mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: syzbot ci <syzbot+ci374b2971a7526572@syzkaller.appspotmail.com>
To: danielmentz@google.com, iommu@lists.linux.dev, jgg@ziepe.ca,
	 joro@8bytes.org, kevin.tian@intel.com,
	linux-kernel@vger.kernel.org,  linux-mm@kvack.org,
	loganodell@google.com, praan@google.com,  robin.murphy@arm.com,
	skhawaja@google.com, smostafa@google.com,  will@kernel.org
Cc: syzbot@lists.linux.dev, syzkaller-bugs@googlegroups.com
Subject: [syzbot ci] Re: iommupt: Introduce IO page table shrinker
Date: Sat, 03 Oct 2026 01:10:31 -0700	[thread overview]
Message-ID: <6ac0b877.81dddff3.363068.0005.GAE@google.com> (raw)
In-Reply-To: <20261001230219.818128-1-praan@google.com>

syzbot ci has tested the following series

[v1] iommupt: Introduce IO page table shrinker
https://lore.kernel.org/all/20261001230219.818128-1-praan@google.com
* [RFC PATCH 1/5] iommu: Add reclaim_list xarray to struct iommu_domain
* [RFC PATCH 2/5] iommupt: Implement refcounting logic for Leaf entries
* [RFC PATCH 3/5] iommupt: Add lockless sever_branch helper
* [RFC PATCH 4/5] iommupt: Introduce lockless page table shrinker
* [RFC PATCH 5/5] iommupt: Return real page count to the shrinker core

and found the following issues:
* BUG: spinlock bad magic in xa_destroy
* INFO: trying to register non-static key in xa_destroy
* INFO: trying to register non-static key in xa_store

Full report is available here:
https://ci.syzbot.org/series/792388cb-7e39-4d83-8008-54d31031a227

***

BUG: spinlock bad magic in xa_destroy

tree:      axboe
URL:       https://kernel.googlesource.com/pub/scm/linux/kernel/git/axboe/linux.git
base:      72d3fcf802c45d00b300f25b848a93c3a2bd7c7e
arch:      amd64
compiler:  Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
config:    https://ci.syzbot.org/builds/40ee62cc-4991-4840-96ac-e3f70bd4b70b/config
syz repro: https://ci.syzbot.org/findings/96c389a5-7ad8-436e-87ca-df20279f6360/syz_repro

iommufd_mock iommufd_mock0: Adding to iommu group 0
BUG: spinlock bad magic on CPU#1, syz.2.19/5813
 lock: mock_blocking_domain+0x70/0xe0 selftest.c:-1, .magic: 00000000, .owner: <none>/-1, .owner_cpu: 0
CPU: 1 UID: 0 PID: 5813 Comm: syz.2.19 Not tainted syzkaller #0 PREEMPT(full) 
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014
Call Trace:
 <TASK>
 dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120
 spin_bug kernel/locking/spinlock_debug.c:78 [inline]
 debug_spin_lock_before kernel/locking/spinlock_debug.c:86 [inline]
 do_raw_spin_lock+0x1e5/0x2f0 kernel/locking/spinlock_debug.c:115
 __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:156 [inline]
 _raw_spin_lock_irqsave+0x4c/0x60 kernel/locking/spinlock.c:181
 xa_destroy+0x59/0x2e0 lib/xarray.c:2393
 iommu_domain_free+0x25/0x170 drivers/iommu/iommu.c:2130
 iommu_deinit_device+0x353/0x5d0 drivers/iommu/iommu.c:600
 __iommu_group_remove_device+0x1dd/0x270 drivers/iommu/iommu.c:764
 iommu_release_device drivers/iommu/iommu.c:783 [inline]
 iommu_bus_notifier+0x6d/0x2c0 drivers/iommu/iommu.c:1826
 notifier_call_chain+0x1a5/0x3d0 kernel/notifier.c:85
 blocking_notifier_call_chain+0x6a/0x90 kernel/notifier.c:380
 bus_notify+0x143/0x180 drivers/base/bus.c:1086
 device_del+0x740/0x8f0 drivers/base/core.c:3982
 device_unregister+0x21/0xf0 drivers/base/core.c:4006
 mock_dev_destroy drivers/iommu/iommufd/selftest.c:1042 [inline]
 iommufd_test_mock_domain drivers/iommu/iommufd/selftest.c:1108 [inline]
 iommufd_test+0x3e03/0x6360 drivers/iommu/iommufd/selftest.c:2109
 iommufd_fops_ioctl+0x465/0x600 drivers/iommu/iommufd/main.c:556
 vfs_ioctl fs/ioctl.c:51 [inline]
 __do_sys_ioctl fs/ioctl.c:597 [inline]
 __se_sys_ioctl+0xfc/0x170 fs/ioctl.c:583
 do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline]
 do_syscall_64+0x166/0x520 arch/x86/entry/syscall_64.c:84
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f9ceff9e159
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f9cf0ea9028 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 00007f9cf0225fa0 RCX: 00007f9ceff9e159
RDX: 0000200000000100 RSI: 0000000000003ba0 RDI: 0000000000000003
RBP: 00007f9cf003506b R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f9cf0226038 R14: 00007f9cf0225fa0 R15: 00007ffe0de56058
 </TASK>


***

INFO: trying to register non-static key in xa_destroy

tree:      axboe
URL:       https://kernel.googlesource.com/pub/scm/linux/kernel/git/axboe/linux.git
base:      72d3fcf802c45d00b300f25b848a93c3a2bd7c7e
arch:      amd64
compiler:  Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
config:    https://ci.syzbot.org/builds/40ee62cc-4991-4840-96ac-e3f70bd4b70b/config

iommufd_mock iommufd_mock0: Adding to iommu group 0
INFO: trying to register non-static key.
The code is fine but needs lockdep annotation, or maybe
you didn't initialize this object before use?
turning off the locking correctness validator.
CPU: 1 UID: 0 PID: 5775 Comm: syz.2.31 Not tainted syzkaller #0 PREEMPT(full) 
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014
Call Trace:
 <TASK>
 dump_stack_lvl+0xe8/0x150
 assign_lock_key+0x133/0x150
 register_lock_class+0xcc/0x2e0
 __lock_acquire+0x10c/0x2de0
 lock_acquire+0x115/0x350
 _raw_spin_lock_irqsave+0x40/0x60
 xa_destroy+0x59/0x2e0
 iommu_domain_free+0x25/0x170
 iommufd_hwpt_nested_destroy+0x4d/0x1a0
 iommufd_object_remove+0x35a/0x4c0
 iommufd_fops_ioctl+0x465/0x600
 __se_sys_ioctl+0xfc/0x170
 do_syscall_64+0x166/0x520
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f593cf9e159
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f593df41028 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 00007f593d225fa0 RCX: 00007f593cf9e159
RDX: 0000200000000300 RSI: 0000000000003b80 RDI: 0000000000000003
RBP: 00007f593d03506b R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f593d226038 R14: 00007f593d225fa0 R15: 00007ffe5c49ab68
 </TASK>


***

INFO: trying to register non-static key in xa_store

tree:      axboe
URL:       https://kernel.googlesource.com/pub/scm/linux/kernel/git/axboe/linux.git
base:      72d3fcf802c45d00b300f25b848a93c3a2bd7c7e
arch:      amd64
compiler:  Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
config:    https://ci.syzbot.org/builds/40ee62cc-4991-4840-96ac-e3f70bd4b70b/config

INFO: trying to register non-static key.
The code is fine but needs lockdep annotation, or maybe
you didn't initialize this object before use?
turning off the locking correctness validator.
CPU: 0 UID: 0 PID: 6433 Comm: syz.2.305 Not tainted syzkaller #0 PREEMPT(full) 
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014
Call Trace:
 <TASK>
 dump_stack_lvl+0xe8/0x150
 assign_lock_key+0x133/0x150
 register_lock_class+0xcc/0x2e0
 __lock_acquire+0x10c/0x2de0
 lock_acquire+0x115/0x350
 _raw_spin_lock+0x2e/0x40
 xa_store+0x23/0x50
 __unmap_range+0x748/0x1190
 __unmap_range+0xbed/0x1190
 __unmap_range+0xbed/0x1190
 amdv1_mock_unmap_range+0x418/0x5e0
 __iommu_unmap+0x138/0x740
 iommu_unmap+0x114/0x200
 iopt_area_unmap_domain_range+0x279/0x310
 __iopt_area_unfill_domain+0x8a2/0xf30
 iopt_table_remove_domain+0x7e8/0xa90
 iommufd_hwpt_paging_destroy+0x1c1/0x2f0
 iommufd_object_remove+0x35a/0x4c0
 iommufd_hw_pagetable_detach+0x564/0x6a0
 iommufd_device_detach+0x1c/0x80
 iommufd_selftest_destroy+0xae/0x130
 iommufd_fops_release+0x186/0x3b0
 __fput+0x418/0xa50
 task_work_run+0x1d9/0x270
 exit_to_user_mode_loop+0x204/0x770
 do_syscall_64+0x328/0x520
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fed0639e159
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fff16748678 EFLAGS: 00000246 ORIG_RAX: 00000000000001b4
RAX: 0000000000000000 RBX: 00007fff16748760 RCX: 00007fed0639e159
RDX: 0000000000000000 RSI: 000000000000001e RDI: 0000000000000003
RBP: 000000000001312c R08: 0000000000000001 R09: 0000000000000000
R10: 0000001b31420000 R11: 0000000000000246 R12: 00007fff167487a0
R13: 00007fed06625fac R14: 0000000000013174 R15: 00007fed06625fa0
 </TASK>


***

If these findings have caused you to resend the series or submit a
separate fix, please add the following tag to your commit message:
  Tested-by: syzbot@syzkaller.appspotmail.com

---
This report is generated by a bot. It may contain errors.
syzbot ci engineers can be reached at syzkaller@googlegroups.com.

To test a fix for this bug, please reply with `#syz test`
(on a separate line) and attach the patch to the email.

Notes:
- The patch will be applied on top of the tested series (as an
  incremental fix).
- To test a new version of the whole series, please send it directly
  to syzbot@lists.linux.dev.
- Arguments like custom git repos and branches are not supported.

      parent reply	other threads:[~2026-10-03  8:10 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-01 23:02 [RFC PATCH 0/5] " Pranjal Shrivastava
2026-10-01 23:02 ` [RFC PATCH 1/5] iommu: Add reclaim_list xarray to struct iommu_domain Pranjal Shrivastava
2026-10-01 23:02 ` [RFC PATCH 2/5] iommupt: Implement refcounting logic for Leaf entries Pranjal Shrivastava
2026-10-01 23:02 ` [RFC PATCH 3/5] iommupt: Add lockless sever_branch helper Pranjal Shrivastava
2026-10-01 23:02 ` [RFC PATCH 4/5] iommupt: Introduce lockless page table shrinker Pranjal Shrivastava
2026-10-01 23:02 ` [RFC PATCH 5/5] iommupt: Return real page count to the shrinker core Pranjal Shrivastava
2026-10-02 15:08 ` [RFC PATCH 0/5] iommupt: Introduce IO page table shrinker Jason Gunthorpe
2026-10-03  8:10 ` syzbot ci [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=6ac0b877.81dddff3.363068.0005.GAE@google.com \
    --to=syzbot+ci374b2971a7526572@syzkaller.appspotmail.com \
    --cc=danielmentz@google.com \
    --cc=iommu@lists.linux.dev \
    --cc=jgg@ziepe.ca \
    --cc=joro@8bytes.org \
    --cc=kevin.tian@intel.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    --cc=loganodell@google.com \
    --cc=praan@google.com \
    --cc=robin.murphy@arm.com \
    --cc=skhawaja@google.com \
    --cc=smostafa@google.com \
    --cc=syzbot@lists.linux.dev \
    --cc=syzkaller-bugs@googlegroups.com \
    --cc=will@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®