From: syzbot <syzbot+c6d94bedd910a8216d25@syzkaller.appspotmail.com>
To: almaz.alexandrovich@paragon-software.com,
linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org,
ntfs3@lists.linux.dev, syzkaller-bugs@googlegroups.com
Subject: [syzbot] [ntfs3?] WARNING: kmalloc bug in wnd_init
Date: Wed, 06 Mar 2024 01:53:17 -0800 [thread overview]
Message-ID: <0000000000009262af0612faed28@google.com> (raw)
Hello,
syzbot found the following issue on:
HEAD commit: 90d35da658da Linux 6.8-rc7
git tree: upstream
console+strace: https://syzkaller.appspot.com/x/log.txt?x=1286d2b2180000
kernel config: https://syzkaller.appspot.com/x/.config?x=119d08814b43915b
dashboard link: https://syzkaller.appspot.com/bug?extid=c6d94bedd910a8216d25
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=101d9fce180000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=15cdacfe180000
Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/821deeb51f0a/disk-90d35da6.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/9a7d492f89d7/vmlinux-90d35da6.xz
kernel image: https://storage.googleapis.com/syzbot-assets/78bfac3e2f5d/bzImage-90d35da6.xz
mounted in repro: https://storage.googleapis.com/syzbot-assets/3f48906195d3/mount_0.gz
The issue was bisected to:
commit fc471e39e38fea6677017cbdd6d928088a59fc67
Author: Konstantin Komarov <almaz.alexandrovich@paragon-software.com>
Date: Fri Jun 30 12:12:58 2023 +0000
fs/ntfs3: Use kvmalloc instead of kmalloc(... __GFP_NOWARN)
bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=12bd9fce180000
final oops: https://syzkaller.appspot.com/x/report.txt?x=11bd9fce180000
console output: https://syzkaller.appspot.com/x/log.txt?x=16bd9fce180000
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+c6d94bedd910a8216d25@syzkaller.appspotmail.com
Fixes: fc471e39e38f ("fs/ntfs3: Use kvmalloc instead of kmalloc(... __GFP_NOWARN)")
loop0: detected capacity change from 0 to 4096
ntfs3: loop0: Different NTFS sector size (1024) and media sector size (512).
------------[ cut here ]------------
WARNING: CPU: 1 PID: 5055 at mm/util.c:632 kvmalloc_node+0x17a/0x190 mm/util.c:632
Modules linked in:
CPU: 1 PID: 5055 Comm: syz-executor362 Not tainted 6.8.0-rc7-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/25/2024
RIP: 0010:kvmalloc_node+0x17a/0x190 mm/util.c:632
Code: cc 44 89 fe 81 e6 00 20 00 00 31 ff e8 bf 35 c0 ff 41 81 e7 00 20 00 00 74 0a e8 71 31 c0 ff e9 3b ff ff ff e8 67 31 c0 ff 90 <0f> 0b 90 e9 2d ff ff ff 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00
RSP: 0018:ffffc90003b1f8b8 EFLAGS: 00010293
RAX: ffffffff81d33ae9 RBX: 0003ffffffffff02 RCX: ffff888023469dc0
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: 0000000000000000 R08: ffffffff81d33ad1 R09: 00000000ffffffff
R10: ffffc90003b1f720 R11: fffff52000763ee9 R12: ffff88802394c0b0
R13: 0003ffffffffff02 R14: 00000000ffffffff R15: 0000000000000000
FS: 0000555556a6f380(0000) GS:ffff8880b9500000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f980f795ed8 CR3: 000000001f008000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
kvmalloc include/linux/slab.h:728 [inline]
kvmalloc_array include/linux/slab.h:746 [inline]
wnd_init+0x1f1/0x320 fs/ntfs3/bitmap.c:663
ntfs_fill_super+0x3076/0x49c0 fs/ntfs3/super.c:1313
get_tree_bdev+0x3f7/0x570 fs/super.c:1614
vfs_get_tree+0x90/0x2a0 fs/super.c:1779
do_new_mount+0x2be/0xb40 fs/namespace.c:3352
do_mount fs/namespace.c:3692 [inline]
__do_sys_mount fs/namespace.c:3898 [inline]
__se_sys_mount+0x2d9/0x3c0 fs/namespace.c:3875
do_syscall_64+0xf9/0x240
entry_SYSCALL_64_after_hwframe+0x6f/0x77
RIP: 0033:0x7f0e7ba728ba
Code: d8 64 89 02 48 c7 c0 ff ff ff ff eb a6 e8 5e 04 00 00 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 49 89 ca b8 a5 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ffe03c98d68 EFLAGS: 00000286 ORIG_RAX: 00000000000000a5
RAX: ffffffffffffffda RBX: 00007ffe03c98d80 RCX: 00007f0e7ba728ba
RDX: 000000002001f800 RSI: 000000002001f840 RDI: 00007ffe03c98d80
RBP: 0000000000000004 R08: 00007ffe03c98dc0 R09: 000000000001f7ef
R10: 0000000000000000 R11: 0000000000000286 R12: 0000000000000000
R13: 00007ffe03c98dc0 R14: 0000000000000003 R15: 0000000000200000
</TASK>
---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
For information about bisection process see: https://goo.gl/tpsmEJ#bisection
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup
next reply other threads:[~2024-03-06 9:53 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-03-06 9:53 syzbot [this message]
2024-08-23 9:00 ` [syzbot] WARNING: kmalloc bug in wnd_init (linux-ntfs3.git/master) syzbot
[not found] <1fa0a253-d36f-49ce-bd6f-d712fb1ca0df@paragon-software.com>
2024-08-23 9:28 ` [syzbot] [ntfs3?] WARNING: kmalloc bug in wnd_init syzbot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=0000000000009262af0612faed28@google.com \
--to=syzbot+c6d94bedd910a8216d25@syzkaller.appspotmail.com \
--cc=almaz.alexandrovich@paragon-software.com \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=ntfs3@lists.linux.dev \
--cc=syzkaller-bugs@googlegroups.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.