Sitelet https://github.com/flutter/flutter/pull/190249
Skip to content

[Android] Refuse external setters of engine entrypoint and cached engine arguments via Intents - #190249

Merged
auto-submit[bot] merged 49 commits into
flutter:masterfrom
camsim99:entrypoint_security
Sep 26, 2026
Merged

auto-submit[bot] merged 49 commits into
flutter:masterfrom
camsim99:entrypoint_security

Conversation

@camsim99

@camsim99 camsim99 commented Jul 29, 2026 •

Copy link
Copy Markdown
Contributor

Warning

This is a breaking change. Though the motivation for this change is the security of our users and migration to accommodate this change is critical, I looked at some top plugins that might have been impacted to ensure they won't be broken: All 1P plugins, firebase_messaging v16.5.0, flutter_local_notifications v22.3.0, awesome_notifications v0.12.1, android_alarm_manager_plus v5.1.1, receive_sharing_intent v1.9.0, onesignal_flutter, workmanager v0.10.7 flutter_background_service v5.1.0, app_links v7.2.1, uni_links v0.5.1

Changes the embedding to only allow setting app launch entry-point and cached engine related arguments via Intents in debug/profile mode or when the Intent sender is verifiably the app itself. This hardens the embedding against arbitrary argument injection by a malicious actor, preventing unauthorized access to sensitive app routes and engine controls. Below Android 13, it is impossible to verify the Intent sender is verifiably the app itself in all cases, so apps/plugins that do not migrate and run on those versions will be impacted.

In debug/profile modes, if an unverified Intent attempts to set these arguments, the embedding now logs a detailed warning containing the target component, the intent details, and the specific Intent extra keys that triggered the verification failure. It also links to the breaking changes migration guide for help on migrating: flutter/website#13645

For deep links, the Intent is compared against the app's Intent filters to ensure the app should allow that link. This is standard for the OS; see Android's Intents and Intent Filters documentation for more information on that.

Fixes #190452 and fixes #190450.

Pre-launch Checklist

If you need help, consider asking for advice on the #hackers-new channel on Discord.

If this change needs to override an active code freeze, provide a comment explaining why. The code freeze workflow can be overridden by code reviewers. See pinned issues for any active code freezes with guidance.

Note: The Flutter team is currently trialing the use of Gemini Code Assist for GitHub. Comments from the gemini-code-assist bot should not be taken as authoritative feedback from the Flutter team. If you find its comments useful you can update your code accordingly, but if you are unsure or disagree with the feedback, please feel free to wait for a Flutter team member's review for guidance on which automated comments should be addressed.

@github-actions github-actions Bot added platform-android Android applications specifically engine flutter/engine related. See also e: labels. team-android Owned by Android platform team labels Jul 29, 2026
@camsim99 camsim99 added the CICD Run CI/CD label Aug 7, 2026
@camsim99 camsim99 changed the title [wip] Entrypoint security [Android] Refuse external setters of engine entrypoint and cached engine arguments via Intents Aug 11, 2026
@camsim99
camsim99 marked this pull request as ready for review August 12, 2026 19:16
@camsim99
camsim99 requested a review from a team as a code owner August 12, 2026 19:16
@camsim99
camsim99 removed the request for review from a team August 12, 2026 19:16
@github-actions github-actions Bot added the tool Affects the "flutter" command-line tool. See also t: labels. label Sep 22, 2026
@github-actions github-actions Bot removed the tool Affects the "flutter" command-line tool. See also t: labels. label Sep 22, 2026
@flutter-dashboard

Copy link
Copy Markdown

CI had a failure that stopped further tests from running. We need to investigate to determine the root cause.

SHA at time of execution: 0de92f8.

Possible causes:

  • Configuration Changes: The .ci.yaml file might have been modified between the creation of this pull request and the start of this test run. This can lead to ci yaml validation errors.
  • Infrastructure Issues: Problems with the CI environment itself (e.g., quota) could have caused the failure.

A blank commit, or merging to head, will be required to resume running CI for this PR.

Error Details:

FormatException: ERROR: Mac_arm64_ios basic_material_app_ios__compile is a new builder added. it needs to be marked bringup: true
If ci.yaml wasn't changed, try `git fetch upstream && git merge upstream/master`



Stack trace:

#0      CiYaml._validate (package:cocoon_service/src/model/ci_yaml/ci_yaml.dart:395:7)
#1      new CiYaml (package:cocoon_service/src/model/ci_yaml/ci_yaml.dart:128:7)
#2      new CiYamlSet (package:cocoon_service/src/model/ci_yaml/ci_yaml.dart:48:23)
#3      CiYamlFetcher._getCiYaml (package:cocoon_service/src/service/scheduler/ci_yaml_fetcher.dart:124:12)
<asynchronous suspension>
#4      Scheduler.getPresubmitTargets (package:cocoon_service/src/service/scheduler.dart:1064:20)
<asynchronous suspension>
#5      Scheduler._getTestsForStage (package:cocoon_service/src/service/scheduler.dart:1367:14)
<asynchronous suspension>
#6      Scheduler._runCiTestingStage (package:cocoon_service/src/service/scheduler.dart:1408:30)
<asynchronous suspension>
#7      Scheduler.proceedToCiTestingStage (package:cocoon_service/src/service/scheduler.dart:1517:7)
<asynchronous suspension>
#8      Scheduler._closeSuccessfulEngineBuildStage (package:cocoon_service/src/service/scheduler.dart:1312:5)
<asynchronous suspension>
#9      Scheduler.processCheckRunCompleted (package:cocoon_service/src/service/scheduler.dart:1253:11)
<asynchronous suspension>
#10     PresubmitSubscription._processBuild (package:cocoon_service/src/request_handlers/presubmit_subscription.dart:228:7)
<asynchronous suspension>
#11     PresubmitSubscription.post (package:cocoon_service/src/request_handlers/presubmit_subscription.dart:119:5)
<asynchronous suspension>
#12     RequestHandler.service (package:cocoon_service/src/request_handling/request_handler.dart:42:20)
<asynchronous suspension>
#13     SubscriptionHandler.service (package:cocoon_service/src/request_handling/subscription_handler.dart:134:5)
<asynchronous suspension>
#14     createServer.<anonymous closure> (package:cocoon_service/server.dart:462:7)
<asynchronous suspension>
#15     main.<anonymous closure>.<anonymous closure> (file:///app/app_dart/bin/gae_server.dart:192:9)
<asynchronous suspension>

@camsim99
camsim99 requested a review from mboetger September 23, 2026 23:23
@camsim99 camsim99 added the autosubmit Merge PR when tree becomes green via auto submit App label Sep 25, 2026
@auto-submit
auto-submit Bot added this pull request to the merge queue Sep 26, 2026
Merged via the queue into flutter:master with commit 4759fcb Sep 26, 2026
23 checks passed
@flutter-dashboard flutter-dashboard Bot removed the autosubmit Merge PR when tree becomes green via auto submit App label Sep 26, 2026
DanTup pushed a commit to DanTup/flutter that referenced this pull request Sep 28, 2026
…ine arguments via `Intent`s (flutter#190249)

> [!WARNING]
> This is a breaking change. Though the motivation for this change is
the security of our users and migration to accommodate this change is
critical, I looked at some top plugins that _might_ have been impacted
to ensure they won't be broken: All 1P plugins,
[`firebase_messaging`](https://pub.dev/packages/firebase_messaging)
v16.5.0,
[`flutter_local_notifications`](https://pub.dev/packages/flutter_local_notifications)
v22.3.0,
[`awesome_notifications`](https://pub.dev/packages/awesome_notifications)
v0.12.1,
[`android_alarm_manager_plus`](https://pub.dev/packages/android_alarm_manager_plus)
v5.1.1,
[`receive_sharing_intent`](https://pub.dev/packages/receive_sharing_intent)
v1.9.0,
[`onesignal_flutter`](https://pub.dev/packages/onesignal_flutter),
[`workmanager`](https://pub.dev/packages/workmanager) v0.10.7
[`flutter_background_service`](https://pub.dev/packages/flutter_background_service)
v5.1.0, [`app_links`](https://pub.dev/packages/app_links) v7.2.1,
[`uni_links`](https://pub.dev/packages/uni_links) v0.5.1


Changes the embedding to only allow setting app launch entry-point and
cached engine related arguments via `Intent`s in debug/profile mode or
when the `Intent` sender is verifiably the app itself. This hardens the
embedding against arbitrary argument injection by a malicious actor,
preventing unauthorized access to sensitive app routes and engine
controls. Below Android 13, it is impossible to verify the `Intent`
sender is verifiably the app itself in all cases, so apps/plugins that
do not migrate and run on those versions will be impacted.

In debug/profile modes, if an unverified `Intent` attempts to set these
arguments, the embedding now logs a detailed warning containing the
target component, the intent details, and the specific `Intent` extra
keys that triggered the verification failure. It also links to the
breaking changes migration guide for help on migrating:
flutter/website#13645

For deep links, the `Intent` is compared against the app's `Intent`
filters to ensure the app should allow that link. This is standard for
the OS; see [Android's Intents and Intent Filters
documentation](https://developer.android.com/guide/components/intents-filters)
for more information on that.

Fixes flutter#190452 and fixes
flutter#190450.

## Pre-launch Checklist

- [x] I read the [Contributor Guide] and followed the process outlined
there for submitting PRs.
- [x] I read the [AI contribution guidelines] and understand my
responsibilities, or I am not using AI tools.
- [x] I read the [Tree Hygiene] wiki page, which explains my
responsibilities.
- [x] I read and followed the [Flutter Style Guide], including [Features
we expect every widget to implement].
- [x] I signed the [CLA].
- [x] I listed at least one issue that this PR fixes in the description
above.
- [x] I updated/added relevant documentation (doc comments with `///`).
- [x] I added new tests to check the change I am making, or this PR is
[test-exempt].
- [x] I followed the [breaking change policy] and added [Data Driven
Fixes] where supported.
- [ ] All existing and new tests are passing.

If you need help, consider asking for advice on the #hackers-new channel
on [Discord].

If this change needs to override an active code freeze, provide a
comment explaining why. The code freeze workflow can be overridden by
code reviewers. See pinned issues for any active code freezes with
guidance.

**Note**: The Flutter team is currently trialing the use of [Gemini Code
Assist for
GitHub](https://developers.google.com/gemini-code-assist/docs/review-github-code).
Comments from the `gemini-code-assist` bot should not be taken as
authoritative feedback from the Flutter team. If you find its comments
useful you can update your code accordingly, but if you are unsure or
disagree with the feedback, please feel free to wait for a Flutter team
member's review for guidance on which automated comments should be
addressed.

<!-- Links -->
[Contributor Guide]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#overview
[AI contribution guidelines]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#ai-contribution-guidelines
[Tree Hygiene]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md
[test-exempt]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#tests
[Flutter Style Guide]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Style-guide-for-Flutter-repo.md
[Features we expect every widget to implement]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Style-guide-for-Flutter-repo.md#features-we-expect-every-widget-to-implement
[CLA]: https://cla.developers.google.com/
[flutter/tests]: https://github.com/flutter/tests
[breaking change policy]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#handling-breaking-changes
[Discord]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Chat.md
[Data Driven Fixes]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Data-driven-Fixes.md

---------

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
DanTup pushed a commit to DanTup/flutter that referenced this pull request Sep 28, 2026
…ine arguments via `Intent`s (flutter#190249)

> [!WARNING]
> This is a breaking change. Though the motivation for this change is
the security of our users and migration to accommodate this change is
critical, I looked at some top plugins that _might_ have been impacted
to ensure they won't be broken: All 1P plugins,
[`firebase_messaging`](https://pub.dev/packages/firebase_messaging)
v16.5.0,
[`flutter_local_notifications`](https://pub.dev/packages/flutter_local_notifications)
v22.3.0,
[`awesome_notifications`](https://pub.dev/packages/awesome_notifications)
v0.12.1,
[`android_alarm_manager_plus`](https://pub.dev/packages/android_alarm_manager_plus)
v5.1.1,
[`receive_sharing_intent`](https://pub.dev/packages/receive_sharing_intent)
v1.9.0,
[`onesignal_flutter`](https://pub.dev/packages/onesignal_flutter),
[`workmanager`](https://pub.dev/packages/workmanager) v0.10.7
[`flutter_background_service`](https://pub.dev/packages/flutter_background_service)
v5.1.0, [`app_links`](https://pub.dev/packages/app_links) v7.2.1,
[`uni_links`](https://pub.dev/packages/uni_links) v0.5.1


Changes the embedding to only allow setting app launch entry-point and
cached engine related arguments via `Intent`s in debug/profile mode or
when the `Intent` sender is verifiably the app itself. This hardens the
embedding against arbitrary argument injection by a malicious actor,
preventing unauthorized access to sensitive app routes and engine
controls. Below Android 13, it is impossible to verify the `Intent`
sender is verifiably the app itself in all cases, so apps/plugins that
do not migrate and run on those versions will be impacted.

In debug/profile modes, if an unverified `Intent` attempts to set these
arguments, the embedding now logs a detailed warning containing the
target component, the intent details, and the specific `Intent` extra
keys that triggered the verification failure. It also links to the
breaking changes migration guide for help on migrating:
flutter/website#13645

For deep links, the `Intent` is compared against the app's `Intent`
filters to ensure the app should allow that link. This is standard for
the OS; see [Android's Intents and Intent Filters
documentation](https://developer.android.com/guide/components/intents-filters)
for more information on that.

Fixes flutter#190452 and fixes
flutter#190450.

## Pre-launch Checklist

- [x] I read the [Contributor Guide] and followed the process outlined
there for submitting PRs.
- [x] I read the [AI contribution guidelines] and understand my
responsibilities, or I am not using AI tools.
- [x] I read the [Tree Hygiene] wiki page, which explains my
responsibilities.
- [x] I read and followed the [Flutter Style Guide], including [Features
we expect every widget to implement].
- [x] I signed the [CLA].
- [x] I listed at least one issue that this PR fixes in the description
above.
- [x] I updated/added relevant documentation (doc comments with `///`).
- [x] I added new tests to check the change I am making, or this PR is
[test-exempt].
- [x] I followed the [breaking change policy] and added [Data Driven
Fixes] where supported.
- [ ] All existing and new tests are passing.

If you need help, consider asking for advice on the #hackers-new channel
on [Discord].

If this change needs to override an active code freeze, provide a
comment explaining why. The code freeze workflow can be overridden by
code reviewers. See pinned issues for any active code freezes with
guidance.

**Note**: The Flutter team is currently trialing the use of [Gemini Code
Assist for
GitHub](https://developers.google.com/gemini-code-assist/docs/review-github-code).
Comments from the `gemini-code-assist` bot should not be taken as
authoritative feedback from the Flutter team. If you find its comments
useful you can update your code accordingly, but if you are unsure or
disagree with the feedback, please feel free to wait for a Flutter team
member's review for guidance on which automated comments should be
addressed.

<!-- Links -->
[Contributor Guide]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#overview
[AI contribution guidelines]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#ai-contribution-guidelines
[Tree Hygiene]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md
[test-exempt]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#tests
[Flutter Style Guide]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Style-guide-for-Flutter-repo.md
[Features we expect every widget to implement]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Style-guide-for-Flutter-repo.md#features-we-expect-every-widget-to-implement
[CLA]: https://cla.developers.google.com/
[flutter/tests]: https://github.com/flutter/tests
[breaking change policy]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#handling-breaking-changes
[Discord]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Chat.md
[Data Driven Fixes]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Data-driven-Fixes.md

---------

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
auto-submit Bot pushed a commit to flutter/packages that referenced this pull request Sep 29, 2026
…#13060)

Manual roll Flutter from 4fcd90be0045 to c5a061b18fa2 (222 revisions)

Manual roll requested by quncheng@google.com

flutter/flutter@4fcd90b...c5a061b

2026-09-28 brackenavaron@gmail.com [cross imports] navigator_test.dart (flutter/flutter#190954)
2026-09-28 154381524+flutteractionsbot@users.noreply.github.com Revert: Reland: Only render views that need to be rendered  (flutter/flutter#193360)
2026-09-28 codefu@google.com ci(bringup): android_intent_security_test is green (flutter/flutter#193469)
2026-09-28 154381524+flutteractionsbot@users.noreply.github.com Sync CHANGELOG.md from stable (flutter/flutter#193020)
2026-09-28 engine-flutter-autoroll@skia.org Roll Fuchsia Linux SDK from ukukV5lEkKabtOATk... to QdgqP02_cYpRQQQNN... (flutter/flutter#193454)
2026-09-28 137456488+flutter-pub-roller-bot@users.noreply.github.com Roll pub packages (flutter/flutter#193460)
2026-09-28 victorsanniay@gmail.com Un-nest sceneBuildDuration and windowRenderDuration in web SceneBuilderRecorder (flutter/flutter#193260)
2026-09-28 zarah@google.com Fix unresolved doc comment references in dev/integration_tests and dev/benchmarks (flutter/flutter#193433)
2026-09-28 engine-flutter-autoroll@skia.org Roll Packages from e55e7ac to ba0364a (9 revisions) (flutter/flutter#193450)
2026-09-28 bkonyi@google.com [tool] Require explicit dependency injection for FlutterDevice and FlutterDevice.create (flutter/flutter#192830)
2026-09-28 137456488+flutter-pub-roller-bot@users.noreply.github.com Roll pub packages (flutter/flutter#193442)
2026-09-28 dacoharkes@google.com [flutter_tools] Include data assets from hooks when pubspec.yaml is empty (flutter/flutter#193434)
2026-09-28 137456488+flutter-pub-roller-bot@users.noreply.github.com Roll pub packages (flutter/flutter#193438)
2026-09-28 zarah@google.com Fix unresolved doc comment references in Material and Cupertino (flutter/flutter#193283)
2026-09-28 zarah@google.com Fix doc references to Material and Cupertino in the widgets library and its tests (flutter/flutter#193334)
2026-09-26 kevmoo@users.noreply.github.com wasm: enforce WasmGC opt-in capability checks and Firefox < 147 guard (flutter/flutter#193180)
2026-09-26 43054281+camsim99@users.noreply.github.com [Android] Refuse external setters of engine entrypoint and cached engine arguments via `Intent`s (flutter/flutter#190249)
2026-09-26 1961493+harryterkelsen@users.noreply.github.com [web] Unskip TextPainter.getWordBoundary test (flutter/flutter#193378)
2026-09-26 bkonyi@google.com Specify non-obvious types in pattern variable declarations (flutter/flutter#192632)
2026-09-26 30870216+gaaclarke@users.noreply.github.com Removes feedback loop from advanced filters without offscreen msaa and framebufferfetch (flutter/flutter#193306)
2026-09-26 1961493+harryterkelsen@users.noreply.github.com [web] Unskip 8 passing image tests in painting and rendering (flutter/flutter#193377)
2026-09-26 154381524+flutteractionsbot@users.noreply.github.com Revert: Allow resetting test invariants in `addTearDown` (flutter/flutter#193383)
2026-09-25 bkonyi@google.com [tool] Migrate CoverageCollector to modular dependency injection (flutter/flutter#192924)
2026-09-25 zarah@google.com Fix more unresolved doc comment references (flutter/flutter#193336)
2026-09-25 dkwingsmt@users.noreply.github.com Allow resetting test invariants in `addTearDown` (flutter/flutter#192082)
2026-09-25 jhy03261997@gmail.com [a11y] Add a semantics role for slider (flutter/flutter#193324)
2026-09-25 stuartmorgan@google.com Fix plugin tests after Pigeon plugin template changes (flutter/flutter#193302)
2026-09-25 jesswon@google.com [Android 17] Bump Standard Test Apps in flutter/flutter to AGP 9.3.1 (flutter/flutter#193263)
2026-09-25 97480502+b-luk@users.noreply.github.com SSBO-based gradients in UberSDF (flutter/flutter#192962)
2026-09-25 robert.ancell@canonical.com [Linux] Handle FlView being destroyed before rendering is complete. (flutter/flutter#193268)
2026-09-25 bkonyi@google.com [flutter_tools] Handle Windows reserved characters in test target path (flutter/flutter#191900)
2026-09-25 sneurlax@gmail.com docs(tools): nit: say hook/build.dart in CMake native assets comment (flutter/flutter#192205)
2026-09-25 kevmoo@users.noreply.github.com [web] Enable Firefox Skwasm UI CI suites, configure COI configs, and fail fast on loader rejections (flutter/flutter#193187)
2026-09-25 jesswon@google.com [Android 17] Bumped Engine Dependencies to 9.3.1 (flutter/flutter#193265)
2026-09-25 kevmoo@users.noreply.github.com [web] Omit group role on menu scrollables and assign region role to named routes (flutter/flutter#192965)
2026-09-25 engine-flutter-autoroll@skia.org Roll Skia from 8eedeed98e79 to f441ca223b2b (5 revisions) (flutter/flutter#193353)
2026-09-25 engine-flutter-autoroll@skia.org Roll Fuchsia Linux SDK from EbPpoJW-Lnsu-8dyZ... to ukukV5lEkKabtOATk... (flutter/flutter#193326)
2026-09-25 engine-flutter-autoroll@skia.org Roll Packages from 431ea69 to e55e7ac (6 revisions) (flutter/flutter#193351)
2026-09-25 139053348+shikharish@users.noreply.github.com Support DynamicLibrary.codeAsset in Flutter (flutter/flutter#188947)
2026-09-25 engine-flutter-autoroll@skia.org Roll Dart SDK from 75d9e87d4e3d to 0e7642b85457 (1 revision) (flutter/flutter#193346)
2026-09-25 15619084+vashworth@users.noreply.github.com Exclude iOS PRs from macOS link (flutter/flutter#193315)
2026-09-25 engine-flutter-autoroll@skia.org Roll Skia from 6357608543ec to 8eedeed98e79 (4 revisions) (flutter/flutter#193341)
2026-09-25 engine-flutter-autoroll@skia.org Roll Dart SDK from d3aedb186aab to 75d9e87d4e3d (3 revisions) (flutter/flutter#193335)
2026-09-25 nickolasdeluca@live.com Cache the paint offset adjusted line metrics in TextPainter (flutter/flutter#191223)
...
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CICD Run CI/CD engine flutter/engine related. See also e: labels. platform-android Android applications specifically team-android Owned by Android platform team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Android] Unauthorized executing of arbitrary Dart entrypoints via Intent extras [Android] Arbitrary route injection via unvalidated explicit Intents

4 participants