From: "Jörn Engel" <joern@wohnheim.fh-wedel.de>
To: Paul Mackerras <paulus@samba.org>
Cc: benh@kernel.crashing.org, torvalds@osdl.org,
linux-kernel@vger.kernel.org, linuxppc-dev@lists.linuxppc.org
Subject: Re: [PATCH 2.5.73] Signal stack fixes #1 introduce PF_SS_ACTIVE
Date: Sun, 6 Jul 2003 12:17:54 +0200 [thread overview]
Message-ID: <20030706101754.GA23341@wohnheim.fh-wedel.de> (raw)
In-Reply-To: <16135.57910.936187.611245@cargo.ozlabs.ibm.com>
On Sun, 6 July 2003 18:47:50 +1000, Paul Mackerras wrote:
>
> You can get the same effect by doing kill(0, SIGINT) inside a handler
> for SIGINT. All you seem to be saying is "if you behave stupidly then
> bad things happen to you". I don't see that this example exposes any
> bug or vulnerability in the kernel.
Maybe we are just working under different assumptions, so let me
explain my background a little.
Two of the reasons, why open source works well, are frequent releases
and lots of feedback. In the embedded world, a typical number of
releases is one and a typical amount of feedback is none. So you
either create a perfect product or you arrange for feedback yourself.
Without any user interaction tools around, the best feedback you can
get is a core dump plus maybe some information from /proc. Remember
the borken patch for ppc I sent to you? We didn't get a core dump and
people were quite unhappy, so the investigation began.
In the course of the investigation, I found another spot, where we
didn't get a core dump, which started this whole thread. Guess what,
people aren't happy either. One workaround would be to never use the
signal stack, but if this can be fixed properly, I would see more
happy faces at work. And I like happy faces.
> You had to go to some trouble to get this effect - you had to use an
> asm statement to change the stack pointer, which is well and truly
> into "undefined behaviour" territory, and so you deserve all you
> get. :) It's a very contrived example IMHO.
There is an open source web server that, combined with a closed source
library, fscks up your stack pointer. I don't know how they did it
and I don't even care. What I do care about is that it happened, that
it can happen again any time, and that we handle this problem as
gracefully as possible. A core dump is graceful, a do_exit(SIGSEGV),
as it was in the ppc code is not, and an inifite loop is anything but
graceful.
I agree that my initial patch can cause other problems, but the
problem itself should still get fixed.
Jörn
--
More computing sins are committed in the name of efficiency (without
necessarily achieving it) than for any other single reason - including
blind stupidity.
-- W. A. Wulf
next prev parent reply other threads:[~2003-07-06 10:04 UTC|newest]
Thread overview: 30+ messages / expand[flat|nested] mbox.gz Atom feed top
2003-07-03 20:24 [PATCH 2.5.73] Fix broken signal optimization for i386 Jörn Engel
2003-07-04 17:43 ` Jörn Engel
2003-07-04 17:45 ` [PATCH 2.5.73] Signal stack fixes #1 introduce PF_SS_ACTIVE Jörn Engel
2003-07-04 17:51 ` [PATCH 2.5.73] Signal stack fixes #2 i386-specific Jörn Engel
2003-07-04 17:54 ` [PATCH 2.5.73] Signal stack fixes #1 introduce PF_SS_ACTIVE Jörn Engel
2003-07-04 17:58 ` [PATCH 2.5.73] Signal handling fix for ppc Jörn Engel
2003-07-04 23:26 ` Paul Mackerras
2003-07-05 7:33 ` Jörn Engel
2003-07-04 23:18 ` [PATCH 2.5.73] Signal stack fixes #1 introduce PF_SS_ACTIVE Paul Mackerras
2003-07-05 7:39 ` Jörn Engel
2003-07-06 8:47 ` Paul Mackerras
2003-07-06 10:17 ` Jörn Engel [this message]
2003-07-07 11:29 ` Paul Mackerras
2003-07-07 11:58 ` Jörn Engel
2003-07-07 11:33 ` Paul Mackerras
2003-07-07 11:46 ` Jörn Engel
2003-07-04 19:21 ` Linus Torvalds
2003-07-04 19:38 ` Jörn Engel
2003-07-04 20:06 ` Linus Torvalds
2003-07-04 20:18 ` Jörn Engel
2003-07-05 0:39 ` Linus Torvalds
2003-07-05 7:30 ` Jörn Engel
2003-07-05 10:44 ` Jörn Engel
2003-07-05 17:16 ` Linus Torvalds
2003-07-06 12:51 ` Jörn Engel
2003-07-07 9:30 ` [PATCH 2.5.74] Signal stack safety #2 i386 specific Jörn Engel
2003-07-05 17:06 ` [PATCH 2.5.73] Signal stack fixes #1 introduce PF_SS_ACTIVE Jamie Lokier
2003-07-06 1:27 ` Eric W. Biederman
2003-07-04 19:39 ` Davide Libenzi
2003-07-04 20:24 ` Jörn Engel
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20030706101754.GA23341@wohnheim.fh-wedel.de \
--to=joern@wohnheim.fh-wedel.de \
--cc=benh@kernel.crashing.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linuxppc-dev@lists.linuxppc.org \
--cc=paulus@samba.org \
--cc=torvalds@osdl.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®