Hello,
syzbot found the following crash on:
HEAD commit: c3038e71 Linux 4.19.80
git tree: linux-4.19.y
console output:
https://syzkaller.appspot.com/x/log.txt?x=103c2f60e00000
kernel config:
https://syzkaller.appspot.com/x/.config?x=44c623b7e5432cee
dashboard link:
https://syzkaller.appspot.com/bug?extid=8cbf4afda1e6f8461f9b
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
Unfortunately, I don't have any reproducer for this crash yet.
IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by:
syzbot+8cbf4a...@syzkaller.appspotmail.com
netlink: 20 bytes leftover after parsing attributes in process
`syz-executor.1'.
netlink: 20 bytes leftover after parsing attributes in process
`syz-executor.3'.
------------[ cut here ]------------
WARNING: CPU: 1 PID: 7 at net/batman-adv/bat_iv_ogm.c:568
batadv_iv_ogm_emit net/batman-adv/bat_iv_ogm.c:568 [inline]
WARNING: CPU: 1 PID: 7 at net/batman-adv/bat_iv_ogm.c:568
batadv_iv_send_outstanding_bat_ogm_packet.cold+0x3f/0x46
net/batman-adv/bat_iv_ogm.c:1811
Kernel panic - not syncing: panic_on_warn set ...
CPU: 1 PID: 7 Comm: kworker/u4:0 Not tainted 4.19.80 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
Workqueue: bat_events batadv_iv_send_outstanding_bat_ogm_packet
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x172/0x1f0 lib/dump_stack.c:113
kobject: 'veth184' (000000003679febb): kobject_add_internal: parent: 'net',
set: 'devices'
panic+0x26a/0x50e kernel/panic.c:186
kobject: 'veth184' (000000003679febb): kobject_uevent_env
kobject: 'veth184' (000000003679febb): fill_kobj_path: path
= '/devices/virtual/net/veth184'
__warn.cold+0x20/0x53 kernel/panic.c:541
report_bug+0x263/0x2b0 lib/bug.c:186
kobject: 'queues' (00000000336fc6af): kobject_add_internal:
parent: 'veth184', set: '<NULL>'
fixup_bug arch/x86/kernel/traps.c:178 [inline]
fixup_bug arch/x86/kernel/traps.c:173 [inline]
do_error_trap+0x204/0x360 arch/x86/kernel/traps.c:296
kobject: 'queues' (00000000336fc6af): kobject_uevent_env
do_invalid_op+0x1b/0x20 arch/x86/kernel/traps.c:316
invalid_op+0x14/0x20 arch/x86/entry/entry_64.S:1037
RIP: 0010:batadv_iv_ogm_emit net/batman-adv/bat_iv_ogm.c:568 [inline]
RIP: 0010:batadv_iv_send_outstanding_bat_ogm_packet.cold+0x3f/0x46
net/batman-adv/bat_iv_ogm.c:1811
Code: a5 ff ff e8 9b c2 97 fa 48 c7 c7 20 48 fb 87 e8 e3 27 82 fa e9 95 a5
ff ff e8 85 c2 97 fa 48 c7 c7 20 45 fb 87 e8 cd 27 82 fa <0f> 0b e9 7d a5
ff ff e8 6d c2 97 fa 48 c7 c7 20 45 fb 87 e8 b5 27
RSP: 0018:ffff8880aa21fcc8 EFLAGS: 00010282
kobject: 'queues' (00000000336fc6af): kobject_uevent_env: filter function
caused the event to drop!
RAX: 0000000000000024 RBX: ffff8880a491e048 RCX: 0000000000000000
RDX: 0000000000000000 RSI: ffffffff81553f06 RDI: ffffed1015443f8b
RBP: ffff8880aa21fd30 R08: 0000000000000024 R09: ffffed1015d25079
R10: ffffed1015d25078 R11: ffff8880ae9283c7 R12: ffff8880603149c0
R13: ffff8880770ec5c0 R14: ffff8880a491e000 R15: ffff8880603149c0
kobject: 'rx-0' (000000005aa260f3): kobject_add_internal: parent: 'queues',
set: 'queues'
process_one_work+0x989/0x1750 kernel/workqueue.c:2153
kobject: 'rx-0' (000000005aa260f3): kobject_uevent_env
kobject: 'rx-0' (000000005aa260f3): fill_kobj_path: path
= '/devices/virtual/net/veth184/queues/rx-0'
worker_thread+0x98/0xe40 kernel/workqueue.c:2296
kthread+0x354/0x420 kernel/kthread.c:246
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:415
kobject: 'tx-0' (00000000eb31d50b): kobject_add_internal: parent: 'queues',
set: 'queues'
Kernel Offset: disabled
Rebooting in 86400 seconds..
---
This bug is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.