[v6.1] WARNING in minstrel_ht_update_caps (2)

2 views
Skip to first unread message

syzbot

unread,
May 25, 2025, 12:09:35 AM5/25/25
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: da3c5173c55f Linux 6.1.140
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=12a2e170580000
kernel config: https://syzkaller.appspot.com/x/.config?x=2bfe5a2f04bb30e3
dashboard link: https://syzkaller.appspot.com/bug?extid=32be8cc0e6d08e99d299
compiler: Debian clang version 20.1.6 (++20250514063057+1e4d39e07757-1~exp1~20250514183223.118), Debian LLD 20.1.6
userspace arch: arm64

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/2c3ee4de68a1/disk-da3c5173.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/19742d73f52b/vmlinux-da3c5173.xz
kernel image: https://storage.googleapis.com/syzbot-assets/0ffdd39d32ee/Image-da3c5173.gz.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+32be8c...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 0 PID: 4958 at include/net/mac80211.h:6657 rate_lowest_index include/net/mac80211.h:-1 [inline]
WARNING: CPU: 0 PID: 4958 at include/net/mac80211.h:6657 minstrel_ht_update_caps+0x3bc/0x13d8 net/mac80211/rc80211_minstrel_ht.c:1734
Modules linked in:
CPU: 0 PID: 4958 Comm: syz.1.103 Not tainted 6.1.140-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025
pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : rate_lowest_index include/net/mac80211.h:-1 [inline]
pc : minstrel_ht_update_caps+0x3bc/0x13d8 net/mac80211/rc80211_minstrel_ht.c:1734
lr : rate_lowest_index include/net/mac80211.h:6652 [inline]
lr : minstrel_ht_update_caps+0x3b4/0x13d8 net/mac80211/rc80211_minstrel_ht.c:1734
sp : ffff800022106e70
x29: ffff800022106f00 x28: ffff0000d45e2658 x27: ffff0000dc64b398
x26: 0000000000000000 x25: 0b00000000000000 x24: 000000000000000b
x23: ffff0000dc64b3a0 x22: 1fffe0001b8c9674 x21: dfff800000000000
x20: ffff0000dc64def8 x19: 0100000000000000 x18: 0000000000000000
x17: 00000000ffff0000 x16: ffff8000082e6f84 x15: 0000000000000002
x14: 0000000000000003 x13: 0000000000000000 x12: 0000000000080000
x11: 0000000000001711 x10: ffff800021099000 x9 : ffff80001131a338
x8 : 0000000000001712 x7 : 0000000000000000 x6 : 000000000000003f
x5 : 0000000000000000 x4 : 0000000000000001 x3 : 0000000000000001
x2 : 000000000000003c x1 : 0000000000000000 x0 : 0000000000000000
Call trace:
rate_lowest_index include/net/mac80211.h:-1 [inline]
minstrel_ht_update_caps+0x3bc/0x13d8 net/mac80211/rc80211_minstrel_ht.c:1734
minstrel_ht_rate_init+0x48/0x60 net/mac80211/rc80211_minstrel_ht.c:1844
rate_control_rate_init+0x2e0/0x538 net/mac80211/rate.c:63
sta_apply_auth_flags+0x158/0x350 net/mac80211/cfg.c:1580
sta_apply_parameters+0xb64/0x131c net/mac80211/cfg.c:1911
ieee80211_add_station+0x2d0/0x4d4 net/mac80211/cfg.c:1976
rdev_add_station+0x148/0x37c net/wireless/rdev-ops.h:201
nl80211_new_station+0x116c/0x1584 net/wireless/nl80211.c:7435
genl_family_rcv_msg_doit+0x1f8/0x2f4 net/netlink/genetlink.c:756
genl_family_rcv_msg net/netlink/genetlink.c:833 [inline]
genl_rcv_msg+0x444/0x62c net/netlink/genetlink.c:850
netlink_rcv_skb+0x208/0x3c4 net/netlink/af_netlink.c:2493
genl_rcv+0x38/0x50 net/netlink/genetlink.c:861
netlink_unicast_kernel net/netlink/af_netlink.c:1311 [inline]
netlink_unicast+0x600/0x818 net/netlink/af_netlink.c:1337
netlink_sendmsg+0x6e8/0x9b0 net/netlink/af_netlink.c:1859
sock_sendmsg_nosec net/socket.c:718 [inline]
__sock_sendmsg net/socket.c:730 [inline]
____sys_sendmsg+0x5b8/0x918 net/socket.c:2519
___sys_sendmsg net/socket.c:2573 [inline]
__sys_sendmsg+0x25c/0x320 net/socket.c:2602
__do_sys_sendmsg net/socket.c:2611 [inline]
__se_sys_sendmsg net/socket.c:2609 [inline]
__arm64_sys_sendmsg+0x80/0x94 net/socket.c:2609
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2bc arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:140
do_el0_svc+0x58/0x13c arch/arm64/kernel/syscall.c:204
el0_svc+0x58/0x138 arch/arm64/kernel/entry-common.c:637
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:585
irq event stamp: 3199
hardirqs last enabled at (3197): [<ffff80000878cb10>] mod_lruvec_page_state include/linux/vmstat.h:563 [inline]
hardirqs last enabled at (3197): [<ffff80000878cb10>] __kmalloc_large_node+0x120/0x1e0 mm/slab_common.c:1080
hardirqs last disabled at (3199): [<ffff8000119153e0>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:405
softirqs last enabled at (3176): [<ffff80000fd00cf0>] local_bh_enable+0x10/0x34 include/linux/bottom_half.h:32
softirqs last disabled at (3198): [<ffff80001119d23c>] spin_lock_bh include/linux/spinlock.h:356 [inline]
softirqs last disabled at (3198): [<ffff80001119d23c>] rate_control_rate_init+0x27c/0x538 net/mac80211/rate.c:62
---[ end trace 0000000000000000 ]---


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Sep 2, 2025, 12:48:21 AM9/2/25
to syzkaller...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages