Re: [PATCH] wait_for_helper: SIGCHLD from user-space can lead touse-after-free

From: Roland McGrath
Date: Wed Mar 10 2010 - 15:32:37 EST


SIGCHLD being blocked doesn't affect reaping, so SIG_IGN or sa_flags &
SA_NOCLDWAIT is the only thing that would do this. How does that come
about here in this kthread? Is it inherited from the instigating user
process? If so, then SA_NOCLDWAIT is as much a problem as SIG_IGN.
Or I guess maybe it's from ignore_signals() in kthreadd()?
In that case SIG_IGN is indeed all that matters. (I don't really
know all the kthread/kmod/userhelper code organization.)

Perhaps it would be cleaner to do:

flush_signal_handlers(current, 1);

in wait_for_helper. That should make it redundant in ____call_usermodehelper,
so it could be removed from there.


Thanks,
Roland
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/