INFO: task hung in __sb_start_write (2)

8 views
Skip to first unread message

syzbot

unread,
Sep 10, 2018, 1:21:03 PM9/10/18
to syzkaller-upst...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: ca16eb342ebe Merge tag 'for-linus-20180906' of git://git.k..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=15f3118e400000
kernel config: https://syzkaller.appspot.com/x/.config?x=6c9564cd177daf0c
dashboard link: https://syzkaller.appspot.com/bug?extid=a434aff66156fa42c41d
compiler: gcc (GCC) 8.0.1 20180413 (experimental)
CC: [linux-...@vger.kernel.org linux-...@vger.kernel.org
vi...@zeniv.linux.org.uk]

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+a434af...@syzkaller.appspotmail.com

INFO: task syz-executor5:4829 blocked for more than 140 seconds.
Not tainted 4.19.0-rc2+ #4
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor5 D17480 4829 1 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2825 [inline]
__schedule+0x87c/0x1df0 kernel/sched/core.c:3473
schedule+0xfb/0x450 kernel/sched/core.c:3517
__rwsem_down_read_failed_common kernel/locking/rwsem-xadd.c:269 [inline]
rwsem_down_read_failed+0x362/0x610 kernel/locking/rwsem-xadd.c:286
call_rwsem_down_read_failed+0x18/0x30 arch/x86/lib/rwsem.S:94
__down_read arch/x86/include/asm/rwsem.h:83 [inline]
__percpu_down_read+0x16e/0x210 kernel/locking/percpu-rwsem.c:85
percpu_down_read_preempt_disable include/linux/percpu-rwsem.h:49 [inline]
percpu_down_read include/linux/percpu-rwsem.h:59 [inline]
__sb_start_write+0x2d7/0x300 fs/super.c:1387
sb_start_write include/linux/fs.h:1566 [inline]
mnt_want_write+0x3f/0xc0 fs/namespace.c:360
do_unlinkat+0x2b7/0xa30 fs/namei.c:4045
__do_sys_unlink fs/namei.c:4110 [inline]
__se_sys_unlink fs/namei.c:4108 [inline]
__x64_sys_unlink+0x42/0x50 fs/namei.c:4108
do_syscall_64+0x1b9/0x820 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x456de7
Code: 0f 1f 00 b8 58 00 00 00 0f 05 48 3d 01 f0 ff ff 0f 83 9d b7 fb ff c3
66 2e 0f 1f 84 00 00 00 00 00 66 90 b8 57 00 00 00 0f 05 <48> 3d 01 f0 ff
ff 0f 83 7d b7 fb ff c3 66 2e 0f 1f 84 00 00 00 00
RSP: 002b:00007fff3ead41f8 EFLAGS: 00000202 ORIG_RAX: 0000000000000057
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 0000000000456de7
RDX: 00007fff3ead4210 RSI: 00007fff3ead42a0 RDI: 00007fff3ead42a0
RBP: 00000000000002a3 R08: 0000000000000000 R09: 0000000000000010
R10: 000000000000000a R11: 0000000000000202 R12: 00007fff3ead5300
R13: 0000000000dc1940 R14: 0000000000000000 R15: badc0ffeebadface
INFO: task syz-executor6:4831 blocked for more than 140 seconds.
Not tainted 4.19.0-rc2+ #4
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor6 D21248 4831 1 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2825 [inline]
__schedule+0x87c/0x1df0 kernel/sched/core.c:3473
schedule+0xfb/0x450 kernel/sched/core.c:3517
__rwsem_down_read_failed_common kernel/locking/rwsem-xadd.c:269 [inline]
rwsem_down_read_failed+0x362/0x610 kernel/locking/rwsem-xadd.c:286
call_rwsem_down_read_failed+0x18/0x30 arch/x86/lib/rwsem.S:94
__down_read arch/x86/include/asm/rwsem.h:83 [inline]
__percpu_down_read+0x16e/0x210 kernel/locking/percpu-rwsem.c:85
percpu_down_read_preempt_disable include/linux/percpu-rwsem.h:49 [inline]
percpu_down_read include/linux/percpu-rwsem.h:59 [inline]
__sb_start_write+0x2d7/0x300 fs/super.c:1387
sb_start_write include/linux/fs.h:1566 [inline]
mnt_want_write+0x3f/0xc0 fs/namespace.c:360
do_unlinkat+0x2b7/0xa30 fs/namei.c:4045
__do_sys_unlink fs/namei.c:4110 [inline]
__se_sys_unlink fs/namei.c:4108 [inline]
__x64_sys_unlink+0x42/0x50 fs/namei.c:4108
do_syscall_64+0x1b9/0x820 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x456de7
Code: 0f 1f 00 b8 58 00 00 00 0f 05 48 3d 01 f0 ff ff 0f 83 9d b7 fb ff c3
66 2e 0f 1f 84 00 00 00 00 00 66 90 b8 57 00 00 00 0f 05 <48> 3d 01 f0 ff
ff 0f 83 7d b7 fb ff c3 66 2e 0f 1f 84 00 00 00 00
RSP: 002b:00007ffcd75a8388 EFLAGS: 00000206 ORIG_RAX: 0000000000000057
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 0000000000456de7
RDX: 00007ffcd75a83a0 RSI: 00007ffcd75a8430 RDI: 00007ffcd75a8430
RBP: 00000000000002d0 R08: 0000000000000000 R09: 0000000000000010
R10: 000000000000000a R11: 0000000000000206 R12: 00007ffcd75a9490
R13: 0000000000fbd940 R14: 0000000000000000 R15: badc0ffeebadface
INFO: task syz-executor2:4832 blocked for more than 140 seconds.
Not tainted 4.19.0-rc2+ #4
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor2 D16904 4832 1 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2825 [inline]
__schedule+0x87c/0x1df0 kernel/sched/core.c:3473
schedule+0xfb/0x450 kernel/sched/core.c:3517
__rwsem_down_read_failed_common kernel/locking/rwsem-xadd.c:269 [inline]
rwsem_down_read_failed+0x362/0x610 kernel/locking/rwsem-xadd.c:286
call_rwsem_down_read_failed+0x18/0x30 arch/x86/lib/rwsem.S:94
__down_read arch/x86/include/asm/rwsem.h:83 [inline]
__percpu_down_read+0x16e/0x210 kernel/locking/percpu-rwsem.c:85
percpu_down_read_preempt_disable include/linux/percpu-rwsem.h:49 [inline]
percpu_down_read include/linux/percpu-rwsem.h:59 [inline]
__sb_start_write+0x2d7/0x300 fs/super.c:1387
sb_start_write include/linux/fs.h:1566 [inline]
mnt_want_write+0x3f/0xc0 fs/namespace.c:360
do_unlinkat+0x2b7/0xa30 fs/namei.c:4045
__do_sys_unlink fs/namei.c:4110 [inline]
__se_sys_unlink fs/namei.c:4108 [inline]
__x64_sys_unlink+0x42/0x50 fs/namei.c:4108
do_syscall_64+0x1b9/0x820 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x456de7
Code: 0f 1f 00 b8 58 00 00 00 0f 05 48 3d 01 f0 ff ff 0f 83 9d b7 fb ff c3
66 2e 0f 1f 84 00 00 00 00 00 66 90 b8 57 00 00 00 0f 05 <48> 3d 01 f0 ff
ff 0f 83 7d b7 fb ff c3 66 2e 0f 1f 84 00 00 00 00
RSP: 002b:00007ffd0a234228 EFLAGS: 00000206 ORIG_RAX: 0000000000000057
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 0000000000456de7
RDX: 00007ffd0a234240 RSI: 00007ffd0a2342d0 RDI: 00007ffd0a2342d0
RBP: 00000000000002a3 R08: 0000000000000000 R09: 0000000000000010
R10: 000000000000000a R11: 0000000000000206 R12: 00007ffd0a235330
R13: 0000000001f6b940 R14: 0000000000000000 R15: badc0ffeebadface
INFO: task syz-executor1:4833 blocked for more than 140 seconds.
Not tainted 4.19.0-rc2+ #4
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor1 D17480 4833 1 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2825 [inline]
__schedule+0x87c/0x1df0 kernel/sched/core.c:3473
schedule+0xfb/0x450 kernel/sched/core.c:3517
__rwsem_down_read_failed_common kernel/locking/rwsem-xadd.c:269 [inline]
rwsem_down_read_failed+0x362/0x610 kernel/locking/rwsem-xadd.c:286
call_rwsem_down_read_failed+0x18/0x30 arch/x86/lib/rwsem.S:94
__down_read arch/x86/include/asm/rwsem.h:83 [inline]
__percpu_down_read+0x16e/0x210 kernel/locking/percpu-rwsem.c:85
percpu_down_read_preempt_disable include/linux/percpu-rwsem.h:49 [inline]
percpu_down_read include/linux/percpu-rwsem.h:59 [inline]
__sb_start_write+0x2d7/0x300 fs/super.c:1387
sb_start_write include/linux/fs.h:1566 [inline]
mnt_want_write+0x3f/0xc0 fs/namespace.c:360
do_unlinkat+0x2b7/0xa30 fs/namei.c:4045
__do_sys_unlink fs/namei.c:4110 [inline]
__se_sys_unlink fs/namei.c:4108 [inline]
__x64_sys_unlink+0x42/0x50 fs/namei.c:4108
do_syscall_64+0x1b9/0x820 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x456de7
Code: 0f 1f 00 b8 58 00 00 00 0f 05 48 3d 01 f0 ff ff 0f 83 9d b7 fb ff c3
66 2e 0f 1f 84 00 00 00 00 00 66 90 b8 57 00 00 00 0f 05 <48> 3d 01 f0 ff
ff 0f 83 7d b7 fb ff c3 66 2e 0f 1f 84 00 00 00 00
RSP: 002b:00007fff7ab2c0c8 EFLAGS: 00000202 ORIG_RAX: 0000000000000057
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 0000000000456de7
RDX: 00007fff7ab2c0e0 RSI: 00007fff7ab2c170 RDI: 00007fff7ab2c170
RBP: 00000000000002d8 R08: 0000000000000000 R09: 0000000000000010
R10: 000000000000000a R11: 0000000000000202 R12: 00007fff7ab2d1d0
R13: 0000000000eb4940 R14: 0000000000000000 R15: badc0ffeebadface
INFO: task syz-executor3:4834 blocked for more than 140 seconds.
Not tainted 4.19.0-rc2+ #4
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor3 D21248 4834 1 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2825 [inline]
__schedule+0x87c/0x1df0 kernel/sched/core.c:3473
schedule+0xfb/0x450 kernel/sched/core.c:3517
__rwsem_down_read_failed_common kernel/locking/rwsem-xadd.c:269 [inline]
rwsem_down_read_failed+0x362/0x610 kernel/locking/rwsem-xadd.c:286
call_rwsem_down_read_failed+0x18/0x30 arch/x86/lib/rwsem.S:94
__down_read arch/x86/include/asm/rwsem.h:83 [inline]
__percpu_down_read+0x16e/0x210 kernel/locking/percpu-rwsem.c:85
percpu_down_read_preempt_disable include/linux/percpu-rwsem.h:49 [inline]
percpu_down_read include/linux/percpu-rwsem.h:59 [inline]
__sb_start_write+0x2d7/0x300 fs/super.c:1387
sb_start_write include/linux/fs.h:1566 [inline]
mnt_want_write+0x3f/0xc0 fs/namespace.c:360
do_unlinkat+0x2b7/0xa30 fs/namei.c:4045
__do_sys_unlink fs/namei.c:4110 [inline]
__se_sys_unlink fs/namei.c:4108 [inline]
__x64_sys_unlink+0x42/0x50 fs/namei.c:4108
do_syscall_64+0x1b9/0x820 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x456de7
Code: 0f 1f 00 b8 58 00 00 00 0f 05 48 3d 01 f0 ff ff 0f 83 9d b7 fb ff c3
66 2e 0f 1f 84 00 00 00 00 00 66 90 b8 57 00 00 00 0f 05 <48> 3d 01 f0 ff
ff 0f 83 7d b7 fb ff c3 66 2e 0f 1f 84 00 00 00 00
RSP: 002b:00007ffc047a0cc8 EFLAGS: 00000202 ORIG_RAX: 0000000000000057
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 0000000000456de7
RDX: 00007ffc047a0ce0 RSI: 00007ffc047a0d70 RDI: 00007ffc047a0d70
RBP: 00000000000002b7 R08: 0000000000000000 R09: 0000000000000010
R10: 000000000000000a R11: 0000000000000202 R12: 00007ffc047a1dd0
R13: 0000000001b27940 R14: 0000000000000000 R15: badc0ffeebadface
INFO: task syz-executor4:4835 blocked for more than 140 seconds.
Not tainted 4.19.0-rc2+ #4
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor4 D21248 4835 1 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2825 [inline]
__schedule+0x87c/0x1df0 kernel/sched/core.c:3473
schedule+0xfb/0x450 kernel/sched/core.c:3517
__rwsem_down_read_failed_common kernel/locking/rwsem-xadd.c:269 [inline]
rwsem_down_read_failed+0x362/0x610 kernel/locking/rwsem-xadd.c:286
call_rwsem_down_read_failed+0x18/0x30 arch/x86/lib/rwsem.S:94
__down_read arch/x86/include/asm/rwsem.h:83 [inline]
__percpu_down_read+0x16e/0x210 kernel/locking/percpu-rwsem.c:85
percpu_down_read_preempt_disable include/linux/percpu-rwsem.h:49 [inline]
percpu_down_read include/linux/percpu-rwsem.h:59 [inline]
__sb_start_write+0x2d7/0x300 fs/super.c:1387
sb_start_write include/linux/fs.h:1566 [inline]
mnt_want_write+0x3f/0xc0 fs/namespace.c:360
do_unlinkat+0x2b7/0xa30 fs/namei.c:4045
__do_sys_unlink fs/namei.c:4110 [inline]
__se_sys_unlink fs/namei.c:4108 [inline]
__x64_sys_unlink+0x42/0x50 fs/namei.c:4108
do_syscall_64+0x1b9/0x820 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x456de7
Code: 0f 1f 00 b8 58 00 00 00 0f 05 48 3d 01 f0 ff ff 0f 83 9d b7 fb ff c3
66 2e 0f 1f 84 00 00 00 00 00 66 90 b8 57 00 00 00 0f 05 <48> 3d 01 f0 ff
ff 0f 83 7d b7 fb ff c3 66 2e 0f 1f 84 00 00 00 00
RSP: 002b:00007ffc6a432dd8 EFLAGS: 00000206 ORIG_RAX: 0000000000000057
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 0000000000456de7
RDX: 00007ffc6a432df0 RSI: 00007ffc6a432e80 RDI: 00007ffc6a432e80
RBP: 00000000000002f1 R08: 0000000000000000 R09: 0000000000000010
R10: 000000000000000a R11: 0000000000000206 R12: 00007ffc6a433ee0
R13: 0000000002410940 R14: 0000000000000000 R15: badc0ffeebadface
INFO: task syz-executor0:11936 blocked for more than 140 seconds.
Not tainted 4.19.0-rc2+ #4
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor0 D26632 11936 4830 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2825 [inline]
__schedule+0x87c/0x1df0 kernel/sched/core.c:3473
schedule+0xfb/0x450 kernel/sched/core.c:3517
__rwsem_down_read_failed_common kernel/locking/rwsem-xadd.c:269 [inline]
rwsem_down_read_failed+0x362/0x610 kernel/locking/rwsem-xadd.c:286
call_rwsem_down_read_failed+0x18/0x30 arch/x86/lib/rwsem.S:94
__down_read arch/x86/include/asm/rwsem.h:83 [inline]
__percpu_down_read+0x16e/0x210 kernel/locking/percpu-rwsem.c:85
percpu_down_read_preempt_disable include/linux/percpu-rwsem.h:49 [inline]
percpu_down_read include/linux/percpu-rwsem.h:59 [inline]
__sb_start_write+0x2d7/0x300 fs/super.c:1387
sb_start_write include/linux/fs.h:1566 [inline]
mnt_want_write+0x3f/0xc0 fs/namespace.c:360
filename_create+0x13e/0x5b0 fs/namei.c:3630
user_path_create fs/namei.c:3693 [inline]
do_symlinkat+0xfe/0x2d0 fs/namei.c:4147
__do_sys_symlink fs/namei.c:4173 [inline]
__se_sys_symlink fs/namei.c:4171 [inline]
__x64_sys_symlink+0x59/0x80 fs/namei.c:4171
do_syscall_64+0x1b9/0x820 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x456dc7
Code: 64 8b 5d 00 e9 14 fd ff ff 4c 8b 74 24 30 64 c7 45 00 22 00 00 00 bb
22 00 00 00 e9 fd fc ff ff 0f 1f 00 b8 58 00 00 00 0f 05 <48> 3d 01 f0 ff
ff 0f 83 9d b7 fb ff c3 66 2e 0f 1f 84 00 00 00 00
RSP: 002b:00007ffc4aa9e7e8 EFLAGS: 00000206 ORIG_RAX: 0000000000000058
RAX: ffffffffffffffda RBX: 0000000000000001 RCX: 0000000000456dc7
RDX: 00007ffc4aa9e837 RSI: 00000000004c2a24 RDI: 00007ffc4aa9e820
RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000017
R10: 0000000000000075 R11: 0000000000000206 R12: 0000000000000010
R13: 000000000004c06f R14: 000000000000005d R15: badc0ffeebadface

Showing all locks held in the system:
1 lock held by khungtaskd/792:
#0: 00000000dced5997 (rcu_read_lock){....}, at:
debug_show_all_locks+0xd0/0x428 kernel/locking/lockdep.c:4436
2 locks held by rs:main Q:Reg/4652:
#0: 00000000702af43c (&f->f_pos_lock){+.+.}, at: __fdget_pos+0x1bb/0x200
fs/file.c:766
#1: 0000000090b4249e (sb_writers#6){++++}, at: file_start_write
include/linux/fs.h:2758 [inline]
#1: 0000000090b4249e (sb_writers#6){++++}, at: vfs_write+0x42a/0x560
fs/read_write.c:548
1 lock held by rsyslogd/4654:
2 locks held by getty/4777:
#0: 000000007c53794b (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x37/0x40 drivers/tty/tty_ldsem.c:353
#1: 0000000015cefbdf (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x335/0x1ce0 drivers/tty/n_tty.c:2140
2 locks held by getty/4778:
#0: 0000000030642f27 (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x37/0x40 drivers/tty/tty_ldsem.c:353
#1: 0000000020600ca2 (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x335/0x1ce0 drivers/tty/n_tty.c:2140
2 locks held by getty/4779:
#0: 000000001e16b217 (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x37/0x40 drivers/tty/tty_ldsem.c:353
#1: 00000000a6c438d9 (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x335/0x1ce0 drivers/tty/n_tty.c:2140
2 locks held by getty/4780:
#0: 00000000c3213138 (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x37/0x40 drivers/tty/tty_ldsem.c:353
#1: 00000000f094c6bc (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x335/0x1ce0 drivers/tty/n_tty.c:2140
2 locks held by getty/4781:
#0: 000000009966848b (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x37/0x40 drivers/tty/tty_ldsem.c:353
#1: 00000000a88c15ad (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x335/0x1ce0 drivers/tty/n_tty.c:2140
2 locks held by getty/4782:
#0: 00000000ef5141f5 (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x37/0x40 drivers/tty/tty_ldsem.c:353
#1: 000000007084ba61 (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x335/0x1ce0 drivers/tty/n_tty.c:2140
2 locks held by getty/4783:
#0: 00000000d9d5d3f5 (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x37/0x40 drivers/tty/tty_ldsem.c:353
#1: 000000005513da84 (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x335/0x1ce0 drivers/tty/n_tty.c:2140
1 lock held by syz-executor5/4829:
#0: 0000000090b4249e (sb_writers#6){++++}, at: sb_start_write
include/linux/fs.h:1566 [inline]
#0: 0000000090b4249e (sb_writers#6){++++}, at: mnt_want_write+0x3f/0xc0
fs/namespace.c:360
1 lock held by syz-executor6/4831:
#0: 0000000090b4249e (sb_writers#6){++++}, at: sb_start_write
include/linux/fs.h:1566 [inline]
#0: 0000000090b4249e (sb_writers#6){++++}, at: mnt_want_write+0x3f/0xc0
fs/namespace.c:360
1 lock held by syz-executor2/4832:
#0: 0000000090b4249e (sb_writers#6){++++}, at: sb_start_write
include/linux/fs.h:1566 [inline]
#0: 0000000090b4249e (sb_writers#6){++++}, at: mnt_want_write+0x3f/0xc0
fs/namespace.c:360
1 lock held by syz-executor1/4833:
#0: 0000000090b4249e (sb_writers#6){++++}, at: sb_start_write
include/linux/fs.h:1566 [inline]
#0: 0000000090b4249e (sb_writers#6){++++}, at: mnt_want_write+0x3f/0xc0
fs/namespace.c:360
1 lock held by syz-executor3/4834:
#0: 0000000090b4249e (sb_writers#6){++++}, at: sb_start_write
include/linux/fs.h:1566 [inline]
#0: 0000000090b4249e (sb_writers#6){++++}, at: mnt_want_write+0x3f/0xc0
fs/namespace.c:360
1 lock held by syz-executor4/4835:
#0: 0000000090b4249e (sb_writers#6){++++}, at: sb_start_write
include/linux/fs.h:1566 [inline]
#0: 0000000090b4249e (sb_writers#6){++++}, at: mnt_want_write+0x3f/0xc0
fs/namespace.c:360
1 lock held by syz-executor3/8054:
#0: 0000000090b4249e (sb_writers#6){++++}, at: file_start_write
include/linux/fs.h:2758 [inline]
#0: 0000000090b4249e (sb_writers#6){++++}, at: do_sendfile+0xac0/0xe20
fs/read_write.c:1439
2 locks held by syz-executor7/11923:
#0: 0000000072a70d99 (&bdev->bd_fsfreeze_mutex){+.+.}, at:
freeze_bdev+0x2d/0x250 fs/block_dev.c:496
#1: 0000000090b4249e (sb_writers#6){++++}, at:
percpu_down_write+0xaf/0x540 kernel/locking/percpu-rwsem.c:145
1 lock held by syz-executor0/11936:
#0: 0000000090b4249e (sb_writers#6){++++}, at: sb_start_write
include/linux/fs.h:1566 [inline]
#0: 0000000090b4249e (sb_writers#6){++++}, at: mnt_want_write+0x3f/0xc0
fs/namespace.c:360

=============================================

NMI backtrace for cpu 0
CPU: 0 PID: 792 Comm: khungtaskd Not tainted 4.19.0-rc2+ #4
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x1c9/0x2b4 lib/dump_stack.c:113
nmi_cpu_backtrace.cold.3+0x48/0x88 lib/nmi_backtrace.c:101
nmi_trigger_cpumask_backtrace+0x151/0x192 lib/nmi_backtrace.c:62
arch_trigger_cpumask_backtrace+0x14/0x20 arch/x86/kernel/apic/hw_nmi.c:38
trigger_all_cpu_backtrace include/linux/nmi.h:144 [inline]
check_hung_uninterruptible_tasks kernel/hung_task.c:204 [inline]
watchdog+0xb39/0x1040 kernel/hung_task.c:265
kthread+0x35a/0x420 kernel/kthread.c:246
ret_from_fork+0x3a/0x50 arch/x86/entry/entry_64.S:413
Sending NMI from CPU 0 to CPUs 1:
NMI backtrace for cpu 1 skipped: idling at native_safe_halt+0x6/0x10
arch/x86/include/asm/irqflags.h:57


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#bug-status-tracking for how to communicate with
syzbot.

Dmitry Vyukov

unread,
Sep 17, 2018, 10:02:58 AM9/17/18
to Tetsuo Handa, syzbot+a434af...@syzkaller.appspotmail.com, syzkaller, 'Dmitry Vyukov' via syzkaller-upstream-moderation
This now should be fixed by:
https://github.com/google/syzkaller/commit/61ed43a86a3721708aeeee72b23bfa1eacd921b2

Thanks for debugging this!

#syz invalid



On Wed, Sep 12, 2018 at 12:14 PM, Tetsuo Handa
<penguin...@i-love.sakura.ne.jp> wrote:
> syzbot is hitting ext4_shutdown() case via ioctl(EXT4_IOC_SHUTDOWN).
> This case should be considered as a syzkaller bug.
>
>
> [ 311.546143] EXT4-fs (sda1): shut down requested (0)
> [ 474.527484] INFO: task syz-executor5:4829 blocked for more than 140 seconds.
>
> [ 1285.854659] EXT4-fs (sda1): shut down requested (0)
> [ 1434.857775] INFO: task rs:main Q:Reg:5210 blocked for more than 140 seconds.
>
> [ 1561.403456] EXT4-fs (sda1): shut down requested (0)
> [ 1721.686807] INFO: task rs:main Q:Reg:4185 blocked for more than 140 seconds.
>
> --
> You received this message because you are subscribed to the Google Groups "syzkaller" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to syzkaller+...@googlegroups.com.
> For more options, visit https://groups.google.com/d/optout.
Reply all
Reply to author
Forward
0 new messages