WARNING in tcp_recvmsg

4 views
Skip to first unread message

syzbot

unread,
Apr 13, 2019, 8:00:42 PM4/13/19
to syzkaller-a...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 498bf612 ANDROID: zram: set comp_len to PAGE_SIZE when pag..
git tree: android-4.4
console output: https://syzkaller.appspot.com/x/log.txt?x=155876f5400000
kernel config: https://syzkaller.appspot.com/x/.config?x=91537011cdb01073
dashboard link: https://syzkaller.appspot.com/bug?extid=d4d3eac861564e096138
compiler: gcc (GCC) 8.0.1 20180413 (experimental)
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=13ca0d33400000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=14e0e26d400000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+d4d3ea...@syzkaller.appspotmail.com

WARNING: CPU: 0 PID: 8914 at net/ipv4/tcp.c:1738 tcp_recvmsg+0x21e7/0x2de0
net/ipv4/tcp.c:1737()

0000000000000000 04acfed235a08304 ffff8801d9c1f770 ffffffff81aa556d
ffffffff828354e0 ffff8800b8e597c0 ffffffff82a7c7c0 0000000000000009
00000000000006ca ffff8801d9c1f830 ffffffff813a1544 0000000041b58ab3
Call Trace:
[<ffffffff81aa556d>] __dump_stack lib/dump_stack.c:15 [inline]
[<ffffffff81aa556d>] dump_stack+0xc1/0x124 lib/dump_stack.c:51
[<ffffffff813a1544>] panic+0x19e/0x359 kernel/panic.c:112
[<ffffffff813a1734>] warn_slowpath_common.cold.6+0x20/0x20
kernel/panic.c:455
[<ffffffff810d4289>] warn_slowpath_null+0x29/0x30 kernel/panic.c:492
[<ffffffff823ee8b7>] tcp_recvmsg+0x21e7/0x2de0 net/ipv4/tcp.c:1737
[<ffffffff824a233e>] inet_recvmsg+0x23e/0x4c0 net/ipv4/af_inet.c:786
[<ffffffff821d03e1>] sock_recvmsg_nosec net/socket.c:740 [inline]
[<ffffffff821d03e1>] sock_recvmsg+0x91/0xc0 net/socket.c:748
[<ffffffff821d1bd5>] ___sys_recvmsg+0x265/0x550 net/socket.c:2129
[<ffffffff821d4da6>] __sys_recvmsg+0xd6/0x190 net/socket.c:2175
[<ffffffff821d4e8d>] SYSC_recvmsg net/socket.c:2187 [inline]
[<ffffffff821d4e8d>] SyS_recvmsg+0x2d/0x50 net/socket.c:2182
[<ffffffff827123e1>] entry_SYSCALL_64_fastpath+0x1e/0x9a
Kernel Offset: disabled
Rebooting in 86400 seconds..


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this bug, for details see:
https://goo.gl/tpsmEJ#testing-patches
Reply all
Reply to author
Forward
0 new messages