All of lore.kernel.org
 help / color / mirror / Atom feed
From: Rik van Riel <riel@surriel.com>
To: Luis Chamberlain <mcgrof@kernel.org>,
	syzbot	 <syzbot+f3c6fda1297c748a7076@syzkaller.appspotmail.com>,
	Jan Kara <jack@suse.cz>,  Dave Chinner <david@fromorbit.com>
Cc: brauner@kernel.org, hare@suse.de, joel.granados@kernel.org,
	 john.g.garry@oracle.com, kees@kernel.org,
	linux-fsdevel@vger.kernel.org,  linux-kernel@vger.kernel.org,
	linux-mm@kvack.org,  syzkaller-bugs@googlegroups.com,
	willy@infradead.org
Subject: Re: [syzbot] [mm?] [fs?] BUG: sleeping function called from invalid context in folio_mc_copy
Date: Sat, 29 Mar 2025 22:05:34 -0400	[thread overview]
Message-ID: <2ccb9f828ea392eb22f8deb7d9644a4575fa9ee5.camel@surriel.com> (raw)
In-Reply-To: <Z-XGWGKJJThjtsXM@bombadil.infradead.org>

On Thu, 2025-03-27 at 14:42 -0700, Luis Chamberlain wrote:
> On Thu, Mar 27, 2025 at 09:26:41AM -0700, syzbot wrote:
> > Hello,
> 
> Thanks, this is a known issue and we're having a hard time
> reproducing [0].
> 
> > C reproducer:  
> > https://syzkaller.appspot.com/x/repro.c?x=152d4de4580000
> 
> Thanks! Sadly this has not yet been able to let me reprodouce the
> issue,
> and so we're trying to come up with other ways to test the imminent
> spin
> lock + sleep on buffer_migrate_folio_norefs() path different ways
> now,
> including a new fstests [1] but no luck yet.

The backtrace in the report seems to make the cause
of the bug fairly clear, though.

The function folio_mc_copy() can sleep.

The function __buffer_migrate_folio() calls
filemap_migrate_folio() with a spinlock held.

That function eventually calls folio_mc_copy():

 __might_resched+0x5d4/0x780 kernel/sched/core.c:8764
 folio_mc_copy+0x13c/0x1d0 mm/util.c:742
 __migrate_folio mm/migrate.c:758 [inline]
 filemap_migrate_folio+0xb4/0x4c0 mm/migrate.c:943
 __buffer_migrate_folio+0x3ec/0x5d0 mm/migrate.c:874
 move_to_new_folio+0x2ac/0xc20 mm/migrate.c:1050
 migrate_folio_move mm/migrate.c:1358 [inline]
 migrate_folios_move mm/migrate.c:1710 [inline]

The big question is how to safely release the
spinlock in __buffer_migrate_folio() before calling
filemap_migrate_folio()

-- 
All Rights Reversed.

  reply	other threads:[~2025-03-30  2:05 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-03-27 16:26 [syzbot] [mm?] [fs?] BUG: sleeping function called from invalid context in folio_mc_copy syzbot
2025-03-27 21:42 ` Luis Chamberlain
2025-03-30  2:05   ` Rik van Riel [this message]
2025-03-30  2:26     ` Luis Chamberlain
2025-03-30  4:02 ` [syzbot] " syzbot
     [not found] <Z-jCVfGaNHmLVN2i@bombadil.infradead.org>
2025-03-30  4:21 ` syzbot
2025-03-30  4:59   ` Luis Chamberlain

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2ccb9f828ea392eb22f8deb7d9644a4575fa9ee5.camel@surriel.com \
    --to=riel@surriel.com \
    --cc=brauner@kernel.org \
    --cc=david@fromorbit.com \
    --cc=hare@suse.de \
    --cc=jack@suse.cz \
    --cc=joel.granados@kernel.org \
    --cc=john.g.garry@oracle.com \
    --cc=kees@kernel.org \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    --cc=mcgrof@kernel.org \
    --cc=syzbot+f3c6fda1297c748a7076@syzkaller.appspotmail.com \
    --cc=syzkaller-bugs@googlegroups.com \
    --cc=willy@infradead.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.