Skip to content

Commit

Permalink
reparent_thread: fix a zombie leak if /sbin/init ignores SIGCHLD
Browse files Browse the repository at this point in the history
If /sbin/init ignores SIGCHLD and we re-parent a zombie, it is leaked.
reparent_thread() does do_notify_parent() which sets ->exit_signal = -1 in
this case.  This means that nobody except us can reap it, the detached
task is not visible to do_wait().

Change reparent_thread() to return a boolean (like __pthread_detach) to
indicate that the thread is dead and must be released.  Also change
forget_original_parent() to add the child to ptrace_dead list in this
case.

The naming becomes insane, the next patch does the cleanup.

Signed-off-by: Oleg Nesterov <oleg@redhat.com>
Cc: Roland McGrath <roland@redhat.com>
Cc: "Eric W. Biederman" <ebiederm@xmission.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
  • Loading branch information
oleg-nesterov authored and torvalds committed Apr 3, 2009
1 parent b1442b0 commit 7f5d365
Showing 1 changed file with 17 additions and 5 deletions.
22 changes: 17 additions & 5 deletions kernel/exit.c
Original file line number Diff line number Diff line change
Expand Up @@ -810,33 +810,44 @@ static void ptrace_exit_finish(struct task_struct *parent,
}
}

static void reparent_thread(struct task_struct *p, struct task_struct *father)
/* Returns nonzero if the child should be released. */
static int reparent_thread(struct task_struct *p, struct task_struct *father)
{
int dead;

if (p->pdeath_signal)
/* We already hold the tasklist_lock here. */
group_send_sig_info(p->pdeath_signal, SEND_SIG_NOINFO, p);

list_move_tail(&p->sibling, &p->real_parent->children);

if (task_detached(p))
return;
return 0;
/* If this is a threaded reparent there is no need to
* notify anyone anything has happened.
*/
if (same_thread_group(p->real_parent, father))
return;
return 0;

/* We don't want people slaying init. */
p->exit_signal = SIGCHLD;

/* If we'd notified the old parent about this child's death,
* also notify the new parent.
*/
dead = 0;
if (!p->ptrace &&
p->exit_state == EXIT_ZOMBIE && thread_group_empty(p))
p->exit_state == EXIT_ZOMBIE && thread_group_empty(p)) {
do_notify_parent(p, p->exit_signal);
if (task_detached(p)) {
p->exit_state = EXIT_DEAD;
dead = 1;
}
}

kill_orphaned_pgrp(p, father);

return dead;
}

/*
Expand Down Expand Up @@ -896,7 +907,8 @@ static void forget_original_parent(struct task_struct *father)
BUG_ON(p->ptrace);
p->parent = p->real_parent;
}
reparent_thread(p, father);
if (reparent_thread(p, father))
list_add(&p->ptrace_entry, &ptrace_dead);;
}

write_unlock_irq(&tasklist_lock);
Expand Down

0 comments on commit 7f5d365

Please sign in to comment.