INFO: trying to register non-static key in dput

10 views
Skip to first unread message

syzbot

unread,
Jul 5, 2022, 11:10:28 PM7/5/22
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 3f8a27f9e27b Linux 4.19.211
git tree: linux-4.19.y
console output: https://syzkaller.appspot.com/x/log.txt?x=146f3410080000
kernel config: https://syzkaller.appspot.com/x/.config?x=9b9277b418617afe
dashboard link: https://syzkaller.appspot.com/bug?extid=98950cc9e13e69dc1413
compiler: gcc version 10.2.1 20210110 (Debian 10.2.1-6)

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+98950c...@syzkaller.appspotmail.com

netlink: 'syz-executor.0': attribute type 2 has an invalid length.
INFO: trying to register non-static key.
The code is fine but needs lockdep annotation, or maybe
you didn't initialize this object before use?
turning off the locking correctness validator.
CPU: 0 PID: 30688 Comm: systemd-udevd Not tainted 4.19.211-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/29/2022
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x1fc/0x2ef lib/dump_stack.c:118
assign_lock_key kernel/locking/lockdep.c:728 [inline]
register_lock_class+0xe82/0x11c0 kernel/locking/lockdep.c:754
__lock_acquire+0x17d/0x3ff0 kernel/locking/lockdep.c:3304
lock_acquire+0x170/0x3c0 kernel/locking/lockdep.c:3908
__raw_spin_lock include/linux/spinlock_api_smp.h:142 [inline]
_raw_spin_lock+0x2a/0x40 kernel/locking/spinlock.c:144
spin_lock include/linux/spinlock.h:329 [inline]
fast_dput fs/dcache.c:729 [inline]
dput+0x4c6/0x640 fs/dcache.c:833
__fput+0x415/0x890 fs/file_table.c:291
task_work_run+0x148/0x1c0 kernel/task_work.c:113
exit_task_work include/linux/task_work.h:22 [inline]
do_exit+0xbf3/0x2be0 kernel/exit.c:870
do_group_exit+0x125/0x310 kernel/exit.c:967
__do_sys_exit_group kernel/exit.c:978 [inline]
__se_sys_exit_group kernel/exit.c:976 [inline]
__x64_sys_exit_group+0x3a/0x50 kernel/exit.c:976
do_syscall_64+0xf9/0x620 arch/x86/entry/common.c:293
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x7f3b06032618
Code: Bad RIP value.
tmpfs: No value for mount option 'h� (%�'Q�'
RSP: 002b:00007ffecff1a778 EFLAGS: 00000212 ORIG_RAX: 00000000000000e7
RAX: ffffffffffffffda RBX: 00007ffecff1a840 RCX: 00007f3b06032618
RDX: 0000000000000000 RSI: 000000000000003c RDI: 0000000000000000
RBP: 00007ffecff1a8f0 R08: 00000000000000e7 R09: fffffffffffffe50
R10: 00000000ffffffff R11: 0000000000000212 R12: 0000000000000000
R13: 0000000000000000 R14: 0000000000000003 R15: 000000000000000e
==================================================================
BUG: KASAN: wild-memory-access in atomic_read include/asm-generic/atomic-instrumented.h:21 [inline]
BUG: KASAN: wild-memory-access in queued_spin_trylock include/asm-generic/qspinlock.h:69 [inline]
BUG: KASAN: wild-memory-access in do_raw_spin_trylock+0xf/0xe0 kernel/locking/spinlock_debug.c:119
Read of size 4 at addr 0007700000007788 by task systemd-udevd/30688

CPU: 0 PID: 30688 Comm: systemd-udevd Not tainted 4.19.211-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/29/2022
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x1fc/0x2ef lib/dump_stack.c:118
kasan_report_error.cold+0x15b/0x1b9 mm/kasan/report.c:352
kasan_report+0x8f/0xa0 mm/kasan/report.c:412
atomic_read include/asm-generic/atomic-instrumented.h:21 [inline]
queued_spin_trylock include/asm-generic/qspinlock.h:69 [inline]
do_raw_spin_trylock+0xf/0xe0 kernel/locking/spinlock_debug.c:119
audit: type=1800 audit(1657076968.182:35517): pid=30707 uid=0 auid=4294967295 ses=4294967295 subj==unconfined op=collect_data cause=failed comm="syz-executor.4" name="bus" dev="sda1" ino=15780 res=0
__raw_spin_trylock include/linux/spinlock_api_smp.h:89 [inline]
_raw_spin_trylock+0x18/0x70 kernel/locking/spinlock.c:128
spin_trylock include/linux/spinlock.h:339 [inline]
dentry_kill+0x52/0x510 fs/dcache.c:657
netlink: 'syz-executor.0': attribute type 2 has an invalid length.
dput+0x55f/0x640 fs/dcache.c:846
__fput+0x415/0x890 fs/file_table.c:291
task_work_run+0x148/0x1c0 kernel/task_work.c:113
exit_task_work include/linux/task_work.h:22 [inline]
do_exit+0xbf3/0x2be0 kernel/exit.c:870
do_group_exit+0x125/0x310 kernel/exit.c:967
__do_sys_exit_group kernel/exit.c:978 [inline]
__se_sys_exit_group kernel/exit.c:976 [inline]
__x64_sys_exit_group+0x3a/0x50 kernel/exit.c:976
do_syscall_64+0xf9/0x620 arch/x86/entry/common.c:293
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x7f3b06032618
Code: Bad RIP value.
RSP: 002b:00007ffecff1a778 EFLAGS: 00000212 ORIG_RAX: 00000000000000e7
RAX: ffffffffffffffda RBX: 00007ffecff1a840 RCX: 00007f3b06032618
RDX: 0000000000000000 RSI: 000000000000003c RDI: 0000000000000000
RBP: 00007ffecff1a8f0 R08: 00000000000000e7 R09: fffffffffffffe50
R10: 00000000ffffffff R11: 0000000000000212 R12: 0000000000000000
R13: 0000000000000000 R14: 0000000000000003 R15: 000000000000000e
==================================================================


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Nov 2, 2022, 11:10:30 PM11/2/22
to syzkaller...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages