Public bug reported:
An Ubuntu 26.04.1 LTS VM on Hyper-V repeatedly oopses in path_is_under(),
called from
complete_walk() during openat(). The faulting address is a different garbage
value each time:
either fffffffffffffff0 or a non-canonical pointer. That suggests a corrupted
or freed struct mount
being walked through mnt_parent. With panic_on_oops=0 the task dies holding a
lock, every
later bubblewrap (bwrap) process soft-locks in create_user_ns -> alloc_ucounts /
current_chrooted -> _raw_spin_lock, and the system wedges. With panic_on_oops=1
it panics and
reboots.
Reproduced on three kernel builds within ~28 hours:
- 7.0.0-34-generic: 3 oopses (Comm: MainThread x2, depmod)
- 7.0.0-38-generic: 1 oops (Comm: MainThread)
- 7.0.0-1017-azure (7.0.14 base): 1 oops (Comm: git)
== Environment ==
- Ubuntu 26.04.1 LTS (resolute), cloud image
(ubuntu-26.04-server-cloudimg-amd64.img)
- Hyper-V Gen 2 VM on Windows 11 Pro 26200, Secure Boot (MS UEFI CA), 8 vCPU, 8
GB static RAM
(Dynamic Memory was enabled for the first incident; disabled since), 8 GB
swapfile, ext4 root
- Host CPU: Intel Core i9-14900K
- kernel.apparmor_restrict_unprivileged_userns=1 (default)
== Trace (7.0.0-1017-azure, representative) ==
Oops: general protection fault, probably for non-canonical address
0xaa72f400ffffffef: 0000 [#1] SMP NOPTI
CPU: 0 UID: 1000 PID: 45217 Comm: git Not tainted 7.0.0-1017-azure #17-Ubuntu
PREEMPTLAZY
Hardware name: Microsoft Corporation Virtual Machine/Virtual Machine, BIOS
Hyper-V UEFI Release v4.1 09/25/2025
RIP: 0010:path_is_under+0x60/0xa0
Call Trace:
complete_walk+0x9c/0xc0
do_open+0x1b3/0x400
path_openat+0x113/0x290
do_file_open+0xdf/0x1a0
do_sys_openat2+0x7a/0xe0
__x64_sys_openat+0x5f/0xa0
do_syscall_64+0x105/0x5a0
entry_SYSCALL_64_after_hwframe+0x76/0x7e
Kernel panic - not syncing: Fatal exception
On -generic the first oops was "BUG: unable to handle page fault for address:
fffffffffffffff0"
at path_is_under+0x50/0x90 with the same call chain.
== Workload / when it happens ==
- The VM ran cleanly for ~24h, then oopsed repeatedly once it was used as a
development box:
Claude Code (Node/Bun), git, pnpm, Chrome under XFCE/xrdp, and Tailscale.
- Faulting tasks are ordinary file opens by unprivileged processes (MainThread
= Claude Code's
main thread, git) and root (depmod during a kernel package postinst).
- Intervals between oopses ranged from ~1 minute to ~2 hours of uptime.
== Ruled out ==
- Filesystem: a forced e2fsck of root was clean apart from an "extent tree
could be narrower"
optimisation note.
- Memory pressure: it reproduces with static RAM and >5 GB free; no OOM events.
- Host problems: no host errors, and a WSL2 guest on the same host is
unaffected.
== Possibly related ==
The first incident followed Hyper-V Dynamic Memory hot-add failures 6 minutes
earlier:
"40-vm-hotadd.rules: Failed to write 'online'" and "workqueue: hot_add_req
[hv_balloon] hogged
CPU". Dynamic Memory has been off since, and the oopses continue.
== Attachments ==
- oops-all-6-crashes.txt: full oops texts from systemd-pstore (efi_pstore) for
every incident
- hyperv-guest-crash-events.txt: Hyper-V Worker event 18590, which includes the
guest's final kmsg
- system-info.txt: version_signature, uname, installed kernels, cmdline,
CPU/memory, userns settings
** Affects: linux (Ubuntu)
Importance: Undecided
Status: New
** Affects: linux-azure (Ubuntu)
Importance: Undecided
Status: New
** Attachment added: "oops-all-6-crashes.txt"
https://bugs.launchpad.net/bugs/2169338/+attachment/6005046/+files/oops-all-6-crashes.txt
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2169338
Title:
Kernel oops / GPF in path_is_under() from complete_walk() on openat
— 7.0.0-34/-38-generic and 7.0.0-1017-azure, Hyper-V Gen2 guest
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2169338/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs