kernel BUG in ext4_ind_remove_space

6 views
Skip to first unread message

syzbot

unread,
Jan 20, 2022, 12:58:27 AM1/20/22
to syzkaller-a...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 946eff433f93 UPSTREAM: vfs: fs_context: fix up param lengt..
git tree: android12-5.4
console output: https://syzkaller.appspot.com/x/log.txt?x=15c89d88700000
kernel config: https://syzkaller.appspot.com/x/.config?x=8844969a6709ae53
dashboard link: https://syzkaller.appspot.com/bug?extid=60224fb0b28144ba93b7
compiler: Debian clang version 11.0.1-2, GNU ld (GNU Binutils for Debian) 2.35.2
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=177526ffb00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1751ea50700000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+60224f...@syzkaller.appspotmail.com

EXT4-fs warning (device sda1): ext4_block_to_path:107: block 1074791436 > max in inode 1137
------------[ cut here ]------------
kernel BUG at fs/ext4/indirect.c:1235!
invalid opcode: 0000 [#1] PREEMPT SMP KASAN
CPU: 1 PID: 298 Comm: syz-executor272 Not tainted 5.4.147-syzkaller-00003-g946eff433f93 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
RIP: 0010:ext4_ind_remove_space+0x2033/0x2040 fs/ext4/indirect.c:1235
Code: f8 ff ff 89 d9 80 e1 07 80 c1 03 38 c1 0f 8c 0e f2 ff ff 48 89 df e8 ec 74 d4 ff e9 01 f2 ff ff e8 42 de 80 ff e8 0d 58 a7 ff <0f> 0b 66 66 2e 0f 1f 84 00 00 00 00 00 55 41 57 41 56 41 55 41 54
RSP: 0018:ffff8881de8cfbd0 EFLAGS: 00010293
RAX: ffffffff81b978b3 RBX: 0000000000000000 RCX: ffff8881e055ee40
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000003
RBP: ffff8881de8cfd58 R08: ffffffff81b961a1 R09: ffffed103ede9608
R10: ffffed103ede9608 R11: 0000000000000000 R12: ffff8881de8cfd00
R13: dffffc0000000000 R14: 000000004010040c R15: 0000000000000000
FS: 0000555555e25300(0000) GS:ffff8881f6f00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000020400002 CR3: 00000001e0601000 CR4: 00000000003406e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
ext4_punch_hole+0x8bb/0xf50 fs/ext4/inode.c:4455
ext4_fallocate+0x11c/0x800 fs/ext4/extents.c:4902
vfs_fallocate+0x564/0x840 fs/open.c:309
ksys_fallocate fs/open.c:332 [inline]
__do_sys_fallocate fs/open.c:340 [inline]
__se_sys_fallocate fs/open.c:338 [inline]
__x64_sys_fallocate+0xb9/0x100 fs/open.c:338
do_syscall_64+0xcb/0x1e0 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x44/0xa9
RIP: 0033:0x7f633df220d9
Code: 28 c3 e8 2a 14 00 00 66 2e 0f 1f 84 00 00 00 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 c0 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ffe1244a6b8 EFLAGS: 00000246 ORIG_RAX: 000000000000011d
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f633df220d9
RDX: 0000000001000000 RSI: 0000000000000003 RDI: 0000000000000005
RBP: 00007f633dee60c0 R08: 0000000000000000 R09: 0000000000000000
R10: 00000ffeffeff000 R11: 0000000000000246 R12: 00007f633dee6150
R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000
Modules linked in:
---[ end trace ba1df9e04d91cd37 ]---
RIP: 0010:ext4_ind_remove_space+0x2033/0x2040 fs/ext4/indirect.c:1235
Code: f8 ff ff 89 d9 80 e1 07 80 c1 03 38 c1 0f 8c 0e f2 ff ff 48 89 df e8 ec 74 d4 ff e9 01 f2 ff ff e8 42 de 80 ff e8 0d 58 a7 ff <0f> 0b 66 66 2e 0f 1f 84 00 00 00 00 00 55 41 57 41 56 41 55 41 54
RSP: 0018:ffff8881de8cfbd0 EFLAGS: 00010293
RAX: ffffffff81b978b3 RBX: 0000000000000000 RCX: ffff8881e055ee40
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000003
RBP: ffff8881de8cfd58 R08: ffffffff81b961a1 R09: ffffed103ede9608
R10: ffffed103ede9608 R11: 0000000000000000 R12: ffff8881de8cfd00
R13: dffffc0000000000 R14: 000000004010040c R15: 0000000000000000
FS: 0000555555e25300(0000) GS:ffff8881f6f00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000020400002 CR3: 00000001e0601000 CR4: 00000000003406e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this issue, for details see:
https://goo.gl/tpsmEJ#testing-patches

syzbot

unread,
Jan 20, 2022, 7:03:30 AM1/20/22
to syzkaller-a...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: f45f895af546 Merge branch 'android12-5.10' into `android12..
git tree: android12-5.10-lts
console output: https://syzkaller.appspot.com/x/log.txt?x=13b34d60700000
kernel config: https://syzkaller.appspot.com/x/.config?x=d10f5fc2051a847d
dashboard link: https://syzkaller.appspot.com/bug?extid=7a806094edd5d07ba029
compiler: Debian clang version 11.0.1-2, GNU ld (GNU Binutils for Debian) 2.35.2
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=11c700a8700000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=14ba0238700000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+7a8060...@syzkaller.appspotmail.com

EXT4-fs warning (device sda1): ext4_block_to_path:107: block 1074791436 > max in inode 1137
------------[ cut here ]------------
kernel BUG at fs/ext4/indirect.c:1239!
invalid opcode: 0000 [#1] PREEMPT SMP KASAN
CPU: 1 PID: 365 Comm: syz-executor042 Not tainted 5.10.92-syzkaller-01003-gf45f895af546 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
RIP: 0010:ext4_ind_remove_space+0x2309/0x2310 fs/ext4/indirect.c:1239
Code: f2 ff ff 89 d9 80 e1 07 80 c1 03 38 c1 0f 8c 84 f3 ff ff 48 89 df e8 16 0b c7 ff e9 77 f3 ff ff e8 9c 67 bb 02 e8 27 16 8d ff <0f> 0b 0f 1f 44 00 00 55 48 89 e5 41 57 41 56 41 55 41 54 53 48 83
RSP: 0018:ffffc90000b67b00 EFLAGS: 00010293
RAX: ffffffff81dfd559 RBX: 0000000000000003 RCX: ffff88810758a780
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: ffffc90000b67d60 R08: ffffffff81dfba39 R09: ffffed103ee2a5d8
R10: ffffed103ee2a5d8 R11: 0000000000000000 R12: dffffc0000000000
R13: ffffc90000b67cf0 R14: ffffc90000b67be0 R15: 0000000000000000
FS: 00005555555d9300(0000) GS:ffff8881f7100000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000020400002 CR3: 000000011cf64000 CR4: 00000000003506a0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
ext4_punch_hole+0x8cc/0xf70 fs/ext4/inode.c:4159
ext4_fallocate+0x125/0x760 fs/ext4/extents.c:4694
vfs_fallocate+0x5e7/0xa90 fs/open.c:310
ksys_fallocate fs/open.c:333 [inline]
__do_sys_fallocate fs/open.c:341 [inline]
__se_sys_fallocate fs/open.c:339 [inline]
__x64_sys_fallocate+0xc0/0x110 fs/open.c:339
do_syscall_64+0x31/0x70 arch/x86/entry/common.c:46
entry_SYSCALL_64_after_hwframe+0x44/0xa9
RIP: 0033:0x7f86a69310d9
Code: 28 c3 e8 2a 14 00 00 66 2e 0f 1f 84 00 00 00 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 c0 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ffe0cd01098 EFLAGS: 00000246 ORIG_RAX: 000000000000011d
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f86a69310d9
RDX: 0000000001000000 RSI: 0000000000000003 RDI: 0000000000000005
RBP: 00007f86a68f50c0 R08: 0000000000000000 R09: 0000000000000000
R10: 00000ffeffeff000 R11: 0000000000000246 R12: 00007f86a68f5150
R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000
Modules linked in:
---[ end trace e7147ca29bc31338 ]---
RIP: 0010:ext4_ind_remove_space+0x2309/0x2310 fs/ext4/indirect.c:1239
Code: f2 ff ff 89 d9 80 e1 07 80 c1 03 38 c1 0f 8c 84 f3 ff ff 48 89 df e8 16 0b c7 ff e9 77 f3 ff ff e8 9c 67 bb 02 e8 27 16 8d ff <0f> 0b 0f 1f 44 00 00 55 48 89 e5 41 57 41 56 41 55 41 54 53 48 83
RSP: 0018:ffffc90000b67b00 EFLAGS: 00010293
RAX: ffffffff81dfd559 RBX: 0000000000000003 RCX: ffff88810758a780
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: ffffc90000b67d60 R08: ffffffff81dfba39 R09: ffffed103ee2a5d8
R10: ffffed103ee2a5d8 R11: 0000000000000000 R12: dffffc0000000000
R13: ffffc90000b67cf0 R14: ffffc90000b67be0 R15: 0000000000000000
FS: 00005555555d9300(0000) GS:ffff8881f7100000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000020400002 CR3: 000000011cf64000 CR4: 00000000003506a0
Reply all
Reply to author
Forward
0 new messages