Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #86726 > unrolled thread

Bug#1086175: linux-image-6.1.0-26-amd64: panic at shutdown with rootfs on RAID1 while initialy resyncing

Started byTj <tj.iam.tj@proton.me>
First post2025-04-03 22:40 +0200
Last post2025-04-09 20:40 +0200
Articles 2 — 2 participants

Back to article view | Back to linux.debian.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Bug#1086175: linux-image-6.1.0-26-amd64: panic at shutdown with rootfs on RAID1 while initialy resyncing Tj <tj.iam.tj@proton.me> - 2025-04-03 22:40 +0200
    Bug#1086175: linux-image-6.1.0-26-amd64: panic at shutdown with rootfs on RAID1 while initialy resyncing Salvatore Bonaccorso <carnil@debian.org> - 2025-04-09 20:40 +0200

#86726 — Bug#1086175: linux-image-6.1.0-26-amd64: panic at shutdown with rootfs on RAID1 while initialy resyncing

FromTj <tj.iam.tj@proton.me>
Date2025-04-03 22:40 +0200
SubjectBug#1086175: linux-image-6.1.0-26-amd64: panic at shutdown with rootfs on RAID1 while initialy resyncing
Message-ID<KxzvX-aQKC-5@gated-at.bofh.it>
Package: linux-image-6.13.1+debian+tj
Followup-For: Bug #1086175
X-Debbugs-Cc: tj.iam.tj@proton.me

Thank-you for the link to the mail-list bug report Alessandro. That has
resulted in a very recent mainline patch in the current v6.15
development cycle that likely fixes the bug:

commit 8542870237c3a48ff049b6c5df5f50c8728284fa
Author: Yu Kuai <yukuai3@huawei.com>
Date:   Thu Feb 20 20:43:48 2025 +0800

    md: fix mddev uaf while iterating all_mddevs list

    While iterating all_mddevs list from md_notify_reboot() and md_exit(),
    list_for_each_entry_safe is used, and this can race with deletint the
    next mddev, causing UAF:
...

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/drivers/md/md.c?id=8542870237c3a48ff049b6c5df5f50c8728284fa

Since this is a race condition it makes some sense that it rarely
affects spinning disks but does affect virtual disks on SSDs and SSDs
themselves since flushing buffers to device before closing will take
longer in most cases.

Are you able to build and test the current mainline kernel master branch
to verify this patch will fix the bug?

If verified we can:

1) check if the patch or a slightly modified version can be applied to
v6.1

2) suggest to upstream the patch should be backported to the LTS/stable
trees.

If (2) happens Debian will automatically benefit.

If you're unable to build a kernel there are a couple of alternatives:

a) I can build it and share it with you, or

b) Test it using an Ubuntu mainline kernel build [0] of v6.15-rc* release
candidates once they are published.

[0] https://kernel.ubuntu.com/mainline/?C=N;O=D

[toc] | [next] | [standalone]


#86802

FromSalvatore Bonaccorso <carnil@debian.org>
Date2025-04-09 20:40 +0200
Message-ID<KzIv7-cl0R-21@gated-at.bofh.it>
In reply to#86726
Hi Tj, hi Alessandro,

On Thu, Apr 03, 2025 at 09:35:33PM +0100, Tj wrote:
> Package: linux-image-6.13.1+debian+tj
> Followup-For: Bug #1086175
> X-Debbugs-Cc: tj.iam.tj@proton.me
> 
> Thank-you for the link to the mail-list bug report Alessandro. That has
> resulted in a very recent mainline patch in the current v6.15
> development cycle that likely fixes the bug:
> 
> commit 8542870237c3a48ff049b6c5df5f50c8728284fa
> Author: Yu Kuai <yukuai3@huawei.com>
> Date:   Thu Feb 20 20:43:48 2025 +0800
> 
>     md: fix mddev uaf while iterating all_mddevs list
> 
>     While iterating all_mddevs list from md_notify_reboot() and md_exit(),
>     list_for_each_entry_safe is used, and this can race with deletint the
>     next mddev, causing UAF:
> ...
> 
> https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/drivers/md/md.c?id=8542870237c3a48ff049b6c5df5f50c8728284fa
> 
> Since this is a race condition it makes some sense that it rarely
> affects spinning disks but does affect virtual disks on SSDs and SSDs
> themselves since flushing buffers to device before closing will take
> longer in most cases.
> 
> Are you able to build and test the current mainline kernel master branch
> to verify this patch will fix the bug?
> 
> If verified we can:
> 
> 1) check if the patch or a slightly modified version can be applied to
> v6.1
> 
> 2) suggest to upstream the patch should be backported to the LTS/stable
> trees.
> 
> If (2) happens Debian will automatically benefit.
> 
> If you're unable to build a kernel there are a couple of alternatives:
> 
> a) I can build it and share it with you, or
> 
> b) Test it using an Ubuntu mainline kernel build [0] of v6.15-rc* release
> candidates once they are published.
> 
> [0] https://kernel.ubuntu.com/mainline/?C=N;O=D

Thanks a lot both for your contributions. I have cherry-picked ahead
the commit for our experimental and unstable upload (pending).

For 6.1.y the commit won't apply cleanly but given it has Fixes tags
accordingly I hope we can see a fix to land in 6.1.y soonish and
include it one of our next uploads. Possible we won't be in time for
the next point release, but that remains to be seen (e.g. prodding
upstream).

Regards,
Salvatore

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.kernel


csiph-web