From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-ot1-f69.google.com (mail-ot1-f69.google.com [209.85.210.69]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D5F503998AE for ; Sun, 16 Aug 2026 15:10:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.69 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786893038; cv=none; b=q0nUvjvBYy3h27TYGydu8bW4eEmCouok5xvRJJEb/kLTUmOFwYhcKfjGZE5yvZLEB/UT/yx7Opp2JzSb2UtJF11HzDZ5s2ru0/iKHFgXHDgTJmld0bKwJiMoTMaQbQs9QoP8/UUW5bG4o5q2YzNmhN/HKjw2Up4y+m7dTmHSk8k= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786893038; c=relaxed/simple; bh=Gew9BxbdsjpqAkGo8zA6jJJ3QS7NJ+zh9fLPhZ6NpcI=; h=MIME-Version:Date:Message-ID:Subject:From:To:Content-Type; b=FyNE5ExPpVc/jb71EktY2yUp/uL4TKBX/KKgn9Zf/Ew4cLU9gli+Efxkww0oY+xTYLnqqcy6luCfurPr840yUwIvQDk5j5LeHw3SDWBJM+l+0pF2SYh0ID5SF8hKl6fQHHM55p7dQkEfZmnxe8Rv2ciABz1aRXRXkd/HxGFtQhw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com; arc=none smtp.client-ip=209.85.210.69 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com Received: by mail-ot1-f69.google.com with SMTP id 46e09a7af769-7ebe970a21fso3199099a34.2 for ; Sun, 16 Aug 2026 08:10:31 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786893030; x=1787497830; h=content-type:to:from:subject:message-id:date:mime-version :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=UaDd5hXeECx1JOdkAFLoPcMiRO0zpSKsGgYzuMLuyG8=; b=PpeoMNBAm3KXf+SljUDrPR+441LGyihiKuXAYgottQb1KWwT6qGLa9s8m9XEav8kbX vPNGtan9qlIf1X6OZ/YKm0UWrbi421ENlhmBpyCl6vQ3RVT/U1CTChTm+hxhm9/BKUDN 8RvI6Am4GVyME6Q+reE9SvOYfrszuvEe+vohMLMTq1JjeFSXkMwfQuNFXCNAt4Ma48QL x6mP1j3aZvcACjFs5U9Obh+2RlgMuDOF0FPpIlcFJ29GJ0WCas/kM4q26jIxvmAMy1GL jHx5LJG7YAZf+ntAttx9XUSWXFWcvxOrvpmWV6FV1VIauwsfKXZcHqAYffV1H0bKx+Z7 ySAA== X-Gm-Message-State: AOJu0Yzo4uLnlXHNURhvNawonW9gBXaXctYZYr9zkah1dO0NDIeqW498 n/hLe+/+c3pKXUvFh8xfwY5q9yjGeHwbF29p5vY54Gnj70Gbymg0h3orpFfv6hJq7+hYzDpD7ab 83KJ9vHE68sfDyVD+rJm9Jn32RIGHWcbefigjZLLzcu8t9MHejW8LI5q2bIk= Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Received: by 2002:a05:6820:1ca1:b0:6a3:e0fb:6f39 with SMTP id 006d021491bc7-6b0d6865f2dmr17175207eaf.23.1786893030618; Sun, 16 Aug 2026 08:10:30 -0700 (PDT) Date: Sun, 16 Aug 2026 08:10:30 -0700 X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <6a81d2e6.9ebadd4d.20b15e.001a.GAE@google.com> Subject: [syzbot] [kernel?] BUG: unable to handle kernel paging request in cirrus_primary_plane_helper_atomic_update From: syzbot To: linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com Content-Type: text/plain; charset="UTF-8" Hello, syzbot found the following issue on: HEAD commit: 3eb40771c00a Merge tag 'soc-fixes-7.2-3' of git://git.kern.. git tree: upstream console output: https://syzkaller.appspot.com/x/log.txt?x=13949949580000 kernel config: https://syzkaller.appspot.com/x/.config?x=1d67342c314f228d dashboard link: https://syzkaller.appspot.com/bug?extid=2442951a6abb004df963 compiler: gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44 C reproducer: https://syzkaller.appspot.com/x/repro.c?x=10d696c6580000 IMPORTANT: if you fix the issue, please add the following tag to the commit: Reported-by: syzbot+2442951a6abb004df963@syzkaller.appspotmail.com BUG: unable to handle page fault for address: ffffc900030a7000 #PF: supervisor write access in kernel mode #PF: error_code(0x0002) - not-present page PGD 1c000067 P4D 1c000067 PUD 1d6a8067 PMD 25dcb067 PTE 0 Oops: Oops: 0002 [#1] SMP KASAN NOPTI CPU: 3 UID: 0 PID: 5985 Comm: syz-executor238 Not tainted syzkaller #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 RIP: 0010:rep_movs arch/x86/lib/iomem.c:13 [inline] RIP: 0010:string_memcpy_toio arch/x86/lib/iomem.c:64 [inline] RIP: 0010:memcpy_toio+0x87/0xe0 arch/x86/lib/iomem.c:110 Code: b6 fc 49 89 dd 31 ff 41 83 e5 02 4c 89 ee e8 70 3f b6 fc 4d 85 ed 75 33 e8 c6 44 b6 fc 48 89 e9 48 89 df 4c 89 e6 48 c1 e9 02 a5 40 f6 c5 02 74 02 66 a5 40 f6 c5 01 74 01 a4 e8 a3 44 b6 fc RSP: 0018:ffffc900036ef4f0 EFLAGS: 00010206 RAX: 0000000000000000 RBX: ffffc900030a6d20 RCX: 00000000000000d8 RDX: ffff88802dc8a540 RSI: ffffc90003c31f60 RDI: ffffc900030a7000 RBP: 0000000000000640 R08: 0000000000000007 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000000 R12: ffffc90003c31c80 R13: 0000000000000000 R14: ffffc900030a6d20 R15: 0000000000000640 FS: 0000000000000000(0000) GS:ffff8880d5ede000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: ffffc900030a7000 CR3: 000000003cd11000 CR4: 0000000000352ef0 Call Trace: iosys_map_memcpy_to include/linux/iosys-map.h:285 [inline] drm_fb_memcpy+0x459/0x620 drivers/gpu/drm/drm_format_helper.c:442 cirrus_primary_plane_helper_atomic_update+0xb1d/0xfe0 drivers/gpu/drm/tiny/cirrus-qemu.c:358 drm_atomic_helper_commit_planes+0x497/0xf10 drivers/gpu/drm/drm_atomic_helper.c:3038 drm_atomic_helper_commit_tail+0x7f/0x130 drivers/gpu/drm/drm_atomic_helper.c:1989 commit_tail+0x338/0x430 drivers/gpu/drm/drm_atomic_helper.c:2074 drm_atomic_helper_commit+0x303/0x380 drivers/gpu/drm/drm_atomic_helper.c:2312 drm_atomic_commit+0x230/0x300 drivers/gpu/drm/drm_atomic.c:1789 drm_client_modeset_commit_atomic+0x6a6/0x7e0 drivers/gpu/drm/drm_client_modeset.c:1104 drm_client_modeset_commit_locked+0x14d/0x580 drivers/gpu/drm/drm_client_modeset.c:1207 drm_client_modeset_commit+0x4f/0x80 drivers/gpu/drm/drm_client_modeset.c:1233 __drm_fb_helper_restore_fbdev_mode_unlocked.part.0+0x137/0x160 drivers/gpu/drm/drm_fb_helper.c:138 __drm_fb_helper_restore_fbdev_mode_unlocked drivers/gpu/drm/drm_fb_helper.c:126 [inline] drm_fb_helper_restore_fbdev_mode_unlocked+0x93/0xc0 drivers/gpu/drm/drm_fb_helper.c:169 drm_fbdev_client_restore+0x1b/0x30 drivers/gpu/drm/clients/drm_fbdev_client.c:45 drm_client_dev_restore+0x205/0x2a0 drivers/gpu/drm/drm_client_event.c:118 drm_lastclose drivers/gpu/drm/drm_file.c:408 [inline] drm_release+0x2c6/0x360 drivers/gpu/drm/drm_file.c:441 __fput+0x3ff/0xb50 fs/file_table.c:512 task_work_run+0x150/0x240 kernel/task_work.c:233 exit_task_work include/linux/task_work.h:40 [inline] do_exit+0x951/0x2ae0 kernel/exit.c:1009 do_group_exit+0xd5/0x2a0 kernel/exit.c:1152 __do_sys_exit_group kernel/exit.c:1163 [inline] __se_sys_exit_group kernel/exit.c:1161 [inline] __x64_sys_exit_group+0x3e/0x50 kernel/exit.c:1161 x64_sys_call+0x102c/0x1530 arch/x86/include/generated/asm/syscalls_64.h:232 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x115/0x870 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f6d6a4b3905 Code: Unable to access opcode bytes at 0x7f6d6a4b38db. RSP: 002b:00007ffd867f5c08 EFLAGS: 00000202 ORIG_RAX: 00000000000000e7 RAX: ffffffffffffffda RBX: 0000000000000001 RCX: 00007f6d6a4b3905 RDX: 00000000000000e7 RSI: ffffffffffffffd8 RDI: 0000000000000001 RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000202 R12: 0000000000000001 R13: 00007f6d6a548100 R14: 00007f6d6a54a388 R15: 00007f6d6a54a3a0 Modules linked in: CR2: ffffc900030a7000 ---[ end trace 0000000000000000 ]--- RIP: 0010:rep_movs arch/x86/lib/iomem.c:13 [inline] RIP: 0010:string_memcpy_toio arch/x86/lib/iomem.c:64 [inline] RIP: 0010:memcpy_toio+0x87/0xe0 arch/x86/lib/iomem.c:110 Code: b6 fc 49 89 dd 31 ff 41 83 e5 02 4c 89 ee e8 70 3f b6 fc 4d 85 ed 75 33 e8 c6 44 b6 fc 48 89 e9 48 89 df 4c 89 e6 48 c1 e9 02 a5 40 f6 c5 02 74 02 66 a5 40 f6 c5 01 74 01 a4 e8 a3 44 b6 fc RSP: 0018:ffffc900036ef4f0 EFLAGS: 00010206 RAX: 0000000000000000 RBX: ffffc900030a6d20 RCX: 00000000000000d8 RDX: ffff88802dc8a540 RSI: ffffc90003c31f60 RDI: ffffc900030a7000 RBP: 0000000000000640 R08: 0000000000000007 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000000 R12: ffffc90003c31c80 R13: 0000000000000000 R14: ffffc900030a6d20 R15: 0000000000000640 FS: 0000000000000000(0000) GS:ffff8880d5ede000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: ffffc900030a7000 CR3: 000000003cd11000 CR4: 0000000000352ef0 ---------------- Code disassembly (best guess): 0: b6 fc mov $0xfc,%dh 2: 49 89 dd mov %rbx,%r13 5: 31 ff xor %edi,%edi 7: 41 83 e5 02 and $0x2,%r13d b: 4c 89 ee mov %r13,%rsi e: e8 70 3f b6 fc call 0xfcb63f83 13: 4d 85 ed test %r13,%r13 16: 75 33 jne 0x4b 18: e8 c6 44 b6 fc call 0xfcb644e3 1d: 48 89 e9 mov %rbp,%rcx 20: 48 89 df mov %rbx,%rdi 23: 4c 89 e6 mov %r12,%rsi 26: 48 c1 e9 02 shr $0x2,%rcx * 2a: f3 a5 rep movsl %ds:(%rsi),%es:(%rdi) <-- trapping instruction 2c: 40 f6 c5 02 test $0x2,%bpl 30: 74 02 je 0x34 32: 66 a5 movsw %ds:(%rsi),%es:(%rdi) 34: 40 f6 c5 01 test $0x1,%bpl 38: 74 01 je 0x3b 3a: a4 movsb %ds:(%rsi),%es:(%rdi) 3b: e8 a3 44 b6 fc call 0xfcb644e3 --- This report is generated by a bot. It may contain errors. See https://goo.gl/tpsmEJ for more information about syzbot. syzbot engineers can be reached at syzkaller@googlegroups.com. syzbot will keep track of this issue. See: https://goo.gl/tpsmEJ#status for how to communicate with syzbot. If the report is already addressed, let syzbot know by replying with: #syz fix: exact-commit-title If you want syzbot to run the reproducer, reply with: #syz test: git://repo/address.git branch-or-commit-hash If you attach or paste a git patch, syzbot will apply it before testing. If you want to overwrite report's subsystems, reply with: #syz set subsystems: new-subsystem (See the list of subsystem names on the web dashboard) If the report is a duplicate of another one, reply with: #syz dup: exact-subject-of-another-report If you want to undo deduplication, reply with: #syz undup