Hello,
syzbot found the following crash on:
HEAD commit: 4d552acf Linux 4.19.34
git tree: linux-4.19.y
console output:
https://syzkaller.appspot.com/x/log.txt?x=11f0f98f200000
kernel config:
https://syzkaller.appspot.com/x/.config?x=c95a88291f095edd
dashboard link:
https://syzkaller.appspot.com/bug?extid=2b51fc95e5df897f47e5
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
Unfortunately, I don't have any reproducer for this crash yet.
IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by:
syzbot+2b51fc...@syzkaller.appspotmail.com
autofs4:pid:6436:check_dev_ioctl_version: ioctl control interface version
mismatch: kernel(1.1), user(1.788529152), cmd(0x00009374)
WARNING: CPU: 1 PID: 31380 at drivers/tty/tty_ioctl.c:319
tty_set_termios+0x7a9/0x8d0 drivers/tty/tty_ioctl.c:319
Kernel panic - not syncing: panic_on_warn set ...
autofs4:pid:6436:validate_dev_ioctl: invalid device control module version
supplied for cmd(0x00009374)
CPU: 1 PID: 31380 Comm: kworker/u5:2 Not tainted 4.19.34 #2
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
Workqueue: hci0 hci_power_on
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x172/0x1f0 lib/dump_stack.c:113
panic+0x263/0x51d kernel/panic.c:185
__warn.cold+0x20/0x54 kernel/panic.c:540
report_bug+0x263/0x2b0 lib/bug.c:186
fixup_bug arch/x86/kernel/traps.c:178 [inline]
fixup_bug arch/x86/kernel/traps.c:173 [inline]
do_error_trap+0x204/0x360 arch/x86/kernel/traps.c:296
kobject: 'input1300' (00000000853e87d9): kobject_add_internal:
parent: 'input', set: 'devices'
do_invalid_op+0x1b/0x20 arch/x86/kernel/traps.c:316
invalid_op+0x14/0x20 arch/x86/entry/entry_64.S:997
RIP: 0010:tty_set_termios+0x7a9/0x8d0 drivers/tty/tty_ioctl.c:319
Code: 0f b6 14 02 48 89 f8 83 e0 07 83 c0 03 38 d0 7c 08 84 d2 0f 85 a3 00
00 00 45 89 a7 d0 03 00 00 e9 47 fe ff ff e8 77 49 05 fe <0f> 0b e9 3a f9
ff ff e8 2b a7 3b fe e9 d2 fa ff ff e8 21 a7 3b fe
RSP: 0018:ffff888084e27990 EFLAGS: 00010293
RAX: ffff888080438540 RBX: ffff888084e27a50 RCX: ffffffff8365e6fd
RDX: 0000000000000000 RSI: ffffffff8365edc9 RDI: 0000000000000005
RBP: ffff888084e27a78 R08: ffff888080438540 R09: fffffbfff15dc791
R10: fffffbfff15dc790 R11: 0000000000000003 R12: ffff888084e27ab8
R13: 0000000000010004 R14: 1ffff110109c4f51 R15: ffff88809bd42240
hci_uart_set_baudrate+0x157/0x1c0 drivers/bluetooth/hci_ldisc.c:378
kobject: 'input1300' (00000000853e87d9): kobject_uevent_env
hci_uart_setup+0xa2/0x490 drivers/bluetooth/hci_ldisc.c:401
hci_dev_do_open+0x67e/0x14b0 net/bluetooth/hci_core.c:1423
kobject: 'input1300' (00000000853e87d9): fill_kobj_path: path
= '/devices/virtual/input/input1300'
kobject: 'input1300' (00000000853e87d9): fill_kobj_path: path
= '/devices/virtual/input/input1300'
hci_power_on+0x10d/0x580 net/bluetooth/hci_core.c:2130
process_one_work+0x98e/0x1760 kernel/workqueue.c:2153
input: syz0 as /devices/virtual/input/input1300
worker_thread+0x98/0xe40 kernel/workqueue.c:2296
kthread+0x357/0x430 kernel/kthread.c:246
ret_from_fork+0x3a/0x50 arch/x86/entry/entry_64.S:413
kobject: 'event4' (0000000005a89f78): kobject_add_internal:
parent: 'input1300', set: 'devices'
Kernel Offset: disabled
Rebooting in 86400 seconds..
---
This bug is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.