linux-mm.kvack.org archive mirror
 help / color / mirror / Atom feed
* Re: [syzbot] [mm?] WARNING in copy_hugetlb_page_range
       [not found] <0000000000005f05820606a0838a@google.com>
@ 2023-10-03 17:23 ` syzbot
  2023-10-03 17:29   ` Mike Kravetz
  2023-10-04  5:16 ` syzbot
  1 sibling, 1 reply; 4+ messages in thread
From: syzbot @ 2023-10-03 17:23 UTC (permalink / raw)
  To: akpm, linux-kernel, linux-mm, llvm, mike.kravetz, muchun.song,
	nathan, ndesaulniers, syzkaller-bugs, trix

syzbot has found a reproducer for the following issue on:

HEAD commit:    c9f2baaa18b5 Add linux-next specific files for 20231003
git tree:       linux-next
console+strace: https://syzkaller.appspot.com/x/log.txt?x=154df992680000
kernel config:  https://syzkaller.appspot.com/x/.config?x=3fe9c462fee1649f
dashboard link: https://syzkaller.appspot.com/bug?extid=ec78016e3d67860eec28
compiler:       gcc (Debian 12.2.0-14) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40
syz repro:      https://syzkaller.appspot.com/x/repro.syz?x=11e4b011680000
C reproducer:   https://syzkaller.appspot.com/x/repro.c?x=11772062680000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/5361e41384fe/disk-c9f2baaa.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/7028b209124d/vmlinux-c9f2baaa.xz
kernel image: https://storage.googleapis.com/syzbot-assets/a167dc667ee5/bzImage-c9f2baaa.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+ec78016e3d67860eec28@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 0 PID: 5054 at include/linux/hugetlb.h:1289 hugetlb_walk include/linux/hugetlb.h:1289 [inline]
WARNING: CPU: 0 PID: 5054 at include/linux/hugetlb.h:1289 copy_hugetlb_page_range+0x675/0x3520 mm/hugetlb.c:4940
Modules linked in:
CPU: 0 PID: 5054 Comm: syz-executor329 Not tainted 6.6.0-rc4-next-20231003-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/06/2023
RIP: 0010:hugetlb_walk include/linux/hugetlb.h:1289 [inline]
RIP: 0010:copy_hugetlb_page_range+0x675/0x3520 mm/hugetlb.c:4940
Code: 00 be ff ff ff ff 48 81 c7 a0 01 00 00 e8 b3 2f 6c 08 31 ff 89 c5 89 c6 e8 68 77 ae ff 85 ed 0f 85 dd fd ff ff e8 eb 7b ae ff <0f> 0b e9 d1 fd ff ff e8 df 7b ae ff 49 89 ec 31 ff 41 81 e4 ff 0f
RSP: 0018:ffffc90003a2f4a0 EFLAGS: 00010293
RAX: 0000000000000000 RBX: 0000000020000000 RCX: ffffffff81d9dcf8
RDX: ffff8880675d0000 RSI: ffffffff81d9dd05 RDI: 0000000000000005
RBP: 0000000000000000 R08: 0000000000000005 R09: 0000000000000000
R10: 0000000000000000 R11: ffffffff910df9a8 R12: ffff88807905b900
R13: ffff88801efab500 R14: 0000000020000000 R15: dffffc0000000000
FS:  0000555557543380(0000) GS:ffff8880b9800000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fcd71918140 CR3: 000000007b828000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
 <TASK>
 copy_page_range+0x1dc2/0x3c70 mm/memory.c:1293
 dup_mmap+0x13f3/0x1d80 kernel/fork.c:758
 dup_mm kernel/fork.c:1684 [inline]
 copy_mm kernel/fork.c:1733 [inline]
 copy_process+0x6cc9/0x74b0 kernel/fork.c:2495
 kernel_clone+0xfd/0x920 kernel/fork.c:2900
 __do_sys_clone3+0x1f1/0x260 kernel/fork.c:3201
 do_syscall_x64 arch/x86/entry/common.c:51 [inline]
 do_syscall_64+0x38/0xb0 arch/x86/entry/common.c:81
 entry_SYSCALL_64_after_hwframe+0x63/0xcd
RIP: 0033:0x7fcd71930ab9
Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 c1 17 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ffc79f4f9b8 EFLAGS: 00000246 ORIG_RAX: 00000000000001b3
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007fcd71930ab9
RDX: 00007ffc79f4f9c0 RSI: 0000000000000058 RDI: 00007ffc79f4f9c0
RBP: 00007fcd719a35f0 R08: 0000000000000000 R09: 0000000000000000
R10: 00000000ffffffff R11: 0000000000000246 R12: 0000000000000001
R13: 431bde82d7b634db R14: 0000000000000001 R15: 0000000000000001
 </TASK>


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.


^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [syzbot] [mm?] WARNING in copy_hugetlb_page_range
  2023-10-03 17:23 ` [syzbot] [mm?] WARNING in copy_hugetlb_page_range syzbot
@ 2023-10-03 17:29   ` Mike Kravetz
  2023-10-04  3:26     ` Rik van Riel
  0 siblings, 1 reply; 4+ messages in thread
From: Mike Kravetz @ 2023-10-03 17:29 UTC (permalink / raw)
  To: Rik van Riel, syzbot
  Cc: akpm, linux-kernel, linux-mm, llvm, muchun.song, nathan,
	ndesaulniers, syzkaller-bugs, trix

Adding Rik as this was a result of the conversion to invalidate_lock patch.
-- 
Mike Kravetz

On 10/03/23 10:23, syzbot wrote:
> syzbot has found a reproducer for the following issue on:
> 
> HEAD commit:    c9f2baaa18b5 Add linux-next specific files for 20231003
> git tree:       linux-next
> console+strace: https://syzkaller.appspot.com/x/log.txt?x=154df992680000
> kernel config:  https://syzkaller.appspot.com/x/.config?x=3fe9c462fee1649f
> dashboard link: https://syzkaller.appspot.com/bug?extid=ec78016e3d67860eec28
> compiler:       gcc (Debian 12.2.0-14) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40
> syz repro:      https://syzkaller.appspot.com/x/repro.syz?x=11e4b011680000
> C reproducer:   https://syzkaller.appspot.com/x/repro.c?x=11772062680000
> 
> Downloadable assets:
> disk image: https://storage.googleapis.com/syzbot-assets/5361e41384fe/disk-c9f2baaa.raw.xz
> vmlinux: https://storage.googleapis.com/syzbot-assets/7028b209124d/vmlinux-c9f2baaa.xz
> kernel image: https://storage.googleapis.com/syzbot-assets/a167dc667ee5/bzImage-c9f2baaa.xz
> 
> IMPORTANT: if you fix the issue, please add the following tag to the commit:
> Reported-by: syzbot+ec78016e3d67860eec28@syzkaller.appspotmail.com
> 
> ------------[ cut here ]------------
> WARNING: CPU: 0 PID: 5054 at include/linux/hugetlb.h:1289 hugetlb_walk include/linux/hugetlb.h:1289 [inline]
> WARNING: CPU: 0 PID: 5054 at include/linux/hugetlb.h:1289 copy_hugetlb_page_range+0x675/0x3520 mm/hugetlb.c:4940
> Modules linked in:
> CPU: 0 PID: 5054 Comm: syz-executor329 Not tainted 6.6.0-rc4-next-20231003-syzkaller #0
> Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/06/2023
> RIP: 0010:hugetlb_walk include/linux/hugetlb.h:1289 [inline]
> RIP: 0010:copy_hugetlb_page_range+0x675/0x3520 mm/hugetlb.c:4940
> Code: 00 be ff ff ff ff 48 81 c7 a0 01 00 00 e8 b3 2f 6c 08 31 ff 89 c5 89 c6 e8 68 77 ae ff 85 ed 0f 85 dd fd ff ff e8 eb 7b ae ff <0f> 0b e9 d1 fd ff ff e8 df 7b ae ff 49 89 ec 31 ff 41 81 e4 ff 0f
> RSP: 0018:ffffc90003a2f4a0 EFLAGS: 00010293
> RAX: 0000000000000000 RBX: 0000000020000000 RCX: ffffffff81d9dcf8
> RDX: ffff8880675d0000 RSI: ffffffff81d9dd05 RDI: 0000000000000005
> RBP: 0000000000000000 R08: 0000000000000005 R09: 0000000000000000
> R10: 0000000000000000 R11: ffffffff910df9a8 R12: ffff88807905b900
> R13: ffff88801efab500 R14: 0000000020000000 R15: dffffc0000000000
> FS:  0000555557543380(0000) GS:ffff8880b9800000(0000) knlGS:0000000000000000
> CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
> CR2: 00007fcd71918140 CR3: 000000007b828000 CR4: 00000000003506f0
> DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
> DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
> Call Trace:
>  <TASK>
>  copy_page_range+0x1dc2/0x3c70 mm/memory.c:1293
>  dup_mmap+0x13f3/0x1d80 kernel/fork.c:758
>  dup_mm kernel/fork.c:1684 [inline]
>  copy_mm kernel/fork.c:1733 [inline]
>  copy_process+0x6cc9/0x74b0 kernel/fork.c:2495
>  kernel_clone+0xfd/0x920 kernel/fork.c:2900
>  __do_sys_clone3+0x1f1/0x260 kernel/fork.c:3201
>  do_syscall_x64 arch/x86/entry/common.c:51 [inline]
>  do_syscall_64+0x38/0xb0 arch/x86/entry/common.c:81
>  entry_SYSCALL_64_after_hwframe+0x63/0xcd
> RIP: 0033:0x7fcd71930ab9
> Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 c1 17 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48
> RSP: 002b:00007ffc79f4f9b8 EFLAGS: 00000246 ORIG_RAX: 00000000000001b3
> RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007fcd71930ab9
> RDX: 00007ffc79f4f9c0 RSI: 0000000000000058 RDI: 00007ffc79f4f9c0
> RBP: 00007fcd719a35f0 R08: 0000000000000000 R09: 0000000000000000
> R10: 00000000ffffffff R11: 0000000000000246 R12: 0000000000000001
> R13: 431bde82d7b634db R14: 0000000000000001 R15: 0000000000000001
>  </TASK>
> 
> 
> ---
> If you want syzbot to run the reproducer, reply with:
> #syz test: git://repo/address.git branch-or-commit-hash
> If you attach or paste a git patch, syzbot will apply it before testing.


^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [syzbot] [mm?] WARNING in copy_hugetlb_page_range
  2023-10-03 17:29   ` Mike Kravetz
@ 2023-10-04  3:26     ` Rik van Riel
  0 siblings, 0 replies; 4+ messages in thread
From: Rik van Riel @ 2023-10-04  3:26 UTC (permalink / raw)
  To: Mike Kravetz, syzbot
  Cc: akpm, linux-kernel, linux-mm, llvm, muchun.song, nathan,
	ndesaulniers, syzkaller-bugs, trix

On Tue, 2023-10-03 at 10:29 -0700, Mike Kravetz wrote:
> Adding Rik as this was a result of the conversion to invalidate_lock
> patch.

I fixed this one in the version I'm about to send out.

-- 
All Rights Reversed.


^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [syzbot] [mm?] WARNING in copy_hugetlb_page_range
       [not found] <0000000000005f05820606a0838a@google.com>
  2023-10-03 17:23 ` [syzbot] [mm?] WARNING in copy_hugetlb_page_range syzbot
@ 2023-10-04  5:16 ` syzbot
  1 sibling, 0 replies; 4+ messages in thread
From: syzbot @ 2023-10-04  5:16 UTC (permalink / raw)
  To: akpm, brauner, hdanton, linux-fsdevel, linux-kernel, linux-mm,
	llvm, mike.kravetz, muchun.song, nathan, ndesaulniers, riel,
	syzkaller-bugs, trix, viro

syzbot has bisected this issue to:

commit 446503572dc452fc544d6898113feb0f3801477b
Author: Rik van Riel <riel@surriel.com>
Date:   Sun Oct 1 00:55:50 2023 +0000

    hugetlbfs: replace hugetlb_vma_lock with invalidate_lock

bisection log:  https://syzkaller.appspot.com/x/bisect.txt?x=146c879e680000
start commit:   c9f2baaa18b5 Add linux-next specific files for 20231003
git tree:       linux-next
final oops:     https://syzkaller.appspot.com/x/report.txt?x=166c879e680000
console output: https://syzkaller.appspot.com/x/log.txt?x=126c879e680000
kernel config:  https://syzkaller.appspot.com/x/.config?x=3fe9c462fee1649f
dashboard link: https://syzkaller.appspot.com/bug?extid=ec78016e3d67860eec28
syz repro:      https://syzkaller.appspot.com/x/repro.syz?x=11e4b011680000
C reproducer:   https://syzkaller.appspot.com/x/repro.c?x=11772062680000

Reported-by: syzbot+ec78016e3d67860eec28@syzkaller.appspotmail.com
Fixes: 446503572dc4 ("hugetlbfs: replace hugetlb_vma_lock with invalidate_lock")

For information about bisection process see: https://goo.gl/tpsmEJ#bisection


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2023-10-04  5:16 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
     [not found] <0000000000005f05820606a0838a@google.com>
2023-10-03 17:23 ` [syzbot] [mm?] WARNING in copy_hugetlb_page_range syzbot
2023-10-03 17:29   ` Mike Kravetz
2023-10-04  3:26     ` Rik van Riel
2023-10-04  5:16 ` syzbot

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox