When I unplug and replug a usb cable of a ups, nut triggers the following bug in libusb (identified with valgrind): ==2383== Process terminating with default action of signal 11 (SIGSEGV) ==2383== Access not within mapped region at address 0x0 ==2383== at 0x4C2F341: strcmp (in /usr/lib64/valgrind/vgpreload_memcheck-amd64-linux.so) ==2383== by 0x561800B: linux_enumerate_device (linux_usbfs.c:1037) ==2383== by 0x5618CB8: linux_hotplug_enumerate (linux_usbfs.c:1113) ==2383== by 0x561A192: linux_netlink_read_message (linux_netlink.c:322) ==2383== by 0x561A724: linux_netlink_hotplug_poll (linux_netlink.c:366) ==2383== by 0x560D168: libusb_get_device_list (core.c:807) ==2383== by 0x4E383DF: usb_find_busses (in /lib64/libusb-0.1.so.4.4.4) ==2383== by 0x120D55: libusb_open (libusb.c:164) ==2383== by 0x11EE09: upsdrv_updateinfo (usbhid-ups.c:1355) ==2383== by 0x11D016: main (main.c:708) Current kernel is 4.1.6-hardened, but it has been happening for a while, I just haven't been able to get the valgrind output until now. Reproducible: Always Steps to Reproduce: 1. Start usb ups driver 2. Disconnect the usb cable 3. Reconnect the usb cable Portage 2.2.7 (hardened/linux/amd64, gcc-4.8.4, unavailable, 4.1.6-hardened x86_64) ================================================================= System uname: Linux-4.1.6-hardened-x86_64-Intel-R-_Core-TM-_i7-3820_CPU_@_3.60GHz-with-gentoo-2.1 KiB Mem: 65915456 total, 467432 free KiB Swap: 134213628 total, 132726332 free Timestamp of tree: Thu, 08 Oct 2015 13:45:01 +0000 ld GNU ld (Gentoo 2.24 p1.4) 2.24 app-shells/bash: 4.2_p53 dev-java/java-config: 1.3.7, 2.1.12-r1 dev-lang/perl: 5.12.2-r6 dev-lang/python: 2.4.4-r14, 2.5.4-r2, 2.6.8, 2.7.5-r3, 3.2.3-r2, 3.3.3 dev-util/cmake: 2.8.10.2-r2 dev-util/pkgconfig: 0.28-r2 sys-apps/baselayout: 2.1-r1 sys-apps/openrc: 0.11.8 sys-apps/sandbox: 2.6-r1 sys-devel/autoconf: 2.13::<unknown repository>, 2.69 sys-devel/automake: 1.4_p6::<unknown repository>, 1.5::<unknown repository>, 1.6.3::<unknown repository>, 1.7.9-r1::<unknown repository>, 1.8.5-r3::<unknown repository>, 1.9.6-r2::<unknown repository>, 1.10.1, 1.11.1, 1.12.6, 1.13.4, 1.14.1, 1.15 sys-devel/binutils: 2.24-r3 sys-devel/gcc: 3.4.6-r2::<unknown repository>, 4.1.2::<unknown repository>, 4.3.6-r1, 4.5.3-r2, 4.6.3, 4.8.4 sys-devel/gcc-config: 1.7.3 sys-devel/libtool: 2.4.6 sys-devel/make: 3.82-r3 sys-kernel/linux-headers: 3.13 (virtual/os-headers) sys-libs/glibc: 2.20-r2 Repositories: gentoo x-portage ACCEPT_KEYWORDS="amd64" ACCEPT_LICENSE="* -@EULA" CBUILD="x86_64-pc-linux-gnu" CFLAGS="-O2 -mtune=amdfam10 -fomit-frame-pointer -ftree-vectorize -fpredictive-commoning -fno-tree-vect-loop-version" CHOST="x86_64-pc-linux-gnu" CONFIG_PROTECT="/etc /usr/kde/3.5/env /usr/kde/3.5/share/config /usr/kde/3.5/shutdown /usr/share/config /usr/share/gnupg/qualified.txt /usr/share/openvpn/easy-rsa /var/bind" CONFIG_PROTECT_MASK="/etc/ca-certificates.conf /etc/env.d /etc/fonts/fonts.conf /etc/gconf /etc/gentoo-release /etc/php/apache2-php5/ext-active/ /etc/php/cgi-php5/ext-active/ /etc/php/cli-php5/ext-active/ /etc/revdep-rebuild /etc/sandbox.d /etc/terminfo" CXXFLAGS="-O2 -mtune=amdfam10 -fomit-frame-pointer -ftree-vectorize -fpredictive-commoning -fno-tree-vect-loop-version" DISTDIR="/usr/portage/distfiles" FCFLAGS="-O2 -pipe" FEATURES="assume-digests binpkg-logs distlocks ebuild-locks fixlafiles merge-sync news parallel-fetch preserve-libs protect-owned sandbox sfperms strict unknown-features-warn unmerge-logs unmerge-orphans userfetch userpriv usersandbox usersync xattr" FFLAGS="-O2 -pipe" GENTOO_MIRRORS="http://mirror.internode.on.net/pub/gentoo http://mirror.pacific.net.au/linux/Gentoo http://distfiles.gentoo.org http://www..ibiblio.org/pub/Linux/distributions/gentoo" LANG="en_AU.utf8" LDFLAGS="-Wl,-O1 -Wl,--as-needed" MAKEOPTS="-j1" PKGDIR="/usr/portage/packages" PORTAGE_CONFIGROOT="/" PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --omit-dir-times --compress --force --whole-file --delete --stats --human-readable --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages" PORTAGE_TMPDIR="/var/tmp" PORTDIR="/usr/portage" PORTDIR_OVERLAY="/usr/local/portage" SYNC="rsync://rsync/gentoo-portage" USE="acl acpi alsa amd64 apache2 berkdb bzip2 caps cjk cli cracklib crypt cups cxx dlloader dri fam gdbm hardened iconv ipv6 jpeg justify kdeenablefinal kdehiddenvisibility kerberos logrotate mmx mmxext mng modules multilib ncurses nls nptl openmp pam pax_kernel pcre pie png qt readline seccomp session sse sse2 ssl ssp tcpd threads tiff unicode urandom vhosts xattr xcb xinerama xtpax zlib" ABI_X86="64" ALSA_CARDS="ali5451 als4000 atiixp atiixp-modem bt87x ca0106 cmipci emu10k1x ens1370 ens1371 es1938 es1968 fm801 hda-intel intel8x0 intel8x0m maestro3 trident usb-audio via82xx via82xx-modem ymfpci" APACHE2_MODULES="actions alias auth_basic auth_digest authn_anon authn_dbd authn_dbm authn_default authn_file authz_dbm authz_default authz_groupfile authz_host authz_owner authz_user autoindex cache dav dav_fs dav_lock dbd deflate dir disk_cache env expires ext_filter file_cache filter headers ident imagemap include info log_config logio mem_cache mime mime_magic negotiation proxy proxy_ajp proxy_balancer proxy_connect proxy_http rewrite setenvif so speling status unique_id userdir usertrack vhost_alias cgid" CALLIGRA_FEATURES="kexi words flow plan sheets stage tables krita karbon braindump author" CAMERAS="ptp2" COLLECTD_PLUGINS="df interface irq load memory rrdtool swap syslog" CPU_FLAGS_X86="mmx mmxext sse sse2" ELIBC="glibc" GPSD_PROTOCOLS="ashtech aivdm earthmate evermore fv18 garmin garmintxt gpsclock itrax mtk3301 nmea ntrip navcom oceanserver oldstyle oncore rtcm104v2 rtcm104v3 sirf superstar2 timing tsip tripmate tnt ublox ubx" INPUT_DEVICES="evdev keyboard mouse" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" LIBREOFFICE_EXTENSIONS="presenter-console presenter-minimizer" LINGUAS="en en_GB en_US en_AU" OFFICE_IMPLEMENTATION="libreoffice" PYTHON_SINGLE_TARGET="python2_7" PYTHON_TARGETS="python2_7 python3_4" QEMU_SOFTMMU_TARGETS="i386 x86_64" QEMU_USER_TARGETS="i386 x86_64" RUBY_TARGETS="ruby20 ruby21" USERLAND="GNU" VIDEO_CARDS="fbdev vesa" XTABLES_ADDONS="quota2 psd pknock lscan length2 ipv4options ipset ipp2p iface geoip fuzzy condition tee tarpit sysrq steal rawnat logmark ipmark dhcpmac delude chaos account" Unset: CC, CPPFLAGS, CTARGET, CXX, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LC_ALL, PORTAGE_BUNZIP2_COMMAND, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS, USE_PYTHON
Oh that valgrind output is for libusb-1.0.20. The following is the output for libusb-1.0.19 but appears to refer to the same code contents: ==1595== at 0x4C2F341: strcmp (in /usr/lib64/valgrind/vgpreload_memcheck-amd64-linux.so) ==1595== by 0x5617863: linux_enumerate_device (linux_usbfs.c:1027) ==1595== by 0x5618518: linux_hotplug_enumerate (linux_usbfs.c:1103) ==1595== by 0x56199D2: linux_netlink_read_message (linux_netlink.c:322) ==1595== by 0x5619F64: linux_netlink_hotplug_poll (linux_netlink.c:366) ==1595== by 0x560D148: libusb_get_device_list (core.c:669) ==1595== by 0x4E383DF: usb_find_busses (in /lib64/libusb-0.1.so.4.4.4) ==1595== by 0x120D55: libusb_open (libusb.c:164) ==1595== by 0x11EE09: upsdrv_updateinfo (usbhid-ups.c:1355) ==1595== by 0x11D016: main (main.c:708)
Created attachment 414404 [details, diff] libusb-1.0.20_fix_null_ref_on_usb_reconnect.patch Here is quick patch that seems to resolve the issue by checking if priv->sysfs_dir is null in the linux_get_parent_info function before calling strcmp. The patch will also apply with libusb-1.0.19. Will I need to post the patch to the libusb developers as well or is a gentoo libusb developer able to do this?
It looks like this bug only occurs with grsecurity based kernels. https://github.com/libusb/libusb/pull/129 is the pull request I've made for libusb with associated debugging comments.
(In reply to Matthew Stapleton from comment #3) > It looks like this bug only occurs with grsecurity based kernels. > https://github.com/libusb/libusb/pull/129 is the pull request I've made for > libusb with associated debugging comments. Merged a while ago. Thanks!