FreeBSD src
Go to file
joerg ff11e8a834 Fix a serious bug in syslogd regarding the handling of pipes. The bug
would cause syslogd to eventually kill innocent processes in the
system over time (note: not `could' but `would').  Many thanks to my
colleague Mirko for digging into the kernel structures and providing
me with the debugging framework to find out about the nature of this
bug (and to isolate that syslogd was the culprit) in a rather large
set of distributed machines at client sites where this happened
occasionally.

Whenever a child process was no longer responsive, or when syslogd
receives a SIGHUP so it closes all its logging file descriptors, for
any descriptor that refers to a pipe syslogd enters the data about the
old logging child process into a `dead queue', where it is being
removed from (and the status of the dead kitten being fetched) upon
receipt of a SIGCHLD.  However, there's a high probability that the
SIGCHLD already arrives before the child's data are actually entered
into the dead queue inside the SIGHUP handler, so the SIGCHLD handler
has nothing to fetch and remove and simply continues.  Whenever this
happens, the process'es data remain on the dead queue forever, and
since domark() tried to get rid of totally unresponsive children by
first sending a SIGTERM and later a SIGKILL, it was only a matter of
time until the system had recycled enough PIDs so an innocent process
got shot to death.

Fix the race by masking SIGHUP and SIGCHLD from both handlers mutually.

Add additional bandaids ``just in case'', i. e. don't enter a process
into the dead queue if we can't signal it (this should only happen in
case it is already dead by that time so we can fetch the status
immediately instead of deferring this to the SIGCHLD handler); for the
kill(2) inside domark(), check for an error status (/* Can't happen */
:) and remove it from the dead queue in this case (which if it would
have been there in the first place would have reduced the problem to a
statistically minimal likelihood so i certainly would never have
noticed the bug at all :).

Mirko also reviewed the fix in priciple (mutual blocking of both
signals inside the handlers), but not the actual code.

Reviewed by:	Mirko Kaffka <mirko@interface-business.de>
Approved by:	jkh
2000-02-28 17:49:43 +00:00
bin Fix style bugs I introduced in the last revision. 2000-02-27 16:40:39 +00:00
contrib Get crypto from libcrypto, not libdes. 2000-02-24 19:28:31 +00:00
crypto Sync with internat.freebsd.org; weak symbols vs static libs == trouble 2000-02-26 16:57:17 +00:00
etc Update the description of NOCRYPT and NOSECURE to match reality. 2000-02-28 07:07:26 +00:00
games Change RETTOKEN from '\n' to '\r'; it didn't work under some or all 2000-02-27 23:02:47 +00:00
gnu Use libcrypto instead of libdes. 2000-02-24 23:15:42 +00:00
include Do not conditionalize function prototype definition for functions we 2000-02-20 07:40:25 +00:00
kerberos5 Use libcrypto instead of libdes. Upgrade for Heimdal-0.2p 2000-02-24 21:15:14 +00:00
kerberosIV Use libcrypto in place of libdes. 2000-02-24 20:57:04 +00:00
lib Add MAP_NOCORE to mmap(2), and MADV_NOCORE and MADV_CORE to madvise(2). 2000-02-28 04:10:35 +00:00
libexec Use libcrypto instead of libdes. 2000-02-24 21:18:08 +00:00
release Add OpenSSH blurb and some other minor changes. 2000-02-28 01:57:15 +00:00
sbin A huge rewrite of the manual page (mostly -mdoc related). 2000-02-28 15:21:12 +00:00
secure Merge from internat.freebsd.org repo, minus change to rsa_eay.c (missing) 2000-02-26 13:13:03 +00:00
share Update the description of NOCRYPT and NOSECURE to match reality. 2000-02-28 07:07:26 +00:00
sys Fixed configuration of fast interrupts for the pci cy driver. They were 2000-02-28 08:12:24 +00:00
tools These are regression tests for the P1003.1B scheduler. 2000-02-16 14:28:42 +00:00
usr.bin Fix diagnostic printing test condition (was always true) 2000-02-28 01:48:50 +00:00
usr.sbin Fix a serious bug in syslogd regarding the handling of pipes. The bug 2000-02-28 17:49:43 +00:00
COPYRIGHT Update to add the July 22, 1999 addendum. 1999-09-05 21:33:47 +00:00
Makefile We have a new world order in libraries. 2000-02-24 23:03:16 +00:00
Makefile.inc1 We have a new world order in libraries. 2000-02-24 23:03:16 +00:00
Makefile.upgrade $Id$ -> $FreeBSD$ 1999-08-28 01:35:59 +00:00
README $Id$ -> $FreeBSD$ 1999-08-28 01:35:59 +00:00
UPDATING Slightly improved 3.x -> current instructions. 2000-02-23 05:51:02 +00:00

This is the top level of the FreeBSD source directory.  This file
was last revised on:
$FreeBSD$

For copyright information, please see the file COPYRIGHT in this
directory (additional copyright information also exists for some
sources in this tree - please see the specific source directories for
more information).

The Makefile in this directory supports a number of targets for
building components (or all) of the FreeBSD source tree, the most
commonly used one being ``world'', which rebuilds and installs
everything in the FreeBSD system from the source tree except the
kernel and the contents of /etc.  Please see the top of the Makefile
in this directory for more information on the standard build targets
and compile-time flags.

Building a kernel with config(8) is a somewhat more involved process,
documentation for which can be found at:
   http://www.freebsd.org/handbook/kernelconfig.html
And in the config(8) man page.

The sample kernel configuration files reside in the sys/i386/conf
sub-directory (assuming that you've installed the kernel sources), the
file named GENERIC being the one used to build your initial installation
kernel.  The file LINT contains entries for all possible devices, not
just those commonly used, and is meant more as a general reference
than an actual kernel configuration file (a kernel built from it
wouldn't even run).


Source Roadmap:
---------------
bin		System/User commands.

contrib		Packages contributed by 3rd parties.

crypto		Export controlled stuff (see crypto/README).

etc		Template files for /etc

games		Amusements.

gnu		Various commands and libraries under the GNU Public License.
		Please see gnu/COPYING* for more information.

include		System include files.

kerberosIV	Kerberos package.

lib		System libraries.

libexec		System daemons.

release		Release building Makefile & associated tools.

sbin		System commands.

secure		DES and DES-related utilities - NOT FOR EXPORT!

share		Shared resources.

sys		Kernel sources.

tools		Utilities for regression testing and miscellaneous tasks.

usr.bin		User commands.

usr.sbin	System administration commands.


For information on synchronizing your source tree with one or more of
the FreeBSD Project's development branches, please see:

  http://www.freebsd.org/handbook/synching.html