mirror of
				https://github.com/torvalds/linux.git
				synced 2025-11-04 10:40:15 +02:00 
			
		
		
		
	ptrace_detach: the wrong wakeup breaks the ERESTARTxxx logic
Another ancient bug. Consider this trivial test-case,
	int main(void)
	{
		int pid = fork();
		if (pid) {
			ptrace(PTRACE_ATTACH, pid, NULL, NULL);
			wait(NULL);
			ptrace(PTRACE_DETACH, pid, NULL, NULL);
		} else {
			pause();
			printf("WE HAVE A KERNEL BUG!!!\n");
		}
		return 0;
	}
the child must not "escape" for sys_pause(), but it can and this was seen
in practice.
This is because ptrace_detach does:
	if (!child->exit_state)
		wake_up_process(child);
this wakeup can happen after this child has already restarted sys_pause(),
because it gets another wakeup from ptrace_untrace().
With or without this patch, perhaps sys_pause() needs a fix.  But this
wakeup also breaks the SIGNAL_STOP_STOPPED logic in ptrace_untrace().
Remove this wakeup.  The caller saw this task in TASK_TRACED state, and
unless it was SIGKILL'ed in between __ptrace_unlink()->ptrace_untrace()
should handle this case correctly.  If it was SIGKILL'ed, we don't need to
wakup the dying tracee too.
Signed-off-by: Oleg Nesterov <oleg@redhat.com>
Cc: Jerome Marchand <jmarchan@redhat.com>
Acked-by: Roland McGrath <roland@redhat.com>
Cc: Denys Vlasenko <dvlasenk@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
			
			
This commit is contained in:
		
							parent
							
								
									bb24c679a5
								
							
						
					
					
						commit
						95a3540da9
					
				
					 1 changed files with 0 additions and 4 deletions
				
			
		| 
						 | 
					@ -301,11 +301,7 @@ int ptrace_detach(struct task_struct *child, unsigned int data)
 | 
				
			||||||
	 */
 | 
						 */
 | 
				
			||||||
	if (child->ptrace) {
 | 
						if (child->ptrace) {
 | 
				
			||||||
		child->exit_code = data;
 | 
							child->exit_code = data;
 | 
				
			||||||
 | 
					 | 
				
			||||||
		dead = __ptrace_detach(current, child);
 | 
							dead = __ptrace_detach(current, child);
 | 
				
			||||||
 | 
					 | 
				
			||||||
		if (!child->exit_state)
 | 
					 | 
				
			||||||
			wake_up_process(child);
 | 
					 | 
				
			||||||
	}
 | 
						}
 | 
				
			||||||
	write_unlock_irq(&tasklist_lock);
 | 
						write_unlock_irq(&tasklist_lock);
 | 
				
			||||||
 | 
					
 | 
				
			||||||
| 
						 | 
					
 | 
				
			||||||
		Loading…
	
		Reference in a new issue