INFO: rcu detected stall in do_idle (2)

13 views
Skip to first unread message

syzbot

unread,
Apr 22, 2022, 6:09:21 AM4/22/22
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 15a1c6b6f516 Linux 4.14.276
git tree: linux-4.14.y
console output: https://syzkaller.appspot.com/x/log.txt?x=10ddd01cf00000
kernel config: https://syzkaller.appspot.com/x/.config?x=3ec12c117082c76f
dashboard link: https://syzkaller.appspot.com/bug?extid=8368796deb9660660296
compiler: gcc version 10.2.1 20210110 (Debian 10.2.1-6)
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1478282cf00000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+836879...@syzkaller.appspotmail.com

clocksource: 'kvm-clock' wd_now: 520582187b wd_last: 51e7b4b602 mask: ffffffffffffffff
clocksource: 'tsc' cs_now: 1a9e83f2 cs_last: b405b561fe mask: ffffffffffffffff
tsc: Marking TSC unstable due to clocksource watchdog
[Firmware Bug]: TSC ADJUST differs: CPU0 0 --> -773843399604. Restoring
INFO: rcu_preempt self-detected stall on CPU
0-...: (1 ticks this GP) idle=c7e/140000000000001/0 softirq=8617/8617 fqs=0
(t=35175 jiffies g=1083 c=1082 q=32)
rcu_preempt kthread starved for 35175 jiffies! g1083 c1082 f0x0 RCU_GP_WAIT_FQS(3) ->state=0x402 ->cpu=0
rcu_preempt I30008 8 2 0x80000000
Call Trace:
context_switch kernel/sched/core.c:2811 [inline]
__schedule+0x88b/0x1de0 kernel/sched/core.c:3387
schedule+0x8d/0x1b0 kernel/sched/core.c:3431
schedule_timeout+0x4af/0xe90 kernel/time/timer.c:1747
rcu_gp_kthread+0xc0a/0x1e60 kernel/rcu/tree.c:2255
kthread+0x30d/0x420 kernel/kthread.c:232
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:404
NMI backtrace for cpu 0
CPU: 0 PID: 0 Comm: swapper/0 Not tainted 4.14.276-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
<IRQ>
__dump_stack lib/dump_stack.c:17 [inline]
dump_stack+0x1b2/0x281 lib/dump_stack.c:58
nmi_cpu_backtrace.cold+0x57/0x93 lib/nmi_backtrace.c:101
nmi_trigger_cpumask_backtrace+0x13a/0x180 lib/nmi_backtrace.c:62
trigger_single_cpu_backtrace include/linux/nmi.h:158 [inline]
rcu_dump_cpu_stacks+0x15f/0x19c kernel/rcu/tree.c:1396
print_cpu_stall kernel/rcu/tree.c:1542 [inline]
check_cpu_stall kernel/rcu/tree.c:1610 [inline]
__rcu_pending kernel/rcu/tree.c:3390 [inline]
rcu_pending kernel/rcu/tree.c:3452 [inline]
rcu_check_callbacks.cold+0x464/0xd8d kernel/rcu/tree.c:2792
update_process_times+0x29/0x60 kernel/time/timer.c:1591
tick_sched_handle+0x7d/0x150 kernel/time/tick-sched.c:165
tick_sched_timer+0x92/0x200 kernel/time/tick-sched.c:1223
__run_hrtimer kernel/time/hrtimer.c:1223 [inline]
__hrtimer_run_queues+0x30b/0xc80 kernel/time/hrtimer.c:1287
hrtimer_interrupt+0x1e6/0x5e0 kernel/time/hrtimer.c:1321
local_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1079 [inline]
smp_apic_timer_interrupt+0x117/0x5e0 arch/x86/kernel/apic/apic.c:1104
apic_timer_interrupt+0x93/0xa0 arch/x86/entry/entry_64.S:793
</IRQ>
RIP: 0010:cpuidle_idle_call kernel/sched/idle.c:145 [inline]
RIP: 0010:do_idle+0x2a8/0x3c0 kernel/sched/idle.c:246
RSP: 0018:ffffffff88e07ea8 EFLAGS: 00000282 ORIG_RAX: ffffffffffffff10
RAX: 1ffffffff11e1313 RBX: dffffc0000000000 RCX: 0000000000000000
RDX: 0000000000000000 RSI: 0000000000000001 RDI: ffffffff88e74d04
RBP: ffffffff88f09890 R08: 0000000000000047 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: fffffbfff11ce890
R13: ffffffff88e74480 R14: 0000000000000000 R15: 0000000000000000
cpu_startup_entry+0x14/0x20 kernel/sched/idle.c:351
start_kernel+0x750/0x770 init/main.c:708
secondary_startup_64+0xa5/0xb0 arch/x86/kernel/head_64.S:240
systemd[1]: Time has been changed
systemd[1]: apt-daily-upgrade.timer: Adding 1min 56.114163s random time.
systemd[1]: apt-daily.timer: Adding 8h 6min 39.234370s random time.
systemd[1]: systemd-journald.service: Main process exited, code=killed, status=6/ABRT
Bluetooth: hci0 command 0x0409 tx timeout
systemd[1]: systemd-journald.service: Unit entered failed state.
systemd[1]: systemd-journald.service: Failed with result 'watchdog'.
systemd[1]: systemd-journald.service: Service has no hold-off time, scheduling restart.
systemd[1]: Stopped Flush Journal to Persistent Storage.
systemd[1]: Stopping Flush Journal to Persistent Storage...
systemd[1]: Stopped Journal Service.
systemd-journald[8262]: File /run/log/journal/04d8c135ee6b410280ba31a58c89679d/system.journal corrupted or uncleanly shut down, renaming and replacing.


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this issue, for details see:
https://goo.gl/tpsmEJ#testing-patches

syzbot

unread,
Apr 22, 2022, 10:37:21 PM4/22/22
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 15a1c6b6f516 Linux 4.14.276
git tree: linux-4.14.y
console output: https://syzkaller.appspot.com/x/log.txt?x=178094fcf00000
kernel config: https://syzkaller.appspot.com/x/.config?x=3ec12c117082c76f
dashboard link: https://syzkaller.appspot.com/bug?extid=8368796deb9660660296
compiler: gcc version 10.2.1 20210110 (Debian 10.2.1-6)
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=16bff030f00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=12bb60fcf00000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+836879...@syzkaller.appspotmail.com

[Firmware Bug]: TSC ADJUST differs: CPU0 0 --> -852877649960. Restoring
clocksource: timekeeping watchdog on CPU0: Marking clocksource 'tsc' as unstable because the skew is too large:
INFO: rcu_preempt self-detected stall on CPU
1-...: (1 GPs behind) idle=d06/1/0 softirq=11874/11881 fqs=0
(t=38766 jiffies g=911 c=910 q=212)
rcu_preempt kthread starved for 38766 jiffies! g911 c910 f0x0 RCU_GP_WAIT_FQS(3) ->state=0x402 ->cpu=0
rcu_preempt I30008 8 2 0x80000000
Call Trace:
context_switch kernel/sched/core.c:2811 [inline]
__schedule+0x88b/0x1de0 kernel/sched/core.c:3387
schedule+0x8d/0x1b0 kernel/sched/core.c:3431
schedule_timeout+0x4af/0xe90 kernel/time/timer.c:1747
rcu_gp_kthread+0xc0a/0x1e60 kernel/rcu/tree.c:2255
kthread+0x30d/0x420 kernel/kthread.c:232
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:404
Sending NMI from CPU 1 to CPUs 0:
NMI backtrace for cpu 0
CPU: 0 PID: 0 Comm: swapper/0 Not tainted 4.14.276-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
task: ffffffff88e74480 task.stack: ffffffff88e00000
RIP: 0010:trace_hardirqs_on_caller+0x20f/0x580 kernel/locking/lockdep.c:2929
RSP: 0018:ffff8880ba4079f8 EFLAGS: 00000046
RAX: 0000000000000007 RBX: ffffffff88e74480 RCX: 0000000000000000
RDX: 0000000000000000 RSI: ffffffff87ccff40 RDI: ffffffff88e74d04
RBP: ffffffff87400976 R08: ffff88823fff7018 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000000
R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000
FS: 0000000000000000(0000) GS:ffff8880ba400000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007ffdc4d658b8 CR3: 00000000b5727000 CR4: 00000000003406f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<IRQ>
trace_hardirqs_on_thunk+0x1a/0x1c
retint_kernel+0x2d/0x2d
RIP: 0010:arch_local_irq_restore arch/x86/include/asm/paravirt.h:780 [inline]
RIP: 0010:console_unlock+0xd81/0xf20 kernel/printk/printk.c:2413
RSP: 0018:ffff8880ba407b18 EFLAGS: 00000206 ORIG_RAX: ffffffffffffff10
RAX: ffffffff88e74480 RBX: 0000000000000200 RCX: 1ffffffff11ce9aa
RDX: 0000000000000100 RSI: ffffffff88e74d30 RDI: 0000000000000206
RBP: 0000000000000001 R08: ffffffff8ba5340c R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: ffffffff83d28470
R13: ffffffff89620ed0 R14: dffffc0000000000 R15: 000000000000007f
vprintk_emit+0x224/0x620 kernel/printk/printk.c:1925
vprintk_func+0x58/0x160 kernel/printk/printk_safe.c:409
printk+0x9e/0xbc kernel/printk/printk.c:1998
clocksource_watchdog+0x73e/0x8b0 kernel/time/clocksource.c:226
call_timer_fn+0x14a/0x650 kernel/time/timer.c:1280
expire_timers+0x232/0x4d0 kernel/time/timer.c:1319
__run_timers kernel/time/timer.c:1637 [inline]
run_timer_softirq+0x1d5/0x5a0 kernel/time/timer.c:1650
__do_softirq+0x24d/0x9ff kernel/softirq.c:288
invoke_softirq kernel/softirq.c:368 [inline]
irq_exit+0x193/0x240 kernel/softirq.c:409
exiting_irq arch/x86/include/asm/apic.h:638 [inline]
smp_apic_timer_interrupt+0x141/0x5e0 arch/x86/kernel/apic/apic.c:1106
apic_timer_interrupt+0x93/0xa0 arch/x86/entry/entry_64.S:793
</IRQ>
RIP: 0010:native_safe_halt+0xe/0x10 arch/x86/include/asm/irqflags.h:61
RSP: 0018:ffffffff88e07e78 EFLAGS: 00000282 ORIG_RAX: ffffffffffffff10
RAX: 1ffffffff11e1314 RBX: dffffc0000000000 RCX: 0000000000000000
RDX: dffffc0000000000 RSI: 0000000000000001 RDI: ffffffff88e74d04
RBP: ffffffff88f09890 R08: 0000000000000047 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: fffffbfff11ce890
R13: ffffffff88e74480 R14: 0000000000000000 R15: 0000000000000000
arch_safe_halt arch/x86/include/asm/paravirt.h:94 [inline]
default_idle+0x47/0x370 arch/x86/kernel/process.c:558
cpuidle_idle_call kernel/sched/idle.c:156 [inline]
do_idle+0x250/0x3c0 kernel/sched/idle.c:246
cpu_startup_entry+0x14/0x20 kernel/sched/idle.c:351
start_kernel+0x750/0x770 init/main.c:708
secondary_startup_64+0xa5/0xb0 arch/x86/kernel/head_64.S:240
Code: 03 38 d0 7c 08 84 d2 0f 85 33 03 00 00 8b 8b 54 08 00 00 85 c9 0f 85 b3 01 00 00 65 48 8b 1c 25 c0 7f 02 00 48 8d bb 84 08 00 00 <48> b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 0f b6 14 02
NMI backtrace for cpu 1
CPU: 1 PID: 0 Comm: swapper/1 Not tainted 4.14.276-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
<IRQ>
__dump_stack lib/dump_stack.c:17 [inline]
dump_stack+0x1b2/0x281 lib/dump_stack.c:58
nmi_cpu_backtrace.cold+0x57/0x93 lib/nmi_backtrace.c:101
nmi_trigger_cpumask_backtrace+0x13a/0x180 lib/nmi_backtrace.c:62
trigger_single_cpu_backtrace include/linux/nmi.h:158 [inline]
rcu_dump_cpu_stacks+0x15f/0x19c kernel/rcu/tree.c:1396
print_cpu_stall kernel/rcu/tree.c:1542 [inline]
check_cpu_stall kernel/rcu/tree.c:1610 [inline]
__rcu_pending kernel/rcu/tree.c:3390 [inline]
rcu_pending kernel/rcu/tree.c:3452 [inline]
rcu_check_callbacks.cold+0x464/0xd8d kernel/rcu/tree.c:2792
update_process_times+0x29/0x60 kernel/time/timer.c:1591
tick_sched_handle+0x7d/0x150 kernel/time/tick-sched.c:165
tick_sched_timer+0x92/0x200 kernel/time/tick-sched.c:1223
__run_hrtimer kernel/time/hrtimer.c:1223 [inline]
__hrtimer_run_queues+0x30b/0xc80 kernel/time/hrtimer.c:1287
hrtimer_interrupt+0x1e6/0x5e0 kernel/time/hrtimer.c:1321
local_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1079 [inline]
smp_apic_timer_interrupt+0x117/0x5e0 arch/x86/kernel/apic/apic.c:1104
apic_timer_interrupt+0x93/0xa0 arch/x86/entry/entry_64.S:793
</IRQ>
RIP: 0010:native_safe_halt+0xe/0x10 arch/x86/include/asm/irqflags.h:61
RSP: 0018:ffff8880b5487e68 EFLAGS: 00000282 ORIG_RAX: ffffffffffffff10
RAX: 1ffffffff11e1314 RBX: dffffc0000000000 RCX: 0000000000000000
RDX: dffffc0000000000 RSI: 0000000000000001 RDI: ffff8880b5478bc4
RBP: ffffffff88f09890 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: ffffed1016a8f068
R13: ffff8880b5478340 R14: 0000000000000000 R15: 0000000000000000
arch_safe_halt arch/x86/include/asm/paravirt.h:94 [inline]
default_idle+0x47/0x370 arch/x86/kernel/process.c:558
cpuidle_idle_call kernel/sched/idle.c:156 [inline]
do_idle+0x250/0x3c0 kernel/sched/idle.c:246
cpu_startup_entry+0x14/0x20 kernel/sched/idle.c:351
start_secondary+0x4db/0x670 arch/x86/kernel/smpboot.c:272
secondary_startup_64+0xa5/0xb0 arch/x86/kernel/head_64.S:240
systemd[1]: systemd-udevd.service: Watchdog timeout (limit 3min)!
systemd[1]: systemd-udevd.service: Killing process 4630 (systemd-udevd) with signal SIGABRT.
systemd[1]: Time has been changed
systemd[1]: apt-daily-upgrade.timer: Adding 6min 57.721758s random time.
systemd[1]: apt-daily.timer: Adding 10h 34min 49.367677s random time.
clocksource: 'kvm-clock' wd_now: b4da0bb863 wd_last: 5a7aa62b22 mask: ffffffffffffffff
clocksource: 'tsc' cs_now: c6ab555f64 cs_last: c6689f65c0 mask: ffffffffffffffff
tsc: Marking TSC unstable due to clocksource watchdog
systemd[1]: systemd-journald.service: Main process exited, code=killed, status=6/ABRT
systemd[1]: systemd-journald.service: Unit entered failed state.
systemd[1]: systemd-journald.service: Failed with result 'watchdog'.
systemd[1]: systemd-journald.service: Service has no hold-off time, scheduling restart.
systemd[1]: Stopped Flush Journal to Persistent Storage.
systemd-journald[8060]: File /run/log/journal/04d8c135ee6b410280ba31a58c89679d/system.journal corrupted or uncleanly shut down, renaming and replacing.
----------------
Code disassembly (best guess):
0: 03 38 add (%rax),%edi
2: d0 7c 08 84 sarb -0x7c(%rax,%rcx,1)
6: d2 0f rorb %cl,(%rdi)
8: 85 33 test %esi,(%rbx)
a: 03 00 add (%rax),%eax
c: 00 8b 8b 54 08 00 add %cl,0x8548b(%rbx)
12: 00 85 c9 0f 85 b3 add %al,-0x4c7af037(%rbp)
18: 01 00 add %eax,(%rax)
1a: 00 65 48 add %ah,0x48(%rbp)
1d: 8b 1c 25 c0 7f 02 00 mov 0x27fc0,%ebx
24: 48 8d bb 84 08 00 00 lea 0x884(%rbx),%rdi
* 2b: 48 b8 00 00 00 00 00 movabs $0xdffffc0000000000,%rax <-- trapping instruction
32: fc ff df
35: 48 89 fa mov %rdi,%rdx
38: 48 c1 ea 03 shr $0x3,%rdx
3c: 0f b6 14 02 movzbl (%rdx,%rax,1),%edx

syzbot

unread,
Apr 26, 2022, 2:47:21 AM4/26/22
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 3f8a27f9e27b Linux 4.19.211
git tree: linux-4.19.y
console output: https://syzkaller.appspot.com/x/log.txt?x=17a37c44f00000
kernel config: https://syzkaller.appspot.com/x/.config?x=9b9277b418617afe
dashboard link: https://syzkaller.appspot.com/bug?extid=60c6d3385e4c30e81e1b
compiler: gcc version 10.2.1 20210110 (Debian 10.2.1-6)

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+60c6d3...@syzkaller.appspotmail.com

[Firmware Bug]: TSC ADJUST differs: CPU0 0 --> -1714491390418. Restoring
rcu: INFO: rcu_preempt detected stalls on CPUs/tasks:
rcu: (detected by 0, t=77929 jiffies, g=134541, q=68)
rcu: All QSes seen, last rcu_preempt kthread activity 77929 (4295092562-4295014633), jiffies_till_next_fqs=1, root ->qsmask 0x0
ip6_tunnel: ip6gretap0 xmit: Local address not yet configured!
swapper/0 R running task 27720 0 0 0x80200008
Call Trace:
<IRQ>
sched_show_task.cold+0x332/0x396 kernel/sched/core.c:5337
print_other_cpu_stall kernel/rcu/tree.c:1430 [inline]
check_cpu_stall kernel/rcu/tree.c:1557 [inline]
__rcu_pending kernel/rcu/tree.c:3293 [inline]
rcu_pending kernel/rcu/tree.c:3336 [inline]
rcu_check_callbacks.cold+0xb37/0xe19 kernel/rcu/tree.c:2682
update_process_times+0x2a/0x70 kernel/time/timer.c:1650
tick_sched_handle+0x9b/0x180 kernel/time/tick-sched.c:168
tick_sched_timer+0xfc/0x290 kernel/time/tick-sched.c:1278
__run_hrtimer kernel/time/hrtimer.c:1465 [inline]
__hrtimer_run_queues+0x3f6/0xe60 kernel/time/hrtimer.c:1527
hrtimer_interrupt+0x326/0x9e0 kernel/time/hrtimer.c:1585
local_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1071 [inline]
smp_apic_timer_interrupt+0x10c/0x550 arch/x86/kernel/apic/apic.c:1096
apic_timer_interrupt+0xf/0x20 arch/x86/entry/entry_64.S:894
</IRQ>
RIP: 0010:cpuidle_idle_call kernel/sched/idle.c:140 [inline]
RIP: 0010:do_idle+0x372/0x4b0 kernel/sched/idle.c:263
Code: 48 c7 c0 98 82 f1 89 48 c1 e8 03 80 3c 18 00 0f 85 0c 01 00 00 48 83 3d 53 59 ae 08 00 0f 84 9a 00 00 00 fb 66 0f 1f 44 00 00 <e9> b5 fd ff ff 0f 0b 0f 0b e8 e0 7f 24 00 48 c7 c0 98 82 f1 89 48
RSP: 0018:ffffffff89e07d78 EFLAGS: 00000286 ORIG_RAX: ffffffffffffff13
RAX: 1ffffffff13e3053 RBX: dffffc0000000000 RCX: 0000000000000000
RDX: 0000000000000000 RSI: 0000000000000001 RDI: ffffffff89e78904
RBP: 0000000000000000 R08: 0000000000000048 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: ffffffff89f18290
R13: 1ffffffff13c0fb2 R14: 0000000000000000 R15: 0000000000000000
cpu_startup_entry+0xc5/0xe0 kernel/sched/idle.c:369
start_kernel+0x8d6/0x911 init/main.c:736
secondary_startup_64+0xa4/0xb0 arch/x86/kernel/head_64.S:243
rcu: rcu_preempt kthread starved for 77929 jiffies! g134541 f0x2 RCU_GP_WAIT_FQS(5) ->state=0x0 ->cpu=0
rcu: RCU grace-period kthread stack dump:
rcu_preempt R running task 29208 10 2 0x80000000
Call Trace:
context_switch kernel/sched/core.c:2828 [inline]
__schedule+0x887/0x2040 kernel/sched/core.c:3517
schedule+0x8d/0x1b0 kernel/sched/core.c:3561
schedule_timeout+0x4cf/0xfe0 kernel/time/timer.c:1818
rcu_gp_kthread+0xdad/0x21c0 kernel/rcu/tree.c:2202
kthread+0x33f/0x460 kernel/kthread.c:259
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:415
clocksource: timekeeping watchdog on CPU0: Marking clocksource 'tsc' as unstable because the skew is too large:
clocksource: 'kvm-clock' wd_now: 16b0fcc6e9c wd_last: b58a82bc36 mask: ffffffffffffffff
clocksource: 'tsc' cs_now: 7448e428 cs_last: 18f44b513fc mask: ffffffffffffffff
tsc: Marking TSC unstable due to clocksource watchdog
ip6_tunnel: ip6gretap0 xmit: Local address not yet configured!
ip6_tunnel: ip6gretap0 xmit: Local address not yet configured!
BUG: workqueue lockup - pool cpus=0-1 flags=0x4 nice=0 stuck for 779s!
Showing busy workqueues and worker pools:
workqueue events: flags=0x0
pwq 2: cpus=1 node=0 flags=0x0 nice=0 active=10/256 refcnt=11
pending: perf_sched_delayed, defense_work_handler, defense_work_handler, defense_work_handler, defense_work_handler, cache_reap, macvlan_process_broadcast, macvlan_process_broadcast, macvlan_process_broadcast, macvlan_process_broadcast
pwq 0: cpus=0 node=0 flags=0x0 nice=0 active=7/256 refcnt=8
pending: defense_work_handler, defense_work_handler, defense_work_handler, clocksource_watchdog_work, switchdev_deferred_process_work, vmstat_shepherd, cache_reap
workqueue events_long: flags=0x0
pwq 2: cpus=1 node=0 flags=0x0 nice=0 active=3/256 refcnt=4
pending: br_fdb_cleanup, br_fdb_cleanup, br_fdb_cleanup
pwq 0: cpus=0 node=0 flags=0x0 nice=0 active=6/256 refcnt=7
pending: br_fdb_cleanup, br_fdb_cleanup, br_fdb_cleanup, br_fdb_cleanup, br_fdb_cleanup, br_fdb_cleanup
workqueue events_power_efficient: flags=0x80
pwq 2: cpus=1 node=0 flags=0x0 nice=0 active=2/256 refcnt=3
pending: fb_flashcursor, reg_check_chans_work
pwq 0: cpus=0 node=0 flags=0x0 nice=0 active=5/256 refcnt=6
pending: check_lifetime, sync_hw_clock, neigh_periodic_work, do_cache_clean, neigh_periodic_work
workqueue rcu_gp: flags=0x8
pwq 0: cpus=0 node=0 flags=0x0 nice=0 active=1/256 refcnt=2
pending: srcu_invoke_callbacks
workqueue mm_percpu_wq: flags=0x8
pwq 2: cpus=1 node=0 flags=0x0 nice=0 active=1/256 refcnt=2
pending: vmstat_update
pwq 0: cpus=0 node=0 flags=0x0 nice=0 active=1/256 refcnt=2
pending: vmstat_update
workqueue cgroup_pidlist_destroy: flags=0x0
pwq 2: cpus=1 node=0 flags=0x0 nice=0 active=1/1 refcnt=2
pending: cgroup_pidlist_destroy_work_fn
workqueue writeback: flags=0x4a
pwq 4: cpus=0-1 flags=0x4 nice=0 active=4/256 refcnt=7
pending: wb_workfn, wb_workfn, wb_workfn, wb_workfn
workqueue kblockd: flags=0x18
pwq 3: cpus=1 node=0 flags=0x0 nice=-20 active=3/256 refcnt=4
pending: blk_mq_timeout_work, blk_mq_timeout_work, blk_mq_timeout_work
pwq 1: cpus=0 node=0 flags=0x0 nice=-20 active=1/256 refcnt=2
pending: blk_mq_timeout_work
workqueue dm_bufio_cache: flags=0x8
pwq 0: cpus=0 node=0 flags=0x0 nice=0 active=1/256 refcnt=2
pending: work_fn
workqueue ipv6_addrconf: flags=0x40008
pwq 0: cpus=0 node=0 flags=0x0 nice=0 active=1/1 refcnt=2
pending: addrconf_verify_work
workqueue krxrpcd: flags=0x0
pwq 2: cpus=1 node=0 flags=0x0 nice=0 active=1/1 refcnt=5
pending: rxrpc_peer_keepalive_worker
delayed: rxrpc_peer_keepalive_worker, rxrpc_peer_keepalive_worker, rxrpc_discard_expired_client_conns
pwq 0: cpus=0 node=0 flags=0x0 nice=0 active=1/1 refcnt=6
pending: rxrpc_peer_keepalive_worker
delayed: rxrpc_peer_keepalive_worker, rxrpc_peer_keepalive_worker, rxrpc_peer_keepalive_worker, rxrpc_discard_expired_client_conns
workqueue bat_events: flags=0xe000a
pwq 4: cpus=0-1 flags=0x4 nice=0 active=1/1 refcnt=19
pending: batadv_iv_send_outstanding_bat_ogm_packet
delayed: batadv_tt_purge, batadv_tt_purge, batadv_nc_worker, batadv_nc_worker, batadv_iv_send_outstanding_bat_ogm_packet, batadv_iv_send_outstanding_bat_ogm_packet, batadv_purge_orig, batadv_purge_orig, batadv_iv_send_outstanding_bat_ogm_packet, batadv_mcast_mla_update, batadv_mcast_mla_update, batadv_bla_periodic_work, batadv_dat_purge, batadv_bla_periodic_work, batadv_dat_purge
workqueue bond0: flags=0xa000a
pwq 4: cpus=0-1 flags=0x4 nice=0 active=1/1 refcnt=4
pending: bond_mii_monitor
workqueue bond0: flags=0xa000a
pwq 4: cpus=0-1 flags=0x4 nice=0 active=1/1 refcnt=4
pending: bond_mii_monitor
workqueue phy3: flags=0xa0002
pwq 4: cpus=0-1 flags=0x4 nice=0 active=1/1 refcnt=4
pending: ieee80211_iface_work
workqueue phy4: flags=0xa0002
pwq 4: cpus=0-1 flags=0x4 nice=0 active=1/1 refcnt=4
pending: ieee80211_iface_work
workqueue phy6: flags=0xa0002
pwq 4: cpus=0-1 flags=0x4 nice=0 active=1/1 refcnt=4
pending: ieee80211_iface_work
workqueue phy7: flags=0xa0002
pwq 4: cpus=0-1 flags=0x4 nice=0 active=1/1 refcnt=4
pending: ieee80211_iface_work
workqueue phy8: flags=0xa0002
pwq 4: cpus=0-1 flags=0x4 nice=0 active=1/1 refcnt=4
pending: ieee80211_iface_work
workqueue phy9: flags=0xa0002
pwq 4: cpus=0-1 flags=0x4 nice=0 active=1/1 refcnt=4
pending: ieee80211_iface_work
workqueue phy10: flags=0xa0002
pwq 4: cpus=0-1 flags=0x4 nice=0 active=1/1 refcnt=4
pending: ieee80211_iface_work
workqueue phy11: flags=0xa0002
pwq 4: cpus=0-1 flags=0x4 nice=0 active=1/1 refcnt=4
pending: ieee80211_iface_work
workqueue phy12: flags=0xa0002
pwq 4: cpus=0-1 flags=0x4 nice=0 active=1/1 refcnt=4
pending: ieee80211_iface_work
workqueue bond1: flags=0xa000a
pwq 4: cpus=0-1 flags=0x4 nice=0 active=1/1 refcnt=5
pending: bond_mii_monitor
delayed: bond_alb_monitor
wlan1: No active IBSS STAs - trying to scan for other IBSS networks with same SSID (merge)
ieee802154 phy0 wpan0: encryption failed: -22
ieee802154 phy1 wpan1: encryption failed: -22
wlan1: No active IBSS STAs - trying to scan for other IBSS networks with same SSID (merge)
rcu: INFO: rcu_preempt self-detected stall on CPU
rcu: 1-...!: (1 GPs behind) idle=7fa/1/0x4000000000000002 softirq=106337/106338 fqs=1
rcu: (t=39529 jiffies g=134545 q=53523)
rcu: rcu_preempt kthread starved for 39529 jiffies! g134545 f0x0 RCU_GP_WAIT_FQS(5) ->state=0x402 ->cpu=0
rcu: RCU grace-period kthread stack dump:
rcu_preempt I29208 10 2 0x80000000
Call Trace:
context_switch kernel/sched/core.c:2828 [inline]
__schedule+0x887/0x2040 kernel/sched/core.c:3517
schedule+0x8d/0x1b0 kernel/sched/core.c:3561
schedule_timeout+0x4cf/0xfe0 kernel/time/timer.c:1818
rcu_gp_kthread+0xdad/0x21c0 kernel/rcu/tree.c:2202
kthread+0x33f/0x460 kernel/kthread.c:259
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:415
Sending NMI from CPU 1 to CPUs 0:
NMI backtrace for cpu 0
CPU: 0 PID: 15343 Comm: syz-executor.3 Not tainted 4.19.211-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
RIP: 0010:preempt_count arch/x86/include/asm/preempt.h:23 [inline]
RIP: 0010:check_kcov_mode kernel/kcov.c:67 [inline]
RIP: 0010:write_comp_data+0xf/0x70 kernel/kcov.c:122
Code: 8b 11 48 83 c2 01 48 39 d0 76 07 48 89 34 d1 48 89 11 c3 0f 1f 84 00 00 00 00 00 49 89 f1 49 89 fa 65 48 8b 34 25 c0 df 01 00 <65> 8b 05 7a 59 9f 7e a9 00 01 1f 00 75 4f 8b 86 60 13 00 00 83 f8
RSP: 0018:ffff8880ba007c88 EFLAGS: 00000046
RAX: 0000000000000005 RBX: 000000000000007f RCX: ffffffff8154e60e
RDX: 000000000000007f RSI: ffff88806ef5e0c0 RDI: 0000000000000007
RBP: 0000000000000000 R08: 0098976e46b67314 R09: 0000000000000000
R10: 0000000000000007 R11: ffffffff8c66501b R12: 0000000000000000
R13: 0098976de6d51eb8 R14: 0000000000000007 R15: 001dcd6500000000
FS: 00007f7aaeb97700(0000) GS:ffff8880ba000000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000055e0a18b1740 CR3: 0000000092ab8000 CR4: 00000000003406f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<IRQ>
ntp_offset_chunk kernel/time/ntp.c:212 [inline]
second_overflow+0xbe/0x400 kernel/time/ntp.c:467
accumulate_nsecs_to_secs kernel/time/timekeeping.c:1985 [inline]
logarithmic_accumulation kernel/time/timekeeping.c:2029 [inline]
timekeeping_advance+0x27c/0x9b0 kernel/time/timekeeping.c:2097
tick_do_update_jiffies64.part.0+0x188/0x290 kernel/time/tick-sched.c:101
tick_do_update_jiffies64 kernel/time/tick-sched.c:67 [inline]
tick_sched_do_timer kernel/time/tick-sched.c:139 [inline]
tick_sched_timer+0x220/0x290 kernel/time/tick-sched.c:1271
__run_hrtimer kernel/time/hrtimer.c:1465 [inline]
__hrtimer_run_queues+0x3f6/0xe60 kernel/time/hrtimer.c:1527
hrtimer_interrupt+0x326/0x9e0 kernel/time/hrtimer.c:1585
local_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1071 [inline]
smp_apic_timer_interrupt+0x10c/0x550 arch/x86/kernel/apic/apic.c:1096
apic_timer_interrupt+0xf/0x20 arch/x86/entry/entry_64.S:894
</IRQ>
RIP: 0010:arch_local_irq_restore arch/x86/include/asm/paravirt.h:789 [inline]
RIP: 0010:generic_exec_single+0x317/0x490 kernel/smp.c:154
Code: 00 fc ff df 48 c1 e8 03 80 3c 10 00 0f 85 5a 01 00 00 48 83 3d 61 04 99 08 00 0f 84 db 00 00 00 e8 3e 07 0a 00 48 89 df 57 9d <0f> 1f 44 00 00 45 31 e4 e9 39 fe ff ff e8 27 07 0a 00 0f 0b e9 3a
RSP: 0018:ffff8880a246f9e8 EFLAGS: 00000246 ORIG_RAX: ffffffffffffff13
RAX: 0000000000040000 RBX: 0000000000000246 RCX: ffffc90008c3c000
RDX: 0000000000040000 RSI: ffffffff81587e32 RDI: 0000000000000246
RBP: 0000000000000200 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: ffff8880a246fa60
R13: ffff8880a246fb28 R14: ffffffff8388f960 R15: 0000000000000010
smp_call_function_single+0x1cf/0x420 kernel/smp.c:299
wrmsr_safe_on_cpu+0x9f/0x100 arch/x86/lib/msr-smp.c:204
msr_write+0x10c/0x1b0 arch/x86/kernel/msr.c:95
do_loop_readv_writev fs/read_write.c:704 [inline]
do_loop_readv_writev fs/read_write.c:688 [inline]
do_iter_write+0x461/0x5d0 fs/read_write.c:962
vfs_writev+0x153/0x2e0 fs/read_write.c:1005
do_pwritev fs/read_write.c:1094 [inline]
__do_sys_pwritev fs/read_write.c:1141 [inline]
__se_sys_pwritev fs/read_write.c:1136 [inline]
__x64_sys_pwritev+0x22b/0x310 fs/read_write.c:1136
do_syscall_64+0xf9/0x620 arch/x86/entry/common.c:293
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x7f7ab02220e9
Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f7aaeb97168 EFLAGS: 00000246 ORIG_RAX: 0000000000000128
RAX: ffffffffffffffda RBX: 00007f7ab0334f60 RCX: 00007f7ab02220e9
RDX: 0000000000000002 RSI: 0000000020000100 RDI: 0000000000000004
RBP: 00007f7ab027c08d R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000010 R11: 0000000000000246 R12: 0000000000000000
R13: 00007ffe4f107c2f R14: 00007f7aaeb97300 R15: 0000000000022000
NMI backtrace for cpu 1
CPU: 1 PID: 18 Comm: ksoftirqd/1 Not tainted 4.19.211-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
<IRQ>
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x1fc/0x2ef lib/dump_stack.c:118
nmi_cpu_backtrace.cold+0x63/0xa2 lib/nmi_backtrace.c:101
nmi_trigger_cpumask_backtrace+0x1a6/0x1f0 lib/nmi_backtrace.c:62
trigger_single_cpu_backtrace include/linux/nmi.h:164 [inline]
rcu_dump_cpu_stacks+0x15f/0x19c kernel/rcu/tree.c:1340
print_cpu_stall kernel/rcu/tree.c:1478 [inline]
check_cpu_stall kernel/rcu/tree.c:1550 [inline]
__rcu_pending kernel/rcu/tree.c:3293 [inline]
rcu_pending kernel/rcu/tree.c:3336 [inline]
rcu_check_callbacks.cold+0x62d/0xe19 kernel/rcu/tree.c:2682
update_process_times+0x2a/0x70 kernel/time/timer.c:1650
tick_sched_handle+0x9b/0x180 kernel/time/tick-sched.c:168
tick_sched_timer+0xfc/0x290 kernel/time/tick-sched.c:1278
__run_hrtimer kernel/time/hrtimer.c:1465 [inline]
__hrtimer_run_queues+0x3f6/0xe60 kernel/time/hrtimer.c:1527
hrtimer_interrupt+0x326/0x9e0 kernel/time/hrtimer.c:1585
local_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1071 [inline]
smp_apic_timer_interrupt+0x10c/0x550 arch/x86/kernel/apic/apic.c:1096
apic_timer_interrupt+0xf/0x20 arch/x86/entry/entry_64.S:894
</IRQ>
RIP: 0010:arch_local_irq_restore arch/x86/include/asm/paravirt.h:789 [inline]
RIP: 0010:__raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:160 [inline]
RIP: 0010:_raw_spin_unlock_irqrestore+0xa3/0xe0 kernel/locking/spinlock.c:184
Code: 48 c7 c0 88 82 f1 89 48 ba 00 00 00 00 00 fc ff df 48 c1 e8 03 80 3c 10 00 75 2f 48 83 3d 7c 31 d8 01 00 74 15 48 89 df 57 9d <0f> 1f 44 00 00 eb b2 e8 fb eb e6 f8 eb c0 0f 0b 0f 0b 48 c7 c7 88
RSP: 0018:ffff8880b5acfd50 EFLAGS: 00000286 ORIG_RAX: ffffffffffffff13
RAX: 1ffffffff13e3051 RBX: 0000000000000286 RCX: 0000000000000000
RDX: dffffc0000000000 RSI: 0000000000000000 RDI: 0000000000000286
RBP: ffff8880ba124cc0 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000000
R13: 0000000000000000 R14: ffff88809e1545c0 R15: dffffc0000000000
hrtimer_start include/linux/hrtimer.h:398 [inline]
tasklet_hrtimer_start include/linux/interrupt.h:641 [inline]
mac80211_hwsim_beacon+0x14b/0x190 drivers/net/wireless/mac80211_hwsim.c:1627
__tasklet_hrtimer_trampoline+0x29/0xa0 kernel/softirq.c:601
tasklet_action_common.constprop.0+0x265/0x360 kernel/softirq.c:522
__do_softirq+0x265/0x980 kernel/softirq.c:292
run_ksoftirqd+0x57/0x110 kernel/softirq.c:653
smpboot_thread_fn+0x655/0x9e0 kernel/smpboot.c:164
kthread+0x33f/0x460 kernel/kthread.c:259
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:415
----------------
Code disassembly (best guess):
0: 48 c7 c0 98 82 f1 89 mov $0xffffffff89f18298,%rax
7: 48 c1 e8 03 shr $0x3,%rax
b: 80 3c 18 00 cmpb $0x0,(%rax,%rbx,1)
f: 0f 85 0c 01 00 00 jne 0x121
15: 48 83 3d 53 59 ae 08 cmpq $0x0,0x8ae5953(%rip) # 0x8ae5970
1c: 00
1d: 0f 84 9a 00 00 00 je 0xbd
23: fb sti
24: 66 0f 1f 44 00 00 nopw 0x0(%rax,%rax,1)
* 2a: e9 b5 fd ff ff jmpq 0xfffffde4 <-- trapping instruction
2f: 0f 0b ud2
31: 0f 0b ud2
33: e8 e0 7f 24 00 callq 0x248018
38: 48 c7 c0 98 82 f1 89 mov $0xffffffff89f18298,%rax
3f: 48 rex.W

syzbot

unread,
Aug 24, 2022, 3:48:21 AM8/24/22
to syzkaller...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages