Received: by 2002:ac0:a5b6:0:0:0:0:0 with SMTP id m51-v6csp4631064imm; Wed, 30 May 2018 09:02:17 -0700 (PDT) X-Google-Smtp-Source: ADUXVKK6c3FOCcngmb6484WMc635b/0xHgqKdPGwFD0GM0mpxRtlg0l7Y3rAlnvXMVmkEicZCLmd X-Received: by 2002:a17:902:b58e:: with SMTP id a14-v6mr3401540pls.261.1527696137346; Wed, 30 May 2018 09:02:17 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1527696137; cv=none; d=google.com; s=arc-20160816; b=LNjp7CY7Bk5r3S4/Q9jG9FLPyq9xCadutC6ZdGqpZ9W4g/F8YERxO68i0kToe3zeC2 amuad++wBrhE4K1zS8G+/6cYn0Z4am97dLCWqUfI+Crm2ZgjBrcGg4o4Bu+WnwitkkCI G8EiVSCoAtCd+P7M8JLjM9MLlNnENQ+fatEHyDUVOeyc3iNVG/yDXDdjFHyMXdAgGibC PA++FzoOVSUSnSLRoOS9xZE9roJOez5azLbi4gdB2JHuh0zKxfiqjws0mEnoGnHF2Yx7 wmw6KR3rCP7VBWjefBiMIMVHvgnY9ypSiDo/3K6pbpqfvYPcw4vuCNw/wRa12DKozQKW dnEw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding :content-language:in-reply-to:mime-version:user-agent:date :message-id:references:cc:to:subject:from:arc-authentication-results; bh=wjkXvntXYg/cCDrHhzsxxHNNIc+QlKEutMZquthcOxs=; b=DsgpqujKU3Xckt+WZ/K8e+qpvHhuFSNeIc/P1CJOvQaI+W1oqYNZ9m4oWSZ0DJzYUb n/9ZI1Ssd1DKRbRLYljCHpSi6FxmzBl8iKu5aX4qKmqDOvonMceLNhPDzw5urqtCNZRp OcGqDWA60jq/9lRJ6o3HVV0V7J9O9buS9b3xXOcc+CJXNCJKc8VeO8Xp1ztA+Evmaxyf uFIL3d8/Jey6Z1plGZHFmOjGsC8wSrvPu9CHXwX2FvzPHlY+l/o9O6OE8HIQ0SUTXozw iDvIX86ufr1tlyagfMaEKG59TvikjnyyZB0RvzvPVidQI3m+ZEqwtyZI9BhIQBnzmuHc axDw== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id p1-v6si34716180pfe.158.2018.05.30.09.02.00; Wed, 30 May 2018 09:02:17 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1753761AbeE3QBP (ORCPT + 99 others); Wed, 30 May 2018 12:01:15 -0400 Received: from www262.sakura.ne.jp ([202.181.97.72]:23683 "EHLO www262.sakura.ne.jp" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1753605AbeE3QBN (ORCPT ); Wed, 30 May 2018 12:01:13 -0400 Received: from fsav403.sakura.ne.jp (fsav403.sakura.ne.jp [133.242.250.102]) by www262.sakura.ne.jp (8.15.2/8.15.2) with ESMTP id w4UG0JnT064793; Thu, 31 May 2018 01:00:19 +0900 (JST) (envelope-from penguin-kernel@I-love.SAKURA.ne.jp) Received: from www262.sakura.ne.jp (202.181.97.72) by fsav403.sakura.ne.jp (F-Secure/fsigk_smtp/530/fsav403.sakura.ne.jp); Thu, 31 May 2018 01:00:19 +0900 (JST) X-Virus-Status: clean(F-Secure/fsigk_smtp/530/fsav403.sakura.ne.jp) Received: from [192.168.1.8] (softbank126074194044.bbtec.net [126.74.194.44]) (authenticated bits=0) by www262.sakura.ne.jp (8.15.2/8.15.2) with ESMTPSA id w4UG0Ats064729 (version=TLSv1.2 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 31 May 2018 01:00:19 +0900 (JST) (envelope-from penguin-kernel@I-love.SAKURA.ne.jp) From: Tetsuo Handa Subject: Re: general protection fault in wb_workfn (2) To: Jan Kara Cc: syzbot , syzkaller-bugs@googlegroups.com, linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, viro@zeniv.linux.org.uk, axboe@kernel.dk, tj@kernel.org, david@fromorbit.com, linux-block@vger.kernel.org References: <000000000000cbd959056d1851ca@google.com> <0c7c5dea-7312-8a59-9d1b-5467f69719bf@I-love.SAKURA.ne.jp> <20180528133503.awomzj6djozbo5bv@quack2.suse.cz> Message-ID: <2dda7a11-3f6b-bdba-a68a-7c0694806cc4@I-love.SAKURA.ne.jp> Date: Thu, 31 May 2018 01:00:08 +0900 User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; rv:52.0) Gecko/20100101 Thunderbird/52.8.0 MIME-Version: 1.0 In-Reply-To: <20180528133503.awomzj6djozbo5bv@quack2.suse.cz> Content-Type: text/plain; charset=utf-8 Content-Language: en-US Content-Transfer-Encoding: 7bit Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org So, we have no idea what is happening... Then, what about starting from temporary debug printk() patch shown below? >From 4f70f72ad3c9ae6ce1678024ef740aca4958e5b0 Mon Sep 17 00:00:00 2001 From: Tetsuo Handa Date: Wed, 30 May 2018 09:57:10 +0900 Subject: [PATCH] bdi: Add temporary config for debugging wb_workfn() versus bdi_unregister() race bug. syzbot is hitting NULL pointer dereference at wb_workfn() [1]. But due to limitations that syzbot cannot find reproducer for this bug (frequency is once or twice per a day) nor we can't capture vmcore in the environment which syzbot is using, for now we need to rely on printk() debugging. [1] https://syzkaller.appspot.com/bug?id=e0818ccb7e46190b3f1038b0c794299208ed4206 Signed-off-by: Tetsuo Handa --- block/Kconfig | 7 +++++++ fs/fs-writeback.c | 31 +++++++++++++++++++++++++++++++ 2 files changed, 38 insertions(+) diff --git a/block/Kconfig b/block/Kconfig index 28ec557..fbce13e 100644 --- a/block/Kconfig +++ b/block/Kconfig @@ -139,6 +139,13 @@ config BLK_CMDLINE_PARSER See Documentation/block/cmdline-partition.txt for more information. +config BLK_DEBUG_WB_WORKFN_RACE + bool "Dump upon hitting wb_workfn() versus bdi_unregister() race bug." + default n + ---help--- + This is a temporary option used for obtaining information for + specific bug. This option will be removed after the bug is fixed. + config BLK_WBT bool "Enable support for block device writeback throttling" default n diff --git a/fs/fs-writeback.c b/fs/fs-writeback.c index 471d863..b4dd078 100644 --- a/fs/fs-writeback.c +++ b/fs/fs-writeback.c @@ -1934,6 +1934,37 @@ void wb_workfn(struct work_struct *work) struct bdi_writeback, dwork); long pages_written; +#ifdef CONFIG_BLK_DEBUG_WB_WORKFN_RACE + if (!wb->bdi->dev) { + pr_warn("WARNING: %s: device is NULL\n", __func__); + pr_warn("wb->state=%lx\n", wb->state); + pr_warn("list_empty(&wb->work_list)=%u\n", + list_empty(&wb->work_list)); + if (!wb->bdi) + pr_warn("wb->bdi == NULL\n"); + else { + pr_warn("list_empty(&wb->bdi->bdi_list)=%u\n", + list_empty(&wb->bdi->bdi_list)); + pr_warn("wb->bdi->wb.state=%lx\n", wb->bdi->wb.state); + } + if (!wb->congested) + pr_warn("wb->congested == NULL\n"); +#ifdef CONFIG_CGROUP_WRITEBACK + else if (!wb->congested->__bdi) + pr_warn("wb->congested->__bdi == NULL\n"); + else { + pr_warn("(wb->congested->__bdi == wb->bdi)=%u\n", + wb->congested->__bdi == wb->bdi); + pr_warn("list_empty(&wb->congested->__bdi->bdi_list)=%u\n", + list_empty(&wb->congested->__bdi->bdi_list)); + pr_warn("wb->congested->__bdi->wb.state=%lx\n", + wb->congested->__bdi->wb.state); + } +#endif + /* Will halt shortly due to NULL pointer dereference... */ + } +#endif + set_worker_desc("flush-%s", dev_name(wb->bdi->dev)); current->flags |= PF_SWAPWRITE; -- 1.8.3.1