INFO: task hung in bit_wait_io

54 views
Skip to first unread message

syzbot

unread,
Apr 12, 2019, 8:00:34 PM4/12/19
to syzkaller-a...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: aa856bd8 Merge 4.4.115 into android-4.4
git tree: android-4.4
console output: https://syzkaller.appspot.com/x/log.txt?x=162f8305800000
kernel config: https://syzkaller.appspot.com/x/.config?x=58e89c40ea7f5c9c
dashboard link: https://syzkaller.appspot.com/bug?extid=ba5f9d3537aeadbb83d6
compiler: gcc (GCC) 7.1.1 20170620
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=15feba65800000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=166d26e5800000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+ba5f9d...@syzkaller.appspotmail.com

binder: 11099:11099 transaction failed 29189/-3, size 0-0 line 3128
binder: BINDER_SET_CONTEXT_MGR already set
binder: 11101:11101 ioctl 40046207 0 returned -16
binder_alloc: 3902: binder_alloc_buf, no vma
binder: 11101:11101 transaction failed 29189/-3, size 0-0 line 3128
INFO: task jbd2/sda1-8:1866 blocked for more than 120 seconds.
Not tainted 4.4.115-gaa856bd #6
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
jbd2/sda1-8 D ffff8801d3b3f580 26632 1866 2 0x00000000
ffff8801d3b3f580 0000000000000000 0000000000000002 0000000000000000
ffff8801d3b3f5a8 0000000000000200 ffff8801db31fdb8 ffff8801db31fde0
ffff8801db31f4d8 ffff8801d9b4e000 ffff8801d3a98000 0000000000000000
Call Trace:
[<ffffffff837662da>] schedule+0x7a/0x1b0 kernel/sched/core.c:3353
[<ffffffff837715f0>] schedule_timeout+0x3a0/0x970 kernel/time/timer.c:1515
[<ffffffff8376426e>] io_schedule_timeout+0x1be/0x390
kernel/sched/core.c:4935
[<ffffffff8376759b>] io_schedule include/linux/sched.h:447 [inline]
[<ffffffff8376759b>] bit_wait_io+0x1b/0xc0 kernel/sched/wait.c:595
[<ffffffff83766cdc>] __wait_on_bit+0x8c/0x140 kernel/sched/wait.c:395
[<ffffffff83766e80>] out_of_line_wait_on_bit+0xf0/0x130
kernel/sched/wait.c:408
[<ffffffff815c5ccc>] wait_on_bit_io include/linux/wait.h:1015 [inline]
[<ffffffff815c5ccc>] __wait_on_buffer+0x5c/0x70 fs/buffer.c:123
[<ffffffff8181df41>] wait_on_buffer include/linux/buffer_head.h:342
[inline]
[<ffffffff8181df41>] journal_wait_on_commit_record fs/jbd2/commit.c:178
[inline]
[<ffffffff8181df41>] jbd2_journal_commit_transaction+0x33b1/0x64e0
fs/jbd2/commit.c:895
[<ffffffff8182e4fa>] kjournald2+0x22a/0x840 fs/jbd2/journal.c:223
[<ffffffff811907e8>] kthread+0x268/0x300 kernel/kthread.c:211
[<ffffffff83774845>] ret_from_fork+0x55/0x80 arch/x86/entry/entry_64.S:506
INFO: lockdep is turned off.
Sending NMI to all CPUs:
NMI backtrace for cpu 0
CPU: 0 PID: 332 Comm: kworker/u4:3 Not tainted 4.4.115-gaa856bd #6
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
Workqueue: binder binder_deferred_func
task: ffff8801d9213000 task.stack: ffff8801d9268000
RIP: 0010:[<ffffffff81f84a4b>] [<ffffffff81f84a4b>] inb
arch/x86/include/asm/io.h:316 [inline]
RIP: 0010:[<ffffffff81f84a4b>] [<ffffffff81f84a4b>] io_serial_in+0x6b/0x90
drivers/tty/serial/8250/8250_port.c:398
RSP: 0018:ffff8801d926f708 EFLAGS: 00000002
RAX: dffffc0000000000 RBX: 00000000000003fd RCX: 0000000000000000
RDX: 00000000000003fd RSI: 0000000000000005 RDI: ffffffff8607a878
RBP: ffff8801d926f718 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000000001 R11: fffffbfff0ad7e33 R12: ffffffff8607a840
R13: 0000000000000060 R14: fffffbfff0c0f54f R15: fffffbfff0c0f511
FS: 0000000000000000(0000) GS:ffff8801db200000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000020008ff3 CR3: 000000000420c000 CR4: 0000000000160670
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Stack:
ffffffff8607a840 0000000000002710 ffff8801d926f768 ffffffff81f86649
ffff8801d926f768 ffffffff8607a888 ffffffff8607aa7a ffffffff8607a840
1ffff1003b24def6 0000000000000000 ffff8801d926f870 ffffffff8607a888
Call Trace:
[<ffffffff81f86649>] serial_in drivers/tty/serial/8250/8250.h:97 [inline]
[<ffffffff81f86649>] wait_for_xmitr+0x89/0x1d0
drivers/tty/serial/8250/8250_port.c:1717
[<ffffffff81f905fd>] serial8250_console_write+0x2ed/0x860
drivers/tty/serial/8250/8250_port.c:2878
[<ffffffff81f7f794>] univ8250_console_write+0x64/0x80
drivers/tty/serial/8250/8250_core.c:594
[<ffffffff81266fdc>] call_console_drivers.constprop.26+0x1ec/0x3e0
kernel/printk/printk.c:1463
[<ffffffff81269b84>] console_unlock+0x534/0xa00 kernel/printk/printk.c:2330
[<ffffffff8126a5ae>] vprintk_emit+0x55e/0x850 kernel/printk/printk.c:1832
[<ffffffff8126a8c8>] vprintk+0x28/0x30 kernel/printk/printk.c:1843
[<ffffffff8126a8ed>] vprintk_default+0x1d/0x30 kernel/printk/printk.c:1844
[<ffffffff8141b91d>] printk+0xb7/0xe2 kernel/printk/printk.c:1922
[<ffffffff82c76978>] binder_release_work+0x148/0x260
drivers/android/binder.c:4373
[<ffffffff82c76d05>] binder_thread_release+0x275/0x540
drivers/android/binder.c:4543
[<ffffffff82c7ba68>] binder_deferred_release drivers/android/binder.c:5082
[inline]
[<ffffffff82c7ba68>] binder_deferred_func+0x438/0xd10
drivers/android/binder.c:5154
[<ffffffff8117fd97>] process_one_work+0x7d7/0x16e0 kernel/workqueue.c:2064
[<ffffffff81180d79>] worker_thread+0xd9/0xfc0 kernel/workqueue.c:2196
[<ffffffff811907e8>] kthread+0x268/0x300 kernel/kthread.c:211
[<ffffffff83774845>] ret_from_fork+0x55/0x80 arch/x86/entry/entry_64.S:506
Code: 24 c1 00 00 00 49 8d 7c 24 38 48 b8 00 00 00 00 00 fc ff df 48 89 fa
48 c1 ea 03 d3 e3 80 3c 02 00 75 17 41 03 5c 24 38 89 da ec <5b> 0f b6 c0
41 5c 5d c3 e8 88 9d 57 ff eb c2 e8 e1 9d 57 ff eb
NMI backtrace for cpu 1
CPU: 1 PID: 486 Comm: khungtaskd Not tainted 4.4.115-gaa856bd #6
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
task: ffff8800bac74800 task.stack: ffff8800bb2f8000
RIP: 0010:[<ffffffff810c3ec7>] [<ffffffff810c3ec7>] native_apic_mem_write
arch/x86/include/asm/apic.h:94 [inline]
RIP: 0010:[<ffffffff810c3ec7>] [<ffffffff810c3ec7>]
__default_send_IPI_dest_field arch/x86/include/asm/ipi.h:119 [inline]
RIP: 0010:[<ffffffff810c3ec7>] [<ffffffff810c3ec7>] _flat_send_IPI_mask
arch/x86/kernel/apic/apic_flat_64.c:61 [inline]
RIP: 0010:[<ffffffff810c3ec7>] [<ffffffff810c3ec7>]
flat_send_IPI_mask+0xf7/0x1a0 arch/x86/kernel/apic/apic_flat_64.c:69
RSP: 0018:ffff8800bb2ffcb8 EFLAGS: 00000046
RAX: 0000000003000000 RBX: 0000000000000c00 RCX: ffffffff8126a292
RDX: 0000000000000c00 RSI: 0000000000000002 RDI: ffffffffff5fb300
RBP: ffff8800bb2ffce0 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000246
R13: 0000000000000003 R14: ffffffff8426f3a0 R15: 0000000000000002
FS: 0000000000000000(0000) GS:ffff8801db300000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f2e00efa1c4 CR3: 00000001b2e0e000 CR4: 0000000000160670
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Stack:
ffffffff8426f3a0 ffffffff847ef7c0 fffffbfff08fd9ac dffffc0000000000
ffff8801db31bca0 ffff8800bb2ffd00 ffffffff810b99fb ffffffff839f61c0
0000000000000003 ffff8800bb2ffd60 ffffffff81d0ed14 0000000000000001
Call Trace:
[<ffffffff810b99fb>] nmi_raise_cpu_backtrace+0x5b/0x70
arch/x86/kernel/apic/hw_nmi.c:33
[<ffffffff81d0ed14>] nmi_trigger_all_cpu_backtrace+0x4a4/0x550
lib/nmi_backtrace.c:85
[<ffffffff810b9a94>] arch_trigger_all_cpu_backtrace+0x14/0x20
arch/x86/kernel/apic/hw_nmi.c:38
[<ffffffff81368cca>] trigger_all_cpu_backtrace include/linux/nmi.h:44
[inline]
[<ffffffff81368cca>] check_hung_task kernel/hung_task.c:125 [inline]
[<ffffffff81368cca>] check_hung_uninterruptible_tasks
kernel/hung_task.c:182 [inline]
[<ffffffff81368cca>] watchdog+0x6fa/0xae0 kernel/hung_task.c:238
[<ffffffff811907e8>] kthread+0x268/0x300 kernel/kthread.c:211
[<ffffffff83774845>] ret_from_fork+0x55/0x80 arch/x86/entry/entry_64.S:506
Code: b3 5f ff f6 c4 10 75 e1 44 89 e8 c1 e0 18 89 04 25 10 b3 5f ff 44 89
fa 09 da 80 cf 04 41 83 ff 02 0f 44 d3 89 14 25 00 b3 5f ff <41> f7 c4 00
02 00 00 74 1a e8 0b 2f 17 00 4c 89 e7 57 9d 0f 1f


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this bug, for details see:
https://goo.gl/tpsmEJ#testing-patches
Reply all
Reply to author
Forward
0 new messages