All of lore.kernel.org
 help / color / mirror / Atom feed
From: syzbot <syzbot+e6e8f6618a2d4b35e4e0@syzkaller.appspotmail.com>
To: andrii@kernel.org, ast@kernel.org, bpf@vger.kernel.org,
	 daniel@iogearbox.net, eddyz87@gmail.com, haoluo@google.com,
	 john.fastabend@gmail.com, jolsa@kernel.org, kpsingh@kernel.org,
	 linux-kernel@vger.kernel.org, martin.lau@linux.dev,
	sdf@fomichev.me,  song@kernel.org,
	syzkaller-bugs@googlegroups.com, yonghong.song@linux.dev
Subject: [syzbot] [bpf?] general protection fault in bpf_get_local_storage
Date: Sun, 13 Apr 2025 20:52:30 -0700	[thread overview]
Message-ID: <67fc867e.050a0220.2970f9.03b8.GAE@google.com> (raw)

Hello,

syzbot found the following issue on:

HEAD commit:    4d872d51bc9d Merge tag 'x86-urgent-2025-03-10' of git://gi..
git tree:       upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=128e67a8580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=f71f17a9b92472b2
dashboard link: https://syzkaller.appspot.com/bug?extid=e6e8f6618a2d4b35e4e0
compiler:       gcc (Debian 12.2.0-14) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40
syz repro:      https://syzkaller.appspot.com/x/repro.syz?x=1385b074580000
C reproducer:   https://syzkaller.appspot.com/x/repro.c?x=1785b074580000

Downloadable assets:
disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/7feb34a89c2a/non_bootable_disk-4d872d51.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/0ca94bd3aed2/vmlinux-4d872d51.xz
kernel image: https://storage.googleapis.com/syzbot-assets/da3cc5389139/bzImage-4d872d51.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+e6e8f6618a2d4b35e4e0@syzkaller.appspotmail.com

Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] PREEMPT SMP KASAN NOPTI
KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
CPU: 1 UID: 0 PID: 5934 Comm: sshd Not tainted 6.14.0-rc6-syzkaller-00003-g4d872d51bc9d #0
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014
RIP: 0010:____bpf_get_local_storage kernel/bpf/cgroup.c:1587 [inline]
RIP: 0010:bpf_get_local_storage+0x17b/0x260 kernel/bpf/cgroup.c:1569
Code: 48 8d 7b 10 48 89 fa 48 c1 ea 03 80 3c 02 00 0f 85 bb 00 00 00 48 b8 00 00 00 00 00 fc ff df 48 8b 5b 10 48 89 da 48 c1 ea 03 <80> 3c 02 00 0f 85 a6 00 00 00 48 8b 1b e8 13 90 73 09 83 f8 07 89
RSP: 0018:ffffc900006c0120 EFLAGS: 00010246
RAX: dffffc0000000000 RBX: 0000000000000000 RCX: ffffffff81e40b82
RDX: 0000000000000000 RSI: ffffffff81e40c38 RDI: ffff8880356f2ca0
RBP: ffffc900006c0140 R08: 0000000000000005 R09: 0000000000000015
R10: 0000000000000015 R11: 0000000000000005 R12: ffff88802ae052c0
R13: ffffc90000d36002 R14: 0000000000000000 R15: ffff88802ae052f0
FS:  00007fb06dfb0d00(0000) GS:ffff88806a700000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000400000001c40 CR3: 0000000025fd8000 CR4: 0000000000352ef0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
 <IRQ>
 bpf_prog_3647604f6c8667e9+0x2e/0x41
 bpf_dispatcher_nop_func include/linux/bpf.h:1290 [inline]
 __bpf_prog_run include/linux/filter.h:701 [inline]
 bpf_prog_run include/linux/filter.h:708 [inline]
 __bpf_prog_run_save_cb+0x11f/0x330 include/linux/filter.h:938
 bpf_prog_run_array_cg kernel/bpf/cgroup.c:68 [inline]
 __cgroup_bpf_run_filter_skb+0x470/0xe60 kernel/bpf/cgroup.c:1425
 sk_filter_trim_cap+0x234/0xac0 net/core/filter.c:147
 tcp_filter net/ipv4/tcp_ipv4.c:2144 [inline]
 tcp_v4_rcv+0x28fd/0x4380 net/ipv4/tcp_ipv4.c:2332
 ip_protocol_deliver_rcu+0xba/0x4c0 net/ipv4/ip_input.c:205
 ip_local_deliver_finish+0x316/0x570 net/ipv4/ip_input.c:233
 NF_HOOK include/linux/netfilter.h:314 [inline]
 NF_HOOK include/linux/netfilter.h:308 [inline]
 ip_local_deliver+0x18e/0x1f0 net/ipv4/ip_input.c:254
 dst_input include/net/dst.h:469 [inline]
 ip_sublist_rcv_finish+0x2c1/0x620 net/ipv4/ip_input.c:578
 ip_list_rcv_finish+0x559/0x720 net/ipv4/ip_input.c:627
 ip_sublist_rcv net/ipv4/ip_input.c:635 [inline]
 ip_list_rcv+0x339/0x450 net/ipv4/ip_input.c:669
 __netif_receive_skb_list_ptype net/core/dev.c:5936 [inline]
 __netif_receive_skb_list_core+0x755/0x950 net/core/dev.c:5983
 __netif_receive_skb_list net/core/dev.c:6035 [inline]
 netif_receive_skb_list_internal+0x753/0xdb0 net/core/dev.c:6126
 gro_normal_list include/net/gro.h:518 [inline]
 gro_normal_list include/net/gro.h:514 [inline]
 napi_complete_done+0x218/0x940 net/core/dev.c:6493
 e1000_clean+0xa28/0x2700 drivers/net/ethernet/intel/e1000/e1000_main.c:3815
 __napi_poll.constprop.0+0xb7/0x550 net/core/dev.c:7188
 napi_poll net/core/dev.c:7257 [inline]
 net_rx_action+0xa94/0x1010 net/core/dev.c:7379
 handle_softirqs+0x213/0x8f0 kernel/softirq.c:561
 do_softirq kernel/softirq.c:462 [inline]
 do_softirq+0xb2/0xf0 kernel/softirq.c:449
 </IRQ>
 <TASK>
 __local_bh_enable_ip+0x100/0x120 kernel/softirq.c:389
 local_bh_enable include/linux/bottom_half.h:33 [inline]
 rcu_read_unlock_bh include/linux/rcupdate.h:919 [inline]
 __dev_queue_xmit+0x8b0/0x43e0 net/core/dev.c:4676
 dev_queue_xmit include/linux/netdevice.h:3313 [inline]
 neigh_hh_output include/net/neighbour.h:523 [inline]
 neigh_output include/net/neighbour.h:537 [inline]
 ip_finish_output2+0xc34/0x2180 net/ipv4/ip_output.c:236
 __ip_finish_output net/ipv4/ip_output.c:314 [inline]
 __ip_finish_output+0x49e/0x950 net/ipv4/ip_output.c:296
 ip_finish_output+0x35/0x380 net/ipv4/ip_output.c:324
 NF_HOOK_COND include/linux/netfilter.h:303 [inline]
 ip_output+0x13b/0x2a0 net/ipv4/ip_output.c:434
 dst_output include/net/dst.h:459 [inline]
 ip_local_out net/ipv4/ip_output.c:130 [inline]
 __ip_queue_xmit+0x1a8d/0x22d0 net/ipv4/ip_output.c:528
 __tcp_transmit_skb+0x2b39/0x3ec0 net/ipv4/tcp_output.c:1471
 tcp_transmit_skb net/ipv4/tcp_output.c:1489 [inline]
 tcp_write_xmit+0x12b1/0x8560 net/ipv4/tcp_output.c:2832
 __tcp_push_pending_frames+0xaf/0x390 net/ipv4/tcp_output.c:3015
 tcp_push+0x221/0x6f0 net/ipv4/tcp.c:751
 tcp_sendmsg_locked+0x290f/0x37c0 net/ipv4/tcp.c:1326
 tcp_sendmsg+0x2e/0x50 net/ipv4/tcp.c:1358
 inet_sendmsg+0xb9/0x140 net/ipv4/af_inet.c:851
 sock_sendmsg_nosec net/socket.c:718 [inline]
 __sock_sendmsg net/socket.c:733 [inline]
 sock_write_iter+0x4ac/0x5b0 net/socket.c:1137
 new_sync_write fs/read_write.c:586 [inline]
 vfs_write+0x5ae/0x1150 fs/read_write.c:679
 ksys_write+0x207/0x250 fs/read_write.c:731
 do_syscall_x64 arch/x86/entry/common.c:52 [inline]
 do_syscall_64+0xcd/0x250 arch/x86/entry/common.c:83
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fb06db16bf2
Code: 89 c7 48 89 44 24 08 e8 7b 34 fa ff 48 8b 44 24 08 48 83 c4 28 c3 c3 64 8b 04 25 18 00 00 00 85 c0 75 20 b8 01 00 00 00 0f 05 <48> 3d 00 f0 ff ff 76 6f 48 8b 15 07 a2 0d 00 f7 d8 64 89 02 48 83
RSP: 002b:00007fff72e409a8 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 0000000000000034 RCX: 00007fb06db16bf2
RDX: 0000000000000034 RSI: 000055e211330970 RDI: 0000000000000004
RBP: 000055e211339400 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 000055e1e6312aa4
R13: 000000000000002b R14: 000055e1e63133e8 R15: 00007fff72e40a18
 </TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:____bpf_get_local_storage kernel/bpf/cgroup.c:1587 [inline]
RIP: 0010:bpf_get_local_storage+0x17b/0x260 kernel/bpf/cgroup.c:1569
Code: 48 8d 7b 10 48 89 fa 48 c1 ea 03 80 3c 02 00 0f 85 bb 00 00 00 48 b8 00 00 00 00 00 fc ff df 48 8b 5b 10 48 89 da 48 c1 ea 03 <80> 3c 02 00 0f 85 a6 00 00 00 48 8b 1b e8 13 90 73 09 83 f8 07 89
RSP: 0018:ffffc900006c0120 EFLAGS: 00010246
RAX: dffffc0000000000 RBX: 0000000000000000 RCX: ffffffff81e40b82
RDX: 0000000000000000 RSI: ffffffff81e40c38 RDI: ffff8880356f2ca0
RBP: ffffc900006c0140 R08: 0000000000000005 R09: 0000000000000015
R10: 0000000000000015 R11: 0000000000000005 R12: ffff88802ae052c0
R13: ffffc90000d36002 R14: 0000000000000000 R15: ffff88802ae052f0
FS:  00007fb06dfb0d00(0000) GS:ffff88806a700000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000400000001c40 CR3: 0000000025fd8000 CR4: 0000000000352ef0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
----------------
Code disassembly (best guess):
   0:	48 8d 7b 10          	lea    0x10(%rbx),%rdi
   4:	48 89 fa             	mov    %rdi,%rdx
   7:	48 c1 ea 03          	shr    $0x3,%rdx
   b:	80 3c 02 00          	cmpb   $0x0,(%rdx,%rax,1)
   f:	0f 85 bb 00 00 00    	jne    0xd0
  15:	48 b8 00 00 00 00 00 	movabs $0xdffffc0000000000,%rax
  1c:	fc ff df
  1f:	48 8b 5b 10          	mov    0x10(%rbx),%rbx
  23:	48 89 da             	mov    %rbx,%rdx
  26:	48 c1 ea 03          	shr    $0x3,%rdx
* 2a:	80 3c 02 00          	cmpb   $0x0,(%rdx,%rax,1) <-- trapping instruction
  2e:	0f 85 a6 00 00 00    	jne    0xda
  34:	48 8b 1b             	mov    (%rbx),%rbx
  37:	e8 13 90 73 09       	call   0x973904f
  3c:	83 f8 07             	cmp    $0x7,%eax
  3f:	89                   	.byte 0x89


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

                 reply	other threads:[~2025-04-14  3:52 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=67fc867e.050a0220.2970f9.03b8.GAE@google.com \
    --to=syzbot+e6e8f6618a2d4b35e4e0@syzkaller.appspotmail.com \
    --cc=andrii@kernel.org \
    --cc=ast@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=daniel@iogearbox.net \
    --cc=eddyz87@gmail.com \
    --cc=haoluo@google.com \
    --cc=john.fastabend@gmail.com \
    --cc=jolsa@kernel.org \
    --cc=kpsingh@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=martin.lau@linux.dev \
    --cc=sdf@fomichev.me \
    --cc=song@kernel.org \
    --cc=syzkaller-bugs@googlegroups.com \
    --cc=yonghong.song@linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.