Hello,
syzbot found the following crash on:
HEAD commit: 4d552acf Linux 4.19.34
git tree: linux-4.19.y
console output:
https://syzkaller.appspot.com/x/log.txt?x=161fe6b7200000
kernel config:
https://syzkaller.appspot.com/x/.config?x=c95a88291f095edd
dashboard link:
https://syzkaller.appspot.com/bug?extid=e716aef347d472a5333a
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
Unfortunately, I don't have any reproducer for this crash yet.
IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by:
syzbot+e716ae...@syzkaller.appspotmail.com
cannot load conntrack support for proto=7
INFO: task syz-executor.1:11853 blocked for more than 140 seconds.
Not tainted 4.19.34 #2
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.1 D28088 11853 7998 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2826 [inline]
__schedule+0x817/0x1d00 kernel/sched/core.c:3474
schedule+0x92/0x1c0 kernel/sched/core.c:3518
schedule_timeout+0x8ca/0xfd0 kernel/time/timer.c:1780
do_wait_for_common kernel/sched/completion.c:83 [inline]
__wait_for_common kernel/sched/completion.c:104 [inline]
wait_for_common kernel/sched/completion.c:115 [inline]
wait_for_completion_timeout+0x2b9/0x480 kernel/sched/completion.c:155
usb_start_wait_urb+0x173/0x2f0 drivers/usb/core/message.c:62
usb_bulk_msg+0x229/0x550 drivers/usb/core/message.c:253
proc_bulk+0x488/0x820 drivers/usb/core/devio.c:1193
usbdev_do_ioctl+0x675/0x2f10 drivers/usb/core/devio.c:2419
usbdev_ioctl+0x26/0x30 drivers/usb/core/devio.c:2569
vfs_ioctl fs/ioctl.c:46 [inline]
file_ioctl fs/ioctl.c:501 [inline]
do_vfs_ioctl+0xd6e/0x1390 fs/ioctl.c:688
ksys_ioctl+0xab/0xd0 fs/ioctl.c:705
__do_sys_ioctl fs/ioctl.c:712 [inline]
__se_sys_ioctl fs/ioctl.c:710 [inline]
__x64_sys_ioctl+0x73/0xb0 fs/ioctl.c:710
do_syscall_64+0x103/0x610 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x458c29
Code: Bad RIP value.
RSP: 002b:00007fe410e47c78 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000003 RCX: 0000000000458c29
RDX: 0000000020000080 RSI: 00000000c0185502 RDI: 0000000000000003
RBP: 000000000073bf00 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 00007fe410e486d4
R13: 00000000004c1161 R14: 00000000004d3758 R15: 00000000ffffffff
Showing all locks held in the system:
1 lock held by khungtaskd/1035:
#0: 00000000aad2f7d6 (rcu_read_lock){....}, at:
debug_show_all_locks+0x5f/0x27e kernel/locking/lockdep.c:4438
1 lock held by rsyslogd/7833:
#0: 00000000297d673d (&f->f_pos_lock){+.+.}, at: __fdget_pos+0xee/0x110
fs/file.c:767
2 locks held by getty/7955:
#0: 00000000ccc88210 (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:363
#1: 000000002d5f92ad (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x232/0x1b30 drivers/tty/n_tty.c:2154
2 locks held by getty/7956:
#0: 000000007d035de6 (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:363
#1: 0000000046123bb1 (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x232/0x1b30 drivers/tty/n_tty.c:2154
2 locks held by getty/7957:
#0: 00000000f33b2d1a (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:363
#1: 00000000283af3fc (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x232/0x1b30 drivers/tty/n_tty.c:2154
2 locks held by getty/7958:
#0: 000000000fbb36e3 (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:363
#1: 00000000a52ab78e (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x232/0x1b30 drivers/tty/n_tty.c:2154
2 locks held by getty/7959:
#0: 00000000252005f5 (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:363
#1: 00000000002dc609 (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x232/0x1b30 drivers/tty/n_tty.c:2154
2 locks held by getty/7960:
#0: 0000000029984d2a (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:363
#1: 00000000836be68b (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x232/0x1b30 drivers/tty/n_tty.c:2154
2 locks held by getty/7961:
#0: 000000000716b2bc (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:363
#1: 00000000da61119f (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x232/0x1b30 drivers/tty/n_tty.c:2154
=============================================
NMI backtrace for cpu 1
CPU: 1 PID: 1035 Comm: khungtaskd Not tainted 4.19.34 #2
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x172/0x1f0 lib/dump_stack.c:113
nmi_cpu_backtrace.cold+0x63/0xa4 lib/nmi_backtrace.c:101
nmi_trigger_cpumask_backtrace+0x1b0/0x1f8 lib/nmi_backtrace.c:62
arch_trigger_cpumask_backtrace+0x14/0x20 arch/x86/kernel/apic/hw_nmi.c:38
trigger_all_cpu_backtrace include/linux/nmi.h:146 [inline]
check_hung_uninterruptible_tasks kernel/hung_task.c:202 [inline]
watchdog+0x9c6/0xec0 kernel/hung_task.c:263
kthread+0x357/0x430 kernel/kthread.c:246
ret_from_fork+0x3a/0x50 arch/x86/entry/entry_64.S:413
Sending NMI from CPU 1 to CPUs 0:
NMI backtrace for cpu 0
CPU: 0 PID: 3598 Comm: udevd Not tainted 4.19.34 #2
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
RIP: 0010:__read_once_size include/linux/compiler.h:190 [inline]
RIP: 0010:list_empty include/linux/list.h:203 [inline]
RIP: 0010:ep_send_events_proc+0x23f/0xc10 fs/eventpoll.c:1642
Code: ff e8 25 05 ae ff 8b b5 68 ff ff ff 4c 8b 85 60 ff ff ff 85 f6 0f 85
9f 04 00 00 e8 8b 03 ae ff 48 8b 85 70 ff ff ff 80 38 00 <0f> 85 c1 07 00
00 49 8b 07 49 39 c7 0f 84 39 04 00 00 e8 6a 03 ae
RSP: 0018:ffff8880960dfb10 EFLAGS: 00000246
RAX: ffffed1012c1bf8c RBX: dffffc0000000000 RCX: 0000000000000000
RDX: 0000000000000000 RSI: ffffffff81bd33b5 RDI: ffff8880960dfdc8
RBP: ffff8880960dfbe8 R08: ffff8880960d00c0 R09: ffff8880960d0960
R10: 0000000000000000 R11: 0000000000000000 R12: dffffc0000000000
R13: ffff8880960dfdc0 R14: ffff8880960dfdc0 R15: ffff8880960dfc60
FS: 00007f2fb98e77a0(0000) GS:ffff8880ae800000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000458bff CR3: 000000009673a000 CR4: 00000000001406f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000600
Call Trace:
ep_scan_ready_list+0x308/0xb20 fs/eventpoll.c:708
ep_send_events fs/eventpoll.c:1713 [inline]
ep_poll+0x3b4/0xd10 fs/eventpoll.c:1840
do_epoll_wait+0x1b3/0x200 fs/eventpoll.c:2198
__do_sys_epoll_wait fs/eventpoll.c:2208 [inline]
__se_sys_epoll_wait fs/eventpoll.c:2205 [inline]
__x64_sys_epoll_wait+0x97/0xf0 fs/eventpoll.c:2205
do_syscall_64+0x103/0x610 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x7f2fb8ffb943
Code: 00 31 d2 48 29 c2 64 89 11 48 83 c8 ff eb ea 90 90 90 90 90 90 90 90
83 3d b5 dc 2a 00 00 75 13 49 89 ca b8 e8 00 00 00 0f 05 <48> 3d 01 f0 ff
ff 73 34 c3 48 83 ec 08 e8 3b c4 00 00 48 89 04 24
RSP: 002b:00007fff323f54f8 EFLAGS: 00000246 ORIG_RAX: 00000000000000e8
RAX: ffffffffffffffda RBX: 0000000000000bb8 RCX: 00007f2fb8ffb943
RDX: 0000000000000008 RSI: 00007fff323f55f0 RDI: 000000000000000a
RBP: 0000000000000001 R08: 0000000000000000 R09: 0000000000000001
R10: 0000000000000bb8 R11: 0000000000000246 R12: 0000000000000003
R13: 0000000000000000 R14: 0000000000d33200 R15: 0000000000d1e030
---
This bug is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.