Hello,
syzbot found the following issue on:
HEAD commit: 090666d3cc90 Linux 6.1.177
git tree: linux-6.1.y
console output:
https://syzkaller.appspot.com/x/log.txt?x=11b0e2b9580000
kernel config:
https://syzkaller.appspot.com/x/.config?x=f5aae664b2df43c2
dashboard link:
https://syzkaller.appspot.com/bug?extid=f1afb0a2511aa87b036a
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/0a97b9de9f21/disk-090666d3.raw.xz
vmlinux:
https://storage.googleapis.com/syzbot-assets/40f470f8fbd0/vmlinux-090666d3.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/baabfa2bfd44/bzImage-090666d3.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+f1afb0...@syzkaller.appspotmail.com
rcu: INFO: rcu_preempt detected expedited stalls on CPUs/tasks: { 0-.... } 2655 jiffies s: 22553 root: 0x1/.
rcu: blocking rcu_node structures (internal RCU debug):
Sending NMI from CPU 1 to CPUs 0:
NMI backtrace for cpu 0
CPU: 0 PID: 4568 Comm: kworker/u4:23 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/25/2026
Workqueue: 0x0 (bat_events)
RIP: 0010:memset+0x2d/0x40 mm/kasan/shadow.c:47
Code: 53 48 89 d3 89 f5 49 89 fe 48 8b 4c 24 18 48 89 d6 ba 01 00 00 00 e8 92 ec ff ff 84 c0 74 11 4c 89 f7 89 ee 48 89 da 5b 41 5e <5d> e9 0d 34 51 08 31 c0 5b 41 5e 5d c3 66 0f 1f 44 00 00 41 57 41
RSP: 0018:ffffc90000007110 EFLAGS: 00000002
RAX: 0000000000000001 RBX: 1ffff92000000e2c RCX: ffffffff816cefd1
RDX: 0000000000000010 RSI: 0000000000000000 RDI: ffff8880b8e3bbf0
RBP: 0000000000000000 R08: ffff8880b8e3bbff R09: 1ffff110171c777f
R10: dffffc0000000000 R11: ffffed10171c7780 R12: 0000000000000046
R13: dffffc0000000000 R14: ffff8880b8e3bbc0 R15: 1ffff110171c7782
FS: 0000000000000000(0000) GS:ffff8880b8e00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000001b2fc0fff8 CR3: 000000000c88e000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000600
Call Trace:
<IRQ>
init_irq_work include/linux/irq_work.h:39 [inline]
rcu_read_unlock_special+0x351/0x510 kernel/rcu/tree_plugin.h:675
__rcu_read_unlock+0x78/0xd0 kernel/rcu/tree_plugin.h:426
rcu_read_unlock include/linux/rcupdate.h:823 [inline]
trace_call_bpf+0x5bb/0x6b0 kernel/trace/bpf_trace.c:137
perf_trace_run_bpf_submit+0x79/0x1c0 kernel/events/core.c:10027
perf_trace_preemptirq_template+0x268/0x320 include/trace/events/preemptirq.h:14
trace_irq_enable_rcuidle+0xd3/0x140 include/trace/events/preemptirq.h:40
trace_hardirqs_on+0x24/0x40 kernel/trace/trace_preemptirq.c:44
asm_sysvec_irq_work+0x16/0x20 arch/x86/include/asm/idtentry.h:728
RIP: 0010:rcu_read_unlock_special+0x7f/0x510 kernel/rcu/tree_plugin.h:685
Code: eb 03 48 b8 f1 f1 f1 f1 f8 f2 f2 f2 4a 89 04 2b 42 c7 44 2b 08 f8 f3 f3 f3 65 44 8b 35 52 82 95 7e 41 f7 c6 00 00 f0 00 74 40 <48> c7 44 24 40 0e 36 e0 45 4a c7 04 2b 00 00 00 00 42 c7 44 2b 08
RSP: 0018:ffffc90000007580 EFLAGS: 00000206
RAX: f6d24c6d3de0df00 RBX: 1ffff92000000eb8 RCX: f6d24c6d3de0df00
RDX: dffffc0000000000 RSI: ffffffff8a8c17a0 RDI: ffffffff8adf42e0
RBP: ffffc90000007680 R08: ffffffff90b1030f R09: 1ffffffff2162061
R10: dffffc0000000000 R11: fffffbfff2162062 R12: 0000000000000246
R13: dffffc0000000000 R14: ffff8880b8e3bb00 R15: 0000000000000001
__rcu_read_unlock+0x78/0xd0 kernel/rcu/tree_plugin.h:426
rcu_read_unlock include/linux/rcupdate.h:823 [inline]
__icmp_send+0x6c4/0x1420 net/ipv4/icmp.c:809
ipv4_send_dest_unreach net/ipv4/route.c:1263 [inline]
ipv4_link_failure+0x667/0xa20 net/ipv4/route.c:1270
dst_link_failure include/net/dst.h:423 [inline]
arp_error_report+0x10e/0x160 net/ipv4/arp.c:296
neigh_invalidate+0x23b/0x460 net/core/neighbour.c:1064
neigh_timer_handler+0x929/0x1090 net/core/neighbour.c:1151
call_timer_fn+0x1ac/0x670 kernel/time/timer.c:1701
expire_timers kernel/time/timer.c:1752 [inline]
__run_timers+0x56c/0x810 kernel/time/timer.c:2023
run_timer_softirq+0x63/0xf0 kernel/time/timer.c:2036
handle_softirqs+0x291/0x910 kernel/softirq.c:596
__do_softirq kernel/softirq.c:630 [inline]
invoke_softirq kernel/softirq.c:470 [inline]
__irq_exit_rcu+0x13b/0x230 kernel/softirq.c:679
irq_exit_rcu+0x5/0x20 kernel/softirq.c:691
instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1118 [inline]
sysvec_apic_timer_interrupt+0xa0/0xc0 arch/x86/kernel/apic/apic.c:1118
</IRQ>
<TASK>
asm_sysvec_apic_timer_interrupt+0x16/0x20 arch/x86/include/asm/idtentry.h:691
RIP: 0010:finish_task_switch+0x267/0x8e0 kernel/sched/core.c:5124
Code: d6 08 85 c0 0f 84 38 01 00 00 48 85 db 0f 85 57 01 00 00 0f 1f 44 00 00 4c 89 e7 e8 d3 e3 e0 08 e8 8e 04 2f 00 fb 4c 8b 65 b8 <49> 8d bc 24 f8 15 00 00 48 89 f8 48 c1 e8 03 42 0f b6 04 30 84 c0
RSP: 0018:ffffc900054dfba0 EFLAGS: 00000286
RAX: f6d24c6d3de0df00 RBX: 0000000000000000 RCX: f6d24c6d3de0df00
RDX: dffffc0000000000 RSI: ffffffff8a8c17a0 RDI: ffffffff8adf42e0
RBP: ffffc900054dfbf0 R08: ffff8880b8e3580b R09: 1ffff110171c6b01
R10: dffffc0000000000 R11: ffffed10171c6b02 R12: ffff888024cc5a00
R13: 1ffff110171c76fa R14: dffffc0000000000 R15: ffff8880b8e3b7d0
context_switch kernel/sched/core.c:5248 [inline]
__schedule+0x1087/0x4030 kernel/sched/core.c:6562
schedule+0xb9/0x180 kernel/sched/core.c:6638
worker_thread+0xf5a/0x12a0 kernel/workqueue.c:2460
kthread+0x29d/0x330 kernel/kthread.c:376
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295
</TASK>
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup