From: Michal Pecio <michal.pecio@gmail.com>
To: Greg KH <gregkh@linuxfoundation.org>
Cc: syzbot <syzbot+fd7be5ad9795b7f29df3@syzkaller.appspotmail.com>,
dakr@kernel.org, driver-core@lists.linux.dev,
linux-kernel@vger.kernel.org, linux-usb@vger.kernel.org,
rafael@kernel.org, syzkaller-bugs@googlegroups.com
Subject: Re: [syzbot] [usb?] INFO: task hung in unbind_store
Date: Thu, 27 Aug 2026 11:00:06 +0200 [thread overview]
Message-ID: <20260827110006.66b07ea4.michal.pecio@gmail.com> (raw)
In-Reply-To: <2026082307-negligent-lusty-750a@gregkh>
On Sun, 23 Aug 2026 13:46:43 +0200, Greg KH wrote:
> On Sun, Aug 23, 2026 at 04:40:33AM -0700, syzbot wrote:
> > INFO: task syz.4.23:6285 blocked for more than 143 seconds.
> > Not tainted syzkaller #0
> > "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
> > task:syz.4.23 state:D stack:27592 pid:6285 tgid:6285 ppid:6213 task_flags:0x400140 flags:0x00080002
> > Call Trace:
> > <TASK>
> > context_switch kernel/sched/core.c:5510 [inline]
> > __schedule+0x17d4/0x5630 kernel/sched/core.c:7239
> > __schedule_loop kernel/sched/core.c:7316 [inline]
> > schedule+0x164/0x2b0 kernel/sched/core.c:7331
> > schedule_preempt_disabled+0x13/0x30 kernel/sched/core.c:7388
> > __mutex_lock_common kernel/locking/mutex.c:726 [inline]
> > __mutex_lock+0x7c1/0x1550 kernel/locking/mutex.c:821
> > device_lock include/linux/device.h:1104 [inline]
> > __device_driver_lock drivers/base/dd.c:1170 [inline]
> > device_release_driver_internal+0x93/0x880 drivers/base/dd.c:1369
> > unbind_store+0x1a1/0x1d0 drivers/base/bus.c:244
>
> Ok, I'm going to add a new TAINT flag for when unbind is written to as
> that is obviously not a normal operation and is only for debugging
> things by kernel developers. Adding loads of work-arounds in the kernel
> for this not-real-workload-path is just not required.
>
> If syzbot could stop hitting this path, that would be great, as it's a
> root-only thing for debugging and not something "real".
The root cause is probe() call of one USB driver (sisusbvga) taking
an eternity to complete on nonresponsive hardware, which is actually
a pretty real and not so uncommon annoying behavior.
And something is also wrong with those timeouts, because 20 times 5s
should still be less than 143 s. I asked Syzbot to try 500ms instead,
which ended up being over 3s in practice:
[ 566.662036][ T6636] usb 4-1: sisusb_send_bulk_msg()
[ 569.717341][ T6636] usb 4-1: sisusb_send_bulk_msg()
[ 572.777761][ T6636] usb 4-1: sisusb_send_bulk_msg()
[ 575.845365][ T6636] usb 4-1: sisusb_send_bulk_msg()
Same on my system, but patch below reduces the timeout to 500ms.
I have no idea what's happening here. Looks like a bug?
Is it known that jiffies are totally unreliable like that?
Regards,
Michal
--- a/drivers/usb/misc/sisusbvga/sisusbvga.c
+++ b/drivers/usb/misc/sisusbvga/sisusbvga.c
@@ -225,9 +225,13 @@ static int sisusb_bulkout_msg(struct sisusb_usb_data *sisusb, int index,
/* If OK, and if timeout > 0, wait for completion */
if ((retval == 0) && timeout) {
+ u64 time = ktime_get_ns();
+
wait_event_timeout(sisusb->wait_q,
(!(sisusb->urbstatus[index] & SU_URB_BUSY)),
timeout);
+ dev_info(&sisusb->sisusb_dev->dev, "sisusb_bulkout_msg() waited %lld\n", ktime_get_ns() - time);
+
if (sisusb->urbstatus[index] & SU_URB_BUSY) {
/* URB timed out... kill it and report error */
usb_kill_urb(urb);
next prev parent reply other threads:[~2026-08-27 9:00 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-23 11:40 [syzbot] [usb?] INFO: task hung in unbind_store syzbot
2026-08-23 11:46 ` Greg KH
2026-08-23 14:40 ` Alan Stern
2026-08-23 17:28 ` Greg KH
2026-08-24 0:29 ` Alan Stern
2026-08-27 9:00 ` Michal Pecio [this message]
2026-08-27 9:08 ` Michal Pecio
2026-08-26 14:51 ` syzbot
2026-08-27 6:02 ` Michal Pecio
2026-08-27 7:44 ` syzbot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260827110006.66b07ea4.michal.pecio@gmail.com \
--to=michal.pecio@gmail.com \
--cc=dakr@kernel.org \
--cc=driver-core@lists.linux.dev \
--cc=gregkh@linuxfoundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-usb@vger.kernel.org \
--cc=rafael@kernel.org \
--cc=syzbot+fd7be5ad9795b7f29df3@syzkaller.appspotmail.com \
--cc=syzkaller-bugs@googlegroups.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.