linux-btrfs.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Chris Bainbridge <chris.bainbridge@gmail.com>
To: dsterba@suse.cz, linux-kernel@vger.kernel.org, clm@fb.com,
	jbacik@fb.com, linux-btrfs@vger.kernel.org,
	aryabinin@virtuozzo.com
Subject: Re: UBSAN: Undefined behaviour in fs/btrfs/inode.c:5845:10
Date: Tue, 26 Jan 2016 11:29:05 +0000	[thread overview]
Message-ID: <20160126112905.GA4818@localhost> (raw)
In-Reply-To: <20160126110339.GE8567@suse.cz>

On Tue, Jan 26, 2016 at 12:03:39PM +0100, David Sterba wrote:
> On Tue, Jan 26, 2016 at 10:13:33AM +0000, Chris Bainbridge wrote:
> > Booting 4.5.0-rc1 with new UBSAN checker enabled:
> > 
> > [    3.859690] ================================================================================
> > [    3.859694] UBSAN: Undefined behaviour in fs/btrfs/inode.c:5845:10
> > [    3.859696] signed integer overflow:
> > [    3.859697] 9223372036854775807 + 1 cannot be represented in type 'long long int'
> > [    3.859701] CPU: 3 PID: 3237 Comm: polkitd Not tainted 4.5.0-rc1 #252
> > [    3.859702] Hardware name: Apple Inc. MacBookPro10,2/Mac-AFD8A9D944EA4843, BIOS MBP102.88Z.0106.B0A.1509130955 09/13/2015
> > [    3.859706]  0000000000000000 0000000000000000 0000000000000001 ffff88024d4bfcf8
> > [    3.859709]  ffffffff81b2e7d9 0000000000000001 ffff88024d4bfd28 ffff88024d4bfd10
> > [    3.859711]  ffffffff81bcb87d ffffffff83aceb48 ffff88024d4bfd98 ffffffff81bcbc4d
> > [    3.859712] Call Trace:
> > [    3.859719]  [<ffffffff81b2e7d9>] dump_stack+0x45/0x6c
> > [    3.859723]  [<ffffffff81bcb87d>] ubsan_epilogue+0xd/0x40
> > [    3.859725]  [<ffffffff81bcbc4d>] handle_overflow+0xbd/0xe0
> > [    3.859728]  [<ffffffff81bcbc7e>] __ubsan_handle_add_overflow+0xe/0x10
> > [    3.859732]  [<ffffffff818c6271>] btrfs_real_readdir+0x881/0xc10
> > [    3.859737]  [<ffffffff8148b05d>] iterate_dir+0xdd/0x2d0
> > [    3.859740]  [<ffffffff8148bb0b>] SyS_getdents+0x9b/0x110
> > [    3.859743]  [<ffffffff8148b250>] ? iterate_dir+0x2d0/0x2d0
> > [    3.859747]  [<ffffffff82b40a57>] entry_SYSCALL_64_fastpath+0x12/0x6a
> > [    3.859749] ================================================================================
> 
> That seems to be the same overflow as reported in the past, caught by
> the PaX SIZE_OVERFLOW plugin. There's a patch but not merged yet.
> 
> https://patchwork.kernel.org/patch/7611351/

Yes, the error does not appear with that patch applied.

      reply	other threads:[~2016-01-26 11:29 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2016-01-26 10:13 UBSAN: Undefined behaviour in fs/btrfs/inode.c:5845:10 Chris Bainbridge
2016-01-26 11:03 ` Holger Hoffstätte
2016-01-26 11:03 ` David Sterba
2016-01-26 11:29   ` Chris Bainbridge [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20160126112905.GA4818@localhost \
    --to=chris.bainbridge@gmail.com \
    --cc=aryabinin@virtuozzo.com \
    --cc=clm@fb.com \
    --cc=dsterba@suse.cz \
    --cc=jbacik@fb.com \
    --cc=linux-btrfs@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).