lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <6795046a.050a0220.3ab881.0012.GAE@google.com>
Date: Sat, 25 Jan 2025 07:34:02 -0800
From: syzbot <syzbot+2875f6362e0214a32381@...kaller.appspotmail.com>
To: aha310510@...il.com, linux-kernel@...r.kernel.org, 
	syzkaller-bugs@...glegroups.com
Subject: Re: [syzbot] [bcachefs?] general protection fault in bch2_subvolume_delete

Hello,

syzbot tried to test the proposed patch but the build/boot failed:

414626][ T3078]  ? __pfx_dump_stack_lvl+0x10/0x10
[   85.414638][ T3078]  ? __pfx__printk+0x10/0x10
[   85.414655][ T3078]  print_circular_bug+0x13a/0x1b0
[   85.414666][ T3078]  check_noncircular+0x36a/0x4a0
[   85.414677][ T3078]  ? __pfx_check_noncircular+0x10/0x10
[   85.414687][ T3078]  ? lockdep_lock+0x123/0x2b0
[   85.414703][ T3078]  validate_chain+0x18ef/0x5920
[   85.414717][ T3078]  ? __pfx_validate_chain+0x10/0x10
[   85.414729][ T3078]  ? mark_lock+0x9a/0x360
[   85.414743][ T3078]  ? __lock_acquire+0x1397/0x2100
[   85.414753][ T3078]  ? mark_lock+0x9a/0x360
[   85.414767][ T3078]  __lock_acquire+0x1397/0x2100
[   85.414782][ T3078]  lock_acquire+0x1ed/0x550
[   85.414795][ T3078]  ? unregister_netdevice_many_notify+0xac2/0x2030
[   85.414812][ T3078]  ? __pfx_lock_acquire+0x10/0x10
[   85.414825][ T3078]  ? __pfx___might_resched+0x10/0x10
[   85.414839][ T3078]  ? finish_wait+0xd4/0x1e0
[   85.414853][ T3078]  __mutex_lock+0x19c/0x1010
[   85.414866][ T3078]  ? unregister_netdevice_many_notify+0xac2/0x2030
[   85.414882][ T3078]  ? unregister_netdevice_many_notify+0xac2/0x2030
[   85.414905][ T3078]  ? __pfx___mutex_lock+0x10/0x10
[   85.414917][ T3078]  ? __pfx___might_resched+0x10/0x10
[   85.414929][ T3078]  ? unregister_netdevice_many_notify+0x9fa/0x2030
[   85.414944][ T3078]  ? unregister_netdevice_many_notify+0x9fa/0x2030
[   85.414959][ T3078]  unregister_netdevice_many_notify+0xac2/0x2030
[   85.414974][ T3078]  ? mark_lock+0x9a/0x360
[   85.414989][ T3078]  ? __pfx_unregister_netdevice_many_notify+0x10/0x10
[   85.415004][ T3078]  ? kernfs_remove_by_name_ns+0x11b/0x160
[   85.415015][ T3078]  ? __pfx_lock_release+0x10/0x10
[   85.415032][ T3078]  unregister_netdevice_queue+0x303/0x370
[   85.415046][ T3078]  ? __pfx_up_write+0x10/0x10
[   85.415055][ T3078]  ? __pfx_unregister_netdevice_queue+0x10/0x10
[   85.415069][ T3078]  ? kernfs_remove_by_name_ns+0x11b/0x160
[   85.415080][ T3078]  _cfg80211_unregister_wdev+0x163/0x590
[   85.415094][ T3078]  ieee80211_remove_interfaces+0x4ef/0x700
[   85.415111][ T3078]  ? __pfx_ieee80211_remove_interfaces+0x10/0x10
[   85.415125][ T3078]  ? rcu_is_watching+0x15/0xb0
[   85.415137][ T3078]  ieee80211_unregister_hw+0x5d/0x2c0
[   85.415150][ T3078]  mac80211_hwsim_del_radio+0x2c4/0x4c0
[   85.415166][ T3078]  ? __pfx_mac80211_hwsim_del_radio+0x10/0x10
[   85.415182][ T3078]  hwsim_exit_net+0x5c1/0x670
[   85.415195][ T3078]  ? __pfx_hwsim_exit_net+0x10/0x10
[   85.415208][ T3078]  ? __ip_vs_dev_cleanup_batch+0x239/0x260
[   85.415222][ T3078]  cleanup_net+0x812/0xd60
[   85.415235][ T3078]  ? __pfx_cleanup_net+0x10/0x10
[   85.415249][ T3078]  ? process_scheduled_works+0x976/0x1840
[   85.415261][ T3078]  process_scheduled_works+0xa66/0x1840
[   85.415278][ T3078]  ? __pfx_process_scheduled_works+0x10/0x10
[   85.415291][ T3078]  ? assign_work+0x364/0x3d0
[   85.415303][ T3078]  worker_thread+0x870/0xd30
[   85.415316][ T3078]  ? _raw_spin_unlock_irqrestore+0xdd/0x140
[   85.415328][ T3078]  ? __kthread_parkme+0x169/0x1d0
[   85.415341][ T3078]  ? __pfx_worker_thread+0x10/0x10
[   85.415353][ T3078]  kthread+0x7a9/0x920
[   85.415366][ T3078]  ? __pfx_kthread+0x10/0x10
[   85.415379][ T3078]  ? __pfx_worker_thread+0x10/0x10
[   85.415389][ T3078]  ? __pfx_kthread+0x10/0x10
[   85.415402][ T3078]  ? __pfx_kthread+0x10/0x10
[   85.415415][ T3078]  ? __pfx_kthread+0x10/0x10
[   85.415427][ T3078]  ? _raw_spin_unlock_irq+0x23/0x50
[   85.415436][ T3078]  ? lockdep_hardirqs_on+0x99/0x150
[   85.415447][ T3078]  ? __pfx_kthread+0x10/0x10
[   85.415460][ T3078]  ret_from_fork+0x4b/0x80
[   85.415472][ T3078]  ? __pfx_kthread+0x10/0x10
[   85.415484][ T3078]  ret_from_fork_asm+0x1a/0x30
[   85.415500][ T3078]  </TASK>
[   85.700925][ T5397] 8021q: adding VLAN 0 to HW filter on device batadv0
[   85.723824][ T5397] veth0_vlan: entered promiscuous mode
[   85.729067][ T5397] veth1_vlan: entered promiscuous mode
[   85.761853][ T5397] veth0_macvtap: entered promiscuous mode
[   85.767400][ T5397] veth1_macvtap: entered promiscuous mode
[   85.792158][ T5397] batman_adv: batadv0: Interface activated: batadv_slave_0
[   85.798611][ T5397] batman_adv: batadv0: Interface activated: batadv_slave_1
[   85.803863][ T5397] netdevsim netdevsim0 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0
[   85.811361][ T5397] netdevsim netdevsim0 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0
[   85.815210][ T5397] netdevsim netdevsim0 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0
[   85.818552][ T5397] netdevsim netdevsim0 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0
[   85.862621][ T5397] ieee80211 phy5: Selected rate control algorithm 'minstrel_ht'
[   85.881473][   T12] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50
[   85.885200][   T12] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50
[   85.898336][ T5397] ieee80211 phy6: Selected rate control algorithm 'minstrel_ht'
[   85.924197][ T1036] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50
[   85.928197][ T1036] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50
[   85.977011][ T5304] syz-executor (5304) used greatest stack depth: 19152 bytes left
[   86.587622][    T9] cfg80211: failed to load regulatory.db
[   87.330925][ T3078] netdevsim netdevsim0 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0
[   88.596774][ T3078] netdevsim netdevsim0 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0
[   88.797633][ T3078] netdevsim netdevsim0 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0
[   88.830266][ T3078] netdevsim netdevsim0 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0
[   88.893747][ T3078] bridge_slave_1: left allmulticast mode
[   88.898084][ T3078] bridge_slave_1: left promiscuous mode
[   88.900371][ T3078] bridge0: port 2(bridge_slave_1) entered disabled state
[   88.916011][ T3078] bridge_slave_0: left allmulticast mode
[   88.918206][ T3078] bridge_slave_0: left promiscuous mode
[   88.920478][ T3078] bridge0: port 1(bridge_slave_0) entered disabled state
[   89.018626][ T3078] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface
[   89.026104][ T3078] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface
[   89.032389][ T3078] bond0 (unregistering): Released all slaves
[   89.142452][ T3078] hsr_slave_0: left promiscuous mode
[   89.146275][ T3078] hsr_slave_1: left promiscuous mode
[   89.155918][ T3078] batman_adv: batadv0: Interface deactivated: batadv_slave_0
[   89.158699][ T3078] batman_adv: batadv0: Removing interface: batadv_slave_0
[   89.165426][ T3078] batman_adv: batadv0: Interface deactivated: batadv_slave_1
[   89.168367][ T3078] batman_adv: batadv0: Removing interface: batadv_slave_1
[   89.180254][ T3078] veth1_macvtap: left promiscuous mode
[   89.182658][ T3078] veth0_macvtap: left promiscuous mode
[   89.194711][ T3078] veth1_vlan: left promiscuous mode
[   89.196779][ T3078] veth0_vlan: left promiscuous mode
[   89.342190][ T3078] team0 (unregistering): Port device team_slave_1 removed
[   89.357532][ T3078] team0 (unregistering): Port device team_slave_0 removed

VM DIAGNOSIS:
15:32:43  Registers:
info registers vcpu 0

CPU#0
RAX=0000000000000073 RBX=ffffffff9a743940 RCX=0000000000000000 RDX=00000000000003f8
RSI=0000000000000000 RDI=0000000000000020 RBP=0000000000000000 RSP=ffffc9000e0164b0
R8 =ffffffff8576147b R9 =1ffff11006802046 R10=dffffc0000000000 R11=ffffffff85761430
R12=dffffc0000000000 R13=ffffffff9a43df3f R14=0000000000000073 R15=00000000000003f8
RIP=ffffffff857614ae RFL=00000002 [-------] CPL=0 II=0 A20=1 SMM=0 HLT=0
ES =0000 0000000000000000 ffffffff 00c00000
CS =0010 0000000000000000 ffffffff 00a09b00 DPL=0 CS64 [-RA]
SS =0018 0000000000000000 ffffffff 00c09300 DPL=0 DS   [-WA]
DS =0000 0000000000000000 ffffffff 00c00000
FS =0000 0000000000000000 ffffffff 00c00000
GS =0000 ffff88801fc00000 ffffffff 00c00000
LDT=0000 0000000000000000 ffffffff 00c00000
TR =0040 fffffe0000003000 00004087 00008b00 DPL=0 TSS64-busy
GDT=     fffffe0000001000 0000007f
IDT=     fffffe0000000000 00000fff
CR0=80050033 CR2=00007f22a0e34ba8 CR3=0000000012456000 CR4=00352ef0
DR0=0000000000000000 DR1=0000000000000000 DR2=0000000000000000 DR3=0000000000000000 
DR6=00000000fffe0ff0 DR7=0000000000000400
EFER=0000000000000d01
FCW=037f FSW=0000 [ST=0] FTW=00 MXCSR=00001f80
FPR0=0000000000000000 0000 FPR1=0000000000000000 0000
FPR2=0000000000000000 0000 FPR3=0000000000000000 0000
FPR4=0000000000000000 0000 FPR5=0000000000000000 0000
FPR6=0000000000000000 0000 FPR7=0000000000000000 0000
Opmask00=0000000000000000 Opmask01=0000000000000000 Opmask02=0000000000000000 Opmask03=0000000000000000
Opmask04=0000000000000000 Opmask05=0000000000000000 Opmask06=0000000000000000 Opmask07=0000000000000000
ZMM00=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM01=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ffffffffffff0000 0000000000000000
ZMM02=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ffff000000000000 ffffffffffffffff
ZMM03=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 ffffffffffffffff ffffffffffffffff
ZMM04=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM05=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM06=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM07=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM08=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM09=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM10=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM11=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM12=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM13=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM14=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM15=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM16=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM17=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM18=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM19=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM20=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM21=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM22=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM23=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM24=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM25=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM26=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM27=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM28=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM29=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM30=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM31=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000


syzkaller build log:
go env (err=<nil>)
GO111MODULE='auto'
GOARCH='amd64'
GOBIN=''
GOCACHE='/syzkaller/.cache/go-build'
GOENV='/syzkaller/.config/go/env'
GOEXE=''
GOEXPERIMENT=''
GOFLAGS=''
GOHOSTARCH='amd64'
GOHOSTOS='linux'
GOINSECURE=''
GOMODCACHE='/syzkaller/jobs/linux/gopath/pkg/mod'
GONOPROXY=''
GONOSUMDB=''
GOOS='linux'
GOPATH='/syzkaller/jobs/linux/gopath'
GOPRIVATE=''
GOPROXY='https://proxy.golang.org,direct'
GOROOT='/usr/local/go'
GOSUMDB='sum.golang.org'
GOTMPDIR=''
GOTOOLCHAIN='auto'
GOTOOLDIR='/usr/local/go/pkg/tool/linux_amd64'
GOVCS=''
GOVERSION='go1.22.7'
GCCGO='gccgo'
GOAMD64='v1'
AR='ar'
CC='gcc'
CXX='g++'
CGO_ENABLED='1'
GOMOD='/syzkaller/jobs/linux/gopath/src/github.com/google/syzkaller/go.mod'
GOWORK=''
CGO_CFLAGS='-O2 -g'
CGO_CPPFLAGS=''
CGO_CXXFLAGS='-O2 -g'
CGO_FFLAGS='-O2 -g'
CGO_LDFLAGS='-O2 -g'
PKG_CONFIG='pkg-config'
GOGCCFLAGS='-fPIC -m64 -pthread -Wl,--no-gc-sections -fmessage-length=0 -ffile-prefix-map=/tmp/go-build3148115579=/tmp/go-build -gno-record-gcc-switches'

git status (err=<nil>)
HEAD detached at da72ac06e38
nothing to commit, working tree clean


tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
go list -f '{{.Stale}}' ./sys/syz-sysgen | grep -q false || go install ./sys/syz-sysgen
make .descriptions
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
bin/syz-sysgen
go fmt ./sys/... >/dev/null
touch .descriptions
GOOS=linux GOARCH=amd64 go build "-ldflags=-s -w -X github.com/google/syzkaller/prog.GitRevision=da72ac06e38cf1dd2ecbddd5502225ff7589542d -X 'github.com/google/syzkaller/prog.gitRevisionDate=20250121-154645'" "-tags=syz_target syz_os_linux syz_arch_amd64 " -o ./bin/linux_amd64/syz-execprog github.com/google/syzkaller/tools/syz-execprog
mkdir -p ./bin/linux_amd64
g++ -o ./bin/linux_amd64/syz-executor executor/executor.cc \
	-m64 -O2 -pthread -Wall -Werror -Wparentheses -Wunused-const-variable -Wframe-larger-than=16384 -Wno-stringop-overflow -Wno-array-bounds -Wno-format-overflow -Wno-unused-but-set-variable -Wno-unused-command-line-argument -static-pie -std=c++17 -I. -Iexecutor/_include   -DGOOS_linux=1 -DGOARCH_amd64=1 \
	-DHOSTGOOS_linux=1 -DGIT_REVISION=\"da72ac06e38cf1dd2ecbddd5502225ff7589542d\"
/usr/bin/ld: /tmp/ccb4CQRN.o: in function `Connection::Connect(char const*, char const*)':
executor.cc:(.text._ZN10Connection7ConnectEPKcS1_[_ZN10Connection7ConnectEPKcS1_]+0x104): warning: Using 'gethostbyname' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking


Error text is too large and was truncated, full error text is at:
https://syzkaller.appspot.com/x/error.txt?x=11605e18580000


Tested on:

commit:         b46c89c0 Merge tag 'spi-fix-v6.14-merge-window' of git..
git tree:       upstream
kernel config:  https://syzkaller.appspot.com/x/.config?x=ba866aed9d46ef97
dashboard link: https://syzkaller.appspot.com/bug?extid=2875f6362e0214a32381
compiler:       Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40

Note: no patches were applied.

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ