Hello,
syzbot found the following issue on:
HEAD commit: 3a8358583626 Linux 6.1.129
git tree: linux-6.1.y
console output:
https://syzkaller.appspot.com/x/log.txt?x=11359c98580000
kernel config:
https://syzkaller.appspot.com/x/.config?x=ff93ecc085d8436e
dashboard link:
https://syzkaller.appspot.com/bug?extid=a88bd1d7bf686e214dbf
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
userspace arch: arm64
syz repro:
https://syzkaller.appspot.com/x/repro.syz?x=13d47fa4580000
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/3cc3985223b7/disk-3a835858.raw.xz
vmlinux:
https://storage.googleapis.com/syzbot-assets/e40398fb298b/vmlinux-3a835858.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/40469708dc9a/Image-3a835858.gz.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+a88bd1...@syzkaller.appspotmail.com
rcu: INFO: rcu_preempt detected stalls on CPUs/tasks:
rcu: Tasks blocked on level-0 rcu_node (CPUs 0-1): P3913/2:b..l
(detected by 0, t=10502 jiffies, g=5853, q=160 ncpus=2)
task:udevd state:R running task stack:0 pid:3913 ppid:1 flags:0x00000004
Call trace:
__switch_to+0x308/0x598 arch/arm64/kernel/process.c:553
context_switch kernel/sched/core.c:5243 [inline]
__schedule+0xef4/0x1d44 kernel/sched/core.c:6560
preempt_schedule_irq+0x8c/0x1b8 kernel/sched/core.c:6872
arm64_preempt_schedule_irq arch/arm64/kernel/entry-common.c:265 [inline]
__el1_irq arch/arm64/kernel/entry-common.c:474 [inline]
el1_interrupt+0x4c/0x68 arch/arm64/kernel/entry-common.c:486
el1h_64_irq_handler+0x18/0x24 arch/arm64/kernel/entry-common.c:491
el1h_64_irq+0x64/0x68 arch/arm64/kernel/entry.S:581
arch_local_irq_restore arch/arm64/include/asm/irqflags.h:122 [inline]
seqcount_lockdep_reader_access include/linux/seqlock.h:104 [inline]
read_seqbegin include/linux/seqlock.h:893 [inline]
read_seqbegin_or_lock+0x160/0x250 include/linux/seqlock.h:1187
prepend_path+0x2b4/0xb48 fs/d_path.c:170
d_absolute_path+0x13c/0x27c fs/d_path.c:233
tomoyo_get_absolute_path security/tomoyo/realpath.c:101 [inline]
tomoyo_realpath_from_path+0x24c/0x4cc security/tomoyo/realpath.c:271
tomoyo_get_realpath security/tomoyo/file.c:151 [inline]
tomoyo_path_perm+0x208/0x568 security/tomoyo/file.c:822
tomoyo_inode_getattr+0x28/0x38 security/tomoyo/tomoyo.c:122
security_inode_getattr+0xd8/0x124 security/security.c:1361
vfs_getattr fs/stat.c:158 [inline]
vfs_statx+0x184/0x420 fs/stat.c:233
vfs_fstatat fs/stat.c:267 [inline]
__do_sys_newfstatat fs/stat.c:437 [inline]
__se_sys_newfstatat fs/stat.c:431 [inline]
__arm64_sys_newfstatat+0x134/0x1c0 fs/stat.c:431
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2bc arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:140
do_el0_svc+0x58/0x13c arch/arm64/kernel/syscall.c:204
el0_svc+0x58/0x168 arch/arm64/kernel/entry-common.c:637
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:585
rcu: rcu_preempt kthread starved for 10502 jiffies! g5853 f0x0 RCU_GP_WAIT_FQS(5) ->state=0x0 ->cpu=0
rcu: Unless rcu_preempt kthread gets sufficient CPU time, OOM is now expected behavior.
rcu: RCU grace-period kthread stack dump:
task:rcu_preempt state:R running task stack:0 pid:16 ppid:2 flags:0x00000008
Call trace:
__switch_to+0x308/0x598 arch/arm64/kernel/process.c:553
context_switch kernel/sched/core.c:5243 [inline]
__schedule+0xef4/0x1d44 kernel/sched/core.c:6560
schedule+0xc4/0x170 kernel/sched/core.c:6636
schedule_timeout+0x1d8/0x344 kernel/time/timer.c:1965
rcu_gp_fqs_loop+0x2cc/0x1538 kernel/rcu/tree.c:1706
rcu_gp_kthread+0xc0/0x308 kernel/rcu/tree.c:1905
kthread+0x250/0x2d8 kernel/kthread.c:376
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:864
rcu: Stack dump where RCU GP kthread last ran:
CPU: 0 PID: 4476 Comm: syz.2.18 Not tainted 6.1.129-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 12/27/2024
pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : __raw_spin_unlock_irq include/linux/spinlock_api_smp.h:160 [inline]
pc : _raw_spin_unlock_irq+0x44/0x90 kernel/locking/spinlock.c:202
lr : __raw_spin_unlock_irq include/linux/spinlock_api_smp.h:159 [inline]
lr : _raw_spin_unlock_irq+0x3c/0x90 kernel/locking/spinlock.c:202
sp : ffff8000219979c0
x29: ffff8000219979c0 x28: ffff0000cde1a998 x27: ffff800021997d60
x26: 1ffff00004332f54 x25: dfff800000000000 x24: 1fffe00019bc3533
x23: 0000000000000021 x22: 0000000000000020 x21: 0000ffffbd781390
x20: ffff0000c99f5340 x19: ffff0000cde1a500 x18: 1fffe0001a30c29c
x17: 0000000000000000 x16: ffff80000830270c x15: 0000000000000000
x14: 0000000000000001 x13: 0000000000000000 x12: 0000000000000003
x11: 0000000000ff0100 x10: 0000000000000003 x9 : 0000000000000000
x8 : 00000000000000e0 x7 : 0000000018000004 x6 : 0000ffffbd781390
x5 : ffff800021997d80 x4 : ffff0000cde1a9b8 x3 : 0000000000000000
x2 : ffff8000219978e0 x1 : ffff80001247d5c0 x0 : ffff80019e280000
Call trace:
arch_local_irq_enable arch/arm64/include/asm/irqflags.h:35 [inline]
__raw_spin_unlock_irq include/linux/spinlock_api_smp.h:159 [inline]
_raw_spin_unlock_irq+0x44/0x90 kernel/locking/spinlock.c:202
spin_unlock_irq include/linux/spinlock.h:401 [inline]
get_signal+0x1258/0x1528 kernel/signal.c:2874
do_signal arch/arm64/kernel/signal.c:1076 [inline]
do_notify_resume+0x2f8/0x2cb8 arch/arm64/kernel/signal.c:1129
prepare_exit_to_user_mode arch/arm64/kernel/entry-common.c:137 [inline]
exit_to_user_mode arch/arm64/kernel/entry-common.c:142 [inline]
el0_svc+0x9c/0x168 arch/arm64/kernel/entry-common.c:638
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:585
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup