general protection fault in quarantine_remove_cache

4 views
Skip to first unread message

syzbot

unread,
Apr 12, 2020, 9:39:12 AM4/12/20
to syzkaller...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 4520f06b Linux 4.14.175
git tree: linux-4.14.y
console output: https://syzkaller.appspot.com/x/log.txt?x=10d21e3fe00000
kernel config: https://syzkaller.appspot.com/x/.config?x=93cf891381c0c347
dashboard link: https://syzkaller.appspot.com/bug?extid=511d2a1de6f4cf416e53
compiler: gcc (GCC) 9.0.0 20181231 (experimental)

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+511d2a...@syzkaller.appspotmail.com

kasan: CONFIG_KASAN_INLINE enabled
kasan: GPF could be caused by NULL-ptr deref or user memory access
general protection fault: 0000 [#1] PREEMPT SMP KASAN
Modules linked in:
CPU: 1 PID: 16323 Comm: kworker/u4:8 Not tainted 4.14.175-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Workqueue: netns cleanup_net
task: ffff88804e72e080 task.stack: ffff88804eb50000
RIP: 0010:qlist_move_cache+0x67/0xd0 mm/kasan/quarantine.c:275
RSP: 0018:ffff88804eb57b08 EFLAGS: 00010006
RAX: ffff888048f427c0 RBX: ffff88804eb57b40 RCX: ffffea000276071f
RDX: 0000000000001100 RSI: ffff88804eb57b40 RDI: ffff8880001580c0
RBP: ffff888095b00240 R08: 0000000000006998 R09: ffffffff8a090540
R10: ffff88804e72e9f0 R11: ffff88804e72e080 R12: ffffea0000000000
R13: 0003300030303030 R14: ffffffff8a59ce18 R15: 0003300030303030
FS: 0000000000000000(0000) GS:ffff8880aeb00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000020008880 CR3: 0000000026d5c000 CR4: 00000000001406e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
quarantine_remove_cache+0x63/0xd0 mm/kasan/quarantine.c:317
shutdown_cache+0xe/0x1b0 mm/slab_common.c:540
kmem_cache_destroy+0x1cd/0x230 mm/slab_common.c:842
tipc_server_stop+0x13a/0x171 net/tipc/server.c:637
tipc_topsrv_stop net/tipc/subscr.c:390 [inline]
tipc_topsrv_exit_net+0x168/0x28a net/tipc/subscr.c:402
ops_exit_list.isra.0+0x9d/0x140 net/core/net_namespace.c:142
cleanup_net+0x3bb/0x820 net/core/net_namespace.c:484
process_one_work+0x813/0x1540 kernel/workqueue.c:2116
worker_thread+0x5d1/0x1070 kernel/workqueue.c:2250
kthread+0x30d/0x420 kernel/kthread.c:232
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:404
Code: 00 00 00 00 eb 22 49 83 3e 00 74 7d 49 8b 46 08 4c 89 28 4d 89 6e 08 49 c7 45 00 00 00 00 00 49 01 56 10 4d 85 ff 74 56 4d 89 fd <4d> 8b 3f 4c 89 ef e8 0e 18 a6 ff 48 c1 e8 0c 48 c1 e0 06 4c 01
RIP: qlist_move_cache+0x67/0xd0 mm/kasan/quarantine.c:275 RSP: ffff88804eb57b08
---[ end trace 6b4aa9cb7683a483 ]---


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Aug 10, 2020, 9:39:13 AM8/10/20
to syzkaller...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages