Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #88819 > unrolled thread

Bug#1111017: linux 6.1.147 hangs when loading audit rules / booting

Started bySalvatore Bonaccorso <carnil@debian.org>
First post2025-08-14 10:00 +0200
Last post2025-08-15 14:30 +0200
Articles 3 — 1 participant

Back to article view | Back to linux.debian.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Bug#1111017: linux 6.1.147 hangs when loading audit rules / booting Salvatore Bonaccorso <carnil@debian.org> - 2025-08-14 10:00 +0200
    Bug#1111017: linux 6.1.147 hangs when loading audit rules / booting Salvatore Bonaccorso <carnil@debian.org> - 2025-08-14 10:50 +0200
      Bug#1111017: linux 6.1.147 hangs when loading audit rules / booting Salvatore Bonaccorso <carnil@debian.org> - 2025-08-15 14:30 +0200

#88819 — Bug#1111017: linux 6.1.147 hangs when loading audit rules / booting

FromSalvatore Bonaccorso <carnil@debian.org>
Date2025-08-14 10:00 +0200
SubjectBug#1111017: linux 6.1.147 hangs when loading audit rules / booting
Message-ID<LjB2p-7vAp-1@gated-at.bofh.it>
Hi,

On Wed, Aug 13, 2025 at 05:41:03PM +0200, Julian Taylor wrote:
> Package: linux-signed-amd64
> Version: 6.1.147-1
> Severity: important
> 
> hello
> the update to 6.1.147 https://lists.debian.org/debian-security-announce/2025/msg00137.html fully hangs the
> machine when auditd rules are loaded (also during boot).
> 
> To reproduce boot into this kernel, install auditd and run:
> $ cat /etc/audit/audit.rules
> -D
> -b 8192
> -f 1
> --backlog_wait_time 60000
> -a always,exit -F arch=b64 -F dir=/var/log/audit/ -F perm=wa  -F auid!=4294967295 -k T1005_Data_From_Local_System_audit_log
> $ auditctl -R /etc/audit/audit.rules
> $ systemctl restart auditd
> 
> 
> It is highly likely to freeze the machine or at least a cpu after a few tries:
>  kernel:[22824.150267] watchdog: BUG: soft lockup - CPU#1 stuck for 48s! [kauditd:28]
> 
> 
> This appears to be a regression introduced in upstream commit ae8f160e7eb2
> This was reported also on amazon linux https://github.com/amazonlinux/amazon-linux-2023/issues/988
> and shows itself in the same way in debian bookworm
> amazon linux revert the commit https://github.com/amazonlinux/linux/commit/585be8ae62c8c0cf802d2a60d49a9878ce41478d
> 
> 
> 
> According to upstream fixes tags this commit upstream should fix the problem:
> https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=759dfc7d04ba
> 
> I have tested this commit added onto the debian 6.1.147-1 kernel package and cannot reproduce the problem anymore.

Thanks for confirming the required fix. I believe this affects as well
other stable series, and in particular as well 6.12.41-1 in trixie and
the curren experimental version.

It looks while the fixing commit was CC'ed to stable, it was not in
time for the current round of stable update reviews. Will have a look.

Regards,
Salvatore

[toc] | [next] | [standalone]


#88822

FromSalvatore Bonaccorso <carnil@debian.org>
Date2025-08-14 10:50 +0200
Message-ID<LjBON-7w9o-17@gated-at.bofh.it>
In reply to#88819
Hi,

On Thu, Aug 14, 2025 at 09:58:47AM +0200, Julian Taylor wrote:
> On 14.08.25 09:48, Salvatore Bonaccorso wrote:
> > Hi,
> > 
> > On Wed, Aug 13, 2025 at 05:41:03PM +0200, Julian Taylor wrote:
> > > Package: linux-signed-amd64
> > > Version: 6.1.147-1
> > > Severity: important
> > > 
> ..
> > > 
> > > 
> > > According to upstream fixes tags this commit upstream should fix the problem:
> > > https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=759dfc7d04ba
> > > 
> > > I have tested this commit added onto the debian 6.1.147-1 kernel package and cannot reproduce the problem anymore.
> > 
> > Thanks for confirming the required fix. I believe this affects as well
> > other stable series, and in particular as well 6.12.41-1 in trixie and
> > the curren experimental version.
> > 
> > It looks while the fixing commit was CC'ed to stable, it was not in
> > time for the current round of stable update reviews. Will have a look.
> > 
> 
> I have tried Debian trixie 6.12.41+deb13-amd64 and have so far not
> been able to reproduce it in the same way with auditd, though this
> could also be due to changes in auditd.

Yes sorry I was imprecise. What I meant is that I believe the
underlying bug is present in other stable series as well, as the
commit referenced in the Fixes tag was backported to the various
stable series.

Regards,
Salvatore

[toc] | [prev] | [next] | [standalone]


#88828

FromSalvatore Bonaccorso <carnil@debian.org>
Date2025-08-15 14:30 +0200
Message-ID<Lk1Jf-7NFB-1@gated-at.bofh.it>
In reply to#88822
On Thu, Aug 14, 2025 at 03:06:32PM +0200, Julian Taylor wrote:
> On 14.08.25 10:41, Salvatore Bonaccorso wrote:
> > Hi,
> > 
> > On Thu, Aug 14, 2025 at 09:58:47AM +0200, Julian Taylor wrote:
> > > On 14.08.25 09:48, Salvatore Bonaccorso wrote:
> > > > Hi,
> > > > 
> > > > On Wed, Aug 13, 2025 at 05:41:03PM +0200, Julian Taylor wrote:
> > > > > Package: linux-signed-amd64
> > > > > Version: 6.1.147-1
> > > > > Severity: important
> > > > > 
> > > ..
> > > > > 
> > > > > 
> > > > > According to upstream fixes tags this commit upstream should fix the problem:
> > > > > https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=759dfc7d04ba
> > > > > 
> > > > > I have tested this commit added onto the debian 6.1.147-1 kernel package and cannot reproduce the problem anymore.
> > > > 
> > > > Thanks for confirming the required fix. I believe this affects as well
> > > > other stable series, and in particular as well 6.12.41-1 in trixie and
> > > > the curren experimental version.
> > > > 
> > > > It looks while the fixing commit was CC'ed to stable, it was not in
> > > > time for the current round of stable update reviews. Will have a look.
> > > > 
> > > 
> > > I have tried Debian trixie 6.12.41+deb13-amd64 and have so far not
> > > been able to reproduce it in the same way with auditd, though this
> > > could also be due to changes in auditd.
> > 
> > Yes sorry I was imprecise. What I meant is that I believe the
> > underlying bug is present in other stable series as well, as the
> > commit referenced in the Fixes tag was backported to the various
> > stable series.
> > 
> 
> I have sent a mail to the upstream inquiring about the stable patch status as 6.1.148 is already in review witout it.
> 
> https://lore.kernel.org/all/9fa0c0ea-9c5d-4039-856f-222486283a3c@1und1.de/

Thanks seen that, and will be queued for the next round of updates.
Depending on when the next update happens (there will be soon upcoming
a point release), either cherry-picking this or rebaing to 6.1.149+.

It will be queued:
https://lore.kernel.org/stable/2025081448-version-excursion-1456@gregkh/

Regards,
Salvatore

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.kernel


csiph-web