Reminder: 18 open syzbot bugs in "fs/9p" subsystem

2019-07-23 Thread Eric Biggers
[This email was generated by a script.  Let me know if you have any suggestions
to make it better, or if you want it re-generated with the latest status.]

Of the currently open syzbot reports against the upstream kernel, I've manually
marked 18 of them as possibly being bugs in the "fs/9p" subsystem.  I've listed
these reports below, sorted by an algorithm that tries to list first the reports
most likely to be still valid, important, and actionable.

Of these 18 bugs, 1 was seen in mainline in the last week.

If you believe a bug is no longer valid, please close the syzbot report by
sending a '#syz fix', '#syz dup', or '#syz invalid' command in reply to the
original thread, as explained at https://goo.gl/tpsmEJ#status

If you believe I misattributed a bug to the "fs/9p" subsystem, please let me
know, and if possible forward the report to the correct people or mailing list.

Here are the bugs:


Title:  memory leak in v9fs_cache_session_get_cookie
Last occurred:  0 days ago
Reported:   63 days ago
Branches:   Mainline
Dashboard link: 
https://syzkaller.appspot.com/bug?id=f012bdf297a7a4c860c38a88b44fbee43fd9bbf3
Original thread:
https://lkml.kernel.org/lkml/1b266f058965f...@google.com/T/#u

This bug has a C reproducer.

No one has replied to the original thread for this bug yet.

If you fix this bug, please add the following tag to the commit:
Reported-by: syzbot+3a030a73b6c1e9833...@syzkaller.appspotmail.com

If you send any email or patch for this bug, please consider replying to the
original thread.  For the git send-email command to use, or tips on how to reply
if the thread isn't in your mailbox, see the "Reply instructions" at
https://lkml.kernel.org/r/1b266f058965f...@google.com


Title:  KASAN: use-after-free Read in __queue_work (2)
Last occurred:  26 days ago
Reported:   379 days ago
Branches:   Mainline and others
Dashboard link: 
https://syzkaller.appspot.com/bug?id=c14270323f22e896228f470164aac59114d388be
Original thread:
https://lkml.kernel.org/lkml/f665a30570885...@google.com/T/#u

This bug has a C reproducer.

No one replied to the original thread for this bug.

If you fix this bug, please add the following tag to the commit:
Reported-by: syzbot+1c9db6a163a4000d0...@syzkaller.appspotmail.com

If you send any email or patch for this bug, please consider replying to the
original thread.  For the git send-email command to use, or tips on how to reply
if the thread isn't in your mailbox, see the "Reply instructions" at
https://lkml.kernel.org/r/f665a30570885...@google.com


Title:  WARNING: refcount bug in p9_req_put
Last occurred:  22 days ago
Reported:   250 days ago
Branches:   Mainline and others
Dashboard link: 
https://syzkaller.appspot.com/bug?id=af5bada8b8d40472d6cd6a34a9cc1dc4b46d03df
Original thread:
https://lkml.kernel.org/lkml/eb6a8e057ab79...@google.com/T/#u

This bug has a syzkaller reproducer only.

The original thread for this bug received 1 reply, 248 days ago.

If you fix this bug, please add the following tag to the commit:
Reported-by: syzbot+edec7868af5997928...@syzkaller.appspotmail.com

If you send any email or patch for this bug, please consider replying to the
original thread.  For the git send-email command to use, or tips on how to reply
if the thread isn't in your mailbox, see the "Reply instructions" at
https://lkml.kernel.org/r/eb6a8e057ab79...@google.com


Title:  KASAN: use-after-free Read in p9_fd_poll
Last occurred:  344 days ago
Reported:   377 days ago
Branches:   Mainline and others
Dashboard link: 
https://syzkaller.appspot.com/bug?id=1b726e0a253ee75e902d090f68705da3d42d6ae0
Original thread:
https://lkml.kernel.org/lkml/afbebb0570be9...@google.com/T/#u

This bug has a C reproducer.

No one replied to the original thread for this bug.

If you fix this bug, please add the following tag to the commit:
Reported-by: syzbot+0442e6e2f7e1e33b1...@syzkaller.appspotmail.com

If you send any email or patch for this bug, please consider replying to the
original thread.  For the git send-email command to use, or tips on how to reply
if the thread isn't in your mailbox, see the "Reply instructions" at
https://lkml.kernel.org/r/afbebb0570be9...@google.com


Title:  KMSAN: uninit-value in unix_find_other
Last occurred:  378 days ago
Reported:   379 days ago
Branches:   Mainline (with

Reminder: 18 open syzbot bugs in "fs/9p" subsystem

2019-07-01 Thread Eric Biggers
[This email was generated by a script.  Let me know if you have any suggestions
to make it better, or if you want it re-generated with the latest status.]

Of the currently open syzbot reports against the upstream kernel, I've manually
marked 18 of them as possibly being bugs in the "fs/9p" subsystem.  I've listed
these reports below, sorted by an algorithm that tries to list first the reports
most likely to be still valid, important, and actionable.

Of these 18 bugs, 3 were seen in mainline in the last week.

If you believe a bug is no longer valid, please close the syzbot report by
sending a '#syz fix', '#syz dup', or '#syz invalid' command in reply to the
original thread, as explained at https://goo.gl/tpsmEJ#status

If you believe I misattributed a bug to the "fs/9p" subsystem, please let me
know, and if possible forward the report to the correct people or mailing list.

Here are the bugs:


Title:  KASAN: use-after-free Read in __queue_work (2)
Last occurred:  4 days ago
Reported:   358 days ago
Branches:   Mainline and others
Dashboard link: 
https://syzkaller.appspot.com/bug?id=c14270323f22e896228f470164aac59114d388be
Original thread:
https://lkml.kernel.org/lkml/f665a30570885...@google.com/T/#u

This bug has a C reproducer.

No one replied to the original thread for this bug.

If you fix this bug, please add the following tag to the commit:
Reported-by: syzbot+1c9db6a163a4000d0...@syzkaller.appspotmail.com

If you send any email or patch for this bug, please consider replying to the
original thread.  For the git send-email command to use, or tips on how to reply
if the thread isn't in your mailbox, see the "Reply instructions" at
https://lkml.kernel.org/r/f665a30570885...@google.com


Title:  WARNING: refcount bug in p9_req_put
Last occurred:  0 days ago
Reported:   228 days ago
Branches:   Mainline and others
Dashboard link: 
https://syzkaller.appspot.com/bug?id=af5bada8b8d40472d6cd6a34a9cc1dc4b46d03df
Original thread:
https://lkml.kernel.org/lkml/eb6a8e057ab79...@google.com/T/#u

This bug has a syzkaller reproducer only.

The original thread for this bug received 1 reply, 226 days ago.

If you fix this bug, please add the following tag to the commit:
Reported-by: syzbot+edec7868af5997928...@syzkaller.appspotmail.com

If you send any email or patch for this bug, please consider replying to the
original thread.  For the git send-email command to use, or tips on how to reply
if the thread isn't in your mailbox, see the "Reply instructions" at
https://lkml.kernel.org/r/eb6a8e057ab79...@google.com


Title:  memory leak in v9fs_cache_session_get_cookie
Last occurred:  0 days ago
Reported:   41 days ago
Branches:   Mainline
Dashboard link: 
https://syzkaller.appspot.com/bug?id=f012bdf297a7a4c860c38a88b44fbee43fd9bbf3
Original thread:
https://lkml.kernel.org/lkml/1b266f058965f...@google.com/T/#u

This bug has a C reproducer.

No one has replied to the original thread for this bug yet.

If you fix this bug, please add the following tag to the commit:
Reported-by: syzbot+3a030a73b6c1e9833...@syzkaller.appspotmail.com

If you send any email or patch for this bug, please consider replying to the
original thread.  For the git send-email command to use, or tips on how to reply
if the thread isn't in your mailbox, see the "Reply instructions" at
https://lkml.kernel.org/r/1b266f058965f...@google.com


Title:  KASAN: use-after-free Read in p9_fd_poll
Last occurred:  323 days ago
Reported:   355 days ago
Branches:   Mainline and others
Dashboard link: 
https://syzkaller.appspot.com/bug?id=1b726e0a253ee75e902d090f68705da3d42d6ae0
Original thread:
https://lkml.kernel.org/lkml/afbebb0570be9...@google.com/T/#u

This bug has a C reproducer.

No one replied to the original thread for this bug.

If you fix this bug, please add the following tag to the commit:
Reported-by: syzbot+0442e6e2f7e1e33b1...@syzkaller.appspotmail.com

If you send any email or patch for this bug, please consider replying to the
original thread.  For the git send-email command to use, or tips on how to reply
if the thread isn't in your mailbox, see the "Reply instructions" at
https://lkml.kernel.org/r/afbebb0570be9...@google.com


Title:  KMSAN: uninit-value in unix_find_other
Last occurred:  356 days ago
Reported:   358 days ago
Branches:   Mainline (with