[Android 5.4] kernel BUG in end_page_writeback

11 views
Skip to first unread message

syzbot

unread,
Feb 6, 2023, 6:18:54 PM2/6/23
to syzkaller-a...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 6a5ec6cea0cd UPSTREAM: 9p/fd: fix issue of list_del corrup..
git tree: android12-5.4
console output: https://syzkaller.appspot.com/x/log.txt?x=16bdaf6b480000
kernel config: https://syzkaller.appspot.com/x/.config?x=c00a32e58def3322
dashboard link: https://syzkaller.appspot.com/bug?extid=ff728271f547ffe48a77
compiler: Debian clang version 13.0.1-6~deb11u1, GNU ld (GNU Binutils for Debian) 2.35.2

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/b0c84a2500cf/disk-6a5ec6ce.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/7c54760baf8c/vmlinux-6a5ec6ce.xz
kernel image: https://storage.googleapis.com/syzbot-assets/838417840fba/bzImage-6a5ec6ce.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+ff7282...@syzkaller.appspotmail.com

------------[ cut here ]------------
kernel BUG at mm/filemap.c:1359!
invalid opcode: 0000 [#1] PREEMPT SMP KASAN
CPU: 1 PID: 378 Comm: kworker/u4:3 Not tainted 5.4.225-syzkaller-00029-g6a5ec6cea0cd #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/12/2023
Workqueue: writeback wb_workfn (flush-7:0)
RIP: 0010:end_page_writeback+0x19c/0x1a0 mm/filemap.c:1359
Code: 5d 41 5e 41 5f 5d e9 73 fa ff ff e8 8e fe e4 ff 49 ff cc e9 d1 fe ff ff e8 81 fe e4 ff 49 ff ce e9 52 ff ff ff e8 74 fe e4 ff <0f> 0b 66 90 55 41 57 41 56 41 55 41 54 53 41 89 d4 89 f3 49 89 fe
RSP: 0018:ffff8881e5fbe950 EFLAGS: 00010293
RAX: ffffffff8180809c RBX: 0000000000000000 RCX: ffff8881ed66ee40
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: dffffc0000000000 R08: ffffffff81808017 R09: fffff94000f42e59
R10: fffff94000f42e59 R11: 1ffffd4000f42e58 R12: ffffea0007a172c0
R13: ffffea0007a172c8 R14: 1ffffd4000f42e59 R15: ffffea0007a172c0
FS: 0000000000000000(0000) GS:ffff8881f6f00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000001b2f12e000 CR3: 00000001ed595000 CR4: 00000000003406e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
f2fs_write_end_io+0x5c7/0xae0 fs/f2fs/data.c:341
generic_make_request_checks+0x25f/0xf80 block/blk-core.c:989
generic_make_request+0xcf/0xe60 block/blk-core.c:1029
submit_bio+0x142/0x640 block/blk-core.c:1203
f2fs_submit_merged_ipu_write+0x4ac/0x520 fs/f2fs/data.c:857
f2fs_write_single_data_page+0x139d/0x19d0 fs/f2fs/data.c:2872
f2fs_write_cache_pages fs/f2fs/data.c:3083 [inline]
__f2fs_write_data_pages+0x15cb/0x2c20 fs/f2fs/data.c:3234
do_writepages+0x13a/0x280 mm/page-writeback.c:2344
__writeback_single_inode+0xc5/0x840 fs/fs-writeback.c:1467
writeback_sb_inodes+0xa04/0x1890 fs/fs-writeback.c:1730
wb_writeback+0x429/0xcb0 fs/fs-writeback.c:1905
wb_do_writeback+0x1f2/0xbd0 fs/fs-writeback.c:2050
wb_workfn+0xf8/0x450 fs/fs-writeback.c:2091
process_one_work+0x6ca/0xc40 kernel/workqueue.c:2287
worker_thread+0xae0/0x1440 kernel/workqueue.c:2433
kthread+0x2d8/0x360 kernel/kthread.c:288
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:354
Modules linked in:
---[ end trace f17b518d47c4b6f1 ]---
RIP: 0010:end_page_writeback+0x19c/0x1a0 mm/filemap.c:1359
Code: 5d 41 5e 41 5f 5d e9 73 fa ff ff e8 8e fe e4 ff 49 ff cc e9 d1 fe ff ff e8 81 fe e4 ff 49 ff ce e9 52 ff ff ff e8 74 fe e4 ff <0f> 0b 66 90 55 41 57 41 56 41 55 41 54 53 41 89 d4 89 f3 49 89 fe
RSP: 0018:ffff8881e5fbe950 EFLAGS: 00010293
RAX: ffffffff8180809c RBX: 0000000000000000 RCX: ffff8881ed66ee40
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: dffffc0000000000 R08: ffffffff81808017 R09: fffff94000f42e59
R10: fffff94000f42e59 R11: 1ffffd4000f42e58 R12: ffffea0007a172c0
R13: ffffea0007a172c8 R14: 1ffffd4000f42e59 R15: ffffea0007a172c0
FS: 0000000000000000(0000) GS:ffff8881f6e00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000001b2f331000 CR3: 00000001e5d2f000 CR4: 00000000003406f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Feb 6, 2023, 6:46:38 PM2/6/23
to syzkaller-a...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 6a5ec6cea0cd UPSTREAM: 9p/fd: fix issue of list_del corrup..
git tree: android12-5.4
console+strace: https://syzkaller.appspot.com/x/log.txt?x=1765c01f480000
kernel config: https://syzkaller.appspot.com/x/.config?x=c00a32e58def3322
dashboard link: https://syzkaller.appspot.com/bug?extid=ff728271f547ffe48a77
compiler: Debian clang version 13.0.1-6~deb11u1, GNU ld (GNU Binutils for Debian) 2.35.2
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=15ff196b480000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=105756a7480000
mounted in repro: https://storage.googleapis.com/syzbot-assets/eae17dd3eabf/mount_0.gz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+ff7282...@syzkaller.appspotmail.com

------------[ cut here ]------------
kernel BUG at mm/filemap.c:1359!
invalid opcode: 0000 [#1] PREEMPT SMP KASAN
CPU: 0 PID: 361 Comm: kworker/u4:3 Not tainted 5.4.225-syzkaller-00029-g6a5ec6cea0cd #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/12/2023
Workqueue: writeback wb_workfn (flush-7:5)
RIP: 0010:end_page_writeback+0x19c/0x1a0 mm/filemap.c:1359
Code: 5d 41 5e 41 5f 5d e9 73 fa ff ff e8 8e fe e4 ff 49 ff cc e9 d1 fe ff ff e8 81 fe e4 ff 49 ff ce e9 52 ff ff ff e8 74 fe e4 ff <0f> 0b 66 90 55 41 57 41 56 41 55 41 54 53 41 89 d4 89 f3 49 89 fe
RSP: 0018:ffff8881d29de950 EFLAGS: 00010293
RAX: ffffffff8180809c RBX: 0000000000000000 RCX: ffff8881d3708000
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: dffffc0000000000 R08: ffffffff81808017 R09: fffff94000f522a9
R10: fffff94000f522a9 R11: 1ffffd4000f522a8 R12: ffffea0007a91540
R13: ffffea0007a91548 R14: 1ffffd4000f522a9 R15: ffffea0007a91540
FS: 0000000000000000(0000) GS:ffff8881f6e00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007faaa80bf000 CR3: 00000001dc86e000 CR4: 00000000003406f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
f2fs_write_end_io+0x5c7/0xae0 fs/f2fs/data.c:341
generic_make_request_checks+0x25f/0xf80 block/blk-core.c:989
generic_make_request+0xcf/0xe60 block/blk-core.c:1029
submit_bio+0x142/0x640 block/blk-core.c:1203
f2fs_submit_merged_ipu_write+0x4ac/0x520 fs/f2fs/data.c:857
f2fs_write_single_data_page+0x139d/0x19d0 fs/f2fs/data.c:2872
f2fs_write_cache_pages fs/f2fs/data.c:3083 [inline]
__f2fs_write_data_pages+0x15cb/0x2c20 fs/f2fs/data.c:3234
do_writepages+0x13a/0x280 mm/page-writeback.c:2344
__writeback_single_inode+0xc5/0x840 fs/fs-writeback.c:1467
writeback_sb_inodes+0xa04/0x1890 fs/fs-writeback.c:1730
wb_writeback+0x429/0xcb0 fs/fs-writeback.c:1905
wb_do_writeback+0x1f2/0xbd0 fs/fs-writeback.c:2050
wb_workfn+0xf8/0x450 fs/fs-writeback.c:2091
process_one_work+0x6ca/0xc40 kernel/workqueue.c:2287
worker_thread+0xae0/0x1440 kernel/workqueue.c:2433
kthread+0x2d8/0x360 kernel/kthread.c:288
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:354
Modules linked in:
---[ end trace b0fe203f8c269521 ]---
RIP: 0010:end_page_writeback+0x19c/0x1a0 mm/filemap.c:1359
Code: 5d 41 5e 41 5f 5d e9 73 fa ff ff e8 8e fe e4 ff 49 ff cc e9 d1 fe ff ff e8 81 fe e4 ff 49 ff ce e9 52 ff ff ff e8 74 fe e4 ff <0f> 0b 66 90 55 41 57 41 56 41 55 41 54 53 41 89 d4 89 f3 49 89 fe
RSP: 0018:ffff8881d29de950 EFLAGS: 00010293
RAX: ffffffff8180809c RBX: 0000000000000000 RCX: ffff8881d3708000
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: dffffc0000000000 R08: ffffffff81808017 R09: fffff94000f522a9
R10: fffff94000f522a9 R11: 1ffffd4000f522a8 R12: ffffea0007a91540
R13: ffffea0007a91548 R14: 1ffffd4000f522a9 R15: ffffea0007a91540
FS: 0000000000000000(0000) GS:ffff8881f6e00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007faaaf68c948 CR3: 00000001d6aba000 CR4: 00000000003406f0

syzbot

unread,
Feb 6, 2023, 7:17:42 PM2/6/23
to syzkaller-a...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 416c4356f372 Merge 5.10.161 into android12-5.10-lts
git tree: android12-5.10-lts
console+strace: https://syzkaller.appspot.com/x/log.txt?x=16cda74b480000
kernel config: https://syzkaller.appspot.com/x/.config?x=ba29236d2f217808
dashboard link: https://syzkaller.appspot.com/bug?extid=e07a04819573e4acc535
compiler: Debian clang version 13.0.1-++20220126092033+75e33f71c2da-1~exp1~20220126212112.63, GNU ld (GNU Binutils for Debian) 2.35.2
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=15b0b66b480000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1157c45d480000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/0149809cf436/disk-416c4356.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/2bf0b26aed77/vmlinux-416c4356.xz
kernel image: https://storage.googleapis.com/syzbot-assets/224b4978be5c/bzImage-416c4356.xz
mounted in repro: https://storage.googleapis.com/syzbot-assets/4df0b4c231b3/mount_0.gz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+e07a04...@syzkaller.appspotmail.com

------------[ cut here ]------------
kernel BUG at mm/filemap.c:1504!
invalid opcode: 0000 [#1] PREEMPT SMP KASAN
CPU: 1 PID: 430 Comm: kworker/u4:3 Not tainted 5.10.161-syzkaller-00019-g416c4356f372 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/12/2023
Workqueue: writeback wb_workfn (flush-7:4)
RIP: 0010:end_page_writeback+0x28c/0x2a0 mm/filemap.c:1504
Code: 32 de ff 49 ff cc e9 d9 fe ff ff e8 1e 32 de ff 49 ff ce 4d 89 f7 eb 8c e8 11 32 de ff 49 ff cc e9 65 fe ff ff e8 04 32 de ff <0f> 0b e8 fd 31 de ff 4c 89 ff e8 75 85 1d 00 eb 87 0f 1f 00 55 48
RSP: 0018:ffffc90000ed66d8 EFLAGS: 00010293
RAX: ffffffff818eefac RBX: 0000000000000000 RCX: ffff88810a6be2c0
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: ffffc90000ed6700 R08: ffffffff818eee8e R09: fffff94000850ff9
R10: fffff94000850ff9 R11: 1ffffd4000850ff8 R12: ffffea0004287fc0
R13: 1ffffd4000850ff9 R14: ffffea0004287fc8 R15: ffffea0004287fc0
FS: 0000000000000000(0000) GS:ffff8881f7100000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007ff0af46a948 CR3: 000000010910d000 CR4: 00000000003506a0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
f2fs_write_end_io+0x597/0x950 fs/f2fs/data.c:342
bio_endio+0x465/0x5c0 block/bio.c:1459
submit_bio_checks+0x25c/0xe80 block/blk-core.c:925
submit_bio_noacct+0x98/0x11f0 block/blk-core.c:1048
submit_bio+0x1f8/0x6e0 block/blk-core.c:1133
__submit_bio+0x717/0x920 fs/f2fs/data.c:499
f2fs_submit_merged_ipu_write+0x668/0x720 fs/f2fs/data.c:858
f2fs_write_single_data_page+0x16aa/0x1d30 fs/f2fs/data.c:2846
f2fs_write_cache_pages fs/f2fs/data.c:3055 [inline]
__f2fs_write_data_pages+0x179e/0x2c80 fs/f2fs/data.c:3206
f2fs_write_data_pages+0x74/0x80 fs/f2fs/data.c:3233
do_writepages+0x13a/0x280 mm/page-writeback.c:2358
__writeback_single_inode+0xb8/0x6e0 fs/fs-writeback.c:1467
writeback_sb_inodes+0x999/0x1700 fs/fs-writeback.c:1730
wb_writeback+0x42f/0xc20 fs/fs-writeback.c:1905
wb_do_writeback+0x222/0xbd0 fs/fs-writeback.c:2050
wb_workfn+0xf8/0x3f0 fs/fs-writeback.c:2091
process_one_work+0x726/0xc10 kernel/workqueue.c:2296
worker_thread+0xb27/0x1550 kernel/workqueue.c:2442
kthread+0x349/0x3d0 kernel/kthread.c:313
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:299
Modules linked in:
---[ end trace 4f194181c5aba59a ]---
RIP: 0010:end_page_writeback+0x28c/0x2a0 mm/filemap.c:1504
Code: 32 de ff 49 ff cc e9 d9 fe ff ff e8 1e 32 de ff 49 ff ce 4d 89 f7 eb 8c e8 11 32 de ff 49 ff cc e9 65 fe ff ff e8 04 32 de ff <0f> 0b e8 fd 31 de ff 4c 89 ff e8 75 85 1d 00 eb 87 0f 1f 00 55 48
RSP: 0018:ffffc90000ed66d8 EFLAGS: 00010293
RAX: ffffffff818eefac RBX: 0000000000000000 RCX: ffff88810a6be2c0
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: ffffc90000ed6700 R08: ffffffff818eee8e R09: fffff94000850ff9
R10: fffff94000850ff9 R11: 1ffffd4000850ff8 R12: ffffea0004287fc0
R13: 1ffffd4000850ff9 R14: ffffea0004287fc8 R15: ffffea0004287fc0
FS: 0000000000000000(0000) GS:ffff8881f7100000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007ff0af46a948 CR3: 000000010c7fa000 CR4: 00000000003506a0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this issue, for details see:
https://goo.gl/tpsmEJ#testing-patches
Reply all
Reply to author
Forward
0 new messages