diff options
author | Seigo Nonaka <nona@google.com> | 2017-06-22 08:22:18 -0700 |
---|---|---|
committer | Neil Fuller <nfuller@google.com> | 2017-06-23 10:02:59 +0000 |
commit | b7773ce8751b424b824cdd1e78a95520d124734c (patch) | |
tree | b936e55c5ca46cd71cbece78d8c265a723d9755e /tools/aapt2/java/JavaClassGenerator.cpp | |
parent | 58ad534db862cbf573e09f8d8109c29440fb7b52 (diff) |
Stop loading other package's font by default.
Since CONTEXT_RESTRICTED is not a default flag of createPackageContext,
we can't rely on it for preventing unexpected font injections.
To protect developers and existing apps from a risk of font injection,
stop loading font from other package's resouce unless the developer
explicitly set CONTEXT_IGNORE_SECURITY.
Bug: 62813533
Bug: 62879353
Test: Manually done
Merged-In: I4442ddc48dadb5c968b444be86038b602074d301
Change-Id: I4442ddc48dadb5c968b444be86038b602074d301
(cherry picked from commit 6d6cd68660635d670b0cb17f348b7c1da13704b3)
Diffstat (limited to 'tools/aapt2/java/JavaClassGenerator.cpp')
0 files changed, 0 insertions, 0 deletions