From: Steven Rostedt <rostedt@goodmis.org>
To: LKML <linux-kernel@vger.kernel.org>
Cc: Andrew Morton <akpm@osdl.org>, Ingo Molnar <mingo@elte.hu>
Subject: [Question] race condition with remove_proc_entry
Date: Fri, 30 Dec 2005 15:04:35 -0500 [thread overview]
Message-ID: <1135973075.6039.63.camel@localhost.localdomain> (raw)
I'm just curious if it is know that remove_proc_entry has an inherit
race condition? I have a modified kernel that would add and remove
stuff from the proc system and it would every so often crash. I traced
the bug to remove_proc_entry.
for (p = &parent->subdir; *p; p=&(*p)->next ) {
if (!proc_match(len, fn, *p))
continue;
Looking at proc_match
int proc_match(int len, const char *name, struct proc_dir_entry *de)
{
if (de->namelen != len)
return 0;
return !memcmp(name, de->name, len);
}
The bug would happen either at de->namelen in proc_match or in the loop
of p=&(*p)->next.
The race is if two threads remove two entries that are siblings. Since
p = &(*p)->next, and this is then dereferenced, the race is with *p
becoming NULL.
The way I'm fixing this is to put a lock around the call to
remove_proc_entry. But is this race already known and the solution is
to have the callers perform their own locking? Or is this an actual
bug? If it is not a bug, where's the documentation on having callers
protect it?
Thanks,
-- Steve
next reply other threads:[~2005-12-30 20:04 UTC|newest]
Thread overview: 25+ messages / expand[flat|nested] mbox.gz Atom feed top
2005-12-30 20:04 Steven Rostedt [this message]
2005-12-30 21:28 ` [PATCH] protect remove_proc_entry Steven Rostedt
2005-12-30 21:34 ` Daniel Walker
2005-12-30 21:55 ` Steven Rostedt
2005-12-30 21:55 ` Mitchell Blank Jr
2005-12-30 22:09 ` Steven Rostedt
2005-12-30 22:18 ` Steven Rostedt
2006-01-04 9:21 ` Andrew Morton
2006-01-04 12:18 ` Steven Rostedt
2006-01-05 1:48 ` Mitchell Blank Jr
2006-01-07 11:25 ` Andrew Morton
2005-12-30 22:11 ` Steven Rostedt
2005-12-30 23:46 ` Andrew Morton
2005-12-31 6:58 ` Steven Rostedt
2005-12-31 8:34 ` Arjan van de Ven
2005-12-31 8:53 ` Kirill Korotaev
2006-01-04 9:36 ` Andrew Morton
2006-01-04 11:27 ` Kirill Korotaev
2006-01-02 13:02 ` Steven Rostedt
2006-01-07 11:36 ` Andrew Morton
2006-01-07 12:04 ` Steven Rostedt
2006-01-09 19:16 ` Steven Rostedt
2006-01-10 0:59 ` Steven Rostedt
2006-01-10 1:05 ` Ingo Molnar
2006-01-10 13:26 ` Steven Rostedt
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1135973075.6039.63.camel@localhost.localdomain \
--to=rostedt@goodmis.org \
--cc=akpm@osdl.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@elte.hu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome