apport information

** Tags added: apport-collected cloud-image resolute

** Description changed:

  An Ubuntu 26.04.1 LTS VM on Hyper-V repeatedly oopses in path_is_under(), 
called from
  complete_walk() during openat(). The faulting address is a different garbage 
value each time:
  either fffffffffffffff0 or a non-canonical pointer. That suggests a corrupted 
or freed struct mount
  being walked through mnt_parent. With panic_on_oops=0 the task dies holding a 
lock, every
  later bubblewrap (bwrap) process soft-locks in create_user_ns -> 
alloc_ucounts /
  current_chrooted -> _raw_spin_lock, and the system wedges. With 
panic_on_oops=1 it panics and
  reboots.
  
  Reproduced on three kernel builds within ~28 hours:
    - 7.0.0-34-generic: 3 oopses (Comm: MainThread x2, depmod)
    - 7.0.0-38-generic: 1 oops (Comm: MainThread)
    - 7.0.0-1017-azure (7.0.14 base): 1 oops (Comm: git)
  
  == Environment ==
  - Ubuntu 26.04.1 LTS (resolute), cloud image 
(ubuntu-26.04-server-cloudimg-amd64.img)
  - Hyper-V Gen 2 VM on Windows 11 Pro 26200, Secure Boot (MS UEFI CA), 8 vCPU, 
8 GB static RAM
    (Dynamic Memory was enabled for the first incident; disabled since), 8 GB 
swapfile, ext4 root
  - Host CPU: Intel Core i9-14900K
  - kernel.apparmor_restrict_unprivileged_userns=1 (default)
  
  == Trace (7.0.0-1017-azure, representative) ==
  Oops: general protection fault, probably for non-canonical address 
0xaa72f400ffffffef: 0000 [#1] SMP NOPTI
  CPU: 0 UID: 1000 PID: 45217 Comm: git Not tainted 7.0.0-1017-azure #17-Ubuntu 
PREEMPTLAZY
  Hardware name: Microsoft Corporation Virtual Machine/Virtual Machine, BIOS 
Hyper-V UEFI Release v4.1 09/25/2025
  RIP: 0010:path_is_under+0x60/0xa0
  Call Trace:
   complete_walk+0x9c/0xc0
   do_open+0x1b3/0x400
   path_openat+0x113/0x290
   do_file_open+0xdf/0x1a0
   do_sys_openat2+0x7a/0xe0
   __x64_sys_openat+0x5f/0xa0
   do_syscall_64+0x105/0x5a0
   entry_SYSCALL_64_after_hwframe+0x76/0x7e
  Kernel panic - not syncing: Fatal exception
  
  On -generic the first oops was "BUG: unable to handle page fault for address: 
fffffffffffffff0"
  at path_is_under+0x50/0x90 with the same call chain.
  
  == Workload / when it happens ==
  - The VM ran cleanly for ~24h, then oopsed repeatedly once it was used as a 
development box:
    Claude Code (Node/Bun), git, pnpm, Chrome under XFCE/xrdp, and Tailscale.
  - Faulting tasks are ordinary file opens by unprivileged processes 
(MainThread = Claude Code's
    main thread, git) and root (depmod during a kernel package postinst).
  - Intervals between oopses ranged from ~1 minute to ~2 hours of uptime.
  
  == Ruled out ==
  - Filesystem: a forced e2fsck of root was clean apart from an "extent tree 
could be narrower"
    optimisation note.
  - Memory pressure: it reproduces with static RAM and >5 GB free; no OOM 
events.
  - Host problems: no host errors, and a WSL2 guest on the same host is 
unaffected.
  
  == Possibly related ==
  The first incident followed Hyper-V Dynamic Memory hot-add failures 6 minutes 
earlier:
  "40-vm-hotadd.rules: Failed to write 'online'" and "workqueue: hot_add_req 
[hv_balloon] hogged
  CPU". Dynamic Memory has been off since, and the oopses continue.
  
  == Attachments ==
  - oops-all-6-crashes.txt: full oops texts from systemd-pstore (efi_pstore) 
for every incident
  - hyperv-guest-crash-events.txt: Hyper-V Worker event 18590, which includes 
the guest's final kmsg
  - system-info.txt: version_signature, uname, installed kernels, cmdline, 
CPU/memory, userns settings
+ --- 
+ ProblemType: Bug
+ AlsaDevices:
+  total 0
+  crw-rw---- 1 root audio 116,  1 Oct  6 21:56 seq
+  crw-rw---- 1 root audio 116, 33 Oct  6 21:56 timer
+ AplayDevices: Error: [Errno 2] No such file or directory: 'aplay'
+ ApportVersion: 2.34.1-0ubuntu0.1
+ Architecture: amd64
+ ArecordDevices: Error: [Errno 2] No such file or directory: 'arecord'
+ AudioDevicesInUse: Error: command ['fuser', '-v', '/dev/snd/seq', 
'/dev/snd/timer'] failed with exit code 1:
+ CRDA: N/A
+ CasperMD5CheckResult: unknown
+ CloudArchitecture: x86_64
+ CloudBuildName: server
+ CloudID: nocloud
+ CloudName: unknown
+ CloudPlatform: nocloud
+ CloudSerial: 20260927
+ CloudSubPlatform: config-disk (/dev/sdb1)
+ DistroRelease: Ubuntu 26.04
+ Lspci:
+  
+ Lspci-vt:
+  
+ Lsusb: Error: command ['lsusb'] failed with exit code 1:
+ Lsusb-t:
+  
+ Lsusb-v: Error: command ['lsusb', '-v'] failed with exit code 1:
+ MachineType: Microsoft Corporation Virtual Machine
+ Package: linux-azure (not installed)
+ PciMultimedia:
+  
+ ProcEnviron:
+  LANG=C.UTF-8
+  PATH=(custom, no user)
+  SHELL=/bin/bash
+  TERM=unknown
+ ProcFB: 0 hyperv_drmdrmfb
+ ProcKernelCmdLine: BOOT_IMAGE=/vmlinuz-7.0.0-38-generic 
root=UUID=747687d9-c20c-41f8-bfb8-7f4a57910c51 ro console=tty1 console=ttyS0
+ ProcVersionSignature: Ubuntu 7.0.0-38.38-generic 7.0.14
+ RfKill: Error: [Errno 2] No such file or directory: 'rfkill'
+ Tags: cloud-image resolute
+ Uname: Linux 7.0.0-38-generic x86_64
+ UpgradeStatus: No upgrade log present (probably fresh install)
+ UserGroups: N/A
+ _MarkForUpload: True
+ dmi.bios.date: 09/25/2025
+ dmi.bios.release: 4.1
+ dmi.bios.vendor: Microsoft Corporation
+ dmi.bios.version: Hyper-V UEFI Release v4.1
+ dmi.board.asset.tag: None
+ dmi.board.name: Virtual Machine
+ dmi.board.vendor: Microsoft Corporation
+ dmi.board.version: Hyper-V UEFI Release v4.1
+ dmi.chassis.asset.tag: 3897-2538-6803-7408-7643-1671-78
+ dmi.chassis.type: 3
+ dmi.chassis.vendor: Microsoft Corporation
+ dmi.chassis.version: Hyper-V UEFI Release v4.1
+ dmi.modalias: 
dmi:bvnMicrosoftCorporation:bvrHyper-VUEFIReleasev4.1:bd09/25/2025:br4.1:svnMicrosoftCorporation:pnVirtualMachine:pvrHyper-VUEFIReleasev4.1:rvnMicrosoftCorporation:rnVirtualMachine:rvrHyper-VUEFIReleasev4.1:cvnMicrosoftCorporation:ct3:cvrHyper-VUEFIReleasev4.1:skuNone:pfaVirtualMachine:
+ dmi.product.family: Virtual Machine
+ dmi.product.name: Virtual Machine
+ dmi.product.sku: None
+ dmi.product.version: Hyper-V UEFI Release v4.1
+ dmi.sys.vendor: Microsoft Corporation

** Attachment added: "CurrentDmesg.txt"
   
https://bugs.launchpad.net/bugs/2169338/+attachment/6006670/+files/CurrentDmesg.txt

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2169338

Title:
  Kernel oops / GPF in path_is_under() from complete_walk() on openat
  — 7.0.0-34/-38-generic and 7.0.0-1017-azure, Hyper-V Gen2 guest

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2169338/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to