From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3049C39656B for ; Mon, 16 Mar 2026 12:44:42 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1773665082; cv=none; b=XGLjRDH9V7v4pHNEU93bRhFbtzEFWlTwWd1JokV4WwVkC55q/TqHxnoBRoA9H5BKeYvBpMWA8FsuIvV3CNLb3RJID3z+vs7jAt37DFoydQcWPaBXaCazkcVxlEhP/Ia+nAvej0ZxOVq1ymyj/ifXLVJBzu+VagHryCszrgv5xoY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1773665082; c=relaxed/simple; bh=B6eErf0Rv8/pOP4wFmEW6JF0kE6gyF/QIuBdqW8vGtQ=; h=Message-ID:Date:MIME-Version:From:Subject:To:Cc:References: In-Reply-To:Content-Type; b=K/nWo3ggcrByelSc3h3zDeb3LBtMn/qSQrxc3w8oBQ74g0iL3CD9pP+TUsctmoZBin3P5y3rrwmBBLN//TfWM5BnjaT1ivVBZQns3wWnMRI30g7c77S1A27HTY5MK9BGf2y/D3dAK35WHOkbcAQvOsYdxfeqUWedf9cT2eWLyPw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=WMjVI9iW; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="WMjVI9iW" Received: by smtp.kernel.org (Postfix) with ESMTPSA id CBCD6C19421; Mon, 16 Mar 2026 12:44:38 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1773665081; bh=B6eErf0Rv8/pOP4wFmEW6JF0kE6gyF/QIuBdqW8vGtQ=; h=Date:From:Subject:To:Cc:References:In-Reply-To:From; b=WMjVI9iWkodLGabPriQPIp3DlznF5/DEc9dSKbJM6eEPare7zajZflkO1uG2lePs0 aflrxJllg4kPZ5nNqLlkqP8hWO4W5ThAinZAww478FjUTEIpBi1Ib+eMZFEPV1p9Bq 63p+2qrAZien6ta+ylnKSPyRklWsFXJUDifDcV3eT1OFfG9G1/DN97+6bwUCZTGOKd +14s/5fh/jo8qh/yHPZXsp5RJgNia7Ku9Kkrf87d7rw5cFJDsiIV4nyTJLMSCEsfYd yYyZ4fB1ojIfWyTkIeeAIiLj9fWOd2G0ELy4Ucd3MnS3UsDjE+SMPDNoot2+UAX7iG bwwId3d/VUuTQ== Message-ID: <12d8c91d-d839-4f3d-aca8-0c63e66354d7@kernel.org> Date: Mon, 16 Mar 2026 13:44:36 +0100 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird From: vbabka@kernel.org Subject: Re: [syzbot] [mm?] KMSAN: uninit-value in copy_from_kernel_nofault Content-Language: en-US To: Christian Brauner , syzbot , Alexander Potapenko , Marco Elver , Dmitry Vyukov Cc: Liam.Howlett@oracle.com, akpm@linux-foundation.org, david@kernel.org, linux-kernel@vger.kernel.org, linux-mm@kvack.org, ljs@kernel.org, mhocko@suse.com, rppt@kernel.org, surenb@google.com, syzkaller-bugs@googlegroups.com, kasan-dev References: <69b7d9f6.050a0220.248e02.0112.GAE@google.com> <20260316-fachtagung-gelitten-17389c00b6c2@brauner> In-Reply-To: <20260316-fachtagung-gelitten-17389c00b6c2@brauner> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit On 3/16/26 12:58, Christian Brauner wrote: > On Mon, Mar 16, 2026 at 03:22:46AM -0700, syzbot wrote: >> Hello, >> >> syzbot found the following issue on: >> >> HEAD commit: 80234b5ab240 Merge tag 'rproc-v7.0-fixes' of git://git.ker.. >> git tree: upstream >> console output: https://syzkaller.appspot.com/x/log.txt?x=1474cd52580000 >> kernel config: https://syzkaller.appspot.com/x/.config?x=242f02fcd3fbc8f3 >> dashboard link: https://syzkaller.appspot.com/bug?extid=c18de0ad13d62f18469d >> compiler: Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8 >> userspace arch: i386 >> >> Unfortunately, I don't have any reproducer for this issue yet. >> >> Downloadable assets: >> disk image: https://storage.googleapis.com/syzbot-assets/a0d037332dff/disk-80234b5a.raw.xz >> vmlinux: https://storage.googleapis.com/syzbot-assets/0a1f7f8b54f8/vmlinux-80234b5a.xz >> kernel image: https://storage.googleapis.com/syzbot-assets/83eb68ee6421/bzImage-80234b5a.xz >> >> IMPORTANT: if you fix the issue, please add the following tag to the commit: >> Reported-by: syzbot+c18de0ad13d62f18469d@syzkaller.appspotmail.com >> >> ===================================================== >> BUG: KMSAN: uninit-value in copy_from_kernel_nofault+0x15f/0x570 mm/maccess.c:41 >> copy_from_kernel_nofault+0x15f/0x570 mm/maccess.c:41 >> prepend_copy fs/d_path.c:50 [inline] >> prepend fs/d_path.c:76 [inline] >> prepend_name fs/d_path.c:101 [inline] >> __prepend_path fs/d_path.c:133 [inline] >> prepend_path+0x64e/0x1090 fs/d_path.c:172 > > I think this might just be KMSAN not being able to deal with seqlocks > appropriately? Let's cc KMSAN folks then. Maybe there's a way to teach it that/add exceptions/ignores. > dentry->d_shortname.string[DNAME_INLINE_LEN-1] = 0; > > is initialized with a zero byte at the end instead of: > > memset(&dentry->d_shortname, 0, sizeof(dentry->d_shortname)); > > which would prevent that warning. But that's zeroing 40 bytes vs one and > the dache is fast-fast-fast. > > prepend_path() detects the initialization race via rename_lock seqlock > and retries d_absolute_path(). So this is entirely harmless and works > correct.