[v5.15] INFO: rcu detected stall in addrconf_rs_timer

2 views
Skip to first unread message

syzbot

unread,
Dec 10, 2023, 5:27:21 AM12/10/23
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 8a1d809b0545 Linux 5.15.142
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=12549d0ae80000
kernel config: https://syzkaller.appspot.com/x/.config?x=ee92f7141049e8f2
dashboard link: https://syzkaller.appspot.com/bug?extid=6048fb0d928dbb84c58f
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/8ff8a0afa367/disk-8a1d809b.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/a93c0225fd2d/vmlinux-8a1d809b.xz
kernel image: https://storage.googleapis.com/syzbot-assets/4c1046cbc0e8/bzImage-8a1d809b.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+6048fb...@syzkaller.appspotmail.com

rcu: INFO: rcu_preempt self-detected stall on CPU
rcu: 1-...!: (10501 ticks this GP) idle=3bb/1/0x4000000000000000 softirq=7068/7068 fqs=0
(t=10502 jiffies g=7201 q=210)
rcu: rcu_preempt kthread starved for 10503 jiffies! g7201 f0x0 RCU_GP_WAIT_FQS(5) ->state=0x0 ->cpu=1
rcu: Unless rcu_preempt kthread gets sufficient CPU time, OOM is now expected behavior.
rcu: RCU grace-period kthread stack dump:
task:rcu_preempt state:R running task stack:27000 pid: 15 ppid: 2 flags:0x00004000
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5030 [inline]
__schedule+0x12c4/0x45b0 kernel/sched/core.c:6376
schedule+0x11b/0x1f0 kernel/sched/core.c:6459
schedule_timeout+0x1b9/0x300 kernel/time/timer.c:1884
rcu_gp_fqs_loop+0x2bf/0x1080 kernel/rcu/tree.c:1972
rcu_gp_kthread+0xa4/0x360 kernel/rcu/tree.c:2145
kthread+0x3f6/0x4f0 kernel/kthread.c:319
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:298
</TASK>
rcu: Stack dump where RCU GP kthread last ran:
NMI backtrace for cpu 1
CPU: 1 PID: 4350 Comm: syz-executor.1 Not tainted 5.15.142-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 11/10/2023
Call Trace:
<IRQ>
__dump_stack lib/dump_stack.c:88 [inline]
dump_stack_lvl+0x1e3/0x2cb lib/dump_stack.c:106
nmi_cpu_backtrace+0x46a/0x4a0 lib/nmi_backtrace.c:111
nmi_trigger_cpumask_backtrace+0x181/0x2a0 lib/nmi_backtrace.c:62
trigger_single_cpu_backtrace include/linux/nmi.h:166 [inline]
rcu_check_gp_kthread_starvation+0x1d2/0x240 kernel/rcu/tree_stall.h:487
print_cpu_stall+0x31b/0x600 kernel/rcu/tree_stall.h:631
check_cpu_stall kernel/rcu/tree_stall.h:727 [inline]
rcu_pending kernel/rcu/tree.c:3932 [inline]
rcu_sched_clock_irq+0x8d9/0x1150 kernel/rcu/tree.c:2619
update_process_times+0x196/0x200 kernel/time/timer.c:1788
tick_sched_handle kernel/time/tick-sched.c:254 [inline]
tick_sched_timer+0x386/0x550 kernel/time/tick-sched.c:1473
__run_hrtimer kernel/time/hrtimer.c:1685 [inline]
__hrtimer_run_queues+0x55b/0xcf0 kernel/time/hrtimer.c:1749
hrtimer_interrupt+0x392/0x980 kernel/time/hrtimer.c:1811
local_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1085 [inline]
__sysvec_apic_timer_interrupt+0x139/0x470 arch/x86/kernel/apic/apic.c:1102
sysvec_apic_timer_interrupt+0x3e/0xb0 arch/x86/kernel/apic/apic.c:1096
asm_sysvec_apic_timer_interrupt+0x16/0x20 arch/x86/include/asm/idtentry.h:638
RIP: 0010:rcu_read_unlock_bh include/linux/rcupdate.h:764 [inline]
RIP: 0010:ip6_finish_output2+0x102d/0x14f0 net/ipv6/ip6_output.c:127
Code: ea ff ff ff eb 35 e8 f2 aa 89 f8 c6 05 ba c5 d9 04 01 48 c7 c7 20 20 86 8b be fb 02 00 00 48 c7 c2 40 21 86 8b e8 43 60 6c f8 <48> c7 c7 40 f1 91 8c e8 37 0c 00 00 e8 52 0c 00 00 48 c7 84 24 80
RSP: 0018:ffffc90000dd0780 EFLAGS: 00000246
RAX: ffffffff88f679dd RBX: 0000000000000001 RCX: ffff888029769dc0
RDX: 0000000000000302 RSI: ffffffff8ad87da0 RDI: ffffffff8ad87d60
RBP: ffffc90000dd08b0 R08: ffffffff88f679cb R09: fffffbfff1f79e38
R10: 0000000000000000 R11: dffffc0000000001 R12: 1ffff920001ba100
R13: dffffc0000000000 R14: 0000000000000000 R15: 1ffff11002ddf4e2
dst_output include/net/dst.h:443 [inline]
NF_HOOK include/linux/netfilter.h:302 [inline]
ndisc_send_skb+0xae0/0x13c0 net/ipv6/ndisc.c:509
addrconf_rs_timer+0x357/0x610 net/ipv6/addrconf.c:3942
call_timer_fn+0x16d/0x560 kernel/time/timer.c:1421
expire_timers kernel/time/timer.c:1466 [inline]
__run_timers+0x67c/0x890 kernel/time/timer.c:1737
run_timer_softirq+0x63/0xf0 kernel/time/timer.c:1750
__do_softirq+0x3b3/0x93a kernel/softirq.c:558
invoke_softirq kernel/softirq.c:432 [inline]
__irq_exit_rcu+0x155/0x240 kernel/softirq.c:637
irq_exit_rcu+0x5/0x20 kernel/softirq.c:649
sysvec_apic_timer_interrupt+0x91/0xb0 arch/x86/kernel/apic/apic.c:1096
</IRQ>
<TASK>
asm_sysvec_apic_timer_interrupt+0x16/0x20 arch/x86/include/asm/idtentry.h:638
RIP: 0010:local_lock_release+0x2/0x170 include/linux/local_lock_internal.h:35
Code: 0b e8 32 36 d4 ff 48 ff cd 48 89 ef 48 c7 c6 20 29 93 8a e8 60 66 0a 00 0f 0b 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 41 57 <41> 56 53 49 89 fe e8 03 36 d4 ff 48 c7 c0 c0 6f 3c 91 48 c1 e8 03
RSP: 0018:ffffc900065e77f0 EFLAGS: 00000282
RAX: 1ffffffff1869aff RBX: ffffffff8c34d7f8 RCX: dffffc0000000000
RDX: 0000000000000000 RSI: 0000000000000001 RDI: ffff8880b9b348d0
RBP: 0000000000000001 R08: ffffffff81ac138b R09: 0000000000000003
R10: ffffffffffffffff R11: dffffc0000000001 R12: ffff8880b9b34900
R13: 000000000000000c R14: ffffea0000a8b980 R15: ffffea0000a8b988
lru_cache_add+0x5af/0x7e0 mm/swap.c:454
wp_page_copy+0xec3/0x2070 mm/memory.c:3087
handle_pte_fault mm/memory.c:4639 [inline]
__handle_mm_fault mm/memory.c:4756 [inline]
handle_mm_fault+0x2a3d/0x5950 mm/memory.c:4854
do_user_addr_fault arch/x86/mm/fault.c:1397 [inline]
handle_page_fault arch/x86/mm/fault.c:1485 [inline]
exc_page_fault+0x271/0x740 arch/x86/mm/fault.c:1541
asm_exc_page_fault+0x22/0x30 arch/x86/include/asm/idtentry.h:568
RIP: 0010:__put_user_nocheck_8+0x3/0x21
Code: 00 00 48 39 d9 73 34 0f 01 cb 89 01 31 c9 0f 01 ca c3 66 0f 1f 44 00 00 48 bb f9 ef ff ff ff 7f 00 00 48 39 d9 73 14 0f 01 cb <48> 89 01 31 c9 0f 01 ca c3 0f 1f 44 00 00 0f 01 ca b9 f2 ff ff ff
RSP: 0000:ffffc900065e7db8 EFLAGS: 00050293
RAX: 0000000000000000 RBX: 00007fffffffeff9 RCX: 00007f362dc30fe8
RDX: 0000000000000000 RSI: ffffffff8a8b2000 RDI: ffffffff8ad87dc0
RBP: ffffc900065e7f00 R08: dffffc0000000000 R09: fffffbfff1bc72d6
R10: 0000000000000000 R11: dffffc0000000001 R12: ffffc900065e7e68
R13: dffffc0000000000 R14: 0000000000000000 R15: 1ffff92000cbcfce
clear_rseq_cs kernel/rseq.c:220 [inline]
rseq_ip_fixup kernel/rseq.c:254 [inline]
__rseq_handle_notify_resume+0x605/0x1250 kernel/rseq.c:292
rseq_handle_notify_resume include/linux/sched.h:2208 [inline]
tracehook_notify_resume include/linux/tracehook.h:201 [inline]
exit_to_user_mode_loop+0xdc/0x130 kernel/entry/common.c:175
exit_to_user_mode_prepare+0xb1/0x140 kernel/entry/common.c:208
irqentry_exit_to_user_mode+0x5/0x40 kernel/entry/common.c:314
asm_sysvec_apic_timer_interrupt+0x16/0x20 arch/x86/include/asm/idtentry.h:638
RIP: 0033:0x7f362f6f0ba9
Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 e1 20 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f362dc300c8 EFLAGS: 00000246
RAX: fffffffffffffffe RBX: 00007f362f810120 RCX: 00007f362f6f0ba9
RDX: bfffffffffffffff RSI: 0000000000000000 RDI: 0000000020000500
RBP: 00007f362f73c47a R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000010 R11: 0000000000000246 R12: 0000000000000000
R13: 000000000000000b R14: 00007f362f810120 R15: 00007fffafcc71e8
</TASK>
NMI backtrace for cpu 1
CPU: 1 PID: 4350 Comm: syz-executor.1 Not tainted 5.15.142-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 11/10/2023
Call Trace:
<IRQ>
__dump_stack lib/dump_stack.c:88 [inline]
dump_stack_lvl+0x1e3/0x2cb lib/dump_stack.c:106
nmi_cpu_backtrace+0x46a/0x4a0 lib/nmi_backtrace.c:111
nmi_trigger_cpumask_backtrace+0x181/0x2a0 lib/nmi_backtrace.c:62
trigger_single_cpu_backtrace include/linux/nmi.h:166 [inline]
rcu_dump_cpu_stacks+0x223/0x390 kernel/rcu/tree_stall.h:349
print_cpu_stall+0x320/0x600 kernel/rcu/tree_stall.h:633
check_cpu_stall kernel/rcu/tree_stall.h:727 [inline]
rcu_pending kernel/rcu/tree.c:3932 [inline]
rcu_sched_clock_irq+0x8d9/0x1150 kernel/rcu/tree.c:2619
update_process_times+0x196/0x200 kernel/time/timer.c:1788
tick_sched_handle kernel/time/tick-sched.c:254 [inline]
tick_sched_timer+0x386/0x550 kernel/time/tick-sched.c:1473
__run_hrtimer kernel/time/hrtimer.c:1685 [inline]
__hrtimer_run_queues+0x55b/0xcf0 kernel/time/hrtimer.c:1749
hrtimer_interrupt+0x392/0x980 kernel/time/hrtimer.c:1811
local_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1085 [inline]
__sysvec_apic_timer_interrupt+0x139/0x470 arch/x86/kernel/apic/apic.c:1102
sysvec_apic_timer_interrupt+0x3e/0xb0 arch/x86/kernel/apic/apic.c:1096
asm_sysvec_apic_timer_interrupt+0x16/0x20 arch/x86/include/asm/idtentry.h:638
RIP: 0010:rcu_read_unlock_bh include/linux/rcupdate.h:764 [inline]
RIP: 0010:ip6_finish_output2+0x102d/0x14f0 net/ipv6/ip6_output.c:127
Code: ea ff ff ff eb 35 e8 f2 aa 89 f8 c6 05 ba c5 d9 04 01 48 c7 c7 20 20 86 8b be fb 02 00 00 48 c7 c2 40 21 86 8b e8 43 60 6c f8 <48> c7 c7 40 f1 91 8c e8 37 0c 00 00 e8 52 0c 00 00 48 c7 84 24 80
RSP: 0018:ffffc90000dd0780 EFLAGS: 00000246
RAX: ffffffff88f679dd RBX: 0000000000000001 RCX: ffff888029769dc0
RDX: 0000000000000302 RSI: ffffffff8ad87da0 RDI: ffffffff8ad87d60
RBP: ffffc90000dd08b0 R08: ffffffff88f679cb R09: fffffbfff1f79e38
R10: 0000000000000000 R11: dffffc0000000001 R12: 1ffff920001ba100
R13: dffffc0000000000 R14: 0000000000000000 R15: 1ffff11002ddf4e2
dst_output include/net/dst.h:443 [inline]
NF_HOOK include/linux/netfilter.h:302 [inline]
ndisc_send_skb+0xae0/0x13c0 net/ipv6/ndisc.c:509
addrconf_rs_timer+0x357/0x610 net/ipv6/addrconf.c:3942
call_timer_fn+0x16d/0x560 kernel/time/timer.c:1421
expire_timers kernel/time/timer.c:1466 [inline]
__run_timers+0x67c/0x890 kernel/time/timer.c:1737
run_timer_softirq+0x63/0xf0 kernel/time/timer.c:1750
__do_softirq+0x3b3/0x93a kernel/softirq.c:558
invoke_softirq kernel/softirq.c:432 [inline]
__irq_exit_rcu+0x155/0x240 kernel/softirq.c:637
irq_exit_rcu+0x5/0x20 kernel/softirq.c:649
sysvec_apic_timer_interrupt+0x91/0xb0 arch/x86/kernel/apic/apic.c:1096
</IRQ>
<TASK>
asm_sysvec_apic_timer_interrupt+0x16/0x20 arch/x86/include/asm/idtentry.h:638
RIP: 0010:local_lock_release+0x2/0x170 include/linux/local_lock_internal.h:35
Code: 0b e8 32 36 d4 ff 48 ff cd 48 89 ef 48 c7 c6 20 29 93 8a e8 60 66 0a 00 0f 0b 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 41 57 <41> 56 53 49 89 fe e8 03 36 d4 ff 48 c7 c0 c0 6f 3c 91 48 c1 e8 03
RSP: 0018:ffffc900065e77f0 EFLAGS: 00000282
RAX: 1ffffffff1869aff RBX: ffffffff8c34d7f8 RCX: dffffc0000000000
RDX: 0000000000000000 RSI: 0000000000000001 RDI: ffff8880b9b348d0
RBP: 0000000000000001 R08: ffffffff81ac138b R09: 0000000000000003
R10: ffffffffffffffff R11: dffffc0000000001 R12: ffff8880b9b34900
R13: 000000000000000c R14: ffffea0000a8b980 R15: ffffea0000a8b988
lru_cache_add+0x5af/0x7e0 mm/swap.c:454
wp_page_copy+0xec3/0x2070 mm/memory.c:3087
handle_pte_fault mm/memory.c:4639 [inline]
__handle_mm_fault mm/memory.c:4756 [inline]
handle_mm_fault+0x2a3d/0x5950 mm/memory.c:4854
do_user_addr_fault arch/x86/mm/fault.c:1397 [inline]
handle_page_fault arch/x86/mm/fault.c:1485 [inline]
exc_page_fault+0x271/0x740 arch/x86/mm/fault.c:1541
asm_exc_page_fault+0x22/0x30 arch/x86/include/asm/idtentry.h:568
RIP: 0010:__put_user_nocheck_8+0x3/0x21
Code: 00 00 48 39 d9 73 34 0f 01 cb 89 01 31 c9 0f 01 ca c3 66 0f 1f 44 00 00 48 bb f9 ef ff ff ff 7f 00 00 48 39 d9 73 14 0f 01 cb <48> 89 01 31 c9 0f 01 ca c3 0f 1f 44 00 00 0f 01 ca b9 f2 ff ff ff
RSP: 0000:ffffc900065e7db8 EFLAGS: 00050293
RAX: 0000000000000000 RBX: 00007fffffffeff9 RCX: 00007f362dc30fe8
RDX: 0000000000000000 RSI: ffffffff8a8b2000 RDI: ffffffff8ad87dc0
RBP: ffffc900065e7f00 R08: dffffc0000000000 R09: fffffbfff1bc72d6
R10: 0000000000000000 R11: dffffc0000000001 R12: ffffc900065e7e68
R13: dffffc0000000000 R14: 0000000000000000 R15: 1ffff92000cbcfce
clear_rseq_cs kernel/rseq.c:220 [inline]
rseq_ip_fixup kernel/rseq.c:254 [inline]
__rseq_handle_notify_resume+0x605/0x1250 kernel/rseq.c:292
rseq_handle_notify_resume include/linux/sched.h:2208 [inline]
tracehook_notify_resume include/linux/tracehook.h:201 [inline]
exit_to_user_mode_loop+0xdc/0x130 kernel/entry/common.c:175
exit_to_user_mode_prepare+0xb1/0x140 kernel/entry/common.c:208
irqentry_exit_to_user_mode+0x5/0x40 kernel/entry/common.c:314
asm_sysvec_apic_timer_interrupt+0x16/0x20 arch/x86/include/asm/idtentry.h:638
RIP: 0033:0x7f362f6f0ba9
Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 e1 20 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f362dc300c8 EFLAGS: 00000246
RAX: fffffffffffffffe RBX: 00007f362f810120 RCX: 00007f362f6f0ba9
RDX: bfffffffffffffff RSI: 0000000000000000 RDI: 0000000020000500
RBP: 00007f362f73c47a R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000010 R11: 0000000000000246 R12: 0000000000000000
R13: 000000000000000b R14: 00007f362f810120 R15: 00007fffafcc71e8
</TASK>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Mar 14, 2024, 12:13:17 AMMar 14
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 574362648507 Linux 5.15.151
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=10b276d6180000
kernel config: https://syzkaller.appspot.com/x/.config?x=9f05b19a5fda27f0
dashboard link: https://syzkaller.appspot.com/bug?extid=6048fb0d928dbb84c58f
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1284c9b9180000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1314d371180000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/3b670cadd741/disk-57436264.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/8160de48506f/vmlinux-57436264.xz
kernel image: https://storage.googleapis.com/syzbot-assets/9cd83ff92303/Image-57436264.gz.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+6048fb...@syzkaller.appspotmail.com

watchdog: BUG: soft lockup - CPU#1 stuck for 22s! [kworker/1:4:4012]
Modules linked in:
irq event stamp: 10841
hardirqs last enabled at (10840): [<ffff800011976ce0>] __exit_to_kernel_mode arch/arm64/kernel/entry-common.c:81 [inline]
hardirqs last enabled at (10840): [<ffff800011976ce0>] exit_to_kernel_mode+0x100/0x178 arch/arm64/kernel/entry-common.c:91
hardirqs last disabled at (10841): [<ffff800011976f28>] enter_el1_irq_or_nmi+0x10/0x1c arch/arm64/kernel/entry-common.c:227
softirqs last enabled at (10382): [<ffff800010903ed0>] spin_unlock_bh include/linux/spinlock.h:408 [inline]
softirqs last enabled at (10382): [<ffff800010903ed0>] __fib6_clean_all+0x2ac/0x428 net/ipv6/ip6_fib.c:2254
softirqs last disabled at (10387): [<ffff8000081b6568>] do_softirq_own_stack include/asm-generic/softirq_stack.h:10 [inline]
softirqs last disabled at (10387): [<ffff8000081b6568>] invoke_softirq kernel/softirq.c:439 [inline]
softirqs last disabled at (10387): [<ffff8000081b6568>] __irq_exit_rcu+0x264/0x4d4 kernel/softirq.c:637
CPU: 1 PID: 4012 Comm: kworker/1:4 Not tainted 5.15.151-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/25/2024
Workqueue: ipv6_addrconf addrconf_dad_work
pstate: 20400005 (nzCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : queued_write_lock_slowpath+0x174/0x49c kernel/locking/qrwlock.c:78
lr : instrument_atomic_read_write include/linux/instrumented.h:101 [inline]
lr : atomic_or include/linux/atomic/atomic-instrumented.h:377 [inline]
lr : queued_write_lock_slowpath+0x11c/0x49c kernel/locking/qrwlock.c:74
sp : ffff800008017300
x29: ffff800008017380 x28: ffff80001485e008 x27: 00000000000000ff
x26: 0000000000000100 x25: 1ffff00001002e6a x24: 1ffff00002d5ef67
x23: 1ffff00001002e64 x22: dfff800000000000 x21: ffff800008017350
x20: ffff800016af7b38 x19: ffff800016af7b3c x18: 0000000000000101
x17: 0000000000000000 x16: ffff80000830421c x15: 000000000000000a
x14: 1ffff0000292206a x13: dfff800000000000 x12: 0000000000000001
x11: 1ffff00002d5ef67 x10: 0000000000000000 x9 : 0000000000000000
x8 : 00000000000001ff x7 : ffff80000fdf5340 x6 : 0000000000000000
x5 : 0000000000000000 x4 : 0000000000000001 x3 : ffff800008305374
x2 : 0000000000000001 x1 : 0000000000000004 x0 : 0000000000000001
Call trace:
__cmpwait_case_32 arch/arm64/include/asm/cmpxchg.h:252 [inline]
__cmpwait arch/arm64/include/asm/cmpxchg.h:278 [inline]
queued_write_lock_slowpath+0x174/0x49c kernel/locking/qrwlock.c:78
queued_write_lock include/asm-generic/qrwlock.h:97 [inline]
do_raw_write_lock+0x464/0x534 kernel/locking/spinlock_debug.c:210
__raw_write_lock_bh include/linux/rwlock_api_smp.h:204 [inline]
_raw_write_lock_bh+0x12c/0x1c4 kernel/locking/spinlock.c:324
neigh_forced_gc net/core/neighbour.c:236 [inline]
neigh_alloc net/core/neighbour.c:429 [inline]
___neigh_create+0x294/0x24fc net/core/neighbour.c:591
__neigh_create+0x44/0x58 net/core/neighbour.c:679
ip6_finish_output2+0xc74/0x1c4c net/ipv6/ip6_output.c:123
__ip6_finish_output+0x580/0x6ec net/ipv6/ip6_output.c:197
ip6_finish_output+0x40/0x218 net/ipv6/ip6_output.c:207
NF_HOOK_COND include/linux/netfilter.h:291 [inline]
ip6_output+0x270/0x594 net/ipv6/ip6_output.c:230
dst_output include/net/dst.h:443 [inline]
NF_HOOK include/linux/netfilter.h:302 [inline]
ndisc_send_skb+0xbf8/0x1788 net/ipv6/ndisc.c:509
ndisc_send_rs+0x494/0x5fc net/ipv6/ndisc.c:703
addrconf_rs_timer+0x308/0x5a8 net/ipv6/addrconf.c:3957
call_timer_fn+0x19c/0x8f0 kernel/time/timer.c:1421
expire_timers kernel/time/timer.c:1466 [inline]
__run_timers+0x554/0x718 kernel/time/timer.c:1737
run_timer_softirq+0x7c/0x114 kernel/time/timer.c:1750
__do_softirq+0x344/0xdb0 kernel/softirq.c:558
do_softirq_own_stack include/asm-generic/softirq_stack.h:10 [inline]
invoke_softirq kernel/softirq.c:439 [inline]
__irq_exit_rcu+0x264/0x4d4 kernel/softirq.c:637
irq_exit+0x14/0x88 kernel/softirq.c:661
handle_domain_irq+0xf4/0x178 kernel/irq/irqdesc.c:710
gic_handle_irq+0x78/0x1c8 drivers/irqchip/irq-gic-v3.c:758
call_on_irq_stack+0x24/0x4c arch/arm64/kernel/entry.S:899
do_interrupt_handler+0x74/0x94 arch/arm64/kernel/entry-common.c:267
el1_interrupt+0x30/0x58 arch/arm64/kernel/entry-common.c:454
el1h_64_irq_handler+0x18/0x24 arch/arm64/kernel/entry-common.c:470
el1h_64_irq+0x78/0x7c arch/arm64/kernel/entry.S:580
mutex_spin_on_owner+0x140/0x2fc kernel/locking/mutex.c:364
mutex_optimistic_spin+0x4c/0x2bc kernel/locking/mutex.c:469
__mutex_lock_common+0x1b4/0x2154 kernel/locking/mutex.c:599
__mutex_lock kernel/locking/mutex.c:729 [inline]
mutex_lock_nested+0xa4/0xf8 kernel/locking/mutex.c:743
rtnl_lock+0x20/0x2c net/core/rtnetlink.c:72
addrconf_dad_work+0xcc/0x126c net/ipv6/addrconf.c:4111
process_one_work+0x790/0x11b8 kernel/workqueue.c:2310
worker_thread+0x910/0x1034 kernel/workqueue.c:2457
kthread+0x37c/0x45c kernel/kthread.c:319
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:870


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
Reply all
Reply to author
Forward
0 new messages