From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-oo1-f71.google.com (mail-oo1-f71.google.com [209.85.161.71]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1E3FD29E11A for ; Mon, 16 Feb 2026 14:48:31 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.161.71 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1771253313; cv=none; b=NCyim/MeYHWeS/bd/z0fJHLFmlRGHd888qZJFSIJaoOlfvuBES6JgijtKNxt1tDS55D7w2sAaOjOFWqn/WaCyd23+1EHFpxrZlb8d2eZx9mbbHZv9JrVdKiGgf9ZUsjCvwED5NEE++LMvntp1RMCKxxdHi5IrGthaU9E2OHTeWk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1771253313; c=relaxed/simple; bh=OS4ORcdhlleRKJlJUcabuKJXaYfljvQG/H+ZDP1Xb3w=; h=MIME-Version:Date:In-Reply-To:Message-ID:Subject:From:To: Content-Type; b=VW5XhjHOt5t+JWfOZAfDd4dOJIsz1eY+w59FeI/2HNKIhuQ+tiO3l3GboRsSeKLCU3jVCvZOi3pyaA08PVQAnppjzEAyqz36/Yqh/K3bo8nnx4T1E/97FFxqOh7MAgdy1oCgK1pxX8QRdcMozRJjBny9karM7yZXxUBslUH7yxQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com; arc=none smtp.client-ip=209.85.161.71 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com Received: by mail-oo1-f71.google.com with SMTP id 006d021491bc7-6795b040562so6752649eaf.2 for ; Mon, 16 Feb 2026 06:48:31 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1771253311; x=1771858111; h=to:from:subject:message-id:in-reply-to:date:mime-version :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=1V/dh/UoV3gCCYVfvcY8xfhmYLXVwC2+jlB1lDdJzgs=; b=FjZ1xG5Nlc9bsDuH00UwcNqPNkH9j+LQW9Hp27LhjSohGlGS0lfheRzEUHTPUvRaEC K7bRU2wxu3e9na0L7d5680u6iRzAEZ/IplIjuKhT/bUHnN/gOybIx4K3SCrf+IHCq+MB adNJmp3HLKTWO9+eSH/rAksy99ibuGYEmMGjshufzS0CpsNm/nnoCJjTEg9mQJPiz7k5 AXrIV1ES95GxNmv0w3A6q9ASVxg9yDk2WbWgimSwMHhg9eQjqenAMZziY3Mv0e5S5DG2 YjTEh2XWO1+8CYk7iZE386os1SlBxgyW8dq7l+cefOD9oG5sKX8EUpyVwAzSbi4Bv5Xo 3Hqw== X-Forwarded-Encrypted: i=1; AJvYcCXVZo1oajRjMFwPq7fUfin/VQzx9nzmXQGJYYw9cWil25F9mPmKc5ewrELgKn0BIaBrCjFA0xsDwSgd78w=@vger.kernel.org X-Gm-Message-State: AOJu0YxdLAri1/7RkyteD3O9KwAozgHjlQT5p5TddqAcFR15ZJRkoCaY YgShi59WRwYytpJa4mVROiPIXHLdow2YYOtm5CmA0CfUCJb0vWjBvX1kVwvUvIzDLPbNH6+Me+i oiAMFnqOnSfKa6sBuUTT3nL2x4PoupPtuBJn0+DZP52JkN/p8AjPrQGsfLdU= Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Received: by 2002:a05:6820:4811:b0:678:6950:e1aa with SMTP id 006d021491bc7-6786950e253mr2837157eaf.84.1771253310988; Mon, 16 Feb 2026 06:48:30 -0800 (PST) Date: Mon, 16 Feb 2026 06:48:30 -0800 In-Reply-To: <68185b7b.a70a0220.254cdc.0046.GAE@google.com> X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <69932e3e.050a0220.2eeac1.00a8.GAE@google.com> Subject: Re: [syzbot] [afs?] INFO: task hung in afs_cell_purge (2) From: syzbot To: dhowells@redhat.com, hdanton@sina.com, linux-afs@lists.infradead.org, linux-kernel@vger.kernel.org, marc.dionne@auristor.com, nogikh@google.com, syzkaller-bugs@googlegroups.com Content-Type: text/plain; charset="UTF-8" syzbot has found a reproducer for the following issue on: HEAD commit: 635c467cc14e Add linux-next specific files for 20260213 git tree: linux-next console output: https://syzkaller.appspot.com/x/log.txt?x=12eeaffa580000 kernel config: https://syzkaller.appspot.com/x/.config?x=f09eec269f9f4746 dashboard link: https://syzkaller.appspot.com/bug?extid=750f21d691e244b473b1 compiler: Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8 syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1563515a580000 C reproducer: https://syzkaller.appspot.com/x/repro.c?x=12c72722580000 Downloadable assets: disk image: https://storage.googleapis.com/syzbot-assets/24870d51cbd0/disk-635c467c.raw.xz vmlinux: https://storage.googleapis.com/syzbot-assets/49283c738806/vmlinux-635c467c.xz kernel image: https://storage.googleapis.com/syzbot-assets/8c5f9d1da977/bzImage-635c467c.xz mounted in repro: https://storage.googleapis.com/syzbot-assets/8509d6e32dde/mount_0.gz The issue was bisected to: commit 1d0b929fc070b4115403a0a6206a0c6a62dd61f5 Author: David Howells Date: Mon Feb 24 09:52:58 2025 +0000 afs: Change dynroot to create contents on demand bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=1522020c580000 final oops: https://syzkaller.appspot.com/x/report.txt?x=1722020c580000 console output: https://syzkaller.appspot.com/x/log.txt?x=1322020c580000 IMPORTANT: if you fix the issue, please add the following tag to the commit: Reported-by: syzbot+750f21d691e244b473b1@syzkaller.appspotmail.com Fixes: 1d0b929fc070 ("afs: Change dynroot to create contents on demand") INFO: task kworker/u8:2:35 blocked for more than 143 seconds. Not tainted syzkaller #0 "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. task:kworker/u8:2 state:D stack:20800 pid:35 tgid:35 ppid:2 task_flags:0x4208160 flags:0x00080000 Workqueue: netns cleanup_net Call Trace: context_switch kernel/sched/core.c:5295 [inline] __schedule+0x1585/0x5340 kernel/sched/core.c:6907 __schedule_loop kernel/sched/core.c:6989 [inline] schedule+0x164/0x360 kernel/sched/core.c:7004 afs_cell_purge+0x40d/0x580 fs/afs/cell.c:921 afs_net_exit+0x50/0x100 fs/afs/main.c:147 ops_exit_list net/core/net_namespace.c:199 [inline] ops_undo_list+0x49f/0x940 net/core/net_namespace.c:252 cleanup_net+0x56b/0x800 net/core/net_namespace.c:704 process_one_work+0x949/0x1650 kernel/workqueue.c:3279 process_scheduled_works kernel/workqueue.c:3362 [inline] worker_thread+0xb46/0x1140 kernel/workqueue.c:3443 kthread+0x388/0x470 kernel/kthread.c:467 ret_from_fork+0x51e/0xb90 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 Showing all locks held in the system: 1 lock held by khungtaskd/30: #0: ffffffff8e7602e0 (rcu_read_lock){....}-{1:3}, at: rcu_lock_acquire include/linux/rcupdate.h:312 [inline] #0: ffffffff8e7602e0 (rcu_read_lock){....}-{1:3}, at: rcu_read_lock include/linux/rcupdate.h:850 [inline] #0: ffffffff8e7602e0 (rcu_read_lock){....}-{1:3}, at: debug_show_all_locks+0x2e/0x180 kernel/locking/lockdep.c:6775 3 locks held by kworker/u8:2/35: #0: ffff88801c2ae948 ((wq_completion)netns){+.+.}-{0:0}, at: process_one_work+0x855/0x1650 kernel/workqueue.c:3254 #1: ffffc90000ab7c40 (net_cleanup_work){+.+.}-{0:0}, at: process_one_work+0x87c/0x1650 kernel/workqueue.c:3255 #2: ffffffff8fbbe770 (pernet_ops_rwsem){++++}-{4:4}, at: cleanup_net+0xf4/0x800 net/core/net_namespace.c:675 3 locks held by kworker/u8:6/143: #0: ffff88801b0ac148 ((wq_completion)events_unbound){+.+.}-{0:0}, at: process_one_work+0x855/0x1650 kernel/workqueue.c:3254 #1: ffffc90002f67c40 ((linkwatch_work).work){+.+.}-{0:0}, at: process_one_work+0x87c/0x1650 kernel/workqueue.c:3255 #2: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: linkwatch_event+0xe/0x60 net/core/link_watch.c:313 2 locks held by kworker/u8:7/156: 2 locks held by getty/5582: #0: ffff888037dc10a0 (&tty->ldisc_sem){++++}-{0:0}, at: tty_ldisc_ref_wait+0x25/0x70 drivers/tty/tty_ldisc.c:243 #1: ffffc9000332b2f0 (&ldata->atomic_read_lock){+.+.}-{4:4}, at: n_tty_read+0x45c/0x13c0 drivers/tty/n_tty.c:2211 3 locks held by kworker/u8:9/7429: #0: ffff8880326c8948 ((wq_completion)ipv6_addrconf){+.+.}-{0:0}, at: process_one_work+0x855/0x1650 kernel/workqueue.c:3254 #1: ffffc9000cd6fc40 ((work_completion)(&(&ifa->dad_work)->work)){+.+.}-{0:0}, at: process_one_work+0x87c/0x1650 kernel/workqueue.c:3255 #2: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_net_lock include/linux/rtnetlink.h:130 [inline] #2: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: addrconf_dad_work+0x11e/0x14c0 net/ipv6/addrconf.c:4199 1 lock held by syz-executor/7852: #0: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_net_lock include/linux/rtnetlink.h:130 [inline] #0: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: inet_rtm_newaddr+0x404/0x1ad0 net/ipv4/devinet.c:978 3 locks held by syz-executor/7859: #0: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_lock net/core/rtnetlink.c:80 [inline] #0: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_nets_lock net/core/rtnetlink.c:341 [inline] #0: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_newlink+0x8a1/0x1be0 net/core/rtnetlink.c:4071 #1: ffff8880580b5528 (&wg->device_update_lock){+.+.}-{4:4}, at: wg_open+0x227/0x420 drivers/net/wireguard/device.c:50 #2: ffffffff8e766578 (rcu_state.exp_mutex){+.+.}-{4:4}, at: exp_funnel_lock kernel/rcu/tree_exp.h:311 [inline] #2: ffffffff8e766578 (rcu_state.exp_mutex){+.+.}-{4:4}, at: synchronize_rcu_expedited+0x2d0/0x770 kernel/rcu/tree_exp.h:961 2 locks held by syz-executor/7943: #0: ffffffff8f309048 (&ops->srcu#2){.+.+}-{0:0}, at: rcu_lock_acquire include/linux/rcupdate.h:312 [inline] #0: ffffffff8f309048 (&ops->srcu#2){.+.+}-{0:0}, at: rcu_read_lock include/linux/rcupdate.h:850 [inline] #0: ffffffff8f309048 (&ops->srcu#2){.+.+}-{0:0}, at: rtnl_link_ops_get+0x23/0x250 net/core/rtnetlink.c:570 #1: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_lock net/core/rtnetlink.c:80 [inline] #1: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_nets_lock net/core/rtnetlink.c:341 [inline] #1: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_newlink+0x8a1/0x1be0 net/core/rtnetlink.c:4071 2 locks held by syz-executor/7974: #0: ffffffff90136ea0 (&ops->srcu#2){.+.+}-{0:0}, at: rcu_lock_acquire include/linux/rcupdate.h:312 [inline] #0: ffffffff90136ea0 (&ops->srcu#2){.+.+}-{0:0}, at: rcu_read_lock include/linux/rcupdate.h:850 [inline] #0: ffffffff90136ea0 (&ops->srcu#2){.+.+}-{0:0}, at: rtnl_link_ops_get+0x23/0x250 net/core/rtnetlink.c:570 #1: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_lock net/core/rtnetlink.c:80 [inline] #1: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_nets_lock net/core/rtnetlink.c:341 [inline] #1: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_newlink+0x8a1/0x1be0 net/core/rtnetlink.c:4071 2 locks held by syz-executor/7981: #0: ffffffff8fbbe770 (pernet_ops_rwsem){++++}-{4:4}, at: copy_net_ns+0x4f7/0x730 net/core/net_namespace.c:577 #1: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_net_lock include/linux/rtnetlink.h:130 [inline] #1: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: register_netdevice_notifier_net+0x1a/0xa0 net/core/dev.c:2096 ============================================= NMI backtrace for cpu 0 CPU: 0 UID: 0 PID: 30 Comm: khungtaskd Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2026 Call Trace: dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120 nmi_cpu_backtrace+0x274/0x2d0 lib/nmi_backtrace.c:113 nmi_trigger_cpumask_backtrace+0x17a/0x300 lib/nmi_backtrace.c:62 trigger_all_cpu_backtrace include/linux/nmi.h:161 [inline] __sys_info lib/sys_info.c:157 [inline] sys_info+0x135/0x170 lib/sys_info.c:165 check_hung_uninterruptible_tasks kernel/hung_task.c:346 [inline] watchdog+0xfd9/0x1030 kernel/hung_task.c:515 kthread+0x388/0x470 kernel/kthread.c:467 ret_from_fork+0x51e/0xb90 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 Sending NMI from CPU 0 to CPUs 1: NMI backtrace for cpu 1 CPU: 1 UID: 0 PID: 7551 Comm: kworker/u8:10 Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2026 Workqueue: events_unbound nsim_dev_trap_report_work RIP: 0010:__orc_find arch/x86/kernel/unwind_orc.c:101 [inline] RIP: 0010:orc_find arch/x86/kernel/unwind_orc.c:238 [inline] RIP: 0010:unwind_next_frame+0x4db/0x23c0 arch/x86/kernel/unwind_orc.c:510 Code: 4c 8b 7c 24 50 48 bd 00 00 00 00 00 fc ff df 4c 8b 64 24 20 4c 8b 6c 24 48 0f 84 72 15 00 00 e9 03 02 00 00 49 89 d5 48 89 d5 <48> 89 d8 48 29 e8 48 89 c1 48 c1 f9 02 48 c1 e8 3f 48 01 c8 48 83 RSP: 0018:ffffc9000d4af4b8 EFLAGS: 00000297 RAX: ffffffff902d0014 RBX: ffffffff902d0014 RCX: ffffffff902d001c RDX: ffffffff902d0010 RSI: ffffffff90aa9e52 RDI: ffffffff8c27aaa0 RBP: ffffffff902d0010 R08: 000000000000000c R09: ffffffff8e7602e0 R10: ffffc9000d4af5d8 R11: ffffffff81b0c580 R12: ffffffff81b0c518 R13: ffffffff902d0010 R14: ffffc9000d4af588 R15: ffffffff902d0018 FS: 0000000000000000(0000) GS:ffff888125560000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f1329d45000 CR3: 000000008888e000 CR4: 00000000003526f0 Call Trace: arch_stack_walk+0x11b/0x150 arch/x86/kernel/stacktrace.c:25 stack_trace_save+0xa9/0x100 kernel/stacktrace.c:122 kasan_save_stack mm/kasan/common.c:57 [inline] kasan_save_track+0x3e/0x80 mm/kasan/common.c:78 kasan_save_free_info+0x46/0x50 mm/kasan/generic.c:584 poison_slab_object mm/kasan/common.c:253 [inline] __kasan_slab_free+0x5c/0x80 mm/kasan/common.c:285 kasan_slab_free include/linux/kasan.h:235 [inline] slab_free_hook mm/slub.c:2687 [inline] slab_free mm/slub.c:6124 [inline] kfree+0x1c1/0x630 mm/slub.c:6442 skb_kfree_head net/core/skbuff.c:1089 [inline] skb_free_head net/core/skbuff.c:1101 [inline] skb_release_data+0x6f0/0x940 net/core/skbuff.c:1128 skb_release_all net/core/skbuff.c:1203 [inline] __kfree_skb+0x5d/0x210 net/core/skbuff.c:1217 nsim_dev_trap_report drivers/net/netdevsim/dev.c:892 [inline] nsim_dev_trap_report_work+0x7cf/0xb80 drivers/net/netdevsim/dev.c:922 process_one_work+0x949/0x1650 kernel/workqueue.c:3279 process_scheduled_works kernel/workqueue.c:3362 [inline] worker_thread+0xb46/0x1140 kernel/workqueue.c:3443 kthread+0x388/0x470 kernel/kthread.c:467 ret_from_fork+0x51e/0xb90 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 --- If you want syzbot to run the reproducer, reply with: #syz test: git://repo/address.git branch-or-commit-hash If you attach or paste a git patch, syzbot will apply it before testing.