]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
pid: reject allocations through dead ancestor pid namespaces
authorJérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
Tue, 11 Aug 2026 19:10:11 +0000 (19:10 +0000)
committerChristian Brauner <brauner@kernel.org>
Wed, 12 Aug 2026 10:56:30 +0000 (12:56 +0200)
alloc_pid() checks PIDNS_ADDING only on the leaf pid namespace before
making a new struct pid visible in every ancestor namespace. That is
insufficient when an unborn descendant pid namespace outlives an
ancestor whose init task has already exited. The descendant can still be
initialized later through setns(), and the new pid is then published
into the dead ancestor as well.

Keep the existing ENOMEM behavior, but require PIDNS_ADDING to be set in
every namespace that will receive the new pid before publishing any of
them. This preserves the invariant that free_pid() never decrements
pid_allocated in a namespace whose child_reaper is no longer live.

Fixes: a3bdc23ba8ea ("pid_namespace: allow opening pid_for_children before init was created")
Signed-off-by: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
Reviewed-by: Pavel Tikhomirov <ptikhomirov@virtuozzo.com>
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
kernel/pid.c

index f55189a3d07d48bb2ede903e28b07057e190e902..d01d0dd7114b277b1e316916e5691268a12cd228 100644 (file)
@@ -324,8 +324,10 @@ struct pid *alloc_pid(struct pid_namespace *ns, pid_t *arg_set_tid,
         * error path may try to wakeup the possibly freed ns->child_reaper.
         */
        retval = -ENOMEM;
-       if (unlikely(!(ns->pid_allocated & PIDNS_ADDING)))
-               goto out_free;
+       for (upid = pid->numbers + ns->level; upid >= pid->numbers; --upid)
+               if (unlikely(!(upid->ns->pid_allocated & PIDNS_ADDING)))
+                       goto out_free;
+
        for (upid = pid->numbers + ns->level; upid >= pid->numbers; --upid) {
                /* Make the PID visible to find_pid_ns. */
                idr_replace(&upid->ns->idr, pid, upid->nr);