All of lore.kernel.org
 help / color / mirror / Atom feed
From: syzbot <syzbot+891c7b195b408052e519@syzkaller.appspotmail.com>
To: cassel@kernel.org, dlemoal@kernel.org, linux-ide@vger.kernel.org,
	 linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com
Subject: Re: [syzbot] [ide?] Internal error in ata_sff_freeze
Date: Fri, 21 Aug 2026 14:02:46 -0700	[thread overview]
Message-ID: <6a88bcf6.dbb3a75c.13dd47.001f.GAE@google.com> (raw)
In-Reply-To: <6a82bc54.10853dc7.22f513.001b.GAE@google.com>

syzbot has found a reproducer for the following issue on:

HEAD commit:    818bebeb63dd drm/xe: Don't hand out the flat CCS storage a..
git tree:       https://kernel.googlesource.com/pub/scm/linux/kernel/git/torvalds/linux master
console output: https://syzkaller.appspot.com/x/log.txt?x=139f8415580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=c2050ae6a504f163
dashboard link: https://syzkaller.appspot.com/bug?extid=891c7b195b408052e519
compiler:       aarch64-linux-gnu-gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
userspace arch: arm64
syz repro:      https://syzkaller.appspot.com/x/repro.syz?x=10021549580000

Downloadable assets:
disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/fa3fbcfdac58/non_bootable_disk-818bebeb.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/6059523242a9/vmlinux-818bebeb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/b5c6a1cf5025/Image-818bebeb.gz.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+891c7b195b408052e519@syzkaller.appspotmail.com

EXT4-fs (vda): shut down requested (2)
Aborting journal on device vda-8.
Internal error: synchronous external abort: 0000000096000050 [#1]  SMP
Modules linked in:
CPU: 1 UID: 0 PID: 3667 Comm: syz.2.17 Tainted: G   M                syzkaller #0 PREEMPT 
Tainted: [M]=MACHINE_CHECK
Hardware name: linux,dummy-virt (DT)
pstate: 414020c9 (nZcv daIF +PAN -UAO -TCO +DIT -SSBS BTYPE=--)
pc : __raw_writeb arch/arm64/include/asm/io.h:29 [inline]
pc : writeb include/asm-generic/io.h:265 [inline]
pc : iowrite8 include/asm-generic/io.h:924 [inline]
pc : ata_sff_set_devctl drivers/ata/libata-sff.c:233 [inline]
pc : ata_sff_freeze+0x7c/0x90 drivers/ata/libata-sff.c:1616
lr : __ata_port_freeze drivers/ata/libata-eh.c:1124 [inline]
lr : ata_eh_freeze_port+0x34/0x5c drivers/ata/libata-eh.c:1167
sp : ffff800089dab960
x29: ffff800089dab960 x28: f2f00000061cb300 x27: 0000000000000000
x26: 0000000000000001 x25: ffff800081f4bcc0 x24: ffff80008279aa48
x23: 0000000000000000 x22: 0000000000000000 x21: f0f0000013e58000
x20: 0000000000000000 x19: f0f0000013e58000 x18: 00000000ffffffff
x17: 0000000000000000 x16: 0000000000000000 x15: f0f0000013e5a3f6
x14: 0000000000000000 x13: 0000000000067000 x12: 0000000000004308
x11: fff000000314a808 x10: ffff800082ea0000 x9 : 0000000000000000
x8 : fbf0000003ff2000 x7 : ffffc1ffc00ffc40 x6 : ffffc1ffc00ffc40
x5 : 0000100000000000 x4 : 01ffdc0000000000 x3 : ffff800082d46be8
x2 : 0000000000000000 x1 : 000000000000000a x0 : ffff800083f55002
Call trace:
 writeb include/asm-generic/io.h:264 [inline] (P)
 iowrite8 include/asm-generic/io.h:924 [inline] (P)
 ata_sff_set_devctl drivers/ata/libata-sff.c:233 [inline] (P)
 ata_sff_freeze+0x7c/0x90 drivers/ata/libata-sff.c:1616 (P)
 __ata_port_freeze drivers/ata/libata-eh.c:1124 [inline]
 ata_eh_freeze_port+0x34/0x5c drivers/ata/libata-eh.c:1167
 ata_host_start+0x13c/0x228 drivers/ata/libata-core.c:6110
 ata_pci_sff_activate_host+0x50/0x340 drivers/ata/libata-sff.c:2285
 ata_pci_init_one+0x19c/0x1d4 drivers/ata/libata-sff.c:2412
 ata_pci_bmdma_init_one+0x14/0x20 drivers/ata/libata-sff.c:3180
 ata_generic_init_one+0xc4/0x1ac drivers/ata/ata_generic.c:209
 local_pci_probe+0x40/0xa8 drivers/pci/pci-driver.c:332
 pci_call_probe drivers/pci/pci-driver.c:394 [inline]
 __pci_device_probe drivers/pci/pci-driver.c:455 [inline]
 pci_device_probe+0xd8/0x288 drivers/pci/pci-driver.c:489
 call_driver_probe drivers/base/dd.c:628 [inline]
 really_probe+0xbc/0x2bc drivers/base/dd.c:706
 __driver_probe_device+0x11c/0x184 drivers/base/dd.c:868
 device_driver_attach+0x48/0xac drivers/base/dd.c:1203
 bind_store+0x7c/0xd8 drivers/base/bus.c:267
 drv_attr_store+0x24/0x40 drivers/base/bus.c:125
 sysfs_kf_write+0x7c/0x98 fs/sysfs/file.c:145
 kernfs_fop_write_iter+0x138/0x200 fs/kernfs/file.c:345
 new_sync_write fs/read_write.c:595 [inline]
 vfs_write+0x244/0x36c fs/read_write.c:687
 ksys_write+0x70/0x108 fs/read_write.c:739
 __do_sys_write fs/read_write.c:750 [inline]
 __se_sys_write fs/read_write.c:747 [inline]
 __arm64_sys_write+0x18/0x24 fs/read_write.c:747
 __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]
 invoke_syscall+0x54/0x10c arch/arm64/kernel/syscall.c:49
 el0_svc_common.constprop.0+0x40/0xe0 arch/arm64/kernel/syscall.c:121
 do_el0_svc+0x1c/0x34 arch/arm64/kernel/syscall.c:140
 el0_svc+0x38/0x1fc arch/arm64/kernel/entry-common.c:758
 el0t_64_sync_handler+0xa0/0xe4 arch/arm64/kernel/entry-common.c:777
 el0t_64_sync+0x1a4/0x1a8 arch/arm64/kernel/entry.S:590
Code: d65f03c0 f9404800 b4fffe60 d50332bf (39000001) 
---[ end trace 0000000000000000 ]---
----------------
Code disassembly (best guess):
   0:	d65f03c0 	ret
   4:	f9404800 	ldr	x0, [x0, #144]
   8:	b4fffe60 	cbz	x0, 0xffffffffffffffd4
   c:	d50332bf 	dmb	oshst
* 10:	39000001 	strb	w1, [x0] <-- trapping instruction


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

      reply	other threads:[~2026-08-21 21:02 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-17  7:46 [syzbot] [ide?] Internal error in ata_sff_freeze syzbot
2026-08-21 21:02 ` syzbot [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=6a88bcf6.dbb3a75c.13dd47.001f.GAE@google.com \
    --to=syzbot+891c7b195b408052e519@syzkaller.appspotmail.com \
    --cc=cassel@kernel.org \
    --cc=dlemoal@kernel.org \
    --cc=linux-ide@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=syzkaller-bugs@googlegroups.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.