[v5.15] INFO: task hung in n_tty_receive_char

0 views
Skip to first unread message

syzbot

unread,
Aug 2, 2026, 10:26:33 AM (10 days ago) Aug 2
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 6e2fd6534337 Linux 5.15.213
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=156c4db9580000
kernel config: https://syzkaller.appspot.com/x/.config?x=f161cbc9aef65db0
dashboard link: https://syzkaller.appspot.com/bug?extid=ecd7004a9d2067ddef1b
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/d7b46606b13d/disk-6e2fd653.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/da120fdeb081/vmlinux-6e2fd653.xz
kernel image: https://storage.googleapis.com/syzbot-assets/3c2643457e3f/bzImage-6e2fd653.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+ecd700...@syzkaller.appspotmail.com

INFO: task kworker/u4:5:4236 blocked for more than 143 seconds.
Not tainted syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:kworker/u4:5 state:D stack:21904 pid: 4236 ppid: 2 flags:0x00004000
Workqueue: events_unbound flush_to_ldisc
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5049 [inline]
__schedule+0x11c3/0x4350 kernel/sched/core.c:6395
schedule+0x11b/0x1e0 kernel/sched/core.c:6478
schedule_preempt_disabled+0xf/0x20 kernel/sched/core.c:6537
__mutex_lock_common+0xdf5/0x2400 kernel/locking/mutex.c:669
__mutex_lock kernel/locking/mutex.c:729 [inline]
mutex_lock_nested+0x17/0x20 kernel/locking/mutex.c:743
commit_echoes drivers/tty/n_tty.c:775 [inline]
n_tty_receive_char+0x5ed/0xbb0 drivers/tty/n_tty.c:1411
n_tty_receive_buf_standard drivers/tty/n_tty.c:-1 [inline]
__receive_buf drivers/tty/n_tty.c:1577 [inline]
n_tty_receive_buf_common+0x170c/0x65b0 drivers/tty/n_tty.c:1674
tty_port_default_receive_buf+0x69/0x90 drivers/tty/tty_port.c:39
receive_buf drivers/tty/tty_buffer.c:471 [inline]
flush_to_ldisc+0x2a1/0x530 drivers/tty/tty_buffer.c:523
process_one_work+0x867/0xff0 kernel/workqueue.c:2310
worker_thread+0xad7/0x12a0 kernel/workqueue.c:2457
kthread+0x42e/0x520 kernel/kthread.c:334
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:287
</TASK>

Showing all locks held in the system:
1 lock held by khungtaskd/27:
#0: ffffffff8c31ef60 (rcu_read_lock){....}-{1:2}, at: rcu_lock_acquire+0x0/0x30
1 lock held by udevd/3558:
#0: ffff888020388518 (&disk->open_mutex){+.+.}-{3:3}, at: blkdev_get_by_dev+0x162/0xa50 block/bdev.c:816
2 locks held by getty/3944:
#0: ffff88814cf5f098 (&tty->ldisc_sem){++++}-{0:0}, at: tty_ldisc_ref_wait+0x21/0x70 drivers/tty/tty_ldisc.c:252
#1: ffffc900025e62e8 (&ldata->atomic_read_lock){+.+.}-{3:3}, at: n_tty_read+0x594/0x1a50 drivers/tty/n_tty.c:2158
6 locks held by kworker/u4:5/4236:
#0: ffff888016c79138 ((wq_completion)events_unbound){+.+.}-{0:0}, at: process_one_work+0x75c/0xff0 kernel/workqueue.c:-1
#1: ffffc9000320fd00 ((work_completion)(&buf->work)){+.+.}-{0:0}, at: process_one_work+0x79e/0xff0 kernel/workqueue.c:2285
#2: ffff888016de00b8 (&buf->lock){+.+.}-{3:3}, at: flush_to_ldisc+0x34/0x530 drivers/tty/tty_buffer.c:495
#3: ffff888023742098 (&tty->ldisc_sem){++++}-{0:0}, at: tty_ldisc_ref+0x18/0x80 drivers/tty/tty_ldisc.c:273
#4: ffff8880237422e8 (&tty->termios_rwsem){++++}-{3:3}, at: n_tty_receive_buf_common+0x87/0x65b0 drivers/tty/n_tty.c:1637
#5: ffffc9000112c378 (&ldata->output_lock){+.+.}-{3:3}, at: commit_echoes drivers/tty/n_tty.c:775 [inline]
#5: ffffc9000112c378 (&ldata->output_lock){+.+.}-{3:3}, at: n_tty_receive_char+0x5ed/0xbb0 drivers/tty/n_tty.c:1411
2 locks held by udevd/4648:
#0: ffff888020390518 (&disk->open_mutex){+.+.}-{3:3}, at: blkdev_put+0xf1/0x780 block/bdev.c:911
#1: ffff888147626468 (&lo->lo_mutex){+.+.}-{3:3}, at: __loop_clr_fd+0xa9/0xb50 drivers/block/loop.c:1366
1 lock held by udevd/4649:
#0: ffff888020388518 (&disk->open_mutex){+.+.}-{3:3}, at: blkdev_get_by_dev+0x162/0xa50 block/bdev.c:816
3 locks held by kworker/0:13/7118:
#0: ffff888016c70938 ((wq_completion)events){+.+.}-{0:0}, at: process_one_work+0x75c/0xff0 kernel/workqueue.c:-1
#1: ffffc90003d1fd00 ((work_completion)(&data->fib_event_work)){+.+.}-{0:0}, at: process_one_work+0x79e/0xff0 kernel/workqueue.c:2285
#2: ffff888067fc9240 (&data->fib_lock){+.+.}-{3:3}, at: nsim_fib_event_work+0x283/0x3380 drivers/net/netdevsim/fib.c:1480
3 locks held by kworker/0:18/7131:
#0: ffff8881417b3938 ((wq_completion)usb_hub_wq){+.+.}-{0:0}, at: process_one_work+0x75c/0xff0 kernel/workqueue.c:-1
#1: ffffc90003ecfd00 ((work_completion)(&hub->events)){+.+.}-{0:0}, at: process_one_work+0x79e/0xff0 kernel/workqueue.c:2285
#2: ffff888024320220 (&dev->mutex){....}-{3:3}, at: device_lock include/linux/device.h:809 [inline]
#2: ffff888024320220 (&dev->mutex){....}-{3:3}, at: hub_event+0x178/0x5260 drivers/usb/core/hub.c:5827
3 locks held by kworker/0:23/16157:
#0: ffff888016c70938 ((wq_completion)events){+.+.}-{0:0}, at: process_one_work+0x75c/0xff0 kernel/workqueue.c:-1
#1: ffffc90004647d00 ((work_completion)(&data->fib_event_work)){+.+.}-{0:0}, at: process_one_work+0x79e/0xff0 kernel/workqueue.c:2285
#2: ffff8880650da240 (&data->fib_lock){+.+.}-{3:3}, at: nsim_fib_event_work+0x283/0x3380 drivers/net/netdevsim/fib.c:1480
5 locks held by syz.7.2894/19073:
1 lock held by syz-executor/19381:
#0: ffff88807aa640e0 (&type->s_umount_key#67){++++}-{3:3}, at: deactivate_super+0xa0/0xd0 fs/super.c:365
4 locks held by kworker/u4:1/19435:
#0: ffff888016dcd938 ((wq_completion)netns){+.+.}-{0:0}, at: process_one_work+0x75c/0xff0 kernel/workqueue.c:-1
#1: ffffc900031bfd00 (net_cleanup_work){+.+.}-{0:0}, at: process_one_work+0x79e/0xff0 kernel/workqueue.c:2285
#2: ffffffff8d441550 (pernet_ops_rwsem){++++}-{3:3}, at: cleanup_net+0x148/0xba0 net/core/net_namespace.c:589
#3: ffffffff8c3238f0 (rcu_state.barrier_mutex){+.+.}-{3:3}, at: rcu_barrier+0xa1/0x4c0 kernel/rcu/tree.c:4043
3 locks held by kworker/u4:3/19859:
2 locks held by syz.1.3122/20451:
#0: ffffffff8c9f62e8 (tty_mutex){+.+.}-{3:3}, at: tty_open_by_driver drivers/tty/tty_io.c:2064 [inline]
#0: ffffffff8c9f62e8 (tty_mutex){+.+.}-{3:3}, at: tty_open+0x20a/0xcd0 drivers/tty/tty_io.c:2148
#1: ffff8880408921c0 (&tty->legacy_mutex){+.+.}-{3:3}, at: tty_init_dev+0x6f/0x470 drivers/tty/tty_io.c:1430
1 lock held by syz-executor/20695:
#0: ffff888147607468 (&lo->lo_mutex){+.+.}-{3:3}, at: __loop_clr_fd+0xa9/0xb50 drivers/block/loop.c:1366
1 lock held by syz.5.3167/20815:
#0: ffffffff8c9f62e8 (tty_mutex){+.+.}-{3:3}, at: tty_open_by_driver drivers/tty/tty_io.c:2064 [inline]
#0: ffffffff8c9f62e8 (tty_mutex){+.+.}-{3:3}, at: tty_open+0x20a/0xcd0 drivers/tty/tty_io.c:2148
1 lock held by syz-executor/21073:
#0: ffff888020390518 (&disk->open_mutex){+.+.}-{3:3}, at: blkdev_get_by_dev+0x162/0xa50 block/bdev.c:816
1 lock held by syz.7.3254/21558:
#0: ffffffff8c9f62e8 (tty_mutex){+.+.}-{3:3}, at: tty_open_by_driver drivers/tty/tty_io.c:2064 [inline]
#0: ffffffff8c9f62e8 (tty_mutex){+.+.}-{3:3}, at: tty_open+0x20a/0xcd0 drivers/tty/tty_io.c:2148
2 locks held by syz.3.3268/21622:
#0: ffff888020388518 (&disk->open_mutex){+.+.}-{3:3}, at: blkdev_put+0xf1/0x780 block/bdev.c:911
#1: ffff888147604468 (&lo->lo_mutex){+.+.}-{3:3}, at: lo_release+0x4d/0x1f0 drivers/block/loop.c:2071

=============================================

NMI backtrace for cpu 0
CPU: 0 PID: 27 Comm: khungtaskd Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
Call Trace:
<TASK>
dump_stack_lvl+0x188/0x250 lib/dump_stack.c:106
nmi_cpu_backtrace+0x3a2/0x3d0 lib/nmi_backtrace.c:111
nmi_trigger_cpumask_backtrace+0x163/0x280 lib/nmi_backtrace.c:62
trigger_all_cpu_backtrace include/linux/nmi.h:148 [inline]
check_hung_uninterruptible_tasks kernel/hung_task.c:212 [inline]
watchdog+0xe1b/0xe60 kernel/hung_task.c:369
kthread+0x42e/0x520 kernel/kthread.c:334
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:287
</TASK>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages