From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail-io0-f194.google.com ([209.85.223.194]:43827 "EHLO mail-io0-f194.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752552AbdLLU4c (ORCPT ); Tue, 12 Dec 2017 15:56:32 -0500 Date: Tue, 12 Dec 2017 12:56:29 -0800 From: Eric Biggers To: syzbot Cc: linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com, viro@zeniv.linux.org.uk Subject: Re: WARNING in mark_buffer_dirty Message-ID: <20171212205629.GB185376@gmail.com> References: <001a114740a0b5fa37055e14cf3b@google.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <001a114740a0b5fa37055e14cf3b@google.com> Sender: linux-fsdevel-owner@vger.kernel.org List-ID: On Wed, Nov 15, 2017 at 11:46:00PM -0800, syzbot wrote: > WARNING: CPU: 3 PID: 13366 at fs/buffer.c:1108 > mark_buffer_dirty+0x48b/0x5d0 fs/buffer.c:1108 > Kernel panic - not syncing: panic_on_warn set ... > > hub 1-0:1.0: activate --> -22 > CPU: 3 PID: 13366 Comm: syzkaller183798 Not tainted > 4.14.0-rc8-next-20171109+ #11 > Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Bochs 01/01/2011 > Call Trace: > __dump_stack lib/dump_stack.c:17 [inline] > dump_stack+0x194/0x257 lib/dump_stack.c:53 > panic+0x1e4/0x41c kernel/panic.c:183 > __warn+0x1c4/0x1e0 kernel/panic.c:546 > report_bug+0x211/0x2d0 lib/bug.c:184 > fixup_bug+0x40/0x90 arch/x86/kernel/traps.c:176 > do_trap_no_signal arch/x86/kernel/traps.c:210 [inline] > do_trap+0x260/0x390 arch/x86/kernel/traps.c:259 > do_error_trap+0x120/0x390 arch/x86/kernel/traps.c:296 > hub 1-0:1.0: activate --> -22 > do_invalid_op+0x1b/0x20 arch/x86/kernel/traps.c:309 > invalid_op+0x18/0x20 arch/x86/entry/entry_64.S:926 > RIP: 0010:mark_buffer_dirty+0x48b/0x5d0 fs/buffer.c:1108 > RSP: 0018:ffff88007ab27188 EFLAGS: 00010293 > RAX: ffff880079fa6500 RBX: ffff88007a727d20 RCX: ffffffff81bbfe5b > RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff88007a727d20 > RBP: ffff88007ab27298 R08: 0000000000000200 R09: ffffea0001e53580 > R10: 0000000000000040 R11: ffffed000f29ac3f R12: 1ffff1000f564e32 > R13: dffffc0000000000 R14: ffff88007ab27270 R15: 0000000000000000 > hub 1-0:1.0: activate --> -22 > __block_commit_write.isra.32+0x13b/0x2f0 fs/buffer.c:2060 > block_write_end+0x99/0x1c0 fs/buffer.c:2138 > blkdev_write_end+0xc3/0x280 fs/block_dev.c:593 > generic_perform_write+0x3a4/0x600 mm/filemap.c:3149 > hub 1-0:1.0: activate --> -22 > __generic_file_write_iter+0x366/0x5b0 mm/filemap.c:3263 > blkdev_write_iter+0x207/0x3e0 fs/block_dev.c:1893 > call_write_iter include/linux/fs.h:1772 [inline] > do_iter_readv_writev+0x531/0x7f0 fs/read_write.c:653 > do_iter_write+0x15a/0x540 fs/read_write.c:932 > vfs_iter_write+0x77/0xb0 fs/read_write.c:945 > iter_file_splice_write+0x7db/0xf30 fs/splice.c:749 > do_splice_from fs/splice.c:851 [inline] > direct_splice_actor+0x125/0x180 fs/splice.c:1018 > splice_direct_to_actor+0x2c1/0x820 fs/splice.c:973 > hub 1-0:1.0: activate --> -22 > do_splice_direct+0x2a7/0x3d0 fs/splice.c:1061 > do_sendfile+0x5d5/0xe90 fs/read_write.c:1413 > SYSC_sendfile64 fs/read_write.c:1468 [inline] > SyS_sendfile64+0xbd/0x160 fs/read_write.c:1460 > entry_SYSCALL_64_fastpath+0x1f/0x96 Still happens on latest Linus tree as of today, though it takes a little while (~30 seconds) for the C reproducer to trigger the WARN.