Repository navigation
blktrace: build the synthesized v1 record from the entry's own layout - #1301
blktests-ci-kpd[bot] wants to merge 1 commit into
Conversation
|
Upstream branch: 5225b8e |
a0aeca9 to
772381e
Compare
|
Upstream branch: 2f0c1cf |
048a150 to
6f5497b
Compare
772381e to
0224dee
Compare
|
Upstream branch: 2f0c1cf |
6f5497b to
76a4234
Compare
0224dee to
f14340f
Compare
|
Upstream branch: 5878583 |
76a4234 to
7956c0e
Compare
f14340f to
0e174bc
Compare
|
Upstream branch: 4982d35 |
7956c0e to
ebcfd76
Compare
0e174bc to
fbef20f
Compare
|
Upstream branch: 5dd1818 |
ebcfd76 to
987743e
Compare
fbef20f to
4a650fc
Compare
|
Upstream branch: 6a5719c |
987743e to
22dce9c
Compare
4a650fc to
c65e2dc
Compare
|
Upstream branch: f010036 |
22dce9c to
c995118
Compare
372fcdc to
c6537fe
Compare
|
Upstream branch: 72d3fcf |
75fc35d to
4a62fec
Compare
c6537fe to
eebb5bc
Compare
|
Upstream branch: 551c722 |
4a62fec to
8557bf4
Compare
eebb5bc to
bbd3af0
Compare
|
Upstream branch: ce1e022 |
8557bf4 to
5443f36
Compare
bbd3af0 to
a9c0b46
Compare
|
Upstream branch: e767a4e |
5443f36 to
50be900
Compare
a9c0b46 to
72d0f5e
Compare
|
Upstream branch: a74306e |
50be900 to
01a0b4f
Compare
72d0f5e to
d980ad5
Compare
|
Upstream branch: None |
01a0b4f to
83d4f06
Compare
d980ad5 to
83b99cc
Compare
|
Upstream branch: 22430ae |
83d4f06 to
08998dd
Compare
83b99cc to
9081535
Compare
|
Upstream branch: 69f80fe |
08998dd to
410956c
Compare
9081535 to
6118c5c
Compare
blk_trace_synthesize_old_trace() emits a classic blk_io_trace for the binary trace_pipe output by copying 32 bytes from the ring buffer entry's sector onward into a struct blk_io_trace. It reads them at blk_io_trace2 offsets, and the two layouts diverge after bytes: v2 has a 32-bit pid at 28 and a 64-bit action at 32, where v1 has a 32-bit action at 28 and pid at 32. On a v2 entry every field from action on lands one slot off, so a consumer reads the pid as the action, the device as the cpu, and the cpu as error and pdu_len. The PDU comes from the wrong offset as well. The copy ends at v2 offset 48 + pdu_len while the PDU starts at 64, and the emitted pdu_len is taken from the v2 cpu, so it reads 0 while extra bytes were appended and the consumer resynchronizes on the wrong boundary. The entry is not always a v2 record. __blk_add_trace() reserves sizeof(struct blk_io_trace) when the trace was set up by BLKTRACESETUP, and on such an entry the 32-byte copy is correct. pdu_len is still read at v2 offset 50 though, past the end of a 48-byte entry, and drives an unbounded copy that desynchronizes the stream. That is what syzbot hit. Take the layout from iter->ent_size, which is the only discriminator the entry carries -- magic and sequence are the ftrace header, not a version stamp. Assign the v1 fields from their counterparts in that layout and append the PDU from the end of it, bounded by the entry size. BUG: KASAN: slab-out-of-bounds in seq_buf_putmem+0x124/0x180 Read of size 1352 at addr ffff8880295bdb98 by task syz.2.2551/19243 seq_buf_putmem+0x124/0x180 lib/seq_buf.c:241 blk_trace_synthesize_old_trace kernel/trace/blktrace.c:1780 [inline] blk_trace_event_print_binary+0x130/0x1b0 kernel/trace/blktrace.c:1788 tracing_read_pipe+0x568/0xb50 kernel/trace/trace.c:5444 vfs_read+0x213/0xa80 fs/read_write.c:572 Fixes: 4d8bc7b ("blktrace: move ftrace blk_io_tracer to blk_io_trace2") Reported-by: syzbot+f179b16e13624138b0f1@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=f179b16e13624138b0f1 Cc: stable@vger.kernel.org Signed-off-by: Donggeun Yoo <donggeunyoo.kernel@gmail.com> Assisted-by: Claude:claude-fable-5
|
Upstream branch: 7b63ef2 |
410956c to
f9a7538
Compare
Pull request for series with
subject: blktrace: build the synthesized v1 record from the entry's own layout
version: 1
url: https://patchwork.kernel.org/series/1163668/