* [syzbot] [mm?] WARNING in vma_add_pgoff
@ 2026-09-08 1:21 syzbot
2026-09-08 2:25 ` Andrew Morton
0 siblings, 1 reply; 6+ messages in thread
From: syzbot @ 2026-09-08 1:21 UTC (permalink / raw)
To: akpm, jannh, liam, linux-kernel, linux-mm, ljs, pfalcato,
syzkaller-bugs, vbabka
Hello,
syzbot found the following issue on:
HEAD commit: 5445d6419962 arm64: Don't read GMID_EL1 when MTE is disabled
git tree: git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git for-kernelci
console output: https://syzkaller.appspot.com/x/log.txt?x=1517ecf9580000
kernel config: https://syzkaller.appspot.com/x/.config?x=56ed23170c168d4c
dashboard link: https://syzkaller.appspot.com/bug?extid=c6879dc677a017f0a21b
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=147ad125580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=127ad125580000
Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/e8b70e3bd109/disk-5445d641.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/e5227e56ac93/vmlinux-5445d641.xz
kernel image: https://storage.googleapis.com/syzbot-assets/54905f78be59/Image-5445d641.gz.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+c6879dc677a017f0a21b@syzkaller.appspotmail.com
------------[ cut here ]------------
WARNING: mm/vma.h:277 at assert_sane_pgoff mm/vma.h:277 [inline], CPU#1: syz.0.17/4912
WARNING: mm/vma.h:277 at vma_set_pgoff mm/vma.h:283 [inline], CPU#1: syz.0.17/4912
WARNING: mm/vma.h:277 at vma_add_pgoff+0x50c/0x700 mm/vma.h:314, CPU#1: syz.0.17/4912
Modules linked in:
CPU: 1 UID: 0 PID: 4912 Comm: syz.0.17 Not tainted syzkaller #0 PREEMPT
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/07/2026
pstate: 83400005 (Nzcv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)
pc : assert_sane_pgoff mm/vma.h:277 [inline]
pc : vma_set_pgoff mm/vma.h:283 [inline]
pc : vma_add_pgoff+0x50c/0x700 mm/vma.h:314
lr : assert_sane_pgoff mm/vma.h:277 [inline]
lr : vma_set_pgoff mm/vma.h:283 [inline]
lr : vma_add_pgoff+0x50c/0x700 mm/vma.h:314
sp : ffff8000963176e0
x29: ffff800096317700 x28: 1fffe00019d174aa x27: 0000000000000001
x26: ffff0000c659b700 x25: dfff800000000000 x24: 1fffe00019d174b0
x23: ffff0000ce8ba580 x22: 0000000000020a97 x21: ffff0000ce8ba548
x20: ffff0000ce8ba500 x19: 0000000020001000 x18: 1fffe00035ba3828
x17: ffff800080adeaf4 x16: ffff800080addecc x15: ffff800080b8bf18
x14: ffff800080b96bac x13: 0000000000000001 x12: 0000000000000000
x11: 0000000000000000 x10: 0000000000000003 x9 : 0000000000000000
x8 : 0000000000000000 x7 : ffff800080bee7b0 x6 : 0000000000000000
x5 : 0000000000000000 x4 : 0000000000000001 x3 : ffff800080ae89e0
x2 : 0000000000020001 x1 : ffff0000c825bb00 x0 : 0000000000000000
Call trace:
assert_sane_pgoff mm/vma.h:277 [inline] (P)
vma_set_pgoff mm/vma.h:283 [inline] (P)
vma_add_pgoff+0x50c/0x700 mm/vma.h:314 (P)
__split_vma+0x6a8/0x83c mm/vma.c:607
split_vma mm/vma.c:643 [inline]
vma_modify+0x11ac/0x18f0 mm/vma.c:1771
vma_modify_policy+0x210/0x2b8 mm/vma.c:1834
mbind_range+0x160/0x3e4 mm/mempolicy.c:1061
do_mbind mm/mempolicy.c:1563 [inline]
kernel_mbind mm/mempolicy.c:1760 [inline]
__do_sys_mbind mm/mempolicy.c:1834 [inline]
__se_sys_mbind mm/mempolicy.c:1830 [inline]
__arm64_sys_mbind+0x5c8/0x994 mm/mempolicy.c:1830
__invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]
invoke_syscall+0x98/0x244 arch/arm64/kernel/syscall.c:49
el0_svc_common+0xec/0x23c arch/arm64/kernel/syscall.c:121
do_el0_svc+0x4c/0x5c arch/arm64/kernel/syscall.c:140
el0_svc+0x64/0x260 arch/arm64/kernel/entry-common.c:758
el0t_64_sync_handler+0x44/0x104 arch/arm64/kernel/entry-common.c:777
el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:590
irq event stamp: 928
hardirqs last enabled at (927): [<ffff8000869a9950>] __raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:210 [inline]
hardirqs last enabled at (927): [<ffff8000869a9950>] _raw_spin_unlock_irqrestore+0x38/0x98 kernel/locking/spinlock.c:221
hardirqs last disabled at (928): [<ffff8000869841d4>] el1_brk64+0x20/0x54 arch/arm64/kernel/entry-common.c:445
softirqs last enabled at (208): [<ffff80008013891c>] local_bh_enable include/linux/bottom_half.h:33 [inline]
softirqs last enabled at (208): [<ffff80008013891c>] put_cpu_fpsimd_context arch/arm64/kernel/fpsimd.c:251 [inline]
softirqs last enabled at (208): [<ffff80008013891c>] do_sve_acc+0x32c/0x4b8 arch/arm64/kernel/fpsimd.c:1349
softirqs last disabled at (206): [<ffff8000801386fc>] local_bh_disable include/linux/bottom_half.h:20 [inline]
softirqs last disabled at (206): [<ffff8000801386fc>] get_cpu_fpsimd_context arch/arm64/kernel/fpsimd.c:234 [inline]
softirqs last disabled at (206): [<ffff8000801386fc>] do_sve_acc+0x10c/0x4b8 arch/arm64/kernel/fpsimd.c:1325
---[ end trace 0000000000000000 ]---
---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [syzbot] [mm?] WARNING in vma_add_pgoff
2026-09-08 1:21 [syzbot] [mm?] WARNING in vma_add_pgoff syzbot
@ 2026-09-08 2:25 ` Andrew Morton
2026-09-08 4:15 ` syzbot
0 siblings, 1 reply; 6+ messages in thread
From: Andrew Morton @ 2026-09-08 2:25 UTC (permalink / raw)
To: syzbot
Cc: jannh, liam, linux-kernel, linux-mm, ljs, pfalcato,
syzkaller-bugs, vbabka
On Mon, 07 Sep 2026 18:21:25 -0700 syzbot <syzbot+c6879dc677a017f0a21b@syzkaller.appspotmail.com> wrote:
> syzbot found the following issue on:
>
> HEAD commit: 5445d6419962 arm64: Don't read GMID_EL1 when MTE is disabled
> git tree: git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git for-kernelci
> console output: https://syzkaller.appspot.com/x/log.txt?x=1517ecf9580000
> kernel config: https://syzkaller.appspot.com/x/.config?x=56ed23170c168d4c
> dashboard link: https://syzkaller.appspot.com/bug?extid=c6879dc677a017f0a21b
> compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
> userspace arch: arm64
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=147ad125580000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=127ad125580000
>
> Downloadable assets:
> disk image: https://storage.googleapis.com/syzbot-assets/e8b70e3bd109/disk-5445d641.raw.xz
> vmlinux: https://storage.googleapis.com/syzbot-assets/e5227e56ac93/vmlinux-5445d641.xz
> kernel image: https://storage.googleapis.com/syzbot-assets/54905f78be59/Image-5445d641.gz.xz
>
> IMPORTANT: if you fix the issue, please add the following tag to the commit:
> Reported-by: syzbot+c6879dc677a017f0a21b@syzkaller.appspotmail.com
>
> ------------[ cut here ]------------
> WARNING: mm/vma.h:277 at assert_sane_pgoff mm/vma.h:277 [inline], CPU#1: syz.0.17/4912
> WARNING: mm/vma.h:277 at vma_set_pgoff mm/vma.h:283 [inline], CPU#1: syz.0.17/4912
> WARNING: mm/vma.h:277 at vma_add_pgoff+0x50c/0x700 mm/vma.h:314, CPU#1: syz.0.17/4912
Thinking Lorenzo already fixed this.
#syz test: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git 35b0fb391b0df57383bc15985bb769f4555c97ba
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [syzbot] [mm?] WARNING in vma_add_pgoff
2026-09-08 2:25 ` Andrew Morton
@ 2026-09-08 4:15 ` syzbot
2026-09-08 9:25 ` Lorenzo Stoakes (ARM)
0 siblings, 1 reply; 6+ messages in thread
From: syzbot @ 2026-09-08 4:15 UTC (permalink / raw)
To: akpm, jannh, liam, linux-kernel, linux-mm, ljs, pfalcato,
syzkaller-bugs, vbabka
Hello,
syzbot has tested the proposed patch and the reproducer did not trigger any issue:
Reported-by: syzbot+c6879dc677a017f0a21b@syzkaller.appspotmail.com
Tested-by: syzbot+c6879dc677a017f0a21b@syzkaller.appspotmail.com
Tested on:
commit: 35b0fb39 mm/mremap: reset unfaulted VMA page offset fo..
git tree: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
console output: https://syzkaller.appspot.com/x/log.txt?x=15e13af9580000
kernel config: https://syzkaller.appspot.com/x/.config?x=56ed23170c168d4c
dashboard link: https://syzkaller.appspot.com/bug?extid=c6879dc677a017f0a21b
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
userspace arch: arm64
Note: no patches were applied.
Note: testing is done by a robot and is best-effort only.
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [syzbot] [mm?] WARNING in vma_add_pgoff
2026-09-08 4:15 ` syzbot
@ 2026-09-08 9:25 ` Lorenzo Stoakes (ARM)
2026-09-08 9:32 ` Vlastimil Babka (SUSE)
0 siblings, 1 reply; 6+ messages in thread
From: Lorenzo Stoakes (ARM) @ 2026-09-08 9:25 UTC (permalink / raw)
To: syzbot
Cc: akpm, jannh, liam, linux-kernel, linux-mm, pfalcato,
syzkaller-bugs, vbabka
On Mon, Sep 07, 2026 at 09:15:02PM -0700, syzbot wrote:
> Hello,
>
> syzbot has tested the proposed patch and the reproducer did not trigger any issue:
>
> Reported-by: syzbot+c6879dc677a017f0a21b@syzkaller.appspotmail.com
> Tested-by: syzbot+c6879dc677a017f0a21b@syzkaller.appspotmail.com
Yup there we are :)
Why is this constantly duplicating I wonder...
>
> Tested on:
>
> commit: 35b0fb39 mm/mremap: reset unfaulted VMA page offset fo..
> git tree: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
> console output: https://syzkaller.appspot.com/x/log.txt?x=15e13af9580000
> kernel config: https://syzkaller.appspot.com/x/.config?x=56ed23170c168d4c
> dashboard link: https://syzkaller.appspot.com/bug?extid=c6879dc677a017f0a21b
> compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
> userspace arch: arm64
>
> Note: no patches were applied.
> Note: testing is done by a robot and is best-effort only.
--
Cheers, Lorenzo
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [syzbot] [mm?] WARNING in vma_add_pgoff
2026-09-08 9:25 ` Lorenzo Stoakes (ARM)
@ 2026-09-08 9:32 ` Vlastimil Babka (SUSE)
2026-09-08 10:24 ` Lorenzo Stoakes (ARM)
0 siblings, 1 reply; 6+ messages in thread
From: Vlastimil Babka (SUSE) @ 2026-09-08 9:32 UTC (permalink / raw)
To: Lorenzo Stoakes (ARM), syzbot
Cc: akpm, jannh, liam, linux-kernel, linux-mm, pfalcato, syzkaller-bugs
On 9/8/26 11:25, Lorenzo Stoakes (ARM) wrote:
> On Mon, Sep 07, 2026 at 09:15:02PM -0700, syzbot wrote:
>> Hello,
>>
>> syzbot has tested the proposed patch and the reproducer did not trigger any issue:
>>
>> Reported-by: syzbot+c6879dc677a017f0a21b@syzkaller.appspotmail.com
>> Tested-by: syzbot+c6879dc677a017f0a21b@syzkaller.appspotmail.com
>
> Yup there we are :)
>
> Why is this constantly duplicating I wonder...
Going back to the first mail:
syzbot found the following issue on:
HEAD commit: 5445d6419962 arm64: Don't read GMID_EL1 when MTE is disabled
git tree:
git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git for-kernelci
We can see it's based from 7.3-rc1:
https://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git/log/?h=for-kernelci
And since the problem was introduced there, all kinds of development trees
for 7.4 (or even pending hotfixes for 7.3) based on 7.3-rc1 will now have it.
I guess syzbot has to learn to recognize it's a known problem and ignore it,
or have some repo of known important fixes merged after rc1 it applies on
top of such development trees, as they generaly won't be rebased to later rcs.
>
>>
>> Tested on:
>>
>> commit: 35b0fb39 mm/mremap: reset unfaulted VMA page offset fo..
>> git tree: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
>> console output: https://syzkaller.appspot.com/x/log.txt?x=15e13af9580000
>> kernel config: https://syzkaller.appspot.com/x/.config?x=56ed23170c168d4c
>> dashboard link: https://syzkaller.appspot.com/bug?extid=c6879dc677a017f0a21b
>> compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
>> userspace arch: arm64
>>
>> Note: no patches were applied.
>> Note: testing is done by a robot and is best-effort only.
>
> --
> Cheers, Lorenzo
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [syzbot] [mm?] WARNING in vma_add_pgoff
2026-09-08 9:32 ` Vlastimil Babka (SUSE)
@ 2026-09-08 10:24 ` Lorenzo Stoakes (ARM)
0 siblings, 0 replies; 6+ messages in thread
From: Lorenzo Stoakes (ARM) @ 2026-09-08 10:24 UTC (permalink / raw)
To: Vlastimil Babka (SUSE)
Cc: syzbot, akpm, jannh, liam, linux-kernel, linux-mm, pfalcato,
syzkaller-bugs
On Tue, Sep 08, 2026 at 11:32:18AM +0200, Vlastimil Babka (SUSE) wrote:
> On 9/8/26 11:25, Lorenzo Stoakes (ARM) wrote:
> > On Mon, Sep 07, 2026 at 09:15:02PM -0700, syzbot wrote:
> >> Hello,
> >>
> >> syzbot has tested the proposed patch and the reproducer did not trigger any issue:
> >>
> >> Reported-by: syzbot+c6879dc677a017f0a21b@syzkaller.appspotmail.com
> >> Tested-by: syzbot+c6879dc677a017f0a21b@syzkaller.appspotmail.com
> >
> > Yup there we are :)
> >
> > Why is this constantly duplicating I wonder...
>
> Going back to the first mail:
>
> syzbot found the following issue on:
>
> HEAD commit: 5445d6419962 arm64: Don't read GMID_EL1 when MTE is disabled
> git tree:
> git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git for-kernelci
>
> We can see it's based from 7.3-rc1:
>
> https://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git/log/?h=for-kernelci
>
> And since the problem was introduced there, all kinds of development trees
> for 7.4 (or even pending hotfixes for 7.3) based on 7.3-rc1 will now have it.
Yeah but I marked this #syz dupe? I guess that's cleared maybe for a new job?
>
> I guess syzbot has to learn to recognize it's a known problem and ignore it,
> or have some repo of known important fixes merged after rc1 it applies on
> top of such development trees, as they generaly won't be rebased to later rcs.
Yeah, be nice if 'hey check this upstream commit does it fix it?' *syzbot
confirms yes* could -> mark reports redundant.
But maybe harder to actually do than that?
>
> >
> >>
> >> Tested on:
> >>
> >> commit: 35b0fb39 mm/mremap: reset unfaulted VMA page offset fo..
> >> git tree: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
> >> console output: https://syzkaller.appspot.com/x/log.txt?x=15e13af9580000
> >> kernel config: https://syzkaller.appspot.com/x/.config?x=56ed23170c168d4c
> >> dashboard link: https://syzkaller.appspot.com/bug?extid=c6879dc677a017f0a21b
> >> compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
> >> userspace arch: arm64
> >>
> >> Note: no patches were applied.
> >> Note: testing is done by a robot and is best-effort only.
> >
> > --
> > Cheers, Lorenzo
>
--
Cheers, Lorenzo
^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2026-09-08 10:24 UTC | newest]
Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-08 1:21 [syzbot] [mm?] WARNING in vma_add_pgoff syzbot
2026-09-08 2:25 ` Andrew Morton
2026-09-08 4:15 ` syzbot
2026-09-08 9:25 ` Lorenzo Stoakes (ARM)
2026-09-08 9:32 ` Vlastimil Babka (SUSE)
2026-09-08 10:24 ` Lorenzo Stoakes (ARM)
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®