Control: tags -1 + moreinfo

Hi,

On Sun, Mar 15, 2026 at 01:19:02PM +0100, Christophe Combelles wrote:
> Package: src:linux
> Version: 6.18.12-1~bpo13+1
> Severity: critical
> Tags: upstream
> Justification: breaks the whole system
> X-Debbugs-Cc: [email protected]
> User: [email protected]
> Usertags: amd64
> 
> Dear Maintainer,
> 
> Got a kernel panic just after plugging a 5 Bay USB Docking Station
> (Sabrent DS-5R15) with 5 BTRFS raid1 disks. I heard and saw the kernel 
> starting to read the disks (though I don't have automounting configured),
> then the large qrcode appeared, which is copied below.
> 
> 
> -- Package-specific info:
> ** Kernel log:
> 
> [531223.838390]  snd_hda_codec_generic snd_hda_codec_atihdmi kvm_amd btintel 
> videobuf2_vmalloc snd_hda_codec_hdmi snd_soc_core mt76 uvc videobuf2_memops 
> videobuf2_v4l2 snd_hda_intel snd_compress videodev snd_pcm_dmaengine kvm 
> bluetooth snd_hda_codec snd_rpl_pci_acp6x videobuf2_common snd_hda_core 
> snd_acp_pci mac80211 gpio_keys mc ecdh_generic irqbypass snd_amd_acpi_mach 
> snd_ctl_led snd_intel_dspcfg ghash_clmulni_intel snd_acp_legacy_common 
> snd_intel_sdw_acpi aesni_intel think_lmi snd_pci_acp6x snd_hwdep rapl snd_pcm 
> cfg80211 thinkpad_acpi snd_pci_acp5x amd_pmf firmware_attributes_class amdtee 
> nvram snd_rn_pci_acp3x snd_timer wmi_bmof sparse_keymap snd_acp_config 
> spd5118 amdxdna pcspkr snd_soc_acpi snd rfkill ccp k10temp libarc4 
> drm_shmem_helper snd_pci_acp3x soundcore amd_sfh ac tee joydev amd_pmc 
> platform_profile soc_button_array evdev msr parport_pc ppdev dm_mod lp 
> parport efi_pstore configfs nfnetlink ip_tables x_tables autofs4 
> crc32c_cryptoapi btrfs blake2b_generic raid10 raid456 async_raid6_recov 
> async_memcpy
> [531223.838449]  async_pq async_xor async_tx xor raid6_pq raid1 raid0 md_mod 
> usbhid amdgpu amdxcp drm_panel_backlight_quirks gpu_sched drm_buddy 
> drm_ttm_helper ttm ucsi_acpi drm_exec typec_ucsi i2c_algo_bit 
> drm_suballoc_helper drm_display_helper typec hid_multitouch nvme cec 
> hid_generic roles rc_core drm_client_lib xhci_pci i2c_hid_acpi nvme_core 
> drm_kms_helper i2c_hid xhci_hcd hid sp5100_tco r8169 psmouse nvme_keyring 
> watchdog thunderbolt usbcore drm nvme_auth i2c_piix4 serio_raw realtek video 
> crc16 battery hkdf usb_common i2c_smbus button fan wmi efivarfs
> [531223.838490] CPU: 12 UID: 0 PID: 1 Comm: systemd Tainted: G      D         
>     6.18.12+deb13-amd64 #1 PREEMPT(lazy)  Debian 6.18.12-1~bpo13+1 
> [531223.838495] Tainted: [D]=DIE
> [531223.838496] Hardware name: LENOVO 21RVCTO1WW/21RVCTO1WW, BIOS R2XET37W 
> (1.17 ) 11/07/2025
> [531223.838498] RIP: 0010:__queue_work+0x48f/0x4d0
> [531223.838501] Code: e8 76 3d fd ff 0f 0b e9 4b fc ff ff 48 8b 73 18 48 8d 
> 95 c0 00 00 00 48 c7 c7 18 e6 1d 9d c6 05 35 f2 f6 01 01 e8 51 3d fd ff <0f> 
> 0b e9 c8 fe ff ff 4c 89 fe 48 c7 c7 80 d4 a6 9d e8 1b 3b 76 00
> [531223.838503] RSP: 0000:ffffd04e800bfd70 EFLAGS: 00010086
> [531223.838505] RAX: 0000000000000000 RBX: ffff8f21c811c808 RCX: 
> 0000000000000027
> [531223.838507] RDX: ffff8f3565f1ce48 RSI: 0000000000000001 RDI: 
> ffff8f3565f1ce40
> [531223.838508] RBP: ffff8f208774d800 R08: 0000000000000000 R09: 
> 0000000000000000
> [531223.838509] R10: 65756575716b726f R11: 756575716b726f77 R12: 
> 0000000000002000
> [531223.838511] R13: 0000000000000296 R14: 0000000000004000 R15: 
> ffff8f21c811c838
> [531223.838512] FS:  00007f370c041540(0000) GS:ffff8f35c7876000(0000) 
> knlGS:0000000000000000
> [531223.838514] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
> [531223.838515] CR2: 0000560a40e64130 CR3: 000000015282e000 CR4: 
> 0000000000f50ef0
> [531223.838517] PKRU: 55555554
> [531223.838518] Call Trace:
> [531223.838521]  <TASK>
> [531223.838525]  queue_work_on+0x65/0x70
> [531223.838528]  blk_update_request+0x17a/0x410
> [531223.838532]  ? __x64_sys_recvfrom+0x24/0x30
> [531223.838536]  ? do_syscall_64+0xbc/0x800
> [531223.838540]  scsi_end_request+0x27/0x1a0 [scsi_mod]
> [531223.838554]  scsi_io_completion+0x53/0x630 [scsi_mod]
> [531223.838565]  blk_done_softirq+0x4d/0x60
> [531223.838568]  handle_softirqs+0xdf/0x320
> [531223.838572]  ? __flush_smp_call_function_queue+0xf0/0x400
> [531223.838575]  __irq_exit_rcu+0xbc/0xe0
> [531223.838577]  sysvec_call_function_single+0x3d/0x90
> [531223.838581]  asm_sysvec_call_function_single+0x1a/0x20
> [531223.838583] RIP: 0033:0x7f370be20a0b
> [531223.838627] Code: 12 d8 48 31 f0 48 c1 c6 20 66 0f 73 d9 08 66 48 0f 7e 
> da 66 0f d4 c8 48 c1 c2 10 66 48 0f 7e c9 48 31 ca 48 01 d6 48 c1 c2 15 <48> 
> 31 f2 48 89 37 48 89 57 18 48 8d 14 08 48 c1 c0 11 48 31 d0 48
> [531223.838629] RSP: 002b:00007ffe5d3bc818 EFLAGS: 00000a02
> [531223.838630] RAX: a53b0a1c7c07e2cd RBX: 00007ffe5d3bc840 RCX: 
> 3b03d2408ea06e14
> [531223.838632] RDX: 8ca04d8849514d00 RSI: 112314df91773e8c RDI: 
> 00007ffe5d3bc840
> [531223.838633] RBP: 0e00005245564952 R08: d40e6c20411e8844 R09: 
> e9959a9a2aab32bf
> [531223.838634] R10: 9ca8d33c67d3bad5 R11: 0000000000000000 R12: 
> 0000560a40ec0fd0
> [531223.838635] R13: 0000560a40f426e0 R14: 0000560a40ec0ff0 R15: 
> 0000560a40ec0fd0
> [531223.838637]  </TASK>
> [531223.838639] ---[ end trace 0000000000000000 ]---
> [531224.033714] RIP: 0010:percpu_counter_add_batch+0x13/0xa0
> [531224.033730] Code: 1f 84 00 00 00 00 00 90 90 90 90 90 90 90 90 90 90 90 
> 90 90 90 90 90 f3 0f 1e fa 55 48 89 fd 4c 63 c2 53 48 8b 7f 20 48 89 f3 <65> 
> 48 63 37 48 8d 0c 1e 48 89 f0 49 89 f1 48 89 ca 48 f7 da 48 0f
> [531224.033732] RSP: 0018:ffffd04e80003e68 EFLAGS: 00010286
> [531224.033735] RAX: ffffffffc2106710 RBX: ffffffffffffffff RCX: 
> ffff8f213913bd80
> [531224.033736] RDX: 0000000000000030 RSI: ffffffffffffffff RDI: 
> 0000000000000000
> [531224.033737] RBP: ffff8f22b7b88c00 R08: 0000000000000030 R09: 
> 0000000000000200
> [531224.033738] R10: 0000000000004650 R11: ffffffff9da080c0 R12: 
> ffff8f26657afc00
> [531224.033739] R13: ffff8f2663494380 R14: 0000000000004000 R15: 
> ffff8f24f969b238
> [531224.033740] FS:  0000000000000000(0000) GS:ffff8f35c7576000(0000) 
> knlGS:0000000000000000
> [531224.033741] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
> [531224.033742] CR2: ffff8f35c7576000 CR3: 0000000673c2c000 CR4: 
> 0000000000f50ef0
> [531224.033743] PKRU: 55555554
> [531224.033745] Kernel panic - not syncing: Fatal exception in interrupt
> [531224.033864] Kernel Offset: 0x1aa00000 from 0xffffffff81000000 (relocation 
> range: 0xffffffff80000000-0xffffffffbfffffff)

AFAICS above, there should not have been the first message, as the
kernel was already tainted. 

So a couple of question: 

- Can you reproduce the issue, and can you get a complete log from the
  beginning of the log?
- Is that a regression for an earlier kernel, which is the last one
  which works?
- 6.18.12-1~bpo13+1 is not a current kernel, can you reproduce the
  issue with the most current kernel in backports? Ideally please as
  well test the current 6.19.8-1 in unstable and report back if the
  problem is triggerable there as well (if yes, the full log from this
  is valuable to potentially make an upstream report).

Rgards,
Salvatore

Reply via email to