Hello,
syzbot found the following issue on:
HEAD commit: 7235a3e71949 Merge branch 'for-next/core' into for-kernelci
git tree: git://
git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git for-kernelci
console output:
https://syzkaller.appspot.com/x/log.txt?x=161d0132580000
kernel config:
https://syzkaller.appspot.com/x/.config?x=ccf4bea59f67007
dashboard link:
https://syzkaller.appspot.com/bug?extid=e147b03c8b9be07d744c
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
userspace arch: arm64
CC: [
jst...@google.com linux-...@vger.kernel.org sb...@kernel.org tg...@kernel.org]
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/fd45635beaae/disk-7235a3e7.raw.xz
vmlinux:
https://storage.googleapis.com/syzbot-assets/d7d2e6507223/vmlinux-7235a3e7.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/b5b5d8de4cea/Image-7235a3e7.gz.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+e147b0...@syzkaller.appspotmail.com
watchdog: BUG: soft lockup - CPU#0 stuck for 22s! [syz.4.1491:10102]
Modules linked in:
irq event stamp: 33885853
hardirqs last enabled at (33885852): [<ffff800080559824>] seqcount_lockdep_reader_access+0x7c/0xf8 include/linux/seqlock.h:75
hardirqs last disabled at (33885853): [<ffff8000868e627c>] __el1_irq arch/arm64/kernel/entry-common.c:506 [inline]
hardirqs last disabled at (33885853): [<ffff8000868e627c>] el1_interrupt+0x28/0x60 arch/arm64/kernel/entry-common.c:522
softirqs last enabled at (49606): [<ffff800084c14ca8>] __alloc_skb+0x1c0/0x610 net/core/skbuff.c:698
softirqs last disabled at (49607): [<ffff8000800204c0>] __do_softirq+0x14/0x20 kernel/softirq.c:656
CPU: 0 UID: 0 PID: 10102 Comm: syz.4.1491 Tainted: G L syzkaller #0 PREEMPT
Tainted: [L]=SOFTLOCKUP
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/02/2026
pstate: 43400005 (nZcv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)
pc : seqcount_lockdep_reader_access+0xd8/0xf8 include/linux/seqlock.h:76
lr : seqcount_lockdep_reader_access+0xd4/0xf8 include/linux/seqlock.h:75
sp : ffff80008eb27ce0
x29: ffff80008eb27ce0 x28: 1fffe00035bc5c3a x27: ffff80008e80e110
x26: dfff800000000000 x25: ffff0000cdab8f80 x24: 1fffe0001bac7226
x23: dfff800000000000 x22: ffff0000cdab8fb0 x21: 0000000000000000
x20: ffff800080559c88 x19: 00000000000000c0 x18: 00000000ffffffff
x17: ffff80008a791000 x16: 0000000000000005 x15: ffff80008a31ada0
x14: 000000008030f608 x13: 0000000000000001 x12: ffff0000c7011d40
x11: ffff80008a590e28 x10: 0000000000000003 x9 : 0000000000000102
x8 : 0000000000000000 x7 : 0000000000000000 x6 : 0000000000000000
x5 : 0000000000000001 x4 : 0000000000000008 x3 : ffff800080559874
x2 : 0000000000000080 x1 : ffff0000c7011d40 x0 : 0000000000000000
Call trace:
__daif_local_irq_restore arch/arm64/include/asm/irqflags.h:175 [inline] (P)
arch_local_irq_restore arch/arm64/include/asm/irqflags.h:195 [inline] (P)
seqcount_lockdep_reader_access+0xd8/0xf8 include/linux/seqlock.h:75 (P)
ktime_get+0x68/0x218 kernel/time/timekeeping.c:971
gate_get_time+0x1c/0xa4 net/sched/act_gate.c:23
gate_timer_func+0x1a8/0x390 net/sched/act_gate.c:101
__run_hrtimer kernel/time/hrtimer.c:2032 [inline]
__hrtimer_run_queues+0x314/0xbe0 kernel/time/hrtimer.c:2096
hrtimer_run_softirq+0x15c/0x21c kernel/time/hrtimer.c:2113
handle_softirqs+0x2ec/0xd98 kernel/softirq.c:622
__do_softirq+0x14/0x20 kernel/softirq.c:656
____do_softirq+0x14/0x20 arch/arm64/kernel/irq.c:78
call_on_irq_stack+0x30/0x48 arch/arm64/kernel/entry.S:889
do_softirq_own_stack+0x20/0x2c arch/arm64/kernel/irq.c:83
do_softirq+0x90/0xf8 kernel/softirq.c:523
__local_bh_enable_ip+0x240/0x35c kernel/softirq.c:450
local_bh_enable include/linux/bottom_half.h:33 [inline]
__alloc_skb+0x1c8/0x610 net/core/skbuff.c:699
alloc_skb include/linux/skbuff.h:1384 [inline]
alloc_skb_with_frags+0xb8/0x690 net/core/skbuff.c:6769
sock_alloc_send_pskb+0x740/0x850 net/core/sock.c:3013
unix_dgram_sendmsg+0x434/0x1078 net/unix/af_unix.c:2136
sock_sendmsg_nosec net/socket.c:775 [inline]
__sock_sendmsg+0xc8/0x17c net/socket.c:790
____sys_sendmsg+0x3f8/0x6c8 net/socket.c:2684
___sys_sendmsg+0x198/0x224 net/socket.c:2738
__sys_sendmmsg+0x204/0x580 net/socket.c:2827
__do_sys_sendmmsg net/socket.c:2854 [inline]
__se_sys_sendmmsg net/socket.c:2851 [inline]
__arm64_sys_sendmmsg+0xac/0xc8 net/socket.c:2851
__invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]
invoke_syscall+0x98/0x244 arch/arm64/kernel/syscall.c:49
el0_svc_common+0xec/0x23c arch/arm64/kernel/syscall.c:121
do_el0_svc+0x4c/0x5c arch/arm64/kernel/syscall.c:140
el0_svc+0x64/0x260 arch/arm64/kernel/entry-common.c:736
el0t_64_sync_handler+0x48/0x148 arch/arm64/kernel/entry-common.c:755
el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:594
Sending NMI from CPU 0 to CPUs 1:
NMI backtrace for cpu 1
CPU: 1 UID: 0 PID: 4696 Comm: syz-executor Tainted: G L syzkaller #0 PREEMPT
Tainted: [L]=SOFTLOCKUP
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/02/2026
pstate: 83400005 (Nzcv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)
pc : __daif_local_irq_enable arch/arm64/include/asm/irqflags.h:-1 [inline]
pc : arch_local_irq_enable arch/arm64/include/asm/irqflags.h:48 [inline]
pc : handle_softirqs+0x1cc/0xd98 kernel/softirq.c:606
lr : handle_softirqs+0x1c8/0xd98 kernel/softirq.c:606
sp : ffff80008eb37ef0
x29: ffff80008eb37f80 x28: ffff0000d2fa3a88 x27: ffff0000d2fa3a90
x26: dfff800000000000 x25: 0000000000000008 x24: dfff800000000000
x23: ffff0001ade63640 x22: ffff0000d2fa3a80 x21: 000000000000000a
x20: ffff800088ac5640 x19: ffff0001ade63640 x18: 1fffe00035bc9e28
x17: ffff80012539e000 x16: ffff80008eb30000 x15: 0000000000000000
x14: 00000000ffff8000 x13: 0000000000000001 x12: 0000000000000000
x11: ffff800080157100 x10: 0000000000000003 x9 : 0000000000000000
x8 : 0000000000164b8c x7 : 0000000000000000 x6 : 0000000000000000
x5 : 0000000000000001 x4 : 0000000000000008 x3 : ffff8000801571a8
x2 : 0000000000000000 x1 : ffff0000d2fa3a80 x0 : ffff80012539e000
Call trace:
__daif_local_irq_enable arch/arm64/include/asm/irqflags.h:26 [inline] (P)
arch_local_irq_enable arch/arm64/include/asm/irqflags.h:48 [inline] (P)
handle_softirqs+0x1cc/0xd98 kernel/softirq.c:606 (P)
__do_softirq+0x14/0x20 kernel/softirq.c:656
____do_softirq+0x14/0x20 arch/arm64/kernel/irq.c:78
call_on_irq_stack+0x30/0x48 arch/arm64/kernel/entry.S:889
do_softirq_own_stack+0x20/0x2c arch/arm64/kernel/irq.c:83
invoke_softirq kernel/softirq.c:503 [inline]
__irq_exit_rcu+0x1ac/0x428 kernel/softirq.c:735
irq_exit_rcu+0x14/0x84 kernel/softirq.c:752
__el1_irq arch/arm64/kernel/entry-common.c:510 [inline]
el1_interrupt+0x40/0x60 arch/arm64/kernel/entry-common.c:522
el1h_64_irq_handler+0x18/0x24 arch/arm64/kernel/entry-common.c:527
el1h_64_irq+0x6c/0x70 arch/arm64/kernel/entry.S:590
__daif_local_irq_enable arch/arm64/include/asm/irqflags.h:26 [inline] (P)
arch_local_irq_enable arch/arm64/include/asm/irqflags.h:48 [inline] (P)
__raw_write_unlock_irq include/linux/rwlock_api_smp.h:301 [inline] (P)
_raw_write_unlock_irq+0x34/0x80 kernel/locking/spinlock.c:362 (P)
exit_notify kernel/exit.c:806 [inline]
do_exit+0x1044/0x1a74 kernel/exit.c:1021
do_group_exit+0x198/0x238 kernel/exit.c:1152
__do_sys_exit_group kernel/exit.c:1163 [inline]
__se_sys_exit_group kernel/exit.c:1161 [inline]
pid_child_should_wake+0x0/0x104 kernel/exit.c:1161
__invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]
invoke_syscall+0x98/0x244 arch/arm64/kernel/syscall.c:49
el0_svc_common+0xec/0x23c arch/arm64/kernel/syscall.c:121
do_el0_svc+0x4c/0x5c arch/arm64/kernel/syscall.c:140
el0_svc+0x64/0x260 arch/arm64/kernel/entry-common.c:736
el0t_64_sync_handler+0x48/0x148 arch/arm64/kernel/entry-common.c:755
el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:594
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup