[v5.15] BUG: soft lockup in addrconf_rs_timer

10 views
Skip to first unread message

syzbot

unread,
Jun 1, 2023, 5:19:07 PM6/1/23
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 0ab06468cbd1 Linux 5.15.114
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1464da01280000
kernel config: https://syzkaller.appspot.com/x/.config?x=9a2696a271d0eba
dashboard link: https://syzkaller.appspot.com/bug?extid=5ae410d749c85c9f54ef
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2
userspace arch: arm64

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/8ff3613d3f6b/disk-0ab06468.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/eebe2d8c6813/vmlinux-0ab06468.xz
kernel image: https://storage.googleapis.com/syzbot-assets/f30284c26197/Image-0ab06468.gz.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+5ae410...@syzkaller.appspotmail.com

watchdog: BUG: soft lockup - CPU#0 stuck for 23s! [ksoftirqd/0:14]
Modules linked in:
irq event stamp: 1867461
hardirqs last enabled at (1867460): [<ffff800011947a48>] __exit_to_kernel_mode arch/arm64/kernel/entry-common.c:81 [inline]
hardirqs last enabled at (1867460): [<ffff800011947a48>] exit_to_kernel_mode+0x100/0x178 arch/arm64/kernel/entry-common.c:91
hardirqs last disabled at (1867461): [<ffff800011947c90>] enter_el1_irq_or_nmi+0x10/0x1c arch/arm64/kernel/entry-common.c:227
softirqs last enabled at (1862894): [<ffff800008020ccc>] softirq_handle_end kernel/softirq.c:401 [inline]
softirqs last enabled at (1862894): [<ffff800008020ccc>] __do_softirq+0xb5c/0xe20 kernel/softirq.c:587
softirqs last disabled at (1862937): [<ffff8000081b7e98>] run_ksoftirqd+0x68/0x258 kernel/softirq.c:920
CPU: 0 PID: 14 Comm: ksoftirqd/0 Not tainted 5.15.114-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/28/2023
pstate: 00400005 (nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : __list_del_entry include/linux/list.h:135 [inline]
pc : list_move_tail include/linux/list.h:227 [inline]
pc : fq_pie_qdisc_dequeue+0x29c/0x874 net/sched/sch_fq_pie.c:248
lr : __list_del_entry include/linux/list.h:135 [inline]
lr : list_move_tail include/linux/list.h:227 [inline]
lr : fq_pie_qdisc_dequeue+0x290/0x874 net/sched/sch_fq_pie.c:248
sp : ffff800018926f90
x29: ffff800018927000 x28: ffff0000d930da30 x27: 1fffe0001b261b44
x26: dfff800000000000 x25: ffff0000f44472e8 x24: ffff0000f44472f0
x23: ffff0000d930da20 x22: ffff0000f44472e0 x21: ffff0000f44472e0
x20: 0000000000000000 x19: 0000000000000000 x18: 0000000000000501
x17: ff8080000ff4d74c x16: 0000000000000000 x15: ffff80000ff4d74c
x14: 0000000000000001 x13: ffffffffffffffff x12: 0000000000000100
x11: ff80800010093ab0 x10: 0000000000000000 x9 : ffff800010093ab0
x8 : 0000000000000000 x7 : ffff80000fd87314 x6 : 0000000000000000
x5 : 0000000000000000 x4 : 0000000000000001 x3 : 0000000000000000
x2 : ffff0000d930da30 x1 : 0000000000000000 x0 : ffff0000d930da38
Call trace:
__list_del_entry include/linux/list.h:135 [inline]
list_move_tail include/linux/list.h:227 [inline]
fq_pie_qdisc_dequeue+0x29c/0x874 net/sched/sch_fq_pie.c:248
dequeue_skb net/sched/sch_generic.c:292 [inline]
qdisc_restart net/sched/sch_generic.c:397 [inline]
__qdisc_run+0x1ec/0x1fc0 net/sched/sch_generic.c:415
__dev_xmit_skb net/core/dev.c:3879 [inline]
__dev_queue_xmit+0x1068/0x2a6c net/core/dev.c:4190
dev_queue_xmit+0x24/0x34 net/core/dev.c:4258
neigh_connected_output+0x334/0x378 net/core/neighbour.c:1553
neigh_output include/net/neighbour.h:516 [inline]
ip6_finish_output2+0x1344/0x1c48 net/ipv6/ip6_output.c:126
__ip6_finish_output+0x518/0x67c net/ipv6/ip6_output.c:191
ip6_finish_output+0x40/0x218 net/ipv6/ip6_output.c:201
NF_HOOK_COND include/linux/netfilter.h:296 [inline]
ip6_output+0x270/0x594 net/ipv6/ip6_output.c:224
dst_output include/net/dst.h:449 [inline]
NF_HOOK include/linux/netfilter.h:307 [inline]
ndisc_send_skb+0xbf8/0x1788 net/ipv6/ndisc.c:508
ndisc_send_rs+0x494/0x5fc net/ipv6/ndisc.c:702
addrconf_rs_timer+0x308/0x5a8 net/ipv6/addrconf.c:3932
call_timer_fn+0x19c/0x8f0 kernel/time/timer.c:1421
expire_timers kernel/time/timer.c:1466 [inline]
__run_timers+0x554/0x718 kernel/time/timer.c:1737
run_timer_softirq+0x7c/0x114 kernel/time/timer.c:1750
__do_softirq+0x344/0xe20 kernel/softirq.c:558
run_ksoftirqd+0x68/0x258 kernel/softirq.c:920
smpboot_thread_fn+0x4b0/0x920 kernel/smpboot.c:164
kthread+0x37c/0x45c kernel/kthread.c:319
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:870


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the bug is already fixed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to change bug's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the bug is a duplicate of another bug, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Jun 1, 2023, 9:05:01 PM6/1/23
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: d2869ace6eeb Linux 6.1.31
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=12ecf401280000
kernel config: https://syzkaller.appspot.com/x/.config?x=11263f470b7a4c92
dashboard link: https://syzkaller.appspot.com/bug?extid=0fefa64fc8412ca9a00e
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2
userspace arch: arm64

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/b17a7cd87498/disk-d2869ace.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/cc8291ae723a/vmlinux-d2869ace.xz
kernel image: https://storage.googleapis.com/syzbot-assets/04943541fc25/Image-d2869ace.gz.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+0fefa6...@syzkaller.appspotmail.com

watchdog: BUG: soft lockup - CPU#0 stuck for 22s! [syz-executor.2:17341]
Modules linked in:
irq event stamp: 8511
hardirqs last enabled at (8510): [<ffff8000120fb1c0>] __exit_to_kernel_mode arch/arm64/kernel/entry-common.c:84 [inline]
hardirqs last enabled at (8510): [<ffff8000120fb1c0>] exit_to_kernel_mode+0xe8/0x118 arch/arm64/kernel/entry-common.c:94
hardirqs last disabled at (8511): [<ffff8000120f8e9c>] __el1_irq arch/arm64/kernel/entry-common.c:468 [inline]
hardirqs last disabled at (8511): [<ffff8000120f8e9c>] el1_interrupt+0x24/0x68 arch/arm64/kernel/entry-common.c:486
softirqs last enabled at (8): [<ffff800008032bc0>] local_bh_enable+0x10/0x34 include/linux/bottom_half.h:32
softirqs last disabled at (157): [<ffff80000802a994>] ____do_softirq+0x14/0x20 arch/arm64/kernel/irq.c:79
CPU: 0 PID: 17341 Comm: syz-executor.2 Not tainted 6.1.31-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/28/2023
pstate: 00400005 (nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : __list_add include/linux/list.h:73 [inline]
pc : list_add_tail include/linux/list.h:102 [inline]
pc : list_move_tail include/linux/list.h:230 [inline]
pc : fq_pie_qdisc_dequeue+0x3e8/0x8ac net/sched/sch_fq_pie.c:248
lr : __list_add include/linux/list.h:72 [inline]
lr : list_add_tail include/linux/list.h:102 [inline]
lr : list_move_tail include/linux/list.h:230 [inline]
lr : fq_pie_qdisc_dequeue+0x3d4/0x8ac net/sched/sch_fq_pie.c:248
sp : ffff8000080071e0
x29: ffff800008007250 x28: ffff000120499880 x27: ffff00012c7fbae8
x26: ffff00012c7fbaf0 x25: dfff800000000000 x24: ffff00012c7fbae0
x23: ffff000120499870 x22: 0000000000000040 x21: ffff00012c7fbae0
x20: ffff00012c7fbae8 x19: ffff00012c7fbae0 x18: ffff800008006ea0
x17: 0000000000000000 x16: ffff8000084fa384 x15: 0000000000000100
x14: 0000000000000000 x13: 0000000000000001 x12: ffff00011dedb780
x11: ff808000107108d0 x10: 0000000000000000 x9 : ffff8000107108d0
x8 : 0000000000000000 x7 : ffff80000840686c x6 : 0000000000000000
x5 : 0000000000000080 x4 : 0000000000000001 x3 : 0000000000000000
x2 : ffff00012c7fbae0 x1 : ffff00012c7fbae0 x0 : 0000000000000001
Call trace:
__list_add include/linux/list.h:72 [inline]
list_add_tail include/linux/list.h:102 [inline]
list_move_tail include/linux/list.h:230 [inline]
fq_pie_qdisc_dequeue+0x3e8/0x8ac net/sched/sch_fq_pie.c:248
dequeue_skb net/sched/sch_generic.c:292 [inline]
qdisc_restart net/sched/sch_generic.c:397 [inline]
__qdisc_run+0x204/0x239c net/sched/sch_generic.c:415
__dev_xmit_skb net/core/dev.c:3885 [inline]
__dev_queue_xmit+0xe14/0x38d8 net/core/dev.c:4227
dev_queue_xmit include/linux/netdevice.h:3018 [inline]
neigh_connected_output+0x2f8/0x38c net/core/neighbour.c:1612
neigh_output include/net/neighbour.h:546 [inline]
ip6_finish_output2+0xdb4/0x1a98 net/ipv6/ip6_output.c:134
__ip6_finish_output net/ipv6/ip6_output.c:195 [inline]
ip6_finish_output+0x538/0x8c8 net/ipv6/ip6_output.c:206
NF_HOOK_COND include/linux/netfilter.h:291 [inline]
ip6_output+0x270/0x594 net/ipv6/ip6_output.c:227
dst_output include/net/dst.h:444 [inline]
NF_HOOK include/linux/netfilter.h:302 [inline]
ndisc_send_skb+0xc30/0x1790 net/ipv6/ndisc.c:508
ndisc_send_rs+0x47c/0x5d4 net/ipv6/ndisc.c:718
addrconf_rs_timer+0x300/0x58c net/ipv6/addrconf.c:3936
call_timer_fn+0x1c0/0xa1c kernel/time/timer.c:1474
expire_timers kernel/time/timer.c:1519 [inline]
__run_timers+0x554/0x718 kernel/time/timer.c:1790
run_timer_softirq+0x7c/0x114 kernel/time/timer.c:1803
__do_softirq+0x30c/0xea0 kernel/softirq.c:571
____do_softirq+0x14/0x20 arch/arm64/kernel/irq.c:79
call_on_irq_stack+0x24/0x4c arch/arm64/kernel/entry.S:889
do_softirq_own_stack+0x20/0x2c arch/arm64/kernel/irq.c:84
invoke_softirq kernel/softirq.c:452 [inline]
__irq_exit_rcu+0x28c/0x534 kernel/softirq.c:650
irq_exit_rcu+0x14/0x84 kernel/softirq.c:662
__el1_irq arch/arm64/kernel/entry-common.c:472 [inline]
el1_interrupt+0x38/0x68 arch/arm64/kernel/entry-common.c:486
el1h_64_irq_handler+0x18/0x24 arch/arm64/kernel/entry-common.c:491
el1h_64_irq+0x64/0x68 arch/arm64/kernel/entry.S:577
preempt_count arch/arm64/include/asm/preempt.h:13 [inline]
check_kcov_mode kernel/kcov.c:173 [inline]
write_comp_data kernel/kcov.c:236 [inline]
__sanitizer_cov_trace_const_cmp8+0x14/0xa0 kernel/kcov.c:311
unmap_single_vma mm/memory.c:1681 [inline]
unmap_vmas+0x394/0x550 mm/memory.c:1720
exit_mmap+0x1d0/0xa60 mm/mmap.c:3127
__mmput+0xec/0x39c kernel/fork.c:1191
mmput+0x70/0xac kernel/fork.c:1213
exit_mm+0x14c/0x244 kernel/exit.c:563
do_exit+0x4d4/0x1a88 kernel/exit.c:856
do_group_exit+0x194/0x22c kernel/exit.c:1019
get_signal+0x14a0/0x158c kernel/signal.c:2858
do_signal arch/arm64/kernel/signal.c:1076 [inline]
do_notify_resume+0x3ac/0x3470 arch/arm64/kernel/signal.c:1129
prepare_exit_to_user_mode arch/arm64/kernel/entry-common.c:137 [inline]
exit_to_user_mode arch/arm64/kernel/entry-common.c:142 [inline]
el0_svc+0x9c/0x168 arch/arm64/kernel/entry-common.c:638
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:581

syzbot

unread,
Jun 2, 2023, 4:44:55 AM6/2/23
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: d2869ace6eeb Linux 6.1.31
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=157d3d71280000
kernel config: https://syzkaller.appspot.com/x/.config?x=11263f470b7a4c92
dashboard link: https://syzkaller.appspot.com/bug?extid=0fefa64fc8412ca9a00e
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1725602d280000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=131f07ed280000
watchdog: BUG: soft lockup - CPU#0 stuck for 26s! [swapper/0:0]
Modules linked in:
irq event stamp: 199813
hardirqs last enabled at (199812): [<ffff8000120f8ed0>] __el1_irq arch/arm64/kernel/entry-common.c:476 [inline]
hardirqs last enabled at (199812): [<ffff8000120f8ed0>] el1_interrupt+0x58/0x68 arch/arm64/kernel/entry-common.c:486
hardirqs last disabled at (199813): [<ffff8000120f8e9c>] __el1_irq arch/arm64/kernel/entry-common.c:468 [inline]
hardirqs last disabled at (199813): [<ffff8000120f8e9c>] el1_interrupt+0x24/0x68 arch/arm64/kernel/entry-common.c:486
softirqs last enabled at (194418): [<ffff800008020d74>] softirq_handle_end kernel/softirq.c:414 [inline]
softirqs last enabled at (194418): [<ffff800008020d74>] __do_softirq+0xc14/0xea0 kernel/softirq.c:600
softirqs last disabled at (194425): [<ffff80000802a994>] ____do_softirq+0x14/0x20 arch/arm64/kernel/irq.c:79
CPU: 0 PID: 0 Comm: swapper/0 Not tainted 6.1.31-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/28/2023
pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : __list_del_entry_valid+0x2c/0x158 lib/list_debug.c:46
lr : __list_del_entry include/linux/list.h:134 [inline]
lr : list_move_tail include/linux/list.h:229 [inline]
lr : fq_pie_qdisc_dequeue+0x288/0x8ac net/sched/sch_fq_pie.c:248
sp : ffff8000080071b0
x29: ffff8000080071b0 x28: ffff0000deb4c140 x27: ffff0000de7182e8
x26: ffff0000de7182f0 x25: dfff800000000000 x24: ffff0000de7182e0
x23: ffff0000deb4c130 x22: dfff800000000000 x21: 1fffe0001bd69826
x20: 0000000000000000 x19: ffff0000deb4c140 x18: ffff800008006ea0
x17: 0000000000000000 x16: ffff8000084fa7f4 x15: 0000000000000100
x14: 0000000000000000 x13: 0000000000000001 x12: ffff8000155e5040
x11: ff8080001071061c x10: 0000000000000000 x9 : ffff0000de718328
x8 : 0000000000000000 x7 : ffff80000840686c x6 : 0000000000000000
x5 : 0000000000000080 x4 : 0000000000000001 x3 : 0000000000000000
x2 : ffff0000de7182e0 x1 : 0000000000000000 x0 : ffff0000deb4c148
Call trace:
__list_del_entry_valid+0x2c/0x158 lib/list_debug.c:46
__list_del_entry include/linux/list.h:134 [inline]
list_move_tail include/linux/list.h:229 [inline]
fq_pie_qdisc_dequeue+0x288/0x8ac net/sched/sch_fq_pie.c:248
arch_local_irq_enable+0xc/0x18 arch/arm64/include/asm/irqflags.h:35
default_idle_call+0x68/0xdc kernel/sched/idle.c:109
cpuidle_idle_call kernel/sched/idle.c:191 [inline]
do_idle+0x1e0/0x514 kernel/sched/idle.c:303
cpu_startup_entry+0x24/0x28 kernel/sched/idle.c:400
rest_init+0x2d8/0x2f0 init/main.c:729
start_kernel+0x0/0x60c init/main.c:890
start_kernel+0x44c/0x60c init/main.c:1145
__primary_switched+0xb8/0xc0 arch/arm64/kernel/head.S:468


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

syzbot

unread,
Jun 2, 2023, 12:35:57 PM6/2/23
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 0ab06468cbd1 Linux 5.15.114
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1190f095280000
kernel config: https://syzkaller.appspot.com/x/.config?x=9a2696a271d0eba
dashboard link: https://syzkaller.appspot.com/bug?extid=5ae410d749c85c9f54ef
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=114282b5280000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=10520b71280000
watchdog: BUG: soft lockup - CPU#0 stuck for 23s! [swapper/0:0]
Modules linked in:
irq event stamp: 193167
hardirqs last enabled at (193166): [<ffff800011947cac>] exit_el1_irq_or_nmi+0x10/0x1c arch/arm64/kernel/entry-common.c:235
hardirqs last disabled at (193167): [<ffff800011947c90>] enter_el1_irq_or_nmi+0x10/0x1c arch/arm64/kernel/entry-common.c:227
softirqs last enabled at (188674): [<ffff800008020ccc>] softirq_handle_end kernel/softirq.c:401 [inline]
softirqs last enabled at (188674): [<ffff800008020ccc>] __do_softirq+0xb5c/0xe20 kernel/softirq.c:587
softirqs last disabled at (188687): [<ffff8000081b573c>] do_softirq_own_stack include/asm-generic/softirq_stack.h:10 [inline]
softirqs last disabled at (188687): [<ffff8000081b573c>] invoke_softirq kernel/softirq.c:439 [inline]
softirqs last disabled at (188687): [<ffff8000081b573c>] __irq_exit_rcu+0x28c/0x534 kernel/softirq.c:636
CPU: 0 PID: 0 Comm: swapper/0 Not tainted 5.15.114-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/28/2023
pstate: 00400005 (nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : preempt_count arch/arm64/include/asm/preempt.h:12 [inline]
pc : check_kcov_mode kernel/kcov.c:163 [inline]
pc : __sanitizer_cov_trace_pc+0x5c/0xa4 kernel/kcov.c:197
lr : fq_pie_qdisc_dequeue+0xe4/0x874 net/sched/sch_fq_pie.c:240
sp : ffff800008007120
x29: ffff8000080071a0 x28: ffff0000db3a02f0 x27: 1fffe0001b67405c
x26: dfff800000000000 x25: ffff0000ca30b2e8 x24: ffff0000ca30b2f0
x23: ffff0000db3a02e0 x22: ffff0000ca30b2e0 x21: ffff0000ca30b2e0
x20: ffff0000db3a02f8 x19: ffff0000ca30b2e0 x18: 0000000000000502
x17: ff8080000ff4d74c x16: 0000000000000000 x15: ffff80000ff4d74c
x14: 0000000000000001 x13: ffffffffffffffff x12: 0000000000000100
x11: ff80800010093904 x10: 0000000000000100 x9 : ffff800010093904
x8 : ffff8000148f4140 x7 : 0000000000000000 x6 : 0000000000000000
x5 : 0000000000000000 x4 : 0000000000000000 x3 : ffff8000082e91ec
x2 : ffff0000ca30b2e0 x1 : ffff0000ca30b2e0 x0 : 0000000000000001
Call trace:
check_kcov_mode kernel/kcov.c:163 [inline]
__sanitizer_cov_trace_pc+0x5c/0xa4 kernel/kcov.c:197
dequeue_skb net/sched/sch_generic.c:292 [inline]
qdisc_restart net/sched/sch_generic.c:397 [inline]
__qdisc_run+0x1ec/0x1fc0 net/sched/sch_generic.c:415
__dev_xmit_skb net/core/dev.c:3879 [inline]
__dev_queue_xmit+0x1068/0x2a6c net/core/dev.c:4190
dev_queue_xmit+0x24/0x34 net/core/dev.c:4258
neigh_connected_output+0x334/0x378 net/core/neighbour.c:1553
neigh_output include/net/neighbour.h:516 [inline]
ip6_finish_output2+0x1344/0x1c48 net/ipv6/ip6_output.c:126
__ip6_finish_output+0x518/0x67c net/ipv6/ip6_output.c:191
ip6_finish_output+0x40/0x218 net/ipv6/ip6_output.c:201
NF_HOOK_COND include/linux/netfilter.h:296 [inline]
ip6_output+0x270/0x594 net/ipv6/ip6_output.c:224
dst_output include/net/dst.h:449 [inline]
NF_HOOK include/linux/netfilter.h:307 [inline]
ndisc_send_skb+0xbf8/0x1788 net/ipv6/ndisc.c:508
ndisc_send_rs+0x494/0x5fc net/ipv6/ndisc.c:702
addrconf_rs_timer+0x308/0x5a8 net/ipv6/addrconf.c:3932
call_timer_fn+0x19c/0x8f0 kernel/time/timer.c:1421
expire_timers kernel/time/timer.c:1466 [inline]
__run_timers+0x554/0x718 kernel/time/timer.c:1737
run_timer_softirq+0x7c/0x114 kernel/time/timer.c:1750
__do_softirq+0x344/0xe20 kernel/softirq.c:558
do_softirq_own_stack include/asm-generic/softirq_stack.h:10 [inline]
invoke_softirq kernel/softirq.c:439 [inline]
__irq_exit_rcu+0x28c/0x534 kernel/softirq.c:636
irq_exit+0x14/0x88 kernel/softirq.c:660
handle_domain_irq+0xf4/0x178 kernel/irq/irqdesc.c:710
gic_handle_irq+0x78/0x1c8 drivers/irqchip/irq-gic-v3.c:757
call_on_irq_stack+0x24/0x4c arch/arm64/kernel/entry.S:899
do_interrupt_handler+0x74/0x94 arch/arm64/kernel/entry-common.c:267
el1_interrupt+0x30/0x58 arch/arm64/kernel/entry-common.c:442
el1h_64_irq_handler+0x18/0x24 arch/arm64/kernel/entry-common.c:458
el1h_64_irq+0x78/0x7c arch/arm64/kernel/entry.S:580
arch_local_irq_enable+0xc/0x18 arch/arm64/include/asm/irqflags.h:35
default_idle_call+0xcc/0x4a8 kernel/sched/idle.c:112
cpuidle_idle_call kernel/sched/idle.c:194 [inline]
do_idle+0x1d4/0x4dc kernel/sched/idle.c:306
cpu_startup_entry+0x24/0x28 kernel/sched/idle.c:403
rest_init+0x364/0x38c init/main.c:736
arch_call_rest_init+0x14/0x20 init/main.c:889
start_kernel+0x444/0x604 init/main.c:1144
__primary_switched+0xa8/0xb0 arch/arm64/kernel/head.S:468

syzbot

unread,
Jul 30, 2023, 3:40:26 AM7/30/23
to syzkaller...@googlegroups.com
syzbot suspects this issue was fixed by commit:

commit 1d37434ffc1376306167dc61f37f78da18455b74
Author: Eric Dumazet <edum...@google.com>
Date: Fri Jun 2 12:37:47 2023 +0000

net/sched: fq_pie: ensure reasonable TCA_FQ_PIE_QUANTUM values

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=13646541a80000
start commit: 76ba310227d2 Linux 6.1.32
git tree: linux-6.1.y
kernel config: https://syzkaller.appspot.com/x/.config?x=3d054c5c4a3e2d63
dashboard link: https://syzkaller.appspot.com/bug?extid=0fefa64fc8412ca9a00e
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=11583b0d280000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=15411559280000

If the result looks correct, please mark the issue as fixed by replying with:

#syz fix: net/sched: fq_pie: ensure reasonable TCA_FQ_PIE_QUANTUM values

For information about bisection process see: https://goo.gl/tpsmEJ#bisection

syzbot

unread,
Aug 23, 2023, 5:06:36 AM8/23/23
to syzkaller...@googlegroups.com
Auto-closing this bug as obsolete.
No recent activity, existing reproducers are no longer triggering the issue.
Reply all
Reply to author
Forward
0 new messages