[v6.1] WARNING in mark_buffer_dirty

10 views
Skip to first unread message

syzbot

unread,
Mar 13, 2023, 10:09:50 AM3/13/23
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 6449a0ba6843 Linux 6.1.19
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=171a92dcc80000
kernel config: https://syzkaller.appspot.com/x/.config?x=9ed8b3ec03e8c126
dashboard link: https://syzkaller.appspot.com/bug?extid=9f01f4e38d051c1b0cff
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/0ad616da3180/disk-6449a0ba.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/42677a30acb3/vmlinux-6449a0ba.xz
kernel image: https://storage.googleapis.com/syzbot-assets/2e21fe35d03d/bzImage-6449a0ba.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+9f01f4...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 1 PID: 3651 at fs/buffer.c:1081 mark_buffer_dirty+0x47b/0x8b0
Modules linked in:
CPU: 1 PID: 3651 Comm: syz-executor.0 Not tainted 6.1.19-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/02/2023
RIP: 0010:mark_buffer_dirty+0x47b/0x8b0 fs/buffer.c:1081
Code: c7 e0 c3 f9 8a be 3f 00 00 00 48 c7 c2 20 c4 f9 8a e8 69 f3 6a ff e9 e2 fc ff ff e8 ff b5 8a ff e9 e0 fe ff ff e8 f5 b5 8a ff <0f> 0b e9 cc fb ff ff e8 e9 b5 8a ff 0f 0b e9 0f fc ff ff e8 dd b5
RSP: 0018:ffffc9000449f8a8 EFLAGS: 00010293
RAX: ffffffff81ffab2b RBX: ffff88804c18f401 RCX: ffff888076538000
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: 0000000000000000 R08: ffffffff81ffa6f1 R09: ffffed1009871b97
R10: 0000000000000000 R11: dffffc0000000001 R12: 0000000000000007
R13: dffffc0000000000 R14: ffffc9000449f920 R15: ffff88804c38dcb0
FS: 0000555556a40400(0000) GS:ffff8880b9900000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fa5749b75a8 CR3: 000000005333d000 CR4: 00000000003506e0
Call Trace:
<TASK>
__nilfs_mark_inode_dirty+0x101/0x280 fs/nilfs2/inode.c:1097
nilfs_mark_inode_dirty fs/nilfs2/nilfs.h:288 [inline]
nilfs_evict_inode+0x185/0x420 fs/nilfs2/inode.c:934
evict+0x2a4/0x620 fs/inode.c:664
__dentry_kill+0x436/0x650 fs/dcache.c:607
shrink_dentry_list+0x398/0x6a0 fs/dcache.c:1201
shrink_dcache_parent+0xc9/0x480
do_one_tree+0x23/0xe0 fs/dcache.c:1682
shrink_dcache_for_umount+0x79/0x120 fs/dcache.c:1699
generic_shutdown_super+0x63/0x340 fs/super.c:473
kill_block_super+0x7a/0xe0 fs/super.c:1441
deactivate_locked_super+0xa0/0x110 fs/super.c:332
cleanup_mnt+0x490/0x520 fs/namespace.c:1186
task_work_run+0x246/0x300 kernel/task_work.c:179
resume_user_mode_work include/linux/resume_user_mode.h:49 [inline]
exit_to_user_mode_loop+0xd9/0x100 kernel/entry/common.c:171
exit_to_user_mode_prepare+0xb1/0x140 kernel/entry/common.c:203
__syscall_exit_to_user_mode_work kernel/entry/common.c:285 [inline]
syscall_exit_to_user_mode+0x60/0x2d0 kernel/entry/common.c:296
do_syscall_64+0x49/0xb0 arch/x86/entry/common.c:86
entry_SYSCALL_64_after_hwframe+0x63/0xcd
RIP: 0033:0x7fb01808d567
Code: ff ff ff f7 d8 64 89 01 48 83 c8 ff c3 66 0f 1f 44 00 00 31 f6 e9 09 00 00 00 66 0f 1f 84 00 00 00 00 00 b8 a6 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ffd4a076f58 EFLAGS: 00000246 ORIG_RAX: 00000000000000a6
RAX: 0000000000000000 RBX: 0000000000000000 RCX: 00007fb01808d567
RDX: 00007ffd4a07702c RSI: 000000000000000a RDI: 00007ffd4a077020
RBP: 00007ffd4a077020 R08: 00000000ffffffff R09: 00007ffd4a076df0
R10: 0000555556a418b3 R11: 0000000000000246 R12: 00007fb0180e6b24
R13: 00007ffd4a0780e0 R14: 0000555556a41810 R15: 00007ffd4a078120
</TASK>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Mar 15, 2023, 6:11:46 PM3/15/23
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 6449a0ba6843 Linux 6.1.19
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=11f89bccc80000
kernel config: https://syzkaller.appspot.com/x/.config?x=75eadb21ef1208e4
dashboard link: https://syzkaller.appspot.com/bug?extid=9f01f4e38d051c1b0cff
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=110a2f42c80000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=123d6972c80000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/dc227ecd3e21/disk-6449a0ba.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/1d08e21b50c2/vmlinux-6449a0ba.xz
kernel image: https://storage.googleapis.com/syzbot-assets/71a43f2c4d2c/Image-6449a0ba.gz.xz
mounted in repro: https://storage.googleapis.com/syzbot-assets/45979c04a552/mount_0.gz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+9f01f4...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 1 PID: 4309 at fs/buffer.c:1081 mark_buffer_dirty+0x474/0x7c4 fs/buffer.c:1081
Modules linked in:
CPU: 1 PID: 4309 Comm: syz-executor221 Not tainted 6.1.19-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/02/2023
pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : mark_buffer_dirty+0x474/0x7c4 fs/buffer.c:1081
lr : mark_buffer_dirty+0x474/0x7c4 fs/buffer.c:1081
sp : ffff80001dc36950
x29: ffff80001dc36950 x28: ffff0000de42e200 x27: ffff0000dee45a00
x26: ffff0000dd688008 x25: ffff0000d9004018 x24: ffff0000dfc5c9f8
x23: ffff0000dfc5c658 x22: ffff0000d9004160 x21: ffff0000dd688018
x20: 0000000000000010 x19: ffff0000dfc5c9f8 x18: 0000000000000150
x17: ffff80001572d000 x16: ffff8000121a2440 x15: 0000000000000000
x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000001
x11: ff80800008b3b9e0 x10: 0000000000000000 x9 : ffff800008b3b9e0
x8 : ffff0000ccfdb680 x7 : 0000000000000000 x6 : 0000000000000000
x5 : ffff0000dee45c00 x4 : ffff0000de42e400 x3 : ffff800008b3b59c
x2 : 0000000000000000 x1 : 0000000000000000 x0 : 0000000000000000
Call trace:
mark_buffer_dirty+0x474/0x7c4 fs/buffer.c:1081
bfs_move_block fs/bfs/file.c:43 [inline]
bfs_move_blocks fs/bfs/file.c:56 [inline]
bfs_get_block+0x6f4/0x9b4 fs/bfs/file.c:125
__block_write_begin_int+0x340/0x13b4 fs/buffer.c:1991
__block_write_begin fs/buffer.c:2041 [inline]
block_write_begin+0x98/0x11c fs/buffer.c:2102
bfs_write_begin+0x48/0xec fs/bfs/file.c:177
generic_perform_write+0x278/0x55c mm/filemap.c:3754
__generic_file_write_iter+0x168/0x388 mm/filemap.c:3882
generic_file_write_iter+0xb8/0x2b4 mm/filemap.c:3914
__kernel_write_iter+0x264/0x5f8 fs/read_write.c:517
__kernel_write+0x11c/0x174 fs/read_write.c:537
__dump_emit fs/coredump.c:804 [inline]
dump_emit+0x248/0x358 fs/coredump.c:841
elf_core_dump+0x2918/0x3714 fs/binfmt_elf.c:2291
do_coredump+0x14a0/0x2234 fs/coredump.c:755
get_signal+0xfd8/0x158c kernel/signal.c:2844
do_signal arch/arm64/kernel/signal.c:1076 [inline]
do_notify_resume+0x314/0x3470 arch/arm64/kernel/signal.c:1129
prepare_exit_to_user_mode arch/arm64/kernel/entry-common.c:137 [inline]
exit_to_user_mode arch/arm64/kernel/entry-common.c:142 [inline]
el0_da+0xb8/0x184 arch/arm64/kernel/entry-common.c:516
el0t_64_sync_handler+0xcc/0xf0 arch/arm64/kernel/entry-common.c:658
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:581
irq event stamp: 882
hardirqs last enabled at (881): [<ffff800008b3af64>] bh_lru_install fs/buffer.c:1258 [inline]
hardirqs last enabled at (881): [<ffff800008b3af64>] __find_get_block+0xcd0/0xeec fs/buffer.c:1309
hardirqs last disabled at (882): [<ffff80001224fad4>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:405
softirqs last enabled at (350): [<ffff8000080337c4>] local_bh_enable+0x10/0x34 include/linux/bottom_half.h:32
softirqs last disabled at (348): [<ffff800008033790>] local_bh_disable+0x10/0x34 include/linux/bottom_half.h:19
---[ end trace 0000000000000000 ]---

syzbot

unread,
Mar 15, 2023, 6:22:38 PM3/15/23
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 2ddbd0f967b3 Linux 5.15.102
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1734b3dcc80000
kernel config: https://syzkaller.appspot.com/x/.config?x=d6af46e4bd7d6a2f
dashboard link: https://syzkaller.appspot.com/bug?extid=5b2e10c67416270b15c0
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=16f24746c80000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1515de2ac80000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/d46a989959b6/disk-2ddbd0f9.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/4d06a9b2ddaf/vmlinux-2ddbd0f9.xz
kernel image: https://storage.googleapis.com/syzbot-assets/0921009430c0/Image-2ddbd0f9.gz.xz
mounted in repro: https://storage.googleapis.com/syzbot-assets/19b5305a50bd/mount_0.gz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+5b2e10...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 1 PID: 4057 at fs/buffer.c:1084 mark_buffer_dirty+0x42c/0x714 fs/buffer.c:1084
Modules linked in:
CPU: 1 PID: 4057 Comm: syz-executor221 Not tainted 5.15.102-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/02/2023
pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : mark_buffer_dirty+0x42c/0x714 fs/buffer.c:1084
lr : mark_buffer_dirty+0x42c/0x714 fs/buffer.c:1084
sp : ffff80001c786980
x29: ffff80001c786980 x28: ffff0000c5ec8000 x27: ffff0000dc4ad200
x26: ffff0000df534530 x25: ffff0000d99e6018 x24: ffff0000dca852b8
x23: ffff0000dca84bc8 x22: ffff0000d99e6160 x21: ffff0000df534540
x20: 0000000000000010 x19: ffff0000dca852b8 x18: 0000000000000000
x17: ff808000086d97a0 x16: ffff8000082eebe4 x15: 0000000000000000
x14: 0000000000000000 x13: ffffffffffffffff x12: 0000000000000000
x11: ff80800008a74964 x10: 0000000000000000 x9 : ffff800008a74964
x8 : ffff0000c22ab580 x7 : 0000000000000000 x6 : 0000000000000000
x5 : ffff0000dc4ad400 x4 : ffff0000c5ec8200 x3 : ffff800008a74564
x2 : 0000000000000000 x1 : 0000000000000000 x0 : 0000000000000000
Call trace:
mark_buffer_dirty+0x42c/0x714 fs/buffer.c:1084
bfs_move_block fs/bfs/file.c:43 [inline]
bfs_move_blocks fs/bfs/file.c:56 [inline]
bfs_get_block+0x6fc/0xa34 fs/bfs/file.c:125
__block_write_begin_int+0x3ec/0x1608 fs/buffer.c:2012
__block_write_begin fs/buffer.c:2062 [inline]
block_write_begin+0x60/0xdc fs/buffer.c:2122
bfs_write_begin+0x50/0xf4 fs/bfs/file.c:177
generic_perform_write+0x24c/0x520 mm/filemap.c:3776
__generic_file_write_iter+0x230/0x454 mm/filemap.c:3903
generic_file_write_iter+0xb4/0x1b8 mm/filemap.c:3935
__kernel_write+0x488/0x8b0 fs/read_write.c:539
__dump_emit+0x200/0x338 fs/coredump.c:875
dump_emit+0x288/0x36c fs/coredump.c:912
elf_core_dump+0x2888/0x3640 fs/binfmt_elf.c:2264
do_coredump+0x12c8/0x2890 fs/coredump.c:826
get_signal+0x3dc/0x1550 kernel/signal.c:2875
do_signal arch/arm64/kernel/signal.c:890 [inline]
do_notify_resume+0x320/0x32b8 arch/arm64/kernel/signal.c:943
prepare_exit_to_user_mode arch/arm64/kernel/entry-common.c:133 [inline]
exit_to_user_mode arch/arm64/kernel/entry-common.c:138 [inline]
el0_da+0x118/0x20c arch/arm64/kernel/entry-common.c:483
el0t_64_sync_handler+0xc0/0xe4 arch/arm64/kernel/entry-common.c:617
el0t_64_sync+0x1a0/0x1a4 <unknown>:584
irq event stamp: 670
hardirqs last enabled at (669): [<ffff800008a73ce0>] bh_lru_install fs/buffer.c:1261 [inline]
hardirqs last enabled at (669): [<ffff800008a73ce0>] __find_get_block+0xb68/0xdd4 fs/buffer.c:1312
hardirqs last disabled at (670): [<ffff800011a03758>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:387
softirqs last enabled at (224): [<ffff800008030cb8>] local_bh_enable+0x10/0x34 include/linux/bottom_half.h:31
softirqs last disabled at (222): [<ffff800008030c84>] local_bh_disable+0x10/0x34 include/linux/bottom_half.h:18
---[ end trace 05b8ff4c121a8f58 ]---


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this issue, for details see:
https://goo.gl/tpsmEJ#testing-patches
Reply all
Reply to author
Forward
0 new messages