WARNING in task_participate_group_stop

14 views
Skip to first unread message

syzbot

unread,
Dec 2, 2019, 8:46:08 AM12/2/19
to syzkaller...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 174651bd Linux 4.19.87
git tree: linux-4.19.y
console output: https://syzkaller.appspot.com/x/log.txt?x=11056196e00000
kernel config: https://syzkaller.appspot.com/x/.config?x=f5916f9ec2ab339c
dashboard link: https://syzkaller.appspot.com/bug?extid=51c9c4fb88f389de5869
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=12def482e00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+51c9c4...@syzkaller.appspotmail.com

IPv6: ADDRCONF(NETDEV_CHANGE): vxcan1: link becomes ready
IPv6: ADDRCONF(NETDEV_CHANGE): vxcan0: link becomes ready
8021q: adding VLAN 0 to HW filter on device batadv0
WARNING: CPU: 0 PID: 8149 at kernel/signal.c:367
task_participate_group_stop+0x204/0x250 kernel/signal.c:367
Kernel panic - not syncing: panic_on_warn set ...

CPU: 0 PID: 8149 Comm: 3 Not tainted 4.19.87-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x197/0x210 lib/dump_stack.c:118
panic+0x26a/0x50e kernel/panic.c:186
__warn.cold+0x20/0x53 kernel/panic.c:541
report_bug+0x263/0x2b0 lib/bug.c:186
fixup_bug arch/x86/kernel/traps.c:178 [inline]
fixup_bug arch/x86/kernel/traps.c:173 [inline]
do_error_trap+0x204/0x360 arch/x86/kernel/traps.c:296
do_invalid_op+0x1b/0x20 arch/x86/kernel/traps.c:316
invalid_op+0x14/0x20 arch/x86/entry/entry_64.S:1037
RIP: 0010:task_participate_group_stop+0x204/0x250 kernel/signal.c:367
kobject: 'loop5' (00000000c1538efd): kobject_uevent_env
Code: d0 7c 04 84 d2 75 58 41 89 9d a4 00 00 00 41 bc 01 00 00 00 e9 55 ff
ff ff e8 48 1a 29 00 0f 0b e9 8d fe ff ff e8 3c 1a 29 00 <0f> 0b e9 fa fe
ff ff 4c 89 e7 e8 5d a7 60 00 e9 c6 fe ff ff e8 73
RSP: 0018:ffff8880a8497b98 EFLAGS: 00010093
RAX: ffff8880a8da2200 RBX: 0000000000000000 RCX: ffffffff8141f8ee
kobject: 'loop5' (00000000c1538efd): fill_kobj_path: path
= '/devices/virtual/block/loop5'
RDX: 0000000000000000 RSI: ffffffff8141fa04 RDI: 0000000000000005
RBP: ffff8880a8497bb8 R08: ffff8880a8da2200 R09: ffffed1012515d0a
R10: ffffed1012515d09 R11: ffff8880928ae84b R12: ffff88807fcee760
R13: ffff88807fcee6c0 R14: 0000000000040000 R15: ffff8880a8da2200
do_signal_stop+0x1e6/0x840 kernel/signal.c:2266
get_signal+0xf56/0x1fc0 kernel/signal.c:2453
do_signal+0x95/0x1960 arch/x86/kernel/signal.c:821
exit_to_usermode_loop+0x244/0x2c0 arch/x86/entry/common.c:163
prepare_exit_to_usermode arch/x86/entry/common.c:198 [inline]
syscall_return_slowpath arch/x86/entry/common.c:271 [inline]
do_syscall_64+0x53d/0x620 arch/x86/entry/common.c:296
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x324
Code: Bad RIP value.
RSP: 002b:00007ffe73f76220 EFLAGS: 00000200 ORIG_RAX: 000000000000003b
RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000000
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000000
R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000
Kernel Offset: disabled
Rebooting in 86400 seconds..


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this bug, for details see:
https://goo.gl/tpsmEJ#testing-patches

syzbot

unread,
Dec 2, 2019, 9:36:07 AM12/2/19
to syzkaller...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: fbc5fe7a Linux 4.14.157
git tree: linux-4.14.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1249a01ee00000
kernel config: https://syzkaller.appspot.com/x/.config?x=19f929d1ebe2b2d8
dashboard link: https://syzkaller.appspot.com/bug?extid=8938286497acfbea0a8d
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=17595482e00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+893828...@syzkaller.appspotmail.com

IPv6: ADDRCONF(NETDEV_CHANGE): vxcan1: link becomes ready
IPv6: ADDRCONF(NETDEV_CHANGE): bond0: link becomes ready
8021q: adding VLAN 0 to HW filter on device batadv0
------------[ cut here ]------------
WARNING: CPU: 0 PID: 8321 at kernel/signal.c:353
task_participate_group_stop+0x1cc/0x230 kernel/signal.c:353
Kernel panic - not syncing: panic_on_warn set ...

CPU: 0 PID: 8321 Comm: 3 Not tainted 4.14.157-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:17 [inline]
dump_stack+0x142/0x197 lib/dump_stack.c:58
panic+0x1f9/0x42d kernel/panic.c:183
__warn.cold+0x2f/0x2f kernel/panic.c:547
report_bug+0x216/0x254 lib/bug.c:186
fixup_bug arch/x86/kernel/traps.c:177 [inline]
fixup_bug arch/x86/kernel/traps.c:172 [inline]
do_error_trap+0x1bb/0x310 arch/x86/kernel/traps.c:295
do_invalid_op+0x1b/0x20 arch/x86/kernel/traps.c:314
invalid_op+0x1b/0x40 arch/x86/entry/entry_64.S:963
RIP: 0010:task_participate_group_stop+0x1cc/0x230 kernel/signal.c:353
RSP: 0018:ffff888098f5fba8 EFLAGS: 00010097
RAX: ffff888095eb66c0 RBX: ffff8880919da640 RCX: ffff8880919da6dc
RDX: 0000000000000000 RSI: 0000000000020000 RDI: ffff888095eb66c0
RBP: ffff888098f5fbc0 R08: 0000000000005aab R09: ffffffff8936bed8
R10: ffff888095eb6f40 R11: ffff888095eb66c0 R12: 0000000000000000
R13: ffff8880919da6d8 R14: ffff888098f5ff58 R15: dffffc0000000000
do_signal_stop+0x19f/0x750 kernel/signal.c:2102
get_signal+0xd28/0x1cd0 kernel/signal.c:2288
do_signal+0x86/0x19a0 arch/x86/kernel/signal.c:814
exit_to_usermode_loop+0x15c/0x220 arch/x86/entry/common.c:160
prepare_exit_to_usermode arch/x86/entry/common.c:199 [inline]
syscall_return_slowpath arch/x86/entry/common.c:270 [inline]
do_syscall_64+0x4bc/0x640 arch/x86/entry/common.c:297
entry_SYSCALL_64_after_hwframe+0x42/0xb7
RIP: 0033:0x324
RSP: 002b:00007ffdb3c7b8f0 EFLAGS: 00000200 ORIG_RAX: 000000000000003b

syzbot

unread,
Mar 29, 2020, 2:13:13 AM3/29/20
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 54b4fa6d Linux 4.19.113
git tree: linux-4.19.y
console output: https://syzkaller.appspot.com/x/log.txt?x=13929c97e00000
kernel config: https://syzkaller.appspot.com/x/.config?x=7b1a0bc5526ebc49
dashboard link: https://syzkaller.appspot.com/bug?extid=51c9c4fb88f389de5869
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=10ebcacbe00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=12f7746de00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+51c9c4...@syzkaller.appspotmail.com

WARNING: CPU: 1 PID: 8624 at kernel/signal.c:372 task_participate_group_stop+0x20a/0x260 kernel/signal.c:372
Kernel panic - not syncing: panic_on_warn set ...

CPU: 1 PID: 8624 Comm: file0 Not tainted 4.19.113-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x188/0x20d lib/dump_stack.c:118
panic+0x26a/0x50e kernel/panic.c:186
__warn.cold+0x20/0x46 kernel/panic.c:541
report_bug+0x262/0x2a0 lib/bug.c:186
fixup_bug arch/x86/kernel/traps.c:178 [inline]
fixup_bug arch/x86/kernel/traps.c:173 [inline]
do_error_trap+0x1d7/0x310 arch/x86/kernel/traps.c:296
invalid_op+0x14/0x20 arch/x86/entry/entry_64.S:1037
RIP: 0010:task_participate_group_stop+0x20a/0x260 kernel/signal.c:372
Code: a4 00 00 00 41 bc 01 00 00 00 e8 c1 b4 27 00 44 89 e0 5b 5d 41 5c 41 5d c3 e8 b2 b4 27 00 0f 0b e9 7e fe ff ff e8 a6 b4 27 00 <0f> 0b e9 ee fe ff ff 48 89 ef e8 f7 7f 5d 00 e9 b8 fe ff ff e8 fd
RSP: 0018:ffff8880986b7bd8 EFLAGS: 00010093
RAX: ffff8880896541c0 RBX: 0000000000000000 RCX: ffffffff813fecd7
RDX: 0000000000000000 RSI: ffffffff813fedfa RDI: 0000000000000005
RBP: ffff88809e7677e0 R08: ffff8880896541c0 R09: ffffed1015218562
R10: ffffed1015218561 R11: ffff8880a90c2b0b R12: ffff88809e767740
R13: 0000000000040000 R14: ffff8880986b7f58 R15: dffffc0000000000
do_signal_stop+0x1df/0x840 kernel/signal.c:2276
get_signal+0xf3c/0x1f90 kernel/signal.c:2463
do_signal+0x8f/0x1710 arch/x86/kernel/signal.c:821
exit_to_usermode_loop+0x22b/0x2b0 arch/x86/entry/common.c:163
prepare_exit_to_usermode arch/x86/entry/common.c:198 [inline]
syscall_return_slowpath arch/x86/entry/common.c:271 [inline]
do_syscall_64+0x538/0x620 arch/x86/entry/common.c:296
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x447c79
Code: Bad RIP value.
RSP: 002b:00007fd68748fd98 EFLAGS: 00000246 ORIG_RAX: 000000000000000b
RAX: ffffffffffffffea RBX: 00000000006e39f8 RCX: 0000000000447c79
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 00000000200000c0
RBP: 00000000006e39f0 R08: 00007fd687490700 R09: 0000000000000000
R10: 00007fd687490700 R11: 0000000000000246 R12: 00000000006e39fc
R13: 0000000000000000 R14: 07007ff8464c457f R15: 000000000000f172

syzbot

unread,
Apr 10, 2020, 12:59:14 PM4/10/20
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 4520f06b Linux 4.14.175
git tree: linux-4.14.y
console output: https://syzkaller.appspot.com/x/log.txt?x=16e18c7de00000
kernel config: https://syzkaller.appspot.com/x/.config?x=93cf891381c0c347
dashboard link: https://syzkaller.appspot.com/bug?extid=8938286497acfbea0a8d
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=17a34007e00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=14d0bdb3e00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+893828...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 0 PID: 6332 at kernel/signal.c:358 task_participate_group_stop+0x1b3/0x210 kernel/signal.c:358
Kernel panic - not syncing: panic_on_warn set ...

CPU: 0 PID: 6332 Comm: file0 Not tainted 4.14.175-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:17 [inline]
dump_stack+0x13e/0x194 lib/dump_stack.c:58
panic+0x1f9/0x42d kernel/panic.c:183
__warn.cold+0x2f/0x30 kernel/panic.c:547
report_bug+0x20a/0x248 lib/bug.c:186
fixup_bug arch/x86/kernel/traps.c:177 [inline]
fixup_bug arch/x86/kernel/traps.c:172 [inline]
do_error_trap+0x195/0x2d0 arch/x86/kernel/traps.c:295
invalid_op+0x1b/0x40 arch/x86/entry/entry_64.S:963
RIP: 0010:task_participate_group_stop+0x1b3/0x210 kernel/signal.c:358
RSP: 0018:ffff88808f8cfbe0 EFLAGS: 00010097
RAX: ffff888097cde680 RBX: ffff8880a7a76e00 RCX: ffff8880a7a76e9c
RDX: 0000000000000000 RSI: 0000000000020000 RDI: ffff888097cde680
RBP: 0000000000000000 R08: 0000000000005aab R09: ffffffff8a088dd8
R10: ffff888097cdef00 R11: ffff888097cde680 R12: ffff8880a7a76e98
R13: ffff88808f8cff58 R14: dffffc0000000000 R15: ffff88808f8cff58
do_signal_stop+0x199/0x750 kernel/signal.c:2112
get_signal+0xd02/0x1ca0 kernel/signal.c:2298
do_signal+0x7c/0x1690 arch/x86/kernel/signal.c:814
exit_to_usermode_loop+0x159/0x220 arch/x86/entry/common.c:160
prepare_exit_to_usermode arch/x86/entry/common.c:199 [inline]
syscall_return_slowpath arch/x86/entry/common.c:270 [inline]
do_syscall_64+0x4a3/0x640 arch/x86/entry/common.c:297
entry_SYSCALL_64_after_hwframe+0x42/0xb7
RIP: 0033:0x4468d9
RSP: 002b:00007f91f8755d98 EFLAGS: 00000246 ORIG_RAX: 000000000000000b
RAX: ffffffffffffffea RBX: 00000000006dbc58 RCX: 00000000004468d9
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 00000000200000c0
RBP: 00000000006dbc50 R08: 00007f91f8756700 R09: 0000000000000000
R10: 00007f91f8756700 R11: 0000000000000246 R12: 00000000006dbc5c
R13: 0000000000000000 R14: 07007ff8464c457f R15: 000000000000f172
Reply all
Reply to author
Forward
0 new messages