WARNING in tcp_close

17 views
Skip to first unread message

syzbot

unread,
Jun 13, 2019, 8:50:05 PM6/13/19
to syzkaller-a...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 8fe42840 Merge 4.9.141 into android-4.9
git tree: android-4.9
console output: https://syzkaller.appspot.com/x/log.txt?x=17f06b7aa00000
kernel config: https://syzkaller.appspot.com/x/.config?x=22a5ba9f73b6da1d
dashboard link: https://syzkaller.appspot.com/bug?extid=32cf18680cbb8ac7e82c
compiler: gcc (GCC) 8.0.1 20180413 (experimental)
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=11901d8ea00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+32cf18...@syzkaller.appspotmail.com

audit: type=1400 audit(1560471928.635:8): avc: denied { read } for
pid=2249 comm="syz-executor.0"
scontext=unconfined_u:system_r:insmod_t:s0-s0:c0.c1023
tcontext=unconfined_u:system_r:insmod_t:s0-s0:c0.c1023
tclass=netlink_generic_socket permissive=1
------------[ cut here ]------------
WARNING: CPU: 1 PID: 2978 at net/ipv4/tcp.c:2193 tcp_close+0xced/0x1070
net/ipv4/tcp.c:2193
Kernel panic - not syncing: panic_on_warn set ...

CPU: 1 PID: 2978 Comm: syz-executor.0 Not tainted 4.9.141+ #1
ffff8801d06c7bc0 ffffffff81b42e79 ffffffff82a38ce0 00000000ffffffff
ffffffff82ca3800 0000000000000001 0000000000000009 ffff8801d06c7c80
ffffffff813f7125 0000000041b58ab3 ffffffff82e2b62b ffffffff813f6f66
Call Trace:
[<ffffffff81b42e79>] __dump_stack lib/dump_stack.c:15 [inline]
[<ffffffff81b42e79>] dump_stack+0xc1/0x128 lib/dump_stack.c:51
[<ffffffff813f7125>] panic+0x1bf/0x39f kernel/panic.c:179
[<ffffffff813f7362>] __warn.cold.8+0x2f/0x2f kernel/panic.c:542
[<ffffffff810dc02c>] warn_slowpath_null+0x2c/0x40 kernel/panic.c:585
[<ffffffff824e662d>] tcp_close+0xced/0x1070 net/ipv4/tcp.c:2193
[<ffffffff8259329f>] inet_release+0xff/0x1d0 net/ipv4/af_inet.c:434
[<ffffffff8268b0b0>] inet6_release+0x50/0x70 net/ipv6/af_inet6.c:440
[<ffffffff8229bdd7>] __sock_release+0xd7/0x260 net/socket.c:605
[<ffffffff8229bf79>] sock_close+0x19/0x20 net/socket.c:1059
[<ffffffff81510293>] __fput+0x263/0x700 fs/file_table.c:208
[<ffffffff815107b5>] ____fput+0x15/0x20 fs/file_table.c:244
[<ffffffff8113dc4c>] task_work_run+0x10c/0x180 kernel/task_work.c:116
[<ffffffff81003e49>] tracehook_notify_resume include/linux/tracehook.h:191
[inline]
[<ffffffff81003e49>] exit_to_usermode_loop+0x129/0x150
arch/x86/entry/common.c:162
[<ffffffff81005932>] prepare_exit_to_usermode arch/x86/entry/common.c:194
[inline]
[<ffffffff81005932>] syscall_return_slowpath arch/x86/entry/common.c:263
[inline]
[<ffffffff81005932>] do_syscall_64+0x3e2/0x550 arch/x86/entry/common.c:290
[<ffffffff82817893>] entry_SYSCALL_64_after_swapgs+0x5d/0xdb
Kernel Offset: disabled
Rebooting in 86400 seconds..


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this bug, for details see:
https://goo.gl/tpsmEJ#testing-patches

syzbot

unread,
Jun 14, 2019, 12:14:05 AM6/14/19
to syzkaller-a...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 62872f95 Merge 4.4.174 into android-4.4
git tree: android-4.4
console output: https://syzkaller.appspot.com/x/log.txt?x=178b06f1a00000
kernel config: https://syzkaller.appspot.com/x/.config?x=47bc4dd423780c4a
dashboard link: https://syzkaller.appspot.com/bug?extid=98ecc3fc40222bb64217
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=162fcbb6a00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+98ecc3...@syzkaller.appspotmail.com

audit: type=1400 audit(1560482346.993:7): avc: denied { read } for
pid=2325 comm="syz-executor.0"
scontext=unconfined_u:system_r:insmod_t:s0-s0:c0.c1023
tcontext=unconfined_u:system_r:insmod_t:s0-s0:c0.c1023
tclass=netlink_generic_socket permissive=1
------------[ cut here ]------------
WARNING: CPU: 0 PID: 2475 at net/ipv4/tcp.c:2131 tcp_close+0xc30/0xfa0
net/ipv4/tcp.c:2131()
Kernel panic - not syncing: panic_on_warn set ...

CPU: 0 PID: 2475 Comm: syz-executor.0 Not tainted 4.4.174+ #4
0000000000000000 cebae34602abafe5 ffff8800b3777bb0 ffffffff81aad1a1
0000000000000000 ffffffff82835ee0 ffffffff82a85940 0000000000000853
ffffffff823fe910 ffff8800b3777c90 ffffffff813a48c2 0000000041b58ab3
Call Trace:
[<ffffffff81aad1a1>] __dump_stack lib/dump_stack.c:15 [inline]
[<ffffffff81aad1a1>] dump_stack+0xc1/0x120 lib/dump_stack.c:51
[<ffffffff813a48c2>] panic+0x1b9/0x37b kernel/panic.c:112
[<ffffffff813a4ab9>] warn_slowpath_common kernel/panic.c:455 [inline]
[<ffffffff813a4ab9>] warn_slowpath_common.cold+0x20/0x20 kernel/panic.c:435
[<ffffffff810d3aaa>] warn_slowpath_null+0x2a/0x30 kernel/panic.c:492
[<ffffffff823fe910>] tcp_close+0xc30/0xfa0 net/ipv4/tcp.c:2131
[<ffffffff824a6a3f>] inet_release+0xff/0x1d0 net/ipv4/af_inet.c:435
[<ffffffff82599893>] inet6_release+0x53/0x80 net/ipv6/af_inet6.c:439
[<ffffffff821d36a5>] __sock_release+0xd5/0x260 net/socket.c:592
[<ffffffff821d384b>] sock_close+0x1b/0x30 net/socket.c:1050
[<ffffffff8149c8c6>] __fput+0x246/0x710 fs/file_table.c:208
[<ffffffff8149ce16>] ____fput+0x16/0x20 fs/file_table.c:244
[<ffffffff8112f352>] task_work_run+0x202/0x2b0 kernel/task_work.c:115
[<ffffffff81003dca>] tracehook_notify_resume include/linux/tracehook.h:191
[inline]
[<ffffffff81003dca>] exit_to_usermode_loop+0x14a/0x170
arch/x86/entry/common.c:188
[<ffffffff8100569b>] prepare_exit_to_usermode arch/x86/entry/common.c:221
[inline]
[<ffffffff8100569b>] syscall_return_slowpath+0x25b/0x2e0
arch/x86/entry/common.c:286
[<ffffffff82718ce1>] int_ret_from_sys_call+0x25/0xa3
Reply all
Reply to author
Forward
0 new messages