Re: [PATCH] signal: Use list_del_init_careful() in flush_sigqueue()
From: Oleg Nesterov
Date: Mon Aug 24 2026 - 10:29:29 EST
On 08/24, Frederic Weisbecker wrote:
>
> Le Mon, Aug 24, 2026 at 01:54:26PM +0200, Oleg Nesterov a écrit :
> >
> > diff --git a/fs/exec.c b/fs/exec.c
> > index a14f28b15607..550367e7fe6c 100644
> > --- a/fs/exec.c
> > +++ b/fs/exec.c
> > @@ -1029,6 +1029,9 @@ static int de_thread(struct task_struct *tsk)
> > write_unlock_irq(&tasklist_lock);
> > cgroup_threadgroup_change_end(tsk);
> >
> > + scoped_guard(spinlock_irq, lock)
> > + flush_sigqueue(&leader->pending);
> > +
>
> Is there something to prevent the timer from firing on another CPU,
> racing with this tiny window and queue the signal to the old leader? After
> all exchange_tids() is just some RCU pointers changed but there is nothing
> to synchronize the readers before the flush_sigqueue(). So pid_task() may
> still return the old leader after it?
Ah yes...
posixtimer_get_target() is obviously called before lock_task_sighand(),
so it can be called even before exchange_tids()...
Thanks!
Oleg.