From nobody Sat Jul 25 21:20:40 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6E6D81C860C; Mon, 13 Jul 2026 12:35:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783946132; cv=none; b=q3gA9B1FohCRJA1yADTtjCCGROdwYw4gdttuvLoKeVqISZd4P1wbhCuljf/Zdcv11342o4k0V7IVidIrSHCuXzrBQx/N26Cr0R0vPCWDs/8OIYnya6ibaB0K7cGHqNc2a/GCNRWtRlcQ0uRW47xi/qW9BIC9dH1trdMsfjYfkQQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783946132; c=relaxed/simple; bh=FPOcRJpsJxmK9Lx1x3CvhzQCvpK3B1kl/Ior1UdgXh8=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=U9BWxP3GBdhWPTwNDvoevP5a4zu6xHEhI0N6oXyVF46iqtUJg5m2VZQPD1G/OeH1HEvZM9PzVNeDvyXITIrT7PyEVcQXufs1hrxGR3M7Et1VIkD2RolrKlg1o8PMBhPH3XJ19qg0h0P4A/WbKWuEgI/wLo5g2jWbW2C6uCIQsqg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=gJHToF82; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="gJHToF82" Received: by smtp.kernel.org (Postfix) with ESMTPS id 0CB04C2BCF4; Mon, 13 Jul 2026 12:35:32 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1783946132; bh=FPOcRJpsJxmK9Lx1x3CvhzQCvpK3B1kl/Ior1UdgXh8=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=gJHToF82kTVIEu/O644q+p2YVMiloqI1qUMzbVvo2RBWFbqenzWIGGK3I45aVtMMx U/9/snkQA+CgJoyzrN37YDv1Ab20w44DwJHCv1GiIp9Bgb4E3NAoZDOtmzqJd7uGbS U4afz/+9S8Jbhtcgq3GcdJ7NT0vqfi6VZakIxv92PwOW4Oa3yz1IObWF8u2VmW9NMz x9lfEseb8vUcxmT/nynYTBPKY0wAr/y6Q8mc4cNpgNrAdTMGKgQzDbyoyAkDhMml/L BoVlRE+zaXwCruk6X9Vpo9LekAxJXCcjARoF6aPdYObfh2XDJyqK5LuWwS2MU8NkYF 9FG0CUiek8l1w== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E339CC44507; Mon, 13 Jul 2026 12:35:31 +0000 (UTC) From: Jahnavi MN via B4 Relay Date: Mon, 13 Jul 2026 12:35:23 +0000 Subject: [PATCH v3 1/7] rust_binder: Add dynamic debug logging mask Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260713-rust_binder_debug_mask-v3-1-0de91bbbbf69@google.com> References: <20260713-rust_binder_debug_mask-v3-0-0de91bbbbf69@google.com> In-Reply-To: <20260713-rust_binder_debug_mask-v3-0-0de91bbbbf69@google.com> To: Greg Kroah-Hartman , =?utf-8?q?Arve_Hj=C3=B8nnev=C3=A5g?= , Todd Kjos , Christian Brauner , Carlos Llamas , Alice Ryhl , Miguel Ojeda , Boqun Feng , Gary Guo , =?utf-8?q?Bj=C3=B6rn_Roy_Baron?= , Benno Lossin , Andreas Hindborg , Trevor Gross , Danilo Krummrich , Daniel Almeida , Tamir Duberstein , Alexandre Courbot , =?utf-8?q?Onur_=C3=96zkan?= Cc: linux-kernel@vger.kernel.org, rust-for-linux@vger.kernel.org, Jahnavi MN X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=ed25519-sha256; t=1783946130; l=7221; i=jahnavimn@google.com; s=20260702; h=from:subject:message-id; bh=msbj099PwXU9qBKAHKkWvtKfvYRAvnNuDuqPTXT8ez8=; b=nUl68Zd/00HhvLrfhJwumGgjs1iKtRZZtE5TLlTTgTnXK12DHTjp1FuXb4BJQ+2qi8NHDashF OAAC+BT1IiCD6quhO0pacg9n8i3OQWGjqNvS8khRnvdbVLmrGrW7K4S X-Developer-Key: i=jahnavimn@google.com; a=ed25519; pk=9aLfw3FepTOJwTS7jRXm7pDH87eBeZMXBPrqwU0//RE= X-Endpoint-Received: by B4 Relay for jahnavimn@google.com/20260702 with auth_id=849 X-Original-From: Jahnavi MN Reply-To: jahnavimn@google.com From: Jahnavi MN Implement a dynamic debug logging mask (`debug_mask`) for the `rust_binder` module to allow dynamic runtime configuration of log levels. This enables parity with the legacy C driver's debug mask. Since the Rust `module!` macro in the current kernel build does not yet support declaring module parameters directly in Rust, we define the `debug_mask` variable in Rust as an `Atomic` exported via FFI using `#[no_mangle]`, and link to it as `extern` in a C companion file to expose it to the kernel runtime. To verify the setup, instrument process lifecycle events (open, flush, and release) in `process.rs` under the new `BINDER_DEBUG_OPEN_CLOSE` logging mask. These entry-point events are chosen for initial validation because they represent the start of the Binder lifecycle and occur at low frequency, allowing simple runtime verification of the dynamic toggle without log noise. Reviewed-by: Carlos Llamas Reviewed-by: Alice Ryhl Signed-off-by: Jahnavi MN --- drivers/android/binder/debug.rs | 76 ++++++++++++++++++++++++++= ++++ drivers/android/binder/process.rs | 7 ++- drivers/android/binder/rust_binder_main.rs | 2 + drivers/android/binder/rust_binderfs.c | 3 ++ rust/kernel/task.rs | 7 +++ 5 files changed, 94 insertions(+), 1 deletion(-) diff --git a/drivers/android/binder/debug.rs b/drivers/android/binder/debug= .rs new file mode 100644 index 000000000000..824b10c004c3 --- /dev/null +++ b/drivers/android/binder/debug.rs @@ -0,0 +1,76 @@ +// SPDX-License-Identifier: GPL-2.0 +// Copyright (C) 2026 Google LLC. + +//! Binder debugging helpers. + +#![allow(dead_code)] + +use kernel::bits::bit_u32; +use kernel::sync::atomic::Atomic; + +kernel::impl_flags!( + /// Represents multiple debug mask flags. + #[derive(Debug, Clone, Default, Copy, PartialEq, Eq)] + pub struct DebugMasks(u32); + + /// Represents a single debug mask category. + #[derive(Debug, Clone, Copy, PartialEq, Eq)] + pub enum DebugMask { + UserError =3D bit_u32(0), + FailedTransaction =3D bit_u32(1), + DeadTransaction =3D bit_u32(2), + OpenClose =3D bit_u32(3), + DeadBinder =3D bit_u32(4), + DeathNotification =3D bit_u32(5), + ReadWrite =3D bit_u32(6), + UserRefs =3D bit_u32(7), + Threads =3D bit_u32(8), + Transaction =3D bit_u32(9), + TransactionComplete =3D bit_u32(10), + FreeBuffer =3D bit_u32(11), + InternalRefs =3D bit_u32(12), + PriorityCap =3D bit_u32(13), + Spinlocks =3D bit_u32(14), + } +); + +#[no_mangle] +pub(crate) static rust_binder_debug_mask: Atomic =3D Atomic::new( + (DebugMask::UserError as u32) + | (DebugMask::FailedTransaction as u32) + | (DebugMask::DeadTransaction as u32), +); + +/// Checks if the given debug logging category is enabled in the mask. +pub(crate) fn debug_mask_enabled(mask: DebugMask) -> bool { + let current_mask =3D rust_binder_debug_mask.load(kernel::sync::atomic:= :Relaxed); + DebugMasks(current_mask).contains(mask) +} + +/// Prints a debug log if the specified mask category is enabled. +#[macro_export] +macro_rules! binder_debug { + // Rule to explicitly specify a PID (used in kworkers). + (pid=3D$pid:expr, $mask:ident, $($arg:tt)*) =3D> { + if $crate::debug::debug_mask_enabled($crate::debug::DebugMask::$ma= sk) { + kernel::pr_info!( + "{}: {}\n", + $pid, + kernel::prelude::fmt!($($arg)*) + ); + } + }; + + // Default rule (automatically prepends "PID:TID" of the current calli= ng thread). + ($mask:ident, $($arg:tt)*) =3D> { + if $crate::debug::debug_mask_enabled($crate::debug::DebugMask::$ma= sk) { + let thread =3D kernel::current!(); + kernel::pr_info!( + "{}:{} {}\n", + thread.tgid(), + thread.pid(), + kernel::prelude::fmt!($($arg)*) + ); + } + }; +} diff --git a/drivers/android/binder/process.rs b/drivers/android/binder/pro= cess.rs index 1abeb83684e4..6dd39939e7ae 100644 --- a/drivers/android/binder/process.rs +++ b/drivers/android/binder/process.rs @@ -1327,6 +1327,7 @@ pub(crate) fn lock_with_nodes(&self) -> WithNodes<'_>= { } =20 fn deferred_flush(&self) { + binder_debug!(pid =3D self.task.pid(), OpenClose, "flushing proces= s"); let inner =3D self.inner.lock(); for thread in inner.threads.values() { thread.exit_looper(); @@ -1334,6 +1335,8 @@ fn deferred_flush(&self) { } =20 fn deferred_release(self: Arc) { + binder_debug!(pid =3D self.task.pid(), OpenClose, "releasing proce= ss"); + let is_manager =3D { let mut inner =3D self.inner.lock(); inner.is_dead =3D true; @@ -1627,7 +1630,9 @@ fn ioctl_write_read( /// The file operations supported by `Process`. impl Process { pub(crate) fn open(ctx: ArcBorrow<'_, Context>, file: &File) -> Result= > { - Self::new(ctx.into(), ARef::from(file.cred())) + let proc =3D Self::new(ctx.into(), ARef::from(file.cred()))?; + binder_debug!(OpenClose, "opened process"); + Ok(proc) } =20 pub(crate) fn release(this: Arc, _file: &File) { diff --git a/drivers/android/binder/rust_binder_main.rs b/drivers/android/b= inder/rust_binder_main.rs index 432390aab25b..29829cb210a4 100644 --- a/drivers/android/binder/rust_binder_main.rs +++ b/drivers/android/binder/rust_binder_main.rs @@ -31,6 +31,8 @@ mod context; mod deferred_close; mod defs; +#[macro_use] +mod debug; mod error; mod node; mod page_range; diff --git a/drivers/android/binder/rust_binderfs.c b/drivers/android/binde= r/rust_binderfs.c index ade1c4d92499..300cc65562d1 100644 --- a/drivers/android/binder/rust_binderfs.c +++ b/drivers/android/binder/rust_binderfs.c @@ -51,6 +51,9 @@ DEFINE_SHOW_ATTRIBUTE(rust_binder_proc); char *rust_binder_devices_param =3D CONFIG_ANDROID_BINDER_DEVICES; module_param_named(rust_devices, rust_binder_devices_param, charp, 0444); =20 +extern u32 rust_binder_debug_mask; +module_param_named(debug_mask, rust_binder_debug_mask, uint, 0644); + static dev_t binderfs_dev; static DEFINE_MUTEX(binderfs_minors_mutex); static DEFINE_IDA(binderfs_minors); diff --git a/rust/kernel/task.rs b/rust/kernel/task.rs index 38273f4eedb5..1b290c61714d 100644 --- a/rust/kernel/task.rs +++ b/rust/kernel/task.rs @@ -210,6 +210,13 @@ pub fn pid(&self) -> Pid { unsafe { *ptr::addr_of!((*self.as_ptr()).pid) } } =20 + /// Returns the TGID (Thread Group ID / Process ID) of the given task. + pub fn tgid(&self) -> Pid { + // SAFETY: The tgid of a task never changes after initialization, = so reading this field is + // not a data race. + unsafe { *ptr::addr_of!((*self.as_ptr()).tgid) } + } + /// Returns the UID of the given task. #[inline] pub fn uid(&self) -> Kuid { --=20 2.55.0.795.g602f6c329a-goog From nobody Sat Jul 25 21:20:40 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6E747271A71; Mon, 13 Jul 2026 12:35:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783946132; cv=none; b=sBPjdyCDTt9VqOExaeNGQk/ArAHJrQmCFCEB8eMvO71KMjfgsaxkpWY0cPNIbwbEgKM/WPI+Uv327tD8eUtN1PoSEz6ax0cKFLX5AVzRZA499yKMWnp35ezuvHLgbWpm0cHzuXuYNBWPXPuRKxDEYlAu7SJXAydLrcJ/mH/15GA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783946132; c=relaxed/simple; bh=ZMjGWIqGKLGEc2OHOnUE0lFXnlBz0ipjagGrnfNuT/8=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=j6+INE5ZKUZ2h+q01oE79qLkMfbQ6dr5dknpyLRRkskSu18w06rCdvudT6Rdb9dbjUWca5MTglLWdfQ7wbLpKmOEu6jJn43CeQxzeAcxENYYUQUKXMpfxNJbMpLkscndSv6mdfDYAPqED/6AGrpCaPF7Fa6n5cjeCRS18xCi3ZI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=FFkw0dzA; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="FFkw0dzA" Received: by smtp.kernel.org (Postfix) with ESMTPS id 1F077C2BCB9; Mon, 13 Jul 2026 12:35:32 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1783946132; bh=ZMjGWIqGKLGEc2OHOnUE0lFXnlBz0ipjagGrnfNuT/8=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=FFkw0dzAn1U1e5EtQWGJWdXGXM+8ABcvYx8k0mLDL5jjMF/KEzcILMw5bWD3xYXJC /2jtUzguf+n48o1DeyldRKgbngqQFhJ/KqW5ANSrCZHIZNgOUUzvTlfKZ8Z5B6k4Vu mG46ZuzQdvhMfsTCp3AqGJmRExuxpTXDPoH7sRC2rovRc7p/wz98TACLrBVkMuvqzR 1cdaWbYaa1r0jcLnei/yV9r9CSZ/ISIAPZsrlvwBRhUlW+nsOMj1M+lslSuMlaE5Bv jK+MBJTIXceTIxdB8eNIEATsbwidltNGXEVnsh6u9ZFprn4JvFbFxI0GOVS5AQGDei YUXcMjnMWePqw== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id F2965C44501; Mon, 13 Jul 2026 12:35:31 +0000 (UTC) From: Jahnavi MN via B4 Relay Date: Mon, 13 Jul 2026 12:35:24 +0000 Subject: [PATCH v3 2/7] rust_binder: Implement BINDER_DEBUG_USER_ERROR for freezer-related operation Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260713-rust_binder_debug_mask-v3-2-0de91bbbbf69@google.com> References: <20260713-rust_binder_debug_mask-v3-0-0de91bbbbf69@google.com> In-Reply-To: <20260713-rust_binder_debug_mask-v3-0-0de91bbbbf69@google.com> To: Greg Kroah-Hartman , =?utf-8?q?Arve_Hj=C3=B8nnev=C3=A5g?= , Todd Kjos , Christian Brauner , Carlos Llamas , Alice Ryhl , Miguel Ojeda , Boqun Feng , Gary Guo , =?utf-8?q?Bj=C3=B6rn_Roy_Baron?= , Benno Lossin , Andreas Hindborg , Trevor Gross , Danilo Krummrich , Daniel Almeida , Tamir Duberstein , Alexandre Courbot , =?utf-8?q?Onur_=C3=96zkan?= Cc: linux-kernel@vger.kernel.org, rust-for-linux@vger.kernel.org, Jahnavi MN X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=ed25519-sha256; t=1783946130; l=4969; i=jahnavimn@google.com; s=20260702; h=from:subject:message-id; bh=mOE8lfucp+ZhQzg83Pu34+Skf+PAioBlv/HfP2YLQJw=; b=AOCRSEa+HRPEMcVRM/VJtkNksGDNJA4N5qzBtL2blprukN4UKzrYAyU13OryzxjbdseoG//cu ob4V2q8MFq8A54aThqbtLNyaybjOzPXkN4nS1MNCmtP8h6xJJKPAETs X-Developer-Key: i=jahnavimn@google.com; a=ed25519; pk=9aLfw3FepTOJwTS7jRXm7pDH87eBeZMXBPrqwU0//RE= X-Endpoint-Received: by B4 Relay for jahnavimn@google.com/20260702 with auth_id=849 X-Original-From: Jahnavi MN Reply-To: jahnavimn@google.com From: Jahnavi MN This adds dynamic debug logs for: - Requesting freeze notifications on invalid references, duplicate cookies, or already active registrations. - Completing freeze notifications that are not pending or not found. - Clearing freeze notifications on invalid references, inactive notifications, or cookie mismatches. Reviewed-by: Carlos Llamas Reviewed-by: Alice Ryhl Signed-off-by: Jahnavi MN --- drivers/android/binder/freeze.rs | 40 ++++++++++++++++++++++++++++++------= ---- 1 file changed, 30 insertions(+), 10 deletions(-) diff --git a/drivers/android/binder/freeze.rs b/drivers/android/binder/free= ze.rs index 918c4e98b66f..2c99e0995554 100644 --- a/drivers/android/binder/freeze.rs +++ b/drivers/android/binder/freeze.rs @@ -182,12 +182,15 @@ pub(crate) fn request_freeze_notif( info =3D match node_refs.by_handle.get_mut(&handle) { Some(info) =3D> info, None =3D> { - pr_warn!("BC_REQUEST_FREEZE_NOTIFICATION invalid ref {= }\n", handle); + binder_debug!( + UserError, + "BC_REQUEST_FREEZE_NOTIFICATION invalid ref {handl= e}" + ); return Err(EINVAL); } }; if info.freeze().is_some() { - pr_warn!("BC_REQUEST_FREEZE_NOTIFICATION already set\n"); + binder_debug!(UserError, "BC_REQUEST_FREEZE_NOTIFICATION a= lready set"); return Err(EINVAL); } let node_ref =3D info.node_ref(); @@ -195,7 +198,7 @@ pub(crate) fn request_freeze_notif( =20 if let rbtree::Entry::Occupied(ref dupe) =3D freeze_entry { if !dupe.get().allow_duplicate(&node_ref.node) { - pr_warn!("BC_REQUEST_FREEZE_NOTIFICATION duplicate coo= kie\n"); + binder_debug!(UserError, "BC_REQUEST_FREEZE_NOTIFICATI= ON duplicate cookie"); return Err(EINVAL); } } @@ -260,7 +263,11 @@ pub(crate) fn freeze_notif_done(self: &Arc, read= er: &mut UserSliceReader) let mut node_refs_guard =3D self.node_refs.lock(); let node_refs =3D &mut *node_refs_guard; let Some(freeze) =3D node_refs.freeze_listeners.get_mut(&cookie) e= lse { - pr_warn!("BC_FREEZE_NOTIFICATION_DONE {:016x} not found\n", co= okie.0); + binder_debug!( + UserError, + "BC_FREEZE_NOTIFICATION_DONE {:016x} not found", + cookie.0 + ); return Err(EINVAL); }; let mut clear_msg =3D None; @@ -270,8 +277,9 @@ pub(crate) fn freeze_notif_done(self: &Arc, reade= r: &mut UserSliceReader) freeze.num_cleared_duplicates +=3D 1; } else { if !freeze.is_pending { - pr_warn!( - "BC_FREEZE_NOTIFICATION_DONE {:016x} not pending\n", + binder_debug!( + UserError, + "BC_FREEZE_NOTIFICATION_DONE {:016x} not pending", cookie.0 ); return Err(EINVAL); @@ -300,19 +308,31 @@ pub(crate) fn clear_freeze_notif(self: &Arc, re= ader: &mut UserSliceReader) let mut node_refs_guard =3D self.node_refs.lock(); let node_refs =3D &mut *node_refs_guard; let Some(info) =3D node_refs.by_handle.get_mut(&handle) else { - pr_warn!("BC_CLEAR_FREEZE_NOTIFICATION invalid ref {}\n", hand= le); + binder_debug!( + UserError, + "BC_CLEAR_FREEZE_NOTIFICATION invalid ref {handle}" + ); return Err(EINVAL); }; let Some(info_cookie) =3D info.freeze() else { - pr_warn!("BC_CLEAR_FREEZE_NOTIFICATION freeze notification not= active\n"); + binder_debug!( + UserError, + "BC_CLEAR_FREEZE_NOTIFICATION freeze notification not acti= ve" + ); return Err(EINVAL); }; if *info_cookie !=3D cookie { - pr_warn!("BC_CLEAR_FREEZE_NOTIFICATION freeze notification coo= kie mismatch\n"); + binder_debug!( + UserError, + "BC_CLEAR_FREEZE_NOTIFICATION freeze notification cookie m= ismatch" + ); return Err(EINVAL); } let Some(listener) =3D node_refs.freeze_listeners.get_mut(&cookie)= else { - pr_warn!("BC_CLEAR_FREEZE_NOTIFICATION invalid cookie {}\n", h= andle); + binder_debug!( + UserError, + "BC_CLEAR_FREEZE_NOTIFICATION invalid cookie {handle}" + ); return Err(EINVAL); }; listener.is_clearing =3D true; --=20 2.55.0.795.g602f6c329a-goog From nobody Sat Jul 25 21:20:40 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 719422D2381; Mon, 13 Jul 2026 12:35:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783946132; cv=none; b=NB3h3Fwdzds4Oxanqda5JzRR5CdI+Vh7E27jPcWlD2TABDzfWOZ8ayS+siQShEP5MrvkHMxkVL8nPH3lhmEMf5y/izayx0tare4jFVYLqQaogvoMMtZ46y8Glif1KO2yFl/oR8dFbZtX2FDb+FiNSemakOrtni6m3Zx4xgXyVwc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783946132; c=relaxed/simple; bh=CJ+aBhhFtA++8udCun/MbN6tEPASrA5cJveBWaNa6Tg=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=lSFimQ2nTcqw+01180pBqrmZa1qKPPg9glHQNCNKMArinEWm8twBiliaY9ynZDkVdZP+QxJHvgE4LHoPEXv2H8imfzBfzrHHQoEtv363LWN0maLl/fT317U45OEONSOAgPitg0ZqlO2E8mdvetVensfm//M0rSVe4otdIfAZ0N8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=GGN+72A4; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="GGN+72A4" Received: by smtp.kernel.org (Postfix) with ESMTPS id 29977C2BCFC; Mon, 13 Jul 2026 12:35:32 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1783946132; bh=CJ+aBhhFtA++8udCun/MbN6tEPASrA5cJveBWaNa6Tg=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=GGN+72A4I8rD/LWkIZddqH0L7uHXqGr1/LG8flFphr27Hpdst1/mzl5RxqSWh3l4U dvknWPN1hS6ICJt094zRPdqHruA9dR0sF9zkCLqRENsraDfGHMUWkwj1I8XQu8Bsm2 wDdFpPsORnGAWFQcz1qVvthALHwMe7TLLF7WxxNvDoG3YTmTQNnOvmAbMMB2A3lj+j u01iJQ0Oz1ikfrfEI2fF8e/l9BwC11Ord5U193hXtIMzsC0K2V9Hp34gDt2Yx3NRRg 5k3T/K/OcrDnHBHo1OyYUndEWued5D7Z9kP87Y/ISPVMun6Ru4U1wbIasy5zpl8/Dj HdI2NIpCozzug== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0D156C44509; Mon, 13 Jul 2026 12:35:32 +0000 (UTC) From: Jahnavi MN via B4 Relay Date: Mon, 13 Jul 2026 12:35:25 +0000 Subject: [PATCH v3 3/7] rust_binder: Implement BINDER_DEBUG_USER_ERROR for refcounting and death notifications Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260713-rust_binder_debug_mask-v3-3-0de91bbbbf69@google.com> References: <20260713-rust_binder_debug_mask-v3-0-0de91bbbbf69@google.com> In-Reply-To: <20260713-rust_binder_debug_mask-v3-0-0de91bbbbf69@google.com> To: Greg Kroah-Hartman , =?utf-8?q?Arve_Hj=C3=B8nnev=C3=A5g?= , Todd Kjos , Christian Brauner , Carlos Llamas , Alice Ryhl , Miguel Ojeda , Boqun Feng , Gary Guo , =?utf-8?q?Bj=C3=B6rn_Roy_Baron?= , Benno Lossin , Andreas Hindborg , Trevor Gross , Danilo Krummrich , Daniel Almeida , Tamir Duberstein , Alexandre Courbot , =?utf-8?q?Onur_=C3=96zkan?= Cc: linux-kernel@vger.kernel.org, rust-for-linux@vger.kernel.org, Jahnavi MN X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=ed25519-sha256; t=1783946130; l=5500; i=jahnavimn@google.com; s=20260702; h=from:subject:message-id; bh=n2ioxy8X3U3e9NVWBVzSAwJusdCsQh1BHz2egIQgfEQ=; b=MO8IlYFjrnEoXStu/brtl94lkacOAz7rfHWwj0c74IKkdRpD40p2ooFFo+bYlbZYemMMVmFn3 4OeRvkYUB9yDw0PAU5zF8cXa3MqWFj/2K7kEmZSZxMc9YOXZ8v55u9o X-Developer-Key: i=jahnavimn@google.com; a=ed25519; pk=9aLfw3FepTOJwTS7jRXm7pDH87eBeZMXBPrqwU0//RE= X-Endpoint-Received: by B4 Relay for jahnavimn@google.com/20260702 with auth_id=849 X-Original-From: Jahnavi MN Reply-To: jahnavimn@google.com From: Jahnavi MN This adds dynamic debug logs for: - Decrementing handle reference counts that are already zero. - Mismatched reference states (calling inc_ref_done with no active inc_refs, or using a weak reference as a strong reference). - Requesting or clearing death notifications on invalid references, already active notifications, or with mismatched cookies. Reviewed-by: Carlos Llamas Reviewed-by: Alice Ryhl Signed-off-by: Jahnavi MN --- drivers/android/binder/node.rs | 10 ++++++---- drivers/android/binder/process.rs | 35 ++++++++++++++++++++++++++++------- 2 files changed, 34 insertions(+), 11 deletions(-) diff --git a/drivers/android/binder/node.rs b/drivers/android/binder/node.rs index fb57c0b20888..3f0757058b84 100644 --- a/drivers/android/binder/node.rs +++ b/drivers/android/binder/node.rs @@ -345,7 +345,7 @@ pub(crate) fn inc_ref_done_locked( ) -> Option> { let inner =3D self.inner.access_mut(owner_inner); if inner.active_inc_refs =3D=3D 0 { - pr_err!("inc_ref_done called when no active inc_refs"); + binder_debug!(UserError, "inc_ref_done called when no active i= nc_refs"); return None; } =20 @@ -819,6 +819,7 @@ pub(crate) fn get_count(&self) -> (usize, usize) { =20 pub(crate) fn clone(&self, strong: bool) -> Result { if strong && self.strong_count =3D=3D 0 { + binder_debug!(UserError, "tried to use weak ref as strong ref"= ); return Err(EINVAL); } Ok(self @@ -859,9 +860,10 @@ pub(crate) fn update(&mut self, inc: bool, strong: boo= l) -> bool { *count +=3D 1; } else { if *count =3D=3D 0 { - pr_warn!( - "pid {} performed invalid decrement on ref\n", - kernel::current!().pid() + binder_debug!( + UserError, + "performed invalid {} decrement on ref", + if strong { "strong" } else { "weak" } ); return false; } diff --git a/drivers/android/binder/process.rs b/drivers/android/binder/pro= cess.rs index 6dd39939e7ae..38190aaa462d 100644 --- a/drivers/android/binder/process.rs +++ b/drivers/android/binder/process.rs @@ -908,7 +908,13 @@ pub(crate) fn get_transaction_node(&self, handle: u32)= -> BinderResult if handle =3D=3D 0 { Ok(self.ctx.get_manager_node(true)?) } else { - Ok(self.get_node_from_handle(handle, true)?) + match self.get_node_from_handle(handle, true) { + Ok(node_ref) =3D> Ok(node_ref), + Err(err) =3D> { + binder_debug!(UserError, "got transaction to invalid h= andle {handle}"); + Err(err.into()) + } + } } } =20 @@ -983,7 +989,7 @@ pub(crate) fn update_ref( } else { // All refs are cleared in process exit, so this warning is ex= pected in that case. if !self.inner.lock().is_dead { - pr_warn!("{}: no such ref {handle}\n", self.pid_in_current= _ns()); + binder_debug!(UserError, "no such ref {handle}"); } } Ok(()) @@ -1236,13 +1242,19 @@ pub(crate) fn request_death( })?; let mut refs =3D self.node_refs.lock(); let Some(info) =3D refs.by_handle.get_mut(&handle) else { - pr_warn!("BC_REQUEST_DEATH_NOTIFICATION invalid ref {handle}\n= "); + binder_debug!( + UserError, + "BC_REQUEST_DEATH_NOTIFICATION invalid ref {handle}" + ); return Ok(()); }; =20 // Nothing to do if there is already a death notification request = for this handle. if info.death().is_some() { - pr_warn!("BC_REQUEST_DEATH_NOTIFICATION death notification alr= eady set\n"); + binder_debug!( + UserError, + "BC_REQUEST_DEATH_NOTIFICATION death notification already = set" + ); return Ok(()); } =20 @@ -1279,17 +1291,26 @@ pub(crate) fn clear_death(&self, reader: &mut UserS= liceReader, thread: &Thread) =20 let mut refs =3D self.node_refs.lock(); let Some(info) =3D refs.by_handle.get_mut(&handle) else { - pr_warn!("BC_CLEAR_DEATH_NOTIFICATION invalid ref {handle}\n"); + binder_debug!( + UserError, + "BC_CLEAR_DEATH_NOTIFICATION invalid ref {handle}" + ); return Ok(()); }; =20 let Some(death) =3D info.death().take() else { - pr_warn!("BC_CLEAR_DEATH_NOTIFICATION death notification not a= ctive\n"); + binder_debug!( + UserError, + "BC_CLEAR_DEATH_NOTIFICATION death notification not active" + ); return Ok(()); }; if death.cookie !=3D cookie { *info.death() =3D Some(death); - pr_warn!("BC_CLEAR_DEATH_NOTIFICATION death notification cooki= e mismatch\n"); + binder_debug!( + UserError, + "BC_CLEAR_DEATH_NOTIFICATION death notification cookie mis= match" + ); return Ok(()); } =20 --=20 2.55.0.795.g602f6c329a-goog From nobody Sat Jul 25 21:20:40 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 71B602D9796; Mon, 13 Jul 2026 12:35:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783946132; cv=none; b=JTZITTRit9P30yJbqgeEe0LcybjOYQP0zhUN9iV/cEdmLCDZ+I0fU+cjzea1hkYmsF1O9IpdTiJf4qW3ULsnrEiNXl5BpXx8Uuz5hg8whZd3QIJWU9+Or5jTUgjaZrIYnqrfO1IicUlhllUz/kb0Sn91nbrCtBcFwu1A+hy+H98= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783946132; c=relaxed/simple; bh=q0IByoYJHtZct1/kh5Sa6SgUojAKdrR9wkZwULUXSWQ=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=ZnRmHhgkBHbxVfvLJCNetSnbx5akD/mfds1AyR7aHj49vsLpIqUh1N91jzVJ3kQz9M7JxkLQqxlRr97089x+Ae12GYziGC6lMPt3vS+KEOBQJzenlNfHuKqVm28N6WAiad1r4BJ4e8dbEDZK7xoooXOCL/cdpz5EB13DmZzwpzs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=WFI4XevL; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="WFI4XevL" Received: by smtp.kernel.org (Postfix) with ESMTPS id 311EDC2BCFF; Mon, 13 Jul 2026 12:35:32 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1783946132; bh=q0IByoYJHtZct1/kh5Sa6SgUojAKdrR9wkZwULUXSWQ=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=WFI4XevL9VDLZ7Z+sYP3Ku1JyBea1h4vNJprYWqsNAJGF/RHO2Qu/ijvRF9blV4jO YJDMyXSnkHlMEqxRQAgSzhsPbDz/id4wX4ffaDKP4oF6k/bux+fbhjzQdjp9oleb4F 9Ug4ow+Tw/b5QiFbH9c9EAhE5P5O9c1lhAfrly3Btswmg9Zg1F6qmLYtlBzlUkgc0y oZlvLinqNOotoO+Lu6/M5Qtk8PutgUbZwkEtvvE4wNi39wpdBtsDj5omjn0Rs/FgSa LOyau/SNsPnyr4+3cSLGt8MLBAteo6kAPOMonuZVUseLsxVdipCooU0l3IVPqDEari QQ8dJlXSctvdQ== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1BD1CC44508; Mon, 13 Jul 2026 12:35:32 +0000 (UTC) From: Jahnavi MN via B4 Relay Date: Mon, 13 Jul 2026 12:35:26 +0000 Subject: [PATCH v3 4/7] rust_binder: Implement BINDER_DEBUG_USER_ERROR for transaction parsing failures Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260713-rust_binder_debug_mask-v3-4-0de91bbbbf69@google.com> References: <20260713-rust_binder_debug_mask-v3-0-0de91bbbbf69@google.com> In-Reply-To: <20260713-rust_binder_debug_mask-v3-0-0de91bbbbf69@google.com> To: Greg Kroah-Hartman , =?utf-8?q?Arve_Hj=C3=B8nnev=C3=A5g?= , Todd Kjos , Christian Brauner , Carlos Llamas , Alice Ryhl , Miguel Ojeda , Boqun Feng , Gary Guo , =?utf-8?q?Bj=C3=B6rn_Roy_Baron?= , Benno Lossin , Andreas Hindborg , Trevor Gross , Danilo Krummrich , Daniel Almeida , Tamir Duberstein , Alexandre Courbot , =?utf-8?q?Onur_=C3=96zkan?= Cc: linux-kernel@vger.kernel.org, rust-for-linux@vger.kernel.org, Jahnavi MN X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=ed25519-sha256; t=1783946130; l=8410; i=jahnavimn@google.com; s=20260702; h=from:subject:message-id; bh=8F82YdQeoMbTNpy+yTKNRYFYnNfyFEuPOM2cE+pN+0U=; b=+O+CH/tUG3KaiPgy/jVyTL7yOaFxa8gM+kdLpX/Yp7IxeblB5WcKbWo6bR7d3r1Hb6xGs/JZX XzWseuyS0qUCtvcYPGj295almSKcH4Uo54rSGpQKgWbnbpYYS2tvaet X-Developer-Key: i=jahnavimn@google.com; a=ed25519; pk=9aLfw3FepTOJwTS7jRXm7pDH87eBeZMXBPrqwU0//RE= X-Endpoint-Received: by B4 Relay for jahnavimn@google.com/20260702 with auth_id=849 X-Original-From: Jahnavi MN Reply-To: jahnavimn@google.com From: Jahnavi MN This adds dynamic debug logs in `thread.rs` for: - File descriptor array (FDA) parent offset and parent buffer address alignment misalignments. - Memory copy, write, and translation failures during transaction serialization (including out-of-bounds pointer fixups). - Incoming transactions or replies that do not match the expected thread calling stack (such as out-of-order replies). Reviewed-by: Carlos Llamas Reviewed-by: Alice Ryhl Signed-off-by: Jahnavi MN --- drivers/android/binder/thread.rs | 54 ++++++++++++++++++++++++------------= ---- 1 file changed, 32 insertions(+), 22 deletions(-) diff --git a/drivers/android/binder/thread.rs b/drivers/android/binder/thre= ad.rs index 87298a8c597d..072cb4674172 100644 --- a/drivers/android/binder/thread.rs +++ b/drivers/android/binder/thread.rs @@ -721,11 +721,12 @@ fn translate_object( let alloc_offset =3D match sg_state.unused_buffer_space.cl= aim_next(obj_length) { Ok(alloc_offset) =3D> alloc_offset, Err(err) =3D> { - pr_warn!( - "Failed to claim space for a BINDER_TYPE_PTR. = (offset: {}, limit: {}, size: {})", + binder_debug!( + UserError, + "failed to claim space for a BINDER_TYPE_PTR (= offset: {}, limit: {}, size: {})", sg_state.unused_buffer_space.offset, sg_state.unused_buffer_space.limit, - obj_length, + obj_length ); return Err(err.into()); } @@ -804,6 +805,7 @@ fn translate_object( let fds_len =3D num_fds.checked_mul(size_of::()).ok_o= r(EINVAL)?; =20 if !is_aligned(parent_offset, size_of::()) { + binder_debug!(UserError, "FDA parent offset not aligne= d correctly"); return Err(EINVAL.into()); } =20 @@ -822,6 +824,7 @@ fn translate_object( }; =20 if !is_aligned(parent_entry.sender_uaddr, size_of::()= ) { + binder_debug!(UserError, "FDA parent buffer not aligne= d correctly"); return Err(EINVAL.into()); } =20 @@ -905,12 +908,9 @@ fn apply_sg(&self, alloc: &mut Allocation, sg_state: &= mut ScatterGatherState) -> =20 let target_offset_end =3D fixup_offset.checked_add(fixup_l= en).ok_or(EINVAL)?; if fixup_offset < end_of_previous_fixup || offset_end < ta= rget_offset_end { - pr_warn!( - "Fixups oob {} {} {} {}", - fixup_offset, - end_of_previous_fixup, - offset_end, - target_offset_end + binder_debug!( + UserError, + "fixups oob {fixup_offset} {end_of_previous_fixup}= {offset_end} {target_offset_end}" ); return Err(EINVAL.into()); } @@ -918,18 +918,21 @@ fn apply_sg(&self, alloc: &mut Allocation, sg_state: = &mut ScatterGatherState) -> let copy_off =3D end_of_previous_fixup; let copy_len =3D fixup_offset - end_of_previous_fixup; if let Err(err) =3D alloc.copy_into(&mut reader, copy_off,= copy_len) { - pr_warn!("Failed copying into alloc: {:?}", err); + binder_debug!(UserError, "failed copying into alloc: {= err:?}"); return Err(err.into()); } if let PointerFixupEntry::Fixup { pointer_value, .. } =3D = fixup { let res =3D alloc.write::(fixup_offset, pointer_v= alue); if let Err(err) =3D res { - pr_warn!("Failed copying ptr into alloc: {:?}", er= r); + binder_debug!(UserError, "failed copying ptr into = alloc: {err:?}"); return Err(err.into()); } } if let Err(err) =3D reader.skip(fixup_len) { - pr_warn!("Failed skipping {} from reader: {:?}", fixup= _len, err); + binder_debug!( + UserError, + "failed skipping {fixup_len} from reader: {err:?}" + ); return Err(err.into()); } end_of_previous_fixup =3D target_offset_end; @@ -937,7 +940,7 @@ fn apply_sg(&self, alloc: &mut Allocation, sg_state: &m= ut ScatterGatherState) -> let copy_off =3D end_of_previous_fixup; let copy_len =3D offset_end - end_of_previous_fixup; if let Err(err) =3D alloc.copy_into(&mut reader, copy_off, cop= y_len) { - pr_warn!("Failed copying remainder into alloc: {:?}", err); + binder_debug!(UserError, "failed copying remainder into al= loc: {err:?}"); return Err(err.into()); } } @@ -1041,7 +1044,7 @@ pub(crate) fn copy_transaction_data( let offset: usize =3D offset.try_into().map_err(|_| EINVAL= )?; =20 if offset < end_of_previous_object || !is_aligned(offset, = size_of::()) { - pr_warn!("Got transaction with invalid offset."); + binder_debug!(UserError, "got transaction with invalid= offset"); return Err(EINVAL.into()); } =20 @@ -1066,7 +1069,7 @@ pub(crate) fn copy_transaction_data( ) { Ok(()) =3D> end_of_previous_object =3D offset + object= .size(), Err(err) =3D> { - pr_warn!("Error while translating object."); + binder_debug!(UserError, "error while translating = object: {err:?}"); return Err(err); } } @@ -1086,15 +1089,12 @@ pub(crate) fn copy_transaction_data( )?; =20 if let Some(sg_state) =3D sg_state.as_mut() { - if let Err(err) =3D self.apply_sg(&mut alloc, sg_state) { - pr_warn!("Failure in apply_sg: {:?}", err); - return Err(err); - } + self.apply_sg(&mut alloc, sg_state)?; } =20 if let Some((off_out, secctx)) =3D secctx.as_mut() { if let Err(err) =3D alloc.write(secctx_off, secctx.as_bytes())= { - pr_warn!("Failed to write security context: {:?}", err); + binder_debug!(UserError, "failed to write security context= : {err:?}"); return Err(err.into()); } **off_out =3D secctx_off; @@ -1282,7 +1282,7 @@ fn transaction_inner(self: &Arc, info: &mut Tra= nsactionInfo) -> BinderResu { let mut inner =3D self.inner.lock(); if !transaction.is_stacked_on(&inner.current_transaction) { - pr_warn!("Transaction stack changed during transaction!"); + binder_debug!(UserError, "got new transaction with bad tra= nsaction stack"); return Err(EINVAL.into()); } inner.current_transaction =3D Some(transaction.clone_arc()); @@ -1305,8 +1305,18 @@ fn transaction_inner(self: &Arc, info: &mut Tr= ansactionInfo) -> BinderResu } =20 fn reply_inner(self: &Arc, info: &mut TransactionInfo) -> Binder= Result { - let orig =3D self.inner.lock().pop_transaction_to_reply(self)?; + let orig =3D match self.inner.lock().pop_transaction_to_reply(self= ) { + Ok(orig) =3D> orig, + Err(err) =3D> { + binder_debug!(UserError, "got reply transaction with no tr= ansaction stack"); + return Err(err.into()); + } + }; if !orig.from.is_current_transaction(&orig) { + binder_debug!( + UserError, + "got reply transaction with bad transaction stack" + ); return Err(EINVAL.into()); } =20 --=20 2.55.0.795.g602f6c329a-goog From nobody Sat Jul 25 21:20:40 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 93F10381EA6; Mon, 13 Jul 2026 12:35:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783946132; cv=none; b=NQ9eM+lOpQTJzO/Wr+/Wp9GLJTgW3qJgBMZBF/BjniVFR5j9jmdJFxJPxAbJgA6LwXZQjYNz3bYT9S63atRIiYZYWLhNsnhE4g3dskkclk9f9nB7GazARMuwFXUtxDxb9zSR+O9lEye5aa58+tdCRlzf8CyCBVgxhfLtLIibsN0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783946132; c=relaxed/simple; bh=QnrDRlKEu8bun6eN18dIMh9PHySYdlnmHKd5uOfo1Rk=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=DSBl4+xlbOsRLSINHniUaPR7cXcPML1mDRf5ix9osPkBKPkygHEbEI0TJgK52yKPk+roePW8T+dfBjy7/SLFafEeO6BEcRI+rqtWIzo2M0xts465paerTKbClWFJgflQWca1znB1gjTXPJ54c7b/HibKwZN8pMzUP5CkFliKIVM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=ZQwoEVF/; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="ZQwoEVF/" Received: by smtp.kernel.org (Postfix) with ESMTPS id 3E462C2BD01; Mon, 13 Jul 2026 12:35:32 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1783946132; bh=QnrDRlKEu8bun6eN18dIMh9PHySYdlnmHKd5uOfo1Rk=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=ZQwoEVF/yfMlquLV1uFejq3k9u7Fv3eBhFP32KLaX/MEeGnglUiR0apYUwcjFD5C3 6MBnVL7QyjuNcLhPpbuIOUuXcVWDrSG9Oq5OXVcU13lW2l4Erf8x6HxWiQpn3XzPL3 9Us9a6+7vaDw3sl+FF6vK3KoNH+3UZ/qR6wE8cjiq1rSZOUaX1Za5exiwk8F9/5p7l KiPwrr9Sv27qjNLxHkWv4ImYUELmghYnLOqheogI28PnEjWZYxHdjO1es9vmX2cIig dl4UBn9hcr+iySkwQDKZXX6Hh1y8LsBcu8JfSYVMvVaG8+DHDN7mk8NOwYaVIUk4ML M3NGsfofre9AA== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 29D9FC43458; Mon, 13 Jul 2026 12:35:32 +0000 (UTC) From: Jahnavi MN via B4 Relay Date: Mon, 13 Jul 2026 12:35:27 +0000 Subject: [PATCH v3 5/7] rust_binder: Implement BINDER_DEBUG_FAILED_TRANSACTION Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260713-rust_binder_debug_mask-v3-5-0de91bbbbf69@google.com> References: <20260713-rust_binder_debug_mask-v3-0-0de91bbbbf69@google.com> In-Reply-To: <20260713-rust_binder_debug_mask-v3-0-0de91bbbbf69@google.com> To: Greg Kroah-Hartman , =?utf-8?q?Arve_Hj=C3=B8nnev=C3=A5g?= , Todd Kjos , Christian Brauner , Carlos Llamas , Alice Ryhl , Miguel Ojeda , Boqun Feng , Gary Guo , =?utf-8?q?Bj=C3=B6rn_Roy_Baron?= , Benno Lossin , Andreas Hindborg , Trevor Gross , Danilo Krummrich , Daniel Almeida , Tamir Duberstein , Alexandre Courbot , =?utf-8?q?Onur_=C3=96zkan?= Cc: linux-kernel@vger.kernel.org, rust-for-linux@vger.kernel.org, Jahnavi MN X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=ed25519-sha256; t=1783946130; l=2626; i=jahnavimn@google.com; s=20260702; h=from:subject:message-id; bh=6DwP7RPLyotGGvt0ZpfxbDZP6CqubJEwhR1a0QtfHZM=; b=SvGLPUdc1Ysb4rBN5h25WKNPRvYefnq2fzN3RH9Kd0Qkq/0ss1uENX0rpePhSn928G23gj3Li L3xt6puJRwuAg09/9LQ+ZLjYDe20LBSFiUYtdi/cEjMZQ8hWzvTIcLi X-Developer-Key: i=jahnavimn@google.com; a=ed25519; pk=9aLfw3FepTOJwTS7jRXm7pDH87eBeZMXBPrqwU0//RE= X-Endpoint-Received: by B4 Relay for jahnavimn@google.com/20260702 with auth_id=849 X-Original-From: Jahnavi MN Reply-To: jahnavimn@google.com From: Jahnavi MN This adds dynamic debug logs for: - Failed replies, target process deaths, and error code deliveries. - Detailed transaction failure diagnostics (including sender/receiver PIDs, TIDs, transaction IDs, buffer sizes, and error codes). Reviewed-by: Carlos Llamas Reviewed-by: Alice Ryhl Signed-off-by: Jahnavi MN --- drivers/android/binder/thread.rs | 21 ++++++++++++++++----- drivers/android/binder/transaction.rs | 8 ++++++++ 2 files changed, 24 insertions(+), 5 deletions(-) diff --git a/drivers/android/binder/thread.rs b/drivers/android/binder/thre= ad.rs index 072cb4674172..26925d094a59 100644 --- a/drivers/android/binder/thread.rs +++ b/drivers/android/binder/thread.rs @@ -1254,11 +1254,22 @@ fn transaction(self: &Arc, cmd: u32, reader: = &mut UserSliceReader) -> Resu ee.param =3D source.to_errno(); } =20 - pr_warn!( - "{}:{} transaction to {} failed: {source:?}", - info.from_pid, - info.from_tid, - info.to_pid + binder_debug!( + FailedTransaction, + "transaction {} to {}:{} failed {:?}, code {} size {}-= {}", + if info.is_reply { + "reply" + } else if info.is_oneway() { + "async" + } else { + "call" + }, + info.to_pid, + info.to_tid, + err, + info.code, + info.data_size, + info.offsets_size ); } } diff --git a/drivers/android/binder/transaction.rs b/drivers/android/binder= /transaction.rs index 38795224a784..b56dca55662d 100644 --- a/drivers/android/binder/transaction.rs +++ b/drivers/android/binder/transaction.rs @@ -405,6 +405,14 @@ fn do_work( } else { // On failure to process the list, we send a reply back to the= sender and ignore the // transaction on the recipient. + binder_debug!( + FailedTransaction, + "transaction {} to {} failed, fd fixups failed, size {}-{}= ", + self.debug_id, + self.to.task.pid(), + self.data_size, + self.offsets_size + ); return Ok(true); }; =20 --=20 2.55.0.795.g602f6c329a-goog From nobody Sat Jul 25 21:20:40 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 93E2137B40E; Mon, 13 Jul 2026 12:35:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783946132; cv=none; b=ktsoFZ1on+pOTX8vHx+zae82dcUHTfcT0U24EC2CPneEp6vKUnHhnTr8y+qNXthr9FAMswt/aNix4YW3GL+3JT0vN0dRVuS3XCQ44YF/GNBzaOYt1FCdpUYRVVAbFZ+N4pJtfRdUU7GhFJMzqvLxwMM0phgb7MoyK4/ueaRImFE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783946132; c=relaxed/simple; bh=OEJqGCGraOc2xljPbhiZUKlm9vDXZ7opcLl4ICt4sXc=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=hSlaBJuKzlKpJnG1BP2/RUEVoE4VgX93a3OkWk9e9ctn55Nwwet4O0DqOTsi/VSHKYtTd1H5YobvptOX8he+Iip5b0gSoMQtIR6CnQwkuytdUsRSqGuRc4ZeJ20XLCYpQTsisQh4zdGk/4NRNZFSktTnguPEXWI2DtGuwKLSsEg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=LSs+FGFL; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="LSs+FGFL" Received: by smtp.kernel.org (Postfix) with ESMTPS id 4F1F4C32781; Mon, 13 Jul 2026 12:35:32 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1783946132; bh=OEJqGCGraOc2xljPbhiZUKlm9vDXZ7opcLl4ICt4sXc=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=LSs+FGFLGlR911W54QkQinnp5Po8MDhxDOp9u6QXgmhNBBXZeQ+HBF0lOMdXHdSXN LJlUSPG7axUQuyr7mdCEGQuTy+SyxbOaaAqN8tYe+NzACv4VhU7aCqmrbB/+pmkyOj vRWEW7qkMqkqKgsYFSx6a+mOZFCB7V0nIhmMGbQx95ydrDrkOmkCNpQiCYGUsHwHJ/ RbAhsja6XKV0l9DbA6yn2FnCjOaNPFhFq1IILHVE6pMt6zb/LmpdVp+RTuQlnyF4oy oCnrpvvjtLYW25NVkCFDfPbYvLFrHMak1QKnzUD1jedN9ZTtxve2VuXli4fk/n/6/Y CAr8ryqIt/zyA== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 374EBC44507; Mon, 13 Jul 2026 12:35:32 +0000 (UTC) From: Jahnavi MN via B4 Relay Date: Mon, 13 Jul 2026 12:35:28 +0000 Subject: [PATCH v3 6/7] rust_binder: Implement BINDER_DEBUG_DEATH_NOTIFICATION Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260713-rust_binder_debug_mask-v3-6-0de91bbbbf69@google.com> References: <20260713-rust_binder_debug_mask-v3-0-0de91bbbbf69@google.com> In-Reply-To: <20260713-rust_binder_debug_mask-v3-0-0de91bbbbf69@google.com> To: Greg Kroah-Hartman , =?utf-8?q?Arve_Hj=C3=B8nnev=C3=A5g?= , Todd Kjos , Christian Brauner , Carlos Llamas , Alice Ryhl , Miguel Ojeda , Boqun Feng , Gary Guo , =?utf-8?q?Bj=C3=B6rn_Roy_Baron?= , Benno Lossin , Andreas Hindborg , Trevor Gross , Danilo Krummrich , Daniel Almeida , Tamir Duberstein , Alexandre Courbot , =?utf-8?q?Onur_=C3=96zkan?= Cc: linux-kernel@vger.kernel.org, rust-for-linux@vger.kernel.org, Jahnavi MN X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=ed25519-sha256; t=1783946130; l=2692; i=jahnavimn@google.com; s=20260702; h=from:subject:message-id; bh=Ac2/HhH4s3DlFi55GxIloHEGDjTqfnRwxNUHDja4HeI=; b=yfGc+GP3VvqjNRlJmoaDXFpEMxjfZRjbMUxz0D4asGe7UYhryD5Cbyby6Z9wSDNV7/0QvQRIx KRCNr1vOHtSBlM1fz8qBveTrC+nc9LL9ev3rLKSb49HhCyOobmILnN8 X-Developer-Key: i=jahnavimn@google.com; a=ed25519; pk=9aLfw3FepTOJwTS7jRXm7pDH87eBeZMXBPrqwU0//RE= X-Endpoint-Received: by B4 Relay for jahnavimn@google.com/20260702 with auth_id=849 X-Original-From: Jahnavi MN Reply-To: jahnavimn@google.com From: Jahnavi MN This adds dynamic debug logs for: - Memory allocation (OOM) failures when requesting death notifications - Registration and cancellation lifecycle events (BC_REQUEST / BC_CLEAR) - Delivery of death notification events to userspace (BR_DEAD_BINDER) Reviewed-by: Carlos Llamas Reviewed-by: Alice Ryhl Signed-off-by: Jahnavi MN --- drivers/android/binder/node.rs | 5 +++++ drivers/android/binder/process.rs | 14 ++++++++++++++ 2 files changed, 19 insertions(+) diff --git a/drivers/android/binder/node.rs b/drivers/android/binder/node.rs index 3f0757058b84..87a2e613a816 100644 --- a/drivers/android/binder/node.rs +++ b/drivers/android/binder/node.rs @@ -1105,6 +1105,11 @@ fn do_work( // We're still holding the inner lock, so it cannot be aborted= while we insert it into // the delivered list. process_inner.death_delivered(self.clone()); + binder_debug!( + DeathNotification, + "sending death notification, cookie {:016x}", + cookie + ); BR_DEAD_BINDER }; =20 diff --git a/drivers/android/binder/process.rs b/drivers/android/binder/pro= cess.rs index 38190aaa462d..42330fd409c4 100644 --- a/drivers/android/binder/process.rs +++ b/drivers/android/binder/process.rs @@ -1239,6 +1239,10 @@ pub(crate) fn request_death( // Queue BR_ERROR if we can't allocate memory for the death notifi= cation. let death =3D UniqueArc::new_uninit(GFP_KERNEL).inspect_err(|_| { thread.push_return_work(BR_ERROR); + binder_debug!( + DeathNotification, + "BC_REQUEST_DEATH_NOTIFICATION failed due to memory alloca= tion failure" + ); })?; let mut refs =3D self.node_refs.lock(); let Some(info) =3D refs.by_handle.get_mut(&handle) else { @@ -1282,6 +1286,11 @@ pub(crate) fn request_death( info.node_ref().node.add_death(death, &mut owner_inner); } } + binder_debug!( + DeathNotification, + "BC_REQUEST_DEATH_NOTIFICATION handle {handle} cookie {:016x}", + cookie + ); Ok(()) } =20 @@ -1325,6 +1334,11 @@ pub(crate) fn clear_death(&self, reader: &mut UserSl= iceReader, thread: &Thread) } } =20 + binder_debug!( + DeathNotification, + "BC_CLEAR_DEATH_NOTIFICATION handle {handle} cookie {:016x}", + cookie + ); Ok(()) } =20 --=20 2.55.0.795.g602f6c329a-goog From nobody Sat Jul 25 21:20:40 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9E5F640B397; Mon, 13 Jul 2026 12:35:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783946132; cv=none; b=brAlWtLDtDhwJUz62CUKhrPNa0DEA5LtW1NW5Ky6C5KMcu2Ogw/QYTWM2vvgIqOiGz0sPwtnsY6gEfuEjoS0o8oWx4v5+dUhJbenlHyBzrwkUhVpKCWAoZ52Ml77HnwZibHo2Jd+DQw7z11Ac5KKzXXjW6pVSg46FrhHx8PIm10= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783946132; c=relaxed/simple; bh=8vc+90L0Mb07IpTALiLRIKYaM5HYvp7a59q+ECH1wM8=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=vD/7DpMyvMGVIFFxsgoVao0pxmi+NGvqKXLIU15/XI6Kh9tDCTMSn/c2LGFjowoR/859UGxdV96ZcyrWxG0MByUVDtyTyfY/cXekr02DqzFJ3fRPCWkxDlcGDJMF6oc6eaPfYgDepXCIk0bYbLwZ9ZFmoPF94TZif+CHDBrgOIg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=m+3VvTkB; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="m+3VvTkB" Received: by smtp.kernel.org (Postfix) with ESMTPS id 7ABD1C2BCFB; Mon, 13 Jul 2026 12:35:32 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1783946132; bh=8vc+90L0Mb07IpTALiLRIKYaM5HYvp7a59q+ECH1wM8=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=m+3VvTkB/cmtm6mPUCDFqSPVQaRRb44uRKuI5w57ryldoqkI21V6fXLg2HM6Ou1dk dw/ghLvBXBJOjWT4DcwA2Om4TTpsjQ1eRAlr/uWmUQjbV0UjM/8z/IqFe/hAwnquGd oP4XyKp5fg7hvuhQephunRgIFL7SacF9Nq96SMk/3WIpxSgQqo4UHCyfCK17+4MzpI ONz0K6my7cV0K7ZrBxF7wvbHotqogmNdnqikEDQs0X3E7FtLDseWl9MgK8FjLIzmAo huqWJas1OXFmsxISOyYoI5BPUJcY3tsnJhCVzUHRsJ7Dk3T/9aZ8zZRAWy9mdSY+6/ TOuwn7qvuKuqQ== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 65EE0C43458; Mon, 13 Jul 2026 12:35:32 +0000 (UTC) From: Jahnavi MN via B4 Relay Date: Mon, 13 Jul 2026 12:35:29 +0000 Subject: [PATCH v3 7/7] rust_binder: Implement BINDER_DEBUG_DEAD_TRANSACTION Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260713-rust_binder_debug_mask-v3-7-0de91bbbbf69@google.com> References: <20260713-rust_binder_debug_mask-v3-0-0de91bbbbf69@google.com> In-Reply-To: <20260713-rust_binder_debug_mask-v3-0-0de91bbbbf69@google.com> To: Greg Kroah-Hartman , =?utf-8?q?Arve_Hj=C3=B8nnev=C3=A5g?= , Todd Kjos , Christian Brauner , Carlos Llamas , Alice Ryhl , Miguel Ojeda , Boqun Feng , Gary Guo , =?utf-8?q?Bj=C3=B6rn_Roy_Baron?= , Benno Lossin , Andreas Hindborg , Trevor Gross , Danilo Krummrich , Daniel Almeida , Tamir Duberstein , Alexandre Courbot , =?utf-8?q?Onur_=C3=96zkan?= Cc: linux-kernel@vger.kernel.org, rust-for-linux@vger.kernel.org, Jahnavi MN X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=ed25519-sha256; t=1783946130; l=12110; i=jahnavimn@google.com; s=20260702; h=from:subject:message-id; bh=FwUrxBU36POBXVorUXVqXXZcgJ41yVN0yFL3RLSiaOo=; b=4lLFDy/jCECWBlfGm8QwlRgbjdkWY+HMOBFBVADqPBuKAoJGUaA9yzNFCSZU7r+JjO8lo3ozZ OdHd/5oOmFABKlFz5K/eh91+y9tJxUwm1Pxf6EXWzR9pcx/4+uxce+B X-Developer-Key: i=jahnavimn@google.com; a=ed25519; pk=9aLfw3FepTOJwTS7jRXm7pDH87eBeZMXBPrqwU0//RE= X-Endpoint-Received: by B4 Relay for jahnavimn@google.com/20260702 with auth_id=849 X-Original-From: Jahnavi MN Reply-To: jahnavimn@google.com From: Jahnavi MN This adds dynamic debug logs for: - Releasing active transactions during thread stack unwinding. - Discarded transaction error codes when a thread exits. - Undelivered transaction acknowledgments (TRANSACTION_COMPLETE) upon thread exit. - Undelivered process death and freeze notifications when processes exit or die. - Undelivered transactions canceled due to target process death. We now store the process PID in `ThreadError`, `DeliverCode`, and `FreezeMessage` to ensure the correct PID is logged on cancellation. This is necessary because `cancel()` runs from background `kworkers`, which would otherwise print the wrong PID. Reviewed-by: Alice Ryhl Signed-off-by: Jahnavi MN --- drivers/android/binder/freeze.rs | 24 +++++++++++------ drivers/android/binder/node.rs | 9 ++++++- drivers/android/binder/rust_binder_main.rs | 14 ++++++++-- drivers/android/binder/thread.rs | 42 +++++++++++++++++++++++---= ---- drivers/android/binder/transaction.rs | 7 +++++ 5 files changed, 76 insertions(+), 20 deletions(-) diff --git a/drivers/android/binder/freeze.rs b/drivers/android/binder/free= ze.rs index 2c99e0995554..7b825ffba557 100644 --- a/drivers/android/binder/freeze.rs +++ b/drivers/android/binder/freeze.rs @@ -60,6 +60,7 @@ fn allow_duplicate(&self, node: &DArc) -> bool { /// Represents a notification that the freeze state has changed. pub(crate) struct FreezeMessage { cookie: FreezeCookie, + pid: i32, } =20 kernel::list::impl_list_arc_safe! { @@ -73,8 +74,8 @@ fn new(flags: kernel::alloc::Flags) -> Result { UniqueArc::new_uninit(flags) } =20 - fn init(ua: UninitFM, cookie: FreezeCookie) -> DLArc { - match ua.pin_init_with(DTRWrap::new(FreezeMessage { cookie })) { + fn init(ua: UninitFM, cookie: FreezeCookie, pid: i32) -> DLArc { + match ua.pin_init_with(DTRWrap::new(FreezeMessage { cookie, pid })= ) { Ok(msg) =3D> ListArc::from(msg), Err(err) =3D> match err {}, } @@ -140,7 +141,14 @@ fn do_work( } } =20 - fn cancel(self: DArc) {} + fn cancel(self: DArc) { + binder_debug!( + pid =3D self.pid, + DeadTransaction, + "undelivered freeze notification, {:016x}", + self.cookie.0 + ); + } =20 fn should_sync_wakeup(&self) -> bool { false @@ -251,7 +259,7 @@ pub(crate) fn request_freeze_notif( } =20 *info.freeze() =3D Some(cookie); - let msg =3D FreezeMessage::init(msg, cookie); + let msg =3D FreezeMessage::init(msg, cookie, self.task.pid()); drop(node_refs_guard); let _ =3D self.push_work(msg); Ok(()) @@ -272,7 +280,7 @@ pub(crate) fn freeze_notif_done(self: &Arc, reade= r: &mut UserSliceReader) }; let mut clear_msg =3D None; if freeze.num_pending_duplicates > 0 { - clear_msg =3D Some(FreezeMessage::init(alloc, cookie)); + clear_msg =3D Some(FreezeMessage::init(alloc, cookie, self.tas= k.pid())); freeze.num_pending_duplicates -=3D 1; freeze.num_cleared_duplicates +=3D 1; } else { @@ -287,7 +295,7 @@ pub(crate) fn freeze_notif_done(self: &Arc, reade= r: &mut UserSliceReader) let is_frozen =3D freeze.node.owner.inner.lock().is_frozen.is_= fully_frozen(); if freeze.is_clearing || freeze.last_is_frozen !=3D Some(is_fr= ozen) { // Immediately send another FreezeMessage. - clear_msg =3D Some(FreezeMessage::init(alloc, cookie)); + clear_msg =3D Some(FreezeMessage::init(alloc, cookie, self= .task.pid())); } freeze.is_pending =3D false; } @@ -340,7 +348,7 @@ pub(crate) fn clear_freeze_notif(self: &Arc, read= er: &mut UserSliceReader) *info.freeze() =3D None; let mut msg =3D None; if !listener.is_pending { - msg =3D Some(FreezeMessage::init(alloc, cookie)); + msg =3D Some(FreezeMessage::init(alloc, cookie, self.task.pid(= ))); } drop(node_refs_guard); =20 @@ -420,7 +428,7 @@ pub(crate) fn prepare_freeze_messages(&self) -> Result<= FreezeMessages, AllocErro continue; }; let msg_alloc =3D FreezeMessage::new(GFP_KERNEL)?; - let msg =3D FreezeMessage::init(msg_alloc, cookie); + let msg =3D FreezeMessage::init(msg_alloc, cookie, proc.task.p= id()); batch.push((proc, msg), GFP_KERNEL)?; } =20 diff --git a/drivers/android/binder/node.rs b/drivers/android/binder/node.rs index 87a2e613a816..b9e21b8ec251 100644 --- a/drivers/android/binder/node.rs +++ b/drivers/android/binder/node.rs @@ -1120,7 +1120,14 @@ fn do_work( Ok(cmd !=3D BR_DEAD_BINDER) } =20 - fn cancel(self: DArc) {} + fn cancel(self: DArc) { + binder_debug!( + pid =3D self.process.task.pid(), + DeadTransaction, + "undelivered death notification, {:016x}", + self.cookie + ); + } =20 fn should_sync_wakeup(&self) -> bool { false diff --git a/drivers/android/binder/rust_binder_main.rs b/drivers/android/b= inder/rust_binder_main.rs index 29829cb210a4..15c7b65928d8 100644 --- a/drivers/android/binder/rust_binder_main.rs +++ b/drivers/android/binder/rust_binder_main.rs @@ -221,6 +221,7 @@ fn arc_pin_init(init: impl PinInit) -> Result, kernel::error::Error> struct DeliverCode { code: u32, skip: Atomic, + pid: i32, } =20 kernel::list::impl_list_arc_safe! { @@ -228,10 +229,11 @@ struct DeliverCode { } =20 impl DeliverCode { - fn new(code: u32) -> Self { + fn new(code: u32, pid: i32) -> Self { Self { code, skip: Atomic::new(false), + pid, } } =20 @@ -256,7 +258,15 @@ fn do_work( Ok(true) } =20 - fn cancel(self: DArc) {} + fn cancel(self: DArc) { + if !self.skip.load(Relaxed) { + binder_debug!( + pid =3D self.pid, + DeadTransaction, + "undelivered TRANSACTION_COMPLETE" + ); + } + } =20 fn should_sync_wakeup(&self) -> bool { false diff --git a/drivers/android/binder/thread.rs b/drivers/android/binder/thre= ad.rs index 26925d094a59..102413879d1d 100644 --- a/drivers/android/binder/thread.rs +++ b/drivers/android/binder/thread.rs @@ -279,7 +279,7 @@ struct InnerThread { const LOOPER_POLL: u32 =3D 0x40; =20 impl InnerThread { - fn new() -> Result { + fn new(pid: i32) -> Result { fn next_err_id() -> u32 { static EE_ID: Atomic =3D Atomic::new(0); EE_ID.fetch_add(1, Relaxed) @@ -290,8 +290,8 @@ fn next_err_id() -> u32 { looper_need_return: false, is_dead: false, process_work_list: false, - reply_work: ThreadError::try_new()?, - return_work: ThreadError::try_new()?, + reply_work: ThreadError::try_new(pid)?, + return_work: ThreadError::try_new(pid)?, work_list: List::new(), current_transaction: None, extended_error: ExtendedError::new(next_err_id(), BR_OK, 0), @@ -445,7 +445,7 @@ impl ListItem<0> for Thread { =20 impl Thread { pub(crate) fn new(id: i32, process: Arc) -> Result>= { - let inner =3D InnerThread::new()?; + let inner =3D InnerThread::new(process.task.pid())?; =20 Arc::pin_init( try_pin_init!(Thread { @@ -1108,6 +1108,12 @@ fn unwind_transaction_stack(self: &Arc) { let mut inner =3D thread.inner.lock(); inner.pop_transaction_to_reply(thread.as_ref()) } { + binder_debug!( + DeadTransaction, + "release transaction {} in, still active", + transaction.debug_id + ); + let reply =3D Err(BR_DEAD_REPLY); if !transaction.from.deliver_single_reply(reply, &transaction)= { break; @@ -1284,7 +1290,10 @@ fn transaction_inner(self: &Arc, info: &mut Tr= ansactionInfo) -> BinderResu // TODO: We need to ensure that there isn't a pending transaction = in the work queue. How // could this happen? let top =3D self.top_of_transaction_stack()?; - let list_completion =3D DTRWrap::arc_try_new(DeliverCode::new(BR_T= RANSACTION_COMPLETE))?; + let list_completion =3D DTRWrap::arc_try_new(DeliverCode::new( + BR_TRANSACTION_COMPLETE, + self.process.task.pid(), + ))?; let completion =3D list_completion.clone_arc(); let transaction =3D Transaction::new(node_ref, top, self, info)?; =20 @@ -1336,7 +1345,10 @@ fn reply_inner(self: &Arc, info: &mut Transact= ionInfo) -> BinderResult { =20 // We need to complete the transaction even if we cannot complete = building the reply. let out =3D (|| -> BinderResult<_> { - let completion =3D DTRWrap::arc_try_new(DeliverCode::new(BR_TR= ANSACTION_COMPLETE))?; + let completion =3D DTRWrap::arc_try_new(DeliverCode::new( + BR_TRANSACTION_COMPLETE, + self.process.task.pid(), + ))?; let process =3D orig.from.process.clone(); let allow_fds =3D orig.flags & TF_ACCEPT_FDS !=3D 0; let reply =3D Transaction::new_reply(self, process, info, allo= w_fds)?; @@ -1370,7 +1382,8 @@ fn oneway_transaction_inner(self: &Arc, info: &= mut TransactionInfo) -> Bin } else { BR_TRANSACTION_COMPLETE }; - let list_completion =3D DTRWrap::arc_try_new(DeliverCode::new(code= ))?; + let list_completion =3D + DTRWrap::arc_try_new(DeliverCode::new(code, self.process.task.= pid()))?; let completion =3D list_completion.clone_arc(); self.inner.lock().push_work(list_completion); match transaction.submit(info) { @@ -1626,14 +1639,16 @@ pub(crate) fn release(self: &Arc) { #[pin_data] struct ThreadError { error_code: Atomic, + pid: i32, #[pin] links_track: AtomicTracker, } =20 impl ThreadError { - fn try_new() -> Result> { + fn try_new(pid: i32) -> Result> { DTRWrap::arc_pin_init(pin_init!(Self { error_code: Atomic::new(BR_OK), + pid, links_track <- AtomicTracker::new(), })) .map(ListArc::into_arc) @@ -1660,7 +1675,16 @@ fn do_work( Ok(true) } =20 - fn cancel(self: DArc) {} + fn cancel(self: DArc) { + let code =3D self.error_code.load(Relaxed); + if code !=3D BR_OK { + binder_debug!( + pid =3D self.pid, + DeadTransaction, + "undelivered TRANSACTION_ERROR: {code}" + ); + } + } =20 fn should_sync_wakeup(&self) -> bool { false diff --git a/drivers/android/binder/transaction.rs b/drivers/android/binder= /transaction.rs index b56dca55662d..0dbc7a9d16f9 100644 --- a/drivers/android/binder/transaction.rs +++ b/drivers/android/binder/transaction.rs @@ -489,6 +489,13 @@ fn cancel(self: DArc) { if self.target_node.is_some() && self.flags & TF_ONE_WAY =3D=3D 0 { let reply =3D Err(BR_DEAD_REPLY); self.from.deliver_reply(reply, &self); + } else { + binder_debug!( + pid =3D self.to.task.pid(), + DeadTransaction, + "undelivered transaction {}, process died", + self.debug_id + ); } =20 self.drop_outstanding_txn(); --=20 2.55.0.795.g602f6c329a-goog