aapt2: Sanitize Javadoc comments to prevent code injection

Prevent Javadoc breakout and arbitrary code injection in generated
R.java.

AAPT2 extracts XML comments and places them in Javadoc blocks in the
generated R.java file. If these comments contain Javadoc terminators
(*/) or Java Unicode escapes (e.g., \u002f), they can break out of the
Javadoc block and inject arbitrary executable Java code.

Bug: 524767048
Test: atest aapt2_tests (added comprehensive sanitization tests)
Flag: EXEMPT CVE_FIX

Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:863026ecf4f3469c0f6e45ad716ed133fbc30a77

Cherrypicked by Aesir
Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:5874a9196fefd485dcb5382198e51580a01e105a
Merged-In: I6a566be2d3772bfbf86897f1ccf70bc8c7250e5f
Change-Id: I6a566be2d3772bfbf86897f1ccf70bc8c7250e5f
2 files changed