All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Serge E. Hallyn" <serue@us.ibm.com>
To: Paul Menage <menage@google.com>
Cc: Li Zefan <lizf@cn.fujitsu.com>,
	Andrew Morton <akpm@linux-foundation.org>,
	LKML <linux-kernel@vger.kernel.org>,
	Linux Containers <containers@lists.linux-foundation.org>
Subject: Re: [PATCH][BUGFIX] cgroups: fix pid namespace bug
Date: Thu, 2 Jul 2009 14:14:10 -0500	[thread overview]
Message-ID: <20090702191410.GA17823@us.ibm.com> (raw)
In-Reply-To: <6599ad830907020946r42735c9es642bddf37af755ed@mail.gmail.com>

Quoting Paul Menage (menage@google.com):
> On Thu, Jul 2, 2009 at 9:37 AM, Serge E. Hallyn<serue@us.ibm.com> wrote:
> >
> >        1. the only way it won't outlive the open file is if the
> >                task opens the file, hands the open fd over a
> >                unix socket, then exits as the last task of its
> >                pidns
> 
> Right.
> 
> >        2. We don't dereference the pid_ns, so there is no actual
> >                safety issue.  So it would become a problem only
> >                if a new pidns gets created at that same address
> 
> Which is fairly likely given that pid_namespace is allocated from a
> specific cache.
> 
> Paul

The scenario as a whole is still pretty unlikely, but there's just
no reason to risk it.

-serge

      parent reply	other threads:[~2009-07-02 19:14 UTC|newest]

Thread overview: 40+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-07-02  1:24 [PATCH][BUGFIX] cgroups: fix pid namespace bug Li Zefan
2009-07-02  1:24 ` Li Zefan
     [not found] ` <4A4C0C60.4050106-BthXqXjhjHXQFUHtdCDX3A@public.gmane.org>
2009-07-02  1:36   ` Paul Menage
2009-07-02  1:36     ` Paul Menage
2009-07-02  1:45     ` Li Zefan
     [not found]     ` <6599ad830907011836x5eccc83eyc896a67295a6486d-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2009-07-02  1:45       ` Li Zefan
2009-07-02  1:57       ` KAMEZAWA Hiroyuki
2009-07-02  2:17       ` Li Zefan
2009-07-02  1:57     ` KAMEZAWA Hiroyuki
2009-07-02 11:40       ` Balbir Singh
     [not found]       ` <20090702105707.8b2135d9.kamezawa.hiroyu-+CUm20s59erQFUHtdCDX3A@public.gmane.org>
2009-07-02 11:40         ` Balbir Singh
2009-07-02  2:17     ` Li Zefan
2009-07-02  2:20       ` Paul Menage
     [not found]         ` <6599ad830907011920r44df4022p53808b574da4a886-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2009-07-02  2:28           ` Li Zefan
2009-07-02  2:28         ` Li Zefan
2009-07-02 13:26           ` Serge E. Hallyn
     [not found]             ` <20090702132659.GA8051-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2009-07-02 15:43               ` Paul Menage
2009-07-02 15:43             ` Paul Menage
2009-07-02 16:15               ` Serge E. Hallyn
     [not found]                 ` <20090702161548.GA13383-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2009-07-02 16:27                   ` Paul Menage
2009-07-02 16:27                 ` Paul Menage
     [not found]                   ` <6599ad830907020927x44a88a6dgb229fb2ad6ef5481-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2009-07-02 23:20                     ` Andrew Morton
2009-07-02 23:20                   ` Andrew Morton
2009-07-02 23:29                     ` Paul Menage
     [not found]                     ` <20090702162019.f34f12d6.akpm-de/tnXTf+JLsfHDXvbKv3WD2FQJk+8+b@public.gmane.org>
2009-07-02 23:29                       ` Paul Menage
2009-07-04  9:13               ` Eric W. Biederman
     [not found]               ` <6599ad830907020843l7ce75abfq3e78b8f67a407ab9-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2009-07-02 16:15                 ` Serge E. Hallyn
2009-07-04  9:13                 ` Eric W. Biederman
     [not found]           ` <4A4C1B33.2030002-BthXqXjhjHXQFUHtdCDX3A@public.gmane.org>
2009-07-02 13:26             ` Serge E. Hallyn
     [not found]       ` <4A4C18D5.7020806-BthXqXjhjHXQFUHtdCDX3A@public.gmane.org>
2009-07-02  2:20         ` Paul Menage
2009-07-02 13:58   ` Serge E. Hallyn
2009-07-02 16:26   ` Paul Menage
2009-07-02 13:58 ` Serge E. Hallyn
2009-07-02 16:26 ` Paul Menage
     [not found]   ` <6599ad830907020926t6305bec9t44a50cc165f6fc28-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2009-07-02 16:37     ` Serge E. Hallyn
2009-07-02 16:37   ` Serge E. Hallyn
     [not found]     ` <20090702163731.GA14267-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2009-07-02 16:46       ` Paul Menage
2009-07-02 16:46     ` Paul Menage
     [not found]       ` <6599ad830907020946r42735c9es642bddf37af755ed-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2009-07-02 19:14         ` Serge E. Hallyn
2009-07-02 19:14       ` Serge E. Hallyn [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20090702191410.GA17823@us.ibm.com \
    --to=serue@us.ibm.com \
    --cc=akpm@linux-foundation.org \
    --cc=containers@lists.linux-foundation.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=lizf@cn.fujitsu.com \
    --cc=menage@google.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.