[syzbot] [acpica?] KCSAN: data-race in vsnprintf / vsnprintf
syzbot <[email protected]> Sun, 09 Aug 2026 03:13:31 -0700
| Newsgroups | gmane.linux.acpi.devel,gmane.linux.kernel |
|---|---|
| Message-ID | <[email protected]> |
Hello, syzbot found the following issue on: HEAD commit: 848acc8ffe1b Merge tag 'fsverity-for-linus' of git://git.k.. git tree: upstream console output: https://syzkaller.appspot.com/x/log.txt?x=1283b649580000 kernel config: https://syzkaller.appspot.com/x/.config?x=84b3039e8461eef5 dashboard link: https://syzkaller.appspot.com/bug?extid=f043307fae47600f98f4 compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8 Unfortunately, I don't have any reproducer for this issue yet. Downloadable assets: disk image: https://storage.googleapis.com/syzbot-assets/d1a0ae21bd78/disk-848acc8f.raw.xz vmlinux: https://storage.googleapis.com/syzbot-assets/9be505d18eb6/vmlinux-848acc8f.xz kernel image: https://storage.googleapis.com/syzbot-assets/8ab6a3838bc0/bzImage-848acc8f.xz IMPORTANT: if you fix the issue, please add the following tag to the commit: Reported-by: [email protected] **** Context Switch from TID 36034112 to TID 2691392 **** nsutils-0719 ns_get_node : ----Entry ffffffff86882de5 utmutex-0235 ut_acquire_mutex : ----Entry **** Cont1292 ================================================================== BUG: KCSAN: data-race in vsnprintf / vsnprintf write to 0xffffffff89405bd8 of 1 bytes by task 39 on cpu 1: vsnprintf+0x815/0x8c0 lib/vsprintf.c:2977 vsprintf+0x2a/0x40 lib/vsprintf.c:3090 acpi_os_vprintf drivers/acpi/osl.c:162 [inline] acpi_os_printf+0x87/0x200 drivers/acpi/osl.c:153 acpi_debug_print+0x1a9/0x200 drivers/acpi/acpica/utdebug.c:197 acpi_ns_build_internal_name+0x589/0x5d0 drivers/acpi/acpica/nsutils.c:-1 acpi_ns_internalize_name+0x265/0x310 drivers/acpi/acpica/nsutils.c:339 acpi_ns_get_node_unlocked+0xed/0x2d0 drivers/acpi/acpica/nsutils.c:666 acpi_ns_get_node+0x76/0xc0 drivers/acpi/acpica/nsutils.c:726 acpi_get_handle+0xfd/0x180 drivers/acpi/acpica/nsxfname.c:98 acpi_has_method+0x46/0x80 drivers/acpi/utils.c:672 acpi_pci_set_power_state+0x5d/0x190 drivers/pci/pci-acpi.c:1084 platform_pci_set_power_state drivers/pci/pci.c:1068 [inline] pci_power_up+0x40/0x3b0 drivers/pci/pci.c:1306 pci_pm_power_up_and_verify_state+0x29/0x130 drivers/pci/pci.c:3153 pci_pm_default_resume_early drivers/pci/pci-driver.c:591 [inline] pci_pm_resume_noirq+0xcb/0x320 drivers/pci/pci-driver.c:996 dpm_run_callback+0x53/0x2f0 drivers/base/power/main.c:510 device_resume_noirq+0x851/0x880 drivers/base/power/main.c:857 async_resume_noirq+0x2c/0x40 drivers/base/power/main.c:879 async_run_entry_fn+0x52/0x180 kernel/async.c:129 process_one_work kernel/workqueue.c:3322 [inline] process_scheduled_works+0x4d4/0x9a0 kernel/workqueue.c:3405 worker_thread+0x569/0x750 kernel/workqueue.c:3486 kthread+0x221/0x270 kernel/kthread.c:436 ret_from_fork+0x146/0x330 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 write to 0xffffffff89405bd8 of 1 bytes by task 12 on cpu 0: vsnprintf+0x815/0x8c0 lib/vsprintf.c:2977 vsprintf+0x2a/0x40 lib/vsprintf.c:3090 acpi_os_vprintf drivers/acpi/osl.c:162 [inline] acpi_os_printf+0x87/0x200 drivers/acpi/osl.c:153 acpi_debug_print+0x1a9/0x200 drivers/acpi/acpica/utdebug.c:197 acpi_os_wait_semaphore+0x11b/0x2b0 drivers/acpi/osl.c:1292 acpi_ut_acquire_mutex+0x242/0x4a0 drivers/acpi/acpica/utmutex.c:241 acpi_ns_get_node+0x46/0xc0 drivers/acpi/acpica/nsutils.c:721 acpi_get_handle+0xfd/0x180 drivers/acpi/acpica/nsxfname.c:98 acpi_has_method+0x46/0x80 drivers/acpi/utils.c:672 acpi_pci_set_power_state+0x5d/0x190 drivers/pci/pci-acpi.c:1084 platform_pci_set_power_state drivers/pci/pci.c:1068 [inline] pci_power_up+0x40/0x3b0 drivers/pci/pci.c:1306 pci_pm_power_up_and_verify_state+0x29/0x130 drivers/pci/pci.c:3153 pci_pm_default_resume_early drivers/pci/pci-driver.c:591 [inline] pci_pm_resume_noirq+0xcb/0x320 drivers/pci/pci-driver.c:996 dpm_run_callback+0x53/0x2f0 drivers/base/power/main.c:510 device_resume_noirq+0x851/0x880 drivers/base/power/main.c:857 async_resume_noirq+0x2c/0x40 drivers/base/power/main.c:879 async_run_entry_fn+0x52/0x180 kernel/async.c:129 process_one_work kernel/workqueue.c:3322 [inline] process_scheduled_works+0x4d4/0x9a0 kernel/workqueue.c:3405 worker_thread+0x569/0x750 kernel/workqueue.c:3486 kthread+0x221/0x270 kernel/kthread.c:436 ret_from_fork+0x146/0x330 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 value changed: 0x6d -> 0x65 Reported by Kernel Concurrency Sanitizer on: CPU: 0 UID: 0 PID: 12 Comm: kworker/u8:0 Tainted: G W syzkaller #0 PREEMPT(lazy) Tainted: [W]=WARN Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026 Workqueue: async async_run_entry_fn ================================================================== ] Waiting for semaphore[ffff8881000c3390|1|65535] **** Context Switch from TID 29995968 to TID 2691392 **** osl-1310 os_wait_semaphore : Acquired semaphore[ffff8881000c3390|1|65535] utmutex-0244 ut_acquire_mutex : Thread 2691392 acquired Mutex [ACPI_MTX_Namespace] nsutils-0644 ns_get_node_unlocked : ----Entry ffffffff86882de5 nsutils-0318 ns_internalize_name : ----Entry nsutils-0208 ns_build_internal_name: ----Entry nsutils-0289 ns_build_internal_name: Returning [ffff88810163f348] (rel) "_EJ0" nsutils-0293 ns_build_internal_name: ----Exit- AE_OK nsutils-0346 ns_internalize_name : ----Exit- AE_OK nsaccess-0303 ns_lookup : ----Entry nsaccess-0399 ns_lookup : Searching relative to prefix scope [S04_] (ffff888100a953f0) nsaccess-0522 ns_lookup : Simple Pathname (1 segment, Flags=2) nsdump-0064 ns_print_pathname : [_EJ0] nssearch-0261 ns_search_and_enter : ----Entry nssearch-0066 ns_search_one_scope : ----Entry nsnames-0301 ns_get_normalized_path: ----Entry ffff888100a953f0 nsnames-0202 ns_build_normalized_pa: ----Entry ffff888100a953f0 nsnames-0275 ns_build_normalized_pa: ----Exit- 000000000000000E nsnames-0202 ns_build_normalized_pa: ----Entry ffff888100a953f0 nsnames-0275 ns_build_normalized_pa: ----Exit- 000000000000000E acpi_ns_get_normalized_pathname: Path "\_SB.PCI0.S04" nsnames-0326 ns_get_normalized_path: ----Exit- ffff888100aaad10 nssearch-0074 ns_search_one_scope : Searching \_SB.PCI0.S04 (ffff888100a953f0) For [_EJ0] (Untyped) nssearch-0126 ns_search_one_scope : Name [_EJ0] (Untyped) not found in search in scope [S04_] ffff888100a953f0 first child ffff888100a953c0 nssearch-0134 ns_search_one_scope : ----Exit- ****Exception****: AE_NOT_FOUND nssearch-0364 ns_search_and_enter : _EJ0 Not found in ffff888100a953f0 [Not adding] nssearch-0368 ns_search_and_enter : ----Exit- ****Exception****: AE_NOT_FOUND nsaccess-0605 ns_lookup : Name [_EJ0] not found in scope [S04_] ffff888100a953f0 nsaccess-0644 ns_lookup : ----Exit- ****Exception****: AE_NOT_FOUND nsutils-0682 ns_get_node_unlocked : _EJ0, AE_NOT_FOUND nsutils-0687 ns_get_node_unlocked : ----Exit- ****Exception****: AE_NOT_FOUND utmutex-0277 ut_release_mutex : Thread 2691392 releasing Mutex [ACPI_MTX_Namespace] osl-1334 os_signal_semaphore : Signaling semaphore[ffff8881000c3390|1] nsutils-0730 ns_get_node : ----Exit- ****Exception****: AE_NOT_FOUND --- This report is generated by a bot. It may contain errors. See https://goo.gl/tpsmEJ for more information about syzbot. syzbot engineers can be reached at [email protected]. syzbot will keep track of this issue. See: https://goo.gl/tpsmEJ#status for how to communicate with syzbot. If the report is already addressed, let syzbot know by replying with: #syz fix: exact-commit-title If you want to overwrite report's subsystems, reply with: #syz set subsystems: new-subsystem (See the list of subsystem names on the web dashboard) If the report is a duplicate of another one, reply with: #syz dup: exact-subject-of-another-report If you want to undo deduplication, reply with: #syz undup