Hello,
syzbot found the following issue on:
HEAD commit: d2869ace6eeb Linux 6.1.31
git tree: linux-6.1.y
console output:
https://syzkaller.appspot.com/x/log.txt?x=12ecf401280000
kernel config:
https://syzkaller.appspot.com/x/.config?x=11263f470b7a4c92
dashboard link:
https://syzkaller.appspot.com/bug?extid=0fefa64fc8412ca9a00e
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2
userspace arch: arm64
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/b17a7cd87498/disk-d2869ace.raw.xz
vmlinux:
https://storage.googleapis.com/syzbot-assets/cc8291ae723a/vmlinux-d2869ace.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/04943541fc25/Image-d2869ace.gz.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+0fefa6...@syzkaller.appspotmail.com
watchdog: BUG: soft lockup - CPU#0 stuck for 22s! [syz-executor.2:17341]
Modules linked in:
irq event stamp: 8511
hardirqs last enabled at (8510): [<ffff8000120fb1c0>] __exit_to_kernel_mode arch/arm64/kernel/entry-common.c:84 [inline]
hardirqs last enabled at (8510): [<ffff8000120fb1c0>] exit_to_kernel_mode+0xe8/0x118 arch/arm64/kernel/entry-common.c:94
hardirqs last disabled at (8511): [<ffff8000120f8e9c>] __el1_irq arch/arm64/kernel/entry-common.c:468 [inline]
hardirqs last disabled at (8511): [<ffff8000120f8e9c>] el1_interrupt+0x24/0x68 arch/arm64/kernel/entry-common.c:486
softirqs last enabled at (8): [<ffff800008032bc0>] local_bh_enable+0x10/0x34 include/linux/bottom_half.h:32
softirqs last disabled at (157): [<ffff80000802a994>] ____do_softirq+0x14/0x20 arch/arm64/kernel/irq.c:79
CPU: 0 PID: 17341 Comm: syz-executor.2 Not tainted 6.1.31-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/28/2023
pstate: 00400005 (nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : __list_add include/linux/list.h:73 [inline]
pc : list_add_tail include/linux/list.h:102 [inline]
pc : list_move_tail include/linux/list.h:230 [inline]
pc : fq_pie_qdisc_dequeue+0x3e8/0x8ac net/sched/sch_fq_pie.c:248
lr : __list_add include/linux/list.h:72 [inline]
lr : list_add_tail include/linux/list.h:102 [inline]
lr : list_move_tail include/linux/list.h:230 [inline]
lr : fq_pie_qdisc_dequeue+0x3d4/0x8ac net/sched/sch_fq_pie.c:248
sp : ffff8000080071e0
x29: ffff800008007250 x28: ffff000120499880 x27: ffff00012c7fbae8
x26: ffff00012c7fbaf0 x25: dfff800000000000 x24: ffff00012c7fbae0
x23: ffff000120499870 x22: 0000000000000040 x21: ffff00012c7fbae0
x20: ffff00012c7fbae8 x19: ffff00012c7fbae0 x18: ffff800008006ea0
x17: 0000000000000000 x16: ffff8000084fa384 x15: 0000000000000100
x14: 0000000000000000 x13: 0000000000000001 x12: ffff00011dedb780
x11: ff808000107108d0 x10: 0000000000000000 x9 : ffff8000107108d0
x8 : 0000000000000000 x7 : ffff80000840686c x6 : 0000000000000000
x5 : 0000000000000080 x4 : 0000000000000001 x3 : 0000000000000000
x2 : ffff00012c7fbae0 x1 : ffff00012c7fbae0 x0 : 0000000000000001
Call trace:
__list_add include/linux/list.h:72 [inline]
list_add_tail include/linux/list.h:102 [inline]
list_move_tail include/linux/list.h:230 [inline]
fq_pie_qdisc_dequeue+0x3e8/0x8ac net/sched/sch_fq_pie.c:248
dequeue_skb net/sched/sch_generic.c:292 [inline]
qdisc_restart net/sched/sch_generic.c:397 [inline]
__qdisc_run+0x204/0x239c net/sched/sch_generic.c:415
__dev_xmit_skb net/core/dev.c:3885 [inline]
__dev_queue_xmit+0xe14/0x38d8 net/core/dev.c:4227
dev_queue_xmit include/linux/netdevice.h:3018 [inline]
neigh_connected_output+0x2f8/0x38c net/core/neighbour.c:1612
neigh_output include/net/neighbour.h:546 [inline]
ip6_finish_output2+0xdb4/0x1a98 net/ipv6/ip6_output.c:134
__ip6_finish_output net/ipv6/ip6_output.c:195 [inline]
ip6_finish_output+0x538/0x8c8 net/ipv6/ip6_output.c:206
NF_HOOK_COND include/linux/netfilter.h:291 [inline]
ip6_output+0x270/0x594 net/ipv6/ip6_output.c:227
dst_output include/net/dst.h:444 [inline]
NF_HOOK include/linux/netfilter.h:302 [inline]
ndisc_send_skb+0xc30/0x1790 net/ipv6/ndisc.c:508
ndisc_send_rs+0x47c/0x5d4 net/ipv6/ndisc.c:718
addrconf_rs_timer+0x300/0x58c net/ipv6/addrconf.c:3936
call_timer_fn+0x1c0/0xa1c kernel/time/timer.c:1474
expire_timers kernel/time/timer.c:1519 [inline]
__run_timers+0x554/0x718 kernel/time/timer.c:1790
run_timer_softirq+0x7c/0x114 kernel/time/timer.c:1803
__do_softirq+0x30c/0xea0 kernel/softirq.c:571
____do_softirq+0x14/0x20 arch/arm64/kernel/irq.c:79
call_on_irq_stack+0x24/0x4c arch/arm64/kernel/entry.S:889
do_softirq_own_stack+0x20/0x2c arch/arm64/kernel/irq.c:84
invoke_softirq kernel/softirq.c:452 [inline]
__irq_exit_rcu+0x28c/0x534 kernel/softirq.c:650
irq_exit_rcu+0x14/0x84 kernel/softirq.c:662
__el1_irq arch/arm64/kernel/entry-common.c:472 [inline]
el1_interrupt+0x38/0x68 arch/arm64/kernel/entry-common.c:486
el1h_64_irq_handler+0x18/0x24 arch/arm64/kernel/entry-common.c:491
el1h_64_irq+0x64/0x68 arch/arm64/kernel/entry.S:577
preempt_count arch/arm64/include/asm/preempt.h:13 [inline]
check_kcov_mode kernel/kcov.c:173 [inline]
write_comp_data kernel/kcov.c:236 [inline]
__sanitizer_cov_trace_const_cmp8+0x14/0xa0 kernel/kcov.c:311
unmap_single_vma mm/memory.c:1681 [inline]
unmap_vmas+0x394/0x550 mm/memory.c:1720
exit_mmap+0x1d0/0xa60 mm/mmap.c:3127
__mmput+0xec/0x39c kernel/fork.c:1191
mmput+0x70/0xac kernel/fork.c:1213
exit_mm+0x14c/0x244 kernel/exit.c:563
do_exit+0x4d4/0x1a88 kernel/exit.c:856
do_group_exit+0x194/0x22c kernel/exit.c:1019
get_signal+0x14a0/0x158c kernel/signal.c:2858
do_signal arch/arm64/kernel/signal.c:1076 [inline]
do_notify_resume+0x3ac/0x3470 arch/arm64/kernel/signal.c:1129
prepare_exit_to_user_mode arch/arm64/kernel/entry-common.c:137 [inline]
exit_to_user_mode arch/arm64/kernel/entry-common.c:142 [inline]
el0_svc+0x9c/0x168 arch/arm64/kernel/entry-common.c:638
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:581