INFO: task hung in genl_rcv_msg

6 views
Skip to first unread message

syzbot

unread,
Jan 17, 2020, 11:43:10 AM1/17/20
to syzkaller...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: c04fc6fa Linux 4.14.165
git tree: linux-4.14.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1704c669e00000
kernel config: https://syzkaller.appspot.com/x/.config?x=d36f53294bbc71f0
dashboard link: https://syzkaller.appspot.com/bug?extid=35aba01a785cf6164fa4
compiler: gcc (GCC) 9.0.0 20181231 (experimental)

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+35aba0...@syzkaller.appspotmail.com

Dropped {multi|broad}cast of type= [86dd]
Dropped {multi|broad}cast of type= [86dd]
INFO: task syz-executor.4:19070 blocked for more than 140 seconds.
Not tainted 4.14.165-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.4 D28672 19070 7297 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2808 [inline]
__schedule+0x7b8/0x1cd0 kernel/sched/core.c:3384
schedule+0x92/0x1c0 kernel/sched/core.c:3428
schedule_preempt_disabled+0x13/0x20 kernel/sched/core.c:3486
__mutex_lock_common kernel/locking/mutex.c:833 [inline]
__mutex_lock+0x73c/0x1470 kernel/locking/mutex.c:893
mutex_lock_nested+0x16/0x20 kernel/locking/mutex.c:908
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x119/0x150 net/netlink/genetlink.c:623
netlink_rcv_skb+0x14f/0x3c0 net/netlink/af_netlink.c:2432
genl_rcv+0x29/0x40 net/netlink/genetlink.c:636
netlink_unicast_kernel net/netlink/af_netlink.c:1286 [inline]
netlink_unicast+0x44d/0x650 net/netlink/af_netlink.c:1312
netlink_sendmsg+0x7c4/0xc60 net/netlink/af_netlink.c:1877
sock_sendmsg_nosec net/socket.c:646 [inline]
sock_sendmsg+0xce/0x110 net/socket.c:656
___sys_sendmsg+0x70a/0x840 net/socket.c:2062
__sys_sendmsg+0xb9/0x140 net/socket.c:2096
SYSC_sendmsg net/socket.c:2107 [inline]
SyS_sendmsg+0x2d/0x50 net/socket.c:2103
do_syscall_64+0x1e8/0x640 arch/x86/entry/common.c:292
entry_SYSCALL_64_after_hwframe+0x42/0xb7
RIP: 0033:0x414cb1
RSP: 002b:00007fe4ecb329c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007fe4ecb32a58 RCX: 0000000000414cb1
RDX: 0000000000000000 RSI: 00007fe4ecb32a00 RDI: 0000000000000005
RBP: 0000000000000005 R08: 000000000000000b R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000293 R12: 00007fe4ecb32a40
R13: 0000000000000b3e R14: 00000000004d5490 R15: 000000000075bf2c
INFO: task syz-executor.4:19071 blocked for more than 140 seconds.
Not tainted 4.14.165-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.4 D28672 19071 7297 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2808 [inline]
__schedule+0x7b8/0x1cd0 kernel/sched/core.c:3384
schedule+0x92/0x1c0 kernel/sched/core.c:3428
schedule_preempt_disabled+0x13/0x20 kernel/sched/core.c:3486
__mutex_lock_common kernel/locking/mutex.c:833 [inline]
__mutex_lock+0x73c/0x1470 kernel/locking/mutex.c:893
mutex_lock_nested+0x16/0x20 kernel/locking/mutex.c:908
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x119/0x150 net/netlink/genetlink.c:623
netlink_rcv_skb+0x14f/0x3c0 net/netlink/af_netlink.c:2432
genl_rcv+0x29/0x40 net/netlink/genetlink.c:636
netlink_unicast_kernel net/netlink/af_netlink.c:1286 [inline]
netlink_unicast+0x44d/0x650 net/netlink/af_netlink.c:1312
netlink_sendmsg+0x7c4/0xc60 net/netlink/af_netlink.c:1877
sock_sendmsg_nosec net/socket.c:646 [inline]
sock_sendmsg+0xce/0x110 net/socket.c:656
___sys_sendmsg+0x70a/0x840 net/socket.c:2062
__sys_sendmsg+0xb9/0x140 net/socket.c:2096
SYSC_sendmsg net/socket.c:2107 [inline]
SyS_sendmsg+0x2d/0x50 net/socket.c:2103
do_syscall_64+0x1e8/0x640 arch/x86/entry/common.c:292
entry_SYSCALL_64_after_hwframe+0x42/0xb7
RIP: 0033:0x414cb1
RSP: 002b:00007fe4ecb119c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007fe4ecb11a58 RCX: 0000000000414cb1
RDX: 0000000000000000 RSI: 00007fe4ecb11a00 RDI: 0000000000000005
RBP: 0000000000000005 R08: 000000000000000b R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000293 R12: 00007fe4ecb11a40
R13: 0000000000000b3e R14: 00000000004d5490 R15: 000000000075bfd4

Showing all locks held in the system:
1 lock held by khungtaskd/1059:
#0: (tasklist_lock){.+.+}, at: [<ffffffff81489c18>]
debug_show_all_locks+0x7f/0x21f kernel/locking/lockdep.c:4544
2 locks held by getty/7246:
#0: (&tty->ldisc_sem){++++}, at: [<ffffffff866a6243>]
ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:376
#1: (&ldata->atomic_read_lock){+.+.}, at: [<ffffffff834ca396>]
n_tty_read+0x1e6/0x17d0 drivers/tty/n_tty.c:2156
2 locks held by getty/7247:
#0: (&tty->ldisc_sem){++++}, at: [<ffffffff866a6243>]
ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:376
#1: (&ldata->atomic_read_lock){+.+.}, at: [<ffffffff834ca396>]
n_tty_read+0x1e6/0x17d0 drivers/tty/n_tty.c:2156
2 locks held by getty/7248:
#0: (&tty->ldisc_sem){++++}, at: [<ffffffff866a6243>]
ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:376
#1: (&ldata->atomic_read_lock){+.+.}, at: [<ffffffff834ca396>]
n_tty_read+0x1e6/0x17d0 drivers/tty/n_tty.c:2156
2 locks held by getty/7249:
#0: (&tty->ldisc_sem){++++}, at: [<ffffffff866a6243>]
ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:376
#1: (&ldata->atomic_read_lock){+.+.}, at: [<ffffffff834ca396>]
n_tty_read+0x1e6/0x17d0 drivers/tty/n_tty.c:2156
2 locks held by getty/7250:
#0: (&tty->ldisc_sem){++++}, at: [<ffffffff866a6243>]
ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:376
#1: (&ldata->atomic_read_lock){+.+.}, at: [<ffffffff834ca396>]
n_tty_read+0x1e6/0x17d0 drivers/tty/n_tty.c:2156
2 locks held by getty/7251:
#0: (&tty->ldisc_sem){++++}, at: [<ffffffff866a6243>]
ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:376
#1: (&ldata->atomic_read_lock){+.+.}, at: [<ffffffff834ca396>]
n_tty_read+0x1e6/0x17d0 drivers/tty/n_tty.c:2156
2 locks held by getty/7252:
#0: (&tty->ldisc_sem){++++}, at: [<ffffffff866a6243>]
ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:376
#1: (&ldata->atomic_read_lock){+.+.}, at: [<ffffffff834ca396>]
n_tty_read+0x1e6/0x17d0 drivers/tty/n_tty.c:2156
2 locks held by syz-executor.4/19070:
#0: (cb_lock){++++}, at: [<ffffffff853fd56a>] genl_rcv+0x1a/0x40
net/netlink/genetlink.c:635
#1: (genl_mutex){+.+.}, at: [<ffffffff85400db9>] genl_lock
net/netlink/genetlink.c:33 [inline]
#1: (genl_mutex){+.+.}, at: [<ffffffff85400db9>] genl_rcv_msg+0x119/0x150
net/netlink/genetlink.c:623
2 locks held by syz-executor.4/19071:
#0: (cb_lock){++++}, at: [<ffffffff853fd56a>] genl_rcv+0x1a/0x40
net/netlink/genetlink.c:635
#1: (genl_mutex){+.+.}, at: [<ffffffff85400db9>] genl_lock
net/netlink/genetlink.c:33 [inline]
#1: (genl_mutex){+.+.}, at: [<ffffffff85400db9>] genl_rcv_msg+0x119/0x150
net/netlink/genetlink.c:623

=============================================

NMI backtrace for cpu 1
CPU: 1 PID: 1059 Comm: khungtaskd Not tainted 4.14.165-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:17 [inline]
dump_stack+0x142/0x197 lib/dump_stack.c:58
nmi_cpu_backtrace.cold+0x57/0x94 lib/nmi_backtrace.c:101
nmi_trigger_cpumask_backtrace+0x141/0x189 lib/nmi_backtrace.c:62
arch_trigger_cpumask_backtrace+0x14/0x20 arch/x86/kernel/apic/hw_nmi.c:38
trigger_all_cpu_backtrace include/linux/nmi.h:140 [inline]
check_hung_uninterruptible_tasks kernel/hung_task.c:195 [inline]
watchdog+0x5e7/0xb90 kernel/hung_task.c:274
kthread+0x319/0x430 kernel/kthread.c:232
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:404
Sending NMI from CPU 1 to CPUs 0:
NMI backtrace for cpu 0
CPU: 0 PID: 7407 Comm: kworker/u4:5 Not tainted 4.14.165-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
Workqueue: bat_events batadv_nc_worker
task: ffff888091064680 task.stack: ffff8880591a0000
RIP: 0010:__lock_acquire+0x53/0x4620 kernel/locking/lockdep.c:3344
RSP: 0018:ffff8880591a7ab0 EFLAGS: 00000806
RAX: 1ffff1100b234f6a RBX: 0000000000000000 RCX: 0000000000000002
RDX: dffffc0000000000 RSI: 0000000000000000 RDI: ffffffff87f872a0
RBP: ffff8880591a7c60 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: ffffffff87f872a0
R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000002
FS: 0000000000000000(0000) GS:ffff8880aec00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000000c424194f40 CR3: 0000000098cf6000 CR4: 00000000001406f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
lock_acquire+0x16f/0x430 kernel/locking/lockdep.c:3994
rcu_lock_acquire include/linux/rcupdate.h:242 [inline]
rcu_read_lock include/linux/rcupdate.h:629 [inline]
batadv_nc_purge_orig_hash net/batman-adv/network-coding.c:416 [inline]
batadv_nc_worker+0x107/0x6d0 net/batman-adv/network-coding.c:726
process_one_work+0x863/0x1600 kernel/workqueue.c:2114
worker_thread+0x5d9/0x1050 kernel/workqueue.c:2248
kthread+0x319/0x430 kernel/kthread.c:232
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:404
Code: 8d 84 24 a0 00 00 00 48 c7 84 24 a0 00 00 00 b3 8a b5 41 48 c7 84 24
a8 00 00 00 e0 76 ad 87 48 c1 e8 03 48 89 84 24 98 00 00 00 <48> 01 d0 48
c7 84 24 b0 00 00 00 d0 14 48 81 c7 00 f1 f1 f1 f1


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Jan 17, 2020, 2:34:09 PM1/17/20
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: c04fc6fa Linux 4.14.165
git tree: linux-4.14.y
console output: https://syzkaller.appspot.com/x/log.txt?x=14847b3ee00000
kernel config: https://syzkaller.appspot.com/x/.config?x=d36f53294bbc71f0
dashboard link: https://syzkaller.appspot.com/bug?extid=35aba01a785cf6164fa4
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=11ee2b3ee00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+35aba0...@syzkaller.appspotmail.com

INFO: task syz-executor.2:26728 blocked for more than 140 seconds.
Not tainted 4.14.165-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.2 D28928 26728 7378 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2808 [inline]
__schedule+0x7b8/0x1cd0 kernel/sched/core.c:3384
schedule+0x92/0x1c0 kernel/sched/core.c:3428
schedule_preempt_disabled+0x13/0x20 kernel/sched/core.c:3486
__mutex_lock_common kernel/locking/mutex.c:833 [inline]
__mutex_lock+0x73c/0x1470 kernel/locking/mutex.c:893
mutex_lock_nested+0x16/0x20 kernel/locking/mutex.c:908
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x119/0x150 net/netlink/genetlink.c:623
netlink_rcv_skb+0x14f/0x3c0 net/netlink/af_netlink.c:2432
genl_rcv+0x29/0x40 net/netlink/genetlink.c:636
netlink_unicast_kernel net/netlink/af_netlink.c:1286 [inline]
netlink_unicast+0x44d/0x650 net/netlink/af_netlink.c:1312
netlink_sendmsg+0x7c4/0xc60 net/netlink/af_netlink.c:1877
sock_sendmsg_nosec net/socket.c:646 [inline]
sock_sendmsg+0xce/0x110 net/socket.c:656
___sys_sendmsg+0x70a/0x840 net/socket.c:2062
__sys_sendmsg+0xb9/0x140 net/socket.c:2096
SYSC_sendmsg net/socket.c:2107 [inline]
SyS_sendmsg+0x2d/0x50 net/socket.c:2103
do_syscall_64+0x1e8/0x640 arch/x86/entry/common.c:292
entry_SYSCALL_64_after_hwframe+0x42/0xb7
RIP: 0033:0x414cb1
RSP: 002b:00007ff78a1099c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007ff78a109a58 RCX: 0000000000414cb1
RDX: 0000000000000000 RSI: 00007ff78a109a00 RDI: 0000000000000006
RBP: 0000000000000006 R08: 000000000000000b R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000293 R12: 00007ff78a109a40
R13: 0000000000000b48 R14: 00000000004d5630 R15: 000000000075bf2c
INFO: task syz-executor.2:26733 blocked for more than 140 seconds.
Not tainted 4.14.165-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.2 D28928 26733 7378 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2808 [inline]
__schedule+0x7b8/0x1cd0 kernel/sched/core.c:3384
schedule+0x92/0x1c0 kernel/sched/core.c:3428
schedule_preempt_disabled+0x13/0x20 kernel/sched/core.c:3486
__mutex_lock_common kernel/locking/mutex.c:833 [inline]
__mutex_lock+0x73c/0x1470 kernel/locking/mutex.c:893
mutex_lock_nested+0x16/0x20 kernel/locking/mutex.c:908
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x119/0x150 net/netlink/genetlink.c:623
netlink_rcv_skb+0x14f/0x3c0 net/netlink/af_netlink.c:2432
genl_rcv+0x29/0x40 net/netlink/genetlink.c:636
netlink_unicast_kernel net/netlink/af_netlink.c:1286 [inline]
netlink_unicast+0x44d/0x650 net/netlink/af_netlink.c:1312
netlink_sendmsg+0x7c4/0xc60 net/netlink/af_netlink.c:1877
sock_sendmsg_nosec net/socket.c:646 [inline]
sock_sendmsg+0xce/0x110 net/socket.c:656
___sys_sendmsg+0x70a/0x840 net/socket.c:2062
__sys_sendmsg+0xb9/0x140 net/socket.c:2096
SYSC_sendmsg net/socket.c:2107 [inline]
SyS_sendmsg+0x2d/0x50 net/socket.c:2103
do_syscall_64+0x1e8/0x640 arch/x86/entry/common.c:292
entry_SYSCALL_64_after_hwframe+0x42/0xb7
RIP: 0033:0x414cb1
RSP: 002b:00007ff78a0e89c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007ff78a0e8a58 RCX: 0000000000414cb1
RDX: 0000000000000000 RSI: 00007ff78a0e8a00 RDI: 0000000000000006
RBP: 0000000000000006 R08: 000000000000000b R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000293 R12: 00007ff78a0e8a40
R13: 0000000000000b48 R14: 00000000004d5630 R15: 000000000075bfd4
INFO: task syz-executor.3:26730 blocked for more than 140 seconds.
Not tainted 4.14.165-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.3 D28928 26730 7373 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2808 [inline]
__schedule+0x7b8/0x1cd0 kernel/sched/core.c:3384
schedule+0x92/0x1c0 kernel/sched/core.c:3428
schedule_preempt_disabled+0x13/0x20 kernel/sched/core.c:3486
__mutex_lock_common kernel/locking/mutex.c:833 [inline]
__mutex_lock+0x73c/0x1470 kernel/locking/mutex.c:893
mutex_lock_nested+0x16/0x20 kernel/locking/mutex.c:908
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x119/0x150 net/netlink/genetlink.c:623
netlink_rcv_skb+0x14f/0x3c0 net/netlink/af_netlink.c:2432
genl_rcv+0x29/0x40 net/netlink/genetlink.c:636
netlink_unicast_kernel net/netlink/af_netlink.c:1286 [inline]
netlink_unicast+0x44d/0x650 net/netlink/af_netlink.c:1312
netlink_sendmsg+0x7c4/0xc60 net/netlink/af_netlink.c:1877
sock_sendmsg_nosec net/socket.c:646 [inline]
sock_sendmsg+0xce/0x110 net/socket.c:656
___sys_sendmsg+0x70a/0x840 net/socket.c:2062
__sys_sendmsg+0xb9/0x140 net/socket.c:2096
SYSC_sendmsg net/socket.c:2107 [inline]
SyS_sendmsg+0x2d/0x50 net/socket.c:2103
do_syscall_64+0x1e8/0x640 arch/x86/entry/common.c:292
entry_SYSCALL_64_after_hwframe+0x42/0xb7
RIP: 0033:0x414cb1
RSP: 002b:00007fa0a941e9c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007fa0a941ea58 RCX: 0000000000414cb1
RDX: 0000000000000000 RSI: 00007fa0a941ea00 RDI: 0000000000000006
RBP: 0000000000000006 R08: 000000000000000b R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000293 R12: 00007fa0a941ea40
R13: 0000000000000b48 R14: 00000000004d5630 R15: 000000000075bf2c
INFO: task syz-executor.3:26737 blocked for more than 140 seconds.
Not tainted 4.14.165-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.3 D28928 26737 7373 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2808 [inline]
__schedule+0x7b8/0x1cd0 kernel/sched/core.c:3384
schedule+0x92/0x1c0 kernel/sched/core.c:3428
schedule_preempt_disabled+0x13/0x20 kernel/sched/core.c:3486
__mutex_lock_common kernel/locking/mutex.c:833 [inline]
__mutex_lock+0x73c/0x1470 kernel/locking/mutex.c:893
mutex_lock_nested+0x16/0x20 kernel/locking/mutex.c:908
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x119/0x150 net/netlink/genetlink.c:623
netlink_rcv_skb+0x14f/0x3c0 net/netlink/af_netlink.c:2432
genl_rcv+0x29/0x40 net/netlink/genetlink.c:636
netlink_unicast_kernel net/netlink/af_netlink.c:1286 [inline]
netlink_unicast+0x44d/0x650 net/netlink/af_netlink.c:1312
netlink_sendmsg+0x7c4/0xc60 net/netlink/af_netlink.c:1877
sock_sendmsg_nosec net/socket.c:646 [inline]
sock_sendmsg+0xce/0x110 net/socket.c:656
___sys_sendmsg+0x70a/0x840 net/socket.c:2062
__sys_sendmsg+0xb9/0x140 net/socket.c:2096
SYSC_sendmsg net/socket.c:2107 [inline]
SyS_sendmsg+0x2d/0x50 net/socket.c:2103
do_syscall_64+0x1e8/0x640 arch/x86/entry/common.c:292
entry_SYSCALL_64_after_hwframe+0x42/0xb7
RIP: 0033:0x414cb1
RSP: 002b:00007fa0a93fd9c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007fa0a93fda58 RCX: 0000000000414cb1
RDX: 0000000000000000 RSI: 00007fa0a93fda00 RDI: 0000000000000006
RBP: 0000000000000006 R08: 000000000000000b R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000293 R12: 00007fa0a93fda40
R13: 0000000000000b48 R14: 00000000004d5630 R15: 000000000075bfd4
INFO: task syz-executor.4:26729 blocked for more than 140 seconds.
Not tainted 4.14.165-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.4 D28928 26729 7382 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2808 [inline]
__schedule+0x7b8/0x1cd0 kernel/sched/core.c:3384
schedule+0x92/0x1c0 kernel/sched/core.c:3428
schedule_preempt_disabled+0x13/0x20 kernel/sched/core.c:3486
__mutex_lock_common kernel/locking/mutex.c:833 [inline]
__mutex_lock+0x73c/0x1470 kernel/locking/mutex.c:893
mutex_lock_nested+0x16/0x20 kernel/locking/mutex.c:908
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x119/0x150 net/netlink/genetlink.c:623
netlink_rcv_skb+0x14f/0x3c0 net/netlink/af_netlink.c:2432
genl_rcv+0x29/0x40 net/netlink/genetlink.c:636
netlink_unicast_kernel net/netlink/af_netlink.c:1286 [inline]
netlink_unicast+0x44d/0x650 net/netlink/af_netlink.c:1312
netlink_sendmsg+0x7c4/0xc60 net/netlink/af_netlink.c:1877
sock_sendmsg_nosec net/socket.c:646 [inline]
sock_sendmsg+0xce/0x110 net/socket.c:656
___sys_sendmsg+0x70a/0x840 net/socket.c:2062
__sys_sendmsg+0xb9/0x140 net/socket.c:2096
SYSC_sendmsg net/socket.c:2107 [inline]
SyS_sendmsg+0x2d/0x50 net/socket.c:2103
do_syscall_64+0x1e8/0x640 arch/x86/entry/common.c:292
entry_SYSCALL_64_after_hwframe+0x42/0xb7
RIP: 0033:0x414cb1
RSP: 002b:00007f5475b769c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007f5475b76a58 RCX: 0000000000414cb1
RDX: 0000000000000000 RSI: 00007f5475b76a00 RDI: 0000000000000006
RBP: 0000000000000006 R08: 000000000000000b R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000293 R12: 00007f5475b76a40
R13: 0000000000000b48 R14: 00000000004d5630 R15: 000000000075bf2c
INFO: task syz-executor.4:26734 blocked for more than 140 seconds.
Not tainted 4.14.165-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.4 D28928 26734 7382 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2808 [inline]
__schedule+0x7b8/0x1cd0 kernel/sched/core.c:3384
schedule+0x92/0x1c0 kernel/sched/core.c:3428
schedule_preempt_disabled+0x13/0x20 kernel/sched/core.c:3486
__mutex_lock_common kernel/locking/mutex.c:833 [inline]
__mutex_lock+0x73c/0x1470 kernel/locking/mutex.c:893
mutex_lock_nested+0x16/0x20 kernel/locking/mutex.c:908
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x119/0x150 net/netlink/genetlink.c:623
netlink_rcv_skb+0x14f/0x3c0 net/netlink/af_netlink.c:2432
genl_rcv+0x29/0x40 net/netlink/genetlink.c:636
netlink_unicast_kernel net/netlink/af_netlink.c:1286 [inline]
netlink_unicast+0x44d/0x650 net/netlink/af_netlink.c:1312
netlink_sendmsg+0x7c4/0xc60 net/netlink/af_netlink.c:1877
sock_sendmsg_nosec net/socket.c:646 [inline]
sock_sendmsg+0xce/0x110 net/socket.c:656
___sys_sendmsg+0x70a/0x840 net/socket.c:2062
__sys_sendmsg+0xb9/0x140 net/socket.c:2096
SYSC_sendmsg net/socket.c:2107 [inline]
SyS_sendmsg+0x2d/0x50 net/socket.c:2103
do_syscall_64+0x1e8/0x640 arch/x86/entry/common.c:292
entry_SYSCALL_64_after_hwframe+0x42/0xb7
RIP: 0033:0x414cb1
RSP: 002b:00007f5475b559c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007f5475b55a58 RCX: 0000000000414cb1
RDX: 0000000000000000 RSI: 00007f5475b55a00 RDI: 0000000000000006
RBP: 0000000000000006 R08: 000000000000000b R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000293 R12: 00007f5475b55a40
R13: 0000000000000b48 R14: 00000000004d5630 R15: 000000000075bfd4
INFO: task syz-executor.5:26732 blocked for more than 140 seconds.
Not tainted 4.14.165-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.5 D28928 26732 7376 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2808 [inline]
__schedule+0x7b8/0x1cd0 kernel/sched/core.c:3384
schedule+0x92/0x1c0 kernel/sched/core.c:3428
schedule_preempt_disabled+0x13/0x20 kernel/sched/core.c:3486
__mutex_lock_common kernel/locking/mutex.c:833 [inline]
__mutex_lock+0x73c/0x1470 kernel/locking/mutex.c:893
mutex_lock_nested+0x16/0x20 kernel/locking/mutex.c:908
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x119/0x150 net/netlink/genetlink.c:623
netlink_rcv_skb+0x14f/0x3c0 net/netlink/af_netlink.c:2432
genl_rcv+0x29/0x40 net/netlink/genetlink.c:636
netlink_unicast_kernel net/netlink/af_netlink.c:1286 [inline]
netlink_unicast+0x44d/0x650 net/netlink/af_netlink.c:1312
netlink_sendmsg+0x7c4/0xc60 net/netlink/af_netlink.c:1877
sock_sendmsg_nosec net/socket.c:646 [inline]
sock_sendmsg+0xce/0x110 net/socket.c:656
___sys_sendmsg+0x70a/0x840 net/socket.c:2062
__sys_sendmsg+0xb9/0x140 net/socket.c:2096
SYSC_sendmsg net/socket.c:2107 [inline]
SyS_sendmsg+0x2d/0x50 net/socket.c:2103
do_syscall_64+0x1e8/0x640 arch/x86/entry/common.c:292
entry_SYSCALL_64_after_hwframe+0x42/0xb7
RIP: 0033:0x414cb1
RSP: 002b:00007f8f9ba8b9c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007f8f9ba8ba58 RCX: 0000000000414cb1
RDX: 0000000000000000 RSI: 00007f8f9ba8ba00 RDI: 0000000000000006
RBP: 0000000000000006 R08: 000000000000000b R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000293 R12: 00007f8f9ba8ba40
R13: 0000000000000b48 R14: 00000000004d5630 R15: 000000000075bf2c
INFO: task syz-executor.5:26736 blocked for more than 140 seconds.
Not tainted 4.14.165-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.5 D28928 26736 7376 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2808 [inline]
__schedule+0x7b8/0x1cd0 kernel/sched/core.c:3384
schedule+0x92/0x1c0 kernel/sched/core.c:3428
schedule_preempt_disabled+0x13/0x20 kernel/sched/core.c:3486
__mutex_lock_common kernel/locking/mutex.c:833 [inline]
__mutex_lock+0x73c/0x1470 kernel/locking/mutex.c:893
mutex_lock_nested+0x16/0x20 kernel/locking/mutex.c:908
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x119/0x150 net/netlink/genetlink.c:623
netlink_rcv_skb+0x14f/0x3c0 net/netlink/af_netlink.c:2432
genl_rcv+0x29/0x40 net/netlink/genetlink.c:636
netlink_unicast_kernel net/netlink/af_netlink.c:1286 [inline]
netlink_unicast+0x44d/0x650 net/netlink/af_netlink.c:1312
netlink_sendmsg+0x7c4/0xc60 net/netlink/af_netlink.c:1877
sock_sendmsg_nosec net/socket.c:646 [inline]
sock_sendmsg+0xce/0x110 net/socket.c:656
___sys_sendmsg+0x70a/0x840 net/socket.c:2062
__sys_sendmsg+0xb9/0x140 net/socket.c:2096
SYSC_sendmsg net/socket.c:2107 [inline]
SyS_sendmsg+0x2d/0x50 net/socket.c:2103
do_syscall_64+0x1e8/0x640 arch/x86/entry/common.c:292
entry_SYSCALL_64_after_hwframe+0x42/0xb7
RIP: 0033:0x414cb1
RSP: 002b:00007f8f9ba6a9c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007f8f9ba6aa58 RCX: 0000000000414cb1
RDX: 0000000000000000 RSI: 00007f8f9ba6aa00 RDI: 0000000000000003
RBP: 0000000000000003 R08: 000000000000000b R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000293 R12: 00007f8f9ba6aa40
R13: 0000000000000b48 R14: 00000000004d5630 R15: 000000000075bfd4
INFO: task syz-executor.0:26731 blocked for more than 140 seconds.
Not tainted 4.14.165-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.0 D28928 26731 7383 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2808 [inline]
__schedule+0x7b8/0x1cd0 kernel/sched/core.c:3384
schedule+0x92/0x1c0 kernel/sched/core.c:3428
schedule_preempt_disabled+0x13/0x20 kernel/sched/core.c:3486
__mutex_lock_common kernel/locking/mutex.c:833 [inline]
__mutex_lock+0x73c/0x1470 kernel/locking/mutex.c:893
mutex_lock_nested+0x16/0x20 kernel/locking/mutex.c:908
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x119/0x150 net/netlink/genetlink.c:623
netlink_rcv_skb+0x14f/0x3c0 net/netlink/af_netlink.c:2432
genl_rcv+0x29/0x40 net/netlink/genetlink.c:636
netlink_unicast_kernel net/netlink/af_netlink.c:1286 [inline]
netlink_unicast+0x44d/0x650 net/netlink/af_netlink.c:1312
netlink_sendmsg+0x7c4/0xc60 net/netlink/af_netlink.c:1877
sock_sendmsg_nosec net/socket.c:646 [inline]
sock_sendmsg+0xce/0x110 net/socket.c:656
___sys_sendmsg+0x70a/0x840 net/socket.c:2062
__sys_sendmsg+0xb9/0x140 net/socket.c:2096
SYSC_sendmsg net/socket.c:2107 [inline]
SyS_sendmsg+0x2d/0x50 net/socket.c:2103
do_syscall_64+0x1e8/0x640 arch/x86/entry/common.c:292
entry_SYSCALL_64_after_hwframe+0x42/0xb7
RIP: 0033:0x414cb1
RSP: 002b:00007f99dbbed9c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007f99dbbeda58 RCX: 0000000000414cb1
RDX: 0000000000000000 RSI: 00007f99dbbeda00 RDI: 0000000000000006
RBP: 0000000000000006 R08: 000000000000000b R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000293 R12: 00007f99dbbeda40
R13: 0000000000000b48 R14: 00000000004d5630 R15: 000000000075bf2c
INFO: task syz-executor.0:26735 blocked for more than 140 seconds.
Not tainted 4.14.165-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.0 D28848 26735 7383 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2808 [inline]
__schedule+0x7b8/0x1cd0 kernel/sched/core.c:3384
schedule+0x92/0x1c0 kernel/sched/core.c:3428
schedule_preempt_disabled+0x13/0x20 kernel/sched/core.c:3486
__mutex_lock_common kernel/locking/mutex.c:833 [inline]
__mutex_lock+0x73c/0x1470 kernel/locking/mutex.c:893
mutex_lock_nested+0x16/0x20 kernel/locking/mutex.c:908
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x119/0x150 net/netlink/genetlink.c:623
netlink_rcv_skb+0x14f/0x3c0 net/netlink/af_netlink.c:2432
genl_rcv+0x29/0x40 net/netlink/genetlink.c:636
netlink_unicast_kernel net/netlink/af_netlink.c:1286 [inline]
netlink_unicast+0x44d/0x650 net/netlink/af_netlink.c:1312
netlink_sendmsg+0x7c4/0xc60 net/netlink/af_netlink.c:1877
sock_sendmsg_nosec net/socket.c:646 [inline]
sock_sendmsg+0xce/0x110 net/socket.c:656
___sys_sendmsg+0x70a/0x840 net/socket.c:2062
__sys_sendmsg+0xb9/0x140 net/socket.c:2096
SYSC_sendmsg net/socket.c:2107 [inline]
SyS_sendmsg+0x2d/0x50 net/socket.c:2103
do_syscall_64+0x1e8/0x640 arch/x86/entry/common.c:292
entry_SYSCALL_64_after_hwframe+0x42/0xb7
RIP: 0033:0x414cb1
RSP: 002b:00007f99dbbcc9c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007f99dbbcca58 RCX: 0000000000414cb1
RDX: 0000000000000000 RSI: 00007f99dbbcca00 RDI: 0000000000000006
RBP: 0000000000000006 R08: 000000000000000b R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000293 R12: 00007f99dbbcca40
R13: 0000000000000b48 R14: 00000000004d5630 R15: 000000000075bfd4

Showing all locks held in the system:
1 lock held by khungtaskd/1056:
#0: (tasklist_lock){.+.+}, at: [<ffffffff81489c18>]
debug_show_all_locks+0x7f/0x21f kernel/locking/lockdep.c:4544
2 locks held by getty/7332:
#0: (&tty->ldisc_sem){++++}, at: [<ffffffff866a6243>]
ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:376
#1: (&ldata->atomic_read_lock){+.+.}, at: [<ffffffff834ca396>]
n_tty_read+0x1e6/0x17d0 drivers/tty/n_tty.c:2156
2 locks held by getty/7333:
#0: (&tty->ldisc_sem){++++}, at: [<ffffffff866a6243>]
ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:376
#1: (&ldata->atomic_read_lock){+.+.}, at: [<ffffffff834ca396>]
n_tty_read+0x1e6/0x17d0 drivers/tty/n_tty.c:2156
2 locks held by getty/7334:
#0: (&tty->ldisc_sem){++++}, at: [<ffffffff866a6243>]
ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:376
#1: (&ldata->atomic_read_lock){+.+.}, at: [<ffffffff834ca396>]
n_tty_read+0x1e6/0x17d0 drivers/tty/n_tty.c:2156
2 locks held by getty/7335:
#0: (&tty->ldisc_sem){++++}, at: [<ffffffff866a6243>]
ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:376
#1: (&ldata->atomic_read_lock){+.+.}, at: [<ffffffff834ca396>]
n_tty_read+0x1e6/0x17d0 drivers/tty/n_tty.c:2156
2 locks held by getty/7336:
#0: (&tty->ldisc_sem){++++}, at: [<ffffffff866a6243>]
ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:376
#1: (&ldata->atomic_read_lock){+.+.}, at: [<ffffffff834ca396>]
n_tty_read+0x1e6/0x17d0 drivers/tty/n_tty.c:2156
2 locks held by getty/7337:
#0: (&tty->ldisc_sem){++++}, at: [<ffffffff866a6243>]
ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:376
#1: (&ldata->atomic_read_lock){+.+.}, at: [<ffffffff834ca396>]
n_tty_read+0x1e6/0x17d0 drivers/tty/n_tty.c:2156
2 locks held by getty/7338:
#0: (&tty->ldisc_sem){++++}, at: [<ffffffff866a6243>]
ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:376
#1: (&ldata->atomic_read_lock){+.+.}, at: [<ffffffff834ca396>]
n_tty_read+0x1e6/0x17d0 drivers/tty/n_tty.c:2156
2 locks held by syz-executor.2/26728:
#0: (cb_lock){++++}, at: [<ffffffff853fd56a>] genl_rcv+0x1a/0x40
net/netlink/genetlink.c:635
#1: (genl_mutex){+.+.}, at: [<ffffffff85400db9>] genl_lock
net/netlink/genetlink.c:33 [inline]
#1: (genl_mutex){+.+.}, at: [<ffffffff85400db9>] genl_rcv_msg+0x119/0x150
net/netlink/genetlink.c:623
2 locks held by syz-executor.2/26733:
#0: (cb_lock){++++}, at: [<ffffffff853fd56a>] genl_rcv+0x1a/0x40
net/netlink/genetlink.c:635
#1: (genl_mutex){+.+.}, at: [<ffffffff85400db9>] genl_lock
net/netlink/genetlink.c:33 [inline]
#1: (genl_mutex){+.+.}, at: [<ffffffff85400db9>] genl_rcv_msg+0x119/0x150
net/netlink/genetlink.c:623
2 locks held by syz-executor.3/26730:
#0: (cb_lock){++++}, at: [<ffffffff853fd56a>] genl_rcv+0x1a/0x40
net/netlink/genetlink.c:635
#1: (genl_mutex){+.+.}, at: [<ffffffff85400db9>] genl_lock
net/netlink/genetlink.c:33 [inline]
#1: (genl_mutex){+.+.}, at: [<ffffffff85400db9>] genl_rcv_msg+0x119/0x150
net/netlink/genetlink.c:623
2 locks held by syz-executor.3/26737:
#0: (cb_lock){++++}, at: [<ffffffff853fd56a>] genl_rcv+0x1a/0x40
net/netlink/genetlink.c:635
#1: (genl_mutex){+.+.}, at: [<ffffffff85400db9>] genl_lock
net/netlink/genetlink.c:33 [inline]
#1: (genl_mutex){+.+.}, at: [<ffffffff85400db9>] genl_rcv_msg+0x119/0x150
net/netlink/genetlink.c:623
2 locks held by syz-executor.4/26729:
#0: (cb_lock){++++}, at: [<ffffffff853fd56a>] genl_rcv+0x1a/0x40
net/netlink/genetlink.c:635
#1: (genl_mutex){+.+.}, at: [<ffffffff85400db9>] genl_lock
net/netlink/genetlink.c:33 [inline]
#1: (genl_mutex){+.+.}, at: [<ffffffff85400db9>] genl_rcv_msg+0x119/0x150
net/netlink/genetlink.c:623
2 locks held by syz-executor.4/26734:
#0: (cb_lock){++++}, at: [<ffffffff853fd56a>] genl_rcv+0x1a/0x40
net/netlink/genetlink.c:635
#1: (genl_mutex){+.+.}, at: [<ffffffff85400db9>] genl_lock
net/netlink/genetlink.c:33 [inline]
#1: (genl_mutex){+.+.}, at: [<ffffffff85400db9>] genl_rcv_msg+0x119/0x150
net/netlink/genetlink.c:623
2 locks held by syz-executor.5/26732:
#0: (cb_lock){++++}, at: [<ffffffff853fd56a>] genl_rcv+0x1a/0x40
net/netlink/genetlink.c:635
#1: (genl_mutex){+.+.}, at: [<ffffffff85400db9>] genl_lock
net/netlink/genetlink.c:33 [inline]
#1: (genl_mutex){+.+.}, at: [<ffffffff85400db9>] genl_rcv_msg+0x119/0x150
net/netlink/genetlink.c:623
2 locks held by syz-executor.5/26736:
#0: (cb_lock){++++}, at: [<ffffffff853fd56a>] genl_rcv+0x1a/0x40
net/netlink/genetlink.c:635
#1: (genl_mutex){+.+.}, at: [<ffffffff85400db9>] genl_lock
net/netlink/genetlink.c:33 [inline]
#1: (genl_mutex){+.+.}, at: [<ffffffff85400db9>] genl_rcv_msg+0x119/0x150
net/netlink/genetlink.c:623
2 locks held by syz-executor.0/26731:
#0: (cb_lock){++++}, at: [<ffffffff853fd56a>] genl_rcv+0x1a/0x40
net/netlink/genetlink.c:635
#1: (genl_mutex){+.+.}, at: [<ffffffff85400db9>] genl_lock
net/netlink/genetlink.c:33 [inline]
#1: (genl_mutex){+.+.}, at: [<ffffffff85400db9>] genl_rcv_msg+0x119/0x150
net/netlink/genetlink.c:623
2 locks held by syz-executor.0/26735:
#0: (cb_lock){++++}, at: [<ffffffff853fd56a>] genl_rcv+0x1a/0x40
net/netlink/genetlink.c:635
#1: (genl_mutex){+.+.}, at: [<ffffffff85400db9>] genl_lock
net/netlink/genetlink.c:33 [inline]
#1: (genl_mutex){+.+.}, at: [<ffffffff85400db9>] genl_rcv_msg+0x119/0x150
net/netlink/genetlink.c:623

=============================================

NMI backtrace for cpu 1
CPU: 1 PID: 1056 Comm: khungtaskd Not tainted 4.14.165-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:17 [inline]
dump_stack+0x142/0x197 lib/dump_stack.c:58
nmi_cpu_backtrace.cold+0x57/0x94 lib/nmi_backtrace.c:101
nmi_trigger_cpumask_backtrace+0x141/0x189 lib/nmi_backtrace.c:62
arch_trigger_cpumask_backtrace+0x14/0x20 arch/x86/kernel/apic/hw_nmi.c:38
trigger_all_cpu_backtrace include/linux/nmi.h:140 [inline]
check_hung_uninterruptible_tasks kernel/hung_task.c:195 [inline]
watchdog+0x5e7/0xb90 kernel/hung_task.c:274
kthread+0x319/0x430 kernel/kthread.c:232
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:404
Sending NMI from CPU 1 to CPUs 0:
NMI backtrace for cpu 0
CPU: 0 PID: 7397 Comm: kworker/u4:1 Not tainted 4.14.165-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
Workqueue: bat_events batadv_nc_worker
task: ffff88808681c380 task.stack: ffff888098e98000
RIP: 0010:arch_local_save_flags arch/x86/include/asm/paravirt.h:774 [inline]
RIP: 0010:arch_local_irq_save arch/x86/include/asm/paravirt.h:796 [inline]
RIP: 0010:lock_acquire+0x8b/0x430 kernel/locking/lockdep.c:3989
RSP: 0018:ffff888098e9fc90 EFLAGS: 00000246
RAX: 1ffffffff0fe2d28 RBX: ffff88808681c380 RCX: 0000000000000002
RDX: dffffc0000000000 RSI: 0000000000000000 RDI: ffff88808681cbfc
RBP: ffff888098e9fcd8 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: ffffffff87f872a0
R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000002
FS: 0000000000000000(0000) GS:ffff8880aec00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000b4e978 CR3: 000000009577a000 CR4: 00000000001406f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
rcu_lock_acquire include/linux/rcupdate.h:242 [inline]
rcu_read_lock include/linux/rcupdate.h:629 [inline]
batadv_nc_purge_orig_hash net/batman-adv/network-coding.c:416 [inline]
batadv_nc_worker+0x107/0x6d0 net/batman-adv/network-coding.c:726
process_one_work+0x863/0x1600 kernel/workqueue.c:2114
worker_thread+0x5d9/0x1050 kernel/workqueue.c:2248
kthread+0x319/0x430 kernel/kthread.c:232
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:404
Code: 7c 08 00 00 85 f6 0f 85 83 01 00 00 48 c7 c0 40 69 f1 87 48 ba 00 00
00 00 00 fc ff df 48 c1 e8 03 80 3c 10 00 0f 85 6a 03 00 00 <48> 83 3d dd
f2 a8 06 00 0f 84 a5 02 00 00 9c 58 0f 1f 44 00 00

syzbot

unread,
Feb 16, 2020, 6:49:02 PM2/16/20
to syzkaller...@googlegroups.com
syzbot suspects this bug was fixed by commit:

commit 24070b40926b42c35ca0649f44711cad5da0cf96
Author: Eric Dumazet <edum...@google.com>
Date: Fri Jan 31 17:14:47 2020 +0000

tcp: clear tp->total_retrans in tcp_disconnect()

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=1484f579e00000
start commit: c04fc6fa Linux 4.14.165
git tree: linux-4.14.y
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=11ee2b3ee00000

If the result looks correct, please mark the bug fixed by replying with:

#syz fix: tcp: clear tp->total_retrans in tcp_disconnect()

For information about bisection process see: https://goo.gl/tpsmEJ#bisection
Reply all
Reply to author
Forward
0 new messages