[v5.15] WARNING in ath6kl_htc_pipe_rx_complete

0 views
Skip to first unread message

syzbot

unread,
Apr 30, 2023, 7:00:40 AM4/30/23
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: f48aeeaaa64c Linux 5.15.109
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=168e6ef8280000
kernel config: https://syzkaller.appspot.com/x/.config?x=f0ea19992afd55ad
dashboard link: https://syzkaller.appspot.com/bug?extid=8781e4be59f679116773
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/fd82b060cee7/disk-f48aeeaa.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/b216234bd1a0/vmlinux-f48aeeaa.xz
kernel image: https://storage.googleapis.com/syzbot-assets/c0609f7a6703/bzImage-f48aeeaa.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+8781e4...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 0 PID: 13 at drivers/net/wireless/ath/ath6kl/htc_pipe.c:963 ath6kl_htc_pipe_rx_complete+0xd6f/0xf60
Modules linked in:
CPU: 0 PID: 13 Comm: kworker/0:1 Not tainted 5.15.109-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/14/2023
Workqueue: events ath6kl_usb_io_comp_work
RIP: 0010:ath6kl_htc_pipe_rx_complete+0xd6f/0xf60 drivers/net/wireless/ath/ath6kl/htc_pipe.c:963
Code: 04 25 28 00 00 00 48 3b 84 24 00 01 00 00 0f 85 00 02 00 00 89 d8 48 8d 65 d8 5b 41 5c 41 5d 41 5e 41 5f 5d c3 e8 71 b5 bd fb <0f> 0b 48 c7 c7 c0 86 16 8b e8 f3 52 fe ff bb ea ff ff ff eb a0 89
RSP: 0018:ffffc90000d27aa0 EFLAGS: 00010293
RAX: ffffffff85c2290f RBX: ffff8880944d0e10 RCX: ffff88813fe20000
RDX: 0000000000000000 RSI: ffff8880764e5780 RDI: ffff8880944d0da0
RBP: ffffc90000d27bf8 R08: ffffffff85c7ee73 R09: fffffbfff1f78e5c
R10: 0000000000000000 R11: dffffc0000000001 R12: 1ffff11012ba8518
R13: 1ffff920001a4f6c R14: 0000000000000000 R15: dffffc0000000000
FS: 0000000000000000(0000) GS:ffff8880b9a00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00000000200014f8 CR3: 000000008ec14000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
ath6kl_usb_io_comp_work+0xf9/0x190 drivers/net/wireless/ath/ath6kl/usb.c:603
process_one_work+0x8a1/0x10c0 kernel/workqueue.c:2306
worker_thread+0xaca/0x1280 kernel/workqueue.c:2453
kthread+0x3f6/0x4f0 kernel/kthread.c:319
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:298
</TASK>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the bug is already fixed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to change bug's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the bug is a duplicate of another bug, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Apr 30, 2023, 7:16:45 AM4/30/23
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: f48aeeaaa64c Linux 5.15.109
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1326377fc80000
kernel config: https://syzkaller.appspot.com/x/.config?x=f0ea19992afd55ad
dashboard link: https://syzkaller.appspot.com/bug?extid=8781e4be59f679116773
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=13e92b1c280000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=17474ad8280000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/fd82b060cee7/disk-f48aeeaa.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/b216234bd1a0/vmlinux-f48aeeaa.xz
kernel image: https://storage.googleapis.com/syzbot-assets/c0609f7a6703/bzImage-f48aeeaa.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+8781e4...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 0 PID: 13 at drivers/net/wireless/ath/ath6kl/htc_pipe.c:963 ath6kl_htc_pipe_rx_complete+0xd6f/0xf60
Modules linked in:
CPU: 0 PID: 13 Comm: kworker/0:1 Not tainted 5.15.109-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/14/2023
Workqueue: events ath6kl_usb_io_comp_work
RIP: 0010:ath6kl_htc_pipe_rx_complete+0xd6f/0xf60 drivers/net/wireless/ath/ath6kl/htc_pipe.c:963
Code: 04 25 28 00 00 00 48 3b 84 24 00 01 00 00 0f 85 00 02 00 00 89 d8 48 8d 65 d8 5b 41 5c 41 5d 41 5e 41 5f 5d c3 e8 71 b5 bd fb <0f> 0b 48 c7 c7 c0 86 16 8b e8 f3 52 fe ff bb ea ff ff ff eb a0 89
RSP: 0018:ffffc90000d27aa0 EFLAGS: 00010293
RAX: ffffffff85c2290f RBX: ffff88807c530e10 RCX: ffff88813fe20000
RDX: 0000000000000000 RSI: ffff888023cab500 RDI: ffff88807c530da0
RBP: ffffc90000d27bf8 R08: ffffffff85c7ee73 R09: fffffbfff1f78e3a
R10: 0000000000000000 R11: dffffc0000000001 R12: 1ffff1100f11c118
R13: 1ffff920001a4f6c R14: 0000000000000000 R15: dffffc0000000000
FS: 0000000000000000(0000) GS:ffff8880b9a00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00000000200014f8 CR3: 000000001efee000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

syzbot

unread,
Apr 30, 2023, 2:44:51 PM4/30/23
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: ca1c9012c941 Linux 6.1.26
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=10d81d40280000
kernel config: https://syzkaller.appspot.com/x/.config?x=f95cba4715d63af9
dashboard link: https://syzkaller.appspot.com/bug?extid=466f488371fea3a64c73
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=11f21008280000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=13671b84280000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/b6b74e769ec1/disk-ca1c9012.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/31fce9ce6f18/vmlinux-ca1c9012.xz
kernel image: https://storage.googleapis.com/syzbot-assets/cd73b5bb5ef4/Image-ca1c9012.gz.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+466f48...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 0 PID: 14 at drivers/net/wireless/ath/ath6kl/htc_pipe.c:963 ath6kl_htc_pipe_rx_complete+0xae0/0xc78 drivers/net/wireless/ath/ath6kl/htc_pipe.c:964
Modules linked in:
CPU: 0 PID: 14 Comm: kworker/0:1 Not tainted 6.1.26-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/30/2023
Workqueue: ath6kl_wq ath6kl_usb_io_comp_work
pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : ath6kl_htc_pipe_rx_complete+0xae0/0xc78 drivers/net/wireless/ath/ath6kl/htc_pipe.c:964
lr : ath6kl_htc_pipe_rx_complete+0xad8/0xc78 drivers/net/wireless/ath/ath6kl/htc_pipe.c:963
sp : ffff800019ba7940
x29: ffff800019ba7a50 x28: 1fffe0001bc88594 x27: 1fffe0001bc88518
x26: dfff800000000000 x25: ffff0000c45efdc0 x24: ffff0000d5940e00
x23: 1ffff00003374f3c x22: ffff800013441930 x21: ffff0000d5940e00
x20: 0000000000000000 x19: dfff800000000000 x18: ffff800019ba7780
x17: ffff80001558d000 x16: ffff80000825e194 x15: 000000000000b652
x14: 000000001b127eb8 x13: dfff800000000000 x12: 0000000000000003
x11: ff8080000d58dc88 x10: 0000000000000000 x9 : ffff80000d58dc88
x8 : ffff0000c09a1b40 x7 : 0000000000000000 x6 : 0000000000000000
x5 : ffff800018736e70 x4 : 0000000000000000 x3 : 0000000000000000
x2 : 0000000000000005 x1 : ffff0000c45efdc0 x0 : ffff800013441ca0
Call trace:
ath6kl_htc_pipe_rx_complete+0xae0/0xc78 drivers/net/wireless/ath/ath6kl/htc_pipe.c:964
ath6kl_htc_rx_complete drivers/net/wireless/ath/ath6kl/htc-ops.h:109 [inline]
ath6kl_core_rx_complete+0x78/0x90 drivers/net/wireless/ath/ath6kl/core.c:62
ath6kl_usb_io_comp_work+0xe0/0x160 drivers/net/wireless/ath/ath6kl/usb.c:604
process_one_work+0x7ac/0x1404 kernel/workqueue.c:2289
worker_thread+0x8e4/0xfec kernel/workqueue.c:2436
kthread+0x250/0x2d8 kernel/kthread.c:376
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:860
irq event stamp: 50238
hardirqs last enabled at (50237): [<ffff8000121bef3c>] __raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:151 [inline]
hardirqs last enabled at (50237): [<ffff8000121bef3c>] _raw_spin_unlock_irqrestore+0x48/0xac kernel/locking/spinlock.c:194
hardirqs last disabled at (50238): [<ffff8000120dc90c>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:405
softirqs last enabled at (3652): [<ffff80000839169c>] local_bh_enable+0xc/0x2c include/linux/bottom_half.h:32
softirqs last disabled at (3648): [<ffff800008391670>] local_bh_disable+0xc/0x2c include/linux/bottom_half.h:19
---[ end trace 0000000000000000 ]---
ath6kl: Target not yet initialized


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the bug is already fixed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

syzbot

unread,
May 31, 2023, 10:04:25 PM5/31/23
to syzkaller...@googlegroups.com
syzbot suspects this issue was fixed by commit:

commit 644df7e865e76ab7a62c67c25cbbc093c944d0ef
Author: Fedor Pchelkin <pche...@ispras.ru>
Date: Fri Feb 24 10:28:05 2023 +0000

wifi: ath6kl: reduce WARN to dev_dbg() in callback

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=1350f07d280000
start commit: ca1c9012c941 Linux 6.1.26
git tree: linux-6.1.y
If the result looks correct, please mark the issue as fixed by replying with:

#syz fix: wifi: ath6kl: reduce WARN to dev_dbg() in callback

For information about bisection process see: https://goo.gl/tpsmEJ#bisection

syzbot

unread,
Aug 23, 2023, 5:08:34 AM8/23/23
to syzkaller...@googlegroups.com
Auto-closing this bug as obsolete.
No recent activity, existing reproducers are no longer triggering the issue.
Reply all
Reply to author
Forward
0 new messages