From: syzbot <syzbot+3b6f9218b1301ddda3e2@syzkaller.appspotmail.com>
To: dvyukov@google.com, jack@suse.com, jack@suse.cz,
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com,
syzkaller@googlegroups.com, tytso@mit.edu
Subject: Re: [syzbot] possible deadlock in dquot_commit
Date: Mon, 09 Aug 2021 05:54:27 -0700 [thread overview]
Message-ID: <000000000000aa4cd605c91fe2b3@google.com> (raw)
In-Reply-To: <000000000000a05b3b05baf9a856@google.com>
syzbot has found a reproducer for the following issue on:
HEAD commit: 66745863ecde Merge tag 'char-misc-5.14-rc5' of git://git.k..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=13edca6e300000
kernel config: https://syzkaller.appspot.com/x/.config?x=702bfdfbf389c324
dashboard link: https://syzkaller.appspot.com/bug?extid=3b6f9218b1301ddda3e2
compiler: Debian clang version 11.0.1-2, GNU ld (GNU Binutils for Debian) 2.35.1
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=15aeba6e300000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=17a609e6300000
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+3b6f9218b1301ddda3e2@syzkaller.appspotmail.com
loop0: detected capacity change from 0 to 4096
EXT4-fs (loop0): mounted filesystem without journal. Opts: ,errors=continue. Quota mode: writeback.
======================================================
WARNING: possible circular locking dependency detected
5.14.0-rc4-syzkaller #0 Not tainted
------------------------------------------------------
syz-executor211/9242 is trying to acquire lock:
ffff88803a37ece8 (&dquot->dq_lock){+.+.}-{3:3}, at: dquot_commit+0x57/0x360 fs/quota/dquot.c:474
but task is already holding lock:
ffff88803a303e48 (&ei->i_data_sem/2){++++}-{3:3}, at: ext4_map_blocks+0x9e5/0x1cb0 fs/ext4/inode.c:631
which lock already depends on the new lock.
the existing dependency chain (in reverse order) is:
-> #2 (&ei->i_data_sem/2){++++}-{3:3}:
lock_acquire+0x182/0x4a0 kernel/locking/lockdep.c:5625
down_read+0x3b/0x50 kernel/locking/rwsem.c:1353
ext4_map_blocks+0x266/0x1cb0 fs/ext4/inode.c:561
ext4_getblk+0x187/0x6c0 fs/ext4/inode.c:848
ext4_bread+0x2a/0x170 fs/ext4/inode.c:900
ext4_quota_write+0x2c7/0x5b0 fs/ext4/super.c:6602
write_blk fs/quota/quota_tree.c:64 [inline]
get_free_dqblk+0x33a/0x660 fs/quota/quota_tree.c:93
do_insert_tree+0x24c/0x1d30 fs/quota/quota_tree.c:300
do_insert_tree+0x659/0x1d30 fs/quota/quota_tree.c:331
do_insert_tree+0x659/0x1d30 fs/quota/quota_tree.c:331
do_insert_tree+0x659/0x1d30 fs/quota/quota_tree.c:331
dq_insert_tree fs/quota/quota_tree.c:357 [inline]
qtree_write_dquot+0x3b6/0x530 fs/quota/quota_tree.c:376
v2_write_dquot+0x110/0x1a0 fs/quota/quota_v2.c:358
dquot_acquire+0x2d7/0x5b0 fs/quota/dquot.c:441
ext4_acquire_dquot+0x2e0/0x400 fs/ext4/super.c:6261
dqget+0x999/0xdc0 fs/quota/dquot.c:899
__dquot_initialize+0x291/0xd40 fs/quota/dquot.c:1477
ext4_create+0xb0/0x550 fs/ext4/namei.c:2731
lookup_open fs/namei.c:3228 [inline]
open_last_lookups fs/namei.c:3298 [inline]
path_openat+0x13b7/0x36b0 fs/namei.c:3504
do_filp_open+0x253/0x4d0 fs/namei.c:3534
do_sys_openat2+0x124/0x460 fs/open.c:1204
do_sys_open fs/open.c:1220 [inline]
__do_sys_creat fs/open.c:1294 [inline]
__se_sys_creat fs/open.c:1288 [inline]
__x64_sys_creat+0x11f/0x160 fs/open.c:1288
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x44/0xae
-> #1 (&s->s_dquot.dqio_sem){++++}-{3:3}:
lock_acquire+0x182/0x4a0 kernel/locking/lockdep.c:5625
down_read+0x3b/0x50 kernel/locking/rwsem.c:1353
v2_read_dquot+0x4a/0x100 fs/quota/quota_v2.c:332
dquot_acquire+0x144/0x5b0 fs/quota/dquot.c:432
ext4_acquire_dquot+0x2e0/0x400 fs/ext4/super.c:6261
dqget+0x999/0xdc0 fs/quota/dquot.c:899
__dquot_initialize+0x291/0xd40 fs/quota/dquot.c:1477
ext4_create+0xb0/0x550 fs/ext4/namei.c:2731
lookup_open fs/namei.c:3228 [inline]
open_last_lookups fs/namei.c:3298 [inline]
path_openat+0x13b7/0x36b0 fs/namei.c:3504
do_filp_open+0x253/0x4d0 fs/namei.c:3534
do_sys_openat2+0x124/0x460 fs/open.c:1204
do_sys_open fs/open.c:1220 [inline]
__do_sys_creat fs/open.c:1294 [inline]
__se_sys_creat fs/open.c:1288 [inline]
__x64_sys_creat+0x11f/0x160 fs/open.c:1288
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x44/0xae
-> #0 (&dquot->dq_lock){+.+.}-{3:3}:
check_prev_add kernel/locking/lockdep.c:3051 [inline]
check_prevs_add+0x4f9/0x5b30 kernel/locking/lockdep.c:3174
validate_chain kernel/locking/lockdep.c:3789 [inline]
__lock_acquire+0x4476/0x6100 kernel/locking/lockdep.c:5015
lock_acquire+0x182/0x4a0 kernel/locking/lockdep.c:5625
__mutex_lock_common+0x1ad/0x3770 kernel/locking/mutex.c:959
__mutex_lock kernel/locking/mutex.c:1104 [inline]
mutex_lock_nested+0x1a/0x20 kernel/locking/mutex.c:1119
dquot_commit+0x57/0x360 fs/quota/dquot.c:474
ext4_write_dquot+0x1e4/0x2b0 fs/ext4/super.c:6245
mark_dquot_dirty fs/quota/dquot.c:345 [inline]
mark_all_dquot_dirty fs/quota/dquot.c:383 [inline]
__dquot_alloc_space+0xa18/0x1020 fs/quota/dquot.c:1707
dquot_alloc_space_nodirty include/linux/quotaops.h:297 [inline]
dquot_alloc_space include/linux/quotaops.h:310 [inline]
dquot_alloc_block include/linux/quotaops.h:334 [inline]
ext4_mb_new_blocks+0xe85/0x2470 fs/ext4/mballoc.c:5477
ext4_ext_map_blocks+0x2be3/0x7210 fs/ext4/extents.c:4245
ext4_map_blocks+0xab3/0x1cb0 fs/ext4/inode.c:638
_ext4_get_block+0x24b/0x710 fs/ext4/inode.c:794
ext4_block_write_begin+0x63a/0x1250 fs/ext4/inode.c:1077
ext4_write_begin+0x5cc/0x1350 fs/ext4/ext4_jbd2.h:498
ext4_da_write_begin+0x384/0x10c0 fs/ext4/inode.c:2960
generic_perform_write+0x262/0x580 mm/filemap.c:3656
ext4_buffered_write_iter+0x41c/0x590 fs/ext4/file.c:269
ext4_file_write_iter+0x8f7/0x1b90 fs/ext4/file.c:519
call_write_iter include/linux/fs.h:2114 [inline]
new_sync_write fs/read_write.c:518 [inline]
vfs_write+0xa39/0xc90 fs/read_write.c:605
ksys_write+0x171/0x2a0 fs/read_write.c:658
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x44/0xae
other info that might help us debug this:
Chain exists of:
&dquot->dq_lock --> &s->s_dquot.dqio_sem --> &ei->i_data_sem/2
Possible unsafe locking scenario:
CPU0 CPU1
---- ----
lock(&ei->i_data_sem/2);
lock(&s->s_dquot.dqio_sem);
lock(&ei->i_data_sem/2);
lock(&dquot->dq_lock);
*** DEADLOCK ***
4 locks held by syz-executor211/9242:
#0: ffff88802ff60460 (sb_writers#5){.+.+}-{0:0}, at: vfs_write+0x21b/0xc90 fs/read_write.c:601
#1: ffff88803a304058 (&sb->s_type->i_mutex_key#9){+.+.}-{3:3}, at: inode_lock include/linux/fs.h:774 [inline]
#1: ffff88803a304058 (&sb->s_type->i_mutex_key#9){+.+.}-{3:3}, at: ext4_buffered_write_iter+0xaf/0x590 fs/ext4/file.c:263
#2: ffff88803a303e48 (&ei->i_data_sem/2){++++}-{3:3}, at: ext4_map_blocks+0x9e5/0x1cb0 fs/ext4/inode.c:631
#3: ffffffff8c840518 (dquot_srcu){....}-{0:0}, at: rcu_lock_acquire+0x5/0x30 include/linux/rcupdate.h:266
stack backtrace:
CPU: 1 PID: 9242 Comm: syz-executor211 Not tainted 5.14.0-rc4-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:88 [inline]
dump_stack_lvl+0x1ae/0x29f lib/dump_stack.c:105
print_circular_bug+0xb17/0xdc0 kernel/locking/lockdep.c:2009
check_noncircular+0x2cc/0x390 kernel/locking/lockdep.c:2131
check_prev_add kernel/locking/lockdep.c:3051 [inline]
check_prevs_add+0x4f9/0x5b30 kernel/locking/lockdep.c:3174
validate_chain kernel/locking/lockdep.c:3789 [inline]
__lock_acquire+0x4476/0x6100 kernel/locking/lockdep.c:5015
lock_acquire+0x182/0x4a0 kernel/locking/lockdep.c:5625
__mutex_lock_common+0x1ad/0x3770 kernel/locking/mutex.c:959
__mutex_lock kernel/locking/mutex.c:1104 [inline]
mutex_lock_nested+0x1a/0x20 kernel/locking/mutex.c:1119
dquot_commit+0x57/0x360 fs/quota/dquot.c:474
ext4_write_dquot+0x1e4/0x2b0 fs/ext4/super.c:6245
mark_dquot_dirty fs/quota/dquot.c:345 [inline]
mark_all_dquot_dirty fs/quota/dquot.c:383 [inline]
__dquot_alloc_space+0xa18/0x1020 fs/quota/dquot.c:1707
dquot_alloc_space_nodirty include/linux/quotaops.h:297 [inline]
dquot_alloc_space include/linux/quotaops.h:310 [inline]
dquot_alloc_block include/linux/quotaops.h:334 [inline]
ext4_mb_new_blocks+0xe85/0x2470 fs/ext4/mballoc.c:5477
ext4_ext_map_blocks+0x2be3/0x7210 fs/ext4/extents.c:4245
ext4_map_blocks+0xab3/0x1cb0 fs/ext4/inode.c:638
_ext4_get_block+0x24b/0x710 fs/ext4/inode.c:794
ext4_block_write_begin+0x63a/0x1250 fs/ext4/inode.c:1077
ext4_write_begin+0x5cc/0x1350 fs/ext4/ext4_jbd2.h:498
ext4_da_write_begin+0x384/0x10c0 fs/ext4/inode.c:2960
generic_perform_write+0x262/0x580 mm/filemap.c:3656
ext4_buffered_write_iter+0x41c/0x590 fs/ext4/file.c:269
ext4_file_write_iter+0x8f7/0x1b90 fs/ext4/file.c:519
call_write_iter include/linux/fs.h:2114 [inline]
new_sync_write fs/read_write.c:518 [inline]
vfs_write+0xa39/0xc90 fs/read_write.c:605
ksys_write+0x171/0x2a0 fs/read_write.c:658
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x445219
Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 c0 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ffd8864cd18 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 00000000004885e9 RCX: 0000000000445219
RDX: 000000000d4ba0ff RSI: 00000000200009c0 RDI: 0000000000000003
RBP: 0000000020010500 R08: 00007ffd8864cd40 R09: 00007ffd8864cd40
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000020010000
R13: 0030656c69662f2e R14: 00007ffd8864cd50 R15: 000000000000004d
next prev parent reply other threads:[~2021-08-09 12:54 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-02-10 11:25 possible deadlock in dquot_commit syzbot
2021-02-11 11:37 ` Jan Kara
2021-02-11 11:47 ` Dmitry Vyukov
2021-02-11 15:47 ` Jan Kara
2021-02-11 21:46 ` Theodore Ts'o
2021-02-12 11:01 ` Dmitry Vyukov
2021-02-12 16:10 ` Theodore Ts'o
2021-02-15 12:50 ` Dmitry Vyukov
2021-08-09 12:54 ` syzbot [this message]
2021-08-09 14:52 ` [syzbot] " Jan Kara
2021-08-09 17:43 ` syzbot
2021-10-07 8:44 ` Jan Kara
2021-10-07 13:50 ` syzbot
[not found] ` <20210810041100.3271-1-hdanton@sina.com>
2021-08-10 9:21 ` Jan Kara
[not found] ` <20210811041232.2449-1-hdanton@sina.com>
2021-08-12 13:55 ` Jan Kara
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=000000000000aa4cd605c91fe2b3@google.com \
--to=syzbot+3b6f9218b1301ddda3e2@syzkaller.appspotmail.com \
--cc=dvyukov@google.com \
--cc=jack@suse.com \
--cc=jack@suse.cz \
--cc=linux-kernel@vger.kernel.org \
--cc=syzkaller-bugs@googlegroups.com \
--cc=syzkaller@googlegroups.com \
--cc=tytso@mit.edu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.