git: 546d15061962 - main - sysvshm: Fix locking in shm_prison_set()

From: Mark Johnston <markj_at_FreeBSD.org>
Date: Fri, 25 Sep 2026 21:39:37 UTC
The branch main has been updated by markj:

URL: https://cgit.FreeBSD.org/src/commit/?id=546d15061962a8c45c779210969015e30124fe8d

commit 546d15061962a8c45c779210969015e30124fe8d
Author:     Mark Johnston <markj@FreeBSD.org>
AuthorDate: 2026-09-25 21:38:06 +0000
Commit:     Mark Johnston <markj@FreeBSD.org>
CommitDate: 2026-09-25 21:38:06 +0000

    sysvshm: Fix locking in shm_prison_set()
    
    We were not acquiring the global sysvshm lock when handling cleanup of
    sysvshm segments.  Acquire the lock in shm_prison_cleanup() instead, to
    be consistent with the sysv semaphore code.
    
    Reviewed by:    jamie
    MFC after:      1 week
    Sponsored by:   The FreeBSD Foundation
    Differential Revision:  https://reviews.freebsd.org/D60030
---
 sys/kern/sysv_shm.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/sys/kern/sysv_shm.c b/sys/kern/sysv_shm.c
index 8d1a469127c6..6942cb90873b 100644
--- a/sys/kern/sysv_shm.c
+++ b/sys/kern/sysv_shm.c
@@ -1304,13 +1304,11 @@ shm_prison_remove(void *obj, void *data __unused)
 	struct prison *pr = obj;
 	struct prison *rpr;
 
-	SYSVSHM_LOCK();
 	prison_lock(pr);
 	rpr = osd_jail_get(pr, shm_prison_slot);
 	prison_unlock(pr);
 	if (rpr == pr)
 		shm_prison_cleanup(pr);
-	SYSVSHM_UNLOCK();
 	return (0);
 }
 
@@ -1320,6 +1318,7 @@ shm_prison_cleanup(struct prison *pr)
 	struct shmid_kernel *shmseg;
 	int i;
 
+	SYSVSHM_LOCK();
 	/* Remove any segments that belong to this jail. */
 	for (i = 0; i < shmalloced; i++) {
 		shmseg = &shmsegs[i];
@@ -1328,6 +1327,7 @@ shm_prison_cleanup(struct prison *pr)
 			shm_remove(shmseg, i);
 		}
 	}
+	SYSVSHM_UNLOCK();
 }
 
 SYSCTL_JAIL_PARAM_SYS_NODE(sysvshm, CTLFLAG_RW, "SYSV shared memory");