WARNING in rt_mutex_slowunlock

10 views
Skip to first unread message

syzbot

unread,
Oct 18, 2019, 1:00:08 PM10/18/19
to syzkaller-a...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 8fe42840 Merge 4.9.141 into android-4.9
git tree: android-4.9
console output: https://syzkaller.appspot.com/x/log.txt?x=14ba1373600000
kernel config: https://syzkaller.appspot.com/x/.config?x=22a5ba9f73b6da1d
dashboard link: https://syzkaller.appspot.com/bug?extid=00915f625ed10d902364
compiler: gcc (GCC) 8.0.1 20180413 (experimental)
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1176a9bb600000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+00915f...@syzkaller.appspotmail.com

audit: type=1400 audit(1571413547.896:8): avc: denied { associate } for
pid=2064 comm="syz-executor.4" name="syz4"
scontext=unconfined_u:object_r:unlabeled_t:s0
tcontext=system_u:object_r:unlabeled_t:s0 tclass=filesystem permissive=1
------------[ cut here ]------------
WARNING: CPU: 1 PID: 2219 at kernel/locking/rtmutex-debug.c:142
debug_rt_mutex_unlock+0xda/0x100 kernel/locking/rtmutex-debug.c:142
DEBUG_LOCKS_WARN_ON(rt_mutex_owner(lock) != current)[ 28.103810] Kernel
panic - not syncing: panic_on_warn set ...

CPU: 1 PID: 2219 Comm: syz-executor.3 Not tainted 4.9.141+ #1
ffff8801cbaf7680 ffffffff81b42e79 ffffffff82a38ce0 00000000ffffffff
ffffffff82a55a00 0000000000000001 0000000000000009 ffff8801cbaf7740
ffffffff813f7125 0000000041b58ab3 ffffffff82e2b62b ffffffff813f6f66
Call Trace:
[<ffffffff81b42e79>] __dump_stack lib/dump_stack.c:15 [inline]
[<ffffffff81b42e79>] dump_stack+0xc1/0x128 lib/dump_stack.c:51
[<ffffffff813f7125>] panic+0x1bf/0x39f kernel/panic.c:179
[<ffffffff813f7362>] __warn.cold.8+0x2f/0x2f kernel/panic.c:542
[<ffffffff810dbec2>] warn_slowpath_fmt+0xc2/0x100 kernel/panic.c:565
[<ffffffff81214bda>] debug_rt_mutex_unlock+0xda/0x100
kernel/locking/rtmutex-debug.c:142
[<ffffffff82811901>] rt_mutex_slowunlock+0x21/0x1c0
kernel/locking/rtmutex.c:1366
[<ffffffff828124ee>] rt_mutex_fastunlock kernel/locking/rtmutex.c:1480
[inline]
[<ffffffff828124ee>] rt_mutex_unlock+0x6e/0xc0
kernel/locking/rtmutex.c:1584
[<ffffffff8129fdec>] exit_pi_state_list+0x34c/0x500 kernel/futex.c:918
[<ffffffff810d2d1e>] mm_release+0x2ee/0x410 kernel/fork.c:1103
[<ffffffff810e6859>] exit_mm kernel/exit.c:469 [inline]
[<ffffffff810e6859>] do_exit+0x399/0x2a50 kernel/exit.c:820
[<ffffffff810ed3a1>] do_group_exit+0x111/0x300 kernel/exit.c:937
[<ffffffff8110eb61>] get_signal+0x4e1/0x1460 kernel/signal.c:2321
[<ffffffff81052aa5>] do_signal+0x95/0x1b00 arch/x86/kernel/signal.c:807
[<ffffffff81003e2e>] exit_to_usermode_loop+0x10e/0x150
arch/x86/entry/common.c:158
[<ffffffff81005932>] prepare_exit_to_usermode arch/x86/entry/common.c:194
[inline]
[<ffffffff81005932>] syscall_return_slowpath arch/x86/entry/common.c:263
[inline]
[<ffffffff81005932>] do_syscall_64+0x3e2/0x550 arch/x86/entry/common.c:290
[<ffffffff82817893>] entry_SYSCALL_64_after_swapgs+0x5d/0xdb
Shutting down cpus with NMI
Kernel Offset: disabled
Rebooting in 86400 seconds..


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this bug, for details see:
https://goo.gl/tpsmEJ#testing-patches

syzbot

unread,
Oct 18, 2019, 1:02:09 PM10/18/19
to syzkaller-a...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 62872f95 Merge 4.4.174 into android-4.4
git tree: android-4.4
console output: https://syzkaller.appspot.com/x/log.txt?x=14714190e00000
kernel config: https://syzkaller.appspot.com/x/.config?x=47bc4dd423780c4a
dashboard link: https://syzkaller.appspot.com/bug?extid=889efe3a3b6ebb1c497f
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
userspace arch: i386
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1720c437600000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+889efe...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 1 PID: 3049 at kernel/locking/rtmutex-debug.c:142
debug_rt_mutex_unlock+0xd4/0x100 kernel/locking/rtmutex-debug.c:142()
DEBUG_LOCKS_WARN_ON(rt_mutex_owner(lock) != current)
Kernel panic - not syncing: panic_on_warn set ...

CPU: 1 PID: 3049 Comm: syz-executor.5 Not tainted 4.4.174+ #17
0000000000000000 d3d30f1c1a958b78 ffff8801d9d77628 ffffffff81aad1a1
ffff8801d9d77778 ffffffff82835ee0 ffffffff82851320 000000000000008e
ffffffff8120e084 ffff8801d9d77708 ffffffff813a48c2 0000000041b58ab3
Call Trace:
[<ffffffff81aad1a1>] __dump_stack lib/dump_stack.c:15 [inline]
[<ffffffff81aad1a1>] dump_stack+0xc1/0x120 lib/dump_stack.c:51
[<ffffffff813a48c2>] panic+0x1b9/0x37b kernel/panic.c:112
[<ffffffff813a4ab9>] warn_slowpath_common kernel/panic.c:455 [inline]
[<ffffffff813a4ab9>] warn_slowpath_common.cold+0x20/0x20 kernel/panic.c:435
[<ffffffff810d394f>] warn_slowpath_fmt+0xbf/0x100 kernel/panic.c:471
[<ffffffff8120e084>] debug_rt_mutex_unlock+0xd4/0x100
kernel/locking/rtmutex-debug.c:142
[<ffffffff82713a7e>] rt_mutex_slowunlock+0x1e/0x1c0
kernel/locking/rtmutex.c:1332
[<ffffffff827147d8>] rt_mutex_fastunlock kernel/locking/rtmutex.c:1446
[inline]
[<ffffffff827147d8>] rt_mutex_unlock+0x88/0xf0
kernel/locking/rtmutex.c:1550
[<ffffffff8129545f>] exit_pi_state_list+0x2af/0x540 kernel/futex.c:913
[<ffffffff810caa33>] mm_release+0x2e3/0x400 kernel/fork.c:932
[<ffffffff810d86da>] exit_mm kernel/exit.c:395 [inline]
[<ffffffff810d86da>] do_exit+0x49a/0x2c60 kernel/exit.c:750
[<ffffffff810df091>] do_group_exit+0x111/0x300 kernel/exit.c:893
[<ffffffff81100a97>] get_signal+0x517/0x1570 kernel/signal.c:2321
[<ffffffff8100bd4c>] do_signal+0x9c/0x1840 arch/x86/kernel/signal.c:712
[<ffffffff81003da7>] exit_to_usermode_loop+0x127/0x170
arch/x86/entry/common.c:184
[<ffffffff810064b9>] prepare_exit_to_usermode arch/x86/entry/common.c:221
[inline]
[<ffffffff810064b9>] syscall_return_slowpath arch/x86/entry/common.c:286
[inline]
[<ffffffff810064b9>] do_syscall_32_irqs_on arch/x86/entry/common.c:336
[inline]
[<ffffffff810064b9>] do_fast_syscall_32+0x7a9/0xa90
arch/x86/entry/common.c:397
[<ffffffff8271a350>] sysenter_flags_fixed+0xd/0x1a
Reply all
Reply to author
Forward
0 new messages