syzbot has found a reproducer for the following issue on:
HEAD commit: 98f47d0e9b8c Linux 5.15.184
git tree: linux-5.15.y
console output:
https://syzkaller.appspot.com/x/log.txt?x=1788fed4580000
kernel config:
https://syzkaller.appspot.com/x/.config?x=9eb2b5a65dfc4761
dashboard link:
https://syzkaller.appspot.com/bug?extid=8b474f5d9a002f13359f
compiler: Debian clang version 20.1.6 (++20250514063057+1e4d39e07757-1~exp1~20250514183223.118), Debian LLD 20.1.6
userspace arch: arm64
syz repro:
https://syzkaller.appspot.com/x/repro.syz?x=17c5a00c580000
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/d2845fb3af6c/disk-98f47d0e.raw.xz
vmlinux:
https://storage.googleapis.com/syzbot-assets/1f12b743be24/vmlinux-98f47d0e.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/8f178b57ea38/Image-98f47d0e.gz.xz
GID entry ref leak for dev syz1 index 2 ref=72
WARNING: CPU: 1 PID: 148 at drivers/infiniband/core/cache.c:809 release_gid_table drivers/infiniband/core/cache.c:806 [inline]
WARNING: CPU: 1 PID: 148 at drivers/infiniband/core/cache.c:809 gid_table_release_one+0x284/0x3cc drivers/infiniband/core/cache.c:886
Modules linked in:
CPU: 1 PID: 148 Comm: kworker/u4:2 Not tainted 5.15.184-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025
Workqueue: events_unbound ib_unregister_work
pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : release_gid_table drivers/infiniband/core/cache.c:806 [inline]
pc : gid_table_release_one+0x284/0x3cc drivers/infiniband/core/cache.c:886
lr : release_gid_table drivers/infiniband/core/cache.c:806 [inline]
lr : gid_table_release_one+0x284/0x3cc drivers/infiniband/core/cache.c:886
sp : ffff80001be27900
x29: ffff80001be27950 x28: ffff0000d2687600 x27: ffff0000d26882d8
x26: ffff0000d2688200 x25: 0000000000000010 x24: 0000000000000001
x23: ffff80001658e000 x22: dfff800000000000 x21: 0000000000000003
x20: 1fffe0001a4d105b x19: 1fffe0001a4d1040 x18: 0000000000000001
x17: 0000000000000000 x16: ffff8000111a5644 x15: 00000000ffffffff
x14: 0000000000ff0100 x13: 0000000000000001 x12: 0000000000ff0100
x11: 0000000000000000 x10: 0000000000000000 x9 : 1082cbb731948700
x8 : 1082cbb731948700 x7 : 0000000000000001 x6 : 0000000000000001
x5 : ffff80001be271f8 x4 : ffff80001422f280 x3 : ffff80000a732644
x2 : ffff0001a111cd10 x1 : 0000000100000000 x0 : 000000000000002e
Call trace:
release_gid_table drivers/infiniband/core/cache.c:806 [inline]
gid_table_release_one+0x284/0x3cc drivers/infiniband/core/cache.c:886
ib_cache_release_one+0x144/0x174 drivers/infiniband/core/cache.c:1648
ib_device_release+0xc4/0x18c drivers/infiniband/core/device.c:497
device_release+0x8c/0x1ac drivers/base/core.c:-1
kobject_cleanup lib/kobject.c:713 [inline]
kobject_release lib/kobject.c:744 [inline]
kref_put include/linux/kref.h:65 [inline]
kobject_put+0x2cc/0x454 lib/kobject.c:761
put_device+0x28/0x40 drivers/base/core.c:3520
ib_unregister_work+0x28/0x38 drivers/infiniband/core/device.c:1595
process_one_work+0x79c/0x1140 kernel/workqueue.c:2310
worker_thread+0x8f4/0x101c kernel/workqueue.c:2457
kthread+0x374/0x454 kernel/kthread.c:334
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:870
irq event stamp: 525608
hardirqs last enabled at (525607): [<ffff8000082f7654>] __up_console_sem+0xb4/0x100 kernel/printk/printk.c:257
hardirqs last disabled at (525608): [<ffff8000111a0f18>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:396
softirqs last enabled at (525604): [<ffff80000819d0d8>] softirq_handle_end kernel/softirq.c:401 [inline]
softirqs last enabled at (525604): [<ffff80000819d0d8>] handle_softirqs+0xa4c/0xbf0 kernel/softirq.c:586
softirqs last disabled at (525459): [<ffff80000819d6dc>] __do_softirq kernel/softirq.c:592 [inline]
softirqs last disabled at (525459): [<ffff80000819d6dc>] do_softirq_own_stack include/asm-generic/softirq_stack.h:10 [inline]
softirqs last disabled at (525459): [<ffff80000819d6dc>] invoke_softirq kernel/softirq.c:439 [inline]
softirqs last disabled at (525459): [<ffff80000819d6dc>] __irq_exit_rcu+0x240/0x440 kernel/softirq.c:641
---[ end trace a0dbd26999cb8cdb ]---
netdevsim netdevsim0 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0
netdevsim netdevsim0 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0
netdevsim netdevsim0 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0
netdevsim netdevsim0 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0
device hsr_slave_0 left promiscuous mode
device hsr_slave_1 left promiscuous mode
batman_adv: batadv0: Interface deactivated: batadv_slave_0
batman_adv: batadv0: Removing interface: batadv_slave_0
batman_adv: batadv0: Interface deactivated: batadv_slave_1
batman_adv: batadv0: Removing interface: batadv_slave_1
device bridge_slave_1 left promiscuous mode
bridge0: port 2(bridge_slave_1) entered disabled state
device bridge_slave_0 left promiscuous mode
bridge0: port 1(bridge_slave_0) entered disabled state
device veth1_macvtap left promiscuous mode
device veth0_macvtap left promiscuous mode
device veth1_vlan left promiscuous mode
device veth0_vlan left promiscuous mode
team0 (unregistering): Port device team_slave_1 removed
team0 (unregistering): Port device team_slave_0 removed
bond0 (unregistering): (slave bond_slave_1): Releasing backup interface
bond0 (unregistering): (slave bond_slave_0): Releasing backup interface
bond0 (unregistering): Released all slaves
---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.