]> git.ipfire.org Git - thirdparty/kernel/linux.git/commit
rust_binder: Avoid holding lock when dropping delivered_death
authorMatthew Maurer <mmaurer@google.com>
Fri, 3 Apr 2026 18:18:58 +0000 (18:18 +0000)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Fri, 22 May 2026 09:55:48 +0000 (11:55 +0200)
commitf6d8fea9e3953151a4adb4f603503dc3dc9c69da
tree3684d52ec49fbad4700814186731bc808aaf8ac4
parent4c19719eb8b8df08c5bec7c499f73ddaea6f09fc
rust_binder: Avoid holding lock when dropping delivered_death

In 6c37bebd8c926, we switched to looping over the list and dropping each
individual node, ostensibly without the lock held in the loop body.

If the kernel were using Rust Edition 2024, the comment would be
accurate, and the lock would not be held across the drop. However, the
kernel is currently using 2021, so tail expression lifetime extension
results in the lock being held across the drop. Explicitly binding the
expression result to a variable makes the lockguard no longer part of a
tail expression, causing the lock to be dropped before entering the loop
body.

This was detected via `CONFIG_PROVE_LOCKING` identifying an invalid wait
context at the drop site.

Reported-by: David Stevens <stevensd@google.com>
Signed-off-by: Matthew Maurer <mmaurer@google.com>
Cc: stable <stable@kernel.org>
Fixes: 6c37bebd8c92 ("rust_binder: avoid mem::take on delivered_deaths")
Reviewed-by: Alice Ryhl <aliceryhl@google.com>
Acked-by: Carlos Llamas <cmllamas@google.com>
Link: https://patch.msgid.link/20260403-lockhold-v1-1-c332b56cd8ae@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
drivers/android/binder/process.rs