All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Serge E. Hallyn" <serue@us.ibm.com>
To: Paul Menage <menage@google.com>
Cc: Li Zefan <lizf@cn.fujitsu.com>,
	Andrew Morton <akpm@linux-foundation.org>,
	LKML <linux-kernel@vger.kernel.org>,
	Linux Containers <containers@lists.linux-foundation.org>
Subject: Re: [PATCH][BUGFIX] cgroups: fix pid namespace bug
Date: Thu, 2 Jul 2009 11:37:31 -0500	[thread overview]
Message-ID: <20090702163731.GA14267@us.ibm.com> (raw)
In-Reply-To: <6599ad830907020926t6305bec9t44a50cc165f6fc28@mail.gmail.com>

Quoting Paul Menage (menage@google.com):
> On Wed, Jul 1, 2009 at 6:24 PM, Li Zefan<lizf@cn.fujitsu.com> wrote:
> > +       cp = kzalloc(sizeof(*cp), GFP_KERNEL);
> > +       if (!cp) {
> > +               up_write(&cgrp->pids_mutex);
> > +               kfree(pidarray);
> > +               return -ENOMEM;
> > +       }
> > +       cp->cgrp = cgrp;
> > +       cp->pid_ns = pid_ns;
> 
> You're storing an uncounted reference to the pid ns here - there's no
> guarantee that the pid_ns will outlive the open file.

Yeah I was thinking about that, but

	1. the only way it won't outlive the open file is if the 
		task opens the file, hands the open fd over a
		unix socket, then exits as the last task of its
		pidns
	2. We don't dereference the pid_ns, so there is no actual
		safety issue.  So it would become a problem only
		if a new pidns gets created at that same address
		*and* a task in the new pidns opens the same
		tasks file.

Still, it wouldn't hurt to do get_pid_ns/put_pid_ns at the open
and release :)

-serge

  parent reply	other threads:[~2009-07-02 16:37 UTC|newest]

Thread overview: 40+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-07-02  1:24 [PATCH][BUGFIX] cgroups: fix pid namespace bug Li Zefan
2009-07-02  1:24 ` Li Zefan
2009-07-02 13:58 ` Serge E. Hallyn
     [not found] ` <4A4C0C60.4050106-BthXqXjhjHXQFUHtdCDX3A@public.gmane.org>
2009-07-02  1:36   ` Paul Menage
2009-07-02  1:36     ` Paul Menage
2009-07-02  1:45     ` Li Zefan
2009-07-02  1:57     ` KAMEZAWA Hiroyuki
2009-07-02 11:40       ` Balbir Singh
     [not found]       ` <20090702105707.8b2135d9.kamezawa.hiroyu-+CUm20s59erQFUHtdCDX3A@public.gmane.org>
2009-07-02 11:40         ` Balbir Singh
2009-07-02  2:17     ` Li Zefan
     [not found]       ` <4A4C18D5.7020806-BthXqXjhjHXQFUHtdCDX3A@public.gmane.org>
2009-07-02  2:20         ` Paul Menage
2009-07-02  2:20       ` Paul Menage
2009-07-02  2:28         ` Li Zefan
2009-07-02 13:26           ` Serge E. Hallyn
     [not found]             ` <20090702132659.GA8051-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2009-07-02 15:43               ` Paul Menage
2009-07-02 15:43             ` Paul Menage
2009-07-02 16:15               ` Serge E. Hallyn
2009-07-02 16:27                 ` Paul Menage
     [not found]                   ` <6599ad830907020927x44a88a6dgb229fb2ad6ef5481-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2009-07-02 23:20                     ` Andrew Morton
2009-07-02 23:20                   ` Andrew Morton
2009-07-02 23:29                     ` Paul Menage
     [not found]                     ` <20090702162019.f34f12d6.akpm-de/tnXTf+JLsfHDXvbKv3WD2FQJk+8+b@public.gmane.org>
2009-07-02 23:29                       ` Paul Menage
     [not found]                 ` <20090702161548.GA13383-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2009-07-02 16:27                   ` Paul Menage
2009-07-04  9:13               ` Eric W. Biederman
     [not found]               ` <6599ad830907020843l7ce75abfq3e78b8f67a407ab9-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2009-07-02 16:15                 ` Serge E. Hallyn
2009-07-04  9:13                 ` Eric W. Biederman
     [not found]           ` <4A4C1B33.2030002-BthXqXjhjHXQFUHtdCDX3A@public.gmane.org>
2009-07-02 13:26             ` Serge E. Hallyn
     [not found]         ` <6599ad830907011920r44df4022p53808b574da4a886-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2009-07-02  2:28           ` Li Zefan
     [not found]     ` <6599ad830907011836x5eccc83eyc896a67295a6486d-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2009-07-02  1:45       ` Li Zefan
2009-07-02  1:57       ` KAMEZAWA Hiroyuki
2009-07-02  2:17       ` Li Zefan
2009-07-02 13:58   ` Serge E. Hallyn
2009-07-02 16:26   ` Paul Menage
2009-07-02 16:26 ` Paul Menage
     [not found]   ` <6599ad830907020926t6305bec9t44a50cc165f6fc28-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2009-07-02 16:37     ` Serge E. Hallyn
2009-07-02 16:37   ` Serge E. Hallyn [this message]
2009-07-02 16:46     ` Paul Menage
     [not found]       ` <6599ad830907020946r42735c9es642bddf37af755ed-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2009-07-02 19:14         ` Serge E. Hallyn
2009-07-02 19:14       ` Serge E. Hallyn
     [not found]     ` <20090702163731.GA14267-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2009-07-02 16:46       ` Paul Menage

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20090702163731.GA14267@us.ibm.com \
    --to=serue@us.ibm.com \
    --cc=akpm@linux-foundation.org \
    --cc=containers@lists.linux-foundation.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=lizf@cn.fujitsu.com \
    --cc=menage@google.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.