From: ebiederm@xmission.com (Eric W. Biederman)
To: Oleg Nesterov <oleg@redhat.com>
Cc: Tycho Andersen <tycho@tycho.ws>,
Linus Torvalds <torvalds@linux-foundation.org>,
Kees Cook <keescook@chromium.org>,
Thomas Gleixner <tglx@linutronix.de>,
Linux List Kernel Mailing <linux-kernel@vger.kernel.org>
Subject: Re: siginfo pid not populated from ptrace?
Date: Mon, 10 Dec 2018 11:36:59 -0600 [thread overview]
Message-ID: <87tvjl1dxg.fsf@xmission.com> (raw)
In-Reply-To: <20181210153717.GA7581@redhat.com> (Oleg Nesterov's message of "Mon, 10 Dec 2018 16:37:18 +0100")
Oleg Nesterov <oleg@redhat.com> writes:
> On 12/06, Eric W. Biederman wrote:
>>
>> The challenge is that we could be delivering this to a zombie signal
>> group leader.
>
> ...
>
>> Sigh it is probably time that I dig in and figure out how to avoid that
>> case which we need to fix anyway because we can get the permission
>> checks wrong for multi-threaded processes that call setuid and friends.
>
> this is another issue... I am sure we have already discussed this, but I
> failed to find any link to the previous discussion.
Now that we have PIDTYPE_TGID I think we are closer to being able to
solve that issue. You are absolutely right it is another issue.
>> Once that is sorted your small change will at least be safe.
>
> I don't think so, any sub-thread can dequeue SIGSTOP unless type == PIDTYPE_PID,
> this has nothing to do with the problems connected to zombie leader, or I
> misunderstood you.
I forgot to check what wants_signal does in this case. I thought
SIGSTOP was like SIGKILL and being unblockable would always be delivered
to the thread we are aiming at. With a zombie leader being the
exception.
Having reread wants_signal you are absolutely correct. SIGSTOP can be
delivered to any thread so this won't help. I don't understand why for
SIGSTOP we don't treat SIGSTOP like SIGKILL, but that is also another
conversation. It feels like the differences between SIGSTOP and SIGKILL
in wants_signal are silly. I don't see them leading to incorrect behavior.
Eric
next prev parent reply other threads:[~2018-12-10 17:37 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-11-12 17:11 siginfo pid not populated from ptrace? Tycho Andersen
2018-11-12 18:30 ` Eric W. Biederman
2018-11-12 18:55 ` Tycho Andersen
2018-11-12 19:22 ` Eric W. Biederman
2018-11-12 19:24 ` Tycho Andersen
2018-11-27 23:21 ` Tycho Andersen
2018-11-28 0:38 ` Kees Cook
2018-11-28 1:17 ` Kees Cook
2018-11-28 4:44 ` Eric W. Biederman
2018-11-29 21:17 ` Kees Cook
2018-11-29 23:22 ` Tycho Andersen
2018-12-01 15:04 ` Eric W. Biederman
2018-12-06 1:00 ` Kees Cook
2018-12-06 14:40 ` Eric W. Biederman
2018-12-06 18:48 ` Linus Torvalds
2018-12-06 19:20 ` Tycho Andersen
2018-12-06 21:11 ` Eric W. Biederman
2018-12-06 21:34 ` Kees Cook
2018-12-06 22:43 ` Eric W. Biederman
2018-12-06 22:55 ` Kees Cook
2018-12-10 15:37 ` Oleg Nesterov
2018-12-10 15:44 ` Tycho Andersen
2018-12-10 17:36 ` Eric W. Biederman [this message]
2018-12-10 14:57 ` Oleg Nesterov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=87tvjl1dxg.fsf@xmission.com \
--to=ebiederm@xmission.com \
--cc=keescook@chromium.org \
--cc=linux-kernel@vger.kernel.org \
--cc=oleg@redhat.com \
--cc=tglx@linutronix.de \
--cc=torvalds@linux-foundation.org \
--cc=tycho@tycho.ws \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.