[PATCH v3] binderfs: free minor on binder-control creation failure

Chao Huang <[email protected]>
Newsgroups gmane.linux.kernel
Message-ID <[email protected]>
From: Chao Huang <[email protected]>

Both binderfs_binder_ctl_create() implementations allocate a minor before
creating the binder-control dentry. If d_alloc_name() fails, the error path
frees the device and drops the inode, but leaves the minor allocated in
binderfs_minors. Repeated failures can therefore exhaust the global minor
IDA.

Release the minor from a dedicated error path after a successful allocation
in both implementations.

Signed-off-by: Chao Huang <[email protected]>
---
Changes in v3:
- Use a dedicated out_with_minor error path instead of an -ENOSPC sentinel.

 drivers/android/binder/rust_binderfs.c | 7 ++++++-
 drivers/android/binderfs.c             | 7 ++++++-
 2 files changed, 12 insertions(+), 2 deletions(-)

diff --git a/drivers/android/binder/rust_binderfs.c b/drivers/android/binder/rust_binderfs.c
index ade1c4d92499..0763e3db54bd 100644
--- a/drivers/android/binder/rust_binderfs.c
+++ b/drivers/android/binder/rust_binderfs.c
@@ -421,7 +421,7 @@ static int binderfs_binder_ctl_create(struct super_block *sb)
 
 	dentry = d_alloc_name(root, "binder-control");
 	if (!dentry)
-		goto out;
+		goto out_with_minor;
 
 	inode->i_private = device;
 	info->control_dentry = dentry;
@@ -430,6 +430,11 @@ static int binderfs_binder_ctl_create(struct super_block *sb)
 
 	return 0;
 
+out_with_minor:
+	mutex_lock(&binderfs_minors_mutex);
+	ida_free(&binderfs_minors, minor);
+	mutex_unlock(&binderfs_minors_mutex);
+
 out:
 	kfree(device);
 	iput(inode);
diff --git a/drivers/android/binderfs.c b/drivers/android/binderfs.c
index 361d69f756f5..0e96146ecf69 100644
--- a/drivers/android/binderfs.c
+++ b/drivers/android/binderfs.c
@@ -431,7 +431,7 @@ static int binderfs_binder_ctl_create(struct super_block *sb)
 
 	dentry = d_alloc_name(root, "binder-control");
 	if (!dentry)
-		goto out;
+		goto out_with_minor;
 
 	inode->i_private = device;
 	info->control_dentry = dentry;
@@ -440,6 +440,11 @@ static int binderfs_binder_ctl_create(struct super_block *sb)
 
 	return 0;
 
+out_with_minor:
+	mutex_lock(&binderfs_minors_mutex);
+	ida_free(&binderfs_minors, minor);
+	mutex_unlock(&binderfs_minors_mutex);
+
 out:
 	kfree(device);
 	iput(inode);

base-commit: c21bb4193868a8de71fc4693fa741e195fdf5d86
-- 
2.25.1
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.