From: ebiederm@xmission.com (Eric W. Biederman)
To: Oleg Nesterov <oleg@tv-sign.ru>
Cc: Jean Delvare <jdelvare@suse.de>, Andrew Morton <akpm@osdl.org>,
KAMEZAWA Hiroyuki <kamezawa.hiroyu@jp.fujitsu.com>,
linux-kernel@vger.kernel.org, ak@suse.de
Subject: Re: [PATCH] proc-readdir-race-fix-take-3-fix-3
Date: Wed, 06 Sep 2006 16:59:12 -0600 [thread overview]
Message-ID: <m1r6yotxdr.fsf@ebiederm.dsl.xmission.com> (raw)
In-Reply-To: <20060906223838.GA198@oleg> (Oleg Nesterov's message of "Thu, 7 Sep 2006 02:38:38 +0400")
Oleg Nesterov <oleg@tv-sign.ru> writes:
> On 09/07, Oleg Nesterov wrote:
>>
>> On 09/06, Jean Delvare wrote:
>> >
>> > On Wednesday 6 September 2006 11:01, Jean Delvare wrote:
>> > > Eric, Kame, thanks a lot for working on this. I'll be giving some good
>> > > testing to this patch today, and will return back to you when I'm done.
>> >
>> > The original issue is indeed fixed, but there's a problem with the patch.
>> > When stressing /proc (to verify the bug was fixed), my test machine ended
>> > up crashing. Here are the 2 traces I found in the logs:
>> >
>> > Sep 6 12:06:00 arrakis kernel: BUG: warning at
>> > kernel/fork.c:113/__put_task_struct()
>> > Sep 6 12:06:00 arrakis kernel: [<c0115f93>] __put_task_struct+0xf3/0x100
>> > Sep 6 12:06:00 arrakis kernel: [<c019666a>] proc_pid_readdir+0x13a/0x150
>> > Sep 6 12:06:00 arrakis kernel: [<c01745f0>] vfs_readdir+0x80/0xa0
>> > Sep 6 12:06:00 arrakis kernel: [<c0174750>] filldir+0x0/0xd0
>> > Sep 6 12:06:00 arrakis kernel: [<c017488c>] sys_getdents+0x6c/0xb0
>> > Sep 6 12:06:00 arrakis kernel: [<c0174750>] filldir+0x0/0xd0
>> > Sep 6 12:06:00 arrakis kernel: [<c0102fb7>] syscall_call+0x7/0xb
>>
>> If the task found is not a group leader, we go to retry, but
>> the task != NULL.
>>
>> Now, if find_ge_pid(tgid) returns NULL, we return that wrong
>> task, and it was not get_task_struct()'ed.
Yep. That would do it. And of course having written the
code it was very hard for me to step back far enough to see that.
The other two failure modes still don't make sense to me but
they may have been a side effect of this.
And it would have taken a thread being the highest pid in the
system that exits while we are calling filldir to trigger this.
Wow. That was a good stress test.
Signed-off-by: Eric W. Biederman <ebiederm@xmission.com>
> Signed-off-by: Oleg Nesterov <oleg@tv-sign.ru>
>
> --- t/fs/proc/base.c~ 2006-09-07 02:33:26.000000000 +0400
> +++ t/fs/proc/base.c 2006-09-07 02:34:19.000000000 +0400
> @@ -2149,9 +2149,9 @@ static struct task_struct *next_tgid(uns
> struct task_struct *task;
> struct pid *pid;
>
> - task = NULL;
> rcu_read_lock();
> retry:
> + task = NULL;
> pid = find_ge_pid(tgid);
> if (pid) {
> tgid = pid->nr + 1;
next prev parent reply other threads:[~2006-09-06 23:00 UTC|newest]
Thread overview: 25+ messages / expand[flat|nested] mbox.gz Atom feed top
2006-08-25 9:29 [RFC][PATCH] ps command race fix take 4 [4/4] proc root open/release/llseek KAMEZAWA Hiroyuki
2006-09-04 23:13 ` [PATCH] proc: readdir race fix Eric W. Biederman
2006-09-05 1:30 ` KAMEZAWA Hiroyuki
2006-09-05 2:30 ` Eric W. Biederman
2006-09-05 2:41 ` KAMEZAWA Hiroyuki
2006-09-05 2:26 ` KAMEZAWA Hiroyuki
2006-09-05 2:54 ` Eric W. Biederman
2006-09-05 3:07 ` Eric W. Biederman
2006-09-05 5:39 ` KAMEZAWA Hiroyuki
2006-09-05 10:10 ` Oleg Nesterov
2006-09-05 11:36 ` Eric W. Biederman
2006-09-05 14:52 ` [PATCH] proc: readdir race fix (take 3) Eric W. Biederman
2006-09-06 9:01 ` Jean Delvare
2006-09-06 21:12 ` Jean Delvare
2006-09-06 22:25 ` Oleg Nesterov
2006-09-06 22:38 ` [PATCH] proc-readdir-race-fix-take-3-fix-3 Oleg Nesterov
2006-09-06 22:59 ` Eric W. Biederman [this message]
2006-09-08 6:38 ` Eric W. Biederman
2006-09-06 22:43 ` [PATCH] proc: readdir race fix (take 3) Eric W. Biederman
2006-09-07 8:31 ` Jean Delvare
2006-09-07 13:57 ` Eric W. Biederman
2006-09-07 18:07 ` Jean Delvare
2006-09-07 18:40 ` Eric W. Biederman
2006-09-05 5:26 ` [PATCH] proc: readdir race fix KAMEZAWA Hiroyuki
2006-09-05 5:41 ` KAMEZAWA Hiroyuki
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=m1r6yotxdr.fsf@ebiederm.dsl.xmission.com \
--to=ebiederm@xmission.com \
--cc=ak@suse.de \
--cc=akpm@osdl.org \
--cc=jdelvare@suse.de \
--cc=kamezawa.hiroyu@jp.fujitsu.com \
--cc=linux-kernel@vger.kernel.org \
--cc=oleg@tv-sign.ru \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®