From 87d20082537ebaa7ca762de79642d0ea2b681bb4 Mon Sep 17 00:00:00 2001 From: Kalesh Singh Date: Mon, 19 May 2025 11:10:04 -0700 Subject: [PATCH 1/2] ANDROID: 16K: Remove ELF padding entry from map_file ranges MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Symbolization techniques use address ranges as reported in /proc/*/maps to infer the corresponding /proc/*/map_files/ entry. Per Daniel, this is done because the path in /proc/*/maps is problematic for at least two reasons: 1. The file could have been deleted from the file system (this is indicated with the (deleted) suffix), meaning that you can't actually open it through the "regular" file system. However, while the mapping is alive, the kernel keeps the inode accessible via the corresponding /proc/*/map_files entry, allowing for access after all. 2. It makes dealing with changed root and file system namespaces much more painful. The /proc/*/maps path is relative, and so now you need to concatenate paths etc. Accessing file through /proc/*/map_files just works (assuming necessary permissions), as the kernel redirects the request to the proper inode, irrespective of how it is exposed through the non-proc filesystem. Android extends ELF padding regions to be contiguously mapped in memory to mitigate increase in unreclaimable VMA slab memory usage. Commit 8c2a805a857914324b077708b45c31c2f20d02da [1] emulates the padding region of such extended mappings to be outputted as PROT_NONE [page size compat] entries from /proc/*/[s]maps. This breaks the use case of /proc/*/maps_files/, as the ranges in /proc/*/map_files/ are the true ranges of the actual underlying VMA layout; while those in /proc/*/[s]maps are the emulated (shortened) ranges. Remove the padding (extended) ranges from /proc/*/maps_files entries. ====== Example Output ====== === maps === ❯ adb shell cat /proc/1/maps | grep -A1 libdl_android.so | sed '$d' 7f76663df000-7f76663e0000 r--p 00000000 fe:09 1911 /system/lib64/bootstrap/libdl_android.so 7f76663e0000-7f76663e3000 ---p 00000000 00:00 0 [page size compat] 7f76663e3000-7f76663e4000 r-xp 00004000 fe:09 1911 /system/lib64/bootstrap/libdl_android.so 7f76663e4000-7f76663e7000 ---p 00000000 00:00 0 [page size compat] 7f76663e7000-7f76663e8000 r--p 00008000 fe:09 1911 /system/lib64/bootstrap/libdl_android.s === map_files - Before patch === ❯ adb shell ls /proc/1/map_files | grep -A2 7f76663df000 7f76663df000-7f76663e3000 7f76663e3000-7f76663e7000 7f76663e7000-7f76663e8000 === map_files - After patch === ❯ adb shell ls /proc/1/map_files | grep -A2 7f76663df000 7f76663df000-7f76663e0000 7f76663e3000-7f76663e4000 7f76663e7000-7f76663e8000 [1] https://android.googlesource.com/kernel/common/+/8c2a805a857914324b077708b45c31c2f20d02da Bug: 418042003 Change-Id: I0f6d703715a0e709fa1d4bd52241b5fd913dd55e Reported-by: Daniel Müller Signed-off-by: Kalesh Singh --- fs/proc/base.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/fs/proc/base.c b/fs/proc/base.c index db9040c4f996..2d1b980df507 100644 --- a/fs/proc/base.c +++ b/fs/proc/base.c @@ -65,6 +65,7 @@ #include #include #include +#include #include #include #include @@ -2290,7 +2291,7 @@ proc_map_files_readdir(struct file *file, struct dir_context *ctx) } p->start = vma->vm_start; - p->end = vma->vm_end; + p->end = VMA_PAD_START(vma); p->mode = vma->vm_file->f_mode; } up_read(&mm->mmap_sem); From 19c222d1fa1b012550595ea81fc039b4b57d933e Mon Sep 17 00:00:00 2001 From: zhanghao56 Date: Tue, 13 May 2025 16:23:13 +0800 Subject: [PATCH 2/2] ANDROID: binder: fix minimum node priority comparison The "desired" priority for a transaction can be adjusted depending on various factors. For instance, it might be set to SCHED_NORMAL 120, when the caller is RT and the target node has !inherit_rt. However, instead of using these adjustments, the existing logic compares the minimum node priority against the original transaction priority. If the transaction priority is "higher", then the minimum node priority is ignored. This is particularly a problem when the "desired" priority has been changed to SCHED_NORMAL. This patch corrects the logic, comparing the minimum node priority against the (potentially adjusted) "desired" priority. This guarantees that the node's minimum priority is honored. Bug: 417382411 Cc: Martijn Coenen Fixes: c46810c23565 ("ANDROID: binder: add RT inheritance flag to node.") Change-Id: I813073241b996c1c38c29f20849b247023697102 Signed-off-by: zhanghao56 Signed-off-by: Carlos Llamas --- drivers/android/binder.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/android/binder.c b/drivers/android/binder.c index 4f7fdc2ab881..d87e0c0402c9 100644 --- a/drivers/android/binder.c +++ b/drivers/android/binder.c @@ -777,8 +777,8 @@ static void binder_transaction_priority(struct binder_thread *thread, desired.sched_policy = SCHED_NORMAL; } - if (node_prio.prio < t->priority.prio || - (node_prio.prio == t->priority.prio && + if (node_prio.prio < desired.prio || + (node_prio.prio == desired.prio && node_prio.sched_policy == SCHED_FIFO)) { /* * In case the minimum priority on the node is