All of lore.kernel.org
 help / color / mirror / Atom feed
From: syzbot <syzbot+eb6201248f684e99b9f8@syzkaller.appspotmail.com>
To: chao@kernel.org, jaegeuk@kernel.org,
	 linux-f2fs-devel@lists.sourceforge.net,
	linux-kernel@vger.kernel.org,  syzkaller-bugs@googlegroups.com
Subject: Re: [f2fs-dev] [syzbot] [f2fs?] WARNING: lock held when returning to user space in f2fs_write_single_data_page
Date: Wed, 03 May 2023 09:08:16 -0700	[thread overview]
Message-ID: <000000000000872ce405facc4319@google.com> (raw)
In-Reply-To: <5540e94e-d744-bf51-6344-95c8a173e89a@kernel.org>

Hello,

syzbot has tested the proposed patch but the reproducer is still triggering an issue:
general protection fault in f2fs_quota_on

general protection fault, probably for non-canonical address 0xdffffc00000000e6: 0000 [#1] PREEMPT SMP KASAN
KASAN: null-ptr-deref in range [0x0000000000000730-0x0000000000000737]
CPU: 0 PID: 5450 Comm: syz-executor.0 Not tainted 6.3.0-syzkaller-05651-gfd78b242ba1b #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/14/2023
RIP: 0010:__lock_acquire+0x69/0x2000 kernel/locking/lockdep.c:4942
Code: df 0f b6 04 30 84 c0 0f 85 5a 16 00 00 83 3d c1 51 e9 0c 00 0f 84 02 11 00 00 83 3d f0 89 74 0b 00 74 2b 4c 89 f0 48 c1 e8 03 <80> 3c 30 00 74 12 4c 89 f7 e8 c9 54 76 00 48 be 00 00 00 00 00 fc
RSP: 0018:ffffc90005a1faf8 EFLAGS: 00010002
RAX: 00000000000000e6 RBX: 0000000000000000 RCX: 0000000000000000
RDX: 0000000000000000 RSI: dffffc0000000000 RDI: 0000000000000730
RBP: 0000000000000000 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000000000 R11: dffffc0000000001 R12: 0000000000000001
R13: 0000000000000000 R14: 0000000000000730 R15: ffff888077f13b80
FS:  00007fc1c2b17700(0000) GS:ffff8880b9800000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000055800180a000 CR3: 00000000706b1000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
 <TASK>
 lock_acquire+0x1e3/0x520 kernel/locking/lockdep.c:5691
 down_write+0x3a/0x50 kernel/locking/rwsem.c:1573
 f2fs_down_write fs/f2fs/f2fs.h:2125 [inline]
 f2fs_quota_on+0x120/0x320 fs/f2fs/super.c:2916
 __do_sys_quotactl fs/quota/quota.c:960 [inline]
 __se_sys_quotactl+0x2b5/0x810 fs/quota/quota.c:916
 do_syscall_x64 arch/x86/entry/common.c:50 [inline]
 do_syscall_64+0x41/0xc0 arch/x86/entry/common.c:80
 entry_SYSCALL_64_after_hwframe+0x63/0xcd
RIP: 0033:0x7fc1c1e8c169
Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 f1 19 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fc1c2b17168 EFLAGS: 00000246 ORIG_RAX: 00000000000000b3
RAX: ffffffffffffffda RBX: 00007fc1c1fac050 RCX: 00007fc1c1e8c169
RDX: 0000000000000000 RSI: 0000000020000080 RDI: ffffffff80000202
RBP: 00007fc1c1ee7ca1 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000020008040 R11: 0000000000000246 R12: 0000000000000000
R13: 00007ffd3e2e112f R14: 00007fc1c2b17300 R15: 0000000000022000
 </TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:__lock_acquire+0x69/0x2000 kernel/locking/lockdep.c:4942
Code: df 0f b6 04 30 84 c0 0f 85 5a 16 00 00 83 3d c1 51 e9 0c 00 0f 84 02 11 00 00 83 3d f0 89 74 0b 00 74 2b 4c 89 f0 48 c1 e8 03 <80> 3c 30 00 74 12 4c 89 f7 e8 c9 54 76 00 48 be 00 00 00 00 00 fc
RSP: 0018:ffffc90005a1faf8 EFLAGS: 00010002
RAX: 00000000000000e6 RBX: 0000000000000000 RCX: 0000000000000000
RDX: 0000000000000000 RSI: dffffc0000000000 RDI: 0000000000000730
RBP: 0000000000000000 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000000000 R11: dffffc0000000001 R12: 0000000000000001
R13: 0000000000000000 R14: 0000000000000730 R15: ffff888077f13b80
FS:  00007fc1c2b17700(0000) GS:ffff8880b9800000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000055800180a000 CR3: 00000000706b1000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
----------------
Code disassembly (best guess):
   0:	df 0f                	fisttps (%rdi)
   2:	b6 04                	mov    $0x4,%dh
   4:	30 84 c0 0f 85 5a 16 	xor    %al,0x165a850f(%rax,%rax,8)
   b:	00 00                	add    %al,(%rax)
   d:	83 3d c1 51 e9 0c 00 	cmpl   $0x0,0xce951c1(%rip)        # 0xce951d5
  14:	0f 84 02 11 00 00    	je     0x111c
  1a:	83 3d f0 89 74 0b 00 	cmpl   $0x0,0xb7489f0(%rip)        # 0xb748a11
  21:	74 2b                	je     0x4e
  23:	4c 89 f0             	mov    %r14,%rax
  26:	48 c1 e8 03          	shr    $0x3,%rax
* 2a:	80 3c 30 00          	cmpb   $0x0,(%rax,%rsi,1) <-- trapping instruction
  2e:	74 12                	je     0x42
  30:	4c 89 f7             	mov    %r14,%rdi
  33:	e8 c9 54 76 00       	callq  0x765501
  38:	48                   	rex.W
  39:	be 00 00 00 00       	mov    $0x0,%esi
  3e:	00 fc                	add    %bh,%ah


Tested on:

commit:         fd78b242 f2fs: fix potential deadlock due to unpaired ..
git tree:       https://git.kernel.org/pub/scm/linux/kernel/git/chao/linux.git dev-test
console output: https://syzkaller.appspot.com/x/log.txt?x=11d46838280000
kernel config:  https://syzkaller.appspot.com/x/.config?x=86e4eb913e90d4b2
dashboard link: https://syzkaller.appspot.com/bug?extid=eb6201248f684e99b9f8
compiler:       Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2

Note: no patches were applied.


_______________________________________________
Linux-f2fs-devel mailing list
Linux-f2fs-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/linux-f2fs-devel

WARNING: multiple messages have this Message-ID (diff)
From: syzbot <syzbot+eb6201248f684e99b9f8@syzkaller.appspotmail.com>
To: chao@kernel.org, jaegeuk@kernel.org,
	linux-f2fs-devel@lists.sourceforge.net,
	linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com
Subject: Re: [syzbot] [f2fs?] WARNING: lock held when returning to user space in f2fs_write_single_data_page
Date: Wed, 03 May 2023 09:08:16 -0700	[thread overview]
Message-ID: <000000000000872ce405facc4319@google.com> (raw)
In-Reply-To: <5540e94e-d744-bf51-6344-95c8a173e89a@kernel.org>

Hello,

syzbot has tested the proposed patch but the reproducer is still triggering an issue:
general protection fault in f2fs_quota_on

general protection fault, probably for non-canonical address 0xdffffc00000000e6: 0000 [#1] PREEMPT SMP KASAN
KASAN: null-ptr-deref in range [0x0000000000000730-0x0000000000000737]
CPU: 0 PID: 5450 Comm: syz-executor.0 Not tainted 6.3.0-syzkaller-05651-gfd78b242ba1b #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/14/2023
RIP: 0010:__lock_acquire+0x69/0x2000 kernel/locking/lockdep.c:4942
Code: df 0f b6 04 30 84 c0 0f 85 5a 16 00 00 83 3d c1 51 e9 0c 00 0f 84 02 11 00 00 83 3d f0 89 74 0b 00 74 2b 4c 89 f0 48 c1 e8 03 <80> 3c 30 00 74 12 4c 89 f7 e8 c9 54 76 00 48 be 00 00 00 00 00 fc
RSP: 0018:ffffc90005a1faf8 EFLAGS: 00010002
RAX: 00000000000000e6 RBX: 0000000000000000 RCX: 0000000000000000
RDX: 0000000000000000 RSI: dffffc0000000000 RDI: 0000000000000730
RBP: 0000000000000000 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000000000 R11: dffffc0000000001 R12: 0000000000000001
R13: 0000000000000000 R14: 0000000000000730 R15: ffff888077f13b80
FS:  00007fc1c2b17700(0000) GS:ffff8880b9800000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000055800180a000 CR3: 00000000706b1000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
 <TASK>
 lock_acquire+0x1e3/0x520 kernel/locking/lockdep.c:5691
 down_write+0x3a/0x50 kernel/locking/rwsem.c:1573
 f2fs_down_write fs/f2fs/f2fs.h:2125 [inline]
 f2fs_quota_on+0x120/0x320 fs/f2fs/super.c:2916
 __do_sys_quotactl fs/quota/quota.c:960 [inline]
 __se_sys_quotactl+0x2b5/0x810 fs/quota/quota.c:916
 do_syscall_x64 arch/x86/entry/common.c:50 [inline]
 do_syscall_64+0x41/0xc0 arch/x86/entry/common.c:80
 entry_SYSCALL_64_after_hwframe+0x63/0xcd
RIP: 0033:0x7fc1c1e8c169
Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 f1 19 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fc1c2b17168 EFLAGS: 00000246 ORIG_RAX: 00000000000000b3
RAX: ffffffffffffffda RBX: 00007fc1c1fac050 RCX: 00007fc1c1e8c169
RDX: 0000000000000000 RSI: 0000000020000080 RDI: ffffffff80000202
RBP: 00007fc1c1ee7ca1 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000020008040 R11: 0000000000000246 R12: 0000000000000000
R13: 00007ffd3e2e112f R14: 00007fc1c2b17300 R15: 0000000000022000
 </TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:__lock_acquire+0x69/0x2000 kernel/locking/lockdep.c:4942
Code: df 0f b6 04 30 84 c0 0f 85 5a 16 00 00 83 3d c1 51 e9 0c 00 0f 84 02 11 00 00 83 3d f0 89 74 0b 00 74 2b 4c 89 f0 48 c1 e8 03 <80> 3c 30 00 74 12 4c 89 f7 e8 c9 54 76 00 48 be 00 00 00 00 00 fc
RSP: 0018:ffffc90005a1faf8 EFLAGS: 00010002
RAX: 00000000000000e6 RBX: 0000000000000000 RCX: 0000000000000000
RDX: 0000000000000000 RSI: dffffc0000000000 RDI: 0000000000000730
RBP: 0000000000000000 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000000000 R11: dffffc0000000001 R12: 0000000000000001
R13: 0000000000000000 R14: 0000000000000730 R15: ffff888077f13b80
FS:  00007fc1c2b17700(0000) GS:ffff8880b9800000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000055800180a000 CR3: 00000000706b1000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
----------------
Code disassembly (best guess):
   0:	df 0f                	fisttps (%rdi)
   2:	b6 04                	mov    $0x4,%dh
   4:	30 84 c0 0f 85 5a 16 	xor    %al,0x165a850f(%rax,%rax,8)
   b:	00 00                	add    %al,(%rax)
   d:	83 3d c1 51 e9 0c 00 	cmpl   $0x0,0xce951c1(%rip)        # 0xce951d5
  14:	0f 84 02 11 00 00    	je     0x111c
  1a:	83 3d f0 89 74 0b 00 	cmpl   $0x0,0xb7489f0(%rip)        # 0xb748a11
  21:	74 2b                	je     0x4e
  23:	4c 89 f0             	mov    %r14,%rax
  26:	48 c1 e8 03          	shr    $0x3,%rax
* 2a:	80 3c 30 00          	cmpb   $0x0,(%rax,%rsi,1) <-- trapping instruction
  2e:	74 12                	je     0x42
  30:	4c 89 f7             	mov    %r14,%rdi
  33:	e8 c9 54 76 00       	callq  0x765501
  38:	48                   	rex.W
  39:	be 00 00 00 00       	mov    $0x0,%esi
  3e:	00 fc                	add    %bh,%ah


Tested on:

commit:         fd78b242 f2fs: fix potential deadlock due to unpaired ..
git tree:       https://git.kernel.org/pub/scm/linux/kernel/git/chao/linux.git dev-test
console output: https://syzkaller.appspot.com/x/log.txt?x=11d46838280000
kernel config:  https://syzkaller.appspot.com/x/.config?x=86e4eb913e90d4b2
dashboard link: https://syzkaller.appspot.com/bug?extid=eb6201248f684e99b9f8
compiler:       Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2

Note: no patches were applied.

  reply	other threads:[~2023-05-03 16:08 UTC|newest]

Thread overview: 16+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2023-05-01 17:05 [f2fs-dev] [syzbot] [f2fs?] WARNING: lock held when returning to user space in f2fs_write_single_data_page syzbot
2023-05-01 17:05 ` syzbot
2023-05-03 15:28 ` [f2fs-dev] " Chao Yu
2023-05-03 15:28   ` Chao Yu
2023-05-03 16:08   ` syzbot [this message]
2023-05-03 16:08     ` syzbot
2023-05-04 12:08 ` [f2fs-dev] " Chao Yu
2023-05-04 12:08   ` Chao Yu
2023-05-04 13:31   ` [f2fs-dev] " syzbot
2023-05-04 13:31     ` syzbot
2023-05-04 13:48     ` [f2fs-dev] " Chao Yu
2023-05-04 13:48       ` Chao Yu
2023-05-04 13:53       ` [f2fs-dev] " Aleksandr Nogikh via Linux-f2fs-devel
2023-05-04 13:53         ` Aleksandr Nogikh
2023-09-15  5:49 ` [f2fs-dev] " syzbot
2023-09-15  5:49   ` syzbot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=000000000000872ce405facc4319@google.com \
    --to=syzbot+eb6201248f684e99b9f8@syzkaller.appspotmail.com \
    --cc=chao@kernel.org \
    --cc=jaegeuk@kernel.org \
    --cc=linux-f2fs-devel@lists.sourceforge.net \
    --cc=linux-kernel@vger.kernel.org \
    --cc=syzkaller-bugs@googlegroups.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.