lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Date:   Tue, 13 Aug 2019 08:28:35 +0800
From:   kernel test robot <rong.a.chen@...el.com>
To:     David Howells <dhowells@...hat.com>
Cc:     LKML <linux-kernel@...r.kernel.org>,
        Linus Torvalds <torvalds@...ux-foundation.org>, lkp@...org
Subject: [keys] f771fde820: kernel_BUG_at_security/keys/keyring.c

FYI, we noticed the following commit (built with gcc-7):

commit: f771fde82051976a6fc0fd570f8b86de4a92124b ("keys: Simplify key description management")
https://kernel.googlesource.com/pub/scm/linux/kernel/git/torvalds/linux.git master

in testcase: trinity
with following parameters:

	runtime: 300s

test-description: Trinity is a linux system call fuzz tester.
test-url: http://codemonkey.org.uk/projects/trinity/


on test machine: qemu-system-x86_64 -enable-kvm -cpu SandyBridge -smp 2 -m 4G

caused below changes (please refer to attached dmesg/kmsg for entire log/backtrace):


+-------------------------------------------------+------------+------------+
|                                                 | 3b8c4a08a4 | f771fde820 |
+-------------------------------------------------+------------+------------+
| boot_successes                                  | 705        | 703        |
| boot_failures                                   | 43         | 32         |
| BUG:kernel_reboot-without-warning_in_test_stage | 12         |            |
| invoked_oom-killer:gfp_mask=0x                  | 20         | 15         |
| Mem-Info                                        | 20         | 15         |
| BUG:kernel_hang_in_boot_stage                   | 10         | 5          |
| RIP:__clear_user                                | 2          |            |
| RIP:copy_user_generic_string                    | 3          | 3          |
| RIP:__get_user_8                                | 1          |            |
| WARNING:at_kernel/rcu/tree.c:#rcu_irq_exit      | 1          |            |
| RIP:rcu_irq_exit                                | 1          |            |
| RIP:native_safe_halt                            | 1          |            |
| WARNING:at_kernel/rcu/tree.c:#rcu_irq_enter     | 1          |            |
| RIP:rcu_irq_enter                               | 1          |            |
| WARNING:at_kernel/rcu/tree.c:#rcu_nmi_enter     | 1          |            |
| RIP:rcu_nmi_enter                               | 1          |            |
| WARNING:at_kernel/rcu/tree.c:#rcu_nmi_exit      | 1          |            |
| RIP:rcu_nmi_exit                                | 1          |            |
| WARNING:at_kernel/rcu/tree.c:#rcu_eqs_exit      | 1          |            |
| RIP:rcu_eqs_exit                                | 1          |            |
| BUG:scheduling_while_atomic                     | 1          |            |
| kernel_BUG_at_security/keys/keyring.c           | 0          | 12         |
| invalid_opcode:#[##]                            | 0          | 12         |
| RIP:__key_link_begin                            | 0          | 12         |
| Kernel_panic-not_syncing:Fatal_exception        | 0          | 12         |
+-------------------------------------------------+------------+------------+


If you fix the issue, kindly add following tag
Reported-by: kernel test robot <rong.a.chen@...el.com>


[   34.431436] kernel BUG at security/keys/keyring.c:1245!
[   34.432866] invalid opcode: 0000 [#1] SMP PTI
[   34.433774] CPU: 1 PID: 2592 Comm: trinity-c7 Not tainted 5.2.0-rc1-00017-gf771fde820519 #1
[   34.435431] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.10.2-1 04/01/2014
[   34.437099] RIP: 0010:__key_link_begin+0x88/0xa0
[   34.438538] Code: 5d 41 5c c3 0f b7 43 76 48 89 df 48 8d 70 04 e8 de dd ff ff 85 c0 79 dd 48 89 ef 89 44 24 04 e8 be f3 0b 00 8b 44 24 04 eb d1 <0f> 0b 0f 0b b8 80 ff ff ff eb c6 66 66 2e 0f 1f 84 00 00 00 00 00
[   34.445962] RSP: 0018:ffffa91140d0fde8 EFLAGS: 00010246
[   34.447932] RAX: 0000000000000000 RBX: ffff99787dd0f401 RCX: ffffa91140d0fe31
[   34.450598] RDX: ffffa91140d0fe28 RSI: ffffa91140d0fe30 RDI: ffff99787dd0f400
[   34.453125] RBP: ffff997895e78a40 R08: 0000000000000000 R09: ffff997907c03980
[   34.455524] R10: ffff99787dd0f400 R11: 00000000d0f9514f R12: 00000000ffffffff
[   34.458190] R13: ffff99793fde86c0 R14: ffffffffffffffec R15: 0000000000000008
[   34.460708] FS:  00007f06eb481740(0000) GS:ffff99793fd00000(0000) knlGS:0000000000000000
[   34.463433] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[   34.465468] CR2: 00007f06e97613cc CR3: 000000007a9fe000 CR4: 00000000000406e0
[   34.467888] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
[   34.470335] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
[   34.472748] Call Trace:
[   34.473852]  key_create_or_update+0x211/0x4b0
[   34.475269]  __x64_sys_add_key+0x101/0x200
[   34.476740]  do_syscall_64+0x5b/0x1e0
[   34.477975]  entry_SYSCALL_64_after_hwframe+0x44/0xa9
[   34.479678] RIP: 0033:0x7f06ead8e1c9
[   34.482108] Code: 01 00 48 81 c4 80 00 00 00 e9 f1 fe ff ff 0f 1f 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d 97 dc 2c 00 f7 d8 64 89 01 48
[   34.490151] RSP: 002b:00007ffd0cc33628 EFLAGS: 00000246 ORIG_RAX: 00000000000000f8
[   34.493640] RAX: ffffffffffffffda RBX: 00000000000000f8 RCX: 00007f06ead8e1c9
[   34.497038] RDX: 00007f06eb342000 RSI: 0000000000400000 RDI: 000000000043c5ae
[   34.500296] RBP: 00007f06eb449000 R08: ffffffffffffffff R09: fffffffffffffffb
[   34.503601] R10: 0000000000000008 R11: 0000000000000246 R12: 00007f06eb449058
[   34.506005] R13: 00007f06eb4816b0 R14: 0000000000000000 R15: 00007f06eb449000
[   34.508374] Modules linked in: af_key mpls_router ip_tunnel vmw_vsock_vmci_transport vsock vmw_vmci ieee802154_socket ieee802154 hidp cmtp kernelcapi bnep rfcomm bluetooth ecdh_generic ecc rfkill can_bcm can_raw can pptp gre l2tp_ppp l2tp_netlink l2tp_core ip6_udp_tunnel udp_tunnel pppoe pppox ppp_generic slhc crypto_user nfnetlink scsi_transport_iscsi dccp_ipv6 atm sctp libcrc32c dccp_ipv4 dccp sr_mod cdrom sg ppdev crct10dif_pclmul crc32_pclmul crc32c_intel ghash_clmulni_intel aesni_intel crypto_simd cryptd glue_helper joydev ata_generic pata_acpi serio_raw pcspkr parport_pc parport floppy bochs_drm ttm drm_kms_helper syscopyarea sysfillrect sysimgblt fb_sys_fops drm ata_piix libata i2c_piix4 ip_tables
[   34.526027] ---[ end trace cfce0f246614c04a ]---


To reproduce:

        # build kernel
	cd linux
	cp config-5.2.0-rc1-00017-gf771fde820519 .config
	make HOSTCC=gcc-7 CC=gcc-7 ARCH=x86_64 olddefconfig prepare modules_prepare bzImage

        git clone https://github.com/intel/lkp-tests.git
        cd lkp-tests
        bin/lkp qemu -k <bzImage> job-script # job-script is attached in this email



Thanks,
Rong Chen


View attachment "config-5.2.0-rc1-00017-gf771fde820519" of type "text/plain" (196481 bytes)

View attachment "job-script" of type "text/plain" (4230 bytes)

Download attachment "dmesg.xz" of type "application/x-xz" (16500 bytes)

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ