lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <68141c95.050a0220.14dd7d.001c.GAE@google.com>
Date: Thu, 01 May 2025 18:15:01 -0700
From: syzbot <syzbot+7b3842775c9ce6b69efc@...kaller.appspotmail.com>
To: hdanton@...a.com, linux-kernel@...r.kernel.org, 
	syzkaller-bugs@...glegroups.com
Subject: Re: [syzbot] [mm?] BUG: Bad page state in page_cache_ra_order

Hello,

syzbot tried to test the proposed patch but the build/boot failed:

_pgtable         ]: Validating architecture page table helpers
[   18.960143][    T1] Key type .fscrypt registered
[   18.963394][    T1] Key type fscrypt-provisioning registered
[   18.997093][    T1] kAFS: Red Hat AFS client v0.1 registering.
[   19.015868][    T1] Btrfs loaded, assert=on, ref-verify=on, zoned=yes, fsverity=yes
[   19.020415][    T1] Key type big_key registered
[   19.028071][    T1] Key type encrypted registered
[   19.031538][    T1] ima: No TPM chip found, activating TPM-bypass!
[   19.034968][    T1] Loading compiled-in module X.509 certificates
[   19.064977][    T1] Loaded X.509 cert 'Build time autogenerated kernel key: 5ffa98226aab18898f938e23c71e38ddbdc3d6be'
[   19.071363][    T1] ima: Allocated hash algorithm: sha256
[   19.074921][    T1] ima: No architecture policies found
[   19.078073][    T1] evm: Initialising EVM extended attributes:
[   19.081136][    T1] evm: security.selinux
[   19.083318][    T1] evm: security.SMACK64 (disabled)
[   19.085959][    T1] evm: security.SMACK64EXEC (disabled)
[   19.088774][    T1] evm: security.SMACK64TRANSMUTE (disabled)
[   19.091720][    T1] evm: security.SMACK64MMAP (disabled)
[   19.094549][    T1] evm: security.apparmor (disabled)
[   19.097192][    T1] evm: security.ima
[   19.099109][    T1] evm: security.capability
[   19.101316][    T1] evm: HMAC attrs: 0x1
[   19.105400][    T1] PM:   Magic number: 9:757:52
[   19.108017][    T1] gadget gadget.3: hash matches
[   19.111074][    T1] printk: legacy console [netcon0] enabled
[   19.114174][    T1] netconsole: network logging started
[   19.117496][    T1] gtp: GTP module loaded (pdp ctx size 128 bytes)
[   19.123577][    T1] rdma_rxe: loaded
[   19.126289][    T1] cfg80211: Loading compiled-in X.509 certificates for regulatory database
[   19.132568][    T1] Loaded X.509 cert 'sforshee: 00b28ddf47aef9cea7'
[   19.137040][    T1] Loaded X.509 cert 'wens: 61c038651aabdcf94bd0ac7ff06c7248db18c600'
[   19.141979][   T64] platform regulatory.0: Direct firmware load for regulatory.db failed with error -2
[   19.144278][    T1] clk: Disabling unused clocks
[   19.147093][   T64] platform regulatory.0: Falling back to sysfs fallback for: regulatory.db
[   19.149365][    T1] ALSA device list:
[   19.156335][    T1]   #0: Dummy 1
[   19.158671][    T1]   #1: Loopback 1
[   19.161218][    T1]   #2: Virtual MIDI Card 1
[   19.168255][    T1] md: Waiting for all devices to be available before autodetect
[   19.171325][    T1] md: If you don't use raid, use raid=noautodetect
[   19.173752][    T1] md: Autodetecting RAID arrays.
[   19.175815][    T1] md: autorun ...
[   19.177419][    T1] md: ... autorun DONE.
[   19.184183][    T1] 
[   19.184924][    T1] ============================================
[   19.186790][    T1] WARNING: possible recursive locking detected
[   19.188720][    T1] 6.15.0-rc4-syzkaller-gebd297a2affa-dirty #0 Not tainted
[   19.190708][    T1] --------------------------------------------
[   19.192499][    T1] swapper/0/1 is trying to acquire lock:
[   19.194144][    T1] ffff88801fa8f0c0 (mapping.invalidate_lock){+.+.}-{4:4}, at: set_blocksize+0x2c7/0x540
[   19.196953][    T1] 
[   19.196953][    T1] but task is already holding lock:
[   19.199108][    T1] ffff88801fa8f0c0 (mapping.invalidate_lock){+.+.}-{4:4}, at: set_blocksize+0x20f/0x540
[   19.201846][    T1] 
[   19.201846][    T1] other info that might help us debug this:
[   19.204121][    T1]  Possible unsafe locking scenario:
[   19.204121][    T1] 
[   19.206228][    T1]        CPU0
[   19.207168][    T1]        ----
[   19.208188][    T1]   lock(mapping.invalidate_lock);
[   19.209671][    T1]   lock(mapping.invalidate_lock);
[   19.211139][    T1] 
[   19.211139][    T1]  *** DEADLOCK ***
[   19.211139][    T1] 
[   19.213468][    T1]  May be due to missing lock nesting notation
[   19.213468][    T1] 
[   19.215860][    T1] 3 locks held by swapper/0/1:
[   19.217308][    T1]  #0: ffff88802b51a0e0 (&type->s_umount_key#24/1){+.+.}-{4:4}, at: alloc_super+0x235/0xbd0
[   19.220365][    T1]  #1: ffff88801fa8ef20 (&sb->s_type->i_mutex_key#7){+.+.}-{4:4}, at: set_blocksize+0x1e0/0x540
[   19.223505][    T1]  #2: ffff88801fa8f0c0 (mapping.invalidate_lock){+.+.}-{4:4}, at: set_blocksize+0x20f/0x540
[   19.226605][    T1] 
[   19.226605][    T1] stack backtrace:
[   19.228455][    T1] CPU: 2 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.15.0-rc4-syzkaller-gebd297a2affa-dirty #0 PREEMPT(full) 
[   19.228469][    T1] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014
[   19.228475][    T1] Call Trace:
[   19.228480][    T1]  <TASK>
[   19.228484][    T1]  dump_stack_lvl+0x116/0x1f0
[   19.228527][    T1]  print_deadlock_bug+0x1e9/0x240
[   19.228542][    T1]  __lock_acquire+0xff7/0x1ba0
[   19.228559][    T1]  lock_acquire+0x179/0x350
[   19.228573][    T1]  ? set_blocksize+0x2c7/0x540
[   19.228584][    T1]  ? __pfx___might_resched+0x10/0x10
[   19.228597][    T1]  ? smp_call_function_many_cond+0x524/0x1290
[   19.228610][    T1]  down_write+0x92/0x200
[   19.228622][    T1]  ? set_blocksize+0x2c7/0x540
[   19.228632][    T1]  ? __pfx_down_write+0x10/0x10
[   19.228645][    T1]  ? __pfx_invalidate_bh_lru+0x10/0x10
[   19.228661][    T1]  ? __pfx_has_bh_in_lru+0x10/0x10
[   19.228675][    T1]  ? on_each_cpu_cond_mask+0x5a/0x90
[   19.228686][    T1]  set_blocksize+0x2c7/0x540
[   19.228697][    T1]  sb_set_blocksize+0xca/0x1d0
[   19.228708][    T1]  ext4_fill_super+0x8b4/0xb020
[   19.228722][    T1]  ? snprintf+0xc7/0x100
[   19.228732][    T1]  ? __pfx_snprintf+0x10/0x10
[   19.228742][    T1]  ? __pfx_ext4_fill_super+0x10/0x10
[   19.228751][    T1]  ? do_raw_spin_lock+0x12c/0x2b0
[   19.228761][    T1]  ? find_held_lock+0x2b/0x80
[   19.228772][    T1]  ? set_blocksize+0x43f/0x540
[   19.228783][    T1]  ? sb_set_blocksize+0x176/0x1d0
[   19.228793][    T1]  ? setup_bdev_super+0x369/0x730
[   19.228807][    T1]  get_tree_bdev_flags+0x389/0x620
[   19.228821][    T1]  ? __pfx_ext4_fill_super+0x10/0x10
[   19.228831][    T1]  ? __pfx_get_tree_bdev_flags+0x10/0x10
[   19.228847][    T1]  ? bpf_lsm_capable+0x9/0x10
[   19.228856][    T1]  ? security_capable+0x7e/0x260
[   19.228867][    T1]  vfs_get_tree+0x8b/0x340
[   19.228879][    T1]  path_mount+0x14d4/0x1f20
[   19.228890][    T1]  ? kmem_cache_free+0x2d4/0x4d0
[   19.228905][    T1]  ? __pfx_path_mount+0x10/0x10
[   19.228916][    T1]  ? putname+0x154/0x1a0
[   19.228926][    T1]  init_mount+0xbe/0x110
[   19.228958][    T1]  ? __pfx_init_mount+0x10/0x10
[   19.228969][    T1]  ? list_bdev_fs_names+0x10d/0x170
[   19.228982][    T1]  do_mount_root+0x22a/0x540
[   19.228994][    T1]  mount_root_generic+0x199/0x690
[   19.229007][    T1]  ? __pfx_mount_root_generic+0x10/0x10
[   19.229019][    T1]  ? __asan_memcpy+0x3c/0x60
[   19.229033][    T1]  ? getname_kernel+0x21b/0x370
[   19.229044][    T1]  mount_root+0x243/0x480
[   19.229054][    T1]  ? kmem_cache_alloc_noprof+0x21e/0x3b0
[   19.229071][    T1]  ? __pfx_mount_root+0x10/0x10
[   19.229082][    T1]  ? __asan_memcpy+0x3c/0x60
[   19.229095][    T1]  ? getname_kernel+0x21b/0x370
[   19.229106][    T1]  prepare_namespace+0xe2/0x3f0
[   19.229121][    T1]  ? __pfx_prepare_namespace+0x10/0x10
[   19.229133][    T1]  ? fput+0x70/0xf0
[   19.229143][    T1]  kernel_init_freeable+0x705/0x900
[   19.229154][    T1]  ? __pfx_kernel_init+0x10/0x10
[   19.229168][    T1]  kernel_init+0x1c/0x2b0
[   19.229181][    T1]  ? __pfx_kernel_init+0x10/0x10
[   19.229194][    T1]  ret_from_fork+0x45/0x80
[   19.229204][    T1]  ? __pfx_kernel_init+0x10/0x10
[   19.229218][    T1]  ret_from_fork_asm+0x1a/0x30
[   19.229235][    T1]  </TASK>
[   81.482424][   T64] cfg80211: failed to load regulatory.db
[  286.281965][   T41] INFO: task swapper/0:1 blocked for more than 143 seconds.
[  286.284156][   T41]       Not tainted 6.15.0-rc4-syzkaller-gebd297a2affa-dirty #0
[  286.286388][   T41] "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
[  286.288911][   T41] task:swapper/0       state:D stack:22520 pid:1     tgid:1     ppid:0      task_flags:0x0140 flags:0x00004002
[  286.292445][   T41] Call Trace:
[  286.293501][   T41]  <TASK>
[  286.294421][   T41]  __schedule+0x116f/0x5de0
[  286.295775][   T41]  ? lock_release+0x201/0x2f0
[  286.297172][   T41]  ? rcu_is_watching+0x12/0xc0
[  286.298603][   T41]  ? trace_sched_exit_tp+0xde/0x130
[  286.300147][   T41]  ? __pfx___schedule+0x10/0x10
[  286.301615][   T41]  ? schedule+0x2d7/0x3a0
[  286.302953][   T41]  ? rcu_is_watching+0x12/0xc0
[  286.304387][   T41]  ? lock_release+0x201/0x2f0
[  286.305836][   T41]  schedule+0xe7/0x3a0
[  286.307106][   T41]  schedule_preempt_disabled+0x13/0x30
[  286.308826][   T41]  rwsem_down_write_slowpath+0x524/0x1310
[  286.310541][   T41]  ? __pfx_rwsem_down_write_slowpath+0x10/0x10
[  286.312447][   T41]  ? __pfx___might_resched+0x10/0x10
[  286.314090][   T41]  ? smp_call_function_many_cond+0x524/0x1290
[  286.315957][   T41]  down_write+0x1d6/0x200
[  286.317252][   T41]  ? __pfx_down_write+0x10/0x10
[  286.318812][   T41]  ? __pfx_invalidate_bh_lru+0x10/0x10
[  286.320534][   T41]  ? __pfx_has_bh_in_lru+0x10/0x10
[  286.322210][   T41]  ? on_each_cpu_cond_mask+0x5a/0x90
[  286.323906][   T41]  set_blocksize+0x2c7/0x540
[  286.325357][   T41]  sb_set_blocksize+0xca/0x1d0
[  286.326869][   T41]  ext4_fill_super+0x8b4/0xb020
[  286.328395][   T41]  ? snprintf+0xc7/0x100
[  286.329760][   T41]  ? __pfx_snprintf+0x10/0x10
[  286.331242][   T41]  ? __pfx_ext4_fill_super+0x10/0x10
[  286.332970][   T41]  ? do_raw_spin_lock+0x12c/0x2b0
[  286.334602][   T41]  ? find_held_lock+0x2b/0x80
[  286.336083][   T41]  ? set_blocksize+0x43f/0x540
[  286.337596][   T41]  ? sb_set_blocksize+0x176/0x1d0
[  286.339191][   T41]  ? setup_bdev_super+0x369/0x730
[  286.340773][   T41]  get_tree_bdev_flags+0x389/0x620
[  286.342447][   T41]  ? __pfx_ext4_fill_super+0x10/0x10
[  286.344107][   T41]  ? __pfx_get_tree_bdev_flags+0x10/0x10
[  286.345871][   T41]  ? bpf_lsm_capable+0x9/0x10
[  286.347344][   T41]  ? security_capable+0x7e/0x260
[  286.348910][   T41]  vfs_get_tree+0x8b/0x340
[  286.350330][   T41]  path_mount+0x14d4/0x1f20
[  286.351768][   T41]  ? kmem_cache_free+0x2d4/0x4d0
[  286.353369][   T41]  ? __pfx_path_mount+0x10/0x10
[  286.354935][   T41]  ? putname+0x154/0x1a0
[  286.356280][   T41]  init_mount+0xbe/0x110
[  286.357635][   T41]  ? __pfx_init_mount+0x10/0x10
[  286.359186][   T41]  ? list_bdev_fs_names+0x10d/0x170
[  286.360819][   T41]  do_mount_root+0x22a/0x540
[  286.362350][   T41]  mount_root_generic+0x199/0x690
[  286.363959][   T41]  ? __pfx_mount_root_generic+0x10/0x10
[  286.365694][   T41]  ? __asan_memcpy+0x3c/0x60
[  286.367173][   T41]  ? getname_kernel+0x21b/0x370
[  286.368720][   T41]  mount_root+0x243/0x480
[  286.370203][   T41]  ? kmem_cache_alloc_noprof+0x21e/0x3b0
[  286.372064][   T41]  ? __pfx_mount_root+0x10/0x10
[  286.373629][   T41]  ? __asan_memcpy+0x3c/0x60
[  286.375086][   T41]  ? getname_kernel+0x21b/0x370
[  286.376619][   T41]  prepare_namespace+0xe2/0x3f0
[  286.378165][   T41]  ? __pfx_prepare_namespace+0x10/0x10
[  286.379885][   T41]  ? fput+0x70/0xf0
[  286.381122][   T41]  kernel_init_freeable+0x705/0x900
[  286.382830][   T41]  ? __pfx_kernel_init+0x10/0x10
[  286.384413][   T41]  kernel_init+0x1c/0x2b0
[  286.385808][   T41]  ? __pfx_kernel_init+0x10/0x10
[  286.387388][   T41]  ret_from_fork+0x45/0x80
[  286.388808][   T41]  ? __pfx_kernel_init+0x10/0x10
[  286.390457][   T41]  ret_from_fork_asm+0x1a/0x30
[  286.392028][   T41]  </TASK>
[  286.393125][   T41] INFO: lockdep is turned off.
[  286.394664][   T41] Kernel panic - not syncing: hung_task: blocked tasks
[  286.396810][   T41] CPU: 3 UID: 0 PID: 41 Comm: khungtaskd Not tainted 6.15.0-rc4-syzkaller-gebd297a2affa-dirty #0 PREEMPT(full) 
[  286.400476][   T41] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014
[  286.404020][   T41] Call Trace:
[  286.405169][   T41]  <TASK>
[  286.406133][   T41]  dump_stack_lvl+0x3d/0x1f0
[  286.407615][   T41]  panic+0x71c/0x800
[  286.408912][   T41]  ? __pfx_panic+0x10/0x10
[  286.410428][   T41]  ? rcu_is_watching+0x12/0xc0
[  286.411948][   T41]  ? rcu_is_watching+0x12/0xc0
[  286.413468][   T41]  ? watchdog+0xdda/0x12c0
[  286.414892][   T41]  ? watchdog+0xdcd/0x12c0
[  286.416296][   T41]  watchdog+0xdeb/0x12c0
[  286.417642][   T41]  ? __pfx_watchdog+0x10/0x10
[  286.419134][   T41]  ? lockdep_hardirqs_on+0x7c/0x110
[  286.420764][   T41]  ? __kthread_parkme+0x19e/0x250
[  286.422370][   T41]  ? __pfx_watchdog+0x10/0x10
[  286.423864][   T41]  kthread+0x3c2/0x780
[  286.425148][   T41]  ? __pfx_kthread+0x10/0x10
[  286.426607][   T41]  ? __pfx_kthread+0x10/0x10
[  286.428061][   T41]  ? __pfx_kthread+0x10/0x10
[  286.429544][   T41]  ? __pfx_kthread+0x10/0x10
[  286.431050][   T41]  ? rcu_is_watching+0x12/0xc0
[  286.432676][   T41]  ? __pfx_kthread+0x10/0x10
[  286.434145][   T41]  ret_from_fork+0x45/0x80
[  286.435555][   T41]  ? __pfx_kthread+0x10/0x10
[  286.437021][   T41]  ret_from_fork_asm+0x1a/0x30
[  286.438545][   T41]  </TASK>
[  286.440143][   T41] Kernel Offset: disabled
[  286.441519][   T41] Rebooting in 86400 seconds..


syzkaller build log:
go env (err=<nil>)
GO111MODULE='auto'
GOARCH='amd64'
GOBIN=''
GOCACHE='/syzkaller/.cache/go-build'
GOENV='/syzkaller/.config/go/env'
GOEXE=''
GOEXPERIMENT=''
GOFLAGS=''
GOHOSTARCH='amd64'
GOHOSTOS='linux'
GOINSECURE=''
GOMODCACHE='/syzkaller/jobs/linux/gopath/pkg/mod'
GONOPROXY=''
GONOSUMDB=''
GOOS='linux'
GOPATH='/syzkaller/jobs/linux/gopath'
GOPRIVATE=''
GOPROXY='https://proxy.golang.org,direct'
GOROOT='/syzkaller/jobs/linux/gopath/pkg/mod/golang.org/toolchain@...0.1-go1.23.7.linux-amd64'
GOSUMDB='sum.golang.org'
GOTMPDIR=''
GOTOOLCHAIN='auto'
GOTOOLDIR='/syzkaller/jobs/linux/gopath/pkg/mod/golang.org/toolchain@...0.1-go1.23.7.linux-amd64/pkg/tool/linux_amd64'
GOVCS=''
GOVERSION='go1.23.7'
GODEBUG=''
GOTELEMETRY='local'
GOTELEMETRYDIR='/syzkaller/.config/go/telemetry'
GCCGO='gccgo'
GOAMD64='v1'
AR='ar'
CC='gcc'
CXX='g++'
CGO_ENABLED='1'
GOMOD='/syzkaller/jobs/linux/gopath/src/github.com/google/syzkaller/go.mod'
GOWORK=''
CGO_CFLAGS='-O2 -g'
CGO_CPPFLAGS=''
CGO_CXXFLAGS='-O2 -g'
CGO_FFLAGS='-O2 -g'
CGO_LDFLAGS='-O2 -g'
PKG_CONFIG='pkg-config'
GOGCCFLAGS='-fPIC -m64 -pthread -Wl,--no-gc-sections -fmessage-length=0 -ffile-prefix-map=/tmp/go-build137835052=/tmp/go-build -gno-record-gcc-switches'

git status (err=<nil>)
HEAD detached at c6b4fb3992
nothing to commit, working tree clean


tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
go list -f '{{.Stale}}' ./sys/syz-sysgen | grep -q false || go install ./sys/syz-sysgen
make .descriptions
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
bin/syz-sysgen
touch .descriptions
GOOS=linux GOARCH=amd64 go build "-ldflags=-s -w -X github.com/google/syzkaller/prog.GitRevision=c6b4fb399236b655a39701fd51c33522caa06811 -X 'github.com/google/syzkaller/prog.gitRevisionDate=20250425-123509'" -o ./bin/linux_amd64/syz-execprog github.com/google/syzkaller/tools/syz-execprog
mkdir -p ./bin/linux_amd64
g++ -o ./bin/linux_amd64/syz-executor executor/executor.cc \
	-m64 -O2 -pthread -Wall -Werror -Wparentheses -Wunused-const-variable -Wframe-larger-than=16384 -Wno-stringop-overflow -Wno-array-bounds -Wno-format-overflow -Wno-unused-but-set-variable -Wno-unused-command-line-argument -static-pie -std=c++17 -I. -Iexecutor/_include   -DGOOS_linux=1 -DGOARCH_amd64=1 \
	-DHOSTGOOS_linux=1 -DGIT_REVISION=\"c6b4fb399236b655a39701fd51c33522caa06811\"
/usr/bin/ld: /tmp/cccPF3Tm.o: in function `Connection::Connect(char const*, char const*)':
executor.cc:(.text._ZN10Connection7ConnectEPKcS1_[_ZN10Connection7ConnectEPKcS1_]+0x104): warning: Using 'gethostbyname' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking


Error text is too large and was truncated, full error text is at:
https://syzkaller.appspot.com/x/error.txt?x=160b3f74580000


Tested on:

commit:         ebd297a2 Merge tag 'net-6.15-rc5' of git://git.kernel...
git tree:       upstream
kernel config:  https://syzkaller.appspot.com/x/.config?x=ca17f2d2ba38f7a0
dashboard link: https://syzkaller.appspot.com/bug?extid=7b3842775c9ce6b69efc
compiler:       gcc (Debian 12.2.0-14) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40
patch:          https://syzkaller.appspot.com/x/patch.diff?x=1481939b980000


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ