From: Linus Torvalds <torvalds@linux-foundation.org>
To: Alexey Dobriyan <adobriyan@gmail.com>
Cc: viro@zeniv.linux.org.uk, ebiederm@xmission.com,
akpm@linux-foundation.org, linux-kernel@vger.kernel.org
Subject: Re: 2.6.27-rc7-sha1: EIP at proc_sys_compare+0x36/0x50
Date: Fri, 26 Sep 2008 08:47:51 -0700 (PDT) [thread overview]
Message-ID: <alpine.LFD.1.10.0809260838120.3265@nehalem.linux-foundation.org> (raw)
In-Reply-To: <20080926152031.GA30831@x200.localdomain>
On Fri, 26 Sep 2008, Alexey Dobriyan wrote:
>
> Gentlemen, this happened while script was slowly rebuilding 300+ configs
> sequentially. Very little recompling activity itself, much seeking.
>
> This is first time I see this. No debugging was on, no preemption.
>
> Version: 2.6.27-rc7-c0f4d6d4b14a75a341d972ff73fb9740e1ceb634 +
> atl1 fixlet + "notes" kobject fixlet, but they don't matter.
>
> ffffffff802bc690 <proc_sys_compare>:
....
> ffffffff802bc6c0: 75 dd jne ffffffff802bc69f <proc_sys_compare+0xf>
> ffffffff802bc6c2: 49 8b 40 e0 mov -0x20(%r8),%rax
> ffffffff802bc6c6: ===> 48 8b 78 f0 mov -0x10(%rax),%rdi <===
> ffffffff802bc6ca: e8 71 96 f7 ff callq ffffffff80235d40 <sysctl_is_seen>
That would be the
sysctl_is_seen(PROC_I(dentry->d_inode)->sysctl)
call, and it really looks like 'dentry->d_inode' is NULL:
> [16526.029537] BUG: unable to handle kernel paging request at fffffffffffffff0
The whole PROC_I() thing just offsets from the inode:
container_of(inode, struct proc_inode, vfs_inode);
and 'sysctl' is indeed 16 bytes below the vfs inode on x86-64:
struct proc_inode {
...
struct ctl_table_header *sysctl;
struct ctl_table *sysctl_entry;
struct inode vfs_inode;
};
and as far as I can tell, there is nothing to say that a /proc inode
cannot be a negative dentry. Sure, we try to get rid of them, but during a
parallel lookup, we will have added the dentry with a NULL inode in the
other lookup.
So assuming that you have an inode at that point seems to be utter crap.
Now, the whole _function_ is utter crap and should probably be dropped,
but whatever. That's just another sysctl insanity. In the meantime,
something like this does look appropriate, no?
Al, did I miss something?
Linus
---
fs/proc/proc_sysctl.c | 2 ++
1 files changed, 2 insertions(+), 0 deletions(-)
diff --git a/fs/proc/proc_sysctl.c b/fs/proc/proc_sysctl.c
index f9a8b89..9435fd0 100644
--- a/fs/proc/proc_sysctl.c
+++ b/fs/proc/proc_sysctl.c
@@ -386,6 +386,8 @@ static int proc_sys_compare(struct dentry *dir, struct qstr *qstr,
return 1;
if (memcmp(qstr->name, name->name, name->len))
return 1;
+ if (!dentry->d_inode)
+ return 1;
return !sysctl_is_seen(PROC_I(dentry->d_inode)->sysctl);
}
next prev parent reply other threads:[~2008-09-26 15:48 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2008-09-26 15:20 Alexey Dobriyan
2008-09-26 15:47 ` Linus Torvalds [this message]
2008-09-27 8:44 ` Eric W. Biederman
2008-09-28 20:38 ` Linus Torvalds
2008-09-28 14:18 ` Al Viro
2008-09-28 19:28 ` Hugh Dickins
2008-09-28 20:55 ` Linus Torvalds
2008-09-28 20:59 ` Linus Torvalds
2008-09-28 22:07 ` Hugh Dickins
2008-09-29 3:05 ` Eric W. Biederman
2008-09-28 20:46 ` Linus Torvalds
2008-09-28 20:50 ` Linus Torvalds
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=alpine.LFD.1.10.0809260838120.3265@nehalem.linux-foundation.org \
--to=torvalds@linux-foundation.org \
--cc=adobriyan@gmail.com \
--cc=akpm@linux-foundation.org \
--cc=ebiederm@xmission.com \
--cc=linux-kernel@vger.kernel.org \
--cc=viro@zeniv.linux.org.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome