From: syzbot <syzbot+4d3cc33ef7a77041efa6@syzkaller.appspotmail.com>
To: dileepsankhla.ds@gmail.com, linux-kernel@vger.kernel.org,
syzkaller-bugs@googlegroups.com
Subject: Re: [syzbot] [fs?] [mm?] kernel BUG in __filemap_add_folio
Date: Wed, 10 Dec 2025 04:22:03 -0800 [thread overview]
Message-ID: <693965eb.a70a0220.33cd7b.000b.GAE@google.com> (raw)
In-Reply-To: <CAHxc4btCUUJB=4YVBDHROaWOVkB1mOfYb37Hw-FGXbZu+n4H6w@mail.gmail.com>
Hello,
syzbot has tested the proposed patch but the reproducer is still triggering an issue:
INFO: task hung in set_blocksize
INFO: task syz.0.1117:9015 blocked for more than 143 seconds.
Not tainted syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:syz.0.1117 state:D stack:27296 pid:9015 tgid:9012 ppid:6400 task_flags:0x400140 flags:0x00080002
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5256 [inline]
__schedule+0x1139/0x6150 kernel/sched/core.c:6863
__schedule_loop kernel/sched/core.c:6945 [inline]
schedule+0xe7/0x3a0 kernel/sched/core.c:6960
schedule_preempt_disabled+0x13/0x30 kernel/sched/core.c:7017
rwsem_down_write_slowpath+0x521/0x1310 kernel/locking/rwsem.c:1185
__down_write_common kernel/locking/rwsem.c:1317 [inline]
__down_write kernel/locking/rwsem.c:1326 [inline]
down_write+0x1d6/0x200 kernel/locking/rwsem.c:1591
filemap_invalidate_lock include/linux/fs.h:1082 [inline]
set_blocksize+0x20f/0x500 block/bdev.c:204
blkdev_bszset+0x19b/0x240 block/ioctl.c:634
blkdev_ioctl+0x2ef/0x6e0 block/ioctl.c:773
vfs_ioctl fs/ioctl.c:51 [inline]
__do_sys_ioctl fs/ioctl.c:597 [inline]
__se_sys_ioctl fs/ioctl.c:583 [inline]
__x64_sys_ioctl+0x18e/0x210 fs/ioctl.c:583
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xcd/0xf80 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f939698eba9
RSP: 002b:00007f93978b0038 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 00007f9396bd5fa0 RCX: 00007f939698eba9
RDX: 0000200000000980 RSI: 0000000040081271 RDI: 0000000000000005
RBP: 00007f9396a11e19 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f9396bd6038 R14: 00007f9396bd5fa0 R15: 00007ffd57bc7cc8
</TASK>
INFO: task syz.1.1118:9013 blocked for more than 143 seconds.
Not tainted syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:syz.1.1118 state:D stack:27536 pid:9013 tgid:9013 ppid:6399 task_flags:0x440040 flags:0x00080002
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5256 [inline]
__schedule+0x1139/0x6150 kernel/sched/core.c:6863
__schedule_loop kernel/sched/core.c:6945 [inline]
schedule+0xe7/0x3a0 kernel/sched/core.c:6960
schedule_preempt_disabled+0x13/0x30 kernel/sched/core.c:7017
rwsem_down_read_slowpath+0x64b/0xbf0 kernel/locking/rwsem.c:1086
__down_read_common kernel/locking/rwsem.c:1261 [inline]
__down_read kernel/locking/rwsem.c:1274 [inline]
down_read+0xef/0x460 kernel/locking/rwsem.c:1539
filemap_invalidate_lock_shared include/linux/fs.h:1092 [inline]
page_cache_ra_unbounded+0x20c/0x9e0 mm/readahead.c:233
do_page_cache_ra mm/readahead.c:332 [inline]
page_cache_ra_order+0x9c8/0xd80 mm/readahead.c:536
do_sync_mmap_readahead mm/filemap.c:3400 [inline]
filemap_fault+0x16ac/0x29d0 mm/filemap.c:3549
__do_fault+0x10d/0x490 mm/memory.c:5320
do_shared_fault mm/memory.c:5819 [inline]
do_fault+0x302/0x1ad0 mm/memory.c:5893
do_pte_missing mm/memory.c:4401 [inline]
handle_pte_fault mm/memory.c:6273 [inline]
__handle_mm_fault+0x1919/0x2bb0 mm/memory.c:6411
handle_mm_fault+0x3fe/0xad0 mm/memory.c:6580
do_user_addr_fault+0x60c/0x1370 arch/x86/mm/fault.c:1336
handle_page_fault arch/x86/mm/fault.c:1476 [inline]
exc_page_fault+0x64/0xc0 arch/x86/mm/fault.c:1532
asm_exc_page_fault+0x26/0x30 arch/x86/include/asm/idtentry.h:618
RIP: 0033:0x7f55be158088
RSP: 002b:00007ffe04457bf8 EFLAGS: 00010202
RAX: 0000200000000080 RBX: 0000000000000004 RCX: 0030626c6c756e2f
RDX: 000000000000000c RSI: 6c756e2f7665642f RDI: 0000200000000080
RBP: 00007f55be3d7da0 R08: 0000001b33920000 R09: 0000000000000001
R10: 0000000000000001 R11: 0000000000000009 R12: 00007f55be3d5fac
R13: 00007f55be3d5fa0 R14: fffffffffffffffe R15: 00007ffe04457d10
</TASK>
INFO: lockdep is turned off.
NMI backtrace for cpu 0
CPU: 0 UID: 0 PID: 31 Comm: khungtaskd Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/25/2025
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:94 [inline]
dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:120
nmi_cpu_backtrace+0x27b/0x390 lib/nmi_backtrace.c:113
nmi_trigger_cpumask_backtrace+0x29c/0x300 lib/nmi_backtrace.c:62
trigger_all_cpu_backtrace include/linux/nmi.h:160 [inline]
__sys_info lib/sys_info.c:157 [inline]
sys_info+0x133/0x180 lib/sys_info.c:165
check_hung_uninterruptible_tasks kernel/hung_task.c:346 [inline]
watchdog+0xe66/0x1180 kernel/hung_task.c:515
kthread+0x3c5/0x780 kernel/kthread.c:463
ret_from_fork+0x983/0xb10 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:246
</TASK>
Sending NMI from CPU 0 to CPUs 1:
NMI backtrace for cpu 1
CPU: 1 UID: 0 PID: 0 Comm: swapper/1 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/25/2025
RIP: 0010:pv_native_safe_halt+0xf/0x20 arch/x86/kernel/paravirt.c:82
Code: 86 6c 02 c3 cc cc cc cc 0f 1f 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 66 90 0f 00 2d 13 69 1f 00 fb f4 <e9> cc 35 03 00 66 2e 0f 1f 84 00 00 00 00 00 66 90 90 90 90 90 90
RSP: 0018:ffffc90000197de8 EFLAGS: 000002c6
RAX: 000000000003249c RBX: 0000000000000001 RCX: ffffffff8b6af6d9
RDX: ffffed10170a673e RSI: ffffffff8bf29c80 RDI: ffffffff819335dd
RBP: ffffed1003b56498 R08: 0000000000000000 R09: ffffed10170a673d
R10: ffff8880b85339eb R11: 0000000000005e25 R12: 0000000000000001
R13: ffff88801dab24c0 R14: ffffffff908653d0 R15: 0000000000000000
FS: 0000000000000000(0000) GS:ffff888124a4e000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000055555cc735c8 CR3: 000000005dfbe000 CR4: 00000000003526f0
Call Trace:
<TASK>
arch_safe_halt arch/x86/include/asm/paravirt.h:107 [inline]
default_idle+0x13/0x20 arch/x86/kernel/process.c:767
default_idle_call+0x6c/0xb0 kernel/sched/idle.c:122
cpuidle_idle_call kernel/sched/idle.c:191 [inline]
do_idle+0x38d/0x510 kernel/sched/idle.c:332
cpu_startup_entry+0x4f/0x60 kernel/sched/idle.c:430
start_secondary+0x21d/0x2d0 arch/x86/kernel/smpboot.c:312
common_startup_64+0x13e/0x148
</TASK>
Tested on:
commit: 0048fbb4 Merge tag 'locking-futex-2025-12-10' of git:/..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=12b6deb4580000
kernel config: https://syzkaller.appspot.com/x/.config?x=219582171d92591c
dashboard link: https://syzkaller.appspot.com/bug?extid=4d3cc33ef7a77041efa6
compiler: gcc (Debian 12.2.0-14+deb12u1) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40
patch: https://syzkaller.appspot.com/x/patch.diff?x=163fda1a580000
next prev parent reply other threads:[~2025-12-10 12:22 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <CAHxc4buC59r-8V89TqXQPT-PnfSed4YU17Okc8jnX5hek22bwA@mail.gmail.com>
2025-11-04 9:40 ` [syzbot] [fs?] [mm?] kernel BUG in __filemap_add_folio syzbot
2025-12-10 11:55 ` Dileep Sankhla
2025-12-10 12:22 ` syzbot [this message]
[not found] <CAD3jPMoXJuoiMRoGkVH9gtmDV6m6+S8u8uZS3by9ECJ1ahjBHw@mail.gmail.com>
2026-03-24 20:07 ` syzbot
2025-12-16 12:05 [PATCH] mm/readahead: read min folio constraints under invalidate lock Jinchao Wang
2025-12-16 12:28 ` [syzbot] [fs?] [mm?] kernel BUG in __filemap_add_folio syzbot
[not found] <CAHxc4btH53u7Y3DRFmaiF3-pqumZi1swOgEi0r2_4=bTnKfjSw@mail.gmail.com>
2025-10-11 12:14 ` syzbot
-- strict thread matches above, loose matches on Subject: below --
2025-04-25 1:19 syzbot
2025-11-30 15:03 ` shaurya
2025-11-30 15:51 ` syzbot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=693965eb.a70a0220.33cd7b.000b.GAE@google.com \
--to=syzbot+4d3cc33ef7a77041efa6@syzkaller.appspotmail.com \
--cc=dileepsankhla.ds@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=syzkaller-bugs@googlegroups.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.