[syzbot] KMSAN: uninit-value in psi_poll_worker

12 views
Skip to first unread message

syzbot

unread,
Aug 26, 2022, 5:19:29 AM8/26/22
to b...@vger.kernel.org, bra...@kernel.org, cgr...@vger.kernel.org, gli...@google.com, han...@cmpxchg.org, linux-...@vger.kernel.org, lize...@bytedance.com, syzkall...@googlegroups.com, t...@kernel.org
Hello,

syzbot found the following issue on:

HEAD commit: 3a2b6b904ea7 x86: kmsan: enable KMSAN builds for x86
git tree: https://github.com/google/kmsan.git master
console output: https://syzkaller.appspot.com/x/log.txt?x=13f51a33080000
kernel config: https://syzkaller.appspot.com/x/.config?x=8e64bc5364a1307e
dashboard link: https://syzkaller.appspot.com/bug?extid=dd8e45eb61404849cde9
compiler: clang version 15.0.0 (https://github.com/llvm/llvm-project.git 610139d2d9ce6746b3c617fb3e2f7886272d26ff), GNU ld (GNU Binutils for Debian) 2.35.2

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+dd8e45...@syzkaller.appspotmail.com

=====================================================
BUG: KMSAN: uninit-value in update_triggers kernel/sched/psi.c:525 [inline]
BUG: KMSAN: uninit-value in psi_poll_work kernel/sched/psi.c:626 [inline]
BUG: KMSAN: uninit-value in psi_poll_worker+0x972/0x16a0 kernel/sched/psi.c:648
update_triggers kernel/sched/psi.c:525 [inline]
psi_poll_work kernel/sched/psi.c:626 [inline]
psi_poll_worker+0x972/0x16a0 kernel/sched/psi.c:648
kthread+0x31b/0x430 kernel/kthread.c:376
ret_from_fork+0x1f/0x30

Uninit was stored to memory at:
collect_percpu_times+0x193d/0x19a0 kernel/sched/psi.c:355
psi_poll_work kernel/sched/psi.c:604 [inline]
psi_poll_worker+0x587/0x16a0 kernel/sched/psi.c:648
kthread+0x31b/0x430 kernel/kthread.c:376
ret_from_fork+0x1f/0x30

Uninit was stored to memory at:
collect_percpu_times+0x193d/0x19a0 kernel/sched/psi.c:355
psi_poll_work kernel/sched/psi.c:604 [inline]
psi_poll_worker+0x587/0x16a0 kernel/sched/psi.c:648
kthread+0x31b/0x430 kernel/kthread.c:376
ret_from_fork+0x1f/0x30

Uninit was created at:
slab_post_alloc_hook mm/slab.h:732 [inline]
slab_alloc_node mm/slub.c:3258 [inline]
slab_alloc mm/slub.c:3266 [inline]
kmem_cache_alloc_trace+0x696/0xdf0 mm/slub.c:3297
kmalloc include/linux/slab.h:600 [inline]
psi_cgroup_alloc+0x83/0x250 kernel/sched/psi.c:960
cgroup_create kernel/cgroup/cgroup.c:5430 [inline]
cgroup_mkdir+0x10a3/0x3080 kernel/cgroup/cgroup.c:5550
kernfs_iop_mkdir+0x2ba/0x520 fs/kernfs/dir.c:1185
vfs_mkdir+0x62a/0x870 fs/namei.c:4013
do_mkdirat+0x466/0x7b0 fs/namei.c:4038
__do_sys_mkdirat fs/namei.c:4053 [inline]
__se_sys_mkdirat fs/namei.c:4051 [inline]
__x64_sys_mkdirat+0xc4/0x120 fs/namei.c:4051
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x63/0xcd

CPU: 0 PID: 19765 Comm: psimon Not tainted 6.0.0-rc2-syzkaller-47460-g3a2b6b904ea7 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/22/2022
=====================================================


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Aug 26, 2022, 5:27:26 AM8/26/22
to b...@vger.kernel.org, bra...@kernel.org, cgr...@vger.kernel.org, gli...@google.com, han...@cmpxchg.org, linux-...@vger.kernel.org, lize...@bytedance.com, syzkall...@googlegroups.com, t...@kernel.org
syzbot has found a reproducer for the following issue on:

HEAD commit: 3a2b6b904ea7 x86: kmsan: enable KMSAN builds for x86
git tree: https://github.com/google/kmsan.git master
console+strace: https://syzkaller.appspot.com/x/log.txt?x=14d6a513080000
kernel config: https://syzkaller.appspot.com/x/.config?x=8e64bc5364a1307e
dashboard link: https://syzkaller.appspot.com/bug?extid=dd8e45eb61404849cde9
compiler: clang version 15.0.0 (https://github.com/llvm/llvm-project.git 610139d2d9ce6746b3c617fb3e2f7886272d26ff), GNU ld (GNU Binutils for Debian) 2.35.2
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=10fc7ac7080000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=14ea06db080000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+dd8e45...@syzkaller.appspotmail.com

=====================================================
BUG: KMSAN: uninit-value in psi_show+0x701/0x810 kernel/sched/psi.c:1082
psi_show+0x701/0x810 kernel/sched/psi.c:1082
cgroup_io_pressure_show+0x2b6/0x2f0 kernel/cgroup/cgroup.c:3662
cgroup_seqfile_show+0x1fe/0x470 kernel/cgroup/cgroup.c:3991
kernfs_seq_show+0x13b/0x1f0 fs/kernfs/file.c:217
seq_read_iter+0x926/0x20c0 fs/seq_file.c:230
kernfs_fop_read_iter+0x1f2/0xa10 fs/kernfs/file.c:299
call_read_iter include/linux/fs.h:2181 [inline]
generic_file_splice_read+0x1e5/0x770 fs/splice.c:309
do_splice_to fs/splice.c:793 [inline]
splice_direct_to_actor+0x5b2/0x1190 fs/splice.c:865
do_splice_direct+0x252/0x3d0 fs/splice.c:974
do_sendfile+0xbe9/0x1ba0 fs/read_write.c:1249
__do_sys_sendfile64 fs/read_write.c:1317 [inline]
__se_sys_sendfile64+0x202/0x2a0 fs/read_write.c:1303
__x64_sys_sendfile64+0xb9/0x110 fs/read_write.c:1303
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x63/0xcd

Uninit was created at:
slab_post_alloc_hook mm/slab.h:732 [inline]
slab_alloc_node mm/slub.c:3258 [inline]
slab_alloc mm/slub.c:3266 [inline]
kmem_cache_alloc_trace+0x696/0xdf0 mm/slub.c:3297
kmalloc include/linux/slab.h:600 [inline]
psi_cgroup_alloc+0x83/0x250 kernel/sched/psi.c:960
cgroup_create kernel/cgroup/cgroup.c:5430 [inline]
cgroup_mkdir+0x10a3/0x3080 kernel/cgroup/cgroup.c:5550
kernfs_iop_mkdir+0x2ba/0x520 fs/kernfs/dir.c:1185
vfs_mkdir+0x62a/0x870 fs/namei.c:4013
do_mkdirat+0x466/0x7b0 fs/namei.c:4038
__do_sys_mkdirat fs/namei.c:4053 [inline]
__se_sys_mkdirat fs/namei.c:4051 [inline]
__x64_sys_mkdirat+0xc4/0x120 fs/namei.c:4051
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x63/0xcd

CPU: 1 PID: 3493 Comm: syz-executor306 Not tainted 6.0.0-rc2-syzkaller-47460-g3a2b6b904ea7 #0

syzbot

unread,
Sep 4, 2022, 10:10:14 PM9/4/22
to 1111...@vivo.com, gli...@google.com, syzkall...@googlegroups.com
Hello,

syzbot has tested the proposed patch and the reproducer did not trigger any issue:

Reported-and-tested-by: syzbot+dd8e45...@syzkaller.appspotmail.com

Tested on:

commit: ad8e4e81 x86: kmsan: enable KMSAN builds for x86
console output: https://syzkaller.appspot.com/x/log.txt?x=1157f9c5080000
kernel config: https://syzkaller.appspot.com/x/.config?x=e42ddd4a35cdbab6
dashboard link: https://syzkaller.appspot.com/bug?extid=dd8e45eb61404849cde9
compiler: clang version 15.0.0 (https://github.com/llvm/llvm-project.git 610139d2d9ce6746b3c617fb3e2f7886272d26ff), GNU ld (GNU Binutils for Debian) 2.35.2
patch: https://syzkaller.appspot.com/x/patch.diff?x=14ad9de5080000

Note: testing is done by a robot and is best-effort only.

syzbot

unread,
Dec 12, 2022, 1:50:57 AM12/12/22
to gli...@google.com, syzkall...@googlegroups.com
Auto-closing this bug as obsolete.
No recent activity, existing reproducers are no longer triggering the issue.
Reply all
Reply to author
Forward
0 new messages