From: "Serge E. Hallyn" <serue-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
To: Oren Laadan <orenl-eQaUEPhvms7ENvBUuze7eA@public.gmane.org>
Cc: Linux Containers
<containers-qjLDD68F18O7TbgM5vRIOg@public.gmane.org>,
David Howells <dhowells-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
Subject: Re: [PATCH 4/6] cr: checkpoint and restore task credentials
Date: Thu, 21 May 2009 09:14:50 -0500 [thread overview]
Message-ID: <20090521141450.GA13835@us.ibm.com> (raw)
In-Reply-To: <4A155EEC.9070509-eQaUEPhvms7ENvBUuze7eA@public.gmane.org>
Quoting Oren Laadan (orenl-eQaUEPhvms7ENvBUuze7eA@public.gmane.org):
>
>
> Serge E. Hallyn wrote:
> > Quoting Oren Laadan (orenl-eQaUEPhvms7ENvBUuze7eA@public.gmane.org):
> >>> /* dump the task_struct of a given task */
> >>> static int checkpoint_task_struct(struct ckpt_ctx *ctx, struct task_struct *t)
> >>> {
> >>> struct ckpt_hdr_task *h;
> >>> int ret;
> >>> + int realcred_ref, ecred_ref;
> >>> +
> >>> + realcred_ref = checkpoint_obj(ctx, t->real_cred, CKPT_OBJ_CRED);
> >>> + if (realcred_ref < 0)
> >>> + return realcred_ref;
> >>> +
> >>> + ecred_ref = checkpoint_obj(ctx, t->cred, CKPT_OBJ_CRED);
> >>> + if (ecred_ref < 0)
> >>> + return ecred_ref;
> >> Is this safe even if the checkpointed task's state changes ?
> >> (e.g. unfrozen - yes, I know there is a patch in the works to
> >> prevent this; but if we ever want to checkpoint STOPPED tasks...
> >> for instance).
> >>
> >> Would incrementing the refcount on t->{cred,real_cred} help ?
> >
> > Doesn't checkpoint_obj already do that through obj_new?
> >
>
> No, it does not. There is a (potentially long) window of opportunity
> between the callback invoked from checkpoint_obj() - where the pointer
> is used, and when checkpoint_obj() later takes the extra reference.
>
> See for comparison checkpoint_mm_obj(), it safely grabs the task->mm
> (with a reference) around the invocation of checkpoint_obj().
Hmm, ok. Will do.
-serge
next prev parent reply other threads:[~2009-05-21 14:14 UTC|newest]
Thread overview: 27+ messages / expand[flat|nested] mbox.gz Atom feed top
2009-05-19 1:44 [PATCH 0/6] cr: credentials Serge E. Hallyn
[not found] ` <20090519014446.GA28277-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2009-05-19 1:45 ` [PATCH 1/6] cr: break out new_user_ns() Serge E. Hallyn
2009-05-19 1:45 ` [PATCH 2/6] cr: split core function out of some set*{u,g}id functions Serge E. Hallyn
2009-05-19 1:45 ` [PATCH 3/6] cr: capabilities: define checkpoint and restore fns Serge E. Hallyn
2009-05-19 1:45 ` [PATCH 4/6] cr: checkpoint and restore task credentials Serge E. Hallyn
2009-05-19 1:45 ` [PATCH 5/6] cr: restore file->f_cred Serge E. Hallyn
[not found] ` <20090519014546.GE28312-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2009-05-20 15:08 ` Oren Laadan
[not found] ` <4A141CEE.2080100-eQaUEPhvms7ENvBUuze7eA@public.gmane.org>
2009-05-20 15:25 ` Serge E. Hallyn
[not found] ` <20090520152527.GA28585-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2009-05-20 15:26 ` Oren Laadan
2009-05-19 1:45 ` [PATCH 6/6] user namespaces: debug refcounts Serge E. Hallyn
[not found] ` <20090519014538.GD28312-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2009-05-19 8:26 ` [PATCH 4/6] cr: checkpoint and restore task credentials David Howells
[not found] ` <16258.1242721606-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
2009-05-19 13:35 ` Serge E. Hallyn
[not found] ` <20090519133526.GB32685-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2009-05-19 14:26 ` David Howells
[not found] ` <19394.1242743199-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
2009-05-19 14:46 ` Serge E. Hallyn
2009-05-20 15:35 ` Oren Laadan
[not found] ` <4A142350.1060308-eQaUEPhvms7ENvBUuze7eA@public.gmane.org>
2009-05-20 15:53 ` Serge E. Hallyn
[not found] ` <20090520155332.GA28999-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2009-05-20 16:08 ` Oren Laadan
[not found] ` <4A142B05.4040907-eQaUEPhvms7ENvBUuze7eA@public.gmane.org>
2009-05-20 16:13 ` Serge E. Hallyn
2009-05-20 16:54 ` Oren Laadan
[not found] ` <4A1435E0.3010306-eQaUEPhvms7ENvBUuze7eA@public.gmane.org>
2009-05-20 21:40 ` Serge E. Hallyn
[not found] ` <20090520214027.GA3517-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2009-05-21 14:02 ` Oren Laadan
[not found] ` <4A155EEC.9070509-eQaUEPhvms7ENvBUuze7eA@public.gmane.org>
2009-05-21 14:14 ` Serge E. Hallyn [this message]
2009-05-20 21:52 ` Serge E. Hallyn
[not found] ` <20090520215250.GB3517-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2009-05-21 14:13 ` Oren Laadan
2009-05-20 22:16 ` Serge E. Hallyn
[not found] ` <20090520221600.GA3925-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2009-05-21 6:03 ` Oren Laadan
2009-05-20 16:56 ` Oren Laadan
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20090521141450.GA13835@us.ibm.com \
--to=serue-r/jw6+rmf7hqt0dzr+alfa@public.gmane.org \
--cc=containers-qjLDD68F18O7TbgM5vRIOg@public.gmane.org \
--cc=dhowells-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org \
--cc=orenl-eQaUEPhvms7ENvBUuze7eA@public.gmane.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.