From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-oo1-f69.google.com (mail-oo1-f69.google.com [209.85.161.69]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8FC8A211A14 for ; Sat, 14 Feb 2026 16:40:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.161.69 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1771087231; cv=none; b=K0BzDyunQPk/LTByQAO7simjTR0I80EyuTJNIGjXuvajYjIC4AE2A4CPg1dD6LwPoplbTEnndUlz9Z0BelbVpB6pYfiRYVJPPF3ZguBwt0W4KJHlPKhAO07di6wgkF7wFZhb9lGj+8YQruAr/O2VgIslAvUHUM3kFxYSWkKO0Wc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1771087231; c=relaxed/simple; bh=FiKMYVTtgF+qf3KtVUQJWQRxQ68V0hEgz97mEVo3oEI=; h=MIME-Version:Date:Message-ID:Subject:From:To:Content-Type; b=cK0kUU1uAETaPTvGc63sDAtOdsOkh/0lvET+pfO9fEqrKu6e7yPdqx9dyJIkla9txnpCJ0RUJz5LDMMkwgGCXq7yhb/qD33EJEap0ObLxcG5WOblULXw1A5GaxfyGSO+9iwhPmfE0NVfAY0HlDLUONQpmTXNpv33D/+dRn959Ik= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com; arc=none smtp.client-ip=209.85.161.69 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com Received: by mail-oo1-f69.google.com with SMTP id 006d021491bc7-678f3fef828so5281385eaf.1 for ; Sat, 14 Feb 2026 08:40:30 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1771087229; x=1771692029; h=to:from:subject:message-id:date:mime-version:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=uPf8MT82Um0ZTVbxxH14r16T9e3M3qG/kIJLzenPqfw=; b=nlXm9KN/PuEktiGgPnr3YKCjRVd+b8hz4t+dswH8giSqAb9sUAMVOxS6mSCjCt29W+ BPh7sXLcSNeh8o84r/uBezuzj855cRhp5bv2jt0KejwpPFstuYRF9jqJgsMn2O/RKzsc TYlyHArxciQXmv1eEqBm7C2exMtuQz4I8B+g8M5Sckd9PbxiLkyjpqwBDkeYXZPdI7lL IMlSmKkaIFWY9Jj3Gst906IbhC28+eGNdWxYFv8dBsMN90Gp1YVhBmfUTfArUSEkIV+j S3t+PIgieFwFkkW4tq7T9PcPYiGzk1LtTR7VwD0oX2sI+J48uZYCuEp7bUm8LMqAPwro asRw== X-Forwarded-Encrypted: i=1; AJvYcCUXaZ6j8yNKm4piR4z04Nu1WgHoT1G/XATnb0e3471PzkBQluiIi2hPaAkS4Zc5vt0rehpRXLYyNRwTSAw=@vger.kernel.org X-Gm-Message-State: AOJu0YzkSBleavFJdaytEvHI2Lk+VewCXXy+OS90ee+bG3pd8AP4DT7E YR64oquXXhuAdBOrr9e55vkktgJy2fw1k0z26rNy9FKiBfl2ytJ+eD04Fgg0uBb34RQtqwL1f5u J29g4s0clEwaiGadHjxFpWqEO+hFje7DBmcpRrCO5RYF1GIzfkDNaMuJfqJA= Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Received: by 2002:a05:6820:4d0c:b0:663:1239:9eae with SMTP id 006d021491bc7-67768ccad6fmr2550954eaf.54.1771087229496; Sat, 14 Feb 2026 08:40:29 -0800 (PST) Date: Sat, 14 Feb 2026 08:40:29 -0800 X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <6990a57d.050a0220.2757fb.0028.GAE@google.com> Subject: [syzbot] [mm?] kernel BUG in __khugepaged_enter From: syzbot To: Liam.Howlett@oracle.com, akpm@linux-foundation.org, baohua@kernel.org, baolin.wang@linux.alibaba.com, david@kernel.org, dev.jain@arm.com, lance.yang@linux.dev, linux-kernel@vger.kernel.org, linux-mm@kvack.org, lorenzo.stoakes@oracle.com, npache@redhat.com, ryan.roberts@arm.com, syzkaller-bugs@googlegroups.com, ziy@nvidia.com Content-Type: text/plain; charset="UTF-8" Hello, syzbot found the following issue on: HEAD commit: 1e83ccd5921a sched/mmcid: Don't assume CID is CPU owned on.. git tree: upstream console output: https://syzkaller.appspot.com/x/log.txt?x=1169dae6580000 kernel config: https://syzkaller.appspot.com/x/.config?x=54ae71b284dd0e13 dashboard link: https://syzkaller.appspot.com/bug?extid=6b554d491efbe066b701 compiler: gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44 Unfortunately, I don't have any reproducer for this issue yet. Downloadable assets: disk image: https://storage.googleapis.com/syzbot-assets/ed43f42e3ea1/disk-1e83ccd5.raw.xz vmlinux: https://storage.googleapis.com/syzbot-assets/d8af54a32588/vmlinux-1e83ccd5.xz kernel image: https://storage.googleapis.com/syzbot-assets/34e6a8cc1037/bzImage-1e83ccd5.xz IMPORTANT: if you fix the issue, please add the following tag to the commit: Reported-by: syzbot+6b554d491efbe066b701@syzkaller.appspotmail.com ------------[ cut here ]------------ kernel BUG at mm/khugepaged.c:438! Oops: invalid opcode: 0000 [#1] SMP KASAN PTI CPU: 0 UID: 0 PID: 16472 Comm: syz.3.2372 Tainted: G U W L XTNJ syzkaller #0 PREEMPT(full) Tainted: [U]=USER, [W]=WARN, [L]=SOFTLOCKUP, [X]=AUX, [T]=RANDSTRUCT, [N]=TEST, [J]=FWCTL Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/24/2026 RIP: 0010:__khugepaged_enter+0x30a/0x380 mm/khugepaged.c:438 Code: 64 7e 8e e8 a8 dc 66 ff e8 93 e6 8d ff 5b 5d 41 5c 41 5d 41 5e 41 5f e9 04 6c 04 09 e8 7f e6 8d ff 48 89 df e8 17 33 d9 ff 90 <0f> 0b 48 89 ef e8 dc 51 f8 ff e9 3b fd ff ff e8 f2 52 f8 ff e9 e1 RSP: 0018:ffffc9000e98fba8 EFLAGS: 00010292 RAX: 000000000000031f RBX: ffff888079b24980 RCX: 0000000000000000 RDX: 000000000000031f RSI: ffffffff81e5b2c9 RDI: fffff52001d31f1c RBP: 0000000000000000 R08: 0000000000000005 R09: 0000000000000000 R10: 0000000080000000 R11: 0000000000000001 R12: 0000000008100177 R13: ffff88804adf9510 R14: 0000000000000000 R15: 0000000000000000 FS: 00007f06093436c0(0000) GS:ffff8881245b1000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007fff341d3f52 CR3: 00000000319b0000 CR4: 00000000003526f0 Call Trace: khugepaged_enter_vma mm/khugepaged.c:467 [inline] khugepaged_enter_vma+0x137/0x2c0 mm/khugepaged.c:461 do_huge_pmd_anonymous_page+0x1c8/0x1c00 mm/huge_memory.c:1469 create_huge_pmd mm/memory.c:6102 [inline] __handle_mm_fault+0x1e96/0x2b50 mm/memory.c:6376 handle_mm_fault+0x36d/0xa20 mm/memory.c:6583 do_user_addr_fault+0x5a3/0x12f0 arch/x86/mm/fault.c:1334 handle_page_fault arch/x86/mm/fault.c:1474 [inline] exc_page_fault+0x6f/0xd0 arch/x86/mm/fault.c:1527 asm_exc_page_fault+0x26/0x30 arch/x86/include/asm/idtentry.h:618 RIP: 0033:0x87560 Code: Unable to access opcode bytes at 0x87536. RSP: 002b:000000000000000e EFLAGS: 00010202 RAX: 0000000000000000 RBX: 00007f0608615fa0 RCX: 00007f060839bf79 RDX: 0000000000000000 RSI: 0000000000000006 RDI: 0002000020003b4a RBP: 00007f06084327e0 R08: 0000000000000103 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 R13: 00007f0608616038 R14: 00007f0608615fa0 R15: 00007ffee482e7a8 Modules linked in: ---[ end trace 0000000000000000 ]--- RIP: 0010:__khugepaged_enter+0x30a/0x380 mm/khugepaged.c:438 Code: 64 7e 8e e8 a8 dc 66 ff e8 93 e6 8d ff 5b 5d 41 5c 41 5d 41 5e 41 5f e9 04 6c 04 09 e8 7f e6 8d ff 48 89 df e8 17 33 d9 ff 90 <0f> 0b 48 89 ef e8 dc 51 f8 ff e9 3b fd ff ff e8 f2 52 f8 ff e9 e1 RSP: 0018:ffffc9000e98fba8 EFLAGS: 00010292 RAX: 000000000000031f RBX: ffff888079b24980 RCX: 0000000000000000 RDX: 000000000000031f RSI: ffffffff81e5b2c9 RDI: fffff52001d31f1c RBP: 0000000000000000 R08: 0000000000000005 R09: 0000000000000000 R10: 0000000080000000 R11: 0000000000000001 R12: 0000000008100177 R13: ffff88804adf9510 R14: 0000000000000000 R15: 0000000000000000 FS: 00007f06093436c0(0000) GS:ffff8881245b1000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 000055906703f168 CR3: 00000000319b0000 CR4: 00000000003526f0 --- This report is generated by a bot. It may contain errors. See https://goo.gl/tpsmEJ for more information about syzbot. syzbot engineers can be reached at syzkaller@googlegroups.com. syzbot will keep track of this issue. See: https://goo.gl/tpsmEJ#status for how to communicate with syzbot. If the report is already addressed, let syzbot know by replying with: #syz fix: exact-commit-title If you want to overwrite report's subsystems, reply with: #syz set subsystems: new-subsystem (See the list of subsystem names on the web dashboard) If the report is a duplicate of another one, reply with: #syz dup: exact-subject-of-another-report If you want to undo deduplication, reply with: #syz undup