From nobody Sat Jul 25 16:19:21 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 05CB33F1AB7; Thu, 16 Jul 2026 08:38:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784191081; cv=none; b=EIaNKF7z9xYdlOGzreCIQ/xm4HCRBGP7xyh8mn2puu0WYJzBDoHvJfLWSxFde4dW+Ft9OeufCcYl9y9aFIl+8gkqQLcXfEF++ZD6T6oMBsnhgTlOrscQJfREchkGn0ck/oXDwMusOAtjBQPNPkgj/yHm9frteZR9XVL54jz3gzs= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784191081; c=relaxed/simple; bh=dTrU65SmAPkR6BctDTxJqsfV7mqivmFMC3XCyyM8rLs=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=R22vckTwtmrjZY4hQsHHorXr1V5V+z49T/u5y9PRN7Z8HHQoT/sQjZOSCr3wZdwhoEc4452pGlN8tje3P11GyDeIpaR7ooZBnJ03eTRNI2YDUPLd9G7fq0qlkgr/55U13BIGSuvBxm+NB5aOVzCv/MQ6IfxzlVivfAwoi10nXZ8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=eOe2ZEG6; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="eOe2ZEG6" Received: by smtp.kernel.org (Postfix) with ESMTPS id 35879C2BCC9; Thu, 16 Jul 2026 08:38:00 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1784191080; bh=dTrU65SmAPkR6BctDTxJqsfV7mqivmFMC3XCyyM8rLs=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=eOe2ZEG6KJMSkBBXbrjTRBF9MaGP8rBp4E3cXlau6IXOD1KQsT8eZM3dOjqnmq9L0 j7rtiS0sDX+3gUIEH6nZJFAfYF6AEDm/fST/3m0B/k7E54187N8/Q3SauN75+tbyJq syQz9Cx/QfOWjU0I6dcYDkrRfZUjEkGPrJDBfOhQHKNxGv1ayJz7P4tIAZEuYsIJF/ FkxIUpLeaf41zX7ZBPNuzdefH6NooxDv0SrbAgDWepKxQr/zQSk0JjE8pqSnftFCW0 VIycl9EZrPy0Hp0m/cZdRkV/sFhZet0ot3PpswoHyC7vbjFdjTFLX/6rL1VGM1W5Yz 1Pln5TtngRHpQ== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 171E9C44501; Thu, 16 Jul 2026 08:38:00 +0000 (UTC) From: Jahnavi MN via B4 Relay Date: Thu, 16 Jul 2026 08:37:43 +0000 Subject: [PATCH v4 1/7] rust_binder: Add dynamic debug logging mask Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260716-rust_binder_debug_mask-v4-1-3d7436c2d2f2@google.com> References: <20260716-rust_binder_debug_mask-v4-0-3d7436c2d2f2@google.com> In-Reply-To: <20260716-rust_binder_debug_mask-v4-0-3d7436c2d2f2@google.com> To: Greg Kroah-Hartman , =?utf-8?q?Arve_Hj=C3=B8nnev=C3=A5g?= , Todd Kjos , Christian Brauner , Carlos Llamas , Alice Ryhl , Miguel Ojeda , Boqun Feng , Gary Guo , =?utf-8?q?Bj=C3=B6rn_Roy_Baron?= , Benno Lossin , Andreas Hindborg , Trevor Gross , Danilo Krummrich , Daniel Almeida , Tamir Duberstein , Alexandre Courbot , =?utf-8?q?Onur_=C3=96zkan?= Cc: linux-kernel@vger.kernel.org, rust-for-linux@vger.kernel.org, Jahnavi MN X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=ed25519-sha256; t=1784191078; l=7221; i=jahnavimn@google.com; s=20260702; h=from:subject:message-id; bh=fNLXc//OvN2pQlLuxzKG8kuvx445LewB4RHamhDF4X4=; b=HcGTHC0GmEHRibHoUcbipqs50rjpjI032Aq6za1JpQUs3pHRudozkXrMm7c4fxa0/sTmRU8aR 8ZNM3C7ICUZCxzIQbLH6d6tWg46WsAj4WQxLWchK9lsAI/zjztwIX9f X-Developer-Key: i=jahnavimn@google.com; a=ed25519; pk=9aLfw3FepTOJwTS7jRXm7pDH87eBeZMXBPrqwU0//RE= X-Endpoint-Received: by B4 Relay for jahnavimn@google.com/20260702 with auth_id=849 X-Original-From: Jahnavi MN Reply-To: jahnavimn@google.com From: Jahnavi MN Implement a dynamic debug logging mask (`debug_mask`) for the `rust_binder` module to allow dynamic runtime configuration of log levels. This enables parity with the legacy C driver's debug mask. Since the Rust `module!` macro in the current kernel build does not yet support declaring module parameters directly in Rust, we define the `debug_mask` variable in Rust as an `Atomic` exported via FFI using `#[no_mangle]`, and link to it as `extern` in a C companion file to expose it to the kernel runtime. To verify the setup, instrument process lifecycle events (open, flush, and release) in `process.rs` under the new `BINDER_DEBUG_OPEN_CLOSE` logging mask. These entry-point events are chosen for initial validation because they represent the start of the Binder lifecycle and occur at low frequency, allowing simple runtime verification of the dynamic toggle without log noise. Reviewed-by: Carlos Llamas Reviewed-by: Alice Ryhl Signed-off-by: Jahnavi MN --- drivers/android/binder/debug.rs | 76 ++++++++++++++++++++++++++= ++++ drivers/android/binder/process.rs | 7 ++- drivers/android/binder/rust_binder_main.rs | 2 + drivers/android/binder/rust_binderfs.c | 3 ++ rust/kernel/task.rs | 7 +++ 5 files changed, 94 insertions(+), 1 deletion(-) diff --git a/drivers/android/binder/debug.rs b/drivers/android/binder/debug= .rs new file mode 100644 index 000000000000..824b10c004c3 --- /dev/null +++ b/drivers/android/binder/debug.rs @@ -0,0 +1,76 @@ +// SPDX-License-Identifier: GPL-2.0 +// Copyright (C) 2026 Google LLC. + +//! Binder debugging helpers. + +#![allow(dead_code)] + +use kernel::bits::bit_u32; +use kernel::sync::atomic::Atomic; + +kernel::impl_flags!( + /// Represents multiple debug mask flags. + #[derive(Debug, Clone, Default, Copy, PartialEq, Eq)] + pub struct DebugMasks(u32); + + /// Represents a single debug mask category. + #[derive(Debug, Clone, Copy, PartialEq, Eq)] + pub enum DebugMask { + UserError =3D bit_u32(0), + FailedTransaction =3D bit_u32(1), + DeadTransaction =3D bit_u32(2), + OpenClose =3D bit_u32(3), + DeadBinder =3D bit_u32(4), + DeathNotification =3D bit_u32(5), + ReadWrite =3D bit_u32(6), + UserRefs =3D bit_u32(7), + Threads =3D bit_u32(8), + Transaction =3D bit_u32(9), + TransactionComplete =3D bit_u32(10), + FreeBuffer =3D bit_u32(11), + InternalRefs =3D bit_u32(12), + PriorityCap =3D bit_u32(13), + Spinlocks =3D bit_u32(14), + } +); + +#[no_mangle] +pub(crate) static rust_binder_debug_mask: Atomic =3D Atomic::new( + (DebugMask::UserError as u32) + | (DebugMask::FailedTransaction as u32) + | (DebugMask::DeadTransaction as u32), +); + +/// Checks if the given debug logging category is enabled in the mask. +pub(crate) fn debug_mask_enabled(mask: DebugMask) -> bool { + let current_mask =3D rust_binder_debug_mask.load(kernel::sync::atomic:= :Relaxed); + DebugMasks(current_mask).contains(mask) +} + +/// Prints a debug log if the specified mask category is enabled. +#[macro_export] +macro_rules! binder_debug { + // Rule to explicitly specify a PID (used in kworkers). + (pid=3D$pid:expr, $mask:ident, $($arg:tt)*) =3D> { + if $crate::debug::debug_mask_enabled($crate::debug::DebugMask::$ma= sk) { + kernel::pr_info!( + "{}: {}\n", + $pid, + kernel::prelude::fmt!($($arg)*) + ); + } + }; + + // Default rule (automatically prepends "PID:TID" of the current calli= ng thread). + ($mask:ident, $($arg:tt)*) =3D> { + if $crate::debug::debug_mask_enabled($crate::debug::DebugMask::$ma= sk) { + let thread =3D kernel::current!(); + kernel::pr_info!( + "{}:{} {}\n", + thread.tgid(), + thread.pid(), + kernel::prelude::fmt!($($arg)*) + ); + } + }; +} diff --git a/drivers/android/binder/process.rs b/drivers/android/binder/pro= cess.rs index 0555c4bd503e..5240686324cf 100644 --- a/drivers/android/binder/process.rs +++ b/drivers/android/binder/process.rs @@ -1341,6 +1341,7 @@ pub(crate) fn lock_with_nodes(&self) -> WithNodes<'_>= { } =20 fn deferred_flush(&self) { + binder_debug!(pid =3D self.task.pid(), OpenClose, "flushing proces= s"); let inner =3D self.inner.lock(); for thread in inner.threads.values() { thread.exit_looper(); @@ -1348,6 +1349,8 @@ fn deferred_flush(&self) { } =20 fn deferred_release(self: Arc) { + binder_debug!(pid =3D self.task.pid(), OpenClose, "releasing proce= ss"); + let is_manager =3D { let mut inner =3D self.inner.lock(); inner.is_dead =3D true; @@ -1641,7 +1644,9 @@ fn ioctl_write_read( /// The file operations supported by `Process`. impl Process { pub(crate) fn open(ctx: ArcBorrow<'_, Context>, file: &File) -> Result= > { - Self::new(ctx.into(), ARef::from(file.cred())) + let proc =3D Self::new(ctx.into(), ARef::from(file.cred()))?; + binder_debug!(OpenClose, "opened process"); + Ok(proc) } =20 pub(crate) fn release(this: Arc, _file: &File) { diff --git a/drivers/android/binder/rust_binder_main.rs b/drivers/android/b= inder/rust_binder_main.rs index 432390aab25b..29829cb210a4 100644 --- a/drivers/android/binder/rust_binder_main.rs +++ b/drivers/android/binder/rust_binder_main.rs @@ -31,6 +31,8 @@ mod context; mod deferred_close; mod defs; +#[macro_use] +mod debug; mod error; mod node; mod page_range; diff --git a/drivers/android/binder/rust_binderfs.c b/drivers/android/binde= r/rust_binderfs.c index ade1c4d92499..300cc65562d1 100644 --- a/drivers/android/binder/rust_binderfs.c +++ b/drivers/android/binder/rust_binderfs.c @@ -51,6 +51,9 @@ DEFINE_SHOW_ATTRIBUTE(rust_binder_proc); char *rust_binder_devices_param =3D CONFIG_ANDROID_BINDER_DEVICES; module_param_named(rust_devices, rust_binder_devices_param, charp, 0444); =20 +extern u32 rust_binder_debug_mask; +module_param_named(debug_mask, rust_binder_debug_mask, uint, 0644); + static dev_t binderfs_dev; static DEFINE_MUTEX(binderfs_minors_mutex); static DEFINE_IDA(binderfs_minors); diff --git a/rust/kernel/task.rs b/rust/kernel/task.rs index 38273f4eedb5..1b290c61714d 100644 --- a/rust/kernel/task.rs +++ b/rust/kernel/task.rs @@ -210,6 +210,13 @@ pub fn pid(&self) -> Pid { unsafe { *ptr::addr_of!((*self.as_ptr()).pid) } } =20 + /// Returns the TGID (Thread Group ID / Process ID) of the given task. + pub fn tgid(&self) -> Pid { + // SAFETY: The tgid of a task never changes after initialization, = so reading this field is + // not a data race. + unsafe { *ptr::addr_of!((*self.as_ptr()).tgid) } + } + /// Returns the UID of the given task. #[inline] pub fn uid(&self) -> Kuid { --=20 2.55.0.229.g6434b31f56-goog From nobody Sat Jul 25 16:19:21 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 259703E2756; Thu, 16 Jul 2026 08:38:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784191081; cv=none; b=dD2uzv30nbXH4NQ0VX/Cq9Zvd2AEagxmeWaJQ/xbS4stNDaBttBgOatnIHUxEQTsoaTvldvcwQsBMHQJPYpRQcGa4HaYjXnlBhMD/glm/hbmARVNMj6BD5O8oJIB82WkomfS9braAKpB7A6w4nBkLSniuUJL9zvV5DpJflo1TkQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784191081; c=relaxed/simple; bh=odShkOaICLyJhGyMzAqUXfcvc03fIy2kAkkmXUoohaY=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=bimkvA1GLlSDOoOStFPL2DSsfsGtZ1VTJ2tSWUtGEfC0CxMHJq6Y9WJphKoEPlsxzzbnaTC+Ll/PhYAb9wErCMg70O6TN/ibxlN2xTbl5AHoNCPXBSEUMzlBEF/tReSHKVdXLn2mvonWMIbMFbCcOTcngHZALpEcqpRBS7PYqVs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=TliY/cpP; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="TliY/cpP" Received: by smtp.kernel.org (Postfix) with ESMTPS id 48031C2BCF5; Thu, 16 Jul 2026 08:38:00 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1784191080; bh=odShkOaICLyJhGyMzAqUXfcvc03fIy2kAkkmXUoohaY=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=TliY/cpPaR1Is+NyKvaVjvN1lppgV2S7/2/JGiQiWH5cDxbG3Nk+P/hbJyRH7F2iP leX6JhUf3yLkaRTu29mimXu9eTnQyJVotpZpcig0LgYMXvcv5W9PiMTVoce/eHRQsD 1kz6XdhWvCHA9z6p0TKh9nkU1/S6NBndviEsSIBYSyjkg6nCDJNsK2+lKb0isVbcn4 tjkmwaZNXRShL/6z6kWg2p+m4bwUQc8e/djXrG0bJ3+/kK2il8dmZ7PRhH+Q7U4gkU WjAm9TPrtq1g26ruOYNycvCoWlxUMbeiEAu0SR1xhLJx5m/FgJjrKk/cjFSWgSkkx9 ySCOtZ/YCtf8g== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2843DC44514; Thu, 16 Jul 2026 08:38:00 +0000 (UTC) From: Jahnavi MN via B4 Relay Date: Thu, 16 Jul 2026 08:37:44 +0000 Subject: [PATCH v4 2/7] rust_binder: Implement BINDER_DEBUG_USER_ERROR for freezer-related operation Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260716-rust_binder_debug_mask-v4-2-3d7436c2d2f2@google.com> References: <20260716-rust_binder_debug_mask-v4-0-3d7436c2d2f2@google.com> In-Reply-To: <20260716-rust_binder_debug_mask-v4-0-3d7436c2d2f2@google.com> To: Greg Kroah-Hartman , =?utf-8?q?Arve_Hj=C3=B8nnev=C3=A5g?= , Todd Kjos , Christian Brauner , Carlos Llamas , Alice Ryhl , Miguel Ojeda , Boqun Feng , Gary Guo , =?utf-8?q?Bj=C3=B6rn_Roy_Baron?= , Benno Lossin , Andreas Hindborg , Trevor Gross , Danilo Krummrich , Daniel Almeida , Tamir Duberstein , Alexandre Courbot , =?utf-8?q?Onur_=C3=96zkan?= Cc: linux-kernel@vger.kernel.org, rust-for-linux@vger.kernel.org, Jahnavi MN X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=ed25519-sha256; t=1784191078; l=4969; i=jahnavimn@google.com; s=20260702; h=from:subject:message-id; bh=UfyiXS9trfI9iQd4i5+rrLa2l3J3zKA1b1RhZsQegXY=; b=9gRkcoVT2fuP2u/CcvQV6K3KAQVEnZd/EsaUFflrQTCqAQuEwWo4DHaaSltg4Wx+j37bM2eLd JgUQc/kI9jTAudPA+3lblUUQqPrsrDcpPFk2PSOj1WKZrdLLFTzIQL4 X-Developer-Key: i=jahnavimn@google.com; a=ed25519; pk=9aLfw3FepTOJwTS7jRXm7pDH87eBeZMXBPrqwU0//RE= X-Endpoint-Received: by B4 Relay for jahnavimn@google.com/20260702 with auth_id=849 X-Original-From: Jahnavi MN Reply-To: jahnavimn@google.com From: Jahnavi MN This adds dynamic debug logs for: - Requesting freeze notifications on invalid references, duplicate cookies, or already active registrations. - Completing freeze notifications that are not pending or not found. - Clearing freeze notifications on invalid references, inactive notifications, or cookie mismatches. Reviewed-by: Carlos Llamas Reviewed-by: Alice Ryhl Signed-off-by: Jahnavi MN --- drivers/android/binder/freeze.rs | 40 ++++++++++++++++++++++++++++++------= ---- 1 file changed, 30 insertions(+), 10 deletions(-) diff --git a/drivers/android/binder/freeze.rs b/drivers/android/binder/free= ze.rs index f43388ed6ae2..318a9d2bb261 100644 --- a/drivers/android/binder/freeze.rs +++ b/drivers/android/binder/freeze.rs @@ -189,12 +189,15 @@ pub(crate) fn request_freeze_notif( info =3D match node_refs.by_handle.get_mut(&handle) { Some(info) =3D> info, None =3D> { - pr_warn!("BC_REQUEST_FREEZE_NOTIFICATION invalid ref {= }\n", handle); + binder_debug!( + UserError, + "BC_REQUEST_FREEZE_NOTIFICATION invalid ref {handl= e}" + ); return Err(EINVAL); } }; if info.freeze().is_some() { - pr_warn!("BC_REQUEST_FREEZE_NOTIFICATION already set\n"); + binder_debug!(UserError, "BC_REQUEST_FREEZE_NOTIFICATION a= lready set"); return Err(EINVAL); } let node_ref =3D info.node_ref(); @@ -202,7 +205,7 @@ pub(crate) fn request_freeze_notif( =20 if let rbtree::Entry::Occupied(ref dupe) =3D freeze_entry { if !dupe.get().allow_duplicate(&node_ref.node) { - pr_warn!("BC_REQUEST_FREEZE_NOTIFICATION duplicate coo= kie\n"); + binder_debug!(UserError, "BC_REQUEST_FREEZE_NOTIFICATI= ON duplicate cookie"); return Err(EINVAL); } } @@ -267,7 +270,11 @@ pub(crate) fn freeze_notif_done(self: &Arc, read= er: &mut UserSliceReader) let mut node_refs_guard =3D self.node_refs.lock(); let node_refs =3D &mut *node_refs_guard; let Some(freeze) =3D node_refs.freeze_listeners.get_mut(&cookie) e= lse { - pr_warn!("BC_FREEZE_NOTIFICATION_DONE {:016x} not found\n", co= okie.0); + binder_debug!( + UserError, + "BC_FREEZE_NOTIFICATION_DONE {:016x} not found", + cookie.0 + ); return Err(EINVAL); }; let mut clear_msg =3D None; @@ -277,8 +284,9 @@ pub(crate) fn freeze_notif_done(self: &Arc, reade= r: &mut UserSliceReader) freeze.num_cleared_duplicates +=3D 1; } else { if !freeze.is_pending { - pr_warn!( - "BC_FREEZE_NOTIFICATION_DONE {:016x} not pending\n", + binder_debug!( + UserError, + "BC_FREEZE_NOTIFICATION_DONE {:016x} not pending", cookie.0 ); return Err(EINVAL); @@ -307,19 +315,31 @@ pub(crate) fn clear_freeze_notif(self: &Arc, re= ader: &mut UserSliceReader) let mut node_refs_guard =3D self.node_refs.lock(); let node_refs =3D &mut *node_refs_guard; let Some(info) =3D node_refs.by_handle.get_mut(&handle) else { - pr_warn!("BC_CLEAR_FREEZE_NOTIFICATION invalid ref {}\n", hand= le); + binder_debug!( + UserError, + "BC_CLEAR_FREEZE_NOTIFICATION invalid ref {handle}" + ); return Err(EINVAL); }; let Some(info_cookie) =3D info.freeze() else { - pr_warn!("BC_CLEAR_FREEZE_NOTIFICATION freeze notification not= active\n"); + binder_debug!( + UserError, + "BC_CLEAR_FREEZE_NOTIFICATION freeze notification not acti= ve" + ); return Err(EINVAL); }; if *info_cookie !=3D cookie { - pr_warn!("BC_CLEAR_FREEZE_NOTIFICATION freeze notification coo= kie mismatch\n"); + binder_debug!( + UserError, + "BC_CLEAR_FREEZE_NOTIFICATION freeze notification cookie m= ismatch" + ); return Err(EINVAL); } let Some(listener) =3D node_refs.freeze_listeners.get_mut(&cookie)= else { - pr_warn!("BC_CLEAR_FREEZE_NOTIFICATION invalid cookie {}\n", h= andle); + binder_debug!( + UserError, + "BC_CLEAR_FREEZE_NOTIFICATION invalid cookie {handle}" + ); return Err(EINVAL); }; listener.is_clearing =3D true; --=20 2.55.0.229.g6434b31f56-goog From nobody Sat Jul 25 16:19:21 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 258773E00B0; Thu, 16 Jul 2026 08:38:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784191081; cv=none; b=SuLyh+vbVNmO6lOIo6sMhdNhtjA5rKgVgjv05c+LekA/uNd1NywpZGzFjwXnCdaMN75kZWnmC9LHm9a4rnpYQ0J9IzJO1HpD5neU7pUl/lF49btcKyyQqpOihjs+KZk6Vm/2ZzqKOYD+xcdHrbLtiKJMWQKjEcbdg5BfXkHaGDQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784191081; c=relaxed/simple; bh=MukFFFnDQ4BtAdIVjvGO+JcNUd67e1LDSEkPePnHsZI=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=HUmmZcyXcwigjR00e8uWI9C3qRxhBzozJs4wz1iiKBGf/Ce75XlYR+FfYufzXr7HekA2PRWL9lBRq+MUpflLVjh/Q+W3vUeq0Yju8Hm8MEMWP8nsTBnPRXdkLl7iZ31PNMsSdFym9OavpBrPP1I+M/gAT3qKciIPQlY2RMybsB4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=JsMPoh+J; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="JsMPoh+J" Received: by smtp.kernel.org (Postfix) with ESMTPS id 5D6BCC2BCF6; Thu, 16 Jul 2026 08:38:00 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1784191080; bh=MukFFFnDQ4BtAdIVjvGO+JcNUd67e1LDSEkPePnHsZI=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=JsMPoh+JWbJPs1RyHxeH/XNR9TKA1GSv14cwpPc8cM/SQ8rgvvqHw7bVlWPev5AJ4 6IB+3+1FYv2e5IGUz7Ba57ULxgYTstRZ53oe9cxrlkJl3RLVPmu507QPpoCe1vdlMz MOs+FJUIxFFNCR7JDEYPbYLspp+pf2LhurnugSZfgBsL0iSX5V4fa/vtLkPfGH093p rQs7rYtmtQv8dsoh4ZPw/wnJNmmFYCtsU4Weom7s3xbqNfYYieeqzBfkPZO2Or04mQ yDiUQnbIDQJ1AUCAqE4qdYXh1J02/S9jp72BpWIvjp9VG0Ln3E9EqxnZE/hB9Zu0AY 2xAZvAHh1nqqA== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 38922C44511; Thu, 16 Jul 2026 08:38:00 +0000 (UTC) From: Jahnavi MN via B4 Relay Date: Thu, 16 Jul 2026 08:37:45 +0000 Subject: [PATCH v4 3/7] rust_binder: Implement BINDER_DEBUG_USER_ERROR for refcounting and death notifications Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260716-rust_binder_debug_mask-v4-3-3d7436c2d2f2@google.com> References: <20260716-rust_binder_debug_mask-v4-0-3d7436c2d2f2@google.com> In-Reply-To: <20260716-rust_binder_debug_mask-v4-0-3d7436c2d2f2@google.com> To: Greg Kroah-Hartman , =?utf-8?q?Arve_Hj=C3=B8nnev=C3=A5g?= , Todd Kjos , Christian Brauner , Carlos Llamas , Alice Ryhl , Miguel Ojeda , Boqun Feng , Gary Guo , =?utf-8?q?Bj=C3=B6rn_Roy_Baron?= , Benno Lossin , Andreas Hindborg , Trevor Gross , Danilo Krummrich , Daniel Almeida , Tamir Duberstein , Alexandre Courbot , =?utf-8?q?Onur_=C3=96zkan?= Cc: linux-kernel@vger.kernel.org, rust-for-linux@vger.kernel.org, Jahnavi MN X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=ed25519-sha256; t=1784191078; l=5466; i=jahnavimn@google.com; s=20260702; h=from:subject:message-id; bh=MPq1+4h96Y5W36DnAhziQal0q+gRTp87hMmSes2tm2c=; b=GWCh9VpDuZZBw2SxZbwOkHILOj25ubXD76KhOKATbv5c2LYatkyZVthJU5yzv7aWLXr9HEtNZ LZ4gp4ukGxPD+9Kqu632d/gWC+GcWpdrcbCDr/aKjSr9RWhTooOBPUI X-Developer-Key: i=jahnavimn@google.com; a=ed25519; pk=9aLfw3FepTOJwTS7jRXm7pDH87eBeZMXBPrqwU0//RE= X-Endpoint-Received: by B4 Relay for jahnavimn@google.com/20260702 with auth_id=849 X-Original-From: Jahnavi MN Reply-To: jahnavimn@google.com From: Jahnavi MN This adds dynamic debug logs for: - Decrementing handle reference counts that are already zero. - Mismatched reference states (calling inc_ref_done with no active inc_refs, or using a weak reference as a strong reference). - Requesting or clearing death notifications on invalid references, already active notifications, or with mismatched cookies. Reviewed-by: Carlos Llamas Reviewed-by: Alice Ryhl Signed-off-by: Jahnavi MN --- drivers/android/binder/node.rs | 10 ++++++---- drivers/android/binder/process.rs | 35 ++++++++++++++++++++++++++++------- 2 files changed, 34 insertions(+), 11 deletions(-) diff --git a/drivers/android/binder/node.rs b/drivers/android/binder/node.rs index 59c5ab747bf4..fefa723d13c4 100644 --- a/drivers/android/binder/node.rs +++ b/drivers/android/binder/node.rs @@ -345,7 +345,7 @@ pub(crate) fn inc_ref_done_locked( ) -> Option> { let inner =3D self.inner.access_mut(owner_inner); if inner.active_inc_refs =3D=3D 0 { - pr_err!("inc_ref_done called when no active inc_refs"); + binder_debug!(UserError, "inc_ref_done called when no active i= nc_refs"); return None; } =20 @@ -821,6 +821,7 @@ pub(crate) fn get_count(&self) -> (usize, usize) { =20 pub(crate) fn clone(&self, strong: bool) -> Result { if strong && self.strong_count =3D=3D 0 { + binder_debug!(UserError, "tried to use weak ref as strong ref"= ); return Err(EINVAL); } Ok(self @@ -861,9 +862,10 @@ pub(crate) fn update(&mut self, inc: bool, strong: boo= l) -> bool { *count +=3D 1; } else { if *count =3D=3D 0 { - pr_warn!( - "pid {} performed invalid decrement on ref\n", - kernel::current!().pid() + binder_debug!( + UserError, + "performed invalid {} decrement on ref", + if strong { "strong" } else { "weak" } ); return false; } diff --git a/drivers/android/binder/process.rs b/drivers/android/binder/pro= cess.rs index 5240686324cf..1d3a71292de0 100644 --- a/drivers/android/binder/process.rs +++ b/drivers/android/binder/process.rs @@ -912,7 +912,13 @@ pub(crate) fn get_transaction_node(&self, handle: u32)= -> BinderResult } Ok(node_ref) } else { - Ok(self.get_node_from_handle(handle, true)?) + match self.get_node_from_handle(handle, true) { + Ok(node_ref) =3D> Ok(node_ref), + Err(err) =3D> { + binder_debug!(UserError, "got transaction to invalid h= andle {handle}"); + Err(err.into()) + } + } } } =20 @@ -997,7 +1003,7 @@ pub(crate) fn update_ref( } else { // All refs are cleared in process exit, so this warning is ex= pected in that case. if !self.inner.lock().is_dead { - pr_warn!("{}: no such ref {handle}\n", self.pid_in_current= _ns()); + binder_debug!(UserError, "no such ref {handle}"); } } Ok(()) @@ -1250,13 +1256,19 @@ pub(crate) fn request_death( })?; let mut refs =3D self.node_refs.lock(); let Some(info) =3D refs.by_handle.get_mut(&handle) else { - pr_warn!("BC_REQUEST_DEATH_NOTIFICATION invalid ref {handle}\n= "); + binder_debug!( + UserError, + "BC_REQUEST_DEATH_NOTIFICATION invalid ref {handle}" + ); return Ok(()); }; =20 // Nothing to do if there is already a death notification request = for this handle. if info.death().is_some() { - pr_warn!("BC_REQUEST_DEATH_NOTIFICATION death notification alr= eady set\n"); + binder_debug!( + UserError, + "BC_REQUEST_DEATH_NOTIFICATION death notification already = set" + ); return Ok(()); } =20 @@ -1293,17 +1305,26 @@ pub(crate) fn clear_death(&self, reader: &mut UserS= liceReader, thread: &Thread) =20 let mut refs =3D self.node_refs.lock(); let Some(info) =3D refs.by_handle.get_mut(&handle) else { - pr_warn!("BC_CLEAR_DEATH_NOTIFICATION invalid ref {handle}\n"); + binder_debug!( + UserError, + "BC_CLEAR_DEATH_NOTIFICATION invalid ref {handle}" + ); return Ok(()); }; =20 let Some(death) =3D info.death().take() else { - pr_warn!("BC_CLEAR_DEATH_NOTIFICATION death notification not a= ctive\n"); + binder_debug!( + UserError, + "BC_CLEAR_DEATH_NOTIFICATION death notification not active" + ); return Ok(()); }; if death.cookie !=3D cookie { *info.death() =3D Some(death); - pr_warn!("BC_CLEAR_DEATH_NOTIFICATION death notification cooki= e mismatch\n"); + binder_debug!( + UserError, + "BC_CLEAR_DEATH_NOTIFICATION death notification cookie mis= match" + ); return Ok(()); } =20 --=20 2.55.0.229.g6434b31f56-goog From nobody Sat Jul 25 16:19:21 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 25AB53F23D9; Thu, 16 Jul 2026 08:38:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784191081; cv=none; b=DUGpA01LnMD+XVLqu8WRrF8xdDk81lXi+HF0zKZfYI8A/lLQcg8bokFkSHbc5Qh09YBSzbwSH1xBtisQMfy/9ggnGA5RJz9mRGddIBeWOz4V1/V8Lp146eSZszIbZPtsoZ3INKa+mmXYAj7gO86mOBqufCNlxuIKNCGK+dTYOb0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784191081; c=relaxed/simple; bh=SBi1trShH97zf8nrrdvyzKaSbwxiVpQL+okLmrxMFnw=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=ufSgvlZ+T8FyTc2gBY4Po/zZJWzNYESpdBZ/sndvHwq0lmt/c6RSlvm1bVHmkTErvuRq9nmcZ0/P1oxpoHKMOKKmLWYG2n4UYQY7OQFv6PRLEGnRxUZN/3bzwXRpGXTaawxD5hPgT8O8kvwNgAD4XPuCSAmOSoFmmOfy3A8xwmg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=FLUFkYNL; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="FLUFkYNL" Received: by smtp.kernel.org (Postfix) with ESMTPS id 65BA2C2BCB9; Thu, 16 Jul 2026 08:38:00 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1784191080; bh=SBi1trShH97zf8nrrdvyzKaSbwxiVpQL+okLmrxMFnw=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=FLUFkYNL+dXWt1JBoH5cI9g9/V9SHC9RRu7zhxqoYWO5KPV9YMuxGxMrUft1iNz4q XQBYXQ2MXEnqAvMZkwxPZxXO0eT0W4WXuErzjATgKqqdW80lweWDzHmcVdVOOhBEfp JS9bEwfzKiffdC0jpH/0tlyt3W15b2sI78rELKFLZosvN8IX+u81HEHgbYu2uczuwb FhQTLdpFMt0VJ+5iPGDZGABmyBc/hwguF9jarnZ62C1nCRJ3DVkBOA06yso6y1U1qf RU+czLck0XO9Q+K8sUURFmKKUfqpD8Fs9Q4iYH6eS4bwVwAE+43/F6Qmgh2htL5htS 1MVklROMsHQbA== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 489E8C44517; Thu, 16 Jul 2026 08:38:00 +0000 (UTC) From: Jahnavi MN via B4 Relay Date: Thu, 16 Jul 2026 08:37:46 +0000 Subject: [PATCH v4 4/7] rust_binder: Implement BINDER_DEBUG_USER_ERROR for transaction parsing failures Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260716-rust_binder_debug_mask-v4-4-3d7436c2d2f2@google.com> References: <20260716-rust_binder_debug_mask-v4-0-3d7436c2d2f2@google.com> In-Reply-To: <20260716-rust_binder_debug_mask-v4-0-3d7436c2d2f2@google.com> To: Greg Kroah-Hartman , =?utf-8?q?Arve_Hj=C3=B8nnev=C3=A5g?= , Todd Kjos , Christian Brauner , Carlos Llamas , Alice Ryhl , Miguel Ojeda , Boqun Feng , Gary Guo , =?utf-8?q?Bj=C3=B6rn_Roy_Baron?= , Benno Lossin , Andreas Hindborg , Trevor Gross , Danilo Krummrich , Daniel Almeida , Tamir Duberstein , Alexandre Courbot , =?utf-8?q?Onur_=C3=96zkan?= Cc: linux-kernel@vger.kernel.org, rust-for-linux@vger.kernel.org, Jahnavi MN X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=ed25519-sha256; t=1784191078; l=8410; i=jahnavimn@google.com; s=20260702; h=from:subject:message-id; bh=q4pagxc+LGq8HMGgmdSA8ewelGGdc1UF+C5kmn3peZM=; b=RwO/0NEJyZ1vzZkcLvbxcD4LoipP4eSshcvPTnb1CtTfGQB1BOKq1UCdIqRuPMKpv3LIQh4zI XW4PqUaxCNMB+SZzW+y5Z63qIEouzHJutWUYvUtArP0tirkGaAwQ+1r X-Developer-Key: i=jahnavimn@google.com; a=ed25519; pk=9aLfw3FepTOJwTS7jRXm7pDH87eBeZMXBPrqwU0//RE= X-Endpoint-Received: by B4 Relay for jahnavimn@google.com/20260702 with auth_id=849 X-Original-From: Jahnavi MN Reply-To: jahnavimn@google.com From: Jahnavi MN This adds dynamic debug logs in `thread.rs` for: - File descriptor array (FDA) parent offset and parent buffer address alignment misalignments. - Memory copy, write, and translation failures during transaction serialization (including out-of-bounds pointer fixups). - Incoming transactions or replies that do not match the expected thread calling stack (such as out-of-order replies). Reviewed-by: Carlos Llamas Reviewed-by: Alice Ryhl Signed-off-by: Jahnavi MN --- drivers/android/binder/thread.rs | 54 ++++++++++++++++++++++++------------= ---- 1 file changed, 32 insertions(+), 22 deletions(-) diff --git a/drivers/android/binder/thread.rs b/drivers/android/binder/thre= ad.rs index 19f881948a84..9f0178a13d6f 100644 --- a/drivers/android/binder/thread.rs +++ b/drivers/android/binder/thread.rs @@ -728,11 +728,12 @@ fn translate_object( let alloc_offset =3D match sg_state.unused_buffer_space.cl= aim_next(obj_length) { Ok(alloc_offset) =3D> alloc_offset, Err(err) =3D> { - pr_warn!( - "Failed to claim space for a BINDER_TYPE_PTR. = (offset: {}, limit: {}, size: {})", + binder_debug!( + UserError, + "failed to claim space for a BINDER_TYPE_PTR (= offset: {}, limit: {}, size: {})", sg_state.unused_buffer_space.offset, sg_state.unused_buffer_space.limit, - obj_length, + obj_length ); return Err(err.into()); } @@ -811,6 +812,7 @@ fn translate_object( let fds_len =3D num_fds.checked_mul(size_of::()).ok_o= r(EINVAL)?; =20 if !is_aligned(parent_offset, size_of::()) { + binder_debug!(UserError, "FDA parent offset not aligne= d correctly"); return Err(EINVAL.into()); } =20 @@ -829,6 +831,7 @@ fn translate_object( }; =20 if !is_aligned(parent_entry.sender_uaddr, size_of::()= ) { + binder_debug!(UserError, "FDA parent buffer not aligne= d correctly"); return Err(EINVAL.into()); } =20 @@ -912,12 +915,9 @@ fn apply_sg(&self, alloc: &mut Allocation, sg_state: &= mut ScatterGatherState) -> =20 let target_offset_end =3D fixup_offset.checked_add(fixup_l= en).ok_or(EINVAL)?; if fixup_offset < end_of_previous_fixup || offset_end < ta= rget_offset_end { - pr_warn!( - "Fixups oob {} {} {} {}", - fixup_offset, - end_of_previous_fixup, - offset_end, - target_offset_end + binder_debug!( + UserError, + "fixups oob {fixup_offset} {end_of_previous_fixup}= {offset_end} {target_offset_end}" ); return Err(EINVAL.into()); } @@ -925,18 +925,21 @@ fn apply_sg(&self, alloc: &mut Allocation, sg_state: = &mut ScatterGatherState) -> let copy_off =3D end_of_previous_fixup; let copy_len =3D fixup_offset - end_of_previous_fixup; if let Err(err) =3D alloc.copy_into(&mut reader, copy_off,= copy_len) { - pr_warn!("Failed copying into alloc: {:?}", err); + binder_debug!(UserError, "failed copying into alloc: {= err:?}"); return Err(err.into()); } if let PointerFixupEntry::Fixup { pointer_value, .. } =3D = fixup { let res =3D alloc.write::(fixup_offset, pointer_v= alue); if let Err(err) =3D res { - pr_warn!("Failed copying ptr into alloc: {:?}", er= r); + binder_debug!(UserError, "failed copying ptr into = alloc: {err:?}"); return Err(err.into()); } } if let Err(err) =3D reader.skip(fixup_len) { - pr_warn!("Failed skipping {} from reader: {:?}", fixup= _len, err); + binder_debug!( + UserError, + "failed skipping {fixup_len} from reader: {err:?}" + ); return Err(err.into()); } end_of_previous_fixup =3D target_offset_end; @@ -944,7 +947,7 @@ fn apply_sg(&self, alloc: &mut Allocation, sg_state: &m= ut ScatterGatherState) -> let copy_off =3D end_of_previous_fixup; let copy_len =3D offset_end - end_of_previous_fixup; if let Err(err) =3D alloc.copy_into(&mut reader, copy_off, cop= y_len) { - pr_warn!("Failed copying remainder into alloc: {:?}", err); + binder_debug!(UserError, "failed copying remainder into al= loc: {err:?}"); return Err(err.into()); } } @@ -1048,7 +1051,7 @@ pub(crate) fn copy_transaction_data( let offset: usize =3D offset.try_into().map_err(|_| EINVAL= )?; =20 if offset < end_of_previous_object || !is_aligned(offset, = size_of::()) { - pr_warn!("Got transaction with invalid offset."); + binder_debug!(UserError, "got transaction with invalid= offset"); return Err(EINVAL.into()); } =20 @@ -1073,7 +1076,7 @@ pub(crate) fn copy_transaction_data( ) { Ok(()) =3D> end_of_previous_object =3D offset + object= .size(), Err(err) =3D> { - pr_warn!("Error while translating object."); + binder_debug!(UserError, "error while translating = object: {err:?}"); return Err(err); } } @@ -1093,15 +1096,12 @@ pub(crate) fn copy_transaction_data( )?; =20 if let Some(sg_state) =3D sg_state.as_mut() { - if let Err(err) =3D self.apply_sg(&mut alloc, sg_state) { - pr_warn!("Failure in apply_sg: {:?}", err); - return Err(err); - } + self.apply_sg(&mut alloc, sg_state)?; } =20 if let Some((off_out, secctx)) =3D secctx.as_mut() { if let Err(err) =3D alloc.write(secctx_off, secctx.as_bytes())= { - pr_warn!("Failed to write security context: {:?}", err); + binder_debug!(UserError, "failed to write security context= : {err:?}"); return Err(err.into()); } **off_out =3D secctx_off; @@ -1303,7 +1303,7 @@ fn transaction_inner(self: &Arc, info: &mut Tra= nsactionInfo) -> BinderResu { let mut inner =3D self.inner.lock(); if !transaction.is_stacked_on(&inner.current_transaction) { - pr_warn!("Transaction stack changed during transaction!"); + binder_debug!(UserError, "got new transaction with bad tra= nsaction stack"); return Err(EINVAL.into()); } inner.current_transaction =3D Some(transaction.clone_arc()); @@ -1326,8 +1326,18 @@ fn transaction_inner(self: &Arc, info: &mut Tr= ansactionInfo) -> BinderResu } =20 fn reply_inner(self: &Arc, info: &mut TransactionInfo) -> Binder= Result { - let orig =3D self.inner.lock().pop_transaction_to_reply(self)?; + let orig =3D match self.inner.lock().pop_transaction_to_reply(self= ) { + Ok(orig) =3D> orig, + Err(err) =3D> { + binder_debug!(UserError, "got reply transaction with no tr= ansaction stack"); + return Err(err.into()); + } + }; if !orig.from.is_current_transaction(&orig) { + binder_debug!( + UserError, + "got reply transaction with bad transaction stack" + ); return Err(EINVAL.into()); } =20 --=20 2.55.0.229.g6434b31f56-goog From nobody Sat Jul 25 16:19:21 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 944A23F39DB; Thu, 16 Jul 2026 08:38:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784191081; cv=none; b=WLGGIXjd5DXNgpxWZe+BAZfH+T4/ghN4DKxpjia+fXyqtyiXgkt4deD3D4tljTygwa8hajhJT7lT16is2gVGNv/xFnwJG4xJIvHXT57tIcE3158K0nYrzirk8lRr+pQ8xdfErciwwG46TECUWKsrgbpGKdz5iu2luV2Goo3mx+g= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784191081; c=relaxed/simple; bh=YfYIYubHv2Q4ihushjbAMl2ffommTXWfGXmYtafqEyM=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=lU8h8zOByK9GRLMT2CNHB0MyR5OtlvymcGajzbACfLahfsZtua+SE99rjiG4/M1a2pDke3n2/XAaILiZVtAGEV66znkbSxVT1OwxZXci0HrT9e636s/SN9ULp/aJe6YOaoly9ZPA5HghxzhHs+6aAFMTXB+99WK8x7dJFztpnpM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=jkcwfs+U; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="jkcwfs+U" Received: by smtp.kernel.org (Postfix) with ESMTPS id 6E5C9C4AF0C; Thu, 16 Jul 2026 08:38:00 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1784191080; bh=YfYIYubHv2Q4ihushjbAMl2ffommTXWfGXmYtafqEyM=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=jkcwfs+U80ZmpRi0HSyYkjjme0S+BX3AiJtRfVjMRbsDth2u0I0PmDSCAvFdb0Ick prgoXeRwfsR4/zF/sQwjtG6Gzs5KY7nOjAwxtet/6i2xBipGfUnX/RmkDvNK+cBXXx IfR9wZ+0gE2GERgSWICojTEvNqCrvAvykbc644hbdwmOydpcwUReL28wrsT4QlpPSM /WrZs7KKvYhwXAWiX1TtinwToP+qALKBqIOrhSfyvG25G+P9VPci2ccKPrrU9v3T2H cKng9/qcaHAX9XCzFXr2JA9AAdLmoGtP/Bd4P4YToOqSW9tUbhwOLKRf528jCgfsjL aiJ84mGB+mrFA== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 58B04C44515; Thu, 16 Jul 2026 08:38:00 +0000 (UTC) From: Jahnavi MN via B4 Relay Date: Thu, 16 Jul 2026 08:37:47 +0000 Subject: [PATCH v4 5/7] rust_binder: Implement BINDER_DEBUG_FAILED_TRANSACTION Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260716-rust_binder_debug_mask-v4-5-3d7436c2d2f2@google.com> References: <20260716-rust_binder_debug_mask-v4-0-3d7436c2d2f2@google.com> In-Reply-To: <20260716-rust_binder_debug_mask-v4-0-3d7436c2d2f2@google.com> To: Greg Kroah-Hartman , =?utf-8?q?Arve_Hj=C3=B8nnev=C3=A5g?= , Todd Kjos , Christian Brauner , Carlos Llamas , Alice Ryhl , Miguel Ojeda , Boqun Feng , Gary Guo , =?utf-8?q?Bj=C3=B6rn_Roy_Baron?= , Benno Lossin , Andreas Hindborg , Trevor Gross , Danilo Krummrich , Daniel Almeida , Tamir Duberstein , Alexandre Courbot , =?utf-8?q?Onur_=C3=96zkan?= Cc: linux-kernel@vger.kernel.org, rust-for-linux@vger.kernel.org, Jahnavi MN X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=ed25519-sha256; t=1784191078; l=2595; i=jahnavimn@google.com; s=20260702; h=from:subject:message-id; bh=+4rw0vNjIoFTKWAClTzY1+yTtFeuL8UUoNYjyIOP6gQ=; b=sNkwuFcD0fc+U58aKKejbz1SmO1qojohE/ZwsyuerIf0aHd30yIeNEiDks1l4am80YKuIwell XmKnzIwIftqCvvTdC6BfsiUC0IPNCg3lyGg1vNqpMxMOsnXNhUoL07D X-Developer-Key: i=jahnavimn@google.com; a=ed25519; pk=9aLfw3FepTOJwTS7jRXm7pDH87eBeZMXBPrqwU0//RE= X-Endpoint-Received: by B4 Relay for jahnavimn@google.com/20260702 with auth_id=849 X-Original-From: Jahnavi MN Reply-To: jahnavimn@google.com From: Jahnavi MN This adds dynamic debug logs for: - Failed replies, target process deaths, and error code deliveries. - Detailed transaction failure diagnostics (including sender/receiver PIDs, TIDs, transaction IDs, buffer sizes, and error codes). Reviewed-by: Carlos Llamas Reviewed-by: Alice Ryhl Signed-off-by: Jahnavi MN --- drivers/android/binder/thread.rs | 21 ++++++++++++++++----- drivers/android/binder/transaction.rs | 8 ++++++++ 2 files changed, 24 insertions(+), 5 deletions(-) diff --git a/drivers/android/binder/thread.rs b/drivers/android/binder/thre= ad.rs index 9f0178a13d6f..38b90c79c057 100644 --- a/drivers/android/binder/thread.rs +++ b/drivers/android/binder/thread.rs @@ -1275,11 +1275,22 @@ fn transaction(self: &Arc, cmd: u32, reader: = &mut UserSliceReader) -> Resu } } =20 - pr_warn!( - "{}:{} transaction to {} failed: {err:?}", - info.from_pid, - info.from_tid, - info.to_pid + binder_debug!( + FailedTransaction, + "transaction {} to {}:{} failed {:?}, code {} size {}-= {}", + if info.is_reply { + "reply" + } else if info.is_oneway() { + "async" + } else { + "call" + }, + info.to_pid, + info.to_tid, + err, + info.code, + info.data_size, + info.offsets_size ); } } diff --git a/drivers/android/binder/transaction.rs b/drivers/android/binder= /transaction.rs index afef5b46eac2..069c792d2200 100644 --- a/drivers/android/binder/transaction.rs +++ b/drivers/android/binder/transaction.rs @@ -404,6 +404,14 @@ fn do_work( } else { // On failure to process the list, we send a reply back to the= sender and ignore the // transaction on the recipient. + binder_debug!( + FailedTransaction, + "transaction {} to {} failed, fd fixups failed, size {}-{}= ", + self.debug_id, + self.to.task.pid(), + self.data_size, + self.offsets_size + ); return Ok(true); }; =20 --=20 2.55.0.229.g6434b31f56-goog From nobody Sat Jul 25 16:19:21 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 945A03F39DC; Thu, 16 Jul 2026 08:38:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784191081; cv=none; b=tG9VTmMWN2OavY98QdjpjcNK7PjOWACxOQ35W4nkb3mW6h8cbVuY8DTKFJ6srZHq2Px94FOOiul3nMeLmzQYm+I6WbKUYE0f0Y6wM0fdEuYxDNXHIEIv2dJ42wOXq1fJBH/OxChFqjEXRrroJ77Rj3gQ4p3wg01yIcVrm7ty6RY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784191081; c=relaxed/simple; bh=T82V1oVLu3MC1fe9ouNqKKzzEAuMrq4/uaOCVzuAqDA=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=YHMujOk09INuqjWh8sQ5gaLS1Ob6f342jdXmVd32y5dbvw0v6ny0gNxWgbRnvj1vZb3GwPWSPdZGHrHs26E4LT0Sj4X5zQKFFvhPZcAru1RWMQ5ZIURb2Yjw1ElHiPtMjGBzw83VEhsVp0Ju1Amo9CsIaxomZ4EJYkQnJ61WpGo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=lx4lfLaw; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="lx4lfLaw" Received: by smtp.kernel.org (Postfix) with ESMTPS id 7D461C32782; Thu, 16 Jul 2026 08:38:00 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1784191080; bh=T82V1oVLu3MC1fe9ouNqKKzzEAuMrq4/uaOCVzuAqDA=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=lx4lfLaw9IUK5vbcByb+5LFYIEdVQhcEO8T364YWOLT0rQ9F15hs9UMqKSRIW/zFh fUBUwdcDCwBRO8DBDJgoS1JptodCv623evIv/H+5pcN7yZxzCsNYNMv318fLV3Lu/G hbAfjdOBtcaN7ngLYEA7/tQEmYSEvjciF7bjmsM50rBvQ8cR9dvU41kXy7QrYAB5W+ I5nAhbxskPFF2FXmuamrPUyd85jwFvpgoL4omJvwSp1Km4+y6E5JVJM7c3WlcV8TNq smnAabNx0o8q4j6ytwvYkXp3rKJtUhaUgEVdM8/ARyMcHigLb3fjnR9npUojfzHBoX 2rXkXTuIk81fw== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 67CD0C44518; Thu, 16 Jul 2026 08:38:00 +0000 (UTC) From: Jahnavi MN via B4 Relay Date: Thu, 16 Jul 2026 08:37:48 +0000 Subject: [PATCH v4 6/7] rust_binder: Implement BINDER_DEBUG_DEATH_NOTIFICATION Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260716-rust_binder_debug_mask-v4-6-3d7436c2d2f2@google.com> References: <20260716-rust_binder_debug_mask-v4-0-3d7436c2d2f2@google.com> In-Reply-To: <20260716-rust_binder_debug_mask-v4-0-3d7436c2d2f2@google.com> To: Greg Kroah-Hartman , =?utf-8?q?Arve_Hj=C3=B8nnev=C3=A5g?= , Todd Kjos , Christian Brauner , Carlos Llamas , Alice Ryhl , Miguel Ojeda , Boqun Feng , Gary Guo , =?utf-8?q?Bj=C3=B6rn_Roy_Baron?= , Benno Lossin , Andreas Hindborg , Trevor Gross , Danilo Krummrich , Daniel Almeida , Tamir Duberstein , Alexandre Courbot , =?utf-8?q?Onur_=C3=96zkan?= Cc: linux-kernel@vger.kernel.org, rust-for-linux@vger.kernel.org, Jahnavi MN X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=ed25519-sha256; t=1784191078; l=2692; i=jahnavimn@google.com; s=20260702; h=from:subject:message-id; bh=JbTuHL6w3vDZL9VcRbA4qukZLLJuEs0Io07aTcZSl3U=; b=0SD0pPCuRQaNLetd1aYsu2934fsLU8mPM1QD1uuqVY6lPn/IXkmXrtoMFC5eoh4urjdqgZKwG kKUbIR2kStsA2LBvGUcWdHBXXFvTSrp7f+oDMeFHFKX9PQ199R4aEcf X-Developer-Key: i=jahnavimn@google.com; a=ed25519; pk=9aLfw3FepTOJwTS7jRXm7pDH87eBeZMXBPrqwU0//RE= X-Endpoint-Received: by B4 Relay for jahnavimn@google.com/20260702 with auth_id=849 X-Original-From: Jahnavi MN Reply-To: jahnavimn@google.com From: Jahnavi MN This adds dynamic debug logs for: - Memory allocation (OOM) failures when requesting death notifications - Registration and cancellation lifecycle events (BC_REQUEST / BC_CLEAR) - Delivery of death notification events to userspace (BR_DEAD_BINDER) Reviewed-by: Carlos Llamas Reviewed-by: Alice Ryhl Signed-off-by: Jahnavi MN --- drivers/android/binder/node.rs | 5 +++++ drivers/android/binder/process.rs | 14 ++++++++++++++ 2 files changed, 19 insertions(+) diff --git a/drivers/android/binder/node.rs b/drivers/android/binder/node.rs index fefa723d13c4..8a87dc366aa9 100644 --- a/drivers/android/binder/node.rs +++ b/drivers/android/binder/node.rs @@ -1107,6 +1107,11 @@ fn do_work( // We're still holding the inner lock, so it cannot be aborted= while we insert it into // the delivered list. process_inner.death_delivered(self.clone()); + binder_debug!( + DeathNotification, + "sending death notification, cookie {:016x}", + cookie + ); BR_DEAD_BINDER }; =20 diff --git a/drivers/android/binder/process.rs b/drivers/android/binder/pro= cess.rs index 1d3a71292de0..eb2f08bec655 100644 --- a/drivers/android/binder/process.rs +++ b/drivers/android/binder/process.rs @@ -1253,6 +1253,10 @@ pub(crate) fn request_death( // Queue BR_ERROR if we can't allocate memory for the death notifi= cation. let death =3D UniqueArc::new_uninit(GFP_KERNEL).inspect_err(|_| { thread.push_return_work(BR_ERROR); + binder_debug!( + DeathNotification, + "BC_REQUEST_DEATH_NOTIFICATION failed due to memory alloca= tion failure" + ); })?; let mut refs =3D self.node_refs.lock(); let Some(info) =3D refs.by_handle.get_mut(&handle) else { @@ -1296,6 +1300,11 @@ pub(crate) fn request_death( info.node_ref().node.add_death(death, &mut owner_inner); } } + binder_debug!( + DeathNotification, + "BC_REQUEST_DEATH_NOTIFICATION handle {handle} cookie {:016x}", + cookie + ); Ok(()) } =20 @@ -1339,6 +1348,11 @@ pub(crate) fn clear_death(&self, reader: &mut UserSl= iceReader, thread: &Thread) } } =20 + binder_debug!( + DeathNotification, + "BC_CLEAR_DEATH_NOTIFICATION handle {handle} cookie {:016x}", + cookie + ); Ok(()) } =20 --=20 2.55.0.229.g6434b31f56-goog From nobody Sat Jul 25 16:19:21 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 830753F39CB; Thu, 16 Jul 2026 08:38:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784191081; cv=none; b=ZfT6O1zzDCtJI3OErtwIjXAJvU5cB2tzQK4AgslIYO152EFTTJVlvW1k2fe1Q7uk2Px20tWdjKeXt0ENhylcdE0Rb1Ejrk9Zfm96kBW7/SC0QS4S5gatoFtFZ3lMUeE8LN47+BTuvcy2Mk4yJhtFi75IWqn/3WPyFP1BJ7/3Ruk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784191081; c=relaxed/simple; bh=bgk2D4V2+BHgkhPzUltec0clKDoxoVmbC0OW/9XowsI=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=h/3cXxqwtD1hImsE4sQbTzw2iops/jRqR8ag3x8ApUFXUnb1aiKi90ZFDEGBbHiKOAZG2qm6bPL2WhOHvuyI7JUShFvmLTjDVhaXTPXYhrjZ1GCCi32N5H1ZJ0Kyy6aBGCj+j8RrY2zrh/udsEdCwETSUONZbg4kdk0y61LQDWE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=Qmncohsp; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="Qmncohsp" Received: by smtp.kernel.org (Postfix) with ESMTPS id 95B96C4AF49; Thu, 16 Jul 2026 08:38:00 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1784191080; bh=bgk2D4V2+BHgkhPzUltec0clKDoxoVmbC0OW/9XowsI=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=QmncohspuIUJ4khDzBo7+RvKI9FI0MtravLFXG2Z6A/uN2/Ut0Njdboy9kEYNgOaA X1ifidnAGYE5mIzLP0RiY7j6Tj+MdQcflUrxm7JMOO0/oaagElIpekYo0/ShkJC0n4 qVUJYohwRbs5+LmmtIBUiBeZ/w3lUV65DpKtWDC06ap1HNrKpwhgXnv/ZMPxkMAIks t2ETA+rvauTBXAhj9YjSVziM4uizdsn863V+e3FL5CvcrNaXniQ7rI84cq0Si879bE ZTa6SxBmW1wMfCMC5fS03zcq278Uc4LIfudG9dbgrOEU4j2vMGu+1ZagVxcI0b7gk3 sJbDZZkgXyL1A== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 78CA0C44501; Thu, 16 Jul 2026 08:38:00 +0000 (UTC) From: Jahnavi MN via B4 Relay Date: Thu, 16 Jul 2026 08:37:49 +0000 Subject: [PATCH v4 7/7] rust_binder: Implement BINDER_DEBUG_DEAD_TRANSACTION Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260716-rust_binder_debug_mask-v4-7-3d7436c2d2f2@google.com> References: <20260716-rust_binder_debug_mask-v4-0-3d7436c2d2f2@google.com> In-Reply-To: <20260716-rust_binder_debug_mask-v4-0-3d7436c2d2f2@google.com> To: Greg Kroah-Hartman , =?utf-8?q?Arve_Hj=C3=B8nnev=C3=A5g?= , Todd Kjos , Christian Brauner , Carlos Llamas , Alice Ryhl , Miguel Ojeda , Boqun Feng , Gary Guo , =?utf-8?q?Bj=C3=B6rn_Roy_Baron?= , Benno Lossin , Andreas Hindborg , Trevor Gross , Danilo Krummrich , Daniel Almeida , Tamir Duberstein , Alexandre Courbot , =?utf-8?q?Onur_=C3=96zkan?= Cc: linux-kernel@vger.kernel.org, rust-for-linux@vger.kernel.org, Jahnavi MN X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=ed25519-sha256; t=1784191078; l=12116; i=jahnavimn@google.com; s=20260702; h=from:subject:message-id; bh=HUSRohfF0RC2eO/wDrADgQuF2C8u3Zj482GgfOMn2ic=; b=9t+WIVTZyOJmhsO2p11t9eoVLdWJunmnyEsRiX+NPVm+aFy77EnSRNS43GGT/BFg/lYWQ96DV nRZBGbfir82BcOiF7P9iB8kTZf+eEUYS+aIljXgI1qo8zp+v2ZPVDjI X-Developer-Key: i=jahnavimn@google.com; a=ed25519; pk=9aLfw3FepTOJwTS7jRXm7pDH87eBeZMXBPrqwU0//RE= X-Endpoint-Received: by B4 Relay for jahnavimn@google.com/20260702 with auth_id=849 X-Original-From: Jahnavi MN Reply-To: jahnavimn@google.com From: Jahnavi MN This adds dynamic debug logs for: - Releasing active transactions during thread stack unwinding. - Discarded transaction error codes when a thread exits. - Undelivered transaction acknowledgments (TRANSACTION_COMPLETE) upon thread exit. - Undelivered process death and freeze notifications when processes exit or die. - Undelivered transactions canceled due to target process death. We now store the process PID in `ThreadError`, `DeliverCode`, and `FreezeMessage` to ensure the correct PID is logged on cancellation. This is necessary because `cancel()` runs from background `kworkers`, which would otherwise print the wrong PID. Reviewed-by: Alice Ryhl Reviewed-by: Carlos Llamas Signed-off-by: Jahnavi MN --- drivers/android/binder/freeze.rs | 24 +++++++++++------ drivers/android/binder/node.rs | 9 ++++++- drivers/android/binder/rust_binder_main.rs | 14 ++++++++-- drivers/android/binder/thread.rs | 42 +++++++++++++++++++++++---= ---- drivers/android/binder/transaction.rs | 7 +++++ 5 files changed, 76 insertions(+), 20 deletions(-) diff --git a/drivers/android/binder/freeze.rs b/drivers/android/binder/free= ze.rs index 318a9d2bb261..66912b4cb527 100644 --- a/drivers/android/binder/freeze.rs +++ b/drivers/android/binder/freeze.rs @@ -60,6 +60,7 @@ fn allow_duplicate(&self, node: &DArc) -> bool { /// Represents a notification that the freeze state has changed. pub(crate) struct FreezeMessage { cookie: FreezeCookie, + pid: i32, } =20 kernel::list::impl_list_arc_safe! { @@ -73,8 +74,8 @@ fn new(flags: kernel::alloc::Flags) -> Result { UniqueArc::new_uninit(flags) } =20 - fn init(ua: UninitFM, cookie: FreezeCookie) -> DLArc { - match ua.pin_init_with(DTRWrap::new(FreezeMessage { cookie })) { + fn init(ua: UninitFM, cookie: FreezeCookie, pid: i32) -> DLArc { + match ua.pin_init_with(DTRWrap::new(FreezeMessage { cookie, pid })= ) { Ok(msg) =3D> ListArc::from(msg), Err(err) =3D> match err {}, } @@ -140,7 +141,14 @@ fn do_work( } } =20 - fn cancel(self: DArc) {} + fn cancel(self: DArc) { + binder_debug!( + pid =3D self.pid, + DeadTransaction, + "undelivered freeze notification, {:016x}", + self.cookie.0 + ); + } =20 fn should_sync_wakeup(&self) -> bool { false @@ -258,7 +266,7 @@ pub(crate) fn request_freeze_notif( } =20 *info.freeze() =3D Some(cookie); - let msg =3D FreezeMessage::init(msg, cookie); + let msg =3D FreezeMessage::init(msg, cookie, self.task.pid()); drop(node_refs_guard); let _ =3D self.push_work(msg); Ok(()) @@ -279,7 +287,7 @@ pub(crate) fn freeze_notif_done(self: &Arc, reade= r: &mut UserSliceReader) }; let mut clear_msg =3D None; if freeze.num_pending_duplicates > 0 { - clear_msg =3D Some(FreezeMessage::init(alloc, cookie)); + clear_msg =3D Some(FreezeMessage::init(alloc, cookie, self.tas= k.pid())); freeze.num_pending_duplicates -=3D 1; freeze.num_cleared_duplicates +=3D 1; } else { @@ -294,7 +302,7 @@ pub(crate) fn freeze_notif_done(self: &Arc, reade= r: &mut UserSliceReader) let is_frozen =3D freeze.node.owner.inner.lock().is_frozen.is_= fully_frozen(); if freeze.is_clearing || freeze.last_is_frozen !=3D Some(is_fr= ozen) { // Immediately send another FreezeMessage. - clear_msg =3D Some(FreezeMessage::init(alloc, cookie)); + clear_msg =3D Some(FreezeMessage::init(alloc, cookie, self= .task.pid())); } freeze.is_pending =3D false; } @@ -347,7 +355,7 @@ pub(crate) fn clear_freeze_notif(self: &Arc, read= er: &mut UserSliceReader) *info.freeze() =3D None; let mut msg =3D None; if !listener.is_pending { - msg =3D Some(FreezeMessage::init(alloc, cookie)); + msg =3D Some(FreezeMessage::init(alloc, cookie, self.task.pid(= ))); } drop(node_refs_guard); =20 @@ -427,7 +435,7 @@ pub(crate) fn prepare_freeze_messages(&self) -> Result<= FreezeMessages, AllocErro continue; }; let msg_alloc =3D FreezeMessage::new(GFP_KERNEL)?; - let msg =3D FreezeMessage::init(msg_alloc, cookie); + let msg =3D FreezeMessage::init(msg_alloc, cookie, proc.task.p= id()); batch.push((proc, msg), GFP_KERNEL)?; } =20 diff --git a/drivers/android/binder/node.rs b/drivers/android/binder/node.rs index 8a87dc366aa9..c73cdf82100f 100644 --- a/drivers/android/binder/node.rs +++ b/drivers/android/binder/node.rs @@ -1122,7 +1122,14 @@ fn do_work( Ok(cmd !=3D BR_DEAD_BINDER) } =20 - fn cancel(self: DArc) {} + fn cancel(self: DArc) { + binder_debug!( + pid =3D self.process.task.pid(), + DeadTransaction, + "undelivered death notification, {:016x}", + self.cookie + ); + } =20 fn should_sync_wakeup(&self) -> bool { false diff --git a/drivers/android/binder/rust_binder_main.rs b/drivers/android/b= inder/rust_binder_main.rs index 29829cb210a4..15c7b65928d8 100644 --- a/drivers/android/binder/rust_binder_main.rs +++ b/drivers/android/binder/rust_binder_main.rs @@ -221,6 +221,7 @@ fn arc_pin_init(init: impl PinInit) -> Result, kernel::error::Error> struct DeliverCode { code: u32, skip: Atomic, + pid: i32, } =20 kernel::list::impl_list_arc_safe! { @@ -228,10 +229,11 @@ struct DeliverCode { } =20 impl DeliverCode { - fn new(code: u32) -> Self { + fn new(code: u32, pid: i32) -> Self { Self { code, skip: Atomic::new(false), + pid, } } =20 @@ -256,7 +258,15 @@ fn do_work( Ok(true) } =20 - fn cancel(self: DArc) {} + fn cancel(self: DArc) { + if !self.skip.load(Relaxed) { + binder_debug!( + pid =3D self.pid, + DeadTransaction, + "undelivered TRANSACTION_COMPLETE" + ); + } + } =20 fn should_sync_wakeup(&self) -> bool { false diff --git a/drivers/android/binder/thread.rs b/drivers/android/binder/thre= ad.rs index 38b90c79c057..edc2613d13b5 100644 --- a/drivers/android/binder/thread.rs +++ b/drivers/android/binder/thread.rs @@ -279,7 +279,7 @@ struct InnerThread { const LOOPER_POLL: u32 =3D 0x40; =20 impl InnerThread { - fn new() -> Result { + fn new(pid: i32) -> Result { fn next_err_id() -> u32 { static EE_ID: Atomic =3D Atomic::new(0); EE_ID.fetch_add(1, Relaxed) @@ -290,8 +290,8 @@ fn next_err_id() -> u32 { looper_need_return: false, is_dead: false, process_work_list: false, - reply_work: ThreadError::try_new()?, - return_work: ThreadError::try_new()?, + reply_work: ThreadError::try_new(pid)?, + return_work: ThreadError::try_new(pid)?, work_list: List::new(), current_transaction: None, extended_error: ExtendedError::new(next_err_id(), BR_OK, 0), @@ -445,7 +445,7 @@ impl ListItem<0> for Thread { =20 impl Thread { pub(crate) fn new(id: i32, process: Arc) -> Result>= { - let inner =3D InnerThread::new()?; + let inner =3D InnerThread::new(process.task.pid())?; =20 Arc::pin_init( try_pin_init!(Thread { @@ -1115,6 +1115,12 @@ fn unwind_transaction_stack(self: &Arc) { let mut inner =3D thread.inner.lock(); inner.pop_transaction_to_reply(thread.as_ref()) } { + binder_debug!( + DeadTransaction, + "release transaction {} in, still active", + transaction.debug_id + ); + let reply =3D Err(BR_DEAD_REPLY); if !transaction .from @@ -1305,7 +1311,10 @@ fn transaction_inner(self: &Arc, info: &mut Tr= ansactionInfo) -> BinderResu // TODO: We need to ensure that there isn't a pending transaction = in the work queue. How // could this happen? let top =3D self.top_of_transaction_stack()?; - let list_completion =3D DTRWrap::arc_try_new(DeliverCode::new(BR_T= RANSACTION_COMPLETE))?; + let list_completion =3D DTRWrap::arc_try_new(DeliverCode::new( + BR_TRANSACTION_COMPLETE, + self.process.task.pid(), + ))?; let completion =3D list_completion.clone_arc(); let transaction =3D Transaction::new(node_ref, top, self, info)?; =20 @@ -1357,7 +1366,10 @@ fn reply_inner(self: &Arc, info: &mut Transact= ionInfo) -> BinderResult { =20 // We need to complete the transaction even if we cannot complete = building the reply. let out =3D (|| -> BinderResult<_> { - let completion =3D DTRWrap::arc_try_new(DeliverCode::new(BR_TR= ANSACTION_COMPLETE))?; + let completion =3D DTRWrap::arc_try_new(DeliverCode::new( + BR_TRANSACTION_COMPLETE, + self.process.task.pid(), + ))?; let process =3D orig.from.process.clone(); let allow_fds =3D orig.flags & TF_ACCEPT_FDS !=3D 0; let reply =3D Transaction::new_reply(self, process, info, allo= w_fds)?; @@ -1397,7 +1409,8 @@ fn oneway_transaction_inner(self: &Arc, info: &= mut TransactionInfo) -> Bin } else { BR_TRANSACTION_COMPLETE }; - let list_completion =3D DTRWrap::arc_try_new(DeliverCode::new(code= ))?; + let list_completion =3D + DTRWrap::arc_try_new(DeliverCode::new(code, self.process.task.= pid()))?; let completion =3D list_completion.clone_arc(); self.inner.lock().push_work(list_completion); match transaction.submit(info) { @@ -1653,14 +1666,16 @@ pub(crate) fn release(self: &Arc) { #[pin_data] struct ThreadError { error_code: Atomic, + pid: i32, #[pin] links_track: AtomicTracker, } =20 impl ThreadError { - fn try_new() -> Result> { + fn try_new(pid: i32) -> Result> { DTRWrap::arc_pin_init(pin_init!(Self { error_code: Atomic::new(BR_OK), + pid, links_track <- AtomicTracker::new(), })) .map(ListArc::into_arc) @@ -1687,7 +1702,16 @@ fn do_work( Ok(true) } =20 - fn cancel(self: DArc) {} + fn cancel(self: DArc) { + let code =3D self.error_code.load(Relaxed); + if code !=3D BR_OK { + binder_debug!( + pid =3D self.pid, + DeadTransaction, + "undelivered TRANSACTION_ERROR: {code}" + ); + } + } =20 fn should_sync_wakeup(&self) -> bool { false diff --git a/drivers/android/binder/transaction.rs b/drivers/android/binder= /transaction.rs index 069c792d2200..0528070fe700 100644 --- a/drivers/android/binder/transaction.rs +++ b/drivers/android/binder/transaction.rs @@ -488,6 +488,13 @@ fn cancel(self: DArc) { if self.target_node.is_some() && self.flags & TF_ONE_WAY =3D=3D 0 { let reply =3D Err(BR_DEAD_REPLY); self.from.deliver_reply(reply, &self, None); + } else { + binder_debug!( + pid =3D self.to.task.pid(), + DeadTransaction, + "undelivered transaction {}, process died", + self.debug_id + ); } =20 self.drop_outstanding_txn(); --=20 2.55.0.229.g6434b31f56-goog