* [syzbot] [kernel?] INFO: task hung in nsim_bus_dev_del
@ 2026-05-16 0:11 syzbot
2026-05-16 11:04 ` Hillf Danton
2026-05-18 6:58 ` Forwarded: " syzbot
0 siblings, 2 replies; 5+ messages in thread
From: syzbot @ 2026-05-16 0:11 UTC (permalink / raw)
To: dakr, driver-core, gregkh, linux-kernel, rafael, syzkaller-bugs
Hello,
syzbot found the following issue on:
HEAD commit: 5cbb61bf4168 arm64/fpsimd: ptrace: zero target's fpsimd_st..
git tree: git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git for-kernelci
console output: https://syzkaller.appspot.com/x/log.txt?x=165db76c580000
kernel config: https://syzkaller.appspot.com/x/.config?x=a834c6344141a58b
dashboard link: https://syzkaller.appspot.com/bug?extid=1cf303af03cf30b1275a
compiler: Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=12c4d56a580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=115db76c580000
Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/04156ec16593/disk-5cbb61bf.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/6bfa041e2c79/vmlinux-5cbb61bf.xz
kernel image: https://storage.googleapis.com/syzbot-assets/a92d82d8a79e/Image-5cbb61bf.gz.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+1cf303af03cf30b1275a@syzkaller.appspotmail.com
INFO: task syz-executor:4797 blocked for more than 143 seconds.
Not tainted syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:syz-executor state:D stack:0 pid:4797 tgid:4797 ppid:4796 task_flags:0x400140 flags:0x00800000
Call trace:
__switch_to+0x2b0/0x6e0 arch/arm64/kernel/process.c:810 (T)
context_switch kernel/sched/core.c:5387 [inline]
__schedule+0x1b74/0x2d24 kernel/sched/core.c:7188
__schedule_loop kernel/sched/core.c:7267 [inline]
schedule+0xa4/0x140 kernel/sched/core.c:7282
schedule_preempt_disabled+0x18/0x2c kernel/sched/core.c:7339
__mutex_lock_common+0x98c/0x20f4 kernel/locking/mutex.c:726
__mutex_lock kernel/locking/mutex.c:820 [inline]
mutex_lock_nested+0x2c/0x38 kernel/locking/mutex.c:873
device_lock include/linux/device.h:1040 [inline]
device_del+0xa0/0x710 drivers/base/core.c:3857
device_unregister+0x2c/0xf0 drivers/base/core.c:3936
nsim_bus_dev_del+0x60/0x88 drivers/net/netdevsim/bus.c:491
del_device_store+0x248/0x2d0 drivers/net/netdevsim/bus.c:244
bus_attr_store+0x80/0xa4 drivers/base/bus.c:172
sysfs_kf_write+0xe0/0x108 fs/sysfs/file.c:142
kernfs_fop_write_iter+0x264/0x3c0 fs/kernfs/file.c:352
new_sync_write fs/read_write.c:595 [inline]
vfs_write+0x52c/0xa14 fs/read_write.c:688
ksys_write+0x12c/0x224 fs/read_write.c:740
__do_sys_write fs/read_write.c:751 [inline]
__se_sys_write fs/read_write.c:748 [inline]
__arm64_sys_write+0x7c/0x90 fs/read_write.c:748
__invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]
invoke_syscall+0x98/0x244 arch/arm64/kernel/syscall.c:49
el0_svc_common+0xe8/0x23c arch/arm64/kernel/syscall.c:121
do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:140
el0_svc+0x60/0x25c arch/arm64/kernel/entry-common.c:723
el0t_64_sync_handler+0x48/0x148 arch/arm64/kernel/entry-common.c:742
el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:594
INFO: task syz-executor:4805 blocked for more than 143 seconds.
Not tainted syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:syz-executor state:D stack:0 pid:4805 tgid:4805 ppid:4801 task_flags:0x400140 flags:0x00800000
Call trace:
__switch_to+0x2b0/0x6e0 arch/arm64/kernel/process.c:810 (T)
context_switch kernel/sched/core.c:5387 [inline]
__schedule+0x1b74/0x2d24 kernel/sched/core.c:7188
__schedule_loop kernel/sched/core.c:7267 [inline]
schedule+0xa4/0x140 kernel/sched/core.c:7282
schedule_preempt_disabled+0x18/0x2c kernel/sched/core.c:7339
__mutex_lock_common+0x98c/0x20f4 kernel/locking/mutex.c:726
__mutex_lock kernel/locking/mutex.c:820 [inline]
mutex_lock_nested+0x2c/0x38 kernel/locking/mutex.c:873
del_device_store+0xd8/0x2d0 drivers/net/netdevsim/bus.c:234
bus_attr_store+0x80/0xa4 drivers/base/bus.c:172
sysfs_kf_write+0xe0/0x108 fs/sysfs/file.c:142
kernfs_fop_write_iter+0x264/0x3c0 fs/kernfs/file.c:352
new_sync_write fs/read_write.c:595 [inline]
vfs_write+0x52c/0xa14 fs/read_write.c:688
ksys_write+0x12c/0x224 fs/read_write.c:740
__do_sys_write fs/read_write.c:751 [inline]
__se_sys_write fs/read_write.c:748 [inline]
__arm64_sys_write+0x7c/0x90 fs/read_write.c:748
__invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]
invoke_syscall+0x98/0x244 arch/arm64/kernel/syscall.c:49
el0_svc_common+0xe8/0x23c arch/arm64/kernel/syscall.c:121
do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:140
el0_svc+0x60/0x25c arch/arm64/kernel/entry-common.c:723
el0t_64_sync_handler+0x48/0x148 arch/arm64/kernel/entry-common.c:742
el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:594
INFO: task syz-executor:4809 blocked for more than 143 seconds.
Not tainted syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:syz-executor state:D stack:0 pid:4809 tgid:4809 ppid:1 task_flags:0x400140 flags:0x00800001
Call trace:
__switch_to+0x2b0/0x6e0 arch/arm64/kernel/process.c:810 (T)
context_switch kernel/sched/core.c:5387 [inline]
__schedule+0x1b74/0x2d24 kernel/sched/core.c:7188
__schedule_loop kernel/sched/core.c:7267 [inline]
schedule+0xa4/0x140 kernel/sched/core.c:7282
schedule_preempt_disabled+0x18/0x2c kernel/sched/core.c:7339
__mutex_lock_common+0x98c/0x20f4 kernel/locking/mutex.c:726
__mutex_lock kernel/locking/mutex.c:820 [inline]
mutex_lock_nested+0x2c/0x38 kernel/locking/mutex.c:873
del_device_store+0xd8/0x2d0 drivers/net/netdevsim/bus.c:234
bus_attr_store+0x80/0xa4 drivers/base/bus.c:172
sysfs_kf_write+0xe0/0x108 fs/sysfs/file.c:142
kernfs_fop_write_iter+0x264/0x3c0 fs/kernfs/file.c:352
new_sync_write fs/read_write.c:595 [inline]
vfs_write+0x52c/0xa14 fs/read_write.c:688
ksys_write+0x12c/0x224 fs/read_write.c:740
__do_sys_write fs/read_write.c:751 [inline]
__se_sys_write fs/read_write.c:748 [inline]
__arm64_sys_write+0x7c/0x90 fs/read_write.c:748
__invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]
invoke_syscall+0x98/0x244 arch/arm64/kernel/syscall.c:49
el0_svc_common+0xe8/0x23c arch/arm64/kernel/syscall.c:121
do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:140
el0_svc+0x60/0x25c arch/arm64/kernel/entry-common.c:723
el0t_64_sync_handler+0x48/0x148 arch/arm64/kernel/entry-common.c:742
el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:594
INFO: task syz-executor:4812 blocked for more than 143 seconds.
Not tainted syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:syz-executor state:D stack:0 pid:4812 tgid:4812 ppid:1 task_flags:0x400140 flags:0x00800001
Call trace:
__switch_to+0x2b0/0x6e0 arch/arm64/kernel/process.c:810 (T)
context_switch kernel/sched/core.c:5387 [inline]
__schedule+0x1b74/0x2d24 kernel/sched/core.c:7188
__schedule_loop kernel/sched/core.c:7267 [inline]
schedule+0xa4/0x140 kernel/sched/core.c:7282
schedule_preempt_disabled+0x18/0x2c kernel/sched/core.c:7339
__mutex_lock_common+0x98c/0x20f4 kernel/locking/mutex.c:726
__mutex_lock kernel/locking/mutex.c:820 [inline]
mutex_lock_nested+0x2c/0x38 kernel/locking/mutex.c:873
del_device_store+0xd8/0x2d0 drivers/net/netdevsim/bus.c:234
bus_attr_store+0x80/0xa4 drivers/base/bus.c:172
sysfs_kf_write+0xe0/0x108 fs/sysfs/file.c:142
kernfs_fop_write_iter+0x264/0x3c0 fs/kernfs/file.c:352
new_sync_write fs/read_write.c:595 [inline]
vfs_write+0x52c/0xa14 fs/read_write.c:688
ksys_write+0x12c/0x224 fs/read_write.c:740
__do_sys_write fs/read_write.c:751 [inline]
__se_sys_write fs/read_write.c:748 [inline]
__arm64_sys_write+0x7c/0x90 fs/read_write.c:748
__invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]
invoke_syscall+0x98/0x244 arch/arm64/kernel/syscall.c:49
el0_svc_common+0xe8/0x23c arch/arm64/kernel/syscall.c:121
do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:140
el0_svc+0x60/0x25c arch/arm64/kernel/entry-common.c:723
el0t_64_sync_handler+0x48/0x148 arch/arm64/kernel/entry-common.c:742
el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:594
Showing all locks held in the system:
3 locks held by kworker/u8:0/12:
1 lock held by khungtaskd/31:
#0: ffff800088ac66e0 (rcu_read_lock){....}-{1:3}, at: __ll_sc_atomic64_fetch_or arch/arm64/include/asm/atomic_ll_sc.h:-1 [inline]
#0: ffff800088ac66e0 (rcu_read_lock){....}-{1:3}, at: arch_atomic64_fetch_or arch/arm64/include/asm/atomic.h:86 [inline]
#0: ffff800088ac66e0 (rcu_read_lock){....}-{1:3}, at: raw_atomic64_fetch_or include/linux/atomic/atomic-arch-fallback.h:3816 [inline]
#0: ffff800088ac66e0 (rcu_read_lock){....}-{1:3}, at: raw_atomic_long_fetch_or include/linux/atomic/atomic-long.h:1090 [inline]
#0: ffff800088ac66e0 (rcu_read_lock){....}-{1:3}, at: arch_test_and_set_bit include/asm-generic/bitops/atomic.h:42 [inline]
#0: ffff800088ac66e0 (rcu_read_lock){....}-{1:3}, at: test_and_set_bit include/asm-generic/bitops/instrumented-atomic.h:72 [inline]
#0: ffff800088ac66e0 (rcu_read_lock){....}-{1:3}, at: rcu_lock_acquire+0x0/0x44 kernel/sched/sched.h:3869
8 locks held by kworker/u8:3/40:
4 locks held by pr/ttyAMA-1/41:
3 locks held by kworker/u8:5/1188:
3 locks held by kworker/u8:6/1389:
3 locks held by kworker/u8:7/1910:
1 lock held by klogd/4292:
3 locks held by udevd/4303:
3 locks held by dhcpcd/4359:
2 locks held by getty/4451:
#0: ffff0000d3bfb0a0 (&tty->ldisc_sem){++++}-{0:0}, at: ldsem_down_read+0x3c/0x4c drivers/tty/tty_ldsem.c:340
#1: ffff80009228b2e8 (&ldata->atomic_read_lock){+.+.}-{4:4}, at: n_tty_read+0x354/0xf84 drivers/tty/n_tty.c:2211
3 locks held by kworker/1:3/4670:
#0: ffff0000c002b540 ((wq_completion)events){+.+.}-{0:0}, at: process_one_work+0x640/0x173c kernel/workqueue.c:3276
#1: ffff8000966d7be0 (reg_work){+.+.}-{0:0}, at: process_one_work+0x6a4/0x173c kernel/workqueue.c:3276
#2: ffff800089b85900 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_lock+0x20/0x2c net/core/rtnetlink.c:80
5 locks held by syz-executor/4797:
#0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: file_start_write include/linux/fs.h:2724 [inline]
#0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: vfs_write+0x240/0xa14 fs/read_write.c:684
#1: ffff0000e8fb8880 (&of->mutex){+.+.}-{4:4}, at: kernfs_fop_write_iter+0x1b4/0x3c0 fs/kernfs/file.c:343
#2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_get_active_of fs/kernfs/file.c:80 [inline]
#2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_fop_write_iter+0x1f4/0x3c0 fs/kernfs/file.c:344
#3: ffff800089383240 (nsim_bus_dev_list_lock){+.+.}-{4:4}, at: del_device_store+0xd8/0x2d0 drivers/net/netdevsim/bus.c:234
#4: ffff0000d7b8a128 (&dev->mutex){....}-{4:4}, at: device_lock include/linux/device.h:1040 [inline]
#4: ffff0000d7b8a128 (&dev->mutex){....}-{4:4}, at: device_del+0xa0/0x710 drivers/base/core.c:3857
4 locks held by syz-executor/4805:
#0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: file_start_write include/linux/fs.h:2724 [inline]
#0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: vfs_write+0x240/0xa14 fs/read_write.c:684
#1: ffff0000eca42080 (&of->mutex){+.+.}-{4:4}, at: kernfs_fop_write_iter+0x1b4/0x3c0 fs/kernfs/file.c:343
#2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_get_active_of fs/kernfs/file.c:80 [inline]
#2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_fop_write_iter+0x1f4/0x3c0 fs/kernfs/file.c:344
#3: ffff800089383240 (nsim_bus_dev_list_lock){+.+.}-{4:4}, at: del_device_store+0xd8/0x2d0 drivers/net/netdevsim/bus.c:234
4 locks held by syz-executor/4809:
#0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: file_start_write include/linux/fs.h:2724 [inline]
#0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: vfs_write+0x240/0xa14 fs/read_write.c:684
#1: ffff0000eca0f880 (&of->mutex){+.+.}-{4:4}, at: kernfs_fop_write_iter+0x1b4/0x3c0 fs/kernfs/file.c:343
#2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_get_active_of fs/kernfs/file.c:80 [inline]
#2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_fop_write_iter+0x1f4/0x3c0 fs/kernfs/file.c:344
#3: ffff800089383240 (nsim_bus_dev_list_lock){+.+.}-{4:4}, at: del_device_store+0xd8/0x2d0 drivers/net/netdevsim/bus.c:234
4 locks held by syz-executor/4812:
#0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: file_start_write include/linux/fs.h:2724 [inline]
#0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: vfs_write+0x240/0xa14 fs/read_write.c:684
#1: ffff0000cd063c80 (&of->mutex){+.+.}-{4:4}, at: kernfs_fop_write_iter+0x1b4/0x3c0 fs/kernfs/file.c:343
#2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_get_active_of fs/kernfs/file.c:80 [inline]
#2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_fop_write_iter+0x1f4/0x3c0 fs/kernfs/file.c:344
#3: ffff800089383240 (nsim_bus_dev_list_lock){+.+.}-{4:4}, at: del_device_store+0xd8/0x2d0 drivers/net/netdevsim/bus.c:234
3 locks held by kworker/u8:11/4904:
#0: ffff0000ce706140 ((wq_completion)ipv6_addrconf){+.+.}-{0:0}, at: process_one_work+0x640/0x173c kernel/workqueue.c:3276
#1: ffff8000995f7be0 ((work_completion)(&(&ifa->dad_work)->work)){+.+.}-{0:0}, at: process_one_work+0x6a4/0x173c kernel/workqueue.c:3276
#2: ffff800089b85900 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_lock+0x20/0x2c net/core/rtnetlink.c:80
2 locks held by kworker/u8:12/4906:
2 locks held by kworker/u8:13/4908:
2 locks held by syz-executor/4913:
2 locks held by syz-executor/4914:
=============================================
---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup
^ permalink raw reply [flat|nested] 5+ messages in thread* Re: [syzbot] [kernel?] INFO: task hung in nsim_bus_dev_del 2026-05-16 0:11 [syzbot] [kernel?] INFO: task hung in nsim_bus_dev_del syzbot @ 2026-05-16 11:04 ` Hillf Danton 2026-05-16 12:35 ` syzbot 2026-05-18 6:58 ` Forwarded: " syzbot 1 sibling, 1 reply; 5+ messages in thread From: Hillf Danton @ 2026-05-16 11:04 UTC (permalink / raw) To: syzbot; +Cc: linux-kernel, syzkaller-bugs > Date: Fri, 15 May 2026 17:11:33 -0700 [thread overview] > Hello, > > syzbot found the following issue on: > > HEAD commit: 5cbb61bf4168 arm64/fpsimd: ptrace: zero target's fpsimd_st.. > git tree: git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git for-kernelci > console output: https://syzkaller.appspot.com/x/log.txt?x=165db76c580000 > kernel config: https://syzkaller.appspot.com/x/.config?x=a834c6344141a58b > dashboard link: https://syzkaller.appspot.com/bug?extid=1cf303af03cf30b1275a > compiler: Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8 > userspace arch: arm64 > syz repro: https://syzkaller.appspot.com/x/repro.syz?x=12c4d56a580000 > C reproducer: https://syzkaller.appspot.com/x/repro.c?x=115db76c580000 #syz test --- x/kernel/workqueue.c +++ y/kernel/workqueue.c @@ -2384,6 +2384,10 @@ retry: work_flags |= WORK_STRUCT_INACTIVE; insert_work(pwq, work, &pwq->inactive_works, work_flags); } + do { + unsigned long data = *work_data_bits(work); + BUG_ON(data & WORK_OFFQ_DISABLE_MASK); + } while (0); out: raw_spin_unlock(&pool->lock); -- ^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [syzbot] [kernel?] INFO: task hung in nsim_bus_dev_del 2026-05-16 11:04 ` Hillf Danton @ 2026-05-16 12:35 ` syzbot 0 siblings, 0 replies; 5+ messages in thread From: syzbot @ 2026-05-16 12:35 UTC (permalink / raw) To: hdanton, linux-kernel, syzkaller-bugs Hello, syzbot tried to test the proposed patch but the build/boot failed: can't ssh into the instance failed to run ["ssh" "-p" "22" "-F" "/dev/null" "-o" "UserKnownHostsFile=/dev/null" "-o" "IdentitiesOnly=yes" "-o" "BatchMode=yes" "-o" "StrictHostKeyChecking=no" "-o" "ConnectTimeout=10" "root@10.128.1.219" "pwd"]: exit status 255 ssh: connect to host 10.128.1.219 port 22: Connection timed out Pseudo-terminal will not be allocated because stdin is not a terminal. Warning: Permanently added '[us-central1-ssh-serialport.googleapis.com]:9600' (ECDSA) to the list of known hosts. UEFI firmware (version built at 09:00:00 on Jan 10 2025) EMU Variable FVB Started EMU Variable invalid PCD sizes Found PL031 RTC @ 0x9010000 InitializeRealTimeClock: using default timezone/daylight settings ^[[2J^[[01;01H^[[=3h^[[2J^[[01;01H^[[2J^[[01;01H^[[=3h^[[2J^[[01;01HBdsDxe: loading Boot0001 "UEFI Misc Device" from PciRoot(0x0)/Pci(0x2,0x0)/NVMe(0x1,00-00-00-00-00-00-00-00) BdsDxe: starting Boot0001 "UEFI Misc Device" from PciRoot(0x0)/Pci(0x2,0x0)/NVMe(0x1,00-00-00-00-00-00-00-00) UEFI: Attempting to start image. Description: UEFI Misc Device FilePath: PciRoot(0x0)/Pci(0x2,0x0)/NVMe(0x1,00-00-00-00-00-00-00-00) OptionNumber: 1. Booting `syzkaller' UEFI firmware (version built at 09:00:00 on Jan 10 2025) EMU Variable FVB Started EMU Variable invalid PCD sizes Found PL031 RTC @ 0x9010000 InitializeRealTimeClock: using default timezone/daylight settings ^[[2J^[[01;01H^[[=3h^[[2J^[[01;01H^[[2J^[[01;01H^[[=3h^[[2J^[[01;01HBdsDxe: loading Boot0001 "UEFI Misc Device" from PciRoot(0x0)/Pci(0x2,0x0)/NVMe(0x1,00-00-00-00-00-00-00-00) BdsDxe: starting Boot0001 "UEFI Misc Device" from PciRoot(0x0)/Pci(0x2,0x0)/NVMe(0x1,00-00-00-00-00-00-00-00) UEFI: Attempting to start image. Description: UEFI Misc Device FilePath: PciRoot(0x0)/Pci(0x2,0x0)/NVMe(0x1,00-00-00-00-00-00-00-00) OptionNumber: 1. Booting `syzkaller' UEFI firmware (version built at 09:00:00 on Jan 10 2025) EMU Variable FVB Started EMU Variable invalid PCD sizes Found PL031 RTC @ 0x9010000 InitializeRealTimeClock: using default timezone/daylight settings ^[[2J^[[01;01H^[[=3h^[[2J^[[01;01H^[[2J^[[01;01H^[[=3h^[[2J^[[01;01HBdsDxe: loading Boot0001 "UEFI Misc Device" from PciRoot(0x0)/Pci(0x2,0x0)/NVMe(0x1,00-00-00-00-00-00-00-00) BdsDxe: starting Boot0001 "UEFI Misc Device" from PciRoot(0x0)/Pci(0x2,0x0)/NVMe(0x1,00-00-00-00-00-00-00-00) UEFI: Attempting to start image. Description: UEFI Misc Device FilePath: PciRoot(0x0)/Pci(0x2,0x0)/NVMe(0x1,00-00-00-00-00-00-00-00) OptionNumber: 1. Booting `syzkaller' UEFI firmware (version built at 09:00:00 on Jan 10 2025) EMU Variable FVB Started EMU Variable invalid PCD sizes Found PL031 RTC @ 0x9010000 InitializeRealTimeClock: using default timezone/daylight settings ^[[2J^[[01;01H^[[=3h^[[2J^[[01;01H^[[2J^[[01;01H^[[=3h^[[2J^[[01;01HBdsDxe: loading Boot0001 "UEFI Misc Device" from PciRoot(0x0)/Pci(0x2,0x0)/NVMe(0x1,00-00-00-00-00-00-00-00) BdsDxe: starting Boot0001 "UEFI Misc Device" from PciRoot(0x0)/Pci(0x2,0x0)/NVMe(0x1,00-00-00-00-00-00-00-00) UEFI: Attempting to start image. Description: UEFI Misc Device FilePath: PciRoot(0x0)/Pci(0x2,0x0)/NVMe(0x1,00-00-00-00-00-00-00-00) OptionNumber: 1. Booting `syzkaller' UEFI firmware (version built at 09:00:00 on Jan 10 2025) EMU Variable FVB Started EMU Variable invalid PCD sizes Found PL031 RTC @ 0x9010000 InitializeRealTimeClock: using default timezone/daylight settings ^[[2J^[[01;01H^[[=3h^[[2J^[[01;01H^[[2J^[[01;01H^[[=3h^[[2J^[[01;01HBdsDxe: loading Boot0001 "UEFI Misc Device" from PciRoot(0x0)/Pci(0x2,0x0)/NVMe(0x1,00-00-00-00-00-00-00-00) BdsDxe: starting Boot0001 "UEFI Misc Device" from PciRoot(0x0)/Pci(0x2,0x0)/NVMe(0x1,00-00-00-00-00-00-00-00) UEFI: Attempting to start image. Description: UEFI Misc Device FilePath: PciRoot(0x0)/Pci(0x2,0x0)/NVMe(0x1,00-00-00-00-00-00-00-00) OptionNumber: 1. Booting `syzkaller' UEFI firmware (version built at 09:00:00 on Jan 10 2025) EMU Variable FVB Started EMU Variable invalid PCD sizes Found PL031 RTC @ 0x9010000 InitializeRealTimeClock: using default timezone/daylight settings ^[[2J^[[01;01H^[[=3h^[[2J^[[01;01H^[[2J^[[01;01H^[[=3h^[[2J^[[01;01HBdsDxe: loading Boot0001 "UEFI Misc Device" from PciRoot(0x0)/Pci(0x2,0x0)/NVMe(0x1,00-00-00-00-00-00-00-00) BdsDxe: starting Boot0001 "UEFI Misc Device" from PciRoot(0x0)/Pci(0x2,0x0)/NVMe(0x1,00-00-00-00-00-00-00-00) UEFI: Attempting to start image. Description: UEFI Misc Device FilePath: PciRoot(0x0)/Pci(0x2,0x0)/NVMe(0x1,00-00-00-00-00-00-00-00) OptionNumber: 1. Booting `syzkaller' UEFI firmware (version built at 09:00:00 on Jan 10 2025) EMU Variable FVB Started EMU Variable invalid PCD sizes Found PL031 RTC @ 0x9010000 InitializeRealTimeClock: using default timezone/daylight settings ^[[2J^[[01;01H^[[=3h^[[2J^[[01;01H^[[2J^[[01;01H^[[=3h^[[2J^[[01;01HBdsDxe: loading Boot0001 "UEFI Misc Device" from PciRoot(0x0)/Pci(0x2,0x0)/NVMe(0x1,00-00-00-00-00-00-00-00) BdsDxe: starting Boot0001 "UEFI Misc Device" from PciRoot(0x0)/Pci(0x2,0x0)/NVMe(0x1,00-00-00-00-00-00-00-00) UEFI: Attempting to start image. Description: UEFI Misc Device FilePath: PciRoot(0x0)/Pci(0x2,0x0)/NVMe(0x1,00-00-00-00-00-00-00-00) OptionNumber: 1. Booting `syzkaller' serialport: Connected to syzkaller.us-central1-f.ci-upstream-gce-arm64-test-job-0 port 1 (session ID: e70122d9217081b58b1e89fac32748d7c58bb332e094bd288395bea51681d062, active connections: 1). UEFI firmware (version built at 09:00:00 on Jan 10 2025) EMU Variable FVB Started EMU Variable invalid PCD sizes Found PL031 RTC @ 0x9010000 InitializeRealTimeClock: using default timezone/daylight settings ^[[2J^[[01;01H^[[=3h^[[2J^[[01;01H^[[2J^[[01;01H^[[=3h^[[2J^[[01;01HBdsDxe: loading Boot0001 "UEFI Misc Device" from PciRoot(0x0)/Pci(0x2,0x0)/NVMe(0x1,00-00-00-00-00-00-00-00) BdsDxe: starting Boot0001 "UEFI Misc Device" from PciRoot(0x0)/Pci(0x2,0x0)/NVMe(0x1,00-00-00-00-00-00-00-00) UEFI: Attempting to start image. Description: UEFI Misc Device FilePath: PciRoot(0x0)/Pci(0x2,0x0)/NVMe(0x1,00-00-00-00-00-00-00-00) OptionNumber: 1. Booting `syzkaller' syzkaller build log: go env (err=<nil>) AR='ar' CC='gcc' CGO_CFLAGS='-O2 -g' CGO_CPPFLAGS='' CGO_CXXFLAGS='-O2 -g' CGO_ENABLED='1' CGO_FFLAGS='-O2 -g' CGO_LDFLAGS='-O2 -g' CXX='g++' GCCGO='gccgo' GO111MODULE='auto' GOAMD64='v1' GOARCH='amd64' GOAUTH='netrc' GOBIN='' GOCACHE='/syzkaller/.cache/go-build' GOCACHEPROG='' GODEBUG='' GOENV='/syzkaller/.config/go/env' GOEXE='' GOEXPERIMENT='' GOFIPS140='off' GOFLAGS='' GOGCCFLAGS='-fPIC -m64 -pthread -Wl,--no-gc-sections -fmessage-length=0 -ffile-prefix-map=/tmp/go-build976075348=/tmp/go-build -gno-record-gcc-switches' GOHOSTARCH='amd64' GOHOSTOS='linux' GOINSECURE='' GOMOD='/syzkaller/jobs/linux/gopath/src/github.com/google/syzkaller/go.mod' GOMODCACHE='/syzkaller/jobs/linux/gopath/pkg/mod' GONOPROXY='' GONOSUMDB='' GOOS='linux' GOPATH='/syzkaller/jobs/linux/gopath' GOPRIVATE='' GOPROXY='https://proxy.golang.org,direct' GOROOT='/usr/local/go' GOSUMDB='sum.golang.org' GOTELEMETRY='local' GOTELEMETRYDIR='/syzkaller/.config/go/telemetry' GOTMPDIR='' GOTOOLCHAIN='auto' GOTOOLDIR='/usr/local/go/pkg/tool/linux_amd64' GOVCS='' GOVERSION='go1.26.0' GOWORK='' PKG_CONFIG='pkg-config' git status (err=<nil>) HEAD detached at d168f260571 nothing to commit, working tree clean tput: No value for $TERM and no -T specified tput: No value for $TERM and no -T specified Makefile:31: run command via tools/syz-env for best compatibility, see: Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env go list -f '{{.Stale}}' -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=d168f2605715ec7b7ab6840d636f69c758e424d9 -X github.com/google/syzkaller/prog.gitRevisionDate=20260511-154029" ./sys/syz-sysgen | grep -q false || go install -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=d168f2605715ec7b7ab6840d636f69c758e424d9 -X github.com/google/syzkaller/prog.gitRevisionDate=20260511-154029" ./sys/syz-sysgen make .descriptions tput: No value for $TERM and no -T specified tput: No value for $TERM and no -T specified Makefile:31: run command via tools/syz-env for best compatibility, see: Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env bin/syz-sysgen touch .descriptions GOOS=linux GOARCH=arm64 go build -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=d168f2605715ec7b7ab6840d636f69c758e424d9 -X github.com/google/syzkaller/prog.gitRevisionDate=20260511-154029" -o ./bin/linux_arm64/syz-execprog github.com/google/syzkaller/tools/syz-execprog mkdir -p ./bin/linux_arm64 aarch64-linux-gnu-g++ -o ./bin/linux_arm64/syz-executor executor/executor.cc \ -O2 -pthread -Wall -Werror -Wparentheses -Wunused-const-variable -Wframe-larger-than=16384 -Wno-stringop-overflow -Wno-array-bounds -Wno-format-overflow -Wno-unused-but-set-variable -Wno-unused-command-line-argument -static-pie -std=c++17 -I. -Iexecutor/_include -DGOOS_linux=1 -DGOARCH_arm64=1 \ -DHOSTGOOS_linux=1 -DGIT_REVISION=\"d168f2605715ec7b7ab6840d636f69c758e424d9\" /usr/lib/gcc-cross/aarch64-linux-gnu/14/../../../../aarch64-linux-gnu/bin/ld: /tmp/ccXJzoBr.o: in function `Connection::Connect(char const*, char const*)': executor.cc:(.text._ZN10Connection7ConnectEPKcS1_[_ZN10Connection7ConnectEPKcS1_]+0x2ec): warning: Using 'gethostbyname' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking ./tools/check-syzos.sh 2>/dev/null Tested on: commit: 5cbb61bf arm64/fpsimd: ptrace: zero target's fpsimd_st.. git tree: git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git for-kernelci kernel config: https://syzkaller.appspot.com/x/.config?x=a834c6344141a58b dashboard link: https://syzkaller.appspot.com/bug?extid=1cf303af03cf30b1275a compiler: Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8 userspace arch: arm64 patch: https://syzkaller.appspot.com/x/patch.diff?x=132e9bce580000 ^ permalink raw reply [flat|nested] 5+ messages in thread
* Forwarded: Re: [syzbot] [kernel?] INFO: task hung in nsim_bus_dev_del 2026-05-16 0:11 [syzbot] [kernel?] INFO: task hung in nsim_bus_dev_del syzbot 2026-05-16 11:04 ` Hillf Danton @ 2026-05-18 6:58 ` syzbot 1 sibling, 0 replies; 5+ messages in thread From: syzbot @ 2026-05-18 6:58 UTC (permalink / raw) To: linux-kernel, syzkaller-bugs For archival purposes, forwarding an incoming command email to linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com. *** Subject: Re: [syzbot] [kernel?] INFO: task hung in nsim_bus_dev_del Author: yun.zhou@windriver.com #syz test On 5/16/26 08:11, syzbot wrote: > CAUTION: This email comes from a non Wind River email account! > Do not click links or open attachments unless you recognize the sender and know the content is safe. > > Hello, > > syzbot found the following issue on: > > HEAD commit: 5cbb61bf4168 arm64/fpsimd: ptrace: zero target's fpsimd_st.. > git tree: git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git for-kernelci > console output: https://syzkaller.appspot.com/x/log.txt?x=165db76c580000 > kernel config: https://syzkaller.appspot.com/x/.config?x=a834c6344141a58b > dashboard link: https://syzkaller.appspot.com/bug?extid=1cf303af03cf30b1275a > compiler: Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8 > userspace arch: arm64 > syz repro: https://syzkaller.appspot.com/x/repro.syz?x=12c4d56a580000 > C reproducer: https://syzkaller.appspot.com/x/repro.c?x=115db76c580000 > > Downloadable assets: > disk image: https://storage.googleapis.com/syzbot-assets/04156ec16593/disk-5cbb61bf.raw.xz > vmlinux: https://storage.googleapis.com/syzbot-assets/6bfa041e2c79/vmlinux-5cbb61bf.xz > kernel image: https://storage.googleapis.com/syzbot-assets/a92d82d8a79e/Image-5cbb61bf.gz.xz > > IMPORTANT: if you fix the issue, please add the following tag to the commit: > Reported-by: syzbot+1cf303af03cf30b1275a@syzkaller.appspotmail.com > > INFO: task syz-executor:4797 blocked for more than 143 seconds. > Not tainted syzkaller #0 > "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. > task:syz-executor state:D stack:0 pid:4797 tgid:4797 ppid:4796 task_flags:0x400140 flags:0x00800000 > Call trace: > __switch_to+0x2b0/0x6e0 arch/arm64/kernel/process.c:810 (T) > context_switch kernel/sched/core.c:5387 [inline] > __schedule+0x1b74/0x2d24 kernel/sched/core.c:7188 > __schedule_loop kernel/sched/core.c:7267 [inline] > schedule+0xa4/0x140 kernel/sched/core.c:7282 > schedule_preempt_disabled+0x18/0x2c kernel/sched/core.c:7339 > __mutex_lock_common+0x98c/0x20f4 kernel/locking/mutex.c:726 > __mutex_lock kernel/locking/mutex.c:820 [inline] > mutex_lock_nested+0x2c/0x38 kernel/locking/mutex.c:873 > device_lock include/linux/device.h:1040 [inline] > device_del+0xa0/0x710 drivers/base/core.c:3857 > device_unregister+0x2c/0xf0 drivers/base/core.c:3936 > nsim_bus_dev_del+0x60/0x88 drivers/net/netdevsim/bus.c:491 > del_device_store+0x248/0x2d0 drivers/net/netdevsim/bus.c:244 > bus_attr_store+0x80/0xa4 drivers/base/bus.c:172 > sysfs_kf_write+0xe0/0x108 fs/sysfs/file.c:142 > kernfs_fop_write_iter+0x264/0x3c0 fs/kernfs/file.c:352 > new_sync_write fs/read_write.c:595 [inline] > vfs_write+0x52c/0xa14 fs/read_write.c:688 > ksys_write+0x12c/0x224 fs/read_write.c:740 > __do_sys_write fs/read_write.c:751 [inline] > __se_sys_write fs/read_write.c:748 [inline] > __arm64_sys_write+0x7c/0x90 fs/read_write.c:748 > __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline] > invoke_syscall+0x98/0x244 arch/arm64/kernel/syscall.c:49 > el0_svc_common+0xe8/0x23c arch/arm64/kernel/syscall.c:121 > do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:140 > el0_svc+0x60/0x25c arch/arm64/kernel/entry-common.c:723 > el0t_64_sync_handler+0x48/0x148 arch/arm64/kernel/entry-common.c:742 > el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:594 > INFO: task syz-executor:4805 blocked for more than 143 seconds. > Not tainted syzkaller #0 > "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. > task:syz-executor state:D stack:0 pid:4805 tgid:4805 ppid:4801 task_flags:0x400140 flags:0x00800000 > Call trace: > __switch_to+0x2b0/0x6e0 arch/arm64/kernel/process.c:810 (T) > context_switch kernel/sched/core.c:5387 [inline] > __schedule+0x1b74/0x2d24 kernel/sched/core.c:7188 > __schedule_loop kernel/sched/core.c:7267 [inline] > schedule+0xa4/0x140 kernel/sched/core.c:7282 > schedule_preempt_disabled+0x18/0x2c kernel/sched/core.c:7339 > __mutex_lock_common+0x98c/0x20f4 kernel/locking/mutex.c:726 > __mutex_lock kernel/locking/mutex.c:820 [inline] > mutex_lock_nested+0x2c/0x38 kernel/locking/mutex.c:873 > del_device_store+0xd8/0x2d0 drivers/net/netdevsim/bus.c:234 > bus_attr_store+0x80/0xa4 drivers/base/bus.c:172 > sysfs_kf_write+0xe0/0x108 fs/sysfs/file.c:142 > kernfs_fop_write_iter+0x264/0x3c0 fs/kernfs/file.c:352 > new_sync_write fs/read_write.c:595 [inline] > vfs_write+0x52c/0xa14 fs/read_write.c:688 > ksys_write+0x12c/0x224 fs/read_write.c:740 > __do_sys_write fs/read_write.c:751 [inline] > __se_sys_write fs/read_write.c:748 [inline] > __arm64_sys_write+0x7c/0x90 fs/read_write.c:748 > __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline] > invoke_syscall+0x98/0x244 arch/arm64/kernel/syscall.c:49 > el0_svc_common+0xe8/0x23c arch/arm64/kernel/syscall.c:121 > do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:140 > el0_svc+0x60/0x25c arch/arm64/kernel/entry-common.c:723 > el0t_64_sync_handler+0x48/0x148 arch/arm64/kernel/entry-common.c:742 > el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:594 > INFO: task syz-executor:4809 blocked for more than 143 seconds. > Not tainted syzkaller #0 > "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. > task:syz-executor state:D stack:0 pid:4809 tgid:4809 ppid:1 task_flags:0x400140 flags:0x00800001 > Call trace: > __switch_to+0x2b0/0x6e0 arch/arm64/kernel/process.c:810 (T) > context_switch kernel/sched/core.c:5387 [inline] > __schedule+0x1b74/0x2d24 kernel/sched/core.c:7188 > __schedule_loop kernel/sched/core.c:7267 [inline] > schedule+0xa4/0x140 kernel/sched/core.c:7282 > schedule_preempt_disabled+0x18/0x2c kernel/sched/core.c:7339 > __mutex_lock_common+0x98c/0x20f4 kernel/locking/mutex.c:726 > __mutex_lock kernel/locking/mutex.c:820 [inline] > mutex_lock_nested+0x2c/0x38 kernel/locking/mutex.c:873 > del_device_store+0xd8/0x2d0 drivers/net/netdevsim/bus.c:234 > bus_attr_store+0x80/0xa4 drivers/base/bus.c:172 > sysfs_kf_write+0xe0/0x108 fs/sysfs/file.c:142 > kernfs_fop_write_iter+0x264/0x3c0 fs/kernfs/file.c:352 > new_sync_write fs/read_write.c:595 [inline] > vfs_write+0x52c/0xa14 fs/read_write.c:688 > ksys_write+0x12c/0x224 fs/read_write.c:740 > __do_sys_write fs/read_write.c:751 [inline] > __se_sys_write fs/read_write.c:748 [inline] > __arm64_sys_write+0x7c/0x90 fs/read_write.c:748 > __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline] > invoke_syscall+0x98/0x244 arch/arm64/kernel/syscall.c:49 > el0_svc_common+0xe8/0x23c arch/arm64/kernel/syscall.c:121 > do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:140 > el0_svc+0x60/0x25c arch/arm64/kernel/entry-common.c:723 > el0t_64_sync_handler+0x48/0x148 arch/arm64/kernel/entry-common.c:742 > el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:594 > INFO: task syz-executor:4812 blocked for more than 143 seconds. > Not tainted syzkaller #0 > "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. > task:syz-executor state:D stack:0 pid:4812 tgid:4812 ppid:1 task_flags:0x400140 flags:0x00800001 > Call trace: > __switch_to+0x2b0/0x6e0 arch/arm64/kernel/process.c:810 (T) > context_switch kernel/sched/core.c:5387 [inline] > __schedule+0x1b74/0x2d24 kernel/sched/core.c:7188 > __schedule_loop kernel/sched/core.c:7267 [inline] > schedule+0xa4/0x140 kernel/sched/core.c:7282 > schedule_preempt_disabled+0x18/0x2c kernel/sched/core.c:7339 > __mutex_lock_common+0x98c/0x20f4 kernel/locking/mutex.c:726 > __mutex_lock kernel/locking/mutex.c:820 [inline] > mutex_lock_nested+0x2c/0x38 kernel/locking/mutex.c:873 > del_device_store+0xd8/0x2d0 drivers/net/netdevsim/bus.c:234 > bus_attr_store+0x80/0xa4 drivers/base/bus.c:172 > sysfs_kf_write+0xe0/0x108 fs/sysfs/file.c:142 > kernfs_fop_write_iter+0x264/0x3c0 fs/kernfs/file.c:352 > new_sync_write fs/read_write.c:595 [inline] > vfs_write+0x52c/0xa14 fs/read_write.c:688 > ksys_write+0x12c/0x224 fs/read_write.c:740 > __do_sys_write fs/read_write.c:751 [inline] > __se_sys_write fs/read_write.c:748 [inline] > __arm64_sys_write+0x7c/0x90 fs/read_write.c:748 > __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline] > invoke_syscall+0x98/0x244 arch/arm64/kernel/syscall.c:49 > el0_svc_common+0xe8/0x23c arch/arm64/kernel/syscall.c:121 > do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:140 > el0_svc+0x60/0x25c arch/arm64/kernel/entry-common.c:723 > el0t_64_sync_handler+0x48/0x148 arch/arm64/kernel/entry-common.c:742 > el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:594 > > Showing all locks held in the system: > 3 locks held by kworker/u8:0/12: > 1 lock held by khungtaskd/31: > #0: ffff800088ac66e0 (rcu_read_lock){....}-{1:3}, at: __ll_sc_atomic64_fetch_or arch/arm64/include/asm/atomic_ll_sc.h:-1 [inline] > #0: ffff800088ac66e0 (rcu_read_lock){....}-{1:3}, at: arch_atomic64_fetch_or arch/arm64/include/asm/atomic.h:86 [inline] > #0: ffff800088ac66e0 (rcu_read_lock){....}-{1:3}, at: raw_atomic64_fetch_or include/linux/atomic/atomic-arch-fallback.h:3816 [inline] > #0: ffff800088ac66e0 (rcu_read_lock){....}-{1:3}, at: raw_atomic_long_fetch_or include/linux/atomic/atomic-long.h:1090 [inline] > #0: ffff800088ac66e0 (rcu_read_lock){....}-{1:3}, at: arch_test_and_set_bit include/asm-generic/bitops/atomic.h:42 [inline] > #0: ffff800088ac66e0 (rcu_read_lock){....}-{1:3}, at: test_and_set_bit include/asm-generic/bitops/instrumented-atomic.h:72 [inline] > #0: ffff800088ac66e0 (rcu_read_lock){....}-{1:3}, at: rcu_lock_acquire+0x0/0x44 kernel/sched/sched.h:3869 > 8 locks held by kworker/u8:3/40: > 4 locks held by pr/ttyAMA-1/41: > 3 locks held by kworker/u8:5/1188: > 3 locks held by kworker/u8:6/1389: > 3 locks held by kworker/u8:7/1910: > 1 lock held by klogd/4292: > 3 locks held by udevd/4303: > 3 locks held by dhcpcd/4359: > 2 locks held by getty/4451: > #0: ffff0000d3bfb0a0 (&tty->ldisc_sem){++++}-{0:0}, at: ldsem_down_read+0x3c/0x4c drivers/tty/tty_ldsem.c:340 > #1: ffff80009228b2e8 (&ldata->atomic_read_lock){+.+.}-{4:4}, at: n_tty_read+0x354/0xf84 drivers/tty/n_tty.c:2211 > 3 locks held by kworker/1:3/4670: > #0: ffff0000c002b540 ((wq_completion)events){+.+.}-{0:0}, at: process_one_work+0x640/0x173c kernel/workqueue.c:3276 > #1: ffff8000966d7be0 (reg_work){+.+.}-{0:0}, at: process_one_work+0x6a4/0x173c kernel/workqueue.c:3276 > #2: ffff800089b85900 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_lock+0x20/0x2c net/core/rtnetlink.c:80 > 5 locks held by syz-executor/4797: > #0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: file_start_write include/linux/fs.h:2724 [inline] > #0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: vfs_write+0x240/0xa14 fs/read_write.c:684 > #1: ffff0000e8fb8880 (&of->mutex){+.+.}-{4:4}, at: kernfs_fop_write_iter+0x1b4/0x3c0 fs/kernfs/file.c:343 > #2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_get_active_of fs/kernfs/file.c:80 [inline] > #2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_fop_write_iter+0x1f4/0x3c0 fs/kernfs/file.c:344 > #3: ffff800089383240 (nsim_bus_dev_list_lock){+.+.}-{4:4}, at: del_device_store+0xd8/0x2d0 drivers/net/netdevsim/bus.c:234 > #4: ffff0000d7b8a128 (&dev->mutex){....}-{4:4}, at: device_lock include/linux/device.h:1040 [inline] > #4: ffff0000d7b8a128 (&dev->mutex){....}-{4:4}, at: device_del+0xa0/0x710 drivers/base/core.c:3857 > 4 locks held by syz-executor/4805: > #0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: file_start_write include/linux/fs.h:2724 [inline] > #0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: vfs_write+0x240/0xa14 fs/read_write.c:684 > #1: ffff0000eca42080 (&of->mutex){+.+.}-{4:4}, at: kernfs_fop_write_iter+0x1b4/0x3c0 fs/kernfs/file.c:343 > #2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_get_active_of fs/kernfs/file.c:80 [inline] > #2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_fop_write_iter+0x1f4/0x3c0 fs/kernfs/file.c:344 > #3: ffff800089383240 (nsim_bus_dev_list_lock){+.+.}-{4:4}, at: del_device_store+0xd8/0x2d0 drivers/net/netdevsim/bus.c:234 > 4 locks held by syz-executor/4809: > #0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: file_start_write include/linux/fs.h:2724 [inline] > #0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: vfs_write+0x240/0xa14 fs/read_write.c:684 > #1: ffff0000eca0f880 (&of->mutex){+.+.}-{4:4}, at: kernfs_fop_write_iter+0x1b4/0x3c0 fs/kernfs/file.c:343 > #2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_get_active_of fs/kernfs/file.c:80 [inline] > #2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_fop_write_iter+0x1f4/0x3c0 fs/kernfs/file.c:344 > #3: ffff800089383240 (nsim_bus_dev_list_lock){+.+.}-{4:4}, at: del_device_store+0xd8/0x2d0 drivers/net/netdevsim/bus.c:234 > 4 locks held by syz-executor/4812: > #0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: file_start_write include/linux/fs.h:2724 [inline] > #0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: vfs_write+0x240/0xa14 fs/read_write.c:684 > #1: ffff0000cd063c80 (&of->mutex){+.+.}-{4:4}, at: kernfs_fop_write_iter+0x1b4/0x3c0 fs/kernfs/file.c:343 > #2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_get_active_of fs/kernfs/file.c:80 [inline] > #2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_fop_write_iter+0x1f4/0x3c0 fs/kernfs/file.c:344 > #3: ffff800089383240 (nsim_bus_dev_list_lock){+.+.}-{4:4}, at: del_device_store+0xd8/0x2d0 drivers/net/netdevsim/bus.c:234 > 3 locks held by kworker/u8:11/4904: > #0: ffff0000ce706140 ((wq_completion)ipv6_addrconf){+.+.}-{0:0}, at: process_one_work+0x640/0x173c kernel/workqueue.c:3276 > #1: ffff8000995f7be0 ((work_completion)(&(&ifa->dad_work)->work)){+.+.}-{0:0}, at: process_one_work+0x6a4/0x173c kernel/workqueue.c:3276 > #2: ffff800089b85900 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_lock+0x20/0x2c net/core/rtnetlink.c:80 > 2 locks held by kworker/u8:12/4906: > 2 locks held by kworker/u8:13/4908: > 2 locks held by syz-executor/4913: > 2 locks held by syz-executor/4914: > > ============================================= > > > > --- > This report is generated by a bot. It may contain errors. > See https://goo.gl/tpsmEJ for more information about syzbot. > syzbot engineers can be reached at syzkaller@googlegroups.com. > > syzbot will keep track of this issue. See: > https://goo.gl/tpsmEJ#status for how to communicate with syzbot. > > If the report is already addressed, let syzbot know by replying with: > #syz fix: exact-commit-title > > If you want syzbot to run the reproducer, reply with: > #syz test: git://repo/address.git branch-or-commit-hash > If you attach or paste a git patch, syzbot will apply it before testing. > > If you want to overwrite report's subsystems, reply with: > #syz set subsystems: new-subsystem > (See the list of subsystem names on the web dashboard) > > If the report is a duplicate of another one, reply with: > #syz dup: exact-subject-of-another-report > > If you want to undo deduplication, reply with: > #syz undup > > -- > You received this message because you are subscribed to the Google Groups "syzkaller-bugs" group. > To unsubscribe from this group and stop receiving emails from it, send an email to syzkaller-bugs+unsubscribe@googlegroups.com. > To view this discussion visit https://groups.google.com/d/msgid/syzkaller-bugs/6a07b635.170a0220.df43.0000.GAE%40google.com. ^ permalink raw reply [flat|nested] 5+ messages in thread
[parent not found: <dbb04f94-8f95-4d04-ae64-bf4f5d134dff@windriver.com>]
* Re: [syzbot] [kernel?] INFO: task hung in nsim_bus_dev_del [not found] <dbb04f94-8f95-4d04-ae64-bf4f5d134dff@windriver.com> @ 2026-05-18 7:34 ` syzbot 0 siblings, 0 replies; 5+ messages in thread From: syzbot @ 2026-05-18 7:34 UTC (permalink / raw) To: linux-kernel, syzkaller-bugs, yun.zhou Hello, syzbot has tested the proposed patch but the reproducer is still triggering an issue: BUG: workqueue lockup BUG: workqueue lockup - pool cpus=0 node=0 flags=0x0 nice=0 stuck for 51s! Showing busy workqueues and worker pools: workqueue events: flags=0x100 pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=14 refcnt=15 pending: psi_avgs_work, delayed_vfree_work, psi_avgs_work, vmstat_shepherd, rht_deferred_worker, 3*nsim_dev_hwstats_traffic_work, ovs_dp_masks_rebalance, psi_avgs_work, 2*ovs_dp_masks_rebalance, free_obj_work, ovs_dp_masks_rebalance pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=9 refcnt=10 pending: 2*nsim_dev_hwstats_traffic_work, 6*ovs_dp_masks_rebalance, drm_fb_helper_damage_work workqueue events_long: flags=0x100 pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=7 refcnt=8 in-flight: 4777:defense_work_handler for 51s pending: 6*defense_work_handler pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=3 refcnt=4 pending: 3*defense_work_handler workqueue events_unbound: flags=0x2 pwq 8: cpus=0-1 flags=0x6 nice=0 active=1 refcnt=2 in-flight: 3589:call_usermodehelper_exec_work for 46s workqueue events_unbound: flags=0x2 pwq 8: cpus=0-1 flags=0x6 nice=0 active=8 refcnt=9 in-flight: 40:cfg80211_wiphy_work for 51s cfg80211_wiphy_work ,5470:cfg80211_wiphy_work for 25s ,14:cfg80211_wiphy_work for 39s cfg80211_wiphy_work pending: macvlan_process_broadcast, cfg80211_wiphy_work, crng_reseed pwq 8: cpus=0-1 flags=0x6 nice=0 active=14 refcnt=15 in-flight: 1284:cfg80211_wiphy_work for 52s cfg80211_wiphy_work ,908:cfg80211_wiphy_work for 52s cfg80211_wiphy_work ,12:cfg80211_wiphy_work for 52s cfg80211_wiphy_work pending: 2*nsim_dev_trap_report_work, flush_memcg_stats_dwork, 3*nsim_dev_trap_report_work, macvlan_process_broadcast, toggle_allocation_gate workqueue events_power_efficient: flags=0x182 pwq 8: cpus=0-1 flags=0x6 nice=0 active=1 refcnt=2 in-flight: 3735:crda_timeout_work for 51s pwq 8: cpus=0-1 flags=0x6 nice=0 active=6 refcnt=7 pending: neigh_managed_work, gc_worker, do_cache_clean, wg_ratelimiter_gc_entries, neigh_managed_work, neigh_periodic_work workqueue netns: flags=0x6000a pwq 8: cpus=0-1 flags=0x6 nice=0 active=1 refcnt=4 in-flight: 3273:cleanup_net for 55s workqueue mm_percpu_wq: flags=0x108 pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=1 refcnt=2 pending: vmstat_update pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=1 refcnt=2 pending: vmstat_update workqueue writeback: flags=0x4a pwq 8: cpus=0-1 flags=0x6 nice=0 active=1 refcnt=4 MAYDAY in-flight: 33(RESCUER):wb_workfn for 44s workqueue mld: flags=0x40108 pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=1 refcnt=20 pending: mld_dad_work inactive: 7*mld_ifc_work, mld_dad_work, 8*mld_ifc_work, 2*mld_dad_work pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=1 refcnt=76 in-flight: 856:mld_ifc_work for 10s inactive: 2*mld_ifc_work, 3*mld_dad_work, 4*mld_ifc_work, mld_dad_work, 2*mld_ifc_work, mld_dad_work, 5*mld_ifc_work, mld_dad_work, mld_ifc_work, 2*mld_dad_work, 13*mld_ifc_work, 2*mld_dad_work, mld_ifc_work, mld_dad_work, mld_ifc_work, 2*mld_dad_work, 2*mld_ifc_work, mld_dad_work, mld_ifc_work, mld_dad_work, 5*mld_ifc_work, 3*mld_dad_work, 2*mld_ifc_work, mld_dad_work, 2*mld_ifc_work, mld_dad_work, 3*mld_ifc_work, mld_dad_work, mld_ifc_work, mld_dad_work, 7*mld_ifc_work workqueue ipv6_addrconf: flags=0x6000a pwq 8: cpus=0-1 flags=0x6 nice=0 active=1 refcnt=270 in-flight: 3446:addrconf_dad_work for 53s inactive: 266*addrconf_dad_work workqueue bat_events: flags=0x6000a pwq 8: cpus=0-1 flags=0x6 nice=0 active=1 refcnt=50 MAYDAY in-flight: 2819(RESCUER):batadv_tt_purge for 9s pending: mayday_cursor_func inactive: 3*batadv_tt_purge, 2*batadv_iv_send_outstanding_bat_ogm_packet, 2*batadv_purge_orig, 2*batadv_iv_send_outstanding_bat_ogm_packet, 3*batadv_purge_orig, batadv_mcast_mla_update, 11*batadv_iv_send_outstanding_bat_ogm_packet, batadv_dat_purge, batadv_bla_periodic_work, batadv_dat_purge, batadv_bla_periodic_work, batadv_dat_purge, batadv_bla_periodic_work, batadv_dat_purge, batadv_bla_periodic_work, batadv_dat_purge, batadv_bla_periodic_work, batadv_dat_purge, batadv_bla_periodic_work, 5*batadv_mcast_mla_update, batadv_purge_orig, 2*batadv_tt_purge workqueue wg-crypt-wg0: flags=0x128 pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=3 refcnt=4 pending: wg_packet_encrypt_worker, wg_packet_tx_worker, wg_packet_decrypt_worker pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=1 refcnt=2 pending: wg_packet_decrypt_worker workqueue wg-crypt-wg1: flags=0x128 pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=3 refcnt=4 pending: wg_packet_encrypt_worker, wg_packet_decrypt_worker, wg_packet_tx_worker pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=1 refcnt=2 pending: wg_packet_decrypt_worker workqueue wg-crypt-wg2: flags=0x128 pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=3 refcnt=4 pending: wg_packet_encrypt_worker, wg_packet_decrypt_worker, wg_packet_tx_worker workqueue wg-kex-wg0: flags=0x124 pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=1 refcnt=2 pending: wg_packet_handshake_receive_worker pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=1 refcnt=2 in-flight: 4807:wg_packet_handshake_receive_worker for 12s workqueue wg-crypt-wg0: flags=0x128 pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=3 refcnt=4 pending: wg_packet_encrypt_worker, wg_packet_tx_worker, wg_packet_decrypt_worker pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=2 refcnt=3 pending: wg_packet_decrypt_worker, wg_packet_encrypt_worker workqueue wg-kex-wg1: flags=0x6 pwq 8: cpus=0-1 flags=0x6 nice=0 active=1 refcnt=2 pending: wg_packet_handshake_send_worker workqueue wg-crypt-wg1: flags=0x128 pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=3 refcnt=4 pending: wg_packet_encrypt_worker, wg_packet_decrypt_worker, wg_packet_tx_worker pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=2 refcnt=3 pending: wg_packet_decrypt_worker, wg_packet_encrypt_worker workqueue wg-kex-wg2: flags=0x124 pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=1 refcnt=2 pending: wg_packet_handshake_receive_worker workqueue wg-kex-wg2: flags=0x6 pwq 8: cpus=0-1 flags=0x6 nice=0 active=1 refcnt=2 pending: wg_packet_handshake_send_worker workqueue wg-crypt-wg2: flags=0x128 pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=2 refcnt=3 pending: wg_packet_encrypt_worker, wg_packet_tx_worker pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=1 refcnt=2 pending: wg_packet_tx_worker workqueue wg-kex-wg0: flags=0x6 pwq 8: cpus=0-1 flags=0x6 nice=0 active=1 refcnt=2 pending: wg_packet_handshake_send_worker workqueue wg-crypt-wg0: flags=0x128 pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=3 refcnt=4 pending: wg_packet_encrypt_worker, wg_packet_tx_worker, wg_packet_decrypt_worker pwq 6: cpus=1 node=0 flags=0x0 nice=0 active=1 refcnt=2 pending: wg_packet_encrypt_worker workqueue wg-crypt-wg1: flags=0x128 pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=3 refcnt=4 pending: wg_packet_tx_worker, wg_packet_decrypt_worker, wg_packet_encrypt_worker workqueue wg-kex-wg2: flags=0x6 pwq 8: cpus=0-1 flags=0x6 nice=0 active=1 refcnt=2 in-flight: 39:wg_packet_handshake_send_worker for 0s workqueue wg-crypt-wg2: flags=0x128 pwq 2: cpus=0 node=0 flags=0x0 nice=0 active=2 refcnt=3 pending: wg_packet_tx_worker, wg_packet_encrypt_worker pool 2: cpus=0 node=0 flags=0x0 nice=0 hung=51s workers=7 idle: 1482 1022 4703 10 5404 9 pool 6: cpus=1 node=0 flags=0x0 nice=0 hung=10s workers=6 idle: 24 5386 4814 26 pool 8: cpus=0-1 flags=0x6 nice=0 hung=0s workers=12 manager: 5472 Showing backtraces of busy workers in stalled worker pools: pool 2: task:kworker/0:5 state:R running task stack:0 pid:4777 tgid:4777 ppid:2 task_flags:0x4208060 flags:0x00000010 Workqueue: events_long defense_work_handler Call trace: __switch_to+0x2b0/0x6e0 arch/arm64/kernel/process.c:810 (T) context_switch kernel/sched/core.c:5387 [inline] __schedule+0x1b74/0x2d24 kernel/sched/core.c:7188 preempt_schedule_common+0xd4/0x190 kernel/sched/core.c:7369 preempt_schedule+0x60/0x78 kernel/sched/core.c:7393 __local_bh_enable_ip+0x20c/0x35c kernel/softirq.c:457 local_bh_enable+0x28/0x34 include/linux/bottom_half.h:33 update_defense_level+0x600/0x9ac net/netfilter/ipvs/ip_vs_ctl.c:210 defense_work_handler+0x30/0xdc net/netfilter/ipvs/ip_vs_ctl.c:235 process_one_work+0x78c/0x173c kernel/workqueue.c:3302 process_scheduled_works+0xdc/0x13c kernel/workqueue.c:3385 worker_thread+0x770/0xbd0 kernel/workqueue.c:3466 kthread+0x2f0/0x3c0 kernel/kthread.c:436 ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:842 Tested on: commit: 5cbb61bf arm64/fpsimd: ptrace: zero target's fpsimd_st.. git tree: git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git for-kernelci console output: https://syzkaller.appspot.com/x/log.txt?x=1608b02e580000 kernel config: https://syzkaller.appspot.com/x/.config?x=a834c6344141a58b dashboard link: https://syzkaller.appspot.com/bug?extid=1cf303af03cf30b1275a compiler: Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8 userspace arch: arm64 patch: https://syzkaller.appspot.com/x/patch.diff?x=173acd6a580000 ^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-05-18 7:34 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-05-16 0:11 [syzbot] [kernel?] INFO: task hung in nsim_bus_dev_del syzbot
2026-05-16 11:04 ` Hillf Danton
2026-05-16 12:35 ` syzbot
2026-05-18 6:58 ` Forwarded: " syzbot
[not found] <dbb04f94-8f95-4d04-ae64-bf4f5d134dff@windriver.com>
2026-05-18 7:34 ` syzbot
This is an external index of several public inboxes, see mirroring instructions on how to clone and mirror all data and code used by this external index.