[v5.15] INFO: rcu detected stall in sys_process_vm_readv

0 views
Skip to first unread message

syzbot

unread,
Oct 11, 2023, 2:31:49 AM10/11/23
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 02e21884dcf2 Linux 5.15.135
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=12eed965680000
kernel config: https://syzkaller.appspot.com/x/.config?x=e4cc6ae646bdb7fa
dashboard link: https://syzkaller.appspot.com/bug?extid=d8060c38208df4d1ae9a
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/070649b789aa/disk-02e21884.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/b4dc88e68ad3/vmlinux-02e21884.xz
kernel image: https://storage.googleapis.com/syzbot-assets/3bf6aaa2a543/bzImage-02e21884.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+d8060c...@syzkaller.appspotmail.com

rcu: INFO: rcu_preempt detected stalls on CPUs/tasks:
rcu: Tasks blocked on level-0 rcu_node (CPUs 0-1): P7711/2:b..l P2965/1:b..l
(detected by 1, t=10502 jiffies, g=195389, q=118)
task:udevd state:R running task stack:22624 pid: 2965 ppid: 1 flags:0x00004002
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5026 [inline]
__schedule+0x12c4/0x45b0 kernel/sched/core.c:6372
preempt_schedule_common+0x83/0xd0 kernel/sched/core.c:6548
preempt_schedule+0xd9/0xe0 kernel/sched/core.c:6573
preempt_schedule_thunk+0x16/0x18 arch/x86/entry/thunk_64.S:34
__raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:161 [inline]
_raw_spin_unlock_irqrestore+0x128/0x130 kernel/locking/spinlock.c:194
spin_unlock_irqrestore include/linux/spinlock.h:418 [inline]
__wake_up_common_lock kernel/sched/wait.c:140 [inline]
__wake_up_sync_key+0x121/0x1c0 kernel/sched/wait.c:205
sock_def_readable+0x135/0x240 net/core/sock.c:3073
__netlink_sendskb net/netlink/af_netlink.c:1277 [inline]
netlink_sendskb+0x8e/0x120 net/netlink/af_netlink.c:1283
netlink_unicast+0x3a1/0x980 net/netlink/af_netlink.c:1371
netlink_sendmsg+0xa30/0xd60 net/netlink/af_netlink.c:1924
sock_sendmsg_nosec net/socket.c:704 [inline]
__sock_sendmsg net/socket.c:716 [inline]
____sys_sendmsg+0x59e/0x8f0 net/socket.c:2429
___sys_sendmsg+0x252/0x2e0 net/socket.c:2483
__sys_sendmsg net/socket.c:2512 [inline]
__do_sys_sendmsg net/socket.c:2521 [inline]
__se_sys_sendmsg+0x19a/0x260 net/socket.c:2519
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x61/0xcb
RIP: 0033:0x7f30f0cada4b
RSP: 002b:00007ffc95490458 EFLAGS: 00000246 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 0000556ca1ef2df0 RCX: 00007f30f0cada4b
RDX: 0000000000000000 RSI: 00007ffc95490468 RDI: 0000000000000004
RBP: 0000556ca1f17400 R08: 0000000000000001 R09: 0000000000000000
R10: 000000000000010f R11: 0000000000000246 R12: 0000000000000000
R13: 00000000000000b5 R14: 0000000000000000 R15: 0000000000000000
</TASK>
task:syz-executor.0 state:R running task stack:25432 pid: 7711 ppid: 3544 flags:0x00004002
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5026 [inline]
__schedule+0x12c4/0x45b0 kernel/sched/core.c:6372
preempt_schedule_irq+0xf7/0x1c0 kernel/sched/core.c:6776
irqentry_exit+0x53/0x80 kernel/entry/common.c:426
asm_sysvec_apic_timer_interrupt+0x16/0x20 arch/x86/include/asm/idtentry.h:638
RIP: 0010:percpu_ref_tryget_many include/linux/percpu-refcount.h:244 [inline]
RIP: 0010:percpu_ref_tryget+0x7e/0x140 include/linux/percpu-refcount.h:266
Code: be 00 00 00 00 00 fc ff df 48 89 d8 48 c1 e8 03 42 80 3c 30 00 74 08 48 89 df e8 fd 92 fa ff 48 8b 03 a8 03 75 59 65 48 ff 00 <b3> 01 e8 fb 1c 4d 08 85 c0 74 3a e8 42 a4 9b ff 84 c0 75 31 e8 e9
RSP: 0018:ffffc90008b8f498 EFLAGS: 00000286
RAX: 0000607f462983f8 RBX: ffff88807d440010 RCX: ffff88803dbcbb80
RDX: dffffc0000000000 RSI: ffffffff8ad87960 RDI: ffffffff8ad87920
RBP: ffffea00010699c0 R08: dffffc0000000000 R09: fffffbfff1f7b221
R10: 0000000000000000 R11: dffffc0000000001 R12: dffffc0000000000
R13: 1ffff1100490adda R14: dffffc0000000000 R15: ffff88807d440000
css_tryget include/linux/cgroup.h:355 [inline]
get_mem_cgroup_from_mm+0xd9/0x260 mm/memcontrol.c:991
__mem_cgroup_charge+0x12/0x80 mm/memcontrol.c:6776
mem_cgroup_charge include/linux/memcontrol.h:700 [inline]
wp_page_copy+0x3e7/0x2070 mm/memory.c:3048
handle_pte_fault mm/memory.c:4639 [inline]
__handle_mm_fault mm/memory.c:4756 [inline]
handle_mm_fault+0x2a3d/0x5950 mm/memory.c:4854
do_user_addr_fault arch/x86/mm/fault.c:1397 [inline]
handle_page_fault arch/x86/mm/fault.c:1485 [inline]
exc_page_fault+0x271/0x740 arch/x86/mm/fault.c:1541
asm_exc_page_fault+0x22/0x30 arch/x86/include/asm/idtentry.h:568
RIP: 0010:copy_user_enhanced_fast_string+0xe/0x40 arch/x86/lib/copy_user_64.S:206
Code: 89 d1 c1 e9 03 83 e2 07 f3 48 a5 89 d1 f3 a4 31 c0 0f 01 ca c3 0f 1f 80 00 00 00 00 0f 01 cb 83 fa 40 0f 82 70 ff ff ff 89 d1 <f3> a4 31 c0 0f 01 ca c3 66 2e 0f 1f 84 00 00 00 00 00 89 d1 83 f8
RSP: 0018:ffffc90008b8fa70 EFLAGS: 00050206
RAX: ffffffff84052601 RBX: 000000002012be80 RCX: 0000000000000e80
RDX: 0000000000001000 RSI: ffff88800f4c3180 RDI: 000000002012b000
RBP: ffffc90008b8fcd0 R08: dffffc0000000000 R09: ffffed1001e98800
R10: 0000000000000000 R11: dffffc0000000001 R12: 000000002012ae80
R13: 0000000000001000 R14: ffff88800f4c3000 R15: 00007ffffffff000
copy_user_generic arch/x86/include/asm/uaccess_64.h:37 [inline]
raw_copy_to_user arch/x86/include/asm/uaccess_64.h:58 [inline]
copyout lib/iov_iter.c:157 [inline]
copy_page_to_iter_iovec lib/iov_iter.c:228 [inline]
__copy_page_to_iter lib/iov_iter.c:861 [inline]
copy_page_to_iter+0x49a/0x10d0 lib/iov_iter.c:889
process_vm_rw_pages mm/process_vm_access.c:45 [inline]
process_vm_rw_single_vec mm/process_vm_access.c:117 [inline]
process_vm_rw_core mm/process_vm_access.c:215 [inline]
process_vm_rw+0x886/0xcc0 mm/process_vm_access.c:283
__do_sys_process_vm_readv mm/process_vm_access.c:295 [inline]
__se_sys_process_vm_readv mm/process_vm_access.c:291 [inline]
__x64_sys_process_vm_readv+0xdc/0xf0 mm/process_vm_access.c:291
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x61/0xcb
RIP: 0033:0x7fc48ae77ae9
RSP: 002b:00007fc4893f90c8 EFLAGS: 00000246 ORIG_RAX: 0000000000000136
RAX: ffffffffffffffda RBX: 00007fc48af96f80 RCX: 00007fc48ae77ae9
RDX: 0000000000000002 RSI: 0000000020008400 RDI: 00000000000015fc
RBP: 00007fc48aec347a R08: 0000000000000286 R09: 0000000000000000
R10: 0000000020008640 R11: 0000000000000246 R12: 0000000000000000
R13: 000000000000000b R14: 00007fc48af96f80 R15: 00007ffebf2b44b8
</TASK>
rcu: rcu_preempt kthread starved for 10571 jiffies! g195389 f0x0 RCU_GP_WAIT_FQS(5) ->state=0x0 ->cpu=1
rcu: Unless rcu_preempt kthread gets sufficient CPU time, OOM is now expected behavior.
rcu: RCU grace-period kthread stack dump:
task:rcu_preempt state:R running task stack:26936 pid: 15 ppid: 2 flags:0x00004000
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5026 [inline]
__schedule+0x12c4/0x45b0 kernel/sched/core.c:6372
schedule+0x11b/0x1f0 kernel/sched/core.c:6455
schedule_timeout+0x1b9/0x300 kernel/time/timer.c:1884
rcu_gp_fqs_loop+0x2af/0xf70 kernel/rcu/tree.c:1959
rcu_gp_kthread+0xa4/0x360 kernel/rcu/tree.c:2132
kthread+0x3f6/0x4f0 kernel/kthread.c:319
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:298
</TASK>
rcu: Stack dump where RCU GP kthread last ran:
NMI backtrace for cpu 1
CPU: 1 PID: 0 Comm: swapper/1 Not tainted 5.15.135-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/06/2023
Call Trace:
<IRQ>
__dump_stack lib/dump_stack.c:88 [inline]
dump_stack_lvl+0x1e3/0x2cb lib/dump_stack.c:106
nmi_cpu_backtrace+0x46a/0x4a0 lib/nmi_backtrace.c:111
nmi_trigger_cpumask_backtrace+0x181/0x2a0 lib/nmi_backtrace.c:62
trigger_single_cpu_backtrace include/linux/nmi.h:166 [inline]
rcu_check_gp_kthread_starvation+0x1d2/0x240 kernel/rcu/tree_stall.h:481
print_other_cpu_stall+0x137a/0x14d0 kernel/rcu/tree_stall.h:586
check_cpu_stall kernel/rcu/tree_stall.h:729 [inline]
rcu_pending kernel/rcu/tree.c:3911 [inline]
rcu_sched_clock_irq+0x94f/0x1770 kernel/rcu/tree.c:2606
update_process_times+0x196/0x200 kernel/time/timer.c:1788
tick_sched_handle kernel/time/tick-sched.c:254 [inline]
tick_sched_timer+0x386/0x550 kernel/time/tick-sched.c:1473
__run_hrtimer kernel/time/hrtimer.c:1685 [inline]
__hrtimer_run_queues+0x55b/0xcf0 kernel/time/hrtimer.c:1749
hrtimer_interrupt+0x392/0x980 kernel/time/hrtimer.c:1811
local_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1085 [inline]
__sysvec_apic_timer_interrupt+0x139/0x470 arch/x86/kernel/apic/apic.c:1102
sysvec_apic_timer_interrupt+0x8c/0xb0 arch/x86/kernel/apic/apic.c:1096
</IRQ>
<TASK>
asm_sysvec_apic_timer_interrupt+0x16/0x20 arch/x86/include/asm/idtentry.h:638
RIP: 0010:native_save_fl arch/x86/include/asm/irqflags.h:22 [inline]
RIP: 0010:arch_local_save_flags arch/x86/include/asm/irqflags.h:70 [inline]
RIP: 0010:arch_irqs_disabled arch/x86/include/asm/irqflags.h:132 [inline]
RIP: 0010:acpi_safe_halt drivers/acpi/processor_idle.c:110 [inline]
RIP: 0010:acpi_idle_do_entry+0x10f/0x340 drivers/acpi/processor_idle.c:570
Code: 55 5a f7 48 83 e3 08 0f 85 0a 01 00 00 4c 8d 74 24 20 e8 f4 d2 60 f7 0f 1f 44 00 00 e8 aa 51 5a f7 0f 00 2d c3 a9 bc 00 fb f4 <4c> 89 f3 48 c1 eb 03 42 80 3c 3b 00 74 08 4c 89 f7 e8 5b 04 a4 f7
RSP: 0018:ffffc90000d67b00 EFLAGS: 000002d3
RAX: ffffffff8a25d036 RBX: 0000000000000000 RCX: ffff88813fe68000
RDX: 0000000000000000 RSI: ffffffff8a8b0b60 RDI: ffffffff8ad87980
RBP: ffffc90000d67b90 R08: ffffffff8186a350 R09: ffffed1027fcd001
R10: 0000000000000000 R11: dffffc0000000001 R12: 1ffff920001acf60
R13: ffff8881462df804 R14: ffffc90000d67b20 R15: dffffc0000000000
acpi_idle_enter+0x352/0x4f0 drivers/acpi/processor_idle.c:705
cpuidle_enter_state+0x521/0xef0 drivers/cpuidle/cpuidle.c:237
cpuidle_enter+0x59/0x90 drivers/cpuidle/cpuidle.c:351
call_cpuidle kernel/sched/idle.c:158 [inline]
cpuidle_idle_call kernel/sched/idle.c:239 [inline]
do_idle+0x3e4/0x670 kernel/sched/idle.c:306
cpu_startup_entry+0x3d/0x60 kernel/sched/idle.c:404
start_secondary+0x371/0x500 arch/x86/kernel/smpboot.c:281
secondary_startup_64_no_verify+0xb1/0xbb
</TASK>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the bug is already fixed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite bug's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the bug is a duplicate of another bug, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Mar 2, 2024, 2:32:13 AMMar 2
to syzkaller...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages