2023-01-25 23:59:36

by Sanan Hasanov

[permalink] [raw]
Subject: WARNING in __split_vma

Good day, dear maintainers,

We found a bug using a modified kernel configuration file used by syzbot.

We enhanced the coverage of the configuration file using our tool, klocalizer.

Kernel Branch:?6.2.0-rc5-next-20230124
Kernel config:?https://drive.google.com/file/d/1MZSgIF4R9QfikEuF5siUIZVPce-GiJQK/view?usp=sharing
Reproducer:?https://drive.google.com/file/d/1L03M-21V_CDlUX3Q281GkLyC5Oxeh3Pg/view?usp=sharing

Thank you!

Best regards,
Sanan Hasanov

------------[ cut here ]------------
WARNING: CPU: 3 PID: 29148 at mm/mmap.c:2167 __split_vma+0x5fc/0x780 mm/mmap.c:2167
Modules linked in:
CPU: 3 PID: 29148 Comm: syz-executor.6 Not tainted 6.2.0-rc5-next-20230124 #1
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014
RIP: 0010:__split_vma+0x5fc/0x780 mm/mmap.c:2167
Code: aa 22 c3 ff 4c 89 f7 e8 a2 11 8c ff e9 26 ff ff ff 41 bc f4 ff ff ff eb e6 e8 90 22 c3 ff 0f 0b e9 ac fa ff ff e8 84 22 c3 ff <0f> 0b e9 e1 fa ff ff e8 78 22 c3 ff 48 8b 54 24 08 48 b8 00 00 00
RSP: 0018:ffffc9000b1d78f0 EFLAGS: 00010246

RAX: 0000000000040000 RBX: ffff88810f524bd0 RCX: ffffc90003d89000
RDX: 0000000000040000 RSI: ffffffff81bbc3fc RDI: 0000000000000006
RBP: 0000000020ffd000 R08: 0000000000000006 R09: 0000000020ffd000
R10: 0000000020ffd000 R11: 0000000000000001 R12: 0000000020ffd000
R13: 1ffff9200163af22 R14: 0000000020ffd000 R15: ffffc9000b1d7cc0
FS: 00007f70ff656700(0000) GS:ffff888119d80000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f6622840260 CR3: 000000007d1bc000 CR4: 0000000000350ee0
Call Trace:
<TASK>
do_vmi_align_munmap+0x223/0xbb0 mm/mmap.c:2305
do_vmi_munmap+0x26c/0x2c0 mm/mmap.c:2451
move_vma+0x7c2/0xf30 mm/mremap.c:704
__do_sys_mremap+0x48c/0x17f0 mm/mremap.c:1095
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x39/0x80 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x63/0xcd
RIP: 0033:0x7f70fe48edcd
Code: 02 b8 ff ff ff ff c3 66 0f 1f 44 00 00 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f70ff655bf8 EFLAGS: 00000246
ORIG_RAX: 0000000000000019
RAX: ffffffffffffffda RBX: 00007f70fe5bbf80 RCX: 00007f70fe48edcd
RDX: 0000000000001000 RSI: 0000000000001000 RDI: 0000000020003000
RBP: 00007f70ff655c50 R08: 0000000020ffd000 R09: 0000000000000000
R10: 0000000000000007 R11: 0000000000000246 R12: 000000000000000e
R13: 00007ffe16c8ac1f R14: 00007ffe16c8adc0 R15: 00007f70ff655d80
</TASK>
irq event stamp: 1113
hardirqs last enabled at (1121): [<ffffffff8163e2e2>] console_emit_next_record kernel/printk/printk.c:2893 [inline]
hardirqs last enabled at (1121): [<ffffffff8163e2e2>] console_flush_all+0x902/0xd10 kernel/printk/printk.c:2942
hardirqs last disabled at (1132): [<ffffffff8997e59c>] __schedule+0x2f1c/0x5a70 kernel/sched/core.c:6518
softirqs last enabled at (922): [<ffffffff814a50bd>] invoke_softirq kernel/softirq.c:445 [inline]
softirqs last enabled at (922): [<ffffffff814a50bd>] __irq_exit_rcu+0x11d/0x190 kernel/softirq.c:650
softirqs last disabled at (771): [<ffffffff814a50bd>] invoke_softirq kernel/softirq.c:445 [inline]
softirqs last disabled at (771): [<ffffffff814a50bd>] __irq_exit_rcu+0x11d/0x190 kernel/softirq.c:650
---[ end trace 0000000000000000 ]---