Fix type confusion in mediatuner service Unprivileged apps could pass remote binder proxies or custom binder stubs to mediatuner methods such as ITunerDvr::attachFilter, ITunerDemux::getAvSyncHwId, ITunerFilter::setDataSource, ITunerDescrambler::setDemuxSource, and ITunerFrontend::setLnb. The mediatuner daemon downcasted these interface pointers to local implementation classes using static_cast without checking if they were remote proxies. This resulted in reading member variables out-of-bounds relative to the proxy allocation, causing type confusion and memory corruption. This change adds isRemote() validation checks across all affected AIDL and HIDL service call sites to reject remote proxy binders with Result::INVALID_ARGUMENT. Bug: 514727559 Test: Tested with custom PoC and valid object flows on Gambit device Flag: EXEMPT BUGFIX TAG=agy CONV=b1db51a1-e8eb-4c27-9029-027db881f867 Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:c2ccf3231695bbb8b144813fe269f9b89624fad3 Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:d1349b27bca56db6ad7ff3c2d88a90c21c97594a Merged-In: Id786837e7dda012109bedf46b95b5e133f898ae3 Change-Id: Id786837e7dda012109bedf46b95b5e133f898ae3