Hello,
syzbot found the following issue on:
HEAD commit: aa0e49877a2e Linux 6.6.148
git tree: linux-6.6.y
console output:
https://syzkaller.appspot.com/x/log.txt?x=16955bb9580000
kernel config:
https://syzkaller.appspot.com/x/.config?x=f0bc3d90c30838b5
dashboard link:
https://syzkaller.appspot.com/bug?extid=48dcddd9870cdc33faee
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/f83b390cfc1f/disk-aa0e4987.raw.xz
vmlinux:
https://storage.googleapis.com/syzbot-assets/1d4bdb338edd/vmlinux-aa0e4987.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/3f57c1d51ee3/bzImage-aa0e4987.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+48dcdd...@syzkaller.appspotmail.com
BUG: sleeping function called from invalid context at kernel/workqueue.c:3414
in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 16, name: ksoftirqd/0
preempt_count: 100, expected: 0
RCU nest depth: 0, expected: 0
1 lock held by ksoftirqd/0/16:
#0: ffffc90000157a40 ((&vub300->inactivity_timer)){+.-.}-{0:0}, at: call_timer_fn+0xd2/0x540 kernel/time/timer.c:1698
Preemption disabled at:
[<ffffffff8152cfe1>] softirq_handle_begin kernel/softirq.c:419 [inline]
[<ffffffff8152cfe1>] handle_softirqs+0x101/0x820 kernel/softirq.c:554
CPU: 0 PID: 16 Comm: ksoftirqd/0 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
Call Trace:
<TASK>
dump_stack_lvl+0x18c/0x250 lib/dump_stack.c:106
__might_resched+0x48d/0x5f0 kernel/sched/core.c:10212
start_flush_work kernel/workqueue.c:3414 [inline]
__flush_work+0x10f/0xac0 kernel/workqueue.c:3474
__cancel_work_timer+0x3f8/0x560 kernel/workqueue.c:3562
mmc_free_host+0x19/0x30 drivers/mmc/core/host.c:694
call_timer_fn+0x189/0x540 kernel/time/timer.c:1701
expire_timers kernel/time/timer.c:1752 [inline]
__run_timers+0x570/0x810 kernel/time/timer.c:2023
run_timer_softirq+0x67/0xf0 kernel/time/timer.c:2036
handle_softirqs+0x27d/0x820 kernel/softirq.c:578
run_ksoftirqd+0xa8/0x100 kernel/softirq.c:950
smpboot_thread_fn+0x651/0x9f0 kernel/smpboot.c:164
kthread+0x2fa/0x390 kernel/kthread.c:388
ret_from_fork+0x48/0x80 arch/x86/kernel/process.c:152
ret_from_fork_asm+0x11/0x20 arch/x86/entry/entry_64.S:293
</TASK>
BUG: scheduling while atomic: ksoftirqd/0/16/0x00000101
1 lock held by ksoftirqd/0/16:
#0: ffffc90000157a40 ((&vub300->inactivity_timer)){+.-.}-{0:0}, at: call_timer_fn+0xd2/0x540 kernel/time/timer.c:1698
Modules linked in:
Preemption disabled at:
[<ffffffff8152cfe1>] softirq_handle_begin kernel/softirq.c:419 [inline]
[<ffffffff8152cfe1>] handle_softirqs+0x101/0x820 kernel/softirq.c:554
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup