From: kernel test robot <oliver.sang@intel.com>
To: "Ahmed S. Darwish" <darwi@linutronix.de>
Cc: <oe-lkp@lists.linux.dev>, <lkp@intel.com>,
<linux-kernel@vger.kernel.org>, Ingo Molnar <mingo@redhat.com>,
Borislav Petkov <bp@alien8.de>,
Dave Hansen <dave.hansen@linux.intel.com>,
Thomas Gleixner <tglx@linutronix.de>,
"Andrew Cooper" <andrew.cooper3@citrix.com>,
"H. Peter Anvin" <hpa@zytor.com>,
"John Ogness" <john.ogness@linutronix.de>, <x86@kernel.org>,
<x86-cpuid@lists.linux.dev>,
"Ahmed S. Darwish" <darwi@linutronix.de>, <oliver.sang@intel.com>
Subject: Re: [PATCH v3 22/29] x86/cpu: Use consolidated leaf 0x2 descriptor table
Date: Mon, 24 Mar 2025 15:37:17 +0800 [thread overview]
Message-ID: <202503241523.6b53646b-lkp@intel.com> (raw)
In-Reply-To: <20250319122137.4004-23-darwi@linutronix.de>
Hello,
kernel test robot noticed "BUG:KASAN:stack-out-of-bounds_in_intel_detect_tlb" on:
commit: e114ca069e278f250be2b7bc49b2679dc5da4a95 ("[PATCH v3 22/29] x86/cpu: Use consolidated leaf 0x2 descriptor table")
url: https://github.com/intel-lab-lkp/linux/commits/Ahmed-S-Darwish/x86-cpu-Remove-leaf-0x2-parsing-loop/20250319-203156
patch link: https://lore.kernel.org/all/20250319122137.4004-23-darwi@linutronix.de/
patch subject: [PATCH v3 22/29] x86/cpu: Use consolidated leaf 0x2 descriptor table
in testcase: boot
config: x86_64-rhel-9.4-kselftests
compiler: gcc-12
test machine: qemu-system-x86_64 -enable-kvm -cpu SandyBridge -smp 2 -m 16G
(please refer to attached dmesg/kmsg for entire log/backtrace)
+---------------------------------------------------+------------+------------+
| | bf82706005 | e114ca069e |
+---------------------------------------------------+------------+------------+
| BUG:KASAN:stack-out-of-bounds_in_intel_detect_tlb | 0 | 12 |
+---------------------------------------------------+------------+------------+
If you fix the issue in a separate patch/commit (i.e. not just a new version of
the same patch/commit), kindly add following tags
| Reported-by: kernel test robot <oliver.sang@intel.com>
| Closes: https://lore.kernel.org/oe-lkp/202503241523.6b53646b-lkp@intel.com
[ 5.001760][ T0] BUG: KASAN: stack-out-of-bounds in intel_detect_tlb (arch/x86/kernel/cpu/intel.c:698 arch/x86/kernel/cpu/intel.c:688)
[ 5.001760][ T0] Read of size 1 at addr ffffffff8a607e80 by task swapper/0/0
[ 5.001760][ T0]
[ 5.001760][ T0] CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 6.14.0-rc5-00152-ge114ca069e27 #1
[ 5.001760][ T0] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.2-debian-1.16.2-1 04/01/2014
[ 5.001760][ T0] Call Trace:
[ 5.001760][ T0] <TASK>
[ 5.001760][ T0] dump_stack_lvl (lib/dump_stack.c:124)
[ 5.001760][ T0] print_address_description+0x2c/0x3f0
[ 5.001760][ T0] ? intel_detect_tlb (arch/x86/kernel/cpu/intel.c:698 arch/x86/kernel/cpu/intel.c:688)
[ 5.001760][ T0] print_report (mm/kasan/report.c:522)
[ 5.001760][ T0] ? kasan_addr_to_slab (mm/kasan/common.c:37)
[ 5.001760][ T0] ? intel_detect_tlb (arch/x86/kernel/cpu/intel.c:698 arch/x86/kernel/cpu/intel.c:688)
[ 5.001760][ T0] kasan_report (mm/kasan/report.c:636)
[ 5.001760][ T0] ? intel_detect_tlb (arch/x86/kernel/cpu/intel.c:698 arch/x86/kernel/cpu/intel.c:688)
[ 5.001760][ T0] intel_detect_tlb (arch/x86/kernel/cpu/intel.c:698 arch/x86/kernel/cpu/intel.c:688)
[ 5.001760][ T0] ? __pfx_intel_detect_tlb (arch/x86/kernel/cpu/intel.c:689)
[ 5.001760][ T0] ? numa_add_cpu (include/linux/nodemask.h:272 (discriminator 2) mm/numa_emulation.c:560 (discriminator 2))
[ 5.001760][ T0] arch_cpu_finalize_init (arch/x86/kernel/cpu/common.c:862 arch/x86/kernel/cpu/common.c:1999 arch/x86/kernel/cpu/common.c:2409)
[ 5.001760][ T0] start_kernel (init/main.c:1067)
[ 5.001760][ T0] x86_64_start_reservations (arch/x86/kernel/head64.c:503)
[ 5.001760][ T0] x86_64_start_kernel (arch/x86/kernel/head64.c:445 (discriminator 17))
[ 5.001760][ T0] ? soft_restart_cpu (arch/x86/kernel/head_64.S:459)
[ 5.001760][ T0] common_startup_64 (arch/x86/kernel/head_64.S:421)
[ 5.001760][ T0] </TASK>
[ 5.001760][ T0]
[ 5.001760][ T0] The buggy address belongs to stack of task swapper/0/0
[ 5.001760][ T0] and is located at offset 48 in frame:
[ 5.001760][ T0] intel_detect_tlb (arch/x86/kernel/cpu/intel.c:689)
[ 5.001760][ T0]
[ 5.001760][ T0] This frame has 1 object:
[ 5.001760][ T0] [32, 48) 'regs'
[ 5.001760][ T0]
[ 5.001760][ T0] The buggy address belongs to the physical page:
[ 5.001760][ T0] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1ab407
[ 5.001760][ T0] flags: 0x17ffffc0002000(reserved|node=0|zone=2|lastcpupid=0x1fffff)
[ 5.001760][ T0] raw: 0017ffffc0002000 ffffea0006ad01c8 ffffea0006ad01c8 0000000000000000
[ 5.001760][ T0] raw: 0000000000000000 0000000000000000 00000001ffffffff 0000000000000000
[ 5.001760][ T0] page dumped because: kasan: bad access detected
[ 5.001760][ T0]
[ 5.001760][ T0] Memory state around the buggy address:
[ 5.001760][ T0] ffffffff8a607d80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[ 5.001760][ T0] ffffffff8a607e00: 00 00 00 00 00 00 00 00 00 00 f1 f1 f1 f1 00 00
[ 5.001760][ T0] >ffffffff8a607e80: f3 f3 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[ 5.001760][ T0] ^
[ 5.001760][ T0] ffffffff8a607f00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[ 5.001760][ T0] ffffffff8a607f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[ 5.001760][ T0] ==================================================================
[ 5.001775][ T0] Disabling lock debugging due to kernel taint
The kernel config and materials to reproduce are available at:
https://download.01.org/0day-ci/archive/20250324/202503241523.6b53646b-lkp@intel.com
--
0-DAY CI Kernel Test Service
https://github.com/intel/lkp-tests/wiki
next prev parent reply other threads:[~2025-03-24 7:37 UTC|newest]
Thread overview: 32+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-03-19 12:21 [PATCH v3 00/29] x86: Leaf 0x2 and leaf 0x4 refactorings Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 01/29] x86/cpu: Remove leaf 0x2 parsing loop Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 02/29] x86/cacheinfo: " Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 03/29] x86/cpu: Introduce and use leaf 0x2 parsing helpers Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 04/29] x86/cacheinfo: Use " Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 05/29] x86/cacheinfo: Refactor leaf 0x2 cache descriptor lookup Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 06/29] x86/cacheinfo: Properly name amd_cpuid4()'s first parameter Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 07/29] x86/cacheinfo: Use proper name for cacheinfo instances Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 08/29] x86/cacheinfo: Constify _cpuid4_info_regs instances Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 09/29] x86/cacheinfo: Align ci_info_init() assignment expressions Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 10/29] x86/cacheinfo: Standardize _cpuid4_info_regs instance naming Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 11/29] x86/cacheinfo: Consolidate AMD/Hygon leaf 0x8000001d calls Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 12/29] x86/cacheinfo: Separate amd_northbridge from _cpuid4_info_regs Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 13/29] x86/cacheinfo: Move AMD cache_disable_0/1 handling to separate file Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 14/29] x86/cacheinfo: Use sysfs_emit() for sysfs attributes show() Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 15/29] x86/cacheinfo: Separate Intel and AMD leaf 0x4 code paths Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 16/29] x86/cacheinfo: Rename _cpuid4_info_regs to _cpuid4_info Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 17/29] x86/cacheinfo: Clarify type markers for leaf 0x2 cache descriptors Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 18/29] x86/cacheinfo: Use enums for cache descriptor types Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 19/29] x86/cpu: Use enums for TLB " Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 20/29] x86/cpu: Consolidate CPUID leaf 0x2 tables Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 21/29] x86/cacheinfo: Use consolidated leaf 0x2 descriptor table Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 22/29] x86/cpu: " Ahmed S. Darwish
2025-03-24 7:37 ` kernel test robot [this message]
2025-03-24 11:15 ` Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 23/29] x86/cacheinfo: Separate leaf 0x2 handling and post-processing logic Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 24/29] x86/cacheinfo: Separate Intel leaf 0x4 handling Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 25/29] x86/cacheinfo: Extract out cache level topology ID calculation Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 26/29] x86/cacheinfo: Extract out cache self-snoop checks Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 27/29] x86/cacheinfo: Relocate leaf 0x4 cache_type mapping Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 28/29] x86/cacheinfo: Introduce cpuid_amd_hygon_has_l3_cache() Ahmed S. Darwish
2025-03-19 12:21 ` [PATCH v3 29/29] x86/cacheinfo: Apply maintainer-tip coding style fixes Ahmed S. Darwish
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=202503241523.6b53646b-lkp@intel.com \
--to=oliver.sang@intel.com \
--cc=andrew.cooper3@citrix.com \
--cc=bp@alien8.de \
--cc=darwi@linutronix.de \
--cc=dave.hansen@linux.intel.com \
--cc=hpa@zytor.com \
--cc=john.ogness@linutronix.de \
--cc=linux-kernel@vger.kernel.org \
--cc=lkp@intel.com \
--cc=mingo@redhat.com \
--cc=oe-lkp@lists.linux.dev \
--cc=tglx@linutronix.de \
--cc=x86-cpuid@lists.linux.dev \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®