From: syzbot <syzbot+33a04338019ac7e43a44@syzkaller.appspotmail.com>
To: kartikey406@gmail.com, linux-kernel@vger.kernel.org,
syzkaller-bugs@googlegroups.com
Subject: Re: [syzbot] [kvm?] WARNING in kvm_gmem_fault_user_mapping
Date: Sun, 01 Feb 2026 03:39:04 -0800 [thread overview]
Message-ID: <697f3b58.050a0220.16b13.009f.GAE@google.com> (raw)
In-Reply-To: <20260201110809.91962-1-kartikey406@gmail.com>
Hello,
syzbot has tested the proposed patch but the reproducer is still triggering an issue:
WARNING in kvm_gmem_fault_user_mapping
------------[ cut here ]------------
folio_test_large(folio)
WARNING: arch/x86/kvm/../../../virt/kvm/guest_memfd.c:416 at kvm_gmem_fault_user_mapping+0x4b5/0x6e0 virt/kvm/guest_memfd.c:416, CPU#0: syz.1.84/6725
Modules linked in:
CPU: 0 UID: 0 PID: 6725 Comm: syz.1.84 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/24/2026
RIP: 0010:kvm_gmem_fault_user_mapping+0x4b5/0x6e0 virt/kvm/guest_memfd.c:416
Code: 00 e9 a1 fe ff ff bd 00 04 00 00 eb d9 e8 43 b8 83 00 48 c7 c6 e0 9f 82 8b 48 89 df e8 54 fb ce 00 90 0f 0b e8 2c b8 83 00 90 <0f> 0b 90 48 8d 6b 34 48 89 df e8 ec f6 bb 00 be 04 00 00 00 48 89
RSP: 0018:ffffc90004d4f848 EFLAGS: 00010293
RAX: 0000000000000000 RBX: ffffea0001380000 RCX: ffffffff81834070
RDX: ffff88802f604980 RSI: ffffffff81834334 RDI: ffff88802f604980
RBP: ffffc90004d4f9f8 R08: 0000000000000007 R09: 0000000000000000
R10: 0000000000000040 R11: 0000000000000000 R12: ffffea0001380000
R13: ffffc90004d4fa08 R14: 0000000000000040 R15: ffffea0001380008
FS: 00007efea6edc6c0(0000) GS:ffff8881245d9000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f0db714da08 CR3: 000000005a1f9000 CR4: 00000000003526f0
Call Trace:
<TASK>
__do_fault+0x10d/0x550 mm/memory.c:5323
do_read_fault mm/memory.c:5758 [inline]
do_fault+0xaf9/0x1990 mm/memory.c:5892
do_pte_missing mm/memory.c:4404 [inline]
handle_pte_fault mm/memory.c:6276 [inline]
__handle_mm_fault+0x1807/0x2b50 mm/memory.c:6414
handle_mm_fault+0x36d/0xa20 mm/memory.c:6583
faultin_page mm/gup.c:1126 [inline]
__get_user_pages+0xf9c/0x34d0 mm/gup.c:1428
populate_vma_page_range+0x267/0x3f0 mm/gup.c:1860
__mm_populate+0x107/0x3a0 mm/gup.c:1963
do_mlock+0x3f0/0x7f0 mm/mlock.c:653
__do_sys_mlock mm/mlock.c:661 [inline]
__se_sys_mlock mm/mlock.c:659 [inline]
__x64_sys_mlock+0x59/0x80 mm/mlock.c:659
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xc9/0xf80 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7efea5f9aeb9
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007efea6edc028 EFLAGS: 00000246 ORIG_RAX: 0000000000000095
RAX: ffffffffffffffda RBX: 00007efea6215fa0 RCX: 00007efea5f9aeb9
RDX: 0000000000000000 RSI: 0000000000800000 RDI: 0000200000000000
RBP: 00007efea6008c1f R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007efea6216038 R14: 00007efea6215fa0 R15: 00007ffd595ac0c8
</TASK>
Tested on:
commit: 162b4244 Merge tag 'iommu-fixes-v6.19-rc7' of git://gi..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=10fde45a580000
kernel config: https://syzkaller.appspot.com/x/.config?x=f1fac0919970b671
dashboard link: https://syzkaller.appspot.com/bug?extid=33a04338019ac7e43a44
compiler: gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
patch: https://syzkaller.appspot.com/x/patch.diff?x=116de45a580000
next parent reply other threads:[~2026-02-01 11:39 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <20260201110809.91962-1-kartikey406@gmail.com>
2026-02-01 11:39 ` syzbot [this message]
2026-02-13 15:43 [PATCH] mm: thp: deny THP for files on anonymous inodes Deepanshu Kartikey
2026-02-13 16:10 ` [syzbot] [kvm?] WARNING in kvm_gmem_fault_user_mapping syzbot
[not found] <20260209131144.33939-1-kartikey406@gmail.com>
2026-02-09 13:38 ` syzbot
[not found] <20260209020250.21590-1-kartikey406@gmail.com>
2026-02-09 3:04 ` syzbot
[not found] <20260209015545.20766-1-kartikey406@gmail.com>
2026-02-09 2:34 ` syzbot
-- strict thread matches above, loose matches on Subject: below --
2026-02-04 17:01 [PATCH] KVM: guest_memfd: Disable VMA merging with VM_DONTEXPAND Ackerley Tng
2026-02-04 18:21 ` [syzbot] [kvm?] WARNING in kvm_gmem_fault_user_mapping syzbot
2026-02-03 22:50 [PATCH 1/2] KVM: guest_memfd: Always use order 0 when allocating for guest_memfd Ackerley Tng
2026-02-03 22:00 ` [syzbot] [kvm?] WARNING in kvm_gmem_fault_user_mapping syzbot
[not found] <20260202151142.99116-1-kartikey406@gmail.com>
2026-02-02 16:39 ` syzbot
[not found] <20260202083439.95644-1-kartikey406@gmail.com>
2026-02-02 10:52 ` syzbot
[not found] <20260201074823.90148-1-kartikey406@gmail.com>
2026-02-01 10:33 ` syzbot
[not found] <20260201054807.88100-1-kartikey406@gmail.com>
2026-02-01 6:25 ` syzbot
[not found] <20260201045720.85957-1-kartikey406@gmail.com>
2026-02-01 5:40 ` syzbot
2026-01-30 20:15 syzbot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=697f3b58.050a0220.16b13.009f.GAE@google.com \
--to=syzbot+33a04338019ac7e43a44@syzkaller.appspotmail.com \
--cc=kartikey406@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=syzkaller-bugs@googlegroups.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.