panic: 2528 callbacks suppressed

51 views
Skip to first unread message

syzbot

unread,
Nov 6, 2019, 2:36:10 PM11/6/19
to syzkaller-a...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 8fe42840 Merge 4.9.141 into android-4.9
git tree: android-4.9
console output: https://syzkaller.appspot.com/x/log.txt?x=1105a89ae00000
kernel config: https://syzkaller.appspot.com/x/.config?x=22a5ba9f73b6da1d
dashboard link: https://syzkaller.appspot.com/bug?extid=b172ee91a9334dc51c4e
compiler: gcc (GCC) 8.0.1 20180413 (experimental)

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+b172ee...@syzkaller.appspotmail.com

audit_panic: 2528 callbacks suppressed
audit: printk limit exceeded
audit: type=1400 audit(1573065316.735:86444): avc: denied { net_admin }
for pid=2077 comm="syz-executor.3" capability=12
scontext=unconfined_u:system_r:insmod_t:s0-s0:c0.c1023
tcontext=unconfined_u:system_r:insmod_t:s0-s0:c0.c1023 tclass=cap_userns
permissive=1
audit: type=1400 audit(1573065316.735:86445): avc: denied { net_admin }
for pid=2077 comm="syz-executor.3" capability=12
scontext=unconfined_u:system_r:insmod_t:s0-s0:c0.c1023
tcontext=unconfined_u:system_r:insmod_t:s0-s0:c0.c1023 tclass=cap_userns
permissive=1
audit: type=1400 audit(1573065316.745:86446): avc: denied { sys_admin }
for pid=26362 comm="syz-executor.0" capability=21
scontext=unconfined_u:system_r:insmod_t:s0-s0:c0.c1023
tcontext=unconfined_u:system_r:insmod_t:s0-s0:c0.c1023 tclass=cap_userns
permissive=1
audit: type=1400 audit(1573065316.745:86447): avc: denied { sys_admin }
for pid=26362 comm="syz-executor.0" capability=21
scontext=unconfined_u:system_r:insmod_t:s0-s0:c0.c1023
tcontext=unconfined_u:system_r:insmod_t:s0-s0:c0.c1023 tclass=cap_userns
permissive=1
audit: type=1400 audit(1573065316.745:86448): avc: denied { sys_admin }
for pid=2066 comm="syz-executor.5" capability=21
scontext=unconfined_u:system_r:insmod_t:s0-s0:c0.c1023
tcontext=unconfined_u:system_r:insmod_t:s0-s0:c0.c1023 tclass=cap_userns
permissive=1
audit: type=1400 audit(1573065316.745:86449): avc: denied { sys_admin }
for pid=2066 comm="syz-executor.5" capability=21
scontext=unconfined_u:system_r:insmod_t:s0-s0:c0.c1023
tcontext=unconfined_u:system_r:insmod_t:s0-s0:c0.c1023 tclass=cap_userns
permissive=1
audit: type=1400 audit(1573065316.755:86450): avc: denied { net_admin }
for pid=2077 comm="syz-executor.3" capability=12
scontext=unconfined_u:system_r:insmod_t:s0-s0:c0.c1023
tcontext=unconfined_u:system_r:insmod_t:s0-s0:c0.c1023 tclass=cap_userns
permissive=1
audit: type=1400 audit(1573065316.755:86451): avc: denied { net_admin }
for pid=2077 comm="syz-executor.3" capability=12
scontext=unconfined_u:system_r:insmod_t:s0-s0:c0.c1023
tcontext=unconfined_u:system_r:insmod_t:s0-s0:c0.c1023 tclass=cap_userns
permissive=1
audit: type=1400 audit(1573065316.755:86452): avc: denied { net_admin }
for pid=2077 comm="syz-executor.3" capability=12
scontext=unconfined_u:system_r:insmod_t:s0-s0:c0.c1023
tcontext=unconfined_u:system_r:insmod_t:s0-s0:c0.c1023 tclass=cap_userns
permissive=1
------------[ cut here ]------------
WARNING: CPU: 0 PID: 26366 at mm/page_alloc.c:3556 __alloc_pages_slowpath
mm/page_alloc.c:3556 [inline]
WARNING: CPU: 0 PID: 26366 at mm/page_alloc.c:3556
__alloc_pages_nodemask+0x13a0/0x1bd0 mm/page_alloc.c:3862
Kernel panic - not syncing: panic_on_warn set ...

CPU: 0 PID: 26366 Comm: syz-executor.0 Not tainted 4.9.141+ #1
ffff88019b996ec0 ffffffff81b42e79 ffffffff82a38ce0 00000000ffffffff
ffffffff82a96600 0000000000000000 0000000000000009 ffff88019b996f80
ffffffff813f7125 0000000041b58ab3 ffffffff82e2b62b ffffffff813f6f66
Call Trace:
[<ffffffff81b42e79>] __dump_stack lib/dump_stack.c:15 [inline]
[<ffffffff81b42e79>] dump_stack+0xc1/0x128 lib/dump_stack.c:51
[<ffffffff813f7125>] panic+0x1bf/0x39f kernel/panic.c:179
[<ffffffff813f7362>] __warn.cold.8+0x2f/0x2f kernel/panic.c:542
[<ffffffff810dc02c>] warn_slowpath_null+0x2c/0x40 kernel/panic.c:585
[<ffffffff81429420>] __alloc_pages_slowpath mm/page_alloc.c:3556 [inline]
[<ffffffff81429420>] __alloc_pages_nodemask+0x13a0/0x1bd0
mm/page_alloc.c:3862
[<ffffffff8147936a>] __alloc_pages include/linux/gfp.h:433 [inline]
[<ffffffff8147936a>] __alloc_pages_node include/linux/gfp.h:446 [inline]
[<ffffffff8147936a>] alloc_pages_node include/linux/gfp.h:460 [inline]
[<ffffffff8147936a>] kmalloc_order+0x2a/0x70 mm/slab_common.c:1043
[<ffffffff814793cf>] kmalloc_order_trace+0x1f/0x190 mm/slab_common.c:1054
[<ffffffff814ee36e>] kmalloc_large include/linux/slab.h:422 [inline]
[<ffffffff814ee36e>] __kmalloc+0x1ae/0x310 mm/slub.c:3730
[<ffffffff81a20c19>] kmalloc include/linux/slab.h:495 [inline]
[<ffffffff81a20c19>] str_read+0x39/0x150
security/selinux/ss/policydb.c:1100
[<ffffffff81a26317>] perm_read.isra.7+0x1b7/0x2b0
security/selinux/ss/policydb.c:1135
[<ffffffff81a26754>] class_read+0x344/0x940
security/selinux/ss/policydb.c:1361
[<ffffffff81a2b1ea>] policydb_read+0xdba/0x2390
security/selinux/ss/policydb.c:2367
[<ffffffff81a3ba84>] security_load_policy+0x264/0x9b0
security/selinux/ss/services.c:2067
[<ffffffff81a1233b>] sel_write_load+0x19b/0xfa0
security/selinux/selinuxfs.c:522
[<ffffffff81508085>] __vfs_write+0x115/0x580 fs/read_write.c:507
[<ffffffff8150ab97>] vfs_write+0x187/0x520 fs/read_write.c:557
[<ffffffff8150e9c9>] SYSC_write fs/read_write.c:604 [inline]
[<ffffffff8150e9c9>] SyS_write+0xd9/0x1c0 fs/read_write.c:596
[<ffffffff810056ef>] do_syscall_64+0x19f/0x550 arch/x86/entry/common.c:285
[<ffffffff82817893>] entry_SYSCALL_64_after_swapgs+0x5d/0xdb
Kernel Offset: disabled
Rebooting in 86400 seconds..


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Mar 5, 2020, 1:36:07 PM3/5/20
to syzkaller-a...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages