Hacktoberfest 2026:維護者為十月標記出來的 issue,仍然開放、適合新手。 瀏覽 Hacktoberfest issue

Recursion in Util.java. I suspect that this will lead to issues passing a Google Tier2 CASA

未關閉
#1,785 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

還沒有人認領這個 Issue。

評估

難度
2/5
預估耗時
1-3 小時
新手友好度
35/100
Issue 類型
缺陷
描述清晰度
基本清楚
活躍度
停滯
技術堆疊
android, java

研究方向

先從 test-app/app/src/main/java/com/tns/Util.java 中參照的 isDebuggableApp catch 區塊開始,然後檢查 test-app/runtime/src/main/java/com/tns/Runtime.java 中的 isDebuggable() 進入點。確認 catch 路徑不會遞迴,並驗證由此產生的行為符合預期行為,且處理了所回報的掃描疑慮。

由索引模型根據 Issue 內容生成。

描述

Environment
Provide version numbers for the following components (information can be retrieved by running tns info in your project folder or by inspecting the package.json of the project):

✔ Getting NativeScript components versions information...
✔ Component nativescript has 8.5.3 version and is up to date.
✔ Component @nativescript/core has 8.5.9 version and is up to date.
✔ Component @nativescript/ios has 8.5.2 version and is up to date.
✔ Component @nativescript/android has 8.5.2 version and is up to date.

Describe the bug
Hello together, I am currently preparing for a Tier2 CASA from Google. As I do have to provide Source Code scans using FluidAttacks and it detected a vulnerability in this context of printStackTrace I found the following issue.

https://github.com/NativeScript/android/blob/57388331bf85473d6c3cf5f115dd9d290b80d59b/test-app/app/src/main/java/com/tns/Util.java#L28

public static boolean isDebuggableApp(Context context) {
        int flags;
        try {
            flags = context.getPackageManager().getPackageInfo(context.getPackageName(), 0).applicationInfo.flags;
        } catch (NameNotFoundException e) {
            flags = 0;
            if (Util.isDebuggableApp(context)) {
                e.printStackTrace();
            }
        }

        boolean isDebuggableApp = ((flags & ApplicationInfo.FLAG_DEBUGGABLE) != 0);
        return isDebuggableApp;
    }

It is clear that printStackTrace() is only called in debug mode. However, I consider telling the guys at Google that this is save code as no good idea as it results in a recursion in the catch block. I would suspect that the e.printStackTrace(); in the catch block is actually never called, hence would it not make sense to completly remove it? I have also seen that the runtime provides
a check for isDebuggableApp. Maybe a save alternative would be to just call com.tns.Runtime.isDebuggable() ?

https://github.com/NativeScript/android/blob/57388331bf85473d6c3cf5f115dd9d290b80d59b/test-app/runtime/src/main/java/com/tns/Runtime.java#L248

I do not know the inner workings good enough to know if the runtime always exists at that point. Please consider it as just an idea.

Expected behavior
Catch should not run into a rekursion

Additional context

https://gitlab.com/fluidattacks/universe/-/issues/10406

Currently I am seeing lots of issues in FluidAttacks indirectly referencing this code. Below output is just an example. To my understanding this is a false positive as printStackTrace is not called for production builds. However, also in production builds the recursion would exist to my understanding.

234. Technical information leak - Stacktrace,CWE-209,The error stacktrace can be printed in OWASP/app/src/debug/java/com/tns/ErrorReport.java,CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:U/RC:R,https://docs.fluidattacks.com/criteria/vulnerabilities/234,skims,SAST,92,"
   82 |         final int version = Build.VERSION.SDK_INT;
   83 |         if (version >= 23) {
   84 |             try {
   85 |                 // Necessary to work around compile errors with compileSdk 22 and lower
   86 |                 Method checkSelfPermissionMethod;
   87 |                 try {
   88 |                     checkSelfPermissionMethod = ActivityCompat.class.getMethod(""checkSelfPermission"", Context.class, Stri
   89 |                 } catch (NoSuchMethodException e) {
   90 |                     // method wasn't found, so there is no need to handle permissions explicitly
   91 |                     if (Util.isDebuggableApp(activity)) {
>  92 |                         e.printStackTrace();
   93 |                     }
   94 |                     return;
   95 |                 }
   96 |
   97 |                 int permission = (int) checkSelfPermissionMethod.invoke(null, activity, Manifest.permission.WRITE_EXTERNA
   98 |
   99 |                 if (permission != PackageManager.PERMISSION_GRANTED) {
  100 |                     // We don't have permission so prompt the user
  101 |                     Method requestPermissionsMethod = ActivityCompat.class.getMethod(""requestPermissions"", Activity.class
  102 |
      ^ Col 0
",java.java_info_leak_stacktrace
主要語言
C++
星號
563
分支
144
平均合併
10 小時 46 分鐘
30 天內合併 PR
14

貢獻指南

開啟貢獻指南

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

NativeScript/android 的其他 Issue

查看 NativeScript/android 的全部 Issue

相似的 Issue

更多 C++ Issue

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。