From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 19D60C71136 for ; Wed, 11 Jun 2025 15:59:04 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 9AD0F6B00A2; Wed, 11 Jun 2025 11:59:03 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 985066B00A5; Wed, 11 Jun 2025 11:59:03 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 89B096B00A7; Wed, 11 Jun 2025 11:59:03 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0010.hostedemail.com [216.40.44.10]) by kanga.kvack.org (Postfix) with ESMTP id 693146B00A2 for ; Wed, 11 Jun 2025 11:59:03 -0400 (EDT) Received: from smtpin26.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay05.hostedemail.com (Postfix) with ESMTP id 109115E152 for ; Wed, 11 Jun 2025 15:59:03 +0000 (UTC) X-FDA: 83543578566.26.31482BB Received: from mail-lf1-f44.google.com (mail-lf1-f44.google.com [209.85.167.44]) by imf27.hostedemail.com (Postfix) with ESMTP id 100B540007 for ; Wed, 11 Jun 2025 15:59:00 +0000 (UTC) Authentication-Results: imf27.hostedemail.com; dkim=pass header.d=gmail.com header.s=20230601 header.b=H1Zu+ihX; spf=pass (imf27.hostedemail.com: domain of urezki@gmail.com designates 209.85.167.44 as permitted sender) smtp.mailfrom=urezki@gmail.com; dmarc=pass (policy=none) header.from=gmail.com ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1749657541; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=ZIiReEJBibfyKym+mddQ8h+3q2gL3jR6Gy15euZGwtk=; b=V9v+Xj4ntdZW97dv6rkh3ZLTSKD4zi6BvCHnXxi9ObNSrIrX6o9NHmAk5ABaZNUDhE2AOF 6BjvcKqd6t+nra/6ts/itIA9KPStBGyAAsbCp+68qrpxjTRGCv6zjtd0/sxy4apDeAvRMW HLil0VChyVsXxPTmTWaWMg52LBEF4KA= ARC-Authentication-Results: i=1; imf27.hostedemail.com; dkim=pass header.d=gmail.com header.s=20230601 header.b=H1Zu+ihX; spf=pass (imf27.hostedemail.com: domain of urezki@gmail.com designates 209.85.167.44 as permitted sender) smtp.mailfrom=urezki@gmail.com; dmarc=pass (policy=none) header.from=gmail.com ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1749657541; a=rsa-sha256; cv=none; b=BquZicvIvlYcznHxbSbveMGKy8O42hfqQ4JsnCDooOtr/pCBoTZCHG7vqPpxw7arWQcpji 7Ihm4Ipvd4OVwLhD3uEx/pr2xnK0aC5ZqQv4Nbg8E3kqepMxdnTa/y6LBOKCxWfF6y0pmP cB4fenwy1OOjnjyImofXtiPPazPkXZo= Received: by mail-lf1-f44.google.com with SMTP id 2adb3069b0e04-5536b9be607so4772108e87.0 for ; Wed, 11 Jun 2025 08:59:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1749657539; x=1750262339; darn=kvack.org; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:date:from:from:to:cc:subject:date:message-id:reply-to; bh=ZIiReEJBibfyKym+mddQ8h+3q2gL3jR6Gy15euZGwtk=; b=H1Zu+ihXn9yq8ISYlW2YFwstUyXritUPnN1anZ9eaErFQKVVx6ueTPvNdFCBUbwx2t VDWEOjyAZq76QyQZaqK60UEwpisoyaJYglS84IpeHtBsgA6XEgtQFiMMheNuc2cQIRcN 2HgWcQcH2WVQNkPZ7UNvyRYdJjlIlUXCs2mfVCM20eOgo9j0D/0eeadF8hZZfBlN/wpg MNOI22qjq0ltZUZ7T0DZJprH7iXSbPwkYDuAM3xZK1aeJpXtq036GN83Dz19R63fyOev /jmAN627yvG7smU91SgiR5xhEW0804r5olsqry0S8l8gdNLGl++RZDMivUKb8uEgDkqt p/SQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1749657539; x=1750262339; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:date:from:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=ZIiReEJBibfyKym+mddQ8h+3q2gL3jR6Gy15euZGwtk=; b=X7CPuyiFgjmvnEbV9YcDUl1WoQpB+TA/kXgIHqQOPLaLizSoH9KmWj0GnMbKsS7xQi WDfGoszBb4/aJmgS1r9/4xuydB7F29qSjHjzUokOKMP7n8dOyGZCwbWHNbQ4cJsoyCmc infRJ462gvIzR1qzfOk2qaX/IKwr/4qOqPsHcpr30X+q4FeWY82Sl3+svb5Z0SMDiAg2 /C7PU5CDZBsP5FmPc3kWuLd9GI4GoQkiCBZk6s1hutGDDO/VaKuSlcCEQgkGQjC+CS1y oAtMFLoigyP5rUn54S75JAYjOL57cGscMRyi1gmDQm/R+MJyvIvPVnOluVh43L80XHky xHMw== X-Forwarded-Encrypted: i=1; AJvYcCXrL42bsz4tlJzv9QZnYmJxxyF5S9r76zkRGlhbv3k2cCCFjWjbAhsSb9c9JZwhYZxWXOrSGghVoA==@kvack.org X-Gm-Message-State: AOJu0Yy1kNZbuMgVcIvVJZsJFORzSiSjkkQLBmPgPKhGZNjqgEB0oix6 hR8kNIrcTGuHkxagG18Mvqi4kzjABVH1h51GfzopFJqDeVL67cWvkQSc X-Gm-Gg: ASbGnctIuJTIvwD1EDwZx3s8UAdbpDi0zXz0J1nUvXI2WFsN13oPGmjEq4sZh39AhLA Oc2Hyc9A9EsblRwXIHXRE3l40N/zZh7PRG6h2tREuAO1Kd56y/tYrWTP9Ou4XAR+vRWLmiOxtGU E+Dv8M1Wl8nmrJPvXfzLFX+99pPonIVWXJFjl12bslOSsdY/2kVp5MIvweVn+Q+6tGdSGRJDJrM D9KCtC53LV2isiIqkaVvCdN2GkxbDy9vaIQ4ha1OjJjqRzIH9jSXJ+O9uWw0WEKb6nnANJX85k4 iS6QyZr00go59SW7BhLLSODrXYKAeUtCrQknHfivpZJlK+AomIczYp8tGqNhLj1CIWhTB8DVIQC 98VrjVt3+0Ws+x3NvvvwS7A== X-Google-Smtp-Source: AGHT+IGR6FlSC3lQaq2+a03g/KZgD2RAZnzFYe8kXns9s6R04xWJKJzw/GuhfWmda0AdU7tvnmI4jw== X-Received: by 2002:a05:6512:3da2:b0:553:291f:92e with SMTP id 2adb3069b0e04-5539c1715cbmr1215100e87.39.1749657538750; Wed, 11 Jun 2025 08:58:58 -0700 (PDT) Received: from pc636 (host-95-203-1-180.mobileonline.telia.com. [95.203.1.180]) by smtp.gmail.com with ESMTPSA id 2adb3069b0e04-553676d75c2sm2013702e87.61.2025.06.11.08.58.57 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 11 Jun 2025 08:58:58 -0700 (PDT) From: Uladzislau Rezki X-Google-Original-From: Uladzislau Rezki Date: Wed, 11 Jun 2025 17:58:55 +0200 To: syzbot Cc: akpm@linux-foundation.org, josh@joshtriplett.org, kent.overstreet@linux.dev, linux-bcachefs@vger.kernel.org, linux-kernel@vger.kernel.org, linux-mm@kvack.org, paulmck@kernel.org, rcu@vger.kernel.org, syzkaller-bugs@googlegroups.com Subject: Re: [syzbot] [rcu?] [bcachefs?] BUG: unable to handle kernel NULL pointer dereference in rcu_core (3) Message-ID: References: <67a2b20a.050a0220.50516.0003.GAE@google.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <67a2b20a.050a0220.50516.0003.GAE@google.com> X-Rspamd-Queue-Id: 100B540007 X-Rspamd-Server: rspam07 X-Stat-Signature: zoc98kgaphr6dmtwf5rbsr9c4cn933qj X-Rspam-User: X-HE-Tag: 1749657540-576288 X-HE-Meta: U2FsdGVkX18/JWZ3v569twQY/LdlIrH9UQoHpgV072NfiYtWlUWXUDksjsW+qUO3t+TJxPjghZiX3OGhmlKrDGH/9zis14eX1y4jyVwKJ2U4hH4rGRRZCro7rGQcCEhSQuyFGhjC/8Ch309rh3HQcnqNPRIjjEXgZ4ypBo4HFluMwSiDgutQCHB8B/4lhvlHWO056qj1/9m1WQJH1skvvwvcfo79eQQ+aFZIA1OK5NEzVGgX26T/HfpSJopSOw9QEaxi3bjGcTUQMkaK6ocCcjmYj6O2pCTRJ8NGswlpaZmpTSU3+V0VUQ6XB/GsX4znRGmQr6MP5e/nEWo9ZhXId7yb4j2APy6LoVkl0BgeekmEhR74DWhWNw3oCdlHMCTaZFNbs8uUlKCtO+YNVMo9iT1wx/urGAS//cHBwkjfdDDtMRSq+hZFpOq1ofnoEl0RFp7gwwwzdBmBTg+LfOGg1u5572JnEqZjntxwE3M35QCh/YiX7S17SyqlqtST0XqOmX5QWJZyccgv4QpoKmD0DhZlsBXDVgnV7777C8g3xgmXGIkLskDr6Cpf16GbFX94In/V1g4NmyaNgXFFAm3dIgGchWgJS7GErgmrt7tddpXJZZQ+SG0XINsNTZUz9UOQYgRVtKMM/aXK2kh/u9mHyNGqQazOOYd8ELhkX0jZqWtkGCcakFLuM22EDI8qfGnt9pb7vkVJT/NTPY4/5z5LrPNrF1hIiRsya6CpHvZ2H24Xc2HCTx20Iy3mSkTgBd9021khaI1N3UFP2hgdAQDzx+rBMJ3X0asN5WDEbMmbMDwFf47JMQZxEnrii2lhxyfpPFER9qVeS+PrY+b1m8dcpDZdNIyFEym0yX5KFv1mrcruZIE90Ldadd2aMblT8n9OlGZe2PaYhGS4quBpb6EcQqVA1yopRD846PJAGyMM4ccuGO5wHcFz5W9ldRCN7g2hT4KkFd/egYNYBIqnYLL 82bw9rdg 021QV/khzHtEt5Jvo2acUAJ4cWTHT2N+xT07QBtacO6jGKRcsLMzuJt/nB448rgk73A6F1ux/Hk9aneq+oIR0wc063Ob2ODz7g+ASXQi52oRfzE/6Hxfq2b0uiQGMkmfoLBpi81DxM/wtMnMcMuxEQXmzKwTNUWpbHx9QEoug/tmPwYsxWNBovZP41xqbdgsaWKQKF+S9jgCspoLSFzeSqskju3Wd+QscH9waANP3SwSdiFCle2wqXRZ41YqkUFOKb1kgzyik2UTbnQy51sT8oa1sVB6cvuCTBjIQyPd40FBW8qOoYrbV0xloGjjnYxpR49jnHnM2nN8+avdS+eCXGbFIrg08apZvqw1kMJg8o6fSXcVkSp3sGORHlC4365fwmFW23jTzSotbFuihsvlsSc0HugvUm/6G+daaUcPmtJtuN+jFMjpR3PrmruPYaJbA/Bg1ymDYpD89bJdFJcJMa57KLKLQcraiUb2GD8Hikt9K3fnSx3UPpTZkagFKOJREJlTyn5sWZnaDZgIO8Ay7oFt1IBRpcOXU600+eOXle8diIJQ/TimHyUjlMHIhictJzPXvPCAbKaT4/2ryUfY+k4ZZS/B3OTjb6dxDvxmlG7FZut4GNWMmsYLiTRwCU2hEJflx6xrj5AASwojqPOfNMgDGphecCsTZ0OL68oU3mpGZYgHrBIArNyhjXOvYYteJNv+LN/XaLmNwJ69QsoWRjpmU09CFbOPUtPoNZabrgT2KG8UbnHF5IZgzyPMMiXmhGJx++FKSWgzneZq+Ozt2tp8sNjmrRPDND9OsvuWZi2Ja6jRn2D2UlkWtNHPkn+NBdiro2CNmXO+EvGiMvdCrRgAgWB6A5+oTceXohLwqPlly3bl3382/JLGveqjGJIOApkYAy60h3rgQ3gKWWKowhNrP2ZZFi8lnH509raUY3kY8B6pjvDhC/ggX937h473XDbSM5c+5f638rM1OKmmhTz3Wccq0 HVCqqyOp IBl/liPXwt9gsKEdb2pag4BlIBCN2vE3oCiEfSPLBuP5GP0nbcmIHhop8EIgsFETjV6QpBE9FrE0udOIgf+HJFNEJHgIfOLHflSjugQxZ+pFVYrcNiYOs3QUHDxcXj7P/rIjCtuTPUnUOKVE+iOz0jdYa0GVH9bdYeM7U/9gOQ7xBXd4pfci7Il9/1lMgJ75DJJw03AmH2lSW6xp0cPfUSixVf9hpPOVBxq1o/a9B8OfH23yFcoJIw== X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: List-Subscribe: List-Unsubscribe: On Tue, Feb 04, 2025 at 04:34:18PM -0800, syzbot wrote: > Hello, > > syzbot found the following issue on: > > HEAD commit: 0de63bb7d919 Merge tag 'pull-fix' of git://git.kernel.org/.. > git tree: upstream > console output: https://syzkaller.appspot.com/x/log.txt?x=10faf5f8580000 > kernel config: https://syzkaller.appspot.com/x/.config?x=1909f2f0d8e641ce > dashboard link: https://syzkaller.appspot.com/bug?extid=80e5d6f453f14a53383a > compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40 > syz repro: https://syzkaller.appspot.com/x/repro.syz?x=16b69d18580000 > > Downloadable assets: > disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/7feb34a89c2a/non_bootable_disk-0de63bb7.raw.xz > vmlinux: https://storage.googleapis.com/syzbot-assets/1142009a30a7/vmlinux-0de63bb7.xz > kernel image: https://storage.googleapis.com/syzbot-assets/5d9e46a8998d/bzImage-0de63bb7.xz > mounted in repro: https://storage.googleapis.com/syzbot-assets/526692501242/mount_0.gz > > IMPORTANT: if you fix the issue, please add the following tag to the commit: > Reported-by: syzbot+80e5d6f453f14a53383a@syzkaller.appspotmail.com > > slab radix_tree_node start ffff88803bf382c0 pointer offset 24 size 576 > BUG: kernel NULL pointer dereference, address: 0000000000000000 > #PF: supervisor instruction fetch in kernel mode > #PF: error_code(0x0010) - not-present page > PGD 0 P4D 0 > Oops: Oops: 0010 [#1] PREEMPT SMP KASAN NOPTI > CPU: 0 UID: 0 PID: 5705 Comm: syz-executor Not tainted 6.14.0-rc1-syzkaller-00020-g0de63bb7d919 #0 > Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014 > RIP: 0010:0x0 > Code: Unable to access opcode bytes at 0xffffffffffffffd6. > RSP: 0018:ffffc90000007bd8 EFLAGS: 00010246 > RAX: dffffc0000000000 RBX: 1ffff110077e705c RCX: 23438dd059a4b100 > RDX: 0000000000000100 RSI: 0000000000000000 RDI: ffff88803bf382d8 > RBP: ffffc90000007e10 R08: ffffffff819f146c R09: 1ffff11003f8519a > R10: dffffc0000000000 R11: 0000000000000000 R12: ffffffff81a6d507 > R13: ffff88803bf382e0 R14: 0000000000000000 R15: ffff88803bf382d8 > FS: 0000555567992500(0000) GS:ffff88801fc00000(0000) knlGS:0000000000000000 > CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 > CR2: ffffffffffffffd6 CR3: 000000004da38000 CR4: 0000000000352ef0 > DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 > DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 > Call Trace: > > rcu_do_batch kernel/rcu/tree.c:2546 [inline] > rcu_core+0xaaa/0x17a0 kernel/rcu/tree.c:2802 > handle_softirqs+0x2d4/0x9b0 kernel/softirq.c:561 > __do_softirq kernel/softirq.c:595 [inline] > invoke_softirq kernel/softirq.c:435 [inline] > __irq_exit_rcu+0xf7/0x220 kernel/softirq.c:662 > irq_exit_rcu+0x9/0x30 kernel/softirq.c:678 > instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1049 [inline] > sysvec_apic_timer_interrupt+0xa6/0xc0 arch/x86/kernel/apic/apic.c:1049 > > > asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:702 > RIP: 0010:__raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:152 [inline] > RIP: 0010:_raw_spin_unlock_irqrestore+0xd8/0x140 kernel/locking/spinlock.c:194 > Code: 9c 8f 44 24 20 42 80 3c 23 00 74 08 4c 89 f7 e8 fe 78 2d f6 f6 44 24 21 02 75 52 41 f7 c7 00 02 00 00 74 01 fb bf 01 00 00 00 c3 0f 95 f5 65 8b 05 d4 58 0b 74 85 c0 74 43 48 c7 04 24 0e 36 > RSP: 0018:ffffc900030fef60 EFLAGS: 00000206 > RAX: 23438dd059a4b100 RBX: 1ffff9200061fdf0 RCX: ffffffff819b316a > RDX: dffffc0000000000 RSI: ffffffff8c0aa680 RDI: 0000000000000001 > RBP: ffffc900030feff8 R08: ffffffff942f9847 R09: 1ffffffff285f308 > R10: dffffc0000000000 R11: fffffbfff285f309 R12: dffffc0000000000 > R13: 1ffff9200061fdec R14: ffffc900030fef80 R15: 0000000000000246 > spin_unlock_irqrestore include/linux/spinlock.h:406 [inline] > rmqueue_bulk mm/page_alloc.c:2329 [inline] > __rmqueue_pcplist+0x21fd/0x2a90 mm/page_alloc.c:3004 > rmqueue_pcplist mm/page_alloc.c:3046 [inline] > rmqueue mm/page_alloc.c:3077 [inline] > get_page_from_freelist+0x886/0x37a0 mm/page_alloc.c:3474 > __alloc_frozen_pages_noprof+0x292/0x710 mm/page_alloc.c:4739 > alloc_pages_mpol+0x311/0x660 mm/mempolicy.c:2270 > folio_alloc_mpol_noprof mm/mempolicy.c:2289 [inline] > vma_alloc_folio_noprof+0x12b/0x260 mm/mempolicy.c:2324 > folio_prealloc+0x2e/0x170 > wp_page_copy mm/memory.c:3435 [inline] > do_wp_page+0x1253/0x49b0 mm/memory.c:3827 > handle_pte_fault mm/memory.c:5905 [inline] > __handle_mm_fault+0x24d5/0x70f0 mm/memory.c:6032 > handle_mm_fault+0x3e5/0x8d0 mm/memory.c:6201 > do_user_addr_fault arch/x86/mm/fault.c:1388 [inline] > handle_page_fault arch/x86/mm/fault.c:1480 [inline] > exc_page_fault+0x2b9/0x8b0 arch/x86/mm/fault.c:1538 > asm_exc_page_fault+0x26/0x30 arch/x86/include/asm/idtentry.h:623 > RIP: 0010:__put_user_4+0x11/0x20 arch/x86/lib/putuser.S:88 > Code: 1f 84 00 00 00 00 00 66 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 48 89 cb 48 c1 fb 3f 48 09 d9 0f 01 cb <89> 01 31 c9 0f 01 ca c3 cc cc cc cc 0f 1f 00 90 90 90 90 90 90 90 > RSP: 0018:ffffc900030fff00 EFLAGS: 00050202 > RAX: 0000000000000005 RBX: 0000000000000000 RCX: 00005555679927d0 > RDX: 0000000000000000 RSI: ffffffff8c0ab8e0 RDI: ffffffff8c608a00 > RBP: ffff888000dfcf20 R08: ffffffff901b5177 R09: 1ffffffff2036a2e > R10: dffffc0000000000 R11: fffffbfff2036a2f R12: 0000000000000000 > R13: 0000000000000000 R14: 0000000000000005 R15: dffffc0000000000 > schedule_tail+0x96/0xb0 kernel/sched/core.c:5312 > ret_from_fork+0x24/0x80 arch/x86/kernel/process.c:144 > ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244 > > Modules linked in: > CR2: 0000000000000000 > ---[ end trace 0000000000000000 ]--- > RIP: 0010:0x0 > Code: Unable to access opcode bytes at 0xffffffffffffffd6. > RSP: 0018:ffffc90000007bd8 EFLAGS: 00010246 > RAX: dffffc0000000000 RBX: 1ffff110077e705c RCX: 23438dd059a4b100 > RDX: 0000000000000100 RSI: 0000000000000000 RDI: ffff88803bf382d8 > RBP: ffffc90000007e10 R08: ffffffff819f146c R09: 1ffff11003f8519a > R10: dffffc0000000000 R11: 0000000000000000 R12: ffffffff81a6d507 > R13: ffff88803bf382e0 R14: 0000000000000000 R15: ffff88803bf382d8 > FS: 0000555567992500(0000) GS:ffff88801fc00000(0000) knlGS:0000000000000000 > CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 > CR2: ffffffffffffffd6 CR3: 000000004da38000 CR4: 0000000000352ef0 > DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 > DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 > ---------------- > Code disassembly (best guess): > 0: 9c pushf > 1: 8f 44 24 20 pop 0x20(%rsp) > 5: 42 80 3c 23 00 cmpb $0x0,(%rbx,%r12,1) > a: 74 08 je 0x14 > c: 4c 89 f7 mov %r14,%rdi > f: e8 fe 78 2d f6 call 0xf62d7912 > 14: f6 44 24 21 02 testb $0x2,0x21(%rsp) > 19: 75 52 jne 0x6d > 1b: 41 f7 c7 00 02 00 00 test $0x200,%r15d > 22: 74 01 je 0x25 > 24: fb sti > 25: bf 01 00 00 00 mov $0x1,%edi > * 2a: e8 c3 0f 95 f5 call 0xf5950ff2 <-- trapping instruction > 2f: 65 8b 05 d4 58 0b 74 mov %gs:0x740b58d4(%rip),%eax # 0x740b590a > 36: 85 c0 test %eax,%eax > 38: 74 43 je 0x7d > 3a: 48 rex.W > 3b: c7 .byte 0xc7 > 3c: 04 24 add $0x24,%al > 3e: 0e (bad) > 3f: 36 ss > > > --- > This report is generated by a bot. It may contain errors. > See https://goo.gl/tpsmEJ for more information about syzbot. > syzbot engineers can be reached at syzkaller@googlegroups.com. > > syzbot will keep track of this issue. See: > https://goo.gl/tpsmEJ#status for how to communicate with syzbot. > > If the report is already addressed, let syzbot know by replying with: > #syz fix: exact-commit-title > > If you want syzbot to run the reproducer, reply with: > #syz test: git://repo/address.git branch-or-commit-hash > If you attach or paste a git patch, syzbot will apply it before testing. > > If you want to overwrite report's subsystems, reply with: > #syz set subsystems: new-subsystem > (See the list of subsystem names on the web dashboard) > > If the report is a duplicate of another one, reply with: > #syz dup: exact-subject-of-another-report > > If you want to undo deduplication, reply with: > #syz undup > #syz test diff --git a/kernel/rcu/tree.c b/kernel/rcu/tree.c index 475f31deed14..b297a32c6779 100644 --- a/kernel/rcu/tree.c +++ b/kernel/rcu/tree.c @@ -3047,6 +3047,10 @@ __call_rcu_common(struct rcu_head *head, rcu_callback_t func, bool lazy_in) /* Misaligned rcu_head! */ WARN_ON_ONCE((unsigned long)head & (sizeof(void *) - 1)); + /* Avoid NULL dereference if callback is NULL. */ + if (WARN_ON_ONCE(!func)) + return; + if (debug_rcu_head_queue(head)) { /* * Probable double call_rcu(), so leak the callback.