Re: [syzbot] [lsm?] [integrity?] possible deadlock in ima_file_truncate

Frederick Lawler <[email protected]>
Newsgroups org.kernel.vger.linux-security-module,org.kernel.vger.linux-integrity,org.kernel.vger.linux-kernel
Message-ID <cc5bsuwzvdoqrhgggqqb6qgkgh2cxymbupt4ghsi2msnudh4rf@slzwriyjykze>
On Sat, Aug 08, 2026 at 05:20:29PM -0700, syzbot wrote:
> Hello,
> 
> syzbot found the following issue on:
> 
> HEAD commit:    c21bb4193868 Merge tag 'for_linus' of git://git.kernel.org..
> git tree:       upstream
> console output: https://syzkaller.appspot.com/x/log.txt?x=113c53b9580000
> kernel config:  https://syzkaller.appspot.com/x/.config?x=145fa60d73086782
> dashboard link: https://syzkaller.appspot.com/bug?extid=448c2e24b1ceff13ed2a
> compiler:       gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
> 
> Unfortunately, I don't have any reproducer for this issue yet.
> 
> Downloadable assets:
> disk image: https://storage.googleapis.com/syzbot-assets/dde4460fa7fd/disk-c21bb419.raw.xz
> vmlinux: https://storage.googleapis.com/syzbot-assets/e1fe13568a84/vmlinux-c21bb419.xz
> kernel image: https://storage.googleapis.com/syzbot-assets/283184100427/bzImage-c21bb419.xz
> 
> IMPORTANT: if you fix the issue, please add the following tag to the commit:
> Reported-by: [email protected]
> 
> ======================================================
> WARNING: possible circular locking dependency detected
> syzkaller #0 Not tainted
> ------------------------------------------------------
> syz.3.857/8643 is trying to acquire lock:
> ffff888037be2480 (&ima_iint_mutex_key[depth]){+.+.}-{4:4}, at: ima_reset_action_flags security/integrity/ima/ima_main.c:708 [inline]
> ffff888037be2480 (&ima_iint_mutex_key[depth]){+.+.}-{4:4}, at: ima_reset_action_flags security/integrity/ima/ima_main.c:697 [inline]
> ffff888037be2480 (&ima_iint_mutex_key[depth]){+.+.}-{4:4}, at: ima_file_truncate+0xe6/0x190 security/integrity/ima/ima_main.c:723
> 
> but task is already holding lock:
> ffff888035fc0450 (sb_writers#6){.+.+}-{0:0}, at: do_open fs/namei.c:4693 [inline]
> ffff888035fc0450 (sb_writers#6){.+.+}-{0:0}, at: path_openat+0x2929/0x4280 fs/namei.c:4863
> 

I had AI whip up a reproducer for this, but it's not mutually exclusive to the
added patch. Tested by running reproducer, then unapplied patch, still
reproduced on v7.2-rc4.

I'll need to simplify it before I post it.

#syz dup: [syzbot] [integrity?] [lsm?] possible deadlock in process_measurement (6)

See below for un-applied repro result.

Best,
Fred

[   23.443936] ======================================================
[   23.443988] WARNING: possible circular locking dependency detected
[   23.444028] 7.2.0-rc4 #11 Not tainted
[   23.444062] ------------------------------------------------------
[   23.444095] repro-deadlock./159 is trying to acquire lock:
[   23.444121] ffff8881033da7b0 (&ima_iint_mutex_key[depth]#2){+.+.}-{4:4}, at: process_measurement+0x298/0xc10
[   23.444184]
[   23.444184] but task is already holding lock:
[   23.444217] ffff88810210ac68 (&subsys->lock){+.+.}-{4:4}, at: nvmet_ns_enable+0x26/0x1e0
[   23.444265]
[   23.444265] which lock already depends on the new lock.
[   23.444265]
[   23.444302]
[   23.444302] the existing dependency chain (in reverse order) is:
[   23.444340]
[   23.444340] -> #2 (&subsys->lock){+.+.}-{4:4}:
[   23.444378]        lock_acquire+0xc7/0x2e0
[   23.444401]        __mutex_lock+0xc7/0x1120
[   23.444425]        nvmet_ns_device_path_store+0x31/0xd0
[   23.444454]        configfs_write_iter+0xc8/0x140
[   23.444484]        vfs_write+0x2af/0x530
[   23.444508]        ksys_write+0x73/0xf0
[   23.444531]        do_syscall_64+0x121/0x630
[   23.444568]        entry_SYSCALL_64_after_hwframe+0x77/0x7f
[   23.444598]
[   23.444598] -> #1 (&p->frag_sem){.+.+}-{4:4}:
[   23.444634]        lock_acquire+0xc7/0x2e0
[   23.444653]        down_read+0x31/0x150
[   23.444678]        __configfs_open_file+0x5d/0x1f0
[   23.444708]        do_dentry_open+0x136/0x4a0
[   23.444740]        vfs_open+0x34/0xf0
[   23.444763]        dentry_open+0x34/0x60
[   23.444786]        ima_calc_file_hash+0x8a/0xe0
[   23.444816]        ima_collect_measurement+0x2eb/0x3a0
[   23.444845]        process_measurement+0x4e4/0xc10
[   23.444874]        ima_file_check+0x60/0x90
[   23.444899]        security_file_post_open+0x2e/0x40
[   23.444928]        path_openat+0x51f/0x1140
[   23.444950]        do_file_open+0xe4/0x1a0
[   23.444976]        do_sys_openat2+0x7f/0xe0
[   23.445003]        __x64_sys_openat+0x56/0xa0
[   23.445040]        do_syscall_64+0x121/0x630
[   23.445075]        entry_SYSCALL_64_after_hwframe+0x77/0x7f
[   23.445112]
[   23.445112] -> #0 (&ima_iint_mutex_key[depth]#2){+.+.}-{4:4}:
[   23.445163]        check_prev_add+0xeb/0xe80
[   23.445199]        __lock_acquire+0x149d/0x1d10
[   23.445233]        lock_acquire+0xc7/0x2e0
[   23.445257]        __mutex_lock+0xc7/0x1120
[   23.445288]        process_measurement+0x298/0xc10
[   23.445323]        ima_file_check+0x60/0x90
[   23.445354]        security_file_post_open+0x2e/0x40
[   23.445396]        path_openat+0x51f/0x1140
[   23.445424]        do_file_open+0xe4/0x1a0
[   23.445452]        file_open_name+0xd1/0x1a0
[   23.445488]        filp_open+0x28/0x40
[   23.445516]        nvmet_file_ns_enable+0x2b/0xf0
[   23.445553]        nvmet_ns_enable+0x13c/0x1e0
[   23.445590]        nvmet_ns_enable_store+0x8a/0xb0
[   23.445626]        configfs_write_iter+0xc8/0x140
[   23.445662]        vfs_write+0x2af/0x530
[   23.445691]        ksys_write+0x73/0xf0
[   23.445719]        do_syscall_64+0x121/0x630
[   23.445755]        entry_SYSCALL_64_after_hwframe+0x77/0x7f
[   23.445790]
[   23.445790] other info that might help us debug this:
[   23.445790]
[   23.445839] Chain exists of:
[   23.445839]   &ima_iint_mutex_key[depth]#2 --> &p->frag_sem --> &subsys->lock
[   23.445839]
[   23.445918]  Possible unsafe locking scenario:
[   23.445918]
[   23.445958]        CPU0                    CPU1
[   23.446004]        ----                    ----
[   23.446035]   lock(&subsys->lock);
[   23.446066]                                lock(&p->frag_sem);
[   23.446109]                                lock(&subsys->lock);
[   23.446153]   lock(&ima_iint_mutex_key[depth]#2);
[   23.446190]
[   23.446190]  *** DEADLOCK ***
[   23.446190]
[   23.446230] 5 locks held by repro-deadlock./159:
[   23.446268]  #0: ffff888101ce6428 (sb_writers#10){.+.+}-{0:0}, at: ksys_write+0x73/0xf0
[   23.446325]  #1: ffff888101f19080 (&buffer->mutex){+.+.}-{4:4}, at: configfs_write_iter+0x2e/0x140
[   23.446382]  #2: ffff88810221faf0 (&p->frag_sem){.+.+}-{4:4}, at: configfs_write_iter+0xa0/0x140
[   23.446439]  #3: ffffffff82e80be8 (nvmet_config_sem){+.+.}-{4:4}, at: nvmet_ns_enable_store+0x4d/0xb0
[   23.446496]  #4: ffff88810210ac68 (&subsys->lock){+.+.}-{4:4}, at: nvmet_ns_enable+0x26/0x1e0
[   23.446553]
[   23.446553] stack backtrace:
[   23.446583] CPU: 0 UID: 0 PID: 159 Comm: repro-deadlock. Not tainted 7.2.0-rc4 #11 PREEMPT(lazy)
[   23.446585] Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[   23.446586] Call Trace:
[   23.446587]  <TASK>
[   23.446588]  dump_stack_lvl+0x78/0xe0
[   23.446591]  print_circular_bug+0x2ca/0x400
[   23.446593]  check_noncircular+0x161/0x180
[   23.446597]  check_prev_add+0xeb/0xe80
[   23.446600]  __lock_acquire+0x149d/0x1d10
[   23.446602]  lock_acquire+0xc7/0x2e0
[   23.446603]  ? process_measurement+0x298/0xc10
[   23.446605]  ? lock_acquire+0xc7/0x2e0
[   23.446607]  __mutex_lock+0xc7/0x1120
[   23.446608]  ? process_measurement+0x298/0xc10
[   23.446610]  ? fs_reclaim_acquire+0x4c/0xd0
[   23.446612]  ? process_measurement+0x298/0xc10
[   23.446614]  ? find_held_lock+0x2b/0x80
[   23.446617]  ? process_measurement+0x298/0xc10
[   23.446618]  process_measurement+0x298/0xc10
[   23.446625]  ima_file_check+0x60/0x90
[   23.446627]  security_file_post_open+0x2e/0x40
[   23.446629]  path_openat+0x51f/0x1140
[   23.446632]  ? __lock_acquire+0x5df/0x1d10
[   23.446633]  do_file_open+0xe4/0x1a0
[   23.446639]  file_open_name+0xd1/0x1a0
[   23.446640]  filp_open+0x28/0x40
[   23.446642]  nvmet_file_ns_enable+0x2b/0xf0
[   23.446644]  nvmet_ns_enable+0x13c/0x1e0
[   23.446646]  nvmet_ns_enable_store+0x8a/0xb0
[   23.446647]  configfs_write_iter+0xc8/0x140
[   23.446650]  vfs_write+0x2af/0x530
[   23.446653]  ksys_write+0x73/0xf0
[   23.446655]  do_syscall_64+0x121/0x630
[   23.446657]  ? clear_bhb_loop+0x40/0x90
[   23.446659]  entry_SYSCALL_64_after_hwframe+0x77/0x7f
[   23.446660] RIP: 0033:0x7f6d63b105a4
[   23.446662] Code: c7 00 16 00 00 00 b8 ff ff ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 f3 0f 1e fa 80 3d a5 ea 0e 00 00 74 13 b8 01 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 54 c3 0f 1f 00 55 48 89 e5 48 83 ec 20 48 89
[   23.446663] RSP: 002b:00007ffdbeb92468 EFLAGS: 00000202 ORIG_RAX: 0000000000000001
[   23.446665] RAX: ffffffffffffffda RBX: 0000000000000002 RCX: 00007f6d63b105a4
[   23.446666] RDX: 0000000000000002 RSI: 000055be1939cba0 RDI: 0000000000000001
[   23.446666] RBP: 00007ffdbeb92490 R08: 0000000000000073 R09: 0000000000000000
[   23.446667] R10: 00000000ffffffff R11: 0000000000000202 R12: 0000000000000002
[   23.446667] R13: 000055be1939cba0 R14: 00007f6d63bf85c0 R15: 00007f6d63bf5ee0
[   23.446670]  </TASK>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.