Fix race conditions in CryptoHal plugin usage

The previous implementation of `decrypt` and `getKeyHandle` unlocked
`mLock` while `mPlugin` could be concurrently reset by
`destroyPlugin()`. This created a window for use-after-free or null
dereference when the plugin was dispatched. Additionally, the manual
unlock within the `Mutex::Autolock` scope caused double-unlocking
undefined behavior upon scope exit.

This commit scopes the `Autolock` explicitly and takes a strong reference
of the plugin under the lock. This ensures safe dispatch of the IPC and
avoids duplicate unlocks, mitigating the TOCTOU issue.

Bug: 503553199
Test: build libmediadrm
Flag: EXEMPT BUGFIX
Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:647973577adb51f42d22b94675ec6992f26f581d
Merged-In: I2e07e603ef641ddf83485a7a0e4c539b1325b91d
Change-Id: I2e07e603ef641ddf83485a7a0e4c539b1325b91d
2 files changed