[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <679a2653.050a0220.ac840.02d6.GAE@google.com>
Date: Wed, 29 Jan 2025 05:00:03 -0800
From: syzbot <syzbot+4a65c3228a624fc51bbd@...kaller.appspotmail.com>
To: aha310510@...il.com, linux-kernel@...r.kernel.org,
syzkaller-bugs@...glegroups.com
Subject: Re: [syzbot] [bcachefs?] possible deadlock in bch2_journal_halt
Hello,
syzbot tried to test the proposed patch but the build/boot failed:
20] The buggy address is located 8 bytes inside of
[ 80.584450][ T5320] freed 512-byte region [ffff88803a124800, ffff88803a124a00)
[ 80.589864][ T5320]
[ 80.590818][ T5320] The buggy address belongs to the physical page:
[ 80.593238][ T5320] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x3a124
[ 80.596455][ T5320] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[ 80.599696][ T5320] flags: 0x4fff00000000040(head|node=1|zone=1|lastcpupid=0x7ff)
[ 80.602655][ T5320] page_type: f5(slab)
[ 80.604188][ T5320] raw: 04fff00000000040 ffff88801ac41c80 ffffea0001010e80 dead000000000002
[ 80.607553][ T5320] raw: 0000000000000000 0000000000080008 00000000f5000000 0000000000000000
[ 80.610778][ T5320] head: 04fff00000000040 ffff88801ac41c80 ffffea0001010e80 dead000000000002
[ 80.614126][ T5320] head: 0000000000000000 0000000000080008 00000000f5000000 0000000000000000
[ 80.617447][ T5320] head: 04fff00000000001 ffffea0000e84901 ffffffffffffffff 0000000000000000
[ 80.620701][ T5320] head: 0000000000000002 0000000000000000 00000000ffffffff 0000000000000000
[ 80.623984][ T5320] page dumped because: kasan: bad access detected
[ 80.626375][ T5320] page_owner tracks the page as allocated
[ 80.628499][ T5320] page last allocated via order 1, migratetype Unmovable, gfp_mask 0xd2040(__GFP_IO|__GFP_NOWARN|__GFP_NORETRY|__GFP_COMP|__GFP_NOMEMALLOC), pid 1, tgid 1 (swapper/0), ts 23262220945, free_ts 23186456949
[ 80.635954][ T5320] post_alloc_hook+0x1f4/0x240
[ 80.637718][ T5320] get_page_from_freelist+0x365c/0x37a0
[ 80.639837][ T5320] __alloc_frozen_pages_noprof+0x292/0x710
[ 80.642325][ T5320] alloc_pages_mpol+0x311/0x660
[ 80.644766][ T5320] allocate_slab+0x8f/0x3a0
[ 80.646574][ T5320] ___slab_alloc+0xc27/0x14a0
[ 80.648410][ T5320] __slab_alloc+0x58/0xa0
[ 80.650056][ T5320] __kmalloc_noprof+0x2e6/0x4c0
[ 80.651966][ T5320] tomoyo_init_log+0x1b3d/0x2050
[ 80.654016][ T5320] tomoyo_supervisor+0x3a4/0x1770
[ 80.656001][ T5320] tomoyo_path_permission+0x243/0x360
[ 80.658121][ T5320] tomoyo_check_open_permission+0x45e/0x4f0
[ 80.660432][ T5320] security_file_open+0xac/0x250
[ 80.662461][ T5320] do_dentry_open+0x320/0x1960
[ 80.664381][ T5320] vfs_open+0x3b/0x370
[ 80.665978][ T5320] path_openat+0x2c74/0x3580
[ 80.667941][ T5320] page last free pid 1 tgid 1 stack trace:
[ 80.670490][ T5320] free_frozen_pages+0xe0d/0x10e0
[ 80.672629][ T5320] __put_partials+0x160/0x1c0
[ 80.674444][ T5320] put_cpu_partial+0x17c/0x250
[ 80.676249][ T5320] __slab_free+0x290/0x380
[ 80.678002][ T5320] qlist_free_all+0x9a/0x140
[ 80.679985][ T5320] kasan_quarantine_reduce+0x14f/0x170
[ 80.682384][ T5320] __kasan_slab_alloc+0x23/0x80
[ 80.684282][ T5320] __kmalloc_cache_noprof+0x1d9/0x390
[ 80.686358][ T5320] bus_add_driver+0x163/0x670
[ 80.688189][ T5320] driver_register+0x23a/0x320
[ 80.690063][ T5320] __hid_register_driver+0x12a/0x170
[ 80.692056][ T5320] do_one_initcall+0x248/0x870
[ 80.693954][ T5320] do_initcall_level+0x157/0x210
[ 80.695876][ T5320] do_initcalls+0x3f/0x80
[ 80.697681][ T5320] kernel_init_freeable+0x435/0x5d0
[ 80.699654][ T5320] kernel_init+0x1d/0x2b0
[ 80.701322][ T5320]
[ 80.702233][ T5320] Memory state around the buggy address:
[ 80.704394][ T5320] ffff88803a124700: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 80.707362][ T5320] ffff88803a124780: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 80.710424][ T5320] >ffff88803a124800: fa fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[ 80.713419][ T5320] ^
[ 80.715030][ T5320] ffff88803a124880: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[ 80.718150][ T5320] ffff88803a124900: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[ 80.721112][ T5320] ==================================================================
[ 80.763220][ T5320] Kernel panic - not syncing: KASAN: panic_on_warn set ...
[ 80.766064][ T5320] CPU: 0 UID: 0 PID: 5320 Comm: syz-executor Not tainted 6.13.0-syzkaller-09338-g05dbaf8dd8bf #0
[ 80.770132][ T5320] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014
[ 80.774362][ T5320] Call Trace:
[ 80.775698][ T5320] <TASK>
[ 80.776895][ T5320] dump_stack_lvl+0x241/0x360
[ 80.778742][ T5320] ? __pfx_dump_stack_lvl+0x10/0x10
[ 80.780694][ T5320] ? __pfx__printk+0x10/0x10
[ 80.782533][ T5320] ? preempt_schedule+0xe1/0xf0
[ 80.784408][ T5320] ? vscnprintf+0x5d/0x90
[ 80.786090][ T5320] panic+0x349/0x880
[ 80.787666][ T5320] ? check_panic_on_warn+0x21/0xb0
[ 80.789676][ T5320] ? __pfx_panic+0x10/0x10
[ 80.791394][ T5320] ? _raw_spin_unlock_irqrestore+0x130/0x140
[ 80.793760][ T5320] ? __pfx__raw_spin_unlock_irqrestore+0x10/0x10
[ 80.796181][ T5320] ? print_report+0x502/0x550
[ 80.797959][ T5320] check_panic_on_warn+0x86/0xb0
[ 80.799850][ T5320] ? binder_add_device+0x5f/0xa0
[ 80.801779][ T5320] end_report+0x77/0x160
[ 80.803507][ T5320] kasan_report+0x154/0x180
[ 80.805264][ T5320] ? binder_add_device+0x5f/0xa0
[ 80.807123][ T5320] binder_add_device+0x5f/0xa0
[ 80.809031][ T5320] binderfs_binder_device_create+0x7bf/0x9c0
[ 80.811095][ T5320] binderfs_fill_super+0x944/0xd90
[ 80.813049][ T5320] ? __pfx_binderfs_fill_super+0x10/0x10
[ 80.815523][ T5320] ? shrinker_register+0x160/0x230
[ 80.817449][ T5320] ? sget_fc+0x909/0x9c0
[ 80.819078][ T5320] ? __pfx_set_anon_super_fc+0x10/0x10
[ 80.821192][ T5320] ? __pfx_binderfs_fill_super+0x10/0x10
[ 80.823333][ T5320] get_tree_nodev+0xb7/0x140
[ 80.825173][ T5320] vfs_get_tree+0x90/0x2b0
[ 80.826899][ T5320] do_new_mount+0x2be/0xb40
[ 80.828694][ T5320] ? __pfx_do_new_mount+0x10/0x10
[ 80.830601][ T5320] __se_sys_mount+0x2d6/0x3c0
[ 80.832398][ T5320] ? lockdep_hardirqs_on_prepare+0x43d/0x780
[ 80.834671][ T5320] ? __pfx___se_sys_mount+0x10/0x10
[ 80.836681][ T5320] ? do_syscall_64+0x100/0x230
[ 80.838547][ T5320] ? __x64_sys_mount+0x20/0xc0
[ 80.840389][ T5320] do_syscall_64+0xf3/0x230
[ 80.842199][ T5320] ? clear_bhb_loop+0x35/0x90
[ 80.844009][ T5320] entry_SYSCALL_64_after_hwframe+0x77/0x7f
[ 80.846282][ T5320] RIP: 0033:0x7fcce71874ca
[ 80.847976][ T5320] Code: d8 64 89 02 48 c7 c0 ff ff ff ff eb a6 e8 de 1a 00 00 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 49 89 ca b8 a5 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48
[ 80.855311][ T5320] RSP: 002b:00007fff7723bf18 EFLAGS: 00000246 ORIG_RAX: 00000000000000a5
[ 80.858516][ T5320] RAX: ffffffffffffffda RBX: 00007fcce7201ecb RCX: 00007fcce71874ca
[ 80.861920][ T5320] RDX: 00007fcce720ec27 RSI: 00007fcce7201ecb RDI: 00007fcce720ec27
[ 80.865502][ T5320] RBP: 00007fcce72020c3 R08: 0000000000000000 R09: 00000000000001ff
[ 80.868574][ T5320] R10: 0000000000000000 R11: 0000000000000246 R12: 00007fcce71e41c8
[ 80.871653][ T5320] R13: 00007fcce71e41a8 R14: 0000000000000009 R15: 0000000000000000
[ 80.874893][ T5320] </TASK>
[ 80.876288][ T5320] Kernel Offset: disabled
[ 80.877994][ T5320] Rebooting in 86400 seconds..
VM DIAGNOSIS:
12:59:33 Registers:
info registers vcpu 0
CPU#0
RAX=000000000000006f RBX=ffffffff9a74c0e0 RCX=0000000000000000 RDX=00000000000003f8
RSI=0000000000000000 RDI=0000000000000020 RBP=0000000000000000 RSP=ffffc9000d1971d0
R8 =ffffffff8576bc5b R9 =1ffff11003d7f046 R10=dffffc0000000000 R11=ffffffff8576bc10
R12=dffffc0000000000 R13=000000000000006f R14=000000000000006f R15=00000000000003f8
RIP=ffffffff8576bc8e RFL=00000002 [-------] CPL=0 II=0 A20=1 SMM=0 HLT=0
ES =0000 0000000000000000 ffffffff 00c00000
CS =0010 0000000000000000 ffffffff 00a09b00 DPL=0 CS64 [-RA]
SS =0018 0000000000000000 ffffffff 00c09300 DPL=0 DS [-WA]
DS =0000 0000000000000000 ffffffff 00c00000
FS =0000 0000555593678500 ffffffff 00c00000
GS =0000 ffff88801fc00000 ffffffff 00c00000
LDT=0000 0000000000000000 ffffffff 00c00000
TR =0040 fffffe0000003000 00004087 00008b00 DPL=0 TSS64-busy
GDT= fffffe0000001000 0000007f
IDT= fffffe0000000000 00000fff
CR0=80050033 CR2=00007fcce710f700 CR3=0000000049aae000 CR4=00352ef0
DR0=0000000000000000 DR1=0000000000000000 DR2=0000000000000000 DR3=0000000000000000
DR6=00000000fffe0ff0 DR7=0000000000000400
EFER=0000000000000d01
FCW=037f FSW=0000 [ST=0] FTW=00 MXCSR=00001f80
FPR0=0000000000000000 0000 FPR1=0000000000000000 0000
FPR2=0000000000000000 0000 FPR3=0000000000000000 0000
FPR4=0000000000000000 0000 FPR5=0000000000000000 0000
FPR6=0000000000000000 0000 FPR7=0000000000000000 0000
Opmask00=00000000eee0c0c0 Opmask01=000000000000000f Opmask02=00000000ffffffef Opmask03=0000000000000000
Opmask04=0000000000000000 Opmask05=0000000000000000 Opmask06=0000000000000000 Opmask07=0000000000000000
ZMM00=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM01=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007fff7723bf30 0000003000000010
ZMM02=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM03=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM04=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM05=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM06=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM07=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM08=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM09=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM10=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM11=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM12=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM13=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM14=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM15=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM16=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM17=0000000000000000 0000000000000000 0000000000000000 0000000000000000 2525252525252525 2525252525252525 2525252525252525 2525252525252525
ZMM18=0000000000000000 0000000000000000 0000000000000000 0000000000000000 2029706d742d7a79 73287269646b6d00 706d742d7a79732f 2e00303030303031
ZMM19=0000000000000000 0000000000000000 0000000000000000 0000000000000000 050c554851085f5c 560d574c414e4800 554851085f5c560a 0b00151515151514
ZMM20=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM21=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM22=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM23=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM24=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM25=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM26=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM27=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM28=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM29=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM30=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM31=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
syzkaller build log:
go env (err=<nil>)
GO111MODULE='auto'
GOARCH='amd64'
GOBIN=''
GOCACHE='/syzkaller/.cache/go-build'
GOENV='/syzkaller/.config/go/env'
GOEXE=''
GOEXPERIMENT=''
GOFLAGS=''
GOHOSTARCH='amd64'
GOHOSTOS='linux'
GOINSECURE=''
GOMODCACHE='/syzkaller/jobs/linux/gopath/pkg/mod'
GONOPROXY=''
GONOSUMDB=''
GOOS='linux'
GOPATH='/syzkaller/jobs/linux/gopath'
GOPRIVATE=''
GOPROXY='https://proxy.golang.org,direct'
GOROOT='/usr/local/go'
GOSUMDB='sum.golang.org'
GOTMPDIR=''
GOTOOLCHAIN='auto'
GOTOOLDIR='/usr/local/go/pkg/tool/linux_amd64'
GOVCS=''
GOVERSION='go1.22.7'
GCCGO='gccgo'
GOAMD64='v1'
AR='ar'
CC='gcc'
CXX='g++'
CGO_ENABLED='1'
GOMOD='/syzkaller/jobs/linux/gopath/src/github.com/google/syzkaller/go.mod'
GOWORK=''
CGO_CFLAGS='-O2 -g'
CGO_CPPFLAGS=''
CGO_CXXFLAGS='-O2 -g'
CGO_FFLAGS='-O2 -g'
CGO_LDFLAGS='-O2 -g'
PKG_CONFIG='pkg-config'
GOGCCFLAGS='-fPIC -m64 -pthread -Wl,--no-gc-sections -fmessage-length=0 -ffile-prefix-map=/tmp/go-build1396050768=/tmp/go-build -gno-record-gcc-switches'
git status (err=<nil>)
HEAD detached at 25e17fd3886
nothing to commit, working tree clean
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
go list -f '{{.Stale}}' ./sys/syz-sysgen | grep -q false || go install ./sys/syz-sysgen
make .descriptions
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
bin/syz-sysgen
go fmt ./sys/... >/dev/null
touch .descriptions
GOOS=linux GOARCH=amd64 go build "-ldflags=-s -w -X github.com/google/syzkaller/prog.GitRevision=25e17fd3886c9c7eda47ce82a8804493b0b792f8 -X 'github.com/google/syzkaller/prog.gitRevisionDate=20250122-131753'" "-tags=syz_target syz_os_linux syz_arch_amd64 " -o ./bin/linux_amd64/syz-execprog github.com/google/syzkaller/tools/syz-execprog
mkdir -p ./bin/linux_amd64
g++ -o ./bin/linux_amd64/syz-executor executor/executor.cc \
-m64 -O2 -pthread -Wall -Werror -Wparentheses -Wunused-const-variable -Wframe-larger-than=16384 -Wno-stringop-overflow -Wno-array-bounds -Wno-format-overflow -Wno-unused-but-set-variable -Wno-unused-command-line-argument -static-pie -std=c++17 -I. -Iexecutor/_include -DGOOS_linux=1 -DGOARCH_amd64=1 \
-DHOSTGOOS_linux=1 -DGIT_REVISION=\"25e17fd3886c9c7eda47ce82a8804493b0b792f8\"
/usr/bin/ld: /tmp/ccX7k8JB.o: in function `Connection::Connect(char const*, char const*)':
executor.cc:(.text._ZN10Connection7ConnectEPKcS1_[_ZN10Connection7ConnectEPKcS1_]+0x104): warning: Using 'gethostbyname' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking
Error text is too large and was truncated, full error text is at:
https://syzkaller.appspot.com/x/error.txt?x=1663c5f8580000
Tested on:
commit: 05dbaf8d Merge tag 'x86-urgent-2025-01-28' of git://gi..
git tree: upstream
kernel config: https://syzkaller.appspot.com/x/.config?x=6f0752505116b954
dashboard link: https://syzkaller.appspot.com/bug?extid=4a65c3228a624fc51bbd
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
Note: no patches were applied.
Powered by blists - more mailing lists