Hello,
syzbot found the following crash on:
HEAD commit: 245a4300 Merge branch 'rcu/kcsan' into tip/locking/kcsan
git tree:
https://github.com/google/ktsan.git kcsan
console output:
https://syzkaller.appspot.com/x/log.txt?x=12f25799e00000
kernel config:
https://syzkaller.appspot.com/x/.config?x=a38292766f8efdaa
dashboard link:
https://syzkaller.appspot.com/bug?extid=acfbdf8f7cb39210723d
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
CC: [
ak...@linux-foundation.org cgr...@vger.kernel.org
han...@cmpxchg.org linux-...@vger.kernel.org linu...@kvack.org
mho...@kernel.org vdavyd...@gmail.com el...@google.com]
Unfortunately, I don't have any reproducer for this crash yet.
IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by:
syzbot+acfbdf...@syzkaller.appspotmail.com
==================================================================
BUG: KCSAN: data-race in lruvec_lru_size / mem_cgroup_update_lru_size
write to 0xffff8881004a0608 of 8 bytes by task 12677 on cpu 0:
mem_cgroup_update_lru_size+0x79/0x110 mm/memcontrol.c:1277
update_lru_size include/linux/mm_inline.h:43 [inline]
move_pages_to_lru+0x36a/0xa40 mm/vmscan.c:1868
shrink_inactive_list+0x4c7/0x920 mm/vmscan.c:1971
shrink_list mm/vmscan.c:2178 [inline]
shrink_lruvec+0x4c8/0xd20 mm/vmscan.c:2496
shrink_node_memcgs mm/vmscan.c:2685 [inline]
shrink_node+0x2fe/0xfe0 mm/vmscan.c:2791
shrink_zones mm/vmscan.c:2996 [inline]
do_try_to_free_pages+0x245/0xb60 mm/vmscan.c:3049
try_to_free_mem_cgroup_pages+0x205/0x4d0 mm/vmscan.c:3371
reclaim_high.constprop.0+0xf7/0x140 mm/memcontrol.c:2232
mem_cgroup_handle_over_high+0x96/0x180 mm/memcontrol.c:2313
tracehook_notify_resume include/linux/tracehook.h:197 [inline]
exit_to_usermode_loop+0x20c/0x2c0 arch/x86/entry/common.c:164
prepare_exit_to_usermode arch/x86/entry/common.c:195 [inline]
syscall_return_slowpath+0x231/0x250 arch/x86/entry/common.c:278
ret_from_fork+0x15/0x30 arch/x86/entry/entry_64.S:344
read to 0xffff8881004a0608 of 8 bytes by task 7901 on cpu 1:
mem_cgroup_get_zone_lru_size include/linux/memcontrol.h:536 [inline]
lruvec_lru_size+0xe6/0x1a0 mm/vmscan.c:340
get_scan_count mm/vmscan.c:2363 [inline]
shrink_lruvec+0x170/0xd20 mm/vmscan.c:2466
shrink_node_memcgs mm/vmscan.c:2685 [inline]
shrink_node+0x2fe/0xfe0 mm/vmscan.c:2791
shrink_zones mm/vmscan.c:2996 [inline]
do_try_to_free_pages+0x245/0xb60 mm/vmscan.c:3049
try_to_free_mem_cgroup_pages+0x205/0x4d0 mm/vmscan.c:3371
reclaim_high.constprop.0+0xf7/0x140 mm/memcontrol.c:2232
mem_cgroup_handle_over_high+0x96/0x180 mm/memcontrol.c:2313
tracehook_notify_resume include/linux/tracehook.h:197 [inline]
exit_to_usermode_loop+0x20c/0x2c0 arch/x86/entry/common.c:164
prepare_exit_to_usermode arch/x86/entry/common.c:195 [inline]
syscall_return_slowpath arch/x86/entry/common.c:278 [inline]
do_syscall_64+0x384/0x3a0 arch/x86/entry/common.c:304
entry_SYSCALL_64_after_hwframe+0x44/0xa9
Reported by Kernel Concurrency Sanitizer on:
CPU: 1 PID: 7901 Comm: syz-executor.0 Not tainted 5.5.0-rc1-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
==================================================================
---
This bug is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.