2024-05-13 10:19:38

by syzbot

[permalink] [raw]
Subject: [syzbot] BUG: Bad rss-counter state (5)

Hello,

syzbot found the following issue on:

HEAD commit: cf87f46fd34d Merge tag 'drm-fixes-2024-05-11' of https://g..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=17e54084980000
kernel config: https://syzkaller.appspot.com/x/.config?x=6d14c12b661fb43
dashboard link: https://syzkaller.appspot.com/bug?extid=f2bbbb592debc978d46d
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/1aa5ad92dfce/disk-cf87f46f.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/67c336f7c1c7/vmlinux-cf87f46f.xz
kernel image: https://storage.googleapis.com/syzbot-assets/bb5b717bd2b8/bzImage-cf87f46f.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: [email protected]

BUG: Bad rss-counter state mm:ffff888079dd9300 type:MM_SWAPENTS val:6
loop2: detected capacity change from 0 to 256
exFAT-fs (loop2): failed to load upcase table (idx : 0x00017f3e, chksum : 0x0b83170a, utbl_chksum : 0xe619d30d)


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at [email protected].

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup


2024-05-30 17:31:15

by syzbot

[permalink] [raw]
Subject: Re: [syzbot] BUG: Bad rss-counter state (5)

syzbot has found a reproducer for the following issue on:

HEAD commit: 4a4be1ad3a6e Revert "vfs: Delete the associated dentry whe..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=17b8eeb4980000
kernel config: https://syzkaller.appspot.com/x/.config?x=bd6024aedb15e15c
dashboard link: https://syzkaller.appspot.com/bug?extid=f2bbbb592debc978d46d
compiler: aarch64-linux-gnu-gcc (Debian 12.2.0-14) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=114401aa980000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=107eb5d2980000

Downloadable assets:
disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/384ffdcca292/non_bootable_disk-4a4be1ad.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/75957361122b/vmlinux-4a4be1ad.xz
kernel image: https://storage.googleapis.com/syzbot-assets/6c766b0ec377/Image-4a4be1ad.gz.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: [email protected]

BUG: Bad rss-counter state mm:00000000b0f34aa6 type:MM_SWAPENTS val:-78


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

2024-06-14 15:16:08

by syzbot

[permalink] [raw]
Subject: Re: [syzbot] BUG: Bad rss-counter state (5)

syzbot has bisected this issue to:

commit 1c05047ad01693ad92bdf8347fad3b5c2b25e8bb
Author: Baolin Wang <[email protected]>
Date: Tue Jun 4 10:17:45 2024 +0000

mm: memory: extend finish_fault() to support large folio

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=106e8e56980000
start commit: d35b2284e966 Add linux-next specific files for 20240607
git tree: linux-next
final oops: https://syzkaller.appspot.com/x/report.txt?x=126e8e56980000
console output: https://syzkaller.appspot.com/x/log.txt?x=146e8e56980000
kernel config: https://syzkaller.appspot.com/x/.config?x=d8bf5cd6bcca7343
dashboard link: https://syzkaller.appspot.com/bug?extid=f2bbbb592debc978d46d
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=17f57a36980000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=10a57696980000

Reported-by: [email protected]
Fixes: 1c05047ad016 ("mm: memory: extend finish_fault() to support large folio")

For information about bisection process see: https://goo.gl/tpsmEJ#bisection

2024-06-14 15:49:49

by Baolin Wang

[permalink] [raw]
Subject: Re: [syzbot] BUG: Bad rss-counter state (5)



On 2024/6/14 23:12, syzbot wrote:
> syzbot has bisected this issue to:
>
> commit 1c05047ad01693ad92bdf8347fad3b5c2b25e8bb
> Author: Baolin Wang <[email protected]>
> Date: Tue Jun 4 10:17:45 2024 +0000
>
> mm: memory: extend finish_fault() to support large folio
>
> bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=106e8e56980000
> start commit: d35b2284e966 Add linux-next specific files for 20240607
> git tree: linux-next
> final oops: https://syzkaller.appspot.com/x/report.txt?x=126e8e56980000
> console output: https://syzkaller.appspot.com/x/log.txt?x=146e8e56980000
> kernel config: https://syzkaller.appspot.com/x/.config?x=d8bf5cd6bcca7343
> dashboard link: https://syzkaller.appspot.com/bug?extid=f2bbbb592debc978d46d
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=17f57a36980000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=10a57696980000
>
> Reported-by: [email protected]
> Fixes: 1c05047ad016 ("mm: memory: extend finish_fault() to support large folio")
>
> For information about bisection process see: https://goo.gl/tpsmEJ#bisection

Thanks. Please try the fix in mm-unstable branch

#syz test:
https://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm.git/commit/?h=mm-unstable&id=4135d2688b42f097f78062ef328f3056db32e3a0

2024-06-14 15:51:13

by Baolin Wang

[permalink] [raw]
Subject: Re: [syzbot] BUG: Bad rss-counter state (5)



On 2024/6/14 23:49, syzbot wrote:
>>
>>
>> On 2024/6/14 23:12, syzbot wrote:
>>> syzbot has bisected this issue to:
>>>
>>> commit 1c05047ad01693ad92bdf8347fad3b5c2b25e8bb
>>> Author: Baolin Wang <[email protected]>
>>> Date: Tue Jun 4 10:17:45 2024 +0000
>>>
>>> mm: memory: extend finish_fault() to support large folio
>>>
>>> bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=106e8e56980000
>>> start commit: d35b2284e966 Add linux-next specific files for 20240607
>>> git tree: linux-next
>>> final oops: https://syzkaller.appspot.com/x/report.txt?x=126e8e56980000
>>> console output: https://syzkaller.appspot.com/x/log.txt?x=146e8e56980000
>>> kernel config: https://syzkaller.appspot.com/x/.config?x=d8bf5cd6bcca7343
>>> dashboard link: https://syzkaller.appspot.com/bug?extid=f2bbbb592debc978d46d
>>> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=17f57a36980000
>>> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=10a57696980000
>>>
>>> Reported-by: [email protected]
>>> Fixes: 1c05047ad016 ("mm: memory: extend finish_fault() to support large folio")
>>>
>>> For information about bisection process see: https://goo.gl/tpsmEJ#bisection
>>
>> Thanks. Please try the fix in mm-unstable branch
>>
>> #syz test:
>
> want either no args or 2 args (repo, branch), got 1
>
>> https://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm.git/commit/?h=mm-unstable&id=4135d2688b42f097f78062ef328f3056db32e3a0

#syz test: git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm.git
mm-unstable

2024-06-14 16:18:12

by syzbot

[permalink] [raw]
Subject: Re: [syzbot] BUG: Bad rss-counter state (5)

Hello,

syzbot has tested the proposed patch and the reproducer did not trigger any issue:

Reported-and-tested-by: [email protected]

Tested on:

commit: 8d0a686e mm: add swappiness= arg to memory.reclaim
git tree: git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm.git mm-unstable
console output: https://syzkaller.appspot.com/x/log.txt?x=14d4e154980000
kernel config: https://syzkaller.appspot.com/x/.config?x=fba40c4590d687b
dashboard link: https://syzkaller.appspot.com/bug?extid=f2bbbb592debc978d46d
compiler: aarch64-linux-gnu-gcc (Debian 12.2.0-14) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40
userspace arch: arm64

Note: no patches were applied.
Note: testing is done by a robot and is best-effort only.

2024-06-14 16:19:23

by syzbot

[permalink] [raw]
Subject: Re: [syzbot] BUG: Bad rss-counter state (5)

>
>
> On 2024/6/14 23:12, syzbot wrote:
>> syzbot has bisected this issue to:
>>
>> commit 1c05047ad01693ad92bdf8347fad3b5c2b25e8bb
>> Author: Baolin Wang <[email protected]>
>> Date: Tue Jun 4 10:17:45 2024 +0000
>>
>> mm: memory: extend finish_fault() to support large folio
>>
>> bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=106e8e56980000
>> start commit: d35b2284e966 Add linux-next specific files for 20240607
>> git tree: linux-next
>> final oops: https://syzkaller.appspot.com/x/report.txt?x=126e8e56980000
>> console output: https://syzkaller.appspot.com/x/log.txt?x=146e8e56980000
>> kernel config: https://syzkaller.appspot.com/x/.config?x=d8bf5cd6bcca7343
>> dashboard link: https://syzkaller.appspot.com/bug?extid=f2bbbb592debc978d46d
>> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=17f57a36980000
>> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=10a57696980000
>>
>> Reported-by: [email protected]
>> Fixes: 1c05047ad016 ("mm: memory: extend finish_fault() to support large folio")
>>
>> For information about bisection process see: https://goo.gl/tpsmEJ#bisection
>
> Thanks. Please try the fix in mm-unstable branch
>
> #syz test:

want either no args or 2 args (repo, branch), got 1

> https://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm.git/commit/?h=mm-unstable&id=4135d2688b42f097f78062ef328f3056db32e3a0