Hello,
syzbot found the following issue on:
HEAD commit: 13af6c74 Linux 4.19.136
git tree: linux-4.19.y
console output:
https://syzkaller.appspot.com/x/log.txt?x=13a5c0dc900000
kernel config:
https://syzkaller.appspot.com/x/.config?x=5b7578d3b5457a49
dashboard link:
https://syzkaller.appspot.com/bug?extid=de1acd8124232a3afac4
compiler: gcc (GCC) 10.1.0-syz 20200507
Unfortunately, I don't have any reproducer for this issue yet.
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+de1acd...@syzkaller.appspotmail.com
------------[ cut here ]------------
kernel BUG at fs/inode.c:519!
invalid opcode: 0000 [#1] PREEMPT SMP KASAN
CPU: 1 PID: 18063 Comm: syz-executor.1 Not tainted 4.19.136-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
RIP: 0010:clear_inode+0x19e/0x1e0 fs/inode.c:519
Code: 5c c3 e8 55 4d b9 ff 0f 0b e8 4e 4d b9 ff 0f 0b e8 47 4d b9 ff 0f 0b e8 40 4d b9 ff 0f 0b e8 39 4d b9 ff 0f 0b e8 32 4d b9 ff <0f> 0b e8 8b 6a ef ff e9 93 fe ff ff e8 81 6a ef ff e9 4a ff ff ff
RSP: 0018:ffff888000a77c08 EFLAGS: 00010293
RAX: ffff888000a66100 RBX: ffff888000c000c0 RCX: ffffffff81b0619d
RDX: 0000000000000000 RSI: ffffffff81b0620e RDI: 0000000000000007
RBP: ffff888000c00278 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000007 R11: 0000000000000000 R12: 0000000000000020
R13: ffff888000c000e8 R14: ffffffff87b968e0 R15: ffff88821b7c2eb8
FS: 0000000001da5940(0000) GS:ffff8880ae700000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000ca8660 CR3: 000000000098c000 CR4: 00000000001426e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
evict+0x5d3/0x760 fs/inode.c:562
iput_final fs/inode.c:1555 [inline]
iput+0x4f1/0x860 fs/inode.c:1581
dentry_unlink_inode+0x265/0x320 fs/dcache.c:374
d_delete+0x210/0x280 fs/dcache.c:2370
__debugfs_remove_file fs/debugfs/inode.c:628 [inline]
__debugfs_remove.part.0+0x10b/0x1b0 fs/debugfs/inode.c:658
__debugfs_remove include/linux/dcache.h:322 [inline]
debugfs_remove_recursive fs/debugfs/inode.c:740 [inline]
debugfs_remove_recursive+0x1ba/0x4c0 fs/debugfs/inode.c:709
kvm_destroy_vm_debugfs arch/x86/kvm/../../../virt/kvm/kvm_main.c:614 [inline]
kvm_destroy_vm arch/x86/kvm/../../../virt/kvm/kvm_main.c:789 [inline]
kvm_put_kvm+0xfb/0xc70 arch/x86/kvm/../../../virt/kvm/kvm_main.c:831
kvm_vcpu_release+0x77/0xa0 arch/x86/kvm/../../../virt/kvm/kvm_main.c:2639
__fput+0x2ce/0x890 fs/file_table.c:278
task_work_run+0x148/0x1c0 kernel/task_work.c:113
tracehook_notify_resume include/linux/tracehook.h:193 [inline]
exit_to_usermode_loop+0x251/0x2a0 arch/x86/entry/common.c:167
prepare_exit_to_usermode arch/x86/entry/common.c:198 [inline]
syscall_return_slowpath arch/x86/entry/common.c:271 [inline]
do_syscall_64+0x538/0x620 arch/x86/entry/common.c:296
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x416791
Code: 75 14 b8 03 00 00 00 0f 05 48 3d 01 f0 ff ff 0f 83 04 1b 00 00 c3 48 83 ec 08 e8 0a fc ff ff 48 89 04 24 b8 03 00 00 00 0f 05 <48> 8b 3c 24 48 89 c2 e8 53 fc ff ff 48 89 d0 48 83 c4 08 48 3d 01
RSP: 002b:00007fffbe897020 EFLAGS: 00000293 ORIG_RAX: 0000000000000003
RAX: 0000000000000000 RBX: 0000000000000006 RCX: 0000000000416791
RDX: 0000000000000000 RSI: 000000000000149d RDI: 0000000000000005
RBP: 0000000000000001 R08: 00000000542a549d R09: 00000000542a54a1
R10: 00007fffbe897110 R11: 0000000000000293 R12: 0000000000792688
R13: 0000000000059f3c R14: ffffffffffffffff R15: 000000000078bf0c
Modules linked in:
---[ end trace d78c1a92d3233b1b ]---
RIP: 0010:clear_inode+0x19e/0x1e0 fs/inode.c:519
Code: 5c c3 e8 55 4d b9 ff 0f 0b e8 4e 4d b9 ff 0f 0b e8 47 4d b9 ff 0f 0b e8 40 4d b9 ff 0f 0b e8 39 4d b9 ff 0f 0b e8 32 4d b9 ff <0f> 0b e8 8b 6a ef ff e9 93 fe ff ff e8 81 6a ef ff e9 4a ff ff ff
RSP: 0018:ffff888000a77c08 EFLAGS: 00010293
RAX: ffff888000a66100 RBX: ffff888000c000c0 RCX: ffffffff81b0619d
RDX: 0000000000000000 RSI: ffffffff81b0620e RDI: 0000000000000007
RBP: ffff888000c00278 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000007 R11: 0000000000000000 R12: 0000000000000020
R13: ffff888000c000e8 R14: ffffffff87b968e0 R15: ffff88821b7c2eb8
FS: 0000000001da5940(0000) GS:ffff8880ae700000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000742138 CR3: 000000000098c000 CR4: 00000000001426e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.