Received: by 2002:a05:6a10:8c0a:0:0:0:0 with SMTP id go10csp286177pxb; Mon, 8 Feb 2021 23:37:15 -0800 (PST) X-Google-Smtp-Source: ABdhPJz3ox7l6BUVHbSOb8nyHy3cFF+AEvxdjuonTfKwqVcmqSTi/P5FHoUxpz11WEQNSpRW+Lbd X-Received: by 2002:a17:906:eb87:: with SMTP id mh7mr21651026ejb.10.1612856235585; Mon, 08 Feb 2021 23:37:15 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1612856235; cv=none; d=google.com; s=arc-20160816; b=TjnwVshdb221RP4njNE4kVNue444iUlJ8TmtDWVhSg5aQB454fFCqRk1/7SHHzuld1 MDVvoNx7bdHBz/C4Q2wAObFBNj5mP6YsgOV/bD3bztSN/wAi7m9Oy0WQ1AnQ66t1lZ1g s2UTInqPNmpmxirp3oztRk5LuqrkZ4Px0vRUE6tsctiP+jYGsAMZ73Gfl379lwA3mx9S 03o8GZljBujWxNLD1kyO2pKZq7Ke9mIqFe4vIxi+uRV6uENmjDluC3A/378CDfdNyx/c 0fMy2ZDf54flfuMzIWRqIXySsBeqdj9SFEFb68kQrQ2WtUMW7a2tPlcjko3jOSNKEH9Z ru4g== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:dkim-signature; bh=VxU9PMMlm0cJYv5FlM8nWSRQFbnHMT6a6kZn8VAvqmU=; b=eYTsNa9qa4N6Z0+DEj9RDWramzNiFmGJmeNUirGSeWJXtoIm0Idmt63bwiYI129Av4 VjhYakWRAaIh1ldeTXyv9Y6nwQTBFn8+2NMtCprTQZkgpJgGhnRFhbKI9pEdLKCRRrfJ OzaXH/HxSbuaxEgQk0WdX9VwVwuvxRvTw8/c3RPNR0ktFQa3Bz7Y535qsyJapGBSuVo2 bGyZ2Z95KCFcwsWfDWZO8qMticoVRm/qnC8I8nELWSmvIfd+0rnyKBwLuDmq5VQmSJ2I CwguoiULsvfV90BcBVVlJjuByA550v1rw7m7QuPImpB4ysLUQbwHPEQtDCFxcg7NtEx9 D3Yg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b=RkwthBqL; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id i25si12542147ejo.710.2021.02.08.23.36.52; Mon, 08 Feb 2021 23:37:15 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b=RkwthBqL; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S230155AbhBIHf6 (ORCPT + 99 others); Tue, 9 Feb 2021 02:35:58 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:37112 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229919AbhBIHfy (ORCPT ); Tue, 9 Feb 2021 02:35:54 -0500 Received: from mail-qt1-x82f.google.com (mail-qt1-x82f.google.com [IPv6:2607:f8b0:4864:20::82f]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 1E865C06178A for ; Mon, 8 Feb 2021 23:35:14 -0800 (PST) Received: by mail-qt1-x82f.google.com with SMTP id e15so12312278qte.9 for ; Mon, 08 Feb 2021 23:35:14 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=VxU9PMMlm0cJYv5FlM8nWSRQFbnHMT6a6kZn8VAvqmU=; b=RkwthBqL6RxhZjL+2Bz/oYdwFXTyhqhSHIWJz4QpwjiU2TFpBBzoXY1lC0cjAilqJh 03Br+jkZCjPMv9aCI42k+zsZs3rfaBovcCaD+bMHKKSTH9xB08bgnnaPjfDLWpemL5ZC 1Zjjxzy/BlgXpOrTIV435Dfc0xk278J67zlI9Nirgv15IiGy+LaxLbGzmIwyT73NdhXq IboIGmQBK6sRmnMBCNC+U6cQfdGdEZ1LGRT6TwTRO0dRSTi7DPxAv6jARaYnuaActd7N 8iz7xh2r1fEPfix6BEp2XKId+foVpGOpcCsrCeD6txRpGst3CWSVcxS5roiNwhoypSHP C+Jw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=VxU9PMMlm0cJYv5FlM8nWSRQFbnHMT6a6kZn8VAvqmU=; b=tMGhV7vf5oxC4Pdm2M/GKwpt5UUKHFvBIMla70whJr7cIwTuQ1nWVK+a5QBDIxwOI0 1wOKrfP0JA+sGvpzHri5/2SpCO/UvGXaDd2ss1SFCqocZ3xXj9kw/ofzXiLrdPa7cslI 0Ozaet0/lD2mIMAv//IMGC1srt8gpoEfgEhzRkGiRNOAqi903jLg4A9WbeYaFUjZKSSK xqkJkUAhoxECE8KxEV5k5h7c0tF/E+NlDWEksj9h1FYjHonXzlVtFehXqwM9Ob6RYvVq EhR3HKQbbV6rCMv0EL3r+hhbxFuFI0HOXzt7fxU5YkYL4H9XqsIxTKgYOVTY+4OrUqtz +mzQ== X-Gm-Message-State: AOAM530homMwElDKjGLOWlS/SpFwaVkzrBq8ddRbyX/hsYvTdPTNDYSV +Ym/InLLy/CBC9HDyddWDNX3CKQTtbzdgC1z9Kd7Hw== X-Received: by 2002:a05:622a:c9:: with SMTP id p9mr18543023qtw.337.1612856112858; Mon, 08 Feb 2021 23:35:12 -0800 (PST) MIME-Version: 1.0 References: <000000000000364d5505babe13f5@google.com> In-Reply-To: <000000000000364d5505babe13f5@google.com> From: Dmitry Vyukov Date: Tue, 9 Feb 2021 08:35:00 +0100 Message-ID: Subject: Re: KMSAN: uninit-value in bpf_iter_prog_supported To: syzbot , Alexei Starovoitov , Daniel Borkmann , andrii@kernel.org, Martin KaFai Lau , netdev , bpf Cc: Alexander Potapenko , LKML , syzkaller-bugs Content-Type: text/plain; charset="UTF-8" Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Sun, Feb 7, 2021 at 1:20 PM syzbot wrote: > > Hello, > > syzbot found the following issue on: > > HEAD commit: 73d62e81 kmsan: random: prevent boot-time reports in _mix_.. > git tree: https://github.com/google/kmsan.git master > console output: https://syzkaller.appspot.com/x/log.txt?x=17ac5f64d00000 > kernel config: https://syzkaller.appspot.com/x/.config?x=df698232b2ac45c9 > dashboard link: https://syzkaller.appspot.com/bug?extid=580f4f2a272e452d55cb > compiler: Debian clang version 11.0.1-2 > userspace arch: i386 > > Unfortunately, I don't have any reproducer for this issue yet. > > IMPORTANT: if you fix the issue, please add the following tag to the commit: > Reported-by: syzbot+580f4f2a272e452d55cb@syzkaller.appspotmail.com +BPF maintainers > ===================================================== > BUG: KMSAN: uninit-value in bpf_iter_prog_supported+0x3dd/0x6a0 syzkaller/managers/upstream-kmsan-gce-386/kernel/kernel/bpf/bpf_iter.c:329 > CPU: 0 PID: 18494 Comm: bpf_preload Not tainted 5.10.0-rc4-syzkaller #0 > Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011 > Call Trace: > __dump_stack syzkaller/managers/upstream-kmsan-gce-386/kernel/lib/dump_stack.c:77 [inline] > dump_stack+0x21c/0x280 syzkaller/managers/upstream-kmsan-gce-386/kernel/lib/dump_stack.c:118 > kmsan_report+0xfb/0x1e0 syzkaller/managers/upstream-kmsan-gce-386/kernel/mm/kmsan/kmsan_report.c:118 > __msan_warning+0x5f/0xa0 syzkaller/managers/upstream-kmsan-gce-386/kernel/mm/kmsan/kmsan_instr.c:197 > bpf_iter_prog_supported+0x3dd/0x6a0 syzkaller/managers/upstream-kmsan-gce-386/kernel/kernel/bpf/bpf_iter.c:329 > check_attach_btf_id syzkaller/managers/upstream-kmsan-gce-386/kernel/kernel/bpf/verifier.c:11772 [inline] > bpf_check+0x11872/0x1c380 syzkaller/managers/upstream-kmsan-gce-386/kernel/kernel/bpf/verifier.c:11900 > bpf_prog_load syzkaller/managers/upstream-kmsan-gce-386/kernel/kernel/bpf/syscall.c:2210 [inline] > __do_sys_bpf+0x17483/0x1aee0 syzkaller/managers/upstream-kmsan-gce-386/kernel/kernel/bpf/syscall.c:4399 > __se_sys_bpf+0x8e/0xa0 syzkaller/managers/upstream-kmsan-gce-386/kernel/kernel/bpf/syscall.c:4357 > __x64_sys_bpf+0x4a/0x70 syzkaller/managers/upstream-kmsan-gce-386/kernel/kernel/bpf/syscall.c:4357 > do_syscall_64+0x9f/0x140 syzkaller/managers/upstream-kmsan-gce-386/kernel/arch/x86/entry/common.c:48 > entry_SYSCALL_64_after_hwframe+0x44/0xa9 > RIP: 0033:0x7fb70b5ab469 > Code: 00 f3 c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d ff 49 2b 00 f7 d8 64 89 01 48 > RSP: 002b:00007ffdbb4cde38 EFLAGS: 00000246 ORIG_RAX: 0000000000000141 > RAX: ffffffffffffffda RBX: 000000000065b110 RCX: 00007fb70b5ab469 > RDX: 0000000000000078 RSI: 00007ffdbb4cdef0 RDI: 0000000000000005 > RBP: 00007ffdbb4cdef0 R08: 0000001000000017 R09: 0000000000000000 > R10: 00007ffdbb4ce0e8 R11: 0000000000000246 R12: 0000000000000000 > R13: 00007ffdbb4cdf20 R14: 0000000000000000 R15: 0000000000000000 > > Uninit was created at: > kmsan_save_stack_with_flags syzkaller/managers/upstream-kmsan-gce-386/kernel/mm/kmsan/kmsan.c:121 [inline] > kmsan_internal_poison_shadow+0x5c/0xf0 syzkaller/managers/upstream-kmsan-gce-386/kernel/mm/kmsan/kmsan.c:104 > kmsan_slab_alloc+0x8d/0xe0 syzkaller/managers/upstream-kmsan-gce-386/kernel/mm/kmsan/kmsan_hooks.c:76 > slab_alloc_node syzkaller/managers/upstream-kmsan-gce-386/kernel/mm/slub.c:2906 [inline] > slab_alloc syzkaller/managers/upstream-kmsan-gce-386/kernel/mm/slub.c:2915 [inline] > kmem_cache_alloc_trace+0x893/0x1000 syzkaller/managers/upstream-kmsan-gce-386/kernel/mm/slub.c:2932 > kmalloc syzkaller/managers/upstream-kmsan-gce-386/kernel/./include/linux/slab.h:552 [inline] > bpf_iter_reg_target+0x81/0x3f0 syzkaller/managers/upstream-kmsan-gce-386/kernel/kernel/bpf/bpf_iter.c:276 > bpf_sk_storage_map_iter_init+0x6a/0x85 syzkaller/managers/upstream-kmsan-gce-386/kernel/net/core/bpf_sk_storage.c:870 > do_one_initcall+0x362/0x8d0 syzkaller/managers/upstream-kmsan-gce-386/kernel/init/main.c:1220 > do_initcall_level+0x1e7/0x35a syzkaller/managers/upstream-kmsan-gce-386/kernel/init/main.c:1293 > do_initcalls+0x127/0x1cb syzkaller/managers/upstream-kmsan-gce-386/kernel/init/main.c:1309 > do_basic_setup+0x33/0x36 syzkaller/managers/upstream-kmsan-gce-386/kernel/init/main.c:1329 > kernel_init_freeable+0x238/0x38b syzkaller/managers/upstream-kmsan-gce-386/kernel/init/main.c:1529 > kernel_init+0x1f/0x840 syzkaller/managers/upstream-kmsan-gce-386/kernel/init/main.c:1418 > ret_from_fork+0x1f/0x30 syzkaller/managers/upstream-kmsan-gce-386/kernel/arch/x86/entry/entry_64.S:296 > ===================================================== > > > --- > This report is generated by a bot. It may contain errors. > See https://goo.gl/tpsmEJ for more information about syzbot. > syzbot engineers can be reached at syzkaller@googlegroups.com. > > syzbot will keep track of this issue. See: > https://goo.gl/tpsmEJ#status for how to communicate with syzbot. > > -- > You received this message because you are subscribed to the Google Groups "syzkaller-bugs" group. > To unsubscribe from this group and stop receiving emails from it, send an email to syzkaller-bugs+unsubscribe@googlegroups.com. > To view this discussion on the web visit https://groups.google.com/d/msgid/syzkaller-bugs/000000000000364d5505babe13f5%40google.com.