Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- program crashed: BUG: unable to handle kernel paging request in corrupted
- extracting C reproducer
- testing compiled C program (duration=22.5s, {Threaded:true Repeat:true RepeatTimes:0 Procs:3 Slowdown:1 Sandbox:none SandboxArg:0 Leak:false NetInjection:false NetDevices:true NetReset:true Cgroups:true BinfmtMisc:true CloseFDs:true KCSAN:false DevlinkPCI:false NicVF:false USB:false VhciInjection:false Wifi:false IEEE802154:false Sysctl:true Swap:true UseTmpDir:true HandleSegv:true Repro:true Trace:false LegacyOptions:{Collide:false Fault:false FaultCall:0 FaultNth:0}}): syz_mount_image$ext4-open-open-mount-open-sendfile-write$binfmt_script-ioctl$FS_IOC_RESVSP
- failed to symbolize report: failed to start scripts/get_maintainer.pl [scripts/get_maintainer.pl --git-min-percent=15 -f root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/ext4/extents.c]: fork/exec scripts/get_maintainer.pl: no such file or directory
- program crashed: BUG: unable to handle kernel paging request in ext4_ext_remove_space
- simplifying C reproducer
- testing compiled C program (duration=22.5s, {Threaded:false Repeat:true RepeatTimes:0 Procs:3 Slowdown:1 Sandbox:none SandboxArg:0 Leak:false NetInjection:false NetDevices:true NetReset:true Cgroups:true BinfmtMisc:true CloseFDs:true KCSAN:false DevlinkPCI:false NicVF:false USB:false VhciInjection:false Wifi:false IEEE802154:false Sysctl:true Swap:true UseTmpDir:true HandleSegv:true Repro:true Trace:false LegacyOptions:{Collide:false Fault:false FaultCall:0 FaultNth:0}}): syz_mount_image$ext4-open-open-mount-open-sendfile-write$binfmt_script-ioctl$FS_IOC_RESVSP
- program did not crash
- testing compiled C program (duration=22.5s, {Threaded:true Repeat:false RepeatTimes:0 Procs:1 Slowdown:1 Sandbox:none SandboxArg:0 Leak:false NetInjection:false NetDevices:true NetReset:false Cgroups:false BinfmtMisc:true CloseFDs:true KCSAN:false DevlinkPCI:false NicVF:false USB:false VhciInjection:false Wifi:false IEEE802154:false Sysctl:true Swap:true UseTmpDir:true HandleSegv:true Repro:true Trace:false LegacyOptions:{Collide:false Fault:false FaultCall:0 FaultNth:0}}): syz_mount_image$ext4-open-open-mount-open-sendfile-write$binfmt_script-ioctl$FS_IOC_RESVSP
- program did not crash
- testing compiled C program (duration=22.5s, {Threaded:true Repeat:true RepeatTimes:0 Procs:1 Slowdown:1 Sandbox:none SandboxArg:0 Leak:false NetInjection:false NetDevices:true NetReset:true Cgroups:true BinfmtMisc:true CloseFDs:true KCSAN:false DevlinkPCI:false NicVF:false USB:false VhciInjection:false Wifi:false IEEE802154:false Sysctl:true Swap:true UseTmpDir:true HandleSegv:true Repro:true Trace:false LegacyOptions:{Collide:false Fault:false FaultCall:0 FaultNth:0}}): syz_mount_image$ext4-open-open-mount-open-sendfile-write$binfmt_script-ioctl$FS_IOC_RESVSP
- failed to symbolize report: failed to start scripts/get_maintainer.pl [scripts/get_maintainer.pl --git-min-percent=15 -f root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/ext4/extents.c]: fork/exec scripts/get_maintainer.pl: no such file or directory
- program crashed: general protection fault in mnt_drop_write
- testing compiled C program (duration=22.5s, {Threaded:true Repeat:true RepeatTimes:0 Procs:1 Slowdown:1 Sandbox: SandboxArg:0 Leak:false NetInjection:false NetDevices:false NetReset:false Cgroups:false BinfmtMisc:false CloseFDs:false KCSAN:false DevlinkPCI:false NicVF:false USB:false VhciInjection:false Wifi:false IEEE802154:false Sysctl:true Swap:false UseTmpDir:true HandleSegv:true Repro:true Trace:false LegacyOptions:{Collide:false Fault:false FaultCall:0 FaultNth:0}}): syz_mount_image$ext4-open-open-mount-open-sendfile-write$binfmt_script-ioctl$FS_IOC_RESVSP
- failed to symbolize report: failed to start scripts/get_maintainer.pl [scripts/get_maintainer.pl --git-min-percent=15 -f root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/kernel/sched/core.c]: fork/exec scripts/get_maintainer.pl: no such file or directory
- program crashed: general protection fault in set_task_cpu
- testing compiled C program (duration=22.5s, {Threaded:true Repeat:true RepeatTimes:0 Procs:1 Slowdown:1 Sandbox: SandboxArg:0 Leak:false NetInjection:false NetDevices:false NetReset:false Cgroups:false BinfmtMisc:false CloseFDs:false KCSAN:false DevlinkPCI:false NicVF:false USB:false VhciInjection:false Wifi:false IEEE802154:false Sysctl:true Swap:false UseTmpDir:false HandleSegv:true Repro:true Trace:false LegacyOptions:{Collide:false Fault:false FaultCall:0 FaultNth:0}}): syz_mount_image$ext4-open-open-mount-open-sendfile-write$binfmt_script-ioctl$FS_IOC_RESVSP
- program did not crash
- testing compiled C program (duration=22.5s, {Threaded:true Repeat:true RepeatTimes:0 Procs:1 Slowdown:1 Sandbox: SandboxArg:0 Leak:false NetInjection:false NetDevices:false NetReset:false Cgroups:false BinfmtMisc:false CloseFDs:false KCSAN:false DevlinkPCI:false NicVF:false USB:false VhciInjection:false Wifi:false IEEE802154:false Sysctl:true Swap:false UseTmpDir:true HandleSegv:false Repro:true Trace:false LegacyOptions:{Collide:false Fault:false FaultCall:0 FaultNth:0}}): syz_mount_image$ext4-open-open-mount-open-sendfile-write$binfmt_script-ioctl$FS_IOC_RESVSP
- failed to symbolize report: failed to start scripts/get_maintainer.pl [scripts/get_maintainer.pl --git-min-percent=15 -f root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/lib/rbtree.c]: fork/exec scripts/get_maintainer.pl: no such file or directory
- program crashed: general protection fault in timerqueue_del
- testing compiled C program (duration=22.5s, {Threaded:true Repeat:true RepeatTimes:0 Procs:1 Slowdown:1 Sandbox: SandboxArg:0 Leak:false NetInjection:false NetDevices:false NetReset:false Cgroups:false BinfmtMisc:false CloseFDs:false KCSAN:false DevlinkPCI:false NicVF:false USB:false VhciInjection:false Wifi:false IEEE802154:false Sysctl:false Swap:false UseTmpDir:true HandleSegv:false Repro:true Trace:false LegacyOptions:{Collide:false Fault:false FaultCall:0 FaultNth:0}}): syz_mount_image$ext4-open-open-mount-open-sendfile-write$binfmt_script-ioctl$FS_IOC_RESVSP
- failed to symbolize report: failed to start scripts/get_maintainer.pl [scripts/get_maintainer.pl --git-min-percent=15 -f root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/ext4/extents.c]: fork/exec scripts/get_maintainer.pl: no such file or directory
- program crashed: BUG: unable to handle kernel paging request in ext4_ext_remove_space
- reproducing took 11m45.317637882s
- repro crashed as (corrupted=false):
- EXT4-fs (loop0): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback.
- ext4 filesystem being mounted at /syzkaller.TPYs2I/19/file1 supports timestamps until 2038-01-19 (0x7fffffff)
- BUG: unable to handle page fault for address: ffff888002cba000
- #PF: supervisor write access in kernel mode
- #PF: error_code(0x0003) - permissions violation
- PGD a4c01067 P4D a4c01067 PUD a4c02067 PMD 2c63063 PTE 8000000002cba121
- Oops: 0003 [#1] PREEMPT SMP KASAN NOPTI
- CPU: 2 PID: 366 Comm: syz-executor127 Not tainted 6.7.0 #2
- Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014
- RIP: 0010:memmove+0x1e/0x1b0 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/arch/x86/lib/memmove_64.S:44
- Code: 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 48 89 f8 48 39 fe 7d 0f 49 89 f0 49 01 d0 49 39 f8 0f 8f b5 00 00 00 48 89 d1 <f3> a4 e9 26 14 1b 00 66 2e 0f 1f 84 00 00 00 00 00 48 81 fa a8 02
- RSP: 0018:ffff88800d84f840 EFLAGS: 00010216
- RAX: ffff888002c9903c RBX: ffff888002c99000 RCX: fffffffffffdf000
- RDX: ffffffffffffffc4 RSI: ffff888002cba00c RDI: ffff888002cba000
- RBP: ffff888002c99002 R08: 0000000000000001 R09: fffff94000039076
- R10: 0000000000000000 R11: 0000000000000000 R12: dffffc0000000000
- R13: ffff88800ba37868 R14: ffff888002c99040 R15: 0000000000000004
- FS: 00007fefc4cb4640(0000) GS:ffff88809e900000(0000) knlGS:0000000000000000
- CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
- CR2: ffff888002cba000 CR3: 00000000092fc005 CR4: 0000000000770ef0
- PKRU: 55555554
- Call Trace:
- <TASK>
- ext4_ext_rm_leaf root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/ext4/extents.c:2736 [inline]
- ext4_ext_remove_space+0x1aae/0x36b0 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/ext4/extents.c:2958
- ext4_punch_hole+0xb8b/0xe50 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/ext4/inode.c:4019
- ext4_fallocate+0xb68/0x3230 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/ext4/extents.c:4707
- vfs_fallocate+0x361/0xae0 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/open.c:324
- ioctl_preallocate+0x172/0x1f0 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/ioctl.c:291
- file_ioctl root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/ioctl.c:334 [inline]
- do_vfs_ioctl+0x109e/0x13c0 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/ioctl.c:850
- __do_sys_ioctl root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/ioctl.c:869 [inline]
- __se_sys_ioctl root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/ioctl.c:857 [inline]
- __x64_sys_ioctl+0xef/0x1e0 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/ioctl.c:857
- do_syscall_x64 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/arch/x86/entry/common.c:52 [inline]
- do_syscall_64+0x46/0xf0 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/arch/x86/entry/common.c:83
- entry_SYSCALL_64_after_hwframe+0x6f/0x77
- RIP: 0033:0x7fefc4d3263d
- Code: c3 e8 27 23 00 00 0f 1f 80 00 00 00 00 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48
- RSP: 002b:00007fefc4cb4198 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
- RAX: ffffffffffffffda RBX: 00007fefc4dc95d0 RCX: 00007fefc4d3263d
- RDX: 0000000020000080 RSI: 0000000040305829 RDI: 0000000000000004
- RBP: 00007fefc4d93598 R08: 00007ffe5e3ab7bf R09: 0000000000000000
- R10: 0000000000000000 R11: 0000000000000246 R12: 0031656c69662f2e
- R13: 6f6f6c2f7665642f R14: 000001ff7fdfd000 R15: 00007fefc4dc95d8
- </TASK>
- Modules linked in:
- CR2: ffff888002cba000
- ---[ end trace 0000000000000000 ]---
- BUG: unable to handle page fault for address: ffffebde001bf808
- RIP: 0010:memmove+0x1e/0x1b0 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/arch/x86/lib/memmove_64.S:44
- #PF: supervisor read access in kernel mode
- Code: 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 48 89 f8 48 39 fe 7d 0f 49 89 f0 49 01 d0 49 39 f8 0f 8f b5 00 00 00 48 89 d1 <f3> a4 e9 26 14 1b 00 66 2e 0f 1f 84 00 00 00 00 00 48 81 fa a8 02
- #PF: error_code(0x0000) - not-present page
- RSP: 0018:ffff88800d84f840 EFLAGS: 00010216
- PGD 0 P4D 0
- RAX: ffff888002c9903c RBX: ffff888002c99000 RCX: fffffffffffdf000
- RDX: ffffffffffffffc4 RSI: ffff888002cba00c RDI: ffff888002cba000
- Oops: 0000 [#2] PREEMPT SMP KASAN NOPTI
- RBP: ffff888002c99002 R08: 0000000000000001 R09: fffff94000039076
- CPU: 1 PID: 1 Comm: systemd Tainted: G D 6.7.0 #2
- R10: 0000000000000000 R11: 0000000000000000 R12: dffffc0000000000
- Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014
- R13: ffff88800ba37868 R14: ffff888002c99040 R15: 0000000000000004
- RIP: 0010:_compound_head root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/./include/linux/page-flags.h:247 [inline]
- RIP: 0010:virt_to_folio root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/./include/linux/mm.h:1283 [inline]
- RIP: 0010:virt_to_slab root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/mm/kasan/../slab.h:213 [inline]
- RIP: 0010:qlink_to_cache root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/mm/kasan/quarantine.c:131 [inline]
- RIP: 0010:qlist_free_all+0xaf/0x190 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/mm/kasan/quarantine.c:184
- FS: 00007fefc4cb4640(0000) GS:ffff88809e900000(0000) knlGS:0000000000000000
- Code: 80 4c 01 c0 0f 82 f5 00 00 00 48 c7 c2 00 00 00 80 48 2b 15 33 fc 31 03 48 01 d0 48 c1 e8 0c 48 c1 e0 06 48 03 05 11 fc 31 03 <48> 8b 48 08 48 89 c2 f6 c1 01 0f 85 b7 00 00 00 0f 1f 44 00 00 48
- CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
- RSP: 0018:ffff88800123fc68 EFLAGS: 00010286
- CR2: ffff888002cba000 CR3: 00000000092fc005 CR4: 0000000000770ef0
- PKRU: 55555554
- RAX: ffffebde001bf800 RBX: 0000000006fe007a RCX: 000000000010000b
- note: syz-executor127[366] exited with irqs disabled
- RDX: 0000777f80000000 RSI: ffffea00000b2900 RDI: ffff888002ca4400
- RBP: 0000000000000000 R08: 0000000006fe007a R09: 000000000010000b
- R10: 0000000040000000 R11: 0000000000000000 R12: dffffc0000000000
- R13: ffff88800123fca8 R14: 0000000000000000 R15: ffff888002ca5e00
- FS: 00007f1338f2f900(0000) GS:ffff88809e880000(0000) knlGS:0000000000000000
- CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
- CR2: ffffebde001bf808 CR3: 00000000013f8004 CR4: 0000000000770ef0
- PKRU: 55555554
- Call Trace:
- <TASK>
- kasan_quarantine_reduce+0x15d/0x180 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/mm/kasan/quarantine.c:294
- __kasan_slab_alloc+0x49/0x70 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/mm/kasan/common.c:305
- kasan_slab_alloc root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/./include/linux/kasan.h:188 [inline]
- slab_post_alloc_hook root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/mm/slab.h:763 [inline]
- slab_alloc_node root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/mm/slub.c:3478 [inline]
- slab_alloc root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/mm/slub.c:3486 [inline]
- __kmem_cache_alloc_lru root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/mm/slub.c:3493 [inline]
- kmem_cache_alloc+0xdc/0x270 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/mm/slub.c:3502
- getname_flags.part.0+0x4f/0x4c0 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/namei.c:140
- getname_flags+0x95/0xe0 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/./include/linux/audit.h:321
- vfs_fstatat+0x5e/0xf0 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/stat.c:298
- vfs_stat root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/./include/linux/fs.h:3111 [inline]
- __do_sys_newstat+0x7f/0xf0 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/stat.c:436
- do_syscall_x64 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/arch/x86/entry/common.c:52 [inline]
- do_syscall_64+0x46/0xf0 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/arch/x86/entry/common.c:83
- entry_SYSCALL_64_after_hwframe+0x6f/0x77
- RIP: 0033:0x7f13396f88e6
- Code: 00 00 75 05 48 83 c4 18 c3 e8 46 0c 02 00 66 0f 1f 44 00 00 41 89 f8 48 89 f7 48 89 d6 41 83 f8 01 77 29 b8 04 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 02 c3 90 48 8b 15 79 35 0e 00 f7 d8 64 89 02
- RSP: 002b:00007ffcb620bbd8 EFLAGS: 00000246 ORIG_RAX: 0000000000000004
- RAX: ffffffffffffffda RBX: 000055f986c1f7e8 RCX: 00007f13396f88e6
- RDX: 00007ffcb620bc40 RSI: 00007ffcb620bc40 RDI: 000055f986c1e460
- RBP: 000055f986c1d370 R08: 0000000000000001 R09: 53297b0592226e1c
- R10: bf7708da564c09ec R11: 0000000000000246 R12: 00007ffcb620bc40
- R13: 000055f986c1e460 R14: 00007ffcb620bc00 R15: 00007ffcb620bd80
- </TASK>
- Modules linked in:
- CR2: ffffebde001bf808
- ---[ end trace 0000000000000000 ]---
- RIP: 0010:memmove+0x1e/0x1b0 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/arch/x86/lib/memmove_64.S:44
- Code: 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 48 89 f8 48 39 fe 7d 0f 49 89 f0 49 01 d0 49 39 f8 0f 8f b5 00 00 00 48 89 d1 <f3> a4 e9 26 14 1b 00 66 2e 0f 1f 84 00 00 00 00 00 48 81 fa a8 02
- RSP: 0018:ffff88800d84f840 EFLAGS: 00010216
- RAX: ffff888002c9903c RBX: ffff888002c99000 RCX: fffffffffffdf000
- RDX: ffffffffffffffc4 RSI: ffff888002cba00c RDI: ffff888002cba000
- RBP: ffff888002c99002 R08: 0000000000000001 R09: fffff94000039076
- R10: 0000000000000000 R11: 0000000000000000 R12: dffffc0000000000
- R13: ffff88800ba37868 R14: ffff888002c99040 R15: 0000000000000004
- FS: 00007f1338f2f900(0000) GS:ffff88809e880000(0000) knlGS:0000000000000000
- CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
- CR2: ffffebde001bf808 CR3: 00000000013f8004 CR4: 0000000000770ef0
- PKRU: 55555554
- note: systemd[1] exited with irqs disabled
- ----------------
- Code disassembly (best guess):
- 0: 90 nop
- 1: 90 nop
- 2: 90 nop
- 3: 90 nop
- 4: 90 nop
- 5: 90 nop
- 6: 90 nop
- 7: 90 nop
- 8: 90 nop
- 9: 90 nop
- a: 90 nop
- b: 90 nop
- c: f3 0f 1e fa endbr64
- 10: 48 89 f8 mov %rdi,%rax
- 13: 48 39 fe cmp %rdi,%rsi
- 16: 7d 0f jge 0x27
- 18: 49 89 f0 mov %rsi,%r8
- 1b: 49 01 d0 add %rdx,%r8
- 1e: 49 39 f8 cmp %rdi,%r8
- 21: 0f 8f b5 00 00 00 jg 0xdc
- 27: 48 89 d1 mov %rdx,%rcx
- * 2a: f3 a4 rep movsb %ds:(%rsi),%es:(%rdi) <-- trapping instruction
- 2c: e9 26 14 1b 00 jmp 0x1b1457
- 31: 66 2e 0f 1f 84 00 00 cs nopw 0x0(%rax,%rax,1)
- 38: 00 00 00
- 3b: 48 rex.W
- 3c: 81 .byte 0x81
- 3d: fa cli
- 3e: a8 02 test $0x2,%al
- final repro crashed as (corrupted=false):
- EXT4-fs (loop0): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: writeback.
- ext4 filesystem being mounted at /syzkaller.TPYs2I/19/file1 supports timestamps until 2038-01-19 (0x7fffffff)
- BUG: unable to handle page fault for address: ffff888002cba000
- #PF: supervisor write access in kernel mode
- #PF: error_code(0x0003) - permissions violation
- PGD a4c01067 P4D a4c01067 PUD a4c02067 PMD 2c63063 PTE 8000000002cba121
- Oops: 0003 [#1] PREEMPT SMP KASAN NOPTI
- CPU: 2 PID: 366 Comm: syz-executor127 Not tainted 6.7.0 #2
- Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014
- RIP: 0010:memmove+0x1e/0x1b0 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/arch/x86/lib/memmove_64.S:44
- Code: 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 48 89 f8 48 39 fe 7d 0f 49 89 f0 49 01 d0 49 39 f8 0f 8f b5 00 00 00 48 89 d1 <f3> a4 e9 26 14 1b 00 66 2e 0f 1f 84 00 00 00 00 00 48 81 fa a8 02
- RSP: 0018:ffff88800d84f840 EFLAGS: 00010216
- RAX: ffff888002c9903c RBX: ffff888002c99000 RCX: fffffffffffdf000
- RDX: ffffffffffffffc4 RSI: ffff888002cba00c RDI: ffff888002cba000
- RBP: ffff888002c99002 R08: 0000000000000001 R09: fffff94000039076
- R10: 0000000000000000 R11: 0000000000000000 R12: dffffc0000000000
- R13: ffff88800ba37868 R14: ffff888002c99040 R15: 0000000000000004
- FS: 00007fefc4cb4640(0000) GS:ffff88809e900000(0000) knlGS:0000000000000000
- CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
- CR2: ffff888002cba000 CR3: 00000000092fc005 CR4: 0000000000770ef0
- PKRU: 55555554
- Call Trace:
- <TASK>
- ext4_ext_rm_leaf root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/ext4/extents.c:2736 [inline]
- ext4_ext_remove_space+0x1aae/0x36b0 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/ext4/extents.c:2958
- ext4_punch_hole+0xb8b/0xe50 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/ext4/inode.c:4019
- ext4_fallocate+0xb68/0x3230 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/ext4/extents.c:4707
- vfs_fallocate+0x361/0xae0 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/open.c:324
- ioctl_preallocate+0x172/0x1f0 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/ioctl.c:291
- file_ioctl root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/ioctl.c:334 [inline]
- do_vfs_ioctl+0x109e/0x13c0 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/ioctl.c:850
- __do_sys_ioctl root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/ioctl.c:869 [inline]
- __se_sys_ioctl root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/ioctl.c:857 [inline]
- __x64_sys_ioctl+0xef/0x1e0 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/ioctl.c:857
- do_syscall_x64 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/arch/x86/entry/common.c:52 [inline]
- do_syscall_64+0x46/0xf0 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/arch/x86/entry/common.c:83
- entry_SYSCALL_64_after_hwframe+0x6f/0x77
- RIP: 0033:0x7fefc4d3263d
- Code: c3 e8 27 23 00 00 0f 1f 80 00 00 00 00 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48
- RSP: 002b:00007fefc4cb4198 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
- RAX: ffffffffffffffda RBX: 00007fefc4dc95d0 RCX: 00007fefc4d3263d
- RDX: 0000000020000080 RSI: 0000000040305829 RDI: 0000000000000004
- RBP: 00007fefc4d93598 R08: 00007ffe5e3ab7bf R09: 0000000000000000
- R10: 0000000000000000 R11: 0000000000000246 R12: 0031656c69662f2e
- R13: 6f6f6c2f7665642f R14: 000001ff7fdfd000 R15: 00007fefc4dc95d8
- </TASK>
- Modules linked in:
- CR2: ffff888002cba000
- ---[ end trace 0000000000000000 ]---
- BUG: unable to handle page fault for address: ffffebde001bf808
- RIP: 0010:memmove+0x1e/0x1b0 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/arch/x86/lib/memmove_64.S:44
- #PF: supervisor read access in kernel mode
- Code: 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 48 89 f8 48 39 fe 7d 0f 49 89 f0 49 01 d0 49 39 f8 0f 8f b5 00 00 00 48 89 d1 <f3> a4 e9 26 14 1b 00 66 2e 0f 1f 84 00 00 00 00 00 48 81 fa a8 02
- #PF: error_code(0x0000) - not-present page
- RSP: 0018:ffff88800d84f840 EFLAGS: 00010216
- PGD 0 P4D 0
- RAX: ffff888002c9903c RBX: ffff888002c99000 RCX: fffffffffffdf000
- RDX: ffffffffffffffc4 RSI: ffff888002cba00c RDI: ffff888002cba000
- Oops: 0000 [#2] PREEMPT SMP KASAN NOPTI
- RBP: ffff888002c99002 R08: 0000000000000001 R09: fffff94000039076
- CPU: 1 PID: 1 Comm: systemd Tainted: G D 6.7.0 #2
- R10: 0000000000000000 R11: 0000000000000000 R12: dffffc0000000000
- Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014
- R13: ffff88800ba37868 R14: ffff888002c99040 R15: 0000000000000004
- RIP: 0010:_compound_head root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/./include/linux/page-flags.h:247 [inline]
- RIP: 0010:virt_to_folio root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/./include/linux/mm.h:1283 [inline]
- RIP: 0010:virt_to_slab root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/mm/kasan/../slab.h:213 [inline]
- RIP: 0010:qlink_to_cache root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/mm/kasan/quarantine.c:131 [inline]
- RIP: 0010:qlist_free_all+0xaf/0x190 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/mm/kasan/quarantine.c:184
- FS: 00007fefc4cb4640(0000) GS:ffff88809e900000(0000) knlGS:0000000000000000
- Code: 80 4c 01 c0 0f 82 f5 00 00 00 48 c7 c2 00 00 00 80 48 2b 15 33 fc 31 03 48 01 d0 48 c1 e8 0c 48 c1 e0 06 48 03 05 11 fc 31 03 <48> 8b 48 08 48 89 c2 f6 c1 01 0f 85 b7 00 00 00 0f 1f 44 00 00 48
- CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
- RSP: 0018:ffff88800123fc68 EFLAGS: 00010286
- CR2: ffff888002cba000 CR3: 00000000092fc005 CR4: 0000000000770ef0
- PKRU: 55555554
- RAX: ffffebde001bf800 RBX: 0000000006fe007a RCX: 000000000010000b
- note: syz-executor127[366] exited with irqs disabled
- RDX: 0000777f80000000 RSI: ffffea00000b2900 RDI: ffff888002ca4400
- RBP: 0000000000000000 R08: 0000000006fe007a R09: 000000000010000b
- R10: 0000000040000000 R11: 0000000000000000 R12: dffffc0000000000
- R13: ffff88800123fca8 R14: 0000000000000000 R15: ffff888002ca5e00
- FS: 00007f1338f2f900(0000) GS:ffff88809e880000(0000) knlGS:0000000000000000
- CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
- CR2: ffffebde001bf808 CR3: 00000000013f8004 CR4: 0000000000770ef0
- PKRU: 55555554
- Call Trace:
- <TASK>
- kasan_quarantine_reduce+0x15d/0x180 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/mm/kasan/quarantine.c:294
- __kasan_slab_alloc+0x49/0x70 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/mm/kasan/common.c:305
- kasan_slab_alloc root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/./include/linux/kasan.h:188 [inline]
- slab_post_alloc_hook root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/mm/slab.h:763 [inline]
- slab_alloc_node root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/mm/slub.c:3478 [inline]
- slab_alloc root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/mm/slub.c:3486 [inline]
- __kmem_cache_alloc_lru root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/mm/slub.c:3493 [inline]
- kmem_cache_alloc+0xdc/0x270 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/mm/slub.c:3502
- getname_flags.part.0+0x4f/0x4c0 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/namei.c:140
- getname_flags+0x95/0xe0 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/./include/linux/audit.h:321
- vfs_fstatat+0x5e/0xf0 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/stat.c:298
- vfs_stat root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/./include/linux/fs.h:3111 [inline]
- __do_sys_newstat+0x7f/0xf0 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/fs/stat.c:436
- do_syscall_x64 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/arch/x86/entry/common.c:52 [inline]
- do_syscall_64+0x46/0xf0 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/arch/x86/entry/common.c:83
- entry_SYSCALL_64_after_hwframe+0x6f/0x77
- RIP: 0033:0x7f13396f88e6
- Code: 00 00 75 05 48 83 c4 18 c3 e8 46 0c 02 00 66 0f 1f 44 00 00 41 89 f8 48 89 f7 48 89 d6 41 83 f8 01 77 29 b8 04 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 02 c3 90 48 8b 15 79 35 0e 00 f7 d8 64 89 02
- RSP: 002b:00007ffcb620bbd8 EFLAGS: 00000246 ORIG_RAX: 0000000000000004
- RAX: ffffffffffffffda RBX: 000055f986c1f7e8 RCX: 00007f13396f88e6
- RDX: 00007ffcb620bc40 RSI: 00007ffcb620bc40 RDI: 000055f986c1e460
- RBP: 000055f986c1d370 R08: 0000000000000001 R09: 53297b0592226e1c
- R10: bf7708da564c09ec R11: 0000000000000246 R12: 00007ffcb620bc40
- R13: 000055f986c1e460 R14: 00007ffcb620bc00 R15: 00007ffcb620bd80
- </TASK>
- Modules linked in:
- CR2: ffffebde001bf808
- ---[ end trace 0000000000000000 ]---
- RIP: 0010:memmove+0x1e/0x1b0 root/zhangqiang/kernel_fuzzing/zq-LLM-OS/llm-syz-environment/linux-6.7/arch/x86/lib/memmove_64.S:44
- Code: 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 48 89 f8 48 39 fe 7d 0f 49 89 f0 49 01 d0 49 39 f8 0f 8f b5 00 00 00 48 89 d1 <f3> a4 e9 26 14 1b 00 66 2e 0f 1f 84 00 00 00 00 00 48 81 fa a8 02
- RSP: 0018:ffff88800d84f840 EFLAGS: 00010216
- RAX: ffff888002c9903c RBX: ffff888002c99000 RCX: fffffffffffdf000
- RDX: ffffffffffffffc4 RSI: ffff888002cba00c RDI: ffff888002cba000
- RBP: ffff888002c99002 R08: 0000000000000001 R09: fffff94000039076
- R10: 0000000000000000 R11: 0000000000000000 R12: dffffc0000000000
- R13: ffff88800ba37868 R14: ffff888002c99040 R15: 0000000000000004
- FS: 00007f1338f2f900(0000) GS:ffff88809e880000(0000) knlGS:0000000000000000
- CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
- CR2: ffffebde001bf808 CR3: 00000000013f8004 CR4: 0000000000770ef0
- PKRU: 55555554
- note: systemd[1] exited with irqs disabled
- ----------------
- Code disassembly (best guess):
- 0: 90 nop
- 1: 90 nop
- 2: 90 nop
- 3: 90 nop
- 4: 90 nop
- 5: 90 nop
- 6: 90 nop
- 7: 90 nop
- 8: 90 nop
- 9: 90 nop
- a: 90 nop
- b: 90 nop
- c: f3 0f 1e fa endbr64
- 10: 48 89 f8 mov %rdi,%rax
- 13: 48 39 fe cmp %rdi,%rsi
- 16: 7d 0f jge 0x27
- 18: 49 89 f0 mov %rsi,%r8
- 1b: 49 01 d0 add %rdx,%r8
- 1e: 49 39 f8 cmp %rdi,%r8
- 21: 0f 8f b5 00 00 00 jg 0xdc
- 27: 48 89 d1 mov %rdx,%rcx
- * 2a: f3 a4 rep movsb %ds:(%rsi),%es:(%rdi) <-- trapping instruction
- 2c: e9 26 14 1b 00 jmp 0x1b1457
- 31: 66 2e 0f 1f 84 00 00 cs nopw 0x0(%rax,%rax,1)
- 38: 00 00 00
- 3b: 48 rex.W
- 3c: 81 .byte 0x81
- 3d: fa cli
- 3e: a8 02 test $0x2,%al
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement