[v6.6] INFO: rcu detected stall in vm_area_alloc

0 views
Skip to first unread message

syzbot

unread,
Jun 8, 2026, 4:55:31 PM (22 hours ago) Jun 8
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 924b4a879cbb Linux 6.6.142
git tree: linux-6.6.y
console output: https://syzkaller.appspot.com/x/log.txt?x=17212f2e580000
kernel config: https://syzkaller.appspot.com/x/.config?x=90249d2d52c08134
dashboard link: https://syzkaller.appspot.com/bug?extid=aa8cbd84a995ad73d540
compiler: Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/bd13425862f1/disk-924b4a87.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/eaa5de9e440b/vmlinux-924b4a87.xz
kernel image: https://storage.googleapis.com/syzbot-assets/5a9aa3293c15/bzImage-924b4a87.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+aa8cbd...@syzkaller.appspotmail.com

rcu: INFO: rcu_preempt detected stalls on CPUs/tasks:
rcu: Tasks blocked on level-0 rcu_node (CPUs 0-1): P8109/1:b..l P5773/1:b..l P5140/1:b..l
rcu: (detected by 1, t=10502 jiffies, g=28685, q=312 ncpus=2)
task:udevd state:R running task stack:23592 pid:5140 ppid:1 flags:0x00004002
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5381 [inline]
__schedule+0x1553/0x45a0 kernel/sched/core.c:6700
preempt_schedule_irq+0xbf/0x150 kernel/sched/core.c:7010
irqentry_exit+0x67/0x70 kernel/entry/common.c:438
asm_sysvec_reschedule_ipi+0x1a/0x20 arch/x86/include/asm/idtentry.h:692
RIP: 0010:rcu_read_lock include/linux/rcupdate.h:787 [inline]
RIP: 0010:is_bpf_text_address+0x68/0x2a0 kernel/bpf/core.c:741
Code: 44 24 08 50 e8 69 ac d3 ff 48 83 c4 08 e8 80 de f3 08 89 c5 31 ff 89 c6 e8 35 ac f2 ff 85 ed 74 10 e8 cc 66 dc ff 84 c0 74 0e <e8> 73 a8 f2 ff eb 56 e8 6c a8 f2 ff eb 4f e8 55 de f3 08 89 c5 31
RSP: 0018:ffffc90003047968 EFLAGS: 00000202
RAX: 0000000000000001 RBX: 00007f673f515a67 RCX: b3e8ab89a793b800
RDX: ffff88807e9ada00 RSI: ffffffff8b1c9c00 RDI: ffffffff8b1c9bc0
RBP: 0000000000000001 R08: dffffc0000000000 R09: 1ffffffff2239aa0
R10: dffffc0000000000 R11: fffffbfff2239aa1 R12: ffffffff8aa000d0
R13: 1ffff92000608fc4 R14: 00007f673f515a67 R15: 1ffff92000608f4a
kernel_text_address+0xa0/0xd0 kernel/extable.c:125
__kernel_text_address+0xd/0x30 kernel/extable.c:79
unwind_get_return_address+0x5d/0xc0 arch/x86/kernel/unwind_orc.c:369
arch_stack_walk+0x11d/0x190 arch/x86/kernel/stacktrace.c:26
stack_trace_save+0xaa/0x100 kernel/stacktrace.c:122
kasan_save_stack+0x3e/0x60 mm/kasan/common.c:46
__kasan_record_aux_stack+0xaf/0xc0 mm/kasan/generic.c:492
__call_rcu_common kernel/rcu/tree.c:2721 [inline]
call_rcu+0x153/0x950 kernel/rcu/tree.c:2837
__do_sys_close fs/open.c:1573 [inline]
__se_sys_close+0x15f/0x220 fs/open.c:1558
do_syscall_x64 arch/x86/entry/common.c:46 [inline]
do_syscall_64+0x55/0xb0 arch/x86/entry/common.c:76
entry_SYSCALL_64_after_hwframe+0x68/0xd2
RIP: 0033:0x7f673f515a67
RSP: 002b:00007fff64f68728 EFLAGS: 00000297 ORIG_RAX: 0000000000000003
RAX: ffffffffffffffda RBX: 000055592782c280 RCX: 00007f673f515a67
RDX: 00007f673f5efea0 RSI: 00005559278d5120 RDI: 000000000000000c
RBP: 00007f673f5efff0 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000297 R12: 0000000000000000
R13: 3d45505954564544 R14: 3d5845444e494649 R15: 3d454d414e564544
</TASK>
task:syz-executor state:R running task stack:21384 pid:5773 ppid:5769 flags:0x00004000
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5381 [inline]
__schedule+0x1553/0x45a0 kernel/sched/core.c:6700
preempt_schedule_common+0x82/0xc0 kernel/sched/core.c:6867
preempt_schedule+0xc0/0xd0 kernel/sched/core.c:6891
preempt_schedule_thunk+0x1a/0x30 arch/x86/entry/thunk_64.S:45
__raw_spin_unlock include/linux/spinlock_api_smp.h:143 [inline]
_raw_spin_unlock+0x3a/0x40 kernel/locking/spinlock.c:186
spin_unlock include/linux/spinlock.h:391 [inline]
copy_pte_range mm/memory.c:1107 [inline]
copy_pmd_range mm/memory.c:1168 [inline]
copy_pud_range mm/memory.c:1205 [inline]
copy_p4d_range mm/memory.c:1229 [inline]
copy_page_range+0x2ba0/0x3670 mm/memory.c:1323
dup_mmap kernel/fork.c:769 [inline]
dup_mm kernel/fork.c:1694 [inline]
copy_mm+0x1281/0x1d80 kernel/fork.c:1743
copy_process+0x16f7/0x3dc0 kernel/fork.c:2508
kernel_clone+0x24b/0x8a0 kernel/fork.c:2917
__do_sys_clone kernel/fork.c:3060 [inline]
__se_sys_clone kernel/fork.c:3044 [inline]
__x64_sys_clone+0x1b7/0x230 kernel/fork.c:3044
do_syscall_x64 arch/x86/entry/common.c:46 [inline]
do_syscall_64+0x55/0xb0 arch/x86/entry/common.c:76
entry_SYSCALL_64_after_hwframe+0x68/0xd2
RIP: 0033:0x7f4026fc58d2
RSP: 002b:00007ffde554ccf0 EFLAGS: 00000246 ORIG_RAX: 0000000000000038
RAX: ffffffffffffffda RBX: 00007ffde554ccf0 RCX: 00007f4026fc58d2
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000001200011
RBP: 00007ffde554ce7c R08: 0000000000000000 R09: 0000000000000001
R10: 0000555589ee27d0 R11: 0000000000000246 R12: 0000000000000001
R13: 00000000000927c0 R14: 000000000005aeea R15: 00007ffde554ced0
</TASK>
task:sed state:R running task stack:24232 pid:8109 ppid:8108 flags:0x00004000
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5381 [inline]
__schedule+0x1553/0x45a0 kernel/sched/core.c:6700
preempt_schedule_irq+0xbf/0x150 kernel/sched/core.c:7010
irqentry_exit+0x67/0x70 kernel/entry/common.c:438
asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:687
RIP: 0010:lock_acquire+0x208/0x420 kernel/locking/lockdep.c:5758
Code: f7 84 24 80 00 00 00 00 02 00 00 43 c6 44 3c 04 f8 0f 85 f0 00 00 00 41 f7 c6 00 02 00 00 74 01 fb 48 c7 44 24 60 0e 36 e0 45 <4b> c7 04 3c 00 00 00 00 43 c7 44 3c 08 00 00 00 00 65 48 8b 04 25
RSP: 0018:ffffc9000dabf840 EFLAGS: 00000206
RAX: 0000000000000001 RBX: 0000000000000000 RCX: d72886468ed06300
RDX: 0000000000000000 RSI: ffffffff8acadd60 RDI: ffffffff8b1c9c20
RBP: ffffc9000dabf958 R08: dffffc0000000000 R09: 1ffffffff2239aa0
R10: dffffc0000000000 R11: fffffbfff2239aa1 R12: 1ffff92001b57f14
R13: ffffffff8d132160 R14: 0000000000000246 R15: dffffc0000000000
rcu_lock_acquire include/linux/rcupdate.h:334 [inline]
rcu_read_lock include/linux/rcupdate.h:786 [inline]
get_obj_cgroup_from_current+0xf0/0x280 mm/memcontrol.c:3058
memcg_slab_pre_alloc_hook mm/slab.h:492 [inline]
slab_pre_alloc_hook+0x91/0x310 mm/slab.h:719
slab_alloc_node mm/slub.c:3477 [inline]
slab_alloc mm/slub.c:3503 [inline]
__kmem_cache_alloc_lru mm/slub.c:3510 [inline]
kmem_cache_alloc+0x5a/0x2d0 mm/slub.c:3519
vma_lock_alloc kernel/fork.c:461 [inline]
vm_area_alloc+0x10e/0x1d0 kernel/fork.c:492
__mmap_region mm/mmap.c:2770 [inline]
mmap_region+0xc2f/0x2000 mm/mmap.c:2941
do_mmap+0x92c/0x10a0 mm/mmap.c:1385
vm_mmap_pgoff+0x1c4/0x3f0 mm/util.c:556
ksys_mmap_pgoff+0x520/0x700 mm/mmap.c:1431
do_syscall_x64 arch/x86/entry/common.c:46 [inline]
do_syscall_64+0x55/0xb0 arch/x86/entry/common.c:76
entry_SYSCALL_64_after_hwframe+0x68/0xd2
RIP: 0033:0x7f47f3b6f242
RSP: 002b:00007ffc430c7b48 EFLAGS: 00000206 ORIG_RAX: 0000000000000009
RAX: ffffffffffffffda RBX: 00007f47f3a76000 RCX: 00007f47f3b6f242
RDX: 0000000000000003 RSI: 0000000000006000 RDI: 00007f47f3a76000
RBP: 0000000000000812 R08: 0000000000000003 R09: 00000000001cc000
R10: 0000000000000812 R11: 0000000000000206 R12: 00007ffc430c7c08
R13: 00007f47f3b4b5f0 R14: 00007ffc430c8380 R15: 00000fff88618f6c
</TASK>
rcu: rcu_preempt kthread starved for 10603 jiffies! g28685 f0x0 RCU_GP_WAIT_FQS(5) ->state=0x0 ->cpu=1
rcu: Unless rcu_preempt kthread gets sufficient CPU time, OOM is now expected behavior.
rcu: RCU grace-period kthread stack dump:
task:rcu_preempt state:R running task stack:26568 pid:17 ppid:2 flags:0x00004000
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5381 [inline]
__schedule+0x1553/0x45a0 kernel/sched/core.c:6700
schedule+0xbd/0x170 kernel/sched/core.c:6774
schedule_timeout+0x188/0x2d0 kernel/time/timer.c:2168
rcu_gp_fqs_loop+0x313/0x1590 kernel/rcu/tree.c:1667
rcu_gp_kthread+0x9d/0x3b0 kernel/rcu/tree.c:1866
kthread+0x2fa/0x390 kernel/kthread.c:388
ret_from_fork+0x48/0x80 arch/x86/kernel/process.c:152
ret_from_fork_asm+0x11/0x20 arch/x86/entry/entry_64.S:293
</TASK>
rcu: Stack dump where RCU GP kthread last ran:
CPU: 1 PID: 0 Comm: swapper/1 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/09/2026
RIP: 0010:pv_native_safe_halt+0xf/0x10 arch/x86/kernel/paravirt.c:148
Code: 88 1f 02 c3 cc cc cc cc cc cc cc f3 0f 1e fa 0f 0b 66 2e 0f 1f 84 00 00 00 00 00 f3 0f 1e fa 66 90 0f 00 2d 43 e4 3f 00 fb f4 <c3> 66 0f 1f 00 55 41 57 41 56 41 54 53 50 8b 2f eb 2e 41 89 de 80
RSP: 0018:ffffc90000187de0 EFLAGS: 000002c2
RAX: bb50b1a74e051200 RBX: ffffffff8162ae21 RCX: bb50b1a74e051200
RDX: 0000000000000001 RSI: ffffffff8acacbe0 RDI: ffffffff8b1c9c20
RBP: ffffc90000187f20 R08: ffff8880b8f36bab R09: 1ffff110171e6d75
R10: dffffc0000000000 R11: ffffed10171e6d76 R12: 1ffff92000030fc8
R13: dffffc0000000000 R14: 1ffff1100344f780 R15: 0000000000000000
FS: 0000000000000000(0000) GS:ffff8880b8f00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f4027d456b8 CR3: 00000000777b8000 CR4: 00000000003506e0
Call Trace:
<TASK>
arch_safe_halt arch/x86/include/asm/paravirt.h:108 [inline]
default_idle+0x13/0x20 arch/x86/kernel/process.c:753
default_idle_call+0x6c/0xa0 kernel/sched/idle.c:97
cpuidle_idle_call kernel/sched/idle.c:178 [inline]
do_idle+0x221/0x590 kernel/sched/idle.c:302
cpu_startup_entry+0x43/0x60 kernel/sched/idle.c:401
start_secondary+0xee/0xf0 arch/x86/kernel/smpboot.c:323
secondary_startup_64_no_verify+0x179/0x17b
</TASK>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages