<feed xmlns='http://www.w3.org/2005/Atom'>
<title>kernel/git/stable/linux-stable.git/drivers/android, branch master</title>
<subtitle>Unnamed repository; edit this file 'description' to name the repository.</subtitle>
<id>http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/atom/drivers/android?h=master</id>
<link rel='self' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/atom/drivers/android?h=master'/>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/'/>
<updated>2026-09-16T18:33:40Z</updated>
<entry>
<title>rust_binderfs: add transaction_report feature entry</title>
<updated>2026-09-16T18:33:40Z</updated>
<author>
<name>Carlos Llamas</name>
<email>cmllamas@google.com</email>
</author>
<published>2026-09-16T12:08:32Z</published>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=137d6ccf0ec8c48ecf0facc47cc46926df5fd0f3'/>
<id>urn:sha1:137d6ccf0ec8c48ecf0facc47cc46926df5fd0f3</id>
<content type='text'>
rust_binderfs is missing the equivalent of commit f37b55ded8ed ("binder:
add transaction_report feature entry"), which adds "transaction_report"
to the binderfs feature list. This helps userspace determine if the
BINDER_CMD_REPORT from the generic netlink API is supported.

Cc: stable &lt;stable@kernel.org&gt;
Fixes: f14e0c8183bc ("rust_binder: report netlink transactions")
Signed-off-by: Carlos Llamas &lt;cmllamas@google.com&gt;
Link: https://patch.msgid.link/20260916120833.593407-1-cmllamas@google.com
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>rust_binder: reschedule node refcount update on thread exit</title>
<updated>2026-09-16T18:33:40Z</updated>
<author>
<name>Alice Ryhl</name>
<email>aliceryhl@google.com</email>
</author>
<published>2026-09-03T11:36:03Z</published>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=2a74ccd1bcc170e66525f34e9de8652b57e2cf3d'/>
<id>urn:sha1:2a74ccd1bcc170e66525f34e9de8652b57e2cf3d</id>
<content type='text'>
When a thread exits via BINDER_THREAD_EXIT, its pending work items are
cancelled. If a thread exits while holding a pending node refcount
increment (e.g. pushed as deferred work to that thread), the refcount
increment was previously dropped because Node::cancel() and
NodeWrapper::cancel() were no-ops.

Dropping the refcount update leaves the node's delivery state and count
state desynchronized, and userspace will not receive the notification,
which can cause the node to never be freed from the process's nodes tree
when all external references are dropped.

Fix this by implementing DeliverToRead::cancel() for Node and NodeWrapper
to move the pending refcount update to the process's work queue on thread
exit so another thread can deliver it to userspace.

Cc: stable &lt;stable@kernel.org&gt;
Fixes: eafedbc7c050 ("rust_binder: add Rust Binder driver")
Signed-off-by: Alice Ryhl &lt;aliceryhl@google.com&gt;
Link: https://patch.msgid.link/20260903-binder-thread-exit-node-v1-1-be09ff14f6a4@google.com
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>rust_binder: cancel deferred work items in thread exit</title>
<updated>2026-09-16T18:33:40Z</updated>
<author>
<name>Alice Ryhl</name>
<email>aliceryhl@google.com</email>
</author>
<published>2026-09-03T09:22:52Z</published>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=62479b6e5df82cbdf3c4145130928f233fae78fb'/>
<id>urn:sha1:62479b6e5df82cbdf3c4145130928f233fae78fb</id>
<content type='text'>
If there are deferred work items on the thread todo list, then they are
not cleaned up in the Thread::release() method. Thus, update the code to
clean up the work items even if they are deferred.

This can happen if the thread dies while it has an active outgoing
transaction.

Cc: stable &lt;stable@kernel.org&gt;
Fixes: eafedbc7c050 ("rust_binder: add Rust Binder driver")
Signed-off-by: Alice Ryhl &lt;aliceryhl@google.com&gt;
Link: https://patch.msgid.link/20260903-binder-exit-get-work-v1-1-2d6129a238df@google.com
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>binderfs: fix UAF write in binder_add_device</title>
<updated>2026-09-16T18:33:40Z</updated>
<author>
<name>Peiyang He</name>
<email>peiyang_he@smail.nju.edu.cn</email>
</author>
<published>2026-09-13T08:56:45Z</published>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=30d15f44a9e513ec2f257fdf192d9d1fa5af0799'/>
<id>urn:sha1:30d15f44a9e513ec2f257fdf192d9d1fa5af0799</id>
<content type='text'>
binderfs_binder_device_create() publishes the new dentry with
d_make_persistent() and then calls simple_done_creating(), which drops
the parent directory lock and the creator's dentry reference. It then
calls binder_add_device() to register the device in the global
binder_devices list.

After simple_done_creating() releases the parent directory lock, a
concurrent unlinkat() can remove the new device entry. Dropping the
creator's dentry reference can then trigger binderfs_evict_inode(),
freeing the device. binder_add_device() later accesses the freed
object, causing UAF write.

Found by a modified Syzkaller:

	BUG: KASAN: slab-use-after-free in hlist_add_head include/linux/list.h:1073 [inline]
	BUG: KASAN: slab-use-after-free in binder_add_device+0xa9/0xc0 drivers/android/binder.c:7068
	Write of size 8 at addr ffff88805b340c00 by task syz.1.532/11389

	CPU: 0 UID: 0 PID: 11389 Comm: syz.1.532 Not tainted 7.2.0 #4 PREEMPT(full)
	Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
	Call Trace:
	&lt;TASK&gt;
	__dump_stack lib/dump_stack.c:94 [inline]
	dump_stack_lvl+0x10e/0x1f0 lib/dump_stack.c:120
	print_address_description mm/kasan/report.c:378 [inline]
	print_report+0xf7/0x600 mm/kasan/report.c:482
	kasan_report+0xe4/0x120 mm/kasan/report.c:595
	hlist_add_head include/linux/list.h:1073 [inline]
	binder_add_device+0xa9/0xc0 drivers/android/binder.c:7068
	binderfs_binder_device_create.isra.0+0x724/0x990 drivers/android/binderfs.c:196
	binder_ctl_ioctl+0x186/0x1b0 drivers/android/binderfs.c:241
	vfs_ioctl fs/ioctl.c:51 [inline]
	__do_sys_ioctl fs/ioctl.c:597 [inline]
	__se_sys_ioctl fs/ioctl.c:583 [inline]
	__x64_sys_ioctl+0x18e/0x210 fs/ioctl.c:583
	do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
	do_syscall_64+0x116/0x800 arch/x86/entry/syscall_64.c:94
	entry_SYSCALL_64_after_hwframe+0x77/0x7f
	RIP: 0033:0x7ff9027a833d
	Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 &lt;48&gt; 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48
	RSP: 002b:00007ff903674018 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
	RAX: ffffffffffffffda RBX: 00007ff902a35fa0 RCX: 00007ff9027a833d
	RDX: 0000200000000500 RSI: 00000000c1086201 RDI: 0000000000000004
	RBP: 00007ff902850733 R08: 0000000000000000 R09: 0000000000000000
	R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
	R13: 00007ff902a36038 R14: 00007ff902a35fa0 R15: 00007ffd7166bfa0
	&lt;/TASK&gt;

	Allocated by task 11389:
	kasan_save_stack+0x33/0x60 mm/kasan/common.c:57
	kasan_save_track+0x14/0x30 mm/kasan/common.c:78
	poison_kmalloc_redzone mm/kasan/common.c:398 [inline]
	__kasan_kmalloc+0xaa/0xb0 mm/kasan/common.c:415
	kasan_kmalloc include/linux/kasan.h:263 [inline]
	__kmalloc_cache_noprof+0x2e4/0x6f0 mm/slub.c:5489
	_kmalloc_noprof include/linux/slab.h:988 [inline]
	_kzalloc_noprof include/linux/slab.h:1309 [inline]
	binderfs_binder_device_create.isra.0+0x17a/0x990 drivers/android/binderfs.c:148
	binder_ctl_ioctl+0x186/0x1b0 drivers/android/binderfs.c:241
	vfs_ioctl fs/ioctl.c:51 [inline]
	__do_sys_ioctl fs/ioctl.c:597 [inline]
	__se_sys_ioctl fs/ioctl.c:583 [inline]
	__x64_sys_ioctl+0x18e/0x210 fs/ioctl.c:583
	do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
	do_syscall_64+0x116/0x800 arch/x86/entry/syscall_64.c:94
	entry_SYSCALL_64_after_hwframe+0x77/0x7f

	Freed by task 11389:
	kasan_save_stack+0x33/0x60 mm/kasan/common.c:57
	kasan_save_track+0x14/0x30 mm/kasan/common.c:78
	kasan_save_free_info+0x3b/0x60 mm/kasan/generic.c:584
	poison_slab_object mm/kasan/common.c:253 [inline]
	__kasan_slab_free+0x5f/0x80 mm/kasan/common.c:285
	kasan_slab_free include/linux/kasan.h:235 [inline]
	slab_free_hook mm/slub.c:2677 [inline]
	slab_free mm/slub.c:6377 [inline]
	kfree+0x2fc/0x6e0 mm/slub.c:6692
	binderfs_evict_inode+0x1e8/0x260 drivers/android/binderfs.c:268
	evict+0x3c2/0xad0 fs/inode.c:825
	iput_final fs/inode.c:2019 [inline]
	iput fs/inode.c:2068 [inline]
	iput+0x79a/0xd30 fs/inode.c:2031
	dentry_unlink_inode+0x27f/0x460 fs/dcache.c:479
	dentry_kill+0x25d/0xc20 fs/dcache.c:826
	finish_dput fs/dcache.c:1001 [inline]
	dput.part.0+0xce/0x230 fs/dcache.c:1042
	dput+0x1f/0x30 fs/dcache.c:1037
	end_dirop+0x7d/0xa0 fs/namei.c:2956
	binderfs_binder_device_create.isra.0+0x71c/0x990 drivers/android/binderfs.c:194
	binder_ctl_ioctl+0x186/0x1b0 drivers/android/binderfs.c:241
	vfs_ioctl fs/ioctl.c:51 [inline]
	__do_sys_ioctl fs/ioctl.c:597 [inline]
	__se_sys_ioctl fs/ioctl.c:583 [inline]
	__x64_sys_ioctl+0x18e/0x210 fs/ioctl.c:583
	do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
	do_syscall_64+0x116/0x800 arch/x86/entry/syscall_64.c:94
	entry_SYSCALL_64_after_hwframe+0x77/0x7f

	The buggy address belongs to the object at ffff88805b340c00
	which belongs to the cache kmalloc-512 of size 512
	The buggy address is located 0 bytes inside of
	freed 512-byte region [ffff88805b340c00, ffff88805b340e00)

Fix by calling binder_add_device() before d_make_persistent(),
while the parent directory lock is still held and the dentry
cannot be discarded.

Cc: stable &lt;stable@kernel.org&gt;
Fixes: b89aa544821d ("convert binderfs")
Signed-off-by: Peiyang He &lt;peiyang_he@smail.nju.edu.cn&gt;
Assisted-by: Codex:gpt-5.5
Acked-by: Carlos Llamas &lt;cmllamas@google.com&gt;
Link: https://patch.msgid.link/F6EF5FB778E87C98+20260913085645.1639558-1-peiyang_he@smail.nju.edu.cn
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>binder: fix is_failure flag for superseded transaction cleanup</title>
<updated>2026-09-16T18:33:40Z</updated>
<author>
<name>Tomer Pomeranc</name>
<email>tomerpo@gmail.com</email>
</author>
<published>2026-08-12T19:53:16Z</published>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=22c135635fdd9816c0ef140d6de7b2e4fdf73e89'/>
<id>urn:sha1:22c135635fdd9816c0ef140d6de7b2e4fdf73e89</id>
<content type='text'>
When a TF_UPDATE_TXN transaction supersedes a pending async transaction,
binder_release_entire_buffer() is called with is_failure=false. Since the
superseded transaction was never delivered, binder_apply_fd_fixups() was
never called and no fds were installed in the target process.

With is_failure=false, the BINDER_TYPE_FDA cleanup handler interprets
stale buffer contents as installed fd numbers and passes them to
binder_deferred_fd_close(), closing unrelated file descriptors.

Pass is_failure=true since the transaction was never delivered to the
target, matching the semantics of all other undelivered-transaction
cleanup paths.

Fixes: 9864bb480133 ("Binder: add TF_UPDATE_TXN to replace outdated txn")
Cc: stable &lt;stable@kernel.org&gt;
Signed-off-by: Tomer Pomeranc &lt;tomerpo@gmail.com&gt;
Acked-by: Carlos Llamas &lt;cmllamas@google.com&gt;
Link: https://patch.msgid.link/20260812195316.259136-3-tomerpo@gmail.com
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>binder: fix leaked fd fixups on TF_UPDATE_TXN supersede</title>
<updated>2026-09-16T18:33:26Z</updated>
<author>
<name>Tomer Pomeranc</name>
<email>tomerpo@gmail.com</email>
</author>
<published>2026-08-12T19:53:15Z</published>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=c4c02084d6687d5cd5edccaf52cc45e5160f1184'/>
<id>urn:sha1:c4c02084d6687d5cd5edccaf52cc45e5160f1184</id>
<content type='text'>
When a TF_UPDATE_TXN transaction supersedes a pending async transaction
in a frozen process, the outdated transaction is freed with kfree()
directly. This skips binder_free_txn_fixups(), leaking all
binder_txn_fd_fixup entries and their fget()'d struct file references.

The leaked file refcounts never reach zero, so the struct file objects
are permanently pinned in memory. They survive process exit and
accumulate across invocations until file-max exhaustion.

Every other transaction cleanup path (binder_free_transaction(),
binder_transaction() error paths, binder_release_work()) correctly
calls binder_free_txn_fixups(). Add the missing call before kfree()
in the t_outdated cleanup block.

Fixes: 9864bb480133 ("Binder: add TF_UPDATE_TXN to replace outdated txn")
Cc: stable &lt;stable@kernel.org&gt;
Signed-off-by: Tomer Pomeranc &lt;tomerpo@gmail.com&gt;
Acked-by: Carlos Llamas &lt;cmllamas@google.com&gt;
Reviewed-by: Alice Ryhl &lt;aliceryhl@google.com&gt;
Link: https://patch.msgid.link/20260812195316.259136-2-tomerpo@gmail.com
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>Merge tag 'driver-core-7.3-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/driver-core/driver-core</title>
<updated>2026-09-05T18:59:05Z</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-09-05T18:59:05Z</published>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=9f0346dcbea363787186c94ef94dd01aaa215afa'/>
<id>urn:sha1:9f0346dcbea363787186c94ef94dd01aaa215afa</id>
<content type='text'>
Pull driver core fixes from Danilo Krummrich:

 - Fix kernfs listxattr() not returning security xattr names (e.g.
   SELinux labels) when the kernfs node has no allocated kernfs_iattrs

 - Fix silent truncation of IRQ vector indices in the Rust PCI
   abstractions

 - Don't select OF from DRIVER_PE_KUNIT_TEST; skip the test when OF is
   disabled instead of silently enabling extra kernel functionality

 - Russ Weight is retiring from kernel development; update the Firmware
   Loader sysfs contact to the driver-core mailing list, add a CREDITS
   entry for Firmware Upload, and update MAINTAINERS accordingly

* tag 'driver-core-7.3-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/driver-core/driver-core:
  MAINTAINERS: Remove Russ Weight from Firmware Loader
  CREDITS: Add CREDITS entry for Firmware Upload
  firmware_loader: Change contact for sysfs nodes
  rust: pci: reject IRQ vector indices that do not fit in u32
  kernfs: preserve security xattrs without allocating iattrs
  drivers: base: test: DRIVER_PE_KUNIT_TEST should not select OF
</content>
</entry>
</feed>
