From: Oleg Nesterov On 09/07, Oleg Nesterov wrote: > > On 09/06, Jean Delvare wrote: > > > > On Wednesday 6 September 2006 11:01, Jean Delvare wrote: > > > Eric, Kame, thanks a lot for working on this. I'll be giving some good > > > testing to this patch today, and will return back to you when I'm done. > > > > The original issue is indeed fixed, but there's a problem with the patch. > > When stressing /proc (to verify the bug was fixed), my test machine ended > > up crashing. Here are the 2 traces I found in the logs: > > > > Sep 6 12:06:00 arrakis kernel: BUG: warning at > > kernel/fork.c:113/__put_task_struct() > > Sep 6 12:06:00 arrakis kernel: [] __put_task_struct+0xf3/0x100 > > Sep 6 12:06:00 arrakis kernel: [] proc_pid_readdir+0x13a/0x150 > > Sep 6 12:06:00 arrakis kernel: [] vfs_readdir+0x80/0xa0 > > Sep 6 12:06:00 arrakis kernel: [] filldir+0x0/0xd0 > > Sep 6 12:06:00 arrakis kernel: [] sys_getdents+0x6c/0xb0 > > Sep 6 12:06:00 arrakis kernel: [] filldir+0x0/0xd0 > > Sep 6 12:06:00 arrakis kernel: [] syscall_call+0x7/0xb > > If the task found is not a group leader, we go to retry, but > the task != NULL. > > Now, if find_ge_pid(tgid) returns NULL, we return that wrong > task, and it was not get_task_struct()'ed. Signed-off-by: Oleg Nesterov Cc: Jean Delvare Cc: "Eric W. Biederman" Signed-off-by: Andrew Morton --- fs/proc/base.c | 2 +- 1 files changed, 1 insertion(+), 1 deletion(-) diff -puN fs/proc/base.c~proc-readdir-race-fix-take-3-race-fix fs/proc/base.c --- a/fs/proc/base.c~proc-readdir-race-fix-take-3-race-fix +++ a/fs/proc/base.c @@ -2150,9 +2150,9 @@ static struct task_struct *next_tgid(uns struct task_struct *task; struct pid *pid; - task = NULL; rcu_read_lock(); retry: + task = NULL; pid = find_ge_pid(tgid); if (pid) { tgid = pid->nr + 1; _