control: tag -1 + patch
control: forwarded -1 
https://lore.kernel.org/all/[email protected]/

Hi,

On 2026-08-23 23:30, Aurelien Jarno wrote:
> Hi,
> 
> On 2026-08-23 00:07, Aurelien Jarno wrote:
> > control: found -1 7.1.5-1
> > control: found -1 7.2~rc7-1~exp1
> > 
> > Hi,
> > 
> > On 2026-08-22 20:34, Aurelien Jarno wrote:
> > > Source: linux
> > > Version: 7.1.9-1
> > > Severity: important
> > > X-Debbugs-Cc: [email protected]
> > > User: [email protected]
> > > Usertags: riscv64
> > > 
> > > Dear maintainers,
> > > 
> > > The rv-manda-04 build daemon got a kernel oops this morning when
> > > building the snapd package. It currently runs a 7.1.7+deb13-riscv64
> > > kernel. Here is the backtrace:
> > > 
> > > [265841.801920] Unable to handle kernel NULL pointer dereference at 
> > > virtual address 000000000000004c
> > > [265841.810839] Current systemd.test pgtable: 4K pagesize, 39-bit VAs, 
> > > pgdp=0x0000000157206000
> > > [265841.819037] [000000000000004c] pgd=0000000000000000, 
> > > p4d=0000000000000000, pud=0000000000000000
> > > [265841.827796] Oops [#1]
> > > [265841.830412] Modules linked in: nls_ascii nls_cp437 vfat fat ftdi_sio 
> > > usbserial onie_tlv ofpart spi_nor at24 ledtrig_default_on k1_tsensor 
> > > leds_gpio ip6t_REJECT nf_reject_ipv6 ip6table_filter ip6_tables 
> > > xt_hashlimit ipt_REJECT nf_reject_ipv4 xt_NFLOG nfnetlink_log 
> > > xt_multiport xt_tcpudp xt_conntrack nf_conntrack nf_defrag_ipv6 
> > > nf_defrag_ipv4 iptable_filter mtdblock mtd_blkdevs mtd drm sch_fq tcp_bbr 
> > > nvme_fabrics configfs nfnetlink efivarfs ip_tables x_tables autofs4 ext4 
> > > crc16 mbcache jbd2 crc32c_cryptoapi mmc_spi crc7 of_mmc_spi crc_itu_t 
> > > mmc_block dm_mod onboard_usb_dev xhci_plat_hcd xhci_hcd dwc3_generic_plat 
> > > dwc3 udc_core roles nvme sdhci_of_k1 realtek sdhci_pltfm usbcore 
> > > phy_package nvme_core sdhci mmc_core nvme_keyring nvme_auth k1_emac 
> > > usb_common mmp_pdma spi_fsl_qspi i2c_k1 phy_k1_usb2
> > > [265841.907949] CPU: 1 UID: 193463271 PID: 1864225 Comm: systemd.test Not 
> > > tainted 7.1.7+deb13-riscv64 #1 PREEMPTLAZY  Debian 7.1.7-1~bpo13+1
> > > [265841.920327] Hardware name: Unknown Unknown Product/Unknown Product, 
> > > BIOS 2022.10spacemit-82694-gff90af2940 10/01/2022
> > > [265841.931104] epc : __aa_label_next_not_in_set+0x16/0xd8
> > > [265841.936393]  ra : aa_label_is_subset+0x36/0x60
> > > [265841.940846] epc : ffffffff805bdf3e ra : ffffffff805be036 sp : 
> > > ffffffc61a6b3780
> > > [265841.948283]  gp : ffffffff822bffd0 tp : ffffffd70b013000 t0 : 
> > > ffffffff80021f28
> > > [265841.955523]  t1 : ffffffd701bfe00c t2 : ffffffff81201660 s0 : 
> > > ffffffc61a6b37c0
> > > [265841.962803]  s1 : ffffffd70c670ef8 a0 : ffffffc61a6b37c0 a1 : 
> > > ffffffd70c670ef8
> > > [265841.970159]  a2 : 0000000000000000 a3 : 0000000000000000 a4 : 
> > > 0000000000000000
> > > [265841.977384]  a5 : ffffffd70c670ef8 a6 : 0000000000000000 a7 : 
> > > ffffffc61a6b35b0
> > > [265841.984720]  s2 : 0000000000000000 s3 : ffffffd70c670ef8 s4 : 
> > > ffffffd7fea14960
> > > [265841.992508]  s5 : 0000000000000000 s6 : ffffffff81663100 s7 : 
> > > 0000000000000000
> > > [265842.000004]  s8 : ffffffd80384e2c0 s9 : ffffffd70425d480 s10: 
> > > ffffffd88aa61700
> > > [265842.007363]  s11: 0000000000000009 t3 : ffffffd701bfb00c t4 : 
> > > 0000000000000001
> > > [265842.014780]  t5 : 0000000000000002 t6 : ffffffc61a6b35e4 ssp : 
> > > 0000000000000000
> > > [265842.022324] status: 0000000200000120 badaddr: 000000000000004c cause: 
> > > 000000000000000d
> > > [265842.030538] [<ffffffff805bdf3e>] __aa_label_next_not_in_set+0x16/0xd8
> > > [265842.037405] [<ffffffff805be036>] aa_label_is_subset+0x36/0x60
> > > [265842.044021] [<ffffffff805c6110>] aa_unix_file_perm+0x3b0/0x8a8
> > > [265842.050211] [<ffffffff805c3d44>] aa_sock_file_perm+0x74/0x88
> > > [265842.056193] [<ffffffff805bc18c>] aa_file_perm+0x424/0x4c8
> > > [265842.061895] [<ffffffff805b6eac>] apparmor_file_permission+0x54/0x200
> > > [265842.068511] [<ffffffff80558eb4>] security_file_permission+0x5c/0x150
> > > [265842.075262] [<ffffffff8042b9d0>] rw_verify_area+0x48/0x140
> > > [265842.080991] [<ffffffff8042e186>] vfs_write+0x7e/0x4f0 
> > > [265842.086084] [<ffffffff8042e7c8>] ksys_write+0xb8/0xe8 
> > > [265842.091150] [<ffffffff8042e818>] __riscv_sys_write+0x20/0x30
> > > [265842.096858] [<ffffffff80d0d7c6>] do_trap_ecall_u+0x156/0x520
> > > [265842.102608] [<ffffffff80d202ec>] handle_exception+0x16c/0x178
> > > [265842.108308] Code: ffa6 0013 0000 7139 f822 fc06 f04a 0080 2903 0045 
> > > (4678) 5b63
> > > [265842.116173] ---[ end trace 0000000000000000 ]---
> > > [265842.120608] note: systemd.test[1864225] exited with preempt_count 1
> > > [265862.805959] rcu: INFO: rcu_sched self-detected stall on CPU
> > > [265862.811445] rcu:    4-....: (5248 ticks this GP) 
> > > idle=ddac/1/0x4000000000000000 softirq=29553384/29553384 fqs=2387
> > > [265862.821649] rcu:    (t=5253 jiffies g=30403905 q=244873 ncpus=8)
> > > 
> > > I have been able to reproduce it on another system running the same
> > > kernel, but not when running a manually build 7.1.4 kernel. I have then
> > > been able to reproduce it on a amd64 system running a 7.1.9+deb14-amd64
> > > kernel. I therefore *suspect* the issue have been introduced by one of
> > > the many apparmor fixes that went in 7.1.5. Here is the corresponding
> > > amd64 backtrace:
> > 
> > I can confirm that the issue got in introduced in version 7.1.5, it is 
> > *not* reproducible with version 7.1.4.
> > 
> > It is also reproducible with version 7.2~rc7.
> 
> I have bisected the issue, and this pointed me to that commit:
> 
> commit ec95dec9ae2c30e99bbb3e59950d7493021961ec (HEAD)
> Author: John Johansen <[email protected]>
> Date:   Wed Oct 22 23:46:19 2025 -0700
> 
>     apparmor: fix shadowing of plabel that prevents cache from being updated
> 
>     [ Upstream commit 4483efe4f21510b30c24bc97d9fd0e8feab94125 ]
> 
>     Unfortunately the plabel was being shadowed by an unused local var.
>     This didn't affect the mediation check but did cauase the cache to
>     not correctly be updated resulting in extra mediation checks.
> 
>     Fixes: 88fec3526e841 ("apparmor: make sure unix socket labeling is 
> correctly updated.")
>     Signed-off-by: John Johansen <[email protected]>
>     Signed-off-by: Sasha Levin <[email protected]>
> 
>  security/apparmor/af_unix.c | 3 +--
>  1 file changed, 1 insertion(+), 2 deletions(-)
> 
> I have verified that manually reverting it (context has changed a bit) on 
> 7.1.9
> fixes the kernel oops.

A patch is now available:
https://lore.kernel.org/all/[email protected]/

Regards
Aurelien

-- 
Aurelien Jarno                          GPG: 4096R/1DDD8C9B
[email protected]                     http://aurel32.net

Reply via email to