mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* Re: [syzbot] [fs?] BUG: sleeping function called from invalid context in null_process_zoned_cmd
       [not found] <tencent_999CB8C41F7DC82430049D1451246C751E07@qq.com>
@ 2026-08-25  5:53 ` syzbot
  0 siblings, 0 replies; 3+ messages in thread
From: syzbot @ 2026-08-25  5:53 UTC (permalink / raw)
  To: chenglingfei, linux-kernel, syzkaller-bugs

Hello,

syzbot tried to test the proposed patch but the build/boot failed:

 CPU 2 isn't AMD or Hygon
[    5.920548][    T1] clocksource: tsc: mask: 0xffffffffffffffff max_cycles: 0x257a472b559, max_idle_ns: 440795210424 ns
[    5.928896][    T1] clocksource: Switched to clocksource tsc
[    5.966744][   T95] kworker/u33:2 (95) used greatest stack depth: 27720 bytes left
[    5.972615][   T90] kworker/u33:2 (90) used greatest stack depth: 27592 bytes left
[    5.979893][  T103] kworker/u33:2 (103) used greatest stack depth: 26920 bytes left
[    5.987926][    T1] Initialise system trusted keyrings
[    5.993265][    T1] workingset: timestamp_bits=40 (anon: 35) max_order=20 bucket_order=0 (anon: 0)
[    6.008184][    T1] DLM installed
[    6.015925][    T1] squashfs: version 4.0 (2009/01/31) Phillip Lougher
[    6.029785][    T1] NFS: Registering the id_resolver key type
[    6.034439][    T1] Key type id_resolver registered
[    6.038151][    T1] Key type id_legacy registered
[    6.042257][    T1] nfs4filelayout_init: NFSv4 File Layout Driver Registering...
[    6.048124][    T1] nfs4flexfilelayout_init: NFSv4 Flexfile Layout Driver Registering...
[    6.058409][    T1] smbdirect: subsystem loading...
[    6.070267][    T1] smbdirect: subsystem loaded
[    6.083793][    T1] Key type cifs.spnego registered
[    6.088182][    T1] Key type cifs.idmap registered
[    6.095602][    T1] ntfs3: Enabled Linux POSIX ACLs support
[    6.099584][    T1] ntfs3: Read-only LZX/Xpress compression included
[    6.105163][    T1] jffs2: version 2.2. (NAND) (SUMMARY)  © 2001-2006 Red Hat, Inc.
[    6.112882][    T1] romfs: ROMFS MTD (C) 2007 Red Hat, Inc.
[    6.116689][    T1] QNX4 filesystem 0.2.3 registered.
[    6.120294][    T1] qnx6: QNX6 filesystem 1.0.0 registered.
[    6.126240][    T1] fuse: init (API version 7.45)
[    6.131465][    T1] orangefs_debugfs_init: called with debug mask: :none: :0:
[    6.136575][    T1] orangefs_init: module version upstream loaded
[    6.141584][    T1] JFS: nTxBlock = 8192, nTxLock = 65536
[    6.157026][    T1] SGI XFS with ACLs, security attributes, realtime, scrub, repair, quota, no debug enabled
[    6.172144][    T1] 9p: Installing v9fs 9p2000 file system support
[    6.177487][    T1] NILFS version 2 loaded
[    6.180358][    T1] befs: version: 0.9.3
[    6.184175][    T1] ocfs2: Registered cluster interface o2cb
[    6.190605][    T1] ocfs2: Registered cluster interface user
[    6.196843][    T1] OCFS2 User DLM kernel interface loaded
[    6.212296][    T1] gfs2: GFS2 installed
[    6.224419][    T1] ceph: loaded (mds proto 32)
[    6.235114][    T1] NET: Registered PF_ALG protocol family
[    6.240190][    T1] async_tx: api initialized (async)
[    6.244290][    T1] Key type asymmetric registered
[    6.247775][    T1] Asymmetric key parser 'x509' registered
[    6.252135][    T1] Asymmetric key parser 'pkcs8' registered
[    6.256739][    T1] Key type pkcs7_test registered
[    6.261335][    T1] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 239)
[    6.268306][    T1] io scheduler mq-deadline registered
[    6.272453][    T1] io scheduler kyber registered
[    6.277229][    T1] io scheduler bfq registered
[    6.282008][    T1] raid6: skipped pq benchmark and selected avx512x4
[    6.326623][    T1] ACPI: \_SB_.GSIE: Enabled at IRQ 20
[    6.339263][    T1] pcieport 0000:00:04.0: PME: Signaling with IRQ 25
[    6.347658][    T1] pcieport 0000:00:04.0: AER: enabled with IRQ 26
[    6.358885][    T1] input: Power Button as /devices/platform/LNXPWRBN:00/input/input0
[    6.365360][    T1] ACPI: button: Power Button [PWRF]
[    6.821471][    T1] ioatdma: Intel(R) QuickData Technology Driver 5.00
[    6.864221][    T1] ACPI: \_SB_.GSIF: Enabled at IRQ 21
[    6.913083][    T1] ACPI: \_SB_.GSIH: Enabled at IRQ 23
[    7.300354][    T1] N_HDLC line discipline registered with maxframe=4096
[    7.306580][    T1] Serial: 8250/16550 driver, 4 ports, IRQ sharing enabled
[    7.316023][    T1] 00:04: ttyS0 at I/O 0x3f8 (irq = 4, base_baud = 115200) is a 16550A
[    7.371153][    T1] Non-volatile memory driver v1.3
[    7.385612][    T1] usbcore: registered new interface driver xillyusb
[    7.391742][    T1] ACPI: bus type drm_connector registered
[    7.402308][    T1] [drm] Initialized vgem 1.0.0 for vgem on minor 0
[    7.406836][    T1] usbcore: registered new interface driver udl
[    7.412639][    T1] [drm] pci: virtio-vga detected at 0000:00:01.0
[    7.416739][    T1] virtio-pci 0000:00:01.0: vgaarb: deactivate vga console
[    7.447723][    T1] Console: switching to colour dummy device 80x25
[    7.454127][    T1] [drm] features: -virgl +edid -resource_blob -host_visible
[    7.454144][    T1] [drm] features: -context_init -blob_alignment
[    7.469464][    T1] [drm] number of scanouts: 1
[    7.472569][    T1] [drm] number of cap sets: 0
[    7.479550][    T1] ------------[ cut here ]------------
[    7.483840][    T1] [PLANE:36:plane-1] pixel format with alpha exposed but blend mode not setup
[    7.483851][    T1] WARNING: drivers/gpu/drm/drm_mode_config.c:872 at drm_mode_config_validate+0xfb4/0x1be0, CPU#2: swapper/0/1
[    7.497077][    T1] Modules linked in:
[    7.499575][    T1] CPU: 2 UID: 0 PID: 1 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT(full) 
[    7.505285][    T1] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[    7.511871][    T1] RIP: 0010:drm_mode_config_validate+0xfbb/0x1be0
[    7.515787][    T1] Code: 00 49 8b 57 18 48 89 f8 48 c1 e8 03 0f b6 04 28 84 c0 74 08 3c 03 0f 8e 00 0b 00 00 48 8d 3d fc 17 7f 0b 41 8b b7 c8 00 00 00 <67> 48 0f b9 3a e9 fa fd ff ff 48 8b 5c 24 20 e8 31 b8 3a fc 48 8d
[    7.528835][    T1] RSP: 0000:ffffc90000047908 EFLAGS: 00010246
[    7.532450][    T1] RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000000
[    7.537352][    T1] RDX: ffff88802673aba0 RSI: 0000000000000024 RDI: ffffffff914f83e0
[    7.543033][    T1] RBP: dffffc0000000000 R08: 0000000000000001 R09: 0000000000000000
[    7.548689][    T1] R10: 0000000000000001 R11: 0000000000000000 R12: ffffed1004a90223
[    7.553929][    T1] R13: ffffed1004a90224 R14: 0000000000000001 R15: ffff888025481028
[    7.559090][    T1] FS:  0000000000000000(0000) GS:ffff8880d5d86000(0000) knlGS:0000000000000000
[    7.565060][    T1] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[    7.569914][    T1] CR2: 0000000000000000 CR3: 000000000eb94000 CR4: 0000000000352ef0
[    7.575236][    T1] Call Trace:
[    7.577408][    T1]  <TASK>
[    7.579346][    T1]  ? queue_work_on+0x137/0x1e0
[    7.582467][    T1]  drm_dev_register+0x56e/0x7b0
[    7.585510][    T1]  ? aperture_remove_conflicting_pci_devices+0x138/0x1e0
[    7.590136][    T1]  virtio_gpu_probe+0x271/0x360
[    7.594261][    T1]  virtio_dev_probe+0x6a2/0xbe0
[    7.597931][    T1]  ? __pfx_virtio_dev_probe+0x10/0x10
[    7.601529][    T1]  ? kernfs_create_link+0x1bd/0x240
[    7.604905][    T1]  ? kernfs_put+0x3f/0x60
[    7.607728][    T1]  ? sysfs_do_create_link_sd+0xbb/0x140
[    7.611608][    T1]  ? sysfs_create_link+0x68/0xc0
[    7.614844][    T1]  ? __pfx_virtio_dev_probe+0x10/0x10
[    7.618832][    T1]  really_probe+0x241/0xa60
[    7.622344][    T1]  __driver_probe_device+0x210/0x460
[    7.625767][    T1]  ? _raw_spin_unlock_irqrestore+0x52/0x80
[    7.629636][    T1]  driver_probe_device+0x4a/0x140
[    7.632912][    T1]  __driver_attach+0x21f/0x5b0
[    7.636213][    T1]  ? __pfx___driver_attach+0x10/0x10
[    7.640349][    T1]  bus_for_each_dev+0x13e/0x1d0
[    7.643783][    T1]  ? __pfx_bus_for_each_dev+0x10/0x10
[    7.647287][    T1]  ? bus_add_driver+0x2b5/0x5b0
[    7.650463][    T1]  bus_add_driver+0x305/0x5b0
[    7.653607][    T1]  driver_register+0x1e2/0x360
[    7.656745][    T1]  ? __pfx_virtio_gpu_driver_init+0x10/0x10
[    7.660840][    T1]  virtio_gpu_driver_init+0xc9/0x170
[    7.664956][    T1]  do_one_initcall+0x11c/0x6f0
[    7.667924][    T1]  ? __pfx_do_one_initcall+0x10/0x10
[    7.671447][    T1]  ? kernel_init_freeable+0x4ca/0x7b0
[    7.674985][    T1]  kernel_init_freeable+0x6ea/0x7b0
[    7.678315][    T1]  ? __pfx_kernel_init+0x10/0x10
[    7.681690][    T1]  kernel_init+0x21/0x1e0
[    7.684914][    T1]  ? __pfx_kernel_init+0x10/0x10
[    7.688165][    T1]  ret_from_fork+0x730/0xd60
[    7.691097][    T1]  ? __pfx_ret_from_fork+0x10/0x10
[    7.694414][    T1]  ? __switch_to+0x800/0x10f0
[    7.697010][    T1]  ? __pfx_kernel_init+0x10/0x10
[    7.700493][    T1]  ret_from_fork_asm+0x1a/0x30
[    7.703873][    T1]  </TASK>
[    7.705916][    T1] Kernel panic - not syncing: kernel: panic_on_warn set ...
[    7.710697][    T1] CPU: 2 UID: 0 PID: 1 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT(full) 
[    7.713825][    T1] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[    7.721936][    T1] Call Trace:
[    7.721936][    T1]  <TASK>
[    7.721936][    T1]  dump_stack_lvl+0x100/0x190
[    7.721936][    T1]  vpanic+0x553/0x970
[    7.731953][    T1]  ? __pfx_vpanic+0x10/0x10
[    7.731953][    T1]  panic+0xd1/0xe0
[    7.731953][    T1]  ? __pfx_panic+0x10/0x10
[    7.731953][    T1]  check_panic_on_warn.cold+0x19/0x34
[    7.741929][    T1]  ? drm_mode_config_validate+0xfb4/0x1be0
[    7.741929][    T1]  __warn.cold+0x191/0x318
[    7.741929][    T1]  __report_bug+0x30f/0x440
[    7.751926][    T1]  ? drm_mode_config_validate+0xfb4/0x1be0
[    7.751926][    T1]  ? __pfx___report_bug+0x10/0x10
[    7.751926][    T1]  ? __pfx___might_resched+0x10/0x10
[    7.751926][    T1]  ? schedule_timeout+0x161/0x280
[    7.761899][    T1]  report_bug_entry+0xe2/0x290
[    7.761899][    T1]  ? drm_mode_config_validate+0xfbb/0x1be0
[    7.761899][    T1]  handle_bug+0x1cd/0x2a0
[    7.771917][    T1]  exc_invalid_op+0x17/0x50
[    7.771917][    T1]  asm_exc_invalid_op+0x1a/0x20
[    7.771917][    T1] RIP: 0010:drm_mode_config_validate+0xfbb/0x1be0
[    7.781934][    T1] Code: 00 49 8b 57 18 48 89 f8 48 c1 e8 03 0f b6 04 28 84 c0 74 08 3c 03 0f 8e 00 0b 00 00 48 8d 3d fc 17 7f 0b 41 8b b7 c8 00 00 00 <67> 48 0f b9 3a e9 fa fd ff ff 48 8b 5c 24 20 e8 31 b8 3a fc 48 8d
[    7.791926][    T1] RSP: 0000:ffffc90000047908 EFLAGS: 00010246
[    7.791926][    T1] RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000000
[    7.801957][    T1] RDX: ffff88802673aba0 RSI: 0000000000000024 RDI: ffffffff914f83e0
[    7.801957][    T1] RBP: dffffc0000000000 R08: 0000000000000001 R09: 0000000000000000
[    7.801957][    T1] R10: 0000000000000001 R11: 0000000000000000 R12: ffffed1004a90223
[    7.811925][    T1] R13: ffffed1004a90224 R14: 0000000000000001 R15: ffff888025481028
[    7.811925][    T1]  ? drm_mode_config_validate+0xf76/0x1be0
[    7.821948][    T1]  ? queue_work_on+0x137/0x1e0
[    7.821948][    T1]  drm_dev_register+0x56e/0x7b0
[    7.821948][    T1]  ? aperture_remove_conflicting_pci_devices+0x138/0x1e0
[    7.831946][    T1]  virtio_gpu_probe+0x271/0x360
[    7.831946][    T1]  virtio_dev_probe+0x6a2/0xbe0
[    7.831946][    T1]  ? __pfx_virtio_dev_probe+0x10/0x10
[    7.831946][    T1]  ? kernfs_create_link+0x1bd/0x240
[    7.841920][    T1]  ? kernfs_put+0x3f/0x60
[    7.841920][    T1]  ? sysfs_do_create_link_sd+0xbb/0x140
[    7.841920][    T1]  ? sysfs_create_link+0x68/0xc0
[    7.851918][    T1]  ? __pfx_virtio_dev_probe+0x10/0x10
[    7.851918][    T1]  really_probe+0x241/0xa60
[    7.851918][    T1]  __driver_probe_device+0x210/0x460
[    7.851918][    T1]  ? _raw_spin_unlock_irqrestore+0x52/0x80
[    7.861907][    T1]  driver_probe_device+0x4a/0x140
[    7.861907][    T1]  __driver_attach+0x21f/0x5b0
[    7.861907][    T1]  ? __pfx___driver_attach+0x10/0x10
[    7.861907][    T1]  bus_for_each_dev+0x13e/0x1d0
[    7.871920][    T1]  ? __pfx_bus_for_each_dev+0x10/0x10
[    7.871920][    T1]  ? bus_add_driver+0x2b5/0x5b0
[    7.871920][    T1]  bus_add_driver+0x305/0x5b0
[    7.882003][    T1]  driver_register+0x1e2/0x360
[    7.882003][    T1]  ? __pfx_virtio_gpu_driver_init+0x10/0x10
[    7.882003][    T1]  virtio_gpu_driver_init+0xc9/0x170
[    7.882003][    T1]  do_one_initcall+0x11c/0x6f0
[    7.891966][    T1]  ? __pfx_do_one_initcall+0x10/0x10
[    7.891966][    T1]  ? kernel_init_freeable+0x4ca/0x7b0
[    7.891966][    T1]  kernel_init_freeable+0x6ea/0x7b0
[    7.901925][    T1]  ? __pfx_kernel_init+0x10/0x10
[    7.901925][    T1]  kernel_init+0x21/0x1e0
[    7.901925][    T1]  ? __pfx_kernel_init+0x10/0x10
[    7.911919][    T1]  ret_from_fork+0x730/0xd60
[    7.911919][    T1]  ? __pfx_ret_from_fork+0x10/0x10
[    7.921868][    T1]  ? __switch_to+0x800/0x10f0
[    7.921933][    T1]  ? __pfx_kernel_init+0x10/0x10
[    7.921933][    T1]  ret_from_fork_asm+0x1a/0x30
[    7.921933][    T1]  </TASK>
[    7.931929][    T1] Kernel Offset: disabled
[    7.931929][    T1] Rebooting in 86400 seconds..


syzkaller build log:
go env (err=<nil>)
AR='ar'
CC='gcc'
CGO_CFLAGS='-O2 -g'
CGO_CPPFLAGS=''
CGO_CXXFLAGS='-O2 -g'
CGO_ENABLED='1'
CGO_FFLAGS='-O2 -g'
CGO_LDFLAGS='-O2 -g'
CXX='g++'
GCCGO='gccgo'
GO111MODULE='auto'
GOAMD64='v1'
GOARCH='amd64'
GOAUTH='netrc'
GOBIN=''
GOCACHE='/syzkaller/.cache/go-build'
GOCACHEPROG=''
GODEBUG=''
GOENV='/syzkaller/.config/go/env'
GOEXE=''
GOEXPERIMENT=''
GOFIPS140='off'
GOFLAGS=''
GOGCCFLAGS='-fPIC -m64 -pthread -Wl,--no-gc-sections -fmessage-length=0 -ffile-prefix-map=/tmp/go-build1704445191=/tmp/go-build -gno-record-gcc-switches'
GOHOSTARCH='amd64'
GOHOSTOS='linux'
GOINSECURE=''
GOMOD='/syzkaller/jobs/linux/gopath/src/github.com/google/syzkaller/go.mod'
GOMODCACHE='/syzkaller/jobs/linux/gopath/pkg/mod'
GONOPROXY=''
GONOSUMDB=''
GOOS='linux'
GOPATH='/syzkaller/jobs/linux/gopath'
GOPRIVATE=''
GOPROXY='https://proxy.golang.org,direct'
GOROOT='/usr/local/go'
GOSUMDB='sum.golang.org'
GOTELEMETRY='local'
GOTELEMETRYDIR='/syzkaller/.config/go/telemetry'
GOTMPDIR=''
GOTOOLCHAIN='auto'
GOTOOLDIR='/usr/local/go/pkg/tool/linux_amd64'
GOVCS=''
GOVERSION='go1.26.0'
GOWORK=''
PKG_CONFIG='pkg-config'

git status (err=<nil>)
HEAD detached at 5d63f80b763
nothing to commit, working tree clean


tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
go list -f '{{.Stale}}' -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=5d63f80b763910b40ae04a96c13dc75d621bea67 -X github.com/google/syzkaller/prog.gitRevisionDate=20260807-150932"  ./sys/syz-sysgen | grep -q false || go install -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=5d63f80b763910b40ae04a96c13dc75d621bea67 -X github.com/google/syzkaller/prog.gitRevisionDate=20260807-150932"  ./sys/syz-sysgen
make .descriptions
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
bin/syz-sysgen
touch .descriptions
GOOS=linux GOARCH=amd64 go build -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=5d63f80b763910b40ae04a96c13dc75d621bea67 -X github.com/google/syzkaller/prog.gitRevisionDate=20260807-150932"  -o ./bin/linux_amd64/syz-execprog github.com/google/syzkaller/tools/syz-execprog
mkdir -p ./bin/linux_amd64
g++ -o ./bin/linux_amd64/syz-executor executor/executor.cc \
	-m64 -O2 -pthread -Wall -Werror -Wparentheses -Wunused-const-variable -Wframe-larger-than=16384 -Wno-stringop-overflow -Wno-array-bounds -Wno-format-overflow -Wno-unused-but-set-variable -Wno-unused-command-line-argument -static-pie -std=c++17 -I. -Iexecutor/_include   -DGOOS_linux=1 -DGOARCH_amd64=1 \
	-DHOSTGOOS_linux=1 -DGIT_REVISION=\"5d63f80b763910b40ae04a96c13dc75d621bea67\"
/usr/bin/ld: /tmp/ccHojYjg.o: in function `Connection::Connect(char const*, char const*)':
executor.cc:(.text._ZN10Connection7ConnectEPKcS1_[_ZN10Connection7ConnectEPKcS1_]+0x386): warning: Using 'gethostbyname' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking
./tools/check-syzos.sh 2>/dev/null


Error text is too large and was truncated, full error text is at:
https://syzkaller.appspot.com/x/error.txt?x=16fd1979580000


Tested on:

commit:         66498c75 Merge tag 'dmaengine-7.3-rc1' of git://git.ke..
git tree:       upstream
kernel config:  https://syzkaller.appspot.com/x/.config?x=a5a468648ec369c9
dashboard link: https://syzkaller.appspot.com/bug?extid=b6fd00508cc05a5c003c
compiler:       gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
patch:          https://syzkaller.appspot.com/x/patch.diff?x=1451b979580000


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [syzbot] [fs?] BUG: sleeping function called from invalid context in null_process_zoned_cmd
       [not found] <tencent_A58B766013F284C4A9FF1041868115E8D40A@qq.com>
@ 2026-08-25  6:09 ` syzbot
  0 siblings, 0 replies; 3+ messages in thread
From: syzbot @ 2026-08-25  6:09 UTC (permalink / raw)
  To: chenglingfei, linux-kernel, syzkaller-bugs

Hello,

syzbot has tested the proposed patch and the reproducer did not trigger any issue:

Reported-by: syzbot+b6fd00508cc05a5c003c@syzkaller.appspotmail.com
Tested-by: syzbot+b6fd00508cc05a5c003c@syzkaller.appspotmail.com

Tested on:

commit:         2f1baf1f Merge tag 'trace-v7.2-rc7' of git://git.kerne..
git tree:       git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
console output: https://syzkaller.appspot.com/x/log.txt?x=105d499e580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=c44651ea7dd2f307
dashboard link: https://syzkaller.appspot.com/bug?extid=b6fd00508cc05a5c003c
compiler:       gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
patch:          https://syzkaller.appspot.com/x/patch.diff?x=142d499e580000

Note: testing is done by a robot and is best-effort only.

^ permalink raw reply	[flat|nested] 3+ messages in thread

* [syzbot] [fs?] BUG: sleeping function called from invalid context in null_process_zoned_cmd
@ 2026-08-14  9:19 syzbot
  0 siblings, 0 replies; 3+ messages in thread
From: syzbot @ 2026-08-14  9:19 UTC (permalink / raw)
  To: linux-fsdevel, linux-kernel, syzkaller-bugs

Hello,

syzbot found the following issue on:

HEAD commit:    2f1baf1fc892 Merge tag 'trace-v7.2-rc7' of git://git.kerne..
git tree:       upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=10498a25580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=c44651ea7dd2f307
dashboard link: https://syzkaller.appspot.com/bug?extid=b6fd00508cc05a5c003c
compiler:       gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
C reproducer:   https://syzkaller.appspot.com/x/repro.c?x=1715f149580000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+b6fd00508cc05a5c003c@syzkaller.appspotmail.com

null_blk: mydev: using native zone append
BUG: sleeping function called from invalid context at kernel/locking/mutex.c:623
in_atomic(): 0, irqs_disabled(): 0, non_block: 0, pid: 6035, name: syz-executor507
preempt_count: 0, expected: 0
RCU nest depth: 1, expected: 0
6 locks held by syz-executor507/6035:
 #0: ffff888023e9e450 (sb_writers#13){.+.+}-{0:0}, at: ksys_write+0x12a/0x250 fs/read_write.c:739
 #1: ffff8880385e1080 (&buffer->mutex){+.+.}-{4:4}, at: configfs_write_iter+0x76/0x4e0 fs/configfs/file.c:226
 #2: ffff88802ca06570 (&p->frag_sem){.+.+}-{4:4}, at: flush_write_buffer fs/configfs/file.c:205 [inline]
 #2: ffff88802ca06570 (&p->frag_sem){.+.+}-{4:4}, at: configfs_write_iter+0x218/0x4e0 fs/configfs/file.c:229
 #3: ffffffff9ba14a40 (&lock){+.+.}-{4:4}, at: nullb_device_power_store+0xde/0x350 drivers/block/null_blk/main.c:496
 #4: ffff888045820350 (&disk->open_mutex){+.+.}-{4:4}, at: bdev_open+0x41a/0xe40 block/bdev.c:948
 #5: ffffffff8ebe8200 (rcu_read_lock){....}-{1:3}, at: rcu_lock_acquire include/linux/rcupdate.h:300 [inline]
 #5: ffffffff8ebe8200 (rcu_read_lock){....}-{1:3}, at: rcu_read_lock include/linux/rcupdate.h:840 [inline]
 #5: ffffffff8ebe8200 (rcu_read_lock){....}-{1:3}, at: blk_mq_submit_bio+0x21b2/0x3000 block/blk-mq.c:3208
CPU: 3 UID: 0 PID: 6035 Comm: syz-executor507 Not tainted syzkaller #0 PREEMPT(full) 
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Call Trace:
 <TASK>
 __dump_stack lib/dump_stack.c:94 [inline]
 dump_stack_lvl+0x100/0x190 lib/dump_stack.c:120
 __might_resched.cold+0x1ec/0x232 kernel/sched/core.c:9197
 __mutex_lock_common kernel/locking/mutex.c:623 [inline]
 __mutex_lock+0x10e/0x1bd0 kernel/locking/mutex.c:821
 null_lock_zone drivers/block/null_blk/zoned.c:39 [inline]
 null_lock_zone drivers/block/null_blk/zoned.c:33 [inline]
 null_process_zoned_cmd+0x943/0x10a0 drivers/block/null_blk/zoned.c:732
 null_handle_cmd drivers/block/null_blk/main.c:1455 [inline]
 null_queue_rq+0x664/0xfb0 drivers/block/null_blk/main.c:1703
 __blk_mq_issue_directly+0xe2/0x200 block/blk-mq.c:2694
 blk_mq_try_issue_directly+0x21b/0x420 block/blk-mq.c:2754
 blk_mq_submit_bio+0x21ec/0x3000 block/blk-mq.c:3208
 __submit_bio+0x90/0x3d0 block/blk-core.c:673
 __submit_bio_noacct_mq block/blk-core.c:756 [inline]
 submit_bio_noacct_nocheck+0x549/0xc00 block/blk-core.c:790
 submit_bio_noacct+0xd18/0x1ff0 block/blk-core.c:921
 blk_crypto_submit_bio include/linux/blk-crypto.h:203 [inline]
 __bh_submit+0x721/0x950 fs/buffer.c:1225
 bh_submit fs/buffer.c:1239 [inline]
 block_read_full_folio+0x496/0x8c0 fs/buffer.c:2463
 filemap_read_folio+0xfc/0x3b0 mm/filemap.c:2516
 do_read_cache_folio+0x2d7/0x6b0 mm/filemap.c:4146
 read_mapping_folio include/linux/pagemap.h:1015 [inline]
 read_part_sector+0xd1/0x370 block/partitions/core.c:724
 adfspart_check_ICS+0x91/0x7d0 block/partitions/acorn.c:357
 check_partition block/partitions/core.c:143 [inline]
 blk_add_partitions block/partitions/core.c:591 [inline]
 bdev_disk_changed+0x7b1/0x1260 block/partitions/core.c:695
 blkdev_get_whole+0x187/0x290 block/bdev.c:751
 bdev_open+0x2c7/0xe40 block/bdev.c:960
 bdev_file_open_by_dev block/bdev.c:1062 [inline]
 bdev_file_open_by_dev+0x179/0x210 block/bdev.c:1037
 disk_scan_partitions+0x1ef/0x320 block/genhd.c:387
 add_disk_final block/genhd.c:412 [inline]
 add_disk_fwnode+0x3f4/0x480 block/genhd.c:606
 add_disk include/linux/blkdev.h:800 [inline]
 null_add_dev+0x129d/0x1df0 drivers/block/null_blk/main.c:2052
 nullb_device_power_store+0x29d/0x350 drivers/block/null_blk/main.c:501
 flush_write_buffer fs/configfs/file.c:207 [inline]
 configfs_write_iter+0x302/0x4e0 fs/configfs/file.c:229
 new_sync_write fs/read_write.c:595 [inline]
 vfs_write+0x6ac/0x1050 fs/read_write.c:687
 ksys_write+0x12a/0x250 fs/read_write.c:739
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0x115/0x870 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fdede8c12f7
Code: 48 89 fa 4c 89 df e8 98 1d 00 00 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 1a 5b c3 0f 1f 84 00 00 00 00 00 48 8b 44 24 10 0f 05 <5b> c3 0f 1f 80 00 00 00 00 83 e2 39 83 fa 08 75 de e8 23 ff ff ff
RSP: 002b:00007ffc5fd85ed0 EFLAGS: 00000202 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 000055557028a400 RCX: 00007fdede8c12f7
RDX: 0000000000000002 RSI: 00007fdede8fa060 RDI: 0000000000000003
RBP: 00007fdede8fa060 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000202 R12: 00007fdede8fc238
R13: 0000000000000002 R14: 00007fdede924cc0 R15: 0000000000000002
 </TASK>

=============================
[ BUG: Invalid wait context ]
syzkaller #0 Tainted: G        W          
-----------------------------
syz-executor507/6035 is trying to lock:
ffff8880455c0060 (&zone->mutex){+.+.}-{4:4}, at: null_lock_zone drivers/block/null_blk/zoned.c:39 [inline]
ffff8880455c0060 (&zone->mutex){+.+.}-{4:4}, at: null_lock_zone drivers/block/null_blk/zoned.c:33 [inline]
ffff8880455c0060 (&zone->mutex){+.+.}-{4:4}, at: null_process_zoned_cmd+0x943/0x10a0 drivers/block/null_blk/zoned.c:732
other info that might help us debug this:
context-{5:5}
6 locks held by syz-executor507/6035:
 #0: ffff888023e9e450 (sb_writers#13){.+.+}-{0:0}, at: ksys_write+0x12a/0x250 fs/read_write.c:739
 #1: ffff8880385e1080 (&buffer->mutex){+.+.}-{4:4}, at: configfs_write_iter+0x76/0x4e0 fs/configfs/file.c:226
 #2: ffff88802ca06570 (&p->frag_sem){.+.+}-{4:4}, at: flush_write_buffer fs/configfs/file.c:205 [inline]
 #2: ffff88802ca06570 (&p->frag_sem){.+.+}-{4:4}, at: configfs_write_iter+0x218/0x4e0 fs/configfs/file.c:229
 #3: ffffffff9ba14a40 (&lock){+.+.}-{4:4}, at: nullb_device_power_store+0xde/0x350 drivers/block/null_blk/main.c:496
 #4: ffff888045820350 (&disk->open_mutex){+.+.}-{4:4}, at: bdev_open+0x41a/0xe40 block/bdev.c:948
 #5: ffffffff8ebe8200 (rcu_read_lock){....}-{1:3}, at: rcu_lock_acquire include/linux/rcupdate.h:300 [inline]
 #5: ffffffff8ebe8200 (rcu_read_lock){....}-{1:3}, at: rcu_read_lock include/linux/rcupdate.h:840 [inline]
 #5: ffffffff8ebe8200 (rcu_read_lock){....}-{1:3}, at: blk_mq_submit_bio+0x21b2/0x3000 block/blk-mq.c:3208
stack backtrace:
CPU: 3 UID: 0 PID: 6035 Comm: syz-executor507 Tainted: G        W           syzkaller #0 PREEMPT(full) 
Tainted: [W]=WARN
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Call Trace:
 <TASK>
 __dump_stack lib/dump_stack.c:94 [inline]
 dump_stack_lvl+0x100/0x190 lib/dump_stack.c:120
 print_lock_invalid_wait_context kernel/locking/lockdep.c:4830 [inline]
 check_wait_context kernel/locking/lockdep.c:4902 [inline]
 __lock_acquire+0xf75/0x1a40 kernel/locking/lockdep.c:5187
 lock_acquire kernel/locking/lockdep.c:5868 [inline]
 lock_acquire+0x1b9/0x370 kernel/locking/lockdep.c:5825
 __mutex_lock_common kernel/locking/mutex.c:646 [inline]
 __mutex_lock+0x1a4/0x1bd0 kernel/locking/mutex.c:821
 null_lock_zone drivers/block/null_blk/zoned.c:39 [inline]
 null_lock_zone drivers/block/null_blk/zoned.c:33 [inline]
 null_process_zoned_cmd+0x943/0x10a0 drivers/block/null_blk/zoned.c:732
 null_handle_cmd drivers/block/null_blk/main.c:1455 [inline]
 null_queue_rq+0x664/0xfb0 drivers/block/null_blk/main.c:1703
 __blk_mq_issue_directly+0xe2/0x200 block/blk-mq.c:2694
 blk_mq_try_issue_directly+0x21b/0x420 block/blk-mq.c:2754
 blk_mq_submit_bio+0x21ec/0x3000 block/blk-mq.c:3208
 __submit_bio+0x90/0x3d0 block/blk-core.c:673
 __submit_bio_noacct_mq block/blk-core.c:756 [inline]
 submit_bio_noacct_nocheck+0x549/0xc00 block/blk-core.c:790
 submit_bio_noacct+0xd18/0x1ff0 block/blk-core.c:921
 blk_crypto_submit_bio include/linux/blk-crypto.h:203 [inline]
 __bh_submit+0x721/0x950 fs/buffer.c:1225
 bh_submit fs/buffer.c:1239 [inline]
 block_read_full_folio+0x496/0x8c0 fs/buffer.c:2463
 filemap_read_folio+0xfc/0x3b0 mm/filemap.c:2516
 do_read_cache_folio+0x2d7/0x6b0 mm/filemap.c:4146
 read_mapping_folio include/linux/pagemap.h:1015 [inline]
 read_part_sector+0xd1/0x370 block/partitions/core.c:724
 adfspart_check_ICS+0x91/0x7d0 block/partitions/acorn.c:357
 check_partition block/partitions/core.c:143 [inline]
 blk_add_partitions block/partitions/core.c:591 [inline]
 bdev_disk_changed+0x7b1/0x1260 block/partitions/core.c:695
 blkdev_get_whole+0x187/0x290 block/bdev.c:751
 bdev_open+0x2c7/0xe40 block/bdev.c:960
 bdev_file_open_by_dev block/bdev.c:1062 [inline]
 bdev_file_open_by_dev+0x179/0x210 block/bdev.c:1037
 disk_scan_partitions+0x1ef/0x320 block/genhd.c:387
 add_disk_final block/genhd.c:412 [inline]
 add_disk_fwnode+0x3f4/0x480 block/genhd.c:606
 add_disk include/linux/blkdev.h:800 [inline]
 null_add_dev+0x129d/0x1df0 drivers/block/null_blk/main.c:2052
 nullb_device_power_store+0x29d/0x350 drivers/block/null_blk/main.c:501
 flush_write_buffer fs/configfs/file.c:207 [inline]
 configfs_write_iter+0x302/0x4e0 fs/configfs/file.c:229
 new_sync_write fs/read_write.c:595 [inline]
 vfs_write+0x6ac/0x1050 fs/read_write.c:687
 ksys_write+0x12a/0x250 fs/read_write.c:739
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0x115/0x870 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fdede8c12f7
Code: 48 89 fa 4c 89 df e8 98 1d 00 00 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 1a 5b c3 0f 1f 84 00 00 00 00 00 48 8b 44 24 10 0f 05 <5b> c3 0f 1f 80 00 00 00 00 83 e2 39 83 fa 08 75 de e8 23 ff ff ff
RSP: 002b:00007ffc5fd85ed0 EFLAGS: 00000202 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 000055557028a400 RCX: 00007fdede8c12f7
RDX: 0000000000000002 RSI: 00007fdede8fa060 RDI: 0000000000000003
RBP: 00007fdede8fa060 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000202 R12: 00007fdede8fc238
R13: 0000000000000002 R14: 00007fdede924cc0 R15: 0000000000000002
 </TASK>
null_blk: disk mydev created


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-08-25  6:09 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
     [not found] <tencent_999CB8C41F7DC82430049D1451246C751E07@qq.com>
2026-08-25  5:53 ` [syzbot] [fs?] BUG: sleeping function called from invalid context in null_process_zoned_cmd syzbot
     [not found] <tencent_A58B766013F284C4A9FF1041868115E8D40A@qq.com>
2026-08-25  6:09 ` syzbot
2026-08-14  9:19 syzbot

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®