On Fri, Nov 29 2019, Martin Pieuchot <[email protected]> wrote:
> For archive, here's the diff on top of -current.

Here's a refreshed diff with the bare minimum changes needed to prevent
a WITNESS kernel from crashing when running /usr/src/regress/sys.


Index: kern/exec_elf.c
===================================================================
RCS file: /home/cvs/src/sys/kern/exec_elf.c,v
retrieving revision 1.166
diff -u -p -r1.166 exec_elf.c
--- kern/exec_elf.c     12 May 2022 16:29:58 -0000      1.166
+++ kern/exec_elf.c     27 Jun 2022 13:37:58 -0000
@@ -1185,12 +1185,14 @@ coredump_notes_elf(struct proc *p, void 
                cpi.cpi_sigcatch = pr->ps_sigacts->ps_sigcatch;
 
                cpi.cpi_pid = pr->ps_pid;
+               rw_enter_read(&proctreelk);
                cpi.cpi_ppid = pr->ps_ppid;
                cpi.cpi_pgrp = pr->ps_pgid;
                if (pr->ps_session->s_leader)
                        cpi.cpi_sid = pr->ps_session->s_leader->ps_pid;
                else
                        cpi.cpi_sid = 0;
+               rw_exit_read(&proctreelk);
 
                cpi.cpi_ruid = p->p_ucred->cr_ruid;
                cpi.cpi_euid = p->p_ucred->cr_uid;
Index: kern/kern_acct.c
===================================================================
RCS file: /home/cvs/src/sys/kern/kern_acct.c,v
retrieving revision 1.46
diff -u -p -r1.46 kern_acct.c
--- kern/kern_acct.c    22 Feb 2022 17:22:29 -0000      1.46
+++ kern/kern_acct.c    27 Jun 2022 13:37:58 -0000
@@ -226,11 +226,13 @@ acct_process(struct proc *p)
        acct.ac_gid = pr->ps_ucred->cr_rgid;
 
        /* (7) The terminal from which the process was started */
+       rw_enter_read(&proctreelk);
        if ((pr->ps_flags & PS_CONTROLT) &&
            pr->ps_pgrp->pg_session->s_ttyp)
                acct.ac_tty = pr->ps_pgrp->pg_session->s_ttyp->t_dev;
        else
                acct.ac_tty = -1;
+       rw_exit_read(&proctreelk);
 
        /* (8) The boolean flags that tell how process terminated or 
misbehaved. */
        acct.ac_flag = pr->ps_acflag;
Index: kern/kern_exec.c
===================================================================
RCS file: /home/cvs/src/sys/kern/kern_exec.c,v
retrieving revision 1.230
diff -u -p -r1.230 kern_exec.c
--- kern/kern_exec.c    22 Feb 2022 17:14:14 -0000      1.230
+++ kern/kern_exec.c    27 Jun 2022 13:37:58 -0000
@@ -520,9 +520,11 @@ sys_execve(struct proc *p, void *v, regi
 
        atomic_setbits_int(&pr->ps_flags, PS_EXEC);
        if (pr->ps_flags & PS_PPWAIT) {
+               rw_enter_read(&proctreelk);
                atomic_clearbits_int(&pr->ps_flags, PS_PPWAIT);
                atomic_clearbits_int(&pr->ps_pptr->ps_flags, PS_ISPWAIT);
                wakeup(pr->ps_pptr);
+               rw_exit_read(&proctreelk);
        }
 
        /*
Index: kern/kern_exit.c
===================================================================
RCS file: /home/cvs/src/sys/kern/kern_exit.c,v
retrieving revision 1.203
diff -u -p -r1.203 kern_exit.c
--- kern/kern_exit.c    31 Mar 2022 01:41:22 -0000      1.203
+++ kern/kern_exit.c    27 Jun 2022 13:37:58 -0000
@@ -154,6 +154,7 @@ exit1(struct proc *p, int xexit, int xsi
                 * is set; we wake up the parent early to avoid deadlock.
                 */
                if (pr->ps_flags & PS_PPWAIT) {
+                       /* XXXPT `proctreelk` ? */
                        atomic_clearbits_int(&pr->ps_flags, PS_PPWAIT);
                        atomic_clearbits_int(&pr->ps_pptr->ps_flags,
                            PS_ISPWAIT);
@@ -222,6 +223,7 @@ exit1(struct proc *p, int xexit, int xsi
                 * If parent has the SAS_NOCLDWAIT flag set, we're not
                 * going to become a zombie.
                 */
+               /* XXXPT `proctreelk` ? */
                if (pr->ps_pptr->ps_sigacts->ps_sigflags & SAS_NOCLDWAIT)
                        atomic_setbits_int(&pr->ps_flags, PS_NOZOMBIE);
        }
@@ -236,11 +238,7 @@ exit1(struct proc *p, int xexit, int xsi
         * thread of a process that isn't PS_NOZOMBIE, we'll put
         * the process on the zombprocess list below.
         */
-       /*
-        * NOTE: WE ARE NO LONGER ALLOWED TO SLEEP!
-        */
-       p->p_stat = SDEAD;
-
+       rw_enter_write(&proctreelk);
        LIST_REMOVE(p, p_hash);
        LIST_REMOVE(p, p_list);
 
@@ -300,6 +298,7 @@ exit1(struct proc *p, int xexit, int xsi
                        process_clear_orphan(qr);
                }
        }
+       rw_exit_write(&proctreelk);
 
        /* add thread's accumulated rusage into the process's total */
        ruadd(rup, &p->p_ru);
@@ -325,9 +324,13 @@ exit1(struct proc *p, int xexit, int xsi
                 * wait4() to return ECHILD.
                 */
                if (pr->ps_flags & PS_NOZOMBIE) {
-                       struct process *ppr = pr->ps_pptr;
+                       struct process *ppr;
+
+                       rw_enter_write(&proctreelk);
+                       ppr = pr->ps_pptr;
                        process_reparent(pr, initprocess);
                        wakeup(ppr);
+                       rw_exit_write(&proctreelk);
                }
        }
 
@@ -349,6 +352,11 @@ exit1(struct proc *p, int xexit, int xsi
        }
 
        /*
+        * NOTE: WE ARE NO LONGER ALLOWED TO SLEEP!
+        */
+       p->p_stat = SDEAD;
+
+       /*
         * Other substructures are freed from reaper and wait().
         */
 
@@ -451,6 +459,7 @@ reaper(void *arg)
                        /* Release the rest of the process's vmspace */
                        uvm_exit(pr);
 
+                       rw_enter_write(&proctreelk);
                        if ((pr->ps_flags & PS_NOZOMBIE) == 0) {
                                /* Process is now a true zombie. */
                                atomic_setbits_int(&pr->ps_flags, PS_ZOMBIE);
@@ -463,8 +472,14 @@ reaper(void *arg)
                                /* Post SIGCHLD and wake up parent. */
                                prsignal(pr->ps_pptr, SIGCHLD);
                                wakeup(pr->ps_pptr);
+                               rw_exit_write(&proctreelk);
                        } else {
-                               /* No one will wait for us, just zap it. */
+                               /*
+                                * No one will wait for us. Just zap the
+                                * process now.
+                                *
+                                * Release `proctreelk' for us.
+                                */
                                process_zap(pr);
                        }
                }
@@ -510,12 +525,12 @@ dowait4(struct proc *q, pid_t pid, int *
        struct proc *p;
        int error;
 
-       if (pid == 0)
-               pid = -q->p_p->ps_pgid;
        if (options &~ (WUNTRACED|WNOHANG|WCONTINUED))
                return (EINVAL);
-
 loop:
+       rw_enter_write(&proctreelk);
+       if (pid == 0)
+               pid = -q->p_p->ps_pgid;
        nfound = 0;
        LIST_FOREACH(pr, &q->p_p->ps_children, ps_sibling) {
                if ((pr->ps_flags & PS_NOZOMBIE) ||
@@ -535,6 +550,7 @@ loop:
                                    pr->ps_xsig);
                        if (rusage != NULL)
                                memcpy(rusage, pr->ps_ru, sizeof(*rusage));
+                       /* Release `proctreelk' for us */
                        proc_finish_wait(q, p);
                        return (0);
                }
@@ -542,6 +558,7 @@ loop:
                    (pr->ps_flags & PS_WAITED) == 0 && pr->ps_single &&
                    pr->ps_single->p_stat == SSTOP &&
                    (pr->ps_single->p_flag & P_SUSPSINGLE) == 0) {
+                       rw_exit_write(&proctreelk);
                        if (single_thread_wait(pr, 0))
                                goto loop;
 
@@ -566,6 +583,7 @@ loop:
                                *statusp = W_STOPCODE(pr->ps_xsig);
                        if (rusage != NULL)
                                memset(rusage, 0, sizeof(*rusage));
+                       rw_exit_write(&proctreelk);
                        return (0);
                }
                if ((options & WCONTINUED) && (p->p_flag & P_CONTINUED)) {
@@ -576,6 +594,7 @@ loop:
                                *statusp = _WCONTINUED;
                        if (rusage != NULL)
                                memset(rusage, 0, sizeof(*rusage));
+                       rw_exit_write(&proctreelk);
                        return (0);
                }
        }
@@ -602,13 +621,18 @@ loop:
                        break;
                }
        }
-       if (nfound == 0)
-               return (ECHILD);
+       if (nfound == 0) {
+               rw_exit_write(&proctreelk);
+               return (ECHILD);
+       }
        if (options & WNOHANG) {
+               rw_exit_write(&proctreelk);
                retval[0] = 0;
                return (0);
        }
-       if ((error = tsleep_nsec(q->p_p, PWAIT | PCATCH, "wait", INFSLP)) != 0)
+       error = rwsleep(q->p_p, &proctreelk, PWAIT | PCATCH | PNORELOCK, "wait",
+           0);
+       if (error != 0)
                return (error);
        goto loop;
 }
@@ -619,6 +643,8 @@ proc_finish_wait(struct proc *waiter, st
        struct process *pr, *tr;
        struct rusage *rup;
 
+       rw_assert_wrlock(&proctreelk);
+
        /*
         * If we got the child via a ptrace 'attach',
         * we need to give it back to the old parent.
@@ -631,12 +657,14 @@ proc_finish_wait(struct proc *waiter, st
                process_reparent(pr, tr);
                prsignal(tr, SIGCHLD);
                wakeup(tr);
+               rw_exit_write(&proctreelk);
        } else {
                scheduler_wait_hook(waiter, p);
                rup = &waiter->p_p->ps_cru;
                ruadd(rup, pr->ps_ru);
                LIST_REMOVE(pr, ps_list);       /* off zombprocess */
                freepid(pr->ps_pid);
+               /* Release `proctreelk' for us */
                process_zap(pr);
        }
 }
@@ -677,6 +705,7 @@ void
 process_reparent(struct process *child, struct process *parent)
 {
 
+       rw_assert_wrlock(&proctreelk);
        if (child->ps_pptr == parent)
                return;
 
@@ -702,6 +731,8 @@ process_zap(struct process *pr)
        struct vnode *otvp;
        struct proc *p = pr->ps_mainproc;
 
+       rw_assert_wrlock(&proctreelk);
+
        /*
         * Finally finished with old proc entry.
         * Unlink it from its process group and free it.
@@ -709,6 +740,7 @@ process_zap(struct process *pr)
        leavepgrp(pr);
        LIST_REMOVE(pr, ps_sibling);
        process_clear_orphan(pr);
+       rw_exit_write(&proctreelk);
 
        /*
         * Decrement the count of procs running with this uid.
Index: kern/kern_fork.c
===================================================================
RCS file: /home/cvs/src/sys/kern/kern_fork.c,v
retrieving revision 1.240
diff -u -p -r1.240 kern_fork.c
--- kern/kern_fork.c    13 May 2022 15:32:00 -0000      1.240
+++ kern/kern_fork.c    27 Jun 2022 13:37:58 -0000
@@ -229,7 +229,6 @@ process_new(struct proc *p, struct proce
            (caddr_t)&pr->ps_endcopy - (caddr_t)&pr->ps_startcopy);
 
        process_initialize(pr, p);
-       pr->ps_pid = allocpid();
        lim_fork(parent, pr);
 
        /* post-copy fixups */
@@ -246,8 +245,6 @@ process_new(struct proc *p, struct proce
 
        pr->ps_flags = parent->ps_flags &
            (PS_SUGID | PS_SUGIDEXEC | PS_PLEDGE | PS_EXECPLEDGE | PS_WXNEEDED);
-       if (parent->ps_session->s_ttyvp != NULL)
-               pr->ps_flags |= parent->ps_flags & PS_CONTROLT;
 
        /*
         * Duplicate sub-structures as needed.
@@ -275,10 +272,11 @@ process_new(struct proc *p, struct proce
        /* mark as embryo to protect against others */
        pr->ps_flags |= PS_EMBRYO;
 
-       /* Force visibility of all of the above changes */
-       membar_producer();
-
        /* it's sufficiently inited to be globally visible */
+       rw_enter_write(&proctreelk);
+       if (parent->ps_session->s_ttyvp != NULL)
+               pr->ps_flags |= parent->ps_flags & PS_CONTROLT;
+       pr->ps_pid = allocpid();
        LIST_INSERT_HEAD(&allprocess, pr, ps_list);
 
        return pr;
@@ -378,6 +376,7 @@ fork1(struct proc *curp, int flags, void
 
        /*
         * From now on, we're committed to the fork and cannot fail.
+        * process_new() returns with proctreelk held!
         */
        p = thread_new(curp, uaddr);
        pr = process_new(p, curpr, flags);
@@ -451,6 +450,7 @@ fork1(struct proc *curp, int flags, void
                        pr->ps_ptstat->pe_other_pid = curpr->ps_pid;
                }
        }
+       rw_exit_write(&proctreelk);
 
        /*
         * For new processes, set accounting bits and mark as complete.
Index: kern/kern_ktrace.c
===================================================================
RCS file: /home/cvs/src/sys/kern/kern_ktrace.c,v
retrieving revision 1.106
diff -u -p -r1.106 kern_ktrace.c
--- kern/kern_ktrace.c  22 Feb 2022 17:14:14 -0000      1.106
+++ kern/kern_ktrace.c  27 Jun 2022 13:37:58 -0000
@@ -465,6 +465,7 @@ doktrace(struct vnode *vp, int ops, int 
        /*
         * do it
         */
+       rw_enter_read(&proctreelk);
        if (pid < 0) {
                /*
                 * by process group
@@ -472,7 +473,7 @@ doktrace(struct vnode *vp, int ops, int 
                pg = pgfind(-pid);
                if (pg == NULL) {
                        error = ESRCH;
-                       goto done;
+                       goto done2;
                }
                LIST_FOREACH(pr, &pg->pg_members, ps_pglist) {
                        if (descend)
@@ -488,7 +489,7 @@ doktrace(struct vnode *vp, int ops, int 
                pr = prfind(pid);
                if (pr == NULL) {
                        error = ESRCH;
-                       goto done;
+                       goto done2;
                }
                if (descend)
                        ret |= ktrsetchildren(p, pr, ops, facs, vp, cred);
@@ -497,6 +498,8 @@ doktrace(struct vnode *vp, int ops, int 
        }
        if (!ret)
                error = EPERM;
+done2:
+       rw_exit_read(&proctreelk);
 done:
        return (error);
 }
@@ -566,6 +569,8 @@ ktrsetchildren(struct proc *curp, struct
 {
        struct process *pr;
        int ret = 0;
+
+       rw_assert_rdlock(&proctreelk);
 
        pr = top;
        for (;;) {
Index: kern/kern_proc.c
===================================================================
RCS file: /home/cvs/src/sys/kern/kern_proc.c,v
retrieving revision 1.91
diff -u -p -r1.91 kern_proc.c
--- kern/kern_proc.c    24 Oct 2021 00:02:25 -0000      1.91
+++ kern/kern_proc.c    27 Jun 2022 13:37:58 -0000
@@ -67,6 +67,7 @@ u_long pgrphash;
 struct processlist allprocess;
 struct processlist zombprocess;
 struct proclist allproc;
+struct rwlock proctreelk;
 
 struct pool proc_pool;
 struct pool process_pool;
@@ -79,9 +80,6 @@ void  pgdelete(struct pgrp *);
 void   fixjobc(struct process *, struct pgrp *, int);
 
 static void orphanpg(struct pgrp *);
-#ifdef DEBUG
-void pgrpdump(void);
-#endif
 
 /*
  * Initialize global process hashing structures.
@@ -93,6 +91,7 @@ procinit(void)
        LIST_INIT(&zombprocess);
        LIST_INIT(&allproc);
 
+       rw_init(&proctreelk, "proctree");
        rw_init(&uidinfolk, "uidinfo");
 
        tidhashtbl = hashinit(maxthread / 4, M_PROC, M_NOWAIT, &tidhash);
@@ -180,6 +179,7 @@ int
 inferior(struct process *pr, struct process *parent)
 {
 
+       rw_assert_wrlock(&proctreelk);
        for (; pr != parent; pr = pr->ps_pptr)
                if (pr->ps_pid == 0 || pr->ps_pid == 1)
                        return (0);
@@ -222,6 +222,7 @@ pgfind(pid_t pgid)
 {
        struct pgrp *pgrp;
 
+       rw_assert_anylock(&proctreelk);
        LIST_FOREACH(pgrp, PGRPHASH(pgid), pg_hash)
                if (pgrp->pg_id == pgid)
                        return (pgrp);
@@ -250,6 +251,8 @@ zombiefind(pid_t pid)
 void
 enternewpgrp(struct process *pr, struct pgrp *pgrp, struct session *newsess)
 {
+       rw_assert_wrlock(&proctreelk);
+
 #ifdef DIAGNOSTIC
        if (SESS_LEADER(pr))
                panic("%s: session leader attempted setpgrp", __func__);
@@ -293,6 +296,8 @@ enterthispgrp(struct process *pr, struct
 {
        struct pgrp *savepgrp = pr->ps_pgrp;
 
+       rw_assert_wrlock(&proctreelk);
+
        /*
         * Adjust eligibility of affected pgrps to participate in job control.
         * Increment eligibility counts before decrementing, otherwise we
@@ -303,6 +308,7 @@ enterthispgrp(struct process *pr, struct
 
        LIST_REMOVE(pr, ps_pglist);
        pr->ps_pgrp = pgrp;
+
        LIST_INSERT_HEAD(&pgrp->pg_members, pr, ps_pglist);
        if (LIST_EMPTY(&savepgrp->pg_members))
                pgdelete(savepgrp);
@@ -315,6 +321,7 @@ void
 leavepgrp(struct process *pr)
 {
 
+       rw_assert_wrlock(&proctreelk);
        if (pr->ps_session->s_verauthppid == pr->ps_pid)
                zapverauth(pr->ps_session);
        LIST_REMOVE(pr, ps_pglist);
@@ -331,6 +338,7 @@ pgdelete(struct pgrp *pgrp)
 {
        sigio_freelist(&pgrp->pg_sigiolst);
 
+       rw_assert_wrlock(&proctreelk);
        if (pgrp->pg_session->s_ttyp != NULL && 
            pgrp->pg_session->s_ttyp->t_pgrp == pgrp)
                pgrp->pg_session->s_ttyp->t_pgrp = NULL;
@@ -343,6 +351,9 @@ void
 zapverauth(void *v)
 {
        struct session *sess = v;
+
+       rw_assert_wrlock(&proctreelk);
+
        sess->s_verauthuid = 0;
        sess->s_verauthppid = 0;
 }
@@ -364,6 +375,8 @@ fixjobc(struct process *pr, struct pgrp 
        struct pgrp *hispgrp;
        struct session *mysession = pgrp->pg_session;
 
+       rw_assert_wrlock(&proctreelk);
+
        /*
         * Check pr's parent to see whether pr qualifies its own process
         * group; if so, adjust count for pr's process group.
@@ -395,6 +408,7 @@ fixjobc(struct process *pr, struct pgrp 
 void
 killjobc(struct process *pr)
 {
+       rw_enter_write(&proctreelk);
        if (SESS_LEADER(pr)) {
                struct session *sp = pr->ps_session;
 
@@ -410,7 +424,9 @@ killjobc(struct process *pr)
                        if (sp->s_ttyp->t_session == sp) {
                                if (sp->s_ttyp->t_pgrp)
                                        pgsignal(sp->s_ttyp->t_pgrp, SIGHUP, 1);
+                               rw_exit_write(&proctreelk);
                                ttywait(sp->s_ttyp);
+                               rw_enter_write(&proctreelk);
                                /*
                                 * The tty could have been revoked
                                 * if we blocked.
@@ -432,6 +448,7 @@ killjobc(struct process *pr)
                sp->s_leader = NULL;
        }
        fixjobc(pr, pr->ps_pgrp, 0);
+       rw_exit_write(&proctreelk);
 }
 
 /* 
@@ -444,6 +461,7 @@ orphanpg(struct pgrp *pg)
 {
        struct process *pr;
 
+       rw_assert_wrlock(&proctreelk);
        LIST_FOREACH(pr, &pg->pg_members, ps_pglist) {
                if (pr->ps_mainproc->p_stat == SSTOP) {
                        LIST_FOREACH(pr, &pg->pg_members, ps_pglist) {
@@ -629,29 +647,3 @@ db_show_all_procs(db_expr_t addr, int ha
        }
 }
 #endif
-
-#ifdef DEBUG
-void
-pgrpdump(void)
-{
-       struct pgrp *pgrp;
-       struct process *pr;
-       int i;
-
-       for (i = 0; i <= pgrphash; i++) {
-               if (!LIST_EMPTY(&pgrphashtbl[i])) {
-                       printf("\tindx %d\n", i);
-                       LIST_FOREACH(pgrp, &pgrphashtbl[i], pg_hash) {
-                               printf("\tpgrp %p, pgid %d, sess %p, sesscnt 
%d, mem %p\n",
-                                   pgrp, pgrp->pg_id, pgrp->pg_session,
-                                   pgrp->pg_session->s_count,
-                                   LIST_FIRST(&pgrp->pg_members));
-                               LIST_FOREACH(pr, &pgrp->pg_members, ps_pglist) {
-                                       printf("\t\tpid %d addr %p pgrp %p\n", 
-                                           pr->ps_pid, pr, pr->ps_pgrp);
-                               }
-                       }
-               }
-       }
-}
-#endif /* DEBUG */
Index: kern/kern_prot.c
===================================================================
RCS file: /home/cvs/src/sys/kern/kern_prot.c,v
retrieving revision 1.79
diff -u -p -r1.79 kern_prot.c
--- kern/kern_prot.c    17 Mar 2022 14:23:34 -0000      1.79
+++ kern/kern_prot.c    27 Jun 2022 13:37:58 -0000
@@ -93,7 +93,9 @@ int
 sys_getpgrp(struct proc *p, void *v, register_t *retval)
 {
 
+       rw_enter_read(&proctreelk);
        *retval = p->p_p->ps_pgrp->pg_id;
+       rw_exit_read(&proctreelk);
        return (0);
 }
 
@@ -107,16 +109,23 @@ sys_getpgid(struct proc *curp, void *v, 
                syscallarg(pid_t) pid;
        } */ *uap = v;
        struct process *targpr = curp->p_p;
+       int error = 0;
 
-       if (SCARG(uap, pid) == 0 || SCARG(uap, pid) == targpr->ps_pid)
-               goto found;
+       if (SCARG(uap, pid) == 0 || SCARG(uap, pid) == targpr->ps_pid) {
+               rw_enter_read(&proctreelk);
+               *retval = targpr->ps_pgid;
+               rw_exit_read(&proctreelk);
+               return 0;
+       }
+       rw_enter_read(&proctreelk);
        if ((targpr = prfind(SCARG(uap, pid))) == NULL)
-               return (ESRCH);
-       if (targpr->ps_session != curp->p_p->ps_session)
-               return (EPERM);
-found:
-       *retval = targpr->ps_pgid;
-       return (0);
+               error = ESRCH;
+       else if (targpr->ps_session != curp->p_p->ps_session)
+               error = EPERM;
+       else
+               *retval = targpr->ps_pgid;
+       rw_exit_read(&proctreelk);
+       return error;
 }
 
 int
@@ -126,19 +135,28 @@ sys_getsid(struct proc *curp, void *v, r
                syscallarg(pid_t) pid;
        } */ *uap = v;
        struct process *targpr = curp->p_p;
+       int error = 0;
+
+       rw_enter_read(&proctreelk);
+       if (SCARG(uap, pid) != 0 && SCARG(uap, pid) != targpr->ps_pid) {
+               if ((targpr = prfind(SCARG(uap, pid))) == NULL) {
+                       error = ESRCH;
+                       goto out;
+               }
+               if (targpr->ps_session != curp->p_p->ps_session) {
+                       error = EPERM;
+                       goto out;
+               }
+       }
 
-       if (SCARG(uap, pid) == 0 || SCARG(uap, pid) == targpr->ps_pid)
-               goto found;
-       if ((targpr = prfind(SCARG(uap, pid))) == NULL)
-               return (ESRCH);
-       if (targpr->ps_session != curp->p_p->ps_session)
-               return (EPERM);
-found:
        /* Skip exiting processes */
        if (targpr->ps_pgrp->pg_session->s_leader == NULL)
-               return (ESRCH);
-       *retval = targpr->ps_pgrp->pg_session->s_leader->ps_pid;
-       return (0);
+               error = ESRCH;
+       else
+               *retval = targpr->ps_pgrp->pg_session->s_leader->ps_pid;
+out:
+       rw_exit_read(&proctreelk);
+       return error;
 }
 
 int
@@ -225,12 +243,15 @@ sys_setsid(struct proc *p, void *v, regi
        newsess = pool_get(&session_pool, PR_WAITOK);
        newpgrp = pool_get(&pgrp_pool, PR_WAITOK);
 
+       rw_enter_write(&proctreelk);
        if (pr->ps_pgid == pid || pgfind(pid) != NULL) {
+               rw_exit_write(&proctreelk);
                pool_put(&pgrp_pool, newpgrp);
                pool_put(&session_pool, newsess);
                return (EPERM);
        } else {
                enternewpgrp(pr, newpgrp, newsess);
+               rw_exit_write(&proctreelk);
                *retval = pid;
                return (0);
        }
@@ -270,6 +291,7 @@ sys_setpgid(struct proc *curp, void *v, 
 
        newpgrp = pool_get(&pgrp_pool, PR_WAITOK);
 
+       rw_enter_write(&proctreelk);
        if (pid != 0 && pid != curpr->ps_pid) {
                if ((targpr = prfind(pid)) == NULL ||
                    !inferior(targpr, curpr)) {
@@ -309,7 +331,8 @@ sys_setpgid(struct proc *curp, void *v, 
                else
                        enterthispgrp(targpr, pgrp);
        }
- out:
+out:
+       rw_exit_write(&proctreelk);
        if (newpgrp != NULL)
                pool_put(&pgrp_pool, newpgrp);
        return (error);
@@ -1030,12 +1053,17 @@ sys_getlogin_r(struct proc *p, void *v, 
                syscallarg(size_t) namelen;
        } */ *uap = v;
        size_t namelen = SCARG(uap, namelen);
-       struct session *s = p->p_p->ps_pgrp->pg_session;
+       struct session *s;
+       char buf[sizeof(s->s_login)];
        int error;
 
+       rw_enter_read(&proctreelk);
+       s = p->p_p->ps_pgrp->pg_session;
        if (namelen > sizeof(s->s_login))
                namelen = sizeof(s->s_login);
-       error = copyoutstr(s->s_login, SCARG(uap, namebuf), namelen, NULL);
+       namelen = strlcpy(buf, s->s_login, namelen) + 1;
+       rw_exit_read(&proctreelk);
+       error = copyoutstr(buf, SCARG(uap, namebuf), namelen, NULL);
        if (error == ENAMETOOLONG)
                error = ERANGE;
        *retval = error;
@@ -1051,15 +1079,19 @@ sys_setlogin(struct proc *p, void *v, re
        struct sys_setlogin_args /* {
                syscallarg(const char *) namebuf;
        } */ *uap = v;
-       struct session *s = p->p_p->ps_pgrp->pg_session;
+       struct session *s;
        char buf[sizeof(s->s_login)];
        int error;
 
        if ((error = suser(p)) != 0)
                return (error);
        error = copyinstr(SCARG(uap, namebuf), buf, sizeof(buf), NULL);
-       if (error == 0)
+       if (error == 0) {
+               rw_enter_write(&proctreelk);
+               s = p->p_p->ps_pgrp->pg_session;
                strlcpy(s->s_login, buf, sizeof(s->s_login));
+               rw_exit_write(&proctreelk);
+       }
        else if (error == ENAMETOOLONG)
                error = EINVAL;
        return (error);
Index: kern/kern_resource.c
===================================================================
RCS file: /home/cvs/src/sys/kern/kern_resource.c,v
retrieving revision 1.74
diff -u -p -r1.74 kern_resource.c
--- kern/kern_resource.c        28 May 2022 03:47:43 -0000      1.74
+++ kern/kern_resource.c        27 Jun 2022 13:37:58 -0000
@@ -108,13 +108,17 @@ sys_getpriority(struct proc *curp, void 
        case PRIO_PGRP: {
                struct pgrp *pg;
 
+               rw_enter_read(&proctreelk);
                if (SCARG(uap, who) == 0)
                        pg = curp->p_p->ps_pgrp;
-               else if ((pg = pgfind(SCARG(uap, who))) == NULL)
+               else if ((pg = pgfind(SCARG(uap, who))) == NULL) {
+                       rw_exit_read(&proctreelk);
                        break;
+               }
                LIST_FOREACH(pr, &pg->pg_members, ps_pglist)
                        if (pr->ps_nice < low)
                                low = pr->ps_nice;
+               rw_exit_read(&proctreelk);
                break;
        }
 
@@ -163,14 +167,18 @@ sys_setpriority(struct proc *curp, void 
        case PRIO_PGRP: {
                struct pgrp *pg;
                 
+               rw_enter_read(&proctreelk);
                if (SCARG(uap, who) == 0)
                        pg = curp->p_p->ps_pgrp;
-               else if ((pg = pgfind(SCARG(uap, who))) == NULL)
-                       break;
+               else if ((pg = pgfind(SCARG(uap, who))) == NULL) {
+                       rw_exit_read(&proctreelk);
+                       break;
+               }
                LIST_FOREACH(pr, &pg->pg_members, ps_pglist) {
                        error = donice(curp, pr, SCARG(uap, prio));
                        found = 1;
                }
+               rw_exit_read(&proctreelk);
                break;
        }
 
Index: kern/kern_sig.c
===================================================================
RCS file: /home/cvs/src/sys/kern/kern_sig.c,v
retrieving revision 1.296
diff -u -p -r1.296 kern_sig.c
--- kern/kern_sig.c     13 May 2022 15:32:00 -0000      1.296
+++ kern/kern_sig.c     27 Jun 2022 13:41:36 -0000
@@ -165,6 +165,7 @@ cansignal(struct proc *p, struct process
        if (uc == quc)
                return (1);
 
+       rw_assert_rdlock(&proctreelk);
        if (signum == SIGCONT && qr->ps_session == pr->ps_session)
                return (1);             /* SIGCONT in session */
 
@@ -597,7 +598,7 @@ sys_kill(struct proc *cp, void *v, regis
        struct process *pr;
        int pid = SCARG(uap, pid);
        int signum = SCARG(uap, signum);
-       int error;
+       int error, cansig;
        int zombie = 0;
 
        if ((error = pledge_kill(cp, pid)) != 0)
@@ -611,7 +612,10 @@ sys_kill(struct proc *cp, void *v, regis
                        else
                                zombie = 1;
                }
-               if (!cansignal(cp, pr, signum))
+               rw_enter_read(&proctreelk);
+               cansig = cansignal(cp, pr, signum);
+               rw_exit_read(&proctreelk);
+               if (!cansig)
                        return (EPERM);
 
                /* kill single process */
@@ -681,6 +685,7 @@ killpg1(struct proc *cp, int signum, int
                /* 
                 * broadcast
                 */
+               rw_enter_read(&proctreelk);
                LIST_FOREACH(pr, &allprocess, ps_list) {
                        if (pr->ps_pid <= 1 ||
                            pr->ps_flags & (PS_SYSTEM | PS_NOBROADCASTKILL) ||
@@ -690,7 +695,9 @@ killpg1(struct proc *cp, int signum, int
                        if (signum)
                                prsignal(pr, signum);
                }
+               rw_exit_read(&proctreelk);
        } else {
+               rw_enter_read(&proctreelk);
                if (pgid == 0)
                        /*
                         * zero pgid means send to my process group.
@@ -698,8 +705,10 @@ killpg1(struct proc *cp, int signum, int
                        pgrp = cp->p_p->ps_pgrp;
                else {
                        pgrp = pgfind(pgid);
-                       if (pgrp == NULL)
+                       if (pgrp == NULL) {
+                               rw_exit_read(&proctreelk);
                                return (ESRCH);
+                       }
                }
                LIST_FOREACH(pr, &pgrp->pg_members, ps_pglist) {
                        if (pr->ps_pid <= 1 || pr->ps_flags & PS_SYSTEM ||
@@ -709,6 +718,7 @@ killpg1(struct proc *cp, int signum, int
                        if (signum)
                                prsignal(pr, signum);
                }
+               rw_exit_read(&proctreelk);
        }
        return (nfound ? 0 : ESRCH);
 }
@@ -734,6 +744,12 @@ pgsignal(struct pgrp *pgrp, int signum, 
 {
        struct process *pr;
 
+       /*
+        * XXXPT `pg_members' needs to be protected but this can be called
+        * from interrupt context.
+        */
+       //rw_assert_wrlock(&proctreelk)
+
        if (pgrp)
                LIST_FOREACH(pr, &pgrp->pg_members, ps_pglist)
                        if (checkctty == 0 || pr->ps_flags & PS_CONTROLT)
@@ -1459,6 +1475,7 @@ proc_stop_sweep(void *v)
 {
        struct process *pr;
 
+       rw_enter_read(&proctreelk);
        LIST_FOREACH(pr, &allprocess, ps_list) {
                if ((pr->ps_flags & PS_STOPPED) == 0)
                        continue;
@@ -1468,6 +1485,7 @@ proc_stop_sweep(void *v)
                        prsignal(pr->ps_pptr, SIGCHLD);
                wakeup(pr->ps_pptr);
        }
+       rw_exit_read(&proctreelk);
 }
 
 /*
@@ -2321,6 +2339,7 @@ sigio_setown(struct sigio_ref *sir, u_lo
         * not disappear unexpectedly.
         */
        KERNEL_LOCK();
+       rw_enter_read(&proctreelk);
        mtx_enter(&sigio_lock);
 
        if (pgid > 0) {
@@ -2380,6 +2399,7 @@ sigio_setown(struct sigio_ref *sir, u_lo
        sir->sir_sigio = sigio;
 
        mtx_leave(&sigio_lock);
+       rw_exit_read(&proctreelk);
        KERNEL_UNLOCK();
 
        sigio_del(&rmlist);
@@ -2388,6 +2408,7 @@ sigio_setown(struct sigio_ref *sir, u_lo
 
 fail:
        mtx_leave(&sigio_lock);
+       rw_exit_read(&proctreelk);
        KERNEL_UNLOCK();
 
        crfree(sigio->sio_ucred);
Index: kern/kern_sysctl.c
===================================================================
RCS file: /home/cvs/src/sys/kern/kern_sysctl.c,v
retrieving revision 1.402
diff -u -p -r1.402 kern_sysctl.c
--- kern/kern_sysctl.c  21 Mar 2022 09:12:34 -0000      1.402
+++ kern/kern_sysctl.c  27 Jun 2022 13:37:58 -0000
@@ -1521,6 +1521,7 @@ sysctl_doproc(int *name, u_int namelen, 
        if (where != NULL)
                kproc = malloc(sizeof(*kproc), M_TEMP, M_WAITOK);
 
+       rw_enter_read(&proctreelk);
        pr = LIST_FIRST(&allprocess);
        doingzomb = 0;
 again:
@@ -1559,6 +1560,7 @@ again:
                        break;
 
                case KERN_PROC_TTY:
+                       /* XXXPT proctreelk? */
                        if ((pr->ps_flags & PS_CONTROLT) == 0 ||
                            pr->ps_session->s_ttyp == NULL ||
                            pr->ps_session->s_ttyp->t_dev != (dev_t)arg)
@@ -1622,6 +1624,7 @@ again:
                doingzomb++;
                goto again;
        }
+       rw_exit_read(&proctreelk);
        if (where != NULL) {
                *sizep = dp - where;
                if (needed > *sizep) {
@@ -1650,6 +1653,8 @@ fill_kproc(struct process *pr, struct ki
        struct vmspace *vm = pr->ps_vmspace;
        struct timespec booted, st, ut, utc;
        int isthread;
+
+       rw_assert_rdlock(&proctreelk);
 
        isthread = p != NULL;
        if (!isthread)
Index: kern/subr_prf.c
===================================================================
RCS file: /home/cvs/src/sys/kern/subr_prf.c,v
retrieving revision 1.105
diff -u -p -r1.105 subr_prf.c
--- kern/subr_prf.c     20 Jan 2022 17:11:30 -0000      1.105
+++ kern/subr_prf.c     27 Jun 2022 13:37:58 -0000
@@ -390,6 +390,7 @@ uprintf(const char *fmt, ...)
        struct process *pr = curproc->p_p;
        va_list ap;
 
+       /* XXXPT proctreelk? */
        if (pr->ps_flags & PS_CONTROLT && pr->ps_session->s_ttyvp) {
                va_start(ap, fmt);
                kprintf(fmt, TOTTY, pr->ps_session->s_ttyp, NULL, ap);
Index: kern/sys_process.c
===================================================================
RCS file: /home/cvs/src/sys/kern/sys_process.c,v
retrieving revision 1.89
diff -u -p -r1.89 sys_process.c
--- kern/sys_process.c  7 Dec 2021 04:19:24 -0000       1.89
+++ kern/sys_process.c  27 Jun 2022 13:37:58 -0000
@@ -277,16 +277,24 @@ ptrace_ctrl(struct proc *p, int req, pid
        struct proc *t;                         /* target thread */
        struct process *tr;                     /* target process */
        int error = 0;
+       int proctree_locked;
        int s;
 
+       /* Lock proctree before looking up the process. */
+       rw_enter_write(&proctreelk);
+       proctree_locked = 1;
+
        switch (req) {
        case PT_TRACE_ME:
                /* Just set the trace flag. */
                tr = p->p_p;
-               if (ISSET(tr->ps_flags, PS_TRACED))
+               if (ISSET(tr->ps_flags, PS_TRACED)) {
+                       rw_exit_write(&proctreelk);
                        return EBUSY;
+               }
                atomic_setbits_int(&tr->ps_flags, PS_TRACED);
                tr->ps_oppid = tr->ps_pptr->ps_pid;
+               rw_exit_write(&proctreelk);
                if (tr->ps_ptstat == NULL)
                        tr->ps_ptstat = malloc(sizeof(*tr->ps_ptstat),
                            M_SUBPROC, M_WAITOK);
@@ -450,6 +458,8 @@ ptrace_ctrl(struct proc *p, int req, pid
                if (error)
                        goto fail;
 #endif
+               proctree_locked = 0;
+               rw_exit_write(&proctreelk);
                goto sendsig;
 
        case PT_DETACH:
@@ -480,7 +490,11 @@ ptrace_ctrl(struct proc *p, int req, pid
                process_untrace(tr);
                atomic_clearbits_int(&tr->ps_flags, PS_WAITED);
 
+               proctree_locked = 0;
+               rw_exit_write(&proctreelk);
        sendsig:
+               KASSERT(proctree_locked == 0);
+
                memset(tr->ps_ptstat, 0, sizeof(*tr->ps_ptstat));
 
                /* Finally, deliver the requested signal (or none). */
@@ -501,6 +515,8 @@ ptrace_ctrl(struct proc *p, int req, pid
 
                /* just send the process a KILL signal. */
                data = SIGKILL;
+               proctree_locked = 0;
+               rw_exit_write(&proctreelk);
                goto sendsig;   /* in PT_CONTINUE, above. */
 
        case PT_ATTACH:
@@ -516,6 +532,8 @@ ptrace_ctrl(struct proc *p, int req, pid
                atomic_setbits_int(&tr->ps_flags, PS_TRACED);
                tr->ps_oppid = tr->ps_pptr->ps_pid;
                process_reparent(tr, p->p_p);
+               proctree_locked = 0;
+               rw_exit_write(&proctreelk);
                if (tr->ps_ptstat == NULL)
                        tr->ps_ptstat = malloc(sizeof(*tr->ps_ptstat),
                            M_SUBPROC, M_WAITOK);
@@ -527,6 +545,8 @@ ptrace_ctrl(struct proc *p, int req, pid
        }
 
 fail:
+       if (proctree_locked)
+               rw_exit_write(&proctreelk);
        return error;
 }
 
Index: kern/syscalls.master
===================================================================
RCS file: /home/cvs/src/sys/kern/syscalls.master,v
retrieving revision 1.224
diff -u -p -r1.224 syscalls.master
--- kern/syscalls.master        16 May 2022 07:36:04 -0000      1.224
+++ kern/syscalls.master        27 Jun 2022 13:37:58 -0000
@@ -128,7 +128,7 @@
 48     STD NOLOCK      { int sys_sigprocmask(int how, sigset_t mask); }
 49     STD             { void *sys_mmap(void *addr, size_t len, int prot, \
                            int flags, int fd, off_t pos); }
-50     STD             { int sys_setlogin(const char *namebuf); }
+50     STD NOLOCK      { int sys_setlogin(const char *namebuf); }
 #ifdef ACCOUNTING
 51     STD             { int sys_acct(const char *path); }
 #else
@@ -186,7 +186,7 @@
                            gid_t *gidset); }
 80     STD             { int sys_setgroups(int gidsetsize, \
                            const gid_t *gidset); }
-81     STD             { int sys_getpgrp(void); }
+81     STD NOLOCK      { int sys_getpgrp(void); }
 82     STD             { int sys_setpgid(pid_t pid, pid_t pgid); }
 83     STD NOLOCK      { int sys_futex(uint32_t *f, int op, int val, \
                            const struct timespec *timeout, uint32_t *g); }
@@ -276,7 +276,7 @@
 139    OBSOL           4.2 sigreturn
 140    STD NOLOCK      { int sys_adjtime(const struct timeval *delta, \
                            struct timeval *olddelta); }
-141    STD             { int sys_getlogin_r(char *namebuf, u_int namelen); }
+141    STD NOLOCK      { int sys_getlogin_r(char *namebuf, u_int namelen); }
 142    OBSOL           ogethostid
 143    OBSOL           osethostid
 144    OBSOL           ogetrlimit
Index: kern/tty.c
===================================================================
RCS file: /home/cvs/src/sys/kern/tty.c,v
retrieving revision 1.174
diff -u -p -r1.174 tty.c
--- kern/tty.c  15 Feb 2022 03:53:58 -0000      1.174
+++ kern/tty.c  27 Jun 2022 13:37:58 -0000
@@ -850,7 +850,9 @@ ttioctl(struct tty *tp, u_long cmd, cadd
        case TIOCGSID:                  /* get sid of tty */
                if (!isctty(pr, tp))
                        return (ENOTTY);
+               rw_enter_read(&proctreelk);
                *(int *)data = tp->t_session->s_leader->ps_pid;
+               rw_exit_read(&proctreelk);
                break;
        case TIOCNXCL:                  /* reset exclusive use of tty */
                s = spltty();
@@ -899,10 +901,12 @@ ttioctl(struct tty *tp, u_long cmd, cadd
                                tp->t_cflag = t->c_cflag;
                                tp->t_ispeed = t->c_ispeed;
                                tp->t_ospeed = t->c_ospeed;
+                               rw_enter_read(&proctreelk);
                                if (t->c_ospeed == 0 && tp->t_session &&
                                    tp->t_session->s_leader)
                                        prsignal(tp->t_session->s_leader,
                                            SIGHUP);
+                               rw_exit_read(&proctreelk);
                        }
                        ttsetwater(tp);
                }
@@ -977,10 +981,13 @@ ttioctl(struct tty *tp, u_long cmd, cadd
                break;
        case TIOCSCTTY:                 /* become controlling tty */
                /* Session ctty vnode pointer set in vnode layer. */
+               rw_enter_write(&proctreelk);
                if (!SESS_LEADER(pr) ||
                    ((pr->ps_session->s_ttyvp || tp->t_session) &&
-                    (tp->t_session != pr->ps_session)))
+                    (tp->t_session != pr->ps_session))) {
+                       rw_exit_write(&proctreelk);
                        return (EPERM);
+               }
                if (tp->t_session)
                        SESSRELE(tp->t_session);
                SESSHOLD(pr->ps_session);
@@ -988,6 +995,7 @@ ttioctl(struct tty *tp, u_long cmd, cadd
                tp->t_pgrp = pr->ps_pgrp;
                pr->ps_session->s_ttyp = tp;
                atomic_setbits_int(&pr->ps_flags, PS_CONTROLT);
+               rw_exit_write(&proctreelk);
                break;
        case FIOSETOWN: {               /* set pgrp of tty */
                struct pgrp *pgrp;
@@ -1012,15 +1020,23 @@ ttioctl(struct tty *tp, u_long cmd, cadd
                break;
        }
        case TIOCSPGRP: {               /* set pgrp of tty */
-               struct pgrp *pgrp = pgfind(*(int *)data);
+               struct pgrp *pgrp;
+
+               rw_enter_write(&proctreelk);
+               pgrp = pgfind(*(int *)data);
 
                if (!isctty(pr, tp))
-                       return (ENOTTY);
+                       error = ENOTTY;
                else if (pgrp == NULL)
-                       return (EINVAL);
+                       error = EINVAL;
                else if (pgrp->pg_session != pr->ps_session)
-                       return (EPERM);
-               tp->t_pgrp = pgrp;
+                       error = EPERM;
+               else {
+                       tp->t_pgrp = pgrp;
+                       error = 0;
+               }
+               rw_exit_write(&proctreelk);
+               return (error);
                break;
        }
        case TIOCSTAT:                  /* get load avg stats */
@@ -1446,6 +1462,11 @@ ttymodem(struct tty *tp, int flag)
                CLR(tp->t_state, TS_CARR_ON);
                if (ISSET(tp->t_state, TS_ISOPEN) &&
                    !ISSET(tp->t_cflag, CLOCAL)) {
+                       /*
+                        * XXXPT `s_leader' needs to be protected but this
+                        * can be called from interrupt context.
+                        */
+                       //rw_assert_wrlock(&proctreelk)
                        if (tp->t_session && tp->t_session->s_leader)
                                prsignal(tp->t_session->s_leader, SIGHUP);
                        ttyflush(tp, FREAD | FWRITE);
@@ -1475,6 +1496,11 @@ nullmodem(struct tty *tp, int flag)
                CLR(tp->t_state, TS_CARR_ON);
                if (ISSET(tp->t_state, TS_ISOPEN) &&
                    !ISSET(tp->t_cflag, CLOCAL)) {
+                       /*
+                        * XXXPT `s_leader' needs to be protected but this
+                        * can be called from interrupt context.
+                        */
+                       //rw_assert_wrlock(&proctreelk)
                        if (tp->t_session && tp->t_session->s_leader)
                                prsignal(tp->t_session->s_leader, SIGHUP);
                        ttyflush(tp, FREAD | FWRITE);
@@ -2191,6 +2217,12 @@ ttyinfo(struct tty *tp)
 
        if (ttycheckoutq(tp,0) == 0)
                return;
+
+       /*
+        * XXXPT `pg_members' needs to be protected but this can be called
+        * from interrupt context.
+        */
+       //rw_assert_wrlock(&proctreelk)
 
        /* Print load average. */
        tmp = (averunnable.ldavg[0] * 100 + FSCALE / 2) >> FSHIFT;
Index: kern/tty_tty.c
===================================================================
RCS file: /home/cvs/src/sys/kern/tty_tty.c,v
retrieving revision 1.30
diff -u -p -r1.30 tty_tty.c
--- kern/tty_tty.c      26 Jun 2022 05:20:42 -0000      1.30
+++ kern/tty_tty.c      27 Jun 2022 13:37:58 -0000
@@ -45,6 +45,9 @@
 #include <sys/fcntl.h>
 
 
+/*
+ * XXXPT Must hold `proctreelk' to dereference `ps_session'.
+ */
 #define cttyvp(p) \
        ((p)->p_p->ps_flags & PS_CONTROLT ? \
            (p)->p_p->ps_session->s_ttyvp : NULL)
@@ -103,11 +106,14 @@ cttyioctl(dev_t dev, u_long cmd, caddr_t
        if (cmd == TIOCSCTTY)           /* XXX */
                return (EINVAL);
        if (cmd == TIOCNOTTY) {
+               rw_enter_read(&proctreelk);
                if (!SESS_LEADER(p->p_p)) {
                        atomic_clearbits_int(&p->p_p->ps_flags, PS_CONTROLT);
-                       return (0);
+                       error = 0;
                } else
-                       return (EINVAL);
+                       error = EINVAL;
+               rw_exit_read(&proctreelk);
+               return error;
        }
        switch (cmd) {
        case TIOCSETVERAUTH:
@@ -116,15 +122,19 @@ cttyioctl(dev_t dev, u_long cmd, caddr_t
                secs = *(int *)addr;
                if (secs < 1 || secs > 3600)
                        return EINVAL;
+               rw_enter_write(&proctreelk);
                sess = p->p_p->ps_pgrp->pg_session;
                sess->s_verauthuid = p->p_ucred->cr_ruid;
                sess->s_verauthppid = p->p_p->ps_pptr->ps_pid;
                timeout_add_sec(&sess->s_verauthto, secs);
+               rw_exit_write(&proctreelk);
                return 0;
        case TIOCCLRVERAUTH:
+               rw_enter_write(&proctreelk);
                sess = p->p_p->ps_pgrp->pg_session;
                timeout_del(&sess->s_verauthto);
                zapverauth(sess);
+               rw_exit_write(&proctreelk);
                return 0;
        case TIOCCHKVERAUTH:
                /*
@@ -134,11 +144,15 @@ cttyioctl(dev_t dev, u_long cmd, caddr_t
                 * Nevertheless, the checks reflect the original intention;
                 * namely, that it be the same user using the same shell.
                 */
+               rw_enter_read(&proctreelk);
                sess = p->p_p->ps_pgrp->pg_session;
                if (sess->s_verauthuid == p->p_ucred->cr_ruid &&
                    sess->s_verauthppid == p->p_p->ps_pptr->ps_pid)
-                       return 0;
-               return EPERM;
+                       error = 0;
+               else
+                       error = EPERM;
+               rw_exit_read(&proctreelk);
+               return error;
        }
        return (VOP_IOCTL(ttyvp, cmd, addr, flag, NOCRED, p));
 }
Index: sys/proc.h
===================================================================
RCS file: /home/cvs/src/sys/sys/proc.h,v
retrieving revision 1.330
diff -u -p -r1.330 proc.h
--- sys/proc.h  13 May 2022 15:32:00 -0000      1.330
+++ sys/proc.h  27 Jun 2022 13:37:58 -0000
@@ -44,6 +44,7 @@
 #include <sys/selinfo.h>               /* For struct selinfo */
 #include <sys/syslimits.h>             /* For LOGIN_NAME_MAX */
 #include <sys/queue.h>
+#include <sys/rwlock.h>                        /* For struct rwlock */
 #include <sys/timeout.h>               /* For struct timeout */
 #include <sys/event.h>                 /* For struct klist */
 #include <sys/mutex.h>                 /* For struct mutex */
@@ -57,16 +58,25 @@
 #endif
 
 /*
+ * Locks used to protect struct members in this file:
+ *     I       immutable after creation
+ *     t       proctreelk
+ *
+ * If multiple locks are listed then all are required for writes,
+ * but any one of them is sufficient for reads.
+ */
+
+/*
  * One structure allocated per session.
  */
 struct process;
 struct session {
        int     s_count;                /* Ref cnt; pgrps in session. */
-       struct  process *s_leader;      /* Session leader. */
+       struct  process *s_leader;      /* [t] Session leader. */
        struct  vnode *s_ttyvp;         /* Vnode of controlling terminal. */
-       struct  tty *s_ttyp;            /* Controlling terminal. */
-       char    s_login[LOGIN_NAME_MAX];        /* Setlogin() name. */
-       pid_t   s_verauthppid;
+       struct  tty *s_ttyp;            /* [t] Controlling terminal. */
+       char    s_login[LOGIN_NAME_MAX];/* [t] setlogin() name. */
+       pid_t   s_verauthppid;          /* TIOCSETVERAUTH info */
        uid_t   s_verauthuid;
        struct timeout s_verauthto;
 };
@@ -77,11 +87,11 @@ void zapverauth(/* struct session */ voi
  * One structure allocated per process group.
  */
 struct pgrp {
-       LIST_ENTRY(pgrp) pg_hash;       /* Hash chain. */
-       LIST_HEAD(, process) pg_members;/* Pointer to pgrp members. */
-       struct  session *pg_session;    /* Pointer to session. */
+       LIST_ENTRY(pgrp) pg_hash;       /* [t] Hash chain. */
+       LIST_HEAD(, process) pg_members;/* [t] Pointer to pgrp members. */
+       struct  session *pg_session;    /* [I] Pointer to session. */
        struct  sigiolst pg_sigiolst;   /* List of sigio structures. */
-       pid_t   pg_id;                  /* Pgrp id. */
+       pid_t   pg_id;                  /* [I] Pgrp id. */
        int     pg_jobc;        /* # procs qualifying pgrp for job control */
 };
 
@@ -140,10 +150,10 @@ struct process {
        LIST_ENTRY(process) ps_list;    /* List of all processes. */
        TAILQ_HEAD(,proc) ps_threads;   /* [K|S] Threads in this process. */
 
-       LIST_ENTRY(process) ps_pglist;  /* List of processes in pgrp. */
-       struct  process *ps_pptr;       /* Pointer to parent process. */
-       LIST_ENTRY(process) ps_sibling; /* List of sibling processes. */
-       LIST_HEAD(, process) ps_children;/* Pointer to list of children. */
+       LIST_ENTRY(process) ps_pglist;  /* [t] List of processes in pgrp. */
+       struct  process *ps_pptr;       /* [t] Pointer to parent process. */
+       LIST_ENTRY(process) ps_sibling; /* [t] List of sibling processes. */
+       LIST_HEAD(, process) ps_children;/* [t] Pointer to list of children. */
        LIST_ENTRY(process) ps_hash;    /* Hash chain. */
 
        /*
@@ -160,7 +170,7 @@ struct process {
        struct  vnode *ps_textvp;       /* Vnode of executable. */
        struct  filedesc *ps_fd;        /* Ptr to open files structure */
        struct  vmspace *ps_vmspace;    /* Address space */
-       pid_t   ps_pid;                 /* Process identifier. */
+       pid_t   ps_pid;                 /* [I] Process identifier. */
 
        struct  futex_list ps_ftlist;   /* futexes attached to this process */
        struct  tslpqueue ps_tslpqueue; /* [p] queue of threads in thrsleep */
@@ -210,7 +220,7 @@ struct process {
 /* The following fields are all copied upon creation in process_new. */
 #define        ps_startcopy    ps_limit
        struct  plimit *ps_limit;       /* [m,R] Process limits. */
-       struct  pgrp *ps_pgrp;          /* Pointer to process group. */
+       struct  pgrp *ps_pgrp;          /* [t] Pointer to process group. */
 
        char    ps_comm[_MAXCOMLEN];    /* command name, incl NUL */
 
@@ -506,6 +516,7 @@ LIST_HEAD(processlist, process);
 extern struct processlist allprocess;  /* List of all processes. */
 extern struct processlist zombprocess; /* List of zombie processes. */
 extern struct proclist allproc;                /* List of all threads. */
+extern struct rwlock proctreelk;       /* parent/child, pgrp, session */
 
 extern struct process *initprocess;    /* Process slot for init. */
 extern struct proc *reaperproc;                /* Thread slot for reaper. */


-- 
jca | PGP : 0x1524E7EE / 5135 92C1 AD36 5293 2BDF  DDCC 0DFA 74AE 1524 E7EE

Reply via email to