Hello, syzbot found the following issue on:
HEAD commit: 66498c75b4f8 Merge tag 'dmaengine-7.3-rc1' of git://git.ke.. git tree: upstream console output: https://syzkaller.appspot.com/x/log.txt?x=149d6625580000 kernel config: https://syzkaller.appspot.com/x/.config?x=780bb9a5c10069a1 dashboard link: https://syzkaller.appspot.com/bug?extid=5caf8faef4fa32603577 compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8 Downloadable assets: disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/d900f083ada3/non_bootable_disk-66498c75.raw.xz vmlinux: https://storage.googleapis.com/syzbot-assets/4708be72b898/vmlinux-66498c75.xz kernel image: https://storage.googleapis.com/syzbot-assets/e5cfcadeec97/bzImage-66498c75.xz IMPORTANT: if you fix the issue, please add the following tag to the commit: Reported-by: [email protected] qnx6: QNX6 filesystem 1.0.0 registered. fuse: init (API version 7.45) orangefs_debugfs_init: called with debug mask: :none: :0: orangefs_init: module version upstream loaded JFS: nTxBlock = 6145, nTxLock = 49167 SGI XFS with ACLs, security attributes, realtime, scrub, repair, quota, no debug enabled 9p: Installing v9fs 9p2000 file system support NILFS version 2 loaded befs: version: 0.9.3 ocfs2: Registered cluster interface o2cb ocfs2: Registered cluster interface user OCFS2 User DLM kernel interface loaded gfs2: GFS2 installed ceph: loaded (mds proto 32) NET: Registered PF_ALG protocol family async_tx: api initialized (async) Key type asymmetric registered Asymmetric key parser 'x509' registered Asymmetric key parser 'pkcs8' registered Key type pkcs7_test registered Block layer SCSI generic (bsg) driver version 0.4 loaded (major 239) io scheduler mq-deadline registered io scheduler kyber registered io scheduler bfq registered raid6: skipped pq benchmark and selected avx512x4 ACPI: \_SB_.GSIE: Enabled at IRQ 20 pcieport 0000:00:04.0: PME: Signaling with IRQ 25 pcieport 0000:00:04.0: AER: enabled with IRQ 26 input: Power Button as /devices/platform/LNXPWRBN:00/input/input0 ACPI: button: Power Button [PWRF] ioatdma: Intel(R) QuickData Technology Driver 5.00 ACPI: \_SB_.GSIF: Enabled at IRQ 21 ACPI: \_SB_.GSIH: Enabled at IRQ 23 N_HDLC line discipline registered with maxframe=4096 Serial: 8250/16550 driver, 4 ports, IRQ sharing enabled 00:03: ttyS0 at I/O 0x3f8 (irq = 4, base_baud = 115200) is a 16550A Non-volatile memory driver v1.3 usbcore: registered new interface driver xillyusb ACPI: bus type drm_connector registered [drm] Initialized vgem 1.0.0 for vgem on minor 0 usbcore: registered new interface driver udl [drm] pci: virtio-vga detected at 0000:00:01.0 virtio-pci 0000:00:01.0: vgaarb: deactivate vga console Console: switching to colour dummy device 80x25 [drm] features: -virgl +edid -resource_blob -host_visible [drm] features: -context_init -blob_alignment [drm] number of scanouts: 1 [drm] number of cap sets: 0 ------------[ cut here ]------------ [PLANE:36:plane-1] pixel format with alpha exposed but blend mode not setup WARNING: drivers/gpu/drm/drm_mode_config.c:873 at validate_blend_mode_for_alpha_formats drivers/gpu/drm/drm_mode_config.c:872 [inline], CPU#0: swapper/0/1 WARNING: drivers/gpu/drm/drm_mode_config.c:873 at drm_mode_config_validate+0x1c6a/0x1e60 drivers/gpu/drm/drm_mode_config.c:938, CPU#0: swapper/0/1 Modules linked in: CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 RIP: 0010:validate_blend_mode_for_alpha_formats drivers/gpu/drm/drm_mode_config.c:872 [inline] RIP: 0010:drm_mode_config_validate+0x1cab/0x1e60 drivers/gpu/drm/drm_mode_config.c:938 Code: 0f 85 ae 00 00 00 4d 8d 77 10 8b 6d 00 4c 89 f0 48 c1 e8 03 80 3c 18 00 74 08 4c 89 f7 e8 3d a7 a3 fc 49 8b 16 4c 89 ef 89 ee <67> 48 0f b9 3a eb 05 e8 49 56 32 fc 49 bd 00 00 00 00 00 fc ff df RSP: 0000:ffffc900001af450 EFLAGS: 00010246 RAX: 1ffff11000022e08 RBX: dffffc0000000000 RCX: ffff88801ceb0000 RDX: ffff88801f5c7900 RSI: 0000000000000024 RDI: ffffffff9085b000 RBP: 0000000000000024 R08: ffffffff8ec2b347 R09: 1ffffffff1d85668 R10: dffffc0000000000 R11: fffffbfff1d85669 R12: dffffc0000000000 R13: ffffffff9085b000 R14: ffff888000117040 R15: ffff888000117030 FS: 0000000000000000(0000) GS:ffff88808c2e6000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: ffff88801af19000 CR3: 000000000eb46000 CR4: 0000000000352ef0 Call Trace: <TASK> drm_dev_register+0x7c/0xd80 drivers/gpu/drm/drm_drv.c:1077 virtio_gpu_probe+0x1cb/0x290 drivers/gpu/drm/virtio/virtgpu_drv.c:107 virtio_dev_probe+0xdf6/0x10c0 drivers/virtio/virtio.c:347 call_driver_probe drivers/base/dd.c:-1 [inline] really_probe+0x254/0xae0 drivers/base/dd.c:706 __driver_probe_device+0x1e8/0x360 drivers/base/dd.c:868 driver_probe_device+0x4f/0x240 drivers/base/dd.c:898 __driver_attach+0x339/0x600 drivers/base/dd.c:1292 bus_for_each_dev+0x23b/0x2c0 drivers/base/bus.c:383 bus_add_driver+0x345/0x670 drivers/base/bus.c:763 driver_register+0x23a/0x320 drivers/base/driver.c:174 virtio_gpu_driver_init+0x96/0x110 drivers/gpu/drm/virtio/virtgpu_drv.c:298 do_one_initcall+0x250/0x870 init/main.c:1353 do_initcall_level+0x10a/0x1a0 init/main.c:1415 do_initcalls+0x59/0xa0 init/main.c:1431 kernel_init_freeable+0x29d/0x3e0 init/main.c:1666 kernel_init+0x22/0x1d0 init/main.c:1556 ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 </TASK> ---------------- Code disassembly (best guess): 0: 0f 85 ae 00 00 00 jne 0xb4 6: 4d 8d 77 10 lea 0x10(%r15),%r14 a: 8b 6d 00 mov 0x0(%rbp),%ebp d: 4c 89 f0 mov %r14,%rax 10: 48 c1 e8 03 shr $0x3,%rax 14: 80 3c 18 00 cmpb $0x0,(%rax,%rbx,1) 18: 74 08 je 0x22 1a: 4c 89 f7 mov %r14,%rdi 1d: e8 3d a7 a3 fc call 0xfca3a75f 22: 49 8b 16 mov (%r14),%rdx 25: 4c 89 ef mov %r13,%rdi 28: 89 ee mov %ebp,%esi * 2a: 67 48 0f b9 3a ud1 (%edx),%rdi <-- trapping instruction 2f: eb 05 jmp 0x36 31: e8 49 56 32 fc call 0xfc32567f 36: 49 bd 00 00 00 00 00 movabs $0xdffffc0000000000,%r13 3d: fc ff df --- This report is generated by a bot. It may contain errors. See https://goo.gl/tpsmEJ for more information about syzbot. syzbot engineers can be reached at [email protected]. syzbot will keep track of this issue. See: https://goo.gl/tpsmEJ#status for how to communicate with syzbot. If the report is already addressed, let syzbot know by replying with: #syz fix: exact-commit-title If you want to overwrite report's subsystems, reply with: #syz set subsystems: new-subsystem (See the list of subsystem names on the web dashboard) If the report is a duplicate of another one, reply with: #syz dup: exact-subject-of-another-report If you want to undo deduplication, reply with: #syz undup
