lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <CACT4Y+aLMmCvChrrqO34neheMT3Ntd-n0xw1cDY5_0WWvzJvDw@mail.gmail.com>
Date: Thu, 26 Sep 2024 08:37:32 +0200
From: Dmitry Vyukov <dvyukov@...gle.com>
To: kernel test robot <oliver.sang@...el.com>
Cc: oe-lkp@...ts.linux.dev, lkp@...el.com, linux-kernel@...r.kernel.org, 
	Thomas Gleixner <tglx@...utronix.de>, Alexander Potapenko <glider@...gle.com>, Marco Elver <elver@...gle.com>, 
	Andrey Konovalov <andreyknvl@...il.com>, kasan-dev@...glegroups.com
Subject: Re: [linus:master] [kcov] 6cd0dd934b: BUG:TASK_stack_guard_page_was_hit_at#(stack_is#..#)

On Tue, 24 Sept 2024 at 15:45, kernel test robot <oliver.sang@...el.com> wrote:
>
> Hello,
>
> kernel test robot noticed "BUG:TASK_stack_guard_page_was_hit_at#(stack_is#..#)" on:
>
> commit: 6cd0dd934b03d4ee4094ac474108723e2f2ed7d6 ("kcov: Add interrupt handling self test")
> https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git master
>
> [test failed on linus/master      de5cb0dcb74c294ec527eddfe5094acfdb21ff21]
> [test failed on linux-next/master ef545bc03a65438cabe87beb1b9a15b0ffcb6ace]
>
> in testcase: trinity
> version: trinity-static-x86_64-x86_64-1c734c75-1_2020-01-06
> with following parameters:
>
>         runtime: 300s
>         group: group-02
>         nr_groups: 5
>
>
>
> compiler: gcc-12
> test machine: qemu-system-x86_64 -enable-kvm -cpu SandyBridge -smp 2 -m 16G
>
> (please refer to attached dmesg/kmsg for entire log/backtrace)
>
>
> +-------------------------------------------------------+------------+------------+
> |                                                       | 477d81a1c4 | 6cd0dd934b |
> +-------------------------------------------------------+------------+------------+
> | BUG:TASK_stack_guard_page_was_hit_at#(stack_is#..#)   | 0          | 18         |
> | Oops:stack_guard_page:#[##]PREEMPT_KASAN              | 0          | 18         |
> | RIP:error_entry                                       | 0          | 18         |
> +-------------------------------------------------------+------------+------------+
>
>
> If you fix the issue in a separate patch/commit (i.e. not just a new version of
> the same patch/commit), kindly add following tags
> | Reported-by: kernel test robot <oliver.sang@...el.com>
> | Closes: https://lore.kernel.org/oe-lkp/202409242144.863b2b22-oliver.sang@intel.com
>
>
> [   16.984454][    C0] BUG: TASK stack guard page was hit at ffffc90000017ff8 (stack is ffffc90000018000..ffffc90000020000)
> [   16.984489][    C0] Oops: stack guard page: 0000 [#1] PREEMPT KASAN
> [   16.984510][    C0] CPU: 0 UID: 0 PID: 1 Comm: swapper Not tainted 6.11.0-rc2-00002-g6cd0dd934b03 #1 4a678012cbfb14407d2e0b76817d9700747886d7
> [   16.984535][    C0] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.2-debian-1.16.2-1 04/01/2014
> [ 16.984547][ C0] RIP: 0010:error_entry (arch/x86/entry/entry_64.S:1007)
> [ 16.984604][ C0] Code: 0f 01 f8 e9 c2 fe ff ff 0f 1f 40 00 56 48 8b 74 24 08 48 89 7c 24 08 52 51 50 41 50 41 51 41 52 41 53 53 55 41 54 41 55 41 56 <41> 57 56 31 f6 31 d2 31 c9 45 31 c0 45 31 c9 45 31 d2 45 31 db 31
> All code
> ========
>    0:   0f 01 f8                swapgs
>    3:   e9 c2 fe ff ff          jmpq   0xfffffffffffffeca
>    8:   0f 1f 40 00             nopl   0x0(%rax)
>    c:   56                      push   %rsi
>    d:   48 8b 74 24 08          mov    0x8(%rsp),%rsi
>   12:   48 89 7c 24 08          mov    %rdi,0x8(%rsp)
>   17:   52                      push   %rdx
>   18:   51                      push   %rcx
>   19:   50                      push   %rax
>   1a:   41 50                   push   %r8
>   1c:   41 51                   push   %r9
>   1e:   41 52                   push   %r10
>   20:   41 53                   push   %r11
>   22:   53                      push   %rbx
>   23:   55                      push   %rbp
>   24:   41 54                   push   %r12
>   26:   41 55                   push   %r13
>   28:   41 56                   push   %r14
>   2a:*  41 57                   push   %r15             <-- trapping instruction
>   2c:   56                      push   %rsi
>   2d:   31 f6                   xor    %esi,%esi
>   2f:   31 d2                   xor    %edx,%edx
>   31:   31 c9                   xor    %ecx,%ecx
>   33:   45 31 c0                xor    %r8d,%r8d
>   36:   45 31 c9                xor    %r9d,%r9d
>   39:   45 31 d2                xor    %r10d,%r10d
>   3c:   45 31 db                xor    %r11d,%r11d
>   3f:   31                      .byte 0x31
>
> Code starting with the faulting instruction
> ===========================================
>    0:   41 57                   push   %r15
>    2:   56                      push   %rsi
>    3:   31 f6                   xor    %esi,%esi
>    5:   31 d2                   xor    %edx,%edx
>    7:   31 c9                   xor    %ecx,%ecx
>    9:   45 31 c0                xor    %r8d,%r8d
>    c:   45 31 c9                xor    %r9d,%r9d
>    f:   45 31 d2                xor    %r10d,%r10d
>   12:   45 31 db                xor    %r11d,%r11d
>   15:   31                      .byte 0x31
> [   16.984624][    C0] RSP: 0000:ffffc90000018000 EFLAGS: 00010046
> [   16.984642][    C0] RAX: 0000000000000002 RBX: ffffc900000180d8 RCX: 0000000000000000
> [   16.984657][    C0] RDX: 0000000000000000 RSI: ffffffff86400af9 RDI: 0000000000000000
> [   16.984671][    C0] RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000
> [   16.984683][    C0] R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000000
> [   16.984697][    C0] R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000
> [   16.984710][    C0] FS:  0000000000000000(0000) GS:ffffffff88355000(0000) knlGS:0000000000000000
> [   16.984733][    C0] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
> [   16.984749][    C0] CR2: ffffc90000017ff8 CR3: 0000000008307000 CR4: 00000000000406b0
> [   16.984765][    C0] Call Trace:
> [   16.984775][    C0]  <#DF>
> [ 16.984785][ C0] ? show_regs (arch/x86/kernel/dumpstack.c:479)
> [ 16.984815][ C0] ? die (arch/x86/kernel/dumpstack.c:421 arch/x86/kernel/dumpstack.c:434 arch/x86/kernel/dumpstack.c:447)
> [ 16.984843][ C0] ? handle_stack_overflow (arch/x86/kernel/traps.c:329)
> [ 16.984865][ C0] ? get_stack_info_noinstr (arch/x86/kernel/dumpstack_64.c:173)
> [ 16.984899][ C0] ? exc_double_fault (arch/x86/kernel/traps.c:380)
> [ 16.984931][ C0] ? asm_exc_double_fault (arch/x86/include/asm/idtentry.h:668)
> [ 16.984955][ C0] ? asm_exc_page_fault (arch/x86/include/asm/idtentry.h:623)
> [ 16.984974][ C0] ? error_entry (arch/x86/entry/entry_64.S:1007)
> [   16.984993][    C0]  </#DF>
> [   16.984999][    C0]  <TASK>
> [ 16.985009][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.985040][ C0] ? __sanitizer_cov_trace_pc (kernel/kcov.c:213)
> [ 16.985066][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.985093][ C0] ? exc_page_fault (arch/x86/mm/fault.c:51 arch/x86/mm/fault.c:1474 arch/x86/mm/fault.c:1539)
> [ 16.985136][ C0] ? asm_exc_page_fault (arch/x86/include/asm/idtentry.h:623)
> [ 16.985154][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.985177][ C0] ? __sanitizer_cov_trace_pc (kernel/kcov.c:213)
> [ 16.985196][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.985218][ C0] ? exc_page_fault (arch/x86/mm/fault.c:51 arch/x86/mm/fault.c:1474 arch/x86/mm/fault.c:1539)
> [ 16.985244][ C0] ? asm_exc_page_fault (arch/x86/include/asm/idtentry.h:623)
> [ 16.985264][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.985290][ C0] ? __sanitizer_cov_trace_pc (kernel/kcov.c:213)
> [ 16.985311][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.985336][ C0] ? exc_page_fault (arch/x86/mm/fault.c:51 arch/x86/mm/fault.c:1474 arch/x86/mm/fault.c:1539)
> [ 16.985363][ C0] ? asm_exc_page_fault (arch/x86/include/asm/idtentry.h:623)
> [ 16.985384][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.985409][ C0] ? __sanitizer_cov_trace_pc (kernel/kcov.c:213)
> [ 16.985430][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.985455][ C0] ? exc_page_fault (arch/x86/mm/fault.c:51 arch/x86/mm/fault.c:1474 arch/x86/mm/fault.c:1539)
> [ 16.985484][ C0] ? asm_exc_page_fault (arch/x86/include/asm/idtentry.h:623)
> [ 16.985505][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.985532][ C0] ? __sanitizer_cov_trace_pc (kernel/kcov.c:213)
> [ 16.985555][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.985579][ C0] ? exc_page_fault (arch/x86/mm/fault.c:51 arch/x86/mm/fault.c:1474 arch/x86/mm/fault.c:1539)
> [ 16.985607][ C0] ? asm_exc_page_fault (arch/x86/include/asm/idtentry.h:623)
> [ 16.985628][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.985655][ C0] ? __sanitizer_cov_trace_pc (kernel/kcov.c:213)
> [ 16.985676][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.985701][ C0] ? exc_page_fault (arch/x86/mm/fault.c:51 arch/x86/mm/fault.c:1474 arch/x86/mm/fault.c:1539)
> [ 16.985725][ C0] ? asm_exc_page_fault (arch/x86/include/asm/idtentry.h:623)
> [ 16.985747][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.985772][ C0] ? __sanitizer_cov_trace_pc (kernel/kcov.c:213)
> [ 16.985794][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.985818][ C0] ? exc_page_fault (arch/x86/mm/fault.c:51 arch/x86/mm/fault.c:1474 arch/x86/mm/fault.c:1539)
> [ 16.985847][ C0] ? asm_exc_page_fault (arch/x86/include/asm/idtentry.h:623)
> [ 16.985869][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.985896][ C0] ? __sanitizer_cov_trace_pc (kernel/kcov.c:213)
> [ 16.985919][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.985944][ C0] ? exc_page_fault (arch/x86/mm/fault.c:51 arch/x86/mm/fault.c:1474 arch/x86/mm/fault.c:1539)
> [ 16.985972][ C0] ? asm_exc_page_fault (arch/x86/include/asm/idtentry.h:623)
> [ 16.985992][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.986017][ C0] ? __sanitizer_cov_trace_pc (kernel/kcov.c:213)
> [ 16.986038][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.986063][ C0] ? exc_page_fault (arch/x86/mm/fault.c:51 arch/x86/mm/fault.c:1474 arch/x86/mm/fault.c:1539)
> [ 16.986093][ C0] ? asm_exc_page_fault (arch/x86/include/asm/idtentry.h:623)
> [ 16.986116][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.986143][ C0] ? __sanitizer_cov_trace_pc (kernel/kcov.c:213)
> [ 16.986165][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.986188][ C0] ? exc_page_fault (arch/x86/mm/fault.c:51 arch/x86/mm/fault.c:1474 arch/x86/mm/fault.c:1539)
> [ 16.986217][ C0] ? asm_exc_page_fault (arch/x86/include/asm/idtentry.h:623)
> [ 16.986239][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.986265][ C0] ? __sanitizer_cov_trace_pc (kernel/kcov.c:213)
> [ 16.986286][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.986310][ C0] ? exc_page_fault (arch/x86/mm/fault.c:51 arch/x86/mm/fault.c:1474 arch/x86/mm/fault.c:1539)
> [ 16.986338][ C0] ? asm_exc_page_fault (arch/x86/include/asm/idtentry.h:623)
> [ 16.986359][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.986385][ C0] ? __sanitizer_cov_trace_pc (kernel/kcov.c:213)
> [ 16.986408][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.986434][ C0] ? exc_page_fault (arch/x86/mm/fault.c:51 arch/x86/mm/fault.c:1474 arch/x86/mm/fault.c:1539)
> [ 16.986464][ C0] ? asm_exc_page_fault (arch/x86/include/asm/idtentry.h:623)
> [ 16.986486][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.986511][ C0] ? __sanitizer_cov_trace_pc (kernel/kcov.c:213)
> [ 16.986532][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.986557][ C0] ? exc_page_fault (arch/x86/mm/fault.c:51 arch/x86/mm/fault.c:1474 arch/x86/mm/fault.c:1539)
> [ 16.986585][ C0] ? asm_exc_page_fault (arch/x86/include/asm/idtentry.h:623)
> [ 16.986606][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.986631][ C0] ? __sanitizer_cov_trace_pc (kernel/kcov.c:213)
> [ 16.986652][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.986676][ C0] ? exc_page_fault (arch/x86/mm/fault.c:51 arch/x86/mm/fault.c:1474 arch/x86/mm/fault.c:1539)
> [ 16.986704][ C0] ? asm_exc_page_fault (arch/x86/include/asm/idtentry.h:623)
> [ 16.986725][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.986751][ C0] ? __sanitizer_cov_trace_pc (kernel/kcov.c:213)
> [ 16.986772][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.986796][ C0] ? exc_page_fault (arch/x86/mm/fault.c:51 arch/x86/mm/fault.c:1474 arch/x86/mm/fault.c:1539)
> [ 16.986824][ C0] ? asm_exc_page_fault (arch/x86/include/asm/idtentry.h:623)
> [ 16.986846][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.986872][ C0] ? __sanitizer_cov_trace_pc (kernel/kcov.c:213)
> [ 16.986893][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
> [ 16.986918][ C0] ? exc_page_fault (arch/x86/mm/fault.c:51 arch/x86/mm/fault.c:1474 arch/x86/mm/fault.c:1539)
> [ 16.986948][ C0] ? asm_exc_page_fault (arch/x86/include/asm/idtentry.h:623)
> [ 16.986968][ C0] ? is_kmmio_active (include/linux/mmiotrace.h:58)
>
>
> The kernel config and materials to reproduce are available at:
> https://download.01.org/0day-ci/archive/20240924/202409242144.863b2b22-oliver.sang@intel.com

FTR this is being debugged in:
https://lore.kernel.org/all/66eb52dc.050a0220.92ef1.0006.GAE@google.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ