RESTRICT AUTOMERGE Fix MediaStore race condition for pending files
Resolves a vulnerability where a malicious app could preemptively squat a MediaStore namespace.
This CL fixes the vulnerability by securing namespace ownership:
1. Explicit Rename Context: Uses explicit parameter passing to identify the target destination of an active rename operation during database conflict resolution.
2. Verified Squatter Deletion: Enhances the SQLiteConstraintException handler in handleNonExistingEntryFile to identify squatter rows by comparing the conflict path with the active rename context. Stale rows are forcefully removed using the consolidated deleteEntryForPath helper, and the update is retried within the same transaction to prevent re-insertion.
3. Implements checkIfPathAlreadyExists to aggressively prune stale database entries before resolving rename paths, ensuring names can be reclaimed safely.
Bug: 395640294
Test: atest MediaProviderTests:com.android.providers.media.MediaProviderTest#testPendingUpdate_SquatterRowDeleted
Test: atest MediaProviderTests:com.android.providers.media.MediaProviderTest#testPendingUpdate_SquatterRowFileExists
Flag: EXEMPT BUGFIX
Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:c1aa32ffa083a24be78ca1ac706c730cceb529b4
Merged-In: Ica7cec90bb2d1870ce8902fa3d3e9899d59a743b
Change-Id: Ica7cec90bb2d1870ce8902fa3d3e9899d59a743b
2 files changed