* [PATCH v3 1/2] pid: deinline kill_cad_pid
@ 2026-07-19 15:58 Cen Zhang (Microsoft)
2026-07-19 15:58 ` [PATCH v3 2/2] pid: fix cad_pid use-after-free race Cen Zhang (Microsoft)
` (3 more replies)
0 siblings, 4 replies; 9+ messages in thread
From: Cen Zhang (Microsoft) @ 2026-07-19 15:58 UTC (permalink / raw)
To: brauner
Cc: oleg, akpm, jack, avagin, ptikhomirov, mjguzik, include, ebiederm,
legion, linux-kernel, AutonomousCodeSecurity, tgopinath, kys,
blbllhy
Move kill_cad_pid() out of the header without changing behavior. This
prepares for taking a reference to cad_pid under RCU in the following
fix.
Suggested-by: Mateusz Guzik <mjguzik@gmail.com>
Suggested-by: Bradley Morgan <include@grrlz.net>
Reviewed-by: Bradley Morgan <include@grrlz.net>
Link: https://lore.kernel.org/all/CAGudoHH0vz=1m97EDHQFLLwGJmDPmqWJ+444b7rMiD059drEwQ@mail.gmail.com/
Signed-off-by: Cen Zhang (Microsoft) <blbllhy@gmail.com>
---
v3: Add Reviewed-by from Bradley Morgan.
v2: New preparatory patch to deinline kill_cad_pid().
include/linux/sched/signal.h | 5 +----
kernel/pid.c | 5 +++++
2 files changed, 6 insertions(+), 4 deletions(-)
diff --git a/include/linux/sched/signal.h b/include/linux/sched/signal.h
index 584ae88b435e..d45a5476b97d 100644
--- a/include/linux/sched/signal.h
+++ b/include/linux/sched/signal.h
@@ -562,10 +562,7 @@ static inline sigset_t *sigmask_to_save(void)
return res;
}
-static inline int kill_cad_pid(int sig, int priv)
-{
- return kill_pid(cad_pid, sig, priv);
-}
+int kill_cad_pid(int sig, int priv);
/* These can be the second arg to send_sig_info/send_group_sig_info. */
#define SEND_SIG_NOINFO ((struct kernel_siginfo *) 0)
diff --git a/kernel/pid.c b/kernel/pid.c
index f55189a3d07d..234ebee29375 100644
--- a/kernel/pid.c
+++ b/kernel/pid.c
@@ -557,6 +557,11 @@ pid_t pid_vnr(struct pid *pid)
}
EXPORT_SYMBOL_GPL(pid_vnr);
+int kill_cad_pid(int sig, int priv)
+{
+ return kill_pid(cad_pid, sig, priv);
+}
+
pid_t __task_pid_nr_ns(struct task_struct *task, enum pid_type type,
struct pid_namespace *ns)
{
--
2.53.0
^ permalink raw reply related [flat|nested] 9+ messages in thread
* [PATCH v3 2/2] pid: fix cad_pid use-after-free race
2026-07-19 15:58 [PATCH v3 1/2] pid: deinline kill_cad_pid Cen Zhang (Microsoft)
@ 2026-07-19 15:58 ` Cen Zhang (Microsoft)
2026-07-20 10:09 ` Pavel Tikhomirov
2026-07-19 16:20 ` [PATCH v3 1/2] pid: deinline kill_cad_pid Oleg Nesterov
` (2 subsequent siblings)
3 siblings, 1 reply; 9+ messages in thread
From: Cen Zhang (Microsoft) @ 2026-07-19 15:58 UTC (permalink / raw)
To: brauner
Cc: oleg, akpm, jack, avagin, ptikhomirov, mjguzik, include, ebiederm,
legion, linux-kernel, AutonomousCodeSecurity, tgopinath, kys,
blbllhy, stable
proc_do_cad_pid() reads the global cad_pid pointer and passes it to
pid_vnr() without protecting the lifetime of the referenced struct pid.
A concurrent writer can replace cad_pid and drop the final reference to
the old struct pid after the reader has loaded the pointer but before
pid_vnr() has finished dereferencing it, causing a use-after-free.
The sysctl is mode 0600, but access is checked against the owning user
namespace, so an unprivileged user can reach it via userns, pidns, and a
proc mount.
Fix this by treating cad_pid as an RCU-protected pointer at both read
sites and by waiting for a grace period before dropping the old reference
on the write side.
KASAN crash stack:
kernel/pid.c:545 pid_nr_ns() # reads freed pid->level
kernel/pid.c:556 pid_vnr()
kernel/pid.c:775 proc_do_cad_pid()
fs/proc/proc_sysctl.c proc_sys_call_handler()
fs/read_write.c vfs_read()
fs/read_write.c __x64_sys_pread64()
Fixes: 9ec52099e4b8 ("[PATCH] replace cad_pid by a struct pid")
Reported-by: AutonomousCodeSecurity@microsoft.com
Closes: https://lore.kernel.org/all/20260717210143.4734-1-blbllhy@gmail.com/
Suggested-by: Mateusz Guzik <mjguzik@gmail.com>
Suggested-by: Oleg Nesterov <oleg@redhat.com>
Reviewed-by: Bradley Morgan <include@grrlz.net>
Cc: stable@vger.kernel.org
Signed-off-by: Cen Zhang (Microsoft) <blbllhy@gmail.com>
---
v3:
- Keep kill_cad_pid() inside the RCU read-side critical section
instead of taking a pid reference, as suggested by Oleg.
v2:
- Split out kill_cad_pid() deinline into a preparatory patch.
- Annotate cad_pid as __rcu and use rcu_dereference().
- Protect kill_cad_pid() by taking a pid reference under RCU.
- Add a comment explaining why synchronize_rcu() is used instead of
call_rcu().
include/linux/sched.h | 2 +-
init/main.c | 2 +-
kernel/pid.c | 22 +++++++++++++++++++---
kernel/reboot.c | 2 +-
4 files changed, 22 insertions(+), 6 deletions(-)
diff --git a/include/linux/sched.h b/include/linux/sched.h
index 373bcc0598d1..31ce72b1233c 100644
--- a/include/linux/sched.h
+++ b/include/linux/sched.h
@@ -1767,7 +1767,7 @@ static inline bool is_lazy_mmu_mode_active(void)
}
#endif
-extern struct pid *cad_pid;
+extern struct pid __rcu *cad_pid;
/*
* Per process flags
diff --git a/init/main.c b/init/main.c
index e363232b428b..19a10d0c2760 100644
--- a/init/main.c
+++ b/init/main.c
@@ -1636,7 +1636,7 @@ static noinline void __init kernel_init_freeable(void)
*/
set_mems_allowed(node_states[N_MEMORY]);
- cad_pid = get_pid(task_pid(current));
+ rcu_assign_pointer(cad_pid, get_pid(task_pid(current)));
smp_prepare_cpus(setup_max_cpus);
diff --git a/kernel/pid.c b/kernel/pid.c
index 234ebee29375..fb7c0d18efa9 100644
--- a/kernel/pid.c
+++ b/kernel/pid.c
@@ -559,7 +559,13 @@ EXPORT_SYMBOL_GPL(pid_vnr);
int kill_cad_pid(int sig, int priv)
{
- return kill_pid(cad_pid, sig, priv);
+ int ret;
+
+ rcu_read_lock();
+ ret = kill_pid(rcu_dereference(cad_pid), sig, priv);
+ rcu_read_unlock();
+
+ return ret;
}
pid_t __task_pid_nr_ns(struct task_struct *task, enum pid_type type,
@@ -773,11 +779,15 @@ static int proc_do_cad_pid(const struct ctl_table *table, int write, void *buffe
size_t *lenp, loff_t *ppos)
{
struct pid *new_pid;
+ struct pid *old_pid;
pid_t tmp_pid;
int r;
struct ctl_table tmp_table = *table;
- tmp_pid = pid_vnr(cad_pid);
+ rcu_read_lock();
+ tmp_pid = pid_vnr(rcu_dereference(cad_pid));
+ rcu_read_unlock();
+
tmp_table.data = &tmp_pid;
r = proc_dointvec(&tmp_table, write, buffer, lenp, ppos);
@@ -788,7 +798,13 @@ static int proc_do_cad_pid(const struct ctl_table *table, int write, void *buffe
if (!new_pid)
return -ESRCH;
- put_pid(xchg(&cad_pid, new_pid));
+ old_pid = unrcu_pointer(xchg(&cad_pid, RCU_INITIALIZER(new_pid)));
+ /*
+ * Wait for cad_pid readers before put_pid(). We cannot use
+ * call_rcu() here because free_pid() already owns pid->rcu.
+ */
+ synchronize_rcu();
+ put_pid(old_pid);
return 0;
}
diff --git a/kernel/reboot.c b/kernel/reboot.c
index 695c33e75efd..fc191a48c0e9 100644
--- a/kernel/reboot.c
+++ b/kernel/reboot.c
@@ -24,7 +24,7 @@
*/
static int C_A_D = 1;
-struct pid *cad_pid;
+struct pid __rcu *cad_pid;
EXPORT_SYMBOL(cad_pid);
#if defined(CONFIG_ARM)
--
2.53.0
^ permalink raw reply related [flat|nested] 9+ messages in thread
* Re: [PATCH v3 1/2] pid: deinline kill_cad_pid
2026-07-19 15:58 [PATCH v3 1/2] pid: deinline kill_cad_pid Cen Zhang (Microsoft)
2026-07-19 15:58 ` [PATCH v3 2/2] pid: fix cad_pid use-after-free race Cen Zhang (Microsoft)
@ 2026-07-19 16:20 ` Oleg Nesterov
2026-07-19 16:26 ` Cen Zhang (Microsoft)
2026-07-20 9:56 ` Pavel Tikhomirov
2026-07-20 13:19 ` Eric W. Biederman
3 siblings, 1 reply; 9+ messages in thread
From: Oleg Nesterov @ 2026-07-19 16:20 UTC (permalink / raw)
To: Cen Zhang (Microsoft)
Cc: brauner, akpm, jack, avagin, ptikhomirov, mjguzik, include,
ebiederm, legion, linux-kernel, AutonomousCodeSecurity, tgopinath,
kys
On 07/19, Cen Zhang (Microsoft) wrote:
>
> Move kill_cad_pid() out of the header without changing behavior. This
> prepares for taking a reference to cad_pid under RCU in the following
> fix.
...
> +int kill_cad_pid(int sig, int priv)
> +{
> + return kill_pid(cad_pid, sig, priv);
> +}
Well... this version doesn't address another comment from sashiko.
Without EXPORT_SYMBOL() this can break the modules which use kill_cad_pid().
Say, drivers/acpi/tiny-power-button.c
I am starting to think that we should apply my patch first, it is more
straightforward. Your 2/2 can be trivially rebased on top of it.
Oleg.
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [PATCH v3 1/2] pid: deinline kill_cad_pid
2026-07-19 16:20 ` [PATCH v3 1/2] pid: deinline kill_cad_pid Oleg Nesterov
@ 2026-07-19 16:26 ` Cen Zhang (Microsoft)
0 siblings, 0 replies; 9+ messages in thread
From: Cen Zhang (Microsoft) @ 2026-07-19 16:26 UTC (permalink / raw)
To: oleg
Cc: AutonomousCodeSecurity, akpm, avagin, blbllhy, brauner, ebiederm,
include, jack, kys, legion, linux-kernel, mjguzik, ptikhomirov,
tgopinath
Ah, I missed checking sashiko. Thanks Oleg, please go ahead.
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [PATCH v3 1/2] pid: deinline kill_cad_pid
2026-07-19 15:58 [PATCH v3 1/2] pid: deinline kill_cad_pid Cen Zhang (Microsoft)
2026-07-19 15:58 ` [PATCH v3 2/2] pid: fix cad_pid use-after-free race Cen Zhang (Microsoft)
2026-07-19 16:20 ` [PATCH v3 1/2] pid: deinline kill_cad_pid Oleg Nesterov
@ 2026-07-20 9:56 ` Pavel Tikhomirov
2026-07-20 13:19 ` Eric W. Biederman
3 siblings, 0 replies; 9+ messages in thread
From: Pavel Tikhomirov @ 2026-07-20 9:56 UTC (permalink / raw)
To: Cen Zhang (Microsoft), brauner
Cc: oleg, akpm, jack, avagin, mjguzik, include, ebiederm, legion,
linux-kernel, AutonomousCodeSecurity, tgopinath, kys
On 7/19/26 17:58, Cen Zhang (Microsoft) wrote:
> Move kill_cad_pid() out of the header without changing behavior. This
> prepares for taking a reference to cad_pid under RCU in the following
> fix.
>
> Suggested-by: Mateusz Guzik <mjguzik@gmail.com>
> Suggested-by: Bradley Morgan <include@grrlz.net>
> Reviewed-by: Bradley Morgan <include@grrlz.net>
> Link: https://lore.kernel.org/all/CAGudoHH0vz=1m97EDHQFLLwGJmDPmqWJ+444b7rMiD059drEwQ@mail.gmail.com/
> Signed-off-by: Cen Zhang (Microsoft) <blbllhy@gmail.com>
> ---
> v3: Add Reviewed-by from Bradley Morgan.
> v2: New preparatory patch to deinline kill_cad_pid().
>
> include/linux/sched/signal.h | 5 +----
> kernel/pid.c | 5 +++++
> 2 files changed, 6 insertions(+), 4 deletions(-)
>
> diff --git a/include/linux/sched/signal.h b/include/linux/sched/signal.h
> index 584ae88b435e..d45a5476b97d 100644
> --- a/include/linux/sched/signal.h
> +++ b/include/linux/sched/signal.h
> @@ -562,10 +562,7 @@ static inline sigset_t *sigmask_to_save(void)
> return res;
> }
>
> -static inline int kill_cad_pid(int sig, int priv)
> -{
> - return kill_pid(cad_pid, sig, priv);
> -}
> +int kill_cad_pid(int sig, int priv);
Maybe we should explicitly include signal.h in kernel/reboot.c to have
kill_cad_pid defined there? This already was there before this patch,
and it compiled somehow, so it's definitely included implicitly somehow.
>
> /* These can be the second arg to send_sig_info/send_group_sig_info. */
> #define SEND_SIG_NOINFO ((struct kernel_siginfo *) 0)
> diff --git a/kernel/pid.c b/kernel/pid.c
> index f55189a3d07d..234ebee29375 100644
> --- a/kernel/pid.c
> +++ b/kernel/pid.c
> @@ -557,6 +557,11 @@ pid_t pid_vnr(struct pid *pid)
> }
> EXPORT_SYMBOL_GPL(pid_vnr);
>
> +int kill_cad_pid(int sig, int priv)
> +{
> + return kill_pid(cad_pid, sig, priv);
> +}
> +
> pid_t __task_pid_nr_ns(struct task_struct *task, enum pid_type type,
> struct pid_namespace *ns)
> {
--
Best regards, Pavel Tikhomirov
Senior Software Developer, Virtuozzo.
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [PATCH v3 2/2] pid: fix cad_pid use-after-free race
2026-07-19 15:58 ` [PATCH v3 2/2] pid: fix cad_pid use-after-free race Cen Zhang (Microsoft)
@ 2026-07-20 10:09 ` Pavel Tikhomirov
0 siblings, 0 replies; 9+ messages in thread
From: Pavel Tikhomirov @ 2026-07-20 10:09 UTC (permalink / raw)
To: Cen Zhang (Microsoft), brauner
Cc: oleg, akpm, jack, avagin, mjguzik, include, ebiederm, legion,
linux-kernel, AutonomousCodeSecurity, tgopinath, kys, stable
Reviewed-by: Pavel Tikhomirov <ptikhomirov@virtuozzo.com>
On 7/19/26 17:58, Cen Zhang (Microsoft) wrote:
> proc_do_cad_pid() reads the global cad_pid pointer and passes it to
> pid_vnr() without protecting the lifetime of the referenced struct pid.
> A concurrent writer can replace cad_pid and drop the final reference to
> the old struct pid after the reader has loaded the pointer but before
> pid_vnr() has finished dereferencing it, causing a use-after-free.
>
> The sysctl is mode 0600, but access is checked against the owning user
> namespace, so an unprivileged user can reach it via userns, pidns, and a
> proc mount.
>
> Fix this by treating cad_pid as an RCU-protected pointer at both read
> sites and by waiting for a grace period before dropping the old reference
> on the write side.
>
> KASAN crash stack:
> kernel/pid.c:545 pid_nr_ns() # reads freed pid->level
> kernel/pid.c:556 pid_vnr()
> kernel/pid.c:775 proc_do_cad_pid()
> fs/proc/proc_sysctl.c proc_sys_call_handler()
> fs/read_write.c vfs_read()
> fs/read_write.c __x64_sys_pread64()
>
> Fixes: 9ec52099e4b8 ("[PATCH] replace cad_pid by a struct pid")
> Reported-by: AutonomousCodeSecurity@microsoft.com
> Closes: https://lore.kernel.org/all/20260717210143.4734-1-blbllhy@gmail.com/
> Suggested-by: Mateusz Guzik <mjguzik@gmail.com>
> Suggested-by: Oleg Nesterov <oleg@redhat.com>
> Reviewed-by: Bradley Morgan <include@grrlz.net>
> Cc: stable@vger.kernel.org
> Signed-off-by: Cen Zhang (Microsoft) <blbllhy@gmail.com>
> ---
> v3:
> - Keep kill_cad_pid() inside the RCU read-side critical section
> instead of taking a pid reference, as suggested by Oleg.
>
> v2:
> - Split out kill_cad_pid() deinline into a preparatory patch.
> - Annotate cad_pid as __rcu and use rcu_dereference().
> - Protect kill_cad_pid() by taking a pid reference under RCU.
> - Add a comment explaining why synchronize_rcu() is used instead of
> call_rcu().
>
> include/linux/sched.h | 2 +-
> init/main.c | 2 +-
> kernel/pid.c | 22 +++++++++++++++++++---
> kernel/reboot.c | 2 +-
> 4 files changed, 22 insertions(+), 6 deletions(-)
>
> diff --git a/include/linux/sched.h b/include/linux/sched.h
> index 373bcc0598d1..31ce72b1233c 100644
> --- a/include/linux/sched.h
> +++ b/include/linux/sched.h
> @@ -1767,7 +1767,7 @@ static inline bool is_lazy_mmu_mode_active(void)
> }
> #endif
>
> -extern struct pid *cad_pid;
> +extern struct pid __rcu *cad_pid;
>
> /*
> * Per process flags
> diff --git a/init/main.c b/init/main.c
> index e363232b428b..19a10d0c2760 100644
> --- a/init/main.c
> +++ b/init/main.c
> @@ -1636,7 +1636,7 @@ static noinline void __init kernel_init_freeable(void)
> */
> set_mems_allowed(node_states[N_MEMORY]);
>
> - cad_pid = get_pid(task_pid(current));
> + rcu_assign_pointer(cad_pid, get_pid(task_pid(current)));
>
> smp_prepare_cpus(setup_max_cpus);
>
> diff --git a/kernel/pid.c b/kernel/pid.c
> index 234ebee29375..fb7c0d18efa9 100644
> --- a/kernel/pid.c
> +++ b/kernel/pid.c
> @@ -559,7 +559,13 @@ EXPORT_SYMBOL_GPL(pid_vnr);
>
> int kill_cad_pid(int sig, int priv)
> {
> - return kill_pid(cad_pid, sig, priv);
> + int ret;
> +
> + rcu_read_lock();
> + ret = kill_pid(rcu_dereference(cad_pid), sig, priv);
> + rcu_read_unlock();
> +
> + return ret;
> }
>
> pid_t __task_pid_nr_ns(struct task_struct *task, enum pid_type type,
> @@ -773,11 +779,15 @@ static int proc_do_cad_pid(const struct ctl_table *table, int write, void *buffe
> size_t *lenp, loff_t *ppos)
> {
> struct pid *new_pid;
> + struct pid *old_pid;
> pid_t tmp_pid;
> int r;
> struct ctl_table tmp_table = *table;
>
> - tmp_pid = pid_vnr(cad_pid);
> + rcu_read_lock();
> + tmp_pid = pid_vnr(rcu_dereference(cad_pid));
> + rcu_read_unlock();
> +
> tmp_table.data = &tmp_pid;
>
> r = proc_dointvec(&tmp_table, write, buffer, lenp, ppos);
> @@ -788,7 +798,13 @@ static int proc_do_cad_pid(const struct ctl_table *table, int write, void *buffe
> if (!new_pid)
> return -ESRCH;
>
> - put_pid(xchg(&cad_pid, new_pid));
> + old_pid = unrcu_pointer(xchg(&cad_pid, RCU_INITIALIZER(new_pid)));
> + /*
> + * Wait for cad_pid readers before put_pid(). We cannot use
> + * call_rcu() here because free_pid() already owns pid->rcu.
> + */
> + synchronize_rcu();
> + put_pid(old_pid);
> return 0;
> }
>
> diff --git a/kernel/reboot.c b/kernel/reboot.c
> index 695c33e75efd..fc191a48c0e9 100644
> --- a/kernel/reboot.c
> +++ b/kernel/reboot.c
> @@ -24,7 +24,7 @@
> */
>
> static int C_A_D = 1;
> -struct pid *cad_pid;
> +struct pid __rcu *cad_pid;
> EXPORT_SYMBOL(cad_pid);
>
> #if defined(CONFIG_ARM)
--
Best regards, Pavel Tikhomirov
Senior Software Developer, Virtuozzo.
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [PATCH v3 1/2] pid: deinline kill_cad_pid
2026-07-19 15:58 [PATCH v3 1/2] pid: deinline kill_cad_pid Cen Zhang (Microsoft)
` (2 preceding siblings ...)
2026-07-20 9:56 ` Pavel Tikhomirov
@ 2026-07-20 13:19 ` Eric W. Biederman
2026-07-20 13:45 ` Oleg Nesterov
3 siblings, 1 reply; 9+ messages in thread
From: Eric W. Biederman @ 2026-07-20 13:19 UTC (permalink / raw)
To: Cen Zhang (Microsoft)
Cc: brauner, oleg, akpm, jack, avagin, ptikhomirov, mjguzik, include,
legion, linux-kernel, AutonomousCodeSecurity, tgopinath, kys
"Cen Zhang (Microsoft)" <blbllhy@gmail.com> writes:
> Move kill_cad_pid() out of the header without changing behavior. This
> prepares for taking a reference to cad_pid under RCU in the following
> fix.
nit: If you are going to uninline kill_cad_pid should be placed in
signal.c not in pid.c
That is where everything else that sends signals lives.
Eric
> Suggested-by: Mateusz Guzik <mjguzik@gmail.com>
> Suggested-by: Bradley Morgan <include@grrlz.net>
> Reviewed-by: Bradley Morgan <include@grrlz.net>
> Link: https://lore.kernel.org/all/CAGudoHH0vz=1m97EDHQFLLwGJmDPmqWJ+444b7rMiD059drEwQ@mail.gmail.com/
> Signed-off-by: Cen Zhang (Microsoft) <blbllhy@gmail.com>
> ---
> v3: Add Reviewed-by from Bradley Morgan.
> v2: New preparatory patch to deinline kill_cad_pid().
>
> include/linux/sched/signal.h | 5 +----
> kernel/pid.c | 5 +++++
> 2 files changed, 6 insertions(+), 4 deletions(-)
>
> diff --git a/include/linux/sched/signal.h b/include/linux/sched/signal.h
> index 584ae88b435e..d45a5476b97d 100644
> --- a/include/linux/sched/signal.h
> +++ b/include/linux/sched/signal.h
> @@ -562,10 +562,7 @@ static inline sigset_t *sigmask_to_save(void)
> return res;
> }
>
> -static inline int kill_cad_pid(int sig, int priv)
> -{
> - return kill_pid(cad_pid, sig, priv);
> -}
> +int kill_cad_pid(int sig, int priv);
>
> /* These can be the second arg to send_sig_info/send_group_sig_info. */
> #define SEND_SIG_NOINFO ((struct kernel_siginfo *) 0)
> diff --git a/kernel/pid.c b/kernel/pid.c
> index f55189a3d07d..234ebee29375 100644
> --- a/kernel/pid.c
> +++ b/kernel/pid.c
> @@ -557,6 +557,11 @@ pid_t pid_vnr(struct pid *pid)
> }
> EXPORT_SYMBOL_GPL(pid_vnr);
>
> +int kill_cad_pid(int sig, int priv)
> +{
> + return kill_pid(cad_pid, sig, priv);
> +}
> +
> pid_t __task_pid_nr_ns(struct task_struct *task, enum pid_type type,
> struct pid_namespace *ns)
> {
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [PATCH v3 1/2] pid: deinline kill_cad_pid
2026-07-20 13:19 ` Eric W. Biederman
@ 2026-07-20 13:45 ` Oleg Nesterov
2026-07-20 14:01 ` Oleg Nesterov
0 siblings, 1 reply; 9+ messages in thread
From: Oleg Nesterov @ 2026-07-20 13:45 UTC (permalink / raw)
To: Eric W. Biederman
Cc: Cen Zhang (Microsoft), brauner, akpm, jack, avagin, ptikhomirov,
mjguzik, include, legion, linux-kernel, AutonomousCodeSecurity,
tgopinath, kys
On 07/20, Eric W. Biederman wrote:
>
> "Cen Zhang (Microsoft)" <blbllhy@gmail.com> writes:
>
> > Move kill_cad_pid() out of the header without changing behavior. This
> > prepares for taking a reference to cad_pid under RCU in the following
> > fix.
>
> nit: If you are going to uninline kill_cad_pid should be placed in
> signal.c not in pid.c
>
> That is where everything else that sends signals lives.
Agreed, but...
I had a private discussion with Alexey. And he pointed out that if
we move kill_cad_pid() to reboot.c we are almost ready to unexport
cad_pid and make it static.
The only problem is kernel_init_freeable(). but I guess we can shift
the cad_pid initialization to reboot_ksysfs_init().
Anyway, this needs another patch. So I agree with signal.c in 1/2.
Oleg.
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [PATCH v3 1/2] pid: deinline kill_cad_pid
2026-07-20 13:45 ` Oleg Nesterov
@ 2026-07-20 14:01 ` Oleg Nesterov
0 siblings, 0 replies; 9+ messages in thread
From: Oleg Nesterov @ 2026-07-20 14:01 UTC (permalink / raw)
To: Eric W. Biederman
Cc: Cen Zhang (Microsoft), brauner, akpm, jack, avagin, ptikhomirov,
mjguzik, include, legion, linux-kernel, AutonomousCodeSecurity,
tgopinath, kys
On 07/20, Oleg Nesterov wrote:
>
> On 07/20, Eric W. Biederman wrote:
> >
> > "Cen Zhang (Microsoft)" <blbllhy@gmail.com> writes:
> >
> > > Move kill_cad_pid() out of the header without changing behavior. This
> > > prepares for taking a reference to cad_pid under RCU in the following
> > > fix.
> >
> > nit: If you are going to uninline kill_cad_pid should be placed in
> > signal.c not in pid.c
> >
> > That is where everything else that sends signals lives.
>
> Agreed, but...
>
> I had a private discussion with Alexey. And he pointed out that if
> we move kill_cad_pid() to reboot.c we are almost ready to unexport
> cad_pid and make it static.
>
> The only problem is kernel_init_freeable(). but I guess we can shift
> the cad_pid initialization to reboot_ksysfs_init().
>
> Anyway, this needs another patch. So I agree with signal.c in 1/2.
Forgot to mention... Either way 1/2 can remove EXPORT_SYMBOL(cad_pid)
but it has to add EXPORT_SYMBOL(kill_cad_pid).
Oleg.
^ permalink raw reply [flat|nested] 9+ messages in thread
end of thread, other threads:[~2026-07-20 14:02 UTC | newest]
Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-19 15:58 [PATCH v3 1/2] pid: deinline kill_cad_pid Cen Zhang (Microsoft)
2026-07-19 15:58 ` [PATCH v3 2/2] pid: fix cad_pid use-after-free race Cen Zhang (Microsoft)
2026-07-20 10:09 ` Pavel Tikhomirov
2026-07-19 16:20 ` [PATCH v3 1/2] pid: deinline kill_cad_pid Oleg Nesterov
2026-07-19 16:26 ` Cen Zhang (Microsoft)
2026-07-20 9:56 ` Pavel Tikhomirov
2026-07-20 13:19 ` Eric W. Biederman
2026-07-20 13:45 ` Oleg Nesterov
2026-07-20 14:01 ` Oleg Nesterov
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.