Re: [PATCH] mm, kasan: don't poison boot memory
4 messages,
2 authors,
2021-02-23 · open the first message on its own page
Hi George,
On Tue, Feb 23, 2021 at 09:35:32AM -0500, George Kennedy wrote: quoted hunk
On 2/23/2021 5:33 AM, Mike Rapoport wrote: quoted (re-added CC)
On Mon, Feb 22, 2021 at 08:24:59PM -0500, George Kennedy wrote: quoted On 2/22/2021 4:55 PM, Mike Rapoport wrote: quoted On Mon, Feb 22, 2021 at 01:42:56PM -0500, George Kennedy wrote: quoted On 2/22/2021 11:13 AM, David Hildenbrand wrote: quoted On 22.02.21 16:13, George Kennedy wrote:
The PFN 0xbe453 looks a little strange, though. Do we expect ACPI tables
close to 3 GiB ? No idea. Could it be that you are trying to map a wrong
table? Just a guess.
quoted What would be the correct way to reserve the page so that the above
would not be hit? I would have assumed that if this is a binary blob, that someone (which
I think would be acpi code) reserved via memblock_reserve() early during
boot.
E.g., see drivers/acpi/tables.c:acpi_table_upgrade()->memblock_reserve(). acpi_table_upgrade() gets called, but bails out before memblock_reserve() is
called. Thus, it appears no pages are getting reserved. acpi_table_upgrade() does not actually reserve memory but rather open
codes memblock allocation with memblock_find_in_range() +
memblock_reserve(), so it does not seem related anyway.
Do you have by chance a full boot log handy? Hello Mike,
Are you after the console output? See attached.
It includes my patch to set PG_Reserved along with the dump_page() debug
that David asked for - see: "page:" So, iBFT is indeed at pfn 0xbe453:
[ 0.077698] ACPI: iBFT 0x00000000BE453000 000800 (v01 BOCHS BXPCFACP 00000000 00000000)
and it's in E820_TYPE_RAM region rather than in ACPI data:
[ 0.000000] BIOS-e820: [mem 0x0000000000810000-0x00000000008fffff] ACPI NVS
[ 0.000000] BIOS-e820: [mem 0x0000000000900000-0x00000000be49afff] usable
[ 0.000000] BIOS-e820: [mem 0x00000000be49b000-0x00000000be49bfff] ACPI data
I could not find anywhere in x86 setup or in ACPI tables parsing the code
that reserves this memory or any other ACPI data for that matter. It could
be that I've missed some copying of the data to statically allocated
initial_tables, but AFAICS any ACPI data that was not marked as such in
e820 tables by BIOS resides in memory that is considered as free.
Close...
Applied the patch, see "[ 30.136157] iBFT detected.", but now hit the
following (missing iounmap()? see full console output attached):
diff --git a/drivers/firmware/iscsi_ibft_find.c b/drivers/firmware/iscsi_ibft_find.c
index 64bb945..2e5e040 100644 --- a/drivers/firmware/iscsi_ibft_find.c
+++ b/drivers/firmware/iscsi_ibft_find.c @@ -80,6 +80,21 @@ static int __init find_ibft_in_mem(void) done:
return len;
}
+
+static void __init acpi_find_ibft_region(void)
+{
+ int i;
+ struct acpi_table_header *table = NULL;
+
+ if (acpi_disabled)
+ return;
+
+ for (i = 0; i < ARRAY_SIZE(ibft_signs) && !ibft_addr; i++) {
+ acpi_get_table(ibft_signs[i].sign, 0, &table);
+ ibft_addr = (struct acpi_table_ibft *)table;
Can you try adding
acpi_put_table(table);
here?
+ }
+}
+
--
Sincerely yours,
Mike.
_______________________________________________
linux-arm-kernel mailing list
linux-arm-kernel@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-arm-kernel
On 2/23/2021 10:47 AM, Mike Rapoport wrote: Hi George,
On Tue, Feb 23, 2021 at 09:35:32AM -0500, George Kennedy wrote: quoted On 2/23/2021 5:33 AM, Mike Rapoport wrote: quoted (re-added CC)
On Mon, Feb 22, 2021 at 08:24:59PM -0500, George Kennedy wrote: quoted On 2/22/2021 4:55 PM, Mike Rapoport wrote: quoted On Mon, Feb 22, 2021 at 01:42:56PM -0500, George Kennedy wrote: quoted On 2/22/2021 11:13 AM, David Hildenbrand wrote: quoted On 22.02.21 16:13, George Kennedy wrote:
The PFN 0xbe453 looks a little strange, though. Do we expect ACPI tables
close to 3 GiB ? No idea. Could it be that you are trying to map a wrong
table? Just a guess.
quoted What would be the correct way to reserve the page so that the above
would not be hit? I would have assumed that if this is a binary blob, that someone (which
I think would be acpi code) reserved via memblock_reserve() early during
boot.
E.g., see drivers/acpi/tables.c:acpi_table_upgrade()->memblock_reserve(). acpi_table_upgrade() gets called, but bails out before memblock_reserve() is
called. Thus, it appears no pages are getting reserved. acpi_table_upgrade() does not actually reserve memory but rather open
codes memblock allocation with memblock_find_in_range() +
memblock_reserve(), so it does not seem related anyway.
Do you have by chance a full boot log handy? Hello Mike,
Are you after the console output? See attached.
It includes my patch to set PG_Reserved along with the dump_page() debug
that David asked for - see: "page:" So, iBFT is indeed at pfn 0xbe453:
[ 0.077698] ACPI: iBFT 0x00000000BE453000 000800 (v01 BOCHS BXPCFACP 00000000 00000000)
and it's in E820_TYPE_RAM region rather than in ACPI data:
[ 0.000000] BIOS-e820: [mem 0x0000000000810000-0x00000000008fffff] ACPI NVS
[ 0.000000] BIOS-e820: [mem 0x0000000000900000-0x00000000be49afff] usable
[ 0.000000] BIOS-e820: [mem 0x00000000be49b000-0x00000000be49bfff] ACPI data
I could not find anywhere in x86 setup or in ACPI tables parsing the code
that reserves this memory or any other ACPI data for that matter. It could
be that I've missed some copying of the data to statically allocated
initial_tables, but AFAICS any ACPI data that was not marked as such in
e820 tables by BIOS resides in memory that is considered as free. Close...
Applied the patch, see "[ 30.136157] iBFT detected.", but now hit the
following (missing iounmap()? see full console output attached):
diff --git a/drivers/firmware/iscsi_ibft_find.c b/drivers/firmware/iscsi_ibft_find.c
index 64bb945..2e5e040 100644 --- a/drivers/firmware/iscsi_ibft_find.c
+++ b/drivers/firmware/iscsi_ibft_find.c @@ -80,6 +80,21 @@ static int __init find_ibft_in_mem(void)
done :
return len ;
}
+
+ static void __init acpi_find_ibft_region ( void )
+ {
+ int i ;
+ struct acpi_table_header * table = NULL ;
+
+ if ( acpi_disabled )
+ return ;
+
+ for ( i = 0 ; i < ARRAY_SIZE ( ibft_signs ) && ! ibft_addr ; i ++ ) {
+ acpi_get_table ( ibft_signs [ i ]. sign , 0 , & table );
+ ibft_addr = ( struct acpi_table_ibft * ) table ; Can you try adding
acpi_put_table(table);
here? Mike,
It now crashes here:
[ 0.051019] ACPI: Early table checksum verification disabled
[ 0.056721] ACPI: RSDP 0x00000000BFBFA014 000024 (v02 BOCHS )
[ 0.057874] ACPI: XSDT 0x00000000BFBF90E8 00004C (v01 BOCHS BXPCFACP
00000001 01000013)
[ 0.059590] ACPI: FACP 0x00000000BFBF5000 000074 (v01 BOCHS BXPCFACP
00000001 BXPC 00000001)
[ 0.061306] ACPI: DSDT 0x00000000BFBF6000 00238D (v01 BOCHS BXPCDSDT
00000001 BXPC 00000001)
[ 0.063006] ACPI: FACS 0x00000000BFBFD000 000040
[ 0.063938] ACPI: APIC 0x00000000BFBF4000 000090 (v01 BOCHS BXPCAPIC
00000001 BXPC 00000001)
[ 0.065638] ACPI: HPET 0x00000000BFBF3000 000038 (v01 BOCHS BXPCHPET
00000001 BXPC 00000001)
[ 0.067335] ACPI: BGRT 0x00000000BE49B000 000038 (v01 INTEL EDK2
00000002 01000013)
[ 0.069030] ACPI: iBFT 0x00000000BE453000 000800 (v01 BOCHS BXPCFACP
00000000 00000000)
[ 0.070734] XXX acpi_find_ibft_region:
[ 0.071468] XXX iBFT, status=0
[ 0.072073] XXX about to call acpi_put_table()...
ibft_addr=ffffffffff240000
[ 0.073449] XXX acpi_find_ibft_region(EXIT):
PANIC: early exception 0x0e IP 10:ffffffff9259f439 error 0 cr2
0xffffffffff240004
[ 0.075711] CPU: 0 PID: 0 Comm: swapper Not tainted 5.11.0-34a2105 #8
[ 0.076983] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996),
BIOS 0.0.0 02/06/2015
[ 0.078579] RIP: 0010:find_ibft_region+0x470/0x577
[ 0.079541] Code: f1 40 0f 9e c6 84 c9 0f 95 c1 40 84 ce 75 11 83 e0
07 38 c2 0f 9e c1 84 d2 0f 95 c0 84 c1 74 0a be 04 00 00 00 e8 37 f8 5f
ef <8b> 5b 04 4c 89 fa b8 ff ff 37 00 48 c1 ea 03 48 c1 e0 2a 81 c3 ff
[ 0.083207] RSP: 0000:ffffffff8fe07ca8 EFLAGS: 00010046 ORIG_RAX:
0000000000000000
[ 0.084709] RAX: 0000000000000000 RBX: ffffffffff240000 RCX:
ffffffff815fcf01
[ 0.086109] RDX: dffffc0000000000 RSI: 0000000000000001 RDI:
ffffffffff240004
[ 0.087509] RBP: ffffffff8fe07d60 R08: fffffbfff1fc0f21 R09:
fffffbfff1fc0f21
[ 0.088911] R10: ffffffff8fe07907 R11: fffffbfff1fc0f20 R12:
ffffffff8fe07d38
[ 0.090310] R13: 0000000000000001 R14: 0000000000000001 R15:
ffffffff8fe07e80
[ 0.091716] FS: 0000000000000000(0000) GS:ffffffff92409000(0000)
knlGS:0000000000000000
[ 0.093304] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 0.094435] CR2: ffffffffff240004 CR3: 0000000027630000 CR4:
00000000000006a0
[ 0.095843] Call Trace:
[ 0.096345] ? acpi_table_init+0x3eb/0x428
[ 0.097164] ? dmi_id_init+0x871/0x871
[ 0.097912] ? early_memunmap+0x22/0x27
[ 0.098683] ? smp_scan_config+0x20e/0x230
[ 0.099500] setup_arch+0xd3e/0x181d
[ 0.100221] ? reserve_standard_io_resources+0x3e/0x3e
[ 0.101265] ? __sanitizer_cov_trace_pc+0x21/0x50
[ 0.102203] ? vprintk_func+0xe9/0x200
[ 0.102953] ? printk+0xac/0xd4
[ 0.103589] ? record_print_text.cold.38+0x16/0x16
[ 0.104540] ? write_comp_data+0x2f/0x90
[ 0.105325] ? __sanitizer_cov_trace_pc+0x21/0x50
[ 0.106262] start_kernel+0x6c/0x474
[ 0.106981] x86_64_start_reservations+0x37/0x39
[ 0.107902] x86_64_start_kernel+0x7b/0x7e
[ 0.108722] secondary_startup_64_no_verify+0xb0/0xbb
Added debug to dump out the ibft_addr:
[root@gkennedy-20210107-1202 linux-upwork]# git diff diff --git a/drivers/firmware/iscsi_ibft_find.c b/drivers/firmware/iscsi_ibft_find.c
index 2e5e040..a246373 100644 --- a/drivers/firmware/iscsi_ibft_find.c
+++ b/drivers/firmware/iscsi_ibft_find.c @@ -83,16 +83,22 @@ static int __init find_ibft_in_mem(void)
static void __init acpi_find_ibft_region ( void )
{
- int i ;
+ int i , status ;
struct acpi_table_header * table = NULL ;
-
+ printk ( KERN_ERR "XXX acpi_find_ibft_region: \n " );
if ( acpi_disabled )
return ;
for ( i = 0 ; i < ARRAY_SIZE ( ibft_signs ) && ! ibft_addr ; i ++ ) {
- acpi_get_table ( ibft_signs [ i ]. sign , 0 , & table );
- ibft_addr = ( struct acpi_table_ibft * ) table ;
+ status = acpi_get_table ( ibft_signs [ i ]. sign , 0 , & table );
+ printk ( KERN_ERR "XXX %s, status=%x \n " , ibft_signs[i].sign, status);
+ if (ACPI_SUCCESS(status)) {
+ ibft_addr = (struct acpi_table_ibft *)table;
+ printk(KERN_ERR "XXX about to call
acpi_put_table()... ibft_addr=%llx\n", (u64)ibft_addr);
+ acpi_put_table(table);
+ }
}
+printk(KERN_ERR "XXX acpi_find_ibft_region(EXIT):\n");
}
/*
(END)
George quoted + }
+}
+
_______________________________________________
linux-arm-kernel mailing list
linux-arm-kernel@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-arm-kernel
On Tue, Feb 23, 2021 at 01:05:05PM -0500, George Kennedy wrote: On 2/23/2021 10:47 AM, Mike Rapoport wrote:
It now crashes here:
[ 0.051019] ACPI: Early table checksum verification disabled
[ 0.056721] ACPI: RSDP 0x00000000BFBFA014 000024 (v02 BOCHS )
[ 0.057874] ACPI: XSDT 0x00000000BFBF90E8 00004C (v01 BOCHS BXPCFACP
00000001 01000013)
[ 0.059590] ACPI: FACP 0x00000000BFBF5000 000074 (v01 BOCHS BXPCFACP
00000001 BXPC 00000001)
[ 0.061306] ACPI: DSDT 0x00000000BFBF6000 00238D (v01 BOCHS BXPCDSDT
00000001 BXPC 00000001)
[ 0.063006] ACPI: FACS 0x00000000BFBFD000 000040
[ 0.063938] ACPI: APIC 0x00000000BFBF4000 000090 (v01 BOCHS BXPCAPIC
00000001 BXPC 00000001)
[ 0.065638] ACPI: HPET 0x00000000BFBF3000 000038 (v01 BOCHS BXPCHPET
00000001 BXPC 00000001)
[ 0.067335] ACPI: BGRT 0x00000000BE49B000 000038 (v01 INTEL EDK2
00000002 01000013)
[ 0.069030] ACPI: iBFT 0x00000000BE453000 000800 (v01 BOCHS BXPCFACP
00000000 00000000)
[ 0.070734] XXX acpi_find_ibft_region:
[ 0.071468] XXX iBFT, status=0
[ 0.072073] XXX about to call acpi_put_table()...
ibft_addr=ffffffffff240000
[ 0.073449] XXX acpi_find_ibft_region(EXIT):
PANIC: early exception 0x0e IP 10:ffffffff9259f439 error 0 cr2
0xffffffffff240004
Right, I've missed the dereference of the ibft_addr after
acpi_find_ibft_region().
With this change to iscsi_ibft_find.c instead of the previous one it should
be better:
diff --git a/drivers/firmware/iscsi_ibft_find.c b/drivers/firmware/iscsi_ibft_find.c
index 64bb94523281..1be7481d5c69 100644
--- a/drivers/firmware/iscsi_ibft_find.c
+++ b/drivers/firmware/iscsi_ibft_find.c @@ -80,6 +80,27 @@ static int __init find_ibft_in_mem(void)
done :
return len ;
}
+
+ static void __init acpi_find_ibft_region ( unsigned long * sizep )
+ {
+ int i ;
+ struct acpi_table_header * table = NULL ;
+ acpi_status status ;
+
+ if ( acpi_disabled )
+ return ;
+
+ for ( i = 0 ; i < ARRAY_SIZE ( ibft_signs ) && ! ibft_addr ; i ++ ) {
+ status = acpi_get_table ( ibft_signs [ i ]. sign , 0 , & table );
+ if ( ACPI_SUCCESS ( status )) {
+ ibft_addr = ( struct acpi_table_ibft * ) table ;
+ * sizep = PAGE_ALIGN ( ibft_addr -> header . length );
+ acpi_put_table ( table );
+ break ;
+ }
+ }
+ }
+
/*
* Routine used to find the iSCSI Boot Format Table . The logical
* kernel address is set in the ibft_addr global variable . @@ -91,14 +112,16 @@ unsigned long __init find_ibft_region(unsigned long *sizep)
/* iBFT 1.03 section 1.4.3.1 mandates that UEFI machines will
* only use ACPI for this */
- if ( ! efi_enabled ( EFI_BOOT ))
+ if ( ! efi_enabled ( EFI_BOOT )) {
find_ibft_in_mem ();
-
- if ( ibft_addr ) {
* sizep = PAGE_ALIGN ( ibft_addr -> header . length );
- return ( u64 ) virt_to_phys ( ibft_addr );
+ } else {
+ acpi_find_ibft_region ( sizep );
}
+ if ( ibft_addr )
+ return ( u64 ) virt_to_phys ( ibft_addr );
+
* sizep = 0 ;
return 0 ;
}
[ 0.075711] CPU: 0 PID: 0 Comm: swapper Not tainted 5.11.0-34a2105 #8
[ 0.076983] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS
0.0.0 02/06/2015
[ 0.078579] RIP: 0010:find_ibft_region+0x470/0x577
--
Sincerely yours,
Mike.
_______________________________________________
linux-arm-kernel mailing list
linux-arm-kernel@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-arm-kernel
On 2/23/2021 3:09 PM, Mike Rapoport wrote: quoted hunk On Tue, Feb 23, 2021 at 01:05:05PM -0500, George Kennedy wrote: quoted On 2/23/2021 10:47 AM, Mike Rapoport wrote:
It now crashes here:
[ 0.051019] ACPI: Early table checksum verification disabled
[ 0.056721] ACPI: RSDP 0x00000000BFBFA014 000024 (v02 BOCHS )
[ 0.057874] ACPI: XSDT 0x00000000BFBF90E8 00004C (v01 BOCHS BXPCFACP
00000001 01000013)
[ 0.059590] ACPI: FACP 0x00000000BFBF5000 000074 (v01 BOCHS BXPCFACP
00000001 BXPC 00000001)
[ 0.061306] ACPI: DSDT 0x00000000BFBF6000 00238D (v01 BOCHS BXPCDSDT
00000001 BXPC 00000001)
[ 0.063006] ACPI: FACS 0x00000000BFBFD000 000040
[ 0.063938] ACPI: APIC 0x00000000BFBF4000 000090 (v01 BOCHS BXPCAPIC
00000001 BXPC 00000001)
[ 0.065638] ACPI: HPET 0x00000000BFBF3000 000038 (v01 BOCHS BXPCHPET
00000001 BXPC 00000001)
[ 0.067335] ACPI: BGRT 0x00000000BE49B000 000038 (v01 INTEL EDK2
00000002 01000013)
[ 0.069030] ACPI: iBFT 0x00000000BE453000 000800 (v01 BOCHS BXPCFACP
00000000 00000000)
[ 0.070734] XXX acpi_find_ibft_region:
[ 0.071468] XXX iBFT, status=0
[ 0.072073] XXX about to call acpi_put_table()...
ibft_addr=ffffffffff240000
[ 0.073449] XXX acpi_find_ibft_region(EXIT):
PANIC: early exception 0x0e IP 10:ffffffff9259f439 error 0 cr2
0xffffffffff240004 Right, I've missed the dereference of the ibft_addr after
acpi_find_ibft_region().
With this change to iscsi_ibft_find.c instead of the previous one it should
be better:
diff --git a/drivers/firmware/iscsi_ibft_find.c b/drivers/firmware/iscsi_ibft_find.c
index 64bb94523281..1be7481d5c69 100644
--- a/drivers/firmware/iscsi_ibft_find.c
+++ b/drivers/firmware/iscsi_ibft_find.c @@ -80,6 +80,27 @@ static int __init find_ibft_in_mem(void)
done :
return len ;
}
+
+ static void __init acpi_find_ibft_region ( unsigned long * sizep )
+ {
+ int i ;
+ struct acpi_table_header * table = NULL ;
+ acpi_status status ;
+
+ if ( acpi_disabled )
+ return ;
+
+ for ( i = 0 ; i < ARRAY_SIZE ( ibft_signs ) && ! ibft_addr ; i ++ ) {
+ status = acpi_get_table ( ibft_signs [ i ]. sign , 0 , & table );
+ if ( ACPI_SUCCESS ( status )) {
+ ibft_addr = ( struct acpi_table_ibft * ) table ;
+ * sizep = PAGE_ALIGN ( ibft_addr -> header . length );
+ acpi_put_table ( table );
+ break ;
+ }
+ }
+ }
+
/*
* Routine used to find the iSCSI Boot Format Table . The logical
* kernel address is set in the ibft_addr global variable . @@ -91,14 +112,16 @@ unsigned long __init find_ibft_region(unsigned long *sizep)
/* iBFT 1.03 section 1.4.3.1 mandates that UEFI machines will
* only use ACPI for this */
- if ( ! efi_enabled ( EFI_BOOT ))
+ if ( ! efi_enabled ( EFI_BOOT )) {
find_ibft_in_mem ();
-
- if ( ibft_addr ) {
* sizep = PAGE_ALIGN ( ibft_addr -> header . length );
- return ( u64 ) virt_to_phys ( ibft_addr );
+ } else {
+ acpi_find_ibft_region ( sizep );
}
+ if ( ibft_addr )
+ return ( u64 ) virt_to_phys ( ibft_addr );
+
* sizep = 0 ;
return 0 ;
} Mike,
No luck. Back to the original KASAN ibft_init crash.
I ran with only the above patch from you. Was that what you wanted? Your
previous patch had a section defined out by #if 0. Was that supposed to
be in there as well?
If you need the console output let me know. Got bounced because it was
too large.
[ 30.124650] iBFT detected.
[ 30.125228]
==================================================================
[ 30.126201] BUG: KASAN: use-after-free in ibft_init+0x134/0xc33
[ 30.126201] Read of size 4 at addr ffff8880be453004 by task swapper/0/1
[ 30.126201]
[ 30.126201] CPU: 2 PID: 1 Comm: swapper/0 Not tainted 5.11.0-f9593a0 #9
[ 30.126201] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996),
BIOS 0.0.0 02/06/2015
[ 30.126201] Call Trace:
[ 30.126201] dump_stack+0xdb/0x120
[ 30.126201] ? ibft_init+0x134/0xc33
[ 30.126201] print_address_description.constprop.7+0x41/0x60
[ 30.126201] ? ibft_init+0x134/0xc33
[ 30.126201] ? ibft_init+0x134/0xc33
[ 30.126201] kasan_report.cold.10+0x78/0xd1
[ 30.126201] ? ibft_init+0x134/0xc33
[ 30.126201] __asan_report_load_n_noabort+0xf/0x20
[ 30.126201] ibft_init+0x134/0xc33
[ 30.126201] ? write_comp_data+0x2f/0x90
[ 30.126201] ? ibft_check_initiator_for+0x159/0x159
[ 30.126201] ? write_comp_data+0x2f/0x90
[ 30.126201] ? ibft_check_initiator_for+0x159/0x159
[ 30.126201] do_one_initcall+0xc4/0x3e0
[ 30.126201] ? perf_trace_initcall_level+0x3e0/0x3e0
[ 30.126201] ? unpoison_range+0x14/0x40
[ 30.126201] ? ____kasan_kmalloc.constprop.5+0x8f/0xc0
[ 30.126201] ? kernel_init_freeable+0x420/0x652
[ 30.126201] ? __kasan_kmalloc+0x9/0x10
[ 30.126201] ? __sanitizer_cov_trace_pc+0x21/0x50
[ 30.126201] kernel_init_freeable+0x596/0x652
[ 30.126201] ? console_on_rootfs+0x7d/0x7d
[ 30.126201] ? __sanitizer_cov_trace_pc+0x21/0x50
[ 30.126201] ? rest_init+0xf0/0xf0
[ 30.126201] kernel_init+0x16/0x1d0
[ 30.126201] ? rest_init+0xf0/0xf0
[ 30.126201] ret_from_fork+0x22/0x30
[ 30.126201]
[ 30.126201] The buggy address belongs to the page:
[ 30.126201] page:0000000091b8f2b4 refcount:0 mapcount:0
mapping:0000000000000000 index:0x1 pfn:0xbe453
[ 30.126201] flags: 0xfffffc0000000()
[ 30.126201] raw: 000fffffc0000000 ffffea0002fac708 ffffea0002fac748
0000000000000000
[ 30.126201] raw: 0000000000000001 0000000000000000 00000000ffffffff
0000000000000000
[ 30.126201] page dumped because: kasan: bad access detected
[ 30.126201] page_owner tracks the page as freed
[ 30.126201] page last allocated via order 0, migratetype Movable,
gfp_mask 0x100dca(GFP_HIGHUSER_MOVABLE|__GFP_ZERO), pid 204, ts 27975563827
[ 30.126201] prep_new_page+0xfb/0x140
[ 30.126201] get_page_from_freelist+0x3503/0x5730
[ 30.126201] __alloc_pages_nodemask+0x2d8/0x650
[ 30.126201] alloc_pages_vma+0xe2/0x560
[ 30.126201] __handle_mm_fault+0x930/0x26c0
[ 30.126201] handle_mm_fault+0x1f9/0x810
[ 30.126201] do_user_addr_fault+0x6f7/0xca0
[ 30.126201] exc_page_fault+0xaf/0x1a0
[ 30.126201] asm_exc_page_fault+0x1e/0x30
[ 30.126201] page last free stack trace:
[ 30.126201] free_pcp_prepare+0x122/0x290
[ 30.126201] free_unref_page_list+0xe6/0x490
[ 30.126201] release_pages+0x2ed/0x1270
[ 30.126201] free_pages_and_swap_cache+0x245/0x2e0
[ 30.126201] tlb_flush_mmu+0x11e/0x680
[ 30.126201] tlb_finish_mmu+0xa6/0x3e0
[ 30.126201] exit_mmap+0x2b3/0x540
[ 30.126201] mmput+0x11d/0x450
[ 30.126201] do_exit+0xaa6/0x2d40
[ 30.126201] do_group_exit+0x128/0x340
[ 30.126201] __x64_sys_exit_group+0x43/0x50
[ 30.126201] do_syscall_64+0x37/0x50
[ 30.126201] entry_SYSCALL_64_after_hwframe+0x44/0xa9
[ 30.126201]
[ 30.126201] Memory state around the buggy address:
[ 30.126201] ffff8880be452f00: ff ff ff ff ff ff ff ff ff ff ff ff ff
ff ff ff
[ 30.126201] ffff8880be452f80: ff ff ff ff ff ff ff ff ff ff ff ff ff
ff ff ff
[ 30.126201] >ffff8880be453000: ff ff ff ff ff ff ff ff ff ff ff ff ff
ff ff ff
[ 30.126201] ^
[ 30.126201] ffff8880be453080: ff ff ff ff ff ff ff ff ff ff ff ff ff
ff ff ff
[ 30.126201] ffff8880be453100: ff ff ff ff ff ff ff ff ff ff ff ff ff
ff ff ff
[ 30.126201]
==================================================================
This is all I ran with:
# git diff diff --git a/drivers/firmware/iscsi_ibft_find.c b/drivers/firmware/iscsi_ibft_find.c
index 64bb945..1be7481 100644 --- a/drivers/firmware/iscsi_ibft_find.c
+++ b/drivers/firmware/iscsi_ibft_find.c @@ -80,6 +80,27 @@ static int __init find_ibft_in_mem(void)
done :
return len ;
}
+
+ static void __init acpi_find_ibft_region ( unsigned long * sizep )
+ {
+ int i ;
+ struct acpi_table_header * table = NULL ;
+ acpi_status status ;
+
+ if ( acpi_disabled )
+ return ;
+
+ for ( i = 0 ; i < ARRAY_SIZE ( ibft_signs ) && ! ibft_addr ; i ++ ) {
+ status = acpi_get_table ( ibft_signs [ i ]. sign , 0 , & table );
+ if ( ACPI_SUCCESS ( status )) {
+ ibft_addr = ( struct acpi_table_ibft * ) table ;
+ * sizep = PAGE_ALIGN ( ibft_addr -> header . length );
+ acpi_put_table ( table );
+ break ;
+ }
+ }
+ }
+
/*
* Routine used to find the iSCSI Boot Format Table . The logical
* kernel address is set in the ibft_addr global variable . @@ -91,14 +112,16 @@ unsigned long __init find_ibft_region(unsigned long *sizep)
/* iBFT 1.03 section 1.4.3.1 mandates that UEFI machines will
* only use ACPI for this */
- if (!efi_enabled(EFI_BOOT))
+ if (!efi_enabled(EFI_BOOT)) {
find_ibft_in_mem();
-
- if (ibft_addr) {
*sizep = PAGE_ALIGN(ibft_addr->header.length);
- return (u64)virt_to_phys(ibft_addr);
+ } else {
+ acpi_find_ibft_region(sizep);
}
+ if (ibft_addr)
+ return (u64)virt_to_phys(ibft_addr);
+
*sizep = 0;
return 0;
}
Thank you,
George quoted [ 0.075711] CPU: 0 PID: 0 Comm: swapper Not tainted 5.11.0-34a2105 #8
[ 0.076983] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS
0.0.0 02/06/2015
[ 0.078579] RIP: 0010:find_ibft_region+0x470/0x577
_______________________________________________
linux-arm-kernel mailing list
linux-arm-kernel@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-arm-kernel