fix: Unbind an A11yService from onNullBinding
With this fix, a service which returns null in onBind() will no longer
stay bound by system_server and will no longer be able to launch
activities from the background.
Bug: 386950836
Test: Follow steps in the bug to reproduce the issue; observe that BAL
is no longer allowed.
Test: atest android.security.cts.Bug_386950836
Flag: EXEMPT security bugfix
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:18980816ce87dcee4530c7d0b707172a982e966f)
Merged-In: Id04111b061881d23346aa90a0b5d08a28bed2c6f
Change-Id: Id04111b061881d23346aa90a0b5d08a28bed2c6f
diff --git a/services/accessibility/java/com/android/server/accessibility/AccessibilityServiceConnection.java b/services/accessibility/java/com/android/server/accessibility/AccessibilityServiceConnection.java index 91fe035..fe6e036 100644 --- a/services/accessibility/java/com/android/server/accessibility/AccessibilityServiceConnection.java +++ b/services/accessibility/java/com/android/server/accessibility/AccessibilityServiceConnection.java
@@ -253,6 +253,16 @@ } @Override + public void onNullBinding(ComponentName componentName) { + // Per guidance from ServiceConnection we must call Context#unbindService here to + // release the tracking resources associated with the ServiceConnection, to prevent + // Background Activity Launches (BAL). + synchronized (mLock) { + unbindLocked(); + } + } + + @Override protected boolean hasRightsToCurrentUserLocked() { // We treat calls from a profile as if made by its parent as profiles // share the accessibility state of the parent. The call below