From: "Serge E. Hallyn" <serue@us.ibm.com>
To: Paul Menage <menage@google.com>
Cc: Li Zefan <lizf@cn.fujitsu.com>,
Andrew Morton <akpm@linux-foundation.org>,
LKML <linux-kernel@vger.kernel.org>,
Linux Containers <containers@lists.linux-foundation.org>
Subject: Re: [PATCH][BUGFIX] cgroups: fix pid namespace bug
Date: Thu, 2 Jul 2009 11:37:31 -0500 [thread overview]
Message-ID: <20090702163731.GA14267@us.ibm.com> (raw)
In-Reply-To: <6599ad830907020926t6305bec9t44a50cc165f6fc28@mail.gmail.com>
Quoting Paul Menage (menage@google.com):
> On Wed, Jul 1, 2009 at 6:24 PM, Li Zefan<lizf@cn.fujitsu.com> wrote:
> > + cp = kzalloc(sizeof(*cp), GFP_KERNEL);
> > + if (!cp) {
> > + up_write(&cgrp->pids_mutex);
> > + kfree(pidarray);
> > + return -ENOMEM;
> > + }
> > + cp->cgrp = cgrp;
> > + cp->pid_ns = pid_ns;
>
> You're storing an uncounted reference to the pid ns here - there's no
> guarantee that the pid_ns will outlive the open file.
Yeah I was thinking about that, but
1. the only way it won't outlive the open file is if the
task opens the file, hands the open fd over a
unix socket, then exits as the last task of its
pidns
2. We don't dereference the pid_ns, so there is no actual
safety issue. So it would become a problem only
if a new pidns gets created at that same address
*and* a task in the new pidns opens the same
tasks file.
Still, it wouldn't hurt to do get_pid_ns/put_pid_ns at the open
and release :)
-serge
next prev parent reply other threads:[~2009-07-02 16:37 UTC|newest]
Thread overview: 40+ messages / expand[flat|nested] mbox.gz Atom feed top
2009-07-02 1:24 [PATCH][BUGFIX] cgroups: fix pid namespace bug Li Zefan
2009-07-02 1:24 ` Li Zefan
2009-07-02 13:58 ` Serge E. Hallyn
[not found] ` <4A4C0C60.4050106-BthXqXjhjHXQFUHtdCDX3A@public.gmane.org>
2009-07-02 1:36 ` Paul Menage
2009-07-02 1:36 ` Paul Menage
2009-07-02 1:45 ` Li Zefan
2009-07-02 1:57 ` KAMEZAWA Hiroyuki
2009-07-02 11:40 ` Balbir Singh
[not found] ` <20090702105707.8b2135d9.kamezawa.hiroyu-+CUm20s59erQFUHtdCDX3A@public.gmane.org>
2009-07-02 11:40 ` Balbir Singh
2009-07-02 2:17 ` Li Zefan
[not found] ` <4A4C18D5.7020806-BthXqXjhjHXQFUHtdCDX3A@public.gmane.org>
2009-07-02 2:20 ` Paul Menage
2009-07-02 2:20 ` Paul Menage
2009-07-02 2:28 ` Li Zefan
2009-07-02 13:26 ` Serge E. Hallyn
[not found] ` <20090702132659.GA8051-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2009-07-02 15:43 ` Paul Menage
2009-07-02 15:43 ` Paul Menage
2009-07-02 16:15 ` Serge E. Hallyn
2009-07-02 16:27 ` Paul Menage
[not found] ` <6599ad830907020927x44a88a6dgb229fb2ad6ef5481-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2009-07-02 23:20 ` Andrew Morton
2009-07-02 23:20 ` Andrew Morton
2009-07-02 23:29 ` Paul Menage
[not found] ` <20090702162019.f34f12d6.akpm-de/tnXTf+JLsfHDXvbKv3WD2FQJk+8+b@public.gmane.org>
2009-07-02 23:29 ` Paul Menage
[not found] ` <20090702161548.GA13383-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2009-07-02 16:27 ` Paul Menage
2009-07-04 9:13 ` Eric W. Biederman
[not found] ` <6599ad830907020843l7ce75abfq3e78b8f67a407ab9-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2009-07-02 16:15 ` Serge E. Hallyn
2009-07-04 9:13 ` Eric W. Biederman
[not found] ` <4A4C1B33.2030002-BthXqXjhjHXQFUHtdCDX3A@public.gmane.org>
2009-07-02 13:26 ` Serge E. Hallyn
[not found] ` <6599ad830907011920r44df4022p53808b574da4a886-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2009-07-02 2:28 ` Li Zefan
[not found] ` <6599ad830907011836x5eccc83eyc896a67295a6486d-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2009-07-02 1:45 ` Li Zefan
2009-07-02 1:57 ` KAMEZAWA Hiroyuki
2009-07-02 2:17 ` Li Zefan
2009-07-02 13:58 ` Serge E. Hallyn
2009-07-02 16:26 ` Paul Menage
2009-07-02 16:26 ` Paul Menage
[not found] ` <6599ad830907020926t6305bec9t44a50cc165f6fc28-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2009-07-02 16:37 ` Serge E. Hallyn
2009-07-02 16:37 ` Serge E. Hallyn [this message]
2009-07-02 16:46 ` Paul Menage
[not found] ` <6599ad830907020946r42735c9es642bddf37af755ed-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2009-07-02 19:14 ` Serge E. Hallyn
2009-07-02 19:14 ` Serge E. Hallyn
[not found] ` <20090702163731.GA14267-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2009-07-02 16:46 ` Paul Menage
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20090702163731.GA14267@us.ibm.com \
--to=serue@us.ibm.com \
--cc=akpm@linux-foundation.org \
--cc=containers@lists.linux-foundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=lizf@cn.fujitsu.com \
--cc=menage@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.