summaryrefslogtreecommitdiffstats
path: root/drivers/android/binder.c
diff options
context:
space:
mode:
authorTomer Pomeranc <tomerpo@gmail.com>2026-08-12 22:53:16 +0300
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>2026-09-16 19:33:40 +0100
commit22c135635fdd9816c0ef140d6de7b2e4fdf73e89 (patch)
treee603ba55540840206a3a78e324ae5c6f7f324fe7 /drivers/android/binder.c
parentc4c02084d6687d5cd5edccaf52cc45e5160f1184 (diff)
downloadlinux-stable-22c135635fdd9816c0ef140d6de7b2e4fdf73e89.tar.gz
linux-stable-22c135635fdd9816c0ef140d6de7b2e4fdf73e89.zip
binder: fix is_failure flag for superseded transaction cleanup
When a TF_UPDATE_TXN transaction supersedes a pending async transaction, binder_release_entire_buffer() is called with is_failure=false. Since the superseded transaction was never delivered, binder_apply_fd_fixups() was never called and no fds were installed in the target process. With is_failure=false, the BINDER_TYPE_FDA cleanup handler interprets stale buffer contents as installed fd numbers and passes them to binder_deferred_fd_close(), closing unrelated file descriptors. Pass is_failure=true since the transaction was never delivered to the target, matching the semantics of all other undelivered-transaction cleanup paths. Fixes: 9864bb480133 ("Binder: add TF_UPDATE_TXN to replace outdated txn") Cc: stable <stable@kernel.org> Signed-off-by: Tomer Pomeranc <tomerpo@gmail.com> Acked-by: Carlos Llamas <cmllamas@google.com> Link: https://patch.msgid.link/20260812195316.259136-3-tomerpo@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Diffstat (limited to 'drivers/android/binder.c')
-rw-r--r--drivers/android/binder.c2
1 files changed, 1 insertions, 1 deletions
diff --git a/drivers/android/binder.c b/drivers/android/binder.c
index f70aeb63a..bc8bc9ee4 100644
--- a/drivers/android/binder.c
+++ b/drivers/android/binder.c
@@ -2930,7 +2930,7 @@ static int binder_proc_transaction(struct binder_transaction *t,
t_outdated->buffer = NULL;
buffer->transaction = NULL;
trace_binder_transaction_update_buffer_release(buffer);
- binder_release_entire_buffer(proc, NULL, buffer, false);
+ binder_release_entire_buffer(proc, NULL, buffer, true);
binder_alloc_free_buf(&proc->alloc, buffer);
binder_free_txn_fixups(t_outdated);
kfree(t_outdated);