From: Oleg Nesterov <oleg@tv-sign.ru>
To: "Eric W. Biederman" <ebiederm@xmission.com>
Cc: Andrew Morton <akpm@osdl.org>, linux-kernel@vger.kernel.org
Subject: [PATCH] introduce get_task_pid() to fix unsafe get_pid()
Date: Mon, 11 Sep 2006 06:25:35 +0400 [thread overview]
Message-ID: <20060911022535.GA7095@oleg> (raw)
(COMPILE TESTED, needs an ack from Eric)
proc_pid_make_inode:
ei->pid = get_pid(task_pid(task));
I think this is not safe. get_pid() can be preempted after checking
"pid != NULL". Then the task exits, does detach_pid(), and RCU frees
the pid.
Signed-off-by: Oleg Nesterov <oleg@tv-sign.ru>
--- rc6-mm1/include/linux/pid.h~1_tgp 2006-09-09 22:34:50.000000000 +0400
+++ rc6-mm1/include/linux/pid.h 2006-09-11 05:46:14.000000000 +0400
@@ -68,6 +68,8 @@ extern struct task_struct *FASTCALL(pid_
extern struct task_struct *FASTCALL(get_pid_task(struct pid *pid,
enum pid_type));
+extern struct pid *get_task_pid(struct task_struct *task, enum pid_type type);
+
/*
* attach_pid() and detach_pid() must be called with the tasklist_lock
* write-held.
--- rc6-mm1/kernel/pid.c~1_tgp 2006-09-09 22:34:50.000000000 +0400
+++ rc6-mm1/kernel/pid.c 2006-09-11 05:39:23.000000000 +0400
@@ -305,6 +305,15 @@ struct task_struct *find_task_by_pid_typ
EXPORT_SYMBOL(find_task_by_pid_type);
+struct pid *get_task_pid(struct task_struct *task, enum pid_type type)
+{
+ struct pid *pid;
+ rcu_read_lock();
+ pid = get_pid(task->pids[type].pid);
+ rcu_read_unlock();
+ return pid;
+}
+
struct task_struct *fastcall get_pid_task(struct pid *pid, enum pid_type type)
{
struct task_struct *result;
--- rc6-mm1/fs/proc/base.c~1_tgp 2006-09-09 22:34:49.000000000 +0400
+++ rc6-mm1/fs/proc/base.c 2006-09-11 05:56:19.000000000 +0400
@@ -958,7 +958,7 @@ static struct inode *proc_pid_make_inode
/*
* grab the reference to task.
*/
- ei->pid = get_pid(task_pid(task));
+ ei->pid = get_task_pid(task, PIDTYPE_PID);
if (!ei->pid)
goto out_unlock;
@@ -1665,7 +1665,7 @@ static struct dentry *proc_base_instanti
/*
* grab the reference to the task.
*/
- ei->pid = get_pid(task_pid(task));
+ ei->pid = get_task_pid(task, PIDTYPE_PID);
if (!ei->pid)
goto out_iput;
next reply other threads:[~2006-09-11 2:25 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2006-09-11 2:25 Oleg Nesterov [this message]
2006-09-11 3:58 ` [PATCH] introduce get_task_pid() to fix unsafe get_pid() Eric W. Biederman
2006-09-11 4:37 ` Oleg Nesterov
2006-09-11 4:59 ` Eric W. Biederman
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20060911022535.GA7095@oleg \
--to=oleg@tv-sign.ru \
--cc=akpm@osdl.org \
--cc=ebiederm@xmission.com \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.