All of lore.kernel.org
 help / color / mirror / Atom feed
From: Oleg Nesterov <oleg@redhat.com>
To: Mike Christie <michael.christie@oracle.com>
Cc: axboe@kernel.dk, brauner@kernel.org, mst@redhat.com,
	linux-kernel@vger.kernel.org, linux@leemhuis.info,
	ebiederm@xmission.com, stefanha@redhat.com,
	nicolas.dichtel@6wind.com,
	virtualization@lists.linux-foundation.org,
	torvalds@linux-foundation.org
Subject: Re: [PATCH 1/1] fork, vhost: Use CLONE_THREAD to fix freezer/ps regression
Date: Mon, 5 Jun 2023 15:48:44 +0200	[thread overview]
Message-ID: <20230605134844.GC32275@redhat.com> (raw)
In-Reply-To: <20230601183232.8384-1-michael.christie@oracle.com>

On 06/01, Mike Christie wrote:
>
> --- a/kernel/signal.c
> +++ b/kernel/signal.c
> @@ -1368,7 +1368,9 @@ int zap_other_threads(struct task_struct *p)
>  
>  	while_each_thread(p, t) {
>  		task_clear_jobctl_pending(t, JOBCTL_PENDING_MASK);
> -		count++;
> +		/* Don't require de_thread to wait for the vhost_worker */
> +		if ((t->flags & (PF_IO_WORKER | PF_USER_WORKER)) != PF_USER_WORKER)
> +			count++;

Well if you do this, then you should also change __exit_signal() to
not decrement sig->notify_count. Otherwise de_thread() can succeed
before the "normal" sub-threads exit.

But this can't be right anyway... If nothing else, suppose we have
a process with 3 threads:

	M	- the main thread, group leader
	T	- sub-thread
	V	- vhost worker

T does exec and calls de_thread().

M exits. T takes the leadership and does release_task()

V is still running but V->group_leader points to already freed M.

Or unshare_sighand() after that... If nothing else this means that
lock_task_sighand(T) and lock_task_sighand(V) will take different
locks.

Oleg.

_______________________________________________
Virtualization mailing list
Virtualization@lists.linux-foundation.org
https://lists.linuxfoundation.org/mailman/listinfo/virtualization

WARNING: multiple messages have this Message-ID (diff)
From: Oleg Nesterov <oleg@redhat.com>
To: Mike Christie <michael.christie@oracle.com>
Cc: linux@leemhuis.info, nicolas.dichtel@6wind.com, axboe@kernel.dk,
	ebiederm@xmission.com, torvalds@linux-foundation.org,
	linux-kernel@vger.kernel.org,
	virtualization@lists.linux-foundation.org, mst@redhat.com,
	sgarzare@redhat.com, jasowang@redhat.com, stefanha@redhat.com,
	brauner@kernel.org
Subject: Re: [PATCH 1/1] fork, vhost: Use CLONE_THREAD to fix freezer/ps regression
Date: Mon, 5 Jun 2023 15:48:44 +0200	[thread overview]
Message-ID: <20230605134844.GC32275@redhat.com> (raw)
In-Reply-To: <20230601183232.8384-1-michael.christie@oracle.com>

On 06/01, Mike Christie wrote:
>
> --- a/kernel/signal.c
> +++ b/kernel/signal.c
> @@ -1368,7 +1368,9 @@ int zap_other_threads(struct task_struct *p)
>  
>  	while_each_thread(p, t) {
>  		task_clear_jobctl_pending(t, JOBCTL_PENDING_MASK);
> -		count++;
> +		/* Don't require de_thread to wait for the vhost_worker */
> +		if ((t->flags & (PF_IO_WORKER | PF_USER_WORKER)) != PF_USER_WORKER)
> +			count++;

Well if you do this, then you should also change __exit_signal() to
not decrement sig->notify_count. Otherwise de_thread() can succeed
before the "normal" sub-threads exit.

But this can't be right anyway... If nothing else, suppose we have
a process with 3 threads:

	M	- the main thread, group leader
	T	- sub-thread
	V	- vhost worker

T does exec and calls de_thread().

M exits. T takes the leadership and does release_task()

V is still running but V->group_leader points to already freed M.

Or unshare_sighand() after that... If nothing else this means that
lock_task_sighand(T) and lock_task_sighand(V) will take different
locks.

Oleg.


  parent reply	other threads:[~2023-06-05 13:49 UTC|newest]

Thread overview: 49+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2023-06-01 18:32 [PATCH 1/1] fork, vhost: Use CLONE_THREAD to fix freezer/ps regression Mike Christie
2023-06-01 18:32 ` Mike Christie
2023-06-01 19:11 ` Michael S. Tsirkin
2023-06-01 19:11   ` Michael S. Tsirkin
2023-06-02  0:43 ` Eric W. Biederman
2023-06-02  0:43   ` Eric W. Biederman
2023-06-02 14:34 ` Nicolas Dichtel
2023-06-02 19:22 ` Oleg Nesterov
2023-06-02 19:22   ` Oleg Nesterov
2023-06-03  3:44   ` Eric W. Biederman
2023-06-03  3:44     ` Eric W. Biederman
2023-06-05 13:26     ` Oleg Nesterov
2023-06-05 13:26       ` Oleg Nesterov
2023-06-03  4:15   ` [CFT][PATCH v3] " Eric W. Biederman
2023-06-03  4:15     ` Eric W. Biederman
2023-06-04  3:28     ` michael.christie
2023-06-04  3:28       ` michael.christie
2023-06-05 15:10       ` Oleg Nesterov
2023-06-05 15:10         ` Oleg Nesterov
2023-06-05 15:46         ` Mike Christie
2023-06-05 15:46           ` Mike Christie
2023-06-06 12:16           ` Oleg Nesterov
2023-06-06 12:16             ` Oleg Nesterov
2023-06-06 15:57             ` Mike Christie
2023-06-06 15:57               ` Mike Christie
2023-06-06 19:39               ` Oleg Nesterov
2023-06-06 19:39                 ` Oleg Nesterov
2023-06-06 20:38                 ` Mike Christie
2023-06-06 20:38                   ` Mike Christie
2023-06-14  6:02                   ` Can vhost translate to io_uring? Eric W. Biederman
2023-06-14  6:02                     ` Eric W. Biederman
2023-06-14  6:25                     ` michael.christie
2023-06-14  6:25                       ` michael.christie
2023-06-14 14:30                       ` Jens Axboe
2023-06-14 14:30                         ` Jens Axboe
2023-06-14 17:59                       ` Mike Christie
2023-06-14 17:59                         ` Mike Christie
2023-06-14 14:20                     ` Michael S. Tsirkin
2023-06-14 14:20                       ` Michael S. Tsirkin
2023-06-14 15:02                     ` Michael S. Tsirkin
2023-06-14 15:02                       ` Michael S. Tsirkin
2023-06-11 20:27                 ` [CFT][PATCH v3] fork, vhost: Use CLONE_THREAD to fix freezer/ps regression Eric W. Biederman
2023-06-11 20:27                   ` Eric W. Biederman
2023-06-14 17:08                   ` Oleg Nesterov
2023-06-14 17:08                     ` Oleg Nesterov
2023-06-05 12:38     ` Oleg Nesterov
2023-06-05 12:38       ` Oleg Nesterov
2023-06-05 13:48 ` Oleg Nesterov [this message]
2023-06-05 13:48   ` [PATCH 1/1] " Oleg Nesterov

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20230605134844.GC32275@redhat.com \
    --to=oleg@redhat.com \
    --cc=axboe@kernel.dk \
    --cc=brauner@kernel.org \
    --cc=ebiederm@xmission.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux@leemhuis.info \
    --cc=michael.christie@oracle.com \
    --cc=mst@redhat.com \
    --cc=nicolas.dichtel@6wind.com \
    --cc=stefanha@redhat.com \
    --cc=torvalds@linux-foundation.org \
    --cc=virtualization@lists.linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.