Hello,
syzbot found the following issue on:
HEAD commit: 1989cd3d56e2 Linux 6.1.167
git tree: linux-6.1.y
console output:
https://syzkaller.appspot.com/x/log.txt?x=149706ba580000
kernel config:
https://syzkaller.appspot.com/x/.config?x=f0605c5af04d7603
dashboard link:
https://syzkaller.appspot.com/bug?extid=e89919ea82f5079dd743
compiler: Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/3e0cf5574b81/disk-1989cd3d.raw.xz
vmlinux:
https://storage.googleapis.com/syzbot-assets/0c1152de55b1/vmlinux-1989cd3d.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/3fe87e3166b1/bzImage-1989cd3d.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+e89919...@syzkaller.appspotmail.com
rcu: INFO: rcu_preempt detected expedited stalls on CPUs/tasks: { 1-.... } 3686 jiffies s: 1173 root: 0x2/.
rcu: blocking rcu_node structures (internal RCU debug):
Sending NMI from CPU 0 to CPUs 1:
NMI backtrace for cpu 1
CPU: 1 PID: 4444 Comm: syz.3.23 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/18/2026
RIP: 0010:strlen+0x1b/0x60 lib/string.c:502
Code: e4 4c 89 f7 e8 f6 1b b5 f7 eb da 0f 1f 40 00 41 57 41 56 41 54 53 48 c7 c0 ff ff ff ff 49 be 00 00 00 00 00 fc ff df 48 89 fb <49> 89 c7 48 89 d8 48 c1 e8 03 42 0f b6 04 30 84 c0 75 11 48 ff c3
RSP: 0018:ffffc900001df9b8 EFLAGS: 00000006
RAX: 000000000000000b RBX: ffffffff8a8e062c RCX: dffffc0000000000
RDX: ffffffff81730bc5 RSI: ffffffff8cb46bc8 RDI: ffffffff8a8e0620
RBP: ffffc900001dfad0 R08: ffffffff8e1fdeef R09: 1ffffffff1c3fbdd
R10: dffffc0000000000 R11: fffffbfff1c3fbde R12: dffffc0000000000
R13: 1ffff9200003bf44 R14: dffffc0000000000 R15: 000000000000000a
FS: 00007f8fd56af6c0(0000) GS:ffff8880b8f00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f1da35eb4b8 CR3: 0000000058d4b000 CR4: 00000000003506e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<IRQ>
__fortify_strlen include/linux/fortify-string.h:196 [inline]
trace_event_get_offsets_lock include/trace/events/lock.h:50 [inline]
perf_trace_lock+0xd1/0x390 include/trace/events/lock.h:50
trace_lock_release include/trace/events/lock.h:69 [inline]
lock_release+0x8ad/0x920 kernel/locking/lockdep.c:5673
seqcount_lockdep_reader_access+0xe0/0x1d0 include/linux/seqlock.h:103
timekeeping_get_delta kernel/time/timekeeping.c:254 [inline]
timekeeping_get_ns kernel/time/timekeeping.c:388 [inline]
ktime_get_update_offsets_now+0x95/0x3e0 kernel/time/timekeeping.c:2320
hrtimer_update_base kernel/time/hrtimer.c:659 [inline]
hrtimer_interrupt+0x130/0x9c0 kernel/time/hrtimer.c:1855
local_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1107 [inline]
__sysvec_apic_timer_interrupt+0x153/0x5a0 arch/x86/kernel/apic/apic.c:1124
instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1118 [inline]
sysvec_apic_timer_interrupt+0x4d/0xc0 arch/x86/kernel/apic/apic.c:1118
asm_sysvec_apic_timer_interrupt+0x16/0x20 arch/x86/include/asm/idtentry.h:691
RIP: 0010:ip6_ignore_linkdown include/net/addrconf.h:419 [inline]
RIP: 0010:find_match+0x131/0xc80 net/ipv6/route.c:784
Code: 15 f7 8f f8 49 bc 00 00 00 00 00 fc ff df 48 85 db 0f 84 00 0a 00 00 48 81 c3 44 06 00 00 48 89 d8 48 c1 e8 03 42 0f b6 04 20 <84> c0 0f 85 2d 0a 00 00 8b 1b 31 ff 89 de e8 3c fa 8f f8 85 db 74
RSP: 0018:ffffc900001dff40 EFLAGS: 00000a03
RAX: 0000000000000000 RBX: ffff888056753644 RCX: ffff8880248d1dc0
RDX: 0000000000000100 RSI: 0000000000000001 RDI: 0000000000000000
RBP: 1ffff1100ac2ab15 R08: ffffc900001e0240 R09: ffffc900001e0250
R10: dffffc0000000000 R11: fffff5200003c016 R12: dffffc0000000000
R13: 0000000000000003 R14: 1ffff1100ac2ab17 R15: ffff8880561558bf
__find_rr_leaf+0x245/0x760 net/ipv6/route.c:872
find_rr_leaf net/ipv6/route.c:893 [inline]
rt6_select net/ipv6/route.c:937 [inline]
fib6_table_lookup+0x3b1/0xa80 net/ipv6/route.c:2224
ip6_pol_route+0x244/0x12a0 net/ipv6/route.c:2260
pol_lookup_func include/net/ip6_fib.h:579 [inline]
fib6_rule_lookup+0x208/0x5d0 net/ipv6/fib6_rules.c:116
ip6_route_input_lookup net/ipv6/route.c:2329 [inline]
ip6_route_input+0x725/0xa40 net/ipv6/route.c:2625
ip6_list_rcv_finish net/ipv6/ip6_input.c:131 [inline]
ip6_sublist_rcv+0x66a/0x1170 net/ipv6/ip6_input.c:320
ipv6_list_rcv+0x3f1/0x440 net/ipv6/ip6_input.c:355
__netif_receive_skb_list_ptype net/core/dev.c:5650 [inline]
__netif_receive_skb_list_core+0x57f/0x750 net/core/dev.c:5698
__netif_receive_skb_list net/core/dev.c:5750 [inline]
netif_receive_skb_list_internal+0x93f/0xca0 net/core/dev.c:5841
netif_receive_skb_list+0x51/0x4e0 net/core/dev.c:5893
ieee80211_rx_napi+0x357/0x3d0 net/mac80211/rx.c:5342
ieee80211_rx include/net/mac80211.h:4849 [inline]
ieee80211_handle_queued_frames+0x105/0x1b0 net/mac80211/main.c:317
tasklet_action_common+0x2fe/0x4d0 kernel/softirq.c:827
handle_softirqs+0x2a1/0x930 kernel/softirq.c:596
__do_softirq kernel/softirq.c:630 [inline]
invoke_softirq kernel/softirq.c:470 [inline]
__irq_exit_rcu+0x13b/0x230 kernel/softirq.c:679
irq_exit_rcu+0x5/0x20 kernel/softirq.c:691
instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1118 [inline]
sysvec_apic_timer_interrupt+0xa0/0xc0 arch/x86/kernel/apic/apic.c:1118
</IRQ>
<TASK>
asm_sysvec_apic_timer_interrupt+0x16/0x20 arch/x86/include/asm/idtentry.h:691
RIP: 0010:info_print_prefix+0x18b/0x360 kernel/printk/printk.c:1302
Code: 8c 8a e8 48 2c b7 08 48 98 48 01 c3 4c 8d 6c 24 40 49 83 c6 14 4c 89 f0 48 c1 e8 03 48 ba 00 00 00 00 00 fc ff df 0f b6 04 10 <84> c0 0f 85 00 01 00 00 45 8b 26 4c 8b 7c 24 10 4d 8d 34 1f 48 89
RSP: 0018:ffffc90004abe7c0 EFLAGS: 00000a07
RAX: 0000000000000000 RBX: 000000000000000e RCX: 21161fde57146300
RDX: dffffc0000000000 RSI: 000000000000cdd8 RDI: 000000000000cdd9
RBP: ffffc90004abe870 R08: ffffc90004abe90d R09: 1ffff92000957d21
R10: dffffc0000000000 R11: fffff52000957d22 R12: 0000000000000000
R13: ffffc90004abe800 R14: ffffc90004abead4 R15: ffffc90004abeac8
record_print_text+0x173/0x440 kernel/printk/printk.c:1349
console_emit_next_record+0x598/0xba0 kernel/printk/printk.c:2760
console_flush_all kernel/printk/printk.c:-1 [inline]
console_unlock+0x223/0x630 kernel/printk/printk.c:2906
vprintk_emit+0x4b3/0x6a0 kernel/printk/printk.c:2303
_printk+0xda/0x130 kernel/printk/printk.c:2328
__nla_validate_parse+0x213f/0x2a40 lib/nlattr.c:619
__nla_parse+0x3c/0x50 lib/nlattr.c:704
__nlmsg_parse include/net/netlink.h:748 [inline]
nlmsg_parse_deprecated include/net/netlink.h:789 [inline]
__rtnl_newlink net/core/rtnetlink.c:3487 [inline]
rtnl_newlink+0x32a/0x2080 net/core/rtnetlink.c:3655
rtnetlink_rcv_msg+0x87c/0xfc0 net/core/rtnetlink.c:6150
netlink_rcv_skb+0x1fb/0x450 net/netlink/af_netlink.c:2511
netlink_unicast_kernel net/netlink/af_netlink.c:1318 [inline]
netlink_unicast+0x74d/0x8d0 net/netlink/af_netlink.c:1344
netlink_sendmsg+0x8ad/0xbd0 net/netlink/af_netlink.c:1872
sock_sendmsg_nosec net/socket.c:718 [inline]
__sock_sendmsg net/socket.c:730 [inline]
____sys_sendmsg+0x5be/0x970 net/socket.c:2518
___sys_sendmsg+0x2a2/0x360 net/socket.c:2572
__sys_sendmsg net/socket.c:2601 [inline]
__do_sys_sendmsg net/socket.c:2610 [inline]
__se_sys_sendmsg+0x1bb/0x2a0 net/socket.c:2608
do_syscall_x64 arch/x86/entry/common.c:46 [inline]
do_syscall_64+0x4c/0xa0 arch/x86/entry/common.c:76
entry_SYSCALL_64_after_hwframe+0x68/0xd2
RIP: 0033:0x7f8fd479c819
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f8fd56af028 EFLAGS: 00000246 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007f8fd4a15fa0 RCX: 00007f8fd479c819
RDX: 0000000000000000 RSI: 0000200000000940 RDI: 0000000000000005
RBP: 00007f8fd4832c91 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f8fd4a16038 R14: 00007f8fd4a15fa0 R15: 00007ffe9bad2928
</TASK>
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup