All of lore.kernel.org
 help / color / mirror / Atom feed
From: syzbot ci <syzbot+cif06ef19c5d178998@syzkaller.appspotmail.com>
To: linux-btrfs@vger.kernel.org, linux-fsdevel@vger.kernel.org,
	 linux-xfs@vger.kernel.org, wqu@suse.com
Cc: syzbot@lists.linux.dev, syzkaller-bugs@googlegroups.com
Subject: [syzbot ci] Re: iomap: follow the alignment requirement for iomap_dio_hole_iter()
Date: Sun, 02 Aug 2026 12:14:09 -0700	[thread overview]
Message-ID: <6a6f9701.1aa927e4.17d4bf.001c.GAE@google.com> (raw)
In-Reply-To: <9209e7204fc6b7b60c28f196750084be8a2faba8.1785489008.git.wqu@suse.com>

syzbot ci has tested the following series

[v2] iomap: follow the alignment requirement for iomap_dio_hole_iter()
https://lore.kernel.org/all/9209e7204fc6b7b60c28f196750084be8a2faba8.1785489008.git.wqu@suse.com
* [PATCH v2] iomap: follow the alignment requirement for iomap_dio_hole_iter()

and found the following issue:
general protection fault in iomap_dio_hole_iter

Full report is available here:
https://ci.syzbot.org/series/9d98023b-4249-4697-ab21-ea7cf83805c8

***

general protection fault in iomap_dio_hole_iter

tree:      vfs
URL:       https://kernel.googlesource.com/pub/scm/linux/kernel/git/vfs/vfs.git
base:      fa20f6cb6063f7f1a6a56693d4a8713f19058d23
arch:      amd64
compiler:  Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
config:    https://ci.syzbot.org/builds/a53b891c-9ac3-484a-a77e-61c04d35157f/config
syz repro: https://ci.syzbot.org/findings/8ed3b1e3-7e4e-4c2c-b0f6-934cfea6e536/syz_repro

syz.0.17: attempt to access beyond end of device
loop0: rw=2049, sector=53248, nr_sectors = 976 limit=40427
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000003: 0000 [#1] SMP KASAN PTI
KASAN: null-ptr-deref in range [0x0000000000000018-0x000000000000001f]
CPU: 1 UID: 0 PID: 6257 Comm: syz.0.17 Not tainted syzkaller #0 PREEMPT(full) 
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014
RIP: 0010:bdev_get_queue include/linux/blkdev.h:1056 [inline]
RIP: 0010:bdev_logical_block_size include/linux/blkdev.h:1401 [inline]
RIP: 0010:iomap_dio_alignment fs/iomap/direct-io.c:412 [inline]
RIP: 0010:iomap_dio_hole_iter+0x1bf/0x390 fs/iomap/direct-io.c:598
Code: fc ff df 80 3c 08 00 74 08 4c 89 ef e8 aa d7 c7 ff 49 8b 6d 00 48 83 c5 18 48 89 e8 48 c1 e8 03 48 b9 00 00 00 00 00 fc ff df <80> 3c 08 00 74 08 48 89 ef e8 83 d7 c7 ff 41 bd 58 01 00 00 4c 03
RSP: 0018:ffffc90003eff500 EFLAGS: 00010206
RAX: 0000000000000003 RBX: ffffc90003eff680 RCX: dffffc0000000000
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: 0000000000000018 R08: ffff88816dc38fff R09: 0000000000000000
R10: ffff88816dc38000 R11: ffffed102db87200 R12: 0000000000001000
R13: ffffc90003eff6c8 R14: ffff88816b839c00 R15: 1ffff1102d707388
FS:  00007ffb1678d6c0(0000) GS:ffff8882a8f4b000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000563ae8dcd0a8 CR3: 0000000110cf4000 CR4: 00000000000006f0
Call Trace:
 <TASK>
 iomap_dio_iter fs/iomap/direct-io.c:-1 [inline]
 __iomap_dio_rw+0xe56/0x1ac0 fs/iomap/direct-io.c:823
 f2fs_dio_read_iter fs/f2fs/file.c:4887 [inline]
 f2fs_file_read_iter+0x60b/0x940 fs/f2fs/file.c:4950
 copy_splice_read+0x5ff/0xaa0 fs/splice.c:362
 do_splice_read fs/splice.c:979 [inline]
 splice_direct_to_actor+0x4b6/0xcb0 fs/splice.c:1084
 do_splice_direct_actor fs/splice.c:1202 [inline]
 do_splice_direct+0x195/0x290 fs/splice.c:1228
 do_sendfile+0x52e/0x7c0 fs/read_write.c:1371
 __do_sys_sendfile64 fs/read_write.c:1432 [inline]
 __se_sys_sendfile64+0x144/0x1a0 fs/read_write.c:1418
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7ffb1599e019
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ffb1678d028 EFLAGS: 00000246 ORIG_RAX: 0000000000000028
RAX: ffffffffffffffda RBX: 00007ffb15c25fa0 RCX: 00007ffb1599e019
RDX: 0000000000000000 RSI: 0000000000000004 RDI: 0000000000000004
RBP: 00007ffb15a3500c R08: 0000000000000000 R09: 0000000000000000
R10: 0000000800000009 R11: 0000000000000246 R12: 0000000000000000
R13: 00007ffb15c26038 R14: 00007ffb15c25fa0 R15: 00007ffc15b4ab58
 </TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:bdev_get_queue include/linux/blkdev.h:1056 [inline]
RIP: 0010:bdev_logical_block_size include/linux/blkdev.h:1401 [inline]
RIP: 0010:iomap_dio_alignment fs/iomap/direct-io.c:412 [inline]
RIP: 0010:iomap_dio_hole_iter+0x1bf/0x390 fs/iomap/direct-io.c:598
Code: fc ff df 80 3c 08 00 74 08 4c 89 ef e8 aa d7 c7 ff 49 8b 6d 00 48 83 c5 18 48 89 e8 48 c1 e8 03 48 b9 00 00 00 00 00 fc ff df <80> 3c 08 00 74 08 48 89 ef e8 83 d7 c7 ff 41 bd 58 01 00 00 4c 03
RSP: 0018:ffffc90003eff500 EFLAGS: 00010206
RAX: 0000000000000003 RBX: ffffc90003eff680 RCX: dffffc0000000000
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: 0000000000000018 R08: ffff88816dc38fff R09: 0000000000000000
R10: ffff88816dc38000 R11: ffffed102db87200 R12: 0000000000001000
R13: ffffc90003eff6c8 R14: ffff88816b839c00 R15: 1ffff1102d707388
FS:  00007ffb1678d6c0(0000) GS:ffff8882a8f4b000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000558d8b221b40 CR3: 0000000110cf4000 CR4: 00000000000006f0
----------------
Code disassembly (best guess), 2 bytes skipped:
   0:	df 80 3c 08 00 74    	filds  0x7400083c(%rax)
   6:	08 4c 89 ef          	or     %cl,-0x11(%rcx,%rcx,4)
   a:	e8 aa d7 c7 ff       	call   0xffc7d7b9
   f:	49 8b 6d 00          	mov    0x0(%r13),%rbp
  13:	48 83 c5 18          	add    $0x18,%rbp
  17:	48 89 e8             	mov    %rbp,%rax
  1a:	48 c1 e8 03          	shr    $0x3,%rax
  1e:	48 b9 00 00 00 00 00 	movabs $0xdffffc0000000000,%rcx
  25:	fc ff df
* 28:	80 3c 08 00          	cmpb   $0x0,(%rax,%rcx,1) <-- trapping instruction
  2c:	74 08                	je     0x36
  2e:	48 89 ef             	mov    %rbp,%rdi
  31:	e8 83 d7 c7 ff       	call   0xffc7d7b9
  36:	41 bd 58 01 00 00    	mov    $0x158,%r13d
  3c:	4c                   	rex.WR
  3d:	03                   	.byte 0x3


***

If these findings have caused you to resend the series or submit a
separate fix, please add the following tag to your commit message:
  Tested-by: syzbot@syzkaller.appspotmail.com

---
This report is generated by a bot. It may contain errors.
syzbot ci engineers can be reached at syzkaller@googlegroups.com.

To test a patch for this bug, please reply with `#syz test`
(should be on a separate line).

The patch should be attached to the email.
Note: arguments like custom git repos and branches are not supported.

  reply	other threads:[~2026-08-02 19:14 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-31  9:11 [PATCH v2] iomap: follow the alignment requirement for iomap_dio_hole_iter() Qu Wenruo
2026-08-02 19:14 ` syzbot ci [this message]
  -- strict thread matches above, loose matches on Subject: below --
2026-07-30  1:22 [PATCH] " Qu Wenruo
2026-07-31 11:41 ` [syzbot ci] " syzbot ci
2026-07-31 21:29   ` Qu Wenruo

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=6a6f9701.1aa927e4.17d4bf.001c.GAE@google.com \
    --to=syzbot+cif06ef19c5d178998@syzkaller.appspotmail.com \
    --cc=linux-btrfs@vger.kernel.org \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=linux-xfs@vger.kernel.org \
    --cc=syzbot@lists.linux.dev \
    --cc=syzkaller-bugs@googlegroups.com \
    --cc=wqu@suse.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.