INFO: task hung in start_this_handle

5 views
Skip to first unread message

syzbot

unread,
Oct 1, 2018, 2:24:05 PM10/1/18
to syzkaller-upst...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 5362700c942b net: sched: make function qdisc_free_cb() sta..
git tree: net-next
console output: https://syzkaller.appspot.com/x/log.txt?x=14e2f756400000
kernel config: https://syzkaller.appspot.com/x/.config?x=6da69433212d7e87
dashboard link: https://syzkaller.appspot.com/bug?extid=fac5fee9390ddc6e8be5
compiler: gcc (GCC) 8.0.1 20180413 (experimental)
CC: [ja...@suse.com linux...@vger.kernel.org
linux-...@vger.kernel.org ty...@mit.edu]

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+fac5fe...@syzkaller.appspotmail.com

EXT4-fs (sda1): resizing filesystem from 524032 to 4 blocks
EXT4-fs warning (device sda1): ext4_resize_fs:1930: can't shrink FS -
resize aborted
INFO: task kworker/u4:0:7 blocked for more than 140 seconds.
Not tainted 4.19.0-rc5+ #236
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
kworker/u4:0 D14376 7 2 0x80000000
Workqueue: writeback wb_workfn (flush-8:0)
Call Trace:
context_switch kernel/sched/core.c:2825 [inline]
__schedule+0x86c/0x1ed0 kernel/sched/core.c:3473
schedule+0xfe/0x460 kernel/sched/core.c:3517
start_this_handle+0x83e/0x1250 fs/jbd2/transaction.c:334
jbd2__journal_start+0x3c9/0xa90 fs/jbd2/transaction.c:439
__ext4_journal_start_sb+0x1a5/0x5f0 fs/ext4/ext4_jbd2.c:81
__ext4_journal_start fs/ext4/ext4_jbd2.h:311 [inline]
ext4_writepages+0x18ba/0x4110 fs/ext4/inode.c:2836
do_writepages+0x9a/0x1a0 mm/page-writeback.c:2340
__writeback_single_inode+0x20a/0x1620 fs/fs-writeback.c:1323
writeback_sb_inodes+0x71f/0x11d0 fs/fs-writeback.c:1587
__writeback_inodes_wb+0x1b9/0x340 fs/fs-writeback.c:1656
wb_writeback+0xa73/0xfc0 fs/fs-writeback.c:1765
wb_check_old_data_flush fs/fs-writeback.c:1867 [inline]
wb_do_writeback fs/fs-writeback.c:1920 [inline]
wb_workfn+0x1008/0x1790 fs/fs-writeback.c:1949
process_one_work+0xc90/0x1b90 kernel/workqueue.c:2153
worker_thread+0x17f/0x1390 kernel/workqueue.c:2296
kthread+0x35a/0x420 kernel/kthread.c:246
ret_from_fork+0x3a/0x50 arch/x86/entry/entry_64.S:413
INFO: task jbd2/sda1-8:3077 blocked for more than 140 seconds.
Not tainted 4.19.0-rc5+ #236
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
jbd2/sda1-8 D18264 3077 2 0x80000000
Call Trace:
context_switch kernel/sched/core.c:2825 [inline]
__schedule+0x86c/0x1ed0 kernel/sched/core.c:3473
schedule+0xfe/0x460 kernel/sched/core.c:3517
jbd2_journal_commit_transaction+0xd42/0x89f8 fs/jbd2/commit.c:435
kjournald2+0x26d/0xb30 fs/jbd2/journal.c:229
kthread+0x35a/0x420 kernel/kthread.c:246
ret_from_fork+0x3a/0x50 arch/x86/entry/entry_64.S:413
INFO: task rs:main Q:Reg:5209 blocked for more than 140 seconds.
Not tainted 4.19.0-rc5+ #236
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
rs:main Q:Reg D22816 5209 1 0x00000000
Call Trace:
context_switch kernel/sched/core.c:2825 [inline]
__schedule+0x86c/0x1ed0 kernel/sched/core.c:3473
schedule+0xfe/0x460 kernel/sched/core.c:3517
start_this_handle+0x83e/0x1250 fs/jbd2/transaction.c:334
jbd2__journal_start+0x3c9/0xa90 fs/jbd2/transaction.c:439
__ext4_journal_start_sb+0x1a5/0x5f0 fs/ext4/ext4_jbd2.c:81
__ext4_journal_start fs/ext4/ext4_jbd2.h:311 [inline]
ext4_dirty_inode+0x62/0xc0 fs/ext4/inode.c:6023
__mark_inode_dirty+0x7c3/0x1510 fs/fs-writeback.c:2129
generic_update_time+0x26a/0x450 fs/inode.c:1651
update_time fs/inode.c:1667 [inline]
file_update_time+0x390/0x640 fs/inode.c:1877
__generic_file_write_iter+0x1dc/0x630 mm/filemap.c:3214
ext4_file_write_iter+0x390/0x1420 fs/ext4/file.c:266
call_write_iter include/linux/fs.h:1808 [inline]
new_sync_write fs/read_write.c:474 [inline]
__vfs_write+0x6b8/0x9f0 fs/read_write.c:487
vfs_write+0x1fc/0x560 fs/read_write.c:549
ksys_write+0x101/0x260 fs/read_write.c:598
__do_sys_write fs/read_write.c:610 [inline]
__se_sys_write fs/read_write.c:607 [inline]
__x64_sys_write+0x73/0xb0 fs/read_write.c:607
do_syscall_64+0x1b9/0x820 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x7fa754e7a19d
Code: d1 20 00 00 75 10 b8 01 00 00 00 0f 05 48 3d 01 f0 ff ff 73 31 c3 48
83 ec 08 e8 be fa ff ff 48 89 04 24 b8 01 00 00 00 0f 05 <48> 8b 3c 24 48
89 c2 e8 07 fb ff ff 48 89 d0 48 83 c4 08 48 3d 01
RSP: 002b:00007fa75341b000 EFLAGS: 00000293 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 0000000000000105 RCX: 00007fa754e7a19d
RDX: 0000000000000105 RSI: 000000000196aa90 RDI: 0000000000000001
RBP: 000000000196aa90 R08: 746170203a687461 R09: 65642f27203d2068
R10: 0000000000000000 R11: 0000000000000293 R12: 0000000000000000
R13: 00007fa75341b480 R14: 0000000000000002 R15: 000000000196a890
INFO: task syz-executor2:8726 blocked for more than 140 seconds.
Not tainted 4.19.0-rc5+ #236
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor2 D23736 8726 5368 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2825 [inline]
__schedule+0x86c/0x1ed0 kernel/sched/core.c:3473
schedule+0xfe/0x460 kernel/sched/core.c:3517
__rwsem_down_write_failed_common+0xbb9/0x1670
kernel/locking/rwsem-xadd.c:566
rwsem_down_write_failed+0xe/0x10 kernel/locking/rwsem-xadd.c:595
call_rwsem_down_write_failed+0x17/0x30 arch/x86/lib/rwsem.S:117
__down_write arch/x86/include/asm/rwsem.h:142 [inline]
down_write+0xa5/0x130 kernel/locking/rwsem.c:72
inode_lock include/linux/fs.h:738 [inline]
process_measurement+0x190f/0x1bf0 security/integrity/ima/ima_main.c:205
ima_file_check+0xe5/0x130 security/integrity/ima/ima_main.c:391
do_last fs/namei.c:3422 [inline]
path_openat+0x134d/0x5160 fs/namei.c:3534
do_filp_open+0x255/0x380 fs/namei.c:3564
do_sys_open+0x568/0x700 fs/open.c:1063
__do_sys_openat fs/open.c:1090 [inline]
__se_sys_openat fs/open.c:1084 [inline]
__x64_sys_openat+0x9d/0x100 fs/open.c:1084
do_syscall_64+0x1b9/0x820 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x457579
Code: Bad RIP value.
RSP: 002b:00007f7587708c78 EFLAGS: 00000246 ORIG_RAX: 0000000000000101
RAX: ffffffffffffffda RBX: 0000000000000004 RCX: 0000000000457579
RDX: 000000000000275a RSI: 0000000020000180 RDI: ffffffffffffff9c
RBP: 000000000072bfa0 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 00007f75877096d4
R13: 00000000004c2b26 R14: 00000000004d4140 R15: 00000000ffffffff
INFO: task syz-executor2:8729 blocked for more than 140 seconds.
Not tainted 4.19.0-rc5+ #236
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor2 D25128 8729 5368 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2825 [inline]
__schedule+0x86c/0x1ed0 kernel/sched/core.c:3473
schedule+0xfe/0x460 kernel/sched/core.c:3517
__rwsem_down_write_failed_common+0xbb9/0x1670
kernel/locking/rwsem-xadd.c:566
rwsem_down_write_failed+0xe/0x10 kernel/locking/rwsem-xadd.c:595
call_rwsem_down_write_failed+0x17/0x30 arch/x86/lib/rwsem.S:117
__down_write arch/x86/include/asm/rwsem.h:142 [inline]
down_write+0xa5/0x130 kernel/locking/rwsem.c:72
inode_lock include/linux/fs.h:738 [inline]
ext4_file_write_iter+0x30b/0x1420 fs/ext4/file.c:235
call_write_iter include/linux/fs.h:1808 [inline]
new_sync_write fs/read_write.c:474 [inline]
__vfs_write+0x6b8/0x9f0 fs/read_write.c:487
vfs_write+0x1fc/0x560 fs/read_write.c:549
ksys_pwrite64+0x181/0x1b0 fs/read_write.c:652
__do_sys_pwrite64 fs/read_write.c:662 [inline]
__se_sys_pwrite64 fs/read_write.c:659 [inline]
__x64_sys_pwrite64+0x97/0xf0 fs/read_write.c:659
do_syscall_64+0x1b9/0x820 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x457579
Code: Bad RIP value.
RSP: 002b:00007f75876e7c78 EFLAGS: 00000246 ORIG_RAX: 0000000000000012
RAX: ffffffffffffffda RBX: 0000000000000004 RCX: 0000000000457579
RDX: 0000000000000001 RSI: 00000000200005c0 RDI: 0000000000000003
RBP: 000000000072c040 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 00007f75876e86d4
R13: 00000000004c319d R14: 00000000004d4c38 R15: 00000000ffffffff
INFO: task syz-executor2:8730 blocked for more than 140 seconds.
Not tainted 4.19.0-rc5+ #236
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor2 D23736 8730 5368 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2825 [inline]
__schedule+0x86c/0x1ed0 kernel/sched/core.c:3473
schedule+0xfe/0x460 kernel/sched/core.c:3517
__rwsem_down_write_failed_common+0xbb9/0x1670
kernel/locking/rwsem-xadd.c:566
rwsem_down_write_failed+0xe/0x10 kernel/locking/rwsem-xadd.c:595
call_rwsem_down_write_failed+0x17/0x30 arch/x86/lib/rwsem.S:117
__down_write arch/x86/include/asm/rwsem.h:142 [inline]
down_write+0xa5/0x130 kernel/locking/rwsem.c:72
inode_lock include/linux/fs.h:738 [inline]
process_measurement+0x190f/0x1bf0 security/integrity/ima/ima_main.c:205
ima_file_check+0xe5/0x130 security/integrity/ima/ima_main.c:391
do_last fs/namei.c:3422 [inline]
path_openat+0x134d/0x5160 fs/namei.c:3534
do_filp_open+0x255/0x380 fs/namei.c:3564
do_sys_open+0x568/0x700 fs/open.c:1063
__do_sys_openat fs/open.c:1090 [inline]
__se_sys_openat fs/open.c:1084 [inline]
__x64_sys_openat+0x9d/0x100 fs/open.c:1084
do_syscall_64+0x1b9/0x820 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x457579
Code: Bad RIP value.
RSP: 002b:00007f75876c6c78 EFLAGS: 00000246 ORIG_RAX: 0000000000000101
RAX: ffffffffffffffda RBX: 0000000000000004 RCX: 0000000000457579
RDX: 000000000000275a RSI: 0000000020000000 RDI: ffffffffffffff9c
RBP: 000000000072c0e0 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 00007f75876c76d4
R13: 00000000004c2b26 R14: 00000000004d4140 R15: 00000000ffffffff
INFO: task syz-executor2:8738 blocked for more than 140 seconds.
Not tainted 4.19.0-rc5+ #236
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor2 D25128 8738 5368 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2825 [inline]
__schedule+0x86c/0x1ed0 kernel/sched/core.c:3473
schedule+0xfe/0x460 kernel/sched/core.c:3517
__rwsem_down_write_failed_common+0xbb9/0x1670
kernel/locking/rwsem-xadd.c:566
rwsem_down_write_failed+0xe/0x10 kernel/locking/rwsem-xadd.c:595
call_rwsem_down_write_failed+0x17/0x30 arch/x86/lib/rwsem.S:117
__down_write arch/x86/include/asm/rwsem.h:142 [inline]
down_write+0xa5/0x130 kernel/locking/rwsem.c:72
inode_lock include/linux/fs.h:738 [inline]
ext4_file_write_iter+0x30b/0x1420 fs/ext4/file.c:235
call_write_iter include/linux/fs.h:1808 [inline]
new_sync_write fs/read_write.c:474 [inline]
__vfs_write+0x6b8/0x9f0 fs/read_write.c:487
vfs_write+0x1fc/0x560 fs/read_write.c:549
ksys_write+0x101/0x260 fs/read_write.c:598
__do_sys_write fs/read_write.c:610 [inline]
__se_sys_write fs/read_write.c:607 [inline]
__x64_sys_write+0x73/0xb0 fs/read_write.c:607
do_syscall_64+0x1b9/0x820 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x457579
Code: Bad RIP value.
RSP: 002b:00007f75876a5c78 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 0000000000000003 RCX: 0000000000457579
RDX: 0000000000000012 RSI: 0000000020000100 RDI: 0000000000000004
RBP: 000000000072c180 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 00007f75876a66d4
R13: 00000000004c5574 R14: 00000000004d8e98 R15: 00000000ffffffff
INFO: task syz-executor2:8739 blocked for more than 140 seconds.
Not tainted 4.19.0-rc5+ #236
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor2 D24872 8739 5368 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2825 [inline]
__schedule+0x86c/0x1ed0 kernel/sched/core.c:3473
schedule+0xfe/0x460 kernel/sched/core.c:3517
__rwsem_down_write_failed_common+0xbb9/0x1670
kernel/locking/rwsem-xadd.c:566
rwsem_down_write_failed+0xe/0x10 kernel/locking/rwsem-xadd.c:595
call_rwsem_down_write_failed+0x17/0x30 arch/x86/lib/rwsem.S:117
__down_write arch/x86/include/asm/rwsem.h:142 [inline]
down_write+0xa5/0x130 kernel/locking/rwsem.c:72
inode_lock include/linux/fs.h:738 [inline]
ext4_fallocate+0x31b/0x2300 fs/ext4/extents.c:4957
vfs_fallocate+0x4b4/0x940 fs/open.c:308
ioctl_preallocate+0x1e8/0x300 fs/ioctl.c:482
file_ioctl fs/ioctl.c:498 [inline]
do_vfs_ioctl+0x1435/0x1720 fs/ioctl.c:685
ksys_ioctl+0xa9/0xd0 fs/ioctl.c:702
__do_sys_ioctl fs/ioctl.c:709 [inline]
__se_sys_ioctl fs/ioctl.c:707 [inline]
__x64_sys_ioctl+0x73/0xb0 fs/ioctl.c:707
do_syscall_64+0x1b9/0x820 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x457579
Code: Bad RIP value.
RSP: 002b:00007f7587684c78 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000003 RCX: 0000000000457579
RDX: 0000000020000080 RSI: 0000000040305828 RDI: 0000000000000004
RBP: 000000000072c220 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 00007f75876856d4
R13: 00000000004bf74c R14: 00000000004cf658 R15: 00000000ffffffff
INFO: task syz-executor2:8743 blocked for more than 140 seconds.
Not tainted 4.19.0-rc5+ #236
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor2 D24872 8743 5368 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2825 [inline]
__schedule+0x86c/0x1ed0 kernel/sched/core.c:3473
schedule+0xfe/0x460 kernel/sched/core.c:3517
__rwsem_down_write_failed_common+0xbb9/0x1670
kernel/locking/rwsem-xadd.c:566
rwsem_down_write_failed+0xe/0x10 kernel/locking/rwsem-xadd.c:595
call_rwsem_down_write_failed+0x17/0x30 arch/x86/lib/rwsem.S:117
__down_write arch/x86/include/asm/rwsem.h:142 [inline]
down_write+0xa5/0x130 kernel/locking/rwsem.c:72
inode_lock include/linux/fs.h:738 [inline]
ext4_fallocate+0x31b/0x2300 fs/ext4/extents.c:4957
vfs_fallocate+0x4b4/0x940 fs/open.c:308
ioctl_preallocate+0x1e8/0x300 fs/ioctl.c:482
file_ioctl fs/ioctl.c:498 [inline]
do_vfs_ioctl+0x1435/0x1720 fs/ioctl.c:685
ksys_ioctl+0xa9/0xd0 fs/ioctl.c:702
__do_sys_ioctl fs/ioctl.c:709 [inline]
__se_sys_ioctl fs/ioctl.c:707 [inline]
__x64_sys_ioctl+0x73/0xb0 fs/ioctl.c:707
do_syscall_64+0x1b9/0x820 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x457579
Code: Bad RIP value.
RSP: 002b:00007f7587663c78 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000003 RCX: 0000000000457579
RDX: 0000000020000140 RSI: 0000000040305828 RDI: 0000000000000003
RBP: 000000000072c2c0 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 00007f75876646d4
R13: 00000000004bf74c R14: 00000000004cf658 R15: 00000000ffffffff
INFO: task syz-executor0:8756 blocked for more than 140 seconds.
Not tainted 4.19.0-rc5+ #236
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor0 D23400 8756 5341 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2825 [inline]
__schedule+0x86c/0x1ed0 kernel/sched/core.c:3473
schedule+0xfe/0x460 kernel/sched/core.c:3517
start_this_handle+0x83e/0x1250 fs/jbd2/transaction.c:334
jbd2__journal_start+0x3c9/0xa90 fs/jbd2/transaction.c:439
__ext4_journal_start_sb+0x1a5/0x5f0 fs/ext4/ext4_jbd2.c:81
__ext4_journal_start fs/ext4/ext4_jbd2.h:311 [inline]
ext4_dirty_inode+0x62/0xc0 fs/ext4/inode.c:6023
__mark_inode_dirty+0x7c3/0x1510 fs/fs-writeback.c:2129
generic_update_time+0x26a/0x450 fs/inode.c:1651
update_time fs/inode.c:1667 [inline]
file_update_time+0x390/0x640 fs/inode.c:1877
ext4_page_mkwrite+0x1fe/0x14a0 fs/ext4/inode.c:6171
do_page_mkwrite+0x14e/0x660 mm/memory.c:2388
do_shared_fault mm/memory.c:3717 [inline]
do_fault mm/memory.c:3756 [inline]
handle_pte_fault mm/memory.c:3983 [inline]
__handle_mm_fault+0x35ca/0x53e0 mm/memory.c:4107
handle_mm_fault+0x54f/0xc70 mm/memory.c:4144
__do_page_fault+0x67d/0xed0 arch/x86/mm/fault.c:1395
do_page_fault+0xf2/0x7e0 arch/x86/mm/fault.c:1470
page_fault+0x1e/0x30 arch/x86/entry/entry_64.S:1161
RIP: 0033:0x4016a7
Code: 20 48 80 98 80 44 00 90 42 58 0a 83 04 01 a5 85 20 01 00 90 81 99 61
00 72 ac a8 55 10 03 02 00 0b 27 10 06 00 00 08 04 2a 00 <02> 00 81 02 82
80 ca 04 24 00 54 00 07 02 24 01 00 10 02 02 42 29
RSP: 002b:00007ffc249765e0 EFLAGS: 00010287
RAX: 0000001b31825000 RBX: 00000000bedaa82a RCX: 0000001b32820000
RDX: 0000001b31825004 RSI: 0000000000001c9a RDI: ffffffff06d79c9a
RBP: 00000000000003de R08: 0000000006d79c9a R09: 0000000006d79c9e
R10: 00007ffc24976750 R11: 0000000000000246 R12: 000000000072bf00
R13: 0000000080000000 R14: 00007f5abb46a008 R15: 0000000000000ba5

Showing all locks held in the system:
4 locks held by kworker/u4:0/7:
#0: 00000000cb693be2 ((wq_completion)"writeback"){+.+.}, at:
__write_once_size include/linux/compiler.h:215 [inline]
#0: 00000000cb693be2 ((wq_completion)"writeback"){+.+.}, at:
arch_atomic64_set arch/x86/include/asm/atomic64_64.h:34 [inline]
#0: 00000000cb693be2 ((wq_completion)"writeback"){+.+.}, at: atomic64_set
include/asm-generic/atomic-instrumented.h:40 [inline]
#0: 00000000cb693be2 ((wq_completion)"writeback"){+.+.}, at:
atomic_long_set include/asm-generic/atomic-long.h:59 [inline]
#0: 00000000cb693be2 ((wq_completion)"writeback"){+.+.}, at: set_work_data
kernel/workqueue.c:617 [inline]
#0: 00000000cb693be2 ((wq_completion)"writeback"){+.+.}, at:
set_work_pool_and_clear_pending kernel/workqueue.c:644 [inline]
#0: 00000000cb693be2 ((wq_completion)"writeback"){+.+.}, at:
process_one_work+0xb43/0x1b90 kernel/workqueue.c:2124
#1: 000000007794059f ((work_completion)(&(&wb->dwork)->work)){+.+.}, at:
process_one_work+0xb9a/0x1b90 kernel/workqueue.c:2128
#2: 000000009a6e0723 (&type->s_umount_key#30){++++}, at:
trylock_super+0x22/0x110 fs/super.c:412
#3: 00000000feb214b2 (&sbi->s_journal_flag_rwsem){.+.+}, at:
do_writepages+0x9a/0x1a0 mm/page-writeback.c:2340
4 locks held by kworker/u4:3/167:
#0: 00000000cb693be2 ((wq_completion)"writeback"){+.+.}, at:
__write_once_size include/linux/compiler.h:215 [inline]
#0: 00000000cb693be2 ((wq_completion)"writeback"){+.+.}, at:
arch_atomic64_set arch/x86/include/asm/atomic64_64.h:34 [inline]
#0: 00000000cb693be2 ((wq_completion)"writeback"){+.+.}, at: atomic64_set
include/asm-generic/atomic-instrumented.h:40 [inline]
#0: 00000000cb693be2 ((wq_completion)"writeback"){+.+.}, at:
atomic_long_set include/asm-generic/atomic-long.h:59 [inline]
#0: 00000000cb693be2 ((wq_completion)"writeback"){+.+.}, at: set_work_data
kernel/workqueue.c:617 [inline]
#0: 00000000cb693be2 ((wq_completion)"writeback"){+.+.}, at:
set_work_pool_and_clear_pending kernel/workqueue.c:644 [inline]
#0: 00000000cb693be2 ((wq_completion)"writeback"){+.+.}, at:
process_one_work+0xb43/0x1b90 kernel/workqueue.c:2124
#1: 000000008c1fc3e2 ((work_completion)(&(&wb->dwork)->work)){+.+.}, at:
process_one_work+0xb9a/0x1b90 kernel/workqueue.c:2128
#2: 000000009a6e0723 (&type->s_umount_key#30){++++}, at:
trylock_super+0x22/0x110 fs/super.c:412
#3: 00000000feb214b2 (&sbi->s_journal_flag_rwsem){.+.+}, at:
do_writepages+0x9a/0x1a0 mm/page-writeback.c:2340
1 lock held by khungtaskd/982:
#0: 00000000ab4a84b7 (rcu_read_lock){....}, at:
debug_show_all_locks+0xd0/0x424 kernel/locking/lockdep.c:4435
4 locks held by kworker/u4:4/2776:
#0: 00000000cb693be2 ((wq_completion)"writeback"){+.+.}, at:
__write_once_size include/linux/compiler.h:215 [inline]
#0: 00000000cb693be2 ((wq_completion)"writeback"){+.+.}, at:
arch_atomic64_set arch/x86/include/asm/atomic64_64.h:34 [inline]
#0: 00000000cb693be2 ((wq_completion)"writeback"){+.+.}, at: atomic64_set
include/asm-generic/atomic-instrumented.h:40 [inline]
#0: 00000000cb693be2 ((wq_completion)"writeback"){+.+.}, at:
atomic_long_set include/asm-generic/atomic-long.h:59 [inline]
#0: 00000000cb693be2 ((wq_completion)"writeback"){+.+.}, at: set_work_data
kernel/workqueue.c:617 [inline]
#0: 00000000cb693be2 ((wq_completion)"writeback"){+.+.}, at:
set_work_pool_and_clear_pending kernel/workqueue.c:644 [inline]
#0: 00000000cb693be2 ((wq_completion)"writeback"){+.+.}, at:
process_one_work+0xb43/0x1b90 kernel/workqueue.c:2124
#1: 000000007bb994ef ((work_completion)(&(&wb->dwork)->work)){+.+.}, at:
process_one_work+0xb9a/0x1b90 kernel/workqueue.c:2128
#2: 000000009a6e0723 (&type->s_umount_key#30){++++}, at:
trylock_super+0x22/0x110 fs/super.c:412
#3: 00000000feb214b2 (&sbi->s_journal_flag_rwsem){.+.+}, at:
do_writepages+0x9a/0x1a0 mm/page-writeback.c:2340
3 locks held by rs:main Q:Reg/5209:
#0: 00000000663c845f (&f->f_pos_lock){+.+.}, at: __fdget_pos+0x1bb/0x200
fs/file.c:766
#1: 00000000dedbff4f (sb_writers#3){.+.+}, at: file_start_write
include/linux/fs.h:2759 [inline]
#1: 00000000dedbff4f (sb_writers#3){.+.+}, at: vfs_write+0x42a/0x560
fs/read_write.c:548
#2: 00000000f3576a5a (&sb->s_type->i_mutex_key#10){+.+.}, at:
inode_trylock include/linux/fs.h:758 [inline]
#2: 00000000f3576a5a (&sb->s_type->i_mutex_key#10){+.+.}, at:
ext4_file_write_iter+0x2a1/0x1420 fs/ext4/file.c:232
1 lock held by rsyslogd/5211:
#0: 00000000e8622796 (&f->f_pos_lock){+.+.}, at: __fdget_pos+0x1bb/0x200
fs/file.c:766
2 locks held by getty/5302:
#0: 00000000581b6fd4 (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x32/0x40 drivers/tty/tty_ldsem.c:353
#1: 000000004a1f10b0 (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x335/0x1ce0 drivers/tty/n_tty.c:2140
2 locks held by getty/5303:
#0: 00000000918d2b92 (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x32/0x40 drivers/tty/tty_ldsem.c:353
#1: 00000000f6663dc9 (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x335/0x1ce0 drivers/tty/n_tty.c:2140
2 locks held by getty/5304:
#0: 00000000c1d7718f (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x32/0x40 drivers/tty/tty_ldsem.c:353
#1: 000000000d7b159f (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x335/0x1ce0 drivers/tty/n_tty.c:2140
2 locks held by getty/5305:
#0: 0000000034a5a1c6 (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x32/0x40 drivers/tty/tty_ldsem.c:353
#1: 000000002d1d3198 (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x335/0x1ce0 drivers/tty/n_tty.c:2140
2 locks held by getty/5306:
#0: 00000000e637a257 (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x32/0x40 drivers/tty/tty_ldsem.c:353
#1: 000000009e115ea8 (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x335/0x1ce0 drivers/tty/n_tty.c:2140
2 locks held by getty/5307:
#0: 00000000740df120 (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x32/0x40 drivers/tty/tty_ldsem.c:353
#1: 0000000071f5b0d8 (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x335/0x1ce0 drivers/tty/n_tty.c:2140
2 locks held by getty/5308:
#0: 00000000502d01f8 (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x32/0x40 drivers/tty/tty_ldsem.c:353
#1: 000000001150f997 (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x335/0x1ce0 drivers/tty/n_tty.c:2140
6 locks held by syz-executor2/8684:
2 locks held by syz-executor2/8726:
#0: 00000000dedbff4f (sb_writers#3){.+.+}, at: sb_start_write
include/linux/fs.h:1566 [inline]
#0: 00000000dedbff4f (sb_writers#3){.+.+}, at: mnt_want_write+0x3f/0xc0
fs/namespace.c:360
#1: 00000000ff7992db (&sb->s_type->i_mutex_key#10){+.+.}, at: inode_lock
include/linux/fs.h:738 [inline]
#1: 00000000ff7992db (&sb->s_type->i_mutex_key#10){+.+.}, at:
process_measurement+0x190f/0x1bf0 security/integrity/ima/ima_main.c:205
2 locks held by syz-executor2/8729:
#0: 00000000dedbff4f (sb_writers#3){.+.+}, at: file_start_write
include/linux/fs.h:2759 [inline]
#0: 00000000dedbff4f (sb_writers#3){.+.+}, at: vfs_write+0x42a/0x560
fs/read_write.c:548
#1: 00000000ff7992db (&sb->s_type->i_mutex_key#10){+.+.}, at: inode_lock
include/linux/fs.h:738 [inline]
#1: 00000000ff7992db (&sb->s_type->i_mutex_key#10){+.+.}, at:
ext4_file_write_iter+0x30b/0x1420 fs/ext4/file.c:235
2 locks held by syz-executor2/8730:
#0: 00000000dedbff4f (sb_writers#3){.+.+}, at: sb_start_write
include/linux/fs.h:1566 [inline]
#0: 00000000dedbff4f (sb_writers#3){.+.+}, at: mnt_want_write+0x3f/0xc0
fs/namespace.c:360
#1: 0000000090fff23e (&sb->s_type->i_mutex_key#10){+.+.}, at: inode_lock
include/linux/fs.h:738 [inline]
#1: 0000000090fff23e (&sb->s_type->i_mutex_key#10){+.+.}, at:
process_measurement+0x190f/0x1bf0 security/integrity/ima/ima_main.c:205
3 locks held by syz-executor2/8738:
#0: 000000009b1a5f48 (&f->f_pos_lock){+.+.}, at: __fdget_pos+0x1bb/0x200
fs/file.c:766
#1: 00000000dedbff4f (sb_writers#3){.+.+}, at: file_start_write
include/linux/fs.h:2759 [inline]
#1: 00000000dedbff4f (sb_writers#3){.+.+}, at: vfs_write+0x42a/0x560
fs/read_write.c:548
#2: 0000000090fff23e (&sb->s_type->i_mutex_key#10){+.+.}, at: inode_lock
include/linux/fs.h:738 [inline]
#2: 0000000090fff23e (&sb->s_type->i_mutex_key#10){+.+.}, at:
ext4_file_write_iter+0x30b/0x1420 fs/ext4/file.c:235
2 locks held by syz-executor2/8739:
#0: 00000000dedbff4f (sb_writers#3){.+.+}, at: file_start_write
include/linux/fs.h:2759 [inline]
#0: 00000000dedbff4f (sb_writers#3){.+.+}, at: vfs_fallocate+0x72a/0x940
fs/open.c:307
#1: 0000000090fff23e (&sb->s_type->i_mutex_key#10){+.+.}, at: inode_lock
include/linux/fs.h:738 [inline]
#1: 0000000090fff23e (&sb->s_type->i_mutex_key#10){+.+.}, at:
ext4_fallocate+0x31b/0x2300 fs/ext4/extents.c:4957
2 locks held by syz-executor2/8743:
#0: 00000000dedbff4f (sb_writers#3){.+.+}, at: file_start_write
include/linux/fs.h:2759 [inline]
#0: 00000000dedbff4f (sb_writers#3){.+.+}, at: vfs_fallocate+0x72a/0x940
fs/open.c:307
#1: 00000000ff7992db (&sb->s_type->i_mutex_key#10){+.+.}, at: inode_lock
include/linux/fs.h:738 [inline]
#1: 00000000ff7992db (&sb->s_type->i_mutex_key#10){+.+.}, at:
ext4_fallocate+0x31b/0x2300 fs/ext4/extents.c:4957
2 locks held by syz-executor0/8756:
#0: 00000000d80d1547 (&mm->mmap_sem){++++}, at:
__do_page_fault+0x3e3/0xed0 arch/x86/mm/fault.c:1324
#1: 00000000e61ca0fd (sb_pagefaults){.+.+}, at: sb_start_pagefault
include/linux/fs.h:1595 [inline]
#1: 00000000e61ca0fd (sb_pagefaults){.+.+}, at:
ext4_page_mkwrite+0x1d0/0x14a0 fs/ext4/inode.c:6170
3 locks held by syz-executor0/8757:
#0: 000000000d7b58cc (&f->f_pos_lock){+.+.}, at: __fdget_pos+0x1bb/0x200
fs/file.c:766
#1: 00000000dedbff4f (sb_writers#3){.+.+}, at: file_start_write
include/linux/fs.h:2759 [inline]
#1: 00000000dedbff4f (sb_writers#3){.+.+}, at: vfs_write+0x42a/0x560
fs/read_write.c:548
#2: 000000008588119e (&sb->s_type->i_mutex_key#10){+.+.}, at:
inode_trylock include/linux/fs.h:758 [inline]
#2: 000000008588119e (&sb->s_type->i_mutex_key#10){+.+.}, at:
ext4_file_write_iter+0x2a1/0x1420 fs/ext4/file.c:232
2 locks held by syz-executor0/8765:
#0: 00000000dedbff4f (sb_writers#3){.+.+}, at: sb_start_write
include/linux/fs.h:1566 [inline]
#0: 00000000dedbff4f (sb_writers#3){.+.+}, at:
mnt_want_write_file+0x68/0x110 fs/namespace.c:418
#1: 000000008588119e (&sb->s_type->i_mutex_key#10){+.+.}, at: inode_lock
include/linux/fs.h:738 [inline]
#1: 000000008588119e (&sb->s_type->i_mutex_key#10){+.+.}, at:
ext4_ioctl+0x529/0x4210 fs/ext4/ioctl.c:836
1 lock held by syz-executor0/8768:
#0: 00000000dedbff4f (sb_writers#3){.+.+}, at: sb_start_write
include/linux/fs.h:1566 [inline]
#0: 00000000dedbff4f (sb_writers#3){.+.+}, at:
mnt_want_write_file+0x68/0x110 fs/namespace.c:418

=============================================

NMI backtrace for cpu 1
CPU: 1 PID: 982 Comm: khungtaskd Not tainted 4.19.0-rc5+ #236
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x1c4/0x2b4 lib/dump_stack.c:113
nmi_cpu_backtrace.cold.3+0x63/0xa2 lib/nmi_backtrace.c:101
nmi_trigger_cpumask_backtrace+0x1b3/0x1ed lib/nmi_backtrace.c:62
arch_trigger_cpumask_backtrace+0x14/0x20 arch/x86/kernel/apic/hw_nmi.c:38
trigger_all_cpu_backtrace include/linux/nmi.h:144 [inline]
check_hung_uninterruptible_tasks kernel/hung_task.c:204 [inline]
watchdog+0xb3e/0x1050 kernel/hung_task.c:265
kthread+0x35a/0x420 kernel/kthread.c:246
ret_from_fork+0x3a/0x50 arch/x86/entry/entry_64.S:413
Sending NMI from CPU 1 to CPUs 0:
INFO: NMI handler (nmi_cpu_backtrace_handler) took too long to run: 1.011
msecs
NMI backtrace for cpu 0
CPU: 0 PID: 8684 Comm: syz-executor2 Not tainted 4.19.0-rc5+ #236
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
RIP: 0010:mext_check_coverage.constprop.13+0x227/0x510
fs/ext4/move_extent.c:102
Code: 49 8d 7c 24 10 48 89 fa 48 c1 ea 03 80 3c 02 00 0f 85 36 02 00 00 48
b8 00 00 00 00 00 fc ff df 4d 8b 64 24 10 49 8d 7c 24 04 <48> 89 fa 48 c1
ea 03 0f b6 14 02 48 89 f8 83 e0 07 83 c0 01 38 d0
RSP: 0018:ffff88019ca6f1c0 EFLAGS: 00000246
RAX: dffffc0000000000 RBX: ffff8801cb7cf100 RCX: ffffc90005e92000
RDX: 1ffff100396f9e22 RSI: ffffffff821e390b RDI: ffff88018f410590
RBP: ffff88019ca6f270 R08: ffff8801ce532480 R09: 1ffffffff1273955
R10: ffffed003b5e4732 R11: ffff8801daf23993 R12: ffff88018f41058c
R13: 0000000095763ea2 R14: ffff88018f410770 R15: ffff88019ca6f3e0
FS: 00007f758772a700(0000) GS:ffff8801dae00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: ffffffffff600400 CR3: 00000001cf2e2000 CR4: 00000000001406f0
Call Trace:
move_extent_per_page fs/ext4/move_extent.c:323 [inline]
ext4_move_extents+0x2784/0x3c20 fs/ext4/move_extent.c:669
ext4_ioctl+0x3154/0x4210 fs/ext4/ioctl.c:799
vfs_ioctl fs/ioctl.c:46 [inline]
file_ioctl fs/ioctl.c:501 [inline]
do_vfs_ioctl+0x1de/0x1720 fs/ioctl.c:685
ksys_ioctl+0xa9/0xd0 fs/ioctl.c:702
__do_sys_ioctl fs/ioctl.c:709 [inline]
__se_sys_ioctl fs/ioctl.c:707 [inline]
__x64_sys_ioctl+0x73/0xb0 fs/ioctl.c:707
do_syscall_64+0x1b9/0x820 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x457579
Code: 1d b4 fb ff c3 66 2e 0f 1f 84 00 00 00 00 00 66 90 48 89 f8 48 89 f7
48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff
ff 0f 83 eb b3 fb ff c3 66 2e 0f 1f 84 00 00 00 00
RSP: 002b:00007f7587729c78 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000003 RCX: 0000000000457579
RDX: 0000000020000300 RSI: 00000000c028660f RDI: 0000000000000003
RBP: 000000000072bf00 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 00007f758772a6d4
R13: 00000000004bf5dd R14: 00000000004cf460 R15: 00000000ffffffff


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#bug-status-tracking for how to communicate with
syzbot.

syzbot

unread,
Apr 7, 2019, 7:35:07 PM4/7/19
to syzkaller-upst...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages