The Linux Kernel Mailing List
 help / color / mirror / Atom feed
* [syzbot] [kernel?] linux-next test error: WARNING: locking bug in change_page_attr_set_clr
@ 2026-07-20 16:59 syzbot
  2026-07-21  2:24 ` Borislav Petkov
  2026-07-21 10:20 ` Forwarded: " syzbot
  0 siblings, 2 replies; 11+ messages in thread
From: syzbot @ 2026-07-20 16:59 UTC (permalink / raw)
  To: bp, dave.hansen, hpa, linux-kernel, linux-next, luto, mingo,
	peterz, sfr, syzkaller-bugs, tglx, x86

Hello,

syzbot found the following issue on:

HEAD commit:    1a1757b76427 Add linux-next specific files for 20260716
git tree:       linux-next
console output: https://syzkaller.appspot.com/x/log.txt?x=16c734b9580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=8d1a274c57796a86
dashboard link: https://syzkaller.appspot.com/bug?extid=ee7ecfcd0e3f185e835a
compiler:       Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/923ee89ba238/disk-1a1757b7.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/cb34d1bf205c/vmlinux-1a1757b7.xz
kernel image: https://storage.googleapis.com/syzbot-assets/bf183d434c82/bzImage-1a1757b7.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+ee7ecfcd0e3f185e835a@syzkaller.appspotmail.com

clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 19112604462750000 ns
kfence: initialized - using 2097152 bytes for 255 objects at 0xffff88823be00000-0xffff88823c000000
Console: colour VGA+ 80x25
printk: legacy console [ttyS0] enabled
printk: legacy console [ttyS0] enabled
printk: legacy bootconsole [earlyser0] disabled
printk: legacy bootconsole [earlyser0] disabled
Lock dependency validator: Copyright (c) 2006 Red Hat, Inc., Ingo Molnar
... MAX_LOCKDEP_SUBCLASSES:  8
... MAX_LOCK_DEPTH:          48
... MAX_LOCKDEP_KEYS:        8192
... CLASSHASH_SIZE:          4096
... MAX_LOCKDEP_ENTRIES:     1048576
... MAX_LOCKDEP_CHAINS:      1048576
... CHAINHASH_SIZE:          524288
 memory used by lock dependency info: 106625 kB
 memory used for stack traces: 8320 kB
 per task-struct memory footprint: 1920 bytes
mempolicy: Enabling automatic NUMA balancing. Configure with numa_balancing= or the kernel.numa_balancing sysctl
ACPI: Core revision 20260408
APIC: Switch to symmetric I/O mode setup
x2apic enabled
APIC: Switched APIC routing to: physical x2apic
..TIMER: vector=0x30 apic1=0 pin1=0 apic2=-1 pin2=-1
clocksource: tsc-early: mask: 0xffffffffffffffff max_cycles: 0x1fb63109b96, max_idle_ns: 440795265316 ns
Calibrating delay loop (skipped) preset value.. 4399.99 BogoMIPS (lpj=21999980)
Last level iTLB entries: 4KB 64, 2MB 8, 4MB 8
Last level dTLB entries: 4KB 64, 2MB 32, 4MB 32, 1GB 4
mitigations: Enabled attack vectors: user_kernel, user_user, guest_host, guest_guest, SMT mitigations: auto
Speculative Store Bypass: Mitigation: Speculative Store Bypass disabled via prctl
Spectre V2 : Mitigation: IBRS
RETBleed: Mitigation: IBRS
ITS: Mitigation: Aligned branch/return thunks
Spectre V2 : User space: Mitigation: STIBP via prctl
MDS: Mitigation: Clear CPU buffers
TAA: Mitigation: Clear CPU buffers
MMIO Stale Data: Vulnerable: Clear CPU buffers attempted, no microcode
Spectre V1 : Mitigation: usercopy/swapgs barriers and __user pointer sanitization
Spectre V2 : Spectre v2 / SpectreRSB: Filling RSB on context switch and VMEXIT
Spectre V2 : Enabling IBPB for BPF
Spectre V2 : mitigation: Enabling conditional Indirect Branch Prediction Barrier
active return thunk: its_return_thunk
Spectre V2 : Spectre BHI mitigation: SW BHB clearing on syscall and VM exit
x86/fpu: Supporting XSAVE feature 0x001: 'x87 floating point registers'
x86/fpu: Supporting XSAVE feature 0x002: 'SSE registers'
x86/fpu: Supporting XSAVE feature 0x004: 'AVX registers'
x86/fpu: xstate_offset[2]:  576, xstate_sizes[2]:  256
x86/fpu: Enabled xstate features 0x7, context size is 832 bytes, using 'standard' format.

=============================
[ BUG: Invalid wait context ]
syzkaller #0 Not tainted
-----------------------------
swapper/0/0 is trying to lock:
ffffffff8f088c78 ((init_mm).mmap_lock){....}-{4:4}, at: mmap_read_lock include/linux/mmap_lock.h:600 [inline]
ffffffff8f088c78 ((init_mm).mmap_lock){....}-{4:4}, at: class_mmap_read_lock_constructor include/linux/mmap_lock.h:631 [inline]
ffffffff8f088c78 ((init_mm).mmap_lock){....}-{4:4}, at: cpa_collapse_large_pages arch/x86/mm/pat/set_memory.c:448 [inline]
ffffffff8f088c78 ((init_mm).mmap_lock){....}-{4:4}, at: cpa_flush arch/x86/mm/pat/set_memory.c:494 [inline]
ffffffff8f088c78 ((init_mm).mmap_lock){....}-{4:4}, at: change_page_attr_set_clr+0xc2c/0x1010 arch/x86/mm/pat/set_memory.c:2142
other info that might help us debug this:
context-{5:5}
locks held by swapper/0/0: 1, last CPU#0:
 #0: ffffffff8edc2078 (cpa_lock){+.+.}-{3:3}, at: spin_lock include/linux/spinlock.h:342 [inline]
 #0: ffffffff8edc2078 (cpa_lock){+.+.}-{3:3}, at: cpa_collapse_large_pages arch/x86/mm/pat/set_memory.c:421 [inline]
 #0: ffffffff8edc2078 (cpa_lock){+.+.}-{3:3}, at: cpa_flush arch/x86/mm/pat/set_memory.c:494 [inline]
 #0: ffffffff8edc2078 (cpa_lock){+.+.}-{3:3}, at: change_page_attr_set_clr+0x967/0x1010 arch/x86/mm/pat/set_memory.c:2142
stack backtrace:
CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT(full) 
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/25/2026
Call Trace:
 <TASK>
 dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120
 print_lock_invalid_wait_context kernel/locking/lockdep.c:4846 [inline]
 check_wait_context kernel/locking/lockdep.c:4918 [inline]
 __lock_acquire+0xef0/0x2e50 kernel/locking/lockdep.c:5204
 lock_acquire+0x115/0x350 kernel/locking/lockdep.c:5906
 down_read+0x4a/0x330 kernel/locking/rwsem.c:1574
 mmap_read_lock include/linux/mmap_lock.h:600 [inline]
 class_mmap_read_lock_constructor include/linux/mmap_lock.h:631 [inline]
 cpa_collapse_large_pages arch/x86/mm/pat/set_memory.c:448 [inline]
 cpa_flush arch/x86/mm/pat/set_memory.c:494 [inline]
 change_page_attr_set_clr+0xc2c/0x1010 arch/x86/mm/pat/set_memory.c:2142
 set_memory_rox+0xbe/0x100 arch/x86/mm/pat/set_memory.c:2341
 its_pages_protect arch/x86/kernel/alternative.c:168 [inline]
 its_fini_core arch/x86/kernel/alternative.c:175 [inline]
 alternative_instructions+0x95/0x100 arch/x86/kernel/alternative.c:2264
 arch_cpu_finalize_init+0xb2/0x1f0 arch/x86/kernel/cpu/common.c:2633
 start_kernel+0x310/0x3e0 init/main.c:1153
 x86_64_start_reservations+0x24/0x30 arch/x86/kernel/head64.c:310
 x86_64_start_kernel+0x137/0x1b0 arch/x86/kernel/head64.c:291
 common_startup_64+0x13e/0x157
 </TASK>
pid_max: default: 32768 minimum: 301
landlock: Up and running.
Yama: becoming mindful.
TOMOYO Linux initialized
AppArmor: AppArmor initialized
LSM support for eBPF active
Dentry cache hash table entries: 1048576 (order: 11, 8388608 bytes, vmalloc hugepage)
Inode-cache hash table entries: 524288 (order: 10, 4194304 bytes, vmalloc hugepage)
Mount-cache hash table entries: 16384 (order: 5, 131072 bytes, vmalloc)
Mountpoint-cache hash table entries: 16384 (order: 5, 131072 bytes, vmalloc)
VFS: Finished mounting rootfs on nullfs
Running RCU synchronous self tests
Running RCU synchronous self tests
numa_add_cpu cpu 1 node 0: mask now 0-1
numa_add_cpu cpu 1 node 1: mask now 0-1


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: [syzbot] [kernel?] linux-next test error: WARNING: locking bug in change_page_attr_set_clr
  2026-07-20 16:59 [syzbot] [kernel?] linux-next test error: WARNING: locking bug in change_page_attr_set_clr syzbot
@ 2026-07-21  2:24 ` Borislav Petkov
  2026-07-21 10:35   ` Mike Rapoport
  2026-07-21 10:20 ` Forwarded: " syzbot
  1 sibling, 1 reply; 11+ messages in thread
From: Borislav Petkov @ 2026-07-21  2:24 UTC (permalink / raw)
  To: syzbot, Denis V. Lunev, Mike Rapoport, Vishal Moola
  Cc: dave.hansen, hpa, linux-kernel, linux-next, luto, mingo, peterz,
	sfr, syzkaller-bugs, tglx, x86

Adding all folks who touched this recently.

On Mon, Jul 20, 2026 at 09:59:25AM -0700, syzbot wrote:
> Hello,
> 
> syzbot found the following issue on:
> 
> HEAD commit:    1a1757b76427 Add linux-next specific files for 20260716
> git tree:       linux-next
> console output: https://syzkaller.appspot.com/x/log.txt?x=16c734b9580000
> kernel config:  https://syzkaller.appspot.com/x/.config?x=8d1a274c57796a86
> dashboard link: https://syzkaller.appspot.com/bug?extid=ee7ecfcd0e3f185e835a
> compiler:       Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
> 
> Downloadable assets:
> disk image: https://storage.googleapis.com/syzbot-assets/923ee89ba238/disk-1a1757b7.raw.xz
> vmlinux: https://storage.googleapis.com/syzbot-assets/cb34d1bf205c/vmlinux-1a1757b7.xz
> kernel image: https://storage.googleapis.com/syzbot-assets/bf183d434c82/bzImage-1a1757b7.xz
> 
> IMPORTANT: if you fix the issue, please add the following tag to the commit:
> Reported-by: syzbot+ee7ecfcd0e3f185e835a@syzkaller.appspotmail.com
> 
> clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 19112604462750000 ns
> kfence: initialized - using 2097152 bytes for 255 objects at 0xffff88823be00000-0xffff88823c000000
> Console: colour VGA+ 80x25
> printk: legacy console [ttyS0] enabled
> printk: legacy console [ttyS0] enabled
> printk: legacy bootconsole [earlyser0] disabled
> printk: legacy bootconsole [earlyser0] disabled
> Lock dependency validator: Copyright (c) 2006 Red Hat, Inc., Ingo Molnar
> ... MAX_LOCKDEP_SUBCLASSES:  8
> ... MAX_LOCK_DEPTH:          48
> ... MAX_LOCKDEP_KEYS:        8192
> ... CLASSHASH_SIZE:          4096
> ... MAX_LOCKDEP_ENTRIES:     1048576
> ... MAX_LOCKDEP_CHAINS:      1048576
> ... CHAINHASH_SIZE:          524288
>  memory used by lock dependency info: 106625 kB
>  memory used for stack traces: 8320 kB
>  per task-struct memory footprint: 1920 bytes
> mempolicy: Enabling automatic NUMA balancing. Configure with numa_balancing= or the kernel.numa_balancing sysctl
> ACPI: Core revision 20260408
> APIC: Switch to symmetric I/O mode setup
> x2apic enabled
> APIC: Switched APIC routing to: physical x2apic
> ..TIMER: vector=0x30 apic1=0 pin1=0 apic2=-1 pin2=-1
> clocksource: tsc-early: mask: 0xffffffffffffffff max_cycles: 0x1fb63109b96, max_idle_ns: 440795265316 ns
> Calibrating delay loop (skipped) preset value.. 4399.99 BogoMIPS (lpj=21999980)
> Last level iTLB entries: 4KB 64, 2MB 8, 4MB 8
> Last level dTLB entries: 4KB 64, 2MB 32, 4MB 32, 1GB 4
> mitigations: Enabled attack vectors: user_kernel, user_user, guest_host, guest_guest, SMT mitigations: auto
> Speculative Store Bypass: Mitigation: Speculative Store Bypass disabled via prctl
> Spectre V2 : Mitigation: IBRS
> RETBleed: Mitigation: IBRS
> ITS: Mitigation: Aligned branch/return thunks
> Spectre V2 : User space: Mitigation: STIBP via prctl
> MDS: Mitigation: Clear CPU buffers
> TAA: Mitigation: Clear CPU buffers
> MMIO Stale Data: Vulnerable: Clear CPU buffers attempted, no microcode
> Spectre V1 : Mitigation: usercopy/swapgs barriers and __user pointer sanitization
> Spectre V2 : Spectre v2 / SpectreRSB: Filling RSB on context switch and VMEXIT
> Spectre V2 : Enabling IBPB for BPF
> Spectre V2 : mitigation: Enabling conditional Indirect Branch Prediction Barrier
> active return thunk: its_return_thunk
> Spectre V2 : Spectre BHI mitigation: SW BHB clearing on syscall and VM exit
> x86/fpu: Supporting XSAVE feature 0x001: 'x87 floating point registers'
> x86/fpu: Supporting XSAVE feature 0x002: 'SSE registers'
> x86/fpu: Supporting XSAVE feature 0x004: 'AVX registers'
> x86/fpu: xstate_offset[2]:  576, xstate_sizes[2]:  256
> x86/fpu: Enabled xstate features 0x7, context size is 832 bytes, using 'standard' format.
> 
> =============================
> [ BUG: Invalid wait context ]
> syzkaller #0 Not tainted
> -----------------------------
> swapper/0/0 is trying to lock:
> ffffffff8f088c78 ((init_mm).mmap_lock){....}-{4:4}, at: mmap_read_lock include/linux/mmap_lock.h:600 [inline]
> ffffffff8f088c78 ((init_mm).mmap_lock){....}-{4:4}, at: class_mmap_read_lock_constructor include/linux/mmap_lock.h:631 [inline]
> ffffffff8f088c78 ((init_mm).mmap_lock){....}-{4:4}, at: cpa_collapse_large_pages arch/x86/mm/pat/set_memory.c:448 [inline]
> ffffffff8f088c78 ((init_mm).mmap_lock){....}-{4:4}, at: cpa_flush arch/x86/mm/pat/set_memory.c:494 [inline]
> ffffffff8f088c78 ((init_mm).mmap_lock){....}-{4:4}, at: change_page_attr_set_clr+0xc2c/0x1010 arch/x86/mm/pat/set_memory.c:2142
> other info that might help us debug this:
> context-{5:5}
> locks held by swapper/0/0: 1, last CPU#0:
>  #0: ffffffff8edc2078 (cpa_lock){+.+.}-{3:3}, at: spin_lock include/linux/spinlock.h:342 [inline]
>  #0: ffffffff8edc2078 (cpa_lock){+.+.}-{3:3}, at: cpa_collapse_large_pages arch/x86/mm/pat/set_memory.c:421 [inline]
>  #0: ffffffff8edc2078 (cpa_lock){+.+.}-{3:3}, at: cpa_flush arch/x86/mm/pat/set_memory.c:494 [inline]
>  #0: ffffffff8edc2078 (cpa_lock){+.+.}-{3:3}, at: change_page_attr_set_clr+0x967/0x1010 arch/x86/mm/pat/set_memory.c:2142
> stack backtrace:
> CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT(full) 
> Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/25/2026
> Call Trace:
>  <TASK>
>  dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120
>  print_lock_invalid_wait_context kernel/locking/lockdep.c:4846 [inline]
>  check_wait_context kernel/locking/lockdep.c:4918 [inline]
>  __lock_acquire+0xef0/0x2e50 kernel/locking/lockdep.c:5204
>  lock_acquire+0x115/0x350 kernel/locking/lockdep.c:5906
>  down_read+0x4a/0x330 kernel/locking/rwsem.c:1574
>  mmap_read_lock include/linux/mmap_lock.h:600 [inline]
>  class_mmap_read_lock_constructor include/linux/mmap_lock.h:631 [inline]
>  cpa_collapse_large_pages arch/x86/mm/pat/set_memory.c:448 [inline]
>  cpa_flush arch/x86/mm/pat/set_memory.c:494 [inline]
>  change_page_attr_set_clr+0xc2c/0x1010 arch/x86/mm/pat/set_memory.c:2142
>  set_memory_rox+0xbe/0x100 arch/x86/mm/pat/set_memory.c:2341
>  its_pages_protect arch/x86/kernel/alternative.c:168 [inline]
>  its_fini_core arch/x86/kernel/alternative.c:175 [inline]
>  alternative_instructions+0x95/0x100 arch/x86/kernel/alternative.c:2264
>  arch_cpu_finalize_init+0xb2/0x1f0 arch/x86/kernel/cpu/common.c:2633
>  start_kernel+0x310/0x3e0 init/main.c:1153
>  x86_64_start_reservations+0x24/0x30 arch/x86/kernel/head64.c:310
>  x86_64_start_kernel+0x137/0x1b0 arch/x86/kernel/head64.c:291
>  common_startup_64+0x13e/0x157
>  </TASK>
> pid_max: default: 32768 minimum: 301
> landlock: Up and running.
> Yama: becoming mindful.
> TOMOYO Linux initialized
> AppArmor: AppArmor initialized
> LSM support for eBPF active
> Dentry cache hash table entries: 1048576 (order: 11, 8388608 bytes, vmalloc hugepage)
> Inode-cache hash table entries: 524288 (order: 10, 4194304 bytes, vmalloc hugepage)
> Mount-cache hash table entries: 16384 (order: 5, 131072 bytes, vmalloc)
> Mountpoint-cache hash table entries: 16384 (order: 5, 131072 bytes, vmalloc)
> VFS: Finished mounting rootfs on nullfs
> Running RCU synchronous self tests
> Running RCU synchronous self tests
> numa_add_cpu cpu 1 node 0: mask now 0-1
> numa_add_cpu cpu 1 node 1: mask now 0-1
> 
> 
> ---
> This report is generated by a bot. It may contain errors.
> See https://goo.gl/tpsmEJ for more information about syzbot.
> syzbot engineers can be reached at syzkaller@googlegroups.com.
> 
> syzbot will keep track of this issue. See:
> https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
> 
> If the report is already addressed, let syzbot know by replying with:
> #syz fix: exact-commit-title
> 
> If you want to overwrite report's subsystems, reply with:
> #syz set subsystems: new-subsystem
> (See the list of subsystem names on the web dashboard)
> 
> If the report is a duplicate of another one, reply with:
> #syz dup: exact-subject-of-another-report
> 
> If you want to undo deduplication, reply with:
> #syz undup

-- 
Regards/Gruss,
    Boris.

https://people.kernel.org/tglx/notes-about-netiquette

^ permalink raw reply	[flat|nested] 11+ messages in thread

* Forwarded: Re: [syzbot] [kernel?] linux-next test error: WARNING: locking bug in change_page_attr_set_clr
  2026-07-20 16:59 [syzbot] [kernel?] linux-next test error: WARNING: locking bug in change_page_attr_set_clr syzbot
  2026-07-21  2:24 ` Borislav Petkov
@ 2026-07-21 10:20 ` syzbot
  1 sibling, 0 replies; 11+ messages in thread
From: syzbot @ 2026-07-21 10:20 UTC (permalink / raw)
  To: linux-kernel

For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org.

***

Subject: Re: [syzbot] [kernel?] linux-next test error: WARNING: locking bug in change_page_attr_set_clr
Author: hokage.newbie@gmail.com

#syz test: https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git
1a1757b76427

^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: [syzbot] [kernel?] linux-next test error: WARNING: locking bug in change_page_attr_set_clr
  2026-07-21  2:24 ` Borislav Petkov
@ 2026-07-21 10:35   ` Mike Rapoport
  2026-07-21 12:39     ` Lorenzo Stoakes (ARM)
  0 siblings, 1 reply; 11+ messages in thread
From: Mike Rapoport @ 2026-07-21 10:35 UTC (permalink / raw)
  To: Borislav Petkov, Lorenzo Stoakes
  Cc: syzbot, Denis V. Lunev, Vishal Moola, dave.hansen, hpa,
	linux-kernel, linux-next, luto, mingo, peterz, sfr,
	syzkaller-bugs, tglx, x86

On Mon, Jul 20, 2026 at 07:24:48PM -0700, Borislav Petkov wrote:
> Adding all folks who touched this recently.

You forgot Lorenzo ;-)
 
> On Mon, Jul 20, 2026 at 09:59:25AM -0700, syzbot wrote:
> > Hello,
> > 
> > syzbot found the following issue on:
> > 
> > HEAD commit:    1a1757b76427 Add linux-next specific files for 20260716
> > git tree:       linux-next
> > console output: https://syzkaller.appspot.com/x/log.txt?x=16c734b9580000
> > kernel config:  https://syzkaller.appspot.com/x/.config?x=8d1a274c57796a86
> > dashboard link: https://syzkaller.appspot.com/bug?extid=ee7ecfcd0e3f185e835a
> > compiler:       Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
> > 
> > Downloadable assets:
> > disk image: https://storage.googleapis.com/syzbot-assets/923ee89ba238/disk-1a1757b7.raw.xz
> > vmlinux: https://storage.googleapis.com/syzbot-assets/cb34d1bf205c/vmlinux-1a1757b7.xz
> > kernel image: https://storage.googleapis.com/syzbot-assets/bf183d434c82/bzImage-1a1757b7.xz
> > 
> > IMPORTANT: if you fix the issue, please add the following tag to the commit:
> > Reported-by: syzbot+ee7ecfcd0e3f185e835a@syzkaller.appspotmail.com
> > 
> > clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 19112604462750000 ns
> > kfence: initialized - using 2097152 bytes for 255 objects at 0xffff88823be00000-0xffff88823c000000
> > Console: colour VGA+ 80x25
> > printk: legacy console [ttyS0] enabled
> > printk: legacy console [ttyS0] enabled
> > printk: legacy bootconsole [earlyser0] disabled
> > printk: legacy bootconsole [earlyser0] disabled
> > Lock dependency validator: Copyright (c) 2006 Red Hat, Inc., Ingo Molnar
> > ... MAX_LOCKDEP_SUBCLASSES:  8
> > ... MAX_LOCK_DEPTH:          48
> > ... MAX_LOCKDEP_KEYS:        8192
> > ... CLASSHASH_SIZE:          4096
> > ... MAX_LOCKDEP_ENTRIES:     1048576
> > ... MAX_LOCKDEP_CHAINS:      1048576
> > ... CHAINHASH_SIZE:          524288
> >  memory used by lock dependency info: 106625 kB
> >  memory used for stack traces: 8320 kB
> >  per task-struct memory footprint: 1920 bytes
> > mempolicy: Enabling automatic NUMA balancing. Configure with numa_balancing= or the kernel.numa_balancing sysctl
> > ACPI: Core revision 20260408
> > APIC: Switch to symmetric I/O mode setup
> > x2apic enabled
> > APIC: Switched APIC routing to: physical x2apic
> > ..TIMER: vector=0x30 apic1=0 pin1=0 apic2=-1 pin2=-1
> > clocksource: tsc-early: mask: 0xffffffffffffffff max_cycles: 0x1fb63109b96, max_idle_ns: 440795265316 ns
> > Calibrating delay loop (skipped) preset value.. 4399.99 BogoMIPS (lpj=21999980)
> > Last level iTLB entries: 4KB 64, 2MB 8, 4MB 8
> > Last level dTLB entries: 4KB 64, 2MB 32, 4MB 32, 1GB 4
> > mitigations: Enabled attack vectors: user_kernel, user_user, guest_host, guest_guest, SMT mitigations: auto
> > Speculative Store Bypass: Mitigation: Speculative Store Bypass disabled via prctl
> > Spectre V2 : Mitigation: IBRS
> > RETBleed: Mitigation: IBRS
> > ITS: Mitigation: Aligned branch/return thunks
> > Spectre V2 : User space: Mitigation: STIBP via prctl
> > MDS: Mitigation: Clear CPU buffers
> > TAA: Mitigation: Clear CPU buffers
> > MMIO Stale Data: Vulnerable: Clear CPU buffers attempted, no microcode
> > Spectre V1 : Mitigation: usercopy/swapgs barriers and __user pointer sanitization
> > Spectre V2 : Spectre v2 / SpectreRSB: Filling RSB on context switch and VMEXIT
> > Spectre V2 : Enabling IBPB for BPF
> > Spectre V2 : mitigation: Enabling conditional Indirect Branch Prediction Barrier
> > active return thunk: its_return_thunk
> > Spectre V2 : Spectre BHI mitigation: SW BHB clearing on syscall and VM exit
> > x86/fpu: Supporting XSAVE feature 0x001: 'x87 floating point registers'
> > x86/fpu: Supporting XSAVE feature 0x002: 'SSE registers'
> > x86/fpu: Supporting XSAVE feature 0x004: 'AVX registers'
> > x86/fpu: xstate_offset[2]:  576, xstate_sizes[2]:  256
> > x86/fpu: Enabled xstate features 0x7, context size is 832 bytes, using 'standard' format.
> > 
> > =============================
> > [ BUG: Invalid wait context ]
> > syzkaller #0 Not tainted
> > -----------------------------
> > swapper/0/0 is trying to lock:
> > ffffffff8f088c78 ((init_mm).mmap_lock){....}-{4:4}, at: mmap_read_lock include/linux/mmap_lock.h:600 [inline]
> > ffffffff8f088c78 ((init_mm).mmap_lock){....}-{4:4}, at: class_mmap_read_lock_constructor include/linux/mmap_lock.h:631 [inline]
> > ffffffff8f088c78 ((init_mm).mmap_lock){....}-{4:4}, at: cpa_collapse_large_pages arch/x86/mm/pat/set_memory.c:448 [inline]
> > ffffffff8f088c78 ((init_mm).mmap_lock){....}-{4:4}, at: cpa_flush arch/x86/mm/pat/set_memory.c:494 [inline]
> > ffffffff8f088c78 ((init_mm).mmap_lock){....}-{4:4}, at: change_page_attr_set_clr+0xc2c/0x1010 arch/x86/mm/pat/set_memory.c:2142
> > other info that might help us debug this:
> > context-{5:5}
> > locks held by swapper/0/0: 1, last CPU#0:
> >  #0: ffffffff8edc2078 (cpa_lock){+.+.}-{3:3}, at: spin_lock include/linux/spinlock.h:342 [inline]
> >  #0: ffffffff8edc2078 (cpa_lock){+.+.}-{3:3}, at: cpa_collapse_large_pages arch/x86/mm/pat/set_memory.c:421 [inline]
> >  #0: ffffffff8edc2078 (cpa_lock){+.+.}-{3:3}, at: cpa_flush arch/x86/mm/pat/set_memory.c:494 [inline]
> >  #0: ffffffff8edc2078 (cpa_lock){+.+.}-{3:3}, at: change_page_attr_set_clr+0x967/0x1010 arch/x86/mm/pat/set_memory.c:2142
> > stack backtrace:
> > CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT(full) 
> > Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/25/2026
> > Call Trace:
> >  <TASK>
> >  dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120
> >  print_lock_invalid_wait_context kernel/locking/lockdep.c:4846 [inline]
> >  check_wait_context kernel/locking/lockdep.c:4918 [inline]
> >  __lock_acquire+0xef0/0x2e50 kernel/locking/lockdep.c:5204
> >  lock_acquire+0x115/0x350 kernel/locking/lockdep.c:5906
> >  down_read+0x4a/0x330 kernel/locking/rwsem.c:1574
> >  mmap_read_lock include/linux/mmap_lock.h:600 [inline]
> >  class_mmap_read_lock_constructor include/linux/mmap_lock.h:631 [inline]
> >  cpa_collapse_large_pages arch/x86/mm/pat/set_memory.c:448 [inline]
> >  cpa_flush arch/x86/mm/pat/set_memory.c:494 [inline]
> >  change_page_attr_set_clr+0xc2c/0x1010 arch/x86/mm/pat/set_memory.c:2142
> >  set_memory_rox+0xbe/0x100 arch/x86/mm/pat/set_memory.c:2341
> >  its_pages_protect arch/x86/kernel/alternative.c:168 [inline]
> >  its_fini_core arch/x86/kernel/alternative.c:175 [inline]
> >  alternative_instructions+0x95/0x100 arch/x86/kernel/alternative.c:2264
> >  arch_cpu_finalize_init+0xb2/0x1f0 arch/x86/kernel/cpu/common.c:2633
> >  start_kernel+0x310/0x3e0 init/main.c:1153
> >  x86_64_start_reservations+0x24/0x30 arch/x86/kernel/head64.c:310
> >  x86_64_start_kernel+0x137/0x1b0 arch/x86/kernel/head64.c:291
> >  common_startup_64+0x13e/0x157
> >  </TASK>
> > pid_max: default: 32768 minimum: 301
> > landlock: Up and running.
> > Yama: becoming mindful.
> > TOMOYO Linux initialized
> > AppArmor: AppArmor initialized
> > LSM support for eBPF active
> > Dentry cache hash table entries: 1048576 (order: 11, 8388608 bytes, vmalloc hugepage)
> > Inode-cache hash table entries: 524288 (order: 10, 4194304 bytes, vmalloc hugepage)
> > Mount-cache hash table entries: 16384 (order: 5, 131072 bytes, vmalloc)
> > Mountpoint-cache hash table entries: 16384 (order: 5, 131072 bytes, vmalloc)
> > VFS: Finished mounting rootfs on nullfs
> > Running RCU synchronous self tests
> > Running RCU synchronous self tests
> > numa_add_cpu cpu 1 node 0: mask now 0-1
> > numa_add_cpu cpu 1 node 1: mask now 0-1
> > 
> > 
> > ---
> > This report is generated by a bot. It may contain errors.
> > See https://goo.gl/tpsmEJ for more information about syzbot.
> > syzbot engineers can be reached at syzkaller@googlegroups.com.
> > 
> > syzbot will keep track of this issue. See:
> > https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
> > 
> > If the report is already addressed, let syzbot know by replying with:
> > #syz fix: exact-commit-title
> > 
> > If you want to overwrite report's subsystems, reply with:
> > #syz set subsystems: new-subsystem
> > (See the list of subsystem names on the web dashboard)
> > 
> > If the report is a duplicate of another one, reply with:
> > #syz dup: exact-subject-of-another-report
> > 
> > If you want to undo deduplication, reply with:
> > #syz undup
> 
> -- 
> Regards/Gruss,
>     Boris.
> 
> https://people.kernel.org/tglx/notes-about-netiquette

-- 
Sincerely yours,
Mike.

^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: [syzbot] [kernel?] linux-next test error: WARNING: locking bug in change_page_attr_set_clr
  2026-07-21 10:35   ` Mike Rapoport
@ 2026-07-21 12:39     ` Lorenzo Stoakes (ARM)
  2026-07-21 13:53       ` Borislav Petkov
  2026-07-21 14:10       ` Lorenzo Stoakes (ARM)
  0 siblings, 2 replies; 11+ messages in thread
From: Lorenzo Stoakes (ARM) @ 2026-07-21 12:39 UTC (permalink / raw)
  To: Mike Rapoport
  Cc: Borislav Petkov, syzbot, Denis V. Lunev, Vishal Moola,
	dave.hansen, hpa, linux-kernel, linux-next, luto, mingo, peterz,
	sfr, syzkaller-bugs, tglx, x86

On Tue, Jul 21, 2026 at 01:35:13PM +0300, Mike Rapoport wrote:
> On Mon, Jul 20, 2026 at 07:24:48PM -0700, Borislav Petkov wrote:
> > Adding all folks who touched this recently.
>
> You forgot Lorenzo ;-)

Yup :) thanks.

OK so this is a screw up with merging.

Two fixes are applied at once here and they are NOT compatible :)

Denis's ([0]) holds a spin lock over the operation during which an older
revision of mine ([1] - current, probable next revision [2]) tries to take a
sleeping mmap lock, hence the report.

But actually my + Denis's fixes, with the latest revision of mine ([2]) are fine
- as I take the mmap lock prior to any spin locks being taken in the (newly
renamed) __cpa_collapse_large_pages().

TL;DR - not a real issue and next will get fixed when the newer version of my
series is taken (with sensible coflict resolution).

And in fact I can see it's fixed at -next master anyway :)

I think actually my + Denis's fixes are actually potentially complimentary, will
reply on that thread about that.

Cheers, Lorenzo

[0]:https://lore.kernel.org/all/20260626163213.2284080-1-den@openvz.org/
[1]:https://lore.kernel.org/linux-mm/20260716-series-vmap-race-fix-v4-0-8c108c4317df@kernel.org/
[2]:https://lore.kernel.org/all/20260714-series-vmap-race-fix-v3-0-b812eccfa0f9@kernel.org/

>
> > On Mon, Jul 20, 2026 at 09:59:25AM -0700, syzbot wrote:
> > > Hello,
> > >
> > > syzbot found the following issue on:
> > >
> > > HEAD commit:    1a1757b76427 Add linux-next specific files for 20260716
> > > git tree:       linux-next
> > > console output: https://syzkaller.appspot.com/x/log.txt?x=16c734b9580000
> > > kernel config:  https://syzkaller.appspot.com/x/.config?x=8d1a274c57796a86
> > > dashboard link: https://syzkaller.appspot.com/bug?extid=ee7ecfcd0e3f185e835a
> > > compiler:       Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
> > >
> > > Downloadable assets:
> > > disk image: https://storage.googleapis.com/syzbot-assets/923ee89ba238/disk-1a1757b7.raw.xz
> > > vmlinux: https://storage.googleapis.com/syzbot-assets/cb34d1bf205c/vmlinux-1a1757b7.xz
> > > kernel image: https://storage.googleapis.com/syzbot-assets/bf183d434c82/bzImage-1a1757b7.xz
> > >
> > > IMPORTANT: if you fix the issue, please add the following tag to the commit:
> > > Reported-by: syzbot+ee7ecfcd0e3f185e835a@syzkaller.appspotmail.com
> > >
> > > clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 19112604462750000 ns
> > > kfence: initialized - using 2097152 bytes for 255 objects at 0xffff88823be00000-0xffff88823c000000
> > > Console: colour VGA+ 80x25
> > > printk: legacy console [ttyS0] enabled
> > > printk: legacy console [ttyS0] enabled
> > > printk: legacy bootconsole [earlyser0] disabled
> > > printk: legacy bootconsole [earlyser0] disabled
> > > Lock dependency validator: Copyright (c) 2006 Red Hat, Inc., Ingo Molnar
> > > ... MAX_LOCKDEP_SUBCLASSES:  8
> > > ... MAX_LOCK_DEPTH:          48
> > > ... MAX_LOCKDEP_KEYS:        8192
> > > ... CLASSHASH_SIZE:          4096
> > > ... MAX_LOCKDEP_ENTRIES:     1048576
> > > ... MAX_LOCKDEP_CHAINS:      1048576
> > > ... CHAINHASH_SIZE:          524288
> > >  memory used by lock dependency info: 106625 kB
> > >  memory used for stack traces: 8320 kB
> > >  per task-struct memory footprint: 1920 bytes
> > > mempolicy: Enabling automatic NUMA balancing. Configure with numa_balancing= or the kernel.numa_balancing sysctl
> > > ACPI: Core revision 20260408
> > > APIC: Switch to symmetric I/O mode setup
> > > x2apic enabled
> > > APIC: Switched APIC routing to: physical x2apic
> > > ..TIMER: vector=0x30 apic1=0 pin1=0 apic2=-1 pin2=-1
> > > clocksource: tsc-early: mask: 0xffffffffffffffff max_cycles: 0x1fb63109b96, max_idle_ns: 440795265316 ns
> > > Calibrating delay loop (skipped) preset value.. 4399.99 BogoMIPS (lpj=21999980)
> > > Last level iTLB entries: 4KB 64, 2MB 8, 4MB 8
> > > Last level dTLB entries: 4KB 64, 2MB 32, 4MB 32, 1GB 4
> > > mitigations: Enabled attack vectors: user_kernel, user_user, guest_host, guest_guest, SMT mitigations: auto
> > > Speculative Store Bypass: Mitigation: Speculative Store Bypass disabled via prctl
> > > Spectre V2 : Mitigation: IBRS
> > > RETBleed: Mitigation: IBRS
> > > ITS: Mitigation: Aligned branch/return thunks
> > > Spectre V2 : User space: Mitigation: STIBP via prctl
> > > MDS: Mitigation: Clear CPU buffers
> > > TAA: Mitigation: Clear CPU buffers
> > > MMIO Stale Data: Vulnerable: Clear CPU buffers attempted, no microcode
> > > Spectre V1 : Mitigation: usercopy/swapgs barriers and __user pointer sanitization
> > > Spectre V2 : Spectre v2 / SpectreRSB: Filling RSB on context switch and VMEXIT
> > > Spectre V2 : Enabling IBPB for BPF
> > > Spectre V2 : mitigation: Enabling conditional Indirect Branch Prediction Barrier
> > > active return thunk: its_return_thunk
> > > Spectre V2 : Spectre BHI mitigation: SW BHB clearing on syscall and VM exit
> > > x86/fpu: Supporting XSAVE feature 0x001: 'x87 floating point registers'
> > > x86/fpu: Supporting XSAVE feature 0x002: 'SSE registers'
> > > x86/fpu: Supporting XSAVE feature 0x004: 'AVX registers'
> > > x86/fpu: xstate_offset[2]:  576, xstate_sizes[2]:  256
> > > x86/fpu: Enabled xstate features 0x7, context size is 832 bytes, using 'standard' format.
> > >
> > > =============================
> > > [ BUG: Invalid wait context ]
> > > syzkaller #0 Not tainted
> > > -----------------------------
> > > swapper/0/0 is trying to lock:
> > > ffffffff8f088c78 ((init_mm).mmap_lock){....}-{4:4}, at: mmap_read_lock include/linux/mmap_lock.h:600 [inline]
> > > ffffffff8f088c78 ((init_mm).mmap_lock){....}-{4:4}, at: class_mmap_read_lock_constructor include/linux/mmap_lock.h:631 [inline]
> > > ffffffff8f088c78 ((init_mm).mmap_lock){....}-{4:4}, at: cpa_collapse_large_pages arch/x86/mm/pat/set_memory.c:448 [inline]
> > > ffffffff8f088c78 ((init_mm).mmap_lock){....}-{4:4}, at: cpa_flush arch/x86/mm/pat/set_memory.c:494 [inline]
> > > ffffffff8f088c78 ((init_mm).mmap_lock){....}-{4:4}, at: change_page_attr_set_clr+0xc2c/0x1010 arch/x86/mm/pat/set_memory.c:2142
> > > other info that might help us debug this:
> > > context-{5:5}
> > > locks held by swapper/0/0: 1, last CPU#0:
> > >  #0: ffffffff8edc2078 (cpa_lock){+.+.}-{3:3}, at: spin_lock include/linux/spinlock.h:342 [inline]
> > >  #0: ffffffff8edc2078 (cpa_lock){+.+.}-{3:3}, at: cpa_collapse_large_pages arch/x86/mm/pat/set_memory.c:421 [inline]
> > >  #0: ffffffff8edc2078 (cpa_lock){+.+.}-{3:3}, at: cpa_flush arch/x86/mm/pat/set_memory.c:494 [inline]
> > >  #0: ffffffff8edc2078 (cpa_lock){+.+.}-{3:3}, at: change_page_attr_set_clr+0x967/0x1010 arch/x86/mm/pat/set_memory.c:2142
> > > stack backtrace:
> > > CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT(full)
> > > Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/25/2026
> > > Call Trace:
> > >  <TASK>
> > >  dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120
> > >  print_lock_invalid_wait_context kernel/locking/lockdep.c:4846 [inline]
> > >  check_wait_context kernel/locking/lockdep.c:4918 [inline]
> > >  __lock_acquire+0xef0/0x2e50 kernel/locking/lockdep.c:5204
> > >  lock_acquire+0x115/0x350 kernel/locking/lockdep.c:5906
> > >  down_read+0x4a/0x330 kernel/locking/rwsem.c:1574
> > >  mmap_read_lock include/linux/mmap_lock.h:600 [inline]
> > >  class_mmap_read_lock_constructor include/linux/mmap_lock.h:631 [inline]
> > >  cpa_collapse_large_pages arch/x86/mm/pat/set_memory.c:448 [inline]
> > >  cpa_flush arch/x86/mm/pat/set_memory.c:494 [inline]
> > >  change_page_attr_set_clr+0xc2c/0x1010 arch/x86/mm/pat/set_memory.c:2142
> > >  set_memory_rox+0xbe/0x100 arch/x86/mm/pat/set_memory.c:2341
> > >  its_pages_protect arch/x86/kernel/alternative.c:168 [inline]
> > >  its_fini_core arch/x86/kernel/alternative.c:175 [inline]
> > >  alternative_instructions+0x95/0x100 arch/x86/kernel/alternative.c:2264
> > >  arch_cpu_finalize_init+0xb2/0x1f0 arch/x86/kernel/cpu/common.c:2633
> > >  start_kernel+0x310/0x3e0 init/main.c:1153
> > >  x86_64_start_reservations+0x24/0x30 arch/x86/kernel/head64.c:310
> > >  x86_64_start_kernel+0x137/0x1b0 arch/x86/kernel/head64.c:291
> > >  common_startup_64+0x13e/0x157
> > >  </TASK>
> > > pid_max: default: 32768 minimum: 301
> > > landlock: Up and running.
> > > Yama: becoming mindful.
> > > TOMOYO Linux initialized
> > > AppArmor: AppArmor initialized
> > > LSM support for eBPF active
> > > Dentry cache hash table entries: 1048576 (order: 11, 8388608 bytes, vmalloc hugepage)
> > > Inode-cache hash table entries: 524288 (order: 10, 4194304 bytes, vmalloc hugepage)
> > > Mount-cache hash table entries: 16384 (order: 5, 131072 bytes, vmalloc)
> > > Mountpoint-cache hash table entries: 16384 (order: 5, 131072 bytes, vmalloc)
> > > VFS: Finished mounting rootfs on nullfs
> > > Running RCU synchronous self tests
> > > Running RCU synchronous self tests
> > > numa_add_cpu cpu 1 node 0: mask now 0-1
> > > numa_add_cpu cpu 1 node 1: mask now 0-1
> > >
> > >
> > > ---
> > > This report is generated by a bot. It may contain errors.
> > > See https://goo.gl/tpsmEJ for more information about syzbot.
> > > syzbot engineers can be reached at syzkaller@googlegroups.com.
> > >
> > > syzbot will keep track of this issue. See:
> > > https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
> > >
> > > If the report is already addressed, let syzbot know by replying with:
> > > #syz fix: exact-commit-title
> > >
> > > If you want to overwrite report's subsystems, reply with:
> > > #syz set subsystems: new-subsystem
> > > (See the list of subsystem names on the web dashboard)
> > >
> > > If the report is a duplicate of another one, reply with:
> > > #syz dup: exact-subject-of-another-report
> > >
> > > If you want to undo deduplication, reply with:
> > > #syz undup
> >
> > --
> > Regards/Gruss,
> >     Boris.
> >
> > https://people.kernel.org/tglx/notes-about-netiquette
>
> --
> Sincerely yours,
> Mike.

^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: [syzbot] [kernel?] linux-next test error: WARNING: locking bug in change_page_attr_set_clr
  2026-07-21 12:39     ` Lorenzo Stoakes (ARM)
@ 2026-07-21 13:53       ` Borislav Petkov
  2026-07-21 14:03         ` Lorenzo Stoakes (ARM)
  2026-07-21 14:10       ` Lorenzo Stoakes (ARM)
  1 sibling, 1 reply; 11+ messages in thread
From: Borislav Petkov @ 2026-07-21 13:53 UTC (permalink / raw)
  To: Lorenzo Stoakes (ARM)
  Cc: Mike Rapoport, syzbot, Denis V. Lunev, Vishal Moola, dave.hansen,
	hpa, linux-kernel, linux-next, luto, mingo, peterz, sfr,
	syzkaller-bugs, tglx, x86

On Tue, Jul 21, 2026 at 01:39:45PM +0100, Lorenzo Stoakes (ARM) wrote:
> OK so this is a screw up with merging.
> 
> Two fixes are applied at once here and they are NOT compatible :)
> 
> Denis's ([0]) holds a spin lock over the operation during which an older
> revision of mine ([1] - current, probable next revision [2]) tries to take a
> sleeping mmap lock, hence the report.

Lemme guess: if those were merged by the same tree - tip - where arch/x86/
changes belong, we would've caught it, right?

Pff.

-- 
Regards/Gruss,
    Boris.

https://people.kernel.org/tglx/notes-about-netiquette

^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: [syzbot] [kernel?] linux-next test error: WARNING: locking bug in change_page_attr_set_clr
  2026-07-21 13:53       ` Borislav Petkov
@ 2026-07-21 14:03         ` Lorenzo Stoakes (ARM)
  2026-07-21 15:05           ` Borislav Petkov
  0 siblings, 1 reply; 11+ messages in thread
From: Lorenzo Stoakes (ARM) @ 2026-07-21 14:03 UTC (permalink / raw)
  To: Borislav Petkov
  Cc: Mike Rapoport, syzbot, Denis V. Lunev, Vishal Moola, dave.hansen,
	hpa, linux-kernel, linux-next, luto, mingo, peterz, sfr,
	syzkaller-bugs, tglx, x86

On Tue, Jul 21, 2026 at 06:53:23AM -0700, Borislav Petkov wrote:
> On Tue, Jul 21, 2026 at 01:39:45PM +0100, Lorenzo Stoakes (ARM) wrote:
> > OK so this is a screw up with merging.
> >
> > Two fixes are applied at once here and they are NOT compatible :)
> >
> > Denis's ([0]) holds a spin lock over the operation during which an older
> > revision of mine ([1] - current, probable next revision [2]) tries to take a
> > sleeping mmap lock, hence the report.
>
> Lemme guess: if those were merged by the same tree - tip - where arch/x86/
> changes belong, we would've caught it, right?
>
> Pff.

You mean the series that changes core mm and has strict dependencies on core mm
changes and solves issues elsewhere than x86 CPA, that one should have gone
through the x86 tree?

>
> --
> Regards/Gruss,
>     Boris.
>
> https://people.kernel.org/tglx/notes-about-netiquette

Thanks, Lorenzo

^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: [syzbot] [kernel?] linux-next test error: WARNING: locking bug in change_page_attr_set_clr
  2026-07-21 12:39     ` Lorenzo Stoakes (ARM)
  2026-07-21 13:53       ` Borislav Petkov
@ 2026-07-21 14:10       ` Lorenzo Stoakes (ARM)
  1 sibling, 0 replies; 11+ messages in thread
From: Lorenzo Stoakes (ARM) @ 2026-07-21 14:10 UTC (permalink / raw)
  To: Mike Rapoport
  Cc: Borislav Petkov, syzbot, Denis V. Lunev, Vishal Moola,
	dave.hansen, hpa, linux-kernel, linux-next, luto, mingo, peterz,
	sfr, syzkaller-bugs, tglx, x86

On Tue, Jul 21, 2026 at 01:39:51PM +0100, Lorenzo Stoakes (ARM) wrote:
> On Tue, Jul 21, 2026 at 01:35:13PM +0300, Mike Rapoport wrote:
> > On Mon, Jul 20, 2026 at 07:24:48PM -0700, Borislav Petkov wrote:
> > > Adding all folks who touched this recently.
> >
> > You forgot Lorenzo ;-)
>
> Yup :) thanks.
>
> OK so this is a screw up with merging.

Well nobody told me there was a v2 ([3]), that it was taken or thought to cc- me on
anything, so that goes some way towards explaining how this happened :)

[3]:https://lore.kernel.org/all/20260715183453.2381141-1-den@openvz.org/

Anyway as per below TL;DR is the latest revision of my series does NOT conflict
with this series and the HEAD of linux-next _is fixed_.

The commit message of that v2 is now not really accurate but it does solve
_another_ possible debug_pagealloc race.

Thanks, Lorenzo

>
> Two fixes are applied at once here and they are NOT compatible :)
>
> Denis's ([0]) holds a spin lock over the operation during which an older
> revision of mine ([1] - current, probable next revision [2]) tries to take a
> sleeping mmap lock, hence the report.
>
> But actually my + Denis's fixes, with the latest revision of mine ([2]) are fine
> - as I take the mmap lock prior to any spin locks being taken in the (newly
> renamed) __cpa_collapse_large_pages().
>
> TL;DR - not a real issue and next will get fixed when the newer version of my
> series is taken (with sensible coflict resolution).
>
> And in fact I can see it's fixed at -next master anyway :)
>
> I think actually my + Denis's fixes are actually potentially complimentary, will
> reply on that thread about that.
>
> Cheers, Lorenzo
>
> [0]:https://lore.kernel.org/all/20260626163213.2284080-1-den@openvz.org/
> [1]:https://lore.kernel.org/linux-mm/20260716-series-vmap-race-fix-v4-0-8c108c4317df@kernel.org/
> [2]:https://lore.kernel.org/all/20260714-series-vmap-race-fix-v3-0-b812eccfa0f9@kernel.org/
>
> >
> > > On Mon, Jul 20, 2026 at 09:59:25AM -0700, syzbot wrote:
> > > > Hello,
> > > >
> > > > syzbot found the following issue on:
> > > >
> > > > HEAD commit:    1a1757b76427 Add linux-next specific files for 20260716
> > > > git tree:       linux-next
> > > > console output: https://syzkaller.appspot.com/x/log.txt?x=16c734b9580000
> > > > kernel config:  https://syzkaller.appspot.com/x/.config?x=8d1a274c57796a86
> > > > dashboard link: https://syzkaller.appspot.com/bug?extid=ee7ecfcd0e3f185e835a
> > > > compiler:       Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
> > > >
> > > > Downloadable assets:
> > > > disk image: https://storage.googleapis.com/syzbot-assets/923ee89ba238/disk-1a1757b7.raw.xz
> > > > vmlinux: https://storage.googleapis.com/syzbot-assets/cb34d1bf205c/vmlinux-1a1757b7.xz
> > > > kernel image: https://storage.googleapis.com/syzbot-assets/bf183d434c82/bzImage-1a1757b7.xz
> > > >
> > > > IMPORTANT: if you fix the issue, please add the following tag to the commit:
> > > > Reported-by: syzbot+ee7ecfcd0e3f185e835a@syzkaller.appspotmail.com
> > > >
> > > > clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 19112604462750000 ns
> > > > kfence: initialized - using 2097152 bytes for 255 objects at 0xffff88823be00000-0xffff88823c000000
> > > > Console: colour VGA+ 80x25
> > > > printk: legacy console [ttyS0] enabled
> > > > printk: legacy console [ttyS0] enabled
> > > > printk: legacy bootconsole [earlyser0] disabled
> > > > printk: legacy bootconsole [earlyser0] disabled
> > > > Lock dependency validator: Copyright (c) 2006 Red Hat, Inc., Ingo Molnar
> > > > ... MAX_LOCKDEP_SUBCLASSES:  8
> > > > ... MAX_LOCK_DEPTH:          48
> > > > ... MAX_LOCKDEP_KEYS:        8192
> > > > ... CLASSHASH_SIZE:          4096
> > > > ... MAX_LOCKDEP_ENTRIES:     1048576
> > > > ... MAX_LOCKDEP_CHAINS:      1048576
> > > > ... CHAINHASH_SIZE:          524288
> > > >  memory used by lock dependency info: 106625 kB
> > > >  memory used for stack traces: 8320 kB
> > > >  per task-struct memory footprint: 1920 bytes
> > > > mempolicy: Enabling automatic NUMA balancing. Configure with numa_balancing= or the kernel.numa_balancing sysctl
> > > > ACPI: Core revision 20260408
> > > > APIC: Switch to symmetric I/O mode setup
> > > > x2apic enabled
> > > > APIC: Switched APIC routing to: physical x2apic
> > > > ..TIMER: vector=0x30 apic1=0 pin1=0 apic2=-1 pin2=-1
> > > > clocksource: tsc-early: mask: 0xffffffffffffffff max_cycles: 0x1fb63109b96, max_idle_ns: 440795265316 ns
> > > > Calibrating delay loop (skipped) preset value.. 4399.99 BogoMIPS (lpj=21999980)
> > > > Last level iTLB entries: 4KB 64, 2MB 8, 4MB 8
> > > > Last level dTLB entries: 4KB 64, 2MB 32, 4MB 32, 1GB 4
> > > > mitigations: Enabled attack vectors: user_kernel, user_user, guest_host, guest_guest, SMT mitigations: auto
> > > > Speculative Store Bypass: Mitigation: Speculative Store Bypass disabled via prctl
> > > > Spectre V2 : Mitigation: IBRS
> > > > RETBleed: Mitigation: IBRS
> > > > ITS: Mitigation: Aligned branch/return thunks
> > > > Spectre V2 : User space: Mitigation: STIBP via prctl
> > > > MDS: Mitigation: Clear CPU buffers
> > > > TAA: Mitigation: Clear CPU buffers
> > > > MMIO Stale Data: Vulnerable: Clear CPU buffers attempted, no microcode
> > > > Spectre V1 : Mitigation: usercopy/swapgs barriers and __user pointer sanitization
> > > > Spectre V2 : Spectre v2 / SpectreRSB: Filling RSB on context switch and VMEXIT
> > > > Spectre V2 : Enabling IBPB for BPF
> > > > Spectre V2 : mitigation: Enabling conditional Indirect Branch Prediction Barrier
> > > > active return thunk: its_return_thunk
> > > > Spectre V2 : Spectre BHI mitigation: SW BHB clearing on syscall and VM exit
> > > > x86/fpu: Supporting XSAVE feature 0x001: 'x87 floating point registers'
> > > > x86/fpu: Supporting XSAVE feature 0x002: 'SSE registers'
> > > > x86/fpu: Supporting XSAVE feature 0x004: 'AVX registers'
> > > > x86/fpu: xstate_offset[2]:  576, xstate_sizes[2]:  256
> > > > x86/fpu: Enabled xstate features 0x7, context size is 832 bytes, using 'standard' format.
> > > >
> > > > =============================
> > > > [ BUG: Invalid wait context ]
> > > > syzkaller #0 Not tainted
> > > > -----------------------------
> > > > swapper/0/0 is trying to lock:
> > > > ffffffff8f088c78 ((init_mm).mmap_lock){....}-{4:4}, at: mmap_read_lock include/linux/mmap_lock.h:600 [inline]
> > > > ffffffff8f088c78 ((init_mm).mmap_lock){....}-{4:4}, at: class_mmap_read_lock_constructor include/linux/mmap_lock.h:631 [inline]
> > > > ffffffff8f088c78 ((init_mm).mmap_lock){....}-{4:4}, at: cpa_collapse_large_pages arch/x86/mm/pat/set_memory.c:448 [inline]
> > > > ffffffff8f088c78 ((init_mm).mmap_lock){....}-{4:4}, at: cpa_flush arch/x86/mm/pat/set_memory.c:494 [inline]
> > > > ffffffff8f088c78 ((init_mm).mmap_lock){....}-{4:4}, at: change_page_attr_set_clr+0xc2c/0x1010 arch/x86/mm/pat/set_memory.c:2142
> > > > other info that might help us debug this:
> > > > context-{5:5}
> > > > locks held by swapper/0/0: 1, last CPU#0:
> > > >  #0: ffffffff8edc2078 (cpa_lock){+.+.}-{3:3}, at: spin_lock include/linux/spinlock.h:342 [inline]
> > > >  #0: ffffffff8edc2078 (cpa_lock){+.+.}-{3:3}, at: cpa_collapse_large_pages arch/x86/mm/pat/set_memory.c:421 [inline]
> > > >  #0: ffffffff8edc2078 (cpa_lock){+.+.}-{3:3}, at: cpa_flush arch/x86/mm/pat/set_memory.c:494 [inline]
> > > >  #0: ffffffff8edc2078 (cpa_lock){+.+.}-{3:3}, at: change_page_attr_set_clr+0x967/0x1010 arch/x86/mm/pat/set_memory.c:2142
> > > > stack backtrace:
> > > > CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT(full)
> > > > Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/25/2026
> > > > Call Trace:
> > > >  <TASK>
> > > >  dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120
> > > >  print_lock_invalid_wait_context kernel/locking/lockdep.c:4846 [inline]
> > > >  check_wait_context kernel/locking/lockdep.c:4918 [inline]
> > > >  __lock_acquire+0xef0/0x2e50 kernel/locking/lockdep.c:5204
> > > >  lock_acquire+0x115/0x350 kernel/locking/lockdep.c:5906
> > > >  down_read+0x4a/0x330 kernel/locking/rwsem.c:1574
> > > >  mmap_read_lock include/linux/mmap_lock.h:600 [inline]
> > > >  class_mmap_read_lock_constructor include/linux/mmap_lock.h:631 [inline]
> > > >  cpa_collapse_large_pages arch/x86/mm/pat/set_memory.c:448 [inline]
> > > >  cpa_flush arch/x86/mm/pat/set_memory.c:494 [inline]
> > > >  change_page_attr_set_clr+0xc2c/0x1010 arch/x86/mm/pat/set_memory.c:2142
> > > >  set_memory_rox+0xbe/0x100 arch/x86/mm/pat/set_memory.c:2341
> > > >  its_pages_protect arch/x86/kernel/alternative.c:168 [inline]
> > > >  its_fini_core arch/x86/kernel/alternative.c:175 [inline]
> > > >  alternative_instructions+0x95/0x100 arch/x86/kernel/alternative.c:2264
> > > >  arch_cpu_finalize_init+0xb2/0x1f0 arch/x86/kernel/cpu/common.c:2633
> > > >  start_kernel+0x310/0x3e0 init/main.c:1153
> > > >  x86_64_start_reservations+0x24/0x30 arch/x86/kernel/head64.c:310
> > > >  x86_64_start_kernel+0x137/0x1b0 arch/x86/kernel/head64.c:291
> > > >  common_startup_64+0x13e/0x157
> > > >  </TASK>
> > > > pid_max: default: 32768 minimum: 301
> > > > landlock: Up and running.
> > > > Yama: becoming mindful.
> > > > TOMOYO Linux initialized
> > > > AppArmor: AppArmor initialized
> > > > LSM support for eBPF active
> > > > Dentry cache hash table entries: 1048576 (order: 11, 8388608 bytes, vmalloc hugepage)
> > > > Inode-cache hash table entries: 524288 (order: 10, 4194304 bytes, vmalloc hugepage)
> > > > Mount-cache hash table entries: 16384 (order: 5, 131072 bytes, vmalloc)
> > > > Mountpoint-cache hash table entries: 16384 (order: 5, 131072 bytes, vmalloc)
> > > > VFS: Finished mounting rootfs on nullfs
> > > > Running RCU synchronous self tests
> > > > Running RCU synchronous self tests
> > > > numa_add_cpu cpu 1 node 0: mask now 0-1
> > > > numa_add_cpu cpu 1 node 1: mask now 0-1
> > > >
> > > >
> > > > ---
> > > > This report is generated by a bot. It may contain errors.
> > > > See https://goo.gl/tpsmEJ for more information about syzbot.
> > > > syzbot engineers can be reached at syzkaller@googlegroups.com.
> > > >
> > > > syzbot will keep track of this issue. See:
> > > > https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
> > > >
> > > > If the report is already addressed, let syzbot know by replying with:
> > > > #syz fix: exact-commit-title
> > > >
> > > > If you want to overwrite report's subsystems, reply with:
> > > > #syz set subsystems: new-subsystem
> > > > (See the list of subsystem names on the web dashboard)
> > > >
> > > > If the report is a duplicate of another one, reply with:
> > > > #syz dup: exact-subject-of-another-report
> > > >
> > > > If you want to undo deduplication, reply with:
> > > > #syz undup
> > >
> > > --
> > > Regards/Gruss,
> > >     Boris.
> > >
> > > https://people.kernel.org/tglx/notes-about-netiquette
> >
> > --
> > Sincerely yours,
> > Mike.

^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: [syzbot] [kernel?] linux-next test error: WARNING: locking bug in change_page_attr_set_clr
       [not found] <CABWoTMsoHK3wOK2bNXEpWdqU5SxE2WcmdTDnJN3V5jybKSNLpQ@mail.gmail.com>
@ 2026-07-21 14:18 ` syzbot
  0 siblings, 0 replies; 11+ messages in thread
From: syzbot @ 2026-07-21 14:18 UTC (permalink / raw)
  To: hokage.newbie, linux-kernel, syzkaller-bugs

Hello,

syzbot tried to test the proposed patch but the build/boot failed:

32][    T1] software IO TLB: mapped [mem 0x00000000b4400000-0x00000000b8400000] (64MB)
[    4.888102][    T1] ACPI: bus type thunderbolt registered
[    4.903297][   T60] kworker/u8:4 (60) used greatest stack depth: 27872 bytes left
[    4.904101][    T1] RAPL PMU: API unit is 2^-32 Joules, 0 fixed counters, 10737418240 ms ovfl timer
[    4.944864][    T1] kvm_amd: CPU 1 isn't AMD or Hygon
[    4.951234][    T1] clocksource: tsc: mask: 0xffffffffffffffff max_cycles: 0x1fb63109b96, max_idle_ns: 440795265316 ns
[    4.965570][    T1] clocksource: Switched to clocksource tsc
[    4.982264][   T71] kworker/u8:1 (71) used greatest stack depth: 27488 bytes left
[    5.006653][    T1] Initialise system trusted keyrings
[    5.014294][    T1] workingset: timestamp_bits=40 (anon: 35) max_order=21 bucket_order=0 (anon: 0)
[    5.031422][    T1] DLM installed
[    5.041336][    T1] squashfs: version 4.0 (2009/01/31) Phillip Lougher
[    5.055213][    T1] NFS: Registering the id_resolver key type
[    5.061906][    T1] Key type id_resolver registered
[    5.068568][    T1] Key type id_legacy registered
[    5.074143][    T1] nfs4filelayout_init: NFSv4 File Layout Driver Registering...
[    5.082519][    T1] nfs4flexfilelayout_init: NFSv4 Flexfile Layout Driver Registering...
[    5.094470][    T1] smbdirect: subsystem loading...
[    5.104567][    T1] smbdirect: subsystem loaded
[    5.125689][    T1] Key type cifs.spnego registered
[    5.132028][    T1] Key type cifs.idmap registered
[    5.141159][    T1] ntfs3: Enabled Linux POSIX ACLs support
[    5.147855][    T1] ntfs3: Read-only LZX/Xpress compression included
[    5.155971][    T1] jffs2: version 2.2. (NAND) (SUMMARY)  © 2001-2006 Red Hat, Inc.
[    5.166871][    T1] romfs: ROMFS MTD (C) 2007 Red Hat, Inc.
[    5.173528][    T1] QNX4 filesystem 0.2.3 registered.
[    5.179103][    T1] qnx6: QNX6 filesystem 1.0.0 registered.
[    5.186758][    T1] fuse: init (API version 7.45)
[    5.196303][    T1] orangefs_debugfs_init: called with debug mask: :none: :0:
[    5.206125][    T1] orangefs_init: module version upstream loaded
[    5.214242][    T1] JFS: nTxBlock = 8192, nTxLock = 65536
[    5.237090][    T1] SGI XFS with ACLs, security attributes, realtime, scrub, repair, quota, no debug enabled
[    5.255483][    T1] 9p: Installing v9fs 9p2000 file system support
[    5.263388][    T1] NILFS version 2 loaded
[    5.267905][    T1] befs: version: 0.9.3
[    5.272893][    T1] ocfs2: Registered cluster interface o2cb
[    5.280833][    T1] ocfs2: Registered cluster interface user
[    5.289020][    T1] OCFS2 User DLM kernel interface loaded
[    5.314195][    T1] gfs2: GFS2 installed
[    5.331699][    T1] ceph: loaded (mds proto 32)
[    5.345000][    T1] NET: Registered PF_ALG protocol family
[    5.351259][    T1] async_tx: api initialized (async)
[    5.357277][    T1] Key type asymmetric registered
[    5.362670][    T1] Asymmetric key parser 'x509' registered
[    5.369174][    T1] Asymmetric key parser 'pkcs8' registered
[    5.375663][    T1] Key type pkcs7_test registered
[    5.382339][    T1] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 239)
[    5.394050][    T1] io scheduler mq-deadline registered
[    5.400204][    T1] io scheduler kyber registered
[    5.405853][    T1] io scheduler bfq registered
[    5.412399][    T1] raid6: skipped pq benchmark and selected avx2x4
[    5.436280][    T1] input: Power Button as /devices/platform/LNXPWRBN:00/input/input0
[    5.448299][    T1] ACPI: button: Power Button [PWRF]
[    5.456737][    T1] input: Sleep Button as /devices/platform/LNXSLPBN:00/input/input1
[    5.466430][    T1] ACPI: button: Sleep Button [SLPF]
[    5.487530][    T1] ioatdma: Intel(R) QuickData Technology Driver 5.00
[    5.514416][   T10] ACPI: \_SB_.LNKC: Enabled at IRQ 11
[    5.520919][   T10] virtio-pci 0000:00:03.0: virtio_pci: leaving for legacy driver
[    5.557828][   T10] ACPI: \_SB_.LNKD: Enabled at IRQ 10
[    5.563680][   T10] virtio-pci 0000:00:04.0: virtio_pci: leaving for legacy driver
[    5.602085][   T10] ACPI: \_SB_.LNKB: Enabled at IRQ 10
[    5.608039][   T10] virtio-pci 0000:00:06.0: virtio_pci: leaving for legacy driver
[    5.634149][   T10] virtio-pci 0000:00:07.0: virtio_pci: leaving for legacy driver
[    5.700761][  T228] kworker/u8:3 (228) used greatest stack depth: 27168 bytes left
[    6.180975][    T1] N_HDLC line discipline registered with maxframe=4096
[    6.191915][    T1] Serial: 8250/16550 driver, 4 ports, IRQ sharing enabled
[    6.205395][    T1] 00:02: ttyS0 at I/O 0x3f8 (irq = 4, base_baud = 115200) is a 16550A
[    6.228327][    T1] 00:03: ttyS1 at I/O 0x2f8 (irq = 3, base_baud = 115200) is a 16550A
[    6.250174][    T1] 00:04: ttyS2 at I/O 0x3e8 (irq = 6, base_baud = 115200) is a 16550A
[    6.272648][    T1] 00:05: ttyS3 at I/O 0x2e8 (irq = 7, base_baud = 115200) is a 16550A
[    6.304382][    T1] Non-volatile memory driver v1.3
[    6.342173][    T1] usbcore: registered new interface driver xillyusb
[    6.355000][    T1] ACPI: bus type drm_connector registered
[    6.368742][    T1] [drm] Initialized vgem 1.0.0 for vgem on minor 0
[    6.381964][    T1] ------------[ cut here ]------------
[    6.389957][    T1] [PLANE:35:plane-0] pixel format with alpha exposed but blend mode not setup
[    6.390002][    T1] WARNING: drivers/gpu/drm/drm_mode_config.c:873 at drm_mode_config_validate+0x1c6a/0x1e60, CPU#1: swapper/0/1
[    6.413950][    T1] Modules linked in:
[    6.417986][    T1] CPU: 1 UID: 0 PID: 1 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT(full) 
[    6.428539][    T1] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/25/2026
[    6.440056][    T1] RIP: 0010:drm_mode_config_validate+0x1cab/0x1e60
[    6.447079][    T1] Code: 0f 85 ae 00 00 00 4d 8d 77 10 8b 6d 00 4c 89 f0 48 c1 e8 03 80 3c 18 00 74 08 4c 89 f7 e8 3d fe 9f fc 49 8b 16 4c 89 ef 89 ee <67> 48 0f b9 3a eb 05 e8 d9 f9 31 fc 49 bd 00 00 00 00 00 fc ff df
[    6.469289][    T1] RSP: 0000:ffffc90000067810 EFLAGS: 00010246
[    6.476012][    T1] RAX: 1ffff11004e60208 RBX: dffffc0000000000 RCX: ffff88801d6fddc0
[    6.484649][    T1] RDX: ffff888026f33b20 RSI: 0000000000000023 RDI: ffffffff90a4f5e0
[    6.493076][    T1] RBP: 0000000000000023 R08: ffff88802442cc7b R09: 1ffff1100488598f
[    6.502490][    T1] R10: dffffc0000000000 R11: ffffed1004885990 R12: dffffc0000000000
[    6.511445][    T1] R13: ffffffff90a4f5e0 R14: ffff888027301040 R15: ffff888027301030
[    6.520347][    T1] FS:  0000000000000000(0000) GS:ffff8881249f2000(0000) knlGS:0000000000000000
[    6.530605][    T1] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[    6.537677][    T1] CR2: 0000000000000000 CR3: 000000000ed46000 CR4: 00000000003526f0
[    6.546098][    T1] Call Trace:
[    6.549499][    T1]  <TASK>
[    6.552592][    T1]  ? debugfs_create_file_full+0x3f/0x60
[    6.559084][    T1]  drm_dev_register+0x7c/0xd80
[    6.564258][    T1]  vkms_create+0x40d/0x4f0
[    6.569092][    T1]  ? __pfx_vkms_init+0x10/0x10
[    6.574598][    T1]  vkms_init+0x57/0x80
[    6.579550][    T1]  do_one_initcall+0x250/0x870
[    6.584760][    T1]  ? __pfx_vkms_init+0x10/0x10
[    6.589758][    T1]  ? __pfx_do_one_initcall+0x10/0x10
[    6.595223][    T1]  ? rcu_is_watching+0x15/0xb0
[    6.600257][    T1]  ? __pfx___schedule+0x10/0x10
[    6.605207][    T1]  ? trace_irq_enable+0x3b/0x140
[    6.611281][    T1]  ? rcu_is_watching+0x15/0xb0
[    6.617176][    T1]  ? trace_irq_enable+0x3b/0x140
[    6.622454][    T1]  ? irqentry_exit+0x218/0x8f0
[    6.627770][    T1]  ? trace_irq_disable+0x3b/0x140
[    6.633035][    T1]  ? strlen+0x32/0x70
[    6.637533][    T1]  ? next_arg+0x4a0/0x5e0
[    6.642383][    T1]  ? parameq+0x14d/0x170
[    6.647198][    T1]  ? parse_args+0x9c3/0xad0
[    6.651995][    T1]  ? rcu_is_watching+0x15/0xb0
[    6.657578][    T1]  do_initcall_level+0x10a/0x1a0
[    6.662915][    T1]  ? kernel_init+0x22/0x1d0
[    6.667762][    T1]  do_initcalls+0x59/0xa0
[    6.672657][    T1]  kernel_init_freeable+0x29d/0x3e0
[    6.678496][    T1]  ? __pfx_kernel_init+0x10/0x10
[    6.684003][    T1]  kernel_init+0x22/0x1d0
[    6.688963][    T1]  ? __pfx_kernel_init+0x10/0x10
[    6.694339][    T1]  ret_from_fork+0x514/0xb70
[    6.699211][    T1]  ? __pfx_ret_from_fork+0x10/0x10
[    6.705620][    T1]  ? __switch_to+0xc89/0x1420
[    6.710526][    T1]  ? __pfx_kernel_init+0x10/0x10
[    6.715879][    T1]  ret_from_fork_asm+0x1a/0x30
[    6.721049][    T1]  </TASK>
[    6.724384][    T1] Kernel panic - not syncing: kernel: panic_on_warn set ...
[    6.725855][    T1] CPU: 1 UID: 0 PID: 1 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT(full) 
[    6.725855][    T1] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/25/2026
[    6.725855][    T1] Call Trace:
[    6.725855][    T1]  <TASK>
[    6.725855][    T1]  vpanic+0x56c/0xa60
[    6.725855][    T1]  ? __pfx__printk+0x10/0x10
[    6.725855][    T1]  ? __pfx_vpanic+0x10/0x10
[    6.725855][    T1]  ? is_bpf_text_address+0x292/0x2b0
[    6.725855][    T1]  ? is_bpf_text_address+0x26/0x2b0
[    6.725855][    T1]  panic+0xc5/0xd0
[    6.725855][    T1]  ? __pfx_panic+0x10/0x10
[    6.725855][    T1]  ? ret_from_fork_asm+0x1a/0x30
[    6.725855][    T1]  __warn+0x315/0x4c0
[    6.725855][    T1]  ? drm_mode_config_validate+0x1c6a/0x1e60
[    6.725855][    T1]  ? drm_mode_config_validate+0x1c6a/0x1e60
[    6.725855][    T1]  __report_bug+0x276/0x570
[    6.725855][    T1]  ? drm_mode_config_validate+0x1c6a/0x1e60
[    6.725855][    T1]  ? __pfx___report_bug+0x10/0x10
[    6.725855][    T1]  ? __pfx_inode_set_ctime_to_ts+0x10/0x10
[    6.725855][    T1]  ? ktime_get_coarse_real_ts64_mg+0x59/0x1e0
[    6.725855][    T1]  ? seqcount_lockdep_reader_access+0xea/0x100
[    6.725855][    T1]  ? ktime_get_coarse_real_ts64_mg+0x1c5/0x1e0
[    6.725855][    T1]  report_bug_entry+0x19a/0x290
[    6.725855][    T1]  ? drm_mode_config_validate+0x1cab/0x1e60
[    6.725855][    T1]  ? drm_mode_config_validate+0x1cb0/0x1e60
[    6.725855][    T1]  handle_bug+0xce/0x200
[    6.725855][    T1]  exc_invalid_op+0x1a/0x50
[    6.725855][    T1]  asm_exc_invalid_op+0x1a/0x20
[    6.725855][    T1] RIP: 0010:drm_mode_config_validate+0x1cab/0x1e60
[    6.725855][    T1] Code: 0f 85 ae 00 00 00 4d 8d 77 10 8b 6d 00 4c 89 f0 48 c1 e8 03 80 3c 18 00 74 08 4c 89 f7 e8 3d fe 9f fc 49 8b 16 4c 89 ef 89 ee <67> 48 0f b9 3a eb 05 e8 d9 f9 31 fc 49 bd 00 00 00 00 00 fc ff df
[    6.725855][    T1] RSP: 0000:ffffc90000067810 EFLAGS: 00010246
[    6.725855][    T1] RAX: 1ffff11004e60208 RBX: dffffc0000000000 RCX: ffff88801d6fddc0
[    6.725855][    T1] RDX: ffff888026f33b20 RSI: 0000000000000023 RDI: ffffffff90a4f5e0
[    6.725855][    T1] RBP: 0000000000000023 R08: ffff88802442cc7b R09: 1ffff1100488598f
[    6.725855][    T1] R10: dffffc0000000000 R11: ffffed1004885990 R12: dffffc0000000000
[    6.725855][    T1] R13: ffffffff90a4f5e0 R14: ffff888027301040 R15: ffff888027301030
[    6.725855][    T1]  ? debugfs_create_file_full+0x3f/0x60
[    6.725855][    T1]  drm_dev_register+0x7c/0xd80
[    6.725855][    T1]  vkms_create+0x40d/0x4f0
[    6.725855][    T1]  ? __pfx_vkms_init+0x10/0x10
[    6.725855][    T1]  vkms_init+0x57/0x80
[    6.725855][    T1]  do_one_initcall+0x250/0x870
[    6.725855][    T1]  ? __pfx_vkms_init+0x10/0x10
[    6.725855][    T1]  ? __pfx_do_one_initcall+0x10/0x10
[    6.725855][    T1]  ? rcu_is_watching+0x15/0xb0
[    6.725855][    T1]  ? __pfx___schedule+0x10/0x10
[    6.725855][    T1]  ? trace_irq_enable+0x3b/0x140
[    6.725855][    T1]  ? rcu_is_watching+0x15/0xb0
[    6.725855][    T1]  ? trace_irq_enable+0x3b/0x140
[    6.725855][    T1]  ? irqentry_exit+0x218/0x8f0
[    6.725855][    T1]  ? trace_irq_disable+0x3b/0x140
[    6.725855][    T1]  ? strlen+0x32/0x70
[    6.725855][    T1]  ? next_arg+0x4a0/0x5e0
[    6.725855][    T1]  ? parameq+0x14d/0x170
[    6.725855][    T1]  ? parse_args+0x9c3/0xad0
[    6.725855][    T1]  ? rcu_is_watching+0x15/0xb0
[    6.725855][    T1]  do_initcall_level+0x10a/0x1a0
[    6.725855][    T1]  ? kernel_init+0x22/0x1d0
[    6.725855][    T1]  do_initcalls+0x59/0xa0
[    6.725855][    T1]  kernel_init_freeable+0x29d/0x3e0
[    6.725855][    T1]  ? __pfx_kernel_init+0x10/0x10
[    6.725855][    T1]  kernel_init+0x22/0x1d0
[    6.725855][    T1]  ? __pfx_kernel_init+0x10/0x10
[    6.725855][    T1]  ret_from_fork+0x514/0xb70
[    6.725855][    T1]  ? __pfx_ret_from_fork+0x10/0x10
[    6.725855][    T1]  ? __switch_to+0xc89/0x1420
[    6.725855][    T1]  ? __pfx_kernel_init+0x10/0x10
[    6.725855][    T1]  ret_from_fork_asm+0x1a/0x30
[    6.725855][    T1]  </TASK>
[    6.725855][    T1] Kernel Offset: disabled
[    6.725855][    T1] Rebooting in 86400 seconds..


syzkaller build log:
go env (err=<nil>)
AR='ar'
CC='gcc'
CGO_CFLAGS='-O2 -g'
CGO_CPPFLAGS=''
CGO_CXXFLAGS='-O2 -g'
CGO_ENABLED='1'
CGO_FFLAGS='-O2 -g'
CGO_LDFLAGS='-O2 -g'
CXX='g++'
GCCGO='gccgo'
GO111MODULE='auto'
GOAMD64='v1'
GOARCH='amd64'
GOAUTH='netrc'
GOBIN=''
GOCACHE='/syzkaller/.cache/go-build'
GOCACHEPROG=''
GODEBUG=''
GOENV='/syzkaller/.config/go/env'
GOEXE=''
GOEXPERIMENT=''
GOFIPS140='off'
GOFLAGS=''
GOGCCFLAGS='-fPIC -m64 -pthread -Wl,--no-gc-sections -fmessage-length=0 -ffile-prefix-map=/tmp/go-build2803433996=/tmp/go-build -gno-record-gcc-switches'
GOHOSTARCH='amd64'
GOHOSTOS='linux'
GOINSECURE=''
GOMOD='/syzkaller/jobs-2/linux/gopath/src/github.com/google/syzkaller/go.mod'
GOMODCACHE='/syzkaller/jobs-2/linux/gopath/pkg/mod'
GONOPROXY=''
GONOSUMDB=''
GOOS='linux'
GOPATH='/syzkaller/jobs-2/linux/gopath'
GOPRIVATE=''
GOPROXY='https://proxy.golang.org,direct'
GOROOT='/usr/local/go'
GOSUMDB='sum.golang.org'
GOTELEMETRY='local'
GOTELEMETRYDIR='/syzkaller/.config/go/telemetry'
GOTMPDIR=''
GOTOOLCHAIN='auto'
GOTOOLDIR='/usr/local/go/pkg/tool/linux_amd64'
GOVCS=''
GOVERSION='go1.26.0'
GOWORK=''
PKG_CONFIG='pkg-config'

git status (err=<nil>)
HEAD detached at 7f27c57aff
nothing to commit, working tree clean


tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
go list -f '{{.Stale}}' -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=7f27c57affd8bddc0f76bd42d53ecfc583fc548b -X github.com/google/syzkaller/prog.gitRevisionDate=20260716-202746"  ./sys/syz-sysgen | grep -q false || go install -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=7f27c57affd8bddc0f76bd42d53ecfc583fc548b -X github.com/google/syzkaller/prog.gitRevisionDate=20260716-202746"  ./sys/syz-sysgen
make .descriptions
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
bin/syz-sysgen
touch .descriptions
GOOS=linux GOARCH=amd64 go build -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=7f27c57affd8bddc0f76bd42d53ecfc583fc548b -X github.com/google/syzkaller/prog.gitRevisionDate=20260716-202746"  -o ./bin/linux_amd64/syz-execprog github.com/google/syzkaller/tools/syz-execprog
mkdir -p ./bin/linux_amd64
g++ -o ./bin/linux_amd64/syz-executor executor/executor.cc \
	-m64 -O2 -pthread -Wall -Werror -Wparentheses -Wunused-const-variable -Wframe-larger-than=16384 -Wno-stringop-overflow -Wno-array-bounds -Wno-format-overflow -Wno-unused-but-set-variable -Wno-unused-command-line-argument -static-pie -std=c++17 -I. -Iexecutor/_include   -DGOOS_linux=1 -DGOARCH_amd64=1 \
	-DHOSTGOOS_linux=1 -DGIT_REVISION=\"7f27c57affd8bddc0f76bd42d53ecfc583fc548b\"
/usr/bin/ld: /tmp/cc4dEmS4.o: in function `Connection::Connect(char const*, char const*)':
executor.cc:(.text._ZN10Connection7ConnectEPKcS1_[_ZN10Connection7ConnectEPKcS1_]+0x386): warning: Using 'gethostbyname' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking
./tools/check-syzos.sh 2>/dev/null


Error text is too large and was truncated, full error text is at:
https://syzkaller.appspot.com/x/error.txt?x=178be746580000


Tested on:

commit:         1a1757b7 Add linux-next specific files for 20260716
git tree:       https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git
kernel config:  https://syzkaller.appspot.com/x/.config?x=8d1a274c57796a86
dashboard link: https://syzkaller.appspot.com/bug?extid=ee7ecfcd0e3f185e835a
compiler:       Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8

Note: no patches were applied.

^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: [syzbot] [kernel?] linux-next test error: WARNING: locking bug in change_page_attr_set_clr
  2026-07-21 14:03         ` Lorenzo Stoakes (ARM)
@ 2026-07-21 15:05           ` Borislav Petkov
  2026-07-21 15:45             ` Lorenzo Stoakes (ARM)
  0 siblings, 1 reply; 11+ messages in thread
From: Borislav Petkov @ 2026-07-21 15:05 UTC (permalink / raw)
  To: Lorenzo Stoakes (ARM)
  Cc: Mike Rapoport, syzbot, Denis V. Lunev, Vishal Moola, dave.hansen,
	hpa, linux-kernel, linux-next, luto, mingo, peterz, sfr,
	syzkaller-bugs, tglx, x86

On Tue, Jul 21, 2026 at 03:03:41PM +0100, Lorenzo Stoakes (ARM) wrote:
> You mean the series that changes core mm and has strict dependencies on core mm
> changes and solves issues elsewhere than x86 CPA, that one should have gone
> through the x86 tree?

We do immutable branches for things like that. For example.

Bottom line is, there needs to be synchronization across trees when they touch
the same file.

-- 
Regards/Gruss,
    Boris.

https://people.kernel.org/tglx/notes-about-netiquette

^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: [syzbot] [kernel?] linux-next test error: WARNING: locking bug in change_page_attr_set_clr
  2026-07-21 15:05           ` Borislav Petkov
@ 2026-07-21 15:45             ` Lorenzo Stoakes (ARM)
  0 siblings, 0 replies; 11+ messages in thread
From: Lorenzo Stoakes (ARM) @ 2026-07-21 15:45 UTC (permalink / raw)
  To: Borislav Petkov
  Cc: Mike Rapoport, syzbot, Denis V. Lunev, Vishal Moola, dave.hansen,
	hpa, linux-kernel, linux-next, luto, mingo, peterz, sfr,
	syzkaller-bugs, tglx, x86

On Tue, Jul 21, 2026 at 08:05:47AM -0700, Borislav Petkov wrote:
> On Tue, Jul 21, 2026 at 03:03:41PM +0100, Lorenzo Stoakes (ARM) wrote:
> > You mean the series that changes core mm and has strict dependencies on core mm
> > changes and solves issues elsewhere than x86 CPA, that one should have gone
> > through the x86 tree?
>
> We do immutable branches for things like that. For example.

Coming soon to mm :)

>
> Bottom line is, there needs to be synchronization across trees when they touch
> the same file.

Yeah completely agreed as discussed off list :) comms is key.

>
> --
> Regards/Gruss,
>     Boris.
>
> https://people.kernel.org/tglx/notes-about-netiquette

Cheers, Lorenzo

^ permalink raw reply	[flat|nested] 11+ messages in thread

end of thread, other threads:[~2026-07-21 15:45 UTC | newest]

Thread overview: 11+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-20 16:59 [syzbot] [kernel?] linux-next test error: WARNING: locking bug in change_page_attr_set_clr syzbot
2026-07-21  2:24 ` Borislav Petkov
2026-07-21 10:35   ` Mike Rapoport
2026-07-21 12:39     ` Lorenzo Stoakes (ARM)
2026-07-21 13:53       ` Borislav Petkov
2026-07-21 14:03         ` Lorenzo Stoakes (ARM)
2026-07-21 15:05           ` Borislav Petkov
2026-07-21 15:45             ` Lorenzo Stoakes (ARM)
2026-07-21 14:10       ` Lorenzo Stoakes (ARM)
2026-07-21 10:20 ` Forwarded: " syzbot
     [not found] <CABWoTMsoHK3wOK2bNXEpWdqU5SxE2WcmdTDnJN3V5jybKSNLpQ@mail.gmail.com>
2026-07-21 14:18 ` syzbot

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox