* [syzbot] [kernel?] INFO: rcu detected stall in __hrtimer_run_queues (3)
@ 2026-08-08 20:09 syzbot
2026-08-31 15:55 ` syzbot
0 siblings, 1 reply; 5+ messages in thread
From: syzbot @ 2026-08-08 20:09 UTC (permalink / raw)
To: anna-maria, frederic, linux-kernel, netdev, syzkaller-bugs, tglx
Hello,
syzbot found the following issue on:
HEAD commit: 594d90519502 af_unix: Unlink scc_entry in unix_del_edge().
git tree: net
console output: https://syzkaller.appspot.com/x/log.txt?x=13d4c132580000
kernel config: https://syzkaller.appspot.com/x/.config?x=3e8a402093abe6b2
dashboard link: https://syzkaller.appspot.com/bug?extid=6d991f16f4bcc8eeea24
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=17d4c132580000
Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/672b53d154af/disk-594d9051.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/6f5c69520cde/vmlinux-594d9051.xz
kernel image: https://storage.googleapis.com/syzbot-assets/5f0629640136/bzImage-594d9051.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+6d991f16f4bcc8eeea24@syzkaller.appspotmail.com
rcu: INFO: rcu_preempt detected stalls on CPUs/tasks:
rcu: Tasks blocked on level-0 rcu_node (CPUs 0-1): P5762
rcu: (detected by 0, t=10502 jiffies, g=15917, q=4592 ncpus=2)
task:syz-executor state:R running task stack:22408 pid:5762 tgid:5762 ppid:1 task_flags:0x400140 flags:0x00080012
Call Trace:
<IRQ>
sched_show_task+0x4aa/0x5f0 kernel/sched/core.c:8184
rcu_print_detail_task_stall_rnp kernel/rcu/tree_stall.h:292 [inline]
print_other_cpu_stall+0xf7d/0x1310 kernel/rcu/tree_stall.h:680
check_cpu_stall kernel/rcu/tree_stall.h:855 [inline]
rcu_pending kernel/rcu/tree.c:3708 [inline]
rcu_sched_clock_irq+0x93d/0x1050 kernel/rcu/tree.c:2744
update_process_times+0x23b/0x2f0 kernel/time/timer.c:2475
tick_sched_handle kernel/time/tick-sched.c:296 [inline]
tick_nohz_handler+0x38f/0x6b0 kernel/time/tick-sched.c:317
__run_hrtimer kernel/time/hrtimer.c:2032 [inline]
__hrtimer_run_queues+0x371/0xa10 kernel/time/hrtimer.c:2096
hrtimer_interrupt+0x448/0x910 kernel/time/hrtimer.c:2215
local_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1051 [inline]
__sysvec_apic_timer_interrupt+0x102/0x430 arch/x86/kernel/apic/apic.c:1068
instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1062 [inline]
sysvec_apic_timer_interrupt+0x52/0xc0 arch/x86/kernel/apic/apic.c:1062
asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:674
RIP: 0010:__raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:179 [inline]
RIP: 0010:_raw_spin_unlock_irqrestore+0x47/0x80 kernel/locking/spinlock.c:198
Code: f7 e8 2d 7d d0 f5 f7 c3 00 02 00 00 74 05 e8 00 5e fc f5 9c 58 a9 00 02 00 00 75 27 f7 c3 00 02 00 00 74 01 fb bf 01 00 00 00 <e8> c4 90 c1 f5 65 8b 05 bd a0 99 07 85 c0 74 18 5b 41 5e c3 cc cc
RSP: 0018:ffffc90000007e08 EFLAGS: 00000206
RAX: 0000000000000002 RBX: 0000000000000246 RCX: 0000000000000102
RDX: 0000000000000000 RSI: ffffffff8e227e64 RDI: 0000000000000001
RBP: ffff88807b4d0938 R08: ffffffff90573637 R09: 1ffffffff20ae6c6
R10: dffffc0000000000 R11: fffffbfff20ae6c7 R12: ffff8880b86281c0
R13: ffffffff89cd5bf0 R14: ffff8880b86281c0 R15: 1ffff110170c50c2
__run_hrtimer kernel/time/hrtimer.c:2028 [inline]
__hrtimer_run_queues+0x2bf/0xa10 kernel/time/hrtimer.c:2096
hrtimer_run_softirq+0x17a/0x240 kernel/time/hrtimer.c:2113
handle_softirqs+0x225/0x840 kernel/softirq.c:622
__do_softirq kernel/softirq.c:656 [inline]
invoke_softirq kernel/softirq.c:496 [inline]
__irq_exit_rcu+0xca/0x220 kernel/softirq.c:735
irq_exit_rcu+0x9/0x30 kernel/softirq.c:752
instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1062 [inline]
sysvec_apic_timer_interrupt+0xa6/0xc0 arch/x86/kernel/apic/apic.c:1062
</IRQ>
<TASK>
asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:674
RIP: 0010:finish_task_switch+0x417/0xc60 kernel/sched/core.c:5361
Code: 04 00 00 41 c7 84 24 20 0e 00 00 00 00 00 00 0f 1f 44 00 00 49 83 c4 48 4c 89 e7 e8 53 4c 3d 0a e8 de aa 39 00 fb 4c 8b 65 c8 <49> 8d bc 24 f8 16 00 00 48 89 f8 48 c1 e8 03 42 0f b6 04 30 84 c0
RSP: 0018:ffffc900031ef320 EFLAGS: 00000206
RAX: 0000000000018aa5 RBX: ffff8880b863bf20 RCX: 0000000080000001
RDX: 0000000000000000 RSI: ffffffff8e227e64 RDI: ffffffff8c4bba80
RBP: ffffc900031ef370 R08: ffffffff90573637 R09: 1ffffffff20ae6c6
R10: dffffc0000000000 R11: fffffbfff20ae6c7 R12: ffff888029f49f00
R13: ffff8880b863bee8 R14: dffffc0000000000 R15: 1ffff110170c77e4
context_switch kernel/sched/core.c:5513 [inline]
__schedule+0x17e1/0x56c0 kernel/sched/core.c:7234
preempt_schedule_irq+0x4d/0xa0 kernel/sched/core.c:7556
irqentry_exit_to_kernel_mode include/linux/irq-entry-common.h:539 [inline]
irqentry_exit+0x14f/0x8f0 kernel/entry/common.c:167
asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:674
RIP: 0010:lock_acquire+0x221/0x350 kernel/locking/lockdep.c:5872
Code: ff ff ff e8 51 6d 2d 0a f7 44 24 08 00 02 00 00 0f 84 3a ff ff ff 65 48 8b 05 db c7 c9 11 48 3b 44 24 58 75 33 fb 48 83 c4 60 <5b> 41 5c 41 5d 41 5e 41 5f 5d e9 80 6f 30 0a cc 48 8d 3d c8 0c b8
RSP: 0018:ffffc900031ef6a0 EFLAGS: 00000286
RAX: fa5918e404740300 RBX: 0000000000000000 RCX: 0000000000000046
RDX: 000000005a44979c RSI: ffffffff8e4acd09 RDI: ffffffff8c4bba80
RBP: ffffffff8177827f R08: ffffffff8177827f R09: 0000000000000000
R10: 0000000000000000 R11: ffffffff8eb59c60 R12: 0000000000000002
R13: ffffffff8eb59c60 R14: 0000000000000000 R15: 0000000000000246
rcu_lock_acquire include/linux/rcupdate.h:300 [inline]
rcu_read_lock include/linux/rcupdate.h:840 [inline]
class_rcu_constructor include/linux/rcupdate.h:1183 [inline]
unwind_next_frame+0xac/0x2550 arch/x86/kernel/unwind_orc.c:495
arch_stack_walk+0x11b/0x150 arch/x86/kernel/stacktrace.c:25
stack_trace_save+0xa9/0x100 kernel/stacktrace.c:122
kasan_save_stack+0x3e/0x60 mm/kasan/common.c:57
kasan_record_aux_stack+0xbd/0xd0 mm/kasan/generic.c:556
__call_rcu_common kernel/rcu/tree.c:3159 [inline]
call_rcu+0xee/0x8b0 kernel/rcu/tree.c:3279
__destroy_inode+0x2a1/0x630 fs/inode.c:362
destroy_inode fs/inode.c:385 [inline]
evict+0x8d4/0xb50 fs/inode.c:849
dentry_kill+0x1b9/0x880 fs/dcache.c:826
finish_dput+0x1a/0x260 fs/dcache.c:1001
__fput+0x675/0xa50 fs/file_table.c:520
fput_close_sync+0x11f/0x240 fs/file_table.c:617
__do_sys_close fs/open.c:1511 [inline]
__se_sys_close fs/open.c:1496 [inline]
__x64_sys_close+0x7e/0x110 fs/open.c:1496
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f6c4799d247
Code: 44 00 00 48 83 ec 10 48 63 ff 45 31 c9 45 31 c0 6a 01 31 c9 e8 3a c0 fb ff 48 83 c4 18 c3 0f 1f 44 00 00 b8 03 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 01 c3 48 c7 c2 e8 ff ff ff f7 d8 64 89 02 b8
RSP: 002b:00007ffdab7221d8 EFLAGS: 00000246 ORIG_RAX: 0000000000000003
RAX: ffffffffffffffda RBX: 0000000000000005 RCX: 00007f6c4799d247
RDX: 0000000000000000 RSI: 0000000000008933 RDI: 0000000000000005
RBP: 0000000000000003 R08: 0000000000000000 R09: 00000000fffffff9
R10: 0000000000000002 R11: 0000000000000246 R12: 00007ffdab722260
R13: 00007ffdab722350 R14: 00007f6c48754620 R15: 00007ffdab722350
</TASK>
rcu: rcu_preempt kthread timer wakeup didn't happen for 10546 jiffies! g15917 f0x0 RCU_GP_WAIT_FQS(5) ->state=0x402
rcu: Possible timer handling issue on cpu=0 timer-softirq=3578
rcu: rcu_preempt kthread starved for 10577 jiffies! g15917 f0x0 RCU_GP_WAIT_FQS(5) ->state=0x402 ->cpu=0
rcu: Unless rcu_preempt kthread gets sufficient CPU time, OOM is now expected behavior.
rcu: RCU grace-period kthread stack dump:
task:rcu_preempt state:I stack:27752 pid:16 tgid:16 ppid:2 task_flags:0x208040 flags:0x00080000
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5510 [inline]
__schedule+0x17d9/0x56c0 kernel/sched/core.c:7234
__schedule_loop kernel/sched/core.c:7311 [inline]
schedule+0x164/0x2b0 kernel/sched/core.c:7326
schedule_timeout+0x152/0x2c0 kernel/time/sleep_timeout.c:99
rcu_gp_fqs_loop+0x30c/0x11f0 kernel/rcu/tree.c:2123
rcu_gp_kthread+0x9e/0x2b0 kernel/rcu/tree.c:2325
kthread+0x388/0x470 kernel/kthread.c:436
ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
rcu: Stack dump where RCU GP kthread last ran:
CPU: 0 UID: 0 PID: 5762 Comm: syz-executor Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
RIP: 0010:__raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:179 [inline]
RIP: 0010:_raw_spin_unlock_irqrestore+0x47/0x80 kernel/locking/spinlock.c:198
Code: f7 e8 2d 7d d0 f5 f7 c3 00 02 00 00 74 05 e8 00 5e fc f5 9c 58 a9 00 02 00 00 75 27 f7 c3 00 02 00 00 74 01 fb bf 01 00 00 00 <e8> c4 90 c1 f5 65 8b 05 bd a0 99 07 85 c0 74 18 5b 41 5e c3 cc cc
RSP: 0018:ffffc90000007e08 EFLAGS: 00000206
RAX: 0000000000000002 RBX: 0000000000000246 RCX: 0000000000000102
RDX: 0000000000000000 RSI: ffffffff8e227e64 RDI: 0000000000000001
RBP: ffff88807b4d0938 R08: ffffffff90573637 R09: 1ffffffff20ae6c6
R10: dffffc0000000000 R11: fffffbfff20ae6c7 R12: ffff8880b86281c0
R13: ffffffff89cd5bf0 R14: ffff8880b86281c0 R15: 1ffff110170c50c2
FS: 000055555c50f500(0000) GS:ffff888124f58000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000055cf03528bd0 CR3: 000000007fb92000 CR4: 00000000003526f0
Call Trace:
<IRQ>
__run_hrtimer kernel/time/hrtimer.c:2028 [inline]
__hrtimer_run_queues+0x2bf/0xa10 kernel/time/hrtimer.c:2096
hrtimer_run_softirq+0x17a/0x240 kernel/time/hrtimer.c:2113
handle_softirqs+0x225/0x840 kernel/softirq.c:622
__do_softirq kernel/softirq.c:656 [inline]
invoke_softirq kernel/softirq.c:496 [inline]
__irq_exit_rcu+0xca/0x220 kernel/softirq.c:735
irq_exit_rcu+0x9/0x30 kernel/softirq.c:752
instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1062 [inline]
sysvec_apic_timer_interrupt+0xa6/0xc0 arch/x86/kernel/apic/apic.c:1062
</IRQ>
<TASK>
asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:674
RIP: 0010:finish_task_switch+0x417/0xc60 kernel/sched/core.c:5361
Code: 04 00 00 41 c7 84 24 20 0e 00 00 00 00 00 00 0f 1f 44 00 00 49 83 c4 48 4c 89 e7 e8 53 4c 3d 0a e8 de aa 39 00 fb 4c 8b 65 c8 <49> 8d bc 24 f8 16 00 00 48 89 f8 48 c1 e8 03 42 0f b6 04 30 84 c0
RSP: 0018:ffffc900031ef320 EFLAGS: 00000206
RAX: 0000000000018aa5 RBX: ffff8880b863bf20 RCX: 0000000080000001
RDX: 0000000000000000 RSI: ffffffff8e227e64 RDI: ffffffff8c4bba80
RBP: ffffc900031ef370 R08: ffffffff90573637 R09: 1ffffffff20ae6c6
R10: dffffc0000000000 R11: fffffbfff20ae6c7 R12: ffff888029f49f00
R13: ffff8880b863bee8 R14: dffffc0000000000 R15: 1ffff110170c77e4
context_switch kernel/sched/core.c:5513 [inline]
__schedule+0x17e1/0x56c0 kernel/sched/core.c:7234
preempt_schedule_irq+0x4d/0xa0 kernel/sched/core.c:7556
irqentry_exit_to_kernel_mode include/linux/irq-entry-common.h:539 [inline]
irqentry_exit+0x14f/0x8f0 kernel/entry/common.c:167
asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:674
RIP: 0010:lock_acquire+0x221/0x350 kernel/locking/lockdep.c:5872
Code: ff ff ff e8 51 6d 2d 0a f7 44 24 08 00 02 00 00 0f 84 3a ff ff ff 65 48 8b 05 db c7 c9 11 48 3b 44 24 58 75 33 fb 48 83 c4 60 <5b> 41 5c 41 5d 41 5e 41 5f 5d e9 80 6f 30 0a cc 48 8d 3d c8 0c b8
RSP: 0018:ffffc900031ef6a0 EFLAGS: 00000286
RAX: fa5918e404740300 RBX: 0000000000000000 RCX: 0000000000000046
RDX: 000000005a44979c RSI: ffffffff8e4acd09 RDI: ffffffff8c4bba80
RBP: ffffffff8177827f R08: ffffffff8177827f R09: 0000000000000000
R10: 0000000000000000 R11: ffffffff8eb59c60 R12: 0000000000000002
R13: ffffffff8eb59c60 R14: 0000000000000000 R15: 0000000000000246
rcu_lock_acquire include/linux/rcupdate.h:300 [inline]
rcu_read_lock include/linux/rcupdate.h:840 [inline]
class_rcu_constructor include/linux/rcupdate.h:1183 [inline]
unwind_next_frame+0xac/0x2550 arch/x86/kernel/unwind_orc.c:495
arch_stack_walk+0x11b/0x150 arch/x86/kernel/stacktrace.c:25
stack_trace_save+0xa9/0x100 kernel/stacktrace.c:122
kasan_save_stack+0x3e/0x60 mm/kasan/common.c:57
kasan_record_aux_stack+0xbd/0xd0 mm/kasan/generic.c:556
__call_rcu_common kernel/rcu/tree.c:3159 [inline]
call_rcu+0xee/0x8b0 kernel/rcu/tree.c:3279
__destroy_inode+0x2a1/0x630 fs/inode.c:362
destroy_inode fs/inode.c:385 [inline]
evict+0x8d4/0xb50 fs/inode.c:849
dentry_kill+0x1b9/0x880 fs/dcache.c:826
finish_dput+0x1a/0x260 fs/dcache.c:1001
__fput+0x675/0xa50 fs/file_table.c:520
fput_close_sync+0x11f/0x240 fs/file_table.c:617
__do_sys_close fs/open.c:1511 [inline]
__se_sys_close fs/open.c:1496 [inline]
__x64_sys_close+0x7e/0x110 fs/open.c:1496
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f6c4799d247
Code: 44 00 00 48 83 ec 10 48 63 ff 45 31 c9 45 31 c0 6a 01 31 c9 e8 3a c0 fb ff 48 83 c4 18 c3 0f 1f 44 00 00 b8 03 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 01 c3 48 c7 c2 e8 ff ff ff f7 d8 64 89 02 b8
RSP: 002b:00007ffdab7221d8 EFLAGS: 00000246 ORIG_RAX: 0000000000000003
RAX: ffffffffffffffda RBX: 0000000000000005 RCX: 00007f6c4799d247
RDX: 0000000000000000 RSI: 0000000000008933 RDI: 0000000000000005
RBP: 0000000000000003 R08: 0000000000000000 R09: 00000000fffffff9
R10: 0000000000000002 R11: 0000000000000246 R12: 00007ffdab722260
R13: 00007ffdab722350 R14: 00007f6c48754620 R15: 00007ffdab722350
</TASK>
sched: DL replenish lagged too much
---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [syzbot] [kernel?] INFO: rcu detected stall in __hrtimer_run_queues (3)
2026-08-08 20:09 [syzbot] [kernel?] INFO: rcu detected stall in __hrtimer_run_queues (3) syzbot
@ 2026-08-31 15:55 ` syzbot
2026-09-04 5:00 ` Thomas Gleixner
0 siblings, 1 reply; 5+ messages in thread
From: syzbot @ 2026-08-31 15:55 UTC (permalink / raw)
To: anna-maria, frederic, linux-kernel, netdev, syzkaller-bugs, tglx
syzbot has found a reproducer for the following issue on:
HEAD commit: f1b8fa82cab7 Merge branch 'for-next/core' into for-kernelci
git tree: git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git for-kernelci
console output: https://syzkaller.appspot.com/x/log.txt?x=15aee379580000
kernel config: https://syzkaller.appspot.com/x/.config?x=d1128bc53f2ef7f3
dashboard link: https://syzkaller.appspot.com/bug?extid=6d991f16f4bcc8eeea24
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=15632d9e580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=15dd1c15580000
Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/932d85a2bda2/disk-f1b8fa82.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/5b6b8fb76e8d/vmlinux-f1b8fa82.xz
kernel image: https://storage.googleapis.com/syzbot-assets/c246b61ee396/Image-f1b8fa82.gz.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+6d991f16f4bcc8eeea24@syzkaller.appspotmail.com
watchdog: BUG: soft lockup - CPU#0 stuck for 22s! [syz-executor:4831]
Modules linked in:
irq event stamp: 38640849
hardirqs last enabled at (38640848): [<ffff800080557cd8>] seqcount_lockdep_reader_access+0x7c/0xf8 include/linux/seqlock.h:75
hardirqs last disabled at (38640849): [<ffff80008690cd0c>] __el1_irq arch/arm64/kernel/entry-common.c:527 [inline]
hardirqs last disabled at (38640849): [<ffff80008690cd0c>] el1_interrupt+0x28/0x60 arch/arm64/kernel/entry-common.c:543
softirqs last enabled at (147672): [<ffff80008013891c>] local_bh_enable include/linux/bottom_half.h:33 [inline]
softirqs last enabled at (147672): [<ffff80008013891c>] put_cpu_fpsimd_context arch/arm64/kernel/fpsimd.c:251 [inline]
softirqs last enabled at (147672): [<ffff80008013891c>] do_sve_acc+0x32c/0x4b8 arch/arm64/kernel/fpsimd.c:1349
softirqs last disabled at (148217): [<ffff8000800204c0>] __do_softirq+0x14/0x20 kernel/softirq.c:656
CPU: 0 UID: 0 PID: 4831 Comm: syz-executor Not tainted syzkaller #0 PREEMPT
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/07/2026
pstate: 43400005 (nZcv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)
pc : trace_hrtimer_expire_exit include/trace/events/timer.h:321 [inline]
pc : __run_hrtimer kernel/time/hrtimer.c:2035 [inline]
pc : __hrtimer_run_queues+0x32c/0xbe0 kernel/time/hrtimer.c:2096
lr : arch_static_branch arch/arm64/include/asm/jump_label.h:36 [inline]
lr : trace_hrtimer_expire_exit include/trace/events/timer.h:321 [inline]
lr : __run_hrtimer kernel/time/hrtimer.c:2035 [inline]
lr : __hrtimer_run_queues+0x32c/0xbe0 kernel/time/hrtimer.c:2096
sp : ffff80008eb67de0
x29: ffff80008eb67e40 x28: 1fffe00034bb7c3a x27: ffff0001a5dbe1c0
x26: ffff0000c6453a90 x25: ffff0000d1a50d38 x24: dfff800000000000
x23: 0000000000000001 x22: ffff800084ec6bd4 x21: 1fffe00018c8a752
x20: ffff0000c64545a8 x19: ffff0000c6453a80 x18: 0000000000000000
x17: ffff80011d2d8000 x16: ffff80008eb60000 x15: 0000000000000000
x14: 00000000ffff8000 x13: 0000000000000001 x12: 0000000000000000
x11: 0000000000000000 x10: 0000000000000102 x9 : 0000000000000101
x8 : 0000000000000000 x7 : 0000000000000000 x6 : 0000000000000000
x5 : 0000000000000001 x4 : 0000000000000008 x3 : ffff80008046a634
x2 : 0000000000000001 x1 : ffff0000c6453a80 x0 : 0000000000000000
Call trace:
arch_static_branch arch/arm64/include/asm/jump_label.h:36 [inline] (P)
trace_hrtimer_expire_exit include/trace/events/timer.h:321 [inline] (P)
__run_hrtimer kernel/time/hrtimer.c:2035 [inline] (P)
__hrtimer_run_queues+0x32c/0xbe0 kernel/time/hrtimer.c:2096 (P)
hrtimer_run_softirq+0x15c/0x21c kernel/time/hrtimer.c:2113
handle_softirqs+0x2ec/0xd98 kernel/softirq.c:622
__do_softirq+0x14/0x20 kernel/softirq.c:656
____do_softirq+0x14/0x20 arch/arm64/kernel/irq.c:78
call_on_irq_stack+0x30/0x48 arch/arm64/kernel/entry.S:885
do_softirq_own_stack+0x20/0x2c arch/arm64/kernel/irq.c:83
invoke_softirq kernel/softirq.c:503 [inline]
__irq_exit_rcu+0x1ac/0x428 kernel/softirq.c:735
irq_exit_rcu+0x14/0x84 kernel/softirq.c:752
__el1_irq arch/arm64/kernel/entry-common.c:531 [inline]
el1_interrupt+0x40/0x60 arch/arm64/kernel/entry-common.c:543
el1h_64_irq_handler+0x18/0x24 arch/arm64/kernel/entry-common.c:548
el1h_64_irq+0x6c/0x70 arch/arm64/kernel/entry.S:586
__daif_local_irq_restore arch/arm64/include/asm/irqflags.h:175 [inline] (P)
arch_local_irq_restore arch/arm64/include/asm/irqflags.h:195 [inline] (P)
__raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:178 [inline] (P)
_raw_spin_unlock_irqrestore+0x44/0x98 kernel/locking/spinlock.c:198 (P)
__debug_check_no_obj_freed lib/debugobjects.c:1180 [inline]
debug_check_no_obj_freed+0x2c8/0x3a4 lib/debugobjects.c:1201
slab_free_hook mm/slub.c:2608 [inline]
slab_free mm/slub.c:6377 [inline]
kmem_cache_free+0x120/0x6b8 mm/slub.c:6504
file_free+0x128/0x1dc fs/file_table.c:104
__fput+0x538/0x74c fs/file_table.c:525
fput_close_sync+0x10c/0x278 fs/file_table.c:617
__do_sys_close fs/open.c:1511 [inline]
__se_sys_close fs/open.c:1496 [inline]
__arm64_sys_close+0x80/0x110 fs/open.c:1496
__invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]
invoke_syscall+0x98/0x244 arch/arm64/kernel/syscall.c:49
el0_svc_common+0xec/0x23c arch/arm64/kernel/syscall.c:121
do_el0_svc+0x4c/0x5c arch/arm64/kernel/syscall.c:140
el0_svc+0x64/0x260 arch/arm64/kernel/entry-common.c:758
el0t_64_sync_handler+0x44/0x104 arch/arm64/kernel/entry-common.c:777
el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:590
Sending NMI from CPU 0 to CPUs 1:
NMI backtrace for cpu 1
CPU: 1 UID: 0 PID: 4802 Comm: kworker/1:3 Not tainted syzkaller #0 PREEMPT
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/07/2026
Workqueue: rcu_gp process_srcu
pstate: 83400005 (Nzcv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)
pc : __raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:179 [inline]
pc : _raw_spin_unlock_irqrestore+0x44/0x98 kernel/locking/spinlock.c:198
lr : __raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:178 [inline]
lr : _raw_spin_unlock_irqrestore+0x38/0x98 kernel/locking/spinlock.c:198
sp : ffff80008eb77dc0
x29: ffff80008eb77dc0 x28: 1fffe00034bbc63a x27: ffff0001a5de31c0
x26: ffff0001a5de31d0 x25: ffff0000d2a4a538 x24: dfff800000000000
x23: 0000000000000001 x22: ffff800084ec6bd4 x21: ffff0001a5de2d80
x20: ffff0001a5de2d80 x19: 0000000000000000 x18: 00000000ffffffff
x17: ffff80008a7d6000 x16: 0000000000000002 x15: ffff80008a35fda0
x14: ffff80008a5d5e28 x13: 0000000000000001 x12: 0000000000000000
x11: ffff80008a5d5e28 x10: 0000000000000003 x9 : 0000000000000000
x8 : 00000000000000c0 x7 : 0000000000000000 x6 : 0000000000000000
x5 : 0000000000000001 x4 : 0000000000000008 x3 : ffff80008015611c
x2 : 0000000000000002 x1 : ffff0000d32c9d40 x0 : ffff80011d2fd000
Call trace:
__daif_local_irq_restore arch/arm64/include/asm/irqflags.h:175 [inline] (P)
arch_local_irq_restore arch/arm64/include/asm/irqflags.h:195 [inline] (P)
__raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:178 [inline] (P)
_raw_spin_unlock_irqrestore+0x44/0x98 kernel/locking/spinlock.c:198 (P)
__run_hrtimer kernel/time/hrtimer.c:2028 [inline]
__hrtimer_run_queues+0x22c/0xbe0 kernel/time/hrtimer.c:2096
hrtimer_run_softirq+0x15c/0x21c kernel/time/hrtimer.c:2113
handle_softirqs+0x2ec/0xd98 kernel/softirq.c:622
__do_softirq+0x14/0x20 kernel/softirq.c:656
____do_softirq+0x14/0x20 arch/arm64/kernel/irq.c:78
call_on_irq_stack+0x30/0x48 arch/arm64/kernel/entry.S:885
do_softirq_own_stack+0x20/0x2c arch/arm64/kernel/irq.c:83
invoke_softirq kernel/softirq.c:503 [inline]
__irq_exit_rcu+0x1ac/0x428 kernel/softirq.c:735
irq_exit_rcu+0x14/0x84 kernel/softirq.c:752
__el1_irq arch/arm64/kernel/entry-common.c:531 [inline]
el1_interrupt+0x40/0x60 arch/arm64/kernel/entry-common.c:543
el1h_64_irq_handler+0x18/0x24 arch/arm64/kernel/entry-common.c:548
el1h_64_irq+0x6c/0x70 arch/arm64/kernel/entry.S:586
__daif_local_irq_restore arch/arm64/include/asm/irqflags.h:175 [inline] (P)
arch_local_irq_restore arch/arm64/include/asm/irqflags.h:195 [inline] (P)
queue_delayed_work_on+0xf4/0x140 kernel/workqueue.c:2624 (P)
queue_delayed_work include/linux/workqueue.h:714 [inline]
srcu_reschedule+0x240/0x338 kernel/rcu/srcutree.c:1957
process_srcu+0xd04/0x1eb8 kernel/rcu/srcutree.c:1991
process_one_work kernel/workqueue.c:3322 [inline]
process_scheduled_works+0x788/0x10b8 kernel/workqueue.c:3405
worker_thread+0x798/0xbd0 kernel/workqueue.c:3486
kthread+0x304/0x3d4 kernel/kthread.c:436
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:838
watchdog: BUG: soft lockup - CPU#1 stuck for 26s! [kworker/1:3:4802]
Modules linked in:
irq event stamp: 44430735
hardirqs last enabled at (44430734): [<ffff800086932074>] __raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:178 [inline]
hardirqs last enabled at (44430734): [<ffff800086932074>] _raw_spin_unlock_irqrestore+0x38/0x98 kernel/locking/spinlock.c:198
hardirqs last disabled at (44430735): [<ffff80008690cd0c>] __el1_irq arch/arm64/kernel/entry-common.c:527 [inline]
hardirqs last disabled at (44430735): [<ffff80008690cd0c>] el1_interrupt+0x28/0x60 arch/arm64/kernel/entry-common.c:543
softirqs last enabled at (6136): [<ffff80008030e6e4>] softirq_handle_end kernel/softirq.c:468 [inline]
softirqs last enabled at (6136): [<ffff80008030e6e4>] handle_softirqs+0xc28/0xd98 kernel/softirq.c:650
softirqs last disabled at (7461): [<ffff8000800204c0>] __do_softirq+0x14/0x20 kernel/softirq.c:656
---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [syzbot] [kernel?] INFO: rcu detected stall in __hrtimer_run_queues (3)
2026-08-31 15:55 ` syzbot
@ 2026-09-04 5:00 ` Thomas Gleixner
2026-09-04 13:51 ` Aleksandr Nogikh
0 siblings, 1 reply; 5+ messages in thread
From: Thomas Gleixner @ 2026-09-04 5:00 UTC (permalink / raw)
To: syzbot, anna-maria, frederic, linux-kernel, netdev,
syzkaller-bugs
Cc: Catalin Marinas, Mark Rutland, Will Deacon
On Mon, Aug 31 2026 at 08:55, syzbot wrote:
CC+: ARM64 folks. It's their magic git tree ....
Maybe some day syzbot people get their act together and actually figure
out who should be CC'ed. Hope dies last...
> syzbot has found a reproducer for the following issue on:
>
> HEAD commit: f1b8fa82cab7 Merge branch 'for-next/core' into for-kernelci
> git tree: git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git for-kernelci
> console output: https://syzkaller.appspot.com/x/log.txt?x=15aee379580000
> kernel config: https://syzkaller.appspot.com/x/.config?x=d1128bc53f2ef7f3
> dashboard link: https://syzkaller.appspot.com/bug?extid=6d991f16f4bcc8eeea24
> compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
> userspace arch: arm64
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=15632d9e580000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=15dd1c15580000
>
> Downloadable assets:
> disk image: https://storage.googleapis.com/syzbot-assets/932d85a2bda2/disk-f1b8fa82.raw.xz
> vmlinux: https://storage.googleapis.com/syzbot-assets/5b6b8fb76e8d/vmlinux-f1b8fa82.xz
> kernel image: https://storage.googleapis.com/syzbot-assets/c246b61ee396/Image-f1b8fa82.gz.xz
>
> IMPORTANT: if you fix the issue, please add the following tag to the commit:
> Reported-by: syzbot+6d991f16f4bcc8eeea24@syzkaller.appspotmail.com
>
> watchdog: BUG: soft lockup - CPU#0 stuck for 22s! [syz-executor:4831]
> Modules linked in:
> irq event stamp: 38640849
> hardirqs last enabled at (38640848): [<ffff800080557cd8>] seqcount_lockdep_reader_access+0x7c/0xf8 include/linux/seqlock.h:75
> hardirqs last disabled at (38640849): [<ffff80008690cd0c>] __el1_irq arch/arm64/kernel/entry-common.c:527 [inline]
> hardirqs last disabled at (38640849): [<ffff80008690cd0c>] el1_interrupt+0x28/0x60 arch/arm64/kernel/entry-common.c:543
> softirqs last enabled at (147672): [<ffff80008013891c>] local_bh_enable include/linux/bottom_half.h:33 [inline]
> softirqs last enabled at (147672): [<ffff80008013891c>] put_cpu_fpsimd_context arch/arm64/kernel/fpsimd.c:251 [inline]
> softirqs last enabled at (147672): [<ffff80008013891c>] do_sve_acc+0x32c/0x4b8 arch/arm64/kernel/fpsimd.c:1349
> softirqs last disabled at (148217): [<ffff8000800204c0>] __do_softirq+0x14/0x20 kernel/softirq.c:656
> CPU: 0 UID: 0 PID: 4831 Comm: syz-executor Not tainted syzkaller #0 PREEMPT
> Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/07/2026
> pstate: 43400005 (nZcv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)
> pc : trace_hrtimer_expire_exit include/trace/events/timer.h:321 [inline]
> pc : __run_hrtimer kernel/time/hrtimer.c:2035 [inline]
> pc : __hrtimer_run_queues+0x32c/0xbe0 kernel/time/hrtimer.c:2096
> lr : arch_static_branch arch/arm64/include/asm/jump_label.h:36 [inline]
> lr : trace_hrtimer_expire_exit include/trace/events/timer.h:321 [inline]
> lr : __run_hrtimer kernel/time/hrtimer.c:2035 [inline]
> lr : __hrtimer_run_queues+0x32c/0xbe0 kernel/time/hrtimer.c:2096
> sp : ffff80008eb67de0
> x29: ffff80008eb67e40 x28: 1fffe00034bb7c3a x27: ffff0001a5dbe1c0
> x26: ffff0000c6453a90 x25: ffff0000d1a50d38 x24: dfff800000000000
> x23: 0000000000000001 x22: ffff800084ec6bd4 x21: 1fffe00018c8a752
> x20: ffff0000c64545a8 x19: ffff0000c6453a80 x18: 0000000000000000
> x17: ffff80011d2d8000 x16: ffff80008eb60000 x15: 0000000000000000
> x14: 00000000ffff8000 x13: 0000000000000001 x12: 0000000000000000
> x11: 0000000000000000 x10: 0000000000000102 x9 : 0000000000000101
> x8 : 0000000000000000 x7 : 0000000000000000 x6 : 0000000000000000
> x5 : 0000000000000001 x4 : 0000000000000008 x3 : ffff80008046a634
> x2 : 0000000000000001 x1 : ffff0000c6453a80 x0 : 0000000000000000
> Call trace:
> arch_static_branch arch/arm64/include/asm/jump_label.h:36 [inline] (P)
> trace_hrtimer_expire_exit include/trace/events/timer.h:321 [inline] (P)
> __run_hrtimer kernel/time/hrtimer.c:2035 [inline] (P)
> __hrtimer_run_queues+0x32c/0xbe0 kernel/time/hrtimer.c:2096 (P)
> hrtimer_run_softirq+0x15c/0x21c kernel/time/hrtimer.c:2113
> handle_softirqs+0x2ec/0xd98 kernel/softirq.c:622
> __do_softirq+0x14/0x20 kernel/softirq.c:656
> ____do_softirq+0x14/0x20 arch/arm64/kernel/irq.c:78
> call_on_irq_stack+0x30/0x48 arch/arm64/kernel/entry.S:885
> do_softirq_own_stack+0x20/0x2c arch/arm64/kernel/irq.c:83
> invoke_softirq kernel/softirq.c:503 [inline]
> __irq_exit_rcu+0x1ac/0x428 kernel/softirq.c:735
> irq_exit_rcu+0x14/0x84 kernel/softirq.c:752
> __el1_irq arch/arm64/kernel/entry-common.c:531 [inline]
> el1_interrupt+0x40/0x60 arch/arm64/kernel/entry-common.c:543
> el1h_64_irq_handler+0x18/0x24 arch/arm64/kernel/entry-common.c:548
> el1h_64_irq+0x6c/0x70 arch/arm64/kernel/entry.S:586
> __daif_local_irq_restore arch/arm64/include/asm/irqflags.h:175 [inline] (P)
> arch_local_irq_restore arch/arm64/include/asm/irqflags.h:195 [inline] (P)
> __raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:178 [inline] (P)
> _raw_spin_unlock_irqrestore+0x44/0x98 kernel/locking/spinlock.c:198 (P)
> __debug_check_no_obj_freed lib/debugobjects.c:1180 [inline]
> debug_check_no_obj_freed+0x2c8/0x3a4 lib/debugobjects.c:1201
> slab_free_hook mm/slub.c:2608 [inline]
> slab_free mm/slub.c:6377 [inline]
> kmem_cache_free+0x120/0x6b8 mm/slub.c:6504
> file_free+0x128/0x1dc fs/file_table.c:104
> __fput+0x538/0x74c fs/file_table.c:525
> fput_close_sync+0x10c/0x278 fs/file_table.c:617
> __do_sys_close fs/open.c:1511 [inline]
> __se_sys_close fs/open.c:1496 [inline]
> __arm64_sys_close+0x80/0x110 fs/open.c:1496
> __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]
> invoke_syscall+0x98/0x244 arch/arm64/kernel/syscall.c:49
> el0_svc_common+0xec/0x23c arch/arm64/kernel/syscall.c:121
> do_el0_svc+0x4c/0x5c arch/arm64/kernel/syscall.c:140
> el0_svc+0x64/0x260 arch/arm64/kernel/entry-common.c:758
> el0t_64_sync_handler+0x44/0x104 arch/arm64/kernel/entry-common.c:777
> el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:590
> Sending NMI from CPU 0 to CPUs 1:
> NMI backtrace for cpu 1
> CPU: 1 UID: 0 PID: 4802 Comm: kworker/1:3 Not tainted syzkaller #0 PREEMPT
> Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/07/2026
> Workqueue: rcu_gp process_srcu
> pstate: 83400005 (Nzcv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)
> pc : __raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:179 [inline]
> pc : _raw_spin_unlock_irqrestore+0x44/0x98 kernel/locking/spinlock.c:198
> lr : __raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:178 [inline]
> lr : _raw_spin_unlock_irqrestore+0x38/0x98 kernel/locking/spinlock.c:198
> sp : ffff80008eb77dc0
> x29: ffff80008eb77dc0 x28: 1fffe00034bbc63a x27: ffff0001a5de31c0
> x26: ffff0001a5de31d0 x25: ffff0000d2a4a538 x24: dfff800000000000
> x23: 0000000000000001 x22: ffff800084ec6bd4 x21: ffff0001a5de2d80
> x20: ffff0001a5de2d80 x19: 0000000000000000 x18: 00000000ffffffff
> x17: ffff80008a7d6000 x16: 0000000000000002 x15: ffff80008a35fda0
> x14: ffff80008a5d5e28 x13: 0000000000000001 x12: 0000000000000000
> x11: ffff80008a5d5e28 x10: 0000000000000003 x9 : 0000000000000000
> x8 : 00000000000000c0 x7 : 0000000000000000 x6 : 0000000000000000
> x5 : 0000000000000001 x4 : 0000000000000008 x3 : ffff80008015611c
> x2 : 0000000000000002 x1 : ffff0000d32c9d40 x0 : ffff80011d2fd000
> Call trace:
> __daif_local_irq_restore arch/arm64/include/asm/irqflags.h:175 [inline] (P)
> arch_local_irq_restore arch/arm64/include/asm/irqflags.h:195 [inline] (P)
> __raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:178 [inline] (P)
> _raw_spin_unlock_irqrestore+0x44/0x98 kernel/locking/spinlock.c:198 (P)
> __run_hrtimer kernel/time/hrtimer.c:2028 [inline]
> __hrtimer_run_queues+0x22c/0xbe0 kernel/time/hrtimer.c:2096
> hrtimer_run_softirq+0x15c/0x21c kernel/time/hrtimer.c:2113
> handle_softirqs+0x2ec/0xd98 kernel/softirq.c:622
> __do_softirq+0x14/0x20 kernel/softirq.c:656
> ____do_softirq+0x14/0x20 arch/arm64/kernel/irq.c:78
> call_on_irq_stack+0x30/0x48 arch/arm64/kernel/entry.S:885
> do_softirq_own_stack+0x20/0x2c arch/arm64/kernel/irq.c:83
> invoke_softirq kernel/softirq.c:503 [inline]
> __irq_exit_rcu+0x1ac/0x428 kernel/softirq.c:735
> irq_exit_rcu+0x14/0x84 kernel/softirq.c:752
> __el1_irq arch/arm64/kernel/entry-common.c:531 [inline]
> el1_interrupt+0x40/0x60 arch/arm64/kernel/entry-common.c:543
> el1h_64_irq_handler+0x18/0x24 arch/arm64/kernel/entry-common.c:548
> el1h_64_irq+0x6c/0x70 arch/arm64/kernel/entry.S:586
> __daif_local_irq_restore arch/arm64/include/asm/irqflags.h:175 [inline] (P)
> arch_local_irq_restore arch/arm64/include/asm/irqflags.h:195 [inline] (P)
> queue_delayed_work_on+0xf4/0x140 kernel/workqueue.c:2624 (P)
> queue_delayed_work include/linux/workqueue.h:714 [inline]
> srcu_reschedule+0x240/0x338 kernel/rcu/srcutree.c:1957
> process_srcu+0xd04/0x1eb8 kernel/rcu/srcutree.c:1991
> process_one_work kernel/workqueue.c:3322 [inline]
> process_scheduled_works+0x788/0x10b8 kernel/workqueue.c:3405
> worker_thread+0x798/0xbd0 kernel/workqueue.c:3486
> kthread+0x304/0x3d4 kernel/kthread.c:436
> ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:838
> watchdog: BUG: soft lockup - CPU#1 stuck for 26s! [kworker/1:3:4802]
> Modules linked in:
> irq event stamp: 44430735
> hardirqs last enabled at (44430734): [<ffff800086932074>] __raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:178 [inline]
> hardirqs last enabled at (44430734): [<ffff800086932074>] _raw_spin_unlock_irqrestore+0x38/0x98 kernel/locking/spinlock.c:198
> hardirqs last disabled at (44430735): [<ffff80008690cd0c>] __el1_irq arch/arm64/kernel/entry-common.c:527 [inline]
> hardirqs last disabled at (44430735): [<ffff80008690cd0c>] el1_interrupt+0x28/0x60 arch/arm64/kernel/entry-common.c:543
> softirqs last enabled at (6136): [<ffff80008030e6e4>] softirq_handle_end kernel/softirq.c:468 [inline]
> softirqs last enabled at (6136): [<ffff80008030e6e4>] handle_softirqs+0xc28/0xd98 kernel/softirq.c:650
> softirqs last disabled at (7461): [<ffff8000800204c0>] __do_softirq+0x14/0x20 kernel/softirq.c:656
>
>
> ---
> If you want syzbot to run the reproducer, reply with:
> #syz test: git://repo/address.git branch-or-commit-hash
> If you attach or paste a git patch, syzbot will apply it before testing.
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [syzbot] [kernel?] INFO: rcu detected stall in __hrtimer_run_queues (3)
2026-09-04 5:00 ` Thomas Gleixner
@ 2026-09-04 13:51 ` Aleksandr Nogikh
2026-09-04 22:32 ` Thomas Gleixner
0 siblings, 1 reply; 5+ messages in thread
From: Aleksandr Nogikh @ 2026-09-04 13:51 UTC (permalink / raw)
To: Thomas Gleixner, Edward Adam Davis
Cc: syzbot, anna-maria, frederic, linux-kernel, netdev,
syzkaller-bugs, Catalin Marinas, Mark Rutland, Will Deacon,
syzkaller
On Fri, Sep 4, 2026 at 7:00 AM 'Thomas Gleixner' via syzkaller-bugs
<syzkaller-bugs@googlegroups.com> wrote:
>
> On Mon, Aug 31 2026 at 08:55, syzbot wrote:
>
> CC+: ARM64 folks. It's their magic git tree ....
>
> Maybe some day syzbot people get their act together and actually figure
> out who should be CC'ed. Hope dies last...
In this particular case, the fact that the reproducer ran against the
arm64 tree does not mean the bug is arm64-specific. As shown on the
dashboard (https://syzkaller.appspot.com/bug?extid=6d991f16f4bcc8eeea24),
most crashes are coming from the x86_64 instances.
Judging by what reproducers do, it seems to be related to
net/sched/act_gate.c's gate_timer_func(), for which a patch has
recently been posted by Edward Adam Davis (Cc'd):
https://lore.kernel.org/all/tencent_19FD76F366C43D4737EE9682371A4BF87409@qq.com/
Syzbot attributes reports to maintainers based on the crash stack
trace rather than the git tree URL. Because CPU lockups and stalls in
a looping timer callback were caught inside kernel/time/hrtimer.c,
get_maintainer.pl pointed it at the timer subsystem.
>
> > syzbot has found a reproducer for the following issue on:
> >
> > HEAD commit: f1b8fa82cab7 Merge branch 'for-next/core' into for-kernelci
> > git tree: git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git for-kernelci
> > console output: https://syzkaller.appspot.com/x/log.txt?x=15aee379580000
> > kernel config: https://syzkaller.appspot.com/x/.config?x=d1128bc53f2ef7f3
> > dashboard link: https://syzkaller.appspot.com/bug?extid=6d991f16f4bcc8eeea24
> > compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
> > userspace arch: arm64
> > syz repro: https://syzkaller.appspot.com/x/repro.syz?x=15632d9e580000
> > C reproducer: https://syzkaller.appspot.com/x/repro.c?x=15dd1c15580000
> >
> > Downloadable assets:
> > disk image: https://storage.googleapis.com/syzbot-assets/932d85a2bda2/disk-f1b8fa82.raw.xz
> > vmlinux: https://storage.googleapis.com/syzbot-assets/5b6b8fb76e8d/vmlinux-f1b8fa82.xz
> > kernel image: https://storage.googleapis.com/syzbot-assets/c246b61ee396/Image-f1b8fa82.gz.xz
> >
> > IMPORTANT: if you fix the issue, please add the following tag to the commit:
> > Reported-by: syzbot+6d991f16f4bcc8eeea24@syzkaller.appspotmail.com
> >
> > watchdog: BUG: soft lockup - CPU#0 stuck for 22s! [syz-executor:4831]
> > Modules linked in:
> > irq event stamp: 38640849
> > hardirqs last enabled at (38640848): [<ffff800080557cd8>] seqcount_lockdep_reader_access+0x7c/0xf8 include/linux/seqlock.h:75
> > hardirqs last disabled at (38640849): [<ffff80008690cd0c>] __el1_irq arch/arm64/kernel/entry-common.c:527 [inline]
> > hardirqs last disabled at (38640849): [<ffff80008690cd0c>] el1_interrupt+0x28/0x60 arch/arm64/kernel/entry-common.c:543
> > softirqs last enabled at (147672): [<ffff80008013891c>] local_bh_enable include/linux/bottom_half.h:33 [inline]
> > softirqs last enabled at (147672): [<ffff80008013891c>] put_cpu_fpsimd_context arch/arm64/kernel/fpsimd.c:251 [inline]
> > softirqs last enabled at (147672): [<ffff80008013891c>] do_sve_acc+0x32c/0x4b8 arch/arm64/kernel/fpsimd.c:1349
> > softirqs last disabled at (148217): [<ffff8000800204c0>] __do_softirq+0x14/0x20 kernel/softirq.c:656
> > CPU: 0 UID: 0 PID: 4831 Comm: syz-executor Not tainted syzkaller #0 PREEMPT
> > Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/07/2026
> > pstate: 43400005 (nZcv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)
> > pc : trace_hrtimer_expire_exit include/trace/events/timer.h:321 [inline]
> > pc : __run_hrtimer kernel/time/hrtimer.c:2035 [inline]
> > pc : __hrtimer_run_queues+0x32c/0xbe0 kernel/time/hrtimer.c:2096
> > lr : arch_static_branch arch/arm64/include/asm/jump_label.h:36 [inline]
> > lr : trace_hrtimer_expire_exit include/trace/events/timer.h:321 [inline]
> > lr : __run_hrtimer kernel/time/hrtimer.c:2035 [inline]
> > lr : __hrtimer_run_queues+0x32c/0xbe0 kernel/time/hrtimer.c:2096
> > sp : ffff80008eb67de0
> > x29: ffff80008eb67e40 x28: 1fffe00034bb7c3a x27: ffff0001a5dbe1c0
> > x26: ffff0000c6453a90 x25: ffff0000d1a50d38 x24: dfff800000000000
> > x23: 0000000000000001 x22: ffff800084ec6bd4 x21: 1fffe00018c8a752
> > x20: ffff0000c64545a8 x19: ffff0000c6453a80 x18: 0000000000000000
> > x17: ffff80011d2d8000 x16: ffff80008eb60000 x15: 0000000000000000
> > x14: 00000000ffff8000 x13: 0000000000000001 x12: 0000000000000000
> > x11: 0000000000000000 x10: 0000000000000102 x9 : 0000000000000101
> > x8 : 0000000000000000 x7 : 0000000000000000 x6 : 0000000000000000
> > x5 : 0000000000000001 x4 : 0000000000000008 x3 : ffff80008046a634
> > x2 : 0000000000000001 x1 : ffff0000c6453a80 x0 : 0000000000000000
> > Call trace:
> > arch_static_branch arch/arm64/include/asm/jump_label.h:36 [inline] (P)
> > trace_hrtimer_expire_exit include/trace/events/timer.h:321 [inline] (P)
> > __run_hrtimer kernel/time/hrtimer.c:2035 [inline] (P)
> > __hrtimer_run_queues+0x32c/0xbe0 kernel/time/hrtimer.c:2096 (P)
> > hrtimer_run_softirq+0x15c/0x21c kernel/time/hrtimer.c:2113
> > handle_softirqs+0x2ec/0xd98 kernel/softirq.c:622
> > __do_softirq+0x14/0x20 kernel/softirq.c:656
> > ____do_softirq+0x14/0x20 arch/arm64/kernel/irq.c:78
> > call_on_irq_stack+0x30/0x48 arch/arm64/kernel/entry.S:885
> > do_softirq_own_stack+0x20/0x2c arch/arm64/kernel/irq.c:83
> > invoke_softirq kernel/softirq.c:503 [inline]
> > __irq_exit_rcu+0x1ac/0x428 kernel/softirq.c:735
> > irq_exit_rcu+0x14/0x84 kernel/softirq.c:752
> > __el1_irq arch/arm64/kernel/entry-common.c:531 [inline]
> > el1_interrupt+0x40/0x60 arch/arm64/kernel/entry-common.c:543
> > el1h_64_irq_handler+0x18/0x24 arch/arm64/kernel/entry-common.c:548
> > el1h_64_irq+0x6c/0x70 arch/arm64/kernel/entry.S:586
> > __daif_local_irq_restore arch/arm64/include/asm/irqflags.h:175 [inline] (P)
> > arch_local_irq_restore arch/arm64/include/asm/irqflags.h:195 [inline] (P)
> > __raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:178 [inline] (P)
> > _raw_spin_unlock_irqrestore+0x44/0x98 kernel/locking/spinlock.c:198 (P)
> > __debug_check_no_obj_freed lib/debugobjects.c:1180 [inline]
> > debug_check_no_obj_freed+0x2c8/0x3a4 lib/debugobjects.c:1201
> > slab_free_hook mm/slub.c:2608 [inline]
> > slab_free mm/slub.c:6377 [inline]
> > kmem_cache_free+0x120/0x6b8 mm/slub.c:6504
> > file_free+0x128/0x1dc fs/file_table.c:104
> > __fput+0x538/0x74c fs/file_table.c:525
> > fput_close_sync+0x10c/0x278 fs/file_table.c:617
> > __do_sys_close fs/open.c:1511 [inline]
> > __se_sys_close fs/open.c:1496 [inline]
> > __arm64_sys_close+0x80/0x110 fs/open.c:1496
> > __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]
> > invoke_syscall+0x98/0x244 arch/arm64/kernel/syscall.c:49
> > el0_svc_common+0xec/0x23c arch/arm64/kernel/syscall.c:121
> > do_el0_svc+0x4c/0x5c arch/arm64/kernel/syscall.c:140
> > el0_svc+0x64/0x260 arch/arm64/kernel/entry-common.c:758
> > el0t_64_sync_handler+0x44/0x104 arch/arm64/kernel/entry-common.c:777
> > el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:590
> > Sending NMI from CPU 0 to CPUs 1:
> > NMI backtrace for cpu 1
> > CPU: 1 UID: 0 PID: 4802 Comm: kworker/1:3 Not tainted syzkaller #0 PREEMPT
> > Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/07/2026
> > Workqueue: rcu_gp process_srcu
> > pstate: 83400005 (Nzcv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)
> > pc : __raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:179 [inline]
> > pc : _raw_spin_unlock_irqrestore+0x44/0x98 kernel/locking/spinlock.c:198
> > lr : __raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:178 [inline]
> > lr : _raw_spin_unlock_irqrestore+0x38/0x98 kernel/locking/spinlock.c:198
> > sp : ffff80008eb77dc0
> > x29: ffff80008eb77dc0 x28: 1fffe00034bbc63a x27: ffff0001a5de31c0
> > x26: ffff0001a5de31d0 x25: ffff0000d2a4a538 x24: dfff800000000000
> > x23: 0000000000000001 x22: ffff800084ec6bd4 x21: ffff0001a5de2d80
> > x20: ffff0001a5de2d80 x19: 0000000000000000 x18: 00000000ffffffff
> > x17: ffff80008a7d6000 x16: 0000000000000002 x15: ffff80008a35fda0
> > x14: ffff80008a5d5e28 x13: 0000000000000001 x12: 0000000000000000
> > x11: ffff80008a5d5e28 x10: 0000000000000003 x9 : 0000000000000000
> > x8 : 00000000000000c0 x7 : 0000000000000000 x6 : 0000000000000000
> > x5 : 0000000000000001 x4 : 0000000000000008 x3 : ffff80008015611c
> > x2 : 0000000000000002 x1 : ffff0000d32c9d40 x0 : ffff80011d2fd000
> > Call trace:
> > __daif_local_irq_restore arch/arm64/include/asm/irqflags.h:175 [inline] (P)
> > arch_local_irq_restore arch/arm64/include/asm/irqflags.h:195 [inline] (P)
> > __raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:178 [inline] (P)
> > _raw_spin_unlock_irqrestore+0x44/0x98 kernel/locking/spinlock.c:198 (P)
> > __run_hrtimer kernel/time/hrtimer.c:2028 [inline]
> > __hrtimer_run_queues+0x22c/0xbe0 kernel/time/hrtimer.c:2096
> > hrtimer_run_softirq+0x15c/0x21c kernel/time/hrtimer.c:2113
> > handle_softirqs+0x2ec/0xd98 kernel/softirq.c:622
> > __do_softirq+0x14/0x20 kernel/softirq.c:656
> > ____do_softirq+0x14/0x20 arch/arm64/kernel/irq.c:78
> > call_on_irq_stack+0x30/0x48 arch/arm64/kernel/entry.S:885
> > do_softirq_own_stack+0x20/0x2c arch/arm64/kernel/irq.c:83
> > invoke_softirq kernel/softirq.c:503 [inline]
> > __irq_exit_rcu+0x1ac/0x428 kernel/softirq.c:735
> > irq_exit_rcu+0x14/0x84 kernel/softirq.c:752
> > __el1_irq arch/arm64/kernel/entry-common.c:531 [inline]
> > el1_interrupt+0x40/0x60 arch/arm64/kernel/entry-common.c:543
> > el1h_64_irq_handler+0x18/0x24 arch/arm64/kernel/entry-common.c:548
> > el1h_64_irq+0x6c/0x70 arch/arm64/kernel/entry.S:586
> > __daif_local_irq_restore arch/arm64/include/asm/irqflags.h:175 [inline] (P)
> > arch_local_irq_restore arch/arm64/include/asm/irqflags.h:195 [inline] (P)
> > queue_delayed_work_on+0xf4/0x140 kernel/workqueue.c:2624 (P)
> > queue_delayed_work include/linux/workqueue.h:714 [inline]
> > srcu_reschedule+0x240/0x338 kernel/rcu/srcutree.c:1957
> > process_srcu+0xd04/0x1eb8 kernel/rcu/srcutree.c:1991
> > process_one_work kernel/workqueue.c:3322 [inline]
> > process_scheduled_works+0x788/0x10b8 kernel/workqueue.c:3405
> > worker_thread+0x798/0xbd0 kernel/workqueue.c:3486
> > kthread+0x304/0x3d4 kernel/kthread.c:436
> > ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:838
> > watchdog: BUG: soft lockup - CPU#1 stuck for 26s! [kworker/1:3:4802]
> > Modules linked in:
> > irq event stamp: 44430735
> > hardirqs last enabled at (44430734): [<ffff800086932074>] __raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:178 [inline]
> > hardirqs last enabled at (44430734): [<ffff800086932074>] _raw_spin_unlock_irqrestore+0x38/0x98 kernel/locking/spinlock.c:198
> > hardirqs last disabled at (44430735): [<ffff80008690cd0c>] __el1_irq arch/arm64/kernel/entry-common.c:527 [inline]
> > hardirqs last disabled at (44430735): [<ffff80008690cd0c>] el1_interrupt+0x28/0x60 arch/arm64/kernel/entry-common.c:543
> > softirqs last enabled at (6136): [<ffff80008030e6e4>] softirq_handle_end kernel/softirq.c:468 [inline]
> > softirqs last enabled at (6136): [<ffff80008030e6e4>] handle_softirqs+0xc28/0xd98 kernel/softirq.c:650
> > softirqs last disabled at (7461): [<ffff8000800204c0>] __do_softirq+0x14/0x20 kernel/softirq.c:656
> >
> >
> > ---
> > If you want syzbot to run the reproducer, reply with:
> > #syz test: git://repo/address.git branch-or-commit-hash
> > If you attach or paste a git patch, syzbot will apply it before testing.
>
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [syzbot] [kernel?] INFO: rcu detected stall in __hrtimer_run_queues (3)
2026-09-04 13:51 ` Aleksandr Nogikh
@ 2026-09-04 22:32 ` Thomas Gleixner
0 siblings, 0 replies; 5+ messages in thread
From: Thomas Gleixner @ 2026-09-04 22:32 UTC (permalink / raw)
To: Aleksandr Nogikh, Edward Adam Davis
Cc: syzbot, anna-maria, frederic, linux-kernel, netdev,
syzkaller-bugs, Catalin Marinas, Mark Rutland, Will Deacon,
syzkaller
On Fri, Sep 04 2026 at 15:51, Aleksandr Nogikh wrote:
> On Fri, Sep 4, 2026 at 7:00 AM 'Thomas Gleixner' via syzkaller-bugs
> <syzkaller-bugs@googlegroups.com> wrote:
>> On Mon, Aug 31 2026 at 08:55, syzbot wrote:
>>
>> CC+: ARM64 folks. It's their magic git tree ....
>>
>> Maybe some day syzbot people get their act together and actually figure
>> out who should be CC'ed. Hope dies last...
>
> In this particular case, the fact that the reproducer ran against the
> arm64 tree does not mean the bug is arm64-specific. As shown on the
> dashboard (https://syzkaller.appspot.com/bug?extid=6d991f16f4bcc8eeea24),
> most crashes are coming from the x86_64 instances.
Honestly I have no time to click through dashboards to figure this
out. If you already have that information then please include it. With
the gazillion of trees which have fresh patches in them it's not
necessarily a wrong assumption that it might be tree specific. It's the
same problem as bug reports against some random out of date kernel
versions.
> Judging by what reproducers do, it seems to be related to
> net/sched/act_gate.c's gate_timer_func(), for which a patch has
> recently been posted by Edward Adam Davis (Cc'd):
> https://lore.kernel.org/all/tencent_19FD76F366C43D4737EE9682371A4BF87409@qq.com/
They look similar, but the reproducers are completely different and the
act_gate backtrace shows the actual problematic code. It might be the
same bug. Edward should be able to tell.
> Syzbot attributes reports to maintainers based on the crash stack
> trace rather than the git tree URL. Because CPU lockups and stalls in
> a looping timer callback were caught inside kernel/time/hrtimer.c,
> get_maintainer.pl pointed it at the timer subsystem.
I get CC'ed on boatloads of reports which happen to show a back trace
somewhere in the code I maintain. In the vast majority of cases the
[hr]timer, interrupt ... core code is just the messenger. The hrtimer
interrupt does not magically rearm timers rapidly or leaves NULL
pointers around.
Don't get me wrong. syszbot is extremly useful, but the amount of work
it creates for those on the receiving end is not really managable and
it's not surprising to me that a lot of reports just fall through the
cracks in general. I try to avoid that, but at times I have to just deal
with more important problems and by the time I come back to it there is
a pile of new reports to wade through.
So having better information in the report would make this definitely
more managable for me and probably for others too:
- a quick summary that this happens on upstream too and is not
restricted to the tree which is in the report
- a TLDR summary of the reproducer operations so it can be seen quickly
which subsystems might be involved without decoding the reproducer
file manually.
Also for these kind of issues the robot might grow some rules how to
provide better debug information. Let's look at this particular report:
__run_hrtimer kernel/time/hrtimer.c:2028 [inline]
__hrtimer_run_queues+0x22c/0xbe0 kernel/time/hrtimer.c:2096
hrtimer_run_softirq+0x15c/0x21c kernel/time/hrtimer.c:2113
handle_softirqs+0x2ec/0xd98 kernel/softirq.c:622
__do_softirq+0x14/0x20 kernel/softirq.c:656
____do_softirq+0x14/0x20 arch/arm64/kernel/irq.c:78
call_on_irq_stack+0x30/0x48 arch/arm64/kernel/entry.S:885
do_softirq_own_stack+0x20/0x2c arch/arm64/kernel/irq.c:83
invoke_softirq kernel/softirq.c:503 [inline]
So it deduces that the lockup is in __hrtimer_run_queues(). So far so
good.
So if I'd had have the time to download and run the reproducer I would
have enabled the hrtimer trace points with a relatively small trace
buffer, added 'ftrace_dump_on_oops' to the command line and let the
kernel dump it when it crashes. In case of a self rearming timer which
keeps it in that loop, that surely would dump a series of
start/expire/start/ events with the same timer and the expire_entry
tracepoint would have the offending function in it.
Just a thought, but maybe there is something which can be done.
Let me stare at __hrtimer_run_queues() whether we can add some
lightweight mechanism to prevent such issues.
Thanks,
tglx
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-09-04 22:32 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-08 20:09 [syzbot] [kernel?] INFO: rcu detected stall in __hrtimer_run_queues (3) syzbot
2026-08-31 15:55 ` syzbot
2026-09-04 5:00 ` Thomas Gleixner
2026-09-04 13:51 ` Aleksandr Nogikh
2026-09-04 22:32 ` Thomas Gleixner
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox