[Android] Refuse external setters of engine entrypoint and cached engine arguments via Intents - #190249
Merged
Conversation
4 tasks done
Intents
|
CI had a failure that stopped further tests from running. We need to investigate to determine the root cause. SHA at time of execution: 0de92f8. Possible causes:
A blank commit, or merging to head, will be required to resume running CI for this PR. Error Details: Stack trace: |
mboetger
approved these changes
Sep 25, 2026
This was referenced Sep 26, 2026
DanTup
pushed a commit
to DanTup/flutter
that referenced
this pull request
Sep 28, 2026
…ine arguments via `Intent`s (flutter#190249) > [!WARNING] > This is a breaking change. Though the motivation for this change is the security of our users and migration to accommodate this change is critical, I looked at some top plugins that _might_ have been impacted to ensure they won't be broken: All 1P plugins, [`firebase_messaging`](https://pub.dev/packages/firebase_messaging) v16.5.0, [`flutter_local_notifications`](https://pub.dev/packages/flutter_local_notifications) v22.3.0, [`awesome_notifications`](https://pub.dev/packages/awesome_notifications) v0.12.1, [`android_alarm_manager_plus`](https://pub.dev/packages/android_alarm_manager_plus) v5.1.1, [`receive_sharing_intent`](https://pub.dev/packages/receive_sharing_intent) v1.9.0, [`onesignal_flutter`](https://pub.dev/packages/onesignal_flutter), [`workmanager`](https://pub.dev/packages/workmanager) v0.10.7 [`flutter_background_service`](https://pub.dev/packages/flutter_background_service) v5.1.0, [`app_links`](https://pub.dev/packages/app_links) v7.2.1, [`uni_links`](https://pub.dev/packages/uni_links) v0.5.1 Changes the embedding to only allow setting app launch entry-point and cached engine related arguments via `Intent`s in debug/profile mode or when the `Intent` sender is verifiably the app itself. This hardens the embedding against arbitrary argument injection by a malicious actor, preventing unauthorized access to sensitive app routes and engine controls. Below Android 13, it is impossible to verify the `Intent` sender is verifiably the app itself in all cases, so apps/plugins that do not migrate and run on those versions will be impacted. In debug/profile modes, if an unverified `Intent` attempts to set these arguments, the embedding now logs a detailed warning containing the target component, the intent details, and the specific `Intent` extra keys that triggered the verification failure. It also links to the breaking changes migration guide for help on migrating: flutter/website#13645 For deep links, the `Intent` is compared against the app's `Intent` filters to ensure the app should allow that link. This is standard for the OS; see [Android's Intents and Intent Filters documentation](https://developer.android.com/guide/components/intents-filters) for more information on that. Fixes flutter#190452 and fixes flutter#190450. ## Pre-launch Checklist - [x] I read the [Contributor Guide] and followed the process outlined there for submitting PRs. - [x] I read the [AI contribution guidelines] and understand my responsibilities, or I am not using AI tools. - [x] I read the [Tree Hygiene] wiki page, which explains my responsibilities. - [x] I read and followed the [Flutter Style Guide], including [Features we expect every widget to implement]. - [x] I signed the [CLA]. - [x] I listed at least one issue that this PR fixes in the description above. - [x] I updated/added relevant documentation (doc comments with `///`). - [x] I added new tests to check the change I am making, or this PR is [test-exempt]. - [x] I followed the [breaking change policy] and added [Data Driven Fixes] where supported. - [ ] All existing and new tests are passing. If you need help, consider asking for advice on the #hackers-new channel on [Discord]. If this change needs to override an active code freeze, provide a comment explaining why. The code freeze workflow can be overridden by code reviewers. See pinned issues for any active code freezes with guidance. **Note**: The Flutter team is currently trialing the use of [Gemini Code Assist for GitHub](https://developers.google.com/gemini-code-assist/docs/review-github-code). Comments from the `gemini-code-assist` bot should not be taken as authoritative feedback from the Flutter team. If you find its comments useful you can update your code accordingly, but if you are unsure or disagree with the feedback, please feel free to wait for a Flutter team member's review for guidance on which automated comments should be addressed. <!-- Links --> [Contributor Guide]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#overview [AI contribution guidelines]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#ai-contribution-guidelines [Tree Hygiene]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md [test-exempt]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#tests [Flutter Style Guide]: https://github.com/flutter/flutter/blob/main/docs/contributing/Style-guide-for-Flutter-repo.md [Features we expect every widget to implement]: https://github.com/flutter/flutter/blob/main/docs/contributing/Style-guide-for-Flutter-repo.md#features-we-expect-every-widget-to-implement [CLA]: https://cla.developers.google.com/ [flutter/tests]: https://github.com/flutter/tests [breaking change policy]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#handling-breaking-changes [Discord]: https://github.com/flutter/flutter/blob/main/docs/contributing/Chat.md [Data Driven Fixes]: https://github.com/flutter/flutter/blob/main/docs/contributing/Data-driven-Fixes.md --------- Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
This was referenced Sep 28, 2026
DanTup
pushed a commit
to DanTup/flutter
that referenced
this pull request
Sep 28, 2026
…ine arguments via `Intent`s (flutter#190249) > [!WARNING] > This is a breaking change. Though the motivation for this change is the security of our users and migration to accommodate this change is critical, I looked at some top plugins that _might_ have been impacted to ensure they won't be broken: All 1P plugins, [`firebase_messaging`](https://pub.dev/packages/firebase_messaging) v16.5.0, [`flutter_local_notifications`](https://pub.dev/packages/flutter_local_notifications) v22.3.0, [`awesome_notifications`](https://pub.dev/packages/awesome_notifications) v0.12.1, [`android_alarm_manager_plus`](https://pub.dev/packages/android_alarm_manager_plus) v5.1.1, [`receive_sharing_intent`](https://pub.dev/packages/receive_sharing_intent) v1.9.0, [`onesignal_flutter`](https://pub.dev/packages/onesignal_flutter), [`workmanager`](https://pub.dev/packages/workmanager) v0.10.7 [`flutter_background_service`](https://pub.dev/packages/flutter_background_service) v5.1.0, [`app_links`](https://pub.dev/packages/app_links) v7.2.1, [`uni_links`](https://pub.dev/packages/uni_links) v0.5.1 Changes the embedding to only allow setting app launch entry-point and cached engine related arguments via `Intent`s in debug/profile mode or when the `Intent` sender is verifiably the app itself. This hardens the embedding against arbitrary argument injection by a malicious actor, preventing unauthorized access to sensitive app routes and engine controls. Below Android 13, it is impossible to verify the `Intent` sender is verifiably the app itself in all cases, so apps/plugins that do not migrate and run on those versions will be impacted. In debug/profile modes, if an unverified `Intent` attempts to set these arguments, the embedding now logs a detailed warning containing the target component, the intent details, and the specific `Intent` extra keys that triggered the verification failure. It also links to the breaking changes migration guide for help on migrating: flutter/website#13645 For deep links, the `Intent` is compared against the app's `Intent` filters to ensure the app should allow that link. This is standard for the OS; see [Android's Intents and Intent Filters documentation](https://developer.android.com/guide/components/intents-filters) for more information on that. Fixes flutter#190452 and fixes flutter#190450. ## Pre-launch Checklist - [x] I read the [Contributor Guide] and followed the process outlined there for submitting PRs. - [x] I read the [AI contribution guidelines] and understand my responsibilities, or I am not using AI tools. - [x] I read the [Tree Hygiene] wiki page, which explains my responsibilities. - [x] I read and followed the [Flutter Style Guide], including [Features we expect every widget to implement]. - [x] I signed the [CLA]. - [x] I listed at least one issue that this PR fixes in the description above. - [x] I updated/added relevant documentation (doc comments with `///`). - [x] I added new tests to check the change I am making, or this PR is [test-exempt]. - [x] I followed the [breaking change policy] and added [Data Driven Fixes] where supported. - [ ] All existing and new tests are passing. If you need help, consider asking for advice on the #hackers-new channel on [Discord]. If this change needs to override an active code freeze, provide a comment explaining why. The code freeze workflow can be overridden by code reviewers. See pinned issues for any active code freezes with guidance. **Note**: The Flutter team is currently trialing the use of [Gemini Code Assist for GitHub](https://developers.google.com/gemini-code-assist/docs/review-github-code). Comments from the `gemini-code-assist` bot should not be taken as authoritative feedback from the Flutter team. If you find its comments useful you can update your code accordingly, but if you are unsure or disagree with the feedback, please feel free to wait for a Flutter team member's review for guidance on which automated comments should be addressed. <!-- Links --> [Contributor Guide]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#overview [AI contribution guidelines]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#ai-contribution-guidelines [Tree Hygiene]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md [test-exempt]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#tests [Flutter Style Guide]: https://github.com/flutter/flutter/blob/main/docs/contributing/Style-guide-for-Flutter-repo.md [Features we expect every widget to implement]: https://github.com/flutter/flutter/blob/main/docs/contributing/Style-guide-for-Flutter-repo.md#features-we-expect-every-widget-to-implement [CLA]: https://cla.developers.google.com/ [flutter/tests]: https://github.com/flutter/tests [breaking change policy]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#handling-breaking-changes [Discord]: https://github.com/flutter/flutter/blob/main/docs/contributing/Chat.md [Data Driven Fixes]: https://github.com/flutter/flutter/blob/main/docs/contributing/Data-driven-Fixes.md --------- Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
This was referenced Sep 28, 2026
auto-submit Bot
pushed a commit
to flutter/packages
that referenced
this pull request
Sep 29, 2026
…#13060) Manual roll Flutter from 4fcd90be0045 to c5a061b18fa2 (222 revisions) Manual roll requested by quncheng@google.com flutter/flutter@4fcd90b...c5a061b 2026-09-28 brackenavaron@gmail.com [cross imports] navigator_test.dart (flutter/flutter#190954) 2026-09-28 154381524+flutteractionsbot@users.noreply.github.com Revert: Reland: Only render views that need to be rendered (flutter/flutter#193360) 2026-09-28 codefu@google.com ci(bringup): android_intent_security_test is green (flutter/flutter#193469) 2026-09-28 154381524+flutteractionsbot@users.noreply.github.com Sync CHANGELOG.md from stable (flutter/flutter#193020) 2026-09-28 engine-flutter-autoroll@skia.org Roll Fuchsia Linux SDK from ukukV5lEkKabtOATk... to QdgqP02_cYpRQQQNN... (flutter/flutter#193454) 2026-09-28 137456488+flutter-pub-roller-bot@users.noreply.github.com Roll pub packages (flutter/flutter#193460) 2026-09-28 victorsanniay@gmail.com Un-nest sceneBuildDuration and windowRenderDuration in web SceneBuilderRecorder (flutter/flutter#193260) 2026-09-28 zarah@google.com Fix unresolved doc comment references in dev/integration_tests and dev/benchmarks (flutter/flutter#193433) 2026-09-28 engine-flutter-autoroll@skia.org Roll Packages from e55e7ac to ba0364a (9 revisions) (flutter/flutter#193450) 2026-09-28 bkonyi@google.com [tool] Require explicit dependency injection for FlutterDevice and FlutterDevice.create (flutter/flutter#192830) 2026-09-28 137456488+flutter-pub-roller-bot@users.noreply.github.com Roll pub packages (flutter/flutter#193442) 2026-09-28 dacoharkes@google.com [flutter_tools] Include data assets from hooks when pubspec.yaml is empty (flutter/flutter#193434) 2026-09-28 137456488+flutter-pub-roller-bot@users.noreply.github.com Roll pub packages (flutter/flutter#193438) 2026-09-28 zarah@google.com Fix unresolved doc comment references in Material and Cupertino (flutter/flutter#193283) 2026-09-28 zarah@google.com Fix doc references to Material and Cupertino in the widgets library and its tests (flutter/flutter#193334) 2026-09-26 kevmoo@users.noreply.github.com wasm: enforce WasmGC opt-in capability checks and Firefox < 147 guard (flutter/flutter#193180) 2026-09-26 43054281+camsim99@users.noreply.github.com [Android] Refuse external setters of engine entrypoint and cached engine arguments via `Intent`s (flutter/flutter#190249) 2026-09-26 1961493+harryterkelsen@users.noreply.github.com [web] Unskip TextPainter.getWordBoundary test (flutter/flutter#193378) 2026-09-26 bkonyi@google.com Specify non-obvious types in pattern variable declarations (flutter/flutter#192632) 2026-09-26 30870216+gaaclarke@users.noreply.github.com Removes feedback loop from advanced filters without offscreen msaa and framebufferfetch (flutter/flutter#193306) 2026-09-26 1961493+harryterkelsen@users.noreply.github.com [web] Unskip 8 passing image tests in painting and rendering (flutter/flutter#193377) 2026-09-26 154381524+flutteractionsbot@users.noreply.github.com Revert: Allow resetting test invariants in `addTearDown` (flutter/flutter#193383) 2026-09-25 bkonyi@google.com [tool] Migrate CoverageCollector to modular dependency injection (flutter/flutter#192924) 2026-09-25 zarah@google.com Fix more unresolved doc comment references (flutter/flutter#193336) 2026-09-25 dkwingsmt@users.noreply.github.com Allow resetting test invariants in `addTearDown` (flutter/flutter#192082) 2026-09-25 jhy03261997@gmail.com [a11y] Add a semantics role for slider (flutter/flutter#193324) 2026-09-25 stuartmorgan@google.com Fix plugin tests after Pigeon plugin template changes (flutter/flutter#193302) 2026-09-25 jesswon@google.com [Android 17] Bump Standard Test Apps in flutter/flutter to AGP 9.3.1 (flutter/flutter#193263) 2026-09-25 97480502+b-luk@users.noreply.github.com SSBO-based gradients in UberSDF (flutter/flutter#192962) 2026-09-25 robert.ancell@canonical.com [Linux] Handle FlView being destroyed before rendering is complete. (flutter/flutter#193268) 2026-09-25 bkonyi@google.com [flutter_tools] Handle Windows reserved characters in test target path (flutter/flutter#191900) 2026-09-25 sneurlax@gmail.com docs(tools): nit: say hook/build.dart in CMake native assets comment (flutter/flutter#192205) 2026-09-25 kevmoo@users.noreply.github.com [web] Enable Firefox Skwasm UI CI suites, configure COI configs, and fail fast on loader rejections (flutter/flutter#193187) 2026-09-25 jesswon@google.com [Android 17] Bumped Engine Dependencies to 9.3.1 (flutter/flutter#193265) 2026-09-25 kevmoo@users.noreply.github.com [web] Omit group role on menu scrollables and assign region role to named routes (flutter/flutter#192965) 2026-09-25 engine-flutter-autoroll@skia.org Roll Skia from 8eedeed98e79 to f441ca223b2b (5 revisions) (flutter/flutter#193353) 2026-09-25 engine-flutter-autoroll@skia.org Roll Fuchsia Linux SDK from EbPpoJW-Lnsu-8dyZ... to ukukV5lEkKabtOATk... (flutter/flutter#193326) 2026-09-25 engine-flutter-autoroll@skia.org Roll Packages from 431ea69 to e55e7ac (6 revisions) (flutter/flutter#193351) 2026-09-25 139053348+shikharish@users.noreply.github.com Support DynamicLibrary.codeAsset in Flutter (flutter/flutter#188947) 2026-09-25 engine-flutter-autoroll@skia.org Roll Dart SDK from 75d9e87d4e3d to 0e7642b85457 (1 revision) (flutter/flutter#193346) 2026-09-25 15619084+vashworth@users.noreply.github.com Exclude iOS PRs from macOS link (flutter/flutter#193315) 2026-09-25 engine-flutter-autoroll@skia.org Roll Skia from 6357608543ec to 8eedeed98e79 (4 revisions) (flutter/flutter#193341) 2026-09-25 engine-flutter-autoroll@skia.org Roll Dart SDK from d3aedb186aab to 75d9e87d4e3d (3 revisions) (flutter/flutter#193335) 2026-09-25 nickolasdeluca@live.com Cache the paint offset adjusted line metrics in TextPainter (flutter/flutter#191223) ...
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Warning
This is a breaking change. Though the motivation for this change is the security of our users and migration to accommodate this change is critical, I looked at some top plugins that might have been impacted to ensure they won't be broken: All 1P plugins,
firebase_messagingv16.5.0,flutter_local_notificationsv22.3.0,awesome_notificationsv0.12.1,android_alarm_manager_plusv5.1.1,receive_sharing_intentv1.9.0,onesignal_flutter,workmanagerv0.10.7flutter_background_servicev5.1.0,app_linksv7.2.1,uni_linksv0.5.1Changes the embedding to only allow setting app launch entry-point and cached engine related arguments via
Intents in debug/profile mode or when theIntentsender is verifiably the app itself. This hardens the embedding against arbitrary argument injection by a malicious actor, preventing unauthorized access to sensitive app routes and engine controls. Below Android 13, it is impossible to verify theIntentsender is verifiably the app itself in all cases, so apps/plugins that do not migrate and run on those versions will be impacted.In debug/profile modes, if an unverified
Intentattempts to set these arguments, the embedding now logs a detailed warning containing the target component, the intent details, and the specificIntentextra keys that triggered the verification failure. It also links to the breaking changes migration guide for help on migrating: flutter/website#13645For deep links, the
Intentis compared against the app'sIntentfilters to ensure the app should allow that link. This is standard for the OS; see Android's Intents and Intent Filters documentation for more information on that.Fixes #190452 and fixes #190450.
Pre-launch Checklist
///).If you need help, consider asking for advice on the #hackers-new channel on Discord.
If this change needs to override an active code freeze, provide a comment explaining why. The code freeze workflow can be overridden by code reviewers. See pinned issues for any active code freezes with guidance.
Note: The Flutter team is currently trialing the use of Gemini Code Assist for GitHub. Comments from the
gemini-code-assistbot should not be taken as authoritative feedback from the Flutter team. If you find its comments useful you can update your code accordingly, but if you are unsure or disagree with the feedback, please feel free to wait for a Flutter team member's review for guidance on which automated comments should be addressed.