All of lore.kernel.org
 help / color / mirror / Atom feed
From: syzbot <syzbot+8a4b520a9affc6d8ea56@syzkaller.appspotmail.com>
To: cluster-devel.redhat.com
Subject: [Cluster-devel] [syzbot] kernel BUG in add_to_queue
Date: Fri, 25 Nov 2022 05:20:48 -0800	[thread overview]
Message-ID: <000000000000ddc6ce05ee4b637d@google.com> (raw)
In-Reply-To: <0000000000003a534305ec1730ec@google.com>

syzbot has found a reproducer for the following issue on:

HEAD commit:    65762d97e6fa Merge branch 'for-next/perf' into for-kernelci
git tree:       git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git for-kernelci
console output: https://syzkaller.appspot.com/x/log.txt?x=12198e75880000
kernel config:  https://syzkaller.appspot.com/x/.config?x=56d0c7c3a2304e8f
dashboard link: https://syzkaller.appspot.com/bug?extid=8a4b520a9affc6d8ea56
compiler:       Debian clang version 13.0.1-++20220126092033+75e33f71c2da-1~exp1~20220126212112.63, GNU ld (GNU Binutils for Debian) 2.35.2
userspace arch: arm64
syz repro:      https://syzkaller.appspot.com/x/repro.syz?x=146e6e75880000
C reproducer:   https://syzkaller.appspot.com/x/repro.c?x=1762a3ed880000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/52f702197b30/disk-65762d97.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/72189c2789ce/vmlinux-65762d97.xz
kernel image: https://storage.googleapis.com/syzbot-assets/ec0349196c98/Image-65762d97.gz.xz
mounted in repro: https://storage.googleapis.com/syzbot-assets/9fcb4ad786f5/mount_0.gz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+8a4b520a9affc6d8ea56 at syzkaller.appspotmail.com

gfs2: fsid=syz:syz.0: G:  s:EX n:8/1 f:qb t:EX d:EX/0 a:0 v:0 r:5 m:20 p:0
gfs2: fsid=syz:syz.0:  H: s:EX f:cH e:0 p:3074 [syz-executor203] gfs2_quota_sync+0xf0/0x204 fs/gfs2/quota.c:1318
------------[ cut here ]------------
kernel BUG at fs/gfs2/glock.c:1560!
Internal error: Oops - BUG: 00000000f2000800 [#1] PREEMPT SMP
Modules linked in:
CPU: 0 PID: 3074 Comm: syz-executor203 Not tainted 6.1.0-rc6-syzkaller-32653-g65762d97e6fa #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/30/2022
pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : add_to_queue+0x6ec/0x780 fs/gfs2/glock.c:1559
lr : add_to_queue+0x6ec/0x780 fs/gfs2/glock.c:1559
sp : ffff800012deb950
x29: ffff800012deb960 x28: ffff0000cbfa6e80 x27: ffff0000ccea2000
x26: ffff0000cbfa6e80 x25: 0000000000000400 x24: ffff0000c207a800
x23: 0000000000000000 x22: ffff0000c207a800 x21: ffff0000ccea3270
x20: ffff0000cbfa6eb8 x19: ffff0000c70fc550 x18: 00000000000000c0
x17: 5d333032726f7475 x16: ffff80000dbe6158 x15: ffff0000c4248000
x14: 0000000000000000 x13: 00000000ffffffff x12: ffff0000c4248000
x11: ff8080000926a440 x10: 0000000000000000 x9 : 739e9965397fe700
x8 : 739e9965397fe700 x7 : ffff80000c08e4f4 x6 : 0000000000000000
x5 : 0000000000000080 x4 : 0000000000000001 x3 : 0000000000000000
x2 : 0000000000000000 x1 : 0000000000000001 x0 : 0000000000000000
Call trace:
 add_to_queue+0x6ec/0x780 fs/gfs2/glock.c:1559
 gfs2_glock_nq+0x90/0x220 fs/gfs2/glock.c:1585
 gfs2_glock_nq_init fs/gfs2/glock.h:264 [inline]
 do_sync+0x1dc/0x650 fs/gfs2/quota.c:910
 gfs2_quota_sync+0xf0/0x204 fs/gfs2/quota.c:1318
 gfs2_sync_fs+0x30/0x78 fs/gfs2/super.c:643
 sync_filesystem+0x68/0x134 fs/sync.c:56
 generic_shutdown_super+0x38/0x198 fs/super.c:474
 kill_block_super+0x30/0x78 fs/super.c:1428
 gfs2_kill_sb+0x68/0x78
 deactivate_locked_super+0x70/0xe8 fs/super.c:332
 deactivate_super+0xd0/0xd4 fs/super.c:363
 cleanup_mnt+0x184/0x1c0 fs/namespace.c:1186
 __cleanup_mnt+0x20/0x30 fs/namespace.c:1193
 task_work_run+0x100/0x148 kernel/task_work.c:179
 exit_task_work include/linux/task_work.h:38 [inline]
 do_exit+0x2dc/0xcac kernel/exit.c:820
 __arm64_sys_exit_group+0x0/0x18 kernel/exit.c:950
 __do_sys_exit_group kernel/exit.c:961 [inline]
 __se_sys_exit_group kernel/exit.c:959 [inline]
 __wake_up_parent+0x0/0x40 kernel/exit.c:959
 __invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
 invoke_syscall arch/arm64/kernel/syscall.c:52 [inline]
 el0_svc_common+0x138/0x220 arch/arm64/kernel/syscall.c:142
 do_el0_svc+0x48/0x164 arch/arm64/kernel/syscall.c:206
 el0_svc+0x58/0x150 arch/arm64/kernel/entry-common.c:637
 el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
 el0t_64_sync+0x190/0x194 arch/arm64/kernel/entry.S:584
Code: 52800022 aa1f03e0 aa1303e1 97fff219 (d4210000) 
---[ end trace 0000000000000000 ]---


WARNING: multiple messages have this Message-ID (diff)
From: syzbot <syzbot+8a4b520a9affc6d8ea56@syzkaller.appspotmail.com>
To: agruenba@redhat.com, cluster-devel@redhat.com,
	linux-kernel@vger.kernel.org, rpeterso@redhat.com,
	syzkaller-bugs@googlegroups.com
Subject: Re: [syzbot] kernel BUG in add_to_queue
Date: Fri, 25 Nov 2022 05:20:48 -0800	[thread overview]
Message-ID: <000000000000ddc6ce05ee4b637d@google.com> (raw)
In-Reply-To: <0000000000003a534305ec1730ec@google.com>

syzbot has found a reproducer for the following issue on:

HEAD commit:    65762d97e6fa Merge branch 'for-next/perf' into for-kernelci
git tree:       git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git for-kernelci
console output: https://syzkaller.appspot.com/x/log.txt?x=12198e75880000
kernel config:  https://syzkaller.appspot.com/x/.config?x=56d0c7c3a2304e8f
dashboard link: https://syzkaller.appspot.com/bug?extid=8a4b520a9affc6d8ea56
compiler:       Debian clang version 13.0.1-++20220126092033+75e33f71c2da-1~exp1~20220126212112.63, GNU ld (GNU Binutils for Debian) 2.35.2
userspace arch: arm64
syz repro:      https://syzkaller.appspot.com/x/repro.syz?x=146e6e75880000
C reproducer:   https://syzkaller.appspot.com/x/repro.c?x=1762a3ed880000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/52f702197b30/disk-65762d97.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/72189c2789ce/vmlinux-65762d97.xz
kernel image: https://storage.googleapis.com/syzbot-assets/ec0349196c98/Image-65762d97.gz.xz
mounted in repro: https://storage.googleapis.com/syzbot-assets/9fcb4ad786f5/mount_0.gz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+8a4b520a9affc6d8ea56@syzkaller.appspotmail.com

gfs2: fsid=syz:syz.0: G:  s:EX n:8/1 f:qb t:EX d:EX/0 a:0 v:0 r:5 m:20 p:0
gfs2: fsid=syz:syz.0:  H: s:EX f:cH e:0 p:3074 [syz-executor203] gfs2_quota_sync+0xf0/0x204 fs/gfs2/quota.c:1318
------------[ cut here ]------------
kernel BUG at fs/gfs2/glock.c:1560!
Internal error: Oops - BUG: 00000000f2000800 [#1] PREEMPT SMP
Modules linked in:
CPU: 0 PID: 3074 Comm: syz-executor203 Not tainted 6.1.0-rc6-syzkaller-32653-g65762d97e6fa #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/30/2022
pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : add_to_queue+0x6ec/0x780 fs/gfs2/glock.c:1559
lr : add_to_queue+0x6ec/0x780 fs/gfs2/glock.c:1559
sp : ffff800012deb950
x29: ffff800012deb960 x28: ffff0000cbfa6e80 x27: ffff0000ccea2000
x26: ffff0000cbfa6e80 x25: 0000000000000400 x24: ffff0000c207a800
x23: 0000000000000000 x22: ffff0000c207a800 x21: ffff0000ccea3270
x20: ffff0000cbfa6eb8 x19: ffff0000c70fc550 x18: 00000000000000c0
x17: 5d333032726f7475 x16: ffff80000dbe6158 x15: ffff0000c4248000
x14: 0000000000000000 x13: 00000000ffffffff x12: ffff0000c4248000
x11: ff8080000926a440 x10: 0000000000000000 x9 : 739e9965397fe700
x8 : 739e9965397fe700 x7 : ffff80000c08e4f4 x6 : 0000000000000000
x5 : 0000000000000080 x4 : 0000000000000001 x3 : 0000000000000000
x2 : 0000000000000000 x1 : 0000000000000001 x0 : 0000000000000000
Call trace:
 add_to_queue+0x6ec/0x780 fs/gfs2/glock.c:1559
 gfs2_glock_nq+0x90/0x220 fs/gfs2/glock.c:1585
 gfs2_glock_nq_init fs/gfs2/glock.h:264 [inline]
 do_sync+0x1dc/0x650 fs/gfs2/quota.c:910
 gfs2_quota_sync+0xf0/0x204 fs/gfs2/quota.c:1318
 gfs2_sync_fs+0x30/0x78 fs/gfs2/super.c:643
 sync_filesystem+0x68/0x134 fs/sync.c:56
 generic_shutdown_super+0x38/0x198 fs/super.c:474
 kill_block_super+0x30/0x78 fs/super.c:1428
 gfs2_kill_sb+0x68/0x78
 deactivate_locked_super+0x70/0xe8 fs/super.c:332
 deactivate_super+0xd0/0xd4 fs/super.c:363
 cleanup_mnt+0x184/0x1c0 fs/namespace.c:1186
 __cleanup_mnt+0x20/0x30 fs/namespace.c:1193
 task_work_run+0x100/0x148 kernel/task_work.c:179
 exit_task_work include/linux/task_work.h:38 [inline]
 do_exit+0x2dc/0xcac kernel/exit.c:820
 __arm64_sys_exit_group+0x0/0x18 kernel/exit.c:950
 __do_sys_exit_group kernel/exit.c:961 [inline]
 __se_sys_exit_group kernel/exit.c:959 [inline]
 __wake_up_parent+0x0/0x40 kernel/exit.c:959
 __invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
 invoke_syscall arch/arm64/kernel/syscall.c:52 [inline]
 el0_svc_common+0x138/0x220 arch/arm64/kernel/syscall.c:142
 do_el0_svc+0x48/0x164 arch/arm64/kernel/syscall.c:206
 el0_svc+0x58/0x150 arch/arm64/kernel/entry-common.c:637
 el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
 el0t_64_sync+0x190/0x194 arch/arm64/kernel/entry.S:584
Code: 52800022 aa1f03e0 aa1303e1 97fff219 (d4210000) 
---[ end trace 0000000000000000 ]---


  reply	other threads:[~2022-11-25 13:20 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2022-10-28 12:13 [Cluster-devel] [syzbot] kernel BUG in add_to_queue syzbot
2022-10-28 12:13 ` syzbot
2022-11-25 13:20 ` syzbot [this message]
2022-11-25 13:20   ` syzbot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=000000000000ddc6ce05ee4b637d@google.com \
    --to=syzbot+8a4b520a9affc6d8ea56@syzkaller.appspotmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.