From: Oscar Salvador <osalvador@suse.de>
To: syzbot <syzbot+f525fd79634858f478e7@syzkaller.appspotmail.com>
Cc: akpm@linux-foundation.org, linux-kernel@vger.kernel.org,
linux-mm@kvack.org, muchun.song@linux.dev,
syzkaller-bugs@googlegroups.com
Subject: Re: [syzbot] [mm?] kernel BUG in resv_map_release (3)
Date: Tue, 12 Nov 2024 13:23:46 +0100 [thread overview]
Message-ID: <ZzNI0ikhneaXRCgY@localhost.localdomain> (raw)
In-Reply-To: <6732e4aa.050a0220.5088e.0007.GAE@google.com>
On Mon, Nov 11, 2024 at 09:16:26PM -0800, syzbot wrote:
> Hello,
...
> ------------[ cut here ]------------
> kernel BUG at mm/hugetlb.c:1131!
> Oops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN NOPTI
> CPU: 0 UID: 0 PID: 16399 Comm: syz-executor416 Not tainted 6.12.0-rc6-syzkaller-00169-g906bd684e4b1 #0
> Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014
> RIP: 0010:resv_map_release mm/hugetlb.c:1131 [inline]
> RIP: 0010:resv_map_release+0x1f3/0x290 mm/hugetlb.c:1116
> Code: a4 ff 48 85 db 75 1d e8 ab 1b a4 ff 48 8b 7c 24 08 48 83 c4 18 5b 5d 41 5c 41 5d 41 5e 41 5f e9 e3 ea fa ff e8 8e 1b a4 ff 90 <0f> 0b 4c 89 ef e8 83 a6 05 00 e9 3d ff ff ff 48 89 ef e8 86 a5 05
> RSP: 0018:ffffc9002634f900 EFLAGS: 00010293
> RAX: 0000000000000000 RBX: 0000000000000001 RCX: ffffffff81e95f9b
> RDX: ffff888020d6c880 RSI: ffffffff81e95fc2 RDI: 0000000000000007
> RBP: ffff88802b289860 R08: 0000000000000007 R09: 0000000000000000
> R10: 0000000000000001 R11: 0000000000000000 R12: ffff88802b289860
> R13: ffff88802b289860 R14: ffff888033f4ed88 R15: dead000000000100
> FS: 0000000000000000(0000) GS:ffff88806a600000(0000) knlGS:0000000000000000
> CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
> CR2: 00007fc9bfa142b8 CR3: 000000000df7c000 CR4: 0000000000352ef0
> DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
> DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
> Call Trace:
> <TASK>
> kref_put include/linux/kref.h:65 [inline]
> hugetlb_vm_op_close+0x4a7/0x5b0 mm/hugetlb.c:5075
> remove_vma+0xa8/0x1a0 mm/vma.c:330
> exit_mmap+0x4e0/0xb30 mm/mmap.c:1937
> __mmput+0x12a/0x480 kernel/fork.c:1348
> mmput+0x62/0x70 kernel/fork.c:1370
> exit_mm kernel/exit.c:571 [inline]
> do_exit+0x9bf/0x2d70 kernel/exit.c:926
> do_group_exit+0xd3/0x2a0 kernel/exit.c:1088
> get_signal+0x25fb/0x2770 kernel/signal.c:2917
> arch_do_signal_or_restart+0x90/0x7e0 arch/x86/kernel/signal.c:337
> exit_to_user_mode_loop kernel/entry/common.c:111 [inline]
> exit_to_user_mode_prepare include/linux/entry-common.h:328 [inline]
> __syscall_exit_to_user_mode_work kernel/entry/common.c:207 [inline]
> syscall_exit_to_user_mode+0x150/0x2a0 kernel/entry/common.c:218
> do_syscall_64+0xda/0x250 arch/x86/entry/common.c:89
> entry_SYSCALL_64_after_hwframe+0x77/0x7f
> RIP: 0033:0x7fc9bf9be159
> Code: Unable to access opcode bytes at 0x7fc9bf9be12f.
> RSP: 002b:00007fc9bf957178 EFLAGS: 00000246 ORIG_RAX: 00000000000000ca
> RAX: fffffffffffffe00 RBX: 00007fc9bfa48338 RCX: 00007fc9bf9be159
> RDX: 0000000000000000 RSI: 0000000000000080 RDI: 00007fc9bfa48338
> RBP: 00007fc9bfa48330 R08: 00007fc9bf9576c0 R09: 00007fc9bf9576c0
> R10: 0000000000000000 R11: 0000000000000246 R12: 00007fc9bfa4833c
> R13: 000000000000000b R14: 00007ffda7c51e30 R15: 00007ffda7c51f18
> </TASK>
> Modules linked in:
> ---[ end trace 0000000000000000 ]---
> RIP: 0010:resv_map_release mm/hugetlb.c:1131 [inline]
> RIP: 0010:resv_map_release+0x1f3/0x290 mm/hugetlb.c:1116
> Code: a4 ff 48 85 db 75 1d e8 ab 1b a4 ff 48 8b 7c 24 08 48 83 c4 18 5b 5d 41 5c 41 5d 41 5e 41 5f e9 e3 ea fa ff e8 8e 1b a4 ff 90 <0f> 0b 4c 89 ef e8 83 a6 05 00 e9 3d ff ff ff 48 89 ef e8 86 a5 05
> RSP: 0018:ffffc9002634f900 EFLAGS: 00010293
> RAX: 0000000000000000 RBX: 0000000000000001 RCX: ffffffff81e95f9b
> RDX: ffff888020d6c880 RSI: ffffffff81e95fc2 RDI: 0000000000000007
> RBP: ffff88802b289860 R08: 0000000000000007 R09: 0000000000000000
> R10: 0000000000000001 R11: 0000000000000000 R12: ffff88802b289860
> R13: ffff88802b289860 R14: ffff888033f4ed88 R15: dead000000000100
> FS: 0000000000000000(0000) GS:ffff88806a700000(0000) knlGS:0000000000000000
> CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
> CR2: 00007ffda7c52014 CR3: 00000000325ae000 CR4: 0000000000352ef0
> DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
> DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
I can reproduce it locally.
I am having a look right now.
--
Oscar Salvador
SUSE Labs
prev parent reply other threads:[~2024-11-12 12:23 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-11-12 5:16 [syzbot] [mm?] kernel BUG in resv_map_release (3) syzbot
2024-11-12 12:23 ` Oscar Salvador [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ZzNI0ikhneaXRCgY@localhost.localdomain \
--to=osalvador@suse.de \
--cc=akpm@linux-foundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=muchun.song@linux.dev \
--cc=syzbot+f525fd79634858f478e7@syzkaller.appspotmail.com \
--cc=syzkaller-bugs@googlegroups.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.