From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1754715AbcBBMhj (ORCPT ); Tue, 2 Feb 2016 07:37:39 -0500 Received: from szxga02-in.huawei.com ([119.145.14.65]:10927 "EHLO szxga02-in.huawei.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1754406AbcBBMhh (ORCPT ); Tue, 2 Feb 2016 07:37:37 -0500 Subject: Re: [PATCH v3] android: binder: Sanity check at binder ioctl To: , , , , , , , , , , , , , , , , , , , References: <1454306642-73580-1-git-send-email-puck.chen@hisilicon.com> CC: , , , From: Chen Feng Message-ID: <56B0A2E6.3090107@hisilicon.com> Date: Tue, 2 Feb 2016 20:36:54 +0800 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:38.0) Gecko/20100101 Thunderbird/38.5.1 MIME-Version: 1.0 In-Reply-To: <1454306642-73580-1-git-send-email-puck.chen@hisilicon.com> Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit X-Originating-IP: [10.142.193.64] X-CFilter-Loop: Reflected X-Mirapoint-Virus-RAPID-Raw: score=unknown(0), refid=str=0001.0A020206.56B0A2FA.0140,ss=1,re=0.000,recu=0.000,reip=0.000,cl=1,cld=1,fgs=0, ip=0.0.0.0, so=2013-06-18 04:22:30, dmn=2013-03-21 17:37:32 X-Mirapoint-Loop-Id: d408bd5f263eae8dcb093fd661042806 Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Add android kernel team. On 2016/2/1 14:04, Chen Feng wrote: > Sanity check at binder ioctl function, > Only allow the shared mm_struct to use the same binder-object > to do binder operate. > > And add proc->vma_vm_mm = current->mm at the open function. > The libbinder do ioctl before mmap called. > > V2: Fix compile error for error commit > V3: Change the condition to proc->vma_vm_mm > > Signed-off-by: Chen Feng > Signed-off-by: Wei Dong > Signed-off-by: Junmin Zhao > Reviewed-by: Zhuangluan Su > --- > drivers/android/binder.c | 5 +++++ > 1 file changed, 5 insertions(+) > > diff --git a/drivers/android/binder.c b/drivers/android/binder.c > index a39e85f..f080a8b 100644 > --- a/drivers/android/binder.c > +++ b/drivers/android/binder.c > @@ -2737,6 +2737,10 @@ static long binder_ioctl(struct file *filp, unsigned int cmd, unsigned long arg) > /*pr_info("binder_ioctl: %d:%d %x %lx\n", > proc->pid, current->pid, cmd, arg);*/ > > + if (unlikely(current->mm != proc->vma_vm_mm)) { > + pr_err("current mm mismatch proc mm\n"); > + return -EINVAL; > + } > trace_binder_ioctl(cmd, arg); > > ret = wait_event_interruptible(binder_user_error_wait, binder_stop_on_user_error < 2); > @@ -2951,6 +2955,7 @@ static int binder_open(struct inode *nodp, struct file *filp) > return -ENOMEM; > get_task_struct(current); > proc->tsk = current; > + proc->vma_vm_mm = current->mm; > INIT_LIST_HEAD(&proc->todo); > init_waitqueue_head(&proc->wait); > proc->default_priority = task_nice(current); >