public inbox for io-uring@vger.kernel.org
 help / color / mirror / Atom feed
* [syzbot] [io-uring?] [ext4?] INFO: task hung in io_write
@ 2026-09-08 22:08 syzbot
  2026-09-09  1:10 ` Jens Axboe
  0 siblings, 1 reply; 9+ messages in thread
From: syzbot @ 2026-09-08 22:08 UTC (permalink / raw)
  To: axboe, io-uring, linux-ext4, linux-kernel, syzkaller-bugs

Hello,

syzbot found the following issue on:

HEAD commit:    28924df2a08f Merge tag 'perf-tools-fixes-for-v7.3-2026-09-..
git tree:       upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=13842af9580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=e909ffe6b35dddb7
dashboard link: https://syzkaller.appspot.com/bug?extid=2eb3d983669d3e49d4fa
compiler:       Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
syz repro:      https://syzkaller.appspot.com/x/repro.syz?x=160d1749580000
C reproducer:   https://syzkaller.appspot.com/x/repro.c?x=13993af9580000

Downloadable assets:
disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/d900f083ada3/non_bootable_disk-28924df2.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/309bf243aefc/vmlinux-28924df2.xz
kernel image: https://storage.googleapis.com/syzbot-assets/5baa1c49144e/bzImage-28924df2.xz
mounted in repro: https://storage.googleapis.com/syzbot-assets/7dba324ffac0/mount_1.gz
  fsck result: OK (log: https://syzkaller.appspot.com/x/fsck.log?x=15842af9580000)

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+2eb3d983669d3e49d4fa@syzkaller.appspotmail.com

INFO: task iou-wrk-5725:5730 blocked for more than 143 seconds.
      Not tainted syzkaller #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:iou-wrk-5725    state:D stack:22112 pid:5730  tgid:5724  ppid:5438   task_flags:0x404050 flags:0x00080002
Call Trace:
 <TASK>
 context_switch kernel/sched/core.c:5526 [inline]
 __schedule+0x17db/0x58f0 kernel/sched/core.c:7276
 __schedule_loop kernel/sched/core.c:7353 [inline]
 schedule+0x164/0x2b0 kernel/sched/core.c:7368
 percpu_rwsem_wait+0x326/0x490 kernel/locking/percpu-rwsem.c:164
 __percpu_down_read+0xee/0x130 kernel/locking/percpu-rwsem.c:180
 percpu_down_read_internal include/linux/percpu-rwsem.h:67 [inline]
 percpu_down_read_freezable include/linux/percpu-rwsem.h:83 [inline]
 __sb_start_write include/linux/fs/super.h:19 [inline]
 sb_start_write include/linux/fs/super.h:125 [inline]
 kiocb_start_write include/linux/fs.h:2787 [inline]
 io_kiocb_start_write io_uring/rw.c:1109 [inline]
 io_write+0x120c/0x1680 io_uring/rw.c:1163
 __io_issue_sqe+0x188/0x4d0 io_uring/io_uring.c:1386
 io_issue_sqe+0x16d/0x1020 io_uring/io_uring.c:1409
 io_wq_submit_work+0x7ab/0xc90 io_uring/io_uring.c:1525
 io_worker_handle_work+0x7a1/0x1140 io_uring/io-wq.c:659
 io_wq_worker+0x452/0xf10 io_uring/io-wq.c:714
 ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158
 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
 </TASK>

Showing all locks held in the system:
locks held by kworker/u4:1/13: 2, last CPU#0:
 #0: ffff88801b094140 ((wq_completion)events_unbound){+.+.}-{0:0}, at: rcu_lock_acquire include/linux/rcupdate.h:309 [inline]
 #0: ffff88801b094140 ((wq_completion)events_unbound){+.+.}-{0:0}, at: rcu_read_lock include/linux/rcupdate.h:849 [inline]
 #0: ffff88801b094140 ((wq_completion)events_unbound){+.+.}-{0:0}, at: process_one_work kernel/workqueue.c:3361 [inline]
 #0: ffff88801b094140 ((wq_completion)events_unbound){+.+.}-{0:0}, at: process_scheduled_works+0x97a/0x1630 kernel/workqueue.c:3479
 #1: ffffc9000026fc40 ((work_completion)(&(&nsim_dev->trap_data->trap_report_dw)->work)){+.+.}-{0:0}, at: rcu_lock_acquire include/linux/rcupdate.h:309 [inline]
 #1: ffffc9000026fc40 ((work_completion)(&(&nsim_dev->trap_data->trap_report_dw)->work)){+.+.}-{0:0}, at: rcu_read_lock include/linux/rcupdate.h:849 [inline]
 #1: ffffc9000026fc40 ((work_completion)(&(&nsim_dev->trap_data->trap_report_dw)->work)){+.+.}-{0:0}, at: process_one_work kernel/workqueue.c:3361 [inline]
 #1: ffffc9000026fc40 ((work_completion)(&(&nsim_dev->trap_data->trap_report_dw)->work)){+.+.}-{0:0}, at: process_scheduled_works+0x97a/0x1630 kernel/workqueue.c:3479
locks held by khungtaskd/26: 1, last CPU#0:
 #0: ffffffff8ed5c760 (rcu_read_lock){....}-{1:3}, at: rcu_lock_acquire include/linux/rcupdate.h:309 [inline]
 #0: ffffffff8ed5c760 (rcu_read_lock){....}-{1:3}, at: rcu_read_lock include/linux/rcupdate.h:849 [inline]
 #0: ffffffff8ed5c760 (rcu_read_lock){....}-{1:3}, at: debug_show_all_locks+0x2e/0x180 kernel/locking/lockdep.c:6871
locks held by kworker/u4:2/37: 3, last CPU#0:
 #0: ffff88801b094140 ((wq_completion)events_unbound){+.+.}-{0:0}, at: rcu_lock_acquire include/linux/rcupdate.h:309 [inline]
 #0: ffff88801b094140 ((wq_completion)events_unbound){+.+.}-{0:0}, at: rcu_read_lock include/linux/rcupdate.h:849 [inline]
 #0: ffff88801b094140 ((wq_completion)events_unbound){+.+.}-{0:0}, at: process_one_work kernel/workqueue.c:3361 [inline]
 #0: ffff88801b094140 ((wq_completion)events_unbound){+.+.}-{0:0}, at: process_scheduled_works+0x97a/0x1630 kernel/workqueue.c:3479
 #1: ffffc900003f7c40 ((work_completion)(&(&nsim_dev->trap_data->trap_report_dw)->work)){+.+.}-{0:0}, at: rcu_lock_acquire include/linux/rcupdate.h:309 [inline]
 #1: ffffc900003f7c40 ((work_completion)(&(&nsim_dev->trap_data->trap_report_dw)->work)){+.+.}-{0:0}, at: rcu_read_lock include/linux/rcupdate.h:849 [inline]
 #1: ffffc900003f7c40 ((work_completion)(&(&nsim_dev->trap_data->trap_report_dw)->work)){+.+.}-{0:0}, at: process_one_work kernel/workqueue.c:3361 [inline]
 #1: ffffc900003f7c40 ((work_completion)(&(&nsim_dev->trap_data->trap_report_dw)->work)){+.+.}-{0:0}, at: process_scheduled_works+0x97a/0x1630 kernel/workqueue.c:3479
 #2: ffff888051872258 (&devlink->lock_key#4){+.+.}-{4:4}, at: nsim_dev_trap_report_work+0x57/0xb40 drivers/net/netdevsim/dev.c:834
locks held by kworker/u4:3/43: 2, on CPU#0:
 #0: ffff88801b094140 ((wq_completion)events_unbound){+.+.}-{0:0}, at: rcu_lock_acquire include/linux/rcupdate.h:309 [inline]
 #0: ffff88801b094140 ((wq_completion)events_unbound){+.+.}-{0:0}, at: rcu_read_lock include/linux/rcupdate.h:849 [inline]
 #0: ffff88801b094140 ((wq_completion)events_unbound){+.+.}-{0:0}, at: process_one_work kernel/workqueue.c:3361 [inline]
 #0: ffff88801b094140 ((wq_completion)events_unbound){+.+.}-{0:0}, at: process_scheduled_works+0x97a/0x1630 kernel/workqueue.c:3479
 #1: ffffc90000877c40 ((work_completion)(&(&kfence_timer)->work)){+.+.}-{0:0}, at: rcu_lock_acquire include/linux/rcupdate.h:309 [inline]
 #1: ffffc90000877c40 ((work_completion)(&(&kfence_timer)->work)){+.+.}-{0:0}, at: rcu_read_lock include/linux/rcupdate.h:849 [inline]
 #1: ffffc90000877c40 ((work_completion)(&(&kfence_timer)->work)){+.+.}-{0:0}, at: process_one_work kernel/workqueue.c:3361 [inline]
 #1: ffffc90000877c40 ((work_completion)(&(&kfence_timer)->work)){+.+.}-{0:0}, at: process_scheduled_works+0x97a/0x1630 kernel/workqueue.c:3479
locks held by kworker/u4:7/187: 4, last CPU#0:
 #0: ffff88803fa20140 ((wq_completion)bat_events){+.+.}-{0:0}, at: rcu_lock_acquire include/linux/rcupdate.h:309 [inline]
 #0: ffff88803fa20140 ((wq_completion)bat_events){+.+.}-{0:0}, at: rcu_read_lock include/linux/rcupdate.h:849 [inline]
 #0: ffff88803fa20140 ((wq_completion)bat_events){+.+.}-{0:0}, at: process_one_work kernel/workqueue.c:3361 [inline]
 #0: ffff88803fa20140 ((wq_completion)bat_events){+.+.}-{0:0}, at: process_scheduled_works+0x97a/0x1630 kernel/workqueue.c:3479
 #1: ffffc900019dfc40 ((work_completion)(&(&forw_packet_aggr->delayed_work)->work)){+.+.}-{0:0}, at: rcu_lock_acquire include/linux/rcupdate.h:309 [inline]
 #1: ffffc900019dfc40 ((work_completion)(&(&forw_packet_aggr->delayed_work)->work)){+.+.}-{0:0}, at: rcu_read_lock include/linux/rcupdate.h:849 [inline]
 #1: ffffc900019dfc40 ((work_completion)(&(&forw_packet_aggr->delayed_work)->work)){+.+.}-{0:0}, at: process_one_work kernel/workqueue.c:3361 [inline]
 #1: ffffc900019dfc40 ((work_completion)(&(&forw_packet_aggr->delayed_work)->work)){+.+.}-{0:0}, at: process_scheduled_works+0x97a/0x1630 kernel/workqueue.c:3479
 #2: ffff88801fc3bb20 (&rq->__lock){-.-.}-{2:2}, at: raw_spin_rq_lock_nested+0x2d/0x160 kernel/sched/core.c:677
 #3: ffff88801fc24408 (psi_seq){-.-.}-{0:0}, at: psi_task_switch+0x57/0x7d0 kernel/sched/psi.c:933
locks held by getty/5086: 2, on CPU#0:
 #0: ffff88803ee570a0 (&tty->ldisc_sem){++++}-{0:0}, at: tty_ldisc_ref_wait+0x25/0x70 drivers/tty/tty_ldisc.c:243
 #1: ffffc90000d202e8 (&ldata->atomic_read_lock){+.+.}-{4:4}, at: n_tty_read+0x45a/0x1360 drivers/tty/n_tty.c:2211
locks held by kworker/0:10/5721: 3, last CPU#0:
 #0: ffff88801b0a8940 ((wq_completion)events){+.+.}-{0:0}, at: rcu_lock_acquire include/linux/rcupdate.h:309 [inline]
 #0: ffff88801b0a8940 ((wq_completion)events){+.+.}-{0:0}, at: rcu_read_lock include/linux/rcupdate.h:849 [inline]
 #0: ffff88801b0a8940 ((wq_completion)events){+.+.}-{0:0}, at: process_one_work kernel/workqueue.c:3361 [inline]
 #0: ffff88801b0a8940 ((wq_completion)events){+.+.}-{0:0}, at: process_scheduled_works+0x97a/0x1630 kernel/workqueue.c:3479
 #1: ffffc900052f7c40 ((work_completion)(&adapter->watchdog_task)){+.+.}-{0:0}, at: rcu_lock_acquire include/linux/rcupdate.h:309 [inline]
 #1: ffffc900052f7c40 ((work_completion)(&adapter->watchdog_task)){+.+.}-{0:0}, at: rcu_read_lock include/linux/rcupdate.h:849 [inline]
 #1: ffffc900052f7c40 ((work_completion)(&adapter->watchdog_task)){+.+.}-{0:0}, at: process_one_work kernel/workqueue.c:3361 [inline]
 #1: ffffc900052f7c40 ((work_completion)(&adapter->watchdog_task)){+.+.}-{0:0}, at: process_scheduled_works+0x97a/0x1630 kernel/workqueue.c:3479
 #2: ffff88801fc26118 (&base->lock){-.-.}-{2:2}, at: lock_timer_base kernel/time/timer.c:1004 [inline]
 #2: ffff88801fc26118 (&base->lock){-.-.}-{2:2}, at: __mod_timer+0x1a9/0xed0 kernel/time/timer.c:1085
locks held by syz.0.23/5725: 2, on CPU#0:
 #0: ffff88801d025220 (&bdev->bd_fsfreeze_mutex){+.+.}-{4:4}, at: bdev_freeze+0x33/0x2f0 block/bdev.c:304
 #1: ffff888048fa4460 (sb_writers#4){++++}-{0:0}, at: sb_wait_write fs/super.c:2043 [inline]
 #1: ffff888048fa4460 (sb_writers#4){++++}-{0:0}, at: freeze_super+0x4f4/0x11c0 fs/super.c:2307
locks held by iou-wrk-5725/5730: 1, on CPU#0:
 #0: ffff888048fa4460 (sb_writers#4){++++}-{0:0}, at: __io_issue_sqe+0x188/0x4d0 io_uring/io_uring.c:1386

=============================================

NMI backtrace for cpu 0
CPU: 0 UID: 0 PID: 26 Comm: khungtaskd Not tainted syzkaller #0 PREEMPT(full) 
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Call Trace:
 <TASK>
 dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120
 nmi_cpu_backtrace+0x274/0x2d0 lib/nmi_backtrace.c:123
 nmi_trigger_cpumask_backtrace+0x17d/0x390 lib/nmi_backtrace.c:66
 trigger_all_cpu_backtrace include/linux/nmi.h:164 [inline]
 __sys_info lib/sys_info.c:157 [inline]
 sys_info+0x135/0x170 lib/sys_info.c:165
 check_hung_uninterruptible_tasks kernel/hung_task.c:353 [inline]
 watchdog+0xfd7/0x1030 kernel/hung_task.c:561
 kthread+0x38b/0x480 kernel/kthread.c:436
 ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158
 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
 </TASK>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [syzbot] [io-uring?] [ext4?] INFO: task hung in io_write
  2026-09-08 22:08 [syzbot] [io-uring?] [ext4?] INFO: task hung in io_write syzbot
@ 2026-09-09  1:10 ` Jens Axboe
  2026-09-09  1:15   ` Jens Axboe
                     ` (3 more replies)
  0 siblings, 4 replies; 9+ messages in thread
From: Jens Axboe @ 2026-09-09  1:10 UTC (permalink / raw)
  To: syzbot, io-uring, linux-ext4, linux-kernel, syzkaller-bugs

#syz test: git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux.git io_uring-7.3

-- 
Jens Axboe


^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [syzbot] [io-uring?] [ext4?] INFO: task hung in io_write
  2026-09-09  1:10 ` Jens Axboe
@ 2026-09-09  1:15   ` Jens Axboe
  2026-09-09  1:58     ` syzbot
  2026-09-09  1:35   ` syzbot
                     ` (2 subsequent siblings)
  3 siblings, 1 reply; 9+ messages in thread
From: Jens Axboe @ 2026-09-09  1:15 UTC (permalink / raw)
  To: syzbot, io-uring, linux-ext4, linux-kernel, syzkaller-bugs

#syz test: git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux.git io_uring-7.3

Forgot to push it out... Let's kick it again.

-- 
Jens Axboe


^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [syzbot] [io-uring?] [ext4?] INFO: task hung in io_write
  2026-09-09  1:10 ` Jens Axboe
  2026-09-09  1:15   ` Jens Axboe
@ 2026-09-09  1:35   ` syzbot
  2026-09-09 11:02   ` Jens Axboe
  2026-09-09 11:46   ` Jens Axboe
  3 siblings, 0 replies; 9+ messages in thread
From: syzbot @ 2026-09-09  1:35 UTC (permalink / raw)
  To: axboe, io-uring, linux-ext4, linux-kernel, syzkaller-bugs

Hello,

syzbot tried to test the proposed patch but the build/boot failed:

t
[    9.311884][    T1] ntfs3: Read-only LZX/Xpress compression included
[    9.324965][    T1] jffs2: version 2.2. (NAND) (SUMMARY)  © 2001-2006 Red Hat, Inc.
[    9.339487][    T1] romfs: ROMFS MTD (C) 2007 Red Hat, Inc.
[    9.354547][    T1] QNX4 filesystem 0.2.3 registered.
[    9.358628][    T1] qnx6: QNX6 filesystem 1.0.0 registered.
[    9.374595][    T1] fuse: init (API version 7.45)
[    9.386259][    T1] orangefs_debugfs_init: called with debug mask: :none: :0:
[    9.405773][    T1] orangefs_init: module version upstream loaded
[    9.411433][    T1] JFS: nTxBlock = 6145, nTxLock = 49167
[    9.432378][    T1] SGI XFS with ACLs, security attributes, realtime, scrub, repair, quota, no debug enabled
[    9.460589][    T1] 9p: Installing v9fs 9p2000 file system support
[    9.474863][    T1] NILFS version 2 loaded
[    9.478065][    T1] befs: version: 0.9.3
[    9.481916][    T1] ocfs2: Registered cluster interface o2cb
[    9.505141][    T1] ocfs2: Registered cluster interface user
[    9.511060][    T1] OCFS2 User DLM kernel interface loaded
[    9.555232][    T1] gfs2: GFS2 installed
[    9.587926][    T1] ceph: loaded (mds proto 32)
[    9.609192][    T1] NET: Registered PF_ALG protocol family
[    9.613568][    T1] async_tx: api initialized (async)
[    9.634473][    T1] Key type asymmetric registered
[    9.638422][    T1] Asymmetric key parser 'x509' registered
[    9.643521][    T1] Asymmetric key parser 'pkcs8' registered
[    9.654318][    T1] Key type pkcs7_test registered
[    9.665499][    T1] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 239)
[    9.676502][    T1] io scheduler mq-deadline registered
[    9.694302][    T1] io scheduler kyber registered
[    9.698347][    T1] io scheduler bfq registered
[    9.703715][    T1] raid6: skipped pq benchmark and selected avx512x4
[    9.803123][    T1] ACPI: \_SB_.GSIE: Enabled at IRQ 20
[    9.844760][    T1] pcieport 0000:00:04.0: PME: Signaling with IRQ 25
[    9.855822][    T1] pcieport 0000:00:04.0: AER: enabled with IRQ 26
[    9.888231][    T1] input: Power Button as /devices/platform/LNXPWRBN:00/input/input0
[    9.907560][    T1] ACPI: button: Power Button [PWRF]
[   10.781900][    T1] ioatdma: Intel(R) QuickData Technology Driver 5.00
[   10.871170][    T1] ACPI: \_SB_.GSIF: Enabled at IRQ 21
[   10.969004][    T1] ACPI: \_SB_.GSIH: Enabled at IRQ 23
[   12.148632][    T1] N_HDLC line discipline registered with maxframe=4096
[   12.165434][    T1] Serial: 8250/16550 driver, 4 ports, IRQ sharing enabled
[   12.190821][    T1] 00:03: ttyS0 at I/O 0x3f8 (irq = 4, base_baud = 115200) is a 16550A
[   12.338747][    T1] Non-volatile memory driver v1.3
[   12.377313][    T1] usbcore: registered new interface driver xillyusb
[   12.393087][    T1] ACPI: bus type drm_connector registered
[   12.432983][    T1] [drm] Initialized vgem 1.0.0 for vgem on minor 0
[   12.445520][    T1] usbcore: registered new interface driver udl
[   12.455961][    T1] [drm] pci: virtio-vga detected at 0000:00:01.0
[   12.460653][    T1] virtio-pci 0000:00:01.0: vgaarb: deactivate vga console
[   12.515474][    T1] Console: switching to colour dummy device 80x25
[   12.523215][    T1] [drm] features: -virgl +edid -resource_blob -host_visible
[   12.523225][    T1] [drm] features: -context_init -blob_alignment
[   12.542435][    T1] [drm] number of scanouts: 1
[   12.545813][    T1] [drm] number of cap sets: 0
[   12.554747][    T1] ------------[ cut here ]------------
[   12.558333][    T1] [PLANE:36:plane-1] pixel format with alpha exposed but blend mode not setup
[   12.558342][    T1] WARNING: drivers/gpu/drm/drm_mode_config.c:873 at drm_mode_config_validate+0x1c6a/0x1e60, CPU#0: swapper/0/1
[   12.573118][    T1] Modules linked in:
[   12.576385][    T1] CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT(full) 
[   12.582807][    T1] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[   12.590090][    T1] RIP: 0010:drm_mode_config_validate+0x1cab/0x1e60
[   12.594850][    T1] Code: 0f 85 ae 00 00 00 4d 8d 77 10 8b 6d 00 4c 89 f0 48 c1 e8 03 80 3c 18 00 74 08 4c 89 f7 e8 bd a5 a3 fc 49 8b 16 4c 89 ef 89 ee <67> 48 0f b9 3a eb 05 e8 c9 54 32 fc 49 bd 00 00 00 00 00 fc ff df
[   12.608988][    T1] RSP: 0000:ffffc900001af450 EFLAGS: 00010246
[   12.613447][    T1] RAX: 1ffff11000029408 RBX: dffffc0000000000 RCX: ffff88801ceb0000
[   12.619368][    T1] RDX: ffff88801f5db780 RSI: 0000000000000024 RDI: ffffffff9085b000
[   12.625154][    T1] RBP: 0000000000000024 R08: ffffffff8ec2b347 R09: 1ffffffff1d85668
[   12.631012][    T1] R10: dffffc0000000000 R11: fffffbfff1d85669 R12: dffffc0000000000
[   12.636862][    T1] R13: ffffffff9085b000 R14: ffff88800014a040 R15: ffff88800014a030
[   12.642683][    T1] FS:  0000000000000000(0000) GS:ffff88808c2e6000(0000) knlGS:0000000000000000
[   12.649778][    T1] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[   12.654807][    T1] CR2: ffff88801af19000 CR3: 000000000eb46000 CR4: 0000000000352ef0
[   12.660778][    T1] Call Trace:
[   12.663243][    T1]  <TASK>
[   12.665510][    T1]  ? __pfx_autoremove_wake_function+0x10/0x10
[   12.669917][    T1]  drm_dev_register+0x7c/0xd80
[   12.673383][    T1]  virtio_gpu_probe+0x1cb/0x290
[   12.677087][    T1]  virtio_dev_probe+0xdf6/0x10c0
[   12.680755][    T1]  ? up_write+0x19d/0x4a0
[   12.684009][    T1]  ? __pfx_virtio_dev_probe+0x10/0x10
[   12.687928][    T1]  ? driver_sysfs_add+0x1fe/0x210
[   12.691505][    T1]  ? __pfx_virtio_dev_probe+0x10/0x10
[   12.695595][    T1]  really_probe+0x254/0xae0
[   12.698866][    T1]  __driver_probe_device+0x1e8/0x360
[   12.702663][    T1]  driver_probe_device+0x4f/0x240
[   12.706350][    T1]  __driver_attach+0x339/0x600
[   12.709736][    T1]  bus_for_each_dev+0x23b/0x2c0
[   12.713247][    T1]  ? __pfx___driver_attach+0x10/0x10
[   12.717330][    T1]  ? __pfx_bus_for_each_dev+0x10/0x10
[   12.721241][    T1]  ? do_raw_spin_unlock+0x4d/0x200
[   12.724984][    T1]  bus_add_driver+0x345/0x670
[   12.728449][    T1]  driver_register+0x23a/0x320
[   12.732054][    T1]  ? __pfx_virtio_gpu_driver_init+0x10/0x10
[   12.736511][    T1]  virtio_gpu_driver_init+0x96/0x110
[   12.740363][    T1]  do_one_initcall+0x250/0x870
[   12.743753][    T1]  ? __pfx_virtio_gpu_driver_init+0x10/0x10
[   12.747725][    T1]  ? __pfx_do_one_initcall+0x10/0x10
[   12.750854][    T1]  ? __pfx___schedule+0x10/0x10
[   12.754246][    T1]  ? irqentry_exit+0x218/0x910
[   12.757543][    T1]  ? lockdep_hardirqs_on+0x7b/0x110
[   12.760932][    T1]  ? irqentry_exit+0x218/0x910
[   12.764435][    T1]  ? trace_irq_disable+0x3b/0x140
[   12.767922][    T1]  ? parameq+0x37/0x170
[   12.770899][    T1]  ? next_arg+0x4a0/0x5e0
[   12.773885][    T1]  ? parameq+0x14d/0x170
[   12.776877][    T1]  ? parse_args+0x9c3/0xad0
[   12.779988][    T1]  ? rcu_is_watching+0x16/0xb0
[   12.783393][    T1]  do_initcall_level+0x10a/0x1a0
[   12.787027][    T1]  ? kernel_init+0x22/0x1d0
[   12.790245][    T1]  do_initcalls+0x59/0xa0
[   12.793486][    T1]  kernel_init_freeable+0x29d/0x3e0
[   12.796995][    T1]  ? __pfx_kernel_init+0x10/0x10
[   12.800223][    T1]  kernel_init+0x22/0x1d0
[   12.803175][    T1]  ? __pfx_kernel_init+0x10/0x10
[   12.806784][    T1]  ret_from_fork+0x514/0xb70
[   12.809992][    T1]  ? __pfx_ret_from_fork+0x10/0x10
[   12.813663][    T1]  ? __switch_to+0xc89/0x1420
[   12.817141][    T1]  ? __pfx_kernel_init+0x10/0x10
[   12.820600][    T1]  ret_from_fork_asm+0x1a/0x30
[   12.824086][    T1]  </TASK>
[   12.826409][    T1] Kernel panic - not syncing: kernel: panic_on_warn set ...
[   12.831660][    T1] CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT(full) 
[   12.836273][    T1] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[   12.836273][    T1] Call Trace:
[   12.836273][    T1]  <TASK>
[   12.836273][    T1]  vpanic+0x56d/0xa60
[   12.836273][    T1]  ? __pfx__printk+0x10/0x10
[   12.836273][    T1]  ? __pfx_vpanic+0x10/0x10
[   12.836273][    T1]  ? is_bpf_text_address+0x292/0x2b0
[   12.836273][    T1]  ? is_bpf_text_address+0x26/0x2b0
[   12.836273][    T1]  panic+0xc5/0xd0
[   12.836273][    T1]  ? __pfx_panic+0x10/0x10
[   12.836273][    T1]  ? ret_from_fork_asm+0x1a/0x30
[   12.836273][    T1]  __warn+0x315/0x4c0
[   12.836273][    T1]  ? drm_mode_config_validate+0x1c6a/0x1e60
[   12.836273][    T1]  ? drm_mode_config_validate+0x1c6a/0x1e60
[   12.836273][    T1]  __report_bug+0x276/0x570
[   12.836273][    T1]  ? blocking_notifier_chain_register+0x50/0xc0
[   12.836273][    T1]  ? drm_mode_config_validate+0x1c6a/0x1e60
[   12.836273][    T1]  ? __pfx___report_bug+0x10/0x10
[   12.836273][    T1]  ? blocking_notifier_chain_register+0x6b/0xc0
[   12.836273][    T1]  report_bug_entry+0x19b/0x290
[   12.836273][    T1]  ? drm_mode_config_validate+0x1cab/0x1e60
[   12.836273][    T1]  ? drm_mode_config_validate+0x1cb0/0x1e60
[   12.836273][    T1]  handle_bug+0xce/0x200
[   12.836273][    T1]  exc_invalid_op+0x1a/0x50
[   12.836273][    T1]  asm_exc_invalid_op+0x1a/0x20
[   12.836273][    T1] RIP: 0010:drm_mode_config_validate+0x1cab/0x1e60
[   12.836273][    T1] Code: 0f 85 ae 00 00 00 4d 8d 77 10 8b 6d 00 4c 89 f0 48 c1 e8 03 80 3c 18 00 74 08 4c 89 f7 e8 bd a5 a3 fc 49 8b 16 4c 89 ef 89 ee <67> 48 0f b9 3a eb 05 e8 c9 54 32 fc 49 bd 00 00 00 00 00 fc ff df
[   12.836273][    T1] RSP: 0000:ffffc900001af450 EFLAGS: 00010246
[   12.836273][    T1] RAX: 1ffff11000029408 RBX: dffffc0000000000 RCX: ffff88801ceb0000
[   12.836273][    T1] RDX: ffff88801f5db780 RSI: 0000000000000024 RDI: ffffffff9085b000
[   12.836273][    T1] RBP: 0000000000000024 R08: ffffffff8ec2b347 R09: 1ffffffff1d85668
[   12.836273][    T1] R10: dffffc0000000000 R11: fffffbfff1d85669 R12: dffffc0000000000
[   12.836273][    T1] R13: ffffffff9085b000 R14: ffff88800014a040 R15: ffff88800014a030
[   12.836273][    T1]  ? __pfx_autoremove_wake_function+0x10/0x10
[   12.836273][    T1]  drm_dev_register+0x7c/0xd80
[   12.836273][    T1]  virtio_gpu_probe+0x1cb/0x290
[   12.836273][    T1]  virtio_dev_probe+0xdf6/0x10c0
[   12.836273][    T1]  ? up_write+0x19d/0x4a0
[   12.836273][    T1]  ? __pfx_virtio_dev_probe+0x10/0x10
[   12.836273][    T1]  ? driver_sysfs_add+0x1fe/0x210
[   12.836273][    T1]  ? __pfx_virtio_dev_probe+0x10/0x10
[   12.836273][    T1]  really_probe+0x254/0xae0
[   12.836273][    T1]  __driver_probe_device+0x1e8/0x360
[   12.836273][    T1]  driver_probe_device+0x4f/0x240
[   12.836273][    T1]  __driver_attach+0x339/0x600
[   12.836273][    T1]  bus_for_each_dev+0x23b/0x2c0
[   12.836273][    T1]  ? __pfx___driver_attach+0x10/0x10
[   12.836273][    T1]  ? __pfx_bus_for_each_dev+0x10/0x10
[   12.836273][    T1]  ? do_raw_spin_unlock+0x4d/0x200
[   12.836273][    T1]  bus_add_driver+0x345/0x670
[   12.836273][    T1]  driver_register+0x23a/0x320
[   12.836273][    T1]  ? __pfx_virtio_gpu_driver_init+0x10/0x10
[   12.836273][    T1]  virtio_gpu_driver_init+0x96/0x110
[   12.836273][    T1]  do_one_initcall+0x250/0x870
[   12.836273][    T1]  ? __pfx_virtio_gpu_driver_init+0x10/0x10
[   12.836273][    T1]  ? __pfx_do_one_initcall+0x10/0x10
[   12.836273][    T1]  ? __pfx___schedule+0x10/0x10
[   12.836273][    T1]  ? irqentry_exit+0x218/0x910
[   12.836273][    T1]  ? lockdep_hardirqs_on+0x7b/0x110
[   12.836273][    T1]  ? irqentry_exit+0x218/0x910
[   12.836273][    T1]  ? trace_irq_disable+0x3b/0x140
[   12.836273][    T1]  ? parameq+0x37/0x170
[   12.836273][    T1]  ? next_arg+0x4a0/0x5e0
[   12.836273][    T1]  ? parameq+0x14d/0x170
[   12.836273][    T1]  ? parse_args+0x9c3/0xad0
[   12.836273][    T1]  ? rcu_is_watching+0x16/0xb0
[   12.836273][    T1]  do_initcall_level+0x10a/0x1a0
[   12.836273][    T1]  ? kernel_init+0x22/0x1d0
[   12.836273][    T1]  do_initcalls+0x59/0xa0
[   12.836273][    T1]  kernel_init_freeable+0x29d/0x3e0
[   12.836273][    T1]  ? __pfx_kernel_init+0x10/0x10
[   12.836273][    T1]  kernel_init+0x22/0x1d0
[   12.836273][    T1]  ? __pfx_kernel_init+0x10/0x10
[   12.836273][    T1]  ret_from_fork+0x514/0xb70
[   12.836273][    T1]  ? __pfx_ret_from_fork+0x10/0x10
[   12.836273][    T1]  ? __switch_to+0xc89/0x1420
[   12.836273][    T1]  ? __pfx_kernel_init+0x10/0x10
[   12.836273][    T1]  ret_from_fork_asm+0x1a/0x30
[   12.836273][    T1]  </TASK>
[   12.836273][    T1] Kernel Offset: disabled
[   12.836273][    T1] Rebooting in 86400 seconds..


syzkaller build log:
go env (err=<nil>)
AR='ar'
CC='gcc'
CGO_CFLAGS='-O2 -g'
CGO_CPPFLAGS=''
CGO_CXXFLAGS='-O2 -g'
CGO_ENABLED='1'
CGO_FFLAGS='-O2 -g'
CGO_LDFLAGS='-O2 -g'
CXX='g++'
GCCGO='gccgo'
GO111MODULE='auto'
GOAMD64='v1'
GOARCH='amd64'
GOAUTH='netrc'
GOBIN=''
GOCACHE='/syzkaller/.cache/go-build'
GOCACHEPROG=''
GODEBUG=''
GOENV='/syzkaller/.config/go/env'
GOEXE=''
GOEXPERIMENT=''
GOFIPS140='off'
GOFLAGS=''
GOGCCFLAGS='-fPIC -m64 -pthread -Wl,--no-gc-sections -fmessage-length=0 -ffile-prefix-map=/tmp/go-build2134465290=/tmp/go-build -gno-record-gcc-switches'
GOHOSTARCH='amd64'
GOHOSTOS='linux'
GOINSECURE=''
GOMOD='/syzkaller/jobs/linux/gopath/src/github.com/google/syzkaller/go.mod'
GOMODCACHE='/syzkaller/jobs/linux/gopath/pkg/mod'
GONOPROXY=''
GONOSUMDB=''
GOOS='linux'
GOPATH='/syzkaller/jobs/linux/gopath'
GOPRIVATE=''
GOPROXY='https://proxy.golang.org,direct'
GOROOT='/usr/local/go'
GOSUMDB='sum.golang.org'
GOTELEMETRY='local'
GOTELEMETRYDIR='/syzkaller/.config/go/telemetry'
GOTMPDIR=''
GOTOOLCHAIN='auto'
GOTOOLDIR='/usr/local/go/pkg/tool/linux_amd64'
GOVCS=''
GOVERSION='go1.26.0'
GOWORK=''
PKG_CONFIG='pkg-config'

git status (err=<nil>)
HEAD detached at 680aa3e19b5
nothing to commit, working tree clean


tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
go list -f '{{.Stale}}' -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=680aa3e19b52574eca8bcba3c41aa18235367abe -X github.com/google/syzkaller/prog.gitRevisionDate=20260907-094615"  ./sys/syz-sysgen | grep -q false || go install -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=680aa3e19b52574eca8bcba3c41aa18235367abe -X github.com/google/syzkaller/prog.gitRevisionDate=20260907-094615"  ./sys/syz-sysgen
make .descriptions
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
bin/syz-sysgen
touch .descriptions
GOOS=linux GOARCH=amd64 go build -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=680aa3e19b52574eca8bcba3c41aa18235367abe -X github.com/google/syzkaller/prog.gitRevisionDate=20260907-094615"  -o ./bin/linux_amd64/syz-execprog github.com/google/syzkaller/tools/syz-execprog
mkdir -p ./bin/linux_amd64
g++ -o ./bin/linux_amd64/syz-executor executor/executor.cc \
	-m64 -O2 -pthread -Wall -Werror -Wparentheses -Wunused-const-variable -Wframe-larger-than=16384 -Wno-stringop-overflow -Wno-array-bounds -Wno-format-overflow -Wno-unused-but-set-variable -Wno-unused-command-line-argument -static-pie -std=c++17 -I. -Iexecutor/_include   -DGOOS_linux=1 -DGOARCH_amd64=1 \
	-DHOSTGOOS_linux=1 -DGIT_REVISION=\"680aa3e19b52574eca8bcba3c41aa18235367abe\"
go: downloading google.golang.org/grpc v1.83.1
go: downloading go.opentelemetry.io/contrib/detectors/gcp v1.44.0
go: downloading github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.33.0
go: downloading github.com/klauspost/compress v1.18.7
go: downloading github.com/spiffe/go-spiffe/v2 v2.7.0
/usr/bin/ld: /tmp/ccpIPst8.o: in function `Connection::Connect(char const*, char const*)':
executor.cc:(.text._ZN10Connection7ConnectEPKcS1_[_ZN10Connection7ConnectEPKcS1_]+0x386): warning: Using 'gethostbyname' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking
./tools/check-syzos.sh 2>/dev/null


Error text is too large and was truncated, full error text is at:
https://syzkaller.appspot.com/x/error.txt?x=161cf125580000


Tested on:

commit:         2cf20c4e io_uring/waitid: avoid siginfo copy during ri..
git tree:       git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux.git io_uring-7.3
kernel config:  https://syzkaller.appspot.com/x/.config?x=780bb9a5c10069a1
dashboard link: https://syzkaller.appspot.com/bug?extid=2eb3d983669d3e49d4fa
compiler:       Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8

Note: no patches were applied.

^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [syzbot] [io-uring?] [ext4?] INFO: task hung in io_write
  2026-09-09  1:15   ` Jens Axboe
@ 2026-09-09  1:58     ` syzbot
  0 siblings, 0 replies; 9+ messages in thread
From: syzbot @ 2026-09-09  1:58 UTC (permalink / raw)
  To: axboe, io-uring, linux-ext4, linux-kernel, syzkaller-bugs

Hello,

syzbot tried to test the proposed patch but the build/boot failed:

TD (C) 2007 Red Hat, Inc.
[    9.051564][    T1] QNX4 filesystem 0.2.3 registered.
[    9.065214][    T1] qnx6: QNX6 filesystem 1.0.0 registered.
[    9.075912][    T1] fuse: init (API version 7.45)
[    9.091183][    T1] orangefs_debugfs_init: called with debug mask: :none: :0:
[    9.106914][    T1] orangefs_init: module version upstream loaded
[    9.113002][    T1] JFS: nTxBlock = 6145, nTxLock = 49167
[    9.142915][    T1] SGI XFS with ACLs, security attributes, realtime, scrub, repair, quota, no debug enabled
[    9.170468][    T1] 9p: Installing v9fs 9p2000 file system support
[    9.185644][    T1] NILFS version 2 loaded
[    9.188849][    T1] befs: version: 0.9.3
[    9.193115][    T1] ocfs2: Registered cluster interface o2cb
[    9.206206][    T1] ocfs2: Registered cluster interface user
[    9.216419][    T1] OCFS2 User DLM kernel interface loaded
[    9.265973][    T1] gfs2: GFS2 installed
[    9.298657][    T1] ceph: loaded (mds proto 32)
[    9.320185][    T1] NET: Registered PF_ALG protocol family
[    9.324663][    T1] async_tx: api initialized (async)
[    9.345185][    T1] Key type asymmetric registered
[    9.349130][    T1] Asymmetric key parser 'x509' registered
[    9.353465][    T1] Asymmetric key parser 'pkcs8' registered
[    9.365187][    T1] Key type pkcs7_test registered
[    9.376596][    T1] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 239)
[    9.396528][    T1] io scheduler mq-deadline registered
[    9.400698][    T1] io scheduler kyber registered
[    9.415450][    T1] io scheduler bfq registered
[    9.420059][    T1] raid6: skipped pq benchmark and selected avx512x4
[    9.442033][  T127] kworker/u4:1 (127) used greatest stack depth: 26984 bytes left
[    9.524259][    T1] ACPI: \_SB_.GSIE: Enabled at IRQ 20
[    9.565511][    T1] pcieport 0000:00:04.0: PME: Signaling with IRQ 25
[    9.578930][    T1] pcieport 0000:00:04.0: AER: enabled with IRQ 26
[    9.601450][    T1] input: Power Button as /devices/platform/LNXPWRBN:00/input/input0
[    9.629341][    T1] ACPI: button: Power Button [PWRF]
[   10.450014][    T1] ioatdma: Intel(R) QuickData Technology Driver 5.00
[   10.532357][    T1] ACPI: \_SB_.GSIF: Enabled at IRQ 21
[   10.629521][    T1] ACPI: \_SB_.GSIH: Enabled at IRQ 23
[   10.892841][  T270] kworker/u4:1 (270) used greatest stack depth: 26960 bytes left
[   11.809081][    T1] N_HDLC line discipline registered with maxframe=4096
[   11.830246][    T1] Serial: 8250/16550 driver, 4 ports, IRQ sharing enabled
[   11.849727][    T1] 00:03: ttyS0 at I/O 0x3f8 (irq = 4, base_baud = 115200) is a 16550A
[   11.999300][    T1] Non-volatile memory driver v1.3
[   12.037071][    T1] usbcore: registered new interface driver xillyusb
[   12.058150][    T1] ACPI: bus type drm_connector registered
[   12.091068][    T1] [drm] Initialized vgem 1.0.0 for vgem on minor 0
[   12.105742][    T1] usbcore: registered new interface driver udl
[   12.112516][    T1] [drm] pci: virtio-vga detected at 0000:00:01.0
[   12.125337][    T1] virtio-pci 0000:00:01.0: vgaarb: deactivate vga console
[   12.186303][    T1] Console: switching to colour dummy device 80x25
[   12.194466][    T1] [drm] features: -virgl +edid -resource_blob -host_visible
[   12.194482][    T1] [drm] features: -context_init -blob_alignment
[   12.230560][    T1] [drm] number of scanouts: 1
[   12.233893][    T1] [drm] number of cap sets: 0
[   12.255974][    T1] ------------[ cut here ]------------
[   12.260092][    T1] [PLANE:36:plane-1] pixel format with alpha exposed but blend mode not setup
[   12.260107][    T1] WARNING: drivers/gpu/drm/drm_mode_config.c:873 at drm_mode_config_validate+0x1c6a/0x1e60, CPU#0: swapper/0/1
[   12.275683][    T1] Modules linked in:
[   12.279250][    T1] CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT(full) 
[   12.285867][    T1] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[   12.293265][    T1] RIP: 0010:drm_mode_config_validate+0x1cab/0x1e60
[   12.298167][    T1] Code: 0f 85 ae 00 00 00 4d 8d 77 10 8b 6d 00 4c 89 f0 48 c1 e8 03 80 3c 18 00 74 08 4c 89 f7 e8 7d a5 a3 fc 49 8b 16 4c 89 ef 89 ee <67> 48 0f b9 3a eb 05 e8 89 54 32 fc 49 bd 00 00 00 00 00 fc ff df
[   12.312441][    T1] RSP: 0000:ffffc900001af450 EFLAGS: 00010246
[   12.316951][    T1] RAX: 1ffff11000030e08 RBX: dffffc0000000000 RCX: ffff88801ceb0000
[   12.322637][    T1] RDX: ffff88801f5b27a0 RSI: 0000000000000024 RDI: ffffffff9085b000
[   12.328653][    T1] RBP: 0000000000000024 R08: ffffffff8ec2b347 R09: 1ffffffff1d85668
[   12.334503][    T1] R10: dffffc0000000000 R11: fffffbfff1d85669 R12: dffffc0000000000
[   12.340419][    T1] R13: ffffffff9085b000 R14: ffff888000187040 R15: ffff888000187030
[   12.346250][    T1] FS:  0000000000000000(0000) GS:ffff88808c2e6000(0000) knlGS:0000000000000000
[   12.352727][    T1] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[   12.357998][    T1] CR2: ffff88801af19000 CR3: 000000000eb46000 CR4: 0000000000352ef0
[   12.363905][    T1] Call Trace:
[   12.366455][    T1]  <TASK>
[   12.368581][    T1]  ? __pfx_autoremove_wake_function+0x10/0x10
[   12.372972][    T1]  drm_dev_register+0x7c/0xd80
[   12.376503][    T1]  virtio_gpu_probe+0x1cb/0x290
[   12.380071][    T1]  virtio_dev_probe+0xdf6/0x10c0
[   12.383655][    T1]  ? up_write+0x19d/0x4a0
[   12.386865][    T1]  ? __pfx_virtio_dev_probe+0x10/0x10
[   12.390829][    T1]  ? driver_sysfs_add+0x1fe/0x210
[   12.394687][    T1]  ? __pfx_virtio_dev_probe+0x10/0x10
[   12.398721][    T1]  really_probe+0x254/0xae0
[   12.402015][    T1]  __driver_probe_device+0x1e8/0x360
[   12.406009][    T1]  driver_probe_device+0x4f/0x240
[   12.413118][    T1]  __driver_attach+0x339/0x600
[   12.416808][    T1]  bus_for_each_dev+0x23b/0x2c0
[   12.420389][    T1]  ? __pfx___driver_attach+0x10/0x10
[   12.424449][    T1]  ? __pfx_bus_for_each_dev+0x10/0x10
[   12.428383][    T1]  ? do_raw_spin_unlock+0x4d/0x200
[   12.431965][    T1]  bus_add_driver+0x345/0x670
[   12.435503][    T1]  driver_register+0x23a/0x320
[   12.438896][    T1]  ? __pfx_virtio_gpu_driver_init+0x10/0x10
[   12.443320][    T1]  virtio_gpu_driver_init+0x96/0x110
[   12.447202][    T1]  do_one_initcall+0x250/0x870
[   12.450824][    T1]  ? __pfx_virtio_gpu_driver_init+0x10/0x10
[   12.455195][    T1]  ? __pfx_do_one_initcall+0x10/0x10
[   12.459086][    T1]  ? __pfx___schedule+0x10/0x10
[   12.462702][    T1]  ? __pfx___schedule+0x10/0x10
[   12.466316][    T1]  ? _raw_spin_unlock_irqrestore+0x30/0x80
[   12.470553][    T1]  ? __pfx___schedule+0x10/0x10
[   12.474166][    T1]  ? irqentry_exit+0x218/0x910
[   12.477695][    T1]  ? lockdep_hardirqs_on+0x7b/0x110
[   12.481598][    T1]  ? irqentry_exit+0x218/0x910
[   12.485220][    T1]  ? trace_irq_disable+0x3b/0x140
[   12.488882][    T1]  ? parameq+0xd6/0x170
[   12.492000][    T1]  ? next_arg+0x4a0/0x5e0
[   12.495249][    T1]  ? parameq+0x14d/0x170
[   12.498246][    T1]  ? parse_args+0x9c3/0xad0
[   12.501454][    T1]  ? rcu_is_watching+0x16/0xb0
[   12.505007][    T1]  do_initcall_level+0x10a/0x1a0
[   12.508580][    T1]  ? kernel_init+0x22/0x1d0
[   12.511816][    T1]  do_initcalls+0x59/0xa0
[   12.515060][    T1]  kernel_init_freeable+0x29d/0x3e0
[   12.518828][    T1]  ? __pfx_kernel_init+0x10/0x10
[   12.522466][    T1]  kernel_init+0x22/0x1d0
[   12.525706][    T1]  ? __pfx_kernel_init+0x10/0x10
[   12.529224][    T1]  ret_from_fork+0x514/0xb70
[   12.532504][    T1]  ? __pfx_ret_from_fork+0x10/0x10
[   12.536233][    T1]  ? __switch_to+0xc89/0x1420
[   12.539759][    T1]  ? __pfx_kernel_init+0x10/0x10
[   12.543298][    T1]  ret_from_fork_asm+0x1a/0x30
[   12.546840][    T1]  </TASK>
[   12.549044][    T1] Kernel panic - not syncing: kernel: panic_on_warn set ...
[   12.554149][    T1] CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT(full) 
[   12.556740][    T1] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[   12.556740][    T1] Call Trace:
[   12.556740][    T1]  <TASK>
[   12.556740][    T1]  vpanic+0x56d/0xa60
[   12.556740][    T1]  ? __pfx__printk+0x10/0x10
[   12.556740][    T1]  ? __pfx_vpanic+0x10/0x10
[   12.556740][    T1]  ? is_bpf_text_address+0x292/0x2b0
[   12.556740][    T1]  ? is_bpf_text_address+0x26/0x2b0
[   12.556740][    T1]  panic+0xc5/0xd0
[   12.556740][    T1]  ? __pfx_panic+0x10/0x10
[   12.556740][    T1]  ? ret_from_fork_asm+0x1a/0x30
[   12.556740][    T1]  __warn+0x315/0x4c0
[   12.556740][    T1]  ? drm_mode_config_validate+0x1c6a/0x1e60
[   12.556740][    T1]  ? drm_mode_config_validate+0x1c6a/0x1e60
[   12.556740][    T1]  __report_bug+0x276/0x570
[   12.556740][    T1]  ? blocking_notifier_chain_register+0x50/0xc0
[   12.556740][    T1]  ? drm_mode_config_validate+0x1c6a/0x1e60
[   12.556740][    T1]  ? __pfx___report_bug+0x10/0x10
[   12.556740][    T1]  ? blocking_notifier_chain_register+0x6b/0xc0
[   12.556740][    T1]  report_bug_entry+0x19b/0x290
[   12.556740][    T1]  ? drm_mode_config_validate+0x1cab/0x1e60
[   12.556740][    T1]  ? drm_mode_config_validate+0x1cb0/0x1e60
[   12.556740][    T1]  handle_bug+0xce/0x200
[   12.556740][    T1]  exc_invalid_op+0x1a/0x50
[   12.556740][    T1]  asm_exc_invalid_op+0x1a/0x20
[   12.556740][    T1] RIP: 0010:drm_mode_config_validate+0x1cab/0x1e60
[   12.556740][    T1] Code: 0f 85 ae 00 00 00 4d 8d 77 10 8b 6d 00 4c 89 f0 48 c1 e8 03 80 3c 18 00 74 08 4c 89 f7 e8 7d a5 a3 fc 49 8b 16 4c 89 ef 89 ee <67> 48 0f b9 3a eb 05 e8 89 54 32 fc 49 bd 00 00 00 00 00 fc ff df
[   12.556740][    T1] RSP: 0000:ffffc900001af450 EFLAGS: 00010246
[   12.556740][    T1] RAX: 1ffff11000030e08 RBX: dffffc0000000000 RCX: ffff88801ceb0000
[   12.556740][    T1] RDX: ffff88801f5b27a0 RSI: 0000000000000024 RDI: ffffffff9085b000
[   12.556740][    T1] RBP: 0000000000000024 R08: ffffffff8ec2b347 R09: 1ffffffff1d85668
[   12.556740][    T1] R10: dffffc0000000000 R11: fffffbfff1d85669 R12: dffffc0000000000
[   12.556740][    T1] R13: ffffffff9085b000 R14: ffff888000187040 R15: ffff888000187030
[   12.556740][    T1]  ? __pfx_autoremove_wake_function+0x10/0x10
[   12.556740][    T1]  drm_dev_register+0x7c/0xd80
[   12.556740][    T1]  virtio_gpu_probe+0x1cb/0x290
[   12.556740][    T1]  virtio_dev_probe+0xdf6/0x10c0
[   12.556740][    T1]  ? up_write+0x19d/0x4a0
[   12.556740][    T1]  ? __pfx_virtio_dev_probe+0x10/0x10
[   12.556740][    T1]  ? driver_sysfs_add+0x1fe/0x210
[   12.556740][    T1]  ? __pfx_virtio_dev_probe+0x10/0x10
[   12.556740][    T1]  really_probe+0x254/0xae0
[   12.556740][    T1]  __driver_probe_device+0x1e8/0x360
[   12.556740][    T1]  driver_probe_device+0x4f/0x240
[   12.556740][    T1]  __driver_attach+0x339/0x600
[   12.556740][    T1]  bus_for_each_dev+0x23b/0x2c0
[   12.556740][    T1]  ? __pfx___driver_attach+0x10/0x10
[   12.556740][    T1]  ? __pfx_bus_for_each_dev+0x10/0x10
[   12.556740][    T1]  ? do_raw_spin_unlock+0x4d/0x200
[   12.556740][    T1]  bus_add_driver+0x345/0x670
[   12.556740][    T1]  driver_register+0x23a/0x320
[   12.556740][    T1]  ? __pfx_virtio_gpu_driver_init+0x10/0x10
[   12.556740][    T1]  virtio_gpu_driver_init+0x96/0x110
[   12.556740][    T1]  do_one_initcall+0x250/0x870
[   12.556740][    T1]  ? __pfx_virtio_gpu_driver_init+0x10/0x10
[   12.556740][    T1]  ? __pfx_do_one_initcall+0x10/0x10
[   12.556740][    T1]  ? __pfx___schedule+0x10/0x10
[   12.556740][    T1]  ? __pfx___schedule+0x10/0x10
[   12.556740][    T1]  ? _raw_spin_unlock_irqrestore+0x30/0x80
[   12.556740][    T1]  ? __pfx___schedule+0x10/0x10
[   12.556740][    T1]  ? irqentry_exit+0x218/0x910
[   12.556740][    T1]  ? lockdep_hardirqs_on+0x7b/0x110
[   12.556740][    T1]  ? irqentry_exit+0x218/0x910
[   12.556740][    T1]  ? trace_irq_disable+0x3b/0x140
[   12.556740][    T1]  ? parameq+0xd6/0x170
[   12.556740][    T1]  ? next_arg+0x4a0/0x5e0
[   12.556740][    T1]  ? parameq+0x14d/0x170
[   12.556740][    T1]  ? parse_args+0x9c3/0xad0
[   12.556740][    T1]  ? rcu_is_watching+0x16/0xb0
[   12.556740][    T1]  do_initcall_level+0x10a/0x1a0
[   12.556740][    T1]  ? kernel_init+0x22/0x1d0
[   12.556740][    T1]  do_initcalls+0x59/0xa0
[   12.556740][    T1]  kernel_init_freeable+0x29d/0x3e0
[   12.556740][    T1]  ? __pfx_kernel_init+0x10/0x10
[   12.556740][    T1]  kernel_init+0x22/0x1d0
[   12.556740][    T1]  ? __pfx_kernel_init+0x10/0x10
[   12.556740][    T1]  ret_from_fork+0x514/0xb70
[   12.556740][    T1]  ? __pfx_ret_from_fork+0x10/0x10
[   12.556740][    T1]  ? __switch_to+0xc89/0x1420
[   12.556740][    T1]  ? __pfx_kernel_init+0x10/0x10
[   12.556740][    T1]  ret_from_fork_asm+0x1a/0x30
[   12.556740][    T1]  </TASK>
[   12.556740][    T1] Kernel Offset: disabled
[   12.556740][    T1] Rebooting in 86400 seconds..


syzkaller build log:
go env (err=<nil>)
AR='ar'
CC='gcc'
CGO_CFLAGS='-O2 -g'
CGO_CPPFLAGS=''
CGO_CXXFLAGS='-O2 -g'
CGO_ENABLED='1'
CGO_FFLAGS='-O2 -g'
CGO_LDFLAGS='-O2 -g'
CXX='g++'
GCCGO='gccgo'
GO111MODULE='auto'
GOAMD64='v1'
GOARCH='amd64'
GOAUTH='netrc'
GOBIN=''
GOCACHE='/syzkaller/.cache/go-build'
GOCACHEPROG=''
GODEBUG=''
GOENV='/syzkaller/.config/go/env'
GOEXE=''
GOEXPERIMENT=''
GOFIPS140='off'
GOFLAGS=''
GOGCCFLAGS='-fPIC -m64 -pthread -Wl,--no-gc-sections -fmessage-length=0 -ffile-prefix-map=/tmp/go-build1726682488=/tmp/go-build -gno-record-gcc-switches'
GOHOSTARCH='amd64'
GOHOSTOS='linux'
GOINSECURE=''
GOMOD='/syzkaller/jobs/linux/gopath/src/github.com/google/syzkaller/go.mod'
GOMODCACHE='/syzkaller/jobs/linux/gopath/pkg/mod'
GONOPROXY=''
GONOSUMDB=''
GOOS='linux'
GOPATH='/syzkaller/jobs/linux/gopath'
GOPRIVATE=''
GOPROXY='https://proxy.golang.org,direct'
GOROOT='/usr/local/go'
GOSUMDB='sum.golang.org'
GOTELEMETRY='local'
GOTELEMETRYDIR='/syzkaller/.config/go/telemetry'
GOTMPDIR=''
GOTOOLCHAIN='auto'
GOTOOLDIR='/usr/local/go/pkg/tool/linux_amd64'
GOVCS=''
GOVERSION='go1.26.0'
GOWORK=''
PKG_CONFIG='pkg-config'

git status (err=<nil>)
HEAD detached at 680aa3e19b5
nothing to commit, working tree clean


tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
go list -f '{{.Stale}}' -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=680aa3e19b52574eca8bcba3c41aa18235367abe -X github.com/google/syzkaller/prog.gitRevisionDate=20260907-094615"  ./sys/syz-sysgen | grep -q false || go install -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=680aa3e19b52574eca8bcba3c41aa18235367abe -X github.com/google/syzkaller/prog.gitRevisionDate=20260907-094615"  ./sys/syz-sysgen
make .descriptions
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
bin/syz-sysgen
touch .descriptions
GOOS=linux GOARCH=amd64 go build -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=680aa3e19b52574eca8bcba3c41aa18235367abe -X github.com/google/syzkaller/prog.gitRevisionDate=20260907-094615"  -o ./bin/linux_amd64/syz-execprog github.com/google/syzkaller/tools/syz-execprog
mkdir -p ./bin/linux_amd64
g++ -o ./bin/linux_amd64/syz-executor executor/executor.cc \
	-m64 -O2 -pthread -Wall -Werror -Wparentheses -Wunused-const-variable -Wframe-larger-than=16384 -Wno-stringop-overflow -Wno-array-bounds -Wno-format-overflow -Wno-unused-but-set-variable -Wno-unused-command-line-argument -static-pie -std=c++17 -I. -Iexecutor/_include   -DGOOS_linux=1 -DGOARCH_amd64=1 \
	-DHOSTGOOS_linux=1 -DGIT_REVISION=\"680aa3e19b52574eca8bcba3c41aa18235367abe\"
/usr/bin/ld: /tmp/ccLyACCI.o: in function `Connection::Connect(char const*, char const*)':
executor.cc:(.text._ZN10Connection7ConnectEPKcS1_[_ZN10Connection7ConnectEPKcS1_]+0x386): warning: Using 'gethostbyname' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking
./tools/check-syzos.sh 2>/dev/null


Error text is too large and was truncated, full error text is at:
https://syzkaller.appspot.com/x/error.txt?x=16bcf125580000


Tested on:

commit:         796aa054 io_uring/rw: end write accounting from ->ki_c..
git tree:       git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux.git io_uring-7.3
kernel config:  https://syzkaller.appspot.com/x/.config?x=780bb9a5c10069a1
dashboard link: https://syzkaller.appspot.com/bug?extid=2eb3d983669d3e49d4fa
compiler:       Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8

Note: no patches were applied.

^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [syzbot] [io-uring?] [ext4?] INFO: task hung in io_write
  2026-09-09  1:10 ` Jens Axboe
  2026-09-09  1:15   ` Jens Axboe
  2026-09-09  1:35   ` syzbot
@ 2026-09-09 11:02   ` Jens Axboe
  2026-09-09 11:27     ` syzbot
  2026-09-09 11:46   ` Jens Axboe
  3 siblings, 1 reply; 9+ messages in thread
From: Jens Axboe @ 2026-09-09 11:02 UTC (permalink / raw)
  To: syzbot, io-uring, linux-ext4, linux-kernel, syzkaller-bugs

#syz test: git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux.git io_uring-7.3

-- 
Jens Axboe


^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [syzbot] [io-uring?] [ext4?] INFO: task hung in io_write
  2026-09-09 11:02   ` Jens Axboe
@ 2026-09-09 11:27     ` syzbot
  0 siblings, 0 replies; 9+ messages in thread
From: syzbot @ 2026-09-09 11:27 UTC (permalink / raw)
  To: axboe, io-uring, linux-ext4, linux-kernel, syzkaller-bugs

Hello,

syzbot tried to test the proposed patch but the build/boot failed:

[    T1] jffs2: version 2.2. (NAND) (SUMMARY)  © 2001-2006 Red Hat, Inc.
[    9.450006][    T1] romfs: ROMFS MTD (C) 2007 Red Hat, Inc.
[    9.454451][    T1] QNX4 filesystem 0.2.3 registered.
[    9.467839][    T1] qnx6: QNX6 filesystem 1.0.0 registered.
[    9.473957][    T1] fuse: init (API version 7.45)
[    9.493414][  T106] kworker/u4:1 (106) used greatest stack depth: 26960 bytes left
[    9.499661][    T1] orangefs_debugfs_init: called with debug mask: :none: :0:
[    9.517806][    T1] orangefs_init: module version upstream loaded
[    9.523522][    T1] JFS: nTxBlock = 6145, nTxLock = 49167
[    9.549727][    T1] SGI XFS with ACLs, security attributes, realtime, scrub, repair, quota, no debug enabled
[    9.587305][    T1] 9p: Installing v9fs 9p2000 file system support
[    9.598431][    T1] NILFS version 2 loaded
[    9.601604][    T1] befs: version: 0.9.3
[    9.605491][    T1] ocfs2: Registered cluster interface o2cb
[    9.629421][    T1] ocfs2: Registered cluster interface user
[    9.648529][    T1] OCFS2 User DLM kernel interface loaded
[    9.683543][  T115] kworker/u4:2 (115) used greatest stack depth: 26504 bytes left
[    9.711809][    T1] gfs2: GFS2 installed
[    9.750240][    T1] ceph: loaded (mds proto 32)
[    9.783162][    T1] NET: Registered PF_ALG protocol family
[    9.798112][    T1] async_tx: api initialized (async)
[    9.802397][    T1] Key type asymmetric registered
[    9.817841][    T1] Asymmetric key parser 'x509' registered
[    9.822530][    T1] Asymmetric key parser 'pkcs8' registered
[    9.826906][    T1] Key type pkcs7_test registered
[    9.839159][    T1] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 239)
[    9.863479][    T1] io scheduler mq-deadline registered
[    9.867560][    T1] io scheduler kyber registered
[    9.878657][    T1] io scheduler bfq registered
[    9.888919][    T1] raid6: skipped pq benchmark and selected avx512x4
[    9.992971][    T1] ACPI: \_SB_.GSIE: Enabled at IRQ 20
[   10.028066][    T1] pcieport 0000:00:04.0: PME: Signaling with IRQ 25
[   10.059120][    T1] pcieport 0000:00:04.0: AER: enabled with IRQ 26
[   10.082251][    T1] input: Power Button as /devices/platform/LNXPWRBN:00/input/input0
[   10.101416][    T1] ACPI: button: Power Button [PWRF]
[   10.994864][    T1] ioatdma: Intel(R) QuickData Technology Driver 5.00
[   11.099208][    T1] ACPI: \_SB_.GSIF: Enabled at IRQ 21
[   11.203563][    T1] ACPI: \_SB_.GSIH: Enabled at IRQ 23
[   12.461571][    T1] N_HDLC line discipline registered with maxframe=4096
[   12.473979][    T1] Serial: 8250/16550 driver, 4 ports, IRQ sharing enabled
[   12.490839][    T1] 00:03: ttyS0 at I/O 0x3f8 (irq = 4, base_baud = 115200) is a 16550A
[   12.596214][    T1] Non-volatile memory driver v1.3
[   12.619055][    T1] usbcore: registered new interface driver xillyusb
[   12.631909][    T1] ACPI: bus type drm_connector registered
[   12.646781][    T1] [drm] Initialized vgem 1.0.0 for vgem on minor 0
[   12.653751][    T1] usbcore: registered new interface driver udl
[   12.660228][    T1] [drm] pci: virtio-vga detected at 0000:00:01.0
[   12.665091][    T1] virtio-pci 0000:00:01.0: vgaarb: deactivate vga console
[   12.690228][    T1] Console: switching to colour dummy device 80x25
[   12.699414][    T1] [drm] features: -virgl +edid -resource_blob -host_visible
[   12.699488][    T1] [drm] features: -context_init -blob_alignment
[   12.717375][    T1] [drm] number of scanouts: 1
[   12.721344][    T1] [drm] number of cap sets: 0
[   12.728666][    T1] ------------[ cut here ]------------
[   12.732715][    T1] [PLANE:36:plane-1] pixel format with alpha exposed but blend mode not setup
[   12.732728][    T1] WARNING: drivers/gpu/drm/drm_mode_config.c:873 at drm_mode_config_validate+0x1c6a/0x1e60, CPU#0: swapper/0/1
[   12.747874][    T1] Modules linked in:
[   12.750657][    T1] CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT(full) 
[   12.756989][    T1] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[   12.764555][    T1] RIP: 0010:drm_mode_config_validate+0x1cab/0x1e60
[   12.769342][    T1] Code: 0f 85 ae 00 00 00 4d 8d 77 10 8b 6d 00 4c 89 f0 48 c1 e8 03 80 3c 18 00 74 08 4c 89 f7 e8 7d a5 a3 fc 49 8b 16 4c 89 ef 89 ee <67> 48 0f b9 3a eb 05 e8 89 54 32 fc 49 bd 00 00 00 00 00 fc ff df
[   12.783031][    T1] RSP: 0000:ffffc900001af450 EFLAGS: 00010246
[   12.787445][    T1] RAX: 1ffff110000a2808 RBX: dffffc0000000000 RCX: ffff88801ceb0000
[   12.793083][    T1] RDX: ffff88801f5dd780 RSI: 0000000000000024 RDI: ffffffff9085b000
[   12.798984][    T1] RBP: 0000000000000024 R08: ffffffff8ec2b347 R09: 1ffffffff1d85668
[   12.804669][    T1] R10: dffffc0000000000 R11: fffffbfff1d85669 R12: dffffc0000000000
[   12.810525][    T1] R13: ffffffff9085b000 R14: ffff888000514040 R15: ffff888000514030
[   12.816240][    T1] FS:  0000000000000000(0000) GS:ffff88808c2e6000(0000) knlGS:0000000000000000
[   12.822827][    T1] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[   12.827688][    T1] CR2: ffff88801af19000 CR3: 000000000eb46000 CR4: 0000000000352ef0
[   12.833506][    T1] Call Trace:
[   12.835839][    T1]  <TASK>
[   12.838056][    T1]  ? __pfx_autoremove_wake_function+0x10/0x10
[   12.842500][    T1]  drm_dev_register+0x7c/0xd80
[   12.845841][    T1]  virtio_gpu_probe+0x1cb/0x290
[   12.849449][    T1]  virtio_dev_probe+0xdf6/0x10c0
[   12.853176][    T1]  ? up_write+0x19d/0x4a0
[   12.856327][    T1]  ? __pfx_virtio_dev_probe+0x10/0x10
[   12.860356][    T1]  ? driver_sysfs_add+0x1fe/0x210
[   12.864021][    T1]  ? __pfx_virtio_dev_probe+0x10/0x10
[   12.867970][    T1]  really_probe+0x254/0xae0
[   12.871209][    T1]  __driver_probe_device+0x1e8/0x360
[   12.875197][    T1]  driver_probe_device+0x4f/0x240
[   12.878980][    T1]  __driver_attach+0x339/0x600
[   12.882501][    T1]  bus_for_each_dev+0x23b/0x2c0
[   12.886017][    T1]  ? __pfx___driver_attach+0x10/0x10
[   12.889911][    T1]  ? __pfx_bus_for_each_dev+0x10/0x10
[   12.893969][    T1]  ? do_raw_spin_unlock+0x4d/0x200
[   12.897821][    T1]  bus_add_driver+0x345/0x670
[   12.901156][    T1]  driver_register+0x23a/0x320
[   12.904616][    T1]  ? __pfx_virtio_gpu_driver_init+0x10/0x10
[   12.908997][    T1]  virtio_gpu_driver_init+0x96/0x110
[   12.912765][    T1]  do_one_initcall+0x250/0x870
[   12.916048][    T1]  ? __pfx_virtio_gpu_driver_init+0x10/0x10
[   12.920425][    T1]  ? __pfx_do_one_initcall+0x10/0x10
[   12.924224][    T1]  ? lapic_next_event+0x11/0x20
[   12.927996][    T1]  ? clockevents_program_event+0x491/0x630
[   12.932173][    T1]  ? __pfx___schedule+0x10/0x10
[   12.935834][    T1]  ? irqentry_exit+0x218/0x910
[   12.939393][    T1]  ? lockdep_hardirqs_on+0x7b/0x110
[   12.943214][    T1]  ? irqentry_exit+0x218/0x910
[   12.946613][    T1]  ? trace_irq_disable+0x3b/0x140
[   12.950297][    T1]  ? strlen+0x2e/0x70
[   12.953299][    T1]  ? next_arg+0x4a0/0x5e0
[   12.956477][    T1]  ? parameq+0x14d/0x170
[   12.959569][    T1]  ? parse_args+0x9c3/0xad0
[   12.962839][    T1]  ? rcu_is_watching+0x16/0xb0
[   12.966030][    T1]  do_initcall_level+0x10a/0x1a0
[   12.969717][    T1]  ? kernel_init+0x22/0x1d0
[   12.973025][    T1]  do_initcalls+0x59/0xa0
[   12.976142][    T1]  kernel_init_freeable+0x29d/0x3e0
[   12.980086][    T1]  ? __pfx_kernel_init+0x10/0x10
[   12.983647][    T1]  kernel_init+0x22/0x1d0
[   12.986760][    T1]  ? __pfx_kernel_init+0x10/0x10
[   12.990406][    T1]  ret_from_fork+0x514/0xb70
[   12.993692][    T1]  ? __pfx_ret_from_fork+0x10/0x10
[   12.997415][    T1]  ? __switch_to+0xc89/0x1420
[   13.000914][    T1]  ? __pfx_kernel_init+0x10/0x10
[   13.004417][    T1]  ret_from_fork_asm+0x1a/0x30
[   13.007943][    T1]  </TASK>
[   13.010159][    T1] Kernel panic - not syncing: kernel: panic_on_warn set ...
[   13.015418][    T1] CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted syzkaller #0 PREEMPT(full) 
[   13.017889][    T1] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[   13.017889][    T1] Call Trace:
[   13.017889][    T1]  <TASK>
[   13.017889][    T1]  vpanic+0x56d/0xa60
[   13.017889][    T1]  ? __pfx__printk+0x10/0x10
[   13.017889][    T1]  ? __pfx_vpanic+0x10/0x10
[   13.017889][    T1]  ? is_bpf_text_address+0x292/0x2b0
[   13.017889][    T1]  ? is_bpf_text_address+0x26/0x2b0
[   13.017889][    T1]  panic+0xc5/0xd0
[   13.017889][    T1]  ? __pfx_panic+0x10/0x10
[   13.017889][    T1]  ? ret_from_fork_asm+0x1a/0x30
[   13.017889][    T1]  __warn+0x315/0x4c0
[   13.017889][    T1]  ? drm_mode_config_validate+0x1c6a/0x1e60
[   13.017889][    T1]  ? drm_mode_config_validate+0x1c6a/0x1e60
[   13.017889][    T1]  __report_bug+0x276/0x570
[   13.017889][    T1]  ? blocking_notifier_chain_register+0x50/0xc0
[   13.017889][    T1]  ? drm_mode_config_validate+0x1c6a/0x1e60
[   13.017889][    T1]  ? __pfx___report_bug+0x10/0x10
[   13.017889][    T1]  ? blocking_notifier_chain_register+0x6b/0xc0
[   13.017889][    T1]  report_bug_entry+0x19b/0x290
[   13.017889][    T1]  ? drm_mode_config_validate+0x1cab/0x1e60
[   13.017889][    T1]  ? drm_mode_config_validate+0x1cb0/0x1e60
[   13.017889][    T1]  handle_bug+0xce/0x200
[   13.017889][    T1]  exc_invalid_op+0x1a/0x50
[   13.017889][    T1]  asm_exc_invalid_op+0x1a/0x20
[   13.017889][    T1] RIP: 0010:drm_mode_config_validate+0x1cab/0x1e60
[   13.017889][    T1] Code: 0f 85 ae 00 00 00 4d 8d 77 10 8b 6d 00 4c 89 f0 48 c1 e8 03 80 3c 18 00 74 08 4c 89 f7 e8 7d a5 a3 fc 49 8b 16 4c 89 ef 89 ee <67> 48 0f b9 3a eb 05 e8 89 54 32 fc 49 bd 00 00 00 00 00 fc ff df
[   13.017889][    T1] RSP: 0000:ffffc900001af450 EFLAGS: 00010246
[   13.017889][    T1] RAX: 1ffff110000a2808 RBX: dffffc0000000000 RCX: ffff88801ceb0000
[   13.017889][    T1] RDX: ffff88801f5dd780 RSI: 0000000000000024 RDI: ffffffff9085b000
[   13.017889][    T1] RBP: 0000000000000024 R08: ffffffff8ec2b347 R09: 1ffffffff1d85668
[   13.017889][    T1] R10: dffffc0000000000 R11: fffffbfff1d85669 R12: dffffc0000000000
[   13.017889][    T1] R13: ffffffff9085b000 R14: ffff888000514040 R15: ffff888000514030
[   13.017889][    T1]  ? __pfx_autoremove_wake_function+0x10/0x10
[   13.017889][    T1]  drm_dev_register+0x7c/0xd80
[   13.017889][    T1]  virtio_gpu_probe+0x1cb/0x290
[   13.017889][    T1]  virtio_dev_probe+0xdf6/0x10c0
[   13.017889][    T1]  ? up_write+0x19d/0x4a0
[   13.017889][    T1]  ? __pfx_virtio_dev_probe+0x10/0x10
[   13.017889][    T1]  ? driver_sysfs_add+0x1fe/0x210
[   13.017889][    T1]  ? __pfx_virtio_dev_probe+0x10/0x10
[   13.017889][    T1]  really_probe+0x254/0xae0
[   13.017889][    T1]  __driver_probe_device+0x1e8/0x360
[   13.017889][    T1]  driver_probe_device+0x4f/0x240
[   13.017889][    T1]  __driver_attach+0x339/0x600
[   13.017889][    T1]  bus_for_each_dev+0x23b/0x2c0
[   13.017889][    T1]  ? __pfx___driver_attach+0x10/0x10
[   13.017889][    T1]  ? __pfx_bus_for_each_dev+0x10/0x10
[   13.017889][    T1]  ? do_raw_spin_unlock+0x4d/0x200
[   13.017889][    T1]  bus_add_driver+0x345/0x670
[   13.017889][    T1]  driver_register+0x23a/0x320
[   13.017889][    T1]  ? __pfx_virtio_gpu_driver_init+0x10/0x10
[   13.017889][    T1]  virtio_gpu_driver_init+0x96/0x110
[   13.017889][    T1]  do_one_initcall+0x250/0x870
[   13.017889][    T1]  ? __pfx_virtio_gpu_driver_init+0x10/0x10
[   13.017889][    T1]  ? __pfx_do_one_initcall+0x10/0x10
[   13.017889][    T1]  ? lapic_next_event+0x11/0x20
[   13.017889][    T1]  ? clockevents_program_event+0x491/0x630
[   13.017889][    T1]  ? __pfx___schedule+0x10/0x10
[   13.017889][    T1]  ? irqentry_exit+0x218/0x910
[   13.017889][    T1]  ? lockdep_hardirqs_on+0x7b/0x110
[   13.017889][    T1]  ? irqentry_exit+0x218/0x910
[   13.017889][    T1]  ? trace_irq_disable+0x3b/0x140
[   13.017889][    T1]  ? strlen+0x2e/0x70
[   13.017889][    T1]  ? next_arg+0x4a0/0x5e0
[   13.017889][    T1]  ? parameq+0x14d/0x170
[   13.017889][    T1]  ? parse_args+0x9c3/0xad0
[   13.017889][    T1]  ? rcu_is_watching+0x16/0xb0
[   13.017889][    T1]  do_initcall_level+0x10a/0x1a0
[   13.017889][    T1]  ? kernel_init+0x22/0x1d0
[   13.017889][    T1]  do_initcalls+0x59/0xa0
[   13.017889][    T1]  kernel_init_freeable+0x29d/0x3e0
[   13.017889][    T1]  ? __pfx_kernel_init+0x10/0x10
[   13.017889][    T1]  kernel_init+0x22/0x1d0
[   13.017889][    T1]  ? __pfx_kernel_init+0x10/0x10
[   13.017889][    T1]  ret_from_fork+0x514/0xb70
[   13.017889][    T1]  ? __pfx_ret_from_fork+0x10/0x10
[   13.017889][    T1]  ? __switch_to+0xc89/0x1420
[   13.017889][    T1]  ? __pfx_kernel_init+0x10/0x10
[   13.017889][    T1]  ret_from_fork_asm+0x1a/0x30
[   13.017889][    T1]  </TASK>
[   13.017889][    T1] Kernel Offset: disabled
[   13.017889][    T1] Rebooting in 86400 seconds..


syzkaller build log:
go env (err=<nil>)
AR='ar'
CC='gcc'
CGO_CFLAGS='-O2 -g'
CGO_CPPFLAGS=''
CGO_CXXFLAGS='-O2 -g'
CGO_ENABLED='1'
CGO_FFLAGS='-O2 -g'
CGO_LDFLAGS='-O2 -g'
CXX='g++'
GCCGO='gccgo'
GO111MODULE='auto'
GOAMD64='v1'
GOARCH='amd64'
GOAUTH='netrc'
GOBIN=''
GOCACHE='/syzkaller/.cache/go-build'
GOCACHEPROG=''
GODEBUG=''
GOENV='/syzkaller/.config/go/env'
GOEXE=''
GOEXPERIMENT=''
GOFIPS140='off'
GOFLAGS=''
GOGCCFLAGS='-fPIC -m64 -pthread -Wl,--no-gc-sections -fmessage-length=0 -ffile-prefix-map=/tmp/go-build2768744602=/tmp/go-build -gno-record-gcc-switches'
GOHOSTARCH='amd64'
GOHOSTOS='linux'
GOINSECURE=''
GOMOD='/syzkaller/jobs/linux/gopath/src/github.com/google/syzkaller/go.mod'
GOMODCACHE='/syzkaller/jobs/linux/gopath/pkg/mod'
GONOPROXY=''
GONOSUMDB=''
GOOS='linux'
GOPATH='/syzkaller/jobs/linux/gopath'
GOPRIVATE=''
GOPROXY='https://proxy.golang.org,direct'
GOROOT='/usr/local/go'
GOSUMDB='sum.golang.org'
GOTELEMETRY='local'
GOTELEMETRYDIR='/syzkaller/.config/go/telemetry'
GOTMPDIR=''
GOTOOLCHAIN='auto'
GOTOOLDIR='/usr/local/go/pkg/tool/linux_amd64'
GOVCS=''
GOVERSION='go1.26.0'
GOWORK=''
PKG_CONFIG='pkg-config'

git status (err=<nil>)
HEAD detached at 680aa3e19b5
nothing to commit, working tree clean


tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
go list -f '{{.Stale}}' -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=680aa3e19b52574eca8bcba3c41aa18235367abe -X github.com/google/syzkaller/prog.gitRevisionDate=20260907-094615"  ./sys/syz-sysgen | grep -q false || go install -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=680aa3e19b52574eca8bcba3c41aa18235367abe -X github.com/google/syzkaller/prog.gitRevisionDate=20260907-094615"  ./sys/syz-sysgen
make .descriptions
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
bin/syz-sysgen
touch .descriptions
GOOS=linux GOARCH=amd64 go build -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=680aa3e19b52574eca8bcba3c41aa18235367abe -X github.com/google/syzkaller/prog.gitRevisionDate=20260907-094615"  -o ./bin/linux_amd64/syz-execprog github.com/google/syzkaller/tools/syz-execprog
mkdir -p ./bin/linux_amd64
g++ -o ./bin/linux_amd64/syz-executor executor/executor.cc \
	-m64 -O2 -pthread -Wall -Werror -Wparentheses -Wunused-const-variable -Wframe-larger-than=16384 -Wno-stringop-overflow -Wno-array-bounds -Wno-format-overflow -Wno-unused-but-set-variable -Wno-unused-command-line-argument -static-pie -std=c++17 -I. -Iexecutor/_include   -DGOOS_linux=1 -DGOARCH_amd64=1 \
	-DHOSTGOOS_linux=1 -DGIT_REVISION=\"680aa3e19b52574eca8bcba3c41aa18235367abe\"
/usr/bin/ld: /tmp/ccdJQzUC.o: in function `Connection::Connect(char const*, char const*)':
executor.cc:(.text._ZN10Connection7ConnectEPKcS1_[_ZN10Connection7ConnectEPKcS1_]+0x386): warning: Using 'gethostbyname' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking
./tools/check-syzos.sh 2>/dev/null


Error text is too large and was truncated, full error text is at:
https://syzkaller.appspot.com/x/error.txt?x=164baa15580000


Tested on:

commit:         796aa054 io_uring/rw: end write accounting from ->ki_c..
git tree:       git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux.git io_uring-7.3
kernel config:  https://syzkaller.appspot.com/x/.config?x=780bb9a5c10069a1
dashboard link: https://syzkaller.appspot.com/bug?extid=2eb3d983669d3e49d4fa
compiler:       Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8

Note: no patches were applied.

^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [syzbot] [io-uring?] [ext4?] INFO: task hung in io_write
  2026-09-09  1:10 ` Jens Axboe
                     ` (2 preceding siblings ...)
  2026-09-09 11:02   ` Jens Axboe
@ 2026-09-09 11:46   ` Jens Axboe
  2026-09-09 12:13     ` syzbot
  3 siblings, 1 reply; 9+ messages in thread
From: Jens Axboe @ 2026-09-09 11:46 UTC (permalink / raw)
  To: syzbot, io-uring, linux-ext4, linux-kernel, syzkaller-bugs

#syz test: git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux.git syztest

Let's try on a new base, perhaps it's a mainline issue keeping syzbot from
booting.

-- 
Jens Axboe


^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [syzbot] [io-uring?] [ext4?] INFO: task hung in io_write
  2026-09-09 11:46   ` Jens Axboe
@ 2026-09-09 12:13     ` syzbot
  0 siblings, 0 replies; 9+ messages in thread
From: syzbot @ 2026-09-09 12:13 UTC (permalink / raw)
  To: axboe, io-uring, linux-ext4, linux-kernel, syzkaller-bugs

Hello,

syzbot has tested the proposed patch and the reproducer did not trigger any issue:

Reported-by: syzbot+2eb3d983669d3e49d4fa@syzkaller.appspotmail.com
Tested-by: syzbot+2eb3d983669d3e49d4fa@syzkaller.appspotmail.com

Tested on:

commit:         57ab5080 io_uring/io-wq: don't trigger hung task for s..
git tree:       git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux.git syztest
console output: https://syzkaller.appspot.com/x/log.txt?x=127b7af9580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=679ea3cb74b430f3
dashboard link: https://syzkaller.appspot.com/bug?extid=2eb3d983669d3e49d4fa
compiler:       Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8

Note: no patches were applied.
Note: testing is done by a robot and is best-effort only.

^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2026-09-09 12:13 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-08 22:08 [syzbot] [io-uring?] [ext4?] INFO: task hung in io_write syzbot
2026-09-09  1:10 ` Jens Axboe
2026-09-09  1:15   ` Jens Axboe
2026-09-09  1:58     ` syzbot
2026-09-09  1:35   ` syzbot
2026-09-09 11:02   ` Jens Axboe
2026-09-09 11:27     ` syzbot
2026-09-09 11:46   ` Jens Axboe
2026-09-09 12:13     ` syzbot

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox