[v6.1] INFO: task hung in do_uevent

2 views
Skip to first unread message

syzbot

unread,
Aug 4, 2026, 5:23:32 PM (3 days ago) Aug 4
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: fb28aa725e05 Linux 6.1.180
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=13215bb9580000
kernel config: https://syzkaller.appspot.com/x/.config?x=31dfefc4a14efea3
dashboard link: https://syzkaller.appspot.com/bug?extid=a250ae8cd98c724fe377
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/9a6fe2a54d0f/disk-fb28aa72.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/742b23a1d931/vmlinux-fb28aa72.xz
kernel image: https://storage.googleapis.com/syzbot-assets/b3f257c16d2e/bzImage-fb28aa72.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+a250ae...@syzkaller.appspotmail.com

INFO: task syz.0.68:4734 blocked for more than 144 seconds.
Not tainted syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:syz.0.68 state:D stack:26000 pid:4734 ppid:4274 flags:0x00004004
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5246 [inline]
__schedule+0x107f/0x4030 kernel/sched/core.c:6563
schedule+0xb9/0x180 kernel/sched/core.c:6639
do_uevent+0x1e9/0x490 fs/dlm/lockspace.c:210
new_lockspace fs/dlm/lockspace.c:659 [inline]
__dlm_new_lockspace+0x1d6a/0x22b0 fs/dlm/lockspace.c:719
device_create_lockspace+0xc4/0x350 fs/dlm/user.c:426
device_write+0x893/0xea0 fs/dlm/user.c:618
vfs_write+0x2dc/0x9a0 fs/read_write.c:582
ksys_write+0x14d/0x260 fs/read_write.c:637
do_syscall_x64 arch/x86/entry/common.c:46 [inline]
do_syscall_64+0x4c/0xa0 arch/x86/entry/common.c:76
entry_SYSCALL_64_after_hwframe+0x68/0xd2
RIP: 0033:0x7f075a99e019
RSP: 002b:00007f075b941028 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 00007f075ac25fa0 RCX: 00007f075a99e019
RDX: 0000000000000078 RSI: 0000200000000400 RDI: 0000000000000005
RBP: 00007f075aa3500c R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f075ac26038 R14: 00007f075ac25fa0 R15: 00007ffc0f74abf8
</TASK>

Showing all locks held in the system:
1 lock held by rcu_tasks_kthre/12:
#0: ffffffff8cb2e4f0 (rcu_tasks.tasks_gp_mutex){+.+.}-{3:3}, at: rcu_tasks_one_gp+0x33/0xef0 kernel/rcu/tasks.h:517
1 lock held by rcu_tasks_trace/13:
#0: ffffffff8cb2ed10 (rcu_tasks_trace.tasks_gp_mutex){+.+.}-{3:3}, at: rcu_tasks_one_gp+0x33/0xef0 kernel/rcu/tasks.h:517
2 locks held by kworker/1:0/22:
#0: ffff888017472138 ((wq_completion)rcu_gp){+.+.}-{0:0}, at: process_one_work+0x7b4/0x1160 kernel/workqueue.c:2267
#1: ffffc900001c7d00 ((work_completion)(&rew->rew_work)){+.+.}-{0:0}, at: process_one_work+0x7b4/0x1160 kernel/workqueue.c:2267
1 lock held by khungtaskd/27:
#0: ffffffff8cb2db60 (rcu_read_lock){....}-{1:2}, at: rcu_lock_acquire include/linux/rcupdate.h:350 [inline]
#0: ffffffff8cb2db60 (rcu_read_lock){....}-{1:2}, at: rcu_read_lock include/linux/rcupdate.h:791 [inline]
#0: ffffffff8cb2db60 (rcu_read_lock){....}-{1:2}, at: debug_show_all_locks+0x51/0x290 kernel/locking/lockdep.c:6527
1 lock held by dhcpcd/3933:
#0: ffffffff8dd5b968 (rtnl_mutex){+.+.}-{3:3}, at: __netlink_dump_start+0x11e/0x6f0 net/netlink/af_netlink.c:2310
2 locks held by getty/4028:
#0: ffff88814cbc6098 (&tty->ldisc_sem){++++}-{0:0}, at: tty_ldisc_ref_wait+0x21/0x70 drivers/tty/tty_ldisc.c:244
#1: ffffc9000327b2f0 (&ldata->atomic_read_lock){+.+.}-{3:3}, at: n_tty_read+0x41e/0x1360 drivers/tty/n_tty.c:2198
2 locks held by kworker/0:3/4290:
3 locks held by kworker/1:4/4320:
#0: ffff88802f3bad38 ((wq_completion)ipv6_addrconf){+.+.}-{0:0}, at: process_one_work+0x7b4/0x1160 kernel/workqueue.c:2267
#1: ffffc90004307d00 ((work_completion)(&(&ifa->dad_work)->work)){+.+.}-{0:0}, at: process_one_work+0x7b4/0x1160 kernel/workqueue.c:2267
#2: ffffffff8dd5b968 (rtnl_mutex){+.+.}-{3:3}, at: addrconf_dad_work+0xc4/0x1500 net/ipv6/addrconf.c:4138
5 locks held by kworker/u4:77/4480:
#0: ffff8880b8e3ad18 (&rq->__lock){-.-.}-{2:2}, at: raw_spin_rq_lock_nested+0x98/0x130 kernel/sched/core.c:546
#1: ffff8880b8e27888 (&per_cpu_ptr(group->pcpu, cpu)->seq){-.-.}-{0:0}, at: psi_task_switch+0x400/0x740 kernel/sched/psi.c:999
#2: ffff8880b8e27888 (&per_cpu_ptr(group->pcpu, cpu)->seq){-.-.}-{0:0}, at: psi_task_change+0xdc/0x240 kernel/sched/psi.c:924
#3: ffffffff96e5b850 (&obj_hash[i].lock){-.-.}-{2:2}, at: debug_object_activate+0x68/0x4f0 lib/debugobjects.c:747
#4: ffffffff8c9df808 (text_mutex){+.+.}-{3:3}, at: arch_jump_label_transform_apply+0xe/0x20 arch/x86/kernel/jump_label.c:145
4 locks held by kworker/u4:98/4501:
#0: ffff888017479138 ((wq_completion)events_unbound){+.+.}-{0:0}, at: process_one_work+0x7b4/0x1160 kernel/workqueue.c:2267
#1: ffffc900063c7d00 ((linkwatch_work).work){+.+.}-{0:0}, at: process_one_work+0x7b4/0x1160 kernel/workqueue.c:2267
#2: ffffffff8dd5b968 (rtnl_mutex){+.+.}-{3:3}, at: linkwatch_event+0xa/0x50 net/core/link_watch.c:263
#3: ffffffff8cb33838 (rcu_state.exp_mutex){+.+.}-{3:3}, at: exp_funnel_lock kernel/rcu/tree_exp.h:323 [inline]
#3: ffffffff8cb33838 (rcu_state.exp_mutex){+.+.}-{3:3}, at: synchronize_rcu_expedited+0x3c0/0x890 kernel/rcu/tree_exp.h:962
4 locks held by kworker/u4:100/4503:
#0: ffff88801761e938 ((wq_completion)netns){+.+.}-{0:0}, at: process_one_work+0x7b4/0x1160 kernel/workqueue.c:2267
#1: ffffc900063e7d00 (net_cleanup_work){+.+.}-{0:0}, at: process_one_work+0x7b4/0x1160 kernel/workqueue.c:2267
#2: ffffffff8dd4ead0 (pernet_ops_rwsem){++++}-{3:3}, at: cleanup_net+0x148/0xba0 net/core/net_namespace.c:594
#3: ffffffff8dd5b968 (rtnl_mutex){+.+.}-{3:3}, at: ip_tunnel_delete_nets+0xd2/0x370 net/ipv4/ip_tunnel.c:1152
1 lock held by syz.0.68/4734:
#0: ffffffff96d4d888 (&ls_lock){+.+.}-{3:3}, at: __dlm_new_lockspace+0xad/0x22b0 fs/dlm/lockspace.c:713
1 lock held by dlm_recoverd/4744:
#0: ffff8880769fcca0 (&ls->ls_in_recovery){+.+.}-{3:3}, at: dlm_recoverd+0xa6/0x1df0 fs/dlm/recoverd.c:312
1 lock held by syz-executor/5233:
#0: ffffffff8cb33838 (rcu_state.exp_mutex){+.+.}-{3:3}, at: exp_funnel_lock kernel/rcu/tree_exp.h:323 [inline]
#0: ffffffff8cb33838 (rcu_state.exp_mutex){+.+.}-{3:3}, at: synchronize_rcu_expedited+0x3c0/0x890 kernel/rcu/tree_exp.h:962
2 locks held by syz-executor/5768:
#0: ffffffff8ddbc170 (cb_lock){++++}-{3:3}, at: genl_rcv+0x15/0x40 net/netlink/genetlink.c:860
#1: ffffffff8dd5b968 (rtnl_mutex){+.+.}-{3:3}, at: nl80211_pre_doit+0x5a/0x890 net/wireless/nl80211.c:16372
3 locks held by syz.1.186/5947:
#0: ffff88807d0d34e8 (&f->f_pos_lock){+.+.}-{3:3}, at: __fdget_pos+0x2ae/0x360 fs/file.c:1038
#1: ffff888048548460 (sb_writers#14){.+.+}-{0:0}, at: vfs_write+0x270/0x9a0 fs/read_write.c:580
#2: ffffffff8cdcce08 (nfsd_mutex){+.+.}-{3:3}, at: nfsd_svc+0x61/0xab0 fs/nfsd/nfssvc.c:783

=============================================

NMI backtrace for cpu 0
CPU: 0 PID: 27 Comm: khungtaskd Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
Call Trace:
<TASK>
dump_stack_lvl+0x188/0x24e lib/dump_stack.c:106
nmi_cpu_backtrace+0x3e6/0x460 lib/nmi_backtrace.c:111
nmi_trigger_cpumask_backtrace+0x1d4/0x450 lib/nmi_backtrace.c:62
trigger_all_cpu_backtrace include/linux/nmi.h:148 [inline]
check_hung_uninterruptible_tasks kernel/hung_task.c:220 [inline]
watchdog+0xf0e/0xf50 kernel/hung_task.c:377
kthread+0x29d/0x330 kernel/kthread.c:376
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295
</TASK>
Sending NMI from CPU 0 to CPUs 1:
NMI backtrace for cpu 1
CPU: 1 PID: 4501 Comm: kworker/u4:98 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
Workqueue: xprtiod xs_tcp_setup_socket
RIP: 0010:preempt_latency_start kernel/sched/core.c:5695 [inline]
RIP: 0010:preempt_count_add+0xbf/0x190 kernel/sched/core.c:5718
Code: e8 86 6e 0c 00 65 4c 8b 35 5e b2 a9 7e 49 81 c6 d8 14 00 00 4c 89 f0 48 c1 e8 03 42 80 3c 38 00 74 08 4c 89 f7 e8 61 9e 7a 00 <49> 89 1e 5b 41 5e 41 5f c3 89 fb e8 11 dc b9 02 89 df 85 c0 74 9b
RSP: 0018:ffffc900063c7640 EFLAGS: 00000046
RAX: 1ffff11005683a1b RBX: 0000000000000000 RCX: ffffffff96c17100
RDX: dffffc0000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: ffffc900063c76f8 R08: ffffffff90b10357 R09: 1ffffffff216206a
R10: dffffc0000000000 R11: fffffbfff216206b R12: dffffc0000000000
R13: 0000000000000000 R14: ffff88802b41d0d8 R15: dffffc0000000000
FS: 0000000000000000(0000) GS:ffff8880b8f00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000056406d735138 CR3: 000000000c88e000 CR4: 00000000003506e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
__raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:109 [inline]
_raw_spin_lock_irqsave+0x95/0x100 kernel/locking/spinlock.c:162
__unfreeze_partials+0x8f/0x1e0 mm/slub.c:2555
put_cpu_partial+0x17c/0x250 mm/slub.c:2667
qlink_free mm/kasan/quarantine.c:168 [inline]
qlist_free_all+0x76/0xe0 mm/kasan/quarantine.c:187
kasan_quarantine_reduce+0x144/0x160 mm/kasan/quarantine.c:294
__kasan_slab_alloc+0x1e/0x80 mm/kasan/common.c:306
kasan_slab_alloc include/linux/kasan.h:201 [inline]
slab_post_alloc_hook+0x4b/0x490 mm/slab.h:737
slab_alloc_node mm/slub.c:3359 [inline]
slab_alloc mm/slub.c:3367 [inline]
__kmem_cache_alloc_lru mm/slub.c:3374 [inline]
kmem_cache_alloc+0x18b/0x2f0 mm/slub.c:3383
kmem_cache_zalloc include/linux/slab.h:689 [inline]
lsm_inode_alloc security/security.c:597 [inline]
security_inode_alloc+0x30/0x110 security/security.c:1041
inode_init_always+0x910/0xc90 fs/inode.c:232
alloc_inode fs/inode.c:268 [inline]
new_inode_pseudo+0x91/0x1c0 fs/inode.c:1063
sock_alloc net/socket.c:631 [inline]
__sock_create+0x129/0x940 net/socket.c:1514
xs_create_sock+0xfa/0x760 net/sunrpc/xprtsock.c:1841
xs_tcp_setup_socket+0x1c2/0xb80 net/sunrpc/xprtsock.c:2303
process_one_work+0x8ab/0x1160 kernel/workqueue.c:2292
worker_thread+0xaf5/0x12a0 kernel/workqueue.c:2439
kthread+0x29d/0x330 kernel/kthread.c:376
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295
</TASK>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Aug 4, 2026, 6:04:42 PM (3 days ago) Aug 4
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: aa0e49877a2e Linux 6.6.148
git tree: linux-6.6.y
console output: https://syzkaller.appspot.com/x/log.txt?x=12e7acc6580000
kernel config: https://syzkaller.appspot.com/x/.config?x=f0bc3d90c30838b5
dashboard link: https://syzkaller.appspot.com/bug?extid=f7adf4cd0ff444911ad2
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/f83b390cfc1f/disk-aa0e4987.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/1d4bdb338edd/vmlinux-aa0e4987.xz
kernel image: https://storage.googleapis.com/syzbot-assets/3f57c1d51ee3/bzImage-aa0e4987.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+f7adf4...@syzkaller.appspotmail.com

INFO: task syz.0.47:6029 blocked for more than 184 seconds.
Not tainted syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:syz.0.47 state:D stack:24496 pid:6029 ppid:5780 flags:0x00004006
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5382 [inline]
__schedule+0x15ae/0x4660 kernel/sched/core.c:6701
schedule+0xbd/0x170 kernel/sched/core.c:6775
do_uevent+0x1ed/0x490 fs/dlm/lockspace.c:210
new_lockspace fs/dlm/lockspace.c:633 [inline]
__dlm_new_lockspace+0x1dca/0x2360 fs/dlm/lockspace.c:693
device_create_lockspace+0xc8/0x350 fs/dlm/user.c:430
device_write+0x875/0xed0 fs/dlm/user.c:622
vfs_write+0x299/0x9a0 fs/read_write.c:582
ksys_write+0x151/0x260 fs/read_write.c:637
do_syscall_x64 arch/x86/entry/common.c:46 [inline]
do_syscall_64+0x55/0xb0 arch/x86/entry/common.c:76
entry_SYSCALL_64_after_hwframe+0x68/0xd2
RIP: 0033:0x7fca3699e019
RSP: 002b:00007fca37907028 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 00007fca36c25fa0 RCX: 00007fca3699e019
RDX: 0000000000000080 RSI: 0000200000000400 RDI: 0000000000000007
RBP: 00007fca36a3500c R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007fca36c26038 R14: 00007fca36c25fa0 R15: 00007ffee77df068
</TASK>

Showing all locks held in the system:
1 lock held by khungtaskd/29:
#0: ffffffff8d131da0 (rcu_read_lock){....}-{1:2}, at: rcu_lock_acquire include/linux/rcupdate.h:334 [inline]
#0: ffffffff8d131da0 (rcu_read_lock){....}-{1:2}, at: rcu_read_lock include/linux/rcupdate.h:786 [inline]
#0: ffffffff8d131da0 (rcu_read_lock){....}-{1:2}, at: debug_show_all_locks+0x55/0x290 kernel/locking/lockdep.c:6633
2 locks held by klogd/5126:
1 lock held by udevd/5137:
3 locks held by crond/5511:
2 locks held by getty/5527:
#0: ffff88802d1320a0 (&tty->ldisc_sem){++++}-{0:0}, at: tty_ldisc_ref_wait+0x25/0x70 drivers/tty/tty_ldisc.c:243
#1: ffffc9000327b2f0 (&ldata->atomic_read_lock){+.+.}-{3:3}, at: n_tty_read+0x428/0x1370 drivers/tty/n_tty.c:2217
8 locks held by kworker/1:5/5809:
#0: ffff888017c70938 ((wq_completion)events){+.+.}-{0:0}, at: process_one_work kernel/workqueue.c:2632 [inline]
#0: ffff888017c70938 ((wq_completion)events){+.+.}-{0:0}, at: process_scheduled_works+0x975/0x1600 kernel/workqueue.c:2734
#1: ffffc900047afd00 (console_work){+.+.}-{0:0}, at: process_one_work kernel/workqueue.c:2632 [inline]
#1: ffffc900047afd00 (console_work){+.+.}-{0:0}, at: process_scheduled_works+0x975/0x1600 kernel/workqueue.c:2734
#2: ffffffff8d126180 (console_lock){+.+.}-{0:0}, at: console_callback+0x6a/0x440 drivers/tty/vt/vt.c:2933
#3: ffff88802146c280 (&helper->lock){+.+.}-{3:3}, at: drm_fb_helper_pan_display+0xbe/0xbd0 drivers/gpu/drm/drm_fb_helper.c:1436
#4: ffff8880213381b0 (&dev->master_mutex){+.+.}-{3:3}, at: drm_master_internal_acquire+0x20/0x70 drivers/gpu/drm/drm_auth.c:458
#5: ffff88802146c098 (&client->modeset_mutex){+.+.}-{3:3}, at: drm_client_modeset_commit_locked+0x4c/0x4c0 drivers/gpu/drm/drm_client_modeset.c:1158
#6: ffffc900047af570 (crtc_ww_class_acquire){+.+.}-{0:0}, at: drm_client_modeset_commit_atomic+0x111/0x7b0 drivers/gpu/drm/drm_client_modeset.c:996
#7: ffff88802146b0b0 (crtc_ww_class_mutex){+.+.}-{3:3}, at: modeset_lock+0x2a6/0x620 drivers/gpu/drm/drm_modeset_lock.c:314
1 lock held by syz.0.47/6029:
#0: ffffffff973c9a68 (&ls_lock){+.+.}-{3:3}, at: __dlm_new_lockspace+0xb1/0x2360 fs/dlm/lockspace.c:687
1 lock held by dlm_recoverd/6036:
#0: ffff88807d1d0aa8 (&ls->ls_in_recovery){+.+.}-{3:3}, at: dlm_recoverd+0xa5/0x1e50 fs/dlm/recoverd.c:310
1 lock held by syz-executor/8528:
1 lock held by syz-executor/8530:
2 locks held by syz-executor/8533:
2 locks held by syz.0.292/8785:
1 lock held by cmp/8799:

=============================================

NMI backtrace for cpu 0
CPU: 0 PID: 29 Comm: khungtaskd Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
Call Trace:
<TASK>
dump_stack_lvl+0x18c/0x250 lib/dump_stack.c:106
nmi_cpu_backtrace+0x3a6/0x3e0 lib/nmi_backtrace.c:113
nmi_trigger_cpumask_backtrace+0x17a/0x2f0 lib/nmi_backtrace.c:62
trigger_all_cpu_backtrace include/linux/nmi.h:160 [inline]
check_hung_uninterruptible_tasks kernel/hung_task.c:222 [inline]
watchdog+0xf59/0xfa0 kernel/hung_task.c:379
kthread+0x2fa/0x390 kernel/kthread.c:388
ret_from_fork+0x48/0x80 arch/x86/kernel/process.c:152
ret_from_fork_asm+0x11/0x20 arch/x86/entry/entry_64.S:293
</TASK>
Sending NMI from CPU 0 to CPUs 1:
NMI backtrace for cpu 1
CPU: 1 PID: 8530 Comm: syz-executor Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
RIP: 0010:__lock_acquire+0xee8/0x7d80 kernel/locking/lockdep.c:5127
Code: c7 44 24 20 00 00 00 00 eb 06 b0 01 89 44 24 20 48 8b 44 24 58 42 0f b6 04 00 84 c0 0f 85 50 0d 00 00 48 8b 44 24 18 44 8b 20 <48> 83 7d 10 00 0f 84 9d 00 00 00 48 8b 44 24 78 42 0f b6 04 00 84
RSP: 0018:ffffc90002e46560 EFLAGS: 00000046
RAX: ffff888019726550 RBX: 000000000006047a RCX: ffffffff81689802
RDX: 0000000000000000 RSI: 0000000000000008 RDI: ffffffff911eb500
RBP: ffffc90002e467a8 R08: dffffc0000000000 R09: 1ffffffff223d6a0
R10: dffffc0000000000 R11: fffffbfff223d6a1 R12: 0000000000020018
R13: ffff888019725a00 R14: ffff8880197264d0 R15: ee0f6b98b878c8ac
FS: 0000555564ef0500(0000) GS:ffff8880b8f00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fc9c12d0286 CR3: 0000000026a9c000 CR4: 00000000003506e0
Call Trace:
<TASK>
lock_acquire+0x19e/0x420 kernel/locking/lockdep.c:5754
rcu_lock_acquire include/linux/rcupdate.h:334 [inline]
rcu_read_lock_sched include/linux/rcupdate.h:878 [inline]
pfn_valid include/linux/mmzone.h:2011 [inline]
__virt_addr_valid+0x128/0x380 arch/x86/mm/physaddr.c:65
kasan_addr_to_slab+0xd/0xd0 mm/kasan/common.c:36
__kasan_record_aux_stack+0xf/0xc0 mm/kasan/generic.c:477
__call_rcu_common kernel/rcu/tree.c:2721 [inline]
call_rcu+0x153/0x900 kernel/rcu/tree.c:2837
fib6_info_release include/net/ip6_fib.h:349 [inline]
fixup_permanent_addr net/ipv6/addrconf.c:3596 [inline]
addrconf_permanent_addr+0x3a4/0xa50 net/ipv6/addrconf.c:3624
addrconf_notify+0x996/0x1010 net/ipv6/addrconf.c:3696
notifier_call_chain+0x18f/0x380 kernel/notifier.c:93
call_netdevice_notifiers_extack net/core/dev.c:2077 [inline]
call_netdevice_notifiers net/core/dev.c:2091 [inline]
__dev_notify_flags+0x1ab/0x310 net/core/dev.c:8762
dev_change_flags+0xde/0x1a0 net/core/dev.c:8800
do_setlink+0xb69/0x3f40 net/core/rtnetlink.c:2917
__rtnl_newlink net/core/rtnetlink.c:3715 [inline]
rtnl_newlink+0x1848/0x2170 net/core/rtnetlink.c:3762
rtnetlink_rcv_msg+0x843/0xf90 net/core/rtnetlink.c:6484
netlink_rcv_skb+0x235/0x4c0 net/netlink/af_netlink.c:2550
netlink_unicast_kernel net/netlink/af_netlink.c:1320 [inline]
netlink_unicast+0x7b1/0x930 net/netlink/af_netlink.c:1346
netlink_sendmsg+0x8d0/0xbf0 net/netlink/af_netlink.c:1899
sock_sendmsg_nosec net/socket.c:730 [inline]
__sock_sendmsg net/socket.c:745 [inline]
__sys_sendto+0x4a9/0x6b0 net/socket.c:2201
__do_sys_sendto net/socket.c:2213 [inline]
__se_sys_sendto net/socket.c:2209 [inline]
__x64_sys_sendto+0xde/0xf0 net/socket.c:2209
do_syscall_x64 arch/x86/entry/common.c:46 [inline]
do_syscall_64+0x55/0xb0 arch/x86/entry/common.c:76
entry_SYSCALL_64_after_hwframe+0x68/0xd2
RIP: 0033:0x7f7092d5e84e
Code: 08 0f 85 a5 a8 ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 <c3> 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 80 00 00 00 00 48 83 ec 08
RSP: 002b:00007ffebde8e088 EFLAGS: 00000246 ORIG_RAX: 000000000000002c
RAX: ffffffffffffffda RBX: 0000555564ef0500 RCX: 00007f7092d5e84e
RDX: 000000000000002c RSI: 00007f7093b54670 RDI: 0000000000000003
RBP: 0000000000000001 R08: 00007ffebde8e104 R09: 000000000000000c
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000003
R13: 0000000000000000 R14: 00007f7093b54670 R15: 0000000000000000

syzbot

unread,
Aug 4, 2026, 8:48:39 PM (3 days ago) Aug 4
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 6e2fd6534337 Linux 5.15.213
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=12bf4bb9580000
kernel config: https://syzkaller.appspot.com/x/.config?x=f161cbc9aef65db0
dashboard link: https://syzkaller.appspot.com/bug?extid=9c4bfb8e6ad2202e4a98
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/d7b46606b13d/disk-6e2fd653.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/da120fdeb081/vmlinux-6e2fd653.xz
kernel image: https://storage.googleapis.com/syzbot-assets/3c2643457e3f/bzImage-6e2fd653.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+9c4bfb...@syzkaller.appspotmail.com

INFO: task syz.1.17:4351 blocked for more than 143 seconds.
Not tainted syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:syz.1.17 state:D stack:25872 pid: 4351 ppid: 4196 flags:0x00004004
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5049 [inline]
__schedule+0x11c3/0x4350 kernel/sched/core.c:6395
schedule+0x11b/0x1e0 kernel/sched/core.c:6478
do_uevent+0x1df/0x480 fs/dlm/lockspace.c:210
new_lockspace fs/dlm/lockspace.c:640 [inline]
dlm_new_lockspace+0x1ca0/0x21a0 fs/dlm/lockspace.c:698
device_create_lockspace+0xc4/0x350 fs/dlm/user.c:405
device_write+0x893/0xea0 fs/dlm/user.c:597
vfs_write+0x304/0xd70 fs/read_write.c:592
ksys_write+0x153/0x260 fs/read_write.c:647
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x4c/0xa0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x66/0xd0
RIP: 0033:0x7f3a94a04019
RSP: 002b:00007f3a92c5c028 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 00007f3a94c8bfa0 RCX: 00007f3a94a04019
RDX: 0000000000000078 RSI: 0000200000000400 RDI: 0000000000000007
RBP: 00007f3a94a9b00c R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f3a94c8c038 R14: 00007f3a94c8bfa0 R15: 00007fff55012ef8
</TASK>

Showing all locks held in the system:
1 lock held by khungtaskd/27:
#0: ffffffff8c31ef60 (rcu_read_lock){....}-{1:2}, at: rcu_lock_acquire+0x0/0x30
1 lock held by klogd/3548:
2 locks held by getty/3945:
#0: ffff88814d471098 (&tty->ldisc_sem){++++}-{0:0}, at: tty_ldisc_ref_wait+0x21/0x70 drivers/tty/tty_ldisc.c:252
#1: ffffc90002cf62e8 (&ldata->atomic_read_lock){+.+.}-{3:3}, at: n_tty_read+0x594/0x1a50 drivers/tty/n_tty.c:2158
1 lock held by syz.1.17/4351:
#0: ffffffff963c8aa8 (&ls_lock){+.+.}-{3:3}, at: dlm_new_lockspace+0xab/0x21a0 fs/dlm/lockspace.c:692
1 lock held by dlm_recoverd/4356:
#0: ffff8880705bccb8 (&ls->ls_in_recovery){+.+.}-{3:3}, at: dlm_recoverd+0xa9/0x19e0 fs/dlm/recoverd.c:286

=============================================

NMI backtrace for cpu 1
CPU: 1 PID: 27 Comm: khungtaskd Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
Call Trace:
<TASK>
dump_stack_lvl+0x188/0x250 lib/dump_stack.c:106
nmi_cpu_backtrace+0x3a2/0x3d0 lib/nmi_backtrace.c:111
nmi_trigger_cpumask_backtrace+0x163/0x280 lib/nmi_backtrace.c:62
trigger_all_cpu_backtrace include/linux/nmi.h:148 [inline]
check_hung_uninterruptible_tasks kernel/hung_task.c:212 [inline]
watchdog+0xe1b/0xe60 kernel/hung_task.c:369
kthread+0x42e/0x520 kernel/kthread.c:334
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:287
</TASK>
Sending NMI from CPU 1 to CPUs 0:
NMI backtrace for cpu 0
CPU: 0 PID: 3541 Comm: syslogd Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
RIP: 0010:rcu_dynticks_curr_cpu_in_eqs kernel/rcu/tree.c:331 [inline]
RIP: 0010:rcu_is_watching+0x36/0xa0 kernel/rcu/tree.c:1123
Code: e8 3f 84 5b 08 89 c3 83 f8 08 73 5c 49 bf 00 00 00 00 00 fc ff df 4c 8d 34 dd 20 d8 e3 8b 4c 89 f0 48 c1 e8 03 42 80 3c 38 00 <74> 08 4c 89 f7 e8 f0 7e 59 00 48 c7 c3 08 b3 03 00 49 03 1e 48 89
RSP: 0018:ffffc90002d2f6e0 EFLAGS: 00000046
RAX: 1ffffffff17c7b04 RBX: 0000000000000000 RCX: 731f21f451998d00
RDX: 0000000000000000 RSI: ffffffff8a7a41e0 RDI: ffffffff8a7a41a0
RBP: ffffc90002d2f810 R08: ffffffff8d8b0def R09: 1ffffffff1b161bd
R10: dffffc0000000000 R11: fffffbfff1b161be R12: 1ffff920005a5eec
R13: dffffc0000000000 R14: ffffffff8be3d820 R15: dffffc0000000000
FS: 00007f80652b1c80(0000) GS:ffff8880b9000000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00005582404fc168 CR3: 000000002aff1000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
trace_lock_release include/trace/events/lock.h:58 [inline]
lock_release+0xb5/0x8a0 kernel/locking/lockdep.c:5634
__raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:158 [inline]
_raw_spin_unlock_irqrestore+0x6d/0x120 kernel/locking/spinlock.c:194
spin_unlock_irqrestore include/linux/spinlock.h:419 [inline]
prepare_to_wait_exclusive+0xce/0x210 kernel/sched/wait.c:288
__skb_wait_for_more_packets+0x142/0x590 net/core/datagram.c:95
__unix_dgram_recvmsg+0x2a0/0xd50 net/unix/af_unix.c:2328
sock_recvmsg_nosec net/socket.c:969 [inline]
sock_recvmsg net/socket.c:987 [inline]
sock_read_iter+0x2c2/0x380 net/socket.c:1068
call_read_iter include/linux/fs.h:2167 [inline]
new_sync_read fs/read_write.c:404 [inline]
vfs_read+0x75e/0xd50 fs/read_write.c:485
ksys_read+0x153/0x260 fs/read_write.c:623
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x4c/0xa0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x66/0xd0
RIP: 0033:0x7f8065401407
Code: 48 89 fa 4c 89 df e8 38 aa 00 00 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 1a 5b c3 0f 1f 84 00 00 00 00 00 48 8b 44 24 10 0f 05 <5b> c3 0f 1f 80 00 00 00 00 83 e2 39 83 fa 08 75 de e8 23 ff ff ff
RSP: 002b:00007ffde8306720 EFLAGS: 00000202 ORIG_RAX: 0000000000000000
RAX: ffffffffffffffda RBX: 00007f80652b1c80 RCX: 00007f8065401407
RDX: 00000000000000ff RSI: 0000555796164950 RDI: 0000000000000000
RBP: 0000555796164910 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000202 R12: 000055579616499d
R13: 0000000000000000 R14: 0000555796164950 R15: 000055576ca3bd98
Reply all
Reply to author
Forward
0 new messages