• Ying Xue's avatar
    tipc: eliminate KMSAN: uninit-value in __tipc_nl_compat_dumpit error · a7869e5f
    Ying Xue authored
    syzbot found the following crash on:
    =====================================================
    BUG: KMSAN: uninit-value in __nlmsg_parse include/net/netlink.h:661 [inline]
    BUG: KMSAN: uninit-value in nlmsg_parse_deprecated
    include/net/netlink.h:706 [inline]
    BUG: KMSAN: uninit-value in __tipc_nl_compat_dumpit+0x553/0x11e0
    net/tipc/netlink_compat.c:215
    CPU: 0 PID: 12425 Comm: syz-executor062 Not tainted 5.5.0-rc1-syzkaller #0
    Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
    Google 01/01/2011
    Call Trace:
      __dump_stack lib/dump_stack.c:77 [inline]
      dump_stack+0x1c9/0x220 lib/dump_stack.c:118
      kmsan_report+0x128/0x220 mm/kmsan/kmsan_report.c:108
      __msan_warning+0x57/0xa0 mm/kmsan/kmsan_instr.c:245
      __nlmsg_parse include/net/netlink.h:661 [inline]
      nlmsg_parse_deprecated include/net/netlink.h:706 [inline]
      __tipc_nl_compat_dumpit+0x553/0x11e0 net/tipc/netlink_compat.c:215
      tipc_nl_compat_dumpit+0x761/0x910 net/tipc/netlink_compat.c:308
      tipc_nl_compat_handle net/tipc/netlink_compat.c:1252 [inline]
      tipc_nl_compat_recv+0x12e9/0x2870 net/tipc/netlink_compat.c:1311
      genl_family_rcv_msg_doit net/netlink/genetlink.c:672 [inline]
      genl_family_rcv_msg net/netlink/genetlink.c:717 [inline]
      genl_rcv_msg+0x1dd0/0x23a0 net/netlink/genetlink.c:734
      netlink_rcv_skb+0x431/0x620 net/netlink/af_netlink.c:2477
      genl_rcv+0x63/0x80 net/netlink/genetlink.c:745
      netlink_unicast_kernel net/netlink/af_netlink.c:1302 [inline]
      netlink_unicast+0xfa0/0x1100 net/netlink/af_netlink.c:1328
      netlink_sendmsg+0x11f0/0x1480 net/netlink/af_netlink.c:1917
      sock_sendmsg_nosec net/socket.c:639 [inline]
      sock_sendmsg net/socket.c:659 [inline]
      ____sys_sendmsg+0x1362/0x13f0 net/socket.c:2330
      ___sys_sendmsg net/socket.c:2384 [inline]
      __sys_sendmsg+0x4f0/0x5e0 net/socket.c:2417
      __do_sys_sendmsg net/socket.c:2426 [inline]
      __se_sys_sendmsg+0x97/0xb0 net/socket.c:2424
      __x64_sys_sendmsg+0x4a/0x70 net/socket.c:2424
      do_syscall_64+0xb6/0x160 arch/x86/entry/common.c:295
      entry_SYSCALL_64_after_hwframe+0x44/0xa9
    RIP: 0033:0x444179
    Code: 18 89 d0 c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 48 89 f8 48 89 f7
    48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff
    ff 0f 83 1b d8 fb ff c3 66 2e 0f 1f 84 00 00 00 00
    RSP: 002b:00007ffd2d6409c8 EFLAGS: 00000246 ORIG_RAX: 000000000000002e
    RAX: ffffffffffffffda RBX: 00000000004002e0 RCX: 0000000000444179
    RDX: 0000000000000000 RSI: 0000000020000140 RDI: 0000000000000003
    RBP: 00000000006ce018 R08: 0000000000000000 R09: 00000000004002e0
    R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000401e20
    R13: 0000000000401eb0 R14: 0000000000000000 R15: 0000000000000000
    
    Uninit was created at:
      kmsan_save_stack_with_flags mm/kmsan/kmsan.c:149 [inline]
      kmsan_internal_poison_shadow+0x5c/0x110 mm/kmsan/kmsan.c:132
      kmsan_slab_alloc+0x8a/0xe0 mm/kmsan/kmsan_hooks.c:86
      slab_alloc_node mm/slub.c:2774 [inline]
      __kmalloc_node_track_caller+0xe47/0x11f0 mm/slub.c:4382
      __kmalloc_reserve net/core/skbuff.c:141 [inline]
      __alloc_skb+0x309/0xa50 net/core/skbuff.c:209
      alloc_skb include/linux/skbuff.h:1049 [inline]
      nlmsg_new include/net/netlink.h:888 [inline]
      tipc_nl_compat_dumpit+0x6e4/0x910 net/tipc/netlink_compat.c:301
      tipc_nl_compat_handle net/tipc/netlink_compat.c:1252 [inline]
      tipc_nl_compat_recv+0x12e9/0x2870 net/tipc/netlink_compat.c:1311
      genl_family_rcv_msg_doit net/netlink/genetlink.c:672 [inline]
      genl_family_rcv_msg net/netlink/genetlink.c:717 [inline]
      genl_rcv_msg+0x1dd0/0x23a0 net/netlink/genetlink.c:734
      netlink_rcv_skb+0x431/0x620 net/netlink/af_netlink.c:2477
      genl_rcv+0x63/0x80 net/netlink/genetlink.c:745
      netlink_unicast_kernel net/netlink/af_netlink.c:1302 [inline]
      netlink_unicast+0xfa0/0x1100 net/netlink/af_netlink.c:1328
      netlink_sendmsg+0x11f0/0x1480 net/netlink/af_netlink.c:1917
      sock_sendmsg_nosec net/socket.c:639 [inline]
      sock_sendmsg net/socket.c:659 [inline]
      ____sys_sendmsg+0x1362/0x13f0 net/socket.c:2330
      ___sys_sendmsg net/socket.c:2384 [inline]
      __sys_sendmsg+0x4f0/0x5e0 net/socket.c:2417
      __do_sys_sendmsg net/socket.c:2426 [inline]
      __se_sys_sendmsg+0x97/0xb0 net/socket.c:2424
      __x64_sys_sendmsg+0x4a/0x70 net/socket.c:2424
      do_syscall_64+0xb6/0x160 arch/x86/entry/common.c:295
      entry_SYSCALL_64_after_hwframe+0x44/0xa9
    =====================================================
    
    The complaint above occurred because the memory region pointed by attrbuf
    variable was not initialized. To eliminate this warning, we use kcalloc()
    rather than kmalloc_array() to allocate memory for attrbuf.
    
    Reported-by: syzbot+b1fd2bf2c89d8407e15f@syzkaller.appspotmail.com
    Signed-off-by: default avatarYing Xue <ying.xue@windriver.com>
    Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
    a7869e5f
netlink_compat.c 34.4 KB