Hello,
syzbot found the following crash on:
HEAD commit: 1ec8f1f0 Linux 4.14.111
git tree: linux-4.14.y
console output:
https://syzkaller.appspot.com/x/log.txt?x=1145774b200000
kernel config:
https://syzkaller.appspot.com/x/.config?x=fdadf290ea9fc6f9
dashboard link:
https://syzkaller.appspot.com/bug?extid=5e945d5336866aa7f96b
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
Unfortunately, I don't have any reproducer for this crash yet.
IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by:
syzbot+5e945d...@syzkaller.appspotmail.com
tc_ctl_action: received NO action attribs
hsr_addr_subst_dest: Unknown node
skbuff: bad partial csum: csum=0/65535 len=14
------------[ cut here ]------------
WARNING: CPU: 1 PID: 30739 at net/hsr/hsr_framereg.c:313
hsr_addr_subst_dest.cold+0x45/0x4f net/hsr/hsr_framereg.c:313
Kernel panic - not syncing: panic_on_warn set ...
CPU: 1 PID: 30739 Comm: syz-executor.0 Not tainted 4.14.111 #1
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:17 [inline]
dump_stack+0x138/0x19c lib/dump_stack.c:53
panic+0x1f2/0x438 kernel/panic.c:182
__warn.cold+0x2f/0x34 kernel/panic.c:546
report_bug+0x216/0x254 lib/bug.c:186
fixup_bug arch/x86/kernel/traps.c:177 [inline]
fixup_bug arch/x86/kernel/traps.c:172 [inline]
do_error_trap+0x1bb/0x310 arch/x86/kernel/traps.c:295
do_invalid_op+0x1b/0x20 arch/x86/kernel/traps.c:314
invalid_op+0x1b/0x40 arch/x86/entry/entry_64.S:944
RIP: 0010:hsr_addr_subst_dest.cold+0x45/0x4f net/hsr/hsr_framereg.c:313
RSP: 0018:ffff88806b1ff158 EFLAGS: 00010282
RAX: 0000000000000021 RBX: dffffc0000000000 RCX: 0000000000000000
RDX: 0000000000007fc1 RSI: ffffffff814b2a55 RDI: ffffed100d63fe21
RBP: ffff88806b1ff198 R08: 0000000000000021 R09: ffff8880986d6d60
R10: 0000000000000000 R11: 0000000000000000 R12: ffff8880719a3520
R13: 00000000aaaaaaaa R14: ffff8880719a3520 R15: 000000000000aaaa
hsr_xmit net/hsr/hsr_forward.c:230 [inline]
hsr_forward_do net/hsr/hsr_forward.c:295 [inline]
hsr_forward_skb+0x1025/0x1940 net/hsr/hsr_forward.c:373
hsr_dev_xmit+0x72/0xa0 net/hsr/hsr_device.c:242
__netdev_start_xmit include/linux/netdevice.h:4033 [inline]
netdev_start_xmit include/linux/netdevice.h:4042 [inline]
xmit_one net/core/dev.c:3009 [inline]
dev_hard_start_xmit+0x191/0x8c0 net/core/dev.c:3025
__dev_queue_xmit+0x1da3/0x25f0 net/core/dev.c:3525
dev_queue_xmit+0x18/0x20 net/core/dev.c:3558
br_dev_queue_push_xmit+0x367/0x530 net/bridge/br_forward.c:55
NF_HOOK include/linux/netfilter.h:250 [inline]
NF_HOOK include/linux/netfilter.h:244 [inline]
br_forward_finish+0xbc/0x320 net/bridge/br_forward.c:67
NF_HOOK include/linux/netfilter.h:250 [inline]
NF_HOOK include/linux/netfilter.h:244 [inline]
__br_forward+0x560/0x9c0 net/bridge/br_forward.c:111
deliver_clone+0x61/0xc0 net/bridge/br_forward.c:127
maybe_deliver net/bridge/br_forward.c:168 [inline]
maybe_deliver net/bridge/br_forward.c:156 [inline]
br_flood+0x3c8/0x530 net/bridge/br_forward.c:210
br_dev_xmit+0x8dc/0xd50 net/bridge/br_device.c:87
__netdev_start_xmit include/linux/netdevice.h:4033 [inline]
netdev_start_xmit include/linux/netdevice.h:4042 [inline]
xmit_one net/core/dev.c:3009 [inline]
dev_hard_start_xmit+0x191/0x8c0 net/core/dev.c:3025
__dev_queue_xmit+0x1da3/0x25f0 net/core/dev.c:3525
dev_queue_xmit+0x18/0x20 net/core/dev.c:3558
pppoe_sendmsg+0x5cf/0x730 drivers/net/ppp/pppoe.c:906
sock_sendmsg_nosec net/socket.c:646 [inline]
sock_sendmsg+0xd0/0x110 net/socket.c:656
___sys_sendmsg+0x349/0x850 net/socket.c:2062
__sys_sendmmsg+0x152/0x3a0 net/socket.c:2152
SYSC_sendmmsg net/socket.c:2183 [inline]
SyS_sendmmsg+0x35/0x60 net/socket.c:2178
do_syscall_64+0x1eb/0x630 arch/x86/entry/common.c:289
entry_SYSCALL_64_after_hwframe+0x42/0xb7
RIP: 0033:0x458c29
RSP: 002b:00007f3a34cefc78 EFLAGS: 00000246 ORIG_RAX: 0000000000000133
RAX: ffffffffffffffda RBX: 0000000000000004 RCX: 0000000000458c29
RDX: 04000000000000eb RSI: 000000002000d180 RDI: 0000000000000005
kobject: 'loop4' (ffff8880a4a782a0): kobject_uevent_env
RBP: 000000000073bf00 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 00007f3a34cf06d4
R13: 00000000004c5e19 R14: 00000000004da5e0 R15: 00000000ffffffff
Kernel Offset: disabled
Rebooting in 86400 seconds..
---
This bug is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.