From: syzbot <syzbot+9b3fb64bcc8c1d807595@syzkaller.appspotmail.com>
To: elver@google.com, linux-fsdevel@vger.kernel.org,
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com,
viro@zeniv.linux.org.uk
Subject: KCSAN: data-race in poll_schedule_timeout.constprop.0 / pollwake (3)
Date: Tue, 17 Dec 2019 12:43:08 -0800 [thread overview]
Message-ID: <00000000000031cefb0599ec600b@google.com> (raw)
Hello,
syzbot found the following crash on:
HEAD commit: 245a4300 Merge branch 'rcu/kcsan' into tip/locking/kcsan
git tree: https://github.com/google/ktsan.git kcsan
console output: https://syzkaller.appspot.com/x/log.txt?x=11beba8ee00000
kernel config: https://syzkaller.appspot.com/x/.config?x=a38292766f8efdaa
dashboard link: https://syzkaller.appspot.com/bug?extid=9b3fb64bcc8c1d807595
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
Unfortunately, I don't have any reproducer for this crash yet.
IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+9b3fb64bcc8c1d807595@syzkaller.appspotmail.com
==================================================================
BUG: KCSAN: data-race in poll_schedule_timeout.constprop.0 / pollwake
write to 0xffffc90001043c30 of 4 bytes by task 17695 on cpu 0:
__pollwake fs/select.c:197 [inline]
pollwake+0xe3/0x140 fs/select.c:217
__wake_up_common+0x7b/0x180 kernel/sched/wait.c:93
__wake_up_common_lock+0x77/0xb0 kernel/sched/wait.c:123
__wake_up+0xe/0x10 kernel/sched/wait.c:142
signalfd_notify include/linux/signalfd.h:22 [inline]
signalfd_notify include/linux/signalfd.h:19 [inline]
__send_signal+0x70e/0x870 kernel/signal.c:1158
send_signal+0x224/0x2b0 kernel/signal.c:1236
__group_send_sig_info kernel/signal.c:1275 [inline]
do_notify_parent+0x55b/0x5e0 kernel/signal.c:1992
exit_notify kernel/exit.c:670 [inline]
do_exit+0x16ef/0x18c0 kernel/exit.c:818
do_group_exit+0xb4/0x1c0 kernel/exit.c:895
__do_sys_exit_group kernel/exit.c:906 [inline]
__se_sys_exit_group kernel/exit.c:904 [inline]
__x64_sys_exit_group+0x2e/0x30 kernel/exit.c:904
do_syscall_64+0xcc/0x3a0 arch/x86/entry/common.c:294
entry_SYSCALL_64_after_hwframe+0x44/0xa9
read to 0xffffc90001043c30 of 4 bytes by task 15995 on cpu 1:
poll_schedule_timeout.constprop.0+0x50/0xc0 fs/select.c:242
do_poll fs/select.c:951 [inline]
do_sys_poll+0x66d/0x990 fs/select.c:1001
__do_sys_poll fs/select.c:1059 [inline]
__se_sys_poll fs/select.c:1047 [inline]
__x64_sys_poll+0x10f/0x250 fs/select.c:1047
do_syscall_64+0xcc/0x3a0 arch/x86/entry/common.c:294
entry_SYSCALL_64_after_hwframe+0x44/0xa9
Reported by Kernel Concurrency Sanitizer on:
CPU: 1 PID: 15995 Comm: udevd Not tainted 5.5.0-rc1-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
==================================================================
---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.
syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
next reply other threads:[~2019-12-17 20:43 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2019-12-17 20:43 syzbot [this message]
2019-12-17 20:59 ` [PATCH] fs/select: Fix data races to pwq->triggered Marco Elver
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=00000000000031cefb0599ec600b@google.com \
--to=syzbot+9b3fb64bcc8c1d807595@syzkaller.appspotmail.com \
--cc=elver@google.com \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=syzkaller-bugs@googlegroups.com \
--cc=viro@zeniv.linux.org.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.