From: Christian Brauner <brauner@kernel.org>
To: Oleg Nesterov <oleg@redhat.com>, Chris Mason <mason@kernel.org>,
linux-fsdevel@vger.kernel.org
Cc: Jens Axboe <axboe@kernel.dk>,
Alexander Viro <viro@zeniv.linux.org.uk>,
Jan Kara <jack@suse.cz>, NeilBrown <neil@brown.name>,
Ingo Molnar <mingo@redhat.com>,
Peter Zijlstra <peterz@infradead.org>,
linux-mm@kvack.org, io-uring@vger.kernel.org,
"Christian Brauner (Amutable)" <brauner@kernel.org>,
stable@vger.kernel.org
Subject: [PATCH v3 00/17] coredump & signals: an impossible affair
Date: Mon, 21 Sep 2026 15:44:49 +0200 [thread overview]
Message-ID: <20260921-work-coredump-fixes-v3-0-8e4adb1619e6@kernel.org> (raw)
Hey,
I asked Chris to look at the coredump code with kres and it found a few
bugs. I started looking as well and found a few more. Here's a fixes
series. I also used TLA+ modeling for this.
Fixes in here:
- UAF in coredump_finish(): a parked thread can be freed before it is
woken
- only SIGKILL and the freezers interrupt a dump now, cgroup v2 included
- core_pattern is parsed from a snapshot instead of racing the sysctl
- the io-wq exit bit wasn't ordered against worker creation task work,
exit could hang on worker_done
- shared signals are no longer retargeted to the dumper, that truncated
cores
- a failed fork released its files under scx_fork_rwsem, deadlock
- a session leader's exit lost the SIGHUP for the foreground job
- an io-wq worker of an SQPOLL ring as the dumper deadlocks the group,
user workers never dump now
- PTRACE_SETSIGMASK can't unmask a user worker anymore, the only way in
- exec cancels io_uring before de_thread(), nothing adds a thread after
it
- no io threads from PF_SIGNALED or PF_POSTCOREDUMP creators, they
broke threads_remaining
- descriptor tables are closed highest fd first again, the order the
deferred puts had
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
---
Changes in v3:
- Address Oleg's reviews.
- Add a couple more fixes.
- Link to v2: https://patch.msgid.link/20260917-work-coredump-fixes-v2-0-f3787fcda051@kernel.org
Changes in v2:
- Add fixes for retarget_shared_signal().
- Expand fixes for signal_pending().
- Link to v1: https://patch.msgid.link/20260915-work-coredump-fixes-v1-0-f354ca41780c@kernel.org
---
Christian Brauner (18):
Merge patch series "files: make closing files synchronous for close_range(), exec, exit"
coredump: hold RCU while releasing parked threads
signal: only SIGKILL and the freezers interrupt a coredumping task
coredump: parse a snapshot of core_pattern
io-wq: order the exit bit against worker creation task work
signal: don't retarget shared signals in a dying thread group
selftests/coredump: test shared signal retargeting during a dump
fork: release the files of a failed fork after sched_cancel_fork()
exit: hang up the tty before closing the files
ptrace: refuse to change the signal mask of a user worker
selftests/coredump: test a user worker as the coredumping thread
selftests/coredump: expect PTRACE_SETSIGMASK to be refused on a user worker
exec: cancel io_uring requests before de_thread()
fork: move the coredump and exec checks into create_io_thread()
fork: don't create io threads once PF_POSTCOREDUMP is set
fork: use SIG_KERNEL_ONLY_MASK for the user worker signal mask
signal: enforce the user worker signal mask in __set_task_blocked()
fs: close files from the highest descriptor down
fs/coredump.c | 73 ++--
fs/exec.c | 11 +-
fs/file.c | 55 +--
include/linux/sched/signal.h | 19 +-
io_uring/io-wq.c | 2 +
kernel/exit.c | 5 +-
kernel/fork.c | 20 +-
kernel/ptrace.c | 6 +
kernel/signal.c | 22 +
tools/testing/selftests/coredump/.gitignore | 2 +
tools/testing/selftests/coredump/Makefile | 6 +-
.../selftests/coredump/coredump_signal_test.c | 238 +++++++++++
.../selftests/coredump/coredump_worker_test.c | 447 +++++++++++++++++++++
13 files changed, 832 insertions(+), 74 deletions(-)
---
base-commit: dadceac9d20a1c90269aafd7746f7c0c05879ad3
change-id: 20260915-work-coredump-fixes-edf98c80fe78
next reply other threads:[~2026-09-21 13:45 UTC|newest]
Thread overview: 29+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-21 13:44 Christian Brauner [this message]
2026-09-21 13:44 ` [PATCH v3 01/17] coredump: hold RCU while releasing parked threads Christian Brauner
2026-09-21 13:44 ` [PATCH v3 02/17] signal: only SIGKILL and the freezers interrupt a coredumping task Christian Brauner
2026-09-22 12:55 ` Oleg Nesterov
2026-09-22 14:33 ` Christian Brauner
2026-09-21 13:44 ` [PATCH v3 03/17] coredump: parse a snapshot of core_pattern Christian Brauner
2026-09-21 13:44 ` [PATCH v3 04/17] io-wq: order the exit bit against worker creation task work Christian Brauner
2026-09-21 13:44 ` [PATCH v3 05/17] signal: don't retarget shared signals in a dying thread group Christian Brauner
2026-09-21 13:44 ` [PATCH v3 06/17] selftests/coredump: test shared signal retargeting during a dump Christian Brauner
2026-09-21 13:44 ` [PATCH v3 07/17] fork: release the files of a failed fork after sched_cancel_fork() Christian Brauner
2026-09-21 13:44 ` [PATCH v3 08/17] exit: hang up the tty before closing the files Christian Brauner
2026-09-24 12:10 ` Oleg Nesterov
2026-09-21 13:44 ` [PATCH v3 09/17] ptrace: refuse to change the signal mask of a user worker Christian Brauner
2026-09-21 14:14 ` Oleg Nesterov
2026-09-21 13:44 ` [PATCH v3 10/17] selftests/coredump: test a user worker as the coredumping thread Christian Brauner
2026-09-21 13:45 ` [PATCH v3 11/17] selftests/coredump: expect PTRACE_SETSIGMASK to be refused on a user worker Christian Brauner
2026-09-21 13:45 ` [PATCH v3 12/17] exec: cancel io_uring requests before de_thread() Christian Brauner
2026-09-21 14:14 ` Oleg Nesterov
2026-09-24 14:19 ` Jens Axboe
2026-09-21 13:45 ` [PATCH v3 13/17] fork: move the coredump and exec checks into create_io_thread() Christian Brauner
2026-09-21 14:15 ` Oleg Nesterov
2026-09-21 13:45 ` [PATCH v3 14/17] fork: don't create io threads once PF_POSTCOREDUMP is set Christian Brauner
2026-09-21 14:26 ` Oleg Nesterov
2026-09-21 13:45 ` [PATCH v3 15/17] fork: use SIG_KERNEL_ONLY_MASK for the user worker signal mask Christian Brauner
2026-09-21 14:29 ` Oleg Nesterov
2026-09-21 13:45 ` [PATCH v3 16/17] signal: enforce the user worker signal mask in __set_task_blocked() Christian Brauner
2026-09-21 16:16 ` Oleg Nesterov
2026-09-21 20:05 ` Christian Brauner
2026-09-21 13:45 ` [PATCH v3 17/17] fs: close files from the highest descriptor down Christian Brauner
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260921-work-coredump-fixes-v3-0-8e4adb1619e6@kernel.org \
--to=brauner@kernel.org \
--cc=axboe@kernel.dk \
--cc=io-uring@vger.kernel.org \
--cc=jack@suse.cz \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=mason@kernel.org \
--cc=mingo@redhat.com \
--cc=neil@brown.name \
--cc=oleg@redhat.com \
--cc=peterz@infradead.org \
--cc=stable@vger.kernel.org \
--cc=viro@zeniv.linux.org.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox