FYI, we noticed the following commit (built with gcc-7):
commit: 3e6e51217dd14dcda10d4bc9a38b1440e2d42c14 ("lib/rbtree,drm/mm: Add rbtree_replace_node_cached()") git://anongit.freedesktop.org/drm-intel topic/core-for-CI
in testcase: trinity with following parameters:
runtime: 300s
test-description: Trinity is a linux system call fuzz tester. test-url: http://codemonkey.org.uk/projects/trinity/
on test machine: qemu-system-x86_64 -enable-kvm -m 512M
caused below changes (please refer to attached dmesg/kmsg for entire log/backtrace):
+-----------------------------------------------+------------+------------+ | | 978de04a3c | 3e6e51217d | +-----------------------------------------------+------------+------------+ | boot_successes | 46 | 0 | | boot_failures | 0 | 8 | | WARNING:at_lib/stackdepot.c:#depot_save_stack | 0 | 8 | | RIP:depot_save_stack | 0 | 8 | | BUG:kernel_hang_in_test_stage | 0 | 4 | +-----------------------------------------------+------------+------------+
[ 278.198833] WARNING: CPU: 0 PID: 1 at lib/stackdepot.c:119 depot_save_stack+0x22e/0x353 [ 278.199990] CPU: 0 PID: 1 Comm: swapper Not tainted 4.15.0-rc2-00005-g3e6e512 #1 [ 278.199990] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.10.2-1 04/01/2014 [ 278.199990] task: 000000009f2da405 task.stack: 0000000018ee505d [ 278.199990] RIP: 0010:depot_save_stack+0x22e/0x353 [ 278.199990] RSP: 0000:ffff88001f5bb9d8 EFLAGS: 00010086 [ 278.199990] RAX: 0000000000000022 RBX: 00000000ae4fc5be RCX: ffff88001f5a8000 [ 278.199990] RDX: 000000221f5a8000 RSI: ffffffff810eb77c RDI: 0000000000000093 [ 278.199990] RBP: 0000000000000020 R08: 00000000e272d5c3 R09: 0000000000000004 [ 278.199990] R10: 0000000000000000 R11: 0000000065e7cb07 R12: 00000000000fc5be [ 278.199990] R13: ffff88001f5bba30 R14: 0000000000000000 R15: 0000000000000286 [ 278.199990] FS: 0000000000000000(0000) GS:ffffffff81e36000(0000) knlGS:0000000000000000 [ 278.199990] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 278.199990] CR2: 0000000000000000 CR3: 0000000001e11000 CR4: 00000000000006b0 [ 278.199990] Call Trace: [ 278.199990] ? save_stack+0x7c/0x89 [ 278.199990] ? drm_mm_interval_tree_add_node+0xf6/0x137 [ 278.199990] ? drm_mm_interval_tree_add_node+0xf6/0x137 [ 278.199990] ? add_hole+0x12d/0x155 [ 278.199990] ? add_hole+0x12d/0x155 [ 278.199990] ? drm_mm_interval_tree_add_node+0xf6/0x137 [ 278.199990] ? add_hole+0x12d/0x155 [ 278.199990] ? drm_mm_interval_tree_compute_subtree_last+0x54/0x5c [ 278.199990] ? drm_mm_interval_tree_augment_copy+0x18/0x18 [ 278.199990] ? add_hole+0x12d/0x155 [ 278.199990] ? drm_mm_reserve_node+0x13f/0x155 [ 278.199990] ? evict_something+0x244/0x2d1 [ 278.199990] ? drm_mm_interval_tree_add_node+0xf6/0x137 [ 278.199990] ? drm_mm_interval_tree_compute_subtree_last+0x54/0x5c [ 278.199990] ? drm_mm_interval_tree_augment_copy+0x18/0x18 [ 278.199990] ? add_hole+0x12d/0x155 [ 278.199990] ? drm_mm_reserve_node+0x13f/0x155 [ 278.199990] ? drm_mm_interval_tree_compute_subtree_last+0x54/0x5c [ 278.199990] ? drm_mm_interval_tree_augment_copy+0x18/0x18 [ 278.199990] ? drm_mm_interval_tree_augment_rotate+0x23/0x2a [ 278.199990] ? drm_mm_interval_tree_compute_subtree_last+0x54/0x5c [ 278.199990] ? rb_erase+0x146/0x270 [ 278.199990] ? drm_mm_interval_tree_add_node+0xf6/0x137 [ 278.199990] ? add_hole+0x12d/0x155 [ 278.199990] ? drm_mm_interval_tree_add_node+0xf6/0x137 [ 278.199990] ? drm_mm_interval_tree_add_node+0xf6/0x137 [ 278.199990] ? add_hole+0x12d/0x155 [ 278.199990] ? drm_mm_reserve_node+0x13f/0x155 [ 278.199990] ? evict_something+0x244/0x2d1 [ 278.199990] ? igt_evict+0x63d/0x75f [ 278.199990] ? test_drm_mm_init+0xb5/0x111 [ 278.199990] ? drm_fb_helper_modinit+0xd/0xd [ 278.199990] ? do_early_param+0xbe/0xbe [ 278.199990] ? drm_mm_reserve_node+0x13f/0x155 [ 278.199990] ? evict_something+0x244/0x2d1 [ 278.199990] ? igt_evict+0x63d/0x75f [ 278.199990] ? test_drm_mm_init+0xb5/0x111 [ 278.199990] ? drm_fb_helper_modinit+0xd/0xd [ 278.199990] ? do_early_param+0xbe/0xbe [ 278.199990] ? do_one_initcall+0x9d/0x158 [ 278.199990] ? do_early_param+0xbe/0xbe [ 278.199990] ? do_early_param+0xbe/0xbe [ 278.199990] ? kernel_init_freeable+0x11c/0x1cc [ 278.199990] ? rest_init+0xbb/0xbb [ 278.199990] ? kernel_init+0x10/0x13d [ 278.199990] ? rest_init+0xbb/0xbb [ 278.199990] ? ret_from_fork+0x24/0x30 [ 278.199990] Code: 8d 50 01 81 fa ff 1f 00 00 7e 27 80 3d 52 04 c0 00 00 0f 85 fd 00 00 00 48 c7 c7 e2 9e d0 81 c6 05 3e 04 c0 00 01 e8 f1 53 d7 ff <0f> ff e9 e3 00 00 00 83 c0 02 89 15 64 7c 6d 01 48 c7 05 4d 7c [ 278.199990] ---[ end trace 4dd271b4182c6be2 ]---
To reproduce:
git clone https://github.com/intel/lkp-tests.git cd lkp-tests bin/lkp qemu -k <bzImage> job-script # job-script is attached in this email
Thanks, Xiaolong