* Re: [syzbot] [input?] [usb?] WARNING in cm109_input_ev/usb_submit_urb (2)
[not found] <20260727204430.583f59db@systembl0wer>
@ 2026-07-27 19:47 ` syzbot
0 siblings, 0 replies; 2+ messages in thread
From: syzbot @ 2026-07-27 19:47 UTC (permalink / raw)
To: joshua.crofts1, linux-kernel, syzkaller-bugs
Hello,
syzbot tried to test the proposed patch but the build/boot failed:
PCI/PCI transfers
[ 5.444186][ T1] PCI: CLS 0 bytes, default 64
[ 5.444816][ T1] PCI-DMA: Using software bounce buffering for IO (SWIOTLB)
[ 5.444832][ T1] software IO TLB: mapped [mem 0x00000000b4600000-0x00000000b8600000] (64MB)
[ 5.456557][ T1] ACPI: bus type thunderbolt registered
[ 5.469792][ T1] RAPL PMU: API unit is 2^-32 Joules, 0 fixed counters, 10737418240 ms ovfl timer
[ 5.493158][ T69] kworker/u8:4 (69) used greatest stack depth: 28264 bytes left
[ 5.495766][ T70] kworker/u8:1 (70) used greatest stack depth: 27600 bytes left
[ 5.529581][ T1] kvm_amd: CPU 1 isn't AMD or Hygon
[ 5.529617][ T1] clocksource: tsc: mask: 0xffffffffffffffff max_cycles: 0x1fb63109b96, max_idle_ns: 440795265316 ns
[ 5.530308][ T1] clocksource: Switched to clocksource tsc
[ 5.548832][ T73] kworker/u8:2 (73) used greatest stack depth: 27048 bytes left
[ 5.627675][ T1] Initialise system trusted keyrings
[ 5.631386][ T1] workingset: timestamp_bits=40 (anon: 35) max_order=21 bucket_order=0 (anon: 0)
[ 5.652577][ T1] DLM installed
[ 5.663401][ T1] squashfs: version 4.0 (2009/01/31) Phillip Lougher
[ 5.683324][ T1] NFS: Registering the id_resolver key type
[ 5.683512][ T1] Key type id_resolver registered
[ 5.683527][ T1] Key type id_legacy registered
[ 5.683912][ T1] nfs4filelayout_init: NFSv4 File Layout Driver Registering...
[ 5.684146][ T1] nfs4flexfilelayout_init: NFSv4 Flexfile Layout Driver Registering...
[ 5.705015][ T1] smbdirect: subsystem loading...
[ 5.722695][ T1] smbdirect: subsystem loaded
[ 5.755508][ T1] Key type cifs.spnego registered
[ 5.755795][ T1] Key type cifs.idmap registered
[ 5.762170][ T1] ntfs3: Enabled Linux POSIX ACLs support
[ 5.762181][ T1] ntfs3: Read-only LZX/Xpress compression included
[ 5.762554][ T1] jffs2: version 2.2. (NAND) (SUMMARY) © 2001-2006 Red Hat, Inc.
[ 5.785507][ T1] romfs: ROMFS MTD (C) 2007 Red Hat, Inc.
[ 5.785733][ T1] QNX4 filesystem 0.2.3 registered.
[ 5.785852][ T1] qnx6: QNX6 filesystem 1.0.0 registered.
[ 5.787232][ T1] fuse: init (API version 7.45)
[ 5.794544][ T1] orangefs_debugfs_init: called with debug mask: :none: :0:
[ 5.808206][ T1] orangefs_init: module version upstream loaded
[ 5.809264][ T1] JFS: nTxBlock = 8192, nTxLock = 65536
[ 5.832413][ T1] SGI XFS with ACLs, security attributes, realtime, scrub, repair, quota, no debug enabled
[ 5.849633][ T1] 9p: Installing v9fs 9p2000 file system support
[ 5.851906][ T1] NILFS version 2 loaded
[ 5.851917][ T1] befs: version: 0.9.3
[ 5.854601][ T1] ocfs2: Registered cluster interface o2cb
[ 5.861599][ T1] ocfs2: Registered cluster interface user
[ 5.868104][ T1] OCFS2 User DLM kernel interface loaded
[ 5.924667][ T1] gfs2: GFS2 installed
[ 5.950604][ T1] ceph: loaded (mds proto 32)
[ 5.970916][ T1] NET: Registered PF_ALG protocol family
[ 5.971417][ T1] async_tx: api initialized (async)
[ 5.971488][ T1] Key type asymmetric registered
[ 5.971574][ T1] Asymmetric key parser 'x509' registered
[ 5.971592][ T1] Asymmetric key parser 'pkcs8' registered
[ 5.971608][ T1] Key type pkcs7_test registered
[ 5.973411][ T1] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 239)
[ 5.980507][ T1] io scheduler mq-deadline registered
[ 5.980585][ T1] io scheduler kyber registered
[ 5.982508][ T1] io scheduler bfq registered
[ 6.001365][ T1] raid6: skipped pq benchmark and selected avx2x4
[ 6.039935][ T1] input: Power Button as /devices/platform/LNXPWRBN:00/input/input0
[ 6.045459][ T1] ACPI: button: Power Button [PWRF]
[ 6.058697][ T1] input: Sleep Button as /devices/platform/LNXSLPBN:00/input/input1
[ 6.063260][ T1] ACPI: button: Sleep Button [SLPF]
[ 6.106537][ T1] ioatdma: Intel(R) QuickData Technology Driver 5.00
[ 6.163872][ T10] ACPI: \_SB_.LNKC: Enabled at IRQ 11
[ 6.164135][ T10] virtio-pci 0000:00:03.0: virtio_pci: leaving for legacy driver
[ 6.214960][ T10] ACPI: \_SB_.LNKD: Enabled at IRQ 10
[ 6.218325][ T10] virtio-pci 0000:00:04.0: virtio_pci: leaving for legacy driver
[ 6.264078][ T10] ACPI: \_SB_.LNKB: Enabled at IRQ 10
[ 6.264234][ T10] virtio-pci 0000:00:06.0: virtio_pci: leaving for legacy driver
[ 6.301576][ T10] virtio-pci 0000:00:07.0: virtio_pci: leaving for legacy driver
[ 6.337562][ T211] kworker/u8:6 (211) used greatest stack depth: 26120 bytes left
[ 7.432947][ T1] N_HDLC line discipline registered with maxframe=4096
[ 7.439409][ T1] Serial: 8250/16550 driver, 4 ports, IRQ sharing enabled
[ 7.458549][ T1] 00:02: ttyS0 I/O:0x3f8 (irq = 4, base_baud = 115200) is a 16550A
[ 7.491690][ T1] 00:03: ttyS1 I/O:0x2f8 (irq = 3, base_baud = 115200) is a 16550A
[ 7.519868][ T1] 00:04: ttyS2 I/O:0x3e8 (irq = 6, base_baud = 115200) is a 16550A
[ 7.546408][ T1] 00:05: ttyS3 I/O:0x2e8 (irq = 7, base_baud = 115200) is a 16550A
[ 7.596237][ T1] Non-volatile memory driver v1.3
[ 7.652884][ T1] usbcore: registered new interface driver xillyusb
[ 7.670115][ T1] ACPI: bus type drm_connector registered
[ 7.685171][ T1] [drm] Initialized vgem 1.0.0 for vgem on minor 0
[ 7.694858][ T1] ------------[ cut here ]------------
[ 7.694873][ T1] [PLANE:35:plane-0] pixel format with alpha exposed but blend mode not setup
[ 7.694896][ T1] WARNING: drivers/gpu/drm/drm_mode_config.c:873 at drm_mode_config_validate+0x1c6d/0x1e60, CPU#1: swapper/0/1
[ 7.694965][ T1] Modules linked in:
[ 7.695014][ T1] CPU: 1 UID: 0 PID: 1 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT_{RT,(full)}
[ 7.695118][ T1] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/16/2026
[ 7.695141][ T1] RIP: 0010:drm_mode_config_validate+0x1cae/0x1e60
[ 7.695170][ T1] Code: 0f 85 ae 00 00 00 4d 8d 77 10 8b 6d 00 4c 89 f0 48 c1 e8 03 80 3c 18 00 74 08 4c 89 f7 e8 fa 9f ac fc 49 8b 16 4c 89 ef 89 ee <67> 48 0f b9 3a eb 05 e8 06 d0 3f fc 49 bd 00 00 00 00 00 fc ff df
[ 7.695192][ T1] RSP: 0000:ffffc90000067810 EFLAGS: 00010246
[ 7.695211][ T1] RAX: 1ffff11004be7c08 RBX: dffffc0000000000 RCX: ffff88801c6f5dc0
[ 7.695228][ T1] RDX: ffff888026454c40 RSI: 0000000000000023 RDI: ffffffff8fdc7790
[ 7.695244][ T1] RBP: 0000000000000023 R08: 0000000000000000 R09: 0000000000000000
[ 7.695258][ T1] R10: dffffc0000000000 R11: fffffbfff1fa25f0 R12: dffffc0000000000
[ 7.695275][ T1] R13: ffffffff8fdc7790 R14: ffff888025f3e040 R15: ffff888025f3e030
[ 7.695291][ T1] FS: 0000000000000000(0000) GS:ffff888125add000(0000) knlGS:0000000000000000
[ 7.695309][ T1] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 7.695324][ T1] CR2: 0000000000000000 CR3: 000000000e1b0000 CR4: 00000000003526f0
[ 7.695343][ T1] Call Trace:
[ 7.695352][ T1] <TASK>
[ 7.695376][ T1] ? debugfs_create_file_full+0x3f/0x60
[ 7.695418][ T1] drm_dev_register+0x7f/0xd80
[ 7.695448][ T1] vkms_create+0x40d/0x4f0
[ 7.695480][ T1] ? __pfx_vkms_init+0x10/0x10
[ 7.695518][ T1] vkms_init+0x57/0x80
[ 7.695551][ T1] do_one_initcall+0x250/0x870
[ 7.695579][ T1] ? __pfx_vkms_init+0x10/0x10
[ 7.695611][ T1] ? __pfx_do_one_initcall+0x10/0x10
[ 7.695647][ T1] ? __pfx___schedule+0x10/0x10
[ 7.695687][ T1] ? irqentry_exit+0x218/0x8f0
[ 7.695718][ T1] ? lockdep_hardirqs_on+0x7a/0x110
[ 7.695741][ T1] ? irqentry_exit+0x218/0x8f0
[ 7.695764][ T1] ? trace_irq_disable+0x3b/0x140
[ 7.695805][ T1] ? strlen+0x5c/0x70
[ 7.695830][ T1] ? next_arg+0x4a0/0x5e0
[ 7.695857][ T1] ? parameq+0x14d/0x170
[ 7.695894][ T1] ? parse_args+0x9c3/0xad0
[ 7.695943][ T1] ? trace_kmalloc+0x2a/0xf0
[ 7.695978][ T1] ? rcu_is_watching+0x15/0xb0
[ 7.696008][ T1] do_initcall_level+0x10a/0x1a0
[ 7.696035][ T1] ? kernel_init+0x22/0x1d0
[ 7.696063][ T1] do_initcalls+0x59/0xa0
[ 7.696090][ T1] kernel_init_freeable+0x29d/0x3e0
[ 7.696115][ T1] ? __pfx_kernel_init+0x10/0x10
[ 7.696147][ T1] kernel_init+0x22/0x1d0
[ 7.696174][ T1] ? __pfx_kernel_init+0x10/0x10
[ 7.696202][ T1] ret_from_fork+0x514/0xb70
[ 7.696235][ T1] ? __pfx_ret_from_fork+0x10/0x10
[ 7.696264][ T1] ? __switch_to+0xc89/0x1420
[ 7.696293][ T1] ? __pfx_kernel_init+0x10/0x10
[ 7.696325][ T1] ret_from_fork_asm+0x1a/0x30
[ 7.696372][ T1] </TASK>
[ 7.696388][ T1] Kernel panic - not syncing: kernel: panic_on_warn set ...
[ 7.696404][ T1] CPU: 1 UID: 0 PID: 1 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT_{RT,(full)}
[ 7.696428][ T1] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/16/2026
[ 7.696440][ T1] Call Trace:
[ 7.696448][ T1] <TASK>
[ 7.696457][ T1] vpanic+0x56c/0xa60
[ 7.696480][ T1] ? __pfx__printk+0x10/0x10
[ 7.696506][ T1] ? __pfx_vpanic+0x10/0x10
[ 7.696529][ T1] ? is_bpf_text_address+0x292/0x2b0
[ 7.696554][ T1] ? is_bpf_text_address+0x26/0x2b0
[ 7.696588][ T1] panic+0xc5/0xd0
[ 7.696610][ T1] ? __pfx_panic+0x10/0x10
[ 7.696640][ T1] ? ret_from_fork_asm+0x1a/0x30
[ 7.696675][ T1] __warn+0x315/0x4c0
[ 7.696695][ T1] ? drm_mode_config_validate+0x1c6d/0x1e60
[ 7.696732][ T1] ? drm_mode_config_validate+0x1c6d/0x1e60
[ 7.696758][ T1] __report_bug+0x276/0x570
[ 7.696785][ T1] ? drm_mode_config_validate+0x1c6d/0x1e60
[ 7.696814][ T1] ? __pfx___report_bug+0x10/0x10
[ 7.696845][ T1] ? _raw_spin_unlock_irqrestore+0x30/0x80
[ 7.696871][ T1] ? lockdep_hardirqs_on+0x7a/0x110
[ 7.696896][ T1] ? rt_mutex_slowunlock+0x4ee/0xa20
[ 7.696930][ T1] report_bug_entry+0x19a/0x290
[ 7.696956][ T1] ? drm_mode_config_validate+0x1cae/0x1e60
[ 7.696980][ T1] ? drm_mode_config_validate+0x1cb3/0x1e60
[ 7.697005][ T1] handle_bug+0xce/0x200
[ 7.697153][ T1] exc_invalid_op+0x1a/0x50
[ 7.697186][ T1] asm_exc_invalid_op+0x1a/0x20
[ 7.697209][ T1] RIP: 0010:drm_mode_config_validate+0x1cae/0x1e60
[ 7.697237][ T1] Code: 0f 85 ae 00 00 00 4d 8d 77 10 8b 6d 00 4c 89 f0 48 c1 e8 03 80 3c 18 00 74 08 4c 89 f7 e8 fa 9f ac fc 49 8b 16 4c 89 ef 89 ee <67> 48 0f b9 3a eb 05 e8 06 d0 3f fc 49 bd 00 00 00 00 00 fc ff df
[ 7.697256][ T1] RSP: 0000:ffffc90000067810 EFLAGS: 00010246
[ 7.697275][ T1] RAX: 1ffff11004be7c08 RBX: dffffc0000000000 RCX: ffff88801c6f5dc0
[ 7.697292][ T1] RDX: ffff888026454c40 RSI: 0000000000000023 RDI: ffffffff8fdc7790
[ 7.697307][ T1] RBP: 0000000000000023 R08: 0000000000000000 R09: 0000000000000000
[ 7.697320][ T1] R10: dffffc0000000000 R11: fffffbfff1fa25f0 R12: dffffc0000000000
[ 7.697336][ T1] R13: ffffffff8fdc7790 R14: ffff888025f3e040 R15: ffff888025f3e030
[ 7.697378][ T1] ? debugfs_create_file_full+0x3f/0x60
[ 7.697418][ T1] drm_dev_register+0x7f/0xd80
[ 7.697447][ T1] vkms_create+0x40d/0x4f0
[ 7.697478][ T1] ? __pfx_vkms_init+0x10/0x10
[ 7.697509][ T1] vkms_init+0x57/0x80
[ 7.697542][ T1] do_one_initcall+0x250/0x870
[ 7.697570][ T1] ? __pfx_vkms_init+0x10/0x10
[ 7.697614][ T1] ? __pfx_do_one_initcall+0x10/0x10
[ 7.697650][ T1] ? __pfx___schedule+0x10/0x10
[ 7.697687][ T1] ? irqentry_exit+0x218/0x8f0
[ 7.697710][ T1] ? lockdep_hardirqs_on+0x7a/0x110
[ 7.697735][ T1] ? irqentry_exit+0x218/0x8f0
[ 7.697757][ T1] ? trace_irq_disable+0x3b/0x140
[ 7.697799][ T1] ? strlen+0x5c/0x70
[ 7.697824][ T1] ? next_arg+0x4a0/0x5e0
[ 7.697852][ T1] ? parameq+0x14d/0x170
[ 7.697888][ T1] ? parse_args+0x9c3/0xad0
[ 7.697937][ T1] ? trace_kmalloc+0x2a/0xf0
[ 7.697972][ T1] ? rcu_is_watching+0x15/0xb0
[ 7.698003][ T1] do_initcall_level+0x10a/0x1a0
[ 7.698032][ T1] ? kernel_init+0x22/0x1d0
[ 7.698063][ T1] do_initcalls+0x59/0xa0
[ 7.698089][ T1] kernel_init_freeable+0x29d/0x3e0
[ 7.698115][ T1] ? __pfx_kernel_init+0x10/0x10
[ 7.698146][ T1] kernel_init+0x22/0x1d0
[ 7.698174][ T1] ? __pfx_kernel_init+0x10/0x10
[ 7.698203][ T1] ret_from_fork+0x514/0xb70
[ 7.698237][ T1] ? __pfx_ret_from_fork+0x10/0x10
[ 7.698268][ T1] ? __switch_to+0xc89/0x1420
[ 7.698304][ T1] ? __pfx_kernel_init+0x10/0x10
[ 7.698337][ T1] ret_from_fork_asm+0x1a/0x30
[ 7.698384][ T1] </TASK>
[ 7.699007][ T1] Kernel Offset: disabled
syzkaller build log:
go env (err=<nil>)
AR='ar'
CC='gcc'
CGO_CFLAGS='-O2 -g'
CGO_CPPFLAGS=''
CGO_CXXFLAGS='-O2 -g'
CGO_ENABLED='1'
CGO_FFLAGS='-O2 -g'
CGO_LDFLAGS='-O2 -g'
CXX='g++'
GCCGO='gccgo'
GO111MODULE='auto'
GOAMD64='v1'
GOARCH='amd64'
GOAUTH='netrc'
GOBIN=''
GOCACHE='/syzkaller/.cache/go-build'
GOCACHEPROG=''
GODEBUG=''
GOENV='/syzkaller/.config/go/env'
GOEXE=''
GOEXPERIMENT=''
GOFIPS140='off'
GOFLAGS=''
GOGCCFLAGS='-fPIC -m64 -pthread -Wl,--no-gc-sections -fmessage-length=0 -ffile-prefix-map=/tmp/go-build18079588=/tmp/go-build -gno-record-gcc-switches'
GOHOSTARCH='amd64'
GOHOSTOS='linux'
GOINSECURE=''
GOMOD='/syzkaller/jobs-2/linux/gopath/src/github.com/google/syzkaller/go.mod'
GOMODCACHE='/syzkaller/jobs-2/linux/gopath/pkg/mod'
GONOPROXY=''
GONOSUMDB=''
GOOS='linux'
GOPATH='/syzkaller/jobs-2/linux/gopath'
GOPRIVATE=''
GOPROXY='https://proxy.golang.org,direct'
GOROOT='/usr/local/go'
GOSUMDB='sum.golang.org'
GOTELEMETRY='local'
GOTELEMETRYDIR='/syzkaller/.config/go/telemetry'
GOTMPDIR=''
GOTOOLCHAIN='auto'
GOTOOLDIR='/usr/local/go/pkg/tool/linux_amd64'
GOVCS=''
GOVERSION='go1.26.0'
GOWORK=''
PKG_CONFIG='pkg-config'
git status (err=<nil>)
HEAD detached at 7c5de9c304
nothing to commit, working tree clean
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
go list -f '{{.Stale}}' -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=7c5de9c304dd32fc045989c69d2821397d56d718 -X github.com/google/syzkaller/prog.gitRevisionDate=20260721-090218" ./sys/syz-sysgen | grep -q false || go install -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=7c5de9c304dd32fc045989c69d2821397d56d718 -X github.com/google/syzkaller/prog.gitRevisionDate=20260721-090218" ./sys/syz-sysgen
make .descriptions
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
bin/syz-sysgen
touch .descriptions
GOOS=linux GOARCH=amd64 go build -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=7c5de9c304dd32fc045989c69d2821397d56d718 -X github.com/google/syzkaller/prog.gitRevisionDate=20260721-090218" -o ./bin/linux_amd64/syz-execprog github.com/google/syzkaller/tools/syz-execprog
mkdir -p ./bin/linux_amd64
g++ -o ./bin/linux_amd64/syz-executor executor/executor.cc \
-m64 -O2 -pthread -Wall -Werror -Wparentheses -Wunused-const-variable -Wframe-larger-than=16384 -Wno-stringop-overflow -Wno-array-bounds -Wno-format-overflow -Wno-unused-but-set-variable -Wno-unused-command-line-argument -static-pie -std=c++17 -I. -Iexecutor/_include -DGOOS_linux=1 -DGOARCH_amd64=1 \
-DHOSTGOOS_linux=1 -DGIT_REVISION=\"7c5de9c304dd32fc045989c69d2821397d56d718\"
/usr/bin/ld: /tmp/cc8B3TAg.o: in function `Connection::Connect(char const*, char const*)':
executor.cc:(.text._ZN10Connection7ConnectEPKcS1_[_ZN10Connection7ConnectEPKcS1_]+0x386): warning: Using 'gethostbyname' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking
./tools/check-syzos.sh 2>/dev/null
Error text is too large and was truncated, full error text is at:
https://syzkaller.appspot.com/x/error.txt?x=13e7f2ea580000
Tested on:
commit: 0d33d21e Add linux-next specific files for 20260727
git tree: linux-next
kernel config: https://syzkaller.appspot.com/x/.config?x=830a7c02f0fee86b
dashboard link: https://syzkaller.appspot.com/bug?extid=25031f01508bf55c62ca
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
patch: https://syzkaller.appspot.com/x/patch.diff?x=140a67b1580000
^ permalink raw reply [flat|nested] 2+ messages in thread
* [syzbot] [input?] [usb?] WARNING in cm109_input_ev/usb_submit_urb (2)
@ 2026-07-25 19:56 syzbot
0 siblings, 0 replies; 2+ messages in thread
From: syzbot @ 2026-07-25 19:56 UTC (permalink / raw)
To: dmitry.torokhov, linux-input, linux-kernel, linux-usb,
syzkaller-bugs
Hello,
syzbot found the following issue on:
HEAD commit: cc2b5f627e8c Add linux-next specific files for 20260714
git tree: linux-next
console output: https://syzkaller.appspot.com/x/log.txt?x=128a1746580000
kernel config: https://syzkaller.appspot.com/x/.config?x=2290ccbf984c524f
dashboard link: https://syzkaller.appspot.com/bug?extid=25031f01508bf55c62ca
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=117b92b9580000
Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/6836f8efb1da/disk-cc2b5f62.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/0109d3477cc7/vmlinux-cc2b5f62.xz
kernel image: https://storage.googleapis.com/syzbot-assets/c2e49e350bbf/bzImage-cc2b5f62.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+25031f01508bf55c62ca@syzkaller.appspotmail.com
------------[ cut here ]------------
URB ffff88802bec5e00 submitted while active
WARNING: drivers/usb/core/urb.c:379 at usb_submit_urb+0x79/0x18b0 drivers/usb/core/urb.c:379, CPU#0: syz.1.696/7407
Modules linked in:
CPU: 0 UID: 0 PID: 7407 Comm: syz.1.696 Not tainted syzkaller #0 PREEMPT_{RT,(full)}
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/25/2026
RIP: 0010:usb_submit_urb+0x7c/0x18b0 drivers/usb/core/urb.c:379
Code: 4c 89 f0 48 c1 e8 03 80 3c 28 00 74 08 4c 89 f7 e8 f9 92 4d fb 49 83 3e 00 74 40 e8 0e 3c e1 fa 48 8d 3d 87 f1 f8 08 48 89 de <67> 48 0f b9 3a b8 f0 ff ff ff eb 11 e8 f3 3b e1 fa eb 05 e8 ec 3b
RSP: 0018:ffffc900054ff3f8 EFLAGS: 00010293
RAX: ffffffff86e467a2 RBX: ffff88802bec5e00 RCX: ffff88803151be80
RDX: 0000000000000000 RSI: ffff88802bec5e00 RDI: ffffffff8fdd5930
RBP: dffffc0000000000 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: ffffffff8e3c3880 R12: 1ffff1100b9e9d0a
R13: dffffc0000000000 R14: ffff88802bec5e08 R15: 0000000000000820
FS: 00007f395df0e6c0(0000) GS:ffff8881259f2000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f29938eb580 CR3: 0000000040c08000 CR4: 00000000003526f0
Call Trace:
<TASK>
cm109_submit_buzz_toggle drivers/input/misc/cm109.c:351 [inline]
cm109_toggle_buzzer_async drivers/input/misc/cm109.c:484 [inline]
cm109_input_ev+0x1d1/0x3b0 drivers/input/misc/cm109.c:615
input_event_dispose+0x80/0x6b0 drivers/input/input.c:322
input_inject_event+0x1fa/0x310 drivers/input/input.c:424
kd_sound_helper+0x101/0x210 drivers/tty/vt/keyboard.c:257
input_handler_for_each_handle+0x101/0x1c0 drivers/input/input.c:2540
kd_mksound+0x96/0x130 drivers/tty/vt/keyboard.c:281
handle_ascii drivers/tty/vt/vt.c:2382 [inline]
do_con_trol drivers/tty/vt/vt.c:2699 [inline]
do_con_write+0x2f5a/0x5540 drivers/tty/vt/vt.c:3325
con_write+0x31/0x2e0 drivers/tty/vt/vt.c:3661
process_output_block drivers/tty/n_tty.c:557 [inline]
n_tty_write+0xd4f/0x11e0 drivers/tty/n_tty.c:2366
iterate_tty_write drivers/tty/tty_io.c:1006 [inline]
file_tty_write+0x50b/0x980 drivers/tty/tty_io.c:1081
new_sync_write fs/read_write.c:595 [inline]
vfs_write+0x61e/0xbb0 fs/read_write.c:687
ksys_write+0x156/0x270 fs/read_write.c:739
do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline]
do_syscall_64+0x17b/0x530 arch/x86/entry/syscall_64.c:85
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f395e8ade99
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f395df0e028 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 00007f395eb35fa0 RCX: 00007f395e8ade99
RDX: 0000000000001006 RSI: 0000200000002080 RDI: 0000000000000004
RBP: 00007f395e943eaf R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f395eb36038 R14: 00007f395eb35fa0 R15: 00007fff65968248
</TASK>
----------------
Code disassembly (best guess):
0: 4c 89 f0 mov %r14,%rax
3: 48 c1 e8 03 shr $0x3,%rax
7: 80 3c 28 00 cmpb $0x0,(%rax,%rbp,1)
b: 74 08 je 0x15
d: 4c 89 f7 mov %r14,%rdi
10: e8 f9 92 4d fb call 0xfb4d930e
15: 49 83 3e 00 cmpq $0x0,(%r14)
19: 74 40 je 0x5b
1b: e8 0e 3c e1 fa call 0xfae13c2e
20: 48 8d 3d 87 f1 f8 08 lea 0x8f8f187(%rip),%rdi # 0x8f8f1ae
27: 48 89 de mov %rbx,%rsi
* 2a: 67 48 0f b9 3a ud1 (%edx),%rdi <-- trapping instruction
2f: b8 f0 ff ff ff mov $0xfffffff0,%eax
34: eb 11 jmp 0x47
36: e8 f3 3b e1 fa call 0xfae13c2e
3b: eb 05 jmp 0x42
3d: e8 .byte 0xe8
3e: ec in (%dx),%al
3f: 3b .byte 0x3b
---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-07-27 19:47 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
[not found] <20260727204430.583f59db@systembl0wer>
2026-07-27 19:47 ` [syzbot] [input?] [usb?] WARNING in cm109_input_ev/usb_submit_urb (2) syzbot
2026-07-25 19:56 syzbot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox