Received: by 2002:a05:6358:45e:b0:b5:b6eb:e1f9 with SMTP id 30csp108432rwe; Wed, 31 Aug 2022 17:29:55 -0700 (PDT) X-Google-Smtp-Source: AA6agR4OiHjCOQ3hKmmfNL0cBD7/DBFqCkTbTlLmU/BMyNViZ8zNrjQqaY9xXlAFFldeK4lJldto X-Received: by 2002:a17:907:5ce:b0:730:bae0:deb with SMTP id wg14-20020a17090705ce00b00730bae00debmr22191445ejb.181.1661992195511; Wed, 31 Aug 2022 17:29:55 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1661992195; cv=none; d=google.com; s=arc-20160816; b=av5BX5/8haEF6baXrB2Hq9/GaetuwcH/Wx3LE1IqCJ+4cPRgvUB5B7IOIZFhRSHc3x cO/T4q2dq1VEPWz3yeYPN+qVck3Nc3uUVgoEizFNHGWdeRk7xACtsOJtry3K4lW4Fo2N 2+ZA+IWgDBWqwFPu667kTcbdgt8Ftgh7VOwfYCL5qoyc6MHpbkt2q79uD6x6bGduwxtX 7K5UQdFD6X4ogcsOrf8rD/NVbqqagZOg2pfxORx9dkg33JMHJqovWYXMx2hmr3MwaQWy r+qVyFoSXdvVwh+San4rBCy6xJQ2lPHFq2UCAVFgRHzNRtFkroTu+1NhKnvo4COtSyky 6JLQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:to:from:subject:message-id:date:mime-version; bh=DFKirfGyg1GeaTnh3qJeoJ4p0uyttCeWuhCQWljHZAQ=; b=dxiGh7ilXfhKTPr7TsZvyYmY2yNTv+h8f5bS1eRdSA9Oau+ZiF8/1V+UI5uuH/CSR6 muH73JEw1ex87bCVZjwfeppRjiqNcQMMotO1sqARmUBg7CvhbifrC+mDxs9Ps0SX/LrQ 1mtSOwsm7KMM0Oafi7NpznAhz113rQ9F7xjTMjZZnLNUOi1gYf7PGB5Ei/smWnp3Tpfo HmqwERLBDubA4l8NjkftV95bC4CpXOy3wjWcBXtNEDT/V7CucXUtZ5rkYcXUmtA/1VXy hDwwhJRLAPLkXQxLnUtC94KXYrL07QbTnNq0dYOF9kHRJU7UXpDtSWCKQW8Qzcc+Or6d FJTw== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=appspotmail.com Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id c12-20020a056402120c00b0043e85391923si540001edw.55.2022.08.31.17.29.29; Wed, 31 Aug 2022 17:29:55 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=appspotmail.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S229602AbiIAANk (ORCPT + 99 others); Wed, 31 Aug 2022 20:13:40 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:55176 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229607AbiIAANi (ORCPT ); Wed, 31 Aug 2022 20:13:38 -0400 Received: from mail-io1-f72.google.com (mail-io1-f72.google.com [209.85.166.72]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id E5D70E3418 for ; Wed, 31 Aug 2022 17:13:36 -0700 (PDT) Received: by mail-io1-f72.google.com with SMTP id y1-20020a056602200100b006893cd97da9so9654108iod.1 for ; Wed, 31 Aug 2022 17:13:36 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=to:from:subject:message-id:date:mime-version:x-gm-message-state :from:to:cc:subject:date; bh=DFKirfGyg1GeaTnh3qJeoJ4p0uyttCeWuhCQWljHZAQ=; b=HJCaZmbiP7kaZmW1bBmG+V0bJOrlkbjX47WloHDwo3Lhbr8QJ0WMjaBdyz++B5ynco iGgAXwTf721YSCPn1l7UGF7U+p+oeA28XZwzEKgMbN4chXOnE7myGAJtkQ+7kzPvN1Md Tv2UDGxk51iJDVWX84guVzEDZOoh6PbNvNnKyoGoDgUYZ2eE0Tlgh8kKhIB8L1L+DOek Ze6C5OX3ey32tcKCDSZ8K0E4xRGqOfaGHAWEBAyInv+SyaS2v9FmGCoOVMc7De5G0wPe HQbn404P4nyydmbiQgNsMHfnlS/eqvliAT6k23yP3JkIWyJXz/GIZL1ppQHD+Fc5G9f1 L9Ug== X-Gm-Message-State: ACgBeo2CplELX1S7rMT5JmkkOOkcxoAkfJcvPUD/kDhTwIAHUJRb9znu TOl6IJ/KRTMaC/fXKKqzdbEALbLebSeI+luXBdIjE/4BQ7ek MIME-Version: 1.0 X-Received: by 2002:a02:84ab:0:b0:34c:d88d:f5b5 with SMTP id f40-20020a0284ab000000b0034cd88df5b5mr293048jai.200.1661991216313; Wed, 31 Aug 2022 17:13:36 -0700 (PDT) Date: Wed, 31 Aug 2022 17:13:36 -0700 X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <000000000000117c7505e7927cb4@google.com> Subject: [syzbot] UBSAN: array-index-out-of-bounds in truncate_inode_pages_range From: syzbot To: akpm@linux-foundation.org, linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, linux-mm@kvack.org, syzkaller-bugs@googlegroups.com, willy@infradead.org Content-Type: text/plain; charset="UTF-8" X-Spam-Status: No, score=-1.7 required=5.0 tests=BAYES_00,FROM_LOCAL_HEX, HEADER_FROM_DIFFERENT_DOMAINS,RCVD_IN_DNSWL_NONE,RCVD_IN_MSPIKE_H2, SPF_HELO_NONE,SPF_PASS,T_SCC_BODY_TEXT_LINE autolearn=no autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Hello, syzbot found the following issue on: HEAD commit: 89b749d8552d Merge tag 'fbdev-for-6.0-rc3' of git://git.ke.. git tree: upstream console output: https://syzkaller.appspot.com/x/log.txt?x=14b9661b080000 kernel config: https://syzkaller.appspot.com/x/.config?x=911efaff115942bb dashboard link: https://syzkaller.appspot.com/bug?extid=5867885efe39089b339b compiler: gcc (Debian 10.2.1-6) 10.2.1 20210110, GNU ld (GNU Binutils for Debian) 2.35.2 userspace arch: i386 Unfortunately, I don't have any reproducer for this issue yet. IMPORTANT: if you fix the issue, please add the following tag to the commit: Reported-by: syzbot+5867885efe39089b339b@syzkaller.appspotmail.com ntfs3: loop0: Different NTFS' sector size (1024) and media sector size (512) ntfs3: loop0: RAW NTFS volume: Filesystem size 0.00 Gb > volume size 0.00 Gb. Mount in read-only ================================================================================ UBSAN: array-index-out-of-bounds in mm/truncate.c:366:18 index 254 is out of range for type 'long unsigned int [15]' CPU: 2 PID: 19915 Comm: syz-executor.0 Not tainted 6.0.0-rc2-syzkaller-00260-g89b749d8552d #0 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.14.0-2 04/01/2014 Call Trace: __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0xcd/0x134 lib/dump_stack.c:106 ubsan_epilogue+0xb/0x50 lib/ubsan.c:151 __ubsan_handle_out_of_bounds.cold+0x62/0x6c lib/ubsan.c:283 truncate_inode_pages_range+0x12f4/0x1510 mm/truncate.c:366 ntfs_evict_inode+0x16/0xa0 fs/ntfs3/inode.c:1741 evict+0x2ed/0x6b0 fs/inode.c:665 iput_final fs/inode.c:1748 [inline] iput.part.0+0x55d/0x810 fs/inode.c:1774 iput+0x58/0x70 fs/inode.c:1764 ntfs_fill_super+0x2e89/0x37f0 fs/ntfs3/super.c:1190 get_tree_bdev+0x440/0x760 fs/super.c:1323 vfs_get_tree+0x89/0x2f0 fs/super.c:1530 do_new_mount fs/namespace.c:3040 [inline] path_mount+0x1326/0x1e20 fs/namespace.c:3370 do_mount fs/namespace.c:3383 [inline] __do_sys_mount fs/namespace.c:3591 [inline] __se_sys_mount fs/namespace.c:3568 [inline] __ia32_sys_mount+0x27e/0x300 fs/namespace.c:3568 do_syscall_32_irqs_on arch/x86/entry/common.c:112 [inline] __do_fast_syscall_32+0x65/0xf0 arch/x86/entry/common.c:178 do_fast_syscall_32+0x2f/0x70 arch/x86/entry/common.c:203 entry_SYSENTER_compat_after_hwframe+0x70/0x82 RIP: 0023:0xf7ff6549 Code: 03 74 c0 01 10 05 03 74 b8 01 10 06 03 74 b4 01 10 07 03 74 b0 01 10 08 03 74 d8 01 00 00 00 00 00 51 52 55 89 e5 0f 34 cd 80 <5d> 5a 59 c3 90 90 90 90 8d b4 26 00 00 00 00 8d b4 26 00 00 00 00 RSP: 002b:00000000f7ff1410 EFLAGS: 00000296 ORIG_RAX: 0000000000000015 RAX: ffffffffffffffda RBX: 00000000f7ff1480 RCX: 0000000020000100 RDX: 0000000020000000 RSI: 0000000000000000 RDI: 00000000f7ff14c0 RBP: 00000000f7ff14c0 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000292 R12: 0000000000000000 R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000 ================================================================================ ---------------- Code disassembly (best guess): 0: 03 74 c0 01 add 0x1(%rax,%rax,8),%esi 4: 10 05 03 74 b8 01 adc %al,0x1b87403(%rip) # 0x1b8740d a: 10 06 adc %al,(%rsi) c: 03 74 b4 01 add 0x1(%rsp,%rsi,4),%esi 10: 10 07 adc %al,(%rdi) 12: 03 74 b0 01 add 0x1(%rax,%rsi,4),%esi 16: 10 08 adc %cl,(%rax) 18: 03 74 d8 01 add 0x1(%rax,%rbx,8),%esi 1c: 00 00 add %al,(%rax) 1e: 00 00 add %al,(%rax) 20: 00 51 52 add %dl,0x52(%rcx) 23: 55 push %rbp 24: 89 e5 mov %esp,%ebp 26: 0f 34 sysenter 28: cd 80 int $0x80 * 2a: 5d pop %rbp <-- trapping instruction 2b: 5a pop %rdx 2c: 59 pop %rcx 2d: c3 retq 2e: 90 nop 2f: 90 nop 30: 90 nop 31: 90 nop 32: 8d b4 26 00 00 00 00 lea 0x0(%rsi,%riz,1),%esi 39: 8d b4 26 00 00 00 00 lea 0x0(%rsi,%riz,1),%esi --- This report is generated by a bot. It may contain errors. See https://goo.gl/tpsmEJ for more information about syzbot. syzbot engineers can be reached at syzkaller@googlegroups.com. syzbot will keep track of this issue. See: https://goo.gl/tpsmEJ#status for how to communicate with syzbot.