Public bug reported:

Since linux 7.0.0-31 (and still in 7.0.0-34) the machine hard-freezes
within ~10-25 minutes of normal desktop use. 7.0.0-29 and 7.0.0-30 are
unaffected; 7.0.0-15 had the same bug.

Sequence, identical every time:
1. Oops (GPF on non-canonical address, or page fault at fffffffffffffff0) at 
path_is_under+0x50/0x90, reached from a plain newfstatat():
   path_is_under <- complete_walk <- path_lookupat <- filename_lookup <- 
vfs_statx <- vfs_fstatat <- __do_sys_newfstatat
   Triggering task is a GLib worker thread (Comm: pool-2 / localsearch-3, the 
GNOME file indexer).
2. The task dies inside the read_seqlock_excl(&mount_lock) critical section 
("exited with preempt_count 1" / "exited with irqs disabled"), so mount_lock is 
never released.
3. Every later task that touches mounts spins in 
native_queued_spin_lock_slowpath: soft lockups on systemd, chrome, bwrap, runc 
(mntput_no_expire_slowpath, drm_release), then RCU stalls, then total freeze.

Boot history on this machine (same NVIDIA 595.71.05 DKMS driver throughout):
  7.0.0-15: 5 of 8 boots froze
  7.0.0-29 / -30: 26 boots, 0 faults (18 with the indexer running)
  7.0.0-31: 2 of 3 boots froze
  7.0.0-34: froze 22 min after re-enabling localsearch-3

Reproduce: boot 7.0.0-34 with localsearch-3 enabled and use the desktop
normally (browser, Docker/bwrap sandboxes); freeze within ~25 min.
Masking localsearch-3 avoids it.

The full kernel log from the crashed boot is attached to the report as
CrashBootKernelLog.

Hardware: ASUS ROG STRIX Z690-I, BIOS 4505. Ubuntu 26.04.

** Affects: linux (Ubuntu)
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2168783

Title:
  Regression in 7.0.0-31/-34: GPF in path_is_under() leaks mount_lock,
  system hard-freezes

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2168783/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to