From: Li Li <dualli@chromium.org>
To: dualli@google.com, corbet@lwn.net, davem@davemloft.net,
edumazet@google.com, kuba@kernel.org, pabeni@redhat.com,
donald.hunter@gmail.com, gregkh@linuxfoundation.org,
arve@android.com, tkjos@android.com, maco@android.com,
joel@joelfernandes.org, brauner@kernel.org, cmllamas@google.com,
surenb@google.com, arnd@arndb.de, masahiroy@kernel.org,
linux-kernel@vger.kernel.org, linux-doc@vger.kernel.org,
netdev@vger.kernel.org, hridya@google.com, smoreland@google.com
Cc: kernel-team@android.com
Subject: [PATCH v3 0/1] binder: report txn errors via generic netlink (genl)
Date: Mon, 21 Oct 2024 11:28:19 -0700 [thread overview]
Message-ID: <20241021182821.1259487-1-dualli@chromium.org> (raw)
From: Li Li <dualli@google.com>
It's a known issue that neither the frozen processes nor the system
administration process of the OS can correctly deal with failed binder
transactions. The reason is that there's no reliable way for the user
space administration process to fetch the binder errors from the kernel
binder driver.
Android is such an OS suffering from this issue. Since cgroup freezer
was used to freeze user applications to save battery, innocent frozen
apps have to be killed when they receive sync binder transactions or
when their async binder buffer is running out.
This patch introduces the Linux generic netlink messages into the binder
driver so that the Linux/Android system administration process can
listen to important events and take corresponding actions, like stopping
a broken app from attacking the OS by sending huge amount of spamming
binder transactiions.
The first version uses a global generic netlink for all binder contexts,
raising potential security concerns. There were a few other feedbacks
like request to kernel docs and test code. The thread can be found at
https://lore.kernel.org/lkml/20240812211844.4107494-1-dualli@chromium.org/
The second version fixes those issues and has been tested on the latest
version of AOSP. See https://r.android.com/3305462 for how userspace is
going to use this feature and the test code. It can be found at
https://lore.kernel.org/lkml/20241011064427.1565287-1-dualli@chromium.org/
This version replaces the handcrafted netlink source code with the
netlink protocal specs in YAML. It also fixes the documentation issues.
v1: add a global binder genl socket for all contexts
v2: change to per-context binder genl for security reason
replace the new ioctl with a netlink command
add corresponding doc Documentation/admin-guide/binder_genl.rst
add user space test code in AOSP
v3: use YNL spec (./tools/net/ynl/ynl-regen.sh)
fix documentation index
Li Li (1):
report binder txn errors via generic netlink
Documentation/admin-guide/binder_genl.rst | 92 ++++++
Documentation/admin-guide/index.rst | 1 +
Documentation/netlink/specs/binder_genl.yaml | 59 ++++
drivers/android/Kconfig | 1 +
drivers/android/Makefile | 2 +-
drivers/android/binder.c | 287 ++++++++++++++++++-
drivers/android/binder_genl.c | 38 +++
drivers/android/binder_genl.h | 18 ++
drivers/android/binder_internal.h | 22 ++
drivers/android/binder_trace.h | 37 +++
drivers/android/binderfs.c | 4 +
include/uapi/linux/android/binder.h | 31 ++
include/uapi/linux/android/binder_genl.h | 37 +++
13 files changed, 625 insertions(+), 4 deletions(-)
create mode 100644 Documentation/admin-guide/binder_genl.rst
create mode 100644 Documentation/netlink/specs/binder_genl.yaml
create mode 100644 drivers/android/binder_genl.c
create mode 100644 drivers/android/binder_genl.h
create mode 100644 include/uapi/linux/android/binder_genl.h
--
2.47.0.105.g07ac214952-goog
next reply other threads:[~2024-10-21 18:28 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-10-21 18:28 Li Li [this message]
2024-10-21 18:28 ` [PATCH v3 1/1] binder: report txn errors via generic netlink Li Li
2024-10-21 18:35 ` Li Li
2024-10-21 18:56 ` Greg KH
2024-10-21 19:23 ` Li Li
2024-10-23 16:47 ` kernel test robot
2024-10-21 18:28 ` [PATCH v3 1/1] report binder " Li Li
2024-10-26 8:04 ` Dan Carpenter
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20241021182821.1259487-1-dualli@chromium.org \
--to=dualli@chromium.org \
--cc=arnd@arndb.de \
--cc=arve@android.com \
--cc=brauner@kernel.org \
--cc=cmllamas@google.com \
--cc=corbet@lwn.net \
--cc=davem@davemloft.net \
--cc=donald.hunter@gmail.com \
--cc=dualli@google.com \
--cc=edumazet@google.com \
--cc=gregkh@linuxfoundation.org \
--cc=hridya@google.com \
--cc=joel@joelfernandes.org \
--cc=kernel-team@android.com \
--cc=kuba@kernel.org \
--cc=linux-doc@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=maco@android.com \
--cc=masahiroy@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=smoreland@google.com \
--cc=surenb@google.com \
--cc=tkjos@android.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox