Thread (1 message) 1 message, 1 author, 2015-11-02

Re: [RFC] unix: fix use-after-free in unix_dgram_poll()/ 4.2.5

From: Rainer Weikusat <hidden>
Date: 2015-11-02 21:56:53
Also in: lkml

Olivier Mauras [off-list ref] writes:

[...]
I've encountered  issues with Jason's patch ported to 3.14.x which would break
openldap, rendering it unable to answer any query - Here's a strace of the
slapd process in this state http://pastebin.ca/3226383
Just ported Rainer's patch to 3.14 and so far I can't reproduce the issue -
I may be missing something here but the final state according to the
trace it that thread 775 of the process blocks in epoll_wait with a
descriptor set containing only a listening TCP socket (8) and waiting
for new connections. I don't think this can execute any code
changed by my patch and I'm fairly certain for this for Jason's, too:
Both are about AF_UNIX datagram sockets and the specific case where
either a write couldn't complete because the backlog of the receive
queue of the 1 side of a n:1 datagram socket arrangement was considered
too large or where a 'poll for write' check returned 'not writeable' for
the same reason.

Judging from the 2.4.42 sources, OpenLDAP doesn't use AF_UNIX datagram
sockets at all so it shouldn't ever be affected by any changes to the
code handling them.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help