From: Carlos Llamas <cmllamas@google.com>
To: Tomer Pomeranc <tomerpo@gmail.com>
Cc: linux-kernel@vger.kernel.org, gregkh@linuxfoundation.org,
arve@android.com, tkjos@android.com, brauner@kernel.org,
aliceryhl@google.com, stable@vger.kernel.org
Subject: Re: [PATCH 0/2] binder: fix TF_UPDATE_TXN supersede cleanup bugs
Date: Wed, 12 Aug 2026 21:30:57 +0000 [thread overview]
Message-ID: <anzmEX3hPwiem5ok@google.com> (raw)
In-Reply-To: <20260812195316.259136-1-tomerpo@gmail.com>
On Wed, Aug 12, 2026 at 10:53:14PM +0300, Tomer Pomeranc wrote:
> Two bugs in the t_outdated cleanup path of binder_proc_transaction(),
> both introduced by commit 9864bb480133 ("binder: add TF_UPDATE_TXN to
> replace outdated txn"):
I was never a fan of this TF_UPDATE_TXN flag. This is a kernel band-aid
patch for a flow-control problem in userspace.
>
> 1. kfree(t_outdated) is called without binder_free_txn_fixups(),
> permanently leaking binder_txn_fd_fixup entries and their fget()'d
> struct file references. The refcount never reaches zero; the leak
> survives process exit and accumulates until file-max exhaustion.
Yes.
>
> 2. binder_release_entire_buffer() is called with is_failure=false for
> a transaction that was never delivered. Since binder_apply_fd_fixups()
> was never called, the BINDER_TYPE_FDA handler reads stale buffer data
> as fd numbers and closes unrelated fds via binder_deferred_fd_close().
Ha! good catch.
>
> Confirmed on mainline Linux (6.8.0-124-generic, binder_linux module)
> and Android (Pixel 8, kernel 6.1.124, /dev/hwbinder).
>
> Tomer Pomeranc (2):
> binder: fix leaked fd fixups on TF_UPDATE_TXN supersede
> binder: fix is_failure flag for superseded transaction cleanup
>
> drivers/android/binder.c | 3 ++-
> 1 file changed, 2 insertions(+), 1 deletion(-)
>
> --
> 2.34.1
>
So both fixes LGTM, and we should take them.
However, I'm thinking we should drop this code. We now have frozen
process notifications and that should prevent duplicate transactions to
frozen processes from happening in the first place. So we remove the
code and mark TF_UPDATE_TXN as obsolete.
... or maybe we just drop the entire C binder code base. I'm tired of
all these memory issues.
--
Carlos Llamas
prev parent reply other threads:[~2026-08-12 21:31 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-12 19:53 [PATCH 0/2] binder: fix TF_UPDATE_TXN supersede cleanup bugs Tomer Pomeranc
2026-08-12 19:53 ` [PATCH 1/2] binder: fix leaked fd fixups on TF_UPDATE_TXN supersede Tomer Pomeranc
2026-08-12 21:31 ` Carlos Llamas
2026-08-12 19:53 ` [PATCH 2/2] binder: fix is_failure flag for superseded transaction cleanup Tomer Pomeranc
2026-08-12 21:31 ` Carlos Llamas
2026-08-12 21:30 ` Carlos Llamas [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=anzmEX3hPwiem5ok@google.com \
--to=cmllamas@google.com \
--cc=aliceryhl@google.com \
--cc=arve@android.com \
--cc=brauner@kernel.org \
--cc=gregkh@linuxfoundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=stable@vger.kernel.org \
--cc=tkjos@android.com \
--cc=tomerpo@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox