Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1684061
| From | ebiederm@xmission.com (Eric W. Biederman) |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [PATCH 1/3] ipc: convert ipc_namespace.count from atomic_t to refcount_t |
| Date | 2017-07-10 10:50 +0200 |
| Message-ID | <u1Cye-2Hm-17@gated-at.bofh.it> (permalink) |
| References | <u0xqX-1Re-15@gated-at.bofh.it> <u0xqX-1Re-23@gated-at.bofh.it> <u1syR-4Xb-5@gated-at.bofh.it> <u1AG5-1v9-7@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
"Reshetova, Elena" <elena.reshetova@intel.com> writes: 2>> Elena Reshetova <elena.reshetova@intel.com> writes: >> >> > refcount_t type and corresponding API should be >> > used instead of atomic_t when the variable is used as >> > a reference counter. This allows to avoid accidental >> > refcounter overflows that might lead to use-after-free >> > situations. >> >> In this patch you can see all of the uses of the count. >> What accidental refcount overflows are possible? > > Even if one can guarantee and prove that in the current implementation > there are no overflows possible, we can't say that for > sure for any future implementation. Bugs might always happen > unfortunately, but if we convert the refcounter to a safer > type we can be sure that overflows are not possible. > > Does it make sense to you? Not for code that is likely to remain unchanged for a decade no. This looks like a large set of unautomated changes without any real thought put into it. That almost always results in a typo somewhere that breaks things. So there is no benefit to the code, and a non-zero chance that there will be a typo breaking the code. All to harden the code for an unlikely future when the code is updated with a full test cycle and people paying attention. Introduce a bug now to avoid a bug in the future. That seems like a very poor engineering trade off. Eric
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH 0/3] v2 ipc subsystem refcount coversions Elena Reshetova <elena.reshetova@intel.com> - 2017-07-07 11:10 +0200
[PATCH 1/3] ipc: convert ipc_namespace.count from atomic_t to refcount_t Elena Reshetova <elena.reshetova@intel.com> - 2017-07-07 11:10 +0200
Re: [PATCH 1/3] ipc: convert ipc_namespace.count from atomic_t to refcount_t ebiederm@xmission.com (Eric W. Biederman) - 2017-07-10 00:10 +0200
RE: [PATCH 1/3] ipc: convert ipc_namespace.count from atomic_t to refcount_t "Reshetova, Elena" <elena.reshetova@intel.com> - 2017-07-10 08:50 +0200
Re: [PATCH 1/3] ipc: convert ipc_namespace.count from atomic_t to refcount_t ebiederm@xmission.com (Eric W. Biederman) - 2017-07-10 10:50 +0200
Re: [PATCH 1/3] ipc: convert ipc_namespace.count from atomic_t to refcount_t Alexey Dobriyan <adobriyan@gmail.com> - 2017-07-10 11:40 +0200
Re: [PATCH 1/3] ipc: convert ipc_namespace.count from atomic_t to refcount_t ebiederm@xmission.com (Eric W. Biederman) - 2017-07-10 13:30 +0200
RE: [PATCH 1/3] ipc: convert ipc_namespace.count from atomic_t to refcount_t "Reshetova, Elena" <elena.reshetova@intel.com> - 2017-07-10 12:00 +0200
Re: [PATCH 1/3] ipc: convert ipc_namespace.count from atomic_t to refcount_t ebiederm@xmission.com (Eric W. Biederman) - 2017-07-10 13:40 +0200
RE: [PATCH 1/3] ipc: convert ipc_namespace.count from atomic_t to refcount_t "Reshetova, Elena" <elena.reshetova@intel.com> - 2017-07-10 14:20 +0200
Re: [PATCH 1/3] ipc: convert ipc_namespace.count from atomic_t to refcount_t ebiederm@xmission.com (Eric W. Biederman) - 2017-07-10 22:50 +0200
RE: [PATCH 1/3] ipc: convert ipc_namespace.count from atomic_t to refcount_t "Reshetova, Elena" <elena.reshetova@intel.com> - 2017-07-12 11:30 +0200
[PATCH 2/3] ipc: convert sem_undo_list.refcnt from atomic_t to refcount_t Elena Reshetova <elena.reshetova@intel.com> - 2017-07-07 11:10 +0200
[PATCH 3/3] ipc: convert kern_ipc_perm.refcount from atomic_t to refcount_t Elena Reshetova <elena.reshetova@intel.com> - 2017-07-07 11:10 +0200
csiph-web