From: Frederic Weisbecker <frederic@kernel.org>
To: Oleg Nesterov <oleg@redhat.com>
Cc: Thomas Gleixner <tglx@kernel.org>,
Hyunwoo Kim <imv4bel@gmail.com>,
brauner@kernel.org, peterz@infradead.org,
anna-maria@linutronix.de, ebiederm@xmission.com,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH] signal: Use list_del_init_careful() in flush_sigqueue()
Date: Mon, 24 Aug 2026 15:59:48 +0200 [thread overview]
Message-ID: <aoxOVAd8ooqHFW12@localhost.localdomain> (raw)
In-Reply-To: <aoww8qi_ce_8ECA9@redhat.com>
Le Mon, Aug 24, 2026 at 01:54:26PM +0200, Oleg Nesterov a écrit :
> On 08/24, Oleg Nesterov wrote:
> >
> > On 08/24, Thomas Gleixner wrote:
> > >
> > > --- a/fs/exec.c
> > > +++ b/fs/exec.c
> > > @@ -983,6 +983,18 @@ static int de_thread(struct task_struct
> > > }
> > >
> > > /*
> > > + * Ensure that POSIX timer SIGEV_THREAD_ID signals pending for
> > > + * the former leader are removed under sighand::siglock _before_
> > > + * taking over the leader's TID. Otherwise the lockless cleanup
> > > + * in release_task() can race against a concurrent signal
> > > + * delivery to the new leader. The former leader has PF_EXITING
> > > + * set which prevents queueing of SIGEV_THREAD_ID signals up to
> > > + * the point where it's sighand gets cleared.
> > > + */
> > > + scoped_guard(spinlock_irq, lock)
> > > + flush_sigqueue(&leader->pending);
>
> scoped_guard(spinlock_irq) is not right. This needs scoped_guard(spinlock),
> the code runs with irqs disabled.
>
> > Hmm, at first glance... If we change de_thread() to do this _after_ transfer_pid's
> > (before release_task(leader)), then posixtimer_send_sigqueue() doesn't need any
> > changes, no?
>
> IOW. Unless I am totally confused, we only need to flush the
> SIGQUEUE_PREALLOC sigqueue's which were sent to the (old) leader
> before it changed its pid. So we can do this
>
> diff --git a/fs/exec.c b/fs/exec.c
> index a14f28b15607..550367e7fe6c 100644
> --- a/fs/exec.c
> +++ b/fs/exec.c
> @@ -1029,6 +1029,9 @@ static int de_thread(struct task_struct *tsk)
> write_unlock_irq(&tasklist_lock);
> cgroup_threadgroup_change_end(tsk);
>
> + scoped_guard(spinlock_irq, lock)
> + flush_sigqueue(&leader->pending);
> +
Is there something to prevent the timer from firing on another CPU,
racing with this tiny window and queue the signal to the old leader? After
all exchange_tids() is just some RCU pointers changed but there is nothing
to synchronize the readers before the flush_sigqueue(). So pid_task() may
still return the old leader after it?
> release_task(leader);
Thanks.
--
Frederic Weisbecker
SUSE Labs
next prev parent reply other threads:[~2026-08-24 13:59 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-22 5:37 [PATCH] signal: Use list_del_init_careful() in flush_sigqueue() Hyunwoo Kim
2026-08-22 10:27 ` Bradley Morgan
2026-08-23 12:47 ` Oleg Nesterov
2026-08-24 2:53 ` Hyunwoo Kim
2026-08-24 8:28 ` Oleg Nesterov
2026-08-24 8:04 ` Thomas Gleixner
2026-08-24 9:45 ` Thomas Gleixner
2026-08-24 11:02 ` Oleg Nesterov
2026-08-24 11:54 ` Oleg Nesterov
2026-08-24 13:59 ` Frederic Weisbecker [this message]
2026-08-24 14:29 ` Oleg Nesterov
2026-08-25 16:58 ` Thomas Gleixner
2026-08-25 18:53 ` Oleg Nesterov
2026-08-25 19:58 ` Thomas Gleixner
2026-08-26 9:36 ` Oleg Nesterov
2026-08-24 12:11 ` Thomas Gleixner
2026-08-24 16:31 ` Frederic Weisbecker
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aoxOVAd8ooqHFW12@localhost.localdomain \
--to=frederic@kernel.org \
--cc=anna-maria@linutronix.de \
--cc=brauner@kernel.org \
--cc=ebiederm@xmission.com \
--cc=imv4bel@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=oleg@redhat.com \
--cc=peterz@infradead.org \
--cc=tglx@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.