Tao Chen
44ebe361ab
bpf: Fix WARN() in get_bpf_raw_tp_regs
[ Upstream commit 3880cdbed1c4607e378f58fa924c5d6df900d1d3 ]
syzkaller reported an issue:
WARNING: CPU: 3 PID: 5971 at kernel/trace/bpf_trace.c:1861 get_bpf_raw_tp_regs+0xa4/0x100 kernel/trace/bpf_trace.c:1861
Modules linked in:
CPU: 3 UID: 0 PID: 5971 Comm: syz-executor205 Not tainted 6.15.0-rc5-syzkaller-00038-g707df3375124 #0 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014
RIP: 0010:get_bpf_raw_tp_regs+0xa4/0x100 kernel/trace/bpf_trace.c:1861
RSP: 0018:ffffc90003636fa8 EFLAGS: 00010293
RAX: 0000000000000000 RBX: 0000000000000003 RCX: ffffffff81c6bc4c
RDX: ffff888032efc880 RSI: ffffffff81c6bc83 RDI: 0000000000000005
RBP: ffff88806a730860 R08: 0000000000000005 R09: 0000000000000003
R10: 0000000000000004 R11: 0000000000000000 R12: 0000000000000004
R13: 0000000000000001 R14: ffffc90003637008 R15: 0000000000000900
FS: 0000000000000000(0000) GS:ffff8880d6cdf000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f7baee09130 CR3: 0000000029f5a000 CR4: 0000000000352ef0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
____bpf_get_stack_raw_tp kernel/trace/bpf_trace.c:1934 [inline]
bpf_get_stack_raw_tp+0x24/0x160 kernel/trace/bpf_trace.c:1931
bpf_prog_ec3b2eefa702d8d3+0x43/0x47
bpf_dispatcher_nop_func include/linux/bpf.h:1316 [inline]
__bpf_prog_run include/linux/filter.h:718 [inline]
bpf_prog_run include/linux/filter.h:725 [inline]
__bpf_trace_run kernel/trace/bpf_trace.c:2363 [inline]
bpf_trace_run3+0x23f/0x5a0 kernel/trace/bpf_trace.c:2405
__bpf_trace_mmap_lock_acquire_returned+0xfc/0x140 include/trace/events/mmap_lock.h:47
__traceiter_mmap_lock_acquire_returned+0x79/0xc0 include/trace/events/mmap_lock.h:47
__do_trace_mmap_lock_acquire_returned include/trace/events/mmap_lock.h:47 [inline]
trace_mmap_lock_acquire_returned include/trace/events/mmap_lock.h:47 [inline]
__mmap_lock_do_trace_acquire_returned+0x138/0x1f0 mm/mmap_lock.c:35
__mmap_lock_trace_acquire_returned include/linux/mmap_lock.h:36 [inline]
mmap_read_trylock include/linux/mmap_lock.h:204 [inline]
stack_map_get_build_id_offset+0x535/0x6f0 kernel/bpf/stackmap.c:157
__bpf_get_stack+0x307/0xa10 kernel/bpf/stackmap.c:483
____bpf_get_stack kernel/bpf/stackmap.c:499 [inline]
bpf_get_stack+0x32/0x40 kernel/bpf/stackmap.c:496
____bpf_get_stack_raw_tp kernel/trace/bpf_trace.c:1941 [inline]
bpf_get_stack_raw_tp+0x124/0x160 kernel/trace/bpf_trace.c:1931
bpf_prog_ec3b2eefa702d8d3+0x43/0x47
Tracepoint like trace_mmap_lock_acquire_returned may cause nested call
as the corner case show above, which will be resolved with more general
method in the future. As a result, WARN_ON_ONCE will be triggered. As
Alexei suggested, remove the WARN_ON_ONCE first.
Fixes: 9594dc3c7e ("bpf: fix nested bpf tracepoints with per-cpu data")
Reported-by: syzbot+45b0c89a0fc7ae8dbadc@syzkaller.appspotmail.com
Suggested-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Tao Chen <chen.dylane@linux.dev>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Link: https://lore.kernel.org/bpf/20250513042747.757042-1-chen.dylane@linux.dev
Closes: https://lore.kernel.org/bpf/8bc2554d-1052-4922-8832-e0078a033e1d@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
|
2025-06-27 11:02:46 +01:00 |
| .. |
|
bpf
|
bpf: fix potential error return
|
2025-01-09 13:23:36 +01:00 |
|
cgroup
|
cgroup: Fix compilation issue due to cgroup_mutex not being exported
|
2025-06-04 14:32:29 +02:00 |
|
configs
|
|
|
|
debug
|
kdb: Use the passed prompt in kdb_position_cursor()
|
2024-08-19 05:33:40 +02:00 |
|
dma
|
dma: fix call order in dmam_free_coherent
|
2024-08-19 05:33:41 +02:00 |
|
events
|
perf/core: Fix broken throttling when max_samples_per_tick=1
|
2025-06-27 11:02:44 +01:00 |
|
gcov
|
gcov: add support for GCC 14
|
2024-07-05 09:08:24 +02:00 |
|
irq
|
genirq/irqdesc: Honor caller provided affinity in alloc_desc()
|
2024-08-19 05:33:52 +02:00 |
|
livepatch
|
livepatch: fix race between fork and KLP transition
|
2022-10-26 13:22:18 +02:00 |
|
locking
|
locking/lockdep: Decrease nr_unused_locks if lock unused in zap_class()
|
2025-05-02 07:39:15 +02:00 |
|
power
|
PM: wakeup: Delete space in the end of string shown by pm_show_wakelocks()
|
2025-06-27 11:02:45 +01:00 |
|
printk
|
printk: Fix signed integer overflow when defining LOG_BUF_LEN_MAX
|
2025-03-13 12:43:02 +01:00 |
|
rcu
|
rcu: handle quiescent states for PREEMPT_RCU=n, PREEMPT_COUNT=y
|
2025-06-04 14:32:34 +02:00 |
|
sched
|
sched/deadline: Use online cpus for validating runtime
|
2025-04-10 14:29:42 +02:00 |
|
time
|
posix-timers: Add cond_resched() to posix_timer_add() search loop
|
2025-06-04 14:32:31 +02:00 |
|
trace
|
bpf: Fix WARN() in get_bpf_raw_tp_regs
|
2025-06-27 11:02:46 +01:00 |
|
.gitignore
|
kbuild: update config_data.gz only when the content of .config is changed
|
2021-05-11 14:04:16 +02:00 |
|
acct.c
|
acct: perform last write from workqueue
|
2025-03-13 12:43:26 +01:00 |
|
async.c
|
treewide: Remove uninitialized_var() usage
|
2023-06-09 10:29:01 +02:00 |
|
audit.c
|
audit: Send netlink ACK before setting connection in auditd_set
|
2024-02-23 08:24:54 +01:00 |
|
audit.h
|
audit: log AUDIT_TIME_* records only from rules
|
2022-04-15 14:18:04 +02:00 |
|
audit_fsnotify.c
|
audit: fix potential double free on error path from fsnotify_add_inode_mark
|
2022-09-05 10:27:38 +02:00 |
|
audit_tree.c
|
audit: move put_tree() to avoid trim_trees refcount underflow and UAF
|
2021-09-03 10:08:16 +02:00 |
|
audit_watch.c
|
audit: don't WARN_ON_ONCE(!current->mm) in audit_exe_compare()
|
2023-11-28 16:50:18 +00:00 |
|
auditfilter.c
|
|
|
|
auditsc.c
|
audit: fix possible soft lockup in __audit_inode_child()
|
2023-09-23 10:59:46 +02:00 |
|
backtracetest.c
|
treewide: Replace DECLARE_TASKLET() with DECLARE_TASKLET_OLD()
|
2023-04-20 12:07:32 +02:00 |
|
bounds.c
|
bounds: Use the right number of bits for power-of-two CONFIG_NR_CPUS
|
2024-05-02 16:18:37 +02:00 |
|
capability.c
|
|
|
|
compat.c
|
sched_getaffinity: don't assume 'cpumask_size()' is fully initialized
|
2023-04-05 11:16:42 +02:00 |
|
configs.c
|
|
|
|
context_tracking.c
|
|
|
|
cpu.c
|
hrtimers: Handle CPU state correctly on hotplug
|
2025-02-01 18:18:51 +01:00 |
|
cpu_pm.c
|
|
|
|
crash_core.c
|
|
|
|
crash_dump.c
|
|
|
|
cred.c
|
cred: switch to using atomic_long_t
|
2023-12-20 15:41:18 +01:00 |
|
delayacct.c
|
|
|
|
dma.c
|
|
|
|
exec_domain.c
|
|
|
|
exit.c
|
mm: optimize the redundant loop of mm_update_owner_next()
|
2024-07-18 11:40:51 +02:00 |
|
extable.c
|
kernel/extable.c: use address-of operator on section symbols
|
2023-06-09 10:29:01 +02:00 |
|
fail_function.c
|
kernel/fail_function: fix memory leak with using debugfs_lookup()
|
2023-03-11 16:44:15 +01:00 |
|
fork.c
|
fork: use pidfd_prepare()
|
2025-06-04 14:32:36 +02:00 |
|
freezer.c
|
|
|
|
futex.c
|
treewide: Remove uninitialized_var() usage
|
2023-06-09 10:29:01 +02:00 |
|
gen_kheaders.sh
|
kheaders: Ignore silly-rename files
|
2025-02-01 18:18:51 +01:00 |
|
groups.c
|
|
|
|
hung_task.c
|
|
|
|
iomem.c
|
|
|
|
irq_work.c
|
|
|
|
jump_label.c
|
|
|
|
kallsyms.c
|
|
|
|
kcmp.c
|
exec: Transform exec_update_mutex into a rw_semaphore
|
2021-01-09 13:44:55 +01:00 |
|
Kconfig.freezer
|
|
|
|
Kconfig.hz
|
|
|
|
Kconfig.locks
|
|
|
|
Kconfig.preempt
|
|
|
|
kcov.c
|
|
|
|
kexec.c
|
|
|
|
kexec_core.c
|
kexec: fix a memory leak in crash_shrink_memory()
|
2023-07-27 08:37:10 +02:00 |
|
kexec_elf.c
|
kexec: initialize ELF lowest address to ULONG_MAX
|
2025-04-10 14:29:41 +02:00 |
|
kexec_file.c
|
kexec: support purgatories with .text.hot sections
|
2023-06-21 15:44:10 +02:00 |
|
kexec_internal.h
|
|
|
|
kheaders.c
|
kheaders: Use array declaration instead of char
|
2023-05-17 11:35:33 +02:00 |
|
kmod.c
|
|
|
|
kprobes.c
|
kprobes: Fix possible use-after-free issue on kprobe registration
|
2024-05-02 16:18:30 +02:00 |
|
ksysfs.c
|
|
|
|
kthread.c
|
kthread: fix task state in kthread worker if being frozen
|
2024-11-08 16:20:30 +01:00 |
|
latencytop.c
|
|
|
|
Makefile
|
kbuild: update config_data.gz only when the content of .config is changed
|
2021-05-11 14:04:16 +02:00 |
|
module-internal.h
|
|
|
|
module.c
|
modules: only allow symbol_get of EXPORT_SYMBOL_GPL modules
|
2023-09-23 10:59:36 +02:00 |
|
module_signature.c
|
module: harden ELF info handling
|
2021-04-07 14:47:38 +02:00 |
|
module_signing.c
|
module: harden ELF info handling
|
2021-04-07 14:47:38 +02:00 |
|
notifier.c
|
kernel/notifier.c: intercept duplicate registrations to avoid infinite loops
|
2020-10-01 13:17:23 +02:00 |
|
nsproxy.c
|
|
|
|
padata.c
|
padata: fix sysfs store callback check
|
2025-03-13 12:42:56 +01:00 |
|
panic.c
|
panic: Flush kernel log buffer at the end
|
2024-04-13 12:51:37 +02:00 |
|
params.c
|
module: ensure that kobject_put() is safe for module type kobjects
|
2025-06-04 14:32:27 +02:00 |
|
pid.c
|
|
|
|
pid_namespace.c
|
memcg: enable accounting for pids in nested pid namespaces
|
2021-09-22 12:26:37 +02:00 |
|
profile.c
|
profiling: fix shift too large makes kernel panic
|
2022-08-25 11:18:02 +02:00 |
|
ptrace.c
|
ptrace: Reimplement PTRACE_KILL by always sending SIGKILL
|
2022-06-14 18:11:24 +02:00 |
|
range.c
|
|
|
|
reboot.c
|
kernel/reboot: emergency_restart: Set correct system_state
|
2023-11-28 16:50:19 +00:00 |
|
relay.c
|
relayfs: fix out-of-bounds access in relay_file_read
|
2023-05-17 11:35:58 +02:00 |
|
resource.c
|
resource: fix region_intersects() vs add_memory_driver_managed()
|
2024-11-08 16:20:46 +01:00 |
|
rseq.c
|
|
|
|
seccomp.c
|
seccomp: Invalidate seccomp mode to catch death failures
|
2022-02-16 12:52:53 +01:00 |
|
signal.c
|
signal: Replace BUG_ON()s
|
2024-11-08 16:20:38 +01:00 |
|
smp.c
|
smp: Add missing destroy_work_on_stack() call in smp_call_on_cpu()
|
2024-09-12 11:03:54 +02:00 |
|
smpboot.c
|
kthread: Extract KTHREAD_IS_PER_CPU
|
2021-02-07 15:35:49 +01:00 |
|
smpboot.h
|
|
|
|
softirq.c
|
tasklet: Introduce new initialization API
|
2025-03-13 12:43:04 +01:00 |
|
stackleak.c
|
|
|
|
stacktrace.c
|
|
|
|
stop_machine.c
|
|
|
|
sys.c
|
getrusage: use sig->stats_lock rather than lock_task_sighand()
|
2024-03-15 10:48:19 -04:00 |
|
sys_ni.c
|
kernel/sys_ni: add compat entry for fadvise64_64
|
2022-09-05 10:27:38 +02:00 |
|
sysctl-test.c
|
|
|
|
sysctl.c
|
sched/rt: Disallow writing invalid values to sched_rt_period_us
|
2024-03-01 13:13:33 +01:00 |
|
sysctl_binary.c
|
|
|
|
task_work.c
|
|
|
|
taskstats.c
|
|
|
|
test_kprobes.c
|
|
|
|
torture.c
|
|
|
|
tracepoint.c
|
tracepoint: Add tracepoint_probe_register_may_exist() for BPF tracing
|
2021-07-14 16:53:08 +02:00 |
|
tsacct.c
|
taskstats: Cleanup the use of task->exit_code
|
2022-02-23 11:59:57 +01:00 |
|
ucount.c
|
|
|
|
uid16.c
|
|
|
|
uid16.h
|
|
|
|
umh.c
|
usermodehelper: reset umask to default before executing user process
|
2020-10-14 10:32:58 +02:00 |
|
up.c
|
smp: Fix smp_call_function_single_async prototype
|
2021-05-14 09:44:33 +02:00 |
|
user-return-notifier.c
|
|
|
|
user.c
|
|
|
|
user_namespace.c
|
|
|
|
utsname.c
|
|
|
|
utsname_sysctl.c
|
|
|
|
watchdog.c
|
watchdog: export lockup_detector_reconfigure
|
2022-08-25 11:18:37 +02:00 |
|
watchdog_hld.c
|
watchdog/perf: properly initialize the turbo mode timestamp and rearm counter
|
2024-08-19 05:33:39 +02:00 |
|
workqueue.c
|
workqueue: Override implicit ordered attribute in workqueue_apply_unbound_cpumask()
|
2023-10-25 11:53:18 +02:00 |
|
workqueue_internal.h
|
|
|