diff options
author | Tejun Heo <tj@kernel.org> | 2014-02-13 13:29:31 -0500 |
---|---|---|
committer | Tejun Heo <tj@kernel.org> | 2014-02-18 18:23:18 -0500 |
commit | 532de3fc72adc2a6525c4d53c07bf81e1732083d (patch) | |
tree | 72ee4b0fe873589f814939a3b4e60fedb1f9c6ef | |
parent | 1a11533fbd71792e8c5d36f6763fbce8df0d231d (diff) |
cgroup: update cgroup_enable_task_cg_lists() to grab siglock
Currently, there's nothing preventing cgroup_enable_task_cg_lists()
from missing set PF_EXITING and race against cgroup_exit(). Depending
on the timing, cgroup_exit() may finish with the task still linked on
css_set leading to list corruption. Fix it by grabbing siglock in
cgroup_enable_task_cg_lists() so that PF_EXITING is guaranteed to be
visible.
This whole on-demand cg_list optimization is extremely fragile and has
ample possibility to lead to bugs which can cause things like
once-a-year oops during boot. I'm wondering whether the better
approach would be just adding "cgroup_disable=all" handling which
disables the whole cgroup rather than tempting fate with this
on-demand craziness.
Signed-off-by: Tejun Heo <tj@kernel.org>
Acked-by: Li Zefan <lizefan@huawei.com>
Cc: stable@vger.kernel.org
-rw-r--r-- | kernel/cgroup.c | 5 |
1 files changed, 5 insertions, 0 deletions
diff --git a/kernel/cgroup.c b/kernel/cgroup.c index 68d87103b493..105f273b6f86 100644 --- a/kernel/cgroup.c +++ b/kernel/cgroup.c | |||
@@ -2905,9 +2905,14 @@ static void cgroup_enable_task_cg_lists(void) | |||
2905 | * We should check if the process is exiting, otherwise | 2905 | * We should check if the process is exiting, otherwise |
2906 | * it will race with cgroup_exit() in that the list | 2906 | * it will race with cgroup_exit() in that the list |
2907 | * entry won't be deleted though the process has exited. | 2907 | * entry won't be deleted though the process has exited. |
2908 | * Do it while holding siglock so that we don't end up | ||
2909 | * racing against cgroup_exit(). | ||
2908 | */ | 2910 | */ |
2911 | spin_lock_irq(&p->sighand->siglock); | ||
2909 | if (!(p->flags & PF_EXITING) && list_empty(&p->cg_list)) | 2912 | if (!(p->flags & PF_EXITING) && list_empty(&p->cg_list)) |
2910 | list_add(&p->cg_list, &task_css_set(p)->tasks); | 2913 | list_add(&p->cg_list, &task_css_set(p)->tasks); |
2914 | spin_unlock_irq(&p->sighand->siglock); | ||
2915 | |||
2911 | task_unlock(p); | 2916 | task_unlock(p); |
2912 | } while_each_thread(g, p); | 2917 | } while_each_thread(g, p); |
2913 | read_unlock(&tasklist_lock); | 2918 | read_unlock(&tasklist_lock); |