All of lore.kernel.org
 help / color / mirror / Atom feed
From: syzbot <syzbot+25031f01508bf55c62ca@syzkaller.appspotmail.com>
To: dmitry.torokhov@gmail.com, linux-input@vger.kernel.org,
	 linux-kernel@vger.kernel.org, linux-usb@vger.kernel.org,
	 syzkaller-bugs@googlegroups.com
Subject: [syzbot] [input?] [usb?] WARNING in cm109_input_ev/usb_submit_urb (2)
Date: Sat, 25 Jul 2026 12:56:35 -0700	[thread overview]
Message-ID: <6a6514f3.70955b6c.323240.0025.GAE@google.com> (raw)

Hello,

syzbot found the following issue on:

HEAD commit:    cc2b5f627e8c Add linux-next specific files for 20260714
git tree:       linux-next
console output: https://syzkaller.appspot.com/x/log.txt?x=128a1746580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=2290ccbf984c524f
dashboard link: https://syzkaller.appspot.com/bug?extid=25031f01508bf55c62ca
compiler:       Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
syz repro:      https://syzkaller.appspot.com/x/repro.syz?x=117b92b9580000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/6836f8efb1da/disk-cc2b5f62.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/0109d3477cc7/vmlinux-cc2b5f62.xz
kernel image: https://storage.googleapis.com/syzbot-assets/c2e49e350bbf/bzImage-cc2b5f62.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+25031f01508bf55c62ca@syzkaller.appspotmail.com

------------[ cut here ]------------
URB ffff88802bec5e00 submitted while active
WARNING: drivers/usb/core/urb.c:379 at usb_submit_urb+0x79/0x18b0 drivers/usb/core/urb.c:379, CPU#0: syz.1.696/7407
Modules linked in:
CPU: 0 UID: 0 PID: 7407 Comm: syz.1.696 Not tainted syzkaller #0 PREEMPT_{RT,(full)} 
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/25/2026
RIP: 0010:usb_submit_urb+0x7c/0x18b0 drivers/usb/core/urb.c:379
Code: 4c 89 f0 48 c1 e8 03 80 3c 28 00 74 08 4c 89 f7 e8 f9 92 4d fb 49 83 3e 00 74 40 e8 0e 3c e1 fa 48 8d 3d 87 f1 f8 08 48 89 de <67> 48 0f b9 3a b8 f0 ff ff ff eb 11 e8 f3 3b e1 fa eb 05 e8 ec 3b
RSP: 0018:ffffc900054ff3f8 EFLAGS: 00010293
RAX: ffffffff86e467a2 RBX: ffff88802bec5e00 RCX: ffff88803151be80
RDX: 0000000000000000 RSI: ffff88802bec5e00 RDI: ffffffff8fdd5930
RBP: dffffc0000000000 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: ffffffff8e3c3880 R12: 1ffff1100b9e9d0a
R13: dffffc0000000000 R14: ffff88802bec5e08 R15: 0000000000000820
FS:  00007f395df0e6c0(0000) GS:ffff8881259f2000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f29938eb580 CR3: 0000000040c08000 CR4: 00000000003526f0
Call Trace:
 <TASK>
 cm109_submit_buzz_toggle drivers/input/misc/cm109.c:351 [inline]
 cm109_toggle_buzzer_async drivers/input/misc/cm109.c:484 [inline]
 cm109_input_ev+0x1d1/0x3b0 drivers/input/misc/cm109.c:615
 input_event_dispose+0x80/0x6b0 drivers/input/input.c:322
 input_inject_event+0x1fa/0x310 drivers/input/input.c:424
 kd_sound_helper+0x101/0x210 drivers/tty/vt/keyboard.c:257
 input_handler_for_each_handle+0x101/0x1c0 drivers/input/input.c:2540
 kd_mksound+0x96/0x130 drivers/tty/vt/keyboard.c:281
 handle_ascii drivers/tty/vt/vt.c:2382 [inline]
 do_con_trol drivers/tty/vt/vt.c:2699 [inline]
 do_con_write+0x2f5a/0x5540 drivers/tty/vt/vt.c:3325
 con_write+0x31/0x2e0 drivers/tty/vt/vt.c:3661
 process_output_block drivers/tty/n_tty.c:557 [inline]
 n_tty_write+0xd4f/0x11e0 drivers/tty/n_tty.c:2366
 iterate_tty_write drivers/tty/tty_io.c:1006 [inline]
 file_tty_write+0x50b/0x980 drivers/tty/tty_io.c:1081
 new_sync_write fs/read_write.c:595 [inline]
 vfs_write+0x61e/0xbb0 fs/read_write.c:687
 ksys_write+0x156/0x270 fs/read_write.c:739
 do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline]
 do_syscall_64+0x17b/0x530 arch/x86/entry/syscall_64.c:85
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f395e8ade99
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f395df0e028 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 00007f395eb35fa0 RCX: 00007f395e8ade99
RDX: 0000000000001006 RSI: 0000200000002080 RDI: 0000000000000004
RBP: 00007f395e943eaf R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f395eb36038 R14: 00007f395eb35fa0 R15: 00007fff65968248
 </TASK>
----------------
Code disassembly (best guess):
   0:	4c 89 f0             	mov    %r14,%rax
   3:	48 c1 e8 03          	shr    $0x3,%rax
   7:	80 3c 28 00          	cmpb   $0x0,(%rax,%rbp,1)
   b:	74 08                	je     0x15
   d:	4c 89 f7             	mov    %r14,%rdi
  10:	e8 f9 92 4d fb       	call   0xfb4d930e
  15:	49 83 3e 00          	cmpq   $0x0,(%r14)
  19:	74 40                	je     0x5b
  1b:	e8 0e 3c e1 fa       	call   0xfae13c2e
  20:	48 8d 3d 87 f1 f8 08 	lea    0x8f8f187(%rip),%rdi        # 0x8f8f1ae
  27:	48 89 de             	mov    %rbx,%rsi
* 2a:	67 48 0f b9 3a       	ud1    (%edx),%rdi <-- trapping instruction
  2f:	b8 f0 ff ff ff       	mov    $0xfffffff0,%eax
  34:	eb 11                	jmp    0x47
  36:	e8 f3 3b e1 fa       	call   0xfae13c2e
  3b:	eb 05                	jmp    0x42
  3d:	e8                   	.byte 0xe8
  3e:	ec                   	in     (%dx),%al
  3f:	3b                   	.byte 0x3b


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

             reply	other threads:[~2026-07-25 19:56 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-25 19:56 syzbot [this message]
2026-07-27 18:44 ` Forwarded: syzbot
     [not found] <20260727204430.583f59db@systembl0wer>
2026-07-27 19:47 ` [syzbot] [input?] [usb?] WARNING in cm109_input_ev/usb_submit_urb (2) syzbot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=6a6514f3.70955b6c.323240.0025.GAE@google.com \
    --to=syzbot+25031f01508bf55c62ca@syzkaller.appspotmail.com \
    --cc=dmitry.torokhov@gmail.com \
    --cc=linux-input@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-usb@vger.kernel.org \
    --cc=syzkaller-bugs@googlegroups.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.