From: "Emiliano 'AlberT' Gabrielli" <AlberT@agilemovement.it>
To: linux-kernel@vger.kernel.org
Subject: Re: Hidden PIDs in /proc
Date: Tue, 23 Mar 2004 17:40:14 +0100 [thread overview]
Message-ID: <200403231740.14351.AlberT@agilemovement.it> (raw)
In-Reply-To: <c3pnr5$29f$1@news.cistron.nl>
On Tuesday 23 March 2004 17:15, Miquel van Smoorenburg wrote:
> In article <200403231708.15812.AlberT@agilemovement.it>,
>
> Emiliano 'AlberT' Gabrielli <AlberT@agilemovement.it> wrote:
> >Hi all,
> >
> > I discovered some "hidden" pid dirs in /proc :
> >
> >root@emc2:# ls -lha /proc/ | grep 4673
> >root@emc2:# ls -lha /proc/4673/
> >totale 0
> >dr-xr-xr-x 3 albert albert 0 2004-03-23 17:02 .
> >dr-xr-xr-x 108 root root 0 2004-03-23 16:10 ..
>
> It's just a thread. For a threaded process, only the thread group
> leader is listed in /proc directly. The other threads are visible
> under /proc/<tgid>/task (try it).
>
I allready did it ... infact the second test I posted correctly shows the
thread ... but, why ps ax -m does *not* show it ??
uhmm ok under task I can see all the threads correcly... the question now
is .. why to show also the secondary threads directly in /proc, even if not
visible by readdir ? It is a confusing issue for chkrootkit and similar...
creating only the /proc/<tgid> in /proc shoud suffice and be cleaner ...
IMHO.
> >After 2 days of headhake searching for possible rootkits, reinstalling all
> > the basic system, libs and so on (from a clean live-CD boot) ...
> >I noticed that these process seem all to use pthreads ... so, the question
> > is:
> >
> >is my problem related/solved by the
> > initramfs-search-for-init-zombie-fix.patch in the -mm1 tree ??
>
> No, by upgrading to a more recent procps.
>
> # ps ax | grep mozilla
> 16252 ? S 10:21 /usr/lib/mozilla-firefox/firefox-bin
> $ ps ax -T | grep moz
> 16252 16252 ? S 10:21 /usr/lib/mozilla-firefox/firefox-bin
> 16252 16264 ? S 0:01 /usr/lib/mozilla-firefox/firefox-bin
> 16252 16266 ? S 0:03 /usr/lib/mozilla-firefox/firefox-bin
> 16252 21530 ? S 0:00 /usr/lib/mozilla-firefox/firefox-bin
>
> Also note:
>
> # ls /proc/16252/task
> 16252/ 16264/ 16266/ 21530/
>
> Mike.
uh oh .. my bad ... but .. my ignorance now ask what is the real diff between
-m and -T option for ps ...
thanks
--
Emiliano `AlberT` Gabrielli
E-Mail: AlberT@SuperAlberT.it - Web: http://SuperAlberT.it
Membro dell'Italian Agile Movement - AlberT@agilemovement.it
next prev parent reply other threads:[~2004-03-23 16:38 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-03-23 16:08 Hidden PIDs in /proc Emiliano 'AlberT' Gabrielli
2004-03-23 16:15 ` Miquel van Smoorenburg
2004-03-23 16:40 ` Emiliano 'AlberT' Gabrielli [this message]
-- strict thread matches above, loose matches on Subject: below --
2004-03-24 2:20 Albert Cahalan
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200403231740.14351.AlberT@agilemovement.it \
--to=albert@agilemovement.it \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox