From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 9B70DC36002 for ; Wed, 9 Apr 2025 14:58:05 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 141126B012C; Wed, 9 Apr 2025 10:58:04 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 11AB3280058; Wed, 9 Apr 2025 10:58:04 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id F22176B0206; Wed, 9 Apr 2025 10:58:03 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0013.hostedemail.com [216.40.44.13]) by kanga.kvack.org (Postfix) with ESMTP id CCE546B0204 for ; Wed, 9 Apr 2025 10:58:03 -0400 (EDT) Received: from smtpin29.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay04.hostedemail.com (Postfix) with ESMTP id 9CFEB1A0B77 for ; Wed, 9 Apr 2025 14:58:04 +0000 (UTC) X-FDA: 83314810488.29.C6079C7 Received: from mail-pj1-f47.google.com (mail-pj1-f47.google.com [209.85.216.47]) by imf16.hostedemail.com (Postfix) with ESMTP id A40F518000C for ; Wed, 9 Apr 2025 14:58:02 +0000 (UTC) Authentication-Results: imf16.hostedemail.com; dkim=pass header.d=google.com header.s=20230601 header.b=BpBx+mC5; spf=pass (imf16.hostedemail.com: domain of nogikh@google.com designates 209.85.216.47 as permitted sender) smtp.mailfrom=nogikh@google.com; dmarc=pass (policy=reject) header.from=google.com ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1744210682; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=CvMlvfko46u4RHI+ZrkaTKVlGUANMNZ6Hd9jSBGGvX0=; b=m5YmJBXKaVfYjOvm4uRFkRmNuoyHgCsnCHu2IOVZxfuSsPZp3vnjnZ0D1iKMgijiZsYONz p6dEs70QhPc1DCQM8WIpeGSiMNpqMtzIy2a0T75azj9mUeU/2M3p81AVaTVh4n41XVSAaG yn5ga2WIBqVQrOPhLct0j4dbu1qJUko= ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1744210682; a=rsa-sha256; cv=none; b=Uzi/ulsv5D8nGltkmoZhzjl3WFVxCtVxdKdd46+7t5V5qxx8iBrNJfAyvaxbmpPoRtJrlt kCOjF7Ogy1+5loK/nrYyQ8IPW0QjXeVDGzjGtGYvSIt7MVEjDpTG6zd79XEwQdizt4tcH3 sZGrd0IXW1tmPj0nh+CxYyQp+ULgS8Q= ARC-Authentication-Results: i=1; imf16.hostedemail.com; dkim=pass header.d=google.com header.s=20230601 header.b=BpBx+mC5; spf=pass (imf16.hostedemail.com: domain of nogikh@google.com designates 209.85.216.47 as permitted sender) smtp.mailfrom=nogikh@google.com; dmarc=pass (policy=reject) header.from=google.com Received: by mail-pj1-f47.google.com with SMTP id 98e67ed59e1d1-2ff6cf448b8so8288578a91.3 for ; Wed, 09 Apr 2025 07:58:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1744210681; x=1744815481; darn=kvack.org; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=CvMlvfko46u4RHI+ZrkaTKVlGUANMNZ6Hd9jSBGGvX0=; b=BpBx+mC5yc3rofM0JOo6sN8qZYZ0TJvJpXihJwoJw+BbpAJmaYHzLIeHMci9IvmFhU 7EI/AlFxym0By1+sx7evT/W1FEFI1bWbN+jnq+P/C6fyU9PcOO7EKwqYLkFTQqhERf0g MQP6gvzkHiUlxyWZ6G7go1XJW6XfL9MQo045oq/ymbNManmOGMDNzo6QMKs2jRNM9JrU 8+9WQbJI8lYo/fQG1OXtgomMZMvg36aG8Egn8FZ1rsNSaBWcVpjaV6WvSG5P9FhH4hNn LHNVa+gr3hIQNBoZb1SNmYlRwe12VHheqeUXajambaalFvvdYAzMiD75/V5oSJeY//u/ SApA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1744210681; x=1744815481; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=CvMlvfko46u4RHI+ZrkaTKVlGUANMNZ6Hd9jSBGGvX0=; b=LwQbZBZO4zqtfwEoTk3L2TDaqsdixyYyMhFLW1GQlXskXLyrLXafMWCUnw629NFbFz 5zWumvm8JT5PAt5We50tPLNiLBASDb5LJiI/A7riZA08KgKBgfnT0kH3GxDimVpTx2Bi Fy/y7CWk3opdR8UAaJ821fyVXViIaRqIVhTNDX1QSzWzcLkW+MC5HuulWo7yCqaMCRm5 3p/pLny2qEWKDtk2HOAYNXNguOrPslEdkuv1ujKawi7QNaGk4YresB0oeiLBgSvOK6Ar cL646wqq9NVRP/OKxmodro+HQl+mY/6m104v9KWspMkaWPt0xXnCoeZBQYcTWRiPBqGu dnCw== X-Forwarded-Encrypted: i=1; AJvYcCWO0cPwUj/g3+v3AqAplSmoi+PKS/ujfqnZ+5IiZRrbLnuXeulScMCZtm3CoJAftvalqYooJBlNcw==@kvack.org X-Gm-Message-State: AOJu0YzVKiMO8jcy3Z68Cjhzc/5Ciz6lNBx0j8qxwu/avxygVFXsZcSn VUqPfoVPEKAeyI/XL1GPkkoAEvwnPjPlaoJeUjrsX51CX+Zc1cKSMBXGRvtSUJramlJrKhzAv/X Q9V7cIRDyLQ0QI/TgeX3UfzbeOVzzm35Z0143 X-Gm-Gg: ASbGncuxDfDBbufiI/JpfQEXdThvMSjUG1UVivqHjLxMinVVMFhCglIFccqLWdVG997 /XkT5zR4a17YjFHLSMueigyRiGXKfOqvXzdZZ7VhdMBz1VGSy4603OpU9MOD0EXs0HhAZb8u4FY JcA7ShV52dinXgv9baK+2ryjT7tjvl7b2R7WglEWrfTWJ+qQu/G2Y= X-Google-Smtp-Source: AGHT+IEBuaQzZT6cZRe8i4Tk3RuO+xRnC2wpUKEDzJxdy3h1MXpKvK37q+3S5kT7paX1Kxc25syW6S0AgqMDQwgmbHI= X-Received: by 2002:a17:90b:58e5:b0:2ee:d024:e4fc with SMTP id 98e67ed59e1d1-306dbc3b998mr5892291a91.33.1744210680984; Wed, 09 Apr 2025 07:58:00 -0700 (PDT) MIME-Version: 1.0 References: <67f1c7df.050a0220.0a13.0256.GAE@google.com> <07a22812-4f5b-44e2-a4ce-ad0537934041@lucifer.local> <6efd1c14-2253-4b7d-a647-dce471ffff6f@lucifer.local> In-Reply-To: <6efd1c14-2253-4b7d-a647-dce471ffff6f@lucifer.local> From: Aleksandr Nogikh Date: Wed, 9 Apr 2025 16:57:48 +0200 X-Gm-Features: ATxdqUG6KUCUBx9kzevP8gUZQU5FsDzE806IM-OMR39N2wxGiq9ldb7sCnOzmjQ Message-ID: Subject: Re: [syzbot] [mm?] general protection fault in mremap To: Lorenzo Stoakes Cc: syzbot , Liam.Howlett@oracle.com, akpm@linux-foundation.org, jannh@google.com, linux-kernel@vger.kernel.org, linux-mm@kvack.org, syzkaller-bugs@googlegroups.com, vbabka@suse.cz, syzkaller Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Rspam-User: X-Rspamd-Server: rspam10 X-Rspamd-Queue-Id: A40F518000C X-Stat-Signature: b86kub4g5i7ghtwm8iierginxs1r4cjj X-HE-Tag: 1744210682-123975 X-HE-Meta: U2FsdGVkX18uUf+UEMs3quE0Klddqb1G6TiET5dq7KF7zeP30HI+P4QPEqfs8XohwFrG1a3hYyD8bFoLrG68e6FrCXZdLwG/3H5i90BO52lPmEQWlAHawgvaibZYR2sDaoNnuDJrraku84Gwg2e7ErGcuTGGbueRyc8GQGdiffn6y8ceV+X4iU90H5DdgP06o7JKYYETVAHTTjqEo/n8r862MNJfxx4DD3LXeUj3n+RKIsDickZ+xqg32sA4WG/a1zNeLNDELlS+rF7mWpMgtCihpCMbkoU1HY4ZZ9XcBxXOc0HCWNeqy2IQku8URV+c+NS2RZXBKrIbYTlGVnEuNQRk6+VaRfQikjJNTloRFHPdUYNcUz1mSWqrqLmSzDVuAVy6YhtX/DCQfY+OOxjeOhB7ZXjwJpMFQsYvq2SAbDL3I0ESkfRMDi/uNeWLwkYQ0KcfhvBR2lf4R39/k2omBC8S2RaMHo/G5fc8JdwdyiRYXzSVEKy2/Y73RcoKxPJHthPjTYQqc69oE0kJYOE5/XhOCygTsNaImRE2I3+pXARaPMHQ0/bAHlDdh7OXKHfxJJGcdKMsnAhfXuHVlN+rYBlWgvtIXnyiYwrxj4M4llSN9/mQVnMZz3bGjP+jzd4Mhu+VoLq5De6+T4DGbECKP5F9cZe9RdDPfLYJxjOh4I/M7YPvsg2zazpc8+gUa6JMMquhr3jckLTih+LfQ2vbou6fEpEoW0z1WctOqaEKtj2K/grcaH16A/6vEI8i4JlZ85ikULvwUUW8/XJTakaL+RA/S/ZUzNnaxQOMO4a56enwIFzRYf4CmPYq4QN6PBs+7WT7FpTFPKr9OzOLW5cEuYZ66/8RHCHBWP0xioNA65QdQrIY+jYK2NkFwL/hlJPT8CH3p+f4mpTjz/4EhDHQ992X2zG1rqRUZUWwfloliOGMFqCKahG1ExvJ0Vhfw3tBMMmqAcx6tsFDbjb2tKy OGpwrSdk fOwcSI9d3YyFIlxvOq0b/RkDhMNrrUdi8j7GPa9v5DY3KHU3nhsQWLB2aoCTyU7ISgMjMYOasAOiLAHT5cu+f59nI+NoaJUIvoh6yuPJAwZqCzznv3UwkEfaBrGQzy3pWYMWJlVdjC2Zgh4aTgQfQSZIys/0veUx54e0q1ZSVg2zqsWjAR+VB1Gae+Iurf/JR9hgZHC9UMkB3eKT4qRuxe99GdYfawptBe8ZX+BhArDQMB1y1mLJrKkPXi2+rjpBDh3R4ZcUSN+aQkn8rkQg+9agyAFP+VB/uSdQ9KY1qaMaBnps+Z1+EPrpH3fD6d/8Cl7sJZ16ScxiGalsJcEuWRDcnSN1h4uAcgL7aJLu2GpcToNqzCrUCvFQBDsoCaabcmfYg9Elvy+UGusIj9DXPTAR/Z1UKiYLipc6gyZSnhOShYwufYUOIIJpNk7uyv/da6b/XWBG5Vf9zeAdKgjLry+MNkAhPVg0qpvmkoHtGsTy7XRaHWK+TzX+9KGElCXfhD/d6qjmjLGqvH1bJ5g0W3BDLuMx2Ao1cA/FZ5Ilftzy0NI1YW6F68of6CZHlYREKJSoIuWV8cELOKgrQ8dpp2xs6l3q6zeOhuDJL5PTrtSETKygOHw2KRbxDnC+bJv8dspaoIT473ueHn4+IXpS7SYtVkdrFNRwRuw0i6f7qcXSiFetU3TvyIIhu04J495VJHT0snxWSRKGJjaHq54nDK965L6va2ZIhEb7QPtbdq46babeoOvLoqJJB3Ooz9XVbwrHAAACgRpey8ApA4fahJhboyiY9K/rmD+00HUwazn9YmLFXU+W6/ho1RrAMxx+U4wjxMIBdgKawmF3dVI/HpA8JjF9i1PHG3bl4lX4z2w2GRvQ1/TR3K7H94FlRbew8lrVeYX0DtFjb5jvvvTMMkToDvMhLyHCVxaassOpBGGfHHM5n/xrui4TSnfRgwddjWt2SXenFZkkfzPzMZKfG6aXGnaZX K8ITYtKN Mb0q+8FjCHIvaGrCQT5N44ndnOtlCtHyjoGqprnwbEEhlQ4zhNG3ffyoClTlzjyjvrAsm/Q9zytuEUq8DqdS/A== X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: List-Subscribe: List-Unsubscribe: On Mon, Apr 7, 2025 at 12:28=E2=80=AFPM Lorenzo Stoakes wrote: > > On Mon, Apr 07, 2025 at 12:13:19PM +0200, Aleksandr Nogikh wrote: > > Hi Lorenzo, > > > > Thanks for looking at the report! > > > > On Mon, Apr 7, 2025 at 12:09=E2=80=AFPM 'Lorenzo Stoakes' via syzkaller= -bugs > > wrote: > > > > > > I did actually try to mark this fixed, but apparently syz fix doesn't= work or > > > doesn't prevent other syzbots from duplicating reports. > > > > This part is not very clear - why would #syz fix: title not work well h= ere? > > Sorry for not being clear. What I mean is that I already did this on > another thread with the same, duplicate, report - and then received this > one afterwards. > > This suggests to me that this does nothing, or does nothing useful at lea= st > if other bots will just keep on reporting the same thing. When syzbot receives the #syz fix command, it keeps the bug open until the fixing commit has reached all the kernel trees it fuzzes. After that, if the bug is seen again, it's reported as a separate issue with the (2) suffix, then (3), etc. If the bug manifested itself with different crash titles, marking just one report as fixed won't affect others indeed - if syzbot knew they were related, it would not have reported them separately. What was the other thread/bug in this case? Maybe we could adjust our kernel crash log parsing rules to prevent similar duplicates. > > I appreciate that recognising that it is the same issue might not be > trivial, but obviously it's not a hugely great use of my time to repeated= ly > chase this stuff up when the fix is already upstream and I've already > -manually- confirmed it works. > > My patience with it was somewhat eroded from my experience of telling > syzbot in the previous thread [0] to re-test, twice, and it failing to do > so due to broken presumably VM images, leading to me having to manually > test the same fix I already tested and fixed a while ago etc. etc. > > [0]: https://lore.kernel.org/all/bee2d5f5-db93-42f1-829e-3fd250649ca8@luc= ifer.local/ FWIW the "unregister_netdevice: waiting for batadv0 to become free. Usage count =3D 3" bug is discussed here: https://lore.kernel.org/all/CANp29Y5RjJD3FK8zciRL92f0+tXEaZ=3DDbzSF3JrnVRGy= Dmag2A@mail.gmail.com/t/#u This is an actual bug in v6.15-rc1 that's plaguing Linux kernel fuzzing on syzbot at the moment. > > We do very much appreciate syzbot reports, don't get me wrong here, but I > do also have to partition my time somewhat :) > > So I'm afraid I can't promise to always do syz fix updates on this basis. Sure. Also please feel free to ping us whenever syzbot's behavior is annoying you= :) --=20 Aleksandr > > Cheers, Lorenzo > > > > > > > > > Anyway, this is fixed in commit 36eed5400805 ("mm/mremap: do not set > > > vrm->vma NULL immediately prior to checking it"), was fixed a long ti= me > > > ago, as soon as reported, and it's been a matter of waiting for this = to > > > land in Linus's tree. > > > > > > This is now fixed, upstream, and this report is - as a result - redun= dant. > > > > > > Thanks, Lorenzo > > > > -- > > Aleksandr > > > > > > > > On Sat, Apr 05, 2025 at 05:16:31PM -0700, syzbot wrote: > > > > Hello, > > > > > > > > syzbot found the following issue on: > > > > > > > > HEAD commit: a2cc6ff5ec8f Merge tag 'firewire-updates-6.15' of g= it://gi.. > > > > git tree: upstream > > > > console+strace: https://syzkaller.appspot.com/x/log.txt?x=3D11ab27c= f980000 > > > > kernel config: https://syzkaller.appspot.com/x/.config?x=3Dadffebe= fc9feb9d6 > > > > dashboard link: https://syzkaller.appspot.com/bug?extid=3D5250c4727= db03e3436cc > > > > compiler: gcc (Debian 12.2.0-14) 12.2.0, GNU ld (GNU Binutils= for Debian) 2.40 > > > > syz repro: https://syzkaller.appspot.com/x/repro.syz?x=3D1693d= 404580000 > > > > C reproducer: https://syzkaller.appspot.com/x/repro.c?x=3D178ac94= c580000 > > > > > > > > Downloadable assets: > > > > disk image: https://storage.googleapis.com/syzbot-assets/8ecd231806= 7e/disk-a2cc6ff5.raw.xz > > > > vmlinux: https://storage.googleapis.com/syzbot-assets/05691b82062c/= vmlinux-a2cc6ff5.xz > > > > kernel image: https://storage.googleapis.com/syzbot-assets/4698994e= 99d4/bzImage-a2cc6ff5.xz > > > > > > > > The issue was bisected to: > > > > > > > > commit d5c8aec0542e2d79b64de9089b88fabdebe05c1e > > > > Author: Lorenzo Stoakes > > > > Date: Mon Mar 10 20:50:37 2025 +0000 > > > > > > > > mm/mremap: initial refactor of move_vma() > > > > > > > > bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=3D11ff= 2a74580000 > > > > final oops: https://syzkaller.appspot.com/x/report.txt?x=3D13ff= 2a74580000 > > > > console output: https://syzkaller.appspot.com/x/log.txt?x=3D15ff2a7= 4580000 > > > > > > > > IMPORTANT: if you fix the issue, please add the following tag to th= e commit: > > > > Reported-by: syzbot+5250c4727db03e3436cc@syzkaller.appspotmail.com > > > > Fixes: d5c8aec0542e ("mm/mremap: initial refactor of move_vma()") > > > > > > > > Code: 48 83 c4 28 c3 e8 17 1a 00 00 0f 1f 80 00 00 00 00 48 89 f8 4= 8 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01= f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48 > > > > RSP: 002b:00007fff0b8738c8 EFLAGS: 00000246 ORIG_RAX: 0000000000000= 019 > > > > RAX: ffffffffffffffda RBX: 00007fff0b8738d0 RCX: 00007f46ffb182e9 > > > > RDX: 0000000000003000 RSI: 0000000000001000 RDI: 0000200000ffc000 > > > > RBP: 0000000000000001 R08: 0000200000ffa000 R09: 00007f46ffb80031 > > > > R10: 0000000000000000 R11: 0000000000000246 R12: 00007f46ffb83618 > > > > R13: 00007fff0b873aa8 R14: 0000000000000001 R15: 0000000000000001 > > > > > > > > Oops: general protection fault, probably for non-canonical address = 0xdffffc0000000004: 0000 [#1] SMP KASAN NOPTI > > > > KASAN: null-ptr-deref in range [0x0000000000000020-0x00000000000000= 27] > > > > CPU: 0 UID: 0 PID: 5820 Comm: syz-executor115 Not tainted 6.14.0-sy= zkaller-12966-ga2cc6ff5ec8f #0 PREEMPT(full) > > > > Hardware name: Google Google Compute Engine/Google Compute Engine, = BIOS Google 02/12/2025 > > > > RIP: 0010:vrm_uncharge mm/mremap.c:964 [inline] > > > > RIP: 0010:expand_vma_in_place mm/mremap.c:1566 [inline] > > > > RIP: 0010:expand_vma mm/mremap.c:1621 [inline] > > > > RIP: 0010:mremap_at mm/mremap.c:1682 [inline] > > > > RIP: 0010:do_mremap mm/mremap.c:1727 [inline] > > > > RIP: 0010:__do_sys_mremap+0x1392/0x15c0 mm/mremap.c:1784 > > > > Code: 0f 85 45 02 00 00 48 8b 04 24 c6 84 24 70 01 00 00 01 48 01 8= 5 68 02 00 00 eb 9a e8 18 34 af ff 48 b8 04 00 00 00 00 fc ff df <80> 38 00= 0f 85 a7 01 00 00 48 8b 2c 25 20 00 00 00 31 ff 81 e5 00 > > > > RSP: 0018:ffffc900039dfd20 EFLAGS: 00010293 > > > > RAX: dffffc0000000004 RBX: ffff88802b765a00 RCX: ffffffff821183c6 > > > > RDX: ffff88805c7b8000 RSI: ffffffff820c0cb8 RDI: 0000000000000005 > > > > RBP: ffff8880341fb780 R08: 0000000000000005 R09: 0000000000000000 > > > > R10: 00000000fffffff4 R11: 0000000000000001 R12: 0000000000002000 > > > > R13: 1ffff9200073bfaa R14: 0000200000ffc000 R15: ffff88802b765b70 > > > > FS: 00005555814db380(0000) GS:ffff8881249b8000(0000) knlGS:0000000= 000000000 > > > > CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 > > > > CR2: 00007fff0b8728e0 CR3: 000000007802e000 CR4: 00000000003526f0 > > > > DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 > > > > DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 > > > > Call Trace: > > > > > > > > do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] > > > > do_syscall_64+0xcd/0x260 arch/x86/entry/syscall_64.c:94 > > > > entry_SYSCALL_64_after_hwframe+0x77/0x7f > > > > RIP: 0033:0x7f46ffb182e9 > > > > Code: 48 83 c4 28 c3 e8 17 1a 00 00 0f 1f 80 00 00 00 00 48 89 f8 4= 8 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01= f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48 > > > > RSP: 002b:00007fff0b8738c8 EFLAGS: 00000246 ORIG_RAX: 0000000000000= 019 > > > > RAX: ffffffffffffffda RBX: 00007fff0b8738d0 RCX: 00007f46ffb182e9 > > > > RDX: 0000000000003000 RSI: 0000000000001000 RDI: 0000200000ffc000 > > > > RBP: 0000000000000001 R08: 0000200000ffa000 R09: 00007f46ffb80031 > > > > R10: 0000000000000000 R11: 0000000000000246 R12: 00007f46ffb83618 > > > > R13: 00007fff0b873aa8 R14: 0000000000000001 R15: 0000000000000001 > > > > > > > > Modules linked in: > > > > ---[ end trace 0000000000000000 ]--- > > > > RIP: 0010:vrm_uncharge mm/mremap.c:964 [inline] > > > > RIP: 0010:expand_vma_in_place mm/mremap.c:1566 [inline] > > > > RIP: 0010:expand_vma mm/mremap.c:1621 [inline] > > > > RIP: 0010:mremap_at mm/mremap.c:1682 [inline] > > > > RIP: 0010:do_mremap mm/mremap.c:1727 [inline] > > > > RIP: 0010:__do_sys_mremap+0x1392/0x15c0 mm/mremap.c:1784 > > > > Code: 0f 85 45 02 00 00 48 8b 04 24 c6 84 24 70 01 00 00 01 48 01 8= 5 68 02 00 00 eb 9a e8 18 34 af ff 48 b8 04 00 00 00 00 fc ff df <80> 38 00= 0f 85 a7 01 00 00 48 8b 2c 25 20 00 00 00 31 ff 81 e5 00 > > > > RSP: 0018:ffffc900039dfd20 EFLAGS: 00010293 > > > > RAX: dffffc0000000004 RBX: ffff88802b765a00 RCX: ffffffff821183c6 > > > > RDX: ffff88805c7b8000 RSI: ffffffff820c0cb8 RDI: 0000000000000005 > > > > RBP: ffff8880341fb780 R08: 0000000000000005 R09: 0000000000000000 > > > > R10: 00000000fffffff4 R11: 0000000000000001 R12: 0000000000002000 > > > > R13: 1ffff9200073bfaa R14: 0000200000ffc000 R15: ffff88802b765b70 > > > > FS: 00005555814db380(0000) GS:ffff8881249b8000(0000) knlGS:0000000= 000000000 > > > > CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 > > > > CR2: 00007fff0b8728e0 CR3: 000000007802e000 CR4: 00000000003526f0 > > > > DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 > > > > DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 > > > > ---------------- > > > > Code disassembly (best guess): > > > > 0: 48 83 c4 28 add $0x28,%rsp > > > > 4: c3 ret > > > > 5: e8 17 1a 00 00 call 0x1a21 > > > > a: 0f 1f 80 00 00 00 00 nopl 0x0(%rax) > > > > 11: 48 89 f8 mov %rdi,%rax > > > > 14: 48 89 f7 mov %rsi,%rdi > > > > 17: 48 89 d6 mov %rdx,%rsi > > > > 1a: 48 89 ca mov %rcx,%rdx > > > > 1d: 4d 89 c2 mov %r8,%r10 > > > > 20: 4d 89 c8 mov %r9,%r8 > > > > 23: 4c 8b 4c 24 08 mov 0x8(%rsp),%r9 > > > > 28: 0f 05 syscall > > > > * 2a: 48 3d 01 f0 ff ff cmp $0xfffffffffffff001,%rax <-- t= rapping instruction > > > > 30: 73 01 jae 0x33 > > > > 32: c3 ret > > > > 33: 48 c7 c1 b8 ff ff ff mov $0xffffffffffffffb8,%rcx > > > > 3a: f7 d8 neg %eax > > > > 3c: 64 89 01 mov %eax,%fs:(%rcx) > > > > 3f: 48 rex.W > > > > > > > > > > > > --- > > > > This report is generated by a bot. It may contain errors. > > > > See https://goo.gl/tpsmEJ for more information about syzbot. > > > > syzbot engineers can be reached at syzkaller@googlegroups.com. > > > > > > > > syzbot will keep track of this issue. See: > > > > https://goo.gl/tpsmEJ#status for how to communicate with syzbot. > > > > For information about bisection process see: https://goo.gl/tpsmEJ#= bisection > > > > > > > > If the report is already addressed, let syzbot know by replying wit= h: > > > > #syz fix: exact-commit-title > > > > > > > > If you want syzbot to run the reproducer, reply with: > > > > #syz test: git://repo/address.git branch-or-commit-hash > > > > If you attach or paste a git patch, syzbot will apply it before tes= ting. > > > > > > > > If you want to overwrite report's subsystems, reply with: > > > > #syz set subsystems: new-subsystem > > > > (See the list of subsystem names on the web dashboard) > > > > > > > > If the report is a duplicate of another one, reply with: > > > > #syz dup: exact-subject-of-another-report > > > > > > > > If you want to undo deduplication, reply with: > > > > #syz undup > > > > > > -- > >