[v6.1] VFS: Busy inodes after unmount (use-after-free)

1 view
Skip to first unread message

syzbot

unread,
Mar 18, 2023, 5:53:55 AM3/18/23
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 7eaef76fbc46 Linux 6.1.20
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=10cc369ac80000
kernel config: https://syzkaller.appspot.com/x/.config?x=28c36fe4d02f8c88
dashboard link: https://syzkaller.appspot.com/bug?extid=8f448a401cc209730b34
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/610a00ba4375/disk-7eaef76f.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/57c1310f9a30/vmlinux-7eaef76f.xz
kernel image: https://storage.googleapis.com/syzbot-assets/81999f717d3b/bzImage-7eaef76f.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+8f448a...@syzkaller.appspotmail.com

VFS: Busy inodes after unmount of loop4 (btrfs)
------------[ cut here ]------------
kernel BUG at fs/super.c:496!
invalid opcode: 0000 [#1] PREEMPT SMP KASAN
CPU: 1 PID: 3672 Comm: syz-executor.4 Not tainted 6.1.20-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/02/2023
RIP: 0010:generic_shutdown_super+0x339/0x340 fs/super.c:494
Code: 8b 1b 48 89 d8 48 c1 e8 03 42 80 3c 28 00 74 08 48 89 df e8 19 f8 f0 ff 48 8b 13 48 c7 c7 a0 12 f9 8a 4c 89 fe e8 a0 74 98 08 <0f> 0b 0f 1f 44 00 00 41 57 41 56 53 49 89 fe 49 bf 00 00 00 00 00
RSP: 0018:ffffc900042cfcf0 EFLAGS: 00010246
RAX: 000000000000002f RBX: ffffffff8d437e60 RCX: 860cba9235d7de00
RDX: 0000000000000000 RSI: 0000000080000000 RDI: 0000000000000000
RBP: 1ffff11007979cfb R08: ffffffff816e120c R09: fffff52000859f55
R10: 0000000000000000 R11: dffffc0000000001 R12: 0000000000000000
R13: dffffc0000000000 R14: ffffffff8b2d0818 R15: ffff88803cbce6a8
FS: 0000555555a1b400(0000) GS:ffff8880b9900000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000020001842 CR3: 000000003649a000 CR4: 00000000003506e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
kill_anon_super+0x37/0x60 fs/super.c:1099
btrfs_kill_super+0x3d/0x50 fs/btrfs/super.c:2441
deactivate_locked_super+0xa0/0x110 fs/super.c:332
cleanup_mnt+0x490/0x520 fs/namespace.c:1186
task_work_run+0x246/0x300 kernel/task_work.c:179
resume_user_mode_work include/linux/resume_user_mode.h:49 [inline]
exit_to_user_mode_loop+0xd9/0x100 kernel/entry/common.c:171
exit_to_user_mode_prepare+0xb1/0x140 kernel/entry/common.c:203
__syscall_exit_to_user_mode_work kernel/entry/common.c:285 [inline]
syscall_exit_to_user_mode+0x60/0x2d0 kernel/entry/common.c:296
do_syscall_64+0x49/0xb0 arch/x86/entry/common.c:86
entry_SYSCALL_64_after_hwframe+0x63/0xcd
RIP: 0033:0x7f6da468d567
Code: ff ff ff f7 d8 64 89 01 48 83 c8 ff c3 66 0f 1f 44 00 00 31 f6 e9 09 00 00 00 66 0f 1f 84 00 00 00 00 00 b8 a6 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ffdfaf41f58 EFLAGS: 00000246 ORIG_RAX: 00000000000000a6
RAX: 0000000000000000 RBX: 0000000000000000 RCX: 00007f6da468d567
RDX: 00007ffdfaf4202a RSI: 000000000000000a RDI: 00007ffdfaf42020
RBP: 00007ffdfaf42020 R08: 00000000ffffffff R09: 00007ffdfaf41df0
R10: 0000555555a1c903 R11: 0000000000000246 R12: 00007f6da46e6b74
R13: 00007ffdfaf430e0 R14: 0000555555a1c810 R15: 00007ffdfaf43120
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:generic_shutdown_super+0x339/0x340 fs/super.c:494
Code: 8b 1b 48 89 d8 48 c1 e8 03 42 80 3c 28 00 74 08 48 89 df e8 19 f8 f0 ff 48 8b 13 48 c7 c7 a0 12 f9 8a 4c 89 fe e8 a0 74 98 08 <0f> 0b 0f 1f 44 00 00 41 57 41 56 53 49 89 fe 49 bf 00 00 00 00 00
RSP: 0018:ffffc900042cfcf0 EFLAGS: 00010246
RAX: 000000000000002f RBX: ffffffff8d437e60 RCX: 860cba9235d7de00
RDX: 0000000000000000 RSI: 0000000080000000 RDI: 0000000000000000
RBP: 1ffff11007979cfb R08: ffffffff816e120c R09: fffff52000859f55
R10: 0000000000000000 R11: dffffc0000000001 R12: 0000000000000000
R13: dffffc0000000000 R14: ffffffff8b2d0818 R15: ffff88803cbce6a8
FS: 0000555555a1b400(0000) GS:ffff8880b9800000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fbce8b821b8 CR3: 000000003649a000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Mar 19, 2023, 7:46:45 AM3/19/23
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 8020ae3c051d Linux 5.15.103
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=12e06e4ac80000
kernel config: https://syzkaller.appspot.com/x/.config?x=d4215fb4040f8f8d
dashboard link: https://syzkaller.appspot.com/bug?extid=d5fb8af502fef70f9aa1
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/857e17de0f0a/disk-8020ae3c.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/9efc49fcd441/vmlinux-8020ae3c.xz
kernel image: https://storage.googleapis.com/syzbot-assets/f14c38b6bfa7/bzImage-8020ae3c.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+d5fb8a...@syzkaller.appspotmail.com

VFS: Busy inodes after unmount of loop4. Self-destruct in 5 seconds. Have a nice day...

syzbot

unread,
Mar 19, 2023, 6:43:41 PM3/19/23
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 8020ae3c051d Linux 5.15.103
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=16c0581cc80000
kernel config: https://syzkaller.appspot.com/x/.config?x=d4215fb4040f8f8d
dashboard link: https://syzkaller.appspot.com/bug?extid=d5fb8af502fef70f9aa1
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=16f5e091c80000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=152a6f26c80000
mounted in repro: https://storage.googleapis.com/syzbot-assets/3365f2dd3305/mount_1.gz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+d5fb8a...@syzkaller.appspotmail.com

VFS: Busy inodes after unmount of loop0. Self-destruct in 5 seconds. Have a nice day...

syzbot

unread,
Jul 9, 2023, 5:29:41 PM7/9/23
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 61fd484b2cf6 Linux 6.1.38
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=14ffa0b0a80000
kernel config: https://syzkaller.appspot.com/x/.config?x=6f0f33ddb500fad0
dashboard link: https://syzkaller.appspot.com/bug?extid=8f448a401cc209730b34
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=15391d1ca80000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=13bf7c82a80000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/898eff1fdc20/disk-61fd484b.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/c5a649af018f/vmlinux-61fd484b.xz
kernel image: https://storage.googleapis.com/syzbot-assets/30a2cee1f58d/Image-61fd484b.gz.xz
mounted in repro: https://storage.googleapis.com/syzbot-assets/c2cf95af6233/mount_0.gz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+8f448a...@syzkaller.appspotmail.com

VFS: Busy inodes after unmount of loop3 (btrfs)
------------[ cut here ]------------
kernel BUG at fs/super.c:505!
Internal error: Oops - BUG: 00000000f2000800 [#1] PREEMPT SMP
Modules linked in:
CPU: 0 PID: 4250 Comm: syz-executor101 Not tainted 6.1.38-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/27/2023
pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : generic_shutdown_super+0x324/0x328 fs/super.c:503
lr : generic_shutdown_super+0x324/0x328 fs/super.c:503
sp : ffff80001d9e78d0
x29: ffff80001d9e78d0 x28: 1ffff00002ab9aa9 x27: dfff800000000000
x26: 0000000000000002 x25: 0000000000000002 x24: 1fffe0001b5638fb
x23: dfff800000000000 x22: ffff80001264d160 x21: 0000000000000000
x20: ffff800015c94d40 x19: ffff0000dab1c6a8 x18: ffff80001d9e7120
x17: ffff8000155cd000 x16: ffff800012110e94 x15: 0000000000000000
x14: 0000000000000000 x13: 0000000000000001 x12: 0000000000000001
x11: ff80800008343e58 x10: 0000000000000000 x9 : 7bd34ceef9fd3b00
x8 : 7bd34ceef9fd3b00 x7 : 0000000000000001 x6 : 0000000000000001
x5 : ffff80001d9e71d8 x4 : ffff8000156b2ac0 x3 : ffff80000aa74bac
x2 : ffff0001b45accd0 x1 : 0000000100000000 x0 : 000000000000002f
Call trace:
generic_shutdown_super+0x324/0x328 fs/super.c:503
kill_anon_super+0x4c/0x74 fs/super.c:1108
btrfs_kill_super+0x40/0x58 fs/btrfs/super.c:2445
deactivate_locked_super+0xac/0x124 fs/super.c:332
deactivate_super+0xf0/0x110 fs/super.c:363
cleanup_mnt+0x394/0x41c fs/namespace.c:1186
__cleanup_mnt+0x20/0x30 fs/namespace.c:1193
task_work_run+0x240/0x2f0 kernel/task_work.c:179
resume_user_mode_work include/linux/resume_user_mode.h:49 [inline]
do_notify_resume+0x2144/0x3470 arch/arm64/kernel/signal.c:1132
prepare_exit_to_user_mode arch/arm64/kernel/entry-common.c:137 [inline]
exit_to_user_mode arch/arm64/kernel/entry-common.c:142 [inline]
el0_svc+0x9c/0x168 arch/arm64/kernel/entry-common.c:638
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:581
Code: b004c720 911a8000 aa1303e1 95d37a4e (d4210000)
---[ end trace 0000000000000000 ]---


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
Reply all
Reply to author
Forward
0 new messages