diff options
| author | Tejun Heo <tj@kernel.org> | 2018-02-21 14:39:22 -0500 |
|---|---|---|
| committer | Tejun Heo <tj@kernel.org> | 2018-02-21 14:39:22 -0500 |
| commit | d1897c9538edafd4ae6bbd03cc075962ddde2c21 (patch) | |
| tree | 96b73265ed9e288fdcd2d153c3e045ef83ec916e | |
| parent | c53593e5cb693d59d9e8b64fb3a79436bf99c3b3 (diff) | |
cgroup: fix rule checking for threaded mode switching
A domain cgroup isn't allowed to be turned threaded if its subtree is
populated or domain controllers are enabled. cgroup_enable_threaded()
depended on cgroup_can_be_thread_root() test to enforce this rule. A
parent which has populated domain descendants or have domain
controllers enabled can't become a thread root, so the above rules are
enforced automatically.
However, for the root cgroup which can host mixed domain and threaded
children, cgroup_can_be_thread_root() doesn't check any of those
conditions and thus first level cgroups ends up escaping those rules.
This patch fixes the bug by adding explicit checks for those rules in
cgroup_enable_threaded().
Reported-by: Michael Kerrisk (man-pages) <mtk.manpages@gmail.com>
Signed-off-by: Tejun Heo <tj@kernel.org>
Fixes: 8cfd8147df67 ("cgroup: implement cgroup v2 thread support")
Cc: stable@vger.kernel.org # v4.14+
| -rw-r--r-- | kernel/cgroup/cgroup.c | 10 |
1 files changed, 10 insertions, 0 deletions
diff --git a/kernel/cgroup/cgroup.c b/kernel/cgroup/cgroup.c index 8cda3bc3ae22..4bfb2908ec15 100644 --- a/kernel/cgroup/cgroup.c +++ b/kernel/cgroup/cgroup.c | |||
| @@ -3183,6 +3183,16 @@ static int cgroup_enable_threaded(struct cgroup *cgrp) | |||
| 3183 | if (cgroup_is_threaded(cgrp)) | 3183 | if (cgroup_is_threaded(cgrp)) |
| 3184 | return 0; | 3184 | return 0; |
| 3185 | 3185 | ||
| 3186 | /* | ||
| 3187 | * If @cgroup is populated or has domain controllers enabled, it | ||
| 3188 | * can't be switched. While the below cgroup_can_be_thread_root() | ||
| 3189 | * test can catch the same conditions, that's only when @parent is | ||
| 3190 | * not mixable, so let's check it explicitly. | ||
| 3191 | */ | ||
| 3192 | if (cgroup_is_populated(cgrp) || | ||
| 3193 | cgrp->subtree_control & ~cgrp_dfl_threaded_ss_mask) | ||
| 3194 | return -EOPNOTSUPP; | ||
| 3195 | |||
| 3186 | /* we're joining the parent's domain, ensure its validity */ | 3196 | /* we're joining the parent's domain, ensure its validity */ |
| 3187 | if (!cgroup_is_valid_domain(dom_cgrp) || | 3197 | if (!cgroup_is_valid_domain(dom_cgrp) || |
| 3188 | !cgroup_can_be_thread_root(dom_cgrp)) | 3198 | !cgroup_can_be_thread_root(dom_cgrp)) |
