Hello,
syzbot found the following issue on:
HEAD commit: bd5f485f3f02 Merge tag 'soc-arm-7.3' of git://git.kernel.o..
git tree: upstream
console output:
https://syzkaller.appspot.com/x/log.txt?x=11617679580000
kernel config:
https://syzkaller.appspot.com/x/.config?x=885647b8fd38e8cc
dashboard link:
https://syzkaller.appspot.com/bug?extid=ae0bbb13f9677c2227da
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
CC: [
linux-...@vger.kernel.org linux-tra...@vger.kernel.org mathieu....@efficios.com mhir...@kernel.org ros...@goodmis.org]
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/8d8487052771/disk-bd5f485f.raw.xz
vmlinux:
https://storage.googleapis.com/syzbot-assets/73cdf4daa507/vmlinux-bd5f485f.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/bac756d0971e/bzImage-bd5f485f.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+ae0bbb...@syzkaller.appspotmail.com
==================================================================
BUG: KCSAN: data-race in rb_get_reader_page / ring_buffer_unlock_commit
write to 0xffff888100078860 of 8 bytes by task 24816 on cpu 0:
__rb_get_reader_page kernel/trace/ring_buffer.c:5925 [inline]
rb_get_reader_page+0xa7d/0xdb0 kernel/trace/ring_buffer.c:5984
rb_buffer_peek+0x44/0x870 kernel/trace/ring_buffer.c:6065
ring_buffer_peek+0xb2/0x210 kernel/trace/ring_buffer.c:6268
peek_next_entry kernel/trace/trace.c:2354 [inline]
__find_next_entry+0x229/0x420 kernel/trace/trace.c:2398
trace_find_next_entry_inc kernel/trace/trace.c:2672 [inline]
tracing_read_pipe+0x2f7/0x790 kernel/trace/trace.c:5440
vfs_read+0x18e/0x7c0 fs/read_write.c:572
ksys_read+0xdc/0x1a0 fs/read_write.c:716
__do_sys_read fs/read_write.c:725 [inline]
__se_sys_read fs/read_write.c:723 [inline]
__x64_sys_read+0x40/0x50 fs/read_write.c:723
x64_sys_call+0x2135/0x2550 arch/x86/include/generated/asm/syscalls_64.h:1
do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline]
do_syscall_64+0x112/0x360 arch/x86/entry/syscall_64.c:84
entry_SYSCALL_64_after_hwframe+0x77/0x7f
read to 0xffff888100078860 of 8 bytes by task 6537 on cpu 1:
rb_wakeups kernel/trace/ring_buffer.c:4312 [inline]
ring_buffer_unlock_commit+0x17b/0x450 kernel/trace/ring_buffer.c:4498
__buffer_unlock_commit kernel/trace/trace.h:1697 [inline]
trace_buffer_unlock_commit_regs+0x43/0x310 kernel/trace/trace.c:2049
trace_event_buffer_commit+0x149/0x590 kernel/trace/trace.c:2024
do_trace_event_raw_event_sys_exit include/trace/events/syscalls.h:44 [inline]
trace_event_raw_event_sys_exit+0x9f/0xf0 include/trace/events/syscalls.h:44
__do_trace_sys_exit include/trace/events/syscalls.h:44 [inline]
trace_sys_exit include/trace/events/syscalls.h:44 [inline]
trace_syscall_exit+0xba/0x110 kernel/entry/syscall-common.c:18
syscall_exit_work include/linux/entry-common.h:262 [inline]
syscall_exit_to_user_mode_work include/linux/entry-common.h:297 [inline]
syscall_exit_to_user_mode include/linux/entry-common.h:334 [inline]
do_syscall_64+0x31c/0x360 arch/x86/entry/syscall_64.c:89
entry_SYSCALL_64_after_hwframe+0x77/0x7f
value changed: 0xffff88810019e440 -> 0xffff88812e644e00
Reported by Kernel Concurrency Sanitizer on:
CPU: 1 UID: 0 PID: 6537 Comm: udevd Tainted: G W syzkaller #0 PREEMPT(lazy)
Tainted: [W]=WARN
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
==================================================================
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup