INFO: task hung in copy_process

42 views
Skip to first unread message

syzbot

unread,
Apr 10, 2019, 12:04:14 PM4/10/19
to syzkaller-a...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: b11964ad ANDROID: cuttlefish: enable CONFIG_INET_UDP_DIAG=y
git tree: android-4.14
console output: https://syzkaller.appspot.com/x/log.txt?x=1581ed9d200000
kernel config: https://syzkaller.appspot.com/x/.config?x=322dd7397c84f390
dashboard link: https://syzkaller.appspot.com/bug?extid=cb8ad9d508ea4878794d
compiler: gcc (GCC) 9.0.0 20181231 (experimental)

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+cb8ad9...@syzkaller.appspotmail.com

ip6_tunnel: ip6tnl6 xmit: Local address not yet configured!
INFO: task syz-executor.4:1865 blocked for more than 140 seconds.
Not tainted 4.14.105+ #29
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.4 D25160 1865 1850 0x00000000
Call Trace:
schedule+0x92/0x1c0 kernel/sched/core.c:3492
__rwsem_down_write_failed_common kernel/locking/rwsem-xadd.c:572 [inline]
rwsem_down_write_failed+0x3b1/0x760 kernel/locking/rwsem-xadd.c:601
call_rwsem_down_write_failed+0x13/0x20 arch/x86/lib/rwsem.S:105
__down_write arch/x86/include/asm/rwsem.h:126 [inline]
down_write+0x4f/0x90 kernel/locking/rwsem.c:56
i_mmap_lock_write include/linux/fs.h:470 [inline]
dup_mmap kernel/fork.c:684 [inline]
dup_mm kernel/fork.c:1202 [inline]
copy_mm kernel/fork.c:1256 [inline]
copy_process.part.0+0x3e67/0x6520 kernel/fork.c:1760
copy_process kernel/fork.c:1573 [inline]
_do_fork+0x193/0xcc0 kernel/fork.c:2063
do_syscall_64+0x19b/0x4b0 arch/x86/entry/common.c:289
INFO: task syz-executor.0:17901 blocked for more than 140 seconds.
Not tainted 4.14.105+ #29
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.0 D26904 17901 1852 0x80000002
Call Trace:
schedule+0x92/0x1c0 kernel/sched/core.c:3492
__rwsem_down_write_failed_common kernel/locking/rwsem-xadd.c:572 [inline]
rwsem_down_write_failed+0x3b1/0x760 kernel/locking/rwsem-xadd.c:601
call_rwsem_down_write_failed+0x13/0x20 arch/x86/lib/rwsem.S:105
__down_write arch/x86/include/asm/rwsem.h:126 [inline]
down_write+0x4f/0x90 kernel/locking/rwsem.c:56
i_mmap_lock_write include/linux/fs.h:470 [inline]
unlink_file_vma+0x6e/0xa0 mm/mmap.c:157
free_pgtables+0xb3/0x1c0 mm/memory.c:644
exit_mmap+0x222/0x440 mm/mmap.c:3068
__mmput kernel/fork.c:929 [inline]
mmput kernel/fork.c:950 [inline]
mmput+0xc8/0x350 kernel/fork.c:945
exit_mm kernel/exit.c:544 [inline]
do_exit+0x84e/0x2960 kernel/exit.c:860
INFO: task syz-executor.5:17947 blocked for more than 140 seconds.
Not tainted 4.14.105+ #29
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.5 D29184 17947 1861 0x80000000
Call Trace:
schedule+0x92/0x1c0 kernel/sched/core.c:3492
__rwsem_down_write_failed_common kernel/locking/rwsem-xadd.c:572 [inline]
rwsem_down_write_failed+0x3b1/0x760 kernel/locking/rwsem-xadd.c:601
call_rwsem_down_write_failed+0x13/0x20 arch/x86/lib/rwsem.S:105
__down_write arch/x86/include/asm/rwsem.h:126 [inline]
down_write+0x4f/0x90 kernel/locking/rwsem.c:56
i_mmap_lock_write include/linux/fs.h:470 [inline]
unlink_file_vma+0x6e/0xa0 mm/mmap.c:157
free_pgtables+0xb3/0x1c0 mm/memory.c:644
exit_mmap+0x222/0x440 mm/mmap.c:3068
__mmput kernel/fork.c:929 [inline]
mmput kernel/fork.c:950 [inline]
mmput+0xc8/0x350 kernel/fork.c:945
exit_mm kernel/exit.c:544 [inline]
do_exit+0x84e/0x2960 kernel/exit.c:860
INFO: task syz-executor.1:17917 blocked for more than 140 seconds.
Not tainted 4.14.105+ #29
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.1 D28832 17917 19780 0x00000004
Call Trace:
schedule+0x92/0x1c0 kernel/sched/core.c:3492
__rwsem_down_read_failed_common kernel/locking/rwsem-xadd.c:276 [inline]
rwsem_down_read_failed+0x21f/0x3c0 kernel/locking/rwsem-xadd.c:293
call_rwsem_down_read_failed+0x14/0x30 arch/x86/lib/rwsem.S:94
__down_read arch/x86/include/asm/rwsem.h:66 [inline]
down_read+0x45/0xa0 kernel/locking/rwsem.c:26
__do_page_fault+0x871/0xb80 arch/x86/mm/fault.c:1361
page_fault+0x42/0x50 arch/x86/entry/entry_64.S:1104
RIP: 268bd4:0x3e8
RSP: 268cf7:000000000073bf00 EFLAGS: 0073c900
INFO: task syz-executor.1:17925 blocked for more than 140 seconds.
Not tainted 4.14.105+ #29
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.1 D28072 17925 19780 0x00000004
Call Trace:
schedule+0x92/0x1c0 kernel/sched/core.c:3492
__rwsem_down_write_failed_common kernel/locking/rwsem-xadd.c:572 [inline]
rwsem_down_write_failed+0x3b1/0x760 kernel/locking/rwsem-xadd.c:601
call_rwsem_down_write_failed+0x13/0x20 arch/x86/lib/rwsem.S:105
__down_write arch/x86/include/asm/rwsem.h:126 [inline]
down_write+0x4f/0x90 kernel/locking/rwsem.c:56
i_mmap_lock_write include/linux/fs.h:470 [inline]
dup_mmap kernel/fork.c:684 [inline]
dup_mm kernel/fork.c:1202 [inline]
copy_mm kernel/fork.c:1256 [inline]
copy_process.part.0+0x3e67/0x6520 kernel/fork.c:1760
copy_process kernel/fork.c:1573 [inline]
_do_fork+0x193/0xcc0 kernel/fork.c:2063
do_syscall_64+0x19b/0x4b0 arch/x86/entry/common.c:289
INFO: task syz-executor.1:17934 blocked for more than 140 seconds.
Not tainted 4.14.105+ #29
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.1 D29312 17934 19780 0x80000004
Call Trace:
schedule+0x92/0x1c0 kernel/sched/core.c:3492
__rwsem_down_read_failed_common kernel/locking/rwsem-xadd.c:276 [inline]
rwsem_down_read_failed+0x21f/0x3c0 kernel/locking/rwsem-xadd.c:293
call_rwsem_down_read_failed+0x14/0x30 arch/x86/lib/rwsem.S:94
__down_read arch/x86/include/asm/rwsem.h:66 [inline]
down_read+0x45/0xa0 kernel/locking/rwsem.c:26
__do_page_fault+0x871/0xb80 arch/x86/mm/fault.c:1361
page_fault+0x22/0x50 arch/x86/entry/entry_64.S:1104
RIP: 0010:__put_user_4+0x19/0x20 arch/x86/lib/putuser.S:70
RSP: 0018:ffff8881382b7a70 EFLAGS: 00010293
RAX: 0000000000000000 RBX: 00007fffffffeffd RCX: 00007f990c8449d0
RDX: 1ffff11033e41699 RSI: 0000000000000001 RDI: 00007f990c8449d0
RBP: ffff88819f20af00 R08: 0000000000000001 R09: 0000000000000000
R10: ffff88819f20b730 R11: 0000000000000001 R12: ffff88819f20b4c8
R13: ffff88819d1dba80 R14: ffff8881382b7f58 R15: ffff8881382b7f58
mm_release+0x2ac/0x3f0 kernel/fork.c:1169
exit_mm kernel/exit.c:499 [inline]
do_exit+0x4de/0x2960 kernel/exit.c:860
INFO: task syz-executor.1:17938 blocked for more than 140 seconds.
Not tainted 4.14.105+ #29
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.1 D29312 17938 19780 0x80000004
Call Trace:
schedule+0x92/0x1c0 kernel/sched/core.c:3492
__rwsem_down_read_failed_common kernel/locking/rwsem-xadd.c:276 [inline]
rwsem_down_read_failed+0x21f/0x3c0 kernel/locking/rwsem-xadd.c:293
call_rwsem_down_read_failed+0x14/0x30 arch/x86/lib/rwsem.S:94
__down_read arch/x86/include/asm/rwsem.h:66 [inline]
down_read+0x45/0xa0 kernel/locking/rwsem.c:26
__do_page_fault+0x871/0xb80 arch/x86/mm/fault.c:1361
page_fault+0x22/0x50 arch/x86/entry/entry_64.S:1104
RIP: 0010:__put_user_4+0x19/0x20 arch/x86/lib/putuser.S:70
RSP: 0018:ffff88818ce1fa70 EFLAGS: 00010293
RAX: 0000000000000000 RBX: 00007fffffffeffd RCX: 00007f990c8239d0
RDX: 1ffff1103057d3a9 RSI: 0000000000000001 RDI: 00007f990c8239d0
RBP: ffff888182be9780 R08: 0000000000000001 R09: 0000000000000000
R10: ffff888182be9fb0 R11: 0000000000000001 R12: ffff888182be9d48
R13: ffff88819d1dba80 R14: ffff88818ce1ff58 R15: ffff88818ce1ff58
mm_release+0x2ac/0x3f0 kernel/fork.c:1169
exit_mm kernel/exit.c:499 [inline]
do_exit+0x4de/0x2960 kernel/exit.c:860
INFO: task syz-executor.3:17949 blocked for more than 140 seconds.
Not tainted 4.14.105+ #29
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.3 D27848 17949 3402 0x80000000
Call Trace:
schedule+0x92/0x1c0 kernel/sched/core.c:3492
__rwsem_down_write_failed_common kernel/locking/rwsem-xadd.c:572 [inline]
rwsem_down_write_failed+0x3b1/0x760 kernel/locking/rwsem-xadd.c:601
call_rwsem_down_write_failed+0x13/0x20 arch/x86/lib/rwsem.S:105
__down_write arch/x86/include/asm/rwsem.h:126 [inline]
down_write+0x4f/0x90 kernel/locking/rwsem.c:56
i_mmap_lock_write include/linux/fs.h:470 [inline]
unlink_file_vma+0x6e/0xa0 mm/mmap.c:157
free_pgtables+0xb3/0x1c0 mm/memory.c:644
exit_mmap+0x222/0x440 mm/mmap.c:3068
__mmput kernel/fork.c:929 [inline]
mmput kernel/fork.c:950 [inline]
mmput+0xc8/0x350 kernel/fork.c:945
exit_mm kernel/exit.c:544 [inline]
do_exit+0x84e/0x2960 kernel/exit.c:860
INFO: task syz-executor.2:17969 blocked for more than 140 seconds.
Not tainted 4.14.105+ #29
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.2 D29112 17969 1853 0x80000000
Call Trace:
schedule+0x92/0x1c0 kernel/sched/core.c:3492
__rwsem_down_write_failed_common kernel/locking/rwsem-xadd.c:572 [inline]
rwsem_down_write_failed+0x3b1/0x760 kernel/locking/rwsem-xadd.c:601
call_rwsem_down_write_failed+0x13/0x20 arch/x86/lib/rwsem.S:105
__down_write arch/x86/include/asm/rwsem.h:126 [inline]
down_write+0x4f/0x90 kernel/locking/rwsem.c:56
i_mmap_lock_write include/linux/fs.h:470 [inline]
unlink_file_vma+0x6e/0xa0 mm/mmap.c:157
free_pgtables+0xb3/0x1c0 mm/memory.c:644
exit_mmap+0x222/0x440 mm/mmap.c:3068
__mmput kernel/fork.c:929 [inline]
mmput kernel/fork.c:950 [inline]
mmput+0xc8/0x350 kernel/fork.c:945
exit_mm kernel/exit.c:544 [inline]
do_exit+0x84e/0x2960 kernel/exit.c:860
INFO: task syz-executor.1:17939 blocked for more than 140 seconds.
Not tainted 4.14.105+ #29
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.1 D27848 17939 17921 0x80000004
Call Trace:
schedule+0x92/0x1c0 kernel/sched/core.c:3492
__rwsem_down_write_failed_common kernel/locking/rwsem-xadd.c:572 [inline]
rwsem_down_write_failed+0x3b1/0x760 kernel/locking/rwsem-xadd.c:601
call_rwsem_down_write_failed+0x13/0x20 arch/x86/lib/rwsem.S:105
__down_write arch/x86/include/asm/rwsem.h:126 [inline]
down_write+0x4f/0x90 kernel/locking/rwsem.c:56
i_mmap_lock_write include/linux/fs.h:470 [inline]
unlink_file_vma+0x6e/0xa0 mm/mmap.c:157
free_pgtables+0xb3/0x1c0 mm/memory.c:644
exit_mmap+0x222/0x440 mm/mmap.c:3068
__mmput kernel/fork.c:929 [inline]
mmput kernel/fork.c:950 [inline]
mmput+0xc8/0x350 kernel/fork.c:945
exit_mm kernel/exit.c:544 [inline]
do_exit+0x84e/0x2960 kernel/exit.c:860

Showing all locks held in the system:
1 lock held by khungtaskd/23:
#0: (tasklist_lock){.+.+}, at: [<ffffffff81600e0c>]
debug_show_all_locks+0x7c/0x21a kernel/locking/lockdep.c:4541
2 locks held by getty/1765:
#0: (&tty->ldisc_sem){++++}, at: [<ffffffff82138782>]
tty_ldisc_ref_wait+0x22/0x80 drivers/tty/tty_ldisc.c:275
#1: (&ldata->atomic_read_lock){+.+.}, at: [<ffffffff82133ba7>]
n_tty_read+0x1f7/0x1700 drivers/tty/n_tty.c:2156
1 lock held by syz-executor.0/1846:
#0: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff818dae7e>]
i_mmap_lock_write include/linux/fs.h:470 [inline]
#0: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff818dae7e>]
unlink_file_vma+0x6e/0xa0 mm/mmap.c:157
1 lock held by syz-executor.5/1847:
#0: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff818dae7e>]
i_mmap_lock_write include/linux/fs.h:470 [inline]
#0: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff818dae7e>]
unlink_file_vma+0x6e/0xa0 mm/mmap.c:157
1 lock held by syz-executor.2/1848:
#0: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff818dae7e>]
i_mmap_lock_write include/linux/fs.h:470 [inline]
#0: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff818dae7e>]
unlink_file_vma+0x6e/0xa0 mm/mmap.c:157
1 lock held by syz-executor.4/1850:
#0: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff818dae7e>]
i_mmap_lock_write include/linux/fs.h:470 [inline]
#0: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff818dae7e>]
unlink_file_vma+0x6e/0xa0 mm/mmap.c:157
4 locks held by syz-executor.4/1865:
#0: (&dup_mmap_sem){.+.+}, at: [<ffffffff814d0dd7>] dup_mmap
kernel/fork.c:609 [inline]
#0: (&dup_mmap_sem){.+.+}, at: [<ffffffff814d0dd7>] dup_mm
kernel/fork.c:1202 [inline]
#0: (&dup_mmap_sem){.+.+}, at: [<ffffffff814d0dd7>] copy_mm
kernel/fork.c:1256 [inline]
#0: (&dup_mmap_sem){.+.+}, at: [<ffffffff814d0dd7>]
copy_process.part.0+0x3997/0x6520 kernel/fork.c:1760
#1: (&mm->mmap_sem){++++}, at: [<ffffffff814d0df3>] dup_mmap
kernel/fork.c:610 [inline]
#1: (&mm->mmap_sem){++++}, at: [<ffffffff814d0df3>] dup_mm
kernel/fork.c:1202 [inline]
#1: (&mm->mmap_sem){++++}, at: [<ffffffff814d0df3>] copy_mm
kernel/fork.c:1256 [inline]
#1: (&mm->mmap_sem){++++}, at: [<ffffffff814d0df3>]
copy_process.part.0+0x39b3/0x6520 kernel/fork.c:1760
#2: (&mm->mmap_sem/1){+.+.}, at: [<ffffffff814d0e3b>] dup_mmap
kernel/fork.c:619 [inline]
#2: (&mm->mmap_sem/1){+.+.}, at: [<ffffffff814d0e3b>] dup_mm
kernel/fork.c:1202 [inline]
#2: (&mm->mmap_sem/1){+.+.}, at: [<ffffffff814d0e3b>] copy_mm
kernel/fork.c:1256 [inline]
#2: (&mm->mmap_sem/1){+.+.}, at: [<ffffffff814d0e3b>]
copy_process.part.0+0x39fb/0x6520 kernel/fork.c:1760
#3: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff814d12a7>]
i_mmap_lock_write include/linux/fs.h:470 [inline]
#3: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff814d12a7>] dup_mmap
kernel/fork.c:684 [inline]
#3: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff814d12a7>] dup_mm
kernel/fork.c:1202 [inline]
#3: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff814d12a7>] copy_mm
kernel/fork.c:1256 [inline]
#3: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff814d12a7>]
copy_process.part.0+0x3e67/0x6520 kernel/fork.c:1760
1 lock held by syz-executor.3/3401:
#0: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff818dae7e>]
i_mmap_lock_write include/linux/fs.h:470 [inline]
#0: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff818dae7e>]
unlink_file_vma+0x6e/0xa0 mm/mmap.c:157
1 lock held by syz-executor.1/19775:
#0: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff818dae7e>]
i_mmap_lock_write include/linux/fs.h:470 [inline]
#0: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff818dae7e>]
unlink_file_vma+0x6e/0xa0 mm/mmap.c:157
1 lock held by syz-executor.0/17901:
#0: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff818dae7e>]
i_mmap_lock_write include/linux/fs.h:470 [inline]
#0: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff818dae7e>]
unlink_file_vma+0x6e/0xa0 mm/mmap.c:157
1 lock held by syz-executor.5/17947:
#0: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff818dae7e>]
i_mmap_lock_write include/linux/fs.h:470 [inline]
#0: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff818dae7e>]
unlink_file_vma+0x6e/0xa0 mm/mmap.c:157
1 lock held by syz-executor.1/17917:
#0: (&mm->mmap_sem){++++}, at: [<ffffffff814b4c71>]
__do_page_fault+0x871/0xb80 arch/x86/mm/fault.c:1361
4 locks held by syz-executor.1/17925:
#0: (&dup_mmap_sem){.+.+}, at: [<ffffffff814d0dd7>] dup_mmap
kernel/fork.c:609 [inline]
#0: (&dup_mmap_sem){.+.+}, at: [<ffffffff814d0dd7>] dup_mm
kernel/fork.c:1202 [inline]
#0: (&dup_mmap_sem){.+.+}, at: [<ffffffff814d0dd7>] copy_mm
kernel/fork.c:1256 [inline]
#0: (&dup_mmap_sem){.+.+}, at: [<ffffffff814d0dd7>]
copy_process.part.0+0x3997/0x6520 kernel/fork.c:1760
#1: (&mm->mmap_sem){++++}, at: [<ffffffff814d0df3>] dup_mmap
kernel/fork.c:610 [inline]
#1: (&mm->mmap_sem){++++}, at: [<ffffffff814d0df3>] dup_mm
kernel/fork.c:1202 [inline]
#1: (&mm->mmap_sem){++++}, at: [<ffffffff814d0df3>] copy_mm
kernel/fork.c:1256 [inline]
#1: (&mm->mmap_sem){++++}, at: [<ffffffff814d0df3>]
copy_process.part.0+0x39b3/0x6520 kernel/fork.c:1760
#2: (&mm->mmap_sem/1){+.+.}, at: [<ffffffff814d0e3b>] dup_mmap
kernel/fork.c:619 [inline]
#2: (&mm->mmap_sem/1){+.+.}, at: [<ffffffff814d0e3b>] dup_mm
kernel/fork.c:1202 [inline]
#2: (&mm->mmap_sem/1){+.+.}, at: [<ffffffff814d0e3b>] copy_mm
kernel/fork.c:1256 [inline]
#2: (&mm->mmap_sem/1){+.+.}, at: [<ffffffff814d0e3b>]
copy_process.part.0+0x39fb/0x6520 kernel/fork.c:1760
#3: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff814d12a7>]
i_mmap_lock_write include/linux/fs.h:470 [inline]
#3: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff814d12a7>] dup_mmap
kernel/fork.c:684 [inline]
#3: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff814d12a7>] dup_mm
kernel/fork.c:1202 [inline]
#3: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff814d12a7>] copy_mm
kernel/fork.c:1256 [inline]
#3: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff814d12a7>]
copy_process.part.0+0x3e67/0x6520 kernel/fork.c:1760
1 lock held by syz-executor.1/17934:
#0: (&mm->mmap_sem){++++}, at: [<ffffffff814b4c71>]
__do_page_fault+0x871/0xb80 arch/x86/mm/fault.c:1361
1 lock held by syz-executor.1/17938:
#0: (&mm->mmap_sem){++++}, at: [<ffffffff814b4c71>]
__do_page_fault+0x871/0xb80 arch/x86/mm/fault.c:1361
1 lock held by syz-executor.3/17949:
#0: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff818dae7e>]
i_mmap_lock_write include/linux/fs.h:470 [inline]
#0: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff818dae7e>]
unlink_file_vma+0x6e/0xa0 mm/mmap.c:157
1 lock held by syz-executor.2/17969:
#0: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff818dae7e>]
i_mmap_lock_write include/linux/fs.h:470 [inline]
#0: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff818dae7e>]
unlink_file_vma+0x6e/0xa0 mm/mmap.c:157
1 lock held by syz-executor.1/17939:
#0: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff818dae7e>]
i_mmap_lock_write include/linux/fs.h:470 [inline]
#0: (&mapping->i_mmap_rwsem){++++}, at: [<ffffffff818dae7e>]
unlink_file_vma+0x6e/0xa0 mm/mmap.c:157
1 lock held by syz-executor.1/17942:
#0: (&mm->mmap_sem){++++}, at: [<ffffffff814b4c71>]
__do_page_fault+0x871/0xb80 arch/x86/mm/fault.c:1361

=============================================

NMI backtrace for cpu 0
CPU: 0 PID: 23 Comm: khungtaskd Not tainted 4.14.105+ #29
Call Trace:
__dump_stack lib/dump_stack.c:17 [inline]
dump_stack+0xb9/0x10e lib/dump_stack.c:53
nmi_cpu_backtrace.cold+0x47/0x86 lib/nmi_backtrace.c:101
Sending NMI from CPU 0 to CPUs 1:
NMI backtrace for cpu 1
CPU: 1 PID: 1861 Comm: syz-executor.5 Not tainted 4.14.105+ #29
task: ffff8881d110c680 task.stack: ffff8881a2ec0000
RIP: 0010:__read_once_size include/linux/compiler.h:183 [inline]
RIP: 0010:atomic_read arch/x86/include/asm/atomic.h:27 [inline]
RIP: 0010:rcu_dynticks_curr_cpu_in_eqs kernel/rcu/tree.c:362 [inline]
RIP: 0010:rcu_is_watching+0x4b/0xb0 kernel/rcu/tree.c:1130
RSP: 0018:ffff8881a2ec79b0 EFLAGS: 00000086
RAX: dffffc0000000000 RBX: ffff8881dbb227c0 RCX: 1ffffffff06d8485
RDX: dffffc0000000000 RSI: ffffffff83350000 RDI: ffffffff836c2428
RBP: ffffffff84e370d0 R08: 0000000000000000 R09: 00000000000a0025
R10: ffff8881d110cf00 R11: 0000000000000001 R12: 0000000000000206
R13: 00000000000000fa R14: 0000000000000001 R15: dffffc0000000000
FS: 0000000000e23940(0000) GS:ffff8881dbb00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00000000007101b4 CR3: 00000001a2eb2002 CR4: 00000000001606a0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000600
Call Trace:
rcu_read_lock include/linux/rcupdate.h:632 [inline]
avc_reclaim_node security/selinux/avc.c:527 [inline]
avc_alloc_node security/selinux/avc.c:557 [inline]
avc_alloc_node+0x29c/0x3c0 security/selinux/avc.c:545
avc_insert security/selinux/avc.c:668 [inline]
avc_compute_av+0x17c/0x550 security/selinux/avc.c:974
Code: ff df 89 c0 48 8d 3c c5 20 24 6c 83 48 89 f9 48 c1 e9 03 80 3c 11 00
75 5b 48 03 1c c5 20 24 6c 83 48 b8 00 00 00 00 00 fc ff df <48> 8d 7b 0c
48 89 fa 48 c1 ea 03 0f b6 14 02 48 89 f8 83 e0 07


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Apr 10, 2019, 12:04:16 PM4/10/19
to syzkaller-a...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 5f5c1657 UPSTREAM: virt_wifi: Remove REGULATORY_WIPHY_SELF..
git tree: android-4.9
console output: https://syzkaller.appspot.com/x/log.txt?x=12a42b7d200000
kernel config: https://syzkaller.appspot.com/x/.config?x=a99a3470ebe9a85e
dashboard link: https://syzkaller.appspot.com/bug?extid=a705275d3dd63281e152
compiler: gcc (GCC) 9.0.0 20181231 (experimental)

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+a70527...@syzkaller.appspotmail.com

INFO: task syz-executor.2:7231 blocked for more than 140 seconds.
Not tainted 4.9.166+ #35
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor.2 D25016 7231 7230 0x00000000
ffff8801c81dc740 ffff880181c58000 ffff8801db721000 ffff880187eeaf80
ffff8801db721018 ffff8801c60a79d0 ffffffff827ffaae ffffffff8280b035
ffff8801c395b8c8 00ff8801c60a7920 ffff8801db7218f0 1ffff10038c14f29
Call Trace:
[<00000000171555ca>] schedule+0x92/0x1c0 kernel/sched/core.c:3546
[<000000009857de2d>] __rwsem_down_write_failed_common
kernel/locking/rwsem-xadd.c:533 [inline]
[<000000009857de2d>] rwsem_down_write_failed+0x3a3/0x750
kernel/locking/rwsem-xadd.c:562
[<00000000eac00a9c>] call_rwsem_down_write_failed+0x17/0x30
arch/x86/lib/rwsem.S:105
[<000000006175c8dd>] __down_write arch/x86/include/asm/rwsem.h:125 [inline]
[<000000006175c8dd>] down_write+0x5c/0xa0 kernel/locking/rwsem.c:54
[<00000000a2f396a8>] i_mmap_lock_write include/linux/fs.h:526 [inline]
[<00000000a2f396a8>] dup_mmap kernel/fork.c:642 [inline]
[<00000000a2f396a8>] dup_mm kernel/fork.c:1156 [inline]
[<00000000a2f396a8>] copy_mm kernel/fork.c:1210 [inline]
[<00000000a2f396a8>] copy_process.part.0+0x3ec7/0x63f0 kernel/fork.c:1694
[<00000000451f64c8>] copy_process kernel/fork.c:1505 [inline]
[<00000000451f64c8>] _do_fork+0x1b8/0xd40 kernel/fork.c:1985
[<00000000e5bb3f83>] SYSC_clone kernel/fork.c:2097 [inline]
[<00000000e5bb3f83>] SyS_clone+0x37/0x50 kernel/fork.c:2091
[<000000007f8b2102>] do_syscall_64+0x1ad/0x570 arch/x86/entry/common.c:285
[<000000002f798948>] entry_SYSCALL_64_after_swapgs+0x5d/0xdb

Showing all locks held in the system:
2 locks held by khungtaskd/24:
#0: (rcu_read_lock){......}, at: [<00000000f984ae0f>]
check_hung_uninterruptible_tasks kernel/hung_task.c:168 [inline]
#0: (rcu_read_lock){......}, at: [<00000000f984ae0f>]
watchdog+0x13c/0xae0 kernel/hung_task.c:239
#1: (tasklist_lock){.+.?..}, at: [<00000000e55fd9be>]
debug_show_all_locks+0x7f/0x21f kernel/locking/lockdep.c:4339
2 locks held by getty/2038:
#0: (&tty->ldisc_sem){++++++}, at: [<00000000ecb11793>]
ldsem_down_read+0x33/0x40 drivers/tty/tty_ldsem.c:377
#1: (&ldata->atomic_read_lock){+.+...}, at: [<00000000af22a496>]
n_tty_read+0x1fe/0x1820 drivers/tty/n_tty.c:2156
1 lock held by syz-executor.1/2120:
#0: (&mapping->i_mmap_rwsem){++++..}, at: [<0000000058d0d7fc>]
i_mmap_lock_write include/linux/fs.h:526 [inline]
#0: (&mapping->i_mmap_rwsem){++++..}, at: [<0000000058d0d7fc>]
unlink_file_vma+0x75/0xb0 mm/mmap.c:156
1 lock held by syz-executor.0/2121:
#0: (&mapping->i_mmap_rwsem){++++..}, at: [<0000000058d0d7fc>]
i_mmap_lock_write include/linux/fs.h:526 [inline]
#0: (&mapping->i_mmap_rwsem){++++..}, at: [<0000000058d0d7fc>]
unlink_file_vma+0x75/0xb0 mm/mmap.c:156
1 lock held by syz-executor.5/2123:
#0: (&mapping->i_mmap_rwsem){++++..}, at: [<0000000058d0d7fc>]
i_mmap_lock_write include/linux/fs.h:526 [inline]
#0: (&mapping->i_mmap_rwsem){++++..}, at: [<0000000058d0d7fc>]
unlink_file_vma+0x75/0xb0 mm/mmap.c:156
1 lock held by syz-executor.4/4758:
#0: (&mapping->i_mmap_rwsem){++++..}, at: [<0000000058d0d7fc>]
i_mmap_lock_write include/linux/fs.h:526 [inline]
#0: (&mapping->i_mmap_rwsem){++++..}, at: [<0000000058d0d7fc>]
unlink_file_vma+0x75/0xb0 mm/mmap.c:156
1 lock held by syz-executor.2/7230:
#0: (&mapping->i_mmap_rwsem){++++..}, at: [<0000000058d0d7fc>]
i_mmap_lock_write include/linux/fs.h:526 [inline]
#0: (&mapping->i_mmap_rwsem){++++..}, at: [<0000000058d0d7fc>]
unlink_file_vma+0x75/0xb0 mm/mmap.c:156
4 locks held by syz-executor.2/7231:
#0: (&dup_mmap_sem){.+.+.+}, at: [<00000000af03a212>] dup_mmap
kernel/fork.c:573 [inline]
#0: (&dup_mmap_sem){.+.+.+}, at: [<00000000af03a212>] dup_mm
kernel/fork.c:1156 [inline]
#0: (&dup_mmap_sem){.+.+.+}, at: [<00000000af03a212>] copy_mm
kernel/fork.c:1210 [inline]
#0: (&dup_mmap_sem){.+.+.+}, at: [<00000000af03a212>]
copy_process.part.0+0x38ca/0x63f0 kernel/fork.c:1694
#1: (&mm->mmap_sem){++++++}, at: [<00000000b4123854>] dup_mmap
kernel/fork.c:574 [inline]
#1: (&mm->mmap_sem){++++++}, at: [<00000000b4123854>] dup_mm
kernel/fork.c:1156 [inline]
#1: (&mm->mmap_sem){++++++}, at: [<00000000b4123854>] copy_mm
kernel/fork.c:1210 [inline]
#1: (&mm->mmap_sem){++++++}, at: [<00000000b4123854>]
copy_process.part.0+0x38e5/0x63f0 kernel/fork.c:1694
#2: (&mm->mmap_sem/1){+.+.+.}, at: [<000000009d52ceda>] dup_mmap
kernel/fork.c:583 [inline]
#2: (&mm->mmap_sem/1){+.+.+.}, at: [<000000009d52ceda>] dup_mm
kernel/fork.c:1156 [inline]
#2: (&mm->mmap_sem/1){+.+.+.}, at: [<000000009d52ceda>] copy_mm
kernel/fork.c:1210 [inline]
#2: (&mm->mmap_sem/1){+.+.+.}, at: [<000000009d52ceda>]
copy_process.part.0+0x391e/0x63f0 kernel/fork.c:1694
#3: (&mapping->i_mmap_rwsem){++++..}, at: [<00000000a2f396a8>]
i_mmap_lock_write include/linux/fs.h:526 [inline]
#3: (&mapping->i_mmap_rwsem){++++..}, at: [<00000000a2f396a8>] dup_mmap
kernel/fork.c:642 [inline]
#3: (&mapping->i_mmap_rwsem){++++..}, at: [<00000000a2f396a8>] dup_mm
kernel/fork.c:1156 [inline]
#3: (&mapping->i_mmap_rwsem){++++..}, at: [<00000000a2f396a8>] copy_mm
kernel/fork.c:1210 [inline]
#3: (&mapping->i_mmap_rwsem){++++..}, at: [<00000000a2f396a8>]
copy_process.part.0+0x3ec7/0x63f0 kernel/fork.c:1694
1 lock held by syz-executor.3/20330:
#0: (&mapping->i_mmap_rwsem){++++..}, at: [<0000000058d0d7fc>]
i_mmap_lock_write include/linux/fs.h:526 [inline]
#0: (&mapping->i_mmap_rwsem){++++..}, at: [<0000000058d0d7fc>]
unlink_file_vma+0x75/0xb0 mm/mmap.c:156
1 lock held by syz-executor.3/11937:
#0: (&sig->cred_guard_mutex){+.+.+.}, at: [<000000005b5fa8b5>]
prepare_bprm_creds+0x55/0x120 fs/exec.c:1369
1 lock held by syz-executor.0/5674:
#0: (&mapping->i_mmap_rwsem){++++..}, at: [<0000000058d0d7fc>]
i_mmap_lock_write include/linux/fs.h:526 [inline]
#0: (&mapping->i_mmap_rwsem){++++..}, at: [<0000000058d0d7fc>]
unlink_file_vma+0x75/0xb0 mm/mmap.c:156
1 lock held by syz-executor.5/5678:
#0: (&mapping->i_mmap_rwsem){++++..}, at: [<0000000058d0d7fc>]
i_mmap_lock_write include/linux/fs.h:526 [inline]
#0: (&mapping->i_mmap_rwsem){++++..}, at: [<0000000058d0d7fc>]
unlink_file_vma+0x75/0xb0 mm/mmap.c:156
1 lock held by syz-executor.3/5675:
#0: (&mapping->i_mmap_rwsem){++++..}, at: [<0000000058d0d7fc>]
i_mmap_lock_write include/linux/fs.h:526 [inline]
#0: (&mapping->i_mmap_rwsem){++++..}, at: [<0000000058d0d7fc>]
unlink_file_vma+0x75/0xb0 mm/mmap.c:156
1 lock held by syz-executor.4/5668:
#0: (&mapping->i_mmap_rwsem){++++..}, at: [<0000000058d0d7fc>]
i_mmap_lock_write include/linux/fs.h:526 [inline]
#0: (&mapping->i_mmap_rwsem){++++..}, at: [<0000000058d0d7fc>]
unlink_file_vma+0x75/0xb0 mm/mmap.c:156
1 lock held by syz-executor.1/5667:
#0: (&mapping->i_mmap_rwsem){++++..}, at: [<0000000058d0d7fc>]
i_mmap_lock_write include/linux/fs.h:526 [inline]
#0: (&mapping->i_mmap_rwsem){++++..}, at: [<0000000058d0d7fc>]
unlink_file_vma+0x75/0xb0 mm/mmap.c:156

=============================================

NMI backtrace for cpu 1
CPU: 1 PID: 24 Comm: khungtaskd Not tainted 4.9.166+ #35
ffff8801d98d7cc8 ffffffff81b4ef81 0000000000000001 0000000000000000
0000000000000001 ffffffff81097401 dffffc0000000000 ffff8801d98d7d00
ffffffff81b5a23c 0000000000000001 0000000000000000 0000000000000001
Call Trace:
[<00000000b15cc3ad>] __dump_stack lib/dump_stack.c:15 [inline]
[<00000000b15cc3ad>] dump_stack+0xc1/0x120 lib/dump_stack.c:51
[<0000000046e06a05>] nmi_cpu_backtrace.cold+0x47/0x87
lib/nmi_backtrace.c:99
[<00000000e498cf0f>] nmi_trigger_cpumask_backtrace+0x124/0x155
lib/nmi_backtrace.c:60
[<000000004bdf6aca>] arch_trigger_cpumask_backtrace+0x14/0x20
arch/x86/kernel/apic/hw_nmi.c:37
[<0000000005f1b853>] trigger_all_cpu_backtrace include/linux/nmi.h:58
[inline]
[<0000000005f1b853>] check_hung_task kernel/hung_task.c:125 [inline]
[<0000000005f1b853>] check_hung_uninterruptible_tasks
kernel/hung_task.c:182 [inline]
[<0000000005f1b853>] watchdog+0x661/0xae0 kernel/hung_task.c:239
[<0000000012c22232>] kthread+0x278/0x310 kernel/kthread.c:211
[<0000000064e9ca50>] ret_from_fork+0x5c/0x70 arch/x86/entry/entry_64.S:373
Sending NMI from CPU 1 to CPUs 0:
NMI backtrace for cpu 0
CPU: 0 PID: 27260 Comm: syz-executor.2 Not tainted 4.9.166+ #35
task: 0000000087141d6c task.stack: 0000000024e50e03
RIP: 0033:[<0000000000401584>] c [<0000000064184ec5>] 0x401584
RSP: 002b:00007f4104bdc690 EFLAGS: 00000282
RAX: 00000000c4caa668 RBX: 000000000000000b RCX: 00000000004582b9
RDX: b700000001000000 RSI: 00007f4104bdc6c0 RDI: 000000000000000b
RBP: 0000000000000000 R08: 91726972ae636573 R09: 0000000000000000
R10: 5400007974dd0836 R11: 0000000000000246 R12: 0000000000000000
R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000
FS: 00007f4104bdd700(0000) GS:ffff8801db600000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f999cfe3000 CR3: 0000000195f6f000 CR4: 00000000001606b0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000600

syzbot

unread,
Sep 30, 2019, 1:31:04 AM9/30/19
to syzkaller-a...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.

syzbot

unread,
Oct 25, 2019, 9:42:06 AM10/25/19
to syzkaller-a...@googlegroups.com
Reply all
Reply to author
Forward
0 new messages