binder.c 197 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388238923902391239223932394239523962397239823992400240124022403240424052406240724082409241024112412241324142415241624172418241924202421242224232424242524262427242824292430243124322433243424352436243724382439244024412442244324442445244624472448244924502451245224532454245524562457245824592460246124622463246424652466246724682469247024712472247324742475247624772478247924802481248224832484248524862487248824892490249124922493249424952496249724982499250025012502250325042505250625072508250925102511251225132514251525162517251825192520252125222523252425252526252725282529253025312532253325342535253625372538253925402541254225432544254525462547254825492550255125522553255425552556255725582559256025612562256325642565256625672568256925702571257225732574257525762577257825792580258125822583258425852586258725882589259025912592259325942595259625972598259926002601260226032604260526062607260826092610261126122613261426152616261726182619262026212622262326242625262626272628262926302631263226332634263526362637263826392640264126422643264426452646264726482649265026512652265326542655265626572658265926602661266226632664266526662667266826692670267126722673267426752676267726782679268026812682268326842685268626872688268926902691269226932694269526962697269826992700270127022703270427052706270727082709271027112712271327142715271627172718271927202721272227232724272527262727272827292730273127322733273427352736273727382739274027412742274327442745274627472748274927502751275227532754275527562757275827592760276127622763276427652766276727682769277027712772277327742775277627772778277927802781278227832784278527862787278827892790279127922793279427952796279727982799280028012802280328042805280628072808280928102811281228132814281528162817281828192820282128222823282428252826282728282829283028312832283328342835283628372838283928402841284228432844284528462847284828492850285128522853285428552856285728582859286028612862286328642865286628672868286928702871287228732874287528762877287828792880288128822883288428852886288728882889289028912892289328942895289628972898289929002901290229032904290529062907290829092910291129122913291429152916291729182919292029212922292329242925292629272928292929302931293229332934293529362937293829392940294129422943294429452946294729482949295029512952295329542955295629572958295929602961296229632964296529662967296829692970297129722973297429752976297729782979298029812982298329842985298629872988298929902991299229932994299529962997299829993000300130023003300430053006300730083009301030113012301330143015301630173018301930203021302230233024302530263027302830293030303130323033303430353036303730383039304030413042304330443045304630473048304930503051305230533054305530563057305830593060306130623063306430653066306730683069307030713072307330743075307630773078307930803081308230833084308530863087308830893090309130923093309430953096309730983099310031013102310331043105310631073108310931103111311231133114311531163117311831193120312131223123312431253126312731283129313031313132313331343135313631373138313931403141314231433144314531463147314831493150315131523153315431553156315731583159316031613162316331643165316631673168316931703171317231733174317531763177317831793180318131823183318431853186318731883189319031913192319331943195319631973198319932003201320232033204320532063207320832093210321132123213321432153216321732183219322032213222322332243225322632273228322932303231323232333234323532363237323832393240324132423243324432453246324732483249325032513252325332543255325632573258325932603261326232633264326532663267326832693270327132723273327432753276327732783279328032813282328332843285328632873288328932903291329232933294329532963297329832993300330133023303330433053306330733083309331033113312331333143315331633173318331933203321332233233324332533263327332833293330333133323333333433353336333733383339334033413342334333443345334633473348334933503351335233533354335533563357335833593360336133623363336433653366336733683369337033713372337333743375337633773378337933803381338233833384338533863387338833893390339133923393339433953396339733983399340034013402340334043405340634073408340934103411341234133414341534163417341834193420342134223423342434253426342734283429343034313432343334343435343634373438343934403441344234433444344534463447344834493450345134523453345434553456345734583459346034613462346334643465346634673468346934703471347234733474347534763477347834793480348134823483348434853486348734883489349034913492349334943495349634973498349935003501350235033504350535063507350835093510351135123513351435153516351735183519352035213522352335243525352635273528352935303531353235333534353535363537353835393540354135423543354435453546354735483549355035513552355335543555355635573558355935603561356235633564356535663567356835693570357135723573357435753576357735783579358035813582358335843585358635873588358935903591359235933594359535963597359835993600360136023603360436053606360736083609361036113612361336143615361636173618361936203621362236233624362536263627362836293630363136323633363436353636363736383639364036413642364336443645364636473648364936503651365236533654365536563657365836593660366136623663366436653666366736683669367036713672367336743675367636773678367936803681368236833684368536863687368836893690369136923693369436953696369736983699370037013702370337043705370637073708370937103711371237133714371537163717371837193720372137223723372437253726372737283729373037313732373337343735373637373738373937403741374237433744374537463747374837493750375137523753375437553756375737583759376037613762376337643765376637673768376937703771377237733774377537763777377837793780378137823783378437853786378737883789379037913792379337943795379637973798379938003801380238033804380538063807380838093810381138123813381438153816381738183819382038213822382338243825382638273828382938303831383238333834383538363837383838393840384138423843384438453846384738483849385038513852385338543855385638573858385938603861386238633864386538663867386838693870387138723873387438753876387738783879388038813882388338843885388638873888388938903891389238933894389538963897389838993900390139023903390439053906390739083909391039113912391339143915391639173918391939203921392239233924392539263927392839293930393139323933393439353936393739383939394039413942394339443945394639473948394939503951395239533954395539563957395839593960396139623963396439653966396739683969397039713972397339743975397639773978397939803981398239833984398539863987398839893990399139923993399439953996399739983999400040014002400340044005400640074008400940104011401240134014401540164017401840194020402140224023402440254026402740284029403040314032403340344035403640374038403940404041404240434044404540464047404840494050405140524053405440554056405740584059406040614062406340644065406640674068406940704071407240734074407540764077407840794080408140824083408440854086408740884089409040914092409340944095409640974098409941004101410241034104410541064107410841094110411141124113411441154116411741184119412041214122412341244125412641274128412941304131413241334134413541364137413841394140414141424143414441454146414741484149415041514152415341544155415641574158415941604161416241634164416541664167416841694170417141724173417441754176417741784179418041814182418341844185418641874188418941904191419241934194419541964197419841994200420142024203420442054206420742084209421042114212421342144215421642174218421942204221422242234224422542264227422842294230423142324233423442354236423742384239424042414242424342444245424642474248424942504251425242534254425542564257425842594260426142624263426442654266426742684269427042714272427342744275427642774278427942804281428242834284428542864287428842894290429142924293429442954296429742984299430043014302430343044305430643074308430943104311431243134314431543164317431843194320432143224323432443254326432743284329433043314332433343344335433643374338433943404341434243434344434543464347434843494350435143524353435443554356435743584359436043614362436343644365436643674368436943704371437243734374437543764377437843794380438143824383438443854386438743884389439043914392439343944395439643974398439944004401440244034404440544064407440844094410441144124413441444154416441744184419442044214422442344244425442644274428442944304431443244334434443544364437443844394440444144424443444444454446444744484449445044514452445344544455445644574458445944604461446244634464446544664467446844694470447144724473447444754476447744784479448044814482448344844485448644874488448944904491449244934494449544964497449844994500450145024503450445054506450745084509451045114512451345144515451645174518451945204521452245234524452545264527452845294530453145324533453445354536453745384539454045414542454345444545454645474548454945504551455245534554455545564557455845594560456145624563456445654566456745684569457045714572457345744575457645774578457945804581458245834584458545864587458845894590459145924593459445954596459745984599460046014602460346044605460646074608460946104611461246134614461546164617461846194620462146224623462446254626462746284629463046314632463346344635463646374638463946404641464246434644464546464647464846494650465146524653465446554656465746584659466046614662466346644665466646674668466946704671467246734674467546764677467846794680468146824683468446854686468746884689469046914692469346944695469646974698469947004701470247034704470547064707470847094710471147124713471447154716471747184719472047214722472347244725472647274728472947304731473247334734473547364737473847394740474147424743474447454746474747484749475047514752475347544755475647574758475947604761476247634764476547664767476847694770477147724773477447754776477747784779478047814782478347844785478647874788478947904791479247934794479547964797479847994800480148024803480448054806480748084809481048114812481348144815481648174818481948204821482248234824482548264827482848294830483148324833483448354836483748384839484048414842484348444845484648474848484948504851485248534854485548564857485848594860486148624863486448654866486748684869487048714872487348744875487648774878487948804881488248834884488548864887488848894890489148924893489448954896489748984899490049014902490349044905490649074908490949104911491249134914491549164917491849194920492149224923492449254926492749284929493049314932493349344935493649374938493949404941494249434944494549464947494849494950495149524953495449554956495749584959496049614962496349644965496649674968496949704971497249734974497549764977497849794980498149824983498449854986498749884989499049914992499349944995499649974998499950005001500250035004500550065007500850095010501150125013501450155016501750185019502050215022502350245025502650275028502950305031503250335034503550365037503850395040504150425043504450455046504750485049505050515052505350545055505650575058505950605061506250635064506550665067506850695070507150725073507450755076507750785079508050815082508350845085508650875088508950905091509250935094509550965097509850995100510151025103510451055106510751085109511051115112511351145115511651175118511951205121512251235124512551265127512851295130513151325133513451355136513751385139514051415142514351445145514651475148514951505151515251535154515551565157515851595160516151625163516451655166516751685169517051715172517351745175517651775178517951805181518251835184518551865187518851895190519151925193519451955196519751985199520052015202520352045205520652075208520952105211521252135214521552165217521852195220522152225223522452255226522752285229523052315232523352345235523652375238523952405241524252435244524552465247524852495250525152525253525452555256525752585259526052615262526352645265526652675268526952705271527252735274527552765277527852795280528152825283528452855286528752885289529052915292529352945295529652975298529953005301530253035304530553065307530853095310531153125313531453155316531753185319532053215322532353245325532653275328532953305331533253335334533553365337533853395340534153425343534453455346534753485349535053515352535353545355535653575358535953605361536253635364536553665367536853695370537153725373537453755376537753785379538053815382538353845385538653875388538953905391539253935394539553965397539853995400540154025403540454055406540754085409541054115412541354145415541654175418541954205421542254235424542554265427542854295430543154325433543454355436543754385439544054415442544354445445544654475448544954505451545254535454545554565457545854595460546154625463546454655466546754685469547054715472547354745475547654775478547954805481548254835484548554865487548854895490549154925493549454955496549754985499550055015502550355045505550655075508550955105511551255135514551555165517551855195520552155225523552455255526552755285529553055315532553355345535553655375538553955405541554255435544554555465547554855495550555155525553555455555556555755585559556055615562556355645565556655675568556955705571557255735574557555765577557855795580558155825583558455855586558755885589559055915592559355945595559655975598559956005601560256035604560556065607560856095610561156125613561456155616561756185619562056215622562356245625562656275628562956305631563256335634563556365637563856395640564156425643564456455646564756485649565056515652565356545655565656575658565956605661566256635664566556665667566856695670567156725673567456755676567756785679568056815682568356845685568656875688568956905691569256935694569556965697569856995700570157025703570457055706570757085709571057115712571357145715571657175718571957205721572257235724572557265727572857295730573157325733573457355736573757385739574057415742574357445745574657475748574957505751575257535754575557565757575857595760576157625763576457655766576757685769577057715772577357745775577657775778577957805781578257835784578557865787578857895790579157925793579457955796579757985799580058015802580358045805580658075808580958105811581258135814581558165817581858195820582158225823582458255826582758285829583058315832583358345835583658375838583958405841584258435844584558465847584858495850585158525853585458555856585758585859586058615862586358645865586658675868586958705871587258735874587558765877587858795880588158825883588458855886588758885889589058915892589358945895589658975898589959005901590259035904590559065907590859095910591159125913591459155916591759185919592059215922592359245925592659275928592959305931593259335934593559365937593859395940594159425943594459455946594759485949595059515952595359545955595659575958595959605961596259635964596559665967596859695970597159725973597459755976597759785979598059815982598359845985598659875988598959905991599259935994599559965997599859996000600160026003600460056006600760086009601060116012601360146015601660176018601960206021602260236024602560266027602860296030603160326033603460356036603760386039604060416042604360446045604660476048604960506051605260536054605560566057605860596060606160626063606460656066606760686069607060716072607360746075607660776078607960806081608260836084608560866087608860896090609160926093609460956096609760986099610061016102610361046105610661076108610961106111611261136114611561166117611861196120612161226123612461256126612761286129613061316132613361346135613661376138613961406141614261436144614561466147614861496150615161526153615461556156615761586159616061616162616361646165616661676168616961706171617261736174617561766177617861796180618161826183618461856186618761886189619061916192619361946195619661976198619962006201620262036204620562066207620862096210621162126213621462156216621762186219622062216222622362246225622662276228622962306231623262336234623562366237623862396240624162426243624462456246624762486249625062516252625362546255625662576258625962606261626262636264626562666267626862696270627162726273627462756276627762786279628062816282628362846285628662876288628962906291629262936294629562966297629862996300630163026303630463056306630763086309631063116312631363146315631663176318631963206321632263236324632563266327632863296330633163326333633463356336633763386339634063416342634363446345634663476348634963506351635263536354635563566357635863596360636163626363636463656366636763686369637063716372637363746375637663776378637963806381638263836384638563866387638863896390639163926393639463956396639763986399640064016402640364046405640664076408640964106411641264136414641564166417641864196420642164226423642464256426642764286429643064316432643364346435643664376438643964406441644264436444644564466447644864496450645164526453645464556456645764586459646064616462646364646465646664676468646964706471647264736474647564766477647864796480648164826483648464856486648764886489649064916492649364946495649664976498649965006501650265036504650565066507650865096510651165126513651465156516651765186519652065216522652365246525652665276528652965306531653265336534653565366537653865396540654165426543654465456546654765486549655065516552655365546555655665576558655965606561656265636564656565666567656865696570657165726573657465756576657765786579658065816582658365846585658665876588658965906591659265936594659565966597659865996600660166026603660466056606660766086609661066116612661366146615661666176618661966206621662266236624662566266627662866296630663166326633663466356636663766386639664066416642664366446645664666476648664966506651665266536654665566566657665866596660666166626663666466656666666766686669667066716672667366746675667666776678667966806681668266836684668566866687668866896690669166926693669466956696669766986699670067016702670367046705670667076708670967106711671267136714671567166717671867196720672167226723672467256726672767286729673067316732673367346735673667376738673967406741674267436744674567466747674867496750675167526753675467556756675767586759676067616762676367646765676667676768676967706771677267736774677567766777677867796780678167826783678467856786678767886789679067916792679367946795679667976798679968006801680268036804680568066807680868096810681168126813681468156816681768186819682068216822682368246825682668276828682968306831683268336834683568366837683868396840684168426843684468456846684768486849685068516852685368546855685668576858685968606861686268636864686568666867686868696870687168726873687468756876687768786879688068816882688368846885688668876888688968906891689268936894689568966897689868996900690169026903690469056906690769086909691069116912691369146915691669176918691969206921692269236924692569266927692869296930693169326933693469356936693769386939694069416942694369446945694669476948694969506951695269536954695569566957695869596960696169626963696469656966696769686969697069716972697369746975697669776978697969806981698269836984698569866987698869896990699169926993699469956996699769986999700070017002700370047005700670077008700970107011701270137014701570167017701870197020702170227023702470257026
  1. // SPDX-License-Identifier: GPL-2.0-only
  2. /* binder.c
  3. *
  4. * Android IPC Subsystem
  5. *
  6. * Copyright (C) 2007-2008 Google, Inc.
  7. */
  8. /*
  9. * Locking overview
  10. *
  11. * There are 3 main spinlocks which must be acquired in the
  12. * order shown:
  13. *
  14. * 1) proc->outer_lock : protects binder_ref
  15. * binder_proc_lock() and binder_proc_unlock() are
  16. * used to acq/rel.
  17. * 2) node->lock : protects most fields of binder_node.
  18. * binder_node_lock() and binder_node_unlock() are
  19. * used to acq/rel
  20. * 3) proc->inner_lock : protects the thread and node lists
  21. * (proc->threads, proc->waiting_threads, proc->nodes)
  22. * and all todo lists associated with the binder_proc
  23. * (proc->todo, thread->todo, proc->delivered_death and
  24. * node->async_todo), as well as thread->transaction_stack
  25. * binder_inner_proc_lock() and binder_inner_proc_unlock()
  26. * are used to acq/rel
  27. *
  28. * Any lock under procA must never be nested under any lock at the same
  29. * level or below on procB.
  30. *
  31. * Functions that require a lock held on entry indicate which lock
  32. * in the suffix of the function name:
  33. *
  34. * foo_olocked() : requires node->outer_lock
  35. * foo_nlocked() : requires node->lock
  36. * foo_ilocked() : requires proc->inner_lock
  37. * foo_oilocked(): requires proc->outer_lock and proc->inner_lock
  38. * foo_nilocked(): requires node->lock and proc->inner_lock
  39. * ...
  40. */
  41. #define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
  42. #include <linux/fdtable.h>
  43. #include <linux/file.h>
  44. #include <linux/freezer.h>
  45. #include <linux/fs.h>
  46. #include <linux/list.h>
  47. #include <linux/miscdevice.h>
  48. #include <linux/module.h>
  49. #include <linux/mutex.h>
  50. #include <linux/nsproxy.h>
  51. #include <linux/poll.h>
  52. #include <linux/debugfs.h>
  53. #include <linux/rbtree.h>
  54. #include <linux/sched/signal.h>
  55. #include <linux/sched/mm.h>
  56. #include <linux/seq_file.h>
  57. #include <linux/string.h>
  58. #include <linux/uaccess.h>
  59. #include <linux/pid_namespace.h>
  60. #include <linux/security.h>
  61. #include <linux/spinlock.h>
  62. #include <linux/ratelimit.h>
  63. #include <linux/syscalls.h>
  64. #include <linux/task_work.h>
  65. #include <linux/sizes.h>
  66. #include <linux/ktime.h>
  67. #include <uapi/linux/android/binder.h>
  68. #include <linux/cacheflush.h>
  69. #include "binder_internal.h"
  70. #include "binder_trace.h"
  71. static HLIST_HEAD(binder_deferred_list);
  72. static DEFINE_MUTEX(binder_deferred_lock);
  73. static HLIST_HEAD(binder_devices);
  74. static HLIST_HEAD(binder_procs);
  75. static DEFINE_MUTEX(binder_procs_lock);
  76. static HLIST_HEAD(binder_dead_nodes);
  77. static DEFINE_SPINLOCK(binder_dead_nodes_lock);
  78. static struct dentry *binder_debugfs_dir_entry_root;
  79. static struct dentry *binder_debugfs_dir_entry_proc;
  80. static atomic_t binder_last_id;
  81. static int proc_show(struct seq_file *m, void *unused);
  82. DEFINE_SHOW_ATTRIBUTE(proc);
  83. #define FORBIDDEN_MMAP_FLAGS (VM_WRITE)
  84. enum {
  85. BINDER_DEBUG_USER_ERROR = 1U << 0,
  86. BINDER_DEBUG_FAILED_TRANSACTION = 1U << 1,
  87. BINDER_DEBUG_DEAD_TRANSACTION = 1U << 2,
  88. BINDER_DEBUG_OPEN_CLOSE = 1U << 3,
  89. BINDER_DEBUG_DEAD_BINDER = 1U << 4,
  90. BINDER_DEBUG_DEATH_NOTIFICATION = 1U << 5,
  91. BINDER_DEBUG_READ_WRITE = 1U << 6,
  92. BINDER_DEBUG_USER_REFS = 1U << 7,
  93. BINDER_DEBUG_THREADS = 1U << 8,
  94. BINDER_DEBUG_TRANSACTION = 1U << 9,
  95. BINDER_DEBUG_TRANSACTION_COMPLETE = 1U << 10,
  96. BINDER_DEBUG_FREE_BUFFER = 1U << 11,
  97. BINDER_DEBUG_INTERNAL_REFS = 1U << 12,
  98. BINDER_DEBUG_PRIORITY_CAP = 1U << 13,
  99. BINDER_DEBUG_SPINLOCKS = 1U << 14,
  100. };
  101. static uint32_t binder_debug_mask = BINDER_DEBUG_USER_ERROR |
  102. BINDER_DEBUG_FAILED_TRANSACTION | BINDER_DEBUG_DEAD_TRANSACTION;
  103. module_param_named(debug_mask, binder_debug_mask, uint, 0644);
  104. char *binder_devices_param = CONFIG_ANDROID_BINDER_DEVICES;
  105. module_param_named(devices, binder_devices_param, charp, 0444);
  106. static DECLARE_WAIT_QUEUE_HEAD(binder_user_error_wait);
  107. static int binder_stop_on_user_error;
  108. static int binder_set_stop_on_user_error(const char *val,
  109. const struct kernel_param *kp)
  110. {
  111. int ret;
  112. ret = param_set_int(val, kp);
  113. if (binder_stop_on_user_error < 2)
  114. wake_up(&binder_user_error_wait);
  115. return ret;
  116. }
  117. module_param_call(stop_on_user_error, binder_set_stop_on_user_error,
  118. param_get_int, &binder_stop_on_user_error, 0644);
  119. static __printf(2, 3) void binder_debug(int mask, const char *format, ...)
  120. {
  121. struct va_format vaf;
  122. va_list args;
  123. if (binder_debug_mask & mask) {
  124. va_start(args, format);
  125. vaf.va = &args;
  126. vaf.fmt = format;
  127. pr_info_ratelimited("%pV", &vaf);
  128. va_end(args);
  129. }
  130. }
  131. #define binder_txn_error(x...) \
  132. binder_debug(BINDER_DEBUG_FAILED_TRANSACTION, x)
  133. static __printf(1, 2) void binder_user_error(const char *format, ...)
  134. {
  135. struct va_format vaf;
  136. va_list args;
  137. if (binder_debug_mask & BINDER_DEBUG_USER_ERROR) {
  138. va_start(args, format);
  139. vaf.va = &args;
  140. vaf.fmt = format;
  141. pr_info_ratelimited("%pV", &vaf);
  142. va_end(args);
  143. }
  144. if (binder_stop_on_user_error)
  145. binder_stop_on_user_error = 2;
  146. }
  147. #define binder_set_extended_error(ee, _id, _command, _param) \
  148. do { \
  149. (ee)->id = _id; \
  150. (ee)->command = _command; \
  151. (ee)->param = _param; \
  152. } while (0)
  153. #define to_flat_binder_object(hdr) \
  154. container_of(hdr, struct flat_binder_object, hdr)
  155. #define to_binder_fd_object(hdr) container_of(hdr, struct binder_fd_object, hdr)
  156. #define to_binder_buffer_object(hdr) \
  157. container_of(hdr, struct binder_buffer_object, hdr)
  158. #define to_binder_fd_array_object(hdr) \
  159. container_of(hdr, struct binder_fd_array_object, hdr)
  160. static struct binder_stats binder_stats;
  161. static inline void binder_stats_deleted(enum binder_stat_types type)
  162. {
  163. atomic_inc(&binder_stats.obj_deleted[type]);
  164. }
  165. static inline void binder_stats_created(enum binder_stat_types type)
  166. {
  167. atomic_inc(&binder_stats.obj_created[type]);
  168. }
  169. struct binder_transaction_log_entry {
  170. int debug_id;
  171. int debug_id_done;
  172. int call_type;
  173. int from_proc;
  174. int from_thread;
  175. int target_handle;
  176. int to_proc;
  177. int to_thread;
  178. int to_node;
  179. int data_size;
  180. int offsets_size;
  181. int return_error_line;
  182. uint32_t return_error;
  183. uint32_t return_error_param;
  184. char context_name[BINDERFS_MAX_NAME + 1];
  185. };
  186. struct binder_transaction_log {
  187. atomic_t cur;
  188. bool full;
  189. struct binder_transaction_log_entry entry[32];
  190. };
  191. static struct binder_transaction_log binder_transaction_log;
  192. static struct binder_transaction_log binder_transaction_log_failed;
  193. static struct binder_transaction_log_entry *binder_transaction_log_add(
  194. struct binder_transaction_log *log)
  195. {
  196. struct binder_transaction_log_entry *e;
  197. unsigned int cur = atomic_inc_return(&log->cur);
  198. if (cur >= ARRAY_SIZE(log->entry))
  199. log->full = true;
  200. e = &log->entry[cur % ARRAY_SIZE(log->entry)];
  201. WRITE_ONCE(e->debug_id_done, 0);
  202. /*
  203. * write-barrier to synchronize access to e->debug_id_done.
  204. * We make sure the initialized 0 value is seen before
  205. * memset() other fields are zeroed by memset.
  206. */
  207. smp_wmb();
  208. memset(e, 0, sizeof(*e));
  209. return e;
  210. }
  211. enum binder_deferred_state {
  212. BINDER_DEFERRED_FLUSH = 0x01,
  213. BINDER_DEFERRED_RELEASE = 0x02,
  214. };
  215. enum {
  216. BINDER_LOOPER_STATE_REGISTERED = 0x01,
  217. BINDER_LOOPER_STATE_ENTERED = 0x02,
  218. BINDER_LOOPER_STATE_EXITED = 0x04,
  219. BINDER_LOOPER_STATE_INVALID = 0x08,
  220. BINDER_LOOPER_STATE_WAITING = 0x10,
  221. BINDER_LOOPER_STATE_POLL = 0x20,
  222. };
  223. /**
  224. * binder_proc_lock() - Acquire outer lock for given binder_proc
  225. * @proc: struct binder_proc to acquire
  226. *
  227. * Acquires proc->outer_lock. Used to protect binder_ref
  228. * structures associated with the given proc.
  229. */
  230. #define binder_proc_lock(proc) _binder_proc_lock(proc, __LINE__)
  231. static void
  232. _binder_proc_lock(struct binder_proc *proc, int line)
  233. __acquires(&proc->outer_lock)
  234. {
  235. binder_debug(BINDER_DEBUG_SPINLOCKS,
  236. "%s: line=%d\n", __func__, line);
  237. spin_lock(&proc->outer_lock);
  238. }
  239. /**
  240. * binder_proc_unlock() - Release outer lock for given binder_proc
  241. * @proc: struct binder_proc to acquire
  242. *
  243. * Release lock acquired via binder_proc_lock()
  244. */
  245. #define binder_proc_unlock(proc) _binder_proc_unlock(proc, __LINE__)
  246. static void
  247. _binder_proc_unlock(struct binder_proc *proc, int line)
  248. __releases(&proc->outer_lock)
  249. {
  250. binder_debug(BINDER_DEBUG_SPINLOCKS,
  251. "%s: line=%d\n", __func__, line);
  252. spin_unlock(&proc->outer_lock);
  253. }
  254. /**
  255. * binder_inner_proc_lock() - Acquire inner lock for given binder_proc
  256. * @proc: struct binder_proc to acquire
  257. *
  258. * Acquires proc->inner_lock. Used to protect todo lists
  259. */
  260. #define binder_inner_proc_lock(proc) _binder_inner_proc_lock(proc, __LINE__)
  261. static void
  262. _binder_inner_proc_lock(struct binder_proc *proc, int line)
  263. __acquires(&proc->inner_lock)
  264. {
  265. binder_debug(BINDER_DEBUG_SPINLOCKS,
  266. "%s: line=%d\n", __func__, line);
  267. spin_lock(&proc->inner_lock);
  268. }
  269. /**
  270. * binder_inner_proc_unlock() - Release inner lock for given binder_proc
  271. * @proc: struct binder_proc to acquire
  272. *
  273. * Release lock acquired via binder_inner_proc_lock()
  274. */
  275. #define binder_inner_proc_unlock(proc) _binder_inner_proc_unlock(proc, __LINE__)
  276. static void
  277. _binder_inner_proc_unlock(struct binder_proc *proc, int line)
  278. __releases(&proc->inner_lock)
  279. {
  280. binder_debug(BINDER_DEBUG_SPINLOCKS,
  281. "%s: line=%d\n", __func__, line);
  282. spin_unlock(&proc->inner_lock);
  283. }
  284. /**
  285. * binder_node_lock() - Acquire spinlock for given binder_node
  286. * @node: struct binder_node to acquire
  287. *
  288. * Acquires node->lock. Used to protect binder_node fields
  289. */
  290. #define binder_node_lock(node) _binder_node_lock(node, __LINE__)
  291. static void
  292. _binder_node_lock(struct binder_node *node, int line)
  293. __acquires(&node->lock)
  294. {
  295. binder_debug(BINDER_DEBUG_SPINLOCKS,
  296. "%s: line=%d\n", __func__, line);
  297. spin_lock(&node->lock);
  298. }
  299. /**
  300. * binder_node_unlock() - Release spinlock for given binder_proc
  301. * @node: struct binder_node to acquire
  302. *
  303. * Release lock acquired via binder_node_lock()
  304. */
  305. #define binder_node_unlock(node) _binder_node_unlock(node, __LINE__)
  306. static void
  307. _binder_node_unlock(struct binder_node *node, int line)
  308. __releases(&node->lock)
  309. {
  310. binder_debug(BINDER_DEBUG_SPINLOCKS,
  311. "%s: line=%d\n", __func__, line);
  312. spin_unlock(&node->lock);
  313. }
  314. /**
  315. * binder_node_inner_lock() - Acquire node and inner locks
  316. * @node: struct binder_node to acquire
  317. *
  318. * Acquires node->lock. If node->proc also acquires
  319. * proc->inner_lock. Used to protect binder_node fields
  320. */
  321. #define binder_node_inner_lock(node) _binder_node_inner_lock(node, __LINE__)
  322. static void
  323. _binder_node_inner_lock(struct binder_node *node, int line)
  324. __acquires(&node->lock) __acquires(&node->proc->inner_lock)
  325. {
  326. binder_debug(BINDER_DEBUG_SPINLOCKS,
  327. "%s: line=%d\n", __func__, line);
  328. spin_lock(&node->lock);
  329. if (node->proc)
  330. binder_inner_proc_lock(node->proc);
  331. else
  332. /* annotation for sparse */
  333. __acquire(&node->proc->inner_lock);
  334. }
  335. /**
  336. * binder_node_inner_unlock() - Release node and inner locks
  337. * @node: struct binder_node to acquire
  338. *
  339. * Release lock acquired via binder_node_lock()
  340. */
  341. #define binder_node_inner_unlock(node) _binder_node_inner_unlock(node, __LINE__)
  342. static void
  343. _binder_node_inner_unlock(struct binder_node *node, int line)
  344. __releases(&node->lock) __releases(&node->proc->inner_lock)
  345. {
  346. struct binder_proc *proc = node->proc;
  347. binder_debug(BINDER_DEBUG_SPINLOCKS,
  348. "%s: line=%d\n", __func__, line);
  349. if (proc)
  350. binder_inner_proc_unlock(proc);
  351. else
  352. /* annotation for sparse */
  353. __release(&node->proc->inner_lock);
  354. spin_unlock(&node->lock);
  355. }
  356. static bool binder_worklist_empty_ilocked(struct list_head *list)
  357. {
  358. return list_empty(list);
  359. }
  360. /**
  361. * binder_worklist_empty() - Check if no items on the work list
  362. * @proc: binder_proc associated with list
  363. * @list: list to check
  364. *
  365. * Return: true if there are no items on list, else false
  366. */
  367. static bool binder_worklist_empty(struct binder_proc *proc,
  368. struct list_head *list)
  369. {
  370. bool ret;
  371. binder_inner_proc_lock(proc);
  372. ret = binder_worklist_empty_ilocked(list);
  373. binder_inner_proc_unlock(proc);
  374. return ret;
  375. }
  376. /**
  377. * binder_enqueue_work_ilocked() - Add an item to the work list
  378. * @work: struct binder_work to add to list
  379. * @target_list: list to add work to
  380. *
  381. * Adds the work to the specified list. Asserts that work
  382. * is not already on a list.
  383. *
  384. * Requires the proc->inner_lock to be held.
  385. */
  386. static void
  387. binder_enqueue_work_ilocked(struct binder_work *work,
  388. struct list_head *target_list)
  389. {
  390. BUG_ON(target_list == NULL);
  391. BUG_ON(work->entry.next && !list_empty(&work->entry));
  392. list_add_tail(&work->entry, target_list);
  393. }
  394. /**
  395. * binder_enqueue_deferred_thread_work_ilocked() - Add deferred thread work
  396. * @thread: thread to queue work to
  397. * @work: struct binder_work to add to list
  398. *
  399. * Adds the work to the todo list of the thread. Doesn't set the process_todo
  400. * flag, which means that (if it wasn't already set) the thread will go to
  401. * sleep without handling this work when it calls read.
  402. *
  403. * Requires the proc->inner_lock to be held.
  404. */
  405. static void
  406. binder_enqueue_deferred_thread_work_ilocked(struct binder_thread *thread,
  407. struct binder_work *work)
  408. {
  409. WARN_ON(!list_empty(&thread->waiting_thread_node));
  410. binder_enqueue_work_ilocked(work, &thread->todo);
  411. }
  412. /**
  413. * binder_enqueue_thread_work_ilocked() - Add an item to the thread work list
  414. * @thread: thread to queue work to
  415. * @work: struct binder_work to add to list
  416. *
  417. * Adds the work to the todo list of the thread, and enables processing
  418. * of the todo queue.
  419. *
  420. * Requires the proc->inner_lock to be held.
  421. */
  422. static void
  423. binder_enqueue_thread_work_ilocked(struct binder_thread *thread,
  424. struct binder_work *work)
  425. {
  426. WARN_ON(!list_empty(&thread->waiting_thread_node));
  427. binder_enqueue_work_ilocked(work, &thread->todo);
  428. /* (e)poll-based threads require an explicit wakeup signal when
  429. * queuing their own work; they rely on these events to consume
  430. * messages without I/O block. Without it, threads risk waiting
  431. * indefinitely without handling the work.
  432. */
  433. if (thread->looper & BINDER_LOOPER_STATE_POLL &&
  434. thread->pid == current->pid && !thread->process_todo)
  435. wake_up_interruptible_sync(&thread->wait);
  436. thread->process_todo = true;
  437. }
  438. /**
  439. * binder_enqueue_thread_work() - Add an item to the thread work list
  440. * @thread: thread to queue work to
  441. * @work: struct binder_work to add to list
  442. *
  443. * Adds the work to the todo list of the thread, and enables processing
  444. * of the todo queue.
  445. */
  446. static void
  447. binder_enqueue_thread_work(struct binder_thread *thread,
  448. struct binder_work *work)
  449. {
  450. binder_inner_proc_lock(thread->proc);
  451. binder_enqueue_thread_work_ilocked(thread, work);
  452. binder_inner_proc_unlock(thread->proc);
  453. }
  454. static void
  455. binder_dequeue_work_ilocked(struct binder_work *work)
  456. {
  457. list_del_init(&work->entry);
  458. }
  459. /**
  460. * binder_dequeue_work() - Removes an item from the work list
  461. * @proc: binder_proc associated with list
  462. * @work: struct binder_work to remove from list
  463. *
  464. * Removes the specified work item from whatever list it is on.
  465. * Can safely be called if work is not on any list.
  466. */
  467. static void
  468. binder_dequeue_work(struct binder_proc *proc, struct binder_work *work)
  469. {
  470. binder_inner_proc_lock(proc);
  471. binder_dequeue_work_ilocked(work);
  472. binder_inner_proc_unlock(proc);
  473. }
  474. static struct binder_work *binder_dequeue_work_head_ilocked(
  475. struct list_head *list)
  476. {
  477. struct binder_work *w;
  478. w = list_first_entry_or_null(list, struct binder_work, entry);
  479. if (w)
  480. list_del_init(&w->entry);
  481. return w;
  482. }
  483. static void
  484. binder_defer_work(struct binder_proc *proc, enum binder_deferred_state defer);
  485. static void binder_free_thread(struct binder_thread *thread);
  486. static void binder_free_proc(struct binder_proc *proc);
  487. static void binder_inc_node_tmpref_ilocked(struct binder_node *node);
  488. static bool binder_has_work_ilocked(struct binder_thread *thread,
  489. bool do_proc_work)
  490. {
  491. return thread->process_todo ||
  492. thread->looper_need_return ||
  493. (do_proc_work &&
  494. !binder_worklist_empty_ilocked(&thread->proc->todo));
  495. }
  496. static bool binder_has_work(struct binder_thread *thread, bool do_proc_work)
  497. {
  498. bool has_work;
  499. binder_inner_proc_lock(thread->proc);
  500. has_work = binder_has_work_ilocked(thread, do_proc_work);
  501. binder_inner_proc_unlock(thread->proc);
  502. return has_work;
  503. }
  504. static bool binder_available_for_proc_work_ilocked(struct binder_thread *thread)
  505. {
  506. return !thread->transaction_stack &&
  507. binder_worklist_empty_ilocked(&thread->todo);
  508. }
  509. static void binder_wakeup_poll_threads_ilocked(struct binder_proc *proc,
  510. bool sync)
  511. {
  512. struct rb_node *n;
  513. struct binder_thread *thread;
  514. for (n = rb_first(&proc->threads); n != NULL; n = rb_next(n)) {
  515. thread = rb_entry(n, struct binder_thread, rb_node);
  516. if (thread->looper & BINDER_LOOPER_STATE_POLL &&
  517. binder_available_for_proc_work_ilocked(thread)) {
  518. if (sync)
  519. wake_up_interruptible_sync(&thread->wait);
  520. else
  521. wake_up_interruptible(&thread->wait);
  522. }
  523. }
  524. }
  525. /**
  526. * binder_select_thread_ilocked() - selects a thread for doing proc work.
  527. * @proc: process to select a thread from
  528. *
  529. * Note that calling this function moves the thread off the waiting_threads
  530. * list, so it can only be woken up by the caller of this function, or a
  531. * signal. Therefore, callers *should* always wake up the thread this function
  532. * returns.
  533. *
  534. * Return: If there's a thread currently waiting for process work,
  535. * returns that thread. Otherwise returns NULL.
  536. */
  537. static struct binder_thread *
  538. binder_select_thread_ilocked(struct binder_proc *proc)
  539. {
  540. struct binder_thread *thread;
  541. assert_spin_locked(&proc->inner_lock);
  542. thread = list_first_entry_or_null(&proc->waiting_threads,
  543. struct binder_thread,
  544. waiting_thread_node);
  545. if (thread)
  546. list_del_init(&thread->waiting_thread_node);
  547. return thread;
  548. }
  549. /**
  550. * binder_wakeup_thread_ilocked() - wakes up a thread for doing proc work.
  551. * @proc: process to wake up a thread in
  552. * @thread: specific thread to wake-up (may be NULL)
  553. * @sync: whether to do a synchronous wake-up
  554. *
  555. * This function wakes up a thread in the @proc process.
  556. * The caller may provide a specific thread to wake-up in
  557. * the @thread parameter. If @thread is NULL, this function
  558. * will wake up threads that have called poll().
  559. *
  560. * Note that for this function to work as expected, callers
  561. * should first call binder_select_thread() to find a thread
  562. * to handle the work (if they don't have a thread already),
  563. * and pass the result into the @thread parameter.
  564. */
  565. static void binder_wakeup_thread_ilocked(struct binder_proc *proc,
  566. struct binder_thread *thread,
  567. bool sync)
  568. {
  569. assert_spin_locked(&proc->inner_lock);
  570. if (thread) {
  571. if (sync)
  572. wake_up_interruptible_sync(&thread->wait);
  573. else
  574. wake_up_interruptible(&thread->wait);
  575. return;
  576. }
  577. /* Didn't find a thread waiting for proc work; this can happen
  578. * in two scenarios:
  579. * 1. All threads are busy handling transactions
  580. * In that case, one of those threads should call back into
  581. * the kernel driver soon and pick up this work.
  582. * 2. Threads are using the (e)poll interface, in which case
  583. * they may be blocked on the waitqueue without having been
  584. * added to waiting_threads. For this case, we just iterate
  585. * over all threads not handling transaction work, and
  586. * wake them all up. We wake all because we don't know whether
  587. * a thread that called into (e)poll is handling non-binder
  588. * work currently.
  589. */
  590. binder_wakeup_poll_threads_ilocked(proc, sync);
  591. }
  592. static void binder_wakeup_proc_ilocked(struct binder_proc *proc)
  593. {
  594. struct binder_thread *thread = binder_select_thread_ilocked(proc);
  595. binder_wakeup_thread_ilocked(proc, thread, /* sync = */false);
  596. }
  597. static void binder_set_nice(long nice)
  598. {
  599. long min_nice;
  600. if (can_nice(current, nice)) {
  601. set_user_nice(current, nice);
  602. return;
  603. }
  604. min_nice = rlimit_to_nice(rlimit(RLIMIT_NICE));
  605. binder_debug(BINDER_DEBUG_PRIORITY_CAP,
  606. "%d: nice value %ld not allowed use %ld instead\n",
  607. current->pid, nice, min_nice);
  608. set_user_nice(current, min_nice);
  609. if (min_nice <= MAX_NICE)
  610. return;
  611. binder_user_error("%d RLIMIT_NICE not set\n", current->pid);
  612. }
  613. static struct binder_node *binder_get_node_ilocked(struct binder_proc *proc,
  614. binder_uintptr_t ptr)
  615. {
  616. struct rb_node *n = proc->nodes.rb_node;
  617. struct binder_node *node;
  618. assert_spin_locked(&proc->inner_lock);
  619. while (n) {
  620. node = rb_entry(n, struct binder_node, rb_node);
  621. if (ptr < node->ptr)
  622. n = n->rb_left;
  623. else if (ptr > node->ptr)
  624. n = n->rb_right;
  625. else {
  626. /*
  627. * take an implicit weak reference
  628. * to ensure node stays alive until
  629. * call to binder_put_node()
  630. */
  631. binder_inc_node_tmpref_ilocked(node);
  632. return node;
  633. }
  634. }
  635. return NULL;
  636. }
  637. static struct binder_node *binder_get_node(struct binder_proc *proc,
  638. binder_uintptr_t ptr)
  639. {
  640. struct binder_node *node;
  641. binder_inner_proc_lock(proc);
  642. node = binder_get_node_ilocked(proc, ptr);
  643. binder_inner_proc_unlock(proc);
  644. return node;
  645. }
  646. static struct binder_node *binder_init_node_ilocked(
  647. struct binder_proc *proc,
  648. struct binder_node *new_node,
  649. struct flat_binder_object *fp)
  650. {
  651. struct rb_node **p = &proc->nodes.rb_node;
  652. struct rb_node *parent = NULL;
  653. struct binder_node *node;
  654. binder_uintptr_t ptr = fp ? fp->binder : 0;
  655. binder_uintptr_t cookie = fp ? fp->cookie : 0;
  656. __u32 flags = fp ? fp->flags : 0;
  657. assert_spin_locked(&proc->inner_lock);
  658. while (*p) {
  659. parent = *p;
  660. node = rb_entry(parent, struct binder_node, rb_node);
  661. if (ptr < node->ptr)
  662. p = &(*p)->rb_left;
  663. else if (ptr > node->ptr)
  664. p = &(*p)->rb_right;
  665. else {
  666. /*
  667. * A matching node is already in
  668. * the rb tree. Abandon the init
  669. * and return it.
  670. */
  671. binder_inc_node_tmpref_ilocked(node);
  672. return node;
  673. }
  674. }
  675. node = new_node;
  676. binder_stats_created(BINDER_STAT_NODE);
  677. node->tmp_refs++;
  678. rb_link_node(&node->rb_node, parent, p);
  679. rb_insert_color(&node->rb_node, &proc->nodes);
  680. node->debug_id = atomic_inc_return(&binder_last_id);
  681. node->proc = proc;
  682. node->ptr = ptr;
  683. node->cookie = cookie;
  684. node->work.type = BINDER_WORK_NODE;
  685. node->min_priority = flags & FLAT_BINDER_FLAG_PRIORITY_MASK;
  686. node->accept_fds = !!(flags & FLAT_BINDER_FLAG_ACCEPTS_FDS);
  687. node->txn_security_ctx = !!(flags & FLAT_BINDER_FLAG_TXN_SECURITY_CTX);
  688. spin_lock_init(&node->lock);
  689. INIT_LIST_HEAD(&node->work.entry);
  690. INIT_LIST_HEAD(&node->async_todo);
  691. binder_debug(BINDER_DEBUG_INTERNAL_REFS,
  692. "%d:%d node %d u%016llx c%016llx created\n",
  693. proc->pid, current->pid, node->debug_id,
  694. (u64)node->ptr, (u64)node->cookie);
  695. return node;
  696. }
  697. static struct binder_node *binder_new_node(struct binder_proc *proc,
  698. struct flat_binder_object *fp)
  699. {
  700. struct binder_node *node;
  701. struct binder_node *new_node = kzalloc(sizeof(*node), GFP_KERNEL);
  702. if (!new_node)
  703. return NULL;
  704. binder_inner_proc_lock(proc);
  705. node = binder_init_node_ilocked(proc, new_node, fp);
  706. binder_inner_proc_unlock(proc);
  707. if (node != new_node)
  708. /*
  709. * The node was already added by another thread
  710. */
  711. kfree(new_node);
  712. return node;
  713. }
  714. static void binder_free_node(struct binder_node *node)
  715. {
  716. kfree(node);
  717. binder_stats_deleted(BINDER_STAT_NODE);
  718. }
  719. static int binder_inc_node_nilocked(struct binder_node *node, int strong,
  720. int internal,
  721. struct list_head *target_list)
  722. {
  723. struct binder_proc *proc = node->proc;
  724. assert_spin_locked(&node->lock);
  725. if (proc)
  726. assert_spin_locked(&proc->inner_lock);
  727. if (strong) {
  728. if (internal) {
  729. if (target_list == NULL &&
  730. node->internal_strong_refs == 0 &&
  731. !(node->proc &&
  732. node == node->proc->context->binder_context_mgr_node &&
  733. node->has_strong_ref)) {
  734. pr_err("invalid inc strong node for %d\n",
  735. node->debug_id);
  736. return -EINVAL;
  737. }
  738. node->internal_strong_refs++;
  739. } else
  740. node->local_strong_refs++;
  741. if (!node->has_strong_ref && target_list) {
  742. struct binder_thread *thread = container_of(target_list,
  743. struct binder_thread, todo);
  744. binder_dequeue_work_ilocked(&node->work);
  745. BUG_ON(&thread->todo != target_list);
  746. binder_enqueue_deferred_thread_work_ilocked(thread,
  747. &node->work);
  748. }
  749. } else {
  750. if (!internal)
  751. node->local_weak_refs++;
  752. if (!node->has_weak_ref && target_list && list_empty(&node->work.entry))
  753. binder_enqueue_work_ilocked(&node->work, target_list);
  754. }
  755. return 0;
  756. }
  757. static int binder_inc_node(struct binder_node *node, int strong, int internal,
  758. struct list_head *target_list)
  759. {
  760. int ret;
  761. binder_node_inner_lock(node);
  762. ret = binder_inc_node_nilocked(node, strong, internal, target_list);
  763. binder_node_inner_unlock(node);
  764. return ret;
  765. }
  766. static bool binder_dec_node_nilocked(struct binder_node *node,
  767. int strong, int internal)
  768. {
  769. struct binder_proc *proc = node->proc;
  770. assert_spin_locked(&node->lock);
  771. if (proc)
  772. assert_spin_locked(&proc->inner_lock);
  773. if (strong) {
  774. if (internal)
  775. node->internal_strong_refs--;
  776. else
  777. node->local_strong_refs--;
  778. if (node->local_strong_refs || node->internal_strong_refs)
  779. return false;
  780. } else {
  781. if (!internal)
  782. node->local_weak_refs--;
  783. if (node->local_weak_refs || node->tmp_refs ||
  784. !hlist_empty(&node->refs))
  785. return false;
  786. }
  787. if (proc && (node->has_strong_ref || node->has_weak_ref)) {
  788. if (list_empty(&node->work.entry)) {
  789. binder_enqueue_work_ilocked(&node->work, &proc->todo);
  790. binder_wakeup_proc_ilocked(proc);
  791. }
  792. } else {
  793. if (hlist_empty(&node->refs) && !node->local_strong_refs &&
  794. !node->local_weak_refs && !node->tmp_refs) {
  795. if (proc) {
  796. binder_dequeue_work_ilocked(&node->work);
  797. rb_erase(&node->rb_node, &proc->nodes);
  798. binder_debug(BINDER_DEBUG_INTERNAL_REFS,
  799. "refless node %d deleted\n",
  800. node->debug_id);
  801. } else {
  802. BUG_ON(!list_empty(&node->work.entry));
  803. spin_lock(&binder_dead_nodes_lock);
  804. /*
  805. * tmp_refs could have changed so
  806. * check it again
  807. */
  808. if (node->tmp_refs) {
  809. spin_unlock(&binder_dead_nodes_lock);
  810. return false;
  811. }
  812. hlist_del(&node->dead_node);
  813. spin_unlock(&binder_dead_nodes_lock);
  814. binder_debug(BINDER_DEBUG_INTERNAL_REFS,
  815. "dead node %d deleted\n",
  816. node->debug_id);
  817. }
  818. return true;
  819. }
  820. }
  821. return false;
  822. }
  823. static void binder_dec_node(struct binder_node *node, int strong, int internal)
  824. {
  825. bool free_node;
  826. binder_node_inner_lock(node);
  827. free_node = binder_dec_node_nilocked(node, strong, internal);
  828. binder_node_inner_unlock(node);
  829. if (free_node)
  830. binder_free_node(node);
  831. }
  832. static void binder_inc_node_tmpref_ilocked(struct binder_node *node)
  833. {
  834. /*
  835. * No call to binder_inc_node() is needed since we
  836. * don't need to inform userspace of any changes to
  837. * tmp_refs
  838. */
  839. node->tmp_refs++;
  840. }
  841. /**
  842. * binder_inc_node_tmpref() - take a temporary reference on node
  843. * @node: node to reference
  844. *
  845. * Take reference on node to prevent the node from being freed
  846. * while referenced only by a local variable. The inner lock is
  847. * needed to serialize with the node work on the queue (which
  848. * isn't needed after the node is dead). If the node is dead
  849. * (node->proc is NULL), use binder_dead_nodes_lock to protect
  850. * node->tmp_refs against dead-node-only cases where the node
  851. * lock cannot be acquired (eg traversing the dead node list to
  852. * print nodes)
  853. */
  854. static void binder_inc_node_tmpref(struct binder_node *node)
  855. {
  856. binder_node_lock(node);
  857. if (node->proc)
  858. binder_inner_proc_lock(node->proc);
  859. else
  860. spin_lock(&binder_dead_nodes_lock);
  861. binder_inc_node_tmpref_ilocked(node);
  862. if (node->proc)
  863. binder_inner_proc_unlock(node->proc);
  864. else
  865. spin_unlock(&binder_dead_nodes_lock);
  866. binder_node_unlock(node);
  867. }
  868. /**
  869. * binder_dec_node_tmpref() - remove a temporary reference on node
  870. * @node: node to reference
  871. *
  872. * Release temporary reference on node taken via binder_inc_node_tmpref()
  873. */
  874. static void binder_dec_node_tmpref(struct binder_node *node)
  875. {
  876. bool free_node;
  877. binder_node_inner_lock(node);
  878. if (!node->proc)
  879. spin_lock(&binder_dead_nodes_lock);
  880. else
  881. __acquire(&binder_dead_nodes_lock);
  882. node->tmp_refs--;
  883. BUG_ON(node->tmp_refs < 0);
  884. if (!node->proc)
  885. spin_unlock(&binder_dead_nodes_lock);
  886. else
  887. __release(&binder_dead_nodes_lock);
  888. /*
  889. * Call binder_dec_node() to check if all refcounts are 0
  890. * and cleanup is needed. Calling with strong=0 and internal=1
  891. * causes no actual reference to be released in binder_dec_node().
  892. * If that changes, a change is needed here too.
  893. */
  894. free_node = binder_dec_node_nilocked(node, 0, 1);
  895. binder_node_inner_unlock(node);
  896. if (free_node)
  897. binder_free_node(node);
  898. }
  899. static void binder_put_node(struct binder_node *node)
  900. {
  901. binder_dec_node_tmpref(node);
  902. }
  903. static struct binder_ref *binder_get_ref_olocked(struct binder_proc *proc,
  904. u32 desc, bool need_strong_ref)
  905. {
  906. struct rb_node *n = proc->refs_by_desc.rb_node;
  907. struct binder_ref *ref;
  908. while (n) {
  909. ref = rb_entry(n, struct binder_ref, rb_node_desc);
  910. if (desc < ref->data.desc) {
  911. n = n->rb_left;
  912. } else if (desc > ref->data.desc) {
  913. n = n->rb_right;
  914. } else if (need_strong_ref && !ref->data.strong) {
  915. binder_user_error("tried to use weak ref as strong ref\n");
  916. return NULL;
  917. } else {
  918. return ref;
  919. }
  920. }
  921. return NULL;
  922. }
  923. /* Find the smallest unused descriptor the "slow way" */
  924. static u32 slow_desc_lookup_olocked(struct binder_proc *proc, u32 offset)
  925. {
  926. struct binder_ref *ref;
  927. struct rb_node *n;
  928. u32 desc;
  929. desc = offset;
  930. for (n = rb_first(&proc->refs_by_desc); n; n = rb_next(n)) {
  931. ref = rb_entry(n, struct binder_ref, rb_node_desc);
  932. if (ref->data.desc > desc)
  933. break;
  934. desc = ref->data.desc + 1;
  935. }
  936. return desc;
  937. }
  938. /*
  939. * Find an available reference descriptor ID. The proc->outer_lock might
  940. * be released in the process, in which case -EAGAIN is returned and the
  941. * @desc should be considered invalid.
  942. */
  943. static int get_ref_desc_olocked(struct binder_proc *proc,
  944. struct binder_node *node,
  945. u32 *desc)
  946. {
  947. struct dbitmap *dmap = &proc->dmap;
  948. unsigned int nbits, offset;
  949. unsigned long *new, bit;
  950. /* 0 is reserved for the context manager */
  951. offset = (node == proc->context->binder_context_mgr_node) ? 0 : 1;
  952. if (!dbitmap_enabled(dmap)) {
  953. *desc = slow_desc_lookup_olocked(proc, offset);
  954. return 0;
  955. }
  956. if (dbitmap_acquire_next_zero_bit(dmap, offset, &bit) == 0) {
  957. *desc = bit;
  958. return 0;
  959. }
  960. /*
  961. * The dbitmap is full and needs to grow. The proc->outer_lock
  962. * is briefly released to allocate the new bitmap safely.
  963. */
  964. nbits = dbitmap_grow_nbits(dmap);
  965. binder_proc_unlock(proc);
  966. new = bitmap_zalloc(nbits, GFP_KERNEL);
  967. binder_proc_lock(proc);
  968. dbitmap_grow(dmap, new, nbits);
  969. return -EAGAIN;
  970. }
  971. /**
  972. * binder_get_ref_for_node_olocked() - get the ref associated with given node
  973. * @proc: binder_proc that owns the ref
  974. * @node: binder_node of target
  975. * @new_ref: newly allocated binder_ref to be initialized or %NULL
  976. *
  977. * Look up the ref for the given node and return it if it exists
  978. *
  979. * If it doesn't exist and the caller provides a newly allocated
  980. * ref, initialize the fields of the newly allocated ref and insert
  981. * into the given proc rb_trees and node refs list.
  982. *
  983. * Return: the ref for node. It is possible that another thread
  984. * allocated/initialized the ref first in which case the
  985. * returned ref would be different than the passed-in
  986. * new_ref. new_ref must be kfree'd by the caller in
  987. * this case.
  988. */
  989. static struct binder_ref *binder_get_ref_for_node_olocked(
  990. struct binder_proc *proc,
  991. struct binder_node *node,
  992. struct binder_ref *new_ref)
  993. {
  994. struct binder_ref *ref;
  995. struct rb_node *parent;
  996. struct rb_node **p;
  997. u32 desc;
  998. retry:
  999. p = &proc->refs_by_node.rb_node;
  1000. parent = NULL;
  1001. while (*p) {
  1002. parent = *p;
  1003. ref = rb_entry(parent, struct binder_ref, rb_node_node);
  1004. if (node < ref->node)
  1005. p = &(*p)->rb_left;
  1006. else if (node > ref->node)
  1007. p = &(*p)->rb_right;
  1008. else
  1009. return ref;
  1010. }
  1011. if (!new_ref)
  1012. return NULL;
  1013. /* might release the proc->outer_lock */
  1014. if (get_ref_desc_olocked(proc, node, &desc) == -EAGAIN)
  1015. goto retry;
  1016. binder_stats_created(BINDER_STAT_REF);
  1017. new_ref->data.debug_id = atomic_inc_return(&binder_last_id);
  1018. new_ref->proc = proc;
  1019. new_ref->node = node;
  1020. rb_link_node(&new_ref->rb_node_node, parent, p);
  1021. rb_insert_color(&new_ref->rb_node_node, &proc->refs_by_node);
  1022. new_ref->data.desc = desc;
  1023. p = &proc->refs_by_desc.rb_node;
  1024. while (*p) {
  1025. parent = *p;
  1026. ref = rb_entry(parent, struct binder_ref, rb_node_desc);
  1027. if (new_ref->data.desc < ref->data.desc)
  1028. p = &(*p)->rb_left;
  1029. else if (new_ref->data.desc > ref->data.desc)
  1030. p = &(*p)->rb_right;
  1031. else
  1032. BUG();
  1033. }
  1034. rb_link_node(&new_ref->rb_node_desc, parent, p);
  1035. rb_insert_color(&new_ref->rb_node_desc, &proc->refs_by_desc);
  1036. binder_node_lock(node);
  1037. hlist_add_head(&new_ref->node_entry, &node->refs);
  1038. binder_debug(BINDER_DEBUG_INTERNAL_REFS,
  1039. "%d new ref %d desc %d for node %d\n",
  1040. proc->pid, new_ref->data.debug_id, new_ref->data.desc,
  1041. node->debug_id);
  1042. binder_node_unlock(node);
  1043. return new_ref;
  1044. }
  1045. static void binder_cleanup_ref_olocked(struct binder_ref *ref)
  1046. {
  1047. struct dbitmap *dmap = &ref->proc->dmap;
  1048. bool delete_node = false;
  1049. binder_debug(BINDER_DEBUG_INTERNAL_REFS,
  1050. "%d delete ref %d desc %d for node %d\n",
  1051. ref->proc->pid, ref->data.debug_id, ref->data.desc,
  1052. ref->node->debug_id);
  1053. if (dbitmap_enabled(dmap))
  1054. dbitmap_clear_bit(dmap, ref->data.desc);
  1055. rb_erase(&ref->rb_node_desc, &ref->proc->refs_by_desc);
  1056. rb_erase(&ref->rb_node_node, &ref->proc->refs_by_node);
  1057. binder_node_inner_lock(ref->node);
  1058. if (ref->data.strong)
  1059. binder_dec_node_nilocked(ref->node, 1, 1);
  1060. hlist_del(&ref->node_entry);
  1061. delete_node = binder_dec_node_nilocked(ref->node, 0, 1);
  1062. binder_node_inner_unlock(ref->node);
  1063. /*
  1064. * Clear ref->node unless we want the caller to free the node
  1065. */
  1066. if (!delete_node) {
  1067. /*
  1068. * The caller uses ref->node to determine
  1069. * whether the node needs to be freed. Clear
  1070. * it since the node is still alive.
  1071. */
  1072. ref->node = NULL;
  1073. }
  1074. if (ref->death) {
  1075. binder_debug(BINDER_DEBUG_DEAD_BINDER,
  1076. "%d delete ref %d desc %d has death notification\n",
  1077. ref->proc->pid, ref->data.debug_id,
  1078. ref->data.desc);
  1079. binder_dequeue_work(ref->proc, &ref->death->work);
  1080. binder_stats_deleted(BINDER_STAT_DEATH);
  1081. }
  1082. if (ref->freeze) {
  1083. binder_dequeue_work(ref->proc, &ref->freeze->work);
  1084. binder_stats_deleted(BINDER_STAT_FREEZE);
  1085. }
  1086. binder_stats_deleted(BINDER_STAT_REF);
  1087. }
  1088. /**
  1089. * binder_inc_ref_olocked() - increment the ref for given handle
  1090. * @ref: ref to be incremented
  1091. * @strong: if true, strong increment, else weak
  1092. * @target_list: list to queue node work on
  1093. *
  1094. * Increment the ref. @ref->proc->outer_lock must be held on entry
  1095. *
  1096. * Return: 0, if successful, else errno
  1097. */
  1098. static int binder_inc_ref_olocked(struct binder_ref *ref, int strong,
  1099. struct list_head *target_list)
  1100. {
  1101. int ret;
  1102. if (strong) {
  1103. if (ref->data.strong == 0) {
  1104. ret = binder_inc_node(ref->node, 1, 1, target_list);
  1105. if (ret)
  1106. return ret;
  1107. }
  1108. ref->data.strong++;
  1109. } else {
  1110. if (ref->data.weak == 0) {
  1111. ret = binder_inc_node(ref->node, 0, 1, target_list);
  1112. if (ret)
  1113. return ret;
  1114. }
  1115. ref->data.weak++;
  1116. }
  1117. return 0;
  1118. }
  1119. /**
  1120. * binder_dec_ref_olocked() - dec the ref for given handle
  1121. * @ref: ref to be decremented
  1122. * @strong: if true, strong decrement, else weak
  1123. *
  1124. * Decrement the ref.
  1125. *
  1126. * Return: %true if ref is cleaned up and ready to be freed.
  1127. */
  1128. static bool binder_dec_ref_olocked(struct binder_ref *ref, int strong)
  1129. {
  1130. if (strong) {
  1131. if (ref->data.strong == 0) {
  1132. binder_user_error("%d invalid dec strong, ref %d desc %d s %d w %d\n",
  1133. ref->proc->pid, ref->data.debug_id,
  1134. ref->data.desc, ref->data.strong,
  1135. ref->data.weak);
  1136. return false;
  1137. }
  1138. ref->data.strong--;
  1139. if (ref->data.strong == 0)
  1140. binder_dec_node(ref->node, strong, 1);
  1141. } else {
  1142. if (ref->data.weak == 0) {
  1143. binder_user_error("%d invalid dec weak, ref %d desc %d s %d w %d\n",
  1144. ref->proc->pid, ref->data.debug_id,
  1145. ref->data.desc, ref->data.strong,
  1146. ref->data.weak);
  1147. return false;
  1148. }
  1149. ref->data.weak--;
  1150. }
  1151. if (ref->data.strong == 0 && ref->data.weak == 0) {
  1152. binder_cleanup_ref_olocked(ref);
  1153. return true;
  1154. }
  1155. return false;
  1156. }
  1157. /**
  1158. * binder_get_node_from_ref() - get the node from the given proc/desc
  1159. * @proc: proc containing the ref
  1160. * @desc: the handle associated with the ref
  1161. * @need_strong_ref: if true, only return node if ref is strong
  1162. * @rdata: the id/refcount data for the ref
  1163. *
  1164. * Given a proc and ref handle, return the associated binder_node
  1165. *
  1166. * Return: a binder_node or NULL if not found or not strong when strong required
  1167. */
  1168. static struct binder_node *binder_get_node_from_ref(
  1169. struct binder_proc *proc,
  1170. u32 desc, bool need_strong_ref,
  1171. struct binder_ref_data *rdata)
  1172. {
  1173. struct binder_node *node;
  1174. struct binder_ref *ref;
  1175. binder_proc_lock(proc);
  1176. ref = binder_get_ref_olocked(proc, desc, need_strong_ref);
  1177. if (!ref)
  1178. goto err_no_ref;
  1179. node = ref->node;
  1180. /*
  1181. * Take an implicit reference on the node to ensure
  1182. * it stays alive until the call to binder_put_node()
  1183. */
  1184. binder_inc_node_tmpref(node);
  1185. if (rdata)
  1186. *rdata = ref->data;
  1187. binder_proc_unlock(proc);
  1188. return node;
  1189. err_no_ref:
  1190. binder_proc_unlock(proc);
  1191. return NULL;
  1192. }
  1193. /**
  1194. * binder_free_ref() - free the binder_ref
  1195. * @ref: ref to free
  1196. *
  1197. * Free the binder_ref. Free the binder_node indicated by ref->node
  1198. * (if non-NULL) and the binder_ref_death indicated by ref->death.
  1199. */
  1200. static void binder_free_ref(struct binder_ref *ref)
  1201. {
  1202. if (ref->node)
  1203. binder_free_node(ref->node);
  1204. kfree(ref->death);
  1205. kfree(ref->freeze);
  1206. kfree(ref);
  1207. }
  1208. /* shrink descriptor bitmap if needed */
  1209. static void try_shrink_dmap(struct binder_proc *proc)
  1210. {
  1211. unsigned long *new;
  1212. int nbits;
  1213. binder_proc_lock(proc);
  1214. nbits = dbitmap_shrink_nbits(&proc->dmap);
  1215. binder_proc_unlock(proc);
  1216. if (!nbits)
  1217. return;
  1218. new = bitmap_zalloc(nbits, GFP_KERNEL);
  1219. binder_proc_lock(proc);
  1220. dbitmap_shrink(&proc->dmap, new, nbits);
  1221. binder_proc_unlock(proc);
  1222. }
  1223. /**
  1224. * binder_update_ref_for_handle() - inc/dec the ref for given handle
  1225. * @proc: proc containing the ref
  1226. * @desc: the handle associated with the ref
  1227. * @increment: true=inc reference, false=dec reference
  1228. * @strong: true=strong reference, false=weak reference
  1229. * @rdata: the id/refcount data for the ref
  1230. *
  1231. * Given a proc and ref handle, increment or decrement the ref
  1232. * according to "increment" arg.
  1233. *
  1234. * Return: 0 if successful, else errno
  1235. */
  1236. static int binder_update_ref_for_handle(struct binder_proc *proc,
  1237. uint32_t desc, bool increment, bool strong,
  1238. struct binder_ref_data *rdata)
  1239. {
  1240. int ret = 0;
  1241. struct binder_ref *ref;
  1242. bool delete_ref = false;
  1243. binder_proc_lock(proc);
  1244. ref = binder_get_ref_olocked(proc, desc, strong);
  1245. if (!ref) {
  1246. ret = -EINVAL;
  1247. goto err_no_ref;
  1248. }
  1249. if (increment)
  1250. ret = binder_inc_ref_olocked(ref, strong, NULL);
  1251. else
  1252. delete_ref = binder_dec_ref_olocked(ref, strong);
  1253. if (rdata)
  1254. *rdata = ref->data;
  1255. binder_proc_unlock(proc);
  1256. if (delete_ref) {
  1257. binder_free_ref(ref);
  1258. try_shrink_dmap(proc);
  1259. }
  1260. return ret;
  1261. err_no_ref:
  1262. binder_proc_unlock(proc);
  1263. return ret;
  1264. }
  1265. /**
  1266. * binder_dec_ref_for_handle() - dec the ref for given handle
  1267. * @proc: proc containing the ref
  1268. * @desc: the handle associated with the ref
  1269. * @strong: true=strong reference, false=weak reference
  1270. * @rdata: the id/refcount data for the ref
  1271. *
  1272. * Just calls binder_update_ref_for_handle() to decrement the ref.
  1273. *
  1274. * Return: 0 if successful, else errno
  1275. */
  1276. static int binder_dec_ref_for_handle(struct binder_proc *proc,
  1277. uint32_t desc, bool strong, struct binder_ref_data *rdata)
  1278. {
  1279. return binder_update_ref_for_handle(proc, desc, false, strong, rdata);
  1280. }
  1281. /**
  1282. * binder_inc_ref_for_node() - increment the ref for given proc/node
  1283. * @proc: proc containing the ref
  1284. * @node: target node
  1285. * @strong: true=strong reference, false=weak reference
  1286. * @target_list: worklist to use if node is incremented
  1287. * @rdata: the id/refcount data for the ref
  1288. *
  1289. * Given a proc and node, increment the ref. Create the ref if it
  1290. * doesn't already exist
  1291. *
  1292. * Return: 0 if successful, else errno
  1293. */
  1294. static int binder_inc_ref_for_node(struct binder_proc *proc,
  1295. struct binder_node *node,
  1296. bool strong,
  1297. struct list_head *target_list,
  1298. struct binder_ref_data *rdata)
  1299. {
  1300. struct binder_ref *ref;
  1301. struct binder_ref *new_ref = NULL;
  1302. int ret = 0;
  1303. binder_proc_lock(proc);
  1304. ref = binder_get_ref_for_node_olocked(proc, node, NULL);
  1305. if (!ref) {
  1306. binder_proc_unlock(proc);
  1307. new_ref = kzalloc(sizeof(*ref), GFP_KERNEL);
  1308. if (!new_ref)
  1309. return -ENOMEM;
  1310. binder_proc_lock(proc);
  1311. ref = binder_get_ref_for_node_olocked(proc, node, new_ref);
  1312. }
  1313. ret = binder_inc_ref_olocked(ref, strong, target_list);
  1314. *rdata = ref->data;
  1315. if (ret && ref == new_ref) {
  1316. /*
  1317. * Cleanup the failed reference here as the target
  1318. * could now be dead and have already released its
  1319. * references by now. Calling on the new reference
  1320. * with strong=0 and a tmp_refs will not decrement
  1321. * the node. The new_ref gets kfree'd below.
  1322. */
  1323. binder_cleanup_ref_olocked(new_ref);
  1324. ref = NULL;
  1325. }
  1326. binder_proc_unlock(proc);
  1327. if (new_ref && ref != new_ref)
  1328. /*
  1329. * Another thread created the ref first so
  1330. * free the one we allocated
  1331. */
  1332. kfree(new_ref);
  1333. return ret;
  1334. }
  1335. static void binder_pop_transaction_ilocked(struct binder_thread *target_thread,
  1336. struct binder_transaction *t)
  1337. {
  1338. BUG_ON(!target_thread);
  1339. assert_spin_locked(&target_thread->proc->inner_lock);
  1340. BUG_ON(target_thread->transaction_stack != t);
  1341. BUG_ON(target_thread->transaction_stack->from != target_thread);
  1342. target_thread->transaction_stack =
  1343. target_thread->transaction_stack->from_parent;
  1344. t->from = NULL;
  1345. }
  1346. /**
  1347. * binder_thread_dec_tmpref() - decrement thread->tmp_ref
  1348. * @thread: thread to decrement
  1349. *
  1350. * A thread needs to be kept alive while being used to create or
  1351. * handle a transaction. binder_get_txn_from() is used to safely
  1352. * extract t->from from a binder_transaction and keep the thread
  1353. * indicated by t->from from being freed. When done with that
  1354. * binder_thread, this function is called to decrement the
  1355. * tmp_ref and free if appropriate (thread has been released
  1356. * and no transaction being processed by the driver)
  1357. */
  1358. static void binder_thread_dec_tmpref(struct binder_thread *thread)
  1359. {
  1360. /*
  1361. * atomic is used to protect the counter value while
  1362. * it cannot reach zero or thread->is_dead is false
  1363. */
  1364. binder_inner_proc_lock(thread->proc);
  1365. atomic_dec(&thread->tmp_ref);
  1366. if (thread->is_dead && !atomic_read(&thread->tmp_ref)) {
  1367. binder_inner_proc_unlock(thread->proc);
  1368. binder_free_thread(thread);
  1369. return;
  1370. }
  1371. binder_inner_proc_unlock(thread->proc);
  1372. }
  1373. /**
  1374. * binder_proc_dec_tmpref() - decrement proc->tmp_ref
  1375. * @proc: proc to decrement
  1376. *
  1377. * A binder_proc needs to be kept alive while being used to create or
  1378. * handle a transaction. proc->tmp_ref is incremented when
  1379. * creating a new transaction or the binder_proc is currently in-use
  1380. * by threads that are being released. When done with the binder_proc,
  1381. * this function is called to decrement the counter and free the
  1382. * proc if appropriate (proc has been released, all threads have
  1383. * been released and not currently in-use to process a transaction).
  1384. */
  1385. static void binder_proc_dec_tmpref(struct binder_proc *proc)
  1386. {
  1387. binder_inner_proc_lock(proc);
  1388. proc->tmp_ref--;
  1389. if (proc->is_dead && RB_EMPTY_ROOT(&proc->threads) &&
  1390. !proc->tmp_ref) {
  1391. binder_inner_proc_unlock(proc);
  1392. binder_free_proc(proc);
  1393. return;
  1394. }
  1395. binder_inner_proc_unlock(proc);
  1396. }
  1397. /**
  1398. * binder_get_txn_from() - safely extract the "from" thread in transaction
  1399. * @t: binder transaction for t->from
  1400. *
  1401. * Atomically return the "from" thread and increment the tmp_ref
  1402. * count for the thread to ensure it stays alive until
  1403. * binder_thread_dec_tmpref() is called.
  1404. *
  1405. * Return: the value of t->from
  1406. */
  1407. static struct binder_thread *binder_get_txn_from(
  1408. struct binder_transaction *t)
  1409. {
  1410. struct binder_thread *from;
  1411. spin_lock(&t->lock);
  1412. from = t->from;
  1413. if (from)
  1414. atomic_inc(&from->tmp_ref);
  1415. spin_unlock(&t->lock);
  1416. return from;
  1417. }
  1418. /**
  1419. * binder_get_txn_from_and_acq_inner() - get t->from and acquire inner lock
  1420. * @t: binder transaction for t->from
  1421. *
  1422. * Same as binder_get_txn_from() except it also acquires the proc->inner_lock
  1423. * to guarantee that the thread cannot be released while operating on it.
  1424. * The caller must call binder_inner_proc_unlock() to release the inner lock
  1425. * as well as call binder_dec_thread_txn() to release the reference.
  1426. *
  1427. * Return: the value of t->from
  1428. */
  1429. static struct binder_thread *binder_get_txn_from_and_acq_inner(
  1430. struct binder_transaction *t)
  1431. __acquires(&t->from->proc->inner_lock)
  1432. {
  1433. struct binder_thread *from;
  1434. from = binder_get_txn_from(t);
  1435. if (!from) {
  1436. __acquire(&from->proc->inner_lock);
  1437. return NULL;
  1438. }
  1439. binder_inner_proc_lock(from->proc);
  1440. if (t->from) {
  1441. BUG_ON(from != t->from);
  1442. return from;
  1443. }
  1444. binder_inner_proc_unlock(from->proc);
  1445. __acquire(&from->proc->inner_lock);
  1446. binder_thread_dec_tmpref(from);
  1447. return NULL;
  1448. }
  1449. /**
  1450. * binder_free_txn_fixups() - free unprocessed fd fixups
  1451. * @t: binder transaction for t->from
  1452. *
  1453. * If the transaction is being torn down prior to being
  1454. * processed by the target process, free all of the
  1455. * fd fixups and fput the file structs. It is safe to
  1456. * call this function after the fixups have been
  1457. * processed -- in that case, the list will be empty.
  1458. */
  1459. static void binder_free_txn_fixups(struct binder_transaction *t)
  1460. {
  1461. struct binder_txn_fd_fixup *fixup, *tmp;
  1462. list_for_each_entry_safe(fixup, tmp, &t->fd_fixups, fixup_entry) {
  1463. fput(fixup->file);
  1464. if (fixup->target_fd >= 0)
  1465. put_unused_fd(fixup->target_fd);
  1466. list_del(&fixup->fixup_entry);
  1467. kfree(fixup);
  1468. }
  1469. }
  1470. static void binder_txn_latency_free(struct binder_transaction *t)
  1471. {
  1472. int from_proc, from_thread, to_proc, to_thread;
  1473. spin_lock(&t->lock);
  1474. from_proc = t->from ? t->from->proc->pid : 0;
  1475. from_thread = t->from ? t->from->pid : 0;
  1476. to_proc = t->to_proc ? t->to_proc->pid : 0;
  1477. to_thread = t->to_thread ? t->to_thread->pid : 0;
  1478. spin_unlock(&t->lock);
  1479. trace_binder_txn_latency_free(t, from_proc, from_thread, to_proc, to_thread);
  1480. }
  1481. static void binder_free_transaction(struct binder_transaction *t)
  1482. {
  1483. struct binder_proc *target_proc = t->to_proc;
  1484. if (target_proc) {
  1485. binder_inner_proc_lock(target_proc);
  1486. target_proc->outstanding_txns--;
  1487. if (target_proc->outstanding_txns < 0)
  1488. pr_warn("%s: Unexpected outstanding_txns %d\n",
  1489. __func__, target_proc->outstanding_txns);
  1490. if (!target_proc->outstanding_txns && target_proc->is_frozen)
  1491. wake_up_interruptible_all(&target_proc->freeze_wait);
  1492. if (t->buffer)
  1493. t->buffer->transaction = NULL;
  1494. binder_inner_proc_unlock(target_proc);
  1495. }
  1496. if (trace_binder_txn_latency_free_enabled())
  1497. binder_txn_latency_free(t);
  1498. /*
  1499. * If the transaction has no target_proc, then
  1500. * t->buffer->transaction has already been cleared.
  1501. */
  1502. binder_free_txn_fixups(t);
  1503. kfree(t);
  1504. binder_stats_deleted(BINDER_STAT_TRANSACTION);
  1505. }
  1506. static void binder_send_failed_reply(struct binder_transaction *t,
  1507. uint32_t error_code)
  1508. {
  1509. struct binder_thread *target_thread;
  1510. struct binder_transaction *next;
  1511. BUG_ON(t->flags & TF_ONE_WAY);
  1512. while (1) {
  1513. target_thread = binder_get_txn_from_and_acq_inner(t);
  1514. if (target_thread) {
  1515. binder_debug(BINDER_DEBUG_FAILED_TRANSACTION,
  1516. "send failed reply for transaction %d to %d:%d\n",
  1517. t->debug_id,
  1518. target_thread->proc->pid,
  1519. target_thread->pid);
  1520. binder_pop_transaction_ilocked(target_thread, t);
  1521. if (target_thread->reply_error.cmd == BR_OK) {
  1522. target_thread->reply_error.cmd = error_code;
  1523. binder_enqueue_thread_work_ilocked(
  1524. target_thread,
  1525. &target_thread->reply_error.work);
  1526. wake_up_interruptible(&target_thread->wait);
  1527. } else {
  1528. /*
  1529. * Cannot get here for normal operation, but
  1530. * we can if multiple synchronous transactions
  1531. * are sent without blocking for responses.
  1532. * Just ignore the 2nd error in this case.
  1533. */
  1534. pr_warn("Unexpected reply error: %u\n",
  1535. target_thread->reply_error.cmd);
  1536. }
  1537. binder_inner_proc_unlock(target_thread->proc);
  1538. binder_thread_dec_tmpref(target_thread);
  1539. binder_free_transaction(t);
  1540. return;
  1541. }
  1542. __release(&target_thread->proc->inner_lock);
  1543. next = t->from_parent;
  1544. binder_debug(BINDER_DEBUG_FAILED_TRANSACTION,
  1545. "send failed reply for transaction %d, target dead\n",
  1546. t->debug_id);
  1547. binder_free_transaction(t);
  1548. if (next == NULL) {
  1549. binder_debug(BINDER_DEBUG_DEAD_BINDER,
  1550. "reply failed, no target thread at root\n");
  1551. return;
  1552. }
  1553. t = next;
  1554. binder_debug(BINDER_DEBUG_DEAD_BINDER,
  1555. "reply failed, no target thread -- retry %d\n",
  1556. t->debug_id);
  1557. }
  1558. }
  1559. /**
  1560. * binder_cleanup_transaction() - cleans up undelivered transaction
  1561. * @t: transaction that needs to be cleaned up
  1562. * @reason: reason the transaction wasn't delivered
  1563. * @error_code: error to return to caller (if synchronous call)
  1564. */
  1565. static void binder_cleanup_transaction(struct binder_transaction *t,
  1566. const char *reason,
  1567. uint32_t error_code)
  1568. {
  1569. if (t->buffer->target_node && !(t->flags & TF_ONE_WAY)) {
  1570. binder_send_failed_reply(t, error_code);
  1571. } else {
  1572. binder_debug(BINDER_DEBUG_DEAD_TRANSACTION,
  1573. "undelivered transaction %d, %s\n",
  1574. t->debug_id, reason);
  1575. binder_free_transaction(t);
  1576. }
  1577. }
  1578. /**
  1579. * binder_get_object() - gets object and checks for valid metadata
  1580. * @proc: binder_proc owning the buffer
  1581. * @u: sender's user pointer to base of buffer
  1582. * @buffer: binder_buffer that we're parsing.
  1583. * @offset: offset in the @buffer at which to validate an object.
  1584. * @object: struct binder_object to read into
  1585. *
  1586. * Copy the binder object at the given offset into @object. If @u is
  1587. * provided then the copy is from the sender's buffer. If not, then
  1588. * it is copied from the target's @buffer.
  1589. *
  1590. * Return: If there's a valid metadata object at @offset, the
  1591. * size of that object. Otherwise, it returns zero. The object
  1592. * is read into the struct binder_object pointed to by @object.
  1593. */
  1594. static size_t binder_get_object(struct binder_proc *proc,
  1595. const void __user *u,
  1596. struct binder_buffer *buffer,
  1597. unsigned long offset,
  1598. struct binder_object *object)
  1599. {
  1600. size_t read_size;
  1601. struct binder_object_header *hdr;
  1602. size_t object_size = 0;
  1603. read_size = min_t(size_t, sizeof(*object), buffer->data_size - offset);
  1604. if (offset > buffer->data_size || read_size < sizeof(*hdr) ||
  1605. !IS_ALIGNED(offset, sizeof(u32)))
  1606. return 0;
  1607. if (u) {
  1608. if (copy_from_user(object, u + offset, read_size))
  1609. return 0;
  1610. } else {
  1611. if (binder_alloc_copy_from_buffer(&proc->alloc, object, buffer,
  1612. offset, read_size))
  1613. return 0;
  1614. }
  1615. /* Ok, now see if we read a complete object. */
  1616. hdr = &object->hdr;
  1617. switch (hdr->type) {
  1618. case BINDER_TYPE_BINDER:
  1619. case BINDER_TYPE_WEAK_BINDER:
  1620. case BINDER_TYPE_HANDLE:
  1621. case BINDER_TYPE_WEAK_HANDLE:
  1622. object_size = sizeof(struct flat_binder_object);
  1623. break;
  1624. case BINDER_TYPE_FD:
  1625. object_size = sizeof(struct binder_fd_object);
  1626. break;
  1627. case BINDER_TYPE_PTR:
  1628. object_size = sizeof(struct binder_buffer_object);
  1629. break;
  1630. case BINDER_TYPE_FDA:
  1631. object_size = sizeof(struct binder_fd_array_object);
  1632. break;
  1633. default:
  1634. return 0;
  1635. }
  1636. if (offset <= buffer->data_size - object_size &&
  1637. buffer->data_size >= object_size)
  1638. return object_size;
  1639. else
  1640. return 0;
  1641. }
  1642. /**
  1643. * binder_validate_ptr() - validates binder_buffer_object in a binder_buffer.
  1644. * @proc: binder_proc owning the buffer
  1645. * @b: binder_buffer containing the object
  1646. * @object: struct binder_object to read into
  1647. * @index: index in offset array at which the binder_buffer_object is
  1648. * located
  1649. * @start_offset: points to the start of the offset array
  1650. * @object_offsetp: offset of @object read from @b
  1651. * @num_valid: the number of valid offsets in the offset array
  1652. *
  1653. * Return: If @index is within the valid range of the offset array
  1654. * described by @start and @num_valid, and if there's a valid
  1655. * binder_buffer_object at the offset found in index @index
  1656. * of the offset array, that object is returned. Otherwise,
  1657. * %NULL is returned.
  1658. * Note that the offset found in index @index itself is not
  1659. * verified; this function assumes that @num_valid elements
  1660. * from @start were previously verified to have valid offsets.
  1661. * If @object_offsetp is non-NULL, then the offset within
  1662. * @b is written to it.
  1663. */
  1664. static struct binder_buffer_object *binder_validate_ptr(
  1665. struct binder_proc *proc,
  1666. struct binder_buffer *b,
  1667. struct binder_object *object,
  1668. binder_size_t index,
  1669. binder_size_t start_offset,
  1670. binder_size_t *object_offsetp,
  1671. binder_size_t num_valid)
  1672. {
  1673. size_t object_size;
  1674. binder_size_t object_offset;
  1675. unsigned long buffer_offset;
  1676. if (index >= num_valid)
  1677. return NULL;
  1678. buffer_offset = start_offset + sizeof(binder_size_t) * index;
  1679. if (binder_alloc_copy_from_buffer(&proc->alloc, &object_offset,
  1680. b, buffer_offset,
  1681. sizeof(object_offset)))
  1682. return NULL;
  1683. object_size = binder_get_object(proc, NULL, b, object_offset, object);
  1684. if (!object_size || object->hdr.type != BINDER_TYPE_PTR)
  1685. return NULL;
  1686. if (object_offsetp)
  1687. *object_offsetp = object_offset;
  1688. return &object->bbo;
  1689. }
  1690. /**
  1691. * binder_validate_fixup() - validates pointer/fd fixups happen in order.
  1692. * @proc: binder_proc owning the buffer
  1693. * @b: transaction buffer
  1694. * @objects_start_offset: offset to start of objects buffer
  1695. * @buffer_obj_offset: offset to binder_buffer_object in which to fix up
  1696. * @fixup_offset: start offset in @buffer to fix up
  1697. * @last_obj_offset: offset to last binder_buffer_object that we fixed
  1698. * @last_min_offset: minimum fixup offset in object at @last_obj_offset
  1699. *
  1700. * Return: %true if a fixup in buffer @buffer at offset @offset is
  1701. * allowed.
  1702. *
  1703. * For safety reasons, we only allow fixups inside a buffer to happen
  1704. * at increasing offsets; additionally, we only allow fixup on the last
  1705. * buffer object that was verified, or one of its parents.
  1706. *
  1707. * Example of what is allowed:
  1708. *
  1709. * A
  1710. * B (parent = A, offset = 0)
  1711. * C (parent = A, offset = 16)
  1712. * D (parent = C, offset = 0)
  1713. * E (parent = A, offset = 32) // min_offset is 16 (C.parent_offset)
  1714. *
  1715. * Examples of what is not allowed:
  1716. *
  1717. * Decreasing offsets within the same parent:
  1718. * A
  1719. * C (parent = A, offset = 16)
  1720. * B (parent = A, offset = 0) // decreasing offset within A
  1721. *
  1722. * Referring to a parent that wasn't the last object or any of its parents:
  1723. * A
  1724. * B (parent = A, offset = 0)
  1725. * C (parent = A, offset = 0)
  1726. * C (parent = A, offset = 16)
  1727. * D (parent = B, offset = 0) // B is not A or any of A's parents
  1728. */
  1729. static bool binder_validate_fixup(struct binder_proc *proc,
  1730. struct binder_buffer *b,
  1731. binder_size_t objects_start_offset,
  1732. binder_size_t buffer_obj_offset,
  1733. binder_size_t fixup_offset,
  1734. binder_size_t last_obj_offset,
  1735. binder_size_t last_min_offset)
  1736. {
  1737. if (!last_obj_offset) {
  1738. /* Nothing to fix up in */
  1739. return false;
  1740. }
  1741. while (last_obj_offset != buffer_obj_offset) {
  1742. unsigned long buffer_offset;
  1743. struct binder_object last_object;
  1744. struct binder_buffer_object *last_bbo;
  1745. size_t object_size = binder_get_object(proc, NULL, b,
  1746. last_obj_offset,
  1747. &last_object);
  1748. if (object_size != sizeof(*last_bbo))
  1749. return false;
  1750. last_bbo = &last_object.bbo;
  1751. /*
  1752. * Safe to retrieve the parent of last_obj, since it
  1753. * was already previously verified by the driver.
  1754. */
  1755. if ((last_bbo->flags & BINDER_BUFFER_FLAG_HAS_PARENT) == 0)
  1756. return false;
  1757. last_min_offset = last_bbo->parent_offset + sizeof(uintptr_t);
  1758. buffer_offset = objects_start_offset +
  1759. sizeof(binder_size_t) * last_bbo->parent;
  1760. if (binder_alloc_copy_from_buffer(&proc->alloc,
  1761. &last_obj_offset,
  1762. b, buffer_offset,
  1763. sizeof(last_obj_offset)))
  1764. return false;
  1765. }
  1766. return (fixup_offset >= last_min_offset);
  1767. }
  1768. /**
  1769. * struct binder_task_work_cb - for deferred close
  1770. *
  1771. * @twork: callback_head for task work
  1772. * @fd: fd to close
  1773. *
  1774. * Structure to pass task work to be handled after
  1775. * returning from binder_ioctl() via task_work_add().
  1776. */
  1777. struct binder_task_work_cb {
  1778. struct callback_head twork;
  1779. struct file *file;
  1780. };
  1781. /**
  1782. * binder_do_fd_close() - close list of file descriptors
  1783. * @twork: callback head for task work
  1784. *
  1785. * It is not safe to call ksys_close() during the binder_ioctl()
  1786. * function if there is a chance that binder's own file descriptor
  1787. * might be closed. This is to meet the requirements for using
  1788. * fdget() (see comments for __fget_light()). Therefore use
  1789. * task_work_add() to schedule the close operation once we have
  1790. * returned from binder_ioctl(). This function is a callback
  1791. * for that mechanism and does the actual ksys_close() on the
  1792. * given file descriptor.
  1793. */
  1794. static void binder_do_fd_close(struct callback_head *twork)
  1795. {
  1796. struct binder_task_work_cb *twcb = container_of(twork,
  1797. struct binder_task_work_cb, twork);
  1798. fput(twcb->file);
  1799. kfree(twcb);
  1800. }
  1801. /**
  1802. * binder_deferred_fd_close() - schedule a close for the given file-descriptor
  1803. * @fd: file-descriptor to close
  1804. *
  1805. * See comments in binder_do_fd_close(). This function is used to schedule
  1806. * a file-descriptor to be closed after returning from binder_ioctl().
  1807. */
  1808. static void binder_deferred_fd_close(int fd)
  1809. {
  1810. struct binder_task_work_cb *twcb;
  1811. twcb = kzalloc(sizeof(*twcb), GFP_KERNEL);
  1812. if (!twcb)
  1813. return;
  1814. init_task_work(&twcb->twork, binder_do_fd_close);
  1815. twcb->file = file_close_fd(fd);
  1816. if (twcb->file) {
  1817. // pin it until binder_do_fd_close(); see comments there
  1818. get_file(twcb->file);
  1819. filp_close(twcb->file, current->files);
  1820. task_work_add(current, &twcb->twork, TWA_RESUME);
  1821. } else {
  1822. kfree(twcb);
  1823. }
  1824. }
  1825. static void binder_transaction_buffer_release(struct binder_proc *proc,
  1826. struct binder_thread *thread,
  1827. struct binder_buffer *buffer,
  1828. binder_size_t off_end_offset,
  1829. bool is_failure)
  1830. {
  1831. int debug_id = buffer->debug_id;
  1832. binder_size_t off_start_offset, buffer_offset;
  1833. binder_debug(BINDER_DEBUG_TRANSACTION,
  1834. "%d buffer release %d, size %zd-%zd, failed at %llx\n",
  1835. proc->pid, buffer->debug_id,
  1836. buffer->data_size, buffer->offsets_size,
  1837. (unsigned long long)off_end_offset);
  1838. if (buffer->target_node)
  1839. binder_dec_node(buffer->target_node, 1, 0);
  1840. off_start_offset = ALIGN(buffer->data_size, sizeof(void *));
  1841. for (buffer_offset = off_start_offset; buffer_offset < off_end_offset;
  1842. buffer_offset += sizeof(binder_size_t)) {
  1843. struct binder_object_header *hdr;
  1844. size_t object_size = 0;
  1845. struct binder_object object;
  1846. binder_size_t object_offset;
  1847. if (!binder_alloc_copy_from_buffer(&proc->alloc, &object_offset,
  1848. buffer, buffer_offset,
  1849. sizeof(object_offset)))
  1850. object_size = binder_get_object(proc, NULL, buffer,
  1851. object_offset, &object);
  1852. if (object_size == 0) {
  1853. pr_err("transaction release %d bad object at offset %lld, size %zd\n",
  1854. debug_id, (u64)object_offset, buffer->data_size);
  1855. continue;
  1856. }
  1857. hdr = &object.hdr;
  1858. switch (hdr->type) {
  1859. case BINDER_TYPE_BINDER:
  1860. case BINDER_TYPE_WEAK_BINDER: {
  1861. struct flat_binder_object *fp;
  1862. struct binder_node *node;
  1863. fp = to_flat_binder_object(hdr);
  1864. node = binder_get_node(proc, fp->binder);
  1865. if (node == NULL) {
  1866. pr_err("transaction release %d bad node %016llx\n",
  1867. debug_id, (u64)fp->binder);
  1868. break;
  1869. }
  1870. binder_debug(BINDER_DEBUG_TRANSACTION,
  1871. " node %d u%016llx\n",
  1872. node->debug_id, (u64)node->ptr);
  1873. binder_dec_node(node, hdr->type == BINDER_TYPE_BINDER,
  1874. 0);
  1875. binder_put_node(node);
  1876. } break;
  1877. case BINDER_TYPE_HANDLE:
  1878. case BINDER_TYPE_WEAK_HANDLE: {
  1879. struct flat_binder_object *fp;
  1880. struct binder_ref_data rdata;
  1881. int ret;
  1882. fp = to_flat_binder_object(hdr);
  1883. ret = binder_dec_ref_for_handle(proc, fp->handle,
  1884. hdr->type == BINDER_TYPE_HANDLE, &rdata);
  1885. if (ret) {
  1886. pr_err("transaction release %d bad handle %d, ret = %d\n",
  1887. debug_id, fp->handle, ret);
  1888. break;
  1889. }
  1890. binder_debug(BINDER_DEBUG_TRANSACTION,
  1891. " ref %d desc %d\n",
  1892. rdata.debug_id, rdata.desc);
  1893. } break;
  1894. case BINDER_TYPE_FD: {
  1895. /*
  1896. * No need to close the file here since user-space
  1897. * closes it for successfully delivered
  1898. * transactions. For transactions that weren't
  1899. * delivered, the new fd was never allocated so
  1900. * there is no need to close and the fput on the
  1901. * file is done when the transaction is torn
  1902. * down.
  1903. */
  1904. } break;
  1905. case BINDER_TYPE_PTR:
  1906. /*
  1907. * Nothing to do here, this will get cleaned up when the
  1908. * transaction buffer gets freed
  1909. */
  1910. break;
  1911. case BINDER_TYPE_FDA: {
  1912. struct binder_fd_array_object *fda;
  1913. struct binder_buffer_object *parent;
  1914. struct binder_object ptr_object;
  1915. binder_size_t fda_offset;
  1916. size_t fd_index;
  1917. binder_size_t fd_buf_size;
  1918. binder_size_t num_valid;
  1919. if (is_failure) {
  1920. /*
  1921. * The fd fixups have not been applied so no
  1922. * fds need to be closed.
  1923. */
  1924. continue;
  1925. }
  1926. num_valid = (buffer_offset - off_start_offset) /
  1927. sizeof(binder_size_t);
  1928. fda = to_binder_fd_array_object(hdr);
  1929. parent = binder_validate_ptr(proc, buffer, &ptr_object,
  1930. fda->parent,
  1931. off_start_offset,
  1932. NULL,
  1933. num_valid);
  1934. if (!parent) {
  1935. pr_err("transaction release %d bad parent offset\n",
  1936. debug_id);
  1937. continue;
  1938. }
  1939. fd_buf_size = sizeof(u32) * fda->num_fds;
  1940. if (fda->num_fds >= SIZE_MAX / sizeof(u32)) {
  1941. pr_err("transaction release %d invalid number of fds (%lld)\n",
  1942. debug_id, (u64)fda->num_fds);
  1943. continue;
  1944. }
  1945. if (fd_buf_size > parent->length ||
  1946. fda->parent_offset > parent->length - fd_buf_size) {
  1947. /* No space for all file descriptors here. */
  1948. pr_err("transaction release %d not enough space for %lld fds in buffer\n",
  1949. debug_id, (u64)fda->num_fds);
  1950. continue;
  1951. }
  1952. /*
  1953. * the source data for binder_buffer_object is visible
  1954. * to user-space and the @buffer element is the user
  1955. * pointer to the buffer_object containing the fd_array.
  1956. * Convert the address to an offset relative to
  1957. * the base of the transaction buffer.
  1958. */
  1959. fda_offset = parent->buffer - buffer->user_data +
  1960. fda->parent_offset;
  1961. for (fd_index = 0; fd_index < fda->num_fds;
  1962. fd_index++) {
  1963. u32 fd;
  1964. int err;
  1965. binder_size_t offset = fda_offset +
  1966. fd_index * sizeof(fd);
  1967. err = binder_alloc_copy_from_buffer(
  1968. &proc->alloc, &fd, buffer,
  1969. offset, sizeof(fd));
  1970. WARN_ON(err);
  1971. if (!err) {
  1972. binder_deferred_fd_close(fd);
  1973. /*
  1974. * Need to make sure the thread goes
  1975. * back to userspace to complete the
  1976. * deferred close
  1977. */
  1978. if (thread)
  1979. thread->looper_need_return = true;
  1980. }
  1981. }
  1982. } break;
  1983. default:
  1984. pr_err("transaction release %d bad object type %x\n",
  1985. debug_id, hdr->type);
  1986. break;
  1987. }
  1988. }
  1989. }
  1990. /* Clean up all the objects in the buffer */
  1991. static inline void binder_release_entire_buffer(struct binder_proc *proc,
  1992. struct binder_thread *thread,
  1993. struct binder_buffer *buffer,
  1994. bool is_failure)
  1995. {
  1996. binder_size_t off_end_offset;
  1997. off_end_offset = ALIGN(buffer->data_size, sizeof(void *));
  1998. off_end_offset += buffer->offsets_size;
  1999. binder_transaction_buffer_release(proc, thread, buffer,
  2000. off_end_offset, is_failure);
  2001. }
  2002. static int binder_translate_binder(struct flat_binder_object *fp,
  2003. struct binder_transaction *t,
  2004. struct binder_thread *thread)
  2005. {
  2006. struct binder_node *node;
  2007. struct binder_proc *proc = thread->proc;
  2008. struct binder_proc *target_proc = t->to_proc;
  2009. struct binder_ref_data rdata;
  2010. int ret = 0;
  2011. node = binder_get_node(proc, fp->binder);
  2012. if (!node) {
  2013. node = binder_new_node(proc, fp);
  2014. if (!node)
  2015. return -ENOMEM;
  2016. }
  2017. if (fp->cookie != node->cookie) {
  2018. binder_user_error("%d:%d sending u%016llx node %d, cookie mismatch %016llx != %016llx\n",
  2019. proc->pid, thread->pid, (u64)fp->binder,
  2020. node->debug_id, (u64)fp->cookie,
  2021. (u64)node->cookie);
  2022. ret = -EINVAL;
  2023. goto done;
  2024. }
  2025. if (security_binder_transfer_binder(proc->cred, target_proc->cred)) {
  2026. ret = -EPERM;
  2027. goto done;
  2028. }
  2029. ret = binder_inc_ref_for_node(target_proc, node,
  2030. fp->hdr.type == BINDER_TYPE_BINDER,
  2031. &thread->todo, &rdata);
  2032. if (ret)
  2033. goto done;
  2034. if (fp->hdr.type == BINDER_TYPE_BINDER)
  2035. fp->hdr.type = BINDER_TYPE_HANDLE;
  2036. else
  2037. fp->hdr.type = BINDER_TYPE_WEAK_HANDLE;
  2038. fp->binder = 0;
  2039. fp->handle = rdata.desc;
  2040. fp->cookie = 0;
  2041. trace_binder_transaction_node_to_ref(t, node, &rdata);
  2042. binder_debug(BINDER_DEBUG_TRANSACTION,
  2043. " node %d u%016llx -> ref %d desc %d\n",
  2044. node->debug_id, (u64)node->ptr,
  2045. rdata.debug_id, rdata.desc);
  2046. done:
  2047. binder_put_node(node);
  2048. return ret;
  2049. }
  2050. static int binder_translate_handle(struct flat_binder_object *fp,
  2051. struct binder_transaction *t,
  2052. struct binder_thread *thread)
  2053. {
  2054. struct binder_proc *proc = thread->proc;
  2055. struct binder_proc *target_proc = t->to_proc;
  2056. struct binder_node *node;
  2057. struct binder_ref_data src_rdata;
  2058. int ret = 0;
  2059. node = binder_get_node_from_ref(proc, fp->handle,
  2060. fp->hdr.type == BINDER_TYPE_HANDLE, &src_rdata);
  2061. if (!node) {
  2062. binder_user_error("%d:%d got transaction with invalid handle, %d\n",
  2063. proc->pid, thread->pid, fp->handle);
  2064. return -EINVAL;
  2065. }
  2066. if (security_binder_transfer_binder(proc->cred, target_proc->cred)) {
  2067. ret = -EPERM;
  2068. goto done;
  2069. }
  2070. binder_node_lock(node);
  2071. if (node->proc == target_proc) {
  2072. if (fp->hdr.type == BINDER_TYPE_HANDLE)
  2073. fp->hdr.type = BINDER_TYPE_BINDER;
  2074. else
  2075. fp->hdr.type = BINDER_TYPE_WEAK_BINDER;
  2076. fp->binder = node->ptr;
  2077. fp->cookie = node->cookie;
  2078. if (node->proc)
  2079. binder_inner_proc_lock(node->proc);
  2080. else
  2081. __acquire(&node->proc->inner_lock);
  2082. binder_inc_node_nilocked(node,
  2083. fp->hdr.type == BINDER_TYPE_BINDER,
  2084. 0, NULL);
  2085. if (node->proc)
  2086. binder_inner_proc_unlock(node->proc);
  2087. else
  2088. __release(&node->proc->inner_lock);
  2089. trace_binder_transaction_ref_to_node(t, node, &src_rdata);
  2090. binder_debug(BINDER_DEBUG_TRANSACTION,
  2091. " ref %d desc %d -> node %d u%016llx\n",
  2092. src_rdata.debug_id, src_rdata.desc, node->debug_id,
  2093. (u64)node->ptr);
  2094. binder_node_unlock(node);
  2095. } else {
  2096. struct binder_ref_data dest_rdata;
  2097. binder_node_unlock(node);
  2098. ret = binder_inc_ref_for_node(target_proc, node,
  2099. fp->hdr.type == BINDER_TYPE_HANDLE,
  2100. NULL, &dest_rdata);
  2101. if (ret)
  2102. goto done;
  2103. fp->binder = 0;
  2104. fp->handle = dest_rdata.desc;
  2105. fp->cookie = 0;
  2106. trace_binder_transaction_ref_to_ref(t, node, &src_rdata,
  2107. &dest_rdata);
  2108. binder_debug(BINDER_DEBUG_TRANSACTION,
  2109. " ref %d desc %d -> ref %d desc %d (node %d)\n",
  2110. src_rdata.debug_id, src_rdata.desc,
  2111. dest_rdata.debug_id, dest_rdata.desc,
  2112. node->debug_id);
  2113. }
  2114. done:
  2115. binder_put_node(node);
  2116. return ret;
  2117. }
  2118. static int binder_translate_fd(u32 fd, binder_size_t fd_offset,
  2119. struct binder_transaction *t,
  2120. struct binder_thread *thread,
  2121. struct binder_transaction *in_reply_to)
  2122. {
  2123. struct binder_proc *proc = thread->proc;
  2124. struct binder_proc *target_proc = t->to_proc;
  2125. struct binder_txn_fd_fixup *fixup;
  2126. struct file *file;
  2127. int ret = 0;
  2128. bool target_allows_fd;
  2129. if (in_reply_to)
  2130. target_allows_fd = !!(in_reply_to->flags & TF_ACCEPT_FDS);
  2131. else
  2132. target_allows_fd = t->buffer->target_node->accept_fds;
  2133. if (!target_allows_fd) {
  2134. binder_user_error("%d:%d got %s with fd, %d, but target does not allow fds\n",
  2135. proc->pid, thread->pid,
  2136. in_reply_to ? "reply" : "transaction",
  2137. fd);
  2138. ret = -EPERM;
  2139. goto err_fd_not_accepted;
  2140. }
  2141. file = fget(fd);
  2142. if (!file) {
  2143. binder_user_error("%d:%d got transaction with invalid fd, %d\n",
  2144. proc->pid, thread->pid, fd);
  2145. ret = -EBADF;
  2146. goto err_fget;
  2147. }
  2148. ret = security_binder_transfer_file(proc->cred, target_proc->cred, file);
  2149. if (ret < 0) {
  2150. ret = -EPERM;
  2151. goto err_security;
  2152. }
  2153. /*
  2154. * Add fixup record for this transaction. The allocation
  2155. * of the fd in the target needs to be done from a
  2156. * target thread.
  2157. */
  2158. fixup = kzalloc(sizeof(*fixup), GFP_KERNEL);
  2159. if (!fixup) {
  2160. ret = -ENOMEM;
  2161. goto err_alloc;
  2162. }
  2163. fixup->file = file;
  2164. fixup->offset = fd_offset;
  2165. fixup->target_fd = -1;
  2166. trace_binder_transaction_fd_send(t, fd, fixup->offset);
  2167. list_add_tail(&fixup->fixup_entry, &t->fd_fixups);
  2168. return ret;
  2169. err_alloc:
  2170. err_security:
  2171. fput(file);
  2172. err_fget:
  2173. err_fd_not_accepted:
  2174. return ret;
  2175. }
  2176. /**
  2177. * struct binder_ptr_fixup - data to be fixed-up in target buffer
  2178. * @offset offset in target buffer to fixup
  2179. * @skip_size bytes to skip in copy (fixup will be written later)
  2180. * @fixup_data data to write at fixup offset
  2181. * @node list node
  2182. *
  2183. * This is used for the pointer fixup list (pf) which is created and consumed
  2184. * during binder_transaction() and is only accessed locally. No
  2185. * locking is necessary.
  2186. *
  2187. * The list is ordered by @offset.
  2188. */
  2189. struct binder_ptr_fixup {
  2190. binder_size_t offset;
  2191. size_t skip_size;
  2192. binder_uintptr_t fixup_data;
  2193. struct list_head node;
  2194. };
  2195. /**
  2196. * struct binder_sg_copy - scatter-gather data to be copied
  2197. * @offset offset in target buffer
  2198. * @sender_uaddr user address in source buffer
  2199. * @length bytes to copy
  2200. * @node list node
  2201. *
  2202. * This is used for the sg copy list (sgc) which is created and consumed
  2203. * during binder_transaction() and is only accessed locally. No
  2204. * locking is necessary.
  2205. *
  2206. * The list is ordered by @offset.
  2207. */
  2208. struct binder_sg_copy {
  2209. binder_size_t offset;
  2210. const void __user *sender_uaddr;
  2211. size_t length;
  2212. struct list_head node;
  2213. };
  2214. /**
  2215. * binder_do_deferred_txn_copies() - copy and fixup scatter-gather data
  2216. * @alloc: binder_alloc associated with @buffer
  2217. * @buffer: binder buffer in target process
  2218. * @sgc_head: list_head of scatter-gather copy list
  2219. * @pf_head: list_head of pointer fixup list
  2220. *
  2221. * Processes all elements of @sgc_head, applying fixups from @pf_head
  2222. * and copying the scatter-gather data from the source process' user
  2223. * buffer to the target's buffer. It is expected that the list creation
  2224. * and processing all occurs during binder_transaction() so these lists
  2225. * are only accessed in local context.
  2226. *
  2227. * Return: 0=success, else -errno
  2228. */
  2229. static int binder_do_deferred_txn_copies(struct binder_alloc *alloc,
  2230. struct binder_buffer *buffer,
  2231. struct list_head *sgc_head,
  2232. struct list_head *pf_head)
  2233. {
  2234. int ret = 0;
  2235. struct binder_sg_copy *sgc, *tmpsgc;
  2236. struct binder_ptr_fixup *tmppf;
  2237. struct binder_ptr_fixup *pf =
  2238. list_first_entry_or_null(pf_head, struct binder_ptr_fixup,
  2239. node);
  2240. list_for_each_entry_safe(sgc, tmpsgc, sgc_head, node) {
  2241. size_t bytes_copied = 0;
  2242. while (bytes_copied < sgc->length) {
  2243. size_t copy_size;
  2244. size_t bytes_left = sgc->length - bytes_copied;
  2245. size_t offset = sgc->offset + bytes_copied;
  2246. /*
  2247. * We copy up to the fixup (pointed to by pf)
  2248. */
  2249. copy_size = pf ? min(bytes_left, (size_t)pf->offset - offset)
  2250. : bytes_left;
  2251. if (!ret && copy_size)
  2252. ret = binder_alloc_copy_user_to_buffer(
  2253. alloc, buffer,
  2254. offset,
  2255. sgc->sender_uaddr + bytes_copied,
  2256. copy_size);
  2257. bytes_copied += copy_size;
  2258. if (copy_size != bytes_left) {
  2259. BUG_ON(!pf);
  2260. /* we stopped at a fixup offset */
  2261. if (pf->skip_size) {
  2262. /*
  2263. * we are just skipping. This is for
  2264. * BINDER_TYPE_FDA where the translated
  2265. * fds will be fixed up when we get
  2266. * to target context.
  2267. */
  2268. bytes_copied += pf->skip_size;
  2269. } else {
  2270. /* apply the fixup indicated by pf */
  2271. if (!ret)
  2272. ret = binder_alloc_copy_to_buffer(
  2273. alloc, buffer,
  2274. pf->offset,
  2275. &pf->fixup_data,
  2276. sizeof(pf->fixup_data));
  2277. bytes_copied += sizeof(pf->fixup_data);
  2278. }
  2279. list_del(&pf->node);
  2280. kfree(pf);
  2281. pf = list_first_entry_or_null(pf_head,
  2282. struct binder_ptr_fixup, node);
  2283. }
  2284. }
  2285. list_del(&sgc->node);
  2286. kfree(sgc);
  2287. }
  2288. list_for_each_entry_safe(pf, tmppf, pf_head, node) {
  2289. BUG_ON(pf->skip_size == 0);
  2290. list_del(&pf->node);
  2291. kfree(pf);
  2292. }
  2293. BUG_ON(!list_empty(sgc_head));
  2294. return ret > 0 ? -EINVAL : ret;
  2295. }
  2296. /**
  2297. * binder_cleanup_deferred_txn_lists() - free specified lists
  2298. * @sgc_head: list_head of scatter-gather copy list
  2299. * @pf_head: list_head of pointer fixup list
  2300. *
  2301. * Called to clean up @sgc_head and @pf_head if there is an
  2302. * error.
  2303. */
  2304. static void binder_cleanup_deferred_txn_lists(struct list_head *sgc_head,
  2305. struct list_head *pf_head)
  2306. {
  2307. struct binder_sg_copy *sgc, *tmpsgc;
  2308. struct binder_ptr_fixup *pf, *tmppf;
  2309. list_for_each_entry_safe(sgc, tmpsgc, sgc_head, node) {
  2310. list_del(&sgc->node);
  2311. kfree(sgc);
  2312. }
  2313. list_for_each_entry_safe(pf, tmppf, pf_head, node) {
  2314. list_del(&pf->node);
  2315. kfree(pf);
  2316. }
  2317. }
  2318. /**
  2319. * binder_defer_copy() - queue a scatter-gather buffer for copy
  2320. * @sgc_head: list_head of scatter-gather copy list
  2321. * @offset: binder buffer offset in target process
  2322. * @sender_uaddr: user address in source process
  2323. * @length: bytes to copy
  2324. *
  2325. * Specify a scatter-gather block to be copied. The actual copy must
  2326. * be deferred until all the needed fixups are identified and queued.
  2327. * Then the copy and fixups are done together so un-translated values
  2328. * from the source are never visible in the target buffer.
  2329. *
  2330. * We are guaranteed that repeated calls to this function will have
  2331. * monotonically increasing @offset values so the list will naturally
  2332. * be ordered.
  2333. *
  2334. * Return: 0=success, else -errno
  2335. */
  2336. static int binder_defer_copy(struct list_head *sgc_head, binder_size_t offset,
  2337. const void __user *sender_uaddr, size_t length)
  2338. {
  2339. struct binder_sg_copy *bc = kzalloc(sizeof(*bc), GFP_KERNEL);
  2340. if (!bc)
  2341. return -ENOMEM;
  2342. bc->offset = offset;
  2343. bc->sender_uaddr = sender_uaddr;
  2344. bc->length = length;
  2345. INIT_LIST_HEAD(&bc->node);
  2346. /*
  2347. * We are guaranteed that the deferred copies are in-order
  2348. * so just add to the tail.
  2349. */
  2350. list_add_tail(&bc->node, sgc_head);
  2351. return 0;
  2352. }
  2353. /**
  2354. * binder_add_fixup() - queue a fixup to be applied to sg copy
  2355. * @pf_head: list_head of binder ptr fixup list
  2356. * @offset: binder buffer offset in target process
  2357. * @fixup: bytes to be copied for fixup
  2358. * @skip_size: bytes to skip when copying (fixup will be applied later)
  2359. *
  2360. * Add the specified fixup to a list ordered by @offset. When copying
  2361. * the scatter-gather buffers, the fixup will be copied instead of
  2362. * data from the source buffer. For BINDER_TYPE_FDA fixups, the fixup
  2363. * will be applied later (in target process context), so we just skip
  2364. * the bytes specified by @skip_size. If @skip_size is 0, we copy the
  2365. * value in @fixup.
  2366. *
  2367. * This function is called *mostly* in @offset order, but there are
  2368. * exceptions. Since out-of-order inserts are relatively uncommon,
  2369. * we insert the new element by searching backward from the tail of
  2370. * the list.
  2371. *
  2372. * Return: 0=success, else -errno
  2373. */
  2374. static int binder_add_fixup(struct list_head *pf_head, binder_size_t offset,
  2375. binder_uintptr_t fixup, size_t skip_size)
  2376. {
  2377. struct binder_ptr_fixup *pf = kzalloc(sizeof(*pf), GFP_KERNEL);
  2378. struct binder_ptr_fixup *tmppf;
  2379. if (!pf)
  2380. return -ENOMEM;
  2381. pf->offset = offset;
  2382. pf->fixup_data = fixup;
  2383. pf->skip_size = skip_size;
  2384. INIT_LIST_HEAD(&pf->node);
  2385. /* Fixups are *mostly* added in-order, but there are some
  2386. * exceptions. Look backwards through list for insertion point.
  2387. */
  2388. list_for_each_entry_reverse(tmppf, pf_head, node) {
  2389. if (tmppf->offset < pf->offset) {
  2390. list_add(&pf->node, &tmppf->node);
  2391. return 0;
  2392. }
  2393. }
  2394. /*
  2395. * if we get here, then the new offset is the lowest so
  2396. * insert at the head
  2397. */
  2398. list_add(&pf->node, pf_head);
  2399. return 0;
  2400. }
  2401. static int binder_translate_fd_array(struct list_head *pf_head,
  2402. struct binder_fd_array_object *fda,
  2403. const void __user *sender_ubuffer,
  2404. struct binder_buffer_object *parent,
  2405. struct binder_buffer_object *sender_uparent,
  2406. struct binder_transaction *t,
  2407. struct binder_thread *thread,
  2408. struct binder_transaction *in_reply_to)
  2409. {
  2410. binder_size_t fdi, fd_buf_size;
  2411. binder_size_t fda_offset;
  2412. const void __user *sender_ufda_base;
  2413. struct binder_proc *proc = thread->proc;
  2414. int ret;
  2415. if (fda->num_fds == 0)
  2416. return 0;
  2417. fd_buf_size = sizeof(u32) * fda->num_fds;
  2418. if (fda->num_fds >= SIZE_MAX / sizeof(u32)) {
  2419. binder_user_error("%d:%d got transaction with invalid number of fds (%lld)\n",
  2420. proc->pid, thread->pid, (u64)fda->num_fds);
  2421. return -EINVAL;
  2422. }
  2423. if (fd_buf_size > parent->length ||
  2424. fda->parent_offset > parent->length - fd_buf_size) {
  2425. /* No space for all file descriptors here. */
  2426. binder_user_error("%d:%d not enough space to store %lld fds in buffer\n",
  2427. proc->pid, thread->pid, (u64)fda->num_fds);
  2428. return -EINVAL;
  2429. }
  2430. /*
  2431. * the source data for binder_buffer_object is visible
  2432. * to user-space and the @buffer element is the user
  2433. * pointer to the buffer_object containing the fd_array.
  2434. * Convert the address to an offset relative to
  2435. * the base of the transaction buffer.
  2436. */
  2437. fda_offset = parent->buffer - t->buffer->user_data +
  2438. fda->parent_offset;
  2439. sender_ufda_base = (void __user *)(uintptr_t)sender_uparent->buffer +
  2440. fda->parent_offset;
  2441. if (!IS_ALIGNED((unsigned long)fda_offset, sizeof(u32)) ||
  2442. !IS_ALIGNED((unsigned long)sender_ufda_base, sizeof(u32))) {
  2443. binder_user_error("%d:%d parent offset not aligned correctly.\n",
  2444. proc->pid, thread->pid);
  2445. return -EINVAL;
  2446. }
  2447. ret = binder_add_fixup(pf_head, fda_offset, 0, fda->num_fds * sizeof(u32));
  2448. if (ret)
  2449. return ret;
  2450. for (fdi = 0; fdi < fda->num_fds; fdi++) {
  2451. u32 fd;
  2452. binder_size_t offset = fda_offset + fdi * sizeof(fd);
  2453. binder_size_t sender_uoffset = fdi * sizeof(fd);
  2454. ret = copy_from_user(&fd, sender_ufda_base + sender_uoffset, sizeof(fd));
  2455. if (!ret)
  2456. ret = binder_translate_fd(fd, offset, t, thread,
  2457. in_reply_to);
  2458. if (ret)
  2459. return ret > 0 ? -EINVAL : ret;
  2460. }
  2461. return 0;
  2462. }
  2463. static int binder_fixup_parent(struct list_head *pf_head,
  2464. struct binder_transaction *t,
  2465. struct binder_thread *thread,
  2466. struct binder_buffer_object *bp,
  2467. binder_size_t off_start_offset,
  2468. binder_size_t num_valid,
  2469. binder_size_t last_fixup_obj_off,
  2470. binder_size_t last_fixup_min_off)
  2471. {
  2472. struct binder_buffer_object *parent;
  2473. struct binder_buffer *b = t->buffer;
  2474. struct binder_proc *proc = thread->proc;
  2475. struct binder_proc *target_proc = t->to_proc;
  2476. struct binder_object object;
  2477. binder_size_t buffer_offset;
  2478. binder_size_t parent_offset;
  2479. if (!(bp->flags & BINDER_BUFFER_FLAG_HAS_PARENT))
  2480. return 0;
  2481. parent = binder_validate_ptr(target_proc, b, &object, bp->parent,
  2482. off_start_offset, &parent_offset,
  2483. num_valid);
  2484. if (!parent) {
  2485. binder_user_error("%d:%d got transaction with invalid parent offset or type\n",
  2486. proc->pid, thread->pid);
  2487. return -EINVAL;
  2488. }
  2489. if (!binder_validate_fixup(target_proc, b, off_start_offset,
  2490. parent_offset, bp->parent_offset,
  2491. last_fixup_obj_off,
  2492. last_fixup_min_off)) {
  2493. binder_user_error("%d:%d got transaction with out-of-order buffer fixup\n",
  2494. proc->pid, thread->pid);
  2495. return -EINVAL;
  2496. }
  2497. if (parent->length < sizeof(binder_uintptr_t) ||
  2498. bp->parent_offset > parent->length - sizeof(binder_uintptr_t)) {
  2499. /* No space for a pointer here! */
  2500. binder_user_error("%d:%d got transaction with invalid parent offset\n",
  2501. proc->pid, thread->pid);
  2502. return -EINVAL;
  2503. }
  2504. buffer_offset = bp->parent_offset + parent->buffer - b->user_data;
  2505. return binder_add_fixup(pf_head, buffer_offset, bp->buffer, 0);
  2506. }
  2507. /**
  2508. * binder_can_update_transaction() - Can a txn be superseded by an updated one?
  2509. * @t1: the pending async txn in the frozen process
  2510. * @t2: the new async txn to supersede the outdated pending one
  2511. *
  2512. * Return: true if t2 can supersede t1
  2513. * false if t2 can not supersede t1
  2514. */
  2515. static bool binder_can_update_transaction(struct binder_transaction *t1,
  2516. struct binder_transaction *t2)
  2517. {
  2518. if ((t1->flags & t2->flags & (TF_ONE_WAY | TF_UPDATE_TXN)) !=
  2519. (TF_ONE_WAY | TF_UPDATE_TXN) || !t1->to_proc || !t2->to_proc)
  2520. return false;
  2521. if (t1->to_proc->tsk == t2->to_proc->tsk && t1->code == t2->code &&
  2522. t1->flags == t2->flags && t1->buffer->pid == t2->buffer->pid &&
  2523. t1->buffer->target_node->ptr == t2->buffer->target_node->ptr &&
  2524. t1->buffer->target_node->cookie == t2->buffer->target_node->cookie)
  2525. return true;
  2526. return false;
  2527. }
  2528. /**
  2529. * binder_find_outdated_transaction_ilocked() - Find the outdated transaction
  2530. * @t: new async transaction
  2531. * @target_list: list to find outdated transaction
  2532. *
  2533. * Return: the outdated transaction if found
  2534. * NULL if no outdated transacton can be found
  2535. *
  2536. * Requires the proc->inner_lock to be held.
  2537. */
  2538. static struct binder_transaction *
  2539. binder_find_outdated_transaction_ilocked(struct binder_transaction *t,
  2540. struct list_head *target_list)
  2541. {
  2542. struct binder_work *w;
  2543. list_for_each_entry(w, target_list, entry) {
  2544. struct binder_transaction *t_queued;
  2545. if (w->type != BINDER_WORK_TRANSACTION)
  2546. continue;
  2547. t_queued = container_of(w, struct binder_transaction, work);
  2548. if (binder_can_update_transaction(t_queued, t))
  2549. return t_queued;
  2550. }
  2551. return NULL;
  2552. }
  2553. /**
  2554. * binder_proc_transaction() - sends a transaction to a process and wakes it up
  2555. * @t: transaction to send
  2556. * @proc: process to send the transaction to
  2557. * @thread: thread in @proc to send the transaction to (may be NULL)
  2558. *
  2559. * This function queues a transaction to the specified process. It will try
  2560. * to find a thread in the target process to handle the transaction and
  2561. * wake it up. If no thread is found, the work is queued to the proc
  2562. * waitqueue.
  2563. *
  2564. * If the @thread parameter is not NULL, the transaction is always queued
  2565. * to the waitlist of that specific thread.
  2566. *
  2567. * Return: 0 if the transaction was successfully queued
  2568. * BR_DEAD_REPLY if the target process or thread is dead
  2569. * BR_FROZEN_REPLY if the target process or thread is frozen and
  2570. * the sync transaction was rejected
  2571. * BR_TRANSACTION_PENDING_FROZEN if the target process is frozen
  2572. * and the async transaction was successfully queued
  2573. */
  2574. static int binder_proc_transaction(struct binder_transaction *t,
  2575. struct binder_proc *proc,
  2576. struct binder_thread *thread)
  2577. {
  2578. struct binder_node *node = t->buffer->target_node;
  2579. bool oneway = !!(t->flags & TF_ONE_WAY);
  2580. bool pending_async = false;
  2581. struct binder_transaction *t_outdated = NULL;
  2582. bool frozen = false;
  2583. BUG_ON(!node);
  2584. binder_node_lock(node);
  2585. if (oneway) {
  2586. BUG_ON(thread);
  2587. if (node->has_async_transaction)
  2588. pending_async = true;
  2589. else
  2590. node->has_async_transaction = true;
  2591. }
  2592. binder_inner_proc_lock(proc);
  2593. if (proc->is_frozen) {
  2594. frozen = true;
  2595. proc->sync_recv |= !oneway;
  2596. proc->async_recv |= oneway;
  2597. }
  2598. if ((frozen && !oneway) || proc->is_dead ||
  2599. (thread && thread->is_dead)) {
  2600. binder_inner_proc_unlock(proc);
  2601. binder_node_unlock(node);
  2602. return frozen ? BR_FROZEN_REPLY : BR_DEAD_REPLY;
  2603. }
  2604. if (!thread && !pending_async)
  2605. thread = binder_select_thread_ilocked(proc);
  2606. if (thread) {
  2607. binder_enqueue_thread_work_ilocked(thread, &t->work);
  2608. } else if (!pending_async) {
  2609. binder_enqueue_work_ilocked(&t->work, &proc->todo);
  2610. } else {
  2611. if ((t->flags & TF_UPDATE_TXN) && frozen) {
  2612. t_outdated = binder_find_outdated_transaction_ilocked(t,
  2613. &node->async_todo);
  2614. if (t_outdated) {
  2615. binder_debug(BINDER_DEBUG_TRANSACTION,
  2616. "txn %d supersedes %d\n",
  2617. t->debug_id, t_outdated->debug_id);
  2618. list_del_init(&t_outdated->work.entry);
  2619. proc->outstanding_txns--;
  2620. }
  2621. }
  2622. binder_enqueue_work_ilocked(&t->work, &node->async_todo);
  2623. }
  2624. if (!pending_async)
  2625. binder_wakeup_thread_ilocked(proc, thread, !oneway /* sync */);
  2626. proc->outstanding_txns++;
  2627. binder_inner_proc_unlock(proc);
  2628. binder_node_unlock(node);
  2629. /*
  2630. * To reduce potential contention, free the outdated transaction and
  2631. * buffer after releasing the locks.
  2632. */
  2633. if (t_outdated) {
  2634. struct binder_buffer *buffer = t_outdated->buffer;
  2635. t_outdated->buffer = NULL;
  2636. buffer->transaction = NULL;
  2637. trace_binder_transaction_update_buffer_release(buffer);
  2638. binder_release_entire_buffer(proc, NULL, buffer, false);
  2639. binder_alloc_free_buf(&proc->alloc, buffer);
  2640. kfree(t_outdated);
  2641. binder_stats_deleted(BINDER_STAT_TRANSACTION);
  2642. }
  2643. if (oneway && frozen)
  2644. return BR_TRANSACTION_PENDING_FROZEN;
  2645. return 0;
  2646. }
  2647. /**
  2648. * binder_get_node_refs_for_txn() - Get required refs on node for txn
  2649. * @node: struct binder_node for which to get refs
  2650. * @procp: returns @node->proc if valid
  2651. * @error: if no @procp then returns BR_DEAD_REPLY
  2652. *
  2653. * User-space normally keeps the node alive when creating a transaction
  2654. * since it has a reference to the target. The local strong ref keeps it
  2655. * alive if the sending process dies before the target process processes
  2656. * the transaction. If the source process is malicious or has a reference
  2657. * counting bug, relying on the local strong ref can fail.
  2658. *
  2659. * Since user-space can cause the local strong ref to go away, we also take
  2660. * a tmpref on the node to ensure it survives while we are constructing
  2661. * the transaction. We also need a tmpref on the proc while we are
  2662. * constructing the transaction, so we take that here as well.
  2663. *
  2664. * Return: The target_node with refs taken or NULL if no @node->proc is NULL.
  2665. * Also sets @procp if valid. If the @node->proc is NULL indicating that the
  2666. * target proc has died, @error is set to BR_DEAD_REPLY.
  2667. */
  2668. static struct binder_node *binder_get_node_refs_for_txn(
  2669. struct binder_node *node,
  2670. struct binder_proc **procp,
  2671. uint32_t *error)
  2672. {
  2673. struct binder_node *target_node = NULL;
  2674. binder_node_inner_lock(node);
  2675. if (node->proc) {
  2676. target_node = node;
  2677. binder_inc_node_nilocked(node, 1, 0, NULL);
  2678. binder_inc_node_tmpref_ilocked(node);
  2679. node->proc->tmp_ref++;
  2680. *procp = node->proc;
  2681. } else
  2682. *error = BR_DEAD_REPLY;
  2683. binder_node_inner_unlock(node);
  2684. return target_node;
  2685. }
  2686. static void binder_set_txn_from_error(struct binder_transaction *t, int id,
  2687. uint32_t command, int32_t param)
  2688. {
  2689. struct binder_thread *from = binder_get_txn_from_and_acq_inner(t);
  2690. if (!from) {
  2691. /* annotation for sparse */
  2692. __release(&from->proc->inner_lock);
  2693. return;
  2694. }
  2695. /* don't override existing errors */
  2696. if (from->ee.command == BR_OK)
  2697. binder_set_extended_error(&from->ee, id, command, param);
  2698. binder_inner_proc_unlock(from->proc);
  2699. binder_thread_dec_tmpref(from);
  2700. }
  2701. static void binder_transaction(struct binder_proc *proc,
  2702. struct binder_thread *thread,
  2703. struct binder_transaction_data *tr, int reply,
  2704. binder_size_t extra_buffers_size)
  2705. {
  2706. int ret;
  2707. struct binder_transaction *t;
  2708. struct binder_work *w;
  2709. struct binder_work *tcomplete;
  2710. binder_size_t buffer_offset = 0;
  2711. binder_size_t off_start_offset, off_end_offset;
  2712. binder_size_t off_min;
  2713. binder_size_t sg_buf_offset, sg_buf_end_offset;
  2714. binder_size_t user_offset = 0;
  2715. struct binder_proc *target_proc = NULL;
  2716. struct binder_thread *target_thread = NULL;
  2717. struct binder_node *target_node = NULL;
  2718. struct binder_transaction *in_reply_to = NULL;
  2719. struct binder_transaction_log_entry *e;
  2720. uint32_t return_error = 0;
  2721. uint32_t return_error_param = 0;
  2722. uint32_t return_error_line = 0;
  2723. binder_size_t last_fixup_obj_off = 0;
  2724. binder_size_t last_fixup_min_off = 0;
  2725. struct binder_context *context = proc->context;
  2726. int t_debug_id = atomic_inc_return(&binder_last_id);
  2727. ktime_t t_start_time = ktime_get();
  2728. char *secctx = NULL;
  2729. u32 secctx_sz = 0;
  2730. struct list_head sgc_head;
  2731. struct list_head pf_head;
  2732. const void __user *user_buffer = (const void __user *)
  2733. (uintptr_t)tr->data.ptr.buffer;
  2734. INIT_LIST_HEAD(&sgc_head);
  2735. INIT_LIST_HEAD(&pf_head);
  2736. e = binder_transaction_log_add(&binder_transaction_log);
  2737. e->debug_id = t_debug_id;
  2738. e->call_type = reply ? 2 : !!(tr->flags & TF_ONE_WAY);
  2739. e->from_proc = proc->pid;
  2740. e->from_thread = thread->pid;
  2741. e->target_handle = tr->target.handle;
  2742. e->data_size = tr->data_size;
  2743. e->offsets_size = tr->offsets_size;
  2744. strscpy(e->context_name, proc->context->name, BINDERFS_MAX_NAME);
  2745. binder_inner_proc_lock(proc);
  2746. binder_set_extended_error(&thread->ee, t_debug_id, BR_OK, 0);
  2747. binder_inner_proc_unlock(proc);
  2748. if (reply) {
  2749. binder_inner_proc_lock(proc);
  2750. in_reply_to = thread->transaction_stack;
  2751. if (in_reply_to == NULL) {
  2752. binder_inner_proc_unlock(proc);
  2753. binder_user_error("%d:%d got reply transaction with no transaction stack\n",
  2754. proc->pid, thread->pid);
  2755. return_error = BR_FAILED_REPLY;
  2756. return_error_param = -EPROTO;
  2757. return_error_line = __LINE__;
  2758. goto err_empty_call_stack;
  2759. }
  2760. if (in_reply_to->to_thread != thread) {
  2761. spin_lock(&in_reply_to->lock);
  2762. binder_user_error("%d:%d got reply transaction with bad transaction stack, transaction %d has target %d:%d\n",
  2763. proc->pid, thread->pid, in_reply_to->debug_id,
  2764. in_reply_to->to_proc ?
  2765. in_reply_to->to_proc->pid : 0,
  2766. in_reply_to->to_thread ?
  2767. in_reply_to->to_thread->pid : 0);
  2768. spin_unlock(&in_reply_to->lock);
  2769. binder_inner_proc_unlock(proc);
  2770. return_error = BR_FAILED_REPLY;
  2771. return_error_param = -EPROTO;
  2772. return_error_line = __LINE__;
  2773. in_reply_to = NULL;
  2774. goto err_bad_call_stack;
  2775. }
  2776. thread->transaction_stack = in_reply_to->to_parent;
  2777. binder_inner_proc_unlock(proc);
  2778. binder_set_nice(in_reply_to->saved_priority);
  2779. target_thread = binder_get_txn_from_and_acq_inner(in_reply_to);
  2780. if (target_thread == NULL) {
  2781. /* annotation for sparse */
  2782. __release(&target_thread->proc->inner_lock);
  2783. binder_txn_error("%d:%d reply target not found\n",
  2784. thread->pid, proc->pid);
  2785. return_error = BR_DEAD_REPLY;
  2786. return_error_line = __LINE__;
  2787. goto err_dead_binder;
  2788. }
  2789. if (target_thread->transaction_stack != in_reply_to) {
  2790. binder_user_error("%d:%d got reply transaction with bad target transaction stack %d, expected %d\n",
  2791. proc->pid, thread->pid,
  2792. target_thread->transaction_stack ?
  2793. target_thread->transaction_stack->debug_id : 0,
  2794. in_reply_to->debug_id);
  2795. binder_inner_proc_unlock(target_thread->proc);
  2796. return_error = BR_FAILED_REPLY;
  2797. return_error_param = -EPROTO;
  2798. return_error_line = __LINE__;
  2799. in_reply_to = NULL;
  2800. target_thread = NULL;
  2801. goto err_dead_binder;
  2802. }
  2803. target_proc = target_thread->proc;
  2804. target_proc->tmp_ref++;
  2805. binder_inner_proc_unlock(target_thread->proc);
  2806. } else {
  2807. if (tr->target.handle) {
  2808. struct binder_ref *ref;
  2809. /*
  2810. * There must already be a strong ref
  2811. * on this node. If so, do a strong
  2812. * increment on the node to ensure it
  2813. * stays alive until the transaction is
  2814. * done.
  2815. */
  2816. binder_proc_lock(proc);
  2817. ref = binder_get_ref_olocked(proc, tr->target.handle,
  2818. true);
  2819. if (ref) {
  2820. target_node = binder_get_node_refs_for_txn(
  2821. ref->node, &target_proc,
  2822. &return_error);
  2823. } else {
  2824. binder_user_error("%d:%d got transaction to invalid handle, %u\n",
  2825. proc->pid, thread->pid, tr->target.handle);
  2826. return_error = BR_FAILED_REPLY;
  2827. }
  2828. binder_proc_unlock(proc);
  2829. } else {
  2830. mutex_lock(&context->context_mgr_node_lock);
  2831. target_node = context->binder_context_mgr_node;
  2832. if (target_node)
  2833. target_node = binder_get_node_refs_for_txn(
  2834. target_node, &target_proc,
  2835. &return_error);
  2836. else
  2837. return_error = BR_DEAD_REPLY;
  2838. mutex_unlock(&context->context_mgr_node_lock);
  2839. if (target_node && target_proc->pid == proc->pid) {
  2840. binder_user_error("%d:%d got transaction to context manager from process owning it\n",
  2841. proc->pid, thread->pid);
  2842. return_error = BR_FAILED_REPLY;
  2843. return_error_param = -EINVAL;
  2844. return_error_line = __LINE__;
  2845. goto err_invalid_target_handle;
  2846. }
  2847. }
  2848. if (!target_node) {
  2849. binder_txn_error("%d:%d cannot find target node\n",
  2850. thread->pid, proc->pid);
  2851. /*
  2852. * return_error is set above
  2853. */
  2854. return_error_param = -EINVAL;
  2855. return_error_line = __LINE__;
  2856. goto err_dead_binder;
  2857. }
  2858. e->to_node = target_node->debug_id;
  2859. if (WARN_ON(proc == target_proc)) {
  2860. binder_txn_error("%d:%d self transactions not allowed\n",
  2861. thread->pid, proc->pid);
  2862. return_error = BR_FAILED_REPLY;
  2863. return_error_param = -EINVAL;
  2864. return_error_line = __LINE__;
  2865. goto err_invalid_target_handle;
  2866. }
  2867. if (security_binder_transaction(proc->cred,
  2868. target_proc->cred) < 0) {
  2869. binder_txn_error("%d:%d transaction credentials failed\n",
  2870. thread->pid, proc->pid);
  2871. return_error = BR_FAILED_REPLY;
  2872. return_error_param = -EPERM;
  2873. return_error_line = __LINE__;
  2874. goto err_invalid_target_handle;
  2875. }
  2876. binder_inner_proc_lock(proc);
  2877. w = list_first_entry_or_null(&thread->todo,
  2878. struct binder_work, entry);
  2879. if (!(tr->flags & TF_ONE_WAY) && w &&
  2880. w->type == BINDER_WORK_TRANSACTION) {
  2881. /*
  2882. * Do not allow new outgoing transaction from a
  2883. * thread that has a transaction at the head of
  2884. * its todo list. Only need to check the head
  2885. * because binder_select_thread_ilocked picks a
  2886. * thread from proc->waiting_threads to enqueue
  2887. * the transaction, and nothing is queued to the
  2888. * todo list while the thread is on waiting_threads.
  2889. */
  2890. binder_user_error("%d:%d new transaction not allowed when there is a transaction on thread todo\n",
  2891. proc->pid, thread->pid);
  2892. binder_inner_proc_unlock(proc);
  2893. return_error = BR_FAILED_REPLY;
  2894. return_error_param = -EPROTO;
  2895. return_error_line = __LINE__;
  2896. goto err_bad_todo_list;
  2897. }
  2898. if (!(tr->flags & TF_ONE_WAY) && thread->transaction_stack) {
  2899. struct binder_transaction *tmp;
  2900. tmp = thread->transaction_stack;
  2901. if (tmp->to_thread != thread) {
  2902. spin_lock(&tmp->lock);
  2903. binder_user_error("%d:%d got new transaction with bad transaction stack, transaction %d has target %d:%d\n",
  2904. proc->pid, thread->pid, tmp->debug_id,
  2905. tmp->to_proc ? tmp->to_proc->pid : 0,
  2906. tmp->to_thread ?
  2907. tmp->to_thread->pid : 0);
  2908. spin_unlock(&tmp->lock);
  2909. binder_inner_proc_unlock(proc);
  2910. return_error = BR_FAILED_REPLY;
  2911. return_error_param = -EPROTO;
  2912. return_error_line = __LINE__;
  2913. goto err_bad_call_stack;
  2914. }
  2915. while (tmp) {
  2916. struct binder_thread *from;
  2917. spin_lock(&tmp->lock);
  2918. from = tmp->from;
  2919. if (from && from->proc == target_proc) {
  2920. atomic_inc(&from->tmp_ref);
  2921. target_thread = from;
  2922. spin_unlock(&tmp->lock);
  2923. break;
  2924. }
  2925. spin_unlock(&tmp->lock);
  2926. tmp = tmp->from_parent;
  2927. }
  2928. }
  2929. binder_inner_proc_unlock(proc);
  2930. }
  2931. if (target_thread)
  2932. e->to_thread = target_thread->pid;
  2933. e->to_proc = target_proc->pid;
  2934. /* TODO: reuse incoming transaction for reply */
  2935. t = kzalloc(sizeof(*t), GFP_KERNEL);
  2936. if (t == NULL) {
  2937. binder_txn_error("%d:%d cannot allocate transaction\n",
  2938. thread->pid, proc->pid);
  2939. return_error = BR_FAILED_REPLY;
  2940. return_error_param = -ENOMEM;
  2941. return_error_line = __LINE__;
  2942. goto err_alloc_t_failed;
  2943. }
  2944. INIT_LIST_HEAD(&t->fd_fixups);
  2945. binder_stats_created(BINDER_STAT_TRANSACTION);
  2946. spin_lock_init(&t->lock);
  2947. tcomplete = kzalloc(sizeof(*tcomplete), GFP_KERNEL);
  2948. if (tcomplete == NULL) {
  2949. binder_txn_error("%d:%d cannot allocate work for transaction\n",
  2950. thread->pid, proc->pid);
  2951. return_error = BR_FAILED_REPLY;
  2952. return_error_param = -ENOMEM;
  2953. return_error_line = __LINE__;
  2954. goto err_alloc_tcomplete_failed;
  2955. }
  2956. binder_stats_created(BINDER_STAT_TRANSACTION_COMPLETE);
  2957. t->debug_id = t_debug_id;
  2958. t->start_time = t_start_time;
  2959. if (reply)
  2960. binder_debug(BINDER_DEBUG_TRANSACTION,
  2961. "%d:%d BC_REPLY %d -> %d:%d, data %016llx-%016llx size %lld-%lld-%lld\n",
  2962. proc->pid, thread->pid, t->debug_id,
  2963. target_proc->pid, target_thread->pid,
  2964. (u64)tr->data.ptr.buffer,
  2965. (u64)tr->data.ptr.offsets,
  2966. (u64)tr->data_size, (u64)tr->offsets_size,
  2967. (u64)extra_buffers_size);
  2968. else
  2969. binder_debug(BINDER_DEBUG_TRANSACTION,
  2970. "%d:%d BC_TRANSACTION %d -> %d - node %d, data %016llx-%016llx size %lld-%lld-%lld\n",
  2971. proc->pid, thread->pid, t->debug_id,
  2972. target_proc->pid, target_node->debug_id,
  2973. (u64)tr->data.ptr.buffer,
  2974. (u64)tr->data.ptr.offsets,
  2975. (u64)tr->data_size, (u64)tr->offsets_size,
  2976. (u64)extra_buffers_size);
  2977. if (!reply && !(tr->flags & TF_ONE_WAY))
  2978. t->from = thread;
  2979. else
  2980. t->from = NULL;
  2981. t->from_pid = proc->pid;
  2982. t->from_tid = thread->pid;
  2983. t->sender_euid = task_euid(proc->tsk);
  2984. t->to_proc = target_proc;
  2985. t->to_thread = target_thread;
  2986. t->code = tr->code;
  2987. t->flags = tr->flags;
  2988. t->priority = task_nice(current);
  2989. if (target_node && target_node->txn_security_ctx) {
  2990. u32 secid;
  2991. size_t added_size;
  2992. security_cred_getsecid(proc->cred, &secid);
  2993. ret = security_secid_to_secctx(secid, &secctx, &secctx_sz);
  2994. if (ret) {
  2995. binder_txn_error("%d:%d failed to get security context\n",
  2996. thread->pid, proc->pid);
  2997. return_error = BR_FAILED_REPLY;
  2998. return_error_param = ret;
  2999. return_error_line = __LINE__;
  3000. goto err_get_secctx_failed;
  3001. }
  3002. added_size = ALIGN(secctx_sz, sizeof(u64));
  3003. extra_buffers_size += added_size;
  3004. if (extra_buffers_size < added_size) {
  3005. binder_txn_error("%d:%d integer overflow of extra_buffers_size\n",
  3006. thread->pid, proc->pid);
  3007. return_error = BR_FAILED_REPLY;
  3008. return_error_param = -EINVAL;
  3009. return_error_line = __LINE__;
  3010. goto err_bad_extra_size;
  3011. }
  3012. }
  3013. trace_binder_transaction(reply, t, target_node);
  3014. t->buffer = binder_alloc_new_buf(&target_proc->alloc, tr->data_size,
  3015. tr->offsets_size, extra_buffers_size,
  3016. !reply && (t->flags & TF_ONE_WAY));
  3017. if (IS_ERR(t->buffer)) {
  3018. char *s;
  3019. ret = PTR_ERR(t->buffer);
  3020. s = (ret == -ESRCH) ? ": vma cleared, target dead or dying"
  3021. : (ret == -ENOSPC) ? ": no space left"
  3022. : (ret == -ENOMEM) ? ": memory allocation failed"
  3023. : "";
  3024. binder_txn_error("cannot allocate buffer%s", s);
  3025. return_error_param = PTR_ERR(t->buffer);
  3026. return_error = return_error_param == -ESRCH ?
  3027. BR_DEAD_REPLY : BR_FAILED_REPLY;
  3028. return_error_line = __LINE__;
  3029. t->buffer = NULL;
  3030. goto err_binder_alloc_buf_failed;
  3031. }
  3032. if (secctx) {
  3033. int err;
  3034. size_t buf_offset = ALIGN(tr->data_size, sizeof(void *)) +
  3035. ALIGN(tr->offsets_size, sizeof(void *)) +
  3036. ALIGN(extra_buffers_size, sizeof(void *)) -
  3037. ALIGN(secctx_sz, sizeof(u64));
  3038. t->security_ctx = t->buffer->user_data + buf_offset;
  3039. err = binder_alloc_copy_to_buffer(&target_proc->alloc,
  3040. t->buffer, buf_offset,
  3041. secctx, secctx_sz);
  3042. if (err) {
  3043. t->security_ctx = 0;
  3044. WARN_ON(1);
  3045. }
  3046. security_release_secctx(secctx, secctx_sz);
  3047. secctx = NULL;
  3048. }
  3049. t->buffer->debug_id = t->debug_id;
  3050. t->buffer->transaction = t;
  3051. t->buffer->target_node = target_node;
  3052. t->buffer->clear_on_free = !!(t->flags & TF_CLEAR_BUF);
  3053. trace_binder_transaction_alloc_buf(t->buffer);
  3054. if (binder_alloc_copy_user_to_buffer(
  3055. &target_proc->alloc,
  3056. t->buffer,
  3057. ALIGN(tr->data_size, sizeof(void *)),
  3058. (const void __user *)
  3059. (uintptr_t)tr->data.ptr.offsets,
  3060. tr->offsets_size)) {
  3061. binder_user_error("%d:%d got transaction with invalid offsets ptr\n",
  3062. proc->pid, thread->pid);
  3063. return_error = BR_FAILED_REPLY;
  3064. return_error_param = -EFAULT;
  3065. return_error_line = __LINE__;
  3066. goto err_copy_data_failed;
  3067. }
  3068. if (!IS_ALIGNED(tr->offsets_size, sizeof(binder_size_t))) {
  3069. binder_user_error("%d:%d got transaction with invalid offsets size, %lld\n",
  3070. proc->pid, thread->pid, (u64)tr->offsets_size);
  3071. return_error = BR_FAILED_REPLY;
  3072. return_error_param = -EINVAL;
  3073. return_error_line = __LINE__;
  3074. goto err_bad_offset;
  3075. }
  3076. if (!IS_ALIGNED(extra_buffers_size, sizeof(u64))) {
  3077. binder_user_error("%d:%d got transaction with unaligned buffers size, %lld\n",
  3078. proc->pid, thread->pid,
  3079. (u64)extra_buffers_size);
  3080. return_error = BR_FAILED_REPLY;
  3081. return_error_param = -EINVAL;
  3082. return_error_line = __LINE__;
  3083. goto err_bad_offset;
  3084. }
  3085. off_start_offset = ALIGN(tr->data_size, sizeof(void *));
  3086. buffer_offset = off_start_offset;
  3087. off_end_offset = off_start_offset + tr->offsets_size;
  3088. sg_buf_offset = ALIGN(off_end_offset, sizeof(void *));
  3089. sg_buf_end_offset = sg_buf_offset + extra_buffers_size -
  3090. ALIGN(secctx_sz, sizeof(u64));
  3091. off_min = 0;
  3092. for (buffer_offset = off_start_offset; buffer_offset < off_end_offset;
  3093. buffer_offset += sizeof(binder_size_t)) {
  3094. struct binder_object_header *hdr;
  3095. size_t object_size;
  3096. struct binder_object object;
  3097. binder_size_t object_offset;
  3098. binder_size_t copy_size;
  3099. if (binder_alloc_copy_from_buffer(&target_proc->alloc,
  3100. &object_offset,
  3101. t->buffer,
  3102. buffer_offset,
  3103. sizeof(object_offset))) {
  3104. binder_txn_error("%d:%d copy offset from buffer failed\n",
  3105. thread->pid, proc->pid);
  3106. return_error = BR_FAILED_REPLY;
  3107. return_error_param = -EINVAL;
  3108. return_error_line = __LINE__;
  3109. goto err_bad_offset;
  3110. }
  3111. /*
  3112. * Copy the source user buffer up to the next object
  3113. * that will be processed.
  3114. */
  3115. copy_size = object_offset - user_offset;
  3116. if (copy_size && (user_offset > object_offset ||
  3117. object_offset > tr->data_size ||
  3118. binder_alloc_copy_user_to_buffer(
  3119. &target_proc->alloc,
  3120. t->buffer, user_offset,
  3121. user_buffer + user_offset,
  3122. copy_size))) {
  3123. binder_user_error("%d:%d got transaction with invalid data ptr\n",
  3124. proc->pid, thread->pid);
  3125. return_error = BR_FAILED_REPLY;
  3126. return_error_param = -EFAULT;
  3127. return_error_line = __LINE__;
  3128. goto err_copy_data_failed;
  3129. }
  3130. object_size = binder_get_object(target_proc, user_buffer,
  3131. t->buffer, object_offset, &object);
  3132. if (object_size == 0 || object_offset < off_min) {
  3133. binder_user_error("%d:%d got transaction with invalid offset (%lld, min %lld max %lld) or object.\n",
  3134. proc->pid, thread->pid,
  3135. (u64)object_offset,
  3136. (u64)off_min,
  3137. (u64)t->buffer->data_size);
  3138. return_error = BR_FAILED_REPLY;
  3139. return_error_param = -EINVAL;
  3140. return_error_line = __LINE__;
  3141. goto err_bad_offset;
  3142. }
  3143. /*
  3144. * Set offset to the next buffer fragment to be
  3145. * copied
  3146. */
  3147. user_offset = object_offset + object_size;
  3148. hdr = &object.hdr;
  3149. off_min = object_offset + object_size;
  3150. switch (hdr->type) {
  3151. case BINDER_TYPE_BINDER:
  3152. case BINDER_TYPE_WEAK_BINDER: {
  3153. struct flat_binder_object *fp;
  3154. fp = to_flat_binder_object(hdr);
  3155. ret = binder_translate_binder(fp, t, thread);
  3156. if (ret < 0 ||
  3157. binder_alloc_copy_to_buffer(&target_proc->alloc,
  3158. t->buffer,
  3159. object_offset,
  3160. fp, sizeof(*fp))) {
  3161. binder_txn_error("%d:%d translate binder failed\n",
  3162. thread->pid, proc->pid);
  3163. return_error = BR_FAILED_REPLY;
  3164. return_error_param = ret;
  3165. return_error_line = __LINE__;
  3166. goto err_translate_failed;
  3167. }
  3168. } break;
  3169. case BINDER_TYPE_HANDLE:
  3170. case BINDER_TYPE_WEAK_HANDLE: {
  3171. struct flat_binder_object *fp;
  3172. fp = to_flat_binder_object(hdr);
  3173. ret = binder_translate_handle(fp, t, thread);
  3174. if (ret < 0 ||
  3175. binder_alloc_copy_to_buffer(&target_proc->alloc,
  3176. t->buffer,
  3177. object_offset,
  3178. fp, sizeof(*fp))) {
  3179. binder_txn_error("%d:%d translate handle failed\n",
  3180. thread->pid, proc->pid);
  3181. return_error = BR_FAILED_REPLY;
  3182. return_error_param = ret;
  3183. return_error_line = __LINE__;
  3184. goto err_translate_failed;
  3185. }
  3186. } break;
  3187. case BINDER_TYPE_FD: {
  3188. struct binder_fd_object *fp = to_binder_fd_object(hdr);
  3189. binder_size_t fd_offset = object_offset +
  3190. (uintptr_t)&fp->fd - (uintptr_t)fp;
  3191. int ret = binder_translate_fd(fp->fd, fd_offset, t,
  3192. thread, in_reply_to);
  3193. fp->pad_binder = 0;
  3194. if (ret < 0 ||
  3195. binder_alloc_copy_to_buffer(&target_proc->alloc,
  3196. t->buffer,
  3197. object_offset,
  3198. fp, sizeof(*fp))) {
  3199. binder_txn_error("%d:%d translate fd failed\n",
  3200. thread->pid, proc->pid);
  3201. return_error = BR_FAILED_REPLY;
  3202. return_error_param = ret;
  3203. return_error_line = __LINE__;
  3204. goto err_translate_failed;
  3205. }
  3206. } break;
  3207. case BINDER_TYPE_FDA: {
  3208. struct binder_object ptr_object;
  3209. binder_size_t parent_offset;
  3210. struct binder_object user_object;
  3211. size_t user_parent_size;
  3212. struct binder_fd_array_object *fda =
  3213. to_binder_fd_array_object(hdr);
  3214. size_t num_valid = (buffer_offset - off_start_offset) /
  3215. sizeof(binder_size_t);
  3216. struct binder_buffer_object *parent =
  3217. binder_validate_ptr(target_proc, t->buffer,
  3218. &ptr_object, fda->parent,
  3219. off_start_offset,
  3220. &parent_offset,
  3221. num_valid);
  3222. if (!parent) {
  3223. binder_user_error("%d:%d got transaction with invalid parent offset or type\n",
  3224. proc->pid, thread->pid);
  3225. return_error = BR_FAILED_REPLY;
  3226. return_error_param = -EINVAL;
  3227. return_error_line = __LINE__;
  3228. goto err_bad_parent;
  3229. }
  3230. if (!binder_validate_fixup(target_proc, t->buffer,
  3231. off_start_offset,
  3232. parent_offset,
  3233. fda->parent_offset,
  3234. last_fixup_obj_off,
  3235. last_fixup_min_off)) {
  3236. binder_user_error("%d:%d got transaction with out-of-order buffer fixup\n",
  3237. proc->pid, thread->pid);
  3238. return_error = BR_FAILED_REPLY;
  3239. return_error_param = -EINVAL;
  3240. return_error_line = __LINE__;
  3241. goto err_bad_parent;
  3242. }
  3243. /*
  3244. * We need to read the user version of the parent
  3245. * object to get the original user offset
  3246. */
  3247. user_parent_size =
  3248. binder_get_object(proc, user_buffer, t->buffer,
  3249. parent_offset, &user_object);
  3250. if (user_parent_size != sizeof(user_object.bbo)) {
  3251. binder_user_error("%d:%d invalid ptr object size: %zd vs %zd\n",
  3252. proc->pid, thread->pid,
  3253. user_parent_size,
  3254. sizeof(user_object.bbo));
  3255. return_error = BR_FAILED_REPLY;
  3256. return_error_param = -EINVAL;
  3257. return_error_line = __LINE__;
  3258. goto err_bad_parent;
  3259. }
  3260. ret = binder_translate_fd_array(&pf_head, fda,
  3261. user_buffer, parent,
  3262. &user_object.bbo, t,
  3263. thread, in_reply_to);
  3264. if (!ret)
  3265. ret = binder_alloc_copy_to_buffer(&target_proc->alloc,
  3266. t->buffer,
  3267. object_offset,
  3268. fda, sizeof(*fda));
  3269. if (ret) {
  3270. binder_txn_error("%d:%d translate fd array failed\n",
  3271. thread->pid, proc->pid);
  3272. return_error = BR_FAILED_REPLY;
  3273. return_error_param = ret > 0 ? -EINVAL : ret;
  3274. return_error_line = __LINE__;
  3275. goto err_translate_failed;
  3276. }
  3277. last_fixup_obj_off = parent_offset;
  3278. last_fixup_min_off =
  3279. fda->parent_offset + sizeof(u32) * fda->num_fds;
  3280. } break;
  3281. case BINDER_TYPE_PTR: {
  3282. struct binder_buffer_object *bp =
  3283. to_binder_buffer_object(hdr);
  3284. size_t buf_left = sg_buf_end_offset - sg_buf_offset;
  3285. size_t num_valid;
  3286. if (bp->length > buf_left) {
  3287. binder_user_error("%d:%d got transaction with too large buffer\n",
  3288. proc->pid, thread->pid);
  3289. return_error = BR_FAILED_REPLY;
  3290. return_error_param = -EINVAL;
  3291. return_error_line = __LINE__;
  3292. goto err_bad_offset;
  3293. }
  3294. ret = binder_defer_copy(&sgc_head, sg_buf_offset,
  3295. (const void __user *)(uintptr_t)bp->buffer,
  3296. bp->length);
  3297. if (ret) {
  3298. binder_txn_error("%d:%d deferred copy failed\n",
  3299. thread->pid, proc->pid);
  3300. return_error = BR_FAILED_REPLY;
  3301. return_error_param = ret;
  3302. return_error_line = __LINE__;
  3303. goto err_translate_failed;
  3304. }
  3305. /* Fixup buffer pointer to target proc address space */
  3306. bp->buffer = t->buffer->user_data + sg_buf_offset;
  3307. sg_buf_offset += ALIGN(bp->length, sizeof(u64));
  3308. num_valid = (buffer_offset - off_start_offset) /
  3309. sizeof(binder_size_t);
  3310. ret = binder_fixup_parent(&pf_head, t,
  3311. thread, bp,
  3312. off_start_offset,
  3313. num_valid,
  3314. last_fixup_obj_off,
  3315. last_fixup_min_off);
  3316. if (ret < 0 ||
  3317. binder_alloc_copy_to_buffer(&target_proc->alloc,
  3318. t->buffer,
  3319. object_offset,
  3320. bp, sizeof(*bp))) {
  3321. binder_txn_error("%d:%d failed to fixup parent\n",
  3322. thread->pid, proc->pid);
  3323. return_error = BR_FAILED_REPLY;
  3324. return_error_param = ret;
  3325. return_error_line = __LINE__;
  3326. goto err_translate_failed;
  3327. }
  3328. last_fixup_obj_off = object_offset;
  3329. last_fixup_min_off = 0;
  3330. } break;
  3331. default:
  3332. binder_user_error("%d:%d got transaction with invalid object type, %x\n",
  3333. proc->pid, thread->pid, hdr->type);
  3334. return_error = BR_FAILED_REPLY;
  3335. return_error_param = -EINVAL;
  3336. return_error_line = __LINE__;
  3337. goto err_bad_object_type;
  3338. }
  3339. }
  3340. /* Done processing objects, copy the rest of the buffer */
  3341. if (binder_alloc_copy_user_to_buffer(
  3342. &target_proc->alloc,
  3343. t->buffer, user_offset,
  3344. user_buffer + user_offset,
  3345. tr->data_size - user_offset)) {
  3346. binder_user_error("%d:%d got transaction with invalid data ptr\n",
  3347. proc->pid, thread->pid);
  3348. return_error = BR_FAILED_REPLY;
  3349. return_error_param = -EFAULT;
  3350. return_error_line = __LINE__;
  3351. goto err_copy_data_failed;
  3352. }
  3353. ret = binder_do_deferred_txn_copies(&target_proc->alloc, t->buffer,
  3354. &sgc_head, &pf_head);
  3355. if (ret) {
  3356. binder_user_error("%d:%d got transaction with invalid offsets ptr\n",
  3357. proc->pid, thread->pid);
  3358. return_error = BR_FAILED_REPLY;
  3359. return_error_param = ret;
  3360. return_error_line = __LINE__;
  3361. goto err_copy_data_failed;
  3362. }
  3363. if (t->buffer->oneway_spam_suspect)
  3364. tcomplete->type = BINDER_WORK_TRANSACTION_ONEWAY_SPAM_SUSPECT;
  3365. else
  3366. tcomplete->type = BINDER_WORK_TRANSACTION_COMPLETE;
  3367. t->work.type = BINDER_WORK_TRANSACTION;
  3368. if (reply) {
  3369. binder_enqueue_thread_work(thread, tcomplete);
  3370. binder_inner_proc_lock(target_proc);
  3371. if (target_thread->is_dead) {
  3372. return_error = BR_DEAD_REPLY;
  3373. binder_inner_proc_unlock(target_proc);
  3374. goto err_dead_proc_or_thread;
  3375. }
  3376. BUG_ON(t->buffer->async_transaction != 0);
  3377. binder_pop_transaction_ilocked(target_thread, in_reply_to);
  3378. binder_enqueue_thread_work_ilocked(target_thread, &t->work);
  3379. target_proc->outstanding_txns++;
  3380. binder_inner_proc_unlock(target_proc);
  3381. wake_up_interruptible_sync(&target_thread->wait);
  3382. binder_free_transaction(in_reply_to);
  3383. } else if (!(t->flags & TF_ONE_WAY)) {
  3384. BUG_ON(t->buffer->async_transaction != 0);
  3385. binder_inner_proc_lock(proc);
  3386. /*
  3387. * Defer the TRANSACTION_COMPLETE, so we don't return to
  3388. * userspace immediately; this allows the target process to
  3389. * immediately start processing this transaction, reducing
  3390. * latency. We will then return the TRANSACTION_COMPLETE when
  3391. * the target replies (or there is an error).
  3392. */
  3393. binder_enqueue_deferred_thread_work_ilocked(thread, tcomplete);
  3394. t->need_reply = 1;
  3395. t->from_parent = thread->transaction_stack;
  3396. thread->transaction_stack = t;
  3397. binder_inner_proc_unlock(proc);
  3398. return_error = binder_proc_transaction(t,
  3399. target_proc, target_thread);
  3400. if (return_error) {
  3401. binder_inner_proc_lock(proc);
  3402. binder_pop_transaction_ilocked(thread, t);
  3403. binder_inner_proc_unlock(proc);
  3404. goto err_dead_proc_or_thread;
  3405. }
  3406. } else {
  3407. BUG_ON(target_node == NULL);
  3408. BUG_ON(t->buffer->async_transaction != 1);
  3409. return_error = binder_proc_transaction(t, target_proc, NULL);
  3410. /*
  3411. * Let the caller know when async transaction reaches a frozen
  3412. * process and is put in a pending queue, waiting for the target
  3413. * process to be unfrozen.
  3414. */
  3415. if (return_error == BR_TRANSACTION_PENDING_FROZEN)
  3416. tcomplete->type = BINDER_WORK_TRANSACTION_PENDING;
  3417. binder_enqueue_thread_work(thread, tcomplete);
  3418. if (return_error &&
  3419. return_error != BR_TRANSACTION_PENDING_FROZEN)
  3420. goto err_dead_proc_or_thread;
  3421. }
  3422. if (target_thread)
  3423. binder_thread_dec_tmpref(target_thread);
  3424. binder_proc_dec_tmpref(target_proc);
  3425. if (target_node)
  3426. binder_dec_node_tmpref(target_node);
  3427. /*
  3428. * write barrier to synchronize with initialization
  3429. * of log entry
  3430. */
  3431. smp_wmb();
  3432. WRITE_ONCE(e->debug_id_done, t_debug_id);
  3433. return;
  3434. err_dead_proc_or_thread:
  3435. binder_txn_error("%d:%d dead process or thread\n",
  3436. thread->pid, proc->pid);
  3437. return_error_line = __LINE__;
  3438. binder_dequeue_work(proc, tcomplete);
  3439. err_translate_failed:
  3440. err_bad_object_type:
  3441. err_bad_offset:
  3442. err_bad_parent:
  3443. err_copy_data_failed:
  3444. binder_cleanup_deferred_txn_lists(&sgc_head, &pf_head);
  3445. binder_free_txn_fixups(t);
  3446. trace_binder_transaction_failed_buffer_release(t->buffer);
  3447. binder_transaction_buffer_release(target_proc, NULL, t->buffer,
  3448. buffer_offset, true);
  3449. if (target_node)
  3450. binder_dec_node_tmpref(target_node);
  3451. target_node = NULL;
  3452. t->buffer->transaction = NULL;
  3453. binder_alloc_free_buf(&target_proc->alloc, t->buffer);
  3454. err_binder_alloc_buf_failed:
  3455. err_bad_extra_size:
  3456. if (secctx)
  3457. security_release_secctx(secctx, secctx_sz);
  3458. err_get_secctx_failed:
  3459. kfree(tcomplete);
  3460. binder_stats_deleted(BINDER_STAT_TRANSACTION_COMPLETE);
  3461. err_alloc_tcomplete_failed:
  3462. if (trace_binder_txn_latency_free_enabled())
  3463. binder_txn_latency_free(t);
  3464. kfree(t);
  3465. binder_stats_deleted(BINDER_STAT_TRANSACTION);
  3466. err_alloc_t_failed:
  3467. err_bad_todo_list:
  3468. err_bad_call_stack:
  3469. err_empty_call_stack:
  3470. err_dead_binder:
  3471. err_invalid_target_handle:
  3472. if (target_node) {
  3473. binder_dec_node(target_node, 1, 0);
  3474. binder_dec_node_tmpref(target_node);
  3475. }
  3476. binder_debug(BINDER_DEBUG_FAILED_TRANSACTION,
  3477. "%d:%d transaction %s to %d:%d failed %d/%d/%d, size %lld-%lld line %d\n",
  3478. proc->pid, thread->pid, reply ? "reply" :
  3479. (tr->flags & TF_ONE_WAY ? "async" : "call"),
  3480. target_proc ? target_proc->pid : 0,
  3481. target_thread ? target_thread->pid : 0,
  3482. t_debug_id, return_error, return_error_param,
  3483. (u64)tr->data_size, (u64)tr->offsets_size,
  3484. return_error_line);
  3485. if (target_thread)
  3486. binder_thread_dec_tmpref(target_thread);
  3487. if (target_proc)
  3488. binder_proc_dec_tmpref(target_proc);
  3489. {
  3490. struct binder_transaction_log_entry *fe;
  3491. e->return_error = return_error;
  3492. e->return_error_param = return_error_param;
  3493. e->return_error_line = return_error_line;
  3494. fe = binder_transaction_log_add(&binder_transaction_log_failed);
  3495. *fe = *e;
  3496. /*
  3497. * write barrier to synchronize with initialization
  3498. * of log entry
  3499. */
  3500. smp_wmb();
  3501. WRITE_ONCE(e->debug_id_done, t_debug_id);
  3502. WRITE_ONCE(fe->debug_id_done, t_debug_id);
  3503. }
  3504. BUG_ON(thread->return_error.cmd != BR_OK);
  3505. if (in_reply_to) {
  3506. binder_set_txn_from_error(in_reply_to, t_debug_id,
  3507. return_error, return_error_param);
  3508. thread->return_error.cmd = BR_TRANSACTION_COMPLETE;
  3509. binder_enqueue_thread_work(thread, &thread->return_error.work);
  3510. binder_send_failed_reply(in_reply_to, return_error);
  3511. } else {
  3512. binder_inner_proc_lock(proc);
  3513. binder_set_extended_error(&thread->ee, t_debug_id,
  3514. return_error, return_error_param);
  3515. binder_inner_proc_unlock(proc);
  3516. thread->return_error.cmd = return_error;
  3517. binder_enqueue_thread_work(thread, &thread->return_error.work);
  3518. }
  3519. }
  3520. static int
  3521. binder_request_freeze_notification(struct binder_proc *proc,
  3522. struct binder_thread *thread,
  3523. struct binder_handle_cookie *handle_cookie)
  3524. {
  3525. struct binder_ref_freeze *freeze;
  3526. struct binder_ref *ref;
  3527. freeze = kzalloc(sizeof(*freeze), GFP_KERNEL);
  3528. if (!freeze)
  3529. return -ENOMEM;
  3530. binder_proc_lock(proc);
  3531. ref = binder_get_ref_olocked(proc, handle_cookie->handle, false);
  3532. if (!ref) {
  3533. binder_user_error("%d:%d BC_REQUEST_FREEZE_NOTIFICATION invalid ref %d\n",
  3534. proc->pid, thread->pid, handle_cookie->handle);
  3535. binder_proc_unlock(proc);
  3536. kfree(freeze);
  3537. return -EINVAL;
  3538. }
  3539. binder_node_lock(ref->node);
  3540. if (ref->freeze) {
  3541. binder_user_error("%d:%d BC_REQUEST_FREEZE_NOTIFICATION already set\n",
  3542. proc->pid, thread->pid);
  3543. binder_node_unlock(ref->node);
  3544. binder_proc_unlock(proc);
  3545. kfree(freeze);
  3546. return -EINVAL;
  3547. }
  3548. binder_stats_created(BINDER_STAT_FREEZE);
  3549. INIT_LIST_HEAD(&freeze->work.entry);
  3550. freeze->cookie = handle_cookie->cookie;
  3551. freeze->work.type = BINDER_WORK_FROZEN_BINDER;
  3552. ref->freeze = freeze;
  3553. if (ref->node->proc) {
  3554. binder_inner_proc_lock(ref->node->proc);
  3555. freeze->is_frozen = ref->node->proc->is_frozen;
  3556. binder_inner_proc_unlock(ref->node->proc);
  3557. binder_inner_proc_lock(proc);
  3558. binder_enqueue_work_ilocked(&freeze->work, &proc->todo);
  3559. binder_wakeup_proc_ilocked(proc);
  3560. binder_inner_proc_unlock(proc);
  3561. }
  3562. binder_node_unlock(ref->node);
  3563. binder_proc_unlock(proc);
  3564. return 0;
  3565. }
  3566. static int
  3567. binder_clear_freeze_notification(struct binder_proc *proc,
  3568. struct binder_thread *thread,
  3569. struct binder_handle_cookie *handle_cookie)
  3570. {
  3571. struct binder_ref_freeze *freeze;
  3572. struct binder_ref *ref;
  3573. binder_proc_lock(proc);
  3574. ref = binder_get_ref_olocked(proc, handle_cookie->handle, false);
  3575. if (!ref) {
  3576. binder_user_error("%d:%d BC_CLEAR_FREEZE_NOTIFICATION invalid ref %d\n",
  3577. proc->pid, thread->pid, handle_cookie->handle);
  3578. binder_proc_unlock(proc);
  3579. return -EINVAL;
  3580. }
  3581. binder_node_lock(ref->node);
  3582. if (!ref->freeze) {
  3583. binder_user_error("%d:%d BC_CLEAR_FREEZE_NOTIFICATION freeze notification not active\n",
  3584. proc->pid, thread->pid);
  3585. binder_node_unlock(ref->node);
  3586. binder_proc_unlock(proc);
  3587. return -EINVAL;
  3588. }
  3589. freeze = ref->freeze;
  3590. binder_inner_proc_lock(proc);
  3591. if (freeze->cookie != handle_cookie->cookie) {
  3592. binder_user_error("%d:%d BC_CLEAR_FREEZE_NOTIFICATION freeze notification cookie mismatch %016llx != %016llx\n",
  3593. proc->pid, thread->pid, (u64)freeze->cookie,
  3594. (u64)handle_cookie->cookie);
  3595. binder_inner_proc_unlock(proc);
  3596. binder_node_unlock(ref->node);
  3597. binder_proc_unlock(proc);
  3598. return -EINVAL;
  3599. }
  3600. ref->freeze = NULL;
  3601. /*
  3602. * Take the existing freeze object and overwrite its work type. There are three cases here:
  3603. * 1. No pending notification. In this case just add the work to the queue.
  3604. * 2. A notification was sent and is pending an ack from userspace. Once an ack arrives, we
  3605. * should resend with the new work type.
  3606. * 3. A notification is pending to be sent. Since the work is already in the queue, nothing
  3607. * needs to be done here.
  3608. */
  3609. freeze->work.type = BINDER_WORK_CLEAR_FREEZE_NOTIFICATION;
  3610. if (list_empty(&freeze->work.entry)) {
  3611. binder_enqueue_work_ilocked(&freeze->work, &proc->todo);
  3612. binder_wakeup_proc_ilocked(proc);
  3613. } else if (freeze->sent) {
  3614. freeze->resend = true;
  3615. }
  3616. binder_inner_proc_unlock(proc);
  3617. binder_node_unlock(ref->node);
  3618. binder_proc_unlock(proc);
  3619. return 0;
  3620. }
  3621. static int
  3622. binder_freeze_notification_done(struct binder_proc *proc,
  3623. struct binder_thread *thread,
  3624. binder_uintptr_t cookie)
  3625. {
  3626. struct binder_ref_freeze *freeze = NULL;
  3627. struct binder_work *w;
  3628. binder_inner_proc_lock(proc);
  3629. list_for_each_entry(w, &proc->delivered_freeze, entry) {
  3630. struct binder_ref_freeze *tmp_freeze =
  3631. container_of(w, struct binder_ref_freeze, work);
  3632. if (tmp_freeze->cookie == cookie) {
  3633. freeze = tmp_freeze;
  3634. break;
  3635. }
  3636. }
  3637. if (!freeze) {
  3638. binder_user_error("%d:%d BC_FREEZE_NOTIFICATION_DONE %016llx not found\n",
  3639. proc->pid, thread->pid, (u64)cookie);
  3640. binder_inner_proc_unlock(proc);
  3641. return -EINVAL;
  3642. }
  3643. binder_dequeue_work_ilocked(&freeze->work);
  3644. freeze->sent = false;
  3645. if (freeze->resend) {
  3646. freeze->resend = false;
  3647. binder_enqueue_work_ilocked(&freeze->work, &proc->todo);
  3648. binder_wakeup_proc_ilocked(proc);
  3649. }
  3650. binder_inner_proc_unlock(proc);
  3651. return 0;
  3652. }
  3653. /**
  3654. * binder_free_buf() - free the specified buffer
  3655. * @proc: binder proc that owns buffer
  3656. * @buffer: buffer to be freed
  3657. * @is_failure: failed to send transaction
  3658. *
  3659. * If buffer for an async transaction, enqueue the next async
  3660. * transaction from the node.
  3661. *
  3662. * Cleanup buffer and free it.
  3663. */
  3664. static void
  3665. binder_free_buf(struct binder_proc *proc,
  3666. struct binder_thread *thread,
  3667. struct binder_buffer *buffer, bool is_failure)
  3668. {
  3669. binder_inner_proc_lock(proc);
  3670. if (buffer->transaction) {
  3671. buffer->transaction->buffer = NULL;
  3672. buffer->transaction = NULL;
  3673. }
  3674. binder_inner_proc_unlock(proc);
  3675. if (buffer->async_transaction && buffer->target_node) {
  3676. struct binder_node *buf_node;
  3677. struct binder_work *w;
  3678. buf_node = buffer->target_node;
  3679. binder_node_inner_lock(buf_node);
  3680. BUG_ON(!buf_node->has_async_transaction);
  3681. BUG_ON(buf_node->proc != proc);
  3682. w = binder_dequeue_work_head_ilocked(
  3683. &buf_node->async_todo);
  3684. if (!w) {
  3685. buf_node->has_async_transaction = false;
  3686. } else {
  3687. binder_enqueue_work_ilocked(
  3688. w, &proc->todo);
  3689. binder_wakeup_proc_ilocked(proc);
  3690. }
  3691. binder_node_inner_unlock(buf_node);
  3692. }
  3693. trace_binder_transaction_buffer_release(buffer);
  3694. binder_release_entire_buffer(proc, thread, buffer, is_failure);
  3695. binder_alloc_free_buf(&proc->alloc, buffer);
  3696. }
  3697. static int binder_thread_write(struct binder_proc *proc,
  3698. struct binder_thread *thread,
  3699. binder_uintptr_t binder_buffer, size_t size,
  3700. binder_size_t *consumed)
  3701. {
  3702. uint32_t cmd;
  3703. struct binder_context *context = proc->context;
  3704. void __user *buffer = (void __user *)(uintptr_t)binder_buffer;
  3705. void __user *ptr = buffer + *consumed;
  3706. void __user *end = buffer + size;
  3707. while (ptr < end && thread->return_error.cmd == BR_OK) {
  3708. int ret;
  3709. if (get_user(cmd, (uint32_t __user *)ptr))
  3710. return -EFAULT;
  3711. ptr += sizeof(uint32_t);
  3712. trace_binder_command(cmd);
  3713. if (_IOC_NR(cmd) < ARRAY_SIZE(binder_stats.bc)) {
  3714. atomic_inc(&binder_stats.bc[_IOC_NR(cmd)]);
  3715. atomic_inc(&proc->stats.bc[_IOC_NR(cmd)]);
  3716. atomic_inc(&thread->stats.bc[_IOC_NR(cmd)]);
  3717. }
  3718. switch (cmd) {
  3719. case BC_INCREFS:
  3720. case BC_ACQUIRE:
  3721. case BC_RELEASE:
  3722. case BC_DECREFS: {
  3723. uint32_t target;
  3724. const char *debug_string;
  3725. bool strong = cmd == BC_ACQUIRE || cmd == BC_RELEASE;
  3726. bool increment = cmd == BC_INCREFS || cmd == BC_ACQUIRE;
  3727. struct binder_ref_data rdata;
  3728. if (get_user(target, (uint32_t __user *)ptr))
  3729. return -EFAULT;
  3730. ptr += sizeof(uint32_t);
  3731. ret = -1;
  3732. if (increment && !target) {
  3733. struct binder_node *ctx_mgr_node;
  3734. mutex_lock(&context->context_mgr_node_lock);
  3735. ctx_mgr_node = context->binder_context_mgr_node;
  3736. if (ctx_mgr_node) {
  3737. if (ctx_mgr_node->proc == proc) {
  3738. binder_user_error("%d:%d context manager tried to acquire desc 0\n",
  3739. proc->pid, thread->pid);
  3740. mutex_unlock(&context->context_mgr_node_lock);
  3741. return -EINVAL;
  3742. }
  3743. ret = binder_inc_ref_for_node(
  3744. proc, ctx_mgr_node,
  3745. strong, NULL, &rdata);
  3746. }
  3747. mutex_unlock(&context->context_mgr_node_lock);
  3748. }
  3749. if (ret)
  3750. ret = binder_update_ref_for_handle(
  3751. proc, target, increment, strong,
  3752. &rdata);
  3753. if (!ret && rdata.desc != target) {
  3754. binder_user_error("%d:%d tried to acquire reference to desc %d, got %d instead\n",
  3755. proc->pid, thread->pid,
  3756. target, rdata.desc);
  3757. }
  3758. switch (cmd) {
  3759. case BC_INCREFS:
  3760. debug_string = "IncRefs";
  3761. break;
  3762. case BC_ACQUIRE:
  3763. debug_string = "Acquire";
  3764. break;
  3765. case BC_RELEASE:
  3766. debug_string = "Release";
  3767. break;
  3768. case BC_DECREFS:
  3769. default:
  3770. debug_string = "DecRefs";
  3771. break;
  3772. }
  3773. if (ret) {
  3774. binder_user_error("%d:%d %s %d refcount change on invalid ref %d ret %d\n",
  3775. proc->pid, thread->pid, debug_string,
  3776. strong, target, ret);
  3777. break;
  3778. }
  3779. binder_debug(BINDER_DEBUG_USER_REFS,
  3780. "%d:%d %s ref %d desc %d s %d w %d\n",
  3781. proc->pid, thread->pid, debug_string,
  3782. rdata.debug_id, rdata.desc, rdata.strong,
  3783. rdata.weak);
  3784. break;
  3785. }
  3786. case BC_INCREFS_DONE:
  3787. case BC_ACQUIRE_DONE: {
  3788. binder_uintptr_t node_ptr;
  3789. binder_uintptr_t cookie;
  3790. struct binder_node *node;
  3791. bool free_node;
  3792. if (get_user(node_ptr, (binder_uintptr_t __user *)ptr))
  3793. return -EFAULT;
  3794. ptr += sizeof(binder_uintptr_t);
  3795. if (get_user(cookie, (binder_uintptr_t __user *)ptr))
  3796. return -EFAULT;
  3797. ptr += sizeof(binder_uintptr_t);
  3798. node = binder_get_node(proc, node_ptr);
  3799. if (node == NULL) {
  3800. binder_user_error("%d:%d %s u%016llx no match\n",
  3801. proc->pid, thread->pid,
  3802. cmd == BC_INCREFS_DONE ?
  3803. "BC_INCREFS_DONE" :
  3804. "BC_ACQUIRE_DONE",
  3805. (u64)node_ptr);
  3806. break;
  3807. }
  3808. if (cookie != node->cookie) {
  3809. binder_user_error("%d:%d %s u%016llx node %d cookie mismatch %016llx != %016llx\n",
  3810. proc->pid, thread->pid,
  3811. cmd == BC_INCREFS_DONE ?
  3812. "BC_INCREFS_DONE" : "BC_ACQUIRE_DONE",
  3813. (u64)node_ptr, node->debug_id,
  3814. (u64)cookie, (u64)node->cookie);
  3815. binder_put_node(node);
  3816. break;
  3817. }
  3818. binder_node_inner_lock(node);
  3819. if (cmd == BC_ACQUIRE_DONE) {
  3820. if (node->pending_strong_ref == 0) {
  3821. binder_user_error("%d:%d BC_ACQUIRE_DONE node %d has no pending acquire request\n",
  3822. proc->pid, thread->pid,
  3823. node->debug_id);
  3824. binder_node_inner_unlock(node);
  3825. binder_put_node(node);
  3826. break;
  3827. }
  3828. node->pending_strong_ref = 0;
  3829. } else {
  3830. if (node->pending_weak_ref == 0) {
  3831. binder_user_error("%d:%d BC_INCREFS_DONE node %d has no pending increfs request\n",
  3832. proc->pid, thread->pid,
  3833. node->debug_id);
  3834. binder_node_inner_unlock(node);
  3835. binder_put_node(node);
  3836. break;
  3837. }
  3838. node->pending_weak_ref = 0;
  3839. }
  3840. free_node = binder_dec_node_nilocked(node,
  3841. cmd == BC_ACQUIRE_DONE, 0);
  3842. WARN_ON(free_node);
  3843. binder_debug(BINDER_DEBUG_USER_REFS,
  3844. "%d:%d %s node %d ls %d lw %d tr %d\n",
  3845. proc->pid, thread->pid,
  3846. cmd == BC_INCREFS_DONE ? "BC_INCREFS_DONE" : "BC_ACQUIRE_DONE",
  3847. node->debug_id, node->local_strong_refs,
  3848. node->local_weak_refs, node->tmp_refs);
  3849. binder_node_inner_unlock(node);
  3850. binder_put_node(node);
  3851. break;
  3852. }
  3853. case BC_ATTEMPT_ACQUIRE:
  3854. pr_err("BC_ATTEMPT_ACQUIRE not supported\n");
  3855. return -EINVAL;
  3856. case BC_ACQUIRE_RESULT:
  3857. pr_err("BC_ACQUIRE_RESULT not supported\n");
  3858. return -EINVAL;
  3859. case BC_FREE_BUFFER: {
  3860. binder_uintptr_t data_ptr;
  3861. struct binder_buffer *buffer;
  3862. if (get_user(data_ptr, (binder_uintptr_t __user *)ptr))
  3863. return -EFAULT;
  3864. ptr += sizeof(binder_uintptr_t);
  3865. buffer = binder_alloc_prepare_to_free(&proc->alloc,
  3866. data_ptr);
  3867. if (IS_ERR_OR_NULL(buffer)) {
  3868. if (PTR_ERR(buffer) == -EPERM) {
  3869. binder_user_error(
  3870. "%d:%d BC_FREE_BUFFER u%016llx matched unreturned or currently freeing buffer\n",
  3871. proc->pid, thread->pid,
  3872. (u64)data_ptr);
  3873. } else {
  3874. binder_user_error(
  3875. "%d:%d BC_FREE_BUFFER u%016llx no match\n",
  3876. proc->pid, thread->pid,
  3877. (u64)data_ptr);
  3878. }
  3879. break;
  3880. }
  3881. binder_debug(BINDER_DEBUG_FREE_BUFFER,
  3882. "%d:%d BC_FREE_BUFFER u%016llx found buffer %d for %s transaction\n",
  3883. proc->pid, thread->pid, (u64)data_ptr,
  3884. buffer->debug_id,
  3885. buffer->transaction ? "active" : "finished");
  3886. binder_free_buf(proc, thread, buffer, false);
  3887. break;
  3888. }
  3889. case BC_TRANSACTION_SG:
  3890. case BC_REPLY_SG: {
  3891. struct binder_transaction_data_sg tr;
  3892. if (copy_from_user(&tr, ptr, sizeof(tr)))
  3893. return -EFAULT;
  3894. ptr += sizeof(tr);
  3895. binder_transaction(proc, thread, &tr.transaction_data,
  3896. cmd == BC_REPLY_SG, tr.buffers_size);
  3897. break;
  3898. }
  3899. case BC_TRANSACTION:
  3900. case BC_REPLY: {
  3901. struct binder_transaction_data tr;
  3902. if (copy_from_user(&tr, ptr, sizeof(tr)))
  3903. return -EFAULT;
  3904. ptr += sizeof(tr);
  3905. binder_transaction(proc, thread, &tr,
  3906. cmd == BC_REPLY, 0);
  3907. break;
  3908. }
  3909. case BC_REGISTER_LOOPER:
  3910. binder_debug(BINDER_DEBUG_THREADS,
  3911. "%d:%d BC_REGISTER_LOOPER\n",
  3912. proc->pid, thread->pid);
  3913. binder_inner_proc_lock(proc);
  3914. if (thread->looper & BINDER_LOOPER_STATE_ENTERED) {
  3915. thread->looper |= BINDER_LOOPER_STATE_INVALID;
  3916. binder_user_error("%d:%d ERROR: BC_REGISTER_LOOPER called after BC_ENTER_LOOPER\n",
  3917. proc->pid, thread->pid);
  3918. } else if (proc->requested_threads == 0) {
  3919. thread->looper |= BINDER_LOOPER_STATE_INVALID;
  3920. binder_user_error("%d:%d ERROR: BC_REGISTER_LOOPER called without request\n",
  3921. proc->pid, thread->pid);
  3922. } else {
  3923. proc->requested_threads--;
  3924. proc->requested_threads_started++;
  3925. }
  3926. thread->looper |= BINDER_LOOPER_STATE_REGISTERED;
  3927. binder_inner_proc_unlock(proc);
  3928. break;
  3929. case BC_ENTER_LOOPER:
  3930. binder_debug(BINDER_DEBUG_THREADS,
  3931. "%d:%d BC_ENTER_LOOPER\n",
  3932. proc->pid, thread->pid);
  3933. if (thread->looper & BINDER_LOOPER_STATE_REGISTERED) {
  3934. thread->looper |= BINDER_LOOPER_STATE_INVALID;
  3935. binder_user_error("%d:%d ERROR: BC_ENTER_LOOPER called after BC_REGISTER_LOOPER\n",
  3936. proc->pid, thread->pid);
  3937. }
  3938. thread->looper |= BINDER_LOOPER_STATE_ENTERED;
  3939. break;
  3940. case BC_EXIT_LOOPER:
  3941. binder_debug(BINDER_DEBUG_THREADS,
  3942. "%d:%d BC_EXIT_LOOPER\n",
  3943. proc->pid, thread->pid);
  3944. thread->looper |= BINDER_LOOPER_STATE_EXITED;
  3945. break;
  3946. case BC_REQUEST_DEATH_NOTIFICATION:
  3947. case BC_CLEAR_DEATH_NOTIFICATION: {
  3948. uint32_t target;
  3949. binder_uintptr_t cookie;
  3950. struct binder_ref *ref;
  3951. struct binder_ref_death *death = NULL;
  3952. if (get_user(target, (uint32_t __user *)ptr))
  3953. return -EFAULT;
  3954. ptr += sizeof(uint32_t);
  3955. if (get_user(cookie, (binder_uintptr_t __user *)ptr))
  3956. return -EFAULT;
  3957. ptr += sizeof(binder_uintptr_t);
  3958. if (cmd == BC_REQUEST_DEATH_NOTIFICATION) {
  3959. /*
  3960. * Allocate memory for death notification
  3961. * before taking lock
  3962. */
  3963. death = kzalloc(sizeof(*death), GFP_KERNEL);
  3964. if (death == NULL) {
  3965. WARN_ON(thread->return_error.cmd !=
  3966. BR_OK);
  3967. thread->return_error.cmd = BR_ERROR;
  3968. binder_enqueue_thread_work(
  3969. thread,
  3970. &thread->return_error.work);
  3971. binder_debug(
  3972. BINDER_DEBUG_FAILED_TRANSACTION,
  3973. "%d:%d BC_REQUEST_DEATH_NOTIFICATION failed\n",
  3974. proc->pid, thread->pid);
  3975. break;
  3976. }
  3977. }
  3978. binder_proc_lock(proc);
  3979. ref = binder_get_ref_olocked(proc, target, false);
  3980. if (ref == NULL) {
  3981. binder_user_error("%d:%d %s invalid ref %d\n",
  3982. proc->pid, thread->pid,
  3983. cmd == BC_REQUEST_DEATH_NOTIFICATION ?
  3984. "BC_REQUEST_DEATH_NOTIFICATION" :
  3985. "BC_CLEAR_DEATH_NOTIFICATION",
  3986. target);
  3987. binder_proc_unlock(proc);
  3988. kfree(death);
  3989. break;
  3990. }
  3991. binder_debug(BINDER_DEBUG_DEATH_NOTIFICATION,
  3992. "%d:%d %s %016llx ref %d desc %d s %d w %d for node %d\n",
  3993. proc->pid, thread->pid,
  3994. cmd == BC_REQUEST_DEATH_NOTIFICATION ?
  3995. "BC_REQUEST_DEATH_NOTIFICATION" :
  3996. "BC_CLEAR_DEATH_NOTIFICATION",
  3997. (u64)cookie, ref->data.debug_id,
  3998. ref->data.desc, ref->data.strong,
  3999. ref->data.weak, ref->node->debug_id);
  4000. binder_node_lock(ref->node);
  4001. if (cmd == BC_REQUEST_DEATH_NOTIFICATION) {
  4002. if (ref->death) {
  4003. binder_user_error("%d:%d BC_REQUEST_DEATH_NOTIFICATION death notification already set\n",
  4004. proc->pid, thread->pid);
  4005. binder_node_unlock(ref->node);
  4006. binder_proc_unlock(proc);
  4007. kfree(death);
  4008. break;
  4009. }
  4010. binder_stats_created(BINDER_STAT_DEATH);
  4011. INIT_LIST_HEAD(&death->work.entry);
  4012. death->cookie = cookie;
  4013. ref->death = death;
  4014. if (ref->node->proc == NULL) {
  4015. ref->death->work.type = BINDER_WORK_DEAD_BINDER;
  4016. binder_inner_proc_lock(proc);
  4017. binder_enqueue_work_ilocked(
  4018. &ref->death->work, &proc->todo);
  4019. binder_wakeup_proc_ilocked(proc);
  4020. binder_inner_proc_unlock(proc);
  4021. }
  4022. } else {
  4023. if (ref->death == NULL) {
  4024. binder_user_error("%d:%d BC_CLEAR_DEATH_NOTIFICATION death notification not active\n",
  4025. proc->pid, thread->pid);
  4026. binder_node_unlock(ref->node);
  4027. binder_proc_unlock(proc);
  4028. break;
  4029. }
  4030. death = ref->death;
  4031. if (death->cookie != cookie) {
  4032. binder_user_error("%d:%d BC_CLEAR_DEATH_NOTIFICATION death notification cookie mismatch %016llx != %016llx\n",
  4033. proc->pid, thread->pid,
  4034. (u64)death->cookie,
  4035. (u64)cookie);
  4036. binder_node_unlock(ref->node);
  4037. binder_proc_unlock(proc);
  4038. break;
  4039. }
  4040. ref->death = NULL;
  4041. binder_inner_proc_lock(proc);
  4042. if (list_empty(&death->work.entry)) {
  4043. death->work.type = BINDER_WORK_CLEAR_DEATH_NOTIFICATION;
  4044. if (thread->looper &
  4045. (BINDER_LOOPER_STATE_REGISTERED |
  4046. BINDER_LOOPER_STATE_ENTERED))
  4047. binder_enqueue_thread_work_ilocked(
  4048. thread,
  4049. &death->work);
  4050. else {
  4051. binder_enqueue_work_ilocked(
  4052. &death->work,
  4053. &proc->todo);
  4054. binder_wakeup_proc_ilocked(
  4055. proc);
  4056. }
  4057. } else {
  4058. BUG_ON(death->work.type != BINDER_WORK_DEAD_BINDER);
  4059. death->work.type = BINDER_WORK_DEAD_BINDER_AND_CLEAR;
  4060. }
  4061. binder_inner_proc_unlock(proc);
  4062. }
  4063. binder_node_unlock(ref->node);
  4064. binder_proc_unlock(proc);
  4065. } break;
  4066. case BC_DEAD_BINDER_DONE: {
  4067. struct binder_work *w;
  4068. binder_uintptr_t cookie;
  4069. struct binder_ref_death *death = NULL;
  4070. if (get_user(cookie, (binder_uintptr_t __user *)ptr))
  4071. return -EFAULT;
  4072. ptr += sizeof(cookie);
  4073. binder_inner_proc_lock(proc);
  4074. list_for_each_entry(w, &proc->delivered_death,
  4075. entry) {
  4076. struct binder_ref_death *tmp_death =
  4077. container_of(w,
  4078. struct binder_ref_death,
  4079. work);
  4080. if (tmp_death->cookie == cookie) {
  4081. death = tmp_death;
  4082. break;
  4083. }
  4084. }
  4085. binder_debug(BINDER_DEBUG_DEAD_BINDER,
  4086. "%d:%d BC_DEAD_BINDER_DONE %016llx found %pK\n",
  4087. proc->pid, thread->pid, (u64)cookie,
  4088. death);
  4089. if (death == NULL) {
  4090. binder_user_error("%d:%d BC_DEAD_BINDER_DONE %016llx not found\n",
  4091. proc->pid, thread->pid, (u64)cookie);
  4092. binder_inner_proc_unlock(proc);
  4093. break;
  4094. }
  4095. binder_dequeue_work_ilocked(&death->work);
  4096. if (death->work.type == BINDER_WORK_DEAD_BINDER_AND_CLEAR) {
  4097. death->work.type = BINDER_WORK_CLEAR_DEATH_NOTIFICATION;
  4098. if (thread->looper &
  4099. (BINDER_LOOPER_STATE_REGISTERED |
  4100. BINDER_LOOPER_STATE_ENTERED))
  4101. binder_enqueue_thread_work_ilocked(
  4102. thread, &death->work);
  4103. else {
  4104. binder_enqueue_work_ilocked(
  4105. &death->work,
  4106. &proc->todo);
  4107. binder_wakeup_proc_ilocked(proc);
  4108. }
  4109. }
  4110. binder_inner_proc_unlock(proc);
  4111. } break;
  4112. case BC_REQUEST_FREEZE_NOTIFICATION: {
  4113. struct binder_handle_cookie handle_cookie;
  4114. int error;
  4115. if (copy_from_user(&handle_cookie, ptr, sizeof(handle_cookie)))
  4116. return -EFAULT;
  4117. ptr += sizeof(handle_cookie);
  4118. error = binder_request_freeze_notification(proc, thread,
  4119. &handle_cookie);
  4120. if (error)
  4121. return error;
  4122. } break;
  4123. case BC_CLEAR_FREEZE_NOTIFICATION: {
  4124. struct binder_handle_cookie handle_cookie;
  4125. int error;
  4126. if (copy_from_user(&handle_cookie, ptr, sizeof(handle_cookie)))
  4127. return -EFAULT;
  4128. ptr += sizeof(handle_cookie);
  4129. error = binder_clear_freeze_notification(proc, thread, &handle_cookie);
  4130. if (error)
  4131. return error;
  4132. } break;
  4133. case BC_FREEZE_NOTIFICATION_DONE: {
  4134. binder_uintptr_t cookie;
  4135. int error;
  4136. if (get_user(cookie, (binder_uintptr_t __user *)ptr))
  4137. return -EFAULT;
  4138. ptr += sizeof(cookie);
  4139. error = binder_freeze_notification_done(proc, thread, cookie);
  4140. if (error)
  4141. return error;
  4142. } break;
  4143. default:
  4144. pr_err("%d:%d unknown command %u\n",
  4145. proc->pid, thread->pid, cmd);
  4146. return -EINVAL;
  4147. }
  4148. *consumed = ptr - buffer;
  4149. }
  4150. return 0;
  4151. }
  4152. static void binder_stat_br(struct binder_proc *proc,
  4153. struct binder_thread *thread, uint32_t cmd)
  4154. {
  4155. trace_binder_return(cmd);
  4156. if (_IOC_NR(cmd) < ARRAY_SIZE(binder_stats.br)) {
  4157. atomic_inc(&binder_stats.br[_IOC_NR(cmd)]);
  4158. atomic_inc(&proc->stats.br[_IOC_NR(cmd)]);
  4159. atomic_inc(&thread->stats.br[_IOC_NR(cmd)]);
  4160. }
  4161. }
  4162. static int binder_put_node_cmd(struct binder_proc *proc,
  4163. struct binder_thread *thread,
  4164. void __user **ptrp,
  4165. binder_uintptr_t node_ptr,
  4166. binder_uintptr_t node_cookie,
  4167. int node_debug_id,
  4168. uint32_t cmd, const char *cmd_name)
  4169. {
  4170. void __user *ptr = *ptrp;
  4171. if (put_user(cmd, (uint32_t __user *)ptr))
  4172. return -EFAULT;
  4173. ptr += sizeof(uint32_t);
  4174. if (put_user(node_ptr, (binder_uintptr_t __user *)ptr))
  4175. return -EFAULT;
  4176. ptr += sizeof(binder_uintptr_t);
  4177. if (put_user(node_cookie, (binder_uintptr_t __user *)ptr))
  4178. return -EFAULT;
  4179. ptr += sizeof(binder_uintptr_t);
  4180. binder_stat_br(proc, thread, cmd);
  4181. binder_debug(BINDER_DEBUG_USER_REFS, "%d:%d %s %d u%016llx c%016llx\n",
  4182. proc->pid, thread->pid, cmd_name, node_debug_id,
  4183. (u64)node_ptr, (u64)node_cookie);
  4184. *ptrp = ptr;
  4185. return 0;
  4186. }
  4187. static int binder_wait_for_work(struct binder_thread *thread,
  4188. bool do_proc_work)
  4189. {
  4190. DEFINE_WAIT(wait);
  4191. struct binder_proc *proc = thread->proc;
  4192. int ret = 0;
  4193. binder_inner_proc_lock(proc);
  4194. for (;;) {
  4195. prepare_to_wait(&thread->wait, &wait, TASK_INTERRUPTIBLE|TASK_FREEZABLE);
  4196. if (binder_has_work_ilocked(thread, do_proc_work))
  4197. break;
  4198. if (do_proc_work)
  4199. list_add(&thread->waiting_thread_node,
  4200. &proc->waiting_threads);
  4201. binder_inner_proc_unlock(proc);
  4202. schedule();
  4203. binder_inner_proc_lock(proc);
  4204. list_del_init(&thread->waiting_thread_node);
  4205. if (signal_pending(current)) {
  4206. ret = -EINTR;
  4207. break;
  4208. }
  4209. }
  4210. finish_wait(&thread->wait, &wait);
  4211. binder_inner_proc_unlock(proc);
  4212. return ret;
  4213. }
  4214. /**
  4215. * binder_apply_fd_fixups() - finish fd translation
  4216. * @proc: binder_proc associated @t->buffer
  4217. * @t: binder transaction with list of fd fixups
  4218. *
  4219. * Now that we are in the context of the transaction target
  4220. * process, we can allocate and install fds. Process the
  4221. * list of fds to translate and fixup the buffer with the
  4222. * new fds first and only then install the files.
  4223. *
  4224. * If we fail to allocate an fd, skip the install and release
  4225. * any fds that have already been allocated.
  4226. */
  4227. static int binder_apply_fd_fixups(struct binder_proc *proc,
  4228. struct binder_transaction *t)
  4229. {
  4230. struct binder_txn_fd_fixup *fixup, *tmp;
  4231. int ret = 0;
  4232. list_for_each_entry(fixup, &t->fd_fixups, fixup_entry) {
  4233. int fd = get_unused_fd_flags(O_CLOEXEC);
  4234. if (fd < 0) {
  4235. binder_debug(BINDER_DEBUG_TRANSACTION,
  4236. "failed fd fixup txn %d fd %d\n",
  4237. t->debug_id, fd);
  4238. ret = -ENOMEM;
  4239. goto err;
  4240. }
  4241. binder_debug(BINDER_DEBUG_TRANSACTION,
  4242. "fd fixup txn %d fd %d\n",
  4243. t->debug_id, fd);
  4244. trace_binder_transaction_fd_recv(t, fd, fixup->offset);
  4245. fixup->target_fd = fd;
  4246. if (binder_alloc_copy_to_buffer(&proc->alloc, t->buffer,
  4247. fixup->offset, &fd,
  4248. sizeof(u32))) {
  4249. ret = -EINVAL;
  4250. goto err;
  4251. }
  4252. }
  4253. list_for_each_entry_safe(fixup, tmp, &t->fd_fixups, fixup_entry) {
  4254. fd_install(fixup->target_fd, fixup->file);
  4255. list_del(&fixup->fixup_entry);
  4256. kfree(fixup);
  4257. }
  4258. return ret;
  4259. err:
  4260. binder_free_txn_fixups(t);
  4261. return ret;
  4262. }
  4263. static int binder_thread_read(struct binder_proc *proc,
  4264. struct binder_thread *thread,
  4265. binder_uintptr_t binder_buffer, size_t size,
  4266. binder_size_t *consumed, int non_block)
  4267. {
  4268. void __user *buffer = (void __user *)(uintptr_t)binder_buffer;
  4269. void __user *ptr = buffer + *consumed;
  4270. void __user *end = buffer + size;
  4271. int ret = 0;
  4272. int wait_for_proc_work;
  4273. if (*consumed == 0) {
  4274. if (put_user(BR_NOOP, (uint32_t __user *)ptr))
  4275. return -EFAULT;
  4276. ptr += sizeof(uint32_t);
  4277. }
  4278. retry:
  4279. binder_inner_proc_lock(proc);
  4280. wait_for_proc_work = binder_available_for_proc_work_ilocked(thread);
  4281. binder_inner_proc_unlock(proc);
  4282. thread->looper |= BINDER_LOOPER_STATE_WAITING;
  4283. trace_binder_wait_for_work(wait_for_proc_work,
  4284. !!thread->transaction_stack,
  4285. !binder_worklist_empty(proc, &thread->todo));
  4286. if (wait_for_proc_work) {
  4287. if (!(thread->looper & (BINDER_LOOPER_STATE_REGISTERED |
  4288. BINDER_LOOPER_STATE_ENTERED))) {
  4289. binder_user_error("%d:%d ERROR: Thread waiting for process work before calling BC_REGISTER_LOOPER or BC_ENTER_LOOPER (state %x)\n",
  4290. proc->pid, thread->pid, thread->looper);
  4291. wait_event_interruptible(binder_user_error_wait,
  4292. binder_stop_on_user_error < 2);
  4293. }
  4294. binder_set_nice(proc->default_priority);
  4295. }
  4296. if (non_block) {
  4297. if (!binder_has_work(thread, wait_for_proc_work))
  4298. ret = -EAGAIN;
  4299. } else {
  4300. ret = binder_wait_for_work(thread, wait_for_proc_work);
  4301. }
  4302. thread->looper &= ~BINDER_LOOPER_STATE_WAITING;
  4303. if (ret)
  4304. return ret;
  4305. while (1) {
  4306. uint32_t cmd;
  4307. struct binder_transaction_data_secctx tr;
  4308. struct binder_transaction_data *trd = &tr.transaction_data;
  4309. struct binder_work *w = NULL;
  4310. struct list_head *list = NULL;
  4311. struct binder_transaction *t = NULL;
  4312. struct binder_thread *t_from;
  4313. size_t trsize = sizeof(*trd);
  4314. binder_inner_proc_lock(proc);
  4315. if (!binder_worklist_empty_ilocked(&thread->todo))
  4316. list = &thread->todo;
  4317. else if (!binder_worklist_empty_ilocked(&proc->todo) &&
  4318. wait_for_proc_work)
  4319. list = &proc->todo;
  4320. else {
  4321. binder_inner_proc_unlock(proc);
  4322. /* no data added */
  4323. if (ptr - buffer == 4 && !thread->looper_need_return)
  4324. goto retry;
  4325. break;
  4326. }
  4327. if (end - ptr < sizeof(tr) + 4) {
  4328. binder_inner_proc_unlock(proc);
  4329. break;
  4330. }
  4331. w = binder_dequeue_work_head_ilocked(list);
  4332. if (binder_worklist_empty_ilocked(&thread->todo))
  4333. thread->process_todo = false;
  4334. switch (w->type) {
  4335. case BINDER_WORK_TRANSACTION: {
  4336. binder_inner_proc_unlock(proc);
  4337. t = container_of(w, struct binder_transaction, work);
  4338. } break;
  4339. case BINDER_WORK_RETURN_ERROR: {
  4340. struct binder_error *e = container_of(
  4341. w, struct binder_error, work);
  4342. WARN_ON(e->cmd == BR_OK);
  4343. binder_inner_proc_unlock(proc);
  4344. if (put_user(e->cmd, (uint32_t __user *)ptr))
  4345. return -EFAULT;
  4346. cmd = e->cmd;
  4347. e->cmd = BR_OK;
  4348. ptr += sizeof(uint32_t);
  4349. binder_stat_br(proc, thread, cmd);
  4350. } break;
  4351. case BINDER_WORK_TRANSACTION_COMPLETE:
  4352. case BINDER_WORK_TRANSACTION_PENDING:
  4353. case BINDER_WORK_TRANSACTION_ONEWAY_SPAM_SUSPECT: {
  4354. if (proc->oneway_spam_detection_enabled &&
  4355. w->type == BINDER_WORK_TRANSACTION_ONEWAY_SPAM_SUSPECT)
  4356. cmd = BR_ONEWAY_SPAM_SUSPECT;
  4357. else if (w->type == BINDER_WORK_TRANSACTION_PENDING)
  4358. cmd = BR_TRANSACTION_PENDING_FROZEN;
  4359. else
  4360. cmd = BR_TRANSACTION_COMPLETE;
  4361. binder_inner_proc_unlock(proc);
  4362. kfree(w);
  4363. binder_stats_deleted(BINDER_STAT_TRANSACTION_COMPLETE);
  4364. if (put_user(cmd, (uint32_t __user *)ptr))
  4365. return -EFAULT;
  4366. ptr += sizeof(uint32_t);
  4367. binder_stat_br(proc, thread, cmd);
  4368. binder_debug(BINDER_DEBUG_TRANSACTION_COMPLETE,
  4369. "%d:%d BR_TRANSACTION_COMPLETE\n",
  4370. proc->pid, thread->pid);
  4371. } break;
  4372. case BINDER_WORK_NODE: {
  4373. struct binder_node *node = container_of(w, struct binder_node, work);
  4374. int strong, weak;
  4375. binder_uintptr_t node_ptr = node->ptr;
  4376. binder_uintptr_t node_cookie = node->cookie;
  4377. int node_debug_id = node->debug_id;
  4378. int has_weak_ref;
  4379. int has_strong_ref;
  4380. void __user *orig_ptr = ptr;
  4381. BUG_ON(proc != node->proc);
  4382. strong = node->internal_strong_refs ||
  4383. node->local_strong_refs;
  4384. weak = !hlist_empty(&node->refs) ||
  4385. node->local_weak_refs ||
  4386. node->tmp_refs || strong;
  4387. has_strong_ref = node->has_strong_ref;
  4388. has_weak_ref = node->has_weak_ref;
  4389. if (weak && !has_weak_ref) {
  4390. node->has_weak_ref = 1;
  4391. node->pending_weak_ref = 1;
  4392. node->local_weak_refs++;
  4393. }
  4394. if (strong && !has_strong_ref) {
  4395. node->has_strong_ref = 1;
  4396. node->pending_strong_ref = 1;
  4397. node->local_strong_refs++;
  4398. }
  4399. if (!strong && has_strong_ref)
  4400. node->has_strong_ref = 0;
  4401. if (!weak && has_weak_ref)
  4402. node->has_weak_ref = 0;
  4403. if (!weak && !strong) {
  4404. binder_debug(BINDER_DEBUG_INTERNAL_REFS,
  4405. "%d:%d node %d u%016llx c%016llx deleted\n",
  4406. proc->pid, thread->pid,
  4407. node_debug_id,
  4408. (u64)node_ptr,
  4409. (u64)node_cookie);
  4410. rb_erase(&node->rb_node, &proc->nodes);
  4411. binder_inner_proc_unlock(proc);
  4412. binder_node_lock(node);
  4413. /*
  4414. * Acquire the node lock before freeing the
  4415. * node to serialize with other threads that
  4416. * may have been holding the node lock while
  4417. * decrementing this node (avoids race where
  4418. * this thread frees while the other thread
  4419. * is unlocking the node after the final
  4420. * decrement)
  4421. */
  4422. binder_node_unlock(node);
  4423. binder_free_node(node);
  4424. } else
  4425. binder_inner_proc_unlock(proc);
  4426. if (weak && !has_weak_ref)
  4427. ret = binder_put_node_cmd(
  4428. proc, thread, &ptr, node_ptr,
  4429. node_cookie, node_debug_id,
  4430. BR_INCREFS, "BR_INCREFS");
  4431. if (!ret && strong && !has_strong_ref)
  4432. ret = binder_put_node_cmd(
  4433. proc, thread, &ptr, node_ptr,
  4434. node_cookie, node_debug_id,
  4435. BR_ACQUIRE, "BR_ACQUIRE");
  4436. if (!ret && !strong && has_strong_ref)
  4437. ret = binder_put_node_cmd(
  4438. proc, thread, &ptr, node_ptr,
  4439. node_cookie, node_debug_id,
  4440. BR_RELEASE, "BR_RELEASE");
  4441. if (!ret && !weak && has_weak_ref)
  4442. ret = binder_put_node_cmd(
  4443. proc, thread, &ptr, node_ptr,
  4444. node_cookie, node_debug_id,
  4445. BR_DECREFS, "BR_DECREFS");
  4446. if (orig_ptr == ptr)
  4447. binder_debug(BINDER_DEBUG_INTERNAL_REFS,
  4448. "%d:%d node %d u%016llx c%016llx state unchanged\n",
  4449. proc->pid, thread->pid,
  4450. node_debug_id,
  4451. (u64)node_ptr,
  4452. (u64)node_cookie);
  4453. if (ret)
  4454. return ret;
  4455. } break;
  4456. case BINDER_WORK_DEAD_BINDER:
  4457. case BINDER_WORK_DEAD_BINDER_AND_CLEAR:
  4458. case BINDER_WORK_CLEAR_DEATH_NOTIFICATION: {
  4459. struct binder_ref_death *death;
  4460. uint32_t cmd;
  4461. binder_uintptr_t cookie;
  4462. death = container_of(w, struct binder_ref_death, work);
  4463. if (w->type == BINDER_WORK_CLEAR_DEATH_NOTIFICATION)
  4464. cmd = BR_CLEAR_DEATH_NOTIFICATION_DONE;
  4465. else
  4466. cmd = BR_DEAD_BINDER;
  4467. cookie = death->cookie;
  4468. binder_debug(BINDER_DEBUG_DEATH_NOTIFICATION,
  4469. "%d:%d %s %016llx\n",
  4470. proc->pid, thread->pid,
  4471. cmd == BR_DEAD_BINDER ?
  4472. "BR_DEAD_BINDER" :
  4473. "BR_CLEAR_DEATH_NOTIFICATION_DONE",
  4474. (u64)cookie);
  4475. if (w->type == BINDER_WORK_CLEAR_DEATH_NOTIFICATION) {
  4476. binder_inner_proc_unlock(proc);
  4477. kfree(death);
  4478. binder_stats_deleted(BINDER_STAT_DEATH);
  4479. } else {
  4480. binder_enqueue_work_ilocked(
  4481. w, &proc->delivered_death);
  4482. binder_inner_proc_unlock(proc);
  4483. }
  4484. if (put_user(cmd, (uint32_t __user *)ptr))
  4485. return -EFAULT;
  4486. ptr += sizeof(uint32_t);
  4487. if (put_user(cookie,
  4488. (binder_uintptr_t __user *)ptr))
  4489. return -EFAULT;
  4490. ptr += sizeof(binder_uintptr_t);
  4491. binder_stat_br(proc, thread, cmd);
  4492. if (cmd == BR_DEAD_BINDER)
  4493. goto done; /* DEAD_BINDER notifications can cause transactions */
  4494. } break;
  4495. case BINDER_WORK_FROZEN_BINDER: {
  4496. struct binder_ref_freeze *freeze;
  4497. struct binder_frozen_state_info info;
  4498. memset(&info, 0, sizeof(info));
  4499. freeze = container_of(w, struct binder_ref_freeze, work);
  4500. info.is_frozen = freeze->is_frozen;
  4501. info.cookie = freeze->cookie;
  4502. freeze->sent = true;
  4503. binder_enqueue_work_ilocked(w, &proc->delivered_freeze);
  4504. binder_inner_proc_unlock(proc);
  4505. if (put_user(BR_FROZEN_BINDER, (uint32_t __user *)ptr))
  4506. return -EFAULT;
  4507. ptr += sizeof(uint32_t);
  4508. if (copy_to_user(ptr, &info, sizeof(info)))
  4509. return -EFAULT;
  4510. ptr += sizeof(info);
  4511. binder_stat_br(proc, thread, BR_FROZEN_BINDER);
  4512. goto done; /* BR_FROZEN_BINDER notifications can cause transactions */
  4513. } break;
  4514. case BINDER_WORK_CLEAR_FREEZE_NOTIFICATION: {
  4515. struct binder_ref_freeze *freeze =
  4516. container_of(w, struct binder_ref_freeze, work);
  4517. binder_uintptr_t cookie = freeze->cookie;
  4518. binder_inner_proc_unlock(proc);
  4519. kfree(freeze);
  4520. binder_stats_deleted(BINDER_STAT_FREEZE);
  4521. if (put_user(BR_CLEAR_FREEZE_NOTIFICATION_DONE, (uint32_t __user *)ptr))
  4522. return -EFAULT;
  4523. ptr += sizeof(uint32_t);
  4524. if (put_user(cookie, (binder_uintptr_t __user *)ptr))
  4525. return -EFAULT;
  4526. ptr += sizeof(binder_uintptr_t);
  4527. binder_stat_br(proc, thread, BR_CLEAR_FREEZE_NOTIFICATION_DONE);
  4528. } break;
  4529. default:
  4530. binder_inner_proc_unlock(proc);
  4531. pr_err("%d:%d: bad work type %d\n",
  4532. proc->pid, thread->pid, w->type);
  4533. break;
  4534. }
  4535. if (!t)
  4536. continue;
  4537. BUG_ON(t->buffer == NULL);
  4538. if (t->buffer->target_node) {
  4539. struct binder_node *target_node = t->buffer->target_node;
  4540. trd->target.ptr = target_node->ptr;
  4541. trd->cookie = target_node->cookie;
  4542. t->saved_priority = task_nice(current);
  4543. if (t->priority < target_node->min_priority &&
  4544. !(t->flags & TF_ONE_WAY))
  4545. binder_set_nice(t->priority);
  4546. else if (!(t->flags & TF_ONE_WAY) ||
  4547. t->saved_priority > target_node->min_priority)
  4548. binder_set_nice(target_node->min_priority);
  4549. cmd = BR_TRANSACTION;
  4550. } else {
  4551. trd->target.ptr = 0;
  4552. trd->cookie = 0;
  4553. cmd = BR_REPLY;
  4554. }
  4555. trd->code = t->code;
  4556. trd->flags = t->flags;
  4557. trd->sender_euid = from_kuid(current_user_ns(), t->sender_euid);
  4558. t_from = binder_get_txn_from(t);
  4559. if (t_from) {
  4560. struct task_struct *sender = t_from->proc->tsk;
  4561. trd->sender_pid =
  4562. task_tgid_nr_ns(sender,
  4563. task_active_pid_ns(current));
  4564. } else {
  4565. trd->sender_pid = 0;
  4566. }
  4567. ret = binder_apply_fd_fixups(proc, t);
  4568. if (ret) {
  4569. struct binder_buffer *buffer = t->buffer;
  4570. bool oneway = !!(t->flags & TF_ONE_WAY);
  4571. int tid = t->debug_id;
  4572. if (t_from)
  4573. binder_thread_dec_tmpref(t_from);
  4574. buffer->transaction = NULL;
  4575. binder_cleanup_transaction(t, "fd fixups failed",
  4576. BR_FAILED_REPLY);
  4577. binder_free_buf(proc, thread, buffer, true);
  4578. binder_debug(BINDER_DEBUG_FAILED_TRANSACTION,
  4579. "%d:%d %stransaction %d fd fixups failed %d/%d, line %d\n",
  4580. proc->pid, thread->pid,
  4581. oneway ? "async " :
  4582. (cmd == BR_REPLY ? "reply " : ""),
  4583. tid, BR_FAILED_REPLY, ret, __LINE__);
  4584. if (cmd == BR_REPLY) {
  4585. cmd = BR_FAILED_REPLY;
  4586. if (put_user(cmd, (uint32_t __user *)ptr))
  4587. return -EFAULT;
  4588. ptr += sizeof(uint32_t);
  4589. binder_stat_br(proc, thread, cmd);
  4590. break;
  4591. }
  4592. continue;
  4593. }
  4594. trd->data_size = t->buffer->data_size;
  4595. trd->offsets_size = t->buffer->offsets_size;
  4596. trd->data.ptr.buffer = t->buffer->user_data;
  4597. trd->data.ptr.offsets = trd->data.ptr.buffer +
  4598. ALIGN(t->buffer->data_size,
  4599. sizeof(void *));
  4600. tr.secctx = t->security_ctx;
  4601. if (t->security_ctx) {
  4602. cmd = BR_TRANSACTION_SEC_CTX;
  4603. trsize = sizeof(tr);
  4604. }
  4605. if (put_user(cmd, (uint32_t __user *)ptr)) {
  4606. if (t_from)
  4607. binder_thread_dec_tmpref(t_from);
  4608. binder_cleanup_transaction(t, "put_user failed",
  4609. BR_FAILED_REPLY);
  4610. return -EFAULT;
  4611. }
  4612. ptr += sizeof(uint32_t);
  4613. if (copy_to_user(ptr, &tr, trsize)) {
  4614. if (t_from)
  4615. binder_thread_dec_tmpref(t_from);
  4616. binder_cleanup_transaction(t, "copy_to_user failed",
  4617. BR_FAILED_REPLY);
  4618. return -EFAULT;
  4619. }
  4620. ptr += trsize;
  4621. trace_binder_transaction_received(t);
  4622. binder_stat_br(proc, thread, cmd);
  4623. binder_debug(BINDER_DEBUG_TRANSACTION,
  4624. "%d:%d %s %d %d:%d, cmd %u size %zd-%zd ptr %016llx-%016llx\n",
  4625. proc->pid, thread->pid,
  4626. (cmd == BR_TRANSACTION) ? "BR_TRANSACTION" :
  4627. (cmd == BR_TRANSACTION_SEC_CTX) ?
  4628. "BR_TRANSACTION_SEC_CTX" : "BR_REPLY",
  4629. t->debug_id, t_from ? t_from->proc->pid : 0,
  4630. t_from ? t_from->pid : 0, cmd,
  4631. t->buffer->data_size, t->buffer->offsets_size,
  4632. (u64)trd->data.ptr.buffer,
  4633. (u64)trd->data.ptr.offsets);
  4634. if (t_from)
  4635. binder_thread_dec_tmpref(t_from);
  4636. t->buffer->allow_user_free = 1;
  4637. if (cmd != BR_REPLY && !(t->flags & TF_ONE_WAY)) {
  4638. binder_inner_proc_lock(thread->proc);
  4639. t->to_parent = thread->transaction_stack;
  4640. t->to_thread = thread;
  4641. thread->transaction_stack = t;
  4642. binder_inner_proc_unlock(thread->proc);
  4643. } else {
  4644. binder_free_transaction(t);
  4645. }
  4646. break;
  4647. }
  4648. done:
  4649. *consumed = ptr - buffer;
  4650. binder_inner_proc_lock(proc);
  4651. if (proc->requested_threads == 0 &&
  4652. list_empty(&thread->proc->waiting_threads) &&
  4653. proc->requested_threads_started < proc->max_threads &&
  4654. (thread->looper & (BINDER_LOOPER_STATE_REGISTERED |
  4655. BINDER_LOOPER_STATE_ENTERED)) /* the user-space code fails to */
  4656. /*spawn a new thread if we leave this out */) {
  4657. proc->requested_threads++;
  4658. binder_inner_proc_unlock(proc);
  4659. binder_debug(BINDER_DEBUG_THREADS,
  4660. "%d:%d BR_SPAWN_LOOPER\n",
  4661. proc->pid, thread->pid);
  4662. if (put_user(BR_SPAWN_LOOPER, (uint32_t __user *)buffer))
  4663. return -EFAULT;
  4664. binder_stat_br(proc, thread, BR_SPAWN_LOOPER);
  4665. } else
  4666. binder_inner_proc_unlock(proc);
  4667. return 0;
  4668. }
  4669. static void binder_release_work(struct binder_proc *proc,
  4670. struct list_head *list)
  4671. {
  4672. struct binder_work *w;
  4673. enum binder_work_type wtype;
  4674. while (1) {
  4675. binder_inner_proc_lock(proc);
  4676. w = binder_dequeue_work_head_ilocked(list);
  4677. wtype = w ? w->type : 0;
  4678. binder_inner_proc_unlock(proc);
  4679. if (!w)
  4680. return;
  4681. switch (wtype) {
  4682. case BINDER_WORK_TRANSACTION: {
  4683. struct binder_transaction *t;
  4684. t = container_of(w, struct binder_transaction, work);
  4685. binder_cleanup_transaction(t, "process died.",
  4686. BR_DEAD_REPLY);
  4687. } break;
  4688. case BINDER_WORK_RETURN_ERROR: {
  4689. struct binder_error *e = container_of(
  4690. w, struct binder_error, work);
  4691. binder_debug(BINDER_DEBUG_DEAD_TRANSACTION,
  4692. "undelivered TRANSACTION_ERROR: %u\n",
  4693. e->cmd);
  4694. } break;
  4695. case BINDER_WORK_TRANSACTION_PENDING:
  4696. case BINDER_WORK_TRANSACTION_ONEWAY_SPAM_SUSPECT:
  4697. case BINDER_WORK_TRANSACTION_COMPLETE: {
  4698. binder_debug(BINDER_DEBUG_DEAD_TRANSACTION,
  4699. "undelivered TRANSACTION_COMPLETE\n");
  4700. kfree(w);
  4701. binder_stats_deleted(BINDER_STAT_TRANSACTION_COMPLETE);
  4702. } break;
  4703. case BINDER_WORK_DEAD_BINDER_AND_CLEAR:
  4704. case BINDER_WORK_CLEAR_DEATH_NOTIFICATION: {
  4705. struct binder_ref_death *death;
  4706. death = container_of(w, struct binder_ref_death, work);
  4707. binder_debug(BINDER_DEBUG_DEAD_TRANSACTION,
  4708. "undelivered death notification, %016llx\n",
  4709. (u64)death->cookie);
  4710. kfree(death);
  4711. binder_stats_deleted(BINDER_STAT_DEATH);
  4712. } break;
  4713. case BINDER_WORK_NODE:
  4714. break;
  4715. case BINDER_WORK_CLEAR_FREEZE_NOTIFICATION: {
  4716. struct binder_ref_freeze *freeze;
  4717. freeze = container_of(w, struct binder_ref_freeze, work);
  4718. binder_debug(BINDER_DEBUG_DEAD_TRANSACTION,
  4719. "undelivered freeze notification, %016llx\n",
  4720. (u64)freeze->cookie);
  4721. kfree(freeze);
  4722. binder_stats_deleted(BINDER_STAT_FREEZE);
  4723. } break;
  4724. default:
  4725. pr_err("unexpected work type, %d, not freed\n",
  4726. wtype);
  4727. break;
  4728. }
  4729. }
  4730. }
  4731. static struct binder_thread *binder_get_thread_ilocked(
  4732. struct binder_proc *proc, struct binder_thread *new_thread)
  4733. {
  4734. struct binder_thread *thread = NULL;
  4735. struct rb_node *parent = NULL;
  4736. struct rb_node **p = &proc->threads.rb_node;
  4737. while (*p) {
  4738. parent = *p;
  4739. thread = rb_entry(parent, struct binder_thread, rb_node);
  4740. if (current->pid < thread->pid)
  4741. p = &(*p)->rb_left;
  4742. else if (current->pid > thread->pid)
  4743. p = &(*p)->rb_right;
  4744. else
  4745. return thread;
  4746. }
  4747. if (!new_thread)
  4748. return NULL;
  4749. thread = new_thread;
  4750. binder_stats_created(BINDER_STAT_THREAD);
  4751. thread->proc = proc;
  4752. thread->pid = current->pid;
  4753. atomic_set(&thread->tmp_ref, 0);
  4754. init_waitqueue_head(&thread->wait);
  4755. INIT_LIST_HEAD(&thread->todo);
  4756. rb_link_node(&thread->rb_node, parent, p);
  4757. rb_insert_color(&thread->rb_node, &proc->threads);
  4758. thread->looper_need_return = true;
  4759. thread->return_error.work.type = BINDER_WORK_RETURN_ERROR;
  4760. thread->return_error.cmd = BR_OK;
  4761. thread->reply_error.work.type = BINDER_WORK_RETURN_ERROR;
  4762. thread->reply_error.cmd = BR_OK;
  4763. thread->ee.command = BR_OK;
  4764. INIT_LIST_HEAD(&new_thread->waiting_thread_node);
  4765. return thread;
  4766. }
  4767. static struct binder_thread *binder_get_thread(struct binder_proc *proc)
  4768. {
  4769. struct binder_thread *thread;
  4770. struct binder_thread *new_thread;
  4771. binder_inner_proc_lock(proc);
  4772. thread = binder_get_thread_ilocked(proc, NULL);
  4773. binder_inner_proc_unlock(proc);
  4774. if (!thread) {
  4775. new_thread = kzalloc(sizeof(*thread), GFP_KERNEL);
  4776. if (new_thread == NULL)
  4777. return NULL;
  4778. binder_inner_proc_lock(proc);
  4779. thread = binder_get_thread_ilocked(proc, new_thread);
  4780. binder_inner_proc_unlock(proc);
  4781. if (thread != new_thread)
  4782. kfree(new_thread);
  4783. }
  4784. return thread;
  4785. }
  4786. static void binder_free_proc(struct binder_proc *proc)
  4787. {
  4788. struct binder_device *device;
  4789. BUG_ON(!list_empty(&proc->todo));
  4790. BUG_ON(!list_empty(&proc->delivered_death));
  4791. if (proc->outstanding_txns)
  4792. pr_warn("%s: Unexpected outstanding_txns %d\n",
  4793. __func__, proc->outstanding_txns);
  4794. device = container_of(proc->context, struct binder_device, context);
  4795. if (refcount_dec_and_test(&device->ref)) {
  4796. kfree(proc->context->name);
  4797. kfree(device);
  4798. }
  4799. binder_alloc_deferred_release(&proc->alloc);
  4800. put_task_struct(proc->tsk);
  4801. put_cred(proc->cred);
  4802. binder_stats_deleted(BINDER_STAT_PROC);
  4803. dbitmap_free(&proc->dmap);
  4804. kfree(proc);
  4805. }
  4806. static void binder_free_thread(struct binder_thread *thread)
  4807. {
  4808. BUG_ON(!list_empty(&thread->todo));
  4809. binder_stats_deleted(BINDER_STAT_THREAD);
  4810. binder_proc_dec_tmpref(thread->proc);
  4811. kfree(thread);
  4812. }
  4813. static int binder_thread_release(struct binder_proc *proc,
  4814. struct binder_thread *thread)
  4815. {
  4816. struct binder_transaction *t;
  4817. struct binder_transaction *send_reply = NULL;
  4818. int active_transactions = 0;
  4819. struct binder_transaction *last_t = NULL;
  4820. binder_inner_proc_lock(thread->proc);
  4821. /*
  4822. * take a ref on the proc so it survives
  4823. * after we remove this thread from proc->threads.
  4824. * The corresponding dec is when we actually
  4825. * free the thread in binder_free_thread()
  4826. */
  4827. proc->tmp_ref++;
  4828. /*
  4829. * take a ref on this thread to ensure it
  4830. * survives while we are releasing it
  4831. */
  4832. atomic_inc(&thread->tmp_ref);
  4833. rb_erase(&thread->rb_node, &proc->threads);
  4834. t = thread->transaction_stack;
  4835. if (t) {
  4836. spin_lock(&t->lock);
  4837. if (t->to_thread == thread)
  4838. send_reply = t;
  4839. } else {
  4840. __acquire(&t->lock);
  4841. }
  4842. thread->is_dead = true;
  4843. while (t) {
  4844. last_t = t;
  4845. active_transactions++;
  4846. binder_debug(BINDER_DEBUG_DEAD_TRANSACTION,
  4847. "release %d:%d transaction %d %s, still active\n",
  4848. proc->pid, thread->pid,
  4849. t->debug_id,
  4850. (t->to_thread == thread) ? "in" : "out");
  4851. if (t->to_thread == thread) {
  4852. thread->proc->outstanding_txns--;
  4853. t->to_proc = NULL;
  4854. t->to_thread = NULL;
  4855. if (t->buffer) {
  4856. t->buffer->transaction = NULL;
  4857. t->buffer = NULL;
  4858. }
  4859. t = t->to_parent;
  4860. } else if (t->from == thread) {
  4861. t->from = NULL;
  4862. t = t->from_parent;
  4863. } else
  4864. BUG();
  4865. spin_unlock(&last_t->lock);
  4866. if (t)
  4867. spin_lock(&t->lock);
  4868. else
  4869. __acquire(&t->lock);
  4870. }
  4871. /* annotation for sparse, lock not acquired in last iteration above */
  4872. __release(&t->lock);
  4873. /*
  4874. * If this thread used poll, make sure we remove the waitqueue from any
  4875. * poll data structures holding it.
  4876. */
  4877. if (thread->looper & BINDER_LOOPER_STATE_POLL)
  4878. wake_up_pollfree(&thread->wait);
  4879. binder_inner_proc_unlock(thread->proc);
  4880. /*
  4881. * This is needed to avoid races between wake_up_pollfree() above and
  4882. * someone else removing the last entry from the queue for other reasons
  4883. * (e.g. ep_remove_wait_queue() being called due to an epoll file
  4884. * descriptor being closed). Such other users hold an RCU read lock, so
  4885. * we can be sure they're done after we call synchronize_rcu().
  4886. */
  4887. if (thread->looper & BINDER_LOOPER_STATE_POLL)
  4888. synchronize_rcu();
  4889. if (send_reply)
  4890. binder_send_failed_reply(send_reply, BR_DEAD_REPLY);
  4891. binder_release_work(proc, &thread->todo);
  4892. binder_thread_dec_tmpref(thread);
  4893. return active_transactions;
  4894. }
  4895. static __poll_t binder_poll(struct file *filp,
  4896. struct poll_table_struct *wait)
  4897. {
  4898. struct binder_proc *proc = filp->private_data;
  4899. struct binder_thread *thread = NULL;
  4900. bool wait_for_proc_work;
  4901. thread = binder_get_thread(proc);
  4902. if (!thread)
  4903. return EPOLLERR;
  4904. binder_inner_proc_lock(thread->proc);
  4905. thread->looper |= BINDER_LOOPER_STATE_POLL;
  4906. wait_for_proc_work = binder_available_for_proc_work_ilocked(thread);
  4907. binder_inner_proc_unlock(thread->proc);
  4908. poll_wait(filp, &thread->wait, wait);
  4909. if (binder_has_work(thread, wait_for_proc_work))
  4910. return EPOLLIN;
  4911. return 0;
  4912. }
  4913. static int binder_ioctl_write_read(struct file *filp, unsigned long arg,
  4914. struct binder_thread *thread)
  4915. {
  4916. int ret = 0;
  4917. struct binder_proc *proc = filp->private_data;
  4918. void __user *ubuf = (void __user *)arg;
  4919. struct binder_write_read bwr;
  4920. if (copy_from_user(&bwr, ubuf, sizeof(bwr))) {
  4921. ret = -EFAULT;
  4922. goto out;
  4923. }
  4924. binder_debug(BINDER_DEBUG_READ_WRITE,
  4925. "%d:%d write %lld at %016llx, read %lld at %016llx\n",
  4926. proc->pid, thread->pid,
  4927. (u64)bwr.write_size, (u64)bwr.write_buffer,
  4928. (u64)bwr.read_size, (u64)bwr.read_buffer);
  4929. if (bwr.write_size > 0) {
  4930. ret = binder_thread_write(proc, thread,
  4931. bwr.write_buffer,
  4932. bwr.write_size,
  4933. &bwr.write_consumed);
  4934. trace_binder_write_done(ret);
  4935. if (ret < 0) {
  4936. bwr.read_consumed = 0;
  4937. if (copy_to_user(ubuf, &bwr, sizeof(bwr)))
  4938. ret = -EFAULT;
  4939. goto out;
  4940. }
  4941. }
  4942. if (bwr.read_size > 0) {
  4943. ret = binder_thread_read(proc, thread, bwr.read_buffer,
  4944. bwr.read_size,
  4945. &bwr.read_consumed,
  4946. filp->f_flags & O_NONBLOCK);
  4947. trace_binder_read_done(ret);
  4948. binder_inner_proc_lock(proc);
  4949. if (!binder_worklist_empty_ilocked(&proc->todo))
  4950. binder_wakeup_proc_ilocked(proc);
  4951. binder_inner_proc_unlock(proc);
  4952. if (ret < 0) {
  4953. if (copy_to_user(ubuf, &bwr, sizeof(bwr)))
  4954. ret = -EFAULT;
  4955. goto out;
  4956. }
  4957. }
  4958. binder_debug(BINDER_DEBUG_READ_WRITE,
  4959. "%d:%d wrote %lld of %lld, read return %lld of %lld\n",
  4960. proc->pid, thread->pid,
  4961. (u64)bwr.write_consumed, (u64)bwr.write_size,
  4962. (u64)bwr.read_consumed, (u64)bwr.read_size);
  4963. if (copy_to_user(ubuf, &bwr, sizeof(bwr))) {
  4964. ret = -EFAULT;
  4965. goto out;
  4966. }
  4967. out:
  4968. return ret;
  4969. }
  4970. static int binder_ioctl_set_ctx_mgr(struct file *filp,
  4971. struct flat_binder_object *fbo)
  4972. {
  4973. int ret = 0;
  4974. struct binder_proc *proc = filp->private_data;
  4975. struct binder_context *context = proc->context;
  4976. struct binder_node *new_node;
  4977. kuid_t curr_euid = current_euid();
  4978. mutex_lock(&context->context_mgr_node_lock);
  4979. if (context->binder_context_mgr_node) {
  4980. pr_err("BINDER_SET_CONTEXT_MGR already set\n");
  4981. ret = -EBUSY;
  4982. goto out;
  4983. }
  4984. ret = security_binder_set_context_mgr(proc->cred);
  4985. if (ret < 0)
  4986. goto out;
  4987. if (uid_valid(context->binder_context_mgr_uid)) {
  4988. if (!uid_eq(context->binder_context_mgr_uid, curr_euid)) {
  4989. pr_err("BINDER_SET_CONTEXT_MGR bad uid %d != %d\n",
  4990. from_kuid(&init_user_ns, curr_euid),
  4991. from_kuid(&init_user_ns,
  4992. context->binder_context_mgr_uid));
  4993. ret = -EPERM;
  4994. goto out;
  4995. }
  4996. } else {
  4997. context->binder_context_mgr_uid = curr_euid;
  4998. }
  4999. new_node = binder_new_node(proc, fbo);
  5000. if (!new_node) {
  5001. ret = -ENOMEM;
  5002. goto out;
  5003. }
  5004. binder_node_lock(new_node);
  5005. new_node->local_weak_refs++;
  5006. new_node->local_strong_refs++;
  5007. new_node->has_strong_ref = 1;
  5008. new_node->has_weak_ref = 1;
  5009. context->binder_context_mgr_node = new_node;
  5010. binder_node_unlock(new_node);
  5011. binder_put_node(new_node);
  5012. out:
  5013. mutex_unlock(&context->context_mgr_node_lock);
  5014. return ret;
  5015. }
  5016. static int binder_ioctl_get_node_info_for_ref(struct binder_proc *proc,
  5017. struct binder_node_info_for_ref *info)
  5018. {
  5019. struct binder_node *node;
  5020. struct binder_context *context = proc->context;
  5021. __u32 handle = info->handle;
  5022. if (info->strong_count || info->weak_count || info->reserved1 ||
  5023. info->reserved2 || info->reserved3) {
  5024. binder_user_error("%d BINDER_GET_NODE_INFO_FOR_REF: only handle may be non-zero.",
  5025. proc->pid);
  5026. return -EINVAL;
  5027. }
  5028. /* This ioctl may only be used by the context manager */
  5029. mutex_lock(&context->context_mgr_node_lock);
  5030. if (!context->binder_context_mgr_node ||
  5031. context->binder_context_mgr_node->proc != proc) {
  5032. mutex_unlock(&context->context_mgr_node_lock);
  5033. return -EPERM;
  5034. }
  5035. mutex_unlock(&context->context_mgr_node_lock);
  5036. node = binder_get_node_from_ref(proc, handle, true, NULL);
  5037. if (!node)
  5038. return -EINVAL;
  5039. info->strong_count = node->local_strong_refs +
  5040. node->internal_strong_refs;
  5041. info->weak_count = node->local_weak_refs;
  5042. binder_put_node(node);
  5043. return 0;
  5044. }
  5045. static int binder_ioctl_get_node_debug_info(struct binder_proc *proc,
  5046. struct binder_node_debug_info *info)
  5047. {
  5048. struct rb_node *n;
  5049. binder_uintptr_t ptr = info->ptr;
  5050. memset(info, 0, sizeof(*info));
  5051. binder_inner_proc_lock(proc);
  5052. for (n = rb_first(&proc->nodes); n != NULL; n = rb_next(n)) {
  5053. struct binder_node *node = rb_entry(n, struct binder_node,
  5054. rb_node);
  5055. if (node->ptr > ptr) {
  5056. info->ptr = node->ptr;
  5057. info->cookie = node->cookie;
  5058. info->has_strong_ref = node->has_strong_ref;
  5059. info->has_weak_ref = node->has_weak_ref;
  5060. break;
  5061. }
  5062. }
  5063. binder_inner_proc_unlock(proc);
  5064. return 0;
  5065. }
  5066. static bool binder_txns_pending_ilocked(struct binder_proc *proc)
  5067. {
  5068. struct rb_node *n;
  5069. struct binder_thread *thread;
  5070. if (proc->outstanding_txns > 0)
  5071. return true;
  5072. for (n = rb_first(&proc->threads); n; n = rb_next(n)) {
  5073. thread = rb_entry(n, struct binder_thread, rb_node);
  5074. if (thread->transaction_stack)
  5075. return true;
  5076. }
  5077. return false;
  5078. }
  5079. static void binder_add_freeze_work(struct binder_proc *proc, bool is_frozen)
  5080. {
  5081. struct binder_node *prev = NULL;
  5082. struct rb_node *n;
  5083. struct binder_ref *ref;
  5084. binder_inner_proc_lock(proc);
  5085. for (n = rb_first(&proc->nodes); n; n = rb_next(n)) {
  5086. struct binder_node *node;
  5087. node = rb_entry(n, struct binder_node, rb_node);
  5088. binder_inc_node_tmpref_ilocked(node);
  5089. binder_inner_proc_unlock(proc);
  5090. if (prev)
  5091. binder_put_node(prev);
  5092. binder_node_lock(node);
  5093. hlist_for_each_entry(ref, &node->refs, node_entry) {
  5094. /*
  5095. * Need the node lock to synchronize
  5096. * with new notification requests and the
  5097. * inner lock to synchronize with queued
  5098. * freeze notifications.
  5099. */
  5100. binder_inner_proc_lock(ref->proc);
  5101. if (!ref->freeze) {
  5102. binder_inner_proc_unlock(ref->proc);
  5103. continue;
  5104. }
  5105. ref->freeze->work.type = BINDER_WORK_FROZEN_BINDER;
  5106. if (list_empty(&ref->freeze->work.entry)) {
  5107. ref->freeze->is_frozen = is_frozen;
  5108. binder_enqueue_work_ilocked(&ref->freeze->work, &ref->proc->todo);
  5109. binder_wakeup_proc_ilocked(ref->proc);
  5110. } else {
  5111. if (ref->freeze->sent && ref->freeze->is_frozen != is_frozen)
  5112. ref->freeze->resend = true;
  5113. ref->freeze->is_frozen = is_frozen;
  5114. }
  5115. binder_inner_proc_unlock(ref->proc);
  5116. }
  5117. prev = node;
  5118. binder_node_unlock(node);
  5119. binder_inner_proc_lock(proc);
  5120. if (proc->is_dead)
  5121. break;
  5122. }
  5123. binder_inner_proc_unlock(proc);
  5124. if (prev)
  5125. binder_put_node(prev);
  5126. }
  5127. static int binder_ioctl_freeze(struct binder_freeze_info *info,
  5128. struct binder_proc *target_proc)
  5129. {
  5130. int ret = 0;
  5131. if (!info->enable) {
  5132. binder_inner_proc_lock(target_proc);
  5133. target_proc->sync_recv = false;
  5134. target_proc->async_recv = false;
  5135. target_proc->is_frozen = false;
  5136. binder_inner_proc_unlock(target_proc);
  5137. binder_add_freeze_work(target_proc, false);
  5138. return 0;
  5139. }
  5140. /*
  5141. * Freezing the target. Prevent new transactions by
  5142. * setting frozen state. If timeout specified, wait
  5143. * for transactions to drain.
  5144. */
  5145. binder_inner_proc_lock(target_proc);
  5146. target_proc->sync_recv = false;
  5147. target_proc->async_recv = false;
  5148. target_proc->is_frozen = true;
  5149. binder_inner_proc_unlock(target_proc);
  5150. if (info->timeout_ms > 0)
  5151. ret = wait_event_interruptible_timeout(
  5152. target_proc->freeze_wait,
  5153. (!target_proc->outstanding_txns),
  5154. msecs_to_jiffies(info->timeout_ms));
  5155. /* Check pending transactions that wait for reply */
  5156. if (ret >= 0) {
  5157. binder_inner_proc_lock(target_proc);
  5158. if (binder_txns_pending_ilocked(target_proc))
  5159. ret = -EAGAIN;
  5160. binder_inner_proc_unlock(target_proc);
  5161. }
  5162. if (ret < 0) {
  5163. binder_inner_proc_lock(target_proc);
  5164. target_proc->is_frozen = false;
  5165. binder_inner_proc_unlock(target_proc);
  5166. } else {
  5167. binder_add_freeze_work(target_proc, true);
  5168. }
  5169. return ret;
  5170. }
  5171. static int binder_ioctl_get_freezer_info(
  5172. struct binder_frozen_status_info *info)
  5173. {
  5174. struct binder_proc *target_proc;
  5175. bool found = false;
  5176. __u32 txns_pending;
  5177. info->sync_recv = 0;
  5178. info->async_recv = 0;
  5179. mutex_lock(&binder_procs_lock);
  5180. hlist_for_each_entry(target_proc, &binder_procs, proc_node) {
  5181. if (target_proc->pid == info->pid) {
  5182. found = true;
  5183. binder_inner_proc_lock(target_proc);
  5184. txns_pending = binder_txns_pending_ilocked(target_proc);
  5185. info->sync_recv |= target_proc->sync_recv |
  5186. (txns_pending << 1);
  5187. info->async_recv |= target_proc->async_recv;
  5188. binder_inner_proc_unlock(target_proc);
  5189. }
  5190. }
  5191. mutex_unlock(&binder_procs_lock);
  5192. if (!found)
  5193. return -EINVAL;
  5194. return 0;
  5195. }
  5196. static int binder_ioctl_get_extended_error(struct binder_thread *thread,
  5197. void __user *ubuf)
  5198. {
  5199. struct binder_extended_error ee;
  5200. binder_inner_proc_lock(thread->proc);
  5201. ee = thread->ee;
  5202. binder_set_extended_error(&thread->ee, 0, BR_OK, 0);
  5203. binder_inner_proc_unlock(thread->proc);
  5204. if (copy_to_user(ubuf, &ee, sizeof(ee)))
  5205. return -EFAULT;
  5206. return 0;
  5207. }
  5208. static long binder_ioctl(struct file *filp, unsigned int cmd, unsigned long arg)
  5209. {
  5210. int ret;
  5211. struct binder_proc *proc = filp->private_data;
  5212. struct binder_thread *thread;
  5213. void __user *ubuf = (void __user *)arg;
  5214. /*pr_info("binder_ioctl: %d:%d %x %lx\n",
  5215. proc->pid, current->pid, cmd, arg);*/
  5216. binder_selftest_alloc(&proc->alloc);
  5217. trace_binder_ioctl(cmd, arg);
  5218. ret = wait_event_interruptible(binder_user_error_wait, binder_stop_on_user_error < 2);
  5219. if (ret)
  5220. goto err_unlocked;
  5221. thread = binder_get_thread(proc);
  5222. if (thread == NULL) {
  5223. ret = -ENOMEM;
  5224. goto err;
  5225. }
  5226. switch (cmd) {
  5227. case BINDER_WRITE_READ:
  5228. ret = binder_ioctl_write_read(filp, arg, thread);
  5229. if (ret)
  5230. goto err;
  5231. break;
  5232. case BINDER_SET_MAX_THREADS: {
  5233. u32 max_threads;
  5234. if (copy_from_user(&max_threads, ubuf,
  5235. sizeof(max_threads))) {
  5236. ret = -EINVAL;
  5237. goto err;
  5238. }
  5239. binder_inner_proc_lock(proc);
  5240. proc->max_threads = max_threads;
  5241. binder_inner_proc_unlock(proc);
  5242. break;
  5243. }
  5244. case BINDER_SET_CONTEXT_MGR_EXT: {
  5245. struct flat_binder_object fbo;
  5246. if (copy_from_user(&fbo, ubuf, sizeof(fbo))) {
  5247. ret = -EINVAL;
  5248. goto err;
  5249. }
  5250. ret = binder_ioctl_set_ctx_mgr(filp, &fbo);
  5251. if (ret)
  5252. goto err;
  5253. break;
  5254. }
  5255. case BINDER_SET_CONTEXT_MGR:
  5256. ret = binder_ioctl_set_ctx_mgr(filp, NULL);
  5257. if (ret)
  5258. goto err;
  5259. break;
  5260. case BINDER_THREAD_EXIT:
  5261. binder_debug(BINDER_DEBUG_THREADS, "%d:%d exit\n",
  5262. proc->pid, thread->pid);
  5263. binder_thread_release(proc, thread);
  5264. thread = NULL;
  5265. break;
  5266. case BINDER_VERSION: {
  5267. struct binder_version __user *ver = ubuf;
  5268. if (put_user(BINDER_CURRENT_PROTOCOL_VERSION,
  5269. &ver->protocol_version)) {
  5270. ret = -EINVAL;
  5271. goto err;
  5272. }
  5273. break;
  5274. }
  5275. case BINDER_GET_NODE_INFO_FOR_REF: {
  5276. struct binder_node_info_for_ref info;
  5277. if (copy_from_user(&info, ubuf, sizeof(info))) {
  5278. ret = -EFAULT;
  5279. goto err;
  5280. }
  5281. ret = binder_ioctl_get_node_info_for_ref(proc, &info);
  5282. if (ret < 0)
  5283. goto err;
  5284. if (copy_to_user(ubuf, &info, sizeof(info))) {
  5285. ret = -EFAULT;
  5286. goto err;
  5287. }
  5288. break;
  5289. }
  5290. case BINDER_GET_NODE_DEBUG_INFO: {
  5291. struct binder_node_debug_info info;
  5292. if (copy_from_user(&info, ubuf, sizeof(info))) {
  5293. ret = -EFAULT;
  5294. goto err;
  5295. }
  5296. ret = binder_ioctl_get_node_debug_info(proc, &info);
  5297. if (ret < 0)
  5298. goto err;
  5299. if (copy_to_user(ubuf, &info, sizeof(info))) {
  5300. ret = -EFAULT;
  5301. goto err;
  5302. }
  5303. break;
  5304. }
  5305. case BINDER_FREEZE: {
  5306. struct binder_freeze_info info;
  5307. struct binder_proc **target_procs = NULL, *target_proc;
  5308. int target_procs_count = 0, i = 0;
  5309. ret = 0;
  5310. if (copy_from_user(&info, ubuf, sizeof(info))) {
  5311. ret = -EFAULT;
  5312. goto err;
  5313. }
  5314. mutex_lock(&binder_procs_lock);
  5315. hlist_for_each_entry(target_proc, &binder_procs, proc_node) {
  5316. if (target_proc->pid == info.pid)
  5317. target_procs_count++;
  5318. }
  5319. if (target_procs_count == 0) {
  5320. mutex_unlock(&binder_procs_lock);
  5321. ret = -EINVAL;
  5322. goto err;
  5323. }
  5324. target_procs = kcalloc(target_procs_count,
  5325. sizeof(struct binder_proc *),
  5326. GFP_KERNEL);
  5327. if (!target_procs) {
  5328. mutex_unlock(&binder_procs_lock);
  5329. ret = -ENOMEM;
  5330. goto err;
  5331. }
  5332. hlist_for_each_entry(target_proc, &binder_procs, proc_node) {
  5333. if (target_proc->pid != info.pid)
  5334. continue;
  5335. binder_inner_proc_lock(target_proc);
  5336. target_proc->tmp_ref++;
  5337. binder_inner_proc_unlock(target_proc);
  5338. target_procs[i++] = target_proc;
  5339. }
  5340. mutex_unlock(&binder_procs_lock);
  5341. for (i = 0; i < target_procs_count; i++) {
  5342. if (ret >= 0)
  5343. ret = binder_ioctl_freeze(&info,
  5344. target_procs[i]);
  5345. binder_proc_dec_tmpref(target_procs[i]);
  5346. }
  5347. kfree(target_procs);
  5348. if (ret < 0)
  5349. goto err;
  5350. break;
  5351. }
  5352. case BINDER_GET_FROZEN_INFO: {
  5353. struct binder_frozen_status_info info;
  5354. if (copy_from_user(&info, ubuf, sizeof(info))) {
  5355. ret = -EFAULT;
  5356. goto err;
  5357. }
  5358. ret = binder_ioctl_get_freezer_info(&info);
  5359. if (ret < 0)
  5360. goto err;
  5361. if (copy_to_user(ubuf, &info, sizeof(info))) {
  5362. ret = -EFAULT;
  5363. goto err;
  5364. }
  5365. break;
  5366. }
  5367. case BINDER_ENABLE_ONEWAY_SPAM_DETECTION: {
  5368. uint32_t enable;
  5369. if (copy_from_user(&enable, ubuf, sizeof(enable))) {
  5370. ret = -EFAULT;
  5371. goto err;
  5372. }
  5373. binder_inner_proc_lock(proc);
  5374. proc->oneway_spam_detection_enabled = (bool)enable;
  5375. binder_inner_proc_unlock(proc);
  5376. break;
  5377. }
  5378. case BINDER_GET_EXTENDED_ERROR:
  5379. ret = binder_ioctl_get_extended_error(thread, ubuf);
  5380. if (ret < 0)
  5381. goto err;
  5382. break;
  5383. default:
  5384. ret = -EINVAL;
  5385. goto err;
  5386. }
  5387. ret = 0;
  5388. err:
  5389. if (thread)
  5390. thread->looper_need_return = false;
  5391. wait_event_interruptible(binder_user_error_wait, binder_stop_on_user_error < 2);
  5392. if (ret && ret != -EINTR)
  5393. pr_info("%d:%d ioctl %x %lx returned %d\n", proc->pid, current->pid, cmd, arg, ret);
  5394. err_unlocked:
  5395. trace_binder_ioctl_done(ret);
  5396. return ret;
  5397. }
  5398. static void binder_vma_open(struct vm_area_struct *vma)
  5399. {
  5400. struct binder_proc *proc = vma->vm_private_data;
  5401. binder_debug(BINDER_DEBUG_OPEN_CLOSE,
  5402. "%d open vm area %lx-%lx (%ld K) vma %lx pagep %lx\n",
  5403. proc->pid, vma->vm_start, vma->vm_end,
  5404. (vma->vm_end - vma->vm_start) / SZ_1K, vma->vm_flags,
  5405. (unsigned long)pgprot_val(vma->vm_page_prot));
  5406. }
  5407. static void binder_vma_close(struct vm_area_struct *vma)
  5408. {
  5409. struct binder_proc *proc = vma->vm_private_data;
  5410. binder_debug(BINDER_DEBUG_OPEN_CLOSE,
  5411. "%d close vm area %lx-%lx (%ld K) vma %lx pagep %lx\n",
  5412. proc->pid, vma->vm_start, vma->vm_end,
  5413. (vma->vm_end - vma->vm_start) / SZ_1K, vma->vm_flags,
  5414. (unsigned long)pgprot_val(vma->vm_page_prot));
  5415. binder_alloc_vma_close(&proc->alloc);
  5416. }
  5417. static vm_fault_t binder_vm_fault(struct vm_fault *vmf)
  5418. {
  5419. return VM_FAULT_SIGBUS;
  5420. }
  5421. static const struct vm_operations_struct binder_vm_ops = {
  5422. .open = binder_vma_open,
  5423. .close = binder_vma_close,
  5424. .fault = binder_vm_fault,
  5425. };
  5426. static int binder_mmap(struct file *filp, struct vm_area_struct *vma)
  5427. {
  5428. struct binder_proc *proc = filp->private_data;
  5429. if (proc->tsk != current->group_leader)
  5430. return -EINVAL;
  5431. binder_debug(BINDER_DEBUG_OPEN_CLOSE,
  5432. "%s: %d %lx-%lx (%ld K) vma %lx pagep %lx\n",
  5433. __func__, proc->pid, vma->vm_start, vma->vm_end,
  5434. (vma->vm_end - vma->vm_start) / SZ_1K, vma->vm_flags,
  5435. (unsigned long)pgprot_val(vma->vm_page_prot));
  5436. if (vma->vm_flags & FORBIDDEN_MMAP_FLAGS) {
  5437. pr_err("%s: %d %lx-%lx %s failed %d\n", __func__,
  5438. proc->pid, vma->vm_start, vma->vm_end, "bad vm_flags", -EPERM);
  5439. return -EPERM;
  5440. }
  5441. vm_flags_mod(vma, VM_DONTCOPY | VM_MIXEDMAP, VM_MAYWRITE);
  5442. vma->vm_ops = &binder_vm_ops;
  5443. vma->vm_private_data = proc;
  5444. return binder_alloc_mmap_handler(&proc->alloc, vma);
  5445. }
  5446. static int binder_open(struct inode *nodp, struct file *filp)
  5447. {
  5448. struct binder_proc *proc, *itr;
  5449. struct binder_device *binder_dev;
  5450. struct binderfs_info *info;
  5451. struct dentry *binder_binderfs_dir_entry_proc = NULL;
  5452. bool existing_pid = false;
  5453. binder_debug(BINDER_DEBUG_OPEN_CLOSE, "%s: %d:%d\n", __func__,
  5454. current->group_leader->pid, current->pid);
  5455. proc = kzalloc(sizeof(*proc), GFP_KERNEL);
  5456. if (proc == NULL)
  5457. return -ENOMEM;
  5458. dbitmap_init(&proc->dmap);
  5459. spin_lock_init(&proc->inner_lock);
  5460. spin_lock_init(&proc->outer_lock);
  5461. get_task_struct(current->group_leader);
  5462. proc->tsk = current->group_leader;
  5463. proc->cred = get_cred(filp->f_cred);
  5464. INIT_LIST_HEAD(&proc->todo);
  5465. init_waitqueue_head(&proc->freeze_wait);
  5466. proc->default_priority = task_nice(current);
  5467. /* binderfs stashes devices in i_private */
  5468. if (is_binderfs_device(nodp)) {
  5469. binder_dev = nodp->i_private;
  5470. info = nodp->i_sb->s_fs_info;
  5471. binder_binderfs_dir_entry_proc = info->proc_log_dir;
  5472. } else {
  5473. binder_dev = container_of(filp->private_data,
  5474. struct binder_device, miscdev);
  5475. }
  5476. refcount_inc(&binder_dev->ref);
  5477. proc->context = &binder_dev->context;
  5478. binder_alloc_init(&proc->alloc);
  5479. binder_stats_created(BINDER_STAT_PROC);
  5480. proc->pid = current->group_leader->pid;
  5481. INIT_LIST_HEAD(&proc->delivered_death);
  5482. INIT_LIST_HEAD(&proc->delivered_freeze);
  5483. INIT_LIST_HEAD(&proc->waiting_threads);
  5484. filp->private_data = proc;
  5485. mutex_lock(&binder_procs_lock);
  5486. hlist_for_each_entry(itr, &binder_procs, proc_node) {
  5487. if (itr->pid == proc->pid) {
  5488. existing_pid = true;
  5489. break;
  5490. }
  5491. }
  5492. hlist_add_head(&proc->proc_node, &binder_procs);
  5493. mutex_unlock(&binder_procs_lock);
  5494. if (binder_debugfs_dir_entry_proc && !existing_pid) {
  5495. char strbuf[11];
  5496. snprintf(strbuf, sizeof(strbuf), "%u", proc->pid);
  5497. /*
  5498. * proc debug entries are shared between contexts.
  5499. * Only create for the first PID to avoid debugfs log spamming
  5500. * The printing code will anyway print all contexts for a given
  5501. * PID so this is not a problem.
  5502. */
  5503. proc->debugfs_entry = debugfs_create_file(strbuf, 0444,
  5504. binder_debugfs_dir_entry_proc,
  5505. (void *)(unsigned long)proc->pid,
  5506. &proc_fops);
  5507. }
  5508. if (binder_binderfs_dir_entry_proc && !existing_pid) {
  5509. char strbuf[11];
  5510. struct dentry *binderfs_entry;
  5511. snprintf(strbuf, sizeof(strbuf), "%u", proc->pid);
  5512. /*
  5513. * Similar to debugfs, the process specific log file is shared
  5514. * between contexts. Only create for the first PID.
  5515. * This is ok since same as debugfs, the log file will contain
  5516. * information on all contexts of a given PID.
  5517. */
  5518. binderfs_entry = binderfs_create_file(binder_binderfs_dir_entry_proc,
  5519. strbuf, &proc_fops, (void *)(unsigned long)proc->pid);
  5520. if (!IS_ERR(binderfs_entry)) {
  5521. proc->binderfs_entry = binderfs_entry;
  5522. } else {
  5523. int error;
  5524. error = PTR_ERR(binderfs_entry);
  5525. pr_warn("Unable to create file %s in binderfs (error %d)\n",
  5526. strbuf, error);
  5527. }
  5528. }
  5529. return 0;
  5530. }
  5531. static int binder_flush(struct file *filp, fl_owner_t id)
  5532. {
  5533. struct binder_proc *proc = filp->private_data;
  5534. binder_defer_work(proc, BINDER_DEFERRED_FLUSH);
  5535. return 0;
  5536. }
  5537. static void binder_deferred_flush(struct binder_proc *proc)
  5538. {
  5539. struct rb_node *n;
  5540. int wake_count = 0;
  5541. binder_inner_proc_lock(proc);
  5542. for (n = rb_first(&proc->threads); n != NULL; n = rb_next(n)) {
  5543. struct binder_thread *thread = rb_entry(n, struct binder_thread, rb_node);
  5544. thread->looper_need_return = true;
  5545. if (thread->looper & BINDER_LOOPER_STATE_WAITING) {
  5546. wake_up_interruptible(&thread->wait);
  5547. wake_count++;
  5548. }
  5549. }
  5550. binder_inner_proc_unlock(proc);
  5551. binder_debug(BINDER_DEBUG_OPEN_CLOSE,
  5552. "binder_flush: %d woke %d threads\n", proc->pid,
  5553. wake_count);
  5554. }
  5555. static int binder_release(struct inode *nodp, struct file *filp)
  5556. {
  5557. struct binder_proc *proc = filp->private_data;
  5558. debugfs_remove(proc->debugfs_entry);
  5559. if (proc->binderfs_entry) {
  5560. binderfs_remove_file(proc->binderfs_entry);
  5561. proc->binderfs_entry = NULL;
  5562. }
  5563. binder_defer_work(proc, BINDER_DEFERRED_RELEASE);
  5564. return 0;
  5565. }
  5566. static int binder_node_release(struct binder_node *node, int refs)
  5567. {
  5568. struct binder_ref *ref;
  5569. int death = 0;
  5570. struct binder_proc *proc = node->proc;
  5571. binder_release_work(proc, &node->async_todo);
  5572. binder_node_lock(node);
  5573. binder_inner_proc_lock(proc);
  5574. binder_dequeue_work_ilocked(&node->work);
  5575. /*
  5576. * The caller must have taken a temporary ref on the node,
  5577. */
  5578. BUG_ON(!node->tmp_refs);
  5579. if (hlist_empty(&node->refs) && node->tmp_refs == 1) {
  5580. binder_inner_proc_unlock(proc);
  5581. binder_node_unlock(node);
  5582. binder_free_node(node);
  5583. return refs;
  5584. }
  5585. node->proc = NULL;
  5586. node->local_strong_refs = 0;
  5587. node->local_weak_refs = 0;
  5588. binder_inner_proc_unlock(proc);
  5589. spin_lock(&binder_dead_nodes_lock);
  5590. hlist_add_head(&node->dead_node, &binder_dead_nodes);
  5591. spin_unlock(&binder_dead_nodes_lock);
  5592. hlist_for_each_entry(ref, &node->refs, node_entry) {
  5593. refs++;
  5594. /*
  5595. * Need the node lock to synchronize
  5596. * with new notification requests and the
  5597. * inner lock to synchronize with queued
  5598. * death notifications.
  5599. */
  5600. binder_inner_proc_lock(ref->proc);
  5601. if (!ref->death) {
  5602. binder_inner_proc_unlock(ref->proc);
  5603. continue;
  5604. }
  5605. death++;
  5606. BUG_ON(!list_empty(&ref->death->work.entry));
  5607. ref->death->work.type = BINDER_WORK_DEAD_BINDER;
  5608. binder_enqueue_work_ilocked(&ref->death->work,
  5609. &ref->proc->todo);
  5610. binder_wakeup_proc_ilocked(ref->proc);
  5611. binder_inner_proc_unlock(ref->proc);
  5612. }
  5613. binder_debug(BINDER_DEBUG_DEAD_BINDER,
  5614. "node %d now dead, refs %d, death %d\n",
  5615. node->debug_id, refs, death);
  5616. binder_node_unlock(node);
  5617. binder_put_node(node);
  5618. return refs;
  5619. }
  5620. static void binder_deferred_release(struct binder_proc *proc)
  5621. {
  5622. struct binder_context *context = proc->context;
  5623. struct rb_node *n;
  5624. int threads, nodes, incoming_refs, outgoing_refs, active_transactions;
  5625. mutex_lock(&binder_procs_lock);
  5626. hlist_del(&proc->proc_node);
  5627. mutex_unlock(&binder_procs_lock);
  5628. mutex_lock(&context->context_mgr_node_lock);
  5629. if (context->binder_context_mgr_node &&
  5630. context->binder_context_mgr_node->proc == proc) {
  5631. binder_debug(BINDER_DEBUG_DEAD_BINDER,
  5632. "%s: %d context_mgr_node gone\n",
  5633. __func__, proc->pid);
  5634. context->binder_context_mgr_node = NULL;
  5635. }
  5636. mutex_unlock(&context->context_mgr_node_lock);
  5637. binder_inner_proc_lock(proc);
  5638. /*
  5639. * Make sure proc stays alive after we
  5640. * remove all the threads
  5641. */
  5642. proc->tmp_ref++;
  5643. proc->is_dead = true;
  5644. proc->is_frozen = false;
  5645. proc->sync_recv = false;
  5646. proc->async_recv = false;
  5647. threads = 0;
  5648. active_transactions = 0;
  5649. while ((n = rb_first(&proc->threads))) {
  5650. struct binder_thread *thread;
  5651. thread = rb_entry(n, struct binder_thread, rb_node);
  5652. binder_inner_proc_unlock(proc);
  5653. threads++;
  5654. active_transactions += binder_thread_release(proc, thread);
  5655. binder_inner_proc_lock(proc);
  5656. }
  5657. nodes = 0;
  5658. incoming_refs = 0;
  5659. while ((n = rb_first(&proc->nodes))) {
  5660. struct binder_node *node;
  5661. node = rb_entry(n, struct binder_node, rb_node);
  5662. nodes++;
  5663. /*
  5664. * take a temporary ref on the node before
  5665. * calling binder_node_release() which will either
  5666. * kfree() the node or call binder_put_node()
  5667. */
  5668. binder_inc_node_tmpref_ilocked(node);
  5669. rb_erase(&node->rb_node, &proc->nodes);
  5670. binder_inner_proc_unlock(proc);
  5671. incoming_refs = binder_node_release(node, incoming_refs);
  5672. binder_inner_proc_lock(proc);
  5673. }
  5674. binder_inner_proc_unlock(proc);
  5675. outgoing_refs = 0;
  5676. binder_proc_lock(proc);
  5677. while ((n = rb_first(&proc->refs_by_desc))) {
  5678. struct binder_ref *ref;
  5679. ref = rb_entry(n, struct binder_ref, rb_node_desc);
  5680. outgoing_refs++;
  5681. binder_cleanup_ref_olocked(ref);
  5682. binder_proc_unlock(proc);
  5683. binder_free_ref(ref);
  5684. binder_proc_lock(proc);
  5685. }
  5686. binder_proc_unlock(proc);
  5687. binder_release_work(proc, &proc->todo);
  5688. binder_release_work(proc, &proc->delivered_death);
  5689. binder_release_work(proc, &proc->delivered_freeze);
  5690. binder_debug(BINDER_DEBUG_OPEN_CLOSE,
  5691. "%s: %d threads %d, nodes %d (ref %d), refs %d, active transactions %d\n",
  5692. __func__, proc->pid, threads, nodes, incoming_refs,
  5693. outgoing_refs, active_transactions);
  5694. binder_proc_dec_tmpref(proc);
  5695. }
  5696. static void binder_deferred_func(struct work_struct *work)
  5697. {
  5698. struct binder_proc *proc;
  5699. int defer;
  5700. do {
  5701. mutex_lock(&binder_deferred_lock);
  5702. if (!hlist_empty(&binder_deferred_list)) {
  5703. proc = hlist_entry(binder_deferred_list.first,
  5704. struct binder_proc, deferred_work_node);
  5705. hlist_del_init(&proc->deferred_work_node);
  5706. defer = proc->deferred_work;
  5707. proc->deferred_work = 0;
  5708. } else {
  5709. proc = NULL;
  5710. defer = 0;
  5711. }
  5712. mutex_unlock(&binder_deferred_lock);
  5713. if (defer & BINDER_DEFERRED_FLUSH)
  5714. binder_deferred_flush(proc);
  5715. if (defer & BINDER_DEFERRED_RELEASE)
  5716. binder_deferred_release(proc); /* frees proc */
  5717. } while (proc);
  5718. }
  5719. static DECLARE_WORK(binder_deferred_work, binder_deferred_func);
  5720. static void
  5721. binder_defer_work(struct binder_proc *proc, enum binder_deferred_state defer)
  5722. {
  5723. mutex_lock(&binder_deferred_lock);
  5724. proc->deferred_work |= defer;
  5725. if (hlist_unhashed(&proc->deferred_work_node)) {
  5726. hlist_add_head(&proc->deferred_work_node,
  5727. &binder_deferred_list);
  5728. schedule_work(&binder_deferred_work);
  5729. }
  5730. mutex_unlock(&binder_deferred_lock);
  5731. }
  5732. static void print_binder_transaction_ilocked(struct seq_file *m,
  5733. struct binder_proc *proc,
  5734. const char *prefix,
  5735. struct binder_transaction *t)
  5736. {
  5737. struct binder_proc *to_proc;
  5738. struct binder_buffer *buffer = t->buffer;
  5739. ktime_t current_time = ktime_get();
  5740. spin_lock(&t->lock);
  5741. to_proc = t->to_proc;
  5742. seq_printf(m,
  5743. "%s %d: %pK from %d:%d to %d:%d code %x flags %x pri %ld r%d elapsed %lldms",
  5744. prefix, t->debug_id, t,
  5745. t->from_pid,
  5746. t->from_tid,
  5747. to_proc ? to_proc->pid : 0,
  5748. t->to_thread ? t->to_thread->pid : 0,
  5749. t->code, t->flags, t->priority, t->need_reply,
  5750. ktime_ms_delta(current_time, t->start_time));
  5751. spin_unlock(&t->lock);
  5752. if (proc != to_proc) {
  5753. /*
  5754. * Can only safely deref buffer if we are holding the
  5755. * correct proc inner lock for this node
  5756. */
  5757. seq_puts(m, "\n");
  5758. return;
  5759. }
  5760. if (buffer == NULL) {
  5761. seq_puts(m, " buffer free\n");
  5762. return;
  5763. }
  5764. if (buffer->target_node)
  5765. seq_printf(m, " node %d", buffer->target_node->debug_id);
  5766. seq_printf(m, " size %zd:%zd offset %lx\n",
  5767. buffer->data_size, buffer->offsets_size,
  5768. buffer->user_data - proc->alloc.buffer);
  5769. }
  5770. static void print_binder_work_ilocked(struct seq_file *m,
  5771. struct binder_proc *proc,
  5772. const char *prefix,
  5773. const char *transaction_prefix,
  5774. struct binder_work *w)
  5775. {
  5776. struct binder_node *node;
  5777. struct binder_transaction *t;
  5778. switch (w->type) {
  5779. case BINDER_WORK_TRANSACTION:
  5780. t = container_of(w, struct binder_transaction, work);
  5781. print_binder_transaction_ilocked(
  5782. m, proc, transaction_prefix, t);
  5783. break;
  5784. case BINDER_WORK_RETURN_ERROR: {
  5785. struct binder_error *e = container_of(
  5786. w, struct binder_error, work);
  5787. seq_printf(m, "%stransaction error: %u\n",
  5788. prefix, e->cmd);
  5789. } break;
  5790. case BINDER_WORK_TRANSACTION_COMPLETE:
  5791. seq_printf(m, "%stransaction complete\n", prefix);
  5792. break;
  5793. case BINDER_WORK_NODE:
  5794. node = container_of(w, struct binder_node, work);
  5795. seq_printf(m, "%snode work %d: u%016llx c%016llx\n",
  5796. prefix, node->debug_id,
  5797. (u64)node->ptr, (u64)node->cookie);
  5798. break;
  5799. case BINDER_WORK_DEAD_BINDER:
  5800. seq_printf(m, "%shas dead binder\n", prefix);
  5801. break;
  5802. case BINDER_WORK_DEAD_BINDER_AND_CLEAR:
  5803. seq_printf(m, "%shas cleared dead binder\n", prefix);
  5804. break;
  5805. case BINDER_WORK_CLEAR_DEATH_NOTIFICATION:
  5806. seq_printf(m, "%shas cleared death notification\n", prefix);
  5807. break;
  5808. case BINDER_WORK_FROZEN_BINDER:
  5809. seq_printf(m, "%shas frozen binder\n", prefix);
  5810. break;
  5811. case BINDER_WORK_CLEAR_FREEZE_NOTIFICATION:
  5812. seq_printf(m, "%shas cleared freeze notification\n", prefix);
  5813. break;
  5814. default:
  5815. seq_printf(m, "%sunknown work: type %d\n", prefix, w->type);
  5816. break;
  5817. }
  5818. }
  5819. static void print_binder_thread_ilocked(struct seq_file *m,
  5820. struct binder_thread *thread,
  5821. int print_always)
  5822. {
  5823. struct binder_transaction *t;
  5824. struct binder_work *w;
  5825. size_t start_pos = m->count;
  5826. size_t header_pos;
  5827. seq_printf(m, " thread %d: l %02x need_return %d tr %d\n",
  5828. thread->pid, thread->looper,
  5829. thread->looper_need_return,
  5830. atomic_read(&thread->tmp_ref));
  5831. header_pos = m->count;
  5832. t = thread->transaction_stack;
  5833. while (t) {
  5834. if (t->from == thread) {
  5835. print_binder_transaction_ilocked(m, thread->proc,
  5836. " outgoing transaction", t);
  5837. t = t->from_parent;
  5838. } else if (t->to_thread == thread) {
  5839. print_binder_transaction_ilocked(m, thread->proc,
  5840. " incoming transaction", t);
  5841. t = t->to_parent;
  5842. } else {
  5843. print_binder_transaction_ilocked(m, thread->proc,
  5844. " bad transaction", t);
  5845. t = NULL;
  5846. }
  5847. }
  5848. list_for_each_entry(w, &thread->todo, entry) {
  5849. print_binder_work_ilocked(m, thread->proc, " ",
  5850. " pending transaction", w);
  5851. }
  5852. if (!print_always && m->count == header_pos)
  5853. m->count = start_pos;
  5854. }
  5855. static void print_binder_node_nilocked(struct seq_file *m,
  5856. struct binder_node *node)
  5857. {
  5858. struct binder_ref *ref;
  5859. struct binder_work *w;
  5860. int count;
  5861. count = hlist_count_nodes(&node->refs);
  5862. seq_printf(m, " node %d: u%016llx c%016llx hs %d hw %d ls %d lw %d is %d iw %d tr %d",
  5863. node->debug_id, (u64)node->ptr, (u64)node->cookie,
  5864. node->has_strong_ref, node->has_weak_ref,
  5865. node->local_strong_refs, node->local_weak_refs,
  5866. node->internal_strong_refs, count, node->tmp_refs);
  5867. if (count) {
  5868. seq_puts(m, " proc");
  5869. hlist_for_each_entry(ref, &node->refs, node_entry)
  5870. seq_printf(m, " %d", ref->proc->pid);
  5871. }
  5872. seq_puts(m, "\n");
  5873. if (node->proc) {
  5874. list_for_each_entry(w, &node->async_todo, entry)
  5875. print_binder_work_ilocked(m, node->proc, " ",
  5876. " pending async transaction", w);
  5877. }
  5878. }
  5879. static void print_binder_ref_olocked(struct seq_file *m,
  5880. struct binder_ref *ref)
  5881. {
  5882. binder_node_lock(ref->node);
  5883. seq_printf(m, " ref %d: desc %d %snode %d s %d w %d d %pK\n",
  5884. ref->data.debug_id, ref->data.desc,
  5885. ref->node->proc ? "" : "dead ",
  5886. ref->node->debug_id, ref->data.strong,
  5887. ref->data.weak, ref->death);
  5888. binder_node_unlock(ref->node);
  5889. }
  5890. static void print_binder_proc(struct seq_file *m,
  5891. struct binder_proc *proc, int print_all)
  5892. {
  5893. struct binder_work *w;
  5894. struct rb_node *n;
  5895. size_t start_pos = m->count;
  5896. size_t header_pos;
  5897. struct binder_node *last_node = NULL;
  5898. seq_printf(m, "proc %d\n", proc->pid);
  5899. seq_printf(m, "context %s\n", proc->context->name);
  5900. header_pos = m->count;
  5901. binder_inner_proc_lock(proc);
  5902. for (n = rb_first(&proc->threads); n != NULL; n = rb_next(n))
  5903. print_binder_thread_ilocked(m, rb_entry(n, struct binder_thread,
  5904. rb_node), print_all);
  5905. for (n = rb_first(&proc->nodes); n != NULL; n = rb_next(n)) {
  5906. struct binder_node *node = rb_entry(n, struct binder_node,
  5907. rb_node);
  5908. if (!print_all && !node->has_async_transaction)
  5909. continue;
  5910. /*
  5911. * take a temporary reference on the node so it
  5912. * survives and isn't removed from the tree
  5913. * while we print it.
  5914. */
  5915. binder_inc_node_tmpref_ilocked(node);
  5916. /* Need to drop inner lock to take node lock */
  5917. binder_inner_proc_unlock(proc);
  5918. if (last_node)
  5919. binder_put_node(last_node);
  5920. binder_node_inner_lock(node);
  5921. print_binder_node_nilocked(m, node);
  5922. binder_node_inner_unlock(node);
  5923. last_node = node;
  5924. binder_inner_proc_lock(proc);
  5925. }
  5926. binder_inner_proc_unlock(proc);
  5927. if (last_node)
  5928. binder_put_node(last_node);
  5929. if (print_all) {
  5930. binder_proc_lock(proc);
  5931. for (n = rb_first(&proc->refs_by_desc);
  5932. n != NULL;
  5933. n = rb_next(n))
  5934. print_binder_ref_olocked(m, rb_entry(n,
  5935. struct binder_ref,
  5936. rb_node_desc));
  5937. binder_proc_unlock(proc);
  5938. }
  5939. binder_alloc_print_allocated(m, &proc->alloc);
  5940. binder_inner_proc_lock(proc);
  5941. list_for_each_entry(w, &proc->todo, entry)
  5942. print_binder_work_ilocked(m, proc, " ",
  5943. " pending transaction", w);
  5944. list_for_each_entry(w, &proc->delivered_death, entry) {
  5945. seq_puts(m, " has delivered dead binder\n");
  5946. break;
  5947. }
  5948. list_for_each_entry(w, &proc->delivered_freeze, entry) {
  5949. seq_puts(m, " has delivered freeze binder\n");
  5950. break;
  5951. }
  5952. binder_inner_proc_unlock(proc);
  5953. if (!print_all && m->count == header_pos)
  5954. m->count = start_pos;
  5955. }
  5956. static const char * const binder_return_strings[] = {
  5957. "BR_ERROR",
  5958. "BR_OK",
  5959. "BR_TRANSACTION",
  5960. "BR_REPLY",
  5961. "BR_ACQUIRE_RESULT",
  5962. "BR_DEAD_REPLY",
  5963. "BR_TRANSACTION_COMPLETE",
  5964. "BR_INCREFS",
  5965. "BR_ACQUIRE",
  5966. "BR_RELEASE",
  5967. "BR_DECREFS",
  5968. "BR_ATTEMPT_ACQUIRE",
  5969. "BR_NOOP",
  5970. "BR_SPAWN_LOOPER",
  5971. "BR_FINISHED",
  5972. "BR_DEAD_BINDER",
  5973. "BR_CLEAR_DEATH_NOTIFICATION_DONE",
  5974. "BR_FAILED_REPLY",
  5975. "BR_FROZEN_REPLY",
  5976. "BR_ONEWAY_SPAM_SUSPECT",
  5977. "BR_TRANSACTION_PENDING_FROZEN",
  5978. "BR_FROZEN_BINDER",
  5979. "BR_CLEAR_FREEZE_NOTIFICATION_DONE",
  5980. };
  5981. static const char * const binder_command_strings[] = {
  5982. "BC_TRANSACTION",
  5983. "BC_REPLY",
  5984. "BC_ACQUIRE_RESULT",
  5985. "BC_FREE_BUFFER",
  5986. "BC_INCREFS",
  5987. "BC_ACQUIRE",
  5988. "BC_RELEASE",
  5989. "BC_DECREFS",
  5990. "BC_INCREFS_DONE",
  5991. "BC_ACQUIRE_DONE",
  5992. "BC_ATTEMPT_ACQUIRE",
  5993. "BC_REGISTER_LOOPER",
  5994. "BC_ENTER_LOOPER",
  5995. "BC_EXIT_LOOPER",
  5996. "BC_REQUEST_DEATH_NOTIFICATION",
  5997. "BC_CLEAR_DEATH_NOTIFICATION",
  5998. "BC_DEAD_BINDER_DONE",
  5999. "BC_TRANSACTION_SG",
  6000. "BC_REPLY_SG",
  6001. "BC_REQUEST_FREEZE_NOTIFICATION",
  6002. "BC_CLEAR_FREEZE_NOTIFICATION",
  6003. "BC_FREEZE_NOTIFICATION_DONE",
  6004. };
  6005. static const char * const binder_objstat_strings[] = {
  6006. "proc",
  6007. "thread",
  6008. "node",
  6009. "ref",
  6010. "death",
  6011. "transaction",
  6012. "transaction_complete",
  6013. "freeze",
  6014. };
  6015. static void print_binder_stats(struct seq_file *m, const char *prefix,
  6016. struct binder_stats *stats)
  6017. {
  6018. int i;
  6019. BUILD_BUG_ON(ARRAY_SIZE(stats->bc) !=
  6020. ARRAY_SIZE(binder_command_strings));
  6021. for (i = 0; i < ARRAY_SIZE(stats->bc); i++) {
  6022. int temp = atomic_read(&stats->bc[i]);
  6023. if (temp)
  6024. seq_printf(m, "%s%s: %d\n", prefix,
  6025. binder_command_strings[i], temp);
  6026. }
  6027. BUILD_BUG_ON(ARRAY_SIZE(stats->br) !=
  6028. ARRAY_SIZE(binder_return_strings));
  6029. for (i = 0; i < ARRAY_SIZE(stats->br); i++) {
  6030. int temp = atomic_read(&stats->br[i]);
  6031. if (temp)
  6032. seq_printf(m, "%s%s: %d\n", prefix,
  6033. binder_return_strings[i], temp);
  6034. }
  6035. BUILD_BUG_ON(ARRAY_SIZE(stats->obj_created) !=
  6036. ARRAY_SIZE(binder_objstat_strings));
  6037. BUILD_BUG_ON(ARRAY_SIZE(stats->obj_created) !=
  6038. ARRAY_SIZE(stats->obj_deleted));
  6039. for (i = 0; i < ARRAY_SIZE(stats->obj_created); i++) {
  6040. int created = atomic_read(&stats->obj_created[i]);
  6041. int deleted = atomic_read(&stats->obj_deleted[i]);
  6042. if (created || deleted)
  6043. seq_printf(m, "%s%s: active %d total %d\n",
  6044. prefix,
  6045. binder_objstat_strings[i],
  6046. created - deleted,
  6047. created);
  6048. }
  6049. }
  6050. static void print_binder_proc_stats(struct seq_file *m,
  6051. struct binder_proc *proc)
  6052. {
  6053. struct binder_work *w;
  6054. struct binder_thread *thread;
  6055. struct rb_node *n;
  6056. int count, strong, weak, ready_threads;
  6057. size_t free_async_space =
  6058. binder_alloc_get_free_async_space(&proc->alloc);
  6059. seq_printf(m, "proc %d\n", proc->pid);
  6060. seq_printf(m, "context %s\n", proc->context->name);
  6061. count = 0;
  6062. ready_threads = 0;
  6063. binder_inner_proc_lock(proc);
  6064. for (n = rb_first(&proc->threads); n != NULL; n = rb_next(n))
  6065. count++;
  6066. list_for_each_entry(thread, &proc->waiting_threads, waiting_thread_node)
  6067. ready_threads++;
  6068. seq_printf(m, " threads: %d\n", count);
  6069. seq_printf(m, " requested threads: %d+%d/%d\n"
  6070. " ready threads %d\n"
  6071. " free async space %zd\n", proc->requested_threads,
  6072. proc->requested_threads_started, proc->max_threads,
  6073. ready_threads,
  6074. free_async_space);
  6075. count = 0;
  6076. for (n = rb_first(&proc->nodes); n != NULL; n = rb_next(n))
  6077. count++;
  6078. binder_inner_proc_unlock(proc);
  6079. seq_printf(m, " nodes: %d\n", count);
  6080. count = 0;
  6081. strong = 0;
  6082. weak = 0;
  6083. binder_proc_lock(proc);
  6084. for (n = rb_first(&proc->refs_by_desc); n != NULL; n = rb_next(n)) {
  6085. struct binder_ref *ref = rb_entry(n, struct binder_ref,
  6086. rb_node_desc);
  6087. count++;
  6088. strong += ref->data.strong;
  6089. weak += ref->data.weak;
  6090. }
  6091. binder_proc_unlock(proc);
  6092. seq_printf(m, " refs: %d s %d w %d\n", count, strong, weak);
  6093. count = binder_alloc_get_allocated_count(&proc->alloc);
  6094. seq_printf(m, " buffers: %d\n", count);
  6095. binder_alloc_print_pages(m, &proc->alloc);
  6096. count = 0;
  6097. binder_inner_proc_lock(proc);
  6098. list_for_each_entry(w, &proc->todo, entry) {
  6099. if (w->type == BINDER_WORK_TRANSACTION)
  6100. count++;
  6101. }
  6102. binder_inner_proc_unlock(proc);
  6103. seq_printf(m, " pending transactions: %d\n", count);
  6104. print_binder_stats(m, " ", &proc->stats);
  6105. }
  6106. static int state_show(struct seq_file *m, void *unused)
  6107. {
  6108. struct binder_proc *proc;
  6109. struct binder_node *node;
  6110. struct binder_node *last_node = NULL;
  6111. seq_puts(m, "binder state:\n");
  6112. spin_lock(&binder_dead_nodes_lock);
  6113. if (!hlist_empty(&binder_dead_nodes))
  6114. seq_puts(m, "dead nodes:\n");
  6115. hlist_for_each_entry(node, &binder_dead_nodes, dead_node) {
  6116. /*
  6117. * take a temporary reference on the node so it
  6118. * survives and isn't removed from the list
  6119. * while we print it.
  6120. */
  6121. node->tmp_refs++;
  6122. spin_unlock(&binder_dead_nodes_lock);
  6123. if (last_node)
  6124. binder_put_node(last_node);
  6125. binder_node_lock(node);
  6126. print_binder_node_nilocked(m, node);
  6127. binder_node_unlock(node);
  6128. last_node = node;
  6129. spin_lock(&binder_dead_nodes_lock);
  6130. }
  6131. spin_unlock(&binder_dead_nodes_lock);
  6132. if (last_node)
  6133. binder_put_node(last_node);
  6134. mutex_lock(&binder_procs_lock);
  6135. hlist_for_each_entry(proc, &binder_procs, proc_node)
  6136. print_binder_proc(m, proc, 1);
  6137. mutex_unlock(&binder_procs_lock);
  6138. return 0;
  6139. }
  6140. static int stats_show(struct seq_file *m, void *unused)
  6141. {
  6142. struct binder_proc *proc;
  6143. seq_puts(m, "binder stats:\n");
  6144. print_binder_stats(m, "", &binder_stats);
  6145. mutex_lock(&binder_procs_lock);
  6146. hlist_for_each_entry(proc, &binder_procs, proc_node)
  6147. print_binder_proc_stats(m, proc);
  6148. mutex_unlock(&binder_procs_lock);
  6149. return 0;
  6150. }
  6151. static int transactions_show(struct seq_file *m, void *unused)
  6152. {
  6153. struct binder_proc *proc;
  6154. seq_puts(m, "binder transactions:\n");
  6155. mutex_lock(&binder_procs_lock);
  6156. hlist_for_each_entry(proc, &binder_procs, proc_node)
  6157. print_binder_proc(m, proc, 0);
  6158. mutex_unlock(&binder_procs_lock);
  6159. return 0;
  6160. }
  6161. static int proc_show(struct seq_file *m, void *unused)
  6162. {
  6163. struct binder_proc *itr;
  6164. int pid = (unsigned long)m->private;
  6165. mutex_lock(&binder_procs_lock);
  6166. hlist_for_each_entry(itr, &binder_procs, proc_node) {
  6167. if (itr->pid == pid) {
  6168. seq_puts(m, "binder proc state:\n");
  6169. print_binder_proc(m, itr, 1);
  6170. }
  6171. }
  6172. mutex_unlock(&binder_procs_lock);
  6173. return 0;
  6174. }
  6175. static void print_binder_transaction_log_entry(struct seq_file *m,
  6176. struct binder_transaction_log_entry *e)
  6177. {
  6178. int debug_id = READ_ONCE(e->debug_id_done);
  6179. /*
  6180. * read barrier to guarantee debug_id_done read before
  6181. * we print the log values
  6182. */
  6183. smp_rmb();
  6184. seq_printf(m,
  6185. "%d: %s from %d:%d to %d:%d context %s node %d handle %d size %d:%d ret %d/%d l=%d",
  6186. e->debug_id, (e->call_type == 2) ? "reply" :
  6187. ((e->call_type == 1) ? "async" : "call "), e->from_proc,
  6188. e->from_thread, e->to_proc, e->to_thread, e->context_name,
  6189. e->to_node, e->target_handle, e->data_size, e->offsets_size,
  6190. e->return_error, e->return_error_param,
  6191. e->return_error_line);
  6192. /*
  6193. * read-barrier to guarantee read of debug_id_done after
  6194. * done printing the fields of the entry
  6195. */
  6196. smp_rmb();
  6197. seq_printf(m, debug_id && debug_id == READ_ONCE(e->debug_id_done) ?
  6198. "\n" : " (incomplete)\n");
  6199. }
  6200. static int transaction_log_show(struct seq_file *m, void *unused)
  6201. {
  6202. struct binder_transaction_log *log = m->private;
  6203. unsigned int log_cur = atomic_read(&log->cur);
  6204. unsigned int count;
  6205. unsigned int cur;
  6206. int i;
  6207. count = log_cur + 1;
  6208. cur = count < ARRAY_SIZE(log->entry) && !log->full ?
  6209. 0 : count % ARRAY_SIZE(log->entry);
  6210. if (count > ARRAY_SIZE(log->entry) || log->full)
  6211. count = ARRAY_SIZE(log->entry);
  6212. for (i = 0; i < count; i++) {
  6213. unsigned int index = cur++ % ARRAY_SIZE(log->entry);
  6214. print_binder_transaction_log_entry(m, &log->entry[index]);
  6215. }
  6216. return 0;
  6217. }
  6218. const struct file_operations binder_fops = {
  6219. .owner = THIS_MODULE,
  6220. .poll = binder_poll,
  6221. .unlocked_ioctl = binder_ioctl,
  6222. .compat_ioctl = compat_ptr_ioctl,
  6223. .mmap = binder_mmap,
  6224. .open = binder_open,
  6225. .flush = binder_flush,
  6226. .release = binder_release,
  6227. };
  6228. DEFINE_SHOW_ATTRIBUTE(state);
  6229. DEFINE_SHOW_ATTRIBUTE(stats);
  6230. DEFINE_SHOW_ATTRIBUTE(transactions);
  6231. DEFINE_SHOW_ATTRIBUTE(transaction_log);
  6232. const struct binder_debugfs_entry binder_debugfs_entries[] = {
  6233. {
  6234. .name = "state",
  6235. .mode = 0444,
  6236. .fops = &state_fops,
  6237. .data = NULL,
  6238. },
  6239. {
  6240. .name = "stats",
  6241. .mode = 0444,
  6242. .fops = &stats_fops,
  6243. .data = NULL,
  6244. },
  6245. {
  6246. .name = "transactions",
  6247. .mode = 0444,
  6248. .fops = &transactions_fops,
  6249. .data = NULL,
  6250. },
  6251. {
  6252. .name = "transaction_log",
  6253. .mode = 0444,
  6254. .fops = &transaction_log_fops,
  6255. .data = &binder_transaction_log,
  6256. },
  6257. {
  6258. .name = "failed_transaction_log",
  6259. .mode = 0444,
  6260. .fops = &transaction_log_fops,
  6261. .data = &binder_transaction_log_failed,
  6262. },
  6263. {} /* terminator */
  6264. };
  6265. static int __init init_binder_device(const char *name)
  6266. {
  6267. int ret;
  6268. struct binder_device *binder_device;
  6269. binder_device = kzalloc(sizeof(*binder_device), GFP_KERNEL);
  6270. if (!binder_device)
  6271. return -ENOMEM;
  6272. binder_device->miscdev.fops = &binder_fops;
  6273. binder_device->miscdev.minor = MISC_DYNAMIC_MINOR;
  6274. binder_device->miscdev.name = name;
  6275. refcount_set(&binder_device->ref, 1);
  6276. binder_device->context.binder_context_mgr_uid = INVALID_UID;
  6277. binder_device->context.name = name;
  6278. mutex_init(&binder_device->context.context_mgr_node_lock);
  6279. ret = misc_register(&binder_device->miscdev);
  6280. if (ret < 0) {
  6281. kfree(binder_device);
  6282. return ret;
  6283. }
  6284. hlist_add_head(&binder_device->hlist, &binder_devices);
  6285. return ret;
  6286. }
  6287. static int __init binder_init(void)
  6288. {
  6289. int ret;
  6290. char *device_name, *device_tmp;
  6291. struct binder_device *device;
  6292. struct hlist_node *tmp;
  6293. char *device_names = NULL;
  6294. const struct binder_debugfs_entry *db_entry;
  6295. ret = binder_alloc_shrinker_init();
  6296. if (ret)
  6297. return ret;
  6298. atomic_set(&binder_transaction_log.cur, ~0U);
  6299. atomic_set(&binder_transaction_log_failed.cur, ~0U);
  6300. binder_debugfs_dir_entry_root = debugfs_create_dir("binder", NULL);
  6301. binder_for_each_debugfs_entry(db_entry)
  6302. debugfs_create_file(db_entry->name,
  6303. db_entry->mode,
  6304. binder_debugfs_dir_entry_root,
  6305. db_entry->data,
  6306. db_entry->fops);
  6307. binder_debugfs_dir_entry_proc = debugfs_create_dir("proc",
  6308. binder_debugfs_dir_entry_root);
  6309. if (!IS_ENABLED(CONFIG_ANDROID_BINDERFS) &&
  6310. strcmp(binder_devices_param, "") != 0) {
  6311. /*
  6312. * Copy the module_parameter string, because we don't want to
  6313. * tokenize it in-place.
  6314. */
  6315. device_names = kstrdup(binder_devices_param, GFP_KERNEL);
  6316. if (!device_names) {
  6317. ret = -ENOMEM;
  6318. goto err_alloc_device_names_failed;
  6319. }
  6320. device_tmp = device_names;
  6321. while ((device_name = strsep(&device_tmp, ","))) {
  6322. ret = init_binder_device(device_name);
  6323. if (ret)
  6324. goto err_init_binder_device_failed;
  6325. }
  6326. }
  6327. ret = init_binderfs();
  6328. if (ret)
  6329. goto err_init_binder_device_failed;
  6330. return ret;
  6331. err_init_binder_device_failed:
  6332. hlist_for_each_entry_safe(device, tmp, &binder_devices, hlist) {
  6333. misc_deregister(&device->miscdev);
  6334. hlist_del(&device->hlist);
  6335. kfree(device);
  6336. }
  6337. kfree(device_names);
  6338. err_alloc_device_names_failed:
  6339. debugfs_remove_recursive(binder_debugfs_dir_entry_root);
  6340. binder_alloc_shrinker_exit();
  6341. return ret;
  6342. }
  6343. device_initcall(binder_init);
  6344. #define CREATE_TRACE_POINTS
  6345. #include "binder_trace.h"
  6346. MODULE_LICENSE("GPL v2");