* [syzbot] [gfs2?] KASAN: slab-use-after-free Read in gfs2_invalidate_folio
@ 2024-04-11 16:17 syzbot
2024-04-13 5:41 ` Edward Adam Davis
` (7 more replies)
0 siblings, 8 replies; 17+ messages in thread
From: syzbot @ 2024-04-11 16:17 UTC (permalink / raw)
To: agruenba, gfs2, linux-fsdevel, linux-kernel, syzkaller-bugs
Hello,
syzbot found the following issue on:
HEAD commit: e8c39d0f57f3 Merge tag 'probes-fixes-v6.9-rc3' of git://gi..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=12ce66a3180000
kernel config: https://syzkaller.appspot.com/x/.config?x=285be8dd6baeb438
dashboard link: https://syzkaller.appspot.com/bug?extid=3a36aeabd31497d63f6e
compiler: gcc (Debian 12.2.0-14) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=16892dcb180000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=130547bd180000
Downloadable assets:
disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/7bc7510fe41f/non_bootable_disk-e8c39d0f.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/d33b002ae0bf/vmlinux-e8c39d0f.xz
kernel image: https://storage.googleapis.com/syzbot-assets/047d0bfb2db7/bzImage-e8c39d0f.xz
mounted in repro: https://storage.googleapis.com/syzbot-assets/749aec76707a/mount_0.gz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+3a36aeabd31497d63f6e@syzkaller.appspotmail.com
==================================================================
BUG: KASAN: slab-use-after-free in list_empty include/linux/list.h:373 [inline]
BUG: KASAN: slab-use-after-free in gfs2_discard fs/gfs2/aops.c:617 [inline]
BUG: KASAN: slab-use-after-free in gfs2_invalidate_folio+0x718/0x820 fs/gfs2/aops.c:655
Read of size 8 at addr ffff88801db08168 by task syz-executor595/5186
CPU: 3 PID: 5186 Comm: syz-executor595 Not tainted 6.9.0-rc3-syzkaller-00073-ge8c39d0f57f3 #0
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:88 [inline]
dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:114
print_address_description mm/kasan/report.c:377 [inline]
print_report+0xc3/0x620 mm/kasan/report.c:488
kasan_report+0xd9/0x110 mm/kasan/report.c:601
list_empty include/linux/list.h:373 [inline]
gfs2_discard fs/gfs2/aops.c:617 [inline]
gfs2_invalidate_folio+0x718/0x820 fs/gfs2/aops.c:655
folio_invalidate mm/truncate.c:158 [inline]
truncate_cleanup_folio+0x2ac/0x3e0 mm/truncate.c:178
truncate_inode_pages_range+0x271/0xe90 mm/truncate.c:358
gfs2_evict_inode+0x75b/0x1460 fs/gfs2/super.c:1508
evict+0x2ed/0x6c0 fs/inode.c:667
iput_final fs/inode.c:1741 [inline]
iput.part.0+0x5a8/0x7f0 fs/inode.c:1767
iput+0x5c/0x80 fs/inode.c:1757
gfs2_put_super+0x2bd/0x760 fs/gfs2/super.c:625
generic_shutdown_super+0x159/0x3d0 fs/super.c:641
kill_block_super+0x3b/0x90 fs/super.c:1675
gfs2_kill_sb+0x360/0x410 fs/gfs2/ops_fstype.c:1804
deactivate_locked_super+0xbe/0x1a0 fs/super.c:472
deactivate_super+0xde/0x100 fs/super.c:505
cleanup_mnt+0x222/0x450 fs/namespace.c:1267
task_work_run+0x14e/0x250 kernel/task_work.c:180
exit_task_work include/linux/task_work.h:38 [inline]
do_exit+0xa7d/0x2c10 kernel/exit.c:878
do_group_exit+0xd3/0x2a0 kernel/exit.c:1027
__do_sys_exit_group kernel/exit.c:1038 [inline]
__se_sys_exit_group kernel/exit.c:1036 [inline]
__x64_sys_exit_group+0x3e/0x50 kernel/exit.c:1036
do_syscall_x64 arch/x86/entry/common.c:52 [inline]
do_syscall_64+0xcf/0x260 arch/x86/entry/common.c:83
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fe708777789
Code: Unable to access opcode bytes at 0x7fe70877775f.
RSP: 002b:00007ffd15e3f838 EFLAGS: 00000246 ORIG_RAX: 00000000000000e7
RAX: ffffffffffffffda RBX: 0000000000000001 RCX: 00007fe708777789
RDX: 000000000000003c RSI: 00000000000000e7 RDI: 0000000000000001
RBP: 00007fe7088122b0 R08: ffffffffffffffb8 R09: 000000000001f6db
R10: 0000000000000000 R11: 0000000000000246 R12: 00007fe7088122b0
R13: 0000000000000000 R14: 00007fe708813020 R15: 00007fe708745cc0
</TASK>
Allocated by task 5186:
kasan_save_stack+0x33/0x60 mm/kasan/common.c:47
kasan_save_track+0x14/0x30 mm/kasan/common.c:68
unpoison_slab_object mm/kasan/common.c:312 [inline]
__kasan_slab_alloc+0x89/0x90 mm/kasan/common.c:338
kasan_slab_alloc include/linux/kasan.h:201 [inline]
slab_post_alloc_hook mm/slub.c:3798 [inline]
slab_alloc_node mm/slub.c:3845 [inline]
kmem_cache_alloc+0x136/0x320 mm/slub.c:3852
kmem_cache_zalloc include/linux/slab.h:739 [inline]
gfs2_alloc_bufdata fs/gfs2/trans.c:168 [inline]
gfs2_trans_add_data+0x4b3/0x7f0 fs/gfs2/trans.c:209
gfs2_unstuffer_folio fs/gfs2/bmap.c:81 [inline]
__gfs2_unstuff_inode fs/gfs2/bmap.c:119 [inline]
gfs2_unstuff_dinode+0xad9/0x1460 fs/gfs2/bmap.c:166
gfs2_adjust_quota+0x124/0xb10 fs/gfs2/quota.c:879
do_sync+0xa73/0xd30 fs/gfs2/quota.c:990
gfs2_quota_sync+0x419/0x630 fs/gfs2/quota.c:1370
gfs2_sync_fs+0x44/0xb0 fs/gfs2/super.c:669
sync_filesystem+0x10d/0x290 fs/sync.c:56
generic_shutdown_super+0x7e/0x3d0 fs/super.c:620
kill_block_super+0x3b/0x90 fs/super.c:1675
gfs2_kill_sb+0x360/0x410 fs/gfs2/ops_fstype.c:1804
deactivate_locked_super+0xbe/0x1a0 fs/super.c:472
deactivate_super+0xde/0x100 fs/super.c:505
cleanup_mnt+0x222/0x450 fs/namespace.c:1267
task_work_run+0x14e/0x250 kernel/task_work.c:180
exit_task_work include/linux/task_work.h:38 [inline]
do_exit+0xa7d/0x2c10 kernel/exit.c:878
do_group_exit+0xd3/0x2a0 kernel/exit.c:1027
__do_sys_exit_group kernel/exit.c:1038 [inline]
__se_sys_exit_group kernel/exit.c:1036 [inline]
__x64_sys_exit_group+0x3e/0x50 kernel/exit.c:1036
do_syscall_x64 arch/x86/entry/common.c:52 [inline]
do_syscall_64+0xcf/0x260 arch/x86/entry/common.c:83
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Freed by task 5186:
kasan_save_stack+0x33/0x60 mm/kasan/common.c:47
kasan_save_track+0x14/0x30 mm/kasan/common.c:68
kasan_save_free_info+0x3b/0x60 mm/kasan/generic.c:579
poison_slab_object mm/kasan/common.c:240 [inline]
__kasan_slab_free+0x11d/0x1a0 mm/kasan/common.c:256
kasan_slab_free include/linux/kasan.h:184 [inline]
slab_free_hook mm/slub.c:2106 [inline]
slab_free mm/slub.c:4280 [inline]
kmem_cache_free+0x12e/0x380 mm/slub.c:4344
trans_drain fs/gfs2/log.c:1028 [inline]
gfs2_log_flush+0x1486/0x29b0 fs/gfs2/log.c:1167
do_sync+0x550/0xd30 fs/gfs2/quota.c:1010
gfs2_quota_sync+0x419/0x630 fs/gfs2/quota.c:1370
gfs2_sync_fs+0x44/0xb0 fs/gfs2/super.c:669
sync_filesystem+0x10d/0x290 fs/sync.c:56
generic_shutdown_super+0x7e/0x3d0 fs/super.c:620
kill_block_super+0x3b/0x90 fs/super.c:1675
gfs2_kill_sb+0x360/0x410 fs/gfs2/ops_fstype.c:1804
deactivate_locked_super+0xbe/0x1a0 fs/super.c:472
deactivate_super+0xde/0x100 fs/super.c:505
cleanup_mnt+0x222/0x450 fs/namespace.c:1267
task_work_run+0x14e/0x250 kernel/task_work.c:180
exit_task_work include/linux/task_work.h:38 [inline]
do_exit+0xa7d/0x2c10 kernel/exit.c:878
do_group_exit+0xd3/0x2a0 kernel/exit.c:1027
__do_sys_exit_group kernel/exit.c:1038 [inline]
__se_sys_exit_group kernel/exit.c:1036 [inline]
__x64_sys_exit_group+0x3e/0x50 kernel/exit.c:1036
do_syscall_x64 arch/x86/entry/common.c:52 [inline]
do_syscall_64+0xcf/0x260 arch/x86/entry/common.c:83
entry_SYSCALL_64_after_hwframe+0x77/0x7f
The buggy address belongs to the object at ffff88801db08150
which belongs to the cache gfs2_bufdata of size 80
The buggy address is located 24 bytes inside of
freed 80-byte region [ffff88801db08150, ffff88801db081a0)
The buggy address belongs to the physical page:
page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1db08
flags: 0xfff80000000800(slab|node=0|zone=1|lastcpupid=0xfff)
page_type: 0xffffffff()
raw: 00fff80000000800 ffff88801a5aedc0 dead000000000122 0000000000000000
raw: 0000000000000000 0000000080240024 00000001ffffffff 0000000000000000
page dumped because: kasan: bad access detected
page_owner tracks the page as allocated
page last allocated via order 0, migratetype Unmovable, gfp_mask 0x12c40(GFP_NOFS|__GFP_NOWARN|__GFP_NORETRY), pid 5186, tgid 5186 (syz-executor595), ts 45296183443, free_ts 44935801807
set_page_owner include/linux/page_owner.h:32 [inline]
post_alloc_hook+0x2d4/0x350 mm/page_alloc.c:1534
prep_new_page mm/page_alloc.c:1541 [inline]
get_page_from_freelist+0xa28/0x3780 mm/page_alloc.c:3317
__alloc_pages+0x22b/0x2460 mm/page_alloc.c:4575
__alloc_pages_node include/linux/gfp.h:238 [inline]
alloc_pages_node include/linux/gfp.h:261 [inline]
alloc_slab_page mm/slub.c:2175 [inline]
allocate_slab mm/slub.c:2338 [inline]
new_slab+0xcc/0x3a0 mm/slub.c:2391
___slab_alloc+0x66d/0x1790 mm/slub.c:3525
__slab_alloc.constprop.0+0x56/0xb0 mm/slub.c:3610
__slab_alloc_node mm/slub.c:3663 [inline]
slab_alloc_node mm/slub.c:3835 [inline]
kmem_cache_alloc+0x2e9/0x320 mm/slub.c:3852
kmem_cache_zalloc include/linux/slab.h:739 [inline]
gfs2_alloc_bufdata fs/gfs2/trans.c:168 [inline]
gfs2_trans_add_meta+0xade/0xf50 fs/gfs2/trans.c:251
gfs2_alloc_extent fs/gfs2/rgrp.c:2239 [inline]
gfs2_alloc_blocks+0x46c/0x19c0 fs/gfs2/rgrp.c:2449
__gfs2_unstuff_inode fs/gfs2/bmap.c:107 [inline]
gfs2_unstuff_dinode+0x499/0x1460 fs/gfs2/bmap.c:166
gfs2_adjust_quota+0x124/0xb10 fs/gfs2/quota.c:879
do_sync+0xa73/0xd30 fs/gfs2/quota.c:990
gfs2_quota_sync+0x419/0x630 fs/gfs2/quota.c:1370
gfs2_sync_fs+0x44/0xb0 fs/gfs2/super.c:669
sync_filesystem+0x10d/0x290 fs/sync.c:56
generic_shutdown_super+0x7e/0x3d0 fs/super.c:620
page last free pid 4684 tgid 4684 stack trace:
reset_page_owner include/linux/page_owner.h:25 [inline]
free_pages_prepare mm/page_alloc.c:1141 [inline]
free_unref_page_prepare+0x527/0xb10 mm/page_alloc.c:2347
free_unref_page+0x33/0x3c0 mm/page_alloc.c:2487
__put_partials+0x14c/0x170 mm/slub.c:2906
qlink_free mm/kasan/quarantine.c:163 [inline]
qlist_free_all+0x4e/0x140 mm/kasan/quarantine.c:179
kasan_quarantine_reduce+0x192/0x1e0 mm/kasan/quarantine.c:286
__kasan_slab_alloc+0x69/0x90 mm/kasan/common.c:322
kasan_slab_alloc include/linux/kasan.h:201 [inline]
slab_post_alloc_hook mm/slub.c:3798 [inline]
slab_alloc_node mm/slub.c:3845 [inline]
kmem_cache_alloc+0x136/0x320 mm/slub.c:3852
getname_flags.part.0+0x50/0x4f0 fs/namei.c:139
getname_flags+0x9b/0xf0 include/linux/audit.h:322
vfs_fstatat+0x9a/0x150 fs/stat.c:303
__do_sys_newfstatat+0x98/0x120 fs/stat.c:468
do_syscall_x64 arch/x86/entry/common.c:52 [inline]
do_syscall_64+0xcf/0x260 arch/x86/entry/common.c:83
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Memory state around the buggy address:
ffff88801db08000: fa fb fb fb fb fb fb fb fb fb fc fc fc fc fa fb
ffff88801db08080: fb fb fb fb fb fb fb fb fc fc fc fc fa fb fb fb
>ffff88801db08100: fb fb fb fb fb fb fc fc fc fc fa fb fb fb fb fb
^
ffff88801db08180: fb fb fb fb fc fc fc fc fa fb fb fb fb fb fb fb
ffff88801db08200: fb fb fc fc fc fc fc fc fc fc fc fc fc fc fc fc
==================================================================
---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup
^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [syzbot] [gfs2?] KASAN: slab-use-after-free Read in gfs2_invalidate_folio 2024-04-11 16:17 [syzbot] [gfs2?] KASAN: slab-use-after-free Read in gfs2_invalidate_folio syzbot @ 2024-04-13 5:41 ` Edward Adam Davis 2024-04-13 5:54 ` syzbot 2024-04-13 9:19 ` Edward Adam Davis ` (6 subsequent siblings) 7 siblings, 1 reply; 17+ messages in thread From: Edward Adam Davis @ 2024-04-13 5:41 UTC (permalink / raw) To: syzbot+3a36aeabd31497d63f6e; +Cc: linux-kernel, syzkaller-bugs please test uaf in gfs2_invalidate_folio #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git e8c39d0f57f3 diff --git a/fs/gfs2/log.c b/fs/gfs2/log.c index 8cddf955ebc0..5585f92e4319 100644 --- a/fs/gfs2/log.c +++ b/fs/gfs2/log.c @@ -1007,6 +1007,7 @@ static void trans_drain(struct gfs2_trans *tr) { struct gfs2_bufdata *bd; struct list_head *head; + struct buffer_head *bh; if (!tr) return; @@ -1022,6 +1023,8 @@ static void trans_drain(struct gfs2_trans *tr) head = &tr->tr_databuf; while (!list_empty(head)) { bd = list_first_entry(head, struct gfs2_bufdata, bd_list); + bh = container_of(bd, struct buffer_head, b_private); + bh->b_private = NULL; list_del_init(&bd->bd_list); if (!list_empty(&bd->bd_ail_st_list)) gfs2_remove_from_ail(bd); ^ permalink raw reply related [flat|nested] 17+ messages in thread
* Re: [syzbot] [gfs2?] KASAN: slab-use-after-free Read in gfs2_invalidate_folio 2024-04-13 5:41 ` Edward Adam Davis @ 2024-04-13 5:54 ` syzbot 0 siblings, 0 replies; 17+ messages in thread From: syzbot @ 2024-04-13 5:54 UTC (permalink / raw) To: eadavis, linux-kernel, syzkaller-bugs Hello, syzbot tried to test the proposed patch but the build/boot failed: ./include/linux/build_bug.h:78:41: error: static assertion failed: "pointer type mismatch in container_of()" Tested on: commit: e8c39d0f Merge tag 'probes-fixes-v6.9-rc3' of git://gi.. git tree: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git kernel config: https://syzkaller.appspot.com/x/.config?x=285be8dd6baeb438 dashboard link: https://syzkaller.appspot.com/bug?extid=3a36aeabd31497d63f6e compiler: gcc (Debian 12.2.0-14) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40 patch: https://syzkaller.appspot.com/x/patch.diff?x=12ba01eb180000 ^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [syzbot] [gfs2?] KASAN: slab-use-after-free Read in gfs2_invalidate_folio 2024-04-11 16:17 [syzbot] [gfs2?] KASAN: slab-use-after-free Read in gfs2_invalidate_folio syzbot 2024-04-13 5:41 ` Edward Adam Davis @ 2024-04-13 9:19 ` Edward Adam Davis 2024-04-13 9:36 ` syzbot 2024-04-13 14:48 ` Edward Adam Davis ` (5 subsequent siblings) 7 siblings, 1 reply; 17+ messages in thread From: Edward Adam Davis @ 2024-04-13 9:19 UTC (permalink / raw) To: syzbot+3a36aeabd31497d63f6e; +Cc: linux-kernel, syzkaller-bugs please test uaf in gfs2_invalidate_folio #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git e8c39d0f57f3 diff --git a/fs/gfs2/log.c b/fs/gfs2/log.c index 8cddf955ebc0..698c9d1bfe20 100644 --- a/fs/gfs2/log.c +++ b/fs/gfs2/log.c @@ -1007,6 +1007,7 @@ static void trans_drain(struct gfs2_trans *tr) { struct gfs2_bufdata *bd; struct list_head *head; + struct buffer_head * bh; if (!tr) return; @@ -1022,6 +1023,8 @@ static void trans_drain(struct gfs2_trans *tr) head = &tr->tr_databuf; while (!list_empty(head)) { bd = list_first_entry(head, struct gfs2_bufdata, bd_list); + bh = container_of((void *)bd, struct buffer_head, b_private); + bh->b_private = NULL; list_del_init(&bd->bd_list); if (!list_empty(&bd->bd_ail_st_list)) gfs2_remove_from_ail(bd); ^ permalink raw reply related [flat|nested] 17+ messages in thread
* Re: [syzbot] [gfs2?] KASAN: slab-use-after-free Read in gfs2_invalidate_folio 2024-04-13 9:19 ` Edward Adam Davis @ 2024-04-13 9:36 ` syzbot 0 siblings, 0 replies; 17+ messages in thread From: syzbot @ 2024-04-13 9:36 UTC (permalink / raw) To: eadavis, linux-kernel, syzkaller-bugs Hello, syzbot has tested the proposed patch but the reproducer is still triggering an issue: KASAN: slab-use-after-free Read in gfs2_invalidate_folio ================================================================== BUG: KASAN: slab-use-after-free in list_empty include/linux/list.h:373 [inline] BUG: KASAN: slab-use-after-free in gfs2_discard fs/gfs2/aops.c:617 [inline] BUG: KASAN: slab-use-after-free in gfs2_invalidate_folio+0x718/0x820 fs/gfs2/aops.c:655 Read of size 8 at addr ffff88801eda0168 by task syz-executor.0/5408 CPU: 1 PID: 5408 Comm: syz-executor.0 Not tainted 6.9.0-rc3-syzkaller-00073-ge8c39d0f57f3-dirty #0 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014 Call Trace: <TASK> __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:114 print_address_description mm/kasan/report.c:377 [inline] print_report+0xc3/0x620 mm/kasan/report.c:488 kasan_report+0xd9/0x110 mm/kasan/report.c:601 list_empty include/linux/list.h:373 [inline] gfs2_discard fs/gfs2/aops.c:617 [inline] gfs2_invalidate_folio+0x718/0x820 fs/gfs2/aops.c:655 folio_invalidate mm/truncate.c:158 [inline] truncate_cleanup_folio+0x2ac/0x3e0 mm/truncate.c:178 truncate_inode_pages_range+0x271/0xe90 mm/truncate.c:358 gfs2_evict_inode+0x75b/0x1460 fs/gfs2/super.c:1508 evict+0x2ed/0x6c0 fs/inode.c:667 iput_final fs/inode.c:1741 [inline] iput.part.0+0x5a8/0x7f0 fs/inode.c:1767 iput+0x5c/0x80 fs/inode.c:1757 gfs2_put_super+0x2bd/0x760 fs/gfs2/super.c:625 generic_shutdown_super+0x159/0x3d0 fs/super.c:641 kill_block_super+0x3b/0x90 fs/super.c:1675 gfs2_kill_sb+0x360/0x410 fs/gfs2/ops_fstype.c:1804 deactivate_locked_super+0xbe/0x1a0 fs/super.c:472 deactivate_super+0xde/0x100 fs/super.c:505 cleanup_mnt+0x222/0x450 fs/namespace.c:1267 task_work_run+0x14e/0x250 kernel/task_work.c:180 resume_user_mode_work include/linux/resume_user_mode.h:50 [inline] exit_to_user_mode_loop kernel/entry/common.c:114 [inline] exit_to_user_mode_prepare include/linux/entry-common.h:328 [inline] __syscall_exit_to_user_mode_work kernel/entry/common.c:207 [inline] syscall_exit_to_user_mode+0x278/0x2a0 kernel/entry/common.c:218 do_syscall_64+0xdc/0x260 arch/x86/entry/common.c:89 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f6eafc7f197 Code: b0 ff ff ff f7 d8 64 89 01 48 83 c8 ff c3 0f 1f 44 00 00 31 f6 e9 09 00 00 00 66 0f 1f 84 00 00 00 00 00 b8 a6 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 01 c3 48 c7 c2 b0 ff ff ff f7 d8 64 89 02 b8 RSP: 002b:00007ffe0a357d88 EFLAGS: 00000246 ORIG_RAX: 00000000000000a6 RAX: 0000000000000000 RBX: 0000000000000000 RCX: 00007f6eafc7f197 RDX: 0000000000000000 RSI: 0000000000000009 RDI: 00007ffe0a357e40 RBP: 00007ffe0a357e40 R08: 0000000000000000 R09: 0000000000000000 R10: 00000000ffffffff R11: 0000000000000246 R12: 00007ffe0a358f00 R13: 00007f6eafcc93b9 R14: 0000000000012bfa R15: 0000000000000001 </TASK> Allocated by task 5408: kasan_save_stack+0x33/0x60 mm/kasan/common.c:47 kasan_save_track+0x14/0x30 mm/kasan/common.c:68 unpoison_slab_object mm/kasan/common.c:312 [inline] __kasan_slab_alloc+0x89/0x90 mm/kasan/common.c:338 kasan_slab_alloc include/linux/kasan.h:201 [inline] slab_post_alloc_hook mm/slub.c:3798 [inline] slab_alloc_node mm/slub.c:3845 [inline] kmem_cache_alloc+0x136/0x320 mm/slub.c:3852 kmem_cache_zalloc include/linux/slab.h:739 [inline] gfs2_alloc_bufdata fs/gfs2/trans.c:168 [inline] gfs2_trans_add_data+0x4b3/0x7f0 fs/gfs2/trans.c:209 gfs2_unstuffer_folio fs/gfs2/bmap.c:81 [inline] __gfs2_unstuff_inode fs/gfs2/bmap.c:119 [inline] gfs2_unstuff_dinode+0xad9/0x1460 fs/gfs2/bmap.c:166 gfs2_adjust_quota+0x124/0xb10 fs/gfs2/quota.c:879 do_sync+0xa73/0xd30 fs/gfs2/quota.c:990 gfs2_quota_sync+0x419/0x630 fs/gfs2/quota.c:1370 gfs2_sync_fs+0x44/0xb0 fs/gfs2/super.c:669 sync_filesystem+0x10d/0x290 fs/sync.c:56 generic_shutdown_super+0x7e/0x3d0 fs/super.c:620 kill_block_super+0x3b/0x90 fs/super.c:1675 gfs2_kill_sb+0x360/0x410 fs/gfs2/ops_fstype.c:1804 deactivate_locked_super+0xbe/0x1a0 fs/super.c:472 deactivate_super+0xde/0x100 fs/super.c:505 cleanup_mnt+0x222/0x450 fs/namespace.c:1267 task_work_run+0x14e/0x250 kernel/task_work.c:180 resume_user_mode_work include/linux/resume_user_mode.h:50 [inline] exit_to_user_mode_loop kernel/entry/common.c:114 [inline] exit_to_user_mode_prepare include/linux/entry-common.h:328 [inline] __syscall_exit_to_user_mode_work kernel/entry/common.c:207 [inline] syscall_exit_to_user_mode+0x278/0x2a0 kernel/entry/common.c:218 do_syscall_64+0xdc/0x260 arch/x86/entry/common.c:89 entry_SYSCALL_64_after_hwframe+0x77/0x7f Freed by task 5408: kasan_save_stack+0x33/0x60 mm/kasan/common.c:47 kasan_save_track+0x14/0x30 mm/kasan/common.c:68 kasan_save_free_info+0x3b/0x60 mm/kasan/generic.c:579 poison_slab_object mm/kasan/common.c:240 [inline] __kasan_slab_free+0x11d/0x1a0 mm/kasan/common.c:256 kasan_slab_free include/linux/kasan.h:184 [inline] slab_free_hook mm/slub.c:2106 [inline] slab_free mm/slub.c:4280 [inline] kmem_cache_free+0x12e/0x380 mm/slub.c:4344 trans_drain fs/gfs2/log.c:1031 [inline] gfs2_log_flush+0x149f/0x29c0 fs/gfs2/log.c:1170 do_sync+0x550/0xd30 fs/gfs2/quota.c:1010 gfs2_quota_sync+0x419/0x630 fs/gfs2/quota.c:1370 gfs2_sync_fs+0x44/0xb0 fs/gfs2/super.c:669 sync_filesystem+0x10d/0x290 fs/sync.c:56 generic_shutdown_super+0x7e/0x3d0 fs/super.c:620 kill_block_super+0x3b/0x90 fs/super.c:1675 gfs2_kill_sb+0x360/0x410 fs/gfs2/ops_fstype.c:1804 deactivate_locked_super+0xbe/0x1a0 fs/super.c:472 deactivate_super+0xde/0x100 fs/super.c:505 cleanup_mnt+0x222/0x450 fs/namespace.c:1267 task_work_run+0x14e/0x250 kernel/task_work.c:180 resume_user_mode_work include/linux/resume_user_mode.h:50 [inline] exit_to_user_mode_loop kernel/entry/common.c:114 [inline] exit_to_user_mode_prepare include/linux/entry-common.h:328 [inline] __syscall_exit_to_user_mode_work kernel/entry/common.c:207 [inline] syscall_exit_to_user_mode+0x278/0x2a0 kernel/entry/common.c:218 do_syscall_64+0xdc/0x260 arch/x86/entry/common.c:89 entry_SYSCALL_64_after_hwframe+0x77/0x7f The buggy address belongs to the object at ffff88801eda0150 which belongs to the cache gfs2_bufdata of size 80 The buggy address is located 24 bytes inside of freed 80-byte region [ffff88801eda0150, ffff88801eda01a0) The buggy address belongs to the physical page: page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1eda0 flags: 0xfff80000000800(slab|node=0|zone=1|lastcpupid=0xfff) page_type: 0xffffffff() raw: 00fff80000000800 ffff88801a5608c0 dead000000000122 0000000000000000 raw: 0000000000000000 0000000080240024 00000001ffffffff 0000000000000000 page dumped because: kasan: bad access detected page_owner tracks the page as allocated page last allocated via order 0, migratetype Unmovable, gfp_mask 0x112c40(GFP_NOFS|__GFP_NOWARN|__GFP_NORETRY|__GFP_HARDWALL), pid 5408, tgid 5408 (syz-executor.0), ts 77566437630, free_ts 77557534093 set_page_owner include/linux/page_owner.h:32 [inline] post_alloc_hook+0x2d4/0x350 mm/page_alloc.c:1534 prep_new_page mm/page_alloc.c:1541 [inline] get_page_from_freelist+0xa28/0x3780 mm/page_alloc.c:3317 __alloc_pages+0x22b/0x2460 mm/page_alloc.c:4575 __alloc_pages_node include/linux/gfp.h:238 [inline] alloc_pages_node include/linux/gfp.h:261 [inline] alloc_slab_page mm/slub.c:2175 [inline] allocate_slab mm/slub.c:2338 [inline] new_slab+0xcc/0x3a0 mm/slub.c:2391 ___slab_alloc+0x66d/0x1790 mm/slub.c:3525 __slab_alloc.constprop.0+0x56/0xb0 mm/slub.c:3610 __slab_alloc_node mm/slub.c:3663 [inline] slab_alloc_node mm/slub.c:3835 [inline] kmem_cache_alloc+0x2e9/0x320 mm/slub.c:3852 kmem_cache_zalloc include/linux/slab.h:739 [inline] gfs2_alloc_bufdata fs/gfs2/trans.c:168 [inline] gfs2_trans_add_meta+0xade/0xf50 fs/gfs2/trans.c:251 gfs2_alloc_extent fs/gfs2/rgrp.c:2239 [inline] gfs2_alloc_blocks+0x46c/0x19c0 fs/gfs2/rgrp.c:2449 __gfs2_unstuff_inode fs/gfs2/bmap.c:107 [inline] gfs2_unstuff_dinode+0x499/0x1460 fs/gfs2/bmap.c:166 gfs2_adjust_quota+0x124/0xb10 fs/gfs2/quota.c:879 do_sync+0xa73/0xd30 fs/gfs2/quota.c:990 gfs2_quota_sync+0x419/0x630 fs/gfs2/quota.c:1370 gfs2_sync_fs+0x44/0xb0 fs/gfs2/super.c:669 sync_filesystem+0x10d/0x290 fs/sync.c:56 generic_shutdown_super+0x7e/0x3d0 fs/super.c:620 page last free pid 5408 tgid 5408 stack trace: reset_page_owner include/linux/page_owner.h:25 [inline] free_pages_prepare mm/page_alloc.c:1141 [inline] free_unref_page_prepare+0x527/0xb10 mm/page_alloc.c:2347 free_unref_page+0x33/0x3c0 mm/page_alloc.c:2487 __folio_put_small mm/swap.c:119 [inline] __folio_put+0x166/0x1f0 mm/swap.c:142 folio_put include/linux/mm.h:1506 [inline] free_page_and_swap_cache+0x1eb/0x250 mm/swap_state.c:305 __tlb_remove_table arch/x86/include/asm/tlb.h:34 [inline] __tlb_remove_table_free mm/mmu_gather.c:227 [inline] tlb_remove_table_rcu+0x89/0xe0 mm/mmu_gather.c:282 rcu_do_batch kernel/rcu/tree.c:2196 [inline] rcu_core+0x828/0x16b0 kernel/rcu/tree.c:2471 __do_softirq+0x218/0x922 kernel/softirq.c:554 Memory state around the buggy address: ffff88801eda0000: fa fb fb fb fb fb fb fb fb fb fc fc fc fc fa fb ffff88801eda0080: fb fb fb fb fb fb fb fb fc fc fc fc fa fb fb fb >ffff88801eda0100: fb fb fb fb fb fb fc fc fc fc fa fb fb fb fb fb ^ ffff88801eda0180: fb fb fb fb fc fc fc fc fa fb fb fb fb fb fb fb ffff88801eda0200: fb fb fc fc fc fc fc fc fc fc fc fc fc fc fc fc ================================================================== Tested on: commit: e8c39d0f Merge tag 'probes-fixes-v6.9-rc3' of git://gi.. git tree: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git console output: https://syzkaller.appspot.com/x/log.txt?x=13904f97180000 kernel config: https://syzkaller.appspot.com/x/.config?x=285be8dd6baeb438 dashboard link: https://syzkaller.appspot.com/bug?extid=3a36aeabd31497d63f6e compiler: gcc (Debian 12.2.0-14) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40 patch: https://syzkaller.appspot.com/x/patch.diff?x=116eabf3180000 ^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [syzbot] [gfs2?] KASAN: slab-use-after-free Read in gfs2_invalidate_folio 2024-04-11 16:17 [syzbot] [gfs2?] KASAN: slab-use-after-free Read in gfs2_invalidate_folio syzbot 2024-04-13 5:41 ` Edward Adam Davis 2024-04-13 9:19 ` Edward Adam Davis @ 2024-04-13 14:48 ` Edward Adam Davis 2024-04-13 15:05 ` syzbot 2024-04-14 1:48 ` Edward Adam Davis ` (4 subsequent siblings) 7 siblings, 1 reply; 17+ messages in thread From: Edward Adam Davis @ 2024-04-13 14:48 UTC (permalink / raw) To: syzbot+3a36aeabd31497d63f6e; +Cc: linux-kernel, syzkaller-bugs please test uaf in gfs2_invalidate_folio #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git e8c39d0f57f3 diff --git a/fs/gfs2/aops.c b/fs/gfs2/aops.c index 974aca9c8ea8..4ae5e73b6992 100644 --- a/fs/gfs2/aops.c +++ b/fs/gfs2/aops.c @@ -613,6 +613,7 @@ static void gfs2_discard(struct gfs2_sbd *sdp, struct buffer_head *bh) gfs2_log_lock(sdp); clear_buffer_dirty(bh); bd = bh->b_private; + printk("bh: %p, bd: %p, %s\n", bh, bd, __func__); if (bd) { if (!list_empty(&bd->bd_list) && !buffer_pinned(bh)) list_del_init(&bd->bd_list); diff --git a/fs/gfs2/log.c b/fs/gfs2/log.c index 8cddf955ebc0..d05decef6af5 100644 --- a/fs/gfs2/log.c +++ b/fs/gfs2/log.c @@ -1007,6 +1007,7 @@ static void trans_drain(struct gfs2_trans *tr) { struct gfs2_bufdata *bd; struct list_head *head; + struct buffer_head *bh; if (!tr) return; @@ -1022,6 +1023,9 @@ static void trans_drain(struct gfs2_trans *tr) head = &tr->tr_databuf; while (!list_empty(head)) { bd = list_first_entry(head, struct gfs2_bufdata, bd_list); + bh = container_of((void *)bd, struct buffer_head, b_private); + printk("bh: %p, bd: %p, %s\n", bh, bd, __func__); + bh->b_private = NULL; list_del_init(&bd->bd_list); if (!list_empty(&bd->bd_ail_st_list)) gfs2_remove_from_ail(bd); ^ permalink raw reply related [flat|nested] 17+ messages in thread
* Re: [syzbot] [gfs2?] KASAN: slab-use-after-free Read in gfs2_invalidate_folio 2024-04-13 14:48 ` Edward Adam Davis @ 2024-04-13 15:05 ` syzbot 0 siblings, 0 replies; 17+ messages in thread From: syzbot @ 2024-04-13 15:05 UTC (permalink / raw) To: eadavis, linux-kernel, syzkaller-bugs Hello, syzbot has tested the proposed patch but the reproducer is still triggering an issue: KASAN: slab-use-after-free Read in gfs2_invalidate_folio </TASK> bh: ffff88802f874110, bd: ffff88802f874150, trans_drain bh: ffff88802ffb5d98, bd: ffff88802f874150, gfs2_discard ================================================================== BUG: KASAN: slab-use-after-free in list_empty include/linux/list.h:373 [inline] BUG: KASAN: slab-use-after-free in gfs2_discard fs/gfs2/aops.c:618 [inline] BUG: KASAN: slab-use-after-free in gfs2_invalidate_folio+0x731/0x840 fs/gfs2/aops.c:656 Read of size 8 at addr ffff88802f874168 by task syz-executor.0/5414 CPU: 3 PID: 5414 Comm: syz-executor.0 Not tainted 6.9.0-rc3-syzkaller-00073-ge8c39d0f57f3-dirty #0 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014 Call Trace: <TASK> __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:114 print_address_description mm/kasan/report.c:377 [inline] print_report+0xc3/0x620 mm/kasan/report.c:488 kasan_report+0xd9/0x110 mm/kasan/report.c:601 list_empty include/linux/list.h:373 [inline] gfs2_discard fs/gfs2/aops.c:618 [inline] gfs2_invalidate_folio+0x731/0x840 fs/gfs2/aops.c:656 folio_invalidate mm/truncate.c:158 [inline] truncate_cleanup_folio+0x2ac/0x3e0 mm/truncate.c:178 truncate_inode_pages_range+0x271/0xe90 mm/truncate.c:358 gfs2_evict_inode+0x75b/0x1460 fs/gfs2/super.c:1508 evict+0x2ed/0x6c0 fs/inode.c:667 iput_final fs/inode.c:1741 [inline] iput.part.0+0x5a8/0x7f0 fs/inode.c:1767 iput+0x5c/0x80 fs/inode.c:1757 gfs2_put_super+0x2bd/0x760 fs/gfs2/super.c:625 generic_shutdown_super+0x159/0x3d0 fs/super.c:641 kill_block_super+0x3b/0x90 fs/super.c:1675 gfs2_kill_sb+0x360/0x410 fs/gfs2/ops_fstype.c:1804 deactivate_locked_super+0xbe/0x1a0 fs/super.c:472 deactivate_super+0xde/0x100 fs/super.c:505 cleanup_mnt+0x222/0x450 fs/namespace.c:1267 task_work_run+0x14e/0x250 kernel/task_work.c:180 resume_user_mode_work include/linux/resume_user_mode.h:50 [inline] exit_to_user_mode_loop kernel/entry/common.c:114 [inline] exit_to_user_mode_prepare include/linux/entry-common.h:328 [inline] __syscall_exit_to_user_mode_work kernel/entry/common.c:207 [inline] syscall_exit_to_user_mode+0x278/0x2a0 kernel/entry/common.c:218 do_syscall_64+0xdc/0x260 arch/x86/entry/common.c:89 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f0c14c7f197 Code: b0 ff ff ff f7 d8 64 89 01 48 83 c8 ff c3 0f 1f 44 00 00 31 f6 e9 09 00 00 00 66 0f 1f 84 00 00 00 00 00 b8 a6 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 01 c3 48 c7 c2 b0 ff ff ff f7 d8 64 89 02 b8 RSP: 002b:00007ffd638aaec8 EFLAGS: 00000246 ORIG_RAX: 00000000000000a6 RAX: 0000000000000000 RBX: 0000000000000000 RCX: 00007f0c14c7f197 RDX: 0000000000000000 RSI: 0000000000000009 RDI: 00007ffd638aaf80 RBP: 00007ffd638aaf80 R08: 0000000000000000 R09: 0000000000000000 R10: 00000000ffffffff R11: 0000000000000246 R12: 00007ffd638ac040 R13: 00007f0c14cc93b9 R14: 000000000001278e R15: 0000000000000001 </TASK> Allocated by task 5414: kasan_save_stack+0x33/0x60 mm/kasan/common.c:47 kasan_save_track+0x14/0x30 mm/kasan/common.c:68 unpoison_slab_object mm/kasan/common.c:312 [inline] __kasan_slab_alloc+0x89/0x90 mm/kasan/common.c:338 kasan_slab_alloc include/linux/kasan.h:201 [inline] slab_post_alloc_hook mm/slub.c:3798 [inline] slab_alloc_node mm/slub.c:3845 [inline] kmem_cache_alloc+0x136/0x320 mm/slub.c:3852 kmem_cache_zalloc include/linux/slab.h:739 [inline] gfs2_alloc_bufdata fs/gfs2/trans.c:168 [inline] gfs2_trans_add_data+0x4b3/0x7f0 fs/gfs2/trans.c:209 gfs2_unstuffer_folio fs/gfs2/bmap.c:81 [inline] __gfs2_unstuff_inode fs/gfs2/bmap.c:119 [inline] gfs2_unstuff_dinode+0xad9/0x1460 fs/gfs2/bmap.c:166 gfs2_adjust_quota+0x124/0xb10 fs/gfs2/quota.c:879 do_sync+0xa73/0xd30 fs/gfs2/quota.c:990 gfs2_quota_sync+0x419/0x630 fs/gfs2/quota.c:1370 gfs2_sync_fs+0x44/0xb0 fs/gfs2/super.c:669 sync_filesystem+0x10d/0x290 fs/sync.c:56 generic_shutdown_super+0x7e/0x3d0 fs/super.c:620 kill_block_super+0x3b/0x90 fs/super.c:1675 gfs2_kill_sb+0x360/0x410 fs/gfs2/ops_fstype.c:1804 deactivate_locked_super+0xbe/0x1a0 fs/super.c:472 deactivate_super+0xde/0x100 fs/super.c:505 cleanup_mnt+0x222/0x450 fs/namespace.c:1267 task_work_run+0x14e/0x250 kernel/task_work.c:180 resume_user_mode_work include/linux/resume_user_mode.h:50 [inline] exit_to_user_mode_loop kernel/entry/common.c:114 [inline] exit_to_user_mode_prepare include/linux/entry-common.h:328 [inline] __syscall_exit_to_user_mode_work kernel/entry/common.c:207 [inline] syscall_exit_to_user_mode+0x278/0x2a0 kernel/entry/common.c:218 do_syscall_64+0xdc/0x260 arch/x86/entry/common.c:89 entry_SYSCALL_64_after_hwframe+0x77/0x7f Freed by task 5414: kasan_save_stack+0x33/0x60 mm/kasan/common.c:47 kasan_save_track+0x14/0x30 mm/kasan/common.c:68 kasan_save_free_info+0x3b/0x60 mm/kasan/generic.c:579 poison_slab_object mm/kasan/common.c:240 [inline] __kasan_slab_free+0x11d/0x1a0 mm/kasan/common.c:256 kasan_slab_free include/linux/kasan.h:184 [inline] slab_free_hook mm/slub.c:2106 [inline] slab_free mm/slub.c:4280 [inline] kmem_cache_free+0x12e/0x380 mm/slub.c:4344 trans_drain fs/gfs2/log.c:1032 [inline] gfs2_log_flush+0x14b8/0x29e0 fs/gfs2/log.c:1171 do_sync+0x550/0xd30 fs/gfs2/quota.c:1010 gfs2_quota_sync+0x419/0x630 fs/gfs2/quota.c:1370 gfs2_sync_fs+0x44/0xb0 fs/gfs2/super.c:669 sync_filesystem+0x10d/0x290 fs/sync.c:56 generic_shutdown_super+0x7e/0x3d0 fs/super.c:620 kill_block_super+0x3b/0x90 fs/super.c:1675 gfs2_kill_sb+0x360/0x410 fs/gfs2/ops_fstype.c:1804 deactivate_locked_super+0xbe/0x1a0 fs/super.c:472 deactivate_super+0xde/0x100 fs/super.c:505 cleanup_mnt+0x222/0x450 fs/namespace.c:1267 task_work_run+0x14e/0x250 kernel/task_work.c:180 resume_user_mode_work include/linux/resume_user_mode.h:50 [inline] exit_to_user_mode_loop kernel/entry/common.c:114 [inline] exit_to_user_mode_prepare include/linux/entry-common.h:328 [inline] __syscall_exit_to_user_mode_work kernel/entry/common.c:207 [inline] syscall_exit_to_user_mode+0x278/0x2a0 kernel/entry/common.c:218 do_syscall_64+0xdc/0x260 arch/x86/entry/common.c:89 entry_SYSCALL_64_after_hwframe+0x77/0x7f The buggy address belongs to the object at ffff88802f874150 which belongs to the cache gfs2_bufdata of size 80 The buggy address is located 24 bytes inside of freed 80-byte region [ffff88802f874150, ffff88802f8741a0) The buggy address belongs to the physical page: page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x2f874 flags: 0xfff80000000800(slab|node=0|zone=1|lastcpupid=0xfff) page_type: 0xffffffff() raw: 00fff80000000800 ffff8880192d0a00 dead000000000122 0000000000000000 raw: 0000000000000000 0000000080240024 00000001ffffffff 0000000000000000 page dumped because: kasan: bad access detected page_owner tracks the page as allocated page last allocated via order 0, migratetype Unmovable, gfp_mask 0x112c40(GFP_NOFS|__GFP_NOWARN|__GFP_NORETRY|__GFP_HARDWALL), pid 5414, tgid 5414 (syz-executor.0), ts 76465317912, free_ts 71995243169 set_page_owner include/linux/page_owner.h:32 [inline] post_alloc_hook+0x2d4/0x350 mm/page_alloc.c:1534 prep_new_page mm/page_alloc.c:1541 [inline] get_page_from_freelist+0xa28/0x3780 mm/page_alloc.c:3317 __alloc_pages+0x22b/0x2460 mm/page_alloc.c:4575 __alloc_pages_node include/linux/gfp.h:238 [inline] alloc_pages_node include/linux/gfp.h:261 [inline] alloc_slab_page mm/slub.c:2175 [inline] allocate_slab mm/slub.c:2338 [inline] new_slab+0xcc/0x3a0 mm/slub.c:2391 ___slab_alloc+0x66d/0x1790 mm/slub.c:3525 __slab_alloc.constprop.0+0x56/0xb0 mm/slub.c:3610 __slab_alloc_node mm/slub.c:3663 [inline] slab_alloc_node mm/slub.c:3835 [inline] kmem_cache_alloc+0x2e9/0x320 mm/slub.c:3852 kmem_cache_zalloc include/linux/slab.h:739 [inline] gfs2_alloc_bufdata fs/gfs2/trans.c:168 [inline] gfs2_trans_add_meta+0xade/0xf50 fs/gfs2/trans.c:251 gfs2_alloc_extent fs/gfs2/rgrp.c:2239 [inline] gfs2_alloc_blocks+0x46c/0x19c0 fs/gfs2/rgrp.c:2449 __gfs2_unstuff_inode fs/gfs2/bmap.c:107 [inline] gfs2_unstuff_dinode+0x499/0x1460 fs/gfs2/bmap.c:166 gfs2_adjust_quota+0x124/0xb10 fs/gfs2/quota.c:879 do_sync+0xa73/0xd30 fs/gfs2/quota.c:990 gfs2_quota_sync+0x419/0x630 fs/gfs2/quota.c:1370 gfs2_sync_fs+0x44/0xb0 fs/gfs2/super.c:669 sync_filesystem+0x10d/0x290 fs/sync.c:56 generic_shutdown_super+0x7e/0x3d0 fs/super.c:620 page last free pid 5364 tgid 5364 stack trace: reset_page_owner include/linux/page_owner.h:25 [inline] free_pages_prepare mm/page_alloc.c:1141 [inline] free_unref_page_prepare+0x527/0xb10 mm/page_alloc.c:2347 free_unref_page+0x33/0x3c0 mm/page_alloc.c:2487 qlink_free mm/kasan/quarantine.c:163 [inline] qlist_free_all+0x4e/0x140 mm/kasan/quarantine.c:179 kasan_quarantine_reduce+0x192/0x1e0 mm/kasan/quarantine.c:286 __kasan_slab_alloc+0x69/0x90 mm/kasan/common.c:322 kasan_slab_alloc include/linux/kasan.h:201 [inline] slab_post_alloc_hook mm/slub.c:3798 [inline] slab_alloc_node mm/slub.c:3845 [inline] __do_kmalloc_node mm/slub.c:3965 [inline] __kmalloc+0x1bd/0x440 mm/slub.c:3979 kmalloc include/linux/slab.h:632 [inline] load_elf_phdrs+0x103/0x210 fs/binfmt_elf.c:526 load_elf_binary+0x1fe/0x4e10 fs/binfmt_elf.c:855 search_binary_handler fs/exec.c:1778 [inline] exec_binprm fs/exec.c:1820 [inline] bprm_execve fs/exec.c:1872 [inline] bprm_execve+0x703/0x19b0 fs/exec.c:1848 do_execveat_common.isra.0+0x5cb/0x750 fs/exec.c:1979 do_execve fs/exec.c:2053 [inline] __do_sys_execve fs/exec.c:2129 [inline] __se_sys_execve fs/exec.c:2124 [inline] __x64_sys_execve+0x8c/0xb0 fs/exec.c:2124 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xcf/0x260 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f Memory state around the buggy address: ffff88802f874000: fa fb fb fb fb fb fb fb fb fb fc fc fc fc fa fb ffff88802f874080: fb fb fb fb fb fb fb fb fc fc fc fc fa fb fb fb >ffff88802f874100: fb fb fb fb fb fb fc fc fc fc fa fb fb fb fb fb ^ ffff88802f874180: fb fb fb fb fc fc fc fc fa fb fb fb fb fb fb fb ffff88802f874200: fb fb fc fc fc fc fc fc fc fc fc fc fc fc fc fc ================================================================== Tested on: commit: e8c39d0f Merge tag 'probes-fixes-v6.9-rc3' of git://gi.. git tree: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git console output: https://syzkaller.appspot.com/x/log.txt?x=127ab493180000 kernel config: https://syzkaller.appspot.com/x/.config?x=285be8dd6baeb438 dashboard link: https://syzkaller.appspot.com/bug?extid=3a36aeabd31497d63f6e compiler: gcc (Debian 12.2.0-14) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40 patch: https://syzkaller.appspot.com/x/patch.diff?x=1073ac7d180000 ^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [syzbot] [gfs2?] KASAN: slab-use-after-free Read in gfs2_invalidate_folio 2024-04-11 16:17 [syzbot] [gfs2?] KASAN: slab-use-after-free Read in gfs2_invalidate_folio syzbot ` (2 preceding siblings ...) 2024-04-13 14:48 ` Edward Adam Davis @ 2024-04-14 1:48 ` Edward Adam Davis 2024-04-14 2:04 ` syzbot 2024-04-14 8:56 ` Edward Adam Davis ` (3 subsequent siblings) 7 siblings, 1 reply; 17+ messages in thread From: Edward Adam Davis @ 2024-04-14 1:48 UTC (permalink / raw) To: syzbot+3a36aeabd31497d63f6e; +Cc: linux-kernel, syzkaller-bugs please test uaf in gfs2_invalidate_folio #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git e8c39d0f57f3 diff --git a/fs/gfs2/trans.c b/fs/gfs2/trans.c index 192213c7359a..8d169b389dc1 100644 --- a/fs/gfs2/trans.c +++ b/fs/gfs2/trans.c @@ -202,16 +202,8 @@ void gfs2_trans_add_data(struct gfs2_glock *gl, struct buffer_head *bh) } gfs2_log_lock(sdp); bd = bh->b_private; - if (bd == NULL) { - gfs2_log_unlock(sdp); - unlock_buffer(bh); - if (bh->b_private == NULL) - bd = gfs2_alloc_bufdata(gl, bh); - else - bd = bh->b_private; - lock_buffer(bh); - gfs2_log_lock(sdp); - } + if (bd == NULL) + bd = gfs2_alloc_bufdata(gl, bh); gfs2_assert(sdp, bd->bd_gl == gl); set_bit(TR_TOUCHED, &tr->tr_flags); if (list_empty(&bd->bd_list)) { ^ permalink raw reply related [flat|nested] 17+ messages in thread
* Re: [syzbot] [gfs2?] KASAN: slab-use-after-free Read in gfs2_invalidate_folio 2024-04-14 1:48 ` Edward Adam Davis @ 2024-04-14 2:04 ` syzbot 0 siblings, 0 replies; 17+ messages in thread From: syzbot @ 2024-04-14 2:04 UTC (permalink / raw) To: eadavis, linux-kernel, syzkaller-bugs Hello, syzbot has tested the proposed patch but the reproducer is still triggering an issue: BUG: sleeping function called from invalid context in gfs2_trans_add_data BUG: sleeping function called from invalid context at include/linux/sched/mm.h:315 in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 5417, name: syz-executor.0 preempt_count: 1, expected: 0 RCU nest depth: 0, expected: 0 7 locks held by syz-executor.0/5417: #0: ffff88802f6340e0 (&type->s_umount_key#67){+.+.}-{3:3}, at: __super_lock fs/super.c:56 [inline] #0: ffff88802f6340e0 (&type->s_umount_key#67){+.+.}-{3:3}, at: __super_lock_excl fs/super.c:71 [inline] #0: ffff88802f6340e0 (&type->s_umount_key#67){+.+.}-{3:3}, at: deactivate_super+0xd6/0x100 fs/super.c:504 #1: ffff88803e574b78 (&sdp->sd_quota_sync_mutex){+.+.}-{3:3}, at: gfs2_quota_sync+0x19e/0x630 fs/gfs2/quota.c:1354 #2: ffff888032be8808 (&gfs2_quota_imutex_key){+.+.}-{3:3}, at: inode_lock include/linux/fs.h:795 [inline] #2: ffff888032be8808 (&gfs2_quota_imutex_key){+.+.}-{3:3}, at: do_sync+0x3af/0xd30 fs/gfs2/quota.c:944 #3: ffff88802f634610 (sb_internal#2){.+.+}-{0:0}, at: gfs2_trans_begin+0x74/0x100 fs/gfs2/trans.c:118 #4: ffff88803e575060 (&sdp->sd_log_flush_lock){++++}-{3:3}, at: __gfs2_trans_begin+0x533/0xb80 fs/gfs2/trans.c:87 #5: ffff888032be8ca0 (&ip->i_rw_mutex){++++}-{3:3}, at: gfs2_unstuff_dinode+0x93/0x1460 fs/gfs2/bmap.c:161 #6: ffff88803e574e88 (&sdp->sd_log_lock){+.+.}-{2:2}, at: spin_lock include/linux/spinlock.h:351 [inline] #6: ffff88803e574e88 (&sdp->sd_log_lock){+.+.}-{2:2}, at: gfs2_log_lock fs/gfs2/log.h:32 [inline] #6: ffff88803e574e88 (&sdp->sd_log_lock){+.+.}-{2:2}, at: gfs2_trans_add_data+0x116/0x710 fs/gfs2/trans.c:203 Preemption disabled at: [<0000000000000000>] 0x0 CPU: 0 PID: 5417 Comm: syz-executor.0 Not tainted 6.9.0-rc3-syzkaller-00073-ge8c39d0f57f3-dirty #0 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014 Call Trace: <TASK> __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0x16c/0x1f0 lib/dump_stack.c:114 __might_resched+0x3c0/0x5e0 kernel/sched/core.c:10197 might_alloc include/linux/sched/mm.h:315 [inline] might_alloc include/linux/sched/mm.h:310 [inline] slab_pre_alloc_hook mm/slub.c:3746 [inline] slab_alloc_node mm/slub.c:3827 [inline] kmem_cache_alloc+0x281/0x320 mm/slub.c:3852 kmem_cache_zalloc include/linux/slab.h:739 [inline] gfs2_alloc_bufdata fs/gfs2/trans.c:168 [inline] gfs2_trans_add_data+0x250/0x710 fs/gfs2/trans.c:206 gfs2_unstuffer_folio fs/gfs2/bmap.c:81 [inline] __gfs2_unstuff_inode fs/gfs2/bmap.c:119 [inline] gfs2_unstuff_dinode+0xad9/0x1460 fs/gfs2/bmap.c:166 gfs2_adjust_quota+0x124/0xb10 fs/gfs2/quota.c:879 do_sync+0xa73/0xd30 fs/gfs2/quota.c:990 gfs2_quota_sync+0x419/0x630 fs/gfs2/quota.c:1370 gfs2_sync_fs+0x44/0xb0 fs/gfs2/super.c:669 sync_filesystem+0x10d/0x290 fs/sync.c:56 generic_shutdown_super+0x7e/0x3d0 fs/super.c:620 kill_block_super+0x3b/0x90 fs/super.c:1675 gfs2_kill_sb+0x360/0x410 fs/gfs2/ops_fstype.c:1804 deactivate_locked_super+0xbe/0x1a0 fs/super.c:472 deactivate_super+0xde/0x100 fs/super.c:505 cleanup_mnt+0x222/0x450 fs/namespace.c:1267 task_work_run+0x14e/0x250 kernel/task_work.c:180 resume_user_mode_work include/linux/resume_user_mode.h:50 [inline] exit_to_user_mode_loop kernel/entry/common.c:114 [inline] exit_to_user_mode_prepare include/linux/entry-common.h:328 [inline] __syscall_exit_to_user_mode_work kernel/entry/common.c:207 [inline] syscall_exit_to_user_mode+0x278/0x2a0 kernel/entry/common.c:218 do_syscall_64+0xdc/0x260 arch/x86/entry/common.c:89 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f5a5ca7f197 Code: b0 ff ff ff f7 d8 64 89 01 48 83 c8 ff c3 0f 1f 44 00 00 31 f6 e9 09 00 00 00 66 0f 1f 84 00 00 00 00 00 b8 a6 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 01 c3 48 c7 c2 b0 ff ff ff f7 d8 64 89 02 b8 RSP: 002b:00007fff82f87ad8 EFLAGS: 00000246 ORIG_RAX: 00000000000000a6 RAX: 0000000000000000 RBX: 0000000000000000 RCX: 00007f5a5ca7f197 RDX: 0000000000000000 RSI: 0000000000000009 RDI: 00007fff82f87b90 RBP: 00007fff82f87b90 R08: 0000000000000000 R09: 0000000000000000 R10: 00000000ffffffff R11: 0000000000000246 R12: 00007fff82f88c50 R13: 00007f5a5cac93b9 R14: 000000000001305f R15: 0000000000000001 </TASK> syz-executor.0: attempt to access beyond end of device loop0: rw=1, sector=131324, nr_sectors = 4 limit=32768 gfs2: fsid=syz:syz.0: Error 10 writing to journal, jid=0 ================================================================== BUG: KASAN: slab-use-after-free in list_empty include/linux/list.h:373 [inline] BUG: KASAN: slab-use-after-free in gfs2_discard fs/gfs2/aops.c:617 [inline] BUG: KASAN: slab-use-after-free in gfs2_invalidate_folio+0x718/0x820 fs/gfs2/aops.c:655 Read of size 8 at addr ffff8880274f9168 by task syz-executor.0/5417 CPU: 2 PID: 5417 Comm: syz-executor.0 Tainted: G W 6.9.0-rc3-syzkaller-00073-ge8c39d0f57f3-dirty #0 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014 Call Trace: <TASK> __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:114 print_address_description mm/kasan/report.c:377 [inline] print_report+0xc3/0x620 mm/kasan/report.c:488 kasan_report+0xd9/0x110 mm/kasan/report.c:601 list_empty include/linux/list.h:373 [inline] gfs2_discard fs/gfs2/aops.c:617 [inline] gfs2_invalidate_folio+0x718/0x820 fs/gfs2/aops.c:655 folio_invalidate mm/truncate.c:158 [inline] truncate_cleanup_folio+0x2ac/0x3e0 mm/truncate.c:178 truncate_inode_pages_range+0x271/0xe90 mm/truncate.c:358 gfs2_evict_inode+0x75b/0x1460 fs/gfs2/super.c:1508 evict+0x2ed/0x6c0 fs/inode.c:667 iput_final fs/inode.c:1741 [inline] iput.part.0+0x5a8/0x7f0 fs/inode.c:1767 iput+0x5c/0x80 fs/inode.c:1757 gfs2_put_super+0x2bd/0x760 fs/gfs2/super.c:625 generic_shutdown_super+0x159/0x3d0 fs/super.c:641 kill_block_super+0x3b/0x90 fs/super.c:1675 gfs2_kill_sb+0x360/0x410 fs/gfs2/ops_fstype.c:1804 deactivate_locked_super+0xbe/0x1a0 fs/super.c:472 deactivate_super+0xde/0x100 fs/super.c:505 cleanup_mnt+0x222/0x450 fs/namespace.c:1267 task_work_run+0x14e/0x250 kernel/task_work.c:180 resume_user_mode_work include/linux/resume_user_mode.h:50 [inline] exit_to_user_mode_loop kernel/entry/common.c:114 [inline] exit_to_user_mode_prepare include/linux/entry-common.h:328 [inline] __syscall_exit_to_user_mode_work kernel/entry/common.c:207 [inline] syscall_exit_to_user_mode+0x278/0x2a0 kernel/entry/common.c:218 do_syscall_64+0xdc/0x260 arch/x86/entry/common.c:89 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f5a5ca7f197 Code: b0 ff ff ff f7 d8 64 89 01 48 83 c8 ff c3 0f 1f 44 00 00 31 f6 e9 09 00 00 00 66 0f 1f 84 00 00 00 00 00 b8 a6 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 01 c3 48 c7 c2 b0 ff ff ff f7 d8 64 89 02 b8 RSP: 002b:00007fff82f87ad8 EFLAGS: 00000246 ORIG_RAX: 00000000000000a6 RAX: 0000000000000000 RBX: 0000000000000000 RCX: 00007f5a5ca7f197 RDX: 0000000000000000 RSI: 0000000000000009 RDI: 00007fff82f87b90 RBP: 00007fff82f87b90 R08: 0000000000000000 R09: 0000000000000000 R10: 00000000ffffffff R11: 0000000000000246 R12: 00007fff82f88c50 R13: 00007f5a5cac93b9 R14: 000000000001305f R15: 0000000000000001 </TASK> Allocated by task 5417: kasan_save_stack+0x33/0x60 mm/kasan/common.c:47 kasan_save_track+0x14/0x30 mm/kasan/common.c:68 unpoison_slab_object mm/kasan/common.c:312 [inline] __kasan_slab_alloc+0x89/0x90 mm/kasan/common.c:338 kasan_slab_alloc include/linux/kasan.h:201 [inline] slab_post_alloc_hook mm/slub.c:3798 [inline] slab_alloc_node mm/slub.c:3845 [inline] kmem_cache_alloc+0x136/0x320 mm/slub.c:3852 kmem_cache_zalloc include/linux/slab.h:739 [inline] gfs2_alloc_bufdata fs/gfs2/trans.c:168 [inline] gfs2_trans_add_data+0x250/0x710 fs/gfs2/trans.c:206 gfs2_unstuffer_folio fs/gfs2/bmap.c:81 [inline] __gfs2_unstuff_inode fs/gfs2/bmap.c:119 [inline] gfs2_unstuff_dinode+0xad9/0x1460 fs/gfs2/bmap.c:166 gfs2_adjust_quota+0x124/0xb10 fs/gfs2/quota.c:879 do_sync+0xa73/0xd30 fs/gfs2/quota.c:990 gfs2_quota_sync+0x419/0x630 fs/gfs2/quota.c:1370 gfs2_sync_fs+0x44/0xb0 fs/gfs2/super.c:669 sync_filesystem+0x10d/0x290 fs/sync.c:56 generic_shutdown_super+0x7e/0x3d0 fs/super.c:620 kill_block_super+0x3b/0x90 fs/super.c:1675 gfs2_kill_sb+0x360/0x410 fs/gfs2/ops_fstype.c:1804 deactivate_locked_super+0xbe/0x1a0 fs/super.c:472 deactivate_super+0xde/0x100 fs/super.c:505 cleanup_mnt+0x222/0x450 fs/namespace.c:1267 task_work_run+0x14e/0x250 kernel/task_work.c:180 resume_user_mode_work include/linux/resume_user_mode.h:50 [inline] exit_to_user_mode_loop kernel/entry/common.c:114 [inline] exit_to_user_mode_prepare include/linux/entry-common.h:328 [inline] __syscall_exit_to_user_mode_work kernel/entry/common.c:207 [inline] syscall_exit_to_user_mode+0x278/0x2a0 kernel/entry/common.c:218 do_syscall_64+0xdc/0x260 arch/x86/entry/common.c:89 entry_SYSCALL_64_after_hwframe+0x77/0x7f Freed by task 5417: kasan_save_stack+0x33/0x60 mm/kasan/common.c:47 kasan_save_track+0x14/0x30 mm/kasan/common.c:68 kasan_save_free_info+0x3b/0x60 mm/kasan/generic.c:579 poison_slab_object mm/kasan/common.c:240 [inline] __kasan_slab_free+0x11d/0x1a0 mm/kasan/common.c:256 kasan_slab_free include/linux/kasan.h:184 [inline] slab_free_hook mm/slub.c:2106 [inline] slab_free mm/slub.c:4280 [inline] kmem_cache_free+0x12e/0x380 mm/slub.c:4344 trans_drain fs/gfs2/log.c:1028 [inline] gfs2_log_flush+0x1486/0x29b0 fs/gfs2/log.c:1167 do_sync+0x550/0xd30 fs/gfs2/quota.c:1010 gfs2_quota_sync+0x419/0x630 fs/gfs2/quota.c:1370 gfs2_sync_fs+0x44/0xb0 fs/gfs2/super.c:669 sync_filesystem+0x10d/0x290 fs/sync.c:56 generic_shutdown_super+0x7e/0x3d0 fs/super.c:620 kill_block_super+0x3b/0x90 fs/super.c:1675 gfs2_kill_sb+0x360/0x410 fs/gfs2/ops_fstype.c:1804 deactivate_locked_super+0xbe/0x1a0 fs/super.c:472 deactivate_super+0xde/0x100 fs/super.c:505 cleanup_mnt+0x222/0x450 fs/namespace.c:1267 task_work_run+0x14e/0x250 kernel/task_work.c:180 resume_user_mode_work include/linux/resume_user_mode.h:50 [inline] exit_to_user_mode_loop kernel/entry/common.c:114 [inline] exit_to_user_mode_prepare include/linux/entry-common.h:328 [inline] __syscall_exit_to_user_mode_work kernel/entry/common.c:207 [inline] syscall_exit_to_user_mode+0x278/0x2a0 kernel/entry/common.c:218 do_syscall_64+0xdc/0x260 arch/x86/entry/common.c:89 entry_SYSCALL_64_after_hwframe+0x77/0x7f The buggy address belongs to the object at ffff8880274f9150 which belongs to the cache gfs2_bufdata of size 80 The buggy address is located 24 bytes inside of freed 80-byte region [ffff8880274f9150, ffff8880274f91a0) The buggy address belongs to the physical page: page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x274f9 flags: 0xfff80000000800(slab|node=0|zone=1|lastcpupid=0xfff) page_type: 0xffffffff() raw: 00fff80000000800 ffff88801668ba40 dead000000000122 0000000000000000 raw: 0000000000000000 0000000080240024 00000001ffffffff 0000000000000000 page dumped because: kasan: bad access detected page_owner tracks the page as allocated page last allocated via order 0, migratetype Unmovable, gfp_mask 0x112c40(GFP_NOFS|__GFP_NOWARN|__GFP_NORETRY|__GFP_HARDWALL), pid 5417, tgid 5417 (syz-executor.0), ts 78780685821, free_ts 78721961391 set_page_owner include/linux/page_owner.h:32 [inline] post_alloc_hook+0x2d4/0x350 mm/page_alloc.c:1534 prep_new_page mm/page_alloc.c:1541 [inline] get_page_from_freelist+0xa28/0x3780 mm/page_alloc.c:3317 __alloc_pages+0x22b/0x2460 mm/page_alloc.c:4575 __alloc_pages_node include/linux/gfp.h:238 [inline] alloc_pages_node include/linux/gfp.h:261 [inline] alloc_slab_page mm/slub.c:2175 [inline] allocate_slab mm/slub.c:2338 [inline] new_slab+0xcc/0x3a0 mm/slub.c:2391 ___slab_alloc+0x66d/0x1790 mm/slub.c:3525 __slab_alloc.constprop.0+0x56/0xb0 mm/slub.c:3610 __slab_alloc_node mm/slub.c:3663 [inline] slab_alloc_node mm/slub.c:3835 [inline] kmem_cache_alloc+0x2e9/0x320 mm/slub.c:3852 kmem_cache_zalloc include/linux/slab.h:739 [inline] gfs2_alloc_bufdata fs/gfs2/trans.c:168 [inline] gfs2_trans_add_meta+0xade/0xf50 fs/gfs2/trans.c:243 gfs2_alloc_extent fs/gfs2/rgrp.c:2239 [inline] gfs2_alloc_blocks+0x46c/0x19c0 fs/gfs2/rgrp.c:2449 __gfs2_unstuff_inode fs/gfs2/bmap.c:107 [inline] gfs2_unstuff_dinode+0x499/0x1460 fs/gfs2/bmap.c:166 gfs2_adjust_quota+0x124/0xb10 fs/gfs2/quota.c:879 do_sync+0xa73/0xd30 fs/gfs2/quota.c:990 gfs2_quota_sync+0x419/0x630 fs/gfs2/quota.c:1370 gfs2_sync_fs+0x44/0xb0 fs/gfs2/super.c:669 sync_filesystem+0x10d/0x290 fs/sync.c:56 generic_shutdown_super+0x7e/0x3d0 fs/super.c:620 page last free pid 15 tgid 15 stack trace: reset_page_owner include/linux/page_owner.h:25 [inline] free_pages_prepare mm/page_alloc.c:1141 [inline] free_unref_page_prepare+0x527/0xb10 mm/page_alloc.c:2347 free_unref_page+0x33/0x3c0 mm/page_alloc.c:2487 __folio_put_small mm/swap.c:119 [inline] __folio_put+0x166/0x1f0 mm/swap.c:142 folio_put include/linux/mm.h:1506 [inline] free_page_and_swap_cache+0x1eb/0x250 mm/swap_state.c:305 __tlb_remove_table arch/x86/include/asm/tlb.h:34 [inline] __tlb_remove_table_free mm/mmu_gather.c:227 [inline] tlb_remove_table_rcu+0x89/0xe0 mm/mmu_gather.c:282 rcu_do_batch kernel/rcu/tree.c:2196 [inline] rcu_core+0x828/0x16b0 kernel/rcu/tree.c:2471 __do_softirq+0x218/0x922 kernel/softirq.c:554 Memory state around the buggy address: ffff8880274f9000: fa fb fb fb fb fb fb fb fb fb fc fc fc fc fa fb ffff8880274f9080: fb fb fb fb fb fb fb fb fc fc fc fc fa fb fb fb >ffff8880274f9100: fb fb fb fb fb fb fc fc fc fc fa fb fb fb fb fb ^ ffff8880274f9180: fb fb fb fb fc fc fc fc fc fc fc fc fc fc fc fc ffff8880274f9200: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc ================================================================== Tested on: commit: e8c39d0f Merge tag 'probes-fixes-v6.9-rc3' of git://gi.. git tree: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git console output: https://syzkaller.appspot.com/x/log.txt?x=15912add180000 kernel config: https://syzkaller.appspot.com/x/.config?x=285be8dd6baeb438 dashboard link: https://syzkaller.appspot.com/bug?extid=3a36aeabd31497d63f6e compiler: gcc (Debian 12.2.0-14) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40 patch: https://syzkaller.appspot.com/x/patch.diff?x=13bfbfcb180000 ^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [syzbot] [gfs2?] KASAN: slab-use-after-free Read in gfs2_invalidate_folio 2024-04-11 16:17 [syzbot] [gfs2?] KASAN: slab-use-after-free Read in gfs2_invalidate_folio syzbot ` (3 preceding siblings ...) 2024-04-14 1:48 ` Edward Adam Davis @ 2024-04-14 8:56 ` Edward Adam Davis 2024-04-14 9:13 ` syzbot 2024-04-15 1:13 ` [syzbot] " syzbot ` (2 subsequent siblings) 7 siblings, 1 reply; 17+ messages in thread From: Edward Adam Davis @ 2024-04-14 8:56 UTC (permalink / raw) To: syzbot+3a36aeabd31497d63f6e; +Cc: linux-kernel, syzkaller-bugs please test uaf in gfs2_invalidate_folio #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git e8c39d0f57f3 diff --git a/fs/gfs2/aops.c b/fs/gfs2/aops.c index 974aca9c8ea8..4ae5e73b6992 100644 --- a/fs/gfs2/aops.c +++ b/fs/gfs2/aops.c @@ -613,6 +613,7 @@ static void gfs2_discard(struct gfs2_sbd *sdp, struct buffer_head *bh) gfs2_log_lock(sdp); clear_buffer_dirty(bh); bd = bh->b_private; + printk("bh: %p, bd: %p, %s\n", bh, bd, __func__); if (bd) { if (!list_empty(&bd->bd_list) && !buffer_pinned(bh)) list_del_init(&bd->bd_list); diff --git a/fs/gfs2/bmap.c b/fs/gfs2/bmap.c index aa1626955b2c..d9092692c2fe 100644 --- a/fs/gfs2/bmap.c +++ b/fs/gfs2/bmap.c @@ -78,7 +78,9 @@ static int gfs2_unstuffer_folio(struct gfs2_inode *ip, struct buffer_head *dibh, map_bh(bh, inode->i_sb, block); set_buffer_uptodate(bh); + printk("1.inode: %p, bh: %p, bd: %p, %s\n", ip, bh, bh->b_private, __func__); gfs2_trans_add_data(ip->i_gl, bh); + printk("2.inode: %p, bh: %p, bd: %p, %s\n", ip, bh, bh->b_private, __func__); } else { folio_mark_dirty(folio); gfs2_ordered_add_inode(ip); @@ -105,6 +107,7 @@ static int __gfs2_unstuff_inode(struct gfs2_inode *ip, struct folio *folio) unsigned int n = 1; error = gfs2_alloc_blocks(ip, &block, &n, 0); + printk("1,inode: %p, n: %d, err: %d, %s\n", ip, n, error, __func__); if (error) goto out_brelse; if (isdir) { @@ -117,6 +120,7 @@ static int __gfs2_unstuff_inode(struct gfs2_inode *ip, struct folio *folio) brelse(bh); } else { error = gfs2_unstuffer_folio(ip, dibh, block, folio); + printk("2,inode: %p, n: %d, err: %d, %s\n", ip, n, error, __func__); if (error) goto out_brelse; } diff --git a/fs/gfs2/log.c b/fs/gfs2/log.c index 8cddf955ebc0..6a65e7f5991a 100644 --- a/fs/gfs2/log.c +++ b/fs/gfs2/log.c @@ -1007,6 +1007,7 @@ static void trans_drain(struct gfs2_trans *tr) { struct gfs2_bufdata *bd; struct list_head *head; + struct buffer_head *bh; if (!tr) return; @@ -1022,6 +1023,8 @@ static void trans_drain(struct gfs2_trans *tr) head = &tr->tr_databuf; while (!list_empty(head)) { bd = list_first_entry(head, struct gfs2_bufdata, bd_list); + bh = container_of((void *)bd, struct buffer_head, b_private); + printk("bh: %p, bd: %p, %s\n", bh, bd, __func__); list_del_init(&bd->bd_list); if (!list_empty(&bd->bd_ail_st_list)) gfs2_remove_from_ail(bd); diff --git a/fs/gfs2/quota.c b/fs/gfs2/quota.c index aa9cf0102848..3f18b066cc0d 100644 --- a/fs/gfs2/quota.c +++ b/fs/gfs2/quota.c @@ -1007,6 +1007,7 @@ static int do_sync(unsigned int num_qd, struct gfs2_quota_data **qda) gfs2_glock_dq_uninit(&ghs[qx]); inode_unlock(&ip->i_inode); kfree(ghs); + printk("err: %d, %s\n", error, __func__); gfs2_log_flush(ip->i_gl->gl_name.ln_sbd, ip->i_gl, GFS2_LOG_HEAD_FLUSH_NORMAL | GFS2_LFC_DO_SYNC); if (!error) { diff --git a/fs/gfs2/rgrp.c b/fs/gfs2/rgrp.c index 26d6c1eea559..2b291270817c 100644 --- a/fs/gfs2/rgrp.c +++ b/fs/gfs2/rgrp.c @@ -2236,7 +2236,9 @@ static void gfs2_alloc_extent(const struct gfs2_rbm *rbm, bool dinode, *n = 1; block = gfs2_rbm_to_block(rbm); + printk("1. bh: %p, bd: %p, %s\n", rbm_bi(rbm)->bi_bh, rbm_bi(rbm)->bi_bh->b_private, __func__); gfs2_trans_add_meta(rbm->rgd->rd_gl, rbm_bi(rbm)->bi_bh); + printk("2. bh: %p, bd: %p, %s\n", rbm_bi(rbm)->bi_bh, rbm_bi(rbm)->bi_bh->b_private, __func__); gfs2_setbit(rbm, true, dinode ? GFS2_BLKST_DINODE : GFS2_BLKST_USED); block++; while (*n < elen) { diff --git a/fs/gfs2/trans.c b/fs/gfs2/trans.c index 192213c7359a..d2353d052d34 100644 --- a/fs/gfs2/trans.c +++ b/fs/gfs2/trans.c @@ -205,10 +205,14 @@ void gfs2_trans_add_data(struct gfs2_glock *gl, struct buffer_head *bh) if (bd == NULL) { gfs2_log_unlock(sdp); unlock_buffer(bh); - if (bh->b_private == NULL) + if (bh->b_private == NULL) { bd = gfs2_alloc_bufdata(gl, bh); - else + printk("1bh: %p, bd: %p, %s\n", bh, bd, __func__); + } + else { bd = bh->b_private; + printk("2bh: %p, bd: %p, %s\n", bh, bd, __func__); + } lock_buffer(bh); gfs2_log_lock(sdp); } @@ -247,10 +251,14 @@ void gfs2_trans_add_meta(struct gfs2_glock *gl, struct buffer_head *bh) gfs2_log_unlock(sdp); unlock_buffer(bh); lock_page(bh->b_page); - if (bh->b_private == NULL) + if (bh->b_private == NULL) { bd = gfs2_alloc_bufdata(gl, bh); - else + printk("1bh: %p, bd: %p, %s\n", bh, bd, __func__); + } + else { bd = bh->b_private; + printk("2bh: %p, bd: %p, %s\n", bh, bd, __func__); + } unlock_page(bh->b_page); lock_buffer(bh); gfs2_log_lock(sdp); ^ permalink raw reply related [flat|nested] 17+ messages in thread
* Re: [syzbot] [gfs2?] KASAN: slab-use-after-free Read in gfs2_invalidate_folio 2024-04-14 8:56 ` Edward Adam Davis @ 2024-04-14 9:13 ` syzbot 0 siblings, 0 replies; 17+ messages in thread From: syzbot @ 2024-04-14 9:13 UTC (permalink / raw) To: eadavis, linux-kernel, syzkaller-bugs Hello, syzbot has tested the proposed patch but the reproducer is still triggering an issue: KASAN: slab-use-after-free Read in gfs2_invalidate_folio </TASK> bh: ffff88802f675110, bd: ffff88802f675150, trans_drain bh: ffff88803dd9dbc8, bd: ffff88802f675150, gfs2_discard ================================================================== BUG: KASAN: slab-use-after-free in list_empty include/linux/list.h:373 [inline] BUG: KASAN: slab-use-after-free in gfs2_discard fs/gfs2/aops.c:618 [inline] BUG: KASAN: slab-use-after-free in gfs2_invalidate_folio+0x731/0x840 fs/gfs2/aops.c:656 Read of size 8 at addr ffff88802f675168 by task syz-executor.0/5425 CPU: 0 PID: 5425 Comm: syz-executor.0 Not tainted 6.9.0-rc3-syzkaller-00073-ge8c39d0f57f3-dirty #0 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014 Call Trace: <TASK> __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:114 print_address_description mm/kasan/report.c:377 [inline] print_report+0xc3/0x620 mm/kasan/report.c:488 kasan_report+0xd9/0x110 mm/kasan/report.c:601 list_empty include/linux/list.h:373 [inline] gfs2_discard fs/gfs2/aops.c:618 [inline] gfs2_invalidate_folio+0x731/0x840 fs/gfs2/aops.c:656 folio_invalidate mm/truncate.c:158 [inline] truncate_cleanup_folio+0x2ac/0x3e0 mm/truncate.c:178 truncate_inode_pages_range+0x271/0xe90 mm/truncate.c:358 gfs2_evict_inode+0x75b/0x1460 fs/gfs2/super.c:1508 evict+0x2ed/0x6c0 fs/inode.c:667 iput_final fs/inode.c:1741 [inline] iput.part.0+0x5a8/0x7f0 fs/inode.c:1767 iput+0x5c/0x80 fs/inode.c:1757 gfs2_put_super+0x2bd/0x760 fs/gfs2/super.c:625 generic_shutdown_super+0x159/0x3d0 fs/super.c:641 kill_block_super+0x3b/0x90 fs/super.c:1675 gfs2_kill_sb+0x360/0x410 fs/gfs2/ops_fstype.c:1804 deactivate_locked_super+0xbe/0x1a0 fs/super.c:472 deactivate_super+0xde/0x100 fs/super.c:505 cleanup_mnt+0x222/0x450 fs/namespace.c:1267 task_work_run+0x14e/0x250 kernel/task_work.c:180 resume_user_mode_work include/linux/resume_user_mode.h:50 [inline] exit_to_user_mode_loop kernel/entry/common.c:114 [inline] exit_to_user_mode_prepare include/linux/entry-common.h:328 [inline] __syscall_exit_to_user_mode_work kernel/entry/common.c:207 [inline] syscall_exit_to_user_mode+0x278/0x2a0 kernel/entry/common.c:218 do_syscall_64+0xdc/0x260 arch/x86/entry/common.c:89 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7ff35ce7f197 Code: b0 ff ff ff f7 d8 64 89 01 48 83 c8 ff c3 0f 1f 44 00 00 31 f6 e9 09 00 00 00 66 0f 1f 84 00 00 00 00 00 b8 a6 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 01 c3 48 c7 c2 b0 ff ff ff f7 d8 64 89 02 b8 RSP: 002b:00007fffb7457c68 EFLAGS: 00000246 ORIG_RAX: 00000000000000a6 RAX: 0000000000000000 RBX: 0000000000000000 RCX: 00007ff35ce7f197 RDX: 0000000000000000 RSI: 0000000000000009 RDI: 00007fffb7457d20 RBP: 00007fffb7457d20 R08: 0000000000000000 R09: 0000000000000000 R10: 00000000ffffffff R11: 0000000000000246 R12: 00007fffb7458de0 R13: 00007ff35cec93b9 R14: 000000000001327f R15: 0000000000000001 </TASK> Allocated by task 5425: kasan_save_stack+0x33/0x60 mm/kasan/common.c:47 kasan_save_track+0x14/0x30 mm/kasan/common.c:68 unpoison_slab_object mm/kasan/common.c:312 [inline] __kasan_slab_alloc+0x89/0x90 mm/kasan/common.c:338 kasan_slab_alloc include/linux/kasan.h:201 [inline] slab_post_alloc_hook mm/slub.c:3798 [inline] slab_alloc_node mm/slub.c:3845 [inline] kmem_cache_alloc+0x136/0x320 mm/slub.c:3852 kmem_cache_zalloc include/linux/slab.h:739 [inline] gfs2_alloc_bufdata fs/gfs2/trans.c:168 [inline] gfs2_trans_add_data+0x4d1/0x820 fs/gfs2/trans.c:209 gfs2_unstuffer_folio fs/gfs2/bmap.c:82 [inline] __gfs2_unstuff_inode fs/gfs2/bmap.c:122 [inline] gfs2_unstuff_dinode+0xb30/0x1510 fs/gfs2/bmap.c:170 gfs2_adjust_quota+0x124/0xb10 fs/gfs2/quota.c:879 do_sync+0xa88/0xd40 fs/gfs2/quota.c:990 gfs2_quota_sync+0x419/0x630 fs/gfs2/quota.c:1371 gfs2_sync_fs+0x44/0xb0 fs/gfs2/super.c:669 sync_filesystem+0x10d/0x290 fs/sync.c:56 generic_shutdown_super+0x7e/0x3d0 fs/super.c:620 kill_block_super+0x3b/0x90 fs/super.c:1675 gfs2_kill_sb+0x360/0x410 fs/gfs2/ops_fstype.c:1804 deactivate_locked_super+0xbe/0x1a0 fs/super.c:472 deactivate_super+0xde/0x100 fs/super.c:505 cleanup_mnt+0x222/0x450 fs/namespace.c:1267 task_work_run+0x14e/0x250 kernel/task_work.c:180 resume_user_mode_work include/linux/resume_user_mode.h:50 [inline] exit_to_user_mode_loop kernel/entry/common.c:114 [inline] exit_to_user_mode_prepare include/linux/entry-common.h:328 [inline] __syscall_exit_to_user_mode_work kernel/entry/common.c:207 [inline] syscall_exit_to_user_mode+0x278/0x2a0 kernel/entry/common.c:218 do_syscall_64+0xdc/0x260 arch/x86/entry/common.c:89 entry_SYSCALL_64_after_hwframe+0x77/0x7f Freed by task 5425: kasan_save_stack+0x33/0x60 mm/kasan/common.c:47 kasan_save_track+0x14/0x30 mm/kasan/common.c:68 kasan_save_free_info+0x3b/0x60 mm/kasan/generic.c:579 poison_slab_object mm/kasan/common.c:240 [inline] __kasan_slab_free+0x11d/0x1a0 mm/kasan/common.c:256 kasan_slab_free include/linux/kasan.h:184 [inline] slab_free_hook mm/slub.c:2106 [inline] slab_free mm/slub.c:4280 [inline] kmem_cache_free+0x12e/0x380 mm/slub.c:4344 trans_drain fs/gfs2/log.c:1031 [inline] gfs2_log_flush+0x149f/0x29c0 fs/gfs2/log.c:1170 do_sync+0x565/0xd40 fs/gfs2/quota.c:1011 gfs2_quota_sync+0x419/0x630 fs/gfs2/quota.c:1371 gfs2_sync_fs+0x44/0xb0 fs/gfs2/super.c:669 sync_filesystem+0x10d/0x290 fs/sync.c:56 generic_shutdown_super+0x7e/0x3d0 fs/super.c:620 kill_block_super+0x3b/0x90 fs/super.c:1675 gfs2_kill_sb+0x360/0x410 fs/gfs2/ops_fstype.c:1804 deactivate_locked_super+0xbe/0x1a0 fs/super.c:472 deactivate_super+0xde/0x100 fs/super.c:505 cleanup_mnt+0x222/0x450 fs/namespace.c:1267 task_work_run+0x14e/0x250 kernel/task_work.c:180 resume_user_mode_work include/linux/resume_user_mode.h:50 [inline] exit_to_user_mode_loop kernel/entry/common.c:114 [inline] exit_to_user_mode_prepare include/linux/entry-common.h:328 [inline] __syscall_exit_to_user_mode_work kernel/entry/common.c:207 [inline] syscall_exit_to_user_mode+0x278/0x2a0 kernel/entry/common.c:218 do_syscall_64+0xdc/0x260 arch/x86/entry/common.c:89 entry_SYSCALL_64_after_hwframe+0x77/0x7f The buggy address belongs to the object at ffff88802f675150 which belongs to the cache gfs2_bufdata of size 80 The buggy address is located 24 bytes inside of freed 80-byte region [ffff88802f675150, ffff88802f6751a0) The buggy address belongs to the physical page: page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x2f675 flags: 0xfff80000000800(slab|node=0|zone=1|lastcpupid=0xfff) page_type: 0xffffffff() raw: 00fff80000000800 ffff888015fa28c0 dead000000000122 0000000000000000 raw: 0000000000000000 0000000080240024 00000001ffffffff 0000000000000000 page dumped because: kasan: bad access detected page_owner tracks the page as allocated page last allocated via order 0, migratetype Unmovable, gfp_mask 0x112c40(GFP_NOFS|__GFP_NOWARN|__GFP_NORETRY|__GFP_HARDWALL), pid 5425, tgid 5425 (syz-executor.0), ts 79266814979, free_ts 79245423591 set_page_owner include/linux/page_owner.h:32 [inline] post_alloc_hook+0x2d4/0x350 mm/page_alloc.c:1534 prep_new_page mm/page_alloc.c:1541 [inline] get_page_from_freelist+0xa28/0x3780 mm/page_alloc.c:3317 __alloc_pages+0x22b/0x2460 mm/page_alloc.c:4575 __alloc_pages_node include/linux/gfp.h:238 [inline] alloc_pages_node include/linux/gfp.h:261 [inline] alloc_slab_page mm/slub.c:2175 [inline] allocate_slab mm/slub.c:2338 [inline] new_slab+0xcc/0x3a0 mm/slub.c:2391 ___slab_alloc+0x66d/0x1790 mm/slub.c:3525 __slab_alloc.constprop.0+0x56/0xb0 mm/slub.c:3610 __slab_alloc_node mm/slub.c:3663 [inline] slab_alloc_node mm/slub.c:3835 [inline] kmem_cache_alloc+0x2e9/0x320 mm/slub.c:3852 kmem_cache_zalloc include/linux/slab.h:739 [inline] gfs2_alloc_bufdata fs/gfs2/trans.c:168 [inline] gfs2_trans_add_meta+0xae4/0xf60 fs/gfs2/trans.c:255 gfs2_alloc_extent fs/gfs2/rgrp.c:2240 [inline] gfs2_alloc_blocks+0x4ea/0x1b30 fs/gfs2/rgrp.c:2451 __gfs2_unstuff_inode fs/gfs2/bmap.c:109 [inline] gfs2_unstuff_dinode+0x49e/0x1510 fs/gfs2/bmap.c:170 gfs2_adjust_quota+0x124/0xb10 fs/gfs2/quota.c:879 do_sync+0xa88/0xd40 fs/gfs2/quota.c:990 gfs2_quota_sync+0x419/0x630 fs/gfs2/quota.c:1371 gfs2_sync_fs+0x44/0xb0 fs/gfs2/super.c:669 sync_filesystem+0x10d/0x290 fs/sync.c:56 generic_shutdown_super+0x7e/0x3d0 fs/super.c:620 page last free pid 5425 tgid 5425 stack trace: reset_page_owner include/linux/page_owner.h:25 [inline] free_pages_prepare mm/page_alloc.c:1141 [inline] free_unref_page_prepare+0x527/0xb10 mm/page_alloc.c:2347 free_unref_page+0x33/0x3c0 mm/page_alloc.c:2487 __folio_put_small mm/swap.c:119 [inline] __folio_put+0x166/0x1f0 mm/swap.c:142 folio_put include/linux/mm.h:1506 [inline] free_page_and_swap_cache+0x1eb/0x250 mm/swap_state.c:305 __tlb_remove_table arch/x86/include/asm/tlb.h:34 [inline] __tlb_remove_table_free mm/mmu_gather.c:227 [inline] tlb_remove_table_rcu+0x89/0xe0 mm/mmu_gather.c:282 rcu_do_batch kernel/rcu/tree.c:2196 [inline] rcu_core+0x828/0x16b0 kernel/rcu/tree.c:2471 __do_softirq+0x218/0x922 kernel/softirq.c:554 Memory state around the buggy address: ffff88802f675000: fa fb fb fb fb fb fb fb fb fb fc fc fc fc fa fb ffff88802f675080: fb fb fb fb fb fb fb fb fc fc fc fc fa fb fb fb >ffff88802f675100: fb fb fb fb fb fb fc fc fc fc fa fb fb fb fb fb ^ ffff88802f675180: fb fb fb fb fc fc fc fc fc fc fc fc fc fc fc fc ffff88802f675200: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc ================================================================== Tested on: commit: e8c39d0f Merge tag 'probes-fixes-v6.9-rc3' of git://gi.. git tree: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git console output: https://syzkaller.appspot.com/x/log.txt?x=150cd74d180000 kernel config: https://syzkaller.appspot.com/x/.config?x=285be8dd6baeb438 dashboard link: https://syzkaller.appspot.com/bug?extid=3a36aeabd31497d63f6e compiler: gcc (Debian 12.2.0-14) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40 patch: https://syzkaller.appspot.com/x/patch.diff?x=11383c43180000 ^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [syzbot] [syzbot] [gfs2?] KASAN: slab-use-after-free Read in gfs2_invalidate_folio 2024-04-11 16:17 [syzbot] [gfs2?] KASAN: slab-use-after-free Read in gfs2_invalidate_folio syzbot ` (4 preceding siblings ...) 2024-04-14 8:56 ` Edward Adam Davis @ 2024-04-15 1:13 ` syzbot 2024-04-15 2:04 ` syzbot 2025-06-05 14:20 ` [syzbot] #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git ec7714e4947909190ffb3041a03311a975350fe0 syzbot 7 siblings, 0 replies; 17+ messages in thread From: syzbot @ 2024-04-15 1:13 UTC (permalink / raw) To: linux-kernel For archival purposes, forwarding an incoming command email to linux-kernel@vger.kernel.org. *** Subject: [syzbot] [gfs2?] KASAN: slab-use-after-free Read in gfs2_invalidate_folio Author: lizhi.xu@windriver.com #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git e8c39d0f57f3 diff --git a/fs/gfs2/log.c b/fs/gfs2/log.c index 8cddf955ebc0..71ce8d1576cc 100644 --- a/fs/gfs2/log.c +++ b/fs/gfs2/log.c @@ -1007,6 +1007,7 @@ static void trans_drain(struct gfs2_trans *tr) { struct gfs2_bufdata *bd; struct list_head *head; + struct buffer_head *bh; if (!tr) return; @@ -1022,6 +1023,8 @@ static void trans_drain(struct gfs2_trans *tr) head = &tr->tr_databuf; while (!list_empty(head)) { bd = list_first_entry(head, struct gfs2_bufdata, bd_list); + bh = bd->bd_bh; + bh->b_private = NULL; list_del_init(&bd->bd_list); if (!list_empty(&bd->bd_ail_st_list)) gfs2_remove_from_ail(bd); ^ permalink raw reply related [flat|nested] 17+ messages in thread
* Re: [syzbot] [syzbot] [gfs2?] KASAN: slab-use-after-free Read in gfs2_invalidate_folio 2024-04-11 16:17 [syzbot] [gfs2?] KASAN: slab-use-after-free Read in gfs2_invalidate_folio syzbot ` (5 preceding siblings ...) 2024-04-15 1:13 ` [syzbot] " syzbot @ 2024-04-15 2:04 ` syzbot 2025-06-05 14:20 ` [syzbot] #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git ec7714e4947909190ffb3041a03311a975350fe0 syzbot 7 siblings, 0 replies; 17+ messages in thread From: syzbot @ 2024-04-15 2:04 UTC (permalink / raw) To: linux-kernel For archival purposes, forwarding an incoming command email to linux-kernel@vger.kernel.org. *** Subject: [syzbot] [gfs2?] KASAN: slab-use-after-free Read in gfs2_invalidate_folio Author: lizhi.xu@windriver.com #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git e8c39d0f57f3 diff --git a/fs/gfs2/log.c b/fs/gfs2/log.c index 8cddf955ebc0..8b1d4d6da855 100644 --- a/fs/gfs2/log.c +++ b/fs/gfs2/log.c @@ -1007,6 +1007,7 @@ static void trans_drain(struct gfs2_trans *tr) { struct gfs2_bufdata *bd; struct list_head *head; + struct buffer_head *bh; if (!tr) return; @@ -1022,10 +1023,12 @@ static void trans_drain(struct gfs2_trans *tr) head = &tr->tr_databuf; while (!list_empty(head)) { bd = list_first_entry(head, struct gfs2_bufdata, bd_list); + bh = bd->bd_bh; list_del_init(&bd->bd_list); if (!list_empty(&bd->bd_ail_st_list)) gfs2_remove_from_ail(bd); kmem_cache_free(gfs2_bufdata_cachep, bd); + bh->b_private = NULL; } } ^ permalink raw reply related [flat|nested] 17+ messages in thread
* Re: [syzbot] #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git ec7714e4947909190ffb3041a03311a975350fe0 2024-04-11 16:17 [syzbot] [gfs2?] KASAN: slab-use-after-free Read in gfs2_invalidate_folio syzbot ` (6 preceding siblings ...) 2024-04-15 2:04 ` syzbot @ 2025-06-05 14:20 ` syzbot 7 siblings, 0 replies; 17+ messages in thread From: syzbot @ 2025-06-05 14:20 UTC (permalink / raw) To: linux-kernel, syzkaller-bugs For archival purposes, forwarding an incoming command email to linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com. *** Subject: #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git ec7714e4947909190ffb3041a03311a975350fe0 Author: dmantipov@yandex.ru #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git ec7714e4947909190ffb3041a03311a975350fe0 ^ permalink raw reply [flat|nested] 17+ messages in thread
[parent not found: <20240415011339.1405027-1-lizhi.xu@windriver.com>]
* Re: [syzbot] [gfs2?] KASAN: slab-use-after-free Read in gfs2_invalidate_folio [not found] <20240415011339.1405027-1-lizhi.xu@windriver.com> @ 2024-04-15 1:32 ` syzbot 0 siblings, 0 replies; 17+ messages in thread From: syzbot @ 2024-04-15 1:32 UTC (permalink / raw) To: linux-kernel, lizhi.xu, syzkaller-bugs Hello, syzbot has tested the proposed patch but the reproducer is still triggering an issue: INFO: task hung in block_invalidate_folio INFO: task kworker/2:1H:120 blocked for more than 143 seconds. Not tainted 6.9.0-rc3-syzkaller-00073-ge8c39d0f57f3-dirty #0 "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. task:kworker/2:1H state:D stack:27488 pid:120 tgid:120 ppid:2 flags:0x00004000 Workqueue: glock_workqueue glock_work_func Call Trace: <TASK> context_switch kernel/sched/core.c:5409 [inline] __schedule+0xf15/0x5d00 kernel/sched/core.c:6746 __schedule_loop kernel/sched/core.c:6823 [inline] schedule+0xe7/0x350 kernel/sched/core.c:6838 io_schedule+0xbf/0x130 kernel/sched/core.c:9044 bit_wait_io+0x15/0xe0 kernel/sched/wait_bit.c:209 __wait_on_bit_lock+0x112/0x1a0 kernel/sched/wait_bit.c:90 out_of_line_wait_on_bit_lock+0xda/0x110 kernel/sched/wait_bit.c:117 wait_on_bit_lock_io include/linux/wait_bit.h:208 [inline] __lock_buffer fs/buffer.c:71 [inline] lock_buffer include/linux/buffer_head.h:401 [inline] discard_buffer fs/buffer.c:1565 [inline] block_invalidate_folio+0x54d/0x5e0 fs/buffer.c:1622 folio_invalidate mm/truncate.c:158 [inline] truncate_cleanup_folio+0x2ac/0x3e0 mm/truncate.c:178 truncate_inode_pages_range+0x271/0xe90 mm/truncate.c:358 rgrp_go_inval+0x15b/0x1c0 fs/gfs2/glops.c:236 do_xmote+0x7ca/0xe00 fs/gfs2/glock.c:750 run_queue+0x2fb/0x650 fs/gfs2/glock.c:861 glock_work_func+0x103/0x390 fs/gfs2/glock.c:1093 process_one_work+0x9a9/0x1ac0 kernel/workqueue.c:3254 process_scheduled_works kernel/workqueue.c:3335 [inline] worker_thread+0x6c8/0xf70 kernel/workqueue.c:3416 kthread+0x2c1/0x3a0 kernel/kthread.c:388 ret_from_fork+0x45/0x80 arch/x86/kernel/process.c:147 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244 </TASK> INFO: task syz-executor.0:5412 blocked for more than 143 seconds. Not tainted 6.9.0-rc3-syzkaller-00073-ge8c39d0f57f3-dirty #0 "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. task:syz-executor.0 state:D stack:23600 pid:5412 tgid:5412 ppid:1 flags:0x00004006 Call Trace: <TASK> context_switch kernel/sched/core.c:5409 [inline] __schedule+0xf15/0x5d00 kernel/sched/core.c:6746 __schedule_loop kernel/sched/core.c:6823 [inline] schedule+0xe7/0x350 kernel/sched/core.c:6838 schedule_timeout+0x258/0x2a0 kernel/time/timer.c:2558 do_wait_for_common kernel/sched/completion.c:95 [inline] __wait_for_common+0x3de/0x5f0 kernel/sched/completion.c:116 __flush_work+0x5c4/0xb10 kernel/workqueue.c:4205 gfs2_clear_rgrpd+0x28d/0x330 fs/gfs2/rgrp.c:731 gfs2_put_super+0x4a6/0x760 fs/gfs2/super.c:643 generic_shutdown_super+0x159/0x3d0 fs/super.c:641 kill_block_super+0x3b/0x90 fs/super.c:1675 gfs2_kill_sb+0x360/0x410 fs/gfs2/ops_fstype.c:1804 deactivate_locked_super+0xbe/0x1a0 fs/super.c:472 deactivate_super+0xde/0x100 fs/super.c:505 cleanup_mnt+0x222/0x450 fs/namespace.c:1267 task_work_run+0x14e/0x250 kernel/task_work.c:180 resume_user_mode_work include/linux/resume_user_mode.h:50 [inline] exit_to_user_mode_loop kernel/entry/common.c:114 [inline] exit_to_user_mode_prepare include/linux/entry-common.h:328 [inline] __syscall_exit_to_user_mode_work kernel/entry/common.c:207 [inline] syscall_exit_to_user_mode+0x278/0x2a0 kernel/entry/common.c:218 do_syscall_64+0xdc/0x260 arch/x86/entry/common.c:89 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7fa977e7f197 RSP: 002b:00007fffe3d88ff8 EFLAGS: 00000246 ORIG_RAX: 00000000000000a6 RAX: 0000000000000000 RBX: 0000000000000000 RCX: 00007fa977e7f197 RDX: 0000000000000000 RSI: 0000000000000009 RDI: 00007fffe3d890b0 RBP: 00007fffe3d890b0 R08: 0000000000000000 R09: 0000000000000000 R10: 00000000ffffffff R11: 0000000000000246 R12: 00007fffe3d8a170 R13: 00007fa977ec93b9 R14: 000000000001375d R15: 0000000000000001 </TASK> Showing all locks held in the system: 1 lock held by khungtaskd/39: #0: ffffffff8d7b0e20 (rcu_read_lock){....}-{1:2}, at: rcu_lock_acquire include/linux/rcupdate.h:329 [inline] #0: ffffffff8d7b0e20 (rcu_read_lock){....}-{1:2}, at: rcu_read_lock include/linux/rcupdate.h:781 [inline] #0: ffffffff8d7b0e20 (rcu_read_lock){....}-{1:2}, at: debug_show_all_locks+0x75/0x340 kernel/locking/lockdep.c:6614 2 locks held by kworker/2:1H/120: #0: ffff8880166e9948 ((wq_completion)glock_workqueue){+.+.}-{0:0}, at: process_one_work+0x1296/0x1ac0 kernel/workqueue.c:3229 #1: ffffc9000280fd80 ((work_completion)(&(&gl->gl_work)->work)){+.+.}-{0:0}, at: process_one_work+0x906/0x1ac0 kernel/workqueue.c:3230 2 locks held by getty/4982: #0: ffff8880162d30a0 (&tty->ldisc_sem){++++}-{0:0}, at: tty_ldisc_ref_wait+0x24/0x80 drivers/tty/tty_ldisc.c:243 #1: ffffc90002fce2f0 (&ldata->atomic_read_lock){+.+.}-{3:3}, at: n_tty_read+0xfc8/0x1490 drivers/tty/n_tty.c:2201 1 lock held by syz-executor.0/5412: #0: ffff88801e6960e0 (&type->s_umount_key#67){+.+.}-{3:3}, at: __super_lock fs/super.c:56 [inline] #0: ffff88801e6960e0 (&type->s_umount_key#67){+.+.}-{3:3}, at: __super_lock_excl fs/super.c:71 [inline] #0: ffff88801e6960e0 (&type->s_umount_key#67){+.+.}-{3:3}, at: deactivate_super+0xd6/0x100 fs/super.c:504 ============================================= NMI backtrace for cpu 3 CPU: 3 PID: 39 Comm: khungtaskd Not tainted 6.9.0-rc3-syzkaller-00073-ge8c39d0f57f3-dirty #0 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014 Call Trace: <TASK> __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:114 nmi_cpu_backtrace+0x27b/0x390 lib/nmi_backtrace.c:113 nmi_trigger_cpumask_backtrace+0x29c/0x300 lib/nmi_backtrace.c:62 trigger_all_cpu_backtrace include/linux/nmi.h:160 [inline] check_hung_uninterruptible_tasks kernel/hung_task.c:223 [inline] watchdog+0xf86/0x1240 kernel/hung_task.c:380 kthread+0x2c1/0x3a0 kernel/kthread.c:388 ret_from_fork+0x45/0x80 arch/x86/kernel/process.c:147 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244 </TASK> Sending NMI from CPU 3 to CPUs 0-2: NMI backtrace for cpu 0 CPU: 0 PID: 4668 Comm: klogd Not tainted 6.9.0-rc3-syzkaller-00073-ge8c39d0f57f3-dirty #0 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014 RIP: 0010:kasan_mem_to_shadow include/linux/kasan.h:61 [inline] RIP: 0010:memory_is_poisoned_n mm/kasan/generic.c:129 [inline] RIP: 0010:memory_is_poisoned mm/kasan/generic.c:161 [inline] RIP: 0010:check_region_inline mm/kasan/generic.c:180 [inline] RIP: 0010:kasan_check_range+0x39/0x1a0 mm/kasan/generic.c:189 Code: f8 41 54 44 0f b6 c2 48 01 f0 55 53 0f 82 c6 00 00 00 48 b8 ff ff ff ff ff 7f ff ff 48 39 f8 0f 83 b3 00 00 00 4c 8d 54 37 ff <48> 89 fd 48 b8 00 00 00 00 00 fc ff df 4d 89 d1 48 c1 ed 03 49 c1 RSP: 0018:ffffc9000f4d7b40 EFLAGS: 00000083 RAX: ffff7fffffffffff RBX: ffff8880194a3640 RCX: ffffffff816c57e3 RDX: 0000000000000000 RSI: 0000000000000004 RDI: ffff8880194a3640 RBP: 0000000000000282 R08: 0000000000000000 R09: fffffbfff1f3e002 R10: ffff8880194a3643 R11: 0000000000000000 R12: ffff888024329980 R13: ffff8880194a3640 R14: 1ffff92001e9af86 R15: ffff888024329800 FS: 00007fcbb3e86500(0000) GS:ffff88806b200000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 000055d46340d028 CR3: 000000002c3e8000 CR4: 0000000000350ef0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: <NMI> </NMI> <TASK> instrument_atomic_read include/linux/instrumented.h:68 [inline] atomic_read include/linux/atomic/atomic-instrumented.h:32 [inline] queued_spin_is_locked include/asm-generic/qspinlock.h:57 [inline] debug_spin_unlock kernel/locking/spinlock_debug.c:101 [inline] do_raw_spin_unlock+0x53/0x230 kernel/locking/spinlock_debug.c:141 __raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:150 [inline] _raw_spin_unlock_irqrestore+0x22/0x80 kernel/locking/spinlock.c:194 sock_def_readable+0x160/0x7a0 net/core/sock.c:3354 unix_dgram_sendmsg+0xff6/0x1b10 net/unix/af_unix.c:2159 sock_sendmsg_nosec net/socket.c:730 [inline] __sock_sendmsg net/socket.c:745 [inline] __sys_sendto+0x47f/0x4e0 net/socket.c:2191 __do_sys_sendto net/socket.c:2203 [inline] __se_sys_sendto net/socket.c:2199 [inline] __x64_sys_sendto+0xe0/0x1c0 net/socket.c:2199 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xcf/0x260 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7fcbb3fe89b5 Code: 8b 44 24 08 48 83 c4 28 48 98 c3 48 98 c3 41 89 ca 64 8b 04 25 18 00 00 00 85 c0 75 26 45 31 c9 45 31 c0 b8 2c 00 00 00 0f 05 <48> 3d 00 f0 ff ff 76 7a 48 8b 15 44 c4 0c 00 f7 d8 64 89 02 48 83 RSP: 002b:00007ffd9ba7e3f8 EFLAGS: 00000246 ORIG_RAX: 000000000000002c RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007fcbb3fe89b5 RDX: 0000000000000053 RSI: 000055d46340b020 RDI: 0000000000000003 RBP: 000055d4634042c0 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000004000 R11: 0000000000000246 R12: 0000000000000013 R13: 00007fcbb4176212 R14: 00007ffd9ba7e4f8 R15: 0000000000000000 </TASK> NMI backtrace for cpu 1 skipped: idling at native_safe_halt arch/x86/include/asm/irqflags.h:48 [inline] NMI backtrace for cpu 1 skipped: idling at arch_safe_halt arch/x86/include/asm/irqflags.h:86 [inline] NMI backtrace for cpu 1 skipped: idling at default_idle+0xf/0x20 arch/x86/kernel/process.c:742 NMI backtrace for cpu 2 skipped: idling at native_safe_halt arch/x86/include/asm/irqflags.h:48 [inline] NMI backtrace for cpu 2 skipped: idling at arch_safe_halt arch/x86/include/asm/irqflags.h:86 [inline] NMI backtrace for cpu 2 skipped: idling at default_idle+0xf/0x20 arch/x86/kernel/process.c:742 Tested on: commit: e8c39d0f Merge tag 'probes-fixes-v6.9-rc3' of git://gi.. git tree: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git console output: https://syzkaller.appspot.com/x/log.txt?x=100d81b3180000 kernel config: https://syzkaller.appspot.com/x/.config?x=285be8dd6baeb438 dashboard link: https://syzkaller.appspot.com/bug?extid=3a36aeabd31497d63f6e compiler: gcc (Debian 12.2.0-14) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40 patch: https://syzkaller.appspot.com/x/patch.diff?x=1335deeb180000 ^ permalink raw reply [flat|nested] 17+ messages in thread
[parent not found: <20240415020448.1876694-1-lizhi.xu@windriver.com>]
* Re: [syzbot] [gfs2?] KASAN: slab-use-after-free Read in gfs2_invalidate_folio [not found] <20240415020448.1876694-1-lizhi.xu@windriver.com> @ 2024-04-15 2:23 ` syzbot 0 siblings, 0 replies; 17+ messages in thread From: syzbot @ 2024-04-15 2:23 UTC (permalink / raw) To: linux-kernel, lizhi.xu, syzkaller-bugs Hello, syzbot has tested the proposed patch but the reproducer is still triggering an issue: INFO: task hung in block_invalidate_folio INFO: task kworker/3:1H:1222 blocked for more than 143 seconds. Not tainted 6.9.0-rc3-syzkaller-00073-ge8c39d0f57f3-dirty #0 "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. task:kworker/3:1H state:D stack:26784 pid:1222 tgid:1222 ppid:2 flags:0x00004000 Workqueue: glock_workqueue glock_work_func Call Trace: <TASK> context_switch kernel/sched/core.c:5409 [inline] __schedule+0xf15/0x5d00 kernel/sched/core.c:6746 __schedule_loop kernel/sched/core.c:6823 [inline] schedule+0xe7/0x350 kernel/sched/core.c:6838 io_schedule+0xbf/0x130 kernel/sched/core.c:9044 bit_wait_io+0x15/0xe0 kernel/sched/wait_bit.c:209 __wait_on_bit_lock+0x112/0x1a0 kernel/sched/wait_bit.c:90 out_of_line_wait_on_bit_lock+0xda/0x110 kernel/sched/wait_bit.c:117 wait_on_bit_lock_io include/linux/wait_bit.h:208 [inline] __lock_buffer fs/buffer.c:71 [inline] lock_buffer include/linux/buffer_head.h:401 [inline] discard_buffer fs/buffer.c:1565 [inline] block_invalidate_folio+0x54d/0x5e0 fs/buffer.c:1622 folio_invalidate mm/truncate.c:158 [inline] truncate_cleanup_folio+0x2ac/0x3e0 mm/truncate.c:178 truncate_inode_pages_range+0x271/0xe90 mm/truncate.c:358 rgrp_go_inval+0x15b/0x1c0 fs/gfs2/glops.c:236 do_xmote+0x7ca/0xe00 fs/gfs2/glock.c:750 run_queue+0x2fb/0x650 fs/gfs2/glock.c:861 glock_work_func+0x103/0x390 fs/gfs2/glock.c:1093 process_one_work+0x9a9/0x1ac0 kernel/workqueue.c:3254 process_scheduled_works kernel/workqueue.c:3335 [inline] worker_thread+0x6c8/0xf70 kernel/workqueue.c:3416 kthread+0x2c1/0x3a0 kernel/kthread.c:388 ret_from_fork+0x45/0x80 arch/x86/kernel/process.c:147 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244 </TASK> INFO: task syz-executor.0:5432 blocked for more than 143 seconds. Not tainted 6.9.0-rc3-syzkaller-00073-ge8c39d0f57f3-dirty #0 "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. task:syz-executor.0 state:D stack:23168 pid:5432 tgid:5432 ppid:1 flags:0x00004006 Call Trace: <TASK> context_switch kernel/sched/core.c:5409 [inline] __schedule+0xf15/0x5d00 kernel/sched/core.c:6746 __schedule_loop kernel/sched/core.c:6823 [inline] schedule+0xe7/0x350 kernel/sched/core.c:6838 schedule_timeout+0x258/0x2a0 kernel/time/timer.c:2558 do_wait_for_common kernel/sched/completion.c:95 [inline] __wait_for_common+0x3de/0x5f0 kernel/sched/completion.c:116 __flush_work+0x5c4/0xb10 kernel/workqueue.c:4205 gfs2_clear_rgrpd+0x28d/0x330 fs/gfs2/rgrp.c:731 gfs2_put_super+0x4a6/0x760 fs/gfs2/super.c:643 generic_shutdown_super+0x159/0x3d0 fs/super.c:641 kill_block_super+0x3b/0x90 fs/super.c:1675 gfs2_kill_sb+0x360/0x410 fs/gfs2/ops_fstype.c:1804 deactivate_locked_super+0xbe/0x1a0 fs/super.c:472 deactivate_super+0xde/0x100 fs/super.c:505 cleanup_mnt+0x222/0x450 fs/namespace.c:1267 task_work_run+0x14e/0x250 kernel/task_work.c:180 resume_user_mode_work include/linux/resume_user_mode.h:50 [inline] exit_to_user_mode_loop kernel/entry/common.c:114 [inline] exit_to_user_mode_prepare include/linux/entry-common.h:328 [inline] __syscall_exit_to_user_mode_work kernel/entry/common.c:207 [inline] syscall_exit_to_user_mode+0x278/0x2a0 kernel/entry/common.c:218 do_syscall_64+0xdc/0x260 arch/x86/entry/common.c:89 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f6a83e7f197 RSP: 002b:00007ffc270ab458 EFLAGS: 00000246 ORIG_RAX: 00000000000000a6 RAX: 0000000000000000 RBX: 0000000000000000 RCX: 00007f6a83e7f197 RDX: 0000000000000000 RSI: 0000000000000009 RDI: 00007ffc270ab510 RBP: 00007ffc270ab510 R08: 0000000000000000 R09: 0000000000000000 R10: 00000000ffffffff R11: 0000000000000246 R12: 00007ffc270ac5d0 R13: 00007f6a83ec93b9 R14: 0000000000012eb3 R15: 0000000000000001 </TASK> Showing all locks held in the system: 1 lock held by khungtaskd/39: #0: ffffffff8d7b0e20 (rcu_read_lock){....}-{1:2}, at: rcu_lock_acquire include/linux/rcupdate.h:329 [inline] #0: ffffffff8d7b0e20 (rcu_read_lock){....}-{1:2}, at: rcu_read_lock include/linux/rcupdate.h:781 [inline] #0: ffffffff8d7b0e20 (rcu_read_lock){....}-{1:2}, at: debug_show_all_locks+0x75/0x340 kernel/locking/lockdep.c:6614 2 locks held by kworker/3:1H/1222: #0: ffff88801bf74148 ((wq_completion)glock_workqueue){+.+.}-{0:0}, at: process_one_work+0x1296/0x1ac0 kernel/workqueue.c:3229 #1: ffffc9000956fd80 ((work_completion)(&(&gl->gl_work)->work)){+.+.}-{0:0}, at: process_one_work+0x906/0x1ac0 kernel/workqueue.c:3230 2 locks held by getty/4998: #0: ffff8880162d60a0 (&tty->ldisc_sem){++++}-{0:0}, at: tty_ldisc_ref_wait+0x24/0x80 drivers/tty/tty_ldisc.c:243 #1: ffffc9000009b2f0 (&ldata->atomic_read_lock){+.+.}-{3:3}, at: n_tty_read+0xfc8/0x1490 drivers/tty/n_tty.c:2201 1 lock held by syz-executor.0/5432: #0: ffff88801fc3c0e0 (&type->s_umount_key#67){+.+.}-{3:3}, at: __super_lock fs/super.c:56 [inline] #0: ffff88801fc3c0e0 (&type->s_umount_key#67){+.+.}-{3:3}, at: __super_lock_excl fs/super.c:71 [inline] #0: ffff88801fc3c0e0 (&type->s_umount_key#67){+.+.}-{3:3}, at: deactivate_super+0xd6/0x100 fs/super.c:504 ============================================= NMI backtrace for cpu 2 CPU: 2 PID: 39 Comm: khungtaskd Not tainted 6.9.0-rc3-syzkaller-00073-ge8c39d0f57f3-dirty #0 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014 Call Trace: <TASK> __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:114 nmi_cpu_backtrace+0x27b/0x390 lib/nmi_backtrace.c:113 nmi_trigger_cpumask_backtrace+0x29c/0x300 lib/nmi_backtrace.c:62 trigger_all_cpu_backtrace include/linux/nmi.h:160 [inline] check_hung_uninterruptible_tasks kernel/hung_task.c:223 [inline] watchdog+0xf86/0x1240 kernel/hung_task.c:380 kthread+0x2c1/0x3a0 kernel/kthread.c:388 ret_from_fork+0x45/0x80 arch/x86/kernel/process.c:147 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244 </TASK> Sending NMI from CPU 2 to CPUs 0-1,3: NMI backtrace for cpu 0 skipped: idling at native_safe_halt arch/x86/include/asm/irqflags.h:48 [inline] NMI backtrace for cpu 0 skipped: idling at arch_safe_halt arch/x86/include/asm/irqflags.h:86 [inline] NMI backtrace for cpu 0 skipped: idling at default_idle+0xf/0x20 arch/x86/kernel/process.c:742 NMI backtrace for cpu 1 skipped: idling at native_safe_halt arch/x86/include/asm/irqflags.h:48 [inline] NMI backtrace for cpu 1 skipped: idling at arch_safe_halt arch/x86/include/asm/irqflags.h:86 [inline] NMI backtrace for cpu 1 skipped: idling at default_idle+0xf/0x20 arch/x86/kernel/process.c:742 NMI backtrace for cpu 3 skipped: idling at native_safe_halt arch/x86/include/asm/irqflags.h:48 [inline] NMI backtrace for cpu 3 skipped: idling at arch_safe_halt arch/x86/include/asm/irqflags.h:86 [inline] NMI backtrace for cpu 3 skipped: idling at default_idle+0xf/0x20 arch/x86/kernel/process.c:742 Tested on: commit: e8c39d0f Merge tag 'probes-fixes-v6.9-rc3' of git://gi.. git tree: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git console output: https://syzkaller.appspot.com/x/log.txt?x=173e4c93180000 kernel config: https://syzkaller.appspot.com/x/.config?x=285be8dd6baeb438 dashboard link: https://syzkaller.appspot.com/bug?extid=3a36aeabd31497d63f6e compiler: gcc (Debian 12.2.0-14) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40 patch: https://syzkaller.appspot.com/x/patch.diff?x=12b101eb180000 ^ permalink raw reply [flat|nested] 17+ messages in thread
[parent not found: <a4c7f11b-b503-4525-adb4-2d7263292614@yandex.ru>]
* Re: [syzbot] [gfs2?] KASAN: slab-use-after-free Read in gfs2_invalidate_folio [not found] <a4c7f11b-b503-4525-adb4-2d7263292614@yandex.ru> @ 2025-06-05 14:36 ` syzbot 0 siblings, 0 replies; 17+ messages in thread From: syzbot @ 2025-06-05 14:36 UTC (permalink / raw) To: dmantipov, linux-kernel, syzkaller-bugs Hello, syzbot has tested the proposed patch but the reproducer is still triggering an issue: INFO: task hung in block_invalidate_folio INFO: task kworker/0:1H:152 blocked for more than 143 seconds. Not tainted 6.15.0-syzkaller-12141-gec7714e49479-dirty #0 "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. task:kworker/0:1H state:D stack:28456 pid:152 tgid:152 ppid:2 task_flags:0x4208060 flags:0x00004000 Workqueue: gfs2-glock/syz:syz glock_work_func Call Trace: <TASK> context_switch kernel/sched/core.c:5396 [inline] __schedule+0x116a/0x5de0 kernel/sched/core.c:6785 __schedule_loop kernel/sched/core.c:6863 [inline] schedule+0xe7/0x3a0 kernel/sched/core.c:6878 io_schedule+0xbf/0x130 kernel/sched/core.c:7723 bit_wait_io+0x15/0xe0 kernel/sched/wait_bit.c:247 __wait_on_bit_lock+0x112/0x1a0 kernel/sched/wait_bit.c:90 out_of_line_wait_on_bit_lock+0xd9/0x110 kernel/sched/wait_bit.c:117 wait_on_bit_lock_io include/linux/wait_bit.h:221 [inline] __lock_buffer fs/buffer.c:71 [inline] lock_buffer include/linux/buffer_head.h:434 [inline] discard_buffer fs/buffer.c:1612 [inline] block_invalidate_folio+0x56c/0x600 fs/buffer.c:1669 folio_invalidate mm/truncate.c:140 [inline] truncate_cleanup_folio+0x2f6/0x490 mm/truncate.c:160 truncate_inode_pages_range+0x24e/0xe50 mm/truncate.c:379 rgrp_go_inval+0x1a4/0x210 fs/gfs2/glops.c:239 do_xmote+0x9ca/0xf70 fs/gfs2/glock.c:759 run_queue+0x4c4/0x6d0 fs/gfs2/glock.c:871 glock_work_func+0x127/0x4d0 fs/gfs2/glock.c:1096 process_one_work+0x9cc/0x1b70 kernel/workqueue.c:3238 process_scheduled_works kernel/workqueue.c:3321 [inline] worker_thread+0x6c8/0xf10 kernel/workqueue.c:3402 kthread+0x3c5/0x780 kernel/kthread.c:464 ret_from_fork+0x5d7/0x6f0 arch/x86/kernel/process.c:148 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 </TASK> INFO: task syz-executor.0:5338 blocked for more than 143 seconds. Not tainted 6.15.0-syzkaller-12141-gec7714e49479-dirty #0 "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. task:syz-executor.0 state:D stack:24136 pid:5338 tgid:5338 ppid:1 task_flags:0x400140 flags:0x00004006 Call Trace: <TASK> context_switch kernel/sched/core.c:5396 [inline] __schedule+0x116a/0x5de0 kernel/sched/core.c:6785 __schedule_loop kernel/sched/core.c:6863 [inline] schedule+0xe7/0x3a0 kernel/sched/core.c:6878 schedule_timeout+0x257/0x290 kernel/time/sleep_timeout.c:75 do_wait_for_common kernel/sched/completion.c:95 [inline] __wait_for_common+0x2fc/0x4e0 kernel/sched/completion.c:116 __flush_work+0x7d7/0xcc0 kernel/workqueue.c:4246 gfs2_clear_rgrpd+0x28d/0x330 fs/gfs2/rgrp.c:731 gfs2_put_super+0x4a1/0x780 fs/gfs2/super.c:637 generic_shutdown_super+0x153/0x390 fs/super.c:643 kill_block_super+0x3b/0x90 fs/super.c:1753 gfs2_kill_sb+0x371/0x420 fs/gfs2/ops_fstype.c:1798 deactivate_locked_super+0xc1/0x1a0 fs/super.c:474 deactivate_super fs/super.c:507 [inline] deactivate_super+0xde/0x100 fs/super.c:503 cleanup_mnt+0x225/0x450 fs/namespace.c:1417 task_work_run+0x150/0x240 kernel/task_work.c:227 resume_user_mode_work include/linux/resume_user_mode.h:50 [inline] exit_to_user_mode_loop+0xeb/0x110 kernel/entry/common.c:114 exit_to_user_mode_prepare include/linux/entry-common.h:330 [inline] syscall_exit_to_user_mode_work include/linux/entry-common.h:414 [inline] syscall_exit_to_user_mode include/linux/entry-common.h:449 [inline] do_syscall_64+0x3f6/0x4c0 arch/x86/entry/syscall_64.c:100 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7fd41ae7f197 RSP: 002b:00007ffc04a0b268 EFLAGS: 00000246 ORIG_RAX: 00000000000000a6 RAX: 0000000000000000 RBX: 00007fd41aec93b9 RCX: 00007fd41ae7f197 RDX: 0000000000000000 RSI: 0000000000000009 RDI: 00007ffc04a0b320 RBP: 00007ffc04a0b320 R08: 0000000000000000 R09: 0000000000000000 R10: 00000000ffffffff R11: 0000000000000246 R12: 00007ffc04a0c3e0 R13: 00007fd41aec93b9 R14: 000000000000f02b R15: 0000000000000001 </TASK> Showing all locks held in the system: 1 lock held by khungtaskd/41: #0: ffffffff8dfc0140 (rcu_read_lock){....}-{1:3}, at: rcu_lock_acquire include/linux/rcupdate.h:331 [inline] #0: ffffffff8dfc0140 (rcu_read_lock){....}-{1:3}, at: rcu_read_lock include/linux/rcupdate.h:841 [inline] #0: ffffffff8dfc0140 (rcu_read_lock){....}-{1:3}, at: debug_show_all_locks+0x36/0x1c0 kernel/locking/lockdep.c:6770 2 locks held by kworker/0:1H/152: #0: ffff888021117148 ((wq_completion)gfs2-glock/syz:syz){+.+.}-{0:0}, at: process_one_work+0x12a2/0x1b70 kernel/workqueue.c:3213 #1: ffffc9000305fd10 ((work_completion)(&(&gl->gl_work)->work)){+.+.}-{0:0}, at: process_one_work+0x929/0x1b70 kernel/workqueue.c:3214 2 locks held by getty/5001: #0: ffff88802b11f0a0 (&tty->ldisc_sem){++++}-{0:0}, at: tty_ldisc_ref_wait+0x24/0x80 drivers/tty/tty_ldisc.c:243 #1: ffffc900000db2f0 (&ldata->atomic_read_lock){+.+.}-{4:4}, at: n_tty_read+0x41b/0x14f0 drivers/tty/n_tty.c:2222 1 lock held by syz-executor.0/5338: #0: ffff888023eb40e0 (&type->s_umount_key#66){+.+.}-{4:4}, at: __super_lock fs/super.c:57 [inline] #0: ffff888023eb40e0 (&type->s_umount_key#66){+.+.}-{4:4}, at: __super_lock_excl fs/super.c:72 [inline] #0: ffff888023eb40e0 (&type->s_umount_key#66){+.+.}-{4:4}, at: deactivate_super fs/super.c:506 [inline] #0: ffff888023eb40e0 (&type->s_umount_key#66){+.+.}-{4:4}, at: deactivate_super+0xd6/0x100 fs/super.c:503 ============================================= NMI backtrace for cpu 1 CPU: 1 UID: 0 PID: 41 Comm: khungtaskd Not tainted 6.15.0-syzkaller-12141-gec7714e49479-dirty #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014 Call Trace: <TASK> __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:120 nmi_cpu_backtrace+0x27b/0x390 lib/nmi_backtrace.c:113 nmi_trigger_cpumask_backtrace+0x29c/0x300 lib/nmi_backtrace.c:62 trigger_all_cpu_backtrace include/linux/nmi.h:158 [inline] check_hung_uninterruptible_tasks kernel/hung_task.c:307 [inline] watchdog+0xfd1/0x1760 kernel/hung_task.c:470 kthread+0x3c5/0x780 kernel/kthread.c:464 ret_from_fork+0x5d7/0x6f0 arch/x86/kernel/process.c:148 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 </TASK> Sending NMI from CPU 1 to CPUs 0,2-3: NMI backtrace for cpu 3 CPU: 3 UID: 0 PID: 0 Comm: swapper/3 Not tainted 6.15.0-syzkaller-12141-gec7714e49479-dirty #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014 RIP: 0010:pv_native_safe_halt+0xf/0x20 arch/x86/kernel/paravirt.c:82 Code: 7b 57 02 c3 cc cc cc cc 0f 1f 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa eb 07 0f 00 2d 43 c0 1e 00 fb f4 <e9> 7c fa 02 00 66 2e 0f 1f 84 00 00 00 00 00 66 90 90 90 90 90 90 RSP: 0018:ffffc90000197df8 EFLAGS: 00000282 RAX: 0000000000076507 RBX: 0000000000000003 RCX: ffffffff8b4b4c79 RDX: 0000000000000000 RSI: ffffffff8d925e13 RDI: ffffffff8bd436e0 RBP: ffffed10030d3000 R08: 0000000000000001 R09: ffffed100d66664d R10: ffff88806b33326b R11: 0000000000000001 R12: 0000000000000003 R13: ffff888018698000 R14: ffffffff9037c950 R15: 0000000000000000 FS: 0000000000000000(0000) GS:ffff8880d7e50000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f7be17576e8 CR3: 0000000025b50000 CR4: 0000000000352ef0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: <TASK> arch_safe_halt arch/x86/include/asm/paravirt.h:107 [inline] default_idle+0x13/0x20 arch/x86/kernel/process.c:743 default_idle_call+0x6d/0xb0 kernel/sched/idle.c:117 cpuidle_idle_call kernel/sched/idle.c:185 [inline] do_idle+0x391/0x510 kernel/sched/idle.c:325 cpu_startup_entry+0x4f/0x60 kernel/sched/idle.c:423 start_secondary+0x21d/0x2b0 arch/x86/kernel/smpboot.c:315 common_startup_64+0x13e/0x148 </TASK> NMI backtrace for cpu 0 CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 6.15.0-syzkaller-12141-gec7714e49479-dirty #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014 RIP: 0010:pv_native_safe_halt+0xf/0x20 arch/x86/kernel/paravirt.c:82 Code: 7b 57 02 c3 cc cc cc cc 0f 1f 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa eb 07 0f 00 2d 43 c0 1e 00 fb f4 <e9> 7c fa 02 00 66 2e 0f 1f 84 00 00 00 00 00 66 90 90 90 90 90 90 RSP: 0018:ffffffff8dc07e08 EFLAGS: 00000282 RAX: 00000000000c0e89 RBX: 0000000000000000 RCX: ffffffff8b4b4c79 RDX: 0000000000000000 RSI: ffffffff8d925e13 RDI: ffffffff8bd436e0 RBP: fffffbfff1b92ef0 R08: 0000000000000001 R09: ffffed100d60664d R10: ffff88806b03326b R11: 0000000000000001 R12: 0000000000000000 R13: ffffffff8dc97780 R14: ffffffff9037c950 R15: 0000000000000000 FS: 0000000000000000(0000) GS:ffff8880d7b50000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007fad04958b18 CR3: 000000000dd82000 CR4: 0000000000352ef0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: <TASK> arch_safe_halt arch/x86/include/asm/paravirt.h:107 [inline] default_idle+0x13/0x20 arch/x86/kernel/process.c:743 default_idle_call+0x6d/0xb0 kernel/sched/idle.c:117 cpuidle_idle_call kernel/sched/idle.c:185 [inline] do_idle+0x391/0x510 kernel/sched/idle.c:325 cpu_startup_entry+0x4f/0x60 kernel/sched/idle.c:423 rest_init+0x16b/0x2b0 init/main.c:744 start_kernel+0x3ee/0x4d0 init/main.c:1101 x86_64_start_reservations+0x18/0x30 arch/x86/kernel/head64.c:307 x86_64_start_kernel+0x130/0x190 arch/x86/kernel/head64.c:288 common_startup_64+0x13e/0x148 </TASK> NMI backtrace for cpu 2 CPU: 2 UID: 0 PID: 0 Comm: swapper/2 Not tainted 6.15.0-syzkaller-12141-gec7714e49479-dirty #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014 RIP: 0010:pv_native_safe_halt+0xf/0x20 arch/x86/kernel/paravirt.c:82 Code: 7b 57 02 c3 cc cc cc cc 0f 1f 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa eb 07 0f 00 2d 43 c0 1e 00 fb f4 <e9> 7c fa 02 00 66 2e 0f 1f 84 00 00 00 00 00 66 90 90 90 90 90 90 RSP: 0018:ffffc90000187df8 EFLAGS: 00000282 RAX: 000000000006f871 RBX: 0000000000000002 RCX: ffffffff8b4b4c79 RDX: 0000000000000000 RSI: ffffffff8d925e13 RDI: ffffffff8bd436e0 RBP: ffffed1003051910 R08: 0000000000000001 R09: ffffed100d64664d R10: ffff88806b23326b R11: 0000000000000001 R12: 0000000000000002 R13: ffff88801828c880 R14: ffffffff9037c950 R15: 0000000000000000 FS: 0000000000000000(0000) GS:ffff8880d7d50000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007fad04915480 CR3: 00000000334de000 CR4: 0000000000352ef0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: <TASK> arch_safe_halt arch/x86/include/asm/paravirt.h:107 [inline] default_idle+0x13/0x20 arch/x86/kernel/process.c:743 default_idle_call+0x6d/0xb0 kernel/sched/idle.c:117 cpuidle_idle_call kernel/sched/idle.c:185 [inline] do_idle+0x391/0x510 kernel/sched/idle.c:325 cpu_startup_entry+0x4f/0x60 kernel/sched/idle.c:423 start_secondary+0x21d/0x2b0 arch/x86/kernel/smpboot.c:315 common_startup_64+0x13e/0x148 </TASK> Tested on: commit: ec7714e4 Merge tag 'rust-6.16' of git://git.kernel.org.. git tree: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git console output: https://syzkaller.appspot.com/x/log.txt?x=17a9e570580000 kernel config: https://syzkaller.appspot.com/x/.config?x=6b90d4aac37eea48 dashboard link: https://syzkaller.appspot.com/bug?extid=3a36aeabd31497d63f6e compiler: gcc (Debian 12.2.0-14) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40 patch: https://syzkaller.appspot.com/x/patch.diff?x=14a2d282580000 ^ permalink raw reply [flat|nested] 17+ messages in thread
end of thread, other threads:[~2025-06-05 14:36 UTC | newest] Thread overview: 17+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2024-04-11 16:17 [syzbot] [gfs2?] KASAN: slab-use-after-free Read in gfs2_invalidate_folio syzbot 2024-04-13 5:41 ` Edward Adam Davis 2024-04-13 5:54 ` syzbot 2024-04-13 9:19 ` Edward Adam Davis 2024-04-13 9:36 ` syzbot 2024-04-13 14:48 ` Edward Adam Davis 2024-04-13 15:05 ` syzbot 2024-04-14 1:48 ` Edward Adam Davis 2024-04-14 2:04 ` syzbot 2024-04-14 8:56 ` Edward Adam Davis 2024-04-14 9:13 ` syzbot 2024-04-15 1:13 ` [syzbot] " syzbot 2024-04-15 2:04 ` syzbot 2025-06-05 14:20 ` [syzbot] #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git ec7714e4947909190ffb3041a03311a975350fe0 syzbot [not found] <20240415011339.1405027-1-lizhi.xu@windriver.com> 2024-04-15 1:32 ` [syzbot] [gfs2?] KASAN: slab-use-after-free Read in gfs2_invalidate_folio syzbot [not found] <20240415020448.1876694-1-lizhi.xu@windriver.com> 2024-04-15 2:23 ` syzbot [not found] <a4c7f11b-b503-4525-adb4-2d7263292614@yandex.ru> 2025-06-05 14:36 ` syzbot
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox; as well as URLs for NNTP newsgroup(s).