general protection fault in do_exit

4 views
Skip to first unread message

syzbot

unread,
Jul 10, 2020, 3:04:19 AM7/10/20
to syzkaller-upst...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 7cc2a8ea Merge tag 'block-5.8-2020-07-01' of git://git.ker..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=15c1cfd3100000
kernel config: https://syzkaller.appspot.com/x/.config?x=7be693511b29b338
dashboard link: https://syzkaller.appspot.com/bug?extid=3c8ad410705a84d57a14
compiler: gcc (GCC) 10.1.0-syz 20200507
CC: [chri...@brauner.io ebie...@xmission.com ja...@google.com linux-...@vger.kernel.org mi...@kernel.org ol...@redhat.com pet...@infradead.org tg...@linutronix.de]

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+3c8ad4...@syzkaller.appspotmail.com

general protection fault, probably for non-canonical address 0xdffffc000000000f: 0000 [#1] PREEMPT SMP KASAN
KASAN: null-ptr-deref in range [0x0000000000000078-0x000000000000007f]
CPU: 0 PID: 24037 Comm: syz-executor.4 Not tainted 5.8.0-rc3-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
RIP: 0010:find_child_reaper kernel/exit.c:504 [inline]
RIP: 0010:forget_original_parent kernel/exit.c:612 [inline]
RIP: 0010:exit_notify kernel/exit.c:649 [inline]
RIP: 0010:do_exit+0xc65/0x2a40 kernel/exit.c:826
Code: 85 fb 11 00 00 e8 fb 86 2d 00 48 89 ef e8 03 b4 06 00 48 8d 78 78 49 89 c4 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 c8 19 00 00 49 8b 44 24 78 48 39 c5 48 89 04 24
RSP: 0018:ffffc90018d87b90 EFLAGS: 00010006
RAX: dffffc0000000000 RBX: ffff888049f7a960 RCX: ffffffff815b03da
RDX: 000000000000000f RSI: ffffffff814ce515 RDI: 0000000000000078
RBP: ffff888049f7a440 R08: 0000000000000001 R09: 0000000000000003
R10: fffff520031b0f64 R11: 0000000000000000 R12: 0000000000000000
R13: 0000000000000001 R14: ffff88804c58f900 R15: ffff88808ebdc840
FS: 00007fb98ffeb700(0000) GS:ffff8880ae600000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000001b2f625000 CR3: 000000005df71000 CR4: 00000000001426f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
do_group_exit+0x125/0x310 kernel/exit.c:903
get_signal+0x40b/0x1ee0 kernel/signal.c:2743
do_signal+0x82/0x2520 arch/x86/kernel/signal.c:810
exit_to_usermode_loop arch/x86/entry/common.c:212 [inline]
__prepare_exit_to_usermode+0x156/0x1f0 arch/x86/entry/common.c:246
do_syscall_64+0x6c/0xe0 arch/x86/entry/common.c:368
entry_SYSCALL_64_after_hwframe+0x44/0xa9
RIP: 0033:0x45cb29
Code: Bad RIP value.
RSP: 002b:00007fb98ffeacf8 EFLAGS: 00000246 ORIG_RAX: 00000000000000ca
RAX: fffffffffffffe00 RBX: 000000000078bfa8 RCX: 000000000045cb29
RDX: 0000000000000000 RSI: 0000000000000080 RDI: 000000000078bfa8
RBP: 000000000078bfa0 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 000000000078bfac
R13: 00007fff377d383f R14: 00007fb98ffeb9c0 R15: 000000000078bfac
Modules linked in:
---[ end trace 5fdb3d286163e54c ]---
RIP: 0010:find_child_reaper kernel/exit.c:504 [inline]
RIP: 0010:forget_original_parent kernel/exit.c:612 [inline]
RIP: 0010:exit_notify kernel/exit.c:649 [inline]
RIP: 0010:do_exit+0xc65/0x2a40 kernel/exit.c:826
Code: 85 fb 11 00 00 e8 fb 86 2d 00 48 89 ef e8 03 b4 06 00 48 8d 78 78 49 89 c4 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 c8 19 00 00 49 8b 44 24 78 48 39 c5 48 89 04 24
RSP: 0018:ffffc90018d87b90 EFLAGS: 00010006
RAX: dffffc0000000000 RBX: ffff888049f7a960 RCX: ffffffff815b03da
RDX: 000000000000000f RSI: ffffffff814ce515 RDI: 0000000000000078
RBP: ffff888049f7a440 R08: 0000000000000001 R09: 0000000000000003
R10: fffff520031b0f64 R11: 0000000000000000 R12: 0000000000000000
R13: 0000000000000001 R14: ffff88804c58f900 R15: ffff88808ebdc840
FS: 00007fb98ffeb700(0000) GS:ffff8880ae600000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000001b2f625000 CR3: 000000005df71000 CR4: 00000000001426f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Oct 4, 2020, 2:58:15 AM10/4/20
to syzkaller-upst...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages