Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1630827 > unrolled thread

SIGNAL_UNKILLABLE and init again

Started byJamie Iles <jamie.iles@oracle.com>
First post2017-04-25 19:40 +0200
Last post2017-04-27 14:20 +0200
Articles 3 — 2 participants

Back to article view | Back to linux.kernel


Contents

  SIGNAL_UNKILLABLE and init again Jamie Iles <jamie.iles@oracle.com> - 2017-04-25 19:40 +0200
    Re: SIGNAL_UNKILLABLE and init again Oleg Nesterov <oleg@redhat.com> - 2017-04-26 17:30 +0200
      Re: SIGNAL_UNKILLABLE and init again Jamie Iles <jamie.iles@oracle.com> - 2017-04-27 14:20 +0200

#1630827 — SIGNAL_UNKILLABLE and init again

FromJamie Iles <jamie.iles@oracle.com>
Date2017-04-25 19:40 +0200
SubjectSIGNAL_UNKILLABLE and init again
Message-ID<tAcBs-7Ga-25@gated-at.bofh.it>
Hi Oleg,

I'm back looking at SIGNAL_UNKILLABLE and debugging child reapers again, 
and the current issue is when running code in the target process, 
SIGTRAP firing and that causing SIGNAL_UNKILLABLE protection to be 
removed in force_sig_info():

	if (action->sa.sa_handler == SIG_DFL)
		t->signal->flags &= ~SIGNAL_UNKILLABLE;

Would relaxing that if the task is being traced with something like

  diff --git i/kernel/signal.c w/kernel/signal.c
  index 7e59ebc2c25e..f701f1889895 100644
  --- i/kernel/signal.c
  +++ w/kernel/signal.c
  @@ -1185,7 +1185,7 @@ force_sig_info(int sig, struct siginfo *info, struct task_struct *t)
   			recalc_sigpending_and_wake(t);
   		}
   	}
  -	if (action->sa.sa_handler == SIG_DFL)
  +	if (action->sa.sa_handler == SIG_DFL && !t->ptrace)
   		t->signal->flags &= ~SIGNAL_UNKILLABLE;
   	ret = specific_send_sig_info(sig, info, t);
   	spin_unlock_irqrestore(&t->sighand->siglock, flags);

make any sense?  It does address the issue that I'm seeing, but are 
there any downsides to doing so?

Thanks,

Jamie

[toc] | [next] | [standalone]


#1631512

FromOleg Nesterov <oleg@redhat.com>
Date2017-04-26 17:30 +0200
Message-ID<tAx3b-46S-1@gated-at.bofh.it>
In reply to#1630827
Hi Jamie,

On 04/25, Jamie Iles wrote:
>
> Hi Oleg,
>
> I'm back looking at SIGNAL_UNKILLABLE and debugging child reapers again, 
> and the current issue is when running code in the target process, 
> SIGTRAP firing and that causing SIGNAL_UNKILLABLE protection to be 
> removed in force_sig_info():
>
> 	if (action->sa.sa_handler == SIG_DFL)
> 		t->signal->flags &= ~SIGNAL_UNKILLABLE;

Yes, this is what I meant when I said force_sig_info() needs changes too.
I was going to fix it "tomorrow" but I was distracted and then forgot.

>   @@ -1185,7 +1185,7 @@ force_sig_info(int sig, struct siginfo *info, struct task_struct *t)
>    			recalc_sigpending_and_wake(t);
>    		}
>    	}
>   -	if (action->sa.sa_handler == SIG_DFL)
>   +	if (action->sa.sa_handler == SIG_DFL && !t->ptrace)
>    		t->signal->flags &= ~SIGNAL_UNKILLABLE;
>    	ret = specific_send_sig_info(sig, info, t);
>    	spin_unlock_irqrestore(&t->sighand->siglock, flags);

Not sure, let me think a bit more... and this is not enough anyway.

perhaps we should start with this simple change, but the "real" fix
needs a lot of cleanups, although I am not sure if we will ever do this.

Oleg.

[toc] | [prev] | [next] | [standalone]


#1632065

FromJamie Iles <jamie.iles@oracle.com>
Date2017-04-27 14:20 +0200
Message-ID<tAQyR-tm-9@gated-at.bofh.it>
In reply to#1631512
On Wed, Apr 26, 2017 at 05:18:58PM +0200, Oleg Nesterov wrote:
> Hi Jamie,
> 
> On 04/25, Jamie Iles wrote:
> >
> > Hi Oleg,
> >
> > I'm back looking at SIGNAL_UNKILLABLE and debugging child reapers again, 
> > and the current issue is when running code in the target process, 
> > SIGTRAP firing and that causing SIGNAL_UNKILLABLE protection to be 
> > removed in force_sig_info():
> >
> > 	if (action->sa.sa_handler == SIG_DFL)
> > 		t->signal->flags &= ~SIGNAL_UNKILLABLE;
> 
> Yes, this is what I meant when I said force_sig_info() needs changes too.
> I was going to fix it "tomorrow" but I was distracted and then forgot.
> 
> >   @@ -1185,7 +1185,7 @@ force_sig_info(int sig, struct siginfo *info, struct task_struct *t)
> >    			recalc_sigpending_and_wake(t);
> >    		}
> >    	}
> >   -	if (action->sa.sa_handler == SIG_DFL)
> >   +	if (action->sa.sa_handler == SIG_DFL && !t->ptrace)
> >    		t->signal->flags &= ~SIGNAL_UNKILLABLE;
> >    	ret = specific_send_sig_info(sig, info, t);
> >    	spin_unlock_irqrestore(&t->sighand->siglock, flags);
> 
> Not sure, let me think a bit more... and this is not enough anyway.
> 
> perhaps we should start with this simple change, but the "real" fix
> needs a lot of cleanups, although I am not sure if we will ever do this.

Okay, sounds good.  I'm happy to spend more time looking at this if you 
have suggestions - in the context of namespaces and containers this 
seems more relevant than when it was just the system init that we were 
protecting.

Jamie

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web