Commit 183d95cd authored by Oleg Nesterov's avatar Oleg Nesterov Committed by Greg Kroah-Hartman

tty: set_termios/set_termiox should not return -EINTR

See https://bugzilla.redhat.com/show_bug.cgi?id=904907
read command causes bash to abort with double free or corruption (out).

A simple test-case from Roman:

	// Compile the reproducer and send sigchld ti that process.
	// EINTR occurs even if SA_RESTART flag is set.

	void handler(int sig)
	{
	}

	main()
	{
	  struct sigaction act;
	  act.sa_handler = handler;
	  act.sa_flags = SA_RESTART;
	  sigaction (SIGCHLD, &act, 0);
	  struct termio ttp;
	  ioctl(0, TCGETA, &ttp);
	  while(1)
	  {
	    if (ioctl(0, TCSETAW, ttp) < 0)
	      {
		if (errno == EINTR)
		{
		  fprintf(stderr, "BUG!"); return(1);
		}
	      }
	  }
	}

Change set_termios/set_termiox to return -ERESTARTSYS to fix this
particular problem.

I didn't dare to change other EINTR's in drivers/tty/, but they look
equally wrong.
Reported-by: default avatarRoman Rakus <rrakus@redhat.com>
Reported-by: default avatarLingzhu Xiang <lxiang@redhat.com>
Signed-off-by: default avatarOleg Nesterov <oleg@redhat.com>
Cc: Jiri Slaby <jslaby@suse.cz>
Cc: stable <stable@vger.kernel.org>
Signed-off-by: default avatarGreg Kroah-Hartman <gregkh@linuxfoundation.org>
parent 4d9b1090
...@@ -617,7 +617,7 @@ static int set_termios(struct tty_struct *tty, void __user *arg, int opt) ...@@ -617,7 +617,7 @@ static int set_termios(struct tty_struct *tty, void __user *arg, int opt)
if (opt & TERMIOS_WAIT) { if (opt & TERMIOS_WAIT) {
tty_wait_until_sent(tty, 0); tty_wait_until_sent(tty, 0);
if (signal_pending(current)) if (signal_pending(current))
return -EINTR; return -ERESTARTSYS;
} }
tty_set_termios(tty, &tmp_termios); tty_set_termios(tty, &tmp_termios);
...@@ -684,7 +684,7 @@ static int set_termiox(struct tty_struct *tty, void __user *arg, int opt) ...@@ -684,7 +684,7 @@ static int set_termiox(struct tty_struct *tty, void __user *arg, int opt)
if (opt & TERMIOS_WAIT) { if (opt & TERMIOS_WAIT) {
tty_wait_until_sent(tty, 0); tty_wait_until_sent(tty, 0);
if (signal_pending(current)) if (signal_pending(current))
return -EINTR; return -ERESTARTSYS;
} }
mutex_lock(&tty->termios_mutex); mutex_lock(&tty->termios_mutex);
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment