Skip to content
Snippets Groups Projects
exit.c 42.6 KiB
Newer Older
  • Learn to ignore specific revisions
  • Linus Torvalds's avatar
    Linus Torvalds committed
    /*
     *  linux/kernel/exit.c
     *
     *  Copyright (C) 1991, 1992  Linus Torvalds
     */
    
    #include <linux/mm.h>
    #include <linux/slab.h>
    #include <linux/interrupt.h>
    #include <linux/module.h>
    
    #include <linux/capability.h>
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    #include <linux/completion.h>
    #include <linux/personality.h>
    #include <linux/tty.h>
    
    #include <linux/iocontext.h>
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    #include <linux/key.h>
    #include <linux/security.h>
    #include <linux/cpu.h>
    #include <linux/acct.h>
    
    #include <linux/tsacct_kern.h>
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    #include <linux/file.h>
    
    Al Viro's avatar
    Al Viro committed
    #include <linux/fdtable.h>
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    #include <linux/binfmts.h>
    
    #include <linux/nsproxy.h>
    
    #include <linux/pid_namespace.h>
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    #include <linux/ptrace.h>
    #include <linux/profile.h>
    #include <linux/mount.h>
    #include <linux/proc_fs.h>
    
    #include <linux/kthread.h>
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    #include <linux/mempolicy.h>
    
    #include <linux/taskstats_kern.h>
    
    #include <linux/delayacct.h>
    
    #include <linux/cgroup.h>
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    #include <linux/syscalls.h>
    
    #include <linux/posix-timers.h>
    
    #include <linux/cn_proc.h>
    
    #include <linux/mutex.h>
    
    #include <linux/futex.h>
    
    #include <linux/pipe_fs_i.h>
    
    #include <linux/audit.h> /* for audit_free() */
    
    #include <linux/resource.h>
    
    #include <linux/task_io_accounting_ops.h>
    
    Roland McGrath's avatar
    Roland McGrath committed
    #include <linux/tracehook.h>
    
    #include <linux/fs_struct.h>
    
    #include <linux/init_task.h>
    
    #include <linux/perf_event.h>
    
    #include <trace/events/sched.h>
    
    #include <linux/oom.h>
    
    #include <linux/writeback.h>
    
    Al Viro's avatar
    Al Viro committed
    #include <linux/shm.h>
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    
    #include <asm/uaccess.h>
    #include <asm/unistd.h>
    #include <asm/pgtable.h>
    #include <asm/mmu_context.h>
    
    
    static void exit_mm(struct task_struct * tsk);
    
    
    static void __unhash_process(struct task_struct *p, bool group_dead)
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    {
    	nr_threads--;
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    		detach_pid(p, PIDTYPE_PGID);
    		detach_pid(p, PIDTYPE_SID);
    
    		list_del_rcu(&p->tasks);
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	}
    
    	list_del_rcu(&p->thread_group);
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    }
    
    
    /*
     * This function expects the tasklist_lock write-locked.
     */
    static void __exit_signal(struct task_struct *tsk)
    {
    	struct signal_struct *sig = tsk->signal;
    
    	bool group_dead = thread_group_leader(tsk);
    
    	struct sighand_struct *sighand;
    
    	struct tty_struct *uninitialized_var(tty);
    
    	cputime_t utime, stime;
    
    	sighand = rcu_dereference_check(tsk->sighand,
    
    					lockdep_tasklist_lock_is_held());
    
    	spin_lock(&sighand->siglock);
    
    	posix_cpu_timers_exit(tsk);
    
    		posix_cpu_timers_exit_group(tsk);
    
    		tty = sig->tty;
    		sig->tty = NULL;
    
    		/*
    		 * This can only happen if the caller is de_thread().
    		 * FIXME: this is the temporary hack, we should teach
    		 * posix-cpu-timers to handle this case correctly.
    		 */
    		if (unlikely(has_group_leader_pid(tsk)))
    			posix_cpu_timers_exit_group(tsk);
    
    
    		/*
    		 * If there is any task waiting for the group exit
    		 * then notify it:
    		 */
    
    		if (sig->notify_count > 0 && !--sig->notify_count)
    
    			wake_up_process(sig->group_exit_task);
    
    		if (tsk == sig->curr_target)
    			sig->curr_target = next_thread(tsk);
    		/*
    		 * Accumulate here the counters for all threads but the
    		 * group leader as they die, so they can be added into
    		 * the process-wide totals when those are taken.
    		 * The group leader stays around as a zombie as long
    		 * as there are other threads.  When it gets reaped,
    		 * the exit.c code will add its counts into these totals.
    		 * We won't ever get here for the group leader, since it
    		 * will have been the last reference on the signal_struct.
    		 */
    
    		task_cputime(tsk, &utime, &stime);
    		sig->utime += utime;
    		sig->stime += stime;
    		sig->gtime += task_gtime(tsk);
    
    		sig->min_flt += tsk->min_flt;
    		sig->maj_flt += tsk->maj_flt;
    		sig->nvcsw += tsk->nvcsw;
    		sig->nivcsw += tsk->nivcsw;
    
    		sig->inblock += task_io_get_inblock(tsk);
    		sig->oublock += task_io_get_oublock(tsk);
    
    		task_io_accounting_add(&sig->ioac, &tsk->ioac);
    
    		sig->sum_sched_runtime += tsk->se.sum_exec_runtime;
    
    	__unhash_process(tsk, group_dead);
    
    	/*
    	 * Do this under ->siglock, we can race with another thread
    	 * doing sigqueue_free() if we have SIGQUEUE_PREALLOC signals.
    	 */
    	flush_sigqueue(&tsk->pending);
    
    	spin_unlock(&sighand->siglock);
    
    
    	__cleanup_sighand(sighand);
    
    	clear_tsk_thread_flag(tsk,TIF_SIGPENDING);
    
    		flush_sigqueue(&sig->shared_pending);
    
    static void delayed_put_task_struct(struct rcu_head *rhp)
    {
    
    	struct task_struct *tsk = container_of(rhp, struct task_struct, rcu);
    
    
    	perf_event_delayed_put(tsk);
    
    	trace_sched_process_free(tsk);
    	put_task_struct(tsk);
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    void release_task(struct task_struct * p)
    {
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	int zap_leader;
    
    	/* don't need to get the RCU readlock here - the process is dead and
    
    	 * can't be modifying its own credentials. But shut RCU-lockdep up */
    	rcu_read_lock();
    
    	atomic_dec(&__task_cred(p)->user->processes);
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	write_lock_irq(&tasklist_lock);
    
    	ptrace_release_task(p);
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	__exit_signal(p);
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	/*
    	 * If we are the last non-leader member of the thread
    	 * group, and the leader is zombie, then notify the
    	 * group leader's parent process. (if it wants notification.)
    	 */
    	zap_leader = 0;
    	leader = p->group_leader;
    	if (leader != p && thread_group_empty(leader) && leader->exit_state == EXIT_ZOMBIE) {
    		/*
    		 * If we were the last child thread and the leader has
    		 * exited already, and the leader's parent ignores SIGCHLD,
    		 * then we are the one who should release the leader.
    
    		zap_leader = do_notify_parent(leader, leader->exit_signal);
    
    Roland McGrath's avatar
    Roland McGrath committed
    		if (zap_leader)
    			leader->exit_state = EXIT_DEAD;
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	}
    
    	write_unlock_irq(&tasklist_lock);
    	release_thread(p);
    
    	call_rcu(&p->rcu, delayed_put_task_struct);
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    
    	p = leader;
    	if (unlikely(zap_leader))
    		goto repeat;
    }
    
    /*
     * This checks not only the pgrp, but falls back on the pid if no
     * satisfactory pgrp is found. I dunno - gdb doesn't work correctly
     * without this...
    
     *
     * The caller must hold rcu lock or the tasklist lock.
    
    Linus Torvalds's avatar
    Linus Torvalds committed
     */
    
    struct pid *session_of_pgrp(struct pid *pgrp)
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    {
    	struct task_struct *p;
    
    	p = pid_task(pgrp, PIDTYPE_PGID);
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	return sid;
    }
    
    /*
     * Determine if a process group is "orphaned", according to the POSIX
     * definition in 2.2.2.52.  Orphaned process groups are not to be affected
     * by terminal-generated stop signals.  Newly orphaned process groups are
     * to receive a SIGHUP and a SIGCONT.
     *
     * "I ask you, have you ever known what it is to be an orphan?"
     */
    
    static int will_become_orphaned_pgrp(struct pid *pgrp, struct task_struct *ignored_task)
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    {
    	struct task_struct *p;
    
    
    	do_each_pid_task(pgrp, PIDTYPE_PGID, p) {
    
    		if ((p == ignored_task) ||
    		    (p->exit_state && thread_group_empty(p)) ||
    		    is_global_init(p->real_parent))
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    			continue;
    
    		if (task_pgrp(p->real_parent) != pgrp &&
    
    		    task_session(p->real_parent) == task_session(p))
    			return 0;
    
    	} while_each_pid_task(pgrp, PIDTYPE_PGID, p);
    
    int is_current_pgrp_orphaned(void)
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    {
    	int retval;
    
    	read_lock(&tasklist_lock);
    
    	retval = will_become_orphaned_pgrp(task_pgrp(current), NULL);
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	read_unlock(&tasklist_lock);
    
    	return retval;
    }
    
    
    static bool has_stopped_jobs(struct pid *pgrp)
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    {
    	struct task_struct *p;
    
    
    	do_each_pid_task(pgrp, PIDTYPE_PGID, p) {
    
    		if (p->signal->flags & SIGNAL_STOP_STOPPED)
    			return true;
    
    	} while_each_pid_task(pgrp, PIDTYPE_PGID, p);
    
    /*
     * Check to see if any process groups have become orphaned as
     * a result of our exiting, and if they have any stopped jobs,
     * send them a SIGHUP and then a SIGCONT. (POSIX 3.2.2.2)
     */
    static void
    kill_orphaned_pgrp(struct task_struct *tsk, struct task_struct *parent)
    {
    	struct pid *pgrp = task_pgrp(tsk);
    	struct task_struct *ignored_task = tsk;
    
    	if (!parent)
    		 /* exit: our father is in a different pgrp than
    		  * we are and we were the only connection outside.
    		  */
    		parent = tsk->real_parent;
    	else
    		/* reparent: our child is in a different pgrp than
    		 * we are, and it was the only connection outside.
    		 */
    		ignored_task = NULL;
    
    	if (task_pgrp(parent) != pgrp &&
    	    task_session(parent) == task_session(tsk) &&
    	    will_become_orphaned_pgrp(pgrp, ignored_task) &&
    	    has_stopped_jobs(pgrp)) {
    		__kill_pgrp_info(SIGHUP, SEND_SIG_PRIV, pgrp);
    		__kill_pgrp_info(SIGCONT, SEND_SIG_PRIV, pgrp);
    	}
    }
    
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    /*
    
     * Let kernel threads use this to say that they allow a certain signal.
     * Must not be used if kthread was cloned with CLONE_SIGHAND.
    
    Linus Torvalds's avatar
    Linus Torvalds committed
     */
    int allow_signal(int sig)
    {
    
    	if (!valid_signal(sig) || sig < 1)
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    		return -EINVAL;
    
    	spin_lock_irq(&current->sighand->siglock);
    
    	/* This is only needed for daemonize()'ed kthreads */
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	sigdelset(&current->blocked, sig);
    
    	/*
    	 * Kernel threads handle their own signals. Let the signal code
    	 * know it'll be handled, so that they don't get converted to
    	 * SIGKILL or just silently dropped.
    	 */
    	current->sighand->action[(sig)-1].sa.sa_handler = (void __user *)2;
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	recalc_sigpending();
    	spin_unlock_irq(&current->sighand->siglock);
    	return 0;
    }
    
    EXPORT_SYMBOL(allow_signal);
    
    int disallow_signal(int sig)
    {
    
    	if (!valid_signal(sig) || sig < 1)
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    		return -EINVAL;
    
    	spin_lock_irq(&current->sighand->siglock);
    
    	current->sighand->action[(sig)-1].sa.sa_handler = SIG_IGN;
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	recalc_sigpending();
    	spin_unlock_irq(&current->sighand->siglock);
    	return 0;
    }
    
    EXPORT_SYMBOL(disallow_signal);
    
    
    #ifdef CONFIG_MM_OWNER
    /*
    
     * A task is exiting.   If it owned this mm, find a new owner for the mm.
    
     */
    void mm_update_next_owner(struct mm_struct *mm)
    {
    	struct task_struct *c, *g, *p = current;
    
    retry:
    
    	/*
    	 * If the exiting or execing task is not the owner, it's
    	 * someone else's problem.
    	 */
    	if (mm->owner != p)
    
    	/*
    	 * The current owner is exiting/execing and there are no other
    	 * candidates.  Do not leave the mm pointing to a possibly
    	 * freed task structure.
    	 */
    	if (atomic_read(&mm->mm_users) <= 1) {
    		mm->owner = NULL;
    		return;
    	}
    
    
    	read_lock(&tasklist_lock);
    	/*
    	 * Search in the children
    	 */
    	list_for_each_entry(c, &p->children, sibling) {
    		if (c->mm == mm)
    			goto assign_new_owner;
    	}
    
    	/*
    	 * Search in the siblings
    	 */
    
    	list_for_each_entry(c, &p->real_parent->children, sibling) {
    
    		if (c->mm == mm)
    			goto assign_new_owner;
    	}
    
    	/*
    	 * Search through everything else. We should not get
    	 * here often
    	 */
    	do_each_thread(g, c) {
    		if (c->mm == mm)
    			goto assign_new_owner;
    	} while_each_thread(g, c);
    
    	read_unlock(&tasklist_lock);
    
    	/*
    	 * We found no owner yet mm_users > 1: this implies that we are
    	 * most likely racing with swapoff (try_to_unuse()) or /proc or
    
    	 * ptrace or page migration (get_task_mm()).  Mark owner as NULL.
    
    	 */
    	mm->owner = NULL;
    
    	return;
    
    assign_new_owner:
    	BUG_ON(c == p);
    	get_task_struct(c);
    	/*
    	 * The task_lock protects c->mm from changing.
    	 * We always want mm->owner->mm == mm
    	 */
    	task_lock(c);
    
    	/*
    	 * Delay read_unlock() till we have the task_lock()
    	 * to ensure that c does not slip away underneath us
    	 */
    	read_unlock(&tasklist_lock);
    
    	if (c->mm != mm) {
    		task_unlock(c);
    		put_task_struct(c);
    		goto retry;
    	}
    	mm->owner = c;
    	task_unlock(c);
    	put_task_struct(c);
    }
    #endif /* CONFIG_MM_OWNER */
    
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    /*
     * Turn us into a lazy TLB process if we
     * aren't already..
     */
    
    static void exit_mm(struct task_struct * tsk)
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    {
    	struct mm_struct *mm = tsk->mm;
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	if (!mm)
    		return;
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	/*
    	 * Serialize with any possible pending coredump.
    
    	 * We must hold mmap_sem around checking core_state
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	 * and clearing tsk->mm.  The core-inducing thread
    
    	 * will increment ->nr_threads for each thread in the
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	 * group with ->mm != NULL.
    	 */
    	down_read(&mm->mmap_sem);
    
    	core_state = mm->core_state;
    	if (core_state) {
    		struct core_thread self;
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    		up_read(&mm->mmap_sem);
    
    
    		self.task = tsk;
    		self.next = xchg(&core_state->dumper.next, &self);
    		/*
    		 * Implies mb(), the result of xchg() must be visible
    		 * to core_state->dumper.
    		 */
    		if (atomic_dec_and_test(&core_state->nr_threads))
    			complete(&core_state->startup);
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    
    
    		for (;;) {
    			set_task_state(tsk, TASK_UNINTERRUPTIBLE);
    			if (!self.task) /* see coredump_finish() */
    				break;
    
    		}
    		__set_task_state(tsk, TASK_RUNNING);
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    		down_read(&mm->mmap_sem);
    	}
    	atomic_inc(&mm->mm_count);
    
    	BUG_ON(mm != tsk->active_mm);
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	/* more a memory barrier than a real lock */
    	task_lock(tsk);
    	tsk->mm = NULL;
    	up_read(&mm->mmap_sem);
    	enter_lazy_tlb(mm, current);
    	task_unlock(tsk);
    
    	mm_update_next_owner(mm);
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	mmput(mm);
    }
    
    /*
    
     * When we die, we re-parent all our children, and try to:
     * 1. give them to another thread in our thread group, if such a member exists
     * 2. give it to the first ancestor process which prctl'd itself as a
     *    child_subreaper for its children (like a service manager)
     * 3. give it to the init process (PID 1) in our pid namespace
    
    Linus Torvalds's avatar
    Linus Torvalds committed
     */
    
    static struct task_struct *find_new_reaper(struct task_struct *father)
    
    	__releases(&tasklist_lock)
    	__acquires(&tasklist_lock)
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    {
    
    	struct pid_namespace *pid_ns = task_active_pid_ns(father);
    	struct task_struct *thread;
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    
    
    	thread = father;
    	while_each_thread(father, thread) {
    		if (thread->flags & PF_EXITING)
    			continue;
    		if (unlikely(pid_ns->child_reaper == father))
    			pid_ns->child_reaper = thread;
    		return thread;
    	}
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    
    
    	if (unlikely(pid_ns->child_reaper == father)) {
    		write_unlock_irq(&tasklist_lock);
    
    		if (unlikely(pid_ns == &init_pid_ns)) {
    			panic("Attempted to kill init! exitcode=0x%08x\n",
    				father->signal->group_exit_code ?:
    					father->exit_code);
    		}
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    
    
    		zap_pid_ns_processes(pid_ns);
    		write_lock_irq(&tasklist_lock);
    
    	} else if (father->signal->has_child_subreaper) {
    		struct task_struct *reaper;
    
    		/*
    		 * Find the first ancestor marked as child_subreaper.
    		 * Note that the code below checks same_thread_group(reaper,
    		 * pid_ns->child_reaper).  This is what we need to DTRT in a
    		 * PID namespace. However we still need the check above, see
    		 * http://marc.info/?l=linux-kernel&m=131385460420380
    		 */
    		for (reaper = father->real_parent;
    		     reaper != &init_task;
    		     reaper = reaper->real_parent) {
    			if (same_thread_group(reaper, pid_ns->child_reaper))
    				break;
    			if (!reaper->signal->is_child_subreaper)
    				continue;
    			thread = reaper;
    			do {
    				if (!(thread->flags & PF_EXITING))
    					return reaper;
    			} while_each_thread(reaper, thread);
    		}
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	}
    
    /*
    * Any that need to be release_task'd are put on the @dead list.
     */
    
    static void reparent_leader(struct task_struct *father, struct task_struct *p,
    
    				struct list_head *dead)
    {
    	list_move_tail(&p->sibling, &p->real_parent->children);
    
    
    	if (p->exit_state == EXIT_DEAD)
    
    		return;
    	/*
    	 * If this is a threaded reparent there is no need to
    	 * notify anyone anything has happened.
    	 */
    	if (same_thread_group(p->real_parent, father))
    		return;
    
    	/* We don't want people slaying init.  */
    	p->exit_signal = SIGCHLD;
    
    	/* If it has exited notify the new parent about this child's death. */
    
    Tejun Heo's avatar
    Tejun Heo committed
    	if (!p->ptrace &&
    
    	    p->exit_state == EXIT_ZOMBIE && thread_group_empty(p)) {
    
    		if (do_notify_parent(p, p->exit_signal)) {
    
    			p->exit_state = EXIT_DEAD;
    			list_move_tail(&p->sibling, dead);
    		}
    	}
    
    	kill_orphaned_pgrp(p, father);
    }
    
    
    static void forget_original_parent(struct task_struct *father)
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    {
    
    	struct task_struct *p, *n, *reaper;
    
    	LIST_HEAD(dead_children);
    
    
    	write_lock_irq(&tasklist_lock);
    
    	/*
    	 * Note that exit_ptrace() and find_new_reaper() might
    	 * drop tasklist_lock and reacquire it.
    	 */
    	exit_ptrace(father);
    
    	list_for_each_entry_safe(p, n, &father->children, sibling) {
    
    		struct task_struct *t = p;
    		do {
    			t->real_parent = reaper;
    			if (t->parent == father) {
    
    Tejun Heo's avatar
    Tejun Heo committed
    				BUG_ON(t->ptrace);
    
    				t->parent = t->real_parent;
    			}
    			if (t->pdeath_signal)
    				group_send_sig_info(t->pdeath_signal,
    						    SEND_SIG_NOINFO, t);
    		} while_each_thread(p, t);
    		reparent_leader(father, p, &dead_children);
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	}
    
    	write_unlock_irq(&tasklist_lock);
    
    	BUG_ON(!list_empty(&father->children));
    
    
    	list_for_each_entry_safe(p, n, &dead_children, sibling) {
    		list_del_init(&p->sibling);
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    }
    
    /*
     * Send signals to all our closest relatives so that they know
     * to properly mourn us..
     */
    
    static void exit_notify(struct task_struct *tsk, int group_dead)
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    {
    
    	bool autoreap;
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    
    	/*
    	 * This does two things:
    	 *
      	 * A.  Make init inherit all the child processes
    	 * B.  Check to see if any process groups have become orphaned
    	 *	as a result of our exiting, and if they have any stopped
    	 *	jobs, send them a SIGHUP and then a SIGCONT.  (POSIX 3.2.2.2)
    	 */
    
    	forget_original_parent(tsk);
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    
    
    	write_lock_irq(&tasklist_lock);
    
    	if (group_dead)
    		kill_orphaned_pgrp(tsk->group_leader, NULL);
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    
    
    	if (unlikely(tsk->ptrace)) {
    		int sig = thread_group_leader(tsk) &&
    				thread_group_empty(tsk) &&
    				!ptrace_reparented(tsk) ?
    			tsk->exit_signal : SIGCHLD;
    		autoreap = do_notify_parent(tsk, sig);
    	} else if (thread_group_leader(tsk)) {
    		autoreap = thread_group_empty(tsk) &&
    			do_notify_parent(tsk, tsk->exit_signal);
    	} else {
    		autoreap = true;
    	}
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    
    
    	tsk->exit_state = autoreap ? EXIT_DEAD : EXIT_ZOMBIE;
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    
    
    	/* mt-exec, de_thread() is waiting for group leader */
    	if (unlikely(tsk->signal->notify_count < 0))
    
    		wake_up_process(tsk->signal->group_exit_task);
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	write_unlock_irq(&tasklist_lock);
    
    	/* If the process is dead, release it - nobody will wait for it */
    
    	if (autoreap)
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    		release_task(tsk);
    }
    
    
    #ifdef CONFIG_DEBUG_STACK_USAGE
    static void check_stack_usage(void)
    {
    	static DEFINE_SPINLOCK(low_water_lock);
    	static int lowest_to_date = THREAD_SIZE;
    	unsigned long free;
    
    
    
    	if (free >= lowest_to_date)
    		return;
    
    	spin_lock(&low_water_lock);
    	if (free < lowest_to_date) {
    
    		printk(KERN_WARNING "%s (%d) used greatest stack depth: "
    				"%lu bytes left\n",
    				current->comm, task_pid_nr(current), free);
    
    		lowest_to_date = free;
    	}
    	spin_unlock(&low_water_lock);
    }
    #else
    static inline void check_stack_usage(void) {}
    #endif
    
    
    void do_exit(long code)
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    {
    	struct task_struct *tsk = current;
    	int group_dead;
    
    	profile_task_exit(tsk);
    
    
    	WARN_ON(blk_needs_flush_plug(tsk));
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	if (unlikely(in_interrupt()))
    		panic("Aiee, killing interrupt handler!");
    	if (unlikely(!tsk->pid))
    		panic("Attempted to kill the idle task!");
    
    
    	/*
    	 * If do_exit is called because this processes oopsed, it's possible
    	 * that get_fs() was left as KERNEL_DS, so reset it to USER_DS before
    	 * continuing. Amongst other possible reasons, this is to prevent
    	 * mm_release()->clear_child_tid() from writing to a user-controlled
    	 * kernel address.
    	 */
    	set_fs(USER_DS);
    
    
    	ptrace_event(PTRACE_EVENT_EXIT, code);
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    
    
    	validate_creds_for_do_exit(tsk);
    
    
    	/*
    	 * We're taking recursive faults here in do_exit. Safest is to just
    	 * leave this task alone and wait for reboot.
    	 */
    	if (unlikely(tsk->flags & PF_EXITING)) {
    		printk(KERN_ALERT
    			"Fixing recursive fault but reboot is needed!\n");
    
    		/*
    		 * We can do this unlocked here. The futex code uses
    		 * this flag just to verify whether the pi state
    		 * cleanup has been done or not. In the worst case it
    		 * loops once more. We pretend that the cleanup was
    		 * done as there is no way to return. Either the
    		 * OWNER_DIED bit is set by now or we push the blocked
    		 * task into the wait for ever nirwana as well.
    		 */
    		tsk->flags |= PF_EXITPIDONE;
    
    		set_current_state(TASK_UNINTERRUPTIBLE);
    		schedule();
    	}
    
    
    	exit_signals(tsk);  /* sets PF_EXITING */
    
    	/*
    	 * tsk->flags are checked in the futex code to protect against
    
    	 * an exiting task cleaning up the robust pi futexes.
    
    	raw_spin_unlock_wait(&tsk->pi_lock);
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    
    	if (unlikely(in_atomic()))
    		printk(KERN_INFO "note: %s[%d] exited with preempt_count %d\n",
    
    				current->comm, task_pid_nr(current),
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    				preempt_count());
    
    	acct_update_integrals(tsk);
    
    	/* sync mm's RSS info before statistics gathering */
    	if (tsk->mm)
    		sync_mm_rss(tsk->mm);
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	group_dead = atomic_dec_and_test(&tsk->signal->live);
    
    	if (group_dead) {
    
    		hrtimer_cancel(&tsk->signal->real_timer);
    
    		exit_itimers(tsk->signal);
    
    		if (tsk->mm)
    			setmax_mm_hiwater_rss(&tsk->signal->maxrss, tsk->mm);
    
    	if (group_dead)
    		tty_audit_exit();
    
    	taskstats_exit(tsk, group_dead);
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	exit_mm(tsk);
    
    
    	trace_sched_process_exit(tsk);
    
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	exit_sem(tsk);
    
    	exit_shm(tsk);
    
    	exit_task_namespaces(tsk);
    
    	exit_task_work(tsk);
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	exit_thread();
    
    
    	/*
    	 * Flush inherited counters to the parent - before the parent
    	 * gets woken up by child-exit notifications.
    	 *
    	 * because of cgroup mode, must be called before cgroup_exit()
    	 */
    	perf_event_exit_task(tsk);
    
    
    	cgroup_exit(tsk, 1);
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    
    
    	if (group_dead)
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    		disassociate_ctty(1);
    
    
    	module_put(task_thread_info(tsk)->exec_domain->module);
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    
    
    	proc_exit_connector(tsk);
    
    	/*
    	 * FIXME: do that only when needed, using sched_exit tracepoint
    	 */
    
    	ptrace_put_breakpoints(tsk);
    
    	exit_notify(tsk, group_dead);
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    #ifdef CONFIG_NUMA
    
    	mpol_put(tsk->mempolicy);
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	tsk->mempolicy = NULL;
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    #endif
    
    #ifdef CONFIG_FUTEX
    
    	if (unlikely(current->pi_state_cache))
    		kfree(current->pi_state_cache);
    
    	 * Make sure we are holding no locks:
    
    	debug_check_no_locks_held(tsk);
    
    	/*
    	 * We can do this unlocked here. The futex code uses this flag
    	 * just to verify whether the pi state cleanup has been done
    	 * or not. In the worst case it loops once more.
    	 */
    	tsk->flags |= PF_EXITPIDONE;
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    
    
    	if (tsk->splice_pipe)
    
    		free_pipe_info(tsk->splice_pipe);
    
    	if (tsk->task_frag.page)
    		put_page(tsk->task_frag.page);
    
    
    	validate_creds_for_do_exit(tsk);
    
    
    Coywolf Qi Hunt's avatar
    Coywolf Qi Hunt committed
    	preempt_disable();
    
    	if (tsk->nr_dirtied)
    		__this_cpu_add(dirty_throttle_leaks, tsk->nr_dirtied);
    
    
    	/*
    	 * The setting of TASK_RUNNING by try_to_wake_up() may be delayed
    	 * when the following two conditions become true.
    	 *   - There is race condition of mmap_sem (It is acquired by
    	 *     exit_mm()), and
    	 *   - SMI occurs before setting TASK_RUNINNG.
    	 *     (or hypervisor of virtual machine switches to other guest)
    	 *  As a result, we may become TASK_RUNNING after becoming TASK_DEAD
    	 *
    	 * To avoid it, we have to wait for releasing tsk->pi_lock which
    	 * is held by try_to_wake_up()
    	 */
    	smp_mb();
    	raw_spin_unlock_wait(&tsk->pi_lock);
    
    
    Oleg Nesterov's avatar
    Oleg Nesterov committed
    	/* causes final put_task_struct in finish_task_switch(). */
    
    	tsk->state = TASK_DEAD;
    
    	tsk->flags |= PF_NOFREEZE;	/* tell freezer to ignore us */
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	schedule();
    	BUG();
    	/* Avoid "noreturn function does return".  */
    
    Alan Cox's avatar
    Alan Cox committed
    	for (;;)
    		cpu_relax();	/* For when BUG is null */
    
    EXPORT_SYMBOL_GPL(do_exit);
    
    
    void complete_and_exit(struct completion *comp, long code)
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    {
    	if (comp)
    		complete(comp);
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	do_exit(code);
    }
    
    EXPORT_SYMBOL(complete_and_exit);
    
    
    SYSCALL_DEFINE1(exit, int, error_code)
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    {
    	do_exit((error_code&0xff)<<8);
    }
    
    /*
     * Take down every thread in the group.  This is called by fatal signals
     * as well as by sys_exit_group (below).
     */
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    do_group_exit(int exit_code)
    {
    
    	struct signal_struct *sig = current->signal;
    
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	BUG_ON(exit_code & 0x80); /* core dumps don't get here */
    
    
    	if (signal_group_exit(sig))
    		exit_code = sig->group_exit_code;
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	else if (!thread_group_empty(current)) {
    		struct sighand_struct *const sighand = current->sighand;
    		spin_lock_irq(&sighand->siglock);
    
    		if (signal_group_exit(sig))
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    			/* Another thread got here before we took the lock.  */
    			exit_code = sig->group_exit_code;
    		else {
    			sig->group_exit_code = exit_code;
    
    			sig->flags = SIGNAL_GROUP_EXIT;
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    			zap_other_threads(current);
    		}
    		spin_unlock_irq(&sighand->siglock);
    	}
    
    	do_exit(exit_code);
    	/* NOTREACHED */
    }
    
    /*
     * this kills every thread in the thread group. Note that any externally
     * wait4()-ing process will get the correct exit code - even if this
     * thread is not the thread group leader.
     */
    
    SYSCALL_DEFINE1(exit_group, int, error_code)
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    {
    	do_group_exit((error_code & 0xff) << 8);
    
    struct wait_opts {
    	enum pid_type		wo_type;
    	int			wo_flags;
    
    
    	struct siginfo __user	*wo_info;
    	int __user		*wo_stat;
    	struct rusage __user	*wo_rusage;
    
    
    static inline
    struct pid *task_pid_type(struct task_struct *task, enum pid_type type)
    
    	if (type != PIDTYPE_PID)
    		task = task->group_leader;
    	return task->pids[type].pid;
    
    static int eligible_pid(struct wait_opts *wo, struct task_struct *p)
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    {
    
    	return	wo->wo_type == PIDTYPE_MAX ||
    		task_pid_type(p, wo->wo_type) == wo->wo_pid;
    }
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    
    
    static int eligible_child(struct wait_opts *wo, struct task_struct *p)
    {
    	if (!eligible_pid(wo, p))
    		return 0;
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	/* Wait for all children (clone and not) if __WALL is set;
    	 * otherwise, wait for clone children *only* if __WCLONE is
    	 * set; otherwise, wait for non-clone children *only*.  (Note:
    	 * A "clone" child here is one that reports to its parent
    	 * using a signal other than SIGCHLD.) */
    
    	if (((p->exit_signal != SIGCHLD) ^ !!(wo->wo_flags & __WCLONE))
    	    && !(wo->wo_flags & __WALL))
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    		return 0;
    
    
    static int wait_noreap_copyout(struct wait_opts *wo, struct task_struct *p,
    				pid_t pid, uid_t uid, int why, int status)
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    {
    
    	struct siginfo __user *infop;
    	int retval = wo->wo_rusage
    		? getrusage(p, RUSAGE_BOTH, wo->wo_rusage) : 0;
    
    Linus Torvalds's avatar
    Linus Torvalds committed
    	put_task_struct(p);
    
    	if (infop) {
    		if (!retval)
    			retval = put_user(SIGCHLD, &infop->si_signo);
    		if (!retval)
    			retval = put_user(0, &infop->si_errno);
    		if (!retval)
    			retval = put_user((short)why, &infop->si_code);
    		if (!retval)
    			retval = put_user(pid, &infop->si_pid);
    		if (!retval)
    			retval = put_user(uid, &infop->si_uid);
    		if (!retval)
    			retval = put_user(status, &infop->si_status);