Thread (2 messages) 2 messages, 2 authors, 2020-06-26

Re: [PATCH 05/14] umh: Separate the user mode driver and the user mode helper support

flat view

From: Tetsuo Handa <penguin-kernel@i-love.sakura.ne.jp>
Date: 2020-06-26 16:23:23
Also in: bpf, linux-fsdevel

Possibly related (same subject, not in this thread)

On 2020/06/26 21:55, Eric W. Biederman wrote:
quoted hunk ↗ jump to hunk
+static void umd_cleanup(struct subprocess_info *info)
+{
+	struct umh_info *umh_info = info->data;
+
+	/* cleanup if umh_pipe_setup() was successful but exec failed */
s/umh_pipe_setup/umd_setup/
quoted hunk ↗ jump to hunk
+	if (info->retval) {
+		fput(umh_info->pipe_to_umh);
+		fput(umh_info->pipe_from_umh);
+	}
+}
After this cleanup, I expect adding some protections/isolation which kernel threads
have (e.g. excluded from ptrace(), excluded from OOM victim selection, excluded from
SysRq-i, won't be terminated by SIGKILL from usermode processes, won't be stopped by
SIGSTOP from usermode processes, what else?). Doing it means giving up Alexei's

  It's nice to be able to compile that blob with -g and be able to 'gdb -p' into it.
  That works and very convenient when it comes to debugging. Compare that to debugging
  a kernel module!

but I think doing it is essential for keeping usermode blob processes as secure/robust
as kernel threads.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help