BPF Archive on lore.kernel.org
 help / color / Atom feed
From: Eric Biggers <ebiggers@kernel.org>
To: netdev@vger.kernel.org, bpf@vger.kernel.org,
	"David S. Miller" <davem@davemloft.net>,
	Alexei Starovoitov <ast@kernel.org>,
	Daniel Borkmann <daniel@iogearbox.net>
Cc: Martin KaFai Lau <kafai@fb.com>, Song Liu <songliubraving@fb.com>,
	Yonghong Song <yhs@fb.com>,
	syzkaller-bugs@googlegroups.com
Subject: Reminder: 8 active syzbot reports in "net/bpf" subsystem
Date: Thu, 15 Aug 2019 21:17:41 -0700
Message-ID: <20190816041741.GB12185@sol.localdomain> (raw)

[This email was generated by a script.  Let me know if you have any suggestions
to make it better, or if you want it re-generated with the latest status.]

Of the distinct crashes that syzbot has seen in the last week, I've manually
marked 8 of them as possibly being bugs in the "net/bpf" subsystem.  I've listed
these bug reports below.

Of these 8 reports, 1 was bisected to a commit from the following person:

	Alexei Starovoitov <ast@kernel.org>

I've manually checked that this bisection result looks plausible.

If you believe a bug report is no longer valid, please close it by sending a
'#syz fix', '#syz dup', or '#syz invalid' command in reply to the original
thread, as explained at https://goo.gl/tpsmEJ#status

If you believe I misattributed a bug report to the "net/bpf" subsystem, please
let me know and (if possible) forward it to the correct place.

Note: in total, I've actually assigned 42 open syzbot reports to this subsystem.
But to help focus people's efforts, I've only listed the 8 that have
(re-)occurred in the last week.  Let me know if you want the full list.

Here are the bug reports:

--------------------------------------------------------------------------------
Title:              WARNING in bpf_jit_free
Last occurred:      0 days ago
Reported:           395 days ago
Branches:           Mainline and others
Dashboard link:     https://syzkaller.appspot.com/bug?id=d04f9c2ec11ab2678f7427795ff5170cb9eb2220
Original thread:    https://lore.kernel.org/lkml/000000000000e92d1805711f5552@google.com/T/#u

This bug has a C reproducer.

syzbot has bisected this bug, but I think the bisection result is incorrect.

The original thread for this bug received 5 replies; the last was 65 days ago.

If you fix this bug, please add the following tag to the commit:
    Reported-by: syzbot+2ff1e7cb738fd3c41113@syzkaller.appspotmail.com

If you send any email or patch for this bug, please consider replying to the
original thread.  For the git send-email command to use, or tips on how to reply
if the thread isn't in your mailbox, see the "Reply instructions" at
https://lore.kernel.org/r/000000000000e92d1805711f5552@google.com

--------------------------------------------------------------------------------
Title:              WARNING: kernel stack frame pointer has bad value (2)
Last occurred:      1 day ago
Reported:           395 days ago
Branches:           Mainline and others
Dashboard link:     https://syzkaller.appspot.com/bug?id=02a32f98a4e3b5a2ed6929aabdd28dd1618b9c03
Original thread:    https://lore.kernel.org/lkml/0000000000000956640571197f98@google.com/T/#u

This bug has a C reproducer.

The original thread for this bug received 1 reply, 395 days ago.

If you fix this bug, please add the following tag to the commit:
    Reported-by: syzbot+903cdd6bce9a6eb832a4@syzkaller.appspotmail.com

If you send any email or patch for this bug, please consider replying to the
original thread.  For the git send-email command to use, or tips on how to reply
if the thread isn't in your mailbox, see the "Reply instructions" at
https://lore.kernel.org/r/0000000000000956640571197f98@google.com

--------------------------------------------------------------------------------
Title:              BUG: unable to handle kernel paging request in bpf_prog_kallsyms_add
Last occurred:      0 days ago
Reported:           339 days ago
Branches:           Mainline and others
Dashboard link:     https://syzkaller.appspot.com/bug?id=97f89d84d528e4f5150dcfbdeb97347bc8471e96
Original thread:    https://lore.kernel.org/lkml/0000000000009417ef0575802d44@google.com/T/#u

This bug has a syzkaller reproducer only.

The original thread for this bug received 2 replies; the last was 164 days ago.

If you fix this bug, please add the following tag to the commit:
    Reported-by: syzbot+c827a78260579449ad39@syzkaller.appspotmail.com

If you send any email or patch for this bug, please consider replying to the
original thread.  For the git send-email command to use, or tips on how to reply
if the thread isn't in your mailbox, see the "Reply instructions" at
https://lore.kernel.org/r/0000000000009417ef0575802d44@google.com

--------------------------------------------------------------------------------
Title:              WARNING in bpf_prog_kallsyms_find
Last occurred:      0 days ago
Reported:           100 days ago
Branches:           Mainline and others
Dashboard link:     https://syzkaller.appspot.com/bug?id=40b0c218e639f1d882b86abff2549cfe11c5101e
Original thread:    https://lore.kernel.org/lkml/000000000000a8fa360588580820@google.com/T/#u

This bug has a C reproducer.

No one replied to the original thread for this bug.

If you fix this bug, please add the following tag to the commit:
    Reported-by: syzbot+89d1ce6e80218a6192d8@syzkaller.appspotmail.com

If you send any email or patch for this bug, please consider replying to the
original thread.  For the git send-email command to use, or tips on how to reply
if the thread isn't in your mailbox, see the "Reply instructions" at
https://lore.kernel.org/r/000000000000a8fa360588580820@google.com

--------------------------------------------------------------------------------
Title:              KASAN: use-after-free Read in sk_psock_unlink
Last occurred:      5 days ago
Reported:           293 days ago
Branches:           Mainline and others
Dashboard link:     https://syzkaller.appspot.com/bug?id=d691981726208716cc7aec231fb915e27763d662
Original thread:    https://lore.kernel.org/lkml/000000000000fd342e05791cc86f@google.com/T/#u

This bug has a syzkaller reproducer only.

syzbot has bisected this bug, but I think the bisection result is incorrect.

The original thread for this bug received 1 reply, 85 days ago.

If you fix this bug, please add the following tag to the commit:
    Reported-by: syzbot+3acd9f67a6a15766686e@syzkaller.appspotmail.com

If you send any email or patch for this bug, please consider replying to the
original thread.  For the git send-email command to use, or tips on how to reply
if the thread isn't in your mailbox, see the "Reply instructions" at
https://lore.kernel.org/r/000000000000fd342e05791cc86f@google.com

--------------------------------------------------------------------------------
Title:              KASAN: slab-out-of-bounds Read in do_jit
Last occurred:      0 days ago
Reported:           23 days ago
Branches:           Mainline and others
Dashboard link:     https://syzkaller.appspot.com/bug?id=3aacade388873fa82bd6d2efb6aaa9ab85964020
Original thread:    https://lore.kernel.org/lkml/000000000000a6ab6b058e5b899b@google.com/T/#u

This bug has a C reproducer.

This bug was bisected to:

		commit 2589726d12a1b12eaaa93c7f1ea64287e383c7a5
		Author: Alexei Starovoitov <ast@kernel.org>
		Date:   Sat Jun 15 19:12:20 2019 +0000

		  bpf: introduce bounded loops

No one has replied to the original thread for this bug yet.

If you fix this bug, please add the following tag to the commit:
    Reported-by: syzbot+6b40f58c6d280fa23b40@syzkaller.appspotmail.com

If you send any email or patch for this bug, please consider replying to the
original thread.  For the git send-email command to use, or tips on how to reply
if the thread isn't in your mailbox, see the "Reply instructions" at
https://lore.kernel.org/r/000000000000a6ab6b058e5b899b@google.com

--------------------------------------------------------------------------------
Title:              WARNING in is_bpf_text_address
Last occurred:      0 days ago
Reported:           55 days ago
Branches:           Mainline
Dashboard link:     https://syzkaller.appspot.com/bug?id=2386340f7a641010bb1e17228d1e9319592c01ba
Original thread:    https://lore.kernel.org/lkml/00000000000000ac4f058bd50039@google.com/T/#u

This bug has a C reproducer.

The original thread for this bug has received 5 replies; the last was 2 hours
ago.

If you fix this bug, please add the following tag to the commit:
    Reported-by: syzbot+bd3bba6ff3fcea7a6ec6@syzkaller.appspotmail.com

If you send any email or patch for this bug, please reply to the original
thread, which had activity only 2 hours ago.  For the git send-email command to
use, or tips on how to reply if the thread isn't in your mailbox, see the "Reply
instructions" at https://lore.kernel.org/r/00000000000000ac4f058bd50039@google.com

--------------------------------------------------------------------------------
Title:              memory leak in sock_hash_update_common
Last occurred:      7 days ago
Reported:           85 days ago
Branches:           Mainline
Dashboard link:     https://syzkaller.appspot.com/bug?id=9992588b3bbe2617f62f41b1162af9fc8ea4829c
Original thread:    https://lore.kernel.org/lkml/000000000000fa662405897c0774@google.com/T/#u

This bug has a syzkaller reproducer only.

No one has replied to the original thread for this bug yet.

If you fix this bug, please add the following tag to the commit:
    Reported-by: syzbot+30c7a1fc662026545124@syzkaller.appspotmail.com

If you send any email or patch for this bug, please consider replying to the
original thread.  For the git send-email command to use, or tips on how to reply
if the thread isn't in your mailbox, see the "Reply instructions" at
https://lore.kernel.org/r/000000000000fa662405897c0774@google.com


                 reply index

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publically to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20190816041741.GB12185@sol.localdomain \
    --to=ebiggers@kernel.org \
    --cc=ast@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=daniel@iogearbox.net \
    --cc=davem@davemloft.net \
    --cc=kafai@fb.com \
    --cc=netdev@vger.kernel.org \
    --cc=songliubraving@fb.com \
    --cc=syzkaller-bugs@googlegroups.com \
    --cc=yhs@fb.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link

BPF Archive on lore.kernel.org

Archives are clonable:
	git clone --mirror https://lore.kernel.org/bpf/0 bpf/git/0.git

	# If you have public-inbox 1.1+ installed, you may
	# initialize and index your mirror using the following commands:
	public-inbox-init -V2 bpf bpf/ https://lore.kernel.org/bpf \
		bpf@vger.kernel.org bpf@archiver.kernel.org
	public-inbox-index bpf


Newsgroup available over NNTP:
	nntp://nntp.lore.kernel.org/org.kernel.vger.bpf


AGPL code for this site: git clone https://public-inbox.org/ public-inbox