WARNING in account_page_dirtied

11 views
Skip to first unread message

syzbot

unread,
Sep 22, 2020, 6:26:27 AM9/22/20
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 015e94d0 Linux 4.19.146
git tree: linux-4.19.y
console output: https://syzkaller.appspot.com/x/log.txt?x=12cc4cbb900000
kernel config: https://syzkaller.appspot.com/x/.config?x=243dd74ad58a8a57
dashboard link: https://syzkaller.appspot.com/bug?extid=bb6a32b547830c3c740d
compiler: gcc (GCC) 10.1.0-syz 20200507

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+bb6a32...@syzkaller.appspotmail.com

WARNING: CPU: 1 PID: 6489 at include/linux/backing-dev.h:339 inode_to_wb include/linux/backing-dev.h:339 [inline]
WARNING: CPU: 1 PID: 6489 at include/linux/backing-dev.h:339 account_page_dirtied+0x8e9/0xbe0 mm/page-writeback.c:2420
Kernel panic - not syncing: panic_on_warn set ...

CPU: 1 PID: 6489 Comm: syz-executor.3 Not tainted 4.19.146-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x22c/0x33e lib/dump_stack.c:118
panic+0x2ac/0x565 kernel/panic.c:186
__warn.cold+0x20/0x5a kernel/panic.c:541
report_bug+0x262/0x2b0 lib/bug.c:186
fixup_bug arch/x86/kernel/traps.c:178 [inline]
fixup_bug arch/x86/kernel/traps.c:173 [inline]
do_error_trap+0x1e1/0x330 arch/x86/kernel/traps.c:296
invalid_op+0x14/0x20 arch/x86/entry/entry_64.S:1038
RIP: 0010:inode_to_wb include/linux/backing-dev.h:339 [inline]
RIP: 0010:account_page_dirtied+0x8e9/0xbe0 mm/page-writeback.c:2420
Code: 88 01 00 00 be ff ff ff ff 48 8d 78 70 e8 0f 30 c6 ff 31 ff 89 c3 89 c6 e8 34 a5 e0 ff 85 db 0f 85 1c f9 ff ff e8 b7 a3 e0 ff <0f> 0b e9 10 f9 ff ff e8 ab a3 e0 ff 4c 89 e6 4c 89 ef e8 a0 d2 2f
RSP: 0018:ffff8880823ef7e8 EFLAGS: 00010093
RAX: ffff8880823e4640 RBX: 0000000000000000 RCX: ffffffff81911f1c
RDX: 0000000000000000 RSI: ffffffff81911f29 RDI: 0000000000000005
RBP: ffff8880a670ba60 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000005 R11: 0000000000000004 R12: ffffea00023e8280
R13: ffff8880a670b8d8 R14: ffff888049691420 R15: ffffea00023e8288
__set_page_dirty+0x7f/0x3f0 fs/buffer.c:582
mark_buffer_dirty+0x442/0x5f0 fs/buffer.c:1111
gfs2_unpin+0xd6/0xeb0 fs/gfs2/lops.c:108
buf_lo_after_commit+0x140/0x210 fs/gfs2/lops.c:512
lops_after_commit fs/gfs2/lops.h:67 [inline]
gfs2_log_flush+0xa98/0x2030 fs/gfs2/log.c:833
do_sync+0x5d0/0xdf0 fs/gfs2/quota.c:961
gfs2_quota_sync+0x2dd/0x640 fs/gfs2/quota.c:1303
gfs2_sync_fs+0x40/0xb0 fs/gfs2/super.c:956
__sync_filesystem fs/sync.c:39 [inline]
sync_filesystem+0x105/0x250 fs/sync.c:64
generic_shutdown_super+0x70/0x370 fs/super.c:442
kill_block_super+0x97/0xf0 fs/super.c:1185
gfs2_kill_sb+0x12c/0x1a0 fs/gfs2/ops_fstype.c:1386
deactivate_locked_super+0x8c/0x100 fs/super.c:329
deactivate_super+0x174/0x1a0 fs/super.c:360
cleanup_mnt+0x1da/0x300 fs/namespace.c:1098
task_work_run+0x141/0x1c0 kernel/task_work.c:113
tracehook_notify_resume include/linux/tracehook.h:193 [inline]
exit_to_usermode_loop+0x269/0x2c0 arch/x86/entry/common.c:167
prepare_exit_to_usermode arch/x86/entry/common.c:198 [inline]
syscall_return_slowpath arch/x86/entry/common.c:271 [inline]
do_syscall_64+0x57c/0x670 arch/x86/entry/common.c:296
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x460ba7
Code: 64 89 04 25 d0 02 00 00 58 5f ff d0 48 89 c7 e8 2f be ff ff 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 b8 a6 00 00 00 0f 05 <48> 3d 01 f0 ff ff 0f 83 dd 87 fb ff c3 66 2e 0f 1f 84 00 00 00 00
RSP: 002b:00007ffec0924d08 EFLAGS: 00000246 ORIG_RAX: 00000000000000a6
RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000460ba7
RDX: 00000000004031b8 RSI: 0000000000000002 RDI: 00007ffec0924db0
RBP: 0000000000000012 R08: 0000000000000000 R09: 0000000000000009
R10: 0000000000000005 R11: 0000000000000246 R12: 00007ffec0925e40
R13: 0000000002f04a60 R14: 0000000000000000 R15: 00007ffec0925e40
Kernel Offset: disabled
Rebooting in 86400 seconds..


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Sep 24, 2020, 11:44:25 AM9/24/20
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: cbfa1702 Linux 4.14.198
git tree: linux-4.14.y
console output: https://syzkaller.appspot.com/x/log.txt?x=14b3f8ad900000
kernel config: https://syzkaller.appspot.com/x/.config?x=3990958d85b55e59
dashboard link: https://syzkaller.appspot.com/bug?extid=51c2a7c6623badaed6fb
compiler: gcc (GCC) 10.1.0-syz 20200507

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+51c2a7...@syzkaller.appspotmail.com

gfs2: fsid=syz:syz.0: jid=0: Looking at journal...
gfs2: fsid=syz:syz.0: jid=0: Done
gfs2: fsid=syz:syz.0: first mount done, others may mount
gfs2: fsid=syz:syz.0: found 1 quota changes
------------[ cut here ]------------
WARNING: CPU: 1 PID: 6365 at include/linux/backing-dev.h:334 inode_to_wb include/linux/backing-dev.h:334 [inline]
WARNING: CPU: 1 PID: 6365 at include/linux/backing-dev.h:334 account_page_dirtied+0x7c7/0xa20 mm/page-writeback.c:2437
Kernel panic - not syncing: panic_on_warn set ...

CPU: 1 PID: 6365 Comm: syz-executor.0 Not tainted 4.14.198-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:17 [inline]
dump_stack+0x1b2/0x283 lib/dump_stack.c:58
panic+0x1f9/0x42d kernel/panic.c:183
__warn.cold+0x20/0x4b kernel/panic.c:547
report_bug+0x208/0x249 lib/bug.c:186
fixup_bug arch/x86/kernel/traps.c:177 [inline]
fixup_bug arch/x86/kernel/traps.c:172 [inline]
do_error_trap+0x195/0x2d0 arch/x86/kernel/traps.c:295
invalid_op+0x1b/0x40 arch/x86/entry/entry_64.S:964
RIP: 0010:inode_to_wb include/linux/backing-dev.h:334 [inline]
RIP: 0010:account_page_dirtied+0x7c7/0xa20 mm/page-writeback.c:2437
RSP: 0000:ffff8880a829f888 EFLAGS: 00010097
RAX: ffff8880881a4340 RBX: ffff8880a437a3c0 RCX: 1ffffffff1027c74
RDX: 0000000000000000 RSI: 00000000ffffffff RDI: 0000000000000086
RBP: ffff8880a6abfa28 R08: ffffffff8a083cf0 R09: 00000000000c022c
R10: ffff8880881a4c68 R11: ffff8880881a4340 R12: ffffea0001386780
R13: ffff8880a6abf898 R14: ffff8880a6abf898 R15: ffffea00013867a0
__set_page_dirty+0x77/0x2a0 fs/buffer.c:634
mark_buffer_dirty+0x307/0x480 fs/buffer.c:1173
gfs2_unpin+0xac/0xe80 fs/gfs2/lops.c:107
buf_lo_after_commit+0x12d/0x1f0 fs/gfs2/lops.c:510
lops_after_commit fs/gfs2/lops.h:64 [inline]
gfs2_log_flush+0x89a/0x1ba0 fs/gfs2/log.c:761
do_sync+0x4bb/0xba0 fs/gfs2/quota.c:958
gfs2_quota_sync+0x4f1/0x690 fs/gfs2/quota.c:1299
gfs2_sync_fs+0x40/0xa0 fs/gfs2/super.c:946
__sync_filesystem fs/sync.c:39 [inline]
sync_filesystem fs/sync.c:64 [inline]
sync_filesystem+0xe2/0x230 fs/sync.c:48
generic_shutdown_super+0x70/0x370 fs/super.c:432
kill_block_super+0x95/0xe0 fs/super.c:1161
gfs2_kill_sb+0x12c/0x1a0 fs/gfs2/ops_fstype.c:1405
deactivate_locked_super+0x6c/0xd0 fs/super.c:319
deactivate_super+0x7f/0xa0 fs/super.c:350
cleanup_mnt+0x186/0x2c0 fs/namespace.c:1183
task_work_run+0x11f/0x190 kernel/task_work.c:113
tracehook_notify_resume include/linux/tracehook.h:191 [inline]
exit_to_usermode_loop+0x1ad/0x200 arch/x86/entry/common.c:164
prepare_exit_to_usermode arch/x86/entry/common.c:199 [inline]
syscall_return_slowpath arch/x86/entry/common.c:270 [inline]
do_syscall_64+0x4a3/0x640 arch/x86/entry/common.c:297
entry_SYSCALL_64_after_hwframe+0x46/0xbb
RIP: 0033:0x460ba7
RSP: 002b:00007ffce41ccf08 EFLAGS: 00000246 ORIG_RAX: 00000000000000a6
RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000460ba7
RDX: 00000000004031b8 RSI: 0000000000000002 RDI: 00007ffce41ccfb0
RBP: 00000000000002e3 R08: 0000000000000000 R09: 000000000000000b
R10: 0000000000000005 R11: 0000000000000246 R12: 00007ffce41ce040
R13: 0000000001710a60 R14: 0000000000000000 R15: 00007ffce41ce040

syzbot

unread,
Sep 28, 2020, 1:47:26 PM9/28/20
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 10ad6cfd Linux 4.19.148
git tree: linux-4.19.y
console output: https://syzkaller.appspot.com/x/log.txt?x=11d8045b900000
kernel config: https://syzkaller.appspot.com/x/.config?x=ef9a7978d84ee42b
dashboard link: https://syzkaller.appspot.com/bug?extid=bb6a32b547830c3c740d
compiler: gcc (GCC) 10.1.0-syz 20200507
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=169d78f3900000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=118a4a37900000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+bb6a32...@syzkaller.appspotmail.com

NILFS (loop0): broken superblock, retrying with spare superblock (blocksize = 1024)
NILFS (loop0): mounting unchecked fs
NILFS (loop0): recovery complete
NILFS (loop0): segctord starting. Construction interval = 5 seconds, CP frequency < 30 seconds
WARNING: CPU: 1 PID: 6493 at include/linux/backing-dev.h:339 inode_to_wb include/linux/backing-dev.h:339 [inline]
WARNING: CPU: 1 PID: 6493 at include/linux/backing-dev.h:339 account_page_dirtied+0x8e9/0xbe0 mm/page-writeback.c:2420
Kernel panic - not syncing: panic_on_warn set ...

CPU: 1 PID: 6493 Comm: segctord Not tainted 4.19.148-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x22c/0x33e lib/dump_stack.c:118
panic+0x2ac/0x565 kernel/panic.c:186
__warn.cold+0x20/0x5a kernel/panic.c:541
report_bug+0x262/0x2b0 lib/bug.c:186
fixup_bug arch/x86/kernel/traps.c:178 [inline]
fixup_bug arch/x86/kernel/traps.c:173 [inline]
do_error_trap+0x1e1/0x330 arch/x86/kernel/traps.c:296
invalid_op+0x14/0x20 arch/x86/entry/entry_64.S:1038
RIP: 0010:inode_to_wb include/linux/backing-dev.h:339 [inline]
RIP: 0010:account_page_dirtied+0x8e9/0xbe0 mm/page-writeback.c:2420
Code: 88 01 00 00 be ff ff ff ff 48 8d 78 70 e8 0f 30 c6 ff 31 ff 89 c3 89 c6 e8 34 a5 e0 ff 85 db 0f 85 1c f9 ff ff e8 b7 a3 e0 ff <0f> 0b e9 10 f9 ff ff e8 ab a3 e0 ff 4c 89 e6 4c 89 ef e8 d0 d7 2f
RSP: 0018:ffff8880a3ed7868 EFLAGS: 00010093
RAX: ffff888094c3e380 RBX: 0000000000000000 RCX: ffffffff81911f1c
RDX: 0000000000000000 RSI: ffffffff81911f29 RDI: 0000000000000005
RBP: ffff888082bceb48 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000005 R11: 000000000000002d R12: ffffea000232f740
R13: ffff888082bce9c0 R14: ffff888082bce838 R15: ffffea000232f748
__set_page_dirty+0x7f/0x3f0 fs/buffer.c:582
mark_buffer_dirty+0x442/0x5f0 fs/buffer.c:1111
nilfs_btree_propagate_p fs/nilfs2/btree.c:1890 [inline]
nilfs_btree_propagate+0x72f/0xd80 fs/nilfs2/btree.c:2086
nilfs_bmap_propagate+0x73/0x170 fs/nilfs2/bmap.c:337
nilfs_collect_dat_data+0x45/0xd0 fs/nilfs2/segment.c:630
nilfs_segctor_apply_buffers+0x14a/0x490 fs/nilfs2/segment.c:1014
nilfs_segctor_scan_file+0x3ae/0x6b0 fs/nilfs2/segment.c:1063
nilfs_segctor_collect_blocks fs/nilfs2/segment.c:1225 [inline]
nilfs_segctor_collect fs/nilfs2/segment.c:1494 [inline]
nilfs_segctor_do_construct+0x15bf/0x80e0 fs/nilfs2/segment.c:2036
nilfs_segctor_construct+0x764/0xae0 fs/nilfs2/segment.c:2372
nilfs_segctor_thread_construct fs/nilfs2/segment.c:2480 [inline]
nilfs_segctor_thread+0x3cb/0xf50 fs/nilfs2/segment.c:2563
kthread+0x33f/0x460 kernel/kthread.c:259
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:415

syzbot

unread,
Oct 21, 2020, 11:11:24 PM10/21/20
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 5b7a52cd Linux 4.14.202
git tree: linux-4.14.y
console output: https://syzkaller.appspot.com/x/log.txt?x=165590f8500000
kernel config: https://syzkaller.appspot.com/x/.config?x=fa386e02ca459165
dashboard link: https://syzkaller.appspot.com/bug?extid=51c2a7c6623badaed6fb
compiler: gcc (GCC) 10.1.0-syz 20200507
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=167313c8500000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=147f79f7900000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+51c2a7...@syzkaller.appspotmail.com

NILFS (loop0): broken superblock, retrying with spare superblock (blocksize = 1024)
NILFS (loop0): segctord starting. Construction interval = 5 seconds, CP frequency < 30 seconds
------------[ cut here ]------------
WARNING: CPU: 0 PID: 8020 at include/linux/backing-dev.h:334 inode_to_wb include/linux/backing-dev.h:334 [inline]
WARNING: CPU: 0 PID: 8020 at include/linux/backing-dev.h:334 account_page_dirtied+0x7c7/0xa20 mm/page-writeback.c:2437
Kernel panic - not syncing: panic_on_warn set ...

CPU: 0 PID: 8020 Comm: segctord Not tainted 4.14.202-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:17 [inline]
dump_stack+0x1b2/0x283 lib/dump_stack.c:58
panic+0x1f9/0x42d kernel/panic.c:183
__warn.cold+0x20/0x4b kernel/panic.c:547
report_bug+0x208/0x249 lib/bug.c:186
fixup_bug arch/x86/kernel/traps.c:177 [inline]
fixup_bug arch/x86/kernel/traps.c:172 [inline]
do_error_trap+0x195/0x2d0 arch/x86/kernel/traps.c:295
invalid_op+0x1b/0x40 arch/x86/entry/entry_64.S:964
RIP: 0010:inode_to_wb include/linux/backing-dev.h:334 [inline]
RIP: 0010:account_page_dirtied+0x7c7/0xa20 mm/page-writeback.c:2437
RSP: 0018:ffff888095a3f908 EFLAGS: 00010097
RAX: ffff8880b43d4480 RBX: ffff8880af3ed4c0 RCX: 1ffffffff1279ee0
RDX: 0000000000000000 RSI: 00000000ffffffff RDI: 0000000000000082
RBP: ffff88808daf1b58 R08: ffffffff8ba4497c R09: 0000000000001d7a
R10: 0000000000000001 R11: ffff8880b43d4480 R12: ffffea0002843a40
R13: ffff88808daf19c8 R14: ffff88808daf19c8 R15: ffffea0002843a60
__set_page_dirty+0x77/0x2a0 fs/buffer.c:634
mark_buffer_dirty+0x307/0x480 fs/buffer.c:1173
nilfs_btree_propagate_p fs/nilfs2/btree.c:1899 [inline]
nilfs_btree_propagate+0x3a3/0xc20 fs/nilfs2/btree.c:2095
nilfs_bmap_propagate+0x73/0x160 fs/nilfs2/bmap.c:346
nilfs_collect_dat_data+0x41/0xb0 fs/nilfs2/segment.c:639
nilfs_segctor_apply_buffers+0x191/0x450 fs/nilfs2/segment.c:1027
nilfs_segctor_scan_file+0x366/0x630 fs/nilfs2/segment.c:1076
nilfs_segctor_collect_blocks fs/nilfs2/segment.c:1238 [inline]
nilfs_segctor_collect fs/nilfs2/segment.c:1507 [inline]
nilfs_segctor_do_construct+0x1426/0x7910 fs/nilfs2/segment.c:2049
nilfs_segctor_construct+0x6db/0x8e0 fs/nilfs2/segment.c:2385
nilfs_segctor_thread_construct fs/nilfs2/segment.c:2493 [inline]
nilfs_segctor_thread+0x3ad/0xdb0 fs/nilfs2/segment.c:2577
kthread+0x30d/0x420 kernel/kthread.c:232
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:404
Reply all
Reply to author
Forward
0 new messages