1 // SPDX-License-Identifier: GPL-2.0-only 2 /* binder.c 3 * 4 * Android IPC Subsystem 5 * 6 * Copyright (C) 2007-2008 Google, Inc. 7 */ 8 9 /* 10 * Locking overview 11 * 12 * There are 3 main spinlocks which must be acquired in the 13 * order shown: 14 * 15 * 1) proc->outer_lock : protects binder_ref 16 * binder_proc_lock() and binder_proc_unlock() are 17 * used to acq/rel. 18 * 2) node->lock : protects most fields of binder_node. 19 * binder_node_lock() and binder_node_unlock() are 20 * used to acq/rel 21 * 3) proc->inner_lock : protects the thread and node lists 22 * (proc->threads, proc->waiting_threads, proc->nodes) 23 * and all todo lists associated with the binder_proc 24 * (proc->todo, thread->todo, proc->delivered_death and 25 * node->async_todo), as well as thread->transaction_stack 26 * binder_inner_proc_lock() and binder_inner_proc_unlock() 27 * are used to acq/rel 28 * 29 * Any lock under procA must never be nested under any lock at the same 30 * level or below on procB. 31 * 32 * Functions that require a lock held on entry indicate which lock 33 * in the suffix of the function name: 34 * 35 * foo_olocked() : requires node->outer_lock 36 * foo_nlocked() : requires node->lock 37 * foo_ilocked() : requires proc->inner_lock 38 * foo_oilocked(): requires proc->outer_lock and proc->inner_lock 39 * foo_nilocked(): requires node->lock and proc->inner_lock 40 * ... 41 */ 42 43 #define pr_fmt(fmt) KBUILD_MODNAME ": " fmt 44 45 #include <linux/fdtable.h> 46 #include <linux/file.h> 47 #include <linux/freezer.h> 48 #include <linux/fs.h> 49 #include <linux/list.h> 50 #include <linux/miscdevice.h> 51 #include <linux/module.h> 52 #include <linux/mutex.h> 53 #include <linux/nsproxy.h> 54 #include <linux/poll.h> 55 #include <linux/debugfs.h> 56 #include <linux/rbtree.h> 57 #include <linux/sched/signal.h> 58 #include <linux/sched/mm.h> 59 #include <linux/seq_file.h> 60 #include <linux/string.h> 61 #include <linux/uaccess.h> 62 #include <linux/pid_namespace.h> 63 #include <linux/security.h> 64 #include <linux/spinlock.h> 65 #include <linux/ratelimit.h> 66 #include <linux/syscalls.h> 67 #include <linux/task_work.h> 68 #include <linux/sizes.h> 69 #include <linux/ktime.h> 70 71 #include <kunit/visibility.h> 72 73 #include <uapi/linux/android/binder.h> 74 75 #include <linux/cacheflush.h> 76 77 #include "binder_netlink.h" 78 #include "binder_internal.h" 79 #include "binder_trace.h" 80 81 static HLIST_HEAD(binder_deferred_list); 82 static DEFINE_MUTEX(binder_deferred_lock); 83 84 static HLIST_HEAD(binder_devices); 85 static DEFINE_SPINLOCK(binder_devices_lock); 86 87 static HLIST_HEAD(binder_procs); 88 static DEFINE_MUTEX(binder_procs_lock); 89 90 static HLIST_HEAD(binder_dead_nodes); 91 static DEFINE_SPINLOCK(binder_dead_nodes_lock); 92 93 static struct dentry *binder_debugfs_dir_entry_root; 94 static struct dentry *binder_debugfs_dir_entry_proc; 95 static atomic_t binder_last_id; 96 97 static int proc_show(struct seq_file *m, void *unused); 98 DEFINE_SHOW_ATTRIBUTE(proc); 99 100 #define FORBIDDEN_MMAP_FLAGS (VM_WRITE) 101 102 enum { 103 BINDER_DEBUG_USER_ERROR = 1U << 0, 104 BINDER_DEBUG_FAILED_TRANSACTION = 1U << 1, 105 BINDER_DEBUG_DEAD_TRANSACTION = 1U << 2, 106 BINDER_DEBUG_OPEN_CLOSE = 1U << 3, 107 BINDER_DEBUG_DEAD_BINDER = 1U << 4, 108 BINDER_DEBUG_DEATH_NOTIFICATION = 1U << 5, 109 BINDER_DEBUG_READ_WRITE = 1U << 6, 110 BINDER_DEBUG_USER_REFS = 1U << 7, 111 BINDER_DEBUG_THREADS = 1U << 8, 112 BINDER_DEBUG_TRANSACTION = 1U << 9, 113 BINDER_DEBUG_TRANSACTION_COMPLETE = 1U << 10, 114 BINDER_DEBUG_FREE_BUFFER = 1U << 11, 115 BINDER_DEBUG_INTERNAL_REFS = 1U << 12, 116 BINDER_DEBUG_PRIORITY_CAP = 1U << 13, 117 BINDER_DEBUG_SPINLOCKS = 1U << 14, 118 }; 119 static uint32_t binder_debug_mask = BINDER_DEBUG_USER_ERROR | 120 BINDER_DEBUG_FAILED_TRANSACTION | BINDER_DEBUG_DEAD_TRANSACTION; 121 module_param_named(debug_mask, binder_debug_mask, uint, 0644); 122 123 char *binder_devices_param = CONFIG_ANDROID_BINDER_DEVICES; 124 module_param_named(devices, binder_devices_param, charp, 0444); 125 126 static DECLARE_WAIT_QUEUE_HEAD(binder_user_error_wait); 127 static int binder_stop_on_user_error; 128 129 static int binder_set_stop_on_user_error(const char *val, 130 const struct kernel_param *kp) 131 { 132 int ret; 133 134 ret = param_set_int(val, kp); 135 if (binder_stop_on_user_error < 2) 136 wake_up(&binder_user_error_wait); 137 return ret; 138 } 139 module_param_call(stop_on_user_error, binder_set_stop_on_user_error, 140 param_get_int, &binder_stop_on_user_error, 0644); 141 142 static __printf(2, 3) void binder_debug(int mask, const char *format, ...) 143 { 144 struct va_format vaf; 145 va_list args; 146 147 if (binder_debug_mask & mask) { 148 va_start(args, format); 149 vaf.va = &args; 150 vaf.fmt = format; 151 pr_info_ratelimited("%pV", &vaf); 152 va_end(args); 153 } 154 } 155 156 #define binder_txn_error(x...) \ 157 binder_debug(BINDER_DEBUG_FAILED_TRANSACTION, x) 158 159 static __printf(1, 2) void binder_user_error(const char *format, ...) 160 { 161 struct va_format vaf; 162 va_list args; 163 164 if (binder_debug_mask & BINDER_DEBUG_USER_ERROR) { 165 va_start(args, format); 166 vaf.va = &args; 167 vaf.fmt = format; 168 pr_info_ratelimited("%pV", &vaf); 169 va_end(args); 170 } 171 172 if (binder_stop_on_user_error) 173 binder_stop_on_user_error = 2; 174 } 175 176 #define binder_set_extended_error(ee, _id, _command, _param) \ 177 do { \ 178 (ee)->id = _id; \ 179 (ee)->command = _command; \ 180 (ee)->param = _param; \ 181 } while (0) 182 183 #define to_flat_binder_object(hdr) \ 184 container_of(hdr, struct flat_binder_object, hdr) 185 186 #define to_binder_fd_object(hdr) container_of(hdr, struct binder_fd_object, hdr) 187 188 #define to_binder_buffer_object(hdr) \ 189 container_of(hdr, struct binder_buffer_object, hdr) 190 191 #define to_binder_fd_array_object(hdr) \ 192 container_of(hdr, struct binder_fd_array_object, hdr) 193 194 static struct binder_stats binder_stats; 195 196 static inline void binder_stats_deleted(enum binder_stat_types type) 197 { 198 atomic_inc(&binder_stats.obj_deleted[type]); 199 } 200 201 static inline void binder_stats_created(enum binder_stat_types type) 202 { 203 atomic_inc(&binder_stats.obj_created[type]); 204 } 205 206 struct binder_transaction_log_entry { 207 int debug_id; 208 int debug_id_done; 209 int call_type; 210 int from_proc; 211 int from_thread; 212 int target_handle; 213 int to_proc; 214 int to_thread; 215 int to_node; 216 int data_size; 217 int offsets_size; 218 int return_error_line; 219 uint32_t return_error; 220 uint32_t return_error_param; 221 char context_name[BINDERFS_MAX_NAME + 1]; 222 }; 223 224 struct binder_transaction_log { 225 atomic_t cur; 226 bool full; 227 struct binder_transaction_log_entry entry[32]; 228 }; 229 230 static struct binder_transaction_log binder_transaction_log; 231 static struct binder_transaction_log binder_transaction_log_failed; 232 233 static struct binder_transaction_log_entry *binder_transaction_log_add( 234 struct binder_transaction_log *log) 235 { 236 struct binder_transaction_log_entry *e; 237 unsigned int cur = atomic_inc_return(&log->cur); 238 239 if (cur >= ARRAY_SIZE(log->entry)) 240 log->full = true; 241 e = &log->entry[cur % ARRAY_SIZE(log->entry)]; 242 WRITE_ONCE(e->debug_id_done, 0); 243 /* 244 * write-barrier to synchronize access to e->debug_id_done. 245 * We make sure the initialized 0 value is seen before 246 * memset() other fields are zeroed by memset. 247 */ 248 smp_wmb(); 249 memset(e, 0, sizeof(*e)); 250 return e; 251 } 252 253 enum binder_deferred_state { 254 BINDER_DEFERRED_FLUSH = 0x01, 255 BINDER_DEFERRED_RELEASE = 0x02, 256 }; 257 258 enum { 259 BINDER_LOOPER_STATE_REGISTERED = 0x01, 260 BINDER_LOOPER_STATE_ENTERED = 0x02, 261 BINDER_LOOPER_STATE_EXITED = 0x04, 262 BINDER_LOOPER_STATE_INVALID = 0x08, 263 BINDER_LOOPER_STATE_WAITING = 0x10, 264 BINDER_LOOPER_STATE_POLL = 0x20, 265 }; 266 267 /** 268 * binder_proc_lock() - Acquire outer lock for given binder_proc 269 * @proc: struct binder_proc to acquire 270 * 271 * Acquires proc->outer_lock. Used to protect binder_ref 272 * structures associated with the given proc. 273 */ 274 #define binder_proc_lock(proc) _binder_proc_lock(proc, __LINE__) 275 static void 276 _binder_proc_lock(struct binder_proc *proc, int line) 277 __acquires(&proc->outer_lock) 278 { 279 binder_debug(BINDER_DEBUG_SPINLOCKS, 280 "%s: line=%d\n", __func__, line); 281 spin_lock(&proc->outer_lock); 282 } 283 284 /** 285 * binder_proc_unlock() - Release outer lock for given binder_proc 286 * @proc: struct binder_proc to acquire 287 * 288 * Release lock acquired via binder_proc_lock() 289 */ 290 #define binder_proc_unlock(proc) _binder_proc_unlock(proc, __LINE__) 291 static void 292 _binder_proc_unlock(struct binder_proc *proc, int line) 293 __releases(&proc->outer_lock) 294 { 295 binder_debug(BINDER_DEBUG_SPINLOCKS, 296 "%s: line=%d\n", __func__, line); 297 spin_unlock(&proc->outer_lock); 298 } 299 300 /** 301 * binder_inner_proc_lock() - Acquire inner lock for given binder_proc 302 * @proc: struct binder_proc to acquire 303 * 304 * Acquires proc->inner_lock. Used to protect todo lists 305 */ 306 #define binder_inner_proc_lock(proc) _binder_inner_proc_lock(proc, __LINE__) 307 static void 308 _binder_inner_proc_lock(struct binder_proc *proc, int line) 309 __acquires(&proc->inner_lock) 310 { 311 binder_debug(BINDER_DEBUG_SPINLOCKS, 312 "%s: line=%d\n", __func__, line); 313 spin_lock(&proc->inner_lock); 314 } 315 316 /** 317 * binder_inner_proc_unlock() - Release inner lock for given binder_proc 318 * @proc: struct binder_proc to acquire 319 * 320 * Release lock acquired via binder_inner_proc_lock() 321 */ 322 #define binder_inner_proc_unlock(proc) _binder_inner_proc_unlock(proc, __LINE__) 323 static void 324 _binder_inner_proc_unlock(struct binder_proc *proc, int line) 325 __releases(&proc->inner_lock) 326 { 327 binder_debug(BINDER_DEBUG_SPINLOCKS, 328 "%s: line=%d\n", __func__, line); 329 spin_unlock(&proc->inner_lock); 330 } 331 332 /** 333 * binder_node_lock() - Acquire spinlock for given binder_node 334 * @node: struct binder_node to acquire 335 * 336 * Acquires node->lock. Used to protect binder_node fields 337 */ 338 #define binder_node_lock(node) _binder_node_lock(node, __LINE__) 339 static void 340 _binder_node_lock(struct binder_node *node, int line) 341 __acquires(&node->lock) 342 { 343 binder_debug(BINDER_DEBUG_SPINLOCKS, 344 "%s: line=%d\n", __func__, line); 345 spin_lock(&node->lock); 346 } 347 348 /** 349 * binder_node_unlock() - Release spinlock for given binder_proc 350 * @node: struct binder_node to acquire 351 * 352 * Release lock acquired via binder_node_lock() 353 */ 354 #define binder_node_unlock(node) _binder_node_unlock(node, __LINE__) 355 static void 356 _binder_node_unlock(struct binder_node *node, int line) 357 __releases(&node->lock) 358 { 359 binder_debug(BINDER_DEBUG_SPINLOCKS, 360 "%s: line=%d\n", __func__, line); 361 spin_unlock(&node->lock); 362 } 363 364 /** 365 * binder_node_inner_lock() - Acquire node and inner locks 366 * @node: struct binder_node to acquire 367 * 368 * Acquires node->lock. If node->proc also acquires 369 * proc->inner_lock. Used to protect binder_node fields 370 */ 371 #define binder_node_inner_lock(node) _binder_node_inner_lock(node, __LINE__) 372 static void 373 _binder_node_inner_lock(struct binder_node *node, int line) 374 __acquires(&node->lock) __acquires(&node->proc->inner_lock) 375 { 376 binder_debug(BINDER_DEBUG_SPINLOCKS, 377 "%s: line=%d\n", __func__, line); 378 spin_lock(&node->lock); 379 if (node->proc) 380 binder_inner_proc_lock(node->proc); 381 else 382 /* annotation for sparse */ 383 __acquire(&node->proc->inner_lock); 384 } 385 386 /** 387 * binder_node_inner_unlock() - Release node and inner locks 388 * @node: struct binder_node to acquire 389 * 390 * Release lock acquired via binder_node_lock() 391 */ 392 #define binder_node_inner_unlock(node) _binder_node_inner_unlock(node, __LINE__) 393 static void 394 _binder_node_inner_unlock(struct binder_node *node, int line) 395 __releases(&node->lock) __releases(&node->proc->inner_lock) 396 { 397 struct binder_proc *proc = node->proc; 398 399 binder_debug(BINDER_DEBUG_SPINLOCKS, 400 "%s: line=%d\n", __func__, line); 401 if (proc) 402 binder_inner_proc_unlock(proc); 403 else 404 /* annotation for sparse */ 405 __release(&node->proc->inner_lock); 406 spin_unlock(&node->lock); 407 } 408 409 static bool binder_worklist_empty_ilocked(struct list_head *list) 410 { 411 return list_empty(list); 412 } 413 414 /** 415 * binder_worklist_empty() - Check if no items on the work list 416 * @proc: binder_proc associated with list 417 * @list: list to check 418 * 419 * Return: true if there are no items on list, else false 420 */ 421 static bool binder_worklist_empty(struct binder_proc *proc, 422 struct list_head *list) 423 { 424 bool ret; 425 426 binder_inner_proc_lock(proc); 427 ret = binder_worklist_empty_ilocked(list); 428 binder_inner_proc_unlock(proc); 429 return ret; 430 } 431 432 /** 433 * binder_enqueue_work_ilocked() - Add an item to the work list 434 * @work: struct binder_work to add to list 435 * @target_list: list to add work to 436 * 437 * Adds the work to the specified list. Asserts that work 438 * is not already on a list. 439 * 440 * Requires the proc->inner_lock to be held. 441 */ 442 static void 443 binder_enqueue_work_ilocked(struct binder_work *work, 444 struct list_head *target_list) 445 { 446 BUG_ON(target_list == NULL); 447 BUG_ON(work->entry.next && !list_empty(&work->entry)); 448 list_add_tail(&work->entry, target_list); 449 } 450 451 /** 452 * binder_enqueue_deferred_thread_work_ilocked() - Add deferred thread work 453 * @thread: thread to queue work to 454 * @work: struct binder_work to add to list 455 * 456 * Adds the work to the todo list of the thread. Doesn't set the process_todo 457 * flag, which means that (if it wasn't already set) the thread will go to 458 * sleep without handling this work when it calls read. 459 * 460 * Requires the proc->inner_lock to be held. 461 */ 462 static void 463 binder_enqueue_deferred_thread_work_ilocked(struct binder_thread *thread, 464 struct binder_work *work) 465 { 466 WARN_ON(!list_empty(&thread->waiting_thread_node)); 467 binder_enqueue_work_ilocked(work, &thread->todo); 468 } 469 470 /** 471 * binder_enqueue_thread_work_ilocked() - Add an item to the thread work list 472 * @thread: thread to queue work to 473 * @work: struct binder_work to add to list 474 * 475 * Adds the work to the todo list of the thread, and enables processing 476 * of the todo queue. 477 * 478 * Requires the proc->inner_lock to be held. 479 */ 480 static void 481 binder_enqueue_thread_work_ilocked(struct binder_thread *thread, 482 struct binder_work *work) 483 { 484 WARN_ON(!list_empty(&thread->waiting_thread_node)); 485 binder_enqueue_work_ilocked(work, &thread->todo); 486 487 /* (e)poll-based threads require an explicit wakeup signal when 488 * queuing their own work; they rely on these events to consume 489 * messages without I/O block. Without it, threads risk waiting 490 * indefinitely without handling the work. 491 */ 492 if (thread->looper & BINDER_LOOPER_STATE_POLL && 493 thread->pid == current->pid && !thread->process_todo) 494 wake_up_interruptible_sync(&thread->wait); 495 496 thread->process_todo = true; 497 } 498 499 /** 500 * binder_enqueue_thread_work() - Add an item to the thread work list 501 * @thread: thread to queue work to 502 * @work: struct binder_work to add to list 503 * 504 * Adds the work to the todo list of the thread, and enables processing 505 * of the todo queue. 506 */ 507 static void 508 binder_enqueue_thread_work(struct binder_thread *thread, 509 struct binder_work *work) 510 { 511 binder_inner_proc_lock(thread->proc); 512 binder_enqueue_thread_work_ilocked(thread, work); 513 binder_inner_proc_unlock(thread->proc); 514 } 515 516 static void 517 binder_dequeue_work_ilocked(struct binder_work *work) 518 { 519 list_del_init(&work->entry); 520 } 521 522 /** 523 * binder_dequeue_work() - Removes an item from the work list 524 * @proc: binder_proc associated with list 525 * @work: struct binder_work to remove from list 526 * 527 * Removes the specified work item from whatever list it is on. 528 * Can safely be called if work is not on any list. 529 */ 530 static void 531 binder_dequeue_work(struct binder_proc *proc, struct binder_work *work) 532 { 533 binder_inner_proc_lock(proc); 534 binder_dequeue_work_ilocked(work); 535 binder_inner_proc_unlock(proc); 536 } 537 538 static struct binder_work *binder_dequeue_work_head_ilocked( 539 struct list_head *list) 540 { 541 struct binder_work *w; 542 543 w = list_first_entry_or_null(list, struct binder_work, entry); 544 if (w) 545 list_del_init(&w->entry); 546 return w; 547 } 548 549 static void 550 binder_defer_work(struct binder_proc *proc, enum binder_deferred_state defer); 551 static void binder_free_thread(struct binder_thread *thread); 552 static void binder_free_proc(struct binder_proc *proc); 553 static void binder_inc_node_tmpref_ilocked(struct binder_node *node); 554 555 static bool binder_has_work_ilocked(struct binder_thread *thread, 556 bool do_proc_work) 557 { 558 return thread->process_todo || 559 thread->looper_need_return || 560 (do_proc_work && 561 !binder_worklist_empty_ilocked(&thread->proc->todo)); 562 } 563 564 static bool binder_has_work(struct binder_thread *thread, bool do_proc_work) 565 { 566 bool has_work; 567 568 binder_inner_proc_lock(thread->proc); 569 has_work = binder_has_work_ilocked(thread, do_proc_work); 570 binder_inner_proc_unlock(thread->proc); 571 572 return has_work; 573 } 574 575 static bool binder_available_for_proc_work_ilocked(struct binder_thread *thread) 576 { 577 return !thread->transaction_stack && 578 binder_worklist_empty_ilocked(&thread->todo); 579 } 580 581 static void binder_wakeup_poll_threads_ilocked(struct binder_proc *proc, 582 bool sync) 583 { 584 struct rb_node *n; 585 struct binder_thread *thread; 586 587 for (n = rb_first(&proc->threads); n != NULL; n = rb_next(n)) { 588 thread = rb_entry(n, struct binder_thread, rb_node); 589 if (thread->looper & BINDER_LOOPER_STATE_POLL && 590 binder_available_for_proc_work_ilocked(thread)) { 591 if (sync) 592 wake_up_interruptible_sync(&thread->wait); 593 else 594 wake_up_interruptible(&thread->wait); 595 } 596 } 597 } 598 599 /** 600 * binder_select_thread_ilocked() - selects a thread for doing proc work. 601 * @proc: process to select a thread from 602 * 603 * Note that calling this function moves the thread off the waiting_threads 604 * list, so it can only be woken up by the caller of this function, or a 605 * signal. Therefore, callers *should* always wake up the thread this function 606 * returns. 607 * 608 * Return: If there's a thread currently waiting for process work, 609 * returns that thread. Otherwise returns NULL. 610 */ 611 static struct binder_thread * 612 binder_select_thread_ilocked(struct binder_proc *proc) 613 { 614 struct binder_thread *thread; 615 616 assert_spin_locked(&proc->inner_lock); 617 thread = list_first_entry_or_null(&proc->waiting_threads, 618 struct binder_thread, 619 waiting_thread_node); 620 621 if (thread) 622 list_del_init(&thread->waiting_thread_node); 623 624 return thread; 625 } 626 627 /** 628 * binder_wakeup_thread_ilocked() - wakes up a thread for doing proc work. 629 * @proc: process to wake up a thread in 630 * @thread: specific thread to wake-up (may be NULL) 631 * @sync: whether to do a synchronous wake-up 632 * 633 * This function wakes up a thread in the @proc process. 634 * The caller may provide a specific thread to wake-up in 635 * the @thread parameter. If @thread is NULL, this function 636 * will wake up threads that have called poll(). 637 * 638 * Note that for this function to work as expected, callers 639 * should first call binder_select_thread() to find a thread 640 * to handle the work (if they don't have a thread already), 641 * and pass the result into the @thread parameter. 642 */ 643 static void binder_wakeup_thread_ilocked(struct binder_proc *proc, 644 struct binder_thread *thread, 645 bool sync) 646 { 647 assert_spin_locked(&proc->inner_lock); 648 649 if (thread) { 650 if (sync) 651 wake_up_interruptible_sync(&thread->wait); 652 else 653 wake_up_interruptible(&thread->wait); 654 return; 655 } 656 657 /* Didn't find a thread waiting for proc work; this can happen 658 * in two scenarios: 659 * 1. All threads are busy handling transactions 660 * In that case, one of those threads should call back into 661 * the kernel driver soon and pick up this work. 662 * 2. Threads are using the (e)poll interface, in which case 663 * they may be blocked on the waitqueue without having been 664 * added to waiting_threads. For this case, we just iterate 665 * over all threads not handling transaction work, and 666 * wake them all up. We wake all because we don't know whether 667 * a thread that called into (e)poll is handling non-binder 668 * work currently. 669 */ 670 binder_wakeup_poll_threads_ilocked(proc, sync); 671 } 672 673 static void binder_wakeup_proc_ilocked(struct binder_proc *proc) 674 { 675 struct binder_thread *thread = binder_select_thread_ilocked(proc); 676 677 binder_wakeup_thread_ilocked(proc, thread, /* sync = */false); 678 } 679 680 static void binder_set_nice(long nice) 681 { 682 long min_nice; 683 684 if (can_nice(current, nice)) { 685 set_user_nice(current, nice); 686 return; 687 } 688 min_nice = rlimit_to_nice(rlimit(RLIMIT_NICE)); 689 binder_debug(BINDER_DEBUG_PRIORITY_CAP, 690 "%d: nice value %ld not allowed use %ld instead\n", 691 current->pid, nice, min_nice); 692 set_user_nice(current, min_nice); 693 if (min_nice <= MAX_NICE) 694 return; 695 binder_user_error("%d RLIMIT_NICE not set\n", current->pid); 696 } 697 698 static struct binder_node *binder_get_node_ilocked(struct binder_proc *proc, 699 binder_uintptr_t ptr) 700 { 701 struct rb_node *n = proc->nodes.rb_node; 702 struct binder_node *node; 703 704 assert_spin_locked(&proc->inner_lock); 705 706 while (n) { 707 node = rb_entry(n, struct binder_node, rb_node); 708 709 if (ptr < node->ptr) 710 n = n->rb_left; 711 else if (ptr > node->ptr) 712 n = n->rb_right; 713 else { 714 /* 715 * take an implicit weak reference 716 * to ensure node stays alive until 717 * call to binder_put_node() 718 */ 719 binder_inc_node_tmpref_ilocked(node); 720 return node; 721 } 722 } 723 return NULL; 724 } 725 726 static struct binder_node *binder_get_node(struct binder_proc *proc, 727 binder_uintptr_t ptr) 728 { 729 struct binder_node *node; 730 731 binder_inner_proc_lock(proc); 732 node = binder_get_node_ilocked(proc, ptr); 733 binder_inner_proc_unlock(proc); 734 return node; 735 } 736 737 static struct binder_node *binder_init_node_ilocked( 738 struct binder_proc *proc, 739 struct binder_node *new_node, 740 struct flat_binder_object *fp) 741 { 742 struct rb_node **p = &proc->nodes.rb_node; 743 struct rb_node *parent = NULL; 744 struct binder_node *node; 745 binder_uintptr_t ptr = fp ? fp->binder : 0; 746 binder_uintptr_t cookie = fp ? fp->cookie : 0; 747 __u32 flags = fp ? fp->flags : 0; 748 749 assert_spin_locked(&proc->inner_lock); 750 751 while (*p) { 752 753 parent = *p; 754 node = rb_entry(parent, struct binder_node, rb_node); 755 756 if (ptr < node->ptr) 757 p = &(*p)->rb_left; 758 else if (ptr > node->ptr) 759 p = &(*p)->rb_right; 760 else { 761 /* 762 * A matching node is already in 763 * the rb tree. Abandon the init 764 * and return it. 765 */ 766 binder_inc_node_tmpref_ilocked(node); 767 return node; 768 } 769 } 770 node = new_node; 771 binder_stats_created(BINDER_STAT_NODE); 772 node->tmp_refs++; 773 rb_link_node(&node->rb_node, parent, p); 774 rb_insert_color(&node->rb_node, &proc->nodes); 775 node->debug_id = atomic_inc_return(&binder_last_id); 776 node->proc = proc; 777 node->ptr = ptr; 778 node->cookie = cookie; 779 node->work.type = BINDER_WORK_NODE; 780 node->min_priority = flags & FLAT_BINDER_FLAG_PRIORITY_MASK; 781 node->accept_fds = !!(flags & FLAT_BINDER_FLAG_ACCEPTS_FDS); 782 node->txn_security_ctx = !!(flags & FLAT_BINDER_FLAG_TXN_SECURITY_CTX); 783 spin_lock_init(&node->lock); 784 INIT_LIST_HEAD(&node->work.entry); 785 INIT_LIST_HEAD(&node->async_todo); 786 binder_debug(BINDER_DEBUG_INTERNAL_REFS, 787 "%d:%d node %d u%016llx c%016llx created\n", 788 proc->pid, current->pid, node->debug_id, 789 (u64)node->ptr, (u64)node->cookie); 790 791 return node; 792 } 793 794 static struct binder_node *binder_new_node(struct binder_proc *proc, 795 struct flat_binder_object *fp) 796 { 797 struct binder_node *node; 798 struct binder_node *new_node = kzalloc_obj(*node); 799 800 if (!new_node) 801 return NULL; 802 binder_inner_proc_lock(proc); 803 node = binder_init_node_ilocked(proc, new_node, fp); 804 binder_inner_proc_unlock(proc); 805 if (node != new_node) 806 /* 807 * The node was already added by another thread 808 */ 809 kfree(new_node); 810 811 return node; 812 } 813 814 static void binder_free_node(struct binder_node *node) 815 { 816 kfree(node); 817 binder_stats_deleted(BINDER_STAT_NODE); 818 } 819 820 static int binder_inc_node_nilocked(struct binder_node *node, int strong, 821 int internal, 822 struct list_head *target_list) 823 { 824 struct binder_proc *proc = node->proc; 825 826 assert_spin_locked(&node->lock); 827 if (proc) 828 assert_spin_locked(&proc->inner_lock); 829 if (strong) { 830 if (internal) { 831 if (target_list == NULL && 832 node->internal_strong_refs == 0 && 833 !(node->proc && 834 node == node->proc->context->binder_context_mgr_node && 835 node->has_strong_ref)) { 836 pr_err("invalid inc strong node for %d\n", 837 node->debug_id); 838 return -EINVAL; 839 } 840 node->internal_strong_refs++; 841 } else 842 node->local_strong_refs++; 843 if (!node->has_strong_ref && target_list) { 844 struct binder_thread *thread = container_of(target_list, 845 struct binder_thread, todo); 846 binder_dequeue_work_ilocked(&node->work); 847 BUG_ON(&thread->todo != target_list); 848 binder_enqueue_deferred_thread_work_ilocked(thread, 849 &node->work); 850 } 851 } else { 852 if (!internal) 853 node->local_weak_refs++; 854 if (!node->has_weak_ref && target_list && list_empty(&node->work.entry)) 855 binder_enqueue_work_ilocked(&node->work, target_list); 856 } 857 return 0; 858 } 859 860 static int binder_inc_node(struct binder_node *node, int strong, int internal, 861 struct list_head *target_list) 862 { 863 int ret; 864 865 binder_node_inner_lock(node); 866 ret = binder_inc_node_nilocked(node, strong, internal, target_list); 867 binder_node_inner_unlock(node); 868 869 return ret; 870 } 871 872 static bool binder_dec_node_nilocked(struct binder_node *node, 873 int strong, int internal) 874 { 875 struct binder_proc *proc = node->proc; 876 877 assert_spin_locked(&node->lock); 878 if (proc) 879 assert_spin_locked(&proc->inner_lock); 880 if (strong) { 881 if (internal) 882 node->internal_strong_refs--; 883 else 884 node->local_strong_refs--; 885 if (node->local_strong_refs || node->internal_strong_refs) 886 return false; 887 } else { 888 if (!internal) 889 node->local_weak_refs--; 890 if (node->local_weak_refs || node->tmp_refs || 891 !hlist_empty(&node->refs)) 892 return false; 893 } 894 895 if (proc && (node->has_strong_ref || node->has_weak_ref)) { 896 if (list_empty(&node->work.entry)) { 897 binder_enqueue_work_ilocked(&node->work, &proc->todo); 898 binder_wakeup_proc_ilocked(proc); 899 } 900 } else { 901 if (hlist_empty(&node->refs) && !node->local_strong_refs && 902 !node->local_weak_refs && !node->tmp_refs) { 903 if (proc) { 904 binder_dequeue_work_ilocked(&node->work); 905 rb_erase(&node->rb_node, &proc->nodes); 906 binder_debug(BINDER_DEBUG_INTERNAL_REFS, 907 "refless node %d deleted\n", 908 node->debug_id); 909 } else { 910 BUG_ON(!list_empty(&node->work.entry)); 911 spin_lock(&binder_dead_nodes_lock); 912 /* 913 * tmp_refs could have changed so 914 * check it again 915 */ 916 if (node->tmp_refs) { 917 spin_unlock(&binder_dead_nodes_lock); 918 return false; 919 } 920 hlist_del(&node->dead_node); 921 spin_unlock(&binder_dead_nodes_lock); 922 binder_debug(BINDER_DEBUG_INTERNAL_REFS, 923 "dead node %d deleted\n", 924 node->debug_id); 925 } 926 return true; 927 } 928 } 929 return false; 930 } 931 932 static void binder_dec_node(struct binder_node *node, int strong, int internal) 933 { 934 bool free_node; 935 936 binder_node_inner_lock(node); 937 free_node = binder_dec_node_nilocked(node, strong, internal); 938 binder_node_inner_unlock(node); 939 if (free_node) 940 binder_free_node(node); 941 } 942 943 static void binder_inc_node_tmpref_ilocked(struct binder_node *node) 944 { 945 /* 946 * No call to binder_inc_node() is needed since we 947 * don't need to inform userspace of any changes to 948 * tmp_refs 949 */ 950 node->tmp_refs++; 951 } 952 953 /** 954 * binder_inc_node_tmpref() - take a temporary reference on node 955 * @node: node to reference 956 * 957 * Take reference on node to prevent the node from being freed 958 * while referenced only by a local variable. The inner lock is 959 * needed to serialize with the node work on the queue (which 960 * isn't needed after the node is dead). If the node is dead 961 * (node->proc is NULL), use binder_dead_nodes_lock to protect 962 * node->tmp_refs against dead-node-only cases where the node 963 * lock cannot be acquired (eg traversing the dead node list to 964 * print nodes) 965 */ 966 static void binder_inc_node_tmpref(struct binder_node *node) 967 { 968 binder_node_lock(node); 969 if (node->proc) 970 binder_inner_proc_lock(node->proc); 971 else 972 spin_lock(&binder_dead_nodes_lock); 973 binder_inc_node_tmpref_ilocked(node); 974 if (node->proc) 975 binder_inner_proc_unlock(node->proc); 976 else 977 spin_unlock(&binder_dead_nodes_lock); 978 binder_node_unlock(node); 979 } 980 981 /** 982 * binder_dec_node_tmpref() - remove a temporary reference on node 983 * @node: node to reference 984 * 985 * Release temporary reference on node taken via binder_inc_node_tmpref() 986 */ 987 static void binder_dec_node_tmpref(struct binder_node *node) 988 { 989 bool free_node; 990 991 binder_node_inner_lock(node); 992 if (!node->proc) 993 spin_lock(&binder_dead_nodes_lock); 994 else 995 __acquire(&binder_dead_nodes_lock); 996 node->tmp_refs--; 997 BUG_ON(node->tmp_refs < 0); 998 if (!node->proc) 999 spin_unlock(&binder_dead_nodes_lock); 1000 else 1001 __release(&binder_dead_nodes_lock); 1002 /* 1003 * Call binder_dec_node() to check if all refcounts are 0 1004 * and cleanup is needed. Calling with strong=0 and internal=1 1005 * causes no actual reference to be released in binder_dec_node(). 1006 * If that changes, a change is needed here too. 1007 */ 1008 free_node = binder_dec_node_nilocked(node, 0, 1); 1009 binder_node_inner_unlock(node); 1010 if (free_node) 1011 binder_free_node(node); 1012 } 1013 1014 static void binder_put_node(struct binder_node *node) 1015 { 1016 binder_dec_node_tmpref(node); 1017 } 1018 1019 static struct binder_ref *binder_get_ref_olocked(struct binder_proc *proc, 1020 u32 desc, bool need_strong_ref) 1021 { 1022 struct rb_node *n = proc->refs_by_desc.rb_node; 1023 struct binder_ref *ref; 1024 1025 while (n) { 1026 ref = rb_entry(n, struct binder_ref, rb_node_desc); 1027 1028 if (desc < ref->data.desc) { 1029 n = n->rb_left; 1030 } else if (desc > ref->data.desc) { 1031 n = n->rb_right; 1032 } else if (need_strong_ref && !ref->data.strong) { 1033 binder_user_error("tried to use weak ref as strong ref\n"); 1034 return NULL; 1035 } else { 1036 return ref; 1037 } 1038 } 1039 return NULL; 1040 } 1041 1042 /* Find the smallest unused descriptor the "slow way" */ 1043 static u32 slow_desc_lookup_olocked(struct binder_proc *proc, u32 offset) 1044 { 1045 struct binder_ref *ref; 1046 struct rb_node *n; 1047 u32 desc; 1048 1049 desc = offset; 1050 for (n = rb_first(&proc->refs_by_desc); n; n = rb_next(n)) { 1051 ref = rb_entry(n, struct binder_ref, rb_node_desc); 1052 if (ref->data.desc > desc) 1053 break; 1054 desc = ref->data.desc + 1; 1055 } 1056 1057 return desc; 1058 } 1059 1060 /* 1061 * Find an available reference descriptor ID. The proc->outer_lock might 1062 * be released in the process, in which case -EAGAIN is returned and the 1063 * @desc should be considered invalid. 1064 */ 1065 static int get_ref_desc_olocked(struct binder_proc *proc, 1066 struct binder_node *node, 1067 u32 *desc) 1068 { 1069 struct dbitmap *dmap = &proc->dmap; 1070 unsigned int nbits, offset; 1071 unsigned long *new, bit; 1072 1073 /* 0 is reserved for the context manager */ 1074 offset = (node == proc->context->binder_context_mgr_node) ? 0 : 1; 1075 1076 if (!dbitmap_enabled(dmap)) { 1077 *desc = slow_desc_lookup_olocked(proc, offset); 1078 return 0; 1079 } 1080 1081 if (dbitmap_acquire_next_zero_bit(dmap, offset, &bit) == 0) { 1082 *desc = bit; 1083 return 0; 1084 } 1085 1086 /* 1087 * The dbitmap is full and needs to grow. The proc->outer_lock 1088 * is briefly released to allocate the new bitmap safely. 1089 */ 1090 nbits = dbitmap_grow_nbits(dmap); 1091 binder_proc_unlock(proc); 1092 new = bitmap_zalloc(nbits, GFP_KERNEL); 1093 binder_proc_lock(proc); 1094 dbitmap_grow(dmap, new, nbits); 1095 1096 return -EAGAIN; 1097 } 1098 1099 /** 1100 * binder_get_ref_for_node_olocked() - get the ref associated with given node 1101 * @proc: binder_proc that owns the ref 1102 * @node: binder_node of target 1103 * @new_ref: newly allocated binder_ref to be initialized or %NULL 1104 * 1105 * Look up the ref for the given node and return it if it exists 1106 * 1107 * If it doesn't exist and the caller provides a newly allocated 1108 * ref, initialize the fields of the newly allocated ref and insert 1109 * into the given proc rb_trees and node refs list. 1110 * 1111 * Return: the ref for node. It is possible that another thread 1112 * allocated/initialized the ref first in which case the 1113 * returned ref would be different than the passed-in 1114 * new_ref. new_ref must be kfree'd by the caller in 1115 * this case. 1116 */ 1117 static struct binder_ref *binder_get_ref_for_node_olocked( 1118 struct binder_proc *proc, 1119 struct binder_node *node, 1120 struct binder_ref *new_ref) 1121 { 1122 struct binder_ref *ref; 1123 struct rb_node *parent; 1124 struct rb_node **p; 1125 u32 desc; 1126 1127 retry: 1128 p = &proc->refs_by_node.rb_node; 1129 parent = NULL; 1130 while (*p) { 1131 parent = *p; 1132 ref = rb_entry(parent, struct binder_ref, rb_node_node); 1133 1134 if (node < ref->node) 1135 p = &(*p)->rb_left; 1136 else if (node > ref->node) 1137 p = &(*p)->rb_right; 1138 else 1139 return ref; 1140 } 1141 if (!new_ref) 1142 return NULL; 1143 1144 /* might release the proc->outer_lock */ 1145 if (get_ref_desc_olocked(proc, node, &desc) == -EAGAIN) 1146 goto retry; 1147 1148 binder_stats_created(BINDER_STAT_REF); 1149 new_ref->data.debug_id = atomic_inc_return(&binder_last_id); 1150 new_ref->proc = proc; 1151 new_ref->node = node; 1152 rb_link_node(&new_ref->rb_node_node, parent, p); 1153 rb_insert_color(&new_ref->rb_node_node, &proc->refs_by_node); 1154 1155 new_ref->data.desc = desc; 1156 p = &proc->refs_by_desc.rb_node; 1157 while (*p) { 1158 parent = *p; 1159 ref = rb_entry(parent, struct binder_ref, rb_node_desc); 1160 1161 if (new_ref->data.desc < ref->data.desc) 1162 p = &(*p)->rb_left; 1163 else if (new_ref->data.desc > ref->data.desc) 1164 p = &(*p)->rb_right; 1165 else 1166 BUG(); 1167 } 1168 rb_link_node(&new_ref->rb_node_desc, parent, p); 1169 rb_insert_color(&new_ref->rb_node_desc, &proc->refs_by_desc); 1170 1171 binder_node_lock(node); 1172 hlist_add_head(&new_ref->node_entry, &node->refs); 1173 1174 binder_debug(BINDER_DEBUG_INTERNAL_REFS, 1175 "%d new ref %d desc %d for node %d\n", 1176 proc->pid, new_ref->data.debug_id, new_ref->data.desc, 1177 node->debug_id); 1178 binder_node_unlock(node); 1179 return new_ref; 1180 } 1181 1182 static void binder_cleanup_ref_olocked(struct binder_ref *ref) 1183 { 1184 struct dbitmap *dmap = &ref->proc->dmap; 1185 bool delete_node = false; 1186 1187 binder_debug(BINDER_DEBUG_INTERNAL_REFS, 1188 "%d delete ref %d desc %d for node %d\n", 1189 ref->proc->pid, ref->data.debug_id, ref->data.desc, 1190 ref->node->debug_id); 1191 1192 if (dbitmap_enabled(dmap)) 1193 dbitmap_clear_bit(dmap, ref->data.desc); 1194 rb_erase(&ref->rb_node_desc, &ref->proc->refs_by_desc); 1195 rb_erase(&ref->rb_node_node, &ref->proc->refs_by_node); 1196 1197 binder_node_inner_lock(ref->node); 1198 if (ref->data.strong) 1199 binder_dec_node_nilocked(ref->node, 1, 1); 1200 1201 hlist_del(&ref->node_entry); 1202 delete_node = binder_dec_node_nilocked(ref->node, 0, 1); 1203 binder_node_inner_unlock(ref->node); 1204 /* 1205 * Clear ref->node unless we want the caller to free the node 1206 */ 1207 if (!delete_node) { 1208 /* 1209 * The caller uses ref->node to determine 1210 * whether the node needs to be freed. Clear 1211 * it since the node is still alive. 1212 */ 1213 ref->node = NULL; 1214 } 1215 1216 if (ref->death) { 1217 binder_debug(BINDER_DEBUG_DEAD_BINDER, 1218 "%d delete ref %d desc %d has death notification\n", 1219 ref->proc->pid, ref->data.debug_id, 1220 ref->data.desc); 1221 binder_dequeue_work(ref->proc, &ref->death->work); 1222 binder_stats_deleted(BINDER_STAT_DEATH); 1223 } 1224 1225 if (ref->freeze) { 1226 binder_dequeue_work(ref->proc, &ref->freeze->work); 1227 binder_stats_deleted(BINDER_STAT_FREEZE); 1228 } 1229 1230 binder_stats_deleted(BINDER_STAT_REF); 1231 } 1232 1233 /** 1234 * binder_inc_ref_olocked() - increment the ref for given handle 1235 * @ref: ref to be incremented 1236 * @strong: if true, strong increment, else weak 1237 * @target_list: list to queue node work on 1238 * 1239 * Increment the ref. @ref->proc->outer_lock must be held on entry 1240 * 1241 * Return: 0, if successful, else errno 1242 */ 1243 static int binder_inc_ref_olocked(struct binder_ref *ref, int strong, 1244 struct list_head *target_list) 1245 { 1246 int ret; 1247 1248 if (strong) { 1249 if (ref->data.strong == 0) { 1250 ret = binder_inc_node(ref->node, 1, 1, target_list); 1251 if (ret) 1252 return ret; 1253 } 1254 ref->data.strong++; 1255 } else { 1256 if (ref->data.weak == 0) { 1257 ret = binder_inc_node(ref->node, 0, 1, target_list); 1258 if (ret) 1259 return ret; 1260 } 1261 ref->data.weak++; 1262 } 1263 return 0; 1264 } 1265 1266 /** 1267 * binder_dec_ref_olocked() - dec the ref for given handle 1268 * @ref: ref to be decremented 1269 * @strong: if true, strong decrement, else weak 1270 * 1271 * Decrement the ref. 1272 * 1273 * Return: %true if ref is cleaned up and ready to be freed. 1274 */ 1275 static bool binder_dec_ref_olocked(struct binder_ref *ref, int strong) 1276 { 1277 if (strong) { 1278 if (ref->data.strong == 0) { 1279 binder_user_error("%d invalid dec strong, ref %d desc %d s %d w %d\n", 1280 ref->proc->pid, ref->data.debug_id, 1281 ref->data.desc, ref->data.strong, 1282 ref->data.weak); 1283 return false; 1284 } 1285 ref->data.strong--; 1286 if (ref->data.strong == 0) 1287 binder_dec_node(ref->node, strong, 1); 1288 } else { 1289 if (ref->data.weak == 0) { 1290 binder_user_error("%d invalid dec weak, ref %d desc %d s %d w %d\n", 1291 ref->proc->pid, ref->data.debug_id, 1292 ref->data.desc, ref->data.strong, 1293 ref->data.weak); 1294 return false; 1295 } 1296 ref->data.weak--; 1297 } 1298 if (ref->data.strong == 0 && ref->data.weak == 0) { 1299 binder_cleanup_ref_olocked(ref); 1300 return true; 1301 } 1302 return false; 1303 } 1304 1305 /** 1306 * binder_get_node_from_ref() - get the node from the given proc/desc 1307 * @proc: proc containing the ref 1308 * @desc: the handle associated with the ref 1309 * @need_strong_ref: if true, only return node if ref is strong 1310 * @rdata: the id/refcount data for the ref 1311 * 1312 * Given a proc and ref handle, return the associated binder_node 1313 * 1314 * Return: a binder_node or NULL if not found or not strong when strong required 1315 */ 1316 static struct binder_node *binder_get_node_from_ref( 1317 struct binder_proc *proc, 1318 u32 desc, bool need_strong_ref, 1319 struct binder_ref_data *rdata) 1320 { 1321 struct binder_node *node; 1322 struct binder_ref *ref; 1323 1324 binder_proc_lock(proc); 1325 ref = binder_get_ref_olocked(proc, desc, need_strong_ref); 1326 if (!ref) 1327 goto err_no_ref; 1328 node = ref->node; 1329 /* 1330 * Take an implicit reference on the node to ensure 1331 * it stays alive until the call to binder_put_node() 1332 */ 1333 binder_inc_node_tmpref(node); 1334 if (rdata) 1335 *rdata = ref->data; 1336 binder_proc_unlock(proc); 1337 1338 return node; 1339 1340 err_no_ref: 1341 binder_proc_unlock(proc); 1342 return NULL; 1343 } 1344 1345 /** 1346 * binder_free_ref() - free the binder_ref 1347 * @ref: ref to free 1348 * 1349 * Free the binder_ref. Free the binder_node indicated by ref->node 1350 * (if non-NULL) and the binder_ref_death indicated by ref->death. 1351 */ 1352 static void binder_free_ref(struct binder_ref *ref) 1353 { 1354 if (ref->node) 1355 binder_free_node(ref->node); 1356 kfree(ref->death); 1357 kfree(ref->freeze); 1358 kfree(ref); 1359 } 1360 1361 /* shrink descriptor bitmap if needed */ 1362 static void try_shrink_dmap(struct binder_proc *proc) 1363 { 1364 unsigned long *new; 1365 int nbits; 1366 1367 binder_proc_lock(proc); 1368 nbits = dbitmap_shrink_nbits(&proc->dmap); 1369 binder_proc_unlock(proc); 1370 1371 if (!nbits) 1372 return; 1373 1374 new = bitmap_zalloc(nbits, GFP_KERNEL); 1375 binder_proc_lock(proc); 1376 dbitmap_shrink(&proc->dmap, new, nbits); 1377 binder_proc_unlock(proc); 1378 } 1379 1380 /** 1381 * binder_update_ref_for_handle() - inc/dec the ref for given handle 1382 * @proc: proc containing the ref 1383 * @desc: the handle associated with the ref 1384 * @increment: true=inc reference, false=dec reference 1385 * @strong: true=strong reference, false=weak reference 1386 * @rdata: the id/refcount data for the ref 1387 * 1388 * Given a proc and ref handle, increment or decrement the ref 1389 * according to "increment" arg. 1390 * 1391 * Return: 0 if successful, else errno 1392 */ 1393 static int binder_update_ref_for_handle(struct binder_proc *proc, 1394 uint32_t desc, bool increment, bool strong, 1395 struct binder_ref_data *rdata) 1396 { 1397 int ret = 0; 1398 struct binder_ref *ref; 1399 bool delete_ref = false; 1400 1401 binder_proc_lock(proc); 1402 ref = binder_get_ref_olocked(proc, desc, strong); 1403 if (!ref) { 1404 ret = -EINVAL; 1405 goto err_no_ref; 1406 } 1407 if (increment) 1408 ret = binder_inc_ref_olocked(ref, strong, NULL); 1409 else 1410 delete_ref = binder_dec_ref_olocked(ref, strong); 1411 1412 if (rdata) 1413 *rdata = ref->data; 1414 binder_proc_unlock(proc); 1415 1416 if (delete_ref) { 1417 binder_free_ref(ref); 1418 try_shrink_dmap(proc); 1419 } 1420 return ret; 1421 1422 err_no_ref: 1423 binder_proc_unlock(proc); 1424 return ret; 1425 } 1426 1427 /** 1428 * binder_dec_ref_for_handle() - dec the ref for given handle 1429 * @proc: proc containing the ref 1430 * @desc: the handle associated with the ref 1431 * @strong: true=strong reference, false=weak reference 1432 * @rdata: the id/refcount data for the ref 1433 * 1434 * Just calls binder_update_ref_for_handle() to decrement the ref. 1435 * 1436 * Return: 0 if successful, else errno 1437 */ 1438 static int binder_dec_ref_for_handle(struct binder_proc *proc, 1439 uint32_t desc, bool strong, struct binder_ref_data *rdata) 1440 { 1441 return binder_update_ref_for_handle(proc, desc, false, strong, rdata); 1442 } 1443 1444 1445 /** 1446 * binder_inc_ref_for_node() - increment the ref for given proc/node 1447 * @proc: proc containing the ref 1448 * @node: target node 1449 * @strong: true=strong reference, false=weak reference 1450 * @target_list: worklist to use if node is incremented 1451 * @rdata: the id/refcount data for the ref 1452 * 1453 * Given a proc and node, increment the ref. Create the ref if it 1454 * doesn't already exist 1455 * 1456 * Return: 0 if successful, else errno 1457 */ 1458 static int binder_inc_ref_for_node(struct binder_proc *proc, 1459 struct binder_node *node, 1460 bool strong, 1461 struct list_head *target_list, 1462 struct binder_ref_data *rdata) 1463 { 1464 struct binder_ref *ref; 1465 struct binder_ref *new_ref = NULL; 1466 int ret = 0; 1467 1468 binder_proc_lock(proc); 1469 ref = binder_get_ref_for_node_olocked(proc, node, NULL); 1470 if (!ref) { 1471 binder_proc_unlock(proc); 1472 new_ref = kzalloc_obj(*ref); 1473 if (!new_ref) 1474 return -ENOMEM; 1475 binder_proc_lock(proc); 1476 ref = binder_get_ref_for_node_olocked(proc, node, new_ref); 1477 } 1478 ret = binder_inc_ref_olocked(ref, strong, target_list); 1479 *rdata = ref->data; 1480 if (ret && ref == new_ref) { 1481 /* 1482 * Cleanup the failed reference here as the target 1483 * could now be dead and have already released its 1484 * references by now. Calling on the new reference 1485 * with strong=0 and a tmp_refs will not decrement 1486 * the node. The new_ref gets kfree'd below. 1487 */ 1488 binder_cleanup_ref_olocked(new_ref); 1489 ref = NULL; 1490 } 1491 1492 binder_proc_unlock(proc); 1493 if (new_ref && ref != new_ref) 1494 /* 1495 * Another thread created the ref first so 1496 * free the one we allocated 1497 */ 1498 kfree(new_ref); 1499 return ret; 1500 } 1501 1502 static void binder_pop_transaction_ilocked(struct binder_thread *target_thread, 1503 struct binder_transaction *t) 1504 { 1505 BUG_ON(!target_thread); 1506 assert_spin_locked(&target_thread->proc->inner_lock); 1507 BUG_ON(target_thread->transaction_stack != t); 1508 BUG_ON(target_thread->transaction_stack->from != target_thread); 1509 target_thread->transaction_stack = 1510 target_thread->transaction_stack->from_parent; 1511 t->from = NULL; 1512 } 1513 1514 /** 1515 * binder_thread_dec_tmpref() - decrement thread->tmp_ref 1516 * @thread: thread to decrement 1517 * 1518 * A thread needs to be kept alive while being used to create or 1519 * handle a transaction. binder_get_txn_from() is used to safely 1520 * extract t->from from a binder_transaction and keep the thread 1521 * indicated by t->from from being freed. When done with that 1522 * binder_thread, this function is called to decrement the 1523 * tmp_ref and free if appropriate (thread has been released 1524 * and no transaction being processed by the driver) 1525 */ 1526 static void binder_thread_dec_tmpref(struct binder_thread *thread) 1527 { 1528 /* 1529 * atomic is used to protect the counter value while 1530 * it cannot reach zero or thread->is_dead is false 1531 */ 1532 binder_inner_proc_lock(thread->proc); 1533 atomic_dec(&thread->tmp_ref); 1534 if (thread->is_dead && !atomic_read(&thread->tmp_ref)) { 1535 binder_inner_proc_unlock(thread->proc); 1536 binder_free_thread(thread); 1537 return; 1538 } 1539 binder_inner_proc_unlock(thread->proc); 1540 } 1541 1542 /** 1543 * binder_proc_dec_tmpref() - decrement proc->tmp_ref 1544 * @proc: proc to decrement 1545 * 1546 * A binder_proc needs to be kept alive while being used to create or 1547 * handle a transaction. proc->tmp_ref is incremented when 1548 * creating a new transaction or the binder_proc is currently in-use 1549 * by threads that are being released. When done with the binder_proc, 1550 * this function is called to decrement the counter and free the 1551 * proc if appropriate (proc has been released, all threads have 1552 * been released and not currently in-use to process a transaction). 1553 */ 1554 static void binder_proc_dec_tmpref(struct binder_proc *proc) 1555 { 1556 binder_inner_proc_lock(proc); 1557 proc->tmp_ref--; 1558 if (proc->is_dead && RB_EMPTY_ROOT(&proc->threads) && 1559 !proc->tmp_ref) { 1560 binder_inner_proc_unlock(proc); 1561 binder_free_proc(proc); 1562 return; 1563 } 1564 binder_inner_proc_unlock(proc); 1565 } 1566 1567 /** 1568 * binder_get_txn_from() - safely extract the "from" thread in transaction 1569 * @t: binder transaction for t->from 1570 * 1571 * Atomically return the "from" thread and increment the tmp_ref 1572 * count for the thread to ensure it stays alive until 1573 * binder_thread_dec_tmpref() is called. 1574 * 1575 * Return: the value of t->from 1576 */ 1577 static struct binder_thread *binder_get_txn_from( 1578 struct binder_transaction *t) 1579 { 1580 struct binder_thread *from; 1581 1582 guard(spinlock)(&t->lock); 1583 from = t->from; 1584 if (from) 1585 atomic_inc(&from->tmp_ref); 1586 return from; 1587 } 1588 1589 /** 1590 * binder_get_txn_from_and_acq_inner() - get t->from and acquire inner lock 1591 * @t: binder transaction for t->from 1592 * 1593 * Same as binder_get_txn_from() except it also acquires the proc->inner_lock 1594 * to guarantee that the thread cannot be released while operating on it. 1595 * The caller must call binder_inner_proc_unlock() to release the inner lock 1596 * as well as call binder_dec_thread_txn() to release the reference. 1597 * 1598 * Return: the value of t->from 1599 */ 1600 static struct binder_thread *binder_get_txn_from_and_acq_inner( 1601 struct binder_transaction *t) 1602 __acquires(&t->from->proc->inner_lock) 1603 { 1604 struct binder_thread *from; 1605 1606 from = binder_get_txn_from(t); 1607 if (!from) { 1608 __acquire(&from->proc->inner_lock); 1609 return NULL; 1610 } 1611 binder_inner_proc_lock(from->proc); 1612 if (t->from) { 1613 BUG_ON(from != t->from); 1614 return from; 1615 } 1616 binder_inner_proc_unlock(from->proc); 1617 __acquire(&from->proc->inner_lock); 1618 binder_thread_dec_tmpref(from); 1619 return NULL; 1620 } 1621 1622 /** 1623 * binder_free_txn_fixups() - free unprocessed fd fixups 1624 * @t: binder transaction for t->from 1625 * 1626 * If the transaction is being torn down prior to being 1627 * processed by the target process, free all of the 1628 * fd fixups and fput the file structs. It is safe to 1629 * call this function after the fixups have been 1630 * processed -- in that case, the list will be empty. 1631 */ 1632 static void binder_free_txn_fixups(struct binder_transaction *t) 1633 { 1634 struct binder_txn_fd_fixup *fixup, *tmp; 1635 1636 list_for_each_entry_safe(fixup, tmp, &t->fd_fixups, fixup_entry) { 1637 fput(fixup->file); 1638 if (fixup->target_fd >= 0) 1639 put_unused_fd(fixup->target_fd); 1640 list_del(&fixup->fixup_entry); 1641 kfree(fixup); 1642 } 1643 } 1644 1645 static void binder_txn_latency_free(struct binder_transaction *t) 1646 { 1647 int from_proc, from_thread, to_proc, to_thread; 1648 1649 spin_lock(&t->lock); 1650 from_proc = t->from ? t->from->proc->pid : 0; 1651 from_thread = t->from ? t->from->pid : 0; 1652 to_proc = t->to_proc ? t->to_proc->pid : 0; 1653 to_thread = t->to_thread ? t->to_thread->pid : 0; 1654 spin_unlock(&t->lock); 1655 1656 trace_binder_txn_latency_free(t, from_proc, from_thread, to_proc, to_thread); 1657 } 1658 1659 static void binder_free_transaction(struct binder_transaction *t) 1660 { 1661 struct binder_thread *target_thread; 1662 struct binder_proc *target_proc; 1663 1664 spin_lock(&t->lock); 1665 target_proc = t->to_proc; 1666 target_thread = t->to_thread; 1667 /* 1668 * Pin target_thread to keep target_proc alive. Undelivered 1669 * transactions with !target_thread are safe, as target_proc 1670 * can only be the current context there. 1671 */ 1672 if (target_thread) 1673 atomic_inc(&target_thread->tmp_ref); 1674 spin_unlock(&t->lock); 1675 1676 if (target_proc) { 1677 binder_inner_proc_lock(target_proc); 1678 target_proc->outstanding_txns--; 1679 if (target_proc->outstanding_txns < 0) 1680 pr_warn("%s: Unexpected outstanding_txns %d\n", 1681 __func__, target_proc->outstanding_txns); 1682 if (!target_proc->outstanding_txns && target_proc->is_frozen) 1683 wake_up_interruptible_all(&target_proc->freeze_wait); 1684 if (t->buffer) 1685 t->buffer->transaction = NULL; 1686 binder_inner_proc_unlock(target_proc); 1687 } 1688 1689 if (target_thread) 1690 binder_thread_dec_tmpref(target_thread); 1691 1692 if (trace_binder_txn_latency_free_enabled()) 1693 binder_txn_latency_free(t); 1694 /* 1695 * If the transaction has no target_proc, then 1696 * t->buffer->transaction has already been cleared. 1697 */ 1698 binder_free_txn_fixups(t); 1699 kfree(t); 1700 binder_stats_deleted(BINDER_STAT_TRANSACTION); 1701 } 1702 1703 static void binder_send_failed_reply(struct binder_transaction *t, 1704 uint32_t error_code) 1705 { 1706 struct binder_thread *target_thread; 1707 struct binder_transaction *next; 1708 1709 BUG_ON(t->flags & TF_ONE_WAY); 1710 while (1) { 1711 target_thread = binder_get_txn_from_and_acq_inner(t); 1712 if (target_thread) { 1713 binder_debug(BINDER_DEBUG_FAILED_TRANSACTION, 1714 "send failed reply for transaction %d to %d:%d\n", 1715 t->debug_id, 1716 target_thread->proc->pid, 1717 target_thread->pid); 1718 1719 binder_pop_transaction_ilocked(target_thread, t); 1720 if (target_thread->reply_error.cmd == BR_OK) { 1721 target_thread->reply_error.cmd = error_code; 1722 binder_enqueue_thread_work_ilocked( 1723 target_thread, 1724 &target_thread->reply_error.work); 1725 wake_up_interruptible(&target_thread->wait); 1726 } else { 1727 /* 1728 * Cannot get here for normal operation, but 1729 * we can if multiple synchronous transactions 1730 * are sent without blocking for responses. 1731 * Just ignore the 2nd error in this case. 1732 */ 1733 pr_warn("Unexpected reply error: %u\n", 1734 target_thread->reply_error.cmd); 1735 } 1736 binder_inner_proc_unlock(target_thread->proc); 1737 binder_thread_dec_tmpref(target_thread); 1738 binder_free_transaction(t); 1739 return; 1740 } 1741 __release(&target_thread->proc->inner_lock); 1742 next = t->from_parent; 1743 1744 binder_debug(BINDER_DEBUG_FAILED_TRANSACTION, 1745 "send failed reply for transaction %d, target dead\n", 1746 t->debug_id); 1747 1748 binder_free_transaction(t); 1749 if (next == NULL) { 1750 binder_debug(BINDER_DEBUG_DEAD_BINDER, 1751 "reply failed, no target thread at root\n"); 1752 return; 1753 } 1754 t = next; 1755 binder_debug(BINDER_DEBUG_DEAD_BINDER, 1756 "reply failed, no target thread -- retry %d\n", 1757 t->debug_id); 1758 } 1759 } 1760 1761 /** 1762 * binder_cleanup_transaction() - cleans up undelivered transaction 1763 * @t: transaction that needs to be cleaned up 1764 * @reason: reason the transaction wasn't delivered 1765 * @error_code: error to return to caller (if synchronous call) 1766 */ 1767 static void binder_cleanup_transaction(struct binder_transaction *t, 1768 const char *reason, 1769 uint32_t error_code) 1770 { 1771 if (t->buffer->target_node && !(t->flags & TF_ONE_WAY)) { 1772 binder_send_failed_reply(t, error_code); 1773 } else { 1774 binder_debug(BINDER_DEBUG_DEAD_TRANSACTION, 1775 "undelivered transaction %d, %s\n", 1776 t->debug_id, reason); 1777 binder_free_transaction(t); 1778 } 1779 } 1780 1781 /** 1782 * binder_get_object() - gets object and checks for valid metadata 1783 * @proc: binder_proc owning the buffer 1784 * @u: sender's user pointer to base of buffer 1785 * @buffer: binder_buffer that we're parsing. 1786 * @offset: offset in the @buffer at which to validate an object. 1787 * @object: struct binder_object to read into 1788 * 1789 * Copy the binder object at the given offset into @object. If @u is 1790 * provided then the copy is from the sender's buffer. If not, then 1791 * it is copied from the target's @buffer. 1792 * 1793 * Return: If there's a valid metadata object at @offset, the 1794 * size of that object. Otherwise, it returns zero. The object 1795 * is read into the struct binder_object pointed to by @object. 1796 */ 1797 static size_t binder_get_object(struct binder_proc *proc, 1798 const void __user *u, 1799 struct binder_buffer *buffer, 1800 unsigned long offset, 1801 struct binder_object *object) 1802 { 1803 size_t read_size; 1804 struct binder_object_header *hdr; 1805 size_t object_size = 0; 1806 1807 read_size = min_t(size_t, sizeof(*object), buffer->data_size - offset); 1808 if (offset > buffer->data_size || read_size < sizeof(*hdr) || 1809 !IS_ALIGNED(offset, sizeof(u32))) 1810 return 0; 1811 1812 if (u) { 1813 if (copy_from_user(object, u + offset, read_size)) 1814 return 0; 1815 } else { 1816 if (binder_alloc_copy_from_buffer(&proc->alloc, object, buffer, 1817 offset, read_size)) 1818 return 0; 1819 } 1820 1821 /* Ok, now see if we read a complete object. */ 1822 hdr = &object->hdr; 1823 switch (hdr->type) { 1824 case BINDER_TYPE_BINDER: 1825 case BINDER_TYPE_WEAK_BINDER: 1826 case BINDER_TYPE_HANDLE: 1827 case BINDER_TYPE_WEAK_HANDLE: 1828 object_size = sizeof(struct flat_binder_object); 1829 break; 1830 case BINDER_TYPE_FD: 1831 object_size = sizeof(struct binder_fd_object); 1832 break; 1833 case BINDER_TYPE_PTR: 1834 object_size = sizeof(struct binder_buffer_object); 1835 break; 1836 case BINDER_TYPE_FDA: 1837 object_size = sizeof(struct binder_fd_array_object); 1838 break; 1839 default: 1840 return 0; 1841 } 1842 if (offset <= buffer->data_size - object_size && 1843 buffer->data_size >= object_size) 1844 return object_size; 1845 else 1846 return 0; 1847 } 1848 1849 /** 1850 * binder_validate_ptr() - validates binder_buffer_object in a binder_buffer. 1851 * @proc: binder_proc owning the buffer 1852 * @b: binder_buffer containing the object 1853 * @object: struct binder_object to read into 1854 * @index: index in offset array at which the binder_buffer_object is 1855 * located 1856 * @start_offset: points to the start of the offset array 1857 * @object_offsetp: offset of @object read from @b 1858 * @num_valid: the number of valid offsets in the offset array 1859 * 1860 * Return: If @index is within the valid range of the offset array 1861 * described by @start and @num_valid, and if there's a valid 1862 * binder_buffer_object at the offset found in index @index 1863 * of the offset array, that object is returned. Otherwise, 1864 * %NULL is returned. 1865 * Note that the offset found in index @index itself is not 1866 * verified; this function assumes that @num_valid elements 1867 * from @start were previously verified to have valid offsets. 1868 * If @object_offsetp is non-NULL, then the offset within 1869 * @b is written to it. 1870 */ 1871 static struct binder_buffer_object *binder_validate_ptr( 1872 struct binder_proc *proc, 1873 struct binder_buffer *b, 1874 struct binder_object *object, 1875 binder_size_t index, 1876 binder_size_t start_offset, 1877 binder_size_t *object_offsetp, 1878 binder_size_t num_valid) 1879 { 1880 size_t object_size; 1881 binder_size_t object_offset; 1882 unsigned long buffer_offset; 1883 1884 if (index >= num_valid) 1885 return NULL; 1886 1887 buffer_offset = start_offset + sizeof(binder_size_t) * index; 1888 if (binder_alloc_copy_from_buffer(&proc->alloc, &object_offset, 1889 b, buffer_offset, 1890 sizeof(object_offset))) 1891 return NULL; 1892 object_size = binder_get_object(proc, NULL, b, object_offset, object); 1893 if (!object_size || object->hdr.type != BINDER_TYPE_PTR) 1894 return NULL; 1895 if (object_offsetp) 1896 *object_offsetp = object_offset; 1897 1898 return &object->bbo; 1899 } 1900 1901 /** 1902 * binder_validate_fixup() - validates pointer/fd fixups happen in order. 1903 * @proc: binder_proc owning the buffer 1904 * @b: transaction buffer 1905 * @objects_start_offset: offset to start of objects buffer 1906 * @buffer_obj_offset: offset to binder_buffer_object in which to fix up 1907 * @fixup_offset: start offset in @buffer to fix up 1908 * @last_obj_offset: offset to last binder_buffer_object that we fixed 1909 * @last_min_offset: minimum fixup offset in object at @last_obj_offset 1910 * 1911 * Return: %true if a fixup in buffer @buffer at offset @offset is 1912 * allowed. 1913 * 1914 * For safety reasons, we only allow fixups inside a buffer to happen 1915 * at increasing offsets; additionally, we only allow fixup on the last 1916 * buffer object that was verified, or one of its parents. 1917 * 1918 * Example of what is allowed: 1919 * 1920 * A 1921 * B (parent = A, offset = 0) 1922 * C (parent = A, offset = 16) 1923 * D (parent = C, offset = 0) 1924 * E (parent = A, offset = 32) // min_offset is 16 (C.parent_offset) 1925 * 1926 * Examples of what is not allowed: 1927 * 1928 * Decreasing offsets within the same parent: 1929 * A 1930 * C (parent = A, offset = 16) 1931 * B (parent = A, offset = 0) // decreasing offset within A 1932 * 1933 * Referring to a parent that wasn't the last object or any of its parents: 1934 * A 1935 * B (parent = A, offset = 0) 1936 * C (parent = A, offset = 0) 1937 * C (parent = A, offset = 16) 1938 * D (parent = B, offset = 0) // B is not A or any of A's parents 1939 */ 1940 static bool binder_validate_fixup(struct binder_proc *proc, 1941 struct binder_buffer *b, 1942 binder_size_t objects_start_offset, 1943 binder_size_t buffer_obj_offset, 1944 binder_size_t fixup_offset, 1945 binder_size_t last_obj_offset, 1946 binder_size_t last_min_offset) 1947 { 1948 if (!last_obj_offset) { 1949 /* Nothing to fix up in */ 1950 return false; 1951 } 1952 1953 while (last_obj_offset != buffer_obj_offset) { 1954 unsigned long buffer_offset; 1955 struct binder_object last_object; 1956 struct binder_buffer_object *last_bbo; 1957 size_t object_size = binder_get_object(proc, NULL, b, 1958 last_obj_offset, 1959 &last_object); 1960 if (object_size != sizeof(*last_bbo)) 1961 return false; 1962 1963 last_bbo = &last_object.bbo; 1964 /* 1965 * Safe to retrieve the parent of last_obj, since it 1966 * was already previously verified by the driver. 1967 */ 1968 if ((last_bbo->flags & BINDER_BUFFER_FLAG_HAS_PARENT) == 0) 1969 return false; 1970 last_min_offset = last_bbo->parent_offset + sizeof(uintptr_t); 1971 buffer_offset = objects_start_offset + 1972 sizeof(binder_size_t) * last_bbo->parent; 1973 if (binder_alloc_copy_from_buffer(&proc->alloc, 1974 &last_obj_offset, 1975 b, buffer_offset, 1976 sizeof(last_obj_offset))) 1977 return false; 1978 } 1979 return (fixup_offset >= last_min_offset); 1980 } 1981 1982 /** 1983 * struct binder_task_work_cb - for deferred close 1984 * 1985 * @twork: callback_head for task work 1986 * @file: file to close 1987 * 1988 * Structure to pass task work to be handled after 1989 * returning from binder_ioctl() via task_work_add(). 1990 */ 1991 struct binder_task_work_cb { 1992 struct callback_head twork; 1993 struct file *file; 1994 }; 1995 1996 /** 1997 * binder_do_fd_close() - close list of file descriptors 1998 * @twork: callback head for task work 1999 * 2000 * It is not safe to call ksys_close() during the binder_ioctl() 2001 * function if there is a chance that binder's own file descriptor 2002 * might be closed. This is to meet the requirements for using 2003 * fdget() (see comments for __fget_light()). Therefore use 2004 * task_work_add() to schedule the close operation once we have 2005 * returned from binder_ioctl(). This function is a callback 2006 * for that mechanism and does the actual ksys_close() on the 2007 * given file descriptor. 2008 */ 2009 static void binder_do_fd_close(struct callback_head *twork) 2010 { 2011 struct binder_task_work_cb *twcb = container_of(twork, 2012 struct binder_task_work_cb, twork); 2013 2014 fput(twcb->file); 2015 kfree(twcb); 2016 } 2017 2018 /** 2019 * binder_deferred_fd_close() - schedule a close for the given file-descriptor 2020 * @fd: file-descriptor to close 2021 * 2022 * See comments in binder_do_fd_close(). This function is used to schedule 2023 * a file-descriptor to be closed after returning from binder_ioctl(). 2024 */ 2025 static void binder_deferred_fd_close(int fd) 2026 { 2027 struct binder_task_work_cb *twcb; 2028 2029 twcb = kzalloc_obj(*twcb); 2030 if (!twcb) 2031 return; 2032 init_task_work(&twcb->twork, binder_do_fd_close); 2033 twcb->file = file_close_fd(fd); 2034 if (twcb->file) { 2035 // pin it until binder_do_fd_close(); see comments there 2036 get_file(twcb->file); 2037 filp_close(twcb->file, current->files); 2038 task_work_add(current, &twcb->twork, TWA_RESUME); 2039 } else { 2040 kfree(twcb); 2041 } 2042 } 2043 2044 static void binder_transaction_buffer_release(struct binder_proc *proc, 2045 struct binder_thread *thread, 2046 struct binder_buffer *buffer, 2047 binder_size_t off_end_offset, 2048 bool is_failure) 2049 { 2050 int debug_id = buffer->debug_id; 2051 binder_size_t off_start_offset, buffer_offset; 2052 2053 binder_debug(BINDER_DEBUG_TRANSACTION, 2054 "%d buffer release %d, size %zd-%zd, failed at %llx\n", 2055 proc->pid, buffer->debug_id, 2056 buffer->data_size, buffer->offsets_size, 2057 (unsigned long long)off_end_offset); 2058 2059 if (buffer->target_node) 2060 binder_dec_node(buffer->target_node, 1, 0); 2061 2062 off_start_offset = ALIGN(buffer->data_size, sizeof(void *)); 2063 2064 for (buffer_offset = off_start_offset; buffer_offset < off_end_offset; 2065 buffer_offset += sizeof(binder_size_t)) { 2066 struct binder_object_header *hdr; 2067 size_t object_size = 0; 2068 struct binder_object object; 2069 binder_size_t object_offset; 2070 2071 if (!binder_alloc_copy_from_buffer(&proc->alloc, &object_offset, 2072 buffer, buffer_offset, 2073 sizeof(object_offset))) 2074 object_size = binder_get_object(proc, NULL, buffer, 2075 object_offset, &object); 2076 if (object_size == 0) { 2077 pr_err("transaction release %d bad object at offset %lld, size %zd\n", 2078 debug_id, (u64)object_offset, buffer->data_size); 2079 continue; 2080 } 2081 hdr = &object.hdr; 2082 switch (hdr->type) { 2083 case BINDER_TYPE_BINDER: 2084 case BINDER_TYPE_WEAK_BINDER: { 2085 struct flat_binder_object *fp; 2086 struct binder_node *node; 2087 2088 fp = to_flat_binder_object(hdr); 2089 node = binder_get_node(proc, fp->binder); 2090 if (node == NULL) { 2091 pr_err("transaction release %d bad node %016llx\n", 2092 debug_id, (u64)fp->binder); 2093 break; 2094 } 2095 binder_debug(BINDER_DEBUG_TRANSACTION, 2096 " node %d u%016llx\n", 2097 node->debug_id, (u64)node->ptr); 2098 binder_dec_node(node, hdr->type == BINDER_TYPE_BINDER, 2099 0); 2100 binder_put_node(node); 2101 } break; 2102 case BINDER_TYPE_HANDLE: 2103 case BINDER_TYPE_WEAK_HANDLE: { 2104 struct flat_binder_object *fp; 2105 struct binder_ref_data rdata; 2106 int ret; 2107 2108 fp = to_flat_binder_object(hdr); 2109 ret = binder_dec_ref_for_handle(proc, fp->handle, 2110 hdr->type == BINDER_TYPE_HANDLE, &rdata); 2111 2112 if (ret) { 2113 pr_err("transaction release %d bad handle %d, ret = %d\n", 2114 debug_id, fp->handle, ret); 2115 break; 2116 } 2117 binder_debug(BINDER_DEBUG_TRANSACTION, 2118 " ref %d desc %d\n", 2119 rdata.debug_id, rdata.desc); 2120 } break; 2121 2122 case BINDER_TYPE_FD: { 2123 /* 2124 * No need to close the file here since user-space 2125 * closes it for successfully delivered 2126 * transactions. For transactions that weren't 2127 * delivered, the new fd was never allocated so 2128 * there is no need to close and the fput on the 2129 * file is done when the transaction is torn 2130 * down. 2131 */ 2132 } break; 2133 case BINDER_TYPE_PTR: 2134 /* 2135 * Nothing to do here, this will get cleaned up when the 2136 * transaction buffer gets freed 2137 */ 2138 break; 2139 case BINDER_TYPE_FDA: { 2140 struct binder_fd_array_object *fda; 2141 struct binder_buffer_object *parent; 2142 struct binder_object ptr_object; 2143 binder_size_t fda_offset; 2144 size_t fd_index; 2145 binder_size_t fd_buf_size; 2146 binder_size_t num_valid; 2147 2148 if (is_failure) { 2149 /* 2150 * The fd fixups have not been applied so no 2151 * fds need to be closed. 2152 */ 2153 continue; 2154 } 2155 2156 num_valid = (buffer_offset - off_start_offset) / 2157 sizeof(binder_size_t); 2158 fda = to_binder_fd_array_object(hdr); 2159 parent = binder_validate_ptr(proc, buffer, &ptr_object, 2160 fda->parent, 2161 off_start_offset, 2162 NULL, 2163 num_valid); 2164 if (!parent) { 2165 pr_err("transaction release %d bad parent offset\n", 2166 debug_id); 2167 continue; 2168 } 2169 fd_buf_size = sizeof(u32) * fda->num_fds; 2170 if (fda->num_fds >= SIZE_MAX / sizeof(u32)) { 2171 pr_err("transaction release %d invalid number of fds (%lld)\n", 2172 debug_id, (u64)fda->num_fds); 2173 continue; 2174 } 2175 if (fd_buf_size > parent->length || 2176 fda->parent_offset > parent->length - fd_buf_size) { 2177 /* No space for all file descriptors here. */ 2178 pr_err("transaction release %d not enough space for %lld fds in buffer\n", 2179 debug_id, (u64)fda->num_fds); 2180 continue; 2181 } 2182 /* 2183 * the source data for binder_buffer_object is visible 2184 * to user-space and the @buffer element is the user 2185 * pointer to the buffer_object containing the fd_array. 2186 * Convert the address to an offset relative to 2187 * the base of the transaction buffer. 2188 */ 2189 fda_offset = parent->buffer - buffer->user_data + 2190 fda->parent_offset; 2191 for (fd_index = 0; fd_index < fda->num_fds; 2192 fd_index++) { 2193 u32 fd; 2194 int err; 2195 binder_size_t offset = fda_offset + 2196 fd_index * sizeof(fd); 2197 2198 err = binder_alloc_copy_from_buffer( 2199 &proc->alloc, &fd, buffer, 2200 offset, sizeof(fd)); 2201 WARN_ON(err); 2202 if (!err) { 2203 binder_deferred_fd_close(fd); 2204 /* 2205 * Need to make sure the thread goes 2206 * back to userspace to complete the 2207 * deferred close 2208 */ 2209 if (thread) 2210 thread->looper_need_return = true; 2211 } 2212 } 2213 } break; 2214 default: 2215 pr_err("transaction release %d bad object type %x\n", 2216 debug_id, hdr->type); 2217 break; 2218 } 2219 } 2220 } 2221 2222 /* Clean up all the objects in the buffer */ 2223 static inline void binder_release_entire_buffer(struct binder_proc *proc, 2224 struct binder_thread *thread, 2225 struct binder_buffer *buffer, 2226 bool is_failure) 2227 { 2228 binder_size_t off_end_offset; 2229 2230 off_end_offset = ALIGN(buffer->data_size, sizeof(void *)); 2231 off_end_offset += buffer->offsets_size; 2232 2233 binder_transaction_buffer_release(proc, thread, buffer, 2234 off_end_offset, is_failure); 2235 } 2236 2237 static int binder_translate_binder(struct flat_binder_object *fp, 2238 struct binder_transaction *t, 2239 struct binder_thread *thread) 2240 { 2241 struct binder_node *node; 2242 struct binder_proc *proc = thread->proc; 2243 struct binder_proc *target_proc = t->to_proc; 2244 struct binder_ref_data rdata; 2245 int ret = 0; 2246 2247 node = binder_get_node(proc, fp->binder); 2248 if (!node) { 2249 node = binder_new_node(proc, fp); 2250 if (!node) 2251 return -ENOMEM; 2252 } 2253 if (fp->cookie != node->cookie) { 2254 binder_user_error("%d:%d sending u%016llx node %d, cookie mismatch %016llx != %016llx\n", 2255 proc->pid, thread->pid, (u64)fp->binder, 2256 node->debug_id, (u64)fp->cookie, 2257 (u64)node->cookie); 2258 ret = -EINVAL; 2259 goto done; 2260 } 2261 if (security_binder_transfer_binder(proc->cred, target_proc->cred)) { 2262 ret = -EPERM; 2263 goto done; 2264 } 2265 2266 ret = binder_inc_ref_for_node(target_proc, node, 2267 fp->hdr.type == BINDER_TYPE_BINDER, 2268 &thread->todo, &rdata); 2269 if (ret) 2270 goto done; 2271 2272 if (fp->hdr.type == BINDER_TYPE_BINDER) 2273 fp->hdr.type = BINDER_TYPE_HANDLE; 2274 else 2275 fp->hdr.type = BINDER_TYPE_WEAK_HANDLE; 2276 fp->binder = 0; 2277 fp->handle = rdata.desc; 2278 fp->cookie = 0; 2279 2280 trace_binder_transaction_node_to_ref(t, node, &rdata); 2281 binder_debug(BINDER_DEBUG_TRANSACTION, 2282 " node %d u%016llx -> ref %d desc %d\n", 2283 node->debug_id, (u64)node->ptr, 2284 rdata.debug_id, rdata.desc); 2285 done: 2286 binder_put_node(node); 2287 return ret; 2288 } 2289 2290 static int binder_translate_handle(struct flat_binder_object *fp, 2291 struct binder_transaction *t, 2292 struct binder_thread *thread) 2293 { 2294 struct binder_proc *proc = thread->proc; 2295 struct binder_proc *target_proc = t->to_proc; 2296 struct binder_node *node; 2297 struct binder_ref_data src_rdata; 2298 int ret = 0; 2299 2300 node = binder_get_node_from_ref(proc, fp->handle, 2301 fp->hdr.type == BINDER_TYPE_HANDLE, &src_rdata); 2302 if (!node) { 2303 binder_user_error("%d:%d got transaction with invalid handle, %d\n", 2304 proc->pid, thread->pid, fp->handle); 2305 return -EINVAL; 2306 } 2307 if (security_binder_transfer_binder(proc->cred, target_proc->cred)) { 2308 ret = -EPERM; 2309 goto done; 2310 } 2311 2312 binder_node_lock(node); 2313 if (node->proc == target_proc) { 2314 if (fp->hdr.type == BINDER_TYPE_HANDLE) 2315 fp->hdr.type = BINDER_TYPE_BINDER; 2316 else 2317 fp->hdr.type = BINDER_TYPE_WEAK_BINDER; 2318 fp->binder = node->ptr; 2319 fp->cookie = node->cookie; 2320 if (node->proc) 2321 binder_inner_proc_lock(node->proc); 2322 else 2323 __acquire(&node->proc->inner_lock); 2324 binder_inc_node_nilocked(node, 2325 fp->hdr.type == BINDER_TYPE_BINDER, 2326 0, NULL); 2327 if (node->proc) 2328 binder_inner_proc_unlock(node->proc); 2329 else 2330 __release(&node->proc->inner_lock); 2331 trace_binder_transaction_ref_to_node(t, node, &src_rdata); 2332 binder_debug(BINDER_DEBUG_TRANSACTION, 2333 " ref %d desc %d -> node %d u%016llx\n", 2334 src_rdata.debug_id, src_rdata.desc, node->debug_id, 2335 (u64)node->ptr); 2336 binder_node_unlock(node); 2337 } else { 2338 struct binder_ref_data dest_rdata; 2339 2340 binder_node_unlock(node); 2341 ret = binder_inc_ref_for_node(target_proc, node, 2342 fp->hdr.type == BINDER_TYPE_HANDLE, 2343 NULL, &dest_rdata); 2344 if (ret) 2345 goto done; 2346 2347 fp->binder = 0; 2348 fp->handle = dest_rdata.desc; 2349 fp->cookie = 0; 2350 trace_binder_transaction_ref_to_ref(t, node, &src_rdata, 2351 &dest_rdata); 2352 binder_debug(BINDER_DEBUG_TRANSACTION, 2353 " ref %d desc %d -> ref %d desc %d (node %d)\n", 2354 src_rdata.debug_id, src_rdata.desc, 2355 dest_rdata.debug_id, dest_rdata.desc, 2356 node->debug_id); 2357 } 2358 done: 2359 binder_put_node(node); 2360 return ret; 2361 } 2362 2363 static int binder_translate_fd(u32 fd, binder_size_t fd_offset, 2364 struct binder_transaction *t, 2365 struct binder_thread *thread, 2366 struct binder_transaction *in_reply_to) 2367 { 2368 struct binder_proc *proc = thread->proc; 2369 struct binder_proc *target_proc = t->to_proc; 2370 struct binder_txn_fd_fixup *fixup; 2371 struct file *file; 2372 int ret = 0; 2373 bool target_allows_fd; 2374 2375 if (in_reply_to) 2376 target_allows_fd = !!(in_reply_to->flags & TF_ACCEPT_FDS); 2377 else 2378 target_allows_fd = t->buffer->target_node->accept_fds; 2379 if (!target_allows_fd) { 2380 binder_user_error("%d:%d got %s with fd, %d, but target does not allow fds\n", 2381 proc->pid, thread->pid, 2382 in_reply_to ? "reply" : "transaction", 2383 fd); 2384 ret = -EPERM; 2385 goto err_fd_not_accepted; 2386 } 2387 2388 file = fget(fd); 2389 if (!file) { 2390 binder_user_error("%d:%d got transaction with invalid fd, %d\n", 2391 proc->pid, thread->pid, fd); 2392 ret = -EBADF; 2393 goto err_fget; 2394 } 2395 ret = security_binder_transfer_file(proc->cred, target_proc->cred, file); 2396 if (ret < 0) { 2397 ret = -EPERM; 2398 goto err_security; 2399 } 2400 2401 /* 2402 * Add fixup record for this transaction. The allocation 2403 * of the fd in the target needs to be done from a 2404 * target thread. 2405 */ 2406 fixup = kzalloc_obj(*fixup); 2407 if (!fixup) { 2408 ret = -ENOMEM; 2409 goto err_alloc; 2410 } 2411 fixup->file = file; 2412 fixup->offset = fd_offset; 2413 fixup->target_fd = -1; 2414 trace_binder_transaction_fd_send(t, fd, fixup->offset); 2415 list_add_tail(&fixup->fixup_entry, &t->fd_fixups); 2416 2417 return ret; 2418 2419 err_alloc: 2420 err_security: 2421 fput(file); 2422 err_fget: 2423 err_fd_not_accepted: 2424 return ret; 2425 } 2426 2427 /** 2428 * struct binder_ptr_fixup - data to be fixed-up in target buffer 2429 * @offset: offset in target buffer to fixup 2430 * @skip_size: bytes to skip in copy (fixup will be written later) 2431 * @fixup_data: data to write at fixup offset 2432 * @node: list node 2433 * 2434 * This is used for the pointer fixup list (pf) which is created and consumed 2435 * during binder_transaction() and is only accessed locally. No 2436 * locking is necessary. 2437 * 2438 * The list is ordered by @offset. 2439 */ 2440 struct binder_ptr_fixup { 2441 binder_size_t offset; 2442 size_t skip_size; 2443 binder_uintptr_t fixup_data; 2444 struct list_head node; 2445 }; 2446 2447 /** 2448 * struct binder_sg_copy - scatter-gather data to be copied 2449 * @offset: offset in target buffer 2450 * @sender_uaddr: user address in source buffer 2451 * @length: bytes to copy 2452 * @node: list node 2453 * 2454 * This is used for the sg copy list (sgc) which is created and consumed 2455 * during binder_transaction() and is only accessed locally. No 2456 * locking is necessary. 2457 * 2458 * The list is ordered by @offset. 2459 */ 2460 struct binder_sg_copy { 2461 binder_size_t offset; 2462 const void __user *sender_uaddr; 2463 size_t length; 2464 struct list_head node; 2465 }; 2466 2467 /** 2468 * binder_do_deferred_txn_copies() - copy and fixup scatter-gather data 2469 * @alloc: binder_alloc associated with @buffer 2470 * @buffer: binder buffer in target process 2471 * @sgc_head: list_head of scatter-gather copy list 2472 * @pf_head: list_head of pointer fixup list 2473 * 2474 * Processes all elements of @sgc_head, applying fixups from @pf_head 2475 * and copying the scatter-gather data from the source process' user 2476 * buffer to the target's buffer. It is expected that the list creation 2477 * and processing all occurs during binder_transaction() so these lists 2478 * are only accessed in local context. 2479 * 2480 * Return: 0=success, else -errno 2481 */ 2482 static int binder_do_deferred_txn_copies(struct binder_alloc *alloc, 2483 struct binder_buffer *buffer, 2484 struct list_head *sgc_head, 2485 struct list_head *pf_head) 2486 { 2487 int ret = 0; 2488 struct binder_sg_copy *sgc, *tmpsgc; 2489 struct binder_ptr_fixup *tmppf; 2490 struct binder_ptr_fixup *pf = 2491 list_first_entry_or_null(pf_head, struct binder_ptr_fixup, 2492 node); 2493 2494 list_for_each_entry_safe(sgc, tmpsgc, sgc_head, node) { 2495 size_t bytes_copied = 0; 2496 2497 while (bytes_copied < sgc->length) { 2498 size_t copy_size; 2499 size_t bytes_left = sgc->length - bytes_copied; 2500 size_t offset = sgc->offset + bytes_copied; 2501 2502 /* 2503 * We copy up to the fixup (pointed to by pf) 2504 */ 2505 copy_size = pf ? min(bytes_left, (size_t)pf->offset - offset) 2506 : bytes_left; 2507 if (!ret && copy_size) 2508 ret = binder_alloc_copy_user_to_buffer( 2509 alloc, buffer, 2510 offset, 2511 sgc->sender_uaddr + bytes_copied, 2512 copy_size); 2513 bytes_copied += copy_size; 2514 if (copy_size != bytes_left) { 2515 BUG_ON(!pf); 2516 /* we stopped at a fixup offset */ 2517 if (pf->skip_size) { 2518 /* 2519 * we are just skipping. This is for 2520 * BINDER_TYPE_FDA where the translated 2521 * fds will be fixed up when we get 2522 * to target context. 2523 */ 2524 bytes_copied += pf->skip_size; 2525 } else { 2526 /* apply the fixup indicated by pf */ 2527 if (!ret) 2528 ret = binder_alloc_copy_to_buffer( 2529 alloc, buffer, 2530 pf->offset, 2531 &pf->fixup_data, 2532 sizeof(pf->fixup_data)); 2533 bytes_copied += sizeof(pf->fixup_data); 2534 } 2535 list_del(&pf->node); 2536 kfree(pf); 2537 pf = list_first_entry_or_null(pf_head, 2538 struct binder_ptr_fixup, node); 2539 } 2540 } 2541 list_del(&sgc->node); 2542 kfree(sgc); 2543 } 2544 list_for_each_entry_safe(pf, tmppf, pf_head, node) { 2545 BUG_ON(pf->skip_size == 0); 2546 list_del(&pf->node); 2547 kfree(pf); 2548 } 2549 BUG_ON(!list_empty(sgc_head)); 2550 2551 return ret > 0 ? -EINVAL : ret; 2552 } 2553 2554 /** 2555 * binder_cleanup_deferred_txn_lists() - free specified lists 2556 * @sgc_head: list_head of scatter-gather copy list 2557 * @pf_head: list_head of pointer fixup list 2558 * 2559 * Called to clean up @sgc_head and @pf_head if there is an 2560 * error. 2561 */ 2562 static void binder_cleanup_deferred_txn_lists(struct list_head *sgc_head, 2563 struct list_head *pf_head) 2564 { 2565 struct binder_sg_copy *sgc, *tmpsgc; 2566 struct binder_ptr_fixup *pf, *tmppf; 2567 2568 list_for_each_entry_safe(sgc, tmpsgc, sgc_head, node) { 2569 list_del(&sgc->node); 2570 kfree(sgc); 2571 } 2572 list_for_each_entry_safe(pf, tmppf, pf_head, node) { 2573 list_del(&pf->node); 2574 kfree(pf); 2575 } 2576 } 2577 2578 /** 2579 * binder_defer_copy() - queue a scatter-gather buffer for copy 2580 * @sgc_head: list_head of scatter-gather copy list 2581 * @offset: binder buffer offset in target process 2582 * @sender_uaddr: user address in source process 2583 * @length: bytes to copy 2584 * 2585 * Specify a scatter-gather block to be copied. The actual copy must 2586 * be deferred until all the needed fixups are identified and queued. 2587 * Then the copy and fixups are done together so un-translated values 2588 * from the source are never visible in the target buffer. 2589 * 2590 * We are guaranteed that repeated calls to this function will have 2591 * monotonically increasing @offset values so the list will naturally 2592 * be ordered. 2593 * 2594 * Return: 0=success, else -errno 2595 */ 2596 static int binder_defer_copy(struct list_head *sgc_head, binder_size_t offset, 2597 const void __user *sender_uaddr, size_t length) 2598 { 2599 struct binder_sg_copy *bc = kzalloc_obj(*bc); 2600 2601 if (!bc) 2602 return -ENOMEM; 2603 2604 bc->offset = offset; 2605 bc->sender_uaddr = sender_uaddr; 2606 bc->length = length; 2607 INIT_LIST_HEAD(&bc->node); 2608 2609 /* 2610 * We are guaranteed that the deferred copies are in-order 2611 * so just add to the tail. 2612 */ 2613 list_add_tail(&bc->node, sgc_head); 2614 2615 return 0; 2616 } 2617 2618 /** 2619 * binder_add_fixup() - queue a fixup to be applied to sg copy 2620 * @pf_head: list_head of binder ptr fixup list 2621 * @offset: binder buffer offset in target process 2622 * @fixup: bytes to be copied for fixup 2623 * @skip_size: bytes to skip when copying (fixup will be applied later) 2624 * 2625 * Add the specified fixup to a list ordered by @offset. When copying 2626 * the scatter-gather buffers, the fixup will be copied instead of 2627 * data from the source buffer. For BINDER_TYPE_FDA fixups, the fixup 2628 * will be applied later (in target process context), so we just skip 2629 * the bytes specified by @skip_size. If @skip_size is 0, we copy the 2630 * value in @fixup. 2631 * 2632 * This function is called *mostly* in @offset order, but there are 2633 * exceptions. Since out-of-order inserts are relatively uncommon, 2634 * we insert the new element by searching backward from the tail of 2635 * the list. 2636 * 2637 * Return: 0=success, else -errno 2638 */ 2639 static int binder_add_fixup(struct list_head *pf_head, binder_size_t offset, 2640 binder_uintptr_t fixup, size_t skip_size) 2641 { 2642 struct binder_ptr_fixup *pf = kzalloc_obj(*pf); 2643 struct binder_ptr_fixup *tmppf; 2644 2645 if (!pf) 2646 return -ENOMEM; 2647 2648 pf->offset = offset; 2649 pf->fixup_data = fixup; 2650 pf->skip_size = skip_size; 2651 INIT_LIST_HEAD(&pf->node); 2652 2653 /* Fixups are *mostly* added in-order, but there are some 2654 * exceptions. Look backwards through list for insertion point. 2655 */ 2656 list_for_each_entry_reverse(tmppf, pf_head, node) { 2657 if (tmppf->offset < pf->offset) { 2658 list_add(&pf->node, &tmppf->node); 2659 return 0; 2660 } 2661 } 2662 /* 2663 * if we get here, then the new offset is the lowest so 2664 * insert at the head 2665 */ 2666 list_add(&pf->node, pf_head); 2667 return 0; 2668 } 2669 2670 static int binder_translate_fd_array(struct list_head *pf_head, 2671 struct binder_fd_array_object *fda, 2672 const void __user *sender_ubuffer, 2673 struct binder_buffer_object *parent, 2674 struct binder_buffer_object *sender_uparent, 2675 struct binder_transaction *t, 2676 struct binder_thread *thread, 2677 struct binder_transaction *in_reply_to) 2678 { 2679 binder_size_t fdi, fd_buf_size; 2680 binder_size_t fda_offset; 2681 const void __user *sender_ufda_base; 2682 struct binder_proc *proc = thread->proc; 2683 int ret; 2684 2685 if (fda->num_fds == 0) 2686 return 0; 2687 2688 fd_buf_size = sizeof(u32) * fda->num_fds; 2689 if (fda->num_fds >= SIZE_MAX / sizeof(u32)) { 2690 binder_user_error("%d:%d got transaction with invalid number of fds (%lld)\n", 2691 proc->pid, thread->pid, (u64)fda->num_fds); 2692 return -EINVAL; 2693 } 2694 if (fd_buf_size > parent->length || 2695 fda->parent_offset > parent->length - fd_buf_size) { 2696 /* No space for all file descriptors here. */ 2697 binder_user_error("%d:%d not enough space to store %lld fds in buffer\n", 2698 proc->pid, thread->pid, (u64)fda->num_fds); 2699 return -EINVAL; 2700 } 2701 /* 2702 * the source data for binder_buffer_object is visible 2703 * to user-space and the @buffer element is the user 2704 * pointer to the buffer_object containing the fd_array. 2705 * Convert the address to an offset relative to 2706 * the base of the transaction buffer. 2707 */ 2708 fda_offset = parent->buffer - t->buffer->user_data + 2709 fda->parent_offset; 2710 sender_ufda_base = (void __user *)(uintptr_t)sender_uparent->buffer + 2711 fda->parent_offset; 2712 2713 if (!IS_ALIGNED((unsigned long)fda_offset, sizeof(u32)) || 2714 !IS_ALIGNED((unsigned long)sender_ufda_base, sizeof(u32))) { 2715 binder_user_error("%d:%d parent offset not aligned correctly.\n", 2716 proc->pid, thread->pid); 2717 return -EINVAL; 2718 } 2719 ret = binder_add_fixup(pf_head, fda_offset, 0, fda->num_fds * sizeof(u32)); 2720 if (ret) 2721 return ret; 2722 2723 for (fdi = 0; fdi < fda->num_fds; fdi++) { 2724 u32 fd; 2725 binder_size_t offset = fda_offset + fdi * sizeof(fd); 2726 binder_size_t sender_uoffset = fdi * sizeof(fd); 2727 2728 ret = copy_from_user(&fd, sender_ufda_base + sender_uoffset, sizeof(fd)); 2729 if (!ret) 2730 ret = binder_translate_fd(fd, offset, t, thread, 2731 in_reply_to); 2732 if (ret) 2733 return ret > 0 ? -EINVAL : ret; 2734 } 2735 return 0; 2736 } 2737 2738 static int binder_fixup_parent(struct list_head *pf_head, 2739 struct binder_transaction *t, 2740 struct binder_thread *thread, 2741 struct binder_buffer_object *bp, 2742 binder_size_t off_start_offset, 2743 binder_size_t num_valid, 2744 binder_size_t last_fixup_obj_off, 2745 binder_size_t last_fixup_min_off) 2746 { 2747 struct binder_buffer_object *parent; 2748 struct binder_buffer *b = t->buffer; 2749 struct binder_proc *proc = thread->proc; 2750 struct binder_proc *target_proc = t->to_proc; 2751 struct binder_object object; 2752 binder_size_t buffer_offset; 2753 binder_size_t parent_offset; 2754 2755 if (!(bp->flags & BINDER_BUFFER_FLAG_HAS_PARENT)) 2756 return 0; 2757 2758 parent = binder_validate_ptr(target_proc, b, &object, bp->parent, 2759 off_start_offset, &parent_offset, 2760 num_valid); 2761 if (!parent) { 2762 binder_user_error("%d:%d got transaction with invalid parent offset or type\n", 2763 proc->pid, thread->pid); 2764 return -EINVAL; 2765 } 2766 2767 if (!binder_validate_fixup(target_proc, b, off_start_offset, 2768 parent_offset, bp->parent_offset, 2769 last_fixup_obj_off, 2770 last_fixup_min_off)) { 2771 binder_user_error("%d:%d got transaction with out-of-order buffer fixup\n", 2772 proc->pid, thread->pid); 2773 return -EINVAL; 2774 } 2775 2776 if (parent->length < sizeof(binder_uintptr_t) || 2777 bp->parent_offset > parent->length - sizeof(binder_uintptr_t)) { 2778 /* No space for a pointer here! */ 2779 binder_user_error("%d:%d got transaction with invalid parent offset\n", 2780 proc->pid, thread->pid); 2781 return -EINVAL; 2782 } 2783 2784 buffer_offset = bp->parent_offset + parent->buffer - b->user_data; 2785 2786 return binder_add_fixup(pf_head, buffer_offset, bp->buffer, 0); 2787 } 2788 2789 /** 2790 * binder_can_update_transaction() - Can a txn be superseded by an updated one? 2791 * @t1: the pending async txn in the frozen process 2792 * @t2: the new async txn to supersede the outdated pending one 2793 * 2794 * Return: true if t2 can supersede t1 2795 * false if t2 can not supersede t1 2796 */ 2797 static bool binder_can_update_transaction(struct binder_transaction *t1, 2798 struct binder_transaction *t2) 2799 { 2800 if ((t1->flags & t2->flags & (TF_ONE_WAY | TF_UPDATE_TXN)) != 2801 (TF_ONE_WAY | TF_UPDATE_TXN) || !t1->to_proc || !t2->to_proc) 2802 return false; 2803 if (t1->to_proc->tsk == t2->to_proc->tsk && t1->code == t2->code && 2804 t1->flags == t2->flags && t1->buffer->pid == t2->buffer->pid && 2805 t1->buffer->target_node->ptr == t2->buffer->target_node->ptr && 2806 t1->buffer->target_node->cookie == t2->buffer->target_node->cookie) 2807 return true; 2808 return false; 2809 } 2810 2811 /** 2812 * binder_find_outdated_transaction_ilocked() - Find the outdated transaction 2813 * @t: new async transaction 2814 * @target_list: list to find outdated transaction 2815 * 2816 * Return: the outdated transaction if found 2817 * NULL if no outdated transacton can be found 2818 * 2819 * Requires the proc->inner_lock to be held. 2820 */ 2821 static struct binder_transaction * 2822 binder_find_outdated_transaction_ilocked(struct binder_transaction *t, 2823 struct list_head *target_list) 2824 { 2825 struct binder_work *w; 2826 2827 list_for_each_entry(w, target_list, entry) { 2828 struct binder_transaction *t_queued; 2829 2830 if (w->type != BINDER_WORK_TRANSACTION) 2831 continue; 2832 t_queued = container_of(w, struct binder_transaction, work); 2833 if (binder_can_update_transaction(t_queued, t)) 2834 return t_queued; 2835 } 2836 return NULL; 2837 } 2838 2839 /** 2840 * binder_proc_transaction() - sends a transaction to a process and wakes it up 2841 * @t: transaction to send 2842 * @proc: process to send the transaction to 2843 * @thread: thread in @proc to send the transaction to (may be NULL) 2844 * 2845 * This function queues a transaction to the specified process. It will try 2846 * to find a thread in the target process to handle the transaction and 2847 * wake it up. If no thread is found, the work is queued to the proc 2848 * waitqueue. 2849 * 2850 * If the @thread parameter is not NULL, the transaction is always queued 2851 * to the waitlist of that specific thread. 2852 * 2853 * Return: 0 if the transaction was successfully queued 2854 * BR_DEAD_REPLY if the target process or thread is dead 2855 * BR_FROZEN_REPLY if the target process or thread is frozen and 2856 * the sync transaction was rejected 2857 * BR_TRANSACTION_PENDING_FROZEN if the target process is frozen 2858 * and the async transaction was successfully queued 2859 */ 2860 static int binder_proc_transaction(struct binder_transaction *t, 2861 struct binder_proc *proc, 2862 struct binder_thread *thread) 2863 { 2864 struct binder_node *node = t->buffer->target_node; 2865 bool oneway = !!(t->flags & TF_ONE_WAY); 2866 bool pending_async = false; 2867 struct binder_transaction *t_outdated = NULL; 2868 bool frozen = false; 2869 2870 BUG_ON(!node); 2871 binder_node_lock(node); 2872 if (oneway) { 2873 BUG_ON(thread); 2874 if (node->has_async_transaction) 2875 pending_async = true; 2876 else 2877 node->has_async_transaction = true; 2878 } 2879 2880 binder_inner_proc_lock(proc); 2881 if (proc->is_frozen) { 2882 frozen = true; 2883 proc->sync_recv |= !oneway; 2884 proc->async_recv |= oneway; 2885 } 2886 2887 if ((frozen && !oneway) || proc->is_dead || 2888 (thread && thread->is_dead)) { 2889 binder_inner_proc_unlock(proc); 2890 binder_node_unlock(node); 2891 return frozen ? BR_FROZEN_REPLY : BR_DEAD_REPLY; 2892 } 2893 2894 if (!thread && !pending_async) 2895 thread = binder_select_thread_ilocked(proc); 2896 2897 if (thread) { 2898 binder_enqueue_thread_work_ilocked(thread, &t->work); 2899 } else if (!pending_async) { 2900 binder_enqueue_work_ilocked(&t->work, &proc->todo); 2901 } else { 2902 if ((t->flags & TF_UPDATE_TXN) && frozen) { 2903 t_outdated = binder_find_outdated_transaction_ilocked(t, 2904 &node->async_todo); 2905 if (t_outdated) { 2906 binder_debug(BINDER_DEBUG_TRANSACTION, 2907 "txn %d supersedes %d\n", 2908 t->debug_id, t_outdated->debug_id); 2909 list_del_init(&t_outdated->work.entry); 2910 proc->outstanding_txns--; 2911 } 2912 } 2913 binder_enqueue_work_ilocked(&t->work, &node->async_todo); 2914 } 2915 2916 if (!pending_async) 2917 binder_wakeup_thread_ilocked(proc, thread, !oneway /* sync */); 2918 2919 proc->outstanding_txns++; 2920 binder_inner_proc_unlock(proc); 2921 binder_node_unlock(node); 2922 2923 /* 2924 * To reduce potential contention, free the outdated transaction and 2925 * buffer after releasing the locks. 2926 */ 2927 if (t_outdated) { 2928 struct binder_buffer *buffer = t_outdated->buffer; 2929 2930 t_outdated->buffer = NULL; 2931 buffer->transaction = NULL; 2932 trace_binder_transaction_update_buffer_release(buffer); 2933 binder_release_entire_buffer(proc, NULL, buffer, true); 2934 binder_alloc_free_buf(&proc->alloc, buffer); 2935 binder_free_txn_fixups(t_outdated); 2936 kfree(t_outdated); 2937 binder_stats_deleted(BINDER_STAT_TRANSACTION); 2938 } 2939 2940 if (oneway && frozen) 2941 return BR_TRANSACTION_PENDING_FROZEN; 2942 2943 return 0; 2944 } 2945 2946 /** 2947 * binder_get_node_refs_for_txn() - Get required refs on node for txn 2948 * @node: struct binder_node for which to get refs 2949 * @procp: returns @node->proc if valid 2950 * @error: if no @procp then returns BR_DEAD_REPLY 2951 * 2952 * User-space normally keeps the node alive when creating a transaction 2953 * since it has a reference to the target. The local strong ref keeps it 2954 * alive if the sending process dies before the target process processes 2955 * the transaction. If the source process is malicious or has a reference 2956 * counting bug, relying on the local strong ref can fail. 2957 * 2958 * Since user-space can cause the local strong ref to go away, we also take 2959 * a tmpref on the node to ensure it survives while we are constructing 2960 * the transaction. We also need a tmpref on the proc while we are 2961 * constructing the transaction, so we take that here as well. 2962 * 2963 * Return: The target_node with refs taken or NULL if no @node->proc is NULL. 2964 * Also sets @procp if valid. If the @node->proc is NULL indicating that the 2965 * target proc has died, @error is set to BR_DEAD_REPLY. 2966 */ 2967 static struct binder_node *binder_get_node_refs_for_txn( 2968 struct binder_node *node, 2969 struct binder_proc **procp, 2970 uint32_t *error) 2971 { 2972 struct binder_node *target_node = NULL; 2973 2974 binder_node_inner_lock(node); 2975 if (node->proc) { 2976 target_node = node; 2977 binder_inc_node_nilocked(node, 1, 0, NULL); 2978 binder_inc_node_tmpref_ilocked(node); 2979 node->proc->tmp_ref++; 2980 *procp = node->proc; 2981 } else 2982 *error = BR_DEAD_REPLY; 2983 binder_node_inner_unlock(node); 2984 2985 return target_node; 2986 } 2987 2988 static void binder_set_txn_from_error(struct binder_transaction *t, int id, 2989 uint32_t command, int32_t param) 2990 { 2991 struct binder_thread *from = binder_get_txn_from_and_acq_inner(t); 2992 2993 if (!from) { 2994 /* annotation for sparse */ 2995 __release(&from->proc->inner_lock); 2996 return; 2997 } 2998 2999 /* don't override existing errors */ 3000 if (from->ee.command == BR_OK) 3001 binder_set_extended_error(&from->ee, id, command, param); 3002 binder_inner_proc_unlock(from->proc); 3003 binder_thread_dec_tmpref(from); 3004 } 3005 3006 /** 3007 * binder_netlink_report() - report a transaction failure via netlink 3008 * @proc: the binder proc sending the transaction 3009 * @t: the binder transaction that failed 3010 * @data_size: the user provided data size for the transaction 3011 * @error: enum binder_driver_return_protocol returned to sender 3012 * 3013 * Note that t->buffer is not safe to access here, as it may have been 3014 * released (or not yet allocated). Callers should guarantee all the 3015 * transaction items used here are safe to access. 3016 */ 3017 static void binder_netlink_report(struct binder_proc *proc, 3018 struct binder_transaction *t, 3019 u32 data_size, 3020 u32 error) 3021 { 3022 const char *context = proc->context->name; 3023 struct sk_buff *skb; 3024 void *hdr; 3025 3026 if (!genl_has_listeners(&binder_nl_family, &init_net, 3027 BINDER_NLGRP_REPORT)) 3028 return; 3029 3030 trace_binder_netlink_report(context, t, data_size, error); 3031 3032 skb = genlmsg_new(GENLMSG_DEFAULT_SIZE, GFP_KERNEL); 3033 if (!skb) 3034 return; 3035 3036 hdr = genlmsg_put(skb, 0, 0, &binder_nl_family, 0, BINDER_CMD_REPORT); 3037 if (!hdr) 3038 goto free_skb; 3039 3040 if (nla_put_u32(skb, BINDER_A_REPORT_ERROR, error) || 3041 nla_put_string(skb, BINDER_A_REPORT_CONTEXT, context) || 3042 nla_put_u32(skb, BINDER_A_REPORT_FROM_PID, t->from_pid) || 3043 nla_put_u32(skb, BINDER_A_REPORT_FROM_TID, t->from_tid)) 3044 goto cancel_skb; 3045 3046 if (t->to_proc && 3047 nla_put_u32(skb, BINDER_A_REPORT_TO_PID, t->to_proc->pid)) 3048 goto cancel_skb; 3049 3050 if (t->to_thread && 3051 nla_put_u32(skb, BINDER_A_REPORT_TO_TID, t->to_thread->pid)) 3052 goto cancel_skb; 3053 3054 if (t->is_reply && nla_put_flag(skb, BINDER_A_REPORT_IS_REPLY)) 3055 goto cancel_skb; 3056 3057 if (nla_put_u32(skb, BINDER_A_REPORT_FLAGS, t->flags) || 3058 nla_put_u32(skb, BINDER_A_REPORT_CODE, t->code) || 3059 nla_put_u32(skb, BINDER_A_REPORT_DATA_SIZE, data_size)) 3060 goto cancel_skb; 3061 3062 genlmsg_end(skb, hdr); 3063 genlmsg_multicast(&binder_nl_family, skb, 0, BINDER_NLGRP_REPORT, 3064 GFP_KERNEL); 3065 return; 3066 3067 cancel_skb: 3068 genlmsg_cancel(skb, hdr); 3069 free_skb: 3070 nlmsg_free(skb); 3071 } 3072 3073 static void binder_transaction(struct binder_proc *proc, 3074 struct binder_thread *thread, 3075 struct binder_transaction_data *tr, int reply, 3076 binder_size_t extra_buffers_size) 3077 { 3078 int ret; 3079 struct binder_transaction *t; 3080 struct binder_work *w; 3081 struct binder_work *tcomplete; 3082 binder_size_t buffer_offset = 0; 3083 binder_size_t off_start_offset, off_end_offset; 3084 binder_size_t off_min; 3085 binder_size_t sg_buf_offset, sg_buf_end_offset; 3086 binder_size_t user_offset = 0; 3087 struct binder_proc *target_proc = NULL; 3088 struct binder_thread *target_thread = NULL; 3089 struct binder_node *target_node = NULL; 3090 struct binder_transaction *in_reply_to = NULL; 3091 struct binder_transaction_log_entry *e; 3092 uint32_t return_error = 0; 3093 uint32_t return_error_param = 0; 3094 uint32_t return_error_line = 0; 3095 binder_size_t last_fixup_obj_off = 0; 3096 binder_size_t last_fixup_min_off = 0; 3097 struct binder_context *context = proc->context; 3098 int t_debug_id = atomic_inc_return(&binder_last_id); 3099 ktime_t t_start_time = ktime_get(); 3100 struct lsm_context lsmctx = { }; 3101 size_t lsmctx_aligned_size = 0; 3102 LIST_HEAD(sgc_head); 3103 LIST_HEAD(pf_head); 3104 const void __user *user_buffer = (const void __user *) 3105 (uintptr_t)tr->data.ptr.buffer; 3106 3107 e = binder_transaction_log_add(&binder_transaction_log); 3108 e->debug_id = t_debug_id; 3109 e->call_type = reply ? 2 : !!(tr->flags & TF_ONE_WAY); 3110 e->from_proc = proc->pid; 3111 e->from_thread = thread->pid; 3112 e->target_handle = tr->target.handle; 3113 e->data_size = tr->data_size; 3114 e->offsets_size = tr->offsets_size; 3115 strscpy(e->context_name, proc->context->name, BINDERFS_MAX_NAME); 3116 3117 binder_inner_proc_lock(proc); 3118 binder_set_extended_error(&thread->ee, t_debug_id, BR_OK, 0); 3119 binder_inner_proc_unlock(proc); 3120 3121 t = kzalloc_obj(*t); 3122 if (!t) { 3123 binder_txn_error("%d:%d cannot allocate transaction\n", 3124 thread->pid, proc->pid); 3125 return_error = BR_FAILED_REPLY; 3126 return_error_param = -ENOMEM; 3127 return_error_line = __LINE__; 3128 goto err_alloc_t_failed; 3129 } 3130 INIT_LIST_HEAD(&t->fd_fixups); 3131 binder_stats_created(BINDER_STAT_TRANSACTION); 3132 spin_lock_init(&t->lock); 3133 t->debug_id = t_debug_id; 3134 t->start_time = t_start_time; 3135 t->from_pid = proc->pid; 3136 t->from_tid = thread->pid; 3137 t->sender_euid = current_euid(); 3138 t->code = tr->code; 3139 t->flags = tr->flags; 3140 t->priority = task_nice(current); 3141 t->work.type = BINDER_WORK_TRANSACTION; 3142 t->is_async = !reply && (tr->flags & TF_ONE_WAY); 3143 t->is_reply = reply; 3144 if (!reply && !(tr->flags & TF_ONE_WAY)) 3145 t->from = thread; 3146 3147 if (reply) { 3148 binder_inner_proc_lock(proc); 3149 in_reply_to = thread->transaction_stack; 3150 if (in_reply_to == NULL) { 3151 binder_inner_proc_unlock(proc); 3152 binder_user_error("%d:%d got reply transaction with no transaction stack\n", 3153 proc->pid, thread->pid); 3154 return_error = BR_FAILED_REPLY; 3155 return_error_param = -EPROTO; 3156 return_error_line = __LINE__; 3157 goto err_empty_call_stack; 3158 } 3159 if (in_reply_to->to_thread != thread) { 3160 spin_lock(&in_reply_to->lock); 3161 binder_user_error("%d:%d got reply transaction with bad transaction stack, transaction %d has target %d:%d\n", 3162 proc->pid, thread->pid, in_reply_to->debug_id, 3163 in_reply_to->to_proc ? 3164 in_reply_to->to_proc->pid : 0, 3165 in_reply_to->to_thread ? 3166 in_reply_to->to_thread->pid : 0); 3167 spin_unlock(&in_reply_to->lock); 3168 binder_inner_proc_unlock(proc); 3169 return_error = BR_FAILED_REPLY; 3170 return_error_param = -EPROTO; 3171 return_error_line = __LINE__; 3172 in_reply_to = NULL; 3173 goto err_bad_call_stack; 3174 } 3175 thread->transaction_stack = in_reply_to->to_parent; 3176 binder_inner_proc_unlock(proc); 3177 binder_set_nice(in_reply_to->saved_priority); 3178 target_thread = binder_get_txn_from_and_acq_inner(in_reply_to); 3179 if (target_thread == NULL) { 3180 /* annotation for sparse */ 3181 __release(&target_thread->proc->inner_lock); 3182 binder_txn_error("%d:%d reply target not found\n", 3183 thread->pid, proc->pid); 3184 return_error = BR_DEAD_REPLY; 3185 return_error_line = __LINE__; 3186 goto err_dead_binder; 3187 } 3188 if (target_thread->transaction_stack != in_reply_to) { 3189 binder_user_error("%d:%d got reply transaction with bad target transaction stack %d, expected %d\n", 3190 proc->pid, thread->pid, 3191 target_thread->transaction_stack ? 3192 target_thread->transaction_stack->debug_id : 0, 3193 in_reply_to->debug_id); 3194 binder_inner_proc_unlock(target_thread->proc); 3195 return_error = BR_FAILED_REPLY; 3196 return_error_param = -EPROTO; 3197 return_error_line = __LINE__; 3198 in_reply_to = NULL; 3199 target_thread = NULL; 3200 goto err_dead_binder; 3201 } 3202 target_proc = target_thread->proc; 3203 target_proc->tmp_ref++; 3204 binder_inner_proc_unlock(target_thread->proc); 3205 } else { 3206 if (tr->target.handle) { 3207 struct binder_ref *ref; 3208 3209 /* 3210 * There must already be a strong ref 3211 * on this node. If so, do a strong 3212 * increment on the node to ensure it 3213 * stays alive until the transaction is 3214 * done. 3215 */ 3216 binder_proc_lock(proc); 3217 ref = binder_get_ref_olocked(proc, tr->target.handle, 3218 true); 3219 if (ref) { 3220 target_node = binder_get_node_refs_for_txn( 3221 ref->node, &target_proc, 3222 &return_error); 3223 } else { 3224 binder_user_error("%d:%d got transaction to invalid handle, %u\n", 3225 proc->pid, thread->pid, tr->target.handle); 3226 return_error = BR_FAILED_REPLY; 3227 } 3228 binder_proc_unlock(proc); 3229 } else { 3230 mutex_lock(&context->context_mgr_node_lock); 3231 target_node = context->binder_context_mgr_node; 3232 if (target_node) 3233 target_node = binder_get_node_refs_for_txn( 3234 target_node, &target_proc, 3235 &return_error); 3236 else 3237 return_error = BR_DEAD_REPLY; 3238 mutex_unlock(&context->context_mgr_node_lock); 3239 if (target_node && target_proc->pid == proc->pid) { 3240 binder_user_error("%d:%d got transaction to context manager from process owning it\n", 3241 proc->pid, thread->pid); 3242 return_error = BR_FAILED_REPLY; 3243 return_error_param = -EINVAL; 3244 return_error_line = __LINE__; 3245 goto err_invalid_target_handle; 3246 } 3247 } 3248 if (!target_node) { 3249 binder_txn_error("%d:%d cannot find target node\n", 3250 proc->pid, thread->pid); 3251 /* return_error is set above */ 3252 return_error_param = -EINVAL; 3253 return_error_line = __LINE__; 3254 goto err_dead_binder; 3255 } 3256 e->to_node = target_node->debug_id; 3257 if (WARN_ON(proc == target_proc)) { 3258 binder_txn_error("%d:%d self transactions not allowed\n", 3259 thread->pid, proc->pid); 3260 return_error = BR_FAILED_REPLY; 3261 return_error_param = -EINVAL; 3262 return_error_line = __LINE__; 3263 goto err_invalid_target_handle; 3264 } 3265 if (security_binder_transaction(proc->cred, 3266 target_proc->cred) < 0) { 3267 binder_txn_error("%d:%d transaction credentials failed\n", 3268 thread->pid, proc->pid); 3269 return_error = BR_FAILED_REPLY; 3270 return_error_param = -EPERM; 3271 return_error_line = __LINE__; 3272 goto err_invalid_target_handle; 3273 } 3274 binder_inner_proc_lock(proc); 3275 3276 w = list_first_entry_or_null(&thread->todo, 3277 struct binder_work, entry); 3278 if (!(tr->flags & TF_ONE_WAY) && w && 3279 w->type == BINDER_WORK_TRANSACTION) { 3280 /* 3281 * Do not allow new outgoing transaction from a 3282 * thread that has a transaction at the head of 3283 * its todo list. Only need to check the head 3284 * because binder_select_thread_ilocked picks a 3285 * thread from proc->waiting_threads to enqueue 3286 * the transaction, and nothing is queued to the 3287 * todo list while the thread is on waiting_threads. 3288 */ 3289 binder_user_error("%d:%d new transaction not allowed when there is a transaction on thread todo\n", 3290 proc->pid, thread->pid); 3291 binder_inner_proc_unlock(proc); 3292 return_error = BR_FAILED_REPLY; 3293 return_error_param = -EPROTO; 3294 return_error_line = __LINE__; 3295 goto err_bad_todo_list; 3296 } 3297 3298 if (!(tr->flags & TF_ONE_WAY) && thread->transaction_stack) { 3299 struct binder_transaction *tmp; 3300 3301 tmp = thread->transaction_stack; 3302 if (tmp->to_thread != thread) { 3303 spin_lock(&tmp->lock); 3304 binder_user_error("%d:%d got new transaction with bad transaction stack, transaction %d has target %d:%d\n", 3305 proc->pid, thread->pid, tmp->debug_id, 3306 tmp->to_proc ? tmp->to_proc->pid : 0, 3307 tmp->to_thread ? 3308 tmp->to_thread->pid : 0); 3309 spin_unlock(&tmp->lock); 3310 binder_inner_proc_unlock(proc); 3311 return_error = BR_FAILED_REPLY; 3312 return_error_param = -EPROTO; 3313 return_error_line = __LINE__; 3314 goto err_bad_call_stack; 3315 } 3316 while (tmp) { 3317 struct binder_thread *from; 3318 3319 spin_lock(&tmp->lock); 3320 from = tmp->from; 3321 if (from && from->proc == target_proc) { 3322 atomic_inc(&from->tmp_ref); 3323 target_thread = from; 3324 spin_unlock(&tmp->lock); 3325 break; 3326 } 3327 spin_unlock(&tmp->lock); 3328 tmp = tmp->from_parent; 3329 } 3330 } 3331 binder_inner_proc_unlock(proc); 3332 } 3333 3334 t->to_proc = target_proc; 3335 t->to_thread = target_thread; 3336 if (target_thread) 3337 e->to_thread = target_thread->pid; 3338 e->to_proc = target_proc->pid; 3339 3340 tcomplete = kzalloc_obj(*tcomplete); 3341 if (tcomplete == NULL) { 3342 binder_txn_error("%d:%d cannot allocate work for transaction\n", 3343 thread->pid, proc->pid); 3344 return_error = BR_FAILED_REPLY; 3345 return_error_param = -ENOMEM; 3346 return_error_line = __LINE__; 3347 goto err_alloc_tcomplete_failed; 3348 } 3349 binder_stats_created(BINDER_STAT_TRANSACTION_COMPLETE); 3350 3351 if (reply) 3352 binder_debug(BINDER_DEBUG_TRANSACTION, 3353 "%d:%d BC_REPLY %d -> %d:%d, data size %lld-%lld-%lld\n", 3354 proc->pid, thread->pid, t->debug_id, 3355 target_proc->pid, target_thread->pid, 3356 (u64)tr->data_size, (u64)tr->offsets_size, 3357 (u64)extra_buffers_size); 3358 else 3359 binder_debug(BINDER_DEBUG_TRANSACTION, 3360 "%d:%d BC_TRANSACTION %d -> %d - node %d, data size %lld-%lld-%lld\n", 3361 proc->pid, thread->pid, t->debug_id, 3362 target_proc->pid, target_node->debug_id, 3363 (u64)tr->data_size, (u64)tr->offsets_size, 3364 (u64)extra_buffers_size); 3365 3366 if (target_node && target_node->txn_security_ctx) { 3367 u32 secid; 3368 3369 security_cred_getsecid(proc->cred, &secid); 3370 ret = security_secid_to_secctx(secid, &lsmctx); 3371 if (ret < 0) { 3372 binder_txn_error("%d:%d failed to get security context\n", 3373 thread->pid, proc->pid); 3374 return_error = BR_FAILED_REPLY; 3375 return_error_param = ret; 3376 return_error_line = __LINE__; 3377 goto err_get_secctx_failed; 3378 } 3379 lsmctx_aligned_size = ALIGN(lsmctx.len, sizeof(u64)); 3380 extra_buffers_size += lsmctx_aligned_size; 3381 if (extra_buffers_size < lsmctx_aligned_size) { 3382 binder_txn_error("%d:%d integer overflow of extra_buffers_size\n", 3383 thread->pid, proc->pid); 3384 return_error = BR_FAILED_REPLY; 3385 return_error_param = -EINVAL; 3386 return_error_line = __LINE__; 3387 goto err_bad_extra_size; 3388 } 3389 } 3390 3391 trace_binder_transaction(reply, t, target_node); 3392 3393 t->buffer = binder_alloc_new_buf(&target_proc->alloc, tr->data_size, 3394 tr->offsets_size, extra_buffers_size, 3395 !reply && (t->flags & TF_ONE_WAY)); 3396 if (IS_ERR(t->buffer)) { 3397 char *s; 3398 3399 ret = PTR_ERR(t->buffer); 3400 s = (ret == -ESRCH) ? ": vma cleared, target dead or dying" 3401 : (ret == -ENOSPC) ? ": no space left" 3402 : (ret == -ENOMEM) ? ": memory allocation failed" 3403 : ""; 3404 binder_txn_error("cannot allocate buffer%s", s); 3405 3406 return_error_param = PTR_ERR(t->buffer); 3407 return_error = return_error_param == -ESRCH ? 3408 BR_DEAD_REPLY : BR_FAILED_REPLY; 3409 return_error_line = __LINE__; 3410 t->buffer = NULL; 3411 goto err_binder_alloc_buf_failed; 3412 } 3413 if (lsmctx.context) { 3414 int err; 3415 size_t buf_offset = ALIGN(tr->data_size, sizeof(void *)) + 3416 ALIGN(tr->offsets_size, sizeof(void *)) + 3417 ALIGN(extra_buffers_size, sizeof(void *)) - 3418 lsmctx_aligned_size; 3419 3420 t->security_ctx = t->buffer->user_data + buf_offset; 3421 err = binder_alloc_copy_to_buffer(&target_proc->alloc, 3422 t->buffer, buf_offset, 3423 lsmctx.context, lsmctx.len); 3424 if (err) { 3425 t->security_ctx = 0; 3426 WARN_ON(1); 3427 } 3428 security_release_secctx(&lsmctx); 3429 lsmctx.context = NULL; 3430 } 3431 t->buffer->debug_id = t->debug_id; 3432 t->buffer->transaction = t; 3433 t->buffer->target_node = target_node; 3434 t->buffer->clear_on_free = !!(t->flags & TF_CLEAR_BUF); 3435 trace_binder_transaction_alloc_buf(t->buffer); 3436 3437 if (binder_alloc_copy_user_to_buffer( 3438 &target_proc->alloc, 3439 t->buffer, 3440 ALIGN(tr->data_size, sizeof(void *)), 3441 (const void __user *) 3442 (uintptr_t)tr->data.ptr.offsets, 3443 tr->offsets_size)) { 3444 binder_user_error("%d:%d got transaction with invalid offsets ptr\n", 3445 proc->pid, thread->pid); 3446 return_error = BR_FAILED_REPLY; 3447 return_error_param = -EFAULT; 3448 return_error_line = __LINE__; 3449 goto err_copy_data_failed; 3450 } 3451 if (!IS_ALIGNED(tr->offsets_size, sizeof(binder_size_t))) { 3452 binder_user_error("%d:%d got transaction with invalid offsets size, %lld\n", 3453 proc->pid, thread->pid, (u64)tr->offsets_size); 3454 return_error = BR_FAILED_REPLY; 3455 return_error_param = -EINVAL; 3456 return_error_line = __LINE__; 3457 goto err_bad_offset; 3458 } 3459 if (!IS_ALIGNED(extra_buffers_size, sizeof(u64))) { 3460 binder_user_error("%d:%d got transaction with unaligned buffers size, %lld\n", 3461 proc->pid, thread->pid, 3462 (u64)extra_buffers_size); 3463 return_error = BR_FAILED_REPLY; 3464 return_error_param = -EINVAL; 3465 return_error_line = __LINE__; 3466 goto err_bad_offset; 3467 } 3468 off_start_offset = ALIGN(tr->data_size, sizeof(void *)); 3469 buffer_offset = off_start_offset; 3470 off_end_offset = off_start_offset + tr->offsets_size; 3471 sg_buf_offset = ALIGN(off_end_offset, sizeof(void *)); 3472 sg_buf_end_offset = sg_buf_offset + extra_buffers_size - 3473 lsmctx_aligned_size; 3474 off_min = 0; 3475 for (buffer_offset = off_start_offset; buffer_offset < off_end_offset; 3476 buffer_offset += sizeof(binder_size_t)) { 3477 struct binder_object_header *hdr; 3478 size_t object_size; 3479 struct binder_object object; 3480 binder_size_t object_offset; 3481 binder_size_t copy_size; 3482 3483 if (binder_alloc_copy_from_buffer(&target_proc->alloc, 3484 &object_offset, 3485 t->buffer, 3486 buffer_offset, 3487 sizeof(object_offset))) { 3488 binder_txn_error("%d:%d copy offset from buffer failed\n", 3489 thread->pid, proc->pid); 3490 return_error = BR_FAILED_REPLY; 3491 return_error_param = -EINVAL; 3492 return_error_line = __LINE__; 3493 goto err_bad_offset; 3494 } 3495 3496 /* 3497 * Copy the source user buffer up to the next object 3498 * that will be processed. 3499 */ 3500 copy_size = object_offset - user_offset; 3501 if (copy_size && (user_offset > object_offset || 3502 object_offset > tr->data_size || 3503 binder_alloc_copy_user_to_buffer( 3504 &target_proc->alloc, 3505 t->buffer, user_offset, 3506 user_buffer + user_offset, 3507 copy_size))) { 3508 binder_user_error("%d:%d got transaction with invalid data ptr\n", 3509 proc->pid, thread->pid); 3510 return_error = BR_FAILED_REPLY; 3511 return_error_param = -EFAULT; 3512 return_error_line = __LINE__; 3513 goto err_copy_data_failed; 3514 } 3515 object_size = binder_get_object(target_proc, user_buffer, 3516 t->buffer, object_offset, &object); 3517 if (object_size == 0 || object_offset < off_min) { 3518 binder_user_error("%d:%d got transaction with invalid offset (%lld, min %lld max %lld) or object.\n", 3519 proc->pid, thread->pid, 3520 (u64)object_offset, 3521 (u64)off_min, 3522 (u64)t->buffer->data_size); 3523 return_error = BR_FAILED_REPLY; 3524 return_error_param = -EINVAL; 3525 return_error_line = __LINE__; 3526 goto err_bad_offset; 3527 } 3528 /* 3529 * Set offset to the next buffer fragment to be 3530 * copied 3531 */ 3532 user_offset = object_offset + object_size; 3533 3534 hdr = &object.hdr; 3535 off_min = object_offset + object_size; 3536 switch (hdr->type) { 3537 case BINDER_TYPE_BINDER: 3538 case BINDER_TYPE_WEAK_BINDER: { 3539 struct flat_binder_object *fp; 3540 3541 fp = to_flat_binder_object(hdr); 3542 ret = binder_translate_binder(fp, t, thread); 3543 3544 if (ret < 0 || 3545 binder_alloc_copy_to_buffer(&target_proc->alloc, 3546 t->buffer, 3547 object_offset, 3548 fp, sizeof(*fp))) { 3549 binder_txn_error("%d:%d translate binder failed\n", 3550 thread->pid, proc->pid); 3551 return_error = BR_FAILED_REPLY; 3552 return_error_param = ret; 3553 return_error_line = __LINE__; 3554 goto err_translate_failed; 3555 } 3556 } break; 3557 case BINDER_TYPE_HANDLE: 3558 case BINDER_TYPE_WEAK_HANDLE: { 3559 struct flat_binder_object *fp; 3560 3561 fp = to_flat_binder_object(hdr); 3562 ret = binder_translate_handle(fp, t, thread); 3563 if (ret < 0 || 3564 binder_alloc_copy_to_buffer(&target_proc->alloc, 3565 t->buffer, 3566 object_offset, 3567 fp, sizeof(*fp))) { 3568 binder_txn_error("%d:%d translate handle failed\n", 3569 thread->pid, proc->pid); 3570 return_error = BR_FAILED_REPLY; 3571 return_error_param = ret; 3572 return_error_line = __LINE__; 3573 goto err_translate_failed; 3574 } 3575 } break; 3576 3577 case BINDER_TYPE_FD: { 3578 struct binder_fd_object *fp = to_binder_fd_object(hdr); 3579 binder_size_t fd_offset = object_offset + 3580 (uintptr_t)&fp->fd - (uintptr_t)fp; 3581 int ret = binder_translate_fd(fp->fd, fd_offset, t, 3582 thread, in_reply_to); 3583 3584 fp->pad_binder = 0; 3585 if (ret < 0 || 3586 binder_alloc_copy_to_buffer(&target_proc->alloc, 3587 t->buffer, 3588 object_offset, 3589 fp, sizeof(*fp))) { 3590 binder_txn_error("%d:%d translate fd failed\n", 3591 thread->pid, proc->pid); 3592 return_error = BR_FAILED_REPLY; 3593 return_error_param = ret; 3594 return_error_line = __LINE__; 3595 goto err_translate_failed; 3596 } 3597 } break; 3598 case BINDER_TYPE_FDA: { 3599 struct binder_object ptr_object; 3600 binder_size_t parent_offset; 3601 struct binder_object user_object; 3602 size_t user_parent_size; 3603 struct binder_fd_array_object *fda = 3604 to_binder_fd_array_object(hdr); 3605 size_t num_valid = (buffer_offset - off_start_offset) / 3606 sizeof(binder_size_t); 3607 struct binder_buffer_object *parent = 3608 binder_validate_ptr(target_proc, t->buffer, 3609 &ptr_object, fda->parent, 3610 off_start_offset, 3611 &parent_offset, 3612 num_valid); 3613 if (!parent) { 3614 binder_user_error("%d:%d got transaction with invalid parent offset or type\n", 3615 proc->pid, thread->pid); 3616 return_error = BR_FAILED_REPLY; 3617 return_error_param = -EINVAL; 3618 return_error_line = __LINE__; 3619 goto err_bad_parent; 3620 } 3621 if (!binder_validate_fixup(target_proc, t->buffer, 3622 off_start_offset, 3623 parent_offset, 3624 fda->parent_offset, 3625 last_fixup_obj_off, 3626 last_fixup_min_off)) { 3627 binder_user_error("%d:%d got transaction with out-of-order buffer fixup\n", 3628 proc->pid, thread->pid); 3629 return_error = BR_FAILED_REPLY; 3630 return_error_param = -EINVAL; 3631 return_error_line = __LINE__; 3632 goto err_bad_parent; 3633 } 3634 /* 3635 * We need to read the user version of the parent 3636 * object to get the original user offset 3637 */ 3638 user_parent_size = 3639 binder_get_object(proc, user_buffer, t->buffer, 3640 parent_offset, &user_object); 3641 if (user_parent_size != sizeof(user_object.bbo)) { 3642 binder_user_error("%d:%d invalid ptr object size: %zd vs %zd\n", 3643 proc->pid, thread->pid, 3644 user_parent_size, 3645 sizeof(user_object.bbo)); 3646 return_error = BR_FAILED_REPLY; 3647 return_error_param = -EINVAL; 3648 return_error_line = __LINE__; 3649 goto err_bad_parent; 3650 } 3651 ret = binder_translate_fd_array(&pf_head, fda, 3652 user_buffer, parent, 3653 &user_object.bbo, t, 3654 thread, in_reply_to); 3655 if (!ret) 3656 ret = binder_alloc_copy_to_buffer(&target_proc->alloc, 3657 t->buffer, 3658 object_offset, 3659 fda, sizeof(*fda)); 3660 if (ret) { 3661 binder_txn_error("%d:%d translate fd array failed\n", 3662 thread->pid, proc->pid); 3663 return_error = BR_FAILED_REPLY; 3664 return_error_param = ret > 0 ? -EINVAL : ret; 3665 return_error_line = __LINE__; 3666 goto err_translate_failed; 3667 } 3668 last_fixup_obj_off = parent_offset; 3669 last_fixup_min_off = 3670 fda->parent_offset + sizeof(u32) * fda->num_fds; 3671 } break; 3672 case BINDER_TYPE_PTR: { 3673 struct binder_buffer_object *bp = 3674 to_binder_buffer_object(hdr); 3675 size_t buf_left = sg_buf_end_offset - sg_buf_offset; 3676 size_t num_valid; 3677 3678 if (bp->length > buf_left) { 3679 binder_user_error("%d:%d got transaction with too large buffer\n", 3680 proc->pid, thread->pid); 3681 return_error = BR_FAILED_REPLY; 3682 return_error_param = -EINVAL; 3683 return_error_line = __LINE__; 3684 goto err_bad_offset; 3685 } 3686 ret = binder_defer_copy(&sgc_head, sg_buf_offset, 3687 (const void __user *)(uintptr_t)bp->buffer, 3688 bp->length); 3689 if (ret) { 3690 binder_txn_error("%d:%d deferred copy failed\n", 3691 thread->pid, proc->pid); 3692 return_error = BR_FAILED_REPLY; 3693 return_error_param = ret; 3694 return_error_line = __LINE__; 3695 goto err_translate_failed; 3696 } 3697 /* Fixup buffer pointer to target proc address space */ 3698 bp->buffer = t->buffer->user_data + sg_buf_offset; 3699 sg_buf_offset += ALIGN(bp->length, sizeof(u64)); 3700 3701 num_valid = (buffer_offset - off_start_offset) / 3702 sizeof(binder_size_t); 3703 ret = binder_fixup_parent(&pf_head, t, 3704 thread, bp, 3705 off_start_offset, 3706 num_valid, 3707 last_fixup_obj_off, 3708 last_fixup_min_off); 3709 if (ret < 0 || 3710 binder_alloc_copy_to_buffer(&target_proc->alloc, 3711 t->buffer, 3712 object_offset, 3713 bp, sizeof(*bp))) { 3714 binder_txn_error("%d:%d failed to fixup parent\n", 3715 thread->pid, proc->pid); 3716 return_error = BR_FAILED_REPLY; 3717 return_error_param = ret; 3718 return_error_line = __LINE__; 3719 goto err_translate_failed; 3720 } 3721 last_fixup_obj_off = object_offset; 3722 last_fixup_min_off = 0; 3723 } break; 3724 default: 3725 binder_user_error("%d:%d got transaction with invalid object type, %x\n", 3726 proc->pid, thread->pid, hdr->type); 3727 return_error = BR_FAILED_REPLY; 3728 return_error_param = -EINVAL; 3729 return_error_line = __LINE__; 3730 goto err_bad_object_type; 3731 } 3732 } 3733 /* Done processing objects, copy the rest of the buffer */ 3734 if (binder_alloc_copy_user_to_buffer( 3735 &target_proc->alloc, 3736 t->buffer, user_offset, 3737 user_buffer + user_offset, 3738 tr->data_size - user_offset)) { 3739 binder_user_error("%d:%d got transaction with invalid data ptr\n", 3740 proc->pid, thread->pid); 3741 return_error = BR_FAILED_REPLY; 3742 return_error_param = -EFAULT; 3743 return_error_line = __LINE__; 3744 goto err_copy_data_failed; 3745 } 3746 3747 ret = binder_do_deferred_txn_copies(&target_proc->alloc, t->buffer, 3748 &sgc_head, &pf_head); 3749 if (ret) { 3750 binder_user_error("%d:%d got transaction with invalid offsets ptr\n", 3751 proc->pid, thread->pid); 3752 return_error = BR_FAILED_REPLY; 3753 return_error_param = ret; 3754 return_error_line = __LINE__; 3755 goto err_copy_data_failed; 3756 } 3757 if (t->buffer->oneway_spam_suspect) { 3758 tcomplete->type = BINDER_WORK_TRANSACTION_ONEWAY_SPAM_SUSPECT; 3759 binder_netlink_report(proc, t, tr->data_size, 3760 BR_ONEWAY_SPAM_SUSPECT); 3761 } else { 3762 tcomplete->type = BINDER_WORK_TRANSACTION_COMPLETE; 3763 } 3764 3765 if (reply) { 3766 binder_enqueue_thread_work(thread, tcomplete); 3767 binder_inner_proc_lock(target_proc); 3768 if (target_thread->is_dead) { 3769 return_error = BR_DEAD_REPLY; 3770 binder_inner_proc_unlock(target_proc); 3771 goto err_dead_proc_or_thread; 3772 } 3773 BUG_ON(t->buffer->async_transaction != 0); 3774 binder_pop_transaction_ilocked(target_thread, in_reply_to); 3775 binder_enqueue_thread_work_ilocked(target_thread, &t->work); 3776 target_proc->outstanding_txns++; 3777 binder_inner_proc_unlock(target_proc); 3778 wake_up_interruptible_sync(&target_thread->wait); 3779 binder_free_transaction(in_reply_to); 3780 } else if (!(t->flags & TF_ONE_WAY)) { 3781 BUG_ON(t->buffer->async_transaction != 0); 3782 binder_inner_proc_lock(proc); 3783 /* 3784 * Defer the TRANSACTION_COMPLETE, so we don't return to 3785 * userspace immediately; this allows the target process to 3786 * immediately start processing this transaction, reducing 3787 * latency. We will then return the TRANSACTION_COMPLETE when 3788 * the target replies (or there is an error). 3789 */ 3790 binder_enqueue_deferred_thread_work_ilocked(thread, tcomplete); 3791 t->from_parent = thread->transaction_stack; 3792 thread->transaction_stack = t; 3793 binder_inner_proc_unlock(proc); 3794 return_error = binder_proc_transaction(t, 3795 target_proc, target_thread); 3796 if (return_error) { 3797 binder_inner_proc_lock(proc); 3798 binder_pop_transaction_ilocked(thread, t); 3799 binder_inner_proc_unlock(proc); 3800 goto err_dead_proc_or_thread; 3801 } 3802 } else { 3803 /* 3804 * Make a transaction copy. It is not safe to access 't' after 3805 * binder_proc_transaction() reported a pending frozen. The 3806 * target could thaw and consume the transaction at any point. 3807 * Instead, use a safe 't_copy' for binder_netlink_report(). 3808 */ 3809 struct binder_transaction t_copy = *t; 3810 3811 BUG_ON(target_node == NULL); 3812 BUG_ON(t->buffer->async_transaction != 1); 3813 return_error = binder_proc_transaction(t, target_proc, NULL); 3814 /* 3815 * Let the caller know when async transaction reaches a frozen 3816 * process and is put in a pending queue, waiting for the target 3817 * process to be unfrozen. 3818 */ 3819 if (return_error == BR_TRANSACTION_PENDING_FROZEN) { 3820 tcomplete->type = BINDER_WORK_TRANSACTION_PENDING; 3821 binder_netlink_report(proc, &t_copy, tr->data_size, 3822 return_error); 3823 } 3824 binder_enqueue_thread_work(thread, tcomplete); 3825 if (return_error && 3826 return_error != BR_TRANSACTION_PENDING_FROZEN) 3827 goto err_dead_proc_or_thread; 3828 } 3829 if (target_thread) 3830 binder_thread_dec_tmpref(target_thread); 3831 binder_proc_dec_tmpref(target_proc); 3832 if (target_node) 3833 binder_dec_node_tmpref(target_node); 3834 /* 3835 * write barrier to synchronize with initialization 3836 * of log entry 3837 */ 3838 smp_wmb(); 3839 WRITE_ONCE(e->debug_id_done, t_debug_id); 3840 return; 3841 3842 err_dead_proc_or_thread: 3843 binder_txn_error("%d:%d %s process or thread\n", 3844 proc->pid, thread->pid, 3845 return_error == BR_FROZEN_REPLY ? "frozen" : "dead"); 3846 return_error_line = __LINE__; 3847 binder_dequeue_work(proc, tcomplete); 3848 err_translate_failed: 3849 err_bad_object_type: 3850 err_bad_offset: 3851 err_bad_parent: 3852 err_copy_data_failed: 3853 binder_cleanup_deferred_txn_lists(&sgc_head, &pf_head); 3854 binder_free_txn_fixups(t); 3855 trace_binder_transaction_failed_buffer_release(t->buffer); 3856 binder_transaction_buffer_release(target_proc, NULL, t->buffer, 3857 buffer_offset, true); 3858 if (target_node) 3859 binder_dec_node_tmpref(target_node); 3860 target_node = NULL; 3861 t->buffer->transaction = NULL; 3862 binder_alloc_free_buf(&target_proc->alloc, t->buffer); 3863 err_binder_alloc_buf_failed: 3864 err_bad_extra_size: 3865 if (lsmctx.context) 3866 security_release_secctx(&lsmctx); 3867 err_get_secctx_failed: 3868 kfree(tcomplete); 3869 binder_stats_deleted(BINDER_STAT_TRANSACTION_COMPLETE); 3870 err_alloc_tcomplete_failed: 3871 if (trace_binder_txn_latency_free_enabled()) 3872 binder_txn_latency_free(t); 3873 err_bad_todo_list: 3874 err_bad_call_stack: 3875 err_empty_call_stack: 3876 err_dead_binder: 3877 err_invalid_target_handle: 3878 if (target_node) { 3879 binder_dec_node(target_node, 1, 0); 3880 binder_dec_node_tmpref(target_node); 3881 } 3882 3883 binder_netlink_report(proc, t, tr->data_size, return_error); 3884 kfree(t); 3885 binder_stats_deleted(BINDER_STAT_TRANSACTION); 3886 err_alloc_t_failed: 3887 3888 binder_debug(BINDER_DEBUG_FAILED_TRANSACTION, 3889 "%d:%d transaction %s to %d:%d failed %d/%d/%d, code %u size %lld-%lld line %d\n", 3890 proc->pid, thread->pid, reply ? "reply" : 3891 (tr->flags & TF_ONE_WAY ? "async" : "call"), 3892 target_proc ? target_proc->pid : 0, 3893 target_thread ? target_thread->pid : 0, 3894 t_debug_id, return_error, return_error_param, 3895 tr->code, (u64)tr->data_size, (u64)tr->offsets_size, 3896 return_error_line); 3897 3898 if (target_thread) 3899 binder_thread_dec_tmpref(target_thread); 3900 if (target_proc) 3901 binder_proc_dec_tmpref(target_proc); 3902 3903 { 3904 struct binder_transaction_log_entry *fe; 3905 3906 e->return_error = return_error; 3907 e->return_error_param = return_error_param; 3908 e->return_error_line = return_error_line; 3909 fe = binder_transaction_log_add(&binder_transaction_log_failed); 3910 *fe = *e; 3911 /* 3912 * write barrier to synchronize with initialization 3913 * of log entry 3914 */ 3915 smp_wmb(); 3916 WRITE_ONCE(e->debug_id_done, t_debug_id); 3917 WRITE_ONCE(fe->debug_id_done, t_debug_id); 3918 } 3919 3920 BUG_ON(thread->return_error.cmd != BR_OK); 3921 if (in_reply_to) { 3922 binder_set_txn_from_error(in_reply_to, t_debug_id, 3923 return_error, return_error_param); 3924 thread->return_error.cmd = BR_TRANSACTION_COMPLETE; 3925 binder_enqueue_thread_work(thread, &thread->return_error.work); 3926 binder_send_failed_reply(in_reply_to, return_error); 3927 } else { 3928 binder_inner_proc_lock(proc); 3929 binder_set_extended_error(&thread->ee, t_debug_id, 3930 return_error, return_error_param); 3931 binder_inner_proc_unlock(proc); 3932 thread->return_error.cmd = return_error; 3933 binder_enqueue_thread_work(thread, &thread->return_error.work); 3934 } 3935 } 3936 3937 static int 3938 binder_request_freeze_notification(struct binder_proc *proc, 3939 struct binder_thread *thread, 3940 struct binder_handle_cookie *handle_cookie) 3941 { 3942 struct binder_ref_freeze *freeze; 3943 struct binder_ref *ref; 3944 3945 freeze = kzalloc_obj(*freeze); 3946 if (!freeze) 3947 return -ENOMEM; 3948 binder_proc_lock(proc); 3949 ref = binder_get_ref_olocked(proc, handle_cookie->handle, false); 3950 if (!ref) { 3951 binder_user_error("%d:%d BC_REQUEST_FREEZE_NOTIFICATION invalid ref %d\n", 3952 proc->pid, thread->pid, handle_cookie->handle); 3953 binder_proc_unlock(proc); 3954 kfree(freeze); 3955 return -EINVAL; 3956 } 3957 3958 binder_node_lock(ref->node); 3959 if (ref->freeze) { 3960 binder_user_error("%d:%d BC_REQUEST_FREEZE_NOTIFICATION already set\n", 3961 proc->pid, thread->pid); 3962 binder_node_unlock(ref->node); 3963 binder_proc_unlock(proc); 3964 kfree(freeze); 3965 return -EINVAL; 3966 } 3967 3968 binder_stats_created(BINDER_STAT_FREEZE); 3969 INIT_LIST_HEAD(&freeze->work.entry); 3970 freeze->cookie = handle_cookie->cookie; 3971 freeze->work.type = BINDER_WORK_FROZEN_BINDER; 3972 ref->freeze = freeze; 3973 3974 if (ref->node->proc) { 3975 binder_inner_proc_lock(ref->node->proc); 3976 freeze->is_frozen = ref->node->proc->is_frozen; 3977 binder_inner_proc_unlock(ref->node->proc); 3978 3979 binder_inner_proc_lock(proc); 3980 binder_enqueue_work_ilocked(&freeze->work, &proc->todo); 3981 binder_wakeup_proc_ilocked(proc); 3982 binder_inner_proc_unlock(proc); 3983 } 3984 3985 binder_node_unlock(ref->node); 3986 binder_proc_unlock(proc); 3987 return 0; 3988 } 3989 3990 static int 3991 binder_clear_freeze_notification(struct binder_proc *proc, 3992 struct binder_thread *thread, 3993 struct binder_handle_cookie *handle_cookie) 3994 { 3995 struct binder_ref_freeze *freeze; 3996 struct binder_ref *ref; 3997 3998 binder_proc_lock(proc); 3999 ref = binder_get_ref_olocked(proc, handle_cookie->handle, false); 4000 if (!ref) { 4001 binder_user_error("%d:%d BC_CLEAR_FREEZE_NOTIFICATION invalid ref %d\n", 4002 proc->pid, thread->pid, handle_cookie->handle); 4003 binder_proc_unlock(proc); 4004 return -EINVAL; 4005 } 4006 4007 binder_node_lock(ref->node); 4008 4009 if (!ref->freeze) { 4010 binder_user_error("%d:%d BC_CLEAR_FREEZE_NOTIFICATION freeze notification not active\n", 4011 proc->pid, thread->pid); 4012 binder_node_unlock(ref->node); 4013 binder_proc_unlock(proc); 4014 return -EINVAL; 4015 } 4016 freeze = ref->freeze; 4017 binder_inner_proc_lock(proc); 4018 if (freeze->cookie != handle_cookie->cookie) { 4019 binder_user_error("%d:%d BC_CLEAR_FREEZE_NOTIFICATION freeze notification cookie mismatch %016llx != %016llx\n", 4020 proc->pid, thread->pid, (u64)freeze->cookie, 4021 (u64)handle_cookie->cookie); 4022 binder_inner_proc_unlock(proc); 4023 binder_node_unlock(ref->node); 4024 binder_proc_unlock(proc); 4025 return -EINVAL; 4026 } 4027 ref->freeze = NULL; 4028 /* 4029 * Take the existing freeze object and overwrite its work type. There are three cases here: 4030 * 1. No pending notification. In this case just add the work to the queue. 4031 * 2. A notification was sent and is pending an ack from userspace. Once an ack arrives, we 4032 * should resend with the new work type. 4033 * 3. A notification is pending to be sent. Since the work is already in the queue, nothing 4034 * needs to be done here. 4035 */ 4036 freeze->work.type = BINDER_WORK_CLEAR_FREEZE_NOTIFICATION; 4037 if (list_empty(&freeze->work.entry)) { 4038 binder_enqueue_work_ilocked(&freeze->work, &proc->todo); 4039 binder_wakeup_proc_ilocked(proc); 4040 } else if (freeze->sent) { 4041 freeze->resend = true; 4042 } 4043 binder_inner_proc_unlock(proc); 4044 binder_node_unlock(ref->node); 4045 binder_proc_unlock(proc); 4046 return 0; 4047 } 4048 4049 static int 4050 binder_freeze_notification_done(struct binder_proc *proc, 4051 struct binder_thread *thread, 4052 binder_uintptr_t cookie) 4053 { 4054 struct binder_ref_freeze *freeze = NULL; 4055 struct binder_work *w; 4056 4057 binder_inner_proc_lock(proc); 4058 list_for_each_entry(w, &proc->delivered_freeze, entry) { 4059 struct binder_ref_freeze *tmp_freeze = 4060 container_of(w, struct binder_ref_freeze, work); 4061 4062 if (tmp_freeze->cookie == cookie) { 4063 freeze = tmp_freeze; 4064 break; 4065 } 4066 } 4067 if (!freeze) { 4068 binder_user_error("%d:%d BC_FREEZE_NOTIFICATION_DONE %016llx not found\n", 4069 proc->pid, thread->pid, (u64)cookie); 4070 binder_inner_proc_unlock(proc); 4071 return -EINVAL; 4072 } 4073 binder_dequeue_work_ilocked(&freeze->work); 4074 freeze->sent = false; 4075 if (freeze->resend) { 4076 freeze->resend = false; 4077 binder_enqueue_work_ilocked(&freeze->work, &proc->todo); 4078 binder_wakeup_proc_ilocked(proc); 4079 } 4080 binder_inner_proc_unlock(proc); 4081 return 0; 4082 } 4083 4084 /** 4085 * binder_free_buf() - free the specified buffer 4086 * @proc: binder proc that owns buffer 4087 * @thread: binder thread performing the buffer release 4088 * @buffer: buffer to be freed 4089 * @is_failure: failed to send transaction 4090 * 4091 * If the buffer is for an async transaction, enqueue the next async 4092 * transaction from the node. 4093 * 4094 * Cleanup the buffer and free it. 4095 */ 4096 static void 4097 binder_free_buf(struct binder_proc *proc, 4098 struct binder_thread *thread, 4099 struct binder_buffer *buffer, bool is_failure) 4100 { 4101 binder_inner_proc_lock(proc); 4102 if (buffer->transaction) { 4103 buffer->transaction->buffer = NULL; 4104 buffer->transaction = NULL; 4105 } 4106 binder_inner_proc_unlock(proc); 4107 if (buffer->async_transaction && buffer->target_node) { 4108 struct binder_node *buf_node; 4109 struct binder_work *w; 4110 4111 buf_node = buffer->target_node; 4112 binder_node_inner_lock(buf_node); 4113 BUG_ON(!buf_node->has_async_transaction); 4114 BUG_ON(buf_node->proc != proc); 4115 w = binder_dequeue_work_head_ilocked( 4116 &buf_node->async_todo); 4117 if (!w) { 4118 buf_node->has_async_transaction = false; 4119 } else { 4120 binder_enqueue_work_ilocked( 4121 w, &proc->todo); 4122 binder_wakeup_proc_ilocked(proc); 4123 } 4124 binder_node_inner_unlock(buf_node); 4125 } 4126 trace_binder_transaction_buffer_release(buffer); 4127 binder_release_entire_buffer(proc, thread, buffer, is_failure); 4128 binder_alloc_free_buf(&proc->alloc, buffer); 4129 } 4130 4131 static int binder_thread_write(struct binder_proc *proc, 4132 struct binder_thread *thread, 4133 binder_uintptr_t binder_buffer, size_t size, 4134 binder_size_t *consumed) 4135 { 4136 uint32_t cmd; 4137 struct binder_context *context = proc->context; 4138 void __user *buffer = (void __user *)(uintptr_t)binder_buffer; 4139 void __user *ptr = buffer + *consumed; 4140 void __user *end = buffer + size; 4141 4142 while (ptr < end && thread->return_error.cmd == BR_OK) { 4143 int ret; 4144 4145 if (get_user(cmd, (uint32_t __user *)ptr)) 4146 return -EFAULT; 4147 ptr += sizeof(uint32_t); 4148 trace_binder_command(cmd); 4149 if (_IOC_NR(cmd) < ARRAY_SIZE(binder_stats.bc)) { 4150 atomic_inc(&binder_stats.bc[_IOC_NR(cmd)]); 4151 atomic_inc(&proc->stats.bc[_IOC_NR(cmd)]); 4152 atomic_inc(&thread->stats.bc[_IOC_NR(cmd)]); 4153 } 4154 switch (cmd) { 4155 case BC_INCREFS: 4156 case BC_ACQUIRE: 4157 case BC_RELEASE: 4158 case BC_DECREFS: { 4159 uint32_t target; 4160 const char *debug_string; 4161 bool strong = cmd == BC_ACQUIRE || cmd == BC_RELEASE; 4162 bool increment = cmd == BC_INCREFS || cmd == BC_ACQUIRE; 4163 struct binder_ref_data rdata; 4164 4165 if (get_user(target, (uint32_t __user *)ptr)) 4166 return -EFAULT; 4167 4168 ptr += sizeof(uint32_t); 4169 ret = -1; 4170 if (increment && !target) { 4171 struct binder_node *ctx_mgr_node; 4172 4173 mutex_lock(&context->context_mgr_node_lock); 4174 ctx_mgr_node = context->binder_context_mgr_node; 4175 if (ctx_mgr_node) { 4176 if (ctx_mgr_node->proc == proc) { 4177 binder_user_error("%d:%d context manager tried to acquire desc 0\n", 4178 proc->pid, thread->pid); 4179 mutex_unlock(&context->context_mgr_node_lock); 4180 return -EINVAL; 4181 } 4182 ret = binder_inc_ref_for_node( 4183 proc, ctx_mgr_node, 4184 strong, NULL, &rdata); 4185 } 4186 mutex_unlock(&context->context_mgr_node_lock); 4187 } 4188 if (ret) 4189 ret = binder_update_ref_for_handle( 4190 proc, target, increment, strong, 4191 &rdata); 4192 if (!ret && rdata.desc != target) { 4193 binder_user_error("%d:%d tried to acquire reference to desc %d, got %d instead\n", 4194 proc->pid, thread->pid, 4195 target, rdata.desc); 4196 } 4197 switch (cmd) { 4198 case BC_INCREFS: 4199 debug_string = "IncRefs"; 4200 break; 4201 case BC_ACQUIRE: 4202 debug_string = "Acquire"; 4203 break; 4204 case BC_RELEASE: 4205 debug_string = "Release"; 4206 break; 4207 case BC_DECREFS: 4208 default: 4209 debug_string = "DecRefs"; 4210 break; 4211 } 4212 if (ret) { 4213 binder_user_error("%d:%d %s %d refcount change on invalid ref %d ret %d\n", 4214 proc->pid, thread->pid, debug_string, 4215 strong, target, ret); 4216 break; 4217 } 4218 binder_debug(BINDER_DEBUG_USER_REFS, 4219 "%d:%d %s ref %d desc %d s %d w %d\n", 4220 proc->pid, thread->pid, debug_string, 4221 rdata.debug_id, rdata.desc, rdata.strong, 4222 rdata.weak); 4223 break; 4224 } 4225 case BC_INCREFS_DONE: 4226 case BC_ACQUIRE_DONE: { 4227 binder_uintptr_t node_ptr; 4228 binder_uintptr_t cookie; 4229 struct binder_node *node; 4230 bool free_node; 4231 4232 if (get_user(node_ptr, (binder_uintptr_t __user *)ptr)) 4233 return -EFAULT; 4234 ptr += sizeof(binder_uintptr_t); 4235 if (get_user(cookie, (binder_uintptr_t __user *)ptr)) 4236 return -EFAULT; 4237 ptr += sizeof(binder_uintptr_t); 4238 node = binder_get_node(proc, node_ptr); 4239 if (node == NULL) { 4240 binder_user_error("%d:%d %s u%016llx no match\n", 4241 proc->pid, thread->pid, 4242 cmd == BC_INCREFS_DONE ? 4243 "BC_INCREFS_DONE" : 4244 "BC_ACQUIRE_DONE", 4245 (u64)node_ptr); 4246 break; 4247 } 4248 if (cookie != node->cookie) { 4249 binder_user_error("%d:%d %s u%016llx node %d cookie mismatch %016llx != %016llx\n", 4250 proc->pid, thread->pid, 4251 cmd == BC_INCREFS_DONE ? 4252 "BC_INCREFS_DONE" : "BC_ACQUIRE_DONE", 4253 (u64)node_ptr, node->debug_id, 4254 (u64)cookie, (u64)node->cookie); 4255 binder_put_node(node); 4256 break; 4257 } 4258 binder_node_inner_lock(node); 4259 if (cmd == BC_ACQUIRE_DONE) { 4260 if (node->pending_strong_ref == 0) { 4261 binder_user_error("%d:%d BC_ACQUIRE_DONE node %d has no pending acquire request\n", 4262 proc->pid, thread->pid, 4263 node->debug_id); 4264 binder_node_inner_unlock(node); 4265 binder_put_node(node); 4266 break; 4267 } 4268 node->pending_strong_ref = 0; 4269 } else { 4270 if (node->pending_weak_ref == 0) { 4271 binder_user_error("%d:%d BC_INCREFS_DONE node %d has no pending increfs request\n", 4272 proc->pid, thread->pid, 4273 node->debug_id); 4274 binder_node_inner_unlock(node); 4275 binder_put_node(node); 4276 break; 4277 } 4278 node->pending_weak_ref = 0; 4279 } 4280 free_node = binder_dec_node_nilocked(node, 4281 cmd == BC_ACQUIRE_DONE, 0); 4282 WARN_ON(free_node); 4283 binder_debug(BINDER_DEBUG_USER_REFS, 4284 "%d:%d %s node %d ls %d lw %d tr %d\n", 4285 proc->pid, thread->pid, 4286 cmd == BC_INCREFS_DONE ? "BC_INCREFS_DONE" : "BC_ACQUIRE_DONE", 4287 node->debug_id, node->local_strong_refs, 4288 node->local_weak_refs, node->tmp_refs); 4289 binder_node_inner_unlock(node); 4290 binder_put_node(node); 4291 break; 4292 } 4293 case BC_ATTEMPT_ACQUIRE: 4294 pr_err("BC_ATTEMPT_ACQUIRE not supported\n"); 4295 return -EINVAL; 4296 case BC_ACQUIRE_RESULT: 4297 pr_err("BC_ACQUIRE_RESULT not supported\n"); 4298 return -EINVAL; 4299 4300 case BC_FREE_BUFFER: { 4301 binder_uintptr_t data_ptr; 4302 struct binder_buffer *buffer; 4303 4304 if (get_user(data_ptr, (binder_uintptr_t __user *)ptr)) 4305 return -EFAULT; 4306 ptr += sizeof(binder_uintptr_t); 4307 4308 buffer = binder_alloc_prepare_to_free(&proc->alloc, 4309 data_ptr); 4310 if (IS_ERR_OR_NULL(buffer)) { 4311 if (PTR_ERR(buffer) == -EPERM) { 4312 binder_user_error( 4313 "%d:%d BC_FREE_BUFFER matched unreturned or currently freeing buffer at offset %lx\n", 4314 proc->pid, thread->pid, 4315 (unsigned long)data_ptr - proc->alloc.vm_start); 4316 } else { 4317 binder_user_error( 4318 "%d:%d BC_FREE_BUFFER no match for buffer at offset %lx\n", 4319 proc->pid, thread->pid, 4320 (unsigned long)data_ptr - proc->alloc.vm_start); 4321 } 4322 break; 4323 } 4324 binder_debug(BINDER_DEBUG_FREE_BUFFER, 4325 "%d:%d BC_FREE_BUFFER at offset %lx found buffer %d for %s transaction\n", 4326 proc->pid, thread->pid, 4327 (unsigned long)data_ptr - proc->alloc.vm_start, 4328 buffer->debug_id, 4329 buffer->transaction ? "active" : "finished"); 4330 binder_free_buf(proc, thread, buffer, false); 4331 break; 4332 } 4333 4334 case BC_TRANSACTION_SG: 4335 case BC_REPLY_SG: { 4336 struct binder_transaction_data_sg tr; 4337 4338 if (copy_from_user(&tr, ptr, sizeof(tr))) 4339 return -EFAULT; 4340 ptr += sizeof(tr); 4341 binder_transaction(proc, thread, &tr.transaction_data, 4342 cmd == BC_REPLY_SG, tr.buffers_size); 4343 break; 4344 } 4345 case BC_TRANSACTION: 4346 case BC_REPLY: { 4347 struct binder_transaction_data tr; 4348 4349 if (copy_from_user(&tr, ptr, sizeof(tr))) 4350 return -EFAULT; 4351 ptr += sizeof(tr); 4352 binder_transaction(proc, thread, &tr, 4353 cmd == BC_REPLY, 0); 4354 break; 4355 } 4356 4357 case BC_REGISTER_LOOPER: 4358 binder_debug(BINDER_DEBUG_THREADS, 4359 "%d:%d BC_REGISTER_LOOPER\n", 4360 proc->pid, thread->pid); 4361 binder_inner_proc_lock(proc); 4362 if (thread->looper & BINDER_LOOPER_STATE_ENTERED) { 4363 thread->looper |= BINDER_LOOPER_STATE_INVALID; 4364 binder_user_error("%d:%d ERROR: BC_REGISTER_LOOPER called after BC_ENTER_LOOPER\n", 4365 proc->pid, thread->pid); 4366 } else if (proc->requested_threads == 0) { 4367 thread->looper |= BINDER_LOOPER_STATE_INVALID; 4368 binder_user_error("%d:%d ERROR: BC_REGISTER_LOOPER called without request\n", 4369 proc->pid, thread->pid); 4370 } else { 4371 proc->requested_threads--; 4372 proc->requested_threads_started++; 4373 } 4374 thread->looper |= BINDER_LOOPER_STATE_REGISTERED; 4375 binder_inner_proc_unlock(proc); 4376 break; 4377 case BC_ENTER_LOOPER: 4378 binder_debug(BINDER_DEBUG_THREADS, 4379 "%d:%d BC_ENTER_LOOPER\n", 4380 proc->pid, thread->pid); 4381 if (thread->looper & BINDER_LOOPER_STATE_REGISTERED) { 4382 thread->looper |= BINDER_LOOPER_STATE_INVALID; 4383 binder_user_error("%d:%d ERROR: BC_ENTER_LOOPER called after BC_REGISTER_LOOPER\n", 4384 proc->pid, thread->pid); 4385 } 4386 thread->looper |= BINDER_LOOPER_STATE_ENTERED; 4387 break; 4388 case BC_EXIT_LOOPER: 4389 binder_debug(BINDER_DEBUG_THREADS, 4390 "%d:%d BC_EXIT_LOOPER\n", 4391 proc->pid, thread->pid); 4392 thread->looper |= BINDER_LOOPER_STATE_EXITED; 4393 break; 4394 4395 case BC_REQUEST_DEATH_NOTIFICATION: 4396 case BC_CLEAR_DEATH_NOTIFICATION: { 4397 uint32_t target; 4398 binder_uintptr_t cookie; 4399 struct binder_ref *ref; 4400 struct binder_ref_death *death = NULL; 4401 4402 if (get_user(target, (uint32_t __user *)ptr)) 4403 return -EFAULT; 4404 ptr += sizeof(uint32_t); 4405 if (get_user(cookie, (binder_uintptr_t __user *)ptr)) 4406 return -EFAULT; 4407 ptr += sizeof(binder_uintptr_t); 4408 if (cmd == BC_REQUEST_DEATH_NOTIFICATION) { 4409 /* 4410 * Allocate memory for death notification 4411 * before taking lock 4412 */ 4413 death = kzalloc_obj(*death); 4414 if (death == NULL) { 4415 WARN_ON(thread->return_error.cmd != 4416 BR_OK); 4417 thread->return_error.cmd = BR_ERROR; 4418 binder_enqueue_thread_work( 4419 thread, 4420 &thread->return_error.work); 4421 binder_debug( 4422 BINDER_DEBUG_FAILED_TRANSACTION, 4423 "%d:%d BC_REQUEST_DEATH_NOTIFICATION failed\n", 4424 proc->pid, thread->pid); 4425 break; 4426 } 4427 } 4428 binder_proc_lock(proc); 4429 ref = binder_get_ref_olocked(proc, target, false); 4430 if (ref == NULL) { 4431 binder_user_error("%d:%d %s invalid ref %d\n", 4432 proc->pid, thread->pid, 4433 cmd == BC_REQUEST_DEATH_NOTIFICATION ? 4434 "BC_REQUEST_DEATH_NOTIFICATION" : 4435 "BC_CLEAR_DEATH_NOTIFICATION", 4436 target); 4437 binder_proc_unlock(proc); 4438 kfree(death); 4439 break; 4440 } 4441 4442 binder_debug(BINDER_DEBUG_DEATH_NOTIFICATION, 4443 "%d:%d %s %016llx ref %d desc %d s %d w %d for node %d\n", 4444 proc->pid, thread->pid, 4445 cmd == BC_REQUEST_DEATH_NOTIFICATION ? 4446 "BC_REQUEST_DEATH_NOTIFICATION" : 4447 "BC_CLEAR_DEATH_NOTIFICATION", 4448 (u64)cookie, ref->data.debug_id, 4449 ref->data.desc, ref->data.strong, 4450 ref->data.weak, ref->node->debug_id); 4451 4452 binder_node_lock(ref->node); 4453 if (cmd == BC_REQUEST_DEATH_NOTIFICATION) { 4454 if (ref->death) { 4455 binder_user_error("%d:%d BC_REQUEST_DEATH_NOTIFICATION death notification already set\n", 4456 proc->pid, thread->pid); 4457 binder_node_unlock(ref->node); 4458 binder_proc_unlock(proc); 4459 kfree(death); 4460 break; 4461 } 4462 binder_stats_created(BINDER_STAT_DEATH); 4463 INIT_LIST_HEAD(&death->work.entry); 4464 death->cookie = cookie; 4465 ref->death = death; 4466 if (ref->node->proc == NULL) { 4467 ref->death->work.type = BINDER_WORK_DEAD_BINDER; 4468 4469 binder_inner_proc_lock(proc); 4470 binder_enqueue_work_ilocked( 4471 &ref->death->work, &proc->todo); 4472 binder_wakeup_proc_ilocked(proc); 4473 binder_inner_proc_unlock(proc); 4474 } 4475 } else { 4476 if (ref->death == NULL) { 4477 binder_user_error("%d:%d BC_CLEAR_DEATH_NOTIFICATION death notification not active\n", 4478 proc->pid, thread->pid); 4479 binder_node_unlock(ref->node); 4480 binder_proc_unlock(proc); 4481 break; 4482 } 4483 death = ref->death; 4484 if (death->cookie != cookie) { 4485 binder_user_error("%d:%d BC_CLEAR_DEATH_NOTIFICATION death notification cookie mismatch %016llx != %016llx\n", 4486 proc->pid, thread->pid, 4487 (u64)death->cookie, 4488 (u64)cookie); 4489 binder_node_unlock(ref->node); 4490 binder_proc_unlock(proc); 4491 break; 4492 } 4493 ref->death = NULL; 4494 binder_inner_proc_lock(proc); 4495 if (list_empty(&death->work.entry)) { 4496 death->work.type = BINDER_WORK_CLEAR_DEATH_NOTIFICATION; 4497 if (thread->looper & 4498 (BINDER_LOOPER_STATE_REGISTERED | 4499 BINDER_LOOPER_STATE_ENTERED)) 4500 binder_enqueue_thread_work_ilocked( 4501 thread, 4502 &death->work); 4503 else { 4504 binder_enqueue_work_ilocked( 4505 &death->work, 4506 &proc->todo); 4507 binder_wakeup_proc_ilocked( 4508 proc); 4509 } 4510 } else { 4511 BUG_ON(death->work.type != BINDER_WORK_DEAD_BINDER); 4512 death->work.type = BINDER_WORK_DEAD_BINDER_AND_CLEAR; 4513 } 4514 binder_inner_proc_unlock(proc); 4515 } 4516 binder_node_unlock(ref->node); 4517 binder_proc_unlock(proc); 4518 } break; 4519 case BC_DEAD_BINDER_DONE: { 4520 struct binder_work *w; 4521 binder_uintptr_t cookie; 4522 struct binder_ref_death *death = NULL; 4523 4524 if (get_user(cookie, (binder_uintptr_t __user *)ptr)) 4525 return -EFAULT; 4526 4527 ptr += sizeof(cookie); 4528 binder_inner_proc_lock(proc); 4529 list_for_each_entry(w, &proc->delivered_death, 4530 entry) { 4531 struct binder_ref_death *tmp_death = 4532 container_of(w, 4533 struct binder_ref_death, 4534 work); 4535 4536 if (tmp_death->cookie == cookie) { 4537 death = tmp_death; 4538 break; 4539 } 4540 } 4541 binder_debug(BINDER_DEBUG_DEAD_BINDER, 4542 "%d:%d BC_DEAD_BINDER_DONE %016llx found %p\n", 4543 proc->pid, thread->pid, (u64)cookie, 4544 death); 4545 if (death == NULL) { 4546 binder_user_error("%d:%d BC_DEAD_BINDER_DONE %016llx not found\n", 4547 proc->pid, thread->pid, (u64)cookie); 4548 binder_inner_proc_unlock(proc); 4549 break; 4550 } 4551 binder_dequeue_work_ilocked(&death->work); 4552 if (death->work.type == BINDER_WORK_DEAD_BINDER_AND_CLEAR) { 4553 death->work.type = BINDER_WORK_CLEAR_DEATH_NOTIFICATION; 4554 if (thread->looper & 4555 (BINDER_LOOPER_STATE_REGISTERED | 4556 BINDER_LOOPER_STATE_ENTERED)) 4557 binder_enqueue_thread_work_ilocked( 4558 thread, &death->work); 4559 else { 4560 binder_enqueue_work_ilocked( 4561 &death->work, 4562 &proc->todo); 4563 binder_wakeup_proc_ilocked(proc); 4564 } 4565 } 4566 binder_inner_proc_unlock(proc); 4567 } break; 4568 4569 case BC_REQUEST_FREEZE_NOTIFICATION: { 4570 struct binder_handle_cookie handle_cookie; 4571 int error; 4572 4573 if (copy_from_user(&handle_cookie, ptr, sizeof(handle_cookie))) 4574 return -EFAULT; 4575 ptr += sizeof(handle_cookie); 4576 error = binder_request_freeze_notification(proc, thread, 4577 &handle_cookie); 4578 if (error) 4579 return error; 4580 } break; 4581 4582 case BC_CLEAR_FREEZE_NOTIFICATION: { 4583 struct binder_handle_cookie handle_cookie; 4584 int error; 4585 4586 if (copy_from_user(&handle_cookie, ptr, sizeof(handle_cookie))) 4587 return -EFAULT; 4588 ptr += sizeof(handle_cookie); 4589 error = binder_clear_freeze_notification(proc, thread, &handle_cookie); 4590 if (error) 4591 return error; 4592 } break; 4593 4594 case BC_FREEZE_NOTIFICATION_DONE: { 4595 binder_uintptr_t cookie; 4596 int error; 4597 4598 if (get_user(cookie, (binder_uintptr_t __user *)ptr)) 4599 return -EFAULT; 4600 4601 ptr += sizeof(cookie); 4602 error = binder_freeze_notification_done(proc, thread, cookie); 4603 if (error) 4604 return error; 4605 } break; 4606 4607 default: 4608 pr_err("%d:%d unknown command %u\n", 4609 proc->pid, thread->pid, cmd); 4610 return -EINVAL; 4611 } 4612 *consumed = ptr - buffer; 4613 } 4614 return 0; 4615 } 4616 4617 static void binder_stat_br(struct binder_proc *proc, 4618 struct binder_thread *thread, uint32_t cmd) 4619 { 4620 trace_binder_return(cmd); 4621 if (_IOC_NR(cmd) < ARRAY_SIZE(binder_stats.br)) { 4622 atomic_inc(&binder_stats.br[_IOC_NR(cmd)]); 4623 atomic_inc(&proc->stats.br[_IOC_NR(cmd)]); 4624 atomic_inc(&thread->stats.br[_IOC_NR(cmd)]); 4625 } 4626 } 4627 4628 static int binder_put_node_cmd(struct binder_proc *proc, 4629 struct binder_thread *thread, 4630 void __user **ptrp, 4631 binder_uintptr_t node_ptr, 4632 binder_uintptr_t node_cookie, 4633 int node_debug_id, 4634 uint32_t cmd, const char *cmd_name) 4635 { 4636 void __user *ptr = *ptrp; 4637 4638 if (put_user(cmd, (uint32_t __user *)ptr)) 4639 return -EFAULT; 4640 ptr += sizeof(uint32_t); 4641 4642 if (put_user(node_ptr, (binder_uintptr_t __user *)ptr)) 4643 return -EFAULT; 4644 ptr += sizeof(binder_uintptr_t); 4645 4646 if (put_user(node_cookie, (binder_uintptr_t __user *)ptr)) 4647 return -EFAULT; 4648 ptr += sizeof(binder_uintptr_t); 4649 4650 binder_stat_br(proc, thread, cmd); 4651 binder_debug(BINDER_DEBUG_USER_REFS, "%d:%d %s %d u%016llx c%016llx\n", 4652 proc->pid, thread->pid, cmd_name, node_debug_id, 4653 (u64)node_ptr, (u64)node_cookie); 4654 4655 *ptrp = ptr; 4656 return 0; 4657 } 4658 4659 static int binder_wait_for_work(struct binder_thread *thread, 4660 bool do_proc_work) 4661 { 4662 DEFINE_WAIT(wait); 4663 struct binder_proc *proc = thread->proc; 4664 int ret = 0; 4665 4666 binder_inner_proc_lock(proc); 4667 for (;;) { 4668 prepare_to_wait(&thread->wait, &wait, TASK_INTERRUPTIBLE|TASK_FREEZABLE); 4669 if (binder_has_work_ilocked(thread, do_proc_work)) 4670 break; 4671 if (do_proc_work) 4672 list_add(&thread->waiting_thread_node, 4673 &proc->waiting_threads); 4674 binder_inner_proc_unlock(proc); 4675 schedule(); 4676 binder_inner_proc_lock(proc); 4677 list_del_init(&thread->waiting_thread_node); 4678 if (signal_pending(current)) { 4679 ret = -EINTR; 4680 break; 4681 } 4682 } 4683 finish_wait(&thread->wait, &wait); 4684 binder_inner_proc_unlock(proc); 4685 4686 return ret; 4687 } 4688 4689 /** 4690 * binder_apply_fd_fixups() - finish fd translation 4691 * @proc: binder_proc associated @t->buffer 4692 * @t: binder transaction with list of fd fixups 4693 * 4694 * Now that we are in the context of the transaction target 4695 * process, we can allocate and install fds. Process the 4696 * list of fds to translate and fixup the buffer with the 4697 * new fds first and only then install the files. 4698 * 4699 * If we fail to allocate an fd, skip the install and release 4700 * any fds that have already been allocated. 4701 * 4702 * Return: 0 on success, a negative errno code on failure. 4703 */ 4704 static int binder_apply_fd_fixups(struct binder_proc *proc, 4705 struct binder_transaction *t) 4706 { 4707 struct binder_txn_fd_fixup *fixup, *tmp; 4708 int ret = 0; 4709 4710 list_for_each_entry(fixup, &t->fd_fixups, fixup_entry) { 4711 int fd = get_unused_fd_flags(O_CLOEXEC); 4712 4713 if (fd < 0) { 4714 binder_debug(BINDER_DEBUG_TRANSACTION, 4715 "failed fd fixup txn %d fd %d\n", 4716 t->debug_id, fd); 4717 ret = -ENOMEM; 4718 goto err; 4719 } 4720 binder_debug(BINDER_DEBUG_TRANSACTION, 4721 "fd fixup txn %d fd %d\n", 4722 t->debug_id, fd); 4723 trace_binder_transaction_fd_recv(t, fd, fixup->offset); 4724 fixup->target_fd = fd; 4725 if (binder_alloc_copy_to_buffer(&proc->alloc, t->buffer, 4726 fixup->offset, &fd, 4727 sizeof(u32))) { 4728 ret = -EINVAL; 4729 goto err; 4730 } 4731 } 4732 list_for_each_entry_safe(fixup, tmp, &t->fd_fixups, fixup_entry) { 4733 fd_install(fixup->target_fd, fixup->file); 4734 list_del(&fixup->fixup_entry); 4735 kfree(fixup); 4736 } 4737 4738 return ret; 4739 4740 err: 4741 binder_free_txn_fixups(t); 4742 return ret; 4743 } 4744 4745 static int binder_thread_read(struct binder_proc *proc, 4746 struct binder_thread *thread, 4747 binder_uintptr_t binder_buffer, size_t size, 4748 binder_size_t *consumed, int non_block) 4749 { 4750 void __user *buffer = (void __user *)(uintptr_t)binder_buffer; 4751 void __user *ptr = buffer + *consumed; 4752 void __user *end = buffer + size; 4753 4754 int ret = 0; 4755 int wait_for_proc_work; 4756 4757 if (*consumed == 0) { 4758 if (put_user(BR_NOOP, (uint32_t __user *)ptr)) 4759 return -EFAULT; 4760 ptr += sizeof(uint32_t); 4761 } 4762 4763 retry: 4764 binder_inner_proc_lock(proc); 4765 wait_for_proc_work = binder_available_for_proc_work_ilocked(thread); 4766 binder_inner_proc_unlock(proc); 4767 4768 thread->looper |= BINDER_LOOPER_STATE_WAITING; 4769 4770 trace_binder_wait_for_work(wait_for_proc_work, 4771 !!thread->transaction_stack, 4772 !binder_worklist_empty(proc, &thread->todo)); 4773 if (wait_for_proc_work) { 4774 if (!(thread->looper & (BINDER_LOOPER_STATE_REGISTERED | 4775 BINDER_LOOPER_STATE_ENTERED))) { 4776 binder_user_error("%d:%d ERROR: Thread waiting for process work before calling BC_REGISTER_LOOPER or BC_ENTER_LOOPER (state %x)\n", 4777 proc->pid, thread->pid, thread->looper); 4778 wait_event_interruptible(binder_user_error_wait, 4779 binder_stop_on_user_error < 2); 4780 } 4781 binder_set_nice(proc->default_priority); 4782 } 4783 4784 if (non_block) { 4785 if (!binder_has_work(thread, wait_for_proc_work)) 4786 ret = -EAGAIN; 4787 } else { 4788 ret = binder_wait_for_work(thread, wait_for_proc_work); 4789 } 4790 4791 thread->looper &= ~BINDER_LOOPER_STATE_WAITING; 4792 4793 if (ret) 4794 return ret; 4795 4796 while (1) { 4797 uint32_t cmd; 4798 struct binder_transaction_data_secctx tr; 4799 struct binder_transaction_data *trd = &tr.transaction_data; 4800 struct binder_work *w = NULL; 4801 struct list_head *list = NULL; 4802 struct binder_transaction *t = NULL; 4803 struct binder_thread *t_from; 4804 size_t trsize = sizeof(*trd); 4805 4806 binder_inner_proc_lock(proc); 4807 if (!binder_worklist_empty_ilocked(&thread->todo)) 4808 list = &thread->todo; 4809 else if (!binder_worklist_empty_ilocked(&proc->todo) && 4810 wait_for_proc_work) 4811 list = &proc->todo; 4812 else { 4813 binder_inner_proc_unlock(proc); 4814 4815 /* no data added */ 4816 if (ptr - buffer == 4 && !thread->looper_need_return) 4817 goto retry; 4818 break; 4819 } 4820 4821 if (end - ptr < sizeof(tr) + 4) { 4822 binder_inner_proc_unlock(proc); 4823 break; 4824 } 4825 w = binder_dequeue_work_head_ilocked(list); 4826 if (binder_worklist_empty_ilocked(&thread->todo)) 4827 thread->process_todo = false; 4828 4829 switch (w->type) { 4830 case BINDER_WORK_TRANSACTION: { 4831 binder_inner_proc_unlock(proc); 4832 t = container_of(w, struct binder_transaction, work); 4833 } break; 4834 case BINDER_WORK_RETURN_ERROR: { 4835 struct binder_error *e = container_of( 4836 w, struct binder_error, work); 4837 4838 WARN_ON(e->cmd == BR_OK); 4839 binder_inner_proc_unlock(proc); 4840 if (put_user(e->cmd, (uint32_t __user *)ptr)) 4841 return -EFAULT; 4842 cmd = e->cmd; 4843 e->cmd = BR_OK; 4844 ptr += sizeof(uint32_t); 4845 4846 binder_stat_br(proc, thread, cmd); 4847 } break; 4848 case BINDER_WORK_TRANSACTION_COMPLETE: 4849 case BINDER_WORK_TRANSACTION_PENDING: 4850 case BINDER_WORK_TRANSACTION_ONEWAY_SPAM_SUSPECT: { 4851 if (proc->oneway_spam_detection_enabled && 4852 w->type == BINDER_WORK_TRANSACTION_ONEWAY_SPAM_SUSPECT) 4853 cmd = BR_ONEWAY_SPAM_SUSPECT; 4854 else if (w->type == BINDER_WORK_TRANSACTION_PENDING) 4855 cmd = BR_TRANSACTION_PENDING_FROZEN; 4856 else 4857 cmd = BR_TRANSACTION_COMPLETE; 4858 binder_inner_proc_unlock(proc); 4859 kfree(w); 4860 binder_stats_deleted(BINDER_STAT_TRANSACTION_COMPLETE); 4861 if (put_user(cmd, (uint32_t __user *)ptr)) 4862 return -EFAULT; 4863 ptr += sizeof(uint32_t); 4864 4865 binder_stat_br(proc, thread, cmd); 4866 binder_debug(BINDER_DEBUG_TRANSACTION_COMPLETE, 4867 "%d:%d BR_TRANSACTION_COMPLETE\n", 4868 proc->pid, thread->pid); 4869 } break; 4870 case BINDER_WORK_NODE: { 4871 struct binder_node *node = container_of(w, struct binder_node, work); 4872 int strong, weak; 4873 binder_uintptr_t node_ptr = node->ptr; 4874 binder_uintptr_t node_cookie = node->cookie; 4875 int node_debug_id = node->debug_id; 4876 int has_weak_ref; 4877 int has_strong_ref; 4878 void __user *orig_ptr = ptr; 4879 4880 BUG_ON(proc != node->proc); 4881 strong = node->internal_strong_refs || 4882 node->local_strong_refs; 4883 weak = !hlist_empty(&node->refs) || 4884 node->local_weak_refs || 4885 node->tmp_refs || strong; 4886 has_strong_ref = node->has_strong_ref; 4887 has_weak_ref = node->has_weak_ref; 4888 4889 if (weak && !has_weak_ref) { 4890 node->has_weak_ref = 1; 4891 node->pending_weak_ref = 1; 4892 node->local_weak_refs++; 4893 } 4894 if (strong && !has_strong_ref) { 4895 node->has_strong_ref = 1; 4896 node->pending_strong_ref = 1; 4897 node->local_strong_refs++; 4898 } 4899 if (!strong && has_strong_ref) 4900 node->has_strong_ref = 0; 4901 if (!weak && has_weak_ref) 4902 node->has_weak_ref = 0; 4903 if (!weak && !strong) { 4904 binder_debug(BINDER_DEBUG_INTERNAL_REFS, 4905 "%d:%d node %d u%016llx c%016llx deleted\n", 4906 proc->pid, thread->pid, 4907 node_debug_id, 4908 (u64)node_ptr, 4909 (u64)node_cookie); 4910 rb_erase(&node->rb_node, &proc->nodes); 4911 binder_inner_proc_unlock(proc); 4912 binder_node_lock(node); 4913 /* 4914 * Acquire the node lock before freeing the 4915 * node to serialize with other threads that 4916 * may have been holding the node lock while 4917 * decrementing this node (avoids race where 4918 * this thread frees while the other thread 4919 * is unlocking the node after the final 4920 * decrement) 4921 */ 4922 binder_node_unlock(node); 4923 binder_free_node(node); 4924 } else 4925 binder_inner_proc_unlock(proc); 4926 4927 if (weak && !has_weak_ref) 4928 ret = binder_put_node_cmd( 4929 proc, thread, &ptr, node_ptr, 4930 node_cookie, node_debug_id, 4931 BR_INCREFS, "BR_INCREFS"); 4932 if (!ret && strong && !has_strong_ref) 4933 ret = binder_put_node_cmd( 4934 proc, thread, &ptr, node_ptr, 4935 node_cookie, node_debug_id, 4936 BR_ACQUIRE, "BR_ACQUIRE"); 4937 if (!ret && !strong && has_strong_ref) 4938 ret = binder_put_node_cmd( 4939 proc, thread, &ptr, node_ptr, 4940 node_cookie, node_debug_id, 4941 BR_RELEASE, "BR_RELEASE"); 4942 if (!ret && !weak && has_weak_ref) 4943 ret = binder_put_node_cmd( 4944 proc, thread, &ptr, node_ptr, 4945 node_cookie, node_debug_id, 4946 BR_DECREFS, "BR_DECREFS"); 4947 if (orig_ptr == ptr) 4948 binder_debug(BINDER_DEBUG_INTERNAL_REFS, 4949 "%d:%d node %d u%016llx c%016llx state unchanged\n", 4950 proc->pid, thread->pid, 4951 node_debug_id, 4952 (u64)node_ptr, 4953 (u64)node_cookie); 4954 if (ret) 4955 return ret; 4956 } break; 4957 case BINDER_WORK_DEAD_BINDER: 4958 case BINDER_WORK_DEAD_BINDER_AND_CLEAR: 4959 case BINDER_WORK_CLEAR_DEATH_NOTIFICATION: { 4960 struct binder_ref_death *death; 4961 uint32_t cmd; 4962 binder_uintptr_t cookie; 4963 4964 death = container_of(w, struct binder_ref_death, work); 4965 if (w->type == BINDER_WORK_CLEAR_DEATH_NOTIFICATION) 4966 cmd = BR_CLEAR_DEATH_NOTIFICATION_DONE; 4967 else 4968 cmd = BR_DEAD_BINDER; 4969 cookie = death->cookie; 4970 4971 binder_debug(BINDER_DEBUG_DEATH_NOTIFICATION, 4972 "%d:%d %s %016llx\n", 4973 proc->pid, thread->pid, 4974 cmd == BR_DEAD_BINDER ? 4975 "BR_DEAD_BINDER" : 4976 "BR_CLEAR_DEATH_NOTIFICATION_DONE", 4977 (u64)cookie); 4978 if (w->type == BINDER_WORK_CLEAR_DEATH_NOTIFICATION) { 4979 binder_inner_proc_unlock(proc); 4980 kfree(death); 4981 binder_stats_deleted(BINDER_STAT_DEATH); 4982 } else { 4983 binder_enqueue_work_ilocked( 4984 w, &proc->delivered_death); 4985 binder_inner_proc_unlock(proc); 4986 } 4987 if (put_user(cmd, (uint32_t __user *)ptr)) 4988 return -EFAULT; 4989 ptr += sizeof(uint32_t); 4990 if (put_user(cookie, 4991 (binder_uintptr_t __user *)ptr)) 4992 return -EFAULT; 4993 ptr += sizeof(binder_uintptr_t); 4994 binder_stat_br(proc, thread, cmd); 4995 if (cmd == BR_DEAD_BINDER) 4996 goto done; /* DEAD_BINDER notifications can cause transactions */ 4997 } break; 4998 4999 case BINDER_WORK_FROZEN_BINDER: { 5000 struct binder_ref_freeze *freeze; 5001 struct binder_frozen_state_info info; 5002 5003 memset(&info, 0, sizeof(info)); 5004 freeze = container_of(w, struct binder_ref_freeze, work); 5005 info.is_frozen = freeze->is_frozen; 5006 info.cookie = freeze->cookie; 5007 freeze->sent = true; 5008 binder_enqueue_work_ilocked(w, &proc->delivered_freeze); 5009 binder_inner_proc_unlock(proc); 5010 5011 if (put_user(BR_FROZEN_BINDER, (uint32_t __user *)ptr)) 5012 return -EFAULT; 5013 ptr += sizeof(uint32_t); 5014 if (copy_to_user(ptr, &info, sizeof(info))) 5015 return -EFAULT; 5016 ptr += sizeof(info); 5017 binder_stat_br(proc, thread, BR_FROZEN_BINDER); 5018 goto done; /* BR_FROZEN_BINDER notifications can cause transactions */ 5019 } break; 5020 5021 case BINDER_WORK_CLEAR_FREEZE_NOTIFICATION: { 5022 struct binder_ref_freeze *freeze = 5023 container_of(w, struct binder_ref_freeze, work); 5024 binder_uintptr_t cookie = freeze->cookie; 5025 5026 binder_inner_proc_unlock(proc); 5027 kfree(freeze); 5028 binder_stats_deleted(BINDER_STAT_FREEZE); 5029 if (put_user(BR_CLEAR_FREEZE_NOTIFICATION_DONE, (uint32_t __user *)ptr)) 5030 return -EFAULT; 5031 ptr += sizeof(uint32_t); 5032 if (put_user(cookie, (binder_uintptr_t __user *)ptr)) 5033 return -EFAULT; 5034 ptr += sizeof(binder_uintptr_t); 5035 binder_stat_br(proc, thread, BR_CLEAR_FREEZE_NOTIFICATION_DONE); 5036 } break; 5037 5038 default: 5039 binder_inner_proc_unlock(proc); 5040 pr_err("%d:%d: bad work type %d\n", 5041 proc->pid, thread->pid, w->type); 5042 break; 5043 } 5044 5045 if (!t) 5046 continue; 5047 5048 BUG_ON(t->buffer == NULL); 5049 if (t->buffer->target_node) { 5050 struct binder_node *target_node = t->buffer->target_node; 5051 5052 trd->target.ptr = target_node->ptr; 5053 trd->cookie = target_node->cookie; 5054 t->saved_priority = task_nice(current); 5055 if (t->priority < target_node->min_priority && 5056 !(t->flags & TF_ONE_WAY)) 5057 binder_set_nice(t->priority); 5058 else if (!(t->flags & TF_ONE_WAY) || 5059 t->saved_priority > target_node->min_priority) 5060 binder_set_nice(target_node->min_priority); 5061 cmd = BR_TRANSACTION; 5062 } else { 5063 trd->target.ptr = 0; 5064 trd->cookie = 0; 5065 cmd = BR_REPLY; 5066 } 5067 trd->code = t->code; 5068 trd->flags = t->flags; 5069 trd->sender_euid = from_kuid(current_user_ns(), t->sender_euid); 5070 5071 t_from = binder_get_txn_from(t); 5072 if (t_from) { 5073 struct task_struct *sender = t_from->proc->tsk; 5074 5075 trd->sender_pid = 5076 task_tgid_nr_ns(sender, 5077 task_active_pid_ns(current)); 5078 } else { 5079 trd->sender_pid = 0; 5080 } 5081 5082 ret = binder_apply_fd_fixups(proc, t); 5083 if (ret) { 5084 struct binder_buffer *buffer = t->buffer; 5085 bool oneway = !!(t->flags & TF_ONE_WAY); 5086 int tid = t->debug_id; 5087 5088 if (t_from) 5089 binder_thread_dec_tmpref(t_from); 5090 buffer->transaction = NULL; 5091 binder_cleanup_transaction(t, "fd fixups failed", 5092 BR_FAILED_REPLY); 5093 binder_free_buf(proc, thread, buffer, true); 5094 binder_debug(BINDER_DEBUG_FAILED_TRANSACTION, 5095 "%d:%d %stransaction %d fd fixups failed %d/%d, line %d\n", 5096 proc->pid, thread->pid, 5097 oneway ? "async " : 5098 (cmd == BR_REPLY ? "reply " : ""), 5099 tid, BR_FAILED_REPLY, ret, __LINE__); 5100 if (cmd == BR_REPLY) { 5101 cmd = BR_FAILED_REPLY; 5102 if (put_user(cmd, (uint32_t __user *)ptr)) 5103 return -EFAULT; 5104 ptr += sizeof(uint32_t); 5105 binder_stat_br(proc, thread, cmd); 5106 break; 5107 } 5108 continue; 5109 } 5110 trd->data_size = t->buffer->data_size; 5111 trd->offsets_size = t->buffer->offsets_size; 5112 trd->data.ptr.buffer = t->buffer->user_data; 5113 trd->data.ptr.offsets = trd->data.ptr.buffer + 5114 ALIGN(t->buffer->data_size, 5115 sizeof(void *)); 5116 5117 tr.secctx = t->security_ctx; 5118 if (t->security_ctx) { 5119 cmd = BR_TRANSACTION_SEC_CTX; 5120 trsize = sizeof(tr); 5121 } 5122 if (put_user(cmd, (uint32_t __user *)ptr)) { 5123 if (t_from) 5124 binder_thread_dec_tmpref(t_from); 5125 5126 binder_cleanup_transaction(t, "put_user failed", 5127 BR_FAILED_REPLY); 5128 5129 return -EFAULT; 5130 } 5131 ptr += sizeof(uint32_t); 5132 if (copy_to_user(ptr, &tr, trsize)) { 5133 if (t_from) 5134 binder_thread_dec_tmpref(t_from); 5135 5136 binder_cleanup_transaction(t, "copy_to_user failed", 5137 BR_FAILED_REPLY); 5138 5139 return -EFAULT; 5140 } 5141 ptr += trsize; 5142 5143 trace_binder_transaction_received(t); 5144 binder_stat_br(proc, thread, cmd); 5145 binder_debug(BINDER_DEBUG_TRANSACTION, 5146 "%d:%d %s %d %d:%d, cmd %u size %zd-%zd\n", 5147 proc->pid, thread->pid, 5148 (cmd == BR_TRANSACTION) ? "BR_TRANSACTION" : 5149 (cmd == BR_TRANSACTION_SEC_CTX) ? 5150 "BR_TRANSACTION_SEC_CTX" : "BR_REPLY", 5151 t->debug_id, t_from ? t_from->proc->pid : 0, 5152 t_from ? t_from->pid : 0, cmd, 5153 t->buffer->data_size, t->buffer->offsets_size); 5154 5155 if (t_from) 5156 binder_thread_dec_tmpref(t_from); 5157 t->buffer->allow_user_free = 1; 5158 if (cmd != BR_REPLY && !(t->flags & TF_ONE_WAY)) { 5159 binder_inner_proc_lock(thread->proc); 5160 t->to_parent = thread->transaction_stack; 5161 t->to_thread = thread; 5162 thread->transaction_stack = t; 5163 binder_inner_proc_unlock(thread->proc); 5164 } else { 5165 binder_free_transaction(t); 5166 } 5167 break; 5168 } 5169 5170 done: 5171 5172 *consumed = ptr - buffer; 5173 binder_inner_proc_lock(proc); 5174 if (proc->requested_threads == 0 && 5175 list_empty(&thread->proc->waiting_threads) && 5176 proc->requested_threads_started < proc->max_threads && 5177 (thread->looper & (BINDER_LOOPER_STATE_REGISTERED | 5178 BINDER_LOOPER_STATE_ENTERED)) /* the user-space code fails to */ 5179 /*spawn a new thread if we leave this out */) { 5180 proc->requested_threads++; 5181 binder_inner_proc_unlock(proc); 5182 binder_debug(BINDER_DEBUG_THREADS, 5183 "%d:%d BR_SPAWN_LOOPER\n", 5184 proc->pid, thread->pid); 5185 if (put_user(BR_SPAWN_LOOPER, (uint32_t __user *)buffer)) 5186 return -EFAULT; 5187 binder_stat_br(proc, thread, BR_SPAWN_LOOPER); 5188 } else 5189 binder_inner_proc_unlock(proc); 5190 return 0; 5191 } 5192 5193 static void binder_release_work(struct binder_proc *proc, 5194 struct list_head *list) 5195 { 5196 struct binder_work *w; 5197 enum binder_work_type wtype; 5198 5199 while (1) { 5200 binder_inner_proc_lock(proc); 5201 w = binder_dequeue_work_head_ilocked(list); 5202 wtype = w ? w->type : 0; 5203 binder_inner_proc_unlock(proc); 5204 if (!w) 5205 return; 5206 5207 switch (wtype) { 5208 case BINDER_WORK_TRANSACTION: { 5209 struct binder_transaction *t; 5210 5211 t = container_of(w, struct binder_transaction, work); 5212 5213 binder_cleanup_transaction(t, "process died.", 5214 BR_DEAD_REPLY); 5215 } break; 5216 case BINDER_WORK_RETURN_ERROR: { 5217 struct binder_error *e = container_of( 5218 w, struct binder_error, work); 5219 5220 binder_debug(BINDER_DEBUG_DEAD_TRANSACTION, 5221 "undelivered TRANSACTION_ERROR: %u\n", 5222 e->cmd); 5223 } break; 5224 case BINDER_WORK_TRANSACTION_PENDING: 5225 case BINDER_WORK_TRANSACTION_ONEWAY_SPAM_SUSPECT: 5226 case BINDER_WORK_TRANSACTION_COMPLETE: { 5227 binder_debug(BINDER_DEBUG_DEAD_TRANSACTION, 5228 "undelivered TRANSACTION_COMPLETE\n"); 5229 kfree(w); 5230 binder_stats_deleted(BINDER_STAT_TRANSACTION_COMPLETE); 5231 } break; 5232 case BINDER_WORK_DEAD_BINDER_AND_CLEAR: 5233 case BINDER_WORK_CLEAR_DEATH_NOTIFICATION: { 5234 struct binder_ref_death *death; 5235 5236 death = container_of(w, struct binder_ref_death, work); 5237 binder_debug(BINDER_DEBUG_DEAD_TRANSACTION, 5238 "undelivered death notification, %016llx\n", 5239 (u64)death->cookie); 5240 kfree(death); 5241 binder_stats_deleted(BINDER_STAT_DEATH); 5242 } break; 5243 case BINDER_WORK_NODE: 5244 break; 5245 case BINDER_WORK_CLEAR_FREEZE_NOTIFICATION: { 5246 struct binder_ref_freeze *freeze; 5247 5248 freeze = container_of(w, struct binder_ref_freeze, work); 5249 binder_debug(BINDER_DEBUG_DEAD_TRANSACTION, 5250 "undelivered freeze notification, %016llx\n", 5251 (u64)freeze->cookie); 5252 kfree(freeze); 5253 binder_stats_deleted(BINDER_STAT_FREEZE); 5254 } break; 5255 default: 5256 pr_err("unexpected work type, %d, not freed\n", 5257 wtype); 5258 break; 5259 } 5260 } 5261 5262 } 5263 5264 static struct binder_thread *binder_get_thread_ilocked( 5265 struct binder_proc *proc, struct binder_thread *new_thread) 5266 { 5267 struct binder_thread *thread = NULL; 5268 struct rb_node *parent = NULL; 5269 struct rb_node **p = &proc->threads.rb_node; 5270 5271 while (*p) { 5272 parent = *p; 5273 thread = rb_entry(parent, struct binder_thread, rb_node); 5274 5275 if (current->pid < thread->pid) 5276 p = &(*p)->rb_left; 5277 else if (current->pid > thread->pid) 5278 p = &(*p)->rb_right; 5279 else 5280 return thread; 5281 } 5282 if (!new_thread) 5283 return NULL; 5284 thread = new_thread; 5285 binder_stats_created(BINDER_STAT_THREAD); 5286 thread->proc = proc; 5287 thread->pid = current->pid; 5288 atomic_set(&thread->tmp_ref, 0); 5289 init_waitqueue_head(&thread->wait); 5290 INIT_LIST_HEAD(&thread->todo); 5291 rb_link_node(&thread->rb_node, parent, p); 5292 rb_insert_color(&thread->rb_node, &proc->threads); 5293 thread->looper_need_return = true; 5294 thread->return_error.work.type = BINDER_WORK_RETURN_ERROR; 5295 thread->return_error.cmd = BR_OK; 5296 thread->reply_error.work.type = BINDER_WORK_RETURN_ERROR; 5297 thread->reply_error.cmd = BR_OK; 5298 thread->ee.command = BR_OK; 5299 INIT_LIST_HEAD(&new_thread->waiting_thread_node); 5300 return thread; 5301 } 5302 5303 static struct binder_thread *binder_get_thread(struct binder_proc *proc) 5304 { 5305 struct binder_thread *thread; 5306 struct binder_thread *new_thread; 5307 5308 binder_inner_proc_lock(proc); 5309 thread = binder_get_thread_ilocked(proc, NULL); 5310 binder_inner_proc_unlock(proc); 5311 if (!thread) { 5312 new_thread = kzalloc_obj(*thread); 5313 if (new_thread == NULL) 5314 return NULL; 5315 binder_inner_proc_lock(proc); 5316 thread = binder_get_thread_ilocked(proc, new_thread); 5317 binder_inner_proc_unlock(proc); 5318 if (thread != new_thread) 5319 kfree(new_thread); 5320 } 5321 return thread; 5322 } 5323 5324 static void binder_free_proc(struct binder_proc *proc) 5325 { 5326 struct binder_device *device; 5327 5328 BUG_ON(!list_empty(&proc->todo)); 5329 BUG_ON(!list_empty(&proc->delivered_death)); 5330 if (proc->outstanding_txns) 5331 pr_warn("%s: Unexpected outstanding_txns %d\n", 5332 __func__, proc->outstanding_txns); 5333 device = container_of(proc->context, struct binder_device, context); 5334 if (refcount_dec_and_test(&device->ref)) { 5335 binder_remove_device(device); 5336 kfree(proc->context->name); 5337 kfree(device); 5338 } 5339 binder_alloc_deferred_release(&proc->alloc); 5340 put_task_struct(proc->tsk); 5341 put_cred(proc->cred); 5342 binder_stats_deleted(BINDER_STAT_PROC); 5343 dbitmap_free(&proc->dmap); 5344 kfree(proc); 5345 } 5346 5347 static void binder_free_thread(struct binder_thread *thread) 5348 { 5349 BUG_ON(!list_empty(&thread->todo)); 5350 binder_stats_deleted(BINDER_STAT_THREAD); 5351 binder_proc_dec_tmpref(thread->proc); 5352 kfree(thread); 5353 } 5354 5355 static int binder_thread_release(struct binder_proc *proc, 5356 struct binder_thread *thread) 5357 { 5358 struct binder_transaction *t; 5359 struct binder_transaction *send_reply = NULL; 5360 int active_transactions = 0; 5361 struct binder_transaction *last_t = NULL; 5362 5363 binder_inner_proc_lock(thread->proc); 5364 /* 5365 * take a ref on the proc so it survives 5366 * after we remove this thread from proc->threads. 5367 * The corresponding dec is when we actually 5368 * free the thread in binder_free_thread() 5369 */ 5370 proc->tmp_ref++; 5371 /* 5372 * take a ref on this thread to ensure it 5373 * survives while we are releasing it 5374 */ 5375 atomic_inc(&thread->tmp_ref); 5376 rb_erase(&thread->rb_node, &proc->threads); 5377 t = thread->transaction_stack; 5378 if (t) { 5379 spin_lock(&t->lock); 5380 if (t->to_thread == thread) 5381 send_reply = t; 5382 } else { 5383 __acquire(&t->lock); 5384 } 5385 thread->is_dead = true; 5386 5387 while (t) { 5388 last_t = t; 5389 active_transactions++; 5390 binder_debug(BINDER_DEBUG_DEAD_TRANSACTION, 5391 "release %d:%d transaction %d %s, still active\n", 5392 proc->pid, thread->pid, 5393 t->debug_id, 5394 (t->to_thread == thread) ? "in" : "out"); 5395 5396 if (t->to_thread == thread) { 5397 thread->proc->outstanding_txns--; 5398 t->to_proc = NULL; 5399 t->to_thread = NULL; 5400 if (t->buffer) { 5401 t->buffer->transaction = NULL; 5402 t->buffer = NULL; 5403 } 5404 t = t->to_parent; 5405 } else if (t->from == thread) { 5406 t->from = NULL; 5407 t = t->from_parent; 5408 } else 5409 BUG(); 5410 spin_unlock(&last_t->lock); 5411 if (t) 5412 spin_lock(&t->lock); 5413 else 5414 __acquire(&t->lock); 5415 } 5416 /* annotation for sparse, lock not acquired in last iteration above */ 5417 __release(&t->lock); 5418 5419 /* 5420 * If this thread used poll, make sure we remove the waitqueue from any 5421 * poll data structures holding it. 5422 */ 5423 if (thread->looper & BINDER_LOOPER_STATE_POLL) 5424 wake_up_pollfree(&thread->wait); 5425 5426 binder_inner_proc_unlock(thread->proc); 5427 5428 /* 5429 * This is needed to avoid races between wake_up_pollfree() above and 5430 * someone else removing the last entry from the queue for other reasons 5431 * (e.g. ep_remove_wait_queue() being called due to an epoll file 5432 * descriptor being closed). Such other users hold an RCU read lock, so 5433 * we can be sure they're done after we call synchronize_rcu(). 5434 */ 5435 if (thread->looper & BINDER_LOOPER_STATE_POLL) 5436 synchronize_rcu(); 5437 5438 if (send_reply) 5439 binder_send_failed_reply(send_reply, BR_DEAD_REPLY); 5440 binder_release_work(proc, &thread->todo); 5441 binder_thread_dec_tmpref(thread); 5442 return active_transactions; 5443 } 5444 5445 static __poll_t binder_poll(struct file *filp, 5446 struct poll_table_struct *wait) 5447 { 5448 struct binder_proc *proc = filp->private_data; 5449 struct binder_thread *thread = NULL; 5450 bool wait_for_proc_work; 5451 5452 thread = binder_get_thread(proc); 5453 if (!thread) 5454 return EPOLLERR; 5455 5456 binder_inner_proc_lock(thread->proc); 5457 thread->looper |= BINDER_LOOPER_STATE_POLL; 5458 wait_for_proc_work = binder_available_for_proc_work_ilocked(thread); 5459 5460 binder_inner_proc_unlock(thread->proc); 5461 5462 poll_wait(filp, &thread->wait, wait); 5463 5464 if (binder_has_work(thread, wait_for_proc_work)) 5465 return EPOLLIN; 5466 5467 return 0; 5468 } 5469 5470 static int binder_ioctl_write_read(struct file *filp, unsigned long arg, 5471 struct binder_thread *thread) 5472 { 5473 int ret = 0; 5474 struct binder_proc *proc = filp->private_data; 5475 void __user *ubuf = (void __user *)arg; 5476 struct binder_write_read bwr; 5477 5478 if (copy_from_user(&bwr, ubuf, sizeof(bwr))) 5479 return -EFAULT; 5480 5481 binder_debug(BINDER_DEBUG_READ_WRITE, 5482 "%d:%d write %lld at %016llx, read %lld at %016llx\n", 5483 proc->pid, thread->pid, 5484 (u64)bwr.write_size, (u64)bwr.write_buffer, 5485 (u64)bwr.read_size, (u64)bwr.read_buffer); 5486 5487 if (bwr.write_size > 0) { 5488 ret = binder_thread_write(proc, thread, 5489 bwr.write_buffer, 5490 bwr.write_size, 5491 &bwr.write_consumed); 5492 trace_binder_write_done(ret); 5493 if (ret < 0) { 5494 bwr.read_consumed = 0; 5495 goto out; 5496 } 5497 } 5498 if (bwr.read_size > 0) { 5499 ret = binder_thread_read(proc, thread, bwr.read_buffer, 5500 bwr.read_size, 5501 &bwr.read_consumed, 5502 filp->f_flags & O_NONBLOCK); 5503 trace_binder_read_done(ret); 5504 binder_inner_proc_lock(proc); 5505 if (!binder_worklist_empty_ilocked(&proc->todo)) 5506 binder_wakeup_proc_ilocked(proc); 5507 binder_inner_proc_unlock(proc); 5508 if (ret < 0) 5509 goto out; 5510 } 5511 binder_debug(BINDER_DEBUG_READ_WRITE, 5512 "%d:%d wrote %lld of %lld, read return %lld of %lld\n", 5513 proc->pid, thread->pid, 5514 (u64)bwr.write_consumed, (u64)bwr.write_size, 5515 (u64)bwr.read_consumed, (u64)bwr.read_size); 5516 out: 5517 if (copy_to_user(ubuf, &bwr, sizeof(bwr))) 5518 ret = -EFAULT; 5519 return ret; 5520 } 5521 5522 static int binder_ioctl_set_ctx_mgr(struct file *filp, 5523 struct flat_binder_object *fbo) 5524 { 5525 int ret = 0; 5526 struct binder_proc *proc = filp->private_data; 5527 struct binder_context *context = proc->context; 5528 struct binder_node *new_node; 5529 kuid_t curr_euid = current_euid(); 5530 5531 guard(mutex)(&context->context_mgr_node_lock); 5532 if (context->binder_context_mgr_node) { 5533 pr_err("BINDER_SET_CONTEXT_MGR already set\n"); 5534 return -EBUSY; 5535 } 5536 ret = security_binder_set_context_mgr(proc->cred); 5537 if (ret < 0) 5538 return ret; 5539 if (uid_valid(context->binder_context_mgr_uid)) { 5540 if (!uid_eq(context->binder_context_mgr_uid, curr_euid)) { 5541 pr_err("BINDER_SET_CONTEXT_MGR bad uid %d != %d\n", 5542 from_kuid(&init_user_ns, curr_euid), 5543 from_kuid(&init_user_ns, 5544 context->binder_context_mgr_uid)); 5545 return -EPERM; 5546 } 5547 } else { 5548 context->binder_context_mgr_uid = curr_euid; 5549 } 5550 new_node = binder_new_node(proc, fbo); 5551 if (!new_node) 5552 return -ENOMEM; 5553 binder_node_lock(new_node); 5554 new_node->local_weak_refs++; 5555 new_node->local_strong_refs++; 5556 new_node->has_strong_ref = 1; 5557 new_node->has_weak_ref = 1; 5558 context->binder_context_mgr_node = new_node; 5559 binder_node_unlock(new_node); 5560 binder_put_node(new_node); 5561 return ret; 5562 } 5563 5564 static int binder_ioctl_get_node_info_for_ref(struct binder_proc *proc, 5565 struct binder_node_info_for_ref *info) 5566 { 5567 struct binder_node *node; 5568 struct binder_context *context = proc->context; 5569 __u32 handle = info->handle; 5570 5571 if (info->strong_count || info->weak_count || info->reserved1 || 5572 info->reserved2 || info->reserved3) { 5573 binder_user_error("%d BINDER_GET_NODE_INFO_FOR_REF: only handle may be non-zero.", 5574 proc->pid); 5575 return -EINVAL; 5576 } 5577 5578 /* This ioctl may only be used by the context manager */ 5579 mutex_lock(&context->context_mgr_node_lock); 5580 if (!context->binder_context_mgr_node || 5581 context->binder_context_mgr_node->proc != proc) { 5582 mutex_unlock(&context->context_mgr_node_lock); 5583 return -EPERM; 5584 } 5585 mutex_unlock(&context->context_mgr_node_lock); 5586 5587 node = binder_get_node_from_ref(proc, handle, true, NULL); 5588 if (!node) 5589 return -EINVAL; 5590 5591 info->strong_count = node->local_strong_refs + 5592 node->internal_strong_refs; 5593 info->weak_count = node->local_weak_refs; 5594 5595 binder_put_node(node); 5596 5597 return 0; 5598 } 5599 5600 static int binder_ioctl_get_node_debug_info(struct binder_proc *proc, 5601 struct binder_node_debug_info *info) 5602 { 5603 struct rb_node *n; 5604 binder_uintptr_t ptr = info->ptr; 5605 5606 memset(info, 0, sizeof(*info)); 5607 5608 binder_inner_proc_lock(proc); 5609 for (n = rb_first(&proc->nodes); n != NULL; n = rb_next(n)) { 5610 struct binder_node *node = rb_entry(n, struct binder_node, 5611 rb_node); 5612 if (node->ptr > ptr) { 5613 info->ptr = node->ptr; 5614 info->cookie = node->cookie; 5615 info->has_strong_ref = node->has_strong_ref; 5616 info->has_weak_ref = node->has_weak_ref; 5617 break; 5618 } 5619 } 5620 binder_inner_proc_unlock(proc); 5621 5622 return 0; 5623 } 5624 5625 static bool binder_txns_pending_ilocked(struct binder_proc *proc) 5626 { 5627 struct rb_node *n; 5628 struct binder_thread *thread; 5629 5630 if (proc->outstanding_txns > 0) 5631 return true; 5632 5633 for (n = rb_first(&proc->threads); n; n = rb_next(n)) { 5634 thread = rb_entry(n, struct binder_thread, rb_node); 5635 if (thread->transaction_stack) 5636 return true; 5637 } 5638 return false; 5639 } 5640 5641 static void binder_add_freeze_work(struct binder_proc *proc, bool is_frozen) 5642 { 5643 struct binder_node *prev = NULL; 5644 struct rb_node *n; 5645 struct binder_ref *ref; 5646 5647 binder_inner_proc_lock(proc); 5648 for (n = rb_first(&proc->nodes); n; n = rb_next(n)) { 5649 struct binder_node *node; 5650 5651 node = rb_entry(n, struct binder_node, rb_node); 5652 binder_inc_node_tmpref_ilocked(node); 5653 binder_inner_proc_unlock(proc); 5654 if (prev) 5655 binder_put_node(prev); 5656 binder_node_lock(node); 5657 hlist_for_each_entry(ref, &node->refs, node_entry) { 5658 /* 5659 * Need the node lock to synchronize 5660 * with new notification requests and the 5661 * inner lock to synchronize with queued 5662 * freeze notifications. 5663 */ 5664 binder_inner_proc_lock(ref->proc); 5665 if (!ref->freeze) { 5666 binder_inner_proc_unlock(ref->proc); 5667 continue; 5668 } 5669 ref->freeze->work.type = BINDER_WORK_FROZEN_BINDER; 5670 if (list_empty(&ref->freeze->work.entry)) { 5671 ref->freeze->is_frozen = is_frozen; 5672 binder_enqueue_work_ilocked(&ref->freeze->work, &ref->proc->todo); 5673 binder_wakeup_proc_ilocked(ref->proc); 5674 } else { 5675 if (ref->freeze->sent && ref->freeze->is_frozen != is_frozen) 5676 ref->freeze->resend = true; 5677 ref->freeze->is_frozen = is_frozen; 5678 } 5679 binder_inner_proc_unlock(ref->proc); 5680 } 5681 prev = node; 5682 binder_node_unlock(node); 5683 binder_inner_proc_lock(proc); 5684 if (proc->is_dead) 5685 break; 5686 } 5687 binder_inner_proc_unlock(proc); 5688 if (prev) 5689 binder_put_node(prev); 5690 } 5691 5692 static int binder_ioctl_freeze(struct binder_freeze_info *info, 5693 struct binder_proc *target_proc) 5694 { 5695 int ret = 0; 5696 5697 if (!info->enable) { 5698 binder_inner_proc_lock(target_proc); 5699 target_proc->sync_recv = false; 5700 target_proc->async_recv = false; 5701 target_proc->is_frozen = false; 5702 binder_inner_proc_unlock(target_proc); 5703 binder_add_freeze_work(target_proc, false); 5704 return 0; 5705 } 5706 5707 /* 5708 * Freezing the target. Prevent new transactions by 5709 * setting frozen state. If timeout specified, wait 5710 * for transactions to drain. 5711 */ 5712 binder_inner_proc_lock(target_proc); 5713 target_proc->sync_recv = false; 5714 target_proc->async_recv = false; 5715 target_proc->is_frozen = true; 5716 binder_inner_proc_unlock(target_proc); 5717 5718 if (info->timeout_ms > 0) 5719 ret = wait_event_interruptible_timeout( 5720 target_proc->freeze_wait, 5721 (!target_proc->outstanding_txns), 5722 msecs_to_jiffies(info->timeout_ms)); 5723 5724 /* Check pending transactions that wait for reply */ 5725 if (ret >= 0) { 5726 binder_inner_proc_lock(target_proc); 5727 if (binder_txns_pending_ilocked(target_proc)) 5728 ret = -EAGAIN; 5729 binder_inner_proc_unlock(target_proc); 5730 } 5731 5732 if (ret < 0) { 5733 binder_inner_proc_lock(target_proc); 5734 target_proc->is_frozen = false; 5735 binder_inner_proc_unlock(target_proc); 5736 } else { 5737 binder_add_freeze_work(target_proc, true); 5738 } 5739 5740 return ret; 5741 } 5742 5743 static int binder_ioctl_get_freezer_info( 5744 struct binder_frozen_status_info *info) 5745 { 5746 struct binder_proc *target_proc; 5747 bool found = false; 5748 __u32 txns_pending; 5749 5750 info->sync_recv = 0; 5751 info->async_recv = 0; 5752 5753 mutex_lock(&binder_procs_lock); 5754 hlist_for_each_entry(target_proc, &binder_procs, proc_node) { 5755 if (target_proc->pid == info->pid) { 5756 found = true; 5757 binder_inner_proc_lock(target_proc); 5758 txns_pending = binder_txns_pending_ilocked(target_proc); 5759 info->sync_recv |= target_proc->sync_recv | 5760 (txns_pending << 1); 5761 info->async_recv |= target_proc->async_recv; 5762 binder_inner_proc_unlock(target_proc); 5763 } 5764 } 5765 mutex_unlock(&binder_procs_lock); 5766 5767 if (!found) 5768 return -EINVAL; 5769 5770 return 0; 5771 } 5772 5773 static int binder_ioctl_get_extended_error(struct binder_thread *thread, 5774 void __user *ubuf) 5775 { 5776 struct binder_extended_error ee; 5777 5778 binder_inner_proc_lock(thread->proc); 5779 ee = thread->ee; 5780 binder_set_extended_error(&thread->ee, 0, BR_OK, 0); 5781 binder_inner_proc_unlock(thread->proc); 5782 5783 if (copy_to_user(ubuf, &ee, sizeof(ee))) 5784 return -EFAULT; 5785 5786 return 0; 5787 } 5788 5789 static long binder_ioctl(struct file *filp, unsigned int cmd, unsigned long arg) 5790 { 5791 int ret; 5792 struct binder_proc *proc = filp->private_data; 5793 struct binder_thread *thread; 5794 void __user *ubuf = (void __user *)arg; 5795 5796 trace_binder_ioctl(cmd, arg); 5797 5798 ret = wait_event_interruptible(binder_user_error_wait, binder_stop_on_user_error < 2); 5799 if (ret) 5800 goto err_unlocked; 5801 5802 thread = binder_get_thread(proc); 5803 if (thread == NULL) { 5804 ret = -ENOMEM; 5805 goto err; 5806 } 5807 5808 switch (cmd) { 5809 case BINDER_WRITE_READ: 5810 ret = binder_ioctl_write_read(filp, arg, thread); 5811 if (ret) 5812 goto err; 5813 break; 5814 case BINDER_SET_MAX_THREADS: { 5815 u32 max_threads; 5816 5817 if (copy_from_user(&max_threads, ubuf, 5818 sizeof(max_threads))) { 5819 ret = -EINVAL; 5820 goto err; 5821 } 5822 binder_inner_proc_lock(proc); 5823 proc->max_threads = max_threads; 5824 binder_inner_proc_unlock(proc); 5825 break; 5826 } 5827 case BINDER_SET_CONTEXT_MGR_EXT: { 5828 struct flat_binder_object fbo; 5829 5830 if (copy_from_user(&fbo, ubuf, sizeof(fbo))) { 5831 ret = -EINVAL; 5832 goto err; 5833 } 5834 ret = binder_ioctl_set_ctx_mgr(filp, &fbo); 5835 if (ret) 5836 goto err; 5837 break; 5838 } 5839 case BINDER_SET_CONTEXT_MGR: 5840 ret = binder_ioctl_set_ctx_mgr(filp, NULL); 5841 if (ret) 5842 goto err; 5843 break; 5844 case BINDER_THREAD_EXIT: 5845 binder_debug(BINDER_DEBUG_THREADS, "%d:%d exit\n", 5846 proc->pid, thread->pid); 5847 binder_thread_release(proc, thread); 5848 thread = NULL; 5849 break; 5850 case BINDER_VERSION: { 5851 struct binder_version __user *ver = ubuf; 5852 5853 if (put_user(BINDER_CURRENT_PROTOCOL_VERSION, 5854 &ver->protocol_version)) { 5855 ret = -EINVAL; 5856 goto err; 5857 } 5858 break; 5859 } 5860 case BINDER_GET_NODE_INFO_FOR_REF: { 5861 struct binder_node_info_for_ref info; 5862 5863 if (copy_from_user(&info, ubuf, sizeof(info))) { 5864 ret = -EFAULT; 5865 goto err; 5866 } 5867 5868 ret = binder_ioctl_get_node_info_for_ref(proc, &info); 5869 if (ret < 0) 5870 goto err; 5871 5872 if (copy_to_user(ubuf, &info, sizeof(info))) { 5873 ret = -EFAULT; 5874 goto err; 5875 } 5876 5877 break; 5878 } 5879 case BINDER_GET_NODE_DEBUG_INFO: { 5880 struct binder_node_debug_info info; 5881 5882 if (copy_from_user(&info, ubuf, sizeof(info))) { 5883 ret = -EFAULT; 5884 goto err; 5885 } 5886 5887 ret = binder_ioctl_get_node_debug_info(proc, &info); 5888 if (ret < 0) 5889 goto err; 5890 5891 if (copy_to_user(ubuf, &info, sizeof(info))) { 5892 ret = -EFAULT; 5893 goto err; 5894 } 5895 break; 5896 } 5897 case BINDER_FREEZE: { 5898 struct binder_freeze_info info; 5899 struct binder_proc **target_procs = NULL, *target_proc; 5900 int target_procs_count = 0, i = 0; 5901 5902 ret = 0; 5903 5904 if (copy_from_user(&info, ubuf, sizeof(info))) { 5905 ret = -EFAULT; 5906 goto err; 5907 } 5908 5909 mutex_lock(&binder_procs_lock); 5910 hlist_for_each_entry(target_proc, &binder_procs, proc_node) { 5911 if (target_proc->pid == info.pid) 5912 target_procs_count++; 5913 } 5914 5915 if (target_procs_count == 0) { 5916 mutex_unlock(&binder_procs_lock); 5917 ret = -EINVAL; 5918 goto err; 5919 } 5920 5921 target_procs = kzalloc_objs(struct binder_proc *, 5922 target_procs_count); 5923 5924 if (!target_procs) { 5925 mutex_unlock(&binder_procs_lock); 5926 ret = -ENOMEM; 5927 goto err; 5928 } 5929 5930 hlist_for_each_entry(target_proc, &binder_procs, proc_node) { 5931 if (target_proc->pid != info.pid) 5932 continue; 5933 5934 binder_inner_proc_lock(target_proc); 5935 target_proc->tmp_ref++; 5936 binder_inner_proc_unlock(target_proc); 5937 5938 target_procs[i++] = target_proc; 5939 } 5940 mutex_unlock(&binder_procs_lock); 5941 5942 for (i = 0; i < target_procs_count; i++) { 5943 if (ret >= 0) 5944 ret = binder_ioctl_freeze(&info, 5945 target_procs[i]); 5946 5947 binder_proc_dec_tmpref(target_procs[i]); 5948 } 5949 5950 kfree(target_procs); 5951 5952 if (ret < 0) 5953 goto err; 5954 break; 5955 } 5956 case BINDER_GET_FROZEN_INFO: { 5957 struct binder_frozen_status_info info; 5958 5959 if (copy_from_user(&info, ubuf, sizeof(info))) { 5960 ret = -EFAULT; 5961 goto err; 5962 } 5963 5964 ret = binder_ioctl_get_freezer_info(&info); 5965 if (ret < 0) 5966 goto err; 5967 5968 if (copy_to_user(ubuf, &info, sizeof(info))) { 5969 ret = -EFAULT; 5970 goto err; 5971 } 5972 break; 5973 } 5974 case BINDER_ENABLE_ONEWAY_SPAM_DETECTION: { 5975 uint32_t enable; 5976 5977 if (copy_from_user(&enable, ubuf, sizeof(enable))) { 5978 ret = -EFAULT; 5979 goto err; 5980 } 5981 binder_inner_proc_lock(proc); 5982 proc->oneway_spam_detection_enabled = (bool)enable; 5983 binder_inner_proc_unlock(proc); 5984 break; 5985 } 5986 case BINDER_GET_EXTENDED_ERROR: 5987 ret = binder_ioctl_get_extended_error(thread, ubuf); 5988 if (ret < 0) 5989 goto err; 5990 break; 5991 default: 5992 ret = -EINVAL; 5993 goto err; 5994 } 5995 ret = 0; 5996 err: 5997 if (thread) 5998 thread->looper_need_return = false; 5999 wait_event_interruptible(binder_user_error_wait, binder_stop_on_user_error < 2); 6000 if (ret && ret != -EINTR) 6001 pr_info("%d:%d ioctl %x %lx returned %d\n", proc->pid, current->pid, cmd, arg, ret); 6002 err_unlocked: 6003 trace_binder_ioctl_done(ret); 6004 return ret; 6005 } 6006 6007 static void binder_vma_open(struct vm_area_struct *vma) 6008 { 6009 struct binder_proc *proc = vma->vm_private_data; 6010 6011 binder_debug(BINDER_DEBUG_OPEN_CLOSE, 6012 "%d open vm area %lx-%lx (%ld K) vma %lx pagep %lx\n", 6013 proc->pid, vma->vm_start, vma->vm_end, 6014 (vma->vm_end - vma->vm_start) / SZ_1K, vma->vm_flags, 6015 (unsigned long)pgprot_val(vma->vm_page_prot)); 6016 } 6017 6018 static void binder_vma_close(struct vm_area_struct *vma) 6019 { 6020 struct binder_proc *proc = vma->vm_private_data; 6021 6022 binder_debug(BINDER_DEBUG_OPEN_CLOSE, 6023 "%d close vm area %lx-%lx (%ld K) vma %lx pagep %lx\n", 6024 proc->pid, vma->vm_start, vma->vm_end, 6025 (vma->vm_end - vma->vm_start) / SZ_1K, vma->vm_flags, 6026 (unsigned long)pgprot_val(vma->vm_page_prot)); 6027 binder_alloc_vma_close(&proc->alloc); 6028 } 6029 6030 VISIBLE_IF_KUNIT vm_fault_t binder_vm_fault(struct vm_fault *vmf) 6031 { 6032 return VM_FAULT_SIGBUS; 6033 } 6034 EXPORT_SYMBOL_IF_KUNIT(binder_vm_fault); 6035 6036 static const struct vm_operations_struct binder_vm_ops = { 6037 .open = binder_vma_open, 6038 .close = binder_vma_close, 6039 .fault = binder_vm_fault, 6040 }; 6041 6042 static int binder_mmap(struct file *filp, struct vm_area_struct *vma) 6043 { 6044 struct binder_proc *proc = filp->private_data; 6045 6046 if (!same_thread_group(proc->tsk, current)) 6047 return -EINVAL; 6048 6049 binder_debug(BINDER_DEBUG_OPEN_CLOSE, 6050 "%s: %d %lx-%lx (%ld K) vma %lx pagep %lx\n", 6051 __func__, proc->pid, vma->vm_start, vma->vm_end, 6052 (vma->vm_end - vma->vm_start) / SZ_1K, vma->vm_flags, 6053 (unsigned long)pgprot_val(vma->vm_page_prot)); 6054 6055 if (vma->vm_flags & FORBIDDEN_MMAP_FLAGS) { 6056 pr_err("%s: %d %lx-%lx %s failed %d\n", __func__, 6057 proc->pid, vma->vm_start, vma->vm_end, "bad vm_flags", -EPERM); 6058 return -EPERM; 6059 } 6060 vm_flags_mod(vma, VM_DONTCOPY | VM_MIXEDMAP, VM_MAYWRITE); 6061 6062 vma->vm_ops = &binder_vm_ops; 6063 vma->vm_private_data = proc; 6064 6065 return binder_alloc_mmap_handler(&proc->alloc, vma); 6066 } 6067 6068 static int binder_open(struct inode *nodp, struct file *filp) 6069 { 6070 struct binder_proc *proc, *itr; 6071 struct binder_device *binder_dev; 6072 struct binderfs_info *info; 6073 struct dentry *binder_binderfs_dir_entry_proc = NULL; 6074 bool existing_pid = false; 6075 6076 binder_debug(BINDER_DEBUG_OPEN_CLOSE, "%s: %d:%d\n", __func__, 6077 current->tgid, current->pid); 6078 6079 proc = kzalloc_obj(*proc); 6080 if (proc == NULL) 6081 return -ENOMEM; 6082 6083 dbitmap_init(&proc->dmap); 6084 spin_lock_init(&proc->inner_lock); 6085 spin_lock_init(&proc->outer_lock); 6086 proc->tsk = get_task_struct(current->group_leader); 6087 proc->pid = current->tgid; 6088 proc->cred = get_cred(filp->f_cred); 6089 INIT_LIST_HEAD(&proc->todo); 6090 init_waitqueue_head(&proc->freeze_wait); 6091 proc->default_priority = task_nice(current); 6092 /* binderfs stashes devices in i_private */ 6093 if (is_binderfs_device(nodp)) { 6094 binder_dev = nodp->i_private; 6095 info = nodp->i_sb->s_fs_info; 6096 binder_binderfs_dir_entry_proc = info->proc_log_dir; 6097 } else { 6098 binder_dev = container_of(filp->private_data, 6099 struct binder_device, miscdev); 6100 } 6101 refcount_inc(&binder_dev->ref); 6102 proc->context = &binder_dev->context; 6103 binder_alloc_init(&proc->alloc); 6104 6105 binder_stats_created(BINDER_STAT_PROC); 6106 INIT_LIST_HEAD(&proc->delivered_death); 6107 INIT_LIST_HEAD(&proc->delivered_freeze); 6108 INIT_LIST_HEAD(&proc->waiting_threads); 6109 filp->private_data = proc; 6110 6111 mutex_lock(&binder_procs_lock); 6112 hlist_for_each_entry(itr, &binder_procs, proc_node) { 6113 if (itr->pid == proc->pid) { 6114 existing_pid = true; 6115 break; 6116 } 6117 } 6118 hlist_add_head(&proc->proc_node, &binder_procs); 6119 mutex_unlock(&binder_procs_lock); 6120 6121 if (binder_debugfs_dir_entry_proc && !existing_pid) { 6122 char strbuf[11]; 6123 6124 snprintf(strbuf, sizeof(strbuf), "%u", proc->pid); 6125 /* 6126 * proc debug entries are shared between contexts. 6127 * Only create for the first PID to avoid debugfs log spamming 6128 * The printing code will anyway print all contexts for a given 6129 * PID so this is not a problem. 6130 */ 6131 proc->debugfs_entry = debugfs_create_file(strbuf, 0444, 6132 binder_debugfs_dir_entry_proc, 6133 (void *)(unsigned long)proc->pid, 6134 &proc_fops); 6135 } 6136 6137 if (binder_binderfs_dir_entry_proc && !existing_pid) { 6138 char strbuf[11]; 6139 struct dentry *binderfs_entry; 6140 6141 snprintf(strbuf, sizeof(strbuf), "%u", proc->pid); 6142 /* 6143 * Similar to debugfs, the process specific log file is shared 6144 * between contexts. Only create for the first PID. 6145 * This is ok since same as debugfs, the log file will contain 6146 * information on all contexts of a given PID. 6147 */ 6148 binderfs_entry = binderfs_create_file(binder_binderfs_dir_entry_proc, 6149 strbuf, &proc_fops, (void *)(unsigned long)proc->pid); 6150 if (!IS_ERR(binderfs_entry)) { 6151 proc->binderfs_entry = binderfs_entry; 6152 } else { 6153 int error; 6154 6155 error = PTR_ERR(binderfs_entry); 6156 pr_warn("Unable to create file %s in binderfs (error %d)\n", 6157 strbuf, error); 6158 } 6159 } 6160 6161 return 0; 6162 } 6163 6164 static int binder_flush(struct file *filp, fl_owner_t id) 6165 { 6166 struct binder_proc *proc = filp->private_data; 6167 6168 binder_defer_work(proc, BINDER_DEFERRED_FLUSH); 6169 6170 return 0; 6171 } 6172 6173 static void binder_deferred_flush(struct binder_proc *proc) 6174 { 6175 struct rb_node *n; 6176 int wake_count = 0; 6177 6178 binder_inner_proc_lock(proc); 6179 for (n = rb_first(&proc->threads); n != NULL; n = rb_next(n)) { 6180 struct binder_thread *thread = rb_entry(n, struct binder_thread, rb_node); 6181 6182 thread->looper_need_return = true; 6183 if (thread->looper & BINDER_LOOPER_STATE_WAITING) { 6184 wake_up_interruptible(&thread->wait); 6185 wake_count++; 6186 } 6187 } 6188 binder_inner_proc_unlock(proc); 6189 6190 binder_debug(BINDER_DEBUG_OPEN_CLOSE, 6191 "binder_flush: %d woke %d threads\n", proc->pid, 6192 wake_count); 6193 } 6194 6195 static int binder_release(struct inode *nodp, struct file *filp) 6196 { 6197 struct binder_proc *proc = filp->private_data; 6198 6199 debugfs_remove(proc->debugfs_entry); 6200 6201 if (proc->binderfs_entry) { 6202 simple_recursive_removal(proc->binderfs_entry, NULL); 6203 proc->binderfs_entry = NULL; 6204 } 6205 6206 binder_defer_work(proc, BINDER_DEFERRED_RELEASE); 6207 6208 return 0; 6209 } 6210 6211 static int binder_node_release(struct binder_node *node, int refs) 6212 { 6213 struct binder_ref *ref; 6214 int death = 0; 6215 struct binder_proc *proc = node->proc; 6216 6217 binder_release_work(proc, &node->async_todo); 6218 6219 binder_node_lock(node); 6220 binder_inner_proc_lock(proc); 6221 binder_dequeue_work_ilocked(&node->work); 6222 /* 6223 * The caller must have taken a temporary ref on the node, 6224 */ 6225 BUG_ON(!node->tmp_refs); 6226 if (hlist_empty(&node->refs) && node->tmp_refs == 1) { 6227 binder_inner_proc_unlock(proc); 6228 binder_node_unlock(node); 6229 binder_free_node(node); 6230 6231 return refs; 6232 } 6233 6234 node->proc = NULL; 6235 node->local_strong_refs = 0; 6236 node->local_weak_refs = 0; 6237 binder_inner_proc_unlock(proc); 6238 6239 spin_lock(&binder_dead_nodes_lock); 6240 hlist_add_head(&node->dead_node, &binder_dead_nodes); 6241 spin_unlock(&binder_dead_nodes_lock); 6242 6243 hlist_for_each_entry(ref, &node->refs, node_entry) { 6244 refs++; 6245 /* 6246 * Need the node lock to synchronize 6247 * with new notification requests and the 6248 * inner lock to synchronize with queued 6249 * death notifications. 6250 */ 6251 binder_inner_proc_lock(ref->proc); 6252 if (!ref->death) { 6253 binder_inner_proc_unlock(ref->proc); 6254 continue; 6255 } 6256 6257 death++; 6258 6259 BUG_ON(!list_empty(&ref->death->work.entry)); 6260 ref->death->work.type = BINDER_WORK_DEAD_BINDER; 6261 binder_enqueue_work_ilocked(&ref->death->work, 6262 &ref->proc->todo); 6263 binder_wakeup_proc_ilocked(ref->proc); 6264 binder_inner_proc_unlock(ref->proc); 6265 } 6266 6267 binder_debug(BINDER_DEBUG_DEAD_BINDER, 6268 "node %d now dead, refs %d, death %d\n", 6269 node->debug_id, refs, death); 6270 binder_node_unlock(node); 6271 binder_put_node(node); 6272 6273 return refs; 6274 } 6275 6276 static void binder_deferred_release(struct binder_proc *proc) 6277 { 6278 struct binder_context *context = proc->context; 6279 struct rb_node *n; 6280 int threads, nodes, incoming_refs, outgoing_refs, active_transactions; 6281 6282 mutex_lock(&binder_procs_lock); 6283 hlist_del(&proc->proc_node); 6284 mutex_unlock(&binder_procs_lock); 6285 6286 mutex_lock(&context->context_mgr_node_lock); 6287 if (context->binder_context_mgr_node && 6288 context->binder_context_mgr_node->proc == proc) { 6289 binder_debug(BINDER_DEBUG_DEAD_BINDER, 6290 "%s: %d context_mgr_node gone\n", 6291 __func__, proc->pid); 6292 context->binder_context_mgr_node = NULL; 6293 } 6294 mutex_unlock(&context->context_mgr_node_lock); 6295 binder_inner_proc_lock(proc); 6296 /* 6297 * Make sure proc stays alive after we 6298 * remove all the threads 6299 */ 6300 proc->tmp_ref++; 6301 6302 proc->is_dead = true; 6303 proc->is_frozen = false; 6304 proc->sync_recv = false; 6305 proc->async_recv = false; 6306 threads = 0; 6307 active_transactions = 0; 6308 while ((n = rb_first(&proc->threads))) { 6309 struct binder_thread *thread; 6310 6311 thread = rb_entry(n, struct binder_thread, rb_node); 6312 binder_inner_proc_unlock(proc); 6313 threads++; 6314 active_transactions += binder_thread_release(proc, thread); 6315 binder_inner_proc_lock(proc); 6316 } 6317 6318 nodes = 0; 6319 incoming_refs = 0; 6320 while ((n = rb_first(&proc->nodes))) { 6321 struct binder_node *node; 6322 6323 node = rb_entry(n, struct binder_node, rb_node); 6324 nodes++; 6325 /* 6326 * take a temporary ref on the node before 6327 * calling binder_node_release() which will either 6328 * kfree() the node or call binder_put_node() 6329 */ 6330 binder_inc_node_tmpref_ilocked(node); 6331 rb_erase(&node->rb_node, &proc->nodes); 6332 binder_inner_proc_unlock(proc); 6333 incoming_refs = binder_node_release(node, incoming_refs); 6334 binder_inner_proc_lock(proc); 6335 } 6336 binder_inner_proc_unlock(proc); 6337 6338 outgoing_refs = 0; 6339 binder_proc_lock(proc); 6340 while ((n = rb_first(&proc->refs_by_desc))) { 6341 struct binder_ref *ref; 6342 6343 ref = rb_entry(n, struct binder_ref, rb_node_desc); 6344 outgoing_refs++; 6345 binder_cleanup_ref_olocked(ref); 6346 binder_proc_unlock(proc); 6347 binder_free_ref(ref); 6348 binder_proc_lock(proc); 6349 } 6350 binder_proc_unlock(proc); 6351 6352 binder_release_work(proc, &proc->todo); 6353 binder_release_work(proc, &proc->delivered_death); 6354 binder_release_work(proc, &proc->delivered_freeze); 6355 6356 binder_debug(BINDER_DEBUG_OPEN_CLOSE, 6357 "%s: %d threads %d, nodes %d (ref %d), refs %d, active transactions %d\n", 6358 __func__, proc->pid, threads, nodes, incoming_refs, 6359 outgoing_refs, active_transactions); 6360 6361 binder_proc_dec_tmpref(proc); 6362 } 6363 6364 static void binder_deferred_func(struct work_struct *work) 6365 { 6366 struct binder_proc *proc; 6367 6368 int defer; 6369 6370 do { 6371 mutex_lock(&binder_deferred_lock); 6372 if (!hlist_empty(&binder_deferred_list)) { 6373 proc = hlist_entry(binder_deferred_list.first, 6374 struct binder_proc, deferred_work_node); 6375 hlist_del_init(&proc->deferred_work_node); 6376 defer = proc->deferred_work; 6377 proc->deferred_work = 0; 6378 } else { 6379 proc = NULL; 6380 defer = 0; 6381 } 6382 mutex_unlock(&binder_deferred_lock); 6383 6384 if (defer & BINDER_DEFERRED_FLUSH) 6385 binder_deferred_flush(proc); 6386 6387 if (defer & BINDER_DEFERRED_RELEASE) 6388 binder_deferred_release(proc); /* frees proc */ 6389 } while (proc); 6390 } 6391 static DECLARE_WORK(binder_deferred_work, binder_deferred_func); 6392 6393 static void 6394 binder_defer_work(struct binder_proc *proc, enum binder_deferred_state defer) 6395 { 6396 guard(mutex)(&binder_deferred_lock); 6397 proc->deferred_work |= defer; 6398 if (hlist_unhashed(&proc->deferred_work_node)) { 6399 hlist_add_head(&proc->deferred_work_node, 6400 &binder_deferred_list); 6401 schedule_work(&binder_deferred_work); 6402 } 6403 } 6404 6405 static void print_binder_transaction_ilocked(struct seq_file *m, 6406 struct binder_proc *proc, 6407 const char *prefix, 6408 struct binder_transaction *t) 6409 { 6410 struct binder_proc *to_proc; 6411 struct binder_buffer *buffer = t->buffer; 6412 ktime_t current_time = ktime_get(); 6413 6414 spin_lock(&t->lock); 6415 to_proc = t->to_proc; 6416 seq_printf(m, 6417 "%s %d: %pK from %d:%d to %d:%d code %x flags %x pri %ld a%d r%d elapsed %lldms", 6418 prefix, t->debug_id, t, 6419 t->from_pid, 6420 t->from_tid, 6421 to_proc ? to_proc->pid : 0, 6422 t->to_thread ? t->to_thread->pid : 0, 6423 t->code, t->flags, t->priority, t->is_async, t->is_reply, 6424 ktime_ms_delta(current_time, t->start_time)); 6425 spin_unlock(&t->lock); 6426 6427 if (proc != to_proc) { 6428 /* 6429 * Can only safely deref buffer if we are holding the 6430 * correct proc inner lock for this node 6431 */ 6432 seq_puts(m, "\n"); 6433 return; 6434 } 6435 6436 if (buffer == NULL) { 6437 seq_puts(m, " buffer free\n"); 6438 return; 6439 } 6440 if (buffer->target_node) 6441 seq_printf(m, " node %d", buffer->target_node->debug_id); 6442 seq_printf(m, " size %zd:%zd offset %lx\n", 6443 buffer->data_size, buffer->offsets_size, 6444 buffer->user_data - proc->alloc.vm_start); 6445 } 6446 6447 static void print_binder_work_ilocked(struct seq_file *m, 6448 struct binder_proc *proc, 6449 const char *prefix, 6450 const char *transaction_prefix, 6451 struct binder_work *w, bool hash_ptrs) 6452 { 6453 struct binder_node *node; 6454 struct binder_transaction *t; 6455 6456 switch (w->type) { 6457 case BINDER_WORK_TRANSACTION: 6458 t = container_of(w, struct binder_transaction, work); 6459 print_binder_transaction_ilocked( 6460 m, proc, transaction_prefix, t); 6461 break; 6462 case BINDER_WORK_RETURN_ERROR: { 6463 struct binder_error *e = container_of( 6464 w, struct binder_error, work); 6465 6466 seq_printf(m, "%stransaction error: %u\n", 6467 prefix, e->cmd); 6468 } break; 6469 case BINDER_WORK_TRANSACTION_COMPLETE: 6470 seq_printf(m, "%stransaction complete\n", prefix); 6471 break; 6472 case BINDER_WORK_NODE: 6473 node = container_of(w, struct binder_node, work); 6474 if (hash_ptrs) 6475 seq_printf(m, "%snode work %d: u%p c%p\n", 6476 prefix, node->debug_id, 6477 (void *)(long)node->ptr, 6478 (void *)(long)node->cookie); 6479 else 6480 seq_printf(m, "%snode work %d: u%016llx c%016llx\n", 6481 prefix, node->debug_id, 6482 (u64)node->ptr, (u64)node->cookie); 6483 break; 6484 case BINDER_WORK_DEAD_BINDER: 6485 seq_printf(m, "%shas dead binder\n", prefix); 6486 break; 6487 case BINDER_WORK_DEAD_BINDER_AND_CLEAR: 6488 seq_printf(m, "%shas cleared dead binder\n", prefix); 6489 break; 6490 case BINDER_WORK_CLEAR_DEATH_NOTIFICATION: 6491 seq_printf(m, "%shas cleared death notification\n", prefix); 6492 break; 6493 case BINDER_WORK_FROZEN_BINDER: 6494 seq_printf(m, "%shas frozen binder\n", prefix); 6495 break; 6496 case BINDER_WORK_CLEAR_FREEZE_NOTIFICATION: 6497 seq_printf(m, "%shas cleared freeze notification\n", prefix); 6498 break; 6499 default: 6500 seq_printf(m, "%sunknown work: type %d\n", prefix, w->type); 6501 break; 6502 } 6503 } 6504 6505 static void print_binder_thread_ilocked(struct seq_file *m, 6506 struct binder_thread *thread, 6507 bool print_always, bool hash_ptrs) 6508 { 6509 struct binder_transaction *t; 6510 struct binder_work *w; 6511 size_t start_pos = m->count; 6512 size_t header_pos; 6513 6514 seq_printf(m, " thread %d: l %02x need_return %d tr %d\n", 6515 thread->pid, thread->looper, 6516 thread->looper_need_return, 6517 atomic_read(&thread->tmp_ref)); 6518 header_pos = m->count; 6519 t = thread->transaction_stack; 6520 while (t) { 6521 if (t->from == thread) { 6522 print_binder_transaction_ilocked(m, thread->proc, 6523 " outgoing transaction", t); 6524 t = t->from_parent; 6525 } else if (t->to_thread == thread) { 6526 print_binder_transaction_ilocked(m, thread->proc, 6527 " incoming transaction", t); 6528 t = t->to_parent; 6529 } else { 6530 print_binder_transaction_ilocked(m, thread->proc, 6531 " bad transaction", t); 6532 t = NULL; 6533 } 6534 } 6535 list_for_each_entry(w, &thread->todo, entry) { 6536 print_binder_work_ilocked(m, thread->proc, " ", 6537 " pending transaction", 6538 w, hash_ptrs); 6539 } 6540 if (!print_always && m->count == header_pos) 6541 m->count = start_pos; 6542 } 6543 6544 static void print_binder_node_nilocked(struct seq_file *m, 6545 struct binder_node *node, 6546 bool hash_ptrs) 6547 { 6548 struct binder_ref *ref; 6549 struct binder_work *w; 6550 int count; 6551 6552 count = hlist_count_nodes(&node->refs); 6553 6554 if (hash_ptrs) 6555 seq_printf(m, " node %d: u%p c%p", node->debug_id, 6556 (void *)(long)node->ptr, (void *)(long)node->cookie); 6557 else 6558 seq_printf(m, " node %d: u%016llx c%016llx", node->debug_id, 6559 (u64)node->ptr, (u64)node->cookie); 6560 seq_printf(m, " hs %d hw %d ls %d lw %d is %d iw %d tr %d", 6561 node->has_strong_ref, node->has_weak_ref, 6562 node->local_strong_refs, node->local_weak_refs, 6563 node->internal_strong_refs, count, node->tmp_refs); 6564 if (count) { 6565 seq_puts(m, " proc"); 6566 hlist_for_each_entry(ref, &node->refs, node_entry) 6567 seq_printf(m, " %d", ref->proc->pid); 6568 } 6569 seq_puts(m, "\n"); 6570 if (node->proc) { 6571 list_for_each_entry(w, &node->async_todo, entry) 6572 print_binder_work_ilocked(m, node->proc, " ", 6573 " pending async transaction", 6574 w, hash_ptrs); 6575 } 6576 } 6577 6578 static void print_binder_ref_olocked(struct seq_file *m, 6579 struct binder_ref *ref) 6580 { 6581 binder_node_lock(ref->node); 6582 seq_printf(m, " ref %d: desc %d %snode %d s %d w %d d %pK\n", 6583 ref->data.debug_id, ref->data.desc, 6584 ref->node->proc ? "" : "dead ", 6585 ref->node->debug_id, ref->data.strong, 6586 ref->data.weak, ref->death); 6587 binder_node_unlock(ref->node); 6588 } 6589 6590 /** 6591 * print_next_binder_node_ilocked() - Print binder_node from a locked list 6592 * @m: struct seq_file for output via seq_printf() 6593 * @proc: struct binder_proc we hold the inner_proc_lock to (if any) 6594 * @node: struct binder_node to print fields of 6595 * @prev_node: struct binder_node we hold a temporary reference to (if any) 6596 * @hash_ptrs: whether to hash @node's binder_uintptr_t fields 6597 * 6598 * Helper function to handle synchronization around printing a struct 6599 * binder_node while iterating through @proc->nodes or the dead nodes list. 6600 * Caller must hold either @proc->inner_lock (for live nodes) or 6601 * binder_dead_nodes_lock. This lock will be released during the body of this 6602 * function, but it will be reacquired before returning to the caller. 6603 * 6604 * Return: pointer to the struct binder_node we hold a tmpref on 6605 */ 6606 static struct binder_node * 6607 print_next_binder_node_ilocked(struct seq_file *m, struct binder_proc *proc, 6608 struct binder_node *node, 6609 struct binder_node *prev_node, bool hash_ptrs) 6610 { 6611 /* 6612 * Take a temporary reference on the node so that isn't freed while 6613 * we print it. 6614 */ 6615 binder_inc_node_tmpref_ilocked(node); 6616 /* 6617 * Live nodes need to drop the inner proc lock and dead nodes need to 6618 * drop the binder_dead_nodes_lock before trying to take the node lock. 6619 */ 6620 if (proc) 6621 binder_inner_proc_unlock(proc); 6622 else 6623 spin_unlock(&binder_dead_nodes_lock); 6624 if (prev_node) 6625 binder_put_node(prev_node); 6626 binder_node_inner_lock(node); 6627 print_binder_node_nilocked(m, node, hash_ptrs); 6628 binder_node_inner_unlock(node); 6629 if (proc) 6630 binder_inner_proc_lock(proc); 6631 else 6632 spin_lock(&binder_dead_nodes_lock); 6633 return node; 6634 } 6635 6636 static void print_binder_proc(struct seq_file *m, struct binder_proc *proc, 6637 bool print_all, bool hash_ptrs) 6638 { 6639 struct binder_work *w; 6640 struct rb_node *n; 6641 size_t start_pos = m->count; 6642 size_t header_pos; 6643 struct binder_node *last_node = NULL; 6644 6645 seq_printf(m, "proc %d\n", proc->pid); 6646 seq_printf(m, "context %s\n", proc->context->name); 6647 header_pos = m->count; 6648 6649 binder_inner_proc_lock(proc); 6650 for (n = rb_first(&proc->threads); n; n = rb_next(n)) 6651 print_binder_thread_ilocked(m, rb_entry(n, struct binder_thread, 6652 rb_node), print_all, hash_ptrs); 6653 6654 for (n = rb_first(&proc->nodes); n; n = rb_next(n)) { 6655 struct binder_node *node = rb_entry(n, struct binder_node, 6656 rb_node); 6657 if (!print_all && !node->has_async_transaction) 6658 continue; 6659 6660 last_node = print_next_binder_node_ilocked(m, proc, node, 6661 last_node, 6662 hash_ptrs); 6663 } 6664 binder_inner_proc_unlock(proc); 6665 if (last_node) 6666 binder_put_node(last_node); 6667 6668 if (print_all) { 6669 binder_proc_lock(proc); 6670 for (n = rb_first(&proc->refs_by_desc); n; n = rb_next(n)) 6671 print_binder_ref_olocked(m, rb_entry(n, 6672 struct binder_ref, 6673 rb_node_desc)); 6674 binder_proc_unlock(proc); 6675 } 6676 binder_alloc_print_allocated(m, &proc->alloc); 6677 binder_inner_proc_lock(proc); 6678 list_for_each_entry(w, &proc->todo, entry) 6679 print_binder_work_ilocked(m, proc, " ", 6680 " pending transaction", w, 6681 hash_ptrs); 6682 list_for_each_entry(w, &proc->delivered_death, entry) { 6683 seq_puts(m, " has delivered dead binder\n"); 6684 break; 6685 } 6686 list_for_each_entry(w, &proc->delivered_freeze, entry) { 6687 seq_puts(m, " has delivered freeze binder\n"); 6688 break; 6689 } 6690 binder_inner_proc_unlock(proc); 6691 if (!print_all && m->count == header_pos) 6692 m->count = start_pos; 6693 } 6694 6695 static const char * const binder_return_strings[] = { 6696 "BR_ERROR", 6697 "BR_OK", 6698 "BR_TRANSACTION", 6699 "BR_REPLY", 6700 "BR_ACQUIRE_RESULT", 6701 "BR_DEAD_REPLY", 6702 "BR_TRANSACTION_COMPLETE", 6703 "BR_INCREFS", 6704 "BR_ACQUIRE", 6705 "BR_RELEASE", 6706 "BR_DECREFS", 6707 "BR_ATTEMPT_ACQUIRE", 6708 "BR_NOOP", 6709 "BR_SPAWN_LOOPER", 6710 "BR_FINISHED", 6711 "BR_DEAD_BINDER", 6712 "BR_CLEAR_DEATH_NOTIFICATION_DONE", 6713 "BR_FAILED_REPLY", 6714 "BR_FROZEN_REPLY", 6715 "BR_ONEWAY_SPAM_SUSPECT", 6716 "BR_TRANSACTION_PENDING_FROZEN", 6717 "BR_FROZEN_BINDER", 6718 "BR_CLEAR_FREEZE_NOTIFICATION_DONE", 6719 }; 6720 6721 static const char * const binder_command_strings[] = { 6722 "BC_TRANSACTION", 6723 "BC_REPLY", 6724 "BC_ACQUIRE_RESULT", 6725 "BC_FREE_BUFFER", 6726 "BC_INCREFS", 6727 "BC_ACQUIRE", 6728 "BC_RELEASE", 6729 "BC_DECREFS", 6730 "BC_INCREFS_DONE", 6731 "BC_ACQUIRE_DONE", 6732 "BC_ATTEMPT_ACQUIRE", 6733 "BC_REGISTER_LOOPER", 6734 "BC_ENTER_LOOPER", 6735 "BC_EXIT_LOOPER", 6736 "BC_REQUEST_DEATH_NOTIFICATION", 6737 "BC_CLEAR_DEATH_NOTIFICATION", 6738 "BC_DEAD_BINDER_DONE", 6739 "BC_TRANSACTION_SG", 6740 "BC_REPLY_SG", 6741 "BC_REQUEST_FREEZE_NOTIFICATION", 6742 "BC_CLEAR_FREEZE_NOTIFICATION", 6743 "BC_FREEZE_NOTIFICATION_DONE", 6744 }; 6745 6746 static const char * const binder_objstat_strings[] = { 6747 "proc", 6748 "thread", 6749 "node", 6750 "ref", 6751 "death", 6752 "transaction", 6753 "transaction_complete", 6754 "freeze", 6755 }; 6756 6757 static void print_binder_stats(struct seq_file *m, const char *prefix, 6758 struct binder_stats *stats) 6759 { 6760 int i; 6761 6762 BUILD_BUG_ON(ARRAY_SIZE(stats->bc) != 6763 ARRAY_SIZE(binder_command_strings)); 6764 for (i = 0; i < ARRAY_SIZE(stats->bc); i++) { 6765 int temp = atomic_read(&stats->bc[i]); 6766 6767 if (temp) 6768 seq_printf(m, "%s%s: %d\n", prefix, 6769 binder_command_strings[i], temp); 6770 } 6771 6772 BUILD_BUG_ON(ARRAY_SIZE(stats->br) != 6773 ARRAY_SIZE(binder_return_strings)); 6774 for (i = 0; i < ARRAY_SIZE(stats->br); i++) { 6775 int temp = atomic_read(&stats->br[i]); 6776 6777 if (temp) 6778 seq_printf(m, "%s%s: %d\n", prefix, 6779 binder_return_strings[i], temp); 6780 } 6781 6782 BUILD_BUG_ON(ARRAY_SIZE(stats->obj_created) != 6783 ARRAY_SIZE(binder_objstat_strings)); 6784 BUILD_BUG_ON(ARRAY_SIZE(stats->obj_created) != 6785 ARRAY_SIZE(stats->obj_deleted)); 6786 for (i = 0; i < ARRAY_SIZE(stats->obj_created); i++) { 6787 int created = atomic_read(&stats->obj_created[i]); 6788 int deleted = atomic_read(&stats->obj_deleted[i]); 6789 6790 if (created || deleted) 6791 seq_printf(m, "%s%s: active %d total %d\n", 6792 prefix, 6793 binder_objstat_strings[i], 6794 created - deleted, 6795 created); 6796 } 6797 } 6798 6799 static void print_binder_proc_stats(struct seq_file *m, 6800 struct binder_proc *proc) 6801 { 6802 struct binder_work *w; 6803 struct binder_thread *thread; 6804 struct rb_node *n; 6805 int count, strong, weak, ready_threads; 6806 size_t free_async_space = 6807 binder_alloc_get_free_async_space(&proc->alloc); 6808 6809 seq_printf(m, "proc %d\n", proc->pid); 6810 seq_printf(m, "context %s\n", proc->context->name); 6811 count = 0; 6812 ready_threads = 0; 6813 binder_inner_proc_lock(proc); 6814 for (n = rb_first(&proc->threads); n; n = rb_next(n)) 6815 count++; 6816 6817 list_for_each_entry(thread, &proc->waiting_threads, waiting_thread_node) 6818 ready_threads++; 6819 6820 seq_printf(m, " threads: %d\n", count); 6821 seq_printf(m, " requested threads: %d+%d/%d\n" 6822 " ready threads %d\n" 6823 " free async space %zd\n", proc->requested_threads, 6824 proc->requested_threads_started, proc->max_threads, 6825 ready_threads, 6826 free_async_space); 6827 count = 0; 6828 for (n = rb_first(&proc->nodes); n; n = rb_next(n)) 6829 count++; 6830 binder_inner_proc_unlock(proc); 6831 seq_printf(m, " nodes: %d\n", count); 6832 count = 0; 6833 strong = 0; 6834 weak = 0; 6835 binder_proc_lock(proc); 6836 for (n = rb_first(&proc->refs_by_desc); n; n = rb_next(n)) { 6837 struct binder_ref *ref = rb_entry(n, struct binder_ref, 6838 rb_node_desc); 6839 count++; 6840 strong += ref->data.strong; 6841 weak += ref->data.weak; 6842 } 6843 binder_proc_unlock(proc); 6844 seq_printf(m, " refs: %d s %d w %d\n", count, strong, weak); 6845 6846 count = binder_alloc_get_allocated_count(&proc->alloc); 6847 seq_printf(m, " buffers: %d\n", count); 6848 6849 binder_alloc_print_pages(m, &proc->alloc); 6850 6851 count = 0; 6852 binder_inner_proc_lock(proc); 6853 list_for_each_entry(w, &proc->todo, entry) { 6854 if (w->type == BINDER_WORK_TRANSACTION) 6855 count++; 6856 } 6857 binder_inner_proc_unlock(proc); 6858 seq_printf(m, " pending transactions: %d\n", count); 6859 6860 print_binder_stats(m, " ", &proc->stats); 6861 } 6862 6863 static void print_binder_state(struct seq_file *m, bool hash_ptrs) 6864 { 6865 struct binder_proc *proc; 6866 struct binder_node *node; 6867 struct binder_node *last_node = NULL; 6868 6869 seq_puts(m, "binder state:\n"); 6870 6871 spin_lock(&binder_dead_nodes_lock); 6872 if (!hlist_empty(&binder_dead_nodes)) 6873 seq_puts(m, "dead nodes:\n"); 6874 hlist_for_each_entry(node, &binder_dead_nodes, dead_node) 6875 last_node = print_next_binder_node_ilocked(m, NULL, node, 6876 last_node, 6877 hash_ptrs); 6878 spin_unlock(&binder_dead_nodes_lock); 6879 if (last_node) 6880 binder_put_node(last_node); 6881 6882 mutex_lock(&binder_procs_lock); 6883 hlist_for_each_entry(proc, &binder_procs, proc_node) 6884 print_binder_proc(m, proc, true, hash_ptrs); 6885 mutex_unlock(&binder_procs_lock); 6886 } 6887 6888 static void print_binder_transactions(struct seq_file *m, bool hash_ptrs) 6889 { 6890 struct binder_proc *proc; 6891 6892 seq_puts(m, "binder transactions:\n"); 6893 mutex_lock(&binder_procs_lock); 6894 hlist_for_each_entry(proc, &binder_procs, proc_node) 6895 print_binder_proc(m, proc, false, hash_ptrs); 6896 mutex_unlock(&binder_procs_lock); 6897 } 6898 6899 static int state_show(struct seq_file *m, void *unused) 6900 { 6901 print_binder_state(m, false); 6902 return 0; 6903 } 6904 6905 static int state_hashed_show(struct seq_file *m, void *unused) 6906 { 6907 print_binder_state(m, true); 6908 return 0; 6909 } 6910 6911 static int stats_show(struct seq_file *m, void *unused) 6912 { 6913 struct binder_proc *proc; 6914 6915 seq_puts(m, "binder stats:\n"); 6916 6917 print_binder_stats(m, "", &binder_stats); 6918 6919 mutex_lock(&binder_procs_lock); 6920 hlist_for_each_entry(proc, &binder_procs, proc_node) 6921 print_binder_proc_stats(m, proc); 6922 mutex_unlock(&binder_procs_lock); 6923 6924 return 0; 6925 } 6926 6927 static int transactions_show(struct seq_file *m, void *unused) 6928 { 6929 print_binder_transactions(m, false); 6930 return 0; 6931 } 6932 6933 static int transactions_hashed_show(struct seq_file *m, void *unused) 6934 { 6935 print_binder_transactions(m, true); 6936 return 0; 6937 } 6938 6939 static int proc_show(struct seq_file *m, void *unused) 6940 { 6941 struct binder_proc *itr; 6942 int pid = (unsigned long)m->private; 6943 6944 guard(mutex)(&binder_procs_lock); 6945 hlist_for_each_entry(itr, &binder_procs, proc_node) { 6946 if (itr->pid == pid) { 6947 seq_puts(m, "binder proc state:\n"); 6948 print_binder_proc(m, itr, true, false); 6949 } 6950 } 6951 6952 return 0; 6953 } 6954 6955 static void print_binder_transaction_log_entry(struct seq_file *m, 6956 struct binder_transaction_log_entry *e) 6957 { 6958 int debug_id = READ_ONCE(e->debug_id_done); 6959 /* 6960 * read barrier to guarantee debug_id_done read before 6961 * we print the log values 6962 */ 6963 smp_rmb(); 6964 seq_printf(m, 6965 "%d: %s from %d:%d to %d:%d context %s node %d handle %d size %d:%d ret %d/%d l=%d", 6966 e->debug_id, (e->call_type == 2) ? "reply" : 6967 ((e->call_type == 1) ? "async" : "call "), e->from_proc, 6968 e->from_thread, e->to_proc, e->to_thread, e->context_name, 6969 e->to_node, e->target_handle, e->data_size, e->offsets_size, 6970 e->return_error, e->return_error_param, 6971 e->return_error_line); 6972 /* 6973 * read-barrier to guarantee read of debug_id_done after 6974 * done printing the fields of the entry 6975 */ 6976 smp_rmb(); 6977 seq_printf(m, debug_id && debug_id == READ_ONCE(e->debug_id_done) ? 6978 "\n" : " (incomplete)\n"); 6979 } 6980 6981 static int transaction_log_show(struct seq_file *m, void *unused) 6982 { 6983 struct binder_transaction_log *log = m->private; 6984 unsigned int log_cur = atomic_read(&log->cur); 6985 unsigned int count; 6986 unsigned int cur; 6987 int i; 6988 6989 count = log_cur + 1; 6990 cur = count < ARRAY_SIZE(log->entry) && !log->full ? 6991 0 : count % ARRAY_SIZE(log->entry); 6992 if (count > ARRAY_SIZE(log->entry) || log->full) 6993 count = ARRAY_SIZE(log->entry); 6994 for (i = 0; i < count; i++) { 6995 unsigned int index = cur++ % ARRAY_SIZE(log->entry); 6996 6997 print_binder_transaction_log_entry(m, &log->entry[index]); 6998 } 6999 return 0; 7000 } 7001 7002 const struct file_operations binder_fops = { 7003 .owner = THIS_MODULE, 7004 .poll = binder_poll, 7005 .unlocked_ioctl = binder_ioctl, 7006 .compat_ioctl = compat_ptr_ioctl, 7007 .mmap = binder_mmap, 7008 .open = binder_open, 7009 .flush = binder_flush, 7010 .release = binder_release, 7011 }; 7012 7013 DEFINE_SHOW_ATTRIBUTE(state); 7014 DEFINE_SHOW_ATTRIBUTE(state_hashed); 7015 DEFINE_SHOW_ATTRIBUTE(stats); 7016 DEFINE_SHOW_ATTRIBUTE(transactions); 7017 DEFINE_SHOW_ATTRIBUTE(transactions_hashed); 7018 DEFINE_SHOW_ATTRIBUTE(transaction_log); 7019 7020 const struct binder_debugfs_entry binder_debugfs_entries[] = { 7021 { 7022 .name = "state", 7023 .mode = 0444, 7024 .fops = &state_fops, 7025 .data = NULL, 7026 }, 7027 { 7028 .name = "state_hashed", 7029 .mode = 0444, 7030 .fops = &state_hashed_fops, 7031 .data = NULL, 7032 }, 7033 { 7034 .name = "stats", 7035 .mode = 0444, 7036 .fops = &stats_fops, 7037 .data = NULL, 7038 }, 7039 { 7040 .name = "transactions", 7041 .mode = 0444, 7042 .fops = &transactions_fops, 7043 .data = NULL, 7044 }, 7045 { 7046 .name = "transactions_hashed", 7047 .mode = 0444, 7048 .fops = &transactions_hashed_fops, 7049 .data = NULL, 7050 }, 7051 { 7052 .name = "transaction_log", 7053 .mode = 0444, 7054 .fops = &transaction_log_fops, 7055 .data = &binder_transaction_log, 7056 }, 7057 { 7058 .name = "failed_transaction_log", 7059 .mode = 0444, 7060 .fops = &transaction_log_fops, 7061 .data = &binder_transaction_log_failed, 7062 }, 7063 {} /* terminator */ 7064 }; 7065 7066 void binder_add_device(struct binder_device *device) 7067 { 7068 guard(spinlock)(&binder_devices_lock); 7069 hlist_add_head(&device->hlist, &binder_devices); 7070 } 7071 7072 void binder_remove_device(struct binder_device *device) 7073 { 7074 guard(spinlock)(&binder_devices_lock); 7075 hlist_del_init(&device->hlist); 7076 } 7077 7078 static int __init init_binder_device(const char *name) 7079 { 7080 int ret; 7081 struct binder_device *binder_device; 7082 7083 binder_device = kzalloc_obj(*binder_device); 7084 if (!binder_device) 7085 return -ENOMEM; 7086 7087 binder_device->miscdev.fops = &binder_fops; 7088 binder_device->miscdev.minor = MISC_DYNAMIC_MINOR; 7089 binder_device->miscdev.name = name; 7090 7091 refcount_set(&binder_device->ref, 1); 7092 binder_device->context.binder_context_mgr_uid = INVALID_UID; 7093 binder_device->context.name = name; 7094 mutex_init(&binder_device->context.context_mgr_node_lock); 7095 7096 ret = misc_register(&binder_device->miscdev); 7097 if (ret < 0) { 7098 kfree(binder_device); 7099 return ret; 7100 } 7101 7102 binder_add_device(binder_device); 7103 7104 return ret; 7105 } 7106 7107 static int __init binder_init(void) 7108 { 7109 int ret; 7110 char *device_name, *device_tmp; 7111 struct binder_device *device; 7112 struct hlist_node *tmp; 7113 char *device_names = NULL; 7114 const struct binder_debugfs_entry *db_entry; 7115 7116 ret = binder_alloc_shrinker_init(); 7117 if (ret) 7118 return ret; 7119 7120 atomic_set(&binder_transaction_log.cur, ~0U); 7121 atomic_set(&binder_transaction_log_failed.cur, ~0U); 7122 7123 binder_debugfs_dir_entry_root = debugfs_create_dir("binder", NULL); 7124 7125 binder_for_each_debugfs_entry(db_entry) 7126 debugfs_create_file(db_entry->name, 7127 db_entry->mode, 7128 binder_debugfs_dir_entry_root, 7129 db_entry->data, 7130 db_entry->fops); 7131 7132 binder_debugfs_dir_entry_proc = debugfs_create_dir("proc", 7133 binder_debugfs_dir_entry_root); 7134 7135 if (!IS_ENABLED(CONFIG_ANDROID_BINDERFS) && 7136 strcmp(binder_devices_param, "") != 0) { 7137 /* 7138 * Copy the module_parameter string, because we don't want to 7139 * tokenize it in-place. 7140 */ 7141 device_names = kstrdup(binder_devices_param, GFP_KERNEL); 7142 if (!device_names) { 7143 ret = -ENOMEM; 7144 goto err_alloc_device_names_failed; 7145 } 7146 7147 device_tmp = device_names; 7148 while ((device_name = strsep(&device_tmp, ","))) { 7149 ret = init_binder_device(device_name); 7150 if (ret) 7151 goto err_init_binder_device_failed; 7152 } 7153 } 7154 7155 ret = genl_register_family(&binder_nl_family); 7156 if (ret) 7157 goto err_init_binder_device_failed; 7158 7159 ret = init_binderfs(); 7160 if (ret) 7161 goto err_init_binderfs_failed; 7162 7163 return ret; 7164 7165 err_init_binderfs_failed: 7166 genl_unregister_family(&binder_nl_family); 7167 7168 err_init_binder_device_failed: 7169 hlist_for_each_entry_safe(device, tmp, &binder_devices, hlist) { 7170 misc_deregister(&device->miscdev); 7171 binder_remove_device(device); 7172 kfree(device); 7173 } 7174 7175 kfree(device_names); 7176 7177 err_alloc_device_names_failed: 7178 debugfs_remove_recursive(binder_debugfs_dir_entry_root); 7179 binder_alloc_shrinker_exit(); 7180 7181 return ret; 7182 } 7183 7184 device_initcall(binder_init); 7185 7186 #define CREATE_TRACE_POINTS 7187 #include "binder_trace.h" 7188