[syzbot] [usb?] stack segment fault in __usb_hcd_giveback_urb

7 views
Skip to first unread message

syzbot

unread,
Jun 6, 2025, 9:16:29 PM6/6/25
to gre...@linuxfoundation.org, linux-...@vger.kernel.org, linu...@vger.kernel.org, marcell...@9elements.com, st...@rowland.harvard.edu, sy...@sylv.io, syzkall...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 7f9039c524a3 Merge tag 'for-linus' of git://git.kernel.org..
git tree: upstream
console+strace: https://syzkaller.appspot.com/x/log.txt?x=10e2180c580000
kernel config: https://syzkaller.appspot.com/x/.config?x=6acfdd5e5c8ef3d0
dashboard link: https://syzkaller.appspot.com/bug?extid=9a4aec827829942045ff
compiler: Debian clang version 20.1.6 (++20250514063057+1e4d39e07757-1~exp1~20250514183223.118), Debian LLD 20.1.6
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=13fd0570580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=17c7c1d4580000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/28a04aa25fd8/disk-7f9039c5.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/5f13feaf2dfc/vmlinux-7f9039c5.xz
kernel image: https://storage.googleapis.com/syzbot-assets/5f3d17075519/bzImage-7f9039c5.xz

The issue was bisected to:

commit a7f3813e589fd8e2834720829a47b5eb914a9afe
Author: Marcello Sylvester Bauer <sy...@sylv.io>
Date: Thu Apr 11 14:51:28 2024 +0000

usb: gadget: dummy_hcd: Switch to hrtimer transfer scheduler

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=16a2b80c580000
final oops: https://syzkaller.appspot.com/x/report.txt?x=15a2b80c580000
console output: https://syzkaller.appspot.com/x/log.txt?x=11a2b80c580000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+9a4aec...@syzkaller.appspotmail.com
Fixes: a7f3813e589f ("usb: gadget: dummy_hcd: Switch to hrtimer transfer scheduler")

Oops: stack segment: 0000 [#1] SMP KASAN PTI
CPU: 0 UID: 0 PID: 5905 Comm: kworker/0:9 Not tainted 6.15.0-syzkaller-11061-g7f9039c524a3 #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025
Workqueue: usb_hub_wq hub_event
RIP: 0010:__queue_work+0x9e/0xfe0 kernel/workqueue.c:2256
Code: 8b 1d de 93 11 11 31 ff 89 de e8 fd 95 35 00 85 db 0f 85 fc 0c 00 00 e8 b0 91 35 00 49 8d 97 c0 01 00 00 48 89 d5 48 c1 ed 03 <42> 0f b6 44 25 00 84 c0 48 89 54 24 08 0f 85 44 0d 00 00 8b 1a 89
RSP: 0018:ffffc90000007708 EFLAGS: 00010002
RAX: ffffffff818ac930 RBX: 0000000000000000 RCX: ffff888030365a00
RDX: 00000000000001c0 RSI: 0000000000000000 RDI: 0000000000000000
RBP: 0000000000000038 R08: ffff88807e0d3bf7 R09: 1ffff1100fc1a77e
R10: dffffc0000000000 R11: ffffed100fc1a77f R12: dffffc0000000000
R13: ffff88807e0d3bf0 R14: 0000000000000008 R15: 0000000000000000
FS: 0000000000000000(0000) GS:ffff888125c5e000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007efc1f35ecf0 CR3: 0000000075fe4000 CR4: 00000000003526f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<IRQ>
queue_work_on+0x181/0x270 kernel/workqueue.c:2392
__usb_hcd_giveback_urb+0x41a/0x690 drivers/usb/core/hcd.c:1650
dummy_timer+0x862/0x4550 drivers/usb/gadget/udc/dummy_hcd.c:1994
__run_hrtimer kernel/time/hrtimer.c:1761 [inline]
__hrtimer_run_queues+0x52c/0xc60 kernel/time/hrtimer.c:1825
hrtimer_run_softirq+0x187/0x2b0 kernel/time/hrtimer.c:1842
handle_softirqs+0x283/0x870 kernel/softirq.c:579
__do_softirq kernel/softirq.c:613 [inline]
invoke_softirq kernel/softirq.c:453 [inline]
__irq_exit_rcu+0xca/0x1f0 kernel/softirq.c:680
irq_exit_rcu+0x9/0x30 kernel/softirq.c:696
common_interrupt+0xbb/0xe0 arch/x86/kernel/irq.c:285
</IRQ>
<TASK>
asm_common_interrupt+0x26/0x40 arch/x86/include/asm/idtentry.h:693
RIP: 0010:console_flush_all+0x7f7/0xc40 kernel/printk/printk.c:3227
Code: 48 21 c3 0f 85 e9 01 00 00 e8 e5 22 1f 00 48 8b 5c 24 20 4d 85 f6 75 07 e8 d6 22 1f 00 eb 06 e8 cf 22 1f 00 fb 48 8b 44 24 28 <42> 80 3c 20 00 74 08 48 89 df e8 8a ac 82 00 48 8b 1b 48 8b 44 24
RSP: 0018:ffffc900047ef0a0 EFLAGS: 00000293
RAX: 1ffffffff1d36baf RBX: ffffffff8e9b5d78 RCX: ffff888030365a00
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: ffffc900047ef1f0 R08: ffffffff8fa0e0f7 R09: 1ffffffff1f41c1e
R10: dffffc0000000000 R11: fffffbfff1f41c1f R12: dffffc0000000000
R13: 0000000000000001 R14: 0000000000000200 R15: ffffffff8e9b5d20
__console_flush_and_unlock kernel/printk/printk.c:3285 [inline]
console_unlock+0xc4/0x270 kernel/printk/printk.c:3325
vprintk_emit+0x5b7/0x7a0 kernel/printk/printk.c:2450
dev_vprintk_emit+0x337/0x3f0 drivers/base/core.c:4917
dev_printk_emit+0xe0/0x130 drivers/base/core.c:4928
_dev_info+0x10a/0x160 drivers/base/core.c:4986
usb_disconnect+0xdd/0x910 drivers/usb/core/hub.c:2298
hub_port_connect drivers/usb/core/hub.c:5371 [inline]
hub_port_connect_change drivers/usb/core/hub.c:5671 [inline]
port_event drivers/usb/core/hub.c:5831 [inline]
hub_event+0x1cdb/0x4a00 drivers/usb/core/hub.c:5913
process_one_work kernel/workqueue.c:3238 [inline]
process_scheduled_works+0xade/0x17b0 kernel/workqueue.c:3321
worker_thread+0x8a0/0xda0 kernel/workqueue.c:3402
kthread+0x711/0x8a0 kernel/kthread.c:464
ret_from_fork+0x3f9/0x770 arch/x86/kernel/process.c:148
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:__queue_work+0x9e/0xfe0 kernel/workqueue.c:2256
Code: 8b 1d de 93 11 11 31 ff 89 de e8 fd 95 35 00 85 db 0f 85 fc 0c 00 00 e8 b0 91 35 00 49 8d 97 c0 01 00 00 48 89 d5 48 c1 ed 03 <42> 0f b6 44 25 00 84 c0 48 89 54 24 08 0f 85 44 0d 00 00 8b 1a 89
RSP: 0018:ffffc90000007708 EFLAGS: 00010002
RAX: ffffffff818ac930 RBX: 0000000000000000 RCX: ffff888030365a00
RDX: 00000000000001c0 RSI: 0000000000000000 RDI: 0000000000000000
RBP: 0000000000000038 R08: ffff88807e0d3bf7 R09: 1ffff1100fc1a77e
R10: dffffc0000000000 R11: ffffed100fc1a77f R12: dffffc0000000000
R13: ffff88807e0d3bf0 R14: 0000000000000008 R15: 0000000000000000
FS: 0000000000000000(0000) GS:ffff888125c5e000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007efc1f35ecf0 CR3: 0000000075fe4000 CR4: 00000000003526f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
----------------
Code disassembly (best guess):
0: 8b 1d de 93 11 11 mov 0x111193de(%rip),%ebx # 0x111193e4
6: 31 ff xor %edi,%edi
8: 89 de mov %ebx,%esi
a: e8 fd 95 35 00 call 0x35960c
f: 85 db test %ebx,%ebx
11: 0f 85 fc 0c 00 00 jne 0xd13
17: e8 b0 91 35 00 call 0x3591cc
1c: 49 8d 97 c0 01 00 00 lea 0x1c0(%r15),%rdx
23: 48 89 d5 mov %rdx,%rbp
26: 48 c1 ed 03 shr $0x3,%rbp
* 2a: 42 0f b6 44 25 00 movzbl 0x0(%rbp,%r12,1),%eax <-- trapping instruction
30: 84 c0 test %al,%al
32: 48 89 54 24 08 mov %rdx,0x8(%rsp)
37: 0f 85 44 0d 00 00 jne 0xd81
3d: 8b 1a mov (%rdx),%ebx
3f: 89 .byte 0x89


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
For information about bisection process see: https://goo.gl/tpsmEJ#bisection

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

Hillf Danton

unread,
Jun 7, 2025, 3:43:19 AM6/7/25
to syzbot, linux-...@vger.kernel.org, syzkall...@googlegroups.com
> Date: Fri, 06 Jun 2025 18:16:27 -0700
> Hello,
>
> syzbot found the following issue on:
>
> HEAD commit: 7f9039c524a3 Merge tag 'for-linus' of git://git.kernel.org..
> git tree: upstream
> console+strace: https://syzkaller.appspot.com/x/log.txt?x=10e2180c580000
> kernel config: https://syzkaller.appspot.com/x/.config?x=6acfdd5e5c8ef3d0
> dashboard link: https://syzkaller.appspot.com/bug?extid=9a4aec827829942045ff
> compiler: Debian clang version 20.1.6 (++20250514063057+1e4d39e07757-1~exp1~20250514183223.118), Debian LLD 20.1.6
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=13fd0570580000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=17c7c1d4580000
>
> The issue was bisected to:
>
> commit a7f3813e589fd8e2834720829a47b5eb914a9afe
> Author: Marcello Sylvester Bauer <sy...@sylv.io>
> Date: Thu Apr 11 14:51:28 2024 +0000
>
> usb: gadget: dummy_hcd: Switch to hrtimer transfer scheduler

#syz test upstream master

syzbot

unread,
Jun 7, 2025, 4:19:04 AM6/7/25
to hda...@sina.com, linux-...@vger.kernel.org, syzkall...@googlegroups.com
Hello,

syzbot has tested the proposed patch but the reproducer is still triggering an issue:
stack segment fault in __usb_hcd_giveback_urb

Oops: stack segment: 0000 [#1] SMP KASAN PTI
CPU: 0 UID: 0 PID: 10 Comm: kworker/0:1 Not tainted 6.15.0-syzkaller-13655-gbdc7f8c5adad #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025
Workqueue: usb_hub_wq hub_event
RIP: 0010:__queue_work+0x9e/0xfe0 kernel/workqueue.c:2256
Code: 8b 1d fe 53 12 11 31 ff 89 de e8 5d 97 35 00 85 db 0f 85 fc 0c 00 00 e8 10 93 35 00 49 8d 97 c0 01 00 00 48 89 d5 48 c1 ed 03 <42> 0f b6 44 25 00 84 c0 48 89 54 24 08 0f 85 44 0d 00 00 8b 1a 89
RSP: 0018:ffffc90000007708 EFLAGS: 00010002
RAX: ffffffff818ac910 RBX: 0000000000000000 RCX: ffff88801d2b1e00
RDX: 00000000000001c0 RSI: 0000000000000000 RDI: 0000000000000000
RBP: 0000000000000038 R08: ffff888030913bf7 R09: 1ffff1100612277e
R10: dffffc0000000000 R11: ffffed100612277f R12: dffffc0000000000
R13: ffff888030913bf0 R14: 0000000000000008 R15: 0000000000000000
FS: 0000000000000000(0000) GS:ffff888125c52000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000055c4d8c01950 CR3: 000000006f4f2000 CR4: 00000000003526f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<IRQ>
queue_work_on+0x181/0x270 kernel/workqueue.c:2392
__usb_hcd_giveback_urb+0x417/0x690 drivers/usb/core/hcd.c:1650
dummy_timer+0x862/0x4550 drivers/usb/gadget/udc/dummy_hcd.c:1994
__run_hrtimer kernel/time/hrtimer.c:1761 [inline]
__hrtimer_run_queues+0x52c/0xc60 kernel/time/hrtimer.c:1825
hrtimer_run_softirq+0x187/0x2b0 kernel/time/hrtimer.c:1842
handle_softirqs+0x286/0x870 kernel/softirq.c:579
__do_softirq kernel/softirq.c:613 [inline]
invoke_softirq kernel/softirq.c:453 [inline]
__irq_exit_rcu+0xca/0x1f0 kernel/softirq.c:680
irq_exit_rcu+0x9/0x30 kernel/softirq.c:696
instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1050 [inline]
sysvec_apic_timer_interrupt+0xa6/0xc0 arch/x86/kernel/apic/apic.c:1050
</IRQ>
<TASK>
asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:702
RIP: 0010:console_flush_all+0x7f7/0xc40 kernel/printk/printk.c:3227
Code: 48 21 c3 0f 85 e9 01 00 00 e8 e5 20 1f 00 48 8b 5c 24 20 4d 85 f6 75 07 e8 d6 20 1f 00 eb 06 e8 cf 20 1f 00 fb 48 8b 44 24 28 <42> 80 3c 20 00 74 08 48 89 df e8 ca 97 82 00 48 8b 1b 48 8b 44 24
RSP: 0018:ffffc900000f70a0 EFLAGS: 00000293
RAX: 1ffffffff1d36b07 RBX: ffffffff8e9b5838 RCX: ffff88801d2b1e00
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: ffffc900000f71f0 R08: ffffffff8fa112f7 R09: 1ffffffff1f4225e
R10: dffffc0000000000 R11: fffffbfff1f4225f R12: dffffc0000000000
R13: 0000000000000001 R14: 0000000000000200 R15: ffffffff8e9b57e0
__console_flush_and_unlock kernel/printk/printk.c:3285 [inline]
console_unlock+0xc4/0x270 kernel/printk/printk.c:3325
vprintk_emit+0x5b7/0x7a0 kernel/printk/printk.c:2450
dev_vprintk_emit+0x337/0x3f0 drivers/base/core.c:4917
dev_printk_emit+0xe0/0x130 drivers/base/core.c:4928
_dev_info+0x10a/0x160 drivers/base/core.c:4986
usb_disconnect+0xdd/0x910 drivers/usb/core/hub.c:2298
hub_port_connect drivers/usb/core/hub.c:5375 [inline]
hub_port_connect_change drivers/usb/core/hub.c:5675 [inline]
port_event drivers/usb/core/hub.c:5835 [inline]
hub_event+0x1cdb/0x4a00 drivers/usb/core/hub.c:5917
process_one_work kernel/workqueue.c:3238 [inline]
process_scheduled_works+0xae1/0x17b0 kernel/workqueue.c:3321
worker_thread+0x8a0/0xda0 kernel/workqueue.c:3402
kthread+0x70e/0x8a0 kernel/kthread.c:464
ret_from_fork+0x3f9/0x770 arch/x86/kernel/process.c:148
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:__queue_work+0x9e/0xfe0 kernel/workqueue.c:2256
Code: 8b 1d fe 53 12 11 31 ff 89 de e8 5d 97 35 00 85 db 0f 85 fc 0c 00 00 e8 10 93 35 00 49 8d 97 c0 01 00 00 48 89 d5 48 c1 ed 03 <42> 0f b6 44 25 00 84 c0 48 89 54 24 08 0f 85 44 0d 00 00 8b 1a 89
RSP: 0018:ffffc90000007708 EFLAGS: 00010002
RAX: ffffffff818ac910 RBX: 0000000000000000 RCX: ffff88801d2b1e00
RDX: 00000000000001c0 RSI: 0000000000000000 RDI: 0000000000000000
RBP: 0000000000000038 R08: ffff888030913bf7 R09: 1ffff1100612277e
R10: dffffc0000000000 R11: ffffed100612277f R12: dffffc0000000000
R13: ffff888030913bf0 R14: 0000000000000008 R15: 0000000000000000
FS: 0000000000000000(0000) GS:ffff888125c52000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000055c4d8c01950 CR3: 000000006f4f2000 CR4: 00000000003526f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
----------------
Code disassembly (best guess):
0: 8b 1d fe 53 12 11 mov 0x111253fe(%rip),%ebx # 0x11125404
6: 31 ff xor %edi,%edi
8: 89 de mov %ebx,%esi
a: e8 5d 97 35 00 call 0x35976c
f: 85 db test %ebx,%ebx
11: 0f 85 fc 0c 00 00 jne 0xd13
17: e8 10 93 35 00 call 0x35932c
1c: 49 8d 97 c0 01 00 00 lea 0x1c0(%r15),%rdx
23: 48 89 d5 mov %rdx,%rbp
26: 48 c1 ed 03 shr $0x3,%rbp
* 2a: 42 0f b6 44 25 00 movzbl 0x0(%rbp,%r12,1),%eax <-- trapping instruction
30: 84 c0 test %al,%al
32: 48 89 54 24 08 mov %rdx,0x8(%rsp)
37: 0f 85 44 0d 00 00 jne 0xd81
3d: 8b 1a mov (%rdx),%ebx
3f: 89 .byte 0x89


Tested on:

commit: bdc7f8c5 Merge tag 'mm-stable-2025-06-06-16-09' of git..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=162f6c0c580000
kernel config: https://syzkaller.appspot.com/x/.config?x=fd0cea6d0f67318f
dashboard link: https://syzkaller.appspot.com/bug?extid=9a4aec827829942045ff
compiler: Debian clang version 20.1.6 (++20250514063057+1e4d39e07757-1~exp1~20250514183223.118), Debian LLD 20.1.6

Note: no patches were applied.

Hillf Danton

unread,
Jun 7, 2025, 4:45:41 AM6/7/25
to syzbot, linux-...@vger.kernel.org, syzkall...@googlegroups.com
> Date: Fri, 06 Jun 2025 18:16:27 -0700
> Hello,
>
> syzbot found the following issue on:
>
> HEAD commit: 7f9039c524a3 Merge tag 'for-linus' of git://git.kernel.org..
> git tree: upstream
> console+strace: https://syzkaller.appspot.com/x/log.txt?x=10e2180c580000
> kernel config: https://syzkaller.appspot.com/x/.config?x=6acfdd5e5c8ef3d0
> dashboard link: https://syzkaller.appspot.com/bug?extid=9a4aec827829942045ff
> compiler: Debian clang version 20.1.6 (++20250514063057+1e4d39e07757-1~exp1~20250514183223.118), Debian LLD 20.1.6
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=13fd0570580000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=17c7c1d4580000
>
> The issue was bisected to:
>
> commit a7f3813e589fd8e2834720829a47b5eb914a9afe
> Author: Marcello Sylvester Bauer <sy...@sylv.io>
> Date: Thu Apr 11 14:51:28 2024 +0000
>
> usb: gadget: dummy_hcd: Switch to hrtimer transfer scheduler

#syz test upstream master

--- x/drivers/usb/core/hub.c
+++ y/drivers/usb/core/hub.c
@@ -2295,8 +2295,6 @@ void usb_disconnect(struct usb_device **
* this quiesces everything except pending urbs.
*/
usb_set_device_state(udev, USB_STATE_NOTATTACHED);
- dev_info(&udev->dev, "USB disconnect, device number %d\n",
- udev->devnum);

/*
* Ensure that the pm runtime code knows that the USB device
--

syzbot

unread,
Jun 7, 2025, 5:19:05 AM6/7/25
to hda...@sina.com, linux-...@vger.kernel.org, syzkall...@googlegroups.com
Hello,

syzbot has tested the proposed patch but the reproducer is still triggering an issue:
stack segment fault in __usb_hcd_giveback_urb

Oops: stack segment: 0000 [#1] SMP KASAN PTI
CPU: 0 UID: 0 PID: 5953 Comm: kworker/0:3 Not tainted 6.15.0-syzkaller-13655-gbdc7f8c5adad-dirty #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025
Workqueue: usb_hub_wq hub_event
RIP: 0010:__queue_work+0x9e/0xfe0 kernel/workqueue.c:2256
Code: 8b 1d fe 53 12 11 31 ff 89 de e8 5d 97 35 00 85 db 0f 85 fc 0c 00 00 e8 10 93 35 00 49 8d 97 c0 01 00 00 48 89 d5 48 c1 ed 03 <42> 0f b6 44 25 00 84 c0 48 89 54 24 08 0f 85 44 0d 00 00 8b 1a 89
RSP: 0018:ffffc90000007708 EFLAGS: 00010002
RAX: ffffffff818ac910 RBX: 0000000000000000 RCX: ffff88802f028000
RDX: 00000000000001c0 RSI: 0000000000000000 RDI: 0000000000000000
RBP: 0000000000000038 R08: ffff88807cca3bf7 R09: 1ffff1100f99477e
R10: dffffc0000000000 R11: ffffed100f99477f R12: dffffc0000000000
R13: ffff88807cca3bf0 R14: 0000000000000008 R15: 0000000000000000
FS: 0000000000000000(0000) GS:ffff888125c52000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f2c1ba76e90 CR3: 000000007655c000 CR4: 00000000003526f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<IRQ>
queue_work_on+0x181/0x270 kernel/workqueue.c:2392
__usb_hcd_giveback_urb+0x41a/0x690 drivers/usb/core/hcd.c:1650
dummy_timer+0x862/0x4550 drivers/usb/gadget/udc/dummy_hcd.c:1994
__run_hrtimer kernel/time/hrtimer.c:1761 [inline]
__hrtimer_run_queues+0x52c/0xc60 kernel/time/hrtimer.c:1825
hrtimer_run_softirq+0x187/0x2b0 kernel/time/hrtimer.c:1842
handle_softirqs+0x286/0x870 kernel/softirq.c:579
__do_softirq kernel/softirq.c:613 [inline]
invoke_softirq kernel/softirq.c:453 [inline]
__irq_exit_rcu+0xca/0x1f0 kernel/softirq.c:680
irq_exit_rcu+0x9/0x30 kernel/softirq.c:696
instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1050 [inline]
sysvec_apic_timer_interrupt+0xa6/0xc0 arch/x86/kernel/apic/apic.c:1050
</IRQ>
<TASK>
asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:702
RIP: 0010:check_kcov_mode kernel/kcov.c:194 [inline]
RIP: 0010:write_comp_data kernel/kcov.c:246 [inline]
RIP: 0010:__sanitizer_cov_trace_const_cmp4+0x37/0x90 kernel/kcov.c:314
Code: 08 e0 9c 92 65 8b 0d b8 7f dc 10 81 e1 00 01 ff 00 74 11 81 f9 00 01 00 00 75 5b 83 ba 3c 16 00 00 00 74 52 8b 8a 18 16 00 00 <83> f9 03 75 47 48 8b 8a 20 16 00 00 44 8b 8a 1c 16 00 00 49 c1 e1
RSP: 0018:ffffc90003fdf4d0 EFLAGS: 00000246
RAX: ffffffff825d79a5 RBX: ffffffff825d787c RCX: 0000000000000000
RDX: ffff88802f028000 RSI: 0000000000000001 RDI: 0000000000000000
RBP: 0000000000000001 R08: 0000000000000000 R09: ffffffff825d787c
R10: dffffc0000000000 R11: ffffed100e5500d3 R12: dffffc0000000000
R13: 0000000000000001 R14: ffff88801b2ff000 R15: ffff88802fa68e10
rcu_read_unlock include/linux/rcupdate.h:869 [inline]
class_rcu_destructor include/linux/rcupdate.h:1155 [inline]
kernfs_root+0x145/0x230 fs/kernfs/kernfs-internal.h:80
kernfs_put+0x57/0x480 fs/kernfs/dir.c:571
device_del+0x251/0x8e0 drivers/base/core.c:3856
device_unregister+0x20/0xc0 drivers/base/core.c:3922
usb_remove_ep_devs+0x50/0x80 drivers/usb/core/endpoint.c:189
remove_intf_ep_devs drivers/usb/core/message.c:1266 [inline]
usb_disable_device+0x36b/0x8a0 drivers/usb/core/message.c:1417
usb_disconnect+0x304/0x8f0 drivers/usb/core/hub.c:2314
hub_port_connect drivers/usb/core/hub.c:5373 [inline]
hub_port_connect_change drivers/usb/core/hub.c:5673 [inline]
port_event drivers/usb/core/hub.c:5833 [inline]
hub_event+0x1cdb/0x4a00 drivers/usb/core/hub.c:5915
process_one_work kernel/workqueue.c:3238 [inline]
process_scheduled_works+0xae1/0x17b0 kernel/workqueue.c:3321
worker_thread+0x8a0/0xda0 kernel/workqueue.c:3402
kthread+0x70e/0x8a0 kernel/kthread.c:464
ret_from_fork+0x3f9/0x770 arch/x86/kernel/process.c:148
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:__queue_work+0x9e/0xfe0 kernel/workqueue.c:2256
Code: 8b 1d fe 53 12 11 31 ff 89 de e8 5d 97 35 00 85 db 0f 85 fc 0c 00 00 e8 10 93 35 00 49 8d 97 c0 01 00 00 48 89 d5 48 c1 ed 03 <42> 0f b6 44 25 00 84 c0 48 89 54 24 08 0f 85 44 0d 00 00 8b 1a 89
RSP: 0018:ffffc90000007708 EFLAGS: 00010002
RAX: ffffffff818ac910 RBX: 0000000000000000 RCX: ffff88802f028000
RDX: 00000000000001c0 RSI: 0000000000000000 RDI: 0000000000000000
RBP: 0000000000000038 R08: ffff88807cca3bf7 R09: 1ffff1100f99477e
R10: dffffc0000000000 R11: ffffed100f99477f R12: dffffc0000000000
R13: ffff88807cca3bf0 R14: 0000000000000008 R15: 0000000000000000
FS: 0000000000000000(0000) GS:ffff888125c52000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f2c1ba76e90 CR3: 000000007655c000 CR4: 00000000003526f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
----------------
Code disassembly (best guess):
0: 8b 1d fe 53 12 11 mov 0x111253fe(%rip),%ebx # 0x11125404
6: 31 ff xor %edi,%edi
8: 89 de mov %ebx,%esi
a: e8 5d 97 35 00 call 0x35976c
f: 85 db test %ebx,%ebx
11: 0f 85 fc 0c 00 00 jne 0xd13
17: e8 10 93 35 00 call 0x35932c
1c: 49 8d 97 c0 01 00 00 lea 0x1c0(%r15),%rdx
23: 48 89 d5 mov %rdx,%rbp
26: 48 c1 ed 03 shr $0x3,%rbp
* 2a: 42 0f b6 44 25 00 movzbl 0x0(%rbp,%r12,1),%eax <-- trapping instruction
30: 84 c0 test %al,%al
32: 48 89 54 24 08 mov %rdx,0x8(%rsp)
37: 0f 85 44 0d 00 00 jne 0xd81
3d: 8b 1a mov (%rdx),%ebx
3f: 89 .byte 0x89


Tested on:

commit: bdc7f8c5 Merge tag 'mm-stable-2025-06-06-16-09' of git..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=1052e20c580000
kernel config: https://syzkaller.appspot.com/x/.config?x=fd0cea6d0f67318f
dashboard link: https://syzkaller.appspot.com/bug?extid=9a4aec827829942045ff
compiler: Debian clang version 20.1.6 (++20250514063057+1e4d39e07757-1~exp1~20250514183223.118), Debian LLD 20.1.6
patch: https://syzkaller.appspot.com/x/patch.diff?x=155f5570580000

syzbot

unread,
Jun 10, 2025, 3:10:59 AM6/10/25
to linux-...@vger.kernel.org, syzkall...@googlegroups.com
For archival purposes, forwarding an incoming command email to
linux-...@vger.kernel.org, syzkall...@googlegroups.com.

***

Subject: #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git 19272b37aa4f83ca52bdf9c16d5d81bdd1354494
Author: dman...@yandex.ru

#syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git 19272b37aa4f83ca52bdf9c16d5d81bdd1354494

syzbot

unread,
Jun 10, 2025, 5:57:04 AM6/10/25
to dman...@yandex.ru, linux-...@vger.kernel.org, syzkall...@googlegroups.com
Hello,

syzbot has tested the proposed patch but the reproducer is still triggering an issue:
WARNING in carl9170_usb_rx_complete

------------[ cut here ]------------
WARNING: CPU: 1 PID: 6612 at drivers/net/wireless/ath/carl9170/usb.c:448 carl9170_usb_rx_complete+0x28a/0x2d0 drivers/net/wireless/ath/carl9170/usb.c:448
Modules linked in:
CPU: 1 UID: 0 PID: 6612 Comm: kworker/1:3 Not tainted 6.16.0-rc1-syzkaller-dirty #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025
Workqueue: usb_hub_wq hub_event
RIP: 0010:carl9170_usb_rx_complete+0x28a/0x2d0 drivers/net/wireless/ath/carl9170/usb.c:448
Code: 5d e9 2a 04 27 04 44 89 e1 80 e1 07 80 c1 03 38 c1 0f 8c 05 fe ff ff 4c 89 e7 e8 c1 da 62 fb e9 f8 fd ff ff e8 77 63 ff fa 90 <0f> 0b 90 e9 f7 fe ff ff 44 89 f1 80 e1 07 80 c1 03 38 c1 0f 8c 4c
RSP: 0018:ffffc90000a08868 EFLAGS: 00010046
RAX: ffffffff86c0fb79 RBX: ffff8880775430a0 RCX: ffff88802f255a00
RDX: 0000000000000100 RSI: 0000000000000000 RDI: 0000000000000000
RBP: 0000000000000000 R08: ffff888077543a6b R09: 1ffff1100eea874d
R10: dffffc0000000000 R11: ffffed100eea874e R12: 00000000ffffffb9
R13: dffffc0000000000 R14: ffff88807754358c R15: ffff8880664d9600
FS: 0000000000000000(0000) GS:ffff888125d52000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007ff0496217d0 CR3: 0000000078f80000 CR4: 00000000003526f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<IRQ>
__usb_hcd_giveback_urb+0x41a/0x690 drivers/usb/core/hcd.c:1650
dummy_timer+0x862/0x4550 drivers/usb/gadget/udc/dummy_hcd.c:1995
__run_hrtimer kernel/time/hrtimer.c:1761 [inline]
__hrtimer_run_queues+0x52c/0xc60 kernel/time/hrtimer.c:1825
hrtimer_run_softirq+0x187/0x2b0 kernel/time/hrtimer.c:1842
handle_softirqs+0x286/0x870 kernel/softirq.c:579
__do_softirq kernel/softirq.c:613 [inline]
invoke_softirq kernel/softirq.c:453 [inline]
__irq_exit_rcu+0xca/0x1f0 kernel/softirq.c:680
irq_exit_rcu+0x9/0x30 kernel/softirq.c:696
instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1050 [inline]
sysvec_apic_timer_interrupt+0xa6/0xc0 arch/x86/kernel/apic/apic.c:1050
</IRQ>
<TASK>
asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:702
RIP: 0010:console_flush_all+0x7f7/0xc40 kernel/printk/printk.c:3227
Code: 48 21 c3 0f 85 e9 01 00 00 e8 b5 23 1f 00 48 8b 5c 24 20 4d 85 f6 75 07 e8 a6 23 1f 00 eb 06 e8 9f 23 1f 00 fb 48 8b 44 24 28 <42> 80 3c 20 00 74 08 48 89 df e8 fa 9a 82 00 48 8b 1b 48 8b 44 24
RSP: 0018:ffffc90003e4f0a0 EFLAGS: 00000293
RAX: 1ffffffff1d36a1f RBX: ffffffff8e9b50f8 RCX: ffff88802f255a00
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: ffffc90003e4f1f0 R08: ffffffff8fa108f7 R09: 1ffffffff1f4211e
R10: dffffc0000000000 R11: fffffbfff1f4211f R12: dffffc0000000000
R13: 0000000000000001 R14: 0000000000000200 R15: ffffffff8e9b50a0
__console_flush_and_unlock kernel/printk/printk.c:3285 [inline]
console_unlock+0xc4/0x270 kernel/printk/printk.c:3325
vprintk_emit+0x5b7/0x7a0 kernel/printk/printk.c:2450
dev_vprintk_emit+0x337/0x3f0 drivers/base/core.c:4917
dev_printk_emit+0xe0/0x130 drivers/base/core.c:4928
_dev_info+0x10a/0x160 drivers/base/core.c:4986
usb_disconnect+0xdd/0x910 drivers/usb/core/hub.c:2298
hub_port_connect drivers/usb/core/hub.c:5375 [inline]
hub_port_connect_change drivers/usb/core/hub.c:5675 [inline]
port_event drivers/usb/core/hub.c:5835 [inline]
hub_event+0x1cdb/0x4a00 drivers/usb/core/hub.c:5917
process_one_work kernel/workqueue.c:3238 [inline]
process_scheduled_works+0xae1/0x17b0 kernel/workqueue.c:3321
worker_thread+0x8a0/0xda0 kernel/workqueue.c:3402
kthread+0x70e/0x8a0 kernel/kthread.c:464
ret_from_fork+0x3fc/0x770 arch/x86/kernel/process.c:148
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
----------------
Code disassembly (best guess):
0: 48 21 c3 and %rax,%rbx
3: 0f 85 e9 01 00 00 jne 0x1f2
9: e8 b5 23 1f 00 call 0x1f23c3
e: 48 8b 5c 24 20 mov 0x20(%rsp),%rbx
13: 4d 85 f6 test %r14,%r14
16: 75 07 jne 0x1f
18: e8 a6 23 1f 00 call 0x1f23c3
1d: eb 06 jmp 0x25
1f: e8 9f 23 1f 00 call 0x1f23c3
24: fb sti
25: 48 8b 44 24 28 mov 0x28(%rsp),%rax
* 2a: 42 80 3c 20 00 cmpb $0x0,(%rax,%r12,1) <-- trapping instruction
2f: 74 08 je 0x39
31: 48 89 df mov %rbx,%rdi
34: e8 fa 9a 82 00 call 0x829b33
39: 48 8b 1b mov (%rbx),%rbx
3c: 48 rex.W
3d: 8b .byte 0x8b
3e: 44 rex.R
3f: 24 .byte 0x24


Tested on:

commit: 19272b37 Linux 6.16-rc1
git tree: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
console output: https://syzkaller.appspot.com/x/log.txt?x=1489c60c580000
kernel config: https://syzkaller.appspot.com/x/.config?x=c07f08ee4bcfb276
dashboard link: https://syzkaller.appspot.com/bug?extid=9a4aec827829942045ff
compiler: Debian clang version 20.1.6 (++20250514063057+1e4d39e07757-1~exp1~20250514183223.118), Debian LLD 20.1.6
patch: https://syzkaller.appspot.com/x/patch.diff?x=11aac60c580000

syzbot

unread,
Jun 16, 2025, 1:44:28 PM6/16/25
to linux-...@vger.kernel.org, syzkall...@googlegroups.com
For archival purposes, forwarding an incoming command email to
linux-...@vger.kernel.org, syzkall...@googlegroups.com.

***

Subject: #syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git 44a5ab7a7958fbf190ae384b8ef252f23b840c1b
Author: dman...@yandex.ru

#syz test https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git 44a5ab7a7958fbf190ae384b8ef252f23b840c1b

syzbot

unread,
Jun 16, 2025, 2:10:08 PM6/16/25
to dman...@yandex.ru, linux-...@vger.kernel.org, syzkall...@googlegroups.com
Hello,

syzbot has tested the proposed patch and the reproducer did not trigger any issue:

Reported-by: syzbot+9a4aec...@syzkaller.appspotmail.com
Tested-by: syzbot+9a4aec...@syzkaller.appspotmail.com

Tested on:

commit: 44a5ab7a Merge tag 'powerpc-6.16-3' of git://git.kerne..
git tree: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
console output: https://syzkaller.appspot.com/x/log.txt?x=11a48370580000
kernel config: https://syzkaller.appspot.com/x/.config?x=8f72e140c622500d
dashboard link: https://syzkaller.appspot.com/bug?extid=9a4aec827829942045ff
compiler: Debian clang version 20.1.6 (++20250514063057+1e4d39e07757-1~exp1~20250514183223.118), Debian LLD 20.1.6
patch: https://syzkaller.appspot.com/x/patch.diff?x=175515d4580000

Note: testing is done by a robot and is best-effort only.

syzbot

unread,
Jul 20, 2025, 1:40:04 AM7/20/25
to chun...@gmail.com, dman...@yandex.ru, gre...@linuxfoundation.org, hda...@sina.com, jeff.j...@oss.qualcomm.com, linux-...@vger.kernel.org, linu...@vger.kernel.org, marcell...@9elements.com, st...@rowland.harvard.edu, sy...@sylv.io, syzkall...@googlegroups.com
syzbot suspects this issue was fixed by commit:

commit 15d25307692312cec4b57052da73387f91a2e870
Author: Dmitry Antipov <dman...@yandex.ru>
Date: Mon Jun 16 18:12:05 2025 +0000

wifi: carl9170: do not ping device which has failed to load firmware

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=129c938c580000
start commit: 7f9039c524a3 Merge tag 'for-linus' of git://git.kernel.org..
git tree: upstream
If the result looks correct, please mark the issue as fixed by replying with:

#syz fix: wifi: carl9170: do not ping device which has failed to load firmware

syzbot

unread,
Sep 15, 2025, 4:19:21 AM9/15/25
to syzkall...@googlegroups.com
Auto-closing this bug as obsolete.
No recent activity, existing reproducers are no longer triggering the issue.
Reply all
Reply to author
Forward
0 new messages