[v6.6] INFO: rcu detected stall in sys_mprotect (2)

2 views
Skip to first unread message

syzbot

unread,
Dec 13, 2025, 10:47:32 PM (2 days ago) Dec 13
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 5fa4793a2d2d Linux 6.6.119
git tree: linux-6.6.y
console output: https://syzkaller.appspot.com/x/log.txt?x=10b37e1a580000
kernel config: https://syzkaller.appspot.com/x/.config?x=691a6769a86ac817
dashboard link: https://syzkaller.appspot.com/bug?extid=5d7bb221a7b75f9747e2
compiler: Debian clang version 20.1.8 (++20250708063551+0c9f909b7976-1~exp1~20250708183702.136), Debian LLD 20.1.8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/63699875f1dd/disk-5fa4793a.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/8506652fcb6f/vmlinux-5fa4793a.xz
kernel image: https://storage.googleapis.com/syzbot-assets/1b30ceed1710/bzImage-5fa4793a.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+5d7bb2...@syzkaller.appspotmail.com

rcu: INFO: rcu_preempt detected stalls on CPUs/tasks:
rcu: Tasks blocked on level-0 rcu_node (CPUs 0-1): P7354/1:b..l
rcu: (detected by 0, t=10502 jiffies, g=27089, q=342 ncpus=2)
task:udevd state:R running task stack:24968 pid:7354 ppid:5136 flags:0x00004002
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5380 [inline]
__schedule+0x14d2/0x44d0 kernel/sched/core.c:6699
preempt_schedule_irq+0xb5/0x140 kernel/sched/core.c:7009
irqentry_exit+0x67/0x70 kernel/entry/common.c:438
asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:687
RIP: 0010:mas_mn lib/maple_tree.c:313 [inline]
RIP: 0010:mas_next_node+0xf1/0xa10 lib/maple_tree.c:4546
Code: 25 7e fe ff 89 c5 31 ff 89 c6 e8 9a b5 2e f7 85 ed 0f 85 30 08 00 00 48 bd 00 00 00 00 00 fc ff df 48 8b 44 24 40 80 3c 28 00 <4c> 8b 74 24 28 74 08 4c 89 f7 e8 b0 1f 86 f7 4d 8b 3e 4d 89 fd 49
RSP: 0018:ffffc9000b8bf670 EFLAGS: 00000246
RAX: 1ffff92001717f07 RBX: ffffc9000b8bf820 RCX: 0000000000000000
RDX: ffff888027c38000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: dffffc0000000000 R08: 0000000000000003 R09: 0000000000000004
R10: dffffc0000000000 R11: fffffbfff2e5551c R12: 00007f0c17b37000
R13: ffff8880777dd800 R14: 0000000000000000 R15: dffffc0000000000
mas_dfs_postorder lib/maple_tree.c:6701 [inline]
mt_validate+0x310c/0x4530 lib/maple_tree.c:7235
validate_mm+0xb1/0x420 mm/mmap.c:288
vma_merge+0x1ab6/0x2110 mm/mmap.c:1035
mprotect_fixup+0x47f/0xc90 mm/mprotect.c:632
do_mprotect_pkey+0x76e/0xc30 mm/mprotect.c:819
__do_sys_mprotect mm/mprotect.c:840 [inline]
__se_sys_mprotect mm/mprotect.c:837 [inline]
__x64_sys_mprotect+0x80/0x90 mm/mprotect.c:837
do_syscall_x64 arch/x86/entry/common.c:51 [inline]
do_syscall_64+0x55/0xb0 arch/x86/entry/common.c:81
entry_SYSCALL_64_after_hwframe+0x68/0xd2
RIP: 0033:0x7f0c1751dfe7
RSP: 002b:00007ffc631bf548 EFLAGS: 00000246 ORIG_RAX: 000000000000000a
RAX: ffffffffffffffda RBX: 0000000000000200 RCX: 00007f0c1751dfe7
RDX: 0000000000000001 RSI: 0000000000000200 RDI: 00007f0c173ba000
RBP: 000055a71756f050 R08: 0000000000000000 R09: 0000000000000200
R10: 000055a71756f0b0 R11: 0000000000000246 R12: 0000000000000038
R13: 0000000000000400 R14: 000055a717570638 R15: 00007f0c17c0d39c
</TASK>
rcu: rcu_preempt kthread starved for 10530 jiffies! g27089 f0x0 RCU_GP_WAIT_FQS(5) ->state=0x0 ->cpu=1
rcu: Unless rcu_preempt kthread gets sufficient CPU time, OOM is now expected behavior.
rcu: RCU grace-period kthread stack dump:
task:rcu_preempt state:R running task stack:27752 pid:17 ppid:2 flags:0x00004000
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5380 [inline]
__schedule+0x14d2/0x44d0 kernel/sched/core.c:6699
schedule+0xbd/0x170 kernel/sched/core.c:6773
schedule_timeout+0x160/0x280 kernel/time/timer.c:2168
rcu_gp_fqs_loop+0x302/0x1560 kernel/rcu/tree.c:1667
rcu_gp_kthread+0x99/0x380 kernel/rcu/tree.c:1866
kthread+0x2fa/0x390 kernel/kthread.c:388
ret_from_fork+0x48/0x80 arch/x86/kernel/process.c:152
ret_from_fork_asm+0x11/0x20 arch/x86/entry/entry_64.S:293
</TASK>
rcu: Stack dump where RCU GP kthread last ran:
Sending NMI from CPU 0 to CPUs 1:
NMI backtrace for cpu 1
CPU: 1 PID: 0 Comm: swapper/1 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/25/2025
RIP: 0010:pv_native_safe_halt+0x13/0x20 arch/x86/kernel/paravirt.c:148
Code: cc cc cc cc cc cc cc f3 0f 1e fa 0f 0b 66 2e 0f 1f 84 00 00 00 00 00 f3 0f 1e fa 66 90 0f 00 2d 23 bb 40 00 f3 0f 1e fa fb f4 <c3> cc cc cc cc cc cc cc cc cc cc cc cc 66 0f 1f 00 55 41 57 41 56
RSP: 0018:ffffc90000187de0 EFLAGS: 000002c2
RAX: de8f67998b20ed00 RBX: ffffffff8161881b RCX: de8f67998b20ed00
RDX: 0000000000000001 RSI: ffffffff8aaabce0 RDI: ffffffff8afc6f80
RBP: ffffc90000187f20 R08: ffff8880b8f36b2b R09: 1ffff110171e6d65
R10: dffffc0000000000 R11: ffffed10171e6d66 R12: ffffffff8e4a2128
R13: 0000000000000001 R14: 0000000000000001 R15: 1ffff1100364e780
FS: 0000000000000000(0000) GS:ffff8880b8f00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000200000000058 CR3: 000000005f253000 CR4: 00000000003506e0
Call Trace:
<TASK>
arch_safe_halt arch/x86/include/asm/paravirt.h:108 [inline]
default_idle+0x13/0x20 arch/x86/kernel/process.c:753
default_idle_call+0x6c/0xa0 kernel/sched/idle.c:97
cpuidle_idle_call kernel/sched/idle.c:170 [inline]
do_idle+0x1eb/0x510 kernel/sched/idle.c:282
cpu_startup_entry+0x43/0x60 kernel/sched/idle.c:380
start_secondary+0xee/0xf0 arch/x86/kernel/smpboot.c:323
secondary_startup_64_no_verify+0x179/0x17b
</TASK>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages