Linux Kernel Performance
 help / color / mirror / Atom feed
* [jimc:jump-batch-apply-fixed] [x86/jump_label]  c80bbdac99: BUG:unable_to_handle_page_fault_for_address
@ 2026-08-26  2:38 kernel test robot
  0 siblings, 0 replies; only message in thread
From: kernel test robot @ 2026-08-26  2:38 UTC (permalink / raw)
  To: Jim Cromie, Łukasz Bartosik; +Cc: oe-lkp, lkp, yi1.lai


Hello,

kernel test robot noticed "BUG:unable_to_handle_page_fault_for_address" on:

commit: c80bbdac99096eb3f00e5c3a18d275b9e07fe0ef ("x86/jump_label: use system_state < SYSTEM_RUNNING for early boot fallback") https://github.com/jimc/linux.git jump-batch-apply-fixed

in testcase: trinity
version: trinity-i386-abe9de86-1_20230429 with following parameters:

	runtime: 300s
	group: group-04
	nr_groups: 5



config: x86_64-randconfig-102-20260813
compiler: gcc-14
test machine: qemu-system-x86_64 -enable-kvm -cpu SandyBridge -smp 2 -m 32G

(please refer to attached dmesg/kmsg for entire log/backtrace)

If you fix the issue in a separate patch/commit (i.e. not just a new version of the same patch/commit), kindly add following tags
| Reported-by: kernel test robot <yi1.lai@intel.com>
| Closes: https://lore.kernel.org/oe-lkp/202608261049.66dbc9f6-lkp@intel.com

[  161.700046][   T10] BUG: unable to handle page fault for address: ffffffff866d0d8b
[  161.700327][   T10] #PF: supervisor write access in kernel mode
[  161.700327][   T10] #PF: error_code(0x0003) - permissions violation
[  161.700327][   T10] PGD 9343067 P4D 9343067 PUD 9344063 PMD 66000a1
[  161.700327][   T10] Oops: Oops: 0003 [#1] KASAN PTI
[  161.700327][   T10] CPU: 0 UID: 0 PID: 10 Comm: kworker/0:1 Tainted: G                T   7.2.0-rc6+ #1 PREEMPT(lazy)
[  161.700327][   T10] Tainted: [T]=RANDSTRUCT
[  161.700327][   T10] Workqueue: events once_deferred
[  161.700327][   T10] RIP: 0010:memcpy_orig (x86/lib/memcpy_64.S:164)
[  161.700327][   T10] Code: 16 fc 89 0f 44 89 44 17 fc c3 cc 66 66 2e 0f 1f 84 00 00 00 00 00 83 ea 01 72 19 0f b6 0e 74 12 4c 0f b6 46 01 4c 0f b6 0c 16 <44> 88 47 01 44 88 0c 17 88 0f c3 cc cc cc cc cc cc cc cc cc cc cc
All code
========
   0:	16                   	(bad)
   1:	fc                   	cld
   2:	89 0f                	mov    %ecx,(%rdi)
   4:	44 89 44 17 fc       	mov    %r8d,-0x4(%rdi,%rdx,1)
   9:	c3                   	ret
   a:	cc                   	int3
   b:	66 66 2e 0f 1f 84 00 	data16 cs nopw 0x0(%rax,%rax,1)
  12:	00 00 00 00 
  16:	83 ea 01             	sub    $0x1,%edx
  19:	72 19                	jb     0x34
  1b:	0f b6 0e             	movzbl (%rsi),%ecx
  1e:	74 12                	je     0x32
  20:	4c 0f b6 46 01       	movzbq 0x1(%rsi),%r8
  25:	4c 0f b6 0c 16       	movzbq (%rsi,%rdx,1),%r9
  2a:*	44 88 47 01          	mov    %r8b,0x1(%rdi)		<-- trapping instruction
  2e:	44 88 0c 17          	mov    %r9b,(%rdi,%rdx,1)
  32:	88 0f                	mov    %cl,(%rdi)
  34:	c3                   	ret
  35:	cc                   	int3
  36:	cc                   	int3
  37:	cc                   	int3
  38:	cc                   	int3
  39:	cc                   	int3
  3a:	cc                   	int3
  3b:	cc                   	int3
  3c:	cc                   	int3
  3d:	cc                   	int3
  3e:	cc                   	int3
  3f:	cc                   	int3

Code starting with the faulting instruction ===========================================
   0:	44 88 47 01          	mov    %r8b,0x1(%rdi)
   4:	44 88 0c 17          	mov    %r9b,(%rdi,%rdx,1)
   8:	88 0f                	mov    %cl,(%rdi)
   a:	c3                   	ret
   b:	cc                   	int3
   c:	cc                   	int3
   d:	cc                   	int3
   e:	cc                   	int3
   f:	cc                   	int3
  10:	cc                   	int3
  11:	cc                   	int3
  12:	cc                   	int3
  13:	cc                   	int3
  14:	cc                   	int3
  15:	cc                   	int3
[  161.700327][   T10] RSP: 0000:ffffc900000afad8 EFLAGS: 00210002
[  161.700327][   T10] RAX: ffffffff866d0d8a RBX: 0000000000000002 RCX: 0000000000000066
[  161.700327][   T10] RDX: 0000000000000001 RSI: ffffffff876529a1 RDI: ffffffff866d0d8a
[  161.700327][   T10] RBP: ffffc900000afaf8 R08: 0000000000000090 R09: 0000000000000090
[  161.700327][   T10] R10: ffffffff866d0d8b R11: ffffffff8996e6a0 R12: ffffffff876529a1
[  161.700327][   T10] R13: ffffffff866d0d8a R14: ffffffff876529a1 R15: ffffffff89001338
[  161.700327][   T10] FS:  0000000000000000(0000) GS:0000000000000000(0000) knlGS:0000000000000000
[  161.700327][   T10] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[  161.700327][   T10] CR2: ffffffff866d0d8b CR3: 0000000009340000 CR4: 00000000000406f0
[  161.700327][   T10] Call Trace:
[  161.700327][   T10]  <TASK>
[  161.700327][   T10]  ? __asan_memcpy (kasan/shadow.c:109)
[  161.700327][   T10]  ? flow_hash_from_keys (core/flow_dissector.c:1820)
[  161.700327][   T10]  text_poke_early (x86/kernel/alternative.c:2505 (discriminator 6))
[  161.700327][   T10]  jump_label_transform+0x8f/0x100
[  161.700327][   T10]  ? sched_clock_noinstr (x86/kernel/tsc.c:274)
[  161.700327][   T10]  arch_jump_label_transform_queue (x86/kernel/jump_label.c:120 x86/kernel/jump_label.c:132)
[  161.700327][   T10]  ? __kasan_check_read (kasan/shadow.c:31 (discriminator 1))
[  161.700327][   T10]  __jump_label_update (jump_label.c:549 (discriminator 1))
[  161.700327][   T10]  jump_label_update_key (jump_label.c:962)
[  161.700327][   T10]  ? process_one_work (workqueue.c:3297 (discriminator 1))
[  161.700327][   T10]  static_key_disable_cpuslocked (jump_label.c:967 jump_label.c:241)
[  161.700327][   T10]  static_key_disable (jump_label.c:249)
[  161.700327][   T10]  once_deferred (once.c:20)
[  161.700327][   T10]  process_one_work (workqueue.c:3322)
[  161.700327][   T10]  ? __queue_delayed_work (workqueue.c:2575)
[  161.700327][   T10]  ? __this_cpu_preempt_check (smp_processor_id.c:64)
[  161.700327][   T10]  ? assign_work (workqueue.c:1233)
[  161.700327][   T10]  worker_thread (workqueue.c:3405 workqueue.c:3486)
[  161.700327][   T10]  ? trace_hardirqs_on (trace/trace_preemptirq.c:79 (discriminator 1))
[  161.700327][   T10]  kthread (kthread.c:436)
[  161.700327][   T10]  ? calculate_sigpending (linux/spinlock.h:402 signal.c:194)
[  161.700327][   T10]  ? rescuer_thread (x86/include/asm/current.h:23)
[  161.700327][   T10]  ? kthread_affine_node (linux/list.h:404 (discriminator 2))
[  161.700327][   T10]  ret_from_fork (x86/kernel/process.c:158)
[  161.700327][   T10]  ? __kasan_check_read (kasan/shadow.c:31 (discriminator 1))
[  161.700327][   T10]  ? arch_exit_to_user_mode_prepare+0x180/0x180
[  161.700327][   T10]  ? __switch_to (x86/kernel/process_64.c:619)
[  161.700327][   T10]  ? kthread_affine_node (linux/list.h:404 (discriminator 2))
[  161.700327][   T10]  ret_from_fork_asm (x86/entry/entry_64.S:245)
[  161.700327][   T10]  </TASK>
[  161.700327][   T10] Modules linked in:
[  161.700327][   T10] CR2: ffffffff866d0d8b
[  161.700327][   T10] ---[ end trace 0000000000000000 ]---
[  161.700327][   T10] RIP: 0010:memcpy_orig (x86/lib/memcpy_64.S:164)
[  161.700327][   T10] Code: 16 fc 89 0f 44 89 44 17 fc c3 cc 66 66 2e 0f 1f 84 00 00 00 00 00 83 ea 01 72 19 0f b6 0e 74 12 4c 0f b6 46 01 4c 0f b6 0c 16 <44> 88 47 01 44 88 0c 17 88 0f c3 cc cc cc cc cc cc cc cc cc cc cc
All code
========
   0:	16                   	(bad)
   1:	fc                   	cld
   2:	89 0f                	mov    %ecx,(%rdi)
   4:	44 89 44 17 fc       	mov    %r8d,-0x4(%rdi,%rdx,1)
   9:	c3                   	ret
   a:	cc                   	int3
   b:	66 66 2e 0f 1f 84 00 	data16 cs nopw 0x0(%rax,%rax,1)
  12:	00 00 00 00 
  16:	83 ea 01             	sub    $0x1,%edx
  19:	72 19                	jb     0x34
  1b:	0f b6 0e             	movzbl (%rsi),%ecx
  1e:	74 12                	je     0x32
  20:	4c 0f b6 46 01       	movzbq 0x1(%rsi),%r8
  25:	4c 0f b6 0c 16       	movzbq (%rsi,%rdx,1),%r9
  2a:*	44 88 47 01          	mov    %r8b,0x1(%rdi)		<-- trapping instruction
  2e:	44 88 0c 17          	mov    %r9b,(%rdi,%rdx,1)
  32:	88 0f                	mov    %cl,(%rdi)
  34:	c3                   	ret
  35:	cc                   	int3
  36:	cc                   	int3
  37:	cc                   	int3
  38:	cc                   	int3
  39:	cc                   	int3
  3a:	cc                   	int3
  3b:	cc                   	int3
  3c:	cc                   	int3
  3d:	cc                   	int3
  3e:	cc                   	int3
  3f:	cc                   	int3

Code starting with the faulting instruction ===========================================
   0:	44 88 47 01          	mov    %r8b,0x1(%rdi)
   4:	44 88 0c 17          	mov    %r9b,(%rdi,%rdx,1)
   8:	88 0f                	mov    %cl,(%rdi)
   a:	c3                   	ret
   b:	cc                   	int3
   c:	cc                   	int3
   d:	cc                   	int3
   e:	cc                   	int3
   f:	cc                   	int3
  10:	cc                   	int3
  11:	cc                   	int3
  12:	cc                   	int3
  13:	cc                   	int3
  14:	cc                   	int3
  15:	cc                   	int3


The kernel config and materials to reproduce are available at:
https://download.01.org/0day-ci/archive/20260826/202608261049.66dbc9f6-lkp@intel.com



--
0-DAY CI Kernel Test Service
https://github.com/intel/lkp-tests/wiki



^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-08-26  2:38 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-26  2:38 [jimc:jump-batch-apply-fixed] [x86/jump_label] c80bbdac99: BUG:unable_to_handle_page_fault_for_address kernel test robot

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox