From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1754521AbcH3UNh (ORCPT ); Tue, 30 Aug 2016 16:13:37 -0400 Received: from mx1.redhat.com ([209.132.183.28]:47902 "EHLO mx1.redhat.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751154AbcH3UNg (ORCPT ); Tue, 30 Aug 2016 16:13:36 -0400 Date: Tue, 30 Aug 2016 22:13:28 +0200 From: Mateusz Guzik To: Richard Guy Briggs Cc: Konstantin Khlebnikov , ebiederm@xmission.com, oleg@redhat.com, sgrubb@redhat.com, pmoore@redhat.com, eparis@redhat.com, luto@amacapital.net, linux-audit@redhat.com, linux-kernel@vger.kernel.org, Al Viro Subject: Re: [PATCHv2 0/2] introduce get_task_exe_file and use it to fix audit_exe_compare Message-ID: <20160830201327.z5tx3c53co2zwqsx@mguzik> References: <1471962039-14940-1-git-send-email-mguzik@redhat.com> <20160830185021.GL5983@madcap2.tricolour.ca> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline In-Reply-To: <20160830185021.GL5983@madcap2.tricolour.ca> User-Agent: Mutt/1.6.0.1 (2016-04-01) X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.5.16 (mx1.redhat.com [10.5.110.30]); Tue, 30 Aug 2016 20:13:35 +0000 (UTC) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Tue, Aug 30, 2016 at 02:50:21PM -0400, Richard Guy Briggs wrote: > On 2016-08-23 16:20, Mateusz Guzik wrote: > > audit_exe_compare directly accesses mm->exe_file without making sure the > > object is stable. Fixing it using current primitives results in > > partially duplicating what proc_exe_link is doing. > > > > As such, introduce a trivial helper which can be used in both places and > > fix the func. > > > > Changes since v1: > > * removed an unused 'out' label which crept in > > > > Mateusz Guzik (2): > > mm: introduce get_task_exe_file > > audit: fix exe_file access in audit_exe_compare > > The task_lock affects a much bigger struct than the mm ref count. Is > this really necessary? Is a spin-lock significantly lower cost than a > refcount? Other than that, this refactorization looks sensible. > proc_exe_link was taking the lock anyway to guarantee a stable mm. I think the helper cleans the code up a little bit and there is microoptimisation to not play with the refcount. If audit_exe_compare has guarantees the task wont reach exit_mm, it can use get_mm_exe_file which means the atomic op would be only on the file object. I was under the impression this is the expected behaviour, but your patch used the task lock to grab mm, so I mimicked it here. -- Mateusz Guzik