From: Christian Hesse <mail@eworm.de>
To: Lizhi Xu <lizhi.xu@windriver.com>
Cc: <hch@infradead.org>, <axboe@kernel.dk>,
<linux-block@vger.kernel.org>, <linux-kernel@vger.kernel.org>,
<ming.lei@redhat.com>,
<syzbot+6af973a3b8dfd2faefdc@syzkaller.appspotmail.com>,
<syzkaller-bugs@googlegroups.com>,
Christian Heusel <christian@heusel.eu>,
Christian Hesse <mail@eworm.de>
Subject: Re: [PATCH V5] loop: Add sanity check for read/write_iter
Date: Mon, 19 May 2025 17:56:40 +0200 [thread overview]
Message-ID: <20250519175640.2fcac001@leda.eworm.net> (raw)
In-Reply-To: <20250428143626.3318717-1-lizhi.xu@windriver.com>
[-- Attachment #1: Type: text/plain, Size: 2139 bytes --]
Lizhi Xu <lizhi.xu@windriver.com> on Mon, 2025/04/28 22:36:
> Some file systems do not support read_iter/write_iter, such as selinuxfs
> in this issue.
> So before calling them, first confirm that the interface is supported and
> then call it.
>
> It is releavant in that vfs_iter_read/write have the check, and removal
> of their used caused szybot to be able to hit this issue.
>
> Fixes: f2fed441c69b ("loop: stop using vfs_iter__{read,write} for buffered
> I/O") Reported-by: syzbot+6af973a3b8dfd2faefdc@syzkaller.appspotmail.com
> Closes: https://syzkaller.appspot.com/bug?extid=6af973a3b8dfd2faefdc
> Signed-off-by: Lizhi Xu <lizhi.xu@windriver.com>
> Reviewed-by: Christoph Hellwig <hch@lst.de>
> ---
> V1 -> V2: move check to loop_configure and loop_change_fd
> V2 -> V3: using helper for this check
> V3 -> V4: remove input parameters change and mode
> V4 -> V5: remove braces around !file->f_op->write_iter
This introduced a regression for Arch Linux, breaking boot media generated
with archiso [0]. More specifically it's this call of losetup [1].
There's a squashfs inside iso9660. Mounting the iso9660 filesystem works
fine, but losetup complains when setting up:
$ losetup --find --show --read-only -- /run/archiso/bootmnt/arch/x86_64/airootfs.sfs
losetup: /run/archiso/bootmnt/arch/x86_64/airootfs.sfs: failed to set up loop device: Invalid argument
This has been bisected to commit d278164832618bf2775c6a89e6434e2633de1eed in
mainline (and 9bd3feb324fce2e93e09d0a5b00887e81d337a8c for linux-6.14.y,
184b147b9f7f07577567a80fcc9314f2bd0b0b00 for linux-6.12.y). Thanks to
Christian Heusel for his work on this.
As the call tries to setup in read-only mode the check for
(file->f_op->read_iter) fails here, returning the -EINVAL we see.
Reported-by: Christian Hesse <mail@eworm.de>
Bisected-by: Christian Heusel <christian@heusel.eu>
[0] https://gitlab.archlinux.org/archlinux/mkinitcpio/mkinitcpio-archiso
[1] https://gitlab.archlinux.org/archlinux/mkinitcpio/mkinitcpio-archiso/-/blob/master/hooks/archiso?ref_type=heads#L88
--
Mit freundlichen Gruessen
Christian Hesse
[-- Attachment #2: OpenPGP digital signature --]
[-- Type: application/pgp-signature, Size: 228 bytes --]
next prev parent reply other threads:[~2025-05-19 16:03 UTC|newest]
Thread overview: 42+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-04-24 14:08 [syzbot] [block?] BUG: unable to handle kernel NULL pointer dereference in lo_rw_aio syzbot
2025-04-25 1:19 ` [syzbot] " syzbot
2025-04-25 1:55 ` syzbot
2025-04-25 3:40 ` [PATCH] loop: Add sanity check for read/write_iter Lizhi Xu
2025-04-25 4:06 ` Zhu Yanjun
2025-04-25 4:19 ` Lizhi Xu
2025-04-25 4:20 ` Ming Lei
2025-04-25 4:33 ` Lizhi Xu
2025-04-25 5:38 ` [PATCH V2] " Lizhi Xu
2025-04-25 13:28 ` Christoph Hellwig
2025-04-26 1:50 ` Lizhi Xu
2025-04-28 12:46 ` Christoph Hellwig
2025-04-28 13:48 ` Lizhi Xu
2025-04-28 13:49 ` Christoph Hellwig
2025-04-26 2:10 ` [PATCH V3] " Lizhi Xu
2025-04-28 12:49 ` Christoph Hellwig
2025-04-28 13:42 ` Lizhi Xu
2025-04-28 13:48 ` Christoph Hellwig
2025-04-28 14:15 ` [PATCH V4] " Lizhi Xu
2025-04-28 14:26 ` Christoph Hellwig
2025-04-28 14:36 ` [PATCH V5] " Lizhi Xu
2025-05-05 13:18 ` Jens Axboe
2025-05-19 15:56 ` Christian Hesse [this message]
2025-05-20 3:00 ` Lizhi Xu
2025-05-20 5:39 ` Christian Hesse
2025-05-20 6:29 ` 回复: " Xu, Lizhi
2025-05-20 6:31 ` Christian Hesse
2025-05-20 6:49 ` Xu, Lizhi
2025-05-20 6:46 ` 回复: " hch
2025-05-20 6:59 ` 回复: " Xu, Lizhi
2025-05-20 11:28 ` hch
2025-05-20 11:39 ` 回复: " Xu, Lizhi
2025-05-20 11:41 ` hch
2025-05-20 11:44 ` 回复: " Xu, Lizhi
2025-05-20 11:52 ` Xu, Lizhi
2025-05-20 12:27 ` Xu, Lizhi
2025-05-20 12:46 ` Christian Hesse
2025-05-20 12:49 ` hch
2025-05-20 13:12 ` Xu, Lizhi
2025-05-20 16:53 ` christian
2025-05-20 12:46 ` hch
2025-04-25 4:54 ` [syzbot] Re: [syzbot] [block?] BUG: unable to handle kernel NULL pointer dereference in lo_rw_aio syzbot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20250519175640.2fcac001@leda.eworm.net \
--to=mail@eworm.de \
--cc=axboe@kernel.dk \
--cc=christian@heusel.eu \
--cc=hch@infradead.org \
--cc=linux-block@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=lizhi.xu@windriver.com \
--cc=ming.lei@redhat.com \
--cc=syzbot+6af973a3b8dfd2faefdc@syzkaller.appspotmail.com \
--cc=syzkaller-bugs@googlegroups.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®