summaryrefslogtreecommitdiff
path: root/drivers/android
diff options
context:
space:
mode:
authorJahnavi MN <jahnavimn@google.com>2026-07-16 08:37:45 +0000
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>2026-07-17 15:15:21 +0200
commit11071c63a91eefaef25d602697fe04fc2b7748e8 (patch)
tree68ce1f90d043af2a5590ac6acb3054f1022e07ae /drivers/android
parentd8f87e4eded64b9e27f6c0f815b71489f29cb95c (diff)
downloadlinux-11071c63a91eefaef25d602697fe04fc2b7748e8.tar.gz
linux-11071c63a91eefaef25d602697fe04fc2b7748e8.zip
rust_binder: Implement BINDER_DEBUG_USER_ERROR for refcounting and death notifications
This adds dynamic debug logs for: - Decrementing handle reference counts that are already zero. - Mismatched reference states (calling inc_ref_done with no active inc_refs, or using a weak reference as a strong reference). - Requesting or clearing death notifications on invalid references, already active notifications, or with mismatched cookies. Reviewed-by: Carlos Llamas <cmllamas@google.com> Reviewed-by: Alice Ryhl <aliceryhl@google.com> Signed-off-by: Jahnavi MN <jahnavimn@google.com> Link: https://patch.msgid.link/20260716-rust_binder_debug_mask-v4-3-3d7436c2d2f2@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Diffstat (limited to 'drivers/android')
-rw-r--r--drivers/android/binder/node.rs10
-rw-r--r--drivers/android/binder/process.rs35
2 files changed, 34 insertions, 11 deletions
diff --git a/drivers/android/binder/node.rs b/drivers/android/binder/node.rs
index 59c5ab747bf4..fefa723d13c4 100644
--- a/drivers/android/binder/node.rs
+++ b/drivers/android/binder/node.rs
@@ -345,7 +345,7 @@ impl Node {
) -> Option<DLArc<Node>> {
let inner = self.inner.access_mut(owner_inner);
if inner.active_inc_refs == 0 {
- pr_err!("inc_ref_done called when no active inc_refs");
+ binder_debug!(UserError, "inc_ref_done called when no active inc_refs");
return None;
}
@@ -821,6 +821,7 @@ impl NodeRef {
pub(crate) fn clone(&self, strong: bool) -> Result<NodeRef> {
if strong && self.strong_count == 0 {
+ binder_debug!(UserError, "tried to use weak ref as strong ref");
return Err(EINVAL);
}
Ok(self
@@ -861,9 +862,10 @@ impl NodeRef {
*count += 1;
} else {
if *count == 0 {
- pr_warn!(
- "pid {} performed invalid decrement on ref\n",
- kernel::current!().pid()
+ binder_debug!(
+ UserError,
+ "performed invalid {} decrement on ref",
+ if strong { "strong" } else { "weak" }
);
return false;
}
diff --git a/drivers/android/binder/process.rs b/drivers/android/binder/process.rs
index 5240686324cf..1d3a71292de0 100644
--- a/drivers/android/binder/process.rs
+++ b/drivers/android/binder/process.rs
@@ -912,7 +912,13 @@ impl Process {
}
Ok(node_ref)
} else {
- Ok(self.get_node_from_handle(handle, true)?)
+ match self.get_node_from_handle(handle, true) {
+ Ok(node_ref) => Ok(node_ref),
+ Err(err) => {
+ binder_debug!(UserError, "got transaction to invalid handle {handle}");
+ Err(err.into())
+ }
+ }
}
}
@@ -997,7 +1003,7 @@ impl Process {
} else {
// All refs are cleared in process exit, so this warning is expected in that case.
if !self.inner.lock().is_dead {
- pr_warn!("{}: no such ref {handle}\n", self.pid_in_current_ns());
+ binder_debug!(UserError, "no such ref {handle}");
}
}
Ok(())
@@ -1250,13 +1256,19 @@ impl Process {
})?;
let mut refs = self.node_refs.lock();
let Some(info) = refs.by_handle.get_mut(&handle) else {
- pr_warn!("BC_REQUEST_DEATH_NOTIFICATION invalid ref {handle}\n");
+ binder_debug!(
+ UserError,
+ "BC_REQUEST_DEATH_NOTIFICATION invalid ref {handle}"
+ );
return Ok(());
};
// Nothing to do if there is already a death notification request for this handle.
if info.death().is_some() {
- pr_warn!("BC_REQUEST_DEATH_NOTIFICATION death notification already set\n");
+ binder_debug!(
+ UserError,
+ "BC_REQUEST_DEATH_NOTIFICATION death notification already set"
+ );
return Ok(());
}
@@ -1293,17 +1305,26 @@ impl Process {
let mut refs = self.node_refs.lock();
let Some(info) = refs.by_handle.get_mut(&handle) else {
- pr_warn!("BC_CLEAR_DEATH_NOTIFICATION invalid ref {handle}\n");
+ binder_debug!(
+ UserError,
+ "BC_CLEAR_DEATH_NOTIFICATION invalid ref {handle}"
+ );
return Ok(());
};
let Some(death) = info.death().take() else {
- pr_warn!("BC_CLEAR_DEATH_NOTIFICATION death notification not active\n");
+ binder_debug!(
+ UserError,
+ "BC_CLEAR_DEATH_NOTIFICATION death notification not active"
+ );
return Ok(());
};
if death.cookie != cookie {
*info.death() = Some(death);
- pr_warn!("BC_CLEAR_DEATH_NOTIFICATION death notification cookie mismatch\n");
+ binder_debug!(
+ UserError,
+ "BC_CLEAR_DEATH_NOTIFICATION death notification cookie mismatch"
+ );
return Ok(());
}