mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [BUG] general protection fault in upd78f0730_tiocmset
@ 2026-09-11 20:16 Farhad Alemi
  2026-09-16 13:47 ` Johan Hovold
  0 siblings, 1 reply; 2+ messages in thread
From: Farhad Alemi @ 2026-09-11 20:16 UTC (permalink / raw)
  To: Johan Hovold; +Cc: linux-kernel

[-- Attachment #1: Type: text/plain, Size: 4820 bytes --]

Hello,

We are reporting the following crash (reproducer attached):
Linux version 7.3.0-rc2 50d05c7c76c96b90462f24debacca971d2e86713
Build Config: UpstreamAppArmorKASAN (KASAN + UBSAN, panic_on_warn=1)

[   44.256596][ T9490] Oops: general protection fault, probably for
non-canonical address 0xdffffc00000000ba: 0000 [#1] SMP KASAN NOPTI
[   44.258408][ T9490] KASAN: null-ptr-deref in range
[0x00000000000005d0-0x00000000000005d7]
[   44.259206][ T9490] CPU: 0 UID: 0 PID: 9490 Comm: repro Not tainted
7.3.0-rc2-00099-g50d05c7c76c9 #1 PREEMPT(full)
[   44.260235][ T9490] Hardware name: QEMU Standard PC (Q35 + ICH9,
2009), BIOS 1.17.0-debian-1.17.0-1ubuntu1 04/01/2014
[   44.261396][ T9490] RIP: 0010:upd78f0730_tiocmset+0x86/0x4b0
[   44.261972][ T9490] Code: 48 c1 e9 03 48 b8 f1 f1 f1 f1 f8 f3 f3 f3
48 89 4c 24 18 4a 89 04 31 e8 b8 7d 2c fa 48 81 c3 d0 05 00 00 48 89
d8 48 c1 e8 03 <42> 80 3c 30 00 74 08 48 89 df e8 2b 77 9c fa 48 8b 1b
48 b9 00 00
[   44.263789][ T9490] RSP: 0018:ffffc90007ab7cc0 EFLAGS: 00010202
[   44.264354][ T9490] RAX: 00000000000000ba RBX: 00000000000005d0
RCX: ffff888023c14c80
[   44.265071][ T9490] RDX: 0000000000000000 RSI: 0000000000000000
RDI: 0000000000000000
[   44.265809][ T9490] RBP: ffffc90007ab7d78 R08: ffff88802ca5e23f
R09: 1ffff1100594bc47
[   44.266578][ T9490] R10: dffffc0000000000 R11: ffffffff879b2310
R12: ffff88802ca5e238
[   44.267349][ T9490] R13: 0000000000000000 R14: dffffc0000000000
R15: 0000000000000006
[   44.268064][ T9490] FS:  000000002dfbb400(0000)
GS:ffff8880d7388000(0000) knlGS:0000000000000000
[   44.268859][ T9490] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[   44.269453][ T9490] CR2: 0000563a83ef0e60 CR3: 0000000109e01000
CR4: 0000000000752ef0
[   44.270165][ T9490] PKRU: 55555554
[   44.270495][ T9490] Call Trace:
[   44.270882][ T9490]  <TASK>
[   44.271160][ T9490]  ? __pfx_upd78f0730_tiocmset+0x10/0x10
[   44.271694][ T9490]  ? __pfx_serial_port_dtr_rts+0x10/0x10
[   44.272208][ T9490]  tty_port_shutdown+0x165/0x220
[   44.272672][ T9490]  tty_port_hangup+0xee/0x170
[   44.273101][ T9490]  ? __pfx_serial_hangup+0x10/0x10
[   44.273600][ T9490]  __tty_hangup+0x5a7/0x650
[   44.274074][ T9490]  tty_ioctl+0x757/0xde0
[   44.274503][ T9490]  ? __pfx_tty_ioctl+0x10/0x10
[   44.274984][ T9490]  __se_sys_ioctl+0xfc/0x170
[   44.275432][ T9490]  do_syscall_64+0x155/0x510
[   44.275862][ T9490]  ? trace_irq_disable+0x3b/0x140
[   44.276329][ T9490]  ? entry_SYSCALL_64_after_hwframe+0x77/0x7f
[   44.276884][ T9490]  ? clear_bhb_loop+0x30/0x80
[   44.277314][ T9490]  entry_SYSCALL_64_after_hwframe+0x77/0x7f
[   44.277850][ T9490] RIP: 0033:0x417a9d
[   44.278211][ T9490] Code: 04 25 28 00 00 00 48 89 45 c8 31 c0 48 8d
45 10 c7 45 b0 10 00 00 00 48 89 45 b8 48 8d 45 d0 48 89 45 c0 b8 10
00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 1a 48 8b 45 c8 64 48 2b 04 25
28 00 00 00
[   44.279975][ T9490] RSP: 002b:00007ffe10b6f070 EFLAGS: 00000246
ORIG_RAX: 0000000000000010
[   44.280825][ T9490] RAX: ffffffffffffffda RBX: 0000000000000001
RCX: 0000000000417a9d
[   44.281622][ T9490] RDX: 0000000000000000 RSI: 0000000000005437
RDI: 0000000000000004
[   44.282389][ T9490] RBP: 00007ffe10b6f0c0 R08: 0000000000000000
R09: 0000000000000000
[   44.283156][ T9490] R10: 0000000000000000 R11: 0000000000000246
R12: 00007ffe10b6f318
[   44.283867][ T9490] R13: 00007ffe10b6f328 R14: 0000000000000002
R15: 00000000004cd9e0
[   44.284586][ T9490]  </TASK>
[   44.284876][ T9490] Modules linked in:
[   44.285291][ T9490] ---[ end trace 0000000000000000 ]---
[   44.286033][ T9490] RIP: 0010:upd78f0730_tiocmset+0x86/0x4b0
[   44.286048][ T9490] Code: 48 c1 e9 03 48 b8 f1 f1 f1 f1 f8 f3 f3 f3
48 89 4c 24 18 4a 89 04 31 e8 b8 7d 2c fa 48 81 c3 d0 05 00 00 48 89
d8 48 c1 e8 03 <42> 80 3c 30 00 74 08 48 89 df e8 2b 77 9c fa 48 8b 1b
48 b9 00 00
[   44.286054][ T9490] RSP: 0018:ffffc90007ab7cc0 EFLAGS: 00010202
[   44.286060][ T9490] RAX: 00000000000000ba RBX: 00000000000005d0
RCX: ffff888023c14c80
[   44.286065][ T9490] RDX: 0000000000000000 RSI: 0000000000000000
RDI: 0000000000000000
[   44.286069][ T9490] RBP: ffffc90007ab7d78 R08: ffff88802ca5e23f
R09: 1ffff1100594bc47
[   44.286074][ T9490] R10: dffffc0000000000 R11: ffffffff879b2310
R12: ffff88802ca5e238
[   44.286079][ T9490] R13: 0000000000000000 R14: dffffc0000000000
R15: 0000000000000006
[   44.286084][ T9490] FS:  000000002dfbb400(0000)
GS:ffff8880d7388000(0000) knlGS:0000000000000000
[   44.286089][ T9490] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[   44.286094][ T9490] CR2: 0000563a83ef0e60 CR3: 0000000109e01000
CR4: 0000000000752ef0
[   44.286100][ T9490] PKRU: 55555554
[   44.286106][ T9490] Kernel panic - not syncing: Fatal exception
[   44.296338][ T9490] Kernel Offset: disabled
[   44.296884][ T9490] Rebooting in 86400 seconds..

Regards,

[-- Attachment #2: reproducer.c --]
[-- Type: application/octet-stream, Size: 3897 bytes --]

/*
 * 282-general-protection-fault-in-upd78f0730-tiocmset
 */
#define _GNU_SOURCE
#include <errno.h>
#include <fcntl.h>
#include <pthread.h>
#include <stdint.h>
#include <stdlib.h>
#include <string.h>
#include <sys/ioctl.h>
#include <unistd.h>
#include <linux/usb/ch9.h>
#include <linux/usb/raw_gadget.h>

#define EP0_BUFFER_BYTES 4096
#define LE16(value) ((value) & 0xff), (((value) >> 8) & 0xff)

static int raw_gadget_fd = -1;

static const uint8_t configuration_descriptor[] = {
	9, USB_DT_CONFIG, LE16(9 + 9), 1, 1, 0, 0xa0, 0xfa,
	9, USB_DT_INTERFACE, 0, 0, 0, 0xff, 0xff, 0xff, 0,
};

static const struct usb_device_descriptor device_descriptor = {
	.bLength = sizeof(struct usb_device_descriptor),
	.bDescriptorType = USB_DT_DEVICE,
	.bcdUSB = 0x0200,
	.bMaxPacketSize0 = 64,
	.idVendor = 0x0409,
	.idProduct = 0x0063,
	.bcdDevice = 0x0100,
	.bNumConfigurations = 1,
};

static void ep0_write(const void *data, uint32_t length)
{
	uint8_t buffer[sizeof(struct usb_raw_ep_io) + EP0_BUFFER_BYTES];
	struct usb_raw_ep_io *transfer = (void *)buffer;

	transfer->ep = 0;
	transfer->flags = 0;
	transfer->length = length;
	if (length)
		memcpy(transfer->data, data, length);
	ioctl(raw_gadget_fd, USB_RAW_IOCTL_EP0_WRITE, transfer);
}

static void handle_control_request(const struct usb_ctrlrequest *ctrl)
{
	uint8_t data[EP0_BUFFER_BYTES];
	uint8_t buffer[sizeof(struct usb_raw_ep_io) + EP0_BUFFER_BYTES];
	struct usb_raw_ep_io *transfer = (void *)buffer;
	int length = -1;

	if ((ctrl->bRequestType & USB_TYPE_MASK) == USB_TYPE_STANDARD) {
		if (ctrl->bRequest == USB_REQ_GET_DESCRIPTOR &&
		    (ctrl->wValue >> 8) == USB_DT_DEVICE) {
			length = sizeof(device_descriptor);
			memcpy(data, &device_descriptor, length);
		} else if (ctrl->bRequest == USB_REQ_GET_DESCRIPTOR &&
			   (ctrl->wValue >> 8) == USB_DT_CONFIG) {
			length = sizeof(configuration_descriptor);
			memcpy(data, configuration_descriptor, length);
		} else if (ctrl->bRequest == USB_REQ_SET_CONFIGURATION) {
			ioctl(raw_gadget_fd, USB_RAW_IOCTL_CONFIGURE, 0);
			length = 0;
		}
	} else {

		length = 0;
	}

	if (length < 0) {
		ioctl(raw_gadget_fd, USB_RAW_IOCTL_EP0_STALL, 0);
		return;
	}
	if (ctrl->bRequestType & USB_DIR_IN) {
		if (length > ctrl->wLength)
			length = ctrl->wLength;
		ep0_write(data, (uint32_t)length);
	} else {
		transfer->ep = 0;
		transfer->flags = 0;
		transfer->length = ctrl->wLength > EP0_BUFFER_BYTES ?
				   EP0_BUFFER_BYTES : ctrl->wLength;
		ioctl(raw_gadget_fd, USB_RAW_IOCTL_EP0_READ, transfer);
	}
}

static void *gadget_ep0_event_pump(void *unused)
{
	uint8_t buffer[sizeof(struct usb_raw_event) + EP0_BUFFER_BYTES];
	struct usb_raw_event *event = (void *)buffer;

	for (;;) {
		event->type = 0;
		event->length = EP0_BUFFER_BYTES;
		if (ioctl(raw_gadget_fd, USB_RAW_IOCTL_EVENT_FETCH, event) < 0) {
			if (errno == EINTR || errno == EBUSY || errno == EAGAIN)
				continue;
			return NULL;
		}
		if (event->type == USB_RAW_EVENT_CONTROL)
			handle_control_request((struct usb_ctrlrequest *)event->data);
	}
}

int main(void)
{
	struct usb_raw_init init;
	pthread_t event_pump_thread;
	int tty_fd = -1, attempt;

	system("modprobe dummy_hcd 2>/dev/null");
	system("modprobe raw_gadget 2>/dev/null");

	raw_gadget_fd = open("/dev/raw-gadget", O_RDWR);
	if (raw_gadget_fd < 0)
		return 1;

	memset(&init, 0, sizeof(init));
	strcpy((char *)init.driver_name, "dummy_udc");
	strcpy((char *)init.device_name, "dummy_udc.0");
	init.speed = USB_SPEED_HIGH;
	if (ioctl(raw_gadget_fd, USB_RAW_IOCTL_INIT, &init) < 0)
		return 1;
	if (ioctl(raw_gadget_fd, USB_RAW_IOCTL_RUN, 0) < 0)
		return 1;

	pthread_create(&event_pump_thread, NULL, gadget_ep0_event_pump, NULL);

	for (attempt = 0; attempt < 100 && tty_fd < 0; attempt++) {
		usleep(100000);
		tty_fd = open("/dev/ttyUSB0", O_RDWR | O_NOCTTY | O_NONBLOCK);
	}
	if (tty_fd < 0)
		return 1;

	ioctl(tty_fd, TIOCVHANGUP, 0);
	return 0;
}

^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [BUG] general protection fault in upd78f0730_tiocmset
  2026-09-11 20:16 [BUG] general protection fault in upd78f0730_tiocmset Farhad Alemi
@ 2026-09-16 13:47 ` Johan Hovold
  0 siblings, 0 replies; 2+ messages in thread
From: Johan Hovold @ 2026-09-16 13:47 UTC (permalink / raw)
  To: Farhad Alemi; +Cc: linux-kernel, Greg Kroah-Hartman

On Fri, Sep 11, 2026 at 01:16:11PM -0700, Farhad Alemi wrote:

> We are reporting the following crash (reproducer attached):
> Linux version 7.3.0-rc2 50d05c7c76c96b90462f24debacca971d2e86713
> Build Config: UpstreamAppArmorKASAN (KASAN + UBSAN, panic_on_warn=1)
> 
> [   44.256596][ T9490] Oops: general protection fault, probably for
> non-canonical address 0xdffffc00000000ba: 0000 [#1] SMP KASAN NOPTI
> [   44.258408][ T9490] KASAN: null-ptr-deref in range
> [0x00000000000005d0-0x00000000000005d7]
> [   44.259206][ T9490] CPU: 0 UID: 0 PID: 9490 Comm: repro Not tainted
> 7.3.0-rc2-00099-g50d05c7c76c9 #1 PREEMPT(full)
> [   44.260235][ T9490] Hardware name: QEMU Standard PC (Q35 + ICH9,
> 2009), BIOS 1.17.0-debian-1.17.0-1ubuntu1 04/01/2014
> [   44.261396][ T9490] RIP: 0010:upd78f0730_tiocmset+0x86/0x4b0

> [   44.270495][ T9490] Call Trace:
> [   44.270882][ T9490]  <TASK>
> [   44.271160][ T9490]  ? __pfx_upd78f0730_tiocmset+0x10/0x10
> [   44.271694][ T9490]  ? __pfx_serial_port_dtr_rts+0x10/0x10
> [   44.272208][ T9490]  tty_port_shutdown+0x165/0x220
> [   44.272672][ T9490]  tty_port_hangup+0xee/0x170
> [   44.273101][ T9490]  ? __pfx_serial_hangup+0x10/0x10
> [   44.273600][ T9490]  __tty_hangup+0x5a7/0x650
> [   44.274074][ T9490]  tty_ioctl+0x757/0xde0

Another symptom of this issue was reported by syzbot a couple of weeks
ago and I posted a fix for the tty layer last week:

	https://lore.kernel.org/lkml/20260910125114.640880-1-johan@kernel.org/

Johan

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-09-16 13:47 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-11 20:16 [BUG] general protection fault in upd78f0730_tiocmset Farhad Alemi
2026-09-16 13:47 ` Johan Hovold

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®