[v6.6] INFO: rcu detected stall in sys_getsockopt (2)

2 views
Skip to first unread message

syzbot

unread,
Nov 21, 2025, 8:54:26 PMNov 21
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 0a805b6ea8cd Linux 6.6.116
git tree: linux-6.6.y
console output: https://syzkaller.appspot.com/x/log.txt?x=13b098b4580000
kernel config: https://syzkaller.appspot.com/x/.config?x=12606d4b8832c7e4
dashboard link: https://syzkaller.appspot.com/bug?extid=ccf0c92386c908894de4
compiler: Debian clang version 20.1.8 (++20250708063551+0c9f909b7976-1~exp1~20250708183702.136), Debian LLD 20.1.8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/13874446b4b2/disk-0a805b6e.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/69a5e59e1ade/vmlinux-0a805b6e.xz
kernel image: https://storage.googleapis.com/syzbot-assets/322c0711f976/bzImage-0a805b6e.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+ccf0c9...@syzkaller.appspotmail.com

rcu: INFO: rcu_preempt detected stalls on CPUs/tasks:
rcu: 0-...0: (1 GPs behind) idle=67c4/1/0x4000000000000000 softirq=52757/52761 fqs=2099
rcu: hardirqs softirqs csw/system
rcu: number: 0 0 0
rcu: cputime: 0 0 0 ==> 52500(ms)
rcu: (detected by 1, t=10505 jiffies, g=63725, q=2664 ncpus=2)
Sending NMI from CPU 1 to CPUs 0:
NMI backtrace for cpu 0
CPU: 0 PID: 8468 Comm: syz-executor Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/02/2025
RIP: 0010:native_save_fl arch/x86/include/asm/irqflags.h:26 [inline]
RIP: 0010:arch_local_save_flags arch/x86/include/asm/irqflags.h:89 [inline]
RIP: 0010:arch_irqs_disabled arch/x86/include/asm/irqflags.h:131 [inline]
RIP: 0010:__raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:151 [inline]
RIP: 0010:_raw_spin_unlock_irqrestore+0x8f/0x110 kernel/locking/spinlock.c:194
Code: 83 c7 18 48 8b 75 08 e8 bf 04 ef f6 4c 89 f7 e8 d7 d6 ef f6 f7 c3 00 02 00 00 74 05 e8 ea 7c 13 f7 48 c7 44 24 20 00 00 00 00 <9c> 8f 44 24 20 f6 44 24 21 02 75 4b f7 c3 00 02 00 00 74 01 fb bf
RSP: 0018:ffffc90000007ca0 EFLAGS: 00000046
RAX: 0000000000000001 RBX: 0000000000000806 RCX: 0000000000000000
RDX: 0000000000000000 RSI: 0000000000000004 RDI: ffff8880b8e2b700
RBP: ffffc90000007d30 R08: ffff8880b8e2b703 R09: 1ffff110171c56e0
R10: dffffc0000000000 R11: ffffed10171c56e1 R12: dffffc0000000000
R13: dffffc0000000000 R14: ffff8880b8e2b700 R15: 1ffff92000000f94
FS: 0000555584e07500(0000) GS:ffff8880b8e00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007ff32c7b42f8 CR3: 00000000305c8000 CR4: 00000000003526f0
Call Trace:
<IRQ>
__run_hrtimer kernel/time/hrtimer.c:1746 [inline]
__hrtimer_run_queues+0x426/0xc40 kernel/time/hrtimer.c:1814
hrtimer_interrupt+0x3c9/0x9c0 kernel/time/hrtimer.c:1876
local_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1077 [inline]
__sysvec_apic_timer_interrupt+0xfb/0x3b0 arch/x86/kernel/apic/apic.c:1094
instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1088 [inline]
sysvec_apic_timer_interrupt+0x9f/0xc0 arch/x86/kernel/apic/apic.c:1088
</IRQ>
<TASK>
asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:687
RIP: 0010:lock_is_held_type+0x13e/0x190 kernel/locking/lockdep.c:5830
Code: 75 40 48 c7 04 24 00 00 00 00 9c 8f 04 24 f7 04 24 00 02 00 00 75 46 41 f7 c5 00 02 00 00 74 01 fb 65 48 8b 04 25 28 00 00 00 <48> 3b 44 24 08 75 3c 89 e8 48 83 c4 10 5b 41 5c 41 5d 41 5e 41 5f
RSP: 0018:ffffc9000331fbf8 EFLAGS: 00000206
RAX: 14d0cb50d1688800 RBX: ffff8880261eda00 RCX: 14d0cb50d1688800
RDX: 0000000000000000 RSI: ffffffff8aaace60 RDI: ffffffff8afc6b00
RBP: 0000000000000000 R08: ffff888020c5c100 R09: 0000000000000000
R10: ffffffff8a6ece00 R11: ffffed1005ea5ad1 R12: dffffc0000000000
R13: 0000000000000246 R14: ffffffff8cd2ffa0 R15: 00000000ffffffff
lock_is_held include/linux/lockdep.h:288 [inline]
__might_resched+0xf6/0x610 kernel/sched/core.c:10170
__might_fault+0x71/0x120 mm/memory.c:5944
_copy_from_user+0x2a/0xe0 lib/usercopy.c:14
copy_from_user include/linux/uaccess.h:183 [inline]
copy_from_sockptr_offset include/linux/sockptr.h:48 [inline]
copy_from_sockptr include/linux/sockptr.h:59 [inline]
do_sock_getsockopt+0x17e/0x440 net/socket.c:2372
__sys_getsockopt net/socket.c:2413 [inline]
__do_sys_getsockopt net/socket.c:2423 [inline]
__se_sys_getsockopt net/socket.c:2420 [inline]
__x64_sys_getsockopt+0x1d6/0x280 net/socket.c:2420
do_syscall_x64 arch/x86/entry/common.c:51 [inline]
do_syscall_64+0x55/0xb0 arch/x86/entry/common.c:81
entry_SYSCALL_64_after_hwframe+0x68/0xd2
RIP: 0033:0x7ff32c59148a
Code: ff c3 66 0f 1f 44 00 00 48 c7 c2 a8 ff ff ff f7 d8 64 89 02 b8 ff ff ff ff eb b8 0f 1f 44 00 00 49 89 ca b8 37 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 06 c3 0f 1f 44 00 00 48 c7 c2 a8 ff ff ff f7
RSP: 002b:00007fff1332a6e8 EFLAGS: 00000212 ORIG_RAX: 0000000000000037
RAX: ffffffffffffffda RBX: 00007fff1332a770 RCX: 00007ff32c59148a
RDX: 0000000000000041 RSI: 0000000000000029 RDI: 0000000000000003
RBP: 0000000000000003 R08: 00007fff1332a70c R09: 0079746972756365
R10: 00007fff1332a770 R11: 0000000000000212 R12: 00007ff32c7b77a0
R13: 00007fff1332a70c R14: 0000000000000000 R15: 00007ff32c7b7e60
</TASK>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages