From: poma <pomidorabelisima@gmail.com>
To: Jan Kara <jack@suse.cz>,
Richard Weinberger <richard.weinberger@gmail.com>
Cc: Mailing-List fedora-kernel <kernel@lists.fedoraproject.org>,
Linux Kernel list <linux-kernel@vger.kernel.org>,
Josh Boyer <jwboyer@redhat.com>,
"Justin M. Forbes" <jforbes@redhat.com>,
Stanislaw Gruszka <sgruszka@redhat.com>,
Jiri Kosina <jkosina@suse.cz>, Dave Jones <davej@redhat.com>,
Christoph Hellwig <hch@lst.de>,
eparis@parisplace.org, Al Viro <viro@zeniv.linux.org.uk>,
Hugh Dickins <hughd@google.com>,
Andrew Morton <akpm@linux-foundation.org>,
Linus Torvalds <torvalds@linux-foundation.org>
Subject: Re: BUG: unable to handle kernel paging request at 0000000100000003 - Oops: 0000 [#1] SMP
Date: Mon, 03 Mar 2014 20:13:00 +0100 [thread overview]
Message-ID: <5314D43C.8030203@gmail.com> (raw)
In-Reply-To: <20140221154823.GA21405@quack.suse.cz>
On 21.02.2014 16:48, Jan Kara wrote:
> On Fri 21-02-14 14:08:03, Richard Weinberger wrote:
>> On Fri, Feb 21, 2014 at 12:40 PM, poma <pomidorabelisima@gmail.com> wrote:
>>>
>>> Affected kernels - 3.14.0-0.rc3*:
>>>
>>> - 3.14.0-0.rc3.git0.1
>>> http://koji.fedoraproject.org/koji/buildinfo?buildID=498711
>>>
>>> - 3.14.0-0.rc3.git0.7 based on 3.14.0-0.rc3.git0.1
>>>
>>> - 3.14.0-0.rc3.git2.1
>>> http://koji.fedoraproject.org/koji/buildinfo?buildID=499061
>>>
>>> - 3.14.0-0.rc3.git5.1
>>> http://koji.fedoraproject.org/koji/buildinfo?buildID=499636
>>>
>>> Memtest86+ 4.20 - OK
>>> http://goo.gl/1nm1nV
>>>
>>> RHBZ
>>> https://bugzilla.redhat.com/show_bug.cgi?id=1067919
>>>
>>> messages-Oops-es-3.14.0-0.rc3
>>> https://bugzilla.redhat.com/attachment.cgi?id=865926
>>
>> Maybe commits 7053aee26a3548ebaba046ae2e52396ccf56ac6c (fsnotify: do
>> not share events between notification groups)
>> and 85816794240b9659e66e4d9b0df7c6e814e5f603 (fanotify: Fix use after
>> free for permission events) introduced this regression.
> So the immediate problem seems to be that event->tgid is 0xffffffff
> instead of a pointer. I don't see how this could be use after free and we
> unconditionally initialize event->tgid to something sensible. Hum, but if
> it is an overflow event, we are in a trouble since that doesn't have ->tgid
> field at all so we read random crap that happens to be beyond the event
> structure. Actually there seem to be more problems in the handling of
> overflow event so I better add that to my testing (both for fanotify and
> inotify). I'll work on the fix. Thanks for report!
>
> Honza
>
The test was successfully completed with the '3.14-rc5'.
Thanks guys, Jan for the patchwork!
poma
next prev parent reply other threads:[~2014-03-03 19:13 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-02-21 11:40 BUG: unable to handle kernel paging request at 0000000100000003 - Oops: 0000 [#1] SMP poma
2014-02-21 13:08 ` Richard Weinberger
2014-02-21 15:48 ` Jan Kara
2014-03-03 19:13 ` poma [this message]
2014-03-03 20:17 ` Jan Kara
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=5314D43C.8030203@gmail.com \
--to=pomidorabelisima@gmail.com \
--cc=akpm@linux-foundation.org \
--cc=davej@redhat.com \
--cc=eparis@parisplace.org \
--cc=hch@lst.de \
--cc=hughd@google.com \
--cc=jack@suse.cz \
--cc=jforbes@redhat.com \
--cc=jkosina@suse.cz \
--cc=jwboyer@redhat.com \
--cc=kernel@lists.fedoraproject.org \
--cc=linux-kernel@vger.kernel.org \
--cc=richard.weinberger@gmail.com \
--cc=sgruszka@redhat.com \
--cc=torvalds@linux-foundation.org \
--cc=viro@zeniv.linux.org.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.