Public bug reported:

An Ubuntu 26.04.1 LTS VM on Hyper-V repeatedly oopses in path_is_under(), 
called from
complete_walk() during openat(). The faulting address is a different garbage 
value each time:
either fffffffffffffff0 or a non-canonical pointer. That suggests a corrupted 
or freed struct mount
being walked through mnt_parent. With panic_on_oops=0 the task dies holding a 
lock, every
later bubblewrap (bwrap) process soft-locks in create_user_ns -> alloc_ucounts /
current_chrooted -> _raw_spin_lock, and the system wedges. With panic_on_oops=1 
it panics and
reboots.

Reproduced on three kernel builds within ~28 hours:
  - 7.0.0-34-generic: 3 oopses (Comm: MainThread x2, depmod)
  - 7.0.0-38-generic: 1 oops (Comm: MainThread)
  - 7.0.0-1017-azure (7.0.14 base): 1 oops (Comm: git)

== Environment ==
- Ubuntu 26.04.1 LTS (resolute), cloud image 
(ubuntu-26.04-server-cloudimg-amd64.img)
- Hyper-V Gen 2 VM on Windows 11 Pro 26200, Secure Boot (MS UEFI CA), 8 vCPU, 8 
GB static RAM
  (Dynamic Memory was enabled for the first incident; disabled since), 8 GB 
swapfile, ext4 root
- Host CPU: Intel Core i9-14900K
- kernel.apparmor_restrict_unprivileged_userns=1 (default)

== Trace (7.0.0-1017-azure, representative) ==
Oops: general protection fault, probably for non-canonical address 
0xaa72f400ffffffef: 0000 [#1] SMP NOPTI
CPU: 0 UID: 1000 PID: 45217 Comm: git Not tainted 7.0.0-1017-azure #17-Ubuntu 
PREEMPTLAZY
Hardware name: Microsoft Corporation Virtual Machine/Virtual Machine, BIOS 
Hyper-V UEFI Release v4.1 09/25/2025
RIP: 0010:path_is_under+0x60/0xa0
Call Trace:
 complete_walk+0x9c/0xc0
 do_open+0x1b3/0x400
 path_openat+0x113/0x290
 do_file_open+0xdf/0x1a0
 do_sys_openat2+0x7a/0xe0
 __x64_sys_openat+0x5f/0xa0
 do_syscall_64+0x105/0x5a0
 entry_SYSCALL_64_after_hwframe+0x76/0x7e
Kernel panic - not syncing: Fatal exception

On -generic the first oops was "BUG: unable to handle page fault for address: 
fffffffffffffff0"
at path_is_under+0x50/0x90 with the same call chain.

== Workload / when it happens ==
- The VM ran cleanly for ~24h, then oopsed repeatedly once it was used as a 
development box:
  Claude Code (Node/Bun), git, pnpm, Chrome under XFCE/xrdp, and Tailscale.
- Faulting tasks are ordinary file opens by unprivileged processes (MainThread 
= Claude Code's
  main thread, git) and root (depmod during a kernel package postinst).
- Intervals between oopses ranged from ~1 minute to ~2 hours of uptime.

== Ruled out ==
- Filesystem: a forced e2fsck of root was clean apart from an "extent tree 
could be narrower"
  optimisation note.
- Memory pressure: it reproduces with static RAM and >5 GB free; no OOM events.
- Host problems: no host errors, and a WSL2 guest on the same host is 
unaffected.

== Possibly related ==
The first incident followed Hyper-V Dynamic Memory hot-add failures 6 minutes 
earlier:
"40-vm-hotadd.rules: Failed to write 'online'" and "workqueue: hot_add_req 
[hv_balloon] hogged
CPU". Dynamic Memory has been off since, and the oopses continue.

== Attachments ==
- oops-all-6-crashes.txt: full oops texts from systemd-pstore (efi_pstore) for 
every incident
- hyperv-guest-crash-events.txt: Hyper-V Worker event 18590, which includes the 
guest's final kmsg
- system-info.txt: version_signature, uname, installed kernels, cmdline, 
CPU/memory, userns settings

** Affects: linux (Ubuntu)
     Importance: Undecided
         Status: New

** Affects: linux-azure (Ubuntu)
     Importance: Undecided
         Status: New

** Attachment added: "oops-all-6-crashes.txt"
   
https://bugs.launchpad.net/bugs/2169338/+attachment/6005046/+files/oops-all-6-crashes.txt

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2169338

Title:
  Kernel oops / GPF in path_is_under() from complete_walk() on openat
  — 7.0.0-34/-38-generic and 7.0.0-1017-azure, Hyper-V Gen2 guest

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2169338/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to