* [syzbot] [mtd?] divide error in block2mtd_setup2
@ 2026-08-10 0:34 ` syzbot
0 siblings, 0 replies; 23+ messages in thread
From: syzbot @ 2026-08-10 0:34 UTC (permalink / raw)
To: joern, linux-kernel, linux-mtd, miquel.raynal, richard,
syzkaller-bugs, vigneshr
Hello,
syzbot found the following issue on:
HEAD commit: 848acc8ffe1b Merge tag 'fsverity-for-linus' of git://git.k..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=149f2cc6580000
kernel config: https://syzkaller.appspot.com/x/.config?x=c05be6c9b0d36cb9
dashboard link: https://syzkaller.appspot.com/bug?extid=b320a4d5f65a61dbbf89
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/d900f083ada3/non_bootable_disk-848acc8f.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/2425c07b5d46/vmlinux-848acc8f.xz
kernel image: https://storage.googleapis.com/syzbot-assets/cf278dd14da3/bzImage-848acc8f.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+b320a4d5f65a61dbbf89@syzkaller.appspotmail.com
Oops: divide error: 0000 [#1] SMP KASAN NOPTI
CPU: 0 UID: 0 PID: 5325 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:add_device drivers/mtd/devices/block2mtd.c:296 [inline]
RIP: 0010:block2mtd_setup2+0x592/0xda0 drivers/mtd/devices/block2mtd.c:459
Code: 48 8b 74 24 30 48 63 ce 48 89 d8 48 09 c8 48 c1 e8 20 4c 8b 64 24 10 74 0d 48 89 d8 48 99 48 f7 f9 49 89 d5 eb 09 89 d8 31 d2 <f7> f6 41 89 d5 31 ff 4c 89 ee e8 1f da 39 fb 4d 85 ed 0f 85 90 04
RSP: 0018:ffffc9000f26f9a0 EFLAGS: 00010246
RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000000
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000001f00000
RBP: ffffc9000f26fb98 R08: ffff8880353962ef R09: 1ffff11006a72c5d
R10: dffffc0000000000 R11: ffffed1006a72c5e R12: 0000000000000000
R13: ffff88801d02d0b4 R14: ffff8880122be000 R15: ffff8880122be000
FS: 00007fa7d8c5d6c0(0000) GS:ffff88808c540000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fa7d801bb30 CR3: 000000003fb3c000 CR4: 0000000000352ef0
Call Trace:
<TASK>
block2mtd_setup+0x27/0xe0 drivers/mtd/devices/block2mtd.c:476
param_attr_store+0x214/0x310 kernel/params.c:589
module_attr_store+0x65/0x90 kernel/params.c:904
kernfs_fop_write_iter+0x3a4/0x540 fs/kernfs/file.c:345
new_sync_write fs/read_write.c:595 [inline]
vfs_write+0x612/0xba0 fs/read_write.c:687
ksys_write+0x150/0x270 fs/read_write.c:739
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fa7d7d9e019
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fa7d8c5cfe8 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 00007fa7d8025fa0 RCX: 00007fa7d7d9e019
RDX: 000000000000000c RSI: 00002000000000c0 RDI: 0000000000000003
RBP: 00007fa7d7e3500c R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007fa7d8026038 R14: 00007fa7d8025fa0 R15: 00007ffe5587a628
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:add_device drivers/mtd/devices/block2mtd.c:296 [inline]
RIP: 0010:block2mtd_setup2+0x592/0xda0 drivers/mtd/devices/block2mtd.c:459
Code: 48 8b 74 24 30 48 63 ce 48 89 d8 48 09 c8 48 c1 e8 20 4c 8b 64 24 10 74 0d 48 89 d8 48 99 48 f7 f9 49 89 d5 eb 09 89 d8 31 d2 <f7> f6 41 89 d5 31 ff 4c 89 ee e8 1f da 39 fb 4d 85 ed 0f 85 90 04
RSP: 0018:ffffc9000f26f9a0 EFLAGS: 00010246
RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000000
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000001f00000
RBP: ffffc9000f26fb98 R08: ffff8880353962ef R09: 1ffff11006a72c5d
R10: dffffc0000000000 R11: ffffed1006a72c5e R12: 0000000000000000
R13: ffff88801d02d0b4 R14: ffff8880122be000 R15: ffff8880122be000
FS: 00007fa7d8c5d6c0(0000) GS:ffff88808c540000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007ffee237bf52 CR3: 000000003fb3c000 CR4: 0000000000352ef0
----------------
Code disassembly (best guess):
0: 48 8b 74 24 30 mov 0x30(%rsp),%rsi
5: 48 63 ce movslq %esi,%rcx
8: 48 89 d8 mov %rbx,%rax
b: 48 09 c8 or %rcx,%rax
e: 48 c1 e8 20 shr $0x20,%rax
12: 4c 8b 64 24 10 mov 0x10(%rsp),%r12
17: 74 0d je 0x26
19: 48 89 d8 mov %rbx,%rax
1c: 48 99 cqto
1e: 48 f7 f9 idiv %rcx
21: 49 89 d5 mov %rdx,%r13
24: eb 09 jmp 0x2f
26: 89 d8 mov %ebx,%eax
28: 31 d2 xor %edx,%edx
* 2a: f7 f6 div %esi <-- trapping instruction
2c: 41 89 d5 mov %edx,%r13d
2f: 31 ff xor %edi,%edi
31: 4c 89 ee mov %r13,%rsi
34: e8 1f da 39 fb call 0xfb39da58
39: 4d 85 ed test %r13,%r13
3c: 0f .byte 0xf
3d: 85 .byte 0x85
3e: 90 nop
3f: 04 .byte 0x4
---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup
______________________________________________________
Linux MTD discussion mailing list
http://lists.infradead.org/mailman/listinfo/linux-mtd/
^ permalink raw reply [flat|nested] 23+ messages in thread
* [syzbot] [mtd?] divide error in block2mtd_setup2
@ 2026-08-10 0:34 ` syzbot
0 siblings, 0 replies; 23+ messages in thread
From: syzbot @ 2026-08-10 0:34 UTC (permalink / raw)
To: joern, linux-kernel, linux-mtd, miquel.raynal, richard,
syzkaller-bugs, vigneshr
Hello,
syzbot found the following issue on:
HEAD commit: 848acc8ffe1b Merge tag 'fsverity-for-linus' of git://git.k..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=149f2cc6580000
kernel config: https://syzkaller.appspot.com/x/.config?x=c05be6c9b0d36cb9
dashboard link: https://syzkaller.appspot.com/bug?extid=b320a4d5f65a61dbbf89
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/d900f083ada3/non_bootable_disk-848acc8f.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/2425c07b5d46/vmlinux-848acc8f.xz
kernel image: https://storage.googleapis.com/syzbot-assets/cf278dd14da3/bzImage-848acc8f.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+b320a4d5f65a61dbbf89@syzkaller.appspotmail.com
Oops: divide error: 0000 [#1] SMP KASAN NOPTI
CPU: 0 UID: 0 PID: 5325 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:add_device drivers/mtd/devices/block2mtd.c:296 [inline]
RIP: 0010:block2mtd_setup2+0x592/0xda0 drivers/mtd/devices/block2mtd.c:459
Code: 48 8b 74 24 30 48 63 ce 48 89 d8 48 09 c8 48 c1 e8 20 4c 8b 64 24 10 74 0d 48 89 d8 48 99 48 f7 f9 49 89 d5 eb 09 89 d8 31 d2 <f7> f6 41 89 d5 31 ff 4c 89 ee e8 1f da 39 fb 4d 85 ed 0f 85 90 04
RSP: 0018:ffffc9000f26f9a0 EFLAGS: 00010246
RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000000
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000001f00000
RBP: ffffc9000f26fb98 R08: ffff8880353962ef R09: 1ffff11006a72c5d
R10: dffffc0000000000 R11: ffffed1006a72c5e R12: 0000000000000000
R13: ffff88801d02d0b4 R14: ffff8880122be000 R15: ffff8880122be000
FS: 00007fa7d8c5d6c0(0000) GS:ffff88808c540000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fa7d801bb30 CR3: 000000003fb3c000 CR4: 0000000000352ef0
Call Trace:
<TASK>
block2mtd_setup+0x27/0xe0 drivers/mtd/devices/block2mtd.c:476
param_attr_store+0x214/0x310 kernel/params.c:589
module_attr_store+0x65/0x90 kernel/params.c:904
kernfs_fop_write_iter+0x3a4/0x540 fs/kernfs/file.c:345
new_sync_write fs/read_write.c:595 [inline]
vfs_write+0x612/0xba0 fs/read_write.c:687
ksys_write+0x150/0x270 fs/read_write.c:739
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fa7d7d9e019
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fa7d8c5cfe8 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 00007fa7d8025fa0 RCX: 00007fa7d7d9e019
RDX: 000000000000000c RSI: 00002000000000c0 RDI: 0000000000000003
RBP: 00007fa7d7e3500c R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007fa7d8026038 R14: 00007fa7d8025fa0 R15: 00007ffe5587a628
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:add_device drivers/mtd/devices/block2mtd.c:296 [inline]
RIP: 0010:block2mtd_setup2+0x592/0xda0 drivers/mtd/devices/block2mtd.c:459
Code: 48 8b 74 24 30 48 63 ce 48 89 d8 48 09 c8 48 c1 e8 20 4c 8b 64 24 10 74 0d 48 89 d8 48 99 48 f7 f9 49 89 d5 eb 09 89 d8 31 d2 <f7> f6 41 89 d5 31 ff 4c 89 ee e8 1f da 39 fb 4d 85 ed 0f 85 90 04
RSP: 0018:ffffc9000f26f9a0 EFLAGS: 00010246
RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000000
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000001f00000
RBP: ffffc9000f26fb98 R08: ffff8880353962ef R09: 1ffff11006a72c5d
R10: dffffc0000000000 R11: ffffed1006a72c5e R12: 0000000000000000
R13: ffff88801d02d0b4 R14: ffff8880122be000 R15: ffff8880122be000
FS: 00007fa7d8c5d6c0(0000) GS:ffff88808c540000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007ffee237bf52 CR3: 000000003fb3c000 CR4: 0000000000352ef0
----------------
Code disassembly (best guess):
0: 48 8b 74 24 30 mov 0x30(%rsp),%rsi
5: 48 63 ce movslq %esi,%rcx
8: 48 89 d8 mov %rbx,%rax
b: 48 09 c8 or %rcx,%rax
e: 48 c1 e8 20 shr $0x20,%rax
12: 4c 8b 64 24 10 mov 0x10(%rsp),%r12
17: 74 0d je 0x26
19: 48 89 d8 mov %rbx,%rax
1c: 48 99 cqto
1e: 48 f7 f9 idiv %rcx
21: 49 89 d5 mov %rdx,%r13
24: eb 09 jmp 0x2f
26: 89 d8 mov %ebx,%eax
28: 31 d2 xor %edx,%edx
* 2a: f7 f6 div %esi <-- trapping instruction
2c: 41 89 d5 mov %edx,%r13d
2f: 31 ff xor %edi,%edi
31: 4c 89 ee mov %r13,%rsi
34: e8 1f da 39 fb call 0xfb39da58
39: 4d 85 ed test %r13,%r13
3c: 0f .byte 0xf
3d: 85 .byte 0x85
3e: 90 nop
3f: 04 .byte 0x4
---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [syzbot] [mtd?] divide error in block2mtd_setup2
2026-08-10 0:34 ` syzbot
@ 2026-08-10 2:03 ` Jörn Engel
-1 siblings, 0 replies; 23+ messages in thread
From: Jörn Engel @ 2026-08-10 2:03 UTC (permalink / raw)
To: syzbot
Cc: joern, linux-kernel, linux-mtd, miquel.raynal, richard,
syzkaller-bugs, vigneshr
On Sun, Aug 09, 2026 at 05:34:28PM -0700, syzbot wrote:
>
> * 2a: f7 f6 div %esi <-- trapping instruction
Best guess would be this:
if ((long)size % erase_size) {
Someone passing an erase_size of 0 would indeed trigger an exception.
Fix would be something like this:
- if ((long)size % erase_size) {
+ if (!erase_size || (long)size % erase_size) {
I haven't touched the code is nearly two decades. If somebody else
feels like sending a patch and gathering all the glory, please be my
guest!
Jörn
--
Those who come seeking peace without a treaty are plotting.
-- Sun Tzu
______________________________________________________
Linux MTD discussion mailing list
http://lists.infradead.org/mailman/listinfo/linux-mtd/
^ permalink raw reply [flat|nested] 23+ messages in thread* Re: [syzbot] [mtd?] divide error in block2mtd_setup2
@ 2026-08-10 2:03 ` Jörn Engel
0 siblings, 0 replies; 23+ messages in thread
From: Jörn Engel @ 2026-08-10 2:03 UTC (permalink / raw)
To: syzbot
Cc: joern, linux-kernel, linux-mtd, miquel.raynal, richard,
syzkaller-bugs, vigneshr
On Sun, Aug 09, 2026 at 05:34:28PM -0700, syzbot wrote:
>
> * 2a: f7 f6 div %esi <-- trapping instruction
Best guess would be this:
if ((long)size % erase_size) {
Someone passing an erase_size of 0 would indeed trigger an exception.
Fix would be something like this:
- if ((long)size % erase_size) {
+ if (!erase_size || (long)size % erase_size) {
I haven't touched the code is nearly two decades. If somebody else
feels like sending a patch and gathering all the glory, please be my
guest!
Jörn
--
Those who come seeking peace without a treaty are plotting.
-- Sun Tzu
^ permalink raw reply [flat|nested] 23+ messages in thread* Re: [syzbot] [mtd?] divide error in block2mtd_setup2
2026-08-10 2:03 ` Jörn Engel
@ 2026-08-10 9:17 ` Pei Xiao
-1 siblings, 0 replies; 23+ messages in thread
From: Pei Xiao @ 2026-08-10 9:17 UTC (permalink / raw)
To: Jörn Engel, syzbot
Cc: joern, linux-kernel, linux-mtd, miquel.raynal, richard,
syzkaller-bugs, vigneshr
在 2026/8/10 10:03, Jörn Engel 写道:
> On Sun, Aug 09, 2026 at 05:34:28PM -0700, syzbot wrote:
>>
>> * 2a: f7 f6 div %esi <-- trapping instruction
>
> Best guess would be this:
>
> if ((long)size % erase_size) {
>
> Someone passing an erase_size of 0 would indeed trigger an exception.
> Fix would be something like this:
>
> - if ((long)size % erase_size) {
> + if (!erase_size || (long)size % erase_size) {
>
> I haven't touched the code is nearly two decades. If somebody else
> feels like sending a patch and gathering all the glory, please be my
> guest!
Thank you for your contribution. I have sent this patch, but I forgot to
add the Suggested-by: tag
Thanks!
Pei.
>
> Jörn
>
> --
> Those who come seeking peace without a treaty are plotting.
> -- Sun Tzu
>
> ______________________________________________________
> Linux MTD discussion mailing list
> http://lists.infradead.org/mailman/listinfo/linux-mtd/
>
> From mboxrd@z Thu Jan 1 00:00:00 1970
> Received: from mx01.bremer-it.com (mx01.bremer-it.com [85.215.132.167])
> (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
> (No client certificate requested)
> by smtp.subspace.kernel.org (Postfix) with ESMTPS id 73877212550
> for <linux-kernel@vger.kernel.org>; Mon, 10 Aug 2026 02:11:08 +0000 (UTC)
> Authentication-Results: smtp.subspace.kernel.org; arc=ne smtp.client-ip….215.132.167
> ARC-Seal:i= a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116;
> t\x1786327871; cv=none; b=pmhQ+YkskPdHVocSl0Q3ONibHDLR7s7fI85cff5H13l/yM9Z8mDYTBscKANq7mGFD2ASRqvBgqTpqe5XwuxKTwZFODwuxMgU6JESnW9mL+RH7dPhx/4yRbt05Zn2YwFK2lesfp+iHyordavupm+PNHamOQyJJwTUw9tjZZ0ntHAARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org;
> s=c-20240116; t\x1786327871; c=relaxed/simple;
> bh=oRdL2tBTFal/JDe029vqeCkmNFJ6Y4/KQ2bpPcX7k=;
> hÚte:From:To:Cc:Subject:Message-ID:References:MIME-Version:
> Content-Type:Content-Disposition:In-Reply-To; b=XeZFkoGl/EX953bQRJEM5Tfe5d/GrpVVJUzcDSc66bRWr8I0onQDDy/7EWgIvCiEGhJzItU2sfKSjm4pNpXCnZj6NtzWG6zriQzO7WsKIZ2npUEbzkr9fxYKPgNq7NiBQehPlmVw8mZbzVsaVdvKHi5zwE5zILA9+gU9cPWxcARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.fromºrelysecure.org; spf=pass smtp.mailfromºrelysecure.org; dkim=pass (2048-bit key) header.dºrelysecure.org header.i=@barelysecure.org header.b=HAaxkQ/6; arc=none smtp.client-ip….215.132.167
> Authentication-Results: smtp.subspace.kernel.org; dmarc=ss (p=none dis=none) header.fromºrelysecure.org
> Authentication-Results: smtp.subspace.kernel.org; spf=ss smtp.mailfromºrelysecure.org
> Authentication-Results: smtp.subspace.kernel.org;
> dkim=ss (2048-bit key) header.dºrelysecure.org header.i=@barelysecure.org header.b="HAaxkQ/6"
> Received: from cashel.logfs.org (c-98-33-96-243.hsd1.ca.comcast.net [98.33.96.243])
> (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
> key-exchange ECDHE (prime256v1) server-signature ECDSA (secp384r1) server-digest SHA384)
> (No client certificate requested)
> by mx01.bremer-it.com (Postfix) with ESMTPSA id 061CA20B86;
> Mon, 10 Aug 2026 04:03:25 +0200 (CEST)
> DKIM-Signature: v= a=rsa-sha256; c=relaxed/relaxed; dºrelysecure.org;
> s=im68; t\x1786327408;
> h=om:from:reply-to:subject:subject:date:date:message-id:message-id:
> to:to:cc:cc:mime-version:mime-version:content-type:content-type:
> content-transfer-encoding:content-transfer-encoding:
> in-reply-to:in-reply-to:references:references;
> bhÍIDTuliDDGgOAKpI245cMmyPRVVKxIWKH3GuXafqZA=;
> b=HAaxkQ/6AawUqio6ZtZxsW0LqcdaN10B/vRSFk0TcWRBU45jxR+oipsFDUbLTtUrltNgoq
> SUJTT9FHYYItqxPYvDw94jAGkuvJipWw3nalbM+Kl5az2K2VReh3w5eQsKr6sdoXp2TYzJ
> R/1QaEGzKjPtOIK5qoT0bvc6jV/0DL6pI9DWuc6O6DxxGrPYGtwZo2mUmQAuO9Qnm4Snbc
> xSJC10kazHhQLi5gnGRmMR3oz+JF66HhtQ+ApzYgkv3zty8o4P/Vk4Bj7YXV9UTiPwdcJq
> HVIfjaeb2e+Z+Q1K56IpiPILzHBRAYt0tcFSf+P7vSEEBvoUD2BFobn0ZIvA2Q=Authentication-Results: ORIGINATING;
> auth=ss smtp.auth=joern@lazybastard.org smtp.mailfrom=joern@barelysecure.org
> Date: Sun, 9 Aug 2026 19:03:22 -0700
> From: =so-8859-1?Q?Jörn?= Engel <joern@barelysecure.org>
> To: syzbot <syzbot+b320a4d5f65a61dbbf89@syzkaller.appspotmail.com>
> Cc: joern@lazybastard.org, linux-kernel@vger.kernel.org,
> linux-mtd@lists.infradead.org, miquel.raynal@bootlin.com,
> richard@nod.at, syzkaller-bugs@googlegroups.com, vigneshr@ti.com
> Subject: Re: [syzbot] [mtd?] divide error in block2mtd_setup2
> Message-ID: <ankxaiwtTltL0xMj@cashel.logfs.org>
> References: <6a791c94.01d0871a.3a0d52.009b.GAE@google.com>
> Precedence: bulk
> X-Mailing-List: linux-kernel@vger.kernel.org
> List-Id: <linux-kernel.vger.kernel.org>
> List-Subscribe: <mailto:linux-kernel+subscribe@vger.kernel.org>
> List-Unsubscribe: <mailto:linux-kernel+unsubscribe@vger.kernel.org>
> MIME-Version: 1.0
> Content-Type: text/plain; charset=o-8859-1
> Content-Disposition: inline
> Content-Transfer-Encoding: 8bit
> In-Reply-To: <6a791c94.01d0871a.3a0d52.009b.GAE@google.com>
> X-Spam-Level: *
> X-Rspamd-Action: no action
> X-Spamd-Result: default: False [1.40 / 14.00];
> SUSPICIOUS_RECIPS(1.50)[];
> MIME_GOOD(-0.10)[text/plain];
> ARC_NA(0.00)[];
> TAGGED_RCPT(0.00)[b320a4d5f65a61dbbf89];
> RCVD_COUNT_ZERO(0.00)[0];
> ASN(0.00)[asn:7922, ipnet:98.32.0.0/11, country:US];
> MIME_TRACE(0.00)[0:+];
> MISSING_XM_UA(0.00)[];
> RCPT_COUNT_SEVEN(0.00)[8];
> FROM_HAS_DN(0.00)[];
> ALIAS_RESOLVED(0.00)[];
> LOCAL_OUTBOUND(0.00)[];
> FROM_EQ_ENVFROM(0.00)[];
> TO_DN_SOME(0.00)[];
> TO_MATCH_ENVRCPT_SOME(0.00)[];
> DKIM_SIGNED(0.00)[barelysecure.org:s=im68];
> URIBL_BLOCKED(0.00)[cashel.logfs.org:mid,cashel.logfs.org:helo];
> SUBJECT_HAS_QUESTION(0.00)[]
> X-Rspamd-Server: server01
> X-Rspamd-Queue-Id: 061CA20B86
> X-Spamd-Bar: +
>
> On Sun, Aug 09, 2026 at 05:34:28PM -0700, syzbot wrote:
>>
>> * 2a: f7 f6 div %esi <-- trapping instruction
>
> Best guess would be this:
>
> if ((long)size % erase_size) {
>
> Someone passing an erase_size of 0 would indeed trigger an exception.
> Fix would be something like this:
>
> - if ((long)size % erase_size) {
> + if (!erase_size || (long)size % erase_size) {
>
> I haven't touched the code is nearly two decades. If somebody else
> feels like sending a patch and gathering all the glory, please be my
> guest!
>
> Jörn
>
> --
> Those who come seeking peace without a treaty are plotting.
> -- Sun Tzu
>
______________________________________________________
Linux MTD discussion mailing list
http://lists.infradead.org/mailman/listinfo/linux-mtd/
^ permalink raw reply [flat|nested] 23+ messages in thread* Re: [syzbot] [mtd?] divide error in block2mtd_setup2
@ 2026-08-10 9:17 ` Pei Xiao
0 siblings, 0 replies; 23+ messages in thread
From: Pei Xiao @ 2026-08-10 9:17 UTC (permalink / raw)
To: Jörn Engel, syzbot
Cc: joern, linux-kernel, linux-mtd, miquel.raynal, richard,
syzkaller-bugs, vigneshr
在 2026/8/10 10:03, Jörn Engel 写道:
> On Sun, Aug 09, 2026 at 05:34:28PM -0700, syzbot wrote:
>>
>> * 2a: f7 f6 div %esi <-- trapping instruction
>
> Best guess would be this:
>
> if ((long)size % erase_size) {
>
> Someone passing an erase_size of 0 would indeed trigger an exception.
> Fix would be something like this:
>
> - if ((long)size % erase_size) {
> + if (!erase_size || (long)size % erase_size) {
>
> I haven't touched the code is nearly two decades. If somebody else
> feels like sending a patch and gathering all the glory, please be my
> guest!
Thank you for your contribution. I have sent this patch, but I forgot to
add the Suggested-by: tag
Thanks!
Pei.
>
> Jörn
>
> --
> Those who come seeking peace without a treaty are plotting.
> -- Sun Tzu
>
> ______________________________________________________
> Linux MTD discussion mailing list
> http://lists.infradead.org/mailman/listinfo/linux-mtd/
>
> From mboxrd@z Thu Jan 1 00:00:00 1970
> Received: from mx01.bremer-it.com (mx01.bremer-it.com [85.215.132.167])
> (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
> (No client certificate requested)
> by smtp.subspace.kernel.org (Postfix) with ESMTPS id 73877212550
> for <linux-kernel@vger.kernel.org>; Mon, 10 Aug 2026 02:11:08 +0000 (UTC)
> Authentication-Results: smtp.subspace.kernel.org; arc=ne smtp.client-ip….215.132.167
> ARC-Seal:i= a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116;
> t\x1786327871; cv=none; b=pmhQ+YkskPdHVocSl0Q3ONibHDLR7s7fI85cff5H13l/yM9Z8mDYTBscKANq7mGFD2ASRqvBgqTpqe5XwuxKTwZFODwuxMgU6JESnW9mL+RH7dPhx/4yRbt05Zn2YwFK2lesfp+iHyordavupm+PNHamOQyJJwTUw9tjZZ0ntHAARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org;
> s=c-20240116; t\x1786327871; c=relaxed/simple;
> bh=oRdL2tBTFal/JDe029vqeCkmNFJ6Y4/KQ2bpPcX7k=;
> hÚte:From:To:Cc:Subject:Message-ID:References:MIME-Version:
> Content-Type:Content-Disposition:In-Reply-To; b=XeZFkoGl/EX953bQRJEM5Tfe5d/GrpVVJUzcDSc66bRWr8I0onQDDy/7EWgIvCiEGhJzItU2sfKSjm4pNpXCnZj6NtzWG6zriQzO7WsKIZ2npUEbzkr9fxYKPgNq7NiBQehPlmVw8mZbzVsaVdvKHi5zwE5zILA9+gU9cPWxcARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.fromºrelysecure.org; spf=pass smtp.mailfromºrelysecure.org; dkim=pass (2048-bit key) header.dºrelysecure.org header.i=@barelysecure.org header.b=HAaxkQ/6; arc=none smtp.client-ip….215.132.167
> Authentication-Results: smtp.subspace.kernel.org; dmarc=ss (p=none dis=none) header.fromºrelysecure.org
> Authentication-Results: smtp.subspace.kernel.org; spf=ss smtp.mailfromºrelysecure.org
> Authentication-Results: smtp.subspace.kernel.org;
> dkim=ss (2048-bit key) header.dºrelysecure.org header.i=@barelysecure.org header.b="HAaxkQ/6"
> Received: from cashel.logfs.org (c-98-33-96-243.hsd1.ca.comcast.net [98.33.96.243])
> (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
> key-exchange ECDHE (prime256v1) server-signature ECDSA (secp384r1) server-digest SHA384)
> (No client certificate requested)
> by mx01.bremer-it.com (Postfix) with ESMTPSA id 061CA20B86;
> Mon, 10 Aug 2026 04:03:25 +0200 (CEST)
> DKIM-Signature: v= a=rsa-sha256; c=relaxed/relaxed; dºrelysecure.org;
> s=im68; t\x1786327408;
> h=om:from:reply-to:subject:subject:date:date:message-id:message-id:
> to:to:cc:cc:mime-version:mime-version:content-type:content-type:
> content-transfer-encoding:content-transfer-encoding:
> in-reply-to:in-reply-to:references:references;
> bhÍIDTuliDDGgOAKpI245cMmyPRVVKxIWKH3GuXafqZA=;
> b=HAaxkQ/6AawUqio6ZtZxsW0LqcdaN10B/vRSFk0TcWRBU45jxR+oipsFDUbLTtUrltNgoq
> SUJTT9FHYYItqxPYvDw94jAGkuvJipWw3nalbM+Kl5az2K2VReh3w5eQsKr6sdoXp2TYzJ
> R/1QaEGzKjPtOIK5qoT0bvc6jV/0DL6pI9DWuc6O6DxxGrPYGtwZo2mUmQAuO9Qnm4Snbc
> xSJC10kazHhQLi5gnGRmMR3oz+JF66HhtQ+ApzYgkv3zty8o4P/Vk4Bj7YXV9UTiPwdcJq
> HVIfjaeb2e+Z+Q1K56IpiPILzHBRAYt0tcFSf+P7vSEEBvoUD2BFobn0ZIvA2Q=Authentication-Results: ORIGINATING;
> auth=ss smtp.auth=joern@lazybastard.org smtp.mailfrom=joern@barelysecure.org
> Date: Sun, 9 Aug 2026 19:03:22 -0700
> From: =so-8859-1?Q?Jörn?= Engel <joern@barelysecure.org>
> To: syzbot <syzbot+b320a4d5f65a61dbbf89@syzkaller.appspotmail.com>
> Cc: joern@lazybastard.org, linux-kernel@vger.kernel.org,
> linux-mtd@lists.infradead.org, miquel.raynal@bootlin.com,
> richard@nod.at, syzkaller-bugs@googlegroups.com, vigneshr@ti.com
> Subject: Re: [syzbot] [mtd?] divide error in block2mtd_setup2
> Message-ID: <ankxaiwtTltL0xMj@cashel.logfs.org>
> References: <6a791c94.01d0871a.3a0d52.009b.GAE@google.com>
> Precedence: bulk
> X-Mailing-List: linux-kernel@vger.kernel.org
> List-Id: <linux-kernel.vger.kernel.org>
> List-Subscribe: <mailto:linux-kernel+subscribe@vger.kernel.org>
> List-Unsubscribe: <mailto:linux-kernel+unsubscribe@vger.kernel.org>
> MIME-Version: 1.0
> Content-Type: text/plain; charset=o-8859-1
> Content-Disposition: inline
> Content-Transfer-Encoding: 8bit
> In-Reply-To: <6a791c94.01d0871a.3a0d52.009b.GAE@google.com>
> X-Spam-Level: *
> X-Rspamd-Action: no action
> X-Spamd-Result: default: False [1.40 / 14.00];
> SUSPICIOUS_RECIPS(1.50)[];
> MIME_GOOD(-0.10)[text/plain];
> ARC_NA(0.00)[];
> TAGGED_RCPT(0.00)[b320a4d5f65a61dbbf89];
> RCVD_COUNT_ZERO(0.00)[0];
> ASN(0.00)[asn:7922, ipnet:98.32.0.0/11, country:US];
> MIME_TRACE(0.00)[0:+];
> MISSING_XM_UA(0.00)[];
> RCPT_COUNT_SEVEN(0.00)[8];
> FROM_HAS_DN(0.00)[];
> ALIAS_RESOLVED(0.00)[];
> LOCAL_OUTBOUND(0.00)[];
> FROM_EQ_ENVFROM(0.00)[];
> TO_DN_SOME(0.00)[];
> TO_MATCH_ENVRCPT_SOME(0.00)[];
> DKIM_SIGNED(0.00)[barelysecure.org:s=im68];
> URIBL_BLOCKED(0.00)[cashel.logfs.org:mid,cashel.logfs.org:helo];
> SUBJECT_HAS_QUESTION(0.00)[]
> X-Rspamd-Server: server01
> X-Rspamd-Queue-Id: 061CA20B86
> X-Spamd-Bar: +
>
> On Sun, Aug 09, 2026 at 05:34:28PM -0700, syzbot wrote:
>>
>> * 2a: f7 f6 div %esi <-- trapping instruction
>
> Best guess would be this:
>
> if ((long)size % erase_size) {
>
> Someone passing an erase_size of 0 would indeed trigger an exception.
> Fix would be something like this:
>
> - if ((long)size % erase_size) {
> + if (!erase_size || (long)size % erase_size) {
>
> I haven't touched the code is nearly two decades. If somebody else
> feels like sending a patch and gathering all the glory, please be my
> guest!
>
> Jörn
>
> --
> Those who come seeking peace without a treaty are plotting.
> -- Sun Tzu
>
^ permalink raw reply [flat|nested] 23+ messages in thread* Re: [syzbot] [mtd?] divide error in block2mtd_setup2
2026-08-10 9:17 ` Pei Xiao
@ 2026-08-10 12:40 ` Miquel Raynal
-1 siblings, 0 replies; 23+ messages in thread
From: Miquel Raynal @ 2026-08-10 12:40 UTC (permalink / raw)
To: Pei Xiao
Cc: Jörn Engel, syzbot, joern, linux-kernel, linux-mtd, richard,
syzkaller-bugs, vigneshr
Hi Pei,
>> Best guess would be this:
>>
>> if ((long)size % erase_size) {
>>
>> Someone passing an erase_size of 0 would indeed trigger an exception.
>> Fix would be something like this:
>>
>> - if ((long)size % erase_size) {
>> + if (!erase_size || (long)size % erase_size) {
>>
>> I haven't touched the code is nearly two decades. If somebody else
>> feels like sending a patch and gathering all the glory, please be my
>> guest!
> Thank you for your contribution. I have sent this patch, but I forgot to
> add the Suggested-by: tag
You are invited to send a v2 with the said tag :)
Thanks,
Miquèl
^ permalink raw reply [flat|nested] 23+ messages in thread* Re: [syzbot] [mtd?] divide error in block2mtd_setup2
@ 2026-08-10 12:40 ` Miquel Raynal
0 siblings, 0 replies; 23+ messages in thread
From: Miquel Raynal @ 2026-08-10 12:40 UTC (permalink / raw)
To: Pei Xiao
Cc: Jörn Engel, syzbot, joern, linux-kernel, linux-mtd, richard,
syzkaller-bugs, vigneshr
Hi Pei,
>> Best guess would be this:
>>
>> if ((long)size % erase_size) {
>>
>> Someone passing an erase_size of 0 would indeed trigger an exception.
>> Fix would be something like this:
>>
>> - if ((long)size % erase_size) {
>> + if (!erase_size || (long)size % erase_size) {
>>
>> I haven't touched the code is nearly two decades. If somebody else
>> feels like sending a patch and gathering all the glory, please be my
>> guest!
> Thank you for your contribution. I have sent this patch, but I forgot to
> add the Suggested-by: tag
You are invited to send a v2 with the said tag :)
Thanks,
Miquèl
______________________________________________________
Linux MTD discussion mailing list
http://lists.infradead.org/mailman/listinfo/linux-mtd/
^ permalink raw reply [flat|nested] 23+ messages in thread* Re: [syzbot] [mtd?] divide error in block2mtd_setup2
2026-08-10 12:40 ` Miquel Raynal
@ 2026-08-11 3:02 ` Pei Xiao
-1 siblings, 0 replies; 23+ messages in thread
From: Pei Xiao @ 2026-08-11 3:02 UTC (permalink / raw)
To: Miquel Raynal
Cc: Jörn Engel, syzbot, joern, linux-kernel, linux-mtd, richard,
syzkaller-bugs, vigneshr
在 2026/8/10 20:40, Miquel Raynal 写道:
> Hi Pei,
>
>>> Best guess would be this:
>>>
>>> if ((long)size % erase_size) {
>>>
>>> Someone passing an erase_size of 0 would indeed trigger an exception.
>>> Fix would be something like this:
>>>
>>> - if ((long)size % erase_size) {
>>> + if (!erase_size || (long)size % erase_size) {
>>>
>>> I haven't touched the code is nearly two decades. If somebody else
>>> feels like sending a patch and gathering all the glory, please be my
>>> guest!
>> Thank you for your contribution. I have sent this patch, but I forgot to
>> add the Suggested-by: tag
>
> You are invited to send a v2 with the said tag :)
Thank you for your reply. I am waiting for a reply on whether the cast
on 'long' needs to be removed. Once that is confirmed, I would be happy
to do it. Thank you.
Pei.
>
> Thanks,
> Miquèl
______________________________________________________
Linux MTD discussion mailing list
http://lists.infradead.org/mailman/listinfo/linux-mtd/
^ permalink raw reply [flat|nested] 23+ messages in thread* Re: [syzbot] [mtd?] divide error in block2mtd_setup2
@ 2026-08-11 3:02 ` Pei Xiao
0 siblings, 0 replies; 23+ messages in thread
From: Pei Xiao @ 2026-08-11 3:02 UTC (permalink / raw)
To: Miquel Raynal
Cc: Jörn Engel, syzbot, joern, linux-kernel, linux-mtd, richard,
syzkaller-bugs, vigneshr
在 2026/8/10 20:40, Miquel Raynal 写道:
> Hi Pei,
>
>>> Best guess would be this:
>>>
>>> if ((long)size % erase_size) {
>>>
>>> Someone passing an erase_size of 0 would indeed trigger an exception.
>>> Fix would be something like this:
>>>
>>> - if ((long)size % erase_size) {
>>> + if (!erase_size || (long)size % erase_size) {
>>>
>>> I haven't touched the code is nearly two decades. If somebody else
>>> feels like sending a patch and gathering all the glory, please be my
>>> guest!
>> Thank you for your contribution. I have sent this patch, but I forgot to
>> add the Suggested-by: tag
>
> You are invited to send a v2 with the said tag :)
Thank you for your reply. I am waiting for a reply on whether the cast
on 'long' needs to be removed. Once that is confirmed, I would be happy
to do it. Thank you.
Pei.
>
> Thanks,
> Miquèl
^ permalink raw reply [flat|nested] 23+ messages in thread* Re: [syzbot] [mtd?] divide error in block2mtd_setup2
2026-08-11 3:02 ` Pei Xiao
@ 2026-08-11 18:19 ` Jörn Engel
-1 siblings, 0 replies; 23+ messages in thread
From: Jörn Engel @ 2026-08-11 18:19 UTC (permalink / raw)
To: Pei Xiao
Cc: Miquel Raynal, syzbot, joern, linux-kernel, linux-mtd, richard,
syzkaller-bugs, vigneshr
On Tue, Aug 11, 2026 at 11:02:53AM +0800, Pei Xiao wrote:
> >
> Thank you for your reply. I am waiting for a reply on whether the cast
> on 'long' needs to be removed. Once that is confirmed, I would be happy
> to do it. Thank you.
It doesn't need to be removed, but it should be removed. Any
unnecessary code should be removed in general and unnecessary casts in
particular should.
One of better parts of the C language is that casts are hardly ever
necessary. Which means that any remaining necessary casts should
immediately draw attention of the reader - something tricky and
potentially dangerous is going on here.
But you stop paying attention when things become too common. Which
means that unnecessary casts are not just noise, they actively do harm.
In this particular case, we can simply test whether the cast makes any
difference:
#include <assert.h>
#include <stdio.h>
int main(void)
{
for (int i=0; i<=1<<16; i++) {
for (int k=1; k<=1<<16; k++) {
long long size = (long long)i << 32;
int erase_size = k;
long long a = size % erase_size;
long long b = (long)size % erase_size;
assert(a==b);
}
}
}
Compile with optimizations and the compiler decides to remove the loop.
Unless you suspect a compiler bug, I guess that settles the question. ;)
Jörn
--
Semper ubi sub ubi ubique.
-- latin pun
^ permalink raw reply [flat|nested] 23+ messages in thread* Re: [syzbot] [mtd?] divide error in block2mtd_setup2
@ 2026-08-11 18:19 ` Jörn Engel
0 siblings, 0 replies; 23+ messages in thread
From: Jörn Engel @ 2026-08-11 18:19 UTC (permalink / raw)
To: Pei Xiao
Cc: Miquel Raynal, syzbot, joern, linux-kernel, linux-mtd, richard,
syzkaller-bugs, vigneshr
On Tue, Aug 11, 2026 at 11:02:53AM +0800, Pei Xiao wrote:
> >
> Thank you for your reply. I am waiting for a reply on whether the cast
> on 'long' needs to be removed. Once that is confirmed, I would be happy
> to do it. Thank you.
It doesn't need to be removed, but it should be removed. Any
unnecessary code should be removed in general and unnecessary casts in
particular should.
One of better parts of the C language is that casts are hardly ever
necessary. Which means that any remaining necessary casts should
immediately draw attention of the reader - something tricky and
potentially dangerous is going on here.
But you stop paying attention when things become too common. Which
means that unnecessary casts are not just noise, they actively do harm.
In this particular case, we can simply test whether the cast makes any
difference:
#include <assert.h>
#include <stdio.h>
int main(void)
{
for (int i=0; i<=1<<16; i++) {
for (int k=1; k<=1<<16; k++) {
long long size = (long long)i << 32;
int erase_size = k;
long long a = size % erase_size;
long long b = (long)size % erase_size;
assert(a==b);
}
}
}
Compile with optimizations and the compiler decides to remove the loop.
Unless you suspect a compiler bug, I guess that settles the question. ;)
Jörn
--
Semper ubi sub ubi ubique.
-- latin pun
______________________________________________________
Linux MTD discussion mailing list
http://lists.infradead.org/mailman/listinfo/linux-mtd/
^ permalink raw reply [flat|nested] 23+ messages in thread* Re: [syzbot] [mtd?] divide error in block2mtd_setup2
2026-08-11 18:19 ` Jörn Engel
@ 2026-08-12 1:45 ` Pei Xiao
-1 siblings, 0 replies; 23+ messages in thread
From: Pei Xiao @ 2026-08-12 1:45 UTC (permalink / raw)
To: Jörn Engel
Cc: Miquel Raynal, syzbot, joern, linux-kernel, linux-mtd, richard,
syzkaller-bugs, vigneshr
在 2026/8/12 02:19, Jörn Engel 写道:
> On Tue, Aug 11, 2026 at 11:02:53AM +0800, Pei Xiao wrote:
>>>
>> Thank you for your reply. I am waiting for a reply on whether the cast
>> on 'long' needs to be removed. Once that is confirmed, I would be happy
>> to do it. Thank you.
>
> It doesn't need to be removed, but it should be removed. Any
> unnecessary code should be removed in general and unnecessary casts in
> particular should.
>
> One of better parts of the C language is that casts are hardly ever
> necessary. Which means that any remaining necessary casts should
> immediately draw attention of the reader - something tricky and
> potentially dangerous is going on here.
>
> But you stop paying attention when things become too common. Which
> means that unnecessary casts are not just noise, they actively do harm.
>
>
> In this particular case, we can simply test whether the cast makes any
> difference:
>
> #include <assert.h>
> #include <stdio.h>
>
> int main(void)
> {
> for (int i=0; i<=1<<16; i++) {
> for (int k=1; k<=1<<16; k++) {
> long long size = (long long)i << 32;
> int erase_size = k;
>
> long long a = size % erase_size;
> long long b = (long)size % erase_size;
> assert(a==b);
> }
> }
> }
Great test! You're truly professional, and I've learned a lot. I'll send
the v2 patch. Thank you for your guidance.
Pei.
>
> Compile with optimizations and the compiler decides to remove the loop.
> Unless you suspect a compiler bug, I guess that settles the question. ;)
>
> Jörn
>
> --
> Semper ubi sub ubi ubique.
> -- latin pun
______________________________________________________
Linux MTD discussion mailing list
http://lists.infradead.org/mailman/listinfo/linux-mtd/
^ permalink raw reply [flat|nested] 23+ messages in thread* Re: [syzbot] [mtd?] divide error in block2mtd_setup2
@ 2026-08-12 1:45 ` Pei Xiao
0 siblings, 0 replies; 23+ messages in thread
From: Pei Xiao @ 2026-08-12 1:45 UTC (permalink / raw)
To: Jörn Engel
Cc: Miquel Raynal, syzbot, joern, linux-kernel, linux-mtd, richard,
syzkaller-bugs, vigneshr
在 2026/8/12 02:19, Jörn Engel 写道:
> On Tue, Aug 11, 2026 at 11:02:53AM +0800, Pei Xiao wrote:
>>>
>> Thank you for your reply. I am waiting for a reply on whether the cast
>> on 'long' needs to be removed. Once that is confirmed, I would be happy
>> to do it. Thank you.
>
> It doesn't need to be removed, but it should be removed. Any
> unnecessary code should be removed in general and unnecessary casts in
> particular should.
>
> One of better parts of the C language is that casts are hardly ever
> necessary. Which means that any remaining necessary casts should
> immediately draw attention of the reader - something tricky and
> potentially dangerous is going on here.
>
> But you stop paying attention when things become too common. Which
> means that unnecessary casts are not just noise, they actively do harm.
>
>
> In this particular case, we can simply test whether the cast makes any
> difference:
>
> #include <assert.h>
> #include <stdio.h>
>
> int main(void)
> {
> for (int i=0; i<=1<<16; i++) {
> for (int k=1; k<=1<<16; k++) {
> long long size = (long long)i << 32;
> int erase_size = k;
>
> long long a = size % erase_size;
> long long b = (long)size % erase_size;
> assert(a==b);
> }
> }
> }
Great test! You're truly professional, and I've learned a lot. I'll send
the v2 patch. Thank you for your guidance.
Pei.
>
> Compile with optimizations and the compiler decides to remove the loop.
> Unless you suspect a compiler bug, I guess that settles the question. ;)
>
> Jörn
>
> --
> Semper ubi sub ubi ubique.
> -- latin pun
^ permalink raw reply [flat|nested] 23+ messages in thread* Re: [syzbot] [mtd?] divide error in block2mtd_setup2
2026-08-12 1:45 ` Pei Xiao
@ 2026-08-12 2:51 ` Jörn Engel
-1 siblings, 0 replies; 23+ messages in thread
From: Jörn Engel @ 2026-08-12 2:51 UTC (permalink / raw)
To: Pei Xiao
Cc: Miquel Raynal, syzbot, joern, linux-kernel, linux-mtd, richard,
syzkaller-bugs, vigneshr
On Wed, Aug 12, 2026 at 09:45:44AM +0800, Pei Xiao wrote:
>
> Great test! You're truly professional, and I've learned a lot. I'll send
> the v2 patch. Thank you for your guidance.
The test was actually a failure of sorts. :)
Actual idea was some kind of fuzzing. Up to 32bit, computers can test
every possibility in a few seconds. The number space here is 96bit,
which is a bit much. But we can still test 4B random combinations or
exhaustively test some subset that is equivalent to about 4B
combinations.
While this is not a mathematical proof, a little bit of brute force is
generally quite cheap and catches the vast majority of bugs. In this
case, the compiler refused to even generate a brute force test. So I
guess that gave us something similar to a mathematical proof.
Jörn
--
The rabbit runs faster than the fox, because the rabbit is running for
his life while the fox is only running for his dinner.
-- Aesop
______________________________________________________
Linux MTD discussion mailing list
http://lists.infradead.org/mailman/listinfo/linux-mtd/
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [syzbot] [mtd?] divide error in block2mtd_setup2
@ 2026-08-12 2:51 ` Jörn Engel
0 siblings, 0 replies; 23+ messages in thread
From: Jörn Engel @ 2026-08-12 2:51 UTC (permalink / raw)
To: Pei Xiao
Cc: Miquel Raynal, syzbot, joern, linux-kernel, linux-mtd, richard,
syzkaller-bugs, vigneshr
On Wed, Aug 12, 2026 at 09:45:44AM +0800, Pei Xiao wrote:
>
> Great test! You're truly professional, and I've learned a lot. I'll send
> the v2 patch. Thank you for your guidance.
The test was actually a failure of sorts. :)
Actual idea was some kind of fuzzing. Up to 32bit, computers can test
every possibility in a few seconds. The number space here is 96bit,
which is a bit much. But we can still test 4B random combinations or
exhaustively test some subset that is equivalent to about 4B
combinations.
While this is not a mathematical proof, a little bit of brute force is
generally quite cheap and catches the vast majority of bugs. In this
case, the compiler refused to even generate a brute force test. So I
guess that gave us something similar to a mathematical proof.
Jörn
--
The rabbit runs faster than the fox, because the rabbit is running for
his life while the fox is only running for his dinner.
-- Aesop
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [syzbot] [mtd?] divide error in block2mtd_setup2
2026-08-10 2:03 ` Jörn Engel
@ 2026-08-10 16:27 ` Jörn Engel
-1 siblings, 0 replies; 23+ messages in thread
From: Jörn Engel @ 2026-08-10 16:27 UTC (permalink / raw)
To: syzbot
Cc: linux-kernel, linux-mtd, miquel.raynal, richard, syzkaller-bugs,
vigneshr, Fabian Frederick
On Sun, Aug 09, 2026 at 07:03:22PM -0700, Jörn Engel wrote:
>
> Best guess would be this:
>
> if ((long)size % erase_size) {
While at it, what purpose does the cast to (long) serve?
As far as I can see, it is useless and should be removed. Fabian, do
you remember why it was necessary?
Jörn
--
The real voyage of discovery consists not in seeking new landscapes,
but in having new eyes.
-- Marcel Proust
______________________________________________________
Linux MTD discussion mailing list
http://lists.infradead.org/mailman/listinfo/linux-mtd/
^ permalink raw reply [flat|nested] 23+ messages in thread* Re: [syzbot] [mtd?] divide error in block2mtd_setup2
@ 2026-08-10 16:27 ` Jörn Engel
0 siblings, 0 replies; 23+ messages in thread
From: Jörn Engel @ 2026-08-10 16:27 UTC (permalink / raw)
To: syzbot
Cc: linux-kernel, linux-mtd, miquel.raynal, richard, syzkaller-bugs,
vigneshr, Fabian Frederick
On Sun, Aug 09, 2026 at 07:03:22PM -0700, Jörn Engel wrote:
>
> Best guess would be this:
>
> if ((long)size % erase_size) {
While at it, what purpose does the cast to (long) serve?
As far as I can see, it is useless and should be removed. Fabian, do
you remember why it was necessary?
Jörn
--
The real voyage of discovery consists not in seeking new landscapes,
but in having new eyes.
-- Marcel Proust
^ permalink raw reply [flat|nested] 23+ messages in thread* Re: [syzbot] [mtd?] divide error in block2mtd_setup2
2026-08-10 16:27 ` Jörn Engel
@ 2026-08-11 1:21 ` Pei Xiao
-1 siblings, 0 replies; 23+ messages in thread
From: Pei Xiao @ 2026-08-11 1:21 UTC (permalink / raw)
To: Jörn Engel, syzbot
Cc: linux-kernel, linux-mtd, miquel.raynal, richard, syzkaller-bugs,
vigneshr, Fabian Frederick
在 2026/8/11 00:27, Jörn Engel 写道:
> On Sun, Aug 09, 2026 at 07:03:22PM -0700, Jörn Engel wrote:
>>
>> Best guess would be this:
>>
>> if ((long)size % erase_size) {
>
> While at it, what purpose does the cast to (long) serve?
>
> As far as I can see, it is useless and should be removed. Fabian, do
> you remember why it was necessary?
The type of size is loff_t (i.e., long long, which is always 64-bit).
Casting it to (long)size on a 32-bit system would truncate it to a
32-bit long, so it seems this long cast needs to be removed.
It's been 12 years.. I wonder if the author still remembers.
Pei.
>
> Jörn
>
> --
> The real voyage of discovery consists not in seeking new landscapes,
> but in having new eyes.
> -- Marcel Proust
>
______________________________________________________
Linux MTD discussion mailing list
http://lists.infradead.org/mailman/listinfo/linux-mtd/
^ permalink raw reply [flat|nested] 23+ messages in thread* Re: [syzbot] [mtd?] divide error in block2mtd_setup2
@ 2026-08-11 1:21 ` Pei Xiao
0 siblings, 0 replies; 23+ messages in thread
From: Pei Xiao @ 2026-08-11 1:21 UTC (permalink / raw)
To: Jörn Engel, syzbot
Cc: linux-kernel, linux-mtd, miquel.raynal, richard, syzkaller-bugs,
vigneshr, Fabian Frederick
在 2026/8/11 00:27, Jörn Engel 写道:
> On Sun, Aug 09, 2026 at 07:03:22PM -0700, Jörn Engel wrote:
>>
>> Best guess would be this:
>>
>> if ((long)size % erase_size) {
>
> While at it, what purpose does the cast to (long) serve?
>
> As far as I can see, it is useless and should be removed. Fabian, do
> you remember why it was necessary?
The type of size is loff_t (i.e., long long, which is always 64-bit).
Casting it to (long)size on a 32-bit system would truncate it to a
32-bit long, so it seems this long cast needs to be removed.
It's been 12 years.. I wonder if the author still remembers.
Pei.
>
> Jörn
>
> --
> The real voyage of discovery consists not in seeking new landscapes,
> but in having new eyes.
> -- Marcel Proust
>
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [syzbot] [mtd?] divide error in block2mtd_setup2
2026-08-10 0:34 ` syzbot
@ 2026-08-11 17:15 ` syzbot
-1 siblings, 0 replies; 23+ messages in thread
From: syzbot @ 2026-08-11 17:15 UTC (permalink / raw)
To: fabf, joern, joern, linux-kernel, linux-mtd, miquel.raynal,
richard, stable, syzkaller-bugs, vigneshr, xiaopei01
syzbot has found a reproducer for the following issue on:
HEAD commit: f5bbbfec59b4 Merge tag 'probes-fixes-v7.2-rc7' of git://gi..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=13a31079580000
kernel config: https://syzkaller.appspot.com/x/.config?x=c44651ea7dd2f307
dashboard link: https://syzkaller.appspot.com/bug?extid=b320a4d5f65a61dbbf89
compiler: gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=16b76149580000
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+b320a4d5f65a61dbbf89@syzkaller.appspotmail.com
Oops: divide error: 0000 [#1] SMP KASAN NOPTI
CPU: 0 UID: 0 PID: 6029 Comm: syz-executor518 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:add_device drivers/mtd/devices/block2mtd.c:296 [inline]
RIP: 0010:block2mtd_setup2.isra.0+0x3c8/0xc70 drivers/mtd/devices/block2mtd.c:459
Code: 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 80 3c 02 00 0f 85 2b 08 00 00 48 8b 6d 08 31 ff 48 89 e8 48 c1 e0 09 48 99 <49> f7 ff 48 89 d6 48 89 54 24 10 e8 98 d5 4d fb 48 8b 54 24 10 48
RSP: 0018:ffffc90004ccf9f0 EFLAGS: 00010206
RAX: 0000000000100000 RBX: 1ffff92000999f41 RCX: ffffffff86bc9838
RDX: 0000000000000000 RSI: ffffffff86bc984a RDI: 0000000000000000
RBP: 0000000000000800 R08: 0000000000000005 R09: 000000000000001f
R10: 0000000000000007 R11: 0000000000000000 R12: ffffc90004ccfaa8
R13: 0000000000000000 R14: ffff8880254fe000 R15: 0000000000000000
FS: 000055558148e400(0000) GS:ffff8880d5dec000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000055a8208cda78 CR3: 000000003ad58000 CR4: 0000000000352ef0
Call Trace:
<TASK>
block2mtd_setup+0xbd/0xd0 drivers/mtd/devices/block2mtd.c:476
param_attr_store+0x199/0x300 kernel/params.c:589
module_attr_store+0x58/0x80 kernel/params.c:904
sysfs_kf_write+0xf2/0x150 fs/sysfs/file.c:145
kernfs_fop_write_iter+0x3e0/0x5f0 fs/kernfs/file.c:345
new_sync_write fs/read_write.c:595 [inline]
vfs_write+0x6ac/0x1050 fs/read_write.c:687
ksys_write+0x12a/0x250 fs/read_write.c:739
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x115/0x870 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f0b39a14737
Code: 48 89 fa 4c 89 df e8 98 1d 00 00 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 1a 5b c3 0f 1f 84 00 00 00 00 00 48 8b 44 24 10 0f 05 <5b> c3 0f 1f 80 00 00 00 00 83 e2 39 83 fa 08 75 de e8 23 ff ff ff
RSP: 002b:00007ffdcc22a9a0 EFLAGS: 00000202 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 000055558148e400 RCX: 00007f0b39a14737
RDX: 000000000000000c RSI: 00007ffdcc22aa50 RDI: 0000000000000004
RBP: 0000000000000003 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000202 R12: 00007ffdcc22aa50
R13: 00007ffdcc22aa10 R14: 00007ffdcc22a9f0 R15: 0000000000000002
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:add_device drivers/mtd/devices/block2mtd.c:296 [inline]
RIP: 0010:block2mtd_setup2.isra.0+0x3c8/0xc70 drivers/mtd/devices/block2mtd.c:459
Code: 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 80 3c 02 00 0f 85 2b 08 00 00 48 8b 6d 08 31 ff 48 89 e8 48 c1 e0 09 48 99 <49> f7 ff 48 89 d6 48 89 54 24 10 e8 98 d5 4d fb 48 8b 54 24 10 48
RSP: 0018:ffffc90004ccf9f0 EFLAGS: 00010206
RAX: 0000000000100000 RBX: 1ffff92000999f41 RCX: ffffffff86bc9838
RDX: 0000000000000000 RSI: ffffffff86bc984a RDI: 0000000000000000
RBP: 0000000000000800 R08: 0000000000000005 R09: 000000000000001f
R10: 0000000000000007 R11: 0000000000000000 R12: ffffc90004ccfaa8
R13: 0000000000000000 R14: ffff8880254fe000 R15: 0000000000000000
FS: 000055558148e400(0000) GS:ffff8880d5dec000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000055a8208cda78 CR3: 000000003ad58000 CR4: 0000000000352ef0
----------------
Code disassembly (best guess):
0: 48 b8 00 00 00 00 00 movabs $0xdffffc0000000000,%rax
7: fc ff df
a: 48 89 fa mov %rdi,%rdx
d: 48 c1 ea 03 shr $0x3,%rdx
11: 80 3c 02 00 cmpb $0x0,(%rdx,%rax,1)
15: 0f 85 2b 08 00 00 jne 0x846
1b: 48 8b 6d 08 mov 0x8(%rbp),%rbp
1f: 31 ff xor %edi,%edi
21: 48 89 e8 mov %rbp,%rax
24: 48 c1 e0 09 shl $0x9,%rax
28: 48 99 cqto
* 2a: 49 f7 ff idiv %r15 <-- trapping instruction
2d: 48 89 d6 mov %rdx,%rsi
30: 48 89 54 24 10 mov %rdx,0x10(%rsp)
35: e8 98 d5 4d fb call 0xfb4dd5d2
3a: 48 8b 54 24 10 mov 0x10(%rsp),%rdx
3f: 48 rex.W
---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
______________________________________________________
Linux MTD discussion mailing list
http://lists.infradead.org/mailman/listinfo/linux-mtd/
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [syzbot] [mtd?] divide error in block2mtd_setup2
@ 2026-08-11 17:15 ` syzbot
0 siblings, 0 replies; 23+ messages in thread
From: syzbot @ 2026-08-11 17:15 UTC (permalink / raw)
To: fabf, joern, joern, linux-kernel, linux-mtd, miquel.raynal,
richard, stable, syzkaller-bugs, vigneshr, xiaopei01
syzbot has found a reproducer for the following issue on:
HEAD commit: f5bbbfec59b4 Merge tag 'probes-fixes-v7.2-rc7' of git://gi..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=13a31079580000
kernel config: https://syzkaller.appspot.com/x/.config?x=c44651ea7dd2f307
dashboard link: https://syzkaller.appspot.com/bug?extid=b320a4d5f65a61dbbf89
compiler: gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=16b76149580000
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+b320a4d5f65a61dbbf89@syzkaller.appspotmail.com
Oops: divide error: 0000 [#1] SMP KASAN NOPTI
CPU: 0 UID: 0 PID: 6029 Comm: syz-executor518 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:add_device drivers/mtd/devices/block2mtd.c:296 [inline]
RIP: 0010:block2mtd_setup2.isra.0+0x3c8/0xc70 drivers/mtd/devices/block2mtd.c:459
Code: 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 80 3c 02 00 0f 85 2b 08 00 00 48 8b 6d 08 31 ff 48 89 e8 48 c1 e0 09 48 99 <49> f7 ff 48 89 d6 48 89 54 24 10 e8 98 d5 4d fb 48 8b 54 24 10 48
RSP: 0018:ffffc90004ccf9f0 EFLAGS: 00010206
RAX: 0000000000100000 RBX: 1ffff92000999f41 RCX: ffffffff86bc9838
RDX: 0000000000000000 RSI: ffffffff86bc984a RDI: 0000000000000000
RBP: 0000000000000800 R08: 0000000000000005 R09: 000000000000001f
R10: 0000000000000007 R11: 0000000000000000 R12: ffffc90004ccfaa8
R13: 0000000000000000 R14: ffff8880254fe000 R15: 0000000000000000
FS: 000055558148e400(0000) GS:ffff8880d5dec000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000055a8208cda78 CR3: 000000003ad58000 CR4: 0000000000352ef0
Call Trace:
<TASK>
block2mtd_setup+0xbd/0xd0 drivers/mtd/devices/block2mtd.c:476
param_attr_store+0x199/0x300 kernel/params.c:589
module_attr_store+0x58/0x80 kernel/params.c:904
sysfs_kf_write+0xf2/0x150 fs/sysfs/file.c:145
kernfs_fop_write_iter+0x3e0/0x5f0 fs/kernfs/file.c:345
new_sync_write fs/read_write.c:595 [inline]
vfs_write+0x6ac/0x1050 fs/read_write.c:687
ksys_write+0x12a/0x250 fs/read_write.c:739
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x115/0x870 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f0b39a14737
Code: 48 89 fa 4c 89 df e8 98 1d 00 00 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 1a 5b c3 0f 1f 84 00 00 00 00 00 48 8b 44 24 10 0f 05 <5b> c3 0f 1f 80 00 00 00 00 83 e2 39 83 fa 08 75 de e8 23 ff ff ff
RSP: 002b:00007ffdcc22a9a0 EFLAGS: 00000202 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 000055558148e400 RCX: 00007f0b39a14737
RDX: 000000000000000c RSI: 00007ffdcc22aa50 RDI: 0000000000000004
RBP: 0000000000000003 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000202 R12: 00007ffdcc22aa50
R13: 00007ffdcc22aa10 R14: 00007ffdcc22a9f0 R15: 0000000000000002
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:add_device drivers/mtd/devices/block2mtd.c:296 [inline]
RIP: 0010:block2mtd_setup2.isra.0+0x3c8/0xc70 drivers/mtd/devices/block2mtd.c:459
Code: 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 80 3c 02 00 0f 85 2b 08 00 00 48 8b 6d 08 31 ff 48 89 e8 48 c1 e0 09 48 99 <49> f7 ff 48 89 d6 48 89 54 24 10 e8 98 d5 4d fb 48 8b 54 24 10 48
RSP: 0018:ffffc90004ccf9f0 EFLAGS: 00010206
RAX: 0000000000100000 RBX: 1ffff92000999f41 RCX: ffffffff86bc9838
RDX: 0000000000000000 RSI: ffffffff86bc984a RDI: 0000000000000000
RBP: 0000000000000800 R08: 0000000000000005 R09: 000000000000001f
R10: 0000000000000007 R11: 0000000000000000 R12: ffffc90004ccfaa8
R13: 0000000000000000 R14: ffff8880254fe000 R15: 0000000000000000
FS: 000055558148e400(0000) GS:ffff8880d5dec000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000055a8208cda78 CR3: 000000003ad58000 CR4: 0000000000352ef0
----------------
Code disassembly (best guess):
0: 48 b8 00 00 00 00 00 movabs $0xdffffc0000000000,%rax
7: fc ff df
a: 48 89 fa mov %rdi,%rdx
d: 48 c1 ea 03 shr $0x3,%rdx
11: 80 3c 02 00 cmpb $0x0,(%rdx,%rax,1)
15: 0f 85 2b 08 00 00 jne 0x846
1b: 48 8b 6d 08 mov 0x8(%rbp),%rbp
1f: 31 ff xor %edi,%edi
21: 48 89 e8 mov %rbp,%rax
24: 48 c1 e0 09 shl $0x9,%rax
28: 48 99 cqto
* 2a: 49 f7 ff idiv %r15 <-- trapping instruction
2d: 48 89 d6 mov %rdx,%rsi
30: 48 89 54 24 10 mov %rdx,0x10(%rsp)
35: e8 98 d5 4d fb call 0xfb4dd5d2
3a: 48 8b 54 24 10 mov 0x10(%rsp),%rdx
3f: 48 rex.W
---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
^ permalink raw reply [flat|nested] 23+ messages in thread
end of thread, other threads:[~2026-08-12 2:51 UTC | newest]
Thread overview: 23+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
[not found] <48230456575d27aa83ce8640de8fc07cc62e8efb.1786498693.git.xiaopei01@kylinos.cn>
2026-08-12 2:05 ` [syzbot] [mtd?] divide error in block2mtd_setup2 syzbot
2026-08-10 0:34 syzbot
2026-08-10 0:34 ` syzbot
2026-08-10 2:03 ` Jörn Engel
2026-08-10 2:03 ` Jörn Engel
2026-08-10 9:17 ` Pei Xiao
2026-08-10 9:17 ` Pei Xiao
2026-08-10 12:40 ` Miquel Raynal
2026-08-10 12:40 ` Miquel Raynal
2026-08-11 3:02 ` Pei Xiao
2026-08-11 3:02 ` Pei Xiao
2026-08-11 18:19 ` Jörn Engel
2026-08-11 18:19 ` Jörn Engel
2026-08-12 1:45 ` Pei Xiao
2026-08-12 1:45 ` Pei Xiao
2026-08-12 2:51 ` Jörn Engel
2026-08-12 2:51 ` Jörn Engel
2026-08-10 16:27 ` Jörn Engel
2026-08-10 16:27 ` Jörn Engel
2026-08-11 1:21 ` Pei Xiao
2026-08-11 1:21 ` Pei Xiao
2026-08-11 17:15 ` syzbot
2026-08-11 17:15 ` syzbot
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.