[v6.6] INFO: rcu detected stall in sys_munmap

8 views
Skip to first unread message

syzbot

unread,
Jul 12, 2025, 8:20:32 AM7/12/25
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 59a2de10b81a Linux 6.6.97
git tree: linux-6.6.y
console output: https://syzkaller.appspot.com/x/log.txt?x=16fe10f0580000
kernel config: https://syzkaller.appspot.com/x/.config?x=ac0b29aca872266f
dashboard link: https://syzkaller.appspot.com/bug?extid=9358c7457a4eb85a257e
compiler: Debian clang version 20.1.7 (++20250616065708+6146a88f6049-1~exp1~20250616065826.132), Debian LLD 20.1.7

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/32864b54a55c/disk-59a2de10.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/b0bbe4ada642/vmlinux-59a2de10.xz
kernel image: https://storage.googleapis.com/syzbot-assets/9e3fe91e14c2/bzImage-59a2de10.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+9358c7...@syzkaller.appspotmail.com

rcu: INFO: rcu_preempt detected stalls on CPUs/tasks:
rcu: Tasks blocked on level-0 rcu_node (CPUs 0-1): P14516/1:b..l
rcu: (detected by 1, t=10502 jiffies, g=72333, q=529 ncpus=2)
task:udevd state:R running task stack:25544 pid:14516 ppid:5161 flags:0x00004002
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5381 [inline]
__schedule+0x14e2/0x4580 kernel/sched/core.c:6700
preempt_schedule_irq+0xb5/0x140 kernel/sched/core.c:7010
irqentry_exit+0x67/0x70 kernel/entry/common.c:438
asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:687
RIP: 0010:lock_is_held_type+0x5/0x190 kernel/locking/lockdep.c:5810
Code: dc 03 00 75 d6 48 c7 c7 e0 b7 aa 8a 48 c7 c6 20 b8 aa 8a e8 5d 70 e1 f6 0f 0b eb bf e8 84 fc ff ff 0f 1f 40 00 f3 0f 1e fa 55 <41> 57 41 56 41 55 41 54 53 48 83 ec 10 65 48 8b 04 25 28 00 00 00
RSP: 0018:ffffc900050f76b0 EFLAGS: 00000293
RAX: ffffffff8a5c5c0c RBX: ffff88802f426f00 RCX: ffff88802ba58000
RDX: 0000000000000000 RSI: 00000000ffffffff RDI: ffff888031f481a0
RBP: ffffc900050f7890 R08: ffff88802ba58000 R09: 0000000000000003
R10: 0000000000000003 R11: 0000000000000000 R12: ffff88802f426a00
R13: ffff88802e778e80 R14: ffff888031f481a0 R15: 0000000000000300
lock_is_held include/linux/lockdep.h:288 [inline]
mt_locked lib/maple_tree.c:-1 [inline]
mt_slot lib/maple_tree.c:812 [inline]
mas_slot lib/maple_tree.c:845 [inline]
mt_validate_nulls lib/maple_tree.c:7177 [inline]
mt_validate+0x3f4b/0x4530 lib/maple_tree.c:7231
validate_mm+0xb1/0x420 mm/mmap.c:287
__split_vma+0xa93/0xc00 mm/mmap.c:2421
do_vmi_align_munmap+0x377/0x1660 mm/mmap.c:2510
do_vmi_munmap+0x252/0x2d0 mm/mmap.c:2656
__vm_munmap+0x193/0x3c0 mm/mmap.c:2957
__do_sys_munmap mm/mmap.c:2974 [inline]
__se_sys_munmap mm/mmap.c:2971 [inline]
__x64_sys_munmap+0x60/0x70 mm/mmap.c:2971
do_syscall_x64 arch/x86/entry/common.c:51 [inline]
do_syscall_64+0x55/0xb0 arch/x86/entry/common.c:81
entry_SYSCALL_64_after_hwframe+0x68/0xd2
RIP: 0033:0x7f84ecb1e097
RSP: 002b:00007ffe56bb4728 EFLAGS: 00000246 ORIG_RAX: 000000000000000b
RAX: ffffffffffffffda RBX: 000055baacd7bfa0 RCX: 00007f84ecb1e097
RDX: 000055baacd6e878 RSI: 0000000000000200 RDI: 00007f84ed152000
RBP: 000055baacd700d0 R08: 000055baacd83500 R09: 0000000000000003
R10: 000055baacd700c0 R11: 0000000000000246 R12: 00007f84ed2907c0
R13: 00007f84ed29239c R14: 0000000000000022 R15: 0000000000000001
</TASK>
rcu: rcu_preempt kthread starved for 10537 jiffies! g72333 f0x0 RCU_GP_WAIT_FQS(5) ->state=0x0 ->cpu=0
rcu: Unless rcu_preempt kthread gets sufficient CPU time, OOM is now expected behavior.
rcu: RCU grace-period kthread stack dump:
task:rcu_preempt state:R running task stack:27496 pid:17 ppid:2 flags:0x00004000
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5381 [inline]
__schedule+0x14e2/0x4580 kernel/sched/core.c:6700
schedule+0xbd/0x170 kernel/sched/core.c:6774
schedule_timeout+0x160/0x280 kernel/time/timer.c:2167
rcu_gp_fqs_loop+0x302/0x1560 kernel/rcu/tree.c:1667
rcu_gp_kthread+0x99/0x380 kernel/rcu/tree.c:1866
kthread+0x2fa/0x390 kernel/kthread.c:388
ret_from_fork+0x48/0x80 arch/x86/kernel/process.c:152
ret_from_fork_asm+0x11/0x20 arch/x86/entry/entry_64.S:293
</TASK>
rcu: Stack dump where RCU GP kthread last ran:
Sending NMI from CPU 1 to CPUs 0:
NMI backtrace for cpu 0
CPU: 0 PID: 0 Comm: swapper/0 Not tainted 6.6.97-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025
RIP: 0010:pv_native_safe_halt+0x13/0x20 arch/x86/kernel/paravirt.c:148
Code: cc cc cc cc cc cc cc f3 0f 1e fa 0f 0b 66 2e 0f 1f 84 00 00 00 00 00 f3 0f 1e fa 66 90 0f 00 2d 33 a6 39 00 f3 0f 1e fa fb f4 <c3> cc cc cc cc cc cc cc cc cc cc cc cc 66 0f 1f 00 55 41 57 41 56
RSP: 0018:ffffffff8ca07d80 EFLAGS: 000002c2
RAX: d763c48a1cba3f00 RBX: ffffffff81618a7b RCX: d763c48a1cba3f00
RDX: 0000000000000001 RSI: ffffffff8aaab940 RDI: ffffffff8afc7880
RBP: ffffffff8ca07eb8 R08: ffff8880b8e36d4b R09: 1ffff110171c6da9
R10: dffffc0000000000 R11: ffffed10171c6daa R12: ffffffff8e4a92e8
R13: 0000000000000000 R14: 0000000000000000 R15: 1ffffffff1952670
FS: 0000000000000000(0000) GS:ffff8880b8e00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000001b2ca1eff8 CR3: 000000005eb28000 CR4: 00000000003506f0
Call Trace:
<TASK>
arch_safe_halt arch/x86/include/asm/paravirt.h:108 [inline]
default_idle+0x13/0x20 arch/x86/kernel/process.c:753
default_idle_call+0x6c/0xa0 kernel/sched/idle.c:97
cpuidle_idle_call kernel/sched/idle.c:170 [inline]
do_idle+0x1eb/0x510 kernel/sched/idle.c:282
cpu_startup_entry+0x43/0x60 kernel/sched/idle.c:380
rest_init+0x2e2/0x300 init/main.c:732
arch_call_rest_init+0xe/0x10 init/main.c:829
start_kernel+0x459/0x4e0 init/main.c:1074
x86_64_start_reservations+0x2a/0x30 arch/x86/kernel/head64.c:555
x86_64_start_kernel+0x60/0x60 arch/x86/kernel/head64.c:536
secondary_startup_64_no_verify+0x179/0x17b
</TASK>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Jul 16, 2025, 8:55:32 AM7/16/25
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 89950c454265 Linux 5.15.188
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=13d2f58c580000
kernel config: https://syzkaller.appspot.com/x/.config?x=714bad923ecb909b
dashboard link: https://syzkaller.appspot.com/bug?extid=1bdbde0ecd9aae5086c3
compiler: Debian clang version 20.1.7 (++20250616065708+6146a88f6049-1~exp1~20250616065826.132), Debian LLD 20.1.7

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/eb5fa4d696cc/disk-89950c45.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/357665817767/vmlinux-89950c45.xz
kernel image: https://storage.googleapis.com/syzbot-assets/d84e95b5c259/bzImage-89950c45.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+1bdbde...@syzkaller.appspotmail.com

rcu: INFO: rcu_preempt detected stalls on CPUs/tasks:
rcu: 1-...!: (1 GPs behind) idle=f93/1/0x4000000000000000 softirq=39517/39518 fqs=39
(detected by 0, t=10502 jiffies, g=56101, q=10)
Sending NMI from CPU 0 to CPUs 1:
NMI backtrace for cpu 1
CPU: 1 PID: 11875 Comm: syz.5.1504 Not tainted 5.15.188-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025
RIP: 0010:arch_static_branch arch/x86/include/asm/jump_label.h:27 [inline]
RIP: 0010:static_key_false include/linux/jump_label.h:212 [inline]
RIP: 0010:trace_hrtimer_expire_entry include/trace/events/timer.h:236 [inline]
RIP: 0010:__run_hrtimer kernel/time/hrtimer.c:1687 [inline]
RIP: 0010:__hrtimer_run_queues+0x441/0xc40 kernel/time/hrtimer.c:1754
Code: 03 42 80 3c 38 00 74 08 4c 89 f7 e8 49 98 55 00 49 8b 06 48 89 44 24 60 48 8b 7c 24 40 48 8b b4 24 b8 00 00 00 e8 ff 56 4b 08 <0f> 1f 44 00 00 e8 25 1f 10 00 65 44 8b 35 55 61 9a 7e bf 07 00 00
RSP: 0018:ffffc90000dd0d20 EFLAGS: 00000046
RAX: 1d3b714ad6cda100 RBX: 00000000fffffffd RCX: 0000000000010000
RDX: 0000000000000000 RSI: 0000000000000004 RDI: 00000000ffffffff
RBP: ffffc90000dd0e98 R08: dffffc0000000000 R09: ffffed1017225441
R10: ffffed1017225441 R11: 1ffff11017225440 R12: ffff8880b912a310
R13: 1ffff11017225462 R14: ffff888064de2368 R15: dffffc0000000000
FS: 00007f64264df6c0(0000) GS:ffff8880b9100000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000200000003c80 CR3: 000000007b761000 CR4: 00000000003506e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 3a810b1eb6134bdc DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<IRQ>
hrtimer_interrupt+0x3bb/0x8d0 kernel/time/hrtimer.c:1816
local_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1097 [inline]
__sysvec_apic_timer_interrupt+0x137/0x4a0 arch/x86/kernel/apic/apic.c:1114
instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1108 [inline]
sysvec_apic_timer_interrupt+0x9b/0xc0 arch/x86/kernel/apic/apic.c:1108
</IRQ>
<TASK>
asm_sysvec_apic_timer_interrupt+0x16/0x20 arch/x86/include/asm/idtentry.h:676
RIP: 0010:get_current arch/x86/include/asm/current.h:15 [inline]
RIP: 0010:write_comp_data kernel/kcov.c:226 [inline]
RIP: 0010:__sanitizer_cov_trace_const_cmp8+0x4/0x80 kernel/kcov.c:300
Code: 77 22 89 ff 89 f6 4a c7 44 02 08 05 00 00 00 4a 89 7c 02 10 4a 89 74 02 18 4a 89 44 02 20 48 ff c1 48 89 0a c3 90 48 8b 04 24 <65> 48 8b 0d b4 98 8a 7e 65 8b 15 b5 98 8a 7e 81 e2 00 01 ff 00 74
RSP: 0018:ffffc900034af9a0 EFLAGS: 00000246
RAX: ffffffff81ac7f2a RBX: 00007f641e851000 RCX: ffff88802cd75940
RDX: 0000000000000002 RSI: 0000000000000200 RDI: 0000000000000000
RBP: ffffc900034afb01 R08: dffffc0000000000 R09: ffffed10059aeb29
R10: ffffed10059aeb29 R11: 1ffff110059aeb28 R12: 000000000000edb7
R13: ffffc900034afce0 R14: 800000000edb7225 R15: ffff8880612ad630
vm_normal_page+0x6a/0x1e0 mm/memory.c:611
zap_pte_range mm/memory.c:1357 [inline]
zap_pmd_range mm/memory.c:1505 [inline]
zap_pud_range mm/memory.c:1534 [inline]
zap_p4d_range mm/memory.c:1555 [inline]
unmap_page_range+0xa95/0x2520 mm/memory.c:1576
unmap_vmas+0x11b/0x230 mm/memory.c:1653
unmap_region+0x202/0x360 mm/mmap.c:2646
__do_munmap+0x9d3/0xdc0 mm/mmap.c:2895
__vm_munmap+0x137/0x230 mm/mmap.c:2948
__do_sys_munmap mm/mmap.c:2974 [inline]
__se_sys_munmap mm/mmap.c:2970 [inline]
__x64_sys_munmap+0x67/0x70 mm/mmap.c:2970
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x4c/0xa0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x66/0xd0
RIP: 0033:0x7f64286779b7
Code: 00 00 00 48 c7 c2 a8 ff ff ff f7 d8 64 89 02 48 c7 c0 ff ff ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 66 90 b8 0b 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f64264dee18 EFLAGS: 00000246 ORIG_RAX: 000000000000000b
RAX: ffffffffffffffda RBX: 00000000013bd7ef RCX: 00007f64286779b7
RDX: 0000000000000000 RSI: 0000000008400000 RDI: 00007f641e0bf000
RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000005568
R10: 00000000000003c8 R11: 0000000000000246 R12: 0000000000000003
R13: 00007f64264deef0 R14: 00007f64264deeb0 R15: 00007f641e0bf000
</TASK>
rcu: rcu_preempt kthread starved for 10411 jiffies! g56101 f0x0 RCU_GP_WAIT_FQS(5) ->state=0x0 ->cpu=0
rcu: Unless rcu_preempt kthread gets sufficient CPU time, OOM is now expected behavior.
rcu: RCU grace-period kthread stack dump:
task:rcu_preempt state:R running task stack:27008 pid: 15 ppid: 2 flags:0x00004000
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5030 [inline]
__schedule+0x11b8/0x43b0 kernel/sched/core.c:6376
schedule+0x11b/0x1e0 kernel/sched/core.c:6459
schedule_timeout+0x15c/0x280 kernel/time/timer.c:1914
rcu_gp_fqs_loop+0x29e/0x11b0 kernel/rcu/tree.c:1972
rcu_gp_kthread+0x98/0x350 kernel/rcu/tree.c:2145
kthread+0x436/0x520 kernel/kthread.c:334
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:287
</TASK>
rcu: Stack dump where RCU GP kthread last ran:
NMI backtrace for cpu 0
CPU: 0 PID: 6070 Comm: kworker/0:19 Not tainted 5.15.188-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025
Workqueue: events bpf_prog_free_deferred
Call Trace:
<IRQ>
dump_stack_lvl+0x168/0x230 lib/dump_stack.c:106
nmi_cpu_backtrace+0x397/0x3d0 lib/nmi_backtrace.c:111
nmi_trigger_cpumask_backtrace+0x163/0x280 lib/nmi_backtrace.c:62
trigger_single_cpu_backtrace include/linux/nmi.h:166 [inline]
rcu_check_gp_kthread_starvation+0x1cd/0x250 kernel/rcu/tree_stall.h:487
print_other_cpu_stall+0x10c8/0x1220 kernel/rcu/tree_stall.h:592
check_cpu_stall kernel/rcu/tree_stall.h:745 [inline]
rcu_pending kernel/rcu/tree.c:3936 [inline]
rcu_sched_clock_irq+0x831/0x1110 kernel/rcu/tree.c:2619
update_process_times+0x193/0x200 kernel/time/timer.c:1818
tick_sched_handle kernel/time/tick-sched.c:254 [inline]
tick_sched_timer+0x37d/0x560 kernel/time/tick-sched.c:1473
__run_hrtimer kernel/time/hrtimer.c:1690 [inline]
__hrtimer_run_queues+0x4fe/0xc40 kernel/time/hrtimer.c:1754
hrtimer_interrupt+0x3bb/0x8d0 kernel/time/hrtimer.c:1816
local_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1097 [inline]
__sysvec_apic_timer_interrupt+0x137/0x4a0 arch/x86/kernel/apic/apic.c:1114
instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1108 [inline]
sysvec_apic_timer_interrupt+0x9b/0xc0 arch/x86/kernel/apic/apic.c:1108
</IRQ>
<TASK>
asm_sysvec_apic_timer_interrupt+0x16/0x20 arch/x86/include/asm/idtentry.h:676
RIP: 0010:check_kcov_mode kernel/kcov.c:183 [inline]
RIP: 0010:__sanitizer_cov_trace_pc+0x32/0x60 kernel/kcov.c:206
Code: 94 9c 8a 7e 65 8b 15 95 9c 8a 7e 81 e2 00 01 ff 00 74 11 81 fa 00 01 00 00 75 35 83 b9 34 16 00 00 00 74 2c 8b 91 10 16 00 00 <83> fa 02 75 21 48 8b 91 18 16 00 00 48 8b 32 48 8d 7e 01 8b 89 14
RSP: 0018:ffffc9000358f838 EFLAGS: 00000246
RAX: ffffffff816c810b RBX: 0000000000000001 RCX: ffff88802be1d940
RDX: 0000000000000000 RSI: 0000000000000001 RDI: 0000000000000000
RBP: ffffc9000358f980 R08: dffffc0000000000 R09: fffffbfff1ff761a
R10: fffffbfff1ff761a R11: 1ffffffff1ff7619 R12: ffff8880b9140588
R13: 1ffff110172280b1 R14: ffff8880b903b380 R15: 0000000000000001
csd_lock_wait kernel/smp.c:440 [inline]
smp_call_function_many_cond+0xbab/0xd70 kernel/smp.c:969
on_each_cpu_cond_mask+0x3b/0x80 kernel/smp.c:1135
__purge_vmap_area_lazy+0x216/0x18f0 mm/vmalloc.c:1683
_vm_unmap_aliases+0x410/0x4a0 mm/vmalloc.c:2107
vm_remove_mappings mm/vmalloc.c:2584 [inline]
__vunmap+0x70d/0xa40 mm/vmalloc.c:2611
bpf_jit_binary_free kernel/bpf/core.c:918 [inline]
bpf_jit_free+0x92/0x180 kernel/bpf/core.c:931
process_one_work+0x863/0x1000 kernel/workqueue.c:2310
worker_thread+0xaa8/0x12a0 kernel/workqueue.c:2457
kthread+0x436/0x520 kernel/kthread.c:334
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:287

syzbot

unread,
Oct 24, 2025, 8:55:19 AM10/24/25
to syzkaller...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages