lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <CAKXUXMzmfeF9K4SkUcR2i6T+ZqEXvwod4hOzCPfQowMJULy7eg@mail.gmail.com>
Date:   Tue, 11 Oct 2022 12:35:29 +0200
From:   Lukas Bulwahn <lukas.bulwahn@...il.com>
To:     "Liam R. Howlett" <Liam.Howlett@...cle.com>,
        Andrew Morton <akpm@...ux-foundation.org>,
        Linux-MM <linux-mm@...ck.org>,
        kernel-janitors <kernel-janitors@...r.kernel.org>,
        Linux Kernel Mailing List <linux-kernel@...r.kernel.org>,
        maple-tree@...ts.infradead.org,
        Matthew Wilcox <willy@...radead.org>
Subject: Observed recent memory leak in __anon_vma_prepare

Dear Liam, dear Matthew, dear all,

The reproducer for the 'memory leak in __anon_vma_prepare' bug (see
https://elisa-builder-00.iol.unh.edu/syzkaller-next/report?id=3113810b9abd3dfeb581759df93d3171d1a90f18)
is reproducible, it is triggering the memory leak on the current
mainline (commit 60bb8154d1d7), and it was not triggering on v6.0. My
build config is a x86_64 defconfig.

My git bisection showed that:

524e00b36e8c547f5582eef3fb645a8d9fc5e3df is the first bad commit
commit 524e00b36e8c547f5582eef3fb645a8d9fc5e3df
Author: Liam R. Howlett <Liam.Howlett@...cle.com>
Date:   Tue Sep 6 19:48:48 2022 +0000

The git bisect log is below, note that the commits 7fdbd37da5c6,
d0cf3dd47f0d and 0c563f148043 are marked good in the git bisect as
they caused bugs "BUG: Bad rss-counter state mm: ... type:MM_ANONPAGES
val:2". This bug report might have overshadowed the actual issue, and
hence the bug might have been introduced earlier, but was only visible
once the Bad rss-counter state bug disappeared.


git bisect start
# bad: [60bb8154d1d77042a5d43d335a68fdb202302cbe] Merge tag
'xfs-6.1-for-linus' of git://git.kernel.org/pub/scm/fs/xfs/xfs-linux
git bisect bad 60bb8154d1d77042a5d43d335a68fdb202302cbe
# good: [4fe89d07dcc2804c8b562f6c7896a45643d34b2f] Linux 6.0
git bisect good 4fe89d07dcc2804c8b562f6c7896a45643d34b2f
# good: [ff6862c23d2e83d12d1759bf4337d41248fb4dc8] Merge tag
'arm-drivers-6.1' of
git://git.kernel.org/pub/scm/linux/kernel/git/soc/soc
git bisect good ff6862c23d2e83d12d1759bf4337d41248fb4dc8
# good: [e8bc52cb8df80c31c73c726ab58ea9746e9ff734] Merge tag
'driver-core-6.1-rc1' of
git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/driver-core
git bisect good e8bc52cb8df80c31c73c726ab58ea9746e9ff734
# good: [4899a36f91a9f9b06878471096bd143e7253006d] Merge tag
'powerpc-6.1-1' of
git://git.kernel.org/pub/scm/linux/kernel/git/powerpc/linux
git bisect good 4899a36f91a9f9b06878471096bd143e7253006d
# good: [0e0073eb1b60f4ec6faecea034a6772fe1409a88] Merge tag
'hyperv-next-signed-20221009' of
git://git.kernel.org/pub/scm/linux/kernel/git/hyperv/linux
git bisect good 0e0073eb1b60f4ec6faecea034a6772fe1409a88
# bad: [2f3568017268fc34eb0b6b4b3163c0f2e619fde6] kasan: move
kasan_get_*_meta to generic.c
git bisect bad 2f3568017268fc34eb0b6b4b3163c0f2e619fde6
# good: [354ed597442952fb680c9cafc7e4eb8a76f9514c] mm: multi-gen LRU:
kill switch
git bisect good 354ed597442952fb680c9cafc7e4eb8a76f9514c
# bad: [b3541d912a84dc40cabb516f2deeac9ae6fa30da] mm: delete unused
MMF_OOM_VICTIM flag
git bisect bad b3541d912a84dc40cabb516f2deeac9ae6fa30da
# bad: [67e7c16764c3cbf84a57d441fba3474217ac08d6] mm/mmap: change
do_brk_munmap() to use do_mas_align_munmap()
git bisect bad 67e7c16764c3cbf84a57d441fba3474217ac08d6
# good: [e15e06a8392321a19d8ebdbdd7643b7fa8874c17]
lib/test_maple_tree: add testing for maple tree
git bisect good e15e06a8392321a19d8ebdbdd7643b7fa8874c17
# bad: [3b0e81a1cdc9afbddb0543d08e38edb4e33c4baf] mmap: change zeroing
of maple tree in __vma_adjust()
git bisect bad 3b0e81a1cdc9afbddb0543d08e38edb4e33c4baf
# good: [7fdbd37da5c6ff002dc6d15e89a7708c2df4928e] mm/mmap: use the
maple tree for find_vma_prev() instead of the rbtree
git bisect good 7fdbd37da5c6ff002dc6d15e89a7708c2df4928e
# good: [d0cf3dd47f0d5d3bc366063f455215b99b06d62b] damon: convert
__damon_va_three_regions to use the VMA iterator
git bisect good d0cf3dd47f0d5d3bc366063f455215b99b06d62b
# bad: [524e00b36e8c547f5582eef3fb645a8d9fc5e3df] mm: remove rb tree.
git bisect bad 524e00b36e8c547f5582eef3fb645a8d9fc5e3df
# good: [0c563f148043569c81724ee0f9c5bad5a36b115a] proc: remove VMA
rbtree use from nommu
git bisect good 0c563f148043569c81724ee0f9c5bad5a36b115a
# first bad commit: [524e00b36e8c547f5582eef3fb645a8d9fc5e3df] mm:
remove rb tree.


If there is more information needed or other bisection to be done,
please let me know.

Best regards,

Lukas

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ