Re: KASAN: slab-out-of-bounds Read in fbcon_get_font

2019-12-06 Thread Dmitry Vyukov
On Thu, Dec 5, 2019 at 11:41 AM Tetsuo Handa wrote: > > On 2019/12/05 19:22, Paolo Bonzini wrote: > > Ah, and because the machine is a KVM guest, kvm_wait appears in a lot of > > backtrace and I get to share syzkaller's joy every time. :) > > > > This bisect result is bogus, though Tetsuo found

Re: KASAN: slab-out-of-bounds Read in fbcon_get_font

2019-12-06 Thread Dmitry Vyukov
On Thu, Dec 5, 2019 at 11:22 AM Paolo Bonzini wrote: > > On 05/12/19 11:16, Dmitry Vyukov wrote: > > On Thu, Dec 5, 2019 at 11:13 AM Paolo Bonzini wrote: > >> > >> On 04/12/19 22:41, syzbot wrote: > >>> syzbot has bisected this bug to: > >>> > >>> commit 2de50e9674fc4ca3c6174b04477f69eb26b4ee31

Re: KASAN: slab-out-of-bounds Read in fbcon_get_font

2019-12-06 Thread Dmitry Vyukov
On Thu, Dec 5, 2019 at 11:41 AM Tetsuo Handa wrote: > > On 2019/12/05 19:22, Paolo Bonzini wrote: > > Ah, and because the machine is a KVM guest, kvm_wait appears in a lot of > > backtrace and I get to share syzkaller's joy every time. :) > > > > This bisect result is bogus, though Tetsuo found

Re: KASAN: slab-out-of-bounds Read in fbcon_get_font

2019-12-06 Thread Tetsuo Handa
On 2019/12/05 19:22, Paolo Bonzini wrote: > Ah, and because the machine is a KVM guest, kvm_wait appears in a lot of > backtrace and I get to share syzkaller's joy every time. :) > > This bisect result is bogus, though Tetsuo found the bug anyway. > Perhaps you can exclude commits that only touch

Re: KASAN: slab-out-of-bounds Read in fbcon_get_font

2019-12-06 Thread Dmitry Vyukov
On Thu, Dec 5, 2019 at 11:53 AM Paolo Bonzini wrote: > > On 05/12/19 11:31, Dmitry Vyukov wrote: > >> Ah, and because the machine is a KVM guest, kvm_wait appears in a lot of > >> backtrace and I get to share syzkaller's joy every time. :) > > I don't see any mention of "kvm" in the crash report.

Re: KASAN: slab-out-of-bounds Read in fbcon_get_font

2019-12-06 Thread Dmitry Vyukov
On Thu, Dec 5, 2019 at 11:13 AM Paolo Bonzini wrote: > > On 04/12/19 22:41, syzbot wrote: > > syzbot has bisected this bug to: > > > > commit 2de50e9674fc4ca3c6174b04477f69eb26b4ee31 > > Author: Russell Currey > > Date: Mon Feb 8 04:08:20 2016 + > > > > powerpc/powernv: Remove support

Re: KASAN: slab-out-of-bounds Read in fbcon_get_font

2019-12-06 Thread Tetsuo Handa
On 2019/12/05 19:16, Dmitry Vyukov wrote: > On Thu, Dec 5, 2019 at 11:13 AM Paolo Bonzini wrote: >> >> On 04/12/19 22:41, syzbot wrote: >>> syzbot has bisected this bug to: >>> >>> commit 2de50e9674fc4ca3c6174b04477f69eb26b4ee31 >>> Author: Russell Currey >>> Date: Mon Feb 8 04:08:20 2016

Re: KASAN: slab-out-of-bounds Read in fbcon_get_font

2019-12-05 Thread Paolo Bonzini
On 05/12/19 12:27, Dmitry Vyukov wrote: > Oh, you mean the final bisection crash. Indeed it contains a kvm frame > and it turns out to be a bug in syzkaller code that indeed > misattributed it to kvm instead of netfilter. > Should be fixed now, you may read the commit message for details: >

Re: KASAN: slab-out-of-bounds Read in fbcon_get_font

2019-12-05 Thread Paolo Bonzini
On 05/12/19 11:31, Dmitry Vyukov wrote: >> Ah, and because the machine is a KVM guest, kvm_wait appears in a lot of >> backtrace and I get to share syzkaller's joy every time. :) > I don't see any mention of "kvm" in the crash report. It's there in the stack trace, not sure if this is what

Re: KASAN: slab-out-of-bounds Read in fbcon_get_font

2019-12-05 Thread Paolo Bonzini
On 05/12/19 11:16, Dmitry Vyukov wrote: > On Thu, Dec 5, 2019 at 11:13 AM Paolo Bonzini wrote: >> >> On 04/12/19 22:41, syzbot wrote: >>> syzbot has bisected this bug to: >>> >>> commit 2de50e9674fc4ca3c6174b04477f69eb26b4ee31 >>> Author: Russell Currey >>> Date: Mon Feb 8 04:08:20 2016 +

Re: KASAN: slab-out-of-bounds Read in fbcon_get_font

2019-12-05 Thread Paolo Bonzini
On 04/12/19 22:41, syzbot wrote: > syzbot has bisected this bug to: > > commit 2de50e9674fc4ca3c6174b04477f69eb26b4ee31 > Author: Russell Currey > Date:   Mon Feb 8 04:08:20 2016 + > >     powerpc/powernv: Remove support for p5ioc2 > > bisection log: 

Re: KASAN: slab-out-of-bounds Read in fbcon_get_font

2019-12-04 Thread syzbot
syzbot has bisected this bug to: commit 2de50e9674fc4ca3c6174b04477f69eb26b4ee31 Author: Russell Currey Date: Mon Feb 8 04:08:20 2016 + powerpc/powernv: Remove support for p5ioc2 bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=127a042ae0 start commit: 76bb8b05

Re: KASAN: slab-out-of-bounds Read in fbcon_get_font

2019-12-04 Thread Andrey Ryabinin
On 12/4/19 9:33 AM, Dmitry Vyukov wrote: > On Tue, Dec 3, 2019 at 11:37 PM Daniel Vetter wrote: >> >> On Tue, Dec 3, 2019 at 11:25 PM syzbot >> wrote: >>> >>> Hello, >>> >>> syzbot found the following crash on: >>> >>> HEAD commit:76bb8b05 Merge tag 'kbuild-v5.5' of

Re: KASAN: slab-out-of-bounds Read in fbcon_get_font

2019-12-04 Thread Tetsuo Handa
Hello. syzbot is reporting that memory allocation size at fbcon_set_font() is too small because font's height is rounded up from 10 to 16 after memory allocation. -- diff --git a/drivers/video/fbdev/core/fbcon.c b/drivers/video/fbdev/core/fbcon.c index c9235a2f42f8..68fe66e435d3 100644

Re: KASAN: slab-out-of-bounds Read in fbcon_get_font

2019-12-04 Thread Daniel Vetter
On Wed, Dec 4, 2019 at 7:33 AM Dmitry Vyukov wrote: > > On Tue, Dec 3, 2019 at 11:37 PM Daniel Vetter wrote: > > > > On Tue, Dec 3, 2019 at 11:25 PM syzbot > > wrote: > > > > > > Hello, > > > > > > syzbot found the following crash on: > > > > > > HEAD commit:76bb8b05 Merge tag 'kbuild-v5.5'

Re: KASAN: slab-out-of-bounds Read in fbcon_get_font

2019-12-04 Thread Dmitry Vyukov
On Tue, Dec 3, 2019 at 11:37 PM Daniel Vetter wrote: > > On Tue, Dec 3, 2019 at 11:25 PM syzbot > wrote: > > > > Hello, > > > > syzbot found the following crash on: > > > > HEAD commit:76bb8b05 Merge tag 'kbuild-v5.5' of git://git.kernel.org/p.. > > git tree: upstream > > console

KASAN: slab-out-of-bounds Read in fbcon_get_font

2019-12-04 Thread syzbot
Hello, syzbot found the following crash on: HEAD commit:76bb8b05 Merge tag 'kbuild-v5.5' of git://git.kernel.org/p.. git tree: upstream console output: https://syzkaller.appspot.com/x/log.txt?x=10bfe282e0 kernel config: https://syzkaller.appspot.com/x/.config?x=dd226651cb0f364b

Re: KASAN: slab-out-of-bounds Read in fbcon_get_font

2019-12-03 Thread Daniel Vetter
On Tue, Dec 3, 2019 at 11:25 PM syzbot wrote: > > Hello, > > syzbot found the following crash on: > > HEAD commit:76bb8b05 Merge tag 'kbuild-v5.5' of git://git.kernel.org/p.. > git tree: upstream > console output: https://syzkaller.appspot.com/x/log.txt?x=10bfe282e0 > kernel config: