From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-oa1-f78.google.com (mail-oa1-f78.google.com [209.85.160.78]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D005031A558 for ; Wed, 4 Feb 2026 22:40:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.160.78 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1770244831; cv=none; b=sdDefEmkoeIm8gBhr84lAg96l70erOHvhsxkgf04FQUvaKyLbKk2fiIha/6ELZGlFlC48fT91mToLfcwhK9tW9rsgtydbO/v2hra82xey7Bgc1wTeRPNoVHaxydnqcLF0CbBApGapwXOu6JrDxXQXM5kaO2j7vDcqaetD9hXcjM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1770244831; c=relaxed/simple; bh=Bn8V/opUdUfJzf5dp9Bq0PwtEOu+x4MeW1cFHx1tirY=; h=MIME-Version:Date:Message-ID:Subject:From:To:Content-Type; b=sW82C/3GX9ovGvY76B/TQOHWoWG2dbqeLkbUeUallT/NVCbzS8PpoGNXaMuvRnSDfS54Ic3MEcU/wNNzHJ/o9VM9gNuo/7DnmELYZNwlnjfQKRyp8CwokzwtK2060n6VxccD1ESI6nnQFmOSQH4bML4Dko7Tk7eqZAVgBMi1kRc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com; arc=none smtp.client-ip=209.85.160.78 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com Received: by mail-oa1-f78.google.com with SMTP id 586e51a60fabf-4042a16a369so988474fac.2 for ; Wed, 04 Feb 2026 14:40:30 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1770244829; x=1770849629; h=to:from:subject:message-id:date:mime-version:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=RvSHQjc3fBobmQ1NoOAjfiWerb9Lj2dArl8aEW8jJv0=; b=SC8WYQVnjsHtM0yU5nALwj65J1sJAkFD/CYMxG0KrPp4kAwH7zXdfiuzIB6XS9MaF1 fHTrcQfmlKAcJIOmWctXw38IYhpHJfHZ42ncI1qUizrDspytF8qoT+SoEmwXhW99tMMT +hhtkkOmBvrxa1f5G9lijuge/rJVlPLxY1pZzjCDURUwY+DAKcwVS/kFA00UvKI7TXHy abLDA8UUwSf9d0SHv8kHSTDi4aKfMT90JJGm+Eyukfg7Xyh780Nbub4SEioH67hH4niU AGGWpWBJlrDHC4ZpDpZBM3YvR/hVCTEXcKilKifDJn/DItc27eNZ6WylwkIXZcU1v+G3 pk5A== X-Forwarded-Encrypted: i=1; AJvYcCV6ln8PAeveBtkji+HUQBfntF4JJ92f2U/3sUUT61hE0u7YuLCzrGNa74bJPOq6kLMuMSOLT+f/NCD7s08=@vger.kernel.org X-Gm-Message-State: AOJu0YyKaEOaDrpFO6MJW+Ln39kDNqaf+LvG0FIBwB3yVuCVSTq8Uuxi Qn+mh0PMN2H5g0Kxz389Q7UXNbiwOGxwsgeTZk4jyHsJ01GWqgb+P7LuMla7WhyjBlkBlu2ntWh //M09ZJo7+ykI1A6TrC7hJjv740cyIa4VVO9zC63IlmDc8orlIjDSFJ0Io8k= Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Received: by 2002:a05:6820:1c88:b0:662:bf42:b98e with SMTP id 006d021491bc7-66a200b8fb4mr2364671eaf.2.1770244829658; Wed, 04 Feb 2026 14:40:29 -0800 (PST) Date: Wed, 04 Feb 2026 14:40:29 -0800 X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <6983cadd.a00a0220.37c87e.0020.GAE@google.com> Subject: [syzbot] [kernel?] INFO: task hung in rxrpc_destroy_all_locals From: syzbot To: anna-maria@linutronix.de, frederic@kernel.org, linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com, tglx@kernel.org Content-Type: text/plain; charset="UTF-8" Hello, syzbot found the following issue on: HEAD commit: ad9a728a3388 Merge tag 'for-linus-iommufd' of git://git.ke.. git tree: upstream console output: https://syzkaller.appspot.com/x/log.txt?x=1710bbfa580000 kernel config: https://syzkaller.appspot.com/x/.config?x=df890e720d1bb80 dashboard link: https://syzkaller.appspot.com/bug?extid=5eb4cf50d2a64db5d9af compiler: gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44 Unfortunately, I don't have any reproducer for this issue yet. Downloadable assets: disk image: https://storage.googleapis.com/syzbot-assets/1b45335ce36e/disk-ad9a728a.raw.xz vmlinux: https://storage.googleapis.com/syzbot-assets/5c4122232bf5/vmlinux-ad9a728a.xz kernel image: https://storage.googleapis.com/syzbot-assets/7628c16f6157/bzImage-ad9a728a.xz IMPORTANT: if you fix the issue, please add the following tag to the commit: Reported-by: syzbot+5eb4cf50d2a64db5d9af@syzkaller.appspotmail.com INFO: task kworker/u8:5:196 blocked for more than 143 seconds. Tainted: G L syzkaller #0 "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. task:kworker/u8:5 state:D stack:25128 pid:196 tgid:196 ppid:2 task_flags:0x4208160 flags:0x00080000 Workqueue: netns cleanup_net Call Trace: context_switch kernel/sched/core.c:5260 [inline] __schedule+0xfe4/0x5e10 kernel/sched/core.c:6867 __schedule_loop kernel/sched/core.c:6949 [inline] schedule+0xdd/0x390 kernel/sched/core.c:6964 schedule_timeout+0x1b2/0x280 kernel/time/sleep_timeout.c:75 do_wait_for_common kernel/sched/completion.c:100 [inline] __wait_for_common+0x2e7/0x4c0 kernel/sched/completion.c:121 __flush_workqueue+0x3f7/0x1200 kernel/workqueue.c:4033 rxrpc_destroy_all_locals+0x3e/0x190 net/rxrpc/local_object.c:475 rxrpc_exit_net+0x8b/0xc0 net/rxrpc/net_ns.c:115 ops_exit_list net/core/net_namespace.c:199 [inline] ops_undo_list+0x2ee/0xab0 net/core/net_namespace.c:252 cleanup_net+0x419/0x830 net/core/net_namespace.c:696 process_one_work+0x9c2/0x1840 kernel/workqueue.c:3257 process_scheduled_works kernel/workqueue.c:3340 [inline] worker_thread+0x5da/0xe40 kernel/workqueue.c:3421 kthread+0x3b3/0x730 kernel/kthread.c:463 ret_from_fork+0x754/0xaf0 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:246 Showing all locks held in the system: 1 lock held by khungtaskd/31: #0: ffffffff8e5e3120 (rcu_read_lock){....}-{1:3}, at: rcu_lock_acquire include/linux/rcupdate.h:331 [inline] #0: ffffffff8e5e3120 (rcu_read_lock){....}-{1:3}, at: rcu_read_lock include/linux/rcupdate.h:867 [inline] #0: ffffffff8e5e3120 (rcu_read_lock){....}-{1:3}, at: debug_show_all_locks+0x3d/0x184 kernel/locking/lockdep.c:6775 3 locks held by kworker/u8:5/196: #0: ffff88801c29f148 ((wq_completion)netns){+.+.}-{0:0}, at: process_one_work+0x11ae/0x1840 kernel/workqueue.c:3232 #1: ffffc90003017c98 (net_cleanup_work){+.+.}-{0:0}, at: process_one_work+0x927/0x1840 kernel/workqueue.c:3233 #2: ffffffff903dcef0 (pernet_ops_rwsem){++++}-{4:4}, at: cleanup_net+0xab/0x830 net/core/net_namespace.c:670 2 locks held by getty/9827: #0: ffff888035bd80a0 (&tty->ldisc_sem){++++}-{0:0}, at: tty_ldisc_ref_wait+0x24/0x80 drivers/tty/tty_ldisc.c:243 #1: ffffc900044332f0 (&ldata->atomic_read_lock){+.+.}-{4:4}, at: n_tty_read+0x419/0x1500 drivers/tty/n_tty.c:2211 1 lock held by syz.1.1096/11746: #0: ffffffff903dcef0 (pernet_ops_rwsem){++++}-{4:4}, at: copy_net_ns+0x451/0x7c0 net/core/net_namespace.c:577 1 lock held by syz.3.1101/11791: #0: ffffffff903dcef0 (pernet_ops_rwsem){++++}-{4:4}, at: copy_net_ns+0x451/0x7c0 net/core/net_namespace.c:577 1 lock held by syz.6.1133/11923: #0: ffffffff903dcef0 (pernet_ops_rwsem){++++}-{4:4}, at: copy_net_ns+0x451/0x7c0 net/core/net_namespace.c:577 1 lock held by syz.9.1221/12496: #0: ffffffff903dcef0 (pernet_ops_rwsem){++++}-{4:4}, at: copy_net_ns+0x451/0x7c0 net/core/net_namespace.c:577 1 lock held by syz.5.1232/12548: #0: ffffffff903dcef0 (pernet_ops_rwsem){++++}-{4:4}, at: copy_net_ns+0x451/0x7c0 net/core/net_namespace.c:577 1 lock held by syz.2.1330/13262: #0: ffffffff903dcef0 (pernet_ops_rwsem){++++}-{4:4}, at: copy_net_ns+0x451/0x7c0 net/core/net_namespace.c:577 1 lock held by syz.8.1513/14257: #0: ffff8880a725aa48 (&sb->s_type->i_mutex_key#13){+.+.}-{4:4}, at: inode_lock include/linux/fs.h:1027 [inline] #0: ffff8880a725aa48 (&sb->s_type->i_mutex_key#13){+.+.}-{4:4}, at: __sock_release+0x86/0x260 net/socket.c:661 ============================================= NMI backtrace for cpu 1 CPU: 1 UID: 0 PID: 31 Comm: khungtaskd Tainted: G L syzkaller #0 PREEMPT(full) Tainted: [L]=SOFTLOCKUP Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/24/2026 Call Trace: __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x100/0x190 lib/dump_stack.c:120 nmi_cpu_backtrace.cold+0x12d/0x151 lib/nmi_backtrace.c:113 nmi_trigger_cpumask_backtrace+0x1d7/0x230 lib/nmi_backtrace.c:62 trigger_all_cpu_backtrace include/linux/nmi.h:161 [inline] __sys_info lib/sys_info.c:157 [inline] sys_info+0x141/0x190 lib/sys_info.c:165 check_hung_uninterruptible_tasks kernel/hung_task.c:346 [inline] watchdog+0xcc3/0xfe0 kernel/hung_task.c:515 kthread+0x3b3/0x730 kernel/kthread.c:463 ret_from_fork+0x754/0xaf0 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:246 Sending NMI from CPU 1 to CPUs 0: NMI backtrace for cpu 0 CPU: 0 UID: 0 PID: 14266 Comm: kworker/u11:33 Tainted: G L syzkaller #0 PREEMPT(full) Tainted: [L]=SOFTLOCKUP Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/24/2026 Workqueue: writeback wb_workfn (flush-8:0) RIP: 0010:__sanitizer_cov_trace_pc+0xb/0x70 kernel/kcov.c:213 Code: 5d 00 be 03 00 00 00 5b e9 f2 a8 de 02 66 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 65 8b 05 a5 85 dd 11 <48> 8b 34 24 65 48 8b 15 81 85 dd 11 a9 00 01 ff 00 74 1b f6 c4 01 RSP: 0018:ffffc90000007e10 EFLAGS: 00000002 RAX: 0000000080010002 RBX: ffffc90003e3fd60 RCX: ffffffff81f26bf4 RDX: 0000000000000001 RSI: 0000000000000000 RDI: ffff888032e55b80 RBP: ffff8880b84284c0 R08: 0000000000000001 R09: 0000000000000000 R10: 0000000000000001 R11: 0000000000000001 R12: 0000000000000001 R13: 0000000000000000 R14: ffff8880b8428440 R15: 0000000000000000 FS: 0000000000000000(0000) GS:ffff8881245e3000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f41649e3358 CR3: 0000000076524000 CR4: 00000000003526f0 Call Trace: __remove_hrtimer+0x92/0x2a0 kernel/time/hrtimer.c:1114 __run_hrtimer kernel/time/hrtimer.c:1757 [inline] __hrtimer_run_queues+0x40c/0x990 kernel/time/hrtimer.c:1841 hrtimer_interrupt+0x397/0x8c0 kernel/time/hrtimer.c:1903 local_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1045 [inline] __sysvec_apic_timer_interrupt+0x109/0x3c0 arch/x86/kernel/apic/apic.c:1062 instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1056 [inline] sysvec_apic_timer_interrupt+0x9e/0xc0 arch/x86/kernel/apic/apic.c:1056 asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:697 RIP: 0010:console_trylock_spinning kernel/printk/printk.c:2037 [inline] RIP: 0010:vprintk_emit+0x553/0x6b0 kernel/printk/printk.c:2425 Code: 00 4d 85 ed 0f 85 1b 01 00 00 e8 c8 07 21 00 9c 5d 81 e5 00 02 00 00 31 ff 48 89 ee e8 96 02 21 00 48 85 ed 0f 85 27 01 00 00 a8 07 21 00 45 31 c9 41 b8 01 00 00 00 31 c9 48 8d 05 00 00 00 RSP: 0018:ffffc9000480eee0 EFLAGS: 00000293 RAX: 0000000000000000 RBX: 0000000000000074 RCX: ffffffff81e543ea RDX: ffff888032e55b80 RSI: ffffffff81e543f4 RDI: ffff888032e55b80 RBP: 0000000000000000 R08: 0000000000000007 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000000 R12: 1ffff92000901dde R13: 0000000000000200 R14: ffff88801e6d9e80 R15: ffffc9000480efa8 _printk+0xcf/0x110 kernel/printk/printk.c:2451 __ext4_msg.cold+0x9f/0xa1 fs/ext4/super.c:990 mpage_map_and_submit_extent fs/ext4/inode.c:2499 [inline] ext4_do_writepages+0x2e28/0x3df0 fs/ext4/inode.c:2932 ext4_writepages+0x347/0x790 fs/ext4/inode.c:3026 do_writepages+0x278/0x600 mm/page-writeback.c:2598 __writeback_single_inode+0x164/0x13c0 fs/fs-writeback.c:1737 writeback_sb_inodes+0x72e/0x1b90 fs/fs-writeback.c:2030 __writeback_inodes_wb+0xf8/0x2d0 fs/fs-writeback.c:2107 wb_writeback+0x6b4/0xab0 fs/fs-writeback.c:2218 wb_check_old_data_flush fs/fs-writeback.c:2322 [inline] wb_do_writeback fs/fs-writeback.c:2375 [inline] wb_workfn+0x885/0xbb0 fs/fs-writeback.c:2403 process_one_work+0x9c2/0x1840 kernel/workqueue.c:3257 process_scheduled_works kernel/workqueue.c:3340 [inline] worker_thread+0x5da/0xe40 kernel/workqueue.c:3421 kthread+0x3b3/0x730 kernel/kthread.c:463 ret_from_fork+0x754/0xaf0 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:246 --- This report is generated by a bot. It may contain errors. See https://goo.gl/tpsmEJ for more information about syzbot. syzbot engineers can be reached at syzkaller@googlegroups.com. syzbot will keep track of this issue. See: https://goo.gl/tpsmEJ#status for how to communicate with syzbot. If the report is already addressed, let syzbot know by replying with: #syz fix: exact-commit-title If you want to overwrite report's subsystems, reply with: #syz set subsystems: new-subsystem (See the list of subsystem names on the web dashboard) If the report is a duplicate of another one, reply with: #syz dup: exact-subject-of-another-report If you want to undo deduplication, reply with: #syz undup