INFO: task hung in genl_rcv_msg (2)

5 views
Skip to first unread message

syzbot

unread,
May 13, 2020, 1:22:14 AM5/13/20
to syzkaller...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: ab9dfda2 Linux 4.14.180
git tree: linux-4.14.y
console output: https://syzkaller.appspot.com/x/log.txt?x=152212b2100000
kernel config: https://syzkaller.appspot.com/x/.config?x=221566a7407ce2de
dashboard link: https://syzkaller.appspot.com/bug?extid=8adaf9beb539c7c10bab
compiler: gcc (GCC) 9.0.0 20181231 (experimental)

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+8adaf9...@syzkaller.appspotmail.com

INFO: task syz-executor.1:10605 blocked for more than 140 seconds.
Not tainted 4.14.180-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.1 D29120 10605 6356 0x00000004
Call Trace:
schedule+0x8d/0x1b0 kernel/sched/core.c:3428
schedule_preempt_disabled+0xf/0x20 kernel/sched/core.c:3486
__mutex_lock_common kernel/locking/mutex.c:833 [inline]
__mutex_lock+0x73c/0x1470 kernel/locking/mutex.c:893
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x112/0x140 net/netlink/genetlink.c:623
netlink_rcv_skb+0x127/0x370 net/netlink/af_netlink.c:2433
genl_rcv+0x24/0x40 net/netlink/genetlink.c:636
netlink_unicast_kernel net/netlink/af_netlink.c:1287 [inline]
netlink_unicast+0x437/0x620 net/netlink/af_netlink.c:1313
netlink_sendmsg+0x733/0xbe0 net/netlink/af_netlink.c:1878
sock_sendmsg_nosec net/socket.c:646 [inline]
sock_sendmsg+0xc5/0x100 net/socket.c:656
___sys_sendmsg+0x70a/0x840 net/socket.c:2062
__sys_sendmsg+0xa3/0x120 net/socket.c:2096
SYSC_sendmsg net/socket.c:2107 [inline]
SyS_sendmsg+0x27/0x40 net/socket.c:2103
do_syscall_64+0x1d5/0x640 arch/x86/entry/common.c:292
entry_SYSCALL_64_after_hwframe+0x42/0xb7
RIP: 0033:0x416541
RSP: 002b:00007f04096199c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007f0409619a58 RCX: 0000000000416541
RDX: 0000000000000000 RSI: 00007f0409619a00 RDI: 0000000000000007
RBP: 0000000000000007 R08: 000000000000000b R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000293 R12: 00007f0409619a40
R13: 0000000000000bd3 R14: 00000000004d82e8 R15: 00007f040961a6d4
INFO: task syz-executor.2:10640 blocked for more than 140 seconds.
Not tainted 4.14.180-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.2 D29120 10640 6358 0x00000004
Call Trace:
schedule+0x8d/0x1b0 kernel/sched/core.c:3428
schedule_preempt_disabled+0xf/0x20 kernel/sched/core.c:3486
__mutex_lock_common kernel/locking/mutex.c:833 [inline]
__mutex_lock+0x73c/0x1470 kernel/locking/mutex.c:893
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x112/0x140 net/netlink/genetlink.c:623
netlink_rcv_skb+0x127/0x370 net/netlink/af_netlink.c:2433
genl_rcv+0x24/0x40 net/netlink/genetlink.c:636
netlink_unicast_kernel net/netlink/af_netlink.c:1287 [inline]
netlink_unicast+0x437/0x620 net/netlink/af_netlink.c:1313
netlink_sendmsg+0x733/0xbe0 net/netlink/af_netlink.c:1878
sock_sendmsg_nosec net/socket.c:646 [inline]
sock_sendmsg+0xc5/0x100 net/socket.c:656
___sys_sendmsg+0x70a/0x840 net/socket.c:2062
__sys_sendmsg+0xa3/0x120 net/socket.c:2096
SYSC_sendmsg net/socket.c:2107 [inline]
SyS_sendmsg+0x27/0x40 net/socket.c:2103
do_syscall_64+0x1d5/0x640 arch/x86/entry/common.c:292
entry_SYSCALL_64_after_hwframe+0x42/0xb7
RIP: 0033:0x416541
RSP: 002b:00007ff70a2029c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007ff70a202a58 RCX: 0000000000416541
RDX: 0000000000000000 RSI: 00007ff70a202a00 RDI: 0000000000000004
RBP: 0000000000000004 R08: 000000000000000b R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000293 R12: 00007ff70a202a40
R13: 0000000000000bd3 R14: 00000000004d82e8 R15: 00007ff70a2036d4
INFO: task syz-executor.3:10653 blocked for more than 140 seconds.
Not tainted 4.14.180-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.3 D29120 10653 6360 0x00000004
Call Trace:
schedule+0x8d/0x1b0 kernel/sched/core.c:3428
schedule_preempt_disabled+0xf/0x20 kernel/sched/core.c:3486
__mutex_lock_common kernel/locking/mutex.c:833 [inline]
__mutex_lock+0x73c/0x1470 kernel/locking/mutex.c:893
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x112/0x140 net/netlink/genetlink.c:623
netlink_rcv_skb+0x127/0x370 net/netlink/af_netlink.c:2433
genl_rcv+0x24/0x40 net/netlink/genetlink.c:636
netlink_unicast_kernel net/netlink/af_netlink.c:1287 [inline]
netlink_unicast+0x437/0x620 net/netlink/af_netlink.c:1313
netlink_sendmsg+0x733/0xbe0 net/netlink/af_netlink.c:1878
sock_sendmsg_nosec net/socket.c:646 [inline]
sock_sendmsg+0xc5/0x100 net/socket.c:656
___sys_sendmsg+0x70a/0x840 net/socket.c:2062
__sys_sendmsg+0xa3/0x120 net/socket.c:2096
SYSC_sendmsg net/socket.c:2107 [inline]
SyS_sendmsg+0x27/0x40 net/socket.c:2103
do_syscall_64+0x1d5/0x640 arch/x86/entry/common.c:292
entry_SYSCALL_64_after_hwframe+0x42/0xb7
RIP: 0033:0x416541
RSP: 002b:00007fee1a91b9c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007fee1a91ba58 RCX: 0000000000416541
RDX: 0000000000000000 RSI: 00007fee1a91ba00 RDI: 0000000000000004
RBP: 0000000000000004 R08: 000000000000000b R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000293 R12: 00007fee1a91ba40
R13: 0000000000000bd3 R14: 00000000004d82e8 R15: 00007fee1a91c6d4
INFO: task syz-executor.3:10654 blocked for more than 140 seconds.
Not tainted 4.14.180-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.3 D29120 10654 6360 0x00000004
Call Trace:
schedule+0x8d/0x1b0 kernel/sched/core.c:3428
schedule_preempt_disabled+0xf/0x20 kernel/sched/core.c:3486
__mutex_lock_common kernel/locking/mutex.c:833 [inline]
__mutex_lock+0x73c/0x1470 kernel/locking/mutex.c:893
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x112/0x140 net/netlink/genetlink.c:623
netlink_rcv_skb+0x127/0x370 net/netlink/af_netlink.c:2433
genl_rcv+0x24/0x40 net/netlink/genetlink.c:636
netlink_unicast_kernel net/netlink/af_netlink.c:1287 [inline]
netlink_unicast+0x437/0x620 net/netlink/af_netlink.c:1313
netlink_sendmsg+0x733/0xbe0 net/netlink/af_netlink.c:1878
sock_sendmsg_nosec net/socket.c:646 [inline]
sock_sendmsg+0xc5/0x100 net/socket.c:656
___sys_sendmsg+0x70a/0x840 net/socket.c:2062
__sys_sendmsg+0xa3/0x120 net/socket.c:2096
SYSC_sendmsg net/socket.c:2107 [inline]
SyS_sendmsg+0x27/0x40 net/socket.c:2103
do_syscall_64+0x1d5/0x640 arch/x86/entry/common.c:292
entry_SYSCALL_64_after_hwframe+0x42/0xb7
RIP: 0033:0x416541
RSP: 002b:00007fee1a8fa9c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007fee1a8faa58 RCX: 0000000000416541
RDX: 0000000000000000 RSI: 00007fee1a8faa00 RDI: 0000000000000004
RBP: 0000000000000004 R08: 000000000000000b R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000293 R12: 00007fee1a8faa40
R13: 0000000000000bd3 R14: 00000000004d82e8 R15: 00007fee1a8fb6d4
INFO: task syz-executor.5:10656 blocked for more than 140 seconds.
Not tainted 4.14.180-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.5 D29120 10656 6357 0x00000004
Call Trace:
schedule+0x8d/0x1b0 kernel/sched/core.c:3428
schedule_preempt_disabled+0xf/0x20 kernel/sched/core.c:3486
__mutex_lock_common kernel/locking/mutex.c:833 [inline]
__mutex_lock+0x73c/0x1470 kernel/locking/mutex.c:893
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x112/0x140 net/netlink/genetlink.c:623
netlink_rcv_skb+0x127/0x370 net/netlink/af_netlink.c:2433
genl_rcv+0x24/0x40 net/netlink/genetlink.c:636
netlink_unicast_kernel net/netlink/af_netlink.c:1287 [inline]
netlink_unicast+0x437/0x620 net/netlink/af_netlink.c:1313
netlink_sendmsg+0x733/0xbe0 net/netlink/af_netlink.c:1878
sock_sendmsg_nosec net/socket.c:646 [inline]
sock_sendmsg+0xc5/0x100 net/socket.c:656
___sys_sendmsg+0x70a/0x840 net/socket.c:2062
__sys_sendmsg+0xa3/0x120 net/socket.c:2096
SYSC_sendmsg net/socket.c:2107 [inline]
SyS_sendmsg+0x27/0x40 net/socket.c:2103
do_syscall_64+0x1d5/0x640 arch/x86/entry/common.c:292
entry_SYSCALL_64_after_hwframe+0x42/0xb7
RIP: 0033:0x416541
RSP: 002b:00007f1e313c49c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007f1e313c4a58 RCX: 0000000000416541
RDX: 0000000000000000 RSI: 00007f1e313c4a00 RDI: 0000000000000007
RBP: 0000000000000007 R08: 000000000000000b R09: 0000000000000000
R10: ffffffffffffffff R11: 0000000000000293 R12: 00007f1e313c4a40
R13: 0000000000000bd3 R14: 00000000004d82e8 R15: 00007f1e313c56d4
INFO: task syz-executor.5:10659 blocked for more than 140 seconds.
Not tainted 4.14.180-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.5 D29120 10659 6357 0x00000004
Call Trace:
schedule+0x8d/0x1b0 kernel/sched/core.c:3428
schedule_preempt_disabled+0xf/0x20 kernel/sched/core.c:3486
__mutex_lock_common kernel/locking/mutex.c:833 [inline]
__mutex_lock+0x73c/0x1470 kernel/locking/mutex.c:893
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x112/0x140 net/netlink/genetlink.c:623
netlink_rcv_skb+0x127/0x370 net/netlink/af_netlink.c:2433
genl_rcv+0x24/0x40 net/netlink/genetlink.c:636
netlink_unicast_kernel net/netlink/af_netlink.c:1287 [inline]
netlink_unicast+0x437/0x620 net/netlink/af_netlink.c:1313
netlink_sendmsg+0x733/0xbe0 net/netlink/af_netlink.c:1878
sock_sendmsg_nosec net/socket.c:646 [inline]
sock_sendmsg+0xc5/0x100 net/socket.c:656
___sys_sendmsg+0x70a/0x840 net/socket.c:2062
__sys_sendmsg+0xa3/0x120 net/socket.c:2096
SYSC_sendmsg net/socket.c:2107 [inline]
SyS_sendmsg+0x27/0x40 net/socket.c:2103
do_syscall_64+0x1d5/0x640 arch/x86/entry/common.c:292
entry_SYSCALL_64_after_hwframe+0x42/0xb7
RIP: 0033:0x416541
RSP: 002b:00007f1e313a39c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007f1e313a3a58 RCX: 0000000000416541
RDX: 0000000000000000 RSI: 00007f1e313a3a00 RDI: 0000000000000009
RBP: 0000000000000009 R08: 000000000000000b R09: 0000000000000000
R10: 0000000000000008 R11: 0000000000000293 R12: 00007f1e313a3a40
R13: 0000000000000bd3 R14: 00000000004d82e8 R15: 00007f1e313a46d4
INFO: task syz-executor.5:10661 blocked for more than 140 seconds.
Not tainted 4.14.180-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.5 D29120 10661 6357 0x00000004
Call Trace:
schedule+0x8d/0x1b0 kernel/sched/core.c:3428
schedule_preempt_disabled+0xf/0x20 kernel/sched/core.c:3486
__mutex_lock_common kernel/locking/mutex.c:833 [inline]
__mutex_lock+0x73c/0x1470 kernel/locking/mutex.c:893
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x112/0x140 net/netlink/genetlink.c:623
netlink_rcv_skb+0x127/0x370 net/netlink/af_netlink.c:2433
genl_rcv+0x24/0x40 net/netlink/genetlink.c:636
netlink_unicast_kernel net/netlink/af_netlink.c:1287 [inline]
netlink_unicast+0x437/0x620 net/netlink/af_netlink.c:1313
netlink_sendmsg+0x733/0xbe0 net/netlink/af_netlink.c:1878
sock_sendmsg_nosec net/socket.c:646 [inline]
sock_sendmsg+0xc5/0x100 net/socket.c:656
___sys_sendmsg+0x70a/0x840 net/socket.c:2062
__sys_sendmsg+0xa3/0x120 net/socket.c:2096
SYSC_sendmsg net/socket.c:2107 [inline]
SyS_sendmsg+0x27/0x40 net/socket.c:2103
do_syscall_64+0x1d5/0x640 arch/x86/entry/common.c:292
entry_SYSCALL_64_after_hwframe+0x42/0xb7
RIP: 0033:0x416541
RSP: 002b:00007f1e313619c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007f1e31361a58 RCX: 0000000000416541
RDX: 0000000000000000 RSI: 00007f1e31361a00 RDI: 0000000000000007
RBP: 0000000000000007 R08: 000000000000000b R09: 0000000000000000
R10: 0000000000000006 R11: 0000000000000293 R12: 00007f1e31361a40
R13: 0000000000000bd3 R14: 00000000004d82e8 R15: 00007f1e313626d4
INFO: task syz-executor.5:10662 blocked for more than 140 seconds.
Not tainted 4.14.180-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.5 D29120 10662 6357 0x00000004
Call Trace:
schedule+0x8d/0x1b0 kernel/sched/core.c:3428
schedule_preempt_disabled+0xf/0x20 kernel/sched/core.c:3486
__mutex_lock_common kernel/locking/mutex.c:833 [inline]
__mutex_lock+0x73c/0x1470 kernel/locking/mutex.c:893
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x112/0x140 net/netlink/genetlink.c:623
netlink_rcv_skb+0x127/0x370 net/netlink/af_netlink.c:2433
genl_rcv+0x24/0x40 net/netlink/genetlink.c:636
netlink_unicast_kernel net/netlink/af_netlink.c:1287 [inline]
netlink_unicast+0x437/0x620 net/netlink/af_netlink.c:1313
netlink_sendmsg+0x733/0xbe0 net/netlink/af_netlink.c:1878
sock_sendmsg_nosec net/socket.c:646 [inline]
sock_sendmsg+0xc5/0x100 net/socket.c:656
___sys_sendmsg+0x70a/0x840 net/socket.c:2062
__sys_sendmsg+0xa3/0x120 net/socket.c:2096
SYSC_sendmsg net/socket.c:2107 [inline]
SyS_sendmsg+0x27/0x40 net/socket.c:2103
do_syscall_64+0x1d5/0x640 arch/x86/entry/common.c:292
entry_SYSCALL_64_after_hwframe+0x42/0xb7
RIP: 0033:0x416541
RSP: 002b:00007f1e313409c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007f1e31340a58 RCX: 0000000000416541
RDX: 0000000000000000 RSI: 00007f1e31340a00 RDI: 0000000000000009
RBP: 0000000000000009 R08: 000000000000000b R09: 0000000000000000
R10: 00007f1e313419d0 R11: 0000000000000293 R12: 00007f1e31340a40
R13: 0000000000000bd3 R14: 00000000004d82e8 R15: 00007f1e313416d4
INFO: task syz-executor.4:10665 blocked for more than 140 seconds.
Not tainted 4.14.180-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.4 D29072 10665 6359 0x00000004
Call Trace:
schedule+0x8d/0x1b0 kernel/sched/core.c:3428
schedule_preempt_disabled+0xf/0x20 kernel/sched/core.c:3486
__mutex_lock_common kernel/locking/mutex.c:833 [inline]
__mutex_lock+0x73c/0x1470 kernel/locking/mutex.c:893
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x112/0x140 net/netlink/genetlink.c:623
netlink_rcv_skb+0x127/0x370 net/netlink/af_netlink.c:2433
genl_rcv+0x24/0x40 net/netlink/genetlink.c:636
netlink_unicast_kernel net/netlink/af_netlink.c:1287 [inline]
netlink_unicast+0x437/0x620 net/netlink/af_netlink.c:1313
netlink_sendmsg+0x733/0xbe0 net/netlink/af_netlink.c:1878
sock_sendmsg_nosec net/socket.c:646 [inline]
sock_sendmsg+0xc5/0x100 net/socket.c:656
___sys_sendmsg+0x70a/0x840 net/socket.c:2062
__sys_sendmsg+0xa3/0x120 net/socket.c:2096
SYSC_sendmsg net/socket.c:2107 [inline]
SyS_sendmsg+0x27/0x40 net/socket.c:2103
do_syscall_64+0x1d5/0x640 arch/x86/entry/common.c:292
entry_SYSCALL_64_after_hwframe+0x42/0xb7
RIP: 0033:0x416541
RSP: 002b:00007fe0f08ce9c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007fe0f08cea58 RCX: 0000000000416541
RDX: 0000000000000000 RSI: 00007fe0f08cea00 RDI: 000000000000000e
RBP: 000000000000000e R08: 0000000000000009 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000293 R12: 00007fe0f08cea40
R13: 0000000000000bc3 R14: 00000000004d8070 R15: 00007fe0f08cf6d4
INFO: task syz-executor.4:10667 blocked for more than 140 seconds.
Not tainted 4.14.180-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.4 D29120 10667 6359 0x00000004
Call Trace:
schedule+0x8d/0x1b0 kernel/sched/core.c:3428
schedule_preempt_disabled+0xf/0x20 kernel/sched/core.c:3486
__mutex_lock_common kernel/locking/mutex.c:833 [inline]
__mutex_lock+0x73c/0x1470 kernel/locking/mutex.c:893
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x112/0x140 net/netlink/genetlink.c:623
netlink_rcv_skb+0x127/0x370 net/netlink/af_netlink.c:2433
genl_rcv+0x24/0x40 net/netlink/genetlink.c:636
netlink_unicast_kernel net/netlink/af_netlink.c:1287 [inline]
netlink_unicast+0x437/0x620 net/netlink/af_netlink.c:1313
netlink_sendmsg+0x733/0xbe0 net/netlink/af_netlink.c:1878
sock_sendmsg_nosec net/socket.c:646 [inline]
sock_sendmsg+0xc5/0x100 net/socket.c:656
___sys_sendmsg+0x70a/0x840 net/socket.c:2062
__sys_sendmsg+0xa3/0x120 net/socket.c:2096
SYSC_sendmsg net/socket.c:2107 [inline]
SyS_sendmsg+0x27/0x40 net/socket.c:2103
do_syscall_64+0x1d5/0x640 arch/x86/entry/common.c:292
entry_SYSCALL_64_after_hwframe+0x42/0xb7
RIP: 0033:0x416541
RSP: 002b:00007fe0f088c9c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007fe0f088ca58 RCX: 0000000000416541
RDX: 0000000000000000 RSI: 00007fe0f088ca00 RDI: 000000000000000e
RBP: 000000000000000e R08: 0000000000000009 R09: 0000000000000000
R10: 000000000000000d R11: 0000000000000293 R12: 00007fe0f088ca40
R13: 0000000000000bc3 R14: 00000000004d8070 R15: 00007fe0f088d6d4

Showing all locks held in the system:
1 lock held by khungtaskd/1057:
#0: (tasklist_lock){.+.+}, at: [<ffffffff81465d33>] debug_show_all_locks+0x7c/0x21a kernel/locking/lockdep.c:4548
2 locks held by syz-executor.1/10605:
#0: (cb_lock){++++}, at: [<ffffffff851e7035>] genl_rcv+0x15/0x40 net/netlink/genetlink.c:635
#1: (genl_mutex){+.+.}, at: [<ffffffff851ea5a2>] genl_lock net/netlink/genetlink.c:33 [inline]
#1: (genl_mutex){+.+.}, at: [<ffffffff851ea5a2>] genl_rcv_msg+0x112/0x140 net/netlink/genetlink.c:623
2 locks held by syz-executor.2/10640:
#0: (cb_lock){++++}, at: [<ffffffff851e7035>] genl_rcv+0x15/0x40 net/netlink/genetlink.c:635
#1: (genl_mutex){+.+.}, at: [<ffffffff851ea5a2>] genl_lock net/netlink/genetlink.c:33 [inline]
#1: (genl_mutex){+.+.}, at: [<ffffffff851ea5a2>] genl_rcv_msg+0x112/0x140 net/netlink/genetlink.c:623
2 locks held by syz-executor.3/10653:
#0: (cb_lock){++++}, at: [<ffffffff851e7035>] genl_rcv+0x15/0x40 net/netlink/genetlink.c:635
#1: (genl_mutex){+.+.}, at: [<ffffffff851ea5a2>] genl_lock net/netlink/genetlink.c:33 [inline]
#1: (genl_mutex){+.+.}, at: [<ffffffff851ea5a2>] genl_rcv_msg+0x112/0x140 net/netlink/genetlink.c:623
2 locks held by syz-executor.3/10654:
#0: (cb_lock){++++}, at: [<ffffffff851e7035>] genl_rcv+0x15/0x40 net/netlink/genetlink.c:635
#1: (genl_mutex){+.+.}, at: [<ffffffff851ea5a2>] genl_lock net/netlink/genetlink.c:33 [inline]
#1: (genl_mutex){+.+.}, at: [<ffffffff851ea5a2>] genl_rcv_msg+0x112/0x140 net/netlink/genetlink.c:623
2 locks held by syz-executor.5/10656:
#0: (cb_lock){++++}, at: [<ffffffff851e7035>] genl_rcv+0x15/0x40 net/netlink/genetlink.c:635
#1: (genl_mutex){+.+.}, at: [<ffffffff851ea5a2>] genl_lock net/netlink/genetlink.c:33 [inline]
#1: (genl_mutex){+.+.}, at: [<ffffffff851ea5a2>] genl_rcv_msg+0x112/0x140 net/netlink/genetlink.c:623
2 locks held by syz-executor.5/10659:
#0: (cb_lock){++++}, at: [<ffffffff851e7035>] genl_rcv+0x15/0x40 net/netlink/genetlink.c:635
#1: (genl_mutex){+.+.}, at: [<ffffffff851ea5a2>] genl_lock net/netlink/genetlink.c:33 [inline]
#1: (genl_mutex){+.+.}, at: [<ffffffff851ea5a2>] genl_rcv_msg+0x112/0x140 net/netlink/genetlink.c:623
2 locks held by syz-executor.5/10661:
#0: (cb_lock){++++}, at: [<ffffffff851e7035>] genl_rcv+0x15/0x40 net/netlink/genetlink.c:635
#1: (genl_mutex){+.+.}, at: [<ffffffff851ea5a2>] genl_lock net/netlink/genetlink.c:33 [inline]
#1: (genl_mutex){+.+.}, at: [<ffffffff851ea5a2>] genl_rcv_msg+0x112/0x140 net/netlink/genetlink.c:623
2 locks held by syz-executor.5/10662:
#0: (cb_lock){++++}, at: [<ffffffff851e7035>] genl_rcv+0x15/0x40 net/netlink/genetlink.c:635
#1: (genl_mutex){+.+.}, at: [<ffffffff851ea5a2>] genl_lock net/netlink/genetlink.c:33 [inline]
#1: (genl_mutex){+.+.}, at: [<ffffffff851ea5a2>] genl_rcv_msg+0x112/0x140 net/netlink/genetlink.c:623
2 locks held by syz-executor.4/10665:
#0: (cb_lock){++++}, at: [<ffffffff851e7035>] genl_rcv+0x15/0x40 net/netlink/genetlink.c:635
#1: (genl_mutex){+.+.}, at: [<ffffffff851ea5a2>] genl_lock net/netlink/genetlink.c:33 [inline]
#1: (genl_mutex){+.+.}, at: [<ffffffff851ea5a2>] genl_rcv_msg+0x112/0x140 net/netlink/genetlink.c:623
2 locks held by syz-executor.4/10667:
#0: (cb_lock){++++}, at: [<ffffffff851e7035>] genl_rcv+0x15/0x40 net/netlink/genetlink.c:635
#1: (genl_mutex){+.+.}, at: [<ffffffff851ea5a2>] genl_lock net/netlink/genetlink.c:33 [inline]
#1: (genl_mutex){+.+.}, at: [<ffffffff851ea5a2>] genl_rcv_msg+0x112/0x140 net/netlink/genetlink.c:623

=============================================

NMI backtrace for cpu 1
CPU: 1 PID: 1057 Comm: khungtaskd Not tainted 4.14.180-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:17 [inline]
dump_stack+0x13e/0x194 lib/dump_stack.c:58
nmi_cpu_backtrace.cold+0x57/0x93 lib/nmi_backtrace.c:101
nmi_trigger_cpumask_backtrace+0x139/0x17e lib/nmi_backtrace.c:62
trigger_all_cpu_backtrace include/linux/nmi.h:140 [inline]
check_hung_uninterruptible_tasks kernel/hung_task.c:195 [inline]
watchdog+0x5e2/0xb80 kernel/hung_task.c:274
kthread+0x30d/0x420 kernel/kthread.c:232
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:404
Sending NMI from CPU 1 to CPUs 0:
NMI backtrace for cpu 0
CPU: 0 PID: 10602 Comm: syz-executor.1 Not tainted 4.14.180-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
task: ffff88808cf1e000 task.stack: ffff88821a8a8000
RIP: 0010:debug_lockdep_rcu_enabled.part.0+0x3d/0x50 kernel/rcu/update.c:299
RSP: 0018:ffff88821a8aefd0 EFLAGS: 00000246
RAX: 0000000000000007 RBX: ffff88808cf1e000 RCX: 1ffffffff10279fc
RDX: 0000000000000000 RSI: ffffffff860ec29b RDI: ffff88808cf1e884
RBP: ffff88805af54880 R08: 0000000000000000 R09: 0000000000020012
R10: ffff88808cf1e900 R11: ffff88808cf1e000 R12: 0000000000000000
R13: dffffc0000000000 R14: 1ffff11043515e03 R15: ffff88805af5597e
FS: 00007f040963b700(0000) GS:ffff8880aea00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fa56afc2020 CR3: 000000020ab3d000 CR4: 00000000001406f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
debug_lockdep_rcu_enabled kernel/rcu/update.c:299 [inline]
rcu_read_lock_held+0x6d/0xc0 kernel/rcu/update.c:326
__rhashtable_lookup include/linux/rhashtable.h:626 [inline]
rhashtable_lookup include/linux/rhashtable.h:650 [inline]
rhashtable_lookup_fast include/linux/rhashtable.h:676 [inline]
tipc_sk_lookup+0x610/0x920 net/tipc/socket.c:2287
tipc_nl_publ_dump+0x197/0xbd8 net/tipc/socket.c:2894
__tipc_nl_compat_dumpit.isra.0+0x190/0x790 net/tipc/netlink_compat.c:203
tipc_nl_compat_publ_dump net/tipc/netlink_compat.c:999 [inline]
tipc_nl_compat_sk_dump+0x4a5/0x830 net/tipc/netlink_compat.c:1050
__tipc_nl_compat_dumpit.isra.0+0x254/0x790 net/tipc/netlink_compat.c:212
tipc_nl_compat_dumpit+0x20d/0x4c0 net/tipc/netlink_compat.c:283
tipc_nl_compat_handle net/tipc/netlink_compat.c:1224 [inline]
tipc_nl_compat_recv+0x851/0xa10 net/tipc/netlink_compat.c:1287
genl_family_rcv_msg+0x57c/0xb30 net/netlink/genetlink.c:600
genl_rcv_msg+0xaf/0x140 net/netlink/genetlink.c:625
netlink_rcv_skb+0x127/0x370 net/netlink/af_netlink.c:2433
genl_rcv+0x24/0x40 net/netlink/genetlink.c:636
netlink_unicast_kernel net/netlink/af_netlink.c:1287 [inline]
netlink_unicast+0x437/0x620 net/netlink/af_netlink.c:1313
netlink_sendmsg+0x733/0xbe0 net/netlink/af_netlink.c:1878
sock_sendmsg_nosec net/socket.c:646 [inline]
sock_sendmsg+0xc5/0x100 net/socket.c:656
___sys_sendmsg+0x70a/0x840 net/socket.c:2062
__sys_sendmsg+0xa3/0x120 net/socket.c:2096
SYSC_sendmsg net/socket.c:2107 [inline]
SyS_sendmsg+0x27/0x40 net/socket.c:2103
do_syscall_64+0x1d5/0x640 arch/x86/entry/common.c:292
entry_SYSCALL_64_after_hwframe+0x42/0xb7
RIP: 0033:0x45c829
RSP: 002b:00007f040963ac78 EFLAGS: 00000246 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00000000004ffee0 RCX: 000000000045c829
RDX: 0000000000000000 RSI: 0000000020000640 RDI: 000000000000000a
RBP: 000000000078bf00 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 00000000ffffffff
R13: 00000000000009cc R14: 00000000004d6140 R15: 00007f040963b6d4
Code: 01 00 48 8d bb 84 08 00 00 48 89 fa 48 c1 ea 03 0f b6 14 02 48 89 f8 83 e0 07 83 c0 03 38 d0 7c 04 84 d2 75 0f 8b 93 84 08 00 00 <31> c0 5b 85 d2 0f 94 c0 c3 e8 e5 a7 38 00 eb ea 0f 1f 00 48 c7


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Mar 17, 2021, 7:44:16 PM3/17/21
to syzkaller...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages