* [syzbot] [mm?] BUG: corrupted list in add_to_unbuddied
@ 2024-09-08 22:22 syzbot
2024-10-15 14:52 ` syzbot
0 siblings, 1 reply; 6+ messages in thread
From: syzbot @ 2024-09-08 22:22 UTC (permalink / raw)
To: akpm, linmiaohe, linux-kernel, linux-mm, syzkaller-bugs, vitaly.wool
Hello,
syzbot found the following issue on:
HEAD commit: 89f5e14d05b4 Merge tag 'timers_urgent_for_v6.11_rc7' of gi..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=164ed89f980000
kernel config: https://syzkaller.appspot.com/x/.config?x=58a85aa6925a8b78
dashboard link: https://syzkaller.appspot.com/bug?extid=30eac43568e2b3d65728
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/7bc7510fe41f/non_bootable_disk-89f5e14d.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/dfc310daee41/vmlinux-89f5e14d.xz
kernel image: https://storage.googleapis.com/syzbot-assets/a92f22c06568/bzImage-89f5e14d.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+30eac43568e2b3d65728@syzkaller.appspotmail.com
list_add corruption. next->prev should be prev (ffffe8ffffc31c60), but was ffff888034ff6800. (next=ffff88801abf5000).
------------[ cut here ]------------
kernel BUG at lib/list_debug.c:31!
Oops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN NOPTI
CPU: 0 UID: 0 PID: 2862 Comm: kworker/u4:12 Not tainted 6.11.0-rc6-syzkaller-00363-g89f5e14d05b4 #0
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014
Workqueue: zswap1 compact_page_work
RIP: 0010:__list_add_valid_or_report+0xd6/0xf0 lib/list_debug.c:29
Code: e8 2f 73 fc 06 90 0f 0b 48 c7 c7 20 90 60 8c e8 20 73 fc 06 90 0f 0b 48 c7 c7 80 90 60 8c 4c 89 e6 4c 89 f1 e8 0b 73 fc 06 90 <0f> 0b 48 c7 c7 00 91 60 8c 4c 89 f6 4c 89 e1 e8 f6 72 fc 06 90 0f
RSP: 0018:ffffc9000c3cfad0 EFLAGS: 00010246
RAX: 0000000000000075 RBX: ffff88801abf5008 RCX: 332bd7343f331c00
RDX: 0000000000000000 RSI: 0000000080000002 RDI: 0000000000000000
RBP: ffffe8ffffc31c60 R08: ffffffff817401bc R09: 1ffff92001879ef8
R10: dffffc0000000000 R11: fffff52001879ef9 R12: ffffe8ffffc31c60
R13: dffffc0000000000 R14: ffff88801abf5000 R15: ffff88801214c000
FS: 0000000000000000(0000) GS:ffff88801fe00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000560d7f0a4dd8 CR3: 000000004108a000 CR4: 0000000000350ef0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
__list_add_valid include/linux/list.h:88 [inline]
__list_add include/linux/list.h:150 [inline]
list_add include/linux/list.h:169 [inline]
add_to_unbuddied+0x2e4/0x4d0 mm/z3fold.c:550
do_compact_page+0x924/0xc50 mm/z3fold.c:772
process_one_work kernel/workqueue.c:3231 [inline]
process_scheduled_works+0xa2c/0x1830 kernel/workqueue.c:3312
worker_thread+0x86d/0xd10 kernel/workqueue.c:3389
kthread+0x2f0/0x390 kernel/kthread.c:389
ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:__list_add_valid_or_report+0xd6/0xf0 lib/list_debug.c:29
Code: e8 2f 73 fc 06 90 0f 0b 48 c7 c7 20 90 60 8c e8 20 73 fc 06 90 0f 0b 48 c7 c7 80 90 60 8c 4c 89 e6 4c 89 f1 e8 0b 73 fc 06 90 <0f> 0b 48 c7 c7 00 91 60 8c 4c 89 f6 4c 89 e1 e8 f6 72 fc 06 90 0f
RSP: 0018:ffffc9000c3cfad0 EFLAGS: 00010246
RAX: 0000000000000075 RBX: ffff88801abf5008 RCX: 332bd7343f331c00
RDX: 0000000000000000 RSI: 0000000080000002 RDI: 0000000000000000
RBP: ffffe8ffffc31c60 R08: ffffffff817401bc R09: 1ffff92001879ef8
R10: dffffc0000000000 R11: fffff52001879ef9 R12: ffffe8ffffc31c60
R13: dffffc0000000000 R14: ffff88801abf5000 R15: ffff88801214c000
FS: 0000000000000000(0000) GS:ffff88801fe00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000560d7f0a4dd8 CR3: 000000004108a000 CR4: 0000000000350ef0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [syzbot] [mm?] BUG: corrupted list in add_to_unbuddied
2024-09-08 22:22 [syzbot] [mm?] BUG: corrupted list in add_to_unbuddied syzbot
@ 2024-10-15 14:52 ` syzbot
2024-10-15 22:39 ` Andrew Morton
0 siblings, 1 reply; 6+ messages in thread
From: syzbot @ 2024-10-15 14:52 UTC (permalink / raw)
To: akpm, linmiaohe, linux-kernel, linux-mm, syzkaller-bugs, vitaly.wool
syzbot has found a reproducer for the following issue on:
HEAD commit: eca631b8fe80 Merge tag 'f2fs-6.12-rc4' of git://git.kernel..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=14d0845f980000
kernel config: https://syzkaller.appspot.com/x/.config?x=cfbd94c114a3d407
dashboard link: https://syzkaller.appspot.com/bug?extid=30eac43568e2b3d65728
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=16df4c40580000
Downloadable assets:
disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/7feb34a89c2a/non_bootable_disk-eca631b8.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/830e1433408d/vmlinux-eca631b8.xz
kernel image: https://storage.googleapis.com/syzbot-assets/5538dfbaa4ef/bzImage-eca631b8.xz
mounted in repro: https://storage.googleapis.com/syzbot-assets/66bf3424533c/mount_0.gz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+30eac43568e2b3d65728@syzkaller.appspotmail.com
list_add corruption. next->prev should be prev (ffffe8ffffc31ed0), but was ffff88803ccdc800. (next=ffff88801e21b400).
------------[ cut here ]------------
kernel BUG at lib/list_debug.c:31!
Oops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN NOPTI
CPU: 0 UID: 0 PID: 11 Comm: kworker/u4:0 Not tainted 6.12.0-rc3-syzkaller-00013-geca631b8fe80 #0
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014
Workqueue: zswap1 compact_page_work
RIP: 0010:__list_add_valid_or_report+0xd6/0xf0 lib/list_debug.c:29
Code: e8 1f 26 00 07 90 0f 0b 48 c7 c7 00 fe 60 8c e8 10 26 00 07 90 0f 0b 48 c7 c7 60 fe 60 8c 4c 89 e6 4c 89 f1 e8 fb 25 00 07 90 <0f> 0b 48 c7 c7 e0 fe 60 8c 4c 89 f6 4c 89 e1 e8 e6 25 00 07 90 0f
RSP: 0000:ffffc900003d7ad0 EFLAGS: 00010246
RAX: 0000000000000075 RBX: ffff88801e21b408 RCX: 18a79d2c00c9a300
RDX: 0000000000000000 RSI: 0000000000000002 RDI: 0000000000000000
RBP: ffffe8ffffc31ed0 R08: ffffffff8174afec R09: 1ffff9200007aef4
R10: dffffc0000000000 R11: fffff5200007aef5 R12: ffffe8ffffc31ed0
R13: dffffc0000000000 R14: ffff88801e21b400 R15: ffff8880400e6000
FS: 0000000000000000(0000) GS:ffff88801fc00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000000c001e70000 CR3: 000000003dd36000 CR4: 0000000000352ef0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
__list_add_valid include/linux/list.h:88 [inline]
__list_add include/linux/list.h:150 [inline]
list_add include/linux/list.h:169 [inline]
add_to_unbuddied+0x2e4/0x4d0 mm/z3fold.c:550
do_compact_page+0x924/0xc50 mm/z3fold.c:772
process_one_work kernel/workqueue.c:3229 [inline]
process_scheduled_works+0xa63/0x1850 kernel/workqueue.c:3310
worker_thread+0x870/0xd30 kernel/workqueue.c:3391
kthread+0x2f0/0x390 kernel/kthread.c:389
ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:__list_add_valid_or_report+0xd6/0xf0 lib/list_debug.c:29
Code: e8 1f 26 00 07 90 0f 0b 48 c7 c7 00 fe 60 8c e8 10 26 00 07 90 0f 0b 48 c7 c7 60 fe 60 8c 4c 89 e6 4c 89 f1 e8 fb 25 00 07 90 <0f> 0b 48 c7 c7 e0 fe 60 8c 4c 89 f6 4c 89 e1 e8 e6 25 00 07 90 0f
RSP: 0000:ffffc900003d7ad0 EFLAGS: 00010246
RAX: 0000000000000075 RBX: ffff88801e21b408 RCX: 18a79d2c00c9a300
RDX: 0000000000000000 RSI: 0000000000000002 RDI: 0000000000000000
RBP: ffffe8ffffc31ed0 R08: ffffffff8174afec R09: 1ffff9200007aef4
R10: dffffc0000000000 R11: fffff5200007aef5 R12: ffffe8ffffc31ed0
R13: dffffc0000000000 R14: ffff88801e21b400 R15: ffff8880400e6000
FS: 0000000000000000(0000) GS:ffff88801fc00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000000c001e70000 CR3: 000000003dd36000 CR4: 0000000000352ef0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [syzbot] [mm?] BUG: corrupted list in add_to_unbuddied
2024-10-15 14:52 ` syzbot
@ 2024-10-15 22:39 ` Andrew Morton
2024-10-16 6:19 ` Aleksandr Nogikh
0 siblings, 1 reply; 6+ messages in thread
From: Andrew Morton @ 2024-10-15 22:39 UTC (permalink / raw)
To: syzbot; +Cc: linmiaohe, linux-kernel, linux-mm, syzkaller-bugs, vitaly.wool
On Tue, 15 Oct 2024 07:52:25 -0700 syzbot <syzbot+30eac43568e2b3d65728@syzkaller.appspotmail.com> wrote:
> syzbot has found a reproducer for the following issue on:
>
> HEAD commit: eca631b8fe80 Merge tag 'f2fs-6.12-rc4' of git://git.kernel..
> git tree: upstream
> console output: https://syzkaller.appspot.com/x/log.txt?x=14d0845f980000
> kernel config: https://syzkaller.appspot.com/x/.config?x=cfbd94c114a3d407
> dashboard link: https://syzkaller.appspot.com/bug?extid=30eac43568e2b3d65728
> compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=16df4c40580000
Something seems rather wrong with the "syz repro" page.
# https://syzkaller.appspot.com/bug?id=6b5f76b3a3783e6b1876d25b2d7a981ac0e0131f
# See https://goo.gl/kgGztJ for information about syzkaller reproducers.
#{"threaded":true,"repeat":true,"procs":6,"slowdown":1,"sandbox":"none","sandbox_arg":0,"tun":true,"netdev":true,"resetnet":true,"cgroups":true,"binfmt_misc":true,"close_fds":true,"usb":true,"vhci":true,"wifi":true,"ieee802154":true,"sysctl":true,"swap":true,"tmpdir":true,"segv":true}
syz_mount_image$ntfs3(&(0x7f0000000000), &(0x7f0000000140)='./bus\x00', 0x19c6038, &(0x7f0000000180)=ANY=[], 0x1, 0x1f231, &(0x7f000003e780)="$eJzs3QmYTeUfB/D37Pu+XLvBWEO2RLLvsm+pZAvZyRalGhJRSSWpFElCQqhUEklEsi8JSZKQVEIS/2fu3JlmufOvadf7/TyPOfeee877nnu+94z5ne0ebz25edsGbRISEhKIzZAU50gGSSSJXIq9xsfGXYoNmdi/EZ3nV9ttftQreZxZcOVtoxYUXjVUa7/MfEsim+xOx09VOLwp3JT7+MW2vXoPSeg9JGHAwKEJXRO6DRw4tGu3fj0Suvce0rdsQst+PboO6ZHQe8CQHoMzvNyz38BBg0YmdB3Q3VAHDe4xZEhC1wEjE/r2GJkwdGDC0MEjE7re2rX3gISyZcsmGCqB36jd/H96CQAAAAAAAAAAAAAAAAAA4M9x6VLaoX0AAAAAAAAAAAAAAAAAAAC4TDVo3LR+OaKkPWcIQxoRhsxlCCH2L9OlXvfPZdNO8qRdoo9yRX82Sn10um/5fuf
<and a huge amount more>
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [syzbot] [mm?] BUG: corrupted list in add_to_unbuddied
2024-10-15 22:39 ` Andrew Morton
@ 2024-10-16 6:19 ` Aleksandr Nogikh
2024-10-16 21:37 ` Andrew Morton
0 siblings, 1 reply; 6+ messages in thread
From: Aleksandr Nogikh @ 2024-10-16 6:19 UTC (permalink / raw)
To: Andrew Morton
Cc: syzbot, linmiaohe, linux-kernel, linux-mm, syzkaller-bugs, vitaly.wool
Hi Andrew,
On Wed, Oct 16, 2024 at 12:40 AM Andrew Morton
<akpm@linux-foundation.org> wrote:
>
> On Tue, 15 Oct 2024 07:52:25 -0700 syzbot <syzbot+30eac43568e2b3d65728@syzkaller.appspotmail.com> wrote:
>
> > syzbot has found a reproducer for the following issue on:
> >
> > HEAD commit: eca631b8fe80 Merge tag 'f2fs-6.12-rc4' of git://git.kernel..
> > git tree: upstream
> > console output: https://syzkaller.appspot.com/x/log.txt?x=14d0845f980000
> > kernel config: https://syzkaller.appspot.com/x/.config?x=cfbd94c114a3d407
> > dashboard link: https://syzkaller.appspot.com/bug?extid=30eac43568e2b3d65728
> > compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
> > syz repro: https://syzkaller.appspot.com/x/repro.syz?x=16df4c40580000
>
> Something seems rather wrong with the "syz repro" page.
>
>
What exactly looks wrong? :)
The repro mounts an ntfs3 disk image as the first operation, so the
compressed base64-encoded image takes quite a bit of space there.
>
>
> # https://syzkaller.appspot.com/bug?id=6b5f76b3a3783e6b1876d25b2d7a981ac0e0131f
> # See https://goo.gl/kgGztJ for information about syzkaller reproducers.
> #{"threaded":true,"repeat":true,"procs":6,"slowdown":1,"sandbox":"none","sandbox_arg":0,"tun":true,"netdev":true,"resetnet":true,"cgroups":true,"binfmt_misc":true,"close_fds":true,"usb":true,"vhci":true,"wifi":true,"ieee802154":true,"sysctl":true,"swap":true,"tmpdir":true,"segv":true}
> syz_mount_image$ntfs3(&(0x7f0000000000), &(0x7f0000000140)='./bus\x00', 0x19c6038, &(0x7f0000000180)=ANY=[], 0x1, 0x1f231, &(0x7f000003e780)="$eJzs3QmYTeUfB/D37Pu+XLvBWEO2RLLvsm+pZAvZyRalGhJRSSWpFElCQqhUEklEsi8JSZKQVEIS/2fu3JlmufOvadf7/TyPOfeee877nnu+94z5ne0ebz25edsGbRISEhKIzZAU50gGSSSJXIq9xsfGXYoNmdi/EZ3nV9ttftQreZxZcOVtoxYUXjVUa7/MfEsim+xOx09VOLwp3JT7+MW2vXoPSeg9JGHAwKEJXRO6DRw4tGu3fj0Suvce0rdsQst+PboO6ZHQe8CQHoMzvNyz38BBg0YmdB3Q3VAHDe4xZEhC1wEjE/r2GJkwdGDC0MEjE7re2rX3gISyZcsmGCqB36jd/H96CQAAAAAAAAAAAAAAAAAA4M9x6VLaoX0AAAAAAAAAAAAAAAAAAAC4TDVo3LR+OaKkPWcIQxoRhsxlCCH2L9OlXvfPZdNO8qRdoo9yRX82Sn10um/5fuf
> <and a huge amount more>
>
--
Aleksandr
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [syzbot] [mm?] BUG: corrupted list in add_to_unbuddied
2024-10-16 6:19 ` Aleksandr Nogikh
@ 2024-10-16 21:37 ` Andrew Morton
2024-10-18 7:56 ` Aleksandr Nogikh
0 siblings, 1 reply; 6+ messages in thread
From: Andrew Morton @ 2024-10-16 21:37 UTC (permalink / raw)
To: Aleksandr Nogikh
Cc: syzbot, linmiaohe, linux-kernel, linux-mm, syzkaller-bugs, vitaly.wool
On Wed, 16 Oct 2024 08:19:25 +0200 Aleksandr Nogikh <nogikh@google.com> wrote:
> Hi Andrew,
>
> On Wed, Oct 16, 2024 at 12:40 AM Andrew Morton
> <akpm@linux-foundation.org> wrote:
> >
> > On Tue, 15 Oct 2024 07:52:25 -0700 syzbot <syzbot+30eac43568e2b3d65728@syzkaller.appspotmail.com> wrote:
> >
> > > syzbot has found a reproducer for the following issue on:
> > >
> > > HEAD commit: eca631b8fe80 Merge tag 'f2fs-6.12-rc4' of git://git.kernel..
> > > git tree: upstream
> > > console output: https://syzkaller.appspot.com/x/log.txt?x=14d0845f980000
> > > kernel config: https://syzkaller.appspot.com/x/.config?x=cfbd94c114a3d407
> > > dashboard link: https://syzkaller.appspot.com/bug?extid=30eac43568e2b3d65728
> > > compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
> > > syz repro: https://syzkaller.appspot.com/x/repro.syz?x=16df4c40580000
> >
> > Something seems rather wrong with the "syz repro" page.
> >
> >
>
> What exactly looks wrong? :)
I click on the link
(https://syzkaller.appspot.com/x/repro.syz?x=16df4c40580000) and I get
the below garbage:
> >
> > # https://syzkaller.appspot.com/bug?id=6b5f76b3a3783e6b1876d25b2d7a981ac0e0131f
> > # See https://goo.gl/kgGztJ for information about syzkaller reproducers.
> > #{"threaded":true,"repeat":true,"procs":6,"slowdown":1,"sandbox":"none","sandbox_arg":0,"tun":true,"netdev":true,"resetnet":true,"cgroups":true,"binfmt_misc":true,"close_fds":true,"usb":true,"vhci":true,"wifi":true,"ieee802154":true,"sysctl":true,"swap":true,"tmpdir":true,"segv":true}
> > syz_mount_image$ntfs3(&(0x7f0000000000), &(0x7f0000000140)='./bus\x00', 0x19c6038, &(0x7f0000000180)=ANY=[], 0x1, 0x1f231, &(0x7f000003e780)="$eJzs3QmYTeUfB/D37Pu+XLvBWEO2RLLvsm+pZAvZyRalGhJRSSWpFElCQqhUEklEsi8JSZKQVEIS/2fu3JlmufOvadf7/TyPOfeee877nnu+94z5ne0ebz25edsGbRISEhKIzZAU50gGSSSJXIq9xsfGXYoNmdi/EZ3nV9ttftQreZxZcOVtoxYUXjVUa7/MfEsim+xOx09VOLwp3JT7+MW2vXoPSeg9JGHAwKEJXRO6DRw4tGu3fj0Suvce0rdsQst+PboO6ZHQe8CQHoMzvNyz38BBg0YmdB3Q3VAHDe4xZEhC1wEjE/r2GJkwdGDC0MEjE7re2rX3gISyZcsmGCqB36jd/H96CQAAAAAAAAAAAAAAAAAA4M9x6VLaoX0AAAAAAAAAAAAAAAAAAAC4TDVo3LR+OaKkPWcIQxoRhsxlCCH2L9OlXvfPZdNO8qRdoo9yRX82Sn10um/5fuf
> > <and a huge amount more>
> >
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [syzbot] [mm?] BUG: corrupted list in add_to_unbuddied
2024-10-16 21:37 ` Andrew Morton
@ 2024-10-18 7:56 ` Aleksandr Nogikh
0 siblings, 0 replies; 6+ messages in thread
From: Aleksandr Nogikh @ 2024-10-18 7:56 UTC (permalink / raw)
To: Andrew Morton
Cc: syzbot, linmiaohe, linux-kernel, linux-mm, syzkaller-bugs, vitaly.wool
On Wed, Oct 16, 2024 at 11:37 PM Andrew Morton
<akpm@linux-foundation.org> wrote:
>
> On Wed, 16 Oct 2024 08:19:25 +0200 Aleksandr Nogikh <nogikh@google.com> wrote:
>
> > Hi Andrew,
> >
> > On Wed, Oct 16, 2024 at 12:40 AM Andrew Morton
> > <akpm@linux-foundation.org> wrote:
> > >
> > > On Tue, 15 Oct 2024 07:52:25 -0700 syzbot <syzbot+30eac43568e2b3d65728@syzkaller.appspotmail.com> wrote:
> > >
> > > > syzbot has found a reproducer for the following issue on:
> > > >
> > > > HEAD commit: eca631b8fe80 Merge tag 'f2fs-6.12-rc4' of git://git.kernel..
> > > > git tree: upstream
> > > > console output: https://syzkaller.appspot.com/x/log.txt?x=14d0845f980000
> > > > kernel config: https://syzkaller.appspot.com/x/.config?x=cfbd94c114a3d407
> > > > dashboard link: https://syzkaller.appspot.com/bug?extid=30eac43568e2b3d65728
> > > > compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
> > > > syz repro: https://syzkaller.appspot.com/x/repro.syz?x=16df4c40580000
> > >
> > > Something seems rather wrong with the "syz repro" page.
> > >
> > >
> >
> > What exactly looks wrong? :)
>
Hi Andrew,
That is not garbage :)
That's the compressed disk image that is mounted by the reproducer.
These images are often also mutated/corrupted and therefore unique in
each case, so we have no other option than to keep them in the
reproducer. If you scroll the file to the bottom, you'll see the other
syscalls that are part of it.
> I click on the link
> (https://syzkaller.appspot.com/x/repro.syz?x=16df4c40580000) and I get
> the below garbage:
--
Aleksandr
>
> > >
> > > # https://syzkaller.appspot.com/bug?id=6b5f76b3a3783e6b1876d25b2d7a981ac0e0131f
> > > # See https://goo.gl/kgGztJ for information about syzkaller reproducers.
> > > #{"threaded":true,"repeat":true,"procs":6,"slowdown":1,"sandbox":"none","sandbox_arg":0,"tun":true,"netdev":true,"resetnet":true,"cgroups":true,"binfmt_misc":true,"close_fds":true,"usb":true,"vhci":true,"wifi":true,"ieee802154":true,"sysctl":true,"swap":true,"tmpdir":true,"segv":true}
> > > syz_mount_image$ntfs3(&(0x7f0000000000), &(0x7f0000000140)='./bus\x00', 0x19c6038, &(0x7f0000000180)=ANY=[], 0x1, 0x1f231, &(0x7f000003e780)="$eJzs3QmYTeUfB/D37Pu+XLvBWEO2RLLvsm+pZAvZyRalGhJRSSWpFElCQqhUEklEsi8JSZKQVEIS/2fu3JlmufOvadf7/TyPOfeee877nnu+94z5ne0ebz25edsGbRISEhKIzZAU50gGSSSJXIq9xsfGXYoNmdi/EZ3nV9ttftQreZxZcOVtoxYUXjVUa7/MfEsim+xOx09VOLwp3JT7+MW2vXoPSeg9JGHAwKEJXRO6DRw4tGu3fj0Suvce0rdsQst+PboO6ZHQe8CQHoMzvNyz38BBg0YmdB3Q3VAHDe4xZEhC1wEjE/r2GJkwdGDC0MEjE7re2rX3gISyZcsmGCqB36jd/H96CQAAAAAAAAAAAAAAAAAA4M9x6VLaoX0AAAAAAAAAAAAAAAAAAAC4TDVo3LR+OaKkPWcIQxoRhsxlCCH2L9OlXvfPZdNO8qRdoo9yRX82Sn10um/5fuf
> > > <and a huge amount more>
> > >
>
^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2024-10-18 7:56 UTC | newest]
Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2024-09-08 22:22 [syzbot] [mm?] BUG: corrupted list in add_to_unbuddied syzbot
2024-10-15 14:52 ` syzbot
2024-10-15 22:39 ` Andrew Morton
2024-10-16 6:19 ` Aleksandr Nogikh
2024-10-16 21:37 ` Andrew Morton
2024-10-18 7:56 ` Aleksandr Nogikh
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox