Page MenuHomeFreeBSD

jail: Fix a race in prison_deref()
AcceptedPublic

Authored by markj on Thu, Sep 24, 1:53 PM.
Tags
None
Referenced Files
F173292171: D59984.diff
Fri, Sep 25, 1:18 AM
F173292165: D59984.id187600.diff
Fri, Sep 25, 1:18 AM
F173280277: D59984.diff
Thu, Sep 24, 10:43 PM
F173275583: D59984.id187600.diff
Thu, Sep 24, 9:54 PM
F173266418: D59984.id187600.diff
Thu, Sep 24, 8:15 PM
F173253018: D59984.diff
Thu, Sep 24, 5:43 PM
Subscribers

Details

Reviewers
jamie
Group Reviewers
Jails
Summary

If we're killing a jail which has some user refs pending, then we would
first drop our ref and then kill all processes in the prison. However,
it's possible for the prison to be freed before we finish that
operation, generally if the processes exit on their own before
prison_proc_iterate() returns.

Thus, defer the release of the prison refcount until after we've killed
all procs.

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped
Build Status
Buildable 77274
Build 74157: arc lint + arc unit

Event Timeline

Yes, I'm referring to a prison I don't hold a reference to, without allprison_lock held. My bad. This look good, with the common path not adding any extra steps.

This revision is now accepted and ready to land.Thu, Sep 24, 5:59 PM