INFO: task hung in vfs_setxattr

6 views
Skip to first unread message

syzbot

unread,
Aug 17, 2019, 11:36:12 AM8/17/19
to syzkaller-a...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 62872f95 Merge 4.4.174 into android-4.4
git tree: android-4.4
console output: https://syzkaller.appspot.com/x/log.txt?x=138953ba600000
kernel config: https://syzkaller.appspot.com/x/.config?x=47bc4dd423780c4a
dashboard link: https://syzkaller.appspot.com/bug?extid=aa4413c9364897d739b4
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=15d9cbee600000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=171c5c4c600000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+aa4413...@syzkaller.appspotmail.com

INFO: task restorecond:1982 blocked for more than 140 seconds.
Not tainted 4.4.174+ #4
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
restorecond D ffff8800b8077ac8 28288 1982 1 0x00000000
ffff8800b8077ac8 ffff8801d64faf80 f3da8355e7d7ceee ffff8801d64faf80
0000000000000001 ffff8801d64fb800 ffff8801db71f180 ffff8801db71f1a8
ffff8801db71e898 ffff8801da6897c0 ffff8801d64faf80 ffffed001700e001
Call Trace:
[<ffffffff82709b79>] schedule+0x99/0x1d0 kernel/sched/core.c:3355
[<ffffffff8270a333>] schedule_preempt_disabled+0x13/0x20
kernel/sched/core.c:3388
[<ffffffff8270c492>] __mutex_lock_common kernel/locking/mutex.c:582
[inline]
[<ffffffff8270c492>] mutex_lock_nested+0x3c2/0xb80
kernel/locking/mutex.c:621
[<ffffffff8150d753>] vfs_setxattr+0x93/0xf0 fs/xattr.c:132
[<ffffffff8150d974>] setxattr+0x1c4/0x390 fs/xattr.c:358
[<ffffffff8150dc95>] path_setxattr+0x155/0x170 fs/xattr.c:379
[<ffffffff8150e148>] SYSC_lsetxattr fs/xattr.c:401 [inline]
[<ffffffff8150e148>] SyS_lsetxattr+0x38/0x50 fs/xattr.c:397
[<ffffffff82718ba1>] entry_SYSCALL_64_fastpath+0x1e/0x9a
2 locks held by restorecond/1982:
#0: (sb_writers#4){.+.+.+}, at: [<ffffffff814fcd3f>] sb_start_write
include/linux/fs.h:1517 [inline]
#0: (sb_writers#4){.+.+.+}, at: [<ffffffff814fcd3f>]
mnt_want_write+0x3f/0xb0 fs/namespace.c:391
#1: (&sb->s_type->i_mutex_key#9){+.+.+.}, at: [<ffffffff8150d753>]
vfs_setxattr+0x93/0xf0 fs/xattr.c:132
Sending NMI to all CPUs:
NMI backtrace for cpu 0
CPU: 0 PID: 2166 Comm: syz-executor906 Not tainted 4.4.174+ #4
task: ffff8800b4c6af80 task.stack: ffff8801d23b8000
RIP: 0010:[<ffffffff81206788>] [<ffffffff81206788>] get_current
arch/x86/include/asm/current.h:14 [inline]
RIP: 0010:[<ffffffff81206788>] [<ffffffff81206788>]
lock_release+0x528/0xcf0 kernel/locking/lockdep.c:3613
RSP: 0018:ffff8801d23bfb20 EFLAGS: 00000046
RAX: ffff8800b4c6af80 RBX: 0000000000000278 RCX: 0000000000000001
RDX: 1ffff1001698d708 RSI: 0000000000000001 RDI: ffff8800b4c6b838
RBP: ffff8801d23bfbd0 R08: 0000000000000001 R09: 0000000000000001
R10: 0000000000000000 R11: 0000000000000000 R12: dffffc0000000000
R13: ffff8800b4c6b848 R14: 0000000000000001 R15: ffff8800b4c6b892
FS: 0000000001f16880(0063) GS:ffff8801db600000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000001c86308 CR3: 00000001d2887000 CR4: 00000000001606b0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Stack:
ffff8800b4c6af80 ffff8801d6fc1e08 0000000000000000 0000000000000000
0000000000000002 ffff8801d23bfbc8 0000000000000246 0000000000000000
ffffffff81744b91 ffff8800b4c6b840 0000000100000000 ffff8800b4c6b848
Call Trace:
[<ffffffff8271839b>] __raw_read_unlock include/linux/rwlock_api_smp.h:225
[inline]
[<ffffffff8271839b>] _raw_read_unlock+0x1b/0x50
kernel/locking/spinlock.c:255
[<ffffffff81744e45>] ext4_es_lookup_extent+0x365/0xc30
fs/ext4/extents_status.c:833
[<ffffffff8164b026>] ext4_map_blocks+0x156/0x16f0 fs/ext4/inode.c:492
[<ffffffff81634dcb>] ext4_seek_data fs/ext4/file.c:576 [inline]
[<ffffffff81634dcb>] ext4_llseek+0x68b/0x970 fs/ext4/file.c:717
[<ffffffff81497af3>] vfs_llseek fs/read_write.c:260 [inline]
[<ffffffff81497af3>] SYSC_lseek fs/read_write.c:285 [inline]
[<ffffffff81497af3>] SyS_lseek+0x113/0x180 fs/read_write.c:276
[<ffffffff82718ba1>] entry_SYSCALL_64_fastpath+0x1e/0x9a
Code: 00 00 8b 05 1b 13 e5 02 85 c0 75 1f 48 c7 c1 a0 ef 84 82 48 c7 c2 a0
bd 84 82 be 7b 0d 00 00 48 c7 c7 20 bd 84 82 e8 08 d1 ec ff <65> 48 8b 1c
25 80 67 01 00 48 8d bb c4 08 00 00 48 b8 00 00 00
NMI backtrace for cpu 1
CPU: 1 PID: 20 Comm: khungtaskd Not tainted 4.4.174+ #4
task: ffff8801da6f4740 task.stack: ffff8800001d0000
RIP: 0010:[<ffffffff8109b617>] [<ffffffff8109b617>] _flat_send_IPI_mask
arch/x86/kernel/apic/apic_flat_64.c:62 [inline]
RIP: 0010:[<ffffffff8109b617>] [<ffffffff8109b617>]
flat_send_IPI_mask+0xf7/0x1b0 arch/x86/kernel/apic/apic_flat_64.c:69
RSP: 0018:ffff8800001d7c88 EFLAGS: 00000046
RAX: 0000000000000000 RBX: 0000000000000c00 RCX: 0000000000000000
RDX: 0000000000000c00 RSI: 0000000000000000 RDI: ffffffffff5fc300
RBP: ffff8800001d7cb8 R08: 0000000000000018 R09: 0000000000000000
R10: 0000000000000001 R11: 0000000000000001 R12: 0000000000000246
R13: 0000000003000000 R14: ffffffff82e5f2e0 R15: 0000000000000002
FS: 0000000000000000(0000) GS:ffff8801db700000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000001c863e0 CR3: 00000000b923a000 CR4: 00000000001606b0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Stack:
0000000000000001 ffffffff82e5f2e0 ffffffff831a6ac0 fffffbfff0634c34
000000000001b6c0 0000000000000008 ffff8800001d7cd8 ffffffff81092bee
0000000000000008 ffffffff82924260 ffff8800001d7d30 ffffffff81ab8252
Call Trace:
[<ffffffff81092bee>] nmi_raise_cpu_backtrace+0x5e/0x80
arch/x86/kernel/apic/hw_nmi.c:33
[<ffffffff81ab8252>] nmi_trigger_all_cpu_backtrace.cold+0xa1/0xae
lib/nmi_backtrace.c:85
[<ffffffff81092ca4>] arch_trigger_all_cpu_backtrace+0x14/0x20
arch/x86/kernel/apic/hw_nmi.c:38
[<ffffffff813b4762>] trigger_all_cpu_backtrace include/linux/nmi.h:44
[inline]
[<ffffffff813b4762>] check_hung_task kernel/hung_task.c:125 [inline]
[<ffffffff813b4762>] check_hung_uninterruptible_tasks
kernel/hung_task.c:182 [inline]
[<ffffffff813b4762>] watchdog.cold+0xd3/0xee kernel/hung_task.c:238
[<ffffffff811342c3>] kthread+0x273/0x310 kernel/kthread.c:211
[<ffffffff82718fc5>] ret_from_fork+0x55/0x80 arch/x86/entry/entry_64.S:537
Code: 00 c3 5f ff 80 e6 10 75 e1 41 c1 e5 18 44 89 2c 25 10 c3 5f ff 44 89
fa 09 da 80 cf 04 41 83 ff 02 0f 44 d3 89 14 25 00 c3 5f ff <41> f7 c4 00
02 00 00 75 1e 4c 89 e7 57 9d 0f 1f 44 00 00 e8 f1


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this bug, for details see:
https://goo.gl/tpsmEJ#testing-patches
Reply all
Reply to author
Forward
0 new messages