Reminder: 6 open syzbot bugs in mm subsystem

From: Eric Biggers
Date: Wed Jul 10 2019 - 02:24:01 EST


[This email was generated by a script. Let me know if you have any suggestions
to make it better, or if you want it re-generated with the latest status.

Note: currently the mm bugs look hard to do anything with and most look
outdated, but I figured I'd send them out just in case someone has any ideas...]

Of the currently open syzbot reports against the upstream kernel, I've manually
marked 6 of them as possibly being bugs in the mm subsystem. I've listed these
reports below, sorted by an algorithm that tries to list first the reports most
likely to be still valid, important, and actionable.

If you believe a bug is no longer valid, please close the syzbot report by
sending a '#syz fix', '#syz dup', or '#syz invalid' command in reply to the
original thread, as explained at https://goo.gl/tpsmEJ#status

If you believe I misattributed a bug to the mm subsystem, please let me know,
and if possible forward the report to the correct people or mailing list.

Here are the bugs:

--------------------------------------------------------------------------------
Title: kernel BUG at mm/huge_memory.c:LINE!
Last occurred: 17 days ago
Reported: 187 days ago
Branches: Mainline and others
Dashboard link: https://syzkaller.appspot.com/bug?id=ce0353d7d140e57d81b6f1cb9252a76e50454955
Original thread: https://lkml.kernel.org/lkml/0000000000004d2e19057e8b6d78@xxxxxxxxxx/T/#u

Unfortunately, this bug does not have a reproducer.

The original thread for this bug received 3 replies; the last was 154 days ago.

If you fix this bug, please add the following tag to the commit:
Reported-by: syzbot+8e075128f7db8555391a@xxxxxxxxxxxxxxxxxxxxxxxxx

If you send any email or patch for this bug, please consider replying to the
original thread. For the git send-email command to use, or tips on how to reply
if the thread isn't in your mailbox, see the "Reply instructions" at
https://lkml.kernel.org/r/0000000000004d2e19057e8b6d78@xxxxxxxxxx

--------------------------------------------------------------------------------
Title: KASAN: use-after-free Read in shmem_fault
Last occurred: 77 days ago
Reported: 143 days ago
Branches: Mainline and others
Dashboard link: https://syzkaller.appspot.com/bug?id=53e0b9f6b68687a4c24339c7a9713c26055d4f63
Original thread: https://lkml.kernel.org/lkml/00000000000045d4f10581fe59a7@xxxxxxxxxx/T/#u

Unfortunately, this bug does not have a reproducer.

No one replied to the original thread for this bug.

If you fix this bug, please add the following tag to the commit:
Reported-by: syzbot+56fbe62f8c55f860fd99@xxxxxxxxxxxxxxxxxxxxxxxxx

If you send any email or patch for this bug, please consider replying to the
original thread. For the git send-email command to use, or tips on how to reply
if the thread isn't in your mailbox, see the "Reply instructions" at
https://lkml.kernel.org/r/00000000000045d4f10581fe59a7@xxxxxxxxxx

--------------------------------------------------------------------------------
Title: WARNING in untrack_pfn
Last occurred: 153 days ago
Reported: 351 days ago
Branches: Mainline and others
Dashboard link: https://syzkaller.appspot.com/bug?id=149d7751733001d683eca36df500722bff6cc350
Original thread: https://lkml.kernel.org/lkml/000000000000f70a0e0571ad8ffb@xxxxxxxxxx/T/#u

This bug has a syzkaller reproducer only.

syzbot has bisected this bug, but I think the bisection result is incorrect.

The original thread for this bug received 3 replies; the last was 62 days ago.

If you fix this bug, please add the following tag to the commit:
Reported-by: syzbot+e1a4f80c370d2381e49f@xxxxxxxxxxxxxxxxxxxxxxxxx

If you send any email or patch for this bug, please consider replying to the
original thread. For the git send-email command to use, or tips on how to reply
if the thread isn't in your mailbox, see the "Reply instructions" at
https://lkml.kernel.org/r/000000000000f70a0e0571ad8ffb@xxxxxxxxxx

--------------------------------------------------------------------------------
Title: WARNING: locking bug in split_huge_page_to_list
Last occurred: 82 days ago
Reported: 77 days ago
Branches: Mainline
Dashboard link: https://syzkaller.appspot.com/bug?id=867f27bec5181128ff0b1729bde7eed6786ec6bc
Original thread: https://lkml.kernel.org/lkml/0000000000003c9bea058734dc28@xxxxxxxxxx/T/#u

Unfortunately, this bug does not have a reproducer.

The original thread for this bug has received 1 reply, 77 days ago.

If you fix this bug, please add the following tag to the commit:
Reported-by: syzbot+35a50f1f6dfd5a0d7378@xxxxxxxxxxxxxxxxxxxxxxxxx

If you send any email or patch for this bug, please consider replying to the
original thread. For the git send-email command to use, or tips on how to reply
if the thread isn't in your mailbox, see the "Reply instructions" at
https://lkml.kernel.org/r/0000000000003c9bea058734dc28@xxxxxxxxxx

--------------------------------------------------------------------------------
Title: kernel BUG at mm/page_alloc.c:LINE!
Last occurred: 94 days ago
Reported: 174 days ago
Branches: Mainline and others
Dashboard link: https://syzkaller.appspot.com/bug?id=858f3346ce928ea82fba5e952e44b7c2758a3609
Original thread: https://lkml.kernel.org/lkml/000000000000cdc61b057f9e360e@xxxxxxxxxx/T/#u

Unfortunately, this bug does not have a reproducer.

The original thread for this bug received 3 replies; the last was 173 days ago.

If you fix this bug, please add the following tag to the commit:
Reported-by: syzbot+80dd4798c16c634daf15@xxxxxxxxxxxxxxxxxxxxxxxxx

If you send any email or patch for this bug, please consider replying to the
original thread. For the git send-email command to use, or tips on how to reply
if the thread isn't in your mailbox, see the "Reply instructions" at
https://lkml.kernel.org/r/000000000000cdc61b057f9e360e@xxxxxxxxxx

--------------------------------------------------------------------------------
Title: kernel BUG at mm/internal.h:LINE!
Last occurred: 108 days ago
Reported: 106 days ago
Branches: Mainline and others
Dashboard link: https://syzkaller.appspot.com/bug?id=ffde950cd7002300185185998616192428c11981
Original thread: https://lkml.kernel.org/lkml/0000000000007311ca0584e690c1@xxxxxxxxxx/T/#u

Unfortunately, this bug does not have a reproducer.

No one replied to the original thread for this bug.

If you fix this bug, please add the following tag to the commit:
Reported-by: syzbot+ce4fa49466985039fb35@xxxxxxxxxxxxxxxxxxxxxxxxx

If you send any email or patch for this bug, please consider replying to the
original thread. For the git send-email command to use, or tips on how to reply
if the thread isn't in your mailbox, see the "Reply instructions" at
https://lkml.kernel.org/r/0000000000007311ca0584e690c1@xxxxxxxxxx