From: "Eric W. Biederman" <ebiederm@xmission.com>
To: Oleg Nesterov <oleg@redhat.com>
Cc: Thomas Gleixner <tglx@kernel.org>,
Frederic Weisbecker <frederic@kernel.org>,
Hyunwoo Kim <imv4bel@gmail.com>,
brauner@kernel.org, peterz@infradead.org,
anna-maria@linutronix.de, linux-kernel@vger.kernel.org
Subject: Re: [PATCH V2] signal: Prevent exec() race
Date: Wed, 02 Sep 2026 10:39:16 -0500 [thread overview]
Message-ID: <87ecfbd5nf.fsf@email.froward.int.ebiederm.org> (raw)
In-Reply-To: <apgwWTwG_oq3ij8n@redhat.com> (Oleg Nesterov's message of "Wed, 2 Sep 2026 16:19:05 +0200")
Oleg Nesterov <oleg@redhat.com> writes:
> as for the change on exit_signal,
>
> On 09/01, Thomas Gleixner wrote:
>>
>> @@ -3120,6 +3137,7 @@ static void retarget_shared_pending(stru
>>
>> void exit_signals(struct task_struct *tsk)
>> {
>> + LIST_HEAD(sigq_list);
>> int group_stop = 0;
>> sigset_t unblocked;
>>
>> @@ -3130,8 +3148,12 @@ void exit_signals(struct task_struct *ts
>> cgroup_threadgroup_change_begin(tsk);
>>
>> if (thread_group_empty(tsk) || (tsk->signal->flags & SIGNAL_GROUP_EXIT)) {
>> - tsk->flags |= PF_EXITING;
>> + scoped_guard(spinlock_irq, &tsk->sighand->siglock) {
>> + tsk->flags |= PF_EXITING;
>> + sigqueue_dequeue_pending(&tsk->pending, &sigq_list);
>> + }
>> cgroup_threadgroup_change_end(tsk);
>> + flush_sigqueue_list(&sigq_list);
>> return;
>> }
>>
>> @@ -3141,6 +3163,7 @@ void exit_signals(struct task_struct *ts
>> * see wants_signal(), do_signal_stop().
>> */
>> tsk->flags |= PF_EXITING;
>> + sigqueue_dequeue_pending(&tsk->pending, &sigq_list);
>>
>> cgroup_threadgroup_change_end(tsk);
>>
>> @@ -3157,6 +3180,8 @@ void exit_signals(struct task_struct *ts
>> out:
>> spin_unlock_irq(&tsk->sighand->siglock);
>>
>> + flush_sigqueue_list(&sigq_list);
>> +
>> /*
>> * If group stop has completed, deliver the notification. This
>> * should always go to the real parent of the group leader.
>
> This is subjective and mostly cosmetic, but what do you think
> about the alternative change below?
>
> I won't insist, but to me both the patch and resulting code look
> a bit simpler this way.
I agree that simply removing the special case that could skip grabbing
siglock is more maintainable. Just one last thing to think about.
Oleg it appears you were the one who added the special case to skip
taking siglock. So if you aren't worried about us removing it then
I am happy to see it go.
Eric
> Oleg.
> ---
>
> --- a/kernel/signal.c
> +++ b/kernel/signal.c
> @@ -3120,6 +3120,7 @@ static void retarget_shared_pending(struct task_struct *tsk, sigset_t *which)
>
> void exit_signals(struct task_struct *tsk)
> {
> + LIST_HEAD(sigq_list);
> int group_stop = 0;
> sigset_t unblocked;
>
> @@ -3129,21 +3130,18 @@ void exit_signals(struct task_struct *tsk)
> */
> cgroup_threadgroup_change_begin(tsk);
>
> - if (thread_group_empty(tsk) || (tsk->signal->flags & SIGNAL_GROUP_EXIT)) {
> - tsk->flags |= PF_EXITING;
> - cgroup_threadgroup_change_end(tsk);
> - return;
> - }
> -
> spin_lock_irq(&tsk->sighand->siglock);
> /*
> * From now this task is not visible for group-wide signals,
> * see wants_signal(), do_signal_stop().
> */
> tsk->flags |= PF_EXITING;
> + sigqueue_dequeue_pending(&tsk->pending, &sigq_list);
>
> cgroup_threadgroup_change_end(tsk);
>
> + if (thread_group_empty(tsk) || (tsk->signal->flags & SIGNAL_GROUP_EXIT))
> + goto out;
> if (!task_sigpending(tsk))
> goto out;
> @@ -3157,6 +3155,7 @@ void exit_signals(struct task_struct *tsk)
> out:
> spin_unlock_irq(&tsk->sighand->siglock);
>
> + flush_sigqueue_list(&sigq_list);
> /*
> * If group stop has completed, deliver the notification. This
> * should always go to the real parent of the group leader.
next prev parent reply other threads:[~2026-09-02 15:39 UTC|newest]
Thread overview: 49+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-22 5:37 [PATCH] signal: Use list_del_init_careful() in flush_sigqueue() Hyunwoo Kim
2026-08-22 10:27 ` Bradley Morgan
2026-08-23 12:47 ` Oleg Nesterov
2026-08-24 2:53 ` Hyunwoo Kim
2026-08-24 8:28 ` Oleg Nesterov
2026-08-24 8:04 ` Thomas Gleixner
2026-08-24 9:45 ` Thomas Gleixner
2026-08-24 11:02 ` Oleg Nesterov
2026-08-24 11:54 ` Oleg Nesterov
2026-08-24 13:59 ` Frederic Weisbecker
2026-08-24 14:29 ` Oleg Nesterov
2026-08-25 16:58 ` Thomas Gleixner
2026-08-25 18:53 ` Oleg Nesterov
2026-08-25 19:58 ` Thomas Gleixner
2026-08-26 9:36 ` Oleg Nesterov
2026-08-26 19:19 ` Thomas Gleixner
2026-08-26 19:32 ` Oleg Nesterov
2026-08-27 3:29 ` Eric W. Biederman
2026-08-27 9:35 ` Thomas Gleixner
2026-08-27 18:43 ` Eric W. Biederman
2026-08-27 22:56 ` Thomas Gleixner
2026-08-30 18:19 ` Thomas Gleixner
2026-08-30 22:04 ` Eric W. Biederman
2026-08-31 9:53 ` Thomas Gleixner
2026-08-31 10:50 ` [PATCH] signal: Prevent exec() race Thomas Gleixner
2026-08-31 11:35 ` David Laight
2026-08-31 12:44 ` Oleg Nesterov
2026-09-01 12:49 ` Thomas Gleixner
2026-08-31 12:52 ` Frederic Weisbecker
2026-09-01 12:55 ` Thomas Gleixner
2026-09-01 13:27 ` Frederic Weisbecker
2026-09-01 15:14 ` Thomas Gleixner
2026-08-31 15:26 ` Eric W. Biederman
2026-09-01 13:35 ` Thomas Gleixner
2026-09-01 17:21 ` Eric W. Biederman
2026-09-01 18:40 ` [PATCH V2] " Thomas Gleixner
2026-09-02 10:28 ` Oleg Nesterov
2026-09-02 10:45 ` Oleg Nesterov
2026-09-03 6:09 ` Thomas Gleixner
2026-09-02 11:23 ` Oleg Nesterov
2026-09-02 14:19 ` Oleg Nesterov
2026-09-02 15:39 ` Eric W. Biederman [this message]
2026-09-02 17:08 ` Oleg Nesterov
2026-09-03 6:42 ` Thomas Gleixner
2026-09-03 7:29 ` Oleg Nesterov
2026-08-27 12:24 ` [PATCH] signal: Use list_del_init_careful() in flush_sigqueue() Thomas Gleixner
2026-08-27 17:51 ` Thomas Gleixner
2026-08-24 12:11 ` Thomas Gleixner
2026-08-24 16:31 ` Frederic Weisbecker
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=87ecfbd5nf.fsf@email.froward.int.ebiederm.org \
--to=ebiederm@xmission.com \
--cc=anna-maria@linutronix.de \
--cc=brauner@kernel.org \
--cc=frederic@kernel.org \
--cc=imv4bel@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=oleg@redhat.com \
--cc=peterz@infradead.org \
--cc=tglx@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®