public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
* [PATCH for 3.1] ptrace: PTRACE_LISTEN forgets to unlock ->siglock
@ 2011-09-25 17:46 Oleg Nesterov
  2011-09-26  8:09 ` Matt Fleming
  0 siblings, 1 reply; 2+ messages in thread
From: Oleg Nesterov @ 2011-09-25 17:46 UTC (permalink / raw)
  To: Linus Torvalds; +Cc: Matt Fleming, Tejun Heo, linux-kernel

If PTRACE_LISTEN fails after lock_task_sighand() it doesn't drop ->siglock.

Reported-by: Matt Fleming <matt.fleming@intel.com>
Signed-off-by: Oleg Nesterov <oleg@redhat.com>
---

 kernel/ptrace.c |   23 ++++++++++-------------
 1 file changed, 10 insertions(+), 13 deletions(-)

--- 3.1/kernel/ptrace.c~1_PTRACE_LISTEN_siglock	2011-09-25 19:14:32.000000000 +0200
+++ 3.1/kernel/ptrace.c	2011-09-25 19:40:57.000000000 +0200
@@ -744,20 +744,17 @@ int ptrace_request(struct task_struct *c
 			break;
 
 		si = child->last_siginfo;
-		if (unlikely(!si || si->si_code >> 8 != PTRACE_EVENT_STOP))
-			break;
-
-		child->jobctl |= JOBCTL_LISTENING;
-
-		/*
-		 * If NOTIFY is set, it means event happened between start
-		 * of this trap and now.  Trigger re-trap immediately.
-		 */
-		if (child->jobctl & JOBCTL_TRAP_NOTIFY)
-			signal_wake_up(child, true);
-
+		if (likely(si && (si->si_code >> 8) == PTRACE_EVENT_STOP)) {
+			child->jobctl |= JOBCTL_LISTENING;
+			/*
+			 * If NOTIFY is set, it means event happened between
+			 * start of this trap and now.  Trigger re-trap.
+			 */
+			if (child->jobctl & JOBCTL_TRAP_NOTIFY)
+				signal_wake_up(child, true);
+			ret = 0;
+		}
 		unlock_task_sighand(child, &flags);
-		ret = 0;
 		break;
 
 	case PTRACE_DETACH:	 /* detach a process that was attached. */


^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2011-09-26  8:09 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-09-25 17:46 [PATCH for 3.1] ptrace: PTRACE_LISTEN forgets to unlock ->siglock Oleg Nesterov
2011-09-26  8:09 ` Matt Fleming

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox