diff options
| author | Andrey Konovalov <andreyknvl@google.com> | 2020-03-19 16:05:37 +0100 |
|---|---|---|
| committer | Dmitry Vyukov <dvyukov@google.com> | 2020-03-21 08:13:09 +0100 |
| commit | 4288d95ef649c8e8e589319e4da2d90589cb8314 (patch) | |
| tree | 3f8cf4a3791a11030cc6b2f77b333c24a08416a0 /pkg/report/testdata/linux | |
| parent | aa6c6a5572a4797ea6109a75ca50a2c86908375e (diff) | |
pkg/report: improve report titles
Diffstat (limited to 'pkg/report/testdata/linux')
| -rw-r--r-- | pkg/report/testdata/linux/report/473 | 81 | ||||
| -rw-r--r-- | pkg/report/testdata/linux/report/474 | 94 | ||||
| -rw-r--r-- | pkg/report/testdata/linux/report/475 | 144 | ||||
| -rw-r--r-- | pkg/report/testdata/linux/report/476 | 93 | ||||
| -rw-r--r-- | pkg/report/testdata/linux/report/477 | 73 | ||||
| -rw-r--r-- | pkg/report/testdata/linux/report/478 | 147 |
6 files changed, 632 insertions, 0 deletions
diff --git a/pkg/report/testdata/linux/report/473 b/pkg/report/testdata/linux/report/473 new file mode 100644 index 000000000..222e5aedb --- /dev/null +++ b/pkg/report/testdata/linux/report/473 @@ -0,0 +1,81 @@ +TITLE: WARNING: refcount bug in htc_connect_service + +[ 347.999844][ T4270] ------------[ cut here ]------------ +[ 348.000384][ T78] steelseries_srws1 0003:1038:1410.00A7: unknown main item tag 0x0 +[ 348.001259][ T4270] refcount_t: underflow; use-after-free. +[ 348.001333][ T4270] WARNING: CPU: 0 PID: 4270 at lib/refcount.c:28 refcount_warn_saturate+0x1d1/0x1e0 +[ 348.002004][ T78] steelseries_srws1 0003:1038:1410.00A7: unknown main item tag 0x0 +[ 348.002964][ T4270] Kernel panic - not syncing: panic_on_warn set ... +[ 348.003632][ T78] steelseries_srws1 0003:1038:1410.00A7: unknown main item tag 0x0 +[ 348.005581][ T4270] CPU: 0 PID: 4270 Comm: kworker/0:12 Not tainted 5.6.0-rc6+ #153 +[ 348.006253][ T78] steelseries_srws1 0003:1038:1410.00A7: unknown main item tag 0x0 +[ 348.008405][ T4270] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014 +[ 348.008422][ T4270] Workqueue: events request_firmware_work_func +[ 348.017246][ T78] steelseries_srws1 0003:1038:1410.00A7: unknown main item tag 0x0 +[ 348.017956][ T4270] Call Trace: +[ 348.017971][ T4270] dump_stack+0xef/0x16e +[ 348.017979][ T4270] ? refcount_warn_saturate+0xf0/0x1e0 +[ 348.017985][ T4270] panic+0x2aa/0x6e1 +[ 348.017990][ T4270] ? add_taint.cold+0x16/0x16 +[ 348.017998][ T4270] ? __probe_kernel_read+0x188/0x1d0 +[ 348.018002][ T4270] ? __warn.cold+0x14/0x30 +[ 348.018008][ T4270] ? refcount_warn_saturate+0x1d1/0x1e0 +[ 348.018012][ T4270] __warn.cold+0x2f/0x30 +[ 348.018025][ T4270] ? refcount_warn_saturate+0x1d1/0x1e0 +[ 348.018036][ T4270] report_bug+0x28a/0x2f0 +[ 348.020428][ T78] steelseries_srws1 0003:1038:1410.00A7: unknown main item tag 0x0 +[ 348.021402][ T4270] do_error_trap+0x12b/0x1e0 +[ 348.021408][ T4270] ? refcount_warn_saturate+0x1d1/0x1e0 +[ 348.021413][ T4270] do_invalid_op+0x32/0x40 +[ 348.021530][ T4270] ? refcount_warn_saturate+0x1d1/0x1e0 +[ 348.024097][ T78] steelseries_srws1 0003:1038:1410.00A7: unknown main item tag 0x0 +[ 348.025509][ T4270] invalid_op+0x23/0x30 +[ 348.025522][ T4270] RIP: 0010:refcount_warn_saturate+0x1d1/0x1e0 +[ 348.027955][ T78] steelseries_srws1 0003:1038:1410.00A7: unknown main item tag 0x0 +[ 348.028903][ T4270] Code: e9 db fe ff ff 48 89 df e8 7c bf 7f ff e9 8a fe ff ff e8 d2 06 57 ff 48 c7 c7 40 ee fb 85 c6 05 60 48 f3 05 01 e8 57 6b 2b ff <0f> 0b e9 af fe ff ff 0f 1f 84 00 00 00 00 00 48 b8 00 00 00 00 00 +[ 348.028907][ T4270] RSP: 0018:ffff88806732f8d0 EFLAGS: 00010282 +[ 348.028912][ T4270] RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000000 +[ 348.028916][ T4270] RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffed100ce65f0c +[ 348.028920][ T4270] RBP: 0000000000000003 R08: ffff888045bb5e80 R09: ffffed100d94439f +[ 348.028923][ T4270] R10: ffffed100d94439e R11: ffff88806ca21cf3 R12: ffff8880614fa5d4 +[ 348.028927][ T4270] R13: 00000000ffffff92 R14: ffff8880429d9000 R15: ffff8880614fa500 +[ 348.028937][ T4270] kfree_skb+0x313/0x3d0 +[ 348.028950][ T4270] htc_connect_service.cold+0xa9/0x109 +[ 348.029348][ T78] steelseries_srws1 0003:1038:1410.00A7: unknown main item tag 0x0 +[ 348.029850][ T4270] ath9k_wmi_connect+0xd2/0x1a0 +[ 348.029856][ T4270] ? ath9k_fatal_work+0x20/0x20 +[ 348.029862][ T4270] ? ath9k_hif_usb_firmware_cb.cold+0xde/0xde +[ 348.029867][ T4270] ? ath9k_wmi_event_tasklet+0x430/0x430 +[ 348.029874][ T4270] ath9k_init_htc_services.constprop.0+0xb4/0x650 +[ 348.029881][ T4270] ? ath9k_htc_wait_for_target.isra.0+0x1b0/0x1b0 +[ 348.029888][ T4270] ? lockdep_init_map+0x1b0/0x5e0 +[ 348.029894][ T4270] ? lockdep_init_map+0x1b0/0x5e0 +[ 348.029901][ T4270] ? tasklet_init+0x69/0x110 +[ 348.029913][ T4270] ath9k_htc_probe_device+0x25a/0x1d80 +[ 348.031985][ T78] steelseries_srws1 0003:1038:1410.00A7: unknown main item tag 0x0 +[ 348.032890][ T4270] ? ath9k_init_htc_services.constprop.0+0x650/0x650 +[ 348.032937][ T4270] ? usb_submit_urb+0x6ed/0x1460 +[ 348.033497][ T78] steelseries_srws1 0003:1038:1410.00A7: unknown main item tag 0x0 +[ 348.034710][ T4270] ? usb_free_urb.part.0+0x52/0x110 +[ 348.036226][ T78] steelseries_srws1 0003:1038:1410.00A7: unknown main item tag 0x0 +[ 348.037306][ T4270] ? usb_free_urb+0x1b/0x30 +[ 348.037314][ T4270] ath9k_htc_hw_init+0x31/0x60 +[ 348.037320][ T4270] ath9k_hif_usb_firmware_cb+0x26b/0x500 +[ 348.037326][ T4270] ? ath9k_hif_usb_resume+0x320/0x320 +[ 348.037334][ T4270] request_firmware_work_func+0x126/0x242 +[ 348.037340][ T4270] ? request_firmware_into_buf+0x90/0x90 +[ 348.037348][ T4270] ? rcu_read_lock_sched_held+0x9c/0xd0 +[ 348.037395][ T4270] ? rcu_read_lock_bh_held+0xb0/0xb0 +[ 348.038174][ T78] steelseries_srws1 0003:1038:1410.00A7: unknown main item tag 0x0 +[ 348.038788][ T4270] process_one_work+0x94b/0x1620 +[ 348.038795][ T4270] ? pwq_dec_nr_in_flight+0x310/0x310 +[ 348.038801][ T4270] ? do_raw_spin_lock+0x129/0x290 +[ 348.038848][ T4270] worker_thread+0x96/0xe20 +[ 348.038855][ T4270] ? process_one_work+0x1620/0x1620 +[ 348.038861][ T4270] kthread+0x318/0x420 +[ 348.038866][ T4270] ? kthread_create_on_node+0xf0/0xf0 +[ 348.038874][ T4270] ret_from_fork+0x24/0x30 +[ 348.039759][ T4270] Dumping ftrace buffer: +[ 348.039817][ T4270] (ftrace buffer empty) +[ 348.039821][ T4270] Kernel Offset: disabled +[ 348.102324][ T4270] Rebooting in 1 seconds.. diff --git a/pkg/report/testdata/linux/report/474 b/pkg/report/testdata/linux/report/474 new file mode 100644 index 000000000..c6b149b3c --- /dev/null +++ b/pkg/report/testdata/linux/report/474 @@ -0,0 +1,94 @@ +TITLE: WARNING in tcf_exts_destroy + +[ 85.150823][ T9436] ------------[ cut here ]------------ +[ 85.156312][ T9436] virt_to_cache: Object is not a Slab page! +[ 85.162424][ T9436] WARNING: CPU: 1 PID: 9436 at mm/slab.h:473 kfree+0x1cf/0x2b0 +[ 85.169953][ T9436] Kernel panic - not syncing: panic_on_warn set ... +[ 85.176545][ T9436] CPU: 1 PID: 9436 Comm: syz-executor.0 Not tainted 5.6.0-rc5-syzkaller #0 +[ 85.185117][ T9436] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011 +[ 85.195148][ T9436] Call Trace: +[ 85.198423][ T9436] dump_stack+0x188/0x20d +[ 85.202736][ T9436] ? kfree+0x170/0x2b0 +[ 85.206790][ T9436] panic+0x2e3/0x75c +[ 85.210770][ T9436] ? add_taint.cold+0x16/0x16 +[ 85.215439][ T9436] ? __probe_kernel_read+0x188/0x1d0 +[ 85.220701][ T9436] ? __warn.cold+0x14/0x35 +[ 85.225091][ T9436] ? __warn+0xd5/0x1c8 +[ 85.229178][ T9436] ? kfree+0x1cf/0x2b0 +[ 85.233226][ T9436] __warn.cold+0x2f/0x35 +[ 85.237442][ T9436] ? irq_work_queue+0xd2/0x100 +[ 85.242182][ T9436] ? kfree+0x1cf/0x2b0 +[ 85.246231][ T9436] report_bug+0x27b/0x2f0 +[ 85.250555][ T9436] do_error_trap+0x12b/0x220 +[ 85.255135][ T9436] ? kfree+0x1cf/0x2b0 +[ 85.259183][ T9436] do_invalid_op+0x32/0x40 +[ 85.263575][ T9436] ? kfree+0x1cf/0x2b0 +[ 85.267619][ T9436] invalid_op+0x23/0x30 +[ 85.271793][ T9436] RIP: 0010:kfree+0x1cf/0x2b0 +[ 85.276448][ T9436] Code: 51 ff e9 67 fe ff ff 80 3d 8a a4 b2 08 00 75 1c 48 c7 c6 40 52 15 88 48 c7 c7 e8 03 26 89 c6 05 73 a4 b2 08 01 e8 b9 9f 95 ff <0f> 0b f6 c7 02 75 6b 48 83 3d 52 2e c5 07 00 0f 85 4e ff ff ff 0f +[ 85.296040][ T9436] RSP: 0018:ffffc900020e7030 EFLAGS: 00010082 +[ 85.302084][ T9436] RAX: 0000000000000000 RBX: 0000000000000282 RCX: 0000000000000000 +[ 85.310035][ T9436] RDX: 0000000000000000 RSI: ffffffff815bf4f1 RDI: fffff5200041cdf8 +[ 85.317992][ T9436] RBP: ffffffff8c3f7080 R08: ffff88808e97c600 R09: ffffed1015ce45c9 +[ 85.326068][ T9436] R10: ffffed1015ce45c8 R11: ffff8880ae722e43 R12: ffffffff8628c202 +[ 85.334020][ T9436] R13: dffffc0000000000 R14: ffff8880a0069c10 R15: 0000000000000000 +[ 85.341983][ T9436] ? tcf_exts_destroy+0x62/0xc0 +[ 85.346820][ T9436] ? vprintk_func+0x81/0x17e +[ 85.351400][ T9436] tcf_exts_destroy+0x62/0xc0 +[ 85.356053][ T9436] tcf_exts_change+0xf4/0x150 +[ 85.360718][ T9436] ? tcf_exts_destroy+0xc0/0xc0 +[ 85.365568][ T9436] tcindex_set_parms+0xed8/0x1a00 +[ 85.370644][ T9436] ? tcindex_alloc_perfect_hash+0x320/0x320 +[ 85.376531][ T9436] ? mark_held_locks+0xe0/0xe0 +[ 85.381453][ T9436] ? nla_memcpy+0xa0/0xa0 +[ 85.385767][ T9436] ? tcindex_change+0x203/0x2e0 +[ 85.390595][ T9436] tcindex_change+0x203/0x2e0 +[ 85.395255][ T9436] ? tcindex_set_parms+0x1a00/0x1a00 +[ 85.400536][ T9436] tc_new_tfilter+0xa59/0x20b0 +[ 85.405283][ T9436] ? tcindex_set_parms+0x1a00/0x1a00 +[ 85.410553][ T9436] ? tc_del_tfilter+0x1430/0x1430 +[ 85.415570][ T9436] ? __lock_acquire+0x80b/0x3ca0 +[ 85.420498][ T9436] ? apparmor_capable+0x454/0x8a0 +[ 85.425514][ T9436] ? rcu_read_lock_held+0x9c/0xb0 +[ 85.430524][ T9436] ? tc_del_tfilter+0x1430/0x1430 +[ 85.435534][ T9436] rtnetlink_rcv_msg+0x810/0xad0 +[ 85.440505][ T9436] ? rtnl_bridge_getlink+0x880/0x880 +[ 85.445772][ T9436] ? netdev_core_pick_tx+0x2e0/0x2e0 +[ 85.451035][ T9436] ? __copy_skb_header+0x210/0x5b0 +[ 85.456138][ T9436] ? skb_splice_bits+0x1a0/0x1a0 +[ 85.461421][ T9436] ? __kasan_kmalloc.constprop.0+0xbf/0xd0 +[ 85.467319][ T9436] ? kmem_cache_alloc+0x261/0x730 +[ 85.472325][ T9436] netlink_rcv_skb+0x15a/0x410 +[ 85.477067][ T9436] ? rtnl_bridge_getlink+0x880/0x880 +[ 85.482439][ T9436] ? netlink_ack+0xa80/0xa80 +[ 85.487019][ T9436] netlink_unicast+0x537/0x740 +[ 85.491772][ T9436] ? netlink_attachskb+0x810/0x810 +[ 85.496875][ T9436] ? _copy_from_iter_full+0x25c/0x870 +[ 85.502233][ T9436] ? __phys_addr_symbol+0x2c/0x70 +[ 85.507287][ T9436] ? __check_object_size+0x171/0x437 +[ 85.512716][ T9436] netlink_sendmsg+0x882/0xe10 +[ 85.517472][ T9436] ? aa_af_perm+0x260/0x260 +[ 85.521954][ T9436] ? netlink_unicast+0x740/0x740 +[ 85.526880][ T9436] ? netlink_unicast+0x740/0x740 +[ 85.531818][ T9436] sock_sendmsg+0xcf/0x120 +[ 85.536282][ T9436] ____sys_sendmsg+0x6b9/0x7d0 +[ 85.541029][ T9436] ? kernel_sendmsg+0x50/0x50 +[ 85.545690][ T9436] ? mark_lock+0xbc/0x1220 +[ 85.550117][ T9436] ___sys_sendmsg+0x100/0x170 +[ 85.554780][ T9436] ? sendmsg_copy_msghdr+0x70/0x70 +[ 85.559871][ T9436] ? find_held_lock+0x2d/0x110 +[ 85.564617][ T9436] ? find_held_lock+0x2d/0x110 +[ 85.569369][ T9436] ? __might_fault+0x11f/0x1d0 +[ 85.574124][ T9436] ? lock_downgrade+0x7f0/0x7f0 +[ 85.578955][ T9436] ? lock_acquire+0x197/0x420 +[ 85.583608][ T9436] ? __might_fault+0xef/0x1d0 +[ 85.588269][ T9436] ? __fget_light+0x1a5/0x270 +[ 85.592933][ T9436] __sys_sendmsg+0xec/0x1b0 +[ 85.597415][ T9436] ? __sys_sendmsg_sock+0xb0/0xb0 +[ 85.602443][ T9436] ? __ia32_sys_futex_time32+0x32a/0x494 +[ 85.608065][ T9436] ? trace_hardirqs_off_caller+0x55/0x230 +[ 85.613764][ T9436] ? do_fast_syscall_32+0xcc/0xe8f +[ 85.618942][ T9436] do_fast_syscall_32+0x270/0xe8f +[ 85.623950][ T9436] entry_SYSENTER_compat+0x70/0x7f +[ 85.630452][ T9436] Kernel Offset: disabled +[ 85.634771][ T9436] Rebooting in 86400 seconds.. diff --git a/pkg/report/testdata/linux/report/475 b/pkg/report/testdata/linux/report/475 new file mode 100644 index 000000000..54b578bab --- /dev/null +++ b/pkg/report/testdata/linux/report/475 @@ -0,0 +1,144 @@ +TITLE: KASAN: use-after-free Read in ip6_fragment + +[ 78.614475][ T8947] ================================================================== +[ 78.622699][ T8947] BUG: KASAN: use-after-free in kfree_skb_list+0x5d/0x60 +[ 78.629722][ T8947] Read of size 8 at addr ffff888085a3cbc0 by task syz-executor303/8947 +[ 78.637952][ T8947] +[ 78.640287][ T8947] CPU: 0 PID: 8947 Comm: syz-executor303 Not tainted 5.2.0-rc2+ #12 +[ 78.648280][ T8947] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011 +[ 78.658341][ T8947] Call Trace: +[ 78.661643][ T8947] dump_stack+0x172/0x1f0 +[ 78.665982][ T8947] ? kfree_skb_list+0x5d/0x60 +[ 78.670671][ T8947] print_address_description.cold+0x7c/0x20d +[ 78.676659][ T8947] ? kfree_skb_list+0x5d/0x60 +[ 78.681387][ T8947] ? kfree_skb_list+0x5d/0x60 +[ 78.686072][ T8947] __kasan_report.cold+0x1b/0x40 +[ 78.691009][ T8947] ? lockdep_hardirqs_on+0x3d0/0x5d0 +[ 78.696297][ T8947] ? kfree_skb_list+0x5d/0x60 +[ 78.700988][ T8947] kasan_report+0x12/0x20 +[ 78.705327][ T8947] __asan_report_load8_noabort+0x14/0x20 +[ 78.710965][ T8947] kfree_skb_list+0x5d/0x60 +[ 78.715481][ T8947] ip6_fragment+0x1ef4/0x2680 +[ 78.720201][ T8947] ? mark_held_locks+0xf0/0xf0 +[ 78.725014][ T8947] ? ip6_forward_finish+0x570/0x570 +[ 78.730245][ T8947] ? ip6_forward+0x3870/0x3870 +[ 78.735019][ T8947] ? ip6_mtu+0x2e6/0x460 +[ 78.739280][ T8947] ? lock_downgrade+0x880/0x880 +[ 78.744150][ T8947] ? __sanitizer_cov_trace_const_cmp4+0x16/0x20 +[ 78.750435][ T8947] ? kasan_check_read+0x11/0x20 +[ 78.755310][ T8947] __ip6_finish_output+0x577/0xaa0 +[ 78.760450][ T8947] ip6_finish_output+0x38/0x1f0 +[ 78.765319][ T8947] ip6_output+0x235/0x7f0 +[ 78.769660][ T8947] ? ip6_finish_output+0x1f0/0x1f0 +[ 78.774785][ T8947] ? __ip6_finish_output+0xaa0/0xaa0 +[ 78.780083][ T8947] ? ip6_autoflowlabel.part.0+0x70/0x70 +[ 78.785636][ T8947] ip6_local_out+0xbb/0x1b0 +[ 78.790178][ T8947] ip6_send_skb+0xbb/0x350 +[ 78.794614][ T8947] ip6_push_pending_frames+0xc8/0xf0 +[ 78.799906][ T8947] rawv6_sendmsg+0x2993/0x35e0 +[ 78.804687][ T8947] ? rawv6_getsockopt+0x150/0x150 +[ 78.809713][ T8947] ? aa_profile_af_perm+0x320/0x320 +[ 78.814913][ T8947] ? tomoyo_check_inet_address+0xf7/0x740 +[ 78.820640][ T8947] ? tomoyo_unix_entry+0x5d0/0x5d0 +[ 78.825757][ T8947] ? __sanitizer_cov_trace_cmp8+0x18/0x20 +[ 78.831481][ T8947] ? rw_copy_check_uvector+0x2a6/0x330 +[ 78.836969][ T8947] ? ___might_sleep+0x163/0x280 +[ 78.841843][ T8947] ? __might_sleep+0x95/0x190 +[ 78.846544][ T8947] ? aa_sock_msg_perm.isra.0+0xba/0x170 +[ 78.852100][ T8947] inet_sendmsg+0x141/0x5d0 +[ 78.856601][ T8947] ? inet_sendmsg+0x141/0x5d0 +[ 78.861285][ T8947] ? ipip_gro_receive+0x100/0x100 +[ 78.866319][ T8947] sock_sendmsg+0xd7/0x130 +[ 78.870748][ T8947] ___sys_sendmsg+0x803/0x920 +[ 78.875431][ T8947] ? copy_msghdr_from_user+0x430/0x430 +[ 78.880909][ T8947] ? lock_downgrade+0x880/0x880 +[ 78.885770][ T8947] ? __sanitizer_cov_trace_const_cmp4+0x16/0x20 +[ 78.892022][ T8947] ? kasan_check_read+0x11/0x20 +[ 78.896881][ T8947] ? __fget+0x381/0x550 +[ 78.901060][ T8947] ? __fget_light+0x1a9/0x230 +[ 78.905757][ T8947] ? __fdget+0x1b/0x20 +[ 78.909838][ T8947] ? __sanitizer_cov_trace_const_cmp8+0x18/0x20 +[ 78.916093][ T8947] __sys_sendmsg+0x105/0x1d0 +[ 78.920694][ T8947] ? __ia32_sys_shutdown+0x80/0x80 +[ 78.925811][ T8947] ? __sanitizer_cov_trace_const_cmp4+0x16/0x20 +[ 78.932068][ T8947] ? trace_hardirqs_on_thunk+0x1a/0x1c +[ 78.937541][ T8947] ? do_syscall_64+0x26/0x680 +[ 78.942233][ T8947] ? entry_SYSCALL_64_after_hwframe+0x49/0xbe +[ 78.948328][ T8947] ? do_syscall_64+0x26/0x680 +[ 78.953042][ T8947] __x64_sys_sendmsg+0x78/0xb0 +[ 78.957841][ T8947] do_syscall_64+0xfd/0x680 +[ 78.962358][ T8947] entry_SYSCALL_64_after_hwframe+0x49/0xbe +[ 78.968274][ T8947] RIP: 0033:0x44add9 +[ 78.972197][ T8947] Code: e8 7c e6 ff ff 48 83 c4 18 c3 0f 1f 80 00 00 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 0f 83 1b 05 fc ff c3 66 2e 0f 1f 84 00 00 00 00 +[ 78.991824][ T8947] RSP: 002b:00007f826f33bce8 EFLAGS: 00000246 ORIG_RAX: 000000000000002e +[ 79.000241][ T8947] RAX: ffffffffffffffda RBX: 00000000006e7a18 RCX: 000000000044add9 +executing program +[ 79.009736][ T8947] RDX: 0000000000000000 RSI: 0000000020000240 RDI: 0000000000000005 +[ 79.017709][ T8947] RBP: 00000000006e7a10 R08: 0000000000000000 R09: 0000000000000000 +[ 79.025681][ T8947] R10: 0000000000000000 R11: 0000000000000246 R12: 00000000006e7a1c +[ 79.033654][ T8947] R13: 00007ffcec4f7ebf R14: 00007f826f33c9c0 R15: 20c49ba5e353f7cf +[ 79.041641][ T8947] +[ 79.043974][ T8947] Allocated by task 8947: +[ 79.048324][ T8947] save_stack+0x23/0x90 +[ 79.052482][ T8947] __kasan_kmalloc.constprop.0+0xcf/0xe0 +[ 79.058114][ T8947] kasan_slab_alloc+0xf/0x20 +[ 79.062719][ T8947] kmem_cache_alloc_node+0x131/0x710 +[ 79.068123][ T8947] __alloc_skb+0xd5/0x5e0 +[ 79.072468][ T8947] __ip6_append_data.isra.0+0x2a24/0x3640 +[ 79.078199][ T8947] ip6_append_data+0x1e5/0x320 +[ 79.082964][ T8947] rawv6_sendmsg+0x1467/0x35e0 +[ 79.087730][ T8947] inet_sendmsg+0x141/0x5d0 +[ 79.092237][ T8947] sock_sendmsg+0xd7/0x130 +[ 79.096674][ T8947] ___sys_sendmsg+0x803/0x920 +[ 79.101353][ T8947] __sys_sendmsg+0x105/0x1d0 +[ 79.105947][ T8947] __x64_sys_sendmsg+0x78/0xb0 +[ 79.110736][ T8947] do_syscall_64+0xfd/0x680 +[ 79.115240][ T8947] entry_SYSCALL_64_after_hwframe+0x49/0xbe +[ 79.121132][ T8947] +[ 79.123465][ T8947] Freed by task 8947: +[ 79.127452][ T8947] save_stack+0x23/0x90 +[ 79.131600][ T8947] __kasan_slab_free+0x102/0x150 +[ 79.136574][ T8947] kasan_slab_free+0xe/0x10 +[ 79.141067][ T8947] kmem_cache_free+0x86/0x260 +[ 79.145724][ T8947] kfree_skbmem+0xc5/0x150 +[ 79.150134][ T8947] kfree_skb+0xf0/0x390 +[ 79.154298][ T8947] kfree_skb_list+0x44/0x60 +[ 79.158808][ T8947] __dev_queue_xmit+0x3034/0x36b0 +[ 79.163835][ T8947] dev_queue_xmit+0x18/0x20 +[ 79.168348][ T8947] neigh_direct_output+0x16/0x20 +[ 79.173293][ T8947] ip6_finish_output2+0x1034/0x2550 +[ 79.178498][ T8947] ip6_fragment+0x1ebb/0x2680 +[ 79.183190][ T8947] __ip6_finish_output+0x577/0xaa0 +[ 79.188297][ T8947] ip6_finish_output+0x38/0x1f0 +[ 79.193160][ T8947] ip6_output+0x235/0x7f0 +[ 79.197491][ T8947] ip6_local_out+0xbb/0x1b0 +[ 79.201985][ T8947] ip6_send_skb+0xbb/0x350 +[ 79.206400][ T8947] ip6_push_pending_frames+0xc8/0xf0 +[ 79.211675][ T8947] rawv6_sendmsg+0x2993/0x35e0 +[ 79.216447][ T8947] inet_sendmsg+0x141/0x5d0 +[ 79.220940][ T8947] sock_sendmsg+0xd7/0x130 +[ 79.225384][ T8947] ___sys_sendmsg+0x803/0x920 +[ 79.230049][ T8947] __sys_sendmsg+0x105/0x1d0 +[ 79.234632][ T8947] __x64_sys_sendmsg+0x78/0xb0 +[ 79.239410][ T8947] do_syscall_64+0xfd/0x680 +[ 79.243915][ T8947] entry_SYSCALL_64_after_hwframe+0x49/0xbe +[ 79.249798][ T8947] +[ 79.252118][ T8947] The buggy address belongs to the object at ffff888085a3cbc0 +[ 79.252118][ T8947] which belongs to the cache skbuff_head_cache of size 224 +[ 79.266696][ T8947] The buggy address is located 0 bytes inside of +[ 79.266696][ T8947] 224-byte region [ffff888085a3cbc0, ffff888085a3cca0) +[ 79.279789][ T8947] The buggy address belongs to the page: +[ 79.285404][ T8947] page:ffffea0002168f00 refcount:1 mapcount:0 mapping:ffff88821b6f63c0 index:0x0 +[ 79.294499][ T8947] flags: 0x1fffc0000000200(slab) +[ 79.299476][ T8947] raw: 01fffc0000000200 ffffea00027bbf88 ffffea0002105b88 ffff88821b6f63c0 +[ 79.308061][ T8947] raw: 0000000000000000 ffff888085a3c080 000000010000000c 0000000000000000 +[ 79.316644][ T8947] page dumped because: kasan: bad access detected +[ 79.323037][ T8947] +[ 79.325351][ T8947] Memory state around the buggy address: +[ 79.330975][ T8947] ffff888085a3ca80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 +[ 79.339204][ T8947] ffff888085a3cb00: 00 00 00 00 00 00 00 00 00 00 00 00 fc fc fc fc +[ 79.347245][ T8947] >ffff888085a3cb80: fc fc fc fc fc fc fc fc fb fb fb fb fb fb fb fb +[ 79.355321][ T8947] ^ +[ 79.361473][ T8947] ffff888085a3cc00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb +[ 79.369580][ T8947] ffff888085a3cc80: fb fb fb fb fc fc fc fc fc fc fc fc fc fc fc fc +[ 79.377631][ T8947] ================================================================== diff --git a/pkg/report/testdata/linux/report/476 b/pkg/report/testdata/linux/report/476 new file mode 100644 index 000000000..2c4d39301 --- /dev/null +++ b/pkg/report/testdata/linux/report/476 @@ -0,0 +1,93 @@ +TITLE: BUG: unable to handle kernel paging request in audit_data_to_entry + +[ 17.577241][ T1878] BUG: unable to handle page fault for address: ffffebde00002008 +[ 17.586014][ T1878] #PF: supervisor read access in kernel mode +[ 17.587766][ T1878] #PF: error_code(0x0000) - not-present page +[ 17.590010][ T1878] PGD 0 P4D 0 +[ 17.591204][ T1878] Oops: 0000 [#1] PREEMPT SMP KASAN +[ 17.592783][ T1878] CPU: 0 PID: 1878 Comm: syz-executor105 Not tainted 5.4.22-syzkaller-01097-gc6059ac63293 #0 +[ 17.595604][ T1878] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011 +[ 17.605746][ T1878] RIP: 0010:kfree+0xd6/0x6d0 +[ 17.610325][ T1878] Code: f0 02 eb 0a 48 bb 00 00 00 80 7f 77 00 00 4c 01 e3 48 81 eb 00 00 00 80 48 c1 eb 06 48 83 e3 c0 48 b9 00 00 00 00 00 ea ff ff <48> 8b 44 0b 08 a8 01 0f 85 a9 01 00 00 48 01 cb 48 8b 43 08 48 89 +[ 17.630106][ T1878] RSP: 0018:ffff8881d0dc7278 EFLAGS: 00010206 +[ 17.636288][ T1878] RAX: ffffffff7fffffff RBX: 000001de00002000 RCX: ffffea0000000000 +[ 17.644368][ T1878] RDX: 0000000000000000 RSI: ffffffff84648d30 RDI: 0000000000080000 +[ 17.652425][ T1878] RBP: ffff8881d0dc72f0 R08: 0000000000000005 R09: ffffffff8140b355 +[ 17.660392][ T1878] R10: ffff8881d1868000 R11: 000000000000000a R12: 0000000000080000 +[ 17.668379][ T1878] R13: ffff8881d310e000 R14: ffffffff8140b3ec R15: 0000000000000001 +[ 17.676486][ T1878] FS: 000000000104c880(0000) GS:ffff8881dba00000(0000) knlGS:0000000000000000 +[ 17.685504][ T1878] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 +[ 17.692079][ T1878] CR2: ffffebde00002008 CR3: 00000001d4f89002 CR4: 00000000001606f0 +[ 17.700191][ T1878] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 +[ 17.708170][ T1878] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 +[ 17.716210][ T1878] Call Trace: +[ 17.719613][ T1878] ? audit_data_to_entry+0x225c/0x26c0 +[ 17.725080][ T1878] ? audit_unpack_string+0x92/0x1b0 +[ 17.730268][ T1878] audit_data_to_entry+0x225c/0x26c0 +[ 17.735536][ T1878] ? audit_rule_change+0x1110/0x1110 +[ 17.740968][ T1878] ? unwind_next_frame+0x415/0x870 +[ 17.746084][ T1878] audit_rule_change+0xbe/0x1110 +[ 17.751026][ T1878] ? selinux_capable+0x39/0x50 +[ 17.755800][ T1878] ? security_capable+0xb2/0xd0 +[ 17.760660][ T1878] ? audit_match_signal+0xc70/0xc70 +[ 17.765994][ T1878] ? ns_capable+0x8c/0xe0 +[ 17.770308][ T1878] audit_receive+0xe73/0x3750 +[ 17.774976][ T1878] ? jhash+0x750/0x750 +[ 17.779560][ T1878] ? audit_net_exit+0x90/0x90 +[ 17.784250][ T1878] ? __alloc_skb+0x109/0x540 +[ 17.788835][ T1878] ? jhash+0x750/0x750 +[ 17.793038][ T1878] ? avc_has_perm+0x15f/0x260 +[ 17.798006][ T1878] ? __rcu_read_lock+0x50/0x50 +[ 17.802809][ T1878] ? __rcu_read_lock+0x50/0x50 +[ 17.807647][ T1878] ? __netlink_lookup+0x585/0x600 +[ 17.812863][ T1878] ? netlink_deliver_tap+0xa4/0x7e0 +[ 17.818136][ T1878] ? netlink_autobind+0x1c0/0x1c0 +[ 17.823450][ T1878] ? __rcu_read_lock+0x50/0x50 +[ 17.829087][ T1878] ? selinux_vm_enough_memory+0x160/0x160 +[ 17.834803][ T1878] netlink_unicast+0x87c/0xa20 +[ 17.839763][ T1878] ? netlink_detachskb+0x60/0x60 +[ 17.844703][ T1878] ? security_netlink_send+0xab/0xc0 +[ 17.849985][ T1878] netlink_sendmsg+0x9a7/0xd40 +[ 17.854744][ T1878] ? netlink_getsockopt+0x900/0x900 +[ 17.859937][ T1878] ? security_socket_sendmsg+0xad/0xc0 +[ 17.865391][ T1878] ? netlink_getsockopt+0x900/0x900 +[ 17.870570][ T1878] ____sys_sendmsg+0x56f/0x860 +[ 17.875379][ T1878] ? __sys_sendmsg_sock+0x2a0/0x2a0 +[ 17.880712][ T1878] ? __kasan_check_read+0x11/0x20 +[ 17.885726][ T1878] ? __kasan_check_read+0x11/0x20 +[ 17.891785][ T1878] ? __fdget+0x156/0x200 +[ 17.896018][ T1878] __sys_sendmsg+0x26a/0x350 +[ 17.900641][ T1878] ? ____sys_sendmsg+0x860/0x860 +[ 17.905653][ T1878] ? finish_fault+0x230/0x230 +[ 17.910332][ T1878] ? __up_read+0x6f/0x1b0 +[ 17.914668][ T1878] ? __down_read+0x240/0x240 +[ 17.919251][ T1878] __x64_sys_sendmsg+0x7f/0x90 +[ 17.924185][ T1878] do_syscall_64+0xc0/0x100 +[ 17.928682][ T1878] entry_SYSCALL_64_after_hwframe+0x44/0xa9 +[ 17.934556][ T1878] RIP: 0033:0x440cf9 +[ 17.938468][ T1878] Code: 18 89 d0 c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 0f 83 fb 13 fc ff c3 66 2e 0f 1f 84 00 00 00 00 +[ 17.958392][ T1878] RSP: 002b:00007fff5acb9b08 EFLAGS: 00000246 ORIG_RAX: 000000000000002e +[ 17.966986][ T1878] RAX: ffffffffffffffda RBX: 00000000004002c8 RCX: 0000000000440cf9 +[ 17.974945][ T1878] RDX: 0000000000000000 RSI: 00000000200004c0 RDI: 0000000000000003 +[ 17.983107][ T1878] RBP: 00000000006cb018 R08: 0000000000000000 R09: 00000000004002c8 +[ 17.991069][ T1878] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000402580 +[ 17.999032][ T1878] R13: 0000000000402610 R14: 0000000000000000 R15: 0000000000000000 +[ 18.006997][ T1878] Modules linked in: +[ 18.010888][ T1878] CR2: ffffebde00002008 +[ 18.015021][ T1878] ---[ end trace f6042e9bcc2fc7f0 ]--- +[ 18.020561][ T1878] RIP: 0010:kfree+0xd6/0x6d0 +[ 18.025157][ T1878] Code: f0 02 eb 0a 48 bb 00 00 00 80 7f 77 00 00 4c 01 e3 48 81 eb 00 00 00 80 48 c1 eb 06 48 83 e3 c0 48 b9 00 00 00 00 00 ea ff ff <48> 8b 44 0b 08 a8 01 0f 85 a9 01 00 00 48 01 cb 48 8b 43 08 48 89 +[ 18.044869][ T1878] RSP: 0018:ffff8881d0dc7278 EFLAGS: 00010206 +[ 18.051280][ T1878] RAX: ffffffff7fffffff RBX: 000001de00002000 RCX: ffffea0000000000 +[ 18.059262][ T1878] RDX: 0000000000000000 RSI: ffffffff84648d30 RDI: 0000000000080000 +[ 18.067221][ T1878] RBP: ffff8881d0dc72f0 R08: 0000000000000005 R09: ffffffff8140b355 +[ 18.075333][ T1878] R10: ffff8881d1868000 R11: 000000000000000a R12: 0000000000080000 +[ 18.083397][ T1878] R13: ffff8881d310e000 R14: ffffffff8140b3ec R15: 0000000000000001 +[ 18.091360][ T1878] FS: 000000000104c880(0000) GS:ffff8881dba00000(0000) knlGS:0000000000000000 +[ 18.101368][ T1878] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 +[ 18.108044][ T1878] CR2: ffffebde00002008 CR3: 00000001d4f89002 CR4: 00000000001606f0 +[ 18.116013][ T1878] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 +[ 18.123982][ T1878] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 +[ 18.131942][ T1878] Kernel panic - not syncing: Fatal exception +[ 18.138889][ T1878] Kernel Offset: disabled +[ 18.143483][ T1878] Rebooting in 86400 seconds.. diff --git a/pkg/report/testdata/linux/report/477 b/pkg/report/testdata/linux/report/477 new file mode 100644 index 000000000..b6302e116 --- /dev/null +++ b/pkg/report/testdata/linux/report/477 @@ -0,0 +1,73 @@ +TITLE: BUG: corrupted list in ath9k_htc_wait_for_target + +[ 348.947111][ T4333] ------------[ cut here ]------------ +[ 348.947754][ T4333] kernel BUG at lib/list_debug.c:51! +[ 348.950815][ T4333] invalid opcode: 0000 [#1] SMP KASAN +[ 348.951779][ T4333] CPU: 0 PID: 4333 Comm: kworker/0:9 Not tainted 5.6.0-rc6+ #156 +[ 348.952713][ T4333] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014 +[ 348.953769][ T4333] Workqueue: events request_firmware_work_func +[ 348.954476][ T4333] RIP: 0010:__list_del_entry_valid.cold+0xf/0x55 +[ 348.955215][ T4333] Code: e8 e4 41 3e ff 0f 0b 48 89 f1 48 c7 c7 c0 27 fc 85 4c 89 e6 e8 d0 41 3e ff 0f 0b 48 89 ee 48 c7 c7 60 29 fc 85 e8 bf 41 3e ff <0f> 0b 4c 89 ea 48 89 ee 48 c7 c7 a0 28 fc 85 e8 ab 41 3e ff 0f 0b +[ 348.965784][ T4333] RSP: 0018:ffff888040e8f9b0 EFLAGS: 00010086 +[ 348.966476][ T4333] RAX: 0000000000000054 RBX: ffff88805b72a440 RCX: 0000000000000000 +[ 348.967431][ T4333] RDX: 0000000000000000 RSI: ffffffff812975ed RDI: ffffed10081d1f28 +[ 348.968357][ T4333] RBP: ffff888040e8fa38 R08: 0000000000000054 R09: ffffed100d946250 +[ 348.969334][ T4333] R10: ffffed100d94624f R11: ffff88806ca3127f R12: ffff88805b72a480 +[ 348.970246][ T4333] R13: ffff88805b72a480 R14: dffffc0000000000 R15: ffff888040e8fa38 +[ 348.971174][ T4333] FS: 0000000000000000(0000) GS:ffff88806ca00000(0000) knlGS:0000000000000000 +[ 348.972229][ T4333] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 +[ 348.972983][ T4333] CR2: 000055b4f6c78d90 CR3: 00000000664d3001 CR4: 0000000000760ef0 +[ 348.973909][ T4333] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 +[ 348.974790][ T4333] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 +[ 348.975705][ T4333] PKRU: 55555554 +[ 348.976109][ T4333] Call Trace: +[ 348.976501][ T4333] wait_for_completion_timeout+0x2b7/0x3e0 +[ 348.977182][ T4333] ? debug_object_fixup+0x20/0x20 +[ 348.977777][ T4333] ? wait_for_completion_io_timeout+0x3e0/0x3e0 +[ 348.978474][ T4333] ? wake_up_q+0x140/0x140 +[ 348.979001][ T4333] ? lockdep_init_map+0x1b0/0x5e0 +[ 348.979583][ T4333] ? ieee80211_roc_setup+0x2b8/0x3a0 +[ 348.980237][ T4333] ath9k_htc_wait_for_target.isra.0+0xb9/0x1b0 +[ 348.981712][ T4333] ath9k_htc_probe_device+0x1a4/0x1d80 +[ 348.982567][ T4333] ? ath9k_init_htc_services.constprop.0+0x650/0x650 +[ 348.983654][ T4333] ? usb_submit_urb+0x6ed/0x1460 +[ 348.984239][ T4333] ? usb_free_urb.part.0+0x52/0x110 +[ 348.984925][ T4333] ? usb_free_urb+0x1b/0x30 +[ 348.985451][ T4333] ath9k_htc_hw_init+0x31/0x60 +[ 348.985996][ T4333] ath9k_hif_usb_firmware_cb+0x26b/0x500 +[ 348.986811][ T4333] ? ath9k_hif_usb_resume+0x320/0x320 +[ 348.987442][ T4333] request_firmware_work_func+0x126/0x242 +[ 348.988100][ T4333] ? request_firmware_into_buf+0x90/0x90 +[ 348.988750][ T4333] ? rcu_read_lock_sched_held+0x9c/0xd0 +[ 348.989392][ T4333] ? rcu_read_lock_bh_held+0xb0/0xb0 +[ 348.989997][ T4333] process_one_work+0x94b/0x1620 +[ 348.990715][ T4333] ? pwq_dec_nr_in_flight+0x310/0x310 +[ 348.991311][ T4333] ? do_raw_spin_lock+0x129/0x290 +[ 348.991892][ T4333] worker_thread+0x96/0xe20 +[ 348.992432][ T4333] ? process_one_work+0x1620/0x1620 +[ 348.993028][ T4333] kthread+0x318/0x420 +[ 348.993507][ T4333] ? kthread_create_on_node+0xf0/0xf0 +[ 348.994258][ T4333] ret_from_fork+0x24/0x30 +[ 348.994818][ T4333] Modules linked in: +[ 348.995262][ T4333] Dumping ftrace buffer: +[ 348.995744][ T4333] (ftrace buffer empty) +[ 348.996257][ T4333] ---[ end trace ccd500e929f6e52d ]--- +[ 348.996945][ T4333] RIP: 0010:__list_del_entry_valid.cold+0xf/0x55 +[ 348.997679][ T4333] Code: e8 e4 41 3e ff 0f 0b 48 89 f1 48 c7 c7 c0 27 fc 85 4c 89 e6 e8 d0 41 3e ff 0f 0b 48 89 ee 48 c7 c7 60 29 fc 85 e8 bf 41 3e ff <0f> 0b 4c 89 ea 48 89 ee 48 c7 c7 a0 28 fc 85 e8 ab 41 3e ff 0f 0b +[ 349.000028][ T4333] RSP: 0018:ffff888040e8f9b0 EFLAGS: 00010086 +[ 349.000727][ T4333] RAX: 0000000000000054 RBX: ffff88805b72a440 RCX: 0000000000000000 +[ 349.001669][ T4333] RDX: 0000000000000000 RSI: ffffffff812975ed RDI: ffffed10081d1f28 +[ 349.002783][ T4333] RBP: ffff888040e8fa38 R08: 0000000000000054 R09: ffffed100d946250 +[ 349.003677][ T4333] R10: ffffed100d94624f R11: ffff88806ca3127f R12: ffff88805b72a480 +[ 349.004578][ T4333] R13: ffff88805b72a480 R14: dffffc0000000000 R15: ffff888040e8fa38 +[ 349.005549][ T4333] FS: 0000000000000000(0000) GS:ffff88806ca00000(0000) knlGS:0000000000000000 +[ 349.006569][ T4333] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 +[ 349.007310][ T4333] CR2: 000055b4f6c78d90 CR3: 00000000664d3001 CR4: 0000000000760ef0 +[ 349.008249][ T4333] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 +[ 349.009174][ T4333] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 +[ 349.010113][ T4333] PKRU: 55555554 +[ 349.010949][ T4333] Kernel panic - not syncing: Fatal exception +[ 349.012076][ T4333] Dumping ftrace buffer: +[ 349.012572][ T4333] (ftrace buffer empty) +[ 349.013132][ T4333] Kernel Offset: disabled +[ 349.013724][ T4333] Rebooting in 1 seconds.. diff --git a/pkg/report/testdata/linux/report/478 b/pkg/report/testdata/linux/report/478 new file mode 100644 index 000000000..7326e4088 --- /dev/null +++ b/pkg/report/testdata/linux/report/478 @@ -0,0 +1,147 @@ +TITLE: KASAN: use-after-free Read in ucma_destroy_id + +[ 308.398169] ================================================================== +[ 308.405617] BUG: KASAN: use-after-free in __lock_acquire+0x37c2/0x4ec0 +[ 308.412292] Read of size 8 at addr ffff8801d28a81a8 by task syz-executor4/12225 +[ 308.419750] +[ 308.421389] CPU: 1 PID: 12225 Comm: syz-executor4 Not tainted 4.19.0-rc8+ #72 +[ 308.428659] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011 +[ 308.438010] Call Trace: +[ 308.440609] dump_stack+0x1c4/0x2b4 +[ 308.444246] ? dump_stack_print_info.cold.2+0x52/0x52 +[ 308.449487] ? printk+0xa7/0xcf +[ 308.452785] ? kmsg_dump_rewind_nolock+0xe4/0xe4 +[ 308.457562] print_address_description.cold.8+0x9/0x1ff +[ 308.462943] kasan_report.cold.9+0x242/0x309 +[ 308.467369] ? __lock_acquire+0x37c2/0x4ec0 +[ 308.471708] __asan_report_load8_noabort+0x14/0x20 +[ 308.476656] __lock_acquire+0x37c2/0x4ec0 +[ 308.480814] ? preempt_notifier_register+0x200/0x200 +[ 308.485944] ? __switch_to_asm+0x34/0x70 +[ 308.490011] ? __switch_to_asm+0x34/0x70 +[ 308.494082] ? __switch_to_asm+0x40/0x70 +[ 308.498152] ? __switch_to_asm+0x34/0x70 +[ 308.502223] ? __switch_to_asm+0x40/0x70 +[ 308.506289] ? __switch_to_asm+0x34/0x70 +[ 308.510378] ? __switch_to_asm+0x40/0x70 +[ 308.514451] ? __switch_to_asm+0x34/0x70 +[ 308.518526] ? __switch_to_asm+0x34/0x70 +[ 308.522605] ? mark_held_locks+0x130/0x130 +[ 308.526855] ? __schedule+0x874/0x1ed0 +[ 308.530756] ? __sched_text_start+0x8/0x8 +[ 308.534909] ? lock_acquire+0x1ed/0x520 +[ 308.538979] ? ucma_destroy_id+0x326/0x550 +[ 308.543230] ? lock_release+0x970/0x970 +[ 308.547210] ? arch_local_save_flags+0x40/0x40 +[ 308.551798] ? mark_held_locks+0x130/0x130 +[ 308.551817] ? graph_lock+0x170/0x170 +[ 308.551837] ? graph_lock+0x170/0x170 +[ 308.551855] ? schedule+0x108/0x460 +[ 308.551874] ? __schedule+0x1ed0/0x1ed0 +[ 308.567340] ? find_held_lock+0x36/0x1c0 +[ 308.567360] lock_acquire+0x1ed/0x520 +[ 308.567378] ? wait_for_completion+0x436/0x8a0 +[ 308.567394] ? lock_release+0x970/0x970 +[ 308.567415] ? trace_hardirqs_off+0xb8/0x310 +[ 308.592166] ? usleep_range+0x1a0/0x1a0 +[ 308.596165] ? wait_for_completion+0x436/0x8a0 +[ 308.600762] ? trace_hardirqs_on+0x310/0x310 +[ 308.605179] ? kasan_check_write+0x14/0x20 +[ 308.609432] _raw_spin_lock_irq+0x61/0x80 +[ 308.613587] ? wait_for_completion+0x436/0x8a0 +[ 308.618179] wait_for_completion+0x436/0x8a0 +[ 308.622598] ? wait_for_completion_interruptible+0x840/0x840 +[ 308.628400] ? wake_up_q+0x100/0x100 +[ 308.632135] ucma_destroy_id+0x38a/0x550 +[ 308.636205] ? ucma_close+0x310/0x310 +[ 308.640009] ? __sanitizer_cov_trace_const_cmp8+0x18/0x20 +[ 308.640024] ? _copy_from_user+0xdf/0x150 +[ 308.640037] ? ucma_close+0x310/0x310 +[ 308.640050] ucma_write+0x365/0x460 +[ 308.640065] ? ucma_open+0x3f0/0x3f0 +[ 308.640096] ? ___might_sleep+0x1ed/0x300 +[ 308.665043] __vfs_write+0x119/0x9f0 +[ 308.668771] ? __fget_light+0x2e9/0x430 +[ 308.672763] ? ucma_open+0x3f0/0x3f0 +[ 308.676489] ? kernel_read+0x120/0x120 +[ 308.680391] ? __might_sleep+0x95/0x190 +[ 308.684384] ? arch_local_save_flags+0x40/0x40 +[ 308.688981] ? __sanitizer_cov_trace_const_cmp1+0x1a/0x20 +[ 308.694535] ? __inode_security_revalidate+0xd9/0x120 +[ 308.699737] ? __sanitizer_cov_trace_cmp4+0x16/0x20 +[ 308.704764] ? selinux_file_permission+0x90/0x540 +[ 308.709616] ? __sanitizer_cov_trace_const_cmp4+0x16/0x20 +[ 308.715162] ? security_file_permission+0x1c2/0x230 +[ 308.720210] ? rw_verify_area+0x118/0x360 +[ 308.720227] vfs_write+0x1fc/0x560 +[ 308.720243] ksys_write+0x101/0x260 +[ 308.720264] ? __ia32_sys_read+0xb0/0xb0 +[ 308.731567] ? __bpf_trace_preemptirq_template+0x30/0x30 +[ 308.731585] __x64_sys_write+0x73/0xb0 +[ 308.731604] do_syscall_64+0x1b9/0x820 +[ 308.731621] ? entry_SYSCALL_64_after_hwframe+0x3e/0xbe +[ 308.731638] ? syscall_return_slowpath+0x5e0/0x5e0 +[ 308.731653] ? trace_hardirqs_on_caller+0x310/0x310 +[ 308.731673] ? prepare_exit_to_usermode+0x3b0/0x3b0 +[ 308.769246] ? recalc_sigpending_tsk+0x180/0x180 +[ 308.774003] ? kasan_check_write+0x14/0x20 +[ 308.778244] ? trace_hardirqs_off_thunk+0x1a/0x1c +[ 308.783088] entry_SYSCALL_64_after_hwframe+0x49/0xbe +[ 308.788267] RIP: 0033:0x457569 +[ 308.791447] Code: fd b3 fb ff c3 66 2e 0f 1f 84 00 00 00 00 00 66 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 0f 83 cb b3 fb ff c3 66 2e 0f 1f 84 00 00 00 00 +[ 308.810345] RSP: 002b:00007fe8a3f8ec78 EFLAGS: 00000246 ORIG_RAX: 0000000000000001 +[ 308.818068] RAX: ffffffffffffffda RBX: 0000000000000003 RCX: 0000000000457569 +[ 308.825345] RDX: 0000000000000018 RSI: 0000000020000280 RDI: 0000000000000005 +[ 308.832614] RBP: 000000000072bfa0 R08: 0000000000000000 R09: 0000000000000000 +[ 308.839871] R10: 0000000000000000 R11: 0000000000000246 R12: 00007fe8a3f8f6d4 +[ 308.847125] R13: 00000000004cb4f8 R14: 00000000004d8b68 R15: 00000000ffffffff +[ 308.854378] +[ 308.855989] Allocated by task 12210: +[ 308.859692] save_stack+0x43/0xd0 +[ 308.863129] kasan_kmalloc+0xc7/0xe0 +[ 308.866833] kmem_cache_alloc_trace+0x152/0x750 +[ 308.871495] ucma_alloc_ctx+0xce/0x690 +[ 308.875363] ucma_create_id+0x27d/0x990 +[ 308.879335] ucma_write+0x365/0x460 +[ 308.882949] __vfs_write+0x119/0x9f0 +[ 308.886645] vfs_write+0x1fc/0x560 +[ 308.890174] ksys_write+0x101/0x260 +[ 308.893802] __x64_sys_write+0x73/0xb0 +[ 308.897694] do_syscall_64+0x1b9/0x820 +[ 308.901569] entry_SYSCALL_64_after_hwframe+0x49/0xbe +[ 308.906732] +[ 308.908342] Freed by task 12210: +[ 308.911691] save_stack+0x43/0xd0 +[ 308.915128] __kasan_slab_free+0x102/0x150 +[ 308.919358] kasan_slab_free+0xe/0x10 +[ 308.923148] kfree+0xcf/0x230 +[ 308.926240] ucma_free_ctx+0x9e6/0xdb0 +[ 308.930118] ucma_close+0x121/0x310 +[ 308.933742] __fput+0x385/0xa30 +[ 308.937015] ____fput+0x15/0x20 +[ 308.940298] task_work_run+0x1e8/0x2a0 +[ 308.944208] get_signal+0x155e/0x1980 +[ 308.948124] do_signal+0x9c/0x21e0 +[ 308.951667] exit_to_usermode_loop+0x2e5/0x380 +[ 308.956234] do_syscall_64+0x6be/0x820 +[ 308.960104] entry_SYSCALL_64_after_hwframe+0x49/0xbe +[ 308.965267] +[ 308.966877] The buggy address belongs to the object at ffff8801d28a8180 +[ 308.966877] which belongs to the cache kmalloc-256 of size 256 +[ 308.979514] The buggy address is located 40 bytes inside of +[ 308.979514] 256-byte region [ffff8801d28a8180, ffff8801d28a8280) +[ 308.991440] The buggy address belongs to the page: +[ 308.996388] page:ffffea00074a2a00 count:1 mapcount:0 mapping:ffff8801da8007c0 index:0x0 +[ 309.004511] flags: 0x2fffc0000000100(slab) +[ 309.008732] raw: 02fffc0000000100 ffffea000760b108 ffffea0007491148 ffff8801da8007c0 +[ 309.016619] raw: 0000000000000000 ffff8801d28a8040 000000010000000c 0000000000000000 +[ 309.024477] page dumped because: kasan: bad access detected +[ 309.030162] +[ 309.031768] Memory state around the buggy address: +[ 309.036685] ffff8801d28a8080: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 +[ 309.044035] ffff8801d28a8100: 00 00 fc fc fc fc fc fc fc fc fc fc fc fc fc fc +[ 309.051377] >ffff8801d28a8180: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb +[ 309.058734] ^ +[ 309.063398] ffff8801d28a8200: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb +[ 309.070750] ffff8801d28a8280: fc fc fc fc fc fc fc fc fb fb fb fb fb fb fb fb +[ 309.078092] ================================================================== |
