Been trying to track this bug down. The original mitigation did not
work. Instead, I'm mitigating by setting
kernel.apparmor_cache_timeout=0.

With AppArmor prompting enabled, notify.c arms a 5-second reclaim timer
on an audit-cache node without checking whether the node was actually
inserted into the cache. When an equivalent entry already exists the
node is not inserted, nothing holds a reference to it, and it is freed
via call_rcu() as soon as the requesting syscall returns — timer still
armed. The stale timer fires into freed memory; slot reuse then links
the same timer_list into two wheel buckets, and detach_timer() faults on
LIST_POISON2.

Steps to reproduce

    Ubuntu 26.04 with prompting on and the prompting-client / desktop-
security-center snaps installed:

    sudo snap set system experimental.apparmor-prompting=true
    sysctl kernel.apparmor_cache_timeout      # 5 (default)

    Log into a desktop session and launch the chromium snap.
    Download several large files — concurrent downloads work best. Answer the 
permission prompts, or leave them standing. Chromium’s download path creates 
and renames files continuously:

    __x64_sys_creat → … → apparmor_path_mknod → aa_audit_file →
check_user

    Each creat() on an un-cached path produces a prompt; each response arms the 
temporal-cache timer.
    Watch the kernel log. Non-fatal WARNs appear within minutes; the panic 
follows within seconds to hours:

    dmesg -w | grep -E 'workqueue.c:2351|dead00000000012a'

    Confirm the owner on any affected system, no rebuild (bpftrace; BTF
is in the Ubuntu kernel):

    sudo bpftrace -e 'kprobe:__queue_work { $w=(struct work_struct*)arg2;
      if ((uint64)$w->entry.next==0) {
        printf("CORRUPT %p func=%s\n", arg2, ksym((uint64)$w->func)); } }'

    CORRUPT 0xffff88bb937d0fc8 func=audit_cache_work_function


I'd imagine something like the following is probably what is needed, but I 
don't have the experience in kernel development to know if I'm missing things 
here.

-               insert_in_cache(knotif);
-               INIT_DELAYED_WORK(&node->work, audit_cache_work_function);
-               schedule_delayed_work(&node->work,
-                                     secs_to_jiffies(aa_cache_timeout));
+               if (insert_in_cache(knotif)) {
+                       INIT_DELAYED_WORK(&node->work, 
audit_cache_work_function);
+                       schedule_delayed_work(&node->work,
+                                             
secs_to_jiffies(aa_cache_timeout));
+               }

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2165930

Title:
  Kernel oops (GPF) in __run_timers via tmigr_handle_remote on
  7.0.0-28-generic under network load

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2165930/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to