* [syzbot] [io-uring?] [ext4?] INFO: task hung in io_write
@ 2026-09-08 22:08 syzbot
2026-09-09 1:10 ` Jens Axboe
0 siblings, 1 reply; 9+ messages in thread
From: syzbot @ 2026-09-08 22:08 UTC (permalink / raw)
To: axboe, io-uring, linux-ext4, linux-kernel, syzkaller-bugs
Hello,
syzbot found the following issue on:
HEAD commit: 28924df2a08f Merge tag 'perf-tools-fixes-for-v7.3-2026-09-..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=13842af9580000
kernel config: https://syzkaller.appspot.com/x/.config?x=e909ffe6b35dddb7
dashboard link: https://syzkaller.appspot.com/bug?extid=2eb3d983669d3e49d4fa
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=160d1749580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=13993af9580000
Downloadable assets:
disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/d900f083ada3/non_bootable_disk-28924df2.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/309bf243aefc/vmlinux-28924df2.xz
kernel image: https://storage.googleapis.com/syzbot-assets/5baa1c49144e/bzImage-28924df2.xz
mounted in repro: https://storage.googleapis.com/syzbot-assets/7dba324ffac0/mount_1.gz
fsck result: OK (log: https://syzkaller.appspot.com/x/fsck.log?x=15842af9580000)
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+2eb3d983669d3e49d4fa@syzkaller.appspotmail.com
INFO: task iou-wrk-5725:5730 blocked for more than 143 seconds.
Not tainted syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:iou-wrk-5725 state:D stack:22112 pid:5730 tgid:5724 ppid:5438 task_flags:0x404050 flags:0x00080002
Call Trace:
<TASK>
context_switch kernel/sched/core.c:5526 [inline]
__schedule+0x17db/0x58f0 kernel/sched/core.c:7276
__schedule_loop kernel/sched/core.c:7353 [inline]
schedule+0x164/0x2b0 kernel/sched/core.c:7368
percpu_rwsem_wait+0x326/0x490 kernel/locking/percpu-rwsem.c:164
__percpu_down_read+0xee/0x130 kernel/locking/percpu-rwsem.c:180
percpu_down_read_internal include/linux/percpu-rwsem.h:67 [inline]
percpu_down_read_freezable include/linux/percpu-rwsem.h:83 [inline]
__sb_start_write include/linux/fs/super.h:19 [inline]
sb_start_write include/linux/fs/super.h:125 [inline]
kiocb_start_write include/linux/fs.h:2787 [inline]
io_kiocb_start_write io_uring/rw.c:1109 [inline]
io_write+0x120c/0x1680 io_uring/rw.c:1163
__io_issue_sqe+0x188/0x4d0 io_uring/io_uring.c:1386
io_issue_sqe+0x16d/0x1020 io_uring/io_uring.c:1409
io_wq_submit_work+0x7ab/0xc90 io_uring/io_uring.c:1525
io_worker_handle_work+0x7a1/0x1140 io_uring/io-wq.c:659
io_wq_worker+0x452/0xf10 io_uring/io-wq.c:714
ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
Showing all locks held in the system:
locks held by kworker/u4:1/13: 2, last CPU#0:
#0: ffff88801b094140 ((wq_completion)events_unbound){+.+.}-{0:0}, at: rcu_lock_acquire include/linux/rcupdate.h:309 [inline]
#0: ffff88801b094140 ((wq_completion)events_unbound){+.+.}-{0:0}, at: rcu_read_lock include/linux/rcupdate.h:849 [inline]
#0: ffff88801b094140 ((wq_completion)events_unbound){+.+.}-{0:0}, at: process_one_work kernel/workqueue.c:3361 [inline]
#0: ffff88801b094140 ((wq_completion)events_unbound){+.+.}-{0:0}, at: process_scheduled_works+0x97a/0x1630 kernel/workqueue.c:3479
#1: ffffc9000026fc40 ((work_completion)(&(&nsim_dev->trap_data->trap_report_dw)->work)){+.+.}-{0:0}, at: rcu_lock_acquire include/linux/rcupdate.h:309 [inline]
#1: ffffc9000026fc40 ((work_completion)(&(&nsim_dev->trap_data->trap_report_dw)->work)){+.+.}-{0:0}, at: rcu_read_lock include/linux/rcupdate.h:849 [inline]
#1: ffffc9000026fc40 ((work_completion)(&(&nsim_dev->trap_data->trap_report_dw)->work)){+.+.}-{0:0}, at: process_one_work kernel/workqueue.c:3361 [inline]
#1: ffffc9000026fc40 ((work_completion)(&(&nsim_dev->trap_data->trap_report_dw)->work)){+.+.}-{0:0}, at: process_scheduled_works+0x97a/0x1630 kernel/workqueue.c:3479
locks held by khungtaskd/26: 1, last CPU#0:
#0: ffffffff8ed5c760 (rcu_read_lock){....}-{1:3}, at: rcu_lock_acquire include/linux/rcupdate.h:309 [inline]
#0: ffffffff8ed5c760 (rcu_read_lock){....}-{1:3}, at: rcu_read_lock include/linux/rcupdate.h:849 [inline]
#0: ffffffff8ed5c760 (rcu_read_lock){....}-{1:3}, at: debug_show_all_locks+0x2e/0x180 kernel/locking/lockdep.c:6871
locks held by kworker/u4:2/37: 3, last CPU#0:
#0: ffff88801b094140 ((wq_completion)events_unbound){+.+.}-{0:0}, at: rcu_lock_acquire include/linux/rcupdate.h:309 [inline]
#0: ffff88801b094140 ((wq_completion)events_unbound){+.+.}-{0:0}, at: rcu_read_lock include/linux/rcupdate.h:849 [inline]
#0: ffff88801b094140 ((wq_completion)events_unbound){+.+.}-{0:0}, at: process_one_work kernel/workqueue.c:3361 [inline]
#0: ffff88801b094140 ((wq_completion)events_unbound){+.+.}-{0:0}, at: process_scheduled_works+0x97a/0x1630 kernel/workqueue.c:3479
#1: ffffc900003f7c40 ((work_completion)(&(&nsim_dev->trap_data->trap_report_dw)->work)){+.+.}-{0:0}, at: rcu_lock_acquire include/linux/rcupdate.h:309 [inline]
#1: ffffc900003f7c40 ((work_completion)(&(&nsim_dev->trap_data->trap_report_dw)->work)){+.+.}-{0:0}, at: rcu_read_lock include/linux/rcupdate.h:849 [inline]
#1: ffffc900003f7c40 ((work_completion)(&(&nsim_dev->trap_data->trap_report_dw)->work)){+.+.}-{0:0}, at: process_one_work kernel/workqueue.c:3361 [inline]
#1: ffffc900003f7c40 ((work_completion)(&(&nsim_dev->trap_data->trap_report_dw)->work)){+.+.}-{0:0}, at: process_scheduled_works+0x97a/0x1630 kernel/workqueue.c:3479
#2: ffff888051872258 (&devlink->lock_key#4){+.+.}-{4:4}, at: nsim_dev_trap_report_work+0x57/0xb40 drivers/net/netdevsim/dev.c:834
locks held by kworker/u4:3/43: 2, on CPU#0:
#0: ffff88801b094140 ((wq_completion)events_unbound){+.+.}-{0:0}, at: rcu_lock_acquire include/linux/rcupdate.h:309 [inline]
#0: ffff88801b094140 ((wq_completion)events_unbound){+.+.}-{0:0}, at: rcu_read_lock include/linux/rcupdate.h:849 [inline]
#0: ffff88801b094140 ((wq_completion)events_unbound){+.+.}-{0:0}, at: process_one_work kernel/workqueue.c:3361 [inline]
#0: ffff88801b094140 ((wq_completion)events_unbound){+.+.}-{0:0}, at: process_scheduled_works+0x97a/0x1630 kernel/workqueue.c:3479
#1: ffffc90000877c40 ((work_completion)(&(&kfence_timer)->work)){+.+.}-{0:0}, at: rcu_lock_acquire include/linux/rcupdate.h:309 [inline]
#1: ffffc90000877c40 ((work_completion)(&(&kfence_timer)->work)){+.+.}-{0:0}, at: rcu_read_lock include/linux/rcupdate.h:849 [inline]
#1: ffffc90000877c40 ((work_completion)(&(&kfence_timer)->work)){+.+.}-{0:0}, at: process_one_work kernel/workqueue.c:3361 [inline]
#1: ffffc90000877c40 ((work_completion)(&(&kfence_timer)->work)){+.+.}-{0:0}, at: process_scheduled_works+0x97a/0x1630 kernel/workqueue.c:3479
locks held by kworker/u4:7/187: 4, last CPU#0:
#0: ffff88803fa20140 ((wq_completion)bat_events){+.+.}-{0:0}, at: rcu_lock_acquire include/linux/rcupdate.h:309 [inline]
#0: ffff88803fa20140 ((wq_completion)bat_events){+.+.}-{0:0}, at: rcu_read_lock include/linux/rcupdate.h:849 [inline]
#0: ffff88803fa20140 ((wq_completion)bat_events){+.+.}-{0:0}, at: process_one_work kernel/workqueue.c:3361 [inline]
#0: ffff88803fa20140 ((wq_completion)bat_events){+.+.}-{0:0}, at: process_scheduled_works+0x97a/0x1630 kernel/workqueue.c:3479
#1: ffffc900019dfc40 ((work_completion)(&(&forw_packet_aggr->delayed_work)->work)){+.+.}-{0:0}, at: rcu_lock_acquire include/linux/rcupdate.h:309 [inline]
#1: ffffc900019dfc40 ((work_completion)(&(&forw_packet_aggr->delayed_work)->work)){+.+.}-{0:0}, at: rcu_read_lock include/linux/rcupdate.h:849 [inline]
#1: ffffc900019dfc40 ((work_completion)(&(&forw_packet_aggr->delayed_work)->work)){+.+.}-{0:0}, at: process_one_work kernel/workqueue.c:3361 [inline]
#1: ffffc900019dfc40 ((work_completion)(&(&forw_packet_aggr->delayed_work)->work)){+.+.}-{0:0}, at: process_scheduled_works+0x97a/0x1630 kernel/workqueue.c:3479
#2: ffff88801fc3bb20 (&rq->__lock){-.-.}-{2:2}, at: raw_spin_rq_lock_nested+0x2d/0x160 kernel/sched/core.c:677
#3: ffff88801fc24408 (psi_seq){-.-.}-{0:0}, at: psi_task_switch+0x57/0x7d0 kernel/sched/psi.c:933
locks held by getty/5086: 2, on CPU#0:
#0: ffff88803ee570a0 (&tty->ldisc_sem){++++}-{0:0}, at: tty_ldisc_ref_wait+0x25/0x70 drivers/tty/tty_ldisc.c:243
#1: ffffc90000d202e8 (&ldata->atomic_read_lock){+.+.}-{4:4}, at: n_tty_read+0x45a/0x1360 drivers/tty/n_tty.c:2211
locks held by kworker/0:10/5721: 3, last CPU#0:
#0: ffff88801b0a8940 ((wq_completion)events){+.+.}-{0:0}, at: rcu_lock_acquire include/linux/rcupdate.h:309 [inline]
#0: ffff88801b0a8940 ((wq_completion)events){+.+.}-{0:0}, at: rcu_read_lock include/linux/rcupdate.h:849 [inline]
#0: ffff88801b0a8940 ((wq_completion)events){+.+.}-{0:0}, at: process_one_work kernel/workqueue.c:3361 [inline]
#0: ffff88801b0a8940 ((wq_completion)events){+.+.}-{0:0}, at: process_scheduled_works+0x97a/0x1630 kernel/workqueue.c:3479
#1: ffffc900052f7c40 ((work_completion)(&adapter->watchdog_task)){+.+.}-{0:0}, at: rcu_lock_acquire include/linux/rcupdate.h:309 [inline]
#1: ffffc900052f7c40 ((work_completion)(&adapter->watchdog_task)){+.+.}-{0:0}, at: rcu_read_lock include/linux/rcupdate.h:849 [inline]
#1: ffffc900052f7c40 ((work_completion)(&adapter->watchdog_task)){+.+.}-{0:0}, at: process_one_work kernel/workqueue.c:3361 [inline]
#1: ffffc900052f7c40 ((work_completion)(&adapter->watchdog_task)){+.+.}-{0:0}, at: process_scheduled_works+0x97a/0x1630 kernel/workqueue.c:3479
#2: ffff88801fc26118 (&base->lock){-.-.}-{2:2}, at: lock_timer_base kernel/time/timer.c:1004 [inline]
#2: ffff88801fc26118 (&base->lock){-.-.}-{2:2}, at: __mod_timer+0x1a9/0xed0 kernel/time/timer.c:1085
locks held by syz.0.23/5725: 2, on CPU#0:
#0: ffff88801d025220 (&bdev->bd_fsfreeze_mutex){+.+.}-{4:4}, at: bdev_freeze+0x33/0x2f0 block/bdev.c:304
#1: ffff888048fa4460 (sb_writers#4){++++}-{0:0}, at: sb_wait_write fs/super.c:2043 [inline]
#1: ffff888048fa4460 (sb_writers#4){++++}-{0:0}, at: freeze_super+0x4f4/0x11c0 fs/super.c:2307
locks held by iou-wrk-5725/5730: 1, on CPU#0:
#0: ffff888048fa4460 (sb_writers#4){++++}-{0:0}, at: __io_issue_sqe+0x188/0x4d0 io_uring/io_uring.c:1386
=============================================
NMI backtrace for cpu 0
CPU: 0 UID: 0 PID: 26 Comm: khungtaskd Not tainted syzkaller #0 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Call Trace:
<TASK>
dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120
nmi_cpu_backtrace+0x274/0x2d0 lib/nmi_backtrace.c:123
nmi_trigger_cpumask_backtrace+0x17d/0x390 lib/nmi_backtrace.c:66
trigger_all_cpu_backtrace include/linux/nmi.h:164 [inline]
__sys_info lib/sys_info.c:157 [inline]
sys_info+0x135/0x170 lib/sys_info.c:165
check_hung_uninterruptible_tasks kernel/hung_task.c:353 [inline]
watchdog+0xfd7/0x1030 kernel/hung_task.c:561
kthread+0x38b/0x480 kernel/kthread.c:436
ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [syzbot] [io-uring?] [ext4?] INFO: task hung in io_write
2026-09-08 22:08 [syzbot] [io-uring?] [ext4?] INFO: task hung in io_write syzbot
@ 2026-09-09 1:10 ` Jens Axboe
2026-09-09 1:15 ` Jens Axboe
` (3 more replies)
0 siblings, 4 replies; 9+ messages in thread
From: Jens Axboe @ 2026-09-09 1:10 UTC (permalink / raw)
To: syzbot, io-uring, linux-ext4, linux-kernel, syzkaller-bugs
#syz test: git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux.git io_uring-7.3
--
Jens Axboe
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [syzbot] [io-uring?] [ext4?] INFO: task hung in io_write
2026-09-09 1:10 ` Jens Axboe
@ 2026-09-09 1:15 ` Jens Axboe
2026-09-09 1:58 ` syzbot
2026-09-09 1:35 ` syzbot
` (2 subsequent siblings)
3 siblings, 1 reply; 9+ messages in thread
From: Jens Axboe @ 2026-09-09 1:15 UTC (permalink / raw)
To: syzbot, io-uring, linux-ext4, linux-kernel, syzkaller-bugs
#syz test: git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux.git io_uring-7.3
Forgot to push it out... Let's kick it again.
--
Jens Axboe
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [syzbot] [io-uring?] [ext4?] INFO: task hung in io_write
2026-09-09 1:10 ` Jens Axboe
2026-09-09 1:15 ` Jens Axboe
@ 2026-09-09 1:35 ` syzbot
2026-09-09 11:02 ` Jens Axboe
2026-09-09 11:46 ` Jens Axboe
3 siblings, 0 replies; 9+ messages in thread
From: syzbot @ 2026-09-09 1:35 UTC (permalink / raw)
To: axboe, io-uring, linux-ext4, linux-kernel, syzkaller-bugs
Hello,
syzbot tried to test the proposed patch but the build/boot failed:
t
[ 9.311884][ T1] ntfs3: Read-only LZX/Xpress compression included
[ 9.324965][ T1] jffs2: version 2.2. (NAND) (SUMMARY) © 2001-2006 Red Hat, Inc.
[ 9.339487][ T1] romfs: ROMFS MTD (C) 2007 Red Hat, Inc.
[ 9.354547][ T1] QNX4 filesystem 0.2.3 registered.
[ 9.358628][ T1] qnx6: QNX6 filesystem 1.0.0 registered.
[ 9.374595][ T1] fuse: init (API version 7.45)
[ 9.386259][ T1] orangefs_debugfs_init: called with debug mask: :none: :0:
[ 9.405773][ T1] orangefs_init: module version upstream loaded
[ 9.411433][ T1] JFS: nTxBlock = 6145, nTxLock = 49167
[ 9.432378][ T1] SGI XFS with ACLs, security attributes, realtime, scrub, repair, quota, no debug enabled
[ 9.460589][ T1] 9p: Installing v9fs 9p2000 file system support
[ 9.474863][ T1] NILFS version 2 loaded
[ 9.478065][ T1] befs: version: 0.9.3
[ 9.481916][ T1] ocfs2: Registered cluster interface o2cb
[ 9.505141][ T1] ocfs2: Registered cluster interface user
[ 9.511060][ T1] OCFS2 User DLM kernel interface loaded
[ 9.555232][ T1] gfs2: GFS2 installed
[ 9.587926][ T1] ceph: loaded (mds proto 32)
[ 9.609192][ T1] NET: Registered PF_ALG protocol family
[ 9.613568][ T1] async_tx: api initialized (async)
[ 9.634473][ T1] Key type asymmetric registered
[ 9.638422][ T1] Asymmetric key parser 'x509' registered
[ 9.643521][ T1] Asymmetric key parser 'pkcs8' registered
[ 9.654318][ T1] Key type pkcs7_test registered
[ 9.665499][ T1] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 239)
[ 9.676502][ T1] io scheduler mq-deadline registered
[ 9.694302][ T1] io scheduler kyber registered
[ 9.698347][ T1] io scheduler bfq registered
[ 9.703715][ T1] raid6: skipped pq benchmark and selected avx512x4
[ 9.803123][ T1] ACPI: \_SB_.GSIE: Enabled at IRQ 20
[ 9.844760][ T1] pcieport 0000:00:04.0: PME: Signaling with IRQ 25
[ 9.855822][ T1] pcieport 0000:00:04.0: AER: enabled with IRQ 26
[ 9.888231][ T1] input: Power Button as /devices/platform/LNXPWRBN:00/input/input0
[ 9.907560][ T1] ACPI: button: Power Button [PWRF]
[ 10.781900][ T1] ioatdma: Intel(R) QuickData Technology Driver 5.00
[ 10.871170][ T1] ACPI: \_SB_.GSIF: Enabled at IRQ 21
[ 10.969004][ T1] ACPI: \_SB_.GSIH: Enabled at IRQ 23
[ 12.148632][ T1] N_HDLC line discipline registered with maxframe=4096
[ 12.165434][ T1] Serial: 8250/16550 driver, 4 ports, IRQ sharing enabled
[ 12.190821][ T1] 00:03: ttyS0 at I/O 0x3f8 (irq = 4, base_baud = 115200) is a 16550A
[ 12.338747][ T1] Non-volatile memory driver v1.3
[ 12.377313][ T1] usbcore: registered new interface driver xillyusb
[ 12.393087][ T1] ACPI: bus type drm_connector registered
[ 12.432983][ T1] [drm] Initialized vgem 1.0.0 for vgem on minor 0
[ 12.445520][ T1] usbcore: registered new interface driver udl
[ 12.455961][ T1] [drm] pci: virtio-vga detected at 0000:00:01.0
[ 12.460653][ T1] virtio-pci 0000:00:01.0: vgaarb: deactivate vga console
[ 12.515474][ T1] Console: switching to colour dummy device 80x25
[ 12.523215][ T1] [drm] features: -virgl +edid -resource_blob -host_visible
[ 12.523225][ T1] [drm] features: -context_init -blob_alignment
[ 12.542435][ T1] [drm] number of scanouts: 1
[ 12.545813][ T1] [drm] number of cap sets: 0
[ 12.554747][ T1] ------------[ cut here ]------------
[ 12.558333][ T1] [PLANE:36:plane-1] pixel format with alpha exposed but blend mode not setup
[ 12.558342][ T1] WARNING: drivers/gpu/drm/drm_mode_config.c:873 at drm_mode_config_validate+0x1c6a/0x1e60, CPU#0: swapper/0/1
[ 12.573118][ T1] Modules linked in:
[ 12.576385][ T1] CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT(full)
[ 12.582807][ T1] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[ 12.590090][ T1] RIP: 0010:drm_mode_config_validate+0x1cab/0x1e60
[ 12.594850][ T1] Code: 0f 85 ae 00 00 00 4d 8d 77 10 8b 6d 00 4c 89 f0 48 c1 e8 03 80 3c 18 00 74 08 4c 89 f7 e8 bd a5 a3 fc 49 8b 16 4c 89 ef 89 ee <67> 48 0f b9 3a eb 05 e8 c9 54 32 fc 49 bd 00 00 00 00 00 fc ff df
[ 12.608988][ T1] RSP: 0000:ffffc900001af450 EFLAGS: 00010246
[ 12.613447][ T1] RAX: 1ffff11000029408 RBX: dffffc0000000000 RCX: ffff88801ceb0000
[ 12.619368][ T1] RDX: ffff88801f5db780 RSI: 0000000000000024 RDI: ffffffff9085b000
[ 12.625154][ T1] RBP: 0000000000000024 R08: ffffffff8ec2b347 R09: 1ffffffff1d85668
[ 12.631012][ T1] R10: dffffc0000000000 R11: fffffbfff1d85669 R12: dffffc0000000000
[ 12.636862][ T1] R13: ffffffff9085b000 R14: ffff88800014a040 R15: ffff88800014a030
[ 12.642683][ T1] FS: 0000000000000000(0000) GS:ffff88808c2e6000(0000) knlGS:0000000000000000
[ 12.649778][ T1] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 12.654807][ T1] CR2: ffff88801af19000 CR3: 000000000eb46000 CR4: 0000000000352ef0
[ 12.660778][ T1] Call Trace:
[ 12.663243][ T1] <TASK>
[ 12.665510][ T1] ? __pfx_autoremove_wake_function+0x10/0x10
[ 12.669917][ T1] drm_dev_register+0x7c/0xd80
[ 12.673383][ T1] virtio_gpu_probe+0x1cb/0x290
[ 12.677087][ T1] virtio_dev_probe+0xdf6/0x10c0
[ 12.680755][ T1] ? up_write+0x19d/0x4a0
[ 12.684009][ T1] ? __pfx_virtio_dev_probe+0x10/0x10
[ 12.687928][ T1] ? driver_sysfs_add+0x1fe/0x210
[ 12.691505][ T1] ? __pfx_virtio_dev_probe+0x10/0x10
[ 12.695595][ T1] really_probe+0x254/0xae0
[ 12.698866][ T1] __driver_probe_device+0x1e8/0x360
[ 12.702663][ T1] driver_probe_device+0x4f/0x240
[ 12.706350][ T1] __driver_attach+0x339/0x600
[ 12.709736][ T1] bus_for_each_dev+0x23b/0x2c0
[ 12.713247][ T1] ? __pfx___driver_attach+0x10/0x10
[ 12.717330][ T1] ? __pfx_bus_for_each_dev+0x10/0x10
[ 12.721241][ T1] ? do_raw_spin_unlock+0x4d/0x200
[ 12.724984][ T1] bus_add_driver+0x345/0x670
[ 12.728449][ T1] driver_register+0x23a/0x320
[ 12.732054][ T1] ? __pfx_virtio_gpu_driver_init+0x10/0x10
[ 12.736511][ T1] virtio_gpu_driver_init+0x96/0x110
[ 12.740363][ T1] do_one_initcall+0x250/0x870
[ 12.743753][ T1] ? __pfx_virtio_gpu_driver_init+0x10/0x10
[ 12.747725][ T1] ? __pfx_do_one_initcall+0x10/0x10
[ 12.750854][ T1] ? __pfx___schedule+0x10/0x10
[ 12.754246][ T1] ? irqentry_exit+0x218/0x910
[ 12.757543][ T1] ? lockdep_hardirqs_on+0x7b/0x110
[ 12.760932][ T1] ? irqentry_exit+0x218/0x910
[ 12.764435][ T1] ? trace_irq_disable+0x3b/0x140
[ 12.767922][ T1] ? parameq+0x37/0x170
[ 12.770899][ T1] ? next_arg+0x4a0/0x5e0
[ 12.773885][ T1] ? parameq+0x14d/0x170
[ 12.776877][ T1] ? parse_args+0x9c3/0xad0
[ 12.779988][ T1] ? rcu_is_watching+0x16/0xb0
[ 12.783393][ T1] do_initcall_level+0x10a/0x1a0
[ 12.787027][ T1] ? kernel_init+0x22/0x1d0
[ 12.790245][ T1] do_initcalls+0x59/0xa0
[ 12.793486][ T1] kernel_init_freeable+0x29d/0x3e0
[ 12.796995][ T1] ? __pfx_kernel_init+0x10/0x10
[ 12.800223][ T1] kernel_init+0x22/0x1d0
[ 12.803175][ T1] ? __pfx_kernel_init+0x10/0x10
[ 12.806784][ T1] ret_from_fork+0x514/0xb70
[ 12.809992][ T1] ? __pfx_ret_from_fork+0x10/0x10
[ 12.813663][ T1] ? __switch_to+0xc89/0x1420
[ 12.817141][ T1] ? __pfx_kernel_init+0x10/0x10
[ 12.820600][ T1] ret_from_fork_asm+0x1a/0x30
[ 12.824086][ T1] </TASK>
[ 12.826409][ T1] Kernel panic - not syncing: kernel: panic_on_warn set ...
[ 12.831660][ T1] CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT(full)
[ 12.836273][ T1] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[ 12.836273][ T1] Call Trace:
[ 12.836273][ T1] <TASK>
[ 12.836273][ T1] vpanic+0x56d/0xa60
[ 12.836273][ T1] ? __pfx__printk+0x10/0x10
[ 12.836273][ T1] ? __pfx_vpanic+0x10/0x10
[ 12.836273][ T1] ? is_bpf_text_address+0x292/0x2b0
[ 12.836273][ T1] ? is_bpf_text_address+0x26/0x2b0
[ 12.836273][ T1] panic+0xc5/0xd0
[ 12.836273][ T1] ? __pfx_panic+0x10/0x10
[ 12.836273][ T1] ? ret_from_fork_asm+0x1a/0x30
[ 12.836273][ T1] __warn+0x315/0x4c0
[ 12.836273][ T1] ? drm_mode_config_validate+0x1c6a/0x1e60
[ 12.836273][ T1] ? drm_mode_config_validate+0x1c6a/0x1e60
[ 12.836273][ T1] __report_bug+0x276/0x570
[ 12.836273][ T1] ? blocking_notifier_chain_register+0x50/0xc0
[ 12.836273][ T1] ? drm_mode_config_validate+0x1c6a/0x1e60
[ 12.836273][ T1] ? __pfx___report_bug+0x10/0x10
[ 12.836273][ T1] ? blocking_notifier_chain_register+0x6b/0xc0
[ 12.836273][ T1] report_bug_entry+0x19b/0x290
[ 12.836273][ T1] ? drm_mode_config_validate+0x1cab/0x1e60
[ 12.836273][ T1] ? drm_mode_config_validate+0x1cb0/0x1e60
[ 12.836273][ T1] handle_bug+0xce/0x200
[ 12.836273][ T1] exc_invalid_op+0x1a/0x50
[ 12.836273][ T1] asm_exc_invalid_op+0x1a/0x20
[ 12.836273][ T1] RIP: 0010:drm_mode_config_validate+0x1cab/0x1e60
[ 12.836273][ T1] Code: 0f 85 ae 00 00 00 4d 8d 77 10 8b 6d 00 4c 89 f0 48 c1 e8 03 80 3c 18 00 74 08 4c 89 f7 e8 bd a5 a3 fc 49 8b 16 4c 89 ef 89 ee <67> 48 0f b9 3a eb 05 e8 c9 54 32 fc 49 bd 00 00 00 00 00 fc ff df
[ 12.836273][ T1] RSP: 0000:ffffc900001af450 EFLAGS: 00010246
[ 12.836273][ T1] RAX: 1ffff11000029408 RBX: dffffc0000000000 RCX: ffff88801ceb0000
[ 12.836273][ T1] RDX: ffff88801f5db780 RSI: 0000000000000024 RDI: ffffffff9085b000
[ 12.836273][ T1] RBP: 0000000000000024 R08: ffffffff8ec2b347 R09: 1ffffffff1d85668
[ 12.836273][ T1] R10: dffffc0000000000 R11: fffffbfff1d85669 R12: dffffc0000000000
[ 12.836273][ T1] R13: ffffffff9085b000 R14: ffff88800014a040 R15: ffff88800014a030
[ 12.836273][ T1] ? __pfx_autoremove_wake_function+0x10/0x10
[ 12.836273][ T1] drm_dev_register+0x7c/0xd80
[ 12.836273][ T1] virtio_gpu_probe+0x1cb/0x290
[ 12.836273][ T1] virtio_dev_probe+0xdf6/0x10c0
[ 12.836273][ T1] ? up_write+0x19d/0x4a0
[ 12.836273][ T1] ? __pfx_virtio_dev_probe+0x10/0x10
[ 12.836273][ T1] ? driver_sysfs_add+0x1fe/0x210
[ 12.836273][ T1] ? __pfx_virtio_dev_probe+0x10/0x10
[ 12.836273][ T1] really_probe+0x254/0xae0
[ 12.836273][ T1] __driver_probe_device+0x1e8/0x360
[ 12.836273][ T1] driver_probe_device+0x4f/0x240
[ 12.836273][ T1] __driver_attach+0x339/0x600
[ 12.836273][ T1] bus_for_each_dev+0x23b/0x2c0
[ 12.836273][ T1] ? __pfx___driver_attach+0x10/0x10
[ 12.836273][ T1] ? __pfx_bus_for_each_dev+0x10/0x10
[ 12.836273][ T1] ? do_raw_spin_unlock+0x4d/0x200
[ 12.836273][ T1] bus_add_driver+0x345/0x670
[ 12.836273][ T1] driver_register+0x23a/0x320
[ 12.836273][ T1] ? __pfx_virtio_gpu_driver_init+0x10/0x10
[ 12.836273][ T1] virtio_gpu_driver_init+0x96/0x110
[ 12.836273][ T1] do_one_initcall+0x250/0x870
[ 12.836273][ T1] ? __pfx_virtio_gpu_driver_init+0x10/0x10
[ 12.836273][ T1] ? __pfx_do_one_initcall+0x10/0x10
[ 12.836273][ T1] ? __pfx___schedule+0x10/0x10
[ 12.836273][ T1] ? irqentry_exit+0x218/0x910
[ 12.836273][ T1] ? lockdep_hardirqs_on+0x7b/0x110
[ 12.836273][ T1] ? irqentry_exit+0x218/0x910
[ 12.836273][ T1] ? trace_irq_disable+0x3b/0x140
[ 12.836273][ T1] ? parameq+0x37/0x170
[ 12.836273][ T1] ? next_arg+0x4a0/0x5e0
[ 12.836273][ T1] ? parameq+0x14d/0x170
[ 12.836273][ T1] ? parse_args+0x9c3/0xad0
[ 12.836273][ T1] ? rcu_is_watching+0x16/0xb0
[ 12.836273][ T1] do_initcall_level+0x10a/0x1a0
[ 12.836273][ T1] ? kernel_init+0x22/0x1d0
[ 12.836273][ T1] do_initcalls+0x59/0xa0
[ 12.836273][ T1] kernel_init_freeable+0x29d/0x3e0
[ 12.836273][ T1] ? __pfx_kernel_init+0x10/0x10
[ 12.836273][ T1] kernel_init+0x22/0x1d0
[ 12.836273][ T1] ? __pfx_kernel_init+0x10/0x10
[ 12.836273][ T1] ret_from_fork+0x514/0xb70
[ 12.836273][ T1] ? __pfx_ret_from_fork+0x10/0x10
[ 12.836273][ T1] ? __switch_to+0xc89/0x1420
[ 12.836273][ T1] ? __pfx_kernel_init+0x10/0x10
[ 12.836273][ T1] ret_from_fork_asm+0x1a/0x30
[ 12.836273][ T1] </TASK>
[ 12.836273][ T1] Kernel Offset: disabled
[ 12.836273][ T1] Rebooting in 86400 seconds..
syzkaller build log:
go env (err=<nil>)
AR='ar'
CC='gcc'
CGO_CFLAGS='-O2 -g'
CGO_CPPFLAGS=''
CGO_CXXFLAGS='-O2 -g'
CGO_ENABLED='1'
CGO_FFLAGS='-O2 -g'
CGO_LDFLAGS='-O2 -g'
CXX='g++'
GCCGO='gccgo'
GO111MODULE='auto'
GOAMD64='v1'
GOARCH='amd64'
GOAUTH='netrc'
GOBIN=''
GOCACHE='/syzkaller/.cache/go-build'
GOCACHEPROG=''
GODEBUG=''
GOENV='/syzkaller/.config/go/env'
GOEXE=''
GOEXPERIMENT=''
GOFIPS140='off'
GOFLAGS=''
GOGCCFLAGS='-fPIC -m64 -pthread -Wl,--no-gc-sections -fmessage-length=0 -ffile-prefix-map=/tmp/go-build2134465290=/tmp/go-build -gno-record-gcc-switches'
GOHOSTARCH='amd64'
GOHOSTOS='linux'
GOINSECURE=''
GOMOD='/syzkaller/jobs/linux/gopath/src/github.com/google/syzkaller/go.mod'
GOMODCACHE='/syzkaller/jobs/linux/gopath/pkg/mod'
GONOPROXY=''
GONOSUMDB=''
GOOS='linux'
GOPATH='/syzkaller/jobs/linux/gopath'
GOPRIVATE=''
GOPROXY='https://proxy.golang.org,direct'
GOROOT='/usr/local/go'
GOSUMDB='sum.golang.org'
GOTELEMETRY='local'
GOTELEMETRYDIR='/syzkaller/.config/go/telemetry'
GOTMPDIR=''
GOTOOLCHAIN='auto'
GOTOOLDIR='/usr/local/go/pkg/tool/linux_amd64'
GOVCS=''
GOVERSION='go1.26.0'
GOWORK=''
PKG_CONFIG='pkg-config'
git status (err=<nil>)
HEAD detached at 680aa3e19b5
nothing to commit, working tree clean
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
go list -f '{{.Stale}}' -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=680aa3e19b52574eca8bcba3c41aa18235367abe -X github.com/google/syzkaller/prog.gitRevisionDate=20260907-094615" ./sys/syz-sysgen | grep -q false || go install -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=680aa3e19b52574eca8bcba3c41aa18235367abe -X github.com/google/syzkaller/prog.gitRevisionDate=20260907-094615" ./sys/syz-sysgen
make .descriptions
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
bin/syz-sysgen
touch .descriptions
GOOS=linux GOARCH=amd64 go build -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=680aa3e19b52574eca8bcba3c41aa18235367abe -X github.com/google/syzkaller/prog.gitRevisionDate=20260907-094615" -o ./bin/linux_amd64/syz-execprog github.com/google/syzkaller/tools/syz-execprog
mkdir -p ./bin/linux_amd64
g++ -o ./bin/linux_amd64/syz-executor executor/executor.cc \
-m64 -O2 -pthread -Wall -Werror -Wparentheses -Wunused-const-variable -Wframe-larger-than=16384 -Wno-stringop-overflow -Wno-array-bounds -Wno-format-overflow -Wno-unused-but-set-variable -Wno-unused-command-line-argument -static-pie -std=c++17 -I. -Iexecutor/_include -DGOOS_linux=1 -DGOARCH_amd64=1 \
-DHOSTGOOS_linux=1 -DGIT_REVISION=\"680aa3e19b52574eca8bcba3c41aa18235367abe\"
go: downloading google.golang.org/grpc v1.83.1
go: downloading go.opentelemetry.io/contrib/detectors/gcp v1.44.0
go: downloading github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.33.0
go: downloading github.com/klauspost/compress v1.18.7
go: downloading github.com/spiffe/go-spiffe/v2 v2.7.0
/usr/bin/ld: /tmp/ccpIPst8.o: in function `Connection::Connect(char const*, char const*)':
executor.cc:(.text._ZN10Connection7ConnectEPKcS1_[_ZN10Connection7ConnectEPKcS1_]+0x386): warning: Using 'gethostbyname' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking
./tools/check-syzos.sh 2>/dev/null
Error text is too large and was truncated, full error text is at:
https://syzkaller.appspot.com/x/error.txt?x=161cf125580000
Tested on:
commit: 2cf20c4e io_uring/waitid: avoid siginfo copy during ri..
git tree: git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux.git io_uring-7.3
kernel config: https://syzkaller.appspot.com/x/.config?x=780bb9a5c10069a1
dashboard link: https://syzkaller.appspot.com/bug?extid=2eb3d983669d3e49d4fa
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
Note: no patches were applied.
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [syzbot] [io-uring?] [ext4?] INFO: task hung in io_write
2026-09-09 1:15 ` Jens Axboe
@ 2026-09-09 1:58 ` syzbot
0 siblings, 0 replies; 9+ messages in thread
From: syzbot @ 2026-09-09 1:58 UTC (permalink / raw)
To: axboe, io-uring, linux-ext4, linux-kernel, syzkaller-bugs
Hello,
syzbot tried to test the proposed patch but the build/boot failed:
TD (C) 2007 Red Hat, Inc.
[ 9.051564][ T1] QNX4 filesystem 0.2.3 registered.
[ 9.065214][ T1] qnx6: QNX6 filesystem 1.0.0 registered.
[ 9.075912][ T1] fuse: init (API version 7.45)
[ 9.091183][ T1] orangefs_debugfs_init: called with debug mask: :none: :0:
[ 9.106914][ T1] orangefs_init: module version upstream loaded
[ 9.113002][ T1] JFS: nTxBlock = 6145, nTxLock = 49167
[ 9.142915][ T1] SGI XFS with ACLs, security attributes, realtime, scrub, repair, quota, no debug enabled
[ 9.170468][ T1] 9p: Installing v9fs 9p2000 file system support
[ 9.185644][ T1] NILFS version 2 loaded
[ 9.188849][ T1] befs: version: 0.9.3
[ 9.193115][ T1] ocfs2: Registered cluster interface o2cb
[ 9.206206][ T1] ocfs2: Registered cluster interface user
[ 9.216419][ T1] OCFS2 User DLM kernel interface loaded
[ 9.265973][ T1] gfs2: GFS2 installed
[ 9.298657][ T1] ceph: loaded (mds proto 32)
[ 9.320185][ T1] NET: Registered PF_ALG protocol family
[ 9.324663][ T1] async_tx: api initialized (async)
[ 9.345185][ T1] Key type asymmetric registered
[ 9.349130][ T1] Asymmetric key parser 'x509' registered
[ 9.353465][ T1] Asymmetric key parser 'pkcs8' registered
[ 9.365187][ T1] Key type pkcs7_test registered
[ 9.376596][ T1] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 239)
[ 9.396528][ T1] io scheduler mq-deadline registered
[ 9.400698][ T1] io scheduler kyber registered
[ 9.415450][ T1] io scheduler bfq registered
[ 9.420059][ T1] raid6: skipped pq benchmark and selected avx512x4
[ 9.442033][ T127] kworker/u4:1 (127) used greatest stack depth: 26984 bytes left
[ 9.524259][ T1] ACPI: \_SB_.GSIE: Enabled at IRQ 20
[ 9.565511][ T1] pcieport 0000:00:04.0: PME: Signaling with IRQ 25
[ 9.578930][ T1] pcieport 0000:00:04.0: AER: enabled with IRQ 26
[ 9.601450][ T1] input: Power Button as /devices/platform/LNXPWRBN:00/input/input0
[ 9.629341][ T1] ACPI: button: Power Button [PWRF]
[ 10.450014][ T1] ioatdma: Intel(R) QuickData Technology Driver 5.00
[ 10.532357][ T1] ACPI: \_SB_.GSIF: Enabled at IRQ 21
[ 10.629521][ T1] ACPI: \_SB_.GSIH: Enabled at IRQ 23
[ 10.892841][ T270] kworker/u4:1 (270) used greatest stack depth: 26960 bytes left
[ 11.809081][ T1] N_HDLC line discipline registered with maxframe=4096
[ 11.830246][ T1] Serial: 8250/16550 driver, 4 ports, IRQ sharing enabled
[ 11.849727][ T1] 00:03: ttyS0 at I/O 0x3f8 (irq = 4, base_baud = 115200) is a 16550A
[ 11.999300][ T1] Non-volatile memory driver v1.3
[ 12.037071][ T1] usbcore: registered new interface driver xillyusb
[ 12.058150][ T1] ACPI: bus type drm_connector registered
[ 12.091068][ T1] [drm] Initialized vgem 1.0.0 for vgem on minor 0
[ 12.105742][ T1] usbcore: registered new interface driver udl
[ 12.112516][ T1] [drm] pci: virtio-vga detected at 0000:00:01.0
[ 12.125337][ T1] virtio-pci 0000:00:01.0: vgaarb: deactivate vga console
[ 12.186303][ T1] Console: switching to colour dummy device 80x25
[ 12.194466][ T1] [drm] features: -virgl +edid -resource_blob -host_visible
[ 12.194482][ T1] [drm] features: -context_init -blob_alignment
[ 12.230560][ T1] [drm] number of scanouts: 1
[ 12.233893][ T1] [drm] number of cap sets: 0
[ 12.255974][ T1] ------------[ cut here ]------------
[ 12.260092][ T1] [PLANE:36:plane-1] pixel format with alpha exposed but blend mode not setup
[ 12.260107][ T1] WARNING: drivers/gpu/drm/drm_mode_config.c:873 at drm_mode_config_validate+0x1c6a/0x1e60, CPU#0: swapper/0/1
[ 12.275683][ T1] Modules linked in:
[ 12.279250][ T1] CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT(full)
[ 12.285867][ T1] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[ 12.293265][ T1] RIP: 0010:drm_mode_config_validate+0x1cab/0x1e60
[ 12.298167][ T1] Code: 0f 85 ae 00 00 00 4d 8d 77 10 8b 6d 00 4c 89 f0 48 c1 e8 03 80 3c 18 00 74 08 4c 89 f7 e8 7d a5 a3 fc 49 8b 16 4c 89 ef 89 ee <67> 48 0f b9 3a eb 05 e8 89 54 32 fc 49 bd 00 00 00 00 00 fc ff df
[ 12.312441][ T1] RSP: 0000:ffffc900001af450 EFLAGS: 00010246
[ 12.316951][ T1] RAX: 1ffff11000030e08 RBX: dffffc0000000000 RCX: ffff88801ceb0000
[ 12.322637][ T1] RDX: ffff88801f5b27a0 RSI: 0000000000000024 RDI: ffffffff9085b000
[ 12.328653][ T1] RBP: 0000000000000024 R08: ffffffff8ec2b347 R09: 1ffffffff1d85668
[ 12.334503][ T1] R10: dffffc0000000000 R11: fffffbfff1d85669 R12: dffffc0000000000
[ 12.340419][ T1] R13: ffffffff9085b000 R14: ffff888000187040 R15: ffff888000187030
[ 12.346250][ T1] FS: 0000000000000000(0000) GS:ffff88808c2e6000(0000) knlGS:0000000000000000
[ 12.352727][ T1] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 12.357998][ T1] CR2: ffff88801af19000 CR3: 000000000eb46000 CR4: 0000000000352ef0
[ 12.363905][ T1] Call Trace:
[ 12.366455][ T1] <TASK>
[ 12.368581][ T1] ? __pfx_autoremove_wake_function+0x10/0x10
[ 12.372972][ T1] drm_dev_register+0x7c/0xd80
[ 12.376503][ T1] virtio_gpu_probe+0x1cb/0x290
[ 12.380071][ T1] virtio_dev_probe+0xdf6/0x10c0
[ 12.383655][ T1] ? up_write+0x19d/0x4a0
[ 12.386865][ T1] ? __pfx_virtio_dev_probe+0x10/0x10
[ 12.390829][ T1] ? driver_sysfs_add+0x1fe/0x210
[ 12.394687][ T1] ? __pfx_virtio_dev_probe+0x10/0x10
[ 12.398721][ T1] really_probe+0x254/0xae0
[ 12.402015][ T1] __driver_probe_device+0x1e8/0x360
[ 12.406009][ T1] driver_probe_device+0x4f/0x240
[ 12.413118][ T1] __driver_attach+0x339/0x600
[ 12.416808][ T1] bus_for_each_dev+0x23b/0x2c0
[ 12.420389][ T1] ? __pfx___driver_attach+0x10/0x10
[ 12.424449][ T1] ? __pfx_bus_for_each_dev+0x10/0x10
[ 12.428383][ T1] ? do_raw_spin_unlock+0x4d/0x200
[ 12.431965][ T1] bus_add_driver+0x345/0x670
[ 12.435503][ T1] driver_register+0x23a/0x320
[ 12.438896][ T1] ? __pfx_virtio_gpu_driver_init+0x10/0x10
[ 12.443320][ T1] virtio_gpu_driver_init+0x96/0x110
[ 12.447202][ T1] do_one_initcall+0x250/0x870
[ 12.450824][ T1] ? __pfx_virtio_gpu_driver_init+0x10/0x10
[ 12.455195][ T1] ? __pfx_do_one_initcall+0x10/0x10
[ 12.459086][ T1] ? __pfx___schedule+0x10/0x10
[ 12.462702][ T1] ? __pfx___schedule+0x10/0x10
[ 12.466316][ T1] ? _raw_spin_unlock_irqrestore+0x30/0x80
[ 12.470553][ T1] ? __pfx___schedule+0x10/0x10
[ 12.474166][ T1] ? irqentry_exit+0x218/0x910
[ 12.477695][ T1] ? lockdep_hardirqs_on+0x7b/0x110
[ 12.481598][ T1] ? irqentry_exit+0x218/0x910
[ 12.485220][ T1] ? trace_irq_disable+0x3b/0x140
[ 12.488882][ T1] ? parameq+0xd6/0x170
[ 12.492000][ T1] ? next_arg+0x4a0/0x5e0
[ 12.495249][ T1] ? parameq+0x14d/0x170
[ 12.498246][ T1] ? parse_args+0x9c3/0xad0
[ 12.501454][ T1] ? rcu_is_watching+0x16/0xb0
[ 12.505007][ T1] do_initcall_level+0x10a/0x1a0
[ 12.508580][ T1] ? kernel_init+0x22/0x1d0
[ 12.511816][ T1] do_initcalls+0x59/0xa0
[ 12.515060][ T1] kernel_init_freeable+0x29d/0x3e0
[ 12.518828][ T1] ? __pfx_kernel_init+0x10/0x10
[ 12.522466][ T1] kernel_init+0x22/0x1d0
[ 12.525706][ T1] ? __pfx_kernel_init+0x10/0x10
[ 12.529224][ T1] ret_from_fork+0x514/0xb70
[ 12.532504][ T1] ? __pfx_ret_from_fork+0x10/0x10
[ 12.536233][ T1] ? __switch_to+0xc89/0x1420
[ 12.539759][ T1] ? __pfx_kernel_init+0x10/0x10
[ 12.543298][ T1] ret_from_fork_asm+0x1a/0x30
[ 12.546840][ T1] </TASK>
[ 12.549044][ T1] Kernel panic - not syncing: kernel: panic_on_warn set ...
[ 12.554149][ T1] CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT(full)
[ 12.556740][ T1] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[ 12.556740][ T1] Call Trace:
[ 12.556740][ T1] <TASK>
[ 12.556740][ T1] vpanic+0x56d/0xa60
[ 12.556740][ T1] ? __pfx__printk+0x10/0x10
[ 12.556740][ T1] ? __pfx_vpanic+0x10/0x10
[ 12.556740][ T1] ? is_bpf_text_address+0x292/0x2b0
[ 12.556740][ T1] ? is_bpf_text_address+0x26/0x2b0
[ 12.556740][ T1] panic+0xc5/0xd0
[ 12.556740][ T1] ? __pfx_panic+0x10/0x10
[ 12.556740][ T1] ? ret_from_fork_asm+0x1a/0x30
[ 12.556740][ T1] __warn+0x315/0x4c0
[ 12.556740][ T1] ? drm_mode_config_validate+0x1c6a/0x1e60
[ 12.556740][ T1] ? drm_mode_config_validate+0x1c6a/0x1e60
[ 12.556740][ T1] __report_bug+0x276/0x570
[ 12.556740][ T1] ? blocking_notifier_chain_register+0x50/0xc0
[ 12.556740][ T1] ? drm_mode_config_validate+0x1c6a/0x1e60
[ 12.556740][ T1] ? __pfx___report_bug+0x10/0x10
[ 12.556740][ T1] ? blocking_notifier_chain_register+0x6b/0xc0
[ 12.556740][ T1] report_bug_entry+0x19b/0x290
[ 12.556740][ T1] ? drm_mode_config_validate+0x1cab/0x1e60
[ 12.556740][ T1] ? drm_mode_config_validate+0x1cb0/0x1e60
[ 12.556740][ T1] handle_bug+0xce/0x200
[ 12.556740][ T1] exc_invalid_op+0x1a/0x50
[ 12.556740][ T1] asm_exc_invalid_op+0x1a/0x20
[ 12.556740][ T1] RIP: 0010:drm_mode_config_validate+0x1cab/0x1e60
[ 12.556740][ T1] Code: 0f 85 ae 00 00 00 4d 8d 77 10 8b 6d 00 4c 89 f0 48 c1 e8 03 80 3c 18 00 74 08 4c 89 f7 e8 7d a5 a3 fc 49 8b 16 4c 89 ef 89 ee <67> 48 0f b9 3a eb 05 e8 89 54 32 fc 49 bd 00 00 00 00 00 fc ff df
[ 12.556740][ T1] RSP: 0000:ffffc900001af450 EFLAGS: 00010246
[ 12.556740][ T1] RAX: 1ffff11000030e08 RBX: dffffc0000000000 RCX: ffff88801ceb0000
[ 12.556740][ T1] RDX: ffff88801f5b27a0 RSI: 0000000000000024 RDI: ffffffff9085b000
[ 12.556740][ T1] RBP: 0000000000000024 R08: ffffffff8ec2b347 R09: 1ffffffff1d85668
[ 12.556740][ T1] R10: dffffc0000000000 R11: fffffbfff1d85669 R12: dffffc0000000000
[ 12.556740][ T1] R13: ffffffff9085b000 R14: ffff888000187040 R15: ffff888000187030
[ 12.556740][ T1] ? __pfx_autoremove_wake_function+0x10/0x10
[ 12.556740][ T1] drm_dev_register+0x7c/0xd80
[ 12.556740][ T1] virtio_gpu_probe+0x1cb/0x290
[ 12.556740][ T1] virtio_dev_probe+0xdf6/0x10c0
[ 12.556740][ T1] ? up_write+0x19d/0x4a0
[ 12.556740][ T1] ? __pfx_virtio_dev_probe+0x10/0x10
[ 12.556740][ T1] ? driver_sysfs_add+0x1fe/0x210
[ 12.556740][ T1] ? __pfx_virtio_dev_probe+0x10/0x10
[ 12.556740][ T1] really_probe+0x254/0xae0
[ 12.556740][ T1] __driver_probe_device+0x1e8/0x360
[ 12.556740][ T1] driver_probe_device+0x4f/0x240
[ 12.556740][ T1] __driver_attach+0x339/0x600
[ 12.556740][ T1] bus_for_each_dev+0x23b/0x2c0
[ 12.556740][ T1] ? __pfx___driver_attach+0x10/0x10
[ 12.556740][ T1] ? __pfx_bus_for_each_dev+0x10/0x10
[ 12.556740][ T1] ? do_raw_spin_unlock+0x4d/0x200
[ 12.556740][ T1] bus_add_driver+0x345/0x670
[ 12.556740][ T1] driver_register+0x23a/0x320
[ 12.556740][ T1] ? __pfx_virtio_gpu_driver_init+0x10/0x10
[ 12.556740][ T1] virtio_gpu_driver_init+0x96/0x110
[ 12.556740][ T1] do_one_initcall+0x250/0x870
[ 12.556740][ T1] ? __pfx_virtio_gpu_driver_init+0x10/0x10
[ 12.556740][ T1] ? __pfx_do_one_initcall+0x10/0x10
[ 12.556740][ T1] ? __pfx___schedule+0x10/0x10
[ 12.556740][ T1] ? __pfx___schedule+0x10/0x10
[ 12.556740][ T1] ? _raw_spin_unlock_irqrestore+0x30/0x80
[ 12.556740][ T1] ? __pfx___schedule+0x10/0x10
[ 12.556740][ T1] ? irqentry_exit+0x218/0x910
[ 12.556740][ T1] ? lockdep_hardirqs_on+0x7b/0x110
[ 12.556740][ T1] ? irqentry_exit+0x218/0x910
[ 12.556740][ T1] ? trace_irq_disable+0x3b/0x140
[ 12.556740][ T1] ? parameq+0xd6/0x170
[ 12.556740][ T1] ? next_arg+0x4a0/0x5e0
[ 12.556740][ T1] ? parameq+0x14d/0x170
[ 12.556740][ T1] ? parse_args+0x9c3/0xad0
[ 12.556740][ T1] ? rcu_is_watching+0x16/0xb0
[ 12.556740][ T1] do_initcall_level+0x10a/0x1a0
[ 12.556740][ T1] ? kernel_init+0x22/0x1d0
[ 12.556740][ T1] do_initcalls+0x59/0xa0
[ 12.556740][ T1] kernel_init_freeable+0x29d/0x3e0
[ 12.556740][ T1] ? __pfx_kernel_init+0x10/0x10
[ 12.556740][ T1] kernel_init+0x22/0x1d0
[ 12.556740][ T1] ? __pfx_kernel_init+0x10/0x10
[ 12.556740][ T1] ret_from_fork+0x514/0xb70
[ 12.556740][ T1] ? __pfx_ret_from_fork+0x10/0x10
[ 12.556740][ T1] ? __switch_to+0xc89/0x1420
[ 12.556740][ T1] ? __pfx_kernel_init+0x10/0x10
[ 12.556740][ T1] ret_from_fork_asm+0x1a/0x30
[ 12.556740][ T1] </TASK>
[ 12.556740][ T1] Kernel Offset: disabled
[ 12.556740][ T1] Rebooting in 86400 seconds..
syzkaller build log:
go env (err=<nil>)
AR='ar'
CC='gcc'
CGO_CFLAGS='-O2 -g'
CGO_CPPFLAGS=''
CGO_CXXFLAGS='-O2 -g'
CGO_ENABLED='1'
CGO_FFLAGS='-O2 -g'
CGO_LDFLAGS='-O2 -g'
CXX='g++'
GCCGO='gccgo'
GO111MODULE='auto'
GOAMD64='v1'
GOARCH='amd64'
GOAUTH='netrc'
GOBIN=''
GOCACHE='/syzkaller/.cache/go-build'
GOCACHEPROG=''
GODEBUG=''
GOENV='/syzkaller/.config/go/env'
GOEXE=''
GOEXPERIMENT=''
GOFIPS140='off'
GOFLAGS=''
GOGCCFLAGS='-fPIC -m64 -pthread -Wl,--no-gc-sections -fmessage-length=0 -ffile-prefix-map=/tmp/go-build1726682488=/tmp/go-build -gno-record-gcc-switches'
GOHOSTARCH='amd64'
GOHOSTOS='linux'
GOINSECURE=''
GOMOD='/syzkaller/jobs/linux/gopath/src/github.com/google/syzkaller/go.mod'
GOMODCACHE='/syzkaller/jobs/linux/gopath/pkg/mod'
GONOPROXY=''
GONOSUMDB=''
GOOS='linux'
GOPATH='/syzkaller/jobs/linux/gopath'
GOPRIVATE=''
GOPROXY='https://proxy.golang.org,direct'
GOROOT='/usr/local/go'
GOSUMDB='sum.golang.org'
GOTELEMETRY='local'
GOTELEMETRYDIR='/syzkaller/.config/go/telemetry'
GOTMPDIR=''
GOTOOLCHAIN='auto'
GOTOOLDIR='/usr/local/go/pkg/tool/linux_amd64'
GOVCS=''
GOVERSION='go1.26.0'
GOWORK=''
PKG_CONFIG='pkg-config'
git status (err=<nil>)
HEAD detached at 680aa3e19b5
nothing to commit, working tree clean
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
go list -f '{{.Stale}}' -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=680aa3e19b52574eca8bcba3c41aa18235367abe -X github.com/google/syzkaller/prog.gitRevisionDate=20260907-094615" ./sys/syz-sysgen | grep -q false || go install -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=680aa3e19b52574eca8bcba3c41aa18235367abe -X github.com/google/syzkaller/prog.gitRevisionDate=20260907-094615" ./sys/syz-sysgen
make .descriptions
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
bin/syz-sysgen
touch .descriptions
GOOS=linux GOARCH=amd64 go build -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=680aa3e19b52574eca8bcba3c41aa18235367abe -X github.com/google/syzkaller/prog.gitRevisionDate=20260907-094615" -o ./bin/linux_amd64/syz-execprog github.com/google/syzkaller/tools/syz-execprog
mkdir -p ./bin/linux_amd64
g++ -o ./bin/linux_amd64/syz-executor executor/executor.cc \
-m64 -O2 -pthread -Wall -Werror -Wparentheses -Wunused-const-variable -Wframe-larger-than=16384 -Wno-stringop-overflow -Wno-array-bounds -Wno-format-overflow -Wno-unused-but-set-variable -Wno-unused-command-line-argument -static-pie -std=c++17 -I. -Iexecutor/_include -DGOOS_linux=1 -DGOARCH_amd64=1 \
-DHOSTGOOS_linux=1 -DGIT_REVISION=\"680aa3e19b52574eca8bcba3c41aa18235367abe\"
/usr/bin/ld: /tmp/ccLyACCI.o: in function `Connection::Connect(char const*, char const*)':
executor.cc:(.text._ZN10Connection7ConnectEPKcS1_[_ZN10Connection7ConnectEPKcS1_]+0x386): warning: Using 'gethostbyname' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking
./tools/check-syzos.sh 2>/dev/null
Error text is too large and was truncated, full error text is at:
https://syzkaller.appspot.com/x/error.txt?x=16bcf125580000
Tested on:
commit: 796aa054 io_uring/rw: end write accounting from ->ki_c..
git tree: git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux.git io_uring-7.3
kernel config: https://syzkaller.appspot.com/x/.config?x=780bb9a5c10069a1
dashboard link: https://syzkaller.appspot.com/bug?extid=2eb3d983669d3e49d4fa
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
Note: no patches were applied.
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [syzbot] [io-uring?] [ext4?] INFO: task hung in io_write
2026-09-09 1:10 ` Jens Axboe
2026-09-09 1:15 ` Jens Axboe
2026-09-09 1:35 ` syzbot
@ 2026-09-09 11:02 ` Jens Axboe
2026-09-09 11:27 ` syzbot
2026-09-09 11:46 ` Jens Axboe
3 siblings, 1 reply; 9+ messages in thread
From: Jens Axboe @ 2026-09-09 11:02 UTC (permalink / raw)
To: syzbot, io-uring, linux-ext4, linux-kernel, syzkaller-bugs
#syz test: git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux.git io_uring-7.3
--
Jens Axboe
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [syzbot] [io-uring?] [ext4?] INFO: task hung in io_write
2026-09-09 11:02 ` Jens Axboe
@ 2026-09-09 11:27 ` syzbot
0 siblings, 0 replies; 9+ messages in thread
From: syzbot @ 2026-09-09 11:27 UTC (permalink / raw)
To: axboe, io-uring, linux-ext4, linux-kernel, syzkaller-bugs
Hello,
syzbot tried to test the proposed patch but the build/boot failed:
[ T1] jffs2: version 2.2. (NAND) (SUMMARY) © 2001-2006 Red Hat, Inc.
[ 9.450006][ T1] romfs: ROMFS MTD (C) 2007 Red Hat, Inc.
[ 9.454451][ T1] QNX4 filesystem 0.2.3 registered.
[ 9.467839][ T1] qnx6: QNX6 filesystem 1.0.0 registered.
[ 9.473957][ T1] fuse: init (API version 7.45)
[ 9.493414][ T106] kworker/u4:1 (106) used greatest stack depth: 26960 bytes left
[ 9.499661][ T1] orangefs_debugfs_init: called with debug mask: :none: :0:
[ 9.517806][ T1] orangefs_init: module version upstream loaded
[ 9.523522][ T1] JFS: nTxBlock = 6145, nTxLock = 49167
[ 9.549727][ T1] SGI XFS with ACLs, security attributes, realtime, scrub, repair, quota, no debug enabled
[ 9.587305][ T1] 9p: Installing v9fs 9p2000 file system support
[ 9.598431][ T1] NILFS version 2 loaded
[ 9.601604][ T1] befs: version: 0.9.3
[ 9.605491][ T1] ocfs2: Registered cluster interface o2cb
[ 9.629421][ T1] ocfs2: Registered cluster interface user
[ 9.648529][ T1] OCFS2 User DLM kernel interface loaded
[ 9.683543][ T115] kworker/u4:2 (115) used greatest stack depth: 26504 bytes left
[ 9.711809][ T1] gfs2: GFS2 installed
[ 9.750240][ T1] ceph: loaded (mds proto 32)
[ 9.783162][ T1] NET: Registered PF_ALG protocol family
[ 9.798112][ T1] async_tx: api initialized (async)
[ 9.802397][ T1] Key type asymmetric registered
[ 9.817841][ T1] Asymmetric key parser 'x509' registered
[ 9.822530][ T1] Asymmetric key parser 'pkcs8' registered
[ 9.826906][ T1] Key type pkcs7_test registered
[ 9.839159][ T1] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 239)
[ 9.863479][ T1] io scheduler mq-deadline registered
[ 9.867560][ T1] io scheduler kyber registered
[ 9.878657][ T1] io scheduler bfq registered
[ 9.888919][ T1] raid6: skipped pq benchmark and selected avx512x4
[ 9.992971][ T1] ACPI: \_SB_.GSIE: Enabled at IRQ 20
[ 10.028066][ T1] pcieport 0000:00:04.0: PME: Signaling with IRQ 25
[ 10.059120][ T1] pcieport 0000:00:04.0: AER: enabled with IRQ 26
[ 10.082251][ T1] input: Power Button as /devices/platform/LNXPWRBN:00/input/input0
[ 10.101416][ T1] ACPI: button: Power Button [PWRF]
[ 10.994864][ T1] ioatdma: Intel(R) QuickData Technology Driver 5.00
[ 11.099208][ T1] ACPI: \_SB_.GSIF: Enabled at IRQ 21
[ 11.203563][ T1] ACPI: \_SB_.GSIH: Enabled at IRQ 23
[ 12.461571][ T1] N_HDLC line discipline registered with maxframe=4096
[ 12.473979][ T1] Serial: 8250/16550 driver, 4 ports, IRQ sharing enabled
[ 12.490839][ T1] 00:03: ttyS0 at I/O 0x3f8 (irq = 4, base_baud = 115200) is a 16550A
[ 12.596214][ T1] Non-volatile memory driver v1.3
[ 12.619055][ T1] usbcore: registered new interface driver xillyusb
[ 12.631909][ T1] ACPI: bus type drm_connector registered
[ 12.646781][ T1] [drm] Initialized vgem 1.0.0 for vgem on minor 0
[ 12.653751][ T1] usbcore: registered new interface driver udl
[ 12.660228][ T1] [drm] pci: virtio-vga detected at 0000:00:01.0
[ 12.665091][ T1] virtio-pci 0000:00:01.0: vgaarb: deactivate vga console
[ 12.690228][ T1] Console: switching to colour dummy device 80x25
[ 12.699414][ T1] [drm] features: -virgl +edid -resource_blob -host_visible
[ 12.699488][ T1] [drm] features: -context_init -blob_alignment
[ 12.717375][ T1] [drm] number of scanouts: 1
[ 12.721344][ T1] [drm] number of cap sets: 0
[ 12.728666][ T1] ------------[ cut here ]------------
[ 12.732715][ T1] [PLANE:36:plane-1] pixel format with alpha exposed but blend mode not setup
[ 12.732728][ T1] WARNING: drivers/gpu/drm/drm_mode_config.c:873 at drm_mode_config_validate+0x1c6a/0x1e60, CPU#0: swapper/0/1
[ 12.747874][ T1] Modules linked in:
[ 12.750657][ T1] CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT(full)
[ 12.756989][ T1] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[ 12.764555][ T1] RIP: 0010:drm_mode_config_validate+0x1cab/0x1e60
[ 12.769342][ T1] Code: 0f 85 ae 00 00 00 4d 8d 77 10 8b 6d 00 4c 89 f0 48 c1 e8 03 80 3c 18 00 74 08 4c 89 f7 e8 7d a5 a3 fc 49 8b 16 4c 89 ef 89 ee <67> 48 0f b9 3a eb 05 e8 89 54 32 fc 49 bd 00 00 00 00 00 fc ff df
[ 12.783031][ T1] RSP: 0000:ffffc900001af450 EFLAGS: 00010246
[ 12.787445][ T1] RAX: 1ffff110000a2808 RBX: dffffc0000000000 RCX: ffff88801ceb0000
[ 12.793083][ T1] RDX: ffff88801f5dd780 RSI: 0000000000000024 RDI: ffffffff9085b000
[ 12.798984][ T1] RBP: 0000000000000024 R08: ffffffff8ec2b347 R09: 1ffffffff1d85668
[ 12.804669][ T1] R10: dffffc0000000000 R11: fffffbfff1d85669 R12: dffffc0000000000
[ 12.810525][ T1] R13: ffffffff9085b000 R14: ffff888000514040 R15: ffff888000514030
[ 12.816240][ T1] FS: 0000000000000000(0000) GS:ffff88808c2e6000(0000) knlGS:0000000000000000
[ 12.822827][ T1] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 12.827688][ T1] CR2: ffff88801af19000 CR3: 000000000eb46000 CR4: 0000000000352ef0
[ 12.833506][ T1] Call Trace:
[ 12.835839][ T1] <TASK>
[ 12.838056][ T1] ? __pfx_autoremove_wake_function+0x10/0x10
[ 12.842500][ T1] drm_dev_register+0x7c/0xd80
[ 12.845841][ T1] virtio_gpu_probe+0x1cb/0x290
[ 12.849449][ T1] virtio_dev_probe+0xdf6/0x10c0
[ 12.853176][ T1] ? up_write+0x19d/0x4a0
[ 12.856327][ T1] ? __pfx_virtio_dev_probe+0x10/0x10
[ 12.860356][ T1] ? driver_sysfs_add+0x1fe/0x210
[ 12.864021][ T1] ? __pfx_virtio_dev_probe+0x10/0x10
[ 12.867970][ T1] really_probe+0x254/0xae0
[ 12.871209][ T1] __driver_probe_device+0x1e8/0x360
[ 12.875197][ T1] driver_probe_device+0x4f/0x240
[ 12.878980][ T1] __driver_attach+0x339/0x600
[ 12.882501][ T1] bus_for_each_dev+0x23b/0x2c0
[ 12.886017][ T1] ? __pfx___driver_attach+0x10/0x10
[ 12.889911][ T1] ? __pfx_bus_for_each_dev+0x10/0x10
[ 12.893969][ T1] ? do_raw_spin_unlock+0x4d/0x200
[ 12.897821][ T1] bus_add_driver+0x345/0x670
[ 12.901156][ T1] driver_register+0x23a/0x320
[ 12.904616][ T1] ? __pfx_virtio_gpu_driver_init+0x10/0x10
[ 12.908997][ T1] virtio_gpu_driver_init+0x96/0x110
[ 12.912765][ T1] do_one_initcall+0x250/0x870
[ 12.916048][ T1] ? __pfx_virtio_gpu_driver_init+0x10/0x10
[ 12.920425][ T1] ? __pfx_do_one_initcall+0x10/0x10
[ 12.924224][ T1] ? lapic_next_event+0x11/0x20
[ 12.927996][ T1] ? clockevents_program_event+0x491/0x630
[ 12.932173][ T1] ? __pfx___schedule+0x10/0x10
[ 12.935834][ T1] ? irqentry_exit+0x218/0x910
[ 12.939393][ T1] ? lockdep_hardirqs_on+0x7b/0x110
[ 12.943214][ T1] ? irqentry_exit+0x218/0x910
[ 12.946613][ T1] ? trace_irq_disable+0x3b/0x140
[ 12.950297][ T1] ? strlen+0x2e/0x70
[ 12.953299][ T1] ? next_arg+0x4a0/0x5e0
[ 12.956477][ T1] ? parameq+0x14d/0x170
[ 12.959569][ T1] ? parse_args+0x9c3/0xad0
[ 12.962839][ T1] ? rcu_is_watching+0x16/0xb0
[ 12.966030][ T1] do_initcall_level+0x10a/0x1a0
[ 12.969717][ T1] ? kernel_init+0x22/0x1d0
[ 12.973025][ T1] do_initcalls+0x59/0xa0
[ 12.976142][ T1] kernel_init_freeable+0x29d/0x3e0
[ 12.980086][ T1] ? __pfx_kernel_init+0x10/0x10
[ 12.983647][ T1] kernel_init+0x22/0x1d0
[ 12.986760][ T1] ? __pfx_kernel_init+0x10/0x10
[ 12.990406][ T1] ret_from_fork+0x514/0xb70
[ 12.993692][ T1] ? __pfx_ret_from_fork+0x10/0x10
[ 12.997415][ T1] ? __switch_to+0xc89/0x1420
[ 13.000914][ T1] ? __pfx_kernel_init+0x10/0x10
[ 13.004417][ T1] ret_from_fork_asm+0x1a/0x30
[ 13.007943][ T1] </TASK>
[ 13.010159][ T1] Kernel panic - not syncing: kernel: panic_on_warn set ...
[ 13.015418][ T1] CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT(full)
[ 13.017889][ T1] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[ 13.017889][ T1] Call Trace:
[ 13.017889][ T1] <TASK>
[ 13.017889][ T1] vpanic+0x56d/0xa60
[ 13.017889][ T1] ? __pfx__printk+0x10/0x10
[ 13.017889][ T1] ? __pfx_vpanic+0x10/0x10
[ 13.017889][ T1] ? is_bpf_text_address+0x292/0x2b0
[ 13.017889][ T1] ? is_bpf_text_address+0x26/0x2b0
[ 13.017889][ T1] panic+0xc5/0xd0
[ 13.017889][ T1] ? __pfx_panic+0x10/0x10
[ 13.017889][ T1] ? ret_from_fork_asm+0x1a/0x30
[ 13.017889][ T1] __warn+0x315/0x4c0
[ 13.017889][ T1] ? drm_mode_config_validate+0x1c6a/0x1e60
[ 13.017889][ T1] ? drm_mode_config_validate+0x1c6a/0x1e60
[ 13.017889][ T1] __report_bug+0x276/0x570
[ 13.017889][ T1] ? blocking_notifier_chain_register+0x50/0xc0
[ 13.017889][ T1] ? drm_mode_config_validate+0x1c6a/0x1e60
[ 13.017889][ T1] ? __pfx___report_bug+0x10/0x10
[ 13.017889][ T1] ? blocking_notifier_chain_register+0x6b/0xc0
[ 13.017889][ T1] report_bug_entry+0x19b/0x290
[ 13.017889][ T1] ? drm_mode_config_validate+0x1cab/0x1e60
[ 13.017889][ T1] ? drm_mode_config_validate+0x1cb0/0x1e60
[ 13.017889][ T1] handle_bug+0xce/0x200
[ 13.017889][ T1] exc_invalid_op+0x1a/0x50
[ 13.017889][ T1] asm_exc_invalid_op+0x1a/0x20
[ 13.017889][ T1] RIP: 0010:drm_mode_config_validate+0x1cab/0x1e60
[ 13.017889][ T1] Code: 0f 85 ae 00 00 00 4d 8d 77 10 8b 6d 00 4c 89 f0 48 c1 e8 03 80 3c 18 00 74 08 4c 89 f7 e8 7d a5 a3 fc 49 8b 16 4c 89 ef 89 ee <67> 48 0f b9 3a eb 05 e8 89 54 32 fc 49 bd 00 00 00 00 00 fc ff df
[ 13.017889][ T1] RSP: 0000:ffffc900001af450 EFLAGS: 00010246
[ 13.017889][ T1] RAX: 1ffff110000a2808 RBX: dffffc0000000000 RCX: ffff88801ceb0000
[ 13.017889][ T1] RDX: ffff88801f5dd780 RSI: 0000000000000024 RDI: ffffffff9085b000
[ 13.017889][ T1] RBP: 0000000000000024 R08: ffffffff8ec2b347 R09: 1ffffffff1d85668
[ 13.017889][ T1] R10: dffffc0000000000 R11: fffffbfff1d85669 R12: dffffc0000000000
[ 13.017889][ T1] R13: ffffffff9085b000 R14: ffff888000514040 R15: ffff888000514030
[ 13.017889][ T1] ? __pfx_autoremove_wake_function+0x10/0x10
[ 13.017889][ T1] drm_dev_register+0x7c/0xd80
[ 13.017889][ T1] virtio_gpu_probe+0x1cb/0x290
[ 13.017889][ T1] virtio_dev_probe+0xdf6/0x10c0
[ 13.017889][ T1] ? up_write+0x19d/0x4a0
[ 13.017889][ T1] ? __pfx_virtio_dev_probe+0x10/0x10
[ 13.017889][ T1] ? driver_sysfs_add+0x1fe/0x210
[ 13.017889][ T1] ? __pfx_virtio_dev_probe+0x10/0x10
[ 13.017889][ T1] really_probe+0x254/0xae0
[ 13.017889][ T1] __driver_probe_device+0x1e8/0x360
[ 13.017889][ T1] driver_probe_device+0x4f/0x240
[ 13.017889][ T1] __driver_attach+0x339/0x600
[ 13.017889][ T1] bus_for_each_dev+0x23b/0x2c0
[ 13.017889][ T1] ? __pfx___driver_attach+0x10/0x10
[ 13.017889][ T1] ? __pfx_bus_for_each_dev+0x10/0x10
[ 13.017889][ T1] ? do_raw_spin_unlock+0x4d/0x200
[ 13.017889][ T1] bus_add_driver+0x345/0x670
[ 13.017889][ T1] driver_register+0x23a/0x320
[ 13.017889][ T1] ? __pfx_virtio_gpu_driver_init+0x10/0x10
[ 13.017889][ T1] virtio_gpu_driver_init+0x96/0x110
[ 13.017889][ T1] do_one_initcall+0x250/0x870
[ 13.017889][ T1] ? __pfx_virtio_gpu_driver_init+0x10/0x10
[ 13.017889][ T1] ? __pfx_do_one_initcall+0x10/0x10
[ 13.017889][ T1] ? lapic_next_event+0x11/0x20
[ 13.017889][ T1] ? clockevents_program_event+0x491/0x630
[ 13.017889][ T1] ? __pfx___schedule+0x10/0x10
[ 13.017889][ T1] ? irqentry_exit+0x218/0x910
[ 13.017889][ T1] ? lockdep_hardirqs_on+0x7b/0x110
[ 13.017889][ T1] ? irqentry_exit+0x218/0x910
[ 13.017889][ T1] ? trace_irq_disable+0x3b/0x140
[ 13.017889][ T1] ? strlen+0x2e/0x70
[ 13.017889][ T1] ? next_arg+0x4a0/0x5e0
[ 13.017889][ T1] ? parameq+0x14d/0x170
[ 13.017889][ T1] ? parse_args+0x9c3/0xad0
[ 13.017889][ T1] ? rcu_is_watching+0x16/0xb0
[ 13.017889][ T1] do_initcall_level+0x10a/0x1a0
[ 13.017889][ T1] ? kernel_init+0x22/0x1d0
[ 13.017889][ T1] do_initcalls+0x59/0xa0
[ 13.017889][ T1] kernel_init_freeable+0x29d/0x3e0
[ 13.017889][ T1] ? __pfx_kernel_init+0x10/0x10
[ 13.017889][ T1] kernel_init+0x22/0x1d0
[ 13.017889][ T1] ? __pfx_kernel_init+0x10/0x10
[ 13.017889][ T1] ret_from_fork+0x514/0xb70
[ 13.017889][ T1] ? __pfx_ret_from_fork+0x10/0x10
[ 13.017889][ T1] ? __switch_to+0xc89/0x1420
[ 13.017889][ T1] ? __pfx_kernel_init+0x10/0x10
[ 13.017889][ T1] ret_from_fork_asm+0x1a/0x30
[ 13.017889][ T1] </TASK>
[ 13.017889][ T1] Kernel Offset: disabled
[ 13.017889][ T1] Rebooting in 86400 seconds..
syzkaller build log:
go env (err=<nil>)
AR='ar'
CC='gcc'
CGO_CFLAGS='-O2 -g'
CGO_CPPFLAGS=''
CGO_CXXFLAGS='-O2 -g'
CGO_ENABLED='1'
CGO_FFLAGS='-O2 -g'
CGO_LDFLAGS='-O2 -g'
CXX='g++'
GCCGO='gccgo'
GO111MODULE='auto'
GOAMD64='v1'
GOARCH='amd64'
GOAUTH='netrc'
GOBIN=''
GOCACHE='/syzkaller/.cache/go-build'
GOCACHEPROG=''
GODEBUG=''
GOENV='/syzkaller/.config/go/env'
GOEXE=''
GOEXPERIMENT=''
GOFIPS140='off'
GOFLAGS=''
GOGCCFLAGS='-fPIC -m64 -pthread -Wl,--no-gc-sections -fmessage-length=0 -ffile-prefix-map=/tmp/go-build2768744602=/tmp/go-build -gno-record-gcc-switches'
GOHOSTARCH='amd64'
GOHOSTOS='linux'
GOINSECURE=''
GOMOD='/syzkaller/jobs/linux/gopath/src/github.com/google/syzkaller/go.mod'
GOMODCACHE='/syzkaller/jobs/linux/gopath/pkg/mod'
GONOPROXY=''
GONOSUMDB=''
GOOS='linux'
GOPATH='/syzkaller/jobs/linux/gopath'
GOPRIVATE=''
GOPROXY='https://proxy.golang.org,direct'
GOROOT='/usr/local/go'
GOSUMDB='sum.golang.org'
GOTELEMETRY='local'
GOTELEMETRYDIR='/syzkaller/.config/go/telemetry'
GOTMPDIR=''
GOTOOLCHAIN='auto'
GOTOOLDIR='/usr/local/go/pkg/tool/linux_amd64'
GOVCS=''
GOVERSION='go1.26.0'
GOWORK=''
PKG_CONFIG='pkg-config'
git status (err=<nil>)
HEAD detached at 680aa3e19b5
nothing to commit, working tree clean
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
go list -f '{{.Stale}}' -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=680aa3e19b52574eca8bcba3c41aa18235367abe -X github.com/google/syzkaller/prog.gitRevisionDate=20260907-094615" ./sys/syz-sysgen | grep -q false || go install -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=680aa3e19b52574eca8bcba3c41aa18235367abe -X github.com/google/syzkaller/prog.gitRevisionDate=20260907-094615" ./sys/syz-sysgen
make .descriptions
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
bin/syz-sysgen
touch .descriptions
GOOS=linux GOARCH=amd64 go build -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=680aa3e19b52574eca8bcba3c41aa18235367abe -X github.com/google/syzkaller/prog.gitRevisionDate=20260907-094615" -o ./bin/linux_amd64/syz-execprog github.com/google/syzkaller/tools/syz-execprog
mkdir -p ./bin/linux_amd64
g++ -o ./bin/linux_amd64/syz-executor executor/executor.cc \
-m64 -O2 -pthread -Wall -Werror -Wparentheses -Wunused-const-variable -Wframe-larger-than=16384 -Wno-stringop-overflow -Wno-array-bounds -Wno-format-overflow -Wno-unused-but-set-variable -Wno-unused-command-line-argument -static-pie -std=c++17 -I. -Iexecutor/_include -DGOOS_linux=1 -DGOARCH_amd64=1 \
-DHOSTGOOS_linux=1 -DGIT_REVISION=\"680aa3e19b52574eca8bcba3c41aa18235367abe\"
/usr/bin/ld: /tmp/ccdJQzUC.o: in function `Connection::Connect(char const*, char const*)':
executor.cc:(.text._ZN10Connection7ConnectEPKcS1_[_ZN10Connection7ConnectEPKcS1_]+0x386): warning: Using 'gethostbyname' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking
./tools/check-syzos.sh 2>/dev/null
Error text is too large and was truncated, full error text is at:
https://syzkaller.appspot.com/x/error.txt?x=164baa15580000
Tested on:
commit: 796aa054 io_uring/rw: end write accounting from ->ki_c..
git tree: git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux.git io_uring-7.3
kernel config: https://syzkaller.appspot.com/x/.config?x=780bb9a5c10069a1
dashboard link: https://syzkaller.appspot.com/bug?extid=2eb3d983669d3e49d4fa
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
Note: no patches were applied.
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [syzbot] [io-uring?] [ext4?] INFO: task hung in io_write
2026-09-09 1:10 ` Jens Axboe
` (2 preceding siblings ...)
2026-09-09 11:02 ` Jens Axboe
@ 2026-09-09 11:46 ` Jens Axboe
2026-09-09 12:13 ` syzbot
3 siblings, 1 reply; 9+ messages in thread
From: Jens Axboe @ 2026-09-09 11:46 UTC (permalink / raw)
To: syzbot, io-uring, linux-ext4, linux-kernel, syzkaller-bugs
#syz test: git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux.git syztest
Let's try on a new base, perhaps it's a mainline issue keeping syzbot from
booting.
--
Jens Axboe
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [syzbot] [io-uring?] [ext4?] INFO: task hung in io_write
2026-09-09 11:46 ` Jens Axboe
@ 2026-09-09 12:13 ` syzbot
0 siblings, 0 replies; 9+ messages in thread
From: syzbot @ 2026-09-09 12:13 UTC (permalink / raw)
To: axboe, io-uring, linux-ext4, linux-kernel, syzkaller-bugs
Hello,
syzbot has tested the proposed patch and the reproducer did not trigger any issue:
Reported-by: syzbot+2eb3d983669d3e49d4fa@syzkaller.appspotmail.com
Tested-by: syzbot+2eb3d983669d3e49d4fa@syzkaller.appspotmail.com
Tested on:
commit: 57ab5080 io_uring/io-wq: don't trigger hung task for s..
git tree: git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux.git syztest
console output: https://syzkaller.appspot.com/x/log.txt?x=127b7af9580000
kernel config: https://syzkaller.appspot.com/x/.config?x=679ea3cb74b430f3
dashboard link: https://syzkaller.appspot.com/bug?extid=2eb3d983669d3e49d4fa
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
Note: no patches were applied.
Note: testing is done by a robot and is best-effort only.
^ permalink raw reply [flat|nested] 9+ messages in thread
end of thread, other threads:[~2026-09-09 12:13 UTC | newest]
Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-08 22:08 [syzbot] [io-uring?] [ext4?] INFO: task hung in io_write syzbot
2026-09-09 1:10 ` Jens Axboe
2026-09-09 1:15 ` Jens Axboe
2026-09-09 1:58 ` syzbot
2026-09-09 1:35 ` syzbot
2026-09-09 11:02 ` Jens Axboe
2026-09-09 11:27 ` syzbot
2026-09-09 11:46 ` Jens Axboe
2026-09-09 12:13 ` syzbot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox