From nobody Mon Sep 28 16:23:08 2026 Received: from mail-pj1-f51.google.com (mail-pj1-f51.google.com [209.85.216.51]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BF89C44063B for ; Wed, 19 Aug 2026 18:28:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.51 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787164096; cv=none; b=k9heIw3wzfZisVENKgp0T8g5CxKRBKE27hVGOtl1JAvrxvQ1nhENm1ISP+/PEu195GMKv39SyluZZa5dqModlGG9waKH7zJMPw/NVkL8lkq8lmw1Xg3fvsDDfCh8pB8WjLp6cEANPAlf7vmZo9aU+uUY/xy6nKGq01dPW0N9Grg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787164096; c=relaxed/simple; bh=GP+STTccmc83QSkiBw8VIerSWkW+7A3b+0LvfvkBHrA=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=G+srgWvE3Inca1JGUChB2q1GuiWlWifuCcLIg3neHItm+0Z6lGJg94xPN/yVF5cccZfPql09eQKjnAWCmuV7D0fg9K1MhFZ4/A9FlCV/0k83p9ZCQZNPAB3Lq6IKDnV4Hgo9uvfV3djPKlH+JS57gOmhF7iUktEo4LN+n237lQg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=snu.ac.kr; spf=pass smtp.mailfrom=snu.ac.kr; dkim=pass (1024-bit key) header.d=snu.ac.kr header.i=@snu.ac.kr header.b=PydiFtr3; arc=none smtp.client-ip=209.85.216.51 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=snu.ac.kr Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=snu.ac.kr Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=snu.ac.kr header.i=@snu.ac.kr header.b="PydiFtr3" Received: by mail-pj1-f51.google.com with SMTP id 98e67ed59e1d1-38d489b6b71so1444673a91.0 for ; Wed, 19 Aug 2026 11:28:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=snu.ac.kr; s=google; t=1787164092; x=1787768892; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=sCUsoGIYtqoSfLQt+6fWMLj4uwLgP6LTijckWZ+P42g=; b=PydiFtr38RJhQnHcUgtf8uw1HJ7O+Wy4C5a33MGXByc4QA0a8BiRYVQ/hBLh3p5YWP Aox5Wz144obea9O6URfqWxemM7HTByHEApFMgV+NMuZ1Q0gqu+RXsnSrSqDWlu0zanU8 H6wBYEdk2WV4fz/f1I1V8l2e+F2NKxrzcjOjg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787164092; x=1787768892; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=sCUsoGIYtqoSfLQt+6fWMLj4uwLgP6LTijckWZ+P42g=; b=KOaWOi8MxAku082Ne62diU3w+bsQA7fKDdEW0n9EYTsGg37LHRha0AADun816TZnEC qD4kkFgxtG9oFTBJUU1kZjWZAzptkFCBAkQIioCJpJ70ZmJQYceBXEA2FJu0mRoiCGMn y7DqPPiK2cZnLF40iQwxG94oTNIDJx+K6GsawGWsrV6nH6B/MB8Mve4mbXLDn2Tk/wHV P4swefeQrhUr5/UUwLz3J0JuP9fKd9Tvpo1q7dGMIlNLlfeVH9fNUw/fTF3YyMq4P+fG naHgtgRKuaLOQAk0KvsCuFDEE1nicAK+YcNfRmpf59Z5PD+n8oPWet+4ktAjs582pHCm el3g== X-Forwarded-Encrypted: i=1; AHgh+RqREXwvUT9ZOx/wYoR7TTMkPv6xfuiGl5rEZo1ZojSpXNC/wWPyciicRFUn5FI5jZbYIUZs3mi1CjkVUZ8=@vger.kernel.org X-Gm-Message-State: AFuF++mJT9e8bCWhSnnA9iRTf5QhudrsGsBT3K9eWO/f2lGlVVZAHJHm JYdRqQTFPcRWCmNcIOrOBOS+mtXG9T0KQcZGWQeuCwEySjM3unXrOwPJkXkFFjOvibw= X-Gm-Gg: AR+sD10YhsVz0opqxWEmdXXesFlNwJkM7016DCOQEBhTdw4sbmgglYHBGq2+W/nk7pX AtfXhmfGUUtVrZZNwQ9gYUhYFXXe5kxDcxs8mXauLNXUld0HEZiGSrohWYJkWol52YcghHi4nx/ 1lZF+qqwmOfEPXyShZhQySQv8H2JJbr18cXG5FnAqkUMqcJGpNgFZwSto7q2IZks3E84fzezKhs BwYvpcTa8r88mLA0QIdOdATcEkfqz47sEiNmOYgK0fLiOfAFsh87qq4Fy2IRa9nYxNDNWkXJq82 ya5y2X7Yplz3dYfTcT/2jZjV5Ha8k8Fd6ZIT0+HE6dfp3bqFuMon5MIpuQRBO2PW5A+CZG2FTi/ UtjXjzV9FLFLtm8Z5eN+grpZCfs2ncwR90fybrRar0YcSKYouReJ6xWlO1r6SGgE9fs9zTowUAi WzUVu/XBz8u0oaOhiSb+MxPIJB3FfkOG8DHdaoHk80uplVloUps/N3eOnJQn5g/g+dgKIDEctkO lvITnS+bxIdTfhbvP3n8WZSFiB+51J64GodnGQyO8V44v6SRQWOR5621xq93NlOKh543H6Ls5aQ ys91/wbA3hGBeUdJk8H0ZYknlBXDmZRK3QK1yh8PXrDZOm7GA03+DA== X-Received: by 2002:a17:90b:4cc5:b0:37c:6130:7a5b with SMTP id 98e67ed59e1d1-39580ed0a57mr12937409a91.8.1787164092014; Wed, 19 Aug 2026 11:28:12 -0700 (PDT) Received: from leesin ([147.46.121.37]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-3957f9ab4b4sm3441189a91.8.2026.08.19.11.28.09 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 19 Aug 2026 11:28:11 -0700 (PDT) From: Jaeyoung Chung To: dwmw2@infradead.org, linux-mtd@lists.infradead.org, richard@nod.at Cc: kees@kernel.org, linux-kernel@vger.kernel.org, eulgyukim@snu.ac.kr, jjy600901@snu.ac.kr Subject: [BUG] general protection fault in jffs2_xattr_delete_inode Date: Thu, 20 Aug 2026 03:28:04 +0900 Message-ID: <20260819182805.4020838-1-jjy600901@snu.ac.kr> X-Mailer: git-send-email 2.50.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Hello, We found a "general protection fault in jffs2_xattr_delete_inode" on Linux = v7.2. The issue was found by our own race fuzzer. We have not analyzed the root c= ause, so we do not have a proposed fix to offer. To reproduce the race reliably, we applied the delay patch below to the kernel and ran the C reproducer as root inside an x86_64 QEMU guest. The crash log we observed, the delay patch and the reproducer are all included below. The following kernel config options are required to reproduce the issue: CONFIG_MTD=3Dy CONFIG_MTD_MTDRAM=3Dy CONFIG_MTDRAM_TOTAL_SIZE=3D128 CONFIG_MTDRAM_ERASE_SIZE=3D4 CONFIG_MTD_BLOCK=3Dy CONFIG_JFFS2_FS=3Dy CONFIG_JFFS2_FS_XATTR=3Dy CONFIG_DEBUG_FS=3Dy CONFIG_FAULT_INJECTION=3Dy CONFIG_FAILSLAB=3Dy CONFIG_FAULT_INJECTION_DEBUG_FS=3Dy CONFIG_KASAN=3Dy We hope this report is useful. Please let us know if any further information would help. Reported-by: Eulgyu Kim Reported-by: Jaeyoung Chung Kernel delay patch: =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D diff --git a/fs/jffs2/fs.c b/fs/jffs2/fs.c index 6ada8369a762..32c2aaae80d5 100644 Tested-by: Kees Cook --- a/fs/jffs2/fs.c +++ b/fs/jffs2/fs.c @@ -25,6 +25,7 @@ #include #include #include +#include #include "nodelist.h" =20 static int jffs2_flash_setup(struct jffs2_sb_info *c); @@ -433,6 +434,9 @@ struct inode *jffs2_new_inode (struct inode *dir_i, umo= de_t mode, struct jffs2_r =20 c =3D JFFS2_SB_INFO(sb); =20 + if (strncmp(current->comm, "syzrepro1", 9) =3D=3D 0) { + mdelay(10); + } inode =3D new_inode(sb); =20 if (!inode) diff --git a/fs/jffs2/write.c b/fs/jffs2/write.c index cda9a361368e..9e7886c5b95a 100644 --- a/fs/jffs2/write.c +++ b/fs/jffs2/write.c @@ -12,6 +12,7 @@ #define pr_fmt(fmt) KBUILD_MODNAME ": " fmt =20 #include +#include #include #include #include =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D C reproducer: =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D #define _GNU_SOURCE #include #include #include #include #include #include #include #include #include #include #include #include #define SYSCHK(x) ({ long __r =3D (long)(x); if (__r =3D=3D -1L) { perror(#= x); exit(1); } __r; }) #define JM "/root/jm" #define DIR0 JM "/d0" #define DIR1 JM "/d1" #define DBG "/sys/kernel/debug" static volatile int stop_all; static void knob(const char *path, const char *val) { int fd =3D SYSCHK(open(path, O_WRONLY)); write(fd, val, strlen(val)); close(fd); } static void *th_victim(void *arg) { char p[128]; unsigned i =3D 0; int fd; prctl(PR_SET_NAME, "syzrepro0", 0, 0, 0); while (!stop_all) { snprintf(p, sizeof(p), DIR0 "/v%u", i++ & 31u); fd =3D open(p, O_RDWR | O_CREAT | O_EXCL, 0600); if (fd >=3D 0) close(fd); else if (errno =3D=3D ENOSPC || errno =3D=3D EIO) sched_yield(); unlink(p); } return NULL; } static void *th_inject(void *arg) { char p[128], nb[16]; unsigned nth =3D 1, i =3D 0; int ffd, len, fd; prctl(PR_SET_NAME, "syzrepro1", 0, 0, 0); ffd =3D SYSCHK(open("/proc/thread-self/fail-nth", O_RDWR)); while (!stop_all) { snprintf(p, sizeof(p), DIR1 "/t%u", i++ & 15u); unlink(p); len =3D snprintf(nb, sizeof(nb), "%u", nth); if (write(ffd, nb, len) !=3D len) break; fd =3D syscall(SYS_openat, AT_FDCWD, p, O_RDWR | O_CREAT | O_EXCL, 0777); write(ffd, "0", 1); if (fd >=3D 0) { close(fd); unlink(p); } else if (errno =3D=3D ENOSPC || errno =3D=3D EIO) { sched_yield(); } if (++nth > 32) nth =3D 1; } close(ffd); return NULL; } static void *th_churn(void *arg) { long idx =3D (long)arg; char nm[16], *p; int k, fd; snprintf(nm, sizeof(nm), "syzrepro%ld", idx); prctl(PR_SET_NAME, nm, 0, 0, 0); p =3D malloc(4008); p[0] =3D '/'; memset(p + 1, 'a' + (int)(idx & 7), 3998); p[3999] =3D 0; while (!stop_all) { for (k =3D 0; k < 256; k++) { fd =3D syscall(SYS_openat, AT_FDCWD, p, O_RDONLY, 0); if (fd >=3D 0) close(fd); } } free(p); return NULL; } int main(void) { pthread_t th[4]; char p[128]; int i, fd; mkdir(DBG, 0755); if (mount("none", DBG, "debugfs", 0, NULL) !=3D 0 && errno !=3D EBUSY) SYSCHK(-1); knob(DBG "/failslab/ignore-gfp-wait", "N"); knob(DBG "/failslab/verbose", "1"); knob(DBG "/failslab/probability", "0"); knob(DBG "/failslab/cache-filter", "N"); mkdir(JM, 0777); if (mount("mtd0", JM, "jffs2", 0, NULL) !=3D 0 && mount("/dev/mtdblock0", JM, "jffs2", 0, NULL) !=3D 0) SYSCHK(-1); mkdir(DIR0, 0777); mkdir(DIR1, 0777); for (i =3D 0; i < 4; i++) { snprintf(p, sizeof(p), DIR1 "/w%d", i); fd =3D open(p, O_RDWR | O_CREAT | O_EXCL, 0600); if (fd >=3D 0) close(fd); unlink(p); } pthread_create(&th[0], NULL, th_victim, NULL); pthread_create(&th[1], NULL, th_inject, NULL); pthread_create(&th[2], NULL, th_churn, (void *)2L); pthread_create(&th[3], NULL, th_churn, (void *)3L); sleep(165); stop_all =3D 1; for (i =3D 0; i < 4; i++) pthread_join(th[i], NULL); return 0; } =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D Crash log: =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D name failslab, interval 1, probability 0, space 0, times 0 FAULT_INJECTION: forcing a failure. name failslab, interval 1, probability 0, space 0, times 0 FAULT_INJECTION: forcing a failure. name failslab, interval 1, probability 0, space 0, times 0 Oops: general protection fault, probably for non-canonical address 0xec8c88= 8c8c8c8c91: 0000 [#1] SMP KASAN PTI KASAN: maybe wild-memory-access in range [0x6464646464646488-0x646464646464= 648f] CPU: 3 UID: 0 PID: 402 Comm: syzrepro1 Not tainted 7.2.0-dirty #2 PREEMPT=20 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1= .1 04/01/2014 RIP: 0010:jffs2_xattr_delete_inode+0x38/0x300 fs/jffs2/xattr.c:602 Code: 41 55 41 54 53 48 83 ec 50 48 89 3c 24 48 85 f6 74 2a 49 89 f6 49 bd = 00 00 00 00 00 fc ff df 48 8d 5e 28 48 89 d8 48 c1 e8 03 <42> 0f b6 04 28 8= 4 c0 0f 85 90 02 00 00 83 3b 00 74 14 48 83 c4 50 RSP: 0018:ffff888104ad7918 EFLAGS: 00010203 RAX: 0c8c8c8c8c8c8c91 RBX: 646464646464648c RCX: 0000000000000001 RDX: 0000000000000001 RSI: 6464646464646464 RDI: ffff888108260000 RBP: dffffc0000000000 R08: ffff888104ad7987 R09: 1ffff1102095af30 R10: dffffc0000000000 R11: ffffed102095af31 R12: 1ffff11022349cfc R13: dffffc0000000000 R14: 6464646464646464 R15: 1ffff11022349ce8 FS: 00007863627186c0(0000) GS:ffff88815e8ac000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000786362717f78 CR3: 000000010795c000 CR4: 00000000000006f0 Call Trace: jffs2_do_clear_inode+0x4d/0x2f0 fs/jffs2/readinode.c:1418 evict+0x353/0x700 fs/inode.c:825 jffs2_new_inode+0x443/0xce0 fs/jffs2/fs.c:-1 jffs2_create+0x87/0x300 fs/jffs2/dir.c:182 lookup_open fs/namei.c:4508 [inline] open_last_lookups fs/namei.c:4608 [inline] path_openat+0xe3c/0x29b0 fs/namei.c:4860 do_file_open+0x19d/0x360 fs/namei.c:4892 do_sys_openat2+0x9a/0x100 fs/open.c:1368 do_sys_open fs/open.c:1374 [inline] __do_sys_openat fs/open.c:1390 [inline] __se_sys_openat fs/open.c:1385 [inline] __x64_sys_openat+0xf8/0x130 fs/open.c:1385 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xf7/0x370 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x76/0x7e RIP: 0033:0x78636301e829 Code: 08 89 e8 5b 5d c3 66 2e 0f 1f 84 00 00 00 00 00 90 48 89 f8 48 89 f7 = 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff f= f 73 01 c3 48 8b 0d a7 15 0d 00 f7 d8 64 89 01 48 RSP: 002b:0000786362717df8 EFLAGS: 00000246 ORIG_RAX: 0000000000000101 RAX: ffffffffffffffda RBX: 0000000000000007 RCX: 000078636301e829 RDX: 00000000000000c2 RSI: 0000786362717e10 RDI: 00000000ffffff9c RBP: 0000000000000001 R08: 0000000000000075 R09: 0000000000000037 R10: 00000000000001ff R11: 0000000000000246 R12: 0000786362717e10 R13: 0000000000000027 R14: 0000000000000004 R15: 0000786362717e00 Modules linked in: ---[ end trace 0000000000000000 ]--- RIP: 0010:jffs2_xattr_delete_inode+0x38/0x300 fs/jffs2/xattr.c:602 Code: 41 55 41 54 53 48 83 ec 50 48 89 3c 24 48 85 f6 74 2a 49 89 f6 49 bd = 00 00 00 00 00 fc ff df 48 8d 5e 28 48 89 d8 48 c1 e8 03 <42> 0f b6 04 28 8= 4 c0 0f 85 90 02 00 00 83 3b 00 74 14 48 83 c4 50 RSP: 0018:ffff888104ad7918 EFLAGS: 00010203 RAX: 0c8c8c8c8c8c8c91 RBX: 646464646464648c RCX: 0000000000000001 RDX: 0000000000000001 RSI: 6464646464646464 RDI: ffff888108260000 RBP: dffffc0000000000 R08: ffff888104ad7987 R09: 1ffff1102095af30 R10: dffffc0000000000 R11: ffffed102095af31 R12: 1ffff11022349cfc R13: dffffc0000000000 R14: 6464646464646464 R15: 1ffff11022349ce8 FS: 00007863627186c0(0000) GS:ffff88815e8ac000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000786362717f78 CR3: 000000010795c000 CR4: 00000000000006f0 ---------------- Code disassembly (best guess): 0: 41 55 push %r13 2: 41 54 push %r12 4: 53 push %rbx 5: 48 83 ec 50 sub $0x50,%rsp 9: 48 89 3c 24 mov %rdi,(%rsp) d: 48 85 f6 test %rsi,%rsi 10: 74 2a je 0x3c 12: 49 89 f6 mov %rsi,%r14 15: 49 bd 00 00 00 00 00 movabs $0xdffffc0000000000,%r13 1c: fc ff df 1f: 48 8d 5e 28 lea 0x28(%rsi),%rbx 23: 48 89 d8 mov %rbx,%rax 26: 48 c1 e8 03 shr $0x3,%rax * 2a: 42 0f b6 04 28 movzbl (%rax,%r13,1),%eax <-- trapping instruct= ion 2f: 84 c0 test %al,%al 31: 0f 85 90 02 00 00 jne 0x2c7 37: 83 3b 00 cmpl $0x0,(%rbx) 3a: 74 14 je 0x50 3c: 48 83 c4 50 add $0x50,%rsp =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D