From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id B9BC7C30630 for ; Thu, 17 Aug 2023 14:49:56 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1352272AbjHQOt1 (ORCPT ); Thu, 17 Aug 2023 10:49:27 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:40272 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1352336AbjHQOtH (ORCPT ); Thu, 17 Aug 2023 10:49:07 -0400 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 6EFB63A94 for ; Thu, 17 Aug 2023 07:48:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1692283673; h=from:from:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=9oGZA/sseErZDodfZN5CQ2lHc0bZoWdbDZNY06uW8a8=; b=BB4PoeRhMQkEObFrZbgfZ9FbhF3MbJY58jF95G2bO/CGeV8nq2ZaEZk6ycGo+s7XZRY7iC QWqmfOieCoR9E1yNkBru5aeUeWoAH5TECGUrpC2Rt2KUFbh/Y9Ctpzg8qm6CZ5ksR3KEdD TtLYnmgyY0SffiSWaWSVP4HgcTgqs2E= Received: from mail-il1-f197.google.com (mail-il1-f197.google.com [209.85.166.197]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-423-2KjcTTNDNvSySwQOfwk6ng-1; Thu, 17 Aug 2023 10:47:51 -0400 X-MC-Unique: 2KjcTTNDNvSySwQOfwk6ng-1 Received: by mail-il1-f197.google.com with SMTP id e9e14a558f8ab-34916ad5387so69136115ab.1 for ; Thu, 17 Aug 2023 07:47:51 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1692283670; x=1692888470; h=content-transfer-encoding:in-reply-to:from:references:cc:to :content-language:subject:reply-to:user-agent:mime-version:date :message-id:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=9oGZA/sseErZDodfZN5CQ2lHc0bZoWdbDZNY06uW8a8=; b=UY2PfUJ6SblISm7d1QmDH3EBWF2Y32kZRB9jWkuQQamKRaW9AGyOq3TqivDhf3x6sP C8U7aqBWgB7j3p40AJ8+6XkTq48UgoUnNOUjBxVzQrqsm/J4dKSapleo0jHzNP6xdmfq rE51sbBgYvkvjdqpVU/T4xNa4o6L6GORA/QBIKphtaG6iD2e6J5cgGs/h4+2YrOBE1E0 MLsjNtvKtT5z9x2TDGSnluJ61ynNiQGWGeMUN4QkpBgCBOeMK6kIp7fpHCmHUtS5HfhP DaJzYFrU6g82w6StJNpJARNnPZaIqvz3Ud0mRE6q3zkg8mlbiVeWcvUYlycdd8OOjoi8 nk7w== X-Gm-Message-State: AOJu0YyNdh3UMZGUR8IX5MI8AKhAmC8e123zsP5OQx27Ed+CEOV+Nebs h2qSsqKJLWfkbsREvaAZx9iMmlDShKtlmSIJbYBquKBFWWmfPWgDt9uwp8BbMGvIiijV4EB4o8H WLhRpYsytz1v3m23rYgaLzEt7 X-Received: by 2002:a05:6e02:1253:b0:34b:f3b:77b5 with SMTP id j19-20020a056e02125300b0034b0f3b77b5mr2475667ilq.30.1692283670611; Thu, 17 Aug 2023 07:47:50 -0700 (PDT) X-Google-Smtp-Source: AGHT+IGrQH+8rKQJl51yXYMvIpUQalzEERVfGo2BzoJLpqamdYa+T7EHfujOKoGDdR3fZK6apXThIA== X-Received: by 2002:a05:6e02:1253:b0:34b:f3b:77b5 with SMTP id j19-20020a056e02125300b0034b0f3b77b5mr2475650ilq.30.1692283670364; Thu, 17 Aug 2023 07:47:50 -0700 (PDT) Received: from [10.0.0.71] (sandeen.net. [63.231.237.45]) by smtp.gmail.com with ESMTPSA id l28-20020a02cd9c000000b0042acf389ac8sm4783835jap.130.2023.08.17.07.47.49 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Thu, 17 Aug 2023 07:47:49 -0700 (PDT) Message-ID: <81f96763-51fe-8ea1-bf81-cd67deed9087@redhat.com> Date: Thu, 17 Aug 2023 09:47:48 -0500 MIME-Version: 1.0 User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:102.0) Gecko/20100101 Thunderbird/102.14.0 Reply-To: sandeen@redhat.com Subject: Re: [syzbot] [ext4?] kernel panic: EXT4-fs (device loop0): panic forced after error (3) Content-Language: en-US To: Theodore Ts'o , syzbot Cc: adilger.kernel@dilger.ca, linux-ext4@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, llvm@lists.linux.dev, nathan@kernel.org, ndesaulniers@google.com, syzkaller-bugs@googlegroups.com, trix@redhat.com References: <000000000000530e0d060312199e@google.com> <20230817142103.GA2247938@mit.edu> From: Eric Sandeen In-Reply-To: <20230817142103.GA2247938@mit.edu> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On 8/17/23 9:21 AM, Theodore Ts'o wrote: > On Wed, Aug 16, 2023 at 03:48:49PM -0700, syzbot wrote: >> Hello, >> >> syzbot found the following issue on: >> >> HEAD commit: ae545c3283dc Merge tag 'gpio-fixes-for-v6.5-rc6' of git://.. >> git tree: upstream >> console+strace: https://syzkaller.appspot.com/x/log.txt?x=13e5d553a80000 >> kernel config: https://syzkaller.appspot.com/x/.config?x=171b698bc2e613cf >> dashboard link: https://syzkaller.appspot.com/bug?extid=27eece6916b914a49ce7 >> compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40 >> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=13433207a80000 >> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=109cd837a80000 >> >> EXT4-fs error (device loop0): ext4_validate_block_bitmap:430: comm syz-executor211: bg 0: block 46: invalid block bitmap >> Kernel panic - not syncing: EXT4-fs (device loop0): panic forced after error > > #syz invalid > > This is fundamentally a syzbot bug. The file system is horrifically > corrupted, *and* the superblock has the "panic on error" (aka "panic > onfile system corruption") bit set. > > This can be desireable because in a failover situation, if the file > system is found to be corrupted, you *want* the primary server to > fail, and let the secondary server to take over. This is a technique > which is decades old. Just to play devil's advocate here - (sorry) - I don't see this as any different from any other "malicious" filesystem image. I've never been a fan of the idea that malicious images are real security threats, but whether the parking lot USB stick paniced the box in an unexpected way or "on purpose," the result is the same ... I wonder if it might make sense to put EXT4_MOUNT_ERRORS_PANIC under a sysctl or something, so that admins can enable it only when needed. Sorry for stealing another 5 minutes of your life. -Eric > So this is Working As Intended, and is a classic example of (a) if you > are root, you can force the file system to crash, and (b) a classic > example of syzbot noise. (Five minutes of my life that I'm never > getting back. :-) > > - Ted > >