All of lore.kernel.org
 help / color / mirror / Atom feed
From: Carlos Llamas <cmllamas@google.com>
To: "Greg Kroah-Hartman" <gregkh@linuxfoundation.org>,
	"Arve Hjønnevåg" <arve@android.com>,
	"Todd Kjos" <tkjos@android.com>,
	"Martijn Coenen" <maco@android.com>,
	"Joel Fernandes" <joel@joelfernandes.org>,
	"Christian Brauner" <brauner@kernel.org>,
	"Carlos Llamas" <cmllamas@google.com>,
	"Suren Baghdasaryan" <surenb@google.com>,
	"Sherry Yang" <sherryy@android.com>
Cc: linux-kernel@vger.kernel.org, kernel-team@android.com,
	Alice Ryhl <aliceryhl@google.com>
Subject: [PATCH v2 04/28] binder: fix async space check for 0-sized buffers
Date: Fri,  1 Dec 2023 17:21:33 +0000	[thread overview]
Message-ID: <20231201172212.1813387-5-cmllamas@google.com> (raw)
In-Reply-To: <20231201172212.1813387-1-cmllamas@google.com>

Move the padding of 0-sized buffers to an earlier stage to account for
this round up during the alloc->free_async_space check.

Fixes: 74310e06be4d ("android: binder: Move buffer out of area shared with user space")
Reviewed-by: Alice Ryhl <aliceryhl@google.com>
Signed-off-by: Carlos Llamas <cmllamas@google.com>
---
 drivers/android/binder_alloc.c | 7 ++++---
 1 file changed, 4 insertions(+), 3 deletions(-)

diff --git a/drivers/android/binder_alloc.c b/drivers/android/binder_alloc.c
index adcec5ec0959..abff1bafcc43 100644
--- a/drivers/android/binder_alloc.c
+++ b/drivers/android/binder_alloc.c
@@ -407,6 +407,10 @@ static struct binder_buffer *binder_alloc_new_buf_locked(
 				alloc->pid, extra_buffers_size);
 		return ERR_PTR(-EINVAL);
 	}
+
+	/* Pad 0-size buffers so they get assigned unique addresses */
+	size = max(size, sizeof(void *));
+
 	if (is_async &&
 	    alloc->free_async_space < size + sizeof(struct binder_buffer)) {
 		binder_alloc_debug(BINDER_DEBUG_BUFFER_ALLOC,
@@ -415,9 +419,6 @@ static struct binder_buffer *binder_alloc_new_buf_locked(
 		return ERR_PTR(-ENOSPC);
 	}
 
-	/* Pad 0-size buffers so they get assigned unique addresses */
-	size = max(size, sizeof(void *));
-
 	while (n) {
 		buffer = rb_entry(n, struct binder_buffer, rb_node);
 		BUG_ON(!buffer->free);
-- 
2.43.0.rc2.451.g8631bc7472-goog


  parent reply	other threads:[~2023-12-01 17:22 UTC|newest]

Thread overview: 68+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2023-12-01 17:21 [PATCH v2 00/28] binder: convert alloc->mutex to spinlock Carlos Llamas
2023-12-01 17:21 ` [PATCH v2 01/28] binder: use EPOLLERR from eventpoll.h Carlos Llamas
2023-12-01 17:21 ` [PATCH v2 02/28] binder: fix use-after-free in shinker's callback Carlos Llamas
2023-12-01 17:21 ` [PATCH v2 03/28] binder: fix race between mmput() and do_exit() Carlos Llamas
2024-01-18 19:29   ` Carlos Llamas
2024-01-19  5:48     ` Greg Kroah-Hartman
2024-01-19 17:06       ` Carlos Llamas
2024-01-19 17:37         ` Carlos Llamas
2024-01-20  6:37           ` Greg Kroah-Hartman
2024-01-22 18:05             ` Carlos Llamas
2023-12-01 17:21 ` Carlos Llamas [this message]
2024-01-18 19:32   ` [PATCH v2 04/28] binder: fix async space check for 0-sized buffers Carlos Llamas
2024-01-19  5:48     ` Greg Kroah-Hartman
2024-01-19 17:11       ` Carlos Llamas
2024-01-22 15:05         ` Greg Kroah-Hartman
2023-12-01 17:21 ` [PATCH v2 05/28] binder: fix unused alloc->free_async_space Carlos Llamas
2023-12-04 11:56   ` Alice Ryhl
2024-01-18 19:33   ` Carlos Llamas
2024-01-19  5:49     ` Greg Kroah-Hartman
2024-01-19 17:27       ` Carlos Llamas
2024-01-22 15:04         ` Greg Kroah-Hartman
2024-01-22 15:05           ` Greg Kroah-Hartman
2024-01-22 18:08             ` Carlos Llamas
2024-01-22 18:35               ` Greg Kroah-Hartman
2023-12-01 17:21 ` [PATCH v2 06/28] binder: fix trivial typo of binder_free_buf_locked() Carlos Llamas
2023-12-01 17:21 ` [PATCH v2 07/28] binder: fix comment on binder_alloc_new_buf() return value Carlos Llamas
2023-12-01 17:21 ` [PATCH v2 08/28] binder: remove extern from function prototypes Carlos Llamas
2023-12-01 17:21 ` [PATCH v2 09/28] binder: keep vma addresses type as unsigned long Carlos Llamas
2023-12-04 11:56   ` Alice Ryhl
2023-12-01 17:21 ` [PATCH v2 10/28] binder: split up binder_update_page_range() Carlos Llamas
2023-12-01 17:21 ` [PATCH v2 11/28] binder: do unlocked work in binder_alloc_new_buf() Carlos Llamas
2023-12-04 11:57   ` Alice Ryhl
2023-12-04 14:22     ` Carlos Llamas
2023-12-04 14:23       ` Alice Ryhl
2023-12-01 17:21 ` [PATCH v2 12/28] binder: remove pid param " Carlos Llamas
2023-12-01 17:21 ` [PATCH v2 13/28] binder: separate the no-space debugging logic Carlos Llamas
2023-12-01 17:21 ` [PATCH v2 14/28] binder: relocate low space calculation Carlos Llamas
2023-12-01 17:21 ` [PATCH v2 15/28] binder: relocate binder_alloc_clear_buf() Carlos Llamas
2023-12-01 17:21 ` [PATCH v2 16/28] binder: refactor page range allocation Carlos Llamas
2023-12-01 17:21 ` [PATCH v2 17/28] binder: malloc new_buffer outside of locks Carlos Llamas
2023-12-04 11:57   ` Alice Ryhl
2023-12-01 17:21 ` [PATCH v2 18/28] binder: initialize lru pages in mmap callback Carlos Llamas
2023-12-01 17:21 ` [PATCH v2 19/28] binder: perform page installation outside of locks Carlos Llamas
2023-12-04 11:57   ` Alice Ryhl
2023-12-01 17:21 ` [PATCH v2 20/28] binder: remove redundant debug log Carlos Llamas
2023-12-04 11:57   ` Alice Ryhl
2023-12-01 17:21 ` [PATCH v2 21/28] binder: make oversized buffer code more readable Carlos Llamas
2023-12-04 11:57   ` Alice Ryhl
2023-12-01 17:21 ` [PATCH v2 22/28] binder: rename lru shrinker utilities Carlos Llamas
2023-12-04 11:57   ` Alice Ryhl
2023-12-01 17:21 ` [PATCH v2 23/28] binder: document the final page calculation Carlos Llamas
2023-12-04 11:57   ` Alice Ryhl
2023-12-04 14:39     ` Carlos Llamas
2023-12-04 14:43       ` Alice Ryhl
2023-12-04 14:53         ` Carlos Llamas
2023-12-01 17:21 ` [PATCH v2 24/28] binder: collapse print_binder_buffer() into caller Carlos Llamas
2023-12-04 11:57   ` Alice Ryhl
2023-12-01 17:21 ` [PATCH v2 25/28] binder: refactor binder_delete_free_buffer() Carlos Llamas
2023-12-04 11:57   ` Alice Ryhl
2023-12-01 17:21 ` [PATCH v2 26/28] binder: avoid user addresses in debug logs Carlos Llamas
2023-12-04 11:57   ` Alice Ryhl
2023-12-06  0:40   ` kernel test robot
2023-12-01 17:21 ` [PATCH v2 27/28] binder: reverse locking order in shrinker callback Carlos Llamas
2023-12-04 11:57   ` Alice Ryhl
2023-12-04 14:45     ` Carlos Llamas
2023-12-04 14:47       ` Alice Ryhl
2023-12-04 15:01         ` Carlos Llamas
2023-12-01 17:21 ` [PATCH v2 28/28] binder: switch alloc->mutex to spinlock_t Carlos Llamas

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20231201172212.1813387-5-cmllamas@google.com \
    --to=cmllamas@google.com \
    --cc=aliceryhl@google.com \
    --cc=arve@android.com \
    --cc=brauner@kernel.org \
    --cc=gregkh@linuxfoundation.org \
    --cc=joel@joelfernandes.org \
    --cc=kernel-team@android.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=maco@android.com \
    --cc=sherryy@android.com \
    --cc=surenb@google.com \
    --cc=tkjos@android.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.