1. plug non-TBT dock with external display and check internal/external displays both work, make sure touch touch also works 2. unplug non-TBT and keep typing on touch, make sure touch is working. 3. Repeat steps 1,2 for 10 times and no hang found. -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2160082 Title: Linux, Ubuntu, 24.04, System hangs for about 10 seconds when unplug external monitor cable on non TBT dock Status in OEM Priority Project: New Status in linux package in Ubuntu: Fix Committed Status in linux-oem-6.17 package in Ubuntu: Invalid Status in linux source package in Noble: Invalid Status in linux-oem-6.17 source package in Noble: Fix Released Status in linux source package in Resolute: In Progress Status in linux-oem-6.17 source package in Resolute: Invalid Status in linux source package in Stonking: Fix Committed Status in linux-oem-6.17 source package in Stonking: Invalid Bug description: [Summary] System hangs for about 10 seconds when unplug external monitor cable on non TBT dock or connected external monitor cable into non TBT dock and then unplug dock cable. [Steps to reproduce] Plug the external monitor into non TBT dock. Plug non TBT dock into the system. Unplug non TBT cable or the external monitor cable. Found the system hangs for about 10 seconds. [Expected result] The system should work without any lagging or hanging when unplugging the monitor or the dock cable. [Actual result] The system hangs/freezes for about 10 seconds whenever the external monitor cable or the non-TBT dock cable is unplugged. [Failure rate] 100% [Affected test cases] 171316 Ubuntu24.04_OS - OOBE Test [Additional information] To manage notifications about this bug go to: https://bugs.launchpad.net/oem-priority/+bug/2160082/+subscriptions
[РЕШЕНО] Ошибка № ...
Ошибки в Программах и Способы их Исправления
понедельник
[Bug 2168825] [NEW] xruns in HDMI audio after kernel 7.0.0-27
Public bug reported: forum thread: https://discourse.ubuntu.com/t/pipewire-crackling-on- kernels-later-than-7-0-0-27/88358 I output audio through HDMI to my receiver, via an AMD gpu (a 9070xt), via pipewire. Since upgrading kernels past 7.0.0-27, there are crackling noises and xruns during lots of different kinds of playback, and even when idle. The receiver makes a small popping noise when the audio stream is interrupted, which happens multiple times per second often times even when no audio is playing. Increasing pipewire’s quantum to very high numbers (like 64k, over half a second) does not seem to fix this. It also happens when the system is idle, not just under load; the only fix I’ve found is to keep booting with the 7.0.0-27 kernel. Playing completely silent audio from certain programs like audacity seems to help, but is not really a fix. I vaguely suspect this might be an issue with amdgpu but I really can’t tell and don’t know how best to debug it from here. This bug report bundle was taken with 7.0.0-34, but it has been happening since at least 7.0.0-29. ProblemType: Bug DistroRelease: Ubuntu 26.04 Package: linux-image-7.0.0-34-generic 7.0.0-34.34 ProcVersionSignature: Ubuntu 7.0.0-34.34-generic 7.0.14 Uname: Linux 7.0.0-34-generic x86_64 NonfreeKernelModules: zfs ApportVersion: 2.34.1-0ubuntu0.1 Architecture: amd64 AudioDevicesInUse: USER PID ACCESS COMMAND /dev/snd/pcmC3D0c: widders 6428 F...m pipewire /dev/snd/pcmC3D0p: widders 6428 F...m pipewire /dev/snd/pcmC0D9p: widders 6428 F...m pipewire /dev/snd/seq: widders 6428 F.... pipewire CasperMD5CheckResult: unknown CurrentDesktop: ubuntu:GNOME Date: Mon Sep 28 23:40:46 2026 InstallationDate: Installed on 2018-11-14 (2876 days ago) InstallationMedia: Ubuntu 18.10 "Cosmic Cuttlefish" - Release amd64 (20181017.3) IwDevWlp11s0Link: Not connected. MachineType: ASUS System Product Name ProcEnviron: LANG=en_US.UTF-8 PATH=(custom, no user) SHELL=/bin/bash TERM=xterm-256color XDG_RUNTIME_DIR=<set> ProcFB: 0 amdgpudrmfb ProcKernelCmdLine: BOOT_IMAGE=/@/boot/vmlinuz-7.0.0-34-generic root=UUID=86127bef-7d71-4426-8373-82798d2c8063 ro rootflags=subvol=@ quiet splash intel_iommu=on snd-hda-intel.snoop=0 crashkernel=2G-4G:320M,4G-32G:512M,32G-64G:1024M,64G-128G:2048M,128G-:4096M PulseList: Error: command ['pacmd', 'list'] failed with exit code 1: No PulseAudio daemon running, or not running as session daemon. SourcePackage: linux UpgradeStatus: Upgraded to resolute on 2026-07-01 (90 days ago) dmi.bios.date: 12/14/2023 dmi.bios.release: 18.7 dmi.bios.vendor: American Megatrends Inc. dmi.bios.version: 1807 dmi.board.asset.tag: Default string dmi.board.name: ROG STRIX X670E-E GAMING WIFI dmi.board.vendor: ASUSTeK COMPUTER INC. dmi.board.version: Rev 1.xx dmi.chassis.asset.tag: Default string dmi.chassis.type: 3 dmi.chassis.vendor: Default string dmi.chassis.version: Default string dmi.modalias: dmi:bvnAmericanMegatrendsInc.:bvr1807:bd12/14/2023:br18.7:svnASUS:pnSystemProductName:pvrSystemVersion:rvnASUSTeKCOMPUTERINC.:rnROGSTRIXX670E-EGAMINGWIFI:rvrRev1.xx:cvnDefaultstring:ct3:cvrDefaultstring:skuSKU:pfaTobefilledbyO.E.M.: dmi.product.family: To be filled by O.E.M. dmi.product.name: System Product Name dmi.product.sku: SKU dmi.product.version: System Version dmi.sys.vendor: ASUS modified.conffile..etc.default.apport: # set this to 0 to disable apport, or to 1 to enable it # you can temporarily override this with # sudo service apport start force_start=1 enabled=0 mtime.conffile..etc.default.apport: 2021-06-29T02:14:01.068739 ** Affects: linux (Ubuntu) Importance: Undecided Status: New ** Tags: amd64 apport-bug resolute wayland-session -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2168825 Title: xruns in HDMI audio after kernel 7.0.0-27 Status in linux package in Ubuntu: New Bug description: forum thread: https://discourse.ubuntu.com/t/pipewire-crackling-on- kernels-later-than-7-0-0-27/88358 I output audio through HDMI to my receiver, via an AMD gpu (a 9070xt), via pipewire. Since upgrading kernels past 7.0.0-27, there are crackling noises and xruns during lots of different kinds of playback, and even when idle. The receiver makes a small popping noise when the audio stream is interrupted, which happens multiple times per second often times even when no audio is playing. Increasing pipewire’s quantum to very high numbers (like 64k, over half a second) does not seem to fix this. It also happens when the system is idle, not just under load; the only fix I’ve found is to keep booting with the 7.0.0-27 kernel. Playing completely silent audio from certain programs like audacity seems to help, but is not really a fix. I vaguely suspect this might be an issue with amdgpu but I really can’t tell and don’t know how best to debug it from here. This bug report bundle was taken with 7.0.0-34, but it has been happening since at least 7.0.0-29. ProblemType: Bug DistroRelease: Ubuntu 26.04 Package: linux-image-7.0.0-34-generic 7.0.0-34.34 ProcVersionSignature: Ubuntu 7.0.0-34.34-generic 7.0.14 Uname: Linux 7.0.0-34-generic x86_64 NonfreeKernelModules: zfs ApportVersion: 2.34.1-0ubuntu0.1 Architecture: amd64 AudioDevicesInUse: USER PID ACCESS COMMAND /dev/snd/pcmC3D0c: widders 6428 F...m pipewire /dev/snd/pcmC3D0p: widders 6428 F...m pipewire /dev/snd/pcmC0D9p: widders 6428 F...m pipewire /dev/snd/seq: widders 6428 F.... pipewire CasperMD5CheckResult: unknown CurrentDesktop: ubuntu:GNOME Date: Mon Sep 28 23:40:46 2026 InstallationDate: Installed on 2018-11-14 (2876 days ago) InstallationMedia: Ubuntu 18.10 "Cosmic Cuttlefish" - Release amd64 (20181017.3) IwDevWlp11s0Link: Not connected. MachineType: ASUS System Product Name ProcEnviron: LANG=en_US.UTF-8 PATH=(custom, no user) SHELL=/bin/bash TERM=xterm-256color XDG_RUNTIME_DIR=<set> ProcFB: 0 amdgpudrmfb ProcKernelCmdLine: BOOT_IMAGE=/@/boot/vmlinuz-7.0.0-34-generic root=UUID=86127bef-7d71-4426-8373-82798d2c8063 ro rootflags=subvol=@ quiet splash intel_iommu=on snd-hda-intel.snoop=0 crashkernel=2G-4G:320M,4G-32G:512M,32G-64G:1024M,64G-128G:2048M,128G-:4096M PulseList: Error: command ['pacmd', 'list'] failed with exit code 1: No PulseAudio daemon running, or not running as session daemon. SourcePackage: linux UpgradeStatus: Upgraded to resolute on 2026-07-01 (90 days ago) dmi.bios.date: 12/14/2023 dmi.bios.release: 18.7 dmi.bios.vendor: American Megatrends Inc. dmi.bios.version: 1807 dmi.board.asset.tag: Default string dmi.board.name: ROG STRIX X670E-E GAMING WIFI dmi.board.vendor: ASUSTeK COMPUTER INC. dmi.board.version: Rev 1.xx dmi.chassis.asset.tag: Default string dmi.chassis.type: 3 dmi.chassis.vendor: Default string dmi.chassis.version: Default string dmi.modalias: dmi:bvnAmericanMegatrendsInc.:bvr1807:bd12/14/2023:br18.7:svnASUS:pnSystemProductName:pvrSystemVersion:rvnASUSTeKCOMPUTERINC.:rnROGSTRIXX670E-EGAMINGWIFI:rvrRev1.xx:cvnDefaultstring:ct3:cvrDefaultstring:skuSKU:pfaTobefilledbyO.E.M.: dmi.product.family: To be filled by O.E.M. dmi.product.name: System Product Name dmi.product.sku: SKU dmi.product.version: System Version dmi.sys.vendor: ASUS modified.conffile..etc.default.apport: # set this to 0 to disable apport, or to 1 to enable it # you can temporarily override this with # sudo service apport start force_start=1 enabled=0 mtime.conffile..etc.default.apport: 2021-06-29T02:14:01.068739 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2168825/+subscriptions
[Bug 2166838] Re: [SRU] Fix for storage corruption on 64 bit DMA on AMD platforms
Patches for Resolute: https://lists.ubuntu.com/archives/kernel-team/2026-September/172562.html (Also working on patches for Noble) -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2166838 Title: [SRU] Fix for storage corruption on 64 bit DMA on AMD platforms Status in linux package in Ubuntu: New Status in linux source package in Noble: New Status in linux source package in Resolute: New Bug description: https://bugs.launchpad.net/bugs/2166838 [ Impact ] We found a issue where if our BIOS enables certain enhanced features for PCIe atomics for PCI root port on a system where some devices don't support, it leads to malfunction on some of those devices. Currently this manifests as storage corruption on PCIe-connected SATA storage, but potentially can lead to more general PCIe device issues. [ Fix ] Cherry-pick a quirk for AMD platforms from this patcheset: - Fix for storage corruption w/ AMD IOMMU on 64-bit addressing[1] They can be found in following commits: 1. 4fde4482 (mainline) x86/PCI: Disable enhanced atomics on AMD NBIO 7.7 and 7.11 2. 6b28e0e7 (linux-next) Revert "ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585" And a dependent patch to make these 2 apply cleanly: 1. 21e7b971 (mainline) ata: Use named initializers for pci_device_id arrays This dependent patch simply cosmetic (e.g. replace struct initialization with designated initializer) and functionally should make no difference before and after. [ Test plan ] Install the kernel with the said fix, and run workload on the PCIe storage to deplete 32bit DMA address for the given storage. When the PCIe The storage start using 64 bit DMA address, content of that storage shouldn't be corrupted. [ Where problems could occur ] The quirk is AMD-specific. This disables certain enhancement feature on PHX/HPT/STX/KRK/STXH platforms. Normal PCIe AtomicOp should not get impacted. Although this is more of a BIOS issue, it's unlikely to get BIOS update for all those platforms in the field. So adding a quirk in kernel would help mitigate that. [ Additional Information ] [1] https://lore.kernel.org/linux- ide/20260908190600.226485-1-mario.limonciello@amd.com/ To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2166838/+subscriptions
[Bug 2168783] Re: Regression in 7.0.0-31/-34: GPF in path_is_under() leaks mount_lock, system hard-freezes
** Tags added: kernel-daily-bug -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2168783 Title: Regression in 7.0.0-31/-34: GPF in path_is_under() leaks mount_lock, system hard-freezes Status in linux package in Ubuntu: New Bug description: Since linux 7.0.0-31 (and still in 7.0.0-34) the machine hard-freezes within ~10-25 minutes of normal desktop use. 7.0.0-29 and 7.0.0-30 are unaffected; 7.0.0-15 had the same bug. Sequence, identical every time: 1. Oops (GPF on non-canonical address, or page fault at fffffffffffffff0) at path_is_under+0x50/0x90, reached from a plain newfstatat(): path_is_under <- complete_walk <- path_lookupat <- filename_lookup <- vfs_statx <- vfs_fstatat <- __do_sys_newfstatat Triggering task is a GLib worker thread (Comm: pool-2 / localsearch-3, the GNOME file indexer). 2. The task dies inside the read_seqlock_excl(&mount_lock) critical section ("exited with preempt_count 1" / "exited with irqs disabled"), so mount_lock is never released. 3. Every later task that touches mounts spins in native_queued_spin_lock_slowpath: soft lockups on systemd, chrome, bwrap, runc (mntput_no_expire_slowpath, drm_release), then RCU stalls, then total freeze. Boot history on this machine (same NVIDIA 595.71.05 DKMS driver throughout): 7.0.0-15: 5 of 8 boots froze 7.0.0-29 / -30: 26 boots, 0 faults (18 with the indexer running) 7.0.0-31: 2 of 3 boots froze 7.0.0-34: froze 22 min after re-enabling localsearch-3 Reproduce: boot 7.0.0-34 with localsearch-3 enabled and use the desktop normally (browser, Docker/bwrap sandboxes); freeze within ~25 min. Masking localsearch-3 avoids it. The full kernel log from the crashed boot is attached to the report as CrashBootKernelLog. Hardware: ASUS ROG STRIX Z690-I, BIOS 4505. Ubuntu 26.04. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2168783/+subscriptions
[Bug 2168799] Re: Complete System shutdown via disconnecting from Power needed
** Tags added: kernel-daily-bug -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2168799 Title: Complete System shutdown via disconnecting from Power needed Status in linux package in Ubuntu: New Bug description: I tried to use Cycles and GPU Compute in Blender and my whole System breaks. I got an Blackscreen and cant reset via the reset button and so i had to restart by turning off the Powerbutton of the Computer and turn it on an start my computer again. This happened all the Time no matter if opengl or vulkan is enabled. I got an Radeon RX9060XT Graphicscard and i guess it has to do with the drivers for amd, but thats just guess... To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2168799/+subscriptions
[Bug 2168698] Re: Keeps freezing
** Tags added: kernel-daily-bug -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2168698 Title: Keeps freezing Status in linux package in Ubuntu: New Bug description: My Ubuntu keeps freezing and I can't find the reason. ProblemType: Bug DistroRelease: Ubuntu 26.04 Package: linux-image-7.0.0-34-generic 7.0.0-34.34 ProcVersionSignature: Ubuntu 7.0.0-34.34-generic 7.0.14 Uname: Linux 7.0.0-34-generic x86_64 NonfreeKernelModules: nvidia_modeset nvidia ApportVersion: 2.34.1-0ubuntu0.1 Architecture: amd64 AudioDevicesInUse: USER PID ACCESS COMMAND /dev/snd/controlC1: ilia 4416 F.... wireplumber /dev/snd/controlC0: ilia 4416 F.... wireplumber /dev/snd/controlC2: ilia 4416 F.... wireplumber /dev/snd/seq: ilia 4397 F.... pipewire CasperMD5CheckResult: pass CurrentDesktop: ubuntu:GNOME Date: Mon Sep 28 01:11:08 2026 InstallationDate: Installed on 2026-08-12 (46 days ago) InstallationMedia: Ubuntu 26.04 "Resolute Raccoon" - Release amd64 (20260423.1) MachineType: ASUS All Series ProcEnviron: LANG=en_US.UTF-8 PATH=(custom, no user) SHELL=/bin/bash TERM=xterm-256color XDG_RUNTIME_DIR=<set> ProcFB: 0 i915drmfb ProcKernelCmdLine: BOOT_IMAGE=/vmlinuz-7.0.0-34-generic root=/dev/mapper/ubuntu--vg-ubuntu--lv ro quiet splash intel_idle.max_cstate=1 crashkernel=2G-4G:320M,4G-32G:512M,32G-64G:1024M,64G-128G:2048M,128G-:4096M SourcePackage: linux UpgradeStatus: No upgrade log present (probably fresh install) dmi.bios.date: 12/08/2014 dmi.bios.release: 4.6 dmi.bios.vendor: American Megatrends Inc. dmi.bios.version: 2202 dmi.board.asset.tag: To be filled by O.E.M. dmi.board.name: B85M-G dmi.board.vendor: ASUSTeK COMPUTER INC. dmi.board.version: Rev X.0x dmi.chassis.asset.tag: Asset-1234567890 dmi.chassis.type: 3 dmi.chassis.vendor: Chassis Manufacture dmi.chassis.version: Chassis Version dmi.modalias: dmi:bvnAmericanMegatrendsInc.:bvr2202:bd12/08/2014:br4.6:svnASUS:pnAllSeries:pvrSystemVersion:rvnASUSTeKCOMPUTERINC.:rnB85M-G:rvrRevX.0x:cvnChassisManufacture:ct3:cvrChassisVersion:skuAll:pfaASUSMB: dmi.product.family: ASUS MB dmi.product.name: All Series dmi.product.sku: All dmi.product.version: System Version dmi.sys.vendor: ASUS To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2168698/+subscriptions
[Bug 2129564] Re: Acer nitro 16s AI makes filesystem emergency ro after suspend
Status changed to 'Confirmed' because the bug affects multiple users. ** Changed in: linux (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2129564 Title: Acer nitro 16s AI makes filesystem emergency ro after suspend Status in linux package in Ubuntu: Confirmed Bug description: I cannot run ubuntu-bug linux after the system is read only; it crashes. However, the system is the same as https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2129554 which has ubuntu-bug as it was executed before suspend. I also cannot make the system read-write again: e2fsck /dev/mapper/ubuntu--vg-ubuntu--lv e2fsck 1.47.2 (1-Jan-2025) /dev/mapper/ubuntu--vg-ubuntu--lv: recovering journal Error reading block 12160538 (Input/output error). Ignore error<y>? cancelled! /dev/mapper/ubuntu--vg-ubuntu--lv: Input/output error while reading block 12160538 JBD2: Failed to read block at offset 69146 e2fsck: Input/output error while recovering journal of /dev/mapper/ubuntu--vg-ubuntu--lv e2fsck: unable to set superblock flags on /dev/mapper/ubuntu--vg-ubuntu--lv I attach dmesg.txt after a suspend -> unsuspend Ubuntu 25.10 Linux acer 6.17.0-5-generic #5-Ubuntu SMP PREEMPT_DYNAMIC Mon Sep 22 10:00:33 UTC 2025 x86_64 GNU/Linux ProblemType: Bug DistroRelease: Ubuntu 25.10 Package: linux-image-6.17.0-5-generic 6.17.0-5.5 ProcVersionSignature: Ubuntu 6.17.0-5.5-generic 6.17.0-rc7 Uname: Linux 6.17.0-5-generic x86_64 ApportVersion: 2.33.1-0ubuntu3 Architecture: amd64 CasperMD5CheckResult: pass CurrentDesktop: ubuntu:GNOME Date: Wed Oct 22 17:04:34 2025 InstallationDate: Installed on 2025-10-19 (3 days ago) InstallationMedia: Ubuntu 25.10 "Questing Quokka" - Release amd64 (20251007) MachineType: Acer Nitro AN16S-61 ProcEnviron: LANG=en_US.UTF-8 PATH=(custom, no user) SHELL=/bin/bash TERM=xterm-256color XDG_RUNTIME_DIR=<set> ProcFB: 0 amdgpudrmfb ProcKernelCmdLine: BOOT_IMAGE=/vmlinuz-6.17.0-5-generic root=/dev/mapper/ubuntu--vg-ubuntu--lv ro quiet splash crashkernel=2G-4G:320M,4G-32G:512M,32G-64G:1024M,64G-128G:2048M,128G-:4096M RelatedPackageVersions: firmware-sof N/A linux-firmware 20250901.git993ff19b-0ubuntu1.2 SourcePackage: linux UpgradeStatus: No upgrade log present (probably fresh install) dmi.bios.date: 04/30/2025 dmi.bios.release: 1.3 dmi.bios.vendor: INSYDE Corp. dmi.bios.version: V1.03 dmi.board.asset.tag: Base Board Asset Tag dmi.board.name: EV3_SKF dmi.board.vendor: SXP dmi.board.version: V1.03 dmi.chassis.type: 10 dmi.chassis.vendor: Acer dmi.chassis.version: Chassis Version dmi.ec.firmware.release: 1.4 dmi.modalias: dmi:bvnINSYDECorp.:bvrV1.03:bd04/30/2025:br1.3:efr1.4:svnAcer:pnNitroAN16S-61:pvrV1.03:rvnSXP:rnEV3_SKF:rvrV1.03:cvnAcer:ct10:cvrChassisVersion:sku0000000000000000: dmi.product.family: Acer Nitro 16S AI dmi.product.name: Nitro AN16S-61 dmi.product.sku: 0000000000000000 dmi.product.version: V1.03 dmi.sys.vendor: Acer To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2129564/+subscriptions
[Bug 2129564] Re: Acer nitro 16s AI makes filesystem emergency ro after suspend
Same machine here (Nitro AN16S-61, board EV3_SKF, Ryzen AI 7 350) and the same failure, so adding evidence that may narrow it. Two things differ from the original report and are worth recording: 1. It is not fixed by newer firmware. This report is on BIOS V1.03 (2025-04-30). I am on V1.53 (2026-03-06) and it still happens, on kernel 7.2.8, mem_sleep=s2idle. 2. It follows the M.2 slot, not the drive. I swapped the two NVMe drives between slots and re-tested: the drive behind root port 0000:00:02.1 dies every time, whichever SSD is installed there; the drive behind 0000:00:03.2 is never affected. So the slot that kills the drive is 0000:00:02.1 (the one whose LnkCap advertises ASPM L1, and which is the ACPI wake entry GPP3 / power resource LNXPOWER:04; the other port reports "ASPM not supported" and is not a wake entry). On resume the link simply never comes back: pcieport 0000:00:02.1: broken device, retraining non-functional downstream link at 2.5GT/s pcieport 0000:00:02.1: retraining failed pcieport 0000:00:02.1: Data Link Layer Link Active not set in 100 msec nvme nvme0: Disabling device after reset failure: -19 What I've been able to rule out: - ASPM: cleared LnkCtl[1:0] on both ends of that link (controller + upstream port), verified afterwards with lspci (ASPM Disabled), then suspended - still fails. amd_pmc reports 'Last S0i3 Status: Success' during that same sleep, so the deepest state is reached without link L1 (ASPM is not needed for sleep depth here, and 'pcie_aspm=off' alone never disabled it either). - D3cold / shared _PR3: 'd3cold_allowed=0' on the drive and its upstream bridge - still fails. - Driver/PM callbacks: 'pm_test' ladder (devices, platform) is clean; only a real S0ix entry/exit breaks it. Workaround that works: Put the OS whose filesystem must stay writable on 0000:00:03.2 and accept that the drive on 0000:00:02.1 dies per suspend (recoverable only by reboot, the firmware exposes no ACPI hotplug slot for either port, and remove + rescan on the dead controller hangs the machine). Note that a root filesystem on the bad port is unrecoverable, which is exactly your report's symptom. -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2129564 Title: Acer nitro 16s AI makes filesystem emergency ro after suspend Status in linux package in Ubuntu: Confirmed Bug description: I cannot run ubuntu-bug linux after the system is read only; it crashes. However, the system is the same as https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2129554 which has ubuntu-bug as it was executed before suspend. I also cannot make the system read-write again: e2fsck /dev/mapper/ubuntu--vg-ubuntu--lv e2fsck 1.47.2 (1-Jan-2025) /dev/mapper/ubuntu--vg-ubuntu--lv: recovering journal Error reading block 12160538 (Input/output error). Ignore error<y>? cancelled! /dev/mapper/ubuntu--vg-ubuntu--lv: Input/output error while reading block 12160538 JBD2: Failed to read block at offset 69146 e2fsck: Input/output error while recovering journal of /dev/mapper/ubuntu--vg-ubuntu--lv e2fsck: unable to set superblock flags on /dev/mapper/ubuntu--vg-ubuntu--lv I attach dmesg.txt after a suspend -> unsuspend Ubuntu 25.10 Linux acer 6.17.0-5-generic #5-Ubuntu SMP PREEMPT_DYNAMIC Mon Sep 22 10:00:33 UTC 2025 x86_64 GNU/Linux ProblemType: Bug DistroRelease: Ubuntu 25.10 Package: linux-image-6.17.0-5-generic 6.17.0-5.5 ProcVersionSignature: Ubuntu 6.17.0-5.5-generic 6.17.0-rc7 Uname: Linux 6.17.0-5-generic x86_64 ApportVersion: 2.33.1-0ubuntu3 Architecture: amd64 CasperMD5CheckResult: pass CurrentDesktop: ubuntu:GNOME Date: Wed Oct 22 17:04:34 2025 InstallationDate: Installed on 2025-10-19 (3 days ago) InstallationMedia: Ubuntu 25.10 "Questing Quokka" - Release amd64 (20251007) MachineType: Acer Nitro AN16S-61 ProcEnviron: LANG=en_US.UTF-8 PATH=(custom, no user) SHELL=/bin/bash TERM=xterm-256color XDG_RUNTIME_DIR=<set> ProcFB: 0 amdgpudrmfb ProcKernelCmdLine: BOOT_IMAGE=/vmlinuz-6.17.0-5-generic root=/dev/mapper/ubuntu--vg-ubuntu--lv ro quiet splash crashkernel=2G-4G:320M,4G-32G:512M,32G-64G:1024M,64G-128G:2048M,128G-:4096M RelatedPackageVersions: firmware-sof N/A linux-firmware 20250901.git993ff19b-0ubuntu1.2 SourcePackage: linux UpgradeStatus: No upgrade log present (probably fresh install) dmi.bios.date: 04/30/2025 dmi.bios.release: 1.3 dmi.bios.vendor: INSYDE Corp. dmi.bios.version: V1.03 dmi.board.asset.tag: Base Board Asset Tag dmi.board.name: EV3_SKF dmi.board.vendor: SXP dmi.board.version: V1.03 dmi.chassis.type: 10 dmi.chassis.vendor: Acer dmi.chassis.version: Chassis Version dmi.ec.firmware.release: 1.4 dmi.modalias: dmi:bvnINSYDECorp.:bvrV1.03:bd04/30/2025:br1.3:efr1.4:svnAcer:pnNitroAN16S-61:pvrV1.03:rvnSXP:rnEV3_SKF:rvrV1.03:cvnAcer:ct10:cvrChassisVersion:sku0000000000000000: dmi.product.family: Acer Nitro 16S AI dmi.product.name: Nitro AN16S-61 dmi.product.sku: 0000000000000000 dmi.product.version: V1.03 dmi.sys.vendor: Acer To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2129564/+subscriptions
[Bug 1960841] Re: Make linux-tools-common Provide linux-cpupower
** Tags removed: update-excuse -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/1960841 Title: Make linux-tools-common Provide linux-cpupower Status in linux package in Ubuntu: Fix Released Status in opa-ff package in Ubuntu: Confirmed Bug description: In Debian, the tools cpupower, turbostat and x86_energy_perf_policy are packaged in linux-cpupower. In turn, some packages that use those CLI tools depend on this package. Currently on Debian sid, we have ❯ reverse-depends linux-cpupower Reverse-Recommends * tuned Reverse-Depends * opa-basic-tools [amd64 Having linux-tools-common Providing linux-cpupower would allow us to keep the aforementioned packages in sync with Debian without introducing a delta. While this is related to https://bugs.launchpad.net/ubuntu/+source/opa-ff/+bug/1215411 it is *not* the same issue, as we're not dealing with the libraries but with the CLI tools. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1960841/+subscriptions
[Bug 2155632] AudioDevicesInUse.txt
apport information ** Attachment added: "AudioDevicesInUse.txt" https://bugs.launchpad.net/bugs/2155632/+attachment/6003344/+files/AudioDevicesInUse.txt -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2155632 Title: Mute LED not working on HP Pavilion 15-cs3xxx (ALC295, subsystem 0x103c86e3) Status in linux package in Ubuntu: New Bug description: The mute button LED works correctly on Windows but does not respond on Linux. Hardware: - Model: HP Pavilion Laptop 15-cs3xxx - Subsystem ID: 0x103c86e3 - Codec: Realtek ALC295 - Kernel: 7.0.0-22-generic (Kubuntu 26.04) The hda::mute LED is visible in /sys/class/leds/ but writing to brightness has no effect. No COEF registers respond to hda-verb commands. The subsystem ID 0x103c86e3 is not present in patch_realtek.c. A quirk similar to ALC295_FIXUP_HP_MUTE_LED_COEFBIT11 may be needed for this subsystem ID.D ProblemType: Bug DistroRelease: Ubuntu 26.04 Package: linux-image-7.0.0-22-generic 7.0.0-22.22 ProcVersionSignature: Ubuntu 7.0.0-22.22-generic 7.0.0 Uname: Linux 7.0.0-22-generic x86_64 NonfreeKernelModules: nvidia_modeset nvidia ApportVersion: 2.34.0-0ubuntu2 Architecture: amd64 AudioDevicesInUse: USER PID ACCESS COMMAND /dev/snd/controlC1: antonio 1819 F.... wireplumber /dev/snd/controlC0: antonio 1819 F.... wireplumber /dev/snd/seq: antonio 1817 F.... pipewire CasperMD5CheckResult: unknown CurrentDesktop: KDE Date: Fri Jun 5 12:06:24 2026 InstallationDate: Installed on 2026-05-19 (17 days ago) InstallationMedia: Kubuntu 26.04 "Resolute Raccoon" - Release amd64 (20260423) Lsusb: Bus 001 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub Bus 001 Device 002: ID 04f2:b634 Chicony Electronics Co., Ltd HP Wide Vision FHD Camera Bus 001 Device 003: ID 8087:0aaa Intel Corp. Bluetooth 9460/9560 Jefferson Peak (JfP) Bus 002 Device 001: ID 1d6b:0003 Linux Foundation 3.0 root hub MachineType: HP HP Pavilion Laptop 15-cs3xxx ProcFB: 0 i915drmfb 1 nvidia-drmdrmfb ProcKernelCmdLine: BOOT_IMAGE=/boot/vmlinuz-7.0.0-22-generic root=UUID=f6336a40-bf4f-43f2-ab94-33cf9429e187 ro quiet splash pcie_aspm=off nvidia-drm.modeset=1 PulseList: Error: command ['pacmd', 'list'] failed with exit code 1: No PulseAudio daemon running, or not running as session daemon. SourcePackage: linux UpgradeStatus: No upgrade log present (probably fresh install) dmi.bios.date: 08/23/2024 dmi.bios.release: 15.23 dmi.bios.vendor: Insyde dmi.bios.version: F.23 dmi.board.asset.tag: Type2 - Board Asset Tag dmi.board.name: 86E3 dmi.board.vendor: HP dmi.board.version: 95.36 dmi.chassis.asset.tag: Chassis Asset Tag dmi.chassis.type: 10 dmi.chassis.vendor: HP dmi.chassis.version: Chassis Version dmi.ec.firmware.release: 95.36 dmi.modalias: dmi:bvnInsyde:bvrF.23:bd08/23/2024:br15.23:efr95.36:svnHP:pnHPPavilionLaptop15-cs3xxx:pvrType1ProductConfigId:rvnHP:rn86E3:rvr95.36:cvnHP:ct10:cvrChassisVersion:sku1C4H8EA#ABZ:pfa103C_5335KVHPPavilion: dmi.product.family: 103C_5335KV HP Pavilion dmi.product.name: HP Pavilion Laptop 15-cs3xxx dmi.product.sku: 1C4H8EA#ABZ dmi.product.version: Type1ProductConfigId dmi.sys.vendor: HP --- ProblemType: Bug ApportVersion: 2.34.1-0ubuntu0.1 Architecture: amd64 CasperMD5CheckResult: unknown CurrentDesktop: KDE DistroRelease: Ubuntu 26.04 InstallationDate: Installed on 2026-05-19 (132 days ago) InstallationMedia: Kubuntu 26.04 "Resolute Raccoon" - Release amd64 (20260423) Lsusb: Bus 001 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub Bus 001 Device 002: ID 04f2:b634 Chicony Electronics Co., Ltd HP Wide Vision FHD Camera Bus 001 Device 003: ID 8087:0aaa Intel Corp. Bluetooth 9460/9560 Jefferson Peak (JfP) Bus 002 Device 001: ID 1d6b:0003 Linux Foundation 3.0 root hub MachineType: HP HP Pavilion Laptop 15-cs3xxx NonfreeKernelModules: nvidia_modeset nvidia Package: linux (not installed) ProcFB: 0 i915drmfb ProcKernelCmdLine: BOOT_IMAGE=/boot/vmlinuz-7.0.0-34-generic root=UUID=f6336a40-bf4f-43f2-ab94-33cf9429e187 ro quiet splash pcie_aspm=off nvidia-drm.modeset=1 ProcVersionSignature: Ubuntu 7.0.0-34.34-generic 7.0.14 PulseList: Error: command ['pacmd', 'list'] failed with exit code 1: No PulseAudio daemon running, or not running as session daemon. Tags: resolute wayland-session Uname: Linux 7.0.0-34-generic x86_64 UpgradeStatus: No upgrade log present (probably fresh install) UserGroups: adm cdrom dip docker lpadmin ollama plugdev sambashare sudo wireshark _MarkForUpload: True dmi.bios.date: 08/23/2024 dmi.bios.release: 15.23 dmi.bios.vendor: Insyde dmi.bios.version: F.23 dmi.board.asset.tag: Type2 - Board Asset Tag dmi.board.name: 86E3 dmi.board.vendor: HP dmi.board.version: 95.36 dmi.chassis.asset.tag: Chassis Asset Tag dmi.chassis.type: 10 dmi.chassis.vendor: HP dmi.chassis.version: Chassis Version dmi.ec.firmware.release: 95.36 dmi.modalias: dmi:bvnInsyde:bvrF.23:bd08/23/2024:br15.23:efr95.36:svnHP:pnHPPavilionLaptop15-cs3xxx:pvrType1ProductConfigId:rvnHP:rn86E3:rvr95.36:cvnHP:ct10:cvrChassisVersion:sku1C4H8EA#ABZ:pfa103C_5335KVHPPavilion: dmi.product.family: 103C_5335KV HP Pavilion dmi.product.name: HP Pavilion Laptop 15-cs3xxx dmi.product.sku: 1C4H8EA#ABZ dmi.product.version: Type1ProductConfigId dmi.sys.vendor: HP --- ProblemType: Bug ApportVersion: 2.34.1-0ubuntu0.1 Architecture: amd64 CasperMD5CheckResult: unknown CurrentDesktop: KDE DistroRelease: Ubuntu 26.04 InstallationDate: Installed on 2026-05-19 (132 days ago) InstallationMedia: Kubuntu 26.04 "Resolute Raccoon" - Release amd64 (20260423) Lsusb: Bus 001 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub Bus 001 Device 002: ID 04f2:b634 Chicony Electronics Co., Ltd HP Wide Vision FHD Camera Bus 001 Device 003: ID 8087:0aaa Intel Corp. Bluetooth 9460/9560 Jefferson Peak (JfP) Bus 002 Device 001: ID 1d6b:0003 Linux Foundation 3.0 root hub MachineType: HP HP Pavilion Laptop 15-cs3xxx NonfreeKernelModules: nvidia_modeset nvidia Package: linux-image-7.0.0-34-generic 7.0.0-34.34 PackageArchitecture: amd64 ProcFB: 0 i915drmfb ProcKernelCmdLine: BOOT_IMAGE=/boot/vmlinuz-7.0.0-34-generic root=UUID=f6336a40-bf4f-43f2-ab94-33cf9429e187 ro quiet splash pcie_aspm=off nvidia-drm.modeset=1 ProcVersionSignature: Ubuntu 7.0.0-34.34-generic 7.0.14 PulseList: Error: command ['pacmd', 'list'] failed with exit code 1: No PulseAudio daemon running, or not running as session daemon. Tags: resolute wayland-session Uname: Linux 7.0.0-34-generic x86_64 UpgradeStatus: No upgrade log present (probably fresh install) UserGroups: adm cdrom dip docker lpadmin ollama plugdev sambashare sudo wireshark _MarkForUpload: True dmi.bios.date: 08/23/2024 dmi.bios.release: 15.23 dmi.bios.vendor: Insyde dmi.bios.version: F.23 dmi.board.asset.tag: Type2 - Board Asset Tag dmi.board.name: 86E3 dmi.board.vendor: HP dmi.board.version: 95.36 dmi.chassis.asset.tag: Chassis Asset Tag dmi.chassis.type: 10 dmi.chassis.vendor: HP dmi.chassis.version: Chassis Version dmi.ec.firmware.release: 95.36 dmi.modalias: dmi:bvnInsyde:bvrF.23:bd08/23/2024:br15.23:efr95.36:svnHP:pnHPPavilionLaptop15-cs3xxx:pvrType1ProductConfigId:rvnHP:rn86E3:rvr95.36:cvnHP:ct10:cvrChassisVersion:sku1C4H8EA#ABZ:pfa103C_5335KVHPPavilion: dmi.product.family: 103C_5335KV HP Pavilion dmi.product.name: HP Pavilion Laptop 15-cs3xxx dmi.product.sku: 1C4H8EA#ABZ dmi.product.version: Type1ProductConfigId dmi.sys.vendor: HP To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2155632/+subscriptions
воскресенье
[Bug 2163121] Re: [Regression] Laptop fails to power off completely when HDMI is connected in kernel 7.0.0-28
Hi all, I can confirm that this issue affected my system when running kernels 7.0.0-31-generic and 7.0.0-34-generic on a Dell Pro laptop with AMD Radeon graphics. The primary symptom was that the system would become completely unresponsive during both restarts and full shutdown/startup cycles. The display would remain black and the system would not recover without a forced power reset. Recovery required holding the power button for approximately 30 seconds, waiting 5 seconds, and then pressing the power button again to start the system. This behaviour occurred during the majority of restart and power cycle operations. Following Krystian's recommendation to test 7.0.0-38-generic (although the referenced wiki page appears to be empty, so I used my own installation method), I found that the issue was completely resolved. To validate the fix, I performed: 10 full shutdown and power-on cycles 10 full system restarts In every test case, the system either restarted successfully or powered on normally with a single press of the power button. I was unable to reproduce the issue while running 7.0.0-38-generic. Please let me know if I can help with further information / logs, or if I can contribute to getting this proposed bugfix into "main" :-) My Rig is as follows: ### System Machine : Dell Pro 16 PC16255 (Dell Pro Laptops) Board : Dell Inc. 18G76C BIOS : 1.17.1 (07/31/2026) CPU : AMD Ryzen AI 7 350 w/ Radeon 860M, 16 threads, ucode 0xb600037 RAM : 30Gi GPU : AMD Radeon 860M [1002:1114] rev c2, driver: amdgpu GFX stack: mesa 25.2.8-0ubuntu0.24.04.2, linux-firmware 20240318.git3b128b60.0ubuntu3.1 ### Software OS : Ubuntu 24.04.5 LTS (amd64) Kernel : 7.0.0-38-generic (pkg 7.0.0-38.38~24.04.4) Previous: 7.0.0-34-generic Installed kernels: 7.0.0-31-generic 7.0.0-34-generic 7.0.0-38-generic Cmdline : BOOT_IMAGE=/vmlinuz-7.0.0-38-generic root=/dev/mapper/ubuntu--vg-ubuntu--lv ro quiet splash vt.handoff=7 Tainted : 0 Boot : UEFI, SecureBoot: enabled Session : wayland / KDE DKMS : none APT : proposed pocket enabled Cheers, Mike -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2163121 Title: [Regression] Laptop fails to power off completely when HDMI is connected in kernel 7.0.0-28 Status in linux package in Ubuntu: Fix Committed Status in linux-hwe-7.0 package in Ubuntu: Fix Committed Status in linux source package in Noble: Invalid Status in linux-hwe-7.0 source package in Noble: Fix Committed Status in linux source package in Resolute: Fix Committed Status in linux-hwe-7.0 source package in Resolute: Invalid Bug description: Issue Description: When shutting down the system with an external monitor connected via HDMI, the OS finishes the shutdown process normally, but the laptop hardware remains powered on (the power LED stays illuminated and the machine does not fully power off). If the HDMI cable is disconnected before the shutdown, the laptop powers off completely and correctly. Important note: Once the system enters this "stuck" state (black screen, power LED on), unplugging the HDMI cable does not recover the system or allow it to finish powering off. It remains completely frozen. The HDMI cable must be unplugged before initiating the shutdown sequence to avoid the hang. Additional troubleshooting: I have also tested this with two different HDMI cables to rule out a faulty cable, but the issue persists regardless of the cable used. Regression Details: This is a regression introduced in kernel 7.0.0-28. I have tested previous kernels on the exact same hardware and they work perfectly (the system powers off completely even with the HDMI connected). Fails in: Kernel 7.0.0-28-generic Works in: Kernel 7.0.0-14-generic, 6.x branch Steps to Reproduce: 1. Boot the laptop with kernel 7.0.0-28. 2, Connect an external monitor via the HDMI port. 3. Shut down the system from the GUI (or via sudo shutdown now). 4. Notice the OS halts, but the laptop's power LED remains on and the machine does not fully power down. 5. Unplugging the HDMI cable at this frozen stage does nothing; the machine remains stuck and must be forced off by holding the physical power button. System Information: OS: Linux Mint 22.3 Zena (Ubuntu 24.04 noble base) Hardware: LENOVO IdeaPad 5 15ALC05 CPU: AMD Ryzen 7 5700U with Radeon Graphics (Lucienne / Zen 2) GPU: AMD Lucienne (amdgpu driver) BIOS: H2CN33WW (08/30/2023) External Monitor: Xiaomi Monitor A22i (Model: A22FAB-RAGL) Hardware Details: Kernel: 7.0.0-28-generic arch: x86_64 bits: 64 compiler: gcc v: 13.3.0 clocksource: tsc Desktop: Cinnamon v: 6.6.9 tk: GTK v: 3.24.41 wm: Muffin v: 6.6.3 with: plank vt: 7 dm: LightDM v: 1.30.0 Distro: Linux Mint 22.3 Zena base: Ubuntu 24.04 noble Machine: Type: Laptop System: LENOVO product: 82LN v: IdeaPad 5 15ALC05 Mobo: LENOVO model: LNVNB161216 UEFI: LENOVO v: H2CN33WW date: 08/30/2023 CPU: Info: 8-core model: AMD Ryzen 7 5700U with Radeon Graphics bits: 64 type: MT MCP smt: enabled arch: Zen 2 rev: 1 Graphics: Device-1: AMD Lucienne vendor: Lenovo driver: amdgpu v: kernel arch: GCN-5 pcie: speed: 8 GT/s lanes: 16 ports: active: eDP-1 empty: DP-1,HDMI-A-1 bus-ID: 03:00.0 chip-ID: 1002:164c class-ID: 0300 --- ProblemType: Bug ApportVersion: 2.28.3-0ubuntu0.1 Architecture: amd64 AudioDevicesInUse: USER PID ACCESS COMMAND /dev/snd/controlC1: user 1698 F.... wireplumber /dev/snd/controlC0: user 1698 F.... wireplumber /dev/snd/seq: user 1696 F.... pipewire CRDA: N/A CasperMD5CheckResult: pass CurrentDesktop: X-Cinnamon DistroRelease: Linux Mint 22.3 InstallationDate: Installed on 2026-07-22 (20 days ago) InstallationMedia: Linux Mint 22.3 "Zena" - Release amd64 20260108 MachineType: LENOVO 82LN Package: linux (not installed) ProcFB: 0 amdgpudrmfb ProcKernelCmdLine: BOOT_IMAGE=/vmlinuz-7.0.0-28-generic root=/dev/mapper/vgmint-root ro quiet splash ProcVersionSignature: Ubuntu 7.0.0-28.28~24.04.1-generic 7.0.12 PulseList: Error: command ['pacmd', 'list'] failed with exit code 1: No PulseAudio daemon running, or not running as session daemon. RelatedPackageVersions: linux-restricted-modules-7.0.0-28-generic N/A linux-backports-modules-7.0.0-28-generic N/A linux-firmware 20240318.git3b128b60-0ubuntu2.27 Tags: zena Uname: Linux 7.0.0-28-generic x86_64 UpgradeStatus: No upgrade log present (probably fresh install) UserGroups: adm cdrom dip kvm libvirt lpadmin plugdev sambashare sudo users _MarkForUpload: True dmi.bios.date: 08/30/2023 dmi.bios.release: 1.33 dmi.bios.vendor: LENOVO dmi.bios.version: H2CN33WW dmi.board.asset.tag: No Asset Tag dmi.board.name: LNVNB161216 dmi.board.vendor: LENOVO dmi.board.version: NO DPK dmi.chassis.asset.tag: No Asset Tag dmi.chassis.type: 10 dmi.chassis.vendor: LENOVO dmi.chassis.version: IdeaPad 5 15ALC05 dmi.ec.firmware.release: 1.33 dmi.modalias: dmi:bvnLENOVO:bvrH2CN33WW:bd08/30/2023:br1.33:efr1.33:svnLENOVO:pn82LN:pvrIdeaPad515ALC05:rvnLENOVO:rnLNVNB161216:rvrNODPK:cvnLENOVO:ct10:cvrIdeaPad515ALC05:skuLENOVO_MT_82LN_BU_idea_FM_IdeaPad515ALC05:pfaIdeaPad515ALC05: dmi.product.family: IdeaPad 5 15ALC05 dmi.product.name: 82LN dmi.product.sku: LENOVO_MT_82LN_BU_idea_FM_IdeaPad 5 15ALC05 dmi.product.version: IdeaPad 5 15ALC05 dmi.sys.vendor: LENOVO To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2163121/+subscriptions
[Bug 2168697] Re: linux (Noble): CIFS unmount use-after-free and panic introduced in 6.8.0-136 (CVE-2026-72315)
** Description changed: SRU Justification: [ Impact ] Noble 6.8.0-136 backported 340cea84f691 ("cifs: open files should not hold ref on superblock", v7.0) via LP: #2154496. Since then an open cifs file pins only its dentry, so umount(2) can complete while a read-ahead (cifs_readdata on cifsiod_wq), an uncached read/write (cifs_aio_ctx) or a writeback (cifs_writedata) still owns a cifsFileInfo. generic_shutdown_super() finds the inode busy, poisons i_sb with VFS_PTR_POISON, and the later _cifsFileInfo_put() from cifs_readahead_complete() faults on 0xdead0000000000f5 + 0x390. With panic_on_oops=1 the host panics; with panic_on_oops=0 every later umount of a cifs filesystem hangs forever in cifs_kill_sb(). Workloads that mount and unmount SMB shares while a reader is killed (containers, per-job mounts) can hit it. 6.8.0-139 (LP: #2160250) added c68337442f03 ("cifs: Fix busy dentry used after unmounting"), which flushes deferredclose_wq only and covers the deferred-close variant (1 of our 9 production panics). The read-ahead variant (8 of 9) is fixed upstream by 75f5c412fa86 ("smb: client: fix busy dentry warning on unmount after DIO", v7.2, CVE-2026-72315), which is in no Noble 6.8 kernel up to 6.8.0-146 and does not apply as-is because the 6.8 cifs read/write path predates the netfs conversion. Observed: 6.8.0-137 (9 panics / 8 hosts / 30 h on ~850 hosts; lab reproducer panics in 5-90 s) and 6.8.0-146 (lab, ~10 s). Not affected: 6.8.0-111 (same workload, ~3,800 hosts, 0 in 17 days). [ Fix ] Backport of 75f5c412fa86 to the pre-netfs 6.8 code: a per-superblock counter (cifs_sb->outstanding_rreq, as upstream) is taken where a cifs_readdata / cifs_writedata / cifs_aio_ctx acquires its cifsFileInfo reference (including the two writeback sites that transfer an already-held reference) and released after the put in the three release functions. cifs_kill_sb() waits for the counter to reach zero, then flushes serverclose_wq and fileinfo_put_wq before kill_anon_super(), exactly as upstream. A flush-only alternative (flush cifsiod_wq, serverclose_wq, fileinfo_put_wq) was built and tested and still panics: the read request is still on the socket when umount runs, so there is nothing queued to flush. [ Test Plan ] Mount an SMB3 share, start a sequential read of a 2-3 MB file (read-ahead queued), SIGKILL the reader after 1-90 ms, open/close another file, umount immediately; repeat in 4-8 parallel workers on separate mount points (script attached). Stock 6.8.0-137 panics within ~90 s at 8 workers; stock 6.8.0-146 within ~10 s. With the patch on 6.8.0-146.146: ~76,000 cycles against a Dell PowerScale (Isilon) share (krb5, ro) and a Samba share (ro and rw, buffered and O_DIRECT writers, 40-150 ms added server delay) with 0 "Dentry still in use" warnings, 0 faults, 0 hung umounts. We can test a -proposed kernel within minutes. [ Where problems could occur ] The change is confined to fs/smb/client. The counter must balance at every cifsFileInfo acquisition and release of cifs_readdata, cifs_writedata and cifs_aio_ctx; an unbalanced path would make umount(2) wait forever in cifs_kill_sb() (an earlier revision of this port missed the two writeback transfer sites; code review caught it before any write test, which is why they are counted explicitly and the write path was tested separately). The wait runs only at unmount, after the VFS has detached the superblock, so no new I/O can start on it; steady-state I/O paths gain one atomic increment and decrement per request. [ Other Info ] Related but separate: 5520e89a5a4f ("smb: client: fix cifsFileInfo reference leak in deferred close") fixes a refcount leak with a different Fixes: tag; it is not part of this bug. == Evidence (details) == Release: Ubuntu 24.04 LTS (Noble) Package: linux, tested at 6.8.0-137.137 and 6.8.0-146.146 Expected: umount(2) returns and the host continues running. Actual: _cifsFileInfo_put() dereferences an inode after superblock teardown and faults. The host panics with panic_on_oops=1, or later CIFS unmounts hang with panic_on_oops=0. Affected kernels: * Tested: 6.8.0-137.137. We saw 9 production panics on 8 hosts in about - 30 hours across about 850 nodes. The lab reproducer panics in 5–90 seconds. + 30 hours across about 850 nodes. The lab reproducer panics in 5–90 seconds. * Tested: 6.8.0-146.146 (noble-proposed). The lab reproducer panics in about - 10 seconds. + 10 seconds. * Code-inferred: 6.8.0-136.136, which introduced 340cea84f691c, and - 6.8.0-138.138, which predates c68337442f03. + 6.8.0-138.138, which predates c68337442f03. * Partial fix from 6.8.0-139.139: c68337442f03 flushes deferredclose_wq only. * Not affected: 6.8.0-111.111. The same workload ran on about 3,800 nodes - for 17 days without an occurrence. This kernel predates 340cea84f691c. + for 17 days without an occurrence. This kernel predates 340cea84f691c. == Summary == Noble 6.8.0-136 introduced upstream 340cea84f691c ("cifs: open files should not hold ref on superblock", mainline v7.0) via the upstream-stable patchset tracked by LP: #2154496. After this change, a cifs open file holds only a dentry reference. umount(2) can complete while asynchronous work still owns a cifsFileInfo. When that work later calls _cifsFileInfo_put(), the superblock is gone and the kernel faults on the VFS_PTR_POISON value written into the surviving inode. We observed these paths: * (a) deferredclose: smb2_deferred_work_close -> _cifsFileInfo_put. - Fixed by c68337442f03 in 6.8.0-139 and later. + Fixed by c68337442f03 in 6.8.0-139 and later. * (b) cifsiod: cifs_readahead_complete -> _cifsFileInfo_put. - Not fixed in any Noble 6.8 kernel through 6.8.0-146. + Not fixed in any Noble 6.8 kernel through 6.8.0-146. * (c) cifsoplockd: cifs_oplock_break -> _cifsFileInfo_put. - This secondary path appeared only after path (b) had already oopsed with - panic_on_oops=0. We have not demonstrated it as an independent race. + This secondary path appeared only after path (b) had already oopsed with + panic_on_oops=0. We have not demonstrated it as an independent race. In production on 6.8.0-137, path (b) caused 8 panics and path (a) caused 1. On 6.8.0-146 the reproducer triggers path (b), followed by path (c) when panic_on_oops=0. The proposed fix eliminated this complete reproduced sequence. We do not claim that it fixes a separate oplock race. == Impact == With panic_on_oops=1, the whole host panics. With panic_on_oops=0, the oopsed kworkers do not complete and later CIFS unmounts hang in D state at: - __flush_workqueue <- cifs_kill_sb + __flush_workqueue <- cifs_kill_sb Workloads that mount and unmount SMB shares for each job, such as container workloads, exercise this path continuously. == Kernel log, variant (b) — 6.8.0-137-generic #137-Ubuntu, production == [24042.343670] BUG: Dentry 000000002c909471{i=c34b9,n=<file>} still in use (1) [unmount of cifs cifs] [24042.343678] WARNING: CPU: 28 PID: 1352709 at fs/dcache.c:1528 umount_check+0x64/0x90 [24042.343780] CPU: 28 PID: 1352709 Comm: umount Kdump: loaded Tainted: P OE 6.8.0-137-generic #137-Ubuntu [24042.343783] RIP: 0010:umount_check+0x64/0x90 [24042.343802] d_walk+0xc0/0x2a0 [24042.343810] generic_shutdown_super+0x21/0x180 [24042.343815] cifs_kill_sb+0x5b/0x70 [cifs] [24042.343853] cleanup_mnt+0xc3/0x170 [24042.343938] WARNING: CPU: 28 PID: 1352709 at fs/super.c:649 generic_shutdown_super+0x120/0x180 - VFS: Busy inodes after unmount of cifs (cifs) + VFS: Busy inodes after unmount of cifs (cifs) [24043.843507] general protection fault, probably for non-canonical address 0xdead000000000485: 0000 [#1] PREEMPT SMP NOPTI [24043.854484] CPU: 4 PID: 1352168 Comm: kworker/4:1 Kdump: loaded Tainted: P W OE 6.8.0-137-generic #137-Ubuntu [24043.875232] Workqueue: cifsiod cifs_readahead_complete [cifs] [24043.881106] RIP: 0010:_cifsFileInfo_put+0x77/0x4a0 [cifs] [24043.910734] RAX: dead0000000000f5 RBX: ffff8e6ee73a1ea8 RCX: 000000000000000a [24043.983676] cifs_readahead_complete+0x23e/0x2f0 [cifs] [24043.988976] process_one_work+0x181/0x3a0 [24043.993014] worker_thread+0x18b/0x330 [24044.001087] kthread+0xef/0x120 [24044.245052] Kernel panic - not syncing: Fatal exception == Kernel log, variant (a) — 6.8.0-137, production == [17180.976882] BUG: Dentry 00000000e23b32d6{i=34fc,n=<file>} still in use (1) [unmount of cifs cifs] [17180.977008] RIP: 0010:umount_check+0x64/0x90 [17180.977052] cifs_kill_sb+0x5b/0x70 [cifs] [17180.977268] VFS: Busy inodes after unmount of cifs (cifs) [17181.900781] Workqueue: deferredclose smb2_deferred_work_close [cifs] [17181.907243] RIP: 0010:_raw_spin_lock+0x13/0x60 [17182.014078] cifsFileInfo_put_final+0xed/0x120 [cifs] [17182.019221] _cifsFileInfo_put+0x350/0x4a0 [cifs] [17182.028127] smb2_deferred_work_close+0x5f/0x70 [cifs] - Kernel panic - not syncing: Fatal exception + Kernel panic - not syncing: Fatal exception == Kernel log, variants (b) and (c) == Kernel: 6.8.0-146-generic #146-Ubuntu, lab, panic_on_oops=0 [ 142.574284] general protection fault, probably for non-canonical address 0xdead000000000485: 0000 [#1] PREEMPT SMP NOPTI [ 142.605742] Workqueue: cifsiod cifs_readahead_complete [cifs] [ 142.611633] RIP: 0010:_cifsFileInfo_put+0x77/0x4a0 [cifs] [ 142.857981] general protection fault, probably for non-canonical address 0xdead000000000485: 0000 [#2] PREEMPT SMP NOPTI [ 142.868925] Workqueue: cifsoplockd cifs_oplock_break [cifs] [ 142.868997] RIP: 0010:cifs_oplock_break+0x43/0x620 [cifs] [ 142.888932] RIP: 0010:_cifsFileInfo_put+0x77/0x4a0 [cifs] (preceded by "BUG: Dentry ... still in use (1) [unmount of cifs cifs]" from umount_check) Afterwards on 6.8.0-146: 8 umount processes in D state, all at - __flush_workqueue+0x14a/0x3e0 - <- cifs_kill_sb+0x3c/0x70 [cifs] - <- deactivate_locked_super - <- cleanup_mnt + __flush_workqueue+0x14a/0x3e0 + <- cifs_kill_sb+0x3c/0x70 [cifs] + <- deactivate_locked_super + <- cleanup_mnt == vmcore analysis (6.8.0-146.146, variant b) == Analysis used crash with linux-image-unsigned-6.8.0-146-generic-dbgsym. The faulting instruction at _cifsFileInfo_put+0x77 is the inlined CIFS_SB(inode->i_sb), which reads sb->s_fs_info at offset 0x390. The inode is d_inode(cifs_file->dentry). Objects in the dump: * inode ffff8bb592233680: - i_ino=0xec6, matching the "i=ec6" umount_check line; i_nlink=1; - i_count=1; i_state=0; still on sb->s_inodes; and - i_op = i_sb = i_mapping = 0xdead0000000000f5 (VFS_PTR_POISON). + i_ino=0xec6, matching the "i=ec6" umount_check line; i_nlink=1; + i_count=1; i_state=0; still on sb->s_inodes; and + i_op = i_sb = i_mapping = 0xdead0000000000f5 (VFS_PTR_POISON). * dentry ffff8bb5861c7380: - "<file>"; d_lockref.count=1, held by the cifsFileInfo. + "<file>"; d_lockref.count=1, held by the cifsFileInfo. * superblock ffff8ab5ae3e9800: - type "cifs"; s_count=0; s_active=0; s_root=NULL. + type "cifs"; s_count=0; s_active=0; s_root=NULL. * cifsFileInfo ffff8bb551338a00: - allocated from kmalloc-512. + allocated from kmalloc-512. * cifs_tcon ffff8ab51c791800: - allocated. + allocated. generic_shutdown_super() writes this VFS_PTR_POISON value when CHECK_DATA_CORRUPTION(!list_empty(&sb->s_inodes), "VFS: Busy inodes after unmount") fires at fs/super.c:649-663. The read-ahead cifsFileInfo kept the dentry and inode alive across unmount. The superblock was torn down, and the completion work then dereferenced inode->i_sb. This matches the mechanism addressed by 75f5c412fa86: wait for in-flight requests and drain final-put work before kill_anon_super(). The deferredclose_wq flush from c68337442f03 does not cover cifsiod or cifsoplockd work. The vmcore and vmlinux are available on request. == Reproducer (lab, both 6.8.0-137 and 6.8.0-146) == Server: Dell PowerScale (Isilon) SMB3 share, mounted read-only with - -o vers=3.0,sec=krb5,dir_mode=0755,file_mode=0755,noperm, - noserverino,nosharesock,cruid=0,nobrl,ro + -o vers=3.0,sec=krb5,dir_mode=0755,file_mode=0755,noperm, + noserverino,nosharesock,cruid=0,nobrl,ro mount.cifs reports: - cache=strict,soft,nounix,mapposix,rsize=1048576,wsize=1048576 + cache=strict,soft,nounix,mapposix,rsize=1048576,wsize=1048576 Loop, N parallel workers, each on its own mount point: 1. Mount the share. 2. Start a sequential read, which queues read-ahead: - dd if=<2–3 MB file on the share> of=/dev/null bs=1M & + dd if=<2–3 MB file on the share> of=/dev/null bs=1M & 3. Sleep for 0.01–0.09 seconds, then kill the dd process while I/O is in - flight. + flight. 4. Open and close another file to leave a deferred close pending: - head -c 65536 <another file> >/dev/null + head -c 65536 <another file> >/dev/null 5. Immediately unmount the mount point. 6. Repeat. Results: * 6.8.0-137, 8 workers: panic within about 90 seconds (variant b), with a - kdump fingerprint on the BMC. + kdump fingerprint on the BMC. * 6.8.0-137, 4 workers, panic_on_oops=0: oops (b), then (c), within about - 5 seconds. + 5 seconds. * 6.8.0-146, 4 workers for 45 seconds: 5 "Dentry ... still in use" - warnings and no fault. + warnings and no fault. * 6.8.0-146, 8 workers: oops (b), then (c), within about 10 seconds. The "still in use" warning occurs several times per minute with 4 workers on 6.8.0-146. The fault requires the deferred work to run after the superblock is freed, so it becomes more likely with parallel workers. == Regression boundary (from the Noble changelog) == * linux 6.8.0-136.136, "Noble update: upstream stable patchset 2026-05-28" - (LP: #2154496), added: - - 340cea84f691c (v7.0) - cifs: open files should not hold ref on superblock + (LP: #2154496), added: + + 340cea84f691c (v7.0) + cifs: open files should not hold ref on superblock * linux 6.8.0-139.139, "Noble update: upstream stable patchset 2026-07-09" - (LP: #2160250), added: - - c68337442f03 (v7.1, Cc: stable, Fixes: 340cea84f691c) - cifs: Fix busy dentry used after unmounting - - This commit adds flush_workqueue(deferredclose_wq) in cifs_kill_sb(). It - covers variant (a) only. + (LP: #2160250), added: + + c68337442f03 (v7.1, Cc: stable, Fixes: 340cea84f691c) + cifs: Fix busy dentry used after unmounting + + This commit adds flush_workqueue(deferredclose_wq) in cifs_kill_sb(). It + covers variant (a) only. * No Noble 6.8 kernel through 6.8.0-146.146 contains: - 75f5c412fa86 (v7.2, Fixes: 340cea84f691c) - smb: client: fix busy dentry warning on unmount after DIO - - This commit adds cifs_sb->outstanding_rreq, waits for in-flight requests, - and flushes serverclose_wq and fileinfo_put_wq before kill_anon_super(). - This is the mechanism that covers variants (b) and (c). + 75f5c412fa86 (v7.2, Fixes: 340cea84f691c) + smb: client: fix busy dentry warning on unmount after DIO + + This commit adds cifs_sb->outstanding_rreq, waits for in-flight requests, + and flushes serverclose_wq and fileinfo_put_wq before kill_anon_super(). + This is the mechanism that covers variants (b) and (c). == Request == Track this under CVE-2026-72315, the outstanding-I/O defect fixed by 75f5c412fa86. 1. Apply the attached Noble 6.8 backport of 75f5c412fa86. Noble predates - the cifs netfs conversion, so the backport accounts for the cifsFileInfo - references held by cifs_readdata, cifs_writedata and cifs_aio_ctx instead - of netfs requests. cifs_kill_sb() waits for that per-superblock count to - reach zero, then flushes serverclose_wq and fileinfo_put_wq before - kill_anon_super(). The patch survived about 76,000 tested cycles. The - flush-only alternative still panicked within about 30 seconds with the - same cifsiod/cifs_readahead_complete trace. + the cifs netfs conversion, so the backport accounts for the cifsFileInfo + references held by cifs_readdata, cifs_writedata and cifs_aio_ctx instead + of netfs requests. cifs_kill_sb() waits for that per-superblock count to + reach zero, then flushes serverclose_wq and fileinfo_put_wq before + kill_anon_super(). The patch survived about 76,000 tested cycles. The + flush-only alternative still panicked within about 30 seconds with the + same cifsiod/cifs_readahead_complete trace. 2. We can validate a candidate kernel within minutes with the attached - reproducer. + reproducer. 3. Consider noting in the 6.8.0-136, 6.8.0-137 and 6.8.0-138 release notes - that 340cea84f691c shipped without its stable follow-up c68337442f03. + that 340cea84f691c shipped without its stable follow-up c68337442f03. Related but separate: 5520e89a5a4f ("smb: client: fix cifsFileInfo reference leak in deferred close", Fixes: c3f207ab29f7) fixes a refcount leak when queue_delayed_work() finds work already pending. It has a different Fixes commit and is not asserted to cause this panic. Please track it separately. == Environment / attachments == Ubuntu 24.04 (Noble), x86_64, HPE ProLiant XL225n Gen10 Plus, in-tree cifs.ko 2.47, and SMB3 to Dell PowerScale. Production mounts and unmounts the share for each cri-o container lifecycle. The lab uses a hand-driven loop. - Attached evidence: - - * Production panic context and kworker trace. - * Firmware pstore record from a lab 6.8.0-137 panic. - * Live and vmcore dmesg from stock 6.8.0-146. - * Vmcore analysis. - * Reproducer. - * Version, PCI, release and package metadata. - * Tested SRU patch. /proc/version_signature reported: - Ubuntu 6.8.0-137.137-generic 6.8.12 - Ubuntu 6.8.0-146.146-generic 6.8.12 + Ubuntu 6.8.0-137.137-generic 6.8.12 + Ubuntu 6.8.0-146.146-generic 6.8.12 A 3.4 GB kdump vmcore of the 6.8.0-146.146 variant-(b) panic was captured on 2026-09-27 with makedumpfile -c -d 31. It is available on request with - the matching vmlinux. Its dmesg and object analysis are attached. + the matching vmlinux. Its dmesg is attached. -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2168697 Title: linux (Noble): CIFS unmount use-after-free and panic introduced in 6.8.0-136 (CVE-2026-72315) Status in linux package in Ubuntu: New Bug description: SRU Justification: [ Impact ] Noble 6.8.0-136 backported 340cea84f691 ("cifs: open files should not hold ref on superblock", v7.0) via LP: #2154496. Since then an open cifs file pins only its dentry, so umount(2) can complete while a read-ahead (cifs_readdata on cifsiod_wq), an uncached read/write (cifs_aio_ctx) or a writeback (cifs_writedata) still owns a cifsFileInfo. generic_shutdown_super() finds the inode busy, poisons i_sb with VFS_PTR_POISON, and the later _cifsFileInfo_put() from cifs_readahead_complete() faults on 0xdead0000000000f5 + 0x390. With panic_on_oops=1 the host panics; with panic_on_oops=0 every later umount of a cifs filesystem hangs forever in cifs_kill_sb(). Workloads that mount and unmount SMB shares while a reader is killed (containers, per-job mounts) can hit it. 6.8.0-139 (LP: #2160250) added c68337442f03 ("cifs: Fix busy dentry used after unmounting"), which flushes deferredclose_wq only and covers the deferred-close variant (1 of our 9 production panics). The read-ahead variant (8 of 9) is fixed upstream by 75f5c412fa86 ("smb: client: fix busy dentry warning on unmount after DIO", v7.2, CVE-2026-72315), which is in no Noble 6.8 kernel up to 6.8.0-146 and does not apply as-is because the 6.8 cifs read/write path predates the netfs conversion. Observed: 6.8.0-137 (9 panics / 8 hosts / 30 h on ~850 hosts; lab reproducer panics in 5-90 s) and 6.8.0-146 (lab, ~10 s). Not affected: 6.8.0-111 (same workload, ~3,800 hosts, 0 in 17 days). [ Fix ] Backport of 75f5c412fa86 to the pre-netfs 6.8 code: a per-superblock counter (cifs_sb->outstanding_rreq, as upstream) is taken where a cifs_readdata / cifs_writedata / cifs_aio_ctx acquires its cifsFileInfo reference (including the two writeback sites that transfer an already-held reference) and released after the put in the three release functions. cifs_kill_sb() waits for the counter to reach zero, then flushes serverclose_wq and fileinfo_put_wq before kill_anon_super(), exactly as upstream. A flush-only alternative (flush cifsiod_wq, serverclose_wq, fileinfo_put_wq) was built and tested and still panics: the read request is still on the socket when umount runs, so there is nothing queued to flush. [ Test Plan ] Mount an SMB3 share, start a sequential read of a 2-3 MB file (read-ahead queued), SIGKILL the reader after 1-90 ms, open/close another file, umount immediately; repeat in 4-8 parallel workers on separate mount points (script attached). Stock 6.8.0-137 panics within ~90 s at 8 workers; stock 6.8.0-146 within ~10 s. With the patch on 6.8.0-146.146: ~76,000 cycles against a Dell PowerScale (Isilon) share (krb5, ro) and a Samba share (ro and rw, buffered and O_DIRECT writers, 40-150 ms added server delay) with 0 "Dentry still in use" warnings, 0 faults, 0 hung umounts. We can test a -proposed kernel within minutes. [ Where problems could occur ] The change is confined to fs/smb/client. The counter must balance at every cifsFileInfo acquisition and release of cifs_readdata, cifs_writedata and cifs_aio_ctx; an unbalanced path would make umount(2) wait forever in cifs_kill_sb() (an earlier revision of this port missed the two writeback transfer sites; code review caught it before any write test, which is why they are counted explicitly and the write path was tested separately). The wait runs only at unmount, after the VFS has detached the superblock, so no new I/O can start on it; steady-state I/O paths gain one atomic increment and decrement per request. [ Other Info ] Related but separate: 5520e89a5a4f ("smb: client: fix cifsFileInfo reference leak in deferred close") fixes a refcount leak with a different Fixes: tag; it is not part of this bug. == Evidence (details) == Release: Ubuntu 24.04 LTS (Noble) Package: linux, tested at 6.8.0-137.137 and 6.8.0-146.146 Expected: umount(2) returns and the host continues running. Actual: _cifsFileInfo_put() dereferences an inode after superblock teardown and faults. The host panics with panic_on_oops=1, or later CIFS unmounts hang with panic_on_oops=0. Affected kernels: * Tested: 6.8.0-137.137. We saw 9 production panics on 8 hosts in about 30 hours across about 850 nodes. The lab reproducer panics in 5–90 seconds. * Tested: 6.8.0-146.146 (noble-proposed). The lab reproducer panics in about 10 seconds. * Code-inferred: 6.8.0-136.136, which introduced 340cea84f691c, and 6.8.0-138.138, which predates c68337442f03. * Partial fix from 6.8.0-139.139: c68337442f03 flushes deferredclose_wq only. * Not affected: 6.8.0-111.111. The same workload ran on about 3,800 nodes for 17 days without an occurrence. This kernel predates 340cea84f691c. == Summary == Noble 6.8.0-136 introduced upstream 340cea84f691c ("cifs: open files should not hold ref on superblock", mainline v7.0) via the upstream-stable patchset tracked by LP: #2154496. After this change, a cifs open file holds only a dentry reference. umount(2) can complete while asynchronous work still owns a cifsFileInfo. When that work later calls _cifsFileInfo_put(), the superblock is gone and the kernel faults on the VFS_PTR_POISON value written into the surviving inode. We observed these paths: * (a) deferredclose: smb2_deferred_work_close -> _cifsFileInfo_put. Fixed by c68337442f03 in 6.8.0-139 and later. * (b) cifsiod: cifs_readahead_complete -> _cifsFileInfo_put. Not fixed in any Noble 6.8 kernel through 6.8.0-146. * (c) cifsoplockd: cifs_oplock_break -> _cifsFileInfo_put. This secondary path appeared only after path (b) had already oopsed with panic_on_oops=0. We have not demonstrated it as an independent race. In production on 6.8.0-137, path (b) caused 8 panics and path (a) caused 1. On 6.8.0-146 the reproducer triggers path (b), followed by path (c) when panic_on_oops=0. The proposed fix eliminated this complete reproduced sequence. We do not claim that it fixes a separate oplock race. == Impact == With panic_on_oops=1, the whole host panics. With panic_on_oops=0, the oopsed kworkers do not complete and later CIFS unmounts hang in D state at: __flush_workqueue <- cifs_kill_sb Workloads that mount and unmount SMB shares for each job, such as container workloads, exercise this path continuously. == Kernel log, variant (b) — 6.8.0-137-generic #137-Ubuntu, production == [24042.343670] BUG: Dentry 000000002c909471{i=c34b9,n=<file>} still in use (1) [unmount of cifs cifs] [24042.343678] WARNING: CPU: 28 PID: 1352709 at fs/dcache.c:1528 umount_check+0x64/0x90 [24042.343780] CPU: 28 PID: 1352709 Comm: umount Kdump: loaded Tainted: P OE 6.8.0-137-generic #137-Ubuntu [24042.343783] RIP: 0010:umount_check+0x64/0x90 [24042.343802] d_walk+0xc0/0x2a0 [24042.343810] generic_shutdown_super+0x21/0x180 [24042.343815] cifs_kill_sb+0x5b/0x70 [cifs] [24042.343853] cleanup_mnt+0xc3/0x170 [24042.343938] WARNING: CPU: 28 PID: 1352709 at fs/super.c:649 generic_shutdown_super+0x120/0x180 VFS: Busy inodes after unmount of cifs (cifs) [24043.843507] general protection fault, probably for non-canonical address 0xdead000000000485: 0000 [#1] PREEMPT SMP NOPTI [24043.854484] CPU: 4 PID: 1352168 Comm: kworker/4:1 Kdump: loaded Tainted: P W OE 6.8.0-137-generic #137-Ubuntu [24043.875232] Workqueue: cifsiod cifs_readahead_complete [cifs] [24043.881106] RIP: 0010:_cifsFileInfo_put+0x77/0x4a0 [cifs] [24043.910734] RAX: dead0000000000f5 RBX: ffff8e6ee73a1ea8 RCX: 000000000000000a [24043.983676] cifs_readahead_complete+0x23e/0x2f0 [cifs] [24043.988976] process_one_work+0x181/0x3a0 [24043.993014] worker_thread+0x18b/0x330 [24044.001087] kthread+0xef/0x120 [24044.245052] Kernel panic - not syncing: Fatal exception == Kernel log, variant (a) — 6.8.0-137, production == [17180.976882] BUG: Dentry 00000000e23b32d6{i=34fc,n=<file>} still in use (1) [unmount of cifs cifs] [17180.977008] RIP: 0010:umount_check+0x64/0x90 [17180.977052] cifs_kill_sb+0x5b/0x70 [cifs] [17180.977268] VFS: Busy inodes after unmount of cifs (cifs) [17181.900781] Workqueue: deferredclose smb2_deferred_work_close [cifs] [17181.907243] RIP: 0010:_raw_spin_lock+0x13/0x60 [17182.014078] cifsFileInfo_put_final+0xed/0x120 [cifs] [17182.019221] _cifsFileInfo_put+0x350/0x4a0 [cifs] [17182.028127] smb2_deferred_work_close+0x5f/0x70 [cifs] Kernel panic - not syncing: Fatal exception == Kernel log, variants (b) and (c) == Kernel: 6.8.0-146-generic #146-Ubuntu, lab, panic_on_oops=0 [ 142.574284] general protection fault, probably for non-canonical address 0xdead000000000485: 0000 [#1] PREEMPT SMP NOPTI [ 142.605742] Workqueue: cifsiod cifs_readahead_complete [cifs] [ 142.611633] RIP: 0010:_cifsFileInfo_put+0x77/0x4a0 [cifs] [ 142.857981] general protection fault, probably for non-canonical address 0xdead000000000485: 0000 [#2] PREEMPT SMP NOPTI [ 142.868925] Workqueue: cifsoplockd cifs_oplock_break [cifs] [ 142.868997] RIP: 0010:cifs_oplock_break+0x43/0x620 [cifs] [ 142.888932] RIP: 0010:_cifsFileInfo_put+0x77/0x4a0 [cifs] (preceded by "BUG: Dentry ... still in use (1) [unmount of cifs cifs]" from umount_check) Afterwards on 6.8.0-146: 8 umount processes in D state, all at __flush_workqueue+0x14a/0x3e0 <- cifs_kill_sb+0x3c/0x70 [cifs] <- deactivate_locked_super <- cleanup_mnt == vmcore analysis (6.8.0-146.146, variant b) == Analysis used crash with linux-image-unsigned-6.8.0-146-generic-dbgsym. The faulting instruction at _cifsFileInfo_put+0x77 is the inlined CIFS_SB(inode->i_sb), which reads sb->s_fs_info at offset 0x390. The inode is d_inode(cifs_file->dentry). Objects in the dump: * inode ffff8bb592233680: i_ino=0xec6, matching the "i=ec6" umount_check line; i_nlink=1; i_count=1; i_state=0; still on sb->s_inodes; and i_op = i_sb = i_mapping = 0xdead0000000000f5 (VFS_PTR_POISON). * dentry ffff8bb5861c7380: "<file>"; d_lockref.count=1, held by the cifsFileInfo. * superblock ffff8ab5ae3e9800: type "cifs"; s_count=0; s_active=0; s_root=NULL. * cifsFileInfo ffff8bb551338a00: allocated from kmalloc-512. * cifs_tcon ffff8ab51c791800: allocated. generic_shutdown_super() writes this VFS_PTR_POISON value when CHECK_DATA_CORRUPTION(!list_empty(&sb->s_inodes), "VFS: Busy inodes after unmount") fires at fs/super.c:649-663. The read-ahead cifsFileInfo kept the dentry and inode alive across unmount. The superblock was torn down, and the completion work then dereferenced inode->i_sb. This matches the mechanism addressed by 75f5c412fa86: wait for in-flight requests and drain final-put work before kill_anon_super(). The deferredclose_wq flush from c68337442f03 does not cover cifsiod or cifsoplockd work. The vmcore and vmlinux are available on request. == Reproducer (lab, both 6.8.0-137 and 6.8.0-146) == Server: Dell PowerScale (Isilon) SMB3 share, mounted read-only with -o vers=3.0,sec=krb5,dir_mode=0755,file_mode=0755,noperm, noserverino,nosharesock,cruid=0,nobrl,ro mount.cifs reports: cache=strict,soft,nounix,mapposix,rsize=1048576,wsize=1048576 Loop, N parallel workers, each on its own mount point: 1. Mount the share. 2. Start a sequential read, which queues read-ahead: dd if=<2–3 MB file on the share> of=/dev/null bs=1M & 3. Sleep for 0.01–0.09 seconds, then kill the dd process while I/O is in flight. 4. Open and close another file to leave a deferred close pending: head -c 65536 <another file> >/dev/null 5. Immediately unmount the mount point. 6. Repeat. Results: * 6.8.0-137, 8 workers: panic within about 90 seconds (variant b), with a kdump fingerprint on the BMC. * 6.8.0-137, 4 workers, panic_on_oops=0: oops (b), then (c), within about 5 seconds. * 6.8.0-146, 4 workers for 45 seconds: 5 "Dentry ... still in use" warnings and no fault. * 6.8.0-146, 8 workers: oops (b), then (c), within about 10 seconds. The "still in use" warning occurs several times per minute with 4 workers on 6.8.0-146. The fault requires the deferred work to run after the superblock is freed, so it becomes more likely with parallel workers. == Regression boundary (from the Noble changelog) == * linux 6.8.0-136.136, "Noble update: upstream stable patchset 2026-05-28" (LP: #2154496), added: 340cea84f691c (v7.0) cifs: open files should not hold ref on superblock * linux 6.8.0-139.139, "Noble update: upstream stable patchset 2026-07-09" (LP: #2160250), added: c68337442f03 (v7.1, Cc: stable, Fixes: 340cea84f691c) cifs: Fix busy dentry used after unmounting This commit adds flush_workqueue(deferredclose_wq) in cifs_kill_sb(). It covers variant (a) only. * No Noble 6.8 kernel through 6.8.0-146.146 contains: 75f5c412fa86 (v7.2, Fixes: 340cea84f691c) smb: client: fix busy dentry warning on unmount after DIO This commit adds cifs_sb->outstanding_rreq, waits for in-flight requests, and flushes serverclose_wq and fileinfo_put_wq before kill_anon_super(). This is the mechanism that covers variants (b) and (c). == Request == Track this under CVE-2026-72315, the outstanding-I/O defect fixed by 75f5c412fa86. 1. Apply the attached Noble 6.8 backport of 75f5c412fa86. Noble predates the cifs netfs conversion, so the backport accounts for the cifsFileInfo references held by cifs_readdata, cifs_writedata and cifs_aio_ctx instead of netfs requests. cifs_kill_sb() waits for that per-superblock count to reach zero, then flushes serverclose_wq and fileinfo_put_wq before kill_anon_super(). The patch survived about 76,000 tested cycles. The flush-only alternative still panicked within about 30 seconds with the same cifsiod/cifs_readahead_complete trace. 2. We can validate a candidate kernel within minutes with the attached reproducer. 3. Consider noting in the 6.8.0-136, 6.8.0-137 and 6.8.0-138 release notes that 340cea84f691c shipped without its stable follow-up c68337442f03. Related but separate: 5520e89a5a4f ("smb: client: fix cifsFileInfo reference leak in deferred close", Fixes: c3f207ab29f7) fixes a refcount leak when queue_delayed_work() finds work already pending. It has a different Fixes commit and is not asserted to cause this panic. Please track it separately. == Environment / attachments == Ubuntu 24.04 (Noble), x86_64, HPE ProLiant XL225n Gen10 Plus, in-tree cifs.ko 2.47, and SMB3 to Dell PowerScale. Production mounts and unmounts the share for each cri-o container lifecycle. The lab uses a hand-driven loop. /proc/version_signature reported: Ubuntu 6.8.0-137.137-generic 6.8.12 Ubuntu 6.8.0-146.146-generic 6.8.12 A 3.4 GB kdump vmcore of the 6.8.0-146.146 variant-(b) panic was captured on 2026-09-27 with makedumpfile -c -d 31. It is available on request with the matching vmlinux. Its dmesg is attached. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2168697/+subscriptions
[Bug 2168697] Re: linux (Noble): CIFS unmount use-after-free and panic introduced in 6.8.0-136 (CVE-2026-72315)
** Attachment added: "01-prod-6.8.0-137-crash-panic-context.txt" https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2168697/+attachment/6003227/+files/01-prod-6.8.0-137-crash-panic-context.txt -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2168697 Title: linux (Noble): CIFS unmount use-after-free and panic introduced in 6.8.0-136 (CVE-2026-72315) Status in linux package in Ubuntu: New Bug description: SRU Justification: [ Impact ] Noble 6.8.0-136 backported 340cea84f691 ("cifs: open files should not hold ref on superblock", v7.0) via LP: #2154496. Since then an open cifs file pins only its dentry, so umount(2) can complete while a read-ahead (cifs_readdata on cifsiod_wq), an uncached read/write (cifs_aio_ctx) or a writeback (cifs_writedata) still owns a cifsFileInfo. generic_shutdown_super() finds the inode busy, poisons i_sb with VFS_PTR_POISON, and the later _cifsFileInfo_put() from cifs_readahead_complete() faults on 0xdead0000000000f5 + 0x390. With panic_on_oops=1 the host panics; with panic_on_oops=0 every later umount of a cifs filesystem hangs forever in cifs_kill_sb(). Workloads that mount and unmount SMB shares while a reader is killed (containers, per-job mounts) can hit it. 6.8.0-139 (LP: #2160250) added c68337442f03 ("cifs: Fix busy dentry used after unmounting"), which flushes deferredclose_wq only and covers the deferred-close variant (1 of our 9 production panics). The read-ahead variant (8 of 9) is fixed upstream by 75f5c412fa86 ("smb: client: fix busy dentry warning on unmount after DIO", v7.2, CVE-2026-72315), which is in no Noble 6.8 kernel up to 6.8.0-146 and does not apply as-is because the 6.8 cifs read/write path predates the netfs conversion. Observed: 6.8.0-137 (9 panics / 8 hosts / 30 h on ~850 hosts; lab reproducer panics in 5-90 s) and 6.8.0-146 (lab, ~10 s). Not affected: 6.8.0-111 (same workload, ~3,800 hosts, 0 in 17 days). [ Fix ] Backport of 75f5c412fa86 to the pre-netfs 6.8 code: a per-superblock counter (cifs_sb->outstanding_rreq, as upstream) is taken where a cifs_readdata / cifs_writedata / cifs_aio_ctx acquires its cifsFileInfo reference (including the two writeback sites that transfer an already-held reference) and released after the put in the three release functions. cifs_kill_sb() waits for the counter to reach zero, then flushes serverclose_wq and fileinfo_put_wq before kill_anon_super(), exactly as upstream. A flush-only alternative (flush cifsiod_wq, serverclose_wq, fileinfo_put_wq) was built and tested and still panics: the read request is still on the socket when umount runs, so there is nothing queued to flush. [ Test Plan ] Mount an SMB3 share, start a sequential read of a 2-3 MB file (read-ahead queued), SIGKILL the reader after 1-90 ms, open/close another file, umount immediately; repeat in 4-8 parallel workers on separate mount points (script attached). Stock 6.8.0-137 panics within ~90 s at 8 workers; stock 6.8.0-146 within ~10 s. With the patch on 6.8.0-146.146: ~76,000 cycles against a Dell PowerScale (Isilon) share (krb5, ro) and a Samba share (ro and rw, buffered and O_DIRECT writers, 40-150 ms added server delay) with 0 "Dentry still in use" warnings, 0 faults, 0 hung umounts. We can test a -proposed kernel within minutes. [ Where problems could occur ] The change is confined to fs/smb/client. The counter must balance at every cifsFileInfo acquisition and release of cifs_readdata, cifs_writedata and cifs_aio_ctx; an unbalanced path would make umount(2) wait forever in cifs_kill_sb() (an earlier revision of this port missed the two writeback transfer sites; code review caught it before any write test, which is why they are counted explicitly and the write path was tested separately). The wait runs only at unmount, after the VFS has detached the superblock, so no new I/O can start on it; steady-state I/O paths gain one atomic increment and decrement per request. [ Other Info ] Related but separate: 5520e89a5a4f ("smb: client: fix cifsFileInfo reference leak in deferred close") fixes a refcount leak with a different Fixes: tag; it is not part of this bug. == Evidence (details) == Release: Ubuntu 24.04 LTS (Noble) Package: linux, tested at 6.8.0-137.137 and 6.8.0-146.146 Expected: umount(2) returns and the host continues running. Actual: _cifsFileInfo_put() dereferences an inode after superblock teardown and faults. The host panics with panic_on_oops=1, or later CIFS unmounts hang with panic_on_oops=0. Affected kernels: * Tested: 6.8.0-137.137. We saw 9 production panics on 8 hosts in about 30 hours across about 850 nodes. The lab reproducer panics in 5–90 seconds. * Tested: 6.8.0-146.146 (noble-proposed). The lab reproducer panics in about 10 seconds. * Code-inferred: 6.8.0-136.136, which introduced 340cea84f691c, and 6.8.0-138.138, which predates c68337442f03. * Partial fix from 6.8.0-139.139: c68337442f03 flushes deferredclose_wq only. * Not affected: 6.8.0-111.111. The same workload ran on about 3,800 nodes for 17 days without an occurrence. This kernel predates 340cea84f691c. == Summary == Noble 6.8.0-136 introduced upstream 340cea84f691c ("cifs: open files should not hold ref on superblock", mainline v7.0) via the upstream-stable patchset tracked by LP: #2154496. After this change, a cifs open file holds only a dentry reference. umount(2) can complete while asynchronous work still owns a cifsFileInfo. When that work later calls _cifsFileInfo_put(), the superblock is gone and the kernel faults on the VFS_PTR_POISON value written into the surviving inode. We observed these paths: * (a) deferredclose: smb2_deferred_work_close -> _cifsFileInfo_put. Fixed by c68337442f03 in 6.8.0-139 and later. * (b) cifsiod: cifs_readahead_complete -> _cifsFileInfo_put. Not fixed in any Noble 6.8 kernel through 6.8.0-146. * (c) cifsoplockd: cifs_oplock_break -> _cifsFileInfo_put. This secondary path appeared only after path (b) had already oopsed with panic_on_oops=0. We have not demonstrated it as an independent race. In production on 6.8.0-137, path (b) caused 8 panics and path (a) caused 1. On 6.8.0-146 the reproducer triggers path (b), followed by path (c) when panic_on_oops=0. The proposed fix eliminated this complete reproduced sequence. We do not claim that it fixes a separate oplock race. == Impact == With panic_on_oops=1, the whole host panics. With panic_on_oops=0, the oopsed kworkers do not complete and later CIFS unmounts hang in D state at: __flush_workqueue <- cifs_kill_sb Workloads that mount and unmount SMB shares for each job, such as container workloads, exercise this path continuously. == Kernel log, variant (b) — 6.8.0-137-generic #137-Ubuntu, production == [24042.343670] BUG: Dentry 000000002c909471{i=c34b9,n=<file>} still in use (1) [unmount of cifs cifs] [24042.343678] WARNING: CPU: 28 PID: 1352709 at fs/dcache.c:1528 umount_check+0x64/0x90 [24042.343780] CPU: 28 PID: 1352709 Comm: umount Kdump: loaded Tainted: P OE 6.8.0-137-generic #137-Ubuntu [24042.343783] RIP: 0010:umount_check+0x64/0x90 [24042.343802] d_walk+0xc0/0x2a0 [24042.343810] generic_shutdown_super+0x21/0x180 [24042.343815] cifs_kill_sb+0x5b/0x70 [cifs] [24042.343853] cleanup_mnt+0xc3/0x170 [24042.343938] WARNING: CPU: 28 PID: 1352709 at fs/super.c:649 generic_shutdown_super+0x120/0x180 VFS: Busy inodes after unmount of cifs (cifs) [24043.843507] general protection fault, probably for non-canonical address 0xdead000000000485: 0000 [#1] PREEMPT SMP NOPTI [24043.854484] CPU: 4 PID: 1352168 Comm: kworker/4:1 Kdump: loaded Tainted: P W OE 6.8.0-137-generic #137-Ubuntu [24043.875232] Workqueue: cifsiod cifs_readahead_complete [cifs] [24043.881106] RIP: 0010:_cifsFileInfo_put+0x77/0x4a0 [cifs] [24043.910734] RAX: dead0000000000f5 RBX: ffff8e6ee73a1ea8 RCX: 000000000000000a [24043.983676] cifs_readahead_complete+0x23e/0x2f0 [cifs] [24043.988976] process_one_work+0x181/0x3a0 [24043.993014] worker_thread+0x18b/0x330 [24044.001087] kthread+0xef/0x120 [24044.245052] Kernel panic - not syncing: Fatal exception == Kernel log, variant (a) — 6.8.0-137, production == [17180.976882] BUG: Dentry 00000000e23b32d6{i=34fc,n=<file>} still in use (1) [unmount of cifs cifs] [17180.977008] RIP: 0010:umount_check+0x64/0x90 [17180.977052] cifs_kill_sb+0x5b/0x70 [cifs] [17180.977268] VFS: Busy inodes after unmount of cifs (cifs) [17181.900781] Workqueue: deferredclose smb2_deferred_work_close [cifs] [17181.907243] RIP: 0010:_raw_spin_lock+0x13/0x60 [17182.014078] cifsFileInfo_put_final+0xed/0x120 [cifs] [17182.019221] _cifsFileInfo_put+0x350/0x4a0 [cifs] [17182.028127] smb2_deferred_work_close+0x5f/0x70 [cifs] Kernel panic - not syncing: Fatal exception == Kernel log, variants (b) and (c) == Kernel: 6.8.0-146-generic #146-Ubuntu, lab, panic_on_oops=0 [ 142.574284] general protection fault, probably for non-canonical address 0xdead000000000485: 0000 [#1] PREEMPT SMP NOPTI [ 142.605742] Workqueue: cifsiod cifs_readahead_complete [cifs] [ 142.611633] RIP: 0010:_cifsFileInfo_put+0x77/0x4a0 [cifs] [ 142.857981] general protection fault, probably for non-canonical address 0xdead000000000485: 0000 [#2] PREEMPT SMP NOPTI [ 142.868925] Workqueue: cifsoplockd cifs_oplock_break [cifs] [ 142.868997] RIP: 0010:cifs_oplock_break+0x43/0x620 [cifs] [ 142.888932] RIP: 0010:_cifsFileInfo_put+0x77/0x4a0 [cifs] (preceded by "BUG: Dentry ... still in use (1) [unmount of cifs cifs]" from umount_check) Afterwards on 6.8.0-146: 8 umount processes in D state, all at __flush_workqueue+0x14a/0x3e0 <- cifs_kill_sb+0x3c/0x70 [cifs] <- deactivate_locked_super <- cleanup_mnt == vmcore analysis (6.8.0-146.146, variant b) == Analysis used crash with linux-image-unsigned-6.8.0-146-generic-dbgsym. The faulting instruction at _cifsFileInfo_put+0x77 is the inlined CIFS_SB(inode->i_sb), which reads sb->s_fs_info at offset 0x390. The inode is d_inode(cifs_file->dentry). Objects in the dump: * inode ffff8bb592233680: i_ino=0xec6, matching the "i=ec6" umount_check line; i_nlink=1; i_count=1; i_state=0; still on sb->s_inodes; and i_op = i_sb = i_mapping = 0xdead0000000000f5 (VFS_PTR_POISON). * dentry ffff8bb5861c7380: "<file>"; d_lockref.count=1, held by the cifsFileInfo. * superblock ffff8ab5ae3e9800: type "cifs"; s_count=0; s_active=0; s_root=NULL. * cifsFileInfo ffff8bb551338a00: allocated from kmalloc-512. * cifs_tcon ffff8ab51c791800: allocated. generic_shutdown_super() writes this VFS_PTR_POISON value when CHECK_DATA_CORRUPTION(!list_empty(&sb->s_inodes), "VFS: Busy inodes after unmount") fires at fs/super.c:649-663. The read-ahead cifsFileInfo kept the dentry and inode alive across unmount. The superblock was torn down, and the completion work then dereferenced inode->i_sb. This matches the mechanism addressed by 75f5c412fa86: wait for in-flight requests and drain final-put work before kill_anon_super(). The deferredclose_wq flush from c68337442f03 does not cover cifsiod or cifsoplockd work. The vmcore and vmlinux are available on request. == Reproducer (lab, both 6.8.0-137 and 6.8.0-146) == Server: Dell PowerScale (Isilon) SMB3 share, mounted read-only with -o vers=3.0,sec=krb5,dir_mode=0755,file_mode=0755,noperm, noserverino,nosharesock,cruid=0,nobrl,ro mount.cifs reports: cache=strict,soft,nounix,mapposix,rsize=1048576,wsize=1048576 Loop, N parallel workers, each on its own mount point: 1. Mount the share. 2. Start a sequential read, which queues read-ahead: dd if=<2–3 MB file on the share> of=/dev/null bs=1M & 3. Sleep for 0.01–0.09 seconds, then kill the dd process while I/O is in flight. 4. Open and close another file to leave a deferred close pending: head -c 65536 <another file> >/dev/null 5. Immediately unmount the mount point. 6. Repeat. Results: * 6.8.0-137, 8 workers: panic within about 90 seconds (variant b), with a kdump fingerprint on the BMC. * 6.8.0-137, 4 workers, panic_on_oops=0: oops (b), then (c), within about 5 seconds. * 6.8.0-146, 4 workers for 45 seconds: 5 "Dentry ... still in use" warnings and no fault. * 6.8.0-146, 8 workers: oops (b), then (c), within about 10 seconds. The "still in use" warning occurs several times per minute with 4 workers on 6.8.0-146. The fault requires the deferred work to run after the superblock is freed, so it becomes more likely with parallel workers. == Regression boundary (from the Noble changelog) == * linux 6.8.0-136.136, "Noble update: upstream stable patchset 2026-05-28" (LP: #2154496), added: 340cea84f691c (v7.0) cifs: open files should not hold ref on superblock * linux 6.8.0-139.139, "Noble update: upstream stable patchset 2026-07-09" (LP: #2160250), added: c68337442f03 (v7.1, Cc: stable, Fixes: 340cea84f691c) cifs: Fix busy dentry used after unmounting This commit adds flush_workqueue(deferredclose_wq) in cifs_kill_sb(). It covers variant (a) only. * No Noble 6.8 kernel through 6.8.0-146.146 contains: 75f5c412fa86 (v7.2, Fixes: 340cea84f691c) smb: client: fix busy dentry warning on unmount after DIO This commit adds cifs_sb->outstanding_rreq, waits for in-flight requests, and flushes serverclose_wq and fileinfo_put_wq before kill_anon_super(). This is the mechanism that covers variants (b) and (c). == Request == Track this under CVE-2026-72315, the outstanding-I/O defect fixed by 75f5c412fa86. 1. Apply the attached Noble 6.8 backport of 75f5c412fa86. Noble predates the cifs netfs conversion, so the backport accounts for the cifsFileInfo references held by cifs_readdata, cifs_writedata and cifs_aio_ctx instead of netfs requests. cifs_kill_sb() waits for that per-superblock count to reach zero, then flushes serverclose_wq and fileinfo_put_wq before kill_anon_super(). The patch survived about 76,000 tested cycles. The flush-only alternative still panicked within about 30 seconds with the same cifsiod/cifs_readahead_complete trace. 2. We can validate a candidate kernel within minutes with the attached reproducer. 3. Consider noting in the 6.8.0-136, 6.8.0-137 and 6.8.0-138 release notes that 340cea84f691c shipped without its stable follow-up c68337442f03. Related but separate: 5520e89a5a4f ("smb: client: fix cifsFileInfo reference leak in deferred close", Fixes: c3f207ab29f7) fixes a refcount leak when queue_delayed_work() finds work already pending. It has a different Fixes commit and is not asserted to cause this panic. Please track it separately. == Environment / attachments == Ubuntu 24.04 (Noble), x86_64, HPE ProLiant XL225n Gen10 Plus, in-tree cifs.ko 2.47, and SMB3 to Dell PowerScale. Production mounts and unmounts the share for each cri-o container lifecycle. The lab uses a hand-driven loop. /proc/version_signature reported: Ubuntu 6.8.0-137.137-generic 6.8.12 Ubuntu 6.8.0-146.146-generic 6.8.12 A 3.4 GB kdump vmcore of the 6.8.0-146.146 variant-(b) panic was captured on 2026-09-27 with makedumpfile -c -d 31. It is available on request with the matching vmlinux. Its dmesg is attached. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2168697/+subscriptions