Fix ArrayIndexOutOfBoundsException in SIMRecords due to invalid EF_CFIS/EF_CFF
A hostile or malformed SIM card can advertise an EF_CFIS with a record
size of 1, or an empty EF_CFF_CPHS. This leads to an uncaught
ArrayIndexOutOfBoundsException in the com.android.phone process when
parsing these records in onAllRecordsLoaded(), which is called from a
finally block in SIMRecords.handleMessage(). Because the exception is
uncaught, it crashes the persistent com.android.phone process, triggering
a continuous crash-loop and rendering all cellular services unavailable.
Fix this by:
1. Enhancing validEfCfis() to verify that the EF_CFIS data is at least
16 bytes (the spec-mandated size). This ensures we can safely read and
write all fields up to the maximum offset (15) without out-of-bounds
accesses.
2. Guarding all accesses to mEfCff[0] with a length check (mEfCff.length > 0)
to prevent crashes if the CPHS Call Forwarding Flags file is empty.
These changes prevent the crash-loop and keep the device functional,
gracefully ignoring the invalid SIM data.
Test: atest SIMRecordsTest
Flag: EXEMPT bugfix
Bug: 517377278
TAG=agy
CONV=d2b601e9-695b-4692-a523-d4db93054894
Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:5a45e108f2ccad5ef55b36ee9ebfde9e3d476bdd
Merged-In: I3f22d63e9f5a871eb2eaf8c5aaea95a467703c86
Change-Id: I3f22d63e9f5a871eb2eaf8c5aaea95a467703c86
2 files changed