summaryrefslogtreecommitdiff
path: root/drivers/android
AgeCommit message (Collapse)Author
18 hoursMerge branch 'char-misc-next' of ↵Mark Brown
https://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc.git # Conflicts: # drivers/android/binder_alloc.c # drivers/android/binderfs.c
20 hoursMerge branch 'fs-next' of linux-nextMark Brown
# Conflicts: # fs/coredump.c # fs/f2fs/f2fs.h # fs/fuse/dax.c # fs/xfs/libxfs/xfs_btree.c
28 hoursMerge https://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm.git ↵David Hildenbrand (Arm)
mm-unstable into for-next Signed-off-by: David Hildenbrand (Arm) <david@kernel.org>
4 daysbinder: remove mmap_lock fallbackDave Hansen
Previously, the per-VMA locking could fail in the face of writers which necessitate a fallback to mmap_lock. The new vma_start_read_unlocked() will wait for writers instead of failing. Use the new helper. Wait for writers. Remove the fallback to mmap_lock. Link: https://lore.kernel.org/20260831203056.838265-5-surenb@google.com Signed-off-by: Dave Hansen <dave.hansen@linux.intel.com> Signed-off-by: Suren Baghdasaryan <surenb@google.com> Signed-off-by: Andrew Morton <akpm@linux-foundation.org> Reviewed-by: Alice Ryhl <aliceryhl@google.com> Acked-by: Lorenzo Stoakes (ARM) <ljs@kernel.org> Cc: Liam R. Howlett <liam@infradead.org> Cc: Vlastimil Babka <vbabka@kernel.org> Cc: Shakeel Butt <shakeel.butt@linux.dev> Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org> Cc: Todd Kjos <tkjos@android.com> Cc: Christian Brauner <christian@brauner.io> Cc: Carlos Llamas <cmllamas@google.com> Cc: David S. Miller <davem@davemloft.net> Cc: David Ahern <dsahern@kernel.org> Cc: Arve Hjønnevåg <arve@android.com> Cc: David Hildenbrand (Arm) <david@kernel.org>
4 daysbinder: make shrinker rely solely on per-VMA lockDave Hansen
tl;dr: lock_vma_under_rcu() is already a trylock. No need to do both it and mmap_read_trylock(). Long Version: == Background == Historically, binder used an mmap_read_trylock() in its shrinker code. This ensures that reclaim is not blocked on an mmap_lock. Commit 95bc2d4a9020 ("binder: use per-vma lock in page reclaiming") added support for the per-VMA lock, but left mmap_read_trylock() as a fallback. This was presumably because the per-VMA locking can fail for several reasons and most (all?) lock_vma_under_rcu() callers have a fallback to mmap_read_trylock(). == Problem == The fallback is not worth the complexity here. lock_vma_under_rcu() is essentially already a non-blocking trylock. The main reason it fails is also the reason mmap_read_trylock() fails: something is holding mmap_write_lock(). The only remedy for a collision with mmap_write_lock() is to wait, which this code can not do. So the "fallback" after lock_vma_under_rcu() failure is not really a fallback: it is really likely to just be retrying in vain. That retry in an of itself isn't horrible. But it adds complexity. == Solution == Now that per-VMA locks are universally available, lock_vma_under_rcu() will not persistently fail. Rely on it alone and simplify the code. The removal of the fallback does not affect NOMMU case because binder driver depends on CONFIG_MMU. While at it we also make the handling of the cases where the original binder VMA is gone consistent. There are two cases to consider when Binder VMA is gone: 1. there is no VMA at that location anymore. 2. there is now another unrelated VMA at that location. Before this change we handle case 1 by having the shrinker proceed to free the page, and just skip the zap_vma_range() call. And we handle case 2 by having the shrinker return LRU_SKIP. While either behavior is acceptable, we need to handle them in a consistent way. Handle both cases by freeing the page without touching the VMA (skipping the zap_vma_range()). Full disclosure: I originally tried to do this with lock_vma_under_rcu_wait(), but it did not fit well with the mmap_lock trylock semantics. Claude caught this in a review and suggested the approach in this path. It seemed sane to me. So, Suggesed-by: Claude, I guess. Link: https://lore.kernel.org/20260831203056.838265-3-surenb@google.com Signed-off-by: Dave Hansen <dave.hansen@linux.intel.com> Signed-off-by: Suren Baghdasaryan <surenb@google.com> Signed-off-by: Andrew Morton <akpm@linux-foundation.org> Reviewed-by: Alice Ryhl <aliceryhl@google.com> Acked-by: Lorenzo Stoakes (ARM) <ljs@kernel.org> Acked-by: Carlos Llamas <cmllamas@google.com> Cc: Liam R. Howlett <liam@infradead.org> Cc: Vlastimil Babka <vbabka@kernel.org> Cc: Shakeel Butt <shakeel.butt@linux.dev> Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org> Cc: Todd Kjos <tkjos@android.com> Cc: Christian Brauner <christian@brauner.io> Cc: David S. Miller <davem@davemloft.net> Cc: David Ahern <dsahern@kernel.org> Cc: Arve Hjønnevåg <arve@android.com> Cc: David Hildenbrand (Arm) <david@kernel.org>
4 daysMerge branch 'vfs-7.4.netfs' into vfs.allChristian Brauner
Signed-off-by: Christian Brauner <brauner@kernel.org>
5 daysMerge 7.3-rc6 into char-misc-nextGreg Kroah-Hartman
This resolves a number of merge conflicts between the branches, and we pick up the fixes in 7.3-rc6 that we need for testing. Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
9 daysrust_binder: add transaction_log and failed_transaction_logAlice Ryhl
Implement the binder_logs/transaction_log and binder_logs/failed_transaction_log binderfs files in Rust Binder, matching the circular 32-entry transaction logs in C Binder. Example output from /dev/binderfs/binder_logs/transaction_log: 261251: call from 6157:6171 to 391:0 context binder node 170 handle 34 size 256:0 ret 0/0 l=0 261254: async from 606:783 to 669:0 context binder node 2048 handle 2 size 144:0 ret 0/0 l=0 261255: reply from 391:552 to 6157:6171 context binder node 0 handle -1 size 2436:8 ret 0/0 l=0 Example output from /dev/binderfs/binder_logs/failed_transaction_log: 194556: async from 6646:6853 to 7452:0 context binder node 177682 handle 450 size 160:0 ret 29189/0 l=process.rs:1081 194846: reply from 6646:6775 to 7452:7544 context binder node 0 handle -1 size 8:0 ret 29201/0 l=process.rs:1081 201573: call from 7771:7793 to 6646:0 context binder node 198883 handle 28 size 0:0 ret 29189/0 l=process.rs:1081 Unlike C Binder, which writes to log entries without a lock using memory barriers (smp_wmb/smp_rmb) and a debug_id_done field, each TransactionLog uses an atomic index cursor with 32 cacheline-aligned SpinLock<TransactionLogEntry> slots initialized in BinderModule::init via SetOnce<_>. Using a SpinLock per slot avoids data races (such as tearing when the ring buffer wraps around while an entry is being printed) without requiring atomic accesses for every field, and has very low risk of contention: concurrent transactions are spread across 32 separate cacheline-aligned locks, each lock is only held briefly for a fixed-size copy, and two writers only contend on a slot if 32 transactions occur before a single copy completes. Assisted-by: LLM Signed-off-by: Alice Ryhl <aliceryhl@google.com> Link: https://patch.msgid.link/20261001141114.2731136-1-aliceryhl@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
9 daysrust_binder: add call site for `trace_transaction_update_buffer_release()`Sagar Taunk
Call `trace_transaction_update_buffer_release()` when an outdated oneway transaction is superseded by a newer one. Signed-off-by: Sagar Taunk <sagartaunk@proton.me> Link: https://patch.msgid.link/20260927125622.676342-5-sagartaunk@proton.me Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
9 daysrust_binder: thread: wire up `transaction_buffer` `alloc/release` tracepointsSagar Taunk
Call `trace_transaction_alloc_buf()` right after a transaction buffer is successfully allocated in `copy_transaction_data()`, and call `trace_transaction_buffer_release()` when a buffer is freed via `BC_FREE_BUFFER` in `Thread::write()`. Signed-off-by: Sagar Taunk <sagartaunk@proton.me> Link: https://patch.msgid.link/20260927125622.676342-4-sagartaunk@proton.me Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
9 daysrust_binder: allocation: call trace_transaction_failed_buffer_release()Sagar Taunk
Call `trace_transaction_failed_buffer_release()` when transaction fails in `NewAllocation`'s destructor. This provides visibility into the failed buffer releases. Signed-off-by: Sagar Taunk <sagartaunk@proton.me> Link: https://patch.msgid.link/20260927125622.676342-3-sagartaunk@proton.me Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
9 daysrust_binder: add transaction buffer tracepointsSagar Taunk
Add `binder_transaction_alloc_buf`, `binder_transaction_buffer_release`, and `binder_transaction_failed_buffer_release`, mirroring C Binder's `binder_buffer_class` events of the same names and following android's fork for the function signatures. Link: https://github.com/Rust-for-Linux/linux/issues/1226 Suggested-by: Alice Ryhl <aliceryhl@google.com> Signed-off-by: Sagar Taunk <sagartaunk@proton.me> Link: https://patch.msgid.link/20260927125622.676342-2-sagartaunk@proton.me Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
9 daysrust_binderfs: add transaction_report feature entryCarlos Llamas
rust_binderfs is missing the equivalent of commit f37b55ded8ed ("binder: add transaction_report feature entry"), which adds "transaction_report" to the binderfs feature list. This helps userspace determine if the BINDER_CMD_REPORT from the generic netlink API is supported. Cc: stable@vger.kernel.org Fixes: f14e0c8183bc ("rust_binder: report netlink transactions") Signed-off-by: Carlos Llamas <cmllamas@google.com> Reviewed-by: Alice Ryhl <aliceryhl@google.com> Link: https://patch.msgid.link/20260916120833.593407-1-cmllamas@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
9 daysrust_binder: track caller location in BinderErrorAlice Ryhl
Record the caller's location in BinderError using #[track_caller] and a new ErrorLocation wrapper around &'static Location<'static> across all BinderError constructors and From implementations. ErrorLocation implements Display by stripping the directory prefix so locations are formatted as filename.rs:line (e.g. process.rs:422). In Context::get_manager_node and Process::buffer_alloc, avoid passing BinderError::new_dead() or BinderError::from() as function pointers to Option::ok_or_else() and Result::map_err() so that #[track_caller] captures the call site in rust_binder correctly. Include the error location in the FailedTransaction debug print and prepare for recording it in the binder transaction log. Example output: rust_binder: 840:4583 transaction async to 7656:0 failed ESRCH, code 1 size 428-16 line thread.rs:711 Assisted-by: LLM Signed-off-by: Alice Ryhl <aliceryhl@google.com> Link: https://patch.msgid.link/20260930-binder-transaction-log-v2-2-8a15e9b8cae3@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
9 daysrust_binder: never return 0 from next_debug_idAlice Ryhl
Retry if fetch_add returns 0 in next_debug_id() so that valid debug IDs start at 1 and 0 is never assigned, even if NEXT_DEBUG_ID wraps around. This allows 0 to be used as a sentinel for an absent or uninitialized debug_id (such as in TransactionInfo::to_node_debug_id and in transaction log entries). Assisted-by: LLM Signed-off-by: Alice Ryhl <aliceryhl@google.com> Link: https://patch.msgid.link/20260930-binder-transaction-log-v2-1-8a15e9b8cae3@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
9 daysbinder: use irrefutable let patternsAlexandre Courbot
Replace matches on infallible results with irrefutable let patterns, which are available since Rust 1.82. This removes boilerplate for handling impossible error variants. Signed-off-by: Alexandre Courbot <acourbot@nvidia.com> Reviewed-by: Gary Guo <gary@garyguo.net> Acked-by: Carlos Llamas <cmllamas@google.com> Reviewed-by: Alice Ryhl <aliceryhl@google.com> Link: https://patch.msgid.link/20260921-binder_let-v1-1-0cfc4c535544@nvidia.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-09-23fs: port ->rename() to pass const mnt_idmapChristian Brauner
Convert to const struct mnt_idmap. A mount's idmapping is immutable. The only thing that is allowed to be modified afterwards is the reference count and that is hidden behind mnt_idmap_get() and mnt_idmap_put(). Everything else only ever reads from the idmapping. This is the same model that struct cred uses and the idmapping is also rather sensitive. So make the idmap argument const wherever we can. The conversion is done from the bottom up so callers can continue to pass a non-const pointer to a const parameter until the conversion is finished. No functional changes. Link: https://patch.msgid.link/20260901-work-idmap-const-v1-19-54ccd48e100b@kernel.org Reviewed-by: Jan Kara <jack@suse.cz> Reviewed-by: Seth Forshee <sforshee@kernel.org> Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
2026-09-17binder: Fix up Kconfig dependancy due to removal of .c codeGreg Kroah-Hartman
When the .c binder code was removed, building the kernel if the rust binder code was enabled, will cause the binder to not be built at all as the option changed from .c to .rs which is probably not what the original build wanted. Fix this up by renaming the option back to the _RUST version. If in the future, that suffix wants to be dropped, we can do so and then it will be prompted for a choice again, but for this release cycle, it should stay as-is. Tested-by: Carlos Llamas <cmllamas@google.com> Link: https://patch.msgid.link/2026091743-pony-prewar-735b@gregkh Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-09-17binder: rm -f binder.cCarlos Llamas
The day has finally come. We are dropping the legacy C implementation of the Binder IPC driver in favor of its Rust version. For 15+ years, the C driver has grown increasingly complex, making it incredibly painful to maintain and land new features without tripping over vulnerabilities. The Rust implementation alleviates most of these issues, so it's time for a change. Alice Ryhl has worked hard on the Rust binder for the past couple of years, not only achieving full feature parity but also proving that it can match and often beat the performance of the C counterpart. Having run successfully on Android devices for some time now, we can no longer call this an "experiment". It's time to move on, yank the C code, and focus all new features and optimizations on the Rust driver. Long live the new Rust Binder king! Cc: rust-for-linux@vger.kernel.org Acked-by: Alice Ryhl <aliceryhl@google.com> Signed-off-by: Carlos Llamas <cmllamas@google.com> Link: https://patch.msgid.link/rm-c-binder@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-09-17rust_binder: simplify Result<()> usesNicolás Antinori
`kernel::error::Result<T = (), E = Error>` is a type alias for `core::result::Result<T, E>` with `()` as the default type argument for T. Explicitly specifying `Result<()>` is redundant. This change makes all usages of `Result` consistent across the driver. Link: https://github.com/Rust-for-Linux/linux/issues/1128 Suggested-by: Miguel Ojeda <ojeda@kernel.org> Signed-off-by: Nicolás Antinori <nico.antinori.7@gmail.com> Acked-by: Alice Ryhl <aliceryhl@google.com> Link: https://github.com/rust-lang/rust-clippy/issues/14848 Link: https://github.com/rust-lang/rust-clippy/pull/16123 Link: https://patch.msgid.link/20260831222857.1402608-1-nico.antinori.7@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-09-17rust_binder: speed up get_node_debug_info using lower_bound iterRafael Passos
Finding the next node in the RBTree can be done more efficiently using the cursor_lower_bound, as it reduces cost from O(n) to O(log n). Reviewed-by: Alice Ryhl <aliceryhl@google.com> Link: https://github.com/Rust-for-Linux/linux/issues/1249 Suggested-by: Alice Ryhl <aliceryhl@google.com> Signed-off-by: Rafael Passos <rafael@rcpassos.me> Link: https://patch.msgid.link/20260814215145.2050599-1-rafael@rcpassos.me Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-09-17rust_binder: use KVVec for files_to_translateSergey Gordeychik
The num_fds value in a binder_fd_array_object is bounded by the transaction buffer. However, its in-kernel metadata is larger than the u32 array on the wire. On 64-bit systems, FileEntry occupies 24 bytes. About 900,000 entries therefore make files_to_translate request roughly 20.6 MiB of physically contiguous memory, triggering a warning in __alloc_frozen_pages_noprof. translate_fds() later allocates Reservation entries from the same count. At 16 bytes per entry, this requires another 13.7 MiB contiguous allocation. Neither vector requires physical contiguity. Use KVVec for both so large allocations can fall back to vmalloc. Tested under QEMU/KVM. The 900,000-entry reproducer no longer triggers a page allocator warning, and a 300,000-entry transaction that repeats one valid fd reaches translate_fds() without WARN or BUG. Found with the rust-in-peace agentic pipeline (https://github.com/scadastrangelove/rust-in-peace). Reviewed-by: Alice Ryhl <aliceryhl@google.com> Signed-off-by: Sergey Gordeychik <scadastrangelove@gmail.com> Link: https://patch.msgid.link/20260828090757.96282-1-scadastrangelove@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-09-17rust_binder: add TF_DEFER_COMPLETE flag for avoiding userspace roundtripAlice Ryhl
Outgoing transactions are able to send a message and wait for its reply in a single ioctl. Why not avoid a userspace roundtrip by applying the same logic for replying to incoming messages and waiting for the next incoming message? Generally, when you send a reply using BC_REPLY, the kernel sends BR_TRANSACTION_COMPLETE as a reply to BC_REPLY right away. The BR_TRANSACTION_COMPLETE command indicates that it's safe for userspace to free any resources associated with this message (such as embedded fds or Binder nodes). However, the BR_TRANSACTION_COMPLETE message is problematic because after BC_REPLY is issued, there will be a pending message for userspace. The kernel will refuse to sleep for incoming messages in this scenario. The way this is handled for outgoing transaction is through a mechanism known as deferred delivery of BR_TRANSACTION_COMPLETE. The idea is that when you send an outgoing transaction, then we do not return to userspace right away if BR_TRANSACTION_COMPLETE is the only pending message. This patch adds a new flag called TF_DEFER_COMPLETE that lets userspace opt-in to the same deferred delivery mechanism for BR_TRANSACTION_COMPLETE when using BC_REPLY. Given this new uapi, we can adjust sendReply in userspace libbinder so that it writes the BC_REPLY command into mOut but does not flush the buffer to the kernel. Then, userspace simply continues running until it returns all the way out to the top-level joinThreadPool() loop, which calls into the kernel to get the next incoming transaction. At this point, mOut is flushed, sending the reply. The same ioctl then proceeds to sleep for an incoming message. Userspace only actually specifies TF_DEFER_COMPLETE when the Parcel does not contain fds or refcounts on binder objects. This is because otherwise said fd or binder node will not be freed until the binder thread receives another incoming transaction, which could be a long time. In the case of fds, this is especially important because delaying fclose() can result in processes hanging because they read from a pipe that isn't being closed due to fclose() not getting called. Note that even if TF_DEFER_COMPLETE is not specified for this transaction, it can still be useful to defer the BC_REPLY command, as it can still avoid a userspace roundtrip when a new incoming transaction is available right away. Observing the cuttlefish logs while booting with this change shows that there were 4297 opportunities for this optimization to kick in (that is, boot invoked BC_REPLY 4297 times). Out of those, 3441 binder ioctls sent and received a transaction in the same ioctl. This indicates that we successfully eliminated a syscall on the server side for 80% of incoming transactions. Generally, this means that a server is now able to handle incoming messages using one syscall per incoming message (for each incoming transaction, the syscall handles one BC_FREE_BUFFER and BC_REPLY command, and then waits for the next incoming transaction). Signed-off-by: Alice Ryhl <aliceryhl@google.com> Link: https://patch.msgid.link/20260811-defer-complete-v3-1-832193c92885@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-09-16rust_binderfs: add transaction_report feature entryCarlos Llamas
rust_binderfs is missing the equivalent of commit f37b55ded8ed ("binder: add transaction_report feature entry"), which adds "transaction_report" to the binderfs feature list. This helps userspace determine if the BINDER_CMD_REPORT from the generic netlink API is supported. Cc: stable <stable@kernel.org> Fixes: f14e0c8183bc ("rust_binder: report netlink transactions") Signed-off-by: Carlos Llamas <cmllamas@google.com> Link: https://patch.msgid.link/20260916120833.593407-1-cmllamas@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-09-16rust_binder: reschedule node refcount update on thread exitAlice Ryhl
When a thread exits via BINDER_THREAD_EXIT, its pending work items are cancelled. If a thread exits while holding a pending node refcount increment (e.g. pushed as deferred work to that thread), the refcount increment was previously dropped because Node::cancel() and NodeWrapper::cancel() were no-ops. Dropping the refcount update leaves the node's delivery state and count state desynchronized, and userspace will not receive the notification, which can cause the node to never be freed from the process's nodes tree when all external references are dropped. Fix this by implementing DeliverToRead::cancel() for Node and NodeWrapper to move the pending refcount update to the process's work queue on thread exit so another thread can deliver it to userspace. Cc: stable <stable@kernel.org> Fixes: eafedbc7c050 ("rust_binder: add Rust Binder driver") Signed-off-by: Alice Ryhl <aliceryhl@google.com> Link: https://patch.msgid.link/20260903-binder-thread-exit-node-v1-1-be09ff14f6a4@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-09-16rust_binder: cancel deferred work items in thread exitAlice Ryhl
If there are deferred work items on the thread todo list, then they are not cleaned up in the Thread::release() method. Thus, update the code to clean up the work items even if they are deferred. This can happen if the thread dies while it has an active outgoing transaction. Cc: stable <stable@kernel.org> Fixes: eafedbc7c050 ("rust_binder: add Rust Binder driver") Signed-off-by: Alice Ryhl <aliceryhl@google.com> Link: https://patch.msgid.link/20260903-binder-exit-get-work-v1-1-2d6129a238df@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-09-16binderfs: fix UAF write in binder_add_devicePeiyang He
binderfs_binder_device_create() publishes the new dentry with d_make_persistent() and then calls simple_done_creating(), which drops the parent directory lock and the creator's dentry reference. It then calls binder_add_device() to register the device in the global binder_devices list. After simple_done_creating() releases the parent directory lock, a concurrent unlinkat() can remove the new device entry. Dropping the creator's dentry reference can then trigger binderfs_evict_inode(), freeing the device. binder_add_device() later accesses the freed object, causing UAF write. Found by a modified Syzkaller: BUG: KASAN: slab-use-after-free in hlist_add_head include/linux/list.h:1073 [inline] BUG: KASAN: slab-use-after-free in binder_add_device+0xa9/0xc0 drivers/android/binder.c:7068 Write of size 8 at addr ffff88805b340c00 by task syz.1.532/11389 CPU: 0 UID: 0 PID: 11389 Comm: syz.1.532 Not tainted 7.2.0 #4 PREEMPT(full) Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 Call Trace: <TASK> __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x10e/0x1f0 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:378 [inline] print_report+0xf7/0x600 mm/kasan/report.c:482 kasan_report+0xe4/0x120 mm/kasan/report.c:595 hlist_add_head include/linux/list.h:1073 [inline] binder_add_device+0xa9/0xc0 drivers/android/binder.c:7068 binderfs_binder_device_create.isra.0+0x724/0x990 drivers/android/binderfs.c:196 binder_ctl_ioctl+0x186/0x1b0 drivers/android/binderfs.c:241 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:597 [inline] __se_sys_ioctl fs/ioctl.c:583 [inline] __x64_sys_ioctl+0x18e/0x210 fs/ioctl.c:583 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x116/0x800 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7ff9027a833d Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007ff903674018 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 RAX: ffffffffffffffda RBX: 00007ff902a35fa0 RCX: 00007ff9027a833d RDX: 0000200000000500 RSI: 00000000c1086201 RDI: 0000000000000004 RBP: 00007ff902850733 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 R13: 00007ff902a36038 R14: 00007ff902a35fa0 R15: 00007ffd7166bfa0 </TASK> Allocated by task 11389: kasan_save_stack+0x33/0x60 mm/kasan/common.c:57 kasan_save_track+0x14/0x30 mm/kasan/common.c:78 poison_kmalloc_redzone mm/kasan/common.c:398 [inline] __kasan_kmalloc+0xaa/0xb0 mm/kasan/common.c:415 kasan_kmalloc include/linux/kasan.h:263 [inline] __kmalloc_cache_noprof+0x2e4/0x6f0 mm/slub.c:5489 _kmalloc_noprof include/linux/slab.h:988 [inline] _kzalloc_noprof include/linux/slab.h:1309 [inline] binderfs_binder_device_create.isra.0+0x17a/0x990 drivers/android/binderfs.c:148 binder_ctl_ioctl+0x186/0x1b0 drivers/android/binderfs.c:241 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:597 [inline] __se_sys_ioctl fs/ioctl.c:583 [inline] __x64_sys_ioctl+0x18e/0x210 fs/ioctl.c:583 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x116/0x800 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f Freed by task 11389: kasan_save_stack+0x33/0x60 mm/kasan/common.c:57 kasan_save_track+0x14/0x30 mm/kasan/common.c:78 kasan_save_free_info+0x3b/0x60 mm/kasan/generic.c:584 poison_slab_object mm/kasan/common.c:253 [inline] __kasan_slab_free+0x5f/0x80 mm/kasan/common.c:285 kasan_slab_free include/linux/kasan.h:235 [inline] slab_free_hook mm/slub.c:2677 [inline] slab_free mm/slub.c:6377 [inline] kfree+0x2fc/0x6e0 mm/slub.c:6692 binderfs_evict_inode+0x1e8/0x260 drivers/android/binderfs.c:268 evict+0x3c2/0xad0 fs/inode.c:825 iput_final fs/inode.c:2019 [inline] iput fs/inode.c:2068 [inline] iput+0x79a/0xd30 fs/inode.c:2031 dentry_unlink_inode+0x27f/0x460 fs/dcache.c:479 dentry_kill+0x25d/0xc20 fs/dcache.c:826 finish_dput fs/dcache.c:1001 [inline] dput.part.0+0xce/0x230 fs/dcache.c:1042 dput+0x1f/0x30 fs/dcache.c:1037 end_dirop+0x7d/0xa0 fs/namei.c:2956 binderfs_binder_device_create.isra.0+0x71c/0x990 drivers/android/binderfs.c:194 binder_ctl_ioctl+0x186/0x1b0 drivers/android/binderfs.c:241 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:597 [inline] __se_sys_ioctl fs/ioctl.c:583 [inline] __x64_sys_ioctl+0x18e/0x210 fs/ioctl.c:583 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x116/0x800 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f The buggy address belongs to the object at ffff88805b340c00 which belongs to the cache kmalloc-512 of size 512 The buggy address is located 0 bytes inside of freed 512-byte region [ffff88805b340c00, ffff88805b340e00) Fix by calling binder_add_device() before d_make_persistent(), while the parent directory lock is still held and the dentry cannot be discarded. Cc: stable <stable@kernel.org> Fixes: b89aa544821d ("convert binderfs") Signed-off-by: Peiyang He <peiyang_he@smail.nju.edu.cn> Assisted-by: Codex:gpt-5.5 Acked-by: Carlos Llamas <cmllamas@google.com> Link: https://patch.msgid.link/F6EF5FB778E87C98+20260913085645.1639558-1-peiyang_he@smail.nju.edu.cn Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-09-16binder: fix is_failure flag for superseded transaction cleanupTomer Pomeranc
When a TF_UPDATE_TXN transaction supersedes a pending async transaction, binder_release_entire_buffer() is called with is_failure=false. Since the superseded transaction was never delivered, binder_apply_fd_fixups() was never called and no fds were installed in the target process. With is_failure=false, the BINDER_TYPE_FDA cleanup handler interprets stale buffer contents as installed fd numbers and passes them to binder_deferred_fd_close(), closing unrelated file descriptors. Pass is_failure=true since the transaction was never delivered to the target, matching the semantics of all other undelivered-transaction cleanup paths. Fixes: 9864bb480133 ("Binder: add TF_UPDATE_TXN to replace outdated txn") Cc: stable <stable@kernel.org> Signed-off-by: Tomer Pomeranc <tomerpo@gmail.com> Acked-by: Carlos Llamas <cmllamas@google.com> Link: https://patch.msgid.link/20260812195316.259136-3-tomerpo@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-09-16binder: fix leaked fd fixups on TF_UPDATE_TXN supersedeTomer Pomeranc
When a TF_UPDATE_TXN transaction supersedes a pending async transaction in a frozen process, the outdated transaction is freed with kfree() directly. This skips binder_free_txn_fixups(), leaking all binder_txn_fd_fixup entries and their fget()'d struct file references. The leaked file refcounts never reach zero, so the struct file objects are permanently pinned in memory. They survive process exit and accumulate across invocations until file-max exhaustion. Every other transaction cleanup path (binder_free_transaction(), binder_transaction() error paths, binder_release_work()) correctly calls binder_free_txn_fixups(). Add the missing call before kfree() in the t_outdated cleanup block. Fixes: 9864bb480133 ("Binder: add TF_UPDATE_TXN to replace outdated txn") Cc: stable <stable@kernel.org> Signed-off-by: Tomer Pomeranc <tomerpo@gmail.com> Acked-by: Carlos Llamas <cmllamas@google.com> Reviewed-by: Alice Ryhl <aliceryhl@google.com> Link: https://patch.msgid.link/20260812195316.259136-2-tomerpo@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-08-25Merge tag 'char-misc-7.3-rc1' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc Pull char/misc/IIO/etc driver updates from Greg KH: "Here is the big set of char, misc, iio, counter, fpga, and other small driver subsystems for 7.3-rc1. Overall, due to some driver removals we only added a bit more code than removed, which was a nice change. Highlights in this merge request are: - Loads of IIO driver updates and additions - binder driver updates (more on that below...) - Removal of the SGI XP and GRU drivers as they are not used anymore and turn out to be pretty insecure overall - Removal of the obsolete ibmasm driver as it's not being used anymore - Coresight driver updates and additions - Mei driver udpates - Counter driver updates - FPGA driver updates - ICC driver updates - lots and lots of other tiny driver updates to resolve reported issues All of these have been in linux-next for a while" * tag 'char-misc-7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc: (513 commits) iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF iio: adc: pac1921: fix wrong channel used in trigger handler read iio: light: gp2ap002: re-enable irq if runtime suspend fails iio: light: gp2ap002: Fix unbalanced runtime PM on repeated event writes iio: light: apds9306: fix PM reference leak in apds9306_read_data() iio: gyro: mpu3050: fix sign of raw angular velocity readings iio: srf04: fix pm_runtime handling on probe error path iio: adc: ad4080: configure backend data size iio: adc: adi-axi-adc: add data size support for AD408X backend iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable iio: dac: ad5446: fix OF module device table iio: light: opt4001: Fix reversed GENMASK() arguments in fault count mask iio: light: opt4001: Reject integration times with a non-zero seconds part iio: light: opt4001: Fix incompatible pointer type passed to div_u64_rem() iio: light: opt4001: Fix power down clearing bits of the wrong register iio: light: opt4060: Fix incorrect register name in threshold read error message iio: light: opt4060: Fix pointer type passed to div_u64_rem() iio: light: opt4060: Reject integration times with a non-zero seconds part iio: light: ltrf216a: fix runtime PM reference leak in error path iio: pressure: dps310: fix NULL pointer dereference on ACPI probe ...
2026-08-18Merge tag 'rust-7.3' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/ojeda/linux Pull Rust updates from Miguel Ojeda: "Toolchain and infrastructure: - Warn when using 'bindgen' < 0.72.1 with 'libclang' >= 22, since that combination may fail to build. It includes a probe for the bug in case 'bindgen' happens to be patched, and tests In parallel, Nathan updated the instructions for the kernel.org LLVM+Rust toolchains so that the latest version of 'bindgen' is installed, which should avoid some of these situations - Support testing 'rust_is_available.sh' with 'bash' as '/bin/sh' - Fix an objtool warning by adding one more 'noreturn' function for Rust 1.99.0 (expected 2026-10-01) - Fix build error in the 'rusttest' target due to ambiguity when the 'rustc-dev' component is installed, which was uncovered by the work to support Rust's GCC backend ('rustc_codegen_gcc') - Fix future Clang warnings in the upcoming powerpc support due to macro redefinitions in the UAPI helper header by including the arch-aware 'ioctl.h' header 'kernel' crate: - Rework module ownership support: - Move the module-related types into a new 'module' module and make the 'THIS_MODULE' pointer a constant of 'ModuleMetadata' so that modules can provide the pointer in const contexts, and add a 'this_module' 'const fn' to retrieve it This was enabled by upstream Rust's work on the 'const_mut_refs' and 'const_refs_to_static' features which were stabilized back in Rust 1.83.0 - Teach '#[vtable]' to associate implementations with their owning module, defaulting to the local one, including fallbacks for doctests, uses within the 'kernel' crate (like upcoming KUnit '#[test]'s for DRM) and 'rusttest' - Set 'fops.owner' from the module pointer for DRM and miscdevice - Migrate Rust Binder and configfs away from the old 'THIS_MODULE' 'static' and finally remove it from the 'module!' macro - 'num' module: - Add the new 'casts' module for lossless integer conversions Rust's 'core' library's 'From' implementations do not cover conversions that are not portable or future-proof. However, the kernel supports a narrower set of architectures, which makes it helpful to provide more infallible conversions, instead of having developers use 'as' casts, which carry the risk of silently losing data This goes along with previous work we did to avoid casts in Rust kernel code since they are more powerful than needed Thus, provide safe 'const' conversion functions (e.g. 'usize_as_u64' and 'u64_into_u8'), as well as the 'FromSafeCast' and 'IntoSafeCast' extension traits that provide conversions that are known to be lossless in the kernel, and an 'arch' submodule defining conversions that are known to be lossless on particular architectures (e.g. 64-bit platforms). For instance: // Conversion in const context. const USIZED_CONST: usize = u8_as_usize(255u8); // Non-const conversions. let a = u64::from_safe_cast(4096usize); let b: u64 = 4096usize.into_safe_cast(); - Add 'Bounded::shr_exact' method in the vein of 'try_shrink' which shifts a bounded right only if it loses no set bits - Fix unsoundness issue in the 'Bounded::shr' method by rejecting, at compile-time, shifts of at least the type's bit width - 'fmt' module: - Route '{:p}' raw pointer formatting through the kernel's hashed '%p' format to prevent address leaks, including support for width and padding. Include tests for both 'no_hash_pointers' case and the default (hashed) one - Fix the '{:p}' forwarding implementation, which could print the address of a temporary stack variable - 'time' module: - Make 'Delta' generic over its time unit, with a default unit of nanoseconds ('Nsec'), preserving the existing behavior. Then, add a 'Jiffy' time unit - Add the 'Delta::as_millis_ceil()' method - Fix 'as_micros_ceil()' rounding near 'i64::MAX', which could yield a result one microsecond too small - 'sync' module: - Implement 'ForeignOwnable' for 'ARef<T>', allowing C code to own an 'ARef<T>' - Add a safe abstraction for 'rcu_barrier()' - 'error' module: add all of the remaining error codes, except the deprecated compatibility aliases - 'bug' module: - Fix build error on UML in 'warn_on!' for callers from within the 'kernel' crate - Fix future 'dead_code' warning on arm and loongarch64 and under 'CONFIG_BUG=n' in 'warn_on!', which would trigger with the upcoming SRCU abstractions - Fix future build error in 'rusttest' on cross-compilation cases, which would trigger when 'warn_on!' has callers inside the 'kernel' crate - 'bitfield' module: fix build error for the upcoming support for Rust's GCC backend ('rustc_codegen_gcc') by always inlining a couple conversions used in tests 'pin-init' crate: - User-visible changes: - Merge the '__pinned_init' and '__init' methods and make 'Init' a marker trait - Introduce public APIs 'raw_init' and 'raw_try_init' to prevent users from needing to invoke the internal '__pinned_init' and '__init' methods - Emit errors for duplicate '#[pin]' attributes - Link 'Zeroable::zeroed' and 'pin_init::zeroed' in documentation - Other changes: - Fix unwind safety issues - Clean up lint 'allow' and 'expect's - Overhaul '#[cfg]' handling to pave the way for tuple structs and self-referential structs - Mark many functions as '#[inline]' for better codegen with '-C opt-level=s' ('CC_OPTIMIZE_FOR_SIZE') 'MAINTAINERS': - Update 'MODULE SUPPORT' to cover the new 'module' module And some other fixes, cleanups and improvements" * tag 'rust-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/ojeda/linux: (54 commits) rust: add functions and traits for lossless integer conversions rust: kernel: add `LocalModule` fallback for `#[vtable]` `impl`s rust: fmt: route {:p} through HashedPtr to prevent address leaks rust: fmt: fix {:p} printing stack addresses rust: module: update MAINTAINERS to cover module.rs rust: macros: remove `THIS_MODULE` static from `module!` rust_binder: use `LocalModule` for `THIS_MODULE` rust: configfs: use `LocalModule` for `THIS_MODULE` rust: miscdevice: set fops.owner from driver module pointer rust: drm: set fops.owner from driver module pointer rust: macros: auto-insert OwnerModule in #[vtable] rust: doctest: add LocalModule fallback for #[vtable] ThisModule rust: module: add `THIS_MODULE` const to `ModuleMetadata` trait rust: module: move module types into `module.rs` rust: num: add Bounded::shr_exact rust: num: reject Bounded::shr overshifts at build time rust: num: use const_assert! in Bounded rust: uapi: replace direct asm-generic/ioctl.h include with linux/ioctl.h rust: time: add Delta::as_millis_ceil() rust: time: add jiffies time unit for Delta ...
2026-08-12rust_binder: use `LocalModule` for `THIS_MODULE`Alvin Sun
Replace the `THIS_MODULE` static reference in the binder fops with `this_module::<LocalModule>()`, consistent with the move of `THIS_MODULE` into the `ModuleMetadata` trait. Assisted-by: opencode:glm-5.2 Reviewed-by: Gary Guo <gary@garyguo.net> Acked-by: Danilo Krummrich <dakr@kernel.org> Reviewed-by: Alice Ryhl <aliceryhl@google.com> Signed-off-by: Alvin Sun <alvin.sun@linux.dev> Link: https://patch.msgid.link/20260811-fix-fops-owner-v10-8-7e71776f9dbe@linux.dev Signed-off-by: Miguel Ojeda <ojeda@kernel.org>
2026-07-31rust_binder: update indentation of failed transaction printAlice Ryhl
To properly take the changes from commit bb66b1a34525 ("rust_binder: only print failure if error has source") into account, the binder_debug! statement was moved inside the if {} block, and so there must be one more level of indentation. Signed-off-by: Alice Ryhl <aliceryhl@google.com> Link: https://patch.msgid.link/20260728061236.198267-1-aliceryhl@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-31rust_binder: Update transaction flags to use kernel::impl_flags!Jahnavi MN
Transaction configuration flags are currently represented as raw integers and manipulated via bitwise operations. This lacks type safety, making it possible to mix up different flag types without compile-time warnings. Use kernel::impl_flags! to migrate the transaction flags to a strongly-typed bitmask, enforcing compile-time safety. Key changes: - Define `TransactionFlags(u32)` and `TransactionFlag` with 4 variants. - Change flags field type to `TransactionFlags` in structs. - Add `is_oneway` helper on `TransactionFlags` to simplify checks. - Update `can_replace` logic to use type-safe combined flag checks. - Convert `flags` to `u32` for FFI boundaries and logging. Reviewed-by: Alice Ryhl <aliceryhl@google.com> Signed-off-by: Jahnavi MN <jahnavimn@google.com> Link: https://patch.msgid.link/20260719-b4-rust_binder_impl_flags-v3-2-f8d0b3ea1b87@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-31rust_binder: Update looper_flags bitmaps to use kernel::impl_flags!Jahnavi MN
Thread looper states are currently represented as raw integers and manipulated via bitwise operations. This lacks type safety, making it possible to mix up different flag types without compile-time warnings. Use kernel::impl_flags! to migrate looper_flags to a strongly-typed bitmask, enforcing compile-time safety. Key changes: - Define `LooperFlags(u32)` and `LooperFlag` enum with 7 variants. - Change `InnerThread.looper_flags` type to `LooperFlags`. - Update looper state transitions and checks to use type-safe methods. - Convert `looper_flags` to `u32` for hex formatting in `debug_print`. Reviewed-by: Alice Ryhl <aliceryhl@google.com> Signed-off-by: Jahnavi MN <jahnavimn@google.com> Link: https://patch.msgid.link/20260719-b4-rust_binder_impl_flags-v3-1-f8d0b3ea1b87@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-31rust_binder: add ownership assertion to Node::add_deathGeorgios Androutsopoulos
The `// SAFETY:` comment in NodeDeath::set_cleared assumes that a NodeDeath is never inserted into the death list of any Node other than its owner. However, this invariant is not enforced by the safe function Node::add_death, which inserts NodeDeath into the death list without checking that death.node == self, leaving a risk for future code that may miss this implicit invariant and cause undefined behavior. Add an assertion to make this precondition explicit and catch potential violations early. Link: https://github.com/Rust-for-Linux/linux/issues/1237 Signed-off-by: Georgios Androutsopoulos <georgeandrout13@gmail.com> Reviewed-by: Alice Ryhl <aliceryhl@google.com> Link: https://patch.msgid.link/20260616170956.2580772-1-georgeandrout13@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-31rust_binder: do not query current thread for all ioctlsAlice Ryhl
The get_current_thread() method is currently called for every ioctl to ensure that a Thread struct exists for the thread calling into the driver. However, not all ioctls require a Thread object, so this means we are unnecessarily creating these objects in cases where we don't need to. If said thread does not invoke BINDER_THREAD_EXIT on exit, Binder's Thread struct stays around until the fd is closed. For long-lived processes the Thread object is effectively leaked. Furthermore, when the BINDER_GET_NODE_DEBUG_INFO ioctl is invoked by libmemunreachable to ensure that objects reachable only through the Binder driver are not considered leaked, this is done from a fork of the process owning the fd, which means that it fails the group_leader check inside get_current_thread(). This results in EINVAL errors for this ioctl, causing libmemunreachable to report a false positive memory leak. Thus, do not invoke get_current_thread() for ioctls that do not require it. Signed-off-by: Alice Ryhl <aliceryhl@google.com> Cc: stable <stable@kernel.org> Fixes: eafedbc7c050 ("rust_binder: add Rust Binder driver") Acked-by: Carlos Llamas <cmllamas@google.com> Link: https://patch.msgid.link/20260727-binder-cur-thread-v1-1-8edf2b64e235@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-27Merge 7.2-rc5 into char-misc-nextGreg Kroah-Hartman
We need the char/misc fixes AND this resolves two merge conflicts in: drivers/android/binder/thread.rs drivers/misc/nsm.c Reported-by: Mark Brown <broonie@kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17rust_binder: only print failure if error has sourceAlice Ryhl
The commit that fixes BINDER_GET_EXTENDED_ERROR changed the condition for printing transaction failures so errors are printed even if the cause is a dead or frozen process. Undo this change so that the error is only printed if the failure has an errno associated with it. Cc: stable@kernel.org Fixes: 77bfebf11077 ("rust_binder: fix BINDER_GET_EXTENDED_ERROR") Signed-off-by: Alice Ryhl <aliceryhl@google.com> Link: https://patch.msgid.link/20260708-get-extended-error-fix-printing-v1-1-6e293b213b70@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17rust_binder: use pin_init::zeroed for file_operations initializationNicolás Antinori
All types in `bindings` implement `Zeroable` if they can. This enables using `pin_init::zeroed()` for `file_operations` initialization instead of relying on `unsafe { core::mem::MaybeUninit::zeroed().assume_init() }`. This change improves readability and removes an unnecessary unsafe block. Link: https://github.com/Rust-for-Linux/linux/issues/1189 Suggested-by: Benno Lossin <lossin@kernel.org> Signed-off-by: Nicolás Antinori <nico.antinori.7@gmail.com> Link: https://patch.msgid.link/20260702205803.552476-1-nico.antinori.7@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17rust_binder: Update defer_work bitmaps to use kernel::impl_flags!Jahnavi MN
- Define `DeferWorks(u8)` and `DeferWork` enum using `bit_u8` offsets. - Change `ProcessInner.defer_work` type from `u8` to `DeferWorks`. - Update `Process::release()` and `Process::flush()` to check for empty states using `DeferWorks::empty()`. - Update the workqueue runner to inspect flags using `.contains()`. Signed-off-by: Jahnavi MN <jahnavimn@google.com> Reviewed-by: Alice Ryhl <aliceryhl@google.com> Link: https://patch.msgid.link/20260716-b4-rust_binder_impl_flags-v1-1-b4201d3f15b3@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17rust_binder: move (e)poll wait queue to ProcessAlice Ryhl
Most processes do not use Rust Binder with epoll, so avoid paying the synchronize_rcu() cost in drop for those that don't need it. For those that do, we also manage to replace synchronize_rcu() with kfree_rcu(), though we introduce an extra allocation. In case the last ref to an Arc<Thread> is dropped outside of deferred_release(), this also ensures that synchronize_rcu() is not called in destructor of Arc<Thread> in other places. Theoretically that could lead to jank by making other syscalls slow, which would be problematic. Signed-off-by: Alice Ryhl <aliceryhl@google.com> Reviewed-by: Boqun Feng <boqun@kernel.org> Link: https://patch.msgid.link/20260707-upgrade-poll-v6-2-4b8fae7bf1d9@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17rust_binder: report netlink transactionsCarlos Llamas
The Android Binder driver supports a netlink API that reports transaction *failures* to a userspace daemon. This allows devices to monitor processes with many failed transactions so that it can e.g. kill misbehaving apps. One very important thing that this monitors is when many oneway messages are sent to a frozen process, so there is special handling to ensure this scenario is surfaced over netlink. Signed-off-by: Carlos Llamas <cmllamas@google.com> Acked-by: Carlos Llamas <cmllamas@google.com> Co-developed-by: Alice Ryhl <aliceryhl@google.com> Signed-off-by: Alice Ryhl <aliceryhl@google.com> Link: https://patch.msgid.link/20260707-binder-netlink-v7-3-42b40e4b1ac8@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17rust_binder: Implement BINDER_DEBUG_DEAD_TRANSACTIONJahnavi MN
This adds dynamic debug logs for: - Releasing active transactions during thread stack unwinding. - Discarded transaction error codes when a thread exits. - Undelivered transaction acknowledgments (TRANSACTION_COMPLETE) upon thread exit. - Undelivered process death and freeze notifications when processes exit or die. - Undelivered transactions canceled due to target process death. We now store the process PID in `ThreadError`, `DeliverCode`, and `FreezeMessage` to ensure the correct PID is logged on cancellation. This is necessary because `cancel()` runs from background `kworkers`, which would otherwise print the wrong PID. Reviewed-by: Alice Ryhl <aliceryhl@google.com> Reviewed-by: Carlos Llamas <cmllamas@google.com> Signed-off-by: Jahnavi MN <jahnavimn@google.com> Link: https://patch.msgid.link/20260716-rust_binder_debug_mask-v4-7-3d7436c2d2f2@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17rust_binder: Implement BINDER_DEBUG_DEATH_NOTIFICATIONJahnavi MN
This adds dynamic debug logs for: - Memory allocation (OOM) failures when requesting death notifications - Registration and cancellation lifecycle events (BC_REQUEST / BC_CLEAR) - Delivery of death notification events to userspace (BR_DEAD_BINDER) Reviewed-by: Carlos Llamas <cmllamas@google.com> Reviewed-by: Alice Ryhl <aliceryhl@google.com> Signed-off-by: Jahnavi MN <jahnavimn@google.com> Link: https://patch.msgid.link/20260716-rust_binder_debug_mask-v4-6-3d7436c2d2f2@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17rust_binder: Implement BINDER_DEBUG_FAILED_TRANSACTIONJahnavi MN
This adds dynamic debug logs for: - Failed replies, target process deaths, and error code deliveries. - Detailed transaction failure diagnostics (including sender/receiver PIDs, TIDs, transaction IDs, buffer sizes, and error codes). Reviewed-by: Carlos Llamas <cmllamas@google.com> Reviewed-by: Alice Ryhl <aliceryhl@google.com> Signed-off-by: Jahnavi MN <jahnavimn@google.com> Link: https://patch.msgid.link/20260716-rust_binder_debug_mask-v4-5-3d7436c2d2f2@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17rust_binder: Implement BINDER_DEBUG_USER_ERROR for transaction parsing failuresJahnavi MN
This adds dynamic debug logs in `thread.rs` for: - File descriptor array (FDA) parent offset and parent buffer address alignment misalignments. - Memory copy, write, and translation failures during transaction serialization (including out-of-bounds pointer fixups). - Incoming transactions or replies that do not match the expected thread calling stack (such as out-of-order replies). Reviewed-by: Carlos Llamas <cmllamas@google.com> Reviewed-by: Alice Ryhl <aliceryhl@google.com> Signed-off-by: Jahnavi MN <jahnavimn@google.com> Link: https://patch.msgid.link/20260716-rust_binder_debug_mask-v4-4-3d7436c2d2f2@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17rust_binder: Implement BINDER_DEBUG_USER_ERROR for refcounting and death ↵Jahnavi MN
notifications This adds dynamic debug logs for: - Decrementing handle reference counts that are already zero. - Mismatched reference states (calling inc_ref_done with no active inc_refs, or using a weak reference as a strong reference). - Requesting or clearing death notifications on invalid references, already active notifications, or with mismatched cookies. Reviewed-by: Carlos Llamas <cmllamas@google.com> Reviewed-by: Alice Ryhl <aliceryhl@google.com> Signed-off-by: Jahnavi MN <jahnavimn@google.com> Link: https://patch.msgid.link/20260716-rust_binder_debug_mask-v4-3-3d7436c2d2f2@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17rust_binder: Implement BINDER_DEBUG_USER_ERROR for freezer-related operationJahnavi MN
This adds dynamic debug logs for: - Requesting freeze notifications on invalid references, duplicate cookies, or already active registrations. - Completing freeze notifications that are not pending or not found. - Clearing freeze notifications on invalid references, inactive notifications, or cookie mismatches. Reviewed-by: Carlos Llamas <cmllamas@google.com> Reviewed-by: Alice Ryhl <aliceryhl@google.com> Signed-off-by: Jahnavi MN <jahnavimn@google.com> Link: https://patch.msgid.link/20260716-rust_binder_debug_mask-v4-2-3d7436c2d2f2@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17rust_binder: Add dynamic debug logging maskJahnavi MN
Implement a dynamic debug logging mask (`debug_mask`) for the `rust_binder` module to allow dynamic runtime configuration of log levels. This enables parity with the legacy C driver's debug mask. Since the Rust `module!` macro in the current kernel build does not yet support declaring module parameters directly in Rust, we define the `debug_mask` variable in Rust as an `Atomic<u32>` exported via FFI using `#[no_mangle]`, and link to it as `extern` in a C companion file to expose it to the kernel runtime. To verify the setup, instrument process lifecycle events (open, flush, and release) in `process.rs` under the new `BINDER_DEBUG_OPEN_CLOSE` logging mask. These entry-point events are chosen for initial validation because they represent the start of the Binder lifecycle and occur at low frequency, allowing simple runtime verification of the dynamic toggle without log noise. Reviewed-by: Carlos Llamas <cmllamas@google.com> Reviewed-by: Alice Ryhl <aliceryhl@google.com> Signed-off-by: Jahnavi MN <jahnavimn@google.com> Link: https://patch.msgid.link/20260716-rust_binder_debug_mask-v4-1-3d7436c2d2f2@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>