public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
From: Peter Zijlstra <peterz@infradead.org>
To: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Bartosz Golaszewski <bartosz.golaszewski@linaro.org>,
	Alexey Dobriyan <adobriyan@gmail.com>,
	linux-kernel@vger.kernel.org,
	Linus Walleij <linus.walleij@linaro.org>,
	akpm@linux-foundation.org
Subject: Re: Buggy __free(kfree) usage pattern already in tree
Date: Tue, 19 Sep 2023 15:10:38 +0200	[thread overview]
Message-ID: <20230919131038.GC39346@noisy.programming.kicks-ass.net> (raw)
In-Reply-To: <20230919125954.GB39346@noisy.programming.kicks-ass.net>

On Tue, Sep 19, 2023 at 02:59:54PM +0200, Peter Zijlstra wrote:


> +	scoped_guard (mutex_intr, &task->signal->cred_guard_mutex) {
>  
> +		scoped_guard (task_lock, task) {
> +			retval = __ptrace_may_access(task, PTRACE_MODE_ATTACH_REALCREDS);
> +			if (retval)
> +				return retval;
> +		}
>  
> +		scoped_guard (write_lock, &tasklist_lock) {
> +			if (unlikely(task->exit_state))
> +				return -EPERM;
> +			if (task->ptrace)
> +				return -EPERM;
>  
> +			task->ptrace = flags;
>  
> +			ptrace_link(task, current);
> +
> +			/* SEIZE doesn't trap tracee on attach */
> +			if (!seize)
> +				send_sig_info(SIGSTOP, SEND_SIG_PRIV, task);
> +
> +			ptrace_set_stopped(task);
> +
> +		}
> +
> +		goto success;
>  	}
> +	return -ERESTARTNOINTR;
>  
> +success:
> +	/*
> +	 * We do not bother to change retval or clear JOBCTL_TRAPPING
> +	 * if wait_on_bit() was interrupted by SIGKILL. The tracer will
> +	 * not return to user-mode, it will exit and clear this bit in
> +	 * __ptrace_unlink() if it wasn't already cleared by the tracee;
> +	 * and until then nobody can ptrace this task.
> +	 */
> +	wait_on_bit(&task->jobctl, JOBCTL_TRAPPING_BIT, TASK_KILLABLE);
> +	proc_ptrace_connector(task, PTRACE_ATTACH);
> +
> +	return 0;

This isn't exactly nice..

I tried something like:

	scoped_cond_guard (mutex_intr, return -EINTR, &task->signal->cred_guard_mutex) {
		...
	}

Which I can make work, but then I also tried to capture my other case:

	scoped_cond_guard (rwsem_down_intr, if (task) return -EINTR,
			   task ? &task->signal->exec_guard_mutex : NULL)  {

		...
	}

But I can't get that to work because of that extra if, the not case
doesn't fall through and do the body.

Anyway, I'll poke more..

  reply	other threads:[~2023-09-19 13:10 UTC|newest]

Thread overview: 21+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2023-09-15  9:56 Buggy __free(kfree) usage pattern already in tree Alexey Dobriyan
2023-09-15 10:09 ` Bartosz Golaszewski
2023-09-15 17:04 ` Linus Torvalds
2023-09-15 17:22   ` Bartosz Golaszewski
2023-09-15 19:06     ` Linus Torvalds
2023-09-15 19:27       ` Bartosz Golaszewski
2023-09-15 20:03         ` Bartosz Golaszewski
2023-09-15 20:40           ` Linus Torvalds
2023-09-15 21:08             ` Peter Zijlstra
2023-09-15 21:18               ` Peter Zijlstra
2023-09-15 21:25                 ` Linus Torvalds
2023-09-15 21:22               ` Linus Torvalds
2023-09-15 21:32                 ` Peter Zijlstra
2023-09-15 21:50                   ` Linus Torvalds
2023-09-15 22:10                     ` Linus Torvalds
2023-09-15 22:13                     ` Peter Zijlstra
2023-09-19 12:57                       ` Peter Zijlstra
2023-09-19 12:59                         ` Peter Zijlstra
2023-09-19 13:10                           ` Peter Zijlstra [this message]
2023-09-19 19:35                             ` Peter Zijlstra
2023-09-20 11:02                               ` David Laight

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20230919131038.GC39346@noisy.programming.kicks-ass.net \
    --to=peterz@infradead.org \
    --cc=adobriyan@gmail.com \
    --cc=akpm@linux-foundation.org \
    --cc=bartosz.golaszewski@linaro.org \
    --cc=linus.walleij@linaro.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=torvalds@linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox