* [syzbot] [mm?] INFO: rcu detected stall in __mmap_complete @ 2026-01-04 22:55 syzbot 2026-08-29 20:56 ` syzbot 0 siblings, 1 reply; 4+ messages in thread From: syzbot @ 2026-01-04 22:55 UTC (permalink / raw) To: Liam.Howlett, akpm, jannh, linux-kernel, linux-mm, lorenzo.stoakes, pfalcato, syzkaller-bugs, vbabka Hello, syzbot found the following issue on: HEAD commit: c8ebd433459b Merge tag 'nfsd-6.19-2' of git://git.kernel.o.. git tree: upstream console output: https://syzkaller.appspot.com/x/log.txt?x=1205b222580000 kernel config: https://syzkaller.appspot.com/x/.config?x=a94030c847137a18 dashboard link: https://syzkaller.appspot.com/bug?extid=e4aa91d7f20c34417d4e compiler: Debian clang version 20.1.8 (++20250708063551+0c9f909b7976-1~exp1~20250708183702.136), Debian LLD 20.1.8 syz repro: https://syzkaller.appspot.com/x/repro.syz?x=11e5cafc580000 Downloadable assets: disk image: https://storage.googleapis.com/syzbot-assets/499025e81349/disk-c8ebd433.raw.xz vmlinux: https://storage.googleapis.com/syzbot-assets/9eacf2e4acfd/vmlinux-c8ebd433.xz kernel image: https://storage.googleapis.com/syzbot-assets/4650397775c2/bzImage-c8ebd433.xz IMPORTANT: if you fix the issue, please add the following tag to the commit: Reported-by: syzbot+e4aa91d7f20c34417d4e@syzkaller.appspotmail.com rcu: INFO: rcu_preempt detected stalls on CPUs/tasks: rcu: 0-...!: (3 ticks this GP) idle=233c/1/0x4000000000000000 softirq=15929/15929 fqs=0 rcu: (detected by 1, t=10502 jiffies, g=10825, q=798 ncpus=2) Sending NMI from CPU 1 to CPUs 0: NMI backtrace for cpu 0 CPU: 0 UID: 0 PID: 6083 Comm: rm Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/25/2025 RIP: 0010:__raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline] RIP: 0010:_raw_spin_lock_irqsave+0x40/0x60 kernel/locking/spinlock.c:162 Code: a6 9a 6c f6 bf 01 00 00 00 e8 5c 85 34 f6 49 8d 7e 18 31 f6 31 d2 31 c9 41 b8 01 00 00 00 45 31 c9 ff 74 24 10 e8 c0 c7 41 f6 <48> 83 c4 08 4c 89 f7 e8 44 68 42 f6 48 89 d8 5b 41 5e e9 89 49 00 RSP: 0018:ffffc90000007ca0 EFLAGS: 00000082 RAX: f6300cf39c3c4f00 RBX: 0000000000000092 RCX: 0000000000010002 RDX: 0000000016fc2300 RSI: ffffffff8d975f94 RDI: ffffffff8bc083e0 RBP: ffffc90000007e90 R08: ffffffff8497cbfd R09: ffffffff99b67028 R10: ffff888035774300 R11: ffffed1006aee863 R12: ffff888035774300 R13: ffffffff99b67008 R14: ffffffff99b67010 R15: ffff888035774300 FS: 0000000000000000(0000) GS:ffff888125e1f000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f1fb067feb8 CR3: 0000000072afc000 CR4: 00000000003526f0 Call Trace: <IRQ> debug_object_deactivate+0x6d/0x360 lib/debugobjects.c:873 debug_hrtimer_deactivate kernel/time/hrtimer.c:443 [inline] debug_deactivate+0x1d/0x1e0 kernel/time/hrtimer.c:483 __run_hrtimer kernel/time/hrtimer.c:1745 [inline] __hrtimer_run_queues+0x2b0/0xc30 kernel/time/hrtimer.c:1841 hrtimer_interrupt+0x45b/0xaa0 kernel/time/hrtimer.c:1903 local_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1045 [inline] __sysvec_apic_timer_interrupt+0x102/0x3e0 arch/x86/kernel/apic/apic.c:1062 instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1056 [inline] sysvec_apic_timer_interrupt+0xa1/0xc0 arch/x86/kernel/apic/apic.c:1056 </IRQ> <TASK> asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:697 RIP: 0010:deref_stack_reg+0x1a7/0x230 arch/x86/kernel/unwind_orc.c:422 Code: 46 49 8d 40 08 48 39 d8 0f 97 c1 4c 39 f0 0f 96 c0 20 c8 3c 01 75 30 4c 89 c7 49 89 f7 e8 11 08 00 00 49 89 c6 48 8b 5c 24 18 <48> 89 d8 48 c1 e8 03 42 80 3c 38 00 74 08 48 89 df e8 13 f4 b2 00 RSP: 0018:ffffc900031f70e0 EFLAGS: 00000202 RAX: ffffc900031f7568 RBX: ffffc900031f7248 RCX: 0000000000000001 RDX: ffffc900031f7248 RSI: dffffc0000000000 RDI: ffffc900031f7330 RBP: 1ffff9200063ee41 R08: ffffc900031f7330 R09: 0000000000000000 R10: ffffc900031f7258 R11: fffff5200063ee4d R12: 1ffff9200063ee42 R13: 1ffff9200063ee43 R14: ffffc900031f7568 R15: dffffc0000000000 unwind_next_frame+0x18cc/0x23d0 arch/x86/kernel/unwind_orc.c:-1 arch_stack_walk+0x11c/0x150 arch/x86/kernel/stacktrace.c:25 stack_trace_save+0x9c/0xe0 kernel/stacktrace.c:122 kasan_save_stack+0x3e/0x60 mm/kasan/common.c:57 kasan_record_aux_stack+0xbd/0xd0 mm/kasan/generic.c:556 slab_free_hook mm/slub.c:2501 [inline] slab_free mm/slub.c:6670 [inline] kmem_cache_free+0x475/0x620 mm/slub.c:6781 remove_vma mm/vma.c:462 [inline] vms_complete_munmap_vmas+0x626/0x8a0 mm/vma.c:1296 __mmap_complete+0x7b/0x610 mm/vma.c:2540 __mmap_region mm/vma.c:2717 [inline] mmap_region+0x11e3/0x1d10 mm/vma.c:2786 do_mmap+0xc45/0x10d0 mm/mmap.c:558 vm_mmap_pgoff+0x2a6/0x4d0 mm/util.c:581 ksys_mmap_pgoff+0x51f/0x760 mm/mmap.c:604 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xec/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f1fb096a242 Code: 08 00 04 00 00 eb e2 90 41 f7 c1 ff 0f 00 00 75 27 55 89 cd 53 48 89 fb 48 85 ff 74 33 41 89 ea 48 89 df b8 09 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 5e 5b 5d c3 0f 1f 00 c7 05 46 40 01 00 16 00 RSP: 002b:00007ffe403d8a68 EFLAGS: 00000206 ORIG_RAX: 0000000000000009 RAX: ffffffffffffffda RBX: 00007f1fb0667000 RCX: 00007f1fb096a242 RDX: 0000000000000001 RSI: 0000000000008000 RDI: 00007f1fb0667000 RBP: 0000000000000812 R08: 0000000000000003 R09: 0000000000024000 R10: 0000000000000812 R11: 0000000000000206 R12: 00007ffe403d8af0 R13: 00007f1fb093fab0 R14: 00007ffe403d8ee0 R15: 00000fffc807b150 </TASK> rcu: rcu_preempt kthread timer wakeup didn't happen for 10501 jiffies! g10825 f0x0 RCU_GP_WAIT_FQS(5) ->state=0x402 rcu: Possible timer handling issue on cpu=0 timer-softirq=3502 rcu: rcu_preempt kthread starved for 10502 jiffies! g10825 f0x0 RCU_GP_WAIT_FQS(5) ->state=0x402 ->cpu=0 rcu: Unless rcu_preempt kthread gets sufficient CPU time, OOM is now expected behavior. rcu: RCU grace-period kthread stack dump: task:rcu_preempt state:I stack:28008 pid:16 tgid:16 ppid:2 task_flags:0x208040 flags:0x00080000 Call Trace: <TASK> context_switch kernel/sched/core.c:5256 [inline] __schedule+0x149b/0x4fd0 kernel/sched/core.c:6863 __schedule_loop kernel/sched/core.c:6945 [inline] schedule+0x165/0x360 kernel/sched/core.c:6960 schedule_timeout+0x12b/0x270 kernel/time/sleep_timeout.c:99 rcu_gp_fqs_loop+0x301/0x1540 kernel/rcu/tree.c:2083 rcu_gp_kthread+0x99/0x390 kernel/rcu/tree.c:2285 kthread+0x711/0x8a0 kernel/kthread.c:463 ret_from_fork+0x510/0xa50 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:246 </TASK> --- This report is generated by a bot. It may contain errors. See https://goo.gl/tpsmEJ for more information about syzbot. syzbot engineers can be reached at syzkaller@googlegroups.com. syzbot will keep track of this issue. See: https://goo.gl/tpsmEJ#status for how to communicate with syzbot. If the report is already addressed, let syzbot know by replying with: #syz fix: exact-commit-title If you want syzbot to run the reproducer, reply with: #syz test: git://repo/address.git branch-or-commit-hash If you attach or paste a git patch, syzbot will apply it before testing. If you want to overwrite report's subsystems, reply with: #syz set subsystems: new-subsystem (See the list of subsystem names on the web dashboard) If the report is a duplicate of another one, reply with: #syz dup: exact-subject-of-another-report If you want to undo deduplication, reply with: #syz undup ^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [syzbot] [mm?] INFO: rcu detected stall in __mmap_complete 2026-01-04 22:55 [syzbot] [mm?] INFO: rcu detected stall in __mmap_complete syzbot @ 2026-08-29 20:56 ` syzbot 2026-08-29 21:58 ` Andrew Morton 0 siblings, 1 reply; 4+ messages in thread From: syzbot @ 2026-08-29 20:56 UTC (permalink / raw) To: akpm, dvyukov, elver, glider, jannh, kasan-dev, liam.howlett, linux-kernel, linux-mm, lorenzo.stoakes, netdev, pfalcato, syzkaller-bugs, vbabka syzbot has found a reproducer for the following issue on: HEAD commit: 1b78070aaef6 Merge tag 'net-7.3-rc1' of git://git.kernel.o.. git tree: net-next console output: https://syzkaller.appspot.com/x/log.txt?x=154d7d49580000 kernel config: https://syzkaller.appspot.com/x/.config?x=5e4e3a0e188a497e dashboard link: https://syzkaller.appspot.com/bug?extid=e4aa91d7f20c34417d4e compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8 syz repro: https://syzkaller.appspot.com/x/repro.syz?x=134d7d49580000 C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1177ae25580000 Downloadable assets: disk image: https://storage.googleapis.com/syzbot-assets/18856a03a9a3/disk-1b78070a.raw.xz vmlinux: https://storage.googleapis.com/syzbot-assets/cc2bc68d7ef4/vmlinux-1b78070a.xz kernel image: https://storage.googleapis.com/syzbot-assets/05a5e00f8f91/bzImage-1b78070a.xz IMPORTANT: if you fix the issue, please add the following tag to the commit: Reported-by: syzbot+e4aa91d7f20c34417d4e@syzkaller.appspotmail.com rcu: INFO: rcu_preempt detected stalls on CPUs/tasks: rcu: 0-...!: (1 GPs behind) idle=a1cc/1/0x4000000000000000 softirq=17251/17256 fqs=2 rcu: Tasks blocked on level-0 rcu_node (CPUs 0-1): P4982/1:b..l rcu: (detected by 1, t=10502 jiffies, g=15057, q=530 ncpus=2) Sending NMI from CPU 1 to CPUs 0: NMI backtrace for cpu 0 CPU: 0 UID: 0 PID: 6026 Comm: cmp Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026 RIP: 0010:arch_atomic_try_cmpxchg arch/x86/include/asm/atomic.h:107 [inline] RIP: 0010:raw_atomic_try_cmpxchg_acquire include/linux/atomic/atomic-arch-fallback.h:2170 [inline] RIP: 0010:atomic_try_cmpxchg_acquire include/linux/atomic/atomic-instrumented.h:1302 [inline] RIP: 0010:queued_spin_lock include/asm-generic/qspinlock.h:112 [inline] RIP: 0010:do_raw_spin_lock+0x12b/0x2f0 kernel/locking/spinlock_debug.c:116 Code: 14 04 04 c7 44 24 40 00 00 00 00 48 89 df be 04 00 00 00 49 89 d6 e8 34 c1 93 00 48 8d 7c 24 40 be 04 00 00 00 e8 25 c1 93 00 <8b> 44 24 40 b9 01 00 00 00 f0 0f b1 0b 0f 85 20 01 00 00 43 c6 44 RSP: 0018:ffffc90000007c40 EFLAGS: 00000097 RAX: 00000000ffffff01 RBX: ffff88807cbce2a8 RCX: ffffffff81a3bd0b RDX: 0000000000000001 RSI: 0000000000000004 RDI: ffffc90000007c80 RBP: ffffc90000007ce8 R08: 0000000000000003 R09: 0000000000000004 R10: dffffc0000000000 R11: fffff52000000f90 R12: 1ffff92000000f8c R13: ffff88807cbce2b0 R14: dffffc0000000000 R15: 1ffff1100f979c56 FS: 0000000000000000(0000) GS:ffff888124ce0000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f2972a84000 CR3: 0000000073aec000 CR4: 00000000003526f0 Call Trace: <IRQ> spin_lock include/linux/spinlock.h:347 [inline] advance_sched+0xc2/0xc80 net/sched/sch_taprio.c:931 __run_hrtimer kernel/time/hrtimer.c:2067 [inline] __hrtimer_run_queues+0x3bc/0xa10 kernel/time/hrtimer.c:2124 hrtimer_interrupt+0x4cd/0xaa0 kernel/time/hrtimer.c:2243 local_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1051 [inline] __sysvec_apic_timer_interrupt+0x102/0x430 arch/x86/kernel/apic/apic.c:1068 instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1062 [inline] sysvec_apic_timer_interrupt+0xa1/0xc0 arch/x86/kernel/apic/apic.c:1062 </IRQ> <TASK> asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:674 RIP: 0010:lock_acquire+0x232/0x350 kernel/locking/lockdep.c:5913 Code: ff ff ff e8 40 dc 3f 0a f7 44 24 10 00 02 00 00 0f 84 38 ff ff ff 65 48 8b 05 92 e7 f0 11 48 3b 44 24 50 75 33 fb 48 83 c4 58 <5b> 41 5c 41 5d 41 5e 41 5f 5d c3 cc cc cc cc cc 48 8d 3d 07 23 da RSP: 0018:ffffc900037eeda0 EFLAGS: 00000296 RAX: 27e016d3b0e95d00 RBX: 0000000000000000 RCX: 0000000000000046 RDX: 00000000e9c5941a RSI: ffffffff8e6fac39 RDI: ffffffff8c6d8b80 RBP: ffff88801df9be80 R08: 7a00000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: ffffffff8ed5c6e0 R12: ffffffff8ed5c6e0 R13: 0000000000000002 R14: 0000000000000000 R15: 0000000000000246 rcu_lock_acquire include/linux/rcupdate.h:309 [inline] rcu_read_lock include/linux/rcupdate.h:849 [inline] class_rcu_constructor include/linux/rcupdate.h:1216 [inline] unwind_next_frame+0xac/0x2550 arch/x86/kernel/unwind_orc.c:495 arch_stack_walk+0x11b/0x150 arch/x86/kernel/stacktrace.c:25 stack_trace_save+0xa9/0x100 kernel/stacktrace.c:122 kasan_save_stack mm/kasan/common.c:57 [inline] kasan_save_track+0x3e/0x80 mm/kasan/common.c:78 poison_kmalloc_redzone mm/kasan/common.c:398 [inline] __kasan_kmalloc+0x93/0xb0 mm/kasan/common.c:415 kasan_kmalloc include/linux/kasan.h:263 [inline] __kmalloc_cache_noprof+0x321/0x600 mm/slub.c:5563 _kmalloc_noprof include/linux/slab.h:991 [inline] slab_free_hook mm/slub.c:2700 [inline] slab_free mm/slub.c:6499 [inline] kmem_cache_free+0x156/0x650 mm/slub.c:6626 remove_vma mm/vma.c:517 [inline] vms_complete_munmap_vmas+0x897/0xbe0 mm/vma.c:1441 __mmap_complete+0xab/0x4b0 mm/vma.c:2721 __mmap_region mm/vma.c:2888 [inline] mmap_region+0x11d0/0x2240 mm/vma.c:2964 do_mmap+0xe0a/0x1300 mm/mmap.c:573 vm_mmap_pgoff+0x272/0x4e0 mm/util.c:581 ksys_mmap_pgoff+0x4dc/0x760 mm/mmap.c:619 do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline] do_syscall_64+0x166/0x520 arch/x86/entry/syscall_64.c:84 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f2972aaf242 Code: 08 00 04 00 00 eb e2 90 41 f7 c1 ff 0f 00 00 75 27 55 89 cd 53 48 89 fb 48 85 ff 74 33 41 89 ea 48 89 df b8 09 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 5e 5b 5d c3 0f 1f 00 c7 05 46 40 01 00 16 00 RSP: 002b:00007ffd9a1c6af8 EFLAGS: 00000206 ORIG_RAX: 0000000000000009 RAX: ffffffffffffffda RBX: 00007f29727db000 RCX: 00007f2972aaf242 RDX: 0000000000000001 RSI: 0000000000004000 RDI: 00007f29727db000 RBP: 0000000000000812 R08: 0000000000000003 R09: 000000000000b000 R10: 0000000000000812 R11: 0000000000000206 R12: 00007ffd9a1c6b80 R13: 00007f2972a83b20 R14: 00007ffd9a1c6f30 R15: 00000fffb3438d62 </TASK> task:udevd state:R running task stack:26384 pid:4982 tgid:4982 ppid:1 task_flags:0x400140 flags:0x00080000 Call Trace: <TASK> context_switch kernel/sched/core.c:5520 [inline] __schedule+0x17d4/0x5820 kernel/sched/core.c:7270 preempt_schedule_irq+0x4b/0x90 kernel/sched/core.c:7592 irqentry_exit_to_kernel_mode include/linux/irq-entry-common.h:539 [inline] irqentry_exit+0x14f/0x910 kernel/entry/common.c:167 asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:674 RIP: 0010:kasan_check_byte include/linux/kasan.h:402 [inline] RIP: 0010:lock_acquire+0x6d/0x350 kernel/locking/lockdep.c:5882 Code: 9b 01 00 00 89 c0 48 0f a3 05 b7 eb d6 0e 73 0d e8 68 34 09 00 84 c0 0f 84 e2 01 00 00 83 3d a9 1c d7 0e 00 0f 84 e9 00 00 00 <48> 8b b4 24 88 00 00 00 4c 89 e7 e8 33 3a 94 00 83 3d 8c 1c d7 0e RSP: 0018:ffffc900044df268 EFLAGS: 00000202 RAX: 0000000000000001 RBX: 0000000000000000 RCX: 8000000000000001 RDX: 0000000000000000 RSI: ffffffff8c6d8b60 RDI: ffffffff8c6d8b20 RBP: 1ffff9200089be7c R08: 0000000000000000 R09: 0000000000000000 R10: ffffc900044df3f8 R11: ffffffff81b272d0 R12: ffffffff8ed5c6e0 R13: 0000000000000002 R14: 0000000000000000 R15: 0000000000000000 rcu_lock_acquire include/linux/rcupdate.h:309 [inline] rcu_read_lock include/linux/rcupdate.h:849 [inline] class_rcu_constructor include/linux/rcupdate.h:1216 [inline] unwind_next_frame+0xac/0x2550 arch/x86/kernel/unwind_orc.c:495 arch_stack_walk+0x11b/0x150 arch/x86/kernel/stacktrace.c:25 stack_trace_save+0xa9/0x100 kernel/stacktrace.c:122 kasan_save_stack mm/kasan/common.c:57 [inline] kasan_save_track+0x3e/0x80 mm/kasan/common.c:78 kasan_save_free_info+0x40/0x50 mm/kasan/generic.c:584 poison_slab_object mm/kasan/common.c:253 [inline] __kasan_slab_free+0x5c/0x80 mm/kasan/common.c:285 kasan_slab_free include/linux/kasan.h:235 [inline] slab_free_hook mm/slub.c:2748 [inline] slab_free mm/slub.c:6499 [inline] kfree+0x1c5/0x650 mm/slub.c:6792 tomoyo_check_open_permission+0x32c/0x470 security/tomoyo/file.c:791 security_file_open+0xa9/0x240 security/security.c:2739 do_dentry_open+0x4a0/0x1380 fs/open.c:973 vfs_open+0x3b/0x340 fs/open.c:1101 do_open fs/namei.c:4837 [inline] path_openat+0x1443/0x1d60 fs/namei.c:5000 do_file_open+0x23e/0x4a0 fs/namei.c:5029 do_sys_openat2+0x115/0x200 fs/open.c:1417 do_sys_open fs/open.c:1423 [inline] __do_sys_openat fs/open.c:1439 [inline] __se_sys_openat fs/open.c:1434 [inline] __x64_sys_openat+0x138/0x170 fs/open.c:1434 do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline] do_syscall_64+0x166/0x520 arch/x86/entry/syscall_64.c:84 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f22b3aa7407 RSP: 002b:00007fffdfe06440 EFLAGS: 00000202 ORIG_RAX: 0000000000000101 RAX: ffffffffffffffda RBX: 00007f22b425c880 RCX: 00007f22b3aa7407 RDX: 0000000000080141 RSI: 0000559823bb502e RDI: ffffffffffffff9c RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000 R10: 00000000000001a4 R11: 0000000000000202 R12: 00000000ffffffff R13: 00000000ffffffff R14: ffffffffffffffff R15: 0000000000000000 </TASK> rcu: rcu_preempt kthread starved for 10498 jiffies! g15057 f0x0 RCU_GP_WAIT_FQS(5) ->state=R ->cpu=1 rcu: Unless rcu_preempt kthread gets sufficient CPU time, OOM is now expected behavior. rcu: RCU grace-period kthread stack dump: task:rcu_preempt state:R running task stack:27496 pid:17 tgid:17 ppid:2 task_flags:0x208040 flags:0x00080000 Call Trace: <TASK> context_switch kernel/sched/core.c:5520 [inline] __schedule+0x17d4/0x5820 kernel/sched/core.c:7270 __schedule_loop kernel/sched/core.c:7347 [inline] schedule+0x164/0x2b0 kernel/sched/core.c:7362 schedule_timeout+0x152/0x2c0 kernel/time/sleep_timeout.c:99 rcu_gp_fqs_loop+0x30c/0x11f0 kernel/rcu/tree.c:2122 rcu_gp_kthread+0x9e/0x2b0 kernel/rcu/tree.c:2330 kthread+0x38b/0x480 kernel/kthread.c:436 ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 </TASK> rcu: Stack dump where RCU GP kthread last ran: CPU: 1 UID: 0 PID: 12 Comm: kworker/u8:0 Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026 Workqueue: events_unbound toggle_allocation_gate RIP: 0010:csd_lock_wait kernel/smp.c:363 [inline] RIP: 0010:csd_lock kernel/smp.c:396 [inline] RIP: 0010:smp_call_function_many_cond+0x61e/0x1500 kernel/smp.c:944 Code: b6 04 04 84 c0 0f 85 d5 03 00 00 44 8b 3b 44 89 fe 83 e6 01 31 ff e8 51 51 0c 00 41 83 e7 01 75 07 e8 46 4c 0c 00 eb 3f f3 90 <48> b8 00 00 00 00 00 fc ff df 41 0f b6 04 04 84 c0 75 0f f7 03 01 RSP: 0018:ffffc90000117720 EFLAGS: 00000293 RAX: ffffffff81bb677e RBX: ffff8880b8643708 RCX: ffff88801def8000 RDX: 0000000000000000 RSI: 0000000000000001 RDI: 0000000000000000 RBP: ffffc90000117870 R08: ffff88801def959f R09: 1ffff11003bdf2b3 R10: dffffc0000000000 R11: 0000000000000000 R12: 1ffff110170c86e1 R13: 0000000000000000 R14: ffff8880b8643700 R15: 0000000000000001 FS: 0000000000000000(0000) GS:ffff888124de0000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000555570500a38 CR3: 000000000eb48000 CR4: 00000000003526f0 Call Trace: <TASK> on_each_cpu include/linux/smp.h:71 [inline] smp_text_poke_sync_each_cpu arch/x86/kernel/alternative.c:2602 [inline] smp_text_poke_batch_finish+0x5fd/0x1110 arch/x86/kernel/alternative.c:2812 arch_jump_label_transform_apply+0x1c/0x30 arch/x86/kernel/jump_label.c:146 static_key_enable_cpuslocked+0x128/0x240 kernel/jump_label.c:210 static_key_enable+0x1a/0x20 kernel/jump_label.c:223 toggle_allocation_gate+0xab/0x290 mm/kfence/core.c:902 process_one_work kernel/workqueue.c:3387 [inline] process_scheduled_works+0xc3d/0x1630 kernel/workqueue.c:3470 worker_thread+0xa47/0xfb0 kernel/workqueue.c:3551 kthread+0x38b/0x480 kernel/kthread.c:436 ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 </TASK> --- If you want syzbot to run the reproducer, reply with: #syz test: git://repo/address.git branch-or-commit-hash If you attach or paste a git patch, syzbot will apply it before testing. ^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [syzbot] [mm?] INFO: rcu detected stall in __mmap_complete 2026-08-29 20:56 ` syzbot @ 2026-08-29 21:58 ` Andrew Morton 2026-08-29 23:44 ` syzbot 0 siblings, 1 reply; 4+ messages in thread From: Andrew Morton @ 2026-08-29 21:58 UTC (permalink / raw) To: syzbot Cc: dvyukov, elver, glider, jannh, kasan-dev, liam.howlett, linux-kernel, linux-mm, lorenzo.stoakes, netdev, pfalcato, syzkaller-bugs, vbabka, Junjie Cao On Sat, 29 Aug 2026 13:56:24 -0700 syzbot <syzbot+e4aa91d7f20c34417d4e@syzkaller.appspotmail.com> wrote: > syzbot has found a reproducer for the following iss > > HEAD commit: 1b78070aaef6 Merge tag 'net-7.3-rc1' of git://git.kernel.o.. > git tree: net-next > console output: https://syzkaller.appspot.com/x/log.txt?x=154d7d49580000 > kernel config: https://syzkaller.appspot.com/x/.config?x=5e4e3a0e188a497e > dashboard link: https://syzkaller.appspot.com/bug?extid=e4aa91d7f20c34417d4e > compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8 > syz repro: https://syzkaller.appspot.com/x/repro.syz?x=134d7d49580000 > C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1177ae25580000 > > Downloadable assets: > disk image: https://storage.googleapis.com/syzbot-assets/18856a03a9a3/disk-1b78070a.raw.xz > vmlinux: https://storage.googleapis.com/syzbot-assets/cc2bc68d7ef4/vmlinux-1b78070a.xz > kernel image: https://storage.googleapis.com/syzbot-assets/05a5e00f8f91/bzImage-1b78070a.xz > > IMPORTANT: if you fix the issue, please add the following tag to the commit: > Reported-by: syzbot+e4aa91d7f20c34417d4e@syzkaller.appspotmail.com #syz test: git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net-next.git main From: Junjie Cao <junjie.cao@intel.com> Subject: net/sched: taprio: catch up in bounded time when the schedule falls behind Date: Thu, 20 Aug 2026 14:27:13 +0800 advance_sched() advances exactly one entry per hrtimer expiry. When the operational schedule falls behind - the timer was delayed, the CPU was starved, or the reference clock stepped forward - every elapsed entry is replayed back to back from hrtimer context with current_entry_lock held, and each replay rearms the timer with an expiry in the past. Once the backlog is large enough the CPU never leaves timer processing and RCU stalls follow. syzbot triggers this with schedules whose intervals are shorter than the cost of servicing one expiry, so the backlog only ever grows. Skip complete cycles arithmetically and walk at most one cycle of entries to land on the entry covering the current time. Gate close times and budgets are still only computed for the entry landed on. An admin schedule crossed by the jump is picked up by the existing should_change_schedules() check on the recomputed end time. The walk is capped at twice the entry count as a safeguard against degenerate intervals; leftover backlog is then handled by the next expiry as today. Link: https://lore.kernel.org/20260820062715.278124-2-junjie.cao@intel.com Fixes: 5a781ccbd19e ("tc: Add support for configuring the taprio scheduler") Signed-off-by: Junjie Cao <junjie.cao@intel.com> Signed-off-by: Andrew Morton <akpm@linux-foundation.org> --- net/sched/sch_taprio.c | 56 ++++++++++++++++++++++++++++++++++++--- 1 file changed, 53 insertions(+), 3 deletions(-) --- a/net/sched/sch_taprio.c~net-sched-taprio-catch-up-in-bounded-time-when-the-schedule-falls-behind +++ a/net/sched/sch_taprio.c @@ -916,6 +916,51 @@ static bool should_change_schedules(cons return false; } +/* The operational schedule fell behind, e.g. because the timer was delayed + * or the reference clock stepped forward. Advancing one entry per timer + * expiry would replay the whole backlog from hrtimer context, so skip + * complete cycles arithmetically and walk the remaining entries to land on + * the entry covering the current time. + */ +static void taprio_catch_up(struct sched_gate_list *oper, + struct sched_entry **next, ktime_t *next_start, + ktime_t *end_time, ktime_t now) +{ + int budget = 2 * oper->num_entries + 1; + struct sched_entry *entry = *next; + ktime_t start = *next_start; + ktime_t end = *end_time; + s64 behind = ktime_sub(now, end); + + if (oper->cycle_time > 0 && behind >= oper->cycle_time) { + s64 jump = div64_s64(behind, oper->cycle_time) * oper->cycle_time; + + start = ktime_add_ns(start, jump); + end = ktime_add_ns(end, jump); + oper->cycle_end_time = ktime_add_ns(oper->cycle_end_time, jump); + } + + while (ktime_before(end, now) && --budget) { + if (list_is_last(&entry->list, &oper->entries) || + ktime_compare(end, oper->cycle_end_time) == 0) { + entry = list_first_entry(&oper->entries, + struct sched_entry, list); + oper->cycle_end_time = ktime_add_ns(oper->cycle_end_time, + oper->cycle_time); + } else { + entry = list_next_entry(entry, list); + } + + start = end; + end = ktime_add_ns(end, entry->interval); + end = min_t(ktime_t, end, oper->cycle_end_time); + } + + *next = entry; + *next_start = start; + *end_time = end; +} + static enum hrtimer_restart advance_sched(struct hrtimer *timer) { struct taprio_sched *q = container_of(timer, struct taprio_sched, @@ -925,7 +970,7 @@ static enum hrtimer_restart advance_sche int num_tc = netdev_get_num_tc(dev); struct sched_entry *entry, *next; struct Qdisc *sch = q->root; - ktime_t end_time; + ktime_t end_time, next_start, now; int tc; spin_lock(&q->current_entry_lock); @@ -961,14 +1006,19 @@ static enum hrtimer_restart advance_sche next = list_next_entry(entry, list); } - end_time = ktime_add_ns(entry->end_time, next->interval); + next_start = entry->end_time; + end_time = ktime_add_ns(next_start, next->interval); end_time = min_t(ktime_t, end_time, oper->cycle_end_time); + now = hrtimer_cb_get_time(timer); + if (unlikely(ktime_before(end_time, now))) + taprio_catch_up(oper, &next, &next_start, &end_time, now); + for (tc = 0; tc < num_tc; tc++) { if (next->gate_duration[tc] == oper->cycle_time) next->gate_close_time[tc] = KTIME_MAX; else - next->gate_close_time[tc] = ktime_add_ns(entry->end_time, + next->gate_close_time[tc] = ktime_add_ns(next_start, next->gate_duration[tc]); } _ ^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [syzbot] [mm?] INFO: rcu detected stall in __mmap_complete 2026-08-29 21:58 ` Andrew Morton @ 2026-08-29 23:44 ` syzbot 0 siblings, 0 replies; 4+ messages in thread From: syzbot @ 2026-08-29 23:44 UTC (permalink / raw) To: akpm, dvyukov, elver, glider, jannh, junjie.cao, kasan-dev, liam.howlett, linux-kernel, linux-mm, lorenzo.stoakes, netdev, pfalcato, syzkaller-bugs, vbabka Hello, syzbot has tested the proposed patch and the reproducer did not trigger any issue: Reported-by: syzbot+e4aa91d7f20c34417d4e@syzkaller.appspotmail.com Tested-by: syzbot+e4aa91d7f20c34417d4e@syzkaller.appspotmail.com Tested on: commit: 1b78070a Merge tag 'net-7.3-rc1' of git://git.kernel.o.. git tree: git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net-next.git main console output: https://syzkaller.appspot.com/x/log.txt?x=14e12c15580000 kernel config: https://syzkaller.appspot.com/x/.config?x=5e4e3a0e188a497e dashboard link: https://syzkaller.appspot.com/bug?extid=e4aa91d7f20c34417d4e compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8 patch: https://syzkaller.appspot.com/x/patch.diff?x=11f37d49580000 Note: testing is done by a robot and is best-effort only. ^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-08-29 23:44 UTC | newest] Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed) -- links below jump to the message on this page -- 2026-01-04 22:55 [syzbot] [mm?] INFO: rcu detected stall in __mmap_complete syzbot 2026-08-29 20:56 ` syzbot 2026-08-29 21:58 ` Andrew Morton 2026-08-29 23:44 ` syzbot
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®