INFO: task hung in rwsem_down_read_failed

163 views
Skip to first unread message

syzbot

unread,
Apr 12, 2019, 8:00:37 PM4/12/19
to syzkaller-a...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 25063787
git tree: android-4.9
console output: https://syzkaller.appspot.com/x/log.txt?x=1605e091800000
kernel config: https://syzkaller.appspot.com/x/.config?x=4fadd453521adb
dashboard link: https://syzkaller.appspot.com/bug?extid=96832b259ab02bab18ef
compiler: gcc (GCC) 7.1.1 20170620
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1015237e800000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=16e1937e800000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+96832b...@syzkaller.appspotmail.com

INFO: task kworker/u4:0:6 blocked for more than 120 seconds.
Not tainted 4.9.71-g2506378 #113
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
kworker/u4:0 D26384 6 2 0x00000000
Workqueue: events_unbound flush_to_ldisc
ffff8801da290000 ffff8801c50d7480 ffff8801c50d7480 ffff8801c3b70000
ffff8801db221458 ffff8801da29f850 ffffffff8389e00b ffff8801da29f828
ffffffff8123940f 00ffffff838a997a ffff8801db221d28 ffff8801db221d50
Call Trace:
[<ffffffff8389f5af>] schedule+0x7f/0x1b0 kernel/sched/core.c:3550
[<ffffffff838a9a90>] rwsem_down_read_failed+0x1e0/0x320
kernel/locking/rwsem-xadd.c:260
[<ffffffff81dc5448>] call_rwsem_down_read_failed+0x18/0x30
arch/x86/lib/rwsem.S:94
[<ffffffff838a8812>] __down_read arch/x86/include/asm/rwsem.h:65 [inline]
[<ffffffff838a8812>] down_read+0x52/0xb0 kernel/locking/rwsem.c:24


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this bug, for details see:
https://goo.gl/tpsmEJ#testing-patches

syzbot

unread,
Apr 12, 2019, 8:00:48 PM4/12/19
to syzkaller-a...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 610c8356
git tree: android-4.4
console output: https://syzkaller.appspot.com/x/log.txt?x=161edf91800000
kernel config: https://syzkaller.appspot.com/x/.config?x=44509e3077d6939
dashboard link: https://syzkaller.appspot.com/bug?extid=a5a16cefc94323a8dab5
compiler: gcc (GCC) 7.1.1 20170620
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=124983d1800000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=17c2f6b1800000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+a5a16c...@syzkaller.appspotmail.com

INFO: task syzkaller001243:3402 blocked for more than 120 seconds.
Not tainted 4.4.107-g610c835 #12
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syzkaller001243 D ffff8801cfd16bf8 24552 3402 3400 0x00000002
ffff8801cfd16bf8 dffffc0000000000 ffff8800b37e8870 ffff8801cfd16bd8
ffffffff8123364f ffff8800b37e8800 ffff8801db21f878 ffff8801db21f8a0
ffff8801db21ef98 ffff8801cff45f00 ffff8800b37e8000 ffff8801cfd10000
Call Trace:
[<ffffffff83765d3a>] schedule+0x9a/0x1c0 kernel/sched/core.c:3351
[<ffffffff8376ffef>] rwsem_down_read_failed+0x1bf/0x300
kernel/locking/rwsem-xadd.c:250
[<ffffffff81d34e44>] call_rwsem_down_read_failed+0x14/0x30
arch/x86/lib/rwsem.S:90
[<ffffffff82d2fd55>] deliver_to_subscribers
sound/core/seq/seq_clientmgr.c:679 [inline]
[<ffffffff82d2fd55>] snd_seq_deliver_event+0x4d5/0x740
sound/core/seq/seq_clientmgr.c:820
[<ffffffff82d30d1e>] snd_seq_kernel_client_dispatch+0x11e/0x150
sound/core/seq/seq_clientmgr.c:2404
[<ffffffff82d55495>] dummy_input+0x235/0x320 sound/core/seq/seq_dummy.c:104
[<ffffffff82d2f3d0>] snd_seq_deliver_single_event.constprop.11+0x310/0x7c0
sound/core/seq/seq_clientmgr.c:634
[<ffffffff82d2fb96>] deliver_to_subscribers
sound/core/seq/seq_clientmgr.c:689 [inline]
[<ffffffff82d2fb96>] snd_seq_deliver_event+0x316/0x740
sound/core/seq/seq_clientmgr.c:820
[<ffffffff82d30d1e>] snd_seq_kernel_client_dispatch+0x11e/0x150
sound/core/seq/seq_clientmgr.c:2404
[<ffffffff82d55495>] dummy_input+0x235/0x320 sound/core/seq/seq_dummy.c:104
[<ffffffff82d2f3d0>] snd_seq_deliver_single_event.constprop.11+0x310/0x7c0
sound/core/seq/seq_clientmgr.c:634
[<ffffffff82d2fb96>] deliver_to_subscribers
sound/core/seq/seq_clientmgr.c:689 [inline]
[<ffffffff82d2fb96>] snd_seq_deliver_event+0x316/0x740
sound/core/seq/seq_clientmgr.c:820
[<ffffffff82d30d1e>] snd_seq_kernel_client_dispatch+0x11e/0x150
sound/core/seq/seq_clientmgr.c:2404
[<ffffffff82d55495>] dummy_input+0x235/0x320 sound/core/seq/seq_dummy.c:104
[<ffffffff82d2f3d0>] snd_seq_deliver_single_event.constprop.11+0x310/0x7c0
sound/core/seq/seq_clientmgr.c:634
[<ffffffff82d2fb96>] deliver_to_subscribers
sound/core/seq/seq_clientmgr.c:689 [inline]
[<ffffffff82d2fb96>] snd_seq_deliver_event+0x316/0x740
sound/core/seq/seq_clientmgr.c:820
[<ffffffff82d30d1e>] snd_seq_kernel_client_dispatch+0x11e/0x150
sound/core/seq/seq_clientmgr.c:2404
[<ffffffff82d55495>] dummy_input+0x235/0x320 sound/core/seq/seq_dummy.c:104
[<ffffffff82d2f3d0>] snd_seq_deliver_single_event.constprop.11+0x310/0x7c0
sound/core/seq/seq_clientmgr.c:634
[<ffffffff82d2f9ad>] snd_seq_deliver_event+0x12d/0x740
sound/core/seq/seq_clientmgr.c:831
[<ffffffff82d30d1e>] snd_seq_kernel_client_dispatch+0x11e/0x150
sound/core/seq/seq_clientmgr.c:2404
[<ffffffff82d51bd0>] snd_seq_oss_dispatch
sound/core/seq/oss/seq_oss_device.h:150 [inline]
[<ffffffff82d51bd0>] snd_seq_oss_midi_reset+0x390/0x570
sound/core/seq/oss/seq_oss_midi.c:481
[<ffffffff82d4e000>] snd_seq_oss_synth_reset+0x3c0/0x8b0
sound/core/seq/oss/seq_oss_synth.c:416
[<ffffffff82d44a6c>] snd_seq_oss_reset+0x6c/0x260
sound/core/seq/oss/seq_oss_init.c:448
[<ffffffff82d44cd1>] snd_seq_oss_release+0x71/0x130
sound/core/seq/oss/seq_oss_init.c:425
[<ffffffff82d434e2>] odev_release+0x52/0x70
sound/core/seq/oss/seq_oss.c:152
[<ffffffff81521163>] __fput+0x233/0x6d0 fs/file_table.c:208
[<ffffffff81521685>] ____fput+0x15/0x20 fs/file_table.c:244
[<ffffffff811890a4>] task_work_run+0x104/0x180 kernel/task_work.c:115
[<ffffffff811304a1>] exit_task_work include/linux/task_work.h:21 [inline]
[<ffffffff811304a1>] do_exit+0x871/0x2a20 kernel/exit.c:755
[<ffffffff81136918>] do_group_exit+0x108/0x320 kernel/exit.c:885
[<ffffffff81136b4d>] SYSC_exit_group kernel/exit.c:896 [inline]
[<ffffffff81136b4d>] SyS_exit_group+0x1d/0x20 kernel/exit.c:894
[<ffffffff83773d36>] entry_SYSCALL_64_fastpath+0x16/0x76
5 locks held by syzkaller001243/3402:
#0: (register_mutex#4){+.+.+.}, at: [<ffffffff82d434da>]
odev_release+0x4a/0x70 sound/core/seq/oss/seq_oss.c:151
#1: (&grp->list_mutex#2/2){.+.+..}, at: [<ffffffff82d2fd55>]
deliver_to_subscribers sound/core/seq/seq_clientmgr.c:679 [inline]
#1: (&grp->list_mutex#2/2){.+.+..}, at: [<ffffffff82d2fd55>]
snd_seq_deliver_event+0x4d5/0x740 sound/core/seq/seq_clientmgr.c:820
#2: (&grp->list_mutex#2/3){.+.+..}, at: [<ffffffff82d2fd55>]
deliver_to_subscribers sound/core/seq/seq_clientmgr.c:679 [inline]
#2: (&grp->list_mutex#2/3){.+.+..}, at: [<ffffffff82d2fd55>]
snd_seq_deliver_event+0x4d5/0x740 sound/core/seq/seq_clientmgr.c:820
#3: (&grp->list_mutex#2/4){.+.+..}, at: [<ffffffff82d2fd55>]
deliver_to_subscribers sound/core/seq/seq_clientmgr.c:679 [inline]
#3: (&grp->list_mutex#2/4){.+.+..}, at: [<ffffffff82d2fd55>]
snd_seq_deliver_event+0x4d5/0x740 sound/core/seq/seq_clientmgr.c:820
#4: (&grp->list_mutex#2/5){.+.+..}, at: [<ffffffff82d2fd55>]
deliver_to_subscribers sound/core/seq/seq_clientmgr.c:679 [inline]
#4: (&grp->list_mutex#2/5){.+.+..}, at: [<ffffffff82d2fd55>]
snd_seq_deliver_event+0x4d5/0x740 sound/core/seq/seq_clientmgr.c:820
Sending NMI to all CPUs:
NMI backtrace for cpu 0
CPU: 0 PID: 485 Comm: khungtaskd Not tainted 4.4.107-g610c835 #12
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
task: ffff8800bb220000 task.stack: ffff8800bac10000
RIP: 0010:[<ffffffff810c32e7>] [<ffffffff810c32e7>] native_apic_mem_write
arch/x86/include/asm/apic.h:94 [inline]
RIP: 0010:[<ffffffff810c32e7>] [<ffffffff810c32e7>]
__default_send_IPI_dest_field arch/x86/include/asm/ipi.h:119 [inline]
RIP: 0010:[<ffffffff810c32e7>] [<ffffffff810c32e7>] _flat_send_IPI_mask
arch/x86/kernel/apic/apic_flat_64.c:61 [inline]
RIP: 0010:[<ffffffff810c32e7>] [<ffffffff810c32e7>]
flat_send_IPI_mask+0xf7/0x1a0 arch/x86/kernel/apic/apic_flat_64.c:69
RSP: 0018:ffff8800bac17cb8 EFLAGS: 00000046
RAX: 0000000003000000 RBX: 0000000000000c00 RCX: 0000000000000000
RDX: 0000000000000c00 RSI: 0000000000000000 RDI: ffffffffff5fb300
RBP: ffff8800bac17ce0 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000001 R12: 0000000000000246
R13: 0000000000000003 R14: ffffffff8426abe0 R15: 0000000000000002
FS: 0000000000000000(0000) GS:ffff8801db200000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f58ddb3a000 CR3: 00000001d4022000 CR4: 00000000001406f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Stack:
ffffffff8426abe0 ffffffff847e8600 00000000000194a0 0000000000000040
dffffc0000000000 ffff8800bac17d00 ffffffff810b8e1b ffffffff839f53e0
0000000000000003 ffff8800bac17d60 ffffffff81d0f4d7 ffffffff81417c73
Call Trace:
[<ffffffff810b8e1b>] nmi_raise_cpu_backtrace+0x5b/0x70
arch/x86/kernel/apic/hw_nmi.c:33
[<ffffffff81d0f4d7>] nmi_trigger_all_cpu_backtrace+0x4a7/0x550
lib/nmi_backtrace.c:85
[<ffffffff810b8eb4>] arch_trigger_all_cpu_backtrace+0x14/0x20
arch/x86/kernel/apic/hw_nmi.c:38
[<ffffffff81365a7a>] trigger_all_cpu_backtrace include/linux/nmi.h:44
[inline]
[<ffffffff81365a7a>] check_hung_task kernel/hung_task.c:125 [inline]
[<ffffffff81365a7a>] check_hung_uninterruptible_tasks
kernel/hung_task.c:182 [inline]
[<ffffffff81365a7a>] watchdog+0x6fa/0xae0 kernel/hung_task.c:238
[<ffffffff8118dea8>] kthread+0x268/0x300 kernel/kthread.c:211
[<ffffffff837740ef>] ret_from_fork+0x3f/0x70 arch/x86/entry/entry_64.S:468
Code: b3 5f ff f6 c4 10 75 e1 44 89 e8 c1 e0 18 89 04 25 10 b3 5f ff 44 89
fa 09 da 80 cf 04 41 83 ff 02 0f 44 d3 89 14 25 00 b3 5f ff <41> f7 c4 00
02 00 00 74 1a e8 3b 09 17 00 4c 89 e7 57 9d 0f 1f
NMI backtrace for cpu 1
CPU: 1 PID: 0 Comm: swapper/1 Not tainted 4.4.107-g610c835 #12
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
task: ffff8801da2997c0 task.stack: ffff8801da2a8000
RIP: 0010:[<ffffffff810cf516>] [<ffffffff810cf516>]
native_safe_halt+0x6/0x10 arch/x86/include/asm/irqflags.h:49
RSP: 0018:ffff8801da2afd78 EFLAGS: 00000246
RAX: 0000000000000007 RBX: ffffffff847d6708 RCX: 0000000000000000
RDX: 0000000000000000 RSI: 0000000000000001 RDI: ffff8801da29a02c
RBP: ffff8801da2afd78 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000001
R13: 0000000000000000 R14: 0000000000000000 R15: dffffc0000000000
FS: 0000000000000000(0000) GS:ffff8801db300000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000000000207a000 CR3: 00000001d4022000 CR4: 00000000001406e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Stack:
ffff8801da2afdb0 ffffffff81027d75 ffff8801da2b0000 ffffffff847d6708
0000000000000000 0000000000000000 dffffc0000000000 ffff8801da2afdc0
ffffffff810292ea ffff8801da2afdd8 ffffffff8121e338 ffff8801da2b0000
Call Trace:
[<ffffffff81027d75>] arch_safe_halt arch/x86/include/asm/paravirt.h:117
[inline]
[<ffffffff81027d75>] default_idle+0x55/0x3c0 arch/x86/kernel/process.c:291
[<ffffffff810292ea>] arch_cpu_idle+0xa/0x10 arch/x86/kernel/process.c:282
[<ffffffff8121e338>] default_idle_call+0x48/0x70 kernel/sched/idle.c:93
[<ffffffff8121ea45>] cpuidle_idle_call kernel/sched/idle.c:157 [inline]
[<ffffffff8121ea45>] cpu_idle_loop kernel/sched/idle.c:253 [inline]
[<ffffffff8121ea45>] cpu_startup_entry+0x605/0x820 kernel/sched/idle.c:301
[<ffffffff810ad2e4>] start_secondary+0x304/0x3e0
arch/x86/kernel/smpboot.c:251
Code: 00 00 00 00 00 55 48 89 e5 fa 5d c3 66 0f 1f 84 00 00 00 00 00 55 48
89 e5 fb 5d c3 66 0f 1f 84 00 00 00 00 00 55 48 89 e5 fb f4 <5d> c3 0f 1f
84 00 00 00 00 00 55 48 89 e5 f4 5d c3 66 0f 1f 84
Reply all
Reply to author
Forward
0 new messages