general protection fault in bdev_read_page

6 views
Skip to first unread message

syzbot

unread,
Aug 22, 2020, 1:04:22 AM8/22/20
to syzkaller-a...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 45551fb3 ANDROID: sched: add vendor hook for correcting cp..
git tree: android-5.4
console output: https://syzkaller.appspot.com/x/log.txt?x=11202d19900000
kernel config: https://syzkaller.appspot.com/x/.config?x=71d36a7b70f701e3
dashboard link: https://syzkaller.appspot.com/bug?extid=abe1d53f7ee6e44eb373
compiler: Android (6032204 based on r370808) clang version 10.0.1 (https://android.googlesource.com/toolchain/llvm-project 6e765c10313d15c02ab29977a82938f66742c3a9)

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+abe1d5...@syzkaller.appspotmail.com

kasan: CONFIG_KASAN_INLINE enabled
kasan: GPF could be caused by NULL-ptr deref or user memory access
general protection fault: 0000 [#1] PREEMPT SMP KASAN
CPU: 0 PID: 15423 Comm: systemd-udevd Not tainted 5.4.59-syzkaller-00526-g45551fb3ebd9 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
RIP: 0010:bdev_read_page+0x37/0x190 fs/block_dev.c:703
Code: 10 49 89 d5 48 89 74 24 08 49 89 fc 49 bf 00 00 00 00 00 fc ff df e8 58 7b be ff 49 8d 9c 24 80 00 00 00 48 89 d8 48 c1 e8 03 <42> 80 3c 38 00 74 08 48 89 df e8 ea b1 ec ff bd c0 04 00 00 48 03
RSP: 0018:ffff8881d0977418 EFLAGS: 00010202
RAX: 0000000000000010 RBX: 0000000000000080 RCX: ffff8881cddfdd00
RDX: 0000000000000000 RSI: aaaaaaaaaaa00000 RDI: 0000000000000000
RBP: ffff8881d0977630 R08: ffffffff8184c95a R09: fffff94000cd1a01
R10: fffff94000cd1a01 R11: 0000000000000000 R12: 0000000000000000
R13: ffffea000668d000 R14: dffffc0000000000 R15: dffffc0000000000
FS: 00007f820c7f28c0(0000) GS:ffff8881db800000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fff7c86fff8 CR3: 00000001d033d005 CR4: 00000000001606f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000600
Call Trace:
do_mpage_readpage+0x142e/0x1af0 fs/mpage.c:338
mpage_readpages+0x395/0x500 fs/mpage.c:440
read_pages+0x11a/0x400 mm/readahead.c:126
__do_page_cache_readahead+0x46c/0x510 mm/readahead.c:212
force_page_cache_readahead mm/readahead.c:243 [inline]
page_cache_sync_readahead+0x331/0x3c0 mm/readahead.c:522
generic_file_buffered_read mm/filemap.c:2051 [inline]
generic_file_read_iter+0x5ce/0x20b0 mm/filemap.c:2324
call_read_iter include/linux/fs.h:1965 [inline]
new_sync_read fs/read_write.c:414 [inline]
__vfs_read+0x59a/0x710 fs/read_write.c:427
vfs_read+0x166/0x380 fs/read_write.c:461
ksys_read+0x18c/0x2c0 fs/read_write.c:590
do_syscall_64+0xcb/0x150 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x44/0xa9
RIP: 0033:0x7f820b939210
Code: 73 01 c3 48 8b 0d 98 7d 20 00 f7 d8 64 89 01 48 83 c8 ff c3 66 0f 1f 44 00 00 83 3d b9 c1 20 00 00 75 10 b8 00 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 31 c3 48 83 ec 08 e8 4e fc ff ff 48 89 04 24
RSP: 002b:00007ffc66c691b8 EFLAGS: 00000246 ORIG_RAX: 0000000000000000
RAX: ffffffffffffffda RBX: 0000558aa1e59410 RCX: 00007f820b939210
RDX: 0000000000000400 RSI: 0000558aa1e59438 RDI: 000000000000000f
RBP: 0000558aa1e4a720 R08: 00007f820b923f68 R09: 0000000000000430
R10: 000000000000006d R11: 0000000000000246 R12: 0000000000000000
R13: 0000000000000400 R14: 0000558aa1e4a770 R15: 0000000000000400
Modules linked in:
---[ end trace 8e276ad66e630cf5 ]---
RIP: 0010:bdev_read_page+0x37/0x190 fs/block_dev.c:703
Code: 10 49 89 d5 48 89 74 24 08 49 89 fc 49 bf 00 00 00 00 00 fc ff df e8 58 7b be ff 49 8d 9c 24 80 00 00 00 48 89 d8 48 c1 e8 03 <42> 80 3c 38 00 74 08 48 89 df e8 ea b1 ec ff bd c0 04 00 00 48 03
RSP: 0018:ffff8881d0977418 EFLAGS: 00010202
RAX: 0000000000000010 RBX: 0000000000000080 RCX: ffff8881cddfdd00
RDX: 0000000000000000 RSI: aaaaaaaaaaa00000 RDI: 0000000000000000
RBP: ffff8881d0977630 R08: ffffffff8184c95a R09: fffff94000cd1a01
R10: fffff94000cd1a01 R11: 0000000000000000 R12: 0000000000000000
R13: ffffea000668d000 R14: dffffc0000000000 R15: dffffc0000000000
FS: 00007f820c7f28c0(0000) GS:ffff8881db900000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f8a1ff92000 CR3: 00000001d033d003 CR4: 00000000001606e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000600


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Aug 22, 2020, 1:31:16 AM8/22/20
to syzkaller-a...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 45551fb3 ANDROID: sched: add vendor hook for correcting cp..
git tree: android-5.4
console output: https://syzkaller.appspot.com/x/log.txt?x=10c54db1900000
kernel config: https://syzkaller.appspot.com/x/.config?x=71d36a7b70f701e3
dashboard link: https://syzkaller.appspot.com/bug?extid=abe1d53f7ee6e44eb373
compiler: Android (6032204 based on r370808) clang version 10.0.1 (https://android.googlesource.com/toolchain/llvm-project 6e765c10313d15c02ab29977a82938f66742c3a9)
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=152f0c96900000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=13420a05900000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+abe1d5...@syzkaller.appspotmail.com

kasan: GPF could be caused by NULL-ptr deref or user memory access
general protection fault: 0000 [#1] PREEMPT SMP KASAN
CPU: 1 PID: 346 Comm: systemd-udevd Not tainted 5.4.59-syzkaller-00526-g45551fb3ebd9 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
RIP: 0010:bdev_read_page+0x37/0x190 fs/block_dev.c:703
Code: 10 49 89 d5 48 89 74 24 08 49 89 fc 49 bf 00 00 00 00 00 fc ff df e8 58 7b be ff 49 8d 9c 24 80 00 00 00 48 89 d8 48 c1 e8 03 <42> 80 3c 38 00 74 08 48 89 df e8 ea b1 ec ff bd c0 04 00 00 48 03
RSP: 0018:ffff8881cde67418 EFLAGS: 00010202
RAX: 0000000000000010 RBX: 0000000000000080 RCX: ffff8881cdf34d80
RDX: 0000000000000000 RSI: aaaaaaaaaaa00000 RDI: 0000000000000000
RBP: ffff8881cde67630 R08: ffffffff8184c95a R09: fffff94000e7a3a1
R10: fffff94000e7a3a1 R11: 0000000000000000 R12: 0000000000000000
R13: ffffea00073d1d00 R14: dffffc0000000000 R15: dffffc0000000000
FS: 00007f00dace08c0(0000) GS:ffff8881db900000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fff057aa784 CR3: 00000001c3d25006 CR4: 00000000001606e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
do_mpage_readpage+0x142e/0x1af0 fs/mpage.c:338
mpage_readpages+0x395/0x500 fs/mpage.c:440
read_pages+0x11a/0x400 mm/readahead.c:126
__do_page_cache_readahead+0x46c/0x510 mm/readahead.c:212
force_page_cache_readahead mm/readahead.c:243 [inline]
page_cache_sync_readahead+0x331/0x3c0 mm/readahead.c:522
generic_file_buffered_read mm/filemap.c:2051 [inline]
generic_file_read_iter+0x5ce/0x20b0 mm/filemap.c:2324
call_read_iter include/linux/fs.h:1965 [inline]
new_sync_read fs/read_write.c:414 [inline]
__vfs_read+0x59a/0x710 fs/read_write.c:427
vfs_read+0x166/0x380 fs/read_write.c:461
ksys_read+0x18c/0x2c0 fs/read_write.c:590
do_syscall_64+0xcb/0x150 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x44/0xa9
RIP: 0033:0x7f00d9e27210
Code: 73 01 c3 48 8b 0d 98 7d 20 00 f7 d8 64 89 01 48 83 c8 ff c3 66 0f 1f 44 00 00 83 3d b9 c1 20 00 00 75 10 b8 00 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 31 c3 48 83 ec 08 e8 4e fc ff ff 48 89 04 24
RSP: 002b:00007ffc8d1b3fc8 EFLAGS: 00000246 ORIG_RAX: 0000000000000000
RAX: ffffffffffffffda RBX: 000055be929de410 RCX: 00007f00d9e27210
RDX: 0000000000000400 RSI: 000055be929de438 RDI: 000000000000000f
RBP: 000055be929dfdf0 R08: 00007f00d9e11f68 R09: 0000000000000430
R10: 000055be929de428 R11: 0000000000000246 R12: 0000000000000000
R13: 0000000000000400 R14: 000055be929dfe40 R15: 0000000000000400
Modules linked in:
---[ end trace fbaffc34c20ee35d ]---
RIP: 0010:bdev_read_page+0x37/0x190 fs/block_dev.c:703
FS: 00007f00dace08c0(0000) GS:ffff8881db900000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00000000004c3a28 CR3: 00000001c3d25006 CR4: 00000000001606e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400

Reply all
Reply to author
Forward
0 new messages