From: Oleg Nesterov <oleg@tv-sign.ru>
To: Neil Horman <nhorman@tuxdriver.com>
Cc: Andrew Morton <akpm@linux-foundation.org>, linux-kernel@vger.kernel.org
Subject: Re: + proc-export-a-processes-resource-limits-via-proc-pid.patch added to -mm tree
Date: Sat, 18 Aug 2007 16:59:26 +0400 [thread overview]
Message-ID: <20070818125926.GA74@tv-sign.ru> (raw)
In-Reply-To: <20070818115816.GA23555@hmsreliant.think-freely.org>
On 08/18, Neil Horman wrote:
>
> On Sat, Aug 18, 2007 at 02:22:28AM +0400, Oleg Nesterov wrote:
> > Neil Horman wrote:
> > >
> > > +static int proc_pid_limits(struct task_struct *task, char *buffer)
> > > +{
> > > + unsigned int i;
> > > + int count = 0;
> > > + char *bufptr = buffer;
> > > +
> > > + struct rlimit rlim[RLIM_NLIMITS];
> > > +
> > > + read_lock(&tasklist_lock);
> > > + memcpy(rlim, task->signal->rlim, sizeof(struct rlimit) * RLIM_NLIMITS);
> > > + read_unlock(&tasklist_lock);
> >
> > Please don't re-introduce tasklist_lock unless strictly needed. And in this case
> > it doesn't help, sys_getrlimit() changes ->rlim[] under task_lock().
> >
> > Hovewer, I think the whole patch is not right. The "tsk" itself is pinned, but its
> > ->signal is not stable and can be == NULL.
> >
> > You can use lock_task_sighand() to access ->signal.
> >
> You're right about the use of task_lock rather than tasklist_lock in getrlimit,
> but the comment from lock_task_sighand indicates that its use is predicated on
> the prerequisite of locking tasklist_lock,
or rcu_read_lock(),
> so I think the situation is not that
> much of an issue. From what I see the use of lock_task_sighand is used when
> modifying values in the signal struct, not when removing it entirely (IIRC it
> needs to exist until such time as all sharing processes exit.
yes, it needs to exist until the whole process exits, but no, __exit_signal()
sets ->signal == NULL under sighand->siglock. This btw happens per thread.
> The fact that we
> have an outstanding task struct we are using here guarantees its continued
> existence).
No. proc_info_read() finds a "pid_alive()" task with a valid signal, and bumps
its ->usage. But nothing prevent this thread from exiting (in fact, it may be
already dead), after that the parent can reap that task, or it can reap itself
if it was detached thread.
This means that proc_read() can assume nothing about the task, except that its
task_struct can't disappear.
> Since we are only reading signal->rlimit, which is only written to
> from sys_setrlimit, we should be safe from corrupted limit reads, which at worst
> would cause an erroneous transient data read, rather than any sort of
> panic/crash.
->signal == NULL leads to panic().
Oleg.
next prev parent reply other threads:[~2007-08-18 12:56 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2007-08-17 22:22 Oleg Nesterov
2007-08-18 11:58 ` Neil Horman
2007-08-18 12:59 ` Oleg Nesterov [this message]
2007-08-18 18:55 ` Neil Horman
2007-08-18 19:03 ` Oleg Nesterov
2007-08-18 23:23 ` Neil Horman
2007-08-19 8:57 ` Oleg Nesterov
2007-08-19 13:03 ` Neil Horman
2007-08-19 15:19 ` Oleg Nesterov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20070818125926.GA74@tv-sign.ru \
--to=oleg@tv-sign.ru \
--cc=akpm@linux-foundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=nhorman@tuxdriver.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®