the PoC in the buganizer to ensure the symptom no longer exists. Change-Id: Ib7b4676d5c54df304d896b9f8260fe08c79dd3ce
Diffstat (limited to 'api/api.go')
0 files changed, 0 insertions, 0 deletions