[v6.1] kernel BUG in add_to_swap (2)

0 views
Skip to first unread message

syzbot

unread,
Aug 10, 2026, 8:58:30 PM (2 days ago) Aug 10
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: e4f7d8be268e Linux 6.1.182
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1217f079580000
kernel config: https://syzkaller.appspot.com/x/.config?x=872c04466179833f
dashboard link: https://syzkaller.appspot.com/bug?extid=6df539bcb1c18bdf732e
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
userspace arch: arm64

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/7cd9b1875376/disk-e4f7d8be.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/4b5d35d18c31/vmlinux-e4f7d8be.xz
kernel image: https://storage.googleapis.com/syzbot-assets/d5ee64c2af77/Image-e4f7d8be.gz.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+6df539...@syzkaller.appspotmail.com

raw: 05ffc00000480809 dead000000000100 dead000000000122 ffff0000f02aaee1
raw: 0000000000020013 0000000000000000 00000002ffffffff ffff0000c66e2000
page dumped because: VM_BUG_ON_FOLIO(!folio_test_uptodate(folio))
------------[ cut here ]------------
kernel BUG at mm/swap_state.c:180!
Internal error: Oops - BUG: 00000000f2000800 [#1] PREEMPT SMP
Modules linked in:
CPU: 0 PID: 7441 Comm: syz.5.396 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/02/2026
pstate: 82400005 (Nzcv daif +PAN -UAO +TCO -DIT -SSBS BTYPE=--)
pc : add_to_swap+0x1b4/0x1b8 mm/swap_state.c:180
lr : add_to_swap+0x1b4/0x1b8 mm/swap_state.c:180
sp : ffff800021116cc0
x29: ffff800021116cc0 x28: ffff800021116e60 x27: dfff800000000000
x26: ffff800021117220 x25: fffffc00039194c0 x24: 05ffc00000480809
x23: 1fffff8000723298 x22: 1fffff8000723299 x21: dead000000000100
x20: 05ffc00000480809 x19: fffffc00039194c0 x18: 1fffe00033e7277e
x17: ffff80001537d000 x16: ffff800011b90080 x15: 0000000040000000
x14: 0000000000000001 x13: 1fffe00033e727a3 x12: 0000000000080000
x11: 0000000000015d44 x10: ffff80002298a000 x9 : ffff8000087c9780
x8 : 0000000000015d45 x7 : ffff80000825ab50 x6 : 0000000000000000
x5 : 0000000000000080 x4 : 0000000000000001 x3 : ffff800008540904
x2 : 0000000000000001 x1 : 0000000100000000 x0 : 0000000000000041
Call trace:
add_to_swap+0x1b4/0x1b8 mm/swap_state.c:180
shrink_folio_list+0x1da8/0x4528 mm/vmscan.c:1845
shrink_inactive_list mm/vmscan.c:2512 [inline]
shrink_list mm/vmscan.c:2751 [inline]
shrink_lruvec+0x2480/0x36a4 mm/vmscan.c:5965
shrink_node_memcgs mm/vmscan.c:6152 [inline]
shrink_node+0x4c0/0x20bc mm/vmscan.c:6183
shrink_zones mm/vmscan.c:6424 [inline]
do_try_to_free_pages+0x55c/0x1470 mm/vmscan.c:6486
try_to_free_mem_cgroup_pages+0x2f4/0xa8c mm/vmscan.c:6801
mem_cgroup_resize_max+0x250/0x2e4 mm/memcontrol.c:3506
mem_cgroup_write+0x1f4/0x224 mm/memcontrol.c:-1
cgroup_file_write+0x258/0x584 kernel/cgroup/cgroup.c:4101
kernfs_fop_write_iter+0x390/0x4b4 fs/kernfs/file.c:352
call_write_iter include/linux/fs.h:2265 [inline]
new_sync_write fs/read_write.c:491 [inline]
vfs_write+0x3c8/0x7c8 fs/read_write.c:584
ksys_write+0x12c/0x228 fs/read_write.c:637
__do_sys_write fs/read_write.c:649 [inline]
__se_sys_write fs/read_write.c:646 [inline]
__arm64_sys_write+0x7c/0x90 fs/read_write.c:646
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x290 arch/arm64/kernel/syscall.c:52
el0_svc_common+0x13c/0x258 arch/arm64/kernel/syscall.c:140
do_el0_svc+0x5c/0x134 arch/arm64/kernel/syscall.c:204
el0_svc+0x58/0x128 arch/arm64/kernel/entry-common.c:637
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:585
Code: 9004a881 91000021 aa1303e0 97fd39e1 (d4210000)
---[ end trace 0000000000000000 ]---


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages