kernel BUG in blk_mq_dispatch_rq_list

11 views
Skip to first unread message

syzbot

unread,
Jan 1, 2022, 11:51:18 PM1/1/22
to syzkaller-a...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 9b28b48fb343 Merge 5.10.89 into android12-5.10-lts
git tree: android12-5.10-lts
console output: https://syzkaller.appspot.com/x/log.txt?x=13106bebb00000
kernel config: https://syzkaller.appspot.com/x/.config?x=194b6725650cc3e2
dashboard link: https://syzkaller.appspot.com/bug?extid=4f441e6ca0fcad141421
compiler: Debian clang version 11.0.1-2, GNU ld (GNU Binutils for Debian) 2.35.2

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+4f441e...@syzkaller.appspotmail.com

ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:296
---[ end trace 7cdd9467215c6dd8 ]---
blk_update_request: I/O error, dev sda, sector 819192 op 0x1:(WRITE) flags 0xc800 phys_seg 0 prio class 0
------------[ cut here ]------------
kernel BUG at block/blk-mq.c:567!
invalid opcode: 0000 [#1] PREEMPT SMP KASAN
CPU: 1 PID: 78 Comm: kworker/1:1H Tainted: G W 5.10.89-syzkaller-00788-g9b28b48fb343 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Workqueue: kblockd blk_mq_requeue_work
RIP: 0010:blk_mq_end_request block/blk-mq.c:567 [inline]
RIP: 0010:blk_mq_dispatch_rq_list+0x17d2/0x17e0 block/blk-mq.c:1395
Code: 61 ff e9 45 f5 ff ff 44 89 e9 80 e1 07 80 c1 03 38 c1 0f 8c 70 f6 ff ff 4c 89 ef e8 c8 20 61 ff e9 63 f6 ff ff e8 ce 43 27 ff <0f> 0b e8 67 27 55 02 0f 1f 80 00 00 00 00 55 48 89 e5 41 57 41 56
RSP: 0018:ffffc900001ff740 EFLAGS: 00010293
RAX: ffffffff82459bf2 RBX: ffff88810ad483c0 RCX: ffff8881055ee2c0
RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff88810ad4848a
RBP: ffffc900001ff8b0 R08: ffffffff82446cef R09: ffffffff82446c86
R10: 0000000000000004 R11: ffff8881055ee2c0 R12: dffffc0000000000
R13: ffffc900001ff980 R14: ffff888109ee8800 R15: 1ffff9200003ff30
FS: 0000000000000000(0000) GS:ffff8881f7100000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000020ea9000 CR3: 000000000640f000 CR4: 00000000003506a0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
__blk_mq_do_dispatch_sched block/blk-mq-sched.c:186 [inline]
blk_mq_do_dispatch_sched+0x623/0xbb0 block/blk-mq-sched.c:199
__blk_mq_sched_dispatch_requests+0x3de/0x4d0 block/blk-mq-sched.c:310
blk_mq_sched_dispatch_requests+0xf0/0x160 block/blk-mq-sched.c:341
__blk_mq_run_hw_queue+0x14f/0x260 block/blk-mq.c:1521
__blk_mq_delay_run_hw_queue+0x230/0x570 block/blk-mq.c:1598
blk_mq_run_hw_queue+0x29d/0x3b0 block/blk-mq.c:1651
blk_mq_run_hw_queues+0x37c/0x450 block/blk-mq.c:1714
blk_mq_requeue_work+0x7e6/0x830 block/blk-mq.c:819
process_one_work+0x6b4/0xfb0 kernel/workqueue.c:2289
worker_thread+0xb15/0x1600 kernel/workqueue.c:2435
kthread+0x371/0x390 kernel/kthread.c:313
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:296
Modules linked in:
---[ end trace 7cdd9467215c6dd9 ]---
RIP: 0010:blk_mq_end_request block/blk-mq.c:567 [inline]
RIP: 0010:blk_mq_dispatch_rq_list+0x17d2/0x17e0 block/blk-mq.c:1395
Code: 61 ff e9 45 f5 ff ff 44 89 e9 80 e1 07 80 c1 03 38 c1 0f 8c 70 f6 ff ff 4c 89 ef e8 c8 20 61 ff e9 63 f6 ff ff e8 ce 43 27 ff <0f> 0b e8 67 27 55 02 0f 1f 80 00 00 00 00 55 48 89 e5 41 57 41 56
RSP: 0018:ffffc900001ff740 EFLAGS: 00010293
RAX: ffffffff82459bf2 RBX: ffff88810ad483c0 RCX: ffff8881055ee2c0
RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff88810ad4848a
RBP: ffffc900001ff8b0 R08: ffffffff82446cef R09: ffffffff82446c86
R10: 0000000000000004 R11: ffff8881055ee2c0 R12: dffffc0000000000
R13: ffffc900001ff980 R14: ffff888109ee8800 R15: 1ffff9200003ff30
FS: 0000000000000000(0000) GS:ffff8881f7100000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000020ea9000 CR3: 000000000640f000 CR4: 00000000003506a0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Jan 2, 2022, 12:12:16 AM1/2/22
to syzkaller-a...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 9b28b48fb343 Merge 5.10.89 into android12-5.10-lts
git tree: android12-5.10-lts
console output: https://syzkaller.appspot.com/x/log.txt?x=178c2259b00000
kernel config: https://syzkaller.appspot.com/x/.config?x=194b6725650cc3e2
dashboard link: https://syzkaller.appspot.com/bug?extid=4f441e6ca0fcad141421
compiler: Debian clang version 11.0.1-2, GNU ld (GNU Binutils for Debian) 2.35.2
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=13a89557b00000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+4f441e...@syzkaller.appspotmail.com

ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:296
---[ end trace 45215325d82abb44 ]---
blk_update_request: I/O error, dev sda, sector 1015800 op 0x1:(WRITE) flags 0xc800 phys_seg 0 prio class 0
------------[ cut here ]------------
kernel BUG at block/blk-mq.c:567!
invalid opcode: 0000 [#1] PREEMPT SMP KASAN
CPU: 1 PID: 78 Comm: kworker/1:1H Tainted: G W 5.10.89-syzkaller-00788-g9b28b48fb343 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Workqueue: kblockd blk_mq_requeue_work
RIP: 0010:blk_mq_end_request block/blk-mq.c:567 [inline]
RIP: 0010:blk_mq_dispatch_rq_list+0x17d2/0x17e0 block/blk-mq.c:1395
Code: 61 ff e9 45 f5 ff ff 44 89 e9 80 e1 07 80 c1 03 38 c1 0f 8c 70 f6 ff ff 4c 89 ef e8 c8 20 61 ff e9 63 f6 ff ff e8 ce 43 27 ff <0f> 0b e8 67 27 55 02 0f 1f 80 00 00 00 00 55 48 89 e5 41 57 41 56
RSP: 0018:ffffc9000030f740 EFLAGS: 00010293
RAX: ffffffff82459bf2 RBX: ffff88810a9394c0 RCX: ffff888105582780
RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff88810a93958a
RBP: ffffc9000030f8b0 R08: ffffffff82446cef R09: ffffffff82446c86
R10: 0000000000000004 R11: ffff888105582780 R12: dffffc0000000000
R13: ffffc9000030f980 R14: ffff888109dcc800 R15: 1ffff92000061f30
FS: 0000000000000000(0000) GS:ffff8881f7100000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000021000000 CR3: 00000001219c9000 CR4: 00000000003506a0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
__blk_mq_do_dispatch_sched block/blk-mq-sched.c:186 [inline]
blk_mq_do_dispatch_sched+0x623/0xbb0 block/blk-mq-sched.c:199
__blk_mq_sched_dispatch_requests+0x3de/0x4d0 block/blk-mq-sched.c:310
blk_mq_sched_dispatch_requests+0xf0/0x160 block/blk-mq-sched.c:341
__blk_mq_run_hw_queue+0x14f/0x260 block/blk-mq.c:1521
__blk_mq_delay_run_hw_queue+0x230/0x570 block/blk-mq.c:1598
blk_mq_run_hw_queue+0x29d/0x3b0 block/blk-mq.c:1651
blk_mq_run_hw_queues+0x37c/0x450 block/blk-mq.c:1714
blk_mq_requeue_work+0x7e6/0x830 block/blk-mq.c:819
process_one_work+0x6b4/0xfb0 kernel/workqueue.c:2289
worker_thread+0xb15/0x1600 kernel/workqueue.c:2435
kthread+0x371/0x390 kernel/kthread.c:313
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:296
Modules linked in:
---[ end trace 45215325d82abb45 ]---
RIP: 0010:blk_mq_end_request block/blk-mq.c:567 [inline]
RIP: 0010:blk_mq_dispatch_rq_list+0x17d2/0x17e0 block/blk-mq.c:1395
Code: 61 ff e9 45 f5 ff ff 44 89 e9 80 e1 07 80 c1 03 38 c1 0f 8c 70 f6 ff ff 4c 89 ef e8 c8 20 61 ff e9 63 f6 ff ff e8 ce 43 27 ff <0f> 0b e8 67 27 55 02 0f 1f 80 00 00 00 00 55 48 89 e5 41 57 41 56
RSP: 0018:ffffc9000030f740 EFLAGS: 00010293
RAX: ffffffff82459bf2 RBX: ffff88810a9394c0 RCX: ffff888105582780
RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff88810a93958a
RBP: ffffc9000030f8b0 R08: ffffffff82446cef R09: ffffffff82446c86
R10: 0000000000000004 R11: ffff888105582780 R12: dffffc0000000000
R13: ffffc9000030f980 R14: ffff888109dcc800 R15: 1ffff92000061f30
FS: 0000000000000000(0000) GS:ffff8881f7100000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000021000000 CR3: 00000001219c9000 CR4: 00000000003506a0

syzbot

unread,
May 29, 2022, 4:57:19 PM5/29/22
to syzkaller-a...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 0974b8411a58 Merge 5.10.117 into android12-5.10-lts
git tree: android12-5.10-lts
console+strace: https://syzkaller.appspot.com/x/log.txt?x=13332abdf00000
kernel config: https://syzkaller.appspot.com/x/.config?x=298c89d0104c8e66
dashboard link: https://syzkaller.appspot.com/bug?extid=4f441e6ca0fcad141421
compiler: Debian clang version 13.0.1-++20220126092033+75e33f71c2da-1~exp1~20220126212112.63, GNU ld (GNU Binutils for Debian) 2.35.2
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=14123b9df00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1520cb7bf00000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+4f441e...@syzkaller.appspotmail.com

------------[ cut here ]------------
kernel BUG at block/blk-mq.c:567!
invalid opcode: 0000 [#1] PREEMPT SMP KASAN
CPU: 1 PID: 78 Comm: kworker/1:1H Tainted: G W 5.10.117-syzkaller-00813-g0974b8411a58 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Workqueue: kblockd blk_mq_requeue_work
RIP: 0010:blk_mq_end_request block/blk-mq.c:567 [inline]
RIP: 0010:blk_mq_dispatch_rq_list+0x17f5/0x1800 block/blk-mq.c:1395
Code: 68 ff e9 24 f5 ff ff 44 89 e9 80 e1 07 80 c1 03 38 c1 0f 8c 25 fe ff ff 4c 89 ef e8 e5 b5 68 ff e9 18 fe ff ff e8 fb df 2e ff <0f> 0b e8 74 e8 52 02 0f 1f 40 00 55 48 89 e5 41 57 41 56 41 55 41
RSP: 0018:ffffc900002ef700 EFLAGS: 00010293
RAX: ffffffff823dd255 RBX: ffff88810a9061c0 RCX: ffff888105198000
RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff88810a90628a
RBP: ffffc900002ef870 R08: ffffffff823ca37f R09: ffffffff823ca315
R10: 0000000000000004 R11: ffff888105198000 R12: dffffc0000000000
R13: ffffc900002ef960 R14: ffff888109edb000 R15: 1ffff9200005df2c
FS: 0000000000000000(0000) GS:ffff8881f7100000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000021000000 CR3: 0000000124208000 CR4: 00000000003506a0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
__blk_mq_do_dispatch_sched block/blk-mq-sched.c:186 [inline]
blk_mq_do_dispatch_sched+0x63c/0xc60 block/blk-mq-sched.c:200
__blk_mq_sched_dispatch_requests+0x3de/0x4d0 block/blk-mq-sched.c:317
blk_mq_sched_dispatch_requests+0xf0/0x160 block/blk-mq-sched.c:348
__blk_mq_run_hw_queue+0x14d/0x260 block/blk-mq.c:1521
__blk_mq_delay_run_hw_queue+0x22a/0x570 block/blk-mq.c:1598
blk_mq_run_hw_queue+0x29d/0x3b0 block/blk-mq.c:1651
blk_mq_run_hw_queues+0x37c/0x450 block/blk-mq.c:1714
blk_mq_requeue_work+0x73b/0x780 block/blk-mq.c:819
process_one_work+0x726/0xc10 kernel/workqueue.c:2296
worker_thread+0xb27/0x1550 kernel/workqueue.c:2442
kthread+0x349/0x3d0 kernel/kthread.c:313
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:296
Modules linked in:
---[ end trace 99a8cc52f99adc54 ]---
RIP: 0010:blk_mq_end_request block/blk-mq.c:567 [inline]
RIP: 0010:blk_mq_dispatch_rq_list+0x17f5/0x1800 block/blk-mq.c:1395
Code: 68 ff e9 24 f5 ff ff 44 89 e9 80 e1 07 80 c1 03 38 c1 0f 8c 25 fe ff ff 4c 89 ef e8 e5 b5 68 ff e9 18 fe ff ff e8 fb df 2e ff <0f> 0b e8 74 e8 52 02 0f 1f 40 00 55 48 89 e5 41 57 41 56 41 55 41
RSP: 0018:ffffc900002ef700 EFLAGS: 00010293
RAX: ffffffff823dd255 RBX: ffff88810a9061c0 RCX: ffff888105198000
RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff88810a90628a
RBP: ffffc900002ef870 R08: ffffffff823ca37f R09: ffffffff823ca315
R10: 0000000000000004 R11: ffff888105198000 R12: dffffc0000000000
R13: ffffc900002ef960 R14: ffff888109edb000 R15: 1ffff9200005df2c
FS: 0000000000000000(0000) GS:ffff8881f7100000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000021000000 CR3: 0000000124208000 CR4: 00000000003506a0
Reply all
Reply to author
Forward
0 new messages