From: Oleg Nesterov <oleg@redhat.com>
To: Thomas Gleixner <tglx@kernel.org>
Cc: Hyunwoo Kim <imv4bel@gmail.com>,
frederic@kernel.org, brauner@kernel.org, peterz@infradead.org,
anna-maria@linutronix.de, ebiederm@xmission.com,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH] signal: Use list_del_init_careful() in flush_sigqueue()
Date: Mon, 24 Aug 2026 13:54:26 +0200 [thread overview]
Message-ID: <aoww8qi_ce_8ECA9@redhat.com> (raw)
In-Reply-To: <aowkvvxg8cPP5V0X@redhat.com>
On 08/24, Oleg Nesterov wrote:
>
> On 08/24, Thomas Gleixner wrote:
> >
> > --- a/fs/exec.c
> > +++ b/fs/exec.c
> > @@ -983,6 +983,18 @@ static int de_thread(struct task_struct
> > }
> >
> > /*
> > + * Ensure that POSIX timer SIGEV_THREAD_ID signals pending for
> > + * the former leader are removed under sighand::siglock _before_
> > + * taking over the leader's TID. Otherwise the lockless cleanup
> > + * in release_task() can race against a concurrent signal
> > + * delivery to the new leader. The former leader has PF_EXITING
> > + * set which prevents queueing of SIGEV_THREAD_ID signals up to
> > + * the point where it's sighand gets cleared.
> > + */
> > + scoped_guard(spinlock_irq, lock)
> > + flush_sigqueue(&leader->pending);
scoped_guard(spinlock_irq) is not right. This needs scoped_guard(spinlock),
the code runs with irqs disabled.
> Hmm, at first glance... If we change de_thread() to do this _after_ transfer_pid's
> (before release_task(leader)), then posixtimer_send_sigqueue() doesn't need any
> changes, no?
IOW. Unless I am totally confused, we only need to flush the
SIGQUEUE_PREALLOC sigqueue's which were sent to the (old) leader
before it changed its pid. So we can do this
diff --git a/fs/exec.c b/fs/exec.c
index a14f28b15607..550367e7fe6c 100644
--- a/fs/exec.c
+++ b/fs/exec.c
@@ -1029,6 +1029,9 @@ static int de_thread(struct task_struct *tsk)
write_unlock_irq(&tasklist_lock);
cgroup_threadgroup_change_end(tsk);
+ scoped_guard(spinlock_irq, lock)
+ flush_sigqueue(&leader->pending);
+
release_task(leader);
}
outside of tasklist_lock.
We do not care if another sigqueue (SIGQUEUE_PREALLOC or not) comes to
leader->pending after that.
No?
Either way, this means that flush_sigqueue() is called again with irqs
disabled... Not a real problem, but can the change below work? Yes,
more fragile and probably "fixes symptom"...
Oleg.
diff --git a/kernel/signal.c b/kernel/signal.c
index bbc0fd4cc4d7..4d12ebba33f9 100644
--- a/kernel/signal.c
+++ b/kernel/signal.c
@@ -477,14 +477,14 @@ static void __sigqueue_free(struct sigqueue *q)
void flush_sigqueue(struct sigpending *queue)
{
- struct sigqueue *q;
+ struct sigqueue *q, *n;
sigemptyset(&queue->signal);
- while (!list_empty(&queue->list)) {
- q = list_entry(queue->list.next, struct sigqueue , list);
- list_del_init(&q->list);
+
+ list_for_each_entry_safe(q, n, &queue->list, list)
__sigqueue_free(q);
- }
+
+ INIT_LIST_HEAD(&queue->list);
}
/*
next prev parent reply other threads:[~2026-08-24 11:54 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-22 5:37 [PATCH] signal: Use list_del_init_careful() in flush_sigqueue() Hyunwoo Kim
2026-08-22 10:27 ` Bradley Morgan
2026-08-23 12:47 ` Oleg Nesterov
2026-08-24 2:53 ` Hyunwoo Kim
2026-08-24 8:28 ` Oleg Nesterov
2026-08-24 8:04 ` Thomas Gleixner
2026-08-24 9:45 ` Thomas Gleixner
2026-08-24 11:02 ` Oleg Nesterov
2026-08-24 11:54 ` Oleg Nesterov [this message]
2026-08-24 13:59 ` Frederic Weisbecker
2026-08-24 14:29 ` Oleg Nesterov
2026-08-25 16:58 ` Thomas Gleixner
2026-08-25 18:53 ` Oleg Nesterov
2026-08-25 19:58 ` Thomas Gleixner
2026-08-26 9:36 ` Oleg Nesterov
2026-08-24 12:11 ` Thomas Gleixner
2026-08-24 16:31 ` Frederic Weisbecker
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aoww8qi_ce_8ECA9@redhat.com \
--to=oleg@redhat.com \
--cc=anna-maria@linutronix.de \
--cc=brauner@kernel.org \
--cc=ebiederm@xmission.com \
--cc=frederic@kernel.org \
--cc=imv4bel@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=peterz@infradead.org \
--cc=tglx@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.