Hello,
syzbot found the following crash on:
HEAD commit: 2c71d338bef2 Merge tag 'powerpc-4.17-6' of git://git.kerne..
git tree: upstream
console output:
https://syzkaller.appspot.com/x/log.txt?x=17c95f97800000
kernel config:
https://syzkaller.appspot.com/x/.config?x=f3b4e30da84ec1ed
dashboard link:
https://syzkaller.appspot.com/bug?extid=3b7e1dc1fb68c5e23648
compiler: gcc (GCC) 8.0.1 20180413 (experimental)
userspace arch: i386
CC: [
ak...@linux-foundation.org dan.j.w...@intel.com
hu...@google.com jgl...@redhat.com kirill....@linux.intel.com
linux-...@vger.kernel.org linu...@kvack.org mho...@suse.com
min...@kernel.org ross.z...@linux.intel.com ying....@intel.com]
Unfortunately, I don't have any reproducer for this crash yet.
IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by:
syzbot+3b7e1d...@syzkaller.appspotmail.com
watchdog: BUG: soft lockup - CPU#0 stuck for 22s! [syz-executor5:3657]
Modules linked in:
irq event stamp: 31502960
hardirqs last enabled at (31502959): [<ffffffff876ef357>]
__raw_spin_unlock_irq include/linux/spinlock_api_smp.h:168 [inline]
hardirqs last enabled at (31502959): [<ffffffff876ef357>]
_raw_spin_unlock_irq+0x27/0x70 kernel/locking/spinlock.c:192
hardirqs last disabled at (31502960): [<ffffffff87800905>]
interrupt_entry+0xb5/0xf0 arch/x86/entry/entry_64.S:625
softirqs last enabled at (23315220): [<ffffffff87a00778>]
__do_softirq+0x778/0xaf5 kernel/softirq.c:311
softirqs last disabled at (23315211): [<ffffffff81475281>] invoke_softirq
kernel/softirq.c:365 [inline]
softirqs last disabled at (23315211): [<ffffffff81475281>]
irq_exit+0x1d1/0x200 kernel/softirq.c:405
CPU: 0 PID: 3657 Comm: syz-executor5 Not tainted 4.17.0-rc5+ #82
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
RIP: 0010:__read_once_size include/linux/compiler.h:188 [inline]
RIP: 0010:__sanitizer_cov_trace_pc+0x3b/0x50 kernel/kcov.c:106
RSP: 0018:ffff88018d2cfa88 EFLAGS: 00000246 ORIG_RAX: ffffffffffffff13
RAX: 0000000000040000 RBX: ffff8801beb203c0 RCX: ffffc900052ca000
RDX: 000000000003ffff RSI: ffffffff81a66d0d RDI: ffffffff88392320
RBP: ffff88018d2cfa88 R08: ffff8801beb203c0 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: ffffffff88392320
R13: 00000000000002ae R14: 0000000000eef27e R15: 000000007ffff000
FS: 0000000000000000(0000) GS:ffff8801dae00000(0063) knlGS:00000000f5f7eb40
CS: 0010 DS: 002b ES: 002b CR0: 0000000080050033
CR2: 00000000f5f5cff0 CR3: 00000001a9fe3000 CR4: 00000000001406f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
get_current arch/x86/include/asm/current.h:15 [inline]
__might_fault+0x1d/0x1e0 mm/memory.c:4548
mousedev_write+0x1cb/0x840 drivers/input/mousedev.c:686
__vfs_write+0x10b/0x960 fs/read_write.c:485
vfs_write+0x1f8/0x560 fs/read_write.c:549
ksys_write+0xf9/0x250 fs/read_write.c:598
__do_sys_write fs/read_write.c:610 [inline]
__se_sys_write fs/read_write.c:607 [inline]
__ia32_sys_write+0x71/0xb0 fs/read_write.c:607
do_syscall_32_irqs_on arch/x86/entry/common.c:323 [inline]
do_fast_syscall_32+0x345/0xf9b arch/x86/entry/common.c:394
entry_SYSENTER_compat+0x70/0x7f arch/x86/entry/entry_64_compat.S:139
RIP: 0023:0xf7fa3cb9
RSP: 002b:00000000f5f7e0ac EFLAGS: 00000282 ORIG_RAX: 0000000000000004
RAX: ffffffffffffffda RBX: 000000000000001a RCX: 0000000020000040
RDX: 00000000ffffff32 RSI: 0000000000000000 RDI: 0000000000000000
RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000296 R12: 0000000000000000
R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000
Code: 7e 48 89 e5 81 e2 00 01 1f 00 48 8b 75 08 75 2b 8b 90 78 12 00 00 83
fa 02 75 20 48 8b 88 80 12 00 00 8b 80 7c 12 00 00 48 8b 11 <48> 83 c2 01
48 39 d0 76 07 48 89 34 d1 48 89 11 5d c3 0f 1f 00
Sending NMI from CPU 0 to CPUs 1:
NMI backtrace for cpu 1
CPU: 1 PID: 3612 Comm: syz-executor5 Not tainted 4.17.0-rc5+ #82
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
RIP: 0010:__lock_acquire+0x3d3/0x5140 kernel/locking/lockdep.c:3372
RSP: 0018:ffff8801b1aff5e0 EFLAGS: 00000806
RAX: dffffc0000000000 RBX: 000000000000058e RCX: 000000000000058e
RDX: 0000000000000000 RSI: ffff8801ac16adf8 RDI: ffffffff8a2a4288
RBP: ffff8801b1aff970 R08: 0000000000000001 R09: 0000000000000000
R10: ffff8801ac16adf8 R11: ffff8801ac16a5c0 R12: 0000000000000001
R13: 0000000000000000 R14: 0000000000000000 R15: ffff8801b1037e40
FS: 0000000000000000(0000) GS:ffff8801daf00000(0063) knlGS:00000000f5f9fb40
CS: 0010 DS: 002b ES: 002b CR0: 0000000080050033
CR2: ffffffffff600400 CR3: 00000001a9fe3000 CR4: 00000000001406e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
lock_acquire+0x1dc/0x520 kernel/locking/lockdep.c:3920
__raw_spin_lock_irq include/linux/spinlock_api_smp.h:128 [inline]
_raw_spin_lock_irq+0x5e/0x80 kernel/locking/spinlock.c:160
spin_lock_irq include/linux/spinlock.h:335 [inline]
mousedev_write+0x203/0x840 drivers/input/mousedev.c:689
__vfs_write+0x10b/0x960 fs/read_write.c:485
vfs_write+0x1f8/0x560 fs/read_write.c:549
ksys_write+0xf9/0x250 fs/read_write.c:598
__do_sys_write fs/read_write.c:610 [inline]
__se_sys_write fs/read_write.c:607 [inline]
__ia32_sys_write+0x71/0xb0 fs/read_write.c:607
do_syscall_32_irqs_on arch/x86/entry/common.c:323 [inline]
do_fast_syscall_32+0x345/0xf9b arch/x86/entry/common.c:394
entry_SYSENTER_compat+0x70/0x7f arch/x86/entry/entry_64_compat.S:139
RIP: 0023:0xf7fa3cb9
RSP: 002b:00000000f5f9f0ac EFLAGS: 00000282 ORIG_RAX: 0000000000000004
RAX: ffffffffffffffda RBX: 0000000000000016 RCX: 0000000020000040
RDX: 00000000ffffff32 RSI: 0000000000000000 RDI: 0000000000000000
RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000296 R12: 0000000000000000
R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000
Code: 00 00 00 89 d9 49 8d 42 20 66 81 e1 ff 1f 48 89 c2 48 89 84 24 80 00
00 00 48 b8 00 00 00 00 00 fc ff df 48 c1 ea 03 0f b6 14 02 <84> d2 74 09
80 fa 03 0f 8e 78 33 00 00 41 0f b7 42 20 49 8d 7a
---
This bug is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#bug-status-tracking for how to communicate with
syzbot.