WARNING in kobject_get

18 views
Skip to first unread message

syzbot

unread,
Apr 14, 2019, 4:52:10 AM4/14/19
to syzkaller-a...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: c4b00eb7 Revert "BACKPORT, FROMLIST: fscrypt: add Speck128..
git tree: android-4.4
console output: https://syzkaller.appspot.com/x/log.txt?x=12e1d999400000
kernel config: https://syzkaller.appspot.com/x/.config?x=88f924cb59937510
dashboard link: https://syzkaller.appspot.com/bug?extid=787b65147019c304a0f6
compiler: gcc (GCC) 8.0.1 20180413 (experimental)
userspace arch: i386

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+787b65...@syzkaller.appspotmail.com

input: syz1 as /devices/virtual/input/input57
------------[ cut here ]------------
WARNING: CPU: 1 PID: 16197 at include/linux/kref.h:46 kref_get
include/linux/kref.h:46 [inline]()
WARNING: CPU: 1 PID: 16197 at include/linux/kref.h:46 kobject_get+0xca/0xf0
lib/kobject.c:596()
Kernel panic - not syncing: panic_on_warn set ...

CPU: 1 PID: 16197 Comm: syz-executor2 Not tainted 4.4.162+ #7
0000000000000000 1357e16fde39503e ffff8800b45af758 ffffffff81a994bd
ffffffff828354e0 ffff8800b5ce97c0 ffffffff82920c20 0000000000000009
000000000000002e ffff8800b45af818 ffffffff813a0e94 0000000041b58ab3
Call Trace:
[<ffffffff81a994bd>] __dump_stack lib/dump_stack.c:15 [inline]
[<ffffffff81a994bd>] dump_stack+0xc1/0x124 lib/dump_stack.c:51
[<ffffffff813a0e94>] panic+0x19e/0x359 kernel/panic.c:112
[<ffffffff813a1084>] warn_slowpath_common.cold.6+0x20/0x20
kernel/panic.c:455
[<ffffffff810d4169>] warn_slowpath_null+0x29/0x30 kernel/panic.c:492
[<ffffffff81a9f02a>] kref_get include/linux/kref.h:46 [inline]
[<ffffffff81a9f02a>] kobject_get+0xca/0xf0 lib/kobject.c:596
[<ffffffff8149d901>] cdev_get+0x51/0xa0 fs/char_dev.c:329
[<ffffffff8149e08d>] chrdev_open+0xad/0x5c0 fs/char_dev.c:374
[<ffffffff8148ba0d>] do_dentry_open+0x38d/0xbd0 fs/open.c:749
[<ffffffff8148f17a>] vfs_open+0x12a/0x210 fs/open.c:862
[<ffffffff814bed5c>] do_last fs/namei.c:3222 [inline]
[<ffffffff814bed5c>] path_openat+0x50c/0x39a0 fs/namei.c:3359
[<ffffffff814c5e87>] do_filp_open+0x197/0x270 fs/namei.c:3393
[<ffffffff8148fa9c>] do_sys_open+0x31c/0x610 fs/open.c:1038
[<ffffffff81591dda>] C_SYSC_open fs/compat.c:1092 [inline]
[<ffffffff81591dda>] compat_SyS_open+0x2a/0x40 fs/compat.c:1090
[<ffffffff8100629e>] do_syscall_32_irqs_on arch/x86/entry/common.c:396
[inline]
[<ffffffff8100629e>] do_fast_syscall_32+0x31e/0xa80
arch/x86/entry/common.c:463
[<ffffffff82707a50>] sysenter_flags_fixed+0xd/0x1a
Kernel Offset: disabled
Rebooting in 86400 seconds..


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Apr 14, 2019, 5:28:16 AM4/14/19
to syzkaller-a...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 826f3285 Revert "BACKPORT, FROMGIT: crypto: speck - add su..
git tree: android-4.9
console output: https://syzkaller.appspot.com/x/log.txt?x=12d359f3400000
kernel config: https://syzkaller.appspot.com/x/.config?x=3303f42e9d7e07c5
dashboard link: https://syzkaller.appspot.com/bug?extid=8d80429dbe6b5b579dec
compiler: gcc (GCC) 8.0.1 20180413 (experimental)
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=107e0b6b400000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+8d8042...@syzkaller.appspotmail.com

input: syz1 as /devices/virtual/input/input6821
input: syz1 as /devices/virtual/input/input6822
input: syz1 as /devices/virtual/input/input6823
input: syz1 as /devices/virtual/input/input6826
------------[ cut here ]------------
WARNING: CPU: 0 PID: 28927 at ./include/linux/kref.h:46 kref_get
include/linux/kref.h:46 [inline]
WARNING: CPU: 0 PID: 28927 at ./include/linux/kref.h:46
kobject_get+0xd1/0xf0 lib/kobject.c:596
Kernel panic - not syncing: panic_on_warn set ...

CPU: 0 PID: 28927 Comm: syz-executor4 Not tainted 4.9.135+ #110
ffff8801c26cf7e0 ffffffff81b36bf9 ffffffff82a38ba0 00000000ffffffff
0000000000000000 0000000000000000 000000000000002e ffff8801c26cf8a0
ffffffff813f6aa5 0000000041b58ab3 ffffffff82e29bcb ffffffff813f68e6
Call Trace:
[<ffffffff81b36bf9>] __dump_stack lib/dump_stack.c:15 [inline]
[<ffffffff81b36bf9>] dump_stack+0xc1/0x128 lib/dump_stack.c:51
[<ffffffff813f6aa5>] panic+0x1bf/0x39f kernel/panic.c:179
[<ffffffff813f6d74>] __warn.cold.9+0xc1/0x17f kernel/panic.c:542
[<ffffffff810dbe2c>] warn_slowpath_null+0x2c/0x40 kernel/panic.c:585
[<ffffffff81b3d051>] kref_get include/linux/kref.h:46 [inline]
[<ffffffff81b3d051>] kobject_get+0xd1/0xf0 lib/kobject.c:596
[<ffffffff815172c1>] cdev_get+0x51/0xa0 fs/char_dev.c:333
[<ffffffff81517a4d>] chrdev_open+0xad/0x5c0 fs/char_dev.c:378
[<ffffffff81501e2f>] do_dentry_open+0x3ef/0xc90 fs/open.c:766
[<ffffffff8150575c>] vfs_open+0x11c/0x210 fs/open.c:879
[<ffffffff8153c532>] do_last fs/namei.c:3410 [inline]
[<ffffffff8153c532>] path_openat+0x542/0x2790 fs/namei.c:3534
[<ffffffff81541607>] do_filp_open+0x197/0x270 fs/namei.c:3568
[<ffffffff8150616d>] do_sys_open+0x30d/0x5c0 fs/open.c:1072
[<ffffffff8150644d>] SYSC_open fs/open.c:1090 [inline]
[<ffffffff8150644d>] SyS_open+0x2d/0x40 fs/open.c:1085
[<ffffffff810056ef>] do_syscall_64+0x19f/0x550 arch/x86/entry/common.c:285
[<ffffffff82803413>] entry_SYSCALL_64_after_swapgs+0x5d/0xdb
Kernel Offset: disabled
Rebooting in 86400 seconds..


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this bug, for details see:
https://goo.gl/tpsmEJ#testing-patches

syzbot

unread,
May 22, 2019, 7:57:05 PM5/22/19
to syzkaller-a...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 62872f95 Merge 4.4.174 into android-4.4
git tree: android-4.4
console output: https://syzkaller.appspot.com/x/log.txt?x=139d0472a00000
kernel config: https://syzkaller.appspot.com/x/.config?x=47bc4dd423780c4a
dashboard link: https://syzkaller.appspot.com/bug?extid=787b65147019c304a0f6
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=10f2a5f8a00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+787b65...@syzkaller.appspotmail.com

input: syz1 as /devices/virtual/input/input7660
input: syz1 as /devices/virtual/input/input7659
input: syz1 as /devices/virtual/input/input7661
input: syz1 as /devices/virtual/input/input7663
------------[ cut here ]------------
WARNING: CPU: 1 PID: 31018 at include/linux/kref.h:46 kref_get
include/linux/kref.h:46 [inline]()
WARNING: CPU: 1 PID: 31018 at include/linux/kref.h:46 kobject_get
lib/kobject.c:596 [inline]()
WARNING: CPU: 1 PID: 31018 at include/linux/kref.h:46 kobject_get+0xd2/0xf0
lib/kobject.c:589()
Kernel panic - not syncing: panic_on_warn set ...

CPU: 1 PID: 31018 Comm: syz-executor.3 Not tainted 4.4.174+ #4
0000000000000000 b279d5346e78ed59 ffff8801d0c6f7f0 ffffffff81aad1a1
0000000000000000 ffffffff82835ee0 ffffffff829236a0 000000000000002e
ffffffff81ab2e12 ffff8801d0c6f8d0 ffffffff813a48c2 0000000041b58ab3
Call Trace:
[<ffffffff81aad1a1>] __dump_stack lib/dump_stack.c:15 [inline]
[<ffffffff81aad1a1>] dump_stack+0xc1/0x120 lib/dump_stack.c:51
[<ffffffff813a48c2>] panic+0x1b9/0x37b kernel/panic.c:112
[<ffffffff813a4ab9>] warn_slowpath_common kernel/panic.c:455 [inline]
[<ffffffff813a4ab9>] warn_slowpath_common.cold+0x20/0x20 kernel/panic.c:435
[<ffffffff810d3aaa>] warn_slowpath_null+0x2a/0x30 kernel/panic.c:492
[<ffffffff81ab2e12>] kref_get include/linux/kref.h:46 [inline]
[<ffffffff81ab2e12>] kobject_get lib/kobject.c:596 [inline]
[<ffffffff81ab2e12>] kobject_get+0xd2/0xf0 lib/kobject.c:589
[<ffffffff814a35b4>] cdev_get+0x54/0xa0 fs/char_dev.c:329
[<ffffffff814a3d40>] chrdev_open+0xb0/0x630 fs/char_dev.c:374
[<ffffffff8149154f>] do_dentry_open+0x38f/0xbd0 fs/open.c:749
[<ffffffff81494d3b>] vfs_open+0x10b/0x210 fs/open.c:862
[<ffffffff814c5ddf>] do_last fs/namei.c:3269 [inline]
[<ffffffff814c5ddf>] path_openat+0x136f/0x4470 fs/namei.c:3406
[<ffffffff814ccab1>] do_filp_open+0x1a1/0x270 fs/namei.c:3440
[<ffffffff81495668>] do_sys_open+0x2f8/0x600 fs/open.c:1038
[<ffffffff8149599d>] SYSC_open fs/open.c:1056 [inline]
[<ffffffff8149599d>] SyS_open+0x2d/0x40 fs/open.c:1051
[<ffffffff82718ba1>] entry_SYSCALL_64_fastpath+0x1e/0x9a
Reply all
Reply to author
Forward
0 new messages