* [syzbot] [wireguard?] BUG: workqueue lockup in wg_packet_decrypt_worker
@ 2026-09-15 21:33 syzbot
2026-09-21 11:47 ` syzbot
0 siblings, 1 reply; 2+ messages in thread
From: syzbot @ 2026-09-15 21:33 UTC (permalink / raw)
To: Jason, andrew+netdev, davem, edumazet, kuba, linux-kernel,
netdev, pabeni, syzkaller-bugs, wireguard
Hello,
syzbot found the following issue on:
HEAD commit: 5445d6419962 arm64: Don't read GMID_EL1 when MTE is disabled
git tree: git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git for-kernelci
console output: https://syzkaller.appspot.com/x/log.txt?x=1114c2d1580000
kernel config: https://syzkaller.appspot.com/x/.config?x=56ed23170c168d4c
dashboard link: https://syzkaller.appspot.com/bug?extid=d0d2f1a65f45b319d25d
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
userspace arch: arm64
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/e8b70e3bd109/disk-5445d641.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/e5227e56ac93/vmlinux-5445d641.xz
kernel image: https://storage.googleapis.com/syzbot-assets/54905f78be59/Image-5445d641.gz.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+d0d2f1a65f45b319d25d@syzkaller.appspotmail.com
BUG: workqueue lockup - pool cpus=1 node=0 flags=0x0 nice=0 stuck for 45s!
Showing busy workqueues and worker pools:
workqueue events: flags=0x100
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=6 refcnt=7
pending: vmstat_shepherd, 2*psi_avgs_work, 3*ovs_dp_masks_rebalance
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=18 refcnt=19
pending: 2*psi_avgs_work, 3*ovs_dp_masks_rebalance, xfrm_state_gc_task, psi_avgs_work, delayed_vfree_work, 8*nsim_dev_hwstats_traffic_work, psi_avgs_work, free_obj_work
workqueue events_unbound: flags=0x2
pwq 8: cpus=0-1 flags=0x6 nice=0 active=20 refcnt=21
in-flight: 3055:cfg80211_wiphy_work for 75s cfg80211_wiphy_work ,54:nsim_dev_trap_report_work for 6s ,431:cfg80211_wiphy_work for 73s cfg80211_wiphy_work ,348:cfg80211_wiphy_work for 91s cfg80211_wiphy_work ,1617:cfg80211_wiphy_work for 76s cfg80211_wiphy_work ,12:cfg80211_wiphy_work for 93s cfg80211_wiphy_work ,1777:nsim_dev_trap_report_work for 11s ,40:cfg80211_wiphy_work for 92s cfg80211_wiphy_work ,3203:nsim_dev_trap_report_work for 1s
pending: nsim_dev_trap_report_work, toggle_allocation_gate, 2*nsim_dev_trap_report_work, cfg80211_wiphy_work
pwq 8: cpus=0-1 flags=0x6 nice=0 active=7 refcnt=8
in-flight: 13:linkwatch_event for 95s ,3020:cfg80211_wiphy_work for 89s cfg80211_wiphy_work ,3157:cfg80211_wiphy_work for 60s cfg80211_wiphy_work
pending: 2*nsim_dev_trap_report_work
workqueue events_power_efficient: flags=0x82
pwq 8: cpus=0-1 flags=0x6 nice=0 active=6 refcnt=7
in-flight: 1756:neigh_periodic_work for 6s ,284:reg_check_chans_work for 75s
pending: neigh_periodic_work, wg_ratelimiter_gc_entries, 2*neigh_managed_work
pwq 8: cpus=0-1 flags=0x6 nice=0 active=1 refcnt=2
pending: gc_worker
workqueue events_dfl_long: flags=0x2
pwq 8: cpus=0-1 flags=0x6 nice=0 active=6 refcnt=7
pending: 6*defense_work_handler
workqueue mm_percpu_wq: flags=0x108
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=1 refcnt=2
pending: vmstat_update
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=1 refcnt=2
pending: vmstat_update
workqueue ipv6_addrconf: flags=0x6000a
pwq 8: cpus=0-1 flags=0x6 nice=0 active=1 refcnt=9
in-flight: 59:addrconf_verify_work for 78s
inactive: 5*addrconf_verify_work
workqueue bat_events: flags=0x6000a
pwq 8: cpus=0-1 flags=0x6 nice=0 active=1 refcnt=45 MAYDAY
in-flight: 2855(RESCUER):batadv_tt_purge for 18s
inactive: batadv_tt_purge, batadv_mcast_mla_update, batadv_tt_purge, batadv_dat_purge, batadv_bla_periodic_work, batadv_dat_purge, 2*batadv_bla_periodic_work, batadv_dat_purge, batadv_mcast_mla_update, batadv_bla_periodic_work, batadv_dat_purge, 2*batadv_mcast_mla_update, 2*batadv_iv_send_outstanding_bat_ogm_packet, batadv_purge_orig, 3*batadv_iv_send_outstanding_bat_ogm_packet, 2*batadv_purge_orig, 5*batadv_iv_send_outstanding_bat_ogm_packet, batadv_purge_orig, batadv_iv_send_outstanding_bat_ogm_packet, batadv_mcast_mla_update, 4*batadv_iv_send_outstanding_bat_ogm_packet, batadv_purge_orig, batadv_bla_periodic_work, batadv_dat_purge, 2*batadv_tt_purge
workqueue wg-kex-wg0: flags=0x124
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=1 refcnt=2
pending: wg_packet_handshake_receive_worker
workqueue wg-kex-wg0: flags=0x6
pwq 8: cpus=0-1 flags=0x6 nice=0 active=1 refcnt=2
pending: wg_packet_handshake_send_worker
workqueue wg-crypt-wg0: flags=0x128
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=2 refcnt=3
pending: wg_packet_encrypt_worker, wg_packet_tx_worker
workqueue wg-kex-wg1: flags=0x124
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=2 refcnt=3
in-flight: 10:wg_packet_handshake_receive_worker for 46s
pending: wg_packet_handshake_receive_worker
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=1 refcnt=2
pending: wg_packet_handshake_receive_worker
workqueue wg-kex-wg1: flags=0x6
pwq 8: cpus=0-1 flags=0x6 nice=0 active=1 refcnt=2
pending: wg_packet_handshake_send_worker
workqueue wg-crypt-wg1: flags=0x128
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=3 refcnt=4
pending: wg_packet_encrypt_worker, wg_packet_tx_worker, wg_packet_decrypt_worker
workqueue wg-kex-wg0: flags=0x6
pwq 8: cpus=0-1 flags=0x6 nice=0 active=1 refcnt=2
in-flight: 3495:wg_packet_handshake_send_worker for 4s
workqueue wg-crypt-wg0: flags=0x128
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=2 refcnt=3
pending: wg_packet_tx_worker, wg_packet_encrypt_worker
workqueue wg-kex-wg2: flags=0x124
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=1 refcnt=2
in-flight: 4477:wg_packet_handshake_receive_worker for 12s
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=1 refcnt=2
pending: wg_packet_handshake_receive_worker
workqueue wg-kex-wg2: flags=0x6
pwq 8: cpus=0-1 flags=0x6 nice=0 active=2 refcnt=3
pending: 2*wg_packet_handshake_send_worker
workqueue wg-crypt-wg2: flags=0x128
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=3 refcnt=4
pending: wg_packet_encrypt_worker, wg_packet_decrypt_worker, wg_packet_tx_worker
workqueue wg-crypt-wg1: flags=0x128
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=2 refcnt=3
pending: wg_packet_encrypt_worker, wg_packet_tx_worker
workqueue wg-kex-wg2: flags=0x124
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=1 refcnt=2
in-flight: 9:wg_packet_handshake_receive_worker for 20s
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=1 refcnt=2
pending: wg_packet_handshake_receive_worker
workqueue wg-crypt-wg2: flags=0x128
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=4 refcnt=5
in-flight: 4889:wg_packet_decrypt_worker for 45s
pending: wg_packet_tx_worker, wg_packet_encrypt_worker, wg_packet_decrypt_worker
workqueue hci0: flags=0x20012
pwq 9: cpus=0-1 node=0 flags=0x4 nice=-20 active=1 refcnt=4
in-flight: 4723:hci_cmd_sync_work for 84s
workqueue wg-kex-wg0: flags=0x124
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=1 refcnt=2
pending: wg_packet_handshake_receive_worker
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=1 refcnt=2
pending: wg_packet_handshake_receive_worker
workqueue wg-crypt-wg0: flags=0x128
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=3 refcnt=4
in-flight: 24:wg_packet_tx_worker for 45s
pending: wg_packet_encrypt_worker, wg_packet_tx_worker
workqueue wg-kex-wg1: flags=0x124
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=1 refcnt=2
in-flight: 4799:wg_packet_handshake_receive_worker for 17s
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=1 refcnt=2
pending: wg_packet_handshake_receive_worker
workqueue wg-crypt-wg1: flags=0x128
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=1 refcnt=2
pending: wg_packet_encrypt_worker
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=3 refcnt=4
pending: wg_packet_encrypt_worker, wg_packet_tx_worker, wg_packet_decrypt_worker
workqueue wg-kex-wg2: flags=0x124
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=1 refcnt=2
pending: wg_packet_handshake_receive_worker
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=1 refcnt=2
pending: wg_packet_handshake_receive_worker
workqueue wg-kex-wg2: flags=0x6
pwq 8: cpus=0-1 flags=0x6 nice=0 active=2 refcnt=3
pending: 2*wg_packet_handshake_send_worker
workqueue wg-crypt-wg2: flags=0x128
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=3 refcnt=4
pending: wg_packet_decrypt_worker, wg_packet_encrypt_worker, wg_packet_tx_worker
workqueue hci3: flags=0x20012
pwq 9: cpus=0-1 node=0 flags=0x4 nice=-20 active=1 refcnt=4
in-flight: 4726:hci_cmd_sync_work for 78s
workqueue wg-kex-wg0: flags=0x124
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=1 refcnt=2
in-flight: 4840:wg_packet_handshake_receive_worker for 11s
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=1 refcnt=2
pending: wg_packet_handshake_receive_worker
workqueue wg-crypt-wg0: flags=0x128
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=2 refcnt=3
pending: wg_packet_tx_worker, wg_packet_encrypt_worker
workqueue wg-kex-wg1: flags=0x124
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=1 refcnt=2
in-flight: 4806:wg_packet_handshake_receive_worker for 19s
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=1 refcnt=2
pending: wg_packet_handshake_receive_worker
workqueue wg-crypt-wg1: flags=0x128
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=3 refcnt=4
pending: wg_packet_encrypt_worker, wg_packet_tx_worker, wg_packet_decrypt_worker
workqueue wg-kex-wg2: flags=0x124
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=1 refcnt=2
in-flight: 4827:wg_packet_handshake_receive_worker for 6s
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=1 refcnt=2
pending: wg_packet_handshake_receive_worker
workqueue wg-kex-wg2: flags=0x6
pwq 8: cpus=0-1 flags=0x6 nice=0 active=1 refcnt=2
pending: wg_packet_handshake_send_worker
workqueue wg-crypt-wg2: flags=0x128
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=1 refcnt=2
pending: wg_packet_decrypt_worker
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=3 refcnt=4
pending: wg_packet_decrypt_worker, wg_packet_encrypt_worker, wg_packet_tx_worker
workqueue wg-kex-wg0: flags=0x124
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=1 refcnt=2
pending: wg_packet_handshake_receive_worker
workqueue wg-kex-wg0: flags=0x6
pwq 8: cpus=0-1 flags=0x6 nice=0 active=1 refcnt=2
pending: wg_packet_handshake_send_worker
workqueue wg-crypt-wg0: flags=0x128
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=2 refcnt=3
pending: wg_packet_encrypt_worker, wg_packet_tx_worker
workqueue wg-crypt-wg1: flags=0x128
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=3 refcnt=4
pending: wg_packet_encrypt_worker, wg_packet_tx_worker, wg_packet_decrypt_worker
workqueue wg-kex-wg2: flags=0x124
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=1 refcnt=2
in-flight: 1159:wg_packet_handshake_receive_worker for 23s
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=1 refcnt=2
pending: wg_packet_handshake_receive_worker
workqueue wg-crypt-wg2: flags=0x128
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=3 refcnt=4
pending: wg_packet_tx_worker, wg_packet_decrypt_worker, wg_packet_encrypt_worker
pool 2: cpus=0 node=0 flags=0x0 nice=0 hung=6s workers=10 idle: 4820 4807
pool 6: cpus=1 node=0 flags=0x0 nice=0 hung=45s workers=8 idle: 5732 5459 26 4798 868 5730
pool 8: cpus=0-1 flags=0x6 nice=0 hung=1s workers=17 manager: 6529
pool 9: cpus=0-1 node=0 flags=0x4 nice=-20 hung=0s workers=8 idle: 4721 4713 4718 4717 50 4720
Showing backtraces of busy workers in stalled worker pools:
pool 6:
task:kworker/1:4 state:R running task stack:0 pid:4889 tgid:4889 ppid:2 task_flags:0x4208060 flags:0x00000010
Workqueue: wg-crypt-wg2 wg_packet_decrypt_worker
Call trace:
__switch_to+0x2b4/0x6e4 arch/arm64/kernel/process.c:775 (T)
context_switch kernel/sched/core.c:5520 [inline]
__schedule+0x1370/0x2d80 kernel/sched/core.c:7270
preempt_schedule_common+0xd4/0x190 kernel/sched/core.c:7449
preempt_schedule kernel/sched/core.c:7473 [inline]
class_preempt_destructor include/linux/preempt.h:500 [inline]
try_to_wake_up+0x5f8/0xdc4 kernel/sched/core.c:4432
wake_up_process+0x18/0x24 kernel/sched/core.c:4557
process_one_work kernel/workqueue.c:3355 [inline]
process_scheduled_works+0x744/0x1250 kernel/workqueue.c:3470
worker_thread+0x798/0xbd0 kernel/workqueue.c:3551
kthread+0x304/0x3d4 kernel/kthread.c:436
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:838
pool 6:
task:kworker/1:0 state:R running task stack:0 pid:24 tgid:24 ppid:2 task_flags:0x4208060 flags:0x00000010
Workqueue: wg-crypt-wg0 wg_packet_tx_worker
Call trace:
__switch_to+0x2b4/0x6e4 arch/arm64/kernel/process.c:775 (T)
context_switch kernel/sched/core.c:5520 [inline]
__schedule+0x1370/0x2d80 kernel/sched/core.c:7270
preempt_schedule_common+0xd4/0x190 kernel/sched/core.c:7449
preempt_schedule+0x60/0x78 kernel/sched/core.c:7473
__local_bh_enable_ip+0x20c/0x35c kernel/softirq.c:480
local_bh_enable include/linux/bottom_half.h:33 [inline]
rcu_read_unlock_bh include/linux/rcupdate.h:923 [inline]
keep_key_fresh drivers/net/wireguard/send.c:135 [inline]
wg_packet_create_data_done drivers/net/wireguard/send.c:259 [inline]
wg_packet_tx_worker+0x520/0x75c drivers/net/wireguard/send.c:276
process_one_work kernel/workqueue.c:3387 [inline]
process_scheduled_works+0x91c/0x1250 kernel/workqueue.c:3470
worker_thread+0x798/0xbd0 kernel/workqueue.c:3551
kthread+0x304/0x3d4 kernel/kthread.c:436
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:838
---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [syzbot] [wireguard?] BUG: workqueue lockup in wg_packet_decrypt_worker
2026-09-15 21:33 [syzbot] [wireguard?] BUG: workqueue lockup in wg_packet_decrypt_worker syzbot
@ 2026-09-21 11:47 ` syzbot
0 siblings, 0 replies; 2+ messages in thread
From: syzbot @ 2026-09-21 11:47 UTC (permalink / raw)
To: Jason, andrew+netdev, andrew, davem, edumazet, jason, kuba,
linux-kernel, netdev, pabeni, syzkaller-bugs, wireguard
syzbot has found a reproducer for the following issue on:
HEAD commit: 38872197cae2 Merge branch 'for-next/fixes' into for-kernelci
git tree: git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git for-kernelci
console output: https://syzkaller.appspot.com/x/log.txt?x=17567005580000
kernel config: https://syzkaller.appspot.com/x/.config?x=56ed23170c168d4c
dashboard link: https://syzkaller.appspot.com/bug?extid=d0d2f1a65f45b319d25d
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1606a805580000
Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/c5963fdd6790/disk-38872197.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/a8c2cab00c45/vmlinux-38872197.xz
kernel image: https://storage.googleapis.com/syzbot-assets/bde15d173380/Image-38872197.gz.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+d0d2f1a65f45b319d25d@syzkaller.appspotmail.com
BUG: workqueue lockup - pool cpus=0 node=0 flags=0x0 nice=0 stuck for 38s!
Showing busy workqueues and worker pools:
workqueue events: flags=0x100
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=16 refcnt=17
in-flight: 4858:nsim_fib_event_work for 39s ,4830:nsim_fib_event_work for 40s
pending: 3*nsim_dev_hwstats_traffic_work, 2*psi_avgs_work, vmstat_shepherd, rht_deferred_worker, free_obj_work, 3*ovs_dp_masks_rebalance, drm_fb_helper_damage_work, 2*nsim_fib_event_work
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=11 refcnt=12
in-flight: 869:nsim_fib_event_work for 44s nsim_fib_event_work ,4806:nsim_fib_event_work for 41s nsim_fib_event_work
pending: psi_avgs_work, 6*ovs_dp_masks_rebalance
workqueue events_unbound: flags=0x2
pwq 8: cpus=0-1 flags=0x6 nice=0 active=22 refcnt=23
in-flight: 1472:cfg80211_wiphy_work for 41s cfg80211_wiphy_work ,1438:cfg80211_wiphy_work for 43s cfg80211_wiphy_work ,1295:cfg80211_wiphy_work for 43s cfg80211_wiphy_work ,14:cfg80211_wiphy_work for 36s ,79:cfg80211_wiphy_work for 43s cfg80211_wiphy_work ,1486:cfg80211_wiphy_work for 42s cfg80211_wiphy_work ,12:cfg80211_wiphy_work for 39s
pending: 2*cfg80211_wiphy_work, nsim_dev_trap_report_work, toggle_allocation_gate, macvlan_process_broadcast, 3*nsim_dev_trap_report_work, flush_memcg_stats_dwork, macvlan_process_broadcast
pwq 8: cpus=0-1 flags=0x6 nice=0 active=7 refcnt=8
in-flight: 1234:cfg80211_wiphy_work for 43s cfg80211_wiphy_work
pending: macvlan_process_broadcast, crng_reseed, 3*macvlan_process_broadcast
workqueue events_power_efficient: flags=0x82
pwq 8: cpus=0-1 flags=0x6 nice=0 active=5 refcnt=6
in-flight: 50:neigh_periodic_work for 33s
pending: neigh_managed_work, fb_flashcursor, wg_ratelimiter_gc_entries, neigh_managed_work
pwq 8: cpus=0-1 flags=0x6 nice=0 active=2 refcnt=3
pending: neigh_periodic_work, do_cache_clean
workqueue events_dfl_long: flags=0x2
pwq 8: cpus=0-1 flags=0x6 nice=0 active=9 refcnt=10
pending: 9*defense_work_handler
workqueue netns: flags=0x6000a
pwq 8: cpus=0-1 flags=0x6 nice=0 active=1 refcnt=4
in-flight: 1183:cleanup_net for 45s
workqueue mm_percpu_wq: flags=0x108
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=1 refcnt=2
pending: vmstat_update
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=1 refcnt=2
pending: vmstat_update
workqueue mld: flags=0x40108
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=1 refcnt=73
pending: mld_ifc_work
inactive: 2*mld_ifc_work, mld_dad_work, mld_ifc_work, mld_dad_work, mld_ifc_work, mld_dad_work, 4*mld_ifc_work, 2*mld_dad_work, mld_ifc_work, mld_dad_work, 3*mld_ifc_work, 2*mld_dad_work, 5*mld_ifc_work, mld_dad_work, mld_ifc_work, mld_dad_work, 3*mld_ifc_work, 3*mld_dad_work, mld_ifc_work, 2*mld_dad_work, 3*mld_ifc_work, mld_dad_work, 2*mld_ifc_work, mld_dad_work, 6*mld_ifc_work, mld_dad_work, mld_ifc_work, 2*mld_dad_work, 3*mld_ifc_work, 2*mld_dad_work, mld_ifc_work, 2*mld_dad_work, mld_ifc_work, 8*mld_dad_work
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=1 refcnt=95
pending: mld_ifc_work
inactive: mld_ifc_work, mld_dad_work, mld_ifc_work, mld_dad_work, 9*mld_ifc_work, 2*mld_dad_work, 6*mld_ifc_work, mld_dad_work, 4*mld_ifc_work, mld_dad_work, 4*mld_ifc_work, 62*mld_dad_work
workqueue ipv6_addrconf: flags=0x6000a
pwq 8: cpus=0-1 flags=0x6 nice=0 active=1 refcnt=178 MAYDAY
in-flight: 2825(RESCUER):addrconf_dad_work for 0s
pending: mayday_cursor_func
inactive: 172*addrconf_dad_work
workqueue bat_events: flags=0x6000a
pwq 8: cpus=0-1 flags=0x6 nice=0 active=1 refcnt=51 MAYDAY
in-flight: 2857(RESCUER):batadv_tt_purge for 11s
pending: mayday_cursor_func
inactive: 4*batadv_tt_purge, batadv_dat_purge, batadv_bla_periodic_work, 6*batadv_mcast_mla_update, 5*batadv_iv_send_outstanding_bat_ogm_packet, batadv_dat_purge, batadv_bla_periodic_work, batadv_dat_purge, batadv_bla_periodic_work, batadv_dat_purge, batadv_bla_periodic_work, batadv_dat_purge, batadv_bla_periodic_work, batadv_dat_purge, batadv_bla_periodic_work, 5*batadv_iv_send_outstanding_bat_ogm_packet, 6*batadv_purge_orig, 6*batadv_iv_send_outstanding_bat_ogm_packet, batadv_tt_purge
workqueue wg-kex-wg0: flags=0x6
pwq 8: cpus=0-1 flags=0x6 nice=0 active=1 refcnt=2
pending: wg_packet_handshake_send_worker
workqueue wg-crypt-wg0: flags=0x128
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=3 refcnt=4
pending: wg_packet_encrypt_worker, wg_packet_tx_worker, wg_packet_decrypt_worker
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=2 refcnt=3
pending: wg_packet_decrypt_worker, wg_packet_encrypt_worker
workqueue wg-crypt-wg1: flags=0x128
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=4 refcnt=5
in-flight: 9:wg_packet_decrypt_worker for 40s wg_packet_decrypt_worker
pending: wg_packet_encrypt_worker, wg_packet_tx_worker
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=3 refcnt=4
pending: wg_packet_decrypt_worker, wg_packet_tx_worker, wg_packet_encrypt_worker
workqueue wg-kex-wg2: flags=0x6
pwq 8: cpus=0-1 flags=0x6 nice=0 active=1 refcnt=2
pending: wg_packet_handshake_send_worker
workqueue wg-crypt-wg2: flags=0x128
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=4 refcnt=5
in-flight: 10:wg_packet_decrypt_worker for 41s wg_packet_decrypt_worker
pending: wg_packet_encrypt_worker, wg_packet_tx_worker
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=2 refcnt=3
pending: wg_packet_tx_worker, wg_packet_encrypt_worker
workqueue wg-kex-wg0: flags=0x124
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=1 refcnt=2
pending: wg_packet_handshake_receive_worker
workqueue wg-kex-wg0: flags=0x6
pwq 8: cpus=0-1 flags=0x6 nice=0 active=1 refcnt=2
pending: wg_packet_handshake_send_worker
workqueue wg-crypt-wg0: flags=0x128
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=2 refcnt=3
pending: wg_packet_decrypt_worker, wg_packet_tx_worker
workqueue wg-kex-wg1: flags=0x124
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=1 refcnt=2
pending: wg_packet_handshake_receive_worker
workqueue wg-kex-wg1: flags=0x6
pwq 8: cpus=0-1 flags=0x6 nice=0 active=1 refcnt=2
pending: wg_packet_handshake_send_worker
workqueue wg-crypt-wg1: flags=0x128
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=3 refcnt=4
in-flight: 1115:wg_packet_decrypt_worker for 41s wg_packet_decrypt_worker
pending: wg_packet_encrypt_worker
workqueue wg-kex-wg2: flags=0x124
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=1 refcnt=2
in-flight: 4356:wg_packet_handshake_receive_worker for 41s
workqueue wg-kex-wg2: flags=0x6
pwq 8: cpus=0-1 flags=0x6 nice=0 active=2 refcnt=3
pending: 2*wg_packet_handshake_send_worker
workqueue wg-crypt-wg2: flags=0x128
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=2 refcnt=3
pending: wg_packet_encrypt_worker, wg_packet_tx_worker
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=1 refcnt=2
pending: wg_packet_tx_worker
workqueue wg-kex-wg0: flags=0x6
pwq 8: cpus=0-1 flags=0x6 nice=0 active=2 refcnt=3
pending: 2*wg_packet_handshake_send_worker
workqueue wg-crypt-wg0: flags=0x128
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=2 refcnt=3
pending: wg_packet_encrypt_worker, wg_packet_tx_worker
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=2 refcnt=3
pending: wg_packet_tx_worker, wg_packet_encrypt_worker
workqueue wg-kex-wg1: flags=0x124
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=1 refcnt=2
pending: wg_packet_handshake_receive_worker
workqueue wg-crypt-wg1: flags=0x128
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=2 refcnt=3
pending: wg_packet_encrypt_worker, wg_packet_tx_worker
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=2 refcnt=3
pending: wg_packet_decrypt_worker, wg_packet_tx_worker
workqueue wg-kex-wg2: flags=0x124
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=1 refcnt=2
pending: wg_packet_handshake_receive_worker
workqueue wg-crypt-wg2: flags=0x128
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=2 refcnt=3
pending: wg_packet_encrypt_worker, wg_packet_tx_worker
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=2 refcnt=3
pending: wg_packet_tx_worker, wg_packet_encrypt_worker
workqueue wg-kex-wg0: flags=0x124
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=1 refcnt=2
pending: wg_packet_handshake_receive_worker
workqueue wg-kex-wg0: flags=0x6
pwq 8: cpus=0-1 flags=0x6 nice=0 active=1 refcnt=2
pending: wg_packet_handshake_send_worker
workqueue wg-crypt-wg0: flags=0x128
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=2 refcnt=3
pending: wg_packet_tx_worker, wg_packet_encrypt_worker
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=1 refcnt=2
pending: wg_packet_tx_worker
workqueue wg-kex-wg1: flags=0x6
pwq 8: cpus=0-1 flags=0x6 nice=0 active=1 refcnt=2
pending: wg_packet_handshake_send_worker
workqueue wg-crypt-wg1: flags=0x128
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=3 refcnt=4
pending: wg_packet_decrypt_worker, wg_packet_encrypt_worker, wg_packet_tx_worker
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=2 refcnt=3
pending: wg_packet_tx_worker, wg_packet_encrypt_worker
workqueue wg-kex-wg2: flags=0x6
pwq 8: cpus=0-1 flags=0x6 nice=0 active=1 refcnt=2
in-flight: 40:wg_packet_handshake_send_worker for 6s
workqueue wg-crypt-wg2: flags=0x128
pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=2 refcnt=3
pending: wg_packet_encrypt_worker, wg_packet_tx_worker
pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=2 refcnt=3
pending: wg_packet_tx_worker, wg_packet_encrypt_worker
pool 2: cpus=0 node=0 flags=0x0 nice=0 hung=38s workers=8 idle: 5002 4997
pool 6: cpus=1 node=0 flags=0x0 nice=0 hung=21s workers=7 idle: 26 24 4967 5000 4999
pool 8: cpus=0-1 flags=0x6 nice=0 hung=0s workers=12 manager: 5001
Showing backtraces of busy workers in stalled worker pools:
pool 2:
task:kworker/0:1 state:R running task stack:0 pid:10 tgid:10 ppid:2 task_flags:0x4208060 flags:0x00000010
Workqueue: wg-crypt-wg2 wg_packet_decrypt_worker
Call trace:
__switch_to+0x2b4/0x6e4 arch/arm64/kernel/process.c:775 (T)
context_switch kernel/sched/core.c:5526 [inline]
__schedule+0x1370/0x2d80 kernel/sched/core.c:7277
preempt_schedule_common+0xd4/0x190 kernel/sched/core.c:7456
preempt_schedule+0x60/0x78 kernel/sched/core.c:7480
__kunmap_atomic include/linux/highmem-internal.h:247 [inline]
sg_miter_stop+0x220/0x2cc lib/scatterlist.c:941
chacha20poly1305_crypt_sg_inplace+0x75c/0xc30 lib/crypto/chacha20poly1305.c:319
chacha20poly1305_decrypt_sg_inplace+0x6c/0x94 lib/crypto/chacha20poly1305.c:353
decrypt_packet drivers/net/wireguard/receive.c:278 [inline]
wg_packet_decrypt_worker+0x490/0xa00 drivers/net/wireguard/receive.c:501
process_one_work kernel/workqueue.c:3396 [inline]
process_scheduled_works+0x91c/0x1250 kernel/workqueue.c:3479
worker_thread+0x798/0xbd0 kernel/workqueue.c:3560
kthread+0x304/0x3d4 kernel/kthread.c:436
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:838
pool 2:
task:kworker/0:5 state:R running task stack:0 pid:4858 tgid:4858 ppid:2 task_flags:0x4208060 flags:0x00000010
Workqueue: events nsim_fib_event_work
Call trace:
__switch_to+0x2b4/0x6e4 arch/arm64/kernel/process.c:775 (T)
context_switch kernel/sched/core.c:5526 [inline]
__schedule+0x1370/0x2d80 kernel/sched/core.c:7277
__schedule_loop kernel/sched/core.c:7354 [inline]
schedule+0x13c/0x20c kernel/sched/core.c:7369
schedule_timeout+0x13c/0x28c kernel/time/sleep_timeout.c:99
schedule_timeout_uninterruptible+0x78/0xbc kernel/time/sleep_timeout.c:158
msleep+0x3c/0x68 kernel/time/sleep_timeout.c:318
nsim_fib6_rt_add drivers/net/netdevsim/fib.c:693 [inline]
nsim_fib6_rt_insert drivers/net/netdevsim/fib.c:759 [inline]
nsim_fib6_event drivers/net/netdevsim/fib.c:856 [inline]
nsim_fib_event+0x57a0/0x60c4 drivers/net/netdevsim/fib.c:889
nsim_fib_event_work+0x1d8/0x320 drivers/net/netdevsim/fib.c:1493
process_one_work kernel/workqueue.c:3396 [inline]
process_scheduled_works+0x91c/0x1250 kernel/workqueue.c:3479
worker_thread+0x798/0xbd0 kernel/workqueue.c:3560
kthread+0x304/0x3d4 kernel/kthread.c:436
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:838
pool 2:
task:kworker/0:4 state:R running task stack:0 pid:4830 tgid:4830 ppid:2 task_flags:0x4208060 flags:0x00000010
Workqueue: events nsim_fib_event_work
Call trace:
__switch_to+0x2b4/0x6e4 arch/arm64/kernel/process.c:775 (T)
context_switch kernel/sched/core.c:5526 [inline]
__schedule+0x1370/0x2d80 kernel/sched/core.c:7277
preempt_schedule_common+0xd4/0x190 kernel/sched/core.c:7456
preempt_schedule+0x60/0x78 kernel/sched/core.c:7480
irq_work_queue+0xa0/0xa4 kernel/irq_work.c:125
__rhashtable_insert_fast include/linux/rhashtable.h:852 [inline]
rhashtable_insert_fast include/linux/rhashtable.h:886 [inline]
nsim_fib6_rt_add drivers/net/netdevsim/fib.c:686 [inline]
nsim_fib6_rt_insert drivers/net/netdevsim/fib.c:759 [inline]
nsim_fib6_event drivers/net/netdevsim/fib.c:856 [inline]
nsim_fib_event+0x4f5c/0x60c4 drivers/net/netdevsim/fib.c:889
nsim_fib_event_work+0x1d8/0x320 drivers/net/netdevsim/fib.c:1493
process_one_work kernel/workqueue.c:3396 [inline]
process_scheduled_works+0x91c/0x1250 kernel/workqueue.c:3479
worker_thread+0x798/0xbd0 kernel/workqueue.c:3560
kthread+0x304/0x3d4 kernel/kthread.c:436
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:838
pool 2:
task:kworker/0:3 state:R running task stack:0 pid:4356 tgid:4356 ppid:2 task_flags:0x4208060 flags:0x00000010
Workqueue: wg-kex-wg2 wg_packet_handshake_receive_worker
Call trace:
__switch_to+0x2b4/0x6e4 arch/arm64/kernel/process.c:775 (T)
context_switch kernel/sched/core.c:5526 [inline]
__schedule+0x1370/0x2d80 kernel/sched/core.c:7277
preempt_schedule_common+0xd4/0x190 kernel/sched/core.c:7456
preempt_schedule+0x60/0x78 kernel/sched/core.c:7480
__local_bh_enable_ip+0x20c/0x35c kernel/softirq.c:480
local_bh_enable include/linux/bottom_half.h:33 [inline]
rcu_read_unlock_bh include/linux/rcupdate.h:923 [inline]
mod_peer_timer+0x21c/0x25c drivers/net/wireguard/timers.c:38
wg_timers_session_derived+0x5c/0x6c drivers/net/wireguard/timers.c:208
wg_receive_handshake_packet drivers/net/wireguard/receive.c:178 [inline]
wg_packet_handshake_receive_worker+0x5b8/0xcf8 drivers/net/wireguard/receive.c:213
process_one_work kernel/workqueue.c:3396 [inline]
process_scheduled_works+0x91c/0x1250 kernel/workqueue.c:3479
worker_thread+0x798/0xbd0 kernel/workqueue.c:3560
kthread+0x304/0x3d4 kernel/kthread.c:436
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:838
pool 2:
task:kworker/0:0 state:R running task stack:0 pid:9 tgid:9 ppid:2 task_flags:0x4208060 flags:0x00000010
Workqueue: wg-crypt-wg1 wg_packet_decrypt_worker
Call trace:
__switch_to+0x2b4/0x6e4 arch/arm64/kernel/process.c:775 (T)
context_switch kernel/sched/core.c:5526 [inline]
__schedule+0x1370/0x2d80 kernel/sched/core.c:7277
preempt_schedule_common+0xd4/0x190 kernel/sched/core.c:7456
preempt_schedule+0x60/0x78 kernel/sched/core.c:7480
__local_bh_enable_ip+0x20c/0x35c kernel/softirq.c:480
__raw_spin_unlock_bh include/linux/spinlock_api_smp.h:237 [inline]
_raw_spin_unlock_bh+0x3c/0x4c kernel/locking/spinlock.c:245
spin_unlock_bh include/linux/spinlock.h:407 [inline]
ptr_ring_consume_bh include/linux/ptr_ring.h:399 [inline]
wg_packet_decrypt_worker+0x980/0xa00 drivers/net/wireguard/receive.c:499
process_one_work kernel/workqueue.c:3396 [inline]
process_scheduled_works+0x91c/0x1250 kernel/workqueue.c:3479
worker_thread+0x798/0xbd0 kernel/workqueue.c:3560
kthread+0x304/0x3d4 kernel/kthread.c:436
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:838
pool 2:
---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-21 11:47 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-15 21:33 [syzbot] [wireguard?] BUG: workqueue lockup in wg_packet_decrypt_worker syzbot
2026-09-21 11:47 ` syzbot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®