From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id 95024C83F15 for ; Mon, 28 Aug 2023 12:43:12 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S231255AbjH1Mmo (ORCPT ); Mon, 28 Aug 2023 08:42:44 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:52710 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S232599AbjH1Mmh (ORCPT ); Mon, 28 Aug 2023 08:42:37 -0400 Received: from mgamail.intel.com (mgamail.intel.com [134.134.136.31]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id C6E27107 for ; Mon, 28 Aug 2023 05:42:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1693226553; x=1724762553; h=date:from:to:cc:subject:message-id:references: mime-version:in-reply-to; bh=tvNba5dsGVy14uXWrWuJ3hHVDQ7/CZCqBs6ssRH5Yfg=; b=kQB9l/5hPwqsfeaJXw9SVX+Z2iDHt5a9NDR814Dm0KGJxj/DS10c4sPV 2eD+WwtU7YWCiHjUpPkcjh1vRkBcguoFTyAaA9j/nZLf6wSn17El8kRLs KbAiDfZBytEEfjDDJNdRdt80XicdiEyqjGxh4Otew/amS597ooJbtcXBf 4MTXOr95+RdfDc4Hwylgp/BzszW9MYpFiALk9ltqD0W3HmYpHxsTuKm/m 7aOYIVIyCINaCu9paou6I1tRujpCIOFbmcD9aaeDAlMp+Mxp53R5yNAf1 0UN/Dc1qgLmAVjG2lUs4T1gk/JUdTWfhOg2UVzi+unt1R13mJheqvaXfP A==; X-IronPort-AV: E=McAfee;i="6600,9927,10816"; a="439037120" X-IronPort-AV: E=Sophos;i="6.02,207,1688454000"; d="scan'208";a="439037120" Received: from orsmga005.jf.intel.com ([10.7.209.41]) by orsmga104.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 28 Aug 2023 05:42:31 -0700 X-ExtLoop1: 1 X-IronPort-AV: E=McAfee;i="6600,9927,10816"; a="912040532" X-IronPort-AV: E=Sophos;i="6.02,207,1688454000"; d="scan'208";a="912040532" Received: from smile.fi.intel.com ([10.237.72.54]) by orsmga005.jf.intel.com with ESMTP; 28 Aug 2023 05:42:30 -0700 Received: from andy by smile.fi.intel.com with local (Exim 4.96) (envelope-from ) id 1qabZc-000yVi-1S; Mon, 28 Aug 2023 15:42:28 +0300 Date: Mon, 28 Aug 2023 15:42:28 +0300 From: Andy Shevchenko To: syzbot , hdanton@sina.com Cc: gregkh@linuxfoundation.org, linux-kernel@vger.kernel.org, rafael@kernel.org, syzkaller-bugs@googlegroups.com Subject: Re: [syzbot] [kernel?] general protection fault in nfc_register_device Message-ID: References: <0000000000001b6a0c0603f8ab85@google.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: Organization: Intel Finland Oy - BIC 0357606-4 - Westendinkatu 7, 02160 Espoo Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Mon, Aug 28, 2023 at 02:35:22PM +0300, Andy Shevchenko wrote: > On Mon, Aug 28, 2023 at 02:53:37AM -0700, syzbot wrote: > > Hello, > > > > syzbot found the following issue on: > > Thanks! Will work on it ASAP. So, can somebody from syzbot explain me what this is? My readings as follows: 1) syzbot inserts fault injection into dev_set_name(&dev->dev, "nfc%d", dev->idx); 2) that becomes a NULL in the corresponding kobj->name, correct? 3) which leads to the device_add() to exercise the paths that check for name being NULL, i.e. if (dev->init_name) { error = dev_set_name(dev, "%s", dev->init_name); dev->init_name = NULL; } if (dev_name(dev)) error = 0; /* subsystems can specify simple device enumeration */ else if (dev->bus && dev->bus->dev_name) error = dev_set_name(dev, "%s%u", dev->bus->dev_name, dev->id); if (error) goto name_error; so, either we have init_name or bus->name defined, but this seems not the case; anyway in both cases the dev_set_name() may fail in strchr() if and only if the fmt is NULL, which is not, as above calls have it hard coded literals. What's going on here? (The error check for dev_set_name() in nfc_allocate_device() probably fixes this, but it must not affect the code execution, right?) P.S. Of course the test patch from hdanton@ doesn't fix it, the error is checked in the code later on. -- With Best Regards, Andy Shevchenko