WARNING in minstrel_rate_init

7 views
Skip to first unread message

syzbot

unread,
Nov 25, 2021, 5:06:39 AM11/25/21
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 3f8a27f9e27b Linux 4.19.211
git tree: linux-4.19.y
console output: https://syzkaller.appspot.com/x/log.txt?x=14abc326b00000
kernel config: https://syzkaller.appspot.com/x/.config?x=9b9277b418617afe
dashboard link: https://syzkaller.appspot.com/bug?extid=3c93a5b672f3dd48e4a3
compiler: gcc version 10.2.1 20210110 (Debian 10.2.1-6)

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+3c93a5...@syzkaller.appspotmail.com

mac80211_hwsim hwsim13 wlan1: disabling VHT as WMM/QoS is not supported by the AP
wlan1: RX AssocResp from 08:02:11:00:00:00 (capab=0x1 status=0 aid=1)
WARNING: CPU: 0 PID: 54 at include/net/mac80211.h:5720 rate_lowest_index include/net/mac80211.h:5720 [inline]
WARNING: CPU: 0 PID: 54 at include/net/mac80211.h:5720 minstrel_rate_init+0x1e2/0x1540 net/mac80211/rc80211_minstrel.c:480
Kernel panic - not syncing: panic_on_warn set ...

CPU: 0 PID: 54 Comm: kworker/u4:2 Not tainted 4.19.211-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Workqueue: phy13 ieee80211_iface_work
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x1fc/0x2ef lib/dump_stack.c:118
panic+0x26a/0x50e kernel/panic.c:186
__warn.cold+0x20/0x5a kernel/panic.c:541
report_bug+0x262/0x2b0 lib/bug.c:183
fixup_bug arch/x86/kernel/traps.c:178 [inline]
fixup_bug arch/x86/kernel/traps.c:173 [inline]
do_error_trap+0x1d7/0x310 arch/x86/kernel/traps.c:296
invalid_op+0x14/0x20 arch/x86/entry/entry_64.S:1038
RIP: 0010:rate_lowest_index include/net/mac80211.h:5720 [inline]
RIP: 0010:minstrel_rate_init+0x1e2/0x1540 net/mac80211/rc80211_minstrel.c:480
Code: 94 75 b0 f9 4d 85 f6 0f 85 f8 0f 00 00 e8 f6 73 b0 f9 41 83 c4 01 89 de 44 89 e7 e8 d8 74 b0 f9 41 39 dc 75 c3 e8 de 73 b0 f9 <0f> 0b 31 db 45 31 e4 eb 13 48 8b 44 24 30 31 db 45 31 e4 48 83 c0
RSP: 0018:ffff8880b516f370 EFLAGS: 00010293
RAX: ffff8880b5162040 RBX: 000000000000000c RCX: ffffffff87b21188
RDX: 0000000000000000 RSI: ffffffff87b21192 RDI: 0000000000000004
RBP: ffff88804d37b5a0 R08: ffff8880915cab00 R09: 000000000000000c
R10: 0000000000000004 R11: 0000000000074071 R12: 000000000000000c
R13: 0000000000000000 R14: 0000000000000000 R15: ffff8880915cab00
minstrel_ht_update_caps+0xf66/0x12e0 net/mac80211/rc80211_minstrel_ht.c:1279
rate_control_rate_init+0x2b3/0x4f0 net/mac80211/rate.c:58
ieee80211_assoc_success+0x161b/0x2b8a net/mac80211/mlme.c:3311
ieee80211_rx_mgmt_assoc_resp net/mac80211/mlme.c:3476 [inline]
ieee80211_sta_rx_queued_mgmt.cold+0x12a6/0x1dfd net/mac80211/mlme.c:3965
ieee80211_iface_work+0x5ad/0x8a0 net/mac80211/iface.c:1338
process_one_work+0x864/0x1570 kernel/workqueue.c:2153
worker_thread+0x64c/0x1130 kernel/workqueue.c:2296
kthread+0x33f/0x460 kernel/kthread.c:259
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:415
Kernel Offset: disabled
Rebooting in 86400 seconds..


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Dec 9, 2021, 1:58:27 AM12/9/21
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 3f8a27f9e27b Linux 4.19.211
git tree: linux-4.19.y
console output: https://syzkaller.appspot.com/x/log.txt?x=13b048b9b00000
kernel config: https://syzkaller.appspot.com/x/.config?x=9b9277b418617afe
dashboard link: https://syzkaller.appspot.com/bug?extid=3c93a5b672f3dd48e4a3
compiler: gcc version 10.2.1 20210110 (Debian 10.2.1-6)
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1522e791b00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1165b3c5b00000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+3c93a5...@syzkaller.appspotmail.com

mac80211_hwsim hwsim3 wlan1: disabling HT as WMM/QoS is not supported by the AP
mac80211_hwsim: wmediumd released netlink socket, switching to perfect channel medium
mac80211_hwsim hwsim3 wlan1: disabling VHT as WMM/QoS is not supported by the AP
wlan1: associating with AP with corrupt probe response
wlan1: RX AssocResp from 08:02:11:00:00:00 (capab=0x1 status=0 aid=1)
WARNING: CPU: 0 PID: 23 at include/net/mac80211.h:5720 rate_lowest_index include/net/mac80211.h:5720 [inline]
WARNING: CPU: 0 PID: 23 at include/net/mac80211.h:5720 minstrel_rate_init+0x1e2/0x1540 net/mac80211/rc80211_minstrel.c:480
Kernel panic - not syncing: panic_on_warn set ...

CPU: 0 PID: 23 Comm: kworker/u4:1 Not tainted 4.19.211-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Workqueue: phy3 ieee80211_iface_work
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x1fc/0x2ef lib/dump_stack.c:118
panic+0x26a/0x50e kernel/panic.c:186
__warn.cold+0x20/0x5a kernel/panic.c:541
report_bug+0x262/0x2b0 lib/bug.c:183
fixup_bug arch/x86/kernel/traps.c:178 [inline]
fixup_bug arch/x86/kernel/traps.c:173 [inline]
do_error_trap+0x1d7/0x310 arch/x86/kernel/traps.c:296
invalid_op+0x14/0x20 arch/x86/entry/entry_64.S:1038
RIP: 0010:rate_lowest_index include/net/mac80211.h:5720 [inline]
RIP: 0010:minstrel_rate_init+0x1e2/0x1540 net/mac80211/rc80211_minstrel.c:480
Code: 94 75 b0 f9 4d 85 f6 0f 85 f8 0f 00 00 e8 f6 73 b0 f9 41 83 c4 01 89 de 44 89 e7 e8 d8 74 b0 f9 41 39 dc 75 c3 e8 de 73 b0 f9 <0f> 0b 31 db 45 31 e4 eb 13 48 8b 44 24 30 31 db 45 31 e4 48 83 c0
RSP: 0018:ffff8880b5047370 EFLAGS: 00010293
RAX: ffff8880b503c600 RBX: 000000000000000c RCX: ffffffff87b21188
RDX: 0000000000000000 RSI: ffffffff87b21192 RDI: 0000000000000004
RBP: ffff88809df12ae0 R08: ffff8880b01dc080 R09: 000000000000000c
R10: 0000000000000004 R11: 0000000000074071 R12: 000000000000000c
R13: 0000000000000000 R14: 0000000000000000 R15: ffff8880b01dc080
Reply all
Reply to author
Forward
0 new messages