[v5.15] WARNING in drm_wait_one_vblank

4 views
Skip to first unread message

syzbot

unread,
Mar 31, 2023, 3:06:09 AM3/31/23
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: c957cbb87315 Linux 5.15.105
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=119aee01c80000
kernel config: https://syzkaller.appspot.com/x/.config?x=6f83fab0469f5de7
dashboard link: https://syzkaller.appspot.com/bug?extid=9a8f87865d5e2e8ef57f
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/35817fda76e5/disk-c957cbb8.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/80f96399b8d4/vmlinux-c957cbb8.xz
kernel image: https://storage.googleapis.com/syzbot-assets/4336a6ad59ec/bzImage-c957cbb8.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+9a8f87...@syzkaller.appspotmail.com

WARNING: CPU: 0 PID: 22537 at drivers/gpu/drm/drm_vblank.c:1269 drm_wait_one_vblank+0x95a/0x9e0 drivers/gpu/drm/drm_vblank.c:1269
Modules linked in:

CPU: 0 PID: 22537 Comm: syz-executor.2 Not tainted 5.15.105-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/02/2023
RIP: 0010:drm_wait_one_vblank+0x95a/0x9e0 drivers/gpu/drm/drm_vblank.c:1269
Code: df 80 3c 08 00 74 08 4c 89 ff e8 d1 11 35 fd 49 8b 1f 48 c7 c7 00 8c ea 8a 4c 89 f6 48 89 da 8b 5c 24 0c 89 d9 e8 d6 ab b7 fc <0f> 0b 49 be 00 00 00 00 00 fc ff df e9 80 fb ff ff 44 89 e9 80 e1
RSP: 0018:ffffc90007a27ac0 EFLAGS: 00010246

RAX: a6da883e3f1dab00 RBX: 0000000000000000 RCX: 0000000000040000
RDX: ffffc90004167000 RSI: 000000000003ffff RDI: 0000000000040000
RBP: ffffc90007a27c00 R08: ffffffff816612fc R09: ffffed10173467a0
R10: 0000000000000000 R11: dffffc0000000001 R12: 1ffff92000f44f64
R13: 0000000000025f89 R14: ffffffff8af91960 R15: ffff888147095010
FS: 00007fcdb716b700(0000) GS:ffff8880b9a00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 000000005e655000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
drm_fb_helper_ioctl+0x110/0x140 drivers/gpu/drm/drm_fb_helper.c:1197
do_fb_ioctl+0x220/0x8c0 drivers/video/fbdev/core/fbmem.c:1189
vfs_ioctl fs/ioctl.c:51 [inline]
__do_sys_ioctl fs/ioctl.c:874 [inline]
__se_sys_ioctl+0xf1/0x160 fs/ioctl.c:860
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x61/0xcb
RIP: 0033:0x7fcdb8bf90f9
Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 f1 19 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fcdb716b168 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 00007fcdb8d18f80 RCX: 00007fcdb8bf90f9
RDX: 0000000000000000 RSI: 0000000040044620 RDI: 0000000000000009
RBP: 00007fcdb8c54b39 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007ffe0bf928af R14: 00007fcdb716b300 R15: 0000000000022000
</TASK>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Mar 31, 2023, 4:09:42 AM3/31/23
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: c957cbb87315 Linux 5.15.105
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=14c1120dc80000
kernel config: https://syzkaller.appspot.com/x/.config?x=6f83fab0469f5de7
dashboard link: https://syzkaller.appspot.com/bug?extid=9a8f87865d5e2e8ef57f
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1635612ec80000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1523aa5dc80000
------------[ cut here ]------------
platform vkms: vblank wait timed out on crtc 0
WARNING: CPU: 0 PID: 3654 at drivers/gpu/drm/drm_vblank.c:1269 drm_wait_one_vblank+0x95a/0x9e0 drivers/gpu/drm/drm_vblank.c:1269
Modules linked in:
CPU: 0 PID: 3654 Comm: syz-executor258 Not tainted 5.15.105-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/02/2023
RIP: 0010:drm_wait_one_vblank+0x95a/0x9e0 drivers/gpu/drm/drm_vblank.c:1269
Code: df 80 3c 08 00 74 08 4c 89 ff e8 d1 11 35 fd 49 8b 1f 48 c7 c7 00 8c ea 8a 4c 89 f6 48 89 da 8b 5c 24 0c 89 d9 e8 d6 ab b7 fc <0f> 0b 49 be 00 00 00 00 00 fc ff df e9 80 fb ff ff 44 89 e9 80 e1
RSP: 0018:ffffc90002d9fac0 EFLAGS: 00010246
RAX: f2cf34561fc83c00 RBX: 0000000000000000 RCX: ffff888079445700
RDX: 0000000000000000 RSI: 0000000080000000 RDI: 0000000000000000
RBP: ffffc90002d9fc00 R08: ffffffff816612fc R09: ffffed10173467a0
R10: 0000000000000000 R11: dffffc0000000001 R12: 1ffff920005b3f64
R13: 0000000000000aec R14: ffffffff8af91960 R15: ffff88801b42b010
FS: 00005555569d83c0(0000) GS:ffff8880b9a00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f073c378290 CR3: 0000000076784000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
drm_fb_helper_ioctl+0x110/0x140 drivers/gpu/drm/drm_fb_helper.c:1197
do_fb_ioctl+0x220/0x8c0 drivers/video/fbdev/core/fbmem.c:1189
vfs_ioctl fs/ioctl.c:51 [inline]
__do_sys_ioctl fs/ioctl.c:874 [inline]
__se_sys_ioctl+0xf1/0x160 fs/ioctl.c:860
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x61/0xcb
RIP: 0033:0x7f073c304f29
Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 b1 14 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 c0 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ffc3565d6c8 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 00007ffc3565d730 RCX: 00007f073c304f29
RDX: 0000000000000000 RSI: 0000000040044620 RDI: 0000000000000004
RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 00000000000f4240
R13: 000000000000c3a5 R14: 00007ffc3565d71c R15: 00007ffc3565d720
</TASK>

syzbot

unread,
Apr 5, 2023, 8:39:42 AM4/5/23
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 3b29299e5f60 Linux 6.1.22
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=14c1ba2dc80000
kernel config: https://syzkaller.appspot.com/x/.config?x=4a782518325cb082
dashboard link: https://syzkaller.appspot.com/bug?extid=6e0b86e99fb5d6cdc18c
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/f6cdeb0f8946/disk-3b29299e.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/cc5e0da6e9ab/vmlinux-3b29299e.xz
kernel image: https://storage.googleapis.com/syzbot-assets/9e31f151a6a5/bzImage-3b29299e.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+6e0b86...@syzkaller.appspotmail.com

platform vkms: vblank wait timed out on crtc 0
WARNING: CPU: 0 PID: 6521 at drivers/gpu/drm/drm_vblank.c:1269 drm_wait_one_vblank+0x958/0x9d0 drivers/gpu/drm/drm_vblank.c:1269
Modules linked in:
CPU: 0 PID: 6521 Comm: syz-executor.0 Not tainted 6.1.22-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/30/2023
RIP: 0010:drm_wait_one_vblank+0x958/0x9d0 drivers/gpu/drm/drm_vblank.c:1269
Code: df 80 3c 08 00 74 08 4c 89 ff e8 83 1a 1f fd 49 8b 1f 48 c7 c7 60 6e 4e 8b 4c 89 f6 48 89 da 8b 5c 24 0c 89 d9 e8 48 93 91 fc <0f> 0b 49 be 00 00 00 00 00 fc ff df e9 80 fb ff ff 44 89 e9 80 e1
RSP: 0018:ffffc9000c937ac0 EFLAGS: 00010246
RAX: 87b1d25906810400 RBX: 0000000000000000 RCX: 0000000000040000
RDX: ffffc90003e71000 RSI: 000000000003ffff RDI: 0000000000040000
RBP: ffffc9000c937c00 R08: ffffffff8152292e R09: fffff52001926f11
R10: 0000000000000000 R11: dffffc0000000001 R12: 1ffff92001926f64
R13: 000000000001d202 R14: ffffffff8b5f4280 R15: ffff88814734b010
FS: 00007fb3833c0700(0000) GS:ffff8880b9800000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fb3827a3a34 CR3: 00000000798d6000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
drm_fb_helper_ioctl+0x110/0x140 drivers/gpu/drm/drm_fb_helper.c:1259
do_fb_ioctl+0x210/0x880 drivers/video/fbdev/core/fbmem.c:1188
vfs_ioctl fs/ioctl.c:51 [inline]
__do_sys_ioctl fs/ioctl.c:870 [inline]
__se_sys_ioctl+0xf1/0x160 fs/ioctl.c:856
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x63/0xcd
RIP: 0033:0x7fb38268c169
Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 f1 19 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fb3833c0168 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 00007fb3827abf80 RCX: 00007fb38268c169
RDX: 0000000007000000 RSI: 0000000040044620 RDI: 0000000000000003
RBP: 00007fb3826e7ca1 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007ffe11053e0f R14: 00007fb3833c0300 R15: 0000000000022000

syzbot

unread,
May 24, 2023, 8:30:58 AM5/24/23
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: fa74641fb6b9 Linux 6.1.29
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=123353ee280000
kernel config: https://syzkaller.appspot.com/x/.config?x=fac5c36c2b16009f
dashboard link: https://syzkaller.appspot.com/bug?extid=6e0b86e99fb5d6cdc18c
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=12122919280000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=10c0b8e5280000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/3e78f005d7f8/disk-fa74641f.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/6527fcf66401/vmlinux-fa74641f.xz
kernel image: https://storage.googleapis.com/syzbot-assets/c5e0d5f8b434/bzImage-fa74641f.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+6e0b86...@syzkaller.appspotmail.com

------------[ cut here ]------------
platform vkms: vblank wait timed out on crtc 0
WARNING: CPU: 0 PID: 3557 at drivers/gpu/drm/drm_vblank.c:1269 drm_wait_one_vblank+0x958/0x9d0 drivers/gpu/drm/drm_vblank.c:1269
Modules linked in:
CPU: 0 PID: 3557 Comm: syz-executor698 Not tainted 6.1.29-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/16/2023
RIP: 0010:drm_wait_one_vblank+0x958/0x9d0 drivers/gpu/drm/drm_vblank.c:1269
Code: df 80 3c 08 00 74 08 4c 89 ff e8 c3 aa 1b fd 49 8b 1f 48 c7 c7 20 ed 4e 8b 4c 89 f6 48 89 da 8b 5c 24 0c 89 d9 e8 d8 db 8d fc <0f> 0b 49 be 00 00 00 00 00 fc ff df e9 80 fb ff ff 44 89 e9 80 e1
RSP: 0018:ffffc90003b7fac0 EFLAGS: 00010246

RAX: ffab83ca0fd0d900 RBX: 0000000000000000 RCX: ffff88801ffc8000
RDX: 0000000000000000 RSI: 0000000000000001 RDI: 0000000000000000
RBP: ffffc90003b7fc00 R08: ffffffff81523d7e R09: fffffbfff205084f
R10: 0000000000000000 R11: dffffc0000000001 R12: 1ffff9200076ff64
R13: 0000000000000c73 R14: ffffffff8b5fc2a0 R15: ffff88801ec63010
FS: 00007fd1d22b0700(0000) GS:ffff8880b9800000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fd1d2331210 CR3: 0000000074474000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
drm_fb_helper_ioctl+0x110/0x140 drivers/gpu/drm/drm_fb_helper.c:1259
do_fb_ioctl+0x1d3/0x850 drivers/video/fbdev/core/fbmem.c:1190
vfs_ioctl fs/ioctl.c:51 [inline]
__do_sys_ioctl fs/ioctl.c:870 [inline]
__se_sys_ioctl+0xf1/0x160 fs/ioctl.c:856
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x63/0xcd
RIP: 0033:0x7fd1d22fec69
Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 11 15 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fd1d22b02f8 EFLAGS: 00000246
ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 00007fd1d23874a8 RCX: 00007fd1d22fec69
RDX: 0000000000000000 RSI: 0000000040044620 RDI: 0000000000000003
RBP: 00007fd1d23874a0 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 3062662f7665642f
R13: 00007ffe73f0caef R14: 00007fd1d22b0400 R15: 0000000000022000
</TASK>


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
Reply all
Reply to author
Forward
0 new messages