[v6.1] WARNING in ieee80211_ibss_csa_beacon

0 views
Skip to first unread message

syzbot

unread,
Mar 7, 2023, 11:59:39 PM3/7/23
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 42616e0f09fb Linux 6.1.15
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=11c45eeac80000
kernel config: https://syzkaller.appspot.com/x/.config?x=690b9ff41783cd73
dashboard link: https://syzkaller.appspot.com/bug?extid=f6fcdbe4e623ba6cde16
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/db869f2ed2bd/disk-42616e0f.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/37951bbe5829/vmlinux-42616e0f.xz
kernel image: https://storage.googleapis.com/syzbot-assets/23aa1a75ce0f/bzImage-42616e0f.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+f6fcdb...@syzkaller.appspotmail.com

WARNING: CPU: 1 PID: 3831 at net/mac80211/ibss.c:500 ieee80211_ibss_csa_beacon+0x500/0x5b0
Modules linked in:
CPU: 1 PID: 3831 Comm: kworker/u4:8 Not tainted 6.1.15-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/02/2023
Workqueue: phy30 ieee80211_csa_finalize_work
RIP: 0010:ieee80211_ibss_csa_beacon+0x500/0x5b0 net/mac80211/ibss.c:500
Code: f7 c6 05 af 50 3f 04 01 48 c7 c7 30 cc fb 8b be fd 01 00 00 48 c7 c2 c0 cc fb 8b e8 1a 42 6b f7 e9 6a fe ff ff e8 00 f1 8a f7 <0f> 0b b8 ea ff ff ff e9 7a ff ff ff e8 ef f0 8a f7 0f 0b e9 68 fb
RSP: 0018:ffffc90004777b60 EFLAGS: 00010293
RAX: ffffffff89ff3920 RBX: ffff88807c879ae0 RCX: ffff888027e19d40
RDX: 0000000000000000 RSI: ffffffff8aebcf60 RDI: ffffffff8b3d0400
RBP: ffff88804458b838 R08: dffffc0000000000 R09: fffffbfff202ea48
R10: 0000000000000000 R11: dffffc0000000001 R12: ffff88807c879ac0
R13: ffff8880445886c0 R14: ffff88807c878c80 R15: ffff88807c879aba
FS: 0000000000000000(0000) GS:ffff8880b9a00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000001b30d33000 CR3: 00000000181d8000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
ieee80211_set_after_csa_beacon net/mac80211/cfg.c:3486 [inline]
__ieee80211_csa_finalize net/mac80211/cfg.c:3542 [inline]
ieee80211_csa_finalize+0x4c3/0xd10 net/mac80211/cfg.c:3565
ieee80211_csa_finalize_work+0xf8/0x140 net/mac80211/cfg.c:3590
process_one_work+0x8ee/0x1350 kernel/workqueue.c:2289
worker_thread+0xa5f/0x1210 kernel/workqueue.c:2436
kthread+0x268/0x300 kernel/kthread.c:376
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:306
</TASK>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Mar 9, 2023, 2:07:40 AM3/9/23
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: d9b4a0c83a2d Linux 5.15.98
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=124c56a2c80000
kernel config: https://syzkaller.appspot.com/x/.config?x=b57cfa804330c3b7
dashboard link: https://syzkaller.appspot.com/bug?extid=f2c2d48314c03db2596d
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2
userspace arch: arm64

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/8088989394e3/disk-d9b4a0c8.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/2651d6753959/vmlinux-d9b4a0c8.xz
kernel image: https://storage.googleapis.com/syzbot-assets/f3fa3f994f9a/Image-d9b4a0c8.gz.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+f2c2d4...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 0 PID: 1602 at net/mac80211/ibss.c:503 ieee80211_ibss_csa_beacon+0x498/0x530
Modules linked in:
CPU: 0 PID: 1602 Comm: kworker/u4:6 Not tainted 5.15.98-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/02/2023
Workqueue: phy14 ieee80211_iface_work
pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : ieee80211_ibss_csa_beacon+0x498/0x530
lr : ieee80211_ibss_csa_beacon+0x494/0x530 net/mac80211/ibss.c:503
sp : ffff800020de7360
x29: ffff800020de7380 x28: 1fffe0002053f251 x27: dfff800000000000
x26: 0000000000000000 x25: ffff000102a585c0 x24: 0000000000000000
x23: ffff0001029f9288 x22: ffff0001029f9b18 x21: 0000000000000002
x20: ffff0001029f8c80 x19: ffff800020de7620 x18: 0000000000000201
x17: ff8080001116b53c x16: ffff8000084c28f4 x15: ffff80001116b53c
x14: 0000000000000003 x13: ffffffffffffffff x12: 0000000000040000
x11: 0000000000001a4e x10: ffff800025046000 x9 : ffff80001131d700
x8 : 0000000000001a4f x7 : 0000000000000000 x6 : 0000000000000000
x5 : 0000000000000020 x4 : 0000000000000000 x3 : ffff800008046698
x2 : 0000000000000006 x1 : ffff800011acb5e0 x0 : 00000000ffffffea
Call trace:
ieee80211_ibss_csa_beacon+0x498/0x530
ieee80211_set_csa_beacon net/mac80211/cfg.c:3374 [inline]
__ieee80211_channel_switch net/mac80211/cfg.c:3504 [inline]
ieee80211_channel_switch+0x1264/0x21f4 net/mac80211/cfg.c:3542
ieee80211_ibss_process_chanswitch+0x9ec/0xd60 net/mac80211/ibss.c:892
ieee80211_rx_mgmt_spectrum_mgmt net/mac80211/ibss.c:931 [inline]
ieee80211_ibss_rx_queued_mgmt+0xf60/0x26d0 net/mac80211/ibss.c:1667
ieee80211_iface_process_skb net/mac80211/iface.c:1441 [inline]
ieee80211_iface_work+0x5b4/0xa80 net/mac80211/iface.c:1495
process_one_work+0x82c/0x1478 kernel/workqueue.c:2306
worker_thread+0x910/0x1034 kernel/workqueue.c:2453
kthread+0x37c/0x45c kernel/kthread.c:319
ret_from_fork+0x10/0x20 <unknown>:870
irq event stamp: 14544032
hardirqs last enabled at (14544031): [<ffff8000081b7c94>] __local_bh_enable_ip+0x258/0x4d0 kernel/softirq.c:388
hardirqs last disabled at (14544032): [<ffff800011976650>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:387
softirqs last enabled at (14544030): [<ffff80001116b9e8>] spin_unlock_bh include/linux/spinlock.h:408 [inline]
softirqs last enabled at (14544030): [<ffff80001116b9e8>] cfg80211_get_bss+0x7a8/0xc28 net/wireless/scan.c:1473
softirqs last disabled at (14544028): [<ffff80001116b428>] spin_lock_bh include/linux/spinlock.h:368 [inline]
softirqs last disabled at (14544028): [<ffff80001116b428>] cfg80211_get_bss+0x1e8/0xc28 net/wireless/scan.c:1447
---[ end trace 70ad25f1bf94ab9d ]---
wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50
wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50
Reply all
Reply to author
Forward
0 new messages