[v6.1] WARNING in blk_mq_release

0 views
Skip to first unread message

syzbot

unread,
Aug 4, 2026, 3:49:49 PM (2 days ago) Aug 4
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: fb28aa725e05 Linux 6.1.180
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=14ee4bb9580000
kernel config: https://syzkaller.appspot.com/x/.config?x=872c04466179833f
dashboard link: https://syzkaller.appspot.com/bug?extid=d0cf39154a61fbf95a18
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
userspace arch: arm64

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/d420eb944682/disk-fb28aa72.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/affae450ab23/vmlinux-fb28aa72.xz
kernel image: https://storage.googleapis.com/syzbot-assets/b9e6919ed519/Image-fb28aa72.gz.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+d0cf39...@syzkaller.appspotmail.com

nvme nvme6: NVME-FC{0}: reset: Reconnect attempt failed (-6)
nvme nvme6: NVME-FC{0}: Max reconnect attempts (5) reached.
nvme nvme6: Removing ctrl: NQN "nqn.2014-08.org.nvmexpress.discovery"
------------[ cut here ]------------
WARNING: CPU: 0 PID: 1705 at block/blk-mq.c:4133 blk_mq_release+0xf0/0x27c block/blk-mq.c:4133
Modules linked in:
CPU: 0 PID: 1705 Comm: kworker/u4:5 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/02/2026
Workqueue: nvme-delete-wq nvme_delete_ctrl_work
pstate: 82400005 (Nzcv daif +PAN -UAO +TCO -DIT -SSBS BTYPE=--)
pc : blk_mq_release+0xf0/0x27c block/blk-mq.c:4133
lr : blk_mq_release+0xf0/0x27c block/blk-mq.c:4133
sp : ffff800026007840
x29: ffff8000260078b0 x28: 0000000000000000 x27: 1ffff00002b73fc4
x26: 1fffe00019f03e99 x25: 1fffe00019f03ea0 x24: 0000000000000001
x23: dfff800000000000 x22: ffff700004c00f08 x21: ffff800026007840
x20: ffff0000dc5a1aa8 x19: ffff0000cf81f3c8 x18: 1fffe00033e7277e
x17: ffff80000bfdc9bc x16: ffff800011b90080 x15: 0000000000000000
x14: 0000000000000406 x13: 0000000000ff0100 x12: ffff800017d39100
x11: ff0080000a7ce740 x10: 0000000000000000 x9 : ffff80000a7ce740
x8 : ffff0000d0180000 x7 : ffff800011aa7e88 x6 : 0000000000000000
x5 : 0000000000000000 x4 : 0000000000000000 x3 : 0000000000000002
x2 : 0000000000000008 x1 : ffff800011ceedc0 x0 : ffff0000dc5a1800
Call trace:
blk_mq_release+0xf0/0x27c block/blk-mq.c:4133
blk_release_queue+0x108/0x1b0 block/blk-sysfs.c:774
kobject_cleanup lib/kobject.c:681 [inline]
kobject_release lib/kobject.c:712 [inline]
kref_put include/linux/kref.h:65 [inline]
kobject_put+0x2a8/0x41c lib/kobject.c:729
blk_put_queue+0x20/0x30 block/blk-core.c:269
nvme_free_ctrl+0xc4/0x46c drivers/nvme/host/core.c:5196
device_release+0x94/0x1b4 drivers/base/core.c:-1
kobject_cleanup lib/kobject.c:681 [inline]
kobject_release lib/kobject.c:712 [inline]
kref_put include/linux/kref.h:65 [inline]
kobject_put+0x2a8/0x41c lib/kobject.c:729
put_device+0x28/0x40 drivers/base/core.c:3820
nvme_put_ctrl drivers/nvme/host/nvme.h:718 [inline]
nvme_uninit_ctrl drivers/nvme/host/core.c:5172 [inline]
nvme_do_delete_ctrl+0x1d8/0x1f4 drivers/nvme/host/core.c:219
nvme_delete_ctrl_work+0x20/0x30 drivers/nvme/host/core.c:227
process_one_work+0x7e4/0x13bc kernel/workqueue.c:2292
worker_thread+0x8cc/0xfe8 kernel/workqueue.c:2439
kthread+0x254/0x2e0 kernel/kthread.c:376
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:850
irq event stamp: 2590858
hardirqs last enabled at (2590857): [<ffff8000088f5614>] kasan_quarantine_put+0xc4/0x200 mm/kasan/quarantine.c:242
hardirqs last disabled at (2590858): [<ffff800011b8c2bc>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:405
softirqs last enabled at (2589706): [<ffff80000d69ac78>] spin_unlock_bh include/linux/spinlock.h:396 [inline]
softirqs last enabled at (2589706): [<ffff80000d69ac78>] nsim_dev_trap_report drivers/net/netdevsim/dev.c:820 [inline]
softirqs last enabled at (2589706): [<ffff80000d69ac78>] nsim_dev_trap_report_work+0x610/0x94c drivers/net/netdevsim/dev.c:851
softirqs last disabled at (2589704): [<ffff80000d69abf8>] spin_lock_bh include/linux/spinlock.h:356 [inline]
softirqs last disabled at (2589704): [<ffff80000d69abf8>] nsim_dev_trap_report drivers/net/netdevsim/dev.c:816 [inline]
softirqs last disabled at (2589704): [<ffff80000d69abf8>] nsim_dev_trap_report_work+0x590/0x94c drivers/net/netdevsim/dev.c:851
---[ end trace 0000000000000000 ]---
nvme nvme11: NVME-FC{3}: create association : host wwpn 0x2222222222222222 rport wwpn 0x4444444444444444: NQN "nqn.2014-08.org.nvmexpress.discovery"
(NULL device *): queue 0 connect admin queue failed (-6).
nvme nvme11: NVME-FC{3}: reset: Reconnect attempt failed (-6)
nvme nvme11: NVME-FC{3}: Reconnect attempt in 2 seconds
nvme nvme10: NVME-FC{2}: create association : host wwpn 0x2222222222222222 rport wwpn 0x4444444444444444: NQN "nqn.2014-08.org.nvmexpress.discovery"
(NULL device *): queue 0 connect admin queue failed (-6).
nvme nvme10: NVME-FC{2}: reset: Reconnect attempt failed (-6)
nvme nvme10: NVME-FC{2}: Reconnect attempt in 2 seconds


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages