All of lore.kernel.org
 help / color / mirror / Atom feed
From: syzbot <syzbot+63bed493aebbf6872647@syzkaller.appspotmail.com>
To: akpm@linux-foundation.org, bp@alien8.de, hkallweit1@gmail.com,
	hpa@zytor.com, linux-kernel@vger.kernel.org, luto@kernel.org,
	mingo@redhat.com, syzkaller-bugs@googlegroups.com,
	tglx@linutronix.de, x86@kernel.org
Subject: WARNING in __queue_work (3)
Date: Mon, 03 Aug 2020 17:36:22 -0700	[thread overview]
Message-ID: <000000000000c79c6b05ac027164@google.com> (raw)

Hello,

syzbot found the following issue on:

HEAD commit:    e2c46b57 Merge tag 'block-5.8-2020-07-30' of git://git.ker..
git tree:       upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=1269bcb8900000
kernel config:  https://syzkaller.appspot.com/x/.config?x=e956cd46a325a50c
dashboard link: https://syzkaller.appspot.com/bug?extid=63bed493aebbf6872647
compiler:       gcc (GCC) 10.1.0-syz 20200507
userspace arch: i386

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+63bed493aebbf6872647@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 1 PID: 0 at kernel/workqueue.c:1413 __queue_work+0xc2c/0xff0 kernel/workqueue.c:1413
Kernel panic - not syncing: panic_on_warn set ...
CPU: 1 PID: 0 Comm: swapper/1 Not tainted 5.8.0-rc7-syzkaller #0
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.12.0-59-gc9ba5276e321-prebuilt.qemu.org 04/01/2014
Call Trace:
 <IRQ>
 __dump_stack lib/dump_stack.c:77 [inline]
 dump_stack+0x18f/0x20d lib/dump_stack.c:118
 panic+0x2e3/0x75c kernel/panic.c:231
 __warn.cold+0x20/0x45 kernel/panic.c:600
 report_bug+0x1bd/0x210 lib/bug.c:198
 handle_bug+0x38/0x90 arch/x86/kernel/traps.c:235
 exc_invalid_op+0x13/0x40 arch/x86/kernel/traps.c:255
 asm_exc_invalid_op+0x12/0x20 arch/x86/include/asm/idtentry.h:540
RIP: 0010:__queue_work+0xc2c/0xff0 kernel/workqueue.c:1413
Code: e0 07 83 c0 03 38 d0 7c 09 84 d2 74 05 e8 ec 38 67 00 8b 5b 24 31 ff 83 e3 20 89 de e8 8d d0 27 00 85 db 75 7c e8 04 d4 27 00 <0f> 0b e9 42 fa ff ff e8 f8 d3 27 00 0f 0b e9 bb f9 ff ff e8 ec d3
RSP: 0018:ffffc900004e8cb0 EFLAGS: 00010046
RAX: 0000000000000000 RBX: 0000000000000100 RCX: ffffffff814be8b3
RDX: ffff88802c1ec380 RSI: ffffffff814be90c RDI: 0000000000000005
RBP: 0000000000000101 R08: 0000000000000001 R09: ffffffff8cb6a4a3
R10: 0000000000000000 R11: 0000000000000000 R12: ffff88805fdfe128
R13: 0000000000000000 R14: ffff88802930e000 R15: 0000000000000040
 call_timer_fn+0x1ac/0x760 kernel/time/timer.c:1416
 expire_timers kernel/time/timer.c:1456 [inline]
 __run_timers.part.0+0x376/0xa20 kernel/time/timer.c:1792
 __run_timers kernel/time/timer.c:1764 [inline]
 run_timer_softirq+0xae/0x1a0 kernel/time/timer.c:1805
 __do_softirq+0x34c/0xa60 kernel/softirq.c:292
 asm_call_on_stack+0xf/0x20 arch/x86/entry/entry_64.S:711
 </IRQ>
 __run_on_irqstack arch/x86/include/asm/irq_stack.h:22 [inline]
 run_on_irqstack_cond arch/x86/include/asm/irq_stack.h:48 [inline]
 do_softirq_own_stack+0x111/0x170 arch/x86/kernel/irq_64.c:77
 invoke_softirq kernel/softirq.c:387 [inline]
 __irq_exit_rcu kernel/softirq.c:417 [inline]
 irq_exit_rcu+0x229/0x270 kernel/softirq.c:429
 sysvec_apic_timer_interrupt+0x54/0x120 arch/x86/kernel/apic/apic.c:1091
 asm_sysvec_apic_timer_interrupt+0x12/0x20 arch/x86/include/asm/idtentry.h:585
RIP: 0010:native_safe_halt+0xe/0x10 arch/x86/include/asm/irqflags.h:61
Code: ff 4c 89 ef e8 e3 69 c8 f9 e9 8e fe ff ff 48 89 df e8 d6 69 c8 f9 eb 8a cc cc cc cc e9 07 00 00 00 0f 00 2d b4 ff 5d 00 fb f4 <c3> 90 e9 07 00 00 00 0f 00 2d a4 ff 5d 00 f4 c3 cc cc 55 53 e8 a9
RSP: 0018:ffffc9000041fde8 EFLAGS: 00000282
RAX: 1ffffffff1369c14 RBX: ffff88802c1ec380 RCX: 0000000000000000
RDX: dffffc0000000000 RSI: 0000000000000000 RDI: ffffffff87eab336
RBP: dffffc0000000000 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000001 R11: 0000000000000000 R12: ffffed100583d870
R13: 0000000000000001 R14: ffffffff8aaf2548 R15: 0000000000000000
 arch_safe_halt arch/x86/include/asm/paravirt.h:150 [inline]
 default_idle+0x40/0x70 arch/x86/kernel/process.c:686
 cpuidle_idle_call kernel/sched/idle.c:163 [inline]
 do_idle+0x38f/0x6d0 kernel/sched/idle.c:276
 cpu_startup_entry+0x14/0x20 kernel/sched/idle.c:372
 start_secondary+0x2b3/0x370 arch/x86/kernel/smpboot.c:268
 secondary_startup_64+0xa4/0xb0 arch/x86/kernel/head_64.S:243
Kernel Offset: disabled
Rebooting in 86400 seconds..


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

             reply	other threads:[~2020-08-04  0:36 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2020-08-04  0:36 syzbot [this message]
2020-12-09 11:48 ` WARNING in __queue_work (3) syzbot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=000000000000c79c6b05ac027164@google.com \
    --to=syzbot+63bed493aebbf6872647@syzkaller.appspotmail.com \
    --cc=akpm@linux-foundation.org \
    --cc=bp@alien8.de \
    --cc=hkallweit1@gmail.com \
    --cc=hpa@zytor.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=luto@kernel.org \
    --cc=mingo@redhat.com \
    --cc=syzkaller-bugs@googlegroups.com \
    --cc=tglx@linutronix.de \
    --cc=x86@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.