Hello,
syzbot found the following crash on:
HEAD commit: 5541782c Merge 4.4.150 into android-4.4
git tree: android-4.4
console output:
https://syzkaller.appspot.com/x/log.txt?x=11dae961400000
kernel config:
https://syzkaller.appspot.com/x/.config?x=84bf0e72c8eb0c7d
dashboard link:
https://syzkaller.appspot.com/bug?extid=44c887b9422bcbb67c36
compiler: gcc (GCC) 8.0.1 20180413 (experimental)
Unfortunately, I don't have any reproducer for this crash yet.
IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by:
syzbot+44c887...@syzkaller.appspotmail.com
------------[ cut here ]------------
WARNING: CPU: 1 PID: 7446 at net/key/af_key.c:111
pfkey_sock_destruct+0x307/0x350 net/key/af_key.c:111()
Kernel panic - not syncing: panic_on_warn set ...
CPU: 1 PID: 7446 Comm: syz-executor1 Not tainted 4.4.150-g5541782 #83
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
0000000000000000 a849bf03ea8d2f7b ffff8800a3b7fbc8 ffffffff81e14e2d
ffffffff83a44e40 ffff8801bdafe000 ffffffff83f40480 0000000000000009
000000000000006f ffff8800a3b7fc88 ffffffff8140d3c4 0000000041b58ab3
Call Trace:
[<ffffffff81e14e2d>] __dump_stack lib/dump_stack.c:15 [inline]
[<ffffffff81e14e2d>] dump_stack+0xc1/0x124 lib/dump_stack.c:51
[<ffffffff8140d3c4>] panic+0x19e/0x38d kernel/panic.c:112
[<ffffffff8140d5e8>] warn_slowpath_common.cold.6+0x20/0x20
kernel/panic.c:455
[<ffffffff81133069>] warn_slowpath_null+0x29/0x30 kernel/panic.c:492
[<ffffffff8359dbf7>] pfkey_sock_destruct+0x307/0x350 net/key/af_key.c:111
[<ffffffff82f36e3c>] sk_destruct+0x4c/0x4c0 net/core/sock.c:1447
[<ffffffff82f372ff>] __sk_free+0x4f/0x220 net/core/sock.c:1480
[<ffffffff82f37500>] sk_free+0x30/0x40 net/core/sock.c:1491
[<ffffffff835882c3>] sock_put include/net/sock.h:1639 [inline]
[<ffffffff835882c3>] pfkey_release+0x263/0x2f0 net/key/af_key.c:194
[<ffffffff82f21c86>] sock_release+0x96/0x1c0 net/socket.c:587
[<ffffffff82f21dc6>] sock_close+0x16/0x20 net/socket.c:1038
[<ffffffff815277d5>] __fput+0x235/0x6f0 fs/file_table.c:208
[<ffffffff81527d15>] ____fput+0x15/0x20 fs/file_table.c:244
[<ffffffff8118ed2f>] task_work_run+0x10f/0x190 kernel/task_work.c:115
[<ffffffff8100362d>] tracehook_notify_resume include/linux/tracehook.h:191
[inline]
[<ffffffff8100362d>] exit_to_usermode_loop+0x13d/0x160
arch/x86/entry/common.c:253
[<ffffffff81006535>] prepare_exit_to_usermode arch/x86/entry/common.c:284
[inline]
[<ffffffff81006535>] syscall_return_slowpath+0x1b5/0x1f0
arch/x86/entry/common.c:349
[<ffffffff838cb235>] int_ret_from_sys_call+0x25/0xa3
Dumping ftrace buffer:
(ftrace buffer empty)
Kernel Offset: disabled
Rebooting in 86400 seconds..
---
This bug is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.