* [PATCH -next 04/10] uml: Fix unsafe pid reference to foreground process group
[not found] <1413485990-16855-1-git-send-email-peter@hurleysoftware.com>
@ 2014-10-16 18:59 ` Peter Hurley
2014-10-17 7:57 ` Richard Weinberger
0 siblings, 1 reply; 2+ messages in thread
From: Peter Hurley @ 2014-10-16 18:59 UTC (permalink / raw)
To: Greg Kroah-Hartman
Cc: linux-serial, linux-kernel, Jiri Slaby, One Thousand Gnomes,
Peter Hurley, Jeff Dike, Richard Weinberger,
user-mode-linux-devel
Although the tty core maintains a pid reference for the foreground
process group, if the foreground process group is changed that
pid reference is dropped. Thus, the pid reference used for signalling
could become stale.
Safely obtain a pid reference to the foreground process group and
release the reference after signalling is complete.
cc: Jeff Dike <jdike@addtoit.com>
cc: Richard Weinberger <richard@nod.at>
cc: user-mode-linux-devel@lists.sourceforge.net
Signed-off-by: Peter Hurley <peter@hurleysoftware.com>
---
arch/um/drivers/line.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/arch/um/drivers/line.c b/arch/um/drivers/line.c
index 8035145..6208702 100644
--- a/arch/um/drivers/line.c
+++ b/arch/um/drivers/line.c
@@ -632,6 +632,7 @@ static irqreturn_t winch_interrupt(int irq, void *data)
int fd = winch->fd;
int err;
char c;
+ struct pid *pgrp;
if (fd != -1) {
err = generic_read(fd, &c, NULL);
@@ -657,7 +658,10 @@ static irqreturn_t winch_interrupt(int irq, void *data)
if (line != NULL) {
chan_window_size(line, &tty->winsize.ws_row,
&tty->winsize.ws_col);
- kill_pgrp(tty->pgrp, SIGWINCH, 1);
+ pgrp = tty_get_pgrp(tty);
+ if (pgrp)
+ kill_pgrp(pgrp, SIGWINCH, 1);
+ put_pid(pgrp);
}
tty_kref_put(tty);
}
--
2.1.1
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCH -next 04/10] uml: Fix unsafe pid reference to foreground process group
2014-10-16 18:59 ` [PATCH -next 04/10] uml: Fix unsafe pid reference to foreground process group Peter Hurley
@ 2014-10-17 7:57 ` Richard Weinberger
0 siblings, 0 replies; 2+ messages in thread
From: Richard Weinberger @ 2014-10-17 7:57 UTC (permalink / raw)
To: Peter Hurley, Greg Kroah-Hartman
Cc: linux-serial, linux-kernel, Jiri Slaby, One Thousand Gnomes,
Jeff Dike, user-mode-linux-devel
Am 16.10.2014 um 20:59 schrieb Peter Hurley:
> Although the tty core maintains a pid reference for the foreground
> process group, if the foreground process group is changed that
> pid reference is dropped. Thus, the pid reference used for signalling
> could become stale.
>
> Safely obtain a pid reference to the foreground process group and
> release the reference after signalling is complete.
>
> cc: Jeff Dike <jdike@addtoit.com>
> cc: Richard Weinberger <richard@nod.at>
> cc: user-mode-linux-devel@lists.sourceforge.net
> Signed-off-by: Peter Hurley <peter@hurleysoftware.com>
Acked-by: Richard Weinberger <richard@nod.at>
> ---
> arch/um/drivers/line.c | 6 +++++-
> 1 file changed, 5 insertions(+), 1 deletion(-)
>
> diff --git a/arch/um/drivers/line.c b/arch/um/drivers/line.c
> index 8035145..6208702 100644
> --- a/arch/um/drivers/line.c
> +++ b/arch/um/drivers/line.c
> @@ -632,6 +632,7 @@ static irqreturn_t winch_interrupt(int irq, void *data)
> int fd = winch->fd;
> int err;
> char c;
> + struct pid *pgrp;
>
> if (fd != -1) {
> err = generic_read(fd, &c, NULL);
> @@ -657,7 +658,10 @@ static irqreturn_t winch_interrupt(int irq, void *data)
> if (line != NULL) {
> chan_window_size(line, &tty->winsize.ws_row,
> &tty->winsize.ws_col);
> - kill_pgrp(tty->pgrp, SIGWINCH, 1);
> + pgrp = tty_get_pgrp(tty);
> + if (pgrp)
> + kill_pgrp(pgrp, SIGWINCH, 1);
> + put_pid(pgrp);
> }
> tty_kref_put(tty);
> }
>
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2014-10-17 7:57 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
[not found] <1413485990-16855-1-git-send-email-peter@hurleysoftware.com>
2014-10-16 18:59 ` [PATCH -next 04/10] uml: Fix unsafe pid reference to foreground process group Peter Hurley
2014-10-17 7:57 ` Richard Weinberger
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox