[syzbot] memory leak in bsg_register_queue

11 views
Skip to first unread message

syzbot

unread,
Sep 10, 2021, 8:01:26 AM9/10/21
to gre...@linuxfoundation.org, linux-...@vger.kernel.org, raf...@kernel.org, syzkall...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 0319b848b155 binfmt: a.out: Fix bogus semicolon
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=1776fab5300000
kernel config: https://syzkaller.appspot.com/x/.config?x=4d196bb8b1e038c0
dashboard link: https://syzkaller.appspot.com/bug?extid=cfe9b7cf55bb54ed4e57
compiler: gcc (Debian 10.2.1-6) 10.2.1 20210110, GNU ld (GNU Binutils for Debian) 2.35.1
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=15b2e115300000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=10f2147d300000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+cfe9b7...@syzkaller.appspotmail.com

BUG: memory leak
unreferenced object 0xffff8881170d6200 (size 256):
comm "kworker/u4:4", pid 2996, jiffies 4294948949 (age 23.430s)
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 08 62 0d 17 81 88 ff ff .........b......
08 62 0d 17 81 88 ff ff 10 26 65 82 ff ff ff ff .b.......&e.....
backtrace:
[<ffffffff82657f2b>] kmalloc include/linux/slab.h:591 [inline]
[<ffffffff82657f2b>] kzalloc include/linux/slab.h:721 [inline]
[<ffffffff82657f2b>] device_private_init drivers/base/core.c:3203 [inline]
[<ffffffff82657f2b>] device_add+0x89b/0xdf0 drivers/base/core.c:3253
[<ffffffff81577864>] cdev_device_add+0x84/0xe0 fs/char_dev.c:549
[<ffffffff822547ff>] bsg_register_queue+0x10f/0x1d0 block/bsg.c:206
[<ffffffff82730abf>] scsi_sysfs_add_sdev+0x13f/0x380 drivers/scsi/scsi_sysfs.c:1376
[<ffffffff8272e309>] scsi_sysfs_add_devices drivers/scsi/scsi_scan.c:1727 [inline]
[<ffffffff8272e309>] scsi_finish_async_scan drivers/scsi/scsi_scan.c:1812 [inline]
[<ffffffff8272e309>] do_scan_async+0x109/0x200 drivers/scsi/scsi_scan.c:1855
[<ffffffff812752a4>] async_run_entry_fn+0x24/0xf0 kernel/async.c:127
[<ffffffff81263d1f>] process_one_work+0x2cf/0x620 kernel/workqueue.c:2297
[<ffffffff81264629>] worker_thread+0x59/0x5d0 kernel/workqueue.c:2444
[<ffffffff8126db28>] kthread+0x188/0x1d0 kernel/kthread.c:319
[<ffffffff8100234f>] ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295

BUG: memory leak
unreferenced object 0xffff8881170da100 (size 32):
comm "kworker/u4:4", pid 2996, jiffies 4294948956 (age 23.360s)
hex dump (first 32 bytes):
38 3a 30 3a 30 3a 31 00 00 00 00 00 00 00 00 00 8:0:0:1.........
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
backtrace:
[<ffffffff8147fc76>] kstrdup+0x36/0x70 mm/util.c:60
[<ffffffff8147fd03>] kstrdup_const+0x53/0x80 mm/util.c:83
[<ffffffff82293362>] kvasprintf_const+0xc2/0x110 lib/kasprintf.c:48
[<ffffffff8235545b>] kobject_set_name_vargs+0x3b/0xe0 lib/kobject.c:289
[<ffffffff82652573>] dev_set_name+0x63/0x90 drivers/base/core.c:3147
[<ffffffff822547d1>] bsg_register_queue+0xe1/0x1d0 block/bsg.c:201
[<ffffffff82730abf>] scsi_sysfs_add_sdev+0x13f/0x380 drivers/scsi/scsi_sysfs.c:1376
[<ffffffff8272e309>] scsi_sysfs_add_devices drivers/scsi/scsi_scan.c:1727 [inline]
[<ffffffff8272e309>] scsi_finish_async_scan drivers/scsi/scsi_scan.c:1812 [inline]
[<ffffffff8272e309>] do_scan_async+0x109/0x200 drivers/scsi/scsi_scan.c:1855
[<ffffffff812752a4>] async_run_entry_fn+0x24/0xf0 kernel/async.c:127
[<ffffffff81263d1f>] process_one_work+0x2cf/0x620 kernel/workqueue.c:2297
[<ffffffff81264629>] worker_thread+0x59/0x5d0 kernel/workqueue.c:2444
[<ffffffff8126db28>] kthread+0x188/0x1d0 kernel/kthread.c:319
[<ffffffff8100234f>] ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295

BUG: memory leak
unreferenced object 0xffff8881157cde00 (size 256):
comm "kworker/u4:4", pid 2996, jiffies 4294948956 (age 23.360s)
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 08 de 7c 15 81 88 ff ff ..........|.....
08 de 7c 15 81 88 ff ff 10 26 65 82 ff ff ff ff ..|......&e.....
backtrace:
[<ffffffff82657f2b>] kmalloc include/linux/slab.h:591 [inline]
[<ffffffff82657f2b>] kzalloc include/linux/slab.h:721 [inline]
[<ffffffff82657f2b>] device_private_init drivers/base/core.c:3203 [inline]
[<ffffffff82657f2b>] device_add+0x89b/0xdf0 drivers/base/core.c:3253
[<ffffffff81577864>] cdev_device_add+0x84/0xe0 fs/char_dev.c:549
[<ffffffff822547ff>] bsg_register_queue+0x10f/0x1d0 block/bsg.c:206
[<ffffffff82730abf>] scsi_sysfs_add_sdev+0x13f/0x380 drivers/scsi/scsi_sysfs.c:1376
[<ffffffff8272e309>] scsi_sysfs_add_devices drivers/scsi/scsi_scan.c:1727 [inline]
[<ffffffff8272e309>] scsi_finish_async_scan drivers/scsi/scsi_scan.c:1812 [inline]
[<ffffffff8272e309>] do_scan_async+0x109/0x200 drivers/scsi/scsi_scan.c:1855
[<ffffffff812752a4>] async_run_entry_fn+0x24/0xf0 kernel/async.c:127
[<ffffffff81263d1f>] process_one_work+0x2cf/0x620 kernel/workqueue.c:2297
[<ffffffff81264629>] worker_thread+0x59/0x5d0 kernel/workqueue.c:2444
[<ffffffff8126db28>] kthread+0x188/0x1d0 kernel/kthread.c:319
[<ffffffff8100234f>] ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295

BUG: memory leak
unreferenced object 0xffff888110f3b620 (size 32):
comm "kworker/u4:4", pid 2996, jiffies 4294948968 (age 23.240s)
hex dump (first 32 bytes):
38 3a 30 3a 30 3a 32 00 00 00 00 00 00 00 00 00 8:0:0:2.........
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
backtrace:
[<ffffffff8147fc76>] kstrdup+0x36/0x70 mm/util.c:60
[<ffffffff8147fd03>] kstrdup_const+0x53/0x80 mm/util.c:83
[<ffffffff82293362>] kvasprintf_const+0xc2/0x110 lib/kasprintf.c:48
[<ffffffff8235545b>] kobject_set_name_vargs+0x3b/0xe0 lib/kobject.c:289
[<ffffffff82652573>] dev_set_name+0x63/0x90 drivers/base/core.c:3147
[<ffffffff822547d1>] bsg_register_queue+0xe1/0x1d0 block/bsg.c:201
[<ffffffff82730abf>] scsi_sysfs_add_sdev+0x13f/0x380 drivers/scsi/scsi_sysfs.c:1376
[<ffffffff8272e309>] scsi_sysfs_add_devices drivers/scsi/scsi_scan.c:1727 [inline]
[<ffffffff8272e309>] scsi_finish_async_scan drivers/scsi/scsi_scan.c:1812 [inline]
[<ffffffff8272e309>] do_scan_async+0x109/0x200 drivers/scsi/scsi_scan.c:1855
[<ffffffff812752a4>] async_run_entry_fn+0x24/0xf0 kernel/async.c:127
[<ffffffff81263d1f>] process_one_work+0x2cf/0x620 kernel/workqueue.c:2297
[<ffffffff81264629>] worker_thread+0x59/0x5d0 kernel/workqueue.c:2444
[<ffffffff8126db28>] kthread+0x188/0x1d0 kernel/kthread.c:319
[<ffffffff8100234f>] ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295

BUG: memory leak
unreferenced object 0xffff888114f6c160 (size 32):
comm "kworker/u4:4", pid 2996, jiffies 4294948949 (age 24.710s)
hex dump (first 32 bytes):
38 3a 30 3a 30 3a 30 00 00 00 00 00 00 00 00 00 8:0:0:0.........
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
backtrace:
[<ffffffff8147fc76>] kstrdup+0x36/0x70 mm/util.c:60
[<ffffffff8147fd03>] kstrdup_const+0x53/0x80 mm/util.c:83
[<ffffffff82293362>] kvasprintf_const+0xc2/0x110 lib/kasprintf.c:48
[<ffffffff8235545b>] kobject_set_name_vargs+0x3b/0xe0 lib/kobject.c:289
[<ffffffff82652573>] dev_set_name+0x63/0x90 drivers/base/core.c:3147
[<ffffffff822547d1>] bsg_register_queue+0xe1/0x1d0 block/bsg.c:201
[<ffffffff82730abf>] scsi_sysfs_add_sdev+0x13f/0x380 drivers/scsi/scsi_sysfs.c:1376
[<ffffffff8272e309>] scsi_sysfs_add_devices drivers/scsi/scsi_scan.c:1727 [inline]
[<ffffffff8272e309>] scsi_finish_async_scan drivers/scsi/scsi_scan.c:1812 [inline]
[<ffffffff8272e309>] do_scan_async+0x109/0x200 drivers/scsi/scsi_scan.c:1855
[<ffffffff812752a4>] async_run_entry_fn+0x24/0xf0 kernel/async.c:127
[<ffffffff81263d1f>] process_one_work+0x2cf/0x620 kernel/workqueue.c:2297
[<ffffffff81264629>] worker_thread+0x59/0x5d0 kernel/workqueue.c:2444
[<ffffffff8126db28>] kthread+0x188/0x1d0 kernel/kthread.c:319
[<ffffffff8100234f>] ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295

BUG: memory leak
unreferenced object 0xffff8881170d6200 (size 256):
comm "kworker/u4:4", pid 2996, jiffies 4294948949 (age 24.710s)
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 08 62 0d 17 81 88 ff ff .........b......
08 62 0d 17 81 88 ff ff 10 26 65 82 ff ff ff ff .b.......&e.....
backtrace:
[<ffffffff82657f2b>] kmalloc include/linux/slab.h:591 [inline]
[<ffffffff82657f2b>] kzalloc include/linux/slab.h:721 [inline]
[<ffffffff82657f2b>] device_private_init drivers/base/core.c:3203 [inline]
[<ffffffff82657f2b>] device_add+0x89b/0xdf0 drivers/base/core.c:3253
[<ffffffff81577864>] cdev_device_add+0x84/0xe0 fs/char_dev.c:549
[<ffffffff822547ff>] bsg_register_queue+0x10f/0x1d0 block/bsg.c:206
[<ffffffff82730abf>] scsi_sysfs_add_sdev+0x13f/0x380 drivers/scsi/scsi_sysfs.c:1376
[<ffffffff8272e309>] scsi_sysfs_add_devices drivers/scsi/scsi_scan.c:1727 [inline]
[<ffffffff8272e309>] scsi_finish_async_scan drivers/scsi/scsi_scan.c:1812 [inline]
[<ffffffff8272e309>] do_scan_async+0x109/0x200 drivers/scsi/scsi_scan.c:1855
[<ffffffff812752a4>] async_run_entry_fn+0x24/0xf0 kernel/async.c:127
[<ffffffff81263d1f>] process_one_work+0x2cf/0x620 kernel/workqueue.c:2297
[<ffffffff81264629>] worker_thread+0x59/0x5d0 kernel/workqueue.c:2444
[<ffffffff8126db28>] kthread+0x188/0x1d0 kernel/kthread.c:319
[<ffffffff8100234f>] ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295

BUG: memory leak
unreferenced object 0xffff8881170da100 (size 32):
comm "kworker/u4:4", pid 2996, jiffies 4294948956 (age 24.640s)
hex dump (first 32 bytes):
38 3a 30 3a 30 3a 31 00 00 00 00 00 00 00 00 00 8:0:0:1.........
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
backtrace:
[<ffffffff8147fc76>] kstrdup+0x36/0x70 mm/util.c:60
[<ffffffff8147fd03>] kstrdup_const+0x53/0x80 mm/util.c:83
[<ffffffff82293362>] kvasprintf_const+0xc2/0x110 lib/kasprintf.c:48
[<ffffffff8235545b>] kobject_set_name_vargs+0x3b/0xe0 lib/kobject.c:289
[<ffffffff82652573>] dev_set_name+0x63/0x90 drivers/base/core.c:3147
[<ffffffff822547d1>] bsg_register_queue+0xe1/0x1d0 block/bsg.c:201
[<ffffffff82730abf>] scsi_sysfs_add_sdev+0x13f/0x380 drivers/scsi/scsi_sysfs.c:1376
[<ffffffff8272e309>] scsi_sysfs_add_devices drivers/scsi/scsi_scan.c:1727 [inline]
[<ffffffff8272e309>] scsi_finish_async_scan drivers/scsi/scsi_scan.c:1812 [inline]
[<ffffffff8272e309>] do_scan_async+0x109/0x200 drivers/scsi/scsi_scan.c:1855
[<ffffffff812752a4>] async_run_entry_fn+0x24/0xf0 kernel/async.c:127
[<ffffffff81263d1f>] process_one_work+0x2cf/0x620 kernel/workqueue.c:2297
[<ffffffff81264629>] worker_thread+0x59/0x5d0 kernel/workqueue.c:2444
[<ffffffff8126db28>] kthread+0x188/0x1d0 kernel/kthread.c:319
[<ffffffff8100234f>] ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295

BUG: memory leak
unreferenced object 0xffff8881157cde00 (size 256):
comm "kworker/u4:4", pid 2996, jiffies 4294948956 (age 24.640s)
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 08 de 7c 15 81 88 ff ff ..........|.....
08 de 7c 15 81 88 ff ff 10 26 65 82 ff ff ff ff ..|......&e.....
backtrace:
[<ffffffff82657f2b>] kmalloc include/linux/slab.h:591 [inline]
[<ffffffff82657f2b>] kzalloc include/linux/slab.h:721 [inline]
[<ffffffff82657f2b>] device_private_init drivers/base/core.c:3203 [inline]
[<ffffffff82657f2b>] device_add+0x89b/0xdf0 drivers/base/core.c:3253
[<ffffffff81577864>] cdev_device_add+0x84/0xe0 fs/char_dev.c:549
[<ffffffff822547ff>] bsg_register_queue+0x10f/0x1d0 block/bsg.c:206
[<ffffffff82730abf>] scsi_sysfs_add_sdev+0x13f/0x380 drivers/scsi/scsi_sysfs.c:1376
[<ffffffff8272e309>] scsi_sysfs_add_devices drivers/scsi/scsi_scan.c:1727 [inline]
[<ffffffff8272e309>] scsi_finish_async_scan drivers/scsi/scsi_scan.c:1812 [inline]
[<ffffffff8272e309>] do_scan_async+0x109/0x200 drivers/scsi/scsi_scan.c:1855
[<ffffffff812752a4>] async_run_entry_fn+0x24/0xf0 kernel/async.c:127
[<ffffffff81263d1f>] process_one_work+0x2cf/0x620 kernel/workqueue.c:2297
[<ffffffff81264629>] worker_thread+0x59/0x5d0 kernel/workqueue.c:2444
[<ffffffff8126db28>] kthread+0x188/0x1d0 kernel/kthread.c:319
[<ffffffff8100234f>] ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295

BUG: memory leak
unreferenced object 0xffff888114f6c160 (size 32):
comm "kworker/u4:4", pid 2996, jiffies 4294948949 (age 28.480s)
hex dump (first 32 bytes):
38 3a 30 3a 30 3a 30 00 00 00 00 00 00 00 00 00 8:0:0:0.........
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
backtrace:
[<ffffffff8147fc76>] kstrdup+0x36/0x70 mm/util.c:60
[<ffffffff8147fd03>] kstrdup_const+0x53/0x80 mm/util.c:83
[<ffffffff82293362>] kvasprintf_const+0xc2/0x110 lib/kasprintf.c:48
[<ffffffff8235545b>] kobject_set_name_vargs+0x3b/0xe0 lib/kobject.c:289
[<ffffffff82652573>] dev_set_name+0x63/0x90 drivers/base/core.c:3147
[<ffffffff822547d1>] bsg_register_queue+0xe1/0x1d0 block/bsg.c:201
[<ffffffff82730abf>] scsi_sysfs_add_sdev+0x13f/0x380 drivers/scsi/scsi_sysfs.c:1376
[<ffffffff8272e309>] scsi_sysfs_add_devices drivers/scsi/scsi_scan.c:1727 [inline]
[<ffffffff8272e309>] scsi_finish_async_scan drivers/scsi/scsi_scan.c:1812 [inline]
[<ffffffff8272e309>] do_scan_async+0x109/0x200 drivers/scsi/scsi_scan.c:1855
[<ffffffff812752a4>] async_run_entry_fn+0x24/0xf0 kernel/async.c:127
[<ffffffff81263d1f>] process_one_work+0x2cf/0x620 kernel/workqueue.c:2297
[<ffffffff81264629>] worker_thread+0x59/0x5d0 kernel/workqueue.c:2444
[<ffffffff8126db28>] kthread+0x188/0x1d0 kernel/kthread.c:319
[<ffffffff8100234f>] ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295

BUG: memory leak
unreferenced object 0xffff8881170d6200 (size 256):
comm "kworker/u4:4", pid 2996, jiffies 4294948949 (age 28.480s)
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 08 62 0d 17 81 88 ff ff .........b......
08 62 0d 17 81 88 ff ff 10 26 65 82 ff ff ff ff .b.......&e.....
backtrace:
[<ffffffff82657f2b>] kmalloc include/linux/slab.h:591 [inline]
[<ffffffff82657f2b>] kzalloc include/linux/slab.h:721 [inline]
[<ffffffff82657f2b>] device_private_init drivers/base/core.c:3203 [inline]
[<ffffffff82657f2b>] device_add+0x89b/0xdf0 drivers/base/core.c:3253
[<ffffffff81577864>] cdev_device_add+0x84/0xe0 fs/char_dev.c:549
[<ffffffff822547ff>] bsg_register_queue+0x10f/0x1d0 block/bsg.c:206
[<ffffffff82730abf>] scsi_sysfs_add_sdev+0x13f/0x380 drivers/scsi/scsi_sysfs.c:1376
[<ffffffff8272e309>] scsi_sysfs_add_devices drivers/scsi/scsi_scan.c:1727 [inline]
[<ffffffff8272e309>] scsi_finish_async_scan drivers/scsi/scsi_scan.c:1812 [inline]
[<ffffffff8272e309>] do_scan_async+0x109/0x200 drivers/scsi/scsi_scan.c:1855
[<ffffffff812752a4>] async_run_entry_fn+0x24/0xf0 kernel/async.c:127
[<ffffffff81263d1f>] process_one_work+0x2cf/0x620 kernel/workqueue.c:2297
[<ffffffff81264629>] worker_thread+0x59/0x5d0 kernel/workqueue.c:2444
[<ffffffff8126db28>] kthread+0x188/0x1d0 kernel/kthread.c:319
[<ffffffff8100234f>] ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295

BUG: memory leak
unreferenced object 0xffff8881170da100 (size 32):
comm "kworker/u4:4", pid 2996, jiffies 4294948956 (age 28.410s)
hex dump (first 32 bytes):
38 3a 30 3a 30 3a 31 00 00 00 00 00 00 00 00 00 8:0:0:1.........
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
backtrace:
[<ffffffff8147fc76>] kstrdup+0x36/0x70 mm/util.c:60
[<ffffffff8147fd03>] kstrdup_const+0x53/0x80 mm/util.c:83
[<ffffffff82293362>] kvasprintf_const+0xc2/0x110 lib/kasprintf.c:48
[<ffffffff8235545b>] kobject_set_name_vargs+0x3b/0xe0 lib/kobject.c:289
[<ffffffff82652573>] dev_set_name+0x63/0x90 drivers/base/core.c:3147
[<ffffffff822547d1>] bsg_register_queue+0xe1/0x1d0 block/bsg.c:201
[<ffffffff82730abf>] scsi_sysfs_add_sdev+0x13f/0x380 drivers/scsi/scsi_sysfs.c:1376
[<ffffffff8272e309>] scsi_sysfs_add_devices drivers/scsi/scsi_scan.c:1727 [inline]
[<ffffffff8272e309>] scsi_finish_async_scan drivers/scsi/scsi_scan.c:1812 [inline]
[<ffffffff8272e309>] do_scan_async+0x109/0x200 drivers/scsi/scsi_scan.c:1855
[<ffffffff812752a4>] async_run_entry_fn+0x24/0xf0 kernel/async.c:127
[<ffffffff81263d1f>] process_one_work+0x2cf/0x620 kernel/workqueue.c:2297
[<ffffffff81264629>] worker_thread+0x59/0x5d0 kernel/workqueue.c:2444
[<ffffffff8126db28>] kthread+0x188/0x1d0 kernel/kthread.c:319
[<ffffffff8100234f>] ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295

BUG: memory leak
unreferenced object 0xffff8881157cde00 (size 256):
comm "kworker/u4:4", pid 2996, jiffies 4294948956 (age 28.410s)
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 08 de 7c 15 81 88 ff ff ..........|.....
08 de 7c 15 81 88 ff ff 10 26 65 82 ff ff ff ff ..|......&e.....
backtrace:
[<ffffffff82657f2b>] kmalloc include/linux/slab.h:591 [inline]
[<ffffffff82657f2b>] kzalloc include/linux/slab.h:721 [inline]
[<ffffffff82657f2b>] device_private_init drivers/base/core.c:3203 [inline]
[<ffffffff82657f2b>] device_add+0x89b/0xdf0 drivers/base/core.c:3253
[<ffffffff81577864>] cdev_device_add+0x84/0xe0 fs/char_dev.c:549
[<ffffffff822547ff>] bsg_register_queue+0x10f/0x1d0 block/bsg.c:206
[<ffffffff82730abf>] scsi_sysfs_add_sdev+0x13f/0x380 drivers/scsi/scsi_sysfs.c:1376
[<ffffffff8272e309>] scsi_sysfs_add_devices drivers/scsi/scsi_scan.c:1727 [inline]
[<ffffffff8272e309>] scsi_finish_async_scan drivers/scsi/scsi_scan.c:1812 [inline]
[<ffffffff8272e309>] do_scan_async+0x109/0x200 drivers/scsi/scsi_scan.c:1855
[<ffffffff812752a4>] async_run_entry_fn+0x24/0xf0 kernel/async.c:127
[<ffffffff81263d1f>] process_one_work+0x2cf/0x620 kernel/workqueue.c:2297
[<ffffffff81264629>] worker_thread+0x59/0x5d0 kernel/workqueue.c:2444
[<ffffffff8126db28>] kthread+0x188/0x1d0 kernel/kthread.c:319
[<ffffffff8100234f>] ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295

BUG: memory leak
unreferenced object 0xffff888114f6c160 (size 32):
comm "kworker/u4:4", pid 2996, jiffies 4294948949 (age 29.750s)
hex dump (first 32 bytes):
38 3a 30 3a 30 3a 30 00 00 00 00 00 00 00 00 00 8:0:0:0.........
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
backtrace:
[<ffffffff8147fc76>] kstrdup+0x36/0x70 mm/util.c:60
[<ffffffff8147fd03>] kstrdup_const+0x53/0x80 mm/util.c:83
[<ffffffff82293362>] kvasprintf_const+0xc2/0x110 lib/kasprintf.c:48
[<ffffffff8235545b>] kobject_set_name_vargs+0x3b/0xe0 lib/kobject.c:289
[<ffffffff82652573>] dev_set_name+0x63/0x90 drivers/base/core.c:3147
[<ffffffff822547d1>] bsg_register_queue+0xe1/0x1d0 block/bsg.c:201
[<ffffffff82730abf>] scsi_sysfs_add_sdev+0x13f/0x380 drivers/scsi/scsi_sysfs.c:1376
[<ffffffff8272e309>] scsi_sysfs_add_devices drivers/scsi/scsi_scan.c:1727 [inline]
[<ffffffff8272e309>] scsi_finish_async_scan drivers/scsi/scsi_scan.c:1812 [inline]
[<ffffffff8272e309>] do_scan_async+0x109/0x200 drivers/scsi/scsi_scan.c:1855
[<ffffffff812752a4>] async_run_entry_fn+0x24/0xf0 kernel/async.c:127
[<ffffffff81263d1f>] process_one_work+0x2cf/0x620 kernel/workqueue.c:2297
[<ffffffff81264629>] worker_thread+0x59/0x5d0 kernel/workqueue.c:2444
[<ffffffff8126db28>] kthread+0x188/0x1d0 kernel/kthread.c:319
[<ffffffff8100234f>] ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295

BUG: memory leak
unreferenced object 0xffff8881170d6200 (size 256):
comm "kworker/u4:4", pid 2996, jiffies 4294948949 (age 29.760s)
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 08 62 0d 17 81 88 ff ff .........b......
08 62 0d 17 81 88 ff ff 10 26 65 82 ff ff ff ff .b.......&e.....
backtrace:
[<ffffffff82657f2b>] kmalloc include/linux/slab.h:591 [inline]
[<ffffffff82657f2b>] kzalloc include/linux/slab.h:721 [inline]
[<ffffffff82657f2b>] device_private_init drivers/base/core.c:3203 [inline]
[<ffffffff82657f2b>] device_add+0x89b/0xdf0 drivers/base/core.c:3253
[<ffffffff81577864>] cdev_device_add+0x84/0xe0 fs/char_dev.c:549
[<ffffffff822547ff>] bsg_register_queue+0x10f/0x1d0 block/bsg.c:206
[<ffffffff82730abf>] scsi_sysfs_add_sdev+0x13f/0x380 drivers/scsi/scsi_sysfs.c:1376
[<ffffffff8272e309>] scsi_sysfs_add_devices drivers/scsi/scsi_scan.c:1727 [inline]
[<ffffffff8272e309>] scsi_finish_async_scan drivers/scsi/scsi_scan.c:1812 [inline]
[<ffffffff8272e309>] do_scan_async+0x109/0x200 drivers/scsi/scsi_scan.c:1855
[<ffffffff812752a4>] async_run_entry_fn+0x24/0xf0 kernel/async.c:127
[<ffffffff81263d1f>] process_one_work+0x2cf/0x620 kernel/workqueue.c:2297
[<ffffffff81264629>] worker_thread+0x59/0x5d0 kernel/workqueue.c:2444
[<ffffffff8126db28>] kthread+0x188/0x1d0 kernel/kthread.c:319
[<ffffffff8100234f>] ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295

BUG: memory leak
unreferenced object 0xffff8881170da100 (size 32):
comm "kworker/u4:4", pid 2996, jiffies 4294948956 (age 29.690s)
hex dump (first 32 bytes):
38 3a 30 3a 30 3a 31 00 00 00 00 00 00 00 00 00 8:0:0:1.........
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
backtrace:
[<ffffffff8147fc76>] kstrdup+0x36/0x70 mm/util.c:60
[<ffffffff8147fd03>] kstrdup_const+0x53/0x80 mm/util.c:83
[<ffffffff82293362>] kvasprintf_const+0xc2/0x110 lib/kasprintf.c:48
[<ffffffff8235545b>] kobject_set_name_vargs+0x3b/0xe0 lib/kobject.c:289
[<ffffffff82652573>] dev_set_name+0x63/0x90 drivers/base/core.c:3147
[<ffffffff822547d1>] bsg_register_queue+0xe1/0x1d0 block/bsg.c:201
[<ffffffff82730abf>] scsi_sysfs_add_sdev+0x13f/0x380 drivers/scsi/scsi_sysfs.c:1376
[<ffffffff8272e309>] scsi_sysfs_add_devices drivers/scsi/scsi_scan.c:1727 [inline]
[<ffffffff8272e309>] scsi_finish_async_scan drivers/scsi/scsi_scan.c:1812 [inline]
[<ffffffff8272e309>] do_scan_async+0x109/0x200 drivers/scsi/scsi_scan.c:1855
[<ffffffff812752a4>] async_run_entry_fn+0x24/0xf0 kernel/async.c:127
[<ffffffff81263d1f>] process_one_work+0x2cf/0x620 kernel/workqueue.c:2297
[<ffffffff81264629>] worker_thread+0x59/0x5d0 kernel/workqueue.c:2444
[<ffffffff8126db28>] kthread+0x188/0x1d0 kernel/kthread.c:319
[<ffffffff8100234f>] ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295

BUG: memory leak
unreferenced object 0xffff8881157cde00 (size 256):
comm "kworker/u4:4", pid 2996, jiffies 4294948956 (age 29.690s)
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 08 de 7c 15 81 88 ff ff ..........|.....
08 de 7c 15 81 88 ff ff 10 26 65 82 ff ff ff ff ..|......&e.....
backtrace:
[<ffffffff82657f2b>] kmalloc include/linux/slab.h:591 [inline]
[<ffffffff82657f2b>] kzalloc include/linux/slab.h:721 [inline]
[<ffffffff82657f2b>] device_private_init drivers/base/core.c:3203 [inline]
[<ffffffff82657f2b>] device_add+0x89b/0xdf0 drivers/base/core.c:3253
[<ffffffff81577864>] cdev_device_add+0x84/0xe0 fs/char_dev.c:549
[<ffffffff822547ff>] bsg_register_queue+0x10f/0x1d0 block/bsg.c:206
[<ffffffff82730abf>] scsi_sysfs_add_sdev+0x13f/0x380 drivers/scsi/scsi_sysfs.c:1376
[<ffffffff8272e309>] scsi_sysfs_add_devices drivers/scsi/scsi_scan.c:1727 [inline]
[<ffffffff8272e309>] scsi_finish_async_scan drivers/scsi/scsi_scan.c:1812 [inline]
[<ffffffff8272e309>] do_scan_async+0x109/0x200 drivers/scsi/scsi_scan.c:1855
[<ffffffff812752a4>] async_run_entry_fn+0x24/0xf0 kernel/async.c:127
[<ffffffff81263d1f>] process_one_work+0x2cf/0x620 kernel/workqueue.c:2297
[<ffffffff81264629>] worker_thread+0x59/0x5d0 kernel/workqueue.c:2444
[<ffffffff8126db28>] kthread+0x188/0x1d0 kernel/kthread.c:319
[<ffffffff8100234f>] ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295

executing program
executing program
executing program
executing program


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this issue, for details see:
https://goo.gl/tpsmEJ#testing-patches

syzbot

unread,
Sep 12, 2021, 2:51:06 AM9/12/21
to phin...@gmail.com, syzkall...@googlegroups.com
Hello,

syzbot has tested the proposed patch but the reproducer is still triggering an issue:
memory leak in kobject_set_name_vargs

BUG: memory leak
unreferenced object 0xffff88812b2b0460 (size 32):
comm "kworker/u4:1", pid 147, jiffies 4294944898 (age 14.640s)
hex dump (first 32 bytes):
31 3a 30 3a 30 3a 30 00 00 00 00 00 00 00 00 00 1:0:0:0.........
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
backtrace:
[<ffffffff81483076>] kstrdup+0x36/0x70 mm/util.c:60
[<ffffffff81483103>] kstrdup_const+0x53/0x80 mm/util.c:83
[<ffffffff82296122>] kvasprintf_const+0xc2/0x110 lib/kasprintf.c:48
[<ffffffff823587db>] kobject_set_name_vargs+0x3b/0xe0 lib/kobject.c:289
[<ffffffff82657393>] dev_set_name+0x63/0x90 drivers/base/core.c:3147
[<ffffffff822577c1>] bsg_register_queue+0xe1/0x1d0 block/bsg.c:201
[<ffffffff82735f2f>] scsi_sysfs_add_sdev+0x13f/0x380 drivers/scsi/scsi_sysfs.c:1376
[<ffffffff82733779>] scsi_sysfs_add_devices drivers/scsi/scsi_scan.c:1727 [inline]
[<ffffffff82733779>] scsi_finish_async_scan drivers/scsi/scsi_scan.c:1812 [inline]
[<ffffffff82733779>] do_scan_async+0x109/0x200 drivers/scsi/scsi_scan.c:1855
[<ffffffff81277234>] async_run_entry_fn+0x24/0xf0 kernel/async.c:127
[<ffffffff81265d22>] process_one_work+0x2c2/0x610 kernel/workqueue.c:2297
[<ffffffff81266629>] worker_thread+0x59/0x5d0 kernel/workqueue.c:2444
[<ffffffff8126fb58>] kthread+0x188/0x1d0 kernel/kthread.c:319
[<ffffffff8100234f>] ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295

BUG: memory leak
unreferenced object 0xffff88812a017d00 (size 256):
comm "kworker/u4:1", pid 147, jiffies 4294944898 (age 14.640s)
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 08 7d 01 2a 81 88 ff ff .........}.*....
08 7d 01 2a 81 88 ff ff 30 74 65 82 ff ff ff ff .}.*....0te.....
backtrace:
[<ffffffff8265cd4b>] kmalloc include/linux/slab.h:594 [inline]
[<ffffffff8265cd4b>] kzalloc include/linux/slab.h:731 [inline]
[<ffffffff8265cd4b>] device_private_init drivers/base/core.c:3203 [inline]
[<ffffffff8265cd4b>] device_add+0x89b/0xdf0 drivers/base/core.c:3253
[<ffffffff815799b4>] cdev_device_add+0x84/0xe0 fs/char_dev.c:549
[<ffffffff822577ef>] bsg_register_queue+0x10f/0x1d0 block/bsg.c:206
[<ffffffff82735f2f>] scsi_sysfs_add_sdev+0x13f/0x380 drivers/scsi/scsi_sysfs.c:1376
[<ffffffff82733779>] scsi_sysfs_add_devices drivers/scsi/scsi_scan.c:1727 [inline]
[<ffffffff82733779>] scsi_finish_async_scan drivers/scsi/scsi_scan.c:1812 [inline]
[<ffffffff82733779>] do_scan_async+0x109/0x200 drivers/scsi/scsi_scan.c:1855
[<ffffffff81277234>] async_run_entry_fn+0x24/0xf0 kernel/async.c:127
[<ffffffff81265d22>] process_one_work+0x2c2/0x610 kernel/workqueue.c:2297
[<ffffffff81266629>] worker_thread+0x59/0x5d0 kernel/workqueue.c:2444
[<ffffffff8126fb58>] kthread+0x188/0x1d0 kernel/kthread.c:319
[<ffffffff8100234f>] ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295

BUG: memory leak
unreferenced object 0xffff88812b2b0be0 (size 32):
comm "kworker/u4:1", pid 147, jiffies 4294944900 (age 14.620s)
hex dump (first 32 bytes):
31 3a 30 3a 30 3a 31 00 00 00 00 00 00 00 00 00 1:0:0:1.........
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
backtrace:
[<ffffffff81483076>] kstrdup+0x36/0x70 mm/util.c:60
[<ffffffff81483103>] kstrdup_const+0x53/0x80 mm/util.c:83
[<ffffffff82296122>] kvasprintf_const+0xc2/0x110 lib/kasprintf.c:48
[<ffffffff823587db>] kobject_set_name_vargs+0x3b/0xe0 lib/kobject.c:289
[<ffffffff82657393>] dev_set_name+0x63/0x90 drivers/base/core.c:3147
[<ffffffff822577c1>] bsg_register_queue+0xe1/0x1d0 block/bsg.c:201
[<ffffffff82735f2f>] scsi_sysfs_add_sdev+0x13f/0x380 drivers/scsi/scsi_sysfs.c:1376
[<ffffffff82733779>] scsi_sysfs_add_devices drivers/scsi/scsi_scan.c:1727 [inline]
[<ffffffff82733779>] scsi_finish_async_scan drivers/scsi/scsi_scan.c:1812 [inline]
[<ffffffff82733779>] do_scan_async+0x109/0x200 drivers/scsi/scsi_scan.c:1855
[<ffffffff81277234>] async_run_entry_fn+0x24/0xf0 kernel/async.c:127
[<ffffffff81265d22>] process_one_work+0x2c2/0x610 kernel/workqueue.c:2297
[<ffffffff81266629>] worker_thread+0x59/0x5d0 kernel/workqueue.c:2444
[<ffffffff8126fb58>] kthread+0x188/0x1d0 kernel/kthread.c:319
[<ffffffff8100234f>] ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295

BUG: memory leak
unreferenced object 0xffff88812a017800 (size 256):
comm "kworker/u4:1", pid 147, jiffies 4294944900 (age 14.620s)
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 08 78 01 2a 81 88 ff ff .........x.*....
08 78 01 2a 81 88 ff ff 30 74 65 82 ff ff ff ff .x.*....0te.....
backtrace:
[<ffffffff8265cd4b>] kmalloc include/linux/slab.h:594 [inline]
[<ffffffff8265cd4b>] kzalloc include/linux/slab.h:731 [inline]
[<ffffffff8265cd4b>] device_private_init drivers/base/core.c:3203 [inline]
[<ffffffff8265cd4b>] device_add+0x89b/0xdf0 drivers/base/core.c:3253
[<ffffffff815799b4>] cdev_device_add+0x84/0xe0 fs/char_dev.c:549
[<ffffffff822577ef>] bsg_register_queue+0x10f/0x1d0 block/bsg.c:206
[<ffffffff82735f2f>] scsi_sysfs_add_sdev+0x13f/0x380 drivers/scsi/scsi_sysfs.c:1376
[<ffffffff82733779>] scsi_sysfs_add_devices drivers/scsi/scsi_scan.c:1727 [inline]
[<ffffffff82733779>] scsi_finish_async_scan drivers/scsi/scsi_scan.c:1812 [inline]
[<ffffffff82733779>] do_scan_async+0x109/0x200 drivers/scsi/scsi_scan.c:1855
[<ffffffff81277234>] async_run_entry_fn+0x24/0xf0 kernel/async.c:127
[<ffffffff81265d22>] process_one_work+0x2c2/0x610 kernel/workqueue.c:2297
[<ffffffff81266629>] worker_thread+0x59/0x5d0 kernel/workqueue.c:2444
[<ffffffff8126fb58>] kthread+0x188/0x1d0 kernel/kthread.c:319
[<ffffffff8100234f>] ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295



Tested on:

commit: aa14a301 Add linux-next specific files for 20210910
git tree: linux-next
console output: https://syzkaller.appspot.com/x/log.txt?x=116e8cc3300000
kernel config: https://syzkaller.appspot.com/x/.config?x=d5fe784b1254f348

Pavel Skripkin

unread,
Sep 29, 2021, 12:30:21 PM9/29/21
to syzbot, gre...@linuxfoundation.org, linux-...@vger.kernel.org, raf...@kernel.org, syzkall...@googlegroups.com
On 9/10/21 15:01, syzbot wrote:
> Hello,
>
> syzbot found the following issue on:
>
> HEAD commit: 0319b848b155 binfmt: a.out: Fix bogus semicolon
> git tree: upstream
> console output: https://syzkaller.appspot.com/x/log.txt?x=1776fab5300000
> kernel config: https://syzkaller.appspot.com/x/.config?x=4d196bb8b1e038c0
> dashboard link: https://syzkaller.appspot.com/bug?extid=cfe9b7cf55bb54ed4e57
> compiler: gcc (Debian 10.2.1-6) 10.2.1 20210110, GNU ld (GNU Binutils for Debian) 2.35.1
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=15b2e115300000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=10f2147d300000
>
> IMPORTANT: if you fix the issue, please add the following tag to the commit:
> Reported-by: syzbot+cfe9b7...@syzkaller.appspotmail.com
>

#syz test:
git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux-block.git
1a0db7744e453844aa2db3f2959aea4a378025ea


With regards,
Pavel Skripkin

syzbot

unread,
Sep 29, 2021, 6:16:08 PM9/29/21
to gre...@linuxfoundation.org, linux-...@vger.kernel.org, paskr...@gmail.com, raf...@kernel.org, syzkall...@googlegroups.com
Hello,

syzbot has tested the proposed patch and the reproducer did not trigger any issue:

Reported-and-tested-by: syzbot+cfe9b7...@syzkaller.appspotmail.com

Tested on:

commit: 1a0db774 scsi: bsg: Fix device unregistration
git tree: git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux-block.git
kernel config: https://syzkaller.appspot.com/x/.config?x=a4a1f32762f17135
dashboard link: https://syzkaller.appspot.com/bug?extid=cfe9b7cf55bb54ed4e57
compiler: gcc (Debian 10.2.1-6) 10.2.1 20210110, GNU ld (GNU Binutils for Debian) 2.35.2

Note: testing is done by a robot and is best-effort only.

Pavel Skripkin

unread,
Sep 30, 2021, 2:13:34 PM9/30/21
to syzbot, gre...@linuxfoundation.org, linux-...@vger.kernel.org, raf...@kernel.org, syzkall...@googlegroups.com
#syz fix: scsi: bsg: Fix device unregistration


With regards,
Pavel Skripkin
Reply all
Reply to author
Forward
0 new messages