From mboxrd@z Thu Jan 1 00:00:00 1970 From: Eric Dumazet Subject: Re: KMSAN: uninit-value in __inet6_bind Date: Fri, 14 Dec 2018 07:14:46 -0800 Message-ID: <2b0f7497-7842-e9c3-c7b0-1b2bf2d5ea59@gmail.com> References: <0000000000001568af057cb456a8@google.com> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit Cc: "syzbot+c56449ed3652e6720f30@syzkaller.appspotmail.com" , Ying Xue , "tipc-discussion@lists.sourceforge.net" , David Miller , Alexey Kuznetsov , LKML , Linux Kernel Network Developers , "syzkaller-bugs@googlegroups.com" , Hideaki YOSHIFUJI To: Jon Maloy , Cong Wang , Dmitry Vyukov Return-path: In-Reply-To: Content-Language: en-US Sender: linux-kernel-owner@vger.kernel.org List-Id: netdev.vger.kernel.org On 12/14/2018 07:04 AM, Jon Maloy wrote: > > >> -----Original Message----- >> From: Cong Wang >> Sent: 12-Dec-18 01:17 >> To: Dmitry Vyukov >> Cc: syzbot+c56449ed3652e6720f30@syzkaller.appspotmail.com; Jon Maloy >> ; Ying Xue ; tipc- >> discussion@lists.sourceforge.net; David Miller ; >> Alexey Kuznetsov ; LKML > kernel@vger.kernel.org>; Linux Kernel Network Developers >> ; syzkaller-bugs@googlegroups.com; Hideaki >> YOSHIFUJI >> Subject: Re: KMSAN: uninit-value in __inet6_bind >> >> On Tue, Dec 11, 2018 at 1:04 AM Dmitry Vyukov >> wrote: >>> >>> On Tue, Dec 11, 2018 at 1:41 AM syzbot >>> wrote: >>>> >>>> Hello, >>>> >>>> syzbot found the following crash on: >>>> >>>> HEAD commit: 3f06bda61398 kmsan: remove excessive KMSAN >> wrappers from a.. >>>> git tree: https://github.com/google/kmsan.git/master >>>> console output: >>>> https://syzkaller.appspot.com/x/log.txt?x=13ca6b05400000 >>>> kernel config: >>>> https://syzkaller.appspot.com/x/.config?x=9b071100dcf8e641 >>>> dashboard link: >> https://syzkaller.appspot.com/bug?extid=c56449ed3652e6720f30 >>>> compiler: clang version 8.0.0 (trunk 348261) >>>> >>>> Unfortunately, I don't have any reproducer for this crash yet. >>>> >>>> IMPORTANT: if you fix the bug, please add the following tag to the >> commit: >>>> Reported-by: syzbot+c56449ed3652e6720f30@syzkaller.appspotmail.com >>> >>> This looks like a bug in TIPC, +TIPC maintainers. >>> >> >> It looks more like udp_sock_create6() doesn't initialize >> udp6_addr.sin6_scope_id. > > Unfortunately udp_sock_create6() has no way of knowing this value, because struct udp_port_cfg is missing a field sin6_scope_id. > So this has to be fixed first by adding this field to the struct, and then setting it correctly in all current users. > Do we reasons to believe values other than 0 are needed ?