INFO: task hung in isig

4 views
Skip to first unread message

syzbot

unread,
Apr 12, 2019, 8:00:47 PM4/12/19
to syzkaller-a...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 320d53a9 Merge 4.9.96 into android-4.9
git tree: android-4.9
console output: https://syzkaller.appspot.com/x/log.txt?x=10d9ab17800000
kernel config: https://syzkaller.appspot.com/x/.config?x=a54f56879744de40
dashboard link: https://syzkaller.appspot.com/bug?extid=3cb4a3d5bce628f17b31
compiler: gcc (GCC) 8.0.1 20180413 (experimental)
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=171272a7800000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=14b05c57800000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+3cb4a3...@syzkaller.appspotmail.com

random: crng init done
INFO: task kworker/u4:0:6 blocked for more than 120 seconds.
Not tainted 4.9.96-g320d53a #7
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
kworker/u4:0 D28312 6 2 0x00000000
Workqueue: events_unbound flush_to_ldisc
ffff8801d9b40000 0000000000000000 ffff8801d91779c0 ffff8801d9b73000
ffff8801db321b98 ffff8801d9b4f6c8 ffffffff839e240d ffffffff81233817
0000000000000000 ffff8801d9b408c0 0000000600000007 ffff8801db322468
Call Trace:
[<ffffffff839e3a0f>] schedule+0x7f/0x1b0 kernel/sched/core.c:3557
[<ffffffff839ef048>] __rwsem_down_write_failed_common
kernel/locking/rwsem-xadd.c:526 [inline]
[<ffffffff839ef048>] rwsem_down_write_failed+0x598/0x990
kernel/locking/rwsem-xadd.c:555
[<ffffffff81ee4e77>] call_rwsem_down_write_failed+0x17/0x30
arch/x86/lib/rwsem.S:105
[<ffffffff839ece1c>] __down_write arch/x86/include/asm/rwsem.h:125 [inline]
[<ffffffff839ece1c>] down_write+0x5c/0xa0 kernel/locking/rwsem.c:54
[<ffffffff8211a88d>] isig+0xbd/0x4c0 drivers/tty/n_tty.c:1100
[<ffffffff8211b332>] n_tty_receive_signal_char+0x22/0xf0
drivers/tty/n_tty.c:1212
[<ffffffff8211f561>] n_tty_receive_char_special+0x10e1/0x2860
drivers/tty/n_tty.c:1258
[<ffffffff82122c2a>] n_tty_receive_buf_fast drivers/tty/n_tty.c:1579
[inline]
[<ffffffff82122c2a>] __receive_buf drivers/tty/n_tty.c:1613 [inline]
[<ffffffff82122c2a>] n_tty_receive_buf_common+0x18ea/0x2300
drivers/tty/n_tty.c:1711
[<ffffffff82123673>] n_tty_receive_buf2+0x33/0x40 drivers/tty/n_tty.c:1746
[<ffffffff8212917f>] tty_ldisc_receive_buf+0xaf/0x190
drivers/tty/tty_buffer.c:455
[<ffffffff8212a183>] receive_buf drivers/tty/tty_buffer.c:474 [inline]
[<ffffffff8212a183>] flush_to_ldisc+0x253/0x370
drivers/tty/tty_buffer.c:533
[<ffffffff8118ae31>] process_one_work+0x7e1/0x1500 kernel/workqueue.c:2092
[<ffffffff8118bc26>] worker_thread+0xd6/0x10a0 kernel/workqueue.c:2226
[<ffffffff8119ad5d>] kthread+0x26d/0x300 kernel/kthread.c:211
[<ffffffff839f34dc>] ret_from_fork+0x5c/0x70 arch/x86/entry/entry_64.S:373

Showing all locks held in the system:
5 locks held by kworker/u4:0/6:
#0: ("events_unbound"){.+.+.+}, at: [<ffffffff8118ad3e>] work_static
include/linux/workqueue.h:186 [inline]
#0: ("events_unbound"){.+.+.+}, at: [<ffffffff8118ad3e>] set_work_data
kernel/workqueue.c:617 [inline]
#0: ("events_unbound"){.+.+.+}, at: [<ffffffff8118ad3e>]
set_work_pool_and_clear_pending kernel/workqueue.c:644 [inline]
#0: ("events_unbound"){.+.+.+}, at: [<ffffffff8118ad3e>]
process_one_work+0x6ee/0x1500 kernel/workqueue.c:2085
#1: ((&buf->work)){+.+...}, at: [<ffffffff8118ad78>]
process_one_work+0x728/0x1500 kernel/workqueue.c:2089
#2: (&tty->ldisc_sem){++++++}, at: [<ffffffff82127940>]
tty_ldisc_ref+0x20/0x80 drivers/tty/tty_ldisc.c:297
#3: (&port->buf.lock/1){+.+...}, at: [<ffffffff82129fb6>]
flush_to_ldisc+0x86/0x370 drivers/tty/tty_buffer.c:505
#4: (&o_tty->termios_rwsem/1){++++..}, at: [<ffffffff8211a88d>]
isig+0xbd/0x4c0 drivers/tty/n_tty.c:1100
2 locks held by khungtaskd/518:
#0: (rcu_read_lock){......}, at: [<ffffffff813646ec>]
check_hung_uninterruptible_tasks kernel/hung_task.c:168 [inline]
#0: (rcu_read_lock){......}, at: [<ffffffff813646ec>]
watchdog+0x11c/0xa20 kernel/hung_task.c:239
#1: (tasklist_lock){.+.+..}, at: [<ffffffff81423ce0>]
debug_show_all_locks+0x79/0x218 kernel/locking/lockdep.c:4336
2 locks held by getty/3773:
#0: (&tty->ldisc_sem){++++++}, at: [<ffffffff839f14b2>]
ldsem_down_read+0x32/0x40 drivers/tty/tty_ldsem.c:367
#1: (&ldata->atomic_read_lock){+.+...}, at: [<ffffffff8211c792>]
n_tty_read+0x202/0x16e0 drivers/tty/n_tty.c:2133

=============================================

NMI backtrace for cpu 0
CPU: 0 PID: 518 Comm: khungtaskd Not tainted 4.9.96-g320d53a #7
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
ffff8801d84d7d08 ffffffff81eb0b69 0000000000000000 0000000000000000
0000000000000000 0000000000000001 ffffffff810b7d60 ffff8801d84d7d40
ffffffff81ebbe97 0000000000000000 0000000000000000 0000000000000002
Call Trace:
[<ffffffff81eb0b69>] __dump_stack lib/dump_stack.c:15 [inline]
[<ffffffff81eb0b69>] dump_stack+0xc1/0x128 lib/dump_stack.c:51
[<ffffffff81ebbe97>] nmi_cpu_backtrace.cold.2+0x48/0x87
lib/nmi_backtrace.c:99
[<ffffffff81ebbe2a>] nmi_trigger_cpumask_backtrace+0x12a/0x14f
lib/nmi_backtrace.c:60
[<ffffffff810b7e64>] arch_trigger_cpumask_backtrace+0x14/0x20
arch/x86/kernel/apic/hw_nmi.c:37
[<ffffffff81364c84>] trigger_all_cpu_backtrace include/linux/nmi.h:58
[inline]
[<ffffffff81364c84>] check_hung_task kernel/hung_task.c:125 [inline]
[<ffffffff81364c84>] check_hung_uninterruptible_tasks
kernel/hung_task.c:182 [inline]
[<ffffffff81364c84>] watchdog+0x6b4/0xa20 kernel/hung_task.c:239
[<ffffffff8119ad5d>] kthread+0x26d/0x300 kernel/kthread.c:211
[<ffffffff839f34dc>] ret_from_fork+0x5c/0x70 arch/x86/entry/entry_64.S:373
Sending NMI from CPU 0 to CPUs 1:
NMI backtrace for cpu 1
CPU: 1 PID: 3868 Comm: syz-executor091 Not tainted 4.9.96-g320d53a #7
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
task: ffff8801d86b6000 task.stack: ffff8801c9f50000
RIP: 0010:[<ffffffff8135ca04>] c [<ffffffff8135ca04>]
__sanitizer_cov_trace_pc+0x4/0x50 kernel/kcov.c:93
RSP: 0018:ffff8801c9f57898 EFLAGS: 00000292
RAX: fffffff74ca39964 RBX: ffffc900008d9000 RCX: 0000000000000002
RDX: 0000000000000000 RSI: ffffffff82118628 RDI: ffffc900008daa22
RBP: ffff8801c9f57898 R08: ffff8801d86b6938 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: 00000008b35c67c3
R13: 0000000000000127 R14: dffffc0000000000 R15: 00000008b35c67c3
FS: 0000000002611880(0000) GS:ffff8801db300000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f3b27467000 CR3: 00000001da3c2000 CR4: 0000000000160670
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Stack:
ffff8801c9f57910 c ffffffff8211863f c ffffc900008db270 c 0000000000001103 c
ffffc900008db278 c ffffed003afe3d35 c ffff8801d7f1e9ac c ffffc900008d9020 c
0000000000001f00 c ffff8801d7f1e600 c ffffc900008d9000 c ffff8801d7f1e600 c
Call Trace:
[<ffffffff8211863f>] echo_buf drivers/tty/n_tty.c:146 [inline]
[<ffffffff8211863f>] __process_echoes+0x5cf/0x780 drivers/tty/n_tty.c:734
[<ffffffff82119f87>] commit_echoes+0x147/0x1b0 drivers/tty/n_tty.c:766
[<ffffffff8211f1e4>] n_tty_receive_char_special+0xd64/0x2860
drivers/tty/n_tty.c:1286
[<ffffffff82122c2a>] n_tty_receive_buf_fast drivers/tty/n_tty.c:1579
[inline]
[<ffffffff82122c2a>] __receive_buf drivers/tty/n_tty.c:1613 [inline]
[<ffffffff82122c2a>] n_tty_receive_buf_common+0x18ea/0x2300
drivers/tty/n_tty.c:1711
[<ffffffff821236b0>] n_tty_receive_buf+0x30/0x40 drivers/tty/n_tty.c:1740
[<ffffffff82113aef>] tiocsti drivers/tty/tty_io.c:2314 [inline]
[<ffffffff82113aef>] tty_ioctl+0xc8f/0x2270 drivers/tty/tty_io.c:2905
[<ffffffff815b051c>] vfs_ioctl fs/ioctl.c:43 [inline]
[<ffffffff815b051c>] file_ioctl fs/ioctl.c:493 [inline]
[<ffffffff815b051c>] do_vfs_ioctl+0x1ac/0x11a0 fs/ioctl.c:677
[<ffffffff815b159f>] SYSC_ioctl fs/ioctl.c:694 [inline]
[<ffffffff815b159f>] SyS_ioctl+0x8f/0xc0 fs/ioctl.c:685
[<ffffffff81006316>] do_syscall_64+0x1a6/0x490 arch/x86/entry/common.c:282
[<ffffffff839f3313>] entry_SYSCALL_64_after_swapgs+0x5d/0xdb
Code: c4c c89 cff ce8 c3f ccb c1d c00 ce9 c5f cff cff cff c48
c89 cdf ce8 c92 cca c1d c00 ce9 cf9 cfe cff cff c66 c2e c0f
c1f c84 c00 c00 c00 c00 c00 c0f c1f c00 c55 c48 c89 ce5
c<65> c48 c8b c04 c25 c40 c7d c01 c00 c65 c8b c15 cbc cb2
ccb c7e c81 ce2 c00 c01 c1f c


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this bug, for details see:
https://goo.gl/tpsmEJ#testing-patches
Reply all
Reply to author
Forward
0 new messages