Hello,
syzbot found the following issue on:
HEAD commit: 3a5928702e71 Linux 5.15.167
git tree: linux-5.15.y
console output:
https://syzkaller.appspot.com/x/log.txt?x=15c33380580000
kernel config:
https://syzkaller.appspot.com/x/.config?x=171882977b524c53
dashboard link:
https://syzkaller.appspot.com/bug?extid=54873342b67d3c8c4a38
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
userspace arch: arm64
syz repro:
https://syzkaller.appspot.com/x/repro.syz?x=17417bd0580000
C reproducer:
https://syzkaller.appspot.com/x/repro.c?x=13c33380580000
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/22ee27cb312d/disk-3a592870.raw.xz
vmlinux:
https://storage.googleapis.com/syzbot-assets/90bf6a3e3d20/vmlinux-3a592870.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/096dd2c73ac3/Image-3a592870.gz.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+548733...@syzkaller.appspotmail.com
------------[ cut here ]------------
WARNING: CPU: 0 PID: 4048 at drivers/gpu/drm/vkms/vkms_crtc.c:103 vkms_get_vblank_timestamp+0x1a4/0x1d4 drivers/gpu/drm/vkms/vkms_crtc.c:103
Modules linked in:
CPU: 0 PID: 4048 Comm: syz-executor350 Not tainted 5.15.167-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/06/2024
pstate: 804000c5 (Nzcv daIF +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : vkms_get_vblank_timestamp+0x1a4/0x1d4 drivers/gpu/drm/vkms/vkms_crtc.c:103
lr : vkms_get_vblank_timestamp+0x1a4/0x1d4 drivers/gpu/drm/vkms/vkms_crtc.c:103
sp : ffff80001f9f6e90
x29: ffff80001f9f6e90 x28: ffff80001f9f6f50 x27: ffff0000cac94ee8
x26: ffff80001f9f6f40 x25: 1ffff00003f3edea x24: 0000000000000000
x23: ffff0000cac94000 x22: dfff800000000000 x21: 000000168b81d701
x20: 000000168b81d701 x19: ffff80001f9f6f50 x18: 0000000000000000
x17: 0000000000000000 x16: ffff80000830532c x15: 0000000000000008
x14: 1ffff0000295806a x13: dfff800000000000 x12: ffff700003f3ede4
x11: 0000000000000003 x10: 0000000000000000 x9 : ffff0000d91e0000
x8 : ffff80000b80caf4 x7 : ffff80000b71e5c0 x6 : 0000000000000000
x5 : 0000000000000080 x4 : 0000000000000001 x3 : 0000000000000000
x2 : ffff80001f9f6f50 x1 : 000000168b81d701 x0 : 000000168b81d701
Call trace:
vkms_get_vblank_timestamp+0x1a4/0x1d4 drivers/gpu/drm/vkms/vkms_crtc.c:103
drm_get_last_vbltimestamp drivers/gpu/drm/drm_vblank.c:881 [inline]
drm_update_vblank_count+0x23c/0xb10 drivers/gpu/drm/drm_vblank.c:303
drm_vblank_disable_and_save+0xc8/0x344 drivers/gpu/drm/drm_vblank.c:477
drm_crtc_vblank_off+0x254/0x7c4 drivers/gpu/drm/drm_vblank.c:1325
vkms_crtc_atomic_disable+0x20/0x30 drivers/gpu/drm/vkms/vkms_crtc.c:234
disable_outputs drivers/gpu/drm/drm_atomic_helper.c:1117 [inline]
drm_atomic_helper_commit_modeset_disables+0xa10/0x1488 drivers/gpu/drm/drm_atomic_helper.c:1321
vkms_atomic_commit_tail+0x5c/0x20c drivers/gpu/drm/vkms/vkms_drv.c:71
commit_tail+0x274/0x3cc drivers/gpu/drm/drm_atomic_helper.c:1693
drm_atomic_helper_commit+0x5fc/0x644 drivers/gpu/drm/drm_atomic_helper.c:1912
drm_atomic_commit+0xd8/0xf8 drivers/gpu/drm/drm_atomic.c:1426
drm_client_modeset_commit_atomic+0x594/0x730 drivers/gpu/drm/drm_client_modeset.c:1055
drm_client_modeset_commit_locked+0xd0/0x4a8 drivers/gpu/drm/drm_client_modeset.c:1158
drm_client_modeset_commit+0x50/0x7c drivers/gpu/drm/drm_client_modeset.c:1184
__drm_fb_helper_restore_fbdev_mode_unlocked drivers/gpu/drm/drm_fb_helper.c:252 [inline]
drm_fb_helper_restore_fbdev_mode_unlocked drivers/gpu/drm/drm_fb_helper.c:279 [inline]
drm_fb_helper_lastclose drivers/gpu/drm/drm_fb_helper.c:2005 [inline]
drm_fbdev_client_restore+0xe8/0x17c drivers/gpu/drm/drm_fb_helper.c:2408
drm_client_dev_restore+0x12c/0x248 drivers/gpu/drm/drm_client.c:226
drm_lastclose drivers/gpu/drm/drm_file.c:467 [inline]
drm_release+0x4dc/0x654 drivers/gpu/drm/drm_file.c:498
__fput+0x1c4/0x800 fs/file_table.c:280
____fput+0x20/0x30 fs/file_table.c:308
task_work_run+0x130/0x1e4 kernel/task_work.c:188
exit_task_work include/linux/task_work.h:33 [inline]
do_exit+0x670/0x20bc kernel/exit.c:874
do_group_exit+0x110/0x268 kernel/exit.c:996
get_signal+0x634/0x1550 kernel/signal.c:2897
do_signal arch/arm64/kernel/signal.c:890 [inline]
do_notify_resume+0x3d0/0x32b8 arch/arm64/kernel/signal.c:943
prepare_exit_to_user_mode arch/arm64/kernel/entry-common.c:133 [inline]
exit_to_user_mode arch/arm64/kernel/entry-common.c:138 [inline]
el0_svc+0xfc/0x1f0 arch/arm64/kernel/entry-common.c:609
el0t_64_sync_handler+0x84/0xe4 arch/arm64/kernel/entry-common.c:626
el0t_64_sync+0x1a0/0x1a4 arch/arm64/kernel/entry.S:584
irq event stamp: 1078
hardirqs last enabled at (1077): [<ffff800011b98e34>] __raw_spin_unlock_irq include/linux/spinlock_api_smp.h:168 [inline]
hardirqs last enabled at (1077): [<ffff800011b98e34>] _raw_spin_unlock_irq+0x9c/0x134 kernel/locking/spinlock.c:202
hardirqs last disabled at (1078): [<ffff800011b98850>] __raw_spin_lock_irq include/linux/spinlock_api_smp.h:126 [inline]
hardirqs last disabled at (1078): [<ffff800011b98850>] _raw_spin_lock_irq+0x38/0x13c kernel/locking/spinlock.c:170
softirqs last enabled at (402): [<ffff8000080308b0>] local_bh_enable+0x10/0x34 include/linux/bottom_half.h:31
softirqs last disabled at (400): [<ffff80000803087c>] local_bh_disable+0x10/0x34 include/linux/bottom_half.h:18
---[ end trace 76f20d82001b0d22 ]---
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup