Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1194682 > unrolled thread

Re: [PATCH] user_ns: use correct check for single-threadedness

Started byAndrew Morton <akpm@linux-foundation.org>
First post2015-07-28 23:40 +0200
Last post2015-07-29 00:00 +0200
Articles 2 — 2 participants

Back to article view | Back to linux.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Re: [PATCH] user_ns: use correct check for single-threadedness Andrew Morton <akpm@linux-foundation.org> - 2015-07-28 23:40 +0200
    Re: [PATCH] user_ns: use correct check for single-threadedness Kees Cook <keescook@chromium.org> - 2015-07-29 00:00 +0200

#1194682 — Re: [PATCH] user_ns: use correct check for single-threadedness

FromAndrew Morton <akpm@linux-foundation.org>
Date2015-07-28 23:40 +0200
SubjectRe: [PATCH] user_ns: use correct check for single-threadedness
Message-ID<pRkLn-4Fc-1@gated-at.bofh.it>
On Tue, 28 Jul 2015 10:15:00 -0700 Kees Cook <keescook@chromium.org> wrote:

> From: Ricky Zhou <rickyz@chromium.org>
> 
> Checking mm_users > 1 does not mean a process is multithreaded. For
> example, reading /proc/PID/maps temporarily increments mm_users, allowing
> other processes to (accidentally) interfere with unshare() calls.
> 
> This fixes observed failures of unshare(CLONE_NEWUSER) incorrectly
> returning EINVAL if another processes happened to be simultaneously
> reading the maps file.

Yikes.  current_is_single_threaded() is expensive.  Are we sure this
isn't going to kill someone's workload?

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [next] | [standalone]


#1194702

FromKees Cook <keescook@chromium.org>
Date2015-07-29 00:00 +0200
Message-ID<pRl4K-51M-5@gated-at.bofh.it>
In reply to#1194682
On Tue, Jul 28, 2015 at 2:35 PM, Andrew Morton
<akpm@linux-foundation.org> wrote:
> On Tue, 28 Jul 2015 10:15:00 -0700 Kees Cook <keescook@chromium.org> wrote:
>
>> From: Ricky Zhou <rickyz@chromium.org>
>>
>> Checking mm_users > 1 does not mean a process is multithreaded. For
>> example, reading /proc/PID/maps temporarily increments mm_users, allowing
>> other processes to (accidentally) interfere with unshare() calls.
>>
>> This fixes observed failures of unshare(CLONE_NEWUSER) incorrectly
>> returning EINVAL if another processes happened to be simultaneously
>> reading the maps file.
>
> Yikes.  current_is_single_threaded() is expensive.  Are we sure this
> isn't going to kill someone's workload?

It _can_ be expensive, but if mm->mm_users == 1 it immediately returns
true, so it's only the cases where there is a race (like what's solved
here), or when it's a legit failure. This doesn't feel to me like it
should hit a real user very hard, since "real" callers of unshare will
normally have mm_users == 1.

-Kees

-- 
Kees Cook
Chrome OS Security
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web