* [jimc:jump-batch-apply-fixed] [x86/jump_label] c80bbdac99: BUG:unable_to_handle_page_fault_for_address
@ 2026-08-26 2:38 kernel test robot
0 siblings, 0 replies; only message in thread
From: kernel test robot @ 2026-08-26 2:38 UTC (permalink / raw)
To: Jim Cromie, Łukasz Bartosik; +Cc: oe-lkp, lkp, yi1.lai
Hello,
kernel test robot noticed "BUG:unable_to_handle_page_fault_for_address" on:
commit: c80bbdac99096eb3f00e5c3a18d275b9e07fe0ef ("x86/jump_label: use system_state < SYSTEM_RUNNING for early boot fallback") https://github.com/jimc/linux.git jump-batch-apply-fixed
in testcase: trinity
version: trinity-i386-abe9de86-1_20230429 with following parameters:
runtime: 300s
group: group-04
nr_groups: 5
config: x86_64-randconfig-102-20260813
compiler: gcc-14
test machine: qemu-system-x86_64 -enable-kvm -cpu SandyBridge -smp 2 -m 32G
(please refer to attached dmesg/kmsg for entire log/backtrace)
If you fix the issue in a separate patch/commit (i.e. not just a new version of the same patch/commit), kindly add following tags
| Reported-by: kernel test robot <yi1.lai@intel.com>
| Closes: https://lore.kernel.org/oe-lkp/202608261049.66dbc9f6-lkp@intel.com
[ 161.700046][ T10] BUG: unable to handle page fault for address: ffffffff866d0d8b
[ 161.700327][ T10] #PF: supervisor write access in kernel mode
[ 161.700327][ T10] #PF: error_code(0x0003) - permissions violation
[ 161.700327][ T10] PGD 9343067 P4D 9343067 PUD 9344063 PMD 66000a1
[ 161.700327][ T10] Oops: Oops: 0003 [#1] KASAN PTI
[ 161.700327][ T10] CPU: 0 UID: 0 PID: 10 Comm: kworker/0:1 Tainted: G T 7.2.0-rc6+ #1 PREEMPT(lazy)
[ 161.700327][ T10] Tainted: [T]=RANDSTRUCT
[ 161.700327][ T10] Workqueue: events once_deferred
[ 161.700327][ T10] RIP: 0010:memcpy_orig (x86/lib/memcpy_64.S:164)
[ 161.700327][ T10] Code: 16 fc 89 0f 44 89 44 17 fc c3 cc 66 66 2e 0f 1f 84 00 00 00 00 00 83 ea 01 72 19 0f b6 0e 74 12 4c 0f b6 46 01 4c 0f b6 0c 16 <44> 88 47 01 44 88 0c 17 88 0f c3 cc cc cc cc cc cc cc cc cc cc cc
All code
========
0: 16 (bad)
1: fc cld
2: 89 0f mov %ecx,(%rdi)
4: 44 89 44 17 fc mov %r8d,-0x4(%rdi,%rdx,1)
9: c3 ret
a: cc int3
b: 66 66 2e 0f 1f 84 00 data16 cs nopw 0x0(%rax,%rax,1)
12: 00 00 00 00
16: 83 ea 01 sub $0x1,%edx
19: 72 19 jb 0x34
1b: 0f b6 0e movzbl (%rsi),%ecx
1e: 74 12 je 0x32
20: 4c 0f b6 46 01 movzbq 0x1(%rsi),%r8
25: 4c 0f b6 0c 16 movzbq (%rsi,%rdx,1),%r9
2a:* 44 88 47 01 mov %r8b,0x1(%rdi) <-- trapping instruction
2e: 44 88 0c 17 mov %r9b,(%rdi,%rdx,1)
32: 88 0f mov %cl,(%rdi)
34: c3 ret
35: cc int3
36: cc int3
37: cc int3
38: cc int3
39: cc int3
3a: cc int3
3b: cc int3
3c: cc int3
3d: cc int3
3e: cc int3
3f: cc int3
Code starting with the faulting instruction ===========================================
0: 44 88 47 01 mov %r8b,0x1(%rdi)
4: 44 88 0c 17 mov %r9b,(%rdi,%rdx,1)
8: 88 0f mov %cl,(%rdi)
a: c3 ret
b: cc int3
c: cc int3
d: cc int3
e: cc int3
f: cc int3
10: cc int3
11: cc int3
12: cc int3
13: cc int3
14: cc int3
15: cc int3
[ 161.700327][ T10] RSP: 0000:ffffc900000afad8 EFLAGS: 00210002
[ 161.700327][ T10] RAX: ffffffff866d0d8a RBX: 0000000000000002 RCX: 0000000000000066
[ 161.700327][ T10] RDX: 0000000000000001 RSI: ffffffff876529a1 RDI: ffffffff866d0d8a
[ 161.700327][ T10] RBP: ffffc900000afaf8 R08: 0000000000000090 R09: 0000000000000090
[ 161.700327][ T10] R10: ffffffff866d0d8b R11: ffffffff8996e6a0 R12: ffffffff876529a1
[ 161.700327][ T10] R13: ffffffff866d0d8a R14: ffffffff876529a1 R15: ffffffff89001338
[ 161.700327][ T10] FS: 0000000000000000(0000) GS:0000000000000000(0000) knlGS:0000000000000000
[ 161.700327][ T10] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 161.700327][ T10] CR2: ffffffff866d0d8b CR3: 0000000009340000 CR4: 00000000000406f0
[ 161.700327][ T10] Call Trace:
[ 161.700327][ T10] <TASK>
[ 161.700327][ T10] ? __asan_memcpy (kasan/shadow.c:109)
[ 161.700327][ T10] ? flow_hash_from_keys (core/flow_dissector.c:1820)
[ 161.700327][ T10] text_poke_early (x86/kernel/alternative.c:2505 (discriminator 6))
[ 161.700327][ T10] jump_label_transform+0x8f/0x100
[ 161.700327][ T10] ? sched_clock_noinstr (x86/kernel/tsc.c:274)
[ 161.700327][ T10] arch_jump_label_transform_queue (x86/kernel/jump_label.c:120 x86/kernel/jump_label.c:132)
[ 161.700327][ T10] ? __kasan_check_read (kasan/shadow.c:31 (discriminator 1))
[ 161.700327][ T10] __jump_label_update (jump_label.c:549 (discriminator 1))
[ 161.700327][ T10] jump_label_update_key (jump_label.c:962)
[ 161.700327][ T10] ? process_one_work (workqueue.c:3297 (discriminator 1))
[ 161.700327][ T10] static_key_disable_cpuslocked (jump_label.c:967 jump_label.c:241)
[ 161.700327][ T10] static_key_disable (jump_label.c:249)
[ 161.700327][ T10] once_deferred (once.c:20)
[ 161.700327][ T10] process_one_work (workqueue.c:3322)
[ 161.700327][ T10] ? __queue_delayed_work (workqueue.c:2575)
[ 161.700327][ T10] ? __this_cpu_preempt_check (smp_processor_id.c:64)
[ 161.700327][ T10] ? assign_work (workqueue.c:1233)
[ 161.700327][ T10] worker_thread (workqueue.c:3405 workqueue.c:3486)
[ 161.700327][ T10] ? trace_hardirqs_on (trace/trace_preemptirq.c:79 (discriminator 1))
[ 161.700327][ T10] kthread (kthread.c:436)
[ 161.700327][ T10] ? calculate_sigpending (linux/spinlock.h:402 signal.c:194)
[ 161.700327][ T10] ? rescuer_thread (x86/include/asm/current.h:23)
[ 161.700327][ T10] ? kthread_affine_node (linux/list.h:404 (discriminator 2))
[ 161.700327][ T10] ret_from_fork (x86/kernel/process.c:158)
[ 161.700327][ T10] ? __kasan_check_read (kasan/shadow.c:31 (discriminator 1))
[ 161.700327][ T10] ? arch_exit_to_user_mode_prepare+0x180/0x180
[ 161.700327][ T10] ? __switch_to (x86/kernel/process_64.c:619)
[ 161.700327][ T10] ? kthread_affine_node (linux/list.h:404 (discriminator 2))
[ 161.700327][ T10] ret_from_fork_asm (x86/entry/entry_64.S:245)
[ 161.700327][ T10] </TASK>
[ 161.700327][ T10] Modules linked in:
[ 161.700327][ T10] CR2: ffffffff866d0d8b
[ 161.700327][ T10] ---[ end trace 0000000000000000 ]---
[ 161.700327][ T10] RIP: 0010:memcpy_orig (x86/lib/memcpy_64.S:164)
[ 161.700327][ T10] Code: 16 fc 89 0f 44 89 44 17 fc c3 cc 66 66 2e 0f 1f 84 00 00 00 00 00 83 ea 01 72 19 0f b6 0e 74 12 4c 0f b6 46 01 4c 0f b6 0c 16 <44> 88 47 01 44 88 0c 17 88 0f c3 cc cc cc cc cc cc cc cc cc cc cc
All code
========
0: 16 (bad)
1: fc cld
2: 89 0f mov %ecx,(%rdi)
4: 44 89 44 17 fc mov %r8d,-0x4(%rdi,%rdx,1)
9: c3 ret
a: cc int3
b: 66 66 2e 0f 1f 84 00 data16 cs nopw 0x0(%rax,%rax,1)
12: 00 00 00 00
16: 83 ea 01 sub $0x1,%edx
19: 72 19 jb 0x34
1b: 0f b6 0e movzbl (%rsi),%ecx
1e: 74 12 je 0x32
20: 4c 0f b6 46 01 movzbq 0x1(%rsi),%r8
25: 4c 0f b6 0c 16 movzbq (%rsi,%rdx,1),%r9
2a:* 44 88 47 01 mov %r8b,0x1(%rdi) <-- trapping instruction
2e: 44 88 0c 17 mov %r9b,(%rdi,%rdx,1)
32: 88 0f mov %cl,(%rdi)
34: c3 ret
35: cc int3
36: cc int3
37: cc int3
38: cc int3
39: cc int3
3a: cc int3
3b: cc int3
3c: cc int3
3d: cc int3
3e: cc int3
3f: cc int3
Code starting with the faulting instruction ===========================================
0: 44 88 47 01 mov %r8b,0x1(%rdi)
4: 44 88 0c 17 mov %r9b,(%rdi,%rdx,1)
8: 88 0f mov %cl,(%rdi)
a: c3 ret
b: cc int3
c: cc int3
d: cc int3
e: cc int3
f: cc int3
10: cc int3
11: cc int3
12: cc int3
13: cc int3
14: cc int3
15: cc int3
The kernel config and materials to reproduce are available at:
https://download.01.org/0day-ci/archive/20260826/202608261049.66dbc9f6-lkp@intel.com
--
0-DAY CI Kernel Test Service
https://github.com/intel/lkp-tests/wiki
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-08-26 2:38 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-26 2:38 [jimc:jump-batch-apply-fixed] [x86/jump_label] c80bbdac99: BUG:unable_to_handle_page_fault_for_address kernel test robot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox