kernel BUG in blk_mq_dispatch_rq_list (2)

8 views
Skip to first unread message

syzbot

unread,
Aug 20, 2022, 12:58:27 AM8/20/22
to syzkaller-a...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: ee965fe12def Merge branch 'android12-5.10' into branch 'an..
git tree: android12-5.10-lts
console+strace: https://syzkaller.appspot.com/x/log.txt?x=141c80cb080000
kernel config: https://syzkaller.appspot.com/x/.config?x=d50a6822f51376ca
dashboard link: https://syzkaller.appspot.com/bug?extid=b06f9e2e9638c69264d9
compiler: Debian clang version 13.0.1-++20220126092033+75e33f71c2da-1~exp1~20220126212112.63, GNU ld (GNU Binutils for Debian) 2.35.2
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=10ae0ab5080000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=164879e3080000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+b06f9e...@syzkaller.appspotmail.com

blk_update_request: I/O error, dev sda, sector 606200 op 0x1:(WRITE) flags 0xc800 phys_seg 0 prio class 0
------------[ cut here ]------------
kernel BUG at block/blk-mq.c:569!
invalid opcode: 0000 [#1] PREEMPT SMP KASAN
CPU: 1 PID: 79 Comm: kworker/1:1H Tainted: G W 5.10.136-syzkaller-01853-gee965fe12def #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/22/2022
Workqueue: kblockd blk_mq_requeue_work
RIP: 0010:blk_mq_end_request block/blk-mq.c:569 [inline]
RIP: 0010:blk_mq_dispatch_rq_list+0x17f5/0x1800 block/blk-mq.c:1397
Code: 68 ff e9 24 f5 ff ff 44 89 e9 80 e1 07 80 c1 03 38 c1 0f 8c 25 fe ff ff 4c 89 ef e8 95 99 68 ff e9 18 fe ff ff e8 0b 92 2e ff <0f> 0b e8 94 39 54 02 0f 1f 40 00 55 48 89 e5 41 57 41 56 41 55 41
RSP: 0018:ffffc900002cf700 EFLAGS: 00010293
RAX: ffffffff823e3435 RBX: ffff88810a972640 RCX: ffff8881065c8000
RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff88810a97270a
RBP: ffffc900002cf870 R08: ffffffff823d050f R09: ffffffff823d04a5
R10: 0000000000000004 R11: ffff8881065c8000 R12: dffffc0000000000
R13: ffffc900002cf960 R14: ffff888109f6d800 R15: 1ffff92000059f2c
FS: 0000000000000000(0000) GS:ffff8881f7100000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000021000000 CR3: 000000011a3da000 CR4: 00000000003506a0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
__blk_mq_do_dispatch_sched block/blk-mq-sched.c:186 [inline]
blk_mq_do_dispatch_sched+0x63c/0xc60 block/blk-mq-sched.c:200
__blk_mq_sched_dispatch_requests+0x3de/0x4d0 block/blk-mq-sched.c:317
blk_mq_sched_dispatch_requests+0xf0/0x160 block/blk-mq-sched.c:348
__blk_mq_run_hw_queue+0x14d/0x260 block/blk-mq.c:1523
__blk_mq_delay_run_hw_queue+0x22a/0x570 block/blk-mq.c:1600
blk_mq_run_hw_queue+0x29d/0x3b0 block/blk-mq.c:1653
blk_mq_run_hw_queues+0x37c/0x450 block/blk-mq.c:1716
blk_mq_requeue_work+0x73b/0x780 block/blk-mq.c:821
process_one_work+0x726/0xc10 kernel/workqueue.c:2296
worker_thread+0xb27/0x1550 kernel/workqueue.c:2442
kthread+0x349/0x3d0 kernel/kthread.c:313
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:299
Modules linked in:
---[ end trace a4fb907579a5c2e5 ]---
RIP: 0010:blk_mq_end_request block/blk-mq.c:569 [inline]
RIP: 0010:blk_mq_dispatch_rq_list+0x17f5/0x1800 block/blk-mq.c:1397
Code: 68 ff e9 24 f5 ff ff 44 89 e9 80 e1 07 80 c1 03 38 c1 0f 8c 25 fe ff ff 4c 89 ef e8 95 99 68 ff e9 18 fe ff ff e8 0b 92 2e ff <0f> 0b e8 94 39 54 02 0f 1f 40 00 55 48 89 e5 41 57 41 56 41 55 41
RSP: 0018:ffffc900002cf700 EFLAGS: 00010293
RAX: ffffffff823e3435 RBX: ffff88810a972640 RCX: ffff8881065c8000
RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff88810a97270a
RBP: ffffc900002cf870 R08: ffffffff823d050f R09: ffffffff823d04a5
R10: 0000000000000004 R11: ffff8881065c8000 R12: dffffc0000000000
R13: ffffc900002cf960 R14: ffff888109f6d800 R15: 1ffff92000059f2c
FS: 0000000000000000(0000) GS:ffff8881f7100000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000021000000 CR3: 000000011a3da000 CR4: 00000000003506a0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this issue, for details see:
https://goo.gl/tpsmEJ#testing-patches
Reply all
Reply to author
Forward
0 new messages