mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: kernel test robot <oliver.sang@intel.com>
To: "Ahmed S. Darwish" <darwi@linutronix.de>
Cc: <oe-lkp@lists.linux.dev>, <lkp@intel.com>,
	<linux-kernel@vger.kernel.org>, Ingo Molnar <mingo@redhat.com>,
	Borislav Petkov <bp@alien8.de>,
	Dave Hansen <dave.hansen@linux.intel.com>,
	Thomas Gleixner <tglx@linutronix.de>,
	"Andrew Cooper" <andrew.cooper3@citrix.com>,
	"H. Peter Anvin" <hpa@zytor.com>,
	"John Ogness" <john.ogness@linutronix.de>, <x86@kernel.org>,
	<x86-cpuid@lists.linux.dev>,
	"Ahmed S. Darwish" <darwi@linutronix.de>, <oliver.sang@intel.com>
Subject: Re: [PATCH v3 22/29] x86/cpu: Use consolidated leaf 0x2 descriptor table
Date: Mon, 24 Mar 2025 15:37:17 +0800	[thread overview]
Message-ID: <202503241523.6b53646b-lkp@intel.com> (raw)
In-Reply-To: <20250319122137.4004-23-darwi@linutronix.de>



Hello,

kernel test robot noticed "BUG:KASAN:stack-out-of-bounds_in_intel_detect_tlb" on:

commit: e114ca069e278f250be2b7bc49b2679dc5da4a95 ("[PATCH v3 22/29] x86/cpu: Use consolidated leaf 0x2 descriptor table")
url: https://github.com/intel-lab-lkp/linux/commits/Ahmed-S-Darwish/x86-cpu-Remove-leaf-0x2-parsing-loop/20250319-203156
patch link: https://lore.kernel.org/all/20250319122137.4004-23-darwi@linutronix.de/
patch subject: [PATCH v3 22/29] x86/cpu: Use consolidated leaf 0x2 descriptor table

in testcase: boot

config: x86_64-rhel-9.4-kselftests
compiler: gcc-12
test machine: qemu-system-x86_64 -enable-kvm -cpu SandyBridge -smp 2 -m 16G

(please refer to attached dmesg/kmsg for entire log/backtrace)


+---------------------------------------------------+------------+------------+
|                                                   | bf82706005 | e114ca069e |
+---------------------------------------------------+------------+------------+
| BUG:KASAN:stack-out-of-bounds_in_intel_detect_tlb | 0          | 12         |
+---------------------------------------------------+------------+------------+


If you fix the issue in a separate patch/commit (i.e. not just a new version of
the same patch/commit), kindly add following tags
| Reported-by: kernel test robot <oliver.sang@intel.com>
| Closes: https://lore.kernel.org/oe-lkp/202503241523.6b53646b-lkp@intel.com


[ 5.001760][ T0] BUG: KASAN: stack-out-of-bounds in intel_detect_tlb (arch/x86/kernel/cpu/intel.c:698 arch/x86/kernel/cpu/intel.c:688) 
[    5.001760][    T0] Read of size 1 at addr ffffffff8a607e80 by task swapper/0/0
[    5.001760][    T0]
[    5.001760][    T0] CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 6.14.0-rc5-00152-ge114ca069e27 #1
[    5.001760][    T0] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.2-debian-1.16.2-1 04/01/2014
[    5.001760][    T0] Call Trace:
[    5.001760][    T0]  <TASK>
[ 5.001760][ T0] dump_stack_lvl (lib/dump_stack.c:124) 
[ 5.001760][ T0] print_address_description+0x2c/0x3f0 
[ 5.001760][ T0] ? intel_detect_tlb (arch/x86/kernel/cpu/intel.c:698 arch/x86/kernel/cpu/intel.c:688) 
[ 5.001760][ T0] print_report (mm/kasan/report.c:522) 
[ 5.001760][ T0] ? kasan_addr_to_slab (mm/kasan/common.c:37) 
[ 5.001760][ T0] ? intel_detect_tlb (arch/x86/kernel/cpu/intel.c:698 arch/x86/kernel/cpu/intel.c:688) 
[ 5.001760][ T0] kasan_report (mm/kasan/report.c:636) 
[ 5.001760][ T0] ? intel_detect_tlb (arch/x86/kernel/cpu/intel.c:698 arch/x86/kernel/cpu/intel.c:688) 
[ 5.001760][ T0] intel_detect_tlb (arch/x86/kernel/cpu/intel.c:698 arch/x86/kernel/cpu/intel.c:688) 
[ 5.001760][ T0] ? __pfx_intel_detect_tlb (arch/x86/kernel/cpu/intel.c:689) 
[ 5.001760][ T0] ? numa_add_cpu (include/linux/nodemask.h:272 (discriminator 2) mm/numa_emulation.c:560 (discriminator 2)) 
[ 5.001760][ T0] arch_cpu_finalize_init (arch/x86/kernel/cpu/common.c:862 arch/x86/kernel/cpu/common.c:1999 arch/x86/kernel/cpu/common.c:2409) 
[ 5.001760][ T0] start_kernel (init/main.c:1067) 
[ 5.001760][ T0] x86_64_start_reservations (arch/x86/kernel/head64.c:503) 
[ 5.001760][ T0] x86_64_start_kernel (arch/x86/kernel/head64.c:445 (discriminator 17)) 
[ 5.001760][ T0] ? soft_restart_cpu (arch/x86/kernel/head_64.S:459) 
[ 5.001760][ T0] common_startup_64 (arch/x86/kernel/head_64.S:421) 
[    5.001760][    T0]  </TASK>
[    5.001760][    T0]
[    5.001760][    T0] The buggy address belongs to stack of task swapper/0/0
[    5.001760][    T0]  and is located at offset 48 in frame:
[ 5.001760][ T0] intel_detect_tlb (arch/x86/kernel/cpu/intel.c:689) 
[    5.001760][    T0]
[    5.001760][    T0] This frame has 1 object:
[    5.001760][    T0]  [32, 48) 'regs'
[    5.001760][    T0]
[    5.001760][    T0] The buggy address belongs to the physical page:
[    5.001760][    T0] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1ab407
[    5.001760][    T0] flags: 0x17ffffc0002000(reserved|node=0|zone=2|lastcpupid=0x1fffff)
[    5.001760][    T0] raw: 0017ffffc0002000 ffffea0006ad01c8 ffffea0006ad01c8 0000000000000000
[    5.001760][    T0] raw: 0000000000000000 0000000000000000 00000001ffffffff 0000000000000000
[    5.001760][    T0] page dumped because: kasan: bad access detected
[    5.001760][    T0]
[    5.001760][    T0] Memory state around the buggy address:
[    5.001760][    T0]  ffffffff8a607d80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[    5.001760][    T0]  ffffffff8a607e00: 00 00 00 00 00 00 00 00 00 00 f1 f1 f1 f1 00 00
[    5.001760][    T0] >ffffffff8a607e80: f3 f3 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[    5.001760][    T0]                    ^
[    5.001760][    T0]  ffffffff8a607f00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[    5.001760][    T0]  ffffffff8a607f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[    5.001760][    T0] ==================================================================
[    5.001775][    T0] Disabling lock debugging due to kernel taint


The kernel config and materials to reproduce are available at:
https://download.01.org/0day-ci/archive/20250324/202503241523.6b53646b-lkp@intel.com



-- 
0-DAY CI Kernel Test Service
https://github.com/intel/lkp-tests/wiki


  reply	other threads:[~2025-03-24  7:37 UTC|newest]

Thread overview: 32+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-03-19 12:21 [PATCH v3 00/29] x86: Leaf 0x2 and leaf 0x4 refactorings Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 01/29] x86/cpu: Remove leaf 0x2 parsing loop Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 02/29] x86/cacheinfo: " Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 03/29] x86/cpu: Introduce and use leaf 0x2 parsing helpers Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 04/29] x86/cacheinfo: Use " Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 05/29] x86/cacheinfo: Refactor leaf 0x2 cache descriptor lookup Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 06/29] x86/cacheinfo: Properly name amd_cpuid4()'s first parameter Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 07/29] x86/cacheinfo: Use proper name for cacheinfo instances Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 08/29] x86/cacheinfo: Constify _cpuid4_info_regs instances Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 09/29] x86/cacheinfo: Align ci_info_init() assignment expressions Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 10/29] x86/cacheinfo: Standardize _cpuid4_info_regs instance naming Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 11/29] x86/cacheinfo: Consolidate AMD/Hygon leaf 0x8000001d calls Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 12/29] x86/cacheinfo: Separate amd_northbridge from _cpuid4_info_regs Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 13/29] x86/cacheinfo: Move AMD cache_disable_0/1 handling to separate file Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 14/29] x86/cacheinfo: Use sysfs_emit() for sysfs attributes show() Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 15/29] x86/cacheinfo: Separate Intel and AMD leaf 0x4 code paths Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 16/29] x86/cacheinfo: Rename _cpuid4_info_regs to _cpuid4_info Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 17/29] x86/cacheinfo: Clarify type markers for leaf 0x2 cache descriptors Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 18/29] x86/cacheinfo: Use enums for cache descriptor types Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 19/29] x86/cpu: Use enums for TLB " Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 20/29] x86/cpu: Consolidate CPUID leaf 0x2 tables Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 21/29] x86/cacheinfo: Use consolidated leaf 0x2 descriptor table Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 22/29] x86/cpu: " Ahmed S. Darwish
2025-03-24  7:37   ` kernel test robot [this message]
2025-03-24 11:15     ` Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 23/29] x86/cacheinfo: Separate leaf 0x2 handling and post-processing logic Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 24/29] x86/cacheinfo: Separate Intel leaf 0x4 handling Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 25/29] x86/cacheinfo: Extract out cache level topology ID calculation Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 26/29] x86/cacheinfo: Extract out cache self-snoop checks Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 27/29] x86/cacheinfo: Relocate leaf 0x4 cache_type mapping Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 28/29] x86/cacheinfo: Introduce cpuid_amd_hygon_has_l3_cache() Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 29/29] x86/cacheinfo: Apply maintainer-tip coding style fixes Ahmed S. Darwish

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=202503241523.6b53646b-lkp@intel.com \
    --to=oliver.sang@intel.com \
    --cc=andrew.cooper3@citrix.com \
    --cc=bp@alien8.de \
    --cc=darwi@linutronix.de \
    --cc=dave.hansen@linux.intel.com \
    --cc=hpa@zytor.com \
    --cc=john.ogness@linutronix.de \
    --cc=linux-kernel@vger.kernel.org \
    --cc=lkp@intel.com \
    --cc=mingo@redhat.com \
    --cc=oe-lkp@lists.linux.dev \
    --cc=tglx@linutronix.de \
    --cc=x86-cpuid@lists.linux.dev \
    --cc=x86@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®