Received: by 10.213.65.68 with SMTP id h4csp1309384imn; Sun, 18 Mar 2018 23:59:08 -0700 (PDT) X-Google-Smtp-Source: AG47ELs+VJSx7dDAU7/MW5OH43Y07cvn8MghZ565aNtH18AiA4mitZdxbcqjAICiPfdjLw4B8KUa X-Received: by 2002:a17:902:9a05:: with SMTP id v5-v6mr11275279plp.69.1521442748280; Sun, 18 Mar 2018 23:59:08 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1521442748; cv=none; d=google.com; s=arc-20160816; b=Pge7wcN9LtWP3i6emAXizBrUhX7sd2S1aovNnGqvVmzxyqORnkV2+bTjeDeQF3bkVI 9+M94qtAbRA2JMaWc4T+988oHCPpur5aXsPwjS3nFHBE05fdsFmnFWUP/r/EnqnLu5z4 6DzaIzhqLd71AJy9PZ20CxkgpL0UBnjqqASz3yJUZ2xGHUwRrZgetpiujOceByANCi+L 8UWaSLHNhmMUdY6Cx/k56uFzymCxfngQEwpn57Aa1z0eY00Tii1Meie8mrNPnGjwHqOY FXZ98i9/3pC3f63Mtp+x4cQgD8w4UltvWfKWv5sICE6xtSlNu30jbtlnt8dVPQqjvCeW InEw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:cc:to:subject:message-id:date:from :references:in-reply-to:mime-version:dkim-signature :arc-authentication-results; bh=eL0ch1hOTmD/eVVO9LcPVN1MAZ5gAZCXK8fsbv2kC1g=; b=Kd/k9avsbF/YroGfk+32yc7+f2n9M7qAINCHov9ISG6Pf32r3xaIO2LbyP2KU8sK40 qwj2tLuSp3EC2dLpWXTO9KT1UzWWJLkUE2iwedmR20WpEJ9KR+YgYbdDw1fqBeH16kgz bNlaqpSchuy/Ueimi1wvNnADBt9PtJtUdYMSve9NIq/ZU66kck9eHxU2rqgC2FPIePuC 0oHJyQsz/XXNyVndMZwEPDO0b7tqbND7zoL7kXvDttBk9b3J25hGIQqG6COX37yjys3x x3PFQ5/9CtXu82JbfvRsayklFtKBG+/vGZ6jGsMk/sZdwCSfCVszpki7n1tNaZQfbq0C 3xuw== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b=p2EUQ0Gb; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id f19-v6si11592940plj.292.2018.03.18.23.58.54; Sun, 18 Mar 2018 23:59:08 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b=p2EUQ0Gb; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S932212AbeCSGrt (ORCPT + 99 others); Mon, 19 Mar 2018 02:47:49 -0400 Received: from mail-pg0-f51.google.com ([74.125.83.51]:35072 "EHLO mail-pg0-f51.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1755122AbeCSGrr (ORCPT ); Mon, 19 Mar 2018 02:47:47 -0400 Received: by mail-pg0-f51.google.com with SMTP id d1so6570895pgv.2 for ; Sun, 18 Mar 2018 23:47:47 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=eL0ch1hOTmD/eVVO9LcPVN1MAZ5gAZCXK8fsbv2kC1g=; b=p2EUQ0GbPQFreChFL9Z21R0JrMawjmSHQzKMSX9+CEaZv2a5Dp1VnIGZPPdZ0cpN2d zoSzbPgrIQehgmAnsnj3zM4K4QkB0Azz/ujWwOOqMuvVbNVn0Tjb49zsojJ1bHy5vT90 Um5mBEK42Ow2Fl8Qii2VduiVNyDiuYEsmkwSf/3dnMvdy5gv7jdgui1SS0Ul+Wh6l/KO mg/1H4+dhLAJxc5o0txyWkXu98MSK+46WbCxZkn0F9GutA/FfCh2dNtD6+ooDXFTBtpE lbdw96x56WIivdKq3qTo56ngZx6rXSPDxUHxUyWvKzkG8sw0PIii7YQPboETkoPaWAwL BFbQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=eL0ch1hOTmD/eVVO9LcPVN1MAZ5gAZCXK8fsbv2kC1g=; b=U18v0z0yG2FvElsamhL4O7d93Kt46JoTbDRC8em4tanZmalNwoOF60JmxFfmqMfTSv dpwK8K3O5//gqlBcsAVCwxEbOHjBYbQjwe8DdP7K+0l+whrasZ53isQYb+FfIC0U7sda +AfDoRO4z3AM71UkGM6XNmehuWZQFOikpo5VEoBt98FVNTJoXWalb5GAk+24OVTW6wK2 DESdWrOpr909wTqfh6mbLycox4AYOWFBH+kBoh+fFVILWz4mX0be+MfOx0sCkQjLj82a gunOHyLJfRpGFNgqIGmQ+suoJLhqY911q+1bywXhvWij0CSokN6wixMoRFt3zLYmYzg+ kzJQ== X-Gm-Message-State: AElRT7GkyKxLPr/1GGJbGNOqG9ikADxU4WoJLiUkMADkGBUMpokazcxM wPKHuubtRuYXgpEc9kRB/BXwyoL4kOkn1WmtFNVzLQ== X-Received: by 10.99.105.202 with SMTP id e193mr8094945pgc.84.1521442066815; Sun, 18 Mar 2018 23:47:46 -0700 (PDT) MIME-Version: 1.0 Received: by 10.100.182.136 with HTTP; Sun, 18 Mar 2018 23:47:26 -0700 (PDT) In-Reply-To: <20180319063708.GB20345@oracle.com> References: <001a114aacf82781120565c9f4fe@google.com> <20180319063708.GB20345@oracle.com> From: Dmitry Vyukov Date: Mon, 19 Mar 2018 09:47:26 +0300 Message-ID: Subject: Re: KASAN: slab-out-of-bounds Read in rds_cong_queue_updates To: Sowmini Varadhan Cc: syzbot , David Miller , LKML , linux-rdma@vger.kernel.org, netdev , rds-devel@oss.oracle.com, Santosh Shilimkar , syzkaller-bugs@googlegroups.com Content-Type: text/plain; charset="UTF-8" Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Mon, Mar 19, 2018 at 9:37 AM, Sowmini Varadhan wrote: > On (03/19/18 09:29), Dmitry Vyukov wrote: >> >> This looks the same as: >> >> #syz dup: KASAN: use-after-free Read in rds_cong_queue_updates > > correct, seems like the rds_destroy_pending() fixes did not seal > this race condition. I need to look at this more carefully to see > what race I missed.. no easy answer here, I am afraid. Hi Sowmini, What fix do you mean? syzbot does not know about any fixes for any of the bugs as far as I see. So maybe your fix actually fixed it, but it's not in upstream yes, and syzbot still finds this in upstream. We tell syzbot about fixes (with Reported-by tags or "#syz fix" email commands) to be able to later make sense of the state of the bugs.