mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Rusty Russell <rusty@rustcorp.com.au>
To: Andrey Borzenkov <arvidjaar@mail.ru>
Cc: Andrew Morton <akpm@osdl.org>, linux-kernel@vger.kernel.org
Subject: Re: Fw: rc3-mm1: oops in keventd_stop_kthread
Date: Thu, 05 Feb 2004 16:09:29 +1100	[thread overview]
Message-ID: <20040205060543.09B542C270@lists.samba.org> (raw)
In-Reply-To: Your message of "Wed, 04 Feb 2004 23:04:10 +0300." <20040204200410.GA3802@localhost.localdomain>

In message <20040204200410.GA3802@localhost.localdomain> you write:
> On Wed, Feb 04, 2004 at 02:00:06PM +1100, Rusty Russell wrote:
> > Um, why is ALSA using kthread?
> > 
> > Is there a modprobe -r in your script somewhere?
> 
> yes. not sure why it is called though.

Reproduced using your config, and fixed.  Classic use-after-free bug:
another victory for DEBUG_PAGEALLOC.

Thanks Andrey!
Rusty.
--
  Anyone who quotes me in their sig is an idiot. -- Rusty Russell.

Name: Kthread waitpid Race II
Author: Rusty Russell
Status: Tested on 2.6.2-rc3
Depends: Hotcpu/kthread-wait-race.patch.gz

We can't compare waitpid() result with stop->k->tgid, since the thread
will be gone by then (thanks to Andrey Borzenkov and
CONFIG_DEBUG_PAGEALLOC!

diff -urpN --exclude TAGS -X /home/rusty/devel/kernel/kernel-patches/current-dontdiff --minimal linux-2.6.2-rc3-mm1/kernel/kthread.c tmp/kernel/kthread.c
--- linux-2.6.2-rc3-mm1/kernel/kthread.c	2004-02-04 12:29:18.000000000 +1100
+++ tmp/kernel/kthread.c	2004-02-05 15:56:07.000000000 +1100
@@ -107,7 +112,7 @@ static void adopt_kthread(struct task_st
 static void keventd_stop_kthread(void *_stop)
 {
 	struct kthread_stop_info *stop = _stop;
-	int status;
+	int status, pid;
 	sigset_t blocked;
 	struct k_sigaction sa;
 
@@ -119,11 +124,14 @@ static void keventd_stop_kthread(void *_
 	allow_signal(SIGCHLD);
 
 	adopt_kthread(stop->k);
+	/* Grab pid now: after waitpid(), stop->k is invalid. */
+	pid = stop->k->tgid;
+
 	/* All signals are blocked, hence the force. */
 	force_sig(SIGTERM, stop->k);
 	/* Other threads might exit: if we ask for one pid that
 	 * returns -ERESTARTSYS. */
-	while (waitpid(-1, &status, __WALL) != stop->k->tgid)
+	while (waitpid(-1, &status, __WALL) != pid)
 		flush_signals(current);
 	stop->result = -((status >> 8) & 0xFF);
 	complete(&stop->done);

       reply	other threads:[~2004-02-05  6:05 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <20040204200410.GA3802@localhost.localdomain>
2004-02-05  5:09 ` Rusty Russell [this message]
2004-02-07 10:10   ` Andrey Borzenkov

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20040205060543.09B542C270@lists.samba.org \
    --to=rusty@rustcorp.com.au \
    --cc=akpm@osdl.org \
    --cc=arvidjaar@mail.ru \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®