<feed xmlns='http://www.w3.org/2005/Atom'>
<title>kernel.git/kernel/exit.c, branch linux-2.6.29.y</title>
<subtitle>Hosts the 0x221E linux distro kernel.
</subtitle>
<id>https://git.0xinfinity.dev/distro/kernel.git/atom?h=linux-2.6.29.y</id>
<link rel='self' href='https://git.0xinfinity.dev/distro/kernel.git/atom?h=linux-2.6.29.y'/>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/'/>
<updated>2009-06-15T16:40:19Z</updated>
<entry>
<title>ptrace: reintroduce __ptrace_detach() as a callee of ptrace_exit()</title>
<updated>2009-06-15T16:40:19Z</updated>
<author>
<name>Oleg Nesterov</name>
</author>
<published>2009-04-02T23:58:13Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=64cd4669da13c829635f0b668a6bd546ee472e01'/>
<id>urn:sha1:64cd4669da13c829635f0b668a6bd546ee472e01</id>
<content type='text'>
commit b1b4c6799fb59e710454bfe0ab477cb8523a8667 upstream.

No functional changes, preparation for the next patch.

Move the "should we release this child" logic into the separate handler,
__ptrace_detach().

Signed-off-by: Oleg Nesterov &lt;oleg@redhat.com&gt;
Cc: Jerome Marchand &lt;jmarchan@redhat.com&gt;
Cc: Roland McGrath &lt;roland@redhat.com&gt;
Cc: Denys Vlasenko &lt;dvlasenk@redhat.com&gt;
Signed-off-by: Andrew Morton &lt;akpm@linux-foundation.org&gt;
Signed-off-by: Linus Torvalds &lt;torvalds@linux-foundation.org&gt;
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@suse.de&gt;

</content>
</entry>
<entry>
<title>ptrace: simplify ptrace_exit()-&gt;ignoring_children() path</title>
<updated>2009-06-15T16:40:19Z</updated>
<author>
<name>Oleg Nesterov</name>
</author>
<published>2009-04-02T23:58:12Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=07325c8e8ed1eedb283941860cafb64fd60b46cd'/>
<id>urn:sha1:07325c8e8ed1eedb283941860cafb64fd60b46cd</id>
<content type='text'>
commit 6d69cb87f05eef3b02370b2f7bae608ad2301a00 upstream.

ignoring_children() takes parent-&gt;sighand-&gt;siglock and checks
k_sigaction[SIGCHLD] atomically.  But this buys nothing, we can't get the
"really" wrong result even if we race with sigaction(SIGCHLD).  If we read
the "stale" sa_handler/sa_flags we can pretend it was changed right after
the check.

Remove spin_lock(-&gt;siglock), and kill "int ign" which caches the result of
ignoring_children() which becomes rather trivial.

Perhaps it makes sense to export this helper, do_notify_parent() can use
it too.

Signed-off-by: Oleg Nesterov &lt;oleg@redhat.com&gt;
Cc: Jerome Marchand &lt;jmarchan@redhat.com&gt;
Cc: Roland McGrath &lt;roland@redhat.com&gt;
Cc: Denys Vlasenko &lt;dvlasenk@redhat.com&gt;
Signed-off-by: Andrew Morton &lt;akpm@linux-foundation.org&gt;
Signed-off-by: Linus Torvalds &lt;torvalds@linux-foundation.org&gt;
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@suse.de&gt;

</content>
</entry>
<entry>
<title>Take fs_struct handling to new file (fs/fs_struct.c)</title>
<updated>2009-05-08T22:45:07Z</updated>
<author>
<name>Al Viro</name>
</author>
<published>2009-03-29T23:00:13Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=83e8c55f17f8d55f755b8983e1192cf1e1f711cd'/>
<id>urn:sha1:83e8c55f17f8d55f755b8983e1192cf1e1f711cd</id>
<content type='text'>
commit 3e93cd671813e204c258f1e6c797959920cf7772 upstream.

Pure code move; two new helper functions for nfsd and daemonize
(unshare_fs_struct() and daemonize_fs_struct() resp.; for now -
the same code as used to be in callers).  unshare_fs_struct()
exported (for nfsd, as copy_fs_struct()/exit_fs() used to be),
copy_fs_struct() and exit_fs() don't need exports anymore.

Signed-off-by: Al Viro &lt;viro@zeniv.linux.org.uk&gt;
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@suse.de&gt;

</content>
</entry>
<entry>
<title>exit_notify: kill the wrong capable(CAP_KILL) check (CVE-2009-1337)</title>
<updated>2009-05-08T22:45:01Z</updated>
<author>
<name>Oleg Nesterov</name>
</author>
<published>2009-04-06T14:16:02Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=8b1b63e0d767f99a35e00f85014ad8778cd8c262'/>
<id>urn:sha1:8b1b63e0d767f99a35e00f85014ad8778cd8c262</id>
<content type='text'>
CVE-2009-1337

commit 432870dab85a2f69dc417022646cb9a70acf7f94 upstream.

The CAP_KILL check in exit_notify() looks just wrong, kill it.

Whatever logic we have to reset -&gt;exit_signal, the malicious user
can bypass it if it execs the setuid application before exiting.

Signed-off-by: Oleg Nesterov &lt;oleg@redhat.com&gt;
Acked-by: Serge Hallyn &lt;serue@us.ibm.com&gt;
Acked-by: Roland McGrath &lt;roland@redhat.com&gt;
Signed-off-by: Linus Torvalds &lt;torvalds@linux-foundation.org&gt;
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@suse.de&gt;

</content>
</entry>
<entry>
<title>signal: re-add dead task accumulation stats.</title>
<updated>2009-02-05T12:04:33Z</updated>
<author>
<name>Peter Zijlstra</name>
</author>
<published>2009-02-05T11:24:15Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=32bd671d6cbeda60dc73be77fa2b9037d9a9bfa0'/>
<id>urn:sha1:32bd671d6cbeda60dc73be77fa2b9037d9a9bfa0</id>
<content type='text'>
We're going to split the process wide cpu accounting into two parts:

 - clocks; which can take all the time they want since they run
           from user context.

 - timers; which need constant time tracing but can affort the overhead
           because they're default off -- and rare.

The clock readout will go back to a full sum of the thread group, for this
we need to re-add the exit stats that were removed in the initial itimer
rework (f06febc9: timers: fix itimer/many thread hang).

Furthermore, since that full sum can be rather slow for large thread groups
and we have the complete dead task stats, revert the do_notify_parent time
computation.

Signed-off-by: Peter Zijlstra &lt;a.p.zijlstra@chello.nl&gt;
Reviewed-by: Ingo Molnar &lt;mingo@elte.hu&gt;
Signed-off-by: Ingo Molnar &lt;mingo@elte.hu&gt;
</content>
</entry>
<entry>
<title>[CVE-2009-0029] System call wrappers part 08</title>
<updated>2009-01-14T13:15:21Z</updated>
<author>
<name>Heiko Carstens</name>
</author>
<published>2009-01-14T13:14:10Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=17da2bd90abf428523de0fb98f7075e00e3ed42e'/>
<id>urn:sha1:17da2bd90abf428523de0fb98f7075e00e3ed42e</id>
<content type='text'>
Signed-off-by: Heiko Carstens &lt;heiko.carstens@de.ibm.com&gt;
</content>
</entry>
<entry>
<title>[CVE-2009-0029] System call wrappers part 07</title>
<updated>2009-01-14T13:15:20Z</updated>
<author>
<name>Heiko Carstens</name>
</author>
<published>2009-01-14T13:14:09Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=754fe8d297bfae7b77f7ce866e2fb0c5fb186506'/>
<id>urn:sha1:754fe8d297bfae7b77f7ce866e2fb0c5fb186506</id>
<content type='text'>
Signed-off-by: Heiko Carstens &lt;heiko.carstens@de.ibm.com&gt;
</content>
</entry>
<entry>
<title>[CVE-2009-0029] Convert all system calls to return a long</title>
<updated>2009-01-14T13:15:14Z</updated>
<author>
<name>Heiko Carstens</name>
</author>
<published>2009-01-14T13:13:54Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=2ed7c03ec17779afb4fcfa3b8c61df61bd4879ba'/>
<id>urn:sha1:2ed7c03ec17779afb4fcfa3b8c61df61bd4879ba</id>
<content type='text'>
Convert all system calls to return a long. This should be a NOP since all
converted types should have the same size anyway.
With the exception of sys_exit_group which returned void. But that doesn't
matter since the system call doesn't return.

Signed-off-by: Heiko Carstens &lt;heiko.carstens@de.ibm.com&gt;
</content>
</entry>
<entry>
<title>mm: introduce get_mm_hiwater_xxx(), fix taskstats-&gt;hiwater_xxx accounting</title>
<updated>2009-01-06T23:59:09Z</updated>
<author>
<name>Oleg Nesterov</name>
</author>
<published>2009-01-06T22:40:29Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=901608d9045146aec6f14a7777ea4b1501c379f0'/>
<id>urn:sha1:901608d9045146aec6f14a7777ea4b1501c379f0</id>
<content type='text'>
xacct_add_tsk() relies on do_exit()-&gt;update_hiwater_xxx() and uses
mm-&gt;hiwater_xxx directly, this leads to 2 problems:

- taskstats_user_cmd() can call fill_pid()-&gt;xacct_add_tsk() at any
  moment before the task exits, so we should check the current values of
  rss/vm anyway.

- do_exit()-&gt;update_hiwater_xxx() calls are racy.  An exiting thread can
  be preempted right before mm-&gt;hiwater_xxx = new_val, and another thread
  can use A_LOT of memory and exit in between.  When the first thread
  resumes it can be the last thread in the thread group, in that case we
  report the wrong hiwater_xxx values which do not take A_LOT into
  account.

Introduce get_mm_hiwater_rss() and get_mm_hiwater_vm() helpers and change
xacct_add_tsk() to use them.  The first helper will also be used by
rusage-&gt;ru_maxrss accounting.

Kill do_exit()-&gt;update_hiwater_xxx() calls.  Unless we are going to
decrease rss/vm there is no point to update mm-&gt;hiwater_xxx, and nobody
can look at this mm_struct when exit_mmap() actually unmaps the memory.

Signed-off-by: Oleg Nesterov &lt;oleg@redhat.com&gt;
Acked-by: Hugh Dickins &lt;hugh@veritas.com&gt;
Reviewed-by: KOSAKI Motohiro &lt;kosaki.motohiro@jp.fujitsu.com&gt;
Acked-by: Balbir Singh &lt;balbir@linux.vnet.ibm.com&gt;
Signed-off-by: Andrew Morton &lt;akpm@linux-foundation.org&gt;
Signed-off-by: Linus Torvalds &lt;torvalds@linux-foundation.org&gt;
</content>
</entry>
<entry>
<title>mm: remove cgroup_mm_owner_callbacks</title>
<updated>2009-01-06T23:59:01Z</updated>
<author>
<name>Hugh Dickins</name>
</author>
<published>2009-01-06T22:39:22Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=e5991371ee0d1c0ce19e133c6f9075b49c5b4ae8'/>
<id>urn:sha1:e5991371ee0d1c0ce19e133c6f9075b49c5b4ae8</id>
<content type='text'>
cgroup_mm_owner_callbacks() was brought in to support the memrlimit
controller, but sneaked into mainline ahead of it.  That controller has
now been shelved, and the mm_owner_changed() args were inadequate for it
anyway (they needed an mm pointer instead of a task pointer).

Remove the dead code, and restore mm_update_next_owner() locking to how it
was before: taking mmap_sem there does nothing for memcontrol.c, now the
only user of mm-&gt;owner.

Signed-off-by: Hugh Dickins &lt;hugh@veritas.com&gt;
Cc: Paul Menage &lt;menage@google.com&gt;
Cc: Balbir Singh &lt;balbir@in.ibm.com&gt;
Signed-off-by: Andrew Morton &lt;akpm@linux-foundation.org&gt;
Signed-off-by: Linus Torvalds &lt;torvalds@linux-foundation.org&gt;
</content>
</entry>
</feed>
