From: syzbot <syzbot+df1db6e034b3953e19f5@syzkaller.appspotmail.com>
To: autofs@vger.kernel.org, jeffinphilip14@gmail.com,
linux-kernel@vger.kernel.org, raven@themaw.net,
syzkaller-bugs@googlegroups.com
Subject: Re: [syzbot] [autofs?] memory leak in autofs_new_ino
Date: Thu, 03 Sep 2026 01:16:02 -0700 [thread overview]
Message-ID: <6a992cc2.0b659fcc.16ebfd.0002.GAE@google.com> (raw)
In-Reply-To: <20260903055751.10197-1-jeffinphilip14@gmail.com>
Hello,
syzbot has tested the proposed patch but the reproducer is still triggering an issue:
memory leak in create_pipe_files
BUG: memory leak
unreferenced object 0xffff88810ceec180 (size 176):
comm "syz.0.17", pid 6581, jiffies 4294948258
hex dump (first 32 bytes):
00 00 00 00 02 00 2c 0c 60 a4 87 85 ff ff ff ff ......,.`.......
d8 a5 46 0d 81 88 ff ff c0 36 91 00 81 88 ff ff ..F......6......
backtrace (crc ec35cd54):
kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline]
slab_post_alloc_hook mm/slub.c:4597 [inline]
slab_alloc_node mm/slub.c:4917 [inline]
kmem_cache_alloc_noprof+0x34f/0x440 mm/slub.c:4931
alloc_empty_file+0x57/0x180 fs/file_table.c:262
alloc_file fs/file_table.c:396 [inline]
alloc_file_pseudo+0xd3/0x180 fs/file_table.c:427
create_pipe_files+0x106/0x2f0 fs/pipe.c:1042
__do_pipe_flags fs/pipe.c:1088 [inline]
do_pipe2+0x6c/0x160 fs/pipe.c:1136
__do_sys_pipe fs/pipe.c:1159 [inline]
__se_sys_pipe fs/pipe.c:1157 [inline]
__x64_sys_pipe+0x18/0x20 fs/pipe.c:1157
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xf8/0x610 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
BUG: memory leak
unreferenced object 0xffff88810d8431c0 (size 56):
comm "syz.0.17", pid 6581, jiffies 4294948258
hex dump (first 32 bytes):
ff ff 01 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
backtrace (crc 2672a0c6):
kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline]
slab_post_alloc_hook mm/slub.c:4597 [inline]
slab_alloc_node mm/slub.c:4917 [inline]
kmem_cache_alloc_noprof+0x34f/0x440 mm/slub.c:4931
lsm_file_alloc security/security.c:171 [inline]
security_file_alloc+0x30/0x250 security/security.c:2406
init_file+0x3e/0x160 fs/file_table.c:184
alloc_empty_file+0x75/0x180 fs/file_table.c:266
alloc_file fs/file_table.c:396 [inline]
alloc_file_pseudo+0xd3/0x180 fs/file_table.c:427
create_pipe_files+0x106/0x2f0 fs/pipe.c:1042
__do_pipe_flags fs/pipe.c:1088 [inline]
do_pipe2+0x6c/0x160 fs/pipe.c:1136
__do_sys_pipe fs/pipe.c:1159 [inline]
__se_sys_pipe fs/pipe.c:1157 [inline]
__x64_sys_pipe+0x18/0x20 fs/pipe.c:1157
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xf8/0x610 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
BUG: memory leak
unreferenced object 0xffff888102f619c0 (size 184):
comm "syz-executor", pid 6483, jiffies 4294948379
hex dump (first 32 bytes):
01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
backtrace (crc 4a068722):
kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline]
slab_post_alloc_hook mm/slub.c:4597 [inline]
slab_alloc_node mm/slub.c:4917 [inline]
kmem_cache_alloc_noprof+0x34f/0x440 mm/slub.c:4931
prepare_creds+0x22/0x570 kernel/cred.c:185
copy_creds+0x44/0x290 kernel/cred.c:286
copy_process+0x988/0x2d70 kernel/fork.c:2153
kernel_clone+0x101/0x710 kernel/fork.c:2748
__do_sys_clone+0x7f/0xb0 kernel/fork.c:2889
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xf8/0x610 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
BUG: memory leak
unreferenced object 0xffff888102e91600 (size 32):
comm "syz-executor", pid 6483, jiffies 4294948379
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
f8 52 0a 00 81 88 ff ff 00 00 00 00 00 00 00 00 .R..............
backtrace (crc 9ae86290):
kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline]
slab_post_alloc_hook mm/slub.c:4597 [inline]
slab_alloc_node mm/slub.c:4917 [inline]
__do_kmalloc_node mm/slub.c:5333 [inline]
__kmalloc_noprof+0x3bf/0x550 mm/slub.c:5359
_kmalloc_noprof include/linux/slab.h:992 [inline]
_kzalloc_noprof include/linux/slab.h:1309 [inline]
lsm_blob_alloc+0x4d/0x80 security/security.c:218
lsm_cred_alloc security/security.c:235 [inline]
security_prepare_creds+0x2d/0x290 security/security.c:2866
prepare_creds+0x317/0x570 kernel/cred.c:215
copy_creds+0x44/0x290 kernel/cred.c:286
copy_process+0x988/0x2d70 kernel/fork.c:2153
kernel_clone+0x101/0x710 kernel/fork.c:2748
__do_sys_clone+0x7f/0xb0 kernel/fork.c:2889
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xf8/0x610 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
BUG: memory leak
unreferenced object 0xffff88810d015000 (size 176):
comm "syz.0.19", pid 6612, jiffies 4294948379
hex dump (first 32 bytes):
00 00 00 00 02 00 2c 0c 60 a4 87 85 ff ff ff ff ......,.`.......
80 8c 9c 11 81 88 ff ff c0 3c 91 00 81 88 ff ff .........<......
backtrace (crc 95068e96):
kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline]
slab_post_alloc_hook mm/slub.c:4597 [inline]
slab_alloc_node mm/slub.c:4917 [inline]
kmem_cache_alloc_noprof+0x34f/0x440 mm/slub.c:4931
alloc_empty_file+0x57/0x180 fs/file_table.c:262
alloc_file fs/file_table.c:396 [inline]
alloc_file_pseudo+0xd3/0x180 fs/file_table.c:427
create_pipe_files+0x106/0x2f0 fs/pipe.c:1042
__do_pipe_flags fs/pipe.c:1088 [inline]
do_pipe2+0x6c/0x160 fs/pipe.c:1136
__do_sys_pipe fs/pipe.c:1159 [inline]
__se_sys_pipe fs/pipe.c:1157 [inline]
__x64_sys_pipe+0x18/0x20 fs/pipe.c:1157
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xf8/0x610 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
BUG: memory leak
unreferenced object 0xffff888127a600e0 (size 56):
comm "syz.0.19", pid 6612, jiffies 4294948379
hex dump (first 32 bytes):
ff ff 01 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
backtrace (crc 2672a0c6):
kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline]
slab_post_alloc_hook mm/slub.c:4597 [inline]
slab_alloc_node mm/slub.c:4917 [inline]
kmem_cache_alloc_noprof+0x34f/0x440 mm/slub.c:4931
lsm_file_alloc security/security.c:171 [inline]
security_file_alloc+0x30/0x250 security/security.c:2406
init_file+0x3e/0x160 fs/file_table.c:184
alloc_empty_file+0x75/0x180 fs/file_table.c:266
alloc_file fs/file_table.c:396 [inline]
alloc_file_pseudo+0xd3/0x180 fs/file_table.c:427
create_pipe_files+0x106/0x2f0 fs/pipe.c:1042
__do_pipe_flags fs/pipe.c:1088 [inline]
do_pipe2+0x6c/0x160 fs/pipe.c:1136
__do_sys_pipe fs/pipe.c:1159 [inline]
__se_sys_pipe fs/pipe.c:1157 [inline]
__x64_sys_pipe+0x18/0x20 fs/pipe.c:1157
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xf8/0x610 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
connection error: failed to recv *flatrpc.ExecutorMessageRawT: EOF
Tested on:
commit: 8d3ae592 Linux 7.2
git tree: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
console output: https://syzkaller.appspot.com/x/log.txt?x=173850f9580000
kernel config: https://syzkaller.appspot.com/x/.config?x=11ad91fcc8fa7933
dashboard link: https://syzkaller.appspot.com/bug?extid=df1db6e034b3953e19f5
compiler: gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
patch: https://syzkaller.appspot.com/x/patch.diff?x=17eb8b49580000
prev parent reply other threads:[~2026-09-03 8:16 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-02 16:33 [syzbot] [autofs?] memory leak in autofs_new_ino syzbot
2026-09-03 5:57 ` Jeffin Philip
2026-09-03 8:16 ` syzbot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=6a992cc2.0b659fcc.16ebfd.0002.GAE@google.com \
--to=syzbot+df1db6e034b3953e19f5@syzkaller.appspotmail.com \
--cc=autofs@vger.kernel.org \
--cc=jeffinphilip14@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=raven@themaw.net \
--cc=syzkaller-bugs@googlegroups.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.