All of lore.kernel.org
 help / color / mirror / Atom feed
From: syzbot <syzbot+3571c93ad7602c02dd81@syzkaller.appspotmail.com>
To: ardb@kernel.org, jbaron@akamai.com, jpoimboe@redhat.com,
	linux-kernel@vger.kernel.org, peterz@infradead.org,
	rostedt@goodmis.org, syzkaller-bugs@googlegroups.com
Subject: [syzbot] WARNING in __static_key_slow_dec_deferred
Date: Sun, 12 Sep 2021 03:00:25 -0700	[thread overview]
Message-ID: <000000000000e123b605cbc96a09@google.com> (raw)

Hello,

syzbot found the following issue on:

HEAD commit:    ac08b1c68d1b Merge tag 'pci-v5.15-changes' of git://git.ke..
git tree:       upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=13fb02ed300000
kernel config:  https://syzkaller.appspot.com/x/.config?x=a7be4cf759c0440a
dashboard link: https://syzkaller.appspot.com/bug?extid=3571c93ad7602c02dd81
compiler:       Debian clang version 11.0.1-2, GNU ld (GNU Binutils for Debian) 2.35.1
syz repro:      https://syzkaller.appspot.com/x/repro.syz?x=14610b15300000
C reproducer:   https://syzkaller.appspot.com/x/repro.c?x=10148bdb300000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+3571c93ad7602c02dd81@syzkaller.appspotmail.com

------------[ cut here ]------------
jump label: negative count!
WARNING: CPU: 0 PID: 12137 at kernel/jump_label.c:235 static_key_slow_try_dec kernel/jump_label.c:235 [inline]
WARNING: CPU: 0 PID: 12137 at kernel/jump_label.c:235 __static_key_slow_dec_deferred+0x15c/0x1c0 kernel/jump_label.c:286
Modules linked in:
CPU: 1 PID: 12137 Comm: syz-executor068 Not tainted 5.14.0-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
RIP: 0010:static_key_slow_try_dec kernel/jump_label.c:235 [inline]
RIP: 0010:__static_key_slow_dec_deferred+0x15c/0x1c0 kernel/jump_label.c:286
Code: 00 00 4c 89 ea 4c 89 f9 5b 41 5c 41 5d 41 5e 41 5f 5d e9 b7 7d aa ff e8 92 6e d8 ff 48 c7 c7 40 94 59 8a 31 c0 e8 c4 a2 a3 ff <0f> 0b e9 74 ff ff ff 48 c7 c1 44 c3 db 8d 80 e1 07 38 c1 0f 8c c3
RSP: 0018:ffffc9000918f980 EFLAGS: 00010246
RAX: 7cd782d8373e9e00 RBX: 00000000ffffffff RCX: ffff888016b49c80
RDX: 0000000000000000 RSI: 0000000080000000 RDI: 0000000000000000
RBP: 00000000ffffffff R08: ffffffff81681fc2 R09: ffffed10173857a8
R10: ffffed10173857a8 R11: 0000000000000000 R12: ffffffff8ddbe2b8
R13: ffffffff8ddbe2d0 R14: ffff8880205ef601 R15: 0000000000000064
FS:  00007f78f9b46700(0000) GS:ffff8880b9d00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00000000004d0600 CR3: 0000000073b4f000 CR4: 00000000001526e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
 kvm_free_lapic+0x9f/0x170 arch/x86/kvm/lapic.c:2211
 kvm_arch_vcpu_create+0x844/0x970 arch/x86/kvm/x86.c:10751
 kvm_vm_ioctl_create_vcpu arch/x86/kvm/../../../virt/kvm/kvm_main.c:3592 [inline]
 kvm_vm_ioctl+0x1400/0x2910 arch/x86/kvm/../../../virt/kvm/kvm_main.c:4314
 vfs_ioctl fs/ioctl.c:51 [inline]
 __do_sys_ioctl fs/ioctl.c:874 [inline]
 __se_sys_ioctl+0xfb/0x170 fs/ioctl.c:860
 do_syscall_x64 arch/x86/entry/common.c:50 [inline]
 do_syscall_64+0x44/0xd0 arch/x86/entry/common.c:80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x445849
Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 11 15 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f78f9b46308 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 00000000004ca438 RCX: 0000000000445849
RDX: 0000000000000000 RSI: 000000000000ae41 RDI: 0000000000000004
RBP: 00000000004ca430 R08: 00007f78f9b46700 R09: 0000000000000000
R10: 00007f78f9b46700 R11: 0000000000000246 R12: 00000000004ca43c
R13: 000000000049a074 R14: 6d766b2f7665642f R15: 0000000000022000


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this issue, for details see:
https://goo.gl/tpsmEJ#testing-patches

                 reply	other threads:[~2021-09-12 10:14 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=000000000000e123b605cbc96a09@google.com \
    --to=syzbot+3571c93ad7602c02dd81@syzkaller.appspotmail.com \
    --cc=ardb@kernel.org \
    --cc=jbaron@akamai.com \
    --cc=jpoimboe@redhat.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=peterz@infradead.org \
    --cc=rostedt@goodmis.org \
    --cc=syzkaller-bugs@googlegroups.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.