invalid opcode in rxrpc_disconnect_client_call

4 views
Skip to first unread message

syzbot

unread,
Jun 24, 2020, 4:59:19 PM6/24/20
to syzkaller...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: b850307b Linux 4.14.184
git tree: linux-4.14.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1474c8c5100000
kernel config: https://syzkaller.appspot.com/x/.config?x=ddc0f08dd6b981c5
dashboard link: https://syzkaller.appspot.com/bug?extid=0253e5416b33ecd3b5fb
compiler: gcc (GCC) 9.0.0 20181231 (experimental)

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+0253e5...@syzkaller.appspotmail.com

invalid opcode: 0000 [#1] PREEMPT SMP KASAN
Modules linked in:
CPU: 1 PID: 4799 Comm: syz-executor.2 Not tainted 4.14.184-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
task: ffff8880636d0400 task.stack: ffff88803f860000
RIP: 0010:rxrpc_disconnect_client_call.cold+0x78/0x7a net/rxrpc/conn_client.c:792
RSP: 0018:ffff88803f867720 EFLAGS: 00010286
RAX: 0000000000000077 RBX: ffff888066720140 RCX: 0000000000000000
RDX: 00000000000008b8 RSI: ffffffff81499420 RDI: ffffed1007f0ceda
RBP: ffff8880853f0040 R08: 0000000000000077 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000000
R13: ffff8880853f0090 R14: ffff888063859c00 R15: ffff8880853f00e0
FS: 00007f4361934700(0000) GS:ffff8880aed00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000000c0101cc087 CR3: 0000000057164000 CR4: 00000000001426e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
rxrpc_connect_call+0x1fa0/0x3e50 net/rxrpc/conn_client.c:701
rxrpc_new_client_call+0x8d3/0x1400 net/rxrpc/call_object.c:276
rxrpc_new_client_call_for_sendmsg net/rxrpc/sendmsg.c:525 [inline]
rxrpc_do_sendmsg+0x8a1/0x1023 net/rxrpc/sendmsg.c:577
rxrpc_sendmsg+0x47d/0x5a0 net/rxrpc/af_rxrpc.c:543
sock_sendmsg_nosec net/socket.c:646 [inline]
sock_sendmsg+0xb5/0x100 net/socket.c:656
___sys_sendmsg+0x349/0x840 net/socket.c:2062
__sys_sendmmsg+0x129/0x330 net/socket.c:2152
SYSC_sendmmsg net/socket.c:2183 [inline]
SyS_sendmmsg+0x2f/0x50 net/socket.c:2178
do_syscall_64+0x1d5/0x640 arch/x86/entry/common.c:292
entry_SYSCALL_64_after_hwframe+0x46/0xbb
RIP: 0033:0x45cb09
RSP: 002b:00007f4361933c78 EFLAGS: 00000246 ORIG_RAX: 0000000000000133
RAX: ffffffffffffffda RBX: 00000000004fd620 RCX: 000000000045cb09
RDX: 0000000000000001 RSI: 0000000020005c00 RDI: 0000000000000003
RBP: 000000000078c0e0 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 00000000ffffffff
R13: 0000000000000901 R14: 00000000004cbdc5 R15: 00007f43619346d4
Code: 0f 0b 48 89 34 24 e8 2a 6f a2 fb 48 8b 34 24 4d 89 f1 4d 89 f0 48 c7 c1 40 26 26 87 48 c7 c7 80 26 26 87 48 89 f2 e8 95 4d 91 fb <0f> 0b e8 03 6f a2 fb 44 89 f6 45 31 c9 45 31 c0 48 c7 c1 40 26
RIP: rxrpc_disconnect_client_call.cold+0x78/0x7a net/rxrpc/conn_client.c:792 RSP: ffff88803f867720
---[ end trace b62e97b2b4d0d5f4 ]---


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Oct 22, 2020, 4:59:10 PM10/22/20
to syzkaller...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages