BUG: soft lockup in d_walk

24 views
Skip to first unread message

syzbot

unread,
Apr 26, 2018, 9:30:03 PM4/26/18
to syzkaller-upst...@googlegroups.com
Hello,

syzbot hit the following crash on bpf-next commit
9b984a20ca84337af81cdab92d1e8ae37007894a (Thu Apr 26 08:18:01 2018 +0000)
tools, bpftool: Display license GPL compatible in prog show/list
syzbot dashboard link:
https://syzkaller.appspot.com/bug?extid=a5a7e1ac68e34c62099d

Unfortunately, I don't have any reproducer for this crash yet.
Raw console output:
https://syzkaller.appspot.com/x/log.txt?id=6276527893250048
Kernel config:
https://syzkaller.appspot.com/x/.config?id=-2918904850634584293
compiler: gcc (GCC) 8.0.1 20180413 (experimental)
CC: [linux-...@vger.kernel.org linux-...@vger.kernel.org
vi...@zeniv.linux.org.uk]

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+a5a7e1...@syzkaller.appspotmail.com
It will help syzbot understand when the bug is fixed. See footer for
details.
If you forward the report, please keep this part and the footer.

random: crng init done
watchdog: BUG: soft lockup - CPU#1 stuck for 134s! [syz-executor7:4596]
Modules linked in:
irq event stamp: 63607920
hardirqs last enabled at (63607919): [<ffffffff81c7075f>]
seqcount_lockdep_reader_access include/linux/seqlock.h:83 [inline]
hardirqs last enabled at (63607919): [<ffffffff81c7075f>]
read_seqcount_begin include/linux/seqlock.h:164 [inline]
hardirqs last enabled at (63607919): [<ffffffff81c7075f>] read_seqbegin
include/linux/seqlock.h:433 [inline]
hardirqs last enabled at (63607919): [<ffffffff81c7075f>]
read_seqbegin_or_lock include/linux/seqlock.h:529 [inline]
hardirqs last enabled at (63607919): [<ffffffff81c7075f>]
d_walk+0x80f/0xc80 fs/dcache.c:1248
hardirqs last disabled at (63607920): [<ffffffff87800905>]
interrupt_entry+0xb5/0xf0 arch/x86/entry/entry_64.S:625
softirqs last enabled at (21927444): [<ffffffff87a00778>]
__do_softirq+0x778/0xaf5 kernel/softirq.c:311
softirqs last disabled at (21927349): [<ffffffff81475041>] invoke_softirq
kernel/softirq.c:365 [inline]
softirqs last disabled at (21927349): [<ffffffff81475041>]
irq_exit+0x1d1/0x200 kernel/softirq.c:405
CPU: 1 PID: 4596 Comm: syz-executor7 Not tainted 4.17.0-rc1+ #13
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
RIP: 0010:arch_local_irq_restore arch/x86/include/asm/paravirt.h:783
[inline]
RIP: 0010:lock_acquire+0x257/0x520 kernel/locking/lockdep.c:3923
RSP: 0018:ffff88019c4b78d8 EFLAGS: 00000286 ORIG_RAX: ffffffffffffff13
RAX: dffffc0000000000 RBX: 1ffff10033896f20 RCX: 0000000000000000
RDX: 1ffffffff11a312d RSI: ffff88019c4ae978 RDI: 0000000000000286
RBP: ffff88019c4b79c8 R08: 00000000000040b4 R09: 0000000000000004
R10: ffff88019c4aea18 R11: ffff88019c4ae140 R12: ffff88019c4ae140
R13: 0000000000000000 R14: 0000000000000001 R15: 0000000000000000
FS: 00000000018dd940(0000) GS:ffff8801daf00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007ffefd13efb8 CR3: 000000019c4b9000 CR4: 00000000001406e0
DR0: 0000000020000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000600
Call Trace:
_raw_spin_lock_nested+0x28/0x40 kernel/locking/spinlock.c:354
d_walk+0x3ad/0xc80 fs/dcache.c:1274
shrink_dcache_parent+0x179/0x230 fs/dcache.c:1486
vfs_rmdir+0x202/0x470 fs/namei.c:3850
do_rmdir+0x523/0x610 fs/namei.c:3911
__do_sys_rmdir fs/namei.c:3929 [inline]
__se_sys_rmdir fs/namei.c:3927 [inline]
__x64_sys_rmdir+0x36/0x40 fs/namei.c:3927
do_syscall_64+0x1b1/0x800 arch/x86/entry/common.c:287
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x4550f7
RSP: 002b:00007ffefd13f778 EFLAGS: 00000206 ORIG_RAX: 0000000000000054
RAX: ffffffffffffffda RBX: 0000000000000065 RCX: 00000000004550f7
RDX: 0000000000000000 RSI: 00007ffefd141520 RDI: 00007ffefd141520
RBP: 00007ffefd141520 R08: 0000000000000000 R09: 0000000000000001
R10: 000000000000000a R11: 0000000000000206 R12: 00000000018de940
R13: 0000000000000000 R14: 000000000000011d R15: 0000000000018a40
Code: 00 00 00 48 89 fa 48 c1 ea 03 80 3c 02 00 0f 85 5e 02 00 00 48 83 3d
e0 7c 74 07 00 0f 84 c8 01 00 00 48 8b bd 20 ff ff ff 57 9d <0f> 1f 44 00
00 48 b8 00 00 00 00 00 fc ff df 48 01 c3 48 c7 03


---
This bug is generated by a dumb bot. It may contain errors.
See https://goo.gl/tpsmEJ for details.
Direct all questions to syzk...@googlegroups.com.

syzbot will keep track of this bug report.
If you forgot to add the Reported-by tag, once the fix for this bug is
merged
into any tree, please reply to this email with:
#syz fix: exact-commit-title
To mark this as a duplicate of another syzbot report, please reply with:
#syz dup: exact-subject-of-another-report
If it's a one-off invalid bug report, please reply with:
#syz invalid
Note: if the crash happens again, it will cause creation of a new bug
report.
Note: all commands must start from beginning of the line in the email body.
To upstream this report, please reply with:
#syz upstream

Dmitry Vyukov

unread,
Apr 27, 2018, 1:23:21 AM4/27/18
to syzbot, 'Dmitry Vyukov' via syzkaller-upstream-moderation
#syz fix: restore cond_resched() in shrink_dcache_parent()
> --
> You received this message because you are subscribed to the Google Groups
> "syzkaller-upstream-moderation" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to syzkaller-upstream-m...@googlegroups.com.
> To view this discussion on the web visit
> https://groups.google.com/d/msgid/syzkaller-upstream-moderation/0000000000006eb4ac056aca7181%40google.com.
> For more options, visit https://groups.google.com/d/optout.

syzbot

unread,
May 18, 2018, 10:28:30 PM5/18/18
to dvy...@google.com, syzkaller-upst...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 82f9e2d5dba6 Merge branch 'bpf-af-xdp-cleanups'
git tree: bpf-next
console output: https://syzkaller.appspot.com/x/log.txt?x=16e0820f800000
kernel config: https://syzkaller.appspot.com/x/.config?x=b632d8e2c2ab2c1
dashboard link: https://syzkaller.appspot.com/bug?extid=a5a7e1ac68e34c62099d
compiler: gcc (GCC) 8.0.1 20180413 (experimental)
syzkaller repro:https://syzkaller.appspot.com/x/repro.syz?x=1556927b800000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1697a20f800000
CC: [linux-...@vger.kernel.org linux-...@vger.kernel.org
vi...@zeniv.linux.org.uk]

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+a5a7e1...@syzkaller.appspotmail.com

watchdog: BUG: soft lockup - CPU#0 stuck for 22s! [syz-executor223:4527]
Modules linked in:
irq event stamp: 12319252
hardirqs last enabled at (12319251): [<ffffffff81c6992f>]
seqcount_lockdep_reader_access include/linux/seqlock.h:83 [inline]
hardirqs last enabled at (12319251): [<ffffffff81c6992f>]
read_seqcount_begin include/linux/seqlock.h:164 [inline]
hardirqs last enabled at (12319251): [<ffffffff81c6992f>] read_seqbegin
include/linux/seqlock.h:433 [inline]
hardirqs last enabled at (12319251): [<ffffffff81c6992f>]
read_seqbegin_or_lock include/linux/seqlock.h:529 [inline]
hardirqs last enabled at (12319251): [<ffffffff81c6992f>]
d_walk+0x80f/0xc80 fs/dcache.c:1248
hardirqs last disabled at (12319252): [<ffffffff87800905>]
interrupt_entry+0xb5/0xf0 arch/x86/entry/entry_64.S:625
softirqs last enabled at (6473308): [<ffffffff87a00778>]
__do_softirq+0x778/0xaf5 kernel/softirq.c:311
softirqs last disabled at (6473243): [<ffffffff81475241>] invoke_softirq
kernel/softirq.c:365 [inline]
softirqs last disabled at (6473243): [<ffffffff81475241>]
irq_exit+0x1d1/0x200 kernel/softirq.c:405
CPU: 0 PID: 4527 Comm: syz-executor223 Not tainted 4.17.0-rc4+ #14
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
RIP: 0010:debug_spin_lock_before kernel/locking/spinlock_debug.c:84 [inline]
RIP: 0010:do_raw_spin_lock+0x62/0x200 kernel/locking/spinlock_debug.c:112
RSP: 0018:ffff8801ad2479a0 EFLAGS: 00000a06 ORIG_RAX: ffffffffffffff13
RAX: dffffc0000000000 RBX: ffff8801a816e640 RCX: 0000000000000000
RDX: 1ffff1003502dcca RSI: ffff8801ac096b38 RDI: ffff8801a816e644
RBP: ffff8801ad2479c8 R08: 0000000000004394 R09: 0000000000000004
R10: ffff8801ac096bd8 R11: ffff8801ac096300 R12: ffff8801a816e5c0
R13: ffff8801a816e650 R14: ffff8801a816e640 R15: ffff8801ad247b50
FS: 00000000023ab880(0000) GS:ffff8801dae00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00000000004a39d0 CR3: 00000001ac6fb000 CR4: 00000000001406f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
_raw_spin_lock_nested+0x30/0x40 kernel/locking/spinlock.c:355
d_walk+0x3ad/0xc80 fs/dcache.c:1274
shrink_dcache_parent+0x179/0x230 fs/dcache.c:1486
vfs_rmdir+0x202/0x470 fs/namei.c:3850
do_rmdir+0x523/0x610 fs/namei.c:3911
__do_sys_rmdir fs/namei.c:3929 [inline]
__se_sys_rmdir fs/namei.c:3927 [inline]
__x64_sys_rmdir+0x36/0x40 fs/namei.c:3927
do_syscall_64+0x1b1/0x800 arch/x86/entry/common.c:287
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x441aa7
RSP: 002b:00007ffed4dd3ce8 EFLAGS: 00000207 ORIG_RAX: 0000000000000054
RAX: ffffffffffffffda RBX: 0000000000000065 RCX: 0000000000441aa7
RDX: 0000000000000000 RSI: 00000000006cd858 RDI: 00007ffed4dd4dd0
RBP: 00007ffed4dd4dd0 R08: 0000000000000000 R09: 0000000000000001
R10: 000000000000000a R11: 0000000000000207 R12: 00000000023ac8a0
R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000
Code: 08 84 d2 0f 85 7b 01 00 00 81 7b 04 ad 4e ad de 0f 85 f2 00 00 00 48
b8 00 00 00 00 00 fc ff df 4c 8d 6b 10 4c 89 ea 48 c1 ea 03 <80> 3c 02 00
0f 85 68 01 00 00 65 48 8b 04 25 c0 ed 01 00 48 39
Sending NMI from CPU 0 to CPUs 1:
NMI backtrace for cpu 1
CPU: 1 PID: 4524 Comm: syz-executor223 Not tainted 4.17.0-rc4+ #14
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
RIP: 0010:bytes_is_nonzero mm/kasan/kasan.c:167 [inline]
RIP: 0010:memory_is_nonzero mm/kasan/kasan.c:184 [inline]
RIP: 0010:memory_is_poisoned_n mm/kasan/kasan.c:210 [inline]
RIP: 0010:memory_is_poisoned mm/kasan/kasan.c:241 [inline]
RIP: 0010:check_memory_region_inline mm/kasan/kasan.c:257 [inline]
RIP: 0010:check_memory_region+0x117/0x1b0 mm/kasan/kasan.c:267
RSP: 0018:ffff8801ac7474e8 EFLAGS: 00000046
RAX: fffffbfff1446fec RBX: 1ffffffff1446feb RCX: ffffffff815c9ec1
RDX: 0000000000000001 RSI: 0000000000000004 RDI: ffffffff8a237f58
RBP: ffff8801ac747500 R08: fffffbfff1446fec R09: fffffbfff1446feb
R10: fffffbfff1446feb R11: ffffffff8a237f5b R12: fffffbfff1446fec
R13: 0000000000000000 R14: 0000000000000000 R15: ffff8801a81c5618
FS: 00000000023ab880(0000) GS:ffff8801daf00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00000000023bc918 CR3: 00000001d8f40000 CR4: 00000000001406e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
kasan_check_write+0x14/0x20 mm/kasan/kasan.c:278
atomic_inc include/asm-generic/atomic-instrumented.h:102 [inline]
__lock_acquire+0x291/0x5140 kernel/locking/lockdep.c:3323
lock_acquire+0x1dc/0x520 kernel/locking/lockdep.c:3920
__raw_spin_lock include/linux/spinlock_api_smp.h:142 [inline]
_raw_spin_lock+0x2a/0x40 kernel/locking/spinlock.c:144
spin_lock include/linux/spinlock.h:310 [inline]
d_walk+0x261/0xc80 fs/dcache.c:1250
shrink_dcache_parent+0x179/0x230 fs/dcache.c:1486
vfs_rmdir+0x202/0x470 fs/namei.c:3850
do_rmdir+0x523/0x610 fs/namei.c:3911
__do_sys_rmdir fs/namei.c:3929 [inline]
__se_sys_rmdir fs/namei.c:3927 [inline]
__x64_sys_rmdir+0x36/0x40 fs/namei.c:3927
do_syscall_64+0x1b1/0x800 arch/x86/entry/common.c:287
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x441aa7
RSP: 002b:00007ffed4dd3ce8 EFLAGS: 00000207 ORIG_RAX: 0000000000000054
RAX: ffffffffffffffda RBX: 0000000000000065 RCX: 0000000000441aa7
RDX: 0000000000000000 RSI: 00000000006cd858 RDI: 00007ffed4dd4dd0
RBP: 00007ffed4dd4dd0 R08: 0000000000000000 R09: 0000000000000001
R10: 000000000000000a R11: 0000000000000207 R12: 00000000023ac8a0
R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000
Code: 0d 00 4d 85 c0 75 3e 4d 89 e0 49 29 c0 e9 6c ff ff ff 4d 85 c0 74 ba
48 b8 01 00 00 00 00 fc ff df 4d 01 c8 48 01 d8 41 80 39 00 <74> 08 e9 8c
00 00 00 48 89 d8 4c 39 c0 74 97 80 38 00 48 8d 58

Dmitry Vyukov

unread,
May 19, 2018, 2:38:30 AM5/19/18
to syzbot, 'Dmitry Vyukov' via syzkaller-upstream-moderation
On Fri, Apr 27, 2018 at 7:23 AM, Dmitry Vyukov <dvy...@google.com> wrote:
> #syz fix: restore cond_resched() in shrink_dcache_parent()


The patch is now called:

#syz fix: fs/dcache.c: re-add cond_resched() in shrink_dcache_parent()

http://lkml.iu.edu/hypermail/linux/kernel/1804.1/06252.html

Dmitry Vyukov

unread,
Sep 4, 2018, 5:34:16 AM9/4/18
to syzbot, 'Dmitry Vyukov' via syzkaller-upstream-moderation
#syz fix: restore cond_resched() in shrink_dcache_parent()

Reply all
Reply to author
Forward
0 new messages