From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-oi1-f198.google.com (mail-oi1-f198.google.com [209.85.167.198]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B231F23EAA6 for ; Thu, 13 Aug 2026 06:01:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.167.198 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786600865; cv=none; b=UTJuQzNoH8Jwadw4aApjFjYWIGcnDnF2opuKcWgFiciO+/CAnzYY6rYCmH7k9jDwTaF7PbVmyQ9Z4hsA8Y+48E3IvLgzkn1DNwZ6C7cs+WU8DL+4s81DyhLp6wJrjDkboQdXDEOpf6f39pVH1MoPs4abdG/VGaCgvDoYqnr7NOY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786600865; c=relaxed/simple; bh=BSAUtCY8GmQeLaZgZOcbWFDLLMixVzZrWsfKckVN/oM=; h=MIME-Version:Date:In-Reply-To:Message-ID:Subject:From:To: Content-Type; b=Po2ChLQEy2V/HTi2q05vvi8XVpI/su+AsVBKih1O887l43BrTT6CwZ9BXWCtdQfib6E66lu1CFwHBuihF8Vro36yVc+nT+nMi73P/+pzuTnEFSqfzs/moUexgPFnXl/u6gJRQLLqyIOfG58uIhJGoeJUwWsad619tGsx2QU3KmM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com; arc=none smtp.client-ip=209.85.167.198 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com Received: by mail-oi1-f198.google.com with SMTP id 5614622812f47-4a41f46d629so2140561b6e.3 for ; Wed, 12 Aug 2026 23:01:03 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786600862; x=1787205662; h=content-type:to:from:subject:message-id:in-reply-to:date :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=EIrqV5AoPNqc/hwxpPbL4KMx5NGcakJoNFsRuP4OROg=; b=aRYaqUPXj1gYInaVDgrWNxVjuStjFoBeraeoIzj6RvKXDlshZNU7bDD7TzXrDuGiQB 8BgJrhi3KhkXerzqugwPzNrzDWhvjIqY8rysJs2nYXODntFrvdkdIr9Df9qRxdnzfep5 h2Dv0/AlNvA1idjPxDdwNcnNeZVb1ol5BhCMqNJiz+H99q8iYvFrIJuk7Zr/3OiRotJm 0mDS0GDOFlw60stwBY37uxfTSAeQ4d7VgMiqwKCRdC+Oksv5BTqzJqYK014+BYe/BpFZ tasT9QflOe2426xbuuPWLfop0e6yh762wPBTCP5Jxy3jP79ZUz1XjFOp1KFae3T+DY7y luHQ== X-Gm-Message-State: AOJu0YxPpEermxP2I1aplLBa8BHtr0XWmz/555f2upCdUoVQYyiXG3rN n+IBUTgGTzVtA8vGujex0VAKeg+eyMF1MkWTLiLyZfyNBVT/lpZxiO8SwY6lCxT8M1/hJn6oLbG l31/6NrO698SphAnS46SZXG5HqwQAkCvcomsXRYoXVS+GDJ0yt/J2FXDHPW8= Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Received: by 2002:a4a:ee83:0:b0:6ac:a9bb:4f1 with SMTP id 006d021491bc7-6b0c434a827mr3719109eaf.17.1786600862514; Wed, 12 Aug 2026 23:01:02 -0700 (PDT) Date: Wed, 12 Aug 2026 23:01:02 -0700 In-Reply-To: <761cea30-ec04-465a-abf5-0d6160e4c759n@googlegroups.com> X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <6a7d5d9e.c5ad36c8.12f49d.002b.GAE@google.com> Subject: Re: [syzbot] [edac?] general protection fault in detach_timer (3) From: syzbot To: linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com, tao1.yu@intel.com Content-Type: text/plain; charset="UTF-8" Hello, syzbot has tested the proposed patch but the reproducer is still triggering an issue: general protection fault in detach_timer Oops: general protection fault, probably for non-canonical address 0xfbd59c0000000025: 0000 [#1] SMP KASAN PTI KASAN: maybe wild-memory-access in range [0xdead000000000128-0xdead00000000012f] CPU: 0 UID: 0 PID: 6706 Comm: syz.0.35 Not tainted syzkaller #0 PREEMPT_{RT,(full)} Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026 RIP: 0010:__hlist_del include/linux/list.h:1031 [inline] RIP: 0010:detach_timer+0x120/0x2d0 kernel/time/timer.c:891 Code: c1 e8 03 80 3c 28 00 74 08 4c 89 e7 e8 c9 48 7d 00 4d 89 3c 24 4d 85 ff 74 46 e8 4b d1 13 00 49 83 c7 08 4c 89 f8 48 c1 e8 03 <80> 3c 28 00 74 08 4c 89 ff e8 a2 48 7d 00 4d 89 27 80 7c 24 04 00 RSP: 0018:ffffc9000492fae8 EFLAGS: 00010802 RAX: 1bd5a00000000025 RBX: 1ffff110170e4694 RCX: ffff888031879f00 RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000 RBP: dffffc0000000000 R08: 0000000000000000 R09: 0000000000000000 R10: dffffc0000000000 R11: fffffbfff1f5e987 R12: ffff8880b86258f0 R13: ffff8880b87234a8 R14: 1ffff110170e4695 R15: dead00000000012a FS: 00007f01d31bd6c0(0000) GS:ffff888125c46000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f01d3bcb7c0 CR3: 0000000032b9e000 CR4: 00000000003526f0 Call Trace: detach_if_pending kernel/time/timer.c:910 [inline] __try_to_del_timer_sync kernel/time/timer.c:1462 [inline] __timer_delete_sync+0x4fb/0x600 kernel/time/timer.c:1621 mce_timer_delete_all arch/x86/kernel/cpu/mce/core.c:1817 [inline] set_ignore_ce+0x1c2/0x2a0 arch/x86/kernel/cpu/mce/core.c:2562 kernfs_fop_write_iter+0x3a5/0x540 fs/kernfs/file.c:345 new_sync_write fs/read_write.c:595 [inline] vfs_write+0x61e/0xbb0 fs/read_write.c:687 ksys_write+0x156/0x270 fs/read_write.c:739 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f01d3b7e0d9 Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007f01d31bd028 EFLAGS: 00000246 ORIG_RAX: 0000000000000001 RAX: ffffffffffffffda RBX: 00007f01d3e06090 RCX: 00007f01d3b7e0d9 RDX: 0000000000000002 RSI: 00002000000001a0 RDI: 0000000000000003 RBP: 00007f01d3c15024 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 R13: 00007f01d3e06128 R14: 00007f01d3e06090 R15: 00007ffc28e9bd68 Modules linked in: ---[ end trace 0000000000000000 ]--- RIP: 0010:__hlist_del include/linux/list.h:1031 [inline] RIP: 0010:detach_timer+0x120/0x2d0 kernel/time/timer.c:891 Code: c1 e8 03 80 3c 28 00 74 08 4c 89 e7 e8 c9 48 7d 00 4d 89 3c 24 4d 85 ff 74 46 e8 4b d1 13 00 49 83 c7 08 4c 89 f8 48 c1 e8 03 <80> 3c 28 00 74 08 4c 89 ff e8 a2 48 7d 00 4d 89 27 80 7c 24 04 00 RSP: 0018:ffffc9000492fae8 EFLAGS: 00010802 RAX: 1bd5a00000000025 RBX: 1ffff110170e4694 RCX: ffff888031879f00 RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000 RBP: dffffc0000000000 R08: 0000000000000000 R09: 0000000000000000 R10: dffffc0000000000 R11: fffffbfff1f5e987 R12: ffff8880b86258f0 R13: ffff8880b87234a8 R14: 1ffff110170e4695 R15: dead00000000012a FS: 00007f01d31bd6c0(0000) GS:ffff888125c46000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f01d3bcb7c0 CR3: 0000000032b9e000 CR4: 00000000003526f0 ---------------- Code disassembly (best guess): 0: c1 e8 03 shr $0x3,%eax 3: 80 3c 28 00 cmpb $0x0,(%rax,%rbp,1) 7: 74 08 je 0x11 9: 4c 89 e7 mov %r12,%rdi c: e8 c9 48 7d 00 call 0x7d48da 11: 4d 89 3c 24 mov %r15,(%r12) 15: 4d 85 ff test %r15,%r15 18: 74 46 je 0x60 1a: e8 4b d1 13 00 call 0x13d16a 1f: 49 83 c7 08 add $0x8,%r15 23: 4c 89 f8 mov %r15,%rax 26: 48 c1 e8 03 shr $0x3,%rax * 2a: 80 3c 28 00 cmpb $0x0,(%rax,%rbp,1) <-- trapping instruction 2e: 74 08 je 0x38 30: 4c 89 ff mov %r15,%rdi 33: e8 a2 48 7d 00 call 0x7d48da 38: 4d 89 27 mov %r12,(%r15) 3b: 80 7c 24 04 00 cmpb $0x0,0x4(%rsp) Tested on: commit: cfeb0849 timers: Abort CPU hotplug on corrupted timer .. git tree: https://github.com/yutao-intel/linux.git fix-edac console output: https://syzkaller.appspot.com/x/log.txt?x=148bec79580000 kernel config: https://syzkaller.appspot.com/x/.config?x=158601bb8cb292dd dashboard link: https://syzkaller.appspot.com/bug?extid=edc6b57cbed1fb72d0f9 compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8 Note: no patches were applied.