From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f51.google.com (mail-wm1-f51.google.com [209.85.128.51]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0ABD01E1DEC for ; Thu, 1 Jan 2026 01:15:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.51 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1767230136; cv=none; b=Yr7oz0W5BJea4w09XbRVl640rNNyrBrKPQAIhiVpN7gu9dXvsE706nXmjbdNlwwRYguJ1ycb6UbCIa9MGtIM7XL9lOKwW/Vmr6Zj0xj6/PskOAIB1unjiTkSrwsQY5On8Jq9a8AflWdvy1s4taADq6msqh3YCXs2XtK15onRIOw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1767230136; c=relaxed/simple; bh=WZP8Mk3QPYqP1XafCBtIPFCwCjR7tvBWQyrv61QEj50=; h=Message-ID:Date:MIME-Version:Subject:From:To:Cc:References: In-Reply-To:Content-Type; b=Zf5x4Q/IompNpxZPD9tg4zdw4QRNqwGGKHc3PgNmv4FXDDcZTLI+ZXZMav7V4muZYJEnD7MVIMhvaR+m+ALmJEGWZ/BJpoRaHwbLSEq0eYfEaxZN2tQ4l4nPF7dSnXZO9DwDGt6NYNjkJ1lJdUP2FLNeSTRuEf7Mxgbj1sGNxZE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=suse.com; spf=pass smtp.mailfrom=suse.com; dkim=pass (2048-bit key) header.d=suse.com header.i=@suse.com header.b=PX9g6s7P; arc=none smtp.client-ip=209.85.128.51 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=suse.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=suse.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=suse.com header.i=@suse.com header.b="PX9g6s7P" Received: by mail-wm1-f51.google.com with SMTP id 5b1f17b1804b1-477ba2c1ca2so118611335e9.2 for ; Wed, 31 Dec 2025 17:15:33 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.com; s=google; t=1767230132; x=1767834932; darn=vger.kernel.org; h=content-transfer-encoding:in-reply-to:autocrypt:content-language :references:cc:to:from:subject:user-agent:mime-version:date :message-id:from:to:cc:subject:date:message-id:reply-to; bh=xkwY3h33tWtBnJzkbT/5FUlQ2yKG1xK3b/1V8KgcBKA=; b=PX9g6s7Ph3PPFIX+Viq5BENmiecv04V+CxrGVMAZt0EyLfzLVKfu3GmGbDuCnHkWDq a8yUdbHDdqSfcSi8PDTfp+dne5NHv2Vq13hQrKH9+GfuBRqU/F9/q1Mjc9VOY0VrR/+P EnOZyyryp4DesfoHCuFuma+jNZtU9YuG3V5199dVc2daSzNrSx0ZUIAwM0h0FzfC2EeX MSrNMT3N6tHqBOPOknxV9ZiJ/7OIqqkTWqmrX98/hRqSdZ+p8FFMK+pWgQqDIZ05t3D4 vKX+AavAMM5Zjk5HjqdsTqSjwxzN6lOxrAVOEWW0TWcbeHo1ggydy822YnDESQW78lM1 c7vQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1767230132; x=1767834932; h=content-transfer-encoding:in-reply-to:autocrypt:content-language :references:cc:to:from:subject:user-agent:mime-version:date :message-id:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=xkwY3h33tWtBnJzkbT/5FUlQ2yKG1xK3b/1V8KgcBKA=; b=NtMM/hPPFEeBhvf/jG+RNpXNWRxGPLkDutuY0P4dM/0YXckPe4vi9A+yxR9tNPw5Mx AZHgbANMTbEA5Zt6O7lQkbfAg33k5Em3M6iIraqW4qJMIwSfgOe5toWIPCU07NC/a8zU YqSdQZNzPI9Cs6xZluoJsxhaN5BOXsN4dzXSj9uzm/AU6y7GZRosca3q2cfhv6o2pGkf Fw0lWT9aLW1Wmh7DgVEe0sF3S/6jRrFWW6tJaa7V8b0v08vAk4rpWXisHyDVAnngJ/KD iKjjbq6o2296jHgYanb0DM8a1qf8nMx51ZqeS/9ChiMDOA4zKSEIyk2lb9LHhASS6YQq rYrQ== X-Forwarded-Encrypted: i=1; AJvYcCUGOufVviW6ajjNCEBlz+0/Gb0VMeISrenj0QlUx1s19y/auNTOwTDmGR50GrYzYYl391nEOJscpe5H7Rw=@vger.kernel.org X-Gm-Message-State: AOJu0Yz/fBRe3Wwpo5PqShRdihIY+DmE2Us2kugztoVi2mH5PC/VTpxj yyHk4vdIjasT2FahJSN95Jhl5QnZDK2H/YrVjeq62fIVEp0XzzEU2ADTOVJK8gH6Hqo= X-Gm-Gg: AY/fxX6VxjPnS/u1/b0LvMcMdcom27M8026dW1ZSPAnEzqSHmugMIRl2Huz18Qm3TvG HX/92i1yCrTuxGVFHdkxo+FktauG+iCFxKRfzLSBwE8dk17jx/g/Ox3DBgcSFDP7ot2fcu6HnRp GGFvGvEXJNKacqfsNjhnQdvKI1jJaj2e6KxJCqSCqoBitSTU/bKjud0lB+8313Lm9tqvGfE4NyU 5pUBRuyEkNkehW6hxfrUlV77dHRV1Pi+F9Th8jYKkAstMlmLziv0+QvAa8ghhWlt3MInXegbLpT WnG2NizyvY69ofX6CJqmmOVM3J3ENZCi8MpCCOiDzhkEhl5JKXtAWG708H0PzKo66f0ab9RiAgA csQ+y5tMwQPkD1bwr0Ogg88qVq74shFHwZKqK0mT3Rtx+yySFziLjzVLPfuzKa8rHfcqKVhHEDA xUnocoPl/T7tf/q/nm4LwaWNNtFvzCSzTDhp4WvdGQUEAs6mqfZQ== X-Google-Smtp-Source: AGHT+IHHvlTnlAqFuFdxrkOeeQhFWwkUxz8xIzyA49UCDGBArtA0A+Cf4JAD2SsHlYIi8ropy5mJIw== X-Received: by 2002:a05:600c:4f4a:b0:477:58:7cf4 with SMTP id 5b1f17b1804b1-47d1953b79dmr511779605e9.4.1767230132347; Wed, 31 Dec 2025 17:15:32 -0800 (PST) Received: from ?IPV6:2403:580d:fda1::299? (2403-580d-fda1--299.ip6.aussiebb.net. [2403:580d:fda1::299]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2a2f3c8a8e3sm332310245ad.41.2025.12.31.17.15.28 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Wed, 31 Dec 2025 17:15:31 -0800 (PST) Message-ID: <03cb035e-e34b-4b95-b1df-c8dc6db5a6b0@suse.com> Date: Thu, 1 Jan 2026 11:45:26 +1030 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: Soft tag and inline kasan triggering NULL pointer dereference, but not for hard tag and outline mode (was Re: [6.19-rc3] xxhash invalid access during BTRFS mount) From: Qu Wenruo To: Daniel J Blueman Cc: David Sterba , Chris Mason , Linux BTRFS , linux-crypto@vger.kernel.org, Linux Kernel , kasan-dev@googlegroups.com, ryabinin.a.a@gmail.com References: <01d84dae-1354-4cd5-97ce-4b64a396316a@suse.com> <642a3e9a-f3f1-4673-8e06-d997b342e96b@suse.com> <17bf8f85-9a9c-4d7d-add7-cd92313f73f1@suse.com> <9d21022d-5051-4165-b8fa-f77ec7e820ab@suse.com> Content-Language: en-US Autocrypt: addr=wqu@suse.com; keydata= xsBNBFnVga8BCACyhFP3ExcTIuB73jDIBA/vSoYcTyysFQzPvez64TUSCv1SgXEByR7fju3o 8RfaWuHCnkkea5luuTZMqfgTXrun2dqNVYDNOV6RIVrc4YuG20yhC1epnV55fJCThqij0MRL 1NxPKXIlEdHvN0Kov3CtWA+R1iNN0RCeVun7rmOrrjBK573aWC5sgP7YsBOLK79H3tmUtz6b 9Imuj0ZyEsa76Xg9PX9Hn2myKj1hfWGS+5og9Va4hrwQC8ipjXik6NKR5GDV+hOZkktU81G5 gkQtGB9jOAYRs86QG/b7PtIlbd3+pppT0gaS+wvwMs8cuNG+Pu6KO1oC4jgdseFLu7NpABEB AAHNGFF1IFdlbnJ1byA8d3F1QHN1c2UuY29tPsLAlAQTAQgAPgIbAwULCQgHAgYVCAkKCwIE FgIDAQIeAQIXgBYhBC3fcuWlpVuonapC4cI9kfOhJf6oBQJnEXVgBQkQ/lqxAAoJEMI9kfOh Jf6o+jIH/2KhFmyOw4XWAYbnnijuYqb/obGae8HhcJO2KIGcxbsinK+KQFTSZnkFxnbsQ+VY fvtWBHGt8WfHcNmfjdejmy9si2jyy8smQV2jiB60a8iqQXGmsrkuR+AM2V360oEbMF3gVvim 2VSX2IiW9KERuhifjseNV1HLk0SHw5NnXiWh1THTqtvFFY+CwnLN2GqiMaSLF6gATW05/sEd V17MdI1z4+WSk7D57FlLjp50F3ow2WJtXwG8yG8d6S40dytZpH9iFuk12Sbg7lrtQxPPOIEU rpmZLfCNJJoZj603613w/M8EiZw6MohzikTWcFc55RLYJPBWQ+9puZtx1DopW2jOwE0EWdWB rwEIAKpT62HgSzL9zwGe+WIUCMB+nOEjXAfvoUPUwk+YCEDcOdfkkM5FyBoJs8TCEuPXGXBO Cl5P5B8OYYnkHkGWutAVlUTV8KESOIm/KJIA7jJA+Ss9VhMjtePfgWexw+P8itFRSRrrwyUf E+0WcAevblUi45LjWWZgpg3A80tHP0iToOZ5MbdYk7YFBE29cDSleskfV80ZKxFv6koQocq0 vXzTfHvXNDELAuH7Ms/WJcdUzmPyBf3Oq6mKBBH8J6XZc9LjjNZwNbyvsHSrV5bgmu/THX2n g/3be+iqf6OggCiy3I1NSMJ5KtR0q2H2Nx2Vqb1fYPOID8McMV9Ll6rh8S8AEQEAAcLAfAQY AQgAJgIbDBYhBC3fcuWlpVuonapC4cI9kfOhJf6oBQJnEXWBBQkQ/lrSAAoJEMI9kfOhJf6o cakH+QHwDszsoYvmrNq36MFGgvAHRjdlrHRBa4A1V1kzd4kOUokongcrOOgHY9yfglcvZqlJ qfa4l+1oxs1BvCi29psteQTtw+memmcGruKi+YHD7793zNCMtAtYidDmQ2pWaLfqSaryjlzR /3tBWMyvIeWZKURnZbBzWRREB7iWxEbZ014B3gICqZPDRwwitHpH8Om3eZr7ygZck6bBa4MU o1XgbZcspyCGqu1xF/bMAY2iCDcq6ULKQceuKkbeQ8qxvt9hVxJC2W3lHq8dlK1pkHPDg9wO JoAXek8MF37R8gpLoGWl41FIUb3hFiu3zhDDvslYM4BmzI18QgQTQnotJH8= In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit 在 2025/12/31 15:39, Qu Wenruo 写道: > > > 在 2025/12/31 15:30, Daniel J Blueman 写道: >> On Wed, 31 Dec 2025 at 12:55, Qu Wenruo wrote: [...] >>> >>> x86_64 + generic + inline:      PASS >>> x86_64 + generic + outline:     PASS >> [..] >>> arm64 + hard tag:               PASS >>> arm64 + generic + inline:       PASS >>> arm64 + generic + outline:      PASS >> >> Do you see "KernelAddressSanitizer initialized" with KASAN_GENERIC >> and/or KASAN_HW_TAGS? > > Yes. For my current running one using generic and inline, it shows at > boot time: > > [    0.000000] cma: Reserved 64 MiB at 0x00000000fc000000 > [    0.000000] crashkernel reserved: 0x00000000dc000000 - > 0x00000000fc000000 (512 MB) > [    0.000000] KernelAddressSanitizer initialized (generic) <<< > [    0.000000] psci: probing for conduit method from ACPI. > [    0.000000] psci: PSCIv1.3 detected in firmware. > > >> >> I didn't see it in either case, suggesting it isn't implemented or >> supported on my system. >> >>> arm64 + soft tag + inline:      KASAN error at boot >>> arm64 + soft tag + outline:     KASAN error at boot >> >> Please retry with CONFIG_BPF unset. > > I will retry but I believe this (along with your reports about hardware > tags/generic not reporting the error) has already proven the problem is > inside KASAN itself. > > Not to mention the checksum verification/calculation is very critical > part of btrfs, although in v6.19 there is a change in the crypto > interface, I still doubt about whether we have a out-of-boundary access > not exposed in such hot path until now. BTW, I tried to bisect the cause, and indeed got the same KASAN warning during some runs just mounting a newly created btrfs, and the csum algorithm doesn't seem to matter. Both xxhash and sha256 can trigger it randomly. Unfortunately there is no reliable way to reproduce the kasan warning, I have to cancel the bisection. For now I strongly doubt if this is a bug in software tag-based KASAN itself, and that's the only combination resulting the warning. If KASAN people has some clue I'm very happy to test, meanwhile I'll keep using hardware tag-based kasan on arm64 and generic one on x86_64 to test btrfs, to make sure no obvious bad memory access. Thanks, Qu > > Thanks, > Qu > >> >> Thanks, >>    Dan > >