rust_binder: Implement BINDER_DEBUG_USER_ERROR for refcounting and death notifications

This adds dynamic debug logs for:
- Decrementing handle reference counts that are already zero.
- Mismatched reference states (calling inc_ref_done with no active
  inc_refs, or using a weak reference as a strong reference).
- Requesting or clearing death notifications on invalid references,
  already active notifications, or with mismatched cookies.

Reviewed-by: Carlos Llamas <cmllamas@google.com>
Reviewed-by: Alice Ryhl <aliceryhl@google.com>
Signed-off-by: Jahnavi MN <jahnavimn@google.com>
Link: https://patch.msgid.link/20260716-rust_binder_debug_mask-v4-3-3d7436c2d2f2@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
Jahnavi MN
2026-07-16 08:37:45 +00:00
committed by Greg Kroah-Hartman
parent d8f87e4ede
commit 11071c63a9
2 changed files with 34 additions and 11 deletions

View File

@@ -345,7 +345,7 @@ pub(crate) fn inc_ref_done_locked(
) -> Option<DLArc<Node>> {
let inner = self.inner.access_mut(owner_inner);
if inner.active_inc_refs == 0 {
pr_err!("inc_ref_done called when no active inc_refs");
binder_debug!(UserError, "inc_ref_done called when no active inc_refs");
return None;
}
@@ -821,6 +821,7 @@ pub(crate) fn get_count(&self) -> (usize, usize) {
pub(crate) fn clone(&self, strong: bool) -> Result<NodeRef> {
if strong && self.strong_count == 0 {
binder_debug!(UserError, "tried to use weak ref as strong ref");
return Err(EINVAL);
}
Ok(self
@@ -861,9 +862,10 @@ pub(crate) fn update(&mut self, inc: bool, strong: bool) -> bool {
*count += 1;
} else {
if *count == 0 {
pr_warn!(
"pid {} performed invalid decrement on ref\n",
kernel::current!().pid()
binder_debug!(
UserError,
"performed invalid {} decrement on ref",
if strong { "strong" } else { "weak" }
);
return false;
}

View File

@@ -912,7 +912,13 @@ pub(crate) fn get_transaction_node(&self, handle: u32) -> BinderResult<NodeRef>
}
Ok(node_ref)
} else {
Ok(self.get_node_from_handle(handle, true)?)
match self.get_node_from_handle(handle, true) {
Ok(node_ref) => Ok(node_ref),
Err(err) => {
binder_debug!(UserError, "got transaction to invalid handle {handle}");
Err(err.into())
}
}
}
}
@@ -997,7 +1003,7 @@ pub(crate) fn update_ref(
} else {
// All refs are cleared in process exit, so this warning is expected in that case.
if !self.inner.lock().is_dead {
pr_warn!("{}: no such ref {handle}\n", self.pid_in_current_ns());
binder_debug!(UserError, "no such ref {handle}");
}
}
Ok(())
@@ -1250,13 +1256,19 @@ pub(crate) fn request_death(
})?;
let mut refs = self.node_refs.lock();
let Some(info) = refs.by_handle.get_mut(&handle) else {
pr_warn!("BC_REQUEST_DEATH_NOTIFICATION invalid ref {handle}\n");
binder_debug!(
UserError,
"BC_REQUEST_DEATH_NOTIFICATION invalid ref {handle}"
);
return Ok(());
};
// Nothing to do if there is already a death notification request for this handle.
if info.death().is_some() {
pr_warn!("BC_REQUEST_DEATH_NOTIFICATION death notification already set\n");
binder_debug!(
UserError,
"BC_REQUEST_DEATH_NOTIFICATION death notification already set"
);
return Ok(());
}
@@ -1293,17 +1305,26 @@ pub(crate) fn clear_death(&self, reader: &mut UserSliceReader, thread: &Thread)
let mut refs = self.node_refs.lock();
let Some(info) = refs.by_handle.get_mut(&handle) else {
pr_warn!("BC_CLEAR_DEATH_NOTIFICATION invalid ref {handle}\n");
binder_debug!(
UserError,
"BC_CLEAR_DEATH_NOTIFICATION invalid ref {handle}"
);
return Ok(());
};
let Some(death) = info.death().take() else {
pr_warn!("BC_CLEAR_DEATH_NOTIFICATION death notification not active\n");
binder_debug!(
UserError,
"BC_CLEAR_DEATH_NOTIFICATION death notification not active"
);
return Ok(());
};
if death.cookie != cookie {
*info.death() = Some(death);
pr_warn!("BC_CLEAR_DEATH_NOTIFICATION death notification cookie mismatch\n");
binder_debug!(
UserError,
"BC_CLEAR_DEATH_NOTIFICATION death notification cookie mismatch"
);
return Ok(());
}