WARNING in xfrm_policy_fini

27 views
Skip to first unread message

syzbot

unread,
Apr 12, 2019, 8:01:26 PM4/12/19
to syzkaller-a...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 666c420f FROMLIST: ANDROID: binder: Add BINDER_GET_NODE_IN..
git tree: android-4.14
console output: https://syzkaller.appspot.com/x/log.txt?x=1475dd2a400000
kernel config: https://syzkaller.appspot.com/x/.config?x=89d929f317ea847c
dashboard link: https://syzkaller.appspot.com/bug?extid=1e51ad54cd276f4e37ad
compiler: gcc (GCC) 8.0.1 20180413 (experimental)

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+1e51ad...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 1 PID: 12569 at net/xfrm/xfrm_policy.c:3004
xfrm_policy_fini+0x1f3/0x260 net/xfrm/xfrm_policy.c:3004
Kernel panic - not syncing: panic_on_warn set ...

CPU: 1 PID: 12569 Comm: kworker/u4:7 Not tainted 4.14.71+ #8
Workqueue: netns cleanup_net
Call Trace:
__dump_stack lib/dump_stack.c:17 [inline]
dump_stack+0xb9/0x11b lib/dump_stack.c:53
panic+0x1bf/0x3a4 kernel/panic.c:181
__warn.cold.7+0x148/0x185 kernel/panic.c:542
report_bug+0x1f7/0x26c lib/bug.c:186
fixup_bug arch/x86/kernel/traps.c:177 [inline]
do_error_trap+0x1ba/0x2c0 arch/x86/kernel/traps.c:295
invalid_op+0x18/0x40 arch/x86/entry/entry_64.S:944
RIP: 0010:xfrm_policy_fini+0x1f3/0x260 net/xfrm/xfrm_policy.c:3004
RSP: 0018:ffff8801c2a1fb90 EFLAGS: 00010297
RAX: ffff8801ce300000 RBX: ffff8801a4f2b530 RCX: 1ffff10039c60114
RDX: 0000000000000000 RSI: ffff8801ce300880 RDI: ffff8801ce30082c
RBP: ffffffffaec366a0 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: ffff8801c2a1fce8
R13: ffffffffafdf6758 R14: ffff8801a4f29d80 R15: fffffbfff5fbeceb
xfrm_net_exit+0x19/0x30 net/xfrm/xfrm_policy.c:3059
ops_exit_list.isra.3+0xa8/0x150 net/core/net_namespace.c:142
cleanup_net+0x3e9/0x880 net/core/net_namespace.c:483
process_one_work+0x86e/0x15c0 kernel/workqueue.c:2114
worker_thread+0xdc/0x1000 kernel/workqueue.c:2248
kthread+0x348/0x420 kernel/kthread.c:232
ret_from_fork+0x3a/0x50 arch/x86/entry/entry_64.S:402
Kernel Offset: 0x2c600000 from 0xffffffff81000000 (relocation range:
0xffffffff80000000-0xffffffffbfffffff)
Rebooting in 86400 seconds..


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Apr 14, 2019, 4:51:37 AM4/14/19
to syzkaller-a...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: a5fc6659 Merge 4.4.147 into android-4.4
git tree: android-4.4
console output: https://syzkaller.appspot.com/x/log.txt?x=1716fb52400000
kernel config: https://syzkaller.appspot.com/x/.config?x=9404302f0450302a
dashboard link: https://syzkaller.appspot.com/bug?extid=7e1c089729a323b110f7
compiler: gcc (GCC) 8.0.1 20180413 (experimental)

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+7e1c08...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 0 PID: 13077 at net/xfrm/xfrm_policy.c:2976
xfrm_policy_fini+0x280/0x310 net/xfrm/xfrm_policy.c:2976()
Kernel panic - not syncing: panic_on_warn set ...

CPU: 0 PID: 13077 Comm: kworker/u4:7 Not tainted 4.4.147-ga5fc665 #80
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
Workqueue: netns cleanup_net
0000000000000000 5329f26df08337eb ffff8800a26f7940 ffffffff81e12a4d
ffffffff83a44d40 ffff8801b9926000 ffffffff83f25c20 0000000000000009
0000000000000ba0 ffff8800a26f7a00 ffffffff8140c6a4 0000000041b58ab3
Call Trace:
[<ffffffff81e12a4d>] __dump_stack lib/dump_stack.c:15 [inline]
[<ffffffff81e12a4d>] dump_stack+0xc1/0x124 lib/dump_stack.c:51
[<ffffffff8140c6a4>] panic+0x19e/0x38d kernel/panic.c:112
[<ffffffff8140c8c8>] warn_slowpath_common.cold.6+0x20/0x20
kernel/panic.c:455
[<ffffffff81132349>] warn_slowpath_null+0x29/0x30 kernel/panic.c:492
[<ffffffff833cb2a0>] xfrm_policy_fini+0x280/0x310
net/xfrm/xfrm_policy.c:2976
[<ffffffff833cb355>] xfrm_net_exit+0x25/0x30 net/xfrm/xfrm_policy.c:3037
[<ffffffff82f62990>] ops_exit_list.isra.6+0xb0/0x160
net/core/net_namespace.c:134
[<ffffffff82f65951>] cleanup_net+0x321/0x600 net/core/net_namespace.c:452
[<ffffffff811841df>] process_one_work+0x7df/0x1600 kernel/workqueue.c:2064
[<ffffffff811850d9>] worker_thread+0xd9/0xfc0 kernel/workqueue.c:2196
[<ffffffff81192be8>] kthread+0x268/0x300 kernel/kthread.c:211
[<ffffffff838c9095>] ret_from_fork+0x55/0x80 arch/x86/entry/entry_64.S:510
Dumping ftrace buffer:
(ftrace buffer empty)
Kernel Offset: disabled

syzbot

unread,
Apr 14, 2019, 5:28:25 AM4/14/19
to syzkaller-a...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: b30d2b5d Merge 4.9.80 into android-4.9
git tree: android-4.9
console output: https://syzkaller.appspot.com/x/log.txt?x=15a51a65800000
kernel config: https://syzkaller.appspot.com/x/.config?x=1951622140a47f94
dashboard link: https://syzkaller.appspot.com/bug?extid=5b81cff1cafbd4059c2a
compiler: gcc (GCC) 7.1.1 20170620

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+5b81cf...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 1 PID: 8445 at net/xfrm/xfrm_policy.c:2997
xfrm_policy_fini+0x24f/0x310 net/xfrm/xfrm_policy.c:2997
Kernel panic - not syncing: panic_on_warn set ...

CPU: 1 PID: 8445 Comm: kworker/u4:8 Not tainted 4.9.80-gb30d2b5 #28
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
Workqueue: netns cleanup_net
ffff8801c001f920 ffffffff81d94b69 ffffffff83a47c40 ffff8801c001f9f8
ffffffff83f42300 ffffffff833bcabf 0000000000000009 ffff8801c001f9e8
ffffffff8142f541 0000000041b58ab3 ffffffff8418ab20 ffffffff8142f385
Call Trace:
[<ffffffff81d94b69>] __dump_stack lib/dump_stack.c:15 [inline]
[<ffffffff81d94b69>] dump_stack+0xc1/0x128 lib/dump_stack.c:51
[<ffffffff8142f541>] panic+0x1bc/0x3a8 kernel/panic.c:179
[<ffffffff81131174>] __warn+0x1c4/0x1e0 kernel/panic.c:542
[<ffffffff811313dc>] warn_slowpath_null+0x2c/0x40 kernel/panic.c:585
[<ffffffff833bcabf>] xfrm_policy_fini+0x24f/0x310
net/xfrm/xfrm_policy.c:2997
[<ffffffff833bcba5>] xfrm_net_exit+0x25/0x30 net/xfrm/xfrm_policy.c:3058
[<ffffffff82f1a8be>] ops_exit_list.isra.4+0xae/0x150
net/core/net_namespace.c:136
[<ffffffff82f1d77d>] cleanup_net+0x31d/0x610 net/core/net_namespace.c:454
[<ffffffff81189820>] process_one_work+0x7e0/0x1610 kernel/workqueue.c:2092
[<ffffffff8118a730>] worker_thread+0xe0/0x10d0 kernel/workqueue.c:2226
[<ffffffff8119a73d>] kthread+0x26d/0x300 kernel/kthread.c:211
[<ffffffff838b37dc>] ret_from_fork+0x5c/0x70 arch/x86/entry/entry_64.S:477

syzbot

unread,
Apr 28, 2019, 4:52:05 AM4/28/19
to syzkaller-a...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.

syzbot

unread,
Oct 25, 2019, 4:43:05 AM10/25/19
to syzkaller-a...@googlegroups.com

syzbot

unread,
Apr 1, 2020, 12:47:09 PM4/1/20
to syzkaller-a...@googlegroups.com
Reply all
Reply to author
Forward
0 new messages