Hello,
syzbot found the following issue on:
HEAD commit: 6a5ec6cea0cd UPSTREAM: 9p/fd: fix issue of list_del corrup..
git tree: android12-5.4
console output:
https://syzkaller.appspot.com/x/log.txt?x=16bdaf6b480000
kernel config:
https://syzkaller.appspot.com/x/.config?x=c00a32e58def3322
dashboard link:
https://syzkaller.appspot.com/bug?extid=ff728271f547ffe48a77
compiler: Debian clang version 13.0.1-6~deb11u1, GNU ld (GNU Binutils for Debian) 2.35.2
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/b0c84a2500cf/disk-6a5ec6ce.raw.xz
vmlinux:
https://storage.googleapis.com/syzbot-assets/7c54760baf8c/vmlinux-6a5ec6ce.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/838417840fba/bzImage-6a5ec6ce.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+ff7282...@syzkaller.appspotmail.com
------------[ cut here ]------------
kernel BUG at mm/filemap.c:1359!
invalid opcode: 0000 [#1] PREEMPT SMP KASAN
CPU: 1 PID: 378 Comm: kworker/u4:3 Not tainted 5.4.225-syzkaller-00029-g6a5ec6cea0cd #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/12/2023
Workqueue: writeback wb_workfn (flush-7:0)
RIP: 0010:end_page_writeback+0x19c/0x1a0 mm/filemap.c:1359
Code: 5d 41 5e 41 5f 5d e9 73 fa ff ff e8 8e fe e4 ff 49 ff cc e9 d1 fe ff ff e8 81 fe e4 ff 49 ff ce e9 52 ff ff ff e8 74 fe e4 ff <0f> 0b 66 90 55 41 57 41 56 41 55 41 54 53 41 89 d4 89 f3 49 89 fe
RSP: 0018:ffff8881e5fbe950 EFLAGS: 00010293
RAX: ffffffff8180809c RBX: 0000000000000000 RCX: ffff8881ed66ee40
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: dffffc0000000000 R08: ffffffff81808017 R09: fffff94000f42e59
R10: fffff94000f42e59 R11: 1ffffd4000f42e58 R12: ffffea0007a172c0
R13: ffffea0007a172c8 R14: 1ffffd4000f42e59 R15: ffffea0007a172c0
FS: 0000000000000000(0000) GS:ffff8881f6f00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000001b2f12e000 CR3: 00000001ed595000 CR4: 00000000003406e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
f2fs_write_end_io+0x5c7/0xae0 fs/f2fs/data.c:341
generic_make_request_checks+0x25f/0xf80 block/blk-core.c:989
generic_make_request+0xcf/0xe60 block/blk-core.c:1029
submit_bio+0x142/0x640 block/blk-core.c:1203
f2fs_submit_merged_ipu_write+0x4ac/0x520 fs/f2fs/data.c:857
f2fs_write_single_data_page+0x139d/0x19d0 fs/f2fs/data.c:2872
f2fs_write_cache_pages fs/f2fs/data.c:3083 [inline]
__f2fs_write_data_pages+0x15cb/0x2c20 fs/f2fs/data.c:3234
do_writepages+0x13a/0x280 mm/page-writeback.c:2344
__writeback_single_inode+0xc5/0x840 fs/fs-writeback.c:1467
writeback_sb_inodes+0xa04/0x1890 fs/fs-writeback.c:1730
wb_writeback+0x429/0xcb0 fs/fs-writeback.c:1905
wb_do_writeback+0x1f2/0xbd0 fs/fs-writeback.c:2050
wb_workfn+0xf8/0x450 fs/fs-writeback.c:2091
process_one_work+0x6ca/0xc40 kernel/workqueue.c:2287
worker_thread+0xae0/0x1440 kernel/workqueue.c:2433
kthread+0x2d8/0x360 kernel/kthread.c:288
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:354
Modules linked in:
---[ end trace f17b518d47c4b6f1 ]---
RIP: 0010:end_page_writeback+0x19c/0x1a0 mm/filemap.c:1359
Code: 5d 41 5e 41 5f 5d e9 73 fa ff ff e8 8e fe e4 ff 49 ff cc e9 d1 fe ff ff e8 81 fe e4 ff 49 ff ce e9 52 ff ff ff e8 74 fe e4 ff <0f> 0b 66 90 55 41 57 41 56 41 55 41 54 53 41 89 d4 89 f3 49 89 fe
RSP: 0018:ffff8881e5fbe950 EFLAGS: 00010293
RAX: ffffffff8180809c RBX: 0000000000000000 RCX: ffff8881ed66ee40
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: dffffc0000000000 R08: ffffffff81808017 R09: fffff94000f42e59
R10: fffff94000f42e59 R11: 1ffffd4000f42e58 R12: ffffea0007a172c0
R13: ffffea0007a172c8 R14: 1ffffd4000f42e59 R15: ffffea0007a172c0
FS: 0000000000000000(0000) GS:ffff8881f6e00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000001b2f331000 CR3: 00000001e5d2f000 CR4: 00000000003406f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.