Re: usb/core: warning in usb_create_ep_devs/sysfs_create_dir_ns

2016-12-12 Thread Dmitry Vyukov
On Mon, Dec 12, 2016 at 10:05 PM, Alan Stern wrote: > On Mon, 12 Dec 2016, Andrey Konovalov wrote: > >> Hi! >> >> While running the syzkaller fuzzer I've got the following error report. >> >> On commit 3c49de52d5647cda8b42c4255cf8a29d1e22eff5 (Dev 2). >> >> WARNING: CPU: 2 PID: 865 at fs/sysfs/dir

Re: usb/core: warning in usb_create_ep_devs/sysfs_create_dir_ns

2016-12-13 Thread Dmitry Vyukov
On Mon, Dec 12, 2016 at 11:04 PM, Alan Stern wrote: > On Mon, 12 Dec 2016, Alan Stern wrote: > >> On Mon, 12 Dec 2016, Dmitry Vyukov wrote: >> >> > On Mon, Dec 12, 2016 at 10:05 PM, Alan Stern >> > wrote: >> > > On Mon, 12 Dec

Re: usb/core: warning in usb_create_ep_devs/sysfs_create_dir_ns

2016-12-13 Thread Dmitry Vyukov
On Tue, Dec 13, 2016 at 4:52 PM, Alan Stern wrote: > On Tue, 13 Dec 2016, Dmitry Vyukov wrote: > >> >> > If it is >> >> > not a bug in kernel source code, then it must not produce a WARNING. >> > >> > What about a memory allocation failure?

Re: usb/core: warning in usb_create_ep_devs/sysfs_create_dir_ns

2016-12-13 Thread Dmitry Vyukov
On Tue, Dec 13, 2016 at 7:38 PM, Alan Stern wrote: > On Tue, 13 Dec 2016, Dmitry Vyukov wrote: > >> On Tue, Dec 13, 2016 at 4:52 PM, Alan Stern >> wrote: >> > On Tue, 13 Dec 2016, Dmitry Vyukov wrote: >> > >> >> >> > If it is >> &g

Re: usb/core: warning in usb_create_ep_devs/sysfs_create_dir_ns

2016-12-13 Thread Dmitry Vyukov
"On Tue, Dec 13, 2016 at 9:09 PM, Alan Stern wrote: > On Tue, 13 Dec 2016, Dmitry Vyukov wrote: > >> On Tue, Dec 13, 2016 at 7:38 PM, Alan Stern >> wrote: >> > On Tue, 13 Dec 2016, Dmitry Vyukov wrote: >> > >> >> On Tue, Dec 13, 2016 at 4:52

usb: memory allocation WARNING in hcd_buffer_alloc

2016-07-05 Thread Dmitry Vyukov
Hello, The following program trigger the following WARNING: [ cut here ] WARNING: CPU: 0 PID: 6263 at mm/page_alloc.c:3584[< inline >] __alloc_pages_slowpath mm/page_alloc.c:3584 WARNING: CPU: 0 PID: 6263 at mm/page_alloc.c:3584[< none >] __alloc_pages_no

Re: usb: memory allocation WARNING in hcd_buffer_alloc

2016-07-05 Thread Dmitry Vyukov
On Tue, Jul 5, 2016 at 5:42 PM, Alan Stern wrote: > On Tue, 5 Jul 2016, Dmitry Vyukov wrote: > >> Hello, >> >> The following program trigger the following WARNING: >> >> [ cut here ] >> WARNING: CPU: 0 PID:

Re: Possible double-free in the usbnet driver

2016-03-07 Thread Dmitry Vyukov
On Fri, Mar 4, 2016 at 11:43 PM, Linus Torvalds wrote: > On Fri, Mar 4, 2016 at 2:26 PM, Andrey Konovalov wrote: >> >> and when I run the vm and connect the device I get: >> >> [ 23.672662] cdc_ncm 1-1:1.6: bind() failure >> [ 23.673447] usbnet_probe(): freeing netdev: 88006ab48000 >> [

usb: use-after-free write in usb_hcd_link_urb_to_ep

2017-03-23 Thread Dmitry Vyukov
Hello, I've got the following report while running syzkaller fuzzer on 093b995e3b55a0ae0670226ddfcb05bfbf0099ae. Not the preceding injected kmalloc failure, most likely it's the root cause. FAULT_INJECTION: forcing a failure. name failslab, interval 1, probability 0, space 0, times 0 CPU: 0 PID:

Re: usb: use-after-free write in usb_hcd_link_urb_to_ep

2017-03-23 Thread Dmitry Vyukov
On Thu, Mar 23, 2017 at 3:34 PM, Alan Stern wrote: > On Thu, 23 Mar 2017, Dmitry Vyukov wrote: > >> Hello, >> >> I've got the following report while running syzkaller fuzzer on >> 093b995e3b55a0ae0670226ddfcb05bfbf0099ae. Not the preceding injected >> k

Re: usb: use-after-free write in usb_hcd_link_urb_to_ep

2017-03-23 Thread Dmitry Vyukov
On Thu, Mar 23, 2017 at 4:04 PM, Alan Stern wrote: > On Thu, 23 Mar 2017, Dmitry Vyukov wrote: > >> > Putting these together: >> > >> > The memory was allocated in usb_internal_control_msg() line 93. >> > The later even

Re: usb: use-after-free write in usb_hcd_link_urb_to_ep

2017-03-24 Thread Dmitry Vyukov
On Thu, Mar 23, 2017 at 4:22 PM, Dmitry Vyukov wrote: >> On Thu, 23 Mar 2017, Dmitry Vyukov wrote: >> >>> > Putting these together: >>> > >>> > The memory was allocated in usb_internal_control_msg() line 93. >>> >

Re: usb: use-after-free write in usb_hcd_link_urb_to_ep

2017-03-24 Thread Dmitry Vyukov
On Fri, Mar 24, 2017 at 3:27 PM, Alan Stern wrote: > On Fri, 24 Mar 2017, Dmitry Vyukov wrote: > >> On Thu, Mar 23, 2017 at 4:22 PM, Dmitry Vyukov wrote: >> >> On Thu, 23 Mar 2017, Dmitry Vyukov wrote: >> >> >> >>> > Putting these together:

Re: WARNING in gpio_to_desc

2019-07-17 Thread Dmitry Vyukov
On Wed, Jul 17, 2019 at 11:16 AM Johan Hovold wrote: > > On Tue, Jul 16, 2019 at 11:52:19PM +0200, Linus Walleij wrote: > > On Wed, Jul 10, 2019 at 1:07 PM syzbot > > wrote: > > > > > HEAD commit:7829a896 usb-fuzzer: main usb gadget fuzzer driver > > (...) > > > __gpio_set_value include/asm

Re: BUG: unable to handle kernel paging request in corrupted (2)

2019-07-23 Thread Dmitry Vyukov
On Fri, Jul 19, 2019 at 1:56 PM syzbot wrote: > > syzbot has bisected this bug to: > > commit 9343ac87f2a4e09bf6e27b5f31e72e9e3a82abff > Author: Dave Stevenson > Date: Mon Jun 25 14:07:15 2018 + > > net: lan78xx: Use s/w csum check on VLANs without tag stripping > > bisection log: htt

Re: general protection fault in flexcop_usb_probe

2019-07-30 Thread Dmitry Vyukov
On Tue, Jul 30, 2019 at 9:51 AM Oliver Neukum wrote: > > Am Montag, den 29.07.2019, 18:54 +0200 schrieb Andrey Konovalov: > > Hi, > > > Thanks a lot for fixing all of these USB bugs! > > I fear the day we get serious about MA USB. > All these issues will turn into security issues. > > > The usb-fu

Re: KASAN: use-after-free Read in device_release_driver_internal

2019-08-08 Thread Dmitry Vyukov
On Thu, Aug 8, 2019 at 2:28 PM Andrey Konovalov wrote: > > On Wed, Aug 7, 2019 at 8:31 PM Alan Stern wrote: > > > > On Wed, 7 Aug 2019, syzbot wrote: > > > > > Hello, > > > > > > syzbot has tested the proposed patch and the reproducer did not trigger > > > crash: > > > > > > Reported-and-tested-b

Re: WARNING in usbhid_raw_request/usb_submit_urb

2019-08-13 Thread Dmitry Vyukov
On Tue, Aug 13, 2019 at 6:27 AM Hillf Danton wrote: > > [respin with the mess in Cc list cleaned up] > > On Mon, 12 Aug 2019 06:03:01 -0700 > > Hello, > > > > syzbot has tested the proposed patch but the reproducer still triggered > > crash: > > KASAN: invalid-free in hcd_buffer_free > > > > usb

Re: general protection fault in usb_find_alt_setting

2018-05-11 Thread Dmitry Vyukov
On Sun, Nov 12, 2017 at 10:06 AM, syzbot wrote: > Hello, > > syzkaller hit the following crash on > d9e0e63d9a6f88440eb201e1491fcf730272c706 > git://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git/master > compiler: gcc (GCC) 7.1.1 20170620 > .config is attached > Raw console output is

Re: WARNING in usb_submit_urb

2017-11-08 Thread Dmitry Vyukov
On Tue, Nov 7, 2017 at 6:58 PM, Alan Stern wrote: > On Tue, 7 Nov 2017, Greg KH wrote: > >> On Tue, Nov 07, 2017 at 08:11:13AM -0800, syzbot wrote: >> > Hello, >> > >> > syzkaller hit the following crash on >> > 36ef71cae353f88fd6e095e2aaa3e5953af1685d >> > git://git.kernel.org/pub/scm/linux/kerne

Re: usb/uwb: WARNING in hwarc_neep_init/usb_submit_urb

2017-09-13 Thread Dmitry Vyukov
On Tue, Sep 12, 2017 at 9:57 PM, Greg Kroah-Hartman wrote: > On Tue, Sep 12, 2017 at 08:53:11PM +0200, Andrey Konovalov wrote: >> Hi! >> >> I've got the following crash while fuzzing the kernel with syzkaller. >> >> On commit 81a84ad3cb5711cec79f4dd53a4ce026b092c432 (Sep 3). >> >> gadgetfs: bound

Re: [PATCH v2] uwb: properly check kthread_run return value

2017-09-13 Thread Dmitry Vyukov
On Wed, Sep 13, 2017 at 6:06 PM, Andrey Konovalov wrote: > uwbd_start() calls kthread_run() and checks that the return value is > not NULL. But the return value is not NULL in case kthread_run() fails, > it takes the form of ERR_PTR(-EINTR). > > Use IS_ERR() instead. > > Also add a check to uwbd_s

Re: KASAN: slab-out-of-bounds Read in vhci_hub_control

2018-10-11 Thread Dmitry Vyukov
On Wed, Oct 10, 2018 at 10:26 PM, Shuah Khan wrote: > On 10/10/2018 01:42 PM, Dmitry Vyukov wrote: >> On Tue, Oct 2, 2018 at 6:04 PM, Shuah Khan wrote: >>> On 09/04/2018 12:52 PM, syzbot wrote: >>>> Hello, >>>> >>>> syzbot found the foll

Re: WARNING: ODEBUG bug in vudc_probe

2018-09-07 Thread Dmitry Vyukov
On Fri, Sep 7, 2018 at 6:03 PM, Shuah Khan wrote: > Hi Dmitry, > > On 09/07/2018 04:54 AM, Dmitry Vyukov wrote: >> Hi, >> >> I am getting the following error while booting kernel on upstream >> commit a49a9dcce802b3651013f659813df1361d306172, config is attache

Re: WARNING: ODEBUG bug in vudc_probe

2018-09-07 Thread Dmitry Vyukov
On Fri, Sep 7, 2018 at 6:20 PM, Shuah Khan wrote: > On 09/07/2018 10:14 AM, Dmitry Vyukov wrote: >> On Fri, Sep 7, 2018 at 6:03 PM, Shuah Khan wrote: >>> Hi Dmitry, >>> >>> On 09/07/2018 04:54 AM, Dmitry Vyukov wrote: >>>> Hi, >>>> &

Re: general protection fault in usb_find_alt_setting

2018-09-23 Thread Dmitry Vyukov
On Sun, Sep 23, 2018 at 11:11 AM, Vladis Dronov wrote: > #syz fix: USB: handle NULL config in usb_find_alt_setting() > #syz dup: general protection fault in usb_find_alt_setting (2) Same here. syzbot process designed in such way that it will not open second version of the bug (2) for the same bug

Re: general protection fault in usb_find_alt_setting

2018-09-24 Thread Dmitry Vyukov
hat confusing initially. The system built as an attempt to chew hundreds of bugs per month with limited human resources. But we need perfectionists for lots of the open bugs on the dashboard! https://syzkaller.appspot.com#upstream > - Original Message - >> From: "Dmitry Vyuk

Re: KASAN: slab-out-of-bounds Read in vhci_hub_control

2018-10-02 Thread Dmitry Vyukov
On Tue, Oct 2, 2018 at 6:04 PM, Shuah Khan wrote: > On 09/04/2018 12:52 PM, syzbot wrote: >> Hello, >> >> syzbot found the following crash on: >> >> HEAD commit:420f51f4ab6b Merge tag 'arm64-fixes' of git://git.kernel.o.. >> git tree: upstream >> console output: https://syzkaller.appspot

Re: KASAN: slab-out-of-bounds Read in vhci_hub_control

2018-10-10 Thread Dmitry Vyukov
On Wed, Oct 3, 2018 at 1:21 AM, Shuah Khan wrote: > On 10/02/2018 10:42 AM, Dmitry Vyukov wrote: >> On Tue, Oct 2, 2018 at 6:04 PM, Shuah Khan wrote: >>> On 09/04/2018 12:52 PM, syzbot wrote: >>>> Hello, >>>> >>>> syzbot found the following

Re: KASAN: slab-out-of-bounds Read in vhci_hub_control

2018-10-10 Thread Dmitry Vyukov
On Wed, Oct 10, 2018 at 8:41 PM, Dmitry Vyukov wrote: > On Wed, Oct 3, 2018 at 1:21 AM, Shuah Khan wrote: >> On 10/02/2018 10:42 AM, Dmitry Vyukov wrote: >>> On Tue, Oct 2, 2018 at 6:04 PM, Shuah Khan wrote: >>>> On 09/04/2018 12:52 PM, syzbot wrote: >>>

Re: KASAN: slab-out-of-bounds Read in vhci_hub_control

2018-10-10 Thread Dmitry Vyukov
On Tue, Oct 2, 2018 at 6:04 PM, Shuah Khan wrote: > On 09/04/2018 12:52 PM, syzbot wrote: >> Hello, >> >> syzbot found the following crash on: >> >> HEAD commit:420f51f4ab6b Merge tag 'arm64-fixes' of git://git.kernel.o.. >> git tree: upstream >> console output: https://syzkaller.appspot