diff options
Diffstat (limited to 'kernel/ptrace.c')
| -rw-r--r-- | kernel/ptrace.c | 74 |
1 files changed, 59 insertions, 15 deletions
diff --git a/kernel/ptrace.c b/kernel/ptrace.c index 1599157336a6..6cbeaae4406d 100644 --- a/kernel/ptrace.c +++ b/kernel/ptrace.c | |||
| @@ -117,11 +117,45 @@ void __ptrace_unlink(struct task_struct *child) | |||
| 117 | * TASK_KILLABLE sleeps. | 117 | * TASK_KILLABLE sleeps. |
| 118 | */ | 118 | */ |
| 119 | if (child->jobctl & JOBCTL_STOP_PENDING || task_is_traced(child)) | 119 | if (child->jobctl & JOBCTL_STOP_PENDING || task_is_traced(child)) |
| 120 | signal_wake_up(child, task_is_traced(child)); | 120 | ptrace_signal_wake_up(child, true); |
| 121 | 121 | ||
| 122 | spin_unlock(&child->sighand->siglock); | 122 | spin_unlock(&child->sighand->siglock); |
| 123 | } | 123 | } |
| 124 | 124 | ||
| 125 | /* Ensure that nothing can wake it up, even SIGKILL */ | ||
| 126 | static bool ptrace_freeze_traced(struct task_struct *task) | ||
| 127 | { | ||
| 128 | bool ret = false; | ||
| 129 | |||
| 130 | /* Lockless, nobody but us can set this flag */ | ||
| 131 | if (task->jobctl & JOBCTL_LISTENING) | ||
| 132 | return ret; | ||
| 133 | |||
| 134 | spin_lock_irq(&task->sighand->siglock); | ||
| 135 | if (task_is_traced(task) && !__fatal_signal_pending(task)) { | ||
| 136 | task->state = __TASK_TRACED; | ||
| 137 | ret = true; | ||
| 138 | } | ||
| 139 | spin_unlock_irq(&task->sighand->siglock); | ||
| 140 | |||
| 141 | return ret; | ||
| 142 | } | ||
| 143 | |||
| 144 | static void ptrace_unfreeze_traced(struct task_struct *task) | ||
| 145 | { | ||
| 146 | if (task->state != __TASK_TRACED) | ||
| 147 | return; | ||
| 148 | |||
| 149 | WARN_ON(!task->ptrace || task->parent != current); | ||
| 150 | |||
| 151 | spin_lock_irq(&task->sighand->siglock); | ||
| 152 | if (__fatal_signal_pending(task)) | ||
| 153 | wake_up_state(task, __TASK_TRACED); | ||
| 154 | else | ||
| 155 | task->state = TASK_TRACED; | ||
| 156 | spin_unlock_irq(&task->sighand->siglock); | ||
| 157 | } | ||
| 158 | |||
| 125 | /** | 159 | /** |
| 126 | * ptrace_check_attach - check whether ptracee is ready for ptrace operation | 160 | * ptrace_check_attach - check whether ptracee is ready for ptrace operation |
| 127 | * @child: ptracee to check for | 161 | * @child: ptracee to check for |
| @@ -139,7 +173,7 @@ void __ptrace_unlink(struct task_struct *child) | |||
| 139 | * RETURNS: | 173 | * RETURNS: |
| 140 | * 0 on success, -ESRCH if %child is not ready. | 174 | * 0 on success, -ESRCH if %child is not ready. |
| 141 | */ | 175 | */ |
| 142 | int ptrace_check_attach(struct task_struct *child, bool ignore_state) | 176 | static int ptrace_check_attach(struct task_struct *child, bool ignore_state) |
| 143 | { | 177 | { |
| 144 | int ret = -ESRCH; | 178 | int ret = -ESRCH; |
| 145 | 179 | ||
| @@ -151,24 +185,29 @@ int ptrace_check_attach(struct task_struct *child, bool ignore_state) | |||
| 151 | * be changed by us so it's not changing right after this. | 185 | * be changed by us so it's not changing right after this. |
| 152 | */ | 186 | */ |
| 153 | read_lock(&tasklist_lock); | 187 | read_lock(&tasklist_lock); |
| 154 | if ((child->ptrace & PT_PTRACED) && child->parent == current) { | 188 | if (child->ptrace && child->parent == current) { |
| 189 | WARN_ON(child->state == __TASK_TRACED); | ||
| 155 | /* | 190 | /* |
| 156 | * child->sighand can't be NULL, release_task() | 191 | * child->sighand can't be NULL, release_task() |
| 157 | * does ptrace_unlink() before __exit_signal(). | 192 | * does ptrace_unlink() before __exit_signal(). |
| 158 | */ | 193 | */ |
| 159 | spin_lock_irq(&child->sighand->siglock); | 194 | if (ignore_state || ptrace_freeze_traced(child)) |
| 160 | WARN_ON_ONCE(task_is_stopped(child)); | ||
| 161 | if (ignore_state || (task_is_traced(child) && | ||
| 162 | !(child->jobctl & JOBCTL_LISTENING))) | ||
| 163 | ret = 0; | 195 | ret = 0; |
| 164 | spin_unlock_irq(&child->sighand->siglock); | ||
| 165 | } | 196 | } |
| 166 | read_unlock(&tasklist_lock); | 197 | read_unlock(&tasklist_lock); |
| 167 | 198 | ||
| 168 | if (!ret && !ignore_state) | 199 | if (!ret && !ignore_state) { |
| 169 | ret = wait_task_inactive(child, TASK_TRACED) ? 0 : -ESRCH; | 200 | if (!wait_task_inactive(child, __TASK_TRACED)) { |
| 201 | /* | ||
| 202 | * This can only happen if may_ptrace_stop() fails and | ||
| 203 | * ptrace_stop() changes ->state back to TASK_RUNNING, | ||
| 204 | * so we should not worry about leaking __TASK_TRACED. | ||
| 205 | */ | ||
| 206 | WARN_ON(child->state == __TASK_TRACED); | ||
| 207 | ret = -ESRCH; | ||
| 208 | } | ||
| 209 | } | ||
| 170 | 210 | ||
| 171 | /* All systems go.. */ | ||
| 172 | return ret; | 211 | return ret; |
| 173 | } | 212 | } |
| 174 | 213 | ||
| @@ -317,7 +356,7 @@ static int ptrace_attach(struct task_struct *task, long request, | |||
| 317 | */ | 356 | */ |
| 318 | if (task_is_stopped(task) && | 357 | if (task_is_stopped(task) && |
| 319 | task_set_jobctl_pending(task, JOBCTL_TRAP_STOP | JOBCTL_TRAPPING)) | 358 | task_set_jobctl_pending(task, JOBCTL_TRAP_STOP | JOBCTL_TRAPPING)) |
| 320 | signal_wake_up(task, 1); | 359 | signal_wake_up_state(task, __TASK_STOPPED); |
| 321 | 360 | ||
| 322 | spin_unlock(&task->sighand->siglock); | 361 | spin_unlock(&task->sighand->siglock); |
| 323 | 362 | ||
| @@ -737,7 +776,7 @@ int ptrace_request(struct task_struct *child, long request, | |||
| 737 | * tracee into STOP. | 776 | * tracee into STOP. |
| 738 | */ | 777 | */ |
| 739 | if (likely(task_set_jobctl_pending(child, JOBCTL_TRAP_STOP))) | 778 | if (likely(task_set_jobctl_pending(child, JOBCTL_TRAP_STOP))) |
| 740 | signal_wake_up(child, child->jobctl & JOBCTL_LISTENING); | 779 | ptrace_signal_wake_up(child, child->jobctl & JOBCTL_LISTENING); |
| 741 | 780 | ||
| 742 | unlock_task_sighand(child, &flags); | 781 | unlock_task_sighand(child, &flags); |
| 743 | ret = 0; | 782 | ret = 0; |
| @@ -763,7 +802,7 @@ int ptrace_request(struct task_struct *child, long request, | |||
| 763 | * start of this trap and now. Trigger re-trap. | 802 | * start of this trap and now. Trigger re-trap. |
| 764 | */ | 803 | */ |
| 765 | if (child->jobctl & JOBCTL_TRAP_NOTIFY) | 804 | if (child->jobctl & JOBCTL_TRAP_NOTIFY) |
| 766 | signal_wake_up(child, true); | 805 | ptrace_signal_wake_up(child, true); |
| 767 | ret = 0; | 806 | ret = 0; |
| 768 | } | 807 | } |
| 769 | unlock_task_sighand(child, &flags); | 808 | unlock_task_sighand(child, &flags); |
| @@ -900,6 +939,8 @@ SYSCALL_DEFINE4(ptrace, long, request, long, pid, unsigned long, addr, | |||
| 900 | goto out_put_task_struct; | 939 | goto out_put_task_struct; |
| 901 | 940 | ||
| 902 | ret = arch_ptrace(child, request, addr, data); | 941 | ret = arch_ptrace(child, request, addr, data); |
| 942 | if (ret || request != PTRACE_DETACH) | ||
| 943 | ptrace_unfreeze_traced(child); | ||
| 903 | 944 | ||
| 904 | out_put_task_struct: | 945 | out_put_task_struct: |
| 905 | put_task_struct(child); | 946 | put_task_struct(child); |
| @@ -1039,8 +1080,11 @@ asmlinkage long compat_sys_ptrace(compat_long_t request, compat_long_t pid, | |||
| 1039 | 1080 | ||
| 1040 | ret = ptrace_check_attach(child, request == PTRACE_KILL || | 1081 | ret = ptrace_check_attach(child, request == PTRACE_KILL || |
| 1041 | request == PTRACE_INTERRUPT); | 1082 | request == PTRACE_INTERRUPT); |
| 1042 | if (!ret) | 1083 | if (!ret) { |
| 1043 | ret = compat_arch_ptrace(child, request, addr, data); | 1084 | ret = compat_arch_ptrace(child, request, addr, data); |
| 1085 | if (ret || request != PTRACE_DETACH) | ||
| 1086 | ptrace_unfreeze_traced(child); | ||
| 1087 | } | ||
| 1044 | 1088 | ||
| 1045 | out_put_task_struct: | 1089 | out_put_task_struct: |
| 1046 | put_task_struct(child); | 1090 | put_task_struct(child); |
