* Re: [syzbot] [afs?] INFO: task hung in afs_cell_purge (2)
2025-05-05 6:32 [syzbot] [afs?] INFO: task hung in afs_cell_purge (2) syzbot
@ 2025-06-07 22:45 ` syzbot
2025-07-21 14:02 ` David Howells
` (3 subsequent siblings)
4 siblings, 0 replies; 9+ messages in thread
From: syzbot @ 2025-06-07 22:45 UTC (permalink / raw)
To: dhowells, linux-afs, linux-kernel, marc.dionne, syzkaller-bugs
syzbot has bisected this issue to:
commit 1d0b929fc070b4115403a0a6206a0c6a62dd61f5
Author: David Howells <dhowells@redhat.com>
Date: Mon Feb 24 09:52:58 2025 +0000
afs: Change dynroot to create contents on demand
bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=1522020c580000
start commit: 7a13c14ee59d Merge tag 'for-6.15-rc4-tag' of git://git.ker..
git tree: upstream
final oops: https://syzkaller.appspot.com/x/report.txt?x=1722020c580000
console output: https://syzkaller.appspot.com/x/log.txt?x=1322020c580000
kernel config: https://syzkaller.appspot.com/x/.config?x=a42a9d552788177b
dashboard link: https://syzkaller.appspot.com/bug?extid=750f21d691e244b473b1
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=13a101cc580000
Reported-by: syzbot+750f21d691e244b473b1@syzkaller.appspotmail.com
Fixes: 1d0b929fc070 ("afs: Change dynroot to create contents on demand")
For information about bisection process see: https://goo.gl/tpsmEJ#bisection
^ permalink raw reply [flat|nested] 9+ messages in thread* Re: [syzbot] [afs?] INFO: task hung in afs_cell_purge (2)
2025-05-05 6:32 [syzbot] [afs?] INFO: task hung in afs_cell_purge (2) syzbot
2025-06-07 22:45 ` syzbot
@ 2025-07-21 14:02 ` David Howells
2025-07-21 15:41 ` Aleksandr Nogikh
2026-02-16 14:48 ` syzbot
` (2 subsequent siblings)
4 siblings, 1 reply; 9+ messages in thread
From: David Howells @ 2025-07-21 14:02 UTC (permalink / raw)
To: syzbot; +Cc: dhowells, linux-afs, linux-kernel, marc.dionne, syzkaller-bugs
Hi,
In this:
syz_mount_image$erofs(&(0x7f00000003c0), &(0x7f0000000880)='./file0\x00', 0x8000c6, &(0x7f0000000240)=ANY=[], 0x0, 0x17d, &(0x7f0000001ac0)="$eJzsmLFP+kAUx7/vyg/yMy6uLg4SxcHSFjUuxLA5mogaNwlUghYx0EGYdPH/cHZwdvOPMM7qYFwY3Uxqej3oQQR10MT4PsPj+7h313evyXcoGIb5szw+vNyvFe+EAWASaaTU/89GXCO0+tfb83Jraj1/OfeUv041robPIwBB8PnnJwDcFAz4Kg+Cwd1p9VuE6OstCCwovQOCqfQeBLaVdkHYVfpA042w3jT3a55rlhteJRRWGOwwOGHIDffXPSNUtP5IW2+1O4clz3Ob3yg+ml+3IJDX+tPfV282ljY/GwK20jkQNpVeRao3m2gk2v2nE/H5xg/fnwULFr9NxP4UXBDmNX9KaP6R9evH2Va7s1irl6pu1T1ynNyKtWRZy05WGlEUx/jff+lPE9r5/0bUJimJk5LvN+0o9nMniu85rpD+J5CZjfLQ+5Mju4nWSe0jqTLGmHKGYRiGYRiGYRiGYRiGYZgvMAOSX0EldIo4GcDZkNVvAQAA///an3MA")
how do I manually extract the erofs image source, if that is indeed what it
is? The obvious thought is that it's base64, but '$' isn't a valid character
for that.
Further, though syz-execprog does manage to extract it, it doesn't seem to
contain what the test is expecting:
[727ms] exec opts: procid=3 threaded=1 cover=0 comps=0 dedup=1 signal=0 timeouts=50/5000/1 prog=0 filter=0
spawned worker pid 2
#0 [731ms] -> syz_mount_image$erofs(0x200003c0, 0x20000880, 0x8000c6, 0x20000240, 0x0, 0x17d, 0x20001ac0)
syz_mount_image: size=381 loop='/dev/loop3' dir='./file0' fs='erofs' flags=8388806 opts=''
#0 [771ms] <- syz_mount_image$erofs=0x3
#0 [771ms] -> mkdirat(0xffffffffffffff9c, 0x20000840, 0xa4)
#0 [772ms] <- mkdirat=0x0
#0 [772ms] -> mount$overlay(0x0, 0x0, 0x0, 0x0, 0x0)
#0 [772ms] <- mount$overlay=0xffffffffffffffff errno=14
#0 [772ms] -> chdir(0x20000140)
#0 [773ms] <- chdir=0x0
#0 [773ms] -> mount$afs(0x0, 0x200001c0, 0x200002c0, 0x0, 0x20000580)
#0 [773ms] <- mount$afs=0xffffffffffffffff errno=2
#0 [774ms] -> chdir(0x200000c0)
#0 [775ms] <- chdir=0xffffffffffffffff errno=2
#0 [775ms] -> renameat2(0xffffffffffffff9c, 0x20000480, 0xffffffffffffff9c, 0x20000000, 0x2)
#0 [776ms] <- renameat2=0xffffffffffffffff errno=2 fault=0
2025/07/21 14:21:05 result: hanged=false err=<nil>
Here's an excerpt of the strace over the relevant thread region with the
write(stderr) syscalls filtered out:
memfd_create("syzkaller", 0) = 3
mmap(NULL, 138412032, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fbdf4200000
write(3, "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0"..., 8192) = 8192
munmap(0x7fbdf4200000, 8192) = 0
openat(AT_FDCWD, "/dev/loop6", O_RDWR) = 4
ioctl(4, LOOP_SET_FD, 3) = 0
close(3) = 0
mkdirat(AT_FDCWD, "./file0", 0777) = 0
mount("/dev/loop6", "./file0", "erofs", MS_NOSUID|MS_NODEV|MS_MANDLOCK|MS_DIRSYNC|MS_I_VERSION,
"") = 0
openat(AT_FDCWD, "./file0", O_RDONLY|O_DIRECTORY) = 3
ioctl(4, LOOP_CLR_FD) = 0
close(4) = 0
mkdirat(AT_FDCWD, "./bus", 0244) = 0
mount(NULL, NULL, NULL, 0, NULL) = -1 EFAULT (Bad address)
chdir("./bus") = 0
mount(NULL, "./file0", "afs", 0, "dyn") = -1 ENOENT (No such file or directory)
chdir("./file0") = -1 ENOENT (No such file or directory)
renameat2(AT_FDCWD, "./file1", AT_FDCWD, "./file0", RENAME_EXCHANGE) = -1 ENOENT (No such file or directory)
Can you see if this can be reproduced by installing kafs-client and doing:
systemctl start afs.mount
cd /afs
mv --exchange ./file0 ./file1
though possibly this needs running in its own network namespace.
I can't get syz-execprog to actually run the test properly, it would seem. I
suspect something it missing from my kernel, but I'm not sure what.
David
^ permalink raw reply [flat|nested] 9+ messages in thread* Re: [syzbot] [afs?] INFO: task hung in afs_cell_purge (2)
2025-07-21 14:02 ` David Howells
@ 2025-07-21 15:41 ` Aleksandr Nogikh
0 siblings, 0 replies; 9+ messages in thread
From: Aleksandr Nogikh @ 2025-07-21 15:41 UTC (permalink / raw)
To: David Howells
Cc: syzbot, linux-afs, linux-kernel, marc.dionne, syzkaller-bugs
Hi David,
On Mon, Jul 21, 2025 at 4:02 PM 'David Howells' via syzkaller-bugs
<syzkaller-bugs@googlegroups.com> wrote:
>
> Hi,
>
> In this:
>
> syz_mount_image$erofs(&(0x7f00000003c0), &(0x7f0000000880)='./file0\x00', 0x8000c6, &(0x7f0000000240)=ANY=[], 0x0, 0x17d, &(0x7f0000001ac0)="$eJzsmLFP+kAUx7/vyg/yMy6uLg4SxcHSFjUuxLA5mogaNwlUghYx0EGYdPH/cHZwdvOPMM7qYFwY3Uxqej3oQQR10MT4PsPj+7h313evyXcoGIb5szw+vNyvFe+EAWASaaTU/89GXCO0+tfb83Jraj1/OfeUv041robPIwBB8PnnJwDcFAz4Kg+Cwd1p9VuE6OstCCwovQOCqfQeBLaVdkHYVfpA042w3jT3a55rlhteJRRWGOwwOGHIDffXPSNUtP5IW2+1O4clz3Ob3yg+ml+3IJDX+tPfV282ljY/GwK20jkQNpVeRao3m2gk2v2nE/H5xg/fnwULFr9NxP4UXBDmNX9KaP6R9evH2Va7s1irl6pu1T1ynNyKtWRZy05WGlEUx/jff+lPE9r5/0bUJimJk5LvN+0o9nMniu85rpD+J5CZjfLQ+5Mju4nWSe0jqTLGmHKGYRiGYRiGYRiGYRiGYZgvMAOSX0EldIo4GcDZkNVvAQAA///an3MA")
>
> how do I manually extract the erofs image source, if that is indeed what it
> is? The obvious thought is that it's base64, but '$' isn't a valid character
> for that.
It's a base64 representation of a gzipped disk image. Syzbot does
extract the full disk image and share it in its bug reports and on its
web dashboard. See these link:
mounted in repro:
https://storage.googleapis.com/syzbot-assets/9edd5a22bff1/mount_0.gz
>
> Further, though syz-execprog does manage to extract it, it doesn't seem to
> contain what the test is expecting:
>
> [727ms] exec opts: procid=3 threaded=1 cover=0 comps=0 dedup=1 signal=0 timeouts=50/5000/1 prog=0 filter=0
> spawned worker pid 2
> #0 [731ms] -> syz_mount_image$erofs(0x200003c0, 0x20000880, 0x8000c6, 0x20000240, 0x0, 0x17d, 0x20001ac0)
> syz_mount_image: size=381 loop='/dev/loop3' dir='./file0' fs='erofs' flags=8388806 opts=''
> #0 [771ms] <- syz_mount_image$erofs=0x3
> #0 [771ms] -> mkdirat(0xffffffffffffff9c, 0x20000840, 0xa4)
> #0 [772ms] <- mkdirat=0x0
> #0 [772ms] -> mount$overlay(0x0, 0x0, 0x0, 0x0, 0x0)
> #0 [772ms] <- mount$overlay=0xffffffffffffffff errno=14
> #0 [772ms] -> chdir(0x20000140)
> #0 [773ms] <- chdir=0x0
> #0 [773ms] -> mount$afs(0x0, 0x200001c0, 0x200002c0, 0x0, 0x20000580)
> #0 [773ms] <- mount$afs=0xffffffffffffffff errno=2
> #0 [774ms] -> chdir(0x200000c0)
> #0 [775ms] <- chdir=0xffffffffffffffff errno=2
> #0 [775ms] -> renameat2(0xffffffffffffff9c, 0x20000480, 0xffffffffffffff9c, 0x20000000, 0x2)
> #0 [776ms] <- renameat2=0xffffffffffffffff errno=2 fault=0
> 2025/07/21 14:21:05 result: hanged=false err=<nil>
>
> Here's an excerpt of the strace over the relevant thread region with the
> write(stderr) syscalls filtered out:
>
> memfd_create("syzkaller", 0) = 3
> mmap(NULL, 138412032, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fbdf4200000
> write(3, "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0"..., 8192) = 8192
> munmap(0x7fbdf4200000, 8192) = 0
> openat(AT_FDCWD, "/dev/loop6", O_RDWR) = 4
> ioctl(4, LOOP_SET_FD, 3) = 0
> close(3) = 0
> mkdirat(AT_FDCWD, "./file0", 0777) = 0
> mount("/dev/loop6", "./file0", "erofs", MS_NOSUID|MS_NODEV|MS_MANDLOCK|MS_DIRSYNC|MS_I_VERSION,
> "") = 0
> openat(AT_FDCWD, "./file0", O_RDONLY|O_DIRECTORY) = 3
> ioctl(4, LOOP_CLR_FD) = 0
> close(4) = 0
> mkdirat(AT_FDCWD, "./bus", 0244) = 0
> mount(NULL, NULL, NULL, 0, NULL) = -1 EFAULT (Bad address)
> chdir("./bus") = 0
> mount(NULL, "./file0", "afs", 0, "dyn") = -1 ENOENT (No such file or directory)
> chdir("./file0") = -1 ENOENT (No such file or directory)
> renameat2(AT_FDCWD, "./file1", AT_FDCWD, "./file0", RENAME_EXCHANGE) = -1 ENOENT (No such file or directory)
>
>
> Can you see if this can be reproduced by installing kafs-client and doing:
>
> systemctl start afs.mount
> cd /afs
> mv --exchange ./file0 ./file1
>
> though possibly this needs running in its own network namespace.
>
> I can't get syz-execprog to actually run the test properly, it would seem. I
> suspect something it missing from my kernel, but I'm not sure what.
>
> David
>
--
Aleksandr
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [syzbot] [afs?] INFO: task hung in afs_cell_purge (2)
2025-05-05 6:32 [syzbot] [afs?] INFO: task hung in afs_cell_purge (2) syzbot
2025-06-07 22:45 ` syzbot
2025-07-21 14:02 ` David Howells
@ 2026-02-16 14:48 ` syzbot
2026-06-16 16:06 ` David Howells
2026-08-04 13:08 ` syzbot
4 siblings, 0 replies; 9+ messages in thread
From: syzbot @ 2026-02-16 14:48 UTC (permalink / raw)
To: dhowells, hdanton, linux-afs, linux-kernel, marc.dionne, nogikh,
syzkaller-bugs
syzbot has found a reproducer for the following issue on:
HEAD commit: 635c467cc14e Add linux-next specific files for 20260213
git tree: linux-next
console output: https://syzkaller.appspot.com/x/log.txt?x=12eeaffa580000
kernel config: https://syzkaller.appspot.com/x/.config?x=f09eec269f9f4746
dashboard link: https://syzkaller.appspot.com/bug?extid=750f21d691e244b473b1
compiler: Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1563515a580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=12c72722580000
Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/24870d51cbd0/disk-635c467c.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/49283c738806/vmlinux-635c467c.xz
kernel image: https://storage.googleapis.com/syzbot-assets/8c5f9d1da977/bzImage-635c467c.xz
mounted in repro: https://storage.googleapis.com/syzbot-assets/8509d6e32dde/mount_0.gz
The issue was bisected to:
commit 1d0b929fc070b4115403a0a6206a0c6a62dd61f5
Author: David Howells <dhowells@redhat.com>
Date: Mon Feb 24 09:52:58 2025 +0000
afs: Change dynroot to create contents on demand
bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=1522020c580000
final oops: https://syzkaller.appspot.com/x/report.txt?x=1722020c580000
console output: https://syzkaller.appspot.com/x/log.txt?x=1322020c580000
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+750f21d691e244b473b1@syzkaller.appspotmail.com
Fixes: 1d0b929fc070 ("afs: Change dynroot to create contents on demand")
INFO: task kworker/u8:2:35 blocked for more than 143 seconds.
Not tainted syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:kworker/u8:2 state:D
stack:20800 pid:35 tgid:35 ppid:2 task_flags:0x4208160 flags:0x00080000
Workqueue: netns cleanup_net
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5295 [inline]
__schedule+0x1585/0x5340 kernel/sched/core.c:6907
__schedule_loop kernel/sched/core.c:6989 [inline]
schedule+0x164/0x360 kernel/sched/core.c:7004
afs_cell_purge+0x40d/0x580 fs/afs/cell.c:921
afs_net_exit+0x50/0x100 fs/afs/main.c:147
ops_exit_list net/core/net_namespace.c:199 [inline]
ops_undo_list+0x49f/0x940 net/core/net_namespace.c:252
cleanup_net+0x56b/0x800 net/core/net_namespace.c:704
process_one_work+0x949/0x1650 kernel/workqueue.c:3279
process_scheduled_works kernel/workqueue.c:3362 [inline]
worker_thread+0xb46/0x1140 kernel/workqueue.c:3443
kthread+0x388/0x470 kernel/kthread.c:467
ret_from_fork+0x51e/0xb90 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
Showing all locks held in the system:
1 lock held by khungtaskd/30:
#0: ffffffff8e7602e0 (rcu_read_lock){....}-{1:3}, at: rcu_lock_acquire include/linux/rcupdate.h:312 [inline]
#0: ffffffff8e7602e0 (rcu_read_lock){....}-{1:3}, at: rcu_read_lock include/linux/rcupdate.h:850 [inline]
#0: ffffffff8e7602e0 (rcu_read_lock){....}-{1:3}, at: debug_show_all_locks+0x2e/0x180 kernel/locking/lockdep.c:6775
3 locks held by kworker/u8:2/35:
#0: ffff88801c2ae948 ((wq_completion)netns){+.+.}-{0:0}, at: process_one_work+0x855/0x1650 kernel/workqueue.c:3254
#1: ffffc90000ab7c40 (net_cleanup_work){+.+.}-{0:0}, at: process_one_work+0x87c/0x1650 kernel/workqueue.c:3255
#2: ffffffff8fbbe770 (pernet_ops_rwsem){++++}-{4:4}, at: cleanup_net+0xf4/0x800 net/core/net_namespace.c:675
3 locks held by kworker/u8:6/143:
#0: ffff88801b0ac148 ((wq_completion)events_unbound){+.+.}-{0:0}, at: process_one_work+0x855/0x1650 kernel/workqueue.c:3254
#1: ffffc90002f67c40 ((linkwatch_work).work){+.+.}-{0:0}, at: process_one_work+0x87c/0x1650 kernel/workqueue.c:3255
#2: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: linkwatch_event+0xe/0x60 net/core/link_watch.c:313
2 locks held by kworker/u8:7/156:
2 locks held by getty/5582:
#0: ffff888037dc10a0 (&tty->ldisc_sem){++++}-{0:0}, at: tty_ldisc_ref_wait+0x25/0x70 drivers/tty/tty_ldisc.c:243
#1: ffffc9000332b2f0 (&ldata->atomic_read_lock){+.+.}-{4:4}, at: n_tty_read+0x45c/0x13c0 drivers/tty/n_tty.c:2211
3 locks held by kworker/u8:9/7429:
#0: ffff8880326c8948 ((wq_completion)ipv6_addrconf){+.+.}-{0:0}, at: process_one_work+0x855/0x1650 kernel/workqueue.c:3254
#1: ffffc9000cd6fc40 ((work_completion)(&(&ifa->dad_work)->work)){+.+.}-{0:0}, at: process_one_work+0x87c/0x1650 kernel/workqueue.c:3255
#2: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_net_lock include/linux/rtnetlink.h:130 [inline]
#2: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: addrconf_dad_work+0x11e/0x14c0 net/ipv6/addrconf.c:4199
1 lock held by syz-executor/7852:
#0: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_net_lock include/linux/rtnetlink.h:130 [inline]
#0: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: inet_rtm_newaddr+0x404/0x1ad0 net/ipv4/devinet.c:978
3 locks held by syz-executor/7859:
#0: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_lock net/core/rtnetlink.c:80 [inline]
#0: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_nets_lock net/core/rtnetlink.c:341 [inline]
#0: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_newlink+0x8a1/0x1be0 net/core/rtnetlink.c:4071
#1: ffff8880580b5528 (&wg->device_update_lock){+.+.}-{4:4}, at: wg_open+0x227/0x420 drivers/net/wireguard/device.c:50
#2: ffffffff8e766578 (rcu_state.exp_mutex){+.+.}-{4:4}, at: exp_funnel_lock kernel/rcu/tree_exp.h:311 [inline]
#2: ffffffff8e766578 (rcu_state.exp_mutex){+.+.}-{4:4}, at: synchronize_rcu_expedited+0x2d0/0x770 kernel/rcu/tree_exp.h:961
2 locks held by syz-executor/7943:
#0: ffffffff8f309048 (&ops->srcu#2){.+.+}-{0:0}, at: rcu_lock_acquire include/linux/rcupdate.h:312 [inline]
#0: ffffffff8f309048 (&ops->srcu#2){.+.+}-{0:0}, at: rcu_read_lock include/linux/rcupdate.h:850 [inline]
#0: ffffffff8f309048 (&ops->srcu#2){.+.+}-{0:0}, at: rtnl_link_ops_get+0x23/0x250 net/core/rtnetlink.c:570
#1: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_lock net/core/rtnetlink.c:80 [inline]
#1: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_nets_lock net/core/rtnetlink.c:341 [inline]
#1: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_newlink+0x8a1/0x1be0 net/core/rtnetlink.c:4071
2 locks held by syz-executor/7974:
#0: ffffffff90136ea0 (&ops->srcu#2){.+.+}-{0:0}, at: rcu_lock_acquire include/linux/rcupdate.h:312 [inline]
#0: ffffffff90136ea0 (&ops->srcu#2){.+.+}-{0:0}, at: rcu_read_lock include/linux/rcupdate.h:850 [inline]
#0: ffffffff90136ea0 (&ops->srcu#2){.+.+}-{0:0}, at: rtnl_link_ops_get+0x23/0x250 net/core/rtnetlink.c:570
#1: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_lock net/core/rtnetlink.c:80 [inline]
#1: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_nets_lock net/core/rtnetlink.c:341 [inline]
#1: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_newlink+0x8a1/0x1be0 net/core/rtnetlink.c:4071
2 locks held by syz-executor/7981:
#0: ffffffff8fbbe770 (pernet_ops_rwsem){++++}-{4:4}, at: copy_net_ns+0x4f7/0x730 net/core/net_namespace.c:577
#1: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_net_lock include/linux/rtnetlink.h:130 [inline]
#1: ffffffff8fbcd588 (rtnl_mutex){+.+.}-{4:4}, at: register_netdevice_notifier_net+0x1a/0xa0 net/core/dev.c:2096
=============================================
NMI backtrace for cpu 0
CPU: 0 UID: 0 PID: 30 Comm: khungtaskd Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2026
Call Trace:
<TASK>
dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120
nmi_cpu_backtrace+0x274/0x2d0 lib/nmi_backtrace.c:113
nmi_trigger_cpumask_backtrace+0x17a/0x300 lib/nmi_backtrace.c:62
trigger_all_cpu_backtrace include/linux/nmi.h:161 [inline]
__sys_info lib/sys_info.c:157 [inline]
sys_info+0x135/0x170 lib/sys_info.c:165
check_hung_uninterruptible_tasks kernel/hung_task.c:346 [inline]
watchdog+0xfd9/0x1030 kernel/hung_task.c:515
kthread+0x388/0x470 kernel/kthread.c:467
ret_from_fork+0x51e/0xb90 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
Sending NMI from CPU 0 to CPUs 1:
NMI backtrace for cpu 1
CPU: 1 UID: 0 PID: 7551 Comm: kworker/u8:10 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2026
Workqueue: events_unbound nsim_dev_trap_report_work
RIP: 0010:__orc_find arch/x86/kernel/unwind_orc.c:101 [inline]
RIP: 0010:orc_find arch/x86/kernel/unwind_orc.c:238 [inline]
RIP: 0010:unwind_next_frame+0x4db/0x23c0 arch/x86/kernel/unwind_orc.c:510
Code: 4c 8b 7c 24 50 48 bd 00 00 00 00 00 fc ff df 4c 8b 64 24 20 4c 8b 6c 24 48 0f 84 72 15 00 00 e9 03 02 00 00 49 89 d5 48 89 d5 <48> 89 d8 48 29 e8 48 89 c1 48 c1 f9 02 48 c1 e8 3f 48 01 c8 48 83
RSP: 0018:ffffc9000d4af4b8 EFLAGS: 00000297
RAX: ffffffff902d0014 RBX: ffffffff902d0014 RCX: ffffffff902d001c
RDX: ffffffff902d0010 RSI: ffffffff90aa9e52 RDI: ffffffff8c27aaa0
RBP: ffffffff902d0010 R08: 000000000000000c R09: ffffffff8e7602e0
R10: ffffc9000d4af5d8 R11: ffffffff81b0c580 R12: ffffffff81b0c518
R13: ffffffff902d0010 R14: ffffc9000d4af588 R15: ffffffff902d0018
FS: 0000000000000000(0000) GS:ffff888125560000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f1329d45000 CR3: 000000008888e000 CR4: 00000000003526f0
Call Trace:
<TASK>
arch_stack_walk+0x11b/0x150 arch/x86/kernel/stacktrace.c:25
stack_trace_save+0xa9/0x100 kernel/stacktrace.c:122
kasan_save_stack mm/kasan/common.c:57 [inline]
kasan_save_track+0x3e/0x80 mm/kasan/common.c:78
kasan_save_free_info+0x46/0x50 mm/kasan/generic.c:584
poison_slab_object mm/kasan/common.c:253 [inline]
__kasan_slab_free+0x5c/0x80 mm/kasan/common.c:285
kasan_slab_free include/linux/kasan.h:235 [inline]
slab_free_hook mm/slub.c:2687 [inline]
slab_free mm/slub.c:6124 [inline]
kfree+0x1c1/0x630 mm/slub.c:6442
skb_kfree_head net/core/skbuff.c:1089 [inline]
skb_free_head net/core/skbuff.c:1101 [inline]
skb_release_data+0x6f0/0x940 net/core/skbuff.c:1128
skb_release_all net/core/skbuff.c:1203 [inline]
__kfree_skb+0x5d/0x210 net/core/skbuff.c:1217
nsim_dev_trap_report drivers/net/netdevsim/dev.c:892 [inline]
nsim_dev_trap_report_work+0x7cf/0xb80 drivers/net/netdevsim/dev.c:922
process_one_work+0x949/0x1650 kernel/workqueue.c:3279
process_scheduled_works kernel/workqueue.c:3362 [inline]
worker_thread+0xb46/0x1140 kernel/workqueue.c:3443
kthread+0x388/0x470 kernel/kthread.c:467
ret_from_fork+0x51e/0xb90 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
^ permalink raw reply [flat|nested] 9+ messages in thread* Re: [syzbot] [afs?] INFO: task hung in afs_cell_purge (2)
2025-05-05 6:32 [syzbot] [afs?] INFO: task hung in afs_cell_purge (2) syzbot
` (2 preceding siblings ...)
2026-02-16 14:48 ` syzbot
@ 2026-06-16 16:06 ` David Howells
2026-06-16 20:08 ` syzbot
2026-08-04 13:08 ` syzbot
4 siblings, 1 reply; 9+ messages in thread
From: David Howells @ 2026-06-16 16:06 UTC (permalink / raw)
To: syzbot
Cc: dhowells, linux-afs, linux-kernel, marc.dionne, Hillf Danton,
syzkaller-bugs
#syz test: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git v7.1
afs: Fix hang in afs_cell_purge()
Fix a hang in afs_cell_purge() due to net->cells_outstanding being updated
before the check for idr_alloc_cyclic() failing.
Reported-by: syzbot+750f21d691e244b473b1@syzkaller.appspotmail.com
Suggested-by: Hillf Danton <hdanton@sina.com>
Signed-off-by: David Howells <dhowells@redhat.com>
cc: Marc Dionne <marc.dionne@auristor.com>
cc: linux-afs@lists.infradead.org
diff --git a/fs/afs/cell.c b/fs/afs/cell.c
index 9738684dbdd2..e0fab1609f27 100644
--- a/fs/afs/cell.c
+++ b/fs/afs/cell.c
@@ -205,11 +205,11 @@ static struct afs_cell *afs_alloc_cell(struct afs_net *net,
cell->dns_source = vllist->source;
cell->dns_status = vllist->status;
smp_store_release(&cell->dns_lookup_count, 1); /* vs source/status */
- atomic_inc(&net->cells_outstanding);
ret = idr_alloc_cyclic(&net->cells_dyn_ino, cell,
2, INT_MAX / 2, GFP_KERNEL);
if (ret < 0)
goto error;
+ atomic_inc(&net->cells_outstanding);
cell->dynroot_ino = ret;
cell->debug_id = atomic_inc_return(&cell_debug_id);
^ permalink raw reply related [flat|nested] 9+ messages in thread* Re: [syzbot] [afs?] INFO: task hung in afs_cell_purge (2)
2025-05-05 6:32 [syzbot] [afs?] INFO: task hung in afs_cell_purge (2) syzbot
` (3 preceding siblings ...)
2026-06-16 16:06 ` David Howells
@ 2026-08-04 13:08 ` syzbot
4 siblings, 0 replies; 9+ messages in thread
From: syzbot @ 2026-08-04 13:08 UTC (permalink / raw)
To: brauner, dhowells, hdanton, linux-afs, linux-kernel, marc.dionne,
nogikh, syzkaller-bugs
syzbot suspects this issue was fixed by commit:
commit c9c3b615a462a4023bd148f02c564e175ed10502
Author: David Howells <dhowells@redhat.com>
Date: Mon Jun 22 09:08:45 2026 +0000
afs: Fix misplaced inc of net->cells_outstanding
bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=10a6be32580000
start commit: 7a13c14ee59d Merge tag 'for-6.15-rc4-tag' of git://git.ker..
git tree: upstream
kernel config: https://syzkaller.appspot.com/x/.config?x=a42a9d552788177b
dashboard link: https://syzkaller.appspot.com/bug?extid=750f21d691e244b473b1
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=13a101cc580000
If the result looks correct, please mark the issue as fixed by replying with:
#syz fix: afs: Fix misplaced inc of net->cells_outstanding
For information about bisection process see: https://goo.gl/tpsmEJ#bisection
^ permalink raw reply [flat|nested] 9+ messages in thread