diff options
| author | Jahnavi MN <jahnavimn@google.com> | 2026-07-16 08:37:45 +0000 |
|---|---|---|
| committer | Greg Kroah-Hartman <gregkh@linuxfoundation.org> | 2026-07-17 15:15:21 +0200 |
| commit | 11071c63a91eefaef25d602697fe04fc2b7748e8 (patch) | |
| tree | 68ce1f90d043af2a5590ac6acb3054f1022e07ae /drivers/android | |
| parent | d8f87e4eded64b9e27f6c0f815b71489f29cb95c (diff) | |
| download | linux-11071c63a91eefaef25d602697fe04fc2b7748e8.tar.gz linux-11071c63a91eefaef25d602697fe04fc2b7748e8.zip | |
rust_binder: Implement BINDER_DEBUG_USER_ERROR for refcounting and death notifications
This adds dynamic debug logs for:
- Decrementing handle reference counts that are already zero.
- Mismatched reference states (calling inc_ref_done with no active
inc_refs, or using a weak reference as a strong reference).
- Requesting or clearing death notifications on invalid references,
already active notifications, or with mismatched cookies.
Reviewed-by: Carlos Llamas <cmllamas@google.com>
Reviewed-by: Alice Ryhl <aliceryhl@google.com>
Signed-off-by: Jahnavi MN <jahnavimn@google.com>
Link: https://patch.msgid.link/20260716-rust_binder_debug_mask-v4-3-3d7436c2d2f2@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Diffstat (limited to 'drivers/android')
| -rw-r--r-- | drivers/android/binder/node.rs | 10 | ||||
| -rw-r--r-- | drivers/android/binder/process.rs | 35 |
2 files changed, 34 insertions, 11 deletions
diff --git a/drivers/android/binder/node.rs b/drivers/android/binder/node.rs index 59c5ab747bf4..fefa723d13c4 100644 --- a/drivers/android/binder/node.rs +++ b/drivers/android/binder/node.rs @@ -345,7 +345,7 @@ impl Node { ) -> Option<DLArc<Node>> { let inner = self.inner.access_mut(owner_inner); if inner.active_inc_refs == 0 { - pr_err!("inc_ref_done called when no active inc_refs"); + binder_debug!(UserError, "inc_ref_done called when no active inc_refs"); return None; } @@ -821,6 +821,7 @@ impl NodeRef { pub(crate) fn clone(&self, strong: bool) -> Result<NodeRef> { if strong && self.strong_count == 0 { + binder_debug!(UserError, "tried to use weak ref as strong ref"); return Err(EINVAL); } Ok(self @@ -861,9 +862,10 @@ impl NodeRef { *count += 1; } else { if *count == 0 { - pr_warn!( - "pid {} performed invalid decrement on ref\n", - kernel::current!().pid() + binder_debug!( + UserError, + "performed invalid {} decrement on ref", + if strong { "strong" } else { "weak" } ); return false; } diff --git a/drivers/android/binder/process.rs b/drivers/android/binder/process.rs index 5240686324cf..1d3a71292de0 100644 --- a/drivers/android/binder/process.rs +++ b/drivers/android/binder/process.rs @@ -912,7 +912,13 @@ impl Process { } Ok(node_ref) } else { - Ok(self.get_node_from_handle(handle, true)?) + match self.get_node_from_handle(handle, true) { + Ok(node_ref) => Ok(node_ref), + Err(err) => { + binder_debug!(UserError, "got transaction to invalid handle {handle}"); + Err(err.into()) + } + } } } @@ -997,7 +1003,7 @@ impl Process { } else { // All refs are cleared in process exit, so this warning is expected in that case. if !self.inner.lock().is_dead { - pr_warn!("{}: no such ref {handle}\n", self.pid_in_current_ns()); + binder_debug!(UserError, "no such ref {handle}"); } } Ok(()) @@ -1250,13 +1256,19 @@ impl Process { })?; let mut refs = self.node_refs.lock(); let Some(info) = refs.by_handle.get_mut(&handle) else { - pr_warn!("BC_REQUEST_DEATH_NOTIFICATION invalid ref {handle}\n"); + binder_debug!( + UserError, + "BC_REQUEST_DEATH_NOTIFICATION invalid ref {handle}" + ); return Ok(()); }; // Nothing to do if there is already a death notification request for this handle. if info.death().is_some() { - pr_warn!("BC_REQUEST_DEATH_NOTIFICATION death notification already set\n"); + binder_debug!( + UserError, + "BC_REQUEST_DEATH_NOTIFICATION death notification already set" + ); return Ok(()); } @@ -1293,17 +1305,26 @@ impl Process { let mut refs = self.node_refs.lock(); let Some(info) = refs.by_handle.get_mut(&handle) else { - pr_warn!("BC_CLEAR_DEATH_NOTIFICATION invalid ref {handle}\n"); + binder_debug!( + UserError, + "BC_CLEAR_DEATH_NOTIFICATION invalid ref {handle}" + ); return Ok(()); }; let Some(death) = info.death().take() else { - pr_warn!("BC_CLEAR_DEATH_NOTIFICATION death notification not active\n"); + binder_debug!( + UserError, + "BC_CLEAR_DEATH_NOTIFICATION death notification not active" + ); return Ok(()); }; if death.cookie != cookie { *info.death() = Some(death); - pr_warn!("BC_CLEAR_DEATH_NOTIFICATION death notification cookie mismatch\n"); + binder_debug!( + UserError, + "BC_CLEAR_DEATH_NOTIFICATION death notification cookie mismatch" + ); return Ok(()); } |
