INFO: rcu detected stall in __perf_sw_event (2)

5 views
Skip to first unread message

syzbot

unread,
Jan 20, 2020, 4:59:09 AM1/20/20
to syzkaller...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: dc4ba5be Linux 4.19.97
git tree: linux-4.19.y
console output: https://syzkaller.appspot.com/x/log.txt?x=15c42cc9e00000
kernel config: https://syzkaller.appspot.com/x/.config?x=cc17a984a7e9c2f3
dashboard link: https://syzkaller.appspot.com/bug?extid=f943e6800c765f72b1f5
compiler: gcc (GCC) 9.0.0 20181231 (experimental)

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+f943e6...@syzkaller.appspotmail.com

NOHZ: local_softirq_pending 08
NOHZ: local_softirq_pending 08
rcu: INFO: rcu_preempt self-detected stall on CPU
rcu: 0-....: (10499 ticks this GP) idle=32e/1/0x4000000000000002 softirq=53585/53585 fqs=5111
rcu: (t=10500 jiffies g=64921 q=3826)
NMI backtrace for cpu 0
CPU: 0 PID: 1854 Comm: syz-executor.3 Not tainted 4.19.97-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
<IRQ>
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x197/0x210 lib/dump_stack.c:118
nmi_cpu_backtrace.cold+0x63/0xa4 lib/nmi_backtrace.c:101
nmi_trigger_cpumask_backtrace+0x1b0/0x1f8 lib/nmi_backtrace.c:62
arch_trigger_cpumask_backtrace+0x14/0x20 arch/x86/kernel/apic/hw_nmi.c:38
trigger_single_cpu_backtrace include/linux/nmi.h:164 [inline]
rcu_dump_cpu_stacks+0x189/0x1d5 kernel/rcu/tree.c:1340
print_cpu_stall kernel/rcu/tree.c:1478 [inline]
check_cpu_stall kernel/rcu/tree.c:1550 [inline]
__rcu_pending kernel/rcu/tree.c:3293 [inline]
rcu_pending kernel/rcu/tree.c:3336 [inline]
rcu_check_callbacks.cold+0x5e3/0xd90 kernel/rcu/tree.c:2682
update_process_times+0x32/0x80 kernel/time/timer.c:1638
tick_sched_handle+0xa2/0x190 kernel/time/tick-sched.c:164
tick_sched_timer+0x47/0x130 kernel/time/tick-sched.c:1274
__run_hrtimer kernel/time/hrtimer.c:1401 [inline]
__hrtimer_run_queues+0x33b/0xdc0 kernel/time/hrtimer.c:1463
hrtimer_interrupt+0x314/0x770 kernel/time/hrtimer.c:1521
local_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1067 [inline]
smp_apic_timer_interrupt+0x111/0x550 arch/x86/kernel/apic/apic.c:1092
apic_timer_interrupt+0xf/0x20 arch/x86/entry/entry_64.S:893
</IRQ>
RIP: 0010:rdtsc arch/x86/include/asm/msr.h:205 [inline]
RIP: 0010:rdtsc_ordered arch/x86/include/asm/msr.h:232 [inline]
RIP: 0010:pvclock_clocksource_read+0xc5/0x4d0 arch/x86/kernel/pvclock.c:87
Code: a8 4c 89 c0 4c 8d 53 10 4d 89 ce 48 c1 e8 03 4c 8d 7b 1d 49 c1 ee 03 4c 01 e0 4d 01 e6 48 89 45 b8 83 e1 fe 89 4d c8 0f ae e8 <0f> 31 48 c1 e2 20 48 8b 7d b0 4c 89 ce 48 09 d0 41 0f b6 16 83 e6
RSP: 0018:ffff88805e076ec8 EFLAGS: 00000202 ORIG_RAX: ffffffffffffff13
RAX: fffffbfff1418c03 RBX: ffffffff8a0c6000 RCX: 0000000000000008
RDX: 0000000000000000 RSI: ffffffff817ebd6f RDI: ffffffff8a0c6000
RBP: ffff88805e076f50 R08: ffffffff8a0c601c R09: ffffffff8a0c6008
R10: ffffffff8a0c6010 R11: ffff88808dc25817 R12: dffffc0000000000
R13: ffffffff8a0c6003 R14: fffffbfff1418c01 R15: ffffffff8a0c601d
kvm_clock_read+0x18/0x30 arch/x86/kernel/kvmclock.c:103
kvm_sched_clock_read+0x9/0x20 arch/x86/kernel/kvmclock.c:115
paravirt_sched_clock arch/x86/include/asm/paravirt.h:175 [inline]
sched_clock+0x2e/0x50 arch/x86/kernel/tsc.c:245
sched_clock_cpu+0x1b/0x1b0 kernel/sched/clock.c:370
local_clock include/linux/sched/clock.h:84 [inline]
cpu_clock_event_update+0x1b/0x50 kernel/events/core.c:9269
cpu_clock_event_read+0x16/0x20 kernel/events/core.c:9302
perf_output_read_group kernel/events/core.c:6172 [inline]
perf_output_read+0xf8e/0x1390 kernel/events/core.c:6211
perf_output_sample+0x13b6/0x1a90 kernel/events/core.c:6253
__perf_event_output kernel/events/core.c:6575 [inline]
perf_event_output_forward+0x150/0x290 kernel/events/core.c:6588
__perf_event_overflow+0x141/0x370 kernel/events/core.c:7834
perf_swevent_overflow+0xaa/0x140 kernel/events/core.c:7910
perf_swevent_event+0x1f7/0x2f0 kernel/events/core.c:7943
do_perf_sw_event kernel/events/core.c:8051 [inline]
___perf_sw_event+0x31c/0x570 kernel/events/core.c:8082
__perf_sw_event+0x51/0xa0 kernel/events/core.c:8094
perf_sw_event include/linux/perf_event.h:1064 [inline]
__do_page_fault+0x7a6/0xe90 arch/x86/mm/fault.c:1431
do_page_fault+0x71/0x57d arch/x86/mm/fault.c:1465
page_fault+0x1e/0x30 arch/x86/entry/entry_64.S:1204
RIP: 0010:copy_user_enhanced_fast_string+0xe/0x20 arch/x86/lib/copy_user_64.S:181
Code: 89 d1 c1 e9 03 83 e2 07 f3 48 a5 89 d1 f3 a4 31 c0 0f 1f 00 c3 0f 1f 80 00 00 00 00 0f 1f 00 83 fa 40 0f 82 70 ff ff ff 89 d1 <f3> a4 31 c0 0f 1f 00 c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 83
RSP: 0018:ffff88805e077a08 EFLAGS: 00010206
RAX: ffffed1012feee9c RBX: 00000000000074e0 RCX: 0000000000000fcb
RDX: 00000000000074e0 RSI: 0000000020fdc000 RDI: ffff888097f76515
RBP: ffff88805e077a40 R08: ffffed1012feee9c R09: 0000000000000004
R10: ffffed1012feee9b R11: ffff888097f774df R12: 0000000020fd5aeb
R13: ffff888097f70000 R14: 0000000020fdcfcb R15: 00007ffffffff000
_copy_from_iter_full+0x1f2/0x800 lib/iov_iter.c:724
copy_from_iter_full include/linux/uio.h:124 [inline]
skb_do_copy_data_nocache include/net/sock.h:1965 [inline]
skb_copy_to_page_nocache include/net/sock.h:1991 [inline]
tcp_sendmsg_locked+0x1364/0x3290 net/ipv4/tcp.c:1355
tcp_sendmsg+0x30/0x50 net/ipv4/tcp.c:1454
inet_sendmsg+0x141/0x5d0 net/ipv4/af_inet.c:798
sock_sendmsg_nosec net/socket.c:622 [inline]
sock_sendmsg+0xd7/0x130 net/socket.c:632
__sys_sendto+0x262/0x380 net/socket.c:1787
__do_sys_sendto net/socket.c:1799 [inline]
__se_sys_sendto net/socket.c:1795 [inline]
__x64_sys_sendto+0xe1/0x1a0 net/socket.c:1795
do_syscall_64+0xfd/0x620 arch/x86/entry/common.c:293
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x45b349
Code: ad b6 fb ff c3 66 2e 0f 1f 84 00 00 00 00 00 66 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 0f 83 7b b6 fb ff c3 66 2e 0f 1f 84 00 00 00 00
RSP: 002b:00007fe00d7dbc78 EFLAGS: 00000246 ORIG_RAX: 000000000000002c
RAX: ffffffffffffffda RBX: 00007fe00d7dc6d4 RCX: 000000000045b349
RDX: ffffffffffffffef RSI: 0000000020d7cfcb RDI: 0000000000000006
RBP: 000000000075bf20 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 00000000ffffffff
R13: 00000000000009a8 R14: 00000000004cb1dc R15: 000000000075bf2c


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Jan 20, 2020, 10:04:44 AM1/20/20
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: dc4ba5be Linux 4.19.97
git tree: linux-4.19.y
console output: https://syzkaller.appspot.com/x/log.txt?x=158c71d1e00000
kernel config: https://syzkaller.appspot.com/x/.config?x=cc17a984a7e9c2f3
dashboard link: https://syzkaller.appspot.com/bug?extid=f943e6800c765f72b1f5
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=179af4c9e00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=120dc135e00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+f943e6...@syzkaller.appspotmail.com

rcu: INFO: rcu_preempt self-detected stall on CPU
rcu: 1-....: (1 GPs behind) idle=652/1/0x4000000000000002 softirq=29557/29558 fqs=4719
rcu: (t=10500 jiffies g=14741 q=23123)
NMI backtrace for cpu 1
CPU: 1 PID: 9630 Comm: syz-executor649 Not tainted 4.19.97-syzkaller #0
RIP: 0010:perf_output_read_group kernel/events/core.c:6172 [inline]
RIP: 0010:perf_output_read+0xf65/0x1390 kernel/events/core.c:6211
Code: ff 0f 85 fb fc ff ff e9 09 f7 ff ff e8 34 29 eb ff 49 8d be 98 00 00 00 48 89 f8 48 c1 e8 03 42 80 3c 28 00 0f 85 67 03 00 00 <49> 8b 9e 98 00 00 00 48 8d bb a0 00 00 00 48 89 f8 48 c1 e8 03 42
RSP: 0018:ffff8880a7f97020 EFLAGS: 00000246 ORIG_RAX: ffffffffffffff13
RAX: 1ffff11012f12423 RBX: 0000000000000001 RCX: ffffffff817fe9c2
RDX: 0000000000000000 RSI: ffffffff817fec8c RDI: ffff888097892118
RBP: ffff8880a7f97208 R08: ffff8880987f4500 R09: ffffed101152eadf
R10: ffffed101152eade R11: ffff88808a9756f7 R12: 0000000000000010
R13: dffffc0000000000 R14: ffff888097892080 R15: ffff8880a7f97388
perf_output_sample+0x13b6/0x1a90 kernel/events/core.c:6253
__perf_event_output kernel/events/core.c:6575 [inline]
perf_event_output_forward+0x150/0x290 kernel/events/core.c:6588
__perf_event_overflow+0x141/0x370 kernel/events/core.c:7834
perf_swevent_overflow+0xaa/0x140 kernel/events/core.c:7910
perf_swevent_event+0x1f7/0x2f0 kernel/events/core.c:7943
do_perf_sw_event kernel/events/core.c:8051 [inline]
___perf_sw_event+0x31c/0x570 kernel/events/core.c:8082
__perf_sw_event+0x51/0xa0 kernel/events/core.c:8094
perf_sw_event include/linux/perf_event.h:1064 [inline]
__do_page_fault+0x7a6/0xe90 arch/x86/mm/fault.c:1431
do_page_fault+0x71/0x57d arch/x86/mm/fault.c:1465
page_fault+0x1e/0x30 arch/x86/entry/entry_64.S:1204
RIP: 0010:copy_user_enhanced_fast_string+0xe/0x20 arch/x86/lib/copy_user_64.S:181
Code: 89 d1 c1 e9 03 83 e2 07 f3 48 a5 89 d1 f3 a4 31 c0 0f 1f 00 c3 0f 1f 80 00 00 00 00 0f 1f 00 83 fa 40 0f 82 70 ff ff ff 89 d1 <f3> a4 31 c0 0f 1f 00 c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 83
RSP: 0018:ffff8880a7f97a08 EFLAGS: 00010206
RAX: ffffed1012a37e9c RBX: 00000000000074e0 RCX: 0000000000001fcb
RDX: 00000000000074e0 RSI: 0000000020e23000 RDI: ffff8880951bd515
RBP: ffff8880a7f97a40 R08: ffffed1012a37e9c R09: 0000000000000004
R10: ffffed1012a37e9b R11: ffff8880951bf4df R12: 0000000020e1daeb
R13: ffff8880951b8000 R14: 0000000020e24fcb R15: 00007ffffffff000
_copy_from_iter_full+0x1f2/0x800 lib/iov_iter.c:724
copy_from_iter_full include/linux/uio.h:124 [inline]
skb_do_copy_data_nocache include/net/sock.h:1965 [inline]
skb_copy_to_page_nocache include/net/sock.h:1991 [inline]
tcp_sendmsg_locked+0x1364/0x3290 net/ipv4/tcp.c:1355
tcp_sendmsg+0x30/0x50 net/ipv4/tcp.c:1454
inet_sendmsg+0x141/0x5d0 net/ipv4/af_inet.c:798
sock_sendmsg_nosec net/socket.c:622 [inline]
sock_sendmsg+0xd7/0x130 net/socket.c:632
__sys_sendto+0x262/0x380 net/socket.c:1787
__do_sys_sendto net/socket.c:1799 [inline]
__se_sys_sendto net/socket.c:1795 [inline]
__x64_sys_sendto+0xe1/0x1a0 net/socket.c:1795
do_syscall_64+0xfd/0x620 arch/x86/entry/common.c:293
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x448799
Code: e8 8c e7 ff ff 48 83 c4 18 c3 0f 1f 80 00 00 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 0f 83 fb 07 fc ff c3 66 2e 0f 1f 84 00 00 00 00
RSP: 002b:00007f6714a21da8 EFLAGS: 00000246 ORIG_RAX: 000000000000002c
RAX: ffffffffffffffda RBX: 00000000006ddc48 RCX: 0000000000448799
RDX: ffffffffffffffef RSI: 0000000020d7cfcb RDI: 0000000000000006
RBP: 00000000006ddc40 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 00000000006ddc4c
R13: 00007fffb675867f R14: 00007f6714a229c0 R15: 00000000006ddc4c

Reply all
Reply to author
Forward
0 new messages