Hello,
syzbot found the following crash on:
HEAD commit: 35766839 Linux 4.19.103
git tree: linux-4.19.y
console output:
https://syzkaller.appspot.com/x/log.txt?x=10fe3231e00000
kernel config:
https://syzkaller.appspot.com/x/.config?x=84f14e7b6cbc7d27
dashboard link:
https://syzkaller.appspot.com/bug?extid=d2af0cc003fc74b65fea
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
Unfortunately, I don't have any reproducer for this crash yet.
IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by:
syzbot+d2af0c...@syzkaller.appspotmail.com
bond0 (unregistering): Releasing backup interface bond_slave_1
bond0 (unregistering): Releasing backup interface bond_slave_0
bond0 (unregistering): Released all slaves
IPv6: ADDRCONF(NETDEV_UP): bridge0: link is not ready
WARNING: CPU: 0 PID: 2935 at drivers/net/geneve.c:1729 geneve_destroy_tunnels drivers/net/geneve.c:1729 [inline]
WARNING: CPU: 0 PID: 2935 at drivers/net/geneve.c:1729 geneve_exit_batch_net+0x537/0x630 drivers/net/geneve.c:1739
Kernel panic - not syncing: panic_on_warn set ...
CPU: 0 PID: 2935 Comm: kworker/u4:3 Not tainted 4.19.103-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Workqueue: netns cleanup_net
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x197/0x210 lib/dump_stack.c:118
panic+0x26a/0x50e kernel/panic.c:186
__warn.cold+0x20/0x53 kernel/panic.c:541
report_bug+0x263/0x2b0 lib/bug.c:186
fixup_bug arch/x86/kernel/traps.c:178 [inline]
fixup_bug arch/x86/kernel/traps.c:173 [inline]
do_error_trap+0x204/0x360 arch/x86/kernel/traps.c:296
do_invalid_op+0x1b/0x20 arch/x86/kernel/traps.c:316
invalid_op+0x14/0x20 arch/x86/entry/entry_64.S:1037
RIP: 0010:geneve_destroy_tunnels drivers/net/geneve.c:1729 [inline]
RIP: 0010:geneve_exit_batch_net+0x537/0x630 drivers/net/geneve.c:1739
Code: fc 48 c7 c2 a0 b7 15 88 be 2d 00 00 00 48 c7 c7 20 bb 15 88 c6 05 e0 ea 52 05 01 e8 0a bb de fc e9 68 fc ff ff e8 29 5a f7 fc <0f> 0b e9 9a fe ff ff 48 8d 43 c0 48 89 85 68 ff ff ff e9 bb fe ff
RSP: 0018:ffff88802eb07b58 EFLAGS: 00010293
RAX: ffff88801038c400 RBX: dffffc0000000000 RCX: ffffffff85c7007c
RDX: 0000000000000000 RSI: ffffffff8473d447 RDI: ffff888050fb4a38
RBP: ffff88802eb07c08 R08: ffff88801038c400 R09: fffffbfff1340715
R10: fffffbfff1340714 R11: ffffffff89a038a7 R12: ffff88807a8cc100
R13: ffff88808dad8910 R14: ffff88808dad8900 R15: ffff88808dad8900
ops_exit_list.isra.0+0xfc/0x150 net/core/net_namespace.c:156
cleanup_net+0x404/0x960 net/core/net_namespace.c:553
process_one_work+0x989/0x1750 kernel/workqueue.c:2153
worker_thread+0x98/0xe40 kernel/workqueue.c:2296
kthread+0x354/0x420 kernel/kthread.c:246
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:415
Kernel Offset: disabled
Rebooting in 86400 seconds..
---
This bug is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.