All of lore.kernel.org
 help / color / mirror / Atom feed
From: Joshua Crofts <joshua.crofts1@gmail.com>
To: Jeffin Philip <jeffinphilip14@gmail.com>
Cc: a.hindborg@kernel.org, leitao@debian.org,
	linux-kernel@vger.kernel.org,
	syzbot+35790eb7861f8fc57382@syzkaller.appspotmail.com
Subject: Re: [PATCH] configfs: fix refcount warning in configfs_get_config_item()
Date: Thu, 30 Jul 2026 09:30:15 +0200	[thread overview]
Message-ID: <20260730093015.000026cd@gmail.com> (raw)
In-Reply-To: <20260729150525.100654-1-jeffinphilip14@gmail.com>

On Wed, 29 Jul 2026 20:35:25 +0530
Jeffin Philip <jeffinphilip14@gmail.com> wrote:
> >> I tested this solution first on syzbot and well, it errored out. But on testing it on a local
> >> build, it seems to trigger a different warning in configfs_get() regarding atomic count. Could you please 
> >> look into it?  
> >
> >Yeah, I've no idea why syzbot keeps failing on "FATAL: Kernel too old",
> >especially when testing against upstream. As for the different warning,
> >that's odd, because when I booted the kernel with the patch in QEMU and
> >ran the reproducer nothing happened. Could you please send the warning
> >in it's entirety?  
> 
> I assume you did not set panic_on_warn to 1. Try setting it first and 
> re-run the reproducer. I would also encourage you to copy the .config file 
> from syzbot and build the kernel yourself to test apart from using the 
> prebuilt bzImage. Also as Breno said, this is more of a workaround, you 
> could attempt to drop the dentry immediately after unlinking the group and 
> then attempt to hold an extra reference(?) to the path and then safely free 
> it later.
> 

Yes, the kernel was build with the .config from syzbot but my script had
panic_on_warn set to zero. Anyhow - ran the reproducer and got a
slab-use-after-free instead :(

[   42.758574][ T5767] BUG: KASAN: slab-use-after-free in configfs_dirent_is_ready+0x6b/0x70
[   42.758655][ T5767] Read of size 4 at addr ffff88804b241fb8 b[   42.758655][ T5767] Read of size 4 at addr ffff88804b241fb8 by task repro/5767
[   42.758661][ T5767] 
[   42.758695][ T5767] CPU: 0 UID: 0 PID: 5767 Comm: repro Not tainted 7.2.0-rc3-g6291aad4984e #8 PREEMPT_{RT,(full)} 
[   42.758705][ T5767] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[   42.758710][ T5767] Call Trace:
[   42.758714][ T5767]  <TASK>
[   42.758717][ T5767]  dump_stack_lvl+0x100/0x190
[   42.758727][ T5767]  print_report+0x13d/0x4b0
[   42.758738][ T5767]  ? __virt_addr_valid+0x239/0x430
[   42.758748][ T5767]  ? configfs_dirent_is_ready+0x6b/0x70
[   42.758755][ T5767]  kasan_report+0xdf/0x1c0
[   42.758765][ T5767]  ? configfs_dirent_is_ready+0x6b/0x70
[   42.758773][ T5767]  configfs_dirent_is_ready+0x6b/0x70
[   42.758832][ T5767]  configfs_symlink+0x5c4/0x11f0
[   42.758840][ T5767]  ? bpf_lsm_inode_permission+0x9/0x10
[   42.758849][ T5767]  ? security_inode_permission+0xbf/0x250
[   42.758857][ T5767]  ? __pfx_configfs_symlink+0x10/0x10
[   42.758866][ T5767]  vfs_symlink+0x178/0x4e0
[   42.758875][ T5767]  filename_symlinkat+0x2a6/0x570
[   42.758888][ T5767]  ? __pfx_filename_symlinkat+0x10/0x10
[   42.758901][ T5767]  ? strncpy_from_user+0x19d/0x2d0
[   42.758911][ T5767]  ? do_getname+0x191/0x390
[   42.758918][ T5767]  __x64_sys_symlinkat+0x9c/0xe0
[   42.758931][ T5767]  do_syscall_64+0x115/0x840
[   42.758958][ T5767]  entry_SYSCALL_64_after_hwframe+0x77/0x7f
[   42.758967][ T5767] RIP: 0033:0x416df9
[   42.758973][ T5767] Code: c0 79 93 eb d5 48 8d 7c 1d 00 eb 99 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 f0 ff ff ff f7 d8 64 89 01 48
[   42.759021][ T5767] RSP: 002b:00007ffe2756add8 EFLAGS: 00000287 ORIG_RAX: 000000000000010a
[   42.759030][ T5767] RAX: ffffffffffffffda RBX: 00007ffe2756af48 RCX: 0000000000416df9
[   42.759035][ T5767] RDX: 0000200000000300 RSI: 00000000ffffff9c RDI: 0000200000000200
[   42.759040][ T5767] RBP: 00007ffe2756ade0 R08: 00007ffe2756ae10 R09: 00007ffe2756ae10
[   42.759045][ T5767] R10: 00007ffe2756ae10 R11: 0000000000000287 R12: 00007ffe2756af38
[   42.759050][ T5767] R13: 0000000000000002 R14: 00000000004a3de0 R15: 0000000000000002
[   42.759058][ T5767]  </TASK>
[   42.759060][ T5767] 
[   42.759062][ T5767] Allocated by task 5764:
[   42.759068][ T5767]  kasan_save_stack+0x30/0x50
[   42.759075][ T5767]  kasan_save_track+0x14/0x30
[   42.759081][ T5767]  __kasan_slab_alloc+0x89/0x90
[   42.759088][ T5767]  kmem_cache_alloc_noprof+0x20e/0x6c0
[   42.759095][ T5767]  configfs_new_dirent+0x52/0x570
[   42.759105][ T5767]  configfs_make_dirent+0x36/0x1a0
[   42.759116][ T5767]  configfs_create_dir+0xbd/0x5c0
[   42.759127][ T5767]  configfs_attach_group+0x2a/0x440
[   42.759138][ T5767]  configfs_mkdir+0x65c/0xb70
[   42.759149][ T5767]  vfs_mkdir+0x361/0x860
[   42.759156][ T5767]  filename_mkdirat+0x491/0x5f0
[   42.759167][ T5767]  __x64_sys_mkdirat+0x89/0xc0
[   42.759177][ T5767]  do_syscall_64+0x115/0x840
[   42.759184][ T5767]  entry_SYSCALL_64_after_hwframe+0x77/0x7f
[   42.759191][ T5767] 
[   42.759192][ T5767] Freed by task 5764:
[   42.759195][ T5767]  kasan_save_stack+0x30/0x50
[   42.759201][ T5767]  kasan_save_track+0x14/0x30
[   42.759207][ T5767]  kasan_save_free_info+0x3b/0x70
[   42.759216][ T5767]  __kasan_slab_free+0x5f/0x80
[   42.759223][ T5767]  kmem_cache_free+0x123/0x6a0
[   42.759245][ T5767]  configfs_d_iput+0x20d/0x290
[   42.759254][ T5767]  dentry_unlink_inode+0x265/0x470
[   42.759265][ T5767]  d_delete+0x213/0x280
[   42.759270][ T5767]  vfs_rmdir+0x4ab/0x8b0
[   42.759278][ T5767]  filename_rmdir+0x31a/0x5d0
[   42.759288][ T5767]  __x64_sys_rmdir+0x46/0x70
[   42.759298][ T5767]  do_syscall_64+0x115/0x840
[   42.759305][ T5767]  entry_SYSCALL_64_after_hwframe+0x77/0x7f
[   42.759312][ T5767] 
[   42.759313][ T5767] The buggy address belongs to the object at ffff88804b241f80
[   42.759313][ T5767]  which belongs to the cache configfs_dir_cache of size 96
[   42.759319][ T5767] The buggy address is located 56 bytes inside of
[   42.759319][ T5767]  freed 96-byte region [ffff88804b241f80, ffff88804b241fe0)
[   42.759326][ T5767] 
[   42.759327][ T5767] The buggy address belongs to the physical page:
[   42.759331][ T5767] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x4b241
[   42.759339][ T5767] flags: 0x480000000000000(node=1|zone=1)
[   42.759344][ T5767] page_type: f5(slab)
[   42.759351][ T5767] raw: 0480000000000000 ffff888040417780 dead000000000122 0000000000000000
[   42.759393][ T5767] raw: 0000000000000000 0000000800200020 00000000f5000000 0000000000000000
[   42.759397][ T5767] page dumped because: kasan: bad access detected
[   42.759401][ T5767] page_owner tracks the page as allocated
[   42.759403][ T5767] page last allocated via order 0, migratetype Unmovable, gfp_mask 0xd2cc0(GFP_KERNEL|__GFP_NOWARN|__GFP_NORETRY|__GFP_COMP|__GFP_NOMEMALLOC), pid 5755, tgid 5755 (repro), ts 42727601277, free_ts 42589616669
[   42.759416][ T5767]  post_alloc_hook+0xfd/0x120
[   42.759426][ T5767]  get_page_from_freelist+0xcb6/0x3400
[   42.759436][ T5767]  __alloc_frozen_pages_noprof+0x299/0x2f60
[   42.759446][ T5767]  new_slab+0xa2/0x660
[   42.759455][ T5767]  refill_objects+0xe3/0x460
[   42.759465][ T5767]  __pcs_replace_empty_main+0x17a/0x6d0
[   42.759483][ T5767]  kmem_cache_alloc_noprof+0x4fd/0x6c0
[   42.759490][ T5767]  configfs_new_dirent+0x52/0x570
[   42.759499][ T5767]  configfs_make_dirent+0x36/0x1a0
[   42.759509][ T5767]  configfs_create_file+0xfe/0x180
[   42.759518][ T5767]  configfs_attach_item.part.0+0x147/0x4f0
[   42.759529][ T5767]  configfs_attach_group+0x63/0x440
[   42.759540][ T5767]  create_default_group+0x75/0x180
[   42.759550][ T5767]  configfs_attach_group+0x212/0x440
[   42.759561][ T5767]  configfs_mkdir+0x65c/0xb70
[   42.759571][ T5767]  vfs_mkdir+0x361/0x860
[   42.759578][ T5767] page last free pid 20 tgid 20 stack trace:
[   42.759581][ T5767]  __free_frozen_pages+0x95e/0x1600
[   42.759590][ T5767]  rcu_core+0x5ef/0x1170
[   42.759599][ T5767]  rcu_cpu_kthread+0x1fa/0x410
[   42.759608][ T5767]  smpboot_thread_fn+0x3d3/0xaa0
[   42.759616][ T5767]  kthread+0x370/0x450
[   42.759625][ T5767]  ret_from_fork+0x72b/0xd50
[   42.759634][ T5767]  ret_from_fork_asm+0x1a/0x30
[   42.759644][ T5767] 
[   42.759645][ T5767] Memory state around the buggy address:
[   42.759649][ T5767]  ffff88804b241e80: fa fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc
[   42.759653][ T5767]  ffff88804b241f00: fa fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc
[   42.759672][ T5767] >ffff88804b241f80: fa fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc
[   42.759675][ T5767]                                         ^
[   42.759679][ T5767]  ffff88804b242000: fa fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[   42.759684][ T5767]  ffff88804b242080: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[   42.759687][ T5767] ==================================================================
[   42.763360][ T5767] Kernel panic - not syncing: KASAN: panic_on_warn set ...


-- 
Kind regards,
Joshua Crofts

      reply	other threads:[~2026-07-30  7:30 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-29  8:55 [PATCH] configfs: fix refcount warning in configfs_get_config_item() Joshua Crofts
2026-07-29  9:00 ` Joshua Crofts
2026-07-29  9:51   ` Jeffin Philip
2026-07-29 13:50     ` Joshua Crofts
2026-07-29 10:06 ` Breno Leitao
2026-07-29 13:31   ` Joshua Crofts
2026-07-29 15:05     ` Jeffin Philip
2026-07-30  7:30       ` Joshua Crofts [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260730093015.000026cd@gmail.com \
    --to=joshua.crofts1@gmail.com \
    --cc=a.hindborg@kernel.org \
    --cc=jeffinphilip14@gmail.com \
    --cc=leitao@debian.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=syzbot+35790eb7861f8fc57382@syzkaller.appspotmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.