KCSAN: data-race in tomoyo_domain_quota_is_ok / tomoyo_merge_path_acl (4)

8 views
Skip to first unread message

syzbot

unread,
Dec 7, 2020, 6:45:12 AM12/7/20
to syzkaller-upst...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: d5beb314 Merge tag 'hyperv-fixes-signed' of git://git.kern..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=1521653e500000
kernel config: https://syzkaller.appspot.com/x/.config?x=cf114765a0c30afa
dashboard link: https://syzkaller.appspot.com/bug?extid=0789a72b46fd91431bd8
compiler: clang version 12.0.0 (https://github.com/llvm/llvm-project.git 913f6005669cfb590c99865a90bc51ed0983d09d)
CC: [jmo...@namei.org linux-...@vger.kernel.org linux-secu...@vger.kernel.org penguin...@I-love.SAKURA.ne.jp se...@hallyn.com take...@nttdata.co.jp]

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+0789a7...@syzkaller.appspotmail.com

==================================================================
BUG: KCSAN: data-race in tomoyo_domain_quota_is_ok / tomoyo_merge_path_acl

write to 0xffff888133f2dada of 2 bytes by task 8444 on cpu 0:
tomoyo_merge_path_acl+0x4c/0x70 security/tomoyo/file.c:372
tomoyo_update_domain+0x337/0x3a0 security/tomoyo/domain.c:131
tomoyo_update_path_acl security/tomoyo/file.c:398 [inline]
tomoyo_write_file+0x210/0x910 security/tomoyo/file.c:1022
tomoyo_write_domain2 security/tomoyo/common.c:1152 [inline]
tomoyo_add_entry security/tomoyo/common.c:2042 [inline]
tomoyo_supervisor+0xaad/0xb20 security/tomoyo/common.c:2103
tomoyo_audit_path_log security/tomoyo/file.c:168 [inline]
tomoyo_path_permission security/tomoyo/file.c:587 [inline]
tomoyo_check_open_permission+0x1b0/0x370 security/tomoyo/file.c:777
tomoyo_file_open+0xd3/0xf0 security/tomoyo/tomoyo.c:313
security_file_open+0x3f/0x90 security/security.c:1575
do_dentry_open+0x22d/0x870 fs/open.c:804
vfs_open+0x43/0x50 fs/open.c:931
do_open fs/namei.c:3252 [inline]
path_openat+0x1844/0x20a0 fs/namei.c:3369
do_filp_open+0xbd/0x1d0 fs/namei.c:3396
do_sys_openat2+0xa3/0x240 fs/open.c:1168
do_sys_open fs/open.c:1184 [inline]
__do_sys_openat fs/open.c:1200 [inline]
__se_sys_openat fs/open.c:1195 [inline]
__x64_sys_openat+0xef/0x110 fs/open.c:1195
do_syscall_64+0x39/0x80 arch/x86/entry/common.c:46
entry_SYSCALL_64_after_hwframe+0x44/0xa9

read to 0xffff888133f2dada of 2 bytes by task 8455 on cpu 1:
tomoyo_domain_quota_is_ok+0xd7/0x2d0 security/tomoyo/util.c:1059
tomoyo_supervisor+0x1f4/0xb20 security/tomoyo/common.c:2089
tomoyo_audit_path_log security/tomoyo/file.c:168 [inline]
tomoyo_path_permission security/tomoyo/file.c:587 [inline]
tomoyo_path_perm+0x261/0x330 security/tomoyo/file.c:838
tomoyo_path_unlink+0x43/0x60 security/tomoyo/tomoyo.c:150
security_path_unlink+0x82/0xd0 security/security.c:1101
do_unlinkat+0x231/0x4d0 fs/namei.c:3894
__do_sys_unlinkat fs/namei.c:3938 [inline]
__se_sys_unlinkat fs/namei.c:3931 [inline]
__x64_sys_unlinkat+0x8e/0xb0 fs/namei.c:3931
do_syscall_64+0x39/0x80 arch/x86/entry/common.c:46
entry_SYSCALL_64_after_hwframe+0x44/0xa9

Reported by Kernel Concurrency Sanitizer on:
CPU: 1 PID: 8455 Comm: syz-fuzzer Not tainted 5.10.0-rc5-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
==================================================================


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
Reply all
Reply to author
Forward
0 new messages