Hello,
syzbot found the following issue on:
HEAD commit: 848acc8ffe1b Merge tag 'fsverity-for-linus' of git://git.k..
git tree:
https://kernel.googlesource.com/pub/scm/linux/kernel/git/torvalds/linux master
console output:
https://syzkaller.appspot.com/x/log.txt?x=1669acc6580000
kernel config:
https://syzkaller.appspot.com/x/.config?x=db7ba9edb9755fc1
dashboard link:
https://syzkaller.appspot.com/bug?extid=ef53e984301fa685c317
compiler: arm-linux-gnueabi-gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
userspace arch: arm
CC: [
da...@kernel.org drive...@lists.linux.dev gre...@linuxfoundation.org le...@kernel.org linux-...@vger.kernel.org linu...@vger.kernel.org pa...@kernel.org raf...@kernel.org]
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image (non-bootable):
https://storage.googleapis.com/syzbot-assets/98a89b9f34e4/non_bootable_disk-848acc8f.raw.xz
vmlinux:
https://storage.googleapis.com/syzbot-assets/ed18b055a7ce/vmlinux-848acc8f.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/d9e1502ff007/zImage-848acc8f.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+ef53e9...@syzkaller.appspotmail.com
ODEBUG: object df805d04 is NOT on stack ea6f8000, but annotated.
------------[ cut here ]------------
WARNING: lib/debugobjects.c:672 at debug_object_is_on_stack lib/debugobjects.c:672 [inline], CPU#1: modprobe/3986
WARNING: lib/debugobjects.c:672 at lookup_object_or_alloc.part.0+0x180/0x1ec lib/debugobjects.c:705, CPU#1: modprobe/3986
Modules linked in:
Kernel panic - not syncing: kernel: panic_on_warn set ...
CPU: 1 UID: 0 PID: 3986 Comm: modprobe Not tainted syzkaller #0 PREEMPT
Hardware name: ARM-Versatile Express
Call trace: frame pointer underflow
[<80201998>] (dump_backtrace) from [<80201a8c>] (show_stack+0x18/0x1c arch/arm/kernel/traps.c:257)
r7:82a20f78 r6:00000000 r5:8233307c r4:00000001
[<80201a74>] (show_stack) from [<8021e5fc>] (__dump_stack lib/dump_stack.c:94 [inline])
[<80201a74>] (show_stack) from [<8021e5fc>] (dump_stack_lvl+0x5c/0x70 lib/dump_stack.c:120)
[<8021e5a0>] (dump_stack_lvl) from [<8021e628>] (dump_stack+0x18/0x1c lib/dump_stack.c:129)
r7:82a20f78 r6:00000000 r5:839955c0 r4:82c83d40
[<8021e610>] (dump_stack) from [<80202590>] (vpanic+0x114/0x320 kernel/panic.c:651)
[<8020247c>] (vpanic) from [<802027d0>] (trace_suspend_resume+0x0/0x100 kernel/panic.c:788)
r7:8095cd48
[<8020279c>] (panic) from [<80250a80>] (check_panic_on_warn kernel/panic.c:525 [inline])
[<8020279c>] (panic) from [<80250a80>] (get_taint+0x0/0x1c kernel/panic.c:520)
r3:82a0b144 r2:00000001 r1:82318de0 r0:8232073c
[<80250a08>] (check_panic_on_warn) from [<80250bfc>] (__warn+0x98/0x1a4 kernel/panic.c:1104)
[<80250b64>] (__warn) from [<80250e80>] (warn_slowpath_fmt+0x178/0x1f4 kernel/panic.c:1136)
r8:00000009 r7:8238d95c r6:df805c1c r5:839955c0 r4:00000000
[<80250d0c>] (warn_slowpath_fmt) from [<8095cd48>] (debug_object_is_on_stack lib/debugobjects.c:672 [inline])
[<80250d0c>] (warn_slowpath_fmt) from [<8095cd48>] (lookup_object_or_alloc.part.0+0x180/0x1ec lib/debugobjects.c:705)
r10:00000001 r9:81c04360 r8:df805d04 r7:00000000 r6:82d1bbec r5:82cfc280
r4:861ca348
[<8095cbc8>] (lookup_object_or_alloc.part.0) from [<8095d358>] (lookup_object_or_alloc lib/debugobjects.c:682 [inline])
[<8095cbc8>] (lookup_object_or_alloc.part.0) from [<8095d358>] (__debug_object_init+0x140/0x1d8 lib/debugobjects.c:798)
r10:0001f930 r9:82cfc2bc r8:00000001 r7:81c04360 r6:20000113 r5:82d1bbf0
r4:df805d04 r3:00000001
[<8095d218>] (__debug_object_init) from [<8095d444>] (debug_object_init_on_stack lib/debugobjects.c:849 [inline])
[<8095d218>] (__debug_object_init) from [<8095d444>] (debug_object_init_on_stack+0x28/0x2c lib/debugobjects.c:844)
r10:df805eb0 r9:ffffb968 r8:00000100 r7:00000000 r6:ddde3e00 r5:82b62308
r4:00000000
[<8095d41c>] (debug_object_init_on_stack) from [<802ffa84>] (init_rcu_head_on_stack+0x18/0x1c kernel/rcu/update.c:487)
[<802ffa6c>] (init_rcu_head_on_stack) from [<80303e4c>] (__synchronize_srcu+0x7c/0xcc kernel/rcu/srcutree.c:1494)
[<80303dd0>] (__synchronize_srcu) from [<80303f38>] (synchronize_srcu_expedited kernel/rcu/srcutree.c:1521 [inline])
[<80303dd0>] (__synchronize_srcu) from [<80303f38>] (synchronize_srcu+0x78/0x14c kernel/rcu/srcutree.c:1577)
r5:60000113 r4:82b62308
[<80303ec0>] (synchronize_srcu) from [<80bef128>] (wakeup_source_remove drivers/base/power/wakeup.c:201 [inline])
[<80303ec0>] (synchronize_srcu) from [<80bef128>] (wakeup_source_unregister.part.0+0x64/0x1b4 drivers/base/power/wakeup.c:237)
r7:00000000 r6:861a4900 r5:00000113 r4:861bc480
[<80bef0c4>] (wakeup_source_unregister.part.0) from [<80bef290>] (wakeup_source_unregister+0x18/0x1c drivers/base/power/wakeup.c:236)
r7:00000000 r6:861a4900 r5:85ec8000 r4:85ec8008
[<80bef278>] (wakeup_source_unregister) from [<812f0bf8>] (mmc_host_classdev_release+0x1c/0x58 drivers/mmc/core/host.c:69)
[<812f0bdc>] (mmc_host_classdev_release) from [<80bcbe24>] (device_release+0x40/0xb0 drivers/base/core.c:2636)
r5:861bb880 r4:85ec8008
[<80bcbde4>] (device_release) from [<81b33490>] (kobject_cleanup lib/kobject.c:689 [inline])
[<80bcbde4>] (device_release) from [<81b33490>] (kobject_release lib/kobject.c:720 [inline])
[<80bcbde4>] (device_release) from [<81b33490>] (kref_put include/linux/kref.h:65 [inline])
[<80bcbde4>] (device_release) from [<81b33490>] (kobject_put+0xa0/0x258 lib/kobject.c:737)
r5:81d5ae9c r4:85ec8008
[<81b333f0>] (kobject_put) from [<80bcbf98>] (put_device+0x18/0x1c drivers/base/core.c:3880)
r8:00000100 r7:8130f3cc r6:85ec8000 r5:00000000 r4:85ec8000
[<80bcbf80>] (put_device) from [<812f1354>] (mmc_free_host+0x28/0x2c drivers/mmc/core/host.c:702)
[<812f132c>] (mmc_free_host) from [<8130f52c>] (vub300_delete drivers/mmc/host/vub300.c:379 [inline])
[<812f132c>] (mmc_free_host) from [<8130f52c>] (kref_put include/linux/kref.h:65 [inline])
[<812f132c>] (mmc_free_host) from [<8130f52c>] (vub300_inactivity_timer_expired drivers/mmc/host/vub300.c:747 [inline])
[<812f132c>] (mmc_free_host) from [<8130f52c>] (vub300_inactivity_timer_expired+0x160/0x1b8 drivers/mmc/host/vub300.c:742)
r5:00000000 r4:85ec8aec
[<8130f3cc>] (vub300_inactivity_timer_expired) from [<8032df48>] (call_timer_fn+0x30/0x268 kernel/time/timer.c:1748)
r7:8130f3cc r6:839955c0 r5:85ec8aec r4:85ec8aec
[<8032df18>] (call_timer_fn) from [<8032e41c>] (expire_timers kernel/time/timer.c:1799 [inline])
[<8032df18>] (call_timer_fn) from [<8032e41c>] (__run_timers+0x29c/0x420 kernel/time/timer.c:2374)
r10:df805eb0 r9:ffffb968 r8:00000000 r7:8130f3cc r6:82a0b150 r5:85ec8aec
r4:ddddafc0
[<8032e180>] (__run_timers) from [<8032e608>] (__run_timer_base kernel/time/timer.c:2386 [inline])
[<8032e180>] (__run_timers) from [<8032e608>] (__run_timer_base kernel/time/timer.c:2378 [inline])
[<8032e180>] (__run_timers) from [<8032e608>] (run_timer_base+0x68/0x78 kernel/time/timer.c:2395)
r10:839955c0 r9:00000282 r8:00000100 r7:00000004 r6:00000002 r5:00000001
r4:ddddafc0
[<8032e5a0>] (run_timer_base) from [<8032e634>] (run_timer_softirq+0x1c/0x34 kernel/time/timer.c:2405)
r4:82a03084
[<8032e618>] (run_timer_softirq) from [<8025a0dc>] (handle_softirqs+0x160/0x4e4 kernel/softirq.c:622)
[<80259f7c>] (handle_softirqs) from [<8025a5fc>] (__do_softirq kernel/softirq.c:656 [inline])
[<80259f7c>] (handle_softirqs) from [<8025a5fc>] (invoke_softirq kernel/softirq.c:496 [inline])
[<80259f7c>] (handle_softirqs) from [<8025a5fc>] (__irq_exit_rcu+0x150/0x1d0 kernel/softirq.c:735)
r10:00000002 r9:839955c0 r8:00000000 r7:ea6f9e88 r6:824e6bb8 r5:82522068
r4:839955c0
[<8025a4ac>] (__irq_exit_rcu) from [<8025a934>] (irq_exit+0x10/0x18 kernel/softirq.c:764)
r5:82522068 r4:828d3e6c
[<8025a924>] (irq_exit) from [<81b5bb1c>] (generic_handle_arch_irq+0x7c/0x80 kernel/irq/handle.c:293)
[<81b5baa0>] (generic_handle_arch_irq) from [<81b287b4>] (call_with_stack+0x1c/0x20 arch/arm/lib/call_with_stack.S:40)
r9:839955c0 r8:00000255 r7:ea6f9ebc r6:ffffffff r5:80000113 r4:804f80b8
[<81b28798>] (call_with_stack) from [<80200bec>] (__irq_svc+0x8c/0xbc arch/arm/kernel/entry-armv.S:228)
Exception stack(0xea6f9e88 to 0xea6f9ed0)
9e80: 848e5380 00000001 0000001b 0000001c ea6f9fb0 76f8d13d
9ea0: 8592a000 839955c0 00000255 8592a000 00000002 ea6f9f2c 00000000 ea6f9ed8
9ec0: 804f80b8 804f80b8 80000113 ffffffff
[<804f8044>] (lock_vma_under_rcu) from [<80233094>] (do_page_fault+0x1f4/0x4d0 arch/arm/mm/fault.c:394)
r6:00000a07 r5:76f8d13d r4:ea6f9fb0
[<80232ea0>] (do_page_fault) from [<8023353c>] (do_DataAbort+0x38/0xac arch/arm/mm/fault.c:633)
r10:00000010 r9:76f8d6f4 r8:80232ea0 r7:ea6f9fb0 r6:76f8d13d r5:00000a07
r4:82a1ec20
[<80233504>] (do_DataAbort) from [<80200edc>] (__dabt_usr+0x5c/0x60 arch/arm/kernel/entry-armv.S:434)
Exception stack(0xea6f9fb0 to 0xea6f9ff8)
9fa0: 76f8d13d 00000000 000005b7 76f8d13d
9fc0: 76f8e390 7e885084 00000002 7e885068 00000002 76f8d6f4 00000010 7e88520c
9fe0: 00000000 7e885040 76f963bc 76faf710 20000010 ffffffff
r8:828c9044 r7:839955c0 r6:ffffffff r5:20000010 r4:76faf710
Rebooting in 86400 seconds..
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup