From: Andrew Rodland <arodland@entermail.net>
To: linux-kernel@vger.kernel.org
Subject: Re: [PATCH] task name handling in proc fs
Date: Thu, 01 Jul 2004 21:27:32 -0400 [thread overview]
Message-ID: <cc2dkn$e63$1@sea.gmane.org> (raw)
In-Reply-To: 20040701224215.GC5090@w-mikek2.beaverton.ibm.com
Mike Kravetz wrote:
> On Thu, Jul 01, 2004 at 03:19:35PM -0700, Andrew Morton wrote:
>> Mike Kravetz <kravetz@us.ibm.com> wrote:
>> >
>> > --- linux-2.6.7/fs/proc/array.c Wed Jun 16 05:19:36 2004
>> > +++ linux-2.6.7.ptest/fs/proc/array.c Thu Jul 1 17:44:14 2004
>> > @@ -97,14 +97,14 @@
>> > name++;
>> > i--;
>> > *buf = c;
>> > - if (!c)
>> > + if (!*buf)
>> > break;
>> > - if (c == '\\') {
>> > - buf[1] = c;
>> > + if (*buf == '\\') {
>> > + buf[1] = *buf;
>> > buf += 2;
>> > continue;
>> > }
>> > - if (c == '\n') {
>> > + if (*buf == '\n') {
>> > buf[0] = '\\';
>> > buf[1] = 'n';
>> > buf += 2;
>>
>> What is this code for?
>
> The code is copying the task name from 'c' to 'buf' one character
> at a time. It is then 'post processing' the characters. Currently,
> the post processing is based on the value of c which is part of the
> source string (task->curr). However, it is possible for the source
> string to change during this copy (think exec).
Except that c is not "part of the source string". The code "c =
*name" (where name starts off pointing to the same place as p->comm) is
executed once and only once per time through the loop. Then it does "*buf =
c". Your change would protect not against a change in "name" (which is
possible), but against a change in "buf" while we're writing to it
(impossible, as long as I'm understanding the proc code correctly).
Not that there is no race here, but that doesn't fix it. What's needed is
either another strcpy or locking around p->comm as suggested by Andrew
Morton.
--Andrew Rodland < arodland@entermail.net > via GMANE
prev parent reply other threads:[~2004-07-02 1:26 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-07-01 22:05 [PATCH] task name handling in proc fs Mike Kravetz
2004-07-01 22:19 ` Andrew Morton
2004-07-01 22:42 ` Mike Kravetz
2004-07-01 23:03 ` Andrew Morton
2004-07-01 23:38 ` Mike Kravetz
2004-07-07 21:52 ` Mike Kravetz
2004-07-07 22:11 ` Andrew Morton
2004-07-07 23:35 ` Mike Kravetz
2004-07-08 2:32 ` Paul Jackson
2004-07-08 17:01 ` Mike Kravetz
2004-07-02 1:27 ` Andrew Rodland [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to='cc2dkn$e63$1@sea.gmane.org' \
--to=arodland@entermail.net \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox