INFO: task hung in copy_process

6 views
Skip to first unread message

syzbot

unread,
May 1, 2020, 12:01:17 AM5/1/20
to syzkaller...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 76567537 Linux 4.19.119
git tree: linux-4.19.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1543f540100000
kernel config: https://syzkaller.appspot.com/x/.config?x=dd6adfe2dd5d771
dashboard link: https://syzkaller.appspot.com/bug?extid=7920390c68c1a040880e
compiler: gcc (GCC) 9.0.0 20181231 (experimental)

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+792039...@syzkaller.appspotmail.com

INFO: task syz-executor.1:6572 blocked for more than 140 seconds.
Not tainted 4.19.119-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.1 D23952 6572 6497 0x00000000
Call Trace:
schedule+0x8d/0x1b0 kernel/sched/core.c:3559
__rwsem_down_write_failed_common kernel/locking/rwsem-xadd.c:589 [inline]
rwsem_down_write_failed+0x774/0xc30 kernel/locking/rwsem-xadd.c:618
call_rwsem_down_write_failed+0x13/0x20 arch/x86/lib/rwsem.S:117
__down_write arch/x86/include/asm/rwsem.h:142 [inline]
down_write+0x4f/0x90 kernel/locking/rwsem.c:72
i_mmap_lock_write include/linux/fs.h:491 [inline]
dup_mmap kernel/fork.c:516 [inline]
dup_mm kernel/fork.c:1288 [inline]
copy_mm kernel/fork.c:1344 [inline]
copy_process.part.0+0x30bb/0x7a50 kernel/fork.c:1897
copy_process kernel/fork.c:1694 [inline]
_do_fork+0x22f/0xf40 kernel/fork.c:2207
do_syscall_64+0xf9/0x620 arch/x86/entry/common.c:293
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x45ae5a
Code: f7 d8 64 89 04 25 d4 02 00 00 64 4c 8b 0c 25 10 00 00 00 31 d2 4d 8d 91 d0 02 00 00 31 f6 bf 11 00 20 01 b8 38 00 00 00 0f 05 <48> 3d 00 f0 ff ff 0f 87 f5 00 00 00 85 c0 41 89 c5 0f 85 fc 00 00
RSP: 002b:00007ffc84bceea0 EFLAGS: 00000246 ORIG_RAX: 0000000000000038
RAX: ffffffffffffffda RBX: 00007ffc84bceea0 RCX: 000000000045ae5a
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000001200011
RBP: 00007ffc84bceee0 R08: 0000000000000001 R09: 0000000001088940
R10: 0000000001088c10 R11: 0000000000000246 R12: 0000000000000001
R13: 0000000000000000 R14: 0000000000000000 R15: 00007ffc84bcef30
INFO: task syz-executor.5:6930 blocked for more than 140 seconds.
Not tainted 4.19.119-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.5 D23952 6930 6888 0x00000000
Call Trace:
schedule+0x8d/0x1b0 kernel/sched/core.c:3559
__rwsem_down_write_failed_common kernel/locking/rwsem-xadd.c:589 [inline]
rwsem_down_write_failed+0x774/0xc30 kernel/locking/rwsem-xadd.c:618
call_rwsem_down_write_failed+0x13/0x20 arch/x86/lib/rwsem.S:117
__down_write arch/x86/include/asm/rwsem.h:142 [inline]
down_write+0x4f/0x90 kernel/locking/rwsem.c:72
i_mmap_lock_write include/linux/fs.h:491 [inline]
dup_mmap kernel/fork.c:516 [inline]
dup_mm kernel/fork.c:1288 [inline]
copy_mm kernel/fork.c:1344 [inline]
copy_process.part.0+0x30bb/0x7a50 kernel/fork.c:1897
copy_process kernel/fork.c:1694 [inline]
_do_fork+0x22f/0xf40 kernel/fork.c:2207
do_syscall_64+0xf9/0x620 arch/x86/entry/common.c:293
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x45ae5a
Code: f7 d8 64 89 04 25 d4 02 00 00 64 4c 8b 0c 25 10 00 00 00 31 d2 4d 8d 91 d0 02 00 00 31 f6 bf 11 00 20 01 b8 38 00 00 00 0f 05 <48> 3d 00 f0 ff ff 0f 87 f5 00 00 00 85 c0 41 89 c5 0f 85 fc 00 00
RSP: 002b:00007fffed547050 EFLAGS: 00000246 ORIG_RAX: 0000000000000038
RAX: ffffffffffffffda RBX: 00007fffed547050 RCX: 000000000045ae5a
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000001200011
RBP: 00007fffed547090 R08: 0000000000000001 R09: 00000000027ec940
R10: 00000000027ecc10 R11: 0000000000000246 R12: 0000000000000001
R13: 0000000000000000 R14: 0000000000000000 R15: 00007fffed5470e0
INFO: task syz-executor.4:12762 blocked for more than 140 seconds.
Not tainted 4.19.119-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.4 D29024 12762 6831 0x80000000
Call Trace:
schedule+0x8d/0x1b0 kernel/sched/core.c:3559
__rwsem_down_write_failed_common kernel/locking/rwsem-xadd.c:589 [inline]
rwsem_down_write_failed+0x774/0xc30 kernel/locking/rwsem-xadd.c:618
call_rwsem_down_write_failed+0x13/0x20 arch/x86/lib/rwsem.S:117
__down_write arch/x86/include/asm/rwsem.h:142 [inline]
down_write+0x4f/0x90 kernel/locking/rwsem.c:72
i_mmap_lock_write include/linux/fs.h:491 [inline]
unlink_file_vma+0x71/0xb0 mm/mmap.c:161
free_pgtables+0x1b3/0x2f0 mm/memory.c:641
exit_mmap+0x2c1/0x510 mm/mmap.c:3092
__mmput kernel/fork.c:1015 [inline]
mmput+0x14e/0x4a0 kernel/fork.c:1036
exit_mm kernel/exit.c:546 [inline]
do_exit+0xac8/0x2f30 kernel/exit.c:867
do_group_exit+0x125/0x350 kernel/exit.c:983
get_signal+0x3ec/0x1f90 kernel/signal.c:2588
do_signal+0x8f/0x1710 arch/x86/kernel/signal.c:821
exit_to_usermode_loop+0x22b/0x2b0 arch/x86/entry/common.c:163
prepare_exit_to_usermode arch/x86/entry/common.c:198 [inline]
syscall_return_slowpath arch/x86/entry/common.c:271 [inline]
do_syscall_64+0x538/0x620 arch/x86/entry/common.c:296
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x45c829
Code: Bad RIP value.
RSP: 002b:00007ff3de635cf8 EFLAGS: 00000246 ORIG_RAX: 00000000000000ca
RAX: fffffffffffffe00 RBX: 000000000078bfa8 RCX: 000000000045c829


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Aug 29, 2020, 12:01:17 AM8/29/20
to syzkaller...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages