kernel BUG in blk_mq_dispatch_rq_list (4)

66 views
Skip to first unread message

syzbot

unread,
Oct 24, 2022, 12:39:37 AM10/24/22
to syzkaller-a...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 69a9a62c66bb ANDROID: GKI: db845c: Update symbols list and..
git tree: android12-5.10-lts
console+strace: https://syzkaller.appspot.com/x/log.txt?x=16303a8c880000
kernel config: https://syzkaller.appspot.com/x/.config?x=585a67b78cadff5
dashboard link: https://syzkaller.appspot.com/bug?extid=c2989769f21f785cc194
compiler: Debian clang version 13.0.1-++20220126092033+75e33f71c2da-1~exp1~20220126212112.63, GNU ld (GNU Binutils for Debian) 2.35.2
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=15a0bb6e880000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=115d3616880000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/094b80968b81/disk-69a9a62c.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/ce1105001a2b/vmlinux-69a9a62c.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+c29897...@syzkaller.appspotmail.com

blk_update_request: I/O error, dev sda, sector 589816 op 0x1:(WRITE) flags 0xc800 phys_seg 0 prio class 0
------------[ cut here ]------------
kernel BUG at block/blk-mq.c:569!
invalid opcode: 0000 [#1] PREEMPT SMP KASAN
CPU: 1 PID: 78 Comm: kworker/1:1H Tainted: G W 5.10.149-syzkaller-01404-g69a9a62c66bb #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/11/2022
Workqueue: kblockd blk_mq_requeue_work
RIP: 0010:blk_mq_end_request block/blk-mq.c:569 [inline]
RIP: 0010:blk_mq_dispatch_rq_list+0x17ef/0x1800 block/blk-mq.c:1397
Code: 68 ff e9 63 f5 ff ff 44 89 e9 80 e1 07 80 c1 03 38 c1 0f 8c 83 f6 ff ff 4c 89 ef e8 3b 7d 68 ff e9 76 f6 ff ff e8 b1 65 2e ff <0f> 0b e8 4a 5f 54 02 66 2e 0f 1f 84 00 00 00 00 00 55 48 89 e5 41
RSP: 0018:ffffc900001ff6e0 EFLAGS: 00010293
RAX: ffffffff823e855f RBX: ffff88810a900000 RCX: ffff8881065f93c0
RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff88810a9000ca
RBP: ffffc900001ff870 R08: ffffffff823d563f R09: ffffffff823d55d5
R10: 0000000000000004 R11: ffff8881065f93c0 R12: dffffc0000000000
R13: ffffc900001ff960 R14: ffffc900001ff800 R15: ffff8881017cf000
FS: 0000000000000000(0000) GS:ffff8881f7100000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000020c17000 CR3: 000000011f66a000 CR4: 00000000003506a0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
__blk_mq_do_dispatch_sched block/blk-mq-sched.c:186 [inline]
blk_mq_do_dispatch_sched+0x63c/0xc60 block/blk-mq-sched.c:200
__blk_mq_sched_dispatch_requests+0x3de/0x4d0 block/blk-mq-sched.c:317
blk_mq_sched_dispatch_requests+0xf0/0x160 block/blk-mq-sched.c:348
__blk_mq_run_hw_queue+0x14d/0x260 block/blk-mq.c:1524
__blk_mq_delay_run_hw_queue+0x22a/0x570 block/blk-mq.c:1601
blk_mq_run_hw_queue+0x29d/0x3b0 block/blk-mq.c:1654
blk_mq_run_hw_queues+0x37c/0x450 block/blk-mq.c:1717
blk_mq_requeue_work+0x73b/0x780 block/blk-mq.c:821
process_one_work+0x726/0xc10 kernel/workqueue.c:2296
worker_thread+0xb27/0x1550 kernel/workqueue.c:2442
kthread+0x349/0x3d0 kernel/kthread.c:313
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:299
Modules linked in:
---[ end trace f7276246772db3d7 ]---
RIP: 0010:blk_mq_end_request block/blk-mq.c:569 [inline]
RIP: 0010:blk_mq_dispatch_rq_list+0x17ef/0x1800 block/blk-mq.c:1397
Code: 68 ff e9 63 f5 ff ff 44 89 e9 80 e1 07 80 c1 03 38 c1 0f 8c 83 f6 ff ff 4c 89 ef e8 3b 7d 68 ff e9 76 f6 ff ff e8 b1 65 2e ff <0f> 0b e8 4a 5f 54 02 66 2e 0f 1f 84 00 00 00 00 00 55 48 89 e5 41
RSP: 0018:ffffc900001ff6e0 EFLAGS: 00010293
RAX: ffffffff823e855f RBX: ffff88810a900000 RCX: ffff8881065f93c0
RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff88810a9000ca
RBP: ffffc900001ff870 R08: ffffffff823d563f R09: ffffffff823d55d5
R10: 0000000000000004 R11: ffff8881065f93c0 R12: dffffc0000000000
R13: ffffc900001ff960 R14: ffffc900001ff800 R15: ffff8881017cf000
FS: 0000000000000000(0000) GS:ffff8881f7100000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000020c17000 CR3: 000000011f66a000 CR4: 00000000003506a0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this issue, for details see:
https://goo.gl/tpsmEJ#testing-patches

Lee Jones

unread,
Nov 4, 2022, 6:50:14 AM11/4/22
to syzkaller-android-bugs
This is a test.

nogikh

unread,
Nov 4, 2022, 6:52:54 AM11/4/22
to syzkaller-android-bugs
One more test (to see the recipients and to see if the bot reacts).

#syz test: some-invalid-repo

syzbot

unread,
Nov 4, 2022, 6:52:56 AM11/4/22
to 'nogikh' via syzkaller-android-bugs, syzkaller-a...@googlegroups.com
> One more test (to see the recipients and to see if the bot reacts).
>
> #syz test: some-invalid-repo

I see the command but can't find the corresponding bug.
Please resend the email to syzbo...@syzkaller.appspotmail.com address
that is the sender of the bug report (also present in the Reported-by tag).
> --
> You received this message because you are subscribed to the Google Groups "syzkaller-android-bugs" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to syzkaller-android...@googlegroups.com.
> To view this discussion on the web visit https://groups.google.com/d/msgid/syzkaller-android-bugs/8040c2ff-6d89-4500-a30c-718a6e13b633n%40googlegroups.com.

nogikh

unread,
Nov 4, 2022, 7:00:35 AM11/4/22
to syzkaller-android-bugs
test (2)

On Monday, October 24, 2022 at 6:39:37 AM UTC+2 syzbot wrote:

nogikh

unread,
Nov 4, 2022, 7:19:55 AM11/4/22
to syzkaller-android-bugs
test (3)

On Monday, October 24, 2022 at 6:39:37 AM UTC+2 syzbot wrote:

nogikh

unread,
Nov 7, 2022, 5:53:27 AM11/7/22
to syzkaller-android-bugs
#syz test: some-invalid-repo2

On Monday, October 24, 2022 at 6:39:37 AM UTC+2 syzbot wrote:

syzbot

unread,
Nov 7, 2022, 5:53:31 AM11/7/22
to 'nogikh' via syzkaller-android-bugs, syzkaller-a...@googlegroups.com
> #syz test: some-invalid-repo2

I see the command but can't find the corresponding bug.
Please resend the email to syzbo...@syzkaller.appspotmail.com address
that is the sender of the bug report (also present in the Reported-by tag).

>
> --
> You received this message because you are subscribed to the Google Groups "syzkaller-android-bugs" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to syzkaller-android...@googlegroups.com.
> To view this discussion on the web visit https://groups.google.com/d/msgid/syzkaller-android-bugs/0f3d75dd-e0ed-4544-86bc-b1c4866392f1n%40googlegroups.com.

nogikh

unread,
Nov 7, 2022, 5:56:24 AM11/7/22
to syzkaller-android-bugs
#syz test: some-invalid-repo3

On Monday, October 24, 2022 at 6:39:37 AM UTC+2 syzbot wrote:

syzbot

unread,
Nov 7, 2022, 5:56:28 AM11/7/22
to 'nogikh' via syzkaller-android-bugs, syzkaller-a...@googlegroups.com
> #syz test: some-invalid-repo3

I see the command but can't find the corresponding bug.
Please resend the email to syzbo...@syzkaller.appspotmail.com address
that is the sender of the bug report (also present in the Reported-by tag).

>
> --
> You received this message because you are subscribed to the Google Groups "syzkaller-android-bugs" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to syzkaller-android...@googlegroups.com.
> To view this discussion on the web visit https://groups.google.com/d/msgid/syzkaller-android-bugs/261c331d-ab7a-4543-a98b-e3d2703a658an%40googlegroups.com.

syzbot

unread,
Jan 29, 2023, 9:11:36 PM1/29/23
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com
This bug is marked as fixed by commit:
block: set .bi_max_vecs as actual allocated vector number

But I can't find it in the tested trees[1] for more than 90 days.
Is it a correct commit? Please update it by replying:

#syz fix: exact-commit-title

Until then the bug is still considered open and new crashes with
the same signature are ignored.

Kernel: Android 5.10
Dashboard link: https://syzkaller.appspot.com/bug?extid=c2989769f21f785cc194

---
[1] I expect the commit to be present in:

1. android12-5.10-lts branch of
https://android.googlesource.com/kernel/common

syzbot

unread,
Feb 12, 2023, 9:11:41 PM2/12/23
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
Feb 26, 2023, 9:12:38 PM2/26/23
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
Mar 12, 2023, 10:13:41 PM3/12/23
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
Mar 26, 2023, 10:14:36 PM3/26/23
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
Apr 9, 2023, 10:15:30 PM4/9/23
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
Apr 23, 2023, 10:15:33 PM4/23/23
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
May 7, 2023, 10:16:02 PM5/7/23
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com
This bug is marked as fixed by commit:
block: set .bi_max_vecs as actual allocated vector number

But I can't find it in the tested trees[1] for more than 90 days.
Is it a correct commit? Please update it by replying:

#syz fix: exact-commit-title

Until then the bug is still considered open and new crashes with
the same signature are ignored.

Kernel: Android 5.10
Dashboard link: https://syzkaller.appspot.com/bug?extid=c2989769f21f785cc194

---
[1] I expect the commit to be present in:

1. android13-5.10-lts branch of
https://android.googlesource.com/kernel/common

syzbot

unread,
May 21, 2023, 10:16:44 PM5/21/23
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
Jun 4, 2023, 10:17:49 PM6/4/23
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
Jun 18, 2023, 10:18:34 PM6/18/23
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
Jul 2, 2023, 10:18:53 PM7/2/23
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
Jul 16, 2023, 10:19:45 PM7/16/23
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
Jul 30, 2023, 10:20:42 PM7/30/23
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
Aug 13, 2023, 10:21:45 PM8/13/23
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
Aug 27, 2023, 10:23:38 PM8/27/23
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
Sep 10, 2023, 10:24:38 PM9/10/23
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
Sep 24, 2023, 10:25:28 PM9/24/23
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
Oct 8, 2023, 10:25:45 PM10/8/23
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
Oct 22, 2023, 10:26:50 PM10/22/23
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
Nov 5, 2023, 9:27:18 PM11/5/23
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
Nov 19, 2023, 9:28:16 PM11/19/23
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
Dec 3, 2023, 9:29:18 PM12/3/23
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
Dec 17, 2023, 9:30:14 PM12/17/23
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
Dec 31, 2023, 9:31:15 PM12/31/23
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
Jan 14, 2024, 9:32:13 PMJan 14
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
Jan 28, 2024, 9:32:21 PMJan 28
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
Feb 11, 2024, 9:33:15 PMFeb 11
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
Feb 25, 2024, 9:34:11 PMFeb 25
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
Mar 10, 2024, 10:34:16 PMMar 10
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
Mar 24, 2024, 10:35:16 PMMar 24
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
Apr 7, 2024, 10:35:20 PMApr 7
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
Apr 21, 2024, 10:36:21 PMApr 21
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com

syzbot

unread,
May 5, 2024, 10:37:16 PM (16 hours ago) May 5
to jone...@google.com, jun...@linaro.org, nog...@google.com, peter....@linaro.org, syzkaller-a...@googlegroups.com
Reply all
Reply to author
Forward
0 new messages