From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f54.google.com (mail-wm1-f54.google.com [209.85.128.54]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1D98723EAAF for ; Wed, 7 Jan 2026 12:34:56 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.54 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1767789299; cv=none; b=dFRiZ04HXRgRTQpzdwAWoOeQGKjJPkp+hPmcynwYO6tntDzpCfdmaLYW6stXabw/Y2Oh3zu3lLSYR3t8o8dPSqpJ4yaCbAz4jfdGpEP0ZKBpzal36COhhW5mG0Idm9CwXMaWBzjsPExDB1NTgd5QXDxCtw+y8uwvXytu2iyZ51Y= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1767789299; c=relaxed/simple; bh=HlKHLPUjZGpN+OEguPuZq/Hgn9nOtyUi7w9SbHYEods=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=ZeVIxYwD4XwUO0Walnup4+bUbXyFSTbbDa3Bs54bIc6ZQmF9wiMAtGxHTvzYBrv04ZFjjgfLSkV/OhC2EVuinRArK8Bgw0KF1TV6fQctW5c6MpOMflPmjIExgHPF9wLBtMpMzOae3NjmP82pp1YvSTgrDmAs2gQSqF7cLVEN6uc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=suse.com; spf=pass smtp.mailfrom=suse.com; dkim=pass (2048-bit key) header.d=suse.com header.i=@suse.com header.b=DkcWK8pP; arc=none smtp.client-ip=209.85.128.54 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=suse.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=suse.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=suse.com header.i=@suse.com header.b="DkcWK8pP" Received: by mail-wm1-f54.google.com with SMTP id 5b1f17b1804b1-47aa03d3326so17103595e9.3 for ; Wed, 07 Jan 2026 04:34:56 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.com; s=google; t=1767789295; x=1768394095; darn=vger.kernel.org; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=/O0QIr4XB4PDPLv27IcTHdbomvfQvv+C4iIgEywE5i0=; b=DkcWK8pPCxqn/VHSEiKlGpnFR6lM7lrChdVX0ou4ae62OroVz+6yHhHa9J2Wqem0Xd U+kxbUIrk9eU997ZxlDcWIqDxZAY9VZ13Ac8wpp2LdKZhvAPhY59YqhfGmPkwnH89b0H DkWaWxikL11t6PxMz1RzT1FzZkl6lPv7rUaVvDe7BBT/2sVb1Zk7RbQm02EU3WQlPego rMglBUh1e8Sv3Gyt2wXm3f1vhRcMW6jCVJANBzG1SqsfwaPxHVo79iRLjuy8EzhcMbSo f38C5r2XLHSPKik68QWhVaBqsbdB63IATKJP2Om9m36gJFGys6wVmQ6uN8i+ibJJxeZI KwKw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1767789295; x=1768394095; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=/O0QIr4XB4PDPLv27IcTHdbomvfQvv+C4iIgEywE5i0=; b=oF3zOINbPseyyfJsGUWBLHifsft80nMZ//DevO8XIQtYkdyq9xi4SEe8gsySmaRwyu IAW3Ogw1oigyiu3jGiYvlPvnVozOLHzTn+XPdHC7+o/9SG050igXaKyu/N+2XLjpltHP B6iOfXuhq8rhJbsNmiFCFpdXaqCc1NHgvUlPmkRYO//TT1mmgWNnCy29XMEA1kSgRAW7 lAEAHl9RfVc6uCmORi2SUvQynclskGU24ch5meGY3P/0bRVv2sKrleKwUMJsalUM8O1j KYvbbETpnYCCkuG0cFQXGmq6n/3G2xpOlqxvgnDqYUUxdo/emld3OJgjkeaOFQZ/mI3T uKEw== X-Forwarded-Encrypted: i=1; AJvYcCVfIuW9AItHPTrCSIZMdGL5RH1QbARASb0x2qtiNQXsPvWRDKLT/Lmw32v0zNXb47yOijJ/lFAH1DGmYAs=@vger.kernel.org X-Gm-Message-State: AOJu0YwfjPi2zxAs1nXA+qOqiOBxgibXzfV700gNXuUAt7GAfmDx3E+a wagKfDB/e6+giGWtgA07HmCDzwnDbCTwJjVWEhGkV/Z5BhrYBnFV0HRrpyg+72cszGY= X-Gm-Gg: AY/fxX7XMd0Nxg/hnco7+ohpmR62Sx/kP147T2cyAbE0l5OyAnGUiTG8Nu2TuKQtKZ4 +3pPYa3oaRFEDJazavWSgEpLDjpjUstK339Hch1UUkpWeBaKn42WTVa/7Jze5pVZEOTPo+4fAyX oyEN0oYjkefIHA771AqwBlIE4keIPhkp2U0qmjhZ1H2pC8ixqhb1dvbiNrwJiUDV1hYieUbPts8 MWnB6+TIhrvUVabyyPNgQ3gcao7oMr5Z/4XXxbxuEA/lLfvy5vntazfhiCHAp9zWvljrcjwkN+O X5EJ1yQ7+PBtIL4ntu2v+28WzoweO7YRdlY4RcUcvcJfmRSSUxykWIVhnQRmi+5AnqDPmHAeYG/ XDHOPzisNtA3kINE8HbZShtLmv6zFEJCndsQlMMGXx9FSTeFVNeJB4EQs348r8Y3548L+EFWNhG g0x/JD1fA45y+7Cw== X-Google-Smtp-Source: AGHT+IFgZ3pI+sztcm8O/5H/FBnuysGF6rwHzmuuAJs7EFdsa0AGubME1KpoIGr0aNX4ex7zKXPMGg== X-Received: by 2002:a05:600c:8b6d:b0:47a:814c:eea1 with SMTP id 5b1f17b1804b1-47d84b4a7b4mr26418045e9.35.1767789295261; Wed, 07 Jan 2026 04:34:55 -0800 (PST) Received: from pathway.suse.cz ([176.114.240.130]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-47d8702534dsm12966485e9.2.2026.01.07.04.34.53 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 07 Jan 2026 04:34:54 -0800 (PST) Date: Wed, 7 Jan 2026 13:34:52 +0100 From: Petr Mladek To: John Ogness Cc: syzbot , linux-kernel@vger.kernel.org, rostedt@goodmis.org, senozhatsky@chromium.org, syzkaller-bugs@googlegroups.com Subject: Re: [syzbot] [kernel?] Internal error in div_u64_rem (4) Message-ID: References: <695569e0.050a0220.a1b6.0321.GAE@google.com> <87eco1hhxl.fsf@jogness.linutronix.de> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <87eco1hhxl.fsf@jogness.linutronix.de> On Wed 2026-01-07 10:54:38, John Ogness wrote: > On 2025-12-31, syzbot wrote: > > syzbot found the following issue on: > > > > HEAD commit: c8ebd433459b Merge tag 'nfsd-6.19-2' of git://git.kernel.o.. > > git tree: upstream > > console output: https://syzkaller.appspot.com/x/log.txt?x=15caa7da580000 > > kernel config: https://syzkaller.appspot.com/x/.config?x=e5753ed355722af > > dashboard link: https://syzkaller.appspot.com/bug?extid=22a26d9b6c0a64335bf7 > > compiler: arm-linux-gnueabi-gcc (Debian 12.2.0-14) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40 > > userspace arch: arm > > > > Unfortunately, I don't have any reproducer for this issue yet. > > > > Downloadable assets: > > disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/98a89b9f34e4/non_bootable_disk-c8ebd433.raw.xz > > vmlinux: https://storage.googleapis.com/syzbot-assets/fd848bb7d9d0/vmlinux-c8ebd433.xz > > kernel image: https://storage.googleapis.com/syzbot-assets/439934b22d51/zImage-c8ebd433.xz > > > > IMPORTANT: if you fix the issue, please add the following tag to the commit: > > Reported-by: syzbot+22a26d9b6c0a64335bf7@syzkaller.appspotmail.com > > > > Insufficient stack space to handle exception! > > Task stack: [0xeda4c000..0xeda4e000] > > IRQ stack: [0xdf804000..0xdf806000] > > Overflow stack: [0x830bc000..0x830bd000] > > Internal error: kernel stack overflow: 0 [#1] SMP ARM > > Modules linked in: > > CPU: 1 UID: 0 PID: 2128 Comm: syz-executor Tainted: G L syzkaller #0 PREEMPT > > Tainted: [L]=SOFTLOCKUP > > Hardware name: ARM-Versatile Express > > PC is at div_u64_rem+0x4/0x4c include/linux/math64.h:91 > > LR is at div_u64 include/linux/math64.h:130 [inline] > > LR is at ___update_load_avg kernel/sched/pelt.c:265 [inline] > > LR is at __update_load_avg_se+0x150/0x518 kernel/sched/pelt.c:312 > > pc : [<802abd9c>] lr : [<802b54f0>] psr: 20000193 > > sp : df804010 ip : df804010 fp : df80406c /> > r10: 00000000 r9 : 00000029 r8 : 0000b993 > > r7 : 85f68c00 r6 : 00000538 r5 : 00000000 r4 : 846c3e80 > > r3 : df804038 r2 : 0000b993 r1 : 00000000 r0 : 00000000 > > Flags: nzCv IRQs off FIQs on Mode SVC_32 ISA ARM Segment none > > Control: 30c5387d Table: 8612bb00 DAC: 00000000 > > Register r0 information: NULL pointer > > Register r1 information: NULL pointer > > Register r2 information: non-paged memory > > Register r3 information: 2-page vmalloc region starting at 0xdf804000 allocated at start_kernel+0x6b0/0x860 init/main.c:1111 > > Register r4 information: slab task_struct start 846c3c00 pointer offset 640 size 3072 > > Register r5 information: NULL pointer > > Register r6 information: non-paged memory > > Register r7 information: slab task_struct start 85f68c00 pointer offset 0 size 3072 > > Register r8 information: non-paged memory > > Register r9 information: non-paged memory > > Register r10 information: NULL pointer > > Register r11 information: 2-page vmalloc region starting at 0xdf804000 allocated at start_kernel+0x6b0/0x860 init/main.c:1111 > > Register r12 information: 2-page vmalloc region starting at 0xdf804000 allocated at start_kernel+0x6b0/0x860 init/main.c:1111 > > Process syz-executor (pid: 2128, stack limit = 0xeda4c000) > > Stack: (0xdf804010 to 0xdf806000) > > 4000: 00000018 00000000 9837f050 00000000 [...] > > 44c0: df804594 df8044e0 815cdeec 80203e84 8245bc84 85db88d8 00001501 85f68c00 ^^^^^^^^ [...] > > 5fc0: 8025be48 8025b9cc df805ffc df805fd8 81aaeb14 8025be44 81abcf40 60000013 > > 5fe0: ffffffff eda4dbac 82aed0d0 85f68c00 eda4db74 df806000 81a7eaa8 81aaeaa4 > > Call trace: frame pointer underflow [...] > > [<802e463c>] (vprintk) from [<80203ea8>] (_printk+0x34/0x58 kernel/printk/printk.c:2451) > > [<80203e74>] (_printk) from [<815cdeec>] (__dev_queue_xmit+0xcb4/0x1244 net/core/dev.c:4834) ^^^^^^^^ I wanted to double check whether printk() was responsible for eating the stack. It might use some buffers somewhere... If I get it correctly then "815cdeec" is the return address for printk(). And if I cound it correctly then printk was called when almost 7k from the 8k stack has already been used: stack size: 0x6000-0x4000 = 0x2000 = 8192 = 8k printk at: 0x6000-0x44c0 = 0x1b40 = 6976 remaining: 0x44c0-0x4000 = 0x4c0 = 1216 My conclusion is that printk() is _not_ the sinner here. > > r3:85f68c00 r2:00001501 r1:85db88d8 r0:8245bc84 > > Note that net/core/dev.c:4834 from __dev_queue_xmit() is: > > /* Recursion is detected! It is possible, > * unfortunately > */ > recursion_alert: > net_crit_ratelimited("Dead loop on virtual device %s, fix it urgently!\n", > dev->name); > Yeah, this seems to be the culprit. If I get it correctly then "81888f18" is the return address (__dev_queue_xmit) and I see it repeated more times on the stack... > > [<815cd238>] (__dev_queue_xmit) from [<81888f18>] (dev_queue_xmit include/linux/netdevice.h:3381 [inline]) ^^^^^^^^^ > > [<815cd238>] (__dev_queue_xmit) from [<81888f18>] (neigh_hh_output include/net/neighbour.h:540 [inline]) Best Regards, Petr