lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <68fb2d93.a70a0220.3bf6c6.014a.GAE@google.com>
Date: Fri, 24 Oct 2025 00:41:07 -0700
From: syzbot <syzbot+c24237f0eee59c0c2abb@...kaller.appspotmail.com>
To: dmantipov@...dex.ru, linux-kernel@...r.kernel.org, 
	syzkaller-bugs@...glegroups.com
Subject: Re: [syzbot] [ocfs2?] kernel BUG in ocfs2_truncate_log_needs_flush (2)

Hello,

syzbot tried to test the proposed patch but the build/boot failed:

im0 netdevsim3: renamed from eth3
[   65.498461][ T5570] bridge0: port 2(bridge_slave_1) entered blocking state
[   65.504458][ T5570] bridge0: port 2(bridge_slave_1) entered forwarding state
[   65.510598][ T5570] bridge0: port 1(bridge_slave_0) entered blocking state
[   65.516333][ T5570] bridge0: port 1(bridge_slave_0) entered forwarding state
[   65.547747][ T5570] 8021q: adding VLAN 0 to HW filter on device bond0
[   65.558428][ T3031] IPv6: ADDRCONF(NETDEV_CHANGE): veth0: link becomes ready
[   65.566437][ T3031] bridge0: port 1(bridge_slave_0) entered disabled state
[   65.573305][ T3031] bridge0: port 2(bridge_slave_1) entered disabled state
[   65.581116][ T3031] IPv6: ADDRCONF(NETDEV_CHANGE): bond0: link becomes ready
[   65.590723][ T5570] 8021q: adding VLAN 0 to HW filter on device team0
[   65.605138][ T3031] IPv6: ADDRCONF(NETDEV_CHANGE): bridge_slave_0: link becomes ready
[   65.617739][ T3031] bridge0: port 1(bridge_slave_0) entered blocking state
[   65.624264][ T3031] bridge0: port 1(bridge_slave_0) entered forwarding state
[   65.632411][ T3031] IPv6: ADDRCONF(NETDEV_CHANGE): bridge_slave_1: link becomes ready
[   65.641431][ T3031] bridge0: port 2(bridge_slave_1) entered blocking state
[   65.647421][ T3031] bridge0: port 2(bridge_slave_1) entered forwarding state
[   65.665596][ T3031] IPv6: ADDRCONF(NETDEV_CHANGE): team_slave_0: link becomes ready
[   65.675817][ T3031] IPv6: ADDRCONF(NETDEV_CHANGE): team_slave_1: link becomes ready
[   65.688046][ T5570] hsr0: Slave A (hsr_slave_0) is not up; please bring it up to get a fully working HSR network
[   65.699422][ T5570] hsr0: Slave B (hsr_slave_1) is not up; please bring it up to get a fully working HSR network
[   65.712142][ T3031] IPv6: ADDRCONF(NETDEV_CHANGE): team0: link becomes ready
[   65.719124][ T3031] IPv6: ADDRCONF(NETDEV_CHANGE): hsr_slave_0: link becomes ready
[   65.726668][ T3031] IPv6: ADDRCONF(NETDEV_CHANGE): hsr_slave_1: link becomes ready
[   65.743599][ T3031] IPv6: ADDRCONF(NETDEV_CHANGE): hsr0: link becomes ready
[   65.795967][ T3061] IPv6: ADDRCONF(NETDEV_CHANGE): vxcan0: link becomes ready
[   65.803090][ T3061] IPv6: ADDRCONF(NETDEV_CHANGE): vxcan1: link becomes ready
[   65.812250][ T5570] 8021q: adding VLAN 0 to HW filter on device batadv0
[   65.826943][ T3061] IPv6: ADDRCONF(NETDEV_CHANGE): veth0_virt_wifi: link becomes ready
[   65.840970][ T5570] device veth0_vlan entered promiscuous mode
[   65.846214][ T3061] IPv6: ADDRCONF(NETDEV_CHANGE): veth0_vlan: link becomes ready
[   65.853729][ T3061] IPv6: ADDRCONF(NETDEV_CHANGE): vlan0: link becomes ready
[   65.859777][ T3061] IPv6: ADDRCONF(NETDEV_CHANGE): vlan1: link becomes ready
[   65.869781][ T5570] device veth1_vlan entered promiscuous mode
[   65.876428][ T3061] IPv6: ADDRCONF(NETDEV_CHANGE): macvlan0: link becomes ready
[   65.893202][ T3061] IPv6: ADDRCONF(NETDEV_CHANGE): macvlan1: link becomes ready
[   65.901517][ T3061] IPv6: ADDRCONF(NETDEV_CHANGE): veth0_macvtap: link becomes ready
[   65.909785][ T5570] device veth0_macvtap entered promiscuous mode
[   65.919316][ T5570] device veth1_macvtap entered promiscuous mode
[   65.932694][ T5570] batman_adv: batadv0: Interface activated: batadv_slave_0
[   65.938869][ T3061] IPv6: ADDRCONF(NETDEV_CHANGE): veth0_to_batadv: link becomes ready
[   65.947434][ T3061] IPv6: ADDRCONF(NETDEV_CHANGE): macvtap0: link becomes ready
[   65.956647][ T5570] batman_adv: batadv0: Interface activated: batadv_slave_1
[   65.963867][ T3061] IPv6: ADDRCONF(NETDEV_CHANGE): veth1_to_batadv: link becomes ready
[   65.973107][ T5570] netdevsim netdevsim0 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0
[   65.981275][ T5570] netdevsim netdevsim0 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0
[   65.988383][ T5570] netdevsim netdevsim0 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0
[   65.996540][ T5570] netdevsim netdevsim0 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0
[   66.009412][ T3061] ================================================================================
[   66.017125][ T3061] UBSAN: signed-integer-overflow in ./arch/x86/include/asm/atomic.h:165:11
[   66.024329][ T3061] -163290563 + -2098288399 cannot be represented in type 'int'
[   66.031757][ T3061] CPU: 0 PID: 3061 Comm: kworker/u2:8 Not tainted syzkaller #0
[   66.038134][ T3061] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014
[   66.048130][ T3061] Workqueue: wg-kex-wg0 wg_packet_handshake_send_worker
[   66.053893][ T3061] Call Trace:
[   66.057427][ T3061]  dump_stack+0xfd/0x16e
[   66.060951][ T3061]  ubsan_epilogue+0xa/0x30
[   66.064639][ T3061]  handle_overflow+0x192/0x1b0
[   66.068437][ T3061]  ? prandom_u32+0x217/0x260
[   66.072280][ T3061]  ip_idents_reserve+0x14a/0x170
[   66.076197][ T3061]  __ip_select_ident+0xe4/0x1c0
[   66.080020][ T3061]  iptunnel_xmit+0x468/0x850
[   66.083815][ T3061]  udp_tunnel_xmit_skb+0x1ba/0x290
[   66.088108][ T3061]  send4+0x5d4/0xaf0
[   66.091339][ T3061]  wg_socket_send_skb_to_peer+0xcd/0x1c0
[   66.095883][ T3061]  wg_packet_handshake_send_worker+0x16b/0x280
[   66.100935][ T3061]  process_one_work+0x85e/0xff0
[   66.104997][ T3061]  worker_thread+0xa9b/0x1430
[   66.108751][ T3061]  ? lock_release+0x69/0x640
[   66.112517][ T3061]  ? rcu_lock_release+0x20/0x20
[   66.116506][ T3061]  kthread+0x386/0x410
[   66.119891][ T3061]  ? rcu_lock_release+0x20/0x20
[   66.124100][ T3061]  ? kthread_blkcg+0xd0/0xd0
[   66.127889][ T3061]  ret_from_fork+0x1f/0x30
[   66.131580][ T3061] ================================================================================
[   66.138816][ T3061] Kernel panic - not syncing: UBSAN: panic_on_warn set ...
[   66.144565][ T3061] CPU: 0 PID: 3061 Comm: kworker/u2:8 Not tainted syzkaller #0
[   66.150499][ T3061] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014
[   66.159482][ T3061] Workqueue: wg-kex-wg0 wg_packet_handshake_send_worker
[   66.165195][ T3061] Call Trace:
[   66.167897][ T3061]  dump_stack+0xfd/0x16e
[   66.171471][ T3061]  panic+0x2f0/0x9c0
[   66.174602][ T3061]  check_panic_on_warn+0x95/0xe0
[   66.178727][ T3061]  handle_overflow+0x192/0x1b0
[   66.182743][ T3061]  ? prandom_u32+0x217/0x260
[   66.186508][ T3061]  ip_idents_reserve+0x14a/0x170
[   66.190664][ T3061]  __ip_select_ident+0xe4/0x1c0
[   66.194678][ T3061]  iptunnel_xmit+0x468/0x850
[   66.198320][ T3061]  udp_tunnel_xmit_skb+0x1ba/0x290
[   66.202576][ T3061]  send4+0x5d4/0xaf0
[   66.205845][ T3061]  wg_socket_send_skb_to_peer+0xcd/0x1c0
[   66.210583][ T3061]  wg_packet_handshake_send_worker+0x16b/0x280
[   66.215775][ T3061]  process_one_work+0x85e/0xff0
[   66.219866][ T3061]  worker_thread+0xa9b/0x1430
[   66.223801][ T3061]  ? lock_release+0x69/0x640
[   66.227824][ T3061]  ? rcu_lock_release+0x20/0x20
[   66.231900][ T3061]  kthread+0x386/0x410
[   66.235406][ T3061]  ? rcu_lock_release+0x20/0x20
[   66.239449][ T3061]  ? kthread_blkcg+0xd0/0xd0
[   66.243419][ T3061]  ret_from_fork+0x1f/0x30
[   66.247485][ T3061] Kernel Offset: disabled
[   66.251127][ T3061] Rebooting in 86400 seconds..

VM DIAGNOSIS:
07:40:09  Registers:
info registers vcpu 0

CPU#0
RAX=0000000000000036 RBX=0000000000000036 RCX=0000000000000000 RDX=00000000000003f8
RSI=0000000000000000 RDI=0000000000000020 RBP=00000000000003f8 RSP=ffffc9000172f4e0
R8 =dffffc0000000000 R9 =fffff520002e5e9e R10=fffff520002e5e9e R11=ffffffff83f79850
R12=dffffc0000000000 R13=1ffffffff2ad2063 R14=ffffffff96179de0 R15=0000000000000000
RIP=ffffffff83f798c8 RFL=00000002 [-------] CPL=0 II=0 A20=1 SMM=0 HLT=0
ES =0000 0000000000000000 ffffffff 00c00000
CS =0010 0000000000000000 ffffffff 00a09b00 DPL=0 CS64 [-RA]
SS =0018 0000000000000000 ffffffff 00c09300 DPL=0 DS   [-WA]
DS =0000 0000000000000000 ffffffff 00c00000
FS =0000 0000000000000000 ffffffff 00c00000
GS =0000 ffff888020600000 ffffffff 00c00000
LDT=0000 0000000000000000 ffffffff 00c00000
TR =0040 fffffe0000003000 00004087 00008b00 DPL=0 TSS64-busy
GDT=     fffffe0000001000 0000007f
IDT=     fffffe0000000000 00000fff
CR0=80050033 CR2=00007f9d25c90e9c CR3=000000003f184000 CR4=00350ef0
DR0=0000000000000000 DR1=0000000000000000 DR2=0000000000000000 DR3=0000000000000000 
DR6=00000000fffe0ff0 DR7=0000000000000400
EFER=0000000000000d01
FCW=037f FSW=0000 [ST=0] FTW=00 MXCSR=00001f80
FPR0=0000000000000000 0000 FPR1=0000000000000000 0000
FPR2=0000000000000000 0000 FPR3=0000000000000000 0000
FPR4=0000000000000000 0000 FPR5=0000000000000000 0000
FPR6=0000000000000000 0000 FPR7=0000000000000000 0000
Opmask00=0000000040410888 Opmask01=0000000000000fff Opmask02=00000000ffffffef Opmask03=0000000000000000
Opmask04=0000000000000000 Opmask05=0000000000000000 Opmask06=0000000000000000 Opmask07=0000000000000000
ZMM00=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 b8a5606d93fbf234 4e6d6128c1c61247
ZMM01=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 e69291a55adf1a4d bc79a80ad3c0fce0
ZMM02=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 be6cebfbb543848d 5148acc6845117c5
ZMM03=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 4a118d849a30d684 02106ca1c36d1727
ZMM04=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00000000ffffffff 00000000000000b4
ZMM05=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000034
ZMM06=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 f280979acd555a03 dd619a0e2b11f92c
ZMM07=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 4db1fdda4413481c 0000000000000000
ZMM08=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 9675387fceff6377 c2b3d307affe2114
ZMM09=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 d99f887700000000 25c03f609d700a96
ZMM10=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 15ad1dc2a12d429b 71118e54ff6cdf2d
ZMM11=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 fbb4f24384a52b52 900c1a64c85601c3
ZMM12=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM13=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM14=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 a54ff53a3c6ef372 bb67ae856a09e667
ZMM15=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 5be0cd191f83d9ab 9b05688c510e527f
ZMM16=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM17=0000000000000000 0000000000000000 0000000000000000 0000000000000000 2525252525252525 2525252525252525 2525252525252525 2525252525252525
ZMM18=0000000000000000 0000000000000000 0000000000000000 0000000000000000 00306e6170737265 0030657267367069 00306c6e74367069 00306974765f3670
ZMM19=0000000000000000 0000000000000000 0000000000000000 0000000000000000 6900306974765f70 6900306c6e757400 3074697300326777 0031677700306777
ZMM20=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM21=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM22=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM23=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM24=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM25=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM26=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM27=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM28=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM29=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM30=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM31=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000


syzkaller build log:
go env (err=<nil>)
AR='ar'
CC='gcc'
CGO_CFLAGS='-O2 -g'
CGO_CPPFLAGS=''
CGO_CXXFLAGS='-O2 -g'
CGO_ENABLED='1'
CGO_FFLAGS='-O2 -g'
CGO_LDFLAGS='-O2 -g'
CXX='g++'
GCCGO='gccgo'
GO111MODULE='auto'
GOAMD64='v1'
GOARCH='amd64'
GOAUTH='netrc'
GOBIN=''
GOCACHE='/syzkaller/.cache/go-build'
GOCACHEPROG=''
GODEBUG=''
GOENV='/syzkaller/.config/go/env'
GOEXE=''
GOEXPERIMENT=''
GOFIPS140='off'
GOFLAGS=''
GOGCCFLAGS='-fPIC -m64 -pthread -Wl,--no-gc-sections -fmessage-length=0 -ffile-prefix-map=/tmp/go-build317169965=/tmp/go-build -gno-record-gcc-switches'
GOHOSTARCH='amd64'
GOHOSTOS='linux'
GOINSECURE=''
GOMOD='/syzkaller/jobs/linux/gopath/src/github.com/google/syzkaller/go.mod'
GOMODCACHE='/syzkaller/jobs/linux/gopath/pkg/mod'
GONOPROXY=''
GONOSUMDB=''
GOOS='linux'
GOPATH='/syzkaller/jobs/linux/gopath'
GOPRIVATE=''
GOPROXY='https://proxy.golang.org,direct'
GOROOT='/usr/local/go'
GOSUMDB='sum.golang.org'
GOTELEMETRY='local'
GOTELEMETRYDIR='/syzkaller/.config/go/telemetry'
GOTMPDIR=''
GOTOOLCHAIN='auto'
GOTOOLDIR='/usr/local/go/pkg/tool/linux_amd64'
GOVCS=''
GOVERSION='go1.24.4'
GOWORK=''
PKG_CONFIG='pkg-config'

git status (err=<nil>)
HEAD detached at d7384b6d0bf
nothing to commit, working tree clean


tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
go list -f '{{.Stale}}' ./sys/syz-sysgen | grep -q false || go install ./sys/syz-sysgen
make .descriptions
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
bin/syz-sysgen
touch .descriptions
GOOS=linux GOARCH=amd64 go build -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=d7384b6d0bff77c60aad349866f126ab16ce5296 -X github.com/google/syzkaller/prog.gitRevisionDate=20250710-085248"  -o ./bin/linux_amd64/syz-execprog github.com/google/syzkaller/tools/syz-execprog
mkdir -p ./bin/linux_amd64
g++ -o ./bin/linux_amd64/syz-executor executor/executor.cc \
	-m64 -O2 -pthread -Wall -Werror -Wparentheses -Wunused-const-variable -Wframe-larger-than=16384 -Wno-stringop-overflow -Wno-array-bounds -Wno-format-overflow -Wno-unused-but-set-variable -Wno-unused-command-line-argument -static-pie -std=c++17 -I. -Iexecutor/_include   -DGOOS_linux=1 -DGOARCH_amd64=1 \
	-DHOSTGOOS_linux=1 -DGIT_REVISION=\"d7384b6d0bff77c60aad349866f126ab16ce5296\"
/usr/bin/ld: /tmp/ccf2gjJF.o: in function `Connection::Connect(char const*, char const*)':
executor.cc:(.text._ZN10Connection7ConnectEPKcS1_[_ZN10Connection7ConnectEPKcS1_]+0x104): warning: Using 'gethostbyname' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking


Error text is too large and was truncated, full error text is at:
https://syzkaller.appspot.com/x/error.txt?x=17bd0be2580000


Tested on:

commit:         d3d0b4e2 Linux 5.10.245
git tree:       https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git linux-5.10.y
kernel config:  https://syzkaller.appspot.com/x/.config?x=768d3f2193745e75
dashboard link: https://syzkaller.appspot.com/bug?extid=c24237f0eee59c0c2abb
compiler:       Debian clang version 20.1.8 (++20250708063551+0c9f909b7976-1~exp1~20250708183702.136), Debian LLD 20.1.8
patch:          https://syzkaller.appspot.com/x/patch.diff?x=16728258580000


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ