mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Josh Poimboeuf <jpoimboe@redhat.com>
To: "Levin, Alexander (Sasha Levin)" <alexander.levin@verizon.com>
Cc: "x86@kernel.org" <x86@kernel.org>,
	"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
	"live-patching@vger.kernel.org" <live-patching@vger.kernel.org>,
	Linus Torvalds <torvalds@linux-foundation.org>,
	Andy Lutomirski <luto@kernel.org>, Jiri Slaby <jslaby@suse.cz>,
	Ingo Molnar <mingo@kernel.org>, "H. Peter Anvin" <hpa@zytor.com>,
	Peter Zijlstra <peterz@infradead.org>,
	Mike Galbraith <efault@gmx.de>
Subject: Re: [PATCH v4 1/2] x86/unwind: add ORC unwinder
Date: Fri, 28 Jul 2017 12:52:34 -0500	[thread overview]
Message-ID: <20170728175234.pmou7z6dosbi7krh@treble> (raw)
In-Reply-To: <20170728164844.tee7ujqluv2fgarf@sasha-lappy>

On Fri, Jul 28, 2017 at 04:48:47PM +0000, Levin, Alexander (Sasha Levin) wrote:
> Hey Josh,
> 
> Syzkaller seems to trigger the following:
> 
> ==================================================================
> BUG: KASAN: stack-out-of-bounds in __read_once_size include/linux/compiler.h:253 [inline]
> BUG: KASAN: stack-out-of-bounds in deref_stack_reg+0x123/0x140 arch/x86/kernel/unwind_orc.c:282
> Read of size 8 at addr ffff8800374a7b28 by task syz-executor4/6474
> 
> CPU: 2 PID: 6474 Comm: syz-executor4 Not tainted 4.13.0-rc2-next-20170727 #232
> Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.10.1-1ubuntu1 04/01/2014
> Call Trace:
>  <IRQ>
>  __dump_stack lib/dump_stack.c:16 [inline]
>  dump_stack+0xab/0x105 lib/dump_stack.c:52
>  print_address_description+0xc2/0x250 mm/kasan/report.c:252
>  kasan_report_error mm/kasan/report.c:351 [inline]
>  kasan_report+0x24f/0x360 mm/kasan/report.c:408
>  __read_once_size include/linux/compiler.h:253 [inline]
>  deref_stack_reg+0x123/0x140 arch/x86/kernel/unwind_orc.c:282
>  unwind_next_frame+0xd9b/0x1b80 arch/x86/kernel/unwind_orc.c:426
>  __save_stack_trace+0x7d/0xf0 arch/x86/kernel/stacktrace.c:44
>  save_stack+0x33/0xa0 mm/kasan/kasan.c:447
>  set_track mm/kasan/kasan.c:459 [inline]
>  kasan_slab_free+0x72/0xc0 mm/kasan/kasan.c:524
>  slab_free_hook mm/slub.c:1357 [inline]
>  slab_free_freelist_hook mm/slub.c:1379 [inline]
>  slab_free mm/slub.c:2955 [inline]
>  kmem_cache_free+0xae/0x310 mm/slub.c:2977
>  put_pid+0xe2/0x120 kernel/pid.c:246
>  __rcu_reclaim kernel/rcu/rcu.h:195 [inline]
>  rcu_do_batch kernel/rcu/tree.c:2666 [inline]
>  invoke_rcu_callbacks kernel/rcu/tree.c:2920 [inline]
>  __rcu_process_callbacks kernel/rcu/tree.c:2887 [inline]
>  rcu_process_callbacks+0x599/0x12b0 kernel/rcu/tree.c:2904
>  __do_softirq+0x234/0x934 kernel/softirq.c:284
>  invoke_softirq kernel/softirq.c:364 [inline]
>  irq_exit+0x164/0x190 kernel/softirq.c:405
>  exiting_irq arch/x86/include/asm/apic.h:638 [inline]
>  smp_apic_timer_interrupt+0x71/0x90 arch/x86/kernel/apic/apic.c:1044
>  apic_timer_interrupt+0xb9/0xc0 arch/x86/entry/entry_64.S:793
>  </IRQ>
> RIP: 0010:arch_local_irq_enable arch/x86/include/asm/paravirt.h:824 [inline]
> RIP: 0010:preempt_schedule_irq+0x71/0xd0 kernel/sched/core.c:3579
> RSP: 0018:ffff8800374a7958 EFLAGS: 00000246 ORIG_RAX: ffffffffffffff10
> RAX: 0000000000000007 RBX: ffffed0006d95808 RCX: 1ffffffff534d022
> RDX: 0000000000000000 RSI: ffffffffa7065fe0 RDI: ffff880036cac9a4
> RBP: 0000000000000000 R08: ffff88007ffd709c R09: 0000000000000000
> R10: 0000000000000000 R11: 0000000000000000 R12: ffff880036cac040
> R13: 00000000000002eb R14: ffff880036cac040 R15: ffff88005fdc2728
>  retint_kernel+0x1b/0x2d
> RIP: 0010:arch_local_save_flags arch/x86/include/asm/paravirt.h:809 [inline]
> RIP: 0010:___might_sleep+0x159/0x480 kernel/sched/core.c:5968
> RSP: 0018:ffff8800374a7a28 EFLAGS: 00000246 ORIG_RAX: ffffffffffffff02
> RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000001
> RDX: 1ffff10006d95882 RSI: 00000000ffffffff RDI: ffff880036cac410
> RBP: 0000000000000000 R08: ffffffffa3b1546e R09: dffffc0000000000
> R10: ffff8800374a7c08 R11: 0000000000000001 R12: ffffffffa7065320
> R13: 00000000000002eb R14: ffff880036cac040 R15: ffff88005fdc2728
>  ext4_orphan_add+0x34e/0xd70 fs/ext4/namei.c:2801

Thanks for reporting this.  I'm confused by the stack trace.  It seems
to end at ext4_orphan_add, which would normally make sense because the
unwinder would have stopped when it read the bad address on the stack.

But there aren't any of the '?' entries, which should still be there.
Any chance your post-processing script removes those?  Can you share the
raw dmesg before it was post-processed?

-- 
Josh

  reply	other threads:[~2017-07-28 17:52 UTC|newest]

Thread overview: 38+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2017-07-24 23:36 [PATCH v4 0/2] " Josh Poimboeuf
2017-07-24 23:36 ` [PATCH v4 1/2] x86/unwind: add " Josh Poimboeuf
2017-07-26 12:10   ` [tip:x86/asm] x86/unwind: Add the " tip-bot for Josh Poimboeuf
2017-07-28 16:48   ` [PATCH v4 1/2] x86/unwind: add " Levin, Alexander (Sasha Levin)
2017-07-28 17:52     ` Josh Poimboeuf [this message]
2017-07-28 18:29       ` Levin, Alexander (Sasha Levin)
2017-07-28 18:57         ` Josh Poimboeuf
2017-07-28 19:59           ` Levin, Alexander (Sasha Levin)
2017-07-29  3:54             ` Josh Poimboeuf
2017-08-08 18:58               ` Josh Poimboeuf
2017-08-08 19:03                 ` Linus Torvalds
2017-08-08 19:13                   ` Josh Poimboeuf
2017-08-08 20:09                     ` Andy Lutomirski
2017-08-08 22:00                       ` Josh Poimboeuf
2017-08-09  8:49                       ` Juergen Gross
2017-08-09  9:16                         ` Peter Zijlstra
2017-08-09  9:24                           ` Juergen Gross
2017-08-09  9:35                             ` Peter Zijlstra
2017-08-09  9:55                               ` Juergen Gross
2017-08-09 20:15                                 ` Josh Poimboeuf
2017-08-10  7:05                                   ` Juergen Gross
2017-08-10 14:09                                     ` Josh Poimboeuf
2017-08-10 14:24                                       ` Juergen Gross
2017-08-10 14:39                                         ` Josh Poimboeuf
2017-08-10 14:59                                           ` Juergen Gross
2017-08-10 15:49                                             ` Josh Poimboeuf
2017-08-10 14:42                                       ` Josh Poimboeuf
2017-08-09 16:11                         ` Andy Lutomirski
2017-08-09 17:52                           ` Juergen Gross
2017-09-27 21:08                       ` Josh Poimboeuf
2017-09-28  6:03                         ` Juergen Gross
2017-09-28 13:55                           ` Josh Poimboeuf
2017-09-28 13:58                             ` Juergen Gross
2017-07-24 23:36 ` [PATCH v4 2/2] x86/kconfig: make it easier to switch to the new " Josh Poimboeuf
2017-07-25  9:10   ` Ingo Molnar
2017-07-25 13:54     ` Josh Poimboeuf
2017-07-26 12:11       ` [tip:x86/asm] x86/kconfig: Consolidate unwinders into multiple choice selection tip-bot for Josh Poimboeuf
2017-07-26 12:10   ` [tip:x86/asm] x86/kconfig: Make it easier to switch to the new ORC unwinder tip-bot for Josh Poimboeuf

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20170728175234.pmou7z6dosbi7krh@treble \
    --to=jpoimboe@redhat.com \
    --cc=alexander.levin@verizon.com \
    --cc=efault@gmx.de \
    --cc=hpa@zytor.com \
    --cc=jslaby@suse.cz \
    --cc=linux-kernel@vger.kernel.org \
    --cc=live-patching@vger.kernel.org \
    --cc=luto@kernel.org \
    --cc=mingo@kernel.org \
    --cc=peterz@infradead.org \
    --cc=torvalds@linux-foundation.org \
    --cc=x86@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®