Hello,
syzbot found the following issue on:
HEAD commit: 365f9c7a6b81 Merge branches 'for-next/core' and 'for-next/..
git tree: git://
git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git for-kernelci
console output:
https://syzkaller.appspot.com/x/log.txt?x=10df7fde580000
kernel config:
https://syzkaller.appspot.com/x/.config?x=72c97575381cec47
dashboard link:
https://syzkaller.appspot.com/bug?extid=4fe15a97f93a978322a4
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
userspace arch: arm64
CC: [
da...@davemloft.net edum...@google.com ho...@kernel.org ji...@resnulli.us ku...@kernel.org linux-...@vger.kernel.org net...@vger.kernel.org pab...@redhat.com]
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/eafe0adb7386/disk-365f9c7a.raw.xz
vmlinux:
https://storage.googleapis.com/syzbot-assets/29422d607579/vmlinux-365f9c7a.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/98ca955a8b54/Image-365f9c7a.gz.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+4fe15a...@syzkaller.appspotmail.com
====================================
WARNING: syz.3.395/6091 still has locks held!
syzkaller #0 Not tainted
------------------------------------
1 lock held by syz.3.395/6091:
#0: ffff0000cf1b4258 (&devlink->lock_key#3){+.+.}-{4:4}, at: devl_lock+0x24/0x34 net/devlink/core.c:292
stack backtrace:
CPU: 1 UID: 0 PID: 6091 Comm: syz.3.395 Not tainted syzkaller #0 PREEMPT
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/02/2026
Call trace:
show_stack+0x2c/0x3c arch/arm64/kernel/stacktrace.c:499 (C)
__dump_stack+0x30/0x40 lib/dump_stack.c:94
dump_stack_lvl+0xd8/0x12c lib/dump_stack.c:120
dump_stack+0x1c/0x28 lib/dump_stack.c:129
print_held_locks_bug+0x90/0x98 kernel/locking/lockdep.c:6752
debug_check_no_locks_held+0x28/0x34 kernel/locking/lockdep.c:6760
try_to_freeze include/linux/freezer.h:62 [inline]
usermodehelper_read_trylock+0x1d8/0x294 kernel/umh.c:230
fw_load_from_user_helper drivers/base/firmware_loader/fallback.c:147 [inline]
firmware_fallback_sysfs+0x158/0x918 drivers/base/firmware_loader/fallback.c:238
_request_firmware+0xb34/0xf5c drivers/base/firmware_loader/main.c:898
request_firmware+0x4c/0x70 drivers/base/firmware_loader/main.c:948
devlink_compat_flash_update+0x134/0x27c net/devlink/dev.c:1247
dev_ethtool+0x63c/0x1c40 net/ethtool/ioctl.c:3676
dev_ioctl+0x2a4/0xcf0 net/core/dev_ioctl.c:751
sock_do_ioctl+0x198/0x254 net/socket.c:1314
sock_ioctl+0x55c/0x7ec net/socket.c:1421
vfs_ioctl fs/ioctl.c:51 [inline]
__do_sys_ioctl fs/ioctl.c:597 [inline]
__se_sys_ioctl fs/ioctl.c:583 [inline]
__arm64_sys_ioctl+0x14c/0x1c4 fs/ioctl.c:583
__invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]
invoke_syscall+0x98/0x244 arch/arm64/kernel/syscall.c:49
el0_svc_common+0xec/0x23c arch/arm64/kernel/syscall.c:121
do_el0_svc+0x4c/0x5c arch/arm64/kernel/syscall.c:140
el0_svc+0x64/0x260 arch/arm64/kernel/entry-common.c:736
el0t_64_sync_handler+0x48/0x148 arch/arm64/kernel/entry-common.c:755
el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:594
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup