All of lore.kernel.org
 help / color / mirror / Atom feed
From: syzbot <syzbot+1e3d934ee3cff1ac188b@syzkaller.appspotmail.com>
To: dmantipov@yandex.ru, linux-kernel@vger.kernel.org,
	 syzkaller-bugs@googlegroups.com
Subject: Re: [syzbot] [fs?] general protection fault in start_dirop
Date: Wed, 29 Jul 2026 01:59:01 -0700	[thread overview]
Message-ID: <6a69c0d5.d9e86bb5.297b12.0059.GAE@google.com> (raw)
In-Reply-To: <37f96cb2-2570-4ae1-848b-c9dd6f042b78@yandex.ru>

Hello,

syzbot has tested the proposed patch but the reproducer is still triggering an issue:
INFO: task hung in dvb_usb_i2c_exit

INFO: task kworker/1:5:6361 blocked for more than 143 seconds.
      Not tainted syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:kworker/1:5     state:D stack:22408 pid:6361  tgid:6361  ppid:2      task_flags:0x4288060 flags:0x00080000
Workqueue: usb_hub_wq hub_event
Call Trace:
 <TASK>
 context_switch kernel/sched/core.c:5510 [inline]
 __schedule+0x125c/0x6730 kernel/sched/core.c:7234
 __schedule_loop kernel/sched/core.c:7311 [inline]
 schedule+0xdd/0x2c0 kernel/sched/core.c:7326
 schedule_timeout+0x1b2/0x280 kernel/time/sleep_timeout.c:75
 do_wait_for_common kernel/sched/completion.c:100 [inline]
 __wait_for_common+0x2e7/0x4c0 kernel/sched/completion.c:121
 i2c_del_adapter+0x1a6/0x2d0 drivers/i2c/i2c-core-base.c:1838
 dvb_usb_i2c_exit+0x9f/0xf0 drivers/media/usb/dvb-usb/dvb-usb-i2c.c:46
 dvb_usb_exit drivers/media/usb/dvb-usb/dvb-usb-init.c:144 [inline]
 dvb_usb_device_exit+0x313/0x520 drivers/media/usb/dvb-usb/dvb-usb-init.c:338
 usb_unbind_interface+0x1dd/0x9e0 drivers/usb/core/driver.c:458
 device_remove drivers/base/dd.c:618 [inline]
 device_remove+0x12a/0x180 drivers/base/dd.c:610
 __device_release_driver drivers/base/dd.c:1349 [inline]
 device_release_driver_internal+0x44e/0x620 drivers/base/dd.c:1372
 bus_remove_device+0x2bc/0x560 drivers/base/bus.c:664
 device_del+0x376/0x9b0 drivers/base/core.c:3961
 usb_disable_device+0x367/0x810 drivers/usb/core/message.c:1478
 usb_disconnect+0x2e2/0x9a0 drivers/usb/core/hub.c:2345
 hub_port_connect drivers/usb/core/hub.c:5407 [inline]
 hub_port_connect_change drivers/usb/core/hub.c:5707 [inline]
 port_event drivers/usb/core/hub.c:5871 [inline]
 hub_event+0x1c4f/0x4a60 drivers/usb/core/hub.c:5953
 process_one_work+0xa23/0x1940 kernel/workqueue.c:3322
 process_scheduled_works kernel/workqueue.c:3405 [inline]
 worker_thread+0x5ef/0xe50 kernel/workqueue.c:3486
 kthread+0x370/0x450 kernel/kthread.c:436
 ret_from_fork+0x72b/0xd50 arch/x86/kernel/process.c:158
 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
 </TASK>

Showing all locks held in the system:
6 locks held by kworker/3:0/34:
 #0: ffff8880231d9940 ((wq_completion)usb_hub_wq){+.+.}-{0:0}, at: process_one_work+0x12b1/0x1940 kernel/workqueue.c:3297
 #1: ffffc900006dfd08 ((work_completion)(&hub->events)){+.+.}-{0:0}, at: process_one_work+0x988/0x1940 kernel/workqueue.c:3298
 #2: ffff88802cd341d8 (&dev->mutex){....}-{4:4}, at: device_lock include/linux/device.h:1102 [inline]
 #2: ffff88802cd341d8 (&dev->mutex){....}-{4:4}, at: hub_event+0x1c0/0x4a60 drivers/usb/core/hub.c:5899
 #3: ffff88802cd49568 (&port_dev->status_lock){+.+.}-{4:4}, at: usb_lock_port drivers/usb/core/hub.c:3252 [inline]
 #3: ffff88802cd49568 (&port_dev->status_lock){+.+.}-{4:4}, at: hub_port_connect drivers/usb/core/hub.c:5464 [inline]
 #3: ffff88802cd49568 (&port_dev->status_lock){+.+.}-{4:4}, at: hub_port_connect_change drivers/usb/core/hub.c:5707 [inline]
 #3: ffff88802cd49568 (&port_dev->status_lock){+.+.}-{4:4}, at: port_event drivers/usb/core/hub.c:5871 [inline]
 #3: ffff88802cd49568 (&port_dev->status_lock){+.+.}-{4:4}, at: hub_event+0x2b25/0x4a60 drivers/usb/core/hub.c:5953
 #4: ffff88802cf28560 (hcd->address0_mutex){+.+.}-{4:4}, at: hub_port_connect drivers/usb/core/hub.c:5465 [inline]
 #4: ffff88802cf28560 (hcd->address0_mutex){+.+.}-{4:4}, at: hub_port_connect_change drivers/usb/core/hub.c:5707 [inline]
 #4: ffff88802cf28560 (hcd->address0_mutex){+.+.}-{4:4}, at: port_event drivers/usb/core/hub.c:5871 [inline]
 #4: ffff88802cf28560 (hcd->address0_mutex){+.+.}-{4:4}, at: hub_event+0x2b4e/0x4a60 drivers/usb/core/hub.c:5953
 #5: ffffffff90055328 (ehci_cf_port_reset_rwsem){++++}-{4:4}, at: hub_port_reset+0x1a1/0x1bd0 drivers/usb/core/hub.c:3067
1 lock held by khungtaskd/43:
 #0: ffffffff8ebe8180 (rcu_read_lock){....}-{1:3}, at: rcu_lock_acquire include/linux/rcupdate.h:300 [inline]
 #0: ffffffff8ebe8180 (rcu_read_lock){....}-{1:3}, at: rcu_read_lock include/linux/rcupdate.h:840 [inline]
 #0: ffffffff8ebe8180 (rcu_read_lock){....}-{1:3}, at: debug_show_all_locks+0x3d/0x184 kernel/locking/lockdep.c:6775
3 locks held by kworker/2:1/58:
 #0: ffff8880231d9940 ((wq_completion)usb_hub_wq){+.+.}-{0:0}, at: process_one_work+0x12b1/0x1940 kernel/workqueue.c:3297
 #1: ffffc90000abfd08 ((work_completion)(&hub->events)){+.+.}-{0:0}, at: process_one_work+0x988/0x1940 kernel/workqueue.c:3298
 #2: ffff88816dbd21d8 (&dev->mutex){....}-{4:4}, at: device_lock include/linux/device.h:1102 [inline]
 #2: ffff88816dbd21d8 (&dev->mutex){....}-{4:4}, at: hub_event+0x1c0/0x4a60 drivers/usb/core/hub.c:5899
5 locks held by kworker/0:2/847:
2 locks held by getty/5534:
 #0: ffff88802bc640a0 (&tty->ldisc_sem){++++}-{0:0}, at: tty_ldisc_ref_wait+0x24/0x80 drivers/tty/tty_ldisc.c:243
 #1: ffffc900033832e8 (&ldata->atomic_read_lock){+.+.}-{4:4}, at: n_tty_read+0x419/0x14e0 drivers/tty/n_tty.c:2211
5 locks held by kworker/1:5/6361:
 #0: ffff8880231d9940 ((wq_completion)usb_hub_wq){+.+.}-{0:0}, at: process_one_work+0x12b1/0x1940 kernel/workqueue.c:3297
 #1: ffffc9000291fd08 ((work_completion)(&hub->events)){+.+.}-{0:0}, at: process_one_work+0x988/0x1940 kernel/workqueue.c:3298
 #2: ffff88802ca3b1d8 (
&dev->mutex){....}-{4:4}, at: device_lock include/linux/device.h:1102 [inline]
&dev->mutex){....}-{4:4}, at: hub_event+0x1c0/0x4a60 drivers/usb/core/hub.c:5899
 #3: ffff888035c711d8 (&dev->mutex){....}-{4:4}, at: device_lock include/linux/device.h:1102 [inline]
 #3: ffff888035c711d8 (&dev->mutex){....}-{4:4}, at: usb_disconnect+0x10a/0x9a0 drivers/usb/core/hub.c:2336
 #4: ffff888035c761a0 (&dev->mutex){....}-{4:4}, at: device_lock include/linux/device.h:1102 [inline]
 #4: ffff888035c761a0 (&dev->mutex){....}-{4:4}, at: __device_driver_lock drivers/base/dd.c:1171 [inline]
 #4: ffff888035c761a0 (&dev->mutex){....}-{4:4}, at: device_release_driver_internal+0xb2/0x620 drivers/base/dd.c:1369
4 locks held by udevd/6479:
 #0: ffff88802dfe4638 (&p->lock){+.+.}-{4:4}, at: seq_read_iter+0xe1/0x1270 fs/seq_file.c:183
 #1: ffff88803ea13480 (&of->mutex#2){+.+.}-{4:4}, at: kernfs_seq_start+0x4f/0x2a0 fs/kernfs/file.c:165
 #2: ffff88805886f878 (kn->active#19){++++}-{0:0}, at: kernfs_get_active_of fs/kernfs/file.c:73 [inline]
 #2: ffff88805886f878 (kn->active#19){++++}-{0:0}, at: kernfs_seq_start+0xbc/0x2a0 fs/kernfs/file.c:166
 #3: ffff888035c711d8 (&dev->mutex){....}-{4:4}, at: device_lock_interruptible include/linux/device.h:1107 [inline]
 #3: ffff888035c711d8 (&dev->mutex){....}-{4:4}, at: manufacturer_show+0x26/0xa0 drivers/usb/core/sysfs.c:142

=============================================

NMI backtrace for cpu 1
CPU: 1 UID: 0 PID: 43 Comm: khungtaskd Not tainted syzkaller #0 PREEMPT(full) 
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Call Trace:
 <TASK>
 __dump_stack lib/dump_stack.c:94 [inline]
 dump_stack_lvl+0x100/0x190 lib/dump_stack.c:120
 nmi_cpu_backtrace.cold+0x12d/0x151 lib/nmi_backtrace.c:122
 nmi_trigger_cpumask_backtrace+0x21c/0x2a0 lib/nmi_backtrace.c:65
 trigger_all_cpu_backtrace include/linux/nmi.h:162 [inline]
 __sys_info lib/sys_info.c:157 [inline]
 sys_info+0x141/0x190 lib/sys_info.c:165
 check_hung_uninterruptible_tasks kernel/hung_task.c:353 [inline]
 watchdog+0xcb1/0x1030 kernel/hung_task.c:561
 kthread+0x370/0x450 kernel/kthread.c:436
 ret_from_fork+0x72b/0xd50 arch/x86/kernel/process.c:158
 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
 </TASK>
Sending NMI from CPU 1 to CPUs 0,2-3:
NMI backtrace for cpu 3
CPU: 3 UID: 0 PID: 34 Comm: kworker/3:0 Not tainted syzkaller #0 PREEMPT(full) 
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Workqueue: usb_hub_wq hub_event
RIP: 0010:set_idle_cores kernel/sched/fair.c:8425 [inline]
RIP: 0010:select_idle_cpu kernel/sched/fair.c:8597 [inline]
RIP: 0010:select_idle_sibling kernel/sched/fair.c:8909 [inline]
RIP: 0010:select_task_rq_fair+0x2ef3/0x5400 kernel/sched/fair.c:9606
Code: 48 89 f9 48 c1 e9 03 80 3c 01 00 0f 85 4d 1c 00 00 49 8b 84 24 40 0d 00 00 89 6c 24 50 45 89 f5 48 89 44 24 48 e9 9f e8 ff ff <48> c7 c3 a8 86 64 94 48 83 7c 24 10 08 0f 83 67 1f 00 00 48 b8 00
RSP: 0018:ffffc900006f8be8 EFLAGS: 00000002
RAX: 0000000000000004 RBX: ffff88806a7243f8 RCX: 0000000000000040
RDX: 0000000000000000 RSI: 1ffff1100d4e487f RDI: ffff88806a7243f8
RBP: ffffffff91227dc0 R08: ffff88806a7243f8 R09: ffff88806a620c88
R10: dffffc0000000000 R11: 0000000000000000 R12: 0000000000000004
R13: 0000000000000002 R14: 0000000000000003 R15: dffffc0000000000
FS:  0000000000000000(0000) GS:ffff8880d60dc000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000559b350e0608 CR3: 0000000035096000 CR4: 0000000000352ef0
Call Trace:
 <IRQ>
 select_task_rq kernel/sched/core.c:3619 [inline]
 try_to_wake_up+0xaa2/0x1c90 kernel/sched/core.c:4393
 hrtimer_wakeup+0x47/0x60 kernel/time/hrtimer.c:2293
 __run_hrtimer kernel/time/hrtimer.c:2032 [inline]
 __hrtimer_run_queues+0x462/0x9c0 kernel/time/hrtimer.c:2096
 hrtimer_interrupt+0x3e5/0x940 kernel/time/hrtimer.c:2215
 local_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1051 [inline]
 __sysvec_apic_timer_interrupt+0x109/0x470 arch/x86/kernel/apic/apic.c:1068
 instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1062 [inline]
 sysvec_apic_timer_interrupt+0x9e/0xc0 arch/x86/kernel/apic/apic.c:1062
 </IRQ>
 <TASK>
 asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:674
RIP: 0010:console_trylock_spinning kernel/printk/printk.c:2039 [inline]
RIP: 0010:vprintk_emit+0x553/0x6b0 kernel/printk/printk.c:2478
Code: 00 4d 85 ed 0f 85 1b 01 00 00 e8 38 af 21 00 9c 5d 81 e5 00 02 00 00 31 ff 48 89 ee e8 c6 a9 21 00 48 85 ed 0f 85 27 01 00 00 <e8> 18 af 21 00 45 31 c9 41 b8 01 00 00 00 31 c9 48 8d 05 00 00 00
RSP: 0018:ffffc900006df518 EFLAGS: 00000293
RAX: 0000000000000000 RBX: 000000000000003d RCX: ffffffff81e8b23a
RDX: ffff88801f6ca540 RSI: ffffffff81e8b244 RDI: ffff88801f6ca540
RBP: 0000000000000000 R08: 0000000000000007 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: 1ffff920000dbea5
R13: 0000000000000200 R14: ffff88801cfb8000 R15: ffffc900006df6d8
 dev_vprintk_emit+0x391/0x3e0 drivers/base/core.c:4996
 dev_printk_emit+0xd2/0x10d drivers/base/core.c:5007
 __dev_printk+0xcb/0x100 drivers/base/core.c:5019
 _dev_notice+0xef/0x130 drivers/base/core.c:5064
 usb_get_bos_descriptor.cold+0x40/0xb4 drivers/usb/core/config.c:1051
 hub_port_init+0x1e37/0x37f0 drivers/usb/core/hub.c:5207
 hub_port_connect drivers/usb/core/hub.c:5496 [inline]
 hub_port_connect_change drivers/usb/core/hub.c:5707 [inline]
 port_event drivers/usb/core/hub.c:5871 [inline]
 hub_event+0x2e7d/0x4a60 drivers/usb/core/hub.c:5953
 process_one_work+0xa23/0x1940 kernel/workqueue.c:3322
 process_scheduled_works kernel/workqueue.c:3405 [inline]
 worker_thread+0x5ef/0xe50 kernel/workqueue.c:3486
 kthread+0x370/0x450 kernel/kthread.c:436
 ret_from_fork+0x72b/0xd50 arch/x86/kernel/process.c:158
 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
 </TASK>
NMI backtrace for cpu 0
CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT(full) 
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:pv_native_safe_halt+0xf/0x20 arch/x86/kernel/paravirt.c:64
Code: d6 8b 02 c3 cc cc cc cc 0f 1f 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa eb 07 0f 00 2d c3 7e 10 00 fb f4 <e9> 3c 4a 03 00 66 2e 0f 1f 84 00 00 00 00 00 66 90 90 90 90 90 90
RSP: 0018:ffffffff8e807e10 EFLAGS: 00000206
RAX: 000000000049aca9 RBX: ffffffff8e891480 RCX: ffffffff8bbb22d5
RDX: 0000000000000000 RSI: ffffffff8e1a5f27 RDI: ffffffff8c401680
RBP: fffffbfff1d12290 R08: 0000000000000001 R09: ffffed100d48678d
R10: ffff88806a433c6b R11: 0000000000000000 R12: 0000000000000000
R13: 0000000000000000 R14: 1ffffffff1d00fc6 R15: dffffc0000000000
FS:  0000000000000000(0000) GS:ffff8880d5ddc000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000559b350da038 CR3: 000000002878b000 CR4: 0000000000352ef0
Call Trace:
 <TASK>
 arch_safe_halt arch/x86/include/asm/paravirt.h:62 [inline]
 default_idle+0x9/0x10 arch/x86/kernel/process.c:768
 default_idle_call+0x6c/0xb0 kernel/sched/idle.c:122
 cpuidle_idle_call kernel/sched/idle.c:199 [inline]
 do_idle+0x3a7/0x5b0 kernel/sched/idle.c:355
 cpu_startup_entry+0x4f/0x60 kernel/sched/idle.c:454
 rest_init+0x251/0x260 init/main.c:717
 start_kernel+0x48e/0x490 init/main.c:1175
 x86_64_start_reservations+0x24/0x30 arch/x86/kernel/head64.c:310
 x86_64_start_kernel+0x12b/0x130 arch/x86/kernel/head64.c:291
 common_startup_64+0x13e/0x158
 </TASK>
NMI backtrace for cpu 2
CPU: 2 UID: 0 PID: 0 Comm: swapper/2 Not tainted syzkaller #0 PREEMPT(full) 
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:pv_native_safe_halt+0xf/0x20 arch/x86/kernel/paravirt.c:64
Code: d6 8b 02 c3 cc cc cc cc 0f 1f 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa eb 07 0f 00 2d c3 7e 10 00 fb f4 <e9> 3c 4a 03 00 66 2e 0f 1f 84 00 00 00 00 00 66 90 90 90 90 90 90
RSP: 0018:ffffc90000187e00 EFLAGS: 00000206
RAX: 00000000004489e7 RBX: ffff88801eed4a80 RCX: ffffffff8bbb22d5
RDX: 0000000000000000 RSI: ffffffff8e1a5f27 RDI: ffffffff8c401680
RBP: ffffed1003dda950 R08: 0000000000000001 R09: ffffed100d4c678d
R10: ffff88806a633c6b R11: 0000000000000000 R12: 0000000000000000
R13: 0000000000000000 R14: 1ffff92000030fc4 R15: dffffc0000000000
FS:  0000000000000000(0000) GS:ffff8880d5fdc000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000559b350e3038 CR3: 0000000034909000 CR4: 0000000000352ef0
Call Trace:
 <TASK>
 arch_safe_halt arch/x86/include/asm/paravirt.h:62 [inline]
 default_idle+0x9/0x10 arch/x86/kernel/process.c:768
 default_idle_call+0x6c/0xb0 kernel/sched/idle.c:122
 cpuidle_idle_call kernel/sched/idle.c:199 [inline]
 do_idle+0x3a7/0x5b0 kernel/sched/idle.c:355
 cpu_startup_entry+0x4f/0x60 kernel/sched/idle.c:454
 start_secondary+0x21d/0x2d0 arch/x86/kernel/smpboot.c:312
 common_startup_64+0x13e/0x158
 </TASK>


Tested on:

commit:         fc02acf6 Merge tag 'platform-drivers-x86-v7.2-4' of gi..
git tree:       https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
console output: https://syzkaller.appspot.com/x/log.txt?x=133938c6580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=145fa60d73086782
dashboard link: https://syzkaller.appspot.com/bug?extid=1e3d934ee3cff1ac188b
compiler:       gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
patch:          https://syzkaller.appspot.com/x/patch.diff?x=128bf8c6580000


       reply	other threads:[~2026-07-29  8:59 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <37f96cb2-2570-4ae1-848b-c9dd6f042b78@yandex.ru>
2026-07-29  8:59 ` syzbot [this message]
     [not found] <7faac2ae-e151-49d6-827c-b496de1808cf@windriver.com>
2026-07-29 15:26 ` [syzbot] [fs?] general protection fault in start_dirop syzbot
     [not found] <d17980db-eb0a-4b0e-b4ab-ed907457ac22@windriver.com>
2026-07-29 14:28 ` syzbot
2026-07-29  0:19 syzbot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=6a69c0d5.d9e86bb5.297b12.0059.GAE@google.com \
    --to=syzbot+1e3d934ee3cff1ac188b@syzkaller.appspotmail.com \
    --cc=dmantipov@yandex.ru \
    --cc=linux-kernel@vger.kernel.org \
    --cc=syzkaller-bugs@googlegroups.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.