Thread (1 message) 1 message, 1 author, 2015-10-01

Re: List corruption on epoll_ctl(EPOLL_CTL_DEL) an AF_UNIX socket

From: Rainer Weikusat <hidden>
Date: 2015-10-01 12:59:44
Also in: lkml

Possibly related (same subject, not in this thread)

Rainer Weikusat [off-list ref] writes:
Rainer Weikusat [off-list ref] writes:
quoted
Jason Baron [off-list ref] writes:
quoted
On 09/30/2015 01:54 AM, Mathias Krause wrote:
quoted
On 29 September 2015 at 21:09, Jason Baron [off-list ref] wrote:
quoted
However, if we call connect on socket 's', to connect to a new socket 'o2', we
drop the reference on the original socket 'o'. Thus, we can now close socket
'o' without unregistering from epoll. Then, when we either close the ep
or unregister 'o', we end up with this list corruption. Thus, this is not a
race per se, but can be triggered sequentially.
[...]

Test program (assumes that it can execute itself as ./a.out):

-------------
#include <fcntl.h>
#include <pthread.h>
#include <string.h>
#include <sys/socket.h>
#include <sys/un.h>
#include <sys/epoll.h>
#include <signal.h>
#include <unistd.h>

static int sk;

static void *epoller(void *unused)
{
    struct epoll_event epev;
    int epfd;
    
    epfd = epoll_create(1);

    epev.events = EPOLLOUT;
    epoll_ctl(epfd, EPOLL_CTL_ADD, sk, &epev);
    epoll_wait(epfd, &epev, 1, 5000);

    execl("./a.out", "./a.out", (void *)0);

    return NULL;
}
[...]

Possibly interesting additional bit of information: The list corruption
warnings appear only if the 2nd connect is there and both the sk and
epfd file descriptors are left open accross the exec. Closing either of
both still triggers the _destructor warnings but nothing else (until the
process runs out of file descriptors).
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help