Skip to content

ipc/mqueue: remove pending notification in mqueue_evict_inode() - #2615

Open
vfsci-bot[bot] wants to merge 1 commit into
vfs.base.cifrom
pw/1169404/vfs.base.ci
Open

vfsci-bot[bot] wants to merge 1 commit into
vfs.base.cifrom
pw/1169404/vfs.base.ci

Conversation

@vfsci-bot

@vfsci-bot vfsci-bot Bot commented Sep 20, 2026

Copy link
Copy Markdown

Series: https://patchwork.kernel.org/project/linux-fsdevel/list/?series=1169404
Submitter: Hui Peng
Version: 1
Patches: 1/1
Message-ID: <20260919210615.3028694-1-benquike@gmail.com>
Base: vfs.base.ci
Lore: https://lore.kernel.org/linux-fsdevel/20260919210615.3028694-1-benquike@gmail.com


Automated by ml2pr

When a process registers a notification via mq_notify(), do_mq_notify()
takes references on info->notify_owner (struct pid) and
info->notify_user_ns (struct user_namespace), and for SIGEV_THREAD
notifications also allocates a 32-byte kernel sk_buff
(info->notify_cookie) charged via netlink_attachskb() to
info->notify_sock (struct sock).

mqueue_flush_file() only calls remove_notification(info) when the
process closing the descriptor has task_tgid(current) ==
info->notify_owner. When a child process created with CLONE_FILES (and
its own TGID) registers a notification via mq_notify() and exits while
the parent still holds the shared file table, exit_files() drops the
child's files_struct reference without calling filp_close(). When the
parent subsequently closes the descriptor and unlinks the queue,
task_tgid(current) != info->notify_owner in mqueue_flush_file(), so the
notification remains active when mqueue_evict_inode() is called.

Because mqueue_evict_inode() does not call remove_notification(info),
the attached sk_buff (and its sk_rmem_alloc charge on the netlink
socket), sock reference, pid reference, and user_namespace reference are
permanently leaked when the inode is evicted.

Call remove_notification(info) in mqueue_evict_inode() if
info->notify_owner is non-NULL.

Fixes: 1da177e ("Linux-2.6.12-rc2")
Assisted-by: LLM
Signed-off-by: Hui Peng <benquike@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant