Received: by 2002:ad5:474a:0:0:0:0:0 with SMTP id i10csp808352imu; Fri, 11 Jan 2019 09:23:00 -0800 (PST) X-Google-Smtp-Source: ALg8bN7/XBrbiY/UqhjaiUj+hMKAJkxWMo0WRiXqHO8SloZtE0f2LmMdK3wXvI1Z2m9fCtn4JVhJ X-Received: by 2002:a63:981:: with SMTP id 123mr14204135pgj.444.1547227380219; Fri, 11 Jan 2019 09:23:00 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1547227380; cv=none; d=google.com; s=arc-20160816; b=TWRHreJTX2g1i0vfbJWyuB32b0detGImyZtmbA2nX0JN8coWXGimKmwwrJhwiPWr4E Bt+f3mzLgB3IbGnfgKhui5z5FKHP1yeL349a0/hPYGRUmRRpGUM5ZRB112UssHu0H4l/ uZi9OO9oj2cojgdmRAGSwsXIdMznqMtxblos4QyTPaiTnZ3/+OJ88+zfrH9544KUXjZc dpD3R6wx6cho+yUeDR2v9Idfw1PEdnsj7vB8A0PDfado/Ymrq+CNXsiPfquNOD2EWbGI FBZyuafKUKFeqx9DkhXZZmNGLP+KOZnHWKPHfPrT97wIqkINbxMP6FcvEaLgKot5R+BL 7A1A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:mime-version :feedback-id:references:in-reply-to:message-id:subject:reply-to:cc :from:to:dkim-signature:date; bh=PfAEbF+XRMQyuHtxVZRiElrUtfwfk50azdNFkZyNRZs=; b=NhnFjQR2Z4Nto7cYnejVecv4gc7kr3xDiBZ3EG0/OnJc5uH15F/BtDqdq2MffGAT+0 X9oMnIq00w5DLl9WOI8wT0lJ5km9R1UoudyaiuEB0AoGpvcCKzbX1O7oZcA2rm8lAb4h iAvJRcu/GCz9qG/hzSuHqPv8eVjmE7bwKOh7Rcqz9Vu5eDhvrBhCwMjPVosWuhLrKHyC pbqZH3cJOWTP8Rb/Ldfcyq+y0xg6pqx0R5hWRwxCBVR0LdLvOD2CtQ/c/V6gKnLwb2Pl q6aTAfZ2Z7bFjeQA0UyfujSpAf5t4lLFZjKPgM1yFWXYXMJY+qSXdZj7x/hIKCPPcRsJ VeeQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@protonmail.ch header.s=default header.b=JSQt8N6g; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=protonmail.ch Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id o10si22143331pgg.373.2019.01.11.09.22.41; Fri, 11 Jan 2019 09:23:00 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@protonmail.ch header.s=default header.b=JSQt8N6g; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=protonmail.ch Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1732729AbfAKNh5 (ORCPT + 99 others); Fri, 11 Jan 2019 08:37:57 -0500 Received: from mail-40136.protonmail.ch ([185.70.40.136]:32999 "EHLO mail-40136.protonmail.ch" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1728590AbfAKNh4 (ORCPT ); Fri, 11 Jan 2019 08:37:56 -0500 Date: Fri, 11 Jan 2019 13:37:50 +0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=protonmail.ch; s=default; t=1547213873; bh=PfAEbF+XRMQyuHtxVZRiElrUtfwfk50azdNFkZyNRZs=; h=Date:To:From:Cc:Reply-To:Subject:In-Reply-To:References: Feedback-ID:From; b=JSQt8N6gzWBUeo1R9+sMHf4WGbUvijdwUbmasGCfp2b5sLHcXg3KulnCLNd42dvvV 1jZc9sbxg2w73574S1cTvliOuU3dBis4MH5ebbyzzK+k/T6jwLAhh95G2RPbzdytI0 DDFOsAa3evEjKBkhyde0O7jzjngQLBuygE7sQaDQ= To: Peter Zijlstra From: Esme Cc: Ingo Molnar , Arnaldo Carvalho de Melo , Alexander Shishkin , JJiri Olsa , Namhyung Kim , "linux-kernel@vger.kernel.org" Reply-To: Esme Subject: Re: PROBLEM: syzkaller found / reduced C repro for non-fatal unchecked MSR access error Message-ID: In-Reply-To: <20190111100253.GO30894@hirez.programming.kicks-ass.net> References: <20190111100253.GO30894@hirez.programming.kicks-ass.net> Feedback-ID: pQGzDYT_k6dzic_kf3kwsxmTXzjnqMJxtC9J3KGyZBepPHdXRBM0BHuwPfpm1pFdJLAMwtJT5KKNaGlRVnFRQw==:Ext:ProtonMail MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable X-Spam-Status: No, score=-1.2 required=7.0 tests=ALL_TRUSTED,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FREEMAIL_FROM autolearn=ham autolearn_force=no version=3.4.2 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on mail.protonmail.ch Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org =E2=80=90=E2=80=90=E2=80=90=E2=80=90=E2=80=90=E2=80=90=E2=80=90 Original Me= ssage =E2=80=90=E2=80=90=E2=80=90=E2=80=90=E2=80=90=E2=80=90=E2=80=90 On Friday, January 11, 2019 5:02 AM, Peter Zijlstra = wrote: > On Thu, Jan 10, 2019 at 11:21:16PM +0000, Esme wrote: > > > Attached is a fairly small C repro I did not see any references to > > this possible flaw (unchecked MSR access) in relation to > > __NR_perf_event_open > > Attached is the config directly extracted from proc. This is the call > > stack in relation to the MSR access error (5.0.0-rc1+), I get a very > > similar stack running this test case on a stock Ubuntu > > "4.18.0-11-generic" (pasted after this one). > > > -- Esme > > [ 70.228744] unchecked MSR access error: WRMSR to 0xc0010000 (tried to = write 0x0000020000130076) at rIP: 0xffffffff812dde28 (native_write_msr+0x8/= 0x30) > > That's K7_EVNTSEL0. What kind of hardware are you running this on? QEMU emulator version 3.0.93 (v3.1.0-rc3-dirty) [ 0.000000] DMI: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.12.0= -0-ga698c8995f-prebuilt.qemu.org 04/01/2014 [ 0.000000] Linux version 4.18.0-11-generic (buildd@lcy01-amd64-027) (gc= c version 8.2.0 (Ubuntu 8.2.0-7ubuntu1)) #12-Ubuntu SMP Tue Oct 23 19:22:37= UTC 2018 (Ubuntu 4.18.0-11.12-generic 4.18.12) [ 0.000000] Command line: BOOT_IMAGE=3D/boot/vmlinuz-4.18.0-11-generic r= oot=3DUUID=3D3a43ccb9-a433-4296-8dc5-0443f2a32128 ro quiet splash vt.handof= f=3D1 [ 0.000000] KERNEL supported cpus: [ 0.000000] Intel GenuineIntel [ 0.000000] AMD AuthenticAMD [ 0.000000] Centaur CentaurHauls [ 0.000000] random: get_random_u32 called from bsp_init_amd+0x205/0x2a0 = with crng_init=3D0 [ 0.000000] x86/fpu: Supporting XSAVE feature 0x001: 'x87 floating point= registers' [ 0.000000] x86/fpu: Supporting XSAVE feature 0x002: 'SSE registers' [ 0.000000] x86/fpu: Supporting XSAVE feature 0x004: 'AVX registers' [ 0.000000] x86/fpu: xstate_offset[2]: 576, xstate_sizes[2]: 256 [ 0.000000] x86/fpu: Enabled xstate features 0x7, context size is 832 by= tes, using 'standard' format.