From: Arve Hjønnevåg Date: Fri, 12 Aug 2016 23:04:28 +0000 (-0700) Subject: ANDROID: binder: Clear binder and cookie when setting handle in flat binder struct X-Git-Url: https://git.stricted.de/?a=commitdiff_plain;h=78c26bebd182874a7383a5d07446673b61d1ea0e;p=GitHub%2Fexynos8895%2Fandroid_kernel_samsung_universal8895.git ANDROID: binder: Clear binder and cookie when setting handle in flat binder struct Prevents leaking pointers between processes BUG: 30768347 Change-Id: Id898076926f658a1b8b27a3ccb848756b36de4ca Signed-off-by: Arve Hjønnevåg --- diff --git a/drivers/android/binder.c b/drivers/android/binder.c index ce84ff14ce9b..b8ba5b7516b9 100644 --- a/drivers/android/binder.c +++ b/drivers/android/binder.c @@ -1583,7 +1583,9 @@ static void binder_transaction(struct binder_proc *proc, fp->type = BINDER_TYPE_HANDLE; else fp->type = BINDER_TYPE_WEAK_HANDLE; + fp->binder = 0; fp->handle = ref->desc; + fp->cookie = 0; binder_inc_ref(ref, fp->type == BINDER_TYPE_HANDLE, &thread->todo); @@ -1631,7 +1633,9 @@ static void binder_transaction(struct binder_proc *proc, return_error = BR_FAILED_REPLY; goto err_binder_get_ref_for_node_failed; } + fp->binder = 0; fp->handle = new_ref->desc; + fp->cookie = 0; binder_inc_ref(new_ref, fp->type == BINDER_TYPE_HANDLE, NULL); trace_binder_transaction_ref_to_ref(t, ref, new_ref); @@ -1685,6 +1689,7 @@ static void binder_transaction(struct binder_proc *proc, binder_debug(BINDER_DEBUG_TRANSACTION, " fd %d -> %d\n", fp->handle, target_fd); /* TODO: fput? */ + fp->binder = 0; fp->handle = target_fd; } break;