From: syzbot <syzbot+ea047a32630b1f47da67@syzkaller.appspotmail.com>
To: linux-kernel@vger.kernel.org, linux-media@vger.kernel.org,
mchehab@kernel.org, syzkaller-bugs@googlegroups.com
Subject: Re: [syzbot] [media?] WARNING in as102_stream_ctrl
Date: Sun, 16 Aug 2026 20:34:24 -0700 [thread overview]
Message-ID: <6a828140.10853dc7.22f513.0018.GAE@google.com> (raw)
In-Reply-To: <6a7135a9.d35e88fd.de8b.0004.GAE@google.com>
syzbot has found a reproducer for the following issue on:
HEAD commit: dcb68831eac7 Merge tag 'block-7.2-20260815' of git://git.k..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=15a356c6580000
kernel config: https://syzkaller.appspot.com/x/.config?x=2ca5f2f2c4197664
dashboard link: https://syzkaller.appspot.com/bug?extid=ea047a32630b1f47da67
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
userspace arch: i386
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=144afa79580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=128fc679580000
Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/ce324780f4da/disk-dcb68831.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/54b24f8a899c/vmlinux-dcb68831.xz
kernel image: https://storage.googleapis.com/syzbot-assets/733dcdb8d8dd/bzImage-dcb68831.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+ea047a32630b1f47da67@syzkaller.appspotmail.com
------------[ cut here ]------------
DEBUG_LOCKS_WARN_ON(lock->magic != lock)
WARNING: kernel/locking/mutex.c:625 at __mutex_lock_common kernel/locking/mutex.c:625 [inline], CPU#1: syz.2.149/6139
WARNING: kernel/locking/mutex.c:625 at __mutex_lock+0x12d8/0x1550 kernel/locking/mutex.c:821, CPU#1: syz.2.149/6139
Modules linked in:
CPU: 1 UID: 0 PID: 6139 Comm: syz.2.149 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
RIP: 0010:__mutex_lock_common kernel/locking/mutex.c:625 [inline]
RIP: 0010:__mutex_lock+0x12df/0x1550 kernel/locking/mutex.c:821
Code: c2 57 90 48 c1 e8 03 0f b6 04 18 84 c0 0f 85 47 02 00 00 83 3d 45 d0 83 04 00 75 13 48 8d 3d c8 1f 87 04 48 c7 c6 40 f7 ec 8b <67> 48 0f b9 3a 90 e9 75 ee ff ff 90 0f 0b 90 e9 48 f2 ff ff 90 0f
RSP: 0000:ffffc9000381f5c0 EFLAGS: 00010246
RAX: 0000000000000000 RBX: dffffc0000000000 RCX: ffff8880321a0000
RDX: 0000000000000000 RSI: ffffffff8becf740 RDI: ffffffff905b11d0
RBP: ffffc9000381f758 R08: ffffffff9057c243 R09: 1ffffffff20af848
R10: dffffc0000000000 R11: fffffbfff20af849 R12: ffff88803476a010
R13: 0000000000000000 R14: 1ffff92000703ecc R15: 0000000000000000
FS: 0000000000000000(0000) GS:ffff888125049000(0063) knlGS:0000000057754480
CS: 0010 DS: 002b ES: 002b CR0: 0000000080050033
CR2: 00000000f741be8c CR3: 000000007d7a2000 CR4: 00000000003526f0
Call Trace:
<TASK>
as102_stream_ctrl+0x27/0xc0 drivers/media/usb/as102/as102_drv.c:259
dvb_frontend_open+0x7e2/0x1410 drivers/media/dvb-core/dvb_frontend.c:2825
dvb_device_open+0x24f/0x340 drivers/media/dvb-core/dvbdev.c:109
chrdev_open+0x4d9/0x600 fs/char_dev.c:411
do_dentry_open+0x816/0x1380 fs/open.c:947
vfs_open+0x3b/0x340 fs/open.c:1052
do_open fs/namei.c:4700 [inline]
path_openat+0x2e44/0x3830 fs/namei.c:4863
do_file_open+0x23e/0x4a0 fs/namei.c:4892
do_sys_openat2+0x115/0x200 fs/open.c:1368
do_sys_open fs/open.c:1374 [inline]
__do_compat_sys_openat fs/open.c:1436 [inline]
__se_compat_sys_openat fs/open.c:1434 [inline]
__ia32_compat_sys_openat+0x131/0x160 fs/open.c:1434
do_syscall_32_irqs_on arch/x86/entry/syscall_32.c:83 [inline]
do_int80_emulation+0x19a/0x550 arch/x86/entry/syscall_32.c:172
asm_int80_emulation+0x1a/0x20 arch/x86/include/asm/idtentry.h:598
RIP: 0023:0xf71374eb
Code: 57 56 53 8b 44 24 14 f6 00 08 75 23 8b 44 24 18 8b 5c 24 1c 8b 4c 24 20 8b 54 24 24 8b 74 24 28 8b 7c 24 2c 8b 6c 24 30 cd 80 <5b> 5e 5f 5d c3 5b 5e 5f 5d e9 f7 a1 ff ff 66 90 66 90 66 90 90 53
RSP: 002b:00000000ff9eefcc EFLAGS: 00000246 ORIG_RAX: 0000000000000127
RAX: ffffffffffffffda RBX: 00000000ffffff9c RCX: 00000000ff9ef090
RDX: 0000000000000802 RSI: 0000000000000000 RDI: 0000000000000000
RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000206 R12: 0000000000000000
R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000
</TASK>
----------------
Code disassembly (best guess):
0: c2 57 90 ret $0x9057
3: 48 c1 e8 03 shr $0x3,%rax
7: 0f b6 04 18 movzbl (%rax,%rbx,1),%eax
b: 84 c0 test %al,%al
d: 0f 85 47 02 00 00 jne 0x25a
13: 83 3d 45 d0 83 04 00 cmpl $0x0,0x483d045(%rip) # 0x483d05f
1a: 75 13 jne 0x2f
1c: 48 8d 3d c8 1f 87 04 lea 0x4871fc8(%rip),%rdi # 0x4871feb
23: 48 c7 c6 40 f7 ec 8b mov $0xffffffff8becf740,%rsi
* 2a: 67 48 0f b9 3a ud1 (%edx),%rdi <-- trapping instruction
2f: 90 nop
30: e9 75 ee ff ff jmp 0xffffeeaa
35: 90 nop
36: 0f 0b ud2
38: 90 nop
39: e9 48 f2 ff ff jmp 0xfffff286
3e: 90 nop
3f: 0f .byte 0xf
---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
prev parent reply other threads:[~2026-08-17 3:34 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-04 0:43 [syzbot] [media?] WARNING in as102_stream_ctrl syzbot
2026-08-11 5:42 ` syzbot
2026-08-17 3:34 ` syzbot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=6a828140.10853dc7.22f513.0018.GAE@google.com \
--to=syzbot+ea047a32630b1f47da67@syzkaller.appspotmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-media@vger.kernel.org \
--cc=mchehab@kernel.org \
--cc=syzkaller-bugs@googlegroups.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.