All of lore.kernel.org
 help / color / mirror / Atom feed
From: syzbot <syzbot+33a04338019ac7e43a44@syzkaller.appspotmail.com>
To: kartikey406@gmail.com, linux-kernel@vger.kernel.org,
	 syzkaller-bugs@googlegroups.com
Subject: Re: [syzbot] [kvm?] WARNING in kvm_gmem_fault_user_mapping
Date: Mon, 02 Feb 2026 02:52:01 -0800	[thread overview]
Message-ID: <698081d1.050a0220.16b13.00a5.GAE@google.com> (raw)
In-Reply-To: <20260202083439.95644-1-kartikey406@gmail.com>

Hello,

syzbot has tested the proposed patch but the reproducer is still triggering an issue:
kernel BUG in filemap_remove_folio

------------[ cut here ]------------
kernel BUG at mm/filemap.c:254!
Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI
CPU: 1 UID: 0 PID: 7475 Comm: syz.2.329 Not tainted syzkaller #0 PREEMPT(full) 
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/24/2026
RIP: 0010:filemap_remove_folio+0x20f/0x270 mm/filemap.c:254
Code: fc 00 10 00 00 0f 86 5f ff ff ff eb 9e e8 b9 e5 c6 ff 48 c7 c6 20 0d 9d 8b 48 89 df e8 6a 2a 12 00 90 0f 0b e8 a2 e5 c6 ff 90 <0f> 0b e8 9a 38 31 00 e9 39 fe ff ff e8 90 38 31 00 e9 0c fe ff ff
RSP: 0018:ffffc9000caaf7f0 EFLAGS: 00010293
RAX: 0000000000000000 RBX: ffffea0001400000 RCX: ffffffff8240149d
RDX: ffff88802bcaa4c0 RSI: ffffffff824015fe RDI: ffff88802bcaa4c0
RBP: ffff88806b3047b0 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000000
R13: ffff88806b3045c0 R14: 0000000000000000 R15: 1000200001ee0000
FS:  00007fa5c3e506c0(0000) GS:ffff8881246d9000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 00000000572cf000 CR4: 00000000003526f0
Call Trace:
 <TASK>
 kvm_gmem_get_folio+0x118/0x320 virt/kvm/guest_memfd.c:166
 kvm_gmem_fault_user_mapping+0x151/0x6e0 virt/kvm/guest_memfd.c:425
 __do_fault+0x10d/0x550 mm/memory.c:5323
 do_read_fault mm/memory.c:5758 [inline]
 do_fault+0xaf9/0x1990 mm/memory.c:5892
 do_pte_missing mm/memory.c:4404 [inline]
 handle_pte_fault mm/memory.c:6276 [inline]
 __handle_mm_fault+0x1807/0x2b50 mm/memory.c:6414
 handle_mm_fault+0x36d/0xa20 mm/memory.c:6583
 faultin_page mm/gup.c:1126 [inline]
 __get_user_pages+0xf9c/0x34d0 mm/gup.c:1428
 populate_vma_page_range+0x267/0x3f0 mm/gup.c:1860
 __mm_populate+0x107/0x3a0 mm/gup.c:1963
 do_mlock+0x3f0/0x7f0 mm/mlock.c:653
 __do_sys_mlock mm/mlock.c:661 [inline]
 __se_sys_mlock mm/mlock.c:659 [inline]
 __x64_sys_mlock+0x59/0x80 mm/mlock.c:659
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0xc9/0xf80 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fa5c2f9aeb9
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fa5c3e50028 EFLAGS: 00000246 ORIG_RAX: 0000000000000095
RAX: ffffffffffffffda RBX: 00007fa5c3215fa0 RCX: 00007fa5c2f9aeb9
RDX: 0000000000000000 RSI: 0000000000800000 RDI: 0000200000000000
RBP: 00007fa5c3008c1f R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007fa5c3216038 R14: 00007fa5c3215fa0 R15: 00007fff2603f848
 </TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:filemap_remove_folio+0x20f/0x270 mm/filemap.c:254
Code: fc 00 10 00 00 0f 86 5f ff ff ff eb 9e e8 b9 e5 c6 ff 48 c7 c6 20 0d 9d 8b 48 89 df e8 6a 2a 12 00 90 0f 0b e8 a2 e5 c6 ff 90 <0f> 0b e8 9a 38 31 00 e9 39 fe ff ff e8 90 38 31 00 e9 0c fe ff ff
RSP: 0018:ffffc9000caaf7f0 EFLAGS: 00010293
RAX: 0000000000000000 RBX: ffffea0001400000 RCX: ffffffff8240149d
RDX: ffff88802bcaa4c0 RSI: ffffffff824015fe RDI: ffff88802bcaa4c0
RBP: ffff88806b3047b0 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000000
R13: ffff88806b3045c0 R14: 0000000000000000 R15: 1000200001ee0000
FS:  00007fa5c3e506c0(0000) GS:ffff8881245d9000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 00000000572cf000 CR4: 00000000003526f0


Tested on:

commit:         18f7fcd5 Linux 6.19-rc8
git tree:       upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=14e73322580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=f1fac0919970b671
dashboard link: https://syzkaller.appspot.com/bug?extid=33a04338019ac7e43a44
compiler:       gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
patch:          https://syzkaller.appspot.com/x/patch.diff?x=17ca453a580000


       reply	other threads:[~2026-02-02 10:52 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <20260202083439.95644-1-kartikey406@gmail.com>
2026-02-02 10:52 ` syzbot [this message]
2026-02-13 15:43 [PATCH] mm: thp: deny THP for files on anonymous inodes Deepanshu Kartikey
2026-02-13 16:10 ` [syzbot] [kvm?] WARNING in kvm_gmem_fault_user_mapping syzbot
     [not found] <20260209131144.33939-1-kartikey406@gmail.com>
2026-02-09 13:38 ` syzbot
     [not found] <20260209020250.21590-1-kartikey406@gmail.com>
2026-02-09  3:04 ` syzbot
     [not found] <20260209015545.20766-1-kartikey406@gmail.com>
2026-02-09  2:34 ` syzbot
  -- strict thread matches above, loose matches on Subject: below --
2026-02-04 17:01 [PATCH] KVM: guest_memfd: Disable VMA merging with VM_DONTEXPAND Ackerley Tng
2026-02-04 18:21 ` [syzbot] [kvm?] WARNING in kvm_gmem_fault_user_mapping syzbot
2026-02-03 22:50 [PATCH 1/2] KVM: guest_memfd: Always use order 0 when allocating for guest_memfd Ackerley Tng
2026-02-03 22:00 ` [syzbot] [kvm?] WARNING in kvm_gmem_fault_user_mapping syzbot
     [not found] <20260202151142.99116-1-kartikey406@gmail.com>
2026-02-02 16:39 ` syzbot
     [not found] <20260201110809.91962-1-kartikey406@gmail.com>
2026-02-01 11:39 ` syzbot
     [not found] <20260201074823.90148-1-kartikey406@gmail.com>
2026-02-01 10:33 ` syzbot
     [not found] <20260201054807.88100-1-kartikey406@gmail.com>
2026-02-01  6:25 ` syzbot
     [not found] <20260201045720.85957-1-kartikey406@gmail.com>
2026-02-01  5:40 ` syzbot
2026-01-30 20:15 syzbot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=698081d1.050a0220.16b13.00a5.GAE@google.com \
    --to=syzbot+33a04338019ac7e43a44@syzkaller.appspotmail.com \
    --cc=kartikey406@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=syzkaller-bugs@googlegroups.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.