um: Track userspace children dying in SECCOMP mode
authorBenjamin Berg <benjamin@sipsolutions.net>
Mon, 2 Jun 2025 13:00:49 +0000 (15:00 +0200)
committerJohannes Berg <johannes.berg@intel.com>
Mon, 2 Jun 2025 13:17:19 +0000 (15:17 +0200)
commit8420e08fe3a594b6ffa07705ac270faa2ed452c5
tree22b578adabd9ef875fdaf560bd8d6a37eb8309b6
parentb1e1bd2e69430445021394536740352be1b41cd0
um: Track userspace children dying in SECCOMP mode

When in seccomp mode, we would hang forever on the futex if a child has
died unexpectedly. In contrast, ptrace mode will notice it and kill the
corresponding thread when it fails to run it.

Fix this issue using a new IRQ that is fired after a SIGCHLD and keeping
an (internal) list of all MMs. In the IRQ handler, find the affected MM
and set its PID to -1 as well as the futex variable to FUTEX_IN_KERN.

This, together with futex returning -EINTR after the signal is
sufficient to implement a race-free detection of a child dying.

Note that this also enables IRQ handling while starting a userspace
process. This should be safe and SECCOMP requires the IRQ in case the
process does not come up properly.

Signed-off-by: Benjamin Berg <benjamin@sipsolutions.net>
Signed-off-by: Benjamin Berg <benjamin.berg@intel.com>
Link: https://patch.msgid.link/20250602130052.545733-5-benjamin@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
arch/um/include/asm/irq.h
arch/um/include/asm/mmu.h
arch/um/include/shared/irq_user.h
arch/um/include/shared/os.h
arch/um/include/shared/skas/mm_id.h
arch/um/include/shared/skas/skas.h
arch/um/kernel/irq.c
arch/um/kernel/skas/mmu.c
arch/um/os-Linux/process.c
arch/um/os-Linux/signal.c
arch/um/os-Linux/skas/process.c