public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
* [PATCH 5/5] do_wait: fix the theoretical race with stop/trace/cont
@ 2009-05-07  6:46 Oleg Nesterov
  2009-05-07  7:29 ` Roland McGrath
  0 siblings, 1 reply; 2+ messages in thread
From: Oleg Nesterov @ 2009-05-07  6:46 UTC (permalink / raw)
  To: Andrew Morton
  Cc: Ingo Molnar, Roland McGrath, Vitaly Mayatskikh, linux-kernel

do_wait:

	current->state = TASK_INTERRUPTIBLE;

	read_lock(&tasklist_lock);
	... search for the task to reap ...

In theory, the ->state changing can leak into the critical section.
Since the child can change its status under read_lock(tasklist) in
parallel (finish_stop/ptrace_stop), we can miss the wakeup if
__wake_up_parent() sees us in TASK_RUNNING state. Add the barrier.

Also, use __set_current_state() to set TASK_RUNNING.

Signed-off-by: Oleg Nesterov <oleg@redhat.com>
---

 kernel/exit.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- PTRACE/kernel/exit.c~5_MB	2009-05-07 05:34:40.000000000 +0200
+++ PTRACE/kernel/exit.c	2009-05-07 05:43:06.000000000 +0200
@@ -1581,7 +1581,7 @@ repeat:
 	   (!wo->wo_pid || hlist_empty(&wo->wo_pid->tasks[wo->wo_type])))
 		goto notask;
 
-	current->state = TASK_INTERRUPTIBLE;
+	set_current_state(TASK_INTERRUPTIBLE);
 	read_lock(&tasklist_lock);
 	tsk = current;
 	do {
@@ -1608,7 +1608,7 @@ notask:
 		}
 	}
 end:
-	current->state = TASK_RUNNING;
+	__set_current_state(TASK_RUNNING);
 	remove_wait_queue(&current->signal->wait_chldexit,&wait);
 	if (wo->wo_info) {
 		struct siginfo __user *infop = wo->wo_info;


^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [PATCH 5/5] do_wait: fix the theoretical race with stop/trace/cont
  2009-05-07  6:46 [PATCH 5/5] do_wait: fix the theoretical race with stop/trace/cont Oleg Nesterov
@ 2009-05-07  7:29 ` Roland McGrath
  0 siblings, 0 replies; 2+ messages in thread
From: Roland McGrath @ 2009-05-07  7:29 UTC (permalink / raw)
  To: Oleg Nesterov; +Cc: Andrew Morton, Ingo Molnar, Vitaly Mayatskikh, linux-kernel

Acked-by: Roland McGrath <roland@redhat.com>

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2009-05-07  7:30 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2009-05-07  6:46 [PATCH 5/5] do_wait: fix the theoretical race with stop/trace/cont Oleg Nesterov
2009-05-07  7:29 ` Roland McGrath

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox