From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id EA955C4345F for ; Fri, 12 Apr 2024 16:24:09 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 1C8F66B0082; Fri, 12 Apr 2024 12:24:09 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 1526E6B0083; Fri, 12 Apr 2024 12:24:09 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id F34906B0087; Fri, 12 Apr 2024 12:24:08 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0015.hostedemail.com [216.40.44.15]) by kanga.kvack.org (Postfix) with ESMTP id CC2536B0082 for ; Fri, 12 Apr 2024 12:24:08 -0400 (EDT) Received: from smtpin11.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay03.hostedemail.com (Postfix) with ESMTP id 595C5A0F46 for ; Fri, 12 Apr 2024 16:24:08 +0000 (UTC) X-FDA: 82001401776.11.4CCF0CB Received: from sin.source.kernel.org (sin.source.kernel.org [145.40.73.55]) by imf02.hostedemail.com (Postfix) with ESMTP id 0532380016 for ; Fri, 12 Apr 2024 16:24:05 +0000 (UTC) Authentication-Results: imf02.hostedemail.com; dkim=pass header.d=kernel.org header.s=k20201202 header.b=EX6n44HP; spf=pass (imf02.hostedemail.com: domain of cem@kernel.org designates 145.40.73.55 as permitted sender) smtp.mailfrom=cem@kernel.org; dmarc=pass (policy=none) header.from=kernel.org ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1712939046; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=RVd0UxsaB2R3fnNLgj9M8w5f/dKK1uSba3F/Xqzj7QQ=; b=st8eCYCt7GjrD81DUzP8dy7kgAn8s465b2cIcJOGHtoaFfy8+3L1jj7bmurbbx/OeETEjC pFjMMllNriDDv/jZQ4MpUr3vgLh6EhPdu4eyNHHzcYHEt2NGgvrqDQXvZn2+oqo6JG7DaY vgCJjGOu6BY1US0XG1x/SxEpK37RtIw= ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1712939046; a=rsa-sha256; cv=none; b=vS0EofwZurN3iGnuNVfdw75NLEGlqwFCVYtF6/IhUnMYwpODHo+tAqVWW9ja3m1hHPFluH 1ZthJQrJAnFMbjYtMvvFrJPse8WDD5xlr8O47ezxExmmJmu9ysIu8nwfkj73xTAncDNa9O /qK8TQdl0e9ZsQlCcnzPPL2oOGdgrPc= ARC-Authentication-Results: i=1; imf02.hostedemail.com; dkim=pass header.d=kernel.org header.s=k20201202 header.b=EX6n44HP; spf=pass (imf02.hostedemail.com: domain of cem@kernel.org designates 145.40.73.55 as permitted sender) smtp.mailfrom=cem@kernel.org; dmarc=pass (policy=none) header.from=kernel.org Received: from smtp.kernel.org (transwarp.subspace.kernel.org [100.75.92.58]) by sin.source.kernel.org (Postfix) with ESMTP id CD558CE384B; Fri, 12 Apr 2024 16:24:01 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id 7F2A1C113CC; Fri, 12 Apr 2024 16:23:59 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1712939041; bh=DVAVeZL/9jWjhVi+2NxW+2kxv9RNUM3iHWEiAb1/zXE=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=EX6n44HPrjlfuhfE9C6H60Q1Kj5fLguRK5tnF8mC3UPreRSx5uCXnmUnjXsaTZA9W s4V9oCm76XtYYG+ckqlBIZIUtt/NIidzByUw2Qj/hOtH+9LSzgWq6Iwyl2ok3ncxbB wez6UhNfsgD3U6jpXVW58H3vtshBNcMXuN927AOSL9ZoN3XIvXohFetIkCZ2T3I8b5 1mPtqfQKPckaALgW/l40Mhk9PDye1mcbrVu4fiBQE4CSD/ucX4dKU3Ccf5ulAE7ijX XDvhxJfauceeDnekNt2W1JLSGawNtxvvmYhjBEHlF/tWoSH/se9j/VmSXoumCgmg/3 ri8tUv4LBirHw== Date: Fri, 12 Apr 2024 18:23:56 +0200 From: Carlos Maiolino To: Andrew Morton Cc: syzbot , linux-kernel@vger.kernel.org, linux-mm@kvack.org, syzkaller-bugs@googlegroups.com, Christian Brauner Subject: Re: [syzbot] [mm?] general protection fault in shmem_get_next_id Message-ID: References: <000000000000a1ff78061517a148@google.com> <20240403183339.7a257066e79ac04a7d6e33fd@linux-foundation.org> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20240403183339.7a257066e79ac04a7d6e33fd@linux-foundation.org> X-Rspamd-Queue-Id: 0532380016 X-Rspam-User: X-Stat-Signature: kzh4he3576ttprmgi7ybu8sb1t4ne4qz X-Rspamd-Server: rspam03 X-HE-Tag: 1712939045-718837 X-HE-Meta: U2FsdGVkX1++aE0+4ARowkqk+wxFX49f5JEwuMSR9ghN9TXJgW/506XsNm9Pz9IRhYXvRRbFQpmnkjkRDhKm9VuH941Mwd1USD904adRyMwmyLhLZXrHbLCy+LiKXgBiBoWHnA41EIHj5+yqeZRSByODgYpU1tvFfx0OdG1l2uP1cfvPPBGwjyFZlUqKkOJonvo55tbWZ6Epfrpe+F9iaRy969FwmsxZ4GsaWHhyRbBiYImJQVJrpiTFNlAF3aEXjpfyX/3VSp2bB+asfPXSR5q/dsSygIwLv0tJuYaLtXzD112xrJUFJNwG8TRokdL6vr61SVLggVaE5JLMLnOMGEs787jwOYCiYjG/9czjm4xUVO6oUhuKSrGWegABLGwSKHPJQFUTVuq+7rS2DBA+AT/63mzwiG0GL70bVzfpZD1N95n/5+RdMXpgrduKNvnFk475jeCopYVHC8S6JrKfb3DlUk49sogUocYDOdgG9enJLFvVjfKH9H1dfd5o6En4QGF5G+SblvLIij6kEPf50xu9dujL50vHqgNJsdWl184fySCu4rBys5iXP20Z0ZwJm7Bo3f188udT5HXCw61OfCIMQAzGzFDucM/gOpBcQZEimiq8EEA3HEEUEAYrMLUtMAXrlpVoJJm4TMkIKhGcTUmnhk8QN5/amnxklPQ09VQULEAuDqFXLA9jC1qEWNUlixKw3lTYA8HcV20v9tQV11eBJ7EwEOVD0A9T/cIgO/9u0Kn3C3jD+lsL+2upbT3UhqgPCxSdA48q2K47E/hvdx41Bi0dSfDAiNzga1WAi/P9zMrfo8Qj/oAe889ZWx7jmDuOMPUTXKmtsYqeO5/t+vPXpC9dQiM9XlgvHLCHDbH16kDgQ4svS1hawkqmjJNs4Nb1eiZyvYRGnnkJu5aR52v6BksmJoLIMqL0h8ZKt9tU0EnWF3uU08RqyonAiqDIQ6pb9uLhM7dCM+Xp94f 898TE93N uOj5BApVmexv17UtwQc0qnCbCZEDwG84kdDXxkzTj874zQnx51CL8LfVqac87Qo2ZN0oRLsa33nI8FrSAQ2njsIbGWYycEh7JRuP6ThlaVjRbZTXOFZUKtZbblmZia2Ccexn4O5EeMattWCJd/crgrwviJyESD9/p+DTz29A4QH+kArmLUzwk6X89e1S6bCI2co29MGIpeLMXItVlbPXzunaWQ8KjxsydjCv55RgVEHo6KBm9N9ikZKGjA6fHOPhT0NfHpjUnSjkpBQRF4IsEbBJagoh33/RtfLCiJsyJii0TJU6QeH36hfvz6T+DSBPO/sBkFMqJSzwqF+tzdpbWW2jLWDp1J7apqMI9KdSsux55OYoI5MThxiCObiYT7atAjcQxQyl6bLUYosiRK7/cRwAyHbMThfNoSevFcCOT4uh5NCQCQoiYzXUYIAQXL+gVdlvTIR+QWG6jwPpQ+kNrFBDfk0ipJxtVzGzqHhC/hqzckorVSHWsBE9emtWGmi/XQVZFoVQXFWri3aVGINPnHOmUJbsUXGOvl56Spp92WhTte/p8dItMHldUVh4TXwRd0b+KT5oe4GI6k4kzSu7tJJaV9ZsbBYfB9QCnLxkeT0EYy1n/+br63LXic4+zM8Hfqu5pInGumfbg3Y5efpkKSvwbMPLJohPAqeHAHgZKhFZHlNFDMtcJSIVwHMuMOtUCJ6ST10cryAFOf41G+R+JFCsUojvaVe/PlF6u4ggVHPX0jbOXuvHBC9VltRQxH2pNzJyYtDUb+oH+CjX+2qSjeZFX5OVjwjpVs95PyCebuqQwM7KC29NYrdG1pS4EU0bA00IHKqQ9Op/PbwIGdGDzrp6uh93SXo6jLWquZyC8aiHTrpMLiyQg3dKm87INKPif3iv0/xzpLerw1k7mfzg44Eist5zVkHzWsoHiiGp3mYBvAwGuoc7vVDjyhYn7X425ye+DTHWtKHkGBdUcNeNlhXQrd1zj g0+y5VbP Zhet5EVp4Zo= X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: List-Subscribe: List-Unsubscribe: On Wed, Apr 03, 2024 at 06:33:39PM -0700, Andrew Morton wrote: > On Mon, 01 Apr 2024 23:58:20 -0700 syzbot wrote: > > > Hello, > > Hello. > > Seems that the new TMPFS_QUOTA code has blown up. Cc's added, thanks > for the report and the reproducer! Yes, this is easily reproducible here. I can't reproduce it with my earlier fix of the RB tree race. We can ignore this report, this has been reproduced before the race fix has been applied to the main tree. Carlos > > > syzbot found the following issue on: > > > > HEAD commit: fe46a7dd189e Merge tag 'sound-6.9-rc1' of git://git.kernel.. > > git tree: upstream > > console+strace: https://syzkaller.appspot.com/x/log.txt?x=10c90795180000 > > kernel config: https://syzkaller.appspot.com/x/.config?x=fe78468a74fdc3b7 > > dashboard link: https://syzkaller.appspot.com/bug?extid=05e63c0981a31f35f3fa > > compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40 > > syz repro: https://syzkaller.appspot.com/x/repro.syz?x=17f51129180000 > > C reproducer: https://syzkaller.appspot.com/x/repro.c?x=150d3cee180000 > > > > Downloadable assets: > > disk image: https://storage.googleapis.com/syzbot-assets/0f7abe4afac7/disk-fe46a7dd.raw.xz > > vmlinux: https://storage.googleapis.com/syzbot-assets/82598d09246c/vmlinux-fe46a7dd.xz > > kernel image: https://storage.googleapis.com/syzbot-assets/efa23788c875/bzImage-fe46a7dd.xz > > > > IMPORTANT: if you fix the issue, please add the following tag to the commit: > > Reported-by: syzbot+05e63c0981a31f35f3fa@syzkaller.appspotmail.com > > > > general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] PREEMPT SMP KASAN NOPTI > > KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] > > CPU: 0 PID: 5070 Comm: syz-executor253 Not tainted 6.8.0-syzkaller-08951-gfe46a7dd189e #0 > > Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024 > > RIP: 0010:shmem_get_next_id+0x92/0x5c0 mm/shmem_quota.c:119 > > Code: 04 db 49 8d 9c c6 90 02 00 00 48 89 d8 48 c1 e8 03 42 80 3c 38 00 74 08 48 89 df e8 f8 66 1b 00 48 8b 1b 48 89 d8 48 c1 e8 03 <42> 80 3c 38 00 74 08 48 89 df e8 df 66 1b 00 4c 8b 23 48 8d 5d 07 > > RSP: 0018:ffffc900043a7be0 EFLAGS: 00010256 > > RAX: 0000000000000000 RBX: 0000000000000000 RCX: ffff8880266c8000 > > RDX: 0000000000000000 RSI: 0000000000000001 RDI: 0000000000000004 > > RBP: ffffc900043a7d00 R08: ffffffff81dcdd47 R09: ffffffff822e7d5a > > R10: 0000000000000003 R11: ffffffff81dcdcf0 R12: 1ffff92000874fa0 > > R13: ffff888022110000 R14: ffff888022110000 R15: dffffc0000000000 > > FS: 0000555578677380(0000) GS:ffff8880b9400000(0000) knlGS:0000000000000000 > > CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 > > CR2: 0000000020001000 CR3: 000000007a384000 CR4: 0000000000350ef0 > > Call Trace: > > > > dquot_get_next_dqblk+0x75/0x3a0 fs/quota/dquot.c:2705 > > quota_getnextquota+0x2c7/0x6c0 fs/quota/quota.c:250 > > __do_sys_quotactl_fd fs/quota/quota.c:1002 [inline] > > __se_sys_quotactl_fd+0x2a1/0x440 fs/quota/quota.c:973 > > do_syscall_64+0xfd/0x240 > > entry_SYSCALL_64_after_hwframe+0x6d/0x75 > > RIP: 0033:0x7f5c0349b329 > > Code: 48 83 c4 28 c3 e8 37 17 00 00 0f 1f 80 00 00 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48 > > RSP: 002b:00007ffc39d71138 EFLAGS: 00000246 ORIG_RAX: 00000000000001bb > > RAX: ffffffffffffffda RBX: 0031656c69662f2e RCX: 00007f5c0349b329 > > RDX: 0000000000000000 RSI: ffffffff80000901 RDI: 0000000000000003 > > RBP: 00007f5c0350e610 R08: 0000000000000000 R09: 00007ffc39d71308 > > R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001 > > R13: 00007ffc39d712f8 R14: 0000000000000001 R15: 0000000000000001 > > > > Modules linked in: > > ---[ end trace 0000000000000000 ]--- > > RIP: 0010:shmem_get_next_id+0x92/0x5c0 mm/shmem_quota.c:119 > > Code: 04 db 49 8d 9c c6 90 02 00 00 48 89 d8 48 c1 e8 03 42 80 3c 38 00 74 08 48 89 df e8 f8 66 1b 00 48 8b 1b 48 89 d8 48 c1 e8 03 <42> 80 3c 38 00 74 08 48 89 df e8 df 66 1b 00 4c 8b 23 48 8d 5d 07 > > RSP: 0018:ffffc900043a7be0 EFLAGS: 00010256 > > RAX: 0000000000000000 RBX: 0000000000000000 RCX: ffff8880266c8000 > > RDX: 0000000000000000 RSI: 0000000000000001 RDI: 0000000000000004 > > RBP: ffffc900043a7d00 R08: ffffffff81dcdd47 R09: ffffffff822e7d5a > > R10: 0000000000000003 R11: ffffffff81dcdcf0 R12: 1ffff92000874fa0 > > R13: ffff888022110000 R14: ffff888022110000 R15: dffffc0000000000 > > FS: 0000555578677380(0000) GS:ffff8880b9400000(0000) knlGS:0000000000000000 > > CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 > > CR2: 0000000020001000 CR3: 000000007a384000 CR4: 0000000000350ef0 > > ---------------- > > Code disassembly (best guess): > > 0: 04 db add $0xdb,%al > > 2: 49 8d 9c c6 90 02 00 lea 0x290(%r14,%rax,8),%rbx > > 9: 00 > > a: 48 89 d8 mov %rbx,%rax > > d: 48 c1 e8 03 shr $0x3,%rax > > 11: 42 80 3c 38 00 cmpb $0x0,(%rax,%r15,1) > > 16: 74 08 je 0x20 > > 18: 48 89 df mov %rbx,%rdi > > 1b: e8 f8 66 1b 00 call 0x1b6718 > > 20: 48 8b 1b mov (%rbx),%rbx > > 23: 48 89 d8 mov %rbx,%rax > > 26: 48 c1 e8 03 shr $0x3,%rax > > * 2a: 42 80 3c 38 00 cmpb $0x0,(%rax,%r15,1) <-- trapping instruction > > 2f: 74 08 je 0x39 > > 31: 48 89 df mov %rbx,%rdi > > 34: e8 df 66 1b 00 call 0x1b6718 > > 39: 4c 8b 23 mov (%rbx),%r12 > > 3c: 48 8d 5d 07 lea 0x7(%rbp),%rbx > > > > > > --- > > This report is generated by a bot. It may contain errors. > > See https://goo.gl/tpsmEJ for more information about syzbot. > > syzbot engineers can be reached at syzkaller@googlegroups.com. > > > > syzbot will keep track of this issue. See: > > https://goo.gl/tpsmEJ#status for how to communicate with syzbot. > > > > If the report is already addressed, let syzbot know by replying with: > > #syz fix: exact-commit-title > > > > If you want syzbot to run the reproducer, reply with: > > #syz test: git://repo/address.git branch-or-commit-hash > > If you attach or paste a git patch, syzbot will apply it before testing. > > > > If you want to overwrite report's subsystems, reply with: > > #syz set subsystems: new-subsystem > > (See the list of subsystem names on the web dashboard) > > > > If the report is a duplicate of another one, reply with: > > #syz dup: exact-subject-of-another-report > > > > If you want to undo deduplication, reply with: > > #syz undup