Forwarded: Re: [syzbot] [kernel?] INFO: task hung in nsim_bus_dev_del

From: syzbot

Date: Mon May 18 2026 - 02:58:21 EST


For archival purposes, forwarding an incoming command email to
linux-kernel@xxxxxxxxxxxxxxx, syzkaller-bugs@xxxxxxxxxxxxxxxx.

***

Subject: Re: [syzbot] [kernel?] INFO: task hung in nsim_bus_dev_del
Author: yun.zhou@xxxxxxxxxxxxx

#syz test

On 5/16/26 08:11, syzbot wrote:
> CAUTION: This email comes from a non Wind River email account!
> Do not click links or open attachments unless you recognize the sender and know the content is safe.
>
> Hello,
>
> syzbot found the following issue on:
>
> HEAD commit: 5cbb61bf4168 arm64/fpsimd: ptrace: zero target's fpsimd_st..
> git tree: git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git for-kernelci
> console output: https://syzkaller.appspot.com/x/log.txt?x=165db76c580000
> kernel config: https://syzkaller.appspot.com/x/.config?x=a834c6344141a58b
> dashboard link: https://syzkaller.appspot.com/bug?extid=1cf303af03cf30b1275a
> compiler: Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8
> userspace arch: arm64
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=12c4d56a580000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=115db76c580000
>
> Downloadable assets:
> disk image: https://storage.googleapis.com/syzbot-assets/04156ec16593/disk-5cbb61bf.raw.xz
> vmlinux: https://storage.googleapis.com/syzbot-assets/6bfa041e2c79/vmlinux-5cbb61bf.xz
> kernel image: https://storage.googleapis.com/syzbot-assets/a92d82d8a79e/Image-5cbb61bf.gz.xz
>
> IMPORTANT: if you fix the issue, please add the following tag to the commit:
> Reported-by: syzbot+1cf303af03cf30b1275a@xxxxxxxxxxxxxxxxxxxxxxxxx
>
> INFO: task syz-executor:4797 blocked for more than 143 seconds.
> Not tainted syzkaller #0
> "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
> task:syz-executor state:D stack:0 pid:4797 tgid:4797 ppid:4796 task_flags:0x400140 flags:0x00800000
> Call trace:
> __switch_to+0x2b0/0x6e0 arch/arm64/kernel/process.c:810 (T)
> context_switch kernel/sched/core.c:5387 [inline]
> __schedule+0x1b74/0x2d24 kernel/sched/core.c:7188
> __schedule_loop kernel/sched/core.c:7267 [inline]
> schedule+0xa4/0x140 kernel/sched/core.c:7282
> schedule_preempt_disabled+0x18/0x2c kernel/sched/core.c:7339
> __mutex_lock_common+0x98c/0x20f4 kernel/locking/mutex.c:726
> __mutex_lock kernel/locking/mutex.c:820 [inline]
> mutex_lock_nested+0x2c/0x38 kernel/locking/mutex.c:873
> device_lock include/linux/device.h:1040 [inline]
> device_del+0xa0/0x710 drivers/base/core.c:3857
> device_unregister+0x2c/0xf0 drivers/base/core.c:3936
> nsim_bus_dev_del+0x60/0x88 drivers/net/netdevsim/bus.c:491
> del_device_store+0x248/0x2d0 drivers/net/netdevsim/bus.c:244
> bus_attr_store+0x80/0xa4 drivers/base/bus.c:172
> sysfs_kf_write+0xe0/0x108 fs/sysfs/file.c:142
> kernfs_fop_write_iter+0x264/0x3c0 fs/kernfs/file.c:352
> new_sync_write fs/read_write.c:595 [inline]
> vfs_write+0x52c/0xa14 fs/read_write.c:688
> ksys_write+0x12c/0x224 fs/read_write.c:740
> __do_sys_write fs/read_write.c:751 [inline]
> __se_sys_write fs/read_write.c:748 [inline]
> __arm64_sys_write+0x7c/0x90 fs/read_write.c:748
> __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]
> invoke_syscall+0x98/0x244 arch/arm64/kernel/syscall.c:49
> el0_svc_common+0xe8/0x23c arch/arm64/kernel/syscall.c:121
> do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:140
> el0_svc+0x60/0x25c arch/arm64/kernel/entry-common.c:723
> el0t_64_sync_handler+0x48/0x148 arch/arm64/kernel/entry-common.c:742
> el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:594
> INFO: task syz-executor:4805 blocked for more than 143 seconds.
> Not tainted syzkaller #0
> "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
> task:syz-executor state:D stack:0 pid:4805 tgid:4805 ppid:4801 task_flags:0x400140 flags:0x00800000
> Call trace:
> __switch_to+0x2b0/0x6e0 arch/arm64/kernel/process.c:810 (T)
> context_switch kernel/sched/core.c:5387 [inline]
> __schedule+0x1b74/0x2d24 kernel/sched/core.c:7188
> __schedule_loop kernel/sched/core.c:7267 [inline]
> schedule+0xa4/0x140 kernel/sched/core.c:7282
> schedule_preempt_disabled+0x18/0x2c kernel/sched/core.c:7339
> __mutex_lock_common+0x98c/0x20f4 kernel/locking/mutex.c:726
> __mutex_lock kernel/locking/mutex.c:820 [inline]
> mutex_lock_nested+0x2c/0x38 kernel/locking/mutex.c:873
> del_device_store+0xd8/0x2d0 drivers/net/netdevsim/bus.c:234
> bus_attr_store+0x80/0xa4 drivers/base/bus.c:172
> sysfs_kf_write+0xe0/0x108 fs/sysfs/file.c:142
> kernfs_fop_write_iter+0x264/0x3c0 fs/kernfs/file.c:352
> new_sync_write fs/read_write.c:595 [inline]
> vfs_write+0x52c/0xa14 fs/read_write.c:688
> ksys_write+0x12c/0x224 fs/read_write.c:740
> __do_sys_write fs/read_write.c:751 [inline]
> __se_sys_write fs/read_write.c:748 [inline]
> __arm64_sys_write+0x7c/0x90 fs/read_write.c:748
> __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]
> invoke_syscall+0x98/0x244 arch/arm64/kernel/syscall.c:49
> el0_svc_common+0xe8/0x23c arch/arm64/kernel/syscall.c:121
> do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:140
> el0_svc+0x60/0x25c arch/arm64/kernel/entry-common.c:723
> el0t_64_sync_handler+0x48/0x148 arch/arm64/kernel/entry-common.c:742
> el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:594
> INFO: task syz-executor:4809 blocked for more than 143 seconds.
> Not tainted syzkaller #0
> "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
> task:syz-executor state:D stack:0 pid:4809 tgid:4809 ppid:1 task_flags:0x400140 flags:0x00800001
> Call trace:
> __switch_to+0x2b0/0x6e0 arch/arm64/kernel/process.c:810 (T)
> context_switch kernel/sched/core.c:5387 [inline]
> __schedule+0x1b74/0x2d24 kernel/sched/core.c:7188
> __schedule_loop kernel/sched/core.c:7267 [inline]
> schedule+0xa4/0x140 kernel/sched/core.c:7282
> schedule_preempt_disabled+0x18/0x2c kernel/sched/core.c:7339
> __mutex_lock_common+0x98c/0x20f4 kernel/locking/mutex.c:726
> __mutex_lock kernel/locking/mutex.c:820 [inline]
> mutex_lock_nested+0x2c/0x38 kernel/locking/mutex.c:873
> del_device_store+0xd8/0x2d0 drivers/net/netdevsim/bus.c:234
> bus_attr_store+0x80/0xa4 drivers/base/bus.c:172
> sysfs_kf_write+0xe0/0x108 fs/sysfs/file.c:142
> kernfs_fop_write_iter+0x264/0x3c0 fs/kernfs/file.c:352
> new_sync_write fs/read_write.c:595 [inline]
> vfs_write+0x52c/0xa14 fs/read_write.c:688
> ksys_write+0x12c/0x224 fs/read_write.c:740
> __do_sys_write fs/read_write.c:751 [inline]
> __se_sys_write fs/read_write.c:748 [inline]
> __arm64_sys_write+0x7c/0x90 fs/read_write.c:748
> __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]
> invoke_syscall+0x98/0x244 arch/arm64/kernel/syscall.c:49
> el0_svc_common+0xe8/0x23c arch/arm64/kernel/syscall.c:121
> do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:140
> el0_svc+0x60/0x25c arch/arm64/kernel/entry-common.c:723
> el0t_64_sync_handler+0x48/0x148 arch/arm64/kernel/entry-common.c:742
> el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:594
> INFO: task syz-executor:4812 blocked for more than 143 seconds.
> Not tainted syzkaller #0
> "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
> task:syz-executor state:D stack:0 pid:4812 tgid:4812 ppid:1 task_flags:0x400140 flags:0x00800001
> Call trace:
> __switch_to+0x2b0/0x6e0 arch/arm64/kernel/process.c:810 (T)
> context_switch kernel/sched/core.c:5387 [inline]
> __schedule+0x1b74/0x2d24 kernel/sched/core.c:7188
> __schedule_loop kernel/sched/core.c:7267 [inline]
> schedule+0xa4/0x140 kernel/sched/core.c:7282
> schedule_preempt_disabled+0x18/0x2c kernel/sched/core.c:7339
> __mutex_lock_common+0x98c/0x20f4 kernel/locking/mutex.c:726
> __mutex_lock kernel/locking/mutex.c:820 [inline]
> mutex_lock_nested+0x2c/0x38 kernel/locking/mutex.c:873
> del_device_store+0xd8/0x2d0 drivers/net/netdevsim/bus.c:234
> bus_attr_store+0x80/0xa4 drivers/base/bus.c:172
> sysfs_kf_write+0xe0/0x108 fs/sysfs/file.c:142
> kernfs_fop_write_iter+0x264/0x3c0 fs/kernfs/file.c:352
> new_sync_write fs/read_write.c:595 [inline]
> vfs_write+0x52c/0xa14 fs/read_write.c:688
> ksys_write+0x12c/0x224 fs/read_write.c:740
> __do_sys_write fs/read_write.c:751 [inline]
> __se_sys_write fs/read_write.c:748 [inline]
> __arm64_sys_write+0x7c/0x90 fs/read_write.c:748
> __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]
> invoke_syscall+0x98/0x244 arch/arm64/kernel/syscall.c:49
> el0_svc_common+0xe8/0x23c arch/arm64/kernel/syscall.c:121
> do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:140
> el0_svc+0x60/0x25c arch/arm64/kernel/entry-common.c:723
> el0t_64_sync_handler+0x48/0x148 arch/arm64/kernel/entry-common.c:742
> el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:594
>
> Showing all locks held in the system:
> 3 locks held by kworker/u8:0/12:
> 1 lock held by khungtaskd/31:
> #0: ffff800088ac66e0 (rcu_read_lock){....}-{1:3}, at: __ll_sc_atomic64_fetch_or arch/arm64/include/asm/atomic_ll_sc.h:-1 [inline]
> #0: ffff800088ac66e0 (rcu_read_lock){....}-{1:3}, at: arch_atomic64_fetch_or arch/arm64/include/asm/atomic.h:86 [inline]
> #0: ffff800088ac66e0 (rcu_read_lock){....}-{1:3}, at: raw_atomic64_fetch_or include/linux/atomic/atomic-arch-fallback.h:3816 [inline]
> #0: ffff800088ac66e0 (rcu_read_lock){....}-{1:3}, at: raw_atomic_long_fetch_or include/linux/atomic/atomic-long.h:1090 [inline]
> #0: ffff800088ac66e0 (rcu_read_lock){....}-{1:3}, at: arch_test_and_set_bit include/asm-generic/bitops/atomic.h:42 [inline]
> #0: ffff800088ac66e0 (rcu_read_lock){....}-{1:3}, at: test_and_set_bit include/asm-generic/bitops/instrumented-atomic.h:72 [inline]
> #0: ffff800088ac66e0 (rcu_read_lock){....}-{1:3}, at: rcu_lock_acquire+0x0/0x44 kernel/sched/sched.h:3869
> 8 locks held by kworker/u8:3/40:
> 4 locks held by pr/ttyAMA-1/41:
> 3 locks held by kworker/u8:5/1188:
> 3 locks held by kworker/u8:6/1389:
> 3 locks held by kworker/u8:7/1910:
> 1 lock held by klogd/4292:
> 3 locks held by udevd/4303:
> 3 locks held by dhcpcd/4359:
> 2 locks held by getty/4451:
> #0: ffff0000d3bfb0a0 (&tty->ldisc_sem){++++}-{0:0}, at: ldsem_down_read+0x3c/0x4c drivers/tty/tty_ldsem.c:340
> #1: ffff80009228b2e8 (&ldata->atomic_read_lock){+.+.}-{4:4}, at: n_tty_read+0x354/0xf84 drivers/tty/n_tty.c:2211
> 3 locks held by kworker/1:3/4670:
> #0: ffff0000c002b540 ((wq_completion)events){+.+.}-{0:0}, at: process_one_work+0x640/0x173c kernel/workqueue.c:3276
> #1: ffff8000966d7be0 (reg_work){+.+.}-{0:0}, at: process_one_work+0x6a4/0x173c kernel/workqueue.c:3276
> #2: ffff800089b85900 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_lock+0x20/0x2c net/core/rtnetlink.c:80
> 5 locks held by syz-executor/4797:
> #0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: file_start_write include/linux/fs.h:2724 [inline]
> #0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: vfs_write+0x240/0xa14 fs/read_write.c:684
> #1: ffff0000e8fb8880 (&of->mutex){+.+.}-{4:4}, at: kernfs_fop_write_iter+0x1b4/0x3c0 fs/kernfs/file.c:343
> #2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_get_active_of fs/kernfs/file.c:80 [inline]
> #2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_fop_write_iter+0x1f4/0x3c0 fs/kernfs/file.c:344
> #3: ffff800089383240 (nsim_bus_dev_list_lock){+.+.}-{4:4}, at: del_device_store+0xd8/0x2d0 drivers/net/netdevsim/bus.c:234
> #4: ffff0000d7b8a128 (&dev->mutex){....}-{4:4}, at: device_lock include/linux/device.h:1040 [inline]
> #4: ffff0000d7b8a128 (&dev->mutex){....}-{4:4}, at: device_del+0xa0/0x710 drivers/base/core.c:3857
> 4 locks held by syz-executor/4805:
> #0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: file_start_write include/linux/fs.h:2724 [inline]
> #0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: vfs_write+0x240/0xa14 fs/read_write.c:684
> #1: ffff0000eca42080 (&of->mutex){+.+.}-{4:4}, at: kernfs_fop_write_iter+0x1b4/0x3c0 fs/kernfs/file.c:343
> #2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_get_active_of fs/kernfs/file.c:80 [inline]
> #2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_fop_write_iter+0x1f4/0x3c0 fs/kernfs/file.c:344
> #3: ffff800089383240 (nsim_bus_dev_list_lock){+.+.}-{4:4}, at: del_device_store+0xd8/0x2d0 drivers/net/netdevsim/bus.c:234
> 4 locks held by syz-executor/4809:
> #0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: file_start_write include/linux/fs.h:2724 [inline]
> #0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: vfs_write+0x240/0xa14 fs/read_write.c:684
> #1: ffff0000eca0f880 (&of->mutex){+.+.}-{4:4}, at: kernfs_fop_write_iter+0x1b4/0x3c0 fs/kernfs/file.c:343
> #2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_get_active_of fs/kernfs/file.c:80 [inline]
> #2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_fop_write_iter+0x1f4/0x3c0 fs/kernfs/file.c:344
> #3: ffff800089383240 (nsim_bus_dev_list_lock){+.+.}-{4:4}, at: del_device_store+0xd8/0x2d0 drivers/net/netdevsim/bus.c:234
> 4 locks held by syz-executor/4812:
> #0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: file_start_write include/linux/fs.h:2724 [inline]
> #0: ffff0000d3e0c410 (sb_writers#6){.+.+}-{0:0}, at: vfs_write+0x240/0xa14 fs/read_write.c:684
> #1: ffff0000cd063c80 (&of->mutex){+.+.}-{4:4}, at: kernfs_fop_write_iter+0x1b4/0x3c0 fs/kernfs/file.c:343
> #2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_get_active_of fs/kernfs/file.c:80 [inline]
> #2: ffff0000c922fd28 (kn->active#55){.+.+}-{0:0}, at: kernfs_fop_write_iter+0x1f4/0x3c0 fs/kernfs/file.c:344
> #3: ffff800089383240 (nsim_bus_dev_list_lock){+.+.}-{4:4}, at: del_device_store+0xd8/0x2d0 drivers/net/netdevsim/bus.c:234
> 3 locks held by kworker/u8:11/4904:
> #0: ffff0000ce706140 ((wq_completion)ipv6_addrconf){+.+.}-{0:0}, at: process_one_work+0x640/0x173c kernel/workqueue.c:3276
> #1: ffff8000995f7be0 ((work_completion)(&(&ifa->dad_work)->work)){+.+.}-{0:0}, at: process_one_work+0x6a4/0x173c kernel/workqueue.c:3276
> #2: ffff800089b85900 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_lock+0x20/0x2c net/core/rtnetlink.c:80
> 2 locks held by kworker/u8:12/4906:
> 2 locks held by kworker/u8:13/4908:
> 2 locks held by syz-executor/4913:
> 2 locks held by syz-executor/4914:
>
> =============================================
>
>
>
> ---
> This report is generated by a bot. It may contain errors.
> See https://goo.gl/tpsmEJ for more information about syzbot.
> syzbot engineers can be reached at syzkaller@xxxxxxxxxxxxxxxx.
>
> syzbot will keep track of this issue. See:
> https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
>
> If the report is already addressed, let syzbot know by replying with:
> #syz fix: exact-commit-title
>
> If you want syzbot to run the reproducer, reply with:
> #syz test: git://repo/address.git branch-or-commit-hash
> If you attach or paste a git patch, syzbot will apply it before testing.
>
> If you want to overwrite report's subsystems, reply with:
> #syz set subsystems: new-subsystem
> (See the list of subsystem names on the web dashboard)
>
> If the report is a duplicate of another one, reply with:
> #syz dup: exact-subject-of-another-report
>
> If you want to undo deduplication, reply with:
> #syz undup
>
> --
> You received this message because you are subscribed to the Google Groups "syzkaller-bugs" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to syzkaller-bugs+unsubscribe@xxxxxxxxxxxxxxxx.
> To view this discussion visit https://groups.google.com/d/msgid/syzkaller-bugs/6a07b635.170a0220.df43.0000.GAE%40google.com.