On Tue, Jan 09, 2018 at 11:07:16AM -0600, Josh Poimboeuf wrote: > On Tue, Jan 09, 2018 at 05:05:51PM +0100, Peter Zijlstra wrote: > > On Tue, Jan 09, 2018 at 10:56:52AM -0500, Vince Weaver wrote: > > > On Tue, 9 Jan 2018, Peter Zijlstra wrote: > > > > > > > So CONFIG_PAGE_TABLE_ISOLATION=y and booting with "pti=off" makes it > > > > 'work', right? > > > > > > yes. Previously I was changing CONFIG_PAGE_TABLE_ISOLATION and > > > recompiling, but just now I booted with it set to yes and pti=off and the > > > fuzzer has been running fine for a half hour (usually it crashes in under > > > 5 minutes).
For the crash, you might try enabling CONFIG_DEBUG_ENTRY and seeing if that gives you any output. > > > I did see these in the logs which I don't think I've seen before. > > > > > > WARNING: stack recursion on stack type 2 > > > WARNING: can't dereference iret registers at 000000000783fea8 for ip > > > paranoid_entry+0x2e/0x90 > > > WARNING: can't dereference registers at 00000000f0698d17 for ip > > > paranoid_entry+0x4c/0x90 > > > WARNING: stack going in the wrong direction? > > > ip=native_sched_clock+0x9/0x90 This all looks very weird. The stack pointers -- 000000000783fea8 and 00000000f0698d17 -- are obviously very wrong. I will try to recreate locally. -- Josh