From: poma <pomidorabelisima@gmail.com>
To: Jan Kara <jack@suse.cz>,
Richard Weinberger <richard.weinberger@gmail.com>
Cc: Mailing-List fedora-kernel <kernel@lists.fedoraproject.org>,
Linux Kernel list <linux-kernel@vger.kernel.org>,
Josh Boyer <jwboyer@redhat.com>,
"Justin M. Forbes" <jforbes@redhat.com>,
Stanislaw Gruszka <sgruszka@redhat.com>,
Jiri Kosina <jkosina@suse.cz>, Dave Jones <davej@redhat.com>,
Christoph Hellwig <hch@lst.de>,
eparis@parisplace.org, Al Viro <viro@zeniv.linux.org.uk>,
Hugh Dickins <hughd@google.com>,
Andrew Morton <akpm@linux-foundation.org>,
Linus Torvalds <torvalds@linux-foundation.org>
Subject: Re: BUG: unable to handle kernel paging request at 0000000100000003 - Oops: 0000 [#1] SMP
Date: Mon, 03 Mar 2014 20:13:00 +0100 [thread overview]
Message-ID: <5314D43C.8030203@gmail.com> (raw)
In-Reply-To: <20140221154823.GA21405@quack.suse.cz>
On 21.02.2014 16:48, Jan Kara wrote:
> On Fri 21-02-14 14:08:03, Richard Weinberger wrote:
>> On Fri, Feb 21, 2014 at 12:40 PM, poma <pomidorabelisima@gmail.com> wrote:
>>>
>>> Affected kernels - 3.14.0-0.rc3*:
>>>
>>> - 3.14.0-0.rc3.git0.1
>>> http://koji.fedoraproject.org/koji/buildinfo?buildID=498711
>>>
>>> - 3.14.0-0.rc3.git0.7 based on 3.14.0-0.rc3.git0.1
>>>
>>> - 3.14.0-0.rc3.git2.1
>>> http://koji.fedoraproject.org/koji/buildinfo?buildID=499061
>>>
>>> - 3.14.0-0.rc3.git5.1
>>> http://koji.fedoraproject.org/koji/buildinfo?buildID=499636
>>>
>>> Memtest86+ 4.20 - OK
>>> http://goo.gl/1nm1nV
>>>
>>> RHBZ
>>> https://bugzilla.redhat.com/show_bug.cgi?id=1067919
>>>
>>> messages-Oops-es-3.14.0-0.rc3
>>> https://bugzilla.redhat.com/attachment.cgi?id=865926
>>
>> Maybe commits 7053aee26a3548ebaba046ae2e52396ccf56ac6c (fsnotify: do
>> not share events between notification groups)
>> and 85816794240b9659e66e4d9b0df7c6e814e5f603 (fanotify: Fix use after
>> free for permission events) introduced this regression.
> So the immediate problem seems to be that event->tgid is 0xffffffff
> instead of a pointer. I don't see how this could be use after free and we
> unconditionally initialize event->tgid to something sensible. Hum, but if
> it is an overflow event, we are in a trouble since that doesn't have ->tgid
> field at all so we read random crap that happens to be beyond the event
> structure. Actually there seem to be more problems in the handling of
> overflow event so I better add that to my testing (both for fanotify and
> inotify). I'll work on the fix. Thanks for report!
>
> Honza
>
The test was successfully completed with the '3.14-rc5'.
Thanks guys, Jan for the patchwork!
poma
next prev parent reply other threads:[~2014-03-03 19:13 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-02-21 11:40 BUG: unable to handle kernel paging request at 0000000100000003 - Oops: 0000 [#1] SMP poma
2014-02-21 13:08 ` Richard Weinberger
2014-02-21 15:48 ` Jan Kara
2014-03-03 19:13 ` poma [this message]
2014-03-03 20:17 ` Jan Kara
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=5314D43C.8030203@gmail.com \
--to=pomidorabelisima@gmail.com \
--cc=akpm@linux-foundation.org \
--cc=davej@redhat.com \
--cc=eparis@parisplace.org \
--cc=hch@lst.de \
--cc=hughd@google.com \
--cc=jack@suse.cz \
--cc=jforbes@redhat.com \
--cc=jkosina@suse.cz \
--cc=jwboyer@redhat.com \
--cc=kernel@lists.fedoraproject.org \
--cc=linux-kernel@vger.kernel.org \
--cc=richard.weinberger@gmail.com \
--cc=sgruszka@redhat.com \
--cc=torvalds@linux-foundation.org \
--cc=viro@zeniv.linux.org.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox