WARNING: suspicious RCU usage in gfs2_lm_withdraw

4 views
Skip to first unread message

syzbot

unread,
Sep 19, 2022, 2:31:47 PM9/19/22
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 5df8b4735177 Linux 4.14.293
git tree: linux-4.14.y
console output: https://syzkaller.appspot.com/x/log.txt?x=14e2c580880000
kernel config: https://syzkaller.appspot.com/x/.config?x=cc7e9ed39471e56f
dashboard link: https://syzkaller.appspot.com/bug?extid=e4459f1351f4c246a927
compiler: gcc version 10.2.1 20210110 (Debian 10.2.1-6)

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/0909a4c9f34f/disk-5df8b473.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/413a44ed225d/vmlinux-5df8b473.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+e4459f...@syzkaller.appspotmail.com

gfs2: fsid=loop3: Trying to join cluster "lock_nolock", "loop3"
=============================
WARNING: suspicious RCU usage
mmap: syz-executor.0 (9897) uses deprecated remap_file_pages() syscall. See Documentation/vm/remap_file_pages.txt.
gfs2: fsid=loop3: Now mounting FS...
4.14.293-syzkaller #0 Not tainted
gfs2: fsid=loop3.0: fatal: invalid metadata block
bh = 2073 (magic number)
function = gfs2_meta_indirect_buffer, file = fs/gfs2/meta_io.c, line = 419
-----------------------------
net/tipc/bearer.c:177 suspicious rcu_dereference_protected() usage!

other info that might help us debug this:

gfs2: fsid=loop3.0: about to withdraw this file system

rcu_scheduler_active = 2, debug_locks = 1
gfs2: fsid=loop3.0: withdrawn
2 locks held by syz-executor.1/9891:
CPU: 1 PID: 9889 Comm: syz-executor.3 Not tainted 4.14.293-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/26/2022
Call Trace:
__dump_stack lib/dump_stack.c:17 [inline]
dump_stack+0x1b2/0x281 lib/dump_stack.c:58
gfs2_lm_withdraw.cold+0x1d8/0x251 fs/gfs2/util.c:73
gfs2_meta_check_ii+0x60/0x90 fs/gfs2/util.c:202
gfs2_metatype_check_i fs/gfs2/util.h:111 [inline]
gfs2_meta_indirect_buffer+0x2dc/0x380 fs/gfs2/meta_io.c:419
gfs2_meta_inode_buffer fs/gfs2/meta_io.h:73 [inline]
gfs2_inode_refresh+0x84/0xd40 fs/gfs2/glops.c:406
inode_go_lock+0x1d5/0x410 fs/gfs2/glops.c:436
do_promote+0x39f/0xc60 fs/gfs2/glock.c:362
finish_xmote+0x3ad/0xc30 fs/gfs2/glock.c:522
do_xmote+0x453/0x580 fs/gfs2/glock.c:590
run_queue+0x1d3/0x4d0 fs/gfs2/glock.c:655
gfs2_glock_nq+0x830/0x1120 fs/gfs2/glock.c:1114
gfs2_glock_nq_init fs/gfs2/glock.h:228 [inline]
gfs2_lookupi+0x299/0x560 fs/gfs2/inode.c:300
gfs2_lookup_simple+0x89/0xc0 fs/gfs2/inode.c:251
init_journal fs/gfs2/ops_fstype.c:671 [inline]
init_inodes+0x242/0x18d0 fs/gfs2/ops_fstype.c:802
fill_super+0x1721/0x2310 fs/gfs2/ops_fstype.c:1172
gfs2_mount+0x439/0x510 fs/gfs2/ops_fstype.c:1335
mount_fs+0x92/0x2a0 fs/super.c:1237
vfs_kern_mount.part.0+0x5b/0x470 fs/namespace.c:1046
vfs_kern_mount fs/namespace.c:1036 [inline]
do_new_mount fs/namespace.c:2572 [inline]
do_mount+0xe65/0x2a30 fs/namespace.c:2905
SYSC_mount fs/namespace.c:3121 [inline]
SyS_mount+0xa8/0x120 fs/namespace.c:3098
do_syscall_64+0x1d5/0x640 arch/x86/entry/common.c:292
entry_SYSCALL_64_after_hwframe+0x46/0xbb
RIP: 0033:0x7f4aeb98993a
RSP: 002b:00007f4aea2fcf88 EFLAGS: 00000202 ORIG_RAX: 00000000000000a5
RAX: ffffffffffffffda RBX: 0000000020000200 RCX: 00007f4aeb98993a
RDX: 0000000020000000 RSI: 0000000020000100 RDI: 00007f4aea2fcfe0
RBP: 00007f4aea2fd020 R08: 00007f4aea2fd020 R09: 0000000020000000
R10: 0000000000000000 R11: 0000000000000202 R12: 0000000020000000
R13: 0000000020000100 R14: 00007f4aea2fcfe0 R15: 0000000020047a20
#0: (cb_lock){++++}, at: [<ffffffff85e370a5>] genl_rcv+0x15/0x40 net/netlink/genetlink.c:635
#1: (genl_mutex){+.+.}, at: [<ffffffff85e37d02>] genl_lock net/netlink/genetlink.c:33 [inline]
#1: (genl_mutex){+.+.}, at: [<ffffffff85e37d02>] genl_rcv_msg+0x112/0x140 net/netlink/genetlink.c:623

stack backtrace:
CPU: 1 PID: 9891 Comm: syz-executor.1 Not tainted 4.14.293-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/26/2022
Call Trace:
__dump_stack lib/dump_stack.c:17 [inline]
dump_stack+0x1b2/0x281 lib/dump_stack.c:58
tipc_bearer_find+0x1ff/0x2f0 net/tipc/bearer.c:177
tipc_nl_compat_link_set+0x40b/0xb90 net/tipc/netlink_compat.c:807
__tipc_nl_compat_doit net/tipc/netlink_compat.c:316 [inline]
tipc_nl_compat_doit+0x192/0x5d0 net/tipc/netlink_compat.c:364
tipc_nl_compat_handle net/tipc/netlink_compat.c:1215 [inline]
tipc_nl_compat_recv+0xa0b/0xae0 net/tipc/netlink_compat.c:1297
genl_family_rcv_msg+0x572/0xb20 net/netlink/genetlink.c:600
genl_rcv_msg+0xaf/0x140 net/netlink/genetlink.c:625
netlink_rcv_skb+0x125/0x390 net/netlink/af_netlink.c:2454
genl_rcv+0x24/0x40 net/netlink/genetlink.c:636
netlink_unicast_kernel net/netlink/af_netlink.c:1296 [inline]
netlink_unicast+0x437/0x610 net/netlink/af_netlink.c:1322
netlink_sendmsg+0x648/0xbc0 net/netlink/af_netlink.c:1893
sock_sendmsg_nosec net/socket.c:646 [inline]
sock_sendmsg+0xb5/0x100 net/socket.c:656
___sys_sendmsg+0x6c8/0x800 net/socket.c:2062
__sys_sendmsg+0xa3/0x120 net/socket.c:2096
SYSC_sendmsg net/socket.c:2107 [inline]
SyS_sendmsg+0x27/0x40 net/socket.c:2103
do_syscall_64+0x1d5/0x640 arch/x86/entry/common.c:292
entry_SYSCALL_64_after_hwframe+0x46/0xbb
RIP: 0033:0x7f934dce7409
RSP: 002b:00007f934c65c168 EFLAGS: 00000246 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007f934ddf9f80 RCX: 00007f934dce7409
RDX: 0000000000000000 RSI: 0000000020000380 RDI: 0000000000000003
RBP: 00007f934dd42367 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007fff79bfb0df R14: 00007f934c65c300 R15: 0000000000022000
gfs2: fsid=loop3.0: can't lookup journal index: 0
hub 9-0:1.0: USB hub found
hub 9-0:1.0: 8 ports detected
netlink: 4 bytes leftover after parsing attributes in process `syz-executor.5'.
hub 9-0:1.0: USB hub found
hub 9-0:1.0: 8 ports detected
audit: type=1800 audit(1663612269.083:2): pid=10062 uid=0 auid=4294967295 ses=4294967295 op="collect_data" cause="failed(directio)" comm="syz-executor.5" name="bus" dev="sda1" ino=13955 res=0
hub 9-0:1.0: USB hub found
hub 9-0:1.0: 8 ports detected
audit: type=1800 audit(1663612269.613:3): pid=10107 uid=0 auid=4294967295 ses=4294967295 op="collect_data" cause="failed(directio)" comm="syz-executor.5" name="bus" dev="sda1" ino=13965 res=0
audit: type=1800 audit(1663612270.234:4): pid=10157 uid=0 auid=4294967295 ses=4294967295 op="collect_data" cause="failed(directio)" comm="syz-executor.5" name="bus" dev="sda1" ino=14023 res=0
netlink: 3740 bytes leftover after parsing attributes in process `syz-executor.1'.
audit: type=1800 audit(1663612270.754:5): pid=10171 uid=0 auid=4294967295 ses=4294967295 op="collect_data" cause="failed(directio)" comm="syz-executor.5" name="bus" dev="sda1" ino=14023 res=0
EXT4-fs (loop3): mounted filesystem without journal. Opts: ,errors=continue
overlayfs: workdir and upperdir must be separate subtrees
ISOFS: Unable to identify CD-ROM format.
sd 0:0:1:0: [sg0] tag#2653 FAILED Result: hostbyte=DID_ABORT driverbyte=DRIVER_OK
sd 0:0:1:0: [sg0] tag#2653 CDB: Service action out(16), sa=0x1e
sd 0:0:1:0: [sg0] tag#2653 CDB[00]: 9f 9e 6e b3 04 d5 f8 21 a9 be 1f 0a a0 17 a2 57
sd 0:0:1:0: [sg0] tag#2653 CDB[10]: 2a ef da 0b 61 d9 8c fc f3 d0 75 37 7b bb 83 36
sd 0:0:1:0: [sg0] tag#2653 CDB[20]: 48 27 d8 fd bc 16 30 fd 7f 79 eb 88 f4 58 9a 55
sd 0:0:1:0: [sg0] tag#2653 CDB[30]: e5 1c 3d e0 a2 b0 e6 c2 f7 3e 1c 75 05 da 6b 19
sd 0:0:1:0: [sg0] tag#2653 CDB[40]: 47 33 4b e9 5d f2 af b0 a3 83 dc 82 e6 74 31 db
sd 0:0:1:0: [sg0] tag#2653 CDB[50]: e9 3e 7a 10 a1 01 62 57 5c 9a 71 16 19 19 2d 9c
sd 0:0:1:0: [sg0] tag#2653 CDB[60]: 14 95 57 98 8b 74 ff 03 22 d9 72 a2 50 f4 14 e6
sd 0:0:1:0: [sg0] tag#2653 FAILED Result: hostbyte=DID_ABORT driverbyte=DRIVER_OK
sd 0:0:1:0: [sg0] tag#2653 CDB: Service action out(16), sa=0x1e
sd 0:0:1:0: [sg0] tag#2653 CDB[00]: 9f 9e 6e b3 04 d5 f8 21 a9 be 1f 0a a0 17 a2 57
sd 0:0:1:0: [sg0] tag#2653 CDB[10]: 2a ef da 0b 61 d9 8c fc f3 d0 75 37 7b bb 83 36
sd 0:0:1:0: [sg0] tag#2653 CDB[20]: 48 27 d8 fd bc 16 30 fd 7f 79 eb 88 f4 58 9a 55
sd 0:0:1:0: [sg0] tag#2653 CDB[30]: e5 1c 3d e0 a2 b0 e6 c2 f7 3e 1c 75 05 da 6b 19
sd 0:0:1:0: [sg0] tag#2653 CDB[40]: 47 33 4b e9 5d f2 af b0 a3 83 dc 82 e6 74 31 db
sd 0:0:1:0: [sg0] tag#2653 CDB[50]: e9 3e 7a 10 a1 01 62 57 5c 9a 71 16 19 19 2d 9c
sd 0:0:1:0: [sg0] tag#2653 CDB[60]: 14 95 57 98 8b 74 ff 03 22 d9 72 a2 50 f4 14 e6
sd 0:0:1:0: [sg0] tag#2653 FAILED Result: hostbyte=DID_ABORT driverbyte=DRIVER_OK
sd 0:0:1:0: [sg0] tag#2653 CDB: Service action out(16), sa=0x1e
sd 0:0:1:0: [sg0] tag#2653 CDB[00]: 9f 9e 6e b3 04 d5 f8 21 a9 be 1f 0a a0 17 a2 57
sd 0:0:1:0: [sg0] tag#2653 CDB[10]: 2a ef da 0b 61 d9 8c fc f3 d0 75 37 7b bb 83 36
sd 0:0:1:0: [sg0] tag#2653 CDB[20]: 48 27 d8 fd bc 16 30 fd 7f 79 eb 88 f4 58 9a 55
sd 0:0:1:0: [sg0] tag#2653 CDB[30]: e5 1c 3d e0 a2 b0 e6 c2 f7 3e 1c 75 05 da 6b 19
sd 0:0:1:0: [sg0] tag#2653 CDB[40]: 47 33 4b e9 5d f2 af b0 a3 83 dc 82 e6 74 31 db
sd 0:0:1:0: [sg0] tag#2653 CDB[50]: e9 3e 7a 10 a1 01 62 57 5c 9a 71 16 19 19 2d 9c
sd 0:0:1:0: [sg0] tag#2653 CDB[60]: 14 95 57 98 8b 74 ff 03 22 d9 72 a2 50 f4 14 e6
EXT4-fs (loop2): mounted filesystem without journal. Opts: ,errors=continue
EXT4-fs (loop3): mounted filesystem without journal. Opts: ,errors=continue
netlink: 24 bytes leftover after parsing attributes in process `syz-executor.5'.
syz-executor.3 (10265) used greatest stack depth: 25136 bytes left
sd 0:0:1:0: [sg0] tag#2637 FAILED Result: hostbyte=DID_ABORT driverbyte=DRIVER_OK
sd 0:0:1:0: [sg0] tag#2637 CDB: Service action out(16), sa=0x1e
sd 0:0:1:0: [sg0] tag#2637 CDB[00]: 9f 9e 6e b3 04 d5 f8 21 a9 be 1f 0a a0 17 a2 57
sd 0:0:1:0: [sg0] tag#2637 CDB[10]: 2a ef da 0b 61 d9 8c fc f3 d0 75 37 7b bb 83 36
sd 0:0:1:0: [sg0] tag#2637 CDB[20]: 48 27 d8 fd bc 16 30 fd 7f 79 eb 88 f4 58 9a 55
sd 0:0:1:0: [sg0] tag#2637 CDB[30]: e5 1c 3d e0 a2 b0 e6 c2 f7 3e 1c 75 05 da 6b 19
sd 0:0:1:0: [sg0] tag#2637 CDB[40]: 47 33 4b e9 5d f2 af b0 a3 83 dc 82 e6 74 31 db
sd 0:0:1:0: [sg0] tag#2637 CDB[50]: e9 3e 7a 10 a1 01 62 57 5c 9a 71 16 19 19 2d 9c
sd 0:0:1:0: [sg0] tag#2637 CDB[60]: 14 95 57 98 8b 74 ff 03 22 d9 72 a2 50 f4 14 e6
netlink: 12 bytes leftover after parsing attributes in process `syz-executor.5'.
Zero length message leads to an empty skb
F2FS-fs (loop4): Magic Mismatch, valid(0xf2f52010) - read(0x0)
F2FS-fs (loop4): Can't find valid F2FS filesystem in 2th superblock
F2FS-fs (loop4): invalid crc value
EXT4-fs (loop2): mounted filesystem without journal. Opts: ,errors=continue
EXT4-fs (loop3): mounted filesystem without journal. Opts: ,errors=continue
F2FS-fs (loop4): Try to recover 2th superblock, ret: 0
F2FS-fs (loop4): Mounted with checkpoint version = 28ccb028
F2FS-fs (loop4): Magic Mismatch, valid(0xf2f52010) - read(0x0)
F2FS-fs (loop4): Can't find valid F2FS filesystem in 2th superblock
F2FS-fs (loop4): invalid crc value
F2FS-fs (loop4): Try to recover 2th superblock, ret: 0
F2FS-fs (loop4): Mounted with checkpoint version = 28ccb028
syz-executor.3 (10332) used greatest stack depth: 25104 bytes left


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Jan 17, 2023, 1:31:34 PM1/17/23
to syzkaller...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages