提交 8f17fc20 编写于 作者: O Oleg Nesterov 提交者: Linus Torvalds

[PATCH] check_process_timers: fix possible lockup

If the local timer interrupt happens just after do_exit() sets PF_EXITING
(and before it clears ->it_xxx_expires) run_posix_cpu_timers() will call
check_process_timers() with tasklist_lock + ->siglock held and

	check_process_timers:

		t = tsk;
		do {
			....

			do {
				t = next_thread(t);
			} while (unlikely(t->flags & PF_EXITING));
		} while (t != tsk);

the outer loop will never stop.

Actually, the window is bigger.  Another process can attach the timer
after ->it_xxx_expires was cleared (see the next commit) and the 'if
(PF_EXITING)' check in arm_timer() is racy (see the one after that).
Signed-off-by: NOleg Nesterov <oleg@tv-sign.ru>
Signed-off-by: NLinus Torvalds <torvalds@osdl.org>
上级 88d11360
...@@ -1173,6 +1173,9 @@ static void check_process_timers(struct task_struct *tsk, ...@@ -1173,6 +1173,9 @@ static void check_process_timers(struct task_struct *tsk,
} }
t = tsk; t = tsk;
do { do {
if (unlikely(t->flags & PF_EXITING))
continue;
ticks = cputime_add(cputime_add(t->utime, t->stime), ticks = cputime_add(cputime_add(t->utime, t->stime),
prof_left); prof_left);
if (!cputime_eq(prof_expires, cputime_zero) && if (!cputime_eq(prof_expires, cputime_zero) &&
...@@ -1193,11 +1196,7 @@ static void check_process_timers(struct task_struct *tsk, ...@@ -1193,11 +1196,7 @@ static void check_process_timers(struct task_struct *tsk,
t->it_sched_expires > sched)) { t->it_sched_expires > sched)) {
t->it_sched_expires = sched; t->it_sched_expires = sched;
} }
} while ((t = next_thread(t)) != tsk);
do {
t = next_thread(t);
} while (unlikely(t->flags & PF_EXITING));
} while (t != tsk);
} }
} }
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册