Hello,
syzbot found the following issue on:
HEAD commit: a989fde763f4 Merge tag 'libnvdimm-fixes-7.0-rc5' of git://..
git tree: upstream
console output:
https://syzkaller.appspot.com/x/log.txt?x=1213b2da580000
kernel config:
https://syzkaller.appspot.com/x/.config?x=d46eab0cfd31c214
dashboard link:
https://syzkaller.appspot.com/bug?extid=2d1037ba71f644cd9246
compiler: Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8
CC: [
fran...@vivo.com glau...@physik.fu-berlin.de linux-...@vger.kernel.org linux-...@vger.kernel.org sl...@dubeyko.com]
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image (non-bootable):
https://storage.googleapis.com/syzbot-assets/d900f083ada3/non_bootable_disk-a989fde7.raw.xz
vmlinux:
https://storage.googleapis.com/syzbot-assets/70fb6efe7e56/vmlinux-a989fde7.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/6019cf0eed26/bzImage-a989fde7.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+2d1037...@syzkaller.appspotmail.com
Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI
CPU: 0 UID: 0 PID: 1053 Comm: kworker/u4:8 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Workqueue: writeback wb_workfn (flush-7:0)
RIP: 0010:hfs_write_inode+0x934/0x960 fs/hfs/inode.c:474
Code: 40 31 ff e8 ae c7 13 ff 81 e3 00 00 00 40 75 1c e8 61 c3 13 ff 48 bb f8 f8 f8 f8 f8 f8 f8 f8 e9 dc f7 ff ff e8 4d c3 13 ff 90 <0f> 0b e8 45 c3 13 ff e8 e0 14 81 fe eb dd 44 89 f1 80 e1 07 80 c1
RSP: 0018:ffffc90005397120 EFLAGS: 00010293
RAX: ffffffff82b1ed33 RBX: ffff888011a43c18 RCX: ffff8880361d24c0
RDX: 0000000000000000 RSI: ffffffff8e9c8cc0 RDI: 0000000000000000
RBP: ffffc900053972a8 R08: ffff8880361d24c0 R09: 0000000000000003
R10: 0000000000000004 R11: 0000000000000000 R12: dffffc0000000000
R13: 1ffff92000a72e28 R14: 0000000000000000 R15: ffff888011a43bd8
FS: 0000000000000000(0000) GS:ffff88808ca55000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f09a82f5340 CR3: 0000000036c38000 CR4: 0000000000352ef0
Call Trace:
<TASK>
write_inode fs/fs-writeback.c:1582 [inline]
__writeback_single_inode+0x75a/0x11a0 fs/fs-writeback.c:1813
writeback_sb_inodes+0x992/0x1a20 fs/fs-writeback.c:2042
__writeback_inodes_wb+0x111/0x240 fs/fs-writeback.c:2118
wb_writeback+0x46a/0xb70 fs/fs-writeback.c:2229
wb_check_start_all fs/fs-writeback.c:2355 [inline]
wb_do_writeback fs/fs-writeback.c:2381 [inline]
wb_workfn+0x95b/0xf50 fs/fs-writeback.c:2414
process_one_work kernel/workqueue.c:3276 [inline]
process_scheduled_works+0xb6e/0x18c0 kernel/workqueue.c:3359
worker_thread+0xa53/0xfc0 kernel/workqueue.c:3440
kthread+0x388/0x470 kernel/kthread.c:436
ret_from_fork+0x51e/0xb90 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:hfs_write_inode+0x934/0x960 fs/hfs/inode.c:474
Code: 40 31 ff e8 ae c7 13 ff 81 e3 00 00 00 40 75 1c e8 61 c3 13 ff 48 bb f8 f8 f8 f8 f8 f8 f8 f8 e9 dc f7 ff ff e8 4d c3 13 ff 90 <0f> 0b e8 45 c3 13 ff e8 e0 14 81 fe eb dd 44 89 f1 80 e1 07 80 c1
RSP: 0018:ffffc90005397120 EFLAGS: 00010293
RAX: ffffffff82b1ed33 RBX: ffff888011a43c18 RCX: ffff8880361d24c0
RDX: 0000000000000000 RSI: ffffffff8e9c8cc0 RDI: 0000000000000000
RBP: ffffc900053972a8 R08: ffff8880361d24c0 R09: 0000000000000003
R10: 0000000000000004 R11: 0000000000000000 R12: dffffc0000000000
R13: 1ffff92000a72e28 R14: 0000000000000000 R15: ffff888011a43bd8
FS: 0000000000000000(0000) GS:ffff88808ca55000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f09a82f5340 CR3: 0000000011a91000 CR4: 0000000000352ef0
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup