[v5.15] BUG: soft lockup in ser_release (2)

3 views
Skip to first unread message

syzbot

unread,
Nov 23, 2024, 8:09:23 PM11/23/24
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 0a51d2d4527b Linux 5.15.173
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=104d575f980000
kernel config: https://syzkaller.appspot.com/x/.config?x=a6b3013b6f1a102b
dashboard link: https://syzkaller.appspot.com/bug?extid=d2508fda0a7c8f8bbb9b
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
userspace arch: arm64

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/731bd13b5412/disk-0a51d2d4.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/a53b07f54a18/vmlinux-0a51d2d4.xz
kernel image: https://storage.googleapis.com/syzbot-assets/5f1392034bb8/Image-0a51d2d4.gz.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+d2508f...@syzkaller.appspotmail.com

watchdog: BUG: soft lockup - CPU#0 stuck for 22s! [kworker/0:1:13]
Modules linked in:
irq event stamp: 123211
hardirqs last enabled at (123210): [<ffff800011ab6ec8>] __exit_to_kernel_mode arch/arm64/kernel/entry-common.c:81 [inline]
hardirqs last enabled at (123210): [<ffff800011ab6ec8>] exit_to_kernel_mode+0x100/0x178 arch/arm64/kernel/entry-common.c:91
hardirqs last disabled at (123211): [<ffff800011ab7110>] enter_el1_irq_or_nmi+0x10/0x1c arch/arm64/kernel/entry-common.c:227
softirqs last enabled at (118902): [<ffff8000108a2e94>] spin_unlock_bh include/linux/spinlock.h:408 [inline]
softirqs last enabled at (118902): [<ffff8000108a2e94>] clusterip_netdev_event+0x37c/0x3a4 net/ipv4/netfilter/ipt_CLUSTERIP.c:233
softirqs last disabled at (118904): [<ffff8000100bf60c>] local_bh_disable+0x10/0x34 include/linux/bottom_half.h:18
CPU: 0 PID: 13 Comm: kworker/0:1 Not tainted 5.15.173-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024
Workqueue: events ser_release
pstate: 00400005 (nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : queued_spin_lock_slowpath+0x160/0x938 kernel/locking/qspinlock.c:382
lr : queued_spin_lock_slowpath+0x16c/0x938 kernel/locking/qspinlock.c:382
sp : ffff80001bc775a0
x29: ffff80001bc77640 x28: 1ffff0000378eec0 x27: 1fffe0001cae8f91
x26: dfff800000000000 x25: ffff70000378eeb8 x24: ffff80001bc775c0
x23: 1fffe0001cae8f90 x22: ffff80001bc77600 x21: 0000000000000001
x20: 0000000000000001 x19: ffff0000e5747c80 x18: ffff80001bc774a0
x17: 0000000000000000 x16: ffff8000083052d8 x15: 000000000001ab9b
x14: 00000000c4a2971c x13: dfff800000000000 x12: 0000000000000001
x11: 1fffe0001cae8f90 x10: 0000000000000000 x9 : 0000000000000000
x8 : 0000000000000101 x7 : 0000000000000000 x6 : 0000000000000000
x5 : ffff80001783f608 x4 : 0000000000000008 x3 : ffff800008304500
x2 : 0000000000000000 x1 : 0000000000000004 x0 : 0000000000000001
Call trace:
__cmpwait_case_32 arch/arm64/include/asm/cmpxchg.h:252 [inline]
__cmpwait arch/arm64/include/asm/cmpxchg.h:278 [inline]
queued_spin_lock_slowpath+0x160/0x938 kernel/locking/qspinlock.c:382
queued_spin_lock include/asm-generic/qspinlock.h:85 [inline]
do_raw_spin_lock+0x334/0x35c kernel/locking/spinlock_debug.c:115
__raw_spin_lock include/linux/spinlock_api_smp.h:143 [inline]
_raw_spin_lock+0xb8/0x10c kernel/locking/spinlock.c:154
spin_lock include/linux/spinlock.h:363 [inline]
__netif_tx_lock include/linux/netdevice.h:4429 [inline]
netif_tx_lock include/linux/netdevice.h:4514 [inline]
netif_tx_lock_bh include/linux/netdevice.h:4523 [inline]
dev_watchdog_down net/sched/sch_generic.c:511 [inline]
dev_deactivate_many+0x2f8/0xbe4 net/sched/sch_generic.c:1302
__dev_close_many+0x28c/0x3e4 net/core/dev.c:1577
dev_close_many+0x1e0/0x468 net/core/dev.c:1615
dev_close+0x174/0x250 net/core/dev.c:1641
ser_release+0x188/0x238 drivers/net/caif/caif_serial.c:309
process_one_work+0x790/0x11b8 kernel/workqueue.c:2310
worker_thread+0x910/0x1034 kernel/workqueue.c:2457
kthread+0x37c/0x45c kernel/kthread.c:334
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:870


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Nov 24, 2024, 1:03:21 PM11/24/24
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 0a51d2d4527b Linux 5.15.173
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=13fc4778580000
kernel config: https://syzkaller.appspot.com/x/.config?x=a6b3013b6f1a102b
dashboard link: https://syzkaller.appspot.com/bug?extid=d2508fda0a7c8f8bbb9b
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=132299c0580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=13bf8530580000
watchdog: BUG: soft lockup - CPU#0 stuck for 23s! [kworker/0:3:4089]
Modules linked in:
irq event stamp: 275903
hardirqs last enabled at (275902): [<ffff800011ab6ec8>] __exit_to_kernel_mode arch/arm64/kernel/entry-common.c:81 [inline]
hardirqs last enabled at (275902): [<ffff800011ab6ec8>] exit_to_kernel_mode+0x100/0x178 arch/arm64/kernel/entry-common.c:91
hardirqs last disabled at (275903): [<ffff800011ab7110>] enter_el1_irq_or_nmi+0x10/0x1c arch/arm64/kernel/entry-common.c:227
softirqs last enabled at (271298): [<ffff8000108a2e94>] spin_unlock_bh include/linux/spinlock.h:408 [inline]
softirqs last enabled at (271298): [<ffff8000108a2e94>] clusterip_netdev_event+0x37c/0x3a4 net/ipv4/netfilter/ipt_CLUSTERIP.c:233
softirqs last disabled at (271300): [<ffff8000100bf60c>] local_bh_disable+0x10/0x34 include/linux/bottom_half.h:18
CPU: 0 PID: 4089 Comm: kworker/0:3 Not tainted 5.15.173-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024
Workqueue: events ser_release
pstate: 00400005 (nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : queued_spin_lock_slowpath+0x160/0x938 kernel/locking/qspinlock.c:382
lr : queued_spin_lock_slowpath+0x16c/0x938 kernel/locking/qspinlock.c:382
sp : ffff80001ffd75a0
x29: ffff80001ffd7640 x28: 1ffff00003ffaec0 x27: 1fffe0001810c791
x26: dfff800000000000 x25: ffff700003ffaeb8 x24: ffff80001ffd75c0
x23: 1fffe0001810c790 x22: ffff80001ffd7600 x21: 0000000000000001
x20: 0000000000000001 x19: ffff0000c0863c80 x18: 0000000000000000
x17: 0000000000000000 x16: ffff8000083052d8 x15: 0000000000000013
x14: 1ffff0000295806a x13: dfff800000000000 x12: 0000000000000001
x11: 1fffe0001810c790 x10: 0000000000000000 x9 : 0000000000000000
x8 : 0000000000000101 x7 : ffff8000100bc37c x6 : 0000000000000000
x5 : 0000000000000000 x4 : 0000000000000001 x3 : ffff800008304500
x2 : 0000000000000000 x1 : 0000000000000004 x0 : 0000000000000001
Call trace:
__cmpwait_case_32 arch/arm64/include/asm/cmpxchg.h:252 [inline]
__cmpwait arch/arm64/include/asm/cmpxchg.h:278 [inline]
queued_spin_lock_slowpath+0x160/0x938 kernel/locking/qspinlock.c:382
queued_spin_lock include/asm-generic/qspinlock.h:85 [inline]
do_raw_spin_lock+0x334/0x35c kernel/locking/spinlock_debug.c:115
__raw_spin_lock include/linux/spinlock_api_smp.h:143 [inline]
_raw_spin_lock+0xb8/0x10c kernel/locking/spinlock.c:154
spin_lock include/linux/spinlock.h:363 [inline]
__netif_tx_lock include/linux/netdevice.h:4429 [inline]
netif_tx_lock include/linux/netdevice.h:4514 [inline]
netif_tx_lock_bh include/linux/netdevice.h:4523 [inline]
dev_watchdog_down net/sched/sch_generic.c:511 [inline]
dev_deactivate_many+0x2f8/0xbe4 net/sched/sch_generic.c:1302
__dev_close_many+0x28c/0x3e4 net/core/dev.c:1577
dev_close_many+0x1e0/0x468 net/core/dev.c:1615
dev_close+0x174/0x250 net/core/dev.c:1641
ser_release+0x188/0x238 drivers/net/caif/caif_serial.c:309
process_one_work+0x790/0x11b8 kernel/workqueue.c:2310
worker_thread+0x910/0x1034 kernel/workqueue.c:2457
kthread+0x37c/0x45c kernel/kthread.c:334
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:870


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

syzbot

unread,
Mar 10, 2025, 11:06:11 PM3/10/25
to syzkaller...@googlegroups.com
Auto-closing this bug as obsolete.
No recent activity, existing reproducers are no longer triggering the issue.
Reply all
Reply to author
Forward
0 new messages