WARNING in alloc_new_node_page

6 views
Skip to first unread message

syzbot

unread,
Nov 9, 2022, 8:20:55 PM11/9/22
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 3f8a27f9e27b Linux 4.19.211
git tree: linux-4.19.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1392b215880000
kernel config: https://syzkaller.appspot.com/x/.config?x=9b9277b418617afe
dashboard link: https://syzkaller.appspot.com/bug?extid=1938f92cf200cc05fc89
compiler: gcc version 10.2.1 20210110 (Debian 10.2.1-6)

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/98c0bdb4abb3/disk-3f8a27f9.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/ea228ff02669/vmlinux-3f8a27f9.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+1938f9...@syzkaller.appspotmail.com

audit: type=1804 audit(1668043200.285:698): pid=967 uid=0 auid=4294967295 ses=4294967295 subj==unconfined op=invalid_pcr cause=open_writers comm="syz-executor.4" name="/root/syzkaller-testdir1659911855/syzkaller.Ju6oKI/7280/file0/bus" dev="loop4" ino=18 res=1
syz-executor.0: page allocation failure: order:0, mode:0x6600ca(GFP_HIGHUSER_MOVABLE|__GFP_THISNODE), nodemask=(null)
syz-executor.0 cpuset=/ mems_allowed=0-1
WARNING: CPU: 0 PID: 967 at include/linux/backing-dev.h:340 inode_to_wb include/linux/backing-dev.h:340 [inline]
WARNING: CPU: 0 PID: 967 at include/linux/backing-dev.h:340 account_page_dirtied+0x8cc/0xbb0 mm/page-writeback.c:2420
CPU: 1 PID: 954 Comm: syz-executor.0 Not tainted 4.19.211-syzkaller #0
Kernel panic - not syncing: panic_on_warn set ...

Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/26/2022
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x1fc/0x2ef lib/dump_stack.c:118
warn_alloc.cold+0x7b/0x18f mm/page_alloc.c:3457
__alloc_pages_slowpath mm/page_alloc.c:4317 [inline]
__alloc_pages_nodemask+0x232f/0x2890 mm/page_alloc.c:4419
__alloc_pages include/linux/gfp.h:496 [inline]
__alloc_pages_node include/linux/gfp.h:509 [inline]
alloc_new_node_page+0x2b6/0x400 mm/mempolicy.c:1003
unmap_and_move mm/migrate.c:1168 [inline]
migrate_pages+0x528/0x2fe0 mm/migrate.c:1419
do_move_pages_to_node mm/migrate.c:1501 [inline]
do_move_pages_to_node mm/migrate.c:1493 [inline]
do_pages_move mm/migrate.c:1686 [inline]
kernel_move_pages+0x506/0x1820 mm/migrate.c:1827
__do_sys_move_pages mm/migrate.c:1845 [inline]
__se_sys_move_pages mm/migrate.c:1840 [inline]
__x64_sys_move_pages+0xdd/0x1b0 mm/migrate.c:1840
do_syscall_64+0xf9/0x620 arch/x86/entry/common.c:293
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x7feeae4c8639
Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007feeaca3b168 EFLAGS: 00000246 ORIG_RAX: 0000000000000117
RAX: ffffffffffffffda RBX: 00007feeae5e8f80 RCX: 00007feeae4c8639
RDX: 0000000020000200 RSI: 0000000000000001 RDI: 0000000000000000
RBP: 00007feeae5237e1 R08: 0000000020000140 R09: 0000000000000000
R10: 000000002026bfec R11: 0000000000000246 R12: 0000000000000000
R13: 00007fff3227f46f R14: 00007feeaca3b300 R15: 0000000000022000
CPU: 0 PID: 967 Comm: syz-executor.4 Not tainted 4.19.211-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/26/2022
Call Trace:
Mem-Info:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x1fc/0x2ef lib/dump_stack.c:118
panic+0x26a/0x50e kernel/panic.c:186
active_anon:247599 inactive_anon:15202 isolated_anon:512
active_file:1840 inactive_file:6909 isolated_file:0
unevictable:0 dirty:246 writeback:0 unstable:0
slab_reclaimable:26272 slab_unreclaimable:662761
mapped:31617 shmem:21212 pagetables:1202 bounce:0
free:683917 free_pcp:1256 free_cma:0
__warn.cold+0x20/0x5a kernel/panic.c:541
report_bug+0x262/0x2b0 lib/bug.c:183
fixup_bug arch/x86/kernel/traps.c:178 [inline]
fixup_bug arch/x86/kernel/traps.c:173 [inline]
do_error_trap+0x1d7/0x310 arch/x86/kernel/traps.c:296
invalid_op+0x14/0x20 arch/x86/entry/entry_64.S:1038
RIP: 0010:inode_to_wb include/linux/backing-dev.h:340 [inline]
RIP: 0010:account_page_dirtied+0x8cc/0xbb0 mm/page-writeback.c:2420
Code: 88 01 00 00 be ff ff ff ff 48 8d 78 70 e8 ec e1 ca ff 31 ff 89 c3 89 c6 e8 f1 b3 e2 ff 85 db 0f 85 39 f9 ff ff e8 74 b2 e2 ff <0f> 0b e9 2d f9 ff ff e8 68 b2 e2 ff 4c 89 e6 4c 89 ef e8 9d b3 2d
RSP: 0018:ffff8881dad96b80 EFLAGS: 00010012
RAX: 0000000000040000 RBX: 0000000000000000 RCX: ffffc90005d4a000
RDX: 000000000000259c RSI: ffffffff817fd2fc RDI: 0000000000000005
RBP: ffff88821021dbc8 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000000005 R11: 0000000000000000 R12: ffffea0007a76d40
R13: ffff88821021da40 R14: ffff88821021d8b8 R15: ffffea0007a76d48
__set_page_dirty+0x7f/0x3e0 fs/buffer.c:582
Node 0 active_anon:874464kB inactive_anon:52432kB active_file:12kB inactive_file:8kB unevictable:0kB isolated(anon):0kB isolated(file):0kB mapped:99728kB dirty:4kB writeback:0kB shmem:69392kB shmem_thp: 0kB shmem_pmdmapped: 0kB anon_thp: 200704kB writeback_tmp:0kB unstable:0kB all_unreclaimable? yes
mark_buffer_dirty+0x424/0x5c0 fs/buffer.c:1111
nilfs_btree_do_insert fs/nilfs2/btree.c:811 [inline]
nilfs_btree_do_insert+0x2d0/0x390 fs/nilfs2/btree.c:798
nilfs_btree_commit_insert fs/nilfs2/btree.c:1212 [inline]
nilfs_btree_insert+0xe0d/0x1ae0 fs/nilfs2/btree.c:1240
nilfs_bmap_do_insert fs/nilfs2/bmap.c:121 [inline]
nilfs_bmap_insert+0x27a/0x3f0 fs/nilfs2/bmap.c:147
nilfs_mdt_insert_new_block fs/nilfs2/mdt.c:44 [inline]
nilfs_mdt_create_block fs/nilfs2/mdt.c:93 [inline]
nilfs_mdt_get_block+0x59a/0xd40 fs/nilfs2/mdt.c:254
Node 1 active_anon:115832kB inactive_anon:8376kB active_file:7348kB inactive_file:27628kB unevictable:0kB isolated(anon):2048kB isolated(file):0kB mapped:26740kB dirty:980kB writeback:0kB shmem:15456kB shmem_thp: 0kB shmem_pmdmapped: 0kB anon_thp: 0kB writeback_tmp:0kB unstable:0kB all_unreclaimable? no
Node 0 DMA free:10864kB min:204kB low:252kB high:300kB active_anon:0kB inactive_anon:0kB active_file:0kB inactive_file:0kB unevictable:0kB writepending:0kB present:15992kB managed:15908kB mlocked:0kB kernel_stack:0kB pagetables:0kB bounce:0kB free_pcp:0kB local_pcp:0kB free_cma:0kB
nilfs_palloc_get_block+0xc4/0x2b0 fs/nilfs2/alloc.c:216
nilfs_palloc_get_entry_block+0x17b/0x230 fs/nilfs2/alloc.c:318
nilfs_dat_prepare_entry fs/nilfs2/dat.c:43 [inline]
nilfs_dat_prepare_alloc fs/nilfs2/dat.c:69 [inline]
nilfs_dat_prepare_alloc+0x61/0xb0 fs/nilfs2/dat.c:61
lowmem_reserve[]: 0 2693 2695 2695 2695
nilfs_bmap_prepare_alloc_ptr fs/nilfs2/bmap.h:183 [inline]
nilfs_direct_insert+0x3cb/0x4e0 fs/nilfs2/direct.c:122
nilfs_bmap_do_insert fs/nilfs2/bmap.c:121 [inline]
nilfs_bmap_insert+0x27a/0x3f0 fs/nilfs2/bmap.c:147
nilfs_get_block+0x4d5/0x970 fs/nilfs2/inode.c:96
__block_write_begin_int+0x46c/0x17b0 fs/buffer.c:1978
__block_write_begin fs/buffer.c:2028 [inline]
block_write_begin+0x58/0x2e0 fs/buffer.c:2087
nilfs_write_begin+0xa5/0x1b0 fs/nilfs2/inode.c:267
generic_perform_write+0x1f8/0x4d0 mm/filemap.c:3170
__generic_file_write_iter+0x24b/0x610 mm/filemap.c:3295
generic_file_write_iter+0x3f8/0x730 mm/filemap.c:3323
call_write_iter include/linux/fs.h:1821 [inline]
new_sync_write fs/read_write.c:474 [inline]
__vfs_write+0x51b/0x770 fs/read_write.c:487
__kernel_write+0x109/0x370 fs/read_write.c:506
write_pipe_buf+0x153/0x1f0 fs/splice.c:798
splice_from_pipe_feed fs/splice.c:503 [inline]
__splice_from_pipe+0x389/0x800 fs/splice.c:627
splice_from_pipe fs/splice.c:662 [inline]
default_file_splice_write+0xd8/0x180 fs/splice.c:810
Node 0 DMA32 free:34652kB min:35996kB low:44992kB high:53988kB active_anon:874464kB inactive_anon:52432kB active_file:12kB inactive_file:8kB unevictable:0kB writepending:4kB present:3129332kB managed:2763452kB mlocked:0kB kernel_stack:7648kB pagetables:4412kB bounce:0kB free_pcp:2452kB local_pcp:1356kB free_cma:0kB
do_splice_from fs/splice.c:852 [inline]
direct_splice_actor+0x115/0x160 fs/splice.c:1025
splice_direct_to_actor+0x33f/0x8d0 fs/splice.c:980
do_splice_direct+0x1a7/0x270 fs/splice.c:1068
do_sendfile+0x550/0xc30 fs/read_write.c:1447
__do_sys_sendfile64 fs/read_write.c:1508 [inline]
__se_sys_sendfile64+0x147/0x160 fs/read_write.c:1494
do_syscall_64+0xf9/0x620 arch/x86/entry/common.c:293
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x7f9a98333639
Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f9a968a6168 EFLAGS: 00000246 ORIG_RAX: 0000000000000028
RAX: ffffffffffffffda RBX: 00007f9a98453f80 RCX: 00007f9a98333639
RDX: 0000000000000000 RSI: 0000000000000007 RDI: 0000000000000004
RBP: 00007f9a9838e7e1 R08: 0000000000000000 R09: 0000000000000000
R10: 00008400fffffffa R11: 0000000000000246 R12: 0000000000000000
R13: 00007ffd29a4f06f R14: 00007f9a968a6300 R15: 0000000000022000
Kernel Offset: disabled
Rebooting in 86400 seconds..


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Mar 9, 2023, 8:20:46 PM3/9/23
to syzkaller...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages