From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id AA0E9C2BA1A for ; Mon, 17 Jun 2024 18:12:18 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 29AA36B026D; Mon, 17 Jun 2024 14:12:18 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 2490C6B026E; Mon, 17 Jun 2024 14:12:18 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 1106A6B026F; Mon, 17 Jun 2024 14:12:18 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0010.hostedemail.com [216.40.44.10]) by kanga.kvack.org (Postfix) with ESMTP id E7F4F6B026D for ; Mon, 17 Jun 2024 14:12:17 -0400 (EDT) Received: from smtpin13.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay04.hostedemail.com (Postfix) with ESMTP id 97CB71A198C for ; Mon, 17 Jun 2024 18:12:17 +0000 (UTC) X-FDA: 82241175114.13.2E6C084 Received: from out-172.mta1.migadu.com (out-172.mta1.migadu.com [95.215.58.172]) by imf21.hostedemail.com (Postfix) with ESMTP id D77A01C0016 for ; Mon, 17 Jun 2024 18:12:13 +0000 (UTC) Authentication-Results: imf21.hostedemail.com; dkim=pass header.d=linux.dev header.s=key1 header.b=aJTjXudC; spf=pass (imf21.hostedemail.com: domain of shakeel.butt@linux.dev designates 95.215.58.172 as permitted sender) smtp.mailfrom=shakeel.butt@linux.dev; dmarc=pass (policy=none) header.from=linux.dev ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1718647929; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=ZyPGVUBymB+/dAn/SDVvysy+ZYXiJ+churruGuGt89w=; b=ekc+3jD4Ev9sx37QceOKRJLJ+luHNntzCh77ABoyHwcAelCDeNveAVPH+kv25Gg2qMAWFe vBKevrBA2IrYEJWYvM0rGMS3cwPYO1qqRVVTeyPmcGizvni248zQdBJYUhBAxA58BNcxJu LS5cHeZcRPq/AATbeM/OjZDWPEl4FrE= ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1718647929; a=rsa-sha256; cv=none; b=5LzGS40461sl5WCFmUkoYjj0KuVitp6Uwv7JHMIRfMFIff1HLf5PmT2JESPzsoRubRp/x0 VXazbfZvohb5qFhheAxcWHLOd3NQ8RZv8Q85NtLy8vGj/4t6b99Rx3ltu58wm6Gk+h5oyi 4s0GVCtReM+/4CVwC20goWYwLPT460k= ARC-Authentication-Results: i=1; imf21.hostedemail.com; dkim=pass header.d=linux.dev header.s=key1 header.b=aJTjXudC; spf=pass (imf21.hostedemail.com: domain of shakeel.butt@linux.dev designates 95.215.58.172 as permitted sender) smtp.mailfrom=shakeel.butt@linux.dev; dmarc=pass (policy=none) header.from=linux.dev X-Envelope-To: yuzhao@google.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.dev; s=key1; t=1718647932; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=ZyPGVUBymB+/dAn/SDVvysy+ZYXiJ+churruGuGt89w=; b=aJTjXudCImxKiLB8FD+NmjoJnnfFghCAgJu+35izCvXsQzxLtmKnOG85hHMCmUXdY4HCkb 6B1QD4R4It4nCCx1dThpdNLqulhb4IQ6/Qd1q8KbKWaJfMURr56fqwjWW5J7d2JFkNvogZ 1CZWObta0v7hdTA7H+kVlFG78Bn7Jm4= X-Envelope-To: syzbot+12f0383f30f497b7f266@syzkaller.appspotmail.com X-Envelope-To: akpm@linux-foundation.org X-Envelope-To: linux-kernel@vger.kernel.org X-Envelope-To: linux-mm@kvack.org X-Envelope-To: syzkaller-bugs@googlegroups.com Date: Mon, 17 Jun 2024 11:12:06 -0700 X-Report-Abuse: Please report any abuse attempt to abuse@migadu.com and include these headers. From: Shakeel Butt To: Yu Zhao Cc: syzbot , akpm@linux-foundation.org, linux-kernel@vger.kernel.org, linux-mm@kvack.org, syzkaller-bugs@googlegroups.com Subject: Re: [syzbot] [mm?] KASAN: slab-use-after-free Read in folio_evictable (2) Message-ID: References: <000000000000c89573061af04607@google.com> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: X-Migadu-Flow: FLOW_OUT X-Stat-Signature: rp1bhtd5gasbmfmrcj1a3h1jegpifxfc X-Rspamd-Queue-Id: D77A01C0016 X-Rspam-User: X-Rspamd-Server: rspam08 X-HE-Tag: 1718647933-270565 X-HE-Meta: U2FsdGVkX18yGfwH70Y25WbpOC5DFRKV+lua18NjRQDoqaKt3Z4ott+6KjDG92Jgcdq3DsqWDWBjtfBg5p/lSA6UmnZYf4MnrCjGsIJw0hdMNApc+HpB+p2vclqA3IIjKyarhxwkPjMuazxDzDnbhRlYDJSqUpTOeX32szDLvDgvEGQxO2nKacRg5JP/9IiX/PoIs6PagTYtxIkL4R0c2HUe/ZHHTFolaQ89t3ziFlXe64xtmO7OO9ujm6VHY17o/JuRytb7Qt1QS3hO+Z/GGqS/12kdlIs8AZucBplgUBToig+IqUN5Tu0JR22bwxpE8xTY20Hr/tvddJG4sLze9sAD3X8PtKrB1BA1K52tsZQ6DrMbqoIczd3n4T1puRBcteboTWIg3wRGMVHQmbuPzUOjtGwOm+9z7xzx/zIMuLkqq2lHZlA9we+M+xwqMmfgnc9EyX9aXi9EYC7LjXInZzJOF8pDWrfzT3pzmFya0Zg5Z9sSYcaTCctB0WYMYzY4g/q9Kgs7oEar2IV/M1ZDf9NE4tF0rg6EOqPYwNzuBGz/6s7oSABKrbvwMfGnWH9FsiXYa/vUg3ZGmU0r2aQJwmSJDUW5Jo5TrGvqB66oI9nfiLJOqqZaDP+KdSqh2rZcX21pwz3IA9ArJz3qXHv6EBJazoAonGoubzLN7Dx+gasPJ3Adr3hnSpUFoOlAf+zfQ4ejANe7KkJCfFetViPqAR3I9ivbl3+6/GWIKSso7TlCDKqv/nosAleUmV7ELuSujiguvrsmj+MtUQ5St7dhAsgLISlqcSSaGFNcYadofPbgHJr8Cgb2G5RyQkmRRoP0So3cp/sk3QotLwgI5HuI7NhLaqD4fXWQKoWPfRQL+xpjRxioRd8sXKnkI6fPCrunL0n+2ymXp4arKewuTzg+PTo8/q860D7kwro1JVM7LavgtduQQlUWb+7bRoxdJDI7PR9mprrf2cECfcPyApr x1MgNBnr Lf959S0V648ehIE1sqqfxcrFN1dGOGNfF94TtB0DmBvOvnz0DSDTmwWNl0exLVptxc80BBCsOdND4xi9NmyYV8HcWdEF/tXyZX7BHSl6Xwgb7XuZtDJVFDyy54JhAuwlbnh7UVJcM+ZGidnBP9F+tLk12PSLndukkc/6H3xasWSvLvt/xRfDuZ4y3DrxEhSPMDg/39Xqkk06YmQLiF6gEY0Qw1KKQq6qnjuTiG3MPzGavSj6Q1E/rKjTsuHh61/PXGjZ74LEsSsKWwdDLF9Kw/bJ35ZX890CR0ritbHU+3LS8SKSCZlmBCm3y8pv1yoo/4vqsagbtT7HOTCAp0CRHZpg9XH/nN+N4by/lSqikSFTYznoCT7ki/0ToamaPDJg9099vvkL05Lcai7rR/gIHKgGx8wHCiBwmzMHwz8EqOOWnTcr6VDmodEK2qakZkPBCgBr+9utly8kQpPTbuwccP4OlnqeDX4i0I3nqin1KVawTjZ7/uFLqJyaHYvRUyoF8WSM4RL0zoG/s6i4rnUMTMkJdI6Wk0PPJ7qTo4lcqSig0IUH3Lss1qO1SXChQ9+Yv2pmXU04XKXgvIT0vGt47jqlRwTtEn+qZfo3sfPM6q1z0VJ5SiGp+XVV2kvFH98TS7QDLaFBUZpwZVFv7jbNimFRBAW2OJ2LANMp6AuowIP7NeTJq1IdN+sj34dAQ0JKlLmiKfljvMRPRVk3jvsyldD1l3AO9zOfm97LF3YNM8z55DD/VBiXXn0TV4Yqa2tgCvo4MQ0+xQd2fKvqxrBJSd66nySkOtuZ0WYvm X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: List-Subscribe: List-Unsubscribe: On Sun, Jun 16, 2024 at 08:19:59PM GMT, Yu Zhao wrote: > On Sat, Jun 15, 2024 at 11:42 AM syzbot > wrote: > > > > Hello, > > > > syzbot found the following issue on: > > > > HEAD commit: 2ef5971ff345 Merge tag 'vfs-6.10-rc4.fixes' of git://git.k.. > > git tree: upstream > > console output: https://syzkaller.appspot.com/x/log.txt?x=12873d96980000 > > kernel config: https://syzkaller.appspot.com/x/.config?x=81c0d76ceef02b39 > > dashboard link: https://syzkaller.appspot.com/bug?extid=12f0383f30f497b7f266 > > compiler: gcc (Debian 12.2.0-14) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40 > > userspace arch: i386 > > > > Unfortunately, I don't have any reproducer for this issue yet. > > > > Downloadable assets: > > disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/7bc7510fe41f/non_bootable_disk-2ef5971f.raw.xz > > vmlinux: https://storage.googleapis.com/syzbot-assets/85722ebc781d/vmlinux-2ef5971f.xz > > kernel image: https://storage.googleapis.com/syzbot-assets/27fd8bd02a1e/bzImage-2ef5971f.xz > > > > IMPORTANT: if you fix the issue, please add the following tag to the commit: > > Reported-by: syzbot+12f0383f30f497b7f266@syzkaller.appspotmail.com > > > > ================================================================== > > BUG: KASAN: slab-use-after-free in instrument_atomic_read include/linux/instrumented.h:68 [inline] > > BUG: KASAN: slab-use-after-free in _test_bit include/asm-generic/bitops/instrumented-non-atomic.h:141 [inline] > > BUG: KASAN: slab-use-after-free in mapping_unevictable include/linux/pagemap.h:259 [inline] > > BUG: KASAN: slab-use-after-free in folio_evictable+0x7b/0x270 mm/internal.h:353 > > Read of size 8 at addr ffff88804b68ab18 by task kswapd0/111 > > > > CPU: 3 PID: 111 Comm: kswapd0 Not tainted 6.10.0-rc3-syzkaller-00021-g2ef5971ff345 #0 > > Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014 > > Call Trace: > > > > __dump_stack lib/dump_stack.c:88 [inline] > > dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:114 > > print_address_description mm/kasan/report.c:377 [inline] > > print_report+0xc3/0x620 mm/kasan/report.c:488 > > kasan_report+0xd9/0x110 mm/kasan/report.c:601 > > check_region_inline mm/kasan/generic.c:183 [inline] > > kasan_check_range+0xef/0x1a0 mm/kasan/generic.c:189 > > instrument_atomic_read include/linux/instrumented.h:68 [inline] > > _test_bit include/asm-generic/bitops/instrumented-non-atomic.h:141 [inline] > > mapping_unevictable include/linux/pagemap.h:259 [inline] > > The memory folio->mapping pointed to was RCU freed and > mapping_unevictable() was under the RCU read lock. > > So probably the owner of that folio forgot to clear the mapping? > This seems like duplicate of another syzbot report at https://lore.kernel.org/all/0000000000008874480617ff1bad@google.com/T/ and https://lore.kernel.org/all/20240614131856.754-1-hdanton@sina.com/T/ #syz dup: [syzbot] [mm?] KASAN: slab-use-after-free Read in lru_add_fn