[v5.15] INFO: task hung in __writeback_inodes_sb_nr

10 views
Skip to first unread message

syzbot

unread,
Mar 9, 2023, 12:32:47 PM3/9/23
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: d9b4a0c83a2d Linux 5.15.98
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1186c30ac80000
kernel config: https://syzkaller.appspot.com/x/.config?x=2f8d9515b973b23b
dashboard link: https://syzkaller.appspot.com/bug?extid=59b165f27afa8541bb41
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/037cabbd3313/disk-d9b4a0c8.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/9967e551eb34/vmlinux-d9b4a0c8.xz
kernel image: https://storage.googleapis.com/syzbot-assets/a050c7a4fd99/bzImage-d9b4a0c8.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+59b165...@syzkaller.appspotmail.com

INFO: task syz-executor.0:22907 blocked for more than 143 seconds.
Not tainted 5.15.98-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:syz-executor.0 state:D stack:22712 pid:22907 ppid: 22743 flags:0x00004000
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5023 [inline]
__schedule+0x132d/0x45e0 kernel/sched/core.c:6369
schedule+0x11b/0x1f0 kernel/sched/core.c:6452
wb_wait_for_completion+0x164/0x290 fs/fs-writeback.c:191
__writeback_inodes_sb_nr+0x2ce/0x370 fs/fs-writeback.c:2659
try_to_writeback_inodes_sb+0x94/0xb0 fs/fs-writeback.c:2707
ext4_nonda_switch fs/ext4/inode.c:2943 [inline]
ext4_da_write_begin+0x228/0xc40 fs/ext4/inode.c:2970
generic_perform_write+0x2bf/0x5b0 mm/filemap.c:3776
ext4_buffered_write_iter+0x22e/0x380 fs/ext4/file.c:269
ext4_file_write_iter+0x87c/0x1990
__kernel_write+0x5b1/0xa60 fs/read_write.c:539
__dump_emit+0x264/0x3a0 fs/coredump.c:875
dump_user_range+0x91/0x320 fs/coredump.c:949
elf_core_dump+0x3af0/0x4310 fs/binfmt_elf.c:2285
do_coredump+0x1856/0x31b0 fs/coredump.c:826
get_signal+0xc06/0x14e0 kernel/signal.c:2875
arch_do_signal_or_restart+0xc3/0x1890 arch/x86/kernel/signal.c:865
handle_signal_work kernel/entry/common.c:148 [inline]
exit_to_user_mode_loop+0x97/0x130 kernel/entry/common.c:172
exit_to_user_mode_prepare+0xb1/0x140 kernel/entry/common.c:207
irqentry_exit_to_user_mode+0x5/0x30 kernel/entry/common.c:313
exc_page_fault+0x33d/0x7f0 arch/x86/mm/fault.c:1544
asm_exc_page_fault+0x22/0x30 arch/x86/include/asm/idtentry.h:568
RIP: 0033:0xe1bb
RSP: 002b:0000000020000468 EFLAGS: 00010217
RAX: 0000000000000000 RBX: 00007feaf2ec5f80 RCX: 00007feaf2da60f9
RDX: 0000000020000480 RSI: 0000000020000460 RDI: 0000000022a08400
RBP: 00007feaf2e01ae9 R08: 0000000020000500 R09: 0000000020000500
R10: 00000000200004c0 R11: 0000000000000206 R12: 0000000000000000
R13: 00007ffef2206dbf R14: 00007feaf1318300 R15: 0000000000022000
</TASK>

Showing all locks held in the system:
1 lock held by khungtaskd/27:
#0: ffffffff8c91c660 (rcu_read_lock){....}-{1:2}, at: rcu_lock_acquire+0x0/0x30
2 locks held by getty/3267:
#0: ffff88814abc0098 (&tty->ldisc_sem){++++}-{0:0}, at: tty_ldisc_ref_wait+0x21/0x70 drivers/tty/tty_ldisc.c:252
#1: ffffc90002bb32e8 (&ldata->atomic_read_lock){+.+.}-{3:3}, at: n_tty_read+0x6af/0x1da0 drivers/tty/n_tty.c:2147
5 locks held by kworker/u4:6/13314:
#0: ffff888011db5138 ((wq_completion)netns){+.+.}-{0:0}, at: process_one_work+0x78a/0x1230 kernel/workqueue.c:2279
#1: ffffc90004e2fd20 (net_cleanup_work){+.+.}-{0:0}, at: process_one_work+0x7cd/0x1230 kernel/workqueue.c:2281
#2: ffffffff8d9cc8d0 (pernet_ops_rwsem){++++}-{3:3}, at: cleanup_net+0xf1/0xb60 net/core/net_namespace.c:558
#3: ffffffff8d9d8628 (rtnl_mutex){+.+.}-{3:3}, at: ip_tunnel_delete_nets+0xc9/0x330 net/ipv4/ip_tunnel.c:1118
#4: ffffffff8c920ba8 (rcu_state.exp_mutex){+.+.}-{3:3}, at: exp_funnel_lock kernel/rcu/tree_exp.h:290 [inline]
#4: ffffffff8c920ba8 (rcu_state.exp_mutex){+.+.}-{3:3}, at: synchronize_rcu_expedited+0x277/0x730 kernel/rcu/tree_exp.h:838
5 locks held by kworker/u4:9/13534:
#0: ffff888142dcc138 ((wq_completion)writeback){+.+.}-{0:0}, at: process_one_work+0x78a/0x1230 kernel/workqueue.c:2279
#1: ffffc900062bfd20 ((work_completion)(&(&wb->dwork)->work)){+.+.}-{0:0}, at: process_one_work+0x7cd/0x1230 kernel/workqueue.c:2281
#2: ffff88814b2100e0 (&type->s_umount_key#32){++++}-{3:3}, at: trylock_super+0x1b/0xf0 fs/super.c:418
#3: ffff88814b212bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3eb0 fs/ext4/inode.c:2687
#4: ffff8880b9b39698 (&rq->__lock){-.-.}-{2:2}, at: raw_spin_rq_lock_nested+0x26/0x140 kernel/sched/core.c:475
2 locks held by kworker/0:1/22724:
#0: ffff888011c66538 ((wq_completion)rcu_gp){+.+.}-{0:0}, at: process_one_work+0x78a/0x1230 kernel/workqueue.c:2279
#1: ffffc90002e1fd20 ((work_completion)(&rew.rew_work)){+.+.}-{0:0}, at: process_one_work+0x7cd/0x1230 kernel/workqueue.c:2281
3 locks held by syz-executor.5/22851:
2 locks held by syz-executor.0/22907:
1 lock held by syz-executor.2/22912:
1 lock held by syz-executor.5/23099:
1 lock held by syz-executor.0/23267:
#0: ffff88814b212bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3eb0 fs/ext4/inode.c:2687
1 lock held by syz-executor.5/23283:
#0: ffff88814b212bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3eb0 fs/ext4/inode.c:2687
1 lock held by syz-executor.5/23304:
1 lock held by syz-executor.1/23307:
1 lock held by syz-executor.2/23314:
#0: ffff88814b212bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3eb0 fs/ext4/inode.c:2687
1 lock held by syz-executor.0/23315:
1 lock held by syz-executor.4/23318:
1 lock held by syz-executor.1/23323:
3 locks held by syz-executor.2/23326:
1 lock held by syz-executor.0/23338:
1 lock held by syz-executor.4/23342:
1 lock held by syz-executor.1/23343:
1 lock held by syz-executor.5/23345:
2 locks held by syz-executor.2/23346:
1 lock held by syz-executor.4/23352:
2 locks held by syz-executor.0/23353:
3 locks held by syz-executor.3/23718:
3 locks held by syz-executor.1/23737:
1 lock held by syz-executor.4/23739:
1 lock held by syz-executor.3/23741:
1 lock held by syz-executor.2/23745:
2 locks held by syz-executor.0/23747:
1 lock held by syz-executor.3/23764:
1 lock held by syz-executor.1/23772:
#0: ffff88814b212bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3eb0 fs/ext4/inode.c:2687
1 lock held by syz-executor.4/23773:
1 lock held by syz-executor.0/23775:
3 locks held by syz-executor.3/23782:
1 lock held by syz-executor.1/23793:
#0: ffff88814b212bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3eb0 fs/ext4/inode.c:2687
1 lock held by syz-executor.0/23798:
1 lock held by syz-executor.4/23804:
2 locks held by syz-executor.3/23808:
#0: ffff88814b212bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3eb0 fs/ext4/inode.c:2687
#1: ffff8880b9b39698 (&rq->__lock){-.-.}-{2:2}, at: raw_spin_rq_lock_nested+0x26/0x140 kernel/sched/core.c:475
2 locks held by syz-executor.0/23828:
#0: ffff88814b212bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3eb0 fs/ext4/inode.c:2687
#1: ffff88814b2143f8 (&journal->j_checkpoint_mutex){+.+.}-{3:3}, at: __jbd2_log_wait_for_space+0x213/0x760 fs/jbd2/checkpoint.c:110
2 locks held by syz-executor.1/23829:
2 locks held by syz-executor.5/23844:
#0: ffff88814b212bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3eb0 fs/ext4/inode.c:2687
#1: ffff88814b2143f8 (&journal->j_checkpoint_mutex){+.+.}-{3:3}, at: __jbd2_log_wait_for_space+0x213/0x760 fs/jbd2/checkpoint.c:110
2 locks held by syz-executor.3/23847:
#0: ffff88814b212bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3eb0 fs/ext4/inode.c:2687
#1: ffffffff8c9ee040 (mmu_notifier_invalidate_range_start){+.+.}-{0:0}, at: __fs_reclaim_acquire mm/page_alloc.c:4547 [inline]
#1: ffffffff8c9ee040 (mmu_notifier_invalidate_range_start){+.+.}-{0:0}, at: fs_reclaim_acquire+0x87/0x120 mm/page_alloc.c:4561
2 locks held by syz-executor.4/23848:
#0: ffff88814b212bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3eb0 fs/ext4/inode.c:2687
#1: ffff88814b214990 (jbd2_handle){++++}-{0:0}, at: start_this_handle+0x12d5/0x1590 fs/jbd2/transaction.c:466
1 lock held by syz-executor.2/23850:
1 lock held by syz-executor.1/23856:
1 lock held by syz-executor.5/23866:
#0: ffff88814b212bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3eb0 fs/ext4/inode.c:2687
1 lock held by syz-executor.2/23883:
#0: ffff88814b212bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3eb0 fs/ext4/inode.c:2687
2 locks held by syz-executor.3/23885:
3 locks held by syz-executor.0/23888:
1 lock held by syz-executor.4/23890:
2 locks held by syz-executor.1/23893:
1 lock held by syz-executor.5/23897:
1 lock held by syz-executor.2/23905:
1 lock held by syz-executor.3/23909:
1 lock held by syz-executor.4/23916:
1 lock held by syz-executor.0/23917:
1 lock held by syz-executor.5/23924:
1 lock held by syz-executor.2/23940:
1 lock held by syz-executor.3/23943:
1 lock held by syz-executor.5/23959:
1 lock held by syz-executor.2/23978:
1 lock held by syz-executor.5/23991:
1 lock held by syz-executor.0/24000:
1 lock held by syz-executor.4/24023:
1 lock held by syz-executor.5/24026:
1 lock held by syz-executor.2/24028:
1 lock held by syz-executor.0/24035:
1 lock held by syz-executor.1/24047:
2 locks held by syz-executor.3/24052:
1 lock held by syz-executor.5/24063:
1 lock held by syz-executor.4/24064:
1 lock held by syz-executor.2/24066:
1 lock held by syz-executor.0/24074:
1 lock held by syz-executor.3/24093:
1 lock held by syz-executor.1/24096:
1 lock held by syz-executor.2/24098:
1 lock held by syz-executor.4/24116:
1 lock held by syz-executor.0/24117:
1 lock held by syz-executor.1/24121:
1 lock held by syz-executor.2/24130:
1 lock held by syz-executor.4/24150:
1 lock held by syz-executor.1/24154:
1 lock held by syz-executor.0/24158:
#0: ffff88814b212bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3eb0 fs/ext4/inode.c:2687
1 lock held by syz-executor.0/24486:
1 lock held by syz-executor.1/24489:

=============================================

NMI backtrace for cpu 0
CPU: 0 PID: 27 Comm: khungtaskd Not tainted 5.15.98-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/02/2023
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:88 [inline]
dump_stack_lvl+0x1e3/0x2cb lib/dump_stack.c:106
nmi_cpu_backtrace+0x46a/0x4a0 lib/nmi_backtrace.c:111
nmi_trigger_cpumask_backtrace+0x181/0x2a0 lib/nmi_backtrace.c:62
trigger_all_cpu_backtrace include/linux/nmi.h:148 [inline]
check_hung_uninterruptible_tasks kernel/hung_task.c:210 [inline]
watchdog+0xec6/0xf10 kernel/hung_task.c:295
kthread+0x3f6/0x4f0 kernel/kthread.c:319
ret_from_fork+0x1f/0x30 <unknown>:298
</TASK>
Sending NMI from CPU 0 to CPUs 1:
NMI backtrace for cpu 1
CPU: 1 PID: 481 Comm: kworker/u4:3 Not tainted 5.15.98-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/02/2023
Workqueue: bat_events batadv_tt_purge
RIP: 0010:variable_test_bit arch/x86/include/asm/bitops.h:214 [inline]
RIP: 0010:test_bit include/asm-generic/bitops/instrumented-non-atomic.h:135 [inline]
RIP: 0010:hlock_class kernel/locking/lockdep.c:197 [inline]
RIP: 0010:mark_lock+0x98/0x340 kernel/locking/lockdep.c:4568
Code: b6 04 28 84 c0 0f 85 27 02 00 00 8b 1b 81 e3 ff 1f 00 00 89 d8 c1 e8 06 48 8d 3c c5 a0 40 ac 8f be 08 00 00 00 e8 f8 70 66 00 <48> 0f a3 1d 00 28 49 0e 73 11 48 8d 04 5b 48 c1 e0 06 48 8d 98 a0
RSP: 0018:ffffc90002c2f958 EFLAGS: 00000056
RAX: 0000000000000001 RBX: 0000000000000796 RCX: ffffffff81631898
RDX: 0000000000000000 RSI: 0000000000000008 RDI: ffffffff8fac4190
RBP: 0000000000000002 R08: dffffc0000000000 R09: fffffbfff1f58833
R10: 0000000000000000 R11: dffffc0000000001 R12: ffff8880198de168
R13: dffffc0000000000 R14: 0000000000000004 R15: ffff8880198de148
FS: 0000000000000000(0000) GS:ffff8880b9b00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000055d1779511b0 CR3: 0000000062433000 CR4: 00000000003506e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
mark_held_locks kernel/locking/lockdep.c:4192 [inline]
__trace_hardirqs_on_caller kernel/locking/lockdep.c:4210 [inline]
lockdep_hardirqs_on_prepare+0x27d/0x7a0 kernel/locking/lockdep.c:4277
trace_hardirqs_on+0x67/0x80 kernel/trace/trace_preemptirq.c:49
__local_bh_enable_ip+0x164/0x1f0 kernel/softirq.c:388
spin_unlock_bh include/linux/spinlock.h:408 [inline]
batadv_tt_local_purge+0x2a0/0x340 net/batman-adv/translation-table.c:1357
batadv_tt_purge+0x31/0xa40 net/batman-adv/translation-table.c:3561
process_one_work+0x8e6/0x1230 kernel/workqueue.c:2306
worker_thread+0xaca/0x1280 kernel/workqueue.c:2453
kthread+0x3f6/0x4f0 kernel/kthread.c:319
ret_from_fork+0x1f/0x30 <unknown>:298
</TASK>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Apr 30, 2023, 8:49:56 PM4/30/23
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: f48aeeaaa64c Linux 5.15.109
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1208f330280000
kernel config: https://syzkaller.appspot.com/x/.config?x=f0ea19992afd55ad
dashboard link: https://syzkaller.appspot.com/bug?extid=59b165f27afa8541bb41
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1664eaf7c80000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/7603b62cce9d/disk-f48aeeaa.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/ff9178f4f061/vmlinux-f48aeeaa.xz
kernel image: https://storage.googleapis.com/syzbot-assets/89ffac9dac28/bzImage-f48aeeaa.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+59b165...@syzkaller.appspotmail.com

INFO: task syz-executor.3:4953 blocked for more than 143 seconds.
Not tainted 5.15.109-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:syz-executor.3 state:D stack:22840 pid: 4953 ppid: 3549 flags:0x00004000
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5026 [inline]
__schedule+0x12c4/0x4590 kernel/sched/core.c:6372
schedule+0x11b/0x1f0 kernel/sched/core.c:6455
wb_wait_for_completion+0x164/0x290 fs/fs-writeback.c:191
__writeback_inodes_sb_nr+0x2ce/0x370 fs/fs-writeback.c:2659
try_to_writeback_inodes_sb+0x94/0xb0 fs/fs-writeback.c:2707
ext4_nonda_switch fs/ext4/inode.c:2943 [inline]
ext4_da_write_begin+0x228/0xb60 fs/ext4/inode.c:2970
generic_perform_write+0x2bf/0x5b0 mm/filemap.c:3776
ext4_buffered_write_iter+0x22e/0x380 fs/ext4/file.c:269
ext4_file_write_iter+0x87c/0x1990
__kernel_write+0x5b1/0xa60 fs/read_write.c:539
__dump_emit+0x264/0x3a0 fs/coredump.c:875
dump_user_range+0x91/0x320 fs/coredump.c:949
elf_core_dump+0x3c7d/0x4570 fs/binfmt_elf.c:2285
do_coredump+0x1852/0x31e0 fs/coredump.c:826
get_signal+0xc06/0x14e0 kernel/signal.c:2875
arch_do_signal_or_restart+0xc3/0x1890 arch/x86/kernel/signal.c:865
handle_signal_work kernel/entry/common.c:148 [inline]
exit_to_user_mode_loop+0x97/0x130 kernel/entry/common.c:172
exit_to_user_mode_prepare+0xb1/0x140 kernel/entry/common.c:208
irqentry_exit_to_user_mode+0x5/0x30 kernel/entry/common.c:314
exc_page_fault+0x342/0x740 arch/x86/mm/fault.c:1544
asm_exc_page_fault+0x22/0x30 arch/x86/include/asm/idtentry.h:568
RIP: 0033:0x6ba5ac1c52
RSP: 002b:0000000020000338 EFLAGS: 00010217
RAX: 0000000000000000 RBX: 00007fa1522df120 RCX: 00007fa1521bf169
RDX: 0000000000000000 RSI: 0000000020000330 RDI: 0000000000008000
RBP: 00007fa15221aca1 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000206 R12: 0000000000000000
R13: 00007ffe85aa104f R14: 00007fa1514ef300 R15: 0000000000022000
</TASK>

Showing all locks held in the system:
1 lock held by khungtaskd/26:
#0: ffffffff8c91c4e0 (rcu_read_lock){....}-{1:2}, at: rcu_lock_acquire+0x0/0x30
2 locks held by kworker/u4:2/154:
#0: ffff888011c69138 ((wq_completion)events_unbound){+.+.}-{0:0}, at: process_one_work+0x78a/0x10c0 kernel/workqueue.c:2279
#1: ffffc9000126fd20 (connector_reaper_work){+.+.}-{0:0}, at: process_one_work+0x7d0/0x10c0 kernel/workqueue.c:2281
2 locks held by getty/3262:
#0: ffff88814b1ba098 (&tty->ldisc_sem){++++}-{0:0}, at: tty_ldisc_ref_wait+0x21/0x70 drivers/tty/tty_ldisc.c:252
#1: ffffc900020a32e8 (&ldata->atomic_read_lock){+.+.}-{3:3}, at: n_tty_read+0x6af/0x1da0 drivers/tty/n_tty.c:2147
3 locks held by kworker/u4:7/4246:
#0: ffff888013db5138 ((wq_completion)writeback){+.+.}-{0:0}, at: process_one_work+0x78a/0x10c0 kernel/workqueue.c:2279
#1: ffffc9000381fd20 ((work_completion)(&(&wb->dwork)->work)){+.+.}-{0:0}, at: process_one_work+0x7d0/0x10c0 kernel/workqueue.c:2281
#2: ffff88814b2f8bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2687
3 locks held by syz-executor.3/4953:
#0: ffff88814b2f6460 (sb_writers#5){.+.+}-{0:0}, at: do_coredump+0x1825/0x31e0 fs/coredump.c:825
#1: ffff8880720d67a0 (&sb->s_type->i_mutex_key#9){++++}-{3:3}, at: inode_lock include/linux/fs.h:787 [inline]
#1: ffff8880720d67a0 (&sb->s_type->i_mutex_key#9){++++}-{3:3}, at: ext4_buffered_write_iter+0xb9/0x380 fs/ext4/file.c:263
#2: ffff88814b2f60e0 (&type->s_umount_key#32){++++}-{3:3}, at: try_to_writeback_inodes_sb+0x1d/0xb0 fs/fs-writeback.c:2704
3 locks held by syz-executor.1/5867:
1 lock held by syz-executor.3/5885:
1 lock held by syz-executor.3/6567:
2 locks held by syz-executor.2/6783:
#0: ffff88814b2f8bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2687
#1: ffff8880b9a39698 (&rq->__lock){-.-.}-{2:2}, at: raw_spin_rq_lock_nested+0x26/0x140 kernel/sched/core.c:475
3 locks held by syz-executor.1/6795:
2 locks held by syz-executor.3/6807:
1 lock held by syz-executor.2/6894:
#0: ffff88814b2f8bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2687
1 lock held by syz-executor.0/7050:
1 lock held by syz-executor.2/7062:
1 lock held by syz-executor.1/8054:
1 lock held by syz-executor.2/8064:
3 locks held by syz-executor.3/8070:
1 lock held by syz-executor.4/8094:
1 lock held by syz-executor.1/8099:
1 lock held by syz-executor.1/8100:
1 lock held by syz-executor.1/8101:
1 lock held by syz-executor.4/8131:
1 lock held by syz-executor.5/8133:
1 lock held by syz-executor.0/8134:
1 lock held by syz-executor.0/8142:
1 lock held by syz-executor.2/8157:
#0: ffff88814b2f8bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2687
1 lock held by syz-executor.1/8160:
1 lock held by syz-executor.3/8165:
1 lock held by syz-executor.4/8166:
1 lock held by syz-executor.2/8170:
1 lock held by syz-executor.5/8199:
1 lock held by syz-executor.5/8203:
1 lock held by syz-executor.1/8205:
#0: ffff88814b2f8bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2687
1 lock held by syz-executor.0/8212:
1 lock held by syz-executor.3/8216:
1 lock held by syz-executor.2/8218:
#0: ffff88814b2f8bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2687
1 lock held by syz-executor.0/8222:
#0: ffff88814b2f8bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2687
1 lock held by syz-executor.2/8229:
1 lock held by syz-executor.3/8230:
1 lock held by syz-executor.2/8232:
1 lock held by syz-executor.0/8263:
1 lock held by syz-executor.3/8267:
2 locks held by syz-executor.4/8290:
1 lock held by syz-executor.1/8294:
1 lock held by syz-executor.4/8296:
1 lock held by syz-executor.2/8305:
1 lock held by syz-executor.5/8313:
2 locks held by syz-executor.4/8330:
2 locks held by syz-executor.4/8339:
1 lock held by syz-executor.4/8340:
1 lock held by syz-executor.2/8350:
1 lock held by syz-executor.1/8352:
1 lock held by syz-executor.3/8405:
1 lock held by syz-executor.2/8518:
1 lock held by syz-executor.0/8600:
1 lock held by syz-executor.5/8621:
1 lock held by syz-executor.2/8627:
2 locks held by syz-executor.0/8852:
1 lock held by syz-executor.1/8988:
1 lock held by syz-executor.5/8992:
1 lock held by syz-executor.2/9265:
1 lock held by syz-executor.1/9665:
1 lock held by syz-executor.3/9909:
1 lock held by syz-executor.1/10004:
#0: ffff88814b2f8bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2687
2 locks held by syz-executor.4/11718:
2 locks held by syz-executor.4/11720:
#0: ffff88814b2f6460 (sb_writers#5){.+.+}-{0:0}, at: do_coredump+0x1825/0x31e0 fs/coredump.c:825
#1: ffff88806a9a3fc0 (&sb->s_type->i_mutex_key#9){++++}-{3:3}, at: inode_lock include/linux/fs.h:787 [inline]
#1: ffff88806a9a3fc0 (&sb->s_type->i_mutex_key#9){++++}-{3:3}, at: ext4_buffered_write_iter+0xb9/0x380 fs/ext4/file.c:263
2 locks held by syz-executor.4/11721:
1 lock held by syz-executor.5/11740:
2 locks held by syz-executor.5/11741:
2 locks held by syz-executor.3/11743:
2 locks held by syz-executor.1/11746:
2 locks held by syz-executor.5/11751:
3 locks held by syz-executor.0/11759:
#0: ffff88814b2f6460 (sb_writers#5){.+.+}-{0:0}, at: do_coredump+0x1825/0x31e0 fs/coredump.c:825
#1: ffff8880720e35c8 (&sb->s_type->i_mutex_key#9){++++}-{3:3}, at: inode_lock include/linux/fs.h:787 [inline]
#1: ffff8880720e35c8 (&sb->s_type->i_mutex_key#9){++++}-{3:3}, at: ext4_buffered_write_iter+0xb9/0x380 fs/ext4/file.c:263
#2: ffff88814b2fa3f8 (&journal->j_checkpoint_mutex){+.+.}-{3:3}, at: jbd2_log_do_checkpoint+0xd61/0x1660 fs/jbd2/checkpoint.c:284
3 locks held by syz-executor.3/11760:
#0: ffff88814b2f6460 (sb_writers#5){.+.+}-{0:0}, at: do_coredump+0x1825/0x31e0 fs/coredump.c:825
#1: ffff88806d1997e0 (&sb->s_type->i_mutex_key#9){++++}-{3:3}, at: inode_lock include/linux/fs.h:787 [inline]
#1: ffff88806d1997e0 (&sb->s_type->i_mutex_key#9){++++}-{3:3}, at: ext4_buffered_write_iter+0xb9/0x380 fs/ext4/file.c:263
#2: ffff8880b9b39698 (&rq->__lock){-.-.}-{2:2}, at: raw_spin_rq_lock_nested+0x26/0x140 kernel/sched/core.c:475
3 locks held by syz-executor.3/11761:
2 locks held by syz-executor.1/11763:
3 locks held by syz-executor.0/11764:
#0: ffff88814b2f6460 (sb_writers#5){.+.+}-{0:0}, at: do_coredump+0x1825/0x31e0 fs/coredump.c:825
#1: ffff88806d19abd0 (&sb->s_type->i_mutex_key#9){++++}-{3:3}, at: inode_lock include/linux/fs.h:787 [inline]
#1: ffff88806d19abd0 (&sb->s_type->i_mutex_key#9){++++}-{3:3}, at: ext4_buffered_write_iter+0xb9/0x380 fs/ext4/file.c:263
#2: ffff88814b2fa990 (jbd2_handle){++++}-{0:0}, at: start_this_handle+0x12d5/0x1590 fs/jbd2/transaction.c:466
3 locks held by syz-executor.2/11765:
2 locks held by syz-executor.1/11768:
2 locks held by syz-executor.4/11769:
2 locks held by syz-executor.4/11773:
2 locks held by syz-executor.2/11775:
3 locks held by syz-executor.4/11778:
2 locks held by syz-executor.0/11786:
2 locks held by syz-executor.0/11797:
2 locks held by syz-executor.0/11798:
3 locks held by syz-executor.1/11801:
2 locks held by syz-executor.5/11806:
2 locks held by syz-executor.2/11812:
2 locks held by syz-executor.5/11817:
2 locks held by syz-executor.1/11823:
2 locks held by syz-executor.5/11824:
2 locks held by syz-executor.4/11825:
2 locks held by syz-executor.2/11829:
3 locks held by syz-executor.3/11833:
2 locks held by syz-executor.2/11831:
3 locks held by syz-executor.1/11835:
1 lock held by syz-executor.3/11837:
#0: ffffffff8c920a28 (rcu_state.exp_mutex){+.+.}-{3:3}, at: exp_funnel_lock kernel/rcu/tree_exp.h:290 [inline]
#0: ffffffff8c920a28 (rcu_state.exp_mutex){+.+.}-{3:3}, at: synchronize_rcu_expedited+0x280/0x740 kernel/rcu/tree_exp.h:840
1 lock held by syz-executor.4/11840:
#0: ffffffff8c920a28 (rcu_state.exp_mutex){+.+.}-{3:3}, at: exp_funnel_lock kernel/rcu/tree_exp.h:322 [inline]
#0: ffffffff8c920a28 (rcu_state.exp_mutex){+.+.}-{3:3}, at: synchronize_rcu_expedited+0x350/0x740 kernel/rcu/tree_exp.h:840
2 locks held by syz-executor.0/11855:
1 lock held by syz-executor.2/11859:
3 locks held by syz-executor.5/11864:
2 locks held by syz-executor.0/11870:
2 locks held by syz-executor.2/11871:
2 locks held by syz-executor.2/11876:
2 locks held by syz-executor.3/11879:
2 locks held by syz-executor.3/11881:
2 locks held by syz-executor.4/11888:
3 locks held by syz-executor.3/11894:
2 locks held by syz-executor.4/11895:
2 locks held by syz-executor.4/11896:
#0: ffff88814b2f6460 (sb_writers#5){.+.+}-{0:0}, at: mnt_want_write+0x3b/0x80 fs/namespace.c:377
#1: ffff8880722d7198 (&type->i_mutex_dir_key#4){++++}-{3:3}, at: inode_lock include/linux/fs.h:787 [inline]
#1: ffff8880722d7198 (&type->i_mutex_dir_key#4){++++}-{3:3}, at: open_last_lookups fs/namei.c:3459 [inline]
#1: ffff8880722d7198 (&type->i_mutex_dir_key#4){++++}-{3:3}, at: path_openat+0x824/0x2f20 fs/namei.c:3669
2 locks held by syz-executor.1/11898:
2 locks held by syz-executor.5/11899:
3 locks held by syz-executor.1/11902:
2 locks held by syz-executor.5/11912:
2 locks held by syz-executor.0/11927:
2 locks held by syz-executor.2/11928:
3 locks held by syz-executor.0/11938:
#0: ffff88814b2f6460 (sb_writers#5){.+.+}-{0:0}, at: mnt_want_write+0x3b/0x80 fs/namespace.c:377
#1: ffff88806abf83f0 (&type->i_mutex_dir_key#4/1){+.+.}-{3:3}, at: inode_lock_nested include/linux/fs.h:822 [inline]
#1: ffff88806abf83f0 (&type->i_mutex_dir_key#4/1){+.+.}-{3:3}, at: do_unlinkat+0x260/0x940 fs/namei.c:4260
#2: ffff88806d090de8 (&sb->s_type->i_mutex_key#9){++++}-{3:3}, at: inode_lock include/linux/fs.h:787 [inline]
#2: ffff88806d090de8 (&sb->s_type->i_mutex_key#9){++++}-{3:3}, at: vfs_unlink+0xe0/0x5f0 fs/namei.c:4198
2 locks held by syz-executor.0/11939:
#0: ffff88814b2f6460 (sb_writers#5){.+.+}-{0:0}, at: mnt_want_write+0x3b/0x80 fs/namespace.c:377
#1: ffff88806abf83f0 (&type->i_mutex_dir_key#4/1){+.+.}-{3:3}, at: inode_lock_nested include/linux/fs.h:822 [inline]
#1: ffff88806abf83f0 (&type->i_mutex_dir_key#4/1){+.+.}-{3:3}, at: do_unlinkat+0x260/0x940 fs/namei.c:4260
2 locks held by syz-executor.3/11941:
1 lock held by syz-executor.2/11942:
2 locks held by syz-executor.3/11943:
2 locks held by syz-executor.3/11944:

=============================================

NMI backtrace for cpu 0
CPU: 0 PID: 26 Comm: khungtaskd Not tainted 5.15.109-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/14/2023
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:88 [inline]
dump_stack_lvl+0x1e3/0x2cb lib/dump_stack.c:106
nmi_cpu_backtrace+0x46a/0x4a0 lib/nmi_backtrace.c:111
nmi_trigger_cpumask_backtrace+0x181/0x2a0 lib/nmi_backtrace.c:62
trigger_all_cpu_backtrace include/linux/nmi.h:148 [inline]
check_hung_uninterruptible_tasks kernel/hung_task.c:210 [inline]
watchdog+0xe72/0xeb0 kernel/hung_task.c:295
kthread+0x3f6/0x4f0 kernel/kthread.c:319
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:298
</TASK>
Sending NMI from CPU 0 to CPUs 1:
NMI backtrace for cpu 1
CPU: 1 PID: 1219 Comm: kworker/u4:5 Not tainted 5.15.109-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/14/2023
Workqueue: ext4-rsv-conversion ext4_end_io_rsv_work
RIP: 0010:rcu_read_unlock include/linux/rcupdate.h:725 [inline]
RIP: 0010:__unlock_page_memcg+0xb5/0x110 mm/memcontrol.c:2090
Code: 2f 00 74 08 4c 89 e7 e8 99 3f fb ff 48 c7 83 b0 06 00 00 00 00 00 00 48 81 c3 70 06 00 00 48 89 df 48 8b 34 24 e8 3b 86 55 08 <e8> 76 34 4c 08 85 c0 74 3a e8 6d c6 9c ff 84 c0 75 31 e8 64 34 4c
RSP: 0018:ffffc900059df8c0 EFLAGS: 00000207
RAX: ffff88801d57d700 RBX: ffff888073d9c000 RCX: ffffffff81cea338
RDX: 0000000000000000 RSI: 0000000000000008 RDI: ffff888073d9c000
RBP: 1ffff1100e7b3a11 R08: dffffc0000000000 R09: fffff94000acfb09
R10: 0000000000000000 R11: dffffc0000000001 R12: dffffc0000000000
R13: dffffc0000000000 R14: ffff888073d9d088 R15: 0000000000000001
FS: 0000000000000000(0000) GS:ffff8880b9b00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007ffea19adfe8 CR3: 000000006e14f000 CR4: 00000000003506e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
test_clear_page_writeback+0xb29/0xd30 mm/page-writeback.c:2813
end_page_writeback+0x2a6/0x690 mm/filemap.c:1603
ext4_finish_bio+0x751/0x8b0 fs/ext4/page-io.c:145
ext4_release_io_end+0xdf/0x2c0 fs/ext4/page-io.c:160
ext4_end_io_end fs/ext4/page-io.c:194 [inline]
ext4_do_flush_completed_IO fs/ext4/page-io.c:259 [inline]
ext4_end_io_rsv_work+0x5d6/0x6e0 fs/ext4/page-io.c:273
process_one_work+0x8a1/0x10c0 kernel/workqueue.c:2306
worker_thread+0xaca/0x1280 kernel/workqueue.c:2453
kthread+0x3f6/0x4f0 kernel/kthread.c:319
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:298
</TASK>


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

syzbot

unread,
Aug 6, 2023, 12:07:34 PM8/6/23
to syzkaller...@googlegroups.com
syzbot suspects this issue could be fixed by backporting the following commit:

commit 8d5459c11f548131ce48b2fbf45cccc5c382558f
git tree: upstream
Author: Jan Kara <ja...@suse.cz>
Date: Fri May 20 11:14:02 2022 +0000

ext4: improve write performance with disabled delalloc

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=11b352eda80000
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1664eaf7c80000


Please keep in mind that other backports might be required as well.

For information about bisection process see: https://goo.gl/tpsmEJ#bisection

syzbot

unread,
Aug 15, 2023, 3:49:56 AM8/15/23
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 24c4de4069cb Linux 5.15.126
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1317bb3ba80000
kernel config: https://syzkaller.appspot.com/x/.config?x=295181026c532aa4
dashboard link: https://syzkaller.appspot.com/bug?extid=59b165f27afa8541bb41
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=13cadf69a80000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=17ae4265a80000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/fc7c92a13bf3/disk-24c4de40.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/7be7d7c70650/vmlinux-24c4de40.xz
kernel image: https://storage.googleapis.com/syzbot-assets/8c1a025e4df3/bzImage-24c4de40.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+59b165...@syzkaller.appspotmail.com

INFO: task syz-executor169:4371 blocked for more than 143 seconds.
Not tainted 5.15.126-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:syz-executor169 state:D stack:23224 pid: 4371 ppid: 3522 flags:0x00004002
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5026 [inline]
__schedule+0x12c4/0x4590 kernel/sched/core.c:6372
schedule+0x11b/0x1f0 kernel/sched/core.c:6455
wb_wait_for_completion+0x164/0x290 fs/fs-writeback.c:191
__writeback_inodes_sb_nr+0x2ce/0x370 fs/fs-writeback.c:2662
try_to_writeback_inodes_sb+0x94/0xb0 fs/fs-writeback.c:2710
ext4_nonda_switch fs/ext4/inode.c:2933 [inline]
ext4_da_write_begin+0x228/0xb60 fs/ext4/inode.c:2960
generic_perform_write+0x2bf/0x5b0 mm/filemap.c:3776
ext4_buffered_write_iter+0x227/0x360 fs/ext4/file.c:268
ext4_file_write_iter+0x87c/0x1990
__kernel_write+0x5b1/0xa60 fs/read_write.c:539
__dump_emit+0x264/0x3a0 fs/coredump.c:875
dump_user_range+0x91/0x320 fs/coredump.c:949
elf_core_dump+0x3c7d/0x4570 fs/binfmt_elf.c:2285
do_coredump+0x1852/0x31e0 fs/coredump.c:826
get_signal+0xc06/0x14e0 kernel/signal.c:2875
arch_do_signal_or_restart+0xc3/0x1890 arch/x86/kernel/signal.c:867
handle_signal_work kernel/entry/common.c:148 [inline]
exit_to_user_mode_loop+0x97/0x130 kernel/entry/common.c:172
exit_to_user_mode_prepare+0xb1/0x140 kernel/entry/common.c:208
irqentry_exit_to_user_mode+0x5/0x30 kernel/entry/common.c:314
exc_page_fault+0x342/0x740 arch/x86/mm/fault.c:1544
asm_exc_page_fault+0x22/0x30 arch/x86/include/asm/idtentry.h:568
RIP: 0033:0x0
RSP: 002b:00000000200000c8 EFLAGS: 00010217
RAX: 0000000000000000 RBX: 0000000000000000 RCX: 00007fe80117c429
RDX: 0000000000000000 RSI: 00000000200000c0 RDI: 0000000000040000
RBP: 00000000000f4240 R08: 0000000020000200 R09: 00007ffe2b51bda0
R10: 0000000000000000 R11: 0000000000000246 R12: 000000000004213e
R13: 00007fe8011fab20 R14: 00007fe8011fcce0 R15: 00007ffe2b51bd90
</TASK>

Showing all locks held in the system:
1 lock held by ksoftirqd/1/20:
1 lock held by khungtaskd/27:
#0: ffffffff8c91f0a0 (rcu_read_lock){....}-{1:2}, at: rcu_lock_acquire+0x0/0x30
2 locks held by kworker/u4:3/155:
#0: ffff8880b9a396d8 (&rq->__lock){-.-.}-{2:2}, at: raw_spin_rq_lock_nested+0x26/0x140 kernel/sched/core.c:475
#1: ffffc90001c4fd20 ((work_completion)(&ei->i_rsv_conversion_work)){+.+.}-{0:0}, at: process_one_work+0x7d0/0x10c0 kernel/workqueue.c:2285
2 locks held by kworker/1:2/1053:
#0: ffff888011c72538 ((wq_completion)rcu_gp){+.+.}-{0:0}, at: process_one_work+0x78a/0x10c0 kernel/workqueue.c:2283
#1: ffffc90004b37d20 ((work_completion)(&rew.rew_work)){+.+.}-{0:0}, at: process_one_work+0x7d0/0x10c0 kernel/workqueue.c:2285
3 locks held by kworker/u4:5/1201:
#0: ffff8880139a4938 ((wq_completion)writeback){+.+.}-{0:0}, at: process_one_work+0x78a/0x10c0 kernel/workqueue.c:2283
#1: ffffc9000543fd20 ((work_completion)(&(&wb->dwork)->work)){+.+.}-{0:0}, at: process_one_work+0x7d0/0x10c0 kernel/workqueue.c:2285
#2: ffff88814b520bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2677
2 locks held by getty/3253:
#0: ffff8880241a0098 (&tty->ldisc_sem){++++}-{0:0}, at: tty_ldisc_ref_wait+0x21/0x70 drivers/tty/tty_ldisc.c:252
#1: ffffc900022a32e8 (&ldata->atomic_read_lock){+.+.}-{3:3}, at: n_tty_read+0x6af/0x1db0 drivers/tty/n_tty.c:2158
1 lock held by syz-executor169/3619:
#0: ffff88814b520bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2677
1 lock held by syz-executor169/3632:
#0: ffff88814b520bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2677
1 lock held by syz-executor169/3641:
#0: ffff88814b520bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2677
1 lock held by syz-executor169/3658:
#0: ffff88814b520bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2677
1 lock held by syz-executor169/3678:
#0: ffff88814b520bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2677
1 lock held by syz-executor169/3682:
#0: ffff88814b520bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2677
1 lock held by syz-executor169/3700:
#0: ffff88814b520bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2677
1 lock held by syz-executor169/3708:
#0: ffff88814b520bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2677
1 lock held by syz-executor169/3723:
#0: ffff88814b520bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2677
2 locks held by syz-executor169/3732:
#0: ffff88814b520bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2677
#1: ffff8880b9a396d8 (&rq->__lock){-.-.}-{2:2}, at: raw_spin_rq_lock_nested+0x26/0x140 kernel/sched/core.c:475
2 locks held by syz-executor169/3735:
#0: ffff88814b520bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2677
#1: ffff88814b5223f8 (&journal->j_checkpoint_mutex){+.+.}-{3:3}, at: __jbd2_log_wait_for_space+0x213/0x760 fs/jbd2/checkpoint.c:88
1 lock held by syz-executor169/3739:
#0: ffff88814b51e650 (sb_internal){.+.+}-{0:0}, at: __sb_start_write include/linux/fs.h:1742 [inline]
#0: ffff88814b51e650 (sb_internal){.+.+}-{0:0}, at: sb_start_intwrite include/linux/fs.h:1859 [inline]
#0: ffff88814b51e650 (sb_internal){.+.+}-{0:0}, at: ext4_evict_inode+0x375/0x1100 fs/ext4/inode.c:243
1 lock held by syz-executor169/3754:
#0: ffff88814b520bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2677
2 locks held by syz-executor169/3755:
#0: ffff88814b520bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2677
#1: ffff88814b5223f8 (&journal->j_checkpoint_mutex){+.+.}-{3:3}, at: __jbd2_log_wait_for_space+0x213/0x760 fs/jbd2/checkpoint.c:88
2 locks held by syz-executor169/3764:
#0: ffff88814b520bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2677
#1: ffff88814b5223f8 (&journal->j_checkpoint_mutex){+.+.}-{3:3}, at: __jbd2_log_wait_for_space+0x213/0x760 fs/jbd2/checkpoint.c:88
2 locks held by syz-executor169/3801:
#0: ffff88814b520bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2677
#1: ffff88814b5223f8 (&journal->j_checkpoint_mutex){+.+.}-{3:3}, at: __jbd2_log_wait_for_space+0x213/0x760 fs/jbd2/checkpoint.c:88
2 locks held by syz-executor169/3803:
#0: ffff88814b520bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2677
#1: ffff88814b5223f8 (&journal->j_checkpoint_mutex){+.+.}-{3:3}, at: __jbd2_log_wait_for_space+0x213/0x760 fs/jbd2/checkpoint.c:88
2 locks held by syz-executor169/3808:
#0: ffff88814b520bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2677
#1: ffff8880b9b396d8 (&rq->__lock){-.-.}-{2:2}, at: raw_spin_rq_lock_nested+0x26/0x140 kernel/sched/core.c:475
1 lock held by syz-executor169/3816:
#0: ffff88814b520bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2677
1 lock held by syz-executor169/3840:
#0: ffff88814b520bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2677
1 lock held by syz-executor169/3852:
#0: ffff88814b520bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2677
2 locks held by syz-executor169/3856:
#0: ffff88814b520bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2677
#1: ffff88814b5223f8 (&journal->j_checkpoint_mutex){+.+.}-{3:3}, at: __jbd2_log_wait_for_space+0x213/0x760 fs/jbd2/checkpoint.c:88
2 locks held by syz-executor169/3869:
#0: ffff88814b520bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2677
#1: ffff88814b5223f8 (&journal->j_checkpoint_mutex){+.+.}-{3:3}, at: __jbd2_log_wait_for_space+0x213/0x760 fs/jbd2/checkpoint.c:88
2 locks held by syz-executor169/3879:
#0: ffff88814b520bd8 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1f6/0x3d10 fs/ext4/inode.c:2677
#1: ffff88814b5223f8 (&journal->j_checkpoint_mutex){+.+.}-{3:3}, at: __jbd2_log_wait_for_space+0x213/0x760 fs/jbd2/checkpoint.c:88
2 locks held by syz-executor169/3887:

syzbot

unread,
Aug 18, 2023, 2:37:04 AM8/18/23
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 6c44e13dc284 Linux 6.1.46
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=12e4a437a80000
kernel config: https://syzkaller.appspot.com/x/.config?x=d53bfb03cd3f0d5d
dashboard link: https://syzkaller.appspot.com/bug?extid=14cba5ca5a8659fdc3b2
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/29901b5379f9/disk-6c44e13d.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/4f5885be1097/vmlinux-6c44e13d.xz
kernel image: https://storage.googleapis.com/syzbot-assets/23c8fefbd6c4/bzImage-6c44e13d.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+14cba5...@syzkaller.appspotmail.com

INFO: task syz-executor.2:1798 blocked for more than 143 seconds.
Not tainted 6.1.46-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:syz-executor.2 state:D stack:21176 pid:1798 ppid:1269 flags:0x00004006
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5241 [inline]
__schedule+0x132c/0x4330 kernel/sched/core.c:6554
schedule+0xbf/0x180 kernel/sched/core.c:6630
wb_wait_for_completion+0x162/0x290 fs/fs-writeback.c:191
__writeback_inodes_sb_nr+0x2ce/0x370 fs/fs-writeback.c:2631
try_to_writeback_inodes_sb+0x94/0xb0 fs/fs-writeback.c:2679
ext4_nonda_switch fs/ext4/inode.c:2947 [inline]
ext4_da_write_begin+0x229/0x9c0 fs/ext4/inode.c:2974
generic_perform_write+0x2fc/0x5e0 mm/filemap.c:3754
ext4_buffered_write_iter+0x122/0x3a0 fs/ext4/file.c:285
ext4_file_write_iter+0x1d2/0x18f0
__kernel_write_iter+0x2ff/0x710 fs/read_write.c:517
dump_emit_page fs/coredump.c:881 [inline]
dump_user_range+0x43d/0x8e0 fs/coredump.c:908
elf_core_dump+0x3cff/0x45b0 fs/binfmt_elf.c:2312
do_coredump+0x18b7/0x2700 fs/coredump.c:755
get_signal+0x1454/0x17d0 kernel/signal.c:2848
arch_do_signal_or_restart+0xb0/0x1a10 arch/x86/kernel/signal.c:871
exit_to_user_mode_loop+0x6a/0x100 kernel/entry/common.c:168
exit_to_user_mode_prepare+0xb1/0x140 kernel/entry/common.c:204
irqentry_exit_to_user_mode+0x5/0x30 kernel/entry/common.c:310
exc_general_protection+0x3e0/0x590 arch/x86/kernel/traps.c:731
asm_exc_general_protection+0x22/0x30 arch/x86/include/asm/idtentry.h:564
RIP: 0033:0x7f0be067caf1
RSP: 002b:0000000020000140 EFLAGS: 00010217
RAX: 0000000000000000 RBX: 00007f0be079bf80 RCX: 00007f0be067cae9
RDX: 0000000000000000 RSI: 0000000020000140 RDI: 0000000000000480
RBP: 00007f0be06c847a R08: 0000000020000200 R09: 0000000020000200
R10: 00000000200001c0 R11: 0000000000000202 R12: 0000000000000000
R13: 000000000000000b R14: 00007f0be079bf80 R15: 00007fff06bb1e28
</TASK>

Showing all locks held in the system:
1 lock held by rcu_tasks_kthre/12:
#0: ffffffff8d12a0b0 (rcu_tasks.tasks_gp_mutex){+.+.}-{3:3}, at: rcu_tasks_one_gp+0x29/0xd20 kernel/rcu/tasks.h:516
1 lock held by rcu_tasks_trace/13:
#0: ffffffff8d12a8b0 (rcu_tasks_trace.tasks_gp_mutex){+.+.}-{3:3}, at: rcu_tasks_one_gp+0x29/0xd20 kernel/rcu/tasks.h:516
1 lock held by khungtaskd/28:
#0: ffffffff8d129ee0 (rcu_read_lock){....}-{1:2}, at: rcu_lock_acquire+0x0/0x30
2 locks held by getty/3270:
#0: ffff88814b2aa098 (&tty->ldisc_sem){++++}-{0:0}, at: tty_ldisc_ref_wait+0x21/0x70 drivers/tty/tty_ldisc.c:244
#1: ffffc900031262f0 (&ldata->atomic_read_lock){+.+.}-{3:3}, at: n_tty_read+0x6a7/0x1db0 drivers/tty/n_tty.c:2188
2 locks held by kworker/0:9/3623:
4 locks held by kworker/u4:8/9748:
#0: ffff88814bc13938 ((wq_completion)ext4-rsv-conversion){+.+.}-{0:0}, at: process_one_work+0x77a/0x11f0
#1: ffffc9000391fd20 ((work_completion)(&ei->i_rsv_conversion_work)){+.+.}-{0:0}, at: process_one_work+0x7bd/0x11f0 kernel/workqueue.c:2267
#2: ffff88807ecd4990 (jbd2_handle){++++}-{0:0}, at: start_this_handle+0x13c8/0x1640 fs/jbd2/transaction.c:461
#3: ffff888082d7d2c8 (&ei->i_data_sem){++++}-{3:3}, at: ext4_map_blocks+0x963/0x1ca0 fs/ext4/inode.c:644
5 locks held by kworker/u4:5/15656:
#0: ffff8880152a6138 ((wq_completion)writeback){+.+.}-{0:0}, at: process_one_work+0x77a/0x11f0
#1: ffffc9000362fd20 ((work_completion)(&(&wb->dwork)->work)){+.+.}-{0:0}, at: process_one_work+0x7bd/0x11f0 kernel/workqueue.c:2267
#2: ffff88807ecd2b98 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1e5/0x3de0 fs/ext4/inode.c:2691
#3: ffff8880b9939e18 (&rq->__lock){-.-.}-{2:2}, at: raw_spin_rq_lock_nested+0x26/0x140 kernel/sched/core.c:537
#4: ffff8880b9827788 (&per_cpu_ptr(group->pcpu, cpu)->seq){-.-.}-{0:0}, at: psi_task_switch+0x43d/0x770 kernel/sched/psi.c:1000
3 locks held by syz-executor.5/29900:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: mnt_want_write+0x3b/0x80 fs/namespace.c:393
#1: ffff88804b965440 (&type->i_mutex_dir_key#3/1){+.+.}-{3:3}, at: inode_lock_nested include/linux/fs.h:791 [inline]
#1: ffff88804b965440 (&type->i_mutex_dir_key#3/1){+.+.}-{3:3}, at: do_unlinkat+0x260/0x940 fs/namei.c:4303
#2: ffff888082dfd440 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#2: ffff888082dfd440 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: vfs_unlink+0xe0/0x5f0 fs/namei.c:4241
3 locks held by syz-executor.0/31166:
3 locks held by syz-executor.4/324:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: mnt_want_write+0x3b/0x80 fs/namespace.c:393
#1: ffff888086ba08d8 (&mm->mmap_lock){++++}-{3:3}, at: mmap_write_lock_killable include/linux/mmap_lock.h:87 [inline]
#1: ffff888086ba08d8 (&mm->mmap_lock){++++}-{3:3}, at: dup_mmap kernel/fork.c:593 [inline]
#1: ffff888086ba08d8 (&mm->mmap_lock){++++}-{3:3}, at: dup_mm kernel/fork.c:1532 [inline]
#1: ffff888086ba08d8 (&mm->mmap_lock){++++}-{3:3}, at: copy_mm+0x3e5/0x1990 kernel/fork.c:1581
#2: ffff88801246c4d8 (&mm->mmap_lock/1){+.+.}-{3:3}, at: mmap_write_lock_nested include/linux/mmap_lock.h:78 [inline]
#2: ffff88801246c4d8 (&mm->mmap_lock/1){+.+.}-{3:3}, at: dup_mmap kernel/fork.c:602 [inline]
#2: ffff88801246c4d8 (&mm->mmap_lock/1){+.+.}-{3:3}, at: dup_mm kernel/fork.c:1532 [inline]
#2: ffff88801246c4d8 (&mm->mmap_lock/1){+.+.}-{3:3}, at: copy_mm+0x4ca/0x1990 kernel/fork.c:1581
3 locks held by syz-executor.2/1798:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff888082c19810 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff888082c19810 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
#2: ffff88807ecd00e0 (&type->s_umount_key#31){++++}-{3:3}, at: try_to_writeback_inodes_sb+0x1d/0xb0 fs/fs-writeback.c:2676
1 lock held by syz-executor.4/1841:
#0: ffff88807ecd2b98 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1e5/0x3de0 fs/ext4/inode.c:2691
1 lock held by syz-executor.5/1976:
#0: ffff88807ecd2b98 (&sbi->s_writepages_rwsem){.+.+}-{0:0}, at: ext4_writepages+0x1e5/0x3de0 fs/ext4/inode.c:2691
3 locks held by syz-executor.5/2174:
1 lock held by syz-executor.0/2185:
1 lock held by syz-executor.1/2440:
2 locks held by syz-executor.5/2471:
3 locks held by syz-executor.0/2478:
3 locks held by syz-executor.5/2507:
3 locks held by syz-executor.4/2508:
2 locks held by syz-executor.1/2529:
3 locks held by syz-executor.0/2536:
4 locks held by syz-executor.1/2555:
2 locks held by syz-executor.0/2565:
4 locks held by syz-executor.1/2578:
3 locks held by syz-executor.5/2597:
1 lock held by syz-executor.4/2604:
4 locks held by syz-executor.1/2616:
2 locks held by syz-executor.4/2665:
4 locks held by syz-executor.0/2777:
2 locks held by syz-executor.1/2799:
2 locks held by syz-executor.0/2805:
3 locks held by syz-executor.1/2962:
4 locks held by syz-executor.5/2973:
4 locks held by syz-executor.0/2996:
4 locks held by syz-executor.0/3006:
2 locks held by syz-executor.1/3007:
3 locks held by syz-executor.5/3009:
2 locks held by syz-executor.0/3013:
2 locks held by syz-executor.0/3020:
4 locks held by syz-executor.0/3026:
3 locks held by syz-executor.4/3033:
4 locks held by syz-executor.1/3036:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff88802ad1e850 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff88802ad1e850 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
#2: ffff8880b9939e18 (&rq->__lock){-.-.}-{2:2}, at: raw_spin_rq_lock_nested+0x26/0x140 kernel/sched/core.c:537
#3: ffff8880b9927788 (&per_cpu_ptr(group->pcpu, cpu)->seq){-.-.}-{0:0}, at: psi_task_switch+0x43d/0x770 kernel/sched/psi.c:1000
3 locks held by syz-executor.5/3043:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff88808404ac20 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff88808404ac20 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
#2: ffff88807ecd4990 (jbd2_handle){++++}-{0:0}, at: start_this_handle+0x13c8/0x1640 fs/jbd2/transaction.c:461
2 locks held by syz-executor.0/3044:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff888084048400 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff888084048400 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
2 locks held by syz-executor.4/3045:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff88802ad1d440 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff88802ad1d440 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
5 locks held by syz-executor.1/3141:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff8880831f0e08 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff8880831f0e08 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
#2: ffff8880831f0fa8 (mapping.invalidate_lock){++++}-{3:3}, at: filemap_invalidate_lock include/linux/fs.h:801 [inline]
#2: ffff8880831f0fa8 (mapping.invalidate_lock){++++}-{3:3}, at: ext4_truncate_failed_write fs/ext4/truncate.h:20 [inline]
#2: ffff8880831f0fa8 (mapping.invalidate_lock){++++}-{3:3}, at: ext4_write_begin+0xa97/0xf80 fs/ext4/inode.c:1252
#3: ffff88807ecd4990 (jbd2_handle){++++}-{0:0}, at: start_this_handle+0x13c8/0x1640 fs/jbd2/transaction.c:461
#4: ffff8880831f0c90 (&ei->i_data_sem){++++}-{3:3}, at: ext4_truncate+0x999/0x1290 fs/ext4/inode.c:4260
4 locks held by syz-executor.3/3314:
#0: ffff8880610ad9e8 (&f->f_pos_lock){+.+.}-{3:3}, at: __fdget_pos+0x2ba/0x360 fs/file.c:1062
#1: ffff888082dfe850 (&type->i_mutex_dir_key#3){++++}-{3:3}, at: iterate_dir+0x10a/0x560 fs/readdir.c:55
#2: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: file_accessed include/linux/fs.h:2535 [inline]
#2: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: iterate_dir+0x484/0x560 fs/readdir.c:70
#3: ffff88807ecd4990 (jbd2_handle){++++}-{0:0}, at: start_this_handle+0x13c8/0x1640 fs/jbd2/transaction.c:461
3 locks held by syz-executor.3/3466:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff88808404d440 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff88808404d440 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
#2: ffff88807ecd4990 (jbd2_handle){++++}-{0:0}, at: start_this_handle+0x13c8/0x1640 fs/jbd2/transaction.c:461
3 locks held by syz-executor.3/3475:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff88803a500400 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff88803a500400 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
#2: ffff88807ecd4990 (jbd2_handle){++++}-{0:0}, at: start_this_handle+0x13c8/0x1640 fs/jbd2/transaction.c:461
5 locks held by syz-executor.3/3488:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff888082dfac20 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff888082dfac20 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
#2: ffff888082dfadc0 (mapping.invalidate_lock){++++}-{3:3}, at: filemap_invalidate_lock include/linux/fs.h:801 [inline]
#2: ffff888082dfadc0 (mapping.invalidate_lock){++++}-{3:3}, at: ext4_truncate_failed_write fs/ext4/truncate.h:20 [inline]
#2: ffff888082dfadc0 (mapping.invalidate_lock){++++}-{3:3}, at: ext4_write_begin+0xa97/0xf80 fs/ext4/inode.c:1252
#3: ffff88807ecd4990 (jbd2_handle){++++}-{0:0}, at: start_this_handle+0x13c8/0x1640 fs/jbd2/transaction.c:461
#4: ffff888082dfaaa8 (&ei->i_data_sem){++++}-{3:3}, at: ext4_truncate+0x999/0x1290 fs/ext4/inode.c:4260
3 locks held by syz-executor.4/3490:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff8880824b8400 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff8880824b8400 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
#2: ffff88807ecd4990 (jbd2_handle){++++}-{0:0}, at: start_this_handle+0x13c8/0x1640 fs/jbd2/transaction.c:461
3 locks held by syz-executor.5/3493:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff888082dff258 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff888082dff258 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
#2: ffff88807ecd4990 (jbd2_handle){++++}-{0:0}, at: start_this_handle+0x13c8/0x1640 fs/jbd2/transaction.c:461
5 locks held by syz-executor.1/3496:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff8880824ba218 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff8880824ba218 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
#2: ffff8880824ba3b8 (mapping.invalidate_lock){++++}-{3:3}, at: filemap_invalidate_lock include/linux/fs.h:801 [inline]
#2: ffff8880824ba3b8 (mapping.invalidate_lock){++++}-{3:3}, at: ext4_truncate_failed_write fs/ext4/truncate.h:20 [inline]
#2: ffff8880824ba3b8 (mapping.invalidate_lock){++++}-{3:3}, at: ext4_write_begin+0xa97/0xf80 fs/ext4/inode.c:1252
#3: ffff88807ecd4990 (jbd2_handle){++++}-{0:0}, at: start_this_handle+0x13c8/0x1640 fs/jbd2/transaction.c:461
#4: ffff8880824ba0a0 (&ei->i_data_sem){++++}-{3:3}, at: ext4_truncate+0x999/0x1290 fs/ext4/inode.c:4260
3 locks held by syz-executor.0/3513:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff88804e9f5440 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff88804e9f5440 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
#2: ffff88807ecd4990 (jbd2_handle){++++}-{0:0}, at: start_this_handle+0x13c8/0x1640 fs/jbd2/transaction.c:461
3 locks held by syz-executor.4/3524:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff88804bb96850 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff88804bb96850 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
#2: ffff88807ecd4990 (jbd2_handle){++++}-{0:0}, at: start_this_handle+0x13c8/0x1640 fs/jbd2/transaction.c:461
2 locks held by syz-executor.3/3528:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff88804bb95440 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff88804bb95440 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
2 locks held by syz-executor.5/3534:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff88804bb92c20 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff88804bb92c20 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
2 locks held by syz-executor.2/3535:
#0: ffff888087910d68 (&f->f_pos_lock){+.+.}-{3:3}, at: __fdget_pos+0x2ba/0x360 fs/file.c:1062
#1: ffff88804bb95e48 (&type->i_mutex_dir_key#3){++++}-{3:3}, at: iterate_dir+0x10a/0x560 fs/readdir.c:55
5 locks held by syz-executor.3/3545:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff88808402ac20 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff88808402ac20 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
#2: ffff88808402adc0 (mapping.invalidate_lock){++++}-{3:3}, at: filemap_invalidate_lock include/linux/fs.h:801 [inline]
#2: ffff88808402adc0 (mapping.invalidate_lock){++++}-{3:3}, at: ext4_truncate_failed_write fs/ext4/truncate.h:20 [inline]
#2: ffff88808402adc0 (mapping.invalidate_lock){++++}-{3:3}, at: ext4_write_begin+0xa97/0xf80 fs/ext4/inode.c:1252
#3: ffff88807ecd4990 (jbd2_handle){++++}-{0:0}, at: start_this_handle+0x13c8/0x1640 fs/jbd2/transaction.c:461
#4: ffff88808402aaa8 (&ei->i_data_sem){++++}-{3:3}, at: ext4_truncate+0x999/0x1290 fs/ext4/inode.c:4260
3 locks held by syz-executor.1/3553:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff88808402f258 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff88808402f258 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
#2: ffff88807ecd4990 (jbd2_handle){++++}-{0:0}, at: start_this_handle+0x13c8/0x1640 fs/jbd2/transaction.c:461
5 locks held by syz-executor.2/3648:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff88802ad1de48 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff88802ad1de48 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
#2: ffff88802ad1dfe8 (mapping.invalidate_lock){++++}-{3:3}, at: filemap_invalidate_lock include/linux/fs.h:801 [inline]
#2: ffff88802ad1dfe8 (mapping.invalidate_lock){++++}-{3:3}, at: ext4_truncate_failed_write fs/ext4/truncate.h:20 [inline]
#2: ffff88802ad1dfe8 (mapping.invalidate_lock){++++}-{3:3}, at: ext4_write_begin+0xa97/0xf80 fs/ext4/inode.c:1252
#3: ffff88807ecd4990 (jbd2_handle){++++}-{0:0}, at: start_this_handle+0x13c8/0x1640 fs/jbd2/transaction.c:461
#4: ffff88802ad1dcd0 (&ei->i_data_sem){++++}-{3:3}, at: ext4_truncate+0x999/0x1290 fs/ext4/inode.c:4260
3 locks held by syz-executor.4/3656:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff888082330e08 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff888082330e08 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
#2: ffff88807ecd4990 (jbd2_handle){++++}-{0:0}, at: start_this_handle+0x13c8/0x1640 fs/jbd2/transaction.c:461
3 locks held by syz-executor.5/3661:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff888033177258 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff888033177258 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
#2: ffff88807ecd4990 (jbd2_handle){++++}-{0:0}, at: start_this_handle+0x13c8/0x1640 fs/jbd2/transaction.c:461
3 locks held by syz-executor.1/3663:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff8880479fac20 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff8880479fac20 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
#2: ffff88807ecd4990 (jbd2_handle){++++}-{0:0}, at: start_this_handle+0x13c8/0x1640 fs/jbd2/transaction.c:461
2 locks held by syz-executor.3/3665:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff888082337258 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff888082337258 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
3 locks held by syz-executor.0/3668:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff888082335440 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff888082335440 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
#2: ffff88807ecd4990 (jbd2_handle){++++}-{0:0}, at: start_this_handle+0x13c8/0x1640 fs/jbd2/transaction.c:461
3 locks held by syz-executor.2/3674:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff8880479ff258 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff8880479ff258 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
#2: ffff88807ecd4990 (jbd2_handle){++++}-{0:0}, at: start_this_handle+0x13c8/0x1640 fs/jbd2/transaction.c:461
2 locks held by syz-executor.3/3682:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff88802f951810 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff88802f951810 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
2 locks held by syz-executor.1/3687:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff88802f954a38 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff88802f954a38 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
2 locks held by syz-executor.5/3688:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff888044435e48 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff888044435e48 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
2 locks held by syz-executor.4/3690:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff888044430400 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff888044430400 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
2 locks held by syz-executor.2/3698:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff888081cec030 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff888081cec030 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
2 locks held by syz-executor.0/3702:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff888082960e08 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff888082960e08 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
2 locks held by syz-executor.1/3705:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff888082965440 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff888082965440 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
2 locks held by syz-executor.3/3708:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff888082c9ac20 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff888082c9ac20 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
2 locks held by syz-executor.4/3711:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff888082c9b628 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff888082c9b628 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
2 locks held by syz-executor.5/3720:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff888082961810 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff888082961810 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
2 locks held by syz-executor.0/3725:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff888082962c20 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff888082962c20 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
2 locks held by syz-executor.1/3731:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff8880828d8e08 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff8880828d8e08 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
2 locks held by syz-executor.3/3736:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff88804b965e48 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff88804b965e48 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
2 locks held by syz-executor.2/3741:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff88804b964a38 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff88804b964a38 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
2 locks held by syz-executor.4/3744:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff888082014a38 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff888082014a38 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
2 locks held by syz-executor.0/3755:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff888082015e48 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff888082015e48 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
2 locks held by syz-executor.1/3756:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff888042d87258 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff888042d87258 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
2 locks held by syz-executor.3/3797:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff8880824bf258 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff8880824bf258 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
2 locks held by syz-executor.2/3799:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff8880824b8e08 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff8880824b8e08 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
2 locks held by syz-executor.5/3800:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff888082dfd440 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff888082dfd440 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
2 locks held by syz-executor.2/3864:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff88804bb91810 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff88804bb91810 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
2 locks held by syz-executor.3/3867:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff888044511810 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff888044511810 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
4 locks held by syz-executor.2/3879:
4 locks held by syz-executor.4/3881:
2 locks held by syz-executor.0/3882:
#0: ffff88807ecd0460 (sb_writers#4){.+.+}-{0:0}, at: do_coredump+0x1892/0x2700 fs/coredump.c:754
#1: ffff88808404de48 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: inode_lock include/linux/fs.h:756 [inline]
#1: ffff88808404de48 (&sb->s_type->i_mutex_key#8){++++}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x3a0 fs/ext4/file.c:279
5 locks held by syz-executor.5/3890:
2 locks held by syz-executor.1/3893:
2 locks held by syz-executor.4/3895:
2 locks held by syz-executor.4/3904:
2 locks held by syz-executor.1/3907:
2 locks held by syz-executor.2/3908:
2 locks held by syz-executor.5/3912:
2 locks held by syz-executor.1/3918:
5 locks held by syz-executor.2/3921:
3 locks held by syz-executor.4/3924:

=============================================

NMI backtrace for cpu 1
CPU: 1 PID: 28 Comm: khungtaskd Not tainted 6.1.46-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/26/2023
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:88 [inline]
dump_stack_lvl+0x1e3/0x2cb lib/dump_stack.c:106
nmi_cpu_backtrace+0x4e1/0x560 lib/nmi_backtrace.c:111
nmi_trigger_cpumask_backtrace+0x1b0/0x3f0 lib/nmi_backtrace.c:62
trigger_all_cpu_backtrace include/linux/nmi.h:148 [inline]
check_hung_uninterruptible_tasks kernel/hung_task.c:220 [inline]
watchdog+0xf18/0xf60 kernel/hung_task.c:377
kthread+0x26e/0x300 kernel/kthread.c:376
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:306
</TASK>
Sending NMI from CPU 1 to CPUs 0:
NMI backtrace for cpu 0
CPU: 0 PID: 4301 Comm: kworker/u4:7 Not tainted 6.1.46-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/26/2023
Workqueue: bat_events batadv_nc_worker
RIP: 0010:__sanitizer_cov_trace_pc+0x58/0x60 kernel/kcov.c:225
Code: f8 15 00 00 83 fa 02 75 21 48 8b 91 00 16 00 00 48 8b 32 48 8d 7e 01 8b 89 fc 15 00 00 48 39 cf 73 08 48 89 3a 48 89 44 f2 08 <c3> 0f 1f 80 00 00 00 00 4c 8b 04 24 65 48 8b 15 d4 70 78 7e 65 8b
RSP: 0018:ffffc900145c7be8 EFLAGS: 00000293
RAX: ffffffff8a56de3a RBX: ffff88807b585558 RCX: ffff888015385940
RDX: 0000000000000000 RSI: ffffffff8aebf3a0 RDI: ffffffff8b3ceae0
RBP: 0000000000000001 R08: dffffc0000000000 R09: fffffbfff1ce6fce
R10: 0000000000000000 R11: dffffc0000000001 R12: 00000000000002ab
R13: dffffc0000000000 R14: ffff888078364c80 R15: ffff88805671a880
FS: 0000000000000000(0000) GS:ffff8880b9800000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f17ee378038 CR3: 000000000ce8e000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<NMI>
</NMI>
<TASK>
rcu_lock_acquire+0xa/0x30 include/linux/rcupdate.h:306
rcu_read_lock include/linux/rcupdate.h:747 [inline]
batadv_nc_purge_orig_hash net/batman-adv/network-coding.c:408 [inline]
batadv_nc_worker+0xc1/0x5b0 net/batman-adv/network-coding.c:719
process_one_work+0x8aa/0x11f0 kernel/workqueue.c:2292
worker_thread+0xa5f/0x1210 kernel/workqueue.c:2439
kthread+0x26e/0x300 kernel/kthread.c:376
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:306
</TASK>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the bug is already fixed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite bug's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the bug is a duplicate of another bug, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Nov 26, 2023, 1:37:17 AM11/26/23
to syzkaller...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages