Hello,
syzbot found the following issue on:
HEAD commit: 1dc22be1f91f Merge branch 'for-next/core' into for-kernelci
git tree: git://
git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git for-kernelci
console output:
https://syzkaller.appspot.com/x/log.txt?x=1553ba01480000
kernel config:
https://syzkaller.appspot.com/x/.config?x=e8cf742d9a45bfb6
dashboard link:
https://syzkaller.appspot.com/bug?extid=301be5988d6e47c62358
compiler: Debian clang version 13.0.1-6~deb11u1, GNU ld (GNU Binutils for Debian) 2.35.2
userspace arch: arm64
CC: [
almaz.ale...@paragon-software.com linux-...@vger.kernel.org nt...@lists.linux.dev]
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/ae0fce51809c/disk-1dc22be1.raw.xz
vmlinux:
https://storage.googleapis.com/syzbot-assets/2e13fba82ffb/vmlinux-1dc22be1.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/8d97a32221e2/Image-1dc22be1.gz.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+301be5...@syzkaller.appspotmail.com
loop2: detected capacity change from 0 to 4096
ntfs3: loop2: Different NTFS' sector size (4096) and media sector size (512)
Unable to handle kernel paging request at virtual address dead4ead00000000
Mem abort info:
ESR = 0x0000000096000004
EC = 0x25: DABT (current EL), IL = 32 bits
SET = 0, FnV = 0
EA = 0, S1PTW = 0
FSC = 0x04: level 0 translation fault
Data abort info:
ISV = 0, ISS = 0x00000004
CM = 0, WnR = 0
[dead4ead00000000] address between user and kernel address ranges
Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP
Modules linked in:
CPU: 1 PID: 26195 Comm: syz-executor.2 Not tainted 6.2.0-rc5-syzkaller-17295-g1dc22be1f91f #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/26/2022
pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : run_lookup fs/ntfs3/run.c:49 [inline]
pc : run_add_entry+0x5c/0x690 fs/ntfs3/run.c:331
lr : run_lookup fs/ntfs3/run.c:39 [inline]
lr : run_add_entry+0x4c/0x690 fs/ntfs3/run.c:331
sp : ffff800018f23810
x29: ffff800018f23830 x28: 0000000000000000 x27: 0000000000000001
x26: 00000000ffffffff x25: dead4ead00000000 x24: 0000000000000046
x23: 0000000000000001 x22: 0000000000000000 x21: 0000000000000000
x20: ffff000128425b20 x19: ffff000124f681db x18: 000000000000005f
x17: ffff80000c16e8bc x16: 0000000000000000 x15: 0000000000000000
x14: 0000000000000002 x13: 0000000000000001 x12: 0000000000040000
x11: ff80800008c3ac20 x10: 0000000000000002 x9 : ffff000118d83400
x8 : ffff800008c3ac20 x7 : 0000000000000008 x6 : ffff000124f681d8
x5 : 0000000000000000 x4 : 0000000000000001 x3 : 0000000000000001
x2 : 0000000000000045 x1 : 0000000000000000 x0 : 0000000000000000
Call trace:
run_lookup fs/ntfs3/run.c:49 [inline]
run_add_entry+0x5c/0x690 fs/ntfs3/run.c:331
run_unpack+0x5c4/0x6f4 fs/ntfs3/run.c:1021
run_unpack_ex+0x78/0x4f0 fs/ntfs3/run.c:1060
ntfs_read_mft fs/ntfs3/inode.c:386 [inline]
ntfs_iget5+0xda0/0x14f8 fs/ntfs3/inode.c:518
ntfs_loadlog_and_replay+0xc4/0x1ec fs/ntfs3/fsntfs.c:306
ntfs_fill_super+0xc84/0x15b8 fs/ntfs3/super.c:1053
get_tree_bdev+0x1e8/0x2a0 fs/super.c:1282
ntfs_fs_get_tree+0x28/0x38 fs/ntfs3/super.c:1408
vfs_get_tree+0x40/0x140 fs/super.c:1489
do_new_mount+0x1dc/0x4e4 fs/namespace.c:3145
path_mount+0x358/0x890 fs/namespace.c:3475
do_mount fs/namespace.c:3488 [inline]
__do_sys_mount fs/namespace.c:3697 [inline]
__se_sys_mount fs/namespace.c:3674 [inline]
__arm64_sys_mount+0x2c4/0x3c4 fs/namespace.c:3674
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall arch/arm64/kernel/syscall.c:52 [inline]
el0_svc_common+0x138/0x220 arch/arm64/kernel/syscall.c:142
do_el0_svc+0x48/0x104 arch/arm64/kernel/syscall.c:193
el0_svc+0x58/0x150 arch/arm64/kernel/entry-common.c:637
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x190/0x194 arch/arm64/kernel/entry.S:584
Code: b81f83bb b400015a f9400299 2a1603e1 (b9400333)
---[ end trace 0000000000000000 ]---
----------------
Code disassembly (best guess):
0: b81f83bb stur w27, [x29, #-8]
4: b400015a cbz x26, 0x2c
8: f9400299 ldr x25, [x20]
c: 2a1603e1 mov w1, w22
* 10: b9400333 ldr w19, [x25] <-- trapping instruction
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.