INFO: task hung in tp_perf_event_destroy

10 views
Skip to first unread message

syzbot

unread,
Sep 11, 2018, 9:52:04 PM9/11/18
to syzkaller-upst...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: a49a9dcce802 Merge tag 'drm-fixes-2018-09-07' of git://ano..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=106e877a400000
kernel config: https://syzkaller.appspot.com/x/.config?x=6c9564cd177daf0c
dashboard link: https://syzkaller.appspot.com/bug?extid=4ed603af5e796994bab9
compiler: gcc (GCC) 8.0.1 20180413 (experimental)
CC: [linux-...@vger.kernel.org mi...@redhat.com
ros...@goodmis.org]

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+4ed603...@syzkaller.appspotmail.com

RAX: ffffffffffffffda RBX: 00007f2bf25e96d4 RCX: 0000000000457099
RDX: 0000000000000001 RSI: 0000000020004740 RDI: 0000000000000004
RBP: 00000000009300a0 R08: 0000000020004840 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000005
R13: 00000000004d42d8 R14: 00000000004c8ad2 R15: 0000000000000000
INFO: task syz-executor6:8829 blocked for more than 140 seconds.
Not tainted 4.19.0-rc2+ #226
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
syz-executor6 D24488 8829 4275 0x00000004
Call Trace:
context_switch kernel/sched/core.c:2825 [inline]
__schedule+0x87c/0x1df0 kernel/sched/core.c:3473
schedule+0xfb/0x450 kernel/sched/core.c:3517
schedule_preempt_disabled+0x10/0x20 kernel/sched/core.c:3575
__mutex_lock_common kernel/locking/mutex.c:1003 [inline]
__mutex_lock+0xbf9/0x1700 kernel/locking/mutex.c:1073
mutex_lock_nested+0x16/0x20 kernel/locking/mutex.c:1088
perf_trace_destroy+0x28/0x100 kernel/trace/trace_event_perf.c:236
tp_perf_event_destroy+0x15/0x20 kernel/events/core.c:8329
_free_event+0x414/0x15e0 kernel/events/core.c:4445
put_event+0x48/0x60 kernel/events/core.c:4531
perf_event_release_kernel+0x8d1/0xfc0 kernel/events/core.c:4637
perf_release+0x37/0x50 kernel/events/core.c:4647
__fput+0x38a/0xa40 fs/file_table.c:278
____fput+0x15/0x20 fs/file_table.c:309
task_work_run+0x1e8/0x2a0 kernel/task_work.c:113
tracehook_notify_resume include/linux/tracehook.h:193 [inline]
exit_to_usermode_loop+0x318/0x380 arch/x86/entry/common.c:166
prepare_exit_to_usermode arch/x86/entry/common.c:197 [inline]
syscall_return_slowpath arch/x86/entry/common.c:268 [inline]
do_syscall_64+0x6be/0x820 arch/x86/entry/common.c:293
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x410c51
Code: 0f ba e3 00 0f 82 dd fb ff ff 49 ff c0 49 83 e0 fe e9 d1 fb ff ff 48
81 fb f8 03 00 00 0f 87 01 01 00 00 4c 8d 43 07 49 c1 e8 <03> 49 81 f8 81
00 00 00 0f 83 3d 02 00 00 4c 8d 0d da 64 75 00 47
RSP: 002b:00007ffecfb0d2b0 EFLAGS: 00000293 ORIG_RAX: 0000000000000003
RAX: 0000000000000000 RBX: 0000000000000004 RCX: 0000000000410c51
RDX: 0000001b2e720000 RSI: 0000000000000005 RDI: 0000000000000003
RBP: 0000000000000000 R08: 00000000000003e7 R09: 0000000000000000
R10: 00007ffecfb0d1e0 R11: 0000000000000293 R12: 0000000000000006
R13: 000000000003e534 R14: 0000000000000042 R15: badc0ffeebadface

Showing all locks held in the system:
1 lock held by khungtaskd/791:
#0: 000000002c6e8ac4 (rcu_read_lock){....}, at:
debug_show_all_locks+0xd0/0x428 kernel/locking/lockdep.c:4436
1 lock held by rsyslogd/4130:
#0: 00000000ec59f6bf (&f->f_pos_lock){+.+.}, at: __fdget_pos+0x1bb/0x200
fs/file.c:766
2 locks held by getty/4221:
#0: 00000000d2876dc3 (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x37/0x40 drivers/tty/tty_ldsem.c:353
#1: 00000000f295900b (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x335/0x1ce0 drivers/tty/n_tty.c:2140
2 locks held by getty/4222:
#0: 000000005316dcc9 (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x37/0x40 drivers/tty/tty_ldsem.c:353
#1: 0000000048e45b55 (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x335/0x1ce0 drivers/tty/n_tty.c:2140
2 locks held by getty/4223:
#0: 000000001d0aedb9 (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x37/0x40 drivers/tty/tty_ldsem.c:353
#1: 00000000c45b0ac7 (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x335/0x1ce0 drivers/tty/n_tty.c:2140
2 locks held by getty/4224:
#0: 000000000f8c2a24 (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x37/0x40 drivers/tty/tty_ldsem.c:353
#1: 00000000ee7e6427 (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x335/0x1ce0 drivers/tty/n_tty.c:2140
2 locks held by getty/4225:
#0: 000000003fce8950 (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x37/0x40 drivers/tty/tty_ldsem.c:353
#1: 000000000688dc62 (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x335/0x1ce0 drivers/tty/n_tty.c:2140
2 locks held by getty/4226:
#0: 000000000d56fa95 (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x37/0x40 drivers/tty/tty_ldsem.c:353
#1: 000000001bcb17d0 (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x335/0x1ce0 drivers/tty/n_tty.c:2140
2 locks held by getty/4227:
#0: 00000000e3083624 (&tty->ldisc_sem){++++}, at:
ldsem_down_read+0x37/0x40 drivers/tty/tty_ldsem.c:353
#1: 00000000ab829469 (&ldata->atomic_read_lock){+.+.}, at:
n_tty_read+0x335/0x1ce0 drivers/tty/n_tty.c:2140
1 lock held by syz-executor7/6607:
#0: 0000000005d01d30 (&rp->fetch_lock){+.+.}, at: mon_bin_read+0x60/0x650
drivers/usb/mon/mon_bin.c:813
3 locks held by syz-executor4/8833:
1 lock held by syz-executor6/8829:
#0: 000000009b2eaf22 (event_mutex){+.+.}, at:
perf_trace_destroy+0x28/0x100 kernel/trace/trace_event_perf.c:236

=============================================

NMI backtrace for cpu 1
CPU: 1 PID: 791 Comm: khungtaskd Not tainted 4.19.0-rc2+ #226
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x1c9/0x2b4 lib/dump_stack.c:113
nmi_cpu_backtrace.cold.3+0x48/0x88 lib/nmi_backtrace.c:101
nmi_trigger_cpumask_backtrace+0x151/0x192 lib/nmi_backtrace.c:62
arch_trigger_cpumask_backtrace+0x14/0x20 arch/x86/kernel/apic/hw_nmi.c:38
trigger_all_cpu_backtrace include/linux/nmi.h:144 [inline]
check_hung_uninterruptible_tasks kernel/hung_task.c:204 [inline]
watchdog+0xb39/0x1040 kernel/hung_task.c:265
kthread+0x35a/0x420 kernel/kthread.c:246
ret_from_fork+0x3a/0x50 arch/x86/entry/entry_64.S:413
Sending NMI from CPU 1 to CPUs 0:
NMI backtrace for cpu 0 skipped: idling at native_safe_halt+0x6/0x10
arch/x86/include/asm/irqflags.h:57


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#bug-status-tracking for how to communicate with
syzbot.

syzbot

unread,
Dec 20, 2019, 3:11:06 PM12/20/19
to syzkaller-upst...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages