All of lore.kernel.org
 help / color / mirror / Atom feed
From: Oleg Nesterov <oleg@redhat.com>
To: Tejun Heo <tj@kernel.org>
Cc: linux-kernel@vger.kernel.org,
	Linus Torvalds <torvalds@linux-foundation.org>,
	Andrew Morton <akpm@linux-foundation.org>
Subject: Re: [PATCH ptrace] ptrace: use GROUP_STOP_TRAPPING for PTRACE_DETACH too
Date: Sun, 8 May 2011 18:07:20 +0200	[thread overview]
Message-ID: <20110508160720.GA11705@redhat.com> (raw)
In-Reply-To: <20110508144424.GB29783@htj.dyndns.org>

On 05/08, Tejun Heo wrote:
>
> Currently GROUP_STOP_TRAPPING is used only for PTRACE_ATTACH to hide
> STOPPED -> RUNNING -> TRACED transition; however, DETACH involves
> similar transition in the reverse direction, which can be visible to
> the next ptracer if it attaches before the transition is complete.

Yes...

> This patch makes DETACH also use TRAPPING and ptrace_attach() always
> wait if TRAPPING is set to hide the transition.

I am not sure, please see below.

> Test program follows.
>
>   int main(int argc, char **argv)
>   {
> 	  pid_t tracee;
> 	  siginfo_t si = {};
> 	  int i, nr_wait_fails = 0, nr_ptrace_fails = 0;
>
> 	  tracee = fork();
> 	  if (!tracee)
> 		  while (1)
> 			  pause();
>
> 	  kill(tracee, SIGSTOP);
> 	  waitid(P_PID, tracee, NULL, WSTOPPED | WNOWAIT);
>
> 	  for (i = 0; i < 100000; i++) {
> 		  ptrace(PTRACE_ATTACH, tracee, NULL, NULL);
> 		  waitid(P_PID, tracee, &si, WSTOPPED | WNOHANG);
> 		  if (!si.si_pid)
> 			  nr_wait_fails++;

OK, this is clear, waitid(WSTOPPED | WNOHANG) can fail if it sees the
tracee inside the transition.

But,

> 		  if (ptrace(PTRACE_DETACH, tracee, NULL, NULL)) {
> 			  nr_ptrace_fails++;

I assume this can only fail for the same reason if waitid() fails?
Or there is something else?

> --- work.orig/kernel/ptrace.c
> +++ work/kernel/ptrace.c
> @@ -77,12 +77,15 @@ void __ptrace_unlink(struct task_struct
>
>  	/*
>  	 * Reinstate GROUP_STOP_PENDING if group stop is in effect and
> -	 * @child isn't dead.
> +	 * @child isn't dead.  This will trigger TRACED -> RUNNING ->
> +	 * STOPPED transition.  As this transition can affect the next
> +	 * ptracer if it attaches before the transition completes, set
> +	 * TRAPPING too.  Read comment in ptrace_attach() for more details.
>  	 */
>  	if (!(child->flags & PF_EXITING) &&
>  	    (child->signal->flags & SIGNAL_STOP_STOPPED ||
>  	     child->signal->group_stop_count))
> -		child->group_stop |= GROUP_STOP_PENDING;
> +		child->group_stop |= GROUP_STOP_PENDING | GROUP_STOP_TRAPPING;

This doesn't look safe, see below. We do not know what the tracee does,
it can be even running.

>  static int ptrace_attach(struct task_struct *task)
>  {
> -	bool wait_trap = false;
>  	int retval;
>
>  	audit_ptrace(task);
> @@ -245,7 +247,6 @@ static int ptrace_attach(struct task_str
>  	if (task_is_stopped(task)) {
>  		task->group_stop |= GROUP_STOP_PENDING | GROUP_STOP_TRAPPING;
>  		signal_wake_up(task, 1);
> -		wait_trap = true;
>  	}
>
>  	spin_unlock(&task->sighand->siglock);
> @@ -256,9 +257,8 @@ unlock_tasklist:
>  unlock_creds:
>  	mutex_unlock(&task->signal->cred_guard_mutex);
>  out:
> -	if (wait_trap)
> -		wait_event(current->signal->wait_chldexit,
> -			   !(task->group_stop & GROUP_STOP_TRAPPING));
> +	wait_event(current->signal->wait_chldexit,
> +		   !(task->group_stop & GROUP_STOP_TRAPPING));

Suppose that SIGCONT or, worse, SIGKILL comes in between.

Oleg.


  reply	other threads:[~2011-05-08 16:08 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-05-08 14:44 [PATCH ptrace] ptrace: use GROUP_STOP_TRAPPING for PTRACE_DETACH too Tejun Heo
2011-05-08 16:07 ` Oleg Nesterov [this message]
2011-05-09  8:37   ` Tejun Heo

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20110508160720.GA11705@redhat.com \
    --to=oleg@redhat.com \
    --cc=akpm@linux-foundation.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=tj@kernel.org \
    --cc=torvalds@linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.