On 7/17/24 6:28 AM, Toke Høiland-Jørgensen wrote:
It looks very similar to
https://lore.kernel.org/bpf/000000000000f6531b061494e696@xxxxxxxxxx/. It has
been fixed in commit 5bcf0dcbf906 ("xdp: use flags field to disambiguate
broadcast redirect")
I tried the C repro. I can reproduce in the bpf tree also which should have the
fix. I cannot reproduce in the bpf-next though.
Cc Toke who knows more details here.
Hmm, yeah, it does look kinda similar. Do you mean that the C repro from
this new report triggers the crash for you on the current -bpf tree?
I was able to repro in bpf tree ~two days ago but not now. The bpf tree has been
fast forwarded and has the 6.10 changes. I just tried linux-stable/linux-6.9.y
which has the fix in the commit 5bcf0dcbf906. The syzbot report (against the
36534d3c5453) also has that fix.
In particular, the syzbot repro I tried:
https://syzkaller.appspot.com/text?tag=ReproC&x=17caa30a980000