[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <CAG_fn=XExLPpgq73V-D_NL9Ebp9n965=PeaZPXwfqstN7DRoBQ@mail.gmail.com>
Date: Tue, 22 Oct 2024 10:06:23 +0200
From: Alexander Potapenko <glider@...gle.com>
To: syzbot <syzbot+0ec1e96c2cdf5c0e512a@...kaller.appspotmail.com>,
Peter Zijlstra <peterz@...radead.org>
Cc: audit@...r.kernel.org, eparis@...hat.com, linux-kernel@...r.kernel.org,
paul@...l-moore.com, syzkaller-bugs@...glegroups.com
Subject: Re: [syzbot] [kernel?] KCSAN: assert: race in dequeue_entities
On Fri, Sep 27, 2024 at 4:57 PM syzbot
<syzbot+0ec1e96c2cdf5c0e512a@...kaller.appspotmail.com> wrote:
>
> Hello,
>
> syzbot found the following issue on:
>
> HEAD commit: 075dbe9f6e3c Merge tag 'soc-ep93xx-dt-6.12' of git://git.k..
> git tree: upstream
> console output: https://syzkaller.appspot.com/x/log.txt?x=15f07a80580000
> kernel config: https://syzkaller.appspot.com/x/.config?x=86254f9e0a8f2c98
> dashboard link: https://syzkaller.appspot.com/bug?extid=0ec1e96c2cdf5c0e512a
> compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
>
> Unfortunately, I don't have any reproducer for this issue yet.
>
> Downloadable assets:
> disk image: https://storage.googleapis.com/syzbot-assets/1be80941df60/disk-075dbe9f.raw.xz
> vmlinux: https://storage.googleapis.com/syzbot-assets/494a9ac89c09/vmlinux-075dbe9f.xz
> kernel image: https://storage.googleapis.com/syzbot-assets/919788d8c731/bzImage-075dbe9f.xz
>
> IMPORTANT: if you fix the issue, please add the following tag to the commit:
> Reported-by: syzbot+0ec1e96c2cdf5c0e512a@...kaller.appspotmail.com
>
> audit: type=1400 audit(6022412112.141:243086): avc: denied { read } for pid=2950 comm="syslogd" name="log" dev="sda1" ino=1915 scontext=system_u:system_r:syslogd_t tcontext=system_u:object_r:var_t tclass=lnk_file permissive=0
> audit: type=1400 audit(6022412112.181:243087): avc: denied { read } for pid=2950 comm="syslogd" name="log" dev="sda1" ino=1915 scontext=system_u:system_r:syslogd_t tcontext=system_u:object_r:var_t tclass=lnk_file permissive=0
> ==================================================================
> BUG: KCSAN: assert: race in __block_task kernel/sched/sched.h:2770 [inline]
> BUG: KCSAN: assert: race in dequeue_entities+0x6df/0x760 kernel/sched/fair.c:7177
>
> race at unknown origin, with assert no writes to 0xffff888101764268 of 4 bytes by task 29 on cpu 1:
> __block_task kernel/sched/sched.h:2770 [inline]
> dequeue_entities+0x6df/0x760 kernel/sched/fair.c:7177
> pick_next_entity kernel/sched/fair.c:5627 [inline]
> pick_task_fair kernel/sched/fair.c:8856 [inline]
> pick_next_task_fair+0x7d/0x410 kernel/sched/fair.c:8876
> __pick_next_task kernel/sched/core.c:5955 [inline]
> pick_next_task kernel/sched/core.c:6477 [inline]
> __schedule+0x284/0x940 kernel/sched/core.c:6629
> __schedule_loop kernel/sched/core.c:6752 [inline]
> schedule+0x55/0xc0 kernel/sched/core.c:6767
> kauditd_thread+0x56b/0x650 kernel/audit.c:911
> kthread+0x1d1/0x210 kernel/kthread.c:389
> ret_from_fork+0x4b/0x60 arch/x86/kernel/process.c:147
> ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244
>
> value changed: 0x00000000 -> 0x00000001
>
> Reported by Kernel Concurrency Sanitizer on:
> CPU: 1 UID: 0 PID: 29 Comm: kauditd Not tainted 6.11.0-syzkaller-11558-g075dbe9f6e3c #0
> Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024
> ==================================================================
+PeterZ, who added the KCSAN assertion.
Peter, I am also hitting the same assert on ARM while fuzzing KVM. It
is tricky to reproduce though (we probably need to stress the
scheduler hard enough):
==================================================================
BUG: KCSAN: assert: race in dequeue_entities+0x6d8/0x794
kernel/sched/sched.h:2773
race at unknown origin, with assert no writes to 0xffffff80039f91e8 of
4 bytes by task 27858 on cpu 2:
dequeue_entities+0x6d8/0x794 kernel/sched/sched.h:2773
pick_next_task_fair+0x84/0x394 kernel/sched/fair.c:5627
__schedule+0x218/0x888 kernel/sched/core.c:5968
preempt_schedule_irq+0x3c/0x68 kernel/sched/core.c:7012
arm64_preempt_schedule_irq+0x2c/0x40 arch/arm64/kernel/entry-common.c:301
__el1_irq arch/arm64/kernel/entry-common.c:539 [inline]
el1_interrupt+0x3c/0x54 arch/arm64/kernel/entry-common.c:551
el1h_64_irq_handler+0x18/0x24 arch/arm64/kernel/entry-common.c:556
el1h_64_irq+0x64/0x68 arch/arm64/kernel/entry.S:594
flush_ptrace_hw_breakpoint+0x4f8/0x6b0 arch/arm64/kernel/ptrace.c:221
flush_thread+0x70/0xf4 arch/arm64/kernel/process.c:287
begin_new_exec+0x9ac/0xcdc fs/exec.c:1307
load_elf_binary+0x4d0/0x1330 fs/binfmt_elf.c:996
bprm_execve+0x3d8/0x958 fs/exec.c:1752
kernel_execve+0x550/0x57c fs/exec.c:2012
call_usermodehelper_exec_async+0x18c/0x270 kernel/umh.c:110
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:860
value changed: 0x00000000 -> 0x00000001
Reported by Kernel Concurrency Sanitizer on:
CPU: 2 UID: 0 PID: 27858 Comm: kworker/u16:3 Not tainted
6.12.0-rc4-00001-g517096192323-dirty #84
Hardware name: linux,dummy-virt (DT)
==================================================================
Powered by blists - more mailing lists