Commit bbc2e3ef authored by Cyrill Gorcunov's avatar Cyrill Gorcunov Committed by Linus Torvalds

pidns: remove recursion from free_pid_ns()

free_pid_ns() operates in a recursive fashion:

    kref_put(&ns->kref, free_pid_ns);

thus if there was a huge nesting of namespaces the userspace may trigger
avalanche calling of free_pid_ns leading to kernel stack exhausting and a
panic eventually.

This patch turns the recursion into an iterative loop.

Based on a patch by Andrew Vagin.

[ export put_pid_ns() to modules]
Signed-off-by: default avatarCyrill Gorcunov <>
Cc: Andrew Vagin <>
Cc: Oleg Nesterov <>
Cc: "Eric W. Biederman" <>
Cc: Pavel Emelyanov <>
Cc: Greg KH <>
Signed-off-by: default avatarAndrew Morton <>
Signed-off-by: default avatarLinus Torvalds <>
parent dc36d7e7
......@@ -47,15 +47,9 @@ static inline struct pid_namespace *get_pid_ns(struct pid_namespace *ns)
extern struct pid_namespace *copy_pid_ns(unsigned long flags, struct pid_namespace *ns);
extern void free_pid_ns(struct kref *kref);
extern void zap_pid_ns_processes(struct pid_namespace *pid_ns);
extern int reboot_pid_ns(struct pid_namespace *pid_ns, int cmd);
static inline void put_pid_ns(struct pid_namespace *ns)
if (ns != &init_pid_ns)
kref_put(&ns->kref, free_pid_ns);
extern void put_pid_ns(struct pid_namespace *ns);
#else /* !CONFIG_PID_NS */
#include <linux/err.h>
......@@ -133,19 +133,26 @@ struct pid_namespace *copy_pid_ns(unsigned long flags, struct pid_namespace *old
return create_pid_namespace(old_ns);
void free_pid_ns(struct kref *kref)
static void free_pid_ns(struct kref *kref)
struct pid_namespace *ns, *parent;
struct pid_namespace *ns;
ns = container_of(kref, struct pid_namespace, kref);
parent = ns->parent;
if (parent != NULL)
void put_pid_ns(struct pid_namespace *ns)
struct pid_namespace *parent;
while (ns != &init_pid_ns) {
parent = ns->parent;
if (!kref_put(&ns->kref, free_pid_ns))
ns = parent;
void zap_pid_ns_processes(struct pid_namespace *pid_ns)
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment