Re: [syzbot] WARNING in floppy_queue_rq

From: syzbot
Date: Mon Jun 20 2022 - 16:32:41 EST


syzbot has found a reproducer for the following issue on:

HEAD commit: a111daf0c53a Linux 5.19-rc3
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=15c2fe60080000
kernel config: https://syzkaller.appspot.com/x/.config?x=25cca39874d6b55f
dashboard link: https://syzkaller.appspot.com/bug?extid=334c1c7dfb084b11520e
compiler: gcc (Debian 10.2.1-6) 10.2.1 20210110, GNU ld (GNU Binutils for Debian) 2.35.2
userspace arch: i386
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=153429f8080000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+334c1c7dfb084b11520e@xxxxxxxxxxxxxxxxxxxxxxxxx

------------[ cut here ]------------
WARNING: CPU: 2 PID: 793 at drivers/block/floppy.c:999 schedule_bh drivers/block/floppy.c:999 [inline]
WARNING: CPU: 2 PID: 793 at drivers/block/floppy.c:999 process_fd_request drivers/block/floppy.c:2847 [inline]
WARNING: CPU: 2 PID: 793 at drivers/block/floppy.c:999 floppy_queue_rq+0x32b/0x390 drivers/block/floppy.c:2879
Modules linked in:
CPU: 2 PID: 793 Comm: kworker/2:1H Not tainted 5.19.0-rc3-syzkaller #0
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.14.0-2 04/01/2014
Workqueue: kblockd blk_mq_run_work_fn
RIP: 0010:schedule_bh drivers/block/floppy.c:999 [inline]
RIP: 0010:process_fd_request drivers/block/floppy.c:2847 [inline]
RIP: 0010:floppy_queue_rq+0x32b/0x390 drivers/block/floppy.c:2879
Code: ea 03 80 3c 02 00 75 67 48 8b 56 30 48 c7 c7 e0 9d 42 8a e8 40 f3 97 04 0f 0b 41 bc 0a 00 00 00 e9 36 ff ff ff e8 b5 69 e0 fc <0f> 0b e9 ec fe ff ff 48 89 df e8 46 2e 2d fd e9 ee fc ff ff 48 89
RSP: 0018:ffffc900042a7928 EFLAGS: 00010293
RAX: 0000000000000000 RBX: 0000000000000001 RCX: 0000000000000000
RDX: ffff88801bce0000 RSI: ffffffff849a0bcb RDI: 0000000000000007
RBP: ffffffff8c8f2a20 R08: 0000000000000007 R09: 0000000000000000
R10: 0000000000000001 R11: 0000000000000001 R12: ffff88801c30c188
R13: ffff88801c30c140 R14: ffffc900042a7b68 R15: ffff88801c30c188
FS: 0000000000000000(0000) GS:ffff88802ca00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00000000f6f5b024 CR3: 000000001c2ba000 CR4: 0000000000150ee0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
blk_mq_dispatch_rq_list+0x6ea/0x2350 block/blk-mq.c:1896
__blk_mq_do_dispatch_sched block/blk-mq-sched.c:173 [inline]
blk_mq_do_dispatch_sched+0x96d/0xc30 block/blk-mq-sched.c:187
__blk_mq_sched_dispatch_requests+0x26d/0x3e0 block/blk-mq-sched.c:313
blk_mq_sched_dispatch_requests+0x101/0x180 block/blk-mq-sched.c:339
__blk_mq_run_hw_queue+0xff/0x350 block/blk-mq.c:2013
blk_mq_run_work_fn+0x55/0x70 block/blk-mq.c:2336
process_one_work+0x996/0x1610 kernel/workqueue.c:2289
worker_thread+0x665/0x1080 kernel/workqueue.c:2436
kthread+0x2e9/0x3a0 kernel/kthread.c:376
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:302
</TASK>