Re: [syzbot] [bcachefs?] KMSAN: uninit-value in bch2_bkey_cmp_packed_inlined

From: syzbot
Date: Sat Sep 14 2024 - 08:15:09 EST


Hello,

syzbot has tested the proposed patch but the reproducer is still triggering an issue:
kernel panic: corrupted stack end in x64_sys_call

bucket 0:127 gen 0 has wrong data_type: got free, should be sb, fixing
bucket 0:127 gen 0 data type sb has wrong dirty_sectors: got 0, should be 256, fixing
done
bcachefs (loop0): going read-write
bcachefs (loop0): journal_replay...
Kernel panic - not syncing: corrupted stack end detected inside scheduler
CPU: 0 UID: 0 PID: 5945 Comm: syz.0.15 Not tainted 6.11.0-rc7-syzkaller-g57719771a244-dirty #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/06/2024
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:93 [inline]
dump_stack_lvl+0x216/0x2d0 lib/dump_stack.c:119
dump_stack+0x1e/0x30 lib/dump_stack.c:128
panic+0x4e2/0xcd0 kernel/panic.c:354
schedule_debug kernel/sched/core.c:5745 [inline]
__schedule+0x660/0x6580 kernel/sched/core.c:6411
__schedule_loop kernel/sched/core.c:6606 [inline]
schedule+0x13d/0x380 kernel/sched/core.c:6621
__closure_sync+0x163/0x1c0 lib/closure.c:146
closure_sync include/linux/closure.h:195 [inline]
bch2_journal_flush_pins+0x263/0x3b0 fs/bcachefs/journal_reclaim.c:851
bch2_journal_flush_all_pins fs/bcachefs/journal_reclaim.h:76 [inline]
bch2_journal_replay+0x4923/0x4d20 fs/bcachefs/recovery.c:383
bch2_run_recovery_pass fs/bcachefs/recovery_passes.c:183 [inline]
bch2_run_recovery_passes+0x400/0xec0 fs/bcachefs/recovery_passes.c:230
bch2_fs_recovery+0x42d2/0x5c60 fs/bcachefs/recovery.c:859
bch2_fs_start+0x7b2/0xbd0 fs/bcachefs/super.c:1036
bch2_fs_get_tree+0x13e8/0x22d0 fs/bcachefs/fs.c:1954
vfs_get_tree+0xb1/0x5a0 fs/super.c:1800
do_new_mount+0x71f/0x15e0 fs/namespace.c:3472
path_mount+0x742/0x1f10 fs/namespace.c:3799
do_mount fs/namespace.c:3812 [inline]
__do_sys_mount fs/namespace.c:4020 [inline]
__se_sys_mount+0x722/0x810 fs/namespace.c:3997
__x64_sys_mount+0xe4/0x150 fs/namespace.c:3997
x64_sys_call+0x255a/0x3ba0 arch/x86/include/generated/asm/syscalls_64.h:166
do_syscall_x64 arch/x86/entry/common.c:52 [inline]
do_syscall_64+0xcd/0x1e0 arch/x86/entry/common.c:83
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f6261f7e69a
Code: d8 64 89 02 48 c7 c0 ff ff ff ff eb a6 e8 de 1a 00 00 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 49 89 ca b8 a5 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f6262e37e68 EFLAGS: 00000246 ORIG_RAX: 00000000000000a5
RAX: ffffffffffffffda RBX: 00007f6262e37ef0 RCX: 00007f6261f7e69a
RDX: 00000000200058c0 RSI: 0000000020005900 RDI: 00007f6262e37eb0
RBP: 00000000200058c0 R08: 00007f6262e37ef0 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000020005900
R13: 00007f6262e37eb0 R14: 0000000000005905 R15: 00000000200001c0
</TASK>
Kernel Offset: disabled
Rebooting in 86400 seconds..


Tested on:

commit: 57719771 Merge tag 'sound-6.11' of git://git.kernel.or..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=162ce900580000
kernel config: https://syzkaller.appspot.com/x/.config?x=ea008021530b2de3
dashboard link: https://syzkaller.appspot.com/bug?extid=6f655a60d3244d0c6718
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
patch: https://syzkaller.appspot.com/x/patch.diff?x=11026200580000