INFO: rcu detected stall in chrdev_open (3)

4 views
Skip to first unread message

syzbot

unread,
Mar 22, 2021, 3:09:15 PM3/22/21
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 12522281 Linux 4.19.182
git tree: linux-4.19.y
console output: https://syzkaller.appspot.com/x/log.txt?x=15c5573ad00000
kernel config: https://syzkaller.appspot.com/x/.config?x=2211c6daad8bbe0
dashboard link: https://syzkaller.appspot.com/bug?extid=ac22ddb8d624dc741fad

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+ac22dd...@syzkaller.appspotmail.com

wlan1: RX AssocResp from 08:02:11:00:00:00 (capab=0x1 status=0 aid=1)
mac80211_hwsim: wmediumd released netlink socket, switching to perfect channel medium
IPv6: ADDRCONF(NETDEV_CHANGE): wlan1: link becomes ready
wlan1: associated
rcu: INFO: rcu_preempt detected stalls on CPUs/tasks:
rcu: (detected by 0, t=10502 jiffies, g=30917, q=142)
rcu: All QSes seen, last rcu_preempt kthread activity 10502 (4294974056-4294963554), jiffies_till_next_fqs=1, root ->qsmask 0x0
syz-executor.4 R running task 27248 15948 8132 0x00000000
Call Trace:
<IRQ>
sched_show_task.cold+0x332/0x396 kernel/sched/core.c:5337
print_other_cpu_stall kernel/rcu/tree.c:1430 [inline]
check_cpu_stall kernel/rcu/tree.c:1557 [inline]
__rcu_pending kernel/rcu/tree.c:3293 [inline]
rcu_pending kernel/rcu/tree.c:3336 [inline]
rcu_check_callbacks.cold+0xb37/0xe19 kernel/rcu/tree.c:2682
update_process_times+0x2a/0x70 kernel/time/timer.c:1650
tick_sched_handle+0x9b/0x180 kernel/time/tick-sched.c:168
tick_sched_timer+0xfc/0x290 kernel/time/tick-sched.c:1278
__run_hrtimer kernel/time/hrtimer.c:1419 [inline]
__hrtimer_run_queues+0x3f6/0xe60 kernel/time/hrtimer.c:1481
hrtimer_interrupt+0x326/0x9e0 kernel/time/hrtimer.c:1539
local_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1071 [inline]
smp_apic_timer_interrupt+0x10c/0x550 arch/x86/kernel/apic/apic.c:1096
apic_timer_interrupt+0xf/0x20 arch/x86/entry/entry_64.S:894
</IRQ>
RIP: 0010:arch_local_irq_restore arch/x86/include/asm/paravirt.h:789 [inline]
RIP: 0010:kfree+0x123/0x210 mm/slab.c:3823
Code: 89 ea 48 89 ee 4c 89 e7 e8 da ee ff ff f6 c7 02 74 ca e8 00 94 cf ff 48 83 3d 60 93 59 08 00 0f 84 eb 00 00 00 48 89 df 57 9d <0f> 1f 44 00 00 5b 5d 41 5c 41 5d c3 65 8b 05 2a 92 69 7e 83 f8 07
RSP: 0018:ffff8880569c78e8 EFLAGS: 00000286 ORIG_RAX: ffffffffffffff13
RAX: 0000000000000007 RBX: 0000000000000286 RCX: 0000000000000000
RDX: 0000000000000000 RSI: 0000000000000001 RDI: 0000000000000286
RBP: ffff88809e883c00 R08: 0000000000400000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: ffff88813bff01c0
R13: ffffffff83b791e7 R14: fffffffffffffff5 R15: 0000000000400043
tty_free_file drivers/tty/tty_io.c:220 [inline]
tty_open+0x5a7/0x990 drivers/tty/tty_io.c:2032
chrdev_open+0x266/0x770 fs/char_dev.c:423
do_dentry_open+0x4aa/0x1160 fs/open.c:796
do_last fs/namei.c:3421 [inline]
path_openat+0x793/0x2df0 fs/namei.c:3537
do_filp_open+0x18c/0x3f0 fs/namei.c:3567
do_sys_open+0x3b3/0x520 fs/open.c:1085
do_syscall_64+0xf9/0x620 arch/x86/entry/common.c:293
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x466459
Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 bc ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fc3fe110188 EFLAGS: 00000246 ORIG_RAX: 0000000000000101
RAX: ffffffffffffffda RBX: 000000000056bf60 RCX: 0000000000466459
RDX: 0000000000000802 RSI: 0000000020000840 RDI: ffffffffffffff9c
RBP: 00000000004bf9fb R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 000000000056bf60
R13: 00007fff13953f6f R14: 00007fc3fe110300 R15: 0000000000022000
rcu: rcu_preempt kthread starved for 10502 jiffies! g30917 f0x2 RCU_GP_WAIT_FQS(5) ->state=0x0 ->cpu=0
rcu: RCU grace-period kthread stack dump:
rcu_preempt R running task 29208 10 2 0x80000000
Call Trace:
context_switch kernel/sched/core.c:2828 [inline]
__schedule+0x887/0x2040 kernel/sched/core.c:3517
schedule+0x8d/0x1b0 kernel/sched/core.c:3561
schedule_timeout+0x4cf/0xfe0 kernel/time/timer.c:1818
rcu_gp_kthread+0xdad/0x21c0 kernel/rcu/tree.c:2202
kthread+0x33f/0x460 kernel/kthread.c:259
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:415


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Mar 22, 2021, 7:14:18 PM3/22/21
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 12522281 Linux 4.19.182
git tree: linux-4.19.y
console output: https://syzkaller.appspot.com/x/log.txt?x=13404826d00000
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=14e27bb2d00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=12fb4e62d00000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+ac22dd...@syzkaller.appspotmail.com

rcu: INFO: rcu_preempt detected stalls on CPUs/tasks:
rcu: (detected by 0, t=10502 jiffies, g=5245, q=53)
rcu: All QSes seen, last rcu_preempt kthread activity 10503 (4294998001-4294987498), jiffies_till_next_fqs=1, root ->qsmask 0x0
syz-executor554 R running task 26984 8175 8095 0x00000000
Call Trace:
<IRQ>
sched_show_task.cold+0x332/0x396 kernel/sched/core.c:5337
print_other_cpu_stall kernel/rcu/tree.c:1430 [inline]
check_cpu_stall kernel/rcu/tree.c:1557 [inline]
__rcu_pending kernel/rcu/tree.c:3293 [inline]
rcu_pending kernel/rcu/tree.c:3336 [inline]
rcu_check_callbacks.cold+0xb37/0xe19 kernel/rcu/tree.c:2682
update_process_times+0x2a/0x70 kernel/time/timer.c:1650
tick_sched_handle+0x9b/0x180 kernel/time/tick-sched.c:168
tick_sched_timer+0xfc/0x290 kernel/time/tick-sched.c:1278
__run_hrtimer kernel/time/hrtimer.c:1419 [inline]
__hrtimer_run_queues+0x3f6/0xe60 kernel/time/hrtimer.c:1481
hrtimer_interrupt+0x326/0x9e0 kernel/time/hrtimer.c:1539
local_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1071 [inline]
smp_apic_timer_interrupt+0x10c/0x550 arch/x86/kernel/apic/apic.c:1096
apic_timer_interrupt+0xf/0x20 arch/x86/entry/entry_64.S:894
</IRQ>
RIP: 0010:get_current arch/x86/include/asm/current.h:15 [inline]
RIP: 0010:__sanitizer_cov_trace_pc+0x4/0x50 kernel/kcov.c:100
Code: e8 c1 c1 35 00 e9 ab fe ff ff 4c 89 ef e8 b4 c1 35 00 e9 23 fe ff ff 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 48 8b 34 24 <65> 48 8b 04 25 80 df 01 00 65 8b 15 7c 84 9f 7e 81 e2 00 01 1f 00
RSP: 0018:ffff888094cb7858 EFLAGS: 00000293 ORIG_RAX: ffffffffffffff13
RAX: ffff8880b0144680 RBX: ffffffff8a45d1e0 RCX: 0000000000000001
RDX: 0000000000000000 RSI: ffffffff8375be65 RDI: ffffffff88b3c180
RBP: ffffffff88b3c180 R08: 00000000006000c0 R09: 0000000000000003
R10: 00000000b0f57453 R11: 000000001c8f048c R12: ffff8880a296ce00
R13: ffffffff88b3c140 R14: 0000000000000020 R15: ffffffff83b78d78
check_preemption_disabled+0x15/0x280 lib/smp_processor_id.c:13
rcu_dynticks_curr_cpu_in_eqs kernel/rcu/tree.c:348 [inline]
rcu_is_watching+0x12/0xc0 kernel/rcu/tree.c:1025
rcu_read_lock_sched_held+0xc6/0x1d0 kernel/rcu/update.c:113
trace_kmalloc include/trace/events/kmem.h:46 [inline]
kmem_cache_alloc_trace+0x323/0x380 mm/slab.c:3626
kmalloc include/linux/slab.h:515 [inline]
tty_alloc_file drivers/tty/tty_io.c:187 [inline]
tty_open+0x138/0x990 drivers/tty/tty_io.c:2023
chrdev_open+0x266/0x770 fs/char_dev.c:423
do_dentry_open+0x4aa/0x1160 fs/open.c:796
do_last fs/namei.c:3421 [inline]
path_openat+0x793/0x2df0 fs/namei.c:3537
do_filp_open+0x18c/0x3f0 fs/namei.c:3567
do_sys_open+0x3b3/0x520 fs/open.c:1085
do_syscall_64+0xf9/0x620 arch/x86/entry/common.c:293
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x445a39
Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 11 15 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f2430ff3308 EFLAGS: 00000246 ORIG_RAX: 0000000000000101
RAX: ffffffffffffffda RBX: 00000000004ca408 RCX: 0000000000445a39
RDX: 0000000000000802 RSI: 0000000020000840 RDI: ffffffffffffff9c
RBP: 00000000004ca400 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 00000000004ca40c
R13: 000000000049a074 R14: 7974742f7665642f R15: 0000000000022000
rcu: rcu_preempt kthread starved for 10540 jiffies! g5245 f0x2 RCU_GP_WAIT_FQS(5) ->state=0x0 ->cpu=1
Reply all
Reply to author
Forward
0 new messages