INFO: task hung in genl_rcv_msg

8 views
Skip to first unread message

syzbot

unread,
May 2, 2019, 11:34:07 AM5/2/19
to syzkaller...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: a03957ab Linux 4.19.38
git tree: linux-4.19.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1163f9b8a00000
kernel config: https://syzkaller.appspot.com/x/.config?x=dd6b74381d776865
dashboard link: https://syzkaller.appspot.com/bug?extid=593571e1fa1efd8f0ae6
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=127c02e0a00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+593571...@syzkaller.appspotmail.com

IPv6: ADDRCONF(NETDEV_CHANGE): hsr_slave_1: link becomes ready
IPv6: ADDRCONF(NETDEV_UP): hsr0: link is not ready
IPv6: ADDRCONF(NETDEV_CHANGE): hsr0: link becomes ready
IPv6: ADDRCONF(NETDEV_UP): vxcan1: link is not ready
8021q: adding VLAN 0 to HW filter on device batadv0
INFO: task syz-executor.5:9568 blocked for more than 140 seconds.
Not tainted 4.19.38 #6
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.5 D28664 9568 7702 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2826 [inline]
__schedule+0x813/0x1d00 kernel/sched/core.c:3474
schedule+0x92/0x1c0 kernel/sched/core.c:3518
schedule_preempt_disabled+0x13/0x20 kernel/sched/core.c:3576
__mutex_lock_common kernel/locking/mutex.c:1002 [inline]
__mutex_lock+0x726/0x1300 kernel/locking/mutex.c:1072
mutex_lock_nested+0x16/0x20 kernel/locking/mutex.c:1087
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x13e/0x16c net/netlink/genetlink.c:625
netlink_rcv_skb+0x180/0x460 net/netlink/af_netlink.c:2454
genl_rcv+0x29/0x40 net/netlink/genetlink.c:638
netlink_unicast_kernel net/netlink/af_netlink.c:1317 [inline]
netlink_unicast+0x53c/0x720 net/netlink/af_netlink.c:1343
netlink_sendmsg+0x8ae/0xd70 net/netlink/af_netlink.c:1908
sock_sendmsg_nosec net/socket.c:622 [inline]
sock_sendmsg+0xdd/0x130 net/socket.c:632
___sys_sendmsg+0x806/0x930 net/socket.c:2115
__sys_sendmsg+0x105/0x1d0 net/socket.c:2153
__do_sys_sendmsg net/socket.c:2162 [inline]
__se_sys_sendmsg net/socket.c:2160 [inline]
__x64_sys_sendmsg+0x78/0xb0 net/socket.c:2160
do_syscall_64+0x103/0x610 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x412c81
Code: 00 31 c0 e8 d1 e3 00 00 e9 ba fd ff ff 0f 1f 40 00 48 8b bb c8 00 00
00 ff 15 db 6a 24 00 85 c0 89 c5 0f 85 0d fe ff ff e9 4d <fe> ff ff 0f 1f
40 00 b8 01 00 00 00 f0 48 0f c1 05 12 aa 24 00 48
RSP: 002b:00007fd0c1ec79c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007fd0c1ec7a58 RCX: 0000000000412c81
RDX: 0000000000000000 RSI: 00007fd0c1ec7a00 RDI: 0000000000000005
RBP: 0000000000000005 R08: 000000000000000b R09: 0000000000000000
R10: 0000000000000004 R11: 0000000000000293 R12: 00007fd0c1ec7a40
R13: 00000000004cefb8 R14: 00000000004dd700 R15: 00000000ffffffff
INFO: task syz-executor.5:9569 blocked for more than 140 seconds.
Not tainted 4.19.38 #6
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.5 D28664 9569 7702 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2826 [inline]
__schedule+0x813/0x1d00 kernel/sched/core.c:3474
schedule+0x92/0x1c0 kernel/sched/core.c:3518
schedule_preempt_disabled+0x13/0x20 kernel/sched/core.c:3576
__mutex_lock_common kernel/locking/mutex.c:1002 [inline]
__mutex_lock+0x726/0x1300 kernel/locking/mutex.c:1072
mutex_lock_nested+0x16/0x20 kernel/locking/mutex.c:1087
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x13e/0x16c net/netlink/genetlink.c:625
netlink_rcv_skb+0x180/0x460 net/netlink/af_netlink.c:2454
genl_rcv+0x29/0x40 net/netlink/genetlink.c:638
netlink_unicast_kernel net/netlink/af_netlink.c:1317 [inline]
netlink_unicast+0x53c/0x720 net/netlink/af_netlink.c:1343
netlink_sendmsg+0x8ae/0xd70 net/netlink/af_netlink.c:1908
sock_sendmsg_nosec net/socket.c:622 [inline]
sock_sendmsg+0xdd/0x130 net/socket.c:632
___sys_sendmsg+0x806/0x930 net/socket.c:2115
__sys_sendmsg+0x105/0x1d0 net/socket.c:2153
__do_sys_sendmsg net/socket.c:2162 [inline]
__se_sys_sendmsg net/socket.c:2160 [inline]
__x64_sys_sendmsg+0x78/0xb0 net/socket.c:2160
do_syscall_64+0x103/0x610 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x458da9
Code: Bad RIP value.
RSP: 002b:00007fd0c1ea6c78 EFLAGS: 00000246 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 0000000000000003 RCX: 0000000000458da9
RDX: 0000000000000000 RSI: 0000000020000500 RDI: 0000000000000004
RBP: 000000000073c040 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 00007fd0c1ea76d4
R13: 00000000004cd190 R14: 00000000004daca0 R15: 00000000ffffffff
INFO: task syz-executor.0:9572 blocked for more than 140 seconds.
Not tainted 4.19.38 #6
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.0 D28664 9572 7708 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2826 [inline]
__schedule+0x813/0x1d00 kernel/sched/core.c:3474
schedule+0x92/0x1c0 kernel/sched/core.c:3518
schedule_preempt_disabled+0x13/0x20 kernel/sched/core.c:3576
__mutex_lock_common kernel/locking/mutex.c:1002 [inline]
__mutex_lock+0x726/0x1300 kernel/locking/mutex.c:1072
mutex_lock_nested+0x16/0x20 kernel/locking/mutex.c:1087
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x13e/0x16c net/netlink/genetlink.c:625
netlink_rcv_skb+0x180/0x460 net/netlink/af_netlink.c:2454
genl_rcv+0x29/0x40 net/netlink/genetlink.c:638
netlink_unicast_kernel net/netlink/af_netlink.c:1317 [inline]
netlink_unicast+0x53c/0x720 net/netlink/af_netlink.c:1343
netlink_sendmsg+0x8ae/0xd70 net/netlink/af_netlink.c:1908
sock_sendmsg_nosec net/socket.c:622 [inline]
sock_sendmsg+0xdd/0x130 net/socket.c:632
___sys_sendmsg+0x806/0x930 net/socket.c:2115
__sys_sendmsg+0x105/0x1d0 net/socket.c:2153
__do_sys_sendmsg net/socket.c:2162 [inline]
__se_sys_sendmsg net/socket.c:2160 [inline]
__x64_sys_sendmsg+0x78/0xb0 net/socket.c:2160
do_syscall_64+0x103/0x610 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x412c81
Code: 00 31 c0 e8 d1 e3 00 00 e9 ba fd ff ff 0f 1f 40 00 48 8b bb c8 00 00
00 ff 15 db 6a 24 00 85 c0 89 c5 0f 85 0d fe ff ff e9 4d <fe> ff ff 0f 1f
40 00 b8 01 00 00 00 f0 48 0f c1 05 12 aa 24 00 48
RSP: 002b:00007f9cebdbe9c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007f9cebdbea58 RCX: 0000000000412c81
RDX: 0000000000000000 RSI: 00007f9cebdbea00 RDI: 0000000000000005
RBP: 0000000000000005 R08: 000000000000000b R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000293 R12: 00007f9cebdbea40
R13: 00000000004cefb8 R14: 00000000004dd700 R15: 00000000ffffffff
INFO: task syz-executor.0:9576 blocked for more than 140 seconds.
Not tainted 4.19.38 #6
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.0 D27912 9576 7708 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2826 [inline]
__schedule+0x813/0x1d00 kernel/sched/core.c:3474
schedule+0x92/0x1c0 kernel/sched/core.c:3518
schedule_preempt_disabled+0x13/0x20 kernel/sched/core.c:3576
__mutex_lock_common kernel/locking/mutex.c:1002 [inline]
__mutex_lock+0x726/0x1300 kernel/locking/mutex.c:1072
mutex_lock_nested+0x16/0x20 kernel/locking/mutex.c:1087
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x13e/0x16c net/netlink/genetlink.c:625
netlink_rcv_skb+0x180/0x460 net/netlink/af_netlink.c:2454
genl_rcv+0x29/0x40 net/netlink/genetlink.c:638
netlink_unicast_kernel net/netlink/af_netlink.c:1317 [inline]
netlink_unicast+0x53c/0x720 net/netlink/af_netlink.c:1343
netlink_sendmsg+0x8ae/0xd70 net/netlink/af_netlink.c:1908
sock_sendmsg_nosec net/socket.c:622 [inline]
sock_sendmsg+0xdd/0x130 net/socket.c:632
___sys_sendmsg+0x806/0x930 net/socket.c:2115
__sys_sendmsg+0x105/0x1d0 net/socket.c:2153
__do_sys_sendmsg net/socket.c:2162 [inline]
__se_sys_sendmsg net/socket.c:2160 [inline]
__x64_sys_sendmsg+0x78/0xb0 net/socket.c:2160
do_syscall_64+0x103/0x610 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x412c81
Code: 00 31 c0 e8 d1 e3 00 00 e9 ba fd ff ff 0f 1f 40 00 48 8b bb c8 00 00
00 ff 15 db 6a 24 00 85 c0 89 c5 0f 85 0d fe ff ff e9 4d <fe> ff ff 0f 1f
40 00 b8 01 00 00 00 f0 48 0f c1 05 12 aa 24 00 48
RSP: 002b:00007f9cebd9d9c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007f9cebd9da58 RCX: 0000000000412c81
RDX: 0000000000000000 RSI: 00007f9cebd9da00 RDI: 0000000000000005
RBP: 0000000000000005 R08: 000000000000000b R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000293 R12: 00007f9cebd9da40
R13: 00000000004cefb8 R14: 00000000004dd700 R15: 00000000ffffffff
INFO: task syz-executor.1:9570 blocked for more than 140 seconds.
Not tainted 4.19.38 #6
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.1 D28664 9570 7707 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2826 [inline]
__schedule+0x813/0x1d00 kernel/sched/core.c:3474
schedule+0x92/0x1c0 kernel/sched/core.c:3518
schedule_preempt_disabled+0x13/0x20 kernel/sched/core.c:3576
__mutex_lock_common kernel/locking/mutex.c:1002 [inline]
__mutex_lock+0x726/0x1300 kernel/locking/mutex.c:1072
mutex_lock_nested+0x16/0x20 kernel/locking/mutex.c:1087
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x13e/0x16c net/netlink/genetlink.c:625
netlink_rcv_skb+0x180/0x460 net/netlink/af_netlink.c:2454
genl_rcv+0x29/0x40 net/netlink/genetlink.c:638
netlink_unicast_kernel net/netlink/af_netlink.c:1317 [inline]
netlink_unicast+0x53c/0x720 net/netlink/af_netlink.c:1343
netlink_sendmsg+0x8ae/0xd70 net/netlink/af_netlink.c:1908
sock_sendmsg_nosec net/socket.c:622 [inline]
sock_sendmsg+0xdd/0x130 net/socket.c:632
___sys_sendmsg+0x806/0x930 net/socket.c:2115
__sys_sendmsg+0x105/0x1d0 net/socket.c:2153
__do_sys_sendmsg net/socket.c:2162 [inline]
__se_sys_sendmsg net/socket.c:2160 [inline]
__x64_sys_sendmsg+0x78/0xb0 net/socket.c:2160
do_syscall_64+0x103/0x610 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x412c81
Code: 00 31 c0 e8 d1 e3 00 00 e9 ba fd ff ff 0f 1f 40 00 48 8b bb c8 00 00
00 ff 15 db 6a 24 00 85 c0 89 c5 0f 85 0d fe ff ff e9 4d <fe> ff ff 0f 1f
40 00 b8 01 00 00 00 f0 48 0f c1 05 12 aa 24 00 48
RSP: 002b:00007f9a8654d9c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007f9a8654da58 RCX: 0000000000412c81
RDX: 0000000000000000 RSI: 00007f9a8654da00 RDI: 0000000000000005
RBP: 0000000000000005 R08: 000000000000000b R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000293 R12: 00007f9a8654da40
R13: 00000000004cefb8 R14: 00000000004dd700 R15: 00000000ffffffff
INFO: task syz-executor.1:9577 blocked for more than 140 seconds.
Not tainted 4.19.38 #6
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.1 D27912 9577 7707 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2826 [inline]
__schedule+0x813/0x1d00 kernel/sched/core.c:3474
schedule+0x92/0x1c0 kernel/sched/core.c:3518
schedule_preempt_disabled+0x13/0x20 kernel/sched/core.c:3576
__mutex_lock_common kernel/locking/mutex.c:1002 [inline]
__mutex_lock+0x726/0x1300 kernel/locking/mutex.c:1072
mutex_lock_nested+0x16/0x20 kernel/locking/mutex.c:1087
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x13e/0x16c net/netlink/genetlink.c:625
netlink_rcv_skb+0x180/0x460 net/netlink/af_netlink.c:2454
genl_rcv+0x29/0x40 net/netlink/genetlink.c:638
netlink_unicast_kernel net/netlink/af_netlink.c:1317 [inline]
netlink_unicast+0x53c/0x720 net/netlink/af_netlink.c:1343
netlink_sendmsg+0x8ae/0xd70 net/netlink/af_netlink.c:1908
sock_sendmsg_nosec net/socket.c:622 [inline]
sock_sendmsg+0xdd/0x130 net/socket.c:632
___sys_sendmsg+0x806/0x930 net/socket.c:2115
__sys_sendmsg+0x105/0x1d0 net/socket.c:2153
__do_sys_sendmsg net/socket.c:2162 [inline]
__se_sys_sendmsg net/socket.c:2160 [inline]
__x64_sys_sendmsg+0x78/0xb0 net/socket.c:2160
do_syscall_64+0x103/0x610 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x412c81
Code: 00 31 c0 e8 d1 e3 00 00 e9 ba fd ff ff 0f 1f 40 00 48 8b bb c8 00 00
00 ff 15 db 6a 24 00 85 c0 89 c5 0f 85 0d fe ff ff e9 4d <fe> ff ff 0f 1f
40 00 b8 01 00 00 00 f0 48 0f c1 05 12 aa 24 00 48
RSP: 002b:00007f9a8652c9c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007f9a8652ca58 RCX: 0000000000412c81
RDX: 0000000000000000 RSI: 00007f9a8652ca00 RDI: 0000000000000005
RBP: 0000000000000005 R08: 000000000000000b R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000293 R12: 00007f9a8652ca40
R13: 00000000004cefb8 R14: 00000000004dd700 R15: 00000000ffffffff
INFO: task syz-executor.4:9573 blocked for more than 140 seconds.
Not tainted 4.19.38 #6
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.4 D28664 9573 7700 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2826 [inline]
__schedule+0x813/0x1d00 kernel/sched/core.c:3474
schedule+0x92/0x1c0 kernel/sched/core.c:3518
schedule_preempt_disabled+0x13/0x20 kernel/sched/core.c:3576
__mutex_lock_common kernel/locking/mutex.c:1002 [inline]
__mutex_lock+0x726/0x1300 kernel/locking/mutex.c:1072
mutex_lock_nested+0x16/0x20 kernel/locking/mutex.c:1087
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x13e/0x16c net/netlink/genetlink.c:625
netlink_rcv_skb+0x180/0x460 net/netlink/af_netlink.c:2454
genl_rcv+0x29/0x40 net/netlink/genetlink.c:638
netlink_unicast_kernel net/netlink/af_netlink.c:1317 [inline]
netlink_unicast+0x53c/0x720 net/netlink/af_netlink.c:1343
netlink_sendmsg+0x8ae/0xd70 net/netlink/af_netlink.c:1908
sock_sendmsg_nosec net/socket.c:622 [inline]
sock_sendmsg+0xdd/0x130 net/socket.c:632
___sys_sendmsg+0x806/0x930 net/socket.c:2115
__sys_sendmsg+0x105/0x1d0 net/socket.c:2153
__do_sys_sendmsg net/socket.c:2162 [inline]
__se_sys_sendmsg net/socket.c:2160 [inline]
__x64_sys_sendmsg+0x78/0xb0 net/socket.c:2160
do_syscall_64+0x103/0x610 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x412c81
Code: 00 31 c0 e8 d1 e3 00 00 e9 ba fd ff ff 0f 1f 40 00 48 8b bb c8 00 00
00 ff 15 db 6a 24 00 85 c0 89 c5 0f 85 0d fe ff ff e9 4d <fe> ff ff 0f 1f
40 00 b8 01 00 00 00 f0 48 0f c1 05 12 aa 24 00 48
RSP: 002b:00007f73718f49c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007f73718f4a58 RCX: 0000000000412c81
RDX: 0000000000000000 RSI: 00007f73718f4a00 RDI: 0000000000000005
RBP: 0000000000000005 R08: 000000000000000b R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000293 R12: 00007f73718f4a40
R13: 00000000004cefb8 R14: 00000000004dd700 R15: 00000000ffffffff
INFO: task syz-executor.4:9578 blocked for more than 140 seconds.
Not tainted 4.19.38 #6
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.4 D27912 9578 7700 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2826 [inline]
__schedule+0x813/0x1d00 kernel/sched/core.c:3474
schedule+0x92/0x1c0 kernel/sched/core.c:3518
schedule_preempt_disabled+0x13/0x20 kernel/sched/core.c:3576
__mutex_lock_common kernel/locking/mutex.c:1002 [inline]
__mutex_lock+0x726/0x1300 kernel/locking/mutex.c:1072
mutex_lock_nested+0x16/0x20 kernel/locking/mutex.c:1087
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x13e/0x16c net/netlink/genetlink.c:625
netlink_rcv_skb+0x180/0x460 net/netlink/af_netlink.c:2454
genl_rcv+0x29/0x40 net/netlink/genetlink.c:638
netlink_unicast_kernel net/netlink/af_netlink.c:1317 [inline]
netlink_unicast+0x53c/0x720 net/netlink/af_netlink.c:1343
netlink_sendmsg+0x8ae/0xd70 net/netlink/af_netlink.c:1908
sock_sendmsg_nosec net/socket.c:622 [inline]
sock_sendmsg+0xdd/0x130 net/socket.c:632
___sys_sendmsg+0x806/0x930 net/socket.c:2115
__sys_sendmsg+0x105/0x1d0 net/socket.c:2153
__do_sys_sendmsg net/socket.c:2162 [inline]
__se_sys_sendmsg net/socket.c:2160 [inline]
__x64_sys_sendmsg+0x78/0xb0 net/socket.c:2160
do_syscall_64+0x103/0x610 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x412c81
Code: 00 31 c0 e8 d1 e3 00 00 e9 ba fd ff ff 0f 1f 40 00 48 8b bb c8 00 00
00 ff 15 db 6a 24 00 85 c0 89 c5 0f 85 0d fe ff ff e9 4d <fe> ff ff 0f 1f
40 00 b8 01 00 00 00 f0 48 0f c1 05 12 aa 24 00 48
RSP: 002b:00007f73718d39c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007f73718d3a58 RCX: 0000000000412c81
RDX: 0000000000000000 RSI: 00007f73718d3a00 RDI: 0000000000000005
RBP: 0000000000000005 R08: 000000000000000b R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000293 R12: 00007f73718d3a40
R13: 00000000004cefb8 R14: 00000000004dd700 R15: 00000000ffffffff
INFO: task syz-executor.3:9575 blocked for more than 140 seconds.
Not tainted 4.19.38 #6
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.3 D28664 9575 7705 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2826 [inline]
__schedule+0x813/0x1d00 kernel/sched/core.c:3474
schedule+0x92/0x1c0 kernel/sched/core.c:3518
schedule_preempt_disabled+0x13/0x20 kernel/sched/core.c:3576
__mutex_lock_common kernel/locking/mutex.c:1002 [inline]
__mutex_lock+0x726/0x1300 kernel/locking/mutex.c:1072
mutex_lock_nested+0x16/0x20 kernel/locking/mutex.c:1087
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x13e/0x16c net/netlink/genetlink.c:625
netlink_rcv_skb+0x180/0x460 net/netlink/af_netlink.c:2454
genl_rcv+0x29/0x40 net/netlink/genetlink.c:638
netlink_unicast_kernel net/netlink/af_netlink.c:1317 [inline]
netlink_unicast+0x53c/0x720 net/netlink/af_netlink.c:1343
netlink_sendmsg+0x8ae/0xd70 net/netlink/af_netlink.c:1908
sock_sendmsg_nosec net/socket.c:622 [inline]
sock_sendmsg+0xdd/0x130 net/socket.c:632
___sys_sendmsg+0x806/0x930 net/socket.c:2115
__sys_sendmsg+0x105/0x1d0 net/socket.c:2153
__do_sys_sendmsg net/socket.c:2162 [inline]
__se_sys_sendmsg net/socket.c:2160 [inline]
__x64_sys_sendmsg+0x78/0xb0 net/socket.c:2160
do_syscall_64+0x103/0x610 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x412c81
Code: 00 31 c0 e8 d1 e3 00 00 e9 ba fd ff ff 0f 1f 40 00 48 8b bb c8 00 00
00 ff 15 db 6a 24 00 85 c0 89 c5 0f 85 0d fe ff ff e9 4d <fe> ff ff 0f 1f
40 00 b8 01 00 00 00 f0 48 0f c1 05 12 aa 24 00 48
RSP: 002b:00007f7fd0b959c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007f7fd0b95a58 RCX: 0000000000412c81
RDX: 0000000000000000 RSI: 00007f7fd0b95a00 RDI: 0000000000000005
RBP: 0000000000000005 R08: 000000000000000b R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000293 R12: 00007f7fd0b95a40
R13: 00000000004cefb8 R14: 00000000004dd700 R15: 00000000ffffffff
INFO: task syz-executor.3:9579 blocked for more than 140 seconds.
Not tainted 4.19.38 #6
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.3 D27912 9579 7705 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2826 [inline]
__schedule+0x813/0x1d00 kernel/sched/core.c:3474
schedule+0x92/0x1c0 kernel/sched/core.c:3518
schedule_preempt_disabled+0x13/0x20 kernel/sched/core.c:3576
__mutex_lock_common kernel/locking/mutex.c:1002 [inline]
__mutex_lock+0x726/0x1300 kernel/locking/mutex.c:1072
mutex_lock_nested+0x16/0x20 kernel/locking/mutex.c:1087
genl_lock net/netlink/genetlink.c:33 [inline]
genl_rcv_msg+0x13e/0x16c net/netlink/genetlink.c:625
netlink_rcv_skb+0x180/0x460 net/netlink/af_netlink.c:2454
genl_rcv+0x29/0x40 net/netlink/genetlink.c:638
netlink_unicast_kernel net/netlink/af_netlink.c:1317 [inline]
netlink_unicast+0x53c/0x720 net/netlink/af_netlink.c:1343
netlink_sendmsg+0x8ae/0xd70 net/netlink/af_netlink.c:1908
sock_sendmsg_nosec net/socket.c:622 [inline]
sock_sendmsg+0xdd/0x130 net/socket.c:632
___sys_sendmsg+0x806/0x930 net/socket.c:2115
__sys_sendmsg+0x105/0x1d0 net/socket.c:2153
__do_sys_sendmsg net/socket.c:2162 [inline]
__se_sys_sendmsg net/socket.c:2160 [inline]
__x64_sys_sendmsg+0x78/0xb0 net/socket.c:2160
do_syscall_64+0x103/0x610 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x412c81
Code: 00 31 c0 e8 d1 e3 00 00 e9 ba fd ff ff 0f 1f 40 00 48 8b bb c8 00 00
00 ff 15 db 6a 24 00 85 c0 89 c5 0f 85 0d fe ff ff e9 4d <fe> ff ff 0f 1f
40 00 b8 01 00 00 00 f0 48 0f c1 05 12 aa 24 00 48
RSP: 002b:00007f7fd0b749c0 EFLAGS: 00000293 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007f7fd0b74a58 RCX: 0000000000412c81
RDX: 0000000000000000 RSI: 00007f7fd0b74a00 RDI: 0000000000000005
RBP: 0000000000000005 R08: 000000000000000b R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000293 R12: 00007f7fd0b74a40
R13: 00000000004cefb8 R14: 00000000004dd700 R15: 00000000ffffffff

Showing all locks held in the system:
1 lock held by khungtaskd/1034:
#0: 00000000c49fb03e (rcu_read_lock){....}, at:
debug_show_all_locks+0x5f/0x27e kernel/locking/lockdep.c:4435
1 lock held by rsyslogd/7533:
#0: 00000000195c4039 (&f->f_pos_lock){+.+.}, at: __fdget_pos+0xee/0x110
fs/file.c:767
2 locks held by getty/7656:
#0: 000000002dbb6de9 (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:363
#1: 00000000235ad456 (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x232/0x1b30 drivers/tty/n_tty.c:2154
2 locks held by getty/7657:
#0: 00000000a7d86b43 (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:363
#1: 0000000020f393a4 (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x232/0x1b30 drivers/tty/n_tty.c:2154
2 locks held by getty/7658:
#0: 000000006d9d7303 (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:363
#1: 000000003a44fb7d (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x232/0x1b30 drivers/tty/n_tty.c:2154
2 locks held by getty/7659:
#0: 00000000ac087619 (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:363
#1: 000000007bd7f887 (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x232/0x1b30 drivers/tty/n_tty.c:2154
2 locks held by getty/7660:
#0: 000000007df042a0 (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:363
#1: 00000000274cbfbd (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x232/0x1b30 drivers/tty/n_tty.c:2154
2 locks held by getty/7661:
#0: 00000000c84c02c3 (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:363
#1: 00000000fd95c24f (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x232/0x1b30 drivers/tty/n_tty.c:2154
2 locks held by getty/7662:
#0: 000000000399f97d (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:363
#1: 000000000b7a45a1 (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x232/0x1b30 drivers/tty/n_tty.c:2154
2 locks held by syz-executor.5/9568:
#0: 00000000207029dd (cb_lock){++++}, at: genl_rcv+0x1a/0x40
net/netlink/genetlink.c:637
#1: 00000000ac421525 (genl_mutex){+.+.}, at: genl_lock
net/netlink/genetlink.c:33 [inline]
#1: 00000000ac421525 (genl_mutex){+.+.}, at: genl_rcv_msg+0x13e/0x16c
net/netlink/genetlink.c:625
2 locks held by syz-executor.5/9569:
#0: 00000000207029dd (cb_lock){++++}, at: genl_rcv+0x1a/0x40
net/netlink/genetlink.c:637
#1: 00000000ac421525 (genl_mutex){+.+.}, at: genl_lock
net/netlink/genetlink.c:33 [inline]
#1: 00000000ac421525 (genl_mutex){+.+.}, at: genl_rcv_msg+0x13e/0x16c
net/netlink/genetlink.c:625
3 locks held by syz-executor.2/9562:
2 locks held by syz-executor.0/9572:
#0: 00000000207029dd (cb_lock){++++}, at: genl_rcv+0x1a/0x40
net/netlink/genetlink.c:637
#1: 00000000ac421525 (genl_mutex){+.+.}, at: genl_lock
net/netlink/genetlink.c:33 [inline]
#1: 00000000ac421525 (genl_mutex){+.+.}, at: genl_rcv_msg+0x13e/0x16c
net/netlink/genetlink.c:625
2 locks held by syz-executor.0/9576:
#0: 00000000207029dd (cb_lock){++++}, at: genl_rcv+0x1a/0x40
net/netlink/genetlink.c:637
#1: 00000000ac421525 (genl_mutex){+.+.}, at: genl_lock
net/netlink/genetlink.c:33 [inline]
#1: 00000000ac421525 (genl_mutex){+.+.}, at: genl_rcv_msg+0x13e/0x16c
net/netlink/genetlink.c:625
2 locks held by syz-executor.1/9570:
#0: 00000000207029dd (cb_lock){++++}, at: genl_rcv+0x1a/0x40
net/netlink/genetlink.c:637
#1: 00000000ac421525 (genl_mutex){+.+.}, at: genl_lock
net/netlink/genetlink.c:33 [inline]
#1: 00000000ac421525 (genl_mutex){+.+.}, at: genl_rcv_msg+0x13e/0x16c
net/netlink/genetlink.c:625
2 locks held by syz-executor.1/9577:
#0: 00000000207029dd (cb_lock){++++}, at: genl_rcv+0x1a/0x40
net/netlink/genetlink.c:637
#1: 00000000ac421525 (genl_mutex){+.+.}, at: genl_lock
net/netlink/genetlink.c:33 [inline]
#1: 00000000ac421525 (genl_mutex){+.+.}, at: genl_rcv_msg+0x13e/0x16c
net/netlink/genetlink.c:625
2 locks held by syz-executor.4/9573:
#0: 00000000207029dd (cb_lock){++++}, at: genl_rcv+0x1a/0x40
net/netlink/genetlink.c:637
#1: 00000000ac421525 (genl_mutex){+.+.}, at: genl_lock
net/netlink/genetlink.c:33 [inline]
#1: 00000000ac421525 (genl_mutex){+.+.}, at: genl_rcv_msg+0x13e/0x16c
net/netlink/genetlink.c:625
2 locks held by syz-executor.4/9578:
#0: 00000000207029dd (cb_lock){++++}, at: genl_rcv+0x1a/0x40
net/netlink/genetlink.c:637
#1: 00000000ac421525 (genl_mutex){+.+.}, at: genl_lock
net/netlink/genetlink.c:33 [inline]
#1: 00000000ac421525 (genl_mutex){+.+.}, at: genl_rcv_msg+0x13e/0x16c
net/netlink/genetlink.c:625
2 locks held by syz-executor.3/9575:
#0: 00000000207029dd (cb_lock){++++}, at: genl_rcv+0x1a/0x40
net/netlink/genetlink.c:637
#1: 00000000ac421525 (genl_mutex){+.+.}, at: genl_lock
net/netlink/genetlink.c:33 [inline]
#1: 00000000ac421525 (genl_mutex){+.+.}, at: genl_rcv_msg+0x13e/0x16c
net/netlink/genetlink.c:625
2 locks held by syz-executor.3/9579:
#0: 00000000207029dd (cb_lock){++++}, at: genl_rcv+0x1a/0x40
net/netlink/genetlink.c:637
#1: 00000000ac421525 (genl_mutex){+.+.}, at: genl_lock
net/netlink/genetlink.c:33 [inline]
#1: 00000000ac421525 (genl_mutex){+.+.}, at: genl_rcv_msg+0x13e/0x16c
net/netlink/genetlink.c:625

=============================================

NMI backtrace for cpu 0
CPU: 0 PID: 1034 Comm: khungtaskd Not tainted 4.19.38 #6
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x172/0x1f0 lib/dump_stack.c:113
nmi_cpu_backtrace.cold+0x63/0xa4 lib/nmi_backtrace.c:101
nmi_trigger_cpumask_backtrace+0x1b0/0x1f8 lib/nmi_backtrace.c:62
arch_trigger_cpumask_backtrace+0x14/0x20 arch/x86/kernel/apic/hw_nmi.c:38
trigger_all_cpu_backtrace include/linux/nmi.h:146 [inline]
check_hung_uninterruptible_tasks kernel/hung_task.c:203 [inline]
watchdog+0x9df/0xee0 kernel/hung_task.c:287
kthread+0x357/0x430 kernel/kthread.c:246
ret_from_fork+0x3a/0x50 arch/x86/entry/entry_64.S:413
Sending NMI from CPU 0 to CPUs 1:
INFO: NMI handler (nmi_cpu_backtrace_handler) took too long to run: 1.045
msecs
NMI backtrace for cpu 1
CPU: 1 PID: 9562 Comm: syz-executor.2 Not tainted 4.19.38 #6
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
RIP: 0010:genl_family_attrbuf+0x44/0x120 net/netlink/genetlink.c:1075
Code: fc ff df 48 89 fa 48 c1 ea 03 0f b6 04 02 48 89 fa 83 e2 07 38 d0 7f
08 84 c0 0f 85 c3 00 00 00 44 0f b6 63 21 31 ff 44 89 e6 <e8> 67 ea d8 fb
45 84 e4 0f 85 a2 00 00 00 e8 19 e9 d8 fb 48 c7 c0
RSP: 0018:ffff8880a5fcedd8 EFLAGS: 00000246
RAX: 0000000000000000 RBX: ffffffff8845b780 RCX: ffffffff86b6d4c6
RDX: 0000000000000001 RSI: 0000000000000000 RDI: 0000000000000000
RBP: ffff8880a5fcede8 R08: ffff8880a5dd2140 R09: 0000000000000002
R10: ffffed1015d24732 R11: ffff8880ae923993 R12: 0000000000000000
R13: ffff8880a5fceed8 R14: 000000000000000a R15: ffff888089db5080
FS: 00007fa38df9d700(0000) GS:ffff8880ae900000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: ffffffffff600400 CR3: 0000000097a3a000 CR4: 00000000001406e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
tipc_nlmsg_parse+0x29/0x100 net/tipc/netlink.c:272
tipc_nl_publ_dump+0x86c/0xd75 net/tipc/socket.c:3509
__tipc_nl_compat_dumpit.isra.0+0x220/0x960 net/tipc/netlink_compat.c:206
tipc_nl_compat_publ_dump net/tipc/netlink_compat.c:989 [inline]
tipc_nl_compat_sk_dump+0x6c2/0x950 net/tipc/netlink_compat.c:1037
__tipc_nl_compat_dumpit.isra.0+0x32c/0x960 net/tipc/netlink_compat.c:215
tipc_nl_compat_dumpit+0x209/0x4d0 net/tipc/netlink_compat.c:286
tipc_nl_compat_handle net/tipc/netlink_compat.c:1236 [inline]
tipc_nl_compat_recv+0x34f/0xb40 net/tipc/netlink_compat.c:1274
genl_family_rcv_msg+0x6e3/0xd40 net/netlink/genetlink.c:602
genl_rcv_msg+0xca/0x16c net/netlink/genetlink.c:627
netlink_rcv_skb+0x180/0x460 net/netlink/af_netlink.c:2454
genl_rcv+0x29/0x40 net/netlink/genetlink.c:638
netlink_unicast_kernel net/netlink/af_netlink.c:1317 [inline]
netlink_unicast+0x53c/0x720 net/netlink/af_netlink.c:1343
netlink_sendmsg+0x8ae/0xd70 net/netlink/af_netlink.c:1908
sock_sendmsg_nosec net/socket.c:622 [inline]
sock_sendmsg+0xdd/0x130 net/socket.c:632
___sys_sendmsg+0x806/0x930 net/socket.c:2115
__sys_sendmsg+0x105/0x1d0 net/socket.c:2153
__do_sys_sendmsg net/socket.c:2162 [inline]
__se_sys_sendmsg net/socket.c:2160 [inline]
__x64_sys_sendmsg+0x78/0xb0 net/socket.c:2160
do_syscall_64+0x103/0x610 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x458da9
Code: ad b8 fb ff c3 66 2e 0f 1f 84 00 00 00 00 00 66 90 48 89 f8 48 89 f7
48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff
ff 0f 83 7b b8 fb ff c3 66 2e 0f 1f 84 00 00 00 00
RSP: 002b:00007fa38df9cc78 EFLAGS: 00000246 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 0000000000000003 RCX: 0000000000458da9
RDX: 0000000000000000 RSI: 0000000020000500 RDI: 0000000000000004
RBP: 000000000073bfa0 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 00007fa38df9d6d4
R13: 00000000004cd190 R14: 00000000004daca0 R15: 00000000ffffffff


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this bug, for details see:
https://goo.gl/tpsmEJ#testing-patches
Reply all
Reply to author
Forward
0 new messages