INFO: task hung in drain_all_pages

15 views
Skip to first unread message

syzbot

unread,
Jan 20, 2020, 3:24:12 PM1/20/20
to syzkaller...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: dc4ba5be Linux 4.19.97
git tree: linux-4.19.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1331f959e00000
kernel config: https://syzkaller.appspot.com/x/.config?x=cc17a984a7e9c2f3
dashboard link: https://syzkaller.appspot.com/bug?extid=6ce3da544a58f51d56ca
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=17780685e00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=12ddc135e00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+6ce3da...@syzkaller.appspotmail.com

xt_CT: You must specify a L4 protocol and not use inversions on it
xt_CT: You must specify a L4 protocol and not use inversions on it
xt_CT: You must specify a L4 protocol and not use inversions on it
xt_CT: You must specify a L4 protocol and not use inversions on it
INFO: task khugepaged:1089 blocked for more than 140 seconds.
Not tainted 4.19.97-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
khugepaged D26144 1089 2 0x80000000
Call Trace:
context_switch kernel/sched/core.c:2826 [inline]
__schedule+0x866/0x1dc0 kernel/sched/core.c:3515
schedule+0x92/0x1c0 kernel/sched/core.c:3559
schedule_timeout+0x8c8/0xfc0 kernel/time/timer.c:1782
do_wait_for_common kernel/sched/completion.c:83 [inline]
__wait_for_common kernel/sched/completion.c:104 [inline]
wait_for_common kernel/sched/completion.c:115 [inline]
wait_for_completion+0x29c/0x440 kernel/sched/completion.c:136
__flush_work+0x49f/0x870 kernel/workqueue.c:2926
flush_work+0x18/0x20 kernel/workqueue.c:2947
drain_all_pages+0x3a6/0x570 mm/page_alloc.c:2697
__alloc_pages_direct_reclaim mm/page_alloc.c:3833 [inline]
__alloc_pages_slowpath+0xa8b/0x2870 mm/page_alloc.c:4209
__alloc_pages_nodemask+0x617/0x750 mm/page_alloc.c:4417
__alloc_pages include/linux/gfp.h:496 [inline]
__alloc_pages_node include/linux/gfp.h:509 [inline]
khugepaged_alloc_page+0x95/0x190 mm/khugepaged.c:773
collapse_huge_page+0x121/0x3d10 mm/khugepaged.c:963
khugepaged_scan_pmd mm/khugepaged.c:1219 [inline]
khugepaged_scan_mm_slot mm/khugepaged.c:1757 [inline]
khugepaged_do_scan mm/khugepaged.c:1838 [inline]
khugepaged+0x2e9a/0x3f20 mm/khugepaged.c:1883
kthread+0x354/0x420 kernel/kthread.c:246
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:415
INFO: task syz-executor156:8113 blocked for more than 140 seconds.
Not tainted 4.19.97-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor156 D27648 8113 8105 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2826 [inline]
__schedule+0x866/0x1dc0 kernel/sched/core.c:3515
schedule+0x92/0x1c0 kernel/sched/core.c:3559
schedule_timeout+0x8c8/0xfc0 kernel/time/timer.c:1782
do_wait_for_common kernel/sched/completion.c:83 [inline]
__wait_for_common kernel/sched/completion.c:104 [inline]
wait_for_common kernel/sched/completion.c:115 [inline]
wait_for_completion+0x29c/0x440 kernel/sched/completion.c:136
__flush_work+0x49f/0x870 kernel/workqueue.c:2926
__cancel_work_timer+0x3bf/0x520 kernel/workqueue.c:3013
cancel_delayed_work_sync+0x1b/0x20 kernel/workqueue.c:3145
htable_destroy net/netfilter/xt_hashlimit.c:414 [inline]
htable_put+0x15f/0x220 net/netfilter/xt_hashlimit.c:443
hashlimit_mt_destroy_v1+0x50/0x70 net/netfilter/xt_hashlimit.c:972
cleanup_match+0xde/0x170 net/ipv6/netfilter/ip6_tables.c:481
find_check_entry.isra.0+0x454/0x920 net/ipv4/netfilter/ip_tables.c:567
translate_table+0xcb4/0x17d0 net/ipv4/netfilter/ip_tables.c:720
do_replace net/ipv4/netfilter/ip_tables.c:1139 [inline]
do_ipt_set_ctl+0x2ef/0x492 net/ipv4/netfilter/ip_tables.c:1675
nf_sockopt net/netfilter/nf_sockopt.c:106 [inline]
nf_setsockopt+0x77/0xd0 net/netfilter/nf_sockopt.c:115
ip_setsockopt net/ipv4/ip_sockglue.c:1258 [inline]
ip_setsockopt+0xdf/0x100 net/ipv4/ip_sockglue.c:1238
tcp_setsockopt net/ipv4/tcp.c:3077 [inline]
tcp_setsockopt+0x8f/0xe0 net/ipv4/tcp.c:3071
sock_common_setsockopt+0x94/0xd0 net/core/sock.c:3046
__sys_setsockopt+0x17a/0x280 net/socket.c:1901
__do_sys_setsockopt net/socket.c:1912 [inline]
__se_sys_setsockopt net/socket.c:1909 [inline]
__x64_sys_setsockopt+0xbe/0x150 net/socket.c:1909
do_syscall_64+0xfd/0x620 arch/x86/entry/common.c:293
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x441279
Code: 2e 0a 43 68 65 63 6b 20 65 72 72 6f 72 20 6c 6f 67 20 66 6f 72 20 64 65 74 61 69 6c 73 2c 20 66 69 78 20 65 72 72 6f 72 73 20 <61> 6e 64 20 72 65 73 74 61 72 74 2e 20 41 73 20 61 20 6c 61 73 74
RSP: 002b:00007ffd952a71c8 EFLAGS: 00000246 ORIG_RAX: 0000000000000036
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 0000000000441279
RDX: 0000000000000040 RSI: 0004000000000000 RDI: 0000000000000003
RBP: 00000000006cc018 R08: 0000000000000509 R09: 00000000004002c8
R10: 00000000200002c0 R11: 0000000000000246 R12: 0000000000401ff0
R13: 0000000000402080 R14: 0000000000000000 R15: 0000000000000000
INFO: task syz-executor156:8130 blocked for more than 140 seconds.
Not tainted 4.19.97-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor156 D28216 8130 8107 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2826 [inline]
__schedule+0x866/0x1dc0 kernel/sched/core.c:3515
schedule+0x92/0x1c0 kernel/sched/core.c:3559
schedule_preempt_disabled+0x13/0x20 kernel/sched/core.c:3617
__mutex_lock_common kernel/locking/mutex.c:1002 [inline]
__mutex_lock+0x726/0x1300 kernel/locking/mutex.c:1072
mutex_lock_nested+0x16/0x20 kernel/locking/mutex.c:1087
hashlimit_mt_check_common.isra.0+0x341/0x1500 net/netfilter/xt_hashlimit.c:897
hashlimit_mt_check_v1+0x325/0x3ab net/netfilter/xt_hashlimit.c:926
xt_check_match+0x280/0x690 net/netfilter/x_tables.c:506
check_match net/ipv4/netfilter/ip_tables.c:475 [inline]
find_check_match net/ipv4/netfilter/ip_tables.c:491 [inline]
find_check_entry.isra.0+0x32f/0x920 net/ipv4/netfilter/ip_tables.c:541
translate_table+0xcb4/0x17d0 net/ipv4/netfilter/ip_tables.c:720
do_replace net/ipv4/netfilter/ip_tables.c:1139 [inline]
do_ipt_set_ctl+0x2ef/0x492 net/ipv4/netfilter/ip_tables.c:1675
nf_sockopt net/netfilter/nf_sockopt.c:106 [inline]
nf_setsockopt+0x77/0xd0 net/netfilter/nf_sockopt.c:115
ip_setsockopt net/ipv4/ip_sockglue.c:1258 [inline]
ip_setsockopt+0xdf/0x100 net/ipv4/ip_sockglue.c:1238
tcp_setsockopt net/ipv4/tcp.c:3077 [inline]
tcp_setsockopt+0x8f/0xe0 net/ipv4/tcp.c:3071
sock_common_setsockopt+0x94/0xd0 net/core/sock.c:3046
__sys_setsockopt+0x17a/0x280 net/socket.c:1901
__do_sys_setsockopt net/socket.c:1912 [inline]
__se_sys_setsockopt net/socket.c:1909 [inline]
__x64_sys_setsockopt+0xbe/0x150 net/socket.c:1909
do_syscall_64+0xfd/0x620 arch/x86/entry/common.c:293
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x441279
Code: 2e 0a 43 68 65 63 6b 20 65 72 72 6f 72 20 6c 6f 67 20 66 6f 72 20 64 65 74 61 69 6c 73 2c 20 66 69 78 20 65 72 72 6f 72 73 20 <61> 6e 64 20 72 65 73 74 61 72 74 2e 20 41 73 20 61 20 6c 61 73 74
RSP: 002b:00007ffd952a71c8 EFLAGS: 00000246 ORIG_RAX: 0000000000000036
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 0000000000441279
RDX: 0000000000000040 RSI: 0004000000000000 RDI: 0000000000000003
RBP: 00000000000c6524 R08: 0000000000000509 R09: 00000000004002c8
R10: 00000000200002c0 R11: 0000000000000246 R12: 0000000000401ff0
R13: 0000000000402080 R14: 0000000000000000 R15: 0000000000000000
INFO: task syz-executor156:8131 blocked for more than 140 seconds.
Not tainted 4.19.97-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor156 D28216 8131 8104 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2826 [inline]
__schedule+0x866/0x1dc0 kernel/sched/core.c:3515
schedule+0x92/0x1c0 kernel/sched/core.c:3559
schedule_preempt_disabled+0x13/0x20 kernel/sched/core.c:3617
__mutex_lock_common kernel/locking/mutex.c:1002 [inline]
__mutex_lock+0x726/0x1300 kernel/locking/mutex.c:1072
mutex_lock_nested+0x16/0x20 kernel/locking/mutex.c:1087
hashlimit_mt_check_common.isra.0+0x341/0x1500 net/netfilter/xt_hashlimit.c:897
hashlimit_mt_check_v1+0x325/0x3ab net/netfilter/xt_hashlimit.c:926
xt_check_match+0x280/0x690 net/netfilter/x_tables.c:506
check_match net/ipv4/netfilter/ip_tables.c:475 [inline]
find_check_match net/ipv4/netfilter/ip_tables.c:491 [inline]
find_check_entry.isra.0+0x32f/0x920 net/ipv4/netfilter/ip_tables.c:541
translate_table+0xcb4/0x17d0 net/ipv4/netfilter/ip_tables.c:720
do_replace net/ipv4/netfilter/ip_tables.c:1139 [inline]
do_ipt_set_ctl+0x2ef/0x492 net/ipv4/netfilter/ip_tables.c:1675
nf_sockopt net/netfilter/nf_sockopt.c:106 [inline]
nf_setsockopt+0x77/0xd0 net/netfilter/nf_sockopt.c:115
ip_setsockopt net/ipv4/ip_sockglue.c:1258 [inline]
ip_setsockopt+0xdf/0x100 net/ipv4/ip_sockglue.c:1238
tcp_setsockopt net/ipv4/tcp.c:3077 [inline]
tcp_setsockopt+0x8f/0xe0 net/ipv4/tcp.c:3071
sock_common_setsockopt+0x94/0xd0 net/core/sock.c:3046
__sys_setsockopt+0x17a/0x280 net/socket.c:1901
__do_sys_setsockopt net/socket.c:1912 [inline]
__se_sys_setsockopt net/socket.c:1909 [inline]
__x64_sys_setsockopt+0xbe/0x150 net/socket.c:1909
do_syscall_64+0xfd/0x620 arch/x86/entry/common.c:293
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x441279
Code: 2e 0a 43 68 65 63 6b 20 65 72 72 6f 72 20 6c 6f 67 20 66 6f 72 20 64 65 74 61 69 6c 73 2c 20 66 69 78 20 65 72 72 6f 72 73 20 <61> 6e 64 20 72 65 73 74 61 72 74 2e 20 41 73 20 61 20 6c 61 73 74
RSP: 002b:00007ffd952a71c8 EFLAGS: 00000246 ORIG_RAX: 0000000000000036
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 0000000000441279
RDX: 0000000000000040 RSI: 0004000000000000 RDI: 0000000000000003
RBP: 00000000000c6526 R08: 0000000000000509 R09: 00000000004002c8
R10: 00000000200002c0 R11: 0000000000000246 R12: 0000000000401ff0
R13: 0000000000402080 R14: 0000000000000000 R15: 0000000000000000
INFO: task syz-executor156:8133 blocked for more than 140 seconds.
Not tainted 4.19.97-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor156 D28216 8133 8103 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2826 [inline]
__schedule+0x866/0x1dc0 kernel/sched/core.c:3515
schedule+0x92/0x1c0 kernel/sched/core.c:3559
schedule_preempt_disabled+0x13/0x20 kernel/sched/core.c:3617
__mutex_lock_common kernel/locking/mutex.c:1002 [inline]
__mutex_lock+0x726/0x1300 kernel/locking/mutex.c:1072
mutex_lock_nested+0x16/0x20 kernel/locking/mutex.c:1087
hashlimit_mt_check_common.isra.0+0x341/0x1500 net/netfilter/xt_hashlimit.c:897
hashlimit_mt_check_v1+0x325/0x3ab net/netfilter/xt_hashlimit.c:926
xt_check_match+0x280/0x690 net/netfilter/x_tables.c:506
check_match net/ipv4/netfilter/ip_tables.c:475 [inline]
find_check_match net/ipv4/netfilter/ip_tables.c:491 [inline]
find_check_entry.isra.0+0x32f/0x920 net/ipv4/netfilter/ip_tables.c:541
translate_table+0xcb4/0x17d0 net/ipv4/netfilter/ip_tables.c:720
do_replace net/ipv4/netfilter/ip_tables.c:1139 [inline]
do_ipt_set_ctl+0x2ef/0x492 net/ipv4/netfilter/ip_tables.c:1675
nf_sockopt net/netfilter/nf_sockopt.c:106 [inline]
nf_setsockopt+0x77/0xd0 net/netfilter/nf_sockopt.c:115
ip_setsockopt net/ipv4/ip_sockglue.c:1258 [inline]
ip_setsockopt+0xdf/0x100 net/ipv4/ip_sockglue.c:1238
tcp_setsockopt net/ipv4/tcp.c:3077 [inline]
tcp_setsockopt+0x8f/0xe0 net/ipv4/tcp.c:3071
sock_common_setsockopt+0x94/0xd0 net/core/sock.c:3046
__sys_setsockopt+0x17a/0x280 net/socket.c:1901
__do_sys_setsockopt net/socket.c:1912 [inline]
__se_sys_setsockopt net/socket.c:1909 [inline]
__x64_sys_setsockopt+0xbe/0x150 net/socket.c:1909
do_syscall_64+0xfd/0x620 arch/x86/entry/common.c:293
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x441279
Code: 2e 0a 43 68 65 63 6b 20 65 72 72 6f 72 20 6c 6f 67 20 66 6f 72 20 64 65 74 61 69 6c 73 2c 20 66 69 78 20 65 72 72 6f 72 73 20 <61> 6e 64 20 72 65 73 74 61 72 74 2e 20 41 73 20 61 20 6c 61 73 74
RSP: 002b:00007ffd952a71c8 EFLAGS: 00000246 ORIG_RAX: 0000000000000036
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 0000000000441279
RDX: 0000000000000040 RSI: 0004000000000000 RDI: 0000000000000003
RBP: 00000000000c64f4 R08: 0000000000000509 R09: 00000000004002c8
R10: 00000000200002c0 R11: 0000000000000246 R12: 0000000000401ff0
R13: 0000000000402080 R14: 0000000000000000 R15: 0000000000000000
INFO: task syz-executor156:8132 blocked for more than 140 seconds.
Not tainted 4.19.97-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor156 D28216 8132 8108 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2826 [inline]
__schedule+0x866/0x1dc0 kernel/sched/core.c:3515
schedule+0x92/0x1c0 kernel/sched/core.c:3559
schedule_preempt_disabled+0x13/0x20 kernel/sched/core.c:3617
__mutex_lock_common kernel/locking/mutex.c:1002 [inline]
__mutex_lock+0x726/0x1300 kernel/locking/mutex.c:1072
mutex_lock_nested+0x16/0x20 kernel/locking/mutex.c:1087
hashlimit_mt_check_common.isra.0+0x341/0x1500 net/netfilter/xt_hashlimit.c:897
hashlimit_mt_check_v1+0x325/0x3ab net/netfilter/xt_hashlimit.c:926
xt_check_match+0x280/0x690 net/netfilter/x_tables.c:506
check_match net/ipv4/netfilter/ip_tables.c:475 [inline]
find_check_match net/ipv4/netfilter/ip_tables.c:491 [inline]
find_check_entry.isra.0+0x32f/0x920 net/ipv4/netfilter/ip_tables.c:541
translate_table+0xcb4/0x17d0 net/ipv4/netfilter/ip_tables.c:720
do_replace net/ipv4/netfilter/ip_tables.c:1139 [inline]
do_ipt_set_ctl+0x2ef/0x492 net/ipv4/netfilter/ip_tables.c:1675
nf_sockopt net/netfilter/nf_sockopt.c:106 [inline]
nf_setsockopt+0x77/0xd0 net/netfilter/nf_sockopt.c:115
ip_setsockopt net/ipv4/ip_sockglue.c:1258 [inline]
ip_setsockopt+0xdf/0x100 net/ipv4/ip_sockglue.c:1238
tcp_setsockopt net/ipv4/tcp.c:3077 [inline]
tcp_setsockopt+0x8f/0xe0 net/ipv4/tcp.c:3071
sock_common_setsockopt+0x94/0xd0 net/core/sock.c:3046
__sys_setsockopt+0x17a/0x280 net/socket.c:1901
__do_sys_setsockopt net/socket.c:1912 [inline]
__se_sys_setsockopt net/socket.c:1909 [inline]
__x64_sys_setsockopt+0xbe/0x150 net/socket.c:1909
do_syscall_64+0xfd/0x620 arch/x86/entry/common.c:293
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x441279
Code: 2e 0a 43 68 65 63 6b 20 65 72 72 6f 72 20 6c 6f 67 20 66 6f 72 20 64 65 74 61 69 6c 73 2c 20 66 69 78 20 65 72 72 6f 72 73 20 <61> 6e 64 20 72 65 73 74 61 72 74 2e 20 41 73 20 61 20 6c 61 73 74
RSP: 002b:00007ffd952a71c8 EFLAGS: 00000246 ORIG_RAX: 0000000000000036
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 0000000000441279
RDX: 0000000000000040 RSI: 0004000000000000 RDI: 0000000000000003
RBP: 00000000000c652b R08: 0000000000000509 R09: 00000000004002c8
R10: 00000000200002c0 R11: 0000000000000246 R12: 0000000000401ff0
R13: 0000000000402080 R14: 0000000000000000 R15: 0000000000000000
INFO: task syz-executor156:8134 blocked for more than 140 seconds.
Not tainted 4.19.97-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor156 D28104 8134 8106 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2826 [inline]
__schedule+0x866/0x1dc0 kernel/sched/core.c:3515
schedule+0x92/0x1c0 kernel/sched/core.c:3559
schedule_preempt_disabled+0x13/0x20 kernel/sched/core.c:3617
__mutex_lock_common kernel/locking/mutex.c:1002 [inline]
__mutex_lock+0x726/0x1300 kernel/locking/mutex.c:1072
mutex_lock_nested+0x16/0x20 kernel/locking/mutex.c:1087
hashlimit_mt_check_common.isra.0+0x341/0x1500 net/netfilter/xt_hashlimit.c:897
hashlimit_mt_check_v1+0x325/0x3ab net/netfilter/xt_hashlimit.c:926
xt_check_match+0x280/0x690 net/netfilter/x_tables.c:506
check_match net/ipv4/netfilter/ip_tables.c:475 [inline]
find_check_match net/ipv4/netfilter/ip_tables.c:491 [inline]
find_check_entry.isra.0+0x32f/0x920 net/ipv4/netfilter/ip_tables.c:541
translate_table+0xcb4/0x17d0 net/ipv4/netfilter/ip_tables.c:720
do_replace net/ipv4/netfilter/ip_tables.c:1139 [inline]
do_ipt_set_ctl+0x2ef/0x492 net/ipv4/netfilter/ip_tables.c:1675
nf_sockopt net/netfilter/nf_sockopt.c:106 [inline]
nf_setsockopt+0x77/0xd0 net/netfilter/nf_sockopt.c:115
ip_setsockopt net/ipv4/ip_sockglue.c:1258 [inline]
ip_setsockopt+0xdf/0x100 net/ipv4/ip_sockglue.c:1238
tcp_setsockopt net/ipv4/tcp.c:3077 [inline]
tcp_setsockopt+0x8f/0xe0 net/ipv4/tcp.c:3071
sock_common_setsockopt+0x94/0xd0 net/core/sock.c:3046
__sys_setsockopt+0x17a/0x280 net/socket.c:1901
__do_sys_setsockopt net/socket.c:1912 [inline]
__se_sys_setsockopt net/socket.c:1909 [inline]
__x64_sys_setsockopt+0xbe/0x150 net/socket.c:1909
do_syscall_64+0xfd/0x620 arch/x86/entry/common.c:293
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x441279
Code: 2e 0a 43 68 65 63 6b 20 65 72 72 6f 72 20 6c 6f 67 20 66 6f 72 20 64 65 74 61 69 6c 73 2c 20 66 69 78 20 65 72 72 6f 72 73 20 <61> 6e 64 20 72 65 73 74 61 72 74 2e 20 41 73 20 61 20 6c 61 73 74
RSP: 002b:00007ffd952a71c8 EFLAGS: 00000246 ORIG_RAX: 0000000000000036
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 0000000000441279
RDX: 0000000000000040 RSI: 0004000000000000 RDI: 0000000000000003
RBP: 00000000000c6500 R08: 0000000000000509 R09: 00000000004002c8
R10: 00000000200002c0 R11: 0000000000000246 R12: 0000000000401ff0
R13: 0000000000402080 R14: 0000000000000000 R15: 0000000000000000

Showing all locks held in the system:
2 locks held by kworker/0:1/14:
1 lock held by khungtaskd/1082:
#0: 00000000a845f339 (rcu_read_lock){....}, at: debug_show_all_locks+0x5f/0x27e kernel/locking/lockdep.c:4438
1 lock held by khugepaged/1089:
#0: 0000000010d96bd1 (pcpu_drain_mutex){+.+.}, at: drain_all_pages+0x4d/0x570 mm/page_alloc.c:2654
1 lock held by rsyslogd/7951:
#0: 00000000133437e1 (&f->f_pos_lock){+.+.}, at: __fdget_pos+0xee/0x110 fs/file.c:767
2 locks held by getty/8073:
#0: 00000000bd457769 (&tty->ldisc_sem){++++}, at: ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:362
#1: 000000007bad4db6 (&ldata->atomic_read_lock){+.+.}, at: n_tty_read+0x232/0x1b70 drivers/tty/n_tty.c:2154
2 locks held by getty/8074:
#0: 00000000aa42c562 (&tty->ldisc_sem){++++}, at: ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:362
#1: 0000000031afbda2 (&ldata->atomic_read_lock){+.+.}, at: n_tty_read+0x232/0x1b70 drivers/tty/n_tty.c:2154
2 locks held by getty/8075:
#0: 00000000f4a5eb02 (&tty->ldisc_sem){++++}, at: ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:362
#1: 000000000cb04ec9 (&ldata->atomic_read_lock){+.+.}, at: n_tty_read+0x232/0x1b70 drivers/tty/n_tty.c:2154
2 locks held by getty/8076:
#0: 000000003867d0a6 (&tty->ldisc_sem){++++}, at: ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:362
#1: 000000006e300308 (&ldata->atomic_read_lock){+.+.}, at: n_tty_read+0x232/0x1b70 drivers/tty/n_tty.c:2154
2 locks held by getty/8077:
#0: 000000008c23ee3a (&tty->ldisc_sem){++++}, at: ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:362
#1: 00000000a658c4a4 (&ldata->atomic_read_lock){+.+.}, at: n_tty_read+0x232/0x1b70 drivers/tty/n_tty.c:2154
2 locks held by getty/8078:
#0: 00000000b1b964e4 (&tty->ldisc_sem){++++}, at: ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:362
#1: 0000000077595b1e (&ldata->atomic_read_lock){+.+.}, at: n_tty_read+0x232/0x1b70 drivers/tty/n_tty.c:2154
2 locks held by getty/8079:
#0: 000000001795ebea (&tty->ldisc_sem){++++}, at: ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:362
#1: 00000000aa928426 (&ldata->atomic_read_lock){+.+.}, at: n_tty_read+0x232/0x1b70 drivers/tty/n_tty.c:2154
1 lock held by syz-executor156/8113:
#0: 00000000c859c9b1 (hashlimit_mutex){+.+.}, at: htable_put+0x21/0x220 net/netfilter/xt_hashlimit.c:440
1 lock held by syz-executor156/8130:
#0: 00000000c859c9b1 (hashlimit_mutex){+.+.}, at: hashlimit_mt_check_common.isra.0+0x341/0x1500 net/netfilter/xt_hashlimit.c:897
1 lock held by syz-executor156/8131:
#0: 00000000c859c9b1 (hashlimit_mutex){+.+.}, at: hashlimit_mt_check_common.isra.0+0x341/0x1500 net/netfilter/xt_hashlimit.c:897
1 lock held by syz-executor156/8133:
#0: 00000000c859c9b1 (hashlimit_mutex){+.+.}, at: hashlimit_mt_check_common.isra.0+0x341/0x1500 net/netfilter/xt_hashlimit.c:897
1 lock held by syz-executor156/8132:
#0: 00000000c859c9b1 (hashlimit_mutex){+.+.}, at: hashlimit_mt_check_common.isra.0+0x341/0x1500 net/netfilter/xt_hashlimit.c:897
1 lock held by syz-executor156/8134:
#0: 00000000c859c9b1 (hashlimit_mutex){+.+.}, at: hashlimit_mt_check_common.isra.0+0x341/0x1500 net/netfilter/xt_hashlimit.c:897

=============================================

NMI backtrace for cpu 1
CPU: 1 PID: 1082 Comm: khungtaskd Not tainted 4.19.97-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x197/0x210 lib/dump_stack.c:118
nmi_cpu_backtrace.cold+0x63/0xa4 lib/nmi_backtrace.c:101
nmi_trigger_cpumask_backtrace+0x1b0/0x1f8 lib/nmi_backtrace.c:62
arch_trigger_cpumask_backtrace+0x14/0x20 arch/x86/kernel/apic/hw_nmi.c:38
trigger_all_cpu_backtrace include/linux/nmi.h:146 [inline]
check_hung_uninterruptible_tasks kernel/hung_task.c:203 [inline]
watchdog+0x9df/0xee0 kernel/hung_task.c:287
kthread+0x354/0x420 kernel/kthread.c:246
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:415
Sending NMI from CPU 1 to CPUs 0:
NMI backtrace for cpu 0
CPU: 0 PID: 14 Comm: kworker/0:1 Not tainted 4.19.97-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Workqueue: events_power_efficient htable_gc
RIP: 0010:lockdep_hardirqs_off+0x83/0x2d0 kernel/locking/lockdep.c:2890
Code: 00 49 8d bd 7c 08 00 00 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 0f b6 14 02 48 89 f8 83 e0 07 83 c0 03 38 d0 7c 08 <84> d2 0f 85 e3 01 00 00 41 8b b5 7c 08 00 00 85 f6 0f 85 16 01 00
RSP: 0018:ffff8880aa3afc00 EFLAGS: 00000002
RAX: 0000000000000007 RBX: ffff8880aa3a0380 RCX: 1ffffffff127906c
RDX: 0000000000000000 RSI: ffffffff81704d39 RDI: ffff8880aa3a0bfc
RBP: ffff8880aa3afc18 R08: ffff8880aa3a0380 R09: fffff52000bd2c0a
R10: fffff52000bd2c09 R11: ffffc90005e9604b R12: ffffffff814033ca
R13: ffff8880aa3a0380 R14: ffffffff814033ca R15: 000000000f4cbc99
FS: 0000000000000000(0000) GS:ffff8880ae800000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00000000200002c0 CR3: 0000000099549000 CR4: 00000000001406f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
trace_hardirqs_off+0x62/0x220 kernel/trace/trace_preemptirq.c:43
__local_bh_enable_ip+0x11a/0x270 kernel/softirq.c:171
__raw_spin_unlock_bh include/linux/spinlock_api_smp.h:176 [inline]
_raw_spin_unlock_bh+0x31/0x40 kernel/locking/spinlock.c:200
spin_unlock_bh include/linux/spinlock.h:374 [inline]
htable_selective_cleanup+0x219/0x330 net/netfilter/xt_hashlimit.c:381
htable_gc+0x26/0xc0 net/netfilter/xt_hashlimit.c:392
process_one_work+0x989/0x1750 kernel/workqueue.c:2153
worker_thread+0x98/0xe40 kernel/workqueue.c:2296
kthread+0x354/0x420 kernel/kthread.c:246
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:415


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this bug, for details see:
https://goo.gl/tpsmEJ#testing-patches

syzbot

unread,
Mar 20, 2020, 9:14:05 PM3/20/20
to syzkaller...@googlegroups.com
syzbot suspects this bug was fixed by commit:

commit 8541452acba5d39c34f81fa7ab1aaca5bc3e4f74
Author: Nathan Chancellor <natecha...@gmail.com>
Date: Fri Feb 14 06:42:07 2020 +0000

s390/mm: Explicitly compare PAGE_DEFAULT_KEY against zero in storage_key_init_range

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=1327a91de00000
start commit: dc4ba5be Linux 4.19.97
git tree: linux-4.19.y
If the result looks correct, please mark the bug fixed by replying with:

#syz fix: s390/mm: Explicitly compare PAGE_DEFAULT_KEY against zero in storage_key_init_range

For information about bisection process see: https://goo.gl/tpsmEJ#bisection
Reply all
Reply to author
Forward
0 new messages