All of lore.kernel.org
 help / color / mirror / Atom feed
* [BUG] afs: ERR_PTR dereference in afs_lookup_server() error path
@ 2026-08-27 22:37 Farhad Alemi
  2026-09-02 11:40 ` David Howells
  0 siblings, 1 reply; 3+ messages in thread
From: Farhad Alemi @ 2026-08-27 22:37 UTC (permalink / raw)
  To: David Howells, Marc Dionne; +Cc: falemi, linux-afs, linux-fsdevel, linux-kernel

Hello David and Marc,

While fuzzing Linux 7.1-rc5 with syzkaller, as part of research at ASU's
SEFCOM lab, we hit the crash below. Crash reports can be found here:

  https://github.com/farhad-alemi/public_bug_reports/tree/main/104-afs-err_ptr-deref-afs_put_addrlist/

  BUG: unable to handle page fault for address: ffffffffffffff9f
  RIP: 0010:afs_put_addrlist+0x43/0x250 fs/afs/addr_list.c:38
  afs_lookup_server+0xd3f/0x1020 fs/afs/server.c:243
  afs_alloc_server_list+0x800/0x11a0 fs/afs/server_list.c:82
  afs_create_volume+0x995/0x1290 fs/afs/volume.c:227
  afs_get_tree+0x955/0x10b0 fs/afs/super.c:555

Our reproducer.c is available upon request.

Happy to test a patch if that would help.

Regards,

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [BUG] afs: ERR_PTR dereference in afs_lookup_server() error path
  2026-08-27 22:37 [BUG] afs: ERR_PTR dereference in afs_lookup_server() error path Farhad Alemi
@ 2026-09-02 11:40 ` David Howells
  2026-09-09 18:12   ` Farhad Alemi
  0 siblings, 1 reply; 3+ messages in thread
From: David Howells @ 2026-09-02 11:40 UTC (permalink / raw)
  To: Farhad Alemi
  Cc: dhowells, Marc Dionne, falemi, linux-afs, linux-fsdevel,
	linux-kernel

Hi Farhad,

> While fuzzing Linux 7.1-rc5 with syzkaller, as part of research at ASU's
> SEFCOM lab, we hit the crash below. Crash reports can be found here:

Have you tried it with 7.3-rc1?

>   BUG: unable to handle page fault for address: ffffffffffffff9f
>   RIP: 0010:afs_put_addrlist+0x43/0x250 fs/afs/addr_list.c:38
>   afs_lookup_server+0xd3f/0x1020 fs/afs/server.c:243
>   afs_alloc_server_list+0x800/0x11a0 fs/afs/server_list.c:82
>   afs_create_volume+0x995/0x1290 fs/afs/volume.c:227
>   afs_get_tree+0x955/0x10b0 fs/afs/super.c:555

It looks like alist is 0xffffffffffffff9f, but it's not immediately obvious
how it could be anything other than a valid pointer at that point.

> Our reproducer.c is available upon request.

If I could have that, please?

Thanks,
David


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [BUG] afs: ERR_PTR dereference in afs_lookup_server() error path
  2026-09-02 11:40 ` David Howells
@ 2026-09-09 18:12   ` Farhad Alemi
  0 siblings, 0 replies; 3+ messages in thread
From: Farhad Alemi @ 2026-09-09 18:12 UTC (permalink / raw)
  To: David Howells; +Cc: Marc Dionne, falemi, linux-afs, linux-fsdevel, linux-kernel

[-- Attachment #1: Type: text/plain, Size: 6798 bytes --]

Hi David,

Tried it w 7.3.0-rc2-00006-g28924df2a08f:

[   43.872155][ T9500] BUG: unable to handle page fault for address:
ffffffffffffffb1
[   43.873156][ T9500] #PF: supervisor read access in kernel mode
[   43.873889][ T9500] #PF: error_code(0x0000) - not-present page
[   43.874619][ T9500] PGD e94b067 P4D e94b067 PUD e94d067 PMD 0
[   43.875371][ T9500] Oops: Oops: 0000 [#1] SMP KASAN NOPTI
[   43.876050][ T9500] CPU: 1 UID: 0 PID: 9500 Comm: repro Not tainted
7.3.0-rc2-00006-g28924df2a08f #1 PREEMPT(full)
[   43.877196][ T9500] Hardware name: QEMU Standard PC (Q35 + ICH9,
2009), BIOS 1.17.0-debian-1.17.0-1ubuntu1 04/01/2014
[   43.878156][ T9500] RIP: 0010:afs_put_addrlist+0x3c/0x110
[   43.878682][ T9500] Code: aa 39 17 fe 4d 85 f6 74 7d 49 8d 7e 18 48
89 f8 48 c1 e8 03 48 b9 00 00 00 00 00 fc ff df 0f b6 04 08 84 c0 0f
85 af 00 00 00 <41> 8b 6e 18 4d 8d 66 10 4c 89 e7 be 04 00 00 00 e8 9f
35 87 fe 41
[   43.880425][ T9500] RSP: 0018:ffffc90007b67618 EFLAGS: 00010246
[   43.880980][ T9500] RAX: 0000000000000000 RBX: 0000000000000009
RCX: dffffc0000000000
[   43.881803][ T9500] RDX: 0000000000000000 RSI: 0000000000000009
RDI: ffffffffffffffb1
[   43.882537][ T9500] RBP: 0000000000000000 R08: ffff88810ea66a87
R09: 1ffff11021d4cd50
[   43.883253][ T9500] R10: dffffc0000000000 R11: ffffed1021d4cd51
R12: ffff88810d211000
[   43.883970][ T9500] R13: ffff88810ea66800 R14: ffffffffffffff99
R15: ffffffffffffff99
[   43.884688][ T9500] FS:  000000003957f400(0000)
GS:ffff8881da58b000(0000) knlGS:0000000000000000
[   43.885493][ T9500] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[   43.886088][ T9500] CR2: ffffffffffffffb1 CR3: 0000000113534000
CR4: 0000000000752ef0
[   43.886811][ T9500] PKRU: 55555554
[   43.887141][ T9500] Call Trace:
[   43.887456][ T9500]  <TASK>
[   43.887733][ T9500]  afs_lookup_server+0xe0a/0x1120
[   43.888196][ T9500]  ? afs_alloc_server_list+0x7da/0x1140
[   43.888704][ T9500]  afs_alloc_server_list+0x7da/0x1140
[   43.889196][ T9500]  ? __pfx_afs_alloc_server_list+0x10/0x10
[   43.889754][ T9500]  ? __raw_spin_lock_init+0x45/0x100
[   43.890262][ T9500]  ? afs_create_volume+0x96d/0x1130
[   43.890766][ T9500]  afs_create_volume+0x994/0x1130
[   43.891294][ T9500]  ? __pfx_afs_create_volume+0x10/0x10
[   43.891791][ T9500]  ? __asan_memset+0x22/0x50
[   43.892221][ T9500]  afs_cell_detect_alias+0x41d/0x1170
[   43.892719][ T9500]  ? __pfx_afs_cell_detect_alias+0x10/0x10
[   43.893249][ T9500]  ? afs_request_key+0x1c8/0x250
[   43.893708][ T9500]  ? __mutex_unlock_slowpath+0x731/0x900
[   43.894230][ T9500]  ? __pfx___mutex_unlock_slowpath+0x10/0x10
[   43.894781][ T9500]  ? afs_request_key+0x13c/0x250
[   43.895235][ T9500]  afs_get_tree+0x24b/0x12b0
[   43.895665][ T9500]  vfs_get_tree+0x92/0x2a0
[   43.896077][ T9500]  do_new_mount+0x341/0xd30
[   43.896498][ T9500]  ? apparmor_capable+0x126/0x170
[   43.896960][ T9500]  ? __pfx_do_new_mount+0x10/0x10
[   43.897422][ T9500]  ? ns_capable+0x89/0xe0
[   43.897821][ T9500]  ? user_path_at+0xd4/0x160
[   43.898254][ T9500]  __se_sys_mount+0x31d/0x420
[   43.898689][ T9500]  ? __pfx___se_sys_mount+0x10/0x10
[   43.899164][ T9500]  ? __x64_sys_mount+0x20/0xc0
[   43.899606][ T9500]  do_syscall_64+0x155/0x510
[   43.900033][ T9500]  ? trace_irq_disable+0x3b/0x140
[   43.900499][ T9500]  ? entry_SYSCALL_64_after_hwframe+0x77/0x7f
[   43.901051][ T9500]  ? clear_bhb_loop+0x30/0x80
[   43.901554][ T9500]  entry_SYSCALL_64_after_hwframe+0x77/0x7f
[   43.902093][ T9500] RIP: 0033:0x426ffe
[   43.902464][ T9500] Code: 0a 00 01 00 00 00 eb 85 e8 0f 09 00 00 66
2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 f3 0f 1e fa 49 89 ca b8 a5
00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8
64 89 01 48
[   43.904183][ T9500] RSP: 002b:00007fff93751b68 EFLAGS: 00000207
ORIG_RAX: 00000000000000a5
[   43.904940][ T9500] RAX: ffffffffffffffda RBX: 0000000000000001
RCX: 0000000000426ffe
[   43.905655][ T9500] RDX: 00000000004a2103 RSI: 00000000004a20fa
RDI: 00000000004a2107
[   43.906369][ T9500] RBP: 00007fff93751b90 R08: 0000000000000000
R09: 0000000000000000
[   43.907082][ T9500] R10: 0000000000000000 R11: 0000000000000207
R12: 00007fff93751cb8
[   43.907837][ T9500] R13: 00007fff93751cc8 R14: 0000000000000002
R15: 00000000004cba40
[   43.908591][ T9500]  </TASK>
[   43.908893][ T9500] Modules linked in:
[   43.909258][ T9500] CR2: ffffffffffffffb1
[   43.909646][ T9500] ---[ end trace 0000000000000000 ]---
[   43.910172][ T9500] RIP: 0010:afs_put_addrlist+0x3c/0x110
[   43.910184][ T9500] Code: aa 39 17 fe 4d 85 f6 74 7d 49 8d 7e 18 48
89 f8 48 c1 e8 03 48 b9 00 00 00 00 00 fc ff df 0f b6 04 08 84 c0 0f
85 af 00 00 00 <41> 8b 6e 18 4d 8d 66 10 4c 89 e7 be 04 00 00 00 e8 9f
35 87 fe 41
[   43.910190][ T9500] RSP: 0018:ffffc90007b67618 EFLAGS: 00010246
[   43.910196][ T9500] RAX: 0000000000000000 RBX: 0000000000000009
RCX: dffffc0000000000
[   43.910201][ T9500] RDX: 0000000000000000 RSI: 0000000000000009
RDI: ffffffffffffffb1
[   43.910205][ T9500] RBP: 0000000000000000 R08: ffff88810ea66a87
R09: 1ffff11021d4cd50
[   43.910210][ T9500] R10: dffffc0000000000 R11: ffffed1021d4cd51
R12: ffff88810d211000
[   43.910216][ T9500] R13: ffff88810ea66800 R14: ffffffffffffff99
R15: ffffffffffffff99
[   43.910221][ T9500] FS:  000000003957f400(0000)
GS:ffff8881da58b000(0000) knlGS:0000000000000000
[   43.910227][ T9500] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[   43.910232][ T9500] CR2: ffffffffffffffb1 CR3: 0000000113534000
CR4: 0000000000752ef0
[   43.910238][ T9500] PKRU: 55555554
[   43.910244][ T9500] Kernel panic - not syncing: Fatal exception
[   43.919939][ T9500] Kernel Offset: disabled
[   43.920340][ T9500] Rebooting in 86400 seconds.

Reproducer attached; thanks!

On Wed, Sep 2, 2026 at 4:41 AM David Howells <dhowells@redhat.com> wrote:
>
> Hi Farhad,
>
> > While fuzzing Linux 7.1-rc5 with syzkaller, as part of research at ASU's
> > SEFCOM lab, we hit the crash below. Crash reports can be found here:
>
> Have you tried it with 7.3-rc1?
>
> >   BUG: unable to handle page fault for address: ffffffffffffff9f
> >   RIP: 0010:afs_put_addrlist+0x43/0x250 fs/afs/addr_list.c:38
> >   afs_lookup_server+0xd3f/0x1020 fs/afs/server.c:243
> >   afs_alloc_server_list+0x800/0x11a0 fs/afs/server_list.c:82
> >   afs_create_volume+0x995/0x1290 fs/afs/volume.c:227
> >   afs_get_tree+0x955/0x10b0 fs/afs/super.c:555
>
> It looks like alist is 0xffffffffffffff9f, but it's not immediately obvious
> how it could be anything other than a valid pointer at that point.
>
> > Our reproducer.c is available upon request.
>
> If I could have that, please?
>
> Thanks,
> David
>

[-- Attachment #2: reproducer.c --]
[-- Type: application/octet-stream, Size: 8904 bytes --]

/*
 * Reproducer for 104-afs-err_ptr-deref-afs_put_addrlist
 */
#define _GNU_SOURCE
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <unistd.h>
#include <errno.h>
#include <fcntl.h>
#include <pthread.h>
#include <sys/socket.h>
#include <sys/types.h>
#include <sys/stat.h>
#include <sys/mount.h>
#include <sys/ioctl.h>
#include <netinet/in.h>
#include <arpa/inet.h>
#include <net/if.h>

#ifndef AF_RXRPC
#define AF_RXRPC 33
#endif
#ifndef SOL_RXRPC
#define SOL_RXRPC 272
#endif

#define RXRPC_USER_CALL_ID	1
#define RXRPC_ABORT		2
#define RXRPC_ACK		3
#define RXRPC_NET_ERROR		5
#define RXRPC_BUSY		6
#define RXRPC_LOCAL_ERROR	7
#define RXRPC_NEW_CALL		8
#define RXRPC_CHARGE_ACCEPT	14

struct sockaddr_rxrpc {
	sa_family_t	srx_family;
	unsigned short	srx_service;
	unsigned short	transport_type;
	unsigned short	transport_len;
	union {
		sa_family_t		family;
		struct sockaddr_in	sin;
		struct sockaddr_in6	sin6;
	} transport;
};

#define VL_SERVICE		52
#define AFS_VL_PORT		7003

#define VLGETENTRYBYNAMEU	527
#define VLGETADDRSU		533
#define VLGETCAPABILITIES	65537

#define AFSVL_IO		363521		/* -> -EREMOTEIO in afs_select_vlserver() */
#define RXGEN_OPCODE		((unsigned int)-455)

#define AFS_VLSF_RWVOL		0x0004
#define AFS_VLF_RWEXISTS	0x1000

#define CELL	"reprocell"
#define VOLUME	"avol"

static volatile int srv_ready = 0;

/*
 * Every message we send is one sendmsg() carrying RXRPC_USER_CALL_ID, plus
 * optionally a second control message (the abort code, or the charge-accept
 * marker) and optionally a payload.
 */
static int rxrpc_sendmsg(int fd, unsigned long call_id,
			 int cmsg_type, const void *cmsg_val, size_t cmsg_len,
			 const void *payload, size_t payload_len)
{
	char control[256];
	struct cmsghdr *cmsg;
	struct msghdr msg;
	struct iovec iov;
	size_t len;

	memset(&msg, 0, sizeof(msg));
	memset(control, 0, sizeof(control));
	msg.msg_control = control;
	msg.msg_controllen = sizeof(control);

	cmsg = CMSG_FIRSTHDR(&msg);
	cmsg->cmsg_level = SOL_RXRPC;
	cmsg->cmsg_type = RXRPC_USER_CALL_ID;
	cmsg->cmsg_len = CMSG_LEN(sizeof(call_id));
	memcpy(CMSG_DATA(cmsg), &call_id, sizeof(call_id));
	len = CMSG_SPACE(sizeof(call_id));

	if (cmsg_type) {
		cmsg = (struct cmsghdr *)(control + len);
		cmsg->cmsg_level = SOL_RXRPC;
		cmsg->cmsg_type = cmsg_type;
		cmsg->cmsg_len = CMSG_LEN(cmsg_len);
		if (cmsg_len)
			memcpy(CMSG_DATA(cmsg), cmsg_val, cmsg_len);
		len += CMSG_SPACE(cmsg_len);
	}
	msg.msg_controllen = len;

	if (payload) {
		iov.iov_base = (void *)payload;
		iov.iov_len = payload_len;
		msg.msg_iov = &iov;
		msg.msg_iovlen = 1;
	}
	return sendmsg(fd, &msg, 0);
}

#define charge_accept(fd, id)		rxrpc_sendmsg(fd, id, RXRPC_CHARGE_ACCEPT, NULL, 0, NULL, 0)
#define send_reply(fd, id, d, n)	rxrpc_sendmsg(fd, id, 0, NULL, 0, d, n)

static int send_abort(int fd, unsigned long call_id, unsigned int abort_code)
{
	return rxrpc_sendmsg(fd, call_id, RXRPC_ABORT, &abort_code,
			     sizeof(abort_code), NULL, 0);
}

/*
 * struct afs_uvldbentry__xdr, 262 be32 words (fs/afs/afs_vl.h):
 *   name[65] nServers serverNumber[13*11] serverUnique[13]
 *   serverPartition[13] serverFlags[13] volumeId[3] cloneId flags spares[9]
 */
#define VLDB_ENTRY_WORDS 262
static unsigned int vldb_entry[VLDB_ENTRY_WORDS];

static void build_uvldbentry(void)
{
	const char *n = VOLUME;
	int i;

	memset(vldb_entry, 0, sizeof(vldb_entry));
	for (i = 0; n[i] && i < 64; i++)
		vldb_entry[i] = htonl((unsigned char)n[i]);

	vldb_entry[65] = htonl(1);			/* nServers */

	/* serverNumber[0]: afs_uuid__xdr, 11 words, arbitrary but nonzero */
	vldb_entry[66 + 0] = htonl(0x11223344);	/* time_low */
	vldb_entry[66 + 1] = htonl(0x5566);		/* time_mid */
	vldb_entry[66 + 2] = htonl(0x7788);		/* time_hi_and_version */
	vldb_entry[66 + 3] = htonl(0x99);		/* clock_seq_hi_and_reserved */
	vldb_entry[66 + 4] = htonl(0xaa);		/* clock_seq_low */
	for (i = 0; i < 6; i++)
		vldb_entry[66 + 5 + i] = htonl(0xb0 + i);	/* node[6] */

	vldb_entry[209] = htonl(1);			/* serverUnique[0] */
	vldb_entry[222] = htonl(0);			/* serverPartition[0] */
	vldb_entry[235] = htonl(AFS_VLSF_RWVOL);	/* serverFlags[0] */
	vldb_entry[248] = htonl(0x02000001);		/* volumeId[RW] */
	vldb_entry[251] = htonl(0);			/* cloneId */
	vldb_entry[252] = htonl(AFS_VLF_RWEXISTS);	/* flags */
}

struct callrec {
	unsigned long	id;
	unsigned int	opcode;
	int		have_op;
};
#define NCALLS 64
static struct callrec calls[NCALLS];

static struct callrec *lookup_call(unsigned long id)
{
	int i, free = -1;
	for (i = 0; i < NCALLS; i++) {
		if (calls[i].id == id && calls[i].have_op >= 0 && calls[i].id)
			return &calls[i];
		if (!calls[i].id && free < 0)
			free = i;
	}
	if (free < 0)
		free = 0;
	calls[free].id = id;
	calls[free].opcode = 0;
	calls[free].have_op = 0;
	return &calls[free];
}

static void drop_call(unsigned long id)
{
	int i;
	for (i = 0; i < NCALLS; i++)
		if (calls[i].id == id)
			memset(&calls[i], 0, sizeof(calls[i]));
}

static void *vlserver(void *unused)
{
	struct sockaddr_rxrpc srx;
	unsigned long next_id = 1000;
	int i, fd;

	fd = socket(AF_RXRPC, SOCK_DGRAM, PF_INET);
	if (fd < 0) {
		fprintf(stderr, "socket(AF_RXRPC): %m\n");
		srv_ready = -1;
		return NULL;
	}

	memset(&srx, 0, sizeof(srx));
	srx.srx_family = AF_RXRPC;
	srx.srx_service = VL_SERVICE;
	srx.transport_type = SOCK_DGRAM;
	srx.transport_len = sizeof(struct sockaddr_in);
	srx.transport.sin.sin_family = AF_INET;
	srx.transport.sin.sin_port = htons(AFS_VL_PORT);
	srx.transport.sin.sin_addr.s_addr = htonl(INADDR_ANY);

	if (bind(fd, (struct sockaddr *)&srx, sizeof(srx)) < 0) {
		fprintf(stderr, "bind: %m\n");
		srv_ready = -1;
		return NULL;
	}
	if (listen(fd, 10) < 0) {
		fprintf(stderr, "listen: %m\n");
		srv_ready = -1;
		return NULL;
	}
	for (i = 0; i < 8; i++)
		charge_accept(fd, next_id++);

	srv_ready = 1;

	for (;;) {
		char buf[4096], ctl[512];
		struct msghdr msg;
		struct iovec iov;
		struct cmsghdr *cm;
		unsigned long id = 0;
		int got_id = 0, terminal = 0;
		ssize_t n;
		struct callrec *c;

		memset(&msg, 0, sizeof(msg));
		iov.iov_base = buf;
		iov.iov_len = sizeof(buf);
		msg.msg_iov = &iov;
		msg.msg_iovlen = 1;
		msg.msg_control = ctl;
		msg.msg_controllen = sizeof(ctl);

		n = recvmsg(fd, &msg, 0);
		if (n < 0) {
			if (errno == EINTR || errno == EAGAIN)
				continue;
			fprintf(stderr, "recvmsg: %m\n");
			break;
		}

		for (cm = CMSG_FIRSTHDR(&msg); cm; cm = CMSG_NXTHDR(&msg, cm)) {
			if (cm->cmsg_level != SOL_RXRPC)
				continue;
			switch (cm->cmsg_type) {
			case RXRPC_USER_CALL_ID:
				memcpy(&id, CMSG_DATA(cm), sizeof(id));
				got_id = 1;
				break;
			case RXRPC_ABORT:
			case RXRPC_ACK:
			case RXRPC_NET_ERROR:
			case RXRPC_BUSY:
			case RXRPC_LOCAL_ERROR: {
				unsigned int v = 0;
				if (cm->cmsg_len >= CMSG_LEN(4))
					memcpy(&v, CMSG_DATA(cm), 4);
				terminal = 1;
			}
				break;
			default:
				break;
			}
		}

		if (!got_id)
			continue;

		if (terminal) {
			drop_call(id);
			charge_accept(fd, next_id++);
			continue;
		}

		c = lookup_call(id);
		if (!c->have_op && n >= 4) {
			unsigned int op;
			memcpy(&op, buf, 4);
			c->opcode = ntohl(op);
			c->have_op = 1;
		}

		if (msg.msg_flags & MSG_MORE)
			continue;

		switch (c->opcode) {
		case VLGETCAPABILITIES: {
			unsigned int reply[2];
			reply[0] = htonl(1);	/* nr capability words */
			reply[1] = htonl(0);
			send_reply(fd, id, reply, sizeof(reply));
			break;
		}
		case VLGETENTRYBYNAMEU:
			send_reply(fd, id, vldb_entry, sizeof(vldb_entry));
			break;
		case VLGETADDRSU:
			/* the whole point: make afs_vl_lookup_addrs() fail */
			send_abort(fd, id, AFSVL_IO);
			break;
		default:
			send_abort(fd, id, RXGEN_OPCODE);
			break;
		}
		drop_call(id);
		charge_accept(fd, next_id++);
	}
	return NULL;
}

int main(void)
{
	pthread_t vlserver_thread;
	int fd, i;
	const char *root = CELL ":127.0.0.1\n";

	build_uvldbentry();

	if (pthread_create(&vlserver_thread, NULL, vlserver, NULL)) {
		fprintf(stderr, "pthread_create: %m\n");
		return 1;
	}
	for (i = 0; i < 500 && !srv_ready; i++)
		usleep(10000);
	if (srv_ready != 1) {
		fprintf(stderr, "vlserver failed to start\n");
		return 1;
	}
	/* Make our fake cell the workstation cell, with a literal VL address
	 * so that no DNS lookup is attempted. */
	fd = open("/proc/fs/afs/rootcell", O_WRONLY);
	if (fd < 0) {
		fprintf(stderr, "open rootcell: %m (is kAFS present?)\n");
		return 1;
	}
	if (write(fd, root, strlen(root)) < 0)
		fprintf(stderr, "write rootcell: %m\n");
	close(fd);

	mkdir("/mnt_afs", 0755);

	/* The source has no cell part, so the workstation cell set above is
	 * used and afs_lookup_cell()/DNS is never entered.  Our VL server
	 * aborts VL.GetAddrsU, so afs_vl_lookup_addrs() returns
	 * ERR_PTR(-EREMOTEIO) and afs_lookup_server()'s create_failed -> out
	 * path hands that ERR_PTR to afs_put_addrlist(), which rejects only
	 * NULL. */
	mount("%" VOLUME, "/mnt_afs", "afs", 0, NULL);

	return 0;
}

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-09 18:12 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-27 22:37 [BUG] afs: ERR_PTR dereference in afs_lookup_server() error path Farhad Alemi
2026-09-02 11:40 ` David Howells
2026-09-09 18:12   ` Farhad Alemi

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.