All of lore.kernel.org
 help / color / mirror / Atom feed
From: syzbot <syzbot+e6616d0dc8ded5dc56d6@syzkaller.appspotmail.com>
To: asml.silence@gmail.com, axboe@kernel.dk,
	io-uring@vger.kernel.org,  linux-kernel@vger.kernel.org,
	syzkaller-bugs@googlegroups.com
Subject: Re: [syzbot] [io-uring?] KMSAN: uninit-value in io_req_cqe_overflow (3)
Date: Thu, 13 Jun 2024 19:20:05 -0700	[thread overview]
Message-ID: <000000000000ed98d9061ad0404e@google.com> (raw)
In-Reply-To: <fc8f4adb-feef-421b-995d-ae9ae059f4c5@kernel.dk>

Hello,

syzbot tried to test the proposed patch but the build/boot failed:

6.343044][    T1] openvswitch: Open vSwitch switching datapath
[   46.363888][    T1] NET: Registered PF_VSOCK protocol family
[   46.372367][    T1] mpls_gso: MPLS GSO support
[   46.524387][    T1] IPI shorthand broadcast: enabled
[   48.017346][    T1] sched_clock: Marking stable (47990050167, 17795964)->(48016243838, -8397707)
[   49.133874][    T1] Timer migration: 1 hierarchy levels; 8 children per group; 0 crossnode level
[   49.302883][    T1] registered taskstats version 1
[   49.367583][    T1] Loading compiled-in X.509 certificates
[   49.405812][    T1] Loaded X.509 cert 'Build time autogenerated kernel key: ef5392d16e2343e2e997a1a8439f31430dca794f'
[   49.643401][    T1] zswap: loaded using pool lzo/zsmalloc
[   49.652895][    T1] Demotion targets for Node 0: null
[   49.658483][    T1] Demotion targets for Node 1: null
[   49.665807][    T1] Key type .fscrypt registered
[   49.672365][    T1] Key type fscrypt-provisioning registered
[   49.679915][    T1] kAFS: Red Hat AFS client v0.1 registering.
[   49.713149][    T1] Btrfs loaded, assert=on, ref-verify=on, zoned=yes, fsverity=yes
[   49.740050][    T1] Key type encrypted registered
[   49.745095][    T1] AppArmor: AppArmor sha256 policy hashing enabled
[   49.753397][    T1] ima: No TPM chip found, activating TPM-bypass!
[   49.759983][    T1] Loading compiled-in module X.509 certificates
[   49.802303][    T1] Loaded X.509 cert 'Build time autogenerated kernel key: ef5392d16e2343e2e997a1a8439f31430dca794f'
[   49.813515][    T1] ima: Allocated hash algorithm: sha256
[   49.819655][    T1] ima: No architecture policies found
[   49.826134][    T1] evm: Initialising EVM extended attributes:
[   49.832247][    T1] evm: security.selinux (disabled)
[   49.837410][    T1] evm: security.SMACK64 (disabled)
[   49.842758][    T1] evm: security.SMACK64EXEC (disabled)
[   49.848460][    T1] evm: security.SMACK64TRANSMUTE (disabled)
[   49.854407][    T1] evm: security.SMACK64MMAP (disabled)
[   49.860131][    T1] evm: security.apparmor
[   49.864545][    T1] evm: security.ima
[   49.868491][    T1] evm: security.capability
[   49.872958][    T1] evm: HMAC attrs: 0x1
[   49.882187][    T1] PM:   Magic number: 12:875:156
[   49.888285][    T1] usb usb36-port7: hash matches
[   49.894166][    T1] bdi 1:8: hash matches
[   49.900642][    T1] printk: legacy console [netcon0] enabled
[   49.906787][    T1] netconsole: network logging started
[   49.913765][    T1] gtp: GTP module loaded (pdp ctx size 128 bytes)
[   49.922755][    T1] rdma_rxe: loaded
[   49.928813][    T1] cfg80211: Loading compiled-in X.509 certificates for regulatory database
[   49.950799][    T1] Loaded X.509 cert 'sforshee: 00b28ddf47aef9cea7'
[   49.969818][    T1] Loaded X.509 cert 'wens: 61c038651aabdcf94bd0ac7ff06c7248db18c600'
[   49.978593][    T1] clk: Disabling unused clocks
[   49.983531][    T1] ALSA device list:
[   49.987431][    T1]   #0: Dummy 1
[   49.991050][    T1]   #1: Loopback 1
[   49.994878][    T1]   #2: Virtual MIDI Card 1
[   50.005050][   T10] platform regulatory.0: Direct firmware load for regulatory.db failed with error -2
[   50.014970][   T10] platform regulatory.0: Falling back to sysfs fallback for: regulatory.db
[   50.024723][    T1] md: Waiting for all devices to be available before autodetect
[   50.032705][    T1] md: If you don't use raid, use raid=noautodetect
[   50.039465][    T1] md: Autodetecting RAID arrays.
[   50.044595][    T1] md: autorun ...
[   50.048512][    T1] md: ... autorun DONE.
[   50.117733][    T1] EXT4-fs (sda1): mounted filesystem 5941fea2-f5fa-4b4e-b5ef-9af118b27b95 ro with ordered data mode. Quota mode: none.
[   50.131603][    T1] VFS: Mounted root (ext4 filesystem) readonly on device 8:1.
[   50.144403][    T1] devtmpfs: mounted
[   50.408360][    T1] Freeing unused kernel image (initmem) memory: 37036K
[   50.420188][    T1] Write protecting the kernel read-only data: 262144k
[   50.467096][    T1] Freeing unused kernel image (rodata/data gap) memory: 1804K
[   52.119267][    T1] x86/mm: Checked W+X mappings: passed, no W+X pages found.
[   52.129621][    T1] x86/mm: Checking user space page tables
[   53.636226][    T1] x86/mm: Checked W+X mappings: passed, no W+X pages found.
[   53.645529][    T1] Failed to set sysctl parameter 'kernel.hung_task_all_cpu_backtrace=1': parameter not found
[   53.666750][    T1] Failed to set sysctl parameter 'max_rcu_stall_to_panic=1': parameter not found
[   53.678915][    T1] Run /sbin/init as init process
[   55.261831][ T4447] mount (4447) used greatest stack depth: 7808 bytes left
[   55.340544][ T4448] EXT4-fs (sda1): re-mounted 5941fea2-f5fa-4b4e-b5ef-9af118b27b95 r/w. Quota mode: none.
mount: mounting smackfs on /sys/fs/smackfs failed: No such file or directory
mount: mounting selinuxfs on /sys/fs/selinux failed: No such file or directory
[   55.675477][ T4451] mount (4451) used greatest stack depth: 5568 bytes left
Starting syslogd: OK
Starting acpid: OK
Starting klogd: OK
Running sysctl: OK
Populating /dev using udev: [   59.510303][ T4481] udevd[4481]: starting version 3.2.11
[   63.097528][ T4482] udevd[4482]: starting eudev-3.2.11
[   63.110491][ T4481] udevd (4481) used greatest stack depth: 5232 bytes left
done
Starting system message bus: done
Starting iptables: OK
Starting network: OK
Starting dhcpcd...
dhcpcd-9.4.1 starting
dev: loaded udev
DUID 00:04:c7:fd:4a:df:9d:a6:e9:60:55:7b:b4:5b:1f:77:00:5c
forked to background, child pid 4695
[  110.977706][ T4696] 8021q: adding VLAN 0 to HW filter on device bond0
[  111.031404][ T4696] eql: remember to turn off Van-Jacobson compression on your slave devices
[  111.650739][   T10] cfg80211: failed to load regulatory.db
Starting sshd: OK


syzkaller

syzkaller login: [  114.063784][    C0] =====================================================
[  114.071021][    C0] BUG: KMSAN: uninit-value in receive_buf+0x25e3/0x5fd0
[  114.078922][    C0]  receive_buf+0x25e3/0x5fd0
[  114.083796][    C0]  virtnet_poll+0xd1c/0x23c0
[  114.088752][    C0]  __napi_poll+0xe7/0x980
[  114.093517][    C0]  net_rx_action+0x82a/0x1850
[  114.098512][    C0]  handle_softirqs+0x1ce/0x800
[  114.103581][    C0]  __irq_exit_rcu+0x68/0x120
[  114.108412][    C0]  irq_exit_rcu+0x12/0x20
[  114.112996][    C0]  common_interrupt+0x94/0xa0
[  114.118086][    C0]  asm_common_interrupt+0x2b/0x40
[  114.123480][    C0]  __msan_metadata_ptr_for_load_8+0x18/0x40
[  114.129797][    C0]  filemap_map_pages+0xe81/0x2e30
[  114.135034][    C0]  handle_mm_fault+0x6f36/0xe610
[  114.140206][    C0]  exc_page_fault+0x41b/0x700
[  114.145072][    C0]  asm_exc_page_fault+0x2b/0x30
[  114.150167][    C0] 
[  114.152572][    C0] Uninit was created at:
[  114.156953][    C0]  __alloc_pages_noprof+0x9d6/0xe70
[  114.162368][    C0]  alloc_pages_mpol_noprof+0x299/0x990
[  114.168132][    C0]  alloc_pages_noprof+0x1bf/0x1e0
[  114.173274][    C0]  skb_page_frag_refill+0x2bf/0x7c0
[  114.178692][    C0]  virtnet_rq_alloc+0x43/0xbb0
[  114.183610][    C0]  try_fill_recv+0x3f0/0x2f50
[  114.188492][    C0]  virtnet_open+0x1cc/0xb00
[  114.193392][    C0]  __dev_open+0x546/0x6f0
[  114.197955][    C0]  __dev_change_flags+0x309/0x9a0
[  114.203263][    C0]  dev_change_flags+0x8e/0x1d0
[  114.208266][    C0]  devinet_ioctl+0x13ec/0x22c0
[  114.213265][    C0]  inet_ioctl+0x4bd/0x6d0
[  114.217709][    C0]  sock_do_ioctl+0xb7/0x540
[  114.222474][    C0]  sock_ioctl+0x727/0xd70
[  114.226915][    C0]  __se_sys_ioctl+0x261/0x450
[  114.231888][    C0]  __x64_sys_ioctl+0x96/0xe0
[  114.236624][    C0]  x64_sys_call+0x18c0/0x3b90
[  114.241782][    C0]  do_syscall_64+0xcd/0x1e0
[  114.246586][    C0]  entry_SYSCALL_64_after_hwframe+0x77/0x7f
[  114.252971][    C0] 
[  114.255409][    C0] CPU: 0 PID: 4803 Comm: rm Not tainted 6.10.0-rc3-syzkaller-00102-ga3027fbd92ad #0
[  114.265197][    C0] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/07/2024
[  114.275517][    C0] =====================================================
[  114.282666][    C0] Disabling lock debugging due to kernel taint
[  114.289094][    C0] Kernel panic - not syncing: kmsan.panic set ...
[  114.295774][    C0] CPU: 0 PID: 4803 Comm: rm Tainted: G    B              6.10.0-rc3-syzkaller-00102-ga3027fbd92ad #0
[  114.307012][    C0] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/07/2024
[  114.317158][    C0] Call Trace:
[  114.320500][    C0]  <IRQ>
[  114.323392][    C0]  dump_stack_lvl+0x216/0x2d0
[  114.328201][    C0]  ? kmsan_get_shadow_origin_ptr+0x4d/0xb0
[  114.334149][    C0]  dump_stack+0x1e/0x30
[  114.338426][    C0]  panic+0x4e2/0xcd0
[  114.342445][    C0]  ? kmsan_get_metadata+0xb1/0x1d0
[  114.348148][    C0]  kmsan_report+0x2d5/0x2e0
[  114.352948][    C0]  ? kmsan_get_metadata+0x146/0x1d0
[  114.358285][    C0]  ? __msan_warning+0x95/0x120
[  114.363159][    C0]  ? receive_buf+0x25e3/0x5fd0
[  114.368024][    C0]  ? virtnet_poll+0xd1c/0x23c0
[  114.372882][    C0]  ? __napi_poll+0xe7/0x980
[  114.377788][    C0]  ? net_rx_action+0x82a/0x1850
[  114.382798][    C0]  ? handle_softirqs+0x1ce/0x800
[  114.387868][    C0]  ? __irq_exit_rcu+0x68/0x120
[  114.392766][    C0]  ? irq_exit_rcu+0x12/0x20
[  114.397357][    C0]  ? common_interrupt+0x94/0xa0
[  114.402324][    C0]  ? asm_common_interrupt+0x2b/0x40
[  114.407634][    C0]  ? __msan_metadata_ptr_for_load_8+0x18/0x40
[  114.413807][    C0]  ? filemap_map_pages+0xe81/0x2e30
[  114.419117][    C0]  ? handle_mm_fault+0x6f36/0xe610
[  114.424461][    C0]  ? exc_page_fault+0x41b/0x700
[  114.429619][    C0]  ? asm_exc_page_fault+0x2b/0x30
[  114.434797][    C0]  ? kmsan_get_metadata+0x146/0x1d0
[  114.440132][    C0]  ? kmsan_get_metadata+0x146/0x1d0
[  114.445631][    C0]  ? kmsan_internal_memmove_metadata+0x17b/0x230
[  114.452123][    C0]  ? kmsan_get_metadata+0x146/0x1d0
[  114.457453][    C0]  ? kmsan_get_metadata+0x146/0x1d0
[  114.462794][    C0]  ? page_to_skb+0xdae/0x1620
[  114.467694][    C0]  ? kmsan_get_metadata+0x146/0x1d0
[  114.473057][    C0]  __msan_warning+0x95/0x120
[  114.477746][    C0]  receive_buf+0x25e3/0x5fd0
[  114.482558][    C0]  ? kmsan_get_metadata+0x146/0x1d0
[  114.488004][    C0]  ? kmsan_get_shadow_origin_ptr+0x4d/0xb0
[  114.493964][    C0]  virtnet_poll+0xd1c/0x23c0
[  114.498684][    C0]  ? __pfx_virtnet_poll+0x10/0x10
[  114.503816][    C0]  __napi_poll+0xe7/0x980
[  114.508269][    C0]  ? kmsan_get_metadata+0x146/0x1d0
[  114.513605][    C0]  net_rx_action+0x82a/0x1850
[  114.518407][    C0]  ? sched_clock_cpu+0x55/0x870
[  114.523437][    C0]  ? __pfx_net_rx_action+0x10/0x10
[  114.528662][    C0]  handle_softirqs+0x1ce/0x800
[  114.533665][    C0]  __irq_exit_rcu+0x68/0x120
[  114.538379][    C0]  irq_exit_rcu+0x12/0x20
[  114.542838][    C0]  common_interrupt+0x94/0xa0
[  114.547656][    C0]  </IRQ>
[  114.550894][    C0]  <TASK>
[  114.553890][    C0]  asm_common_interrupt+0x2b/0x40
[  114.559040][    C0] RIP: 0010:__msan_metadata_ptr_for_load_8+0x18/0x40
[  114.565833][    C0] Code: 00 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 55 48 89 e5 53 48 83 ec 10 9c 8f 45 e8 0f 01 ca 48 8b 5d e8 <be> 08 00 00 00 31 d2 e8 9c 25 00 00 48 89 5d f0 ff 75 f0 9d 48 83
[  114.585747][    C0] RSP: 0000:ffff88811852fa60 EFLAGS: 00000286
[  114.591926][    C0] RAX: 0000000000000000 RBX: 0000000000000286 RCX: ffff888116094180
[  114.600091][    C0] RDX: 0000000000000000 RSI: 0000000000000036 RDI: ffff88811852fa90
[  114.608158][    C0] RBP: ffff88811852fa78 R08: ffffffff8203f34a R09: ffffffff8203e5a8
[  114.616220][    C0] R10: 0000000000000002 R11: ffff888116094180 R12: 0000000002b000d1
[  114.624272][    C0] R13: 000000000000000c R14: 000000000000000b R15: 0000000000000000
[  114.632317][    C0]  ? next_uptodate_folio+0x4c8/0x1730
[  114.637792][    C0]  ? next_uptodate_folio+0x126a/0x1730
[  114.643393][    C0]  filemap_map_pages+0xe81/0x2e30
[  114.648516][    C0]  ? kmsan_get_metadata+0x146/0x1d0
[  114.653822][    C0]  ? kmsan_get_shadow_origin_ptr+0x4d/0xb0
[  114.659840][    C0]  ? kmsan_get_metadata+0x146/0x1d0
[  114.665189][    C0]  handle_mm_fault+0x6f36/0xe610
[  114.670266][    C0]  ? kmsan_get_metadata+0x146/0x1d0
[  114.675574][    C0]  ? kmsan_get_metadata+0x146/0x1d0
[  114.681161][    C0]  ? __pfx_filemap_map_pages+0x10/0x10
[  114.686733][    C0]  exc_page_fault+0x41b/0x700
[  114.691535][    C0]  asm_exc_page_fault+0x2b/0x30
[  114.696492][    C0] RIP: 0033:0x7fc22a8cdd20
[  114.701001][    C0] Code: Unable to access opcode bytes at 0x7fc22a8cdcf6.
[  114.708193][    C0] RSP: 002b:00007ffd152fccc0 EFLAGS: 00010202
[  114.714661][    C0] RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000000
[  114.722723][    C0] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
[  114.730785][    C0] RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000
[  114.738829][    C0] R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000000
[  114.747002][    C0] R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000
[  114.755163][    C0]  </TASK>
[  114.758494][    C0] Kernel Offset: disabled
[  114.762888][    C0] Rebooting in 86400 seconds..


syzkaller build log:
go env (err=<nil>)
GO111MODULE='auto'
GOARCH='amd64'
GOBIN=''
GOCACHE='/syzkaller/.cache/go-build'
GOENV='/syzkaller/.config/go/env'
GOEXE=''
GOEXPERIMENT=''
GOFLAGS=''
GOHOSTARCH='amd64'
GOHOSTOS='linux'
GOINSECURE=''
GOMODCACHE='/syzkaller/jobs-2/linux/gopath/pkg/mod'
GONOPROXY=''
GONOSUMDB=''
GOOS='linux'
GOPATH='/syzkaller/jobs-2/linux/gopath'
GOPRIVATE=''
GOPROXY='https://proxy.golang.org,direct'
GOROOT='/usr/local/go'
GOSUMDB='sum.golang.org'
GOTMPDIR=''
GOTOOLCHAIN='auto'
GOTOOLDIR='/usr/local/go/pkg/tool/linux_amd64'
GOVCS=''
GOVERSION='go1.21.4'
GCCGO='gccgo'
GOAMD64='v1'
AR='ar'
CC='gcc'
CXX='g++'
CGO_ENABLED='1'
GOMOD='/syzkaller/jobs-2/linux/gopath/src/github.com/google/syzkaller/go.mod'
GOWORK=''
CGO_CFLAGS='-O2 -g'
CGO_CPPFLAGS=''
CGO_CXXFLAGS='-O2 -g'
CGO_FFLAGS='-O2 -g'
CGO_LDFLAGS='-O2 -g'
PKG_CONFIG='pkg-config'
GOGCCFLAGS='-fPIC -m64 -pthread -Wl,--no-gc-sections -fmessage-length=0 -ffile-prefix-map=/tmp/go-build2855798142=/tmp/go-build -gno-record-gcc-switches'

git status (err=<nil>)
HEAD detached at 2aa5052fed
nothing to commit, working tree clean


tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
go list -f '{{.Stale}}' ./sys/syz-sysgen | grep -q false || go install ./sys/syz-sysgen
make .descriptions
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
bin/syz-sysgen
go fmt ./sys/... >/dev/null
touch .descriptions
GOOS=linux GOARCH=amd64 go build "-ldflags=-s -w -X github.com/google/syzkaller/prog.GitRevision=2aa5052fed5f8993afacfce02174322df0f03ec4 -X 'github.com/google/syzkaller/prog.gitRevisionDate=20240612-135002'" "-tags=syz_target syz_os_linux syz_arch_amd64 " -o ./bin/linux_amd64/syz-fuzzer github.com/google/syzkaller/syz-fuzzer
GOOS=linux GOARCH=amd64 go build "-ldflags=-s -w -X github.com/google/syzkaller/prog.GitRevision=2aa5052fed5f8993afacfce02174322df0f03ec4 -X 'github.com/google/syzkaller/prog.gitRevisionDate=20240612-135002'" "-tags=syz_target syz_os_linux syz_arch_amd64 " -o ./bin/linux_amd64/syz-execprog github.com/google/syzkaller/tools/syz-execprog
mkdir -p ./bin/linux_amd64
g++ -o ./bin/linux_amd64/syz-executor executor/executor.cc \
	-m64 -O2 -pthread -Wall -Werror -Wparentheses -Wunused-const-variable -Wframe-larger-than=16384 -Wno-stringop-overflow -Wno-array-bounds -Wno-format-overflow -Wno-unused-but-set-variable -Wno-unused-command-line-argument -static-pie -std=c++17 -I. -Iexecutor/_include -fpermissive -w -DGOOS_linux=1 -DGOARCH_amd64=1 \
	-DHOSTGOOS_linux=1 -DGIT_REVISION=\"2aa5052fed5f8993afacfce02174322df0f03ec4\"


Error text is too large and was truncated, full error text is at:
https://syzkaller.appspot.com/x/error.txt?x=12e30256980000


Tested on:

commit:         a3027fbd Merge branch 'master' into syz-test
git tree:       git://git.kernel.dk/linux.git syz-test
kernel config:  https://syzkaller.appspot.com/x/.config?x=3486f1660f47f855
dashboard link: https://syzkaller.appspot.com/bug?extid=e6616d0dc8ded5dc56d6
compiler:       Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40

Note: no patches were applied.

  reply	other threads:[~2024-06-14  2:20 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-06-13 19:38 [syzbot] [io-uring?] KMSAN: uninit-value in io_req_cqe_overflow (3) syzbot
2024-06-14  1:28 ` Jens Axboe
2024-06-14  1:53   ` syzbot
2024-06-14  1:56     ` Jens Axboe
2024-06-14  2:20       ` syzbot [this message]
2024-07-25 15:09 ` Jens Axboe
2024-07-25 17:58   ` syzbot
2024-07-25 15:33 ` Jens Axboe

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=000000000000ed98d9061ad0404e@google.com \
    --to=syzbot+e6616d0dc8ded5dc56d6@syzkaller.appspotmail.com \
    --cc=asml.silence@gmail.com \
    --cc=axboe@kernel.dk \
    --cc=io-uring@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=syzkaller-bugs@googlegroups.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.