INFO: rcu detected stall in call_timer_fn (2)

6 views
Skip to first unread message

syzbot

unread,
Sep 2, 2020, 6:00:23 PM9/2/20
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: d7e78d08 Linux 4.14.195
git tree: linux-4.14.y
console output: https://syzkaller.appspot.com/x/log.txt?x=133e0271900000
kernel config: https://syzkaller.appspot.com/x/.config?x=6608b656f49b4e8c
dashboard link: https://syzkaller.appspot.com/bug?extid=6a4eff2c8f2f1d434ce2
compiler: gcc (GCC) 10.1.0-syz 20200507

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+6a4eff...@syzkaller.appspotmail.com

libceph: parse_ips bad ip '1��� pcA'
INFO: rcu_preempt detected stalls on CPUs/tasks:
(detected by 1, t=10502 jiffies, g=16072, c=16071, q=840)
All QSes seen, last rcu_preempt kthread activity 10502 (4295005554-4294995052), jiffies_till_next_fqs=1, root ->qsmask 0x0
syz-executor.5 R running task 29320 24897 24629 0x00000008
Call Trace:
<IRQ>
sched_show_task.cold+0x333/0x39a kernel/sched/core.c:5169
print_other_cpu_stall kernel/rcu/tree.c:1501 [inline]
check_cpu_stall kernel/rcu/tree.c:1616 [inline]
__rcu_pending kernel/rcu/tree.c:3390 [inline]
rcu_pending kernel/rcu/tree.c:3452 [inline]
rcu_check_callbacks.cold+0xd29/0xd99 kernel/rcu/tree.c:2792
update_process_times+0x28/0xa0 kernel/time/timer.c:1591
tick_sched_handle+0x7d/0x150 kernel/time/tick-sched.c:165
tick_sched_timer+0x92/0x200 kernel/time/tick-sched.c:1223
__run_hrtimer kernel/time/hrtimer.c:1223 [inline]
__hrtimer_run_queues+0x30b/0xc80 kernel/time/hrtimer.c:1287
hrtimer_interrupt+0x1e6/0x5e0 kernel/time/hrtimer.c:1321
local_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1075 [inline]
smp_apic_timer_interrupt+0x117/0x5e0 arch/x86/kernel/apic/apic.c:1100
apic_timer_interrupt+0x93/0xa0 arch/x86/entry/entry_64.S:793
RIP: 0010:arch_local_irq_restore arch/x86/include/asm/paravirt.h:779 [inline]
RIP: 0010:lock_release+0x41e/0x870 kernel/locking/lockdep.c:4020
RSP: 0018:ffff8880aeb07cb8 EFLAGS: 00000286 ORIG_RAX: ffffffffffffff10
RAX: 1ffffffff0fa2d21 RBX: 1ffff11015d60f9a RCX: 1ffff1100ac1517e
RDX: dffffc0000000000 RSI: 0000000000000002 RDI: 0000000000000286
RBP: ffff8880560a8340 R08: ffffffff8a083e38 R09: 0000000000000001
R10: 0000000000000000 R11: 0000000000000000 R12: e5b39926b5ec0716
R13: 0000000000000003 R14: ffff8880560a8340 R15: 0000000000000002
call_timer_fn+0x197/0x650 kernel/time/timer.c:1283
expire_timers+0x232/0x4d0 kernel/time/timer.c:1319
__run_timers kernel/time/timer.c:1644 [inline]
run_timer_softirq+0x1d5/0x5a0 kernel/time/timer.c:1657
__do_softirq+0x254/0xa1d kernel/softirq.c:288
invoke_softirq kernel/softirq.c:368 [inline]
irq_exit+0x193/0x240 kernel/softirq.c:409
exiting_irq arch/x86/include/asm/apic.h:648 [inline]
smp_apic_timer_interrupt+0x141/0x5e0 arch/x86/kernel/apic/apic.c:1102
apic_timer_interrupt+0x93/0xa0 arch/x86/entry/entry_64.S:793
</IRQ>
RIP: 0010:plist_del+0x0/0x410 lib/plist.c:114
RSP: 0018:ffff888044c57b28 EFLAGS: 00000216 ORIG_RAX: ffffffffffffff10
RAX: 0000000000040000 RBX: ffffc90000c6e808 RCX: ffffc90007cfb000
RDX: 00000000000063a4 RSI: ffffc90000c6e840 RDI: ffff88804afdfb78
RBP: ffff88804afdfb78 R08: ffffffff8a09d980 R09: 0000000000040512
R10: ffff8880560a8bc8 R11: ffff8880560a8340 R12: ffff88804afdfb90
R13: ffff88804afdfbb0 R14: ffffc90000c6e840 R15: 0000000000000001
__unqueue_futex+0x9f/0xf0 kernel/futex.c:1530
mark_wake_futex+0x9e/0x120 kernel/futex.c:1548
futex_wake+0x304/0x3c0 kernel/futex.c:1707
do_futex+0x287/0x1930 kernel/futex.c:3924
SYSC_futex kernel/futex.c:3980 [inline]
SyS_futex+0x1da/0x290 kernel/futex.c:3948
do_syscall_64+0x1d5/0x640 arch/x86/entry/common.c:292
entry_SYSCALL_64_after_hwframe+0x46/0xbb
RIP: 0033:0x45d5b9
RSP: 002b:00007f099b412cf8 EFLAGS: 00000246 ORIG_RAX: 00000000000000ca
RAX: ffffffffffffffda RBX: 000000000118cfe8 RCX: 000000000045d5b9
RDX: 00000000000f4240 RSI: 0000000000000081 RDI: 000000000118cfec
RBP: 000000000118cfe0 R08: 0000000000000009 R09: 0000000000000000
R10: ffffffffffffffff R11: 0000000000000246 R12: 000000000118cfec
R13: 00007ffff65913ff R14: 00007f099b4139c0 R15: 000000000118cfec
rcu_preempt kthread starved for 10502 jiffies! g16072 c16071 f0x2 RCU_GP_WAIT_FQS(3) ->state=0x0 ->cpu=0
rcu_preempt R running task 29552 8 2 0x80000000
Call Trace:
context_switch kernel/sched/core.c:2808 [inline]
__schedule+0x88b/0x1de0 kernel/sched/core.c:3384
schedule+0x8d/0x1b0 kernel/sched/core.c:3428
schedule_timeout+0x4af/0xe90 kernel/time/timer.c:1754
rcu_gp_kthread+0xc0a/0x1e60 kernel/rcu/tree.c:2255
kthread+0x30d/0x420 kernel/kthread.c:232
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:404
Bluetooth: hci5 command 0x040f tx timeout
Cannot find set identified by id 0 to match
Bluetooth: hci5 command 0x0419 tx timeout


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Dec 31, 2020, 5:00:11 PM12/31/20
to syzkaller...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages