On 10/14, Christian Brauner wrote:
The child helper process on Linux posix_spawn must ensure that no signal handlers are enabled, so the signal disposition must be either SIG_DFL or SIG_IGN. However, it requires a sigprocmask to obtain the current signal mask and at least _NSIG sigaction calls to reset the signal handlers for each posix_spawn call
Plus the caller has to block/unblock all signals around clone(VM|VFORK).
Can this justify the new CLONE_ flag? Honestly, I have no idea. But the patch is simple and looks technically correct to me. FWIW,
Reviewed-by: Oleg Nesterov oleg@redhat.com