[syzbot] general protection fault in ieee80211_subif_start_xmit (2)

30 views
Skip to first unread message

syzbot

unread,
Oct 23, 2022, 2:32:31ā€ÆPM10/23/22
to da...@davemloft.net, edum...@google.com, joha...@sipsolutions.net, ku...@kernel.org, linux-...@vger.kernel.org, linux-w...@vger.kernel.org, net...@vger.kernel.org, pab...@redhat.com, syzkall...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 4d48f589d294 Add linux-next specific files for 20221021
git tree: linux-next
console+strace: https://syzkaller.appspot.com/x/log.txt?x=11d36de2880000
kernel config: https://syzkaller.appspot.com/x/.config?x=2c4b7d600a5739a6
dashboard link: https://syzkaller.appspot.com/bug?extid=c6e8fca81c294fd5620a
compiler: gcc (Debian 10.2.1-6) 10.2.1 20210110, GNU ld (GNU Binutils for Debian) 2.35.2
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=12a9544a880000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1662d48c880000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/0c86bd0b39a0/disk-4d48f589.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/074059d37f1f/vmlinux-4d48f589.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+c6e8fc...@syzkaller.appspotmail.com

general protection fault, probably for non-canonical address 0xdffffc000000002f: 0000 [#1] PREEMPT SMP KASAN
KASAN: null-ptr-deref in range [0x0000000000000178-0x000000000000017f]
CPU: 1 PID: 147 Comm: kworker/1:2 Not tainted 6.1.0-rc1-next-20221021-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/11/2022
Workqueue: mld mld_ifc_work
RIP: 0010:ieee80211_multicast_to_unicast net/mac80211/tx.c:4281 [inline]
RIP: 0010:ieee80211_subif_start_xmit+0x25b/0x1310 net/mac80211/tx.c:4409
Code: 80 3c 02 00 0f 85 94 10 00 00 49 8b 8c 24 28 19 00 00 48 b8 00 00 00 00 00 fc ff df 48 8d b9 7c 01 00 00 48 89 fa 48 c1 ea 03 <0f> b6 04 02 48 89 fa 83 e2 07 38 d0 7f 08 84 c0 0f 85 68 10 00 00
RSP: 0000:ffffc90002d3f628 EFLAGS: 00010203
RAX: dffffc0000000000 RBX: 0000000000000003 RCX: 0000000000000000
RDX: 000000000000002f RSI: ffffffff88dc6bf8 RDI: 000000000000017c
RBP: ffff88807b8cf140 R08: 0000000000000005 R09: 0000000000000004
R10: 0000000000000003 R11: 000000000008c001 R12: ffff8880200b4000
R13: ffff88807b8cf218 R14: ffff888020ea4042 R15: 1ffff920005a7ecf
FS: 0000000000000000(0000) GS:ffff8880b9b00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000055b3e4199708 CR3: 000000007b8d0000 CR4: 00000000003506e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
__netdev_start_xmit include/linux/netdevice.h:4840 [inline]
netdev_start_xmit include/linux/netdevice.h:4854 [inline]
xmit_one net/core/dev.c:3590 [inline]
dev_hard_start_xmit+0x1be/0x990 net/core/dev.c:3606
__dev_queue_xmit+0x2c9a/0x3b60 net/core/dev.c:4256
dev_queue_xmit include/linux/netdevice.h:3008 [inline]
neigh_resolve_output net/core/neighbour.c:1552 [inline]
neigh_resolve_output+0x517/0x840 net/core/neighbour.c:1532
neigh_output include/net/neighbour.h:546 [inline]
ip6_finish_output2+0x564/0x1520 net/ipv6/ip6_output.c:134
__ip6_finish_output net/ipv6/ip6_output.c:195 [inline]
ip6_finish_output+0x690/0x1160 net/ipv6/ip6_output.c:206
NF_HOOK_COND include/linux/netfilter.h:291 [inline]
ip6_output+0x1ed/0x540 net/ipv6/ip6_output.c:227
dst_output include/net/dst.h:445 [inline]
NF_HOOK include/linux/netfilter.h:302 [inline]
NF_HOOK include/linux/netfilter.h:296 [inline]
mld_sendpack+0xa09/0xe70 net/ipv6/mcast.c:1820
mld_send_cr net/ipv6/mcast.c:2121 [inline]
mld_ifc_work+0x71c/0xdb0 net/ipv6/mcast.c:2653
process_one_work+0x9bf/0x1710 kernel/workqueue.c:2289
worker_thread+0x665/0x1080 kernel/workqueue.c:2436
kthread+0x2e4/0x3a0 kernel/kthread.c:376
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:308
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:ieee80211_multicast_to_unicast net/mac80211/tx.c:4281 [inline]
RIP: 0010:ieee80211_subif_start_xmit+0x25b/0x1310 net/mac80211/tx.c:4409
Code: 80 3c 02 00 0f 85 94 10 00 00 49 8b 8c 24 28 19 00 00 48 b8 00 00 00 00 00 fc ff df 48 8d b9 7c 01 00 00 48 89 fa 48 c1 ea 03 <0f> b6 04 02 48 89 fa 83 e2 07 38 d0 7f 08 84 c0 0f 85 68 10 00 00
RSP: 0000:ffffc90002d3f628 EFLAGS: 00010203
RAX: dffffc0000000000 RBX: 0000000000000003 RCX: 0000000000000000
RDX: 000000000000002f RSI: ffffffff88dc6bf8 RDI: 000000000000017c
RBP: ffff88807b8cf140 R08: 0000000000000005 R09: 0000000000000004
R10: 0000000000000003 R11: 000000000008c001 R12: ffff8880200b4000
R13: ffff88807b8cf218 R14: ffff888020ea4042 R15: 1ffff920005a7ecf
FS: 0000000000000000(0000) GS:ffff8880b9b00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000055b3e4199708 CR3: 000000000ba8e000 CR4: 00000000003506e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
----------------
Code disassembly (best guess):
0: 80 3c 02 00 cmpb $0x0,(%rdx,%rax,1)
4: 0f 85 94 10 00 00 jne 0x109e
a: 49 8b 8c 24 28 19 00 mov 0x1928(%r12),%rcx
11: 00
12: 48 b8 00 00 00 00 00 movabs $0xdffffc0000000000,%rax
19: fc ff df
1c: 48 8d b9 7c 01 00 00 lea 0x17c(%rcx),%rdi
23: 48 89 fa mov %rdi,%rdx
26: 48 c1 ea 03 shr $0x3,%rdx
* 2a: 0f b6 04 02 movzbl (%rdx,%rax,1),%eax <-- trapping instruction
2e: 48 89 fa mov %rdi,%rdx
31: 83 e2 07 and $0x7,%edx
34: 38 d0 cmp %dl,%al
36: 7f 08 jg 0x40
38: 84 c0 test %al,%al
3a: 0f 85 68 10 00 00 jne 0x10a8


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this issue, for details see:
https://goo.gl/tpsmEJ#testing-patches

syzbot

unread,
Oct 25, 2022, 4:33:28ā€ÆAM10/25/22
to gautamme...@gmail.com, syzkall...@googlegroups.com
Hello,

syzbot tried to test the proposed patch but the build/boot failed:

03 Google GOOGSRAT 00000001 GOOG 00000001)
ACPI: APIC 0x00000000BFFFFDB0 000076 (v05 Google GOOGAPIC 00000001 GOOG 00000001)
ACPI: SSDT 0x00000000BFFFF430 000980 (v01 Google GOOGSSDT 00000001 GOOG 00000001)
ACPI: WAET 0x00000000BFFFFE30 000028 (v01 Google GOOGWAET 00000001 GOOG 00000001)
ACPI: Reserving FACP table memory at [mem 0xbffff330-0xbffff423]
ACPI: Reserving DSDT table memory at [mem 0xbfffd8c0-0xbffff323]
ACPI: Reserving FACS table memory at [mem 0xbfffd880-0xbfffd8bf]
ACPI: Reserving FACS table memory at [mem 0xbfffd880-0xbfffd8bf]
ACPI: Reserving SRAT table memory at [mem 0xbffffe60-0xbfffff27]
ACPI: Reserving APIC table memory at [mem 0xbffffdb0-0xbffffe25]
ACPI: Reserving SSDT table memory at [mem 0xbffff430-0xbffffdaf]
ACPI: Reserving WAET table memory at [mem 0xbffffe30-0xbffffe57]
SRAT: PXM 0 -> APIC 0x00 -> Node 0
SRAT: PXM 0 -> APIC 0x01 -> Node 0
ACPI: SRAT: Node 0 PXM 0 [mem 0x00000000-0x0009ffff]
ACPI: SRAT: Node 0 PXM 0 [mem 0x00100000-0xbfffffff]
ACPI: SRAT: Node 0 PXM 0 [mem 0x100000000-0x23fffffff]
NUMA: Node 0 [mem 0x00000000-0x0009ffff] + [mem 0x00100000-0xbfffffff] -> [mem 0x00000000-0xbfffffff]
NUMA: Node 0 [mem 0x00000000-0xbfffffff] + [mem 0x100000000-0x23fffffff] -> [mem 0x00000000-0x23fffffff]
Faking node 0 at [mem 0x0000000000000000-0x000000013fffffff] (5120MB)
Faking node 1 at [mem 0x0000000140000000-0x000000023fffffff] (4096MB)
NODE_DATA(0) allocated [mem 0x13fffa000-0x13fffffff]
NODE_DATA(1) allocated [mem 0x23fff7000-0x23fffcfff]
Zone ranges:
DMA [mem 0x0000000000001000-0x0000000000ffffff]
DMA32 [mem 0x0000000001000000-0x00000000ffffffff]
Normal [mem 0x0000000100000000-0x000000023fffffff]
Device empty
Movable zone start for each node
Early memory node ranges
node 0: [mem 0x0000000000001000-0x000000000009efff]
node 0: [mem 0x0000000000100000-0x00000000bfffcfff]
node 0: [mem 0x0000000100000000-0x000000013fffffff]
node 1: [mem 0x0000000140000000-0x000000023fffffff]
Initmem setup node 0 [mem 0x0000000000001000-0x000000013fffffff]
Initmem setup node 1 [mem 0x0000000140000000-0x000000023fffffff]
On node 0, zone DMA: 1 pages in unavailable ranges
On node 0, zone DMA: 97 pages in unavailable ranges
On node 0, zone Normal: 3 pages in unavailable ranges
Kernel panic - not syncing: kasan_populate_pmd arch/x86/mm/kasan_init_64.c:67 [inline]: Failed to allocate page, nid=0 from=1000000
Kernel panic - not syncing: kasan_populate_pud arch/x86/mm/kasan_init_64.c:99 [inline]: Failed to allocate page, nid=0 from=1000000
Kernel panic - not syncing: kasan_populate_p4d arch/x86/mm/kasan_init_64.c:119 [inline]: Failed to allocate page, nid=0 from=1000000
Kernel panic - not syncing: kasan_populate_pgd arch/x86/mm/kasan_init_64.c:138 [inline]: Failed to allocate page, nid=0 from=1000000
Kernel panic - not syncing: kasan_populate_shadow+0x57f/0x71f arch/x86/mm/kasan_init_64.c:153: Failed to allocate page, nid=0 from=1000000
CPU: 0 PID: 0 Comm: swapper Not tainted 6.1.0-rc2-next-20221025-syzkaller-03191-g89bf6e28373b #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/11/2022
Call Trace:
<TASK>
</TASK>
Rebooting in 86400 seconds..


failed to run ["ssh" "-p" "22" "-F" "/dev/null" "-o" "UserKnownHostsFile=/dev/null" "-o" "BatchMode=yes" "-o" "IdentitiesOnly=yes" "-o" "StrictHostKeyChecking=no" "-o" "ConnectTimeout=10" "ro...@10.128.10.11" "pwd"]: exit status 255
ssh: connect to host 10.128.10.11 port 22: Connection timed out
Pseudo-terminal will not be allocated because stdin is not a terminal.
Warning: Permanently added '[ssh-serialport.googleapis.com]:9600,[216.239.38.127]:9600' (RSA) to the list of known hosts.
serialport: Connected to syzkaller.us-central1-c.ci-upstream-linux-next-kasan-gce-root-test-job-test-job-2 port 1 (session ID: 7a84a14ec8e5bf64baf0c37e26b0ae0b75c7c4fb825867692e2cdcb72e96ebb0, active connections: 1).
SeaBIOS (version 1.8.2-google)
Total RAM Size = 0x0000000200000000 = 8192 MiB
CPUs found: 2 Max CPUs supported: 2
SeaBIOS (version 1.8.2-google)
Machine UUID 5fafaa8f-8474-0792-0122-c42702b244e2
found virtio-scsi at 0:3
virtio-scsi vendor='Google' product='PersistentDisk' rev='1' type=0 removable=0
virtio-scsi blksize=512 sectors=4194304 = 2048 MiB
drive 0x000f2490: PCHS=0/0/0 translation=lba LCHS=520/128/63 s=4194304
Sending Seabios boot VM event.
Booting from Hard Disk 0...
[ 0.000000][ T0] Linux version 6.1.0-rc2-next-20221025-syzkaller-03191-g89bf6e28373b (syzkaller@syzkaller) (gcc (Debian 10.2.1-6) 10.2.1 20210110, GNU ld (GNU Binutils for Debian) 2.35.2) #0 SMP PREEMPT_DYNAMIC now
[ 0.000000][ T0] Command line: BOOT_IMAGE=/boot/bzImage root=/dev/sda1 console=ttyS0
[ 0.000000][ T0] KERNEL supported cpus:
[ 0.000000][ T0] Intel GenuineIntel
[ 0.000000][ T0] AMD AuthenticAMD
[ 0.000000][ T0] x86/fpu: Supporting XSAVE feature 0x001: 'x87 floating point registers'
[ 0.000000][ T0] x86/fpu: Supporting XSAVE feature 0x002: 'SSE registers'
[ 0.000000][ T0] x86/fpu: Supporting XSAVE feature 0x004: 'AVX registers'
[ 0.000000][ T0] x86/fpu: xstate_offset[2]: 576, xstate_sizes[2]: 256
[ 0.000000][ T0] x86/fpu: Enabled xstate features 0x7, context size is 832 bytes, using 'standard' format.
[ 0.000000][ T0] signal: max sigframe size: 1776
[ 0.000000][ T0] BIOS-provided physical RAM map:
[ 0.000000][ T0] BIOS-e820: [mem 0x0000000000000000-0x000000000009fbff] usable
[ 0.000000][ T0] BIOS-e820: [mem 0x000000000009fc00-0x000000000009ffff] reserved
[ 0.000000][ T0] BIOS-e820: [mem 0x00000000000f0000-0x00000000000fffff] reserved
[ 0.000000][ T0] BIOS-e820: [mem 0x0000000000100000-0x00000000bfffcfff] usable
[ 0.000000][ T0] BIOS-e820: [mem 0x00000000bfffd000-0x00000000bfffffff] reserved
[ 0.000000][ T0] BIOS-e820: [mem 0x00000000fffbc000-0x00000000ffffffff] reserved
[ 0.000000][ T0] BIOS-e820: [mem 0x0000000100000000-0x000000023fffffff] usable
[ 0.000000][ T0] printk: bootconsole [earlyser0] enabled
[ 0.000000][ T0] ERROR: earlyprintk= earlyser already used
[ 0.000000][ T0] ERROR: earlyprintk= earlyser already used
[ 0.000000][ T0] **********************************************************
[ 0.000000][ T0] ** NOTICE NOTICE NOTICE NOTICE NOTICE NOTICE NOTICE **
[ 0.000000][ T0] ** **
[ 0.000000][ T0] ** This system shows unhashed kernel memory addresses **
[ 0.000000][ T0] ** via the console, logs, and other interfaces. This **
[ 0.000000][ T0] ** might reduce the security of your system. **
[ 0.000000][ T0] ** **
[ 0.000000][ T0] ** If you see this message and you are not debugging **
[ 0.000000][ T0] ** the kernel, report this immediately to your system **
[ 0.000000][ T0] ** administrator! **
[ 0.000000][ T0] ** **
[ 0.000000][ T0] ** NOTICE NOTICE NOTICE NOTICE NOTICE NOTICE NOTICE **
[ 0.000000][ T0] **********************************************************
[ 0.000000][ T0] Malformed early option 'vsyscall'
[ 0.000000][ T0] nopcid: PCID feature disabled
[ 0.000000][ T0] NX (Execute Disable) protection: active
[ 0.000000][ T0] SMBIOS 2.4 present.
[ 0.000000][ T0] DMI: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/11/2022
[ 0.000000][ T0] Hypervisor detected: KVM
[ 0.000000][ T0] kvm-clock: Using msrs 4b564d01 and 4b564d00
[ 0.000007][ T0] kvm-clock: using sched offset of 4207669543 cycles
[ 0.001391][ T0] clocksource: kvm-clock: mask: 0xffffffffffffffff max_cycles: 0x1cd42e4dffb, max_idle_ns: 881590591483 ns
[ 0.004736][ T0] tsc: Detected 2200.220 MHz processor
[ 0.010158][ T0] last_pfn = 0x240000 max_arch_pfn = 0x400000000
[ 0.011583][ T0] x86/PAT: Configuration [0-7]: WB WC UC- UC WB WP UC- WT
[ 0.012989][ T0] last_pfn = 0xbfffd max_arch_pfn = 0x400000000
[ 0.019751][ T0] found SMP MP-table at [mem 0x000f2750-0x000f275f]
[ 0.021239][ T0] Using GB pages for direct mapping
[ 0.024081][ T0] ACPI: Early table checksum verification disabled
[ 0.025192][ T0] ACPI: RSDP 0x00000000000F24D0 000014 (v00 Google)
[ 0.026554][ T0] ACPI: RSDT 0x00000000BFFFFFA0 000038 (v01 Google GOOGRSDT 00000001 GOOG 00000001)
[ 0.028411][ T0] ACPI: FACP 0x00000000BFFFF330 0000F4 (v02 Google GOOGFACP 00000001 GOOG 00000001)
[ 0.030750][ T0] ACPI: DSDT 0x00000000BFFFD8C0 001A64 (v01 Google GOOGDSDT 00000001 GOOG 00000001)
[ 0.032900][ T0] ACPI: FACS 0x00000000BFFFD880 000040
[ 0.033792][ T0] ACPI: FACS 0x00000000BFFFD880 000040
[ 0.034927][ T0] ACPI: SRAT 0x00000000BFFFFE60 0000C8 (v03 Google GOOGSRAT 00000001 GOOG 00000001)
[ 0.036890][ T0] ACPI: APIC 0x00000000BFFFFDB0 000076 (v05 Google GOOGAPIC 00000001 GOOG 00000001)
[ 0.040630][ T0] ACPI: SSDT 0x00000000BFFFF430 000980 (v01 Google GOOGSSDT 00000001 GOOG 00000001)
[ 0.042687][ T0] ACPI: WAET 0x00000000BFFFFE30 000028 (v01 Google GOOGWAET 00000001 GOOG 00000001)
[ 0.043937][ T0] ACPI: Reserving FACP table memory at [mem 0xbffff330-0xbffff423]
[ 0.045315][ T0] ACPI: Reserving DSDT table memory at [mem 0xbfffd8c0-0xbffff323]
[ 0.046517][ T0] ACPI: Reserving FACS table memory at [mem 0xbfffd880-0xbfffd8bf]
[ 0.047777][ T0] ACPI: Reserving FACS table memory at [mem 0xbfffd880-0xbfffd8bf]
[ 0.049483][ T0] ACPI: Reserving SRAT table memory at [mem 0xbffffe60-0xbfffff27]
[ 0.051284][ T0] ACPI: Reserving APIC table memory at [mem 0xbffffdb0-0xbffffe25]
[ 0.053040][ T0] ACPI: Reserving SSDT table memory at [mem 0xbffff430-0xbffffdaf]
[ 0.055101][ T0] ACPI: Reserving WAET table memory at [mem 0xbffffe30-0xbffffe57]
[ 0.057047][ T0] SRAT: PXM 0 -> APIC 0x00 -> Node 0
[ 0.057998][ T0] SRAT: PXM 0 -> APIC 0x01 -> Node 0
[ 0.059429][ T0] ACPI: SRAT: Node 0 PXM 0 [mem 0x00000000-0x0009ffff]
[ 0.060957][ T0] ACPI: SRAT: Node 0 PXM 0 [mem 0x00100000-0xbfffffff]
[ 0.062471][ T0] ACPI: SRAT: Node 0 PXM 0 [mem 0x100000000-0x23fffffff]
[ 0.063786][ T0] NUMA: Node 0 [mem 0x00000000-0x0009ffff] + [mem 0x00100000-0xbfffffff] -> [mem 0x00000000-0xbfffffff]
[ 0.065918][ T0] NUMA: Node 0 [mem 0x00000000-0xbfffffff] + [mem 0x100000000-0x23fffffff] -> [mem 0x00000000-0x23fffffff]
[ 0.068286][ T0] Faking node 0 at [mem 0x0000000000000000-0x000000013fffffff] (5120MB)
[ 0.070144][ T0] Faking node 1 at [mem 0x0000000140000000-0x000000023fffffff] (4096MB)
[ 0.072536][ T0] NODE_DATA(0) allocated [mem 0x13fffa000-0x13fffffff]
[ 0.074099][ T0] NODE_DATA(1) allocated [mem 0x23fff7000-0x23fffcfff]
[ 0.114344][ T0] Zone ranges:
[ 0.115079][ T0] DMA [mem 0x0000000000001000-0x0000000000ffffff]
[ 0.118832][ T0] DMA32 [mem 0x0000000001000000-0x00000000ffffffff]
[ 0.119985][ T0] Normal [mem 0x0000000100000000-0x000000023fffffff]
[ 0.121146][ T0] Device empty
[ 0.121701][ T0] Movable zone start for each node
[ 0.122615][ T0] Early memory node ranges
[ 0.123437][ T0] node 0: [mem 0x0000000000001000-0x000000000009efff]
[ 0.124672][ T0] node 0: [mem 0x0000000000100000-0x00000000bfffcfff]
[ 0.125959][ T0] node 0: [mem 0x0000000100000000-0x000000013fffffff]
[ 0.127460][ T0] node 1: [mem 0x0000000140000000-0x000000023fffffff]
[ 0.128595][ T0] Initmem setup node 0 [mem 0x0000000000001000-0x000000013fffffff]
[ 0.130294][ T0] Initmem setup node 1 [mem 0x0000000140000000-0x000000023fffffff]
[ 0.131724][ T0] On node 0, zone DMA: 1 pages in unavailable ranges
[ 0.131879][ T0] On node 0, zone DMA: 97 pages in unavailable ranges
[ 0.171515][ T0] On node 0, zone Normal: 3 pages in unavailable ranges
[ 2.739470][ T0] Kernel panic - not syncing: kasan_populate_shadow+0x57f/0x71f: Failed to allocate page, nid=0 from=1000000
[ 2.743596][ T0] CPU: 0 PID: 0 Comm: swapper Not tainted 6.1.0-rc2-next-20221025-syzkaller-03191-g89bf6e28373b #0
[ 2.745190][ T0] Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/11/2022
[ 2.747169][ T0] Call Trace:
[ 2.747761][ T0] <TASK>
[ 2.748410][ T0] ? dump_stack_lvl+0xcd/0x134
[ 2.749449][ T0] ? panic+0x2c8/0x622
[ 2.750360][ T0] ? panic+0x0/0x622
[ 2.750882][ T0] ? memblock_alloc_try_nid+0x0/0x13c
[ 2.751698][ T0] ? pmd_set_huge+0x0/0x390
[ 2.752392][ T0] ? kasan_populate_shadow+0x57f/0x71f
[ 2.753326][ T0] ? kasan_populate_shadow-0xe/0x71f
[ 2.754119][ T0] ? kasan_populate_shadow+0x57f/0x71f
[ 2.754974][ T0] ? kasan_init+0x28a/0x3b2
[ 2.755749][ T0] ? setup_arch+0x1466/0x16d3
[ 2.756541][ T0] ? setup_arch+0x0/0x16d3
[ 2.757206][ T0] ? _printk+0x0/0xed
[ 2.757888][ T0] ? security_add_hooks+0x1e2/0x234
[ 2.758931][ T0] ? start_kernel+0x90/0x471
[ 2.759865][ T0] ? verify_cpu-0xd/0x100
[ 2.761116][ T0] </TASK>
[ 2.761699][ T0] Rebooting in 86400 seconds..


syzkaller build log:
go env (err=<nil>)
GO111MODULE="auto"
GOARCH="amd64"
GOBIN=""
GOCACHE="/syzkaller/.cache/go-build"
GOENV="/syzkaller/.config/go/env"
GOEXE=""
GOEXPERIMENT=""
GOFLAGS=""
GOHOSTARCH="amd64"
GOHOSTOS="linux"
GOINSECURE=""
GOMODCACHE="/syzkaller/jobs/linux/gopath/pkg/mod"
GONOPROXY=""
GONOSUMDB=""
GOOS="linux"
GOPATH="/syzkaller/jobs/linux/gopath"
GOPRIVATE=""
GOPROXY="https://proxy.golang.org,direct"
GOROOT="/usr/local/go"
GOSUMDB="sum.golang.org"
GOTMPDIR=""
GOTOOLDIR="/usr/local/go/pkg/tool/linux_amd64"
GOVCS=""
GOVERSION="go1.17"
GCCGO="gccgo"
AR="ar"
CC="gcc"
CXX="g++"
CGO_ENABLED="1"
GOMOD="/syzkaller/jobs/linux/gopath/src/github.com/google/syzkaller/go.mod"
CGO_CFLAGS="-g -O2"
CGO_CPPFLAGS=""
CGO_CXXFLAGS="-g -O2"
CGO_FFLAGS="-g -O2"
CGO_LDFLAGS="-g -O2"
PKG_CONFIG="pkg-config"
GOGCCFLAGS="-fPIC -m64 -pthread -fmessage-length=0 -fdebug-prefix-map=/tmp/go-build1988942238=/tmp/go-build -gno-record-gcc-switches"

git status (err=<nil>)
HEAD detached at c0b80a55c
nothing to commit, working tree clean


tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:32: run command via tools/syz-env for best compatibility, see:
Makefile:33: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
go list -f '{{.Stale}}' ./sys/syz-sysgen | grep -q false || go install ./sys/syz-sysgen
make .descriptions
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
bin/syz-sysgen
touch .descriptions
GOOS=linux GOARCH=amd64 go build "-ldflags=-s -w -X github.com/google/syzkaller/prog.GitRevision=c0b80a55c9c8cfe75e77c555ed0d4ae7aa373cc2 -X 'github.com/google/syzkaller/prog.gitRevisionDate=20221021-135310'" "-tags=syz_target syz_os_linux syz_arch_amd64 " -o ./bin/linux_amd64/syz-fuzzer github.com/google/syzkaller/syz-fuzzer
GOOS=linux GOARCH=amd64 go build "-ldflags=-s -w -X github.com/google/syzkaller/prog.GitRevision=c0b80a55c9c8cfe75e77c555ed0d4ae7aa373cc2 -X 'github.com/google/syzkaller/prog.gitRevisionDate=20221021-135310'" "-tags=syz_target syz_os_linux syz_arch_amd64 " -o ./bin/linux_amd64/syz-execprog github.com/google/syzkaller/tools/syz-execprog
GOOS=linux GOARCH=amd64 go build "-ldflags=-s -w -X github.com/google/syzkaller/prog.GitRevision=c0b80a55c9c8cfe75e77c555ed0d4ae7aa373cc2 -X 'github.com/google/syzkaller/prog.gitRevisionDate=20221021-135310'" "-tags=syz_target syz_os_linux syz_arch_amd64 " -o ./bin/linux_amd64/syz-stress github.com/google/syzkaller/tools/syz-stress
mkdir -p ./bin/linux_amd64
gcc -o ./bin/linux_amd64/syz-executor executor/executor.cc \
-m64 -O2 -pthread -Wall -Werror -Wparentheses -Wunused-const-variable -Wframe-larger-than=16384 -Wno-stringop-overflow -Wno-array-bounds -Wno-format-overflow -static-pie -fpermissive -w -DGOOS_linux=1 -DGOARCH_amd64=1 \
-DHOSTGOOS_linux=1 -DGIT_REVISION=\"c0b80a55c9c8cfe75e77c555ed0d4ae7aa373cc2\"


Error text is too large and was truncated, full error text is at:
https://syzkaller.appspot.com/x/error.txt?x=17f3025a880000


Tested on:

commit: 89bf6e28 Add linux-next specific files for 20221025
git tree: linux-next
kernel config: https://syzkaller.appspot.com/x/.config?x=a74f0bc30ea648a3
dashboard link: https://syzkaller.appspot.com/bug?extid=c6e8fca81c294fd5620a
compiler: gcc (Debian 10.2.1-6) 10.2.1 20210110, GNU ld (GNU Binutils for Debian) 2.35.2

Note: no patches were applied.
Reply all
Reply to author
Forward
0 new messages