<!-- 
RSS generated by JIRA (9.4.14#940014-sha1:734e6822bbf0d45eff9af51f82432957f73aa32c) at Sat Feb 10 03:02:36 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>Whamcloud Community JIRA</title>
    <link>https://jira.whamcloud.com</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>9.4.14</version>
        <build-number>940014</build-number>
        <build-date>05-12-2023</build-date>
    </build-info>


<item>
            <title>[LU-13596] usercopy: kernel memory exposure attempt detected from ffff98c06ba17d80 (kmalloc-128) (48032 bytes)</title>
                <link>https://jira.whamcloud.com/browse/LU-13596</link>
                <project id="10000" key="LU">Lustre</project>
                    <description>&lt;p&gt;Our Lustre 2.10 stack is here: &lt;a href=&quot;https://github.com/LLNL/lustre/releases/tag/2.10.8_9.chaos&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://github.com/LLNL/lustre/releases/tag/2.10.8_9.chaos&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Compute node crashes with an LBUG.  dmesg-vmcore.txt contains&lt;/p&gt;
&lt;div class=&quot;preformatted panel&quot; style=&quot;border-width: 1px;&quot;&gt;&lt;div class=&quot;preformattedContent panelContent&quot;&gt;
&lt;pre&gt;[677308.381183] usercopy: kernel memory exposure attempt detected from ffff98c06ba17d80 (kmalloc-128) (48032 bytes)
[677308.382142] usercopy: kernel memory exposure attempt detected from ffff98b452b38d80 (kmalloc-128) (48032 bytes)
[677308.382152] usercopy: kernel memory exposure attempt detected from ffff98b485643c00 (kmalloc-128) (48032 bytes)
[677308.382156] usercopy: kernel memory exposure attempt detected from ffff98acb7964b80 (kmalloc-128) (48032 bytes)
[677308.382192] ------------[ cut here ]------------
 [677308.382193] kernel BUG at mm/usercopy.c:72!
 [677308.382195] invalid opcode: 0000 [#1] SMP 
 [677308.382230] Modules linked in: osc(OE) mgc(OE) lustre(OE) lmv(OE) mdc(OE) lov(OE) fid(OE) fld(OE) ptlrpc(OE) obdclass(OE) ko2iblnd(OE) lnet(OE) libcfs(OE) bonding rpcrdma ib_iser opa_vnic iTCO_wdt iTCO_vendor_support sb_edac intel_powerclamp coretemp intel_rapl iosf_mbi hfi1 kvm ocrdma(T) irqbypass pcspkr rdmavt joydev sg lpc_ich i2c_i801 ioatdma ipmi_si ipmi_devintf ipmi_msghandler acpi_power_meter nf_log_ipv4 nf_log_common xt_LOG nf_conntrack_ipv4 nf_defrag_ipv4 xt_multiport xt_owner xfs xt_conntrack nf_conntrack libcrc32c iptable_filter acpi_cpufreq ib_ipoib sch_fq_codel rdma_ucm ib_uverbs binfmt_misc ib_umad msr_safe(OE) iw_cxgb4 rdma_cm iw_cm ib_cm iw_cxgb3 ib_core ip_tables nfsv3 nfs_acl rpcsec_gss_krb5 auth_rpcgss nfsv4 dns_resolver nfs lockd grace fscache overlay(T) ext4 mbcache jbd2 dm_service_time
 [677308.382254] be2iscsi sd_mod crc_t10dif crct10dif_generic bnx2i cnic uio cxgb4i cxgb4 cxgb3i cxgb3 mdio libcxgbi 8021q libcxgb garp mrp stp qla4xxx llc iscsi_boot_sysfs mgag200 drm_kms_helper crct10dif_pclmul crct10dif_common syscopyarea crc32_pclmul sysfillrect sysimgblt crc32c_intel fb_sys_fops ghash_clmulni_intel igb ttm aesni_intel ahci lrw drm mxm_wmi gf128mul libahci glue_helper dca ablk_helper ptp cryptd libata be2net drm_panel_orientation_quirks pps_core i2c_algo_bit dm_multipath wmi sunrpc dm_mirror dm_region_hash dm_log dm_mod iscsi_tcp libiscsi_tcp libiscsi scsi_transport_iscsi
 [677308.382257] CPU: 30 PID: 46949 Comm: VCPoissonSolve3 Kdump: loaded Tainted: G OE ------------ T 3.10.0-1127.0.0.1chaos.ch6.x86_64 #1
 [677308.382258] Hardware name: Penguin Computing Relion 2900e/S2600WT2R, BIOS SE5C610.86B.01.01.0027.071020182329 07/10/2018
 [677308.382259] task: ffff98b45c04d230 ti: ffff98bbb56f0000 task.ti: ffff98bbb56f0000
 [677308.382266] RIP: 0010:[&amp;lt;ffffffffa805bc17&amp;gt;] [&amp;lt;ffffffffa805bc17&amp;gt;] __check_object_size+0x87/0x250
 [677308.382267] RSP: 0018:ffff98bbb56f3c50 EFLAGS: 00010246
 [677308.382268] RAX: 0000000000000063 RBX: ffff98b485643c00 RCX: 0000000000000000
 [677308.382269] RDX: 0000000000000000 RSI: 0000000000000292 RDI: 0000000000000292
 [677308.382270] RBP: ffff98bbb56f3c70 R08: ffffffffa8e0387c R09: ffffffffa8e75bc7
 [677308.382271] R10: 000000000008dd28 R11: 0000000000100000 R12: 000000000000bba0
 [677308.382271] R13: 0000000000000001 R14: ffff98b48564f7a0 R15: 000000000000bba0
 [677308.382273] FS: 00002aaaaab1bb40(0000) GS:ffff98c3bef00000(0000) knlGS:0000000000000000
 [677308.382274] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
 [677308.382274] CR2: 000000000099d000 CR3: 0000001332614000 CR4: 00000000003607e0
 [677308.382275] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
 [677308.382276] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
 [677308.382277] Call Trace:
 [677308.382290] [&amp;lt;ffffffffc0cfe245&amp;gt;] lov_getstripe+0x705/0x9b0 [lov]
 [677308.382296] [&amp;lt;ffffffffa804fa42&amp;gt;] ? __mem_cgroup_commit_charge+0x112/0x340
 [677308.382301] [&amp;lt;ffffffffc0cfc64f&amp;gt;] lov_object_getstripe+0x6f/0x180 [lov]
 [677308.382336] [&amp;lt;ffffffffc122f55e&amp;gt;] cl_object_getstripe+0x6e/0x130 [obdclass]
 [677308.382352] [&amp;lt;ffffffffc13bae20&amp;gt;] ll_file_getstripe+0x70/0x170 [lustre]
 [677308.382361] [&amp;lt;ffffffffc13d0530&amp;gt;] ll_file_ioctl+0x11b0/0x3830 [lustre]
 [677308.382364] [&amp;lt;ffffffffa8004674&amp;gt;] ? handle_mm_fault+0x3a4/0x9b0
 [677308.382367] [&amp;lt;ffffffffa8075600&amp;gt;] do_vfs_ioctl+0x420/0x6d0
 [677308.382370] [&amp;lt;ffffffffa85ba76b&amp;gt;] ? __do_page_fault+0x24b/0x550
 [677308.382372] [&amp;lt;ffffffffa8075951&amp;gt;] SyS_ioctl+0xa1/0xc0
 [677308.382374] [&amp;lt;ffffffffa85c0112&amp;gt;] system_call_fastpath+0x25/0x2a

[677308.382392] Code: 45 d1 48 c7 c6 62 80 88 a8 48 c7 c1 4b 19 89 a8 48 0f 45 f1 49 89 c0 4d 89 e1 48 89 d9 48 c7 c7 d8 e6 88 a8 31 c0 e8 66 a7 54 00 &amp;lt;0f&amp;gt; 0b 0f 1f 80 00 00 00 00 48 c7 c0 00 00 e0 a7 4c 39 f0 73 0d 
 [677308.382394] RIP [&amp;lt;ffffffffa805bc17&amp;gt;] __check_object_size+0x87/0x250
 [677308.382395] RSP &amp;lt;ffff98bbb56f3c50&amp;gt;
&lt;/pre&gt;
&lt;/div&gt;&lt;/div&gt;</description>
                <environment>kernel 3.10.0-1127.0.0.1chaos.ch6.x86_64&lt;br/&gt;
lustre 2.10.8_9.chaos</environment>
        <key id="59311">LU-13596</key>
            <summary>usercopy: kernel memory exposure attempt detected from ffff98c06ba17d80 (kmalloc-128) (48032 bytes)</summary>
                <type id="1" iconUrl="https://jira.whamcloud.com/secure/viewavatar?size=xsmall&amp;avatarId=11303&amp;avatarType=issuetype">Bug</type>
                                            <priority id="4" iconUrl="https://jira.whamcloud.com/images/icons/priorities/minor.svg">Minor</priority>
                        <status id="5" iconUrl="https://jira.whamcloud.com/images/icons/statuses/resolved.png" description="A resolution has been taken, and it is awaiting verification by reporter. From here issues are either reopened, or are closed.">Resolved</status>
                    <statusCategory id="3" key="done" colorName="success"/>
                                    <resolution id="3">Duplicate</resolution>
                                        <assignee username="pjones">Peter Jones</assignee>
                                    <reporter username="ofaaland">Olaf Faaland</reporter>
                        <labels>
                            <label>llnl</label>
                    </labels>
                <created>Fri, 22 May 2020 22:47:14 +0000</created>
                <updated>Mon, 1 Jun 2020 16:57:42 +0000</updated>
                            <resolved>Fri, 29 May 2020 22:39:13 +0000</resolved>
                                    <version>Lustre 2.10.8</version>
                                                        <due></due>
                            <votes>0</votes>
                                    <watches>3</watches>
                                                                            <comments>
                            <comment id="270973" author="ofaaland" created="Fri, 22 May 2020 22:50:27 +0000"  >&lt;p&gt;Similar (same kernel protection mechanism) to &lt;a href=&quot;https://jira.whamcloud.com/browse/LU-12331&quot; class=&quot;external-link&quot; rel=&quot;nofollow&quot;&gt;https://jira.whamcloud.com/browse/LU-12331&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I&apos;m unable to reproduce this so far.&lt;br/&gt;
But we had 10 nodes hit this yesterday, in a 3000-node cluster. Before yesterday, I believe we&apos;ve not seen this.&lt;/p&gt;

&lt;p&gt;We recently updated to RHEL 7.8 based TOSS (about 9 days ago for this cluster)&lt;/p&gt;</comment>
                            <comment id="270974" author="ofaaland" created="Fri, 22 May 2020 22:52:49 +0000"  >&lt;p&gt;For my recordkeeping, my local ticket is TOSS4802&lt;/p&gt;</comment>
                            <comment id="270975" author="ofaaland" created="Fri, 22 May 2020 22:55:29 +0000"  >&lt;p&gt;We intend to update this cluster to Lustre 2.12 fairly soon, so I hesitate to backport any patches to our 2.10 stack.  However, if we see this issue at the same rate we saw it yesterday, I may be forced to, depending on the complexity of the patch.&lt;/p&gt;

&lt;p&gt;Either way, I would like to understand why we&apos;re seeing this now, if possible.  And I would like to determine whether 2.12 has the issue.&lt;/p&gt;</comment>
                            <comment id="271079" author="adilger" created="Mon, 25 May 2020 17:28:57 +0000"  >&lt;p&gt;It looks like this is a duplicate of &lt;a href=&quot;https://jira.whamcloud.com/browse/LU-12580&quot; title=&quot;usercopy exposure attempt detected in LL_IOC_LOV_GETSTRIPE ioctl&quot; class=&quot;issue-link&quot; data-issue-key=&quot;LU-12580&quot;&gt;&lt;del&gt;LU-12580&lt;/del&gt;&lt;/a&gt; &quot;&lt;tt&gt;usercopy exposure attempt detected in LL_IOC_LOV_GETSTRIPE ioctl&lt;/tt&gt;&quot; and is fixed by patch &lt;a href=&quot;https://review.whamcloud.com/38050&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://review.whamcloud.com/38050&lt;/a&gt;&lt;br/&gt;
&quot;&lt;tt&gt;&lt;a href=&quot;https://jira.whamcloud.com/browse/LU-12580&quot; title=&quot;usercopy exposure attempt detected in LL_IOC_LOV_GETSTRIPE ioctl&quot; class=&quot;issue-link&quot; data-issue-key=&quot;LU-12580&quot;&gt;&lt;del&gt;LU-12580&lt;/del&gt;&lt;/a&gt; lov: fix typo in lov_comp_md_size&lt;/tt&gt;&quot; and patch &lt;a href=&quot;https://review.whamcloud.com/38051&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://review.whamcloud.com/38051&lt;/a&gt;&lt;br/&gt;
&quot;&lt;tt&gt;&lt;a href=&quot;https://jira.whamcloud.com/browse/LU-12580&quot; title=&quot;usercopy exposure attempt detected in LL_IOC_LOV_GETSTRIPE ioctl&quot; class=&quot;issue-link&quot; data-issue-key=&quot;LU-12580&quot;&gt;&lt;del&gt;LU-12580&lt;/del&gt;&lt;/a&gt; lov: fix out of bound usercopy&lt;/tt&gt;&quot;.&lt;/p&gt;</comment>
                            <comment id="271567" author="ofaaland" created="Fri, 29 May 2020 22:25:45 +0000"  >&lt;p&gt;I agree, it looks like a dupe of &lt;a href=&quot;https://jira.whamcloud.com/browse/LU-12580&quot; title=&quot;usercopy exposure attempt detected in LL_IOC_LOV_GETSTRIPE ioctl&quot; class=&quot;issue-link&quot; data-issue-key=&quot;LU-12580&quot;&gt;&lt;del&gt;LU-12580&lt;/del&gt;&lt;/a&gt;.  Sorry, not sure how I missed that.&lt;/p&gt;</comment>
                            <comment id="271570" author="pjones" created="Fri, 29 May 2020 22:39:13 +0000"  >&lt;p&gt;NP. Should be fixed in 2.12.5 then.&lt;/p&gt;</comment>
                    </comments>
                <issuelinks>
                            <issuelinktype id="10010">
                    <name>Duplicate</name>
                                            <outwardlinks description="duplicates">
                                        <issuelink>
            <issuekey id="56476">LU-12580</issuekey>
        </issuelink>
                            </outwardlinks>
                                                        </issuelinktype>
                    </issuelinks>
                <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                                                                                                                                            <customfield id="customfield_10890" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        <customfield id="customfield_10390" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>1|i01153:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10090" key="com.pyxis.greenhopper.jira:gh-global-rank">
                        <customfieldname>Rank (Obsolete)</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>9223372036854775807</customfieldvalue>
                        </customfieldvalues>
                    </customfield>
                                                                                            <customfield id="customfield_10060" key="com.atlassian.jira.plugin.system.customfieldtypes:select">
                        <customfieldname>Severity</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue key="10022"><![CDATA[3]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        </customfields>
    </item>
</channel>
</rss>