Hello,
syzbot found the following issue on:
HEAD commit: 8cf0b93919e1 Linux 6.12-rc2
git tree: upstream
console output:
https://syzkaller.appspot.com/x/log.txt?x=16c35b07980000
kernel config:
https://syzkaller.appspot.com/x/.config?x=a2f7ae2f221e9eae
dashboard link:
https://syzkaller.appspot.com/bug?extid=c27a4f864fd990610379
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
CC: [
bra...@kernel.org ja...@suse.cz linux-...@vger.kernel.org linux-...@vger.kernel.org vi...@zeniv.linux.org.uk]
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/8f5ff8e3b043/disk-8cf0b939.raw.xz
vmlinux:
https://storage.googleapis.com/syzbot-assets/8d714b153cdb/vmlinux-8cf0b939.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/dd32c91c7643/bzImage-8cf0b939.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+c27a4f...@syzkaller.appspotmail.com
==================================================================
BUG: KCSAN: data-race in file_update_time / inode_update_timestamps
read to 0xffff8881158c83dc of 4 bytes by task 31756 on cpu 1:
inode_get_mtime_nsec include/linux/fs.h:1630 [inline]
inode_get_mtime include/linux/fs.h:1636 [inline]
inode_needs_update_time fs/inode.c:2222 [inline]
file_update_time+0x92/0x2b0 fs/inode.c:2269
fault_dirty_shared_page+0xde/0x340 mm/memory.c:3204
do_shared_fault mm/memory.c:5374 [inline]
do_fault mm/memory.c:5420 [inline]
do_pte_missing mm/memory.c:3965 [inline]
handle_pte_fault mm/memory.c:5751 [inline]
__handle_mm_fault mm/memory.c:5894 [inline]
handle_mm_fault+0x1370/0x2a80 mm/memory.c:6062
do_user_addr_fault arch/x86/mm/fault.c:1338 [inline]
handle_page_fault arch/x86/mm/fault.c:1481 [inline]
exc_page_fault+0x3b9/0x650 arch/x86/mm/fault.c:1539
asm_exc_page_fault+0x26/0x30 arch/x86/include/asm/idtentry.h:623
write to 0xffff8881158c83dc of 4 bytes by task 31757 on cpu 0:
inode_set_mtime_to_ts include/linux/fs.h:1644 [inline]
inode_update_timestamps+0x166/0x280 fs/inode.c:1999
generic_update_time fs/inode.c:2034 [inline]
inode_update_time fs/inode.c:2054 [inline]
__file_update_time fs/inode.c:2243 [inline]
file_update_time+0x220/0x2b0 fs/inode.c:2273
fault_dirty_shared_page+0xde/0x340 mm/memory.c:3204
do_shared_fault mm/memory.c:5374 [inline]
do_fault mm/memory.c:5420 [inline]
do_pte_missing mm/memory.c:3965 [inline]
handle_pte_fault mm/memory.c:5751 [inline]
__handle_mm_fault mm/memory.c:5894 [inline]
handle_mm_fault+0x1370/0x2a80 mm/memory.c:6062
faultin_page mm/gup.c:1187 [inline]
__get_user_pages+0xf2c/0x2670 mm/gup.c:1485
__get_user_pages_locked mm/gup.c:1751 [inline]
faultin_page_range+0x352/0x5d0 mm/gup.c:1975
madvise_populate mm/madvise.c:943 [inline]
do_madvise+0x3dc/0x2660 mm/madvise.c:1458
__do_sys_madvise mm/madvise.c:1477 [inline]
__se_sys_madvise mm/madvise.c:1475 [inline]
__x64_sys_madvise+0x61/0x70 mm/madvise.c:1475
x64_sys_call+0x2320/0x2d60 arch/x86/include/generated/asm/syscalls_64.h:29
do_syscall_x64 arch/x86/entry/common.c:52 [inline]
do_syscall_64+0xc9/0x1c0 arch/x86/entry/common.c:83
entry_SYSCALL_64_after_hwframe+0x77/0x7f
value changed: 0x06bd406c -> 0x0755d6eb
Reported by Kernel Concurrency Sanitizer on:
CPU: 0 UID: 0 PID: 31757 Comm: syz.1.7009 Not tainted 6.12.0-rc2-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024
==================================================================
syz.1.7009[31757] is installing a program with bpf_probe_write_user helper that may corrupt user memory!
syz.1.7009[31757] is installing a program with bpf_probe_write_user helper that may corrupt user memory!
syz.1.7009[31757] is installing a program with bpf_probe_write_user helper that may corrupt user memory!
SELinux: unrecognized netlink message: protocol=9 nlmsg_type=16 sclass=netlink_audit_socket pid=31757 comm=syz.1.7009
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup