Received: by 2002:ac0:a5a6:0:0:0:0:0 with SMTP id m35-v6csp3404147imm; Fri, 24 Aug 2018 16:53:10 -0700 (PDT) X-Google-Smtp-Source: ANB0VdaMSs+xV3cGFo1kea1rRYXpMShvzKpIDaGzaxNIqX3WYDiVTr8AQi3NOlc3qp8DCGwGHwVu X-Received: by 2002:a63:eb53:: with SMTP id b19-v6mr3538695pgk.371.1535154790860; Fri, 24 Aug 2018 16:53:10 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1535154790; cv=none; d=google.com; s=arc-20160816; b=WuiuV4++mH72UDQAO9SRLCJ49ZrLSk1wH/PLdCGkCBSvbFALyXe+wUDFuQsEpEWzkd EjmaSCLFWWRQG+NZ6GQQ2G39O1W9h+TSdd5VU6cduU5He0VUHBZ60kZAwHk1uKeuv4Ds ICjfAdwnHVbJnpRNIkmCPDMUGhqjzZ00WDgtaTjLms5zLRzUkgSGbSBC4fUbZHv8CkNn zJYkLBBI0innz4aLioDkXn1aiIpPmn8XqWr9DxZZLDmbnSTS/TNP6pGcM2Q5HTA0bwVv sOqWk84z0/Nu3GqXUvB+hNu2VsKIj85Wa9csoOFqSfGCDl+y0BpFHII1k2YNSrBBJlKt pRcw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:cc:to:subject:message-id:date:from :references:in-reply-to:mime-version:dkim-signature :arc-authentication-results; bh=duJuPK+dtQzH4YpSOFDKCwqBwjwZNDXnUUdnYEd1Ts8=; b=NA4gDihztWAV0I7brb+/cRjV9zCNYqyujKut2hncwNvZEEbQBmYhpkAIc+cL8yCxYN twjAePJkfFo5Xfi7NDmP+zcuUt/tNjbOGfhiBjIeHdfcQMc8S6kCwNsOHNxUezL2ZD7J 70dIqgOhNxZrA9BlBSEh6hUik4Sr8hnnoZSWqsnLZ0+DnebQIvzvvlLb/fapgXXRy/wq xGgC6roT3Iy4Pvqis/ERIuoLgi4QTeC7LCZFWG648HJMY67ofFzWnjag+EFAnJvBtWLb rT2Va33SttlcI8Ux3j67iwoDmCVfZVDPFno7eYa2JqpLBMUgU7JoRILKxbqA1/18vUUr HWog== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b=oFI4g+y+; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id 71-v6si6589303pfv.139.2018.08.24.16.52.53; Fri, 24 Aug 2018 16:53:10 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b=oFI4g+y+; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727626AbeHYD2B (ORCPT + 99 others); Fri, 24 Aug 2018 23:28:01 -0400 Received: from mail-pf1-f193.google.com ([209.85.210.193]:36996 "EHLO mail-pf1-f193.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1727044AbeHYD2A (ORCPT ); Fri, 24 Aug 2018 23:28:00 -0400 Received: by mail-pf1-f193.google.com with SMTP id h69-v6so5208887pfd.4 for ; Fri, 24 Aug 2018 16:51:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=duJuPK+dtQzH4YpSOFDKCwqBwjwZNDXnUUdnYEd1Ts8=; b=oFI4g+y+rlRFAgG/LDpKsKaO+54eqoSX+utPiidmxeEZvTv6JGNjGqU1Ndxy5yzZJV gIeumgLiTaw/yhdRlTZmVFRRaIOq+rCGmzMlwRQXIGXPxjLbLmbAj8EOQFLPJrF/kIuj 1k77mzGkjepku82MGcB6LSQ600L3Kho3j+bDoIaMFlfA5taukuFUQ15ieFi5AjWrg3Z3 A1eHbpx1/Ej9hbBSotW7fVnmsFCdIyOesQVVRq7/ZYDL9xoGb3W4nPwghCyYnI4/lO2H Llw8OgSbaCTtqxby+jDQAwg9FGnvVieLpZSC++uKcEpr7LrrgTJRPxCsMJ02ip/KZs7r TKxw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=duJuPK+dtQzH4YpSOFDKCwqBwjwZNDXnUUdnYEd1Ts8=; b=DmKiDwKBgOayUZ8Svv6EQud3gtVMKB9ZaKz8muaXr1er9DTphDUrZomZj7ef/4ksje y4e/v0uMjVyUv7j21ftKVi4IcRt/2ZKxvS5qzMdrZKTZ9D467n8FW93cfWCjq2V+RQqu LFjkGmvWFcQ10JUX7GaPCuSMsMT4ex3qewxGKL9NzLdbe09qYSoqydjFWkc88ZOCSaer r7B9EGcNOmtIZJByXZpE8Nvf/1A58u+nZB0+bB+ujR9SUAqfMC5hzhx2Erw0c7KXHwJr /wz2788WYwLcDC9uEdvchOYU83rH8aTogZakk2QESOy3H8pC7k3G0NgsBCzlEG06xw74 wJNA== X-Gm-Message-State: APzg51A86WLeLNZjopqvHuX1JB9lu0bFqDNFz0QxVgrI1eojO5BqmBjp gH33dYgFQ0+4N1mmj0yQRaDj2FdjpKdZjl/Cn0JL1g== X-Received: by 2002:a62:a05:: with SMTP id s5-v6mr4010896pfi.147.1535154669329; Fri, 24 Aug 2018 16:51:09 -0700 (PDT) MIME-Version: 1.0 Received: by 2002:a17:90a:ac14:0:0:0:0 with HTTP; Fri, 24 Aug 2018 16:50:48 -0700 (PDT) In-Reply-To: <20180824233700.GC31961@oracle.com> References: <20180824230446.GA16891@oracle.com> <000000000000d8879a05743667a2@google.com> <20180824233700.GC31961@oracle.com> From: Dmitry Vyukov Date: Fri, 24 Aug 2018 16:50:48 -0700 Message-ID: Subject: Re: KASAN: use-after-free Read in __rhashtable_lookup (2) To: Sowmini Varadhan Cc: syzbot , David Miller , LKML , linux-rdma@vger.kernel.org, netdev , rds-devel@oss.oracle.com, Santosh Shilimkar , syzkaller-bugs Content-Type: text/plain; charset="UTF-8" Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Fri, Aug 24, 2018 at 4:37 PM, Sowmini Varadhan wrote: > On (08/24/18 16:10), Dmitry Vyukov wrote: >> You need a colon after dup. > > I see. > >> But this can't possibly be a dup of that bug. That bug was fixed in February: > > Apologies, I unknowingly made a mistake in my > syzbot-tiquette in that case, > > I did not intend to *close* the bug as a dup, I was > merely trying to indicate that this is yet another > manifestation of the original report with subject > "KASAN: use-after-free Read in rds_find_bound" > > All of these problems are happening because we are missing > a synchronize_net() in rds_release. > > A full description of the race conditon can be found in > https://www.spinics.net/lists/netdev/msg475074.html > > If rds_release is going to nuke the rds_socket > it needs to sychronize_net() with other threads that may be > looking up the bind_hash_table. If we dont do that, > all of these "use-after-free" races can happen. > As long as we dont have the synchronize_net() we are > missing a big (and standard) bit of RCU synchronization. If it's a note for humans, then just a plain English comment will do.