[v5.15] INFO: task hung in evict

4 views
Skip to first unread message

syzbot

unread,
Jan 27, 2025, 12:28:26 PM1/27/25
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 003148680b79 Linux 5.15.177
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=13385118580000
kernel config: https://syzkaller.appspot.com/x/.config?x=f2c956168ff5b89
dashboard link: https://syzkaller.appspot.com/bug?extid=c6778d0597c63956b321
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/452e6089e1b8/disk-00314868.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/368807beca93/vmlinux-00314868.xz
kernel image: https://storage.googleapis.com/syzbot-assets/e98b52fba46c/bzImage-00314868.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+c6778d...@syzkaller.appspotmail.com

INFO: task syz-executor:4175 blocked for more than 145 seconds.
Not tainted 5.15.177-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:syz-executor state:D stack:18520 pid: 4175 ppid: 1 flags:0x00004004
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5027 [inline]
__schedule+0x12c4/0x45b0 kernel/sched/core.c:6373
schedule+0x11b/0x1f0 kernel/sched/core.c:6456
io_schedule+0x88/0x100 kernel/sched/core.c:8481
wait_on_page_bit_common+0xa13/0x1180 mm/filemap.c:1356
lock_page include/linux/pagemap.h:625 [inline]
truncate_inode_pages_range+0xc17/0x1290 mm/truncate.c:394
evict+0x53c/0x930 fs/inode.c:624
dispose_list fs/inode.c:655 [inline]
evict_inodes+0x668/0x700 fs/inode.c:709
generic_shutdown_super+0x94/0x310 fs/super.c:454
kill_block_super+0x7a/0xe0 fs/super.c:1427
deactivate_locked_super+0xa0/0x110 fs/super.c:335
cleanup_mnt+0x44e/0x500 fs/namespace.c:1143
task_work_run+0x129/0x1a0 kernel/task_work.c:188
tracehook_notify_resume include/linux/tracehook.h:189 [inline]
exit_to_user_mode_loop+0x106/0x130 kernel/entry/common.c:181
exit_to_user_mode_prepare+0xb1/0x140 kernel/entry/common.c:214
__syscall_exit_to_user_mode_work kernel/entry/common.c:296 [inline]
syscall_exit_to_user_mode+0x5d/0x240 kernel/entry/common.c:307
do_syscall_64+0x47/0xb0 arch/x86/entry/common.c:86
entry_SYSCALL_64_after_hwframe+0x66/0xd0
RIP: 0033:0x7f8425e41057
RSP: 002b:00007ffda7d4d368 EFLAGS: 00000246 ORIG_RAX: 00000000000000a6
RAX: 0000000000000000 RBX: 00007f8425ec108c RCX: 00007f8425e41057
RDX: 0000000000000000 RSI: 0000000000000009 RDI: 00007ffda7d4d420
RBP: 00007ffda7d4d420 R08: 0000000000000000 R09: 0000000000000000
R10: 00000000ffffffff R11: 0000000000000246 R12: 00007ffda7d4e4a0
R13: 00007f8425ec108c R14: 00007ffda7d4e4e0 R15: 0000000000000059
</TASK>

Showing all locks held in the system:
1 lock held by khungtaskd/27:
#0: ffffffff8cb1fce0 (rcu_read_lock){....}-{1:2}, at: rcu_lock_acquire+0x0/0x30
1 lock held by udevd/3544:
#0: ffff888020a0b518 (&disk->open_mutex){+.+.}-{3:3}, at: blkdev_get_by_dev+0x14d/0xa50 block/bdev.c:817
2 locks held by getty/3919:
#0: ffff88802c709098 (&tty->ldisc_sem){++++}-{0:0}, at: tty_ldisc_ref_wait+0x21/0x70 drivers/tty/tty_ldisc.c:252
#1: ffffc90002cd62e8 (&ldata->atomic_read_lock){+.+.}-{3:3}, at: n_tty_read+0x6af/0x1db0 drivers/tty/n_tty.c:2158
2 locks held by syz-executor/4165:
#0: ffff88807eaa20e0 (&type->s_umount_key#72){+.+.}-{3:3}, at: deactivate_super+0xa9/0xe0 fs/super.c:365
#1: ffffffff8cb242a8 (rcu_state.exp_mutex){+.+.}-{3:3}, at: exp_funnel_lock kernel/rcu/tree_exp.h:290 [inline]
#1: ffffffff8cb242a8 (rcu_state.exp_mutex){+.+.}-{3:3}, at: synchronize_rcu_expedited+0x280/0x740 kernel/rcu/tree_exp.h:845
2 locks held by syz-executor/4169:
#0: ffff888147588118 (&disk->open_mutex){+.+.}-{3:3}, at: blkdev_put+0xfb/0x790 block/bdev.c:912
#1: ffff8880209e4468 (&lo->lo_mutex){+.+.}-{3:3}, at: __loop_clr_fd+0xa9/0xbe0 drivers/block/loop.c:1365
1 lock held by syz-executor/4175:
#0: ffff88805e3980e0 (&type->s_umount_key#90){+.+.}-{3:3}, at: deactivate_super+0xa9/0xe0 fs/super.c:365
2 locks held by kworker/u4:6/4247:
2 locks held by udevd/4738:
2 locks held by kworker/1:17/7631:
#0: ffff888017472138 ((wq_completion)rcu_gp){+.+.}-{0:0}, at: process_one_work+0x78a/0x10c0 kernel/workqueue.c:2283
#1: ffffc900030f7d20 ((work_completion)(&rew.rew_work)){+.+.}-{0:0}, at: process_one_work+0x7d0/0x10c0 kernel/workqueue.c:2285
2 locks held by syz.6.790/7810:
7 locks held by syz.5.788/7812:
#0: ffffffff8c9fc5a0 (console_lock){+.+.}-{0:0}, at: do_fb_ioctl+0x1e4/0x890 drivers/video/fbdev/core/fbmem.c:1179
#1: ffff88802065c078 (&fb_info->lock){+.+.}-{3:3}, at: lock_fb_info include/linux/fb.h:650 [inline]
#1: ffff88802065c078 (&fb_info->lock){+.+.}-{3:3}, at: do_fb_ioctl+0x1f9/0x890 drivers/video/fbdev/core/fbmem.c:1180
#2: ffff8881475e1278 (&helper->lock){+.+.}-{3:3}, at: drm_fb_helper_dpms drivers/gpu/drm/drm_fb_helper.c:323 [inline]
#2: ffff8881475e1278 (&helper->lock){+.+.}-{3:3}, at: drm_fb_helper_blank+0xa7/0x1e0 drivers/gpu/drm/drm_fb_helper.c:341
#3: ffff8881476501a8 (&dev->master_mutex){+.+.}-{3:3}, at: drm_master_internal_acquire+0x1c/0x70 drivers/gpu/drm/drm_auth.c:453
#4: ffff8881475e1098 (&client->modeset_mutex){+.+.}-{3:3}, at: drm_client_modeset_dpms+0xbf/0x890 drivers/gpu/drm/drm_client_modeset.c:1234
#5: ffffc90003057990 (crtc_ww_class_acquire){+.+.}-{0:0}, at: drm_client_modeset_commit_atomic+0xc3/0x7b0 drivers/gpu/drm/drm_client_modeset.c:994
#6: ffff88801ea3f8b0 (crtc_ww_class_mutex){+.+.}-{3:3}, at: modeset_lock+0x288/0x5f0 drivers/gpu/drm/drm_modeset_lock.c:263

=============================================

NMI backtrace for cpu 1
CPU: 1 PID: 27 Comm: khungtaskd Not tainted 5.15.177-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 12/27/2024
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:88 [inline]
dump_stack_lvl+0x1e3/0x2d0 lib/dump_stack.c:106
nmi_cpu_backtrace+0x46a/0x4a0 lib/nmi_backtrace.c:111
nmi_trigger_cpumask_backtrace+0x181/0x2a0 lib/nmi_backtrace.c:62
trigger_all_cpu_backtrace include/linux/nmi.h:148 [inline]
check_hung_uninterruptible_tasks kernel/hung_task.c:210 [inline]
watchdog+0xe72/0xeb0 kernel/hung_task.c:295
kthread+0x3f6/0x4f0 kernel/kthread.c:334
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:287
</TASK>
Sending NMI from CPU 1 to CPUs 0:
NMI backtrace for cpu 0
CPU: 0 PID: 9 Comm: kworker/u4:0 Not tainted 5.15.177-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 12/27/2024
Workqueue: phy11 ieee80211_iface_work
RIP: 0010:__lock_acquire+0x92/0x1ff0
Code: 03 80 3c 10 00 74 14 e8 2c 9a 67 00 48 8b 7c 24 08 48 ba 00 00 00 00 00 fc ff df 48 c7 c0 c0 bf 4f 90 48 39 07 75 03 45 31 ff <89> 5c 24 60 83 fd 01 77 33 89 e8 48 8d 5c c7 08 48 89 d8 48 c1 e8
RSP: 0018:ffffc90000ce78c0 EFLAGS: 00000002
RAX: ffffffff904fbfc0 RBX: 0000000000000000 RCX: 0000000000000000
RDX: dffffc0000000000 RSI: 0000000000000000 RDI: ffff88805e095890
RBP: 0000000000000000 R08: 0000000000000001 R09: 0000000000000001
R10: 0000000000000000 R11: dffffc0000000001 R12: 0000000000000001
R13: ffff88813ff90000 R14: 0000000000000000 R15: 0000000000000001
FS: 0000000000000000(0000) GS:ffff8880b8e00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007ffeabcc2000 CR3: 0000000072c18000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<NMI>
</NMI>
<TASK>
lock_acquire+0x1db/0x4f0 kernel/locking/lockdep.c:5623
__raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline]
_raw_spin_lock_irqsave+0xd1/0x120 kernel/locking/spinlock.c:162
skb_dequeue+0x29/0x140 net/core/skbuff.c:3285
ieee80211_iface_work+0x9d7/0xcc0 net/mac80211/iface.c:1517
process_one_work+0x8a1/0x10c0 kernel/workqueue.c:2310
worker_thread+0xaca/0x1280 kernel/workqueue.c:2457
kthread+0x3f6/0x4f0 kernel/kthread.c:334
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:287
</TASK>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Jan 27, 2025, 1:40:30 PM1/27/25
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 75cefdf153f5 Linux 6.1.127
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=150df9f8580000
kernel config: https://syzkaller.appspot.com/x/.config?x=3dc848f1f9c50685
dashboard link: https://syzkaller.appspot.com/bug?extid=225be6e3832c203b8460
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/9fa70d9fd10a/disk-75cefdf1.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/d01cb9bb9789/vmlinux-75cefdf1.xz
kernel image: https://storage.googleapis.com/syzbot-assets/487423b91d50/bzImage-75cefdf1.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+225be6...@syzkaller.appspotmail.com

INFO: task syz-executor:4256 blocked for more than 147 seconds.
Not tainted 6.1.127-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:syz-executor state:D stack:19864 pid:4256 ppid:1 flags:0x00004004
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5241 [inline]
__schedule+0x143f/0x4570 kernel/sched/core.c:6558
schedule+0xbf/0x180 kernel/sched/core.c:6634
io_schedule+0x88/0x100 kernel/sched/core.c:8786
folio_wait_bit_common+0x878/0x1290 mm/filemap.c:1324
truncate_inode_pages_range+0xbb5/0x1340 mm/truncate.c:422
evict+0x53c/0x930 fs/inode.c:707
dispose_list fs/inode.c:738 [inline]
evict_inodes+0x668/0x700 fs/inode.c:792
generic_shutdown_super+0x94/0x340 fs/super.c:480
kill_block_super+0x7a/0xe0 fs/super.c:1470
deactivate_locked_super+0xa0/0x110 fs/super.c:332
cleanup_mnt+0x490/0x520 fs/namespace.c:1186
task_work_run+0x246/0x300 kernel/task_work.c:203
resume_user_mode_work include/linux/resume_user_mode.h:49 [inline]
exit_to_user_mode_loop+0xde/0x100 kernel/entry/common.c:177
exit_to_user_mode_prepare+0xb1/0x140 kernel/entry/common.c:210
__syscall_exit_to_user_mode_work kernel/entry/common.c:292 [inline]
syscall_exit_to_user_mode+0x60/0x270 kernel/entry/common.c:303
do_syscall_64+0x47/0xb0 arch/x86/entry/common.c:87
entry_SYSCALL_64_after_hwframe+0x68/0xd2
RIP: 0033:0x7f072838e057
RSP: 002b:00007ffe98a6ae08 EFLAGS: 00000246 ORIG_RAX: 00000000000000a6
RAX: 0000000000000000 RBX: 00007f072840e08c RCX: 00007f072838e057
RDX: 0000000000000000 RSI: 0000000000000009 RDI: 00007ffe98a6aec0
RBP: 00007ffe98a6aec0 R08: 0000000000000000 R09: 0000000000000000
R10: 00000000ffffffff R11: 0000000000000246 R12: 00007ffe98a6bf40
R13: 00007f072840e08c R14: 00007ffe98a6bf80 R15: 0000000000000051
</TASK>

Showing all locks held in the system:
1 lock held by rcu_tasks_kthre/12:
#0: ffffffff8d32b290 (rcu_tasks.tasks_gp_mutex){+.+.}-{3:3}, at: rcu_tasks_one_gp+0x29/0xe30 kernel/rcu/tasks.h:517
1 lock held by rcu_tasks_trace/13:
#0: ffffffff8d32ba90 (rcu_tasks_trace.tasks_gp_mutex){+.+.}-{3:3}, at: rcu_tasks_one_gp+0x29/0xe30 kernel/rcu/tasks.h:517
1 lock held by khungtaskd/28:
#0: ffffffff8d32b0c0 (rcu_read_lock){....}-{1:2}, at: rcu_lock_acquire include/linux/rcupdate.h:350 [inline]
#0: ffffffff8d32b0c0 (rcu_read_lock){....}-{1:2}, at: rcu_read_lock include/linux/rcupdate.h:791 [inline]
#0: ffffffff8d32b0c0 (rcu_read_lock){....}-{1:2}, at: debug_show_all_locks+0x51/0x290 kernel/locking/lockdep.c:6510
2 locks held by getty/4003:
#0: ffff888030e42098 (&tty->ldisc_sem){++++}-{0:0}, at: tty_ldisc_ref_wait+0x21/0x70 drivers/tty/tty_ldisc.c:244
#1: ffffc9000325e2f0 (&ldata->atomic_read_lock){+.+.}-{3:3}, at: n_tty_read+0x6a7/0x1db0 drivers/tty/n_tty.c:2198
1 lock held by syz-executor/4256:
#0: ffff88804f7640e0 (&type->s_umount_key#58){+.+.}-{3:3}, at: deactivate_super+0xa9/0xe0 fs/super.c:362
1 lock held by udevd/4325:
#0: ffff888140c476c0 (mapping.invalidate_lock#2){.+.+}-{3:3}, at: filemap_invalidate_lock_shared include/linux/fs.h:813 [inline]
#0: ffff888140c476c0 (mapping.invalidate_lock#2){.+.+}-{3:3}, at: page_cache_ra_unbounded+0xed/0x7b0 mm/readahead.c:226
2 locks held by kworker/u4:7/4329:
2 locks held by kworker/u4:12/4411:
1 lock held by syz-executor/5315:
#0: ffff88802f8f40e0 (&type->s_umount_key#58){+.+.}-{3:3}, at: deactivate_super+0xa9/0xe0 fs/super.c:362
2 locks held by kworker/1:20/6772:
#0: ffff888017c72138 ((wq_completion)rcu_gp){+.+.}-{0:0}, at: process_one_work+0x7a9/0x11d0 kernel/workqueue.c:2267
#1: ffffc900047f7d20 ((work_completion)(&rew->rew_work)){+.+.}-{0:0}, at: process_one_work+0x7a9/0x11d0 kernel/workqueue.c:2267
1 lock held by dhcpcd/7340:
#0: ffff888074dd2610 (&sb->s_type->i_mutex_key#10){+.+.}-{3:3}, at: inode_lock include/linux/fs.h:758 [inline]
#0: ffff888074dd2610 (&sb->s_type->i_mutex_key#10){+.+.}-{3:3}, at: __sock_release net/socket.c:653 [inline]
#0: ffff888074dd2610 (&sb->s_type->i_mutex_key#10){+.+.}-{3:3}, at: sock_close+0x98/0x230 net/socket.c:1400
1 lock held by dhcpcd/7341:
#0: ffff888075fa2130 (sk_lock-AF_PACKET){+.+.}-{0:0}, at: lock_sock include/net/sock.h:1756 [inline]
#0: ffff888075fa2130 (sk_lock-AF_PACKET){+.+.}-{0:0}, at: packet_do_bind+0x32/0xd00 net/packet/af_packet.c:3249
2 locks held by dhcpcd/7342:
#0: ffff888075370130 (sk_lock-AF_PACKET){+.+.}-{0:0}, at: lock_sock include/net/sock.h:1756 [inline]
#0: ffff888075370130 (sk_lock-AF_PACKET){+.+.}-{0:0}, at: packet_do_bind+0x32/0xd00 net/packet/af_packet.c:3249
#1: ffffffff8d3306b8 (rcu_state.exp_mutex){+.+.}-{3:3}, at: exp_funnel_lock kernel/rcu/tree_exp.h:323 [inline]
#1: ffffffff8d3306b8 (rcu_state.exp_mutex){+.+.}-{3:3}, at: synchronize_rcu_expedited+0x360/0x930 kernel/rcu/tree_exp.h:962
2 locks held by dhcpcd/7343:
#0: ffff88806507c130 (sk_lock-AF_PACKET){+.+.}-{0:0}, at: lock_sock include/net/sock.h:1756 [inline]
#0: ffff88806507c130 (sk_lock-AF_PACKET){+.+.}-{0:0}, at: packet_do_bind+0x32/0xd00 net/packet/af_packet.c:3249
#1: ffffffff8d3306b8 (rcu_state.exp_mutex){+.+.}-{3:3}, at: exp_funnel_lock kernel/rcu/tree_exp.h:323 [inline]
#1: ffffffff8d3306b8 (rcu_state.exp_mutex){+.+.}-{3:3}, at: synchronize_rcu_expedited+0x360/0x930 kernel/rcu/tree_exp.h:962
1 lock held by dhcpcd/7344:
#0: ffff888075372130 (sk_lock-AF_PACKET){+.+.}-{0:0}, at: lock_sock include/net/sock.h:1756 [inline]
#0: ffff888075372130 (sk_lock-AF_PACKET){+.+.}-{0:0}, at: packet_do_bind+0x32/0xd00 net/packet/af_packet.c:3249
1 lock held by dhcpcd/7345:
#0: ffff88806507e130 (sk_lock-AF_PACKET){+.+.}-{0:0}, at: lock_sock include/net/sock.h:1756 [inline]
#0: ffff88806507e130 (sk_lock-AF_PACKET){+.+.}-{0:0}, at: packet_do_bind+0x32/0xd00 net/packet/af_packet.c:3249
1 lock held by dhcpcd/7346:
#0: ffff888024a22130 (sk_lock-AF_PACKET){+.+.}-{0:0}, at: lock_sock include/net/sock.h:1756 [inline]
#0: ffff888024a22130 (sk_lock-AF_PACKET){+.+.}-{0:0}, at: packet_do_bind+0x32/0xd00 net/packet/af_packet.c:3249
1 lock held by dhcpcd/7347:
#0: ffff888024a24130 (sk_lock-AF_PACKET){+.+.}-{0:0}, at: lock_sock include/net/sock.h:1756 [inline]
#0: ffff888024a24130 (sk_lock-AF_PACKET){+.+.}-{0:0}, at: packet_do_bind+0x32/0xd00 net/packet/af_packet.c:3249
1 lock held by dhcpcd/7348:
#0: ffff8880783ca130 (sk_lock-AF_PACKET){+.+.}-{0:0}, at: lock_sock include/net/sock.h:1756 [inline]
#0: ffff8880783ca130 (sk_lock-AF_PACKET){+.+.}-{0:0}, at: packet_do_bind+0x32/0xd00 net/packet/af_packet.c:3249
1 lock held by dhcpcd/7349:
#0: ffff8880783cc130 (sk_lock-AF_PACKET){+.+.}-{0:0}, at: lock_sock include/net/sock.h:1756 [inline]
#0: ffff8880783cc130 (sk_lock-AF_PACKET){+.+.}-{0:0}, at: packet_do_bind+0x32/0xd00 net/packet/af_packet.c:3249
1 lock held by dhcpcd/7350:
#0: ffff888075374130 (sk_lock-AF_PACKET){+.+.}-{0:0}, at: lock_sock include/net/sock.h:1756 [inline]
#0: ffff888075374130 (sk_lock-AF_PACKET){+.+.}-{0:0}, at: packet_do_bind+0x32/0xd00 net/packet/af_packet.c:3249
1 lock held by dhcpcd/7351:
#0: ffff888025032130 (sk_lock-AF_PACKET){+.+.}-{0:0}, at: lock_sock include/net/sock.h:1756 [inline]
#0: ffff888025032130 (sk_lock-AF_PACKET){+.+.}-{0:0}, at: packet_do_bind+0x32/0xd00 net/packet/af_packet.c:3249
1 lock held by dhcpcd/7352:
#0: ffff888075376130 (sk_lock-AF_PACKET){+.+.}-{0:0}, at: lock_sock include/net/sock.h:1756 [inline]
#0: ffff888075376130 (sk_lock-AF_PACKET){+.+.}-{0:0}, at: packet_do_bind+0x32/0xd00 net/packet/af_packet.c:3249
1 lock held by dhcpcd/7353:
#0: ffff888028a20130 (sk_lock-AF_PACKET){+.+.}-{0:0}, at: lock_sock include/net/sock.h:1756 [inline]
#0: ffff888028a20130 (sk_lock-AF_PACKET){+.+.}-{0:0}, at: packet_do_bind+0x32/0xd00 net/packet/af_packet.c:3249
1 lock held by dhcpcd/7356:
#0: ffff888056998130 (sk_lock-AF_PACKET){+.+.}-{0:0}, at: lock_sock include/net/sock.h:1756 [inline]
#0: ffff888056998130 (sk_lock-AF_PACKET){+.+.}-{0:0}, at: packet_do_bind+0x32/0xd00 net/packet/af_packet.c:3249

=============================================

NMI backtrace for cpu 1
CPU: 1 PID: 28 Comm: khungtaskd Not tainted 6.1.127-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 12/27/2024
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:88 [inline]
dump_stack_lvl+0x1e3/0x2cb lib/dump_stack.c:106
nmi_cpu_backtrace+0x4e1/0x560 lib/nmi_backtrace.c:111
nmi_trigger_cpumask_backtrace+0x1ae/0x3f0 lib/nmi_backtrace.c:62
trigger_all_cpu_backtrace include/linux/nmi.h:148 [inline]
check_hung_uninterruptible_tasks kernel/hung_task.c:220 [inline]
watchdog+0xf88/0xfd0 kernel/hung_task.c:377
kthread+0x28d/0x320 kernel/kthread.c:376
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295
</TASK>
Sending NMI from CPU 1 to CPUs 0:
NMI backtrace for cpu 0
CPU: 0 PID: 4585 Comm: udevd Not tainted 6.1.127-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 12/27/2024
RIP: 0010:psi_task_switch+0x0/0x790 kernel/sched/psi.c:930
Code: c7 c7 c0 47 1f 8d e8 5f ff 06 03 48 8b 34 24 48 ba 00 00 00 00 00 fc ff df e9 dd f5 ff ff 66 2e 0f 1f 84 00 00 00 00 00 66 90 <55> 41 57 41 56 41 55 41 54 53 48 83 ec 38 41 89 d7 48 89 f5 49 89
RSP: 0018:ffffc900055af838 EFLAGS: 00000046
RAX: 0000000000000001 RBX: ffff88801e730068 RCX: dffffc0000000000
RDX: 0000000000000000 RSI: ffff888028053b80 RDI: ffff88801e730000
RBP: ffffc900055af9f0 R08: dffffc0000000000 R09: ffffed1003ce6001
R10: 0000000000000000 R11: dffffc0000000001 R12: dffffc0000000000
R13: 1ffff11003ce6052 R14: ffff88801e730290 R15: ffff888028053b80
FS: 00007f56456b8c80(0000) GS:ffff8880b8e00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fa584d78ab8 CR3: 00000000593bf000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<NMI>
</NMI>
<TASK>
psi_sched_switch kernel/sched/stats.h:203 [inline]
__schedule+0x2068/0x4570 kernel/sched/core.c:6553
preempt_schedule_common+0x83/0xd0 kernel/sched/core.c:6727
preempt_schedule+0xd9/0xe0 kernel/sched/core.c:6751
preempt_schedule_thunk+0x16/0x18 arch/x86/entry/thunk_64.S:34
__slab_alloc mm/slub.c:3281 [inline]
slab_alloc_node mm/slub.c:3364 [inline]
__kmem_cache_alloc_node+0x1c6/0x260 mm/slub.c:3437
__do_kmalloc_node mm/slab_common.c:935 [inline]
__kmalloc_node+0xa2/0x230 mm/slab_common.c:943
kmalloc_node include/linux/slab.h:589 [inline]
kvmalloc_node+0x6e/0x180 mm/util.c:581
kvmalloc include/linux/slab.h:716 [inline]
seq_buf_alloc fs/seq_file.c:38 [inline]
seq_read_iter+0x1fe/0xd10 fs/seq_file.c:210
call_read_iter include/linux/fs.h:2259 [inline]
new_sync_read fs/read_write.c:389 [inline]
vfs_read+0x88d/0xbf0 fs/read_write.c:470
ksys_read+0x19c/0x2c0 fs/read_write.c:613
do_syscall_x64 arch/x86/entry/common.c:51 [inline]
do_syscall_64+0x3b/0xb0 arch/x86/entry/common.c:81
entry_SYSCALL_64_after_hwframe+0x68/0xd2
RIP: 0033:0x7f5645316b6a
Code: 00 3d 00 00 41 00 75 0d 50 48 8d 3d 2d 08 0a 00 e8 ea 7d 01 00 31 c0 e9 07 ff ff ff 64 8b 04 25 18 00 00 00 85 c0 75 1b 0f 05 <48> 3d 00 f0 ff ff 76 6c 48 8b 15 8f a2 0d 00 f7 d8 64 89 02 48 83
RSP: 002b:00007ffe6aecbce8 EFLAGS: 00000246 ORIG_RAX: 0000000000000000
RAX: ffffffffffffffda RBX: 00005583095935c0 RCX: 00007f5645316b6a
RDX: 0000000000001000 RSI: 0000558309682790 RDI: 0000000000000009
RBP: 00005583095935c0 R08: 0000000000000009 R09: 0000000000000008
R10: 000000000000010f R11: 0000000000000246 R12: 0000000000000000
R13: 0000000000003fff R14: 00007ffe6aecc1c8 R15: 000000000000000a

syzbot

unread,
Jan 28, 2025, 6:40:23 AM1/28/25
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 75cefdf153f5 Linux 6.1.127
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=10c6cddf980000
kernel config: https://syzkaller.appspot.com/x/.config?x=3dc848f1f9c50685
dashboard link: https://syzkaller.appspot.com/bug?extid=225be6e3832c203b8460
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=14c6cddf980000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=109a6e24580000
mounted in repro: https://storage.googleapis.com/syzbot-assets/243b4c8a4b6c/mount_0.gz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+225be6...@syzkaller.appspotmail.com

INFO: task syz-executor634:4271 blocked for more than 143 seconds.
Not tainted 6.1.127-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:syz-executor634 state:D stack:23880 pid:4271 ppid:4269 flags:0x00004002
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5241 [inline]
__schedule+0x143f/0x4570 kernel/sched/core.c:6558
schedule+0xbf/0x180 kernel/sched/core.c:6634
io_schedule+0x88/0x100 kernel/sched/core.c:8786
folio_wait_bit_common+0x878/0x1290 mm/filemap.c:1324
truncate_inode_pages_range+0xbb5/0x1340 mm/truncate.c:422
evict+0x53c/0x930 fs/inode.c:707
dispose_list fs/inode.c:738 [inline]
evict_inodes+0x668/0x700 fs/inode.c:792
generic_shutdown_super+0x94/0x340 fs/super.c:480
kill_block_super+0x7a/0xe0 fs/super.c:1470
deactivate_locked_super+0xa0/0x110 fs/super.c:332
cleanup_mnt+0x490/0x520 fs/namespace.c:1186
task_work_run+0x246/0x300 kernel/task_work.c:203
resume_user_mode_work include/linux/resume_user_mode.h:49 [inline]
exit_to_user_mode_loop+0xde/0x100 kernel/entry/common.c:177
exit_to_user_mode_prepare+0xb1/0x140 kernel/entry/common.c:210
__syscall_exit_to_user_mode_work kernel/entry/common.c:292 [inline]
syscall_exit_to_user_mode+0x60/0x270 kernel/entry/common.c:303
do_syscall_64+0x47/0xb0 arch/x86/entry/common.c:87
entry_SYSCALL_64_after_hwframe+0x68/0xd2
RIP: 0033:0x7fe99532a407
RSP: 002b:00007ffcf55844f8 EFLAGS: 00000202 ORIG_RAX: 00000000000000a6
RAX: 0000000000000000 RBX: 0000000000000000 RCX: 00007fe99532a407
RDX: 0000000000000000 RSI: 0000000000000009 RDI: 00007ffcf55845b0
RBP: 00007ffcf55845b0 R08: 0000000000000000 R09: 0000000000000000
R10: 00000000ffffffff R11: 0000000000000202 R12: 00007ffcf5585610
R13: 0000555577b446c0 R14: 0000000000000001 R15: 431bde82d7b634db
</TASK>

Showing all locks held in the system:
1 lock held by rcu_tasks_kthre/12:
#0: ffffffff8d32b290 (rcu_tasks.tasks_gp_mutex){+.+.}-{3:3}, at: rcu_tasks_one_gp+0x29/0xe30 kernel/rcu/tasks.h:517
1 lock held by rcu_tasks_trace/13:
#0: ffffffff8d32ba90 (rcu_tasks_trace.tasks_gp_mutex){+.+.}-{3:3}, at: rcu_tasks_one_gp+0x29/0xe30 kernel/rcu/tasks.h:517
1 lock held by khungtaskd/28:
#0: ffffffff8d32b0c0 (rcu_read_lock){....}-{1:2}, at: rcu_lock_acquire include/linux/rcupdate.h:350 [inline]
#0: ffffffff8d32b0c0 (rcu_read_lock){....}-{1:2}, at: rcu_read_lock include/linux/rcupdate.h:791 [inline]
#0: ffffffff8d32b0c0 (rcu_read_lock){....}-{1:2}, at: debug_show_all_locks+0x51/0x290 kernel/locking/lockdep.c:6510
2 locks held by getty/4019:
#0: ffff8880311a6098 (&tty->ldisc_sem){++++}-{0:0}, at: tty_ldisc_ref_wait+0x21/0x70 drivers/tty/tty_ldisc.c:244
#1: ffffc9000325e2f0 (&ldata->atomic_read_lock){+.+.}-{3:3}, at: n_tty_read+0x6a7/0x1db0 drivers/tty/n_tty.c:2198
1 lock held by syz-executor634/4271:
#0: ffff8880310220e0 (&type->s_umount_key#42){+.+.}-{3:3}, at: deactivate_super+0xa9/0xe0 fs/super.c:362

=============================================

NMI backtrace for cpu 1
CPU: 1 PID: 28 Comm: khungtaskd Not tainted 6.1.127-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 12/27/2024
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:88 [inline]
dump_stack_lvl+0x1e3/0x2cb lib/dump_stack.c:106
nmi_cpu_backtrace+0x4e1/0x560 lib/nmi_backtrace.c:111
nmi_trigger_cpumask_backtrace+0x1ae/0x3f0 lib/nmi_backtrace.c:62
trigger_all_cpu_backtrace include/linux/nmi.h:148 [inline]
check_hung_uninterruptible_tasks kernel/hung_task.c:220 [inline]
watchdog+0xf88/0xfd0 kernel/hung_task.c:377
kthread+0x28d/0x320 kernel/kthread.c:376
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295
</TASK>
Sending NMI from CPU 1 to CPUs 0:
NMI backtrace for cpu 0
CPU: 0 PID: 11 Comm: kworker/u4:1 Not tainted 6.1.127-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 12/27/2024
Workqueue: events_unbound toggle_allocation_gate
RIP: 0010:__mutex_lock+0x95/0xd80 kernel/locking/mutex.c:746
Code: 00 c0 e3 bb 8a 48 8d 84 24 80 00 00 00 48 c1 e8 03 42 c7 04 20 f1 f1 f1 f1 42 c7 44 20 09 f3 f3 f3 f3 66 42 c7 44 20 0d f3 f3 <48> 89 44 24 28 42 c6 44 20 0f f3 ba 28 00 00 00 31 f6 e8 d4 4c 26
RSP: 0018:ffffc900001079a0 EFLAGS: 00000a06
RAX: 1ffff92000020f44 RBX: 0000000000000000 RCX: 0000000000000000
RDX: 0000000000000000 RSI: 0000000000000002 RDI: ffffc90000107a40
RBP: ffffc90000107af0 R08: ffffffff8131107e R09: fffff52000020f41
R10: 0000000000000000 R11: dffffc0000000001 R12: dffffc0000000000
R13: ffffffff8d1dd380 R14: 0000000000000000 R15: ffffffff973bcf20
FS: 0000000000000000(0000) GS:ffff8880b8e00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000055f1fedcb600 CR3: 000000000d08e000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<NMI>
</NMI>
<TASK>
arch_jump_label_transform_apply+0xe/0x20 arch/x86/kernel/jump_label.c:145
static_key_disable_cpuslocked+0xce/0x1b0 kernel/jump_label.c:237
static_key_disable+0x16/0x20 kernel/jump_label.c:245
toggle_allocation_gate+0x3e0/0x480 mm/kfence/core.c:818
process_one_work+0x8a9/0x11d0 kernel/workqueue.c:2292
worker_thread+0xa47/0x1200 kernel/workqueue.c:2439
kthread+0x28d/0x320 kernel/kthread.c:376
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295
</TASK>


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

syzbot

unread,
Feb 2, 2025, 1:05:26 PM2/2/25
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: c16c81c81336 Linux 5.15.178
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=11f86d18580000
kernel config: https://syzkaller.appspot.com/x/.config?x=d302c69e93fb6774
dashboard link: https://syzkaller.appspot.com/bug?extid=c6778d0597c63956b321
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=136f1724580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=15f86d18580000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/267e46ee7273/disk-c16c81c8.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/944e289206cf/vmlinux-c16c81c8.xz
kernel image: https://storage.googleapis.com/syzbot-assets/f8cadf62458e/bzImage-c16c81c8.xz
mounted in repro: https://storage.googleapis.com/syzbot-assets/010a358f3581/mount_0.gz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+c6778d...@syzkaller.appspotmail.com

INFO: task syz-executor360:4180 blocked for more than 143 seconds.
Not tainted 5.15.178-syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:syz-executor360 state:D stack:24352 pid: 4180 ppid: 4178 flags:0x00004002
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5027 [inline]
__schedule+0x12c4/0x45b0 kernel/sched/core.c:6373
schedule+0x11b/0x1f0 kernel/sched/core.c:6456
io_schedule+0x88/0x100 kernel/sched/core.c:8481
wait_on_page_bit_common+0xa13/0x1180 mm/filemap.c:1356
lock_page include/linux/pagemap.h:625 [inline]
truncate_inode_pages_range+0xc17/0x1290 mm/truncate.c:394
evict+0x53c/0x930 fs/inode.c:624
dispose_list fs/inode.c:655 [inline]
evict_inodes+0x668/0x700 fs/inode.c:709
generic_shutdown_super+0x94/0x310 fs/super.c:454
kill_block_super+0x7a/0xe0 fs/super.c:1427
deactivate_locked_super+0xa0/0x110 fs/super.c:335
cleanup_mnt+0x44e/0x500 fs/namespace.c:1143
task_work_run+0x129/0x1a0 kernel/task_work.c:188
tracehook_notify_resume include/linux/tracehook.h:189 [inline]
exit_to_user_mode_loop+0x106/0x130 kernel/entry/common.c:181
exit_to_user_mode_prepare+0xb1/0x140 kernel/entry/common.c:214
__syscall_exit_to_user_mode_work kernel/entry/common.c:296 [inline]
syscall_exit_to_user_mode+0x5d/0x240 kernel/entry/common.c:307
do_syscall_64+0x47/0xb0 arch/x86/entry/common.c:86
entry_SYSCALL_64_after_hwframe+0x66/0xd0
RIP: 0033:0x7f15ffea8407
RSP: 002b:00007ffe5ad57c68 EFLAGS: 00000202 ORIG_RAX: 00000000000000a6
RAX: 0000000000000000 RBX: 0000000000000000 RCX: 00007f15ffea8407
RDX: 0000000000000000 RSI: 0000000000000009 RDI: 00007ffe5ad57d20
RBP: 00007ffe5ad57d20 R08: 0000000000000000 R09: 0000000000000000
R10: 00000000ffffffff R11: 0000000000000202 R12: 00007ffe5ad58d80
R13: 0000555569faf6c0 R14: 0000000000000001 R15: 431bde82d7b634db
</TASK>

Showing all locks held in the system:
1 lock held by khungtaskd/27:
#0: ffffffff8cb1fce0 (rcu_read_lock){....}-{1:2}, at: rcu_lock_acquire+0x0/0x30
2 locks held by getty/3929:
#0: ffff88814d05b098 (&tty->ldisc_sem){++++}-{0:0}, at: tty_ldisc_ref_wait+0x21/0x70 drivers/tty/tty_ldisc.c:252
#1: ffffc90002cd62e8 (&ldata->atomic_read_lock){+.+.}-{3:3}, at: n_tty_read+0x6af/0x1db0 drivers/tty/n_tty.c:2158
1 lock held by syz-executor360/4180:
#0: ffff88802aab60e0 (&type->s_umount_key#43){+.+.}-{3:3}, at: deactivate_super+0xa9/0xe0 fs/super.c:365

=============================================

NMI backtrace for cpu 1
CPU: 1 PID: 27 Comm: khungtaskd Not tainted 5.15.178-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 12/27/2024
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:88 [inline]
dump_stack_lvl+0x1e3/0x2d0 lib/dump_stack.c:106
nmi_cpu_backtrace+0x46a/0x4a0 lib/nmi_backtrace.c:111
nmi_trigger_cpumask_backtrace+0x181/0x2a0 lib/nmi_backtrace.c:62
trigger_all_cpu_backtrace include/linux/nmi.h:148 [inline]
check_hung_uninterruptible_tasks kernel/hung_task.c:210 [inline]
watchdog+0xe72/0xeb0 kernel/hung_task.c:295
kthread+0x3f6/0x4f0 kernel/kthread.c:334
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:287
</TASK>
Sending NMI from CPU 1 to CPUs 0:
NMI backtrace for cpu 0 skipped: idling at native_safe_halt arch/x86/include/asm/irqflags.h:51 [inline]
NMI backtrace for cpu 0 skipped: idling at arch_safe_halt arch/x86/include/asm/irqflags.h:89 [inline]
NMI backtrace for cpu 0 skipped: idling at acpi_safe_halt drivers/acpi/processor_idle.c:108 [inline]
NMI backtrace for cpu 0 skipped: idling at acpi_idle_do_entry+0x10f/0x340 drivers/acpi/processor_idle.c:562

syzbot

unread,
May 18, 2025, 8:30:04 PM5/18/25
to syzkaller...@googlegroups.com
syzbot suspects this issue could be fixed by backporting the following commit:

commit 5641371fd0b3703d11809a0ae249aed270cb8add
git tree: upstream
Author: Matthew Wilcox (Oracle) <wi...@infradead.org>
Date: Fri Dec 20 22:46:27 2024 +0000

squashfs; convert squashfs_copy_cache() to take a folio

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=14d9c1f4580000
Please keep in mind that other backports might be required as well.

For information about bisection process see: https://goo.gl/tpsmEJ#bisection
Reply all
Reply to author
Forward
0 new messages