RESTRICT AUTOMERGE Camera3StreamSplitter: Add bounds check for slot index
In returnOutputBufferLocked, an app-supplied slot index was used to
index the outputSlots vector without any bounds check. This could
lead to an out-of-bounds read and type confusion.
This change adds a range check for the slot index and also verifies
that the retrieved buffer is not null. It also ensures the buffer is
correctly tracked in mBuffers before use.
Additionally, the outputSlots vector is now taken by reference to
avoid unnecessary copying and ensure that modifications to the
slots are correctly persisted.
Bug: 514734206
Test: m cameraservice_test
Flag: EXEMPT BUGFIX
Note: Autogenerated by MendIt (go/androidmendit)
Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:349203358d1b697187c79f4728388de5ebf9bebb
Merged-In: I12684395411ff45393e724345f1cbbb870167101
Change-Id: I12684395411ff45393e724345f1cbbb870167101
1 file changed