Received: by 2002:a05:7412:8d09:b0:fa:4c10:6cad with SMTP id bj9csp176217rdb; Mon, 15 Jan 2024 17:15:40 -0800 (PST) X-Google-Smtp-Source: AGHT+IFpzdJnTes2zb6NjCr4oXNn96N6IZKCjB3nfBB/PLwIpeDxom30hOE+aK9gtFmlvtDur2bd X-Received: by 2002:a17:907:728a:b0:a2c:9fcb:b1b3 with SMTP id dt10-20020a170907728a00b00a2c9fcbb1b3mr3681781ejc.20.1705367740525; Mon, 15 Jan 2024 17:15:40 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1705367740; cv=none; d=google.com; s=arc-20160816; b=g7p9VX2uwRxRa8LT71chmQTZlTliHAAaZubJA6DzDm84ulZ5FTOE0tj7Ff/Dz8y4Ax QkslQ8S0fy33fJ5aGHlUpaJq0PMv+pVKrEiDpk+JFkrtucVZfRxEdipP0SiovIHjnT2T Xqu9EazjkKPI8b+lAdZDW/UiBVVyaU68GIIAB13NEK5SKLyJffz+hhMBmiEIOeFcCuKx PUt69Fg2hRDAiBvE8PW56jUL0eH5NhpI48xZQnyaML5l6CWwNSK0B6d29OrGwIEyjtin Qz0R42YRZGqNTqM7X6371KBUrY60AtBvC3La0pcaLhgdfqvLpk6+ld4VQd7U9RlBUK8F NALg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=content-transfer-encoding:mime-version:list-unsubscribe :list-subscribe:list-id:precedence:references:in-reply-to:date :subject:cc:to:from:message-id:dkim-signature; bh=AaWRhfFRqMRx8OraIcHJJr5JSRNlzcYHNh8VVa2Pf4o=; fh=KOBm+RVWGa5IGbyIIZbgWSLWhZqxMkUNFW5/rXvn0Bk=; b=h/EZ3IcKIPDg4NtqyGDJjjm6rWzEq27YQo9/ffgNOHo+8mE9IgkS5rgt7aI0Z3MfUC C4Ay8NNjY2uQxoK1bS9pbeFNYJsLvwH2yqjDq3fc3H/FnTwy/YKCTPDhp4WWfvudNXjM fTbqPm79pFk+DUyB9/BTzYSls6HOyBkUpeuHIiVRYoOaDO/ii34nPkbezqcO7Jhh0e4/ ebLNE403SF+fy+sBg1gvQkQr/8beYw/94YDEbKBIWdz9lezt5fRewJ9JH7wFC8UOsg4F Q9VERYx74xifClnobgAzr1/eH9dw8UlVYBtv7tIBhLIox46r7Sen6/o4xkkZ4FVmOKEt 78sQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@qq.com header.s=s201512 header.b=rqemMBSp; spf=pass (google.com: domain of linux-kernel+bounces-26808-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:4601:e00::3 as permitted sender) smtp.mailfrom="linux-kernel+bounces-26808-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=qq.com Return-Path: Received: from am.mirrors.kernel.org (am.mirrors.kernel.org. [2604:1380:4601:e00::3]) by mx.google.com with ESMTPS id u4-20020a17090626c400b00a279d254ae9si4297620ejc.23.2024.01.15.17.15.40 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 15 Jan 2024 17:15:40 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel+bounces-26808-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:4601:e00::3 as permitted sender) client-ip=2604:1380:4601:e00::3; Authentication-Results: mx.google.com; dkim=pass header.i=@qq.com header.s=s201512 header.b=rqemMBSp; spf=pass (google.com: domain of linux-kernel+bounces-26808-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:4601:e00::3 as permitted sender) smtp.mailfrom="linux-kernel+bounces-26808-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=qq.com Received: from smtp.subspace.kernel.org (wormhole.subspace.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by am.mirrors.kernel.org (Postfix) with ESMTPS id 2FBA31F23319 for ; Tue, 16 Jan 2024 01:15:40 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 1F6FA749F; Tue, 16 Jan 2024 00:51:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=qq.com header.i=@qq.com header.b="rqemMBSp" Received: from out162-62-57-49.mail.qq.com (out162-62-57-49.mail.qq.com [162.62.57.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0720779C0 for ; Tue, 16 Jan 2024 00:51:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=qq.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=qq.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qq.com; s=s201512; t=1705365989; bh=AaWRhfFRqMRx8OraIcHJJr5JSRNlzcYHNh8VVa2Pf4o=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=rqemMBSpE8A8BDhyCiAm+cpo2No+kJ68Ja1FazuJVNM4PC+xU8niAIOfMD9RDwsI4 GZQqOj6fRHmALmyKqFlbnqILTkzI+45oIzOZUPTJ1Q/cRAQmF3uefhSWm8/16GMHMM cjkunhJ0WtBZfGlKh9kbUJbffVJ8WSlG3zsbTZcM= Received: from pek-lxu-l1.wrs.com ([111.198.225.215]) by newxmesmtplogicsvrszb9-0.qq.com (NewEsmtp) with SMTP id B9B390FD; Tue, 16 Jan 2024 08:46:27 +0800 X-QQ-mid: xmsmtpt1705365987t46ebr0jl Message-ID: X-QQ-XMAILINFO: N26DAMVpW7UEELg1dy+GMZBv7LJgSjgJQ/S2AF4DiZ/3aw6QNPj3K5zURTibns QiZGucUVkN6bwHXpDT7RV13BTgDCG/6gB6n1IOKxuiFQQzbLPipNRnfNejGMgzJqDPJMtnc9RMe7 IO7Ggm/9NYSCPf0AJb/XuibU5L2rQum8AW/0Z7pAoFrcpm9X7/W46/oVhD4JD21chhF4CK18qhKJ boIaOcNMYv+f6rJ0Knz67UCLLUw8pNVxm7TCd58fddk+gB2bNSzMhZAGfojn2669kk279WCaPAvy +T2Mt+pEhvMfSvkN9ZklrIhz8GasYDEJCyUwV/mvbHoH1mSNG3nRpkSdUHhyS6pc4LsNlPht7FtP oOOaSaXXUmCvlOXJc3yrFYFldSzBAm3rD9Wn2+i2PRdmADrYqpMmOU2FL8opym0r2oXqa7iTSuzO 3bQd80iUq39GtaBkvlKgfpD3udp1KfdXewNi/vjSgEjVLeQJ+vl6nIBS2BcvTQ1EdLZUB75ZYOoh MbN8Z02uWB8ceQea/Cs5g8tfyiDFCOQ9pp5vWD2tf/ZJ1u9MWGHBEMv7DEcbn1ml0f8u7eRwZ8Di wiknBkZxPl3yqs780+xhbzt+oZDks08xf7VcTN94Qmlm37VoV1xDq0nieGDleB2Yn9nVN4APV2BW TvnGRSenmxdl2JyBbuoIpNU5ZWOIx4C0eCwSvjD07tkV5GViJ/boqO4FcYRd2Kgwwr7Hik5tYECD HUXy49ETrpCPR30+NsSBymK8dg+EoceXtKXupHwBgPALAx39t4/ju1/AINSYF0s8AQNRH8z3Qt2/ WvUyggNUgSQrteHqoimSHeUrnzYgKUmohYYBVAgEY+QwIhGen+UbOUw3M7c02ax9lT2C5pasFTMr y380tiLKRexueQQSS8d3IB31MATucCmSashmdT27oVBCupCFKoRU6onH9xtQvST+9p1+poYuKInx zn7c7m2Dw8KhuKS6fGAmUzoKJ1vIujgMcsY4Y78d/YF4JPOoZyHiONifjDxkZG X-QQ-XMRINFO: Nq+8W0+stu50PRdwbJxPCL0= From: Edward Adam Davis To: syzbot+33f23b49ac24f986c9e8@syzkaller.appspotmail.com Cc: linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com Subject: Re: [syzbot] [btrfs?] KASAN: slab-out-of-bounds Read in getname_kernel (2) Date: Tue, 16 Jan 2024 08:46:28 +0800 X-OQ-MSGID: <20240116004627.35201-2-eadavis@qq.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <000000000000d1a1d1060cc9c5e7@google.com> References: <000000000000d1a1d1060cc9c5e7@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit please test slab-out-of-bounds Read in getname_kernel #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git 3bd7d7488169 diff --git a/fs/btrfs/dev-replace.c b/fs/btrfs/dev-replace.c index 1502d664c892..fe6172707151 100644 --- a/fs/btrfs/dev-replace.c +++ b/fs/btrfs/dev-replace.c @@ -742,6 +742,7 @@ int btrfs_dev_replace_by_ioctl(struct btrfs_fs_info *fs_info, args->start.tgtdev_name[0] == '\0') return -EINVAL; + args->start.tgtdev_name[BTRFS_DEVICE_PATH_NAME_MAX] = '\0'; ret = btrfs_dev_replace_start(fs_info, args->start.tgtdev_name, args->start.srcdevid, args->start.srcdev_name,