Hello, syzbot found the following issue on: HEAD commit: d082ecbc71e9 Linux 6.14-rc4 git tree: upstream console+strace: https://syzkaller.appspot.com/x/log.txt?x=107eec98580000 kernel config: https://syzkaller.appspot.com/x/.config?x=5b4c41bdaeea1964 dashboard link: https://syzkaller.appspot.com/bug?extid=0b544778e9923a3de766 compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40 syz repro: https://syzkaller.appspot.com/x/repro.syz?x=176626e4580000 C reproducer: https://syzkaller.appspot.com/x/repro.c?x=147eec98580000 Downloadable assets: disk image: https://storage.googleapis.com/syzbot-assets/1e5dabe499e7/disk-d082ecbc.raw.xz vmlinux: https://storage.googleapis.com/syzbot-assets/1e0f27be469a/vmlinux-d082ecbc.xz kernel image: https://storage.googleapis.com/syzbot-assets/7e058c08d6c9/bzImage-d082ecbc.xz mounted in repro: https://storage.googleapis.com/syzbot-assets/24600c6adfb8/mount_0.gz fsck result: OK (log: https://syzkaller.appspot.com/x/fsck.log?x=16397fdf980000) The issue was bisected to: commit 5121711eb8dbcbed70b1db429a4665f413844164 Author: Josef Bacik <josef@xxxxxxxxxxxxxx> Date: Fri Nov 15 15:30:32 2024 +0000 fs: enable pre-content events on supported file systems bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=10ae1db0580000 final oops: https://syzkaller.appspot.com/x/report.txt?x=12ae1db0580000 console output: https://syzkaller.appspot.com/x/log.txt?x=14ae1db0580000 IMPORTANT: if you fix the issue, please add the following tag to the commit: Reported-by: syzbot+0b544778e9923a3de766@xxxxxxxxxxxxxxxxxxxxxxxxx Fixes: 5121711eb8db ("fs: enable pre-content events on supported file systems") WARNING: CPU: 0 PID: 5840 at mm/gup.c:1856 __get_user_pages_locked mm/gup.c:1856 [inline] WARNING: CPU: 0 PID: 5840 at mm/gup.c:1856 get_dump_page+0x242/0x2f0 mm/gup.c:2275 Modules linked in: CPU: 0 UID: 0 PID: 5840 Comm: syz-executor267 Not tainted 6.14.0-rc4-syzkaller #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 RIP: 0010:__get_user_pages_locked mm/gup.c:1856 [inline] RIP: 0010:get_dump_page+0x242/0x2f0 mm/gup.c:2275 Code: 00 00 00 48 3b 8c 24 80 00 00 00 0f 85 a3 00 00 00 48 8d 65 d8 5b 41 5c 41 5d 41 5e 41 5f 5d e9 1f 37 03 ff e8 0f b4 b4 ff 90 <0f> 0b 90 eb ae 44 89 c9 80 e1 07 80 c1 03 38 c1 0f 8c db fe ff ff RSP: 0018:ffffc900032c7180 EFLAGS: 00010293 RAX: ffffffff820d09f1 RBX: 0000000000000000 RCX: ffff8880346f0000 RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000 RBP: ffffc900032c7250 R08: ffffffff820d0968 R09: 1ffffd4000399126 R10: dffffc0000000000 R11: fffff94000399127 R12: 1ffff92000658e38 R13: dffffc0000000000 R14: 1ffff92000658e34 R15: 0000000000000000 FS: 0000555587160380(0000) GS:ffff8880b8600000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007fff9150b8f8 CR3: 0000000075dae000 CR4: 0000000000350ef0 Call Trace: <TASK> dump_user_range+0x14d/0x970 fs/coredump.c:943 elf_core_dump+0x4054/0x4a80 fs/binfmt_elf.c:2129 do_coredump+0x232c/0x32c0 fs/coredump.c:758 get_signal+0x13e5/0x1720 kernel/signal.c:3021 arch_do_signal_or_restart+0x96/0x860 arch/x86/kernel/signal.c:337 exit_to_user_mode_loop kernel/entry/common.c:111 [inline] exit_to_user_mode_prepare include/linux/entry-common.h:329 [inline] irqentry_exit_to_user_mode+0x7e/0x250 kernel/entry/common.c:231 exc_page_fault+0x590/0x8b0 arch/x86/mm/fault.c:1541 asm_exc_page_fault+0x26/0x30 arch/x86/include/asm/idtentry.h:623 RIP: 0033:0x7ff653b312d1 Code: c4 28 c3 e8 51 18 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 48 3d 01 f0 ff ff 73 01 <c3> 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f RSP: 002b:00000000fffffe10 EFLAGS: 00010217 RAX: 0000000000000000 RBX: 0000000000000003 RCX: 00007ff653b312c9 RDX: 0000000000000000 RSI: 00000000fffffe10 RDI: 0000000000000000 RBP: 00007fff9150b940 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 00000000000f4240 R13: 00007ff653b7f9dc R14: 00007ff653b7a0e2 R15: 00007fff9150b930 </TASK> --- This report is generated by a bot. It may contain errors. See https://goo.gl/tpsmEJ for more information about syzbot. syzbot engineers can be reached at syzkaller@xxxxxxxxxxxxxxxx. syzbot will keep track of this issue. See: https://goo.gl/tpsmEJ#status for how to communicate with syzbot. For information about bisection process see: https://goo.gl/tpsmEJ#bisection If the report is already addressed, let syzbot know by replying with: #syz fix: exact-commit-title If you want syzbot to run the reproducer, reply with: #syz test: git://repo/address.git branch-or-commit-hash If you attach or paste a git patch, syzbot will apply it before testing. If you want to overwrite report's subsystems, reply with: #syz set subsystems: new-subsystem (See the list of subsystem names on the web dashboard) If the report is a duplicate of another one, reply with: #syz dup: exact-subject-of-another-report If you want to undo deduplication, reply with: #syz undup