net/core: BUG in copy_net_ns()

Message ID bc63c776-99f9-ca6e-0e81-f91b1448932b@gmail.com
State Changes Requested
Delegated to: David Miller
Headers show
Series
  • net/core: BUG in copy_net_ns()
Related show

Commit Message

zzoru Jan. 11, 2019, 6:07 p.m.
net/core: BUG in copy_net_ns() (net_namespace.c)

Hello,

I've got the following error report while fuzzing the kernel with syzkaller.

On commit 1bdbe227492075d058e37cb3d400e6468d0095b5

Syzkaller hit 'WARNING in __alloc_pages_slowpath' bug.

syz-executor561 (17453) used greatest stack depth: 25056 bytes left
WARNING: CPU: 0 PID: 692 at mm/page_alloc.c:4415
__alloc_pages_slowpath+0x1cb1/0x2220 mm/page_alloc.c:4386
Kernel panic - not syncing: panic_on_warn set ...
CPU: 0 PID: 692 Comm: kswapd0 Not tainted 5.0.0-rc1+ #4
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS
Ubuntu-1.8.2-1ubuntu1 04/01/2014
Call Trace:
 __dump_stack lib/dump_stack.c:77 [inline]
 dump_stack+0xca/0x13e lib/dump_stack.c:113
 panic+0x278/0x5bf kernel/panic.c:214
 __warn.cold.10+0x20/0x45 kernel/panic.c:571
 report_bug+0x246/0x2d0 lib/bug.c:186
 fixup_bug arch/x86/kernel/traps.c:178 [inline]
 do_error_trap+0x123/0x1e0 arch/x86/kernel/traps.c:271
 do_invalid_op+0x31/0x40 arch/x86/kernel/traps.c:290
 invalid_op+0x14/0x20 arch/x86/entry/entry_64.S:973
RIP: 0010:__alloc_pages_slowpath+0x1cb1/0x2220 mm/page_alloc.c:4415
Code: 8b 84 24 a8 00 00 00 e9 ea f1 ff ff 85 d2 0f 85 0b 01 00 00 48 c7
c7 c0 5e 55 84 e8 79 f8 23 02 e9 86 f9 ff ff 44 8b 74 24 0c <0f> 0b 48
b8 00 00 00 00 00 fc ff df 48 8b 54 24 18 48 c1 ea 03 80
RSP: 0018:ffff8880683fedb8 EFLAGS: 00010046
RAX: 0000000000000000 RBX: 0000000000000000 RCX: 1ffff1100d07fda4
RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff88807ffdd528
RBP: dffffc0000000000 R08: 0000000000000000 R09: 000000000000067a
R10: 0000000000000000 R11: ffff88807ffdc487 R12: 0000000000000000
R13: ffff8880683ff010 R14: 0000000000415a00 R15: ffff8880683ff010
 __alloc_pages_nodemask+0x521/0x5f0 mm/page_alloc.c:4555
 __alloc_pages include/linux/gfp.h:473 [inline]
 __alloc_pages_node include/linux/gfp.h:486 [inline]
 kmem_getpages mm/slab.c:1398 [inline]
 cache_grow_begin+0x95/0x300 mm/slab.c:2666
 fallback_alloc+0x1ce/0x270 mm/slab.c:3208
 __do_cache_alloc mm/slab.c:3345 [inline]
 slab_alloc mm/slab.c:3373 [inline]
 kmem_cache_alloc+0x286/0x2f0 mm/slab.c:3541
 create_object+0x83/0x880 mm/kmemleak.c:578
 kmemleak_alloc_recursive include/linux/kmemleak.h:55 [inline]
 slab_post_alloc_hook mm/slab.h:442 [inline]
 slab_alloc mm/slab.c:3381 [inline]
 kmem_cache_alloc+0x18f/0x2f0 mm/slab.c:3541
 mempool_alloc+0x13e/0x340 mm/mempool.c:385
 bio_alloc_bioset+0x36f/0x5d0 block/bio.c:489
 bio_alloc include/linux/bio.h:393 [inline]
 submit_bh_wbc.isra.57+0x128/0x680 fs/buffer.c:3061
 __block_write_full_page+0x6e8/0xcd0 fs/buffer.c:1765
 block_write_full_page+0x202/0x250 fs/buffer.c:2955
 pageout mm/vmscan.c:865 [inline]
 shrink_page_list+0x220f/0x3800 mm/vmscan.c:1383
 shrink_inactive_list+0x3c2/0xaa0 mm/vmscan.c:1961
 shrink_list mm/vmscan.c:2273 [inline]
 shrink_node_memcg.constprop.83+0x4bf/0x10e0 mm/vmscan.c:2538
 shrink_node+0x162/0xd10 mm/vmscan.c:2753
 kswapd_shrink_node mm/vmscan.c:3516 [inline]
 balance_pgdat+0x47f/0xc00 mm/vmscan.c:3674
 kswapd+0x57c/0xde0 mm/vmscan.c:3929
 kthread+0x347/0x410 kernel/kthread.c:246
 ret_from_fork+0x3a/0x50 arch/x86/entry/entry_64.S:352
Dumping ftrace buffer:
   (ftrace buffer empty)
Kernel Offset: disabled
Rebooting in 86400 seconds..


Syzkaller reproducer:
# {Threaded:false Collide:false Repeat:true RepeatTimes:0 Procs:8
Sandbox:none Fault:false FaultCall:-1 FaultNth:0 EnableTun:false
UseTmpDir:true EnableCgroups:false EnableNetdev:true ResetNet:false
HandleSegv:false Repro:false Trace:false}
unshare(0x40000000)


C reproducer:
// autogenerated by syzkaller (https://github.com/google/syzkaller)

#define _GNU_SOURCE

#include <arpa/inet.h>
#include <dirent.h>
#include <endian.h>
#include <errno.h>
#include <fcntl.h>
#include <net/if.h>
#include <net/if_arp.h>
#include <netinet/in.h>
#include <sched.h>
#include <signal.h>
#include <stdarg.h>
#include <stdbool.h>
#include <stdint.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <sys/ioctl.h>
#include <sys/mount.h>
#include <sys/prctl.h>
#include <sys/resource.h>
#include <sys/socket.h>
#include <sys/stat.h>
#include <sys/syscall.h>
#include <sys/time.h>
#include <sys/types.h>
#include <sys/uio.h>
#include <sys/wait.h>
#include <time.h>
#include <unistd.h>

#include <linux/if_addr.h>
#include <linux/if_ether.h>
#include <linux/if_link.h>
#include <linux/if_tun.h>
#include <linux/in6.h>
#include <linux/ip.h>
#include <linux/neighbour.h>
#include <linux/net.h>
#include <linux/netlink.h>
#include <linux/rtnetlink.h>
#include <linux/tcp.h>
#include <linux/veth.h>

unsigned long long procid;

static void sleep_ms(uint64_t ms)
{
  usleep(ms * 1000);
}

static uint64_t current_time_ms(void)
{
  struct timespec ts;
  if (clock_gettime(CLOCK_MONOTONIC, &ts))
    exit(1);
  return (uint64_t)ts.tv_sec * 1000 + (uint64_t)ts.tv_nsec / 1000000;
}

static void use_temporary_dir(void)
{
  char tmpdir_template[] = "./syzkaller.XXXXXX";
  char* tmpdir = mkdtemp(tmpdir_template);
  if (!tmpdir)
    exit(1);
  if (chmod(tmpdir, 0777))
    exit(1);
  if (chdir(tmpdir))
    exit(1);
}

static bool write_file(const char* file, const char* what, ...)
{
  char buf[1024];
  va_list args;
  va_start(args, what);
  vsnprintf(buf, sizeof(buf), what, args);
  va_end(args);
  buf[sizeof(buf) - 1] = 0;
  int len = strlen(buf);
  int fd = open(file, O_WRONLY | O_CLOEXEC);
  if (fd == -1)
    return false;
  if (write(fd, buf, len) != len) {
    int err = errno;
    close(fd);
    errno = err;
    return false;
  }
  close(fd);
  return true;
}

static struct {
  char* pos;
  int nesting;
  struct nlattr* nested[8];
  char buf[1024];
} nlmsg;

static void netlink_init(int typ, int flags, const void* data, int size)
{
  memset(&nlmsg, 0, sizeof(nlmsg));
  struct nlmsghdr* hdr = (struct nlmsghdr*)nlmsg.buf;
  hdr->nlmsg_type = typ;
  hdr->nlmsg_flags = NLM_F_REQUEST | NLM_F_ACK | flags;
  memcpy(hdr + 1, data, size);
  nlmsg.pos = (char*)(hdr + 1) + NLMSG_ALIGN(size);
}

static void netlink_attr(int typ, const void* data, int size)
{
  struct nlattr* attr = (struct nlattr*)nlmsg.pos;
  attr->nla_len = sizeof(*attr) + size;
  attr->nla_type = typ;
  memcpy(attr + 1, data, size);
  nlmsg.pos += NLMSG_ALIGN(attr->nla_len);
}

static void netlink_nest(int typ)
{
  struct nlattr* attr = (struct nlattr*)nlmsg.pos;
  attr->nla_type = typ;
  nlmsg.pos += sizeof(*attr);
  nlmsg.nested[nlmsg.nesting++] = attr;
}

static void netlink_done(void)
{
  struct nlattr* attr = nlmsg.nested[--nlmsg.nesting];
  attr->nla_len = nlmsg.pos - (char*)attr;
}

static int netlink_send(int sock)
{
  if (nlmsg.pos > nlmsg.buf + sizeof(nlmsg.buf) || nlmsg.nesting)
    exit(1);
  struct nlmsghdr* hdr = (struct nlmsghdr*)nlmsg.buf;
  hdr->nlmsg_len = nlmsg.pos - nlmsg.buf;
  struct sockaddr_nl addr;
  memset(&addr, 0, sizeof(addr));
  addr.nl_family = AF_NETLINK;
  unsigned n = sendto(sock, nlmsg.buf, hdr->nlmsg_len, 0,
                      (struct sockaddr*)&addr, sizeof(addr));
  if (n != hdr->nlmsg_len)
    exit(1);
  n = recv(sock, nlmsg.buf, sizeof(nlmsg.buf), 0);
  if (n < sizeof(struct nlmsghdr) + sizeof(struct nlmsgerr))
    exit(1);
  if (hdr->nlmsg_type != NLMSG_ERROR)
    exit(1);
  return -((struct nlmsgerr*)(hdr + 1))->error;
}

static void netlink_add_device_impl(const char* type, const char* name)
{
  struct ifinfomsg hdr;
  memset(&hdr, 0, sizeof(hdr));
  netlink_init(RTM_NEWLINK, NLM_F_EXCL | NLM_F_CREATE, &hdr, sizeof(hdr));
  if (name)
    netlink_attr(IFLA_IFNAME, name, strlen(name));
  netlink_nest(IFLA_LINKINFO);
  netlink_attr(IFLA_INFO_KIND, type, strlen(type));
}

static void netlink_add_device(int sock, const char* type, const char* name)
{
  netlink_add_device_impl(type, name);
  netlink_done();
  int err = netlink_send(sock);
  (void)err;
}

static void netlink_add_veth(int sock, const char* name, const char* peer)
{
  netlink_add_device_impl("veth", name);
  netlink_nest(IFLA_INFO_DATA);
  netlink_nest(VETH_INFO_PEER);
  nlmsg.pos += sizeof(struct ifinfomsg);
  netlink_attr(IFLA_IFNAME, peer, strlen(peer));
  netlink_done();
  netlink_done();
  netlink_done();
  int err = netlink_send(sock);
  (void)err;
}

static void netlink_add_hsr(int sock, const char* name, const char* slave1,
                            const char* slave2)
{
  netlink_add_device_impl("hsr", name);
  netlink_nest(IFLA_INFO_DATA);
  int ifindex1 = if_nametoindex(slave1);
  netlink_attr(IFLA_HSR_SLAVE1, &ifindex1, sizeof(ifindex1));
  int ifindex2 = if_nametoindex(slave2);
  netlink_attr(IFLA_HSR_SLAVE2, &ifindex2, sizeof(ifindex2));
  netlink_done();
  netlink_done();
  int err = netlink_send(sock);
  (void)err;
}

static void netlink_device_change(int sock, const char* name, bool up,
                                  const char* master, const void* mac,
                                  int macsize)
{
  struct ifinfomsg hdr;
  memset(&hdr, 0, sizeof(hdr));
  if (up)
    hdr.ifi_flags = hdr.ifi_change = IFF_UP;
  netlink_init(RTM_NEWLINK, 0, &hdr, sizeof(hdr));
  netlink_attr(IFLA_IFNAME, name, strlen(name));
  if (master) {
    int ifindex = if_nametoindex(master);
    netlink_attr(IFLA_MASTER, &ifindex, sizeof(ifindex));
  }
  if (macsize)
    netlink_attr(IFLA_ADDRESS, mac, macsize);
  int err = netlink_send(sock);
  (void)err;
}

static int netlink_add_addr(int sock, const char* dev, const void* addr,
                            int addrsize)
{
  struct ifaddrmsg hdr;
  memset(&hdr, 0, sizeof(hdr));
  hdr.ifa_family = addrsize == 4 ? AF_INET : AF_INET6;
  hdr.ifa_prefixlen = addrsize == 4 ? 24 : 120;
  hdr.ifa_scope = RT_SCOPE_UNIVERSE;
  hdr.ifa_index = if_nametoindex(dev);
  netlink_init(RTM_NEWADDR, NLM_F_CREATE | NLM_F_REPLACE, &hdr,
sizeof(hdr));
  netlink_attr(IFA_LOCAL, addr, addrsize);
  netlink_attr(IFA_ADDRESS, addr, addrsize);
  return netlink_send(sock);
}

static void netlink_add_addr4(int sock, const char* dev, const char* addr)
{
  struct in_addr in_addr;
  inet_pton(AF_INET, addr, &in_addr);
  int err = netlink_add_addr(sock, dev, &in_addr, sizeof(in_addr));
  (void)err;
}

static void netlink_add_addr6(int sock, const char* dev, const char* addr)
{
  struct in6_addr in6_addr;
  inet_pton(AF_INET6, addr, &in6_addr);
  int err = netlink_add_addr(sock, dev, &in6_addr, sizeof(in6_addr));
  (void)err;
}

#define DEV_IPV4 "172.20.20.%d"
#define DEV_IPV6 "fe80::%02hx"
#define DEV_MAC 0x00aaaaaaaaaa
static void initialize_netdevices(void)
{
  char netdevsim[16];
  sprintf(netdevsim, "netdevsim%d", (int)procid);
  struct {
    const char* type;
    const char* dev;
  } devtypes[] = {
      {"ip6gretap", "ip6gretap0"}, {"bridge", "bridge0"},
      {"vcan", "vcan0"},           {"bond", "bond0"},
      {"team", "team0"},           {"dummy", "dummy0"},
      {"nlmon", "nlmon0"},         {"caif", "caif0"},
      {"batadv", "batadv0"},       {"vxcan", "vxcan1"},
      {"netdevsim", netdevsim},    {"veth", 0},
  };
  const char* devmasters[] = {"bridge", "bond", "team"};
  struct {
    const char* name;
    int macsize;
    bool noipv6;
  } devices[] = {
      {"lo", ETH_ALEN},
      {"sit0", 0},
      {"bridge0", ETH_ALEN},
      {"vcan0", 0, true},
      {"tunl0", 0},
      {"gre0", 0},
      {"gretap0", ETH_ALEN},
      {"ip_vti0", 0},
      {"ip6_vti0", 0},
      {"ip6tnl0", 0},
      {"ip6gre0", 0},
      {"ip6gretap0", ETH_ALEN},
      {"erspan0", ETH_ALEN},
      {"bond0", ETH_ALEN},
      {"veth0", ETH_ALEN},
      {"veth1", ETH_ALEN},
      {"team0", ETH_ALEN},
      {"veth0_to_bridge", ETH_ALEN},
      {"veth1_to_bridge", ETH_ALEN},
      {"veth0_to_bond", ETH_ALEN},
      {"veth1_to_bond", ETH_ALEN},
      {"veth0_to_team", ETH_ALEN},
      {"veth1_to_team", ETH_ALEN},
      {"veth0_to_hsr", ETH_ALEN},
      {"veth1_to_hsr", ETH_ALEN},
      {"hsr0", 0},
      {"dummy0", ETH_ALEN},
      {"nlmon0", 0},
      {"vxcan1", 0, true},
      {"caif0", ETH_ALEN},
      {"batadv0", ETH_ALEN},
      {netdevsim, ETH_ALEN},
  };
  int sock = socket(AF_NETLINK, SOCK_RAW, NETLINK_ROUTE);
  if (sock == -1)
    exit(1);
  unsigned i;
  for (i = 0; i < sizeof(devtypes) / sizeof(devtypes[0]); i++)
    netlink_add_device(sock, devtypes[i].type, devtypes[i].dev);
  for (i = 0; i < sizeof(devmasters) / (sizeof(devmasters[0])); i++) {
    char master[32], slave0[32], veth0[32], slave1[32], veth1[32];
    sprintf(slave0, "%s_slave_0", devmasters[i]);
    sprintf(veth0, "veth0_to_%s", devmasters[i]);
    netlink_add_veth(sock, slave0, veth0);
    sprintf(slave1, "%s_slave_1", devmasters[i]);
    sprintf(veth1, "veth1_to_%s", devmasters[i]);
    netlink_add_veth(sock, slave1, veth1);
    sprintf(master, "%s0", devmasters[i]);
    netlink_device_change(sock, slave0, false, master, 0, 0);
    netlink_device_change(sock, slave1, false, master, 0, 0);
  }
  netlink_device_change(sock, "bridge_slave_0", true, 0, 0, 0);
  netlink_device_change(sock, "bridge_slave_1", true, 0, 0, 0);
  netlink_add_veth(sock, "hsr_slave_0", "veth0_to_hsr");
  netlink_add_veth(sock, "hsr_slave_1", "veth1_to_hsr");
  netlink_add_hsr(sock, "hsr0", "hsr_slave_0", "hsr_slave_1");
  netlink_device_change(sock, "hsr_slave_0", true, 0, 0, 0);
  netlink_device_change(sock, "hsr_slave_1", true, 0, 0, 0);
  for (i = 0; i < sizeof(devices) / (sizeof(devices[0])); i++) {
    char addr[32];
    sprintf(addr, DEV_IPV4, i + 10);
    netlink_add_addr4(sock, devices[i].name, addr);
    if (!devices[i].noipv6) {
      sprintf(addr, DEV_IPV6, i + 10);
      netlink_add_addr6(sock, devices[i].name, addr);
    }
    uint64_t macaddr = DEV_MAC + ((i + 10ull) << 40);
    netlink_device_change(sock, devices[i].name, true, 0, &macaddr,
                          devices[i].macsize);
  }
  close(sock);
}
static void initialize_netdevices_init(void)
{
  int sock = socket(AF_NETLINK, SOCK_RAW, NETLINK_ROUTE);
  if (sock == -1)
    exit(1);
  struct {
    const char* type;
    int macsize;
    bool noipv6;
    bool noup;
  } devtypes[] = {
      {"nr", 7, true}, {"rose", 5, true, true},
  };
  unsigned i;
  for (i = 0; i < sizeof(devtypes) / sizeof(devtypes[0]); i++) {
    char dev[32], addr[32];
    sprintf(dev, "%s%d", devtypes[i].type, (int)procid);
    sprintf(addr, "172.30.%d.%d", i, (int)procid + 1);
    netlink_add_addr4(sock, dev, addr);
    if (!devtypes[i].noipv6) {
      sprintf(addr, "fe88::%02hx:%02hx", i, (int)procid + 1);
      netlink_add_addr6(sock, dev, addr);
    }
    int macsize = devtypes[i].macsize;
    uint64_t macaddr = 0xbbbbbb +
                       ((unsigned long long)i << (8 * (macsize - 2))) +
                       (procid << (8 * (macsize - 1)));
    netlink_device_change(sock, dev, !devtypes[i].noup, 0, &macaddr,
macsize);
  }
  close(sock);
}

static void setup_common()
{
  if (mount(0, "/sys/fs/fuse/connections", "fusectl", 0, 0)) {
  }
}

static void loop();

static void sandbox_common()
{
  prctl(PR_SET_PDEATHSIG, SIGKILL, 0, 0, 0);
  setpgrp();
  setsid();
  struct rlimit rlim;
  rlim.rlim_cur = rlim.rlim_max = 200 << 20;
  setrlimit(RLIMIT_AS, &rlim);
  rlim.rlim_cur = rlim.rlim_max = 32 << 20;
  setrlimit(RLIMIT_MEMLOCK, &rlim);
  rlim.rlim_cur = rlim.rlim_max = 136 << 20;
  setrlimit(RLIMIT_FSIZE, &rlim);
  rlim.rlim_cur = rlim.rlim_max = 1 << 20;
  setrlimit(RLIMIT_STACK, &rlim);
  rlim.rlim_cur = rlim.rlim_max = 0;
  setrlimit(RLIMIT_CORE, &rlim);
  rlim.rlim_cur = rlim.rlim_max = 256;
  setrlimit(RLIMIT_NOFILE, &rlim);
  if (unshare(CLONE_NEWNS)) {
  }
  if (unshare(CLONE_NEWIPC)) {
  }
  if (unshare(0x02000000)) {
  }
  if (unshare(CLONE_NEWUTS)) {
  }
  if (unshare(CLONE_SYSVSEM)) {
  }
  typedef struct {
    const char* name;
    const char* value;
  } sysctl_t;
  static const sysctl_t sysctls[] = {
      {"/proc/sys/kernel/shmmax", "16777216"},
      {"/proc/sys/kernel/shmall", "536870912"},
      {"/proc/sys/kernel/shmmni", "1024"},
      {"/proc/sys/kernel/msgmax", "8192"},
      {"/proc/sys/kernel/msgmni", "1024"},
      {"/proc/sys/kernel/msgmnb", "1024"},
      {"/proc/sys/kernel/sem", "1024 1048576 500 1024"},
  };
  unsigned i;
  for (i = 0; i < sizeof(sysctls) / sizeof(sysctls[0]); i++)
    write_file(sysctls[i].name, sysctls[i].value);
}

int wait_for_loop(int pid)
{
  if (pid < 0)
    exit(1);
  int status = 0;
  while (waitpid(-1, &status, __WALL) != pid) {
  }
  return WEXITSTATUS(status);
}

static int do_sandbox_none(void)
{
  if (unshare(CLONE_NEWPID)) {
  }
  int pid = fork();
  if (pid != 0)
    return wait_for_loop(pid);
  setup_common();
  sandbox_common();
  initialize_netdevices_init();
  if (unshare(CLONE_NEWNET)) {
  }
  initialize_netdevices();
  loop();
  exit(1);
}

#define FS_IOC_SETFLAGS _IOW('f', 2, long)
static void remove_dir(const char* dir)
{
  DIR* dp;
  struct dirent* ep;
  int iter = 0;
retry:
  while (umount2(dir, MNT_DETACH) == 0) {
  }
  dp = opendir(dir);
  if (dp == NULL) {
    if (errno == EMFILE) {
      exit(1);
    }
    exit(1);
  }
  while ((ep = readdir(dp))) {
    if (strcmp(ep->d_name, ".") == 0 || strcmp(ep->d_name, "..") == 0)
      continue;
    char filename[FILENAME_MAX];
    snprintf(filename, sizeof(filename), "%s/%s", dir, ep->d_name);
    while (umount2(filename, MNT_DETACH) == 0) {
    }
    struct stat st;
    if (lstat(filename, &st))
      exit(1);
    if (S_ISDIR(st.st_mode)) {
      remove_dir(filename);
      continue;
    }
    int i;
    for (i = 0;; i++) {
      if (unlink(filename) == 0)
        break;
      if (errno == EPERM) {
        int fd = open(filename, O_RDONLY);
        if (fd != -1) {
          long flags = 0;
          if (ioctl(fd, FS_IOC_SETFLAGS, &flags) == 0)
            close(fd);
          continue;
        }
      }
      if (errno == EROFS) {
        break;
      }
      if (errno != EBUSY || i > 100)
        exit(1);
      if (umount2(filename, MNT_DETACH))
        exit(1);
    }
  }
  closedir(dp);
  int i;
  for (i = 0;; i++) {
    if (rmdir(dir) == 0)
      break;
    if (i < 100) {
      if (errno == EPERM) {
        int fd = open(dir, O_RDONLY);
        if (fd != -1) {
          long flags = 0;
          if (ioctl(fd, FS_IOC_SETFLAGS, &flags) == 0)
            close(fd);
          continue;
        }
      }
      if (errno == EROFS) {
        break;
      }
      if (errno == EBUSY) {
        if (umount2(dir, MNT_DETACH))
          exit(1);
        continue;
      }
      if (errno == ENOTEMPTY) {
        if (iter < 100) {
          iter++;
          goto retry;
        }
      }
    }
    exit(1);
  }
}

static void kill_and_wait(int pid, int* status)
{
  kill(-pid, SIGKILL);
  kill(pid, SIGKILL);
  int i;
  for (i = 0; i < 100; i++) {
    if (waitpid(-1, status, WNOHANG | __WALL) == pid)
      return;
    usleep(1000);
  }
  DIR* dir = opendir("/sys/fs/fuse/connections");
  if (dir) {
    for (;;) {
      struct dirent* ent = readdir(dir);
      if (!ent)
        break;
      if (strcmp(ent->d_name, ".") == 0 || strcmp(ent->d_name, "..") == 0)
        continue;
      char abort[300];
      snprintf(abort, sizeof(abort), "/sys/fs/fuse/connections/%s/abort",
               ent->d_name);
      int fd = open(abort, O_WRONLY);
      if (fd == -1) {
        continue;
      }
      if (write(fd, abort, 1) < 0) {
      }
      close(fd);
    }
    closedir(dir);
  } else {
  }
  while (waitpid(-1, status, __WALL) != pid) {
  }
}

#define SYZ_HAVE_SETUP_TEST 1
static void setup_test()
{
  prctl(PR_SET_PDEATHSIG, SIGKILL, 0, 0, 0);
  setpgrp();
}

#define SYZ_HAVE_RESET_TEST 1
static void reset_test()
{
  int fd;
  for (fd = 3; fd < 30; fd++)
    close(fd);
}

static void execute_one(void);

#define WAIT_FLAGS __WALL

static void loop(void)
{
  int iter;
  for (iter = 0;; iter++) {
    char cwdbuf[32];
    sprintf(cwdbuf, "./%d", iter);
    if (mkdir(cwdbuf, 0777))
      exit(1);
    int pid = fork();
    if (pid < 0)
      exit(1);
    if (pid == 0) {
      if (chdir(cwdbuf))
        exit(1);
      setup_test();
      execute_one();
      reset_test();
      exit(0);
    }
    int status = 0;
    uint64_t start = current_time_ms();
    for (;;) {
      if (waitpid(-1, &status, WNOHANG | WAIT_FLAGS) == pid)
        break;
      sleep_ms(1);
      if (current_time_ms() - start < 5 * 1000)
        continue;
      kill_and_wait(pid, &status);
      break;
    }
    remove_dir(cwdbuf);
  }
}

void execute_one(void)
{
  syscall(__NR_unshare, 0x40000000);
}
int main(void)
{
  syscall(__NR_mmap, 0x20000000, 0x1000000, 3, 0x32, -1, 0);
  for (procid = 0; procid < 8; procid++) {
    if (fork() == 0) {
      use_temporary_dir();
      do_sandbox_none();
    }
  }
  sleep(1000000);
  return 0;
}


I reviewed kernel code and found a bug that
net_drop_ns func doesn't call net_free func when refcount_dec_and_test's
return value is zero.
or
when rv = down_read_killable(&pernet_ops_rwsem) < 0, it doesn't need to
call refcount_dec_and_test.
https://github.com/torvalds/linux/commit/5ba049a5cc8e24a1643df75bbf65b4efa070fa74#diff-9312644e2968a45510bacdd2b2872ad2
(I can't reproduce this bug on v4.15 , and
1bdbe227492075d058e37cb3d400e6468d0095b5 with my patch. Because of the
previous version of kernel doesn't have this bug.)
This bug can lead to memory leak or DOS.

I made a patch for this bug. (just revert to a before commit)


and, sorry for my encrypted mails.

Comments

Eric W. Biederman Jan. 11, 2019, 8:33 p.m. | #1
zzoru <zzoru007@gmail.com> writes:

> net/core: BUG in copy_net_ns() (net_namespace.c)

I don't understand this failure report at all.

I don't see the connection to copy_net_ns().  And I don't see how the
suggested patch short of covering up a memory stomp could possibly make
a difference.

What am I missing?


> Hello,
>
> I've got the following error report while fuzzing the kernel with syzkaller.
>
> On commit 1bdbe227492075d058e37cb3d400e6468d0095b5
>
> Syzkaller hit 'WARNING in __alloc_pages_slowpath' bug.
>
> syz-executor561 (17453) used greatest stack depth: 25056 bytes left
> WARNING: CPU: 0 PID: 692 at mm/page_alloc.c:4415
> __alloc_pages_slowpath+0x1cb1/0x2220 mm/page_alloc.c:4386
> Kernel panic - not syncing: panic_on_warn set ...
> CPU: 0 PID: 692 Comm: kswapd0 Not tainted 5.0.0-rc1+ #4
> Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS
> Ubuntu-1.8.2-1ubuntu1 04/01/2014
> Call Trace:
>  __dump_stack lib/dump_stack.c:77 [inline]
>  dump_stack+0xca/0x13e lib/dump_stack.c:113
>  panic+0x278/0x5bf kernel/panic.c:214
>  __warn.cold.10+0x20/0x45 kernel/panic.c:571
>  report_bug+0x246/0x2d0 lib/bug.c:186
>  fixup_bug arch/x86/kernel/traps.c:178 [inline]
>  do_error_trap+0x123/0x1e0 arch/x86/kernel/traps.c:271
>  do_invalid_op+0x31/0x40 arch/x86/kernel/traps.c:290
>  invalid_op+0x14/0x20 arch/x86/entry/entry_64.S:973
> RIP: 0010:__alloc_pages_slowpath+0x1cb1/0x2220 mm/page_alloc.c:4415
> Code: 8b 84 24 a8 00 00 00 e9 ea f1 ff ff 85 d2 0f 85 0b 01 00 00 48 c7
> c7 c0 5e 55 84 e8 79 f8 23 02 e9 86 f9 ff ff 44 8b 74 24 0c <0f> 0b 48
> b8 00 00 00 00 00 fc ff df 48 8b 54 24 18 48 c1 ea 03 80
> RSP: 0018:ffff8880683fedb8 EFLAGS: 00010046
> RAX: 0000000000000000 RBX: 0000000000000000 RCX: 1ffff1100d07fda4
> RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff88807ffdd528
> RBP: dffffc0000000000 R08: 0000000000000000 R09: 000000000000067a
> R10: 0000000000000000 R11: ffff88807ffdc487 R12: 0000000000000000
> R13: ffff8880683ff010 R14: 0000000000415a00 R15: ffff8880683ff010
>  __alloc_pages_nodemask+0x521/0x5f0 mm/page_alloc.c:4555
>  __alloc_pages include/linux/gfp.h:473 [inline]
>  __alloc_pages_node include/linux/gfp.h:486 [inline]
>  kmem_getpages mm/slab.c:1398 [inline]
>  cache_grow_begin+0x95/0x300 mm/slab.c:2666
>  fallback_alloc+0x1ce/0x270 mm/slab.c:3208
>  __do_cache_alloc mm/slab.c:3345 [inline]
>  slab_alloc mm/slab.c:3373 [inline]
>  kmem_cache_alloc+0x286/0x2f0 mm/slab.c:3541
>  create_object+0x83/0x880 mm/kmemleak.c:578
>  kmemleak_alloc_recursive include/linux/kmemleak.h:55 [inline]
>  slab_post_alloc_hook mm/slab.h:442 [inline]
>  slab_alloc mm/slab.c:3381 [inline]
>  kmem_cache_alloc+0x18f/0x2f0 mm/slab.c:3541
>  mempool_alloc+0x13e/0x340 mm/mempool.c:385
>  bio_alloc_bioset+0x36f/0x5d0 block/bio.c:489
>  bio_alloc include/linux/bio.h:393 [inline]
>  submit_bh_wbc.isra.57+0x128/0x680 fs/buffer.c:3061
>  __block_write_full_page+0x6e8/0xcd0 fs/buffer.c:1765
>  block_write_full_page+0x202/0x250 fs/buffer.c:2955
>  pageout mm/vmscan.c:865 [inline]
>  shrink_page_list+0x220f/0x3800 mm/vmscan.c:1383
>  shrink_inactive_list+0x3c2/0xaa0 mm/vmscan.c:1961
>  shrink_list mm/vmscan.c:2273 [inline]
>  shrink_node_memcg.constprop.83+0x4bf/0x10e0 mm/vmscan.c:2538
>  shrink_node+0x162/0xd10 mm/vmscan.c:2753
>  kswapd_shrink_node mm/vmscan.c:3516 [inline]
>  balance_pgdat+0x47f/0xc00 mm/vmscan.c:3674
>  kswapd+0x57c/0xde0 mm/vmscan.c:3929
>  kthread+0x347/0x410 kernel/kthread.c:246
>  ret_from_fork+0x3a/0x50 arch/x86/entry/entry_64.S:352
> Dumping ftrace buffer:
>    (ftrace buffer empty)
> Kernel Offset: disabled
> Rebooting in 86400 seconds..
>
>
> Syzkaller reproducer:
> # {Threaded:false Collide:false Repeat:true RepeatTimes:0 Procs:8
> Sandbox:none Fault:false FaultCall:-1 FaultNth:0 EnableTun:false
> UseTmpDir:true EnableCgroups:false EnableNetdev:true ResetNet:false
> HandleSegv:false Repro:false Trace:false}
> unshare(0x40000000)
>
>
> C reproducer:
> // autogenerated by syzkaller (https://github.com/google/syzkaller)
>
> #define _GNU_SOURCE
>
> #include <arpa/inet.h>
> #include <dirent.h>
> #include <endian.h>
> #include <errno.h>
> #include <fcntl.h>
> #include <net/if.h>
> #include <net/if_arp.h>
> #include <netinet/in.h>
> #include <sched.h>
> #include <signal.h>
> #include <stdarg.h>
> #include <stdbool.h>
> #include <stdint.h>
> #include <stdio.h>
> #include <stdlib.h>
> #include <string.h>
> #include <sys/ioctl.h>
> #include <sys/mount.h>
> #include <sys/prctl.h>
> #include <sys/resource.h>
> #include <sys/socket.h>
> #include <sys/stat.h>
> #include <sys/syscall.h>
> #include <sys/time.h>
> #include <sys/types.h>
> #include <sys/uio.h>
> #include <sys/wait.h>
> #include <time.h>
> #include <unistd.h>
>
> #include <linux/if_addr.h>
> #include <linux/if_ether.h>
> #include <linux/if_link.h>
> #include <linux/if_tun.h>
> #include <linux/in6.h>
> #include <linux/ip.h>
> #include <linux/neighbour.h>
> #include <linux/net.h>
> #include <linux/netlink.h>
> #include <linux/rtnetlink.h>
> #include <linux/tcp.h>
> #include <linux/veth.h>
>
> unsigned long long procid;
>
> static void sleep_ms(uint64_t ms)
> {
>   usleep(ms * 1000);
> }
>
> static uint64_t current_time_ms(void)
> {
>   struct timespec ts;
>   if (clock_gettime(CLOCK_MONOTONIC, &ts))
>     exit(1);
>   return (uint64_t)ts.tv_sec * 1000 + (uint64_t)ts.tv_nsec / 1000000;
> }
>
> static void use_temporary_dir(void)
> {
>   char tmpdir_template[] = "./syzkaller.XXXXXX";
>   char* tmpdir = mkdtemp(tmpdir_template);
>   if (!tmpdir)
>     exit(1);
>   if (chmod(tmpdir, 0777))
>     exit(1);
>   if (chdir(tmpdir))
>     exit(1);
> }
>
> static bool write_file(const char* file, const char* what, ...)
> {
>   char buf[1024];
>   va_list args;
>   va_start(args, what);
>   vsnprintf(buf, sizeof(buf), what, args);
>   va_end(args);
>   buf[sizeof(buf) - 1] = 0;
>   int len = strlen(buf);
>   int fd = open(file, O_WRONLY | O_CLOEXEC);
>   if (fd == -1)
>     return false;
>   if (write(fd, buf, len) != len) {
>     int err = errno;
>     close(fd);
>     errno = err;
>     return false;
>   }
>   close(fd);
>   return true;
> }
>
> static struct {
>   char* pos;
>   int nesting;
>   struct nlattr* nested[8];
>   char buf[1024];
> } nlmsg;
>
> static void netlink_init(int typ, int flags, const void* data, int size)
> {
>   memset(&nlmsg, 0, sizeof(nlmsg));
>   struct nlmsghdr* hdr = (struct nlmsghdr*)nlmsg.buf;
>   hdr->nlmsg_type = typ;
>   hdr->nlmsg_flags = NLM_F_REQUEST | NLM_F_ACK | flags;
>   memcpy(hdr + 1, data, size);
>   nlmsg.pos = (char*)(hdr + 1) + NLMSG_ALIGN(size);
> }
>
> static void netlink_attr(int typ, const void* data, int size)
> {
>   struct nlattr* attr = (struct nlattr*)nlmsg.pos;
>   attr->nla_len = sizeof(*attr) + size;
>   attr->nla_type = typ;
>   memcpy(attr + 1, data, size);
>   nlmsg.pos += NLMSG_ALIGN(attr->nla_len);
> }
>
> static void netlink_nest(int typ)
> {
>   struct nlattr* attr = (struct nlattr*)nlmsg.pos;
>   attr->nla_type = typ;
>   nlmsg.pos += sizeof(*attr);
>   nlmsg.nested[nlmsg.nesting++] = attr;
> }
>
> static void netlink_done(void)
> {
>   struct nlattr* attr = nlmsg.nested[--nlmsg.nesting];
>   attr->nla_len = nlmsg.pos - (char*)attr;
> }
>
> static int netlink_send(int sock)
> {
>   if (nlmsg.pos > nlmsg.buf + sizeof(nlmsg.buf) || nlmsg.nesting)
>     exit(1);
>   struct nlmsghdr* hdr = (struct nlmsghdr*)nlmsg.buf;
>   hdr->nlmsg_len = nlmsg.pos - nlmsg.buf;
>   struct sockaddr_nl addr;
>   memset(&addr, 0, sizeof(addr));
>   addr.nl_family = AF_NETLINK;
>   unsigned n = sendto(sock, nlmsg.buf, hdr->nlmsg_len, 0,
>                       (struct sockaddr*)&addr, sizeof(addr));
>   if (n != hdr->nlmsg_len)
>     exit(1);
>   n = recv(sock, nlmsg.buf, sizeof(nlmsg.buf), 0);
>   if (n < sizeof(struct nlmsghdr) + sizeof(struct nlmsgerr))
>     exit(1);
>   if (hdr->nlmsg_type != NLMSG_ERROR)
>     exit(1);
>   return -((struct nlmsgerr*)(hdr + 1))->error;
> }
>
> static void netlink_add_device_impl(const char* type, const char* name)
> {
>   struct ifinfomsg hdr;
>   memset(&hdr, 0, sizeof(hdr));
>   netlink_init(RTM_NEWLINK, NLM_F_EXCL | NLM_F_CREATE, &hdr, sizeof(hdr));
>   if (name)
>     netlink_attr(IFLA_IFNAME, name, strlen(name));
>   netlink_nest(IFLA_LINKINFO);
>   netlink_attr(IFLA_INFO_KIND, type, strlen(type));
> }
>
> static void netlink_add_device(int sock, const char* type, const char* name)
> {
>   netlink_add_device_impl(type, name);
>   netlink_done();
>   int err = netlink_send(sock);
>   (void)err;
> }
>
> static void netlink_add_veth(int sock, const char* name, const char* peer)
> {
>   netlink_add_device_impl("veth", name);
>   netlink_nest(IFLA_INFO_DATA);
>   netlink_nest(VETH_INFO_PEER);
>   nlmsg.pos += sizeof(struct ifinfomsg);
>   netlink_attr(IFLA_IFNAME, peer, strlen(peer));
>   netlink_done();
>   netlink_done();
>   netlink_done();
>   int err = netlink_send(sock);
>   (void)err;
> }
>
> static void netlink_add_hsr(int sock, const char* name, const char* slave1,
>                             const char* slave2)
> {
>   netlink_add_device_impl("hsr", name);
>   netlink_nest(IFLA_INFO_DATA);
>   int ifindex1 = if_nametoindex(slave1);
>   netlink_attr(IFLA_HSR_SLAVE1, &ifindex1, sizeof(ifindex1));
>   int ifindex2 = if_nametoindex(slave2);
>   netlink_attr(IFLA_HSR_SLAVE2, &ifindex2, sizeof(ifindex2));
>   netlink_done();
>   netlink_done();
>   int err = netlink_send(sock);
>   (void)err;
> }
>
> static void netlink_device_change(int sock, const char* name, bool up,
>                                   const char* master, const void* mac,
>                                   int macsize)
> {
>   struct ifinfomsg hdr;
>   memset(&hdr, 0, sizeof(hdr));
>   if (up)
>     hdr.ifi_flags = hdr.ifi_change = IFF_UP;
>   netlink_init(RTM_NEWLINK, 0, &hdr, sizeof(hdr));
>   netlink_attr(IFLA_IFNAME, name, strlen(name));
>   if (master) {
>     int ifindex = if_nametoindex(master);
>     netlink_attr(IFLA_MASTER, &ifindex, sizeof(ifindex));
>   }
>   if (macsize)
>     netlink_attr(IFLA_ADDRESS, mac, macsize);
>   int err = netlink_send(sock);
>   (void)err;
> }
>
> static int netlink_add_addr(int sock, const char* dev, const void* addr,
>                             int addrsize)
> {
>   struct ifaddrmsg hdr;
>   memset(&hdr, 0, sizeof(hdr));
>   hdr.ifa_family = addrsize == 4 ? AF_INET : AF_INET6;
>   hdr.ifa_prefixlen = addrsize == 4 ? 24 : 120;
>   hdr.ifa_scope = RT_SCOPE_UNIVERSE;
>   hdr.ifa_index = if_nametoindex(dev);
>   netlink_init(RTM_NEWADDR, NLM_F_CREATE | NLM_F_REPLACE, &hdr,
> sizeof(hdr));
>   netlink_attr(IFA_LOCAL, addr, addrsize);
>   netlink_attr(IFA_ADDRESS, addr, addrsize);
>   return netlink_send(sock);
> }
>
> static void netlink_add_addr4(int sock, const char* dev, const char* addr)
> {
>   struct in_addr in_addr;
>   inet_pton(AF_INET, addr, &in_addr);
>   int err = netlink_add_addr(sock, dev, &in_addr, sizeof(in_addr));
>   (void)err;
> }
>
> static void netlink_add_addr6(int sock, const char* dev, const char* addr)
> {
>   struct in6_addr in6_addr;
>   inet_pton(AF_INET6, addr, &in6_addr);
>   int err = netlink_add_addr(sock, dev, &in6_addr, sizeof(in6_addr));
>   (void)err;
> }
>
> #define DEV_IPV4 "172.20.20.%d"
> #define DEV_IPV6 "fe80::%02hx"
> #define DEV_MAC 0x00aaaaaaaaaa
> static void initialize_netdevices(void)
> {
>   char netdevsim[16];
>   sprintf(netdevsim, "netdevsim%d", (int)procid);
>   struct {
>     const char* type;
>     const char* dev;
>   } devtypes[] = {
>       {"ip6gretap", "ip6gretap0"}, {"bridge", "bridge0"},
>       {"vcan", "vcan0"},           {"bond", "bond0"},
>       {"team", "team0"},           {"dummy", "dummy0"},
>       {"nlmon", "nlmon0"},         {"caif", "caif0"},
>       {"batadv", "batadv0"},       {"vxcan", "vxcan1"},
>       {"netdevsim", netdevsim},    {"veth", 0},
>   };
>   const char* devmasters[] = {"bridge", "bond", "team"};
>   struct {
>     const char* name;
>     int macsize;
>     bool noipv6;
>   } devices[] = {
>       {"lo", ETH_ALEN},
>       {"sit0", 0},
>       {"bridge0", ETH_ALEN},
>       {"vcan0", 0, true},
>       {"tunl0", 0},
>       {"gre0", 0},
>       {"gretap0", ETH_ALEN},
>       {"ip_vti0", 0},
>       {"ip6_vti0", 0},
>       {"ip6tnl0", 0},
>       {"ip6gre0", 0},
>       {"ip6gretap0", ETH_ALEN},
>       {"erspan0", ETH_ALEN},
>       {"bond0", ETH_ALEN},
>       {"veth0", ETH_ALEN},
>       {"veth1", ETH_ALEN},
>       {"team0", ETH_ALEN},
>       {"veth0_to_bridge", ETH_ALEN},
>       {"veth1_to_bridge", ETH_ALEN},
>       {"veth0_to_bond", ETH_ALEN},
>       {"veth1_to_bond", ETH_ALEN},
>       {"veth0_to_team", ETH_ALEN},
>       {"veth1_to_team", ETH_ALEN},
>       {"veth0_to_hsr", ETH_ALEN},
>       {"veth1_to_hsr", ETH_ALEN},
>       {"hsr0", 0},
>       {"dummy0", ETH_ALEN},
>       {"nlmon0", 0},
>       {"vxcan1", 0, true},
>       {"caif0", ETH_ALEN},
>       {"batadv0", ETH_ALEN},
>       {netdevsim, ETH_ALEN},
>   };
>   int sock = socket(AF_NETLINK, SOCK_RAW, NETLINK_ROUTE);
>   if (sock == -1)
>     exit(1);
>   unsigned i;
>   for (i = 0; i < sizeof(devtypes) / sizeof(devtypes[0]); i++)
>     netlink_add_device(sock, devtypes[i].type, devtypes[i].dev);
>   for (i = 0; i < sizeof(devmasters) / (sizeof(devmasters[0])); i++) {
>     char master[32], slave0[32], veth0[32], slave1[32], veth1[32];
>     sprintf(slave0, "%s_slave_0", devmasters[i]);
>     sprintf(veth0, "veth0_to_%s", devmasters[i]);
>     netlink_add_veth(sock, slave0, veth0);
>     sprintf(slave1, "%s_slave_1", devmasters[i]);
>     sprintf(veth1, "veth1_to_%s", devmasters[i]);
>     netlink_add_veth(sock, slave1, veth1);
>     sprintf(master, "%s0", devmasters[i]);
>     netlink_device_change(sock, slave0, false, master, 0, 0);
>     netlink_device_change(sock, slave1, false, master, 0, 0);
>   }
>   netlink_device_change(sock, "bridge_slave_0", true, 0, 0, 0);
>   netlink_device_change(sock, "bridge_slave_1", true, 0, 0, 0);
>   netlink_add_veth(sock, "hsr_slave_0", "veth0_to_hsr");
>   netlink_add_veth(sock, "hsr_slave_1", "veth1_to_hsr");
>   netlink_add_hsr(sock, "hsr0", "hsr_slave_0", "hsr_slave_1");
>   netlink_device_change(sock, "hsr_slave_0", true, 0, 0, 0);
>   netlink_device_change(sock, "hsr_slave_1", true, 0, 0, 0);
>   for (i = 0; i < sizeof(devices) / (sizeof(devices[0])); i++) {
>     char addr[32];
>     sprintf(addr, DEV_IPV4, i + 10);
>     netlink_add_addr4(sock, devices[i].name, addr);
>     if (!devices[i].noipv6) {
>       sprintf(addr, DEV_IPV6, i + 10);
>       netlink_add_addr6(sock, devices[i].name, addr);
>     }
>     uint64_t macaddr = DEV_MAC + ((i + 10ull) << 40);
>     netlink_device_change(sock, devices[i].name, true, 0, &macaddr,
>                           devices[i].macsize);
>   }
>   close(sock);
> }
> static void initialize_netdevices_init(void)
> {
>   int sock = socket(AF_NETLINK, SOCK_RAW, NETLINK_ROUTE);
>   if (sock == -1)
>     exit(1);
>   struct {
>     const char* type;
>     int macsize;
>     bool noipv6;
>     bool noup;
>   } devtypes[] = {
>       {"nr", 7, true}, {"rose", 5, true, true},
>   };
>   unsigned i;
>   for (i = 0; i < sizeof(devtypes) / sizeof(devtypes[0]); i++) {
>     char dev[32], addr[32];
>     sprintf(dev, "%s%d", devtypes[i].type, (int)procid);
>     sprintf(addr, "172.30.%d.%d", i, (int)procid + 1);
>     netlink_add_addr4(sock, dev, addr);
>     if (!devtypes[i].noipv6) {
>       sprintf(addr, "fe88::%02hx:%02hx", i, (int)procid + 1);
>       netlink_add_addr6(sock, dev, addr);
>     }
>     int macsize = devtypes[i].macsize;
>     uint64_t macaddr = 0xbbbbbb +
>                        ((unsigned long long)i << (8 * (macsize - 2))) +
>                        (procid << (8 * (macsize - 1)));
>     netlink_device_change(sock, dev, !devtypes[i].noup, 0, &macaddr,
> macsize);
>   }
>   close(sock);
> }
>
> static void setup_common()
> {
>   if (mount(0, "/sys/fs/fuse/connections", "fusectl", 0, 0)) {
>   }
> }
>
> static void loop();
>
> static void sandbox_common()
> {
>   prctl(PR_SET_PDEATHSIG, SIGKILL, 0, 0, 0);
>   setpgrp();
>   setsid();
>   struct rlimit rlim;
>   rlim.rlim_cur = rlim.rlim_max = 200 << 20;
>   setrlimit(RLIMIT_AS, &rlim);
>   rlim.rlim_cur = rlim.rlim_max = 32 << 20;
>   setrlimit(RLIMIT_MEMLOCK, &rlim);
>   rlim.rlim_cur = rlim.rlim_max = 136 << 20;
>   setrlimit(RLIMIT_FSIZE, &rlim);
>   rlim.rlim_cur = rlim.rlim_max = 1 << 20;
>   setrlimit(RLIMIT_STACK, &rlim);
>   rlim.rlim_cur = rlim.rlim_max = 0;
>   setrlimit(RLIMIT_CORE, &rlim);
>   rlim.rlim_cur = rlim.rlim_max = 256;
>   setrlimit(RLIMIT_NOFILE, &rlim);
>   if (unshare(CLONE_NEWNS)) {
>   }
>   if (unshare(CLONE_NEWIPC)) {
>   }
>   if (unshare(0x02000000)) {
>   }
>   if (unshare(CLONE_NEWUTS)) {
>   }
>   if (unshare(CLONE_SYSVSEM)) {
>   }
>   typedef struct {
>     const char* name;
>     const char* value;
>   } sysctl_t;
>   static const sysctl_t sysctls[] = {
>       {"/proc/sys/kernel/shmmax", "16777216"},
>       {"/proc/sys/kernel/shmall", "536870912"},
>       {"/proc/sys/kernel/shmmni", "1024"},
>       {"/proc/sys/kernel/msgmax", "8192"},
>       {"/proc/sys/kernel/msgmni", "1024"},
>       {"/proc/sys/kernel/msgmnb", "1024"},
>       {"/proc/sys/kernel/sem", "1024 1048576 500 1024"},
>   };
>   unsigned i;
>   for (i = 0; i < sizeof(sysctls) / sizeof(sysctls[0]); i++)
>     write_file(sysctls[i].name, sysctls[i].value);
> }
>
> int wait_for_loop(int pid)
> {
>   if (pid < 0)
>     exit(1);
>   int status = 0;
>   while (waitpid(-1, &status, __WALL) != pid) {
>   }
>   return WEXITSTATUS(status);
> }
>
> static int do_sandbox_none(void)
> {
>   if (unshare(CLONE_NEWPID)) {
>   }
>   int pid = fork();
>   if (pid != 0)
>     return wait_for_loop(pid);
>   setup_common();
>   sandbox_common();
>   initialize_netdevices_init();
>   if (unshare(CLONE_NEWNET)) {
>   }
>   initialize_netdevices();
>   loop();
>   exit(1);
> }
>
> #define FS_IOC_SETFLAGS _IOW('f', 2, long)
> static void remove_dir(const char* dir)
> {
>   DIR* dp;
>   struct dirent* ep;
>   int iter = 0;
> retry:
>   while (umount2(dir, MNT_DETACH) == 0) {
>   }
>   dp = opendir(dir);
>   if (dp == NULL) {
>     if (errno == EMFILE) {
>       exit(1);
>     }
>     exit(1);
>   }
>   while ((ep = readdir(dp))) {
>     if (strcmp(ep->d_name, ".") == 0 || strcmp(ep->d_name, "..") == 0)
>       continue;
>     char filename[FILENAME_MAX];
>     snprintf(filename, sizeof(filename), "%s/%s", dir, ep->d_name);
>     while (umount2(filename, MNT_DETACH) == 0) {
>     }
>     struct stat st;
>     if (lstat(filename, &st))
>       exit(1);
>     if (S_ISDIR(st.st_mode)) {
>       remove_dir(filename);
>       continue;
>     }
>     int i;
>     for (i = 0;; i++) {
>       if (unlink(filename) == 0)
>         break;
>       if (errno == EPERM) {
>         int fd = open(filename, O_RDONLY);
>         if (fd != -1) {
>           long flags = 0;
>           if (ioctl(fd, FS_IOC_SETFLAGS, &flags) == 0)
>             close(fd);
>           continue;
>         }
>       }
>       if (errno == EROFS) {
>         break;
>       }
>       if (errno != EBUSY || i > 100)
>         exit(1);
>       if (umount2(filename, MNT_DETACH))
>         exit(1);
>     }
>   }
>   closedir(dp);
>   int i;
>   for (i = 0;; i++) {
>     if (rmdir(dir) == 0)
>       break;
>     if (i < 100) {
>       if (errno == EPERM) {
>         int fd = open(dir, O_RDONLY);
>         if (fd != -1) {
>           long flags = 0;
>           if (ioctl(fd, FS_IOC_SETFLAGS, &flags) == 0)
>             close(fd);
>           continue;
>         }
>       }
>       if (errno == EROFS) {
>         break;
>       }
>       if (errno == EBUSY) {
>         if (umount2(dir, MNT_DETACH))
>           exit(1);
>         continue;
>       }
>       if (errno == ENOTEMPTY) {
>         if (iter < 100) {
>           iter++;
>           goto retry;
>         }
>       }
>     }
>     exit(1);
>   }
> }
>
> static void kill_and_wait(int pid, int* status)
> {
>   kill(-pid, SIGKILL);
>   kill(pid, SIGKILL);
>   int i;
>   for (i = 0; i < 100; i++) {
>     if (waitpid(-1, status, WNOHANG | __WALL) == pid)
>       return;
>     usleep(1000);
>   }
>   DIR* dir = opendir("/sys/fs/fuse/connections");
>   if (dir) {
>     for (;;) {
>       struct dirent* ent = readdir(dir);
>       if (!ent)
>         break;
>       if (strcmp(ent->d_name, ".") == 0 || strcmp(ent->d_name, "..") == 0)
>         continue;
>       char abort[300];
>       snprintf(abort, sizeof(abort), "/sys/fs/fuse/connections/%s/abort",
>                ent->d_name);
>       int fd = open(abort, O_WRONLY);
>       if (fd == -1) {
>         continue;
>       }
>       if (write(fd, abort, 1) < 0) {
>       }
>       close(fd);
>     }
>     closedir(dir);
>   } else {
>   }
>   while (waitpid(-1, status, __WALL) != pid) {
>   }
> }
>
> #define SYZ_HAVE_SETUP_TEST 1
> static void setup_test()
> {
>   prctl(PR_SET_PDEATHSIG, SIGKILL, 0, 0, 0);
>   setpgrp();
> }
>
> #define SYZ_HAVE_RESET_TEST 1
> static void reset_test()
> {
>   int fd;
>   for (fd = 3; fd < 30; fd++)
>     close(fd);
> }
>
> static void execute_one(void);
>
> #define WAIT_FLAGS __WALL
>
> static void loop(void)
> {
>   int iter;
>   for (iter = 0;; iter++) {
>     char cwdbuf[32];
>     sprintf(cwdbuf, "./%d", iter);
>     if (mkdir(cwdbuf, 0777))
>       exit(1);
>     int pid = fork();
>     if (pid < 0)
>       exit(1);
>     if (pid == 0) {
>       if (chdir(cwdbuf))
>         exit(1);
>       setup_test();
>       execute_one();
>       reset_test();
>       exit(0);
>     }
>     int status = 0;
>     uint64_t start = current_time_ms();
>     for (;;) {
>       if (waitpid(-1, &status, WNOHANG | WAIT_FLAGS) == pid)
>         break;
>       sleep_ms(1);
>       if (current_time_ms() - start < 5 * 1000)
>         continue;
>       kill_and_wait(pid, &status);
>       break;
>     }
>     remove_dir(cwdbuf);
>   }
> }
>
> void execute_one(void)
> {
>   syscall(__NR_unshare, 0x40000000);
> }
> int main(void)
> {
>   syscall(__NR_mmap, 0x20000000, 0x1000000, 3, 0x32, -1, 0);
>   for (procid = 0; procid < 8; procid++) {
>     if (fork() == 0) {
>       use_temporary_dir();
>       do_sandbox_none();
>     }
>   }
>   sleep(1000000);
>   return 0;
> }
>
>
> I reviewed kernel code and found a bug that
> net_drop_ns func doesn't call net_free func when refcount_dec_and_test's
> return value is zero.

Yes.  We don't call net_free when the reference count does not decrement
to zero.  The reference count is initialized to 1 a few lines above the
section of code in your patch so that should not be a problem.

> or
> when rv = down_read_killable(&pernet_ops_rwsem) < 0, it doesn't need to
> call refcount_dec_and_test.

It doesn't need to but it should be harmless.

> https://github.com/torvalds/linux/commit/5ba049a5cc8e24a1643df75bbf65b4efa070fa74#diff-9312644e2968a45510bacdd2b2872ad2
> (I can't reproduce this bug on v4.15 , and
> 1bdbe227492075d058e37cb3d400e6468d0095b5 with my patch. Because of the
> previous version of kernel doesn't have this bug.)
> This bug can lead to memory leak or DOS.
>
> I made a patch for this bug. (just revert to a before commit)

What am I missing?

The only thing I can see your patch doing is covering up a memory stomp
that has the effect of changing the value of net->passive.  I am not
really keen on hiding bugs of that kind.


> diff --git a/net/core/net_namespace.c b/net/core/net_namespace.c
> index b02fb19df2cc..9de0ade14956 100644
> --- a/net/core/net_namespace.c
> +++ b/net/core/net_namespace.c
> @@ -431,15 +431,18 @@ struct net *copy_net_ns(unsigned long flags,
>         get_user_ns(user_ns);
>
>         rv = down_read_killable(&pernet_ops_rwsem);
> -       if (rv < 0)
> -               goto put_userns;
> +       if (rv < 0){
> +        net_free(net);
> +        dec_net_namespaces(ucounts);
> +        put_user_ns(user_ns);
> +        return ERR_PTR(rv);
> +    }
>
>         rv = setup_net(net, user_ns);
>
>         up_read(&pernet_ops_rwsem);
>
>         if (rv < 0) {
> -put_userns:
>                 put_user_ns(user_ns);
>                 net_drop_ns(net);
>  dec_ucounts:
>
> and, sorry for my encrypted mails.

Eric
Kirill Tkhai Jan. 11, 2019, 8:41 p.m. | #2
On 11.01.2019 23:33, Eric W. Biederman wrote:
> zzoru <zzoru007@gmail.com> writes:
> 
>> net/core: BUG in copy_net_ns() (net_namespace.c)
> 
> I don't understand this failure report at all.
> 
> I don't see the connection to copy_net_ns().  And I don't see how the
> suggested patch short of covering up a memory stomp could possibly make
> a difference.
> 
> What am I missing?

I received 3 spam messages from this address today.
We can simply ignore this report.

> 
> 
>> Hello,
>>
>> I've got the following error report while fuzzing the kernel with syzkaller.
>>
>> On commit 1bdbe227492075d058e37cb3d400e6468d0095b5
>>
>> Syzkaller hit 'WARNING in __alloc_pages_slowpath' bug.
>>
>> syz-executor561 (17453) used greatest stack depth: 25056 bytes left
>> WARNING: CPU: 0 PID: 692 at mm/page_alloc.c:4415
>> __alloc_pages_slowpath+0x1cb1/0x2220 mm/page_alloc.c:4386
>> Kernel panic - not syncing: panic_on_warn set ...
>> CPU: 0 PID: 692 Comm: kswapd0 Not tainted 5.0.0-rc1+ #4
>> Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS
>> Ubuntu-1.8.2-1ubuntu1 04/01/2014
>> Call Trace:
>>  __dump_stack lib/dump_stack.c:77 [inline]
>>  dump_stack+0xca/0x13e lib/dump_stack.c:113
>>  panic+0x278/0x5bf kernel/panic.c:214
>>  __warn.cold.10+0x20/0x45 kernel/panic.c:571
>>  report_bug+0x246/0x2d0 lib/bug.c:186
>>  fixup_bug arch/x86/kernel/traps.c:178 [inline]
>>  do_error_trap+0x123/0x1e0 arch/x86/kernel/traps.c:271
>>  do_invalid_op+0x31/0x40 arch/x86/kernel/traps.c:290
>>  invalid_op+0x14/0x20 arch/x86/entry/entry_64.S:973
>> RIP: 0010:__alloc_pages_slowpath+0x1cb1/0x2220 mm/page_alloc.c:4415
>> Code: 8b 84 24 a8 00 00 00 e9 ea f1 ff ff 85 d2 0f 85 0b 01 00 00 48 c7
>> c7 c0 5e 55 84 e8 79 f8 23 02 e9 86 f9 ff ff 44 8b 74 24 0c <0f> 0b 48
>> b8 00 00 00 00 00 fc ff df 48 8b 54 24 18 48 c1 ea 03 80
>> RSP: 0018:ffff8880683fedb8 EFLAGS: 00010046
>> RAX: 0000000000000000 RBX: 0000000000000000 RCX: 1ffff1100d07fda4
>> RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff88807ffdd528
>> RBP: dffffc0000000000 R08: 0000000000000000 R09: 000000000000067a
>> R10: 0000000000000000 R11: ffff88807ffdc487 R12: 0000000000000000
>> R13: ffff8880683ff010 R14: 0000000000415a00 R15: ffff8880683ff010
>>  __alloc_pages_nodemask+0x521/0x5f0 mm/page_alloc.c:4555
>>  __alloc_pages include/linux/gfp.h:473 [inline]
>>  __alloc_pages_node include/linux/gfp.h:486 [inline]
>>  kmem_getpages mm/slab.c:1398 [inline]
>>  cache_grow_begin+0x95/0x300 mm/slab.c:2666
>>  fallback_alloc+0x1ce/0x270 mm/slab.c:3208
>>  __do_cache_alloc mm/slab.c:3345 [inline]
>>  slab_alloc mm/slab.c:3373 [inline]
>>  kmem_cache_alloc+0x286/0x2f0 mm/slab.c:3541
>>  create_object+0x83/0x880 mm/kmemleak.c:578
>>  kmemleak_alloc_recursive include/linux/kmemleak.h:55 [inline]
>>  slab_post_alloc_hook mm/slab.h:442 [inline]
>>  slab_alloc mm/slab.c:3381 [inline]
>>  kmem_cache_alloc+0x18f/0x2f0 mm/slab.c:3541
>>  mempool_alloc+0x13e/0x340 mm/mempool.c:385
>>  bio_alloc_bioset+0x36f/0x5d0 block/bio.c:489
>>  bio_alloc include/linux/bio.h:393 [inline]
>>  submit_bh_wbc.isra.57+0x128/0x680 fs/buffer.c:3061
>>  __block_write_full_page+0x6e8/0xcd0 fs/buffer.c:1765
>>  block_write_full_page+0x202/0x250 fs/buffer.c:2955
>>  pageout mm/vmscan.c:865 [inline]
>>  shrink_page_list+0x220f/0x3800 mm/vmscan.c:1383
>>  shrink_inactive_list+0x3c2/0xaa0 mm/vmscan.c:1961
>>  shrink_list mm/vmscan.c:2273 [inline]
>>  shrink_node_memcg.constprop.83+0x4bf/0x10e0 mm/vmscan.c:2538
>>  shrink_node+0x162/0xd10 mm/vmscan.c:2753
>>  kswapd_shrink_node mm/vmscan.c:3516 [inline]
>>  balance_pgdat+0x47f/0xc00 mm/vmscan.c:3674
>>  kswapd+0x57c/0xde0 mm/vmscan.c:3929
>>  kthread+0x347/0x410 kernel/kthread.c:246
>>  ret_from_fork+0x3a/0x50 arch/x86/entry/entry_64.S:352
>> Dumping ftrace buffer:
>>    (ftrace buffer empty)
>> Kernel Offset: disabled
>> Rebooting in 86400 seconds..
>>
>>
>> Syzkaller reproducer:
>> # {Threaded:false Collide:false Repeat:true RepeatTimes:0 Procs:8
>> Sandbox:none Fault:false FaultCall:-1 FaultNth:0 EnableTun:false
>> UseTmpDir:true EnableCgroups:false EnableNetdev:true ResetNet:false
>> HandleSegv:false Repro:false Trace:false}
>> unshare(0x40000000)
>>
>>
>> C reproducer:
>> // autogenerated by syzkaller (https://github.com/google/syzkaller)
>>
>> #define _GNU_SOURCE
>>
>> #include <arpa/inet.h>
>> #include <dirent.h>
>> #include <endian.h>
>> #include <errno.h>
>> #include <fcntl.h>
>> #include <net/if.h>
>> #include <net/if_arp.h>
>> #include <netinet/in.h>
>> #include <sched.h>
>> #include <signal.h>
>> #include <stdarg.h>
>> #include <stdbool.h>
>> #include <stdint.h>
>> #include <stdio.h>
>> #include <stdlib.h>
>> #include <string.h>
>> #include <sys/ioctl.h>
>> #include <sys/mount.h>
>> #include <sys/prctl.h>
>> #include <sys/resource.h>
>> #include <sys/socket.h>
>> #include <sys/stat.h>
>> #include <sys/syscall.h>
>> #include <sys/time.h>
>> #include <sys/types.h>
>> #include <sys/uio.h>
>> #include <sys/wait.h>
>> #include <time.h>
>> #include <unistd.h>
>>
>> #include <linux/if_addr.h>
>> #include <linux/if_ether.h>
>> #include <linux/if_link.h>
>> #include <linux/if_tun.h>
>> #include <linux/in6.h>
>> #include <linux/ip.h>
>> #include <linux/neighbour.h>
>> #include <linux/net.h>
>> #include <linux/netlink.h>
>> #include <linux/rtnetlink.h>
>> #include <linux/tcp.h>
>> #include <linux/veth.h>
>>
>> unsigned long long procid;
>>
>> static void sleep_ms(uint64_t ms)
>> {
>>   usleep(ms * 1000);
>> }
>>
>> static uint64_t current_time_ms(void)
>> {
>>   struct timespec ts;
>>   if (clock_gettime(CLOCK_MONOTONIC, &ts))
>>     exit(1);
>>   return (uint64_t)ts.tv_sec * 1000 + (uint64_t)ts.tv_nsec / 1000000;
>> }
>>
>> static void use_temporary_dir(void)
>> {
>>   char tmpdir_template[] = "./syzkaller.XXXXXX";
>>   char* tmpdir = mkdtemp(tmpdir_template);
>>   if (!tmpdir)
>>     exit(1);
>>   if (chmod(tmpdir, 0777))
>>     exit(1);
>>   if (chdir(tmpdir))
>>     exit(1);
>> }
>>
>> static bool write_file(const char* file, const char* what, ...)
>> {
>>   char buf[1024];
>>   va_list args;
>>   va_start(args, what);
>>   vsnprintf(buf, sizeof(buf), what, args);
>>   va_end(args);
>>   buf[sizeof(buf) - 1] = 0;
>>   int len = strlen(buf);
>>   int fd = open(file, O_WRONLY | O_CLOEXEC);
>>   if (fd == -1)
>>     return false;
>>   if (write(fd, buf, len) != len) {
>>     int err = errno;
>>     close(fd);
>>     errno = err;
>>     return false;
>>   }
>>   close(fd);
>>   return true;
>> }
>>
>> static struct {
>>   char* pos;
>>   int nesting;
>>   struct nlattr* nested[8];
>>   char buf[1024];
>> } nlmsg;
>>
>> static void netlink_init(int typ, int flags, const void* data, int size)
>> {
>>   memset(&nlmsg, 0, sizeof(nlmsg));
>>   struct nlmsghdr* hdr = (struct nlmsghdr*)nlmsg.buf;
>>   hdr->nlmsg_type = typ;
>>   hdr->nlmsg_flags = NLM_F_REQUEST | NLM_F_ACK | flags;
>>   memcpy(hdr + 1, data, size);
>>   nlmsg.pos = (char*)(hdr + 1) + NLMSG_ALIGN(size);
>> }
>>
>> static void netlink_attr(int typ, const void* data, int size)
>> {
>>   struct nlattr* attr = (struct nlattr*)nlmsg.pos;
>>   attr->nla_len = sizeof(*attr) + size;
>>   attr->nla_type = typ;
>>   memcpy(attr + 1, data, size);
>>   nlmsg.pos += NLMSG_ALIGN(attr->nla_len);
>> }
>>
>> static void netlink_nest(int typ)
>> {
>>   struct nlattr* attr = (struct nlattr*)nlmsg.pos;
>>   attr->nla_type = typ;
>>   nlmsg.pos += sizeof(*attr);
>>   nlmsg.nested[nlmsg.nesting++] = attr;
>> }
>>
>> static void netlink_done(void)
>> {
>>   struct nlattr* attr = nlmsg.nested[--nlmsg.nesting];
>>   attr->nla_len = nlmsg.pos - (char*)attr;
>> }
>>
>> static int netlink_send(int sock)
>> {
>>   if (nlmsg.pos > nlmsg.buf + sizeof(nlmsg.buf) || nlmsg.nesting)
>>     exit(1);
>>   struct nlmsghdr* hdr = (struct nlmsghdr*)nlmsg.buf;
>>   hdr->nlmsg_len = nlmsg.pos - nlmsg.buf;
>>   struct sockaddr_nl addr;
>>   memset(&addr, 0, sizeof(addr));
>>   addr.nl_family = AF_NETLINK;
>>   unsigned n = sendto(sock, nlmsg.buf, hdr->nlmsg_len, 0,
>>                       (struct sockaddr*)&addr, sizeof(addr));
>>   if (n != hdr->nlmsg_len)
>>     exit(1);
>>   n = recv(sock, nlmsg.buf, sizeof(nlmsg.buf), 0);
>>   if (n < sizeof(struct nlmsghdr) + sizeof(struct nlmsgerr))
>>     exit(1);
>>   if (hdr->nlmsg_type != NLMSG_ERROR)
>>     exit(1);
>>   return -((struct nlmsgerr*)(hdr + 1))->error;
>> }
>>
>> static void netlink_add_device_impl(const char* type, const char* name)
>> {
>>   struct ifinfomsg hdr;
>>   memset(&hdr, 0, sizeof(hdr));
>>   netlink_init(RTM_NEWLINK, NLM_F_EXCL | NLM_F_CREATE, &hdr, sizeof(hdr));
>>   if (name)
>>     netlink_attr(IFLA_IFNAME, name, strlen(name));
>>   netlink_nest(IFLA_LINKINFO);
>>   netlink_attr(IFLA_INFO_KIND, type, strlen(type));
>> }
>>
>> static void netlink_add_device(int sock, const char* type, const char* name)
>> {
>>   netlink_add_device_impl(type, name);
>>   netlink_done();
>>   int err = netlink_send(sock);
>>   (void)err;
>> }
>>
>> static void netlink_add_veth(int sock, const char* name, const char* peer)
>> {
>>   netlink_add_device_impl("veth", name);
>>   netlink_nest(IFLA_INFO_DATA);
>>   netlink_nest(VETH_INFO_PEER);
>>   nlmsg.pos += sizeof(struct ifinfomsg);
>>   netlink_attr(IFLA_IFNAME, peer, strlen(peer));
>>   netlink_done();
>>   netlink_done();
>>   netlink_done();
>>   int err = netlink_send(sock);
>>   (void)err;
>> }
>>
>> static void netlink_add_hsr(int sock, const char* name, const char* slave1,
>>                             const char* slave2)
>> {
>>   netlink_add_device_impl("hsr", name);
>>   netlink_nest(IFLA_INFO_DATA);
>>   int ifindex1 = if_nametoindex(slave1);
>>   netlink_attr(IFLA_HSR_SLAVE1, &ifindex1, sizeof(ifindex1));
>>   int ifindex2 = if_nametoindex(slave2);
>>   netlink_attr(IFLA_HSR_SLAVE2, &ifindex2, sizeof(ifindex2));
>>   netlink_done();
>>   netlink_done();
>>   int err = netlink_send(sock);
>>   (void)err;
>> }
>>
>> static void netlink_device_change(int sock, const char* name, bool up,
>>                                   const char* master, const void* mac,
>>                                   int macsize)
>> {
>>   struct ifinfomsg hdr;
>>   memset(&hdr, 0, sizeof(hdr));
>>   if (up)
>>     hdr.ifi_flags = hdr.ifi_change = IFF_UP;
>>   netlink_init(RTM_NEWLINK, 0, &hdr, sizeof(hdr));
>>   netlink_attr(IFLA_IFNAME, name, strlen(name));
>>   if (master) {
>>     int ifindex = if_nametoindex(master);
>>     netlink_attr(IFLA_MASTER, &ifindex, sizeof(ifindex));
>>   }
>>   if (macsize)
>>     netlink_attr(IFLA_ADDRESS, mac, macsize);
>>   int err = netlink_send(sock);
>>   (void)err;
>> }
>>
>> static int netlink_add_addr(int sock, const char* dev, const void* addr,
>>                             int addrsize)
>> {
>>   struct ifaddrmsg hdr;
>>   memset(&hdr, 0, sizeof(hdr));
>>   hdr.ifa_family = addrsize == 4 ? AF_INET : AF_INET6;
>>   hdr.ifa_prefixlen = addrsize == 4 ? 24 : 120;
>>   hdr.ifa_scope = RT_SCOPE_UNIVERSE;
>>   hdr.ifa_index = if_nametoindex(dev);
>>   netlink_init(RTM_NEWADDR, NLM_F_CREATE | NLM_F_REPLACE, &hdr,
>> sizeof(hdr));
>>   netlink_attr(IFA_LOCAL, addr, addrsize);
>>   netlink_attr(IFA_ADDRESS, addr, addrsize);
>>   return netlink_send(sock);
>> }
>>
>> static void netlink_add_addr4(int sock, const char* dev, const char* addr)
>> {
>>   struct in_addr in_addr;
>>   inet_pton(AF_INET, addr, &in_addr);
>>   int err = netlink_add_addr(sock, dev, &in_addr, sizeof(in_addr));
>>   (void)err;
>> }
>>
>> static void netlink_add_addr6(int sock, const char* dev, const char* addr)
>> {
>>   struct in6_addr in6_addr;
>>   inet_pton(AF_INET6, addr, &in6_addr);
>>   int err = netlink_add_addr(sock, dev, &in6_addr, sizeof(in6_addr));
>>   (void)err;
>> }
>>
>> #define DEV_IPV4 "172.20.20.%d"
>> #define DEV_IPV6 "fe80::%02hx"
>> #define DEV_MAC 0x00aaaaaaaaaa
>> static void initialize_netdevices(void)
>> {
>>   char netdevsim[16];
>>   sprintf(netdevsim, "netdevsim%d", (int)procid);
>>   struct {
>>     const char* type;
>>     const char* dev;
>>   } devtypes[] = {
>>       {"ip6gretap", "ip6gretap0"}, {"bridge", "bridge0"},
>>       {"vcan", "vcan0"},           {"bond", "bond0"},
>>       {"team", "team0"},           {"dummy", "dummy0"},
>>       {"nlmon", "nlmon0"},         {"caif", "caif0"},
>>       {"batadv", "batadv0"},       {"vxcan", "vxcan1"},
>>       {"netdevsim", netdevsim},    {"veth", 0},
>>   };
>>   const char* devmasters[] = {"bridge", "bond", "team"};
>>   struct {
>>     const char* name;
>>     int macsize;
>>     bool noipv6;
>>   } devices[] = {
>>       {"lo", ETH_ALEN},
>>       {"sit0", 0},
>>       {"bridge0", ETH_ALEN},
>>       {"vcan0", 0, true},
>>       {"tunl0", 0},
>>       {"gre0", 0},
>>       {"gretap0", ETH_ALEN},
>>       {"ip_vti0", 0},
>>       {"ip6_vti0", 0},
>>       {"ip6tnl0", 0},
>>       {"ip6gre0", 0},
>>       {"ip6gretap0", ETH_ALEN},
>>       {"erspan0", ETH_ALEN},
>>       {"bond0", ETH_ALEN},
>>       {"veth0", ETH_ALEN},
>>       {"veth1", ETH_ALEN},
>>       {"team0", ETH_ALEN},
>>       {"veth0_to_bridge", ETH_ALEN},
>>       {"veth1_to_bridge", ETH_ALEN},
>>       {"veth0_to_bond", ETH_ALEN},
>>       {"veth1_to_bond", ETH_ALEN},
>>       {"veth0_to_team", ETH_ALEN},
>>       {"veth1_to_team", ETH_ALEN},
>>       {"veth0_to_hsr", ETH_ALEN},
>>       {"veth1_to_hsr", ETH_ALEN},
>>       {"hsr0", 0},
>>       {"dummy0", ETH_ALEN},
>>       {"nlmon0", 0},
>>       {"vxcan1", 0, true},
>>       {"caif0", ETH_ALEN},
>>       {"batadv0", ETH_ALEN},
>>       {netdevsim, ETH_ALEN},
>>   };
>>   int sock = socket(AF_NETLINK, SOCK_RAW, NETLINK_ROUTE);
>>   if (sock == -1)
>>     exit(1);
>>   unsigned i;
>>   for (i = 0; i < sizeof(devtypes) / sizeof(devtypes[0]); i++)
>>     netlink_add_device(sock, devtypes[i].type, devtypes[i].dev);
>>   for (i = 0; i < sizeof(devmasters) / (sizeof(devmasters[0])); i++) {
>>     char master[32], slave0[32], veth0[32], slave1[32], veth1[32];
>>     sprintf(slave0, "%s_slave_0", devmasters[i]);
>>     sprintf(veth0, "veth0_to_%s", devmasters[i]);
>>     netlink_add_veth(sock, slave0, veth0);
>>     sprintf(slave1, "%s_slave_1", devmasters[i]);
>>     sprintf(veth1, "veth1_to_%s", devmasters[i]);
>>     netlink_add_veth(sock, slave1, veth1);
>>     sprintf(master, "%s0", devmasters[i]);
>>     netlink_device_change(sock, slave0, false, master, 0, 0);
>>     netlink_device_change(sock, slave1, false, master, 0, 0);
>>   }
>>   netlink_device_change(sock, "bridge_slave_0", true, 0, 0, 0);
>>   netlink_device_change(sock, "bridge_slave_1", true, 0, 0, 0);
>>   netlink_add_veth(sock, "hsr_slave_0", "veth0_to_hsr");
>>   netlink_add_veth(sock, "hsr_slave_1", "veth1_to_hsr");
>>   netlink_add_hsr(sock, "hsr0", "hsr_slave_0", "hsr_slave_1");
>>   netlink_device_change(sock, "hsr_slave_0", true, 0, 0, 0);
>>   netlink_device_change(sock, "hsr_slave_1", true, 0, 0, 0);
>>   for (i = 0; i < sizeof(devices) / (sizeof(devices[0])); i++) {
>>     char addr[32];
>>     sprintf(addr, DEV_IPV4, i + 10);
>>     netlink_add_addr4(sock, devices[i].name, addr);
>>     if (!devices[i].noipv6) {
>>       sprintf(addr, DEV_IPV6, i + 10);
>>       netlink_add_addr6(sock, devices[i].name, addr);
>>     }
>>     uint64_t macaddr = DEV_MAC + ((i + 10ull) << 40);
>>     netlink_device_change(sock, devices[i].name, true, 0, &macaddr,
>>                           devices[i].macsize);
>>   }
>>   close(sock);
>> }
>> static void initialize_netdevices_init(void)
>> {
>>   int sock = socket(AF_NETLINK, SOCK_RAW, NETLINK_ROUTE);
>>   if (sock == -1)
>>     exit(1);
>>   struct {
>>     const char* type;
>>     int macsize;
>>     bool noipv6;
>>     bool noup;
>>   } devtypes[] = {
>>       {"nr", 7, true}, {"rose", 5, true, true},
>>   };
>>   unsigned i;
>>   for (i = 0; i < sizeof(devtypes) / sizeof(devtypes[0]); i++) {
>>     char dev[32], addr[32];
>>     sprintf(dev, "%s%d", devtypes[i].type, (int)procid);
>>     sprintf(addr, "172.30.%d.%d", i, (int)procid + 1);
>>     netlink_add_addr4(sock, dev, addr);
>>     if (!devtypes[i].noipv6) {
>>       sprintf(addr, "fe88::%02hx:%02hx", i, (int)procid + 1);
>>       netlink_add_addr6(sock, dev, addr);
>>     }
>>     int macsize = devtypes[i].macsize;
>>     uint64_t macaddr = 0xbbbbbb +
>>                        ((unsigned long long)i << (8 * (macsize - 2))) +
>>                        (procid << (8 * (macsize - 1)));
>>     netlink_device_change(sock, dev, !devtypes[i].noup, 0, &macaddr,
>> macsize);
>>   }
>>   close(sock);
>> }
>>
>> static void setup_common()
>> {
>>   if (mount(0, "/sys/fs/fuse/connections", "fusectl", 0, 0)) {
>>   }
>> }
>>
>> static void loop();
>>
>> static void sandbox_common()
>> {
>>   prctl(PR_SET_PDEATHSIG, SIGKILL, 0, 0, 0);
>>   setpgrp();
>>   setsid();
>>   struct rlimit rlim;
>>   rlim.rlim_cur = rlim.rlim_max = 200 << 20;
>>   setrlimit(RLIMIT_AS, &rlim);
>>   rlim.rlim_cur = rlim.rlim_max = 32 << 20;
>>   setrlimit(RLIMIT_MEMLOCK, &rlim);
>>   rlim.rlim_cur = rlim.rlim_max = 136 << 20;
>>   setrlimit(RLIMIT_FSIZE, &rlim);
>>   rlim.rlim_cur = rlim.rlim_max = 1 << 20;
>>   setrlimit(RLIMIT_STACK, &rlim);
>>   rlim.rlim_cur = rlim.rlim_max = 0;
>>   setrlimit(RLIMIT_CORE, &rlim);
>>   rlim.rlim_cur = rlim.rlim_max = 256;
>>   setrlimit(RLIMIT_NOFILE, &rlim);
>>   if (unshare(CLONE_NEWNS)) {
>>   }
>>   if (unshare(CLONE_NEWIPC)) {
>>   }
>>   if (unshare(0x02000000)) {
>>   }
>>   if (unshare(CLONE_NEWUTS)) {
>>   }
>>   if (unshare(CLONE_SYSVSEM)) {
>>   }
>>   typedef struct {
>>     const char* name;
>>     const char* value;
>>   } sysctl_t;
>>   static const sysctl_t sysctls[] = {
>>       {"/proc/sys/kernel/shmmax", "16777216"},
>>       {"/proc/sys/kernel/shmall", "536870912"},
>>       {"/proc/sys/kernel/shmmni", "1024"},
>>       {"/proc/sys/kernel/msgmax", "8192"},
>>       {"/proc/sys/kernel/msgmni", "1024"},
>>       {"/proc/sys/kernel/msgmnb", "1024"},
>>       {"/proc/sys/kernel/sem", "1024 1048576 500 1024"},
>>   };
>>   unsigned i;
>>   for (i = 0; i < sizeof(sysctls) / sizeof(sysctls[0]); i++)
>>     write_file(sysctls[i].name, sysctls[i].value);
>> }
>>
>> int wait_for_loop(int pid)
>> {
>>   if (pid < 0)
>>     exit(1);
>>   int status = 0;
>>   while (waitpid(-1, &status, __WALL) != pid) {
>>   }
>>   return WEXITSTATUS(status);
>> }
>>
>> static int do_sandbox_none(void)
>> {
>>   if (unshare(CLONE_NEWPID)) {
>>   }
>>   int pid = fork();
>>   if (pid != 0)
>>     return wait_for_loop(pid);
>>   setup_common();
>>   sandbox_common();
>>   initialize_netdevices_init();
>>   if (unshare(CLONE_NEWNET)) {
>>   }
>>   initialize_netdevices();
>>   loop();
>>   exit(1);
>> }
>>
>> #define FS_IOC_SETFLAGS _IOW('f', 2, long)
>> static void remove_dir(const char* dir)
>> {
>>   DIR* dp;
>>   struct dirent* ep;
>>   int iter = 0;
>> retry:
>>   while (umount2(dir, MNT_DETACH) == 0) {
>>   }
>>   dp = opendir(dir);
>>   if (dp == NULL) {
>>     if (errno == EMFILE) {
>>       exit(1);
>>     }
>>     exit(1);
>>   }
>>   while ((ep = readdir(dp))) {
>>     if (strcmp(ep->d_name, ".") == 0 || strcmp(ep->d_name, "..") == 0)
>>       continue;
>>     char filename[FILENAME_MAX];
>>     snprintf(filename, sizeof(filename), "%s/%s", dir, ep->d_name);
>>     while (umount2(filename, MNT_DETACH) == 0) {
>>     }
>>     struct stat st;
>>     if (lstat(filename, &st))
>>       exit(1);
>>     if (S_ISDIR(st.st_mode)) {
>>       remove_dir(filename);
>>       continue;
>>     }
>>     int i;
>>     for (i = 0;; i++) {
>>       if (unlink(filename) == 0)
>>         break;
>>       if (errno == EPERM) {
>>         int fd = open(filename, O_RDONLY);
>>         if (fd != -1) {
>>           long flags = 0;
>>           if (ioctl(fd, FS_IOC_SETFLAGS, &flags) == 0)
>>             close(fd);
>>           continue;
>>         }
>>       }
>>       if (errno == EROFS) {
>>         break;
>>       }
>>       if (errno != EBUSY || i > 100)
>>         exit(1);
>>       if (umount2(filename, MNT_DETACH))
>>         exit(1);
>>     }
>>   }
>>   closedir(dp);
>>   int i;
>>   for (i = 0;; i++) {
>>     if (rmdir(dir) == 0)
>>       break;
>>     if (i < 100) {
>>       if (errno == EPERM) {
>>         int fd = open(dir, O_RDONLY);
>>         if (fd != -1) {
>>           long flags = 0;
>>           if (ioctl(fd, FS_IOC_SETFLAGS, &flags) == 0)
>>             close(fd);
>>           continue;
>>         }
>>       }
>>       if (errno == EROFS) {
>>         break;
>>       }
>>       if (errno == EBUSY) {
>>         if (umount2(dir, MNT_DETACH))
>>           exit(1);
>>         continue;
>>       }
>>       if (errno == ENOTEMPTY) {
>>         if (iter < 100) {
>>           iter++;
>>           goto retry;
>>         }
>>       }
>>     }
>>     exit(1);
>>   }
>> }
>>
>> static void kill_and_wait(int pid, int* status)
>> {
>>   kill(-pid, SIGKILL);
>>   kill(pid, SIGKILL);
>>   int i;
>>   for (i = 0; i < 100; i++) {
>>     if (waitpid(-1, status, WNOHANG | __WALL) == pid)
>>       return;
>>     usleep(1000);
>>   }
>>   DIR* dir = opendir("/sys/fs/fuse/connections");
>>   if (dir) {
>>     for (;;) {
>>       struct dirent* ent = readdir(dir);
>>       if (!ent)
>>         break;
>>       if (strcmp(ent->d_name, ".") == 0 || strcmp(ent->d_name, "..") == 0)
>>         continue;
>>       char abort[300];
>>       snprintf(abort, sizeof(abort), "/sys/fs/fuse/connections/%s/abort",
>>                ent->d_name);
>>       int fd = open(abort, O_WRONLY);
>>       if (fd == -1) {
>>         continue;
>>       }
>>       if (write(fd, abort, 1) < 0) {
>>       }
>>       close(fd);
>>     }
>>     closedir(dir);
>>   } else {
>>   }
>>   while (waitpid(-1, status, __WALL) != pid) {
>>   }
>> }
>>
>> #define SYZ_HAVE_SETUP_TEST 1
>> static void setup_test()
>> {
>>   prctl(PR_SET_PDEATHSIG, SIGKILL, 0, 0, 0);
>>   setpgrp();
>> }
>>
>> #define SYZ_HAVE_RESET_TEST 1
>> static void reset_test()
>> {
>>   int fd;
>>   for (fd = 3; fd < 30; fd++)
>>     close(fd);
>> }
>>
>> static void execute_one(void);
>>
>> #define WAIT_FLAGS __WALL
>>
>> static void loop(void)
>> {
>>   int iter;
>>   for (iter = 0;; iter++) {
>>     char cwdbuf[32];
>>     sprintf(cwdbuf, "./%d", iter);
>>     if (mkdir(cwdbuf, 0777))
>>       exit(1);
>>     int pid = fork();
>>     if (pid < 0)
>>       exit(1);
>>     if (pid == 0) {
>>       if (chdir(cwdbuf))
>>         exit(1);
>>       setup_test();
>>       execute_one();
>>       reset_test();
>>       exit(0);
>>     }
>>     int status = 0;
>>     uint64_t start = current_time_ms();
>>     for (;;) {
>>       if (waitpid(-1, &status, WNOHANG | WAIT_FLAGS) == pid)
>>         break;
>>       sleep_ms(1);
>>       if (current_time_ms() - start < 5 * 1000)
>>         continue;
>>       kill_and_wait(pid, &status);
>>       break;
>>     }
>>     remove_dir(cwdbuf);
>>   }
>> }
>>
>> void execute_one(void)
>> {
>>   syscall(__NR_unshare, 0x40000000);
>> }
>> int main(void)
>> {
>>   syscall(__NR_mmap, 0x20000000, 0x1000000, 3, 0x32, -1, 0);
>>   for (procid = 0; procid < 8; procid++) {
>>     if (fork() == 0) {
>>       use_temporary_dir();
>>       do_sandbox_none();
>>     }
>>   }
>>   sleep(1000000);
>>   return 0;
>> }
>>
>>
>> I reviewed kernel code and found a bug that
>> net_drop_ns func doesn't call net_free func when refcount_dec_and_test's
>> return value is zero.
> 
> Yes.  We don't call net_free when the reference count does not decrement
> to zero.  The reference count is initialized to 1 a few lines above the
> section of code in your patch so that should not be a problem.
> 
>> or
>> when rv = down_read_killable(&pernet_ops_rwsem) < 0, it doesn't need to
>> call refcount_dec_and_test.
> 
> It doesn't need to but it should be harmless.
> 
>> https://github.com/torvalds/linux/commit/5ba049a5cc8e24a1643df75bbf65b4efa070fa74#diff-9312644e2968a45510bacdd2b2872ad2
>> (I can't reproduce this bug on v4.15 , and
>> 1bdbe227492075d058e37cb3d400e6468d0095b5 with my patch. Because of the
>> previous version of kernel doesn't have this bug.)
>> This bug can lead to memory leak or DOS.
>>
>> I made a patch for this bug. (just revert to a before commit)
> 
> What am I missing?
> 
> The only thing I can see your patch doing is covering up a memory stomp
> that has the effect of changing the value of net->passive.  I am not
> really keen on hiding bugs of that kind.
> 
> 
>> diff --git a/net/core/net_namespace.c b/net/core/net_namespace.c
>> index b02fb19df2cc..9de0ade14956 100644
>> --- a/net/core/net_namespace.c
>> +++ b/net/core/net_namespace.c
>> @@ -431,15 +431,18 @@ struct net *copy_net_ns(unsigned long flags,
>>         get_user_ns(user_ns);
>>
>>         rv = down_read_killable(&pernet_ops_rwsem);
>> -       if (rv < 0)
>> -               goto put_userns;
>> +       if (rv < 0){
>> +        net_free(net);
>> +        dec_net_namespaces(ucounts);
>> +        put_user_ns(user_ns);
>> +        return ERR_PTR(rv);
>> +    }
>>
>>         rv = setup_net(net, user_ns);
>>
>>         up_read(&pernet_ops_rwsem);
>>
>>         if (rv < 0) {
>> -put_userns:
>>                 put_user_ns(user_ns);
>>                 net_drop_ns(net);
>>  dec_ucounts:
>>
>> and, sorry for my encrypted mails.
> 
> Eric
>
zzoru Jan. 11, 2019, 11:31 p.m. | #3
> I received 3 spam messages from this address today.
> We can simply ignore this report.
I already mentioned about this.

> and, sorry for my encrypted mails.
> I don't understand this failure report at all.
>
> I don't see the connection to copy_net_ns().  And I don't see how the
> suggested patch short of covering up a memory stomp could possibly make
> a difference.
>
> What am I missing?
> void execute_one(void)
> {
>   syscall(__NR_unshare, 0x40000000);
> }
ksys_unshare -> unshare_nsproxy_namespaces -> create_new_namespaces ->
copy_net_ns
unshare(CLONE_NEWNET) calls copy_net_ns() (It requires the CAP_SYS_ADMIN
capability)

I made many error reports about this bug, and the other one is

[   90.289025] WARNING: CPU: 1 PID: 1732 at mm/page_alloc.c:4415
__alloc_pages_slowpath+0x1cb1/0x2220
[   90.290223] Modules linked in:
[   90.290639] CPU: 1 PID: 1732 Comm: kworker/u4:5 Not tainted 5.0.0-rc1+ #6
[   90.291475] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996),
BIOS Ubuntu-1.8.2-1ubuntu1 04/01/2014
[   90.292681] Workqueue: writeback wb_workfn (flush-8:0)
[   90.293350] RIP: 0010:__alloc_pages_slowpath+0x1cb1/0x2220
[   90.294075] Code: 8b 84 24 a8 00 00 00 e9 ea f1 ff ff 85 d2 0f 85 0b
01 00 00 48 c7 c7 c0 5e 55 84 e8 79 f8 23 02 e9 86 f9 ff ff 44 8b 74 24
0c <0f> 0b 48 b8 00 00 00 00 00 fc ff df 48 8b 54 24 18 48 c1 ea 03 80
[   90.296527] RSP: 0018:ffff888064276dd8 EFLAGS: 00010046
[   90.297203] RAX: 0000000000000000 RBX: 0000000000000000 RCX:
1ffff1100c84eda8
[   90.297784] kmemleak: Cannot allocate a kmemleak_object structure
[   90.298186] RDX: 0000000000000000 RSI: 0000000000000000 RDI:
ffff88807ffdd528
[   90.298242] RBP: dffffc0000000000 R08: 0000000000000000 R09:
0000000000000679
[   90.298247] R10: 0000000000000000 R11: ffff88807ffdc487 R12:
0000000000000000
[   90.298251] R13: ffff888064277030 R14: 0000000000415a00 R15:
ffff888064277030
[   90.298257] FS:  0000000000000000(0000) GS:ffff88806d500000(0000)
knlGS:0000000000000000
[   90.298262] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[   90.298267] CR2: 00007fff6ac6a718 CR3: 0000000056578000 CR4:
00000000000006e0
[   90.298272] Call Trace:
[   90.298283]  ? __alloc_pages_slowpath+0x1ce6/0x2220
[   90.298299]  ? warn_alloc+0x120/0x120
[   90.302432] kmemleak: Kernel memory leak detector disabled
[   90.303346]  ? lock_acquire+0x103/0x2e0
[   90.303358]  ? __isolate_free_page+0x4b0/0x4b0
[   90.303366]  ? __lock_is_held+0xad/0x140
[   90.303377]  __alloc_pages_nodemask+0x521/0x5f0
[   90.303386]  ? __alloc_pages_slowpath+0x2220/0x2220
[   90.315010]  cache_grow_begin+0x95/0x300
[   90.315613]  fallback_alloc+0x1ce/0x270
[   90.316211]  ? mempool_free+0x360/0x360
[   90.316767]  kmem_cache_alloc+0x286/0x2f0
[   90.317348]  ? mempool_free+0x360/0x360
[   90.317919]  create_object+0x83/0x880
[   90.318517]  ? kmemleak_disable+0x90/0x90
[   90.319103]  ? mark_held_locks+0xc1/0x140
[   90.319679]  ? kmem_cache_alloc+0x9c/0x2f0
[   90.320307]  ? mempool_free+0x360/0x360
[   90.320900]  kmem_cache_alloc+0x18f/0x2f0
[   90.321650]  ? mempool_free+0x360/0x360
[   90.322228]  mempool_alloc+0x13e/0x340
[   90.322765]  ? mempool_destroy+0x30/0x30
[   90.323370]  ? mark_held_locks+0xc1/0x140
[   90.323993]  ? _raw_spin_unlock_irqrestore+0x3e/0x50
[   90.324786]  bio_alloc_bioset+0x36f/0x5d0
[   90.325397]  ? __test_set_page_writeback+0x136/0x960
[   90.326161]  ? bvec_alloc+0x2d0/0x2d0
[   90.326708]  ? wait_for_stable_page+0x290/0x290
[   90.327392]  submit_bh_wbc.isra.57+0x128/0x680
[   90.328053]  ? create_page_buffers+0x111/0x200
[   90.328685]  __block_write_full_page+0x6e8/0xcd0
[   90.329339]  ? check_disk_change+0x130/0x130
[   90.329966]  block_write_full_page+0x202/0x250
[   90.330675]  ? check_disk_change+0x130/0x130
[   90.331291]  __writepage+0x62/0xe0
[   90.331786]  write_cache_pages+0x5b8/0xf60
[   90.332375]  ? __wb_calc_thresh+0x290/0x290
[   90.332976]  ? clear_page_dirty_for_io+0x5c0/0x5c0
[   90.333686]  ? mark_held_locks+0x140/0x140
[   90.334301]  ? print_circular_bug_entry+0x1f/0x60
[   90.334999]  ? __lock_acquire+0x5d6/0x4630
[   90.335621]  generic_writepages+0xda/0x150
[   90.336243]  ? write_cache_pages+0xf60/0xf60
[   90.336852]  ? mark_held_locks+0x140/0x140
[   90.337453]  ? blkdev_readpages+0x30/0x30
[   90.338020]  do_writepages+0xf0/0x290
[   90.338611]  ? page_writeback_cpu_online+0x10/0x10
[   90.339324]  ? __lock_is_held+0xad/0x140
[   90.339900]  __writeback_single_inode+0xf3/0x1000
[   90.340587]  writeback_sb_inodes+0x4e7/0xce0
[   90.341214]  ? __writeback_single_inode+0x1000/0x1000
[   90.341929]  ? down_read_trylock+0x5b/0x90
[   90.342579]  ? trylock_super+0x1d/0x100
[   90.343162]  __writeback_inodes_wb+0x109/0x220
[   90.343799]  wb_writeback+0x7a1/0xb90
[   90.344347]  ? writeback_inodes_wb.constprop.44+0x190/0x190
[   90.345143]  ? cpumask_next+0x1f/0x30
[   90.345679]  ? find_next_bit+0x101/0x130
[   90.346281]  ? get_nr_dirty_inodes+0xd0/0x130
[   90.346909]  wb_workfn+0x921/0xec0
[   90.347397]  ? process_one_work+0xadd/0x1bb0
[   90.348025]  ? inode_wait_for_writeback+0x30/0x30
[   90.348700]  process_one_work+0xbbd/0x1bb0
[   90.349314]  ? max_active_store+0x130/0x130
[   90.349915]  ? do_raw_spin_lock+0x11b/0x280
[   90.350557]  worker_thread+0x8c/0x1060
[   90.351096]  ? __kthread_parkme+0xf8/0x1a0
[   90.351673]  ? process_one_work+0x1bb0/0x1bb0
[   90.352334]  kthread+0x347/0x410
[   90.352798]  ? kthread_create_worker_on_cpu+0xe0/0xe0
[   90.353509]  ret_from_fork+0x3a/0x50
[   90.354020] irq event stamp: 282384
[   90.354590] hardirqs last  enabled at (282383): [<ffffffff8160678c>]
kmem_cache_alloc+0x9c/0x2f0
[   90.355832] hardirqs last disabled at (282384): [<ffffffff8160674d>]
kmem_cache_alloc+0x5d/0x2f0
[   90.357066] softirqs last  enabled at (282196): [<ffffffff816daa87>]
wb_workfn+0x387/0xec0
[   90.358280] softirqs last disabled at (282194): [<ffffffff816da918>]
wb_workfn+0x218/0xec0
[   90.359426] ---[ end trace 71c4462c6227f0d8 ]---
[   90.360135] kmemleak: Cannot allocate a kmemleak_object structure
[   90.888624] a.out invoked oom-killer:
gfp_mask=0x6040d0(GFP_KERNEL|__GFP_COMP|__GFP_RECLAIMABLE), order=0,
oom_score_adj=0
[   90.890564] CPU: 0 PID: 22248 Comm: a.out Tainted: G        W        
5.0.0-rc1+ #6
[   90.891793] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996),
BIOS Ubuntu-1.8.2-1ubuntu1 04/01/2014
[   90.893263] Call Trace:
[   90.893678]  dump_stack+0xca/0x13e
[   90.894242]  dump_header+0x108/0xaef
[   90.894822]  ? ___ratelimit+0x5b/0x436
[   90.895430]  oom_kill_process.cold.38+0x10/0xa87
[   90.896164]  ? lock_downgrade+0x5d0/0x5d0
[   90.896806]  ? _raw_spin_unlock+0x1f/0x30
[   90.897445]  ? oom_badness+0xc8/0x770
[   90.898045]  out_of_memory+0x32a/0x1ab0
[   90.898668]  ? oom_killer_disable+0x280/0x280
[   90.899365]  ? mutex_trylock+0x162/0x1a0
[   90.899998]  __alloc_pages_slowpath+0x1b7a/0x2220
[   90.900754]  ? warn_alloc+0x120/0x120
[   90.901344]  ? find_held_lock+0x33/0x1c0
[   90.901985]  __alloc_pages_nodemask+0x521/0x5f0
[   90.902723]  ? __alloc_pages_slowpath+0x2220/0x2220
[   90.903499]  ? mark_held_locks+0xc1/0x140
[   90.904137]  ? cache_grow_begin+0x28f/0x300
[   90.904807]  cache_grow_begin+0x95/0x300
[   90.905443]  fallback_alloc+0x1ce/0x270
[   90.906074]  kmem_cache_alloc+0x286/0x2f0
[   90.906720]  ? sock_destroy_inode+0x60/0x60
[   90.907392]  sock_alloc_inode+0x18/0x250
[   90.908021]  ? sock_destroy_inode+0x60/0x60
[   90.908690]  alloc_inode+0x5e/0x180
[   90.909254]  new_inode_pseudo+0x12/0xd0
[   90.909868]  sock_alloc+0x3c/0x270
[   90.910428]  __sock_create+0xbe/0x740
[   90.911026]  inet_ctl_sock_create+0x8c/0x1e0
[   90.911710]  ? inet_current_timestamp+0xc0/0xc0
[   90.912432]  ? rcu_read_lock_sched_held+0x10f/0x130
[   90.913205]  ? find_next_bit+0x101/0x130
[   90.913837]  icmpv6_sk_init+0x12a/0x2b0
[   90.914463]  ? inet6_net_init+0x437/0x7c0
[   90.915102]  ? icmpv6_err_convert+0x180/0x180
[   90.915799]  ? ac6_proc_init+0x5a/0x70
[   90.916402]  ? inet6_net_init+0x53b/0x7c0
[   90.917041]  ? icmpv6_err_convert+0x180/0x180
[   90.917734]  ops_init+0xb2/0x400
[   90.918265]  setup_net+0x24c/0x5e0
[   90.918817]  ? ops_init+0x400/0x400
[   90.919386]  copy_net_ns+0x1a2/0x270
[   90.919969]  create_new_namespaces+0x579/0x790
[   90.920676]  unshare_nsproxy_namespaces+0xc3/0x190
[   90.921435]  ksys_unshare+0x428/0x810
[   90.922029]  ? walk_process_tree+0x2c0/0x2c0
[   90.922712]  ? __change_pid+0x19c/0x2c0
[   90.923328]  ? _raw_write_unlock_irq+0x24/0x30
[   90.924038]  ? trace_hardirqs_on_thunk+0x1a/0x1c
[   90.924771]  ? trace_hardirqs_off_caller+0x55/0x1c0
[   90.925547]  __x64_sys_unshare+0x2d/0x40
[   90.926187]  do_syscall_64+0xbc/0x4e0
[   90.926777]  entry_SYSCALL_64_after_hwframe+0x49/0xbe
[   90.927573] RIP: 0033:0x7f827ad52229
[   90.928146] Code: Bad RIP value.
[   90.928663] RSP: 002b:00007fff6ac6a6c8 EFLAGS: 00000217 ORIG_RAX:
0000000000000110
[   90.929837] RAX: ffffffffffffffda RBX: 0000000000000000 RCX:
00007f827ad52229
[   90.930952] RDX: 00007f827ad27147 RSI: 0000000000000000 RDI:
0000000040000000
[   90.932056] RBP: 00007fff6ac6a6d0 R08: 0000000000000005 R09:
00007fff6ac6a720
[   90.933165] R10: 0000000000000000 R11: 0000000000000217 R12:
00005607242822e0
[   90.934278] R13: 00007fff6ac6a830 R14: 0000000000000000 R15:
0000000000000000

I just guess that copy_net_ns func doesn't call net_free, and it makes OOM.

And, I found that

diff --git a/include/net/net_namespace.h b/include/net/net_namespace.h
index 99d4148e0f90..38c474e4ab4c 100644
--- a/include/net/net_namespace.h
+++ b/include/net/net_namespace.h
@@ -50,12 +50,12 @@ struct bpf_prog;
 #define NETDEV_HASHENTRIES (1 << NETDEV_HASHBITS)

 struct net {
-       refcount_t              passive;        /* To decided when the
network
-                                                * namespace should be
freed.
-                                                */
        refcount_t              count;          /* To decided when the
network
                                                 *  namespace should be
shut down.
                                                 */
+       refcount_t              passive;        /* To decided when the
network
+                                                * namespace should be
freed.
+                                                */
        spinlock_t              rules_mod_lock;

        atomic64_t              cookie_gen;

this patch also works on this bug. (Just swap the order of net struct.)
I don't know why this patch works (I just thought that compiler
optimization issue can make this bug and try this one.)
I need to review code more on copy_net_ns().

Also, I reproduce this bug on Ubuntu 18.10 (4.18.0-10-generic) on VMWare
Workstation Pro 15.0.2 by C reproducer.

On 12/01/2019 5:41 오전, Kirill Tkhai wrote:
> On 11.01.2019 23:33, Eric W. Biederman wrote:
>> zzoru <zzoru007@gmail.com> writes:
>>
>>> net/core: BUG in copy_net_ns() (net_namespace.c)
>> I don't understand this failure report at all.
>>
>> I don't see the connection to copy_net_ns().  And I don't see how the
>> suggested patch short of covering up a memory stomp could possibly make
>> a difference.
>>
>> What am I missing?
> I received 3 spam messages from this address today.
> We can simply ignore this report.
>
>>
>>> Hello,
>>>
>>> I've got the following error report while fuzzing the kernel with syzkaller.
>>>
>>> On commit 1bdbe227492075d058e37cb3d400e6468d0095b5
>>>
>>> Syzkaller hit 'WARNING in __alloc_pages_slowpath' bug.
>>>
>>> syz-executor561 (17453) used greatest stack depth: 25056 bytes left
>>> WARNING: CPU: 0 PID: 692 at mm/page_alloc.c:4415
>>> __alloc_pages_slowpath+0x1cb1/0x2220 mm/page_alloc.c:4386
>>> Kernel panic - not syncing: panic_on_warn set ...
>>> CPU: 0 PID: 692 Comm: kswapd0 Not tainted 5.0.0-rc1+ #4
>>> Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS
>>> Ubuntu-1.8.2-1ubuntu1 04/01/2014
>>> Call Trace:
>>>  __dump_stack lib/dump_stack.c:77 [inline]
>>>  dump_stack+0xca/0x13e lib/dump_stack.c:113
>>>  panic+0x278/0x5bf kernel/panic.c:214
>>>  __warn.cold.10+0x20/0x45 kernel/panic.c:571
>>>  report_bug+0x246/0x2d0 lib/bug.c:186
>>>  fixup_bug arch/x86/kernel/traps.c:178 [inline]
>>>  do_error_trap+0x123/0x1e0 arch/x86/kernel/traps.c:271
>>>  do_invalid_op+0x31/0x40 arch/x86/kernel/traps.c:290
>>>  invalid_op+0x14/0x20 arch/x86/entry/entry_64.S:973
>>> RIP: 0010:__alloc_pages_slowpath+0x1cb1/0x2220 mm/page_alloc.c:4415
>>> Code: 8b 84 24 a8 00 00 00 e9 ea f1 ff ff 85 d2 0f 85 0b 01 00 00 48 c7
>>> c7 c0 5e 55 84 e8 79 f8 23 02 e9 86 f9 ff ff 44 8b 74 24 0c <0f> 0b 48
>>> b8 00 00 00 00 00 fc ff df 48 8b 54 24 18 48 c1 ea 03 80
>>> RSP: 0018:ffff8880683fedb8 EFLAGS: 00010046
>>> RAX: 0000000000000000 RBX: 0000000000000000 RCX: 1ffff1100d07fda4
>>> RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff88807ffdd528
>>> RBP: dffffc0000000000 R08: 0000000000000000 R09: 000000000000067a
>>> R10: 0000000000000000 R11: ffff88807ffdc487 R12: 0000000000000000
>>> R13: ffff8880683ff010 R14: 0000000000415a00 R15: ffff8880683ff010
>>>  __alloc_pages_nodemask+0x521/0x5f0 mm/page_alloc.c:4555
>>>  __alloc_pages include/linux/gfp.h:473 [inline]
>>>  __alloc_pages_node include/linux/gfp.h:486 [inline]
>>>  kmem_getpages mm/slab.c:1398 [inline]
>>>  cache_grow_begin+0x95/0x300 mm/slab.c:2666
>>>  fallback_alloc+0x1ce/0x270 mm/slab.c:3208
>>>  __do_cache_alloc mm/slab.c:3345 [inline]
>>>  slab_alloc mm/slab.c:3373 [inline]
>>>  kmem_cache_alloc+0x286/0x2f0 mm/slab.c:3541
>>>  create_object+0x83/0x880 mm/kmemleak.c:578
>>>  kmemleak_alloc_recursive include/linux/kmemleak.h:55 [inline]
>>>  slab_post_alloc_hook mm/slab.h:442 [inline]
>>>  slab_alloc mm/slab.c:3381 [inline]
>>>  kmem_cache_alloc+0x18f/0x2f0 mm/slab.c:3541
>>>  mempool_alloc+0x13e/0x340 mm/mempool.c:385
>>>  bio_alloc_bioset+0x36f/0x5d0 block/bio.c:489
>>>  bio_alloc include/linux/bio.h:393 [inline]
>>>  submit_bh_wbc.isra.57+0x128/0x680 fs/buffer.c:3061
>>>  __block_write_full_page+0x6e8/0xcd0 fs/buffer.c:1765
>>>  block_write_full_page+0x202/0x250 fs/buffer.c:2955
>>>  pageout mm/vmscan.c:865 [inline]
>>>  shrink_page_list+0x220f/0x3800 mm/vmscan.c:1383
>>>  shrink_inactive_list+0x3c2/0xaa0 mm/vmscan.c:1961
>>>  shrink_list mm/vmscan.c:2273 [inline]
>>>  shrink_node_memcg.constprop.83+0x4bf/0x10e0 mm/vmscan.c:2538
>>>  shrink_node+0x162/0xd10 mm/vmscan.c:2753
>>>  kswapd_shrink_node mm/vmscan.c:3516 [inline]
>>>  balance_pgdat+0x47f/0xc00 mm/vmscan.c:3674
>>>  kswapd+0x57c/0xde0 mm/vmscan.c:3929
>>>  kthread+0x347/0x410 kernel/kthread.c:246
>>>  ret_from_fork+0x3a/0x50 arch/x86/entry/entry_64.S:352
>>> Dumping ftrace buffer:
>>>    (ftrace buffer empty)
>>> Kernel Offset: disabled
>>> Rebooting in 86400 seconds..
>>>
>>>
>>> Syzkaller reproducer:
>>> # {Threaded:false Collide:false Repeat:true RepeatTimes:0 Procs:8
>>> Sandbox:none Fault:false FaultCall:-1 FaultNth:0 EnableTun:false
>>> UseTmpDir:true EnableCgroups:false EnableNetdev:true ResetNet:false
>>> HandleSegv:false Repro:false Trace:false}
>>> unshare(0x40000000)
>>>
>>>
>>> C reproducer:
>>> // autogenerated by syzkaller (https://github.com/google/syzkaller)
>>>
>>> #define _GNU_SOURCE
>>>
>>> #include <arpa/inet.h>
>>> #include <dirent.h>
>>> #include <endian.h>
>>> #include <errno.h>
>>> #include <fcntl.h>
>>> #include <net/if.h>
>>> #include <net/if_arp.h>
>>> #include <netinet/in.h>
>>> #include <sched.h>
>>> #include <signal.h>
>>> #include <stdarg.h>
>>> #include <stdbool.h>
>>> #include <stdint.h>
>>> #include <stdio.h>
>>> #include <stdlib.h>
>>> #include <string.h>
>>> #include <sys/ioctl.h>
>>> #include <sys/mount.h>
>>> #include <sys/prctl.h>
>>> #include <sys/resource.h>
>>> #include <sys/socket.h>
>>> #include <sys/stat.h>
>>> #include <sys/syscall.h>
>>> #include <sys/time.h>
>>> #include <sys/types.h>
>>> #include <sys/uio.h>
>>> #include <sys/wait.h>
>>> #include <time.h>
>>> #include <unistd.h>
>>>
>>> #include <linux/if_addr.h>
>>> #include <linux/if_ether.h>
>>> #include <linux/if_link.h>
>>> #include <linux/if_tun.h>
>>> #include <linux/in6.h>
>>> #include <linux/ip.h>
>>> #include <linux/neighbour.h>
>>> #include <linux/net.h>
>>> #include <linux/netlink.h>
>>> #include <linux/rtnetlink.h>
>>> #include <linux/tcp.h>
>>> #include <linux/veth.h>
>>>
>>> unsigned long long procid;
>>>
>>> static void sleep_ms(uint64_t ms)
>>> {
>>>   usleep(ms * 1000);
>>> }
>>>
>>> static uint64_t current_time_ms(void)
>>> {
>>>   struct timespec ts;
>>>   if (clock_gettime(CLOCK_MONOTONIC, &ts))
>>>     exit(1);
>>>   return (uint64_t)ts.tv_sec * 1000 + (uint64_t)ts.tv_nsec / 1000000;
>>> }
>>>
>>> static void use_temporary_dir(void)
>>> {
>>>   char tmpdir_template[] = "./syzkaller.XXXXXX";
>>>   char* tmpdir = mkdtemp(tmpdir_template);
>>>   if (!tmpdir)
>>>     exit(1);
>>>   if (chmod(tmpdir, 0777))
>>>     exit(1);
>>>   if (chdir(tmpdir))
>>>     exit(1);
>>> }
>>>
>>> static bool write_file(const char* file, const char* what, ...)
>>> {
>>>   char buf[1024];
>>>   va_list args;
>>>   va_start(args, what);
>>>   vsnprintf(buf, sizeof(buf), what, args);
>>>   va_end(args);
>>>   buf[sizeof(buf) - 1] = 0;
>>>   int len = strlen(buf);
>>>   int fd = open(file, O_WRONLY | O_CLOEXEC);
>>>   if (fd == -1)
>>>     return false;
>>>   if (write(fd, buf, len) != len) {
>>>     int err = errno;
>>>     close(fd);
>>>     errno = err;
>>>     return false;
>>>   }
>>>   close(fd);
>>>   return true;
>>> }
>>>
>>> static struct {
>>>   char* pos;
>>>   int nesting;
>>>   struct nlattr* nested[8];
>>>   char buf[1024];
>>> } nlmsg;
>>>
>>> static void netlink_init(int typ, int flags, const void* data, int size)
>>> {
>>>   memset(&nlmsg, 0, sizeof(nlmsg));
>>>   struct nlmsghdr* hdr = (struct nlmsghdr*)nlmsg.buf;
>>>   hdr->nlmsg_type = typ;
>>>   hdr->nlmsg_flags = NLM_F_REQUEST | NLM_F_ACK | flags;
>>>   memcpy(hdr + 1, data, size);
>>>   nlmsg.pos = (char*)(hdr + 1) + NLMSG_ALIGN(size);
>>> }
>>>
>>> static void netlink_attr(int typ, const void* data, int size)
>>> {
>>>   struct nlattr* attr = (struct nlattr*)nlmsg.pos;
>>>   attr->nla_len = sizeof(*attr) + size;
>>>   attr->nla_type = typ;
>>>   memcpy(attr + 1, data, size);
>>>   nlmsg.pos += NLMSG_ALIGN(attr->nla_len);
>>> }
>>>
>>> static void netlink_nest(int typ)
>>> {
>>>   struct nlattr* attr = (struct nlattr*)nlmsg.pos;
>>>   attr->nla_type = typ;
>>>   nlmsg.pos += sizeof(*attr);
>>>   nlmsg.nested[nlmsg.nesting++] = attr;
>>> }
>>>
>>> static void netlink_done(void)
>>> {
>>>   struct nlattr* attr = nlmsg.nested[--nlmsg.nesting];
>>>   attr->nla_len = nlmsg.pos - (char*)attr;
>>> }
>>>
>>> static int netlink_send(int sock)
>>> {
>>>   if (nlmsg.pos > nlmsg.buf + sizeof(nlmsg.buf) || nlmsg.nesting)
>>>     exit(1);
>>>   struct nlmsghdr* hdr = (struct nlmsghdr*)nlmsg.buf;
>>>   hdr->nlmsg_len = nlmsg.pos - nlmsg.buf;
>>>   struct sockaddr_nl addr;
>>>   memset(&addr, 0, sizeof(addr));
>>>   addr.nl_family = AF_NETLINK;
>>>   unsigned n = sendto(sock, nlmsg.buf, hdr->nlmsg_len, 0,
>>>                       (struct sockaddr*)&addr, sizeof(addr));
>>>   if (n != hdr->nlmsg_len)
>>>     exit(1);
>>>   n = recv(sock, nlmsg.buf, sizeof(nlmsg.buf), 0);
>>>   if (n < sizeof(struct nlmsghdr) + sizeof(struct nlmsgerr))
>>>     exit(1);
>>>   if (hdr->nlmsg_type != NLMSG_ERROR)
>>>     exit(1);
>>>   return -((struct nlmsgerr*)(hdr + 1))->error;
>>> }
>>>
>>> static void netlink_add_device_impl(const char* type, const char* name)
>>> {
>>>   struct ifinfomsg hdr;
>>>   memset(&hdr, 0, sizeof(hdr));
>>>   netlink_init(RTM_NEWLINK, NLM_F_EXCL | NLM_F_CREATE, &hdr, sizeof(hdr));
>>>   if (name)
>>>     netlink_attr(IFLA_IFNAME, name, strlen(name));
>>>   netlink_nest(IFLA_LINKINFO);
>>>   netlink_attr(IFLA_INFO_KIND, type, strlen(type));
>>> }
>>>
>>> static void netlink_add_device(int sock, const char* type, const char* name)
>>> {
>>>   netlink_add_device_impl(type, name);
>>>   netlink_done();
>>>   int err = netlink_send(sock);
>>>   (void)err;
>>> }
>>>
>>> static void netlink_add_veth(int sock, const char* name, const char* peer)
>>> {
>>>   netlink_add_device_impl("veth", name);
>>>   netlink_nest(IFLA_INFO_DATA);
>>>   netlink_nest(VETH_INFO_PEER);
>>>   nlmsg.pos += sizeof(struct ifinfomsg);
>>>   netlink_attr(IFLA_IFNAME, peer, strlen(peer));
>>>   netlink_done();
>>>   netlink_done();
>>>   netlink_done();
>>>   int err = netlink_send(sock);
>>>   (void)err;
>>> }
>>>
>>> static void netlink_add_hsr(int sock, const char* name, const char* slave1,
>>>                             const char* slave2)
>>> {
>>>   netlink_add_device_impl("hsr", name);
>>>   netlink_nest(IFLA_INFO_DATA);
>>>   int ifindex1 = if_nametoindex(slave1);
>>>   netlink_attr(IFLA_HSR_SLAVE1, &ifindex1, sizeof(ifindex1));
>>>   int ifindex2 = if_nametoindex(slave2);
>>>   netlink_attr(IFLA_HSR_SLAVE2, &ifindex2, sizeof(ifindex2));
>>>   netlink_done();
>>>   netlink_done();
>>>   int err = netlink_send(sock);
>>>   (void)err;
>>> }
>>>
>>> static void netlink_device_change(int sock, const char* name, bool up,
>>>                                   const char* master, const void* mac,
>>>                                   int macsize)
>>> {
>>>   struct ifinfomsg hdr;
>>>   memset(&hdr, 0, sizeof(hdr));
>>>   if (up)
>>>     hdr.ifi_flags = hdr.ifi_change = IFF_UP;
>>>   netlink_init(RTM_NEWLINK, 0, &hdr, sizeof(hdr));
>>>   netlink_attr(IFLA_IFNAME, name, strlen(name));
>>>   if (master) {
>>>     int ifindex = if_nametoindex(master);
>>>     netlink_attr(IFLA_MASTER, &ifindex, sizeof(ifindex));
>>>   }
>>>   if (macsize)
>>>     netlink_attr(IFLA_ADDRESS, mac, macsize);
>>>   int err = netlink_send(sock);
>>>   (void)err;
>>> }
>>>
>>> static int netlink_add_addr(int sock, const char* dev, const void* addr,
>>>                             int addrsize)
>>> {
>>>   struct ifaddrmsg hdr;
>>>   memset(&hdr, 0, sizeof(hdr));
>>>   hdr.ifa_family = addrsize == 4 ? AF_INET : AF_INET6;
>>>   hdr.ifa_prefixlen = addrsize == 4 ? 24 : 120;
>>>   hdr.ifa_scope = RT_SCOPE_UNIVERSE;
>>>   hdr.ifa_index = if_nametoindex(dev);
>>>   netlink_init(RTM_NEWADDR, NLM_F_CREATE | NLM_F_REPLACE, &hdr,
>>> sizeof(hdr));
>>>   netlink_attr(IFA_LOCAL, addr, addrsize);
>>>   netlink_attr(IFA_ADDRESS, addr, addrsize);
>>>   return netlink_send(sock);
>>> }
>>>
>>> static void netlink_add_addr4(int sock, const char* dev, const char* addr)
>>> {
>>>   struct in_addr in_addr;
>>>   inet_pton(AF_INET, addr, &in_addr);
>>>   int err = netlink_add_addr(sock, dev, &in_addr, sizeof(in_addr));
>>>   (void)err;
>>> }
>>>
>>> static void netlink_add_addr6(int sock, const char* dev, const char* addr)
>>> {
>>>   struct in6_addr in6_addr;
>>>   inet_pton(AF_INET6, addr, &in6_addr);
>>>   int err = netlink_add_addr(sock, dev, &in6_addr, sizeof(in6_addr));
>>>   (void)err;
>>> }
>>>
>>> #define DEV_IPV4 "172.20.20.%d"
>>> #define DEV_IPV6 "fe80::%02hx"
>>> #define DEV_MAC 0x00aaaaaaaaaa
>>> static void initialize_netdevices(void)
>>> {
>>>   char netdevsim[16];
>>>   sprintf(netdevsim, "netdevsim%d", (int)procid);
>>>   struct {
>>>     const char* type;
>>>     const char* dev;
>>>   } devtypes[] = {
>>>       {"ip6gretap", "ip6gretap0"}, {"bridge", "bridge0"},
>>>       {"vcan", "vcan0"},           {"bond", "bond0"},
>>>       {"team", "team0"},           {"dummy", "dummy0"},
>>>       {"nlmon", "nlmon0"},         {"caif", "caif0"},
>>>       {"batadv", "batadv0"},       {"vxcan", "vxcan1"},
>>>       {"netdevsim", netdevsim},    {"veth", 0},
>>>   };
>>>   const char* devmasters[] = {"bridge", "bond", "team"};
>>>   struct {
>>>     const char* name;
>>>     int macsize;
>>>     bool noipv6;
>>>   } devices[] = {
>>>       {"lo", ETH_ALEN},
>>>       {"sit0", 0},
>>>       {"bridge0", ETH_ALEN},
>>>       {"vcan0", 0, true},
>>>       {"tunl0", 0},
>>>       {"gre0", 0},
>>>       {"gretap0", ETH_ALEN},
>>>       {"ip_vti0", 0},
>>>       {"ip6_vti0", 0},
>>>       {"ip6tnl0", 0},
>>>       {"ip6gre0", 0},
>>>       {"ip6gretap0", ETH_ALEN},
>>>       {"erspan0", ETH_ALEN},
>>>       {"bond0", ETH_ALEN},
>>>       {"veth0", ETH_ALEN},
>>>       {"veth1", ETH_ALEN},
>>>       {"team0", ETH_ALEN},
>>>       {"veth0_to_bridge", ETH_ALEN},
>>>       {"veth1_to_bridge", ETH_ALEN},
>>>       {"veth0_to_bond", ETH_ALEN},
>>>       {"veth1_to_bond", ETH_ALEN},
>>>       {"veth0_to_team", ETH_ALEN},
>>>       {"veth1_to_team", ETH_ALEN},
>>>       {"veth0_to_hsr", ETH_ALEN},
>>>       {"veth1_to_hsr", ETH_ALEN},
>>>       {"hsr0", 0},
>>>       {"dummy0", ETH_ALEN},
>>>       {"nlmon0", 0},
>>>       {"vxcan1", 0, true},
>>>       {"caif0", ETH_ALEN},
>>>       {"batadv0", ETH_ALEN},
>>>       {netdevsim, ETH_ALEN},
>>>   };
>>>   int sock = socket(AF_NETLINK, SOCK_RAW, NETLINK_ROUTE);
>>>   if (sock == -1)
>>>     exit(1);
>>>   unsigned i;
>>>   for (i = 0; i < sizeof(devtypes) / sizeof(devtypes[0]); i++)
>>>     netlink_add_device(sock, devtypes[i].type, devtypes[i].dev);
>>>   for (i = 0; i < sizeof(devmasters) / (sizeof(devmasters[0])); i++) {
>>>     char master[32], slave0[32], veth0[32], slave1[32], veth1[32];
>>>     sprintf(slave0, "%s_slave_0", devmasters[i]);
>>>     sprintf(veth0, "veth0_to_%s", devmasters[i]);
>>>     netlink_add_veth(sock, slave0, veth0);
>>>     sprintf(slave1, "%s_slave_1", devmasters[i]);
>>>     sprintf(veth1, "veth1_to_%s", devmasters[i]);
>>>     netlink_add_veth(sock, slave1, veth1);
>>>     sprintf(master, "%s0", devmasters[i]);
>>>     netlink_device_change(sock, slave0, false, master, 0, 0);
>>>     netlink_device_change(sock, slave1, false, master, 0, 0);
>>>   }
>>>   netlink_device_change(sock, "bridge_slave_0", true, 0, 0, 0);
>>>   netlink_device_change(sock, "bridge_slave_1", true, 0, 0, 0);
>>>   netlink_add_veth(sock, "hsr_slave_0", "veth0_to_hsr");
>>>   netlink_add_veth(sock, "hsr_slave_1", "veth1_to_hsr");
>>>   netlink_add_hsr(sock, "hsr0", "hsr_slave_0", "hsr_slave_1");
>>>   netlink_device_change(sock, "hsr_slave_0", true, 0, 0, 0);
>>>   netlink_device_change(sock, "hsr_slave_1", true, 0, 0, 0);
>>>   for (i = 0; i < sizeof(devices) / (sizeof(devices[0])); i++) {
>>>     char addr[32];
>>>     sprintf(addr, DEV_IPV4, i + 10);
>>>     netlink_add_addr4(sock, devices[i].name, addr);
>>>     if (!devices[i].noipv6) {
>>>       sprintf(addr, DEV_IPV6, i + 10);
>>>       netlink_add_addr6(sock, devices[i].name, addr);
>>>     }
>>>     uint64_t macaddr = DEV_MAC + ((i + 10ull) << 40);
>>>     netlink_device_change(sock, devices[i].name, true, 0, &macaddr,
>>>                           devices[i].macsize);
>>>   }
>>>   close(sock);
>>> }
>>> static void initialize_netdevices_init(void)
>>> {
>>>   int sock = socket(AF_NETLINK, SOCK_RAW, NETLINK_ROUTE);
>>>   if (sock == -1)
>>>     exit(1);
>>>   struct {
>>>     const char* type;
>>>     int macsize;
>>>     bool noipv6;
>>>     bool noup;
>>>   } devtypes[] = {
>>>       {"nr", 7, true}, {"rose", 5, true, true},
>>>   };
>>>   unsigned i;
>>>   for (i = 0; i < sizeof(devtypes) / sizeof(devtypes[0]); i++) {
>>>     char dev[32], addr[32];
>>>     sprintf(dev, "%s%d", devtypes[i].type, (int)procid);
>>>     sprintf(addr, "172.30.%d.%d", i, (int)procid + 1);
>>>     netlink_add_addr4(sock, dev, addr);
>>>     if (!devtypes[i].noipv6) {
>>>       sprintf(addr, "fe88::%02hx:%02hx", i, (int)procid + 1);
>>>       netlink_add_addr6(sock, dev, addr);
>>>     }
>>>     int macsize = devtypes[i].macsize;
>>>     uint64_t macaddr = 0xbbbbbb +
>>>                        ((unsigned long long)i << (8 * (macsize - 2))) +
>>>                        (procid << (8 * (macsize - 1)));
>>>     netlink_device_change(sock, dev, !devtypes[i].noup, 0, &macaddr,
>>> macsize);
>>>   }
>>>   close(sock);
>>> }
>>>
>>> static void setup_common()
>>> {
>>>   if (mount(0, "/sys/fs/fuse/connections", "fusectl", 0, 0)) {
>>>   }
>>> }
>>>
>>> static void loop();
>>>
>>> static void sandbox_common()
>>> {
>>>   prctl(PR_SET_PDEATHSIG, SIGKILL, 0, 0, 0);
>>>   setpgrp();
>>>   setsid();
>>>   struct rlimit rlim;
>>>   rlim.rlim_cur = rlim.rlim_max = 200 << 20;
>>>   setrlimit(RLIMIT_AS, &rlim);
>>>   rlim.rlim_cur = rlim.rlim_max = 32 << 20;
>>>   setrlimit(RLIMIT_MEMLOCK, &rlim);
>>>   rlim.rlim_cur = rlim.rlim_max = 136 << 20;
>>>   setrlimit(RLIMIT_FSIZE, &rlim);
>>>   rlim.rlim_cur = rlim.rlim_max = 1 << 20;
>>>   setrlimit(RLIMIT_STACK, &rlim);
>>>   rlim.rlim_cur = rlim.rlim_max = 0;
>>>   setrlimit(RLIMIT_CORE, &rlim);
>>>   rlim.rlim_cur = rlim.rlim_max = 256;
>>>   setrlimit(RLIMIT_NOFILE, &rlim);
>>>   if (unshare(CLONE_NEWNS)) {
>>>   }
>>>   if (unshare(CLONE_NEWIPC)) {
>>>   }
>>>   if (unshare(0x02000000)) {
>>>   }
>>>   if (unshare(CLONE_NEWUTS)) {
>>>   }
>>>   if (unshare(CLONE_SYSVSEM)) {
>>>   }
>>>   typedef struct {
>>>     const char* name;
>>>     const char* value;
>>>   } sysctl_t;
>>>   static const sysctl_t sysctls[] = {
>>>       {"/proc/sys/kernel/shmmax", "16777216"},
>>>       {"/proc/sys/kernel/shmall", "536870912"},
>>>       {"/proc/sys/kernel/shmmni", "1024"},
>>>       {"/proc/sys/kernel/msgmax", "8192"},
>>>       {"/proc/sys/kernel/msgmni", "1024"},
>>>       {"/proc/sys/kernel/msgmnb", "1024"},
>>>       {"/proc/sys/kernel/sem", "1024 1048576 500 1024"},
>>>   };
>>>   unsigned i;
>>>   for (i = 0; i < sizeof(sysctls) / sizeof(sysctls[0]); i++)
>>>     write_file(sysctls[i].name, sysctls[i].value);
>>> }
>>>
>>> int wait_for_loop(int pid)
>>> {
>>>   if (pid < 0)
>>>     exit(1);
>>>   int status = 0;
>>>   while (waitpid(-1, &status, __WALL) != pid) {
>>>   }
>>>   return WEXITSTATUS(status);
>>> }
>>>
>>> static int do_sandbox_none(void)
>>> {
>>>   if (unshare(CLONE_NEWPID)) {
>>>   }
>>>   int pid = fork();
>>>   if (pid != 0)
>>>     return wait_for_loop(pid);
>>>   setup_common();
>>>   sandbox_common();
>>>   initialize_netdevices_init();
>>>   if (unshare(CLONE_NEWNET)) {
>>>   }
>>>   initialize_netdevices();
>>>   loop();
>>>   exit(1);
>>> }
>>>
>>> #define FS_IOC_SETFLAGS _IOW('f', 2, long)
>>> static void remove_dir(const char* dir)
>>> {
>>>   DIR* dp;
>>>   struct dirent* ep;
>>>   int iter = 0;
>>> retry:
>>>   while (umount2(dir, MNT_DETACH) == 0) {
>>>   }
>>>   dp = opendir(dir);
>>>   if (dp == NULL) {
>>>     if (errno == EMFILE) {
>>>       exit(1);
>>>     }
>>>     exit(1);
>>>   }
>>>   while ((ep = readdir(dp))) {
>>>     if (strcmp(ep->d_name, ".") == 0 || strcmp(ep->d_name, "..") == 0)
>>>       continue;
>>>     char filename[FILENAME_MAX];
>>>     snprintf(filename, sizeof(filename), "%s/%s", dir, ep->d_name);
>>>     while (umount2(filename, MNT_DETACH) == 0) {
>>>     }
>>>     struct stat st;
>>>     if (lstat(filename, &st))
>>>       exit(1);
>>>     if (S_ISDIR(st.st_mode)) {
>>>       remove_dir(filename);
>>>       continue;
>>>     }
>>>     int i;
>>>     for (i = 0;; i++) {
>>>       if (unlink(filename) == 0)
>>>         break;
>>>       if (errno == EPERM) {
>>>         int fd = open(filename, O_RDONLY);
>>>         if (fd != -1) {
>>>           long flags = 0;
>>>           if (ioctl(fd, FS_IOC_SETFLAGS, &flags) == 0)
>>>             close(fd);
>>>           continue;
>>>         }
>>>       }
>>>       if (errno == EROFS) {
>>>         break;
>>>       }
>>>       if (errno != EBUSY || i > 100)
>>>         exit(1);
>>>       if (umount2(filename, MNT_DETACH))
>>>         exit(1);
>>>     }
>>>   }
>>>   closedir(dp);
>>>   int i;
>>>   for (i = 0;; i++) {
>>>     if (rmdir(dir) == 0)
>>>       break;
>>>     if (i < 100) {
>>>       if (errno == EPERM) {
>>>         int fd = open(dir, O_RDONLY);
>>>         if (fd != -1) {
>>>           long flags = 0;
>>>           if (ioctl(fd, FS_IOC_SETFLAGS, &flags) == 0)
>>>             close(fd);
>>>           continue;
>>>         }
>>>       }
>>>       if (errno == EROFS) {
>>>         break;
>>>       }
>>>       if (errno == EBUSY) {
>>>         if (umount2(dir, MNT_DETACH))
>>>           exit(1);
>>>         continue;
>>>       }
>>>       if (errno == ENOTEMPTY) {
>>>         if (iter < 100) {
>>>           iter++;
>>>           goto retry;
>>>         }
>>>       }
>>>     }
>>>     exit(1);
>>>   }
>>> }
>>>
>>> static void kill_and_wait(int pid, int* status)
>>> {
>>>   kill(-pid, SIGKILL);
>>>   kill(pid, SIGKILL);
>>>   int i;
>>>   for (i = 0; i < 100; i++) {
>>>     if (waitpid(-1, status, WNOHANG | __WALL) == pid)
>>>       return;
>>>     usleep(1000);
>>>   }
>>>   DIR* dir = opendir("/sys/fs/fuse/connections");
>>>   if (dir) {
>>>     for (;;) {
>>>       struct dirent* ent = readdir(dir);
>>>       if (!ent)
>>>         break;
>>>       if (strcmp(ent->d_name, ".") == 0 || strcmp(ent->d_name, "..") == 0)
>>>         continue;
>>>       char abort[300];
>>>       snprintf(abort, sizeof(abort), "/sys/fs/fuse/connections/%s/abort",
>>>                ent->d_name);
>>>       int fd = open(abort, O_WRONLY);
>>>       if (fd == -1) {
>>>         continue;
>>>       }
>>>       if (write(fd, abort, 1) < 0) {
>>>       }
>>>       close(fd);
>>>     }
>>>     closedir(dir);
>>>   } else {
>>>   }
>>>   while (waitpid(-1, status, __WALL) != pid) {
>>>   }
>>> }
>>>
>>> #define SYZ_HAVE_SETUP_TEST 1
>>> static void setup_test()
>>> {
>>>   prctl(PR_SET_PDEATHSIG, SIGKILL, 0, 0, 0);
>>>   setpgrp();
>>> }
>>>
>>> #define SYZ_HAVE_RESET_TEST 1
>>> static void reset_test()
>>> {
>>>   int fd;
>>>   for (fd = 3; fd < 30; fd++)
>>>     close(fd);
>>> }
>>>
>>> static void execute_one(void);
>>>
>>> #define WAIT_FLAGS __WALL
>>>
>>> static void loop(void)
>>> {
>>>   int iter;
>>>   for (iter = 0;; iter++) {
>>>     char cwdbuf[32];
>>>     sprintf(cwdbuf, "./%d", iter);
>>>     if (mkdir(cwdbuf, 0777))
>>>       exit(1);
>>>     int pid = fork();
>>>     if (pid < 0)
>>>       exit(1);
>>>     if (pid == 0) {
>>>       if (chdir(cwdbuf))
>>>         exit(1);
>>>       setup_test();
>>>       execute_one();
>>>       reset_test();
>>>       exit(0);
>>>     }
>>>     int status = 0;
>>>     uint64_t start = current_time_ms();
>>>     for (;;) {
>>>       if (waitpid(-1, &status, WNOHANG | WAIT_FLAGS) == pid)
>>>         break;
>>>       sleep_ms(1);
>>>       if (current_time_ms() - start < 5 * 1000)
>>>         continue;
>>>       kill_and_wait(pid, &status);
>>>       break;
>>>     }
>>>     remove_dir(cwdbuf);
>>>   }
>>> }
>>>
>>> void execute_one(void)
>>> {
>>>   syscall(__NR_unshare, 0x40000000);
>>> }
>>> int main(void)
>>> {
>>>   syscall(__NR_mmap, 0x20000000, 0x1000000, 3, 0x32, -1, 0);
>>>   for (procid = 0; procid < 8; procid++) {
>>>     if (fork() == 0) {
>>>       use_temporary_dir();
>>>       do_sandbox_none();
>>>     }
>>>   }
>>>   sleep(1000000);
>>>   return 0;
>>> }
>>>
>>>
>>> I reviewed kernel code and found a bug that
>>> net_drop_ns func doesn't call net_free func when refcount_dec_and_test's
>>> return value is zero.
>> Yes.  We don't call net_free when the reference count does not decrement
>> to zero.  The reference count is initialized to 1 a few lines above the
>> section of code in your patch so that should not be a problem.
>>
>>> or
>>> when rv = down_read_killable(&pernet_ops_rwsem) < 0, it doesn't need to
>>> call refcount_dec_and_test.
>> It doesn't need to but it should be harmless.
>>
>>> https://github.com/torvalds/linux/commit/5ba049a5cc8e24a1643df75bbf65b4efa070fa74#diff-9312644e2968a45510bacdd2b2872ad2
>>> (I can't reproduce this bug on v4.15 , and
>>> 1bdbe227492075d058e37cb3d400e6468d0095b5 with my patch. Because of the
>>> previous version of kernel doesn't have this bug.)
>>> This bug can lead to memory leak or DOS.
>>>
>>> I made a patch for this bug. (just revert to a before commit)
>> What am I missing?
>>
>> The only thing I can see your patch doing is covering up a memory stomp
>> that has the effect of changing the value of net->passive.  I am not
>> really keen on hiding bugs of that kind.
>>
>>
>>> diff --git a/net/core/net_namespace.c b/net/core/net_namespace.c
>>> index b02fb19df2cc..9de0ade14956 100644
>>> --- a/net/core/net_namespace.c
>>> +++ b/net/core/net_namespace.c
>>> @@ -431,15 +431,18 @@ struct net *copy_net_ns(unsigned long flags,
>>>         get_user_ns(user_ns);
>>>
>>>         rv = down_read_killable(&pernet_ops_rwsem);
>>> -       if (rv < 0)
>>> -               goto put_userns;
>>> +       if (rv < 0){
>>> +        net_free(net);
>>> +        dec_net_namespaces(ucounts);
>>> +        put_user_ns(user_ns);
>>> +        return ERR_PTR(rv);
>>> +    }
>>>
>>>         rv = setup_net(net, user_ns);
>>>
>>>         up_read(&pernet_ops_rwsem);
>>>
>>>         if (rv < 0) {
>>> -put_userns:
>>>                 put_user_ns(user_ns);
>>>                 net_drop_ns(net);
>>>  dec_ucounts:
>>>
>>> and, sorry for my encrypted mails.
>> Eric
>>
#
# Automatically generated file; DO NOT EDIT.
# Linux/x86 5.0.0-rc1 Kernel Configuration
#

#
# Compiler: gcc-8 (Homebrew GCC 8.2.0) 8.2.0
#
CONFIG_CC_IS_GCC=y
CONFIG_GCC_VERSION=80200
CONFIG_CLANG_VERSION=0
CONFIG_CC_HAS_ASM_GOTO=y
CONFIG_CONSTRUCTORS=y
CONFIG_IRQ_WORK=y
CONFIG_BUILDTIME_EXTABLE_SORT=y
CONFIG_THREAD_INFO_IN_TASK=y

#
# General setup
#
CONFIG_INIT_ENV_ARG_LIMIT=32
# CONFIG_COMPILE_TEST is not set
CONFIG_LOCALVERSION=""
# CONFIG_LOCALVERSION_AUTO is not set
CONFIG_BUILD_SALT=""
CONFIG_HAVE_KERNEL_GZIP=y
CONFIG_HAVE_KERNEL_BZIP2=y
CONFIG_HAVE_KERNEL_LZMA=y
CONFIG_HAVE_KERNEL_XZ=y
CONFIG_HAVE_KERNEL_LZO=y
CONFIG_HAVE_KERNEL_LZ4=y
CONFIG_KERNEL_GZIP=y
# CONFIG_KERNEL_BZIP2 is not set
# CONFIG_KERNEL_LZMA is not set
# CONFIG_KERNEL_XZ is not set
# CONFIG_KERNEL_LZO is not set
# CONFIG_KERNEL_LZ4 is not set
CONFIG_DEFAULT_HOSTNAME="(none)"
CONFIG_SWAP=y
CONFIG_SYSVIPC=y
CONFIG_SYSVIPC_SYSCTL=y
CONFIG_POSIX_MQUEUE=y
CONFIG_POSIX_MQUEUE_SYSCTL=y
CONFIG_CROSS_MEMORY_ATTACH=y
CONFIG_USELIB=y
CONFIG_AUDIT=y
CONFIG_HAVE_ARCH_AUDITSYSCALL=y
CONFIG_AUDITSYSCALL=y

#
# IRQ subsystem
#
CONFIG_GENERIC_IRQ_PROBE=y
CONFIG_GENERIC_IRQ_SHOW=y
CONFIG_GENERIC_IRQ_EFFECTIVE_AFF_MASK=y
CONFIG_GENERIC_PENDING_IRQ=y
CONFIG_GENERIC_IRQ_MIGRATION=y
CONFIG_IRQ_DOMAIN=y
CONFIG_IRQ_DOMAIN_HIERARCHY=y
CONFIG_GENERIC_MSI_IRQ=y
CONFIG_GENERIC_MSI_IRQ_DOMAIN=y
CONFIG_GENERIC_IRQ_MATRIX_ALLOCATOR=y
CONFIG_GENERIC_IRQ_RESERVATION_MODE=y
CONFIG_IRQ_FORCED_THREADING=y
CONFIG_SPARSE_IRQ=y
# CONFIG_GENERIC_IRQ_DEBUGFS is not set
CONFIG_CLOCKSOURCE_WATCHDOG=y
CONFIG_ARCH_CLOCKSOURCE_DATA=y
CONFIG_ARCH_CLOCKSOURCE_INIT=y
CONFIG_CLOCKSOURCE_VALIDATE_LAST_CYCLE=y
CONFIG_GENERIC_TIME_VSYSCALL=y
CONFIG_GENERIC_CLOCKEVENTS=y
CONFIG_GENERIC_CLOCKEVENTS_BROADCAST=y
CONFIG_GENERIC_CLOCKEVENTS_MIN_ADJUST=y
CONFIG_GENERIC_CMOS_UPDATE=y

#
# Timers subsystem
#
CONFIG_TICK_ONESHOT=y
CONFIG_NO_HZ_COMMON=y
# CONFIG_HZ_PERIODIC is not set
CONFIG_NO_HZ_IDLE=y
# CONFIG_NO_HZ_FULL is not set
CONFIG_NO_HZ=y
CONFIG_HIGH_RES_TIMERS=y
# CONFIG_PREEMPT_NONE is not set
CONFIG_PREEMPT_VOLUNTARY=y
# CONFIG_PREEMPT is not set
CONFIG_PREEMPT_COUNT=y

#
# CPU/Task time and stats accounting
#
CONFIG_TICK_CPU_ACCOUNTING=y
# CONFIG_VIRT_CPU_ACCOUNTING_GEN is not set
# CONFIG_IRQ_TIME_ACCOUNTING is not set
CONFIG_BSD_PROCESS_ACCT=y
# CONFIG_BSD_PROCESS_ACCT_V3 is not set
CONFIG_TASKSTATS=y
CONFIG_TASK_DELAY_ACCT=y
CONFIG_TASK_XACCT=y
CONFIG_TASK_IO_ACCOUNTING=y
# CONFIG_PSI is not set
CONFIG_CPU_ISOLATION=y

#
# RCU Subsystem
#
CONFIG_TREE_RCU=y
# CONFIG_RCU_EXPERT is not set
CONFIG_SRCU=y
CONFIG_TREE_SRCU=y
CONFIG_RCU_STALL_COMMON=y
CONFIG_RCU_NEED_SEGCBLIST=y
# CONFIG_IKCONFIG is not set
CONFIG_LOG_BUF_SHIFT=18
CONFIG_LOG_CPU_MAX_BUF_SHIFT=12
CONFIG_PRINTK_SAFE_LOG_BUF_SHIFT=13
CONFIG_HAVE_UNSTABLE_SCHED_CLOCK=y
CONFIG_ARCH_SUPPORTS_NUMA_BALANCING=y
CONFIG_ARCH_WANT_BATCHED_UNMAP_TLB_FLUSH=y
CONFIG_ARCH_SUPPORTS_INT128=y
# CONFIG_NUMA_BALANCING is not set
CONFIG_CGROUPS=y
# CONFIG_MEMCG is not set
# CONFIG_BLK_CGROUP is not set
CONFIG_CGROUP_SCHED=y
CONFIG_FAIR_GROUP_SCHED=y
# CONFIG_CFS_BANDWIDTH is not set
# CONFIG_RT_GROUP_SCHED is not set
# CONFIG_CGROUP_PIDS is not set
# CONFIG_CGROUP_RDMA is not set
CONFIG_CGROUP_FREEZER=y
# CONFIG_CGROUP_HUGETLB is not set
CONFIG_CPUSETS=y
CONFIG_PROC_PID_CPUSET=y
# CONFIG_CGROUP_DEVICE is not set
CONFIG_CGROUP_CPUACCT=y
# CONFIG_CGROUP_PERF is not set
# CONFIG_CGROUP_DEBUG is not set
CONFIG_NAMESPACES=y
CONFIG_UTS_NS=y
CONFIG_IPC_NS=y
# CONFIG_USER_NS is not set
CONFIG_PID_NS=y
CONFIG_NET_NS=y
# CONFIG_CHECKPOINT_RESTORE is not set
# CONFIG_SCHED_AUTOGROUP is not set
# CONFIG_SYSFS_DEPRECATED is not set
CONFIG_RELAY=y
CONFIG_BLK_DEV_INITRD=y
CONFIG_INITRAMFS_SOURCE=""
CONFIG_RD_GZIP=y
CONFIG_RD_BZIP2=y
CONFIG_RD_LZMA=y
CONFIG_RD_XZ=y
CONFIG_RD_LZO=y
CONFIG_RD_LZ4=y
CONFIG_CC_OPTIMIZE_FOR_PERFORMANCE=y
# CONFIG_CC_OPTIMIZE_FOR_SIZE is not set
CONFIG_SYSCTL=y
CONFIG_ANON_INODES=y
CONFIG_HAVE_UID16=y
CONFIG_SYSCTL_EXCEPTION_TRACE=y
CONFIG_HAVE_PCSPKR_PLATFORM=y
CONFIG_BPF=y
# CONFIG_EXPERT is not set
CONFIG_UID16=y
CONFIG_MULTIUSER=y
CONFIG_SGETMASK_SYSCALL=y
CONFIG_SYSFS_SYSCALL=y
CONFIG_FHANDLE=y
CONFIG_POSIX_TIMERS=y
CONFIG_PRINTK=y
CONFIG_PRINTK_NMI=y
CONFIG_BUG=y
CONFIG_ELF_CORE=y
CONFIG_PCSPKR_PLATFORM=y
CONFIG_BASE_FULL=y
CONFIG_FUTEX=y
CONFIG_FUTEX_PI=y
CONFIG_EPOLL=y
CONFIG_SIGNALFD=y
CONFIG_TIMERFD=y
CONFIG_EVENTFD=y
CONFIG_SHMEM=y
CONFIG_AIO=y
CONFIG_ADVISE_SYSCALLS=y
CONFIG_MEMBARRIER=y
CONFIG_KALLSYMS=y
CONFIG_KALLSYMS_ALL=y
CONFIG_KALLSYMS_ABSOLUTE_PERCPU=y
CONFIG_KALLSYMS_BASE_RELATIVE=y
# CONFIG_BPF_SYSCALL is not set
# CONFIG_USERFAULTFD is not set
CONFIG_ARCH_HAS_MEMBARRIER_SYNC_CORE=y
CONFIG_RSEQ=y
# CONFIG_EMBEDDED is not set
CONFIG_HAVE_PERF_EVENTS=y

#
# Kernel Performance Events And Counters
#
CONFIG_PERF_EVENTS=y
# CONFIG_DEBUG_PERF_USE_VMALLOC is not set
CONFIG_VM_EVENT_COUNTERS=y
# CONFIG_COMPAT_BRK is not set
CONFIG_SLAB=y
# CONFIG_SLUB is not set
CONFIG_SLAB_MERGE_DEFAULT=y
# CONFIG_SLAB_FREELIST_RANDOM is not set
CONFIG_SYSTEM_DATA_VERIFICATION=y
CONFIG_PROFILING=y
CONFIG_TRACEPOINTS=y
CONFIG_64BIT=y
CONFIG_X86_64=y
CONFIG_X86=y
CONFIG_INSTRUCTION_DECODER=y
CONFIG_OUTPUT_FORMAT="elf64-x86-64"
CONFIG_ARCH_DEFCONFIG="arch/x86/configs/x86_64_defconfig"
CONFIG_LOCKDEP_SUPPORT=y
CONFIG_STACKTRACE_SUPPORT=y
CONFIG_MMU=y
CONFIG_ARCH_MMAP_RND_BITS_MIN=28
CONFIG_ARCH_MMAP_RND_BITS_MAX=32
CONFIG_ARCH_MMAP_RND_COMPAT_BITS_MIN=8
CONFIG_ARCH_MMAP_RND_COMPAT_BITS_MAX=16
CONFIG_GENERIC_ISA_DMA=y
CONFIG_GENERIC_BUG=y
CONFIG_GENERIC_BUG_RELATIVE_POINTERS=y
CONFIG_GENERIC_HWEIGHT=y
CONFIG_ARCH_MAY_HAVE_PC_FDC=y
CONFIG_RWSEM_XCHGADD_ALGORITHM=y
CONFIG_GENERIC_CALIBRATE_DELAY=y
CONFIG_ARCH_HAS_CPU_RELAX=y
CONFIG_ARCH_HAS_CACHE_LINE_SIZE=y
CONFIG_ARCH_HAS_FILTER_PGPROT=y
CONFIG_HAVE_SETUP_PER_CPU_AREA=y
CONFIG_NEED_PER_CPU_EMBED_FIRST_CHUNK=y
CONFIG_NEED_PER_CPU_PAGE_FIRST_CHUNK=y
CONFIG_ARCH_HIBERNATION_POSSIBLE=y
CONFIG_ARCH_SUSPEND_POSSIBLE=y
CONFIG_ARCH_WANT_HUGE_PMD_SHARE=y
CONFIG_ARCH_WANT_GENERAL_HUGETLB=y
CONFIG_ZONE_DMA32=y
CONFIG_AUDIT_ARCH=y
CONFIG_ARCH_SUPPORTS_OPTIMIZED_INLINING=y
CONFIG_ARCH_SUPPORTS_DEBUG_PAGEALLOC=y
CONFIG_KASAN_SHADOW_OFFSET=0xdffffc0000000000
CONFIG_HAVE_INTEL_TXT=y
CONFIG_X86_64_SMP=y
CONFIG_ARCH_SUPPORTS_UPROBES=y
CONFIG_FIX_EARLYCON_MEM=y
CONFIG_PGTABLE_LEVELS=4
CONFIG_CC_HAS_SANE_STACKPROTECTOR=y

#
# Processor type and features
#
CONFIG_ZONE_DMA=y
CONFIG_SMP=y
CONFIG_X86_FEATURE_NAMES=y
# CONFIG_X86_X2APIC is not set
CONFIG_X86_MPPARSE=y
# CONFIG_GOLDFISH is not set
CONFIG_RETPOLINE=y
# CONFIG_RESCTRL is not set
CONFIG_X86_EXTENDED_PLATFORM=y
# CONFIG_X86_VSMP is not set
# CONFIG_X86_GOLDFISH is not set
# CONFIG_X86_INTEL_MID is not set
# CONFIG_X86_INTEL_LPSS is not set
# CONFIG_X86_AMD_PLATFORM_DEVICE is not set
CONFIG_IOSF_MBI=y
# CONFIG_IOSF_MBI_DEBUG is not set
CONFIG_X86_SUPPORTS_MEMORY_FAILURE=y
CONFIG_SCHED_OMIT_FRAME_POINTER=y
CONFIG_HYPERVISOR_GUEST=y
CONFIG_PARAVIRT=y
# CONFIG_PARAVIRT_DEBUG is not set
# CONFIG_PARAVIRT_SPINLOCKS is not set
# CONFIG_XEN is not set
CONFIG_KVM_GUEST=y
# CONFIG_PVH is not set
# CONFIG_KVM_DEBUG_FS is not set
# CONFIG_PARAVIRT_TIME_ACCOUNTING is not set
CONFIG_PARAVIRT_CLOCK=y
# CONFIG_JAILHOUSE_GUEST is not set
# CONFIG_MK8 is not set
# CONFIG_MPSC is not set
# CONFIG_MCORE2 is not set
# CONFIG_MATOM is not set
CONFIG_GENERIC_CPU=y
CONFIG_X86_INTERNODE_CACHE_SHIFT=6
CONFIG_X86_L1_CACHE_SHIFT=6
CONFIG_X86_TSC=y
CONFIG_X86_CMPXCHG64=y
CONFIG_X86_CMOV=y
CONFIG_X86_MINIMUM_CPU_FAMILY=64
CONFIG_X86_DEBUGCTLMSR=y
CONFIG_CPU_SUP_INTEL=y
CONFIG_CPU_SUP_AMD=y
CONFIG_CPU_SUP_HYGON=y
CONFIG_CPU_SUP_CENTAUR=y
CONFIG_HPET_TIMER=y
CONFIG_HPET_EMULATE_RTC=y
CONFIG_DMI=y
# CONFIG_GART_IOMMU is not set
CONFIG_CALGARY_IOMMU=y
CONFIG_CALGARY_IOMMU_ENABLED_BY_DEFAULT=y
# CONFIG_MAXSMP is not set
CONFIG_NR_CPUS_RANGE_BEGIN=2
CONFIG_NR_CPUS_RANGE_END=512
CONFIG_NR_CPUS_DEFAULT=64
CONFIG_NR_CPUS=64
CONFIG_SCHED_SMT=y
CONFIG_SCHED_MC=y
CONFIG_SCHED_MC_PRIO=y
CONFIG_X86_LOCAL_APIC=y
CONFIG_X86_IO_APIC=y
CONFIG_X86_REROUTE_FOR_BROKEN_BOOT_IRQS=y
CONFIG_X86_MCE=y
# CONFIG_X86_MCELOG_LEGACY is not set
CONFIG_X86_MCE_INTEL=y
CONFIG_X86_MCE_AMD=y
CONFIG_X86_MCE_THRESHOLD=y
# CONFIG_X86_MCE_INJECT is not set
CONFIG_X86_THERMAL_VECTOR=y

#
# Performance monitoring
#
CONFIG_PERF_EVENTS_INTEL_UNCORE=y
CONFIG_PERF_EVENTS_INTEL_RAPL=y
CONFIG_PERF_EVENTS_INTEL_CSTATE=y
# CONFIG_PERF_EVENTS_AMD_POWER is not set
CONFIG_X86_16BIT=y
CONFIG_X86_ESPFIX64=y
CONFIG_X86_VSYSCALL_EMULATION=y
# CONFIG_I8K is not set
CONFIG_MICROCODE=y
CONFIG_MICROCODE_INTEL=y
CONFIG_MICROCODE_AMD=y
CONFIG_MICROCODE_OLD_INTERFACE=y
CONFIG_X86_MSR=y
CONFIG_X86_CPUID=y
# CONFIG_X86_5LEVEL is not set
CONFIG_X86_DIRECT_GBPAGES=y
# CONFIG_X86_CPA_STATISTICS is not set
CONFIG_ARCH_HAS_MEM_ENCRYPT=y
# CONFIG_AMD_MEM_ENCRYPT is not set
CONFIG_NUMA=y
CONFIG_AMD_NUMA=y
CONFIG_X86_64_ACPI_NUMA=y
CONFIG_NODES_SPAN_OTHER_NODES=y
# CONFIG_NUMA_EMU is not set
CONFIG_NODES_SHIFT=6
CONFIG_ARCH_SPARSEMEM_ENABLE=y
CONFIG_ARCH_SPARSEMEM_DEFAULT=y
CONFIG_ARCH_SELECT_MEMORY_MODEL=y
CONFIG_ARCH_PROC_KCORE_TEXT=y
CONFIG_ILLEGAL_POINTER_VALUE=0xdead000000000000
# CONFIG_X86_PMEM_LEGACY is not set
CONFIG_X86_CHECK_BIOS_CORRUPTION=y
CONFIG_X86_BOOTPARAM_MEMORY_CORRUPTION_CHECK=y
CONFIG_X86_RESERVE_LOW=64
CONFIG_MTRR=y
# CONFIG_MTRR_SANITIZER is not set
CONFIG_X86_PAT=y
CONFIG_ARCH_USES_PG_UNCACHED=y
CONFIG_ARCH_RANDOM=y
CONFIG_X86_SMAP=y
CONFIG_X86_INTEL_UMIP=y
# CONFIG_X86_INTEL_MPX is not set
CONFIG_X86_INTEL_MEMORY_PROTECTION_KEYS=y
CONFIG_EFI=y
# CONFIG_EFI_STUB is not set
CONFIG_SECCOMP=y
# CONFIG_HZ_100 is not set
# CONFIG_HZ_250 is not set
# CONFIG_HZ_300 is not set
CONFIG_HZ_1000=y
CONFIG_HZ=1000
CONFIG_SCHED_HRTICK=y
CONFIG_KEXEC=y
# CONFIG_KEXEC_FILE is not set
CONFIG_CRASH_DUMP=y
# CONFIG_KEXEC_JUMP is not set
CONFIG_PHYSICAL_START=0x1000000
CONFIG_RELOCATABLE=y
# CONFIG_RANDOMIZE_BASE is not set
CONFIG_PHYSICAL_ALIGN=0x200000
CONFIG_HOTPLUG_CPU=y
# CONFIG_BOOTPARAM_HOTPLUG_CPU0 is not set
# CONFIG_DEBUG_HOTPLUG_CPU0 is not set
# CONFIG_COMPAT_VDSO is not set
CONFIG_LEGACY_VSYSCALL_EMULATE=y
# CONFIG_LEGACY_VSYSCALL_NONE is not set
# CONFIG_CMDLINE_BOOL is not set
CONFIG_MODIFY_LDT_SYSCALL=y
CONFIG_HAVE_LIVEPATCH=y
CONFIG_ARCH_HAS_ADD_PAGES=y
CONFIG_ARCH_ENABLE_MEMORY_HOTPLUG=y
CONFIG_USE_PERCPU_NUMA_NODE_ID=y
CONFIG_ARCH_ENABLE_SPLIT_PMD_PTLOCK=y
CONFIG_ARCH_ENABLE_HUGEPAGE_MIGRATION=y

#
# Power management and ACPI options
#
CONFIG_ARCH_HIBERNATION_HEADER=y
CONFIG_SUSPEND=y
CONFIG_SUSPEND_FREEZER=y
CONFIG_HIBERNATE_CALLBACKS=y
CONFIG_HIBERNATION=y
CONFIG_PM_STD_PARTITION=""
CONFIG_PM_SLEEP=y
CONFIG_PM_SLEEP_SMP=y
# CONFIG_PM_AUTOSLEEP is not set
# CONFIG_PM_WAKELOCKS is not set
CONFIG_PM=y
CONFIG_PM_DEBUG=y
# CONFIG_PM_ADVANCED_DEBUG is not set
# CONFIG_PM_TEST_SUSPEND is not set
CONFIG_PM_SLEEP_DEBUG=y
CONFIG_PM_TRACE=y
CONFIG_PM_TRACE_RTC=y
CONFIG_PM_CLK=y
# CONFIG_WQ_POWER_EFFICIENT_DEFAULT is not set
# CONFIG_ENERGY_MODEL is not set
CONFIG_ARCH_SUPPORTS_ACPI=y
CONFIG_ACPI=y
CONFIG_ACPI_LEGACY_TABLES_LOOKUP=y
CONFIG_ARCH_MIGHT_HAVE_ACPI_PDC=y
CONFIG_ACPI_SYSTEM_POWER_STATES_SUPPORT=y
# CONFIG_ACPI_DEBUGGER is not set
CONFIG_ACPI_SPCR_TABLE=y
CONFIG_ACPI_LPIT=y
CONFIG_ACPI_SLEEP=y
# CONFIG_ACPI_PROCFS_POWER is not set
CONFIG_ACPI_REV_OVERRIDE_POSSIBLE=y
# CONFIG_ACPI_EC_DEBUGFS is not set
CONFIG_ACPI_AC=y
CONFIG_ACPI_BATTERY=y
CONFIG_ACPI_BUTTON=y
CONFIG_ACPI_VIDEO=y
CONFIG_ACPI_FAN=y
# CONFIG_ACPI_TAD is not set
CONFIG_ACPI_DOCK=y
CONFIG_ACPI_CPU_FREQ_PSS=y
CONFIG_ACPI_PROCESSOR_CSTATE=y
CONFIG_ACPI_PROCESSOR_IDLE=y
CONFIG_ACPI_CPPC_LIB=y
CONFIG_ACPI_PROCESSOR=y
CONFIG_ACPI_HOTPLUG_CPU=y
# CONFIG_ACPI_PROCESSOR_AGGREGATOR is not set
CONFIG_ACPI_THERMAL=y
CONFIG_ACPI_NUMA=y
CONFIG_ARCH_HAS_ACPI_TABLE_UPGRADE=y
CONFIG_ACPI_TABLE_UPGRADE=y
# CONFIG_ACPI_DEBUG is not set
# CONFIG_ACPI_PCI_SLOT is not set
CONFIG_ACPI_CONTAINER=y
CONFIG_ACPI_HOTPLUG_IOAPIC=y
# CONFIG_ACPI_SBS is not set
# CONFIG_ACPI_HED is not set
# CONFIG_ACPI_CUSTOM_METHOD is not set
# CONFIG_ACPI_BGRT is not set
# CONFIG_ACPI_NFIT is not set
CONFIG_HAVE_ACPI_APEI=y
CONFIG_HAVE_ACPI_APEI_NMI=y
# CONFIG_ACPI_APEI is not set
# CONFIG_DPTF_POWER is not set
# CONFIG_ACPI_EXTLOG is not set
# CONFIG_PMIC_OPREGION is not set
# CONFIG_ACPI_CONFIGFS is not set
CONFIG_X86_PM_TIMER=y
# CONFIG_SFI is not set

#
# CPU Frequency scaling
#
CONFIG_CPU_FREQ=y
CONFIG_CPU_FREQ_GOV_ATTR_SET=y
CONFIG_CPU_FREQ_GOV_COMMON=y
# CONFIG_CPU_FREQ_STAT is not set
# CONFIG_CPU_FREQ_DEFAULT_GOV_PERFORMANCE is not set
# CONFIG_CPU_FREQ_DEFAULT_GOV_POWERSAVE is not set
CONFIG_CPU_FREQ_DEFAULT_GOV_USERSPACE=y
# CONFIG_CPU_FREQ_DEFAULT_GOV_ONDEMAND is not set
# CONFIG_CPU_FREQ_DEFAULT_GOV_CONSERVATIVE is not set
# CONFIG_CPU_FREQ_DEFAULT_GOV_SCHEDUTIL is not set
CONFIG_CPU_FREQ_GOV_PERFORMANCE=y
# CONFIG_CPU_FREQ_GOV_POWERSAVE is not set
CONFIG_CPU_FREQ_GOV_USERSPACE=y
CONFIG_CPU_FREQ_GOV_ONDEMAND=y
# CONFIG_CPU_FREQ_GOV_CONSERVATIVE is not set
# CONFIG_CPU_FREQ_GOV_SCHEDUTIL is not set

#
# CPU frequency scaling drivers
#
CONFIG_X86_INTEL_PSTATE=y
# CONFIG_X86_PCC_CPUFREQ is not set
CONFIG_X86_ACPI_CPUFREQ=y
CONFIG_X86_ACPI_CPUFREQ_CPB=y
# CONFIG_X86_POWERNOW_K8 is not set
# CONFIG_X86_AMD_FREQ_SENSITIVITY is not set
# CONFIG_X86_SPEEDSTEP_CENTRINO is not set
# CONFIG_X86_P4_CLOCKMOD is not set

#
# shared options
#

#
# CPU Idle
#
CONFIG_CPU_IDLE=y
# CONFIG_CPU_IDLE_GOV_LADDER is not set
CONFIG_CPU_IDLE_GOV_MENU=y
# CONFIG_INTEL_IDLE is not set

#
# Bus options (PCI etc.)
#
CONFIG_PCI_DIRECT=y
CONFIG_PCI_MMCONFIG=y
CONFIG_MMCONF_FAM10H=y
CONFIG_ISA_DMA_API=y
CONFIG_AMD_NB=y
# CONFIG_X86_SYSFB is not set

#
# Binary Emulations
#
CONFIG_IA32_EMULATION=y
# CONFIG_IA32_AOUT is not set
# CONFIG_X86_X32 is not set
CONFIG_COMPAT_32=y
CONFIG_COMPAT=y
CONFIG_COMPAT_FOR_U64_ALIGNMENT=y
CONFIG_SYSVIPC_COMPAT=y
CONFIG_X86_DEV_DMA_OPS=y
CONFIG_HAVE_GENERIC_GUP=y

#
# Firmware Drivers
#
# CONFIG_EDD is not set
CONFIG_FIRMWARE_MEMMAP=y
CONFIG_DMIID=y
# CONFIG_DMI_SYSFS is not set
CONFIG_DMI_SCAN_MACHINE_NON_EFI_FALLBACK=y
# CONFIG_ISCSI_IBFT_FIND is not set
# CONFIG_FW_CFG_SYSFS is not set
# CONFIG_GOOGLE_FIRMWARE is not set

#
# EFI (Extensible Firmware Interface) Support
#
CONFIG_EFI_VARS=y
CONFIG_EFI_ESRT=y
CONFIG_EFI_RUNTIME_MAP=y
# CONFIG_EFI_FAKE_MEMMAP is not set
CONFIG_EFI_RUNTIME_WRAPPERS=y
# CONFIG_EFI_BOOTLOADER_CONTROL is not set
# CONFIG_EFI_CAPSULE_LOADER is not set
# CONFIG_EFI_TEST is not set

#
# Tegra firmware driver
#
CONFIG_HAVE_KVM=y
CONFIG_VIRTUALIZATION=y
# CONFIG_KVM is not set
# CONFIG_VHOST_NET is not set
# CONFIG_VHOST_CROSS_ENDIAN_LEGACY is not set

#
# General architecture-dependent options
#
CONFIG_CRASH_CORE=y
CONFIG_KEXEC_CORE=y
CONFIG_HOTPLUG_SMT=y
# CONFIG_OPROFILE is not set
CONFIG_HAVE_OPROFILE=y
CONFIG_OPROFILE_NMI_TIMER=y
CONFIG_KPROBES=y
CONFIG_JUMP_LABEL=y
# CONFIG_STATIC_KEYS_SELFTEST is not set
CONFIG_OPTPROBES=y
CONFIG_UPROBES=y
CONFIG_HAVE_EFFICIENT_UNALIGNED_ACCESS=y
CONFIG_ARCH_USE_BUILTIN_BSWAP=y
CONFIG_KRETPROBES=y
CONFIG_HAVE_IOREMAP_PROT=y
CONFIG_HAVE_KPROBES=y
CONFIG_HAVE_KRETPROBES=y
CONFIG_HAVE_OPTPROBES=y
CONFIG_HAVE_KPROBES_ON_FTRACE=y
CONFIG_HAVE_FUNCTION_ERROR_INJECTION=y
CONFIG_HAVE_NMI=y
CONFIG_HAVE_ARCH_TRACEHOOK=y
CONFIG_HAVE_DMA_CONTIGUOUS=y
CONFIG_GENERIC_SMP_IDLE_THREAD=y
CONFIG_ARCH_HAS_FORTIFY_SOURCE=y
CONFIG_ARCH_HAS_SET_MEMORY=y
CONFIG_HAVE_ARCH_THREAD_STRUCT_WHITELIST=y
CONFIG_ARCH_WANTS_DYNAMIC_TASK_STRUCT=y
CONFIG_HAVE_REGS_AND_STACK_ACCESS_API=y
CONFIG_HAVE_RSEQ=y
CONFIG_HAVE_FUNCTION_ARG_ACCESS_API=y
CONFIG_HAVE_CLK=y
CONFIG_HAVE_HW_BREAKPOINT=y
CONFIG_HAVE_MIXED_BREAKPOINTS_REGS=y
CONFIG_HAVE_USER_RETURN_NOTIFIER=y
CONFIG_HAVE_PERF_EVENTS_NMI=y
CONFIG_HAVE_HARDLOCKUP_DETECTOR_PERF=y
CONFIG_HAVE_PERF_REGS=y
CONFIG_HAVE_PERF_USER_STACK_DUMP=y
CONFIG_HAVE_ARCH_JUMP_LABEL=y
CONFIG_HAVE_ARCH_JUMP_LABEL_RELATIVE=y
CONFIG_HAVE_RCU_TABLE_FREE=y
CONFIG_HAVE_RCU_TABLE_INVALIDATE=y
CONFIG_ARCH_HAVE_NMI_SAFE_CMPXCHG=y
CONFIG_HAVE_CMPXCHG_LOCAL=y
CONFIG_HAVE_CMPXCHG_DOUBLE=y
CONFIG_ARCH_WANT_COMPAT_IPC_PARSE_VERSION=y
CONFIG_ARCH_WANT_OLD_COMPAT_IPC=y
CONFIG_HAVE_ARCH_SECCOMP_FILTER=y
CONFIG_SECCOMP_FILTER=y
CONFIG_HAVE_ARCH_STACKLEAK=y
CONFIG_HAVE_STACKPROTECTOR=y
CONFIG_CC_HAS_STACKPROTECTOR_NONE=y
CONFIG_STACKPROTECTOR=y
CONFIG_STACKPROTECTOR_STRONG=y
CONFIG_HAVE_ARCH_WITHIN_STACK_FRAMES=y
CONFIG_HAVE_CONTEXT_TRACKING=y
CONFIG_HAVE_VIRT_CPU_ACCOUNTING_GEN=y
CONFIG_HAVE_IRQ_TIME_ACCOUNTING=y
CONFIG_HAVE_MOVE_PMD=y
CONFIG_HAVE_ARCH_TRANSPARENT_HUGEPAGE=y
CONFIG_HAVE_ARCH_TRANSPARENT_HUGEPAGE_PUD=y
CONFIG_HAVE_ARCH_HUGE_VMAP=y
CONFIG_HAVE_ARCH_SOFT_DIRTY=y
CONFIG_HAVE_MOD_ARCH_SPECIFIC=y
CONFIG_MODULES_USE_ELF_RELA=y
CONFIG_HAVE_IRQ_EXIT_ON_IRQ_STACK=y
CONFIG_ARCH_HAS_ELF_RANDOMIZE=y
CONFIG_HAVE_ARCH_MMAP_RND_BITS=y
CONFIG_HAVE_EXIT_THREAD=y
CONFIG_ARCH_MMAP_RND_BITS=28
CONFIG_HAVE_ARCH_MMAP_RND_COMPAT_BITS=y
CONFIG_ARCH_MMAP_RND_COMPAT_BITS=8
CONFIG_HAVE_ARCH_COMPAT_MMAP_BASES=y
CONFIG_HAVE_COPY_THREAD_TLS=y
CONFIG_HAVE_STACK_VALIDATION=y
CONFIG_HAVE_RELIABLE_STACKTRACE=y
CONFIG_OLD_SIGSUSPEND3=y
CONFIG_COMPAT_OLD_SIGACTION=y
CONFIG_COMPAT_32BIT_TIME=y
CONFIG_HAVE_ARCH_VMAP_STACK=y
CONFIG_ARCH_HAS_STRICT_KERNEL_RWX=y
CONFIG_STRICT_KERNEL_RWX=y
CONFIG_ARCH_HAS_STRICT_MODULE_RWX=y
CONFIG_STRICT_MODULE_RWX=y
CONFIG_ARCH_HAS_REFCOUNT=y
CONFIG_REFCOUNT_FULL=y
CONFIG_HAVE_ARCH_PREL32_RELOCATIONS=y

#
# GCOV-based kernel profiling
#
# CONFIG_GCOV_KERNEL is not set
CONFIG_ARCH_HAS_GCOV_PROFILE_ALL=y
CONFIG_PLUGIN_HOSTCC="g++"
CONFIG_HAVE_GCC_PLUGINS=y
CONFIG_GCC_PLUGINS=y
# CONFIG_GCC_PLUGIN_LATENT_ENTROPY is not set
# CONFIG_GCC_PLUGIN_STRUCTLEAK is not set
# CONFIG_GCC_PLUGIN_RANDSTRUCT is not set
# CONFIG_GCC_PLUGIN_STACKLEAK is not set
CONFIG_RT_MUTEXES=y
CONFIG_BASE_SMALL=0
CONFIG_MODULES=y
# CONFIG_MODULE_FORCE_LOAD is not set
CONFIG_MODULE_UNLOAD=y
CONFIG_MODULE_FORCE_UNLOAD=y
# CONFIG_MODVERSIONS is not set
# CONFIG_MODULE_SRCVERSION_ALL is not set
# CONFIG_MODULE_SIG is not set
# CONFIG_MODULE_COMPRESS is not set
# CONFIG_TRIM_UNUSED_KSYMS is not set
CONFIG_MODULES_TREE_LOOKUP=y
CONFIG_BLOCK=y
CONFIG_BLK_SCSI_REQUEST=y
CONFIG_BLK_DEV_BSG=y
# CONFIG_BLK_DEV_BSGLIB is not set
# CONFIG_BLK_DEV_INTEGRITY is not set
# CONFIG_BLK_DEV_ZONED is not set
# CONFIG_BLK_CMDLINE_PARSER is not set
# CONFIG_BLK_WBT is not set
CONFIG_BLK_DEBUG_FS=y
# CONFIG_BLK_SED_OPAL is not set

#
# Partition Types
#
CONFIG_PARTITION_ADVANCED=y
# CONFIG_ACORN_PARTITION is not set
# CONFIG_AIX_PARTITION is not set
CONFIG_OSF_PARTITION=y
CONFIG_AMIGA_PARTITION=y
# CONFIG_ATARI_PARTITION is not set
CONFIG_MAC_PARTITION=y
CONFIG_MSDOS_PARTITION=y
CONFIG_BSD_DISKLABEL=y
CONFIG_MINIX_SUBPARTITION=y
CONFIG_SOLARIS_X86_PARTITION=y
CONFIG_UNIXWARE_DISKLABEL=y
# CONFIG_LDM_PARTITION is not set
CONFIG_SGI_PARTITION=y
# CONFIG_ULTRIX_PARTITION is not set
CONFIG_SUN_PARTITION=y
CONFIG_KARMA_PARTITION=y
CONFIG_EFI_PARTITION=y
# CONFIG_SYSV68_PARTITION is not set
# CONFIG_CMDLINE_PARTITION is not set
CONFIG_BLOCK_COMPAT=y
CONFIG_BLK_MQ_PCI=y
CONFIG_BLK_MQ_VIRTIO=y
CONFIG_BLK_PM=y

#
# IO Schedulers
#
CONFIG_MQ_IOSCHED_DEADLINE=y
CONFIG_MQ_IOSCHED_KYBER=y
# CONFIG_IOSCHED_BFQ is not set
CONFIG_ASN1=y
CONFIG_UNINLINE_SPIN_UNLOCK=y
CONFIG_ARCH_SUPPORTS_ATOMIC_RMW=y
CONFIG_MUTEX_SPIN_ON_OWNER=y
CONFIG_RWSEM_SPIN_ON_OWNER=y
CONFIG_LOCK_SPIN_ON_OWNER=y
CONFIG_ARCH_USE_QUEUED_SPINLOCKS=y
CONFIG_QUEUED_SPINLOCKS=y
CONFIG_ARCH_USE_QUEUED_RWLOCKS=y
CONFIG_QUEUED_RWLOCKS=y
CONFIG_ARCH_HAS_SYNC_CORE_BEFORE_USERMODE=y
CONFIG_ARCH_HAS_SYSCALL_WRAPPER=y
CONFIG_FREEZER=y

#
# Executable file formats
#
CONFIG_BINFMT_ELF=y
CONFIG_COMPAT_BINFMT_ELF=y
CONFIG_ELFCORE=y
CONFIG_CORE_DUMP_DEFAULT_ELF_HEADERS=y
CONFIG_BINFMT_SCRIPT=y
CONFIG_BINFMT_MISC=y
CONFIG_COREDUMP=y

#
# Memory Management options
#
CONFIG_SELECT_MEMORY_MODEL=y
CONFIG_SPARSEMEM_MANUAL=y
CONFIG_SPARSEMEM=y
CONFIG_NEED_MULTIPLE_NODES=y
CONFIG_HAVE_MEMORY_PRESENT=y
CONFIG_SPARSEMEM_EXTREME=y
CONFIG_SPARSEMEM_VMEMMAP_ENABLE=y
CONFIG_SPARSEMEM_VMEMMAP=y
CONFIG_HAVE_MEMBLOCK_NODE_MAP=y
CONFIG_ARCH_DISCARD_MEMBLOCK=y
# CONFIG_MEMORY_HOTPLUG is not set
CONFIG_SPLIT_PTLOCK_CPUS=4
CONFIG_COMPACTION=y
CONFIG_MIGRATION=y
CONFIG_PHYS_ADDR_T_64BIT=y
CONFIG_BOUNCE=y
CONFIG_VIRT_TO_BUS=y
CONFIG_MMU_NOTIFIER=y
# CONFIG_KSM is not set
CONFIG_DEFAULT_MMAP_MIN_ADDR=4096
CONFIG_ARCH_SUPPORTS_MEMORY_FAILURE=y
# CONFIG_MEMORY_FAILURE is not set
# CONFIG_TRANSPARENT_HUGEPAGE is not set
CONFIG_ARCH_WANTS_THP_SWAP=y
# CONFIG_CLEANCACHE is not set
# CONFIG_FRONTSWAP is not set
# CONFIG_CMA is not set
# CONFIG_ZPOOL is not set
# CONFIG_ZBUD is not set
# CONFIG_ZSMALLOC is not set
CONFIG_GENERIC_EARLY_IOREMAP=y
# CONFIG_DEFERRED_STRUCT_PAGE_INIT is not set
# CONFIG_IDLE_PAGE_TRACKING is not set
CONFIG_ARCH_HAS_ZONE_DEVICE=y
CONFIG_ARCH_USES_HIGH_VMA_FLAGS=y
CONFIG_ARCH_HAS_PKEYS=y
# CONFIG_PERCPU_STATS is not set
# CONFIG_GUP_BENCHMARK is not set
CONFIG_ARCH_HAS_PTE_SPECIAL=y
CONFIG_NET=y
CONFIG_NET_INGRESS=y
CONFIG_SKB_EXTENSIONS=y

#
# Networking options
#
CONFIG_PACKET=y
# CONFIG_PACKET_DIAG is not set
CONFIG_UNIX=y
# CONFIG_UNIX_DIAG is not set
# CONFIG_TLS is not set
CONFIG_XFRM=y
CONFIG_XFRM_ALGO=y
CONFIG_XFRM_USER=y
# CONFIG_XFRM_INTERFACE is not set
# CONFIG_XFRM_SUB_POLICY is not set
# CONFIG_XFRM_MIGRATE is not set
# CONFIG_XFRM_STATISTICS is not set
# CONFIG_NET_KEY is not set
CONFIG_INET=y
CONFIG_IP_MULTICAST=y
CONFIG_IP_ADVANCED_ROUTER=y
# CONFIG_IP_FIB_TRIE_STATS is not set
CONFIG_IP_MULTIPLE_TABLES=y
CONFIG_IP_ROUTE_MULTIPATH=y
CONFIG_IP_ROUTE_VERBOSE=y
CONFIG_IP_PNP=y
CONFIG_IP_PNP_DHCP=y
CONFIG_IP_PNP_BOOTP=y
CONFIG_IP_PNP_RARP=y
# CONFIG_NET_IPIP is not set
# CONFIG_NET_IPGRE_DEMUX is not set
CONFIG_NET_IP_TUNNEL=y
CONFIG_IP_MROUTE_COMMON=y
CONFIG_IP_MROUTE=y
# CONFIG_IP_MROUTE_MULTIPLE_TABLES is not set
CONFIG_IP_PIMSM_V1=y
CONFIG_IP_PIMSM_V2=y
CONFIG_SYN_COOKIES=y
# CONFIG_NET_FOU is not set
# CONFIG_NET_FOU_IP_TUNNELS is not set
# CONFIG_INET_AH is not set
# CONFIG_INET_ESP is not set
# CONFIG_INET_IPCOMP is not set
CONFIG_INET_TUNNEL=y
# CONFIG_INET_XFRM_MODE_TRANSPORT is not set
# CONFIG_INET_XFRM_MODE_TUNNEL is not set
# CONFIG_INET_XFRM_MODE_BEET is not set
# CONFIG_INET_DIAG is not set
CONFIG_TCP_CONG_ADVANCED=y
# CONFIG_TCP_CONG_BIC is not set
CONFIG_TCP_CONG_CUBIC=y
# CONFIG_TCP_CONG_WESTWOOD is not set
# CONFIG_TCP_CONG_HTCP is not set
# CONFIG_TCP_CONG_HSTCP is not set
# CONFIG_TCP_CONG_HYBLA is not set
# CONFIG_TCP_CONG_VEGAS is not set
# CONFIG_TCP_CONG_NV is not set
# CONFIG_TCP_CONG_SCALABLE is not set
# CONFIG_TCP_CONG_LP is not set
# CONFIG_TCP_CONG_VENO is not set
# CONFIG_TCP_CONG_YEAH is not set
# CONFIG_TCP_CONG_ILLINOIS is not set
# CONFIG_TCP_CONG_DCTCP is not set
# CONFIG_TCP_CONG_CDG is not set
# CONFIG_TCP_CONG_BBR is not set
CONFIG_DEFAULT_CUBIC=y
# CONFIG_DEFAULT_RENO is not set
CONFIG_DEFAULT_TCP_CONG="cubic"
CONFIG_TCP_MD5SIG=y
CONFIG_IPV6=y
# CONFIG_IPV6_ROUTER_PREF is not set
# CONFIG_IPV6_OPTIMISTIC_DAD is not set
CONFIG_INET6_AH=y
CONFIG_INET6_ESP=y
# CONFIG_INET6_ESP_OFFLOAD is not set
# CONFIG_INET6_IPCOMP is not set
# CONFIG_IPV6_MIP6 is not set
# CONFIG_IPV6_ILA is not set
CONFIG_INET6_XFRM_MODE_TRANSPORT=y
CONFIG_INET6_XFRM_MODE_TUNNEL=y
CONFIG_INET6_XFRM_MODE_BEET=y
# CONFIG_INET6_XFRM_MODE_ROUTEOPTIMIZATION is not set
# CONFIG_IPV6_VTI is not set
CONFIG_IPV6_SIT=y
# CONFIG_IPV6_SIT_6RD is not set
CONFIG_IPV6_NDISC_NODETYPE=y
# CONFIG_IPV6_TUNNEL is not set
# CONFIG_IPV6_MULTIPLE_TABLES is not set
# CONFIG_IPV6_MROUTE is not set
# CONFIG_IPV6_SEG6_LWTUNNEL is not set
# CONFIG_IPV6_SEG6_HMAC is not set
CONFIG_NETLABEL=y
CONFIG_NETWORK_SECMARK=y
CONFIG_NET_PTP_CLASSIFY=y
# CONFIG_NETWORK_PHY_TIMESTAMPING is not set
CONFIG_NETFILTER=y
# CONFIG_NETFILTER_ADVANCED is not set

#
# Core Netfilter Configuration
#
CONFIG_NETFILTER_INGRESS=y
CONFIG_NETFILTER_NETLINK=y
CONFIG_NETFILTER_NETLINK_LOG=y
CONFIG_NF_CONNTRACK=y
CONFIG_NF_LOG_COMMON=m
# CONFIG_NF_LOG_NETDEV is not set
CONFIG_NF_CONNTRACK_SECMARK=y
CONFIG_NF_CONNTRACK_PROCFS=y
# CONFIG_NF_CONNTRACK_LABELS is not set
CONFIG_NF_CONNTRACK_FTP=y
CONFIG_NF_CONNTRACK_IRC=y
# CONFIG_NF_CONNTRACK_NETBIOS_NS is not set
CONFIG_NF_CONNTRACK_SIP=y
CONFIG_NF_CT_NETLINK=y
# CONFIG_NETFILTER_NETLINK_GLUE_CT is not set
CONFIG_NF_NAT=m
CONFIG_NF_NAT_NEEDED=y
CONFIG_NF_NAT_FTP=m
CONFIG_NF_NAT_IRC=m
CONFIG_NF_NAT_SIP=m
# CONFIG_NF_TABLES is not set
CONFIG_NETFILTER_XTABLES=y

#
# Xtables combined modules
#
CONFIG_NETFILTER_XT_MARK=m

#
# Xtables targets
#
CONFIG_NETFILTER_XT_TARGET_CONNSECMARK=y
CONFIG_NETFILTER_XT_TARGET_LOG=m
CONFIG_NETFILTER_XT_NAT=m
# CONFIG_NETFILTER_XT_TARGET_NETMAP is not set
CONFIG_NETFILTER_XT_TARGET_NFLOG=y
# CONFIG_NETFILTER_XT_TARGET_REDIRECT is not set
CONFIG_NETFILTER_XT_TARGET_SECMARK=y
CONFIG_NETFILTER_XT_TARGET_TCPMSS=y

#
# Xtables matches
#
CONFIG_NETFILTER_XT_MATCH_ADDRTYPE=m
CONFIG_NETFILTER_XT_MATCH_CONNTRACK=y
CONFIG_NETFILTER_XT_MATCH_POLICY=y
CONFIG_NETFILTER_XT_MATCH_STATE=y
# CONFIG_IP_SET is not set
# CONFIG_IP_VS is not set

#
# IP: Netfilter Configuration
#
CONFIG_NF_DEFRAG_IPV4=y
# CONFIG_NF_SOCKET_IPV4 is not set
# CONFIG_NF_TPROXY_IPV4 is not set
# CONFIG_NF_DUP_IPV4 is not set
CONFIG_NF_LOG_ARP=m
CONFIG_NF_LOG_IPV4=m
CONFIG_NF_REJECT_IPV4=y
CONFIG_NF_NAT_IPV4=m
CONFIG_NF_NAT_MASQUERADE_IPV4=y
CONFIG_IP_NF_IPTABLES=y
CONFIG_IP_NF_FILTER=y
CONFIG_IP_NF_TARGET_REJECT=y
CONFIG_IP_NF_NAT=m
CONFIG_IP_NF_TARGET_MASQUERADE=m
CONFIG_IP_NF_MANGLE=y
# CONFIG_IP_NF_RAW is not set

#
# IPv6: Netfilter Configuration
#
# CONFIG_NF_SOCKET_IPV6 is not set
# CONFIG_NF_TPROXY_IPV6 is not set
# CONFIG_NF_DUP_IPV6 is not set
CONFIG_NF_REJECT_IPV6=y
CONFIG_NF_LOG_IPV6=m
CONFIG_IP6_NF_IPTABLES=y
CONFIG_IP6_NF_MATCH_IPV6HEADER=y
CONFIG_IP6_NF_FILTER=y
CONFIG_IP6_NF_TARGET_REJECT=y
CONFIG_IP6_NF_MANGLE=y
# CONFIG_IP6_NF_RAW is not set
CONFIG_NF_DEFRAG_IPV6=y
# CONFIG_BPFILTER is not set
# CONFIG_IP_DCCP is not set
# CONFIG_IP_SCTP is not set
# CONFIG_RDS is not set
# CONFIG_TIPC is not set
# CONFIG_ATM is not set
# CONFIG_L2TP is not set
# CONFIG_BRIDGE is not set
CONFIG_HAVE_NET_DSA=y
# CONFIG_NET_DSA is not set
# CONFIG_VLAN_8021Q is not set
# CONFIG_DECNET is not set
# CONFIG_LLC2 is not set
# CONFIG_ATALK is not set
# CONFIG_X25 is not set
# CONFIG_LAPB is not set
# CONFIG_PHONET is not set
# CONFIG_6LOWPAN is not set
# CONFIG_IEEE802154 is not set
CONFIG_NET_SCHED=y

#
# Queueing/Scheduling
#
# CONFIG_NET_SCH_CBQ is not set
# CONFIG_NET_SCH_HTB is not set
# CONFIG_NET_SCH_HFSC is not set
# CONFIG_NET_SCH_PRIO is not set
# CONFIG_NET_SCH_MULTIQ is not set
# CONFIG_NET_SCH_RED is not set
# CONFIG_NET_SCH_SFB is not set
# CONFIG_NET_SCH_SFQ is not set
# CONFIG_NET_SCH_TEQL is not set
# CONFIG_NET_SCH_TBF is not set
# CONFIG_NET_SCH_CBS is not set
# CONFIG_NET_SCH_ETF is not set
# CONFIG_NET_SCH_TAPRIO is not set
# CONFIG_NET_SCH_GRED is not set
# CONFIG_NET_SCH_DSMARK is not set
# CONFIG_NET_SCH_NETEM is not set
# CONFIG_NET_SCH_DRR is not set
# CONFIG_NET_SCH_MQPRIO is not set
# CONFIG_NET_SCH_SKBPRIO is not set
# CONFIG_NET_SCH_CHOKE is not set
# CONFIG_NET_SCH_QFQ is not set
# CONFIG_NET_SCH_CODEL is not set
# CONFIG_NET_SCH_FQ_CODEL is not set
# CONFIG_NET_SCH_CAKE is not set
# CONFIG_NET_SCH_FQ is not set
# CONFIG_NET_SCH_HHF is not set
# CONFIG_NET_SCH_PIE is not set
# CONFIG_NET_SCH_INGRESS is not set
# CONFIG_NET_SCH_PLUG is not set
# CONFIG_NET_SCH_DEFAULT is not set

#
# Classification
#
CONFIG_NET_CLS=y
# CONFIG_NET_CLS_BASIC is not set
# CONFIG_NET_CLS_TCINDEX is not set
# CONFIG_NET_CLS_ROUTE4 is not set
# CONFIG_NET_CLS_FW is not set
# CONFIG_NET_CLS_U32 is not set
# CONFIG_NET_CLS_RSVP is not set
# CONFIG_NET_CLS_RSVP6 is not set
# CONFIG_NET_CLS_FLOW is not set
# CONFIG_NET_CLS_CGROUP is not set
# CONFIG_NET_CLS_BPF is not set
# CONFIG_NET_CLS_FLOWER is not set
# CONFIG_NET_CLS_MATCHALL is not set
CONFIG_NET_EMATCH=y
CONFIG_NET_EMATCH_STACK=32
# CONFIG_NET_EMATCH_CMP is not set
# CONFIG_NET_EMATCH_NBYTE is not set
# CONFIG_NET_EMATCH_U32 is not set
# CONFIG_NET_EMATCH_META is not set
# CONFIG_NET_EMATCH_TEXT is not set
# CONFIG_NET_EMATCH_IPT is not set
CONFIG_NET_CLS_ACT=y
# CONFIG_NET_ACT_POLICE is not set
# CONFIG_NET_ACT_GACT is not set
# CONFIG_NET_ACT_MIRRED is not set
# CONFIG_NET_ACT_SAMPLE is not set
# CONFIG_NET_ACT_IPT is not set
# CONFIG_NET_ACT_NAT is not set
# CONFIG_NET_ACT_PEDIT is not set
# CONFIG_NET_ACT_SIMP is not set
# CONFIG_NET_ACT_SKBEDIT is not set
# CONFIG_NET_ACT_CSUM is not set
# CONFIG_NET_ACT_VLAN is not set
# CONFIG_NET_ACT_BPF is not set
# CONFIG_NET_ACT_SKBMOD is not set
# CONFIG_NET_ACT_IFE is not set
# CONFIG_NET_ACT_TUNNEL_KEY is not set
CONFIG_NET_SCH_FIFO=y
# CONFIG_DCB is not set
CONFIG_DNS_RESOLVER=y
# CONFIG_BATMAN_ADV is not set
# CONFIG_OPENVSWITCH is not set
# CONFIG_VSOCKETS is not set
# CONFIG_NETLINK_DIAG is not set
# CONFIG_MPLS is not set
# CONFIG_NET_NSH is not set
# CONFIG_HSR is not set
# CONFIG_NET_SWITCHDEV is not set
# CONFIG_NET_L3_MASTER_DEV is not set
# CONFIG_NET_NCSI is not set
CONFIG_RPS=y
CONFIG_RFS_ACCEL=y
CONFIG_XPS=y
# CONFIG_CGROUP_NET_PRIO is not set
# CONFIG_CGROUP_NET_CLASSID is not set
CONFIG_NET_RX_BUSY_POLL=y
CONFIG_BQL=y
# CONFIG_BPF_JIT is not set
CONFIG_NET_FLOW_LIMIT=y

#
# Network testing
#
# CONFIG_NET_PKTGEN is not set
# CONFIG_NET_DROP_MONITOR is not set
CONFIG_HAMRADIO=y

#
# Packet Radio protocols
#
# CONFIG_AX25 is not set
# CONFIG_CAN is not set
# CONFIG_BT is not set
# CONFIG_AF_RXRPC is not set
# CONFIG_AF_KCM is not set
CONFIG_FIB_RULES=y
CONFIG_WIRELESS=y
CONFIG_CFG80211=y
# CONFIG_NL80211_TESTMODE is not set
# CONFIG_CFG80211_DEVELOPER_WARNINGS is not set
CONFIG_CFG80211_REQUIRE_SIGNED_REGDB=y
CONFIG_CFG80211_USE_KERNEL_REGDB_KEYS=y
CONFIG_CFG80211_DEFAULT_PS=y
# CONFIG_CFG80211_DEBUGFS is not set
CONFIG_CFG80211_CRDA_SUPPORT=y
# CONFIG_CFG80211_WEXT is not set
CONFIG_MAC80211=y
CONFIG_MAC80211_HAS_RC=y
CONFIG_MAC80211_RC_MINSTREL=y
CONFIG_MAC80211_RC_DEFAULT_MINSTREL=y
CONFIG_MAC80211_RC_DEFAULT="minstrel_ht"
# CONFIG_MAC80211_MESH is not set
CONFIG_MAC80211_LEDS=y
# CONFIG_MAC80211_DEBUGFS is not set
# CONFIG_MAC80211_MESSAGE_TRACING is not set
# CONFIG_MAC80211_DEBUG_MENU is not set
CONFIG_MAC80211_STA_HASH_MAX_SIZE=0
# CONFIG_WIMAX is not set
CONFIG_RFKILL=y
CONFIG_RFKILL_LEDS=y
CONFIG_RFKILL_INPUT=y
CONFIG_NET_9P=y
CONFIG_NET_9P_VIRTIO=y
# CONFIG_NET_9P_DEBUG is not set
# CONFIG_CAIF is not set
# CONFIG_CEPH_LIB is not set
# CONFIG_NFC is not set
# CONFIG_PSAMPLE is not set
# CONFIG_NET_IFE is not set
# CONFIG_LWTUNNEL is not set
CONFIG_DST_CACHE=y
CONFIG_GRO_CELLS=y
# CONFIG_NET_DEVLINK is not set
CONFIG_MAY_USE_DEVLINK=y
CONFIG_FAILOVER=y
CONFIG_HAVE_EBPF_JIT=y

#
# Device Drivers
#
CONFIG_HAVE_EISA=y
# CONFIG_EISA is not set
CONFIG_HAVE_PCI=y
CONFIG_PCI=y
CONFIG_PCI_DOMAINS=y
CONFIG_PCIEPORTBUS=y
# CONFIG_HOTPLUG_PCI_PCIE is not set
CONFIG_PCIEAER=y
# CONFIG_PCIEAER_INJECT is not set
# CONFIG_PCIE_ECRC is not set
CONFIG_PCIEASPM=y
# CONFIG_PCIEASPM_DEBUG is not set
CONFIG_PCIEASPM_DEFAULT=y
# CONFIG_PCIEASPM_POWERSAVE is not set
# CONFIG_PCIEASPM_POWER_SUPERSAVE is not set
# CONFIG_PCIEASPM_PERFORMANCE is not set
CONFIG_PCIE_PME=y
# CONFIG_PCIE_DPC is not set
# CONFIG_PCIE_PTM is not set
CONFIG_PCI_MSI=y
CONFIG_PCI_MSI_IRQ_DOMAIN=y
CONFIG_PCI_QUIRKS=y
# CONFIG_PCI_DEBUG is not set
# CONFIG_PCI_STUB is not set
CONFIG_PCI_ATS=y
CONFIG_PCI_LOCKLESS_CONFIG=y
# CONFIG_PCI_IOV is not set
CONFIG_PCI_PRI=y
CONFIG_PCI_PASID=y
CONFIG_PCI_LABEL=y
CONFIG_HOTPLUG_PCI=y
# CONFIG_HOTPLUG_PCI_ACPI is not set
# CONFIG_HOTPLUG_PCI_CPCI is not set
# CONFIG_HOTPLUG_PCI_SHPC is not set

#
# PCI controller drivers
#

#
# Cadence PCIe controllers support
#
# CONFIG_VMD is not set

#
# DesignWare PCI Core Support
#
# CONFIG_PCIE_DW_PLAT_HOST is not set
# CONFIG_PCI_MESON is not set

#
# PCI Endpoint
#
# CONFIG_PCI_ENDPOINT is not set

#
# PCI switch controller drivers
#
# CONFIG_PCI_SW_SWITCHTEC is not set
CONFIG_PCCARD=y
CONFIG_PCMCIA=y
CONFIG_PCMCIA_LOAD_CIS=y
CONFIG_CARDBUS=y

#
# PC-card bridges
#
CONFIG_YENTA=y
CONFIG_YENTA_O2=y
CONFIG_YENTA_RICOH=y
CONFIG_YENTA_TI=y
CONFIG_YENTA_ENE_TUNE=y
CONFIG_YENTA_TOSHIBA=y
# CONFIG_PD6729 is not set
# CONFIG_I82092 is not set
CONFIG_PCCARD_NONSTATIC=y
# CONFIG_RAPIDIO is not set

#
# Generic Driver Options
#
CONFIG_UEVENT_HELPER=y
CONFIG_UEVENT_HELPER_PATH="/sbin/hotplug"
CONFIG_DEVTMPFS=y
CONFIG_DEVTMPFS_MOUNT=y
CONFIG_STANDALONE=y
CONFIG_PREVENT_FIRMWARE_BUILD=y

#
# Firmware loader
#
CONFIG_FW_LOADER=y
CONFIG_EXTRA_FIRMWARE=""
# CONFIG_FW_LOADER_USER_HELPER is not set
CONFIG_ALLOW_DEV_COREDUMP=y
# CONFIG_DEBUG_DRIVER is not set
CONFIG_DEBUG_DEVRES=y
# CONFIG_DEBUG_TEST_DRIVER_REMOVE is not set
# CONFIG_TEST_ASYNC_DRIVER_PROBE is not set
CONFIG_GENERIC_CPU_AUTOPROBE=y
CONFIG_GENERIC_CPU_VULNERABILITIES=y
CONFIG_REGMAP=y
CONFIG_REGMAP_I2C=y
CONFIG_DMA_SHARED_BUFFER=y
# CONFIG_DMA_FENCE_TRACE is not set

#
# Bus devices
#
CONFIG_CONNECTOR=y
CONFIG_PROC_EVENTS=y
# CONFIG_GNSS is not set
# CONFIG_MTD is not set
# CONFIG_OF is not set
CONFIG_ARCH_MIGHT_HAVE_PC_PARPORT=y
# CONFIG_PARPORT is not set
CONFIG_PNP=y
CONFIG_PNP_DEBUG_MESSAGES=y

#
# Protocols
#
CONFIG_PNPACPI=y
CONFIG_BLK_DEV=y
# CONFIG_BLK_DEV_NULL_BLK is not set
# CONFIG_BLK_DEV_FD is not set
CONFIG_CDROM=y
# CONFIG_BLK_DEV_PCIESSD_MTIP32XX is not set
# CONFIG_BLK_DEV_UMEM is not set
CONFIG_BLK_DEV_LOOP=y
CONFIG_BLK_DEV_LOOP_MIN_COUNT=8
# CONFIG_BLK_DEV_CRYPTOLOOP is not set
# CONFIG_BLK_DEV_DRBD is not set
# CONFIG_BLK_DEV_NBD is not set
# CONFIG_BLK_DEV_SKD is not set
# CONFIG_BLK_DEV_SX8 is not set
# CONFIG_BLK_DEV_RAM is not set
# CONFIG_CDROM_PKTCDVD is not set
# CONFIG_ATA_OVER_ETH is not set
CONFIG_VIRTIO_BLK=y
# CONFIG_VIRTIO_BLK_SCSI is not set
# CONFIG_BLK_DEV_RBD is not set
# CONFIG_BLK_DEV_RSXX is not set

#
# NVME Support
#
# CONFIG_BLK_DEV_NVME is not set
# CONFIG_NVME_FC is not set
# CONFIG_NVME_TARGET is not set

#
# Misc devices
#
# CONFIG_AD525X_DPOT is not set
# CONFIG_DUMMY_IRQ is not set
# CONFIG_IBM_ASM is not set
# CONFIG_PHANTOM is not set
# CONFIG_SGI_IOC4 is not set
# CONFIG_TIFM_CORE is not set
# CONFIG_ICS932S401 is not set
# CONFIG_ENCLOSURE_SERVICES is not set
# CONFIG_HP_ILO is not set
# CONFIG_APDS9802ALS is not set
# CONFIG_ISL29003 is not set
# CONFIG_ISL29020 is not set
# CONFIG_SENSORS_TSL2550 is not set
# CONFIG_SENSORS_BH1770 is not set
# CONFIG_SENSORS_APDS990X is not set
# CONFIG_HMC6352 is not set
# CONFIG_DS1682 is not set
# CONFIG_USB_SWITCH_FSA9480 is not set
# CONFIG_SRAM is not set
# CONFIG_PCI_ENDPOINT_TEST is not set
# CONFIG_PVPANIC is not set
# CONFIG_C2PORT is not set

#
# EEPROM support
#
# CONFIG_EEPROM_AT24 is not set
# CONFIG_EEPROM_LEGACY is not set
# CONFIG_EEPROM_MAX6875 is not set
# CONFIG_EEPROM_93CX6 is not set
# CONFIG_EEPROM_IDT_89HPESX is not set
# CONFIG_EEPROM_EE1004 is not set
# CONFIG_CB710_CORE is not set

#
# Texas Instruments shared transport line discipline
#
# CONFIG_SENSORS_LIS3_I2C is not set
# CONFIG_ALTERA_STAPL is not set
# CONFIG_INTEL_MEI is not set
# CONFIG_INTEL_MEI_ME is not set
# CONFIG_INTEL_MEI_TXE is not set
# CONFIG_VMWARE_VMCI is not set

#
# Intel MIC & related support
#

#
# Intel MIC Bus Driver
#
# CONFIG_INTEL_MIC_BUS is not set

#
# SCIF Bus Driver
#
# CONFIG_SCIF_BUS is not set

#
# VOP Bus Driver
#
# CONFIG_VOP_BUS is not set

#
# Intel MIC Host Driver
#

#
# Intel MIC Card Driver
#

#
# SCIF Driver
#

#
# Intel MIC Coprocessor State Management (COSM) Drivers
#

#
# VOP Driver
#
# CONFIG_GENWQE is not set
# CONFIG_ECHO is not set
# CONFIG_MISC_ALCOR_PCI is not set
# CONFIG_MISC_RTSX_PCI is not set
# CONFIG_MISC_RTSX_USB is not set
CONFIG_HAVE_IDE=y
# CONFIG_IDE is not set

#
# SCSI device support
#
CONFIG_SCSI_MOD=y
# CONFIG_RAID_ATTRS is not set
CONFIG_SCSI=y
CONFIG_SCSI_DMA=y
CONFIG_SCSI_PROC_FS=y

#
# SCSI support type (disk, tape, CD-ROM)
#
CONFIG_BLK_DEV_SD=y
# CONFIG_CHR_DEV_ST is not set
# CONFIG_CHR_DEV_OSST is not set
CONFIG_BLK_DEV_SR=y
CONFIG_BLK_DEV_SR_VENDOR=y
CONFIG_CHR_DEV_SG=y
# CONFIG_CHR_DEV_SCH is not set
CONFIG_SCSI_CONSTANTS=y
# CONFIG_SCSI_LOGGING is not set
# CONFIG_SCSI_SCAN_ASYNC is not set

#
# SCSI Transports
#
CONFIG_SCSI_SPI_ATTRS=y
# CONFIG_SCSI_FC_ATTRS is not set
# CONFIG_SCSI_ISCSI_ATTRS is not set
# CONFIG_SCSI_SAS_ATTRS is not set
# CONFIG_SCSI_SAS_LIBSAS is not set
# CONFIG_SCSI_SRP_ATTRS is not set
CONFIG_SCSI_LOWLEVEL=y
# CONFIG_ISCSI_TCP is not set
# CONFIG_ISCSI_BOOT_SYSFS is not set
# CONFIG_SCSI_CXGB3_ISCSI is not set
# CONFIG_SCSI_CXGB4_ISCSI is not set
# CONFIG_SCSI_BNX2_ISCSI is not set
# CONFIG_BE2ISCSI is not set
# CONFIG_BLK_DEV_3W_XXXX_RAID is not set
# CONFIG_SCSI_HPSA is not set
# CONFIG_SCSI_3W_9XXX is not set
# CONFIG_SCSI_3W_SAS is not set
# CONFIG_SCSI_ACARD is not set
# CONFIG_SCSI_AACRAID is not set
# CONFIG_SCSI_AIC7XXX is not set
# CONFIG_SCSI_AIC79XX is not set
# CONFIG_SCSI_AIC94XX is not set
# CONFIG_SCSI_MVSAS is not set
# CONFIG_SCSI_MVUMI is not set
# CONFIG_SCSI_DPT_I2O is not set
# CONFIG_SCSI_ADVANSYS is not set
# CONFIG_SCSI_ARCMSR is not set
# CONFIG_SCSI_ESAS2R is not set
# CONFIG_MEGARAID_NEWGEN is not set
# CONFIG_MEGARAID_LEGACY is not set
# CONFIG_MEGARAID_SAS is not set
# CONFIG_SCSI_MPT3SAS is not set
# CONFIG_SCSI_MPT2SAS is not set
# CONFIG_SCSI_SMARTPQI is not set
# CONFIG_SCSI_UFSHCD is not set
# CONFIG_SCSI_HPTIOP is not set
# CONFIG_SCSI_BUSLOGIC is not set
# CONFIG_SCSI_MYRB is not set
# CONFIG_SCSI_MYRS is not set
# CONFIG_VMWARE_PVSCSI is not set
# CONFIG_SCSI_SNIC is not set
# CONFIG_SCSI_DMX3191D is not set
# CONFIG_SCSI_GDTH is not set
# CONFIG_SCSI_ISCI is not set
# CONFIG_SCSI_IPS is not set
# CONFIG_SCSI_INITIO is not set
# CONFIG_SCSI_INIA100 is not set
# CONFIG_SCSI_STEX is not set
# CONFIG_SCSI_SYM53C8XX_2 is not set
# CONFIG_SCSI_IPR is not set
# CONFIG_SCSI_QLOGIC_1280 is not set
# CONFIG_SCSI_QLA_ISCSI is not set
# CONFIG_SCSI_DC395x is not set
# CONFIG_SCSI_AM53C974 is not set
# CONFIG_SCSI_WD719X is not set
# CONFIG_SCSI_DEBUG is not set
# CONFIG_SCSI_PMCRAID is not set
# CONFIG_SCSI_PM8001 is not set
CONFIG_SCSI_VIRTIO=y
# CONFIG_SCSI_LOWLEVEL_PCMCIA is not set
# CONFIG_SCSI_DH is not set
# CONFIG_SCSI_OSD_INITIATOR is not set
CONFIG_ATA=y
CONFIG_ATA_VERBOSE_ERROR=y
CONFIG_ATA_ACPI=y
# CONFIG_SATA_ZPODD is not set
CONFIG_SATA_PMP=y

#
# Controllers with non-SFF native interface
#
CONFIG_SATA_AHCI=y
CONFIG_SATA_MOBILE_LPM_POLICY=0
# CONFIG_SATA_AHCI_PLATFORM is not set
# CONFIG_SATA_INIC162X is not set
# CONFIG_SATA_ACARD_AHCI is not set
# CONFIG_SATA_SIL24 is not set
CONFIG_ATA_SFF=y

#
# SFF controllers with custom DMA interface
#
# CONFIG_PDC_ADMA is not set
# CONFIG_SATA_QSTOR is not set
# CONFIG_SATA_SX4 is not set
CONFIG_ATA_BMDMA=y

#
# SATA SFF controllers with BMDMA
#
CONFIG_ATA_PIIX=y
# CONFIG_SATA_DWC is not set
# CONFIG_SATA_MV is not set
# CONFIG_SATA_NV is not set
# CONFIG_SATA_PROMISE is not set
# CONFIG_SATA_SIL is not set
# CONFIG_SATA_SIS is not set
# CONFIG_SATA_SVW is not set
# CONFIG_SATA_ULI is not set
# CONFIG_SATA_VIA is not set
# CONFIG_SATA_VITESSE is not set

#
# PATA SFF controllers with BMDMA
#
# CONFIG_PATA_ALI is not set
CONFIG_PATA_AMD=y
# CONFIG_PATA_ARTOP is not set
# CONFIG_PATA_ATIIXP is not set
# CONFIG_PATA_ATP867X is not set
# CONFIG_PATA_CMD64X is not set
# CONFIG_PATA_CYPRESS is not set
# CONFIG_PATA_EFAR is not set
# CONFIG_PATA_HPT366 is not set
# CONFIG_PATA_HPT37X is not set
# CONFIG_PATA_HPT3X2N is not set
# CONFIG_PATA_HPT3X3 is not set
# CONFIG_PATA_IT8213 is not set
# CONFIG_PATA_IT821X is not set
# CONFIG_PATA_JMICRON is not set
# CONFIG_PATA_MARVELL is not set
# CONFIG_PATA_NETCELL is not set
# CONFIG_PATA_NINJA32 is not set
# CONFIG_PATA_NS87415 is not set
CONFIG_PATA_OLDPIIX=y
# CONFIG_PATA_OPTIDMA is not set
# CONFIG_PATA_PDC2027X is not set
# CONFIG_PATA_PDC_OLD is not set
# CONFIG_PATA_RADISYS is not set
# CONFIG_PATA_RDC is not set
CONFIG_PATA_SCH=y
# CONFIG_PATA_SERVERWORKS is not set
# CONFIG_PATA_SIL680 is not set
# CONFIG_PATA_SIS is not set
# CONFIG_PATA_TOSHIBA is not set
# CONFIG_PATA_TRIFLEX is not set
# CONFIG_PATA_VIA is not set
# CONFIG_PATA_WINBOND is not set

#
# PIO-only SFF controllers
#
# CONFIG_PATA_CMD640_PCI is not set
# CONFIG_PATA_MPIIX is not set
# CONFIG_PATA_NS87410 is not set
# CONFIG_PATA_OPTI is not set
# CONFIG_PATA_PCMCIA is not set
# CONFIG_PATA_RZ1000 is not set

#
# Generic fallback / legacy drivers
#
# CONFIG_PATA_ACPI is not set
# CONFIG_ATA_GENERIC is not set
# CONFIG_PATA_LEGACY is not set
CONFIG_MD=y
CONFIG_BLK_DEV_MD=y
CONFIG_MD_AUTODETECT=y
# CONFIG_MD_LINEAR is not set
# CONFIG_MD_RAID0 is not set
# CONFIG_MD_RAID1 is not set
# CONFIG_MD_RAID10 is not set
# CONFIG_MD_RAID456 is not set
# CONFIG_MD_MULTIPATH is not set
# CONFIG_MD_FAULTY is not set
# CONFIG_BCACHE is not set
CONFIG_BLK_DEV_DM_BUILTIN=y
CONFIG_BLK_DEV_DM=y
# CONFIG_DM_DEBUG is not set
# CONFIG_DM_UNSTRIPED is not set
# CONFIG_DM_CRYPT is not set
# CONFIG_DM_SNAPSHOT is not set
# CONFIG_DM_THIN_PROVISIONING is not set
# CONFIG_DM_CACHE is not set
# CONFIG_DM_WRITECACHE is not set
# CONFIG_DM_ERA is not set
CONFIG_DM_MIRROR=y
# CONFIG_DM_LOG_USERSPACE is not set
# CONFIG_DM_RAID is not set
CONFIG_DM_ZERO=y
# CONFIG_DM_MULTIPATH is not set
# CONFIG_DM_DELAY is not set
# CONFIG_DM_UEVENT is not set
# CONFIG_DM_FLAKEY is not set
# CONFIG_DM_VERITY is not set
# CONFIG_DM_SWITCH is not set
# CONFIG_DM_LOG_WRITES is not set
# CONFIG_DM_INTEGRITY is not set
# CONFIG_TARGET_CORE is not set
# CONFIG_FUSION is not set

#
# IEEE 1394 (FireWire) support
#
# CONFIG_FIREWIRE is not set
# CONFIG_FIREWIRE_NOSY is not set
CONFIG_MACINTOSH_DRIVERS=y
CONFIG_MAC_EMUMOUSEBTN=y
CONFIG_NETDEVICES=y
CONFIG_MII=y
CONFIG_NET_CORE=y
# CONFIG_BONDING is not set
# CONFIG_DUMMY is not set
# CONFIG_EQUALIZER is not set
# CONFIG_NET_FC is not set
# CONFIG_IFB is not set
# CONFIG_NET_TEAM is not set
# CONFIG_MACVLAN is not set
# CONFIG_IPVLAN is not set
# CONFIG_VXLAN is not set
# CONFIG_MACSEC is not set
CONFIG_NETCONSOLE=y
CONFIG_NETCONSOLE_DYNAMIC=y
CONFIG_NETPOLL=y
CONFIG_NET_POLL_CONTROLLER=y
CONFIG_TUN=y
# CONFIG_TUN_VNET_CROSS_LE is not set
# CONFIG_VETH is not set
CONFIG_VIRTIO_NET=y
# CONFIG_NLMON is not set
# CONFIG_ARCNET is not set

#
# CAIF transport drivers
#

#
# Distributed Switch Architecture drivers
#
CONFIG_ETHERNET=y
CONFIG_NET_VENDOR_3COM=y
# CONFIG_PCMCIA_3C574 is not set
# CONFIG_PCMCIA_3C589 is not set
# CONFIG_VORTEX is not set
# CONFIG_TYPHOON is not set
CONFIG_NET_VENDOR_ADAPTEC=y
# CONFIG_ADAPTEC_STARFIRE is not set
CONFIG_NET_VENDOR_AGERE=y
# CONFIG_ET131X is not set
CONFIG_NET_VENDOR_ALACRITECH=y
# CONFIG_SLICOSS is not set
CONFIG_NET_VENDOR_ALTEON=y
# CONFIG_ACENIC is not set
# CONFIG_ALTERA_TSE is not set
CONFIG_NET_VENDOR_AMAZON=y
# CONFIG_ENA_ETHERNET is not set
CONFIG_NET_VENDOR_AMD=y
# CONFIG_AMD8111_ETH is not set
# CONFIG_PCNET32 is not set
# CONFIG_PCMCIA_NMCLAN is not set
# CONFIG_AMD_XGBE is not set
CONFIG_NET_VENDOR_AQUANTIA=y
# CONFIG_AQTION is not set
CONFIG_NET_VENDOR_ARC=y
CONFIG_NET_VENDOR_ATHEROS=y
# CONFIG_ATL2 is not set
# CONFIG_ATL1 is not set
# CONFIG_ATL1E is not set
# CONFIG_ATL1C is not set
# CONFIG_ALX is not set
CONFIG_NET_VENDOR_AURORA=y
# CONFIG_AURORA_NB8800 is not set
CONFIG_NET_VENDOR_BROADCOM=y
# CONFIG_B44 is not set
# CONFIG_BCMGENET is not set
# CONFIG_BNX2 is not set
# CONFIG_CNIC is not set
CONFIG_TIGON3=y
CONFIG_TIGON3_HWMON=y
# CONFIG_BNX2X is not set
# CONFIG_SYSTEMPORT is not set
# CONFIG_BNXT is not set
CONFIG_NET_VENDOR_BROCADE=y
# CONFIG_BNA is not set
CONFIG_NET_VENDOR_CADENCE=y
# CONFIG_MACB is not set
CONFIG_NET_VENDOR_CAVIUM=y
# CONFIG_THUNDER_NIC_PF is not set
# CONFIG_THUNDER_NIC_VF is not set
# CONFIG_THUNDER_NIC_BGX is not set
# CONFIG_THUNDER_NIC_RGX is not set
CONFIG_CAVIUM_PTP=y
# CONFIG_LIQUIDIO is not set
# CONFIG_LIQUIDIO_VF is not set
CONFIG_NET_VENDOR_CHELSIO=y
# CONFIG_CHELSIO_T1 is not set
# CONFIG_CHELSIO_T3 is not set
# CONFIG_CHELSIO_T4 is not set
# CONFIG_CHELSIO_T4VF is not set
CONFIG_NET_VENDOR_CISCO=y
# CONFIG_ENIC is not set
CONFIG_NET_VENDOR_CORTINA=y
# CONFIG_CX_ECAT is not set
# CONFIG_DNET is not set
CONFIG_NET_VENDOR_DEC=y
CONFIG_NET_TULIP=y
# CONFIG_DE2104X is not set
# CONFIG_TULIP is not set
# CONFIG_DE4X5 is not set
# CONFIG_WINBOND_840 is not set
# CONFIG_DM9102 is not set
# CONFIG_ULI526X is not set
# CONFIG_PCMCIA_XIRCOM is not set
CONFIG_NET_VENDOR_DLINK=y
# CONFIG_DL2K is not set
# CONFIG_SUNDANCE is not set
CONFIG_NET_VENDOR_EMULEX=y
# CONFIG_BE2NET is not set
CONFIG_NET_VENDOR_EZCHIP=y
CONFIG_NET_VENDOR_FUJITSU=y
# CONFIG_PCMCIA_FMVJ18X is not set
CONFIG_NET_VENDOR_HP=y
# CONFIG_HP100 is not set
CONFIG_NET_VENDOR_HUAWEI=y
# CONFIG_HINIC is not set
CONFIG_NET_VENDOR_I825XX=y
CONFIG_NET_VENDOR_INTEL=y
CONFIG_E100=y
CONFIG_E1000=y
CONFIG_E1000E=y
CONFIG_E1000E_HWTS=y
# CONFIG_IGB is not set
# CONFIG_IGBVF is not set
# CONFIG_IXGB is not set
# CONFIG_IXGBE is not set
# CONFIG_IXGBEVF is not set
# CONFIG_I40E is not set
# CONFIG_I40EVF is not set
# CONFIG_ICE is not set
# CONFIG_FM10K is not set
# CONFIG_IGC is not set
# CONFIG_JME is not set
CONFIG_NET_VENDOR_MARVELL=y
# CONFIG_MVMDIO is not set
# CONFIG_SKGE is not set
CONFIG_SKY2=y
# CONFIG_SKY2_DEBUG is not set
CONFIG_NET_VENDOR_MELLANOX=y
# CONFIG_MLX4_EN is not set
# CONFIG_MLX5_CORE is not set
# CONFIG_MLXSW_CORE is not set
# CONFIG_MLXFW is not set
CONFIG_NET_VENDOR_MICREL=y
# CONFIG_KS8842 is not set
# CONFIG_KS8851_MLL is not set
# CONFIG_KSZ884X_PCI is not set
CONFIG_NET_VENDOR_MICROCHIP=y
# CONFIG_LAN743X is not set
CONFIG_NET_VENDOR_MICROSEMI=y
CONFIG_NET_VENDOR_MYRI=y
# CONFIG_MYRI10GE is not set
# CONFIG_FEALNX is not set
CONFIG_NET_VENDOR_NATSEMI=y
# CONFIG_NATSEMI is not set
# CONFIG_NS83820 is not set
CONFIG_NET_VENDOR_NETERION=y
# CONFIG_S2IO is not set
# CONFIG_VXGE is not set
CONFIG_NET_VENDOR_NETRONOME=y
# CONFIG_NFP is not set
CONFIG_NET_VENDOR_NI=y
# CONFIG_NI_XGE_MANAGEMENT_ENET is not set
CONFIG_NET_VENDOR_8390=y
# CONFIG_PCMCIA_AXNET is not set
# CONFIG_NE2K_PCI is not set
# CONFIG_PCMCIA_PCNET is not set
CONFIG_NET_VENDOR_NVIDIA=y
CONFIG_FORCEDETH=y
CONFIG_NET_VENDOR_OKI=y
# CONFIG_ETHOC is not set
CONFIG_NET_VENDOR_PACKET_ENGINES=y
# CONFIG_HAMACHI is not set
# CONFIG_YELLOWFIN is not set
CONFIG_NET_VENDOR_QLOGIC=y
# CONFIG_QLA3XXX is not set
# CONFIG_QLCNIC is not set
# CONFIG_QLGE is not set
# CONFIG_NETXEN_NIC is not set
# CONFIG_QED is not set
CONFIG_NET_VENDOR_QUALCOMM=y
# CONFIG_QCOM_EMAC is not set
# CONFIG_RMNET is not set
CONFIG_NET_VENDOR_RDC=y
# CONFIG_R6040 is not set
CONFIG_NET_VENDOR_REALTEK=y
# CONFIG_8139CP is not set
CONFIG_8139TOO=y
CONFIG_8139TOO_PIO=y
# CONFIG_8139TOO_TUNE_TWISTER is not set
# CONFIG_8139TOO_8129 is not set
# CONFIG_8139_OLD_RX_RESET is not set
CONFIG_R8169=y
CONFIG_NET_VENDOR_RENESAS=y
CONFIG_NET_VENDOR_ROCKER=y
CONFIG_NET_VENDOR_SAMSUNG=y
# CONFIG_SXGBE_ETH is not set
CONFIG_NET_VENDOR_SEEQ=y
CONFIG_NET_VENDOR_SOLARFLARE=y
# CONFIG_SFC is not set
# CONFIG_SFC_FALCON is not set
CONFIG_NET_VENDOR_SILAN=y
# CONFIG_SC92031 is not set
CONFIG_NET_VENDOR_SIS=y
# CONFIG_SIS900 is not set
# CONFIG_SIS190 is not set
CONFIG_NET_VENDOR_SMSC=y
# CONFIG_PCMCIA_SMC91C92 is not set
# CONFIG_EPIC100 is not set
# CONFIG_SMSC911X is not set
# CONFIG_SMSC9420 is not set
CONFIG_NET_VENDOR_SOCIONEXT=y
CONFIG_NET_VENDOR_STMICRO=y
# CONFIG_STMMAC_ETH is not set
CONFIG_NET_VENDOR_SUN=y
# CONFIG_HAPPYMEAL is not set
# CONFIG_SUNGEM is not set
# CONFIG_CASSINI is not set
# CONFIG_NIU is not set
CONFIG_NET_VENDOR_SYNOPSYS=y
# CONFIG_DWC_XLGMAC is not set
CONFIG_NET_VENDOR_TEHUTI=y
# CONFIG_TEHUTI is not set
CONFIG_NET_VENDOR_TI=y
# CONFIG_TI_CPSW_ALE is not set
# CONFIG_TLAN is not set
CONFIG_NET_VENDOR_VIA=y
# CONFIG_VIA_RHINE is not set
# CONFIG_VIA_VELOCITY is not set
CONFIG_NET_VENDOR_WIZNET=y
# CONFIG_WIZNET_W5100 is not set
# CONFIG_WIZNET_W5300 is not set
CONFIG_NET_VENDOR_XIRCOM=y
# CONFIG_PCMCIA_XIRC2PS is not set
CONFIG_FDDI=y
# CONFIG_DEFXX is not set
# CONFIG_SKFP is not set
# CONFIG_HIPPI is not set
# CONFIG_NET_SB1000 is not set
CONFIG_MDIO_DEVICE=y
CONFIG_MDIO_BUS=y
# CONFIG_MDIO_BCM_UNIMAC is not set
# CONFIG_MDIO_BITBANG is not set
# CONFIG_MDIO_MSCC_MIIM is not set
# CONFIG_MDIO_THUNDER is not set
CONFIG_PHYLIB=y
# CONFIG_LED_TRIGGER_PHY is not set

#
# MII PHY device drivers
#
# CONFIG_AMD_PHY is not set
# CONFIG_AQUANTIA_PHY is not set
# CONFIG_ASIX_PHY is not set
# CONFIG_AT803X_PHY is not set
# CONFIG_BCM7XXX_PHY is not set
# CONFIG_BCM87XX_PHY is not set
# CONFIG_BROADCOM_PHY is not set
# CONFIG_CICADA_PHY is not set
# CONFIG_CORTINA_PHY is not set
# CONFIG_DAVICOM_PHY is not set
# CONFIG_DP83822_PHY is not set
# CONFIG_DP83TC811_PHY is not set
# CONFIG_DP83848_PHY is not set
# CONFIG_DP83867_PHY is not set
# CONFIG_FIXED_PHY is not set
# CONFIG_ICPLUS_PHY is not set
# CONFIG_INTEL_XWAY_PHY is not set
# CONFIG_LSI_ET1011C_PHY is not set
# CONFIG_LXT_PHY is not set
# CONFIG_MARVELL_PHY is not set
# CONFIG_MARVELL_10G_PHY is not set
# CONFIG_MICREL_PHY is not set
# CONFIG_MICROCHIP_PHY is not set
# CONFIG_MICROCHIP_T1_PHY is not set
# CONFIG_MICROSEMI_PHY is not set
# CONFIG_NATIONAL_PHY is not set
# CONFIG_QSEMI_PHY is not set
CONFIG_REALTEK_PHY=y
# CONFIG_RENESAS_PHY is not set
# CONFIG_ROCKCHIP_PHY is not set
# CONFIG_SMSC_PHY is not set
# CONFIG_STE10XP is not set
# CONFIG_TERANETICS_PHY is not set
# CONFIG_VITESSE_PHY is not set
# CONFIG_XILINX_GMII2RGMII is not set
# CONFIG_PPP is not set
# CONFIG_SLIP is not set
CONFIG_USB_NET_DRIVERS=y
# CONFIG_USB_CATC is not set
# CONFIG_USB_KAWETH is not set
# CONFIG_USB_PEGASUS is not set
# CONFIG_USB_RTL8150 is not set
# CONFIG_USB_RTL8152 is not set
# CONFIG_USB_LAN78XX is not set
# CONFIG_USB_USBNET is not set
# CONFIG_USB_HSO is not set
# CONFIG_USB_IPHETH is not set
CONFIG_WLAN=y
CONFIG_WLAN_VENDOR_ADMTEK=y
# CONFIG_ADM8211 is not set
CONFIG_WLAN_VENDOR_ATH=y
# CONFIG_ATH_DEBUG is not set
# CONFIG_ATH5K is not set
# CONFIG_ATH5K_PCI is not set
# CONFIG_ATH9K is not set
# CONFIG_ATH9K_HTC is not set
# CONFIG_CARL9170 is not set
# CONFIG_ATH6KL is not set
# CONFIG_AR5523 is not set
# CONFIG_WIL6210 is not set
# CONFIG_ATH10K is not set
# CONFIG_WCN36XX is not set
CONFIG_WLAN_VENDOR_ATMEL=y
# CONFIG_ATMEL is not set
# CONFIG_AT76C50X_USB is not set
CONFIG_WLAN_VENDOR_BROADCOM=y
# CONFIG_B43 is not set
# CONFIG_B43LEGACY is not set
# CONFIG_BRCMSMAC is not set
# CONFIG_BRCMFMAC is not set
CONFIG_WLAN_VENDOR_CISCO=y
# CONFIG_AIRO is not set
# CONFIG_AIRO_CS is not set
CONFIG_WLAN_VENDOR_INTEL=y
# CONFIG_IPW2100 is not set
# CONFIG_IPW2200 is not set
# CONFIG_IWL4965 is not set
# CONFIG_IWL3945 is not set
# CONFIG_IWLWIFI is not set
CONFIG_WLAN_VENDOR_INTERSIL=y
# CONFIG_HOSTAP is not set
# CONFIG_HERMES is not set
# CONFIG_P54_COMMON is not set
# CONFIG_PRISM54 is not set
CONFIG_WLAN_VENDOR_MARVELL=y
# CONFIG_LIBERTAS is not set
# CONFIG_LIBERTAS_THINFIRM is not set
# CONFIG_MWIFIEX is not set
# CONFIG_MWL8K is not set
CONFIG_WLAN_VENDOR_MEDIATEK=y
# CONFIG_MT7601U is not set
# CONFIG_MT76x0U is not set
# CONFIG_MT76x0E is not set
# CONFIG_MT76x2E is not set
# CONFIG_MT76x2U is not set
CONFIG_WLAN_VENDOR_RALINK=y
# CONFIG_RT2X00 is not set
CONFIG_WLAN_VENDOR_REALTEK=y
# CONFIG_RTL8180 is not set
# CONFIG_RTL8187 is not set
CONFIG_RTL_CARDS=y
# CONFIG_RTL8192CE is not set
# CONFIG_RTL8192SE is not set
# CONFIG_RTL8192DE is not set
# CONFIG_RTL8723AE is not set
# CONFIG_RTL8723BE is not set
# CONFIG_RTL8188EE is not set
# CONFIG_RTL8192EE is not set
# CONFIG_RTL8821AE is not set
# CONFIG_RTL8192CU is not set
# CONFIG_RTL8XXXU is not set
CONFIG_WLAN_VENDOR_RSI=y
# CONFIG_RSI_91X is not set
CONFIG_WLAN_VENDOR_ST=y
# CONFIG_CW1200 is not set
CONFIG_WLAN_VENDOR_TI=y
# CONFIG_WL1251 is not set
# CONFIG_WL12XX is not set
# CONFIG_WL18XX is not set
# CONFIG_WLCORE is not set
CONFIG_WLAN_VENDOR_ZYDAS=y
# CONFIG_USB_ZD1201 is not set
# CONFIG_ZD1211RW is not set
CONFIG_WLAN_VENDOR_QUANTENNA=y
# CONFIG_QTNFMAC_PCIE is not set
# CONFIG_PCMCIA_RAYCS is not set
# CONFIG_PCMCIA_WL3501 is not set
# CONFIG_MAC80211_HWSIM is not set
# CONFIG_USB_NET_RNDIS_WLAN is not set
# CONFIG_VIRT_WIFI is not set

#
# Enable WiMAX (Networking options) to see the WiMAX drivers
#
# CONFIG_WAN is not set
# CONFIG_VMXNET3 is not set
# CONFIG_FUJITSU_ES is not set
# CONFIG_NETDEVSIM is not set
CONFIG_NET_FAILOVER=y
# CONFIG_ISDN is not set
# CONFIG_NVM is not set

#
# Input device support
#
CONFIG_INPUT=y
CONFIG_INPUT_LEDS=y
CONFIG_INPUT_FF_MEMLESS=y
CONFIG_INPUT_POLLDEV=y
CONFIG_INPUT_SPARSEKMAP=y
# CONFIG_INPUT_MATRIXKMAP is not set

#
# Userland interfaces
#
# CONFIG_INPUT_MOUSEDEV is not set
# CONFIG_INPUT_JOYDEV is not set
CONFIG_INPUT_EVDEV=y
# CONFIG_INPUT_EVBUG is not set

#
# Input Device Drivers
#
CONFIG_INPUT_KEYBOARD=y
# CONFIG_KEYBOARD_ADP5588 is not set
# CONFIG_KEYBOARD_ADP5589 is not set
CONFIG_KEYBOARD_ATKBD=y
# CONFIG_KEYBOARD_QT1070 is not set
# CONFIG_KEYBOARD_QT2160 is not set
# CONFIG_KEYBOARD_DLINK_DIR685 is not set
# CONFIG_KEYBOARD_LKKBD is not set
# CONFIG_KEYBOARD_TCA6416 is not set
# CONFIG_KEYBOARD_TCA8418 is not set
# CONFIG_KEYBOARD_LM8323 is not set
# CONFIG_KEYBOARD_LM8333 is not set
# CONFIG_KEYBOARD_MAX7359 is not set
# CONFIG_KEYBOARD_MCS is not set
# CONFIG_KEYBOARD_MPR121 is not set
# CONFIG_KEYBOARD_NEWTON is not set
# CONFIG_KEYBOARD_OPENCORES is not set
# CONFIG_KEYBOARD_SAMSUNG is not set
# CONFIG_KEYBOARD_STOWAWAY is not set
# CONFIG_KEYBOARD_SUNKBD is not set
# CONFIG_KEYBOARD_TM2_TOUCHKEY is not set
# CONFIG_KEYBOARD_XTKBD is not set
CONFIG_INPUT_MOUSE=y
CONFIG_MOUSE_PS2=y
CONFIG_MOUSE_PS2_ALPS=y
CONFIG_MOUSE_PS2_BYD=y
CONFIG_MOUSE_PS2_LOGIPS2PP=y
CONFIG_MOUSE_PS2_SYNAPTICS=y
CONFIG_MOUSE_PS2_SYNAPTICS_SMBUS=y
CONFIG_MOUSE_PS2_CYPRESS=y
CONFIG_MOUSE_PS2_LIFEBOOK=y
CONFIG_MOUSE_PS2_TRACKPOINT=y
# CONFIG_MOUSE_PS2_ELANTECH is not set
# CONFIG_MOUSE_PS2_SENTELIC is not set
# CONFIG_MOUSE_PS2_TOUCHKIT is not set
CONFIG_MOUSE_PS2_FOCALTECH=y
# CONFIG_MOUSE_PS2_VMMOUSE is not set
CONFIG_MOUSE_PS2_SMBUS=y
# CONFIG_MOUSE_SERIAL is not set
# CONFIG_MOUSE_APPLETOUCH is not set
# CONFIG_MOUSE_BCM5974 is not set
# CONFIG_MOUSE_CYAPA is not set
# CONFIG_MOUSE_ELAN_I2C is not set
# CONFIG_MOUSE_VSXXXAA is not set
# CONFIG_MOUSE_SYNAPTICS_I2C is not set
# CONFIG_MOUSE_SYNAPTICS_USB is not set
CONFIG_INPUT_JOYSTICK=y
# CONFIG_JOYSTICK_ANALOG is not set
# CONFIG_JOYSTICK_A3D is not set
# CONFIG_JOYSTICK_ADI is not set
# CONFIG_JOYSTICK_COBRA is not set
# CONFIG_JOYSTICK_GF2K is not set
# CONFIG_JOYSTICK_GRIP is not set
# CONFIG_JOYSTICK_GRIP_MP is not set
# CONFIG_JOYSTICK_GUILLEMOT is not set
# CONFIG_JOYSTICK_INTERACT is not set
# CONFIG_JOYSTICK_SIDEWINDER is not set
# CONFIG_JOYSTICK_TMDC is not set
# CONFIG_JOYSTICK_IFORCE is not set
# CONFIG_JOYSTICK_WARRIOR is not set
# CONFIG_JOYSTICK_MAGELLAN is not set
# CONFIG_JOYSTICK_SPACEORB is not set
# CONFIG_JOYSTICK_SPACEBALL is not set
# CONFIG_JOYSTICK_STINGER is not set
# CONFIG_JOYSTICK_TWIDJOY is not set
# CONFIG_JOYSTICK_ZHENHUA is not set
# CONFIG_JOYSTICK_AS5011 is not set
# CONFIG_JOYSTICK_JOYDUMP is not set
# CONFIG_JOYSTICK_XPAD is not set
# CONFIG_JOYSTICK_PXRC is not set
CONFIG_INPUT_TABLET=y
# CONFIG_TABLET_USB_ACECAD is not set
# CONFIG_TABLET_USB_AIPTEK is not set
# CONFIG_TABLET_USB_GTCO is not set
# CONFIG_TABLET_USB_HANWANG is not set
# CONFIG_TABLET_USB_KBTAB is not set
# CONFIG_TABLET_USB_PEGASUS is not set
# CONFIG_TABLET_SERIAL_WACOM4 is not set
CONFIG_INPUT_TOUCHSCREEN=y
CONFIG_TOUCHSCREEN_PROPERTIES=y
# CONFIG_TOUCHSCREEN_AD7879 is not set
# CONFIG_TOUCHSCREEN_ATMEL_MXT is not set
# CONFIG_TOUCHSCREEN_BU21013 is not set
# CONFIG_TOUCHSCREEN_BU21029 is not set
# CONFIG_TOUCHSCREEN_CHIPONE_ICN8505 is not set
# CONFIG_TOUCHSCREEN_CYTTSP_CORE is not set
# CONFIG_TOUCHSCREEN_CYTTSP4_CORE is not set
# CONFIG_TOUCHSCREEN_DYNAPRO is not set
# CONFIG_TOUCHSCREEN_HAMPSHIRE is not set
# CONFIG_TOUCHSCREEN_EETI is not set
# CONFIG_TOUCHSCREEN_EGALAX_SERIAL is not set
# CONFIG_TOUCHSCREEN_EXC3000 is not set
# CONFIG_TOUCHSCREEN_FUJITSU is not set
# CONFIG_TOUCHSCREEN_HIDEEP is not set
# CONFIG_TOUCHSCREEN_ILI210X is not set
# CONFIG_TOUCHSCREEN_S6SY761 is not set
# CONFIG_TOUCHSCREEN_GUNZE is not set
# CONFIG_TOUCHSCREEN_EKTF2127 is not set
# CONFIG_TOUCHSCREEN_ELAN is not set
# CONFIG_TOUCHSCREEN_ELO is not set
# CONFIG_TOUCHSCREEN_WACOM_W8001 is not set
# CONFIG_TOUCHSCREEN_WACOM_I2C is not set
# CONFIG_TOUCHSCREEN_MAX11801 is not set
# CONFIG_TOUCHSCREEN_MCS5000 is not set
# CONFIG_TOUCHSCREEN_MMS114 is not set
# CONFIG_TOUCHSCREEN_MELFAS_MIP4 is not set
# CONFIG_TOUCHSCREEN_MTOUCH is not set
# CONFIG_TOUCHSCREEN_INEXIO is not set
# CONFIG_TOUCHSCREEN_MK712 is not set
# CONFIG_TOUCHSCREEN_PENMOUNT is not set
# CONFIG_TOUCHSCREEN_EDT_FT5X06 is not set
# CONFIG_TOUCHSCREEN_TOUCHRIGHT is not set
# CONFIG_TOUCHSCREEN_TOUCHWIN is not set
# CONFIG_TOUCHSCREEN_PIXCIR is not set
# CONFIG_TOUCHSCREEN_WDT87XX_I2C is not set
# CONFIG_TOUCHSCREEN_USB_COMPOSITE is not set
# CONFIG_TOUCHSCREEN_TOUCHIT213 is not set
# CONFIG_TOUCHSCREEN_TSC_SERIO is not set
# CONFIG_TOUCHSCREEN_TSC2004 is not set
# CONFIG_TOUCHSCREEN_TSC2007 is not set
# CONFIG_TOUCHSCREEN_SILEAD is not set
# CONFIG_TOUCHSCREEN_ST1232 is not set
# CONFIG_TOUCHSCREEN_STMFTS is not set
# CONFIG_TOUCHSCREEN_SX8654 is not set
# CONFIG_TOUCHSCREEN_TPS6507X is not set
# CONFIG_TOUCHSCREEN_ZET6223 is not set
# CONFIG_TOUCHSCREEN_ROHM_BU21023 is not set
CONFIG_INPUT_MISC=y
# CONFIG_INPUT_AD714X is not set
# CONFIG_INPUT_BMA150 is not set
# CONFIG_INPUT_E3X0_BUTTON is not set
# CONFIG_INPUT_PCSPKR is not set
# CONFIG_INPUT_MMA8450 is not set
# CONFIG_INPUT_APANEL is not set
# CONFIG_INPUT_ATLAS_BTNS is not set
# CONFIG_INPUT_ATI_REMOTE2 is not set
# CONFIG_INPUT_KEYSPAN_REMOTE is not set
# CONFIG_INPUT_KXTJ9 is not set
# CONFIG_INPUT_POWERMATE is not set
# CONFIG_INPUT_YEALINK is not set
# CONFIG_INPUT_CM109 is not set
# CONFIG_INPUT_UINPUT is not set
# CONFIG_INPUT_PCF8574 is not set
# CONFIG_INPUT_ADXL34X is not set
# CONFIG_INPUT_IMS_PCU is not set
# CONFIG_INPUT_CMA3000 is not set
# CONFIG_INPUT_IDEAPAD_SLIDEBAR is not set
# CONFIG_INPUT_DRV2665_HAPTICS is not set
# CONFIG_INPUT_DRV2667_HAPTICS is not set
# CONFIG_RMI4_CORE is not set

#
# Hardware I/O ports
#
CONFIG_SERIO=y
CONFIG_ARCH_MIGHT_HAVE_PC_SERIO=y
CONFIG_SERIO_I8042=y
CONFIG_SERIO_SERPORT=y
# CONFIG_SERIO_CT82C710 is not set
# CONFIG_SERIO_PCIPS2 is not set
CONFIG_SERIO_LIBPS2=y
# CONFIG_SERIO_RAW is not set
# CONFIG_SERIO_ALTERA_PS2 is not set
# CONFIG_SERIO_PS2MULT is not set
# CONFIG_SERIO_ARC_PS2 is not set
# CONFIG_SERIO_OLPC_APSP is not set
# CONFIG_USERIO is not set
# CONFIG_GAMEPORT is not set

#
# Character devices
#
CONFIG_TTY=y
CONFIG_VT=y
CONFIG_CONSOLE_TRANSLATIONS=y
CONFIG_VT_CONSOLE=y
CONFIG_VT_CONSOLE_SLEEP=y
CONFIG_HW_CONSOLE=y
CONFIG_VT_HW_CONSOLE_BINDING=y
CONFIG_UNIX98_PTYS=y
# CONFIG_LEGACY_PTYS is not set
CONFIG_SERIAL_NONSTANDARD=y
# CONFIG_ROCKETPORT is not set
# CONFIG_CYCLADES is not set
# CONFIG_MOXA_INTELLIO is not set
# CONFIG_MOXA_SMARTIO is not set
# CONFIG_SYNCLINK is not set
# CONFIG_SYNCLINKMP is not set
# CONFIG_SYNCLINK_GT is not set
# CONFIG_NOZOMI is not set
# CONFIG_ISI is not set
# CONFIG_N_HDLC is not set
# CONFIG_N_GSM is not set
# CONFIG_TRACE_SINK is not set
CONFIG_DEVMEM=y
# CONFIG_DEVKMEM is not set

#
# Serial drivers
#
CONFIG_SERIAL_EARLYCON=y
CONFIG_SERIAL_8250=y
CONFIG_SERIAL_8250_DEPRECATED_OPTIONS=y
CONFIG_SERIAL_8250_PNP=y
# CONFIG_SERIAL_8250_FINTEK is not set
CONFIG_SERIAL_8250_CONSOLE=y
CONFIG_SERIAL_8250_DMA=y
CONFIG_SERIAL_8250_PCI=y
CONFIG_SERIAL_8250_EXAR=y
# CONFIG_SERIAL_8250_CS is not set
CONFIG_SERIAL_8250_NR_UARTS=32
CONFIG_SERIAL_8250_RUNTIME_UARTS=4
CONFIG_SERIAL_8250_EXTENDED=y
CONFIG_SERIAL_8250_MANY_PORTS=y
CONFIG_SERIAL_8250_SHARE_IRQ=y
CONFIG_SERIAL_8250_DETECT_IRQ=y
CONFIG_SERIAL_8250_RSA=y
# CONFIG_SERIAL_8250_DW is not set
# CONFIG_SERIAL_8250_RT288X is not set
CONFIG_SERIAL_8250_LPSS=y
CONFIG_SERIAL_8250_MID=y
# CONFIG_SERIAL_8250_MOXA is not set

#
# Non-8250 serial port support
#
# CONFIG_SERIAL_UARTLITE is not set
CONFIG_SERIAL_CORE=y
CONFIG_SERIAL_CORE_CONSOLE=y
# CONFIG_SERIAL_JSM is not set
# CONFIG_SERIAL_SCCNXP is not set
# CONFIG_SERIAL_SC16IS7XX is not set
# CONFIG_SERIAL_ALTERA_JTAGUART is not set
# CONFIG_SERIAL_ALTERA_UART is not set
# CONFIG_SERIAL_ARC is not set
# CONFIG_SERIAL_RP2 is not set
# CONFIG_SERIAL_FSL_LPUART is not set
# CONFIG_SERIAL_DEV_BUS is not set
CONFIG_HVC_DRIVER=y
CONFIG_VIRTIO_CONSOLE=y
# CONFIG_IPMI_HANDLER is not set
CONFIG_HW_RANDOM=y
# CONFIG_HW_RANDOM_TIMERIOMEM is not set
# CONFIG_HW_RANDOM_INTEL is not set
# CONFIG_HW_RANDOM_AMD is not set
CONFIG_HW_RANDOM_VIA=y
# CONFIG_HW_RANDOM_VIRTIO is not set
CONFIG_NVRAM=y
# CONFIG_R3964 is not set
# CONFIG_APPLICOM is not set

#
# PCMCIA character devices
#
# CONFIG_SYNCLINK_CS is not set
# CONFIG_CARDMAN_4000 is not set
# CONFIG_CARDMAN_4040 is not set
# CONFIG_SCR24X is not set
# CONFIG_IPWIRELESS is not set
# CONFIG_MWAVE is not set
# CONFIG_RAW_DRIVER is not set
CONFIG_HPET=y
# CONFIG_HPET_MMAP is not set
# CONFIG_HANGCHECK_TIMER is not set
# CONFIG_TCG_TPM is not set
# CONFIG_TELCLOCK is not set
CONFIG_DEVPORT=y
# CONFIG_XILLYBUS is not set
# CONFIG_RANDOM_TRUST_CPU is not set

#
# I2C support
#
CONFIG_I2C=y
CONFIG_ACPI_I2C_OPREGION=y
CONFIG_I2C_BOARDINFO=y
CONFIG_I2C_COMPAT=y
# CONFIG_I2C_CHARDEV is not set
# CONFIG_I2C_MUX is not set
CONFIG_I2C_HELPER_AUTO=y
CONFIG_I2C_SMBUS=y
CONFIG_I2C_ALGOBIT=y

#
# I2C Hardware Bus support
#

#
# PC SMBus host controller drivers
#
# CONFIG_I2C_ALI1535 is not set
# CONFIG_I2C_ALI1563 is not set
# CONFIG_I2C_ALI15X3 is not set
# CONFIG_I2C_AMD756 is not set
# CONFIG_I2C_AMD8111 is not set
CONFIG_I2C_I801=y
# CONFIG_I2C_ISCH is not set
# CONFIG_I2C_ISMT is not set
# CONFIG_I2C_PIIX4 is not set
# CONFIG_I2C_NFORCE2 is not set
# CONFIG_I2C_NVIDIA_GPU is not set
# CONFIG_I2C_SIS5595 is not set
# CONFIG_I2C_SIS630 is not set
# CONFIG_I2C_SIS96X is not set
# CONFIG_I2C_VIA is not set
# CONFIG_I2C_VIAPRO is not set

#
# ACPI drivers
#
# CONFIG_I2C_SCMI is not set

#
# I2C system bus drivers (mostly embedded / system-on-chip)
#
# CONFIG_I2C_DESIGNWARE_PLATFORM is not set
# CONFIG_I2C_DESIGNWARE_PCI is not set
# CONFIG_I2C_EMEV2 is not set
# CONFIG_I2C_OCORES is not set
# CONFIG_I2C_PCA_PLATFORM is not set
# CONFIG_I2C_SIMTEC is not set
# CONFIG_I2C_XILINX is not set

#
# External I2C/SMBus adapter drivers
#
# CONFIG_I2C_DIOLAN_U2C is not set
# CONFIG_I2C_PARPORT_LIGHT is not set
# CONFIG_I2C_ROBOTFUZZ_OSIF is not set
# CONFIG_I2C_TAOS_EVM is not set
# CONFIG_I2C_TINY_USB is not set

#
# Other I2C/SMBus bus drivers
#
# CONFIG_I2C_MLXCPLD is not set
# CONFIG_I2C_STUB is not set
# CONFIG_I2C_SLAVE is not set
# CONFIG_I2C_DEBUG_CORE is not set
# CONFIG_I2C_DEBUG_ALGO is not set
# CONFIG_I2C_DEBUG_BUS is not set
# CONFIG_I3C is not set
# CONFIG_SPI is not set
# CONFIG_SPMI is not set
# CONFIG_HSI is not set
CONFIG_PPS=y
# CONFIG_PPS_DEBUG is not set

#
# PPS clients support
#
# CONFIG_PPS_CLIENT_KTIMER is not set
# CONFIG_PPS_CLIENT_LDISC is not set
# CONFIG_PPS_CLIENT_GPIO is not set

#
# PPS generators support
#

#
# PTP clock support
#
CONFIG_PTP_1588_CLOCK=y

#
# Enable PHYLIB and NETWORK_PHY_TIMESTAMPING to see the additional clocks.
#
CONFIG_PTP_1588_CLOCK_KVM=y
# CONFIG_PINCTRL is not set
# CONFIG_GPIOLIB is not set
# CONFIG_W1 is not set
# CONFIG_POWER_AVS is not set
# CONFIG_POWER_RESET is not set
CONFIG_POWER_SUPPLY=y
# CONFIG_POWER_SUPPLY_DEBUG is not set
# CONFIG_PDA_POWER is not set
# CONFIG_TEST_POWER is not set
# CONFIG_CHARGER_ADP5061 is not set
# CONFIG_BATTERY_DS2780 is not set
# CONFIG_BATTERY_DS2781 is not set
# CONFIG_BATTERY_DS2782 is not set
# CONFIG_BATTERY_SBS is not set
# CONFIG_CHARGER_SBS is not set
# CONFIG_BATTERY_BQ27XXX is not set
# CONFIG_BATTERY_MAX17040 is not set
# CONFIG_BATTERY_MAX17042 is not set
# CONFIG_CHARGER_MAX8903 is not set
# CONFIG_CHARGER_LP8727 is not set
# CONFIG_CHARGER_BQ2415X is not set
# CONFIG_CHARGER_SMB347 is not set
# CONFIG_BATTERY_GAUGE_LTC2941 is not set
CONFIG_HWMON=y
# CONFIG_HWMON_DEBUG_CHIP is not set

#
# Native drivers
#
# CONFIG_SENSORS_ABITUGURU is not set
# CONFIG_SENSORS_ABITUGURU3 is not set
# CONFIG_SENSORS_AD7414 is not set
# CONFIG_SENSORS_AD7418 is not set
# CONFIG_SENSORS_ADM1021 is not set
# CONFIG_SENSORS_ADM1025 is not set
# CONFIG_SENSORS_ADM1026 is not set
# CONFIG_SENSORS_ADM1029 is not set
# CONFIG_SENSORS_ADM1031 is not set
# CONFIG_SENSORS_ADM9240 is not set
# CONFIG_SENSORS_ADT7410 is not set
# CONFIG_SENSORS_ADT7411 is not set
# CONFIG_SENSORS_ADT7462 is not set
# CONFIG_SENSORS_ADT7470 is not set
# CONFIG_SENSORS_ADT7475 is not set
# CONFIG_SENSORS_ASC7621 is not set
# CONFIG_SENSORS_K8TEMP is not set
# CONFIG_SENSORS_K10TEMP is not set
# CONFIG_SENSORS_FAM15H_POWER is not set
# CONFIG_SENSORS_APPLESMC is not set
# CONFIG_SENSORS_ASB100 is not set
# CONFIG_SENSORS_ASPEED is not set
# CONFIG_SENSORS_ATXP1 is not set
# CONFIG_SENSORS_DS620 is not set
# CONFIG_SENSORS_DS1621 is not set
# CONFIG_SENSORS_DELL_SMM is not set
# CONFIG_SENSORS_I5K_AMB is not set
# CONFIG_SENSORS_F71805F is not set
# CONFIG_SENSORS_F71882FG is not set
# CONFIG_SENSORS_F75375S is not set
# CONFIG_SENSORS_FSCHMD is not set
# CONFIG_SENSORS_FTSTEUTATES is not set
# CONFIG_SENSORS_GL518SM is not set
# CONFIG_SENSORS_GL520SM is not set
# CONFIG_SENSORS_G760A is not set
# CONFIG_SENSORS_G762 is not set
# CONFIG_SENSORS_HIH6130 is not set
# CONFIG_SENSORS_I5500 is not set
# CONFIG_SENSORS_CORETEMP is not set
# CONFIG_SENSORS_IT87 is not set
# CONFIG_SENSORS_JC42 is not set
# CONFIG_SENSORS_POWR1220 is not set
# CONFIG_SENSORS_LINEAGE is not set
# CONFIG_SENSORS_LTC2945 is not set
# CONFIG_SENSORS_LTC2990 is not set
# CONFIG_SENSORS_LTC4151 is not set
# CONFIG_SENSORS_LTC4215 is not set
# CONFIG_SENSORS_LTC4222 is not set
# CONFIG_SENSORS_LTC4245 is not set
# CONFIG_SENSORS_LTC4260 is not set
# CONFIG_SENSORS_LTC4261 is not set
# CONFIG_SENSORS_MAX16065 is not set
# CONFIG_SENSORS_MAX1619 is not set
# CONFIG_SENSORS_MAX1668 is not set
# CONFIG_SENSORS_MAX197 is not set
# CONFIG_SENSORS_MAX6621 is not set
# CONFIG_SENSORS_MAX6639 is not set
# CONFIG_SENSORS_MAX6642 is not set
# CONFIG_SENSORS_MAX6650 is not set
# CONFIG_SENSORS_MAX6697 is not set
# CONFIG_SENSORS_MAX31790 is not set
# CONFIG_SENSORS_MCP3021 is not set
# CONFIG_SENSORS_TC654 is not set
# CONFIG_SENSORS_LM63 is not set
# CONFIG_SENSORS_LM73 is not set
# CONFIG_SENSORS_LM75 is not set
# CONFIG_SENSORS_LM77 is not set
# CONFIG_SENSORS_LM78 is not set
# CONFIG_SENSORS_LM80 is not set
# CONFIG_SENSORS_LM83 is not set
# CONFIG_SENSORS_LM85 is not set
# CONFIG_SENSORS_LM87 is not set
# CONFIG_SENSORS_LM90 is not set
# CONFIG_SENSORS_LM92 is not set
# CONFIG_SENSORS_LM93 is not set
# CONFIG_SENSORS_LM95234 is not set
# CONFIG_SENSORS_LM95241 is not set
# CONFIG_SENSORS_LM95245 is not set
# CONFIG_SENSORS_PC87360 is not set
# CONFIG_SENSORS_PC87427 is not set
# CONFIG_SENSORS_NTC_THERMISTOR is not set
# CONFIG_SENSORS_NCT6683 is not set
# CONFIG_SENSORS_NCT6775 is not set
# CONFIG_SENSORS_NCT7802 is not set
# CONFIG_SENSORS_NCT7904 is not set
# CONFIG_SENSORS_NPCM7XX is not set
# CONFIG_SENSORS_OCC_P8_I2C is not set
# CONFIG_SENSORS_PCF8591 is not set
# CONFIG_PMBUS is not set
# CONFIG_SENSORS_SHT21 is not set
# CONFIG_SENSORS_SHT3x is not set
# CONFIG_SENSORS_SHTC1 is not set
# CONFIG_SENSORS_SIS5595 is not set
# CONFIG_SENSORS_DME1737 is not set
# CONFIG_SENSORS_EMC1403 is not set
# CONFIG_SENSORS_EMC2103 is not set
# CONFIG_SENSORS_EMC6W201 is not set
# CONFIG_SENSORS_SMSC47M1 is not set
# CONFIG_SENSORS_SMSC47M192 is not set
# CONFIG_SENSORS_SMSC47B397 is not set
# CONFIG_SENSORS_SCH5627 is not set
# CONFIG_SENSORS_SCH5636 is not set
# CONFIG_SENSORS_STTS751 is not set
# CONFIG_SENSORS_SMM665 is not set
# CONFIG_SENSORS_ADC128D818 is not set
# CONFIG_SENSORS_ADS1015 is not set
# CONFIG_SENSORS_ADS7828 is not set
# CONFIG_SENSORS_AMC6821 is not set
# CONFIG_SENSORS_INA209 is not set
# CONFIG_SENSORS_INA2XX is not set
# CONFIG_SENSORS_INA3221 is not set
# CONFIG_SENSORS_TC74 is not set
# CONFIG_SENSORS_THMC50 is not set
# CONFIG_SENSORS_TMP102 is not set
# CONFIG_SENSORS_TMP103 is not set
# CONFIG_SENSORS_TMP108 is not set
# CONFIG_SENSORS_TMP401 is not set
# CONFIG_SENSORS_TMP421 is not set
# CONFIG_SENSORS_VIA_CPUTEMP is not set
# CONFIG_SENSORS_VIA686A is not set
# CONFIG_SENSORS_VT1211 is not set
# CONFIG_SENSORS_VT8231 is not set
# CONFIG_SENSORS_W83773G is not set
# CONFIG_SENSORS_W83781D is not set
# CONFIG_SENSORS_W83791D is not set
# CONFIG_SENSORS_W83792D is not set
# CONFIG_SENSORS_W83793 is not set
# CONFIG_SENSORS_W83795 is not set
# CONFIG_SENSORS_W83L785TS is not set
# CONFIG_SENSORS_W83L786NG is not set
# CONFIG_SENSORS_W83627HF is not set
# CONFIG_SENSORS_W83627EHF is not set
# CONFIG_SENSORS_XGENE is not set

#
# ACPI drivers
#
# CONFIG_SENSORS_ACPI_POWER is not set
# CONFIG_SENSORS_ATK0110 is not set
CONFIG_THERMAL=y
# CONFIG_THERMAL_STATISTICS is not set
CONFIG_THERMAL_EMERGENCY_POWEROFF_DELAY_MS=0
CONFIG_THERMAL_HWMON=y
CONFIG_THERMAL_WRITABLE_TRIPS=y
CONFIG_THERMAL_DEFAULT_GOV_STEP_WISE=y
# CONFIG_THERMAL_DEFAULT_GOV_FAIR_SHARE is not set
# CONFIG_THERMAL_DEFAULT_GOV_USER_SPACE is not set
# CONFIG_THERMAL_DEFAULT_GOV_POWER_ALLOCATOR is not set
# CONFIG_THERMAL_GOV_FAIR_SHARE is not set
CONFIG_THERMAL_GOV_STEP_WISE=y
# CONFIG_THERMAL_GOV_BANG_BANG is not set
CONFIG_THERMAL_GOV_USER_SPACE=y
# CONFIG_THERMAL_GOV_POWER_ALLOCATOR is not set
# CONFIG_THERMAL_EMULATION is not set

#
# Intel thermal drivers
#
# CONFIG_INTEL_POWERCLAMP is not set
CONFIG_X86_PKG_TEMP_THERMAL=m
# CONFIG_INTEL_SOC_DTS_THERMAL is not set

#
# ACPI INT340X thermal drivers
#
# CONFIG_INT340X_THERMAL is not set
# CONFIG_INTEL_PCH_THERMAL is not set
CONFIG_WATCHDOG=y
# CONFIG_WATCHDOG_CORE is not set
# CONFIG_WATCHDOG_NOWAYOUT is not set
CONFIG_WATCHDOG_HANDLE_BOOT_ENABLED=y
# CONFIG_WATCHDOG_SYSFS is not set

#
# Watchdog Device Drivers
#
# CONFIG_SOFT_WATCHDOG is not set
# CONFIG_WDAT_WDT is not set
# CONFIG_XILINX_WATCHDOG is not set
# CONFIG_ZIIRAVE_WATCHDOG is not set
# CONFIG_CADENCE_WATCHDOG is not set
# CONFIG_DW_WATCHDOG is not set
# CONFIG_MAX63XX_WATCHDOG is not set
# CONFIG_ACQUIRE_WDT is not set
# CONFIG_ADVANTECH_WDT is not set
# CONFIG_ALIM1535_WDT is not set
# CONFIG_ALIM7101_WDT is not set
# CONFIG_EBC_C384_WDT is not set
# CONFIG_F71808E_WDT is not set
# CONFIG_SP5100_TCO is not set
# CONFIG_SBC_FITPC2_WATCHDOG is not set
# CONFIG_EUROTECH_WDT is not set
# CONFIG_IB700_WDT is not set
# CONFIG_IBMASR is not set
# CONFIG_WAFER_WDT is not set
# CONFIG_I6300ESB_WDT is not set
# CONFIG_IE6XX_WDT is not set
# CONFIG_ITCO_WDT is not set
# CONFIG_IT8712F_WDT is not set
# CONFIG_IT87_WDT is not set
# CONFIG_HP_WATCHDOG is not set
# CONFIG_SC1200_WDT is not set
# CONFIG_PC87413_WDT is not set
# CONFIG_NV_TCO is not set
# CONFIG_60XX_WDT is not set
# CONFIG_CPU5_WDT is not set
# CONFIG_SMSC_SCH311X_WDT is not set
# CONFIG_SMSC37B787_WDT is not set
# CONFIG_TQMX86_WDT is not set
# CONFIG_VIA_WDT is not set
# CONFIG_W83627HF_WDT is not set
# CONFIG_W83877F_WDT is not set
# CONFIG_W83977F_WDT is not set
# CONFIG_MACHZ_WDT is not set
# CONFIG_SBC_EPX_C3_WATCHDOG is not set
# CONFIG_NI903X_WDT is not set
# CONFIG_NIC7018_WDT is not set

#
# PCI-based Watchdog Cards
#
# CONFIG_PCIPCWATCHDOG is not set
# CONFIG_WDTPCI is not set

#
# USB-based Watchdog Cards
#
# CONFIG_USBPCWATCHDOG is not set

#
# Watchdog Pretimeout Governors
#
# CONFIG_WATCHDOG_PRETIMEOUT_GOV is not set
CONFIG_SSB_POSSIBLE=y
# CONFIG_SSB is not set
CONFIG_BCMA_POSSIBLE=y
# CONFIG_BCMA is not set

#
# Multifunction device drivers
#
# CONFIG_MFD_AS3711 is not set
# CONFIG_PMIC_ADP5520 is not set
# CONFIG_MFD_AT91_USART is not set
# CONFIG_MFD_BCM590XX is not set
# CONFIG_MFD_BD9571MWV is not set
# CONFIG_MFD_AXP20X_I2C is not set
# CONFIG_MFD_CROS_EC is not set
# CONFIG_MFD_MADERA is not set
# CONFIG_PMIC_DA903X is not set
# CONFIG_MFD_DA9052_I2C is not set
# CONFIG_MFD_DA9055 is not set
# CONFIG_MFD_DA9062 is not set
# CONFIG_MFD_DA9063 is not set
# CONFIG_MFD_DA9150 is not set
# CONFIG_MFD_DLN2 is not set
# CONFIG_MFD_MC13XXX_I2C is not set
# CONFIG_HTC_PASIC3 is not set
# CONFIG_MFD_INTEL_QUARK_I2C_GPIO is not set
# CONFIG_LPC_ICH is not set
# CONFIG_LPC_SCH is not set
# CONFIG_INTEL_SOC_PMIC_CHTWC is not set
# CONFIG_MFD_INTEL_LPSS_ACPI is not set
# CONFIG_MFD_INTEL_LPSS_PCI is not set
# CONFIG_MFD_JANZ_CMODIO is not set
# CONFIG_MFD_KEMPLD is not set
# CONFIG_MFD_88PM800 is not set
# CONFIG_MFD_88PM805 is not set
# CONFIG_MFD_88PM860X is not set
# CONFIG_MFD_MAX14577 is not set
# CONFIG_MFD_MAX77693 is not set
# CONFIG_MFD_MAX77843 is not set
# CONFIG_MFD_MAX8907 is not set
# CONFIG_MFD_MAX8925 is not set
# CONFIG_MFD_MAX8997 is not set
# CONFIG_MFD_MAX8998 is not set
# CONFIG_MFD_MT6397 is not set
# CONFIG_MFD_MENF21BMC is not set
# CONFIG_MFD_VIPERBOARD is not set
# CONFIG_MFD_RETU is not set
# CONFIG_MFD_PCF50633 is not set
# CONFIG_MFD_RDC321X is not set
# CONFIG_MFD_RT5033 is not set
# CONFIG_MFD_RC5T583 is not set
# CONFIG_MFD_SEC_CORE is not set
# CONFIG_MFD_SI476X_CORE is not set
# CONFIG_MFD_SM501 is not set
# CONFIG_MFD_SKY81452 is not set
# CONFIG_MFD_SMSC is not set
# CONFIG_ABX500_CORE is not set
# CONFIG_MFD_SYSCON is not set
# CONFIG_MFD_TI_AM335X_TSCADC is not set
# CONFIG_MFD_LP3943 is not set
# CONFIG_MFD_LP8788 is not set
# CONFIG_MFD_TI_LMU is not set
# CONFIG_MFD_PALMAS is not set
# CONFIG_TPS6105X is not set
# CONFIG_TPS6507X is not set
# CONFIG_MFD_TPS65086 is not set
# CONFIG_MFD_TPS65090 is not set
# CONFIG_MFD_TPS68470 is not set
# CONFIG_MFD_TI_LP873X is not set
# CONFIG_MFD_TPS6586X is not set
# CONFIG_MFD_TPS65912_I2C is not set
# CONFIG_MFD_TPS80031 is not set
# CONFIG_TWL4030_CORE is not set
# CONFIG_TWL6040_CORE is not set
# CONFIG_MFD_WL1273_CORE is not set
# CONFIG_MFD_LM3533 is not set
# CONFIG_MFD_VX855 is not set
# CONFIG_MFD_ARIZONA_I2C is not set
# CONFIG_MFD_WM8400 is not set
# CONFIG_MFD_WM831X_I2C is not set
# CONFIG_MFD_WM8350_I2C is not set
# CONFIG_MFD_WM8994 is not set
# CONFIG_REGULATOR is not set
# CONFIG_RC_CORE is not set
# CONFIG_MEDIA_SUPPORT is not set

#
# Graphics support
#
CONFIG_AGP=y
CONFIG_AGP_AMD64=y
CONFIG_AGP_INTEL=y
# CONFIG_AGP_SIS is not set
# CONFIG_AGP_VIA is not set
CONFIG_INTEL_GTT=y
CONFIG_VGA_ARB=y
CONFIG_VGA_ARB_MAX_GPUS=16
# CONFIG_VGA_SWITCHEROO is not set
CONFIG_DRM=y
CONFIG_DRM_MIPI_DSI=y
# CONFIG_DRM_DP_AUX_CHARDEV is not set
# CONFIG_DRM_DEBUG_MM is not set
# CONFIG_DRM_DEBUG_SELFTEST is not set
CONFIG_DRM_KMS_HELPER=y
CONFIG_DRM_KMS_FB_HELPER=y
CONFIG_DRM_FBDEV_EMULATION=y
CONFIG_DRM_FBDEV_OVERALLOC=100
# CONFIG_DRM_LOAD_EDID_FIRMWARE is not set
# CONFIG_DRM_DP_CEC is not set
CONFIG_DRM_TTM=y

#
# I2C encoder or helper chips
#
# CONFIG_DRM_I2C_CH7006 is not set
# CONFIG_DRM_I2C_SIL164 is not set
# CONFIG_DRM_I2C_NXP_TDA998X is not set
# CONFIG_DRM_I2C_NXP_TDA9950 is not set
# CONFIG_DRM_RADEON is not set
# CONFIG_DRM_AMDGPU is not set

#
# ACP (Audio CoProcessor) Configuration
#

#
# AMD Library routines
#
# CONFIG_DRM_NOUVEAU is not set
CONFIG_DRM_I915=y
# CONFIG_DRM_I915_ALPHA_SUPPORT is not set
CONFIG_DRM_I915_CAPTURE_ERROR=y
CONFIG_DRM_I915_COMPRESS_ERROR=y
CONFIG_DRM_I915_USERPTR=y
# CONFIG_DRM_I915_GVT is not set
# CONFIG_DRM_VGEM is not set
# CONFIG_DRM_VKMS is not set
# CONFIG_DRM_VMWGFX is not set
# CONFIG_DRM_GMA500 is not set
# CONFIG_DRM_UDL is not set
# CONFIG_DRM_AST is not set
# CONFIG_DRM_MGAG200 is not set
# CONFIG_DRM_CIRRUS_QEMU is not set
# CONFIG_DRM_QXL is not set
# CONFIG_DRM_BOCHS is not set
CONFIG_DRM_VIRTIO_GPU=y
CONFIG_DRM_PANEL=y

#
# Display Panels
#
# CONFIG_DRM_PANEL_RASPBERRYPI_TOUCHSCREEN is not set
CONFIG_DRM_BRIDGE=y
CONFIG_DRM_PANEL_BRIDGE=y

#
# Display Interface Bridges
#
# CONFIG_DRM_ANALOGIX_ANX78XX is not set
# CONFIG_DRM_HISI_HIBMC is not set
# CONFIG_DRM_TINYDRM is not set
# CONFIG_DRM_LEGACY is not set
CONFIG_DRM_PANEL_ORIENTATION_QUIRKS=y

#
# Frame buffer Devices
#
CONFIG_FB_CMDLINE=y
CONFIG_FB_NOTIFY=y
CONFIG_FB=y
# CONFIG_FIRMWARE_EDID is not set
CONFIG_FB_CFB_FILLRECT=y
CONFIG_FB_CFB_COPYAREA=y
CONFIG_FB_CFB_IMAGEBLIT=y
CONFIG_FB_SYS_FILLRECT=y
CONFIG_FB_SYS_COPYAREA=y
CONFIG_FB_SYS_IMAGEBLIT=y
# CONFIG_FB_FOREIGN_ENDIAN is not set
CONFIG_FB_SYS_FOPS=y
CONFIG_FB_DEFERRED_IO=y
CONFIG_FB_MODE_HELPERS=y
CONFIG_FB_TILEBLITTING=y

#
# Frame buffer hardware drivers
#
# CONFIG_FB_CIRRUS is not set
# CONFIG_FB_PM2 is not set
# CONFIG_FB_CYBER2000 is not set
# CONFIG_FB_ARC is not set
# CONFIG_FB_ASILIANT is not set
# CONFIG_FB_IMSTT is not set
# CONFIG_FB_VGA16 is not set
# CONFIG_FB_UVESA is not set
# CONFIG_FB_VESA is not set
CONFIG_FB_EFI=y
# CONFIG_FB_N411 is not set
# CONFIG_FB_HGA is not set
# CONFIG_FB_OPENCORES is not set
# CONFIG_FB_S1D13XXX is not set
# CONFIG_FB_NVIDIA is not set
# CONFIG_FB_RIVA is not set
# CONFIG_FB_I740 is not set
# CONFIG_FB_LE80578 is not set
# CONFIG_FB_MATROX is not set
# CONFIG_FB_RADEON is not set
# CONFIG_FB_ATY128 is not set
# CONFIG_FB_ATY is not set
# CONFIG_FB_S3 is not set
# CONFIG_FB_SAVAGE is not set
# CONFIG_FB_SIS is not set
# CONFIG_FB_NEOMAGIC is not set
# CONFIG_FB_KYRO is not set
# CONFIG_FB_3DFX is not set
# CONFIG_FB_VOODOO1 is not set
# CONFIG_FB_VT8623 is not set
# CONFIG_FB_TRIDENT is not set
# CONFIG_FB_ARK is not set
# CONFIG_FB_PM3 is not set
# CONFIG_FB_CARMINE is not set
# CONFIG_FB_SMSCUFX is not set
# CONFIG_FB_UDL is not set
# CONFIG_FB_IBM_GXT4500 is not set
# CONFIG_FB_VIRTUAL is not set
# CONFIG_FB_METRONOME is not set
# CONFIG_FB_MB862XX is not set
# CONFIG_FB_SIMPLE is not set
# CONFIG_FB_SM712 is not set
CONFIG_BACKLIGHT_LCD_SUPPORT=y
# CONFIG_LCD_CLASS_DEVICE is not set
CONFIG_BACKLIGHT_CLASS_DEVICE=y
CONFIG_BACKLIGHT_GENERIC=y
# CONFIG_BACKLIGHT_APPLE is not set
# CONFIG_BACKLIGHT_PM8941_WLED is not set
# CONFIG_BACKLIGHT_SAHARA is not set
# CONFIG_BACKLIGHT_ADP8860 is not set
# CONFIG_BACKLIGHT_ADP8870 is not set
# CONFIG_BACKLIGHT_LM3639 is not set
# CONFIG_BACKLIGHT_LV5207LP is not set
# CONFIG_BACKLIGHT_BD6107 is not set
# CONFIG_BACKLIGHT_ARCXCNN is not set
CONFIG_HDMI=y

#
# Console display driver support
#
CONFIG_VGA_CONSOLE=y
CONFIG_VGACON_SOFT_SCROLLBACK=y
CONFIG_VGACON_SOFT_SCROLLBACK_SIZE=64
# CONFIG_VGACON_SOFT_SCROLLBACK_PERSISTENT_ENABLE_BY_DEFAULT is not set
CONFIG_DUMMY_CONSOLE=y
CONFIG_DUMMY_CONSOLE_COLUMNS=80
CONFIG_DUMMY_CONSOLE_ROWS=25
CONFIG_FRAMEBUFFER_CONSOLE=y
CONFIG_FRAMEBUFFER_CONSOLE_DETECT_PRIMARY=y
# CONFIG_FRAMEBUFFER_CONSOLE_ROTATION is not set
# CONFIG_FRAMEBUFFER_CONSOLE_DEFERRED_TAKEOVER is not set
CONFIG_LOGO=y
# CONFIG_FB_LOGO_CENTER is not set
# CONFIG_LOGO_LINUX_MONO is not set
# CONFIG_LOGO_LINUX_VGA16 is not set
CONFIG_LOGO_LINUX_CLUT224=y
CONFIG_SOUND=y
CONFIG_SND=y
CONFIG_SND_TIMER=y
CONFIG_SND_PCM=y
CONFIG_SND_HWDEP=y
CONFIG_SND_SEQ_DEVICE=y
CONFIG_SND_JACK=y
CONFIG_SND_JACK_INPUT_DEV=y
# CONFIG_SND_OSSEMUL is not set
CONFIG_SND_PCM_TIMER=y
CONFIG_SND_HRTIMER=y
# CONFIG_SND_DYNAMIC_MINORS is not set
CONFIG_SND_SUPPORT_OLD_API=y
CONFIG_SND_PROC_FS=y
CONFIG_SND_VERBOSE_PROCFS=y
# CONFIG_SND_VERBOSE_PRINTK is not set
# CONFIG_SND_DEBUG is not set
CONFIG_SND_VMASTER=y
CONFIG_SND_DMA_SGBUF=y
CONFIG_SND_SEQUENCER=y
CONFIG_SND_SEQ_DUMMY=y
CONFIG_SND_SEQ_HRTIMER_DEFAULT=y
CONFIG_SND_DRIVERS=y
# CONFIG_SND_PCSP is not set
# CONFIG_SND_DUMMY is not set
# CONFIG_SND_ALOOP is not set
# CONFIG_SND_VIRMIDI is not set
# CONFIG_SND_MTPAV is not set
# CONFIG_SND_SERIAL_U16550 is not set
# CONFIG_SND_MPU401 is not set
CONFIG_SND_PCI=y
# CONFIG_SND_AD1889 is not set
# CONFIG_SND_ALS300 is not set
# CONFIG_SND_ALS4000 is not set
# CONFIG_SND_ALI5451 is not set
# CONFIG_SND_ASIHPI is not set
# CONFIG_SND_ATIIXP is not set
# CONFIG_SND_ATIIXP_MODEM is not set
# CONFIG_SND_AU8810 is not set
# CONFIG_SND_AU8820 is not set
# CONFIG_SND_AU8830 is not set
# CONFIG_SND_AW2 is not set
# CONFIG_SND_AZT3328 is not set
# CONFIG_SND_BT87X is not set
# CONFIG_SND_CA0106 is not set
# CONFIG_SND_CMIPCI is not set
# CONFIG_SND_OXYGEN is not set
# CONFIG_SND_CS4281 is not set
# CONFIG_SND_CS46XX is not set
# CONFIG_SND_CTXFI is not set
# CONFIG_SND_DARLA20 is not set
# CONFIG_SND_GINA20 is not set
# CONFIG_SND_LAYLA20 is not set
# CONFIG_SND_DARLA24 is not set
# CONFIG_SND_GINA24 is not set
# CONFIG_SND_LAYLA24 is not set
# CONFIG_SND_MONA is not set
# CONFIG_SND_MIA is not set
# CONFIG_SND_ECHO3G is not set
# CONFIG_SND_INDIGO is not set
# CONFIG_SND_INDIGOIO is not set
# CONFIG_SND_INDIGODJ is not set
# CONFIG_SND_INDIGOIOX is not set
# CONFIG_SND_INDIGODJX is not set
# CONFIG_SND_EMU10K1 is not set
# CONFIG_SND_EMU10K1X is not set
# CONFIG_SND_ENS1370 is not set
# CONFIG_SND_ENS1371 is not set
# CONFIG_SND_ES1938 is not set
# CONFIG_SND_ES1968 is not set
# CONFIG_SND_FM801 is not set
# CONFIG_SND_HDSP is not set
# CONFIG_SND_HDSPM is not set
# CONFIG_SND_ICE1712 is not set
# CONFIG_SND_ICE1724 is not set
# CONFIG_SND_INTEL8X0 is not set
# CONFIG_SND_INTEL8X0M is not set
# CONFIG_SND_KORG1212 is not set
# CONFIG_SND_LOLA is not set
# CONFIG_SND_LX6464ES is not set
# CONFIG_SND_MAESTRO3 is not set
# CONFIG_SND_MIXART is not set
# CONFIG_SND_NM256 is not set
# CONFIG_SND_PCXHR is not set
# CONFIG_SND_RIPTIDE is not set
# CONFIG_SND_RME32 is not set
# CONFIG_SND_RME96 is not set
# CONFIG_SND_RME9652 is not set
# CONFIG_SND_SE6X is not set
# CONFIG_SND_SONICVIBES is not set
# CONFIG_SND_TRIDENT is not set
# CONFIG_SND_VIA82XX is not set
# CONFIG_SND_VIA82XX_MODEM is not set
# CONFIG_SND_VIRTUOSO is not set
# CONFIG_SND_VX222 is not set
# CONFIG_SND_YMFPCI is not set

#
# HD-Audio
#
CONFIG_SND_HDA=y
CONFIG_SND_HDA_INTEL=y
CONFIG_SND_HDA_HWDEP=y
# CONFIG_SND_HDA_RECONFIG is not set
# CONFIG_SND_HDA_INPUT_BEEP is not set
# CONFIG_SND_HDA_PATCH_LOADER is not set
# CONFIG_SND_HDA_CODEC_REALTEK is not set
# CONFIG_SND_HDA_CODEC_ANALOG is not set
# CONFIG_SND_HDA_CODEC_SIGMATEL is not set
# CONFIG_SND_HDA_CODEC_VIA is not set
# CONFIG_SND_HDA_CODEC_HDMI is not set
# CONFIG_SND_HDA_CODEC_CIRRUS is not set
# CONFIG_SND_HDA_CODEC_CONEXANT is not set
# CONFIG_SND_HDA_CODEC_CA0110 is not set
# CONFIG_SND_HDA_CODEC_CA0132 is not set
# CONFIG_SND_HDA_CODEC_CMEDIA is not set
# CONFIG_SND_HDA_CODEC_SI3054 is not set
# CONFIG_SND_HDA_GENERIC is not set
CONFIG_SND_HDA_POWER_SAVE_DEFAULT=0
CONFIG_SND_HDA_CORE=y
CONFIG_SND_HDA_COMPONENT=y
CONFIG_SND_HDA_I915=y
CONFIG_SND_HDA_PREALLOC_SIZE=64
CONFIG_SND_USB=y
# CONFIG_SND_USB_AUDIO is not set
# CONFIG_SND_USB_UA101 is not set
# CONFIG_SND_USB_USX2Y is not set
# CONFIG_SND_USB_CAIAQ is not set
# CONFIG_SND_USB_US122L is not set
# CONFIG_SND_USB_6FIRE is not set
# CONFIG_SND_USB_HIFACE is not set
# CONFIG_SND_BCD2000 is not set
# CONFIG_SND_USB_POD is not set
# CONFIG_SND_USB_PODHD is not set
# CONFIG_SND_USB_TONEPORT is not set
# CONFIG_SND_USB_VARIAX is not set
CONFIG_SND_PCMCIA=y
# CONFIG_SND_VXPOCKET is not set
# CONFIG_SND_PDAUDIOCF is not set
# CONFIG_SND_SOC is not set
CONFIG_SND_X86=y
# CONFIG_HDMI_LPE_AUDIO is not set

#
# HID support
#
CONFIG_HID=y
# CONFIG_HID_BATTERY_STRENGTH is not set
CONFIG_HIDRAW=y
# CONFIG_UHID is not set
CONFIG_HID_GENERIC=y

#
# Special HID drivers
#
CONFIG_HID_A4TECH=y
# CONFIG_HID_ACCUTOUCH is not set
# CONFIG_HID_ACRUX is not set
CONFIG_HID_APPLE=y
# CONFIG_HID_APPLEIR is not set
# CONFIG_HID_ASUS is not set
# CONFIG_HID_AUREAL is not set
CONFIG_HID_BELKIN=y
# CONFIG_HID_BETOP_FF is not set
# CONFIG_HID_BIGBEN_FF is not set
CONFIG_HID_CHERRY=y
CONFIG_HID_CHICONY=y
# CONFIG_HID_CORSAIR is not set
# CONFIG_HID_COUGAR is not set
# CONFIG_HID_PRODIKEYS is not set
# CONFIG_HID_CMEDIA is not set
CONFIG_HID_CYPRESS=y
# CONFIG_HID_DRAGONRISE is not set
# CONFIG_HID_EMS_FF is not set
# CONFIG_HID_ELAN is not set
# CONFIG_HID_ELECOM is not set
# CONFIG_HID_ELO is not set
CONFIG_HID_EZKEY=y
# CONFIG_HID_GEMBIRD is not set
# CONFIG_HID_GFRM is not set
# CONFIG_HID_HOLTEK is not set
# CONFIG_HID_GT683R is not set
# CONFIG_HID_KEYTOUCH is not set
# CONFIG_HID_KYE is not set
# CONFIG_HID_UCLOGIC is not set
# CONFIG_HID_WALTOP is not set
CONFIG_HID_GYRATION=y
# CONFIG_HID_ICADE is not set
CONFIG_HID_ITE=y
# CONFIG_HID_JABRA is not set
# CONFIG_HID_TWINHAN is not set
CONFIG_HID_KENSINGTON=y
# CONFIG_HID_LCPOWER is not set
# CONFIG_HID_LED is not set
# CONFIG_HID_LENOVO is not set
CONFIG_HID_LOGITECH=y
# CONFIG_HID_LOGITECH_DJ is not set
# CONFIG_HID_LOGITECH_HIDPP is not set
CONFIG_LOGITECH_FF=y
# CONFIG_LOGIRUMBLEPAD2_FF is not set
# CONFIG_LOGIG940_FF is not set
CONFIG_LOGIWHEELS_FF=y
# CONFIG_HID_MAGICMOUSE is not set
# CONFIG_HID_MAYFLASH is not set
CONFIG_HID_REDRAGON=y
CONFIG_HID_MICROSOFT=y
CONFIG_HID_MONTEREY=y
# CONFIG_HID_MULTITOUCH is not set
# CONFIG_HID_NTI is not set
CONFIG_HID_NTRIG=y
# CONFIG_HID_ORTEK is not set
CONFIG_HID_PANTHERLORD=y
CONFIG_PANTHERLORD_FF=y
# CONFIG_HID_PENMOUNT is not set
CONFIG_HID_PETALYNX=y
# CONFIG_HID_PICOLCD is not set
# CONFIG_HID_PLANTRONICS is not set
# CONFIG_HID_PRIMAX is not set
# CONFIG_HID_RETRODE is not set
# CONFIG_HID_ROCCAT is not set
# CONFIG_HID_SAITEK is not set
CONFIG_HID_SAMSUNG=y
CONFIG_HID_SONY=y
# CONFIG_SONY_FF is not set
# CONFIG_HID_SPEEDLINK is not set
# CONFIG_HID_STEAM is not set
# CONFIG_HID_STEELSERIES is not set
CONFIG_HID_SUNPLUS=y
# CONFIG_HID_RMI is not set
# CONFIG_HID_GREENASIA is not set
# CONFIG_HID_SMARTJOYPLUS is not set
# CONFIG_HID_TIVO is not set
CONFIG_HID_TOPSEED=y
# CONFIG_HID_THINGM is not set
# CONFIG_HID_THRUSTMASTER is not set
# CONFIG_HID_UDRAW_PS3 is not set
# CONFIG_HID_WACOM is not set
# CONFIG_HID_WIIMOTE is not set
# CONFIG_HID_XINMO is not set
# CONFIG_HID_ZEROPLUS is not set
# CONFIG_HID_ZYDACRON is not set
# CONFIG_HID_SENSOR_HUB is not set
# CONFIG_HID_ALPS is not set

#
# USB HID support
#
CONFIG_USB_HID=y
CONFIG_HID_PID=y
CONFIG_USB_HIDDEV=y

#
# I2C HID support
#
# CONFIG_I2C_HID is not set

#
# Intel ISH HID support
#
# CONFIG_INTEL_ISH_HID is not set
CONFIG_USB_OHCI_LITTLE_ENDIAN=y
CONFIG_USB_SUPPORT=y
CONFIG_USB_COMMON=y
CONFIG_USB_ARCH_HAS_HCD=y
CONFIG_USB=y
CONFIG_USB_PCI=y
CONFIG_USB_ANNOUNCE_NEW_DEVICES=y

#
# Miscellaneous USB options
#
CONFIG_USB_DEFAULT_PERSIST=y
# CONFIG_USB_DYNAMIC_MINORS is not set
# CONFIG_USB_OTG is not set
# CONFIG_USB_OTG_WHITELIST is not set
# CONFIG_USB_LEDS_TRIGGER_USBPORT is not set
CONFIG_USB_MON=y
# CONFIG_USB_WUSB_CBAF is not set

#
# USB Host Controller Drivers
#
# CONFIG_USB_C67X00_HCD is not set
CONFIG_USB_XHCI_HCD=y
# CONFIG_USB_XHCI_DBGCAP is not set
CONFIG_USB_XHCI_PCI=y
# CONFIG_USB_XHCI_PLATFORM is not set
CONFIG_USB_EHCI_HCD=y
# CONFIG_USB_EHCI_ROOT_HUB_TT is not set
CONFIG_USB_EHCI_TT_NEWSCHED=y
CONFIG_USB_EHCI_PCI=y
# CONFIG_USB_EHCI_HCD_PLATFORM is not set
# CONFIG_USB_OXU210HP_HCD is not set
# CONFIG_USB_ISP116X_HCD is not set
# CONFIG_USB_FOTG210_HCD is not set
CONFIG_USB_OHCI_HCD=y
CONFIG_USB_OHCI_HCD_PCI=y
# CONFIG_USB_OHCI_HCD_PLATFORM is not set
CONFIG_USB_UHCI_HCD=y
# CONFIG_USB_SL811_HCD is not set
# CONFIG_USB_R8A66597_HCD is not set
# CONFIG_USB_HCD_TEST_MODE is not set

#
# USB Device Class drivers
#
# CONFIG_USB_ACM is not set
CONFIG_USB_PRINTER=y
# CONFIG_USB_WDM is not set
# CONFIG_USB_TMC is not set

#
# NOTE: USB_STORAGE depends on SCSI but BLK_DEV_SD may
#

#
# also be needed; see USB_STORAGE Help for more info
#
CONFIG_USB_STORAGE=y
# CONFIG_USB_STORAGE_DEBUG is not set
# CONFIG_USB_STORAGE_REALTEK is not set
# CONFIG_USB_STORAGE_DATAFAB is not set
# CONFIG_USB_STORAGE_FREECOM is not set
# CONFIG_USB_STORAGE_ISD200 is not set
# CONFIG_USB_STORAGE_USBAT is not set
# CONFIG_USB_STORAGE_SDDR09 is not set
# CONFIG_USB_STORAGE_SDDR55 is not set
# CONFIG_USB_STORAGE_JUMPSHOT is not set
# CONFIG_USB_STORAGE_ALAUDA is not set
# CONFIG_USB_STORAGE_ONETOUCH is not set
# CONFIG_USB_STORAGE_KARMA is not set
# CONFIG_USB_STORAGE_CYPRESS_ATACB is not set
# CONFIG_USB_STORAGE_ENE_UB6250 is not set
# CONFIG_USB_UAS is not set

#
# USB Imaging devices
#
# CONFIG_USB_MDC800 is not set
# CONFIG_USB_MICROTEK is not set
# CONFIG_USBIP_CORE is not set
# CONFIG_USB_MUSB_HDRC is not set
# CONFIG_USB_DWC3 is not set
# CONFIG_USB_DWC2 is not set
# CONFIG_USB_CHIPIDEA is not set
# CONFIG_USB_ISP1760 is not set

#
# USB port drivers
#
# CONFIG_USB_SERIAL is not set

#
# USB Miscellaneous drivers
#
# CONFIG_USB_EMI62 is not set
# CONFIG_USB_EMI26 is not set
# CONFIG_USB_ADUTUX is not set
# CONFIG_USB_SEVSEG is not set
# CONFIG_USB_RIO500 is not set
# CONFIG_USB_LEGOTOWER is not set
# CONFIG_USB_LCD is not set
# CONFIG_USB_CYPRESS_CY7C63 is not set
# CONFIG_USB_CYTHERM is not set
# CONFIG_USB_IDMOUSE is not set
# CONFIG_USB_FTDI_ELAN is not set
# CONFIG_USB_APPLEDISPLAY is not set
# CONFIG_USB_SISUSBVGA is not set
# CONFIG_USB_LD is not set
# CONFIG_USB_TRANCEVIBRATOR is not set
# CONFIG_USB_IOWARRIOR is not set
# CONFIG_USB_TEST is not set
# CONFIG_USB_EHSET_TEST_FIXTURE is not set
# CONFIG_USB_ISIGHTFW is not set
# CONFIG_USB_YUREX is not set
# CONFIG_USB_EZUSB_FX2 is not set
# CONFIG_USB_HUB_USB251XB is not set
# CONFIG_USB_HSIC_USB3503 is not set
# CONFIG_USB_HSIC_USB4604 is not set
# CONFIG_USB_LINK_LAYER_TEST is not set
# CONFIG_USB_CHAOSKEY is not set

#
# USB Physical Layer drivers
#
# CONFIG_NOP_USB_XCEIV is not set
# CONFIG_USB_ISP1301 is not set
# CONFIG_USB_GADGET is not set
# CONFIG_TYPEC is not set
# CONFIG_USB_ROLE_SWITCH is not set
# CONFIG_USB_LED_TRIG is not set
# CONFIG_USB_ULPI_BUS is not set
# CONFIG_UWB is not set
# CONFIG_MMC is not set
# CONFIG_MEMSTICK is not set
CONFIG_NEW_LEDS=y
CONFIG_LEDS_CLASS=y
# CONFIG_LEDS_CLASS_FLASH is not set
# CONFIG_LEDS_BRIGHTNESS_HW_CHANGED is not set

#
# LED drivers
#
# CONFIG_LEDS_APU is not set
# CONFIG_LEDS_LM3530 is not set
# CONFIG_LEDS_LM3642 is not set
# CONFIG_LEDS_PCA9532 is not set
# CONFIG_LEDS_LP3944 is not set
# CONFIG_LEDS_LP5521 is not set
# CONFIG_LEDS_LP5523 is not set
# CONFIG_LEDS_LP5562 is not set
# CONFIG_LEDS_LP8501 is not set
# CONFIG_LEDS_CLEVO_MAIL is not set
# CONFIG_LEDS_PCA955X is not set
# CONFIG_LEDS_PCA963X is not set
# CONFIG_LEDS_BD2802 is not set
# CONFIG_LEDS_INTEL_SS4200 is not set
# CONFIG_LEDS_TCA6507 is not set
# CONFIG_LEDS_TLC591XX is not set
# CONFIG_LEDS_LM355x is not set

#
# LED driver for blink(1) USB RGB LED is under Special HID drivers (HID_THINGM)
#
# CONFIG_LEDS_BLINKM is not set
# CONFIG_LEDS_MLXCPLD is not set
# CONFIG_LEDS_MLXREG is not set
# CONFIG_LEDS_USER is not set
# CONFIG_LEDS_NIC78BX is not set

#
# LED Triggers
#
CONFIG_LEDS_TRIGGERS=y
# CONFIG_LEDS_TRIGGER_TIMER is not set
# CONFIG_LEDS_TRIGGER_ONESHOT is not set
# CONFIG_LEDS_TRIGGER_DISK is not set
# CONFIG_LEDS_TRIGGER_HEARTBEAT is not set
# CONFIG_LEDS_TRIGGER_BACKLIGHT is not set
# CONFIG_LEDS_TRIGGER_CPU is not set
# CONFIG_LEDS_TRIGGER_ACTIVITY is not set
# CONFIG_LEDS_TRIGGER_DEFAULT_ON is not set

#
# iptables trigger is under Netfilter config (LED target)
#
# CONFIG_LEDS_TRIGGER_TRANSIENT is not set
# CONFIG_LEDS_TRIGGER_CAMERA is not set
# CONFIG_LEDS_TRIGGER_PANIC is not set
# CONFIG_LEDS_TRIGGER_NETDEV is not set
# CONFIG_LEDS_TRIGGER_PATTERN is not set
# CONFIG_LEDS_TRIGGER_AUDIO is not set
# CONFIG_ACCESSIBILITY is not set
# CONFIG_INFINIBAND is not set
CONFIG_EDAC_ATOMIC_SCRUB=y
CONFIG_EDAC_SUPPORT=y
CONFIG_EDAC=y
CONFIG_EDAC_LEGACY_SYSFS=y
# CONFIG_EDAC_DEBUG is not set
CONFIG_EDAC_DECODE_MCE=y
# CONFIG_EDAC_AMD64 is not set
# CONFIG_EDAC_E752X is not set
# CONFIG_EDAC_I82975X is not set
# CONFIG_EDAC_I3000 is not set
# CONFIG_EDAC_I3200 is not set
# CONFIG_EDAC_IE31200 is not set
# CONFIG_EDAC_X38 is not set
# CONFIG_EDAC_I5400 is not set
# CONFIG_EDAC_I7CORE is not set
# CONFIG_EDAC_I5000 is not set
# CONFIG_EDAC_I5100 is not set
# CONFIG_EDAC_I7300 is not set
# CONFIG_EDAC_SBRIDGE is not set
# CONFIG_EDAC_SKX is not set
# CONFIG_EDAC_PND2 is not set
CONFIG_RTC_LIB=y
CONFIG_RTC_MC146818_LIB=y
CONFIG_RTC_CLASS=y
# CONFIG_RTC_HCTOSYS is not set
CONFIG_RTC_SYSTOHC=y
CONFIG_RTC_SYSTOHC_DEVICE="rtc0"
# CONFIG_RTC_DEBUG is not set
CONFIG_RTC_NVMEM=y

#
# RTC interfaces
#
CONFIG_RTC_INTF_SYSFS=y
CONFIG_RTC_INTF_PROC=y
CONFIG_RTC_INTF_DEV=y
# CONFIG_RTC_INTF_DEV_UIE_EMUL is not set
# CONFIG_RTC_DRV_TEST is not set

#
# I2C RTC drivers
#
# CONFIG_RTC_DRV_ABB5ZES3 is not set
# CONFIG_RTC_DRV_ABX80X is not set
# CONFIG_RTC_DRV_DS1307 is not set
# CONFIG_RTC_DRV_DS1374 is not set
# CONFIG_RTC_DRV_DS1672 is not set
# CONFIG_RTC_DRV_MAX6900 is not set
# CONFIG_RTC_DRV_RS5C372 is not set
# CONFIG_RTC_DRV_ISL1208 is not set
# CONFIG_RTC_DRV_ISL12022 is not set
# CONFIG_RTC_DRV_X1205 is not set
# CONFIG_RTC_DRV_PCF8523 is not set
# CONFIG_RTC_DRV_PCF85063 is not set
# CONFIG_RTC_DRV_PCF85363 is not set
# CONFIG_RTC_DRV_PCF8563 is not set
# CONFIG_RTC_DRV_PCF8583 is not set
# CONFIG_RTC_DRV_M41T80 is not set
# CONFIG_RTC_DRV_BQ32K is not set
# CONFIG_RTC_DRV_S35390A is not set
# CONFIG_RTC_DRV_FM3130 is not set
# CONFIG_RTC_DRV_RX8010 is not set
# CONFIG_RTC_DRV_RX8581 is not set
# CONFIG_RTC_DRV_RX8025 is not set
# CONFIG_RTC_DRV_EM3027 is not set
# CONFIG_RTC_DRV_RV8803 is not set

#
# SPI RTC drivers
#
CONFIG_RTC_I2C_AND_SPI=y

#
# SPI and I2C RTC drivers
#
# CONFIG_RTC_DRV_DS3232 is not set
# CONFIG_RTC_DRV_PCF2127 is not set
# CONFIG_RTC_DRV_RV3029C2 is not set

#
# Platform RTC drivers
#
CONFIG_RTC_DRV_CMOS=y
# CONFIG_RTC_DRV_DS1286 is not set
# CONFIG_RTC_DRV_DS1511 is not set
# CONFIG_RTC_DRV_DS1553 is not set
# CONFIG_RTC_DRV_DS1685_FAMILY is not set
# CONFIG_RTC_DRV_DS1742 is not set
# CONFIG_RTC_DRV_DS2404 is not set
# CONFIG_RTC_DRV_STK17TA8 is not set
# CONFIG_RTC_DRV_M48T86 is not set
# CONFIG_RTC_DRV_M48T35 is not set
# CONFIG_RTC_DRV_M48T59 is not set
# CONFIG_RTC_DRV_MSM6242 is not set
# CONFIG_RTC_DRV_BQ4802 is not set
# CONFIG_RTC_DRV_RP5C01 is not set
# CONFIG_RTC_DRV_V3020 is not set

#
# on-CPU RTC drivers
#
# CONFIG_RTC_DRV_FTRTC010 is not set

#
# HID Sensor RTC drivers
#
# CONFIG_RTC_DRV_HID_SENSOR_TIME is not set
CONFIG_DMADEVICES=y
# CONFIG_DMADEVICES_DEBUG is not set

#
# DMA Devices
#
CONFIG_DMA_ENGINE=y
CONFIG_DMA_VIRTUAL_CHANNELS=y
CONFIG_DMA_ACPI=y
# CONFIG_ALTERA_MSGDMA is not set
# CONFIG_INTEL_IDMA64 is not set
# CONFIG_INTEL_IOATDMA is not set
# CONFIG_QCOM_HIDMA_MGMT is not set
# CONFIG_QCOM_HIDMA is not set
CONFIG_DW_DMAC_CORE=y
# CONFIG_DW_DMAC is not set
# CONFIG_DW_DMAC_PCI is not set
CONFIG_HSU_DMA=y

#
# DMA Clients
#
# CONFIG_ASYNC_TX_DMA is not set
# CONFIG_DMATEST is not set

#
# DMABUF options
#
CONFIG_SYNC_FILE=y
# CONFIG_SW_SYNC is not set
# CONFIG_UDMABUF is not set
# CONFIG_AUXDISPLAY is not set
# CONFIG_UIO is not set
# CONFIG_VFIO is not set
# CONFIG_VIRT_DRIVERS is not set
CONFIG_VIRTIO=y
CONFIG_VIRTIO_MENU=y
CONFIG_VIRTIO_PCI=y
CONFIG_VIRTIO_PCI_LEGACY=y
# CONFIG_VIRTIO_BALLOON is not set
CONFIG_VIRTIO_INPUT=y
# CONFIG_VIRTIO_MMIO is not set

#
# Microsoft Hyper-V guest support
#
# CONFIG_HYPERV is not set
# CONFIG_STAGING is not set
CONFIG_X86_PLATFORM_DEVICES=y
# CONFIG_ACER_WIRELESS is not set
# CONFIG_ACERHDF is not set
# CONFIG_ASUS_LAPTOP is not set
# CONFIG_DCDBAS is not set
# CONFIG_DELL_SMBIOS is not set
# CONFIG_DELL_SMO8800 is not set
# CONFIG_DELL_RBTN is not set
# CONFIG_DELL_RBU is not set
# CONFIG_FUJITSU_LAPTOP is not set
# CONFIG_FUJITSU_TABLET is not set
# CONFIG_AMILO_RFKILL is not set
# CONFIG_GPD_POCKET_FAN is not set
# CONFIG_HP_ACCEL is not set
# CONFIG_HP_WIRELESS is not set
# CONFIG_MSI_LAPTOP is not set
# CONFIG_PANASONIC_LAPTOP is not set
# CONFIG_COMPAL_LAPTOP is not set
# CONFIG_SONY_LAPTOP is not set
# CONFIG_IDEAPAD_LAPTOP is not set
# CONFIG_THINKPAD_ACPI is not set
# CONFIG_SENSORS_HDAPS is not set
# CONFIG_INTEL_MENLOW is not set
CONFIG_EEEPC_LAPTOP=y
# CONFIG_ASUS_WIRELESS is not set
# CONFIG_ACPI_WMI is not set
# CONFIG_TOPSTAR_LAPTOP is not set
# CONFIG_TOSHIBA_BT_RFKILL is not set
# CONFIG_TOSHIBA_HAPS is not set
# CONFIG_ACPI_CMPC is not set
# CONFIG_INTEL_HID_EVENT is not set
# CONFIG_INTEL_VBTN is not set
# CONFIG_INTEL_IPS is not set
# CONFIG_INTEL_PMC_CORE is not set
# CONFIG_IBM_RTL is not set
# CONFIG_SAMSUNG_LAPTOP is not set
# CONFIG_INTEL_OAKTRAIL is not set
# CONFIG_SAMSUNG_Q10 is not set
# CONFIG_APPLE_GMUX is not set
# CONFIG_INTEL_RST is not set
# CONFIG_INTEL_SMARTCONNECT is not set
# CONFIG_INTEL_PMC_IPC is not set
# CONFIG_SURFACE_PRO3_BUTTON is not set
# CONFIG_INTEL_PUNIT_IPC is not set
# CONFIG_MLX_PLATFORM is not set
# CONFIG_INTEL_TURBO_MAX_3 is not set
# CONFIG_I2C_MULTI_INSTANTIATE is not set
# CONFIG_INTEL_ATOMISP2_PM is not set
CONFIG_PMC_ATOM=y
# CONFIG_CHROME_PLATFORMS is not set
# CONFIG_MELLANOX_PLATFORM is not set
CONFIG_CLKDEV_LOOKUP=y
CONFIG_HAVE_CLK_PREPARE=y
CONFIG_COMMON_CLK=y

#
# Common Clock Framework
#
# CONFIG_COMMON_CLK_MAX9485 is not set
# CONFIG_COMMON_CLK_SI5351 is not set
# CONFIG_COMMON_CLK_SI544 is not set
# CONFIG_COMMON_CLK_CDCE706 is not set
# CONFIG_COMMON_CLK_CS2000_CP is not set
# CONFIG_HWSPINLOCK is not set

#
# Clock Source drivers
#
CONFIG_CLKEVT_I8253=y
CONFIG_I8253_LOCK=y
CONFIG_CLKBLD_I8253=y
CONFIG_MAILBOX=y
CONFIG_PCC=y
# CONFIG_ALTERA_MBOX is not set
CONFIG_IOMMU_API=y
CONFIG_IOMMU_SUPPORT=y

#
# Generic IOMMU Pagetable Support
#
# CONFIG_IOMMU_DEBUGFS is not set
# CONFIG_IOMMU_DEFAULT_PASSTHROUGH is not set
CONFIG_IOMMU_IOVA=y
CONFIG_AMD_IOMMU=y
# CONFIG_AMD_IOMMU_V2 is not set
CONFIG_DMAR_TABLE=y
CONFIG_INTEL_IOMMU=y
# CONFIG_INTEL_IOMMU_SVM is not set
# CONFIG_INTEL_IOMMU_DEFAULT_ON is not set
CONFIG_INTEL_IOMMU_FLOPPY_WA=y
# CONFIG_IRQ_REMAP is not set

#
# Remoteproc drivers
#
# CONFIG_REMOTEPROC is not set

#
# Rpmsg drivers
#
# CONFIG_RPMSG_QCOM_GLINK_RPM is not set
# CONFIG_RPMSG_VIRTIO is not set
# CONFIG_SOUNDWIRE is not set

#
# SOC (System On Chip) specific Drivers
#

#
# Amlogic SoC drivers
#

#
# Broadcom SoC drivers
#

#
# NXP/Freescale QorIQ SoC drivers
#

#
# i.MX SoC drivers
#

#
# Qualcomm SoC drivers
#
# CONFIG_SOC_TI is not set

#
# Xilinx SoC drivers
#
# CONFIG_XILINX_VCU is not set
# CONFIG_PM_DEVFREQ is not set
# CONFIG_EXTCON is not set
# CONFIG_MEMORY is not set
# CONFIG_IIO is not set
# CONFIG_NTB is not set
# CONFIG_VME_BUS is not set
# CONFIG_PWM is not set

#
# IRQ chip support
#
CONFIG_ARM_GIC_MAX_NR=1
# CONFIG_IPACK_BUS is not set
# CONFIG_RESET_CONTROLLER is not set
# CONFIG_FMC is not set

#
# PHY Subsystem
#
# CONFIG_GENERIC_PHY is not set
# CONFIG_BCM_KONA_USB2_PHY is not set
# CONFIG_PHY_PXA_28NM_HSIC is not set
# CONFIG_PHY_PXA_28NM_USB2 is not set
# CONFIG_POWERCAP is not set
# CONFIG_MCB is not set

#
# Performance monitor support
#
CONFIG_RAS=y
# CONFIG_THUNDERBOLT is not set

#
# Android
#
# CONFIG_ANDROID is not set
# CONFIG_LIBNVDIMM is not set
# CONFIG_DAX is not set
CONFIG_NVMEM=y

#
# HW tracing support
#
# CONFIG_STM is not set
# CONFIG_INTEL_TH is not set
# CONFIG_FPGA is not set
# CONFIG_UNISYS_VISORBUS is not set
# CONFIG_SIOX is not set
# CONFIG_SLIMBUS is not set

#
# File systems
#
CONFIG_DCACHE_WORD_ACCESS=y
CONFIG_FS_IOMAP=y
# CONFIG_EXT2_FS is not set
# CONFIG_EXT3_FS is not set
CONFIG_EXT4_FS=y
CONFIG_EXT4_USE_FOR_EXT2=y
CONFIG_EXT4_FS_POSIX_ACL=y
CONFIG_EXT4_FS_SECURITY=y
# CONFIG_EXT4_ENCRYPTION is not set
# CONFIG_EXT4_DEBUG is not set
CONFIG_JBD2=y
# CONFIG_JBD2_DEBUG is not set
CONFIG_FS_MBCACHE=y
# CONFIG_REISERFS_FS is not set
# CONFIG_JFS_FS is not set
# CONFIG_XFS_FS is not set
# CONFIG_GFS2_FS is not set
# CONFIG_OCFS2_FS is not set
# CONFIG_BTRFS_FS is not set
# CONFIG_NILFS2_FS is not set
# CONFIG_F2FS_FS is not set
# CONFIG_FS_DAX is not set
CONFIG_FS_POSIX_ACL=y
CONFIG_EXPORTFS=y
# CONFIG_EXPORTFS_BLOCK_OPS is not set
CONFIG_FILE_LOCKING=y
CONFIG_MANDATORY_FILE_LOCKING=y
# CONFIG_FS_ENCRYPTION is not set
CONFIG_FSNOTIFY=y
CONFIG_DNOTIFY=y
CONFIG_INOTIFY_USER=y
# CONFIG_FANOTIFY is not set
CONFIG_QUOTA=y
CONFIG_QUOTA_NETLINK_INTERFACE=y
# CONFIG_PRINT_QUOTA_WARNING is not set
# CONFIG_QUOTA_DEBUG is not set
CONFIG_QUOTA_TREE=y
# CONFIG_QFMT_V1 is not set
CONFIG_QFMT_V2=y
CONFIG_QUOTACTL=y
CONFIG_QUOTACTL_COMPAT=y
CONFIG_AUTOFS4_FS=y
CONFIG_AUTOFS_FS=y
# CONFIG_FUSE_FS is not set
# CONFIG_OVERLAY_FS is not set

#
# Caches
#
# CONFIG_FSCACHE is not set

#
# CD-ROM/DVD Filesystems
#
CONFIG_ISO9660_FS=y
CONFIG_JOLIET=y
CONFIG_ZISOFS=y
# CONFIG_UDF_FS is not set

#
# DOS/FAT/NT Filesystems
#
CONFIG_FAT_FS=y
CONFIG_MSDOS_FS=y
CONFIG_VFAT_FS=y
CONFIG_FAT_DEFAULT_CODEPAGE=437
CONFIG_FAT_DEFAULT_IOCHARSET="iso8859-1"
# CONFIG_FAT_DEFAULT_UTF8 is not set
# CONFIG_NTFS_FS is not set

#
# Pseudo filesystems
#
CONFIG_PROC_FS=y
CONFIG_PROC_KCORE=y
CONFIG_PROC_VMCORE=y
# CONFIG_PROC_VMCORE_DEVICE_DUMP is not set
CONFIG_PROC_SYSCTL=y
CONFIG_PROC_PAGE_MONITOR=y
# CONFIG_PROC_CHILDREN is not set
CONFIG_KERNFS=y
CONFIG_SYSFS=y
CONFIG_TMPFS=y
CONFIG_TMPFS_POSIX_ACL=y
CONFIG_TMPFS_XATTR=y
CONFIG_HUGETLBFS=y
CONFIG_HUGETLB_PAGE=y
CONFIG_MEMFD_CREATE=y
CONFIG_CONFIGFS_FS=y
CONFIG_EFIVAR_FS=m
CONFIG_MISC_FILESYSTEMS=y
# CONFIG_ORANGEFS_FS is not set
# CONFIG_ADFS_FS is not set
# CONFIG_AFFS_FS is not set
# CONFIG_ECRYPT_FS is not set
# CONFIG_HFS_FS is not set
# CONFIG_HFSPLUS_FS is not set
# CONFIG_BEFS_FS is not set
# CONFIG_BFS_FS is not set
# CONFIG_EFS_FS is not set
# CONFIG_CRAMFS is not set
# CONFIG_SQUASHFS is not set
# CONFIG_VXFS_FS is not set
# CONFIG_MINIX_FS is not set
# CONFIG_OMFS_FS is not set
# CONFIG_HPFS_FS is not set
# CONFIG_QNX4FS_FS is not set
# CONFIG_QNX6FS_FS is not set
# CONFIG_ROMFS_FS is not set
# CONFIG_PSTORE is not set
# CONFIG_SYSV_FS is not set
# CONFIG_UFS_FS is not set
CONFIG_NETWORK_FILESYSTEMS=y
CONFIG_NFS_FS=y
CONFIG_NFS_V2=y
CONFIG_NFS_V3=y
CONFIG_NFS_V3_ACL=y
CONFIG_NFS_V4=y
# CONFIG_NFS_SWAP is not set
# CONFIG_NFS_V4_1 is not set
CONFIG_ROOT_NFS=y
# CONFIG_NFS_USE_LEGACY_DNS is not set
CONFIG_NFS_USE_KERNEL_DNS=y
# CONFIG_NFSD is not set
CONFIG_GRACE_PERIOD=y
CONFIG_LOCKD=y
CONFIG_LOCKD_V4=y
CONFIG_NFS_ACL_SUPPORT=y
CONFIG_NFS_COMMON=y
CONFIG_SUNRPC=y
CONFIG_SUNRPC_GSS=y
# CONFIG_SUNRPC_DEBUG is not set
# CONFIG_CEPH_FS is not set
# CONFIG_CIFS is not set
# CONFIG_CODA_FS is not set
# CONFIG_AFS_FS is not set
CONFIG_9P_FS=y
# CONFIG_9P_FS_POSIX_ACL is not set
# CONFIG_9P_FS_SECURITY is not set
CONFIG_NLS=y
CONFIG_NLS_DEFAULT="utf8"
CONFIG_NLS_CODEPAGE_437=y
# CONFIG_NLS_CODEPAGE_737 is not set
# CONFIG_NLS_CODEPAGE_775 is not set
# CONFIG_NLS_CODEPAGE_850 is not set
# CONFIG_NLS_CODEPAGE_852 is not set
# CONFIG_NLS_CODEPAGE_855 is not set
# CONFIG_NLS_CODEPAGE_857 is not set
# CONFIG_NLS_CODEPAGE_860 is not set
# CONFIG_NLS_CODEPAGE_861 is not set
# CONFIG_NLS_CODEPAGE_862 is not set
# CONFIG_NLS_CODEPAGE_863 is not set
# CONFIG_NLS_CODEPAGE_864 is not set
# CONFIG_NLS_CODEPAGE_865 is not set
# CONFIG_NLS_CODEPAGE_866 is not set
# CONFIG_NLS_CODEPAGE_869 is not set
# CONFIG_NLS_CODEPAGE_936 is not set
# CONFIG_NLS_CODEPAGE_950 is not set
# CONFIG_NLS_CODEPAGE_932 is not set
# CONFIG_NLS_CODEPAGE_949 is not set
# CONFIG_NLS_CODEPAGE_874 is not set
# CONFIG_NLS_ISO8859_8 is not set
# CONFIG_NLS_CODEPAGE_1250 is not set
# CONFIG_NLS_CODEPAGE_1251 is not set
CONFIG_NLS_ASCII=y
CONFIG_NLS_ISO8859_1=y
# CONFIG_NLS_ISO8859_2 is not set
# CONFIG_NLS_ISO8859_3 is not set
# CONFIG_NLS_ISO8859_4 is not set
# CONFIG_NLS_ISO8859_5 is not set
# CONFIG_NLS_ISO8859_6 is not set
# CONFIG_NLS_ISO8859_7 is not set
# CONFIG_NLS_ISO8859_9 is not set
# CONFIG_NLS_ISO8859_13 is not set
# CONFIG_NLS_ISO8859_14 is not set
# CONFIG_NLS_ISO8859_15 is not set
# CONFIG_NLS_KOI8_R is not set
# CONFIG_NLS_KOI8_U is not set
# CONFIG_NLS_MAC_ROMAN is not set
# CONFIG_NLS_MAC_CELTIC is not set
# CONFIG_NLS_MAC_CENTEURO is not set
# CONFIG_NLS_MAC_CROATIAN is not set
# CONFIG_NLS_MAC_CYRILLIC is not set
# CONFIG_NLS_MAC_GAELIC is not set
# CONFIG_NLS_MAC_GREEK is not set
# CONFIG_NLS_MAC_ICELAND is not set
# CONFIG_NLS_MAC_INUIT is not set
# CONFIG_NLS_MAC_ROMANIAN is not set
# CONFIG_NLS_MAC_TURKISH is not set
CONFIG_NLS_UTF8=y
# CONFIG_DLM is not set

#
# Security options
#
CONFIG_KEYS=y
CONFIG_KEYS_COMPAT=y
# CONFIG_PERSISTENT_KEYRINGS is not set
# CONFIG_BIG_KEYS is not set
# CONFIG_ENCRYPTED_KEYS is not set
# CONFIG_KEY_DH_OPERATIONS is not set
# CONFIG_SECURITY_DMESG_RESTRICT is not set
CONFIG_SECURITY=y
CONFIG_SECURITY_WRITABLE_HOOKS=y
CONFIG_SECURITYFS=y
CONFIG_SECURITY_NETWORK=y
CONFIG_PAGE_TABLE_ISOLATION=y
# CONFIG_SECURITY_NETWORK_XFRM is not set
# CONFIG_SECURITY_PATH is not set
# CONFIG_INTEL_TXT is not set
CONFIG_LSM_MMAP_MIN_ADDR=65536
CONFIG_HAVE_HARDENED_USERCOPY_ALLOCATOR=y
CONFIG_HARDENED_USERCOPY=y
CONFIG_HARDENED_USERCOPY_FALLBACK=y
CONFIG_FORTIFY_SOURCE=y
# CONFIG_STATIC_USERMODEHELPER is not set
CONFIG_SECURITY_SELINUX=y
CONFIG_SECURITY_SELINUX_BOOTPARAM=y
CONFIG_SECURITY_SELINUX_BOOTPARAM_VALUE=1
CONFIG_SECURITY_SELINUX_DISABLE=y
CONFIG_SECURITY_SELINUX_DEVELOP=y
CONFIG_SECURITY_SELINUX_AVC_STATS=y
CONFIG_SECURITY_SELINUX_CHECKREQPROT_VALUE=0
# CONFIG_SECURITY_SMACK is not set
# CONFIG_SECURITY_TOMOYO is not set
# CONFIG_SECURITY_APPARMOR is not set
# CONFIG_SECURITY_LOADPIN is not set
# CONFIG_SECURITY_YAMA is not set
CONFIG_INTEGRITY=y
# CONFIG_INTEGRITY_SIGNATURE is not set
CONFIG_INTEGRITY_AUDIT=y
# CONFIG_IMA is not set
# CONFIG_EVM is not set
CONFIG_DEFAULT_SECURITY_SELINUX=y
# CONFIG_DEFAULT_SECURITY_DAC is not set
CONFIG_DEFAULT_SECURITY="selinux"
CONFIG_CRYPTO=y

#
# Crypto core or helper
#
CONFIG_CRYPTO_ALGAPI=y
CONFIG_CRYPTO_ALGAPI2=y
CONFIG_CRYPTO_AEAD=y
CONFIG_CRYPTO_AEAD2=y
CONFIG_CRYPTO_BLKCIPHER=y
CONFIG_CRYPTO_BLKCIPHER2=y
CONFIG_CRYPTO_HASH=y
CONFIG_CRYPTO_HASH2=y
CONFIG_CRYPTO_RNG=y
CONFIG_CRYPTO_RNG2=y
CONFIG_CRYPTO_RNG_DEFAULT=y
CONFIG_CRYPTO_AKCIPHER2=y
CONFIG_CRYPTO_AKCIPHER=y
CONFIG_CRYPTO_KPP2=y
CONFIG_CRYPTO_ACOMP2=y
CONFIG_CRYPTO_RSA=y
# CONFIG_CRYPTO_DH is not set
# CONFIG_CRYPTO_ECDH is not set
CONFIG_CRYPTO_MANAGER=y
CONFIG_CRYPTO_MANAGER2=y
# CONFIG_CRYPTO_USER is not set
CONFIG_CRYPTO_MANAGER_DISABLE_TESTS=y
CONFIG_CRYPTO_GF128MUL=y
CONFIG_CRYPTO_NULL=y
CONFIG_CRYPTO_NULL2=y
# CONFIG_CRYPTO_PCRYPT is not set
CONFIG_CRYPTO_WORKQUEUE=y
# CONFIG_CRYPTO_CRYPTD is not set
CONFIG_CRYPTO_AUTHENC=y
# CONFIG_CRYPTO_TEST is not set
CONFIG_CRYPTO_ENGINE=m

#
# Authenticated Encryption with Associated Data
#
CONFIG_CRYPTO_CCM=y
CONFIG_CRYPTO_GCM=y
# CONFIG_CRYPTO_CHACHA20POLY1305 is not set
# CONFIG_CRYPTO_AEGIS128 is not set
# CONFIG_CRYPTO_AEGIS128L is not set
# CONFIG_CRYPTO_AEGIS256 is not set
# CONFIG_CRYPTO_AEGIS128_AESNI_SSE2 is not set
# CONFIG_CRYPTO_AEGIS128L_AESNI_SSE2 is not set
# CONFIG_CRYPTO_AEGIS256_AESNI_SSE2 is not set
# CONFIG_CRYPTO_MORUS640 is not set
# CONFIG_CRYPTO_MORUS640_SSE2 is not set
# CONFIG_CRYPTO_MORUS1280 is not set
# CONFIG_CRYPTO_MORUS1280_SSE2 is not set
# CONFIG_CRYPTO_MORUS1280_AVX2 is not set
CONFIG_CRYPTO_SEQIV=y
CONFIG_CRYPTO_ECHAINIV=y

#
# Block modes
#
CONFIG_CRYPTO_CBC=y
# CONFIG_CRYPTO_CFB is not set
CONFIG_CRYPTO_CTR=y
# CONFIG_CRYPTO_CTS is not set
# CONFIG_CRYPTO_ECB is not set
# CONFIG_CRYPTO_LRW is not set
# CONFIG_CRYPTO_OFB is not set
# CONFIG_CRYPTO_PCBC is not set
# CONFIG_CRYPTO_XTS is not set
# CONFIG_CRYPTO_KEYWRAP is not set
# CONFIG_CRYPTO_NHPOLY1305_SSE2 is not set
# CONFIG_CRYPTO_NHPOLY1305_AVX2 is not set
# CONFIG_CRYPTO_ADIANTUM is not set

#
# Hash modes
#
CONFIG_CRYPTO_CMAC=y
CONFIG_CRYPTO_HMAC=y
# CONFIG_CRYPTO_XCBC is not set
# CONFIG_CRYPTO_VMAC is not set

#
# Digest
#
CONFIG_CRYPTO_CRC32C=y
# CONFIG_CRYPTO_CRC32C_INTEL is not set
# CONFIG_CRYPTO_CRC32 is not set
# CONFIG_CRYPTO_CRC32_PCLMUL is not set
# CONFIG_CRYPTO_CRCT10DIF is not set
CONFIG_CRYPTO_GHASH=y
# CONFIG_CRYPTO_POLY1305 is not set
# CONFIG_CRYPTO_POLY1305_X86_64 is not set
# CONFIG_CRYPTO_MD4 is not set
CONFIG_CRYPTO_MD5=y
# CONFIG_CRYPTO_MICHAEL_MIC is not set
# CONFIG_CRYPTO_RMD128 is not set
# CONFIG_CRYPTO_RMD160 is not set
# CONFIG_CRYPTO_RMD256 is not set
# CONFIG_CRYPTO_RMD320 is not set
CONFIG_CRYPTO_SHA1=y
# CONFIG_CRYPTO_SHA1_SSSE3 is not set
# CONFIG_CRYPTO_SHA256_SSSE3 is not set
# CONFIG_CRYPTO_SHA512_SSSE3 is not set
CONFIG_CRYPTO_SHA256=y
# CONFIG_CRYPTO_SHA512 is not set
# CONFIG_CRYPTO_SHA3 is not set
# CONFIG_CRYPTO_SM3 is not set
# CONFIG_CRYPTO_STREEBOG is not set
# CONFIG_CRYPTO_TGR192 is not set
# CONFIG_CRYPTO_WP512 is not set
# CONFIG_CRYPTO_GHASH_CLMUL_NI_INTEL is not set

#
# Ciphers
#
CONFIG_CRYPTO_AES=y
# CONFIG_CRYPTO_AES_TI is not set
# CONFIG_CRYPTO_AES_X86_64 is not set
# CONFIG_CRYPTO_AES_NI_INTEL is not set
# CONFIG_CRYPTO_ANUBIS is not set
CONFIG_CRYPTO_ARC4=y
# CONFIG_CRYPTO_BLOWFISH is not set
# CONFIG_CRYPTO_BLOWFISH_X86_64 is not set
# CONFIG_CRYPTO_CAMELLIA is not set
# CONFIG_CRYPTO_CAMELLIA_X86_64 is not set
# CONFIG_CRYPTO_CAMELLIA_AESNI_AVX_X86_64 is not set
# CONFIG_CRYPTO_CAMELLIA_AESNI_AVX2_X86_64 is not set
# CONFIG_CRYPTO_CAST5 is not set
# CONFIG_CRYPTO_CAST5_AVX_X86_64 is not set
# CONFIG_CRYPTO_CAST6 is not set
# CONFIG_CRYPTO_CAST6_AVX_X86_64 is not set
CONFIG_CRYPTO_DES=y
# CONFIG_CRYPTO_DES3_EDE_X86_64 is not set
# CONFIG_CRYPTO_FCRYPT is not set
# CONFIG_CRYPTO_KHAZAD is not set
# CONFIG_CRYPTO_SALSA20 is not set
# CONFIG_CRYPTO_CHACHA20 is not set
# CONFIG_CRYPTO_CHACHA20_X86_64 is not set
# CONFIG_CRYPTO_SEED is not set
# CONFIG_CRYPTO_SERPENT is not set
# CONFIG_CRYPTO_SERPENT_SSE2_X86_64 is not set
# CONFIG_CRYPTO_SERPENT_AVX_X86_64 is not set
# CONFIG_CRYPTO_SERPENT_AVX2_X86_64 is not set
# CONFIG_CRYPTO_SM4 is not set
# CONFIG_CRYPTO_TEA is not set
# CONFIG_CRYPTO_TWOFISH is not set
# CONFIG_CRYPTO_TWOFISH_X86_64 is not set
# CONFIG_CRYPTO_TWOFISH_X86_64_3WAY is not set
# CONFIG_CRYPTO_TWOFISH_AVX_X86_64 is not set

#
# Compression
#
# CONFIG_CRYPTO_DEFLATE is not set
# CONFIG_CRYPTO_LZO is not set
# CONFIG_CRYPTO_842 is not set
# CONFIG_CRYPTO_LZ4 is not set
# CONFIG_CRYPTO_LZ4HC is not set
# CONFIG_CRYPTO_ZSTD is not set

#
# Random Number Generation
#
# CONFIG_CRYPTO_ANSI_CPRNG is not set
CONFIG_CRYPTO_DRBG_MENU=y
CONFIG_CRYPTO_DRBG_HMAC=y
# CONFIG_CRYPTO_DRBG_HASH is not set
# CONFIG_CRYPTO_DRBG_CTR is not set
CONFIG_CRYPTO_DRBG=y
CONFIG_CRYPTO_JITTERENTROPY=y
# CONFIG_CRYPTO_USER_API_HASH is not set
# CONFIG_CRYPTO_USER_API_SKCIPHER is not set
# CONFIG_CRYPTO_USER_API_RNG is not set
# CONFIG_CRYPTO_USER_API_AEAD is not set
CONFIG_CRYPTO_HASH_INFO=y
CONFIG_CRYPTO_HW=y
# CONFIG_CRYPTO_DEV_PADLOCK is not set
# CONFIG_CRYPTO_DEV_CCP is not set
# CONFIG_CRYPTO_DEV_QAT_DH895xCC is not set
# CONFIG_CRYPTO_DEV_QAT_C3XXX is not set
# CONFIG_CRYPTO_DEV_QAT_C62X is not set
# CONFIG_CRYPTO_DEV_QAT_DH895xCCVF is not set
# CONFIG_CRYPTO_DEV_QAT_C3XXXVF is not set
# CONFIG_CRYPTO_DEV_QAT_C62XVF is not set
# CONFIG_CRYPTO_DEV_NITROX_CNN55XX is not set
CONFIG_CRYPTO_DEV_VIRTIO=m
CONFIG_ASYMMETRIC_KEY_TYPE=y
CONFIG_ASYMMETRIC_PUBLIC_KEY_SUBTYPE=y
CONFIG_X509_CERTIFICATE_PARSER=y
# CONFIG_PKCS8_PRIVATE_KEY_PARSER is not set
CONFIG_PKCS7_MESSAGE_PARSER=y
# CONFIG_PKCS7_TEST_KEY is not set
# CONFIG_SIGNED_PE_FILE_VERIFICATION is not set

#
# Certificates for signature checking
#
CONFIG_SYSTEM_TRUSTED_KEYRING=y
CONFIG_SYSTEM_TRUSTED_KEYS=""
# CONFIG_SYSTEM_EXTRA_CERTIFICATE is not set
# CONFIG_SECONDARY_TRUSTED_KEYRING is not set
# CONFIG_SYSTEM_BLACKLIST_KEYRING is not set
CONFIG_BINARY_PRINTF=y

#
# Library routines
#
CONFIG_BITREVERSE=y
CONFIG_RATIONAL=y
CONFIG_GENERIC_STRNCPY_FROM_USER=y
CONFIG_GENERIC_STRNLEN_USER=y
CONFIG_GENERIC_NET_UTILS=y
CONFIG_GENERIC_FIND_FIRST_BIT=y
CONFIG_GENERIC_PCI_IOMAP=y
CONFIG_GENERIC_IOMAP=y
CONFIG_ARCH_USE_CMPXCHG_LOCKREF=y
CONFIG_ARCH_HAS_FAST_MULTIPLIER=y
CONFIG_CRC_CCITT=y
CONFIG_CRC16=y
# CONFIG_CRC_T10DIF is not set
# CONFIG_CRC_ITU_T is not set
CONFIG_CRC32=y
# CONFIG_CRC32_SELFTEST is not set
CONFIG_CRC32_SLICEBY8=y
# CONFIG_CRC32_SLICEBY4 is not set
# CONFIG_CRC32_SARWATE is not set
# CONFIG_CRC32_BIT is not set
# CONFIG_CRC64 is not set
# CONFIG_CRC4 is not set
# CONFIG_CRC7 is not set
# CONFIG_LIBCRC32C is not set
# CONFIG_CRC8 is not set
# CONFIG_RANDOM32_SELFTEST is not set
CONFIG_ZLIB_INFLATE=y
CONFIG_ZLIB_DEFLATE=y
CONFIG_LZO_COMPRESS=y
CONFIG_LZO_DECOMPRESS=y
CONFIG_LZ4_DECOMPRESS=y
CONFIG_XZ_DEC=y
CONFIG_XZ_DEC_X86=y
CONFIG_XZ_DEC_POWERPC=y
CONFIG_XZ_DEC_IA64=y
CONFIG_XZ_DEC_ARM=y
CONFIG_XZ_DEC_ARMTHUMB=y
CONFIG_XZ_DEC_SPARC=y
CONFIG_XZ_DEC_BCJ=y
# CONFIG_XZ_DEC_TEST is not set
CONFIG_DECOMPRESS_GZIP=y
CONFIG_DECOMPRESS_BZIP2=y
CONFIG_DECOMPRESS_LZMA=y
CONFIG_DECOMPRESS_XZ=y
CONFIG_DECOMPRESS_LZO=y
CONFIG_DECOMPRESS_LZ4=y
CONFIG_GENERIC_ALLOCATOR=y
CONFIG_INTERVAL_TREE=y
CONFIG_ASSOCIATIVE_ARRAY=y
CONFIG_HAS_IOMEM=y
CONFIG_HAS_IOPORT_MAP=y
CONFIG_HAS_DMA=y
CONFIG_NEED_SG_DMA_LENGTH=y
CONFIG_NEED_DMA_MAP_STATE=y
CONFIG_ARCH_DMA_ADDR_T_64BIT=y
CONFIG_SWIOTLB=y
CONFIG_SGL_ALLOC=y
CONFIG_IOMMU_HELPER=y
CONFIG_CHECK_SIGNATURE=y
CONFIG_CPU_RMAP=y
CONFIG_DQL=y
CONFIG_GLOB=y
# CONFIG_GLOB_SELFTEST is not set
CONFIG_NLATTR=y
CONFIG_CLZ_TAB=y
# CONFIG_CORDIC is not set
# CONFIG_DDR is not set
# CONFIG_IRQ_POLL is not set
CONFIG_MPILIB=y
CONFIG_OID_REGISTRY=y
CONFIG_UCS2_STRING=y
CONFIG_FONT_SUPPORT=y
# CONFIG_FONTS is not set
CONFIG_FONT_8x8=y
CONFIG_FONT_8x16=y
CONFIG_SG_POOL=y
CONFIG_ARCH_HAS_PMEM_API=y
CONFIG_ARCH_HAS_UACCESS_FLUSHCACHE=y
CONFIG_ARCH_HAS_UACCESS_MCSAFE=y
CONFIG_STACKDEPOT=y
CONFIG_SBITMAP=y
# CONFIG_STRING_SELFTEST is not set

#
# Kernel hacking
#

#
# printk and dmesg options
#
CONFIG_PRINTK_TIME=y
CONFIG_CONSOLE_LOGLEVEL_DEFAULT=7
CONFIG_CONSOLE_LOGLEVEL_QUIET=4
CONFIG_MESSAGE_LOGLEVEL_DEFAULT=4
# CONFIG_BOOT_PRINTK_DELAY is not set
# CONFIG_DYNAMIC_DEBUG is not set

#
# Compile-time checks and compiler options
#
CONFIG_DEBUG_INFO=y
# CONFIG_DEBUG_INFO_REDUCED is not set
# CONFIG_DEBUG_INFO_SPLIT is not set
# CONFIG_DEBUG_INFO_DWARF4 is not set
# CONFIG_GDB_SCRIPTS is not set
CONFIG_ENABLE_MUST_CHECK=y
CONFIG_FRAME_WARN=2048
# CONFIG_STRIP_ASM_SYMS is not set
# CONFIG_READABLE_ASM is not set
# CONFIG_UNUSED_SYMBOLS is not set
# CONFIG_PAGE_OWNER is not set
CONFIG_DEBUG_FS=y
# CONFIG_HEADERS_CHECK is not set
# CONFIG_DEBUG_SECTION_MISMATCH is not set
CONFIG_SECTION_MISMATCH_WARN_ONLY=y
CONFIG_STACK_VALIDATION=y
# CONFIG_DEBUG_FORCE_WEAK_PER_CPU is not set
CONFIG_MAGIC_SYSRQ=y
CONFIG_MAGIC_SYSRQ_DEFAULT_ENABLE=0x1
CONFIG_MAGIC_SYSRQ_SERIAL=y
CONFIG_DEBUG_KERNEL=y

#
# Memory Debugging
#
# CONFIG_PAGE_EXTENSION is not set
# CONFIG_DEBUG_PAGEALLOC is not set
# CONFIG_PAGE_POISONING is not set
# CONFIG_DEBUG_PAGE_REF is not set
# CONFIG_DEBUG_RODATA_TEST is not set
# CONFIG_DEBUG_OBJECTS is not set
# CONFIG_DEBUG_SLAB is not set
CONFIG_HAVE_DEBUG_KMEMLEAK=y
CONFIG_DEBUG_KMEMLEAK=y
CONFIG_DEBUG_KMEMLEAK_EARLY_LOG_SIZE=4096
# CONFIG_DEBUG_KMEMLEAK_TEST is not set
# CONFIG_DEBUG_KMEMLEAK_DEFAULT_OFF is not set
CONFIG_DEBUG_KMEMLEAK_AUTO_SCAN=y
CONFIG_DEBUG_STACK_USAGE=y
CONFIG_DEBUG_VM=y
# CONFIG_DEBUG_VM_VMACACHE is not set
# CONFIG_DEBUG_VM_RB is not set
# CONFIG_DEBUG_VM_PGFLAGS is not set
CONFIG_ARCH_HAS_DEBUG_VIRTUAL=y
# CONFIG_DEBUG_VIRTUAL is not set
CONFIG_DEBUG_MEMORY_INIT=y
# CONFIG_DEBUG_PER_CPU_MAPS is not set
CONFIG_HAVE_DEBUG_STACKOVERFLOW=y
CONFIG_DEBUG_STACKOVERFLOW=y
CONFIG_HAVE_ARCH_KASAN=y
CONFIG_CC_HAS_KASAN_GENERIC=y
CONFIG_KASAN=y
CONFIG_KASAN_GENERIC=y
# CONFIG_KASAN_EXTRA is not set
# CONFIG_KASAN_OUTLINE is not set
CONFIG_KASAN_INLINE=y
# CONFIG_TEST_KASAN is not set
CONFIG_ARCH_HAS_KCOV=y
CONFIG_CC_HAS_SANCOV_TRACE_PC=y
CONFIG_KCOV=y
CONFIG_KCOV_ENABLE_COMPARISONS=y
CONFIG_KCOV_INSTRUMENT_ALL=y
# CONFIG_DEBUG_SHIRQ is not set

#
# Debug Lockups and Hangs
#
CONFIG_LOCKUP_DETECTOR=y
CONFIG_SOFTLOCKUP_DETECTOR=y
# CONFIG_BOOTPARAM_SOFTLOCKUP_PANIC is not set
CONFIG_BOOTPARAM_SOFTLOCKUP_PANIC_VALUE=0
CONFIG_HARDLOCKUP_DETECTOR_PERF=y
CONFIG_HARDLOCKUP_CHECK_TIMESTAMP=y
CONFIG_HARDLOCKUP_DETECTOR=y
CONFIG_BOOTPARAM_HARDLOCKUP_PANIC=y
CONFIG_BOOTPARAM_HARDLOCKUP_PANIC_VALUE=1
CONFIG_DETECT_HUNG_TASK=y
CONFIG_DEFAULT_HUNG_TASK_TIMEOUT=140
# CONFIG_BOOTPARAM_HUNG_TASK_PANIC is not set
CONFIG_BOOTPARAM_HUNG_TASK_PANIC_VALUE=0
CONFIG_WQ_WATCHDOG=y
# CONFIG_PANIC_ON_OOPS is not set
CONFIG_PANIC_ON_OOPS_VALUE=0
CONFIG_PANIC_TIMEOUT=0
# CONFIG_SCHED_DEBUG is not set
CONFIG_SCHED_INFO=y
CONFIG_SCHEDSTATS=y
# CONFIG_SCHED_STACK_END_CHECK is not set
# CONFIG_DEBUG_TIMEKEEPING is not set

#
# Lock Debugging (spinlocks, mutexes, etc...)
#
CONFIG_LOCK_DEBUGGING_SUPPORT=y
CONFIG_PROVE_LOCKING=y
# CONFIG_LOCK_STAT is not set
CONFIG_DEBUG_RT_MUTEXES=y
CONFIG_DEBUG_SPINLOCK=y
CONFIG_DEBUG_MUTEXES=y
CONFIG_DEBUG_WW_MUTEX_SLOWPATH=y
CONFIG_DEBUG_RWSEMS=y
CONFIG_DEBUG_LOCK_ALLOC=y
CONFIG_LOCKDEP=y
# CONFIG_DEBUG_LOCKDEP is not set
CONFIG_DEBUG_ATOMIC_SLEEP=y
# CONFIG_DEBUG_LOCKING_API_SELFTESTS is not set
# CONFIG_LOCK_TORTURE_TEST is not set
# CONFIG_WW_MUTEX_SELFTEST is not set
CONFIG_TRACE_IRQFLAGS=y
CONFIG_STACKTRACE=y
# CONFIG_WARN_ALL_UNSEEDED_RANDOM is not set
# CONFIG_DEBUG_KOBJECT is not set
CONFIG_DEBUG_BUGVERBOSE=y
# CONFIG_DEBUG_LIST is not set
# CONFIG_DEBUG_PI_LIST is not set
# CONFIG_DEBUG_SG is not set
# CONFIG_DEBUG_NOTIFIERS is not set
# CONFIG_DEBUG_CREDENTIALS is not set

#
# RCU Debugging
#
CONFIG_PROVE_RCU=y
# CONFIG_RCU_PERF_TEST is not set
# CONFIG_RCU_TORTURE_TEST is not set
CONFIG_RCU_CPU_STALL_TIMEOUT=100
CONFIG_RCU_TRACE=y
# CONFIG_RCU_EQS_DEBUG is not set
# CONFIG_DEBUG_WQ_FORCE_RR_CPU is not set
# CONFIG_DEBUG_BLOCK_EXT_DEVT is not set
# CONFIG_CPU_HOTPLUG_STATE_CONTROL is not set
# CONFIG_NOTIFIER_ERROR_INJECTION is not set
CONFIG_FUNCTION_ERROR_INJECTION=y
CONFIG_FAULT_INJECTION=y
CONFIG_FAILSLAB=y
CONFIG_FAIL_PAGE_ALLOC=y
CONFIG_FAIL_MAKE_REQUEST=y
CONFIG_FAIL_IO_TIMEOUT=y
CONFIG_FAIL_FUTEX=y
CONFIG_FAULT_INJECTION_DEBUG_FS=y
# CONFIG_FAIL_FUNCTION is not set
# CONFIG_LATENCYTOP is not set
CONFIG_USER_STACKTRACE_SUPPORT=y
CONFIG_NOP_TRACER=y
CONFIG_HAVE_FUNCTION_TRACER=y
CONFIG_HAVE_FUNCTION_GRAPH_TRACER=y
CONFIG_HAVE_DYNAMIC_FTRACE=y
CONFIG_HAVE_DYNAMIC_FTRACE_WITH_REGS=y
CONFIG_HAVE_FTRACE_MCOUNT_RECORD=y
CONFIG_HAVE_SYSCALL_TRACEPOINTS=y
CONFIG_HAVE_FENTRY=y
CONFIG_HAVE_C_RECORDMCOUNT=y
CONFIG_TRACE_CLOCK=y
CONFIG_RING_BUFFER=y
CONFIG_EVENT_TRACING=y
CONFIG_CONTEXT_SWITCH_TRACER=y
CONFIG_PREEMPTIRQ_TRACEPOINTS=y
CONFIG_TRACING=y
CONFIG_GENERIC_TRACER=y
CONFIG_TRACING_SUPPORT=y
CONFIG_FTRACE=y
# CONFIG_FUNCTION_TRACER is not set
# CONFIG_PREEMPTIRQ_EVENTS is not set
# CONFIG_IRQSOFF_TRACER is not set
# CONFIG_SCHED_TRACER is not set
# CONFIG_HWLAT_TRACER is not set
# CONFIG_FTRACE_SYSCALLS is not set
# CONFIG_TRACER_SNAPSHOT is not set
CONFIG_BRANCH_PROFILE_NONE=y
# CONFIG_PROFILE_ANNOTATED_BRANCHES is not set
# CONFIG_STACK_TRACER is not set
CONFIG_BLK_DEV_IO_TRACE=y
CONFIG_KPROBE_EVENTS=y
CONFIG_UPROBE_EVENTS=y
CONFIG_DYNAMIC_EVENTS=y
CONFIG_PROBE_EVENTS=y
# CONFIG_FTRACE_STARTUP_TEST is not set
# CONFIG_MMIOTRACE is not set
# CONFIG_HIST_TRIGGERS is not set
# CONFIG_TRACEPOINT_BENCHMARK is not set
# CONFIG_RING_BUFFER_BENCHMARK is not set
# CONFIG_RING_BUFFER_STARTUP_TEST is not set
# CONFIG_PREEMPTIRQ_DELAY_TEST is not set
# CONFIG_TRACE_EVAL_MAP_FILE is not set
CONFIG_PROVIDE_OHCI1394_DMA_INIT=y
# CONFIG_DMA_API_DEBUG is not set
CONFIG_RUNTIME_TESTING_MENU=y
# CONFIG_LKDTM is not set
# CONFIG_TEST_LIST_SORT is not set
# CONFIG_TEST_SORT is not set
# CONFIG_KPROBES_SANITY_TEST is not set
# CONFIG_BACKTRACE_SELF_TEST is not set
# CONFIG_RBTREE_TEST is not set
# CONFIG_INTERVAL_TREE_TEST is not set
# CONFIG_PERCPU_TEST is not set
# CONFIG_ATOMIC64_SELFTEST is not set
# CONFIG_TEST_HEXDUMP is not set
# CONFIG_TEST_STRING_HELPERS is not set
# CONFIG_TEST_KSTRTOX is not set
# CONFIG_TEST_PRINTF is not set
# CONFIG_TEST_BITMAP is not set
# CONFIG_TEST_BITFIELD is not set
# CONFIG_TEST_UUID is not set
# CONFIG_TEST_XARRAY is not set
# CONFIG_TEST_OVERFLOW is not set
# CONFIG_TEST_RHASHTABLE is not set
# CONFIG_TEST_HASH is not set
# CONFIG_TEST_IDA is not set
# CONFIG_TEST_LKM is not set
# CONFIG_TEST_USER_COPY is not set
# CONFIG_TEST_BPF is not set
# CONFIG_FIND_BIT_BENCHMARK is not set
# CONFIG_TEST_FIRMWARE is not set
# CONFIG_TEST_SYSCTL is not set
# CONFIG_TEST_UDELAY is not set
# CONFIG_TEST_STATIC_KEYS is not set
# CONFIG_TEST_KMOD is not set
# CONFIG_TEST_MEMCAT_P is not set
# CONFIG_MEMTEST is not set
# CONFIG_BUG_ON_DATA_CORRUPTION is not set
# CONFIG_SAMPLES is not set
CONFIG_HAVE_ARCH_KGDB=y
# CONFIG_KGDB is not set
CONFIG_ARCH_HAS_UBSAN_SANITIZE_ALL=y
CONFIG_UBSAN=y
# CONFIG_UBSAN_SANITIZE_ALL is not set
# CONFIG_UBSAN_ALIGNMENT is not set
# CONFIG_TEST_UBSAN is not set
CONFIG_ARCH_HAS_DEVMEM_IS_ALLOWED=y
CONFIG_STRICT_DEVMEM=y
# CONFIG_IO_STRICT_DEVMEM is not set
CONFIG_TRACE_IRQFLAGS_SUPPORT=y
CONFIG_EARLY_PRINTK_USB=y
CONFIG_X86_VERBOSE_BOOTUP=y
CONFIG_EARLY_PRINTK=y
CONFIG_EARLY_PRINTK_DBGP=y
# CONFIG_EARLY_PRINTK_EFI is not set
# CONFIG_EARLY_PRINTK_USB_XDBC is not set
# CONFIG_X86_PTDUMP is not set
# CONFIG_EFI_PGT_DUMP is not set
# CONFIG_DEBUG_WX is not set
CONFIG_DOUBLEFAULT=y
# CONFIG_DEBUG_TLBFLUSH is not set
CONFIG_HAVE_MMIOTRACE_SUPPORT=y
# CONFIG_X86_DECODER_SELFTEST is not set
CONFIG_IO_DELAY_TYPE_0X80=0
CONFIG_IO_DELAY_TYPE_0XED=1
CONFIG_IO_DELAY_TYPE_UDELAY=2
CONFIG_IO_DELAY_TYPE_NONE=3
CONFIG_IO_DELAY_0X80=y
# CONFIG_IO_DELAY_0XED is not set
# CONFIG_IO_DELAY_UDELAY is not set
# CONFIG_IO_DELAY_NONE is not set
CONFIG_DEFAULT_IO_DELAY_TYPE=0
CONFIG_DEBUG_BOOT_PARAMS=y
# CONFIG_CPA_DEBUG is not set
CONFIG_OPTIMIZE_INLINING=y
# CONFIG_DEBUG_ENTRY is not set
# CONFIG_DEBUG_NMI_SELFTEST is not set
CONFIG_X86_DEBUG_FPU=y
# CONFIG_PUNIT_ATOM_DEBUG is not set
CONFIG_UNWINDER_ORC=y
# CONFIG_UNWINDER_FRAME_POINTER is not set
Eric W. Biederman Jan. 11, 2019, 11:50 p.m. | #4
zzoru <zzoru007@gmail.com> writes:

>> I received 3 spam messages from this address today.
>> We can simply ignore this report.
> I already mentioned about this.
>
>> and, sorry for my encrypted mails.
>> I don't understand this failure report at all.
>>
>> I don't see the connection to copy_net_ns().  And I don't see how the
>> suggested patch short of covering up a memory stomp could possibly make
>> a difference.
>>
>> What am I missing?
>> void execute_one(void)
>> {
>>   syscall(__NR_unshare, 0x40000000);
>> }
> ksys_unshare -> unshare_nsproxy_namespaces -> create_new_namespaces ->
> copy_net_ns
> unshare(CLONE_NEWNET) calls copy_net_ns() (It requires the CAP_SYS_ADMIN
> capability)

Looking at your alternate patch where you switch the structure
order it looks like there is a memory stomp.  Probably a use
after free.  It is a shame that KASAN is not catching the problem.
That is my only suggestion at the moment.

The OOM may be because network namespaces are created in quick
succession and they take a while to free.

One of the nasty truths about testing is sometimes you can be testing
one thing and you can trigger a bug in something completely different.
Right now it looks like anything that copy_net_ns calls could be
responsible for the memory problems.

Eric


> I made many error reports about this bug, and the other one is
>
> [   90.289025] WARNING: CPU: 1 PID: 1732 at mm/page_alloc.c:4415
> __alloc_pages_slowpath+0x1cb1/0x2220
> [   90.290223] Modules linked in:
> [   90.290639] CPU: 1 PID: 1732 Comm: kworker/u4:5 Not tainted 5.0.0-rc1+ #6
> [   90.291475] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996),
> BIOS Ubuntu-1.8.2-1ubuntu1 04/01/2014
> [   90.292681] Workqueue: writeback wb_workfn (flush-8:0)
> [   90.293350] RIP: 0010:__alloc_pages_slowpath+0x1cb1/0x2220
> [   90.294075] Code: 8b 84 24 a8 00 00 00 e9 ea f1 ff ff 85 d2 0f 85 0b
> 01 00 00 48 c7 c7 c0 5e 55 84 e8 79 f8 23 02 e9 86 f9 ff ff 44 8b 74 24
> 0c <0f> 0b 48 b8 00 00 00 00 00 fc ff df 48 8b 54 24 18 48 c1 ea 03 80
> [   90.296527] RSP: 0018:ffff888064276dd8 EFLAGS: 00010046
> [   90.297203] RAX: 0000000000000000 RBX: 0000000000000000 RCX:
> 1ffff1100c84eda8
> [   90.297784] kmemleak: Cannot allocate a kmemleak_object structure
> [   90.298186] RDX: 0000000000000000 RSI: 0000000000000000 RDI:
> ffff88807ffdd528
> [   90.298242] RBP: dffffc0000000000 R08: 0000000000000000 R09:
> 0000000000000679
> [   90.298247] R10: 0000000000000000 R11: ffff88807ffdc487 R12:
> 0000000000000000
> [   90.298251] R13: ffff888064277030 R14: 0000000000415a00 R15:
> ffff888064277030
> [   90.298257] FS:  0000000000000000(0000) GS:ffff88806d500000(0000)
> knlGS:0000000000000000
> [   90.298262] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
> [   90.298267] CR2: 00007fff6ac6a718 CR3: 0000000056578000 CR4:
> 00000000000006e0
> [   90.298272] Call Trace:
> [   90.298283]  ? __alloc_pages_slowpath+0x1ce6/0x2220
> [   90.298299]  ? warn_alloc+0x120/0x120
> [   90.302432] kmemleak: Kernel memory leak detector disabled
> [   90.303346]  ? lock_acquire+0x103/0x2e0
> [   90.303358]  ? __isolate_free_page+0x4b0/0x4b0
> [   90.303366]  ? __lock_is_held+0xad/0x140
> [   90.303377]  __alloc_pages_nodemask+0x521/0x5f0
> [   90.303386]  ? __alloc_pages_slowpath+0x2220/0x2220
> [   90.315010]  cache_grow_begin+0x95/0x300
> [   90.315613]  fallback_alloc+0x1ce/0x270
> [   90.316211]  ? mempool_free+0x360/0x360
> [   90.316767]  kmem_cache_alloc+0x286/0x2f0
> [   90.317348]  ? mempool_free+0x360/0x360
> [   90.317919]  create_object+0x83/0x880
> [   90.318517]  ? kmemleak_disable+0x90/0x90
> [   90.319103]  ? mark_held_locks+0xc1/0x140
> [   90.319679]  ? kmem_cache_alloc+0x9c/0x2f0
> [   90.320307]  ? mempool_free+0x360/0x360
> [   90.320900]  kmem_cache_alloc+0x18f/0x2f0
> [   90.321650]  ? mempool_free+0x360/0x360
> [   90.322228]  mempool_alloc+0x13e/0x340
> [   90.322765]  ? mempool_destroy+0x30/0x30
> [   90.323370]  ? mark_held_locks+0xc1/0x140
> [   90.323993]  ? _raw_spin_unlock_irqrestore+0x3e/0x50
> [   90.324786]  bio_alloc_bioset+0x36f/0x5d0
> [   90.325397]  ? __test_set_page_writeback+0x136/0x960
> [   90.326161]  ? bvec_alloc+0x2d0/0x2d0
> [   90.326708]  ? wait_for_stable_page+0x290/0x290
> [   90.327392]  submit_bh_wbc.isra.57+0x128/0x680
> [   90.328053]  ? create_page_buffers+0x111/0x200
> [   90.328685]  __block_write_full_page+0x6e8/0xcd0
> [   90.329339]  ? check_disk_change+0x130/0x130
> [   90.329966]  block_write_full_page+0x202/0x250
> [   90.330675]  ? check_disk_change+0x130/0x130
> [   90.331291]  __writepage+0x62/0xe0
> [   90.331786]  write_cache_pages+0x5b8/0xf60
> [   90.332375]  ? __wb_calc_thresh+0x290/0x290
> [   90.332976]  ? clear_page_dirty_for_io+0x5c0/0x5c0
> [   90.333686]  ? mark_held_locks+0x140/0x140
> [   90.334301]  ? print_circular_bug_entry+0x1f/0x60
> [   90.334999]  ? __lock_acquire+0x5d6/0x4630
> [   90.335621]  generic_writepages+0xda/0x150
> [   90.336243]  ? write_cache_pages+0xf60/0xf60
> [   90.336852]  ? mark_held_locks+0x140/0x140
> [   90.337453]  ? blkdev_readpages+0x30/0x30
> [   90.338020]  do_writepages+0xf0/0x290
> [   90.338611]  ? page_writeback_cpu_online+0x10/0x10
> [   90.339324]  ? __lock_is_held+0xad/0x140
> [   90.339900]  __writeback_single_inode+0xf3/0x1000
> [   90.340587]  writeback_sb_inodes+0x4e7/0xce0
> [   90.341214]  ? __writeback_single_inode+0x1000/0x1000
> [   90.341929]  ? down_read_trylock+0x5b/0x90
> [   90.342579]  ? trylock_super+0x1d/0x100
> [   90.343162]  __writeback_inodes_wb+0x109/0x220
> [   90.343799]  wb_writeback+0x7a1/0xb90
> [   90.344347]  ? writeback_inodes_wb.constprop.44+0x190/0x190
> [   90.345143]  ? cpumask_next+0x1f/0x30
> [   90.345679]  ? find_next_bit+0x101/0x130
> [   90.346281]  ? get_nr_dirty_inodes+0xd0/0x130
> [   90.346909]  wb_workfn+0x921/0xec0
> [   90.347397]  ? process_one_work+0xadd/0x1bb0
> [   90.348025]  ? inode_wait_for_writeback+0x30/0x30
> [   90.348700]  process_one_work+0xbbd/0x1bb0
> [   90.349314]  ? max_active_store+0x130/0x130
> [   90.349915]  ? do_raw_spin_lock+0x11b/0x280
> [   90.350557]  worker_thread+0x8c/0x1060
> [   90.351096]  ? __kthread_parkme+0xf8/0x1a0
> [   90.351673]  ? process_one_work+0x1bb0/0x1bb0
> [   90.352334]  kthread+0x347/0x410
> [   90.352798]  ? kthread_create_worker_on_cpu+0xe0/0xe0
> [   90.353509]  ret_from_fork+0x3a/0x50
> [   90.354020] irq event stamp: 282384
> [   90.354590] hardirqs last  enabled at (282383): [<ffffffff8160678c>]
> kmem_cache_alloc+0x9c/0x2f0
> [   90.355832] hardirqs last disabled at (282384): [<ffffffff8160674d>]
> kmem_cache_alloc+0x5d/0x2f0
> [   90.357066] softirqs last  enabled at (282196): [<ffffffff816daa87>]
> wb_workfn+0x387/0xec0
> [   90.358280] softirqs last disabled at (282194): [<ffffffff816da918>]
> wb_workfn+0x218/0xec0
> [   90.359426] ---[ end trace 71c4462c6227f0d8 ]---
> [   90.360135] kmemleak: Cannot allocate a kmemleak_object structure
> [   90.888624] a.out invoked oom-killer:
> gfp_mask=0x6040d0(GFP_KERNEL|__GFP_COMP|__GFP_RECLAIMABLE), order=0,
> oom_score_adj=0
> [   90.890564] CPU: 0 PID: 22248 Comm: a.out Tainted: G        W        
> 5.0.0-rc1+ #6
> [   90.891793] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996),
> BIOS Ubuntu-1.8.2-1ubuntu1 04/01/2014
> [   90.893263] Call Trace:
> [   90.893678]  dump_stack+0xca/0x13e
> [   90.894242]  dump_header+0x108/0xaef
> [   90.894822]  ? ___ratelimit+0x5b/0x436
> [   90.895430]  oom_kill_process.cold.38+0x10/0xa87
> [   90.896164]  ? lock_downgrade+0x5d0/0x5d0
> [   90.896806]  ? _raw_spin_unlock+0x1f/0x30
> [   90.897445]  ? oom_badness+0xc8/0x770
> [   90.898045]  out_of_memory+0x32a/0x1ab0
> [   90.898668]  ? oom_killer_disable+0x280/0x280
> [   90.899365]  ? mutex_trylock+0x162/0x1a0
> [   90.899998]  __alloc_pages_slowpath+0x1b7a/0x2220
> [   90.900754]  ? warn_alloc+0x120/0x120
> [   90.901344]  ? find_held_lock+0x33/0x1c0
> [   90.901985]  __alloc_pages_nodemask+0x521/0x5f0
> [   90.902723]  ? __alloc_pages_slowpath+0x2220/0x2220
> [   90.903499]  ? mark_held_locks+0xc1/0x140
> [   90.904137]  ? cache_grow_begin+0x28f/0x300
> [   90.904807]  cache_grow_begin+0x95/0x300
> [   90.905443]  fallback_alloc+0x1ce/0x270
> [   90.906074]  kmem_cache_alloc+0x286/0x2f0
> [   90.906720]  ? sock_destroy_inode+0x60/0x60
> [   90.907392]  sock_alloc_inode+0x18/0x250
> [   90.908021]  ? sock_destroy_inode+0x60/0x60
> [   90.908690]  alloc_inode+0x5e/0x180
> [   90.909254]  new_inode_pseudo+0x12/0xd0
> [   90.909868]  sock_alloc+0x3c/0x270
> [   90.910428]  __sock_create+0xbe/0x740
> [   90.911026]  inet_ctl_sock_create+0x8c/0x1e0
> [   90.911710]  ? inet_current_timestamp+0xc0/0xc0
> [   90.912432]  ? rcu_read_lock_sched_held+0x10f/0x130
> [   90.913205]  ? find_next_bit+0x101/0x130
> [   90.913837]  icmpv6_sk_init+0x12a/0x2b0
> [   90.914463]  ? inet6_net_init+0x437/0x7c0
> [   90.915102]  ? icmpv6_err_convert+0x180/0x180
> [   90.915799]  ? ac6_proc_init+0x5a/0x70
> [   90.916402]  ? inet6_net_init+0x53b/0x7c0
> [   90.917041]  ? icmpv6_err_convert+0x180/0x180
> [   90.917734]  ops_init+0xb2/0x400
> [   90.918265]  setup_net+0x24c/0x5e0
> [   90.918817]  ? ops_init+0x400/0x400
> [   90.919386]  copy_net_ns+0x1a2/0x270
> [   90.919969]  create_new_namespaces+0x579/0x790
> [   90.920676]  unshare_nsproxy_namespaces+0xc3/0x190
> [   90.921435]  ksys_unshare+0x428/0x810
> [   90.922029]  ? walk_process_tree+0x2c0/0x2c0
> [   90.922712]  ? __change_pid+0x19c/0x2c0
> [   90.923328]  ? _raw_write_unlock_irq+0x24/0x30
> [   90.924038]  ? trace_hardirqs_on_thunk+0x1a/0x1c
> [   90.924771]  ? trace_hardirqs_off_caller+0x55/0x1c0
> [   90.925547]  __x64_sys_unshare+0x2d/0x40
> [   90.926187]  do_syscall_64+0xbc/0x4e0
> [   90.926777]  entry_SYSCALL_64_after_hwframe+0x49/0xbe
> [   90.927573] RIP: 0033:0x7f827ad52229
> [   90.928146] Code: Bad RIP value.
> [   90.928663] RSP: 002b:00007fff6ac6a6c8 EFLAGS: 00000217 ORIG_RAX:
> 0000000000000110
> [   90.929837] RAX: ffffffffffffffda RBX: 0000000000000000 RCX:
> 00007f827ad52229
> [   90.930952] RDX: 00007f827ad27147 RSI: 0000000000000000 RDI:
> 0000000040000000
> [   90.932056] RBP: 00007fff6ac6a6d0 R08: 0000000000000005 R09:
> 00007fff6ac6a720
> [   90.933165] R10: 0000000000000000 R11: 0000000000000217 R12:
> 00005607242822e0
> [   90.934278] R13: 00007fff6ac6a830 R14: 0000000000000000 R15:
> 0000000000000000
>
> I just guess that copy_net_ns func doesn't call net_free, and it makes OOM.
>
> And, I found that
>
> diff --git a/include/net/net_namespace.h b/include/net/net_namespace.h
> index 99d4148e0f90..38c474e4ab4c 100644
> --- a/include/net/net_namespace.h
> +++ b/include/net/net_namespace.h
> @@ -50,12 +50,12 @@ struct bpf_prog;
>  #define NETDEV_HASHENTRIES (1 << NETDEV_HASHBITS)
>
>  struct net {
> -       refcount_t              passive;        /* To decided when the
> network
> -                                                * namespace should be
> freed.
> -                                                */
>         refcount_t              count;          /* To decided when the
> network
>                                                  *  namespace should be
> shut down.
>                                                  */
> +       refcount_t              passive;        /* To decided when the
> network
> +                                                * namespace should be
> freed.
> +                                                */
>         spinlock_t              rules_mod_lock;
>
>         atomic64_t              cookie_gen;
>
> this patch also works on this bug. (Just swap the order of net struct.)
> I don't know why this patch works (I just thought that compiler
> optimization issue can make this bug and try this one.)
> I need to review code more on copy_net_ns().
>
> Also, I reproduce this bug on Ubuntu 18.10 (4.18.0-10-generic) on VMWare
> Workstation Pro 15.0.2 by C reproducer.
>
> On 12/01/2019 5:41 오전, Kirill Tkhai wrote:
>> On 11.01.2019 23:33, Eric W. Biederman wrote:
>>> zzoru <zzoru007@gmail.com> writes:
>>>
>>>> net/core: BUG in copy_net_ns() (net_namespace.c)
>>> I don't understand this failure report at all.
>>>
>>> I don't see the connection to copy_net_ns().  And I don't see how the
>>> suggested patch short of covering up a memory stomp could possibly make
>>> a difference.
>>>
>>> What am I missing?
>> I received 3 spam messages from this address today.
>> We can simply ignore this report.
>>
>>>
>>>> Hello,
>>>>
>>>> I've got the following error report while fuzzing the kernel with syzkaller.
>>>>
>>>> On commit 1bdbe227492075d058e37cb3d400e6468d0095b5
>>>>
>>>> Syzkaller hit 'WARNING in __alloc_pages_slowpath' bug.
>>>>
>>>> syz-executor561 (17453) used greatest stack depth: 25056 bytes left
>>>> WARNING: CPU: 0 PID: 692 at mm/page_alloc.c:4415
>>>> __alloc_pages_slowpath+0x1cb1/0x2220 mm/page_alloc.c:4386
>>>> Kernel panic - not syncing: panic_on_warn set ...
>>>> CPU: 0 PID: 692 Comm: kswapd0 Not tainted 5.0.0-rc1+ #4
>>>> Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS
>>>> Ubuntu-1.8.2-1ubuntu1 04/01/2014
>>>> Call Trace:
>>>>  __dump_stack lib/dump_stack.c:77 [inline]
>>>>  dump_stack+0xca/0x13e lib/dump_stack.c:113
>>>>  panic+0x278/0x5bf kernel/panic.c:214
>>>>  __warn.cold.10+0x20/0x45 kernel/panic.c:571
>>>>  report_bug+0x246/0x2d0 lib/bug.c:186
>>>>  fixup_bug arch/x86/kernel/traps.c:178 [inline]
>>>>  do_error_trap+0x123/0x1e0 arch/x86/kernel/traps.c:271
>>>>  do_invalid_op+0x31/0x40 arch/x86/kernel/traps.c:290
>>>>  invalid_op+0x14/0x20 arch/x86/entry/entry_64.S:973
>>>> RIP: 0010:__alloc_pages_slowpath+0x1cb1/0x2220 mm/page_alloc.c:4415
>>>> Code: 8b 84 24 a8 00 00 00 e9 ea f1 ff ff 85 d2 0f 85 0b 01 00 00 48 c7
>>>> c7 c0 5e 55 84 e8 79 f8 23 02 e9 86 f9 ff ff 44 8b 74 24 0c <0f> 0b 48
>>>> b8 00 00 00 00 00 fc ff df 48 8b 54 24 18 48 c1 ea 03 80
>>>> RSP: 0018:ffff8880683fedb8 EFLAGS: 00010046
>>>> RAX: 0000000000000000 RBX: 0000000000000000 RCX: 1ffff1100d07fda4
>>>> RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff88807ffdd528
>>>> RBP: dffffc0000000000 R08: 0000000000000000 R09: 000000000000067a
>>>> R10: 0000000000000000 R11: ffff88807ffdc487 R12: 0000000000000000
>>>> R13: ffff8880683ff010 R14: 0000000000415a00 R15: ffff8880683ff010
>>>>  __alloc_pages_nodemask+0x521/0x5f0 mm/page_alloc.c:4555
>>>>  __alloc_pages include/linux/gfp.h:473 [inline]
>>>>  __alloc_pages_node include/linux/gfp.h:486 [inline]
>>>>  kmem_getpages mm/slab.c:1398 [inline]
>>>>  cache_grow_begin+0x95/0x300 mm/slab.c:2666
>>>>  fallback_alloc+0x1ce/0x270 mm/slab.c:3208
>>>>  __do_cache_alloc mm/slab.c:3345 [inline]
>>>>  slab_alloc mm/slab.c:3373 [inline]
>>>>  kmem_cache_alloc+0x286/0x2f0 mm/slab.c:3541
>>>>  create_object+0x83/0x880 mm/kmemleak.c:578
>>>>  kmemleak_alloc_recursive include/linux/kmemleak.h:55 [inline]
>>>>  slab_post_alloc_hook mm/slab.h:442 [inline]
>>>>  slab_alloc mm/slab.c:3381 [inline]
>>>>  kmem_cache_alloc+0x18f/0x2f0 mm/slab.c:3541
>>>>  mempool_alloc+0x13e/0x340 mm/mempool.c:385
>>>>  bio_alloc_bioset+0x36f/0x5d0 block/bio.c:489
>>>>  bio_alloc include/linux/bio.h:393 [inline]
>>>>  submit_bh_wbc.isra.57+0x128/0x680 fs/buffer.c:3061
>>>>  __block_write_full_page+0x6e8/0xcd0 fs/buffer.c:1765
>>>>  block_write_full_page+0x202/0x250 fs/buffer.c:2955
>>>>  pageout mm/vmscan.c:865 [inline]
>>>>  shrink_page_list+0x220f/0x3800 mm/vmscan.c:1383
>>>>  shrink_inactive_list+0x3c2/0xaa0 mm/vmscan.c:1961
>>>>  shrink_list mm/vmscan.c:2273 [inline]
>>>>  shrink_node_memcg.constprop.83+0x4bf/0x10e0 mm/vmscan.c:2538
>>>>  shrink_node+0x162/0xd10 mm/vmscan.c:2753
>>>>  kswapd_shrink_node mm/vmscan.c:3516 [inline]
>>>>  balance_pgdat+0x47f/0xc00 mm/vmscan.c:3674
>>>>  kswapd+0x57c/0xde0 mm/vmscan.c:3929
>>>>  kthread+0x347/0x410 kernel/kthread.c:246
>>>>  ret_from_fork+0x3a/0x50 arch/x86/entry/entry_64.S:352
>>>> Dumping ftrace buffer:
>>>>    (ftrace buffer empty)
>>>> Kernel Offset: disabled
>>>> Rebooting in 86400 seconds..
>>>>
>>>>
>>>> Syzkaller reproducer:
>>>> # {Threaded:false Collide:false Repeat:true RepeatTimes:0 Procs:8
>>>> Sandbox:none Fault:false FaultCall:-1 FaultNth:0 EnableTun:false
>>>> UseTmpDir:true EnableCgroups:false EnableNetdev:true ResetNet:false
>>>> HandleSegv:false Repro:false Trace:false}
>>>> unshare(0x40000000)
>>>>
>>>>
>>>> C reproducer:
>>>> // autogenerated by syzkaller (https://github.com/google/syzkaller)
>>>>
>>>> #define _GNU_SOURCE
>>>>
>>>> #include <arpa/inet.h>
>>>> #include <dirent.h>
>>>> #include <endian.h>
>>>> #include <errno.h>
>>>> #include <fcntl.h>
>>>> #include <net/if.h>
>>>> #include <net/if_arp.h>
>>>> #include <netinet/in.h>
>>>> #include <sched.h>
>>>> #include <signal.h>
>>>> #include <stdarg.h>
>>>> #include <stdbool.h>
>>>> #include <stdint.h>
>>>> #include <stdio.h>
>>>> #include <stdlib.h>
>>>> #include <string.h>
>>>> #include <sys/ioctl.h>
>>>> #include <sys/mount.h>
>>>> #include <sys/prctl.h>
>>>> #include <sys/resource.h>
>>>> #include <sys/socket.h>
>>>> #include <sys/stat.h>
>>>> #include <sys/syscall.h>
>>>> #include <sys/time.h>
>>>> #include <sys/types.h>
>>>> #include <sys/uio.h>
>>>> #include <sys/wait.h>
>>>> #include <time.h>
>>>> #include <unistd.h>
>>>>
>>>> #include <linux/if_addr.h>
>>>> #include <linux/if_ether.h>
>>>> #include <linux/if_link.h>
>>>> #include <linux/if_tun.h>
>>>> #include <linux/in6.h>
>>>> #include <linux/ip.h>
>>>> #include <linux/neighbour.h>
>>>> #include <linux/net.h>
>>>> #include <linux/netlink.h>
>>>> #include <linux/rtnetlink.h>
>>>> #include <linux/tcp.h>
>>>> #include <linux/veth.h>
>>>>
>>>> unsigned long long procid;
>>>>
>>>> static void sleep_ms(uint64_t ms)
>>>> {
>>>>   usleep(ms * 1000);
>>>> }
>>>>
>>>> static uint64_t current_time_ms(void)
>>>> {
>>>>   struct timespec ts;
>>>>   if (clock_gettime(CLOCK_MONOTONIC, &ts))
>>>>     exit(1);
>>>>   return (uint64_t)ts.tv_sec * 1000 + (uint64_t)ts.tv_nsec / 1000000;
>>>> }
>>>>
>>>> static void use_temporary_dir(void)
>>>> {
>>>>   char tmpdir_template[] = "./syzkaller.XXXXXX";
>>>>   char* tmpdir = mkdtemp(tmpdir_template);
>>>>   if (!tmpdir)
>>>>     exit(1);
>>>>   if (chmod(tmpdir, 0777))
>>>>     exit(1);
>>>>   if (chdir(tmpdir))
>>>>     exit(1);
>>>> }
>>>>
>>>> static bool write_file(const char* file, const char* what, ...)
>>>> {
>>>>   char buf[1024];
>>>>   va_list args;
>>>>   va_start(args, what);
>>>>   vsnprintf(buf, sizeof(buf), what, args);
>>>>   va_end(args);
>>>>   buf[sizeof(buf) - 1] = 0;
>>>>   int len = strlen(buf);
>>>>   int fd = open(file, O_WRONLY | O_CLOEXEC);
>>>>   if (fd == -1)
>>>>     return false;
>>>>   if (write(fd, buf, len) != len) {
>>>>     int err = errno;
>>>>     close(fd);
>>>>     errno = err;
>>>>     return false;
>>>>   }
>>>>   close(fd);
>>>>   return true;
>>>> }
>>>>
>>>> static struct {
>>>>   char* pos;
>>>>   int nesting;
>>>>   struct nlattr* nested[8];
>>>>   char buf[1024];
>>>> } nlmsg;
>>>>
>>>> static void netlink_init(int typ, int flags, const void* data, int size)
>>>> {
>>>>   memset(&nlmsg, 0, sizeof(nlmsg));
>>>>   struct nlmsghdr* hdr = (struct nlmsghdr*)nlmsg.buf;
>>>>   hdr->nlmsg_type = typ;
>>>>   hdr->nlmsg_flags = NLM_F_REQUEST | NLM_F_ACK | flags;
>>>>   memcpy(hdr + 1, data, size);
>>>>   nlmsg.pos = (char*)(hdr + 1) + NLMSG_ALIGN(size);
>>>> }
>>>>
>>>> static void netlink_attr(int typ, const void* data, int size)
>>>> {
>>>>   struct nlattr* attr = (struct nlattr*)nlmsg.pos;
>>>>   attr->nla_len = sizeof(*attr) + size;
>>>>   attr->nla_type = typ;
>>>>   memcpy(attr + 1, data, size);
>>>>   nlmsg.pos += NLMSG_ALIGN(attr->nla_len);
>>>> }
>>>>
>>>> static void netlink_nest(int typ)
>>>> {
>>>>   struct nlattr* attr = (struct nlattr*)nlmsg.pos;
>>>>   attr->nla_type = typ;
>>>>   nlmsg.pos += sizeof(*attr);
>>>>   nlmsg.nested[nlmsg.nesting++] = attr;
>>>> }
>>>>
>>>> static void netlink_done(void)
>>>> {
>>>>   struct nlattr* attr = nlmsg.nested[--nlmsg.nesting];
>>>>   attr->nla_len = nlmsg.pos - (char*)attr;
>>>> }
>>>>
>>>> static int netlink_send(int sock)
>>>> {
>>>>   if (nlmsg.pos > nlmsg.buf + sizeof(nlmsg.buf) || nlmsg.nesting)
>>>>     exit(1);
>>>>   struct nlmsghdr* hdr = (struct nlmsghdr*)nlmsg.buf;
>>>>   hdr->nlmsg_len = nlmsg.pos - nlmsg.buf;
>>>>   struct sockaddr_nl addr;
>>>>   memset(&addr, 0, sizeof(addr));
>>>>   addr.nl_family = AF_NETLINK;
>>>>   unsigned n = sendto(sock, nlmsg.buf, hdr->nlmsg_len, 0,
>>>>                       (struct sockaddr*)&addr, sizeof(addr));
>>>>   if (n != hdr->nlmsg_len)
>>>>     exit(1);
>>>>   n = recv(sock, nlmsg.buf, sizeof(nlmsg.buf), 0);
>>>>   if (n < sizeof(struct nlmsghdr) + sizeof(struct nlmsgerr))
>>>>     exit(1);
>>>>   if (hdr->nlmsg_type != NLMSG_ERROR)
>>>>     exit(1);
>>>>   return -((struct nlmsgerr*)(hdr + 1))->error;
>>>> }
>>>>
>>>> static void netlink_add_device_impl(const char* type, const char* name)
>>>> {
>>>>   struct ifinfomsg hdr;
>>>>   memset(&hdr, 0, sizeof(hdr));
>>>>   netlink_init(RTM_NEWLINK, NLM_F_EXCL | NLM_F_CREATE, &hdr, sizeof(hdr));
>>>>   if (name)
>>>>     netlink_attr(IFLA_IFNAME, name, strlen(name));
>>>>   netlink_nest(IFLA_LINKINFO);
>>>>   netlink_attr(IFLA_INFO_KIND, type, strlen(type));
>>>> }
>>>>
>>>> static void netlink_add_device(int sock, const char* type, const char* name)
>>>> {
>>>>   netlink_add_device_impl(type, name);
>>>>   netlink_done();
>>>>   int err = netlink_send(sock);
>>>>   (void)err;
>>>> }
>>>>
>>>> static void netlink_add_veth(int sock, const char* name, const char* peer)
>>>> {
>>>>   netlink_add_device_impl("veth", name);
>>>>   netlink_nest(IFLA_INFO_DATA);
>>>>   netlink_nest(VETH_INFO_PEER);
>>>>   nlmsg.pos += sizeof(struct ifinfomsg);
>>>>   netlink_attr(IFLA_IFNAME, peer, strlen(peer));
>>>>   netlink_done();
>>>>   netlink_done();
>>>>   netlink_done();
>>>>   int err = netlink_send(sock);
>>>>   (void)err;
>>>> }
>>>>
>>>> static void netlink_add_hsr(int sock, const char* name, const char* slave1,
>>>>                             const char* slave2)
>>>> {
>>>>   netlink_add_device_impl("hsr", name);
>>>>   netlink_nest(IFLA_INFO_DATA);
>>>>   int ifindex1 = if_nametoindex(slave1);
>>>>   netlink_attr(IFLA_HSR_SLAVE1, &ifindex1, sizeof(ifindex1));
>>>>   int ifindex2 = if_nametoindex(slave2);
>>>>   netlink_attr(IFLA_HSR_SLAVE2, &ifindex2, sizeof(ifindex2));
>>>>   netlink_done();
>>>>   netlink_done();
>>>>   int err = netlink_send(sock);
>>>>   (void)err;
>>>> }
>>>>
>>>> static void netlink_device_change(int sock, const char* name, bool up,
>>>>                                   const char* master, const void* mac,
>>>>                                   int macsize)
>>>> {
>>>>   struct ifinfomsg hdr;
>>>>   memset(&hdr, 0, sizeof(hdr));
>>>>   if (up)
>>>>     hdr.ifi_flags = hdr.ifi_change = IFF_UP;
>>>>   netlink_init(RTM_NEWLINK, 0, &hdr, sizeof(hdr));
>>>>   netlink_attr(IFLA_IFNAME, name, strlen(name));
>>>>   if (master) {
>>>>     int ifindex = if_nametoindex(master);
>>>>     netlink_attr(IFLA_MASTER, &ifindex, sizeof(ifindex));
>>>>   }
>>>>   if (macsize)
>>>>     netlink_attr(IFLA_ADDRESS, mac, macsize);
>>>>   int err = netlink_send(sock);
>>>>   (void)err;
>>>> }
>>>>
>>>> static int netlink_add_addr(int sock, const char* dev, const void* addr,
>>>>                             int addrsize)
>>>> {
>>>>   struct ifaddrmsg hdr;
>>>>   memset(&hdr, 0, sizeof(hdr));
>>>>   hdr.ifa_family = addrsize == 4 ? AF_INET : AF_INET6;
>>>>   hdr.ifa_prefixlen = addrsize == 4 ? 24 : 120;
>>>>   hdr.ifa_scope = RT_SCOPE_UNIVERSE;
>>>>   hdr.ifa_index = if_nametoindex(dev);
>>>>   netlink_init(RTM_NEWADDR, NLM_F_CREATE | NLM_F_REPLACE, &hdr,
>>>> sizeof(hdr));
>>>>   netlink_attr(IFA_LOCAL, addr, addrsize);
>>>>   netlink_attr(IFA_ADDRESS, addr, addrsize);
>>>>   return netlink_send(sock);
>>>> }
>>>>
>>>> static void netlink_add_addr4(int sock, const char* dev, const char* addr)
>>>> {
>>>>   struct in_addr in_addr;
>>>>   inet_pton(AF_INET, addr, &in_addr);
>>>>   int err = netlink_add_addr(sock, dev, &in_addr, sizeof(in_addr));
>>>>   (void)err;
>>>> }
>>>>
>>>> static void netlink_add_addr6(int sock, const char* dev, const char* addr)
>>>> {
>>>>   struct in6_addr in6_addr;
>>>>   inet_pton(AF_INET6, addr, &in6_addr);
>>>>   int err = netlink_add_addr(sock, dev, &in6_addr, sizeof(in6_addr));
>>>>   (void)err;
>>>> }
>>>>
>>>> #define DEV_IPV4 "172.20.20.%d"
>>>> #define DEV_IPV6 "fe80::%02hx"
>>>> #define DEV_MAC 0x00aaaaaaaaaa
>>>> static void initialize_netdevices(void)
>>>> {
>>>>   char netdevsim[16];
>>>>   sprintf(netdevsim, "netdevsim%d", (int)procid);
>>>>   struct {
>>>>     const char* type;
>>>>     const char* dev;
>>>>   } devtypes[] = {
>>>>       {"ip6gretap", "ip6gretap0"}, {"bridge", "bridge0"},
>>>>       {"vcan", "vcan0"},           {"bond", "bond0"},
>>>>       {"team", "team0"},           {"dummy", "dummy0"},
>>>>       {"nlmon", "nlmon0"},         {"caif", "caif0"},
>>>>       {"batadv", "batadv0"},       {"vxcan", "vxcan1"},
>>>>       {"netdevsim", netdevsim},    {"veth", 0},
>>>>   };
>>>>   const char* devmasters[] = {"bridge", "bond", "team"};
>>>>   struct {
>>>>     const char* name;
>>>>     int macsize;
>>>>     bool noipv6;
>>>>   } devices[] = {
>>>>       {"lo", ETH_ALEN},
>>>>       {"sit0", 0},
>>>>       {"bridge0", ETH_ALEN},
>>>>       {"vcan0", 0, true},
>>>>       {"tunl0", 0},
>>>>       {"gre0", 0},
>>>>       {"gretap0", ETH_ALEN},
>>>>       {"ip_vti0", 0},
>>>>       {"ip6_vti0", 0},
>>>>       {"ip6tnl0", 0},
>>>>       {"ip6gre0", 0},
>>>>       {"ip6gretap0", ETH_ALEN},
>>>>       {"erspan0", ETH_ALEN},
>>>>       {"bond0", ETH_ALEN},
>>>>       {"veth0", ETH_ALEN},
>>>>       {"veth1", ETH_ALEN},
>>>>       {"team0", ETH_ALEN},
>>>>       {"veth0_to_bridge", ETH_ALEN},
>>>>       {"veth1_to_bridge", ETH_ALEN},
>>>>       {"veth0_to_bond", ETH_ALEN},
>>>>       {"veth1_to_bond", ETH_ALEN},
>>>>       {"veth0_to_team", ETH_ALEN},
>>>>       {"veth1_to_team", ETH_ALEN},
>>>>       {"veth0_to_hsr", ETH_ALEN},
>>>>       {"veth1_to_hsr", ETH_ALEN},
>>>>       {"hsr0", 0},
>>>>       {"dummy0", ETH_ALEN},
>>>>       {"nlmon0", 0},
>>>>       {"vxcan1", 0, true},
>>>>       {"caif0", ETH_ALEN},
>>>>       {"batadv0", ETH_ALEN},
>>>>       {netdevsim, ETH_ALEN},
>>>>   };
>>>>   int sock = socket(AF_NETLINK, SOCK_RAW, NETLINK_ROUTE);
>>>>   if (sock == -1)
>>>>     exit(1);
>>>>   unsigned i;
>>>>   for (i = 0; i < sizeof(devtypes) / sizeof(devtypes[0]); i++)
>>>>     netlink_add_device(sock, devtypes[i].type, devtypes[i].dev);
>>>>   for (i = 0; i < sizeof(devmasters) / (sizeof(devmasters[0])); i++) {
>>>>     char master[32], slave0[32], veth0[32], slave1[32], veth1[32];
>>>>     sprintf(slave0, "%s_slave_0", devmasters[i]);
>>>>     sprintf(veth0, "veth0_to_%s", devmasters[i]);
>>>>     netlink_add_veth(sock, slave0, veth0);
>>>>     sprintf(slave1, "%s_slave_1", devmasters[i]);
>>>>     sprintf(veth1, "veth1_to_%s", devmasters[i]);
>>>>     netlink_add_veth(sock, slave1, veth1);
>>>>     sprintf(master, "%s0", devmasters[i]);
>>>>     netlink_device_change(sock, slave0, false, master, 0, 0);
>>>>     netlink_device_change(sock, slave1, false, master, 0, 0);
>>>>   }
>>>>   netlink_device_change(sock, "bridge_slave_0", true, 0, 0, 0);
>>>>   netlink_device_change(sock, "bridge_slave_1", true, 0, 0, 0);
>>>>   netlink_add_veth(sock, "hsr_slave_0", "veth0_to_hsr");
>>>>   netlink_add_veth(sock, "hsr_slave_1", "veth1_to_hsr");
>>>>   netlink_add_hsr(sock, "hsr0", "hsr_slave_0", "hsr_slave_1");
>>>>   netlink_device_change(sock, "hsr_slave_0", true, 0, 0, 0);
>>>>   netlink_device_change(sock, "hsr_slave_1", true, 0, 0, 0);
>>>>   for (i = 0; i < sizeof(devices) / (sizeof(devices[0])); i++) {
>>>>     char addr[32];
>>>>     sprintf(addr, DEV_IPV4, i + 10);
>>>>     netlink_add_addr4(sock, devices[i].name, addr);
>>>>     if (!devices[i].noipv6) {
>>>>       sprintf(addr, DEV_IPV6, i + 10);
>>>>       netlink_add_addr6(sock, devices[i].name, addr);
>>>>     }
>>>>     uint64_t macaddr = DEV_MAC + ((i + 10ull) << 40);
>>>>     netlink_device_change(sock, devices[i].name, true, 0, &macaddr,
>>>>                           devices[i].macsize);
>>>>   }
>>>>   close(sock);
>>>> }
>>>> static void initialize_netdevices_init(void)
>>>> {
>>>>   int sock = socket(AF_NETLINK, SOCK_RAW, NETLINK_ROUTE);
>>>>   if (sock == -1)
>>>>     exit(1);
>>>>   struct {
>>>>     const char* type;
>>>>     int macsize;
>>>>     bool noipv6;
>>>>     bool noup;
>>>>   } devtypes[] = {
>>>>       {"nr", 7, true}, {"rose", 5, true, true},
>>>>   };
>>>>   unsigned i;
>>>>   for (i = 0; i < sizeof(devtypes) / sizeof(devtypes[0]); i++) {
>>>>     char dev[32], addr[32];
>>>>     sprintf(dev, "%s%d", devtypes[i].type, (int)procid);
>>>>     sprintf(addr, "172.30.%d.%d", i, (int)procid + 1);
>>>>     netlink_add_addr4(sock, dev, addr);
>>>>     if (!devtypes[i].noipv6) {
>>>>       sprintf(addr, "fe88::%02hx:%02hx", i, (int)procid + 1);
>>>>       netlink_add_addr6(sock, dev, addr);
>>>>     }
>>>>     int macsize = devtypes[i].macsize;
>>>>     uint64_t macaddr = 0xbbbbbb +
>>>>                        ((unsigned long long)i << (8 * (macsize - 2))) +
>>>>                        (procid << (8 * (macsize - 1)));
>>>>     netlink_device_change(sock, dev, !devtypes[i].noup, 0, &macaddr,
>>>> macsize);
>>>>   }
>>>>   close(sock);
>>>> }
>>>>
>>>> static void setup_common()
>>>> {
>>>>   if (mount(0, "/sys/fs/fuse/connections", "fusectl", 0, 0)) {
>>>>   }
>>>> }
>>>>
>>>> static void loop();
>>>>
>>>> static void sandbox_common()
>>>> {
>>>>   prctl(PR_SET_PDEATHSIG, SIGKILL, 0, 0, 0);
>>>>   setpgrp();
>>>>   setsid();
>>>>   struct rlimit rlim;
>>>>   rlim.rlim_cur = rlim.rlim_max = 200 << 20;
>>>>   setrlimit(RLIMIT_AS, &rlim);
>>>>   rlim.rlim_cur = rlim.rlim_max = 32 << 20;
>>>>   setrlimit(RLIMIT_MEMLOCK, &rlim);
>>>>   rlim.rlim_cur = rlim.rlim_max = 136 << 20;
>>>>   setrlimit(RLIMIT_FSIZE, &rlim);
>>>>   rlim.rlim_cur = rlim.rlim_max = 1 << 20;
>>>>   setrlimit(RLIMIT_STACK, &rlim);
>>>>   rlim.rlim_cur = rlim.rlim_max = 0;
>>>>   setrlimit(RLIMIT_CORE, &rlim);
>>>>   rlim.rlim_cur = rlim.rlim_max = 256;
>>>>   setrlimit(RLIMIT_NOFILE, &rlim);
>>>>   if (unshare(CLONE_NEWNS)) {
>>>>   }
>>>>   if (unshare(CLONE_NEWIPC)) {
>>>>   }
>>>>   if (unshare(0x02000000)) {
>>>>   }
>>>>   if (unshare(CLONE_NEWUTS)) {
>>>>   }
>>>>   if (unshare(CLONE_SYSVSEM)) {
>>>>   }
>>>>   typedef struct {
>>>>     const char* name;
>>>>     const char* value;
>>>>   } sysctl_t;
>>>>   static const sysctl_t sysctls[] = {
>>>>       {"/proc/sys/kernel/shmmax", "16777216"},
>>>>       {"/proc/sys/kernel/shmall", "536870912"},
>>>>       {"/proc/sys/kernel/shmmni", "1024"},
>>>>       {"/proc/sys/kernel/msgmax", "8192"},
>>>>       {"/proc/sys/kernel/msgmni", "1024"},
>>>>       {"/proc/sys/kernel/msgmnb", "1024"},
>>>>       {"/proc/sys/kernel/sem", "1024 1048576 500 1024"},
>>>>   };
>>>>   unsigned i;
>>>>   for (i = 0; i < sizeof(sysctls) / sizeof(sysctls[0]); i++)
>>>>     write_file(sysctls[i].name, sysctls[i].value);
>>>> }
>>>>
>>>> int wait_for_loop(int pid)
>>>> {
>>>>   if (pid < 0)
>>>>     exit(1);
>>>>   int status = 0;
>>>>   while (waitpid(-1, &status, __WALL) != pid) {
>>>>   }
>>>>   return WEXITSTATUS(status);
>>>> }
>>>>
>>>> static int do_sandbox_none(void)
>>>> {
>>>>   if (unshare(CLONE_NEWPID)) {
>>>>   }
>>>>   int pid = fork();
>>>>   if (pid != 0)
>>>>     return wait_for_loop(pid);
>>>>   setup_common();
>>>>   sandbox_common();
>>>>   initialize_netdevices_init();
>>>>   if (unshare(CLONE_NEWNET)) {
>>>>   }
>>>>   initialize_netdevices();
>>>>   loop();
>>>>   exit(1);
>>>> }
>>>>
>>>> #define FS_IOC_SETFLAGS _IOW('f', 2, long)
>>>> static void remove_dir(const char* dir)
>>>> {
>>>>   DIR* dp;
>>>>   struct dirent* ep;
>>>>   int iter = 0;
>>>> retry:
>>>>   while (umount2(dir, MNT_DETACH) == 0) {
>>>>   }
>>>>   dp = opendir(dir);
>>>>   if (dp == NULL) {
>>>>     if (errno == EMFILE) {
>>>>       exit(1);
>>>>     }
>>>>     exit(1);
>>>>   }
>>>>   while ((ep = readdir(dp))) {
>>>>     if (strcmp(ep->d_name, ".") == 0 || strcmp(ep->d_name, "..") == 0)
>>>>       continue;
>>>>     char filename[FILENAME_MAX];
>>>>     snprintf(filename, sizeof(filename), "%s/%s", dir, ep->d_name);
>>>>     while (umount2(filename, MNT_DETACH) == 0) {
>>>>     }
>>>>     struct stat st;
>>>>     if (lstat(filename, &st))
>>>>       exit(1);
>>>>     if (S_ISDIR(st.st_mode)) {
>>>>       remove_dir(filename);
>>>>       continue;
>>>>     }
>>>>     int i;
>>>>     for (i = 0;; i++) {
>>>>       if (unlink(filename) == 0)
>>>>         break;
>>>>       if (errno == EPERM) {
>>>>         int fd = open(filename, O_RDONLY);
>>>>         if (fd != -1) {
>>>>           long flags = 0;
>>>>           if (ioctl(fd, FS_IOC_SETFLAGS, &flags) == 0)
>>>>             close(fd);
>>>>           continue;
>>>>         }
>>>>       }
>>>>       if (errno == EROFS) {
>>>>         break;
>>>>       }
>>>>       if (errno != EBUSY || i > 100)
>>>>         exit(1);
>>>>       if (umount2(filename, MNT_DETACH))
>>>>         exit(1);
>>>>     }
>>>>   }
>>>>   closedir(dp);
>>>>   int i;
>>>>   for (i = 0;; i++) {
>>>>     if (rmdir(dir) == 0)
>>>>       break;
>>>>     if (i < 100) {
>>>>       if (errno == EPERM) {
>>>>         int fd = open(dir, O_RDONLY);
>>>>         if (fd != -1) {
>>>>           long flags = 0;
>>>>           if (ioctl(fd, FS_IOC_SETFLAGS, &flags) == 0)
>>>>             close(fd);
>>>>           continue;
>>>>         }
>>>>       }
>>>>       if (errno == EROFS) {
>>>>         break;
>>>>       }
>>>>       if (errno == EBUSY) {
>>>>         if (umount2(dir, MNT_DETACH))
>>>>           exit(1);
>>>>         continue;
>>>>       }
>>>>       if (errno == ENOTEMPTY) {
>>>>         if (iter < 100) {
>>>>           iter++;
>>>>           goto retry;
>>>>         }
>>>>       }
>>>>     }
>>>>     exit(1);
>>>>   }
>>>> }
>>>>
>>>> static void kill_and_wait(int pid, int* status)
>>>> {
>>>>   kill(-pid, SIGKILL);
>>>>   kill(pid, SIGKILL);
>>>>   int i;
>>>>   for (i = 0; i < 100; i++) {
>>>>     if (waitpid(-1, status, WNOHANG | __WALL) == pid)
>>>>       return;
>>>>     usleep(1000);
>>>>   }
>>>>   DIR* dir = opendir("/sys/fs/fuse/connections");
>>>>   if (dir) {
>>>>     for (;;) {
>>>>       struct dirent* ent = readdir(dir);
>>>>       if (!ent)
>>>>         break;
>>>>       if (strcmp(ent->d_name, ".") == 0 || strcmp(ent->d_name, "..") == 0)
>>>>         continue;
>>>>       char abort[300];
>>>>       snprintf(abort, sizeof(abort), "/sys/fs/fuse/connections/%s/abort",
>>>>                ent->d_name);
>>>>       int fd = open(abort, O_WRONLY);
>>>>       if (fd == -1) {
>>>>         continue;
>>>>       }
>>>>       if (write(fd, abort, 1) < 0) {
>>>>       }
>>>>       close(fd);
>>>>     }
>>>>     closedir(dir);
>>>>   } else {
>>>>   }
>>>>   while (waitpid(-1, status, __WALL) != pid) {
>>>>   }
>>>> }
>>>>
>>>> #define SYZ_HAVE_SETUP_TEST 1
>>>> static void setup_test()
>>>> {
>>>>   prctl(PR_SET_PDEATHSIG, SIGKILL, 0, 0, 0);
>>>>   setpgrp();
>>>> }
>>>>
>>>> #define SYZ_HAVE_RESET_TEST 1
>>>> static void reset_test()
>>>> {
>>>>   int fd;
>>>>   for (fd = 3; fd < 30; fd++)
>>>>     close(fd);
>>>> }
>>>>
>>>> static void execute_one(void);
>>>>
>>>> #define WAIT_FLAGS __WALL
>>>>
>>>> static void loop(void)
>>>> {
>>>>   int iter;
>>>>   for (iter = 0;; iter++) {
>>>>     char cwdbuf[32];
>>>>     sprintf(cwdbuf, "./%d", iter);
>>>>     if (mkdir(cwdbuf, 0777))
>>>>       exit(1);
>>>>     int pid = fork();
>>>>     if (pid < 0)
>>>>       exit(1);
>>>>     if (pid == 0) {
>>>>       if (chdir(cwdbuf))
>>>>         exit(1);
>>>>       setup_test();
>>>>       execute_one();
>>>>       reset_test();
>>>>       exit(0);
>>>>     }
>>>>     int status = 0;
>>>>     uint64_t start = current_time_ms();
>>>>     for (;;) {
>>>>       if (waitpid(-1, &status, WNOHANG | WAIT_FLAGS) == pid)
>>>>         break;
>>>>       sleep_ms(1);
>>>>       if (current_time_ms() - start < 5 * 1000)
>>>>         continue;
>>>>       kill_and_wait(pid, &status);
>>>>       break;
>>>>     }
>>>>     remove_dir(cwdbuf);
>>>>   }
>>>> }
>>>>
>>>> void execute_one(void)
>>>> {
>>>>   syscall(__NR_unshare, 0x40000000);
>>>> }
>>>> int main(void)
>>>> {
>>>>   syscall(__NR_mmap, 0x20000000, 0x1000000, 3, 0x32, -1, 0);
>>>>   for (procid = 0; procid < 8; procid++) {
>>>>     if (fork() == 0) {
>>>>       use_temporary_dir();
>>>>       do_sandbox_none();
>>>>     }
>>>>   }
>>>>   sleep(1000000);
>>>>   return 0;
>>>> }
>>>>
>>>>
>>>> I reviewed kernel code and found a bug that
>>>> net_drop_ns func doesn't call net_free func when refcount_dec_and_test's
>>>> return value is zero.
>>> Yes.  We don't call net_free when the reference count does not decrement
>>> to zero.  The reference count is initialized to 1 a few lines above the
>>> section of code in your patch so that should not be a problem.
>>>
>>>> or
>>>> when rv = down_read_killable(&pernet_ops_rwsem) < 0, it doesn't need to
>>>> call refcount_dec_and_test.
>>> It doesn't need to but it should be harmless.
>>>
>>>> https://github.com/torvalds/linux/commit/5ba049a5cc8e24a1643df75bbf65b4efa070fa74#diff-9312644e2968a45510bacdd2b2872ad2
>>>> (I can't reproduce this bug on v4.15 , and
>>>> 1bdbe227492075d058e37cb3d400e6468d0095b5 with my patch. Because of the
>>>> previous version of kernel doesn't have this bug.)
>>>> This bug can lead to memory leak or DOS.
>>>>
>>>> I made a patch for this bug. (just revert to a before commit)
>>> What am I missing?
>>>
>>> The only thing I can see your patch doing is covering up a memory stomp
>>> that has the effect of changing the value of net->passive.  I am not
>>> really keen on hiding bugs of that kind.
>>>
>>>
>>>> diff --git a/net/core/net_namespace.c b/net/core/net_namespace.c
>>>> index b02fb19df2cc..9de0ade14956 100644
>>>> --- a/net/core/net_namespace.c
>>>> +++ b/net/core/net_namespace.c
>>>> @@ -431,15 +431,18 @@ struct net *copy_net_ns(unsigned long flags,
>>>>         get_user_ns(user_ns);
>>>>
>>>>         rv = down_read_killable(&pernet_ops_rwsem);
>>>> -       if (rv < 0)
>>>> -               goto put_userns;
>>>> +       if (rv < 0){
>>>> +        net_free(net);
>>>> +        dec_net_namespaces(ucounts);
>>>> +        put_user_ns(user_ns);
>>>> +        return ERR_PTR(rv);
>>>> +    }
>>>>
>>>>         rv = setup_net(net, user_ns);
>>>>
>>>>         up_read(&pernet_ops_rwsem);
>>>>
>>>>         if (rv < 0) {
>>>> -put_userns:
>>>>                 put_user_ns(user_ns);
>>>>                 net_drop_ns(net);
>>>>  dec_ucounts:
>>>>
>>>> and, sorry for my encrypted mails.
>>> Eric
>>>
Dmitry Vyukov Jan. 14, 2019, 11:58 a.m. | #5
On Sat, Jan 12, 2019 at 11:34 AM zzoru <zzoru007@gmail.com> wrote:
>
> Probably, there is a memory bug on net object by setup_net() -> ops_init(). (ipv4_sysctl_init_net,  ipmr_net_init, etc...)
> I also found that this bug can reproduce v4.18-rc1~
>
> On Sat, Jan 12, 2019 at 8:51 AM Eric W. Biederman <ebiederm@xmission.com> wrote:
>>
>> zzoru <zzoru007@gmail.com> writes:
>>
>> >> I received 3 spam messages from this address today.
>> >> We can simply ignore this report.
>> > I already mentioned about this.
>> >
>> >> and, sorry for my encrypted mails.
>> >> I don't understand this failure report at all.
>> >>
>> >> I don't see the connection to copy_net_ns().  And I don't see how the
>> >> suggested patch short of covering up a memory stomp could possibly make
>> >> a difference.
>> >>
>> >> What am I missing?
>> >> void execute_one(void)
>> >> {
>> >>   syscall(__NR_unshare, 0x40000000);
>> >> }
>> > ksys_unshare -> unshare_nsproxy_namespaces -> create_new_namespaces ->
>> > copy_net_ns
>> > unshare(CLONE_NEWNET) calls copy_net_ns() (It requires the CAP_SYS_ADMIN
>> > capability)
>>
>> Looking at your alternate patch where you switch the structure
>> order it looks like there is a memory stomp.  Probably a use
>> after free.  It is a shame that KASAN is not catching the problem.
>> That is my only suggestion at the moment.
>>
>> The OOM may be because network namespaces are created in quick
>> succession and they take a while to free.
>>
>> One of the nasty truths about testing is sometimes you can be testing
>> one thing and you can trigger a bug in something completely different.
>> Right now it looks like anything that copy_net_ns calls could be
>> responsible for the memory problems.

This looks superciliously similar to:
https://groups.google.com/d/msg/syzkaller-bugs/nFeC8-UG1gg/B6GFaZFrFQAJ

The crux: for the last ~half a year low memory conditions randomly
corrupt kernel memory with stack overflows.


>> > I made many error reports about this bug, and the other one is
>> >
>> > [   90.289025] WARNING: CPU: 1 PID: 1732 at mm/page_alloc.c:4415
>> > __alloc_pages_slowpath+0x1cb1/0x2220
>> > [   90.290223] Modules linked in:
>> > [   90.290639] CPU: 1 PID: 1732 Comm: kworker/u4:5 Not tainted 5.0.0-rc1+ #6
>> > [   90.291475] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996),
>> > BIOS Ubuntu-1.8.2-1ubuntu1 04/01/2014
>> > [   90.292681] Workqueue: writeback wb_workfn (flush-8:0)
>> > [   90.293350] RIP: 0010:__alloc_pages_slowpath+0x1cb1/0x2220
>> > [   90.294075] Code: 8b 84 24 a8 00 00 00 e9 ea f1 ff ff 85 d2 0f 85 0b
>> > 01 00 00 48 c7 c7 c0 5e 55 84 e8 79 f8 23 02 e9 86 f9 ff ff 44 8b 74 24
>> > 0c <0f> 0b 48 b8 00 00 00 00 00 fc ff df 48 8b 54 24 18 48 c1 ea 03 80
>> > [   90.296527] RSP: 0018:ffff888064276dd8 EFLAGS: 00010046
>> > [   90.297203] RAX: 0000000000000000 RBX: 0000000000000000 RCX:
>> > 1ffff1100c84eda8
>> > [   90.297784] kmemleak: Cannot allocate a kmemleak_object structure
>> > [   90.298186] RDX: 0000000000000000 RSI: 0000000000000000 RDI:
>> > ffff88807ffdd528
>> > [   90.298242] RBP: dffffc0000000000 R08: 0000000000000000 R09:
>> > 0000000000000679
>> > [   90.298247] R10: 0000000000000000 R11: ffff88807ffdc487 R12:
>> > 0000000000000000
>> > [   90.298251] R13: ffff888064277030 R14: 0000000000415a00 R15:
>> > ffff888064277030
>> > [   90.298257] FS:  0000000000000000(0000) GS:ffff88806d500000(0000)
>> > knlGS:0000000000000000
>> > [   90.298262] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
>> > [   90.298267] CR2: 00007fff6ac6a718 CR3: 0000000056578000 CR4:
>> > 00000000000006e0
>> > [   90.298272] Call Trace:
>> > [   90.298283]  ? __alloc_pages_slowpath+0x1ce6/0x2220
>> > [   90.298299]  ? warn_alloc+0x120/0x120
>> > [   90.302432] kmemleak: Kernel memory leak detector disabled
>> > [   90.303346]  ? lock_acquire+0x103/0x2e0
>> > [   90.303358]  ? __isolate_free_page+0x4b0/0x4b0
>> > [   90.303366]  ? __lock_is_held+0xad/0x140
>> > [   90.303377]  __alloc_pages_nodemask+0x521/0x5f0
>> > [   90.303386]  ? __alloc_pages_slowpath+0x2220/0x2220
>> > [   90.315010]  cache_grow_begin+0x95/0x300
>> > [   90.315613]  fallback_alloc+0x1ce/0x270
>> > [   90.316211]  ? mempool_free+0x360/0x360
>> > [   90.316767]  kmem_cache_alloc+0x286/0x2f0
>> > [   90.317348]  ? mempool_free+0x360/0x360
>> > [   90.317919]  create_object+0x83/0x880
>> > [   90.318517]  ? kmemleak_disable+0x90/0x90
>> > [   90.319103]  ? mark_held_locks+0xc1/0x140
>> > [   90.319679]  ? kmem_cache_alloc+0x9c/0x2f0
>> > [   90.320307]  ? mempool_free+0x360/0x360
>> > [   90.320900]  kmem_cache_alloc+0x18f/0x2f0
>> > [   90.321650]  ? mempool_free+0x360/0x360
>> > [   90.322228]  mempool_alloc+0x13e/0x340
>> > [   90.322765]  ? mempool_destroy+0x30/0x30
>> > [   90.323370]  ? mark_held_locks+0xc1/0x140
>> > [   90.323993]  ? _raw_spin_unlock_irqrestore+0x3e/0x50
>> > [   90.324786]  bio_alloc_bioset+0x36f/0x5d0
>> > [   90.325397]  ? __test_set_page_writeback+0x136/0x960
>> > [   90.326161]  ? bvec_alloc+0x2d0/0x2d0
>> > [   90.326708]  ? wait_for_stable_page+0x290/0x290
>> > [   90.327392]  submit_bh_wbc.isra.57+0x128/0x680
>> > [   90.328053]  ? create_page_buffers+0x111/0x200
>> > [   90.328685]  __block_write_full_page+0x6e8/0xcd0
>> > [   90.329339]  ? check_disk_change+0x130/0x130
>> > [   90.329966]  block_write_full_page+0x202/0x250
>> > [   90.330675]  ? check_disk_change+0x130/0x130
>> > [   90.331291]  __writepage+0x62/0xe0
>> > [   90.331786]  write_cache_pages+0x5b8/0xf60
>> > [   90.332375]  ? __wb_calc_thresh+0x290/0x290
>> > [   90.332976]  ? clear_page_dirty_for_io+0x5c0/0x5c0
>> > [   90.333686]  ? mark_held_locks+0x140/0x140
>> > [   90.334301]  ? print_circular_bug_entry+0x1f/0x60
>> > [   90.334999]  ? __lock_acquire+0x5d6/0x4630
>> > [   90.335621]  generic_writepages+0xda/0x150
>> > [   90.336243]  ? write_cache_pages+0xf60/0xf60
>> > [   90.336852]  ? mark_held_locks+0x140/0x140
>> > [   90.337453]  ? blkdev_readpages+0x30/0x30
>> > [   90.338020]  do_writepages+0xf0/0x290
>> > [   90.338611]  ? page_writeback_cpu_online+0x10/0x10
>> > [   90.339324]  ? __lock_is_held+0xad/0x140
>> > [   90.339900]  __writeback_single_inode+0xf3/0x1000
>> > [   90.340587]  writeback_sb_inodes+0x4e7/0xce0
>> > [   90.341214]  ? __writeback_single_inode+0x1000/0x1000
>> > [   90.341929]  ? down_read_trylock+0x5b/0x90
>> > [   90.342579]  ? trylock_super+0x1d/0x100
>> > [   90.343162]  __writeback_inodes_wb+0x109/0x220
>> > [   90.343799]  wb_writeback+0x7a1/0xb90
>> > [   90.344347]  ? writeback_inodes_wb.constprop.44+0x190/0x190
>> > [   90.345143]  ? cpumask_next+0x1f/0x30
>> > [   90.345679]  ? find_next_bit+0x101/0x130
>> > [   90.346281]  ? get_nr_dirty_inodes+0xd0/0x130
>> > [   90.346909]  wb_workfn+0x921/0xec0
>> > [   90.347397]  ? process_one_work+0xadd/0x1bb0
>> > [   90.348025]  ? inode_wait_for_writeback+0x30/0x30
>> > [   90.348700]  process_one_work+0xbbd/0x1bb0
>> > [   90.349314]  ? max_active_store+0x130/0x130
>> > [   90.349915]  ? do_raw_spin_lock+0x11b/0x280
>> > [   90.350557]  worker_thread+0x8c/0x1060
>> > [   90.351096]  ? __kthread_parkme+0xf8/0x1a0
>> > [   90.351673]  ? process_one_work+0x1bb0/0x1bb0
>> > [   90.352334]  kthread+0x347/0x410
>> > [   90.352798]  ? kthread_create_worker_on_cpu+0xe0/0xe0
>> > [   90.353509]  ret_from_fork+0x3a/0x50
>> > [   90.354020] irq event stamp: 282384
>> > [   90.354590] hardirqs last  enabled at (282383): [<ffffffff8160678c>]
>> > kmem_cache_alloc+0x9c/0x2f0
>> > [   90.355832] hardirqs last disabled at (282384): [<ffffffff8160674d>]
>> > kmem_cache_alloc+0x5d/0x2f0
>> > [   90.357066] softirqs last  enabled at (282196): [<ffffffff816daa87>]
>> > wb_workfn+0x387/0xec0
>> > [   90.358280] softirqs last disabled at (282194): [<ffffffff816da918>]
>> > wb_workfn+0x218/0xec0
>> > [   90.359426] ---[ end trace 71c4462c6227f0d8 ]---
>> > [   90.360135] kmemleak: Cannot allocate a kmemleak_object structure
>> > [   90.888624] a.out invoked oom-killer:
>> > gfp_mask=0x6040d0(GFP_KERNEL|__GFP_COMP|__GFP_RECLAIMABLE), order=0,
>> > oom_score_adj=0
>> > [   90.890564] CPU: 0 PID: 22248 Comm: a.out Tainted: G        W
>> > 5.0.0-rc1+ #6
>> > [   90.891793] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996),
>> > BIOS Ubuntu-1.8.2-1ubuntu1 04/01/2014
>> > [   90.893263] Call Trace:
>> > [   90.893678]  dump_stack+0xca/0x13e
>> > [   90.894242]  dump_header+0x108/0xaef
>> > [   90.894822]  ? ___ratelimit+0x5b/0x436
>> > [   90.895430]  oom_kill_process.cold.38+0x10/0xa87
>> > [   90.896164]  ? lock_downgrade+0x5d0/0x5d0
>> > [   90.896806]  ? _raw_spin_unlock+0x1f/0x30
>> > [   90.897445]  ? oom_badness+0xc8/0x770
>> > [   90.898045]  out_of_memory+0x32a/0x1ab0
>> > [   90.898668]  ? oom_killer_disable+0x280/0x280
>> > [   90.899365]  ? mutex_trylock+0x162/0x1a0
>> > [   90.899998]  __alloc_pages_slowpath+0x1b7a/0x2220
>> > [   90.900754]  ? warn_alloc+0x120/0x120
>> > [   90.901344]  ? find_held_lock+0x33/0x1c0
>> > [   90.901985]  __alloc_pages_nodemask+0x521/0x5f0
>> > [   90.902723]  ? __alloc_pages_slowpath+0x2220/0x2220
>> > [   90.903499]  ? mark_held_locks+0xc1/0x140
>> > [   90.904137]  ? cache_grow_begin+0x28f/0x300
>> > [   90.904807]  cache_grow_begin+0x95/0x300
>> > [   90.905443]  fallback_alloc+0x1ce/0x270
>> > [   90.906074]  kmem_cache_alloc+0x286/0x2f0
>> > [   90.906720]  ? sock_destroy_inode+0x60/0x60
>> > [   90.907392]  sock_alloc_inode+0x18/0x250
>> > [   90.908021]  ? sock_destroy_inode+0x60/0x60
>> > [   90.908690]  alloc_inode+0x5e/0x180
>> > [   90.909254]  new_inode_pseudo+0x12/0xd0
>> > [   90.909868]  sock_alloc+0x3c/0x270
>> > [   90.910428]  __sock_create+0xbe/0x740
>> > [   90.911026]  inet_ctl_sock_create+0x8c/0x1e0
>> > [   90.911710]  ? inet_current_timestamp+0xc0/0xc0
>> > [   90.912432]  ? rcu_read_lock_sched_held+0x10f/0x130
>> > [   90.913205]  ? find_next_bit+0x101/0x130
>> > [   90.913837]  icmpv6_sk_init+0x12a/0x2b0
>> > [   90.914463]  ? inet6_net_init+0x437/0x7c0
>> > [   90.915102]  ? icmpv6_err_convert+0x180/0x180
>> > [   90.915799]  ? ac6_proc_init+0x5a/0x70
>> > [   90.916402]  ? inet6_net_init+0x53b/0x7c0
>> > [   90.917041]  ? icmpv6_err_convert+0x180/0x180
>> > [   90.917734]  ops_init+0xb2/0x400
>> > [   90.918265]  setup_net+0x24c/0x5e0
>> > [   90.918817]  ? ops_init+0x400/0x400
>> > [   90.919386]  copy_net_ns+0x1a2/0x270
>> > [   90.919969]  create_new_namespaces+0x579/0x790
>> > [   90.920676]  unshare_nsproxy_namespaces+0xc3/0x190
>> > [   90.921435]  ksys_unshare+0x428/0x810
>> > [   90.922029]  ? walk_process_tree+0x2c0/0x2c0
>> > [   90.922712]  ? __change_pid+0x19c/0x2c0
>> > [   90.923328]  ? _raw_write_unlock_irq+0x24/0x30
>> > [   90.924038]  ? trace_hardirqs_on_thunk+0x1a/0x1c
>> > [   90.924771]  ? trace_hardirqs_off_caller+0x55/0x1c0
>> > [   90.925547]  __x64_sys_unshare+0x2d/0x40
>> > [   90.926187]  do_syscall_64+0xbc/0x4e0
>> > [   90.926777]  entry_SYSCALL_64_after_hwframe+0x49/0xbe
>> > [   90.927573] RIP: 0033:0x7f827ad52229
>> > [   90.928146] Code: Bad RIP value.
>> > [   90.928663] RSP: 002b:00007fff6ac6a6c8 EFLAGS: 00000217 ORIG_RAX:
>> > 0000000000000110
>> > [   90.929837] RAX: ffffffffffffffda RBX: 0000000000000000 RCX:
>> > 00007f827ad52229
>> > [   90.930952] RDX: 00007f827ad27147 RSI: 0000000000000000 RDI:
>> > 0000000040000000
>> > [   90.932056] RBP: 00007fff6ac6a6d0 R08: 0000000000000005 R09:
>> > 00007fff6ac6a720
>> > [   90.933165] R10: 0000000000000000 R11: 0000000000000217 R12:
>> > 00005607242822e0
>> > [   90.934278] R13: 00007fff6ac6a830 R14: 0000000000000000 R15:
>> > 0000000000000000
>> >
>> > I just guess that copy_net_ns func doesn't call net_free, and it makes OOM.
>> >
>> > And, I found that
>> >
>> > diff --git a/include/net/net_namespace.h b/include/net/net_namespace.h
>> > index 99d4148e0f90..38c474e4ab4c 100644
>> > --- a/include/net/net_namespace.h
>> > +++ b/include/net/net_namespace.h
>> > @@ -50,12 +50,12 @@ struct bpf_prog;
>> >  #define NETDEV_HASHENTRIES (1 << NETDEV_HASHBITS)
>> >
>> >  struct net {
>> > -       refcount_t              passive;        /* To decided when the
>> > network
>> > -                                                * namespace should be
>> > freed.
>> > -                                                */
>> >         refcount_t              count;          /* To decided when the
>> > network
>> >                                                  *  namespace should be
>> > shut down.
>> >                                                  */
>> > +       refcount_t              passive;        /* To decided when the
>> > network
>> > +                                                * namespace should be
>> > freed.
>> > +                                                */
>> >         spinlock_t              rules_mod_lock;
>> >
>> >         atomic64_t              cookie_gen;
>> >
>> > this patch also works on this bug. (Just swap the order of net struct.)
>> > I don't know why this patch works (I just thought that compiler
>> > optimization issue can make this bug and try this one.)
>> > I need to review code more on copy_net_ns().
>> >
>> > Also, I reproduce this bug on Ubuntu 18.10 (4.18.0-10-generic) on VMWare
>> > Workstation Pro 15.0.2 by C reproducer.
>> >
>> > On 12/01/2019 5:41 오전, Kirill Tkhai wrote:
>> >> On 11.01.2019 23:33, Eric W. Biederman wrote:
>> >>> zzoru <zzoru007@gmail.com> writes:
>> >>>
>> >>>> net/core: BUG in copy_net_ns() (net_namespace.c)
>> >>> I don't understand this failure report at all.
>> >>>
>> >>> I don't see the connection to copy_net_ns().  And I don't see how the
>> >>> suggested patch short of covering up a memory stomp could possibly make
>> >>> a difference.
>> >>>
>> >>> What am I missing?
>> >> I received 3 spam messages from this address today.
>> >> We can simply ignore this report.
>> >>
>> >>>
>> >>>> Hello,
>> >>>>
>> >>>> I've got the following error report while fuzzing the kernel with syzkaller.
>> >>>>
>> >>>> On commit 1bdbe227492075d058e37cb3d400e6468d0095b5
>> >>>>
>> >>>> Syzkaller hit 'WARNING in __alloc_pages_slowpath' bug.
>> >>>>
>> >>>> syz-executor561 (17453) used greatest stack depth: 25056 bytes left
>> >>>> WARNING: CPU: 0 PID: 692 at mm/page_alloc.c:4415
>> >>>> __alloc_pages_slowpath+0x1cb1/0x2220 mm/page_alloc.c:4386
>> >>>> Kernel panic - not syncing: panic_on_warn set ...
>> >>>> CPU: 0 PID: 692 Comm: kswapd0 Not tainted 5.0.0-rc1+ #4
>> >>>> Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS
>> >>>> Ubuntu-1.8.2-1ubuntu1 04/01/2014
>> >>>> Call Trace:
>> >>>>  __dump_stack lib/dump_stack.c:77 [inline]
>> >>>>  dump_stack+0xca/0x13e lib/dump_stack.c:113
>> >>>>  panic+0x278/0x5bf kernel/panic.c:214
>> >>>>  __warn.cold.10+0x20/0x45 kernel/panic.c:571
>> >>>>  report_bug+0x246/0x2d0 lib/bug.c:186
>> >>>>  fixup_bug arch/x86/kernel/traps.c:178 [inline]
>> >>>>  do_error_trap+0x123/0x1e0 arch/x86/kernel/traps.c:271
>> >>>>  do_invalid_op+0x31/0x40 arch/x86/kernel/traps.c:290
>> >>>>  invalid_op+0x14/0x20 arch/x86/entry/entry_64.S:973
>> >>>> RIP: 0010:__alloc_pages_slowpath+0x1cb1/0x2220 mm/page_alloc.c:4415
>> >>>> Code: 8b 84 24 a8 00 00 00 e9 ea f1 ff ff 85 d2 0f 85 0b 01 00 00 48 c7
>> >>>> c7 c0 5e 55 84 e8 79 f8 23 02 e9 86 f9 ff ff 44 8b 74 24 0c <0f> 0b 48
>> >>>> b8 00 00 00 00 00 fc ff df 48 8b 54 24 18 48 c1 ea 03 80
>> >>>> RSP: 0018:ffff8880683fedb8 EFLAGS: 00010046
>> >>>> RAX: 0000000000000000 RBX: 0000000000000000 RCX: 1ffff1100d07fda4
>> >>>> RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff88807ffdd528
>> >>>> RBP: dffffc0000000000 R08: 0000000000000000 R09: 000000000000067a
>> >>>> R10: 0000000000000000 R11: ffff88807ffdc487 R12: 0000000000000000
>> >>>> R13: ffff8880683ff010 R14: 0000000000415a00 R15: ffff8880683ff010
>> >>>>  __alloc_pages_nodemask+0x521/0x5f0 mm/page_alloc.c:4555
>> >>>>  __alloc_pages include/linux/gfp.h:473 [inline]
>> >>>>  __alloc_pages_node include/linux/gfp.h:486 [inline]
>> >>>>  kmem_getpages mm/slab.c:1398 [inline]
>> >>>>  cache_grow_begin+0x95/0x300 mm/slab.c:2666
>> >>>>  fallback_alloc+0x1ce/0x270 mm/slab.c:3208
>> >>>>  __do_cache_alloc mm/slab.c:3345 [inline]
>> >>>>  slab_alloc mm/slab.c:3373 [inline]
>> >>>>  kmem_cache_alloc+0x286/0x2f0 mm/slab.c:3541
>> >>>>  create_object+0x83/0x880 mm/kmemleak.c:578
>> >>>>  kmemleak_alloc_recursive include/linux/kmemleak.h:55 [inline]
>> >>>>  slab_post_alloc_hook mm/slab.h:442 [inline]
>> >>>>  slab_alloc mm/slab.c:3381 [inline]
>> >>>>  kmem_cache_alloc+0x18f/0x2f0 mm/slab.c:3541
>> >>>>  mempool_alloc+0x13e/0x340 mm/mempool.c:385
>> >>>>  bio_alloc_bioset+0x36f/0x5d0 block/bio.c:489
>> >>>>  bio_alloc include/linux/bio.h:393 [inline]
>> >>>>  submit_bh_wbc.isra.57+0x128/0x680 fs/buffer.c:3061
>> >>>>  __block_write_full_page+0x6e8/0xcd0 fs/buffer.c:1765
>> >>>>  block_write_full_page+0x202/0x250 fs/buffer.c:2955
>> >>>>  pageout mm/vmscan.c:865 [inline]
>> >>>>  shrink_page_list+0x220f/0x3800 mm/vmscan.c:1383
>> >>>>  shrink_inactive_list+0x3c2/0xaa0 mm/vmscan.c:1961
>> >>>>  shrink_list mm/vmscan.c:2273 [inline]
>> >>>>  shrink_node_memcg.constprop.83+0x4bf/0x10e0 mm/vmscan.c:2538
>> >>>>  shrink_node+0x162/0xd10 mm/vmscan.c:2753
>> >>>>  kswapd_shrink_node mm/vmscan.c:3516 [inline]
>> >>>>  balance_pgdat+0x47f/0xc00 mm/vmscan.c:3674
>> >>>>  kswapd+0x57c/0xde0 mm/vmscan.c:3929
>> >>>>  kthread+0x347/0x410 kernel/kthread.c:246
>> >>>>  ret_from_fork+0x3a/0x50 arch/x86/entry/entry_64.S:352
>> >>>> Dumping ftrace buffer:
>> >>>>    (ftrace buffer empty)
>> >>>> Kernel Offset: disabled
>> >>>> Rebooting in 86400 seconds..
>> >>>>
>> >>>>
>> >>>> Syzkaller reproducer:
>> >>>> # {Threaded:false Collide:false Repeat:true RepeatTimes:0 Procs:8
>> >>>> Sandbox:none Fault:false FaultCall:-1 FaultNth:0 EnableTun:false
>> >>>> UseTmpDir:true EnableCgroups:false EnableNetdev:true ResetNet:false
>> >>>> HandleSegv:false Repro:false Trace:false}
>> >>>> unshare(0x40000000)
>> >>>>
>> >>>>
>> >>>> C reproducer:
>> >>>> // autogenerated by syzkaller (https://github.com/google/syzkaller)
>> >>>>
>> >>>> #define _GNU_SOURCE
>> >>>>
>> >>>> #include <arpa/inet.h>
>> >>>> #include <dirent.h>
>> >>>> #include <endian.h>
>> >>>> #include <errno.h>
>> >>>> #include <fcntl.h>
>> >>>> #include <net/if.h>
>> >>>> #include <net/if_arp.h>
>> >>>> #include <netinet/in.h>
>> >>>> #include <sched.h>
>> >>>> #include <signal.h>
>> >>>> #include <stdarg.h>
>> >>>> #include <stdbool.h>
>> >>>> #include <stdint.h>
>> >>>> #include <stdio.h>
>> >>>> #include <stdlib.h>
>> >>>> #include <string.h>
>> >>>> #include <sys/ioctl.h>
>> >>>> #include <sys/mount.h>
>> >>>> #include <sys/prctl.h>
>> >>>> #include <sys/resource.h>
>> >>>> #include <sys/socket.h>
>> >>>> #include <sys/stat.h>
>> >>>> #include <sys/syscall.h>
>> >>>> #include <sys/time.h>
>> >>>> #include <sys/types.h>
>> >>>> #include <sys/uio.h>
>> >>>> #include <sys/wait.h>
>> >>>> #include <time.h>
>> >>>> #include <unistd.h>
>> >>>>
>> >>>> #include <linux/if_addr.h>
>> >>>> #include <linux/if_ether.h>
>> >>>> #include <linux/if_link.h>
>> >>>> #include <linux/if_tun.h>
>> >>>> #include <linux/in6.h>
>> >>>> #include <linux/ip.h>
>> >>>> #include <linux/neighbour.h>
>> >>>> #include <linux/net.h>
>> >>>> #include <linux/netlink.h>
>> >>>> #include <linux/rtnetlink.h>
>> >>>> #include <linux/tcp.h>
>> >>>> #include <linux/veth.h>
>> >>>>
>> >>>> unsigned long long procid;
>> >>>>
>> >>>> static void sleep_ms(uint64_t ms)
>> >>>> {
>> >>>>   usleep(ms * 1000);
>> >>>> }
>> >>>>
>> >>>> static uint64_t current_time_ms(void)
>> >>>> {
>> >>>>   struct timespec ts;
>> >>>>   if (clock_gettime(CLOCK_MONOTONIC, &ts))
>> >>>>     exit(1);
>> >>>>   return (uint64_t)ts.tv_sec * 1000 + (uint64_t)ts.tv_nsec / 1000000;
>> >>>> }
>> >>>>
>> >>>> static void use_temporary_dir(void)
>> >>>> {
>> >>>>   char tmpdir_template[] = "./syzkaller.XXXXXX";
>> >>>>   char* tmpdir = mkdtemp(tmpdir_template);
>> >>>>   if (!tmpdir)
>> >>>>     exit(1);
>> >>>>   if (chmod(tmpdir, 0777))
>> >>>>     exit(1);
>> >>>>   if (chdir(tmpdir))
>> >>>>     exit(1);
>> >>>> }
>> >>>>
>> >>>> static bool write_file(const char* file, const char* what, ...)
>> >>>> {
>> >>>>   char buf[1024];
>> >>>>   va_list args;
>> >>>>   va_start(args, what);
>> >>>>   vsnprintf(buf, sizeof(buf), what, args);
>> >>>>   va_end(args);
>> >>>>   buf[sizeof(buf) - 1] = 0;
>> >>>>   int len = strlen(buf);
>> >>>>   int fd = open(file, O_WRONLY | O_CLOEXEC);
>> >>>>   if (fd == -1)
>> >>>>     return false;
>> >>>>   if (write(fd, buf, len) != len) {
>> >>>>     int err = errno;
>> >>>>     close(fd);
>> >>>>     errno = err;
>> >>>>     return false;
>> >>>>   }
>> >>>>   close(fd);
>> >>>>   return true;
>> >>>> }
>> >>>>
>> >>>> static struct {
>> >>>>   char* pos;
>> >>>>   int nesting;
>> >>>>   struct nlattr* nested[8];
>> >>>>   char buf[1024];
>> >>>> } nlmsg;
>> >>>>
>> >>>> static void netlink_init(int typ, int flags, const void* data, int size)
>> >>>> {
>> >>>>   memset(&nlmsg, 0, sizeof(nlmsg));
>> >>>>   struct nlmsghdr* hdr = (struct nlmsghdr*)nlmsg.buf;
>> >>>>   hdr->nlmsg_type = typ;
>> >>>>   hdr->nlmsg_flags = NLM_F_REQUEST | NLM_F_ACK | flags;
>> >>>>   memcpy(hdr + 1, data, size);
>> >>>>   nlmsg.pos = (char*)(hdr + 1) + NLMSG_ALIGN(size);
>> >>>> }
>> >>>>
>> >>>> static void netlink_attr(int typ, const void* data, int size)
>> >>>> {
>> >>>>   struct nlattr* attr = (struct nlattr*)nlmsg.pos;
>> >>>>   attr->nla_len = sizeof(*attr) + size;
>> >>>>   attr->nla_type = typ;
>> >>>>   memcpy(attr + 1, data, size);
>> >>>>   nlmsg.pos += NLMSG_ALIGN(attr->nla_len);
>> >>>> }
>> >>>>
>> >>>> static void netlink_nest(int typ)
>> >>>> {
>> >>>>   struct nlattr* attr = (struct nlattr*)nlmsg.pos;
>> >>>>   attr->nla_type = typ;
>> >>>>   nlmsg.pos += sizeof(*attr);
>> >>>>   nlmsg.nested[nlmsg.nesting++] = attr;
>> >>>> }
>> >>>>
>> >>>> static void netlink_done(void)
>> >>>> {
>> >>>>   struct nlattr* attr = nlmsg.nested[--nlmsg.nesting];
>> >>>>   attr->nla_len = nlmsg.pos - (char*)attr;
>> >>>> }
>> >>>>
>> >>>> static int netlink_send(int sock)
>> >>>> {
>> >>>>   if (nlmsg.pos > nlmsg.buf + sizeof(nlmsg.buf) || nlmsg.nesting)
>> >>>>     exit(1);
>> >>>>   struct nlmsghdr* hdr = (struct nlmsghdr*)nlmsg.buf;
>> >>>>   hdr->nlmsg_len = nlmsg.pos - nlmsg.buf;
>> >>>>   struct sockaddr_nl addr;
>> >>>>   memset(&addr, 0, sizeof(addr));
>> >>>>   addr.nl_family = AF_NETLINK;
>> >>>>   unsigned n = sendto(sock, nlmsg.buf, hdr->nlmsg_len, 0,
>> >>>>                       (struct sockaddr*)&addr, sizeof(addr));
>> >>>>   if (n != hdr->nlmsg_len)
>> >>>>     exit(1);
>> >>>>   n = recv(sock, nlmsg.buf, sizeof(nlmsg.buf), 0);
>> >>>>   if (n < sizeof(struct nlmsghdr) + sizeof(struct nlmsgerr))
>> >>>>     exit(1);
>> >>>>   if (hdr->nlmsg_type != NLMSG_ERROR)
>> >>>>     exit(1);
>> >>>>   return -((struct nlmsgerr*)(hdr + 1))->error;
>> >>>> }
>> >>>>
>> >>>> static void netlink_add_device_impl(const char* type, const char* name)
>> >>>> {
>> >>>>   struct ifinfomsg hdr;
>> >>>>   memset(&hdr, 0, sizeof(hdr));
>> >>>>   netlink_init(RTM_NEWLINK, NLM_F_EXCL | NLM_F_CREATE, &hdr, sizeof(hdr));
>> >>>>   if (name)
>> >>>>     netlink_attr(IFLA_IFNAME, name, strlen(name));
>> >>>>   netlink_nest(IFLA_LINKINFO);
>> >>>>   netlink_attr(IFLA_INFO_KIND, type, strlen(type));
>> >>>> }
>> >>>>
>> >>>> static void netlink_add_device(int sock, const char* type, const char* name)
>> >>>> {
>> >>>>   netlink_add_device_impl(type, name);
>> >>>>   netlink_done();
>> >>>>   int err = netlink_send(sock);
>> >>>>   (void)err;
>> >>>> }
>> >>>>
>> >>>> static void netlink_add_veth(int sock, const char* name, const char* peer)
>> >>>> {
>> >>>>   netlink_add_device_impl("veth", name);
>> >>>>   netlink_nest(IFLA_INFO_DATA);
>> >>>>   netlink_nest(VETH_INFO_PEER);
>> >>>>   nlmsg.pos += sizeof(struct ifinfomsg);
>> >>>>   netlink_attr(IFLA_IFNAME, peer, strlen(peer));
>> >>>>   netlink_done();
>> >>>>   netlink_done();
>> >>>>   netlink_done();
>> >>>>   int err = netlink_send(sock);
>> >>>>   (void)err;
>> >>>> }
>> >>>>
>> >>>> static void netlink_add_hsr(int sock, const char* name, const char* slave1,
>> >>>>                             const char* slave2)
>> >>>> {
>> >>>>   netlink_add_device_impl("hsr", name);
>> >>>>   netlink_nest(IFLA_INFO_DATA);
>> >>>>   int ifindex1 = if_nametoindex(slave1);
>> >>>>   netlink_attr(IFLA_HSR_SLAVE1, &ifindex1, sizeof(ifindex1));
>> >>>>   int ifindex2 = if_nametoindex(slave2);
>> >>>>   netlink_attr(IFLA_HSR_SLAVE2, &ifindex2, sizeof(ifindex2));
>> >>>>   netlink_done();
>> >>>>   netlink_done();
>> >>>>   int err = netlink_send(sock);
>> >>>>   (void)err;
>> >>>> }
>> >>>>
>> >>>> static void netlink_device_change(int sock, const char* name, bool up,
>> >>>>                                   const char* master, const void* mac,
>> >>>>                                   int macsize)
>> >>>> {
>> >>>>   struct ifinfomsg hdr;
>> >>>>   memset(&hdr, 0, sizeof(hdr));
>> >>>>   if (up)
>> >>>>     hdr.ifi_flags = hdr.ifi_change = IFF_UP;
>> >>>>   netlink_init(RTM_NEWLINK, 0, &hdr, sizeof(hdr));
>> >>>>   netlink_attr(IFLA_IFNAME, name, strlen(name));
>> >>>>   if (master) {
>> >>>>     int ifindex = if_nametoindex(master);
>> >>>>     netlink_attr(IFLA_MASTER, &ifindex, sizeof(ifindex));
>> >>>>   }
>> >>>>   if (macsize)
>> >>>>     netlink_attr(IFLA_ADDRESS, mac, macsize);
>> >>>>   int err = netlink_send(sock);
>> >>>>   (void)err;
>> >>>> }
>> >>>>
>> >>>> static int netlink_add_addr(int sock, const char* dev, const void* addr,
>> >>>>                             int addrsize)
>> >>>> {
>> >>>>   struct ifaddrmsg hdr;
>> >>>>   memset(&hdr, 0, sizeof(hdr));
>> >>>>   hdr.ifa_family = addrsize == 4 ? AF_INET : AF_INET6;
>> >>>>   hdr.ifa_prefixlen = addrsize == 4 ? 24 : 120;
>> >>>>   hdr.ifa_scope = RT_SCOPE_UNIVERSE;
>> >>>>   hdr.ifa_index = if_nametoindex(dev);
>> >>>>   netlink_init(RTM_NEWADDR, NLM_F_CREATE | NLM_F_REPLACE, &hdr,
>> >>>> sizeof(hdr));
>> >>>>   netlink_attr(IFA_LOCAL, addr, addrsize);
>> >>>>   netlink_attr(IFA_ADDRESS, addr, addrsize);
>> >>>>   return netlink_send(sock);
>> >>>> }
>> >>>>
>> >>>> static void netlink_add_addr4(int sock, const char* dev, const char* addr)
>> >>>> {
>> >>>>   struct in_addr in_addr;
>> >>>>   inet_pton(AF_INET, addr, &in_addr);
>> >>>>   int err = netlink_add_addr(sock, dev, &in_addr, sizeof(in_addr));
>> >>>>   (void)err;
>> >>>> }
>> >>>>
>> >>>> static void netlink_add_addr6(int sock, const char* dev, const char* addr)
>> >>>> {
>> >>>>   struct in6_addr in6_addr;
>> >>>>   inet_pton(AF_INET6, addr, &in6_addr);
>> >>>>   int err = netlink_add_addr(sock, dev, &in6_addr, sizeof(in6_addr));
>> >>>>   (void)err;
>> >>>> }
>> >>>>
>> >>>> #define DEV_IPV4 "172.20.20.%d"
>> >>>> #define DEV_IPV6 "fe80::%02hx"
>> >>>> #define DEV_MAC 0x00aaaaaaaaaa
>> >>>> static void initialize_netdevices(void)
>> >>>> {
>> >>>>   char netdevsim[16];
>> >>>>   sprintf(netdevsim, "netdevsim%d", (int)procid);
>> >>>>   struct {
>> >>>>     const char* type;
>> >>>>     const char* dev;
>> >>>>   } devtypes[] = {
>> >>>>       {"ip6gretap", "ip6gretap0"}, {"bridge", "bridge0"},
>> >>>>       {"vcan", "vcan0"},           {"bond", "bond0"},
>> >>>>       {"team", "team0"},           {"dummy", "dummy0"},
>> >>>>       {"nlmon", "nlmon0"},         {"caif", "caif0"},
>> >>>>       {"batadv", "batadv0"},       {"vxcan", "vxcan1"},
>> >>>>       {"netdevsim", netdevsim},    {"veth", 0},
>> >>>>   };
>> >>>>   const char* devmasters[] = {"bridge", "bond", "team"};
>> >>>>   struct {
>> >>>>     const char* name;
>> >>>>     int macsize;
>> >>>>     bool noipv6;
>> >>>>   } devices[] = {
>> >>>>       {"lo", ETH_ALEN},
>> >>>>       {"sit0", 0},
>> >>>>       {"bridge0", ETH_ALEN},
>> >>>>       {"vcan0", 0, true},
>> >>>>       {"tunl0", 0},
>> >>>>       {"gre0", 0},
>> >>>>       {"gretap0", ETH_ALEN},
>> >>>>       {"ip_vti0", 0},
>> >>>>       {"ip6_vti0", 0},
>> >>>>       {"ip6tnl0", 0},
>> >>>>       {"ip6gre0", 0},
>> >>>>       {"ip6gretap0", ETH_ALEN},
>> >>>>       {"erspan0", ETH_ALEN},
>> >>>>       {"bond0", ETH_ALEN},
>> >>>>       {"veth0", ETH_ALEN},
>> >>>>       {"veth1", ETH_ALEN},
>> >>>>       {"team0", ETH_ALEN},
>> >>>>       {"veth0_to_bridge", ETH_ALEN},
>> >>>>       {"veth1_to_bridge", ETH_ALEN},
>> >>>>       {"veth0_to_bond", ETH_ALEN},
>> >>>>       {"veth1_to_bond", ETH_ALEN},
>> >>>>       {"veth0_to_team", ETH_ALEN},
>> >>>>       {"veth1_to_team", ETH_ALEN},
>> >>>>       {"veth0_to_hsr", ETH_ALEN},
>> >>>>       {"veth1_to_hsr", ETH_ALEN},
>> >>>>       {"hsr0", 0},
>> >>>>       {"dummy0", ETH_ALEN},
>> >>>>       {"nlmon0", 0},
>> >>>>       {"vxcan1", 0, true},
>> >>>>       {"caif0", ETH_ALEN},
>> >>>>       {"batadv0", ETH_ALEN},
>> >>>>       {netdevsim, ETH_ALEN},
>> >>>>   };
>> >>>>   int sock = socket(AF_NETLINK, SOCK_RAW, NETLINK_ROUTE);
>> >>>>   if (sock == -1)
>> >>>>     exit(1);
>> >>>>   unsigned i;
>> >>>>   for (i = 0; i < sizeof(devtypes) / sizeof(devtypes[0]); i++)
>> >>>>     netlink_add_device(sock, devtypes[i].type, devtypes[i].dev);
>> >>>>   for (i = 0; i < sizeof(devmasters) / (sizeof(devmasters[0])); i++) {
>> >>>>     char master[32], slave0[32], veth0[32], slave1[32], veth1[32];
>> >>>>     sprintf(slave0, "%s_slave_0", devmasters[i]);
>> >>>>     sprintf(veth0, "veth0_to_%s", devmasters[i]);
>> >>>>     netlink_add_veth(sock, slave0, veth0);
>> >>>>     sprintf(slave1, "%s_slave_1", devmasters[i]);
>> >>>>     sprintf(veth1, "veth1_to_%s", devmasters[i]);
>> >>>>     netlink_add_veth(sock, slave1, veth1);
>> >>>>     sprintf(master, "%s0", devmasters[i]);
>> >>>>     netlink_device_change(sock, slave0, false, master, 0, 0);
>> >>>>     netlink_device_change(sock, slave1, false, master, 0, 0);
>> >>>>   }
>> >>>>   netlink_device_change(sock, "bridge_slave_0", true, 0, 0, 0);
>> >>>>   netlink_device_change(sock, "bridge_slave_1", true, 0, 0, 0);
>> >>>>   netlink_add_veth(sock, "hsr_slave_0", "veth0_to_hsr");
>> >>>>   netlink_add_veth(sock, "hsr_slave_1", "veth1_to_hsr");
>> >>>>   netlink_add_hsr(sock, "hsr0", "hsr_slave_0", "hsr_slave_1");
>> >>>>   netlink_device_change(sock, "hsr_slave_0", true, 0, 0, 0);
>> >>>>   netlink_device_change(sock, "hsr_slave_1", true, 0, 0, 0);
>> >>>>   for (i = 0; i < sizeof(devices) / (sizeof(devices[0])); i++) {
>> >>>>     char addr[32];
>> >>>>     sprintf(addr, DEV_IPV4, i + 10);
>> >>>>     netlink_add_addr4(sock, devices[i].name, addr);
>> >>>>     if (!devices[i].noipv6) {
>> >>>>       sprintf(addr, DEV_IPV6, i + 10);
>> >>>>       netlink_add_addr6(sock, devices[i].name, addr);
>> >>>>     }
>> >>>>     uint64_t macaddr = DEV_MAC + ((i + 10ull) << 40);
>> >>>>     netlink_device_change(sock, devices[i].name, true, 0, &macaddr,
>> >>>>                           devices[i].macsize);
>> >>>>   }
>> >>>>   close(sock);
>> >>>> }
>> >>>> static void initialize_netdevices_init(void)
>> >>>> {
>> >>>>   int sock = socket(AF_NETLINK, SOCK_RAW, NETLINK_ROUTE);
>> >>>>   if (sock == -1)
>> >>>>     exit(1);
>> >>>>   struct {
>> >>>>     const char* type;
>> >>>>     int macsize;
>> >>>>     bool noipv6;
>> >>>>     bool noup;
>> >>>>   } devtypes[] = {
>> >>>>       {"nr", 7, true}, {"rose", 5, true, true},
>> >>>>   };
>> >>>>   unsigned i;
>> >>>>   for (i = 0; i < sizeof(devtypes) / sizeof(devtypes[0]); i++) {
>> >>>>     char dev[32], addr[32];
>> >>>>     sprintf(dev, "%s%d", devtypes[i].type, (int)procid);
>> >>>>     sprintf(addr, "172.30.%d.%d", i, (int)procid + 1);
>> >>>>     netlink_add_addr4(sock, dev, addr);
>> >>>>     if (!devtypes[i].noipv6) {
>> >>>>       sprintf(addr, "fe88::%02hx:%02hx", i, (int)procid + 1);
>> >>>>       netlink_add_addr6(sock, dev, addr);
>> >>>>     }
>> >>>>     int macsize = devtypes[i].macsize;
>> >>>>     uint64_t macaddr = 0xbbbbbb +
>> >>>>                        ((unsigned long long)i << (8 * (macsize - 2))) +
>> >>>>                        (procid << (8 * (macsize - 1)));
>> >>>>     netlink_device_change(sock, dev, !devtypes[i].noup, 0, &macaddr,
>> >>>> macsize);
>> >>>>   }
>> >>>>   close(sock);
>> >>>> }
>> >>>>
>> >>>> static void setup_common()
>> >>>> {
>> >>>>   if (mount(0, "/sys/fs/fuse/connections", "fusectl", 0, 0)) {
>> >>>>   }
>> >>>> }
>> >>>>
>> >>>> static void loop();
>> >>>>
>> >>>> static void sandbox_common()
>> >>>> {
>> >>>>   prctl(PR_SET_PDEATHSIG, SIGKILL, 0, 0, 0);
>> >>>>   setpgrp();
>> >>>>   setsid();
>> >>>>   struct rlimit rlim;
>> >>>>   rlim.rlim_cur = rlim.rlim_max = 200 << 20;
>> >>>>   setrlimit(RLIMIT_AS, &rlim);
>> >>>>   rlim.rlim_cur = rlim.rlim_max = 32 << 20;
>> >>>>   setrlimit(RLIMIT_MEMLOCK, &rlim);
>> >>>>   rlim.rlim_cur = rlim.rlim_max = 136 << 20;
>> >>>>   setrlimit(RLIMIT_FSIZE, &rlim);
>> >>>>   rlim.rlim_cur = rlim.rlim_max = 1 << 20;
>> >>>>   setrlimit(RLIMIT_STACK, &rlim);
>> >>>>   rlim.rlim_cur = rlim.rlim_max = 0;
>> >>>>   setrlimit(RLIMIT_CORE, &rlim);
>> >>>>   rlim.rlim_cur = rlim.rlim_max = 256;
>> >>>>   setrlimit(RLIMIT_NOFILE, &rlim);
>> >>>>   if (unshare(CLONE_NEWNS)) {
>> >>>>   }
>> >>>>   if (unshare(CLONE_NEWIPC)) {
>> >>>>   }
>> >>>>   if (unshare(0x02000000)) {
>> >>>>   }
>> >>>>   if (unshare(CLONE_NEWUTS)) {
>> >>>>   }
>> >>>>   if (unshare(CLONE_SYSVSEM)) {
>> >>>>   }
>> >>>>   typedef struct {
>> >>>>     const char* name;
>> >>>>     const char* value;
>> >>>>   } sysctl_t;
>> >>>>   static const sysctl_t sysctls[] = {
>> >>>>       {"/proc/sys/kernel/shmmax", "16777216"},
>> >>>>       {"/proc/sys/kernel/shmall", "536870912"},
>> >>>>       {"/proc/sys/kernel/shmmni", "1024"},
>> >>>>       {"/proc/sys/kernel/msgmax", "8192"},
>> >>>>       {"/proc/sys/kernel/msgmni", "1024"},
>> >>>>       {"/proc/sys/kernel/msgmnb", "1024"},
>> >>>>       {"/proc/sys/kernel/sem", "1024 1048576 500 1024"},
>> >>>>   };
>> >>>>   unsigned i;
>> >>>>   for (i = 0; i < sizeof(sysctls) / sizeof(sysctls[0]); i++)
>> >>>>     write_file(sysctls[i].name, sysctls[i].value);
>> >>>> }
>> >>>>
>> >>>> int wait_for_loop(int pid)
>> >>>> {
>> >>>>   if (pid < 0)
>> >>>>     exit(1);
>> >>>>   int status = 0;
>> >>>>   while (waitpid(-1, &status, __WALL) != pid) {
>> >>>>   }
>> >>>>   return WEXITSTATUS(status);
>> >>>> }
>> >>>>
>> >>>> static int do_sandbox_none(void)
>> >>>> {
>> >>>>   if (unshare(CLONE_NEWPID)) {
>> >>>>   }
>> >>>>   int pid = fork();
>> >>>>   if (pid != 0)
>> >>>>     return wait_for_loop(pid);
>> >>>>   setup_common();
>> >>>>   sandbox_common();
>> >>>>   initialize_netdevices_init();
>> >>>>   if (unshare(CLONE_NEWNET)) {
>> >>>>   }
>> >>>>   initialize_netdevices();
>> >>>>   loop();
>> >>>>   exit(1);
>> >>>> }
>> >>>>
>> >>>> #define FS_IOC_SETFLAGS _IOW('f', 2, long)
>> >>>> static void remove_dir(const char* dir)
>> >>>> {
>> >>>>   DIR* dp;
>> >>>>   struct dirent* ep;
>> >>>>   int iter = 0;
>> >>>> retry:
>> >>>>   while (umount2(dir, MNT_DETACH) == 0) {
>> >>>>   }
>> >>>>   dp = opendir(dir);
>> >>>>   if (dp == NULL) {
>> >>>>     if (errno == EMFILE) {
>> >>>>       exit(1);
>> >>>>     }
>> >>>>     exit(1);
>> >>>>   }
>> >>>>   while ((ep = readdir(dp))) {
>> >>>>     if (strcmp(ep->d_name, ".") == 0 || strcmp(ep->d_name, "..") == 0)
>> >>>>       continue;
>> >>>>     char filename[FILENAME_MAX];
>> >>>>     snprintf(filename, sizeof(filename), "%s/%s", dir, ep->d_name);
>> >>>>     while (umount2(filename, MNT_DETACH) == 0) {
>> >>>>     }
>> >>>>     struct stat st;
>> >>>>     if (lstat(filename, &st))
>> >>>>       exit(1);
>> >>>>     if (S_ISDIR(st.st_mode)) {
>> >>>>       remove_dir(filename);
>> >>>>       continue;
>> >>>>     }
>> >>>>     int i;
>> >>>>     for (i = 0;; i++) {
>> >>>>       if (unlink(filename) == 0)
>> >>>>         break;
>> >>>>       if (errno == EPERM) {
>> >>>>         int fd = open(filename, O_RDONLY);
>> >>>>         if (fd != -1) {
>> >>>>           long flags = 0;
>> >>>>           if (ioctl(fd, FS_IOC_SETFLAGS, &flags) == 0)
>> >>>>             close(fd);
>> >>>>           continue;
>> >>>>         }
>> >>>>       }
>> >>>>       if (errno == EROFS) {
>> >>>>         break;
>> >>>>       }
>> >>>>       if (errno != EBUSY || i > 100)
>> >>>>         exit(1);
>> >>>>       if (umount2(filename, MNT_DETACH))
>> >>>>         exit(1);
>> >>>>     }
>> >>>>   }
>> >>>>   closedir(dp);
>> >>>>   int i;
>> >>>>   for (i = 0;; i++) {
>> >>>>     if (rmdir(dir) == 0)
>> >>>>       break;
>> >>>>     if (i < 100) {
>> >>>>       if (errno == EPERM) {
>> >>>>         int fd = open(dir, O_RDONLY);
>> >>>>         if (fd != -1) {
>> >>>>           long flags = 0;
>> >>>>           if (ioctl(fd, FS_IOC_SETFLAGS, &flags) == 0)
>> >>>>             close(fd);
>> >>>>           continue;
>> >>>>         }
>> >>>>       }
>> >>>>       if (errno == EROFS) {
>> >>>>         break;
>> >>>>       }
>> >>>>       if (errno == EBUSY) {
>> >>>>         if (umount2(dir, MNT_DETACH))
>> >>>>           exit(1);
>> >>>>         continue;
>> >>>>       }
>> >>>>       if (errno == ENOTEMPTY) {
>> >>>>         if (iter < 100) {
>> >>>>           iter++;
>> >>>>           goto retry;
>> >>>>         }
>> >>>>       }
>> >>>>     }
>> >>>>     exit(1);
>> >>>>   }
>> >>>> }
>> >>>>
>> >>>> static void kill_and_wait(int pid, int* status)
>> >>>> {
>> >>>>   kill(-pid, SIGKILL);
>> >>>>   kill(pid, SIGKILL);
>> >>>>   int i;
>> >>>>   for (i = 0; i < 100; i++) {
>> >>>>     if (waitpid(-1, status, WNOHANG | __WALL) == pid)
>> >>>>       return;
>> >>>>     usleep(1000);
>> >>>>   }
>> >>>>   DIR* dir = opendir("/sys/fs/fuse/connections");
>> >>>>   if (dir) {
>> >>>>     for (;;) {
>> >>>>       struct dirent* ent = readdir(dir);
>> >>>>       if (!ent)
>> >>>>         break;
>> >>>>       if (strcmp(ent->d_name, ".") == 0 || strcmp(ent->d_name, "..") == 0)
>> >>>>         continue;
>> >>>>       char abort[300];
>> >>>>       snprintf(abort, sizeof(abort), "/sys/fs/fuse/connections/%s/abort",
>> >>>>                ent->d_name);
>> >>>>       int fd = open(abort, O_WRONLY);
>> >>>>       if (fd == -1) {
>> >>>>         continue;
>> >>>>       }
>> >>>>       if (write(fd, abort, 1) < 0) {
>> >>>>       }
>> >>>>       close(fd);
>> >>>>     }
>> >>>>     closedir(dir);
>> >>>>   } else {
>> >>>>   }
>> >>>>   while (waitpid(-1, status, __WALL) != pid) {
>> >>>>   }
>> >>>> }
>> >>>>
>> >>>> #define SYZ_HAVE_SETUP_TEST 1
>> >>>> static void setup_test()
>> >>>> {
>> >>>>   prctl(PR_SET_PDEATHSIG, SIGKILL, 0, 0, 0);
>> >>>>   setpgrp();
>> >>>> }
>> >>>>
>> >>>> #define SYZ_HAVE_RESET_TEST 1
>> >>>> static void reset_test()
>> >>>> {
>> >>>>   int fd;
>> >>>>   for (fd = 3; fd < 30; fd++)
>> >>>>     close(fd);
>> >>>> }
>> >>>>
>> >>>> static void execute_one(void);
>> >>>>
>> >>>> #define WAIT_FLAGS __WALL
>> >>>>
>> >>>> static void loop(void)
>> >>>> {
>> >>>>   int iter;
>> >>>>   for (iter = 0;; iter++) {
>> >>>>     char cwdbuf[32];
>> >>>>     sprintf(cwdbuf, "./%d", iter);
>> >>>>     if (mkdir(cwdbuf, 0777))
>> >>>>       exit(1);
>> >>>>     int pid = fork();
>> >>>>     if (pid < 0)
>> >>>>       exit(1);
>> >>>>     if (pid == 0) {
>> >>>>       if (chdir(cwdbuf))
>> >>>>         exit(1);
>> >>>>       setup_test();
>> >>>>       execute_one();
>> >>>>       reset_test();
>> >>>>       exit(0);
>> >>>>     }
>> >>>>     int status = 0;
>> >>>>     uint64_t start = current_time_ms();
>> >>>>     for (;;) {
>> >>>>       if (waitpid(-1, &status, WNOHANG | WAIT_FLAGS) == pid)
>> >>>>         break;
>> >>>>       sleep_ms(1);
>> >>>>       if (current_time_ms() - start < 5 * 1000)
>> >>>>         continue;
>> >>>>       kill_and_wait(pid, &status);
>> >>>>       break;
>> >>>>     }
>> >>>>     remove_dir(cwdbuf);
>> >>>>   }
>> >>>> }
>> >>>>
>> >>>> void execute_one(void)
>> >>>> {
>> >>>>   syscall(__NR_unshare, 0x40000000);
>> >>>> }
>> >>>> int main(void)
>> >>>> {
>> >>>>   syscall(__NR_mmap, 0x20000000, 0x1000000, 3, 0x32, -1, 0);
>> >>>>   for (procid = 0; procid < 8; procid++) {
>> >>>>     if (fork() == 0) {
>> >>>>       use_temporary_dir();
>> >>>>       do_sandbox_none();
>> >>>>     }
>> >>>>   }
>> >>>>   sleep(1000000);
>> >>>>   return 0;
>> >>>> }
>> >>>>
>> >>>>
>> >>>> I reviewed kernel code and found a bug that
>> >>>> net_drop_ns func doesn't call net_free func when refcount_dec_and_test's
>> >>>> return value is zero.
>> >>> Yes.  We don't call net_free when the reference count does not decrement
>> >>> to zero.  The reference count is initialized to 1 a few lines above the
>> >>> section of code in your patch so that should not be a problem.
>> >>>
>> >>>> or
>> >>>> when rv = down_read_killable(&pernet_ops_rwsem) < 0, it doesn't need to
>> >>>> call refcount_dec_and_test.
>> >>> It doesn't need to but it should be harmless.
>> >>>
>> >>>> https://github.com/torvalds/linux/commit/5ba049a5cc8e24a1643df75bbf65b4efa070fa74#diff-9312644e2968a45510bacdd2b2872ad2
>> >>>> (I can't reproduce this bug on v4.15 , and
>> >>>> 1bdbe227492075d058e37cb3d400e6468d0095b5 with my patch. Because of the
>> >>>> previous version of kernel doesn't have this bug.)
>> >>>> This bug can lead to memory leak or DOS.
>> >>>>
>> >>>> I made a patch for this bug. (just revert to a before commit)
>> >>> What am I missing?
>> >>>
>> >>> The only thing I can see your patch doing is covering up a memory stomp
>> >>> that has the effect of changing the value of net->passive.  I am not
>> >>> really keen on hiding bugs of that kind.
>> >>>
>> >>>
>> >>>> diff --git a/net/core/net_namespace.c b/net/core/net_namespace.c
>> >>>> index b02fb19df2cc..9de0ade14956 100644
>> >>>> --- a/net/core/net_namespace.c
>> >>>> +++ b/net/core/net_namespace.c
>> >>>> @@ -431,15 +431,18 @@ struct net *copy_net_ns(unsigned long flags,
>> >>>>         get_user_ns(user_ns);
>> >>>>
>> >>>>         rv = down_read_killable(&pernet_ops_rwsem);
>> >>>> -       if (rv < 0)
>> >>>> -               goto put_userns;
>> >>>> +       if (rv < 0){
>> >>>> +        net_free(net);
>> >>>> +        dec_net_namespaces(ucounts);
>> >>>> +        put_user_ns(user_ns);
>> >>>> +        return ERR_PTR(rv);
>> >>>> +    }
>> >>>>
>> >>>>         rv = setup_net(net, user_ns);
>> >>>>
>> >>>>         up_read(&pernet_ops_rwsem);
>> >>>>
>> >>>>         if (rv < 0) {
>> >>>> -put_userns:
>> >>>>                 put_user_ns(user_ns);
>> >>>>                 net_drop_ns(net);
>> >>>>  dec_ucounts:
>> >>>>
>> >>>> and, sorry for my encrypted mails.
>> >>> Eric
>> >>>
>
> --
> You received this message because you are subscribed to the Google Groups "syzkaller" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to syzkaller+unsubscribe@googlegroups.com.
> For more options, visit https://groups.google.com/d/optout.
Eric W. Biederman Jan. 14, 2019, 6:12 p.m. | #6
Dmitry Vyukov <dvyukov@google.com> writes:

> This looks superciliously similar to:
> https://groups.google.com/d/msg/syzkaller-bugs/nFeC8-UG1gg/B6GFaZFrFQAJ
>
> The crux: for the last ~half a year low memory conditions randomly
> corrupt kernel memory with stack overflows.

Does enabling virtually mapped stacks catch those problems?

Eric
Eric W. Biederman Jan. 14, 2019, 6:29 p.m. | #7
zzoru <zzoru007@gmail.com> writes:

> I think that it is exactly same to:
> https://groups.google.com/forum/#!searchin/linux.kernel/cleanup_net$20is$20slow%7Csort:date/linux.kernel/IMJ9OzonDSI/QH86oy1PAQAJ
> Already, patch was maded, but maybe he forgot to push it.

That patch was made to address speed, and lifetime of network stack
objects.  At best it will make things go faster (a good thing), and
reduce the memory consumption during a test (another good thing).
The patch you point to will not correct your memory corruption.

So right now the best hypothesis seems to be Dmitriy's idea that
there is stack overflow causing corruption. You have a lot of stack
debugging already enabled but I don't see CONFIG_VMAP_STACK enabled
which might catch something ordinary stack overflow checking won't.

Any chance you can enable CONFIG_VMAP_STACK and see if it is stack
overflow?

With a little luck you will catch the stack overflow in the act and we
can see the problematic code path.

Eric
Dmitry Vyukov Jan. 15, 2019, 10:36 a.m. | #8
On Mon, Jan 14, 2019 at 7:30 PM Eric W. Biederman <ebiederm@xmission.com> wrote:
>
> zzoru <zzoru007@gmail.com> writes:
>
> > I think that it is exactly same to:
> > https://groups.google.com/forum/#!searchin/linux.kernel/cleanup_net$20is$20slow%7Csort:date/linux.kernel/IMJ9OzonDSI/QH86oy1PAQAJ
> > Already, patch was maded, but maybe he forgot to push it.
>
> That patch was made to address speed, and lifetime of network stack
> objects.  At best it will make things go faster (a good thing), and
> reduce the memory consumption during a test (another good thing).
> The patch you point to will not correct your memory corruption.
>
> So right now the best hypothesis seems to be Dmitriy's idea that
> there is stack overflow causing corruption. You have a lot of stack
> debugging already enabled but I don't see CONFIG_VMAP_STACK enabled
> which might catch something ordinary stack overflow checking won't.
>
> Any chance you can enable CONFIG_VMAP_STACK and see if it is stack
> overflow?
>
> With a little luck you will catch the stack overflow in the act and we
> can see the problematic code path.

Most likely the stack overflow should be detectable with
CONFIG_VMAP_STACK. But CONFIG_VMAP_STACK is incompatible with KASAN:
https://bugzilla.kernel.org/show_bug.cgi?id=202009

I reproduced the other stack overflow without KASAN and without
CONFIG_VMAP_STACK and it was detected as "corrupted stack end
detected inside scheduler". We can try the same here. But without
KASAN and with CONFIG_VMAP_STACK should be more reliable.

But how I read it is if we see wb_workfn in stacks, kernel memory is
corrupted. Overflow at that async stack is not dependent on how
exactly low memory condition was provoked.

Patch

diff --git a/net/core/net_namespace.c b/net/core/net_namespace.c
index b02fb19df2cc..9de0ade14956 100644
--- a/net/core/net_namespace.c
+++ b/net/core/net_namespace.c
@@ -431,15 +431,18 @@  struct net *copy_net_ns(unsigned long flags,
        get_user_ns(user_ns);

        rv = down_read_killable(&pernet_ops_rwsem);
-       if (rv < 0)
-               goto put_userns;
+       if (rv < 0){
+        net_free(net);
+        dec_net_namespaces(ucounts);
+        put_user_ns(user_ns);
+        return ERR_PTR(rv);
+    }

        rv = setup_net(net, user_ns);

        up_read(&pernet_ops_rwsem);

        if (rv < 0) {
-put_userns:
                put_user_ns(user_ns);
                net_drop_ns(net);
 dec_ucounts: