[v5.15] WARNING in __rate_control_send_low

0 views
Skip to first unread message

syzbot

unread,
Mar 17, 2023, 7:53:42 PM3/17/23
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 8020ae3c051d Linux 5.15.103
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=16ed349ac80000
kernel config: https://syzkaller.appspot.com/x/.config?x=d4215fb4040f8f8d
dashboard link: https://syzkaller.appspot.com/bug?extid=3b0a4c021dc15719a4c4
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/857e17de0f0a/disk-8020ae3c.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/9efc49fcd441/vmlinux-8020ae3c.xz
kernel image: https://storage.googleapis.com/syzbot-assets/f14c38b6bfa7/bzImage-8020ae3c.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+3b0a4c...@syzkaller.appspotmail.com

------------[ cut here ]------------
no supported rates for sta (null) (0xffffffff, band 1) in rate_mask 0x0 with flags 0x0
WARNING: CPU: 1 PID: 4494 at net/mac80211/rate.c:376 __rate_control_send_low+0x653/0x890 net/mac80211/rate.c:371
Modules linked in:
CPU: 1 PID: 4494 Comm: kworker/u4:8 Not tainted 5.15.103-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/02/2023
Workqueue: phy10 ieee80211_scan_work
RIP: 0010:__rate_control_send_low+0x653/0x890 net/mac80211/rate.c:371
Code: 84 c0 48 8b 14 24 0f 85 d9 01 00 00 8b 0a 48 c7 c7 a0 4a 93 8b 4c 89 f6 44 89 fa 44 8b 44 24 0c 44 8b 4c 24 08 e8 bd 9f 99 f7 <0f> 0b e9 75 fe ff ff 89 d9 80 e1 07 80 c1 03 38 c1 0f 8c e3 f9 ff
RSP: 0018:ffffc900069f7408 EFLAGS: 00010246
RAX: 0c5c9a7c221cea00 RBX: 0000000000000008 RCX: ffff88802de3ba00
RDX: 0000000000000000 RSI: 0000000000000200 RDI: 0000000000000000
RBP: ffff8880234c0de8 R08: ffffffff8166a76c R09: fffff52000d3edc1
R10: 0000000000000000 R11: dffffc0000000001 R12: dffffc0000000000
R13: 0000000000000008 R14: 0000000000000000 R15: 00000000ffffffff
FS: 0000000000000000(0000) GS:ffff8880b9b00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000020157030 CR3: 000000007549f000 CR4: 00000000003506e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
rate_control_send_low+0x1a8/0x770 net/mac80211/rate.c:396
rate_control_get_rate+0x20a/0x5d0 net/mac80211/rate.c:908
ieee80211_tx_h_rate_ctrl+0xc6e/0x1990 net/mac80211/tx.c:743
invoke_tx_handlers_late+0xb2/0x17f0 net/mac80211/tx.c:1825
ieee80211_tx+0x2df/0x460 net/mac80211/tx.c:1946
__ieee80211_tx_skb_tid_band+0x164/0x200 net/mac80211/tx.c:5667
ieee80211_tx_skb_tid_band net/mac80211/ieee80211_i.h:2199 [inline]
ieee80211_send_scan_probe_req net/mac80211/scan.c:647 [inline]
ieee80211_scan_state_send_probe+0x557/0x8f0 net/mac80211/scan.c:675
ieee80211_scan_work+0x62b/0x1d00 net/mac80211/scan.c:1139
process_one_work+0x90d/0x1270 kernel/workqueue.c:2306
worker_thread+0xaca/0x1280 kernel/workqueue.c:2453
kthread+0x3f6/0x4f0 kernel/kthread.c:319
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:298
</TASK>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Mar 27, 2023, 5:44:54 PM3/27/23
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: e3a87a10f259 Linux 6.1.21
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=143d3c9ec80000
kernel config: https://syzkaller.appspot.com/x/.config?x=b49b0405a60858ed
dashboard link: https://syzkaller.appspot.com/bug?extid=23022e34b968091fd781
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/ed3d1f3e75e6/disk-e3a87a10.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/6d8e44c8c75c/vmlinux-e3a87a10.xz
kernel image: https://storage.googleapis.com/syzbot-assets/cebe803ea4fa/bzImage-e3a87a10.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+23022e...@syzkaller.appspotmail.com

------------[ cut here ]------------
no supported rates for sta (null) (0xffffffff, band 1) in rate_mask 0x0 with flags 0x0
WARNING: CPU: 0 PID: 29200 at net/mac80211/rate.c:384 __rate_control_send_low+0x653/0x890 net/mac80211/rate.c:379
Modules linked in:
CPU: 0 PID: 29200 Comm: kworker/u4:4 Not tainted 6.1.21-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/02/2023
Workqueue: phy6 ieee80211_scan_work
RIP: 0010:__rate_control_send_low+0x653/0x890 net/mac80211/rate.c:379
Code: 48 8b 14 24 0f 85 db 01 00 00 8b 0a 48 c7 c7 c0 8f fb 8b 48 8b 74 24 10 44 89 f2 44 8b 44 24 1c 44 8b 4c 24 0c e8 1d 62 54 f7 <0f> 0b e9 79 fe ff ff 89 d9 80 e1 07 80 c1 03 38 c1 0f 8c e3 f9 ff
RSP: 0018:ffffc90006147400 EFLAGS: 00010246
RAX: 9e0c0f299e8e1000 RBX: 0000000000000008 RCX: ffff88807cd18000
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: ffff8880767aea28 R08: ffffffff8152292e R09: fffff52000c28df9
R10: 0000000000000000 R11: dffffc0000000001 R12: 0000000000000080
R13: 0000000000000008 R14: 00000000ffffffff R15: dffffc0000000000
FS: 0000000000000000(0000) GS:ffff8880b9800000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f038c2c7990 CR3: 000000005d572000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
rate_control_send_low+0x1a8/0x770 net/mac80211/rate.c:404
rate_control_get_rate+0x20a/0x5d0 net/mac80211/rate.c:916
ieee80211_tx_h_rate_ctrl+0xc72/0x1990 net/mac80211/tx.c:779
invoke_tx_handlers_late+0xb2/0x1910 net/mac80211/tx.c:1872
ieee80211_tx+0x2df/0x460 net/mac80211/tx.c:1993
__ieee80211_tx_skb_tid_band+0x4af/0x5e0 net/mac80211/tx.c:5842
ieee80211_tx_skb_tid_band net/mac80211/ieee80211_i.h:2186 [inline]
ieee80211_send_scan_probe_req net/mac80211/scan.c:651 [inline]
ieee80211_scan_state_send_probe+0x55d/0x8f0 net/mac80211/scan.c:679
ieee80211_scan_work+0x62b/0x1d20 net/mac80211/scan.c:1143
process_one_work+0x8aa/0x11f0 kernel/workqueue.c:2289
worker_thread+0xa5f/0x1210 kernel/workqueue.c:2436
kthread+0x268/0x300 kernel/kthread.c:376
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:306

syzbot

unread,
May 29, 2023, 2:19:10 PM5/29/23
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: a343b0dd87b4 Linux 6.1.30
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1559f385280000
kernel config: https://syzkaller.appspot.com/x/.config?x=8ec86bd749598dca
dashboard link: https://syzkaller.appspot.com/bug?extid=23022e34b968091fd781
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=119f1c71280000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=139bf435280000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/aebc00d6f042/disk-a343b0dd.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/7ff0321ebb5a/vmlinux-a343b0dd.xz
kernel image: https://storage.googleapis.com/syzbot-assets/c928974a56d6/Image-a343b0dd.gz.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+23022e...@syzkaller.appspotmail.com

------------[ cut here ]------------
no supported rates for sta (null) (0xffffffff, band 0) in rate_mask 0x0 with flags 0x0
WARNING: CPU: 0 PID: 70 at net/mac80211/rate.c:384 __rate_control_send_low+0x578/0x770 net/mac80211/rate.c:379
Modules linked in:
CPU: 0 PID: 70 Comm: kworker/u4:3 Not tainted 6.1.30-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/28/2023
Workqueue: phy1 ieee80211_scan_work
pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : __rate_control_send_low+0x578/0x770 net/mac80211/rate.c:379
lr : __rate_control_send_low+0x578/0x770 net/mac80211/rate.c:379
sp : ffff80001ba471d0
x29: ffff80001ba47220 x28: ffff0000d14d33f0 x27: 000000000000000c
x26: dfff800000000000 x25: 00000000ffffffff x24: ffff0000d14d0e00
x23: 0000000000000000 x22: ffff0000c896bca8 x21: 000000000000000c
x20: 1fffe0001a29a680 x19: ffff0000d14d33f8 x18: ffff80001ba465c0
x17: 6d5f65746172206e x16: ffff8000120fc834 x15: 0000000000000000
x14: 0000000000000000 x13: 0000000000000001 x12: 0000000000000001
x11: ff808000081af018 x10: 0000000000000000 x9 : 233ce384d73c5100
x8 : 233ce384d73c5100 x7 : 0000000000000001 x6 : 0000000000000001
x5 : ffff80001ba46ab8 x4 : ffff800015692ac0 x3 : ffff8000085879f4
x2 : 0000000000000001 x1 : 0000000100000200 x0 : 0000000000000000
Call trace:
__rate_control_send_low+0x578/0x770 net/mac80211/rate.c:379
rate_control_send_low+0x16c/0x694 net/mac80211/rate.c:404
rate_control_get_rate+0x1a4/0x4b0 net/mac80211/rate.c:916
ieee80211_tx_h_rate_ctrl+0x960/0x140c net/mac80211/tx.c:779
invoke_tx_handlers_late+0xa8/0x13a4 net/mac80211/tx.c:1872
ieee80211_tx+0x278/0x400 net/mac80211/tx.c:1993
ieee80211_xmit+0x278/0x354 net/mac80211/tx.c:2086
__ieee80211_tx_skb_tid_band+0x46c/0x59c net/mac80211/tx.c:5843
ieee80211_tx_skb_tid_band net/mac80211/ieee80211_i.h:2186 [inline]
ieee80211_send_scan_probe_req net/mac80211/scan.c:651 [inline]
ieee80211_scan_state_send_probe+0x4f8/0x840 net/mac80211/scan.c:679
ieee80211_scan_work+0x45c/0x1950 net/mac80211/scan.c:1143
process_one_work+0x7ac/0x1404 kernel/workqueue.c:2289
worker_thread+0x8e4/0xfec kernel/workqueue.c:2436
kthread+0x250/0x2d8 kernel/kthread.c:376
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:860
irq event stamp: 336541
hardirqs last enabled at (336540): [<ffff8000083435a8>] __up_console_sem+0xb4/0x100 kernel/printk/printk.c:261
hardirqs last disabled at (336541): [<ffff8000120f84ec>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:405
softirqs last enabled at (336162): [<ffff8000104348dc>] neigh_managed_work+0x1e0/0x21c net/core/neighbour.c:1638
softirqs last disabled at (336520): [<ffff800011a5a5ec>] local_bh_disable+0x10/0x34 include/linux/bottom_half.h:19
---[ end trace 0000000000000000 ]---


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

syzbot

unread,
Jun 23, 2023, 6:12:54 AM6/23/23
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: f67653019430 Linux 5.15.118
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=117cbedb280000
kernel config: https://syzkaller.appspot.com/x/.config?x=717fa62bb7f0fe9
dashboard link: https://syzkaller.appspot.com/bug?extid=3b0a4c021dc15719a4c4
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=10861960a80000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=14098347280000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/d21188fbe046/disk-f6765301.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/f0c688e23e63/vmlinux-f6765301.xz
kernel image: https://storage.googleapis.com/syzbot-assets/eca85b3bf72c/bzImage-f6765301.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+3b0a4c...@syzkaller.appspotmail.com

------------[ cut here ]------------
no supported rates for sta (null) (0xffffffff, band 0) in rate_mask 0x0 with flags 0x0
WARNING: CPU: 1 PID: 144 at net/mac80211/rate.c:376 __rate_control_send_low+0x653/0x890 net/mac80211/rate.c:371
Modules linked in:
CPU: 1 PID: 144 Comm: kworker/u4:1 Not tainted 5.15.118-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/27/2023
Workqueue: phy1 ieee80211_scan_work
RIP: 0010:__rate_control_send_low+0x653/0x890 net/mac80211/rate.c:371
Code: 84 c0 48 8b 14 24 0f 85 d9 01 00 00 8b 0a 48 c7 c7 e0 5f 93 8b 4c 89 f6 44 89 fa 44 8b 44 24 0c 44 8b 4c 24 08 e8 7d 82 a0 f7 <0f> 0b e9 75 fe ff ff 89 d9 80 e1 07 80 c1 03 38 c1 0f 8c e3 f9 ff
RSP: 0018:ffffc9000123f408 EFLAGS: 00010246
RAX: 8828fe3b35ddcc00 RBX: 000000000000000c RCX: ffff8880131c9dc0
RDX: 0000000000000000 RSI: 0000000080000200 RDI: 0000000000000000
RBP: ffff88807733e3e8 R08: ffffffff8166491c R09: fffff52000247dc1
R10: 0000000000000000 R11: dffffc0000000001 R12: dffffc0000000000
R13: 000000000000000c R14: 0000000000000000 R15: 00000000ffffffff
FS: 0000000000000000(0000) GS:ffff8880b9b00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f21ef150230 CR3: 000000000c68e000 CR4: 00000000003506e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
rate_control_send_low+0x1a8/0x770 net/mac80211/rate.c:396
rate_control_get_rate+0x20a/0x5d0 net/mac80211/rate.c:908
ieee80211_tx_h_rate_ctrl+0xc6e/0x1990 net/mac80211/tx.c:743
invoke_tx_handlers_late+0xb2/0x17f0 net/mac80211/tx.c:1825
ieee80211_tx+0x2df/0x460 net/mac80211/tx.c:1946
__ieee80211_tx_skb_tid_band+0x164/0x200 net/mac80211/tx.c:5667
ieee80211_tx_skb_tid_band net/mac80211/ieee80211_i.h:2199 [inline]
ieee80211_send_scan_probe_req net/mac80211/scan.c:647 [inline]
ieee80211_scan_state_send_probe+0x557/0x8f0 net/mac80211/scan.c:675
ieee80211_scan_work+0x62b/0x1d00 net/mac80211/scan.c:1139
process_one_work+0x8a1/0x10c0 kernel/workqueue.c:2307
worker_thread+0xaca/0x1280 kernel/workqueue.c:2454
kthread+0x3f6/0x4f0 kernel/kthread.c:319
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:298
</TASK>


---
Reply all
Reply to author
Forward
0 new messages