general protection fault in ath9k_hif_usb_rx_cb

16 views
Skip to first unread message

syzbot

unread,
Mar 26, 2020, 7:34:17 AM3/26/20
to andre...@google.com, ath9k...@qca.qualcomm.com, da...@davemloft.net, kv...@codeaurora.org, linux-...@vger.kernel.org, linu...@vger.kernel.org, linux-w...@vger.kernel.org, net...@vger.kernel.org, syzkall...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: e17994d1 usb: core: kcov: collect coverage from usb comple..
git tree: https://github.com/google/kasan.git usb-fuzzer
console output: https://syzkaller.appspot.com/x/log.txt?x=112072ade00000
kernel config: https://syzkaller.appspot.com/x/.config?x=5d64370c438bc60
dashboard link: https://syzkaller.appspot.com/bug?extid=40d5d2e8a4680952f042
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=143981d3e00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=152072ade00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+40d5d2...@syzkaller.appspotmail.com

general protection fault, probably for non-canonical address 0xdffffc0000000015: 0000 [#1] SMP KASAN
KASAN: null-ptr-deref in range [0x00000000000000a8-0x00000000000000af]
CPU: 0 PID: 0 Comm: swapper/0 Not tainted 5.6.0-rc5-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
RIP: 0010:usb_get_intfdata include/linux/usb.h:265 [inline]
RIP: 0010:ath9k_hif_usb_rx_cb+0x103/0xf70 drivers/net/wireless/ath/ath9k/hif_usb.c:643
Code: 83 3c 24 00 48 89 c3 0f 84 19 04 00 00 e8 95 d5 6e fe 48 8d bb a8 00 00 00 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 27 0c 00 00 4c 8b a3 a8 00 00 00 4d 85 e4 0f 84
RSP: 0018:ffff8881db209928 EFLAGS: 00010002
RAX: dffffc0000000000 RBX: 0000000000000000 RCX: ffffffff835ed4bc
RDX: 0000000000000015 RSI: ffffffff82d0804b RDI: 00000000000000a8
RBP: ffff8881d3c03b00 R08: ffffffff8702cc40 R09: fffffbfff0e28205
R10: fffffbfff0e28204 R11: ffffffff87141023 R12: 0100000000000001
R13: ffff8881ceef31c8 R14: ffff8881d3c03b00 R15: ffff8881d3c03b40
FS: 0000000000000000(0000) GS:ffff8881db200000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000056168f698a48 CR3: 00000001d050a000 CR4: 00000000001406f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<IRQ>
__usb_hcd_giveback_urb+0x29a/0x550 drivers/usb/core/hcd.c:1650
usb_hcd_giveback_urb+0x368/0x420 drivers/usb/core/hcd.c:1716
dummy_timer+0x1258/0x32ae drivers/usb/gadget/udc/dummy_hcd.c:1966
call_timer_fn+0x195/0x6f0 kernel/time/timer.c:1404
expire_timers kernel/time/timer.c:1449 [inline]
__run_timers kernel/time/timer.c:1773 [inline]
__run_timers kernel/time/timer.c:1740 [inline]
run_timer_softirq+0x5f9/0x1500 kernel/time/timer.c:1786
__do_softirq+0x21e/0x950 kernel/softirq.c:292
invoke_softirq kernel/softirq.c:373 [inline]
irq_exit+0x178/0x1a0 kernel/softirq.c:413
exiting_irq arch/x86/include/asm/apic.h:546 [inline]
smp_apic_timer_interrupt+0x141/0x540 arch/x86/kernel/apic/apic.c:1146
apic_timer_interrupt+0xf/0x20 arch/x86/entry/entry_64.S:829
</IRQ>
RIP: 0010:default_idle+0x28/0x300 arch/x86/kernel/process.c:696
Code: cc cc 41 56 41 55 65 44 8b 2d 44 77 72 7a 41 54 55 53 0f 1f 44 00 00 e8 b6 62 b5 fb e9 07 00 00 00 0f 00 2d ea 0c 53 00 fb f4 <65> 44 8b 2d 20 77 72 7a 0f 1f 44 00 00 5b 5d 41 5c 41 5d 41 5e c3
RSP: 0018:ffffffff87007d80 EFLAGS: 00000246 ORIG_RAX: ffffffffffffff13
RAX: 0000000000000007 RBX: ffffffff8702cc40 RCX: 0000000000000000
RDX: 0000000000000000 RSI: 0000000000000006 RDI: ffffffff8702d48c
RBP: fffffbfff0e05988 R08: ffffffff8702cc40 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000000
R13: 0000000000000000 R14: ffffffff87e607c0 R15: 0000000000000000
cpuidle_idle_call kernel/sched/idle.c:154 [inline]
do_idle+0x3e0/0x500 kernel/sched/idle.c:269
cpu_startup_entry+0x14/0x20 kernel/sched/idle.c:361
start_kernel+0xe16/0xe5a init/main.c:998
secondary_startup_64+0xb6/0xc0 arch/x86/kernel/head_64.S:242
Modules linked in:
---[ end trace eca37a89cc7a3629 ]---
RIP: 0010:usb_get_intfdata include/linux/usb.h:265 [inline]
RIP: 0010:ath9k_hif_usb_rx_cb+0x103/0xf70 drivers/net/wireless/ath/ath9k/hif_usb.c:643
Code: 83 3c 24 00 48 89 c3 0f 84 19 04 00 00 e8 95 d5 6e fe 48 8d bb a8 00 00 00 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 27 0c 00 00 4c 8b a3 a8 00 00 00 4d 85 e4 0f 84
RSP: 0018:ffff8881db209928 EFLAGS: 00010002
RAX: dffffc0000000000 RBX: 0000000000000000 RCX: ffffffff835ed4bc
RDX: 0000000000000015 RSI: ffffffff82d0804b RDI: 00000000000000a8
RBP: ffff8881d3c03b00 R08: ffffffff8702cc40 R09: fffffbfff0e28205
R10: fffffbfff0e28204 R11: ffffffff87141023 R12: 0100000000000001
R13: ffff8881ceef31c8 R14: ffff8881d3c03b00 R15: ffff8881d3c03b40
FS: 0000000000000000(0000) GS:ffff8881db200000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000056168f698a48 CR3: 00000001d050a000 CR4: 00000000001406f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this bug, for details see:
https://goo.gl/tpsmEJ#testing-patches

Qiujun Huang

unread,
Apr 2, 2020, 9:52:01 PM4/2/20
to syzbot, Andrey Konovalov, ath9k...@qca.qualcomm.com, da...@davemloft.net, kv...@codeaurora.org, LKML, USB list, linux-w...@vger.kernel.org, net...@vger.kernel.org, syzkaller-bugs
0001-ath9k-fix-use-after-free-read-in-htc_connect_service.patch

syzbot

unread,
Apr 2, 2020, 10:27:06 PM4/2/20
to andre...@google.com, anen...@gmail.com, ath9k...@qca.qualcomm.com, da...@davemloft.net, kv...@codeaurora.org, linux-...@vger.kernel.org, linu...@vger.kernel.org, linux-w...@vger.kernel.org, net...@vger.kernel.org, syzkall...@googlegroups.com
Hello,

syzbot has tested the proposed patch but the reproducer still triggered crash:
general protection fault in ath9k_hif_usb_rx_cb

general protection fault, probably for non-canonical address 0xdffffc0000000015: 0000 [#1] SMP KASAN
KASAN: null-ptr-deref in range [0x00000000000000a8-0x00000000000000af]
CPU: 0 PID: 3247 Comm: kworker/0:5 Not tainted 5.6.0-rc7-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Workqueue: usb_hub_wq hub_event
RIP: 0010:usb_get_intfdata include/linux/usb.h:265 [inline]
RIP: 0010:ath9k_hif_usb_rx_cb+0x103/0xf70 drivers/net/wireless/ath/ath9k/hif_usb.c:643
Code: 83 3c 24 00 48 89 c3 0f 84 19 04 00 00 e8 25 bb 6e fe 48 8d bb a8 00 00 00 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 27 0c 00 00 4c 8b a3 a8 00 00 00 4d 85 e4 0f 84
RSP: 0018:ffff8881db209930 EFLAGS: 00010002
RAX: dffffc0000000000 RBX: 0000000000000000 RCX: ffffffff835ef3fc
RDX: 0000000000000015 RSI: ffffffff82d09cfb RDI: 00000000000000a8
RBP: ffff8881c6aa1100 R08: ffff8881bda26200 R09: ffffed103b115045
R10: ffffed103b115044 R11: ffff8881d88a8223 R12: 00000000ffffffb9
R13: ffff8881d4d98000 R14: ffff8881c6aa1100 R15: ffff8881c6aa1100
FS: 0000000000000000(0000) GS:ffff8881db200000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000000000076c061 CR3: 00000001bdacb000 CR4: 00000000001406f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<IRQ>
__usb_hcd_giveback_urb+0x1f2/0x470 drivers/usb/core/hcd.c:1648
usb_hcd_giveback_urb+0x368/0x420 drivers/usb/core/hcd.c:1713
dummy_timer+0x1258/0x32ae drivers/usb/gadget/udc/dummy_hcd.c:1966
call_timer_fn+0x195/0x6f0 kernel/time/timer.c:1404
expire_timers kernel/time/timer.c:1449 [inline]
__run_timers kernel/time/timer.c:1773 [inline]
__run_timers kernel/time/timer.c:1740 [inline]
run_timer_softirq+0x5f9/0x1500 kernel/time/timer.c:1786
__do_softirq+0x21e/0x950 kernel/softirq.c:292
invoke_softirq kernel/softirq.c:373 [inline]
irq_exit+0x178/0x1a0 kernel/softirq.c:413
exiting_irq arch/x86/include/asm/apic.h:546 [inline]
smp_apic_timer_interrupt+0x141/0x540 arch/x86/kernel/apic/apic.c:1146
apic_timer_interrupt+0xf/0x20 arch/x86/entry/entry_64.S:829
</IRQ>
RIP: 0010:lock_is_held_type+0x1ce/0x240 kernel/locking/lockdep.c:4526
Code: 89 f9 48 c1 e9 03 0f b6 0c 11 48 89 fa 83 e2 07 83 c2 03 38 ca 7c 04 84 c9 75 6e c7 83 4c 08 00 00 00 00 00 00 ff 74 24 08 9d <48> 83 c4 18 5b 5d 41 5c 41 5d 41 5e 41 5f c3 31 c0 eb a8 48 83 c4
RSP: 0018:ffff8881cc707698 EFLAGS: 00000246 ORIG_RAX: ffffffffffffff13
RAX: 0000000000000001 RBX: ffff8881bda26200 RCX: 0000000000000000
RDX: 0000000000000007 RSI: ffffffff871e1540 RDI: ffff8881bda26a4c
RBP: ffff8881bda26200 R08: ffff8881bda26200 R09: fffffbfff0e3c29d
R10: ffff8881cc707830 R11: ffffffff871e14e7 R12: ffff8881bda26a48
R13: ffffed1037b44d49 R14: ffffffff871e1540 R15: ffff8881bda26af0
lock_is_held include/linux/lockdep.h:361 [inline]
kernfs_active+0xb3/0xf0 fs/kernfs/dir.c:29
__kernfs_remove fs/kernfs/dir.c:1301 [inline]
__kernfs_remove+0x173/0x9b0 fs/kernfs/dir.c:1282
kernfs_remove_by_name_ns+0x51/0xb0 fs/kernfs/dir.c:1516
kernfs_remove_by_name include/linux/kernfs.h:586 [inline]
remove_files.isra.0+0x76/0x190 fs/sysfs/group.c:27
sysfs_remove_group+0xb3/0x1b0 fs/sysfs/group.c:288
sysfs_remove_groups fs/sysfs/group.c:312 [inline]
sysfs_remove_groups+0x5c/0xa0 fs/sysfs/group.c:304
device_remove_groups drivers/base/core.c:1602 [inline]
device_remove_attrs+0xa9/0x150 drivers/base/core.c:1784
device_del+0x479/0xd30 drivers/base/core.c:2676
device_unregister+0x22/0xc0 drivers/base/core.c:2709
usb_remove_ep_devs+0x3e/0x80 drivers/usb/core/endpoint.c:215
remove_intf_ep_devs+0x108/0x1d0 drivers/usb/core/message.c:1113
usb_disable_device+0x235/0x790 drivers/usb/core/message.c:1237
usb_disconnect+0x293/0x900 drivers/usb/core/hub.c:2211
hub_port_connect drivers/usb/core/hub.c:5046 [inline]
hub_port_connect_change drivers/usb/core/hub.c:5335 [inline]
port_event drivers/usb/core/hub.c:5481 [inline]
hub_event+0x1a1d/0x4300 drivers/usb/core/hub.c:5563
process_one_work+0x94b/0x1620 kernel/workqueue.c:2266
worker_thread+0x96/0xe20 kernel/workqueue.c:2412
kthread+0x318/0x420 kernel/kthread.c:255
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:352
Modules linked in:
---[ end trace 37b88c5796d54927 ]---
RIP: 0010:usb_get_intfdata include/linux/usb.h:265 [inline]
RIP: 0010:ath9k_hif_usb_rx_cb+0x103/0xf70 drivers/net/wireless/ath/ath9k/hif_usb.c:643
Code: 83 3c 24 00 48 89 c3 0f 84 19 04 00 00 e8 25 bb 6e fe 48 8d bb a8 00 00 00 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 27 0c 00 00 4c 8b a3 a8 00 00 00 4d 85 e4 0f 84
RSP: 0018:ffff8881db209930 EFLAGS: 00010002
RAX: dffffc0000000000 RBX: 0000000000000000 RCX: ffffffff835ef3fc
RDX: 0000000000000015 RSI: ffffffff82d09cfb RDI: 00000000000000a8
RBP: ffff8881c6aa1100 R08: ffff8881bda26200 R09: ffffed103b115045
R10: ffffed103b115044 R11: ffff8881d88a8223 R12: 00000000ffffffb9
R13: ffff8881d4d98000 R14: ffff8881c6aa1100 R15: ffff8881c6aa1100
FS: 0000000000000000(0000) GS:ffff8881db200000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000000000076c061 CR3: 00000001bdacb000 CR4: 00000000001406f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400


Tested on:

commit: 0fa84af8 Merge tag 'usb-serial-5.7-rc1' of https://git.ker..
console output: https://syzkaller.appspot.com/x/log.txt?x=14c6c02be00000
kernel config: https://syzkaller.appspot.com/x/.config?x=a782c087b1f425c6
dashboard link: https://syzkaller.appspot.com/bug?extid=40d5d2e8a4680952f042
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
patch: https://syzkaller.appspot.com/x/patch.diff?x=125bf733e00000

syzbot

unread,
Apr 3, 2020, 3:25:06 AM4/3/20
to anen...@gmail.com, syzkall...@googlegroups.com
Hello,

syzbot has tested the proposed patch but the reproducer still triggered crash:
general protection fault in ath9k_hif_usb_rx_cb

general protection fault, probably for non-canonical address 0xdffffc0000000015: 0000 [#1] SMP KASAN
KASAN: null-ptr-deref in range [0x00000000000000a8-0x00000000000000af]
CPU: 1 PID: 17 Comm: kworker/1:0 Not tainted 5.6.0-rc7-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Workqueue: events request_firmware_work_func
RIP: 0010:usb_get_intfdata include/linux/usb.h:265 [inline]
RIP: 0010:ath9k_hif_usb_rx_cb+0xf6/0x1010 drivers/net/wireless/ath/ath9k/hif_usb.c:655
Code: 00 00 48 8b 44 24 08 31 f6 48 8b 78 40 e8 02 53 8e 00 48 ba 00 00 00 00 00 fc ff df 48 8d b8 a8 00 00 00 48 89 f9 48 c1 e9 03 <80> 3c 11 00 0f 85 2a 0d 00 00 4c 8b b0 a8 00 00 00 41 b8 92 02 00
RSP: 0018:ffff8881db309928 EFLAGS: 00010002
RAX: 0000000000000000 RBX: dffffc0000000000 RCX: 0000000000000015
RDX: dffffc0000000000 RSI: ffffffff835eeddb RDI: 00000000000000a8
RBP: ffff8881d3493c00 R08: ffff8881da24b100 R09: ffffed10399f9845
R10: ffffed10399f9844 R11: ffff8881ccfcc223 R12: 00000000ffffffb9
R13: ffff8881d4cd9000 R14: ffff8881ccfcc1c8 R15: ffff8881d3493c00
FS: 0000000000000000(0000) GS:ffff8881db300000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000055d25b1aa160 CR3: 00000001d050a000 CR4: 00000000001406e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<IRQ>
__usb_hcd_giveback_urb+0x1f2/0x470 drivers/usb/core/hcd.c:1648
usb_hcd_giveback_urb+0x368/0x420 drivers/usb/core/hcd.c:1713
dummy_timer+0x1258/0x32ae drivers/usb/gadget/udc/dummy_hcd.c:1966
call_timer_fn+0x195/0x6f0 kernel/time/timer.c:1404
expire_timers kernel/time/timer.c:1449 [inline]
__run_timers kernel/time/timer.c:1773 [inline]
__run_timers kernel/time/timer.c:1740 [inline]
run_timer_softirq+0x5f9/0x1500 kernel/time/timer.c:1786
__do_softirq+0x21e/0x950 kernel/softirq.c:292
invoke_softirq kernel/softirq.c:373 [inline]
irq_exit+0x178/0x1a0 kernel/softirq.c:413
exiting_irq arch/x86/include/asm/apic.h:546 [inline]
smp_apic_timer_interrupt+0x141/0x540 arch/x86/kernel/apic/apic.c:1146
apic_timer_interrupt+0xf/0x20 arch/x86/entry/entry_64.S:829
</IRQ>
RIP: 0010:arch_local_irq_restore arch/x86/include/asm/irqflags.h:85 [inline]
RIP: 0010:console_unlock+0xbb4/0xca0 kernel/printk/printk.c:2477
Code: 0d fe ff ff e8 dd 35 16 00 48 8b bc 24 80 00 00 00 e8 e0 dc ff ff e9 f9 fa ff ff e8 c6 35 16 00 e8 c1 7d 1b 00 ff 74 24 30 9d <e9> e5 fa ff ff e8 12 ff 3e 00 e9 93 f6 ff ff e8 18 ff 3e 00 e9 4d
RSP: 0018:ffff8881da267a38 EFLAGS: 00000293 ORIG_RAX: ffffffffffffff13
RAX: 0000000000000007 RBX: 0000000000000200 RCX: 0000000000000006
RDX: 0000000000000000 RSI: 0000000000000008 RDI: ffff8881da24b94c
RBP: 0000000000000001 R08: ffff8881da24b100 R09: fffffbfff1267090
R10: fffffbfff126708f R11: ffffffff8933847f R12: ffffffff82a092f0
R13: ffffffff874d4830 R14: 000000000000006f R15: dffffc0000000000
vprintk_emit+0x171/0x3d0 kernel/printk/printk.c:1996
vprintk_func+0x75/0x113 kernel/printk/printk_safe.c:386
printk+0xba/0xed kernel/printk/printk.c:2056
ath9k_hif_usb_alloc_rx_urbs drivers/net/wireless/ath/ath9k/hif_usb.c:885 [inline]
ath9k_hif_usb_alloc_urbs+0x6b6/0xab1 drivers/net/wireless/ath/ath9k/hif_usb.c:984
ath9k_hif_usb_dev_init drivers/net/wireless/ath/ath9k/hif_usb.c:1075 [inline]
ath9k_hif_usb_firmware_cb+0x247/0x53f drivers/net/wireless/ath/ath9k/hif_usb.c:1216
request_firmware_work_func+0x126/0x242 drivers/base/firmware_loader/main.c:976
process_one_work+0x94b/0x1620 kernel/workqueue.c:2266
worker_thread+0x96/0xe20 kernel/workqueue.c:2412
kthread+0x318/0x420 kernel/kthread.c:255
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:352
Modules linked in:
---[ end trace 891a6abc99156acc ]---
RIP: 0010:usb_get_intfdata include/linux/usb.h:265 [inline]
RIP: 0010:ath9k_hif_usb_rx_cb+0xf6/0x1010 drivers/net/wireless/ath/ath9k/hif_usb.c:655
Code: 00 00 48 8b 44 24 08 31 f6 48 8b 78 40 e8 02 53 8e 00 48 ba 00 00 00 00 00 fc ff df 48 8d b8 a8 00 00 00 48 89 f9 48 c1 e9 03 <80> 3c 11 00 0f 85 2a 0d 00 00 4c 8b b0 a8 00 00 00 41 b8 92 02 00
RSP: 0018:ffff8881db309928 EFLAGS: 00010002
RAX: 0000000000000000 RBX: dffffc0000000000 RCX: 0000000000000015
RDX: dffffc0000000000 RSI: ffffffff835eeddb RDI: 00000000000000a8
RBP: ffff8881d3493c00 R08: ffff8881da24b100 R09: ffffed10399f9845
R10: ffffed10399f9844 R11: ffff8881ccfcc223 R12: 00000000ffffffb9
R13: ffff8881d4cd9000 R14: ffff8881ccfcc1c8 R15: ffff8881d3493c00
FS: 0000000000000000(0000) GS:ffff8881db300000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000055d25b1aa160 CR3: 00000001d050a000 CR4: 00000000001406e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400


Tested on:

commit: 0fa84af8 Merge tag 'usb-serial-5.7-rc1' of https://git.ker..
git tree: https://github.com/google/kasan.git usb-fuzzer
console output: https://syzkaller.appspot.com/x/log.txt?x=15a2b4c7e00000
kernel config: https://syzkaller.appspot.com/x/.config?x=a782c087b1f425c6
dashboard link: https://syzkaller.appspot.com/bug?extid=40d5d2e8a4680952f042
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
patch: https://syzkaller.appspot.com/x/patch.diff?x=1222e9b7e00000

syzbot

unread,
Apr 3, 2020, 5:39:06 AM4/3/20
to anen...@gmail.com, syzkall...@googlegroups.com
Hello,

syzbot has tested the proposed patch but the reproducer still triggered crash:
general protection fault in ath9k_hif_usb_rx_cb

haley: catch dev null, urb 0xffff8881cf923d00. ath9k_hif_usb_rx_cb, 658
general protection fault, probably for non-canonical address 0xdffffc0000000015: 0000 [#1] SMP KASAN
KASAN: null-ptr-deref in range [0x00000000000000a8-0x00000000000000af]
CPU: 0 PID: 155 Comm: systemd-udevd Not tainted 5.6.0-rc7-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
RIP: 0010:usb_get_intfdata include/linux/usb.h:265 [inline]
RIP: 0010:ath9k_hif_usb_rx_cb+0x153/0x1050 drivers/net/wireless/ath/ath9k/hif_usb.c:665
Code: 83 3c 24 00 48 89 c3 0f 84 11 04 00 00 e8 e5 bd 6e fe 48 8d bb a8 00 00 00 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 0b 0d 00 00 4c 8b b3 a8 00 00 00 4d 85 f6 0f 84
RSP: 0018:ffff8881db209928 EFLAGS: 00010002
RAX: dffffc0000000000 RBX: 0000000000000000 RCX: ffffffff835eeebc
RDX: 0000000000000015 RSI: ffffffff82d09a3b RDI: 00000000000000a8
RBP: ffff8881cf923d40 R08: ffff8881d23e4980 R09: ffffed103b646248
R10: ffffed103b646247 R11: ffff8881db23123f R12: ffff8881d8dc8000
R13: ffff8881d4c8f000 R14: ffff8881d88631c8 R15: ffff8881cf923d00
FS: 00007f003751c8c0(0000) GS:ffff8881db200000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000563119e80d58 CR3: 00000001cf92f000 CR4: 00000000001406f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<IRQ>
__usb_hcd_giveback_urb+0x1f2/0x470 drivers/usb/core/hcd.c:1648
usb_hcd_giveback_urb+0x368/0x420 drivers/usb/core/hcd.c:1713
dummy_timer+0x1258/0x32ae drivers/usb/gadget/udc/dummy_hcd.c:1966
call_timer_fn+0x195/0x6f0 kernel/time/timer.c:1404
expire_timers kernel/time/timer.c:1449 [inline]
__run_timers kernel/time/timer.c:1773 [inline]
__run_timers kernel/time/timer.c:1740 [inline]
run_timer_softirq+0x5f9/0x1500 kernel/time/timer.c:1786
__do_softirq+0x21e/0x950 kernel/softirq.c:292
invoke_softirq kernel/softirq.c:373 [inline]
irq_exit+0x178/0x1a0 kernel/softirq.c:413
exiting_irq arch/x86/include/asm/apic.h:546 [inline]
smp_apic_timer_interrupt+0x141/0x540 arch/x86/kernel/apic/apic.c:1146
apic_timer_interrupt+0xf/0x20 arch/x86/entry/entry_64.S:829
</IRQ>
RIP: 0010:unwind_next_frame+0x779/0x19e0 arch/x86/kernel/unwind_orc.c:428
Code: 0f b6 0c 0f 4c 89 cf 83 e7 07 40 38 fe 40 0f 9e c7 40 84 f6 40 0f 95 c6 40 84 f7 0f 85 bd 0b 00 00 83 e2 07 38 d1 40 0f 9e c6 <84> c9 0f 95 c2 40 84 d6 0f 85 a6 0b 00 00 83 e0 0f 3c 09 0f 87 2e
RSP: 0018:ffff8881cf8f7530 EFLAGS: 00000293 ORIG_RAX: ffffffffffffff13
RAX: 0000000000000014 RBX: ffff8881cf8f7608 RCX: 0000000000000000
RDX: 0000000000000005 RSI: 0000000000000001 RDI: 0000000000000001
RBP: 1ffff11039f1eeae R08: ffffffff882c6a30 R09: ffffffff882c6a34
R10: 0000000000006790 R11: 000000000004c01a R12: ffff8881cf8f763d
R13: ffff8881cf8f7658 R14: ffff8881cf8f7650 R15: 0000000000000001
arch_stack_walk+0x74/0xd0 arch/x86/kernel/stacktrace.c:25
stack_trace_save+0x8c/0xc0 kernel/stacktrace.c:123
save_stack+0x1b/0x80 mm/kasan/common.c:72
set_track mm/kasan/common.c:80 [inline]
__kasan_kmalloc mm/kasan/common.c:515 [inline]
__kasan_kmalloc.constprop.0+0xbf/0xd0 mm/kasan/common.c:488
slab_post_alloc_hook mm/slab.h:584 [inline]
slab_alloc_node mm/slub.c:2786 [inline]
slab_alloc mm/slub.c:2794 [inline]
kmem_cache_alloc+0xd8/0x300 mm/slub.c:2799
anon_vma_chain_alloc mm/rmap.c:130 [inline]
anon_vma_clone+0x10e/0x5d0 mm/rmap.c:289
anon_vma_fork+0x82/0x490 mm/rmap.c:352
dup_mmap kernel/fork.c:559 [inline]
dup_mm+0x8e6/0x1180 kernel/fork.c:1360
copy_mm kernel/fork.c:1416 [inline]
copy_process+0x26ef/0x6640 kernel/fork.c:2081
_do_fork+0x12d/0xfd0 kernel/fork.c:2430
__do_sys_clone kernel/fork.c:2585 [inline]
__se_sys_clone kernel/fork.c:2566 [inline]
__x64_sys_clone+0x182/0x210 kernel/fork.c:2566
do_syscall_64+0xb6/0x5a0 arch/x86/entry/common.c:294
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x7f003636c38b
Code: db 45 85 f6 0f 85 95 01 00 00 64 4c 8b 04 25 10 00 00 00 31 d2 4d 8d 90 d0 02 00 00 31 f6 bf 11 00 20 01 b8 38 00 00 00 0f 05 <48> 3d 00 f0 ff ff 0f 87 de 00 00 00 85 c0 41 89 c5 0f 85 e5 00 00
RSP: 002b:00007ffd35e3e1b0 EFLAGS: 00000246 ORIG_RAX: 0000000000000038
RAX: ffffffffffffffda RBX: 00007ffd35e3e1b0 RCX: 00007f003636c38b
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000001200011
RBP: 00007ffd35e3e200 R08: 00007f003751c8c0 R09: 0000000000000210
R10: 00007f003751cb90 R11: 0000000000000246 R12: 0000000000000000
R13: 0000000000000020 R14: 0000000000000000 R15: 0000000000000000
Modules linked in:
---[ end trace a3086d59686f9a7e ]---
RIP: 0010:usb_get_intfdata include/linux/usb.h:265 [inline]
RIP: 0010:ath9k_hif_usb_rx_cb+0x153/0x1050 drivers/net/wireless/ath/ath9k/hif_usb.c:665
Code: 83 3c 24 00 48 89 c3 0f 84 11 04 00 00 e8 e5 bd 6e fe 48 8d bb a8 00 00 00 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 0b 0d 00 00 4c 8b b3 a8 00 00 00 4d 85 f6 0f 84
RSP: 0018:ffff8881db209928 EFLAGS: 00010002
RAX: dffffc0000000000 RBX: 0000000000000000 RCX: ffffffff835eeebc
RDX: 0000000000000015 RSI: ffffffff82d09a3b RDI: 00000000000000a8
RBP: ffff8881cf923d40 R08: ffff8881d23e4980 R09: ffffed103b646248
R10: ffffed103b646247 R11: ffff8881db23123f R12: ffff8881d8dc8000
R13: ffff8881d4c8f000 R14: ffff8881d88631c8 R15: ffff8881cf923d00
FS: 00007f003751c8c0(0000) GS:ffff8881db200000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000563119e80d58 CR3: 00000001cf92f000 CR4: 00000000001406f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400


Tested on:

commit: 0fa84af8 Merge tag 'usb-serial-5.7-rc1' of https://git.ker..
git tree: https://github.com/google/kasan.git usb-fuzzer
console output: https://syzkaller.appspot.com/x/log.txt?x=15c56d93e00000
kernel config: https://syzkaller.appspot.com/x/.config?x=a782c087b1f425c6
dashboard link: https://syzkaller.appspot.com/bug?extid=40d5d2e8a4680952f042
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
patch: https://syzkaller.appspot.com/x/patch.diff?x=119fbc63e00000

syzbot

unread,
Apr 3, 2020, 8:33:04 AM4/3/20
to anen...@gmail.com, syzkall...@googlegroups.com
Hello,

syzbot has tested the proposed patch but the reproducer still triggered crash:
WARNING in format_decode

haley: dev 0xffff8881d25fb000. ath9k_hif_request_firmware, 1193
usb 3-1: ath9k_htc: Firmware ath9k_htc/htc_9271-1.4.0.fw requested
------------[ cut here ]------------
Please remove unsupported %$ in format string
WARNING: CPU: 1 PID: 17 at lib/vsprintf.c:2430 format_decode+0x8ef/0xad0 lib/vsprintf.c:2430
Kernel panic - not syncing: panic_on_warn set ...
CPU: 1 PID: 17 Comm: kworker/1:0 Not tainted 5.6.0-rc7-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Workqueue: usb_hub_wq hub_event
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0xef/0x16e lib/dump_stack.c:118
panic+0x2aa/0x6e1 kernel/panic.c:221
__warn.cold+0x2f/0x30 kernel/panic.c:582
report_bug+0x27b/0x2f0 lib/bug.c:195
fixup_bug arch/x86/kernel/traps.c:174 [inline]
fixup_bug arch/x86/kernel/traps.c:169 [inline]
do_error_trap+0x12b/0x1e0 arch/x86/kernel/traps.c:267
do_invalid_op+0x32/0x40 arch/x86/kernel/traps.c:286
invalid_op+0x23/0x30 arch/x86/entry/entry_64.S:1027
RIP: 0010:format_decode+0x8ef/0xad0 lib/vsprintf.c:2430
Code: e8 56 ae b3 fb c6 45 00 12 e9 3f fe ff ff e8 48 ae b3 fb 41 0f be f4 48 c7 c7 60 64 a2 86 c6 05 cc 25 50 02 01 e8 f9 3e 88 fb <0f> 0b 48 8b 44 24 38 48 89 04 24 e9 da fc ff ff 4c 89 ef e8 79 77
RSP: 0018:ffff8881da266f58 EFLAGS: 00010082
RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000000
RDX: 0000000000000000 RSI: ffffffff8129755d RDI: ffffed103b44cddd
RBP: ffff8881da267070 R08: ffff8881da24b100 R09: ffffed103b6647aa
R10: ffffed103b6647a9 R11: ffff8881db323d4b R12: 0000000000000024
R13: ffffffff86278c79 R14: 1ffff1103b44cdee R15: 0000000000000024
vsnprintf+0x155/0x14f0 lib/vsprintf.c:2526
vscnprintf+0x29/0x80 lib/vsprintf.c:2677
vprintk_store+0x40/0x4b0 kernel/printk/printk.c:1917
vprintk_emit+0xc8/0x3d0 kernel/printk/printk.c:1978
vprintk_func+0x75/0x113 kernel/printk/printk_safe.c:386
printk+0xba/0xed kernel/printk/printk.c:2056
ath9k_hif_usb_probe.cold+0x23a/0x29f drivers/net/wireless/ath/ath9k/hif_usb.c:1354
usb_probe_interface+0x310/0x800 drivers/usb/core/driver.c:374
really_probe+0x290/0xac0 drivers/base/dd.c:551
driver_probe_device+0x223/0x350 drivers/base/dd.c:724
__device_attach_driver+0x1d1/0x290 drivers/base/dd.c:831
bus_for_each_drv+0x162/0x1e0 drivers/base/bus.c:431
__device_attach+0x217/0x390 drivers/base/dd.c:897
bus_probe_device+0x1e4/0x290 drivers/base/bus.c:491
device_add+0x1459/0x1bf0 drivers/base/core.c:2500
usb_set_configuration+0xece/0x1840 drivers/usb/core/message.c:2025
usb_generic_driver_probe+0x9d/0xe0 drivers/usb/core/generic.c:241
usb_probe_device+0xd9/0x230 drivers/usb/core/driver.c:272
really_probe+0x290/0xac0 drivers/base/dd.c:551
driver_probe_device+0x223/0x350 drivers/base/dd.c:724
__device_attach_driver+0x1d1/0x290 drivers/base/dd.c:831
bus_for_each_drv+0x162/0x1e0 drivers/base/bus.c:431
__device_attach+0x217/0x390 drivers/base/dd.c:897
bus_probe_device+0x1e4/0x290 drivers/base/bus.c:491
device_add+0x1459/0x1bf0 drivers/base/core.c:2500
usb_new_device.cold+0x540/0xcd0 drivers/usb/core/hub.c:2548
hub_port_connect drivers/usb/core/hub.c:5195 [inline]
hub_port_connect_change drivers/usb/core/hub.c:5335 [inline]
port_event drivers/usb/core/hub.c:5481 [inline]
hub_event+0x21cb/0x4300 drivers/usb/core/hub.c:5563
process_one_work+0x94b/0x1620 kernel/workqueue.c:2266
worker_thread+0x96/0xe20 kernel/workqueue.c:2412
kthread+0x318/0x420 kernel/kthread.c:255
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:352
Shutting down cpus with NMI
Kernel Offset: disabled


Tested on:

commit: 0fa84af8 Merge tag 'usb-serial-5.7-rc1' of https://git.ker..
git tree: https://github.com/google/kasan.git usb-fuzzer
console output: https://syzkaller.appspot.com/x/log.txt?x=10d90f9de00000
kernel config: https://syzkaller.appspot.com/x/.config?x=a782c087b1f425c6
dashboard link: https://syzkaller.appspot.com/bug?extid=40d5d2e8a4680952f042
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
patch: https://syzkaller.appspot.com/x/patch.diff?x=1030482be00000

syzbot

unread,
Apr 3, 2020, 8:55:05 AM4/3/20
to anen...@gmail.com, syzkall...@googlegroups.com
Hello,

syzbot has tested the proposed patch but the reproducer still triggered crash:
general protection fault in ath9k_hif_usb_rx_cb

haley: catch dev null, urb 0xffff8881ccfea800. ath9k_hif_usb_rx_cb, 658
general protection fault, probably for non-canonical address 0xdffffc0000000015: 0000 [#1] SMP KASAN
KASAN: null-ptr-deref in range [0x00000000000000a8-0x00000000000000af]
CPU: 0 PID: 9 Comm: ksoftirqd/0 Not tainted 5.6.0-rc7-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
RIP: 0010:usb_get_intfdata include/linux/usb.h:265 [inline]
RIP: 0010:ath9k_hif_usb_rx_cb+0x153/0x1050 drivers/net/wireless/ath/ath9k/hif_usb.c:665
Code: 83 3c 24 00 48 89 c3 0f 84 11 04 00 00 e8 e5 bd 6e fe 48 8d bb a8 00 00 00 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 0b 0d 00 00 4c 8b b3 a8 00 00 00 4d 85 f6 0f 84
RSP: 0018:ffff8881da2077e8 EFLAGS: 00010002
RAX: dffffc0000000000 RBX: 0000000000000000 RCX: ffffffff835eef2c
RDX: 0000000000000015 RSI: ffffffff82d09a3b RDI: 00000000000000a8
RBP: ffff8881ccfea840 R08: ffff8881da1e4980 R09: ffffed103b646248
R10: ffffed103b646247 R11: ffff8881db23123f R12: ffff8881d8f9b000
R13: ffff8881d4d24000 R14: ffff8881d886b1c8 R15: ffff8881ccfea800
FS: 0000000000000000(0000) GS:ffff8881db200000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000055a769b94158 CR3: 00000001cfde2000 CR4: 00000000001406f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
__usb_hcd_giveback_urb+0x1f2/0x470 drivers/usb/core/hcd.c:1648
usb_hcd_giveback_urb+0x368/0x420 drivers/usb/core/hcd.c:1713
dummy_timer+0x1258/0x32ae drivers/usb/gadget/udc/dummy_hcd.c:1966
call_timer_fn+0x195/0x6f0 kernel/time/timer.c:1404
expire_timers kernel/time/timer.c:1449 [inline]
__run_timers kernel/time/timer.c:1773 [inline]
__run_timers kernel/time/timer.c:1740 [inline]
run_timer_softirq+0x5f9/0x1500 kernel/time/timer.c:1786
__do_softirq+0x21e/0x950 kernel/softirq.c:292
run_ksoftirqd kernel/softirq.c:603 [inline]
run_ksoftirqd+0x1f/0x40 kernel/softirq.c:595
smpboot_thread_fn+0x3e8/0x870 kernel/smpboot.c:165
kthread+0x318/0x420 kernel/kthread.c:255
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:352
Modules linked in:
---[ end trace 45127d0cdc795b9f ]---
RIP: 0010:usb_get_intfdata include/linux/usb.h:265 [inline]
RIP: 0010:ath9k_hif_usb_rx_cb+0x153/0x1050 drivers/net/wireless/ath/ath9k/hif_usb.c:665
Code: 83 3c 24 00 48 89 c3 0f 84 11 04 00 00 e8 e5 bd 6e fe 48 8d bb a8 00 00 00 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 0b 0d 00 00 4c 8b b3 a8 00 00 00 4d 85 f6 0f 84
RSP: 0018:ffff8881da2077e8 EFLAGS: 00010002
RAX: dffffc0000000000 RBX: 0000000000000000 RCX: ffffffff835eef2c
RDX: 0000000000000015 RSI: ffffffff82d09a3b RDI: 00000000000000a8
RBP: ffff8881ccfea840 R08: ffff8881da1e4980 R09: ffffed103b646248
R10: ffffed103b646247 R11: ffff8881db23123f R12: ffff8881d8f9b000
R13: ffff8881d4d24000 R14: ffff8881d886b1c8 R15: ffff8881ccfea800
FS: 0000000000000000(0000) GS:ffff8881db200000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000055a769b94158 CR3: 00000001cfde2000 CR4: 00000000001406f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400


Tested on:

commit: 0fa84af8 Merge tag 'usb-serial-5.7-rc1' of https://git.ker..
git tree: https://github.com/google/kasan.git usb-fuzzer
console output: https://syzkaller.appspot.com/x/log.txt?x=14a1d533e00000
kernel config: https://syzkaller.appspot.com/x/.config?x=a782c087b1f425c6
dashboard link: https://syzkaller.appspot.com/bug?extid=40d5d2e8a4680952f042
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
patch: https://syzkaller.appspot.com/x/patch.diff?x=10e8f393e00000

syzbot

unread,
Apr 3, 2020, 10:26:05 AM4/3/20
to anen...@gmail.com, syzkall...@googlegroups.com
Hello,

syzbot tried to test the proposed patch but build/boot failed:

ia2_v4l.o
CC drivers/gpu/drm/i915/display/intel_bw.o
CC drivers/media/usb/dvb-usb-v2/mxl111sf-tuner.o
CC drivers/media/dvb-frontends/cxd2820r_c.o
CC drivers/gpu/drm/i915/display/intel_cdclk.o
CC drivers/media/usb/pwc/pwc-timon.o
CC drivers/gpu/drm/i915/display/intel_color.o
CC drivers/media/usb/dvb-usb-v2/rtl28xxu.o
CC drivers/media/rc/keymaps/rc-tango.o
CC drivers/media/usb/gspca/gspca.o
CC drivers/media/usb/gspca/autogain_functions.o
CC drivers/media/usb/dvb-usb/dibusb-mb.o
CC drivers/media/usb/dvb-usb/dibusb-mc.o
CC drivers/media/usb/uvc/uvc_queue.o
CC drivers/media/usb/dvb-usb/nova-t-usb2.o
CC drivers/media/usb/gspca/m5602/m5602_po1030.o
CC drivers/media/usb/dvb-usb/umt-010.o
AR drivers/media/usb/airspy/built-in.a
CC drivers/media/dvb-frontends/cxd2820r_t.o
CC drivers/media/usb/dvb-usb-v2/dvbsky.o
CC drivers/media/usb/gspca/stv06xx/stv06xx_pb0100.o
CC drivers/media/usb/cpia2/cpia2_usb.o
CC drivers/media/usb/cpia2/cpia2_core.o
CC drivers/media/rc/keymaps/rc-tanix-tx3mini.o
CC drivers/media/usb/gspca/benq.o
AR drivers/mmc/core/built-in.a
CC drivers/media/usb/dvb-usb-v2/zd1301.o
AR drivers/mmc/built-in.a
AR drivers/media/usb/gspca/gl860/built-in.a
CC drivers/media/dvb-frontends/cxd2820r_t2.o
AR drivers/media/usb/pwc/built-in.a
CC drivers/media/usb/gspca/stv06xx/stv06xx_st6422.o
CC drivers/media/dvb-frontends/cxd2841er.o
CC drivers/media/usb/au0828/au0828-core.o
CC drivers/media/usb/au0828/au0828-i2c.o
AR drivers/media/usb/hackrf/built-in.a
CC drivers/media/usb/gspca/conex.o
CC drivers/media/usb/uvc/uvc_v4l2.o
CC drivers/media/rc/keymaps/rc-tanix-tx5max.o
CC drivers/media/rc/keymaps/rc-tbs-nec.o
CC drivers/media/dvb-frontends/drxk_hard.o
CC drivers/media/usb/hdpvr/hdpvr-control.o
CC drivers/media/usb/pvrusb2/pvrusb2-i2c-core.o
AR drivers/media/usb/msi2500/built-in.a
CC drivers/gpu/drm/i915/display/intel_combo_phy.o
CC drivers/media/rc/keymaps/rc-technisat-ts35.o
CC drivers/media/usb/hdpvr/hdpvr-core.o
CC drivers/media/usb/uvc/uvc_video.o
CC drivers/media/usb/pvrusb2/pvrusb2-encoder.o
CC drivers/media/usb/pvrusb2/pvrusb2-audio.o
CC drivers/media/usb/gspca/m5602/m5602_s5k83a.o
CC drivers/media/usb/dvb-usb/m920x.o
AR drivers/media/usb/gspca/stv06xx/built-in.a
CC drivers/media/usb/gspca/m5602/m5602_s5k4aa.o
CC drivers/media/dvb-frontends/tda18271c2dd.o
CC drivers/gpu/drm/i915/display/intel_connector.o
CC drivers/media/rc/keymaps/rc-technisat-usb2.o
CC drivers/media/usb/dvb-usb/digitv.o
CC drivers/media/usb/dvb-usb/cxusb.o
CC drivers/media/usb/dvb-usb/ttusb2.o
CC drivers/media/rc/keymaps/rc-terratec-cinergy-c-pci.o
CC drivers/media/usb/hdpvr/hdpvr-video.o
CC drivers/media/rc/keymaps/rc-terratec-cinergy-s2-hd.o
CC drivers/gpu/drm/i915/display/intel_display.o
CC drivers/gpu/drm/i915/display/intel_display_power.o
CC drivers/media/usb/au0828/au0828-cards.o
CC drivers/media/usb/au0828/au0828-dvb.o
CC drivers/media/rc/keymaps/rc-terratec-cinergy-xs.o
AR drivers/media/usb/cpia2/built-in.a
CC drivers/media/usb/uvc/uvc_ctrl.o
AR drivers/media/usb/dvb-usb-v2/built-in.a
CC drivers/media/usb/usbvision/usbvision-core.o
CC drivers/media/usb/uvc/uvc_status.o
CC drivers/media/usb/hdpvr/hdpvr-i2c.o
CC drivers/media/usb/pvrusb2/pvrusb2-video-v4l.o
CC drivers/media/usb/usbvision/usbvision-video.o
CC drivers/media/dvb-frontends/si2165.o
CC drivers/media/usb/gspca/cpia1.o
CC drivers/gpu/drm/i915/display/intel_dpio_phy.o
AR drivers/media/usb/gspca/m5602/built-in.a
CC drivers/media/rc/keymaps/rc-terratec-slim.o
CC drivers/gpu/drm/i915/display/intel_dpll_mgr.o
CC drivers/media/usb/au0828/au0828-video.o
CC drivers/media/usb/gspca/dtcs033.o
CC drivers/media/usb/uvc/uvc_isight.o
CC drivers/media/usb/au0828/au0828-vbi.o
CC drivers/media/usb/uvc/uvc_debugfs.o
CC drivers/media/usb/gspca/etoms.o
CC drivers/media/usb/pvrusb2/pvrusb2-eeprom.o
CC drivers/media/rc/keymaps/rc-terratec-slim-2.o
CC drivers/media/usb/stk1160/stk1160-core.o
CC drivers/gpu/drm/i915/display/intel_dsb.o
CC drivers/media/usb/pvrusb2/pvrusb2-main.o
CC drivers/gpu/drm/i915/display/intel_fbc.o
CC drivers/media/usb/pvrusb2/pvrusb2-hdw.o
CC drivers/media/usb/stk1160/stk1160-v4l.o
CC drivers/media/usb/stk1160/stk1160-video.o
CC drivers/media/usb/stk1160/stk1160-i2c.o
CC drivers/media/usb/cx231xx/cx231xx-video.o
AR drivers/media/usb/hdpvr/built-in.a
CC drivers/media/usb/usbvision/usbvision-i2c.o
CC drivers/media/rc/keymaps/rc-tivo.o
CC drivers/media/rc/keymaps/rc-tevii-nec.o
CC drivers/media/usb/dvb-usb/dib0700_core.o
CC drivers/media/usb/uvc/uvc_entity.o
CC drivers/media/usb/uvc/uvc_metadata.o
CC drivers/media/dvb-frontends/a8293.o
CC drivers/media/usb/au0828/au0828-input.o
CC drivers/media/usb/usbvision/usbvision-cards.o
CC drivers/media/usb/tm6000/tm6000-cards.o
CC drivers/media/usb/tm6000/tm6000-core.o
CC drivers/media/usb/pvrusb2/pvrusb2-v4l2.o
CC drivers/media/usb/pvrusb2/pvrusb2-ctrl.o
CC drivers/media/usb/pvrusb2/pvrusb2-std.o
CC drivers/media/dvb-frontends/sp2.o
CC drivers/media/rc/keymaps/rc-total-media-in-hand-02.o
CC drivers/media/rc/keymaps/rc-total-media-in-hand.o
CC drivers/media/usb/tm6000/tm6000-i2c.o
CC drivers/media/usb/gspca/finepix.o
CC drivers/media/dvb-frontends/tda10071.o
CC drivers/media/rc/keymaps/rc-trekstor.o
CC drivers/media/rc/keymaps/rc-tt-1500.o
CC drivers/media/usb/gspca/jeilinj.o
CC drivers/gpu/drm/i915/display/intel_fifo_underrun.o
CC drivers/media/usb/stk1160/stk1160-ac97.o
AR drivers/media/usb/uvc/built-in.a
CC drivers/media/rc/keymaps/rc-twinhan-dtv-cab-ci.o
CC drivers/media/rc/keymaps/rc-twinhan1027.o
CC drivers/media/usb/em28xx/em28xx-core.o
CC drivers/media/usb/em28xx/em28xx-i2c.o
CC drivers/media/rc/keymaps/rc-vega-s9x.o
CC drivers/media/usb/tm6000/tm6000-video.o
CC drivers/media/dvb-frontends/rtl2830.o
CC drivers/media/rc/keymaps/rc-videomate-m1f.o
CC drivers/media/usb/pvrusb2/pvrusb2-devattr.o
CC drivers/media/rc/keymaps/rc-videomate-s350.o
CC drivers/gpu/drm/i915/display/intel_frontbuffer.o
CC drivers/media/rc/keymaps/rc-videomate-tv-pvr.o
CC drivers/media/usb/pvrusb2/pvrusb2-context.o
CC drivers/media/usb/em28xx/em28xx-cards.o
CC drivers/media/usb/em28xx/em28xx-camera.o
CC drivers/gpu/drm/i915/display/intel_hdcp.o
CC drivers/media/usb/dvb-usb/dib0700_devices.o
CC drivers/media/usb/usbtv/usbtv-core.o
CC drivers/media/usb/tm6000/tm6000-stds.o
AR drivers/media/usb/stk1160/built-in.a
CC drivers/media/usb/usbtv/usbtv-video.o
CC drivers/media/usb/usbtv/usbtv-audio.o
CC drivers/media/rc/keymaps/rc-wetek-hub.o
CC drivers/media/rc/keymaps/rc-wetek-play2.o
CC drivers/media/usb/gspca/jl2005bcd.o
CC drivers/gpu/drm/i915/display/intel_hotplug.o
AR drivers/media/usb/au0828/built-in.a
CC drivers/media/rc/keymaps/rc-winfast.o
CC drivers/media/usb/em28xx/em28xx-video.o
AR drivers/media/usb/usbvision/built-in.a
CC drivers/media/usb/em28xx/em28xx-vbi.o
CC drivers/media/usb/em28xx/em28xx-audio.o
CC drivers/media/usb/em28xx/em28xx-dvb.o
CC drivers/gpu/drm/i915/display/intel_lpe_audio.o
CC drivers/media/dvb-frontends/rtl2832.o
CC drivers/media/usb/gspca/kinect.o
CC drivers/media/usb/cx231xx/cx231xx-i2c.o
CC drivers/media/usb/em28xx/em28xx-input.o
CC drivers/media/usb/gspca/konica.o
CC drivers/media/usb/gspca/mars.o
CC drivers/media/usb/tm6000/tm6000-input.o
CC drivers/media/usb/gspca/mr97310a.o
CC drivers/media/rc/keymaps/rc-winfast-usbii-deluxe.o
CC drivers/media/usb/pvrusb2/pvrusb2-io.o
CC drivers/gpu/drm/i915/display/intel_overlay.o
CC drivers/media/usb/gspca/nw80x.o
CC drivers/media/usb/gspca/ov519.o
CC drivers/media/usb/gspca/ov534.o
CC drivers/media/usb/go7007/go7007-v4l2.o
CC drivers/media/usb/gspca/ov534_9.o
CC drivers/media/usb/go7007/go7007-driver.o
CC drivers/gpu/drm/i915/display/intel_psr.o
CC drivers/media/usb/gspca/pac207.o
AR drivers/media/usb/usbtv/built-in.a
CC drivers/media/rc/keymaps/rc-su3000.o
CC drivers/media/usb/tm6000/tm6000-alsa.o
CC drivers/media/usb/tm6000/tm6000-dvb.o
CC drivers/media/usb/cx231xx/cx231xx-cards.o
CC drivers/media/usb/cx231xx/cx231xx-core.o
CC drivers/gpu/drm/i915/display/intel_quirks.o
CC drivers/gpu/drm/i915/display/intel_sprite.o
CC drivers/media/dvb-frontends/rtl2832_sdr.o
CC drivers/media/rc/keymaps/rc-xbox-dvd.o
CC drivers/gpu/drm/i915/display/intel_tc.o
CC drivers/media/usb/pvrusb2/pvrusb2-ioread.o
CC drivers/media/usb/go7007/go7007-i2c.o
CC drivers/media/usb/as102/as102_drv.o
CC drivers/media/usb/cx231xx/cx231xx-avcore.o
CC drivers/media/usb/pulse8-cec/pulse8-cec.o
CC drivers/media/usb/pvrusb2/pvrusb2-cx2584x-v4l.o
CC drivers/media/usb/go7007/go7007-fw.o
CC drivers/media/usb/pvrusb2/pvrusb2-wm8775.o
CC drivers/gpu/drm/i915/display/intel_vga.o
CC drivers/gpu/drm/i915/display/intel_acpi.o
CC drivers/media/rc/keymaps/rc-x96max.o
CC drivers/media/dvb-frontends/m88rs2000.o
AR drivers/media/usb/tm6000/built-in.a
CC drivers/media/usb/gspca/pac7302.o
CC drivers/media/usb/dvb-usb/opera1.o
CC drivers/media/dvb-frontends/af9033.o
CC drivers/media/rc/keymaps/rc-zx-irdec.o
CC drivers/gpu/drm/i915/display/intel_opregion.o
CC drivers/media/usb/rainshadow-cec/rainshadow-cec.o
CC drivers/media/usb/cx231xx/cx231xx-417.o
CC drivers/gpu/drm/i915/display/intel_fbdev.o
CC drivers/media/usb/as102/as102_fw.o
CC drivers/media/usb/dvb-usb/af9005.o
CC drivers/media/usb/as102/as10x_cmd.o
CC drivers/media/usb/cx231xx/cx231xx-pcb-cfg.o
CC drivers/media/usb/go7007/snd-go7007.o
AR drivers/media/rc/keymaps/built-in.a
CC drivers/gpu/drm/i915/display/dvo_ch7017.o
AR drivers/media/rc/built-in.a
CC drivers/gpu/drm/i915/display/dvo_ch7xxx.o
CC drivers/media/usb/gspca/pac7311.o
CC drivers/media/usb/gspca/se401.o
CC drivers/media/usb/gspca/sn9c2028.o
AR drivers/media/usb/pulse8-cec/built-in.a
CC drivers/media/usb/gspca/sn9c20x.o
CC drivers/media/usb/dvb-usb/af9005-fe.o
CC drivers/media/usb/dvb-usb/af9005-remote.o
CC drivers/media/usb/gspca/sonixb.o
CC drivers/media/usb/dvb-usb/pctv452e.o
AR drivers/media/usb/em28xx/built-in.a
AR drivers/media/usb/rainshadow-cec/built-in.a
CC drivers/media/usb/gspca/sonixj.o
CC drivers/gpu/drm/i915/display/dvo_ivch.o
CC drivers/media/usb/as102/as10x_cmd_stream.o
CC drivers/media/usb/cx231xx/cx231xx-vbi.o
CC drivers/media/usb/pvrusb2/pvrusb2-cs53l32a.o
CC drivers/media/usb/gspca/spca500.o
CC drivers/media/dvb-frontends/as102_fe.o
CC drivers/media/dvb-frontends/gp8psk-fe.o
CC drivers/gpu/drm/i915/display/dvo_ns2501.o
CC drivers/media/usb/go7007/go7007-usb.o
CC drivers/media/usb/cx231xx/cx231xx-input.o
CC drivers/media/usb/dvb-usb/dw2102.o
CC drivers/media/usb/cx231xx/cx231xx-audio.o
CC drivers/media/usb/dvb-usb/dtv5100.o
CC drivers/media/usb/gspca/spca501.o
CC drivers/media/usb/gspca/spca505.o
CC drivers/media/usb/as102/as102_usb_drv.o
CC drivers/media/usb/gspca/spca506.o
CC drivers/media/usb/cx231xx/cx231xx-dvb.o
CC drivers/media/usb/as102/as10x_cmd_cfg.o
CC drivers/media/usb/gspca/spca508.o
CC drivers/media/usb/go7007/go7007-loader.o
CC drivers/media/usb/pvrusb2/pvrusb2-dvb.o
CC drivers/media/dvb-frontends/tc90522.o
CC drivers/gpu/drm/i915/display/dvo_sil164.o
CC drivers/media/usb/gspca/spca561.o
CC drivers/media/usb/gspca/spca1528.o
CC drivers/media/usb/gspca/sq905.o
CC drivers/media/usb/dvb-usb/cinergyT2-core.o
CC drivers/media/usb/gspca/sq905c.o
CC drivers/media/usb/gspca/sq930x.o
CC drivers/media/usb/go7007/s2250-board.o
CC drivers/media/usb/dvb-usb/cinergyT2-fe.o
CC drivers/media/usb/dvb-usb/az6027.o
CC drivers/gpu/drm/i915/display/icl_dsi.o
CC drivers/media/usb/gspca/sunplus.o
CC drivers/gpu/drm/i915/display/dvo_tfp410.o
CC drivers/media/usb/dvb-usb/technisat-usb2.o
CC drivers/media/usb/gspca/stk014.o
CC drivers/media/usb/pvrusb2/pvrusb2-sysfs.o
CC drivers/media/usb/gspca/stk1135.o
CC drivers/media/usb/gspca/stv0680.o
CC drivers/media/dvb-frontends/zd1301_demod.o
CC drivers/media/usb/gspca/t613.o
CC drivers/gpu/drm/i915/display/intel_ddi.o
CC drivers/gpu/drm/i915/display/intel_crt.o
AR drivers/media/usb/as102/built-in.a
CC drivers/media/usb/gspca/topro.o
CC drivers/media/usb/gspca/touptek.o
CC drivers/gpu/drm/i915/display/intel_dp.o
CC drivers/media/usb/gspca/tv8532.o
CC drivers/gpu/drm/i915/display/intel_dp_aux_backlight.o
CC drivers/media/usb/gspca/vc032x.o
CC drivers/media/usb/gspca/vicam.o
CC drivers/media/usb/gspca/xirlink_cit.o
CC drivers/media/usb/gspca/zc3xx.o
CC drivers/gpu/drm/i915/display/intel_dp_link_training.o
CC drivers/gpu/drm/i915/display/intel_dp_mst.o
CC drivers/gpu/drm/i915/display/intel_dsi.o
CC drivers/gpu/drm/i915/display/intel_dsi_dcs_backlight.o
AR drivers/media/usb/go7007/built-in.a
CC drivers/gpu/drm/i915/display/intel_dsi_vbt.o
CC drivers/gpu/drm/i915/display/intel_dvo.o
CC drivers/gpu/drm/i915/display/intel_hdmi.o
CC drivers/gpu/drm/i915/display/intel_gmbus.o
AR drivers/media/usb/cx231xx/built-in.a
CC drivers/gpu/drm/i915/display/intel_lspcon.o
CC drivers/gpu/drm/i915/display/intel_lvds.o
CC drivers/gpu/drm/i915/display/intel_panel.o
CC drivers/gpu/drm/i915/display/intel_sdvo.o
CC drivers/gpu/drm/i915/display/intel_tv.o
AR drivers/media/usb/pvrusb2/built-in.a
CC drivers/gpu/drm/i915/display/vlv_dsi.o
CC drivers/gpu/drm/i915/display/intel_vdsc.o
AR drivers/media/dvb-frontends/built-in.a
CC drivers/gpu/drm/i915/display/vlv_dsi_pll.o
CC drivers/gpu/drm/i915/oa/i915_oa_hsw.o
CC drivers/gpu/drm/i915/oa/i915_oa_bdw.o
AR drivers/media/usb/dvb-usb/built-in.a
CC drivers/gpu/drm/i915/oa/i915_oa_chv.o
CC drivers/gpu/drm/i915/oa/i915_oa_sklgt2.o
CC drivers/gpu/drm/i915/oa/i915_oa_sklgt3.o
CC drivers/gpu/drm/i915/oa/i915_oa_sklgt4.o
CC drivers/gpu/drm/i915/oa/i915_oa_bxt.o
CC drivers/gpu/drm/i915/oa/i915_oa_kblgt2.o
CC drivers/gpu/drm/i915/oa/i915_oa_kblgt3.o
CC drivers/gpu/drm/i915/oa/i915_oa_glk.o
CC drivers/gpu/drm/i915/oa/i915_oa_cflgt2.o
CC drivers/gpu/drm/i915/oa/i915_oa_cflgt3.o
CC drivers/gpu/drm/i915/oa/i915_oa_cnl.o
CC drivers/gpu/drm/i915/oa/i915_oa_icl.o
CC drivers/gpu/drm/i915/oa/i915_oa_tgl.o
CC drivers/gpu/drm/i915/i915_perf.o
CC drivers/gpu/drm/i915/i915_gpu_error.o
CC drivers/gpu/drm/i915/i915_vgpu.o
AR drivers/media/usb/gspca/built-in.a
AR drivers/media/usb/built-in.a
AR drivers/media/built-in.a
AR drivers/gpu/drm/i915/built-in.a
AR drivers/gpu/drm/built-in.a
AR drivers/gpu/built-in.a
Makefile:1683: recipe for target 'drivers' failed
make: *** [drivers] Error 2


Error text is too large and was truncated, full error text is at:
https://syzkaller.appspot.com/x/error.txt?x=13bc10b3e00000


Tested on:

commit: 0fa84af8 Merge tag 'usb-serial-5.7-rc1' of https://git.ker..
git tree: https://github.com/google/kasan.git usb-fuzzer
dashboard link: https://syzkaller.appspot.com/bug?extid=40d5d2e8a4680952f042
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
patch: https://syzkaller.appspot.com/x/patch.diff?x=16d39ccde00000

syzbot

unread,
Apr 3, 2020, 11:09:05 AM4/3/20
to anen...@gmail.com, syzkall...@googlegroups.com
Hello,

syzbot tried to test the proposed patch but build/boot failed:

rtlwifi/rtl8192ee/sw.o
CC drivers/staging/uwb/ie-rcv.o
CC drivers/media/usb/au0828/au0828-cards.o
CC drivers/media/usb/au0828/au0828-dvb.o
AR drivers/iio/humidity/built-in.a
CC drivers/media/usb/au0828/au0828-video.o
CC drivers/staging/uwb/lc-dev.o
AR drivers/iio/imu/bmi160/built-in.a
CC drivers/staging/uwb/neh.o
CC drivers/staging/uwb/lc-rc.o
AR drivers/iio/imu/inv_mpu6050/built-in.a
AR drivers/iio/imu/st_lsm6dsx/built-in.a
CC drivers/media/usb/gspca/ov534_9.o
AR drivers/iio/imu/built-in.a
CC drivers/iio/magnetometer/hid-sensor-magn-3d.o
CC drivers/iio/light/hid-sensor-als.o
CC drivers/gpu/drm/i915/display/intel_vga.o
CC drivers/staging/rtl8712/rtl8712_io.o
CC drivers/iio/light/hid-sensor-prox.o
CC drivers/media/usb/gspca/pac207.o
CC drivers/hid/hid-gembird.o
CC drivers/media/usb/gspca/pac7302.o
CC drivers/media/usb/gspca/pac7311.o
CC drivers/media/usb/gspca/se401.o
AR drivers/staging/wusbcore/host/whci/built-in.a
AR drivers/staging/wusbcore/host/built-in.a
CC drivers/staging/wusbcore/mmc.o
CC drivers/staging/uwb/pal.o
CC drivers/staging/wusbcore/pal.o
CC drivers/staging/uwb/radio.o
CC drivers/media/usb/gspca/sn9c2028.o
CC drivers/media/usb/gspca/sn9c20x.o
CC drivers/hid/hid-gfrm.o
CC drivers/staging/uwb/reset.o
CC drivers/hid/hid-gt683r.o
CC drivers/hid/hid-gyration.o
CC drivers/gpu/drm/i915/display/intel_acpi.o
CC drivers/staging/wusbcore/rh.o
AR drivers/iio/light/built-in.a
CC drivers/media/usb/au0828/au0828-vbi.o
AR drivers/iio/magnetometer/built-in.a
CC drivers/staging/rtl8712/rtl871x_ioctl_linux.o
CC drivers/staging/rtl8712/rtl871x_ioctl_rtl.o
AR drivers/iio/multiplexer/built-in.a
AR drivers/media/usb/hdpvr/built-in.a
CC drivers/hid/hid-holtek-kbd.o
CC drivers/iio/orientation/hid-sensor-incl-3d.o
CC drivers/iio/orientation/hid-sensor-rotation.o
CC drivers/media/usb/au0828/au0828-input.o
CC drivers/net/wireless/realtek/rtlwifi/rtl8192ee/table.o
CC drivers/net/wireless/realtek/rtlwifi/rtl8192ee/trx.o
AR drivers/iio/potentiometer/built-in.a
CC drivers/staging/wusbcore/reservation.o
CC drivers/staging/rtl8712/rtl871x_ioctl_set.o
CC drivers/staging/rtl8712/rtl8712_led.o
CC drivers/media/usb/gspca/sonixb.o
CC drivers/media/usb/gspca/sonixj.o
CC drivers/gpu/drm/i915/display/intel_opregion.o
CC drivers/staging/uwb/rsv.o
AR drivers/iio/potentiostat/built-in.a
CC drivers/staging/uwb/scan.o
CC drivers/staging/uwb/uwb-debug.o
CC drivers/hid/hid-holtek-mouse.o
CC drivers/media/usb/pvrusb2/pvrusb2-i2c-core.o
CC drivers/media/usb/usbvision/usbvision-core.o
CC drivers/media/usb/gspca/spca500.o
CC drivers/staging/uwb/uwbd.o
CC drivers/gpu/drm/i915/display/intel_fbdev.o
CC drivers/media/usb/usbvision/usbvision-video.o
CC drivers/gpu/drm/i915/display/dvo_ch7017.o
CC drivers/media/usb/stk1160/stk1160-core.o
CC drivers/media/usb/cx231xx/cx231xx-video.o
CC drivers/staging/rtl8712/rtl871x_mlme.o
AR drivers/iio/orientation/built-in.a
CC drivers/staging/rtl8712/ieee80211.o
CC drivers/iio/pressure/hid-sensor-press.o
AR drivers/iio/proximity/built-in.a
CC drivers/staging/wusbcore/security.o
CC drivers/media/usb/pvrusb2/pvrusb2-audio.o
CC drivers/hid/hid-holtekff.o
CC drivers/media/usb/pvrusb2/pvrusb2-encoder.o
CC drivers/staging/rtl8712/rtl871x_mp_ioctl.o
CC drivers/hid/hid-hyperv.o
CC drivers/staging/rtl8712/rtl871x_mp.o
CC drivers/staging/rtl8712/mlme_linux.o
CC drivers/media/usb/pvrusb2/pvrusb2-video-v4l.o
CC drivers/media/usb/pvrusb2/pvrusb2-eeprom.o
CC drivers/media/usb/pvrusb2/pvrusb2-main.o
CC drivers/media/usb/pvrusb2/pvrusb2-hdw.o
AR drivers/iio/pressure/built-in.a
AR drivers/media/usb/au0828/built-in.a
CC drivers/staging/uwb/umc-bus.o
AR drivers/iio/resolver/built-in.a
CC drivers/hid/hid-icade.o
CC drivers/iio/temperature/hid-sensor-temperature.o
CC drivers/media/usb/pvrusb2/pvrusb2-v4l2.o
CC drivers/media/usb/stk1160/stk1160-v4l.o
CC drivers/media/usb/pvrusb2/pvrusb2-std.o
CC drivers/media/usb/pvrusb2/pvrusb2-ctrl.o
CC drivers/gpu/drm/i915/display/dvo_ch7xxx.o
CC drivers/staging/wusbcore/wusbhc.o
CC drivers/media/usb/pvrusb2/pvrusb2-devattr.o
CC drivers/gpu/drm/i915/display/dvo_ivch.o
CC drivers/gpu/drm/i915/display/dvo_ns2501.o
CC drivers/staging/wusbcore/wa-hc.o
CC drivers/staging/wusbcore/wa-nep.o
CC drivers/media/usb/gspca/spca501.o
CC drivers/gpu/drm/i915/display/dvo_sil164.o
CC drivers/staging/uwb/umc-dev.o
AR drivers/iio/trigger/built-in.a
CC drivers/media/usb/usbvision/usbvision-i2c.o
CC drivers/hid/hid-ite.o
CC drivers/staging/uwb/umc-drv.o
AR drivers/net/wireless/realtek/rtlwifi/rtl8192ee/built-in.a
CC drivers/staging/uwb/whc-rc.o
CC drivers/staging/uwb/whci.o
AR drivers/iio/temperature/built-in.a
CC drivers/media/usb/pvrusb2/pvrusb2-context.o
AR drivers/net/wireless/realtek/rtlwifi/built-in.a
CC drivers/iio/industrialio-core.o
AR drivers/net/wireless/realtek/built-in.a
CC drivers/staging/uwb/hwa-rc.o
CC drivers/media/usb/gspca/spca505.o
scripts/Makefile.build:505: recipe for target 'drivers/net/wireless' failed
make[2]: *** [drivers/net/wireless] Error 2
scripts/Makefile.build:505: recipe for target 'drivers/net' failed
make[1]: *** [drivers/net] Error 2
make[1]: *** Waiting for unfinished jobs....
CC drivers/media/usb/usbvision/usbvision-cards.o
CC drivers/iio/industrialio-event.o
CC drivers/iio/inkern.o
CC drivers/media/usb/pvrusb2/pvrusb2-io.o
CC drivers/hid/hid-kensington.o
CC drivers/media/usb/gspca/spca506.o
CC drivers/media/usb/stk1160/stk1160-video.o
CC drivers/staging/rtl8712/recv_linux.o
CC drivers/media/usb/tm6000/tm6000-cards.o
CC drivers/staging/rtl8712/xmit_linux.o
CC drivers/media/usb/gspca/spca508.o
CC drivers/media/usb/cx231xx/cx231xx-i2c.o
CC drivers/staging/wusbcore/wa-rpipe.o
CC drivers/staging/rtl8712/usb_intf.o
CC drivers/media/usb/pvrusb2/pvrusb2-ioread.o
CC drivers/staging/wusbcore/wa-xfer.o
CC drivers/staging/wusbcore/cbaf.o
CC drivers/media/usb/tm6000/tm6000-core.o
CC drivers/media/usb/pvrusb2/pvrusb2-cx2584x-v4l.o
CC drivers/media/usb/gspca/spca561.o
CC drivers/media/usb/stk1160/stk1160-i2c.o
CC drivers/iio/industrialio-buffer.o
CC drivers/media/usb/stk1160/stk1160-ac97.o
CC drivers/iio/industrialio-trigger.o
CC drivers/media/usb/em28xx/em28xx-core.o
CC drivers/media/usb/pvrusb2/pvrusb2-wm8775.o
CC drivers/hid/hid-keytouch.o
CC drivers/gpu/drm/i915/display/dvo_tfp410.o
CC drivers/media/usb/tm6000/tm6000-i2c.o
CC drivers/media/usb/tm6000/tm6000-video.o
AR drivers/staging/uwb/built-in.a
CC drivers/media/usb/usbtv/usbtv-core.o
CC drivers/hid/hid-kye.o
CC drivers/hid/hid-lcpower.o
AR drivers/media/usb/usbvision/built-in.a
CC drivers/media/usb/tm6000/tm6000-stds.o
CC drivers/media/usb/pvrusb2/pvrusb2-cs53l32a.o
CC drivers/media/usb/cx231xx/cx231xx-cards.o
CC drivers/hid/hid-lenovo.o
CC drivers/hid/hid-lg.o
CC drivers/media/usb/gspca/spca1528.o
CC drivers/media/usb/cx231xx/cx231xx-core.o
CC drivers/hid/hid-lgff.o
CC drivers/media/usb/pvrusb2/pvrusb2-dvb.o
CC drivers/hid/hid-lg2ff.o
AR drivers/media/usb/stk1160/built-in.a
CC drivers/media/usb/tm6000/tm6000-input.o
CC drivers/media/usb/cx231xx/cx231xx-417.o
CC drivers/gpu/drm/i915/display/icl_dsi.o
CC drivers/media/usb/cx231xx/cx231xx-avcore.o
CC drivers/gpu/drm/i915/display/intel_crt.o
CC drivers/staging/rtl8712/os_intfs.o
CC drivers/media/usb/gspca/sq905.o
CC drivers/media/usb/gspca/sq905c.o
CC drivers/media/usb/tm6000/tm6000-alsa.o
CC drivers/media/usb/go7007/go7007-v4l2.o
CC drivers/gpu/drm/i915/display/intel_ddi.o
CC drivers/gpu/drm/i915/display/intel_dp.o
CC drivers/media/usb/tm6000/tm6000-dvb.o
CC drivers/media/usb/usbtv/usbtv-video.o
CC drivers/media/usb/pvrusb2/pvrusb2-sysfs.o
CC drivers/media/usb/usbtv/usbtv-audio.o
CC drivers/gpu/drm/i915/display/intel_dp_aux_backlight.o
CC drivers/media/usb/go7007/go7007-driver.o
CC drivers/media/usb/as102/as102_drv.o
CC drivers/media/usb/as102/as102_fw.o
AR drivers/iio/built-in.a
CC drivers/media/usb/em28xx/em28xx-i2c.o
CC drivers/media/usb/as102/as10x_cmd.o
CC drivers/media/usb/em28xx/em28xx-cards.o
CC drivers/media/usb/gspca/sq930x.o
CC drivers/media/usb/gspca/sunplus.o
CC drivers/media/usb/gspca/stk014.o
CC drivers/media/usb/as102/as10x_cmd_stream.o
CC drivers/staging/rtl8712/rtl871x_pwrctrl.o
CC drivers/hid/hid-lg3ff.o
CC drivers/gpu/drm/i915/display/intel_dp_link_training.o
CC drivers/staging/rtl8712/rtl8712_recv.o
CC drivers/gpu/drm/i915/display/intel_dp_mst.o
CC drivers/media/usb/go7007/go7007-i2c.o
CC drivers/media/usb/go7007/go7007-fw.o
AR drivers/media/usb/tm6000/built-in.a
CC drivers/media/usb/go7007/snd-go7007.o
CC drivers/staging/rtl8712/rtl871x_recv.o
AR drivers/media/usb/usbtv/built-in.a
CC drivers/hid/hid-lg4ff.o
CC drivers/media/usb/as102/as102_usb_drv.o
CC drivers/staging/rtl8712/rtl871x_sta_mgt.o
CC drivers/staging/rtl8712/rtl871x_xmit.o
CC drivers/hid/hid-lg-g15.o
CC drivers/hid/hid-logitech-dj.o
CC drivers/hid/hid-logitech-hidpp.o
CC drivers/media/usb/as102/as10x_cmd_cfg.o
CC drivers/media/usb/go7007/go7007-usb.o
CC drivers/media/usb/go7007/go7007-loader.o
CC drivers/media/usb/go7007/s2250-board.o
CC drivers/media/usb/cx231xx/cx231xx-pcb-cfg.o
CC drivers/media/usb/cx231xx/cx231xx-vbi.o
CC drivers/media/usb/em28xx/em28xx-camera.o
CC drivers/media/usb/gspca/stk1135.o
CC drivers/media/usb/gspca/stv0680.o
CC drivers/media/usb/pulse8-cec/pulse8-cec.o
CC drivers/media/usb/em28xx/em28xx-video.o
AR drivers/staging/wusbcore/built-in.a
CC drivers/hid/hid-magicmouse.o
CC drivers/media/usb/rainshadow-cec/rainshadow-cec.o
CC drivers/media/usb/cx231xx/cx231xx-input.o
CC drivers/hid/hid-mf.o
CC drivers/hid/hid-microsoft.o
AR drivers/media/usb/as102/built-in.a
CC drivers/media/usb/cx231xx/cx231xx-audio.o
CC drivers/media/usb/cx231xx/cx231xx-dvb.o
CC drivers/media/usb/gspca/t613.o
CC drivers/media/usb/gspca/topro.o
CC drivers/media/usb/em28xx/em28xx-vbi.o
CC drivers/staging/rtl8712/rtl8712_xmit.o
CC drivers/media/usb/gspca/touptek.o
CC drivers/media/usb/gspca/tv8532.o
CC drivers/media/usb/em28xx/em28xx-audio.o
CC drivers/hid/hid-monterey.o
CC drivers/gpu/drm/i915/display/intel_dsi.o
CC drivers/hid/hid-multitouch.o
CC drivers/gpu/drm/i915/display/intel_dsi_dcs_backlight.o
CC drivers/hid/hid-nti.o
CC drivers/media/usb/em28xx/em28xx-dvb.o
CC drivers/hid/hid-ntrig.o
CC drivers/media/usb/gspca/vc032x.o
AR drivers/media/usb/pvrusb2/built-in.a
CC drivers/media/usb/gspca/vicam.o
CC drivers/hid/hid-ortek.o
CC drivers/hid/hid-prodikeys.o
AR drivers/media/usb/rainshadow-cec/built-in.a
CC drivers/gpu/drm/i915/display/intel_dsi_vbt.o
CC drivers/media/usb/em28xx/em28xx-input.o
CC drivers/hid/hid-pl.o
CC drivers/media/usb/gspca/xirlink_cit.o
AR drivers/media/usb/pulse8-cec/built-in.a
CC drivers/media/usb/gspca/zc3xx.o
CC drivers/hid/hid-penmount.o
CC drivers/gpu/drm/i915/display/intel_dvo.o
CC drivers/hid/hid-petalynx.o
CC drivers/hid/hid-picolcd_core.o
CC drivers/hid/hid-picolcd_fb.o
CC drivers/gpu/drm/i915/display/intel_gmbus.o
CC drivers/hid/hid-picolcd_backlight.o
AR drivers/media/usb/go7007/built-in.a
CC drivers/hid/hid-picolcd_lcd.o
CC drivers/gpu/drm/i915/display/intel_hdmi.o
CC drivers/gpu/drm/i915/display/intel_lspcon.o
AR drivers/staging/rtl8712/built-in.a
AR drivers/staging/built-in.a
CC drivers/hid/hid-picolcd_leds.o
CC drivers/gpu/drm/i915/display/intel_lvds.o
CC drivers/hid/hid-picolcd_cir.o
CC drivers/gpu/drm/i915/display/intel_panel.o
CC drivers/hid/hid-picolcd_debugfs.o
CC drivers/hid/hid-plantronics.o
CC drivers/gpu/drm/i915/display/intel_sdvo.o
AR drivers/media/usb/cx231xx/built-in.a
CC drivers/hid/hid-primax.o
CC drivers/hid/hid-retrode.o
CC drivers/gpu/drm/i915/display/intel_vdsc.o
CC drivers/gpu/drm/i915/display/intel_tv.o
CC drivers/gpu/drm/i915/display/vlv_dsi.o
CC drivers/hid/hid-roccat.o
CC drivers/gpu/drm/i915/display/vlv_dsi_pll.o
CC drivers/hid/hid-roccat-common.o
CC drivers/hid/hid-roccat-isku.o
CC drivers/hid/hid-roccat-arvo.o
CC drivers/gpu/drm/i915/oa/i915_oa_hsw.o
CC drivers/gpu/drm/i915/oa/i915_oa_bdw.o
CC drivers/hid/hid-roccat-kone.o
CC drivers/hid/hid-roccat-koneplus.o
CC drivers/gpu/drm/i915/oa/i915_oa_chv.o
CC drivers/hid/hid-roccat-konepure.o
CC drivers/hid/hid-roccat-kovaplus.o
CC drivers/hid/hid-roccat-lua.o
CC drivers/gpu/drm/i915/oa/i915_oa_sklgt2.o
CC drivers/gpu/drm/i915/oa/i915_oa_sklgt3.o
CC drivers/hid/hid-roccat-pyra.o
CC drivers/hid/hid-roccat-ryos.o
CC drivers/hid/hid-roccat-savu.o
CC drivers/gpu/drm/i915/oa/i915_oa_sklgt4.o
CC drivers/hid/hid-rmi.o
CC drivers/hid/hid-saitek.o
CC drivers/hid/hid-samsung.o
CC drivers/hid/hid-sjoy.o
CC drivers/hid/hid-sony.o
CC drivers/gpu/drm/i915/oa/i915_oa_bxt.o
AR drivers/media/usb/gspca/built-in.a
CC drivers/gpu/drm/i915/oa/i915_oa_kblgt2.o
CC drivers/hid/hid-speedlink.o
CC drivers/hid/hid-steelseries.o
CC drivers/gpu/drm/i915/oa/i915_oa_kblgt3.o
AR drivers/media/usb/em28xx/built-in.a
CC drivers/hid/hid-sunplus.o
AR drivers/media/usb/built-in.a
AR drivers/media/built-in.a
CC drivers/gpu/drm/i915/oa/i915_oa_glk.o
CC drivers/gpu/drm/i915/oa/i915_oa_cflgt2.o
CC drivers/hid/hid-gaff.o
CC drivers/gpu/drm/i915/oa/i915_oa_cflgt3.o
CC drivers/hid/hid-tmff.o
CC drivers/gpu/drm/i915/oa/i915_oa_cnl.o
CC drivers/hid/hid-tivo.o
CC drivers/gpu/drm/i915/oa/i915_oa_tgl.o
CC drivers/gpu/drm/i915/oa/i915_oa_icl.o
CC drivers/hid/hid-topseed.o
CC drivers/hid/hid-twinhan.o
CC drivers/gpu/drm/i915/i915_perf.o
CC drivers/hid/hid-uclogic-core.o
CC drivers/gpu/drm/i915/i915_gpu_error.o
CC drivers/gpu/drm/i915/i915_vgpu.o
CC drivers/hid/hid-uclogic-rdesc.o
CC drivers/hid/hid-uclogic-params.o
CC drivers/hid/hid-udraw-ps3.o
CC drivers/hid/hid-led.o
CC drivers/hid/hid-xinmo.o
CC drivers/hid/hid-zpff.o
CC drivers/hid/hid-zydacron.o
CC drivers/hid/wacom_wac.o
CC drivers/hid/wacom_sys.o
CC drivers/hid/hid-waltop.o
CC drivers/hid/hid-wiimote-modules.o
CC drivers/hid/hid-wiimote-core.o
CC drivers/hid/hid-wiimote-debug.o
CC drivers/hid/hid-sensor-hub.o
CC drivers/hid/hid-sensor-custom.o
AR drivers/gpu/drm/i915/built-in.a
AR drivers/gpu/drm/built-in.a
AR drivers/gpu/built-in.a
AR drivers/hid/built-in.a
Makefile:1683: recipe for target 'drivers' failed
make: *** [drivers] Error 2


Error text is too large and was truncated, full error text is at:
https://syzkaller.appspot.com/x/error.txt?x=13869db7e00000


Tested on:

commit: 0fa84af8 Merge tag 'usb-serial-5.7-rc1' of https://git.ker..
git tree: https://github.com/google/kasan.git usb-fuzzer
dashboard link: https://syzkaller.appspot.com/bug?extid=40d5d2e8a4680952f042
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
patch: https://syzkaller.appspot.com/x/patch.diff?x=178e12cde00000

syzbot

unread,
Apr 3, 2020, 11:21:05 AM4/3/20
to anen...@gmail.com, syzkall...@googlegroups.com
Hello,

syzbot tried to test the proposed patch but build/boot failed:

c/pwc-uncompress.o
CC drivers/media/usb/gspca/stv06xx/stv06xx_pb0100.o
CC drivers/media/usb/dvb-usb-v2/mxl111sf-demod.o
CC drivers/media/usb/pwc/pwc-dec1.o
CC drivers/media/usb/dvb-usb/umt-010.o
CC drivers/usb/serial/xsens_mt.o
CC drivers/media/usb/dvb-usb/m920x.o
CC drivers/media/usb/airspy/airspy.o
CC drivers/media/usb/uvc/uvc_ctrl.o
CC drivers/media/usb/pwc/pwc-dec23.o
CC drivers/media/usb/pwc/pwc-kiara.o
CC drivers/media/rc/keymaps/rc-medion-x10-or2x.o
CC drivers/media/usb/uvc/uvc_status.o
CC drivers/media/usb/gspca/stv06xx/stv06xx_st6422.o
CC drivers/media/usb/dvb-usb/digitv.o
CC drivers/media/dvb-frontends/isl6423.o
CC drivers/md/dm-stats.o
CC drivers/media/usb/gspca/gspca.o
CC drivers/media/usb/gspca/gl860/gl860-mi1320.o
CC drivers/media/usb/gspca/autogain_functions.o
CC drivers/media/usb/gspca/benq.o
CC drivers/media/usb/pwc/pwc-timon.o
CC drivers/media/usb/dvb-usb-v2/mxl111sf-tuner.o
CC drivers/media/rc/keymaps/rc-msi-digivox-ii.o
CC drivers/media/rc/keymaps/rc-msi-digivox-iii.o
CC drivers/media/usb/hackrf/hackrf.o
CC drivers/md/dm-rq.o
AR drivers/usb/serial/built-in.a
CC drivers/md/dm-builtin.o
CC drivers/media/usb/msi2500/msi2500.o
AR drivers/isdn/mISDN/built-in.a
CC drivers/media/usb/cpia2/cpia2_v4l.o
AR drivers/isdn/built-in.a
CC drivers/gpu/drm/i915/display/intel_tv.o
CC drivers/media/usb/gspca/gl860/gl860-ov2640.o
CC drivers/media/usb/gspca/conex.o
CC drivers/media/dvb-frontends/ec100.o
CC drivers/media/usb/gspca/gl860/gl860-ov9655.o
CC drivers/usb/usbip/vudc_rx.o
AR drivers/media/usb/gspca/stv06xx/built-in.a
CC drivers/media/usb/gspca/gl860/gl860-mi2020.o
CC drivers/gpu/drm/i915/display/intel_vdsc.o
CC drivers/gpu/drm/i915/display/vlv_dsi.o
CC drivers/media/rc/keymaps/rc-msi-tvanywhere.o
CC drivers/gpu/drm/i915/display/vlv_dsi_pll.o
CC drivers/media/usb/dvb-usb/cxusb.o
CC drivers/media/rc/keymaps/rc-msi-tvanywhere-plus.o
AR drivers/media/usb/pwc/built-in.a
CC drivers/media/rc/keymaps/rc-nebula.o
CC drivers/media/rc/keymaps/rc-nec-terratec-cinergy-xs.o
CC drivers/media/usb/cpia2/cpia2_usb.o
CC drivers/usb/usbip/vudc_transfer.o
AR drivers/usb/gadget/udc/built-in.a
CC drivers/usb/usbip/vudc_main.o
AR drivers/media/usb/airspy/built-in.a
AR drivers/usb/gadget/built-in.a
CC drivers/md/dm-raid1.o
CC drivers/md/dm-log.o
CC drivers/md/dm-region-hash.o
CC drivers/md/dm-zero.o
CC drivers/media/usb/dvb-usb-v2/rtl28xxu.o
AR drivers/cpufreq/built-in.a
CC drivers/media/usb/dvb-usb-v2/dvbsky.o
CC drivers/media/dvb-frontends/ds3000.o
CC drivers/media/usb/cpia2/cpia2_core.o
CC drivers/media/usb/dvb-usb/ttusb2.o
CC drivers/media/usb/dvb-usb/dib0700_core.o
CC drivers/gpu/drm/i915/oa/i915_oa_hsw.o
CC drivers/gpu/drm/i915/oa/i915_oa_bdw.o
CC drivers/media/rc/keymaps/rc-norwood.o
CC drivers/media/usb/dvb-usb/dib0700_devices.o
CC drivers/media/dvb-frontends/ts2020.o
CC drivers/media/usb/uvc/uvc_isight.o
CC drivers/media/usb/uvc/uvc_debugfs.o
CC drivers/media/usb/uvc/uvc_metadata.o
AR drivers/media/usb/gspca/gl860/built-in.a
CC drivers/media/usb/dvb-usb/opera1.o
CC drivers/media/usb/au0828/au0828-core.o
CC drivers/media/usb/au0828/au0828-cards.o
CC drivers/media/usb/au0828/au0828-i2c.o
CC drivers/media/usb/gspca/cpia1.o
AR drivers/media/usb/msi2500/built-in.a
CC drivers/media/usb/gspca/dtcs033.o
AR drivers/usb/usbip/built-in.a
CC drivers/media/rc/keymaps/rc-npgtech.o
AR drivers/usb/built-in.a
CC drivers/media/rc/keymaps/rc-odroid.o
AR drivers/media/usb/hackrf/built-in.a
CC drivers/media/usb/au0828/au0828-dvb.o
CC drivers/media/usb/au0828/au0828-video.o
CC drivers/media/usb/au0828/au0828-vbi.o
CC drivers/media/usb/au0828/au0828-input.o
CC drivers/gpu/drm/i915/oa/i915_oa_chv.o
CC drivers/gpu/drm/i915/oa/i915_oa_sklgt2.o
CC drivers/media/usb/dvb-usb-v2/zd1301.o
CC drivers/media/rc/keymaps/rc-pctv-sedna.o
CC drivers/media/rc/keymaps/rc-pinnacle-color.o
CC drivers/media/rc/keymaps/rc-pinnacle-grey.o
CC drivers/media/usb/uvc/uvc_entity.o
CC drivers/media/rc/keymaps/rc-pinnacle-pctv-hd.o
CC drivers/media/usb/hdpvr/hdpvr-control.o
CC drivers/media/rc/keymaps/rc-pixelview.o
CC drivers/media/usb/pvrusb2/pvrusb2-i2c-core.o
CC drivers/media/usb/dvb-usb/af9005-fe.o
CC drivers/media/usb/dvb-usb/af9005.o
CC drivers/media/rc/keymaps/rc-pixelview-mk12.o
CC drivers/media/dvb-frontends/mb86a20s.o
AR drivers/md/built-in.a
CC drivers/media/dvb-frontends/ix2505v.o
CC drivers/media/usb/gspca/etoms.o
AR drivers/media/usb/cpia2/built-in.a
CC drivers/media/rc/keymaps/rc-pixelview-002t.o
CC drivers/media/rc/keymaps/rc-pixelview-new.o
CC drivers/media/usb/hdpvr/hdpvr-core.o
CC drivers/media/usb/pvrusb2/pvrusb2-audio.o
CC drivers/media/rc/keymaps/rc-powercolor-real-angel.o
CC drivers/media/usb/gspca/finepix.o
CC drivers/media/usb/usbvision/usbvision-core.o
CC drivers/media/usb/gspca/jl2005bcd.o
CC drivers/media/usb/gspca/jeilinj.o
CC drivers/media/usb/stk1160/stk1160-core.o
CC drivers/media/usb/gspca/kinect.o
CC drivers/media/usb/stk1160/stk1160-v4l.o
CC drivers/media/usb/stk1160/stk1160-video.o
AR drivers/media/usb/uvc/built-in.a
CC drivers/media/rc/keymaps/rc-proteus-2309.o
CC drivers/media/rc/keymaps/rc-purpletv.o
CC drivers/media/usb/stk1160/stk1160-i2c.o
CC drivers/media/usb/gspca/konica.o
CC drivers/media/rc/keymaps/rc-pv951.o
CC drivers/media/usb/gspca/mars.o
CC drivers/gpu/drm/i915/oa/i915_oa_sklgt3.o
CC drivers/media/usb/hdpvr/hdpvr-video.o
CC drivers/media/rc/keymaps/rc-hauppauge.o
AR drivers/media/usb/dvb-usb-v2/built-in.a
CC drivers/media/rc/keymaps/rc-rc6-mce.o
CC drivers/media/usb/stk1160/stk1160-ac97.o
CC drivers/media/usb/cx231xx/cx231xx-video.o
CC drivers/media/usb/cx231xx/cx231xx-i2c.o
CC drivers/media/usb/cx231xx/cx231xx-cards.o
CC drivers/media/usb/cx231xx/cx231xx-core.o
CC drivers/media/usb/pvrusb2/pvrusb2-encoder.o
CC drivers/media/rc/keymaps/rc-real-audio-220-32-keys.o
CC drivers/media/usb/pvrusb2/pvrusb2-video-v4l.o
CC drivers/gpu/drm/i915/oa/i915_oa_sklgt4.o
CC drivers/media/rc/keymaps/rc-reddo.o
CC drivers/gpu/drm/i915/oa/i915_oa_bxt.o
CC drivers/gpu/drm/i915/oa/i915_oa_kblgt2.o
CC drivers/media/usb/cx231xx/cx231xx-avcore.o
CC drivers/gpu/drm/i915/oa/i915_oa_kblgt3.o
CC drivers/media/usb/pvrusb2/pvrusb2-eeprom.o
CC drivers/gpu/drm/i915/oa/i915_oa_glk.o
CC drivers/gpu/drm/i915/oa/i915_oa_cflgt2.o
CC drivers/media/usb/cx231xx/cx231xx-417.o
CC drivers/media/usb/gspca/mr97310a.o
CC drivers/media/usb/tm6000/tm6000-cards.o
CC drivers/media/usb/gspca/nw80x.o
CC drivers/media/usb/dvb-usb/af9005-remote.o
CC drivers/media/usb/tm6000/tm6000-core.o
CC drivers/media/usb/pvrusb2/pvrusb2-main.o
AR drivers/media/usb/stk1160/built-in.a
CC drivers/media/usb/tm6000/tm6000-i2c.o
CC drivers/media/usb/hdpvr/hdpvr-i2c.o
CC drivers/media/dvb-frontends/cxd2820r_core.o
CC drivers/media/dvb-frontends/cxd2820r_c.o
CC drivers/media/dvb-frontends/cxd2820r_t.o
CC drivers/media/rc/keymaps/rc-snapstream-firefly.o
CC drivers/media/usb/cx231xx/cx231xx-pcb-cfg.o
CC drivers/media/usb/pvrusb2/pvrusb2-hdw.o
CC drivers/gpu/drm/i915/oa/i915_oa_cflgt3.o
CC drivers/media/usb/tm6000/tm6000-video.o
CC drivers/media/rc/keymaps/rc-streamzap.o
AR drivers/media/usb/au0828/built-in.a
CC drivers/media/usb/cx231xx/cx231xx-vbi.o
CC drivers/media/usb/cx231xx/cx231xx-input.o
CC drivers/gpu/drm/i915/oa/i915_oa_cnl.o
CC drivers/media/usb/em28xx/em28xx-core.o
CC drivers/gpu/drm/i915/oa/i915_oa_icl.o
CC drivers/media/usb/em28xx/em28xx-i2c.o
CC drivers/media/usb/usbvision/usbvision-video.o
CC drivers/media/usb/usbvision/usbvision-i2c.o
CC drivers/media/usb/pvrusb2/pvrusb2-v4l2.o
AR drivers/media/usb/hdpvr/built-in.a
CC drivers/media/usb/gspca/ov519.o
CC drivers/media/usb/em28xx/em28xx-cards.o
CC drivers/media/usb/dvb-usb/pctv452e.o
CC drivers/media/usb/em28xx/em28xx-camera.o
CC drivers/media/dvb-frontends/cxd2820r_t2.o
CC drivers/media/usb/usbtv/usbtv-video.o
CC drivers/media/usb/tm6000/tm6000-stds.o
CC drivers/media/usb/usbtv/usbtv-core.o
CC drivers/media/usb/tm6000/tm6000-input.o
CC drivers/media/usb/tm6000/tm6000-alsa.o
CC drivers/media/dvb-frontends/cxd2841er.o
CC drivers/media/usb/dvb-usb/dw2102.o
CC drivers/media/usb/em28xx/em28xx-video.o
CC drivers/media/rc/keymaps/rc-tango.o
CC drivers/media/usb/cx231xx/cx231xx-audio.o
CC drivers/media/usb/gspca/ov534.o
CC drivers/media/usb/gspca/ov534_9.o
CC drivers/media/usb/gspca/pac207.o
CC drivers/media/usb/gspca/pac7302.o
CC drivers/media/usb/cx231xx/cx231xx-dvb.o
CC drivers/media/usb/usbtv/usbtv-audio.o
CC drivers/media/rc/keymaps/rc-tanix-tx3mini.o
CC drivers/media/dvb-frontends/drxk_hard.o
CC drivers/gpu/drm/i915/oa/i915_oa_tgl.o
CC drivers/media/usb/usbvision/usbvision-cards.o
CC drivers/media/usb/gspca/pac7311.o
CC drivers/gpu/drm/i915/i915_perf.o
CC drivers/media/usb/em28xx/em28xx-vbi.o
CC drivers/media/usb/em28xx/em28xx-audio.o
CC drivers/media/rc/keymaps/rc-tanix-tx5max.o
CC drivers/media/usb/tm6000/tm6000-dvb.o
CC drivers/media/usb/gspca/se401.o
CC drivers/media/usb/gspca/sn9c2028.o
CC drivers/media/rc/keymaps/rc-tbs-nec.o
CC drivers/media/usb/dvb-usb/dtv5100.o
CC drivers/media/rc/keymaps/rc-technisat-ts35.o
CC drivers/media/usb/dvb-usb/cinergyT2-core.o
CC drivers/media/rc/keymaps/rc-technisat-usb2.o
CC drivers/media/usb/dvb-usb/cinergyT2-fe.o
CC drivers/media/rc/keymaps/rc-terratec-cinergy-c-pci.o
CC drivers/media/usb/pvrusb2/pvrusb2-ctrl.o
CC drivers/media/usb/gspca/sn9c20x.o
CC drivers/media/usb/em28xx/em28xx-dvb.o
AR drivers/media/usb/usbtv/built-in.a
CC drivers/media/usb/em28xx/em28xx-input.o
AR drivers/media/usb/usbvision/built-in.a
CC drivers/media/usb/dvb-usb/az6027.o
CC drivers/media/usb/pvrusb2/pvrusb2-std.o
CC drivers/media/usb/gspca/sonixb.o
CC drivers/media/rc/keymaps/rc-terratec-cinergy-s2-hd.o
CC drivers/media/usb/gspca/sonixj.o
CC drivers/gpu/drm/i915/i915_gpu_error.o
CC drivers/gpu/drm/i915/i915_vgpu.o
CC drivers/media/usb/gspca/spca500.o
CC drivers/media/usb/pvrusb2/pvrusb2-devattr.o
CC drivers/media/rc/keymaps/rc-terratec-cinergy-xs.o
CC drivers/media/usb/pvrusb2/pvrusb2-context.o
CC drivers/media/rc/keymaps/rc-terratec-slim.o
CC drivers/media/usb/dvb-usb/technisat-usb2.o
AR drivers/media/usb/tm6000/built-in.a
CC drivers/media/rc/keymaps/rc-tevii-nec.o
CC drivers/media/rc/keymaps/rc-terratec-slim-2.o
CC drivers/media/usb/gspca/spca501.o
AR drivers/media/usb/cx231xx/built-in.a
CC drivers/media/rc/keymaps/rc-tivo.o
CC drivers/media/usb/go7007/go7007-v4l2.o
CC drivers/media/rc/keymaps/rc-total-media-in-hand.o
CC drivers/media/usb/go7007/go7007-driver.o
CC drivers/media/usb/gspca/spca505.o
CC drivers/media/usb/go7007/go7007-i2c.o
CC drivers/media/usb/go7007/go7007-fw.o
CC drivers/media/usb/go7007/snd-go7007.o
CC drivers/media/rc/keymaps/rc-total-media-in-hand-02.o
CC drivers/media/usb/as102/as102_drv.o
CC drivers/media/dvb-frontends/tda18271c2dd.o
CC drivers/media/dvb-frontends/si2165.o
CC drivers/media/usb/as102/as102_fw.o
CC drivers/media/usb/as102/as10x_cmd.o
CC drivers/media/rc/keymaps/rc-trekstor.o
CC drivers/media/usb/as102/as10x_cmd_stream.o
CC drivers/media/usb/gspca/spca506.o
CC drivers/media/usb/pulse8-cec/pulse8-cec.o
CC drivers/media/rc/keymaps/rc-tt-1500.o
CC drivers/media/rc/keymaps/rc-twinhan-dtv-cab-ci.o
CC drivers/media/rc/keymaps/rc-twinhan1027.o
CC drivers/media/dvb-frontends/a8293.o
CC drivers/media/rc/keymaps/rc-vega-s9x.o
CC drivers/media/usb/rainshadow-cec/rainshadow-cec.o
CC drivers/media/dvb-frontends/sp2.o
CC drivers/media/usb/gspca/spca508.o
CC drivers/media/rc/keymaps/rc-videomate-m1f.o
CC drivers/media/dvb-frontends/tda10071.o
AR drivers/media/usb/dvb-usb/built-in.a
CC drivers/media/usb/go7007/go7007-usb.o
CC drivers/media/usb/gspca/spca1528.o
CC drivers/media/usb/gspca/spca561.o
CC drivers/media/usb/gspca/sq905.o
CC drivers/media/usb/as102/as102_usb_drv.o
CC drivers/media/rc/keymaps/rc-videomate-s350.o
CC drivers/media/usb/as102/as10x_cmd_cfg.o
CC drivers/media/usb/pvrusb2/pvrusb2-io.o
CC drivers/media/usb/pvrusb2/pvrusb2-ioread.o
CC drivers/media/usb/gspca/sq905c.o
CC drivers/media/rc/keymaps/rc-videomate-tv-pvr.o
CC drivers/media/dvb-frontends/rtl2830.o
CC drivers/media/rc/keymaps/rc-wetek-hub.o
CC drivers/media/usb/go7007/go7007-loader.o
CC drivers/media/rc/keymaps/rc-wetek-play2.o
CC drivers/media/usb/gspca/sunplus.o
CC drivers/media/usb/gspca/sq930x.o
AR drivers/media/usb/rainshadow-cec/built-in.a
CC drivers/media/rc/keymaps/rc-winfast.o
CC drivers/media/rc/keymaps/rc-winfast-usbii-deluxe.o
CC drivers/media/usb/go7007/s2250-board.o
AR drivers/media/usb/em28xx/built-in.a
CC drivers/media/dvb-frontends/rtl2832.o
CC drivers/media/dvb-frontends/rtl2832_sdr.o
CC drivers/media/usb/pvrusb2/pvrusb2-cx2584x-v4l.o
CC drivers/media/usb/gspca/stk014.o
CC drivers/media/rc/keymaps/rc-su3000.o
CC drivers/media/usb/pvrusb2/pvrusb2-wm8775.o
CC drivers/media/dvb-frontends/m88rs2000.o
AR drivers/media/usb/pulse8-cec/built-in.a
CC drivers/media/usb/gspca/stk1135.o
CC drivers/media/usb/pvrusb2/pvrusb2-cs53l32a.o
CC drivers/media/dvb-frontends/af9033.o
CC drivers/media/dvb-frontends/as102_fe.o
CC drivers/media/usb/pvrusb2/pvrusb2-dvb.o
CC drivers/media/usb/gspca/stv0680.o
CC drivers/media/usb/gspca/t613.o
AR drivers/media/usb/as102/built-in.a
CC drivers/media/rc/keymaps/rc-xbox-dvd.o
CC drivers/media/usb/pvrusb2/pvrusb2-sysfs.o
CC drivers/media/rc/keymaps/rc-x96max.o
CC drivers/media/usb/gspca/topro.o
CC drivers/media/usb/gspca/touptek.o
CC drivers/media/dvb-frontends/gp8psk-fe.o
CC drivers/media/rc/keymaps/rc-zx-irdec.o
CC drivers/media/dvb-frontends/tc90522.o
CC drivers/media/dvb-frontends/zd1301_demod.o
CC drivers/media/usb/gspca/tv8532.o
CC drivers/media/usb/gspca/vc032x.o
CC drivers/media/usb/gspca/vicam.o
CC drivers/media/usb/gspca/xirlink_cit.o
AR drivers/gpu/drm/i915/built-in.a
CC drivers/media/usb/gspca/zc3xx.o
AR drivers/gpu/drm/built-in.a
AR drivers/media/rc/keymaps/built-in.a
AR drivers/gpu/built-in.a
AR drivers/media/usb/go7007/built-in.a
AR drivers/media/rc/built-in.a
AR drivers/media/usb/pvrusb2/built-in.a
AR drivers/media/dvb-frontends/built-in.a
AR drivers/media/usb/gspca/built-in.a
AR drivers/media/usb/built-in.a
AR drivers/media/built-in.a
Makefile:1683: recipe for target 'drivers' failed
make: *** [drivers] Error 2


Error text is too large and was truncated, full error text is at:
https://syzkaller.appspot.com/x/error.txt?x=141cd243e00000


Tested on:

commit: 0fa84af8 Merge tag 'usb-serial-5.7-rc1' of https://git.ker..
git tree: https://github.com/google/kasan.git usb-fuzzer
dashboard link: https://syzkaller.appspot.com/bug?extid=40d5d2e8a4680952f042
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
patch: https://syzkaller.appspot.com/x/patch.diff?x=11294793e00000

syzbot

unread,
Apr 3, 2020, 11:36:05 AM4/3/20
to anen...@gmail.com, syzkall...@googlegroups.com
Hello,

syzbot has tested the proposed patch but the reproducer still triggered crash:
INFO: rcu detected stall in dummy_timer

haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
rcu: INFO: rcu_sched self-detected stall on CPU
rcu: 0-...!: (2304 ticks this GP) idle=e82/1/0x4000000000000002 softirq=7985/7985 fqs=6
(t=10500 jiffies g=3961 q=3383)
rcu: rcu_sched kthread starved for 9414 jiffies! g3961 f0x0 RCU_GP_WAIT_FQS(5) ->state=0x0 ->cpu=1
rcu: RCU grace-period kthread stack dump:
rcu_sched R running task 29400 10 2 0x80004000
Call Trace:
schedule+0xcd/0x2b0 kernel/sched/core.c:4154
schedule_timeout+0x440/0xb20 kernel/time/timer.c:1895
rcu_gp_fqs_loop kernel/rcu/tree.c:1658 [inline]
rcu_gp_kthread+0xad8/0x1e90 kernel/rcu/tree.c:1818
kthread+0x318/0x420 kernel/kthread.c:255
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:352
NMI backtrace for cpu 0
CPU: 0 PID: 9 Comm: ksoftirqd/0 Not tainted 5.6.0-rc7-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
<IRQ>
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0xef/0x16e lib/dump_stack.c:118
nmi_cpu_backtrace.cold+0x70/0xb1 lib/nmi_backtrace.c:101
nmi_trigger_cpumask_backtrace+0x1db/0x207 lib/nmi_backtrace.c:62
trigger_single_cpu_backtrace include/linux/nmi.h:164 [inline]
rcu_dump_cpu_stacks+0x169/0x1b3 kernel/rcu/tree_stall.h:254
print_cpu_stall kernel/rcu/tree_stall.h:475 [inline]
check_cpu_stall kernel/rcu/tree_stall.h:549 [inline]
rcu_pending kernel/rcu/tree.c:3030 [inline]
rcu_sched_clock_irq.cold+0x4da/0x901 kernel/rcu/tree.c:2276
update_process_times+0x25/0x60 kernel/time/timer.c:1726
tick_sched_handle+0x9b/0x180 kernel/time/tick-sched.c:171
tick_sched_timer+0x42/0x130 kernel/time/tick-sched.c:1314
__run_hrtimer kernel/time/hrtimer.c:1517 [inline]
__hrtimer_run_queues+0x32c/0xd20 kernel/time/hrtimer.c:1579
hrtimer_interrupt+0x2e8/0x730 kernel/time/hrtimer.c:1641
local_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1119 [inline]
smp_apic_timer_interrupt+0xfe/0x540 arch/x86/kernel/apic/apic.c:1144
apic_timer_interrupt+0xf/0x20 arch/x86/entry/entry_64.S:829
</IRQ>
RIP: 0010:arch_local_irq_restore arch/x86/include/asm/irqflags.h:85 [inline]
RIP: 0010:__raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:160 [inline]
RIP: 0010:_raw_spin_unlock_irqrestore+0x3b/0x40 kernel/locking/spinlock.c:191
Code: e8 ca ad 96 fb 48 89 ef e8 92 8f 97 fb f6 c7 02 75 11 53 9d e8 16 15 b5 fb 65 ff 0d b7 81 72 7a 5b 5d c3 e8 07 13 b5 fb 53 9d <eb> ed 0f 1f 00 55 48 89 fd 65 ff 05 9d 81 72 7a 45 31 c9 41 b8 01
RSP: 0018:ffff8881da2079d0 EFLAGS: 00000206 ORIG_RAX: ffffffffffffff13
RAX: 0000000000000007 RBX: 0000000000000206 RCX: 0000000000000002
RDX: 0000000000000000 RSI: 0000000000000008 RDI: ffff8881da1e51cc
RBP: ffff8881d4cd0000 R08: ffff8881da1e4980 R09: fffffbfff126709a
R10: fffffbfff1267099 R11: ffffffff893384cf R12: dffffc0000000000
R13: ffff8881d4d57400 R14: 0000000000000000 R15: ffff8881d9a4b600
spin_unlock_irqrestore include/linux/spinlock.h:393 [inline]
dummy_timer+0x1364/0x32ae drivers/usb/gadget/udc/dummy_hcd.c:1980
call_timer_fn+0x195/0x6f0 kernel/time/timer.c:1404
expire_timers kernel/time/timer.c:1449 [inline]
__run_timers kernel/time/timer.c:1773 [inline]
__run_timers kernel/time/timer.c:1740 [inline]
run_timer_softirq+0x5f9/0x1500 kernel/time/timer.c:1786
__do_softirq+0x21e/0x950 kernel/softirq.c:292
run_ksoftirqd kernel/softirq.c:603 [inline]
run_ksoftirqd+0x1f/0x40 kernel/softirq.c:595
smpboot_thread_fn+0x3e8/0x870 kernel/smpboot.c:165
kthread+0x318/0x420 kernel/kthread.c:255
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:352
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b900. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b600. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d25fed00. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b700. ath9k_hif_usb_rx_cb, 663
haley: catch if null, urb 0xffff8881d9a4b800. ath9k_hif_usb_rx_cb, 663


Tested on:

commit: 0fa84af8 Merge tag 'usb-serial-5.7-rc1' of https://git.ker..
git tree: https://github.com/google/kasan.git usb-fuzzer
console output: https://syzkaller.appspot.com/x/log.txt?x=12bd5963e00000
kernel config: https://syzkaller.appspot.com/x/.config?x=a782c087b1f425c6
dashboard link: https://syzkaller.appspot.com/bug?extid=40d5d2e8a4680952f042
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
patch: https://syzkaller.appspot.com/x/patch.diff?x=1305901be00000

syzbot

unread,
Apr 3, 2020, 12:38:05 PM4/3/20
to anen...@gmail.com, syzkall...@googlegroups.com
Hello,

syzbot has tested the proposed patch and the reproducer did not trigger crash:

Reported-and-tested-by: syzbot+40d5d2...@syzkaller.appspotmail.com

Tested on:

commit: 0fa84af8 Merge tag 'usb-serial-5.7-rc1' of https://git.ker..
git tree: https://github.com/google/kasan.git usb-fuzzer
kernel config: https://syzkaller.appspot.com/x/.config?x=a782c087b1f425c6
dashboard link: https://syzkaller.appspot.com/bug?extid=40d5d2e8a4680952f042
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
patch: https://syzkaller.appspot.com/x/patch.diff?x=149ddf6de00000

Note: testing is done by a robot and is best-effort only.

Qiujun Huang

unread,
Apr 3, 2020, 4:14:09 PM4/3/20
to syzbot, Andrey Konovalov, ath9k...@qca.qualcomm.com, da...@davemloft.net, kv...@codeaurora.org, LKML, USB list, linux-w...@vger.kernel.org, net...@vger.kernel.org, syzkaller-bugs
ath9k_040401.patch

syzbot

unread,
Apr 3, 2020, 4:32:04 PM4/3/20
to andre...@google.com, anen...@gmail.com, ath9k...@qca.qualcomm.com, da...@davemloft.net, kv...@codeaurora.org, linux-...@vger.kernel.org, linu...@vger.kernel.org, linux-w...@vger.kernel.org, net...@vger.kernel.org, syzkall...@googlegroups.com
Hello,

syzbot has tested the proposed patch and the reproducer did not trigger crash:

Reported-and-tested-by: syzbot+40d5d2...@syzkaller.appspotmail.com

Tested on:

commit: 0fa84af8 Merge tag 'usb-serial-5.7-rc1' of https://git.ker..
git tree: https://github.com/google/kasan.git usb-fuzzer
kernel config: https://syzkaller.appspot.com/x/.config?x=a782c087b1f425c6
dashboard link: https://syzkaller.appspot.com/bug?extid=40d5d2e8a4680952f042
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
patch: https://syzkaller.appspot.com/x/patch.diff?x=17b013b7e00000
Reply all
Reply to author
Forward
0 new messages