public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
From: syzbot <syzbot+62f0f99d2f2bb8e3bbd7@syzkaller.appspotmail.com>
To: kartikey406@gmail.com, linux-kernel@vger.kernel.org,
	 syzkaller-bugs@googlegroups.com
Subject: Re: [syzbot] [nilfs?] INFO: task hung in nilfs_transaction_begin (2)
Date: Mon, 27 Apr 2026 20:05:04 -0700	[thread overview]
Message-ID: <69f023e0.050a0220.1d2f3.0001.GAE@google.com> (raw)
In-Reply-To: <20260427234728.81020-1-kartikey406@gmail.com>

Hello,

syzbot has tested the proposed patch but the reproducer is still triggering an issue:
INFO: task hung in nilfs_transaction_begin

INFO: task syz.0.17:6369 blocked for more than 143 seconds.
      Not tainted syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:syz.0.17        state:D
 stack:26072 pid:6369  tgid:6366  ppid:6267   task_flags:0x400040 flags:0x00080002
Call Trace:
 <TASK>
 context_switch kernel/sched/core.c:5387 [inline]
 __schedule+0x17b4/0x5680 kernel/sched/core.c:7188
 __schedule_loop kernel/sched/core.c:7267 [inline]
 schedule+0x164/0x360 kernel/sched/core.c:7282
 schedule_preempt_disabled+0x13/0x30 kernel/sched/core.c:7339
 rwsem_down_read_slowpath+0x6d9/0x940 kernel/locking/rwsem.c:1114
 __down_read_common kernel/locking/rwsem.c:1291 [inline]
 __down_read kernel/locking/rwsem.c:1304 [inline]
 down_read+0x99/0x2e0 kernel/locking/rwsem.c:1570
 nilfs_transaction_begin+0x364/0x710 fs/nilfs2/segment.c:221
 nilfs_setattr+0x124/0x2c0 fs/nilfs2/inode.c:921
 notify_change+0xc1a/0xf40 fs/attr.c:556
 chmod_common+0x273/0x4a0 fs/open.c:637
 do_fchmodat+0x12d/0x230 fs/open.c:682
 __do_sys_fchmodat fs/open.c:701 [inline]
 __se_sys_fchmodat fs/open.c:698 [inline]
 __x64_sys_fchmodat+0x7d/0x90 fs/open.c:698
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0x15f/0xf80 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f5998f9cdd9
RSP: 002b:00007f5999d84028 EFLAGS: 00000246
 ORIG_RAX: 000000000000010c
RAX: ffffffffffffffda RBX: 00007f5999216090 RCX: 00007f5998f9cdd9
RDX: 000000000000017f RSI: 0000200000000300 RDI: ffffffffffffff9c
RBP: 00007f5999032d69 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f5999216128 R14: 00007f5999216090 R15: 00007ffdbc74df58
 </TASK>
INFO: task syz.1.18:6408 blocked for more than 146 seconds.
      Not tainted syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:syz.1.18        state:D
 stack:26072 pid:6408  tgid:6405  ppid:6371   task_flags:0x400040 flags:0x00080002
Call Trace:
 <TASK>
 context_switch kernel/sched/core.c:5387 [inline]
 __schedule+0x17b4/0x5680 kernel/sched/core.c:7188
 __schedule_loop kernel/sched/core.c:7267 [inline]
 schedule+0x164/0x360 kernel/sched/core.c:7282
 schedule_preempt_disabled+0x13/0x30 kernel/sched/core.c:7339
 rwsem_down_read_slowpath+0x6d9/0x940 kernel/locking/rwsem.c:1114
 __down_read_common kernel/locking/rwsem.c:1291 [inline]
 __down_read kernel/locking/rwsem.c:1304 [inline]
 down_read+0x99/0x2e0 kernel/locking/rwsem.c:1570
 nilfs_transaction_begin+0x364/0x710 fs/nilfs2/segment.c:221
 nilfs_setattr+0x124/0x2c0 fs/nilfs2/inode.c:921
 notify_change+0xc1a/0xf40 fs/attr.c:556
 chmod_common+0x273/0x4a0 fs/open.c:637
 do_fchmodat+0x12d/0x230 fs/open.c:682
 __do_sys_fchmodat fs/open.c:701 [inline]
 __se_sys_fchmodat fs/open.c:698 [inline]
 __x64_sys_fchmodat+0x7d/0x90 fs/open.c:698
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0x15f/0xf80 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fbc13b9cdd9
RSP: 002b:00007fbc14a1b028 EFLAGS: 00000246 ORIG_RAX: 000000000000010c
RAX: ffffffffffffffda RBX: 00007fbc13e16090 RCX: 00007fbc13b9cdd9
RDX: 000000000000017f RSI: 0000200000000300 RDI: ffffffffffffff9c
RBP: 00007fbc13c32d69 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007fbc13e16128 R14: 00007fbc13e16090 R15: 00007ffcbf037038
 </TASK>

Showing all locks held in the system:
5 locks held by kworker/u8:1/13:
 #0: 
ffff8880b863aea0
 (
&rq->__lock
){-.-.}-{2:2}
, at: raw_spin_rq_lock_nested+0x31/0x150 kernel/sched/core.c:652
 #1: 
ffff8880b8624588
 (
psi_seq
){-.-.}-{0:0}, at: psi_task_switch+0x53/0x880 kernel/sched/psi.c:933
 #2: ffff8880b8626118 (&base->lock){-.-.}-{2:2}, at: lock_timer_base kernel/time/timer.c:1004 [inline]
 #2: ffff8880b8626118 (&base->lock){-.-.}-{2:2}, at: __mod_timer+0x1ae/0xf30 kernel/time/timer.c:1085
 #3: 
ffffffff9a6630d8
 (
&obj_hash[i].lock){-.-.}-{2:2}, at: debug_object_activate+0x83/0x580 lib/debugobjects.c:835
 #4: ffffffff8e95cd60 (rcu_read_lock){....}-{1:3}, at: rcu_lock_acquire include/linux/rcupdate.h:300 [inline]
 #4: ffffffff8e95cd60 (rcu_read_lock){....}-{1:3}, at: rcu_read_lock include/linux/rcupdate.h:838 [inline]
 #4: ffffffff8e95cd60 (rcu_read_lock){....}-{1:3}, at: class_rcu_constructor include/linux/rcupdate.h:1181 [inline]
 #4: ffffffff8e95cd60 (rcu_read_lock){....}-{1:3}, at: unwind_next_frame+0xa6/0x2550 arch/x86/kernel/unwind_orc.c:495
1 lock held by khungtaskd/32:
 #0: 
ffffffff8e95cd60
 (
rcu_read_lock
){....}-{1:3}, at: rcu_lock_acquire include/linux/rcupdate.h:300 [inline]
){....}-{1:3}, at: rcu_read_lock include/linux/rcupdate.h:838 [inline]
){....}-{1:3}, at: debug_show_all_locks+0x2e/0x180 kernel/locking/lockdep.c:6775
4 locks held by kworker/u8:3/49:
 #0: ffff88813fe7c140 ((wq_completion)events_unbound){+.+.}-{0:0}, at: process_one_work kernel/workqueue.c:3277 [inline]
 #0: ffff88813fe7c140 ((wq_completion)events_unbound){+.+.}-{0:0}, at: process_scheduled_works+0xa35/0x1860 kernel/workqueue.c:3385
 #1: ffffc90000b97c40 ((linkwatch_work).work){+.+.}-{0:0}, at: process_one_work kernel/workqueue.c:3278 [inline]
 #1: ffffc90000b97c40 ((linkwatch_work).work){+.+.}-{0:0}, at: process_scheduled_works+0xa70/0x1860 kernel/workqueue.c:3385
 #2: ffffffff8fdceac0 (rtnl_mutex){+.+.}-{4:4}
, at: linkwatch_event+0xe/0x60 net/core/link_watch.c:313
 #3: 
ffffffff8e963068
 (
rcu_state.exp_mutex
){+.+.}-{4:4}, at: exp_funnel_lock kernel/rcu/tree_exp.h:311 [inline]
){+.+.}-{4:4}, at: synchronize_rcu_expedited+0x2d0/0x770 kernel/rcu/tree_exp.h:961
2 locks held by getty/5374:
 #0: 
ffff8880369100a0
 (
&tty->ldisc_sem
){++++}-{0:0}
, at: tty_ldisc_ref_wait+0x25/0x70 drivers/tty/tty_ldisc.c:243
 #1: 
ffffc9000322b2e8
 (
&ldata->atomic_read_lock
){+.+.}-{4:4}
, at: n_tty_read+0x45c/0x13a0 drivers/tty/n_tty.c:2211
2 locks held by syz.0.17/6367:
4 locks held by syz.0.17/6369:
 #0: 
ffff8880793ac410
 (
sb_writers
#12
){.+.+}-{0:0}
, at: mnt_want_write+0x41/0x90 fs/namespace.c:493
 #1: 
ffff88806a8f9af0
 (
&type->i_mutex_dir_key
#8
){++++}-{4:4}, at: inode_lock_killable include/linux/fs.h:1034 [inline]
){++++}-{4:4}, at: chmod_common+0x191/0x4a0 fs/open.c:629
 #2: ffff8880793ac600 (sb_internal#2){.+.+}-{0:0}, at: nilfs_setattr+0x124/0x2c0 fs/nilfs2/inode.c:921
 #3: ffff88807c577288 (&nilfs->ns_segctor_sem){++++}-{4:4}, at: nilfs_transaction_begin+0x364/0x710 fs/nilfs2/segment.c:221
3 locks held by syz.1.18/6406:
4 locks held by syz.1.18/6408:
 #0: ffff888033ae0410
 (
sb_writers
#12){.+.+}-{0:0}
, at: mnt_want_write+0x41/0x90 fs/namespace.c:493


Tested on:

commit:         3b3bea6d Merge tag 'cgroup-for-7.1-rc1-fixes' of git:/..
git tree:       upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=175d9348580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=4caf64b1ee83dac0
dashboard link: https://syzkaller.appspot.com/bug?extid=62f0f99d2f2bb8e3bbd7
compiler:       Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8
patch:          https://syzkaller.appspot.com/x/patch.diff?x=169f5ace580000


       reply	other threads:[~2026-04-28  3:05 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <20260427234728.81020-1-kartikey406@gmail.com>
2026-04-28  3:05 ` syzbot [this message]
     [not found] <20260428003142.82400-1-kartikey406@gmail.com>
2026-04-28  3:50 ` [syzbot] [nilfs?] INFO: task hung in nilfs_transaction_begin (2) syzbot
2026-04-27 15:04 syzbot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=69f023e0.050a0220.1d2f3.0001.GAE@google.com \
    --to=syzbot+62f0f99d2f2bb8e3bbd7@syzkaller.appspotmail.com \
    --cc=kartikey406@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=syzkaller-bugs@googlegroups.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox