From: syzbot <syzbot+1cf303af03cf30b1275a@syzkaller.appspotmail.com>
To: dakr@kernel.org, driver-core@lists.linux.dev,
gregkh@linuxfoundation.org, linux-kernel@vger.kernel.org,
rafael@kernel.org, syzkaller-bugs@googlegroups.com
Subject: [syzbot] [kernel?] INFO: task hung in nsim_bus_dev_del
Date: Fri, 15 May 2026 17:11:33 -0700 [thread overview]
Message-ID: <6a07b635.170a0220.df43.0000.GAE@google.com> (raw)
Hello,
syzbot found the following issue on:
HEAD commit: 5cbb61bf4168 arm64/fpsimd: ptrace: zero target's fpsimd_st..
git tree: git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git for-kernelci
console output: https://syzkaller.appspot.com/x/log.txt?x=165db76c580000
kernel config: https://syzkaller.appspot.com/x/.config?x=a834c6344141a58b
dashboard link: https://syzkaller.appspot.com/bug?extid=1cf303af03cf30b1275a
compiler: Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=12c4d56a580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=115db76c580000
Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/04156ec16593/disk-5cbb61bf.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/6bfa041e2c79/vmlinux-5cbb61bf.xz
kernel image: https://storage.googleapis.com/syzbot-assets/a92d82d8a79e/Image-5cbb61bf.gz.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+1cf303af03cf30b1275a@syzkaller.appspotmail.com
INFO: task syz-executor:4797 blocked for more than 143 seconds.
Not tainted syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:syz-executor state:D stack:0 pid:4797 tgid:4797 ppid:4796 task_flags:0x400140 flags:0x00800000
Call trace:
__switch_to+0x2b0/0x6e0 arch/arm64/kernel/process.c:810 (T)
context_switch kernel/sched/core.c:5387 [inline]
__schedule+0x1b74/0x2d24 kernel/sched/core.c:7188
__schedule_loop kernel/sched/core.c:7267 [inline]
schedule+0xa4/0x140 kernel/sched/core.c:7282
schedule_preempt_disabled+0x18/0x2c kernel/sched/core.c:7339
__mutex_lock_common+0x98c/0x20f4 kernel/locking/mutex.c:726
__mutex_lock kernel/locking/mutex.c:820 [inline]
mutex_lock_nested+0x2c/0x38 kernel/locking/mutex.c:873
device_lock include/linux/device.h:1040 [inline]
device_del+0xa0/0x710 drivers/base/core.c:3857
device_unregister+0x2c/0xf0 drivers/base/core.c:3936
nsim_bus_dev_del+0x60/0x88 drivers/net/netdevsim/bus.c:491
del_device_store+0x248/0x2d0 drivers/net/netdevsim/bus.c:244
bus_attr_store+0x80/0xa4 drivers/base/bus.c:172
sysfs_kf_write+0xe0/0x108 fs/sysfs/file.c:142
kernfs_fop_write_iter+0x264/0x3c0 fs/kernfs/file.c:352
new_sync_write fs/read_write.c:595 [inline]
vfs_write+0x52c/0xa14 fs/read_write.c:688
ksys_write+0x12c/0x224 fs/read_write.c:740
__do_sys_write fs/read_write.c:751 [inline]
__se_sys_write fs/read_write.c:748 [inline]
__arm64_sys_write+0x7c/0x90 fs/read_write.c:748
__invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]
invoke_syscall+0x98/0x244 arch/arm64/kernel/syscall.c:49
el0_svc_common+0xe8/0x23c arch/arm64/kernel/syscall.c:121
do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:140
el0_svc+0x60/0x25c arch/arm64/kernel/entry-common.c:723
el0t_64_sync_handler+0x48/0x148 arch/arm64/kernel/entry-common.c:742
el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:594
INFO: task syz-executor:4805 blocked for more than 143 seconds.
Not tainted syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:syz-executor state:D stack:0 pid:4805 tgid:4805 ppid:4801 task_flags:0x400140 flags:0x00800000
Call trace:
__switch_to+0x2b0/0x6e0 arch/arm64/kernel/process.c:810 (T)
context_switch kernel/sched/core.c:5387 [inline]
__schedule+0x1b74/0x2d24 kernel/sched/core.c:7188
__schedule_loop kernel/sched/core.c:7267 [inline]
schedule+0xa4/0x140 kernel/sched/core.c:7282
schedule_preempt_disabled+0x18/0x2c kernel/sched/core.c:7339
__mutex_lock_common+0x98c/0x20f4 kernel/locking/mutex.c:726
__mutex_lock kernel/locking/mutex.c:820 [inline]
mutex_lock_nested+0x2c/0x38 kernel/locking/mutex.c:873
del_device_store+0xd8/0x2d0 drivers/net/netdevsim/bus.c:234
bus_attr_store+0x80/0xa4 drivers/base/bus.c:172
sysfs_kf_write+0xe0/0x108 fs/sysfs/file.c:142
kernfs_fop_write_iter+0x264/0x3c0 fs/kernfs/file.c:352
new_sync_write fs/read_write.c:595 [inline]
vfs_write+0x52c/0xa14 fs/read_write.c:688
ksys_write+0x12c/0x224 fs/read_write.c:740
__do_sys_write fs/read_write.c:751 [inline]
__se_sys_write fs/read_write.c:748 [inline]
__arm64_sys_write+0x7c/0x90 fs/read_write.c:748
__invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]
invoke_syscall+0x98/0x244 arch/arm64/kernel/syscall.c:49
el0_svc_common+0xe8/0x23c arch/arm64/kernel/syscall.c:121
do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:140
el0_svc+0x60/0x25c arch/arm64/kernel/entry-common.c:723
el0t_64_sync_handler+0x48/0x148 arch/arm64/kernel/entry-common.c:742
el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:594
INFO: task syz-executor:4809 blocked for more than 143 seconds.
Not tainted syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:syz-executor state:D stack:0 pid:4809 tgid:4809 ppid:1 task_flags:0x400140 flags:0x00800001
Call trace:
__switch_to+0x2b0/0x6e0 arch/arm64/kernel/process.c:810 (T)
context_switch kernel/sched/core.c:5387 [inline]
__schedule+0x1b74/0x2d24 kernel/sched/core.c:7188
__schedule_loop kernel/sched/core.c:7267 [inline]
schedule+0xa4/0x140 kernel/sched/core.c:7282
schedule_preempt_disabled+0x18/0x2c kernel/sched/core.c:7339
__mutex_lock_common+0x98c/0x20f4 kernel/locking/mutex.c:726
__mutex_lock kernel/locking/mutex.c:820 [inline]
mutex_lock_nested+0x2c/0x38 kernel/locking/mutex.c:873
del_device_store+0xd8/0x2d0 drivers/net/netdevsim/bus.c:234
bus_attr_store+0x80/0xa4 drivers/base/bus.c:172
sysfs_kf_write+0xe0/0x108 fs/sysfs/file.c:142
kernfs_fop_write_iter+0x264/0x3c0 fs/kernfs/file.c:352
new_sync_write fs/read_write.c:595 [inline]
vfs_write+0x52c/0xa14 fs/read_write.c:688
ksys_write+0x12c/0x224 fs/read_write.c:740
__do_sys_write fs/read_write.c:751 [inline]
__se_sys_write fs/read_write.c:748 [inline]
__arm64_sys_write+0x7c/0x90 fs/read_write.c:748
__invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]
invoke_syscall+0x98/0x244 arch/arm64/kernel/syscall.c:49
el0_svc_common+0xe8/0x23c arch/arm64/kernel/syscall.c:121
do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:140
el0_svc+0x60/0x25c arch/arm64/kernel/entry-common.c:723
el0t_64_sync_handler+0x48/0x148 arch/arm64/kernel/entry-common.c:742
el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:594
INFO: task syz-executor:4812 blocked for more than 143 seconds.
Not tainted syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:syz-executor state:D stack:0 pid:4812 tgid:4812 ppid:1 task_flags:0x400140 flags:0x00800001
Call trace:
__switch_to+0x2b0/0x6e0 arch/arm64/kernel/process.c:810 (T)
context_switch kernel/sched/core.c:5387 [inline]
__schedule+0x1b74/0x2d24 kernel/sched/core.c:7188
__schedule_loop kernel/sched/core.c:7267 [inline]
schedule+0xa4/0x140 kernel/sched/core.c:7282
schedule_preempt_disabled+0x18/0x2c kernel/sched/core.c:7339
__mutex_lock_common+0x98c/0x20f4 kernel/locking/mutex.c:726
__mutex_lock kernel/locking/mutex.c:820 [inline]
mutex_lock_nested+0x2c/0x38 kernel/locking/mutex.c:873
del_device_store+0xd8/0x2d0 drivers/net/netdevsim/bus.c:234
bus_attr_store+0x80/0xa4 drivers/base/bus.c:172
sysfs_kf_write+0xe0/0x108 fs/sysfs/file.c:142
kernfs_fop_write_iter+0x264/0x3c0 fs/kernfs/file.c:352
new_sync_write fs/read_write.c:595 [inline]
vfs_write+0x52c/0xa14 fs/read_write.c:688
ksys_write+0x12c/0x224 fs/read_write.c:740
__do_sys_write fs/read_write.c:751 [inline]
__se_sys_write fs/read_write.c:748 [inline]
__arm64_sys_write+0x7c/0x90 fs/read_write.c:748
__invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]
invoke_syscall+0x98/0x244 arch/arm64/kernel/syscall.c:49
el0_svc_common+0xe8/0x23c arch/arm64/kernel/syscall.c:121
do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:140
el0_svc+0x60/0x25c arch/arm64/kernel/entry-common.c:723
el0t_64_sync_handler+0x48/0x148 arch/arm64/kernel/entry-common.c:742
el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:594
Showing all locks held in the system:
3 locks held by kworker/u8:0/12:
1 lock held by khungtaskd/31:
#0: ffff800088ac66e0 (rcu_read_lock){....}-{1:3}, at: __ll_sc_atomic64_fetch_or arch/arm64/include/asm/atomic_ll_sc.h:-1 [inline]
#0: ffff800088ac66e0 (rcu_read_lock){....}-{1:3}, at: arch_atomic64_fetch_or arch/arm64/include/asm/atomic.h:86 [inline]
#0: ffff800088ac66e0 (rcu_read_lock){....}-{1:3}, at: raw_atomic64_fetch_or include/linux/atomic/atomic-arch-fallback.h:3816 [inline]
#0: ffff800088ac66e0 (rcu_read_lock){....}-{1:3}, at: raw_atomic_long_fetch_or include/linux/atomic/atomic-long.h:1090 [inline]
#0: ffff800088ac66e0 (rcu_read_lock){....}-{1:3}, at: arch_test_and_set_bit include/asm-generic/bitops/atomic.h:42 [inline]
#0: ffff800088ac66e0 (rcu_read_lock){....}-{1:3}, at: test_and_set_bit include/asm-generic/bitops/instrumented-atomic.h:72 [inline]
#0: ffff800088ac66e0 (rcu_read_lock){....}-{1:3}, at: rcu_lock_acquire+0x0/0x44 kernel/sched/sched.h:3869
8 locks held by kworker/u8:3/40:
4 locks held by pr/ttyAMA-1/41:
3 locks held by kworker/u8:5/1188:
3 locks held by kworker/u8:6/1389:
3 locks held by kworker/u8:7/1910:
1 lock held by klogd/4292:
3 locks held by udevd/4303:
3 locks held by dhcpcd/4359:
2 locks held by getty/4451:
#0: ffff0000d3bfb0a0 (&tty->ldisc_sem){++++}-{0:0}, at: ldsem_down_read+0x3c/0x4c drivers/tty/tty_ldsem.c:340
#1: ffff80009228b2e8 (&ldata->atomic_read_lock){+.+.}-{4:4}, at: n_tty_read+0x354/0xf84 drivers/tty/n_tty.c:2211
3 locks held by kworker/1:3/4670:
#0: ffff0000c002b540 ((wq_completion)events){+.+.}-{0:0}, at: process_one_work+0x640/0x173c kernel/workqueue.c:3276
#1: ffff8000966d7be0 (reg_work){+.+.}-{0:0}, at: process_one_work+0x6a4/0x173c kernel/workqueue.c:3276
#2: ffff800089b85900 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_lock+0x20/0x2c net/core/rtnetlink.c:80
5 locks held by syz-executor/4797:
#0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: file_start_write include/linux/fs.h:2724 [inline]
#0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: vfs_write+0x240/0xa14 fs/read_write.c:684
#1: ffff0000e8fb8880 (&of->mutex){+.+.}-{4:4}, at: kernfs_fop_write_iter+0x1b4/0x3c0 fs/kernfs/file.c:343
#2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_get_active_of fs/kernfs/file.c:80 [inline]
#2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_fop_write_iter+0x1f4/0x3c0 fs/kernfs/file.c:344
#3: ffff800089383240 (nsim_bus_dev_list_lock){+.+.}-{4:4}, at: del_device_store+0xd8/0x2d0 drivers/net/netdevsim/bus.c:234
#4: ffff0000d7b8a128 (&dev->mutex){....}-{4:4}, at: device_lock include/linux/device.h:1040 [inline]
#4: ffff0000d7b8a128 (&dev->mutex){....}-{4:4}, at: device_del+0xa0/0x710 drivers/base/core.c:3857
4 locks held by syz-executor/4805:
#0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: file_start_write include/linux/fs.h:2724 [inline]
#0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: vfs_write+0x240/0xa14 fs/read_write.c:684
#1: ffff0000eca42080 (&of->mutex){+.+.}-{4:4}, at: kernfs_fop_write_iter+0x1b4/0x3c0 fs/kernfs/file.c:343
#2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_get_active_of fs/kernfs/file.c:80 [inline]
#2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_fop_write_iter+0x1f4/0x3c0 fs/kernfs/file.c:344
#3: ffff800089383240 (nsim_bus_dev_list_lock){+.+.}-{4:4}, at: del_device_store+0xd8/0x2d0 drivers/net/netdevsim/bus.c:234
4 locks held by syz-executor/4809:
#0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: file_start_write include/linux/fs.h:2724 [inline]
#0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: vfs_write+0x240/0xa14 fs/read_write.c:684
#1: ffff0000eca0f880 (&of->mutex){+.+.}-{4:4}, at: kernfs_fop_write_iter+0x1b4/0x3c0 fs/kernfs/file.c:343
#2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_get_active_of fs/kernfs/file.c:80 [inline]
#2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_fop_write_iter+0x1f4/0x3c0 fs/kernfs/file.c:344
#3: ffff800089383240 (nsim_bus_dev_list_lock){+.+.}-{4:4}, at: del_device_store+0xd8/0x2d0 drivers/net/netdevsim/bus.c:234
4 locks held by syz-executor/4812:
#0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: file_start_write include/linux/fs.h:2724 [inline]
#0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: vfs_write+0x240/0xa14 fs/read_write.c:684
#1: ffff0000cd063c80 (&of->mutex){+.+.}-{4:4}, at: kernfs_fop_write_iter+0x1b4/0x3c0 fs/kernfs/file.c:343
#2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_get_active_of fs/kernfs/file.c:80 [inline]
#2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_fop_write_iter+0x1f4/0x3c0 fs/kernfs/file.c:344
#3: ffff800089383240 (nsim_bus_dev_list_lock){+.+.}-{4:4}, at: del_device_store+0xd8/0x2d0 drivers/net/netdevsim/bus.c:234
3 locks held by kworker/u8:11/4904:
#0: ffff0000ce706140 ((wq_completion)ipv6_addrconf){+.+.}-{0:0}, at: process_one_work+0x640/0x173c kernel/workqueue.c:3276
#1: ffff8000995f7be0 ((work_completion)(&(&ifa->dad_work)->work)){+.+.}-{0:0}, at: process_one_work+0x6a4/0x173c kernel/workqueue.c:3276
#2: ffff800089b85900 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_lock+0x20/0x2c net/core/rtnetlink.c:80
2 locks held by kworker/u8:12/4906:
2 locks held by kworker/u8:13/4908:
2 locks held by syz-executor/4913:
2 locks held by syz-executor/4914:
=============================================
---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup
reply other threads:[~2026-05-16 0:11 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=6a07b635.170a0220.df43.0000.GAE@google.com \
--to=syzbot+1cf303af03cf30b1275a@syzkaller.appspotmail.com \
--cc=dakr@kernel.org \
--cc=driver-core@lists.linux.dev \
--cc=gregkh@linuxfoundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=rafael@kernel.org \
--cc=syzkaller-bugs@googlegroups.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.