public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
* [PATCH] sched: fix fork() error path to not crash.
@ 2012-06-26  1:18 Salman Qazi
  2012-06-26  8:40 ` Peter Zijlstra
  2012-07-06  6:18 ` [tip:sched/core] sched: Fix " tip-bot for Salman Qazi
  0 siblings, 2 replies; 4+ messages in thread
From: Salman Qazi @ 2012-06-26  1:18 UTC (permalink / raw)
  To: a.p.zijlstra, linux-kernel

In dup_task_struct, if arch_dup_task_struct fails, the clean up
code fails to clean up correctly.  That's because the clean up
code depends on unininitalized ti->task pointer.  We fix this
by making sure that the task and thread_info know about each other
before we attempt to take the error path.

Signed-off-by: Salman Qazi <sqazi@google.com>
---
 kernel/fork.c |   11 ++++++++---
 1 files changed, 8 insertions(+), 3 deletions(-)

diff --git a/kernel/fork.c b/kernel/fork.c
index ab5211b..f00e319 100644
--- a/kernel/fork.c
+++ b/kernel/fork.c
@@ -304,12 +304,17 @@ static struct task_struct *dup_task_struct(struct task_struct *orig)
 	}
 
 	err = arch_dup_task_struct(tsk, orig);
-	if (err)
-		goto out;
 
+	/*
+	 * We defer looking at err, because we will need this setup
+	 * for the clean up path to work correctly.
+	 */
 	tsk->stack = ti;
-
 	setup_thread_stack(tsk, orig);
+
+	if (err)
+		goto out;
+
 	clear_user_return_notifier(tsk);
 	clear_tsk_need_resched(tsk);
 	stackend = end_of_stack(tsk);


^ permalink raw reply related	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2012-07-06  6:19 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2012-06-26  1:18 [PATCH] sched: fix fork() error path to not crash Salman Qazi
2012-06-26  8:40 ` Peter Zijlstra
2012-06-26 16:58   ` Salman Qazi
2012-07-06  6:18 ` [tip:sched/core] sched: Fix " tip-bot for Salman Qazi

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox