Re: [syzbot] [lsm?] [integrity?] possible deadlock in ima_file_truncate
Frederick Lawler <[email protected]>
| Newsgroups | org.kernel.vger.linux-security-module,org.kernel.vger.linux-integrity,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <cc5bsuwzvdoqrhgggqqb6qgkgh2cxymbupt4ghsi2msnudh4rf@slzwriyjykze> |
On Sat, Aug 08, 2026 at 05:20:29PM -0700, syzbot wrote: > Hello, > > syzbot found the following issue on: > > HEAD commit: c21bb4193868 Merge tag 'for_linus' of git://git.kernel.org.. > git tree: upstream > console output: https://syzkaller.appspot.com/x/log.txt?x=113c53b9580000 > kernel config: https://syzkaller.appspot.com/x/.config?x=145fa60d73086782 > dashboard link: https://syzkaller.appspot.com/bug?extid=448c2e24b1ceff13ed2a > compiler: gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44 > > Unfortunately, I don't have any reproducer for this issue yet. > > Downloadable assets: > disk image: https://storage.googleapis.com/syzbot-assets/dde4460fa7fd/disk-c21bb419.raw.xz > vmlinux: https://storage.googleapis.com/syzbot-assets/e1fe13568a84/vmlinux-c21bb419.xz > kernel image: https://storage.googleapis.com/syzbot-assets/283184100427/bzImage-c21bb419.xz > > IMPORTANT: if you fix the issue, please add the following tag to the commit: > Reported-by: [email protected] > > ====================================================== > WARNING: possible circular locking dependency detected > syzkaller #0 Not tainted > ------------------------------------------------------ > syz.3.857/8643 is trying to acquire lock: > ffff888037be2480 (&ima_iint_mutex_key[depth]){+.+.}-{4:4}, at: ima_reset_action_flags security/integrity/ima/ima_main.c:708 [inline] > ffff888037be2480 (&ima_iint_mutex_key[depth]){+.+.}-{4:4}, at: ima_reset_action_flags security/integrity/ima/ima_main.c:697 [inline] > ffff888037be2480 (&ima_iint_mutex_key[depth]){+.+.}-{4:4}, at: ima_file_truncate+0xe6/0x190 security/integrity/ima/ima_main.c:723 > > but task is already holding lock: > ffff888035fc0450 (sb_writers#6){.+.+}-{0:0}, at: do_open fs/namei.c:4693 [inline] > ffff888035fc0450 (sb_writers#6){.+.+}-{0:0}, at: path_openat+0x2929/0x4280 fs/namei.c:4863 > I had AI whip up a reproducer for this, but it's not mutually exclusive to the added patch. Tested by running reproducer, then unapplied patch, still reproduced on v7.2-rc4. I'll need to simplify it before I post it. #syz dup: [syzbot] [integrity?] [lsm?] possible deadlock in process_measurement (6) See below for un-applied repro result. Best, Fred [ 23.443936] ====================================================== [ 23.443988] WARNING: possible circular locking dependency detected [ 23.444028] 7.2.0-rc4 #11 Not tainted [ 23.444062] ------------------------------------------------------ [ 23.444095] repro-deadlock./159 is trying to acquire lock: [ 23.444121] ffff8881033da7b0 (&ima_iint_mutex_key[depth]#2){+.+.}-{4:4}, at: process_measurement+0x298/0xc10 [ 23.444184] [ 23.444184] but task is already holding lock: [ 23.444217] ffff88810210ac68 (&subsys->lock){+.+.}-{4:4}, at: nvmet_ns_enable+0x26/0x1e0 [ 23.444265] [ 23.444265] which lock already depends on the new lock. [ 23.444265] [ 23.444302] [ 23.444302] the existing dependency chain (in reverse order) is: [ 23.444340] [ 23.444340] -> #2 (&subsys->lock){+.+.}-{4:4}: [ 23.444378] lock_acquire+0xc7/0x2e0 [ 23.444401] __mutex_lock+0xc7/0x1120 [ 23.444425] nvmet_ns_device_path_store+0x31/0xd0 [ 23.444454] configfs_write_iter+0xc8/0x140 [ 23.444484] vfs_write+0x2af/0x530 [ 23.444508] ksys_write+0x73/0xf0 [ 23.444531] do_syscall_64+0x121/0x630 [ 23.444568] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 23.444598] [ 23.444598] -> #1 (&p->frag_sem){.+.+}-{4:4}: [ 23.444634] lock_acquire+0xc7/0x2e0 [ 23.444653] down_read+0x31/0x150 [ 23.444678] __configfs_open_file+0x5d/0x1f0 [ 23.444708] do_dentry_open+0x136/0x4a0 [ 23.444740] vfs_open+0x34/0xf0 [ 23.444763] dentry_open+0x34/0x60 [ 23.444786] ima_calc_file_hash+0x8a/0xe0 [ 23.444816] ima_collect_measurement+0x2eb/0x3a0 [ 23.444845] process_measurement+0x4e4/0xc10 [ 23.444874] ima_file_check+0x60/0x90 [ 23.444899] security_file_post_open+0x2e/0x40 [ 23.444928] path_openat+0x51f/0x1140 [ 23.444950] do_file_open+0xe4/0x1a0 [ 23.444976] do_sys_openat2+0x7f/0xe0 [ 23.445003] __x64_sys_openat+0x56/0xa0 [ 23.445040] do_syscall_64+0x121/0x630 [ 23.445075] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 23.445112] [ 23.445112] -> #0 (&ima_iint_mutex_key[depth]#2){+.+.}-{4:4}: [ 23.445163] check_prev_add+0xeb/0xe80 [ 23.445199] __lock_acquire+0x149d/0x1d10 [ 23.445233] lock_acquire+0xc7/0x2e0 [ 23.445257] __mutex_lock+0xc7/0x1120 [ 23.445288] process_measurement+0x298/0xc10 [ 23.445323] ima_file_check+0x60/0x90 [ 23.445354] security_file_post_open+0x2e/0x40 [ 23.445396] path_openat+0x51f/0x1140 [ 23.445424] do_file_open+0xe4/0x1a0 [ 23.445452] file_open_name+0xd1/0x1a0 [ 23.445488] filp_open+0x28/0x40 [ 23.445516] nvmet_file_ns_enable+0x2b/0xf0 [ 23.445553] nvmet_ns_enable+0x13c/0x1e0 [ 23.445590] nvmet_ns_enable_store+0x8a/0xb0 [ 23.445626] configfs_write_iter+0xc8/0x140 [ 23.445662] vfs_write+0x2af/0x530 [ 23.445691] ksys_write+0x73/0xf0 [ 23.445719] do_syscall_64+0x121/0x630 [ 23.445755] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 23.445790] [ 23.445790] other info that might help us debug this: [ 23.445790] [ 23.445839] Chain exists of: [ 23.445839] &ima_iint_mutex_key[depth]#2 --> &p->frag_sem --> &subsys->lock [ 23.445839] [ 23.445918] Possible unsafe locking scenario: [ 23.445918] [ 23.445958] CPU0 CPU1 [ 23.446004] ---- ---- [ 23.446035] lock(&subsys->lock); [ 23.446066] lock(&p->frag_sem); [ 23.446109] lock(&subsys->lock); [ 23.446153] lock(&ima_iint_mutex_key[depth]#2); [ 23.446190] [ 23.446190] *** DEADLOCK *** [ 23.446190] [ 23.446230] 5 locks held by repro-deadlock./159: [ 23.446268] #0: ffff888101ce6428 (sb_writers#10){.+.+}-{0:0}, at: ksys_write+0x73/0xf0 [ 23.446325] #1: ffff888101f19080 (&buffer->mutex){+.+.}-{4:4}, at: configfs_write_iter+0x2e/0x140 [ 23.446382] #2: ffff88810221faf0 (&p->frag_sem){.+.+}-{4:4}, at: configfs_write_iter+0xa0/0x140 [ 23.446439] #3: ffffffff82e80be8 (nvmet_config_sem){+.+.}-{4:4}, at: nvmet_ns_enable_store+0x4d/0xb0 [ 23.446496] #4: ffff88810210ac68 (&subsys->lock){+.+.}-{4:4}, at: nvmet_ns_enable+0x26/0x1e0 [ 23.446553] [ 23.446553] stack backtrace: [ 23.446583] CPU: 0 UID: 0 PID: 159 Comm: repro-deadlock. Not tainted 7.2.0-rc4 #11 PREEMPT(lazy) [ 23.446585] Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 23.446586] Call Trace: [ 23.446587] <TASK> [ 23.446588] dump_stack_lvl+0x78/0xe0 [ 23.446591] print_circular_bug+0x2ca/0x400 [ 23.446593] check_noncircular+0x161/0x180 [ 23.446597] check_prev_add+0xeb/0xe80 [ 23.446600] __lock_acquire+0x149d/0x1d10 [ 23.446602] lock_acquire+0xc7/0x2e0 [ 23.446603] ? process_measurement+0x298/0xc10 [ 23.446605] ? lock_acquire+0xc7/0x2e0 [ 23.446607] __mutex_lock+0xc7/0x1120 [ 23.446608] ? process_measurement+0x298/0xc10 [ 23.446610] ? fs_reclaim_acquire+0x4c/0xd0 [ 23.446612] ? process_measurement+0x298/0xc10 [ 23.446614] ? find_held_lock+0x2b/0x80 [ 23.446617] ? process_measurement+0x298/0xc10 [ 23.446618] process_measurement+0x298/0xc10 [ 23.446625] ima_file_check+0x60/0x90 [ 23.446627] security_file_post_open+0x2e/0x40 [ 23.446629] path_openat+0x51f/0x1140 [ 23.446632] ? __lock_acquire+0x5df/0x1d10 [ 23.446633] do_file_open+0xe4/0x1a0 [ 23.446639] file_open_name+0xd1/0x1a0 [ 23.446640] filp_open+0x28/0x40 [ 23.446642] nvmet_file_ns_enable+0x2b/0xf0 [ 23.446644] nvmet_ns_enable+0x13c/0x1e0 [ 23.446646] nvmet_ns_enable_store+0x8a/0xb0 [ 23.446647] configfs_write_iter+0xc8/0x140 [ 23.446650] vfs_write+0x2af/0x530 [ 23.446653] ksys_write+0x73/0xf0 [ 23.446655] do_syscall_64+0x121/0x630 [ 23.446657] ? clear_bhb_loop+0x40/0x90 [ 23.446659] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 23.446660] RIP: 0033:0x7f6d63b105a4 [ 23.446662] Code: c7 00 16 00 00 00 b8 ff ff ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 f3 0f 1e fa 80 3d a5 ea 0e 00 00 74 13 b8 01 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 54 c3 0f 1f 00 55 48 89 e5 48 83 ec 20 48 89 [ 23.446663] RSP: 002b:00007ffdbeb92468 EFLAGS: 00000202 ORIG_RAX: 0000000000000001 [ 23.446665] RAX: ffffffffffffffda RBX: 0000000000000002 RCX: 00007f6d63b105a4 [ 23.446666] RDX: 0000000000000002 RSI: 000055be1939cba0 RDI: 0000000000000001 [ 23.446666] RBP: 00007ffdbeb92490 R08: 0000000000000073 R09: 0000000000000000 [ 23.446667] R10: 00000000ffffffff R11: 0000000000000202 R12: 0000000000000002 [ 23.446667] R13: 000055be1939cba0 R14: 00007f6d63bf85c0 R15: 00007f6d63bf5ee0 [ 23.446670] </TASK>