Received: by 2002:a05:6a10:8c0a:0:0:0:0 with SMTP id go10csp1562353pxb; Wed, 10 Feb 2021 11:10:41 -0800 (PST) X-Google-Smtp-Source: ABdhPJzpe9H+wgdRsAFlaolIkQQlnz5xytyf9dMhZGb2EucCCtus8FwSyezleSMObxswCJcsaBLa X-Received: by 2002:a17:906:a898:: with SMTP id ha24mr4617294ejb.413.1612984241433; Wed, 10 Feb 2021 11:10:41 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1612984241; cv=none; d=google.com; s=arc-20160816; b=s/7a4hycHA//DXYS0zDFNKB0oXX+3G9Dhp3smRRYN6Y86MUqZUC7lcAk8/1Odw7ZSS t6TDN0oXbeQDVW6lfIBXNiCdYuO9fuFV0qERaxp3TNSw6yCKuyc7nW8EL6KwYfMxX0gQ D0wExfqvC1ahnaxB3lX9z5e+x93rtLwqmo4DuMDX12efwK5tRxCss11XJmRQoZJL9/Oh nGuSb3HwXmBizLfrm780Tsrzv2vnwaiZvNigPcN5c6/TEPqSSgMb2A4BWPn+z093Azzo 0Mg6rU3R53W9tPAlb7uov2oMKlIiGQGd049xym7dX/dKqx8Xp3WRVRBAviIfzFfATlQe X39Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:content-language :in-reply-to:mime-version:user-agent:date:message-id:from:references :cc:to:subject; bh=tl0zeVKDh3cgu823ZBUBVBlD2Bk0NlGif00+MRfjUMY=; b=t1TheviWBUWJKLKvqVc7AjS3qZ3WJRj/pmOQ7Td8wxrOl0iZe2cfuxlWRKjq5y6rnR Ie2EvVZAXHrgT9+nIl+70sMVL1CDJYeewMNf2+NJw8W71+LJP3uh2IiMopHyQ5lAvaHb 14kkHzDFDvE8vukC87T1idqwmnuNFIc/WO9/XG5wBAQHTHEJDh9GolzXp1AIOu2FcJdT 6lwcqxdwHuKurLaykURwkKRqlaaMZkY5AoDk/Qa+QiS6kCpz9EAf4MNZOiFgyFbA8ZNS 9eMqlgvrCkwZ2+PHIBEUyWN8yxJqgYJEKzn0l+4O2H2ch0Kl9a7IXDvFn79GnA/A/Khy /Ajw== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id gz3si1928677ejc.665.2021.02.10.11.10.17; Wed, 10 Feb 2021 11:10:41 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S234200AbhBJTJr (ORCPT + 99 others); Wed, 10 Feb 2021 14:09:47 -0500 Received: from www262.sakura.ne.jp ([202.181.97.72]:57910 "EHLO www262.sakura.ne.jp" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S234415AbhBJTJo (ORCPT ); Wed, 10 Feb 2021 14:09:44 -0500 Received: from fsav104.sakura.ne.jp (fsav104.sakura.ne.jp [27.133.134.231]) by www262.sakura.ne.jp (8.15.2/8.15.2) with ESMTP id 11AJ85iP098318; Thu, 11 Feb 2021 04:08:05 +0900 (JST) (envelope-from penguin-kernel@i-love.sakura.ne.jp) Received: from www262.sakura.ne.jp (202.181.97.72) by fsav104.sakura.ne.jp (F-Secure/fsigk_smtp/550/fsav104.sakura.ne.jp); Thu, 11 Feb 2021 04:08:05 +0900 (JST) X-Virus-Status: clean(F-Secure/fsigk_smtp/550/fsav104.sakura.ne.jp) Received: from [192.168.1.9] (M106072142033.v4.enabler.ne.jp [106.72.142.33]) (authenticated bits=0) by www262.sakura.ne.jp (8.15.2/8.15.2) with ESMTPSA id 11AJ843F098315 (version=TLSv1.2 cipher=AES256-GCM-SHA384 bits=256 verify=NO); Thu, 11 Feb 2021 04:08:04 +0900 (JST) (envelope-from penguin-kernel@i-love.sakura.ne.jp) Subject: Re: general protection fault in tomoyo_socket_sendmsg_permission To: Shuah Khan , Hillf Danton , syzbot Cc: linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, Andrey Konovalov , Valentina Manea , Greg Kroah-Hartman , syzkaller-bugs@googlegroups.com References: <000000000000647eff05b3f7e0d4@google.com> <20201113120055.11748-1-hdanton@sina.com> <5f71e0c1-d387-6d72-d8e4-edb11cf57f72@linuxfoundation.org> <2b70d360-a293-4acb-ea6c-2badda5e8b8b@linuxfoundation.org> <9bdd3f10-bddb-bd87-d7ad-b4b706477006@i-love.sakura.ne.jp> <6b8da36f-a994-7604-77f4-52e29434605f@linuxfoundation.org> <5f9ec159-77d8-ffba-21d1-2810e059f998@i-love.sakura.ne.jp> <40617d66-1334-13a0-de9b-bd7cc1155ce5@i-love.sakura.ne.jp> <43d8d6bf-53f3-11e6-894d-c257f7f4bd07@linuxfoundation.org> From: Tetsuo Handa Message-ID: <4368349b-fc0c-6da3-a502-2733f953d271@i-love.sakura.ne.jp> Date: Thu, 11 Feb 2021 04:07:59 +0900 User-Agent: Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:78.0) Gecko/20100101 Thunderbird/78.7.0 MIME-Version: 1.0 In-Reply-To: <43d8d6bf-53f3-11e6-894d-c257f7f4bd07@linuxfoundation.org> Content-Type: text/plain; charset=utf-8 Content-Language: en-US Content-Transfer-Encoding: 7bit Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On 2021/02/11 3:17, Shuah Khan wrote: > I am looking to understand the syzbot configuration and a reproducer > to be able to debug and fix the problem. How is syzbot triggering the > vhci_hcd attach and detach sequence? I don't know. I'm waiting for syzbot to reproduce the problem on linux-next with https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/drivers/usb/usbip?id=f1bdf414e7dd0cbc26460425719fc3ea479947a2 . > > This helps me determine all these fix suggestions that are coming in > are fixes or papering over a real problem. What are these fix suggestions? "general protection fault in tomoyo_socket_sendmsg_permission" is a NULL pointer dereference which can happen if vhci_device_reset() and/or vhci_device_init() (which does vdev->ud.tcp_socket = NULL;) were unexpectedly called. There is no reproducer, and (as far as I know) no fix suggestion. "KASAN: null-ptr-deref Write in vhci_shutdown_connection" is an ERR_PTR(-EINTR) pointer dereference which can happen if kthread_create() was SIGKILLed. There is a reproducer, and https://lkml.kernel.org/r/20210205135707.4574-1-penguin-kernel@I-love.SAKURA.ne.jp is a fix suggestion.