* [syzbot] [mm?] INFO: rcu detected stall in __mmap_complete
@ 2026-01-04 22:55 syzbot
2026-08-29 20:56 ` syzbot
0 siblings, 1 reply; 4+ messages in thread
From: syzbot @ 2026-01-04 22:55 UTC (permalink / raw)
To: Liam.Howlett, akpm, jannh, linux-kernel, linux-mm,
lorenzo.stoakes, pfalcato, syzkaller-bugs, vbabka
Hello,
syzbot found the following issue on:
HEAD commit: c8ebd433459b Merge tag 'nfsd-6.19-2' of git://git.kernel.o..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=1205b222580000
kernel config: https://syzkaller.appspot.com/x/.config?x=a94030c847137a18
dashboard link: https://syzkaller.appspot.com/bug?extid=e4aa91d7f20c34417d4e
compiler: Debian clang version 20.1.8 (++20250708063551+0c9f909b7976-1~exp1~20250708183702.136), Debian LLD 20.1.8
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=11e5cafc580000
Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/499025e81349/disk-c8ebd433.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/9eacf2e4acfd/vmlinux-c8ebd433.xz
kernel image: https://storage.googleapis.com/syzbot-assets/4650397775c2/bzImage-c8ebd433.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+e4aa91d7f20c34417d4e@syzkaller.appspotmail.com
rcu: INFO: rcu_preempt detected stalls on CPUs/tasks:
rcu: 0-...!: (3 ticks this GP) idle=233c/1/0x4000000000000000 softirq=15929/15929 fqs=0
rcu: (detected by 1, t=10502 jiffies, g=10825, q=798 ncpus=2)
Sending NMI from CPU 1 to CPUs 0:
NMI backtrace for cpu 0
CPU: 0 UID: 0 PID: 6083 Comm: rm Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/25/2025
RIP: 0010:__raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline]
RIP: 0010:_raw_spin_lock_irqsave+0x40/0x60 kernel/locking/spinlock.c:162
Code: a6 9a 6c f6 bf 01 00 00 00 e8 5c 85 34 f6 49 8d 7e 18 31 f6 31 d2 31 c9 41 b8 01 00 00 00 45 31 c9 ff 74 24 10 e8 c0 c7 41 f6 <48> 83 c4 08 4c 89 f7 e8 44 68 42 f6 48 89 d8 5b 41 5e e9 89 49 00
RSP: 0018:ffffc90000007ca0 EFLAGS: 00000082
RAX: f6300cf39c3c4f00 RBX: 0000000000000092 RCX: 0000000000010002
RDX: 0000000016fc2300 RSI: ffffffff8d975f94 RDI: ffffffff8bc083e0
RBP: ffffc90000007e90 R08: ffffffff8497cbfd R09: ffffffff99b67028
R10: ffff888035774300 R11: ffffed1006aee863 R12: ffff888035774300
R13: ffffffff99b67008 R14: ffffffff99b67010 R15: ffff888035774300
FS: 0000000000000000(0000) GS:ffff888125e1f000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f1fb067feb8 CR3: 0000000072afc000 CR4: 00000000003526f0
Call Trace:
<IRQ>
debug_object_deactivate+0x6d/0x360 lib/debugobjects.c:873
debug_hrtimer_deactivate kernel/time/hrtimer.c:443 [inline]
debug_deactivate+0x1d/0x1e0 kernel/time/hrtimer.c:483
__run_hrtimer kernel/time/hrtimer.c:1745 [inline]
__hrtimer_run_queues+0x2b0/0xc30 kernel/time/hrtimer.c:1841
hrtimer_interrupt+0x45b/0xaa0 kernel/time/hrtimer.c:1903
local_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1045 [inline]
__sysvec_apic_timer_interrupt+0x102/0x3e0 arch/x86/kernel/apic/apic.c:1062
instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1056 [inline]
sysvec_apic_timer_interrupt+0xa1/0xc0 arch/x86/kernel/apic/apic.c:1056
</IRQ>
<TASK>
asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:697
RIP: 0010:deref_stack_reg+0x1a7/0x230 arch/x86/kernel/unwind_orc.c:422
Code: 46 49 8d 40 08 48 39 d8 0f 97 c1 4c 39 f0 0f 96 c0 20 c8 3c 01 75 30 4c 89 c7 49 89 f7 e8 11 08 00 00 49 89 c6 48 8b 5c 24 18 <48> 89 d8 48 c1 e8 03 42 80 3c 38 00 74 08 48 89 df e8 13 f4 b2 00
RSP: 0018:ffffc900031f70e0 EFLAGS: 00000202
RAX: ffffc900031f7568 RBX: ffffc900031f7248 RCX: 0000000000000001
RDX: ffffc900031f7248 RSI: dffffc0000000000 RDI: ffffc900031f7330
RBP: 1ffff9200063ee41 R08: ffffc900031f7330 R09: 0000000000000000
R10: ffffc900031f7258 R11: fffff5200063ee4d R12: 1ffff9200063ee42
R13: 1ffff9200063ee43 R14: ffffc900031f7568 R15: dffffc0000000000
unwind_next_frame+0x18cc/0x23d0 arch/x86/kernel/unwind_orc.c:-1
arch_stack_walk+0x11c/0x150 arch/x86/kernel/stacktrace.c:25
stack_trace_save+0x9c/0xe0 kernel/stacktrace.c:122
kasan_save_stack+0x3e/0x60 mm/kasan/common.c:57
kasan_record_aux_stack+0xbd/0xd0 mm/kasan/generic.c:556
slab_free_hook mm/slub.c:2501 [inline]
slab_free mm/slub.c:6670 [inline]
kmem_cache_free+0x475/0x620 mm/slub.c:6781
remove_vma mm/vma.c:462 [inline]
vms_complete_munmap_vmas+0x626/0x8a0 mm/vma.c:1296
__mmap_complete+0x7b/0x610 mm/vma.c:2540
__mmap_region mm/vma.c:2717 [inline]
mmap_region+0x11e3/0x1d10 mm/vma.c:2786
do_mmap+0xc45/0x10d0 mm/mmap.c:558
vm_mmap_pgoff+0x2a6/0x4d0 mm/util.c:581
ksys_mmap_pgoff+0x51f/0x760 mm/mmap.c:604
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xec/0xf80 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f1fb096a242
Code: 08 00 04 00 00 eb e2 90 41 f7 c1 ff 0f 00 00 75 27 55 89 cd 53 48 89 fb 48 85 ff 74 33 41 89 ea 48 89 df b8 09 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 5e 5b 5d c3 0f 1f 00 c7 05 46 40 01 00 16 00
RSP: 002b:00007ffe403d8a68 EFLAGS: 00000206 ORIG_RAX: 0000000000000009
RAX: ffffffffffffffda RBX: 00007f1fb0667000 RCX: 00007f1fb096a242
RDX: 0000000000000001 RSI: 0000000000008000 RDI: 00007f1fb0667000
RBP: 0000000000000812 R08: 0000000000000003 R09: 0000000000024000
R10: 0000000000000812 R11: 0000000000000206 R12: 00007ffe403d8af0
R13: 00007f1fb093fab0 R14: 00007ffe403d8ee0 R15: 00000fffc807b150
</TASK>
rcu: rcu_preempt kthread timer wakeup didn't happen for 10501 jiffies! g10825 f0x0 RCU_GP_WAIT_FQS(5) ->state=0x402
rcu: Possible timer handling issue on cpu=0 timer-softirq=3502
rcu: rcu_preempt kthread starved for 10502 jiffies! g10825 f0x0 RCU_GP_WAIT_FQS(5) ->state=0x402 ->cpu=0
rcu: Unless rcu_preempt kthread gets sufficient CPU time, OOM is now expected behavior.
rcu: RCU grace-period kthread stack dump:
task:rcu_preempt state:I stack:28008 pid:16 tgid:16 ppid:2 task_flags:0x208040 flags:0x00080000
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5256 [inline]
__schedule+0x149b/0x4fd0 kernel/sched/core.c:6863
__schedule_loop kernel/sched/core.c:6945 [inline]
schedule+0x165/0x360 kernel/sched/core.c:6960
schedule_timeout+0x12b/0x270 kernel/time/sleep_timeout.c:99
rcu_gp_fqs_loop+0x301/0x1540 kernel/rcu/tree.c:2083
rcu_gp_kthread+0x99/0x390 kernel/rcu/tree.c:2285
kthread+0x711/0x8a0 kernel/kthread.c:463
ret_from_fork+0x510/0xa50 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:246
</TASK>
---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [syzbot] [mm?] INFO: rcu detected stall in __mmap_complete
2026-01-04 22:55 [syzbot] [mm?] INFO: rcu detected stall in __mmap_complete syzbot
@ 2026-08-29 20:56 ` syzbot
2026-08-29 21:58 ` Andrew Morton
0 siblings, 1 reply; 4+ messages in thread
From: syzbot @ 2026-08-29 20:56 UTC (permalink / raw)
To: akpm, dvyukov, elver, glider, jannh, kasan-dev, liam.howlett,
linux-kernel, linux-mm, lorenzo.stoakes, netdev, pfalcato,
syzkaller-bugs, vbabka
syzbot has found a reproducer for the following issue on:
HEAD commit: 1b78070aaef6 Merge tag 'net-7.3-rc1' of git://git.kernel.o..
git tree: net-next
console output: https://syzkaller.appspot.com/x/log.txt?x=154d7d49580000
kernel config: https://syzkaller.appspot.com/x/.config?x=5e4e3a0e188a497e
dashboard link: https://syzkaller.appspot.com/bug?extid=e4aa91d7f20c34417d4e
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=134d7d49580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1177ae25580000
Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/18856a03a9a3/disk-1b78070a.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/cc2bc68d7ef4/vmlinux-1b78070a.xz
kernel image: https://storage.googleapis.com/syzbot-assets/05a5e00f8f91/bzImage-1b78070a.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+e4aa91d7f20c34417d4e@syzkaller.appspotmail.com
rcu: INFO: rcu_preempt detected stalls on CPUs/tasks:
rcu: 0-...!: (1 GPs behind) idle=a1cc/1/0x4000000000000000 softirq=17251/17256 fqs=2
rcu: Tasks blocked on level-0 rcu_node (CPUs 0-1): P4982/1:b..l
rcu: (detected by 1, t=10502 jiffies, g=15057, q=530 ncpus=2)
Sending NMI from CPU 1 to CPUs 0:
NMI backtrace for cpu 0
CPU: 0 UID: 0 PID: 6026 Comm: cmp Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
RIP: 0010:arch_atomic_try_cmpxchg arch/x86/include/asm/atomic.h:107 [inline]
RIP: 0010:raw_atomic_try_cmpxchg_acquire include/linux/atomic/atomic-arch-fallback.h:2170 [inline]
RIP: 0010:atomic_try_cmpxchg_acquire include/linux/atomic/atomic-instrumented.h:1302 [inline]
RIP: 0010:queued_spin_lock include/asm-generic/qspinlock.h:112 [inline]
RIP: 0010:do_raw_spin_lock+0x12b/0x2f0 kernel/locking/spinlock_debug.c:116
Code: 14 04 04 c7 44 24 40 00 00 00 00 48 89 df be 04 00 00 00 49 89 d6 e8 34 c1 93 00 48 8d 7c 24 40 be 04 00 00 00 e8 25 c1 93 00 <8b> 44 24 40 b9 01 00 00 00 f0 0f b1 0b 0f 85 20 01 00 00 43 c6 44
RSP: 0018:ffffc90000007c40 EFLAGS: 00000097
RAX: 00000000ffffff01 RBX: ffff88807cbce2a8 RCX: ffffffff81a3bd0b
RDX: 0000000000000001 RSI: 0000000000000004 RDI: ffffc90000007c80
RBP: ffffc90000007ce8 R08: 0000000000000003 R09: 0000000000000004
R10: dffffc0000000000 R11: fffff52000000f90 R12: 1ffff92000000f8c
R13: ffff88807cbce2b0 R14: dffffc0000000000 R15: 1ffff1100f979c56
FS: 0000000000000000(0000) GS:ffff888124ce0000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f2972a84000 CR3: 0000000073aec000 CR4: 00000000003526f0
Call Trace:
<IRQ>
spin_lock include/linux/spinlock.h:347 [inline]
advance_sched+0xc2/0xc80 net/sched/sch_taprio.c:931
__run_hrtimer kernel/time/hrtimer.c:2067 [inline]
__hrtimer_run_queues+0x3bc/0xa10 kernel/time/hrtimer.c:2124
hrtimer_interrupt+0x4cd/0xaa0 kernel/time/hrtimer.c:2243
local_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1051 [inline]
__sysvec_apic_timer_interrupt+0x102/0x430 arch/x86/kernel/apic/apic.c:1068
instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1062 [inline]
sysvec_apic_timer_interrupt+0xa1/0xc0 arch/x86/kernel/apic/apic.c:1062
</IRQ>
<TASK>
asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:674
RIP: 0010:lock_acquire+0x232/0x350 kernel/locking/lockdep.c:5913
Code: ff ff ff e8 40 dc 3f 0a f7 44 24 10 00 02 00 00 0f 84 38 ff ff ff 65 48 8b 05 92 e7 f0 11 48 3b 44 24 50 75 33 fb 48 83 c4 58 <5b> 41 5c 41 5d 41 5e 41 5f 5d c3 cc cc cc cc cc 48 8d 3d 07 23 da
RSP: 0018:ffffc900037eeda0 EFLAGS: 00000296
RAX: 27e016d3b0e95d00 RBX: 0000000000000000 RCX: 0000000000000046
RDX: 00000000e9c5941a RSI: ffffffff8e6fac39 RDI: ffffffff8c6d8b80
RBP: ffff88801df9be80 R08: 7a00000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: ffffffff8ed5c6e0 R12: ffffffff8ed5c6e0
R13: 0000000000000002 R14: 0000000000000000 R15: 0000000000000246
rcu_lock_acquire include/linux/rcupdate.h:309 [inline]
rcu_read_lock include/linux/rcupdate.h:849 [inline]
class_rcu_constructor include/linux/rcupdate.h:1216 [inline]
unwind_next_frame+0xac/0x2550 arch/x86/kernel/unwind_orc.c:495
arch_stack_walk+0x11b/0x150 arch/x86/kernel/stacktrace.c:25
stack_trace_save+0xa9/0x100 kernel/stacktrace.c:122
kasan_save_stack mm/kasan/common.c:57 [inline]
kasan_save_track+0x3e/0x80 mm/kasan/common.c:78
poison_kmalloc_redzone mm/kasan/common.c:398 [inline]
__kasan_kmalloc+0x93/0xb0 mm/kasan/common.c:415
kasan_kmalloc include/linux/kasan.h:263 [inline]
__kmalloc_cache_noprof+0x321/0x600 mm/slub.c:5563
_kmalloc_noprof include/linux/slab.h:991 [inline]
slab_free_hook mm/slub.c:2700 [inline]
slab_free mm/slub.c:6499 [inline]
kmem_cache_free+0x156/0x650 mm/slub.c:6626
remove_vma mm/vma.c:517 [inline]
vms_complete_munmap_vmas+0x897/0xbe0 mm/vma.c:1441
__mmap_complete+0xab/0x4b0 mm/vma.c:2721
__mmap_region mm/vma.c:2888 [inline]
mmap_region+0x11d0/0x2240 mm/vma.c:2964
do_mmap+0xe0a/0x1300 mm/mmap.c:573
vm_mmap_pgoff+0x272/0x4e0 mm/util.c:581
ksys_mmap_pgoff+0x4dc/0x760 mm/mmap.c:619
do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline]
do_syscall_64+0x166/0x520 arch/x86/entry/syscall_64.c:84
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f2972aaf242
Code: 08 00 04 00 00 eb e2 90 41 f7 c1 ff 0f 00 00 75 27 55 89 cd 53 48 89 fb 48 85 ff 74 33 41 89 ea 48 89 df b8 09 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 5e 5b 5d c3 0f 1f 00 c7 05 46 40 01 00 16 00
RSP: 002b:00007ffd9a1c6af8 EFLAGS: 00000206 ORIG_RAX: 0000000000000009
RAX: ffffffffffffffda RBX: 00007f29727db000 RCX: 00007f2972aaf242
RDX: 0000000000000001 RSI: 0000000000004000 RDI: 00007f29727db000
RBP: 0000000000000812 R08: 0000000000000003 R09: 000000000000b000
R10: 0000000000000812 R11: 0000000000000206 R12: 00007ffd9a1c6b80
R13: 00007f2972a83b20 R14: 00007ffd9a1c6f30 R15: 00000fffb3438d62
</TASK>
task:udevd state:R running task stack:26384 pid:4982 tgid:4982 ppid:1 task_flags:0x400140 flags:0x00080000
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5520 [inline]
__schedule+0x17d4/0x5820 kernel/sched/core.c:7270
preempt_schedule_irq+0x4b/0x90 kernel/sched/core.c:7592
irqentry_exit_to_kernel_mode include/linux/irq-entry-common.h:539 [inline]
irqentry_exit+0x14f/0x910 kernel/entry/common.c:167
asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:674
RIP: 0010:kasan_check_byte include/linux/kasan.h:402 [inline]
RIP: 0010:lock_acquire+0x6d/0x350 kernel/locking/lockdep.c:5882
Code: 9b 01 00 00 89 c0 48 0f a3 05 b7 eb d6 0e 73 0d e8 68 34 09 00 84 c0 0f 84 e2 01 00 00 83 3d a9 1c d7 0e 00 0f 84 e9 00 00 00 <48> 8b b4 24 88 00 00 00 4c 89 e7 e8 33 3a 94 00 83 3d 8c 1c d7 0e
RSP: 0018:ffffc900044df268 EFLAGS: 00000202
RAX: 0000000000000001 RBX: 0000000000000000 RCX: 8000000000000001
RDX: 0000000000000000 RSI: ffffffff8c6d8b60 RDI: ffffffff8c6d8b20
RBP: 1ffff9200089be7c R08: 0000000000000000 R09: 0000000000000000
R10: ffffc900044df3f8 R11: ffffffff81b272d0 R12: ffffffff8ed5c6e0
R13: 0000000000000002 R14: 0000000000000000 R15: 0000000000000000
rcu_lock_acquire include/linux/rcupdate.h:309 [inline]
rcu_read_lock include/linux/rcupdate.h:849 [inline]
class_rcu_constructor include/linux/rcupdate.h:1216 [inline]
unwind_next_frame+0xac/0x2550 arch/x86/kernel/unwind_orc.c:495
arch_stack_walk+0x11b/0x150 arch/x86/kernel/stacktrace.c:25
stack_trace_save+0xa9/0x100 kernel/stacktrace.c:122
kasan_save_stack mm/kasan/common.c:57 [inline]
kasan_save_track+0x3e/0x80 mm/kasan/common.c:78
kasan_save_free_info+0x40/0x50 mm/kasan/generic.c:584
poison_slab_object mm/kasan/common.c:253 [inline]
__kasan_slab_free+0x5c/0x80 mm/kasan/common.c:285
kasan_slab_free include/linux/kasan.h:235 [inline]
slab_free_hook mm/slub.c:2748 [inline]
slab_free mm/slub.c:6499 [inline]
kfree+0x1c5/0x650 mm/slub.c:6792
tomoyo_check_open_permission+0x32c/0x470 security/tomoyo/file.c:791
security_file_open+0xa9/0x240 security/security.c:2739
do_dentry_open+0x4a0/0x1380 fs/open.c:973
vfs_open+0x3b/0x340 fs/open.c:1101
do_open fs/namei.c:4837 [inline]
path_openat+0x1443/0x1d60 fs/namei.c:5000
do_file_open+0x23e/0x4a0 fs/namei.c:5029
do_sys_openat2+0x115/0x200 fs/open.c:1417
do_sys_open fs/open.c:1423 [inline]
__do_sys_openat fs/open.c:1439 [inline]
__se_sys_openat fs/open.c:1434 [inline]
__x64_sys_openat+0x138/0x170 fs/open.c:1434
do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline]
do_syscall_64+0x166/0x520 arch/x86/entry/syscall_64.c:84
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f22b3aa7407
RSP: 002b:00007fffdfe06440 EFLAGS: 00000202 ORIG_RAX: 0000000000000101
RAX: ffffffffffffffda RBX: 00007f22b425c880 RCX: 00007f22b3aa7407
RDX: 0000000000080141 RSI: 0000559823bb502e RDI: ffffffffffffff9c
RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000
R10: 00000000000001a4 R11: 0000000000000202 R12: 00000000ffffffff
R13: 00000000ffffffff R14: ffffffffffffffff R15: 0000000000000000
</TASK>
rcu: rcu_preempt kthread starved for 10498 jiffies! g15057 f0x0 RCU_GP_WAIT_FQS(5) ->state=R ->cpu=1
rcu: Unless rcu_preempt kthread gets sufficient CPU time, OOM is now expected behavior.
rcu: RCU grace-period kthread stack dump:
task:rcu_preempt state:R running task stack:27496 pid:17 tgid:17 ppid:2 task_flags:0x208040 flags:0x00080000
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5520 [inline]
__schedule+0x17d4/0x5820 kernel/sched/core.c:7270
__schedule_loop kernel/sched/core.c:7347 [inline]
schedule+0x164/0x2b0 kernel/sched/core.c:7362
schedule_timeout+0x152/0x2c0 kernel/time/sleep_timeout.c:99
rcu_gp_fqs_loop+0x30c/0x11f0 kernel/rcu/tree.c:2122
rcu_gp_kthread+0x9e/0x2b0 kernel/rcu/tree.c:2330
kthread+0x38b/0x480 kernel/kthread.c:436
ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
rcu: Stack dump where RCU GP kthread last ran:
CPU: 1 UID: 0 PID: 12 Comm: kworker/u8:0 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
Workqueue: events_unbound toggle_allocation_gate
RIP: 0010:csd_lock_wait kernel/smp.c:363 [inline]
RIP: 0010:csd_lock kernel/smp.c:396 [inline]
RIP: 0010:smp_call_function_many_cond+0x61e/0x1500 kernel/smp.c:944
Code: b6 04 04 84 c0 0f 85 d5 03 00 00 44 8b 3b 44 89 fe 83 e6 01 31 ff e8 51 51 0c 00 41 83 e7 01 75 07 e8 46 4c 0c 00 eb 3f f3 90 <48> b8 00 00 00 00 00 fc ff df 41 0f b6 04 04 84 c0 75 0f f7 03 01
RSP: 0018:ffffc90000117720 EFLAGS: 00000293
RAX: ffffffff81bb677e RBX: ffff8880b8643708 RCX: ffff88801def8000
RDX: 0000000000000000 RSI: 0000000000000001 RDI: 0000000000000000
RBP: ffffc90000117870 R08: ffff88801def959f R09: 1ffff11003bdf2b3
R10: dffffc0000000000 R11: 0000000000000000 R12: 1ffff110170c86e1
R13: 0000000000000000 R14: ffff8880b8643700 R15: 0000000000000001
FS: 0000000000000000(0000) GS:ffff888124de0000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000555570500a38 CR3: 000000000eb48000 CR4: 00000000003526f0
Call Trace:
<TASK>
on_each_cpu include/linux/smp.h:71 [inline]
smp_text_poke_sync_each_cpu arch/x86/kernel/alternative.c:2602 [inline]
smp_text_poke_batch_finish+0x5fd/0x1110 arch/x86/kernel/alternative.c:2812
arch_jump_label_transform_apply+0x1c/0x30 arch/x86/kernel/jump_label.c:146
static_key_enable_cpuslocked+0x128/0x240 kernel/jump_label.c:210
static_key_enable+0x1a/0x20 kernel/jump_label.c:223
toggle_allocation_gate+0xab/0x290 mm/kfence/core.c:902
process_one_work kernel/workqueue.c:3387 [inline]
process_scheduled_works+0xc3d/0x1630 kernel/workqueue.c:3470
worker_thread+0xa47/0xfb0 kernel/workqueue.c:3551
kthread+0x38b/0x480 kernel/kthread.c:436
ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [syzbot] [mm?] INFO: rcu detected stall in __mmap_complete
2026-08-29 20:56 ` syzbot
@ 2026-08-29 21:58 ` Andrew Morton
2026-08-29 23:44 ` syzbot
0 siblings, 1 reply; 4+ messages in thread
From: Andrew Morton @ 2026-08-29 21:58 UTC (permalink / raw)
To: syzbot
Cc: dvyukov, elver, glider, jannh, kasan-dev, liam.howlett,
linux-kernel, linux-mm, lorenzo.stoakes, netdev, pfalcato,
syzkaller-bugs, vbabka, Junjie Cao
On Sat, 29 Aug 2026 13:56:24 -0700 syzbot <syzbot+e4aa91d7f20c34417d4e@syzkaller.appspotmail.com> wrote:
> syzbot has found a reproducer for the following iss
>
> HEAD commit: 1b78070aaef6 Merge tag 'net-7.3-rc1' of git://git.kernel.o..
> git tree: net-next
> console output: https://syzkaller.appspot.com/x/log.txt?x=154d7d49580000
> kernel config: https://syzkaller.appspot.com/x/.config?x=5e4e3a0e188a497e
> dashboard link: https://syzkaller.appspot.com/bug?extid=e4aa91d7f20c34417d4e
> compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=134d7d49580000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1177ae25580000
>
> Downloadable assets:
> disk image: https://storage.googleapis.com/syzbot-assets/18856a03a9a3/disk-1b78070a.raw.xz
> vmlinux: https://storage.googleapis.com/syzbot-assets/cc2bc68d7ef4/vmlinux-1b78070a.xz
> kernel image: https://storage.googleapis.com/syzbot-assets/05a5e00f8f91/bzImage-1b78070a.xz
>
> IMPORTANT: if you fix the issue, please add the following tag to the commit:
> Reported-by: syzbot+e4aa91d7f20c34417d4e@syzkaller.appspotmail.com
#syz test: git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net-next.git main
From: Junjie Cao <junjie.cao@intel.com>
Subject: net/sched: taprio: catch up in bounded time when the schedule falls behind
Date: Thu, 20 Aug 2026 14:27:13 +0800
advance_sched() advances exactly one entry per hrtimer expiry. When the
operational schedule falls behind - the timer was delayed, the CPU was
starved, or the reference clock stepped forward - every elapsed entry is
replayed back to back from hrtimer context with current_entry_lock held,
and each replay rearms the timer with an expiry in the past. Once the
backlog is large enough the CPU never leaves timer processing and RCU
stalls follow. syzbot triggers this with schedules whose intervals are
shorter than the cost of servicing one expiry, so the backlog only ever
grows.
Skip complete cycles arithmetically and walk at most one cycle of entries
to land on the entry covering the current time. Gate close times and
budgets are still only computed for the entry landed on. An admin
schedule crossed by the jump is picked up by the existing
should_change_schedules() check on the recomputed end time. The walk is
capped at twice the entry count as a safeguard against degenerate
intervals; leftover backlog is then handled by the next expiry as today.
Link: https://lore.kernel.org/20260820062715.278124-2-junjie.cao@intel.com
Fixes: 5a781ccbd19e ("tc: Add support for configuring the taprio scheduler")
Signed-off-by: Junjie Cao <junjie.cao@intel.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
---
net/sched/sch_taprio.c | 56 ++++++++++++++++++++++++++++++++++++---
1 file changed, 53 insertions(+), 3 deletions(-)
--- a/net/sched/sch_taprio.c~net-sched-taprio-catch-up-in-bounded-time-when-the-schedule-falls-behind
+++ a/net/sched/sch_taprio.c
@@ -916,6 +916,51 @@ static bool should_change_schedules(cons
return false;
}
+/* The operational schedule fell behind, e.g. because the timer was delayed
+ * or the reference clock stepped forward. Advancing one entry per timer
+ * expiry would replay the whole backlog from hrtimer context, so skip
+ * complete cycles arithmetically and walk the remaining entries to land on
+ * the entry covering the current time.
+ */
+static void taprio_catch_up(struct sched_gate_list *oper,
+ struct sched_entry **next, ktime_t *next_start,
+ ktime_t *end_time, ktime_t now)
+{
+ int budget = 2 * oper->num_entries + 1;
+ struct sched_entry *entry = *next;
+ ktime_t start = *next_start;
+ ktime_t end = *end_time;
+ s64 behind = ktime_sub(now, end);
+
+ if (oper->cycle_time > 0 && behind >= oper->cycle_time) {
+ s64 jump = div64_s64(behind, oper->cycle_time) * oper->cycle_time;
+
+ start = ktime_add_ns(start, jump);
+ end = ktime_add_ns(end, jump);
+ oper->cycle_end_time = ktime_add_ns(oper->cycle_end_time, jump);
+ }
+
+ while (ktime_before(end, now) && --budget) {
+ if (list_is_last(&entry->list, &oper->entries) ||
+ ktime_compare(end, oper->cycle_end_time) == 0) {
+ entry = list_first_entry(&oper->entries,
+ struct sched_entry, list);
+ oper->cycle_end_time = ktime_add_ns(oper->cycle_end_time,
+ oper->cycle_time);
+ } else {
+ entry = list_next_entry(entry, list);
+ }
+
+ start = end;
+ end = ktime_add_ns(end, entry->interval);
+ end = min_t(ktime_t, end, oper->cycle_end_time);
+ }
+
+ *next = entry;
+ *next_start = start;
+ *end_time = end;
+}
+
static enum hrtimer_restart advance_sched(struct hrtimer *timer)
{
struct taprio_sched *q = container_of(timer, struct taprio_sched,
@@ -925,7 +970,7 @@ static enum hrtimer_restart advance_sche
int num_tc = netdev_get_num_tc(dev);
struct sched_entry *entry, *next;
struct Qdisc *sch = q->root;
- ktime_t end_time;
+ ktime_t end_time, next_start, now;
int tc;
spin_lock(&q->current_entry_lock);
@@ -961,14 +1006,19 @@ static enum hrtimer_restart advance_sche
next = list_next_entry(entry, list);
}
- end_time = ktime_add_ns(entry->end_time, next->interval);
+ next_start = entry->end_time;
+ end_time = ktime_add_ns(next_start, next->interval);
end_time = min_t(ktime_t, end_time, oper->cycle_end_time);
+ now = hrtimer_cb_get_time(timer);
+ if (unlikely(ktime_before(end_time, now)))
+ taprio_catch_up(oper, &next, &next_start, &end_time, now);
+
for (tc = 0; tc < num_tc; tc++) {
if (next->gate_duration[tc] == oper->cycle_time)
next->gate_close_time[tc] = KTIME_MAX;
else
- next->gate_close_time[tc] = ktime_add_ns(entry->end_time,
+ next->gate_close_time[tc] = ktime_add_ns(next_start,
next->gate_duration[tc]);
}
_
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [syzbot] [mm?] INFO: rcu detected stall in __mmap_complete
2026-08-29 21:58 ` Andrew Morton
@ 2026-08-29 23:44 ` syzbot
0 siblings, 0 replies; 4+ messages in thread
From: syzbot @ 2026-08-29 23:44 UTC (permalink / raw)
To: akpm, dvyukov, elver, glider, jannh, junjie.cao, kasan-dev,
liam.howlett, linux-kernel, linux-mm, lorenzo.stoakes, netdev,
pfalcato, syzkaller-bugs, vbabka
Hello,
syzbot has tested the proposed patch and the reproducer did not trigger any issue:
Reported-by: syzbot+e4aa91d7f20c34417d4e@syzkaller.appspotmail.com
Tested-by: syzbot+e4aa91d7f20c34417d4e@syzkaller.appspotmail.com
Tested on:
commit: 1b78070a Merge tag 'net-7.3-rc1' of git://git.kernel.o..
git tree: git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net-next.git main
console output: https://syzkaller.appspot.com/x/log.txt?x=14e12c15580000
kernel config: https://syzkaller.appspot.com/x/.config?x=5e4e3a0e188a497e
dashboard link: https://syzkaller.appspot.com/bug?extid=e4aa91d7f20c34417d4e
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
patch: https://syzkaller.appspot.com/x/patch.diff?x=11f37d49580000
Note: testing is done by a robot and is best-effort only.
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-08-29 23:44 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-01-04 22:55 [syzbot] [mm?] INFO: rcu detected stall in __mmap_complete syzbot
2026-08-29 20:56 ` syzbot
2026-08-29 21:58 ` Andrew Morton
2026-08-29 23:44 ` syzbot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®