INFO: trying to register non-static key in skb_dequeue

11 views
Skip to first unread message

syzbot

unread,
Aug 3, 2020, 5:08:19 PM8/3/20
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 13af6c74 Linux 4.19.136
git tree: linux-4.19.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1449abea900000
kernel config: https://syzkaller.appspot.com/x/.config?x=5b7578d3b5457a49
dashboard link: https://syzkaller.appspot.com/bug?extid=60b55f8368659c5bb4b9
compiler: gcc (GCC) 10.1.0-syz 20200507
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1459a746900000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+60b55f...@syzkaller.appspotmail.com

IPv6: ADDRCONF(NETDEV_UP): batadv_slave_1: link is not ready
batman_adv: batadv0: Interface activated: batadv_slave_1
IPv6: ADDRCONF(NETDEV_CHANGE): batadv_slave_1: link becomes ready
IPv6: ADDRCONF(NETDEV_CHANGE): veth1_to_batadv: link becomes ready
INFO: trying to register non-static key.
the code is fine but needs lockdep annotation.
turning off the locking correctness validator.
CPU: 0 PID: 6748 Comm: syz-executor.0 Not tainted 4.19.136-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x1fc/0x2fe lib/dump_stack.c:118
assign_lock_key kernel/locking/lockdep.c:727 [inline]
register_lock_class+0xe76/0x11c0 kernel/locking/lockdep.c:753
__lock_acquire+0x17d/0x3ff0 kernel/locking/lockdep.c:3303
lock_acquire+0x170/0x3c0 kernel/locking/lockdep.c:3907
__raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline]
_raw_spin_lock_irqsave+0x8c/0xc0 kernel/locking/spinlock.c:152
skb_dequeue+0x1c/0x170 net/core/skbuff.c:2819
skb_queue_purge+0x21/0x30 net/core/skbuff.c:2857
l2cap_chan_del+0x616/0x8e0 net/bluetooth/l2cap_core.c:634
l2cap_chan_close+0x108/0x820 net/bluetooth/l2cap_core.c:754
l2cap_sock_shutdown+0x85e/0xbd0 net/bluetooth/l2cap_sock.c:1159
l2cap_sock_release+0x63/0x190 net/bluetooth/l2cap_sock.c:1201
__sock_release+0xcd/0x2a0 net/socket.c:579
sock_close+0x15/0x20 net/socket.c:1140
__fput+0x2ce/0x890 fs/file_table.c:278
task_work_run+0x148/0x1c0 kernel/task_work.c:113
get_signal+0x1b64/0x1f70 kernel/signal.c:2399
do_signal+0x8f/0x1670 arch/x86/kernel/signal.c:821
exit_to_usermode_loop+0x204/0x2a0 arch/x86/entry/common.c:163
prepare_exit_to_usermode arch/x86/entry/common.c:198 [inline]
syscall_return_slowpath arch/x86/entry/common.c:271 [inline]
do_syscall_64+0x538/0x620 arch/x86/entry/common.c:296
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x45cc79
Code: 2d b6 fb ff c3 66 2e 0f 1f 84 00 00 00 00 00 66 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 0f 83 fb b5 fb ff c3 66 2e 0f 1f 84 00 00 00 00
RSP: 002b:00007f8070054c78 EFLAGS: 00000246 ORIG_RAX: 000000000000002a
RAX: fffffffffffffffc RBX: 0000000000002040 RCX: 000000000045cc79
RDX: 0000000000000080 RSI: 0000000020000100 RDI: 0000000000000006
RBP: 000000000078bfe0 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 000000000078bfac
R13: 00007ffcc26244df R14: 00007f80700559c0 R15: 000000000078bfac
Bluetooth: hci0: command 0x0409 tx timeout
Bluetooth: hci0: command 0x041b tx timeout
Bluetooth: hci0: command 0x040f tx timeout
Bluetooth: hci0: command 0x0419 tx timeout


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this issue, for details see:
https://goo.gl/tpsmEJ#testing-patches

syzbot

unread,
Aug 6, 2020, 1:40:17 AM8/6/20
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: ca4f2c56 Linux 4.14.192
git tree: linux-4.14.y
console output: https://syzkaller.appspot.com/x/log.txt?x=17a5f770900000
kernel config: https://syzkaller.appspot.com/x/.config?x=60834b36c72d3e64
dashboard link: https://syzkaller.appspot.com/bug?extid=dbd5c927457cd84fb324
compiler: gcc (GCC) 10.1.0-syz 20200507
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=16c4e392900000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+dbd5c9...@syzkaller.appspotmail.com

Bluetooth: hci0 command 0x040f tx timeout
Bluetooth: hci0 command 0x0419 tx timeout
Bluetooth: hci0 command 0x0405 tx timeout
INFO: trying to register non-static key.
the code is fine but needs lockdep annotation.
turning off the locking correctness validator.
CPU: 1 PID: 10343 Comm: syz-executor.0 Not tainted 4.14.192-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:17 [inline]
dump_stack+0x1b2/0x283 lib/dump_stack.c:58
register_lock_class+0x32b/0x1320 kernel/locking/lockdep.c:768
__lock_acquire+0x167/0x3f20 kernel/locking/lockdep.c:3378
lock_acquire+0x170/0x3f0 kernel/locking/lockdep.c:3998
__raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline]
_raw_spin_lock_irqsave+0x8c/0xc0 kernel/locking/spinlock.c:160
skb_dequeue+0x1c/0x170 net/core/skbuff.c:2816
skb_queue_purge+0x21/0x30 net/core/skbuff.c:2854
l2cap_chan_del+0x51d/0x800 net/bluetooth/l2cap_core.c:634
l2cap_chan_close+0xd5/0x770 net/bluetooth/l2cap_core.c:754
l2cap_sock_shutdown+0x74e/0xa60 net/bluetooth/l2cap_sock.c:1160
l2cap_sock_release+0x63/0x180 net/bluetooth/l2cap_sock.c:1202
__sock_release+0xcd/0x2b0 net/socket.c:602
sock_close+0x15/0x20 net/socket.c:1139
__fput+0x25f/0x7a0 fs/file_table.c:210
task_work_run+0x11f/0x190 kernel/task_work.c:113
get_signal+0x18a3/0x1ca0 kernel/signal.c:2234
do_signal+0x7c/0x1550 arch/x86/kernel/signal.c:814
exit_to_usermode_loop+0x160/0x200 arch/x86/entry/common.c:160
prepare_exit_to_usermode arch/x86/entry/common.c:199 [inline]
syscall_return_slowpath arch/x86/entry/common.c:270 [inline]
do_syscall_64+0x4a3/0x640 arch/x86/entry/common.c:297
entry_SYSCALL_64_after_hwframe+0x46/0xbb
RIP: 0033:0x45ccd9
RSP: 002b:00007fed0f3ffc78 EFLAGS: 00000246 ORIG_RAX: 000000000000002a
RAX: fffffffffffffffc RBX: 0000000000002040 RCX: 000000000045ccd9
RDX: 0000000000000080 RSI: 0000000020000100 RDI: 0000000000000005
RBP: 000000000078bfe0 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 000000000078bfac
R13: 00007fff8d0d1bff R14: 00007fed0f4009c0 R15: 000000000078bfac

syzbot

unread,
Nov 8, 2020, 9:26:19 PM11/8/20
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 6b6446ef Linux 4.14.204
git tree: linux-4.14.y
console output: https://syzkaller.appspot.com/x/log.txt?x=10f2958a500000
kernel config: https://syzkaller.appspot.com/x/.config?x=3b2e3745f25cbc4e
dashboard link: https://syzkaller.appspot.com/bug?extid=dbd5c927457cd84fb324
compiler: gcc (GCC) 10.1.0-syz 20200507
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=14265c3a500000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=16dd0a34500000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+dbd5c9...@syzkaller.appspotmail.com

IPVS: ftp: loaded support on port[0] = 21
Bluetooth: hci0 command 0x0409 tx timeout
Bluetooth: hci0 command 0x041b tx timeout
INFO: trying to register non-static key.
the code is fine but needs lockdep annotation.
turning off the locking correctness validator.
CPU: 0 PID: 8021 Comm: syz-executor911 Not tainted 4.14.204-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:17 [inline]
dump_stack+0x1b2/0x283 lib/dump_stack.c:58
register_lock_class+0x32b/0x1320 kernel/locking/lockdep.c:768
__lock_acquire+0x167/0x3f20 kernel/locking/lockdep.c:3378
lock_acquire+0x170/0x3f0 kernel/locking/lockdep.c:3998
__raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline]
_raw_spin_lock_irqsave+0x8c/0xc0 kernel/locking/spinlock.c:160
skb_dequeue+0x1c/0x180 net/core/skbuff.c:2816
skb_queue_purge+0x21/0x30 net/core/skbuff.c:2854
l2cap_chan_del+0x56d/0x950 net/bluetooth/l2cap_core.c:637
l2cap_chan_close+0x103/0x870 net/bluetooth/l2cap_core.c:757
l2cap_sock_shutdown+0x2e7/0xc20 net/bluetooth/l2cap_sock.c:1160
l2cap_sock_release+0x77/0x280 net/bluetooth/l2cap_sock.c:1203
__sock_release+0xcd/0x2b0 net/socket.c:602
sock_close+0x15/0x20 net/socket.c:1139
__fput+0x25f/0x7a0 fs/file_table.c:210
task_work_run+0x11f/0x190 kernel/task_work.c:113
exit_task_work include/linux/task_work.h:22 [inline]
do_exit+0xa08/0x27f0 kernel/exit.c:865
do_group_exit+0x100/0x2e0 kernel/exit.c:962
get_signal+0x38d/0x1ca0 kernel/signal.c:2423
do_signal+0x7c/0x1550 arch/x86/kernel/signal.c:814
exit_to_usermode_loop+0x160/0x200 arch/x86/entry/common.c:160
prepare_exit_to_usermode arch/x86/entry/common.c:199 [inline]
syscall_return_slowpath arch/x86/entry/common.c:270 [inline]
do_syscall_64+0x4a3/0x640 arch/x86/entry/common.c:297
entry_SYSCALL_64_after_hwframe+0x46/0xbb
RIP: 0033:0x446eb9
RSP: 002b:00007ffe6633e878 EFLAGS: 00000246 ORIG_RAX: 000000000000002a
RAX: fffffffffffffffc RBX: 0000000000000003 RCX: 0000000000446eb9
RDX: 000000000000000e RSI: 0000000020000080 RDI: 0000000000000004
RBP: 0000000000000003 R08: 00000000000000ff R09: 00000000000000ff
R10: 000000000000000c R11: 0000000000000246 R12: 00000000018b7850
R13: 0000000000000072 R14: 0000000000000000 R15: 0000000000000000

syzbot

unread,
Dec 2, 2020, 10:03:18 AM12/2/20
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: daefdc9e Linux 4.19.161
git tree: linux-4.19.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1107b29d500000
kernel config: https://syzkaller.appspot.com/x/.config?x=5e8be1f59358cc24
dashboard link: https://syzkaller.appspot.com/bug?extid=60b55f8368659c5bb4b9
compiler: gcc (GCC) 10.1.0-syz 20200507
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1519d353500000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=11c0a1c9500000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+60b55f...@syzkaller.appspotmail.com

IPVS: ftp: loaded support on port[0] = 21
Bluetooth: hci0: command 0x0409 tx timeout
Bluetooth: hci0: command 0x041b tx timeout
INFO: trying to register non-static key.
the code is fine but needs lockdep annotation.
turning off the locking correctness validator.
CPU: 0 PID: 8136 Comm: syz-executor488 Not tainted 4.19.161-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x1fc/0x2fe lib/dump_stack.c:118
assign_lock_key kernel/locking/lockdep.c:727 [inline]
register_lock_class+0xe76/0x11c0 kernel/locking/lockdep.c:753
__lock_acquire+0x17d/0x3ff0 kernel/locking/lockdep.c:3303
lock_acquire+0x170/0x3c0 kernel/locking/lockdep.c:3907
__raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline]
_raw_spin_lock_irqsave+0x8c/0xc0 kernel/locking/spinlock.c:152
skb_dequeue+0x1c/0x180 net/core/skbuff.c:2819
skb_queue_purge+0x21/0x30 net/core/skbuff.c:2857
l2cap_chan_del+0x690/0xa50 net/bluetooth/l2cap_core.c:637
l2cap_chan_close+0x1b5/0x950 net/bluetooth/l2cap_core.c:757
l2cap_sock_shutdown+0x339/0xe10 net/bluetooth/l2cap_sock.c:1159
l2cap_sock_release+0x77/0x290 net/bluetooth/l2cap_sock.c:1202
__sock_release+0xcd/0x2a0 net/socket.c:579
sock_close+0x15/0x20 net/socket.c:1140
__fput+0x2ce/0x890 fs/file_table.c:278
task_work_run+0x148/0x1c0 kernel/task_work.c:113
exit_task_work include/linux/task_work.h:22 [inline]
do_exit+0xbed/0x2be0 kernel/exit.c:890
do_group_exit+0x125/0x310 kernel/exit.c:993
get_signal+0x3f2/0x1f70 kernel/signal.c:2589
do_signal+0x8f/0x1670 arch/x86/kernel/signal.c:821
exit_to_usermode_loop+0x204/0x2a0 arch/x86/entry/common.c:163
prepare_exit_to_usermode arch/x86/entry/common.c:198 [inline]
syscall_return_slowpath arch/x86/entry/common.c:271 [inline]
do_syscall_64+0x538/0x620 arch/x86/entry/common.c:296
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x446eb9
Code: Bad RIP value.
RSP: 002b:00007ffc25dc31a8 EFLAGS: 00000246 ORIG_RAX: 000000000000002a
RAX: fffffffffffffffc RBX: 0000000000000003 RCX: 0000000000446eb9
RDX: 000000000000000e RSI: 0000000020000080 RDI: 0000000000000004
RBP: 0000000000000003 R08: 00000000000000ff R09: 00000000000000ff
R10: 000000000000000c R11: 0000000000000246 R12: 00000000014af850
R13: 0000000000000072 R14: 0000000000000000 R15: 0000000000000000
Bluetooth: hci0: command 0x040f tx timeout
Bluetooth: hci0: command 0x0419 tx timeout
Reply all
Reply to author
Forward
0 new messages