Hello,
syzbot found the following crash on:
HEAD commit: 7fe05eed Merge 4.9.194 into android-4.9
git tree: android-4.9
console output:
https://syzkaller.appspot.com/x/log.txt?x=15555fe7600000
kernel config:
https://syzkaller.appspot.com/x/.config?x=c6d462552c77f021
dashboard link:
https://syzkaller.appspot.com/bug?extid=6f6e4f6efef7ffb4fdd8
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
syz repro:
https://syzkaller.appspot.com/x/repro.syz?x=15cee2bb600000
C reproducer:
https://syzkaller.appspot.com/x/repro.c?x=11e0a76f600000
IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by:
syzbot+6f6e4f...@syzkaller.appspotmail.com
random: crng init done
kasan: CONFIG_KASAN_INLINE enabled
kasan: GPF could be caused by NULL-ptr deref or user memory access
general protection fault: 0000 [#1] PREEMPT SMP KASAN
Modules linked in:
CPU: 1 PID: 2043 Comm: syz-executor521 Not tainted 4.9.194+ #0
task: 0000000000a98544 task.stack: 00000000a68fd96b
RIP: 0010:[<ffffffff81ae5d7a>] [<00000000e3e86a92>] bdev_get_queue
include/linux/blkdev.h:847 [inline]
RIP: 0010:[<ffffffff81ae5d7a>] [<00000000e3e86a92>]
blk_get_backing_dev_info+0x4a/0x70 block/blk-core.c:118
RSP: 0018:ffff8801cf3076c8 EFLAGS: 00010206
RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 1ffff10039e60f0a
RDX: 00000000000000a6 RSI: ffffffff81ae5d3d RDI: 0000000000000530
RBP: ffff8801cf3076d0 R08: 0000000000000000 R09: 0000000000000001
R10: 0000000000000001 R11: 0000000000000001 R12: ffffea00073da200
R13: ffff8801d476c888 R14: ffff8801d476c690 R15: ffffffff833f1db8
FS: 0000000001f08880(0000) GS:ffff8801db700000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000000000049f500 CR3: 0000000003026000 CR4: 00000000001606b0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Stack:
ffff8801da49a200 ffff8801cf307710 ffffffff8143e202 ffff8801d476c888
ffff8801d476c888 ffffea00073da200 ffffea00073da220 ffff8801d476c888
0000000000000000 ffff8801cf307740 ffffffff8144a790 dffffc0000000000
Call Trace:
[<0000000035f25f36>] inode_to_bdi include/linux/backing-dev.h:186 [inline]
[<0000000035f25f36>] mapping_cap_account_dirty
include/linux/backing-dev.h:234 [inline]
[<0000000035f25f36>] cancel_dirty_page+0x1a2/0x3d0 mm/page-writeback.c:2609
[<0000000074aee529>] truncate_complete_page mm/truncate.c:126 [inline]
[<0000000074aee529>] truncate_inode_page+0x130/0x260 mm/truncate.c:167
[<00000000fe7a56ba>] truncate_inode_pages_range+0x20e/0xfe0
mm/truncate.c:291
[<0000000027bd6642>] truncate_inode_pages mm/truncate.c:401 [inline]
[<0000000027bd6642>] truncate_inode_pages_final+0x81/0xc0 mm/truncate.c:452
[<0000000008d53e93>] bdev_evict_inode+0x21/0x190 fs/block_dev.c:639
[<000000009aea899a>] evict+0x2e9/0x630 fs/inode.c:553
[<00000000d9fb2b34>] iput_final fs/inode.c:1516 [inline]
[<00000000d9fb2b34>] iput fs/inode.c:1543 [inline]
[<00000000d9fb2b34>] iput+0x370/0x900 fs/inode.c:1528
[<00000000ef614325>] bdput fs/block_dev.c:775 [inline]
[<00000000ef614325>] bd_forget+0xf0/0x1a0 fs/block_dev.c:826
[<000000004fa6049d>] evict+0x485/0x630 fs/inode.c:559
[<00000000d9fb2b34>] iput_final fs/inode.c:1516 [inline]
[<00000000d9fb2b34>] iput fs/inode.c:1543 [inline]
[<00000000d9fb2b34>] iput+0x370/0x900 fs/inode.c:1528
[<00000000e49cb3e8>] dentry_unlink_inode+0x277/0x330 fs/dcache.c:369
[<000000005c849b1e>] __dentry_kill+0x333/0x580 fs/dcache.c:571
[<00000000b807dca8>] dentry_kill fs/dcache.c:612 [inline]
[<00000000b807dca8>] dput.part.0+0x5d9/0x7c0 fs/dcache.c:829
[<00000000324367b9>] dput fs/dcache.c:791 [inline]
[<00000000324367b9>] do_one_tree+0x44/0x50 fs/dcache.c:1483
[<00000000c3cfac58>] shrink_dcache_for_umount+0x67/0x160 fs/dcache.c:1497
[<00000000f18392b0>] generic_shutdown_super+0x6d/0x300 fs/super.c:432
[<00000000380acbae>] kill_anon_super+0x3f/0x60 fs/super.c:978
[<00000000d1518128>] fuse_kill_sb_anon+0x42/0x50 fs/fuse/inode.c:1223
[<0000000014368a59>] deactivate_locked_super+0x79/0xe0 fs/super.c:320
[<00000000f8c2be77>] deactivate_super fs/super.c:351 [inline]
[<00000000f8c2be77>] deactivate_super+0x8a/0xb0 fs/super.c:347
[<00000000fcebe4a1>] cleanup_mnt+0xb2/0x160 fs/namespace.c:1143
[<00000000a5842d7a>] __cleanup_mnt+0x16/0x20 fs/namespace.c:1150
[<000000005841f59d>] task_work_run+0x108/0x180 kernel/task_work.c:116
[<00000000f2cf76d3>] exit_task_work include/linux/task_work.h:21 [inline]
[<00000000f2cf76d3>] do_exit+0x78f/0x2aa0 kernel/exit.c:842
[<00000000714fc9f2>] do_group_exit+0x111/0x300 kernel/exit.c:946
[<000000005d1bb262>] SYSC_exit_group kernel/exit.c:957 [inline]
[<000000005d1bb262>] SyS_exit_group+0x1d/0x20 kernel/exit.c:955
[<0000000081938096>] do_syscall_64+0x1ad/0x5c0 arch/x86/entry/common.c:288
[<000000006c9aeff4>] entry_SYSCALL_64_after_swapgs+0x5d/0xdb
Code: 89 fa 48 c1 ea 03 80 3c 02 00 75 35 48 8b 9b e0 00 00 00 48 b8 00 00
00 00 00 fc ff df 48 8d bb 30 05 00 00 48 89 fa 48 c1 ea 03 <80> 3c 02 00
75 17 48 8b 83 30 05 00 00 5b 5d 48 05 20 02 00 00
RIP [<00000000e3e86a92>] bdev_get_queue include/linux/blkdev.h:847 [inline]
RIP [<00000000e3e86a92>] blk_get_backing_dev_info+0x4a/0x70
block/blk-core.c:118
RSP <ffff8801cf3076c8>
---[ end trace d28dd60130a57b01 ]---
---
This bug is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this bug, for details see:
https://goo.gl/tpsmEJ#testing-patches