1 TITLE: BUG: bad unlock balance detected! ] 2 CORRUPTED: Y 3 4 [ 76.640408] binder: undelivered TRANSACTION_ERROR: 29189 5 [ 76.649866] [ BUG: bad unlock balance detected! ] 6 [ 76.654695] 4.9.65-g8ae26d1 #98 Not tainted 7 [ 76.658991] ------------------------------------- 8 [ 76.661695] FAULT_FLAG_ALLOW_RETRY missing 30 9 [ 76.661705] CPU: 0 PID: 14413 Comm: syz-executor0 Not tainted 4.9.65-g8ae26d1 #98 10 [ 76.661710] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011 11 [ 76.661725] ffff8801ce46f9a0 ffffffff81d90469 ffff8801ce46fc80 0000000000000000 12 [ 76.661737] ffff8801ccd7ad10 ffff8801ce46fb70 ffff8801ccd7ac00 ffff8801ce46fb98 13 [ 76.661749] ffffffff8165e417 0000000000000282 ffff8801ce46faf0 00000001c52a4067 14 [ 76.661751] Call Trace: 15 [ 76.661765] [<ffffffff81d90469>] dump_stack+0xc1/0x128 16 ... 17 [ 76.661991] [<ffffffff838a9745>] entry_SYSCALL_64_fastpath+0x23/0xc6 18 [ 76.693507] binder: 14407:14442 BC_DEAD_BINDER_DONE 0000000000000000 not found 19 [ 76.694637] binder: 14407:14426 transaction failed 29189/-22, size 0-0 line 3007 20 [ 76.882228] syz-executor2/14420 is trying to release lock (mrt_lock) at: 21 [ 76.889259] [<ffffffff834dea24>] ipmr_mfc_seq_stop+0xe4/0x140 22 [ 76.895105] but there are no more locks to release! 23 [ 76.900080] 24 [ 76.900080] other info that might help us debug this: 25 [ 76.906710] 2 locks held by syz-executor2/14420: 26 [ 76.911425] #0: (&f->f_pos_lock){+.+.+.}, at: [<ffffffff815cf9ef>] __fdget_pos+0x9f/0xc0 27 [ 76.920249] #1: (&p->lock){+.+.+.}, at: [<ffffffff815e4ded>] seq_read+0xdd/0x1290 28 [ 76.928457] 29 [ 76.928457] stack backtrace: 30 [ 76.932918] CPU: 1 PID: 14420 Comm: syz-executor2 Not tainted 4.9.65-g8ae26d1 #98 31 [ 76.940499] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011 32 [ 76.949817] ffff8801cef3f8e8 ffffffff81d90469 ffffffff849ae8b8 ffff8801c8344800 33 [ 76.957769] ffffffff834dea24 ffffffff849ae8b8 ffff8801c8345088 ffff8801cef3f918 34 [ 76.965718] ffffffff81235524 dffffc0000000000 ffffffff849ae8b8 00000000ffffffff 35 [ 76.973663] Call Trace: 36 [ 76.976220] [<ffffffff81d90469>] dump_stack+0xc1/0x128 37 ... 38 [ 77.180814] [<ffffffff838a9745>] entry_SYSCALL_64_fastpath+0x23/0xc6 39