From: "Jacek Łuczak" <difrost@pin.if.uz.zgora.pl>
To: linux-kernel@vger.kernel.org
Subject: Re: forkbombing Linux distributions
Date: Wed, 30 Mar 2005 19:40:28 +0200 [thread overview]
Message-ID: <424AE48C.8000805@pin.if.uz.zgora.pl> (raw)
[-- Attachment #1: Type: text/plain, Size: 627 bytes --]
Hi
I made some tests and almost all Linux distros brings down while freebsd
survive!Forkbombing is a big problem but i don't think that something like
max_threads = mempages / (16 * THREAD_SIZE / PAGE_SIZE);
is good solution!!!
How about add max_user_threads to the kernel? It could be tunable via
proc filesystem. Limit is set only for users.
I made a fast:) patch - see below - and test it on 2.6.11,
2.6.11ac4,2.6.12rc1...works great!!!New forks are stoped in
copy_process() before dup_task_struct() and EAGAIN is returned. System
works without any problems and root can killall -9 forkbomb.
Regards,
Jacek Luczak
[-- Attachment #2: user_threads_limit.patch --]
[-- Type: text/plain, Size: 3009 bytes --]
--- linux-2.6.12-rc1/kernel/fork.c 2005-03-29 00:53:37.000000000 +0200
+++ linux/kernel/fork.c 2005-03-29 00:54:19.000000000 +0200
@@ -57,6 +57,8 @@
int max_threads; /* tunable limit on nr_threads */
+int max_user_threads; /* tunable limit on nr_threads per user */
+
DEFINE_PER_CPU(unsigned long, process_counts) = 0;
__cacheline_aligned DEFINE_RWLOCK(tasklist_lock); /* outer */
@@ -146,6 +148,21 @@
if(max_threads < 20)
max_threads = 20;
+ /*
+ * The default maximum number of threads per user.
+ *
+ * FIXME: this value is based on my experiments and is
+ * rather good on desktop system; it should be fixed to
+ * the more universal value.
+ */
+ max_user_threads = 300;
+
+ /*
+ * default value is too high - set to max_threads
+ */
+ if (max_threads < max_user_threads)
+ max_user_threads = max_threads;
+
init_task.signal->rlim[RLIMIT_NPROC].rlim_cur = max_threads/2;
init_task.signal->rlim[RLIMIT_NPROC].rlim_max = max_threads/2;
init_task.signal->rlim[RLIMIT_SIGPENDING] =
@@ -179,6 +196,16 @@
return tsk;
}
+/*
+ * This is used to get number of user processes
+ * from current running task.
+ */
+static inline int get_user_processes(void)
+{
+ return atomic_read(¤t->user->processes);
+}
+#define user_nr_processes get_user_processes()
+
#ifdef CONFIG_MMU
static inline int dup_mmap(struct mm_struct * mm, struct mm_struct * oldmm)
{
@@ -869,6 +896,13 @@
goto fork_out;
retval = -ENOMEM;
+
+ /*
+ * Stop creation of new user process if limit is reached.
+ */
+ if ( (current->user != &root_user) && (user_nr_processes >= max_user_threads) )
+ goto max_user_fork;
+
p = dup_task_struct(current);
if (!p)
goto fork_out;
@@ -1109,6 +1143,9 @@
return ERR_PTR(retval);
return p;
+max_user_fork:
+ retval = -EAGAIN;
+ return ERR_PTR(retval);
bad_fork_cleanup_namespace:
exit_namespace(p);
bad_fork_cleanup_keys:
--- linux-2.6.12-rc1/kernel/sysctl.c 2005-03-29 00:53:38.000000000 +0200
+++ linux/kernel/sysctl.c 2005-03-29 00:54:19.000000000 +0200
@@ -56,6 +56,7 @@
extern int sysctl_overcommit_memory;
extern int sysctl_overcommit_ratio;
extern int max_threads;
+extern int max_user_threads;
extern int sysrq_enabled;
extern int core_uses_pid;
extern char core_pattern[];
@@ -642,6 +643,14 @@
.mode = 0644,
.proc_handler = &proc_dointvec,
},
+ {
+ .ctl_name = KERN_MAX_USER_THREADS,
+ .procname = "user_threads_max",
+ .data = &max_user_threads,
+ .maxlen = sizeof(int),
+ .mode = 0644,
+ .proc_handler = &proc_dointvec,
+ },
{ .ctl_name = 0 }
};
--- linux-2.6.12-rc1/include/linux/sysctl.h 2005-03-29 00:54:06.000000000 +0200
+++ linux/include/linux/sysctl.h 2005-03-29 00:54:36.000000000 +0200
@@ -136,6 +136,7 @@
KERN_UNKNOWN_NMI_PANIC=66, /* int: unknown nmi panic flag */
KERN_BOOTLOADER_TYPE=67, /* int: boot loader type */
KERN_RANDOMIZE=68, /* int: randomize virtual address space */
+ KERN_MAX_USER_THREADS=69, /* int: Maximum nr of threads per user in the system */
};
[-- Attachment #3: difrost.vcf --]
[-- Type: text/x-vcard, Size: 304 bytes --]
begin:vcard
fn;quoted-printable:Jacek =C5=81uczak
n;quoted-printable:=C5=81uczak;Jacek
adr:;;Prof. Z. Szafrana 4a;Zielona Gora;;65-516;Poland
email;internet:difrost@pin.if.uz.zgora.pl
title:Linux Registered User # 337142
x-mozilla-html:FALSE
url:http://pin.if.uz.zgora.pl/~difrost
version:2.1
end:vcard
next reply other threads:[~2005-03-30 18:40 UTC|newest]
Thread overview: 51+ messages / expand[flat|nested] mbox.gz Atom feed top
2005-03-30 17:40 Jacek Łuczak [this message]
2005-03-31 10:00 ` Natanael Copa
2005-03-31 17:11 ` Lee Revell
2005-04-05 9:47 ` Natanael Copa
2005-04-05 10:18 ` Jacek Luczak
-- strict thread matches above, loose matches on Subject: below --
2005-03-28 17:28 Matthieu Castet
2005-03-28 17:56 ` folkert
2005-03-28 19:33 ` Jan Engelhardt
2005-03-28 19:39 ` folkert
2005-03-28 20:35 ` Renate Meijer
2005-03-29 12:31 ` Natanael Copa
2005-03-30 23:46 ` Felipe Alfaro Solana
2005-03-31 6:55 ` Natanael Copa
2005-03-31 7:09 ` Jacek Łuczak
2005-03-22 17:09 Natanael Copa
2005-03-21 3:06 William Beebe
2005-03-21 3:22 ` Dave Jones
2005-03-21 3:26 ` William Beebe
2005-03-21 3:27 ` Peter Chubb
2005-03-21 5:14 ` Grant Coady
2005-03-21 7:41 ` Jan Engelhardt
2005-03-22 11:26 ` Hikaru1
2005-03-22 11:49 ` Jan Engelhardt
[not found] ` <20050322124812.GB18256@roll>
2005-03-22 12:50 ` Hikaru1
2005-03-23 10:56 ` aq
2005-03-23 12:37 ` Natanael Copa
2005-03-23 13:04 ` aq
2005-03-23 13:38 ` Jan Engelhardt
2005-03-23 13:54 ` Natanael Copa
2005-03-23 14:20 ` Måns Rullgård
2005-03-23 14:43 ` Jan Engelhardt
2005-03-23 15:04 ` Natanael Copa
2005-03-24 7:07 ` Jan Engelhardt
2005-03-24 10:05 ` Natanael Copa
2005-03-23 19:38 ` Kyle Moffett
2005-03-23 20:26 ` Natanael Copa
2005-03-23 17:05 ` aq
2005-03-23 18:05 ` Paul Jackson
2005-03-23 18:44 ` aq
2005-03-23 20:15 ` Natanael Copa
2005-03-23 20:48 ` Natanael Copa
2005-03-23 13:45 ` Erik Mouw
2005-03-23 14:03 ` Natanael Copa
2005-03-23 13:53 ` Max Kellermann
2005-03-23 14:23 ` Natanael Copa
2005-03-23 14:27 ` Max Kellermann
2005-03-23 14:44 ` Natanael Copa
2005-03-23 14:52 ` Max Kellermann
2005-03-23 15:18 ` Natanael Copa
2005-03-26 10:37 ` Tux
2005-03-28 8:03 ` Natanael Copa
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=424AE48C.8000805@pin.if.uz.zgora.pl \
--to=difrost@pin.if.uz.zgora.pl \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®