[v6.1] WARNING in ceph_con_v1_try_read

3 views
Skip to first unread message

syzbot

unread,
Aug 3, 2026, 1:32:34 PM (4 days ago) Aug 3
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: fb28aa725e05 Linux 6.1.180
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=138263b9580000
kernel config: https://syzkaller.appspot.com/x/.config?x=872c04466179833f
dashboard link: https://syzkaller.appspot.com/bug?extid=2c455222b38ef24a567c
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
userspace arch: arm64

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/d420eb944682/disk-fb28aa72.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/affae450ab23/vmlinux-fb28aa72.xz
kernel image: https://storage.googleapis.com/syzbot-assets/b9e6919ed519/Image-fb28aa72.gz.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+2c4552...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 0 PID: 7 at net/ceph/messenger_v1.c:912 process_connect net/ceph/messenger_v1.c:911 [inline]
WARNING: CPU: 0 PID: 7 at net/ceph/messenger_v1.c:912 ceph_con_v1_try_read+0x26e4/0x5354 net/ceph/messenger_v1.c:1294
Modules linked in:
CPU: 0 PID: 7 Comm: kworker/0:0 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/02/2026
Workqueue: ceph-msgr ceph_con_workfn
pstate: 82400005 (Nzcv daif +PAN -UAO +TCO -DIT -SSBS BTYPE=--)
pc : process_connect net/ceph/messenger_v1.c:911 [inline]
pc : ceph_con_v1_try_read+0x26e4/0x5354 net/ceph/messenger_v1.c:1294
lr : process_connect net/ceph/messenger_v1.c:911 [inline]
lr : ceph_con_v1_try_read+0x26e4/0x5354 net/ceph/messenger_v1.c:1294
sp : ffff80001cb17140
x29: ffff80001cb17ad0 x28: 2f018fb87aa4aafe x27: ffff0000de154428
x26: dfff800000000000 x25: f8f8f8f8f8f8f8f8 x24: 0000000000000000
x23: 0000000000000001 x22: ffff0000de1548c0 x21: ffff0000de154440
x20: ffff700003962e6c x19: ffff0000de1548bc x18: 1fffe00033e7277e
x17: ffff80001537d000 x16: ffff8000082dd248 x15: 0000000000000000
x14: 000000000000000d x13: 0000000000ff0100 x12: ffff800017cebef8
x11: ff008000117d9c4c x10: 0000000000000000 x9 : ffff8000117d9c4c
x8 : ffff0000c09a3800 x7 : 0000000000000000 x6 : 0000000000000000
x5 : 0000000000000000 x4 : 0000000000000000 x3 : 0000000000000010
x2 : 0000000000000000 x1 : 0000000000000000 x0 : 0000000000000001
Call trace:
process_connect net/ceph/messenger_v1.c:911 [inline]
ceph_con_v1_try_read+0x26e4/0x5354 net/ceph/messenger_v1.c:1294
ceph_con_workfn+0x1b0/0xdcc net/ceph/messenger.c:1505
process_one_work+0x7e4/0x13bc kernel/workqueue.c:2292
worker_thread+0x8cc/0xfe8 kernel/workqueue.c:2439
kthread+0x254/0x2e0 kernel/kthread.c:376
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:850
irq event stamp: 47056
hardirqs last enabled at (47055): [<ffff8000081ad57c>] __local_bh_enable_ip+0x1f8/0x37c kernel/softirq.c:426
hardirqs last disabled at (47056): [<ffff800011b8c2bc>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:405
softirqs last enabled at (47054): [<ffff80000fe7f9c4>] spin_unlock_bh include/linux/spinlock.h:396 [inline]
softirqs last enabled at (47054): [<ffff80000fe7f9c4>] release_sock+0x16c/0x1bc net/core/sock.c:3531
softirqs last disabled at (47052): [<ffff80000fe7f88c>] spin_lock_bh include/linux/spinlock.h:356 [inline]
softirqs last disabled at (47052): [<ffff80000fe7f88c>] release_sock+0x34/0x1bc net/core/sock.c:3518
---[ end trace 0000000000000000 ]---
libceph: read_partial_message bad hdr crc 552194265 != expected 671088640
libceph: mon0 (1)127.0.0.1:6789 bad crc/signature


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Aug 3, 2026, 3:06:32 PM (4 days ago) Aug 3
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 6e2fd6534337 Linux 5.15.213
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=118c1649580000
kernel config: https://syzkaller.appspot.com/x/.config?x=f161cbc9aef65db0
dashboard link: https://syzkaller.appspot.com/bug?extid=7e30a4b55dcfeab9b21d
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/d7b46606b13d/disk-6e2fd653.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/da120fdeb081/vmlinux-6e2fd653.xz
kernel image: https://storage.googleapis.com/syzbot-assets/3c2643457e3f/bzImage-6e2fd653.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+7e30a4...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 1 PID: 4264 at net/ceph/messenger_v1.c:912 process_connect net/ceph/messenger_v1.c:911 [inline]
WARNING: CPU: 1 PID: 4264 at net/ceph/messenger_v1.c:912 ceph_con_v1_try_read+0x3166/0x6440 net/ceph/messenger_v1.c:1252
Modules linked in:
CPU: 1 PID: 4264 Comm: kworker/1:7 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
Workqueue: ceph-msgr ceph_con_workfn
RIP: 0010:process_connect net/ceph/messenger_v1.c:911 [inline]
RIP: 0010:ceph_con_v1_try_read+0x3166/0x6440 net/ceph/messenger_v1.c:1252
Code: e8 af f9 eb f7 45 31 ff e9 d9 d2 ff ff e8 a2 f9 eb f7 0f 0b e9 6a d5 ff ff e8 96 f9 eb f7 0f 0b e9 7e e7 ff ff e8 8a f9 eb f7 <0f> 0b e9 82 e8 ff ff 89 d9 80 e1 07 80 c1 03 38 c1 0f 8c d0 d2 ff
RSP: 0018:ffffc9000319f240 EFLAGS: 00010293
RAX: ffffffff898d0326 RBX: 0000000000000001 RCX: ffff888022c55940
RDX: 0000000000000000 RSI: 00000000ffffffff RDI: 0000000000000001
RBP: ffffc9000319fbb8 R08: ffff888022c55940 R09: 0000000000000009
R10: 000000000000000d R11: 0000000000000000 R12: ffff8880252cc8b8
R13: fffff52000633e84 R14: dffffc0000000000 R15: 00000000ffffffff
FS: 0000000000000000(0000) GS:ffff8880b9100000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f5fc78e9ff8 CR3: 000000004c73a000 CR4: 00000000003506e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
ceph_con_workfn+0x201/0x1110 net/ceph/messenger.c:1530
process_one_work+0x867/0xff0 kernel/workqueue.c:2310
worker_thread+0xad7/0x12a0 kernel/workqueue.c:2457
kthread+0x42e/0x520 kernel/kthread.c:334
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:287
</TASK>

syzbot

unread,
Aug 3, 2026, 3:55:45 PM (4 days ago) Aug 3
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: fb28aa725e05 Linux 6.1.180
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=12175c9e580000
kernel config: https://syzkaller.appspot.com/x/.config?x=872c04466179833f
dashboard link: https://syzkaller.appspot.com/bug?extid=2c455222b38ef24a567c
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=16c21649580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=149e63b9580000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/d420eb944682/disk-fb28aa72.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/affae450ab23/vmlinux-fb28aa72.xz
kernel image: https://storage.googleapis.com/syzbot-assets/b9e6919ed519/Image-fb28aa72.gz.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+2c4552...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 0 PID: 4404 at net/ceph/messenger_v1.c:912 process_connect net/ceph/messenger_v1.c:911 [inline]
WARNING: CPU: 0 PID: 4404 at net/ceph/messenger_v1.c:912 ceph_con_v1_try_read+0x26e4/0x5354 net/ceph/messenger_v1.c:1294
Modules linked in:
CPU: 0 PID: 4404 Comm: kworker/0:4 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/02/2026
Workqueue: ceph-msgr ceph_con_workfn
pstate: 82400005 (Nzcv daif +PAN -UAO +TCO -DIT -SSBS BTYPE=--)
pc : process_connect net/ceph/messenger_v1.c:911 [inline]
pc : ceph_con_v1_try_read+0x26e4/0x5354 net/ceph/messenger_v1.c:1294
lr : process_connect net/ceph/messenger_v1.c:911 [inline]
lr : ceph_con_v1_try_read+0x26e4/0x5354 net/ceph/messenger_v1.c:1294
sp : ffff800020fb7140
x29: ffff800020fb7ad0 x28: 2f018fb87aa4aafe x27: ffff0000d2518428
x26: dfff800000000000 x25: f8f8f8f8f8f8f8f8 x24: 0000000000000000
x23: 0000000000000001 x22: ffff0000d25188c0 x21: ffff0000d2518440
x20: ffff7000041f6e6c x19: ffff0000d25188bc x18: 1fffe00033e7277e
x17: ffff80018a0bd000 x16: ffff8000082dd248 x15: 0000000000000000
x14: 000000000000000d x13: 0000000000ff0100 x12: ffff800017cebef8
x11: ff008000117d9c4c x10: 0000000000000000 x9 : ffff8000117d9c4c
x8 : ffff0000d669b800 x7 : 0000000000000000 x6 : 0000000000000000
x5 : 0000000000000000 x4 : 0000000000000000 x3 : 0000000000000010
x2 : 0000000000000000 x1 : 0000000000000000 x0 : 0000000000000001
Call trace:
process_connect net/ceph/messenger_v1.c:911 [inline]
ceph_con_v1_try_read+0x26e4/0x5354 net/ceph/messenger_v1.c:1294
ceph_con_workfn+0x1b0/0xdcc net/ceph/messenger.c:1505
process_one_work+0x7e4/0x13bc kernel/workqueue.c:2292
worker_thread+0x8cc/0xfe8 kernel/workqueue.c:2439
kthread+0x254/0x2e0 kernel/kthread.c:376
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:850
irq event stamp: 19314
hardirqs last enabled at (19313): [<ffff8000081ad57c>] __local_bh_enable_ip+0x1f8/0x37c kernel/softirq.c:426
hardirqs last disabled at (19314): [<ffff800011b8c2bc>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:405
softirqs last enabled at (19312): [<ffff80000fe7f9c4>] spin_unlock_bh include/linux/spinlock.h:396 [inline]
softirqs last enabled at (19312): [<ffff80000fe7f9c4>] release_sock+0x16c/0x1bc net/core/sock.c:3531
softirqs last disabled at (19310): [<ffff80000fe7f88c>] spin_lock_bh include/linux/spinlock.h:356 [inline]
softirqs last disabled at (19310): [<ffff80000fe7f88c>] release_sock+0x34/0x1bc net/core/sock.c:3518
---[ end trace 0000000000000000 ]---


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

syzbot

unread,
Aug 3, 2026, 6:36:40 PM (4 days ago) Aug 3
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: aa0e49877a2e Linux 6.6.148
git tree: linux-6.6.y
console output: https://syzkaller.appspot.com/x/log.txt?x=15c11649580000
kernel config: https://syzkaller.appspot.com/x/.config?x=f0bc3d90c30838b5
dashboard link: https://syzkaller.appspot.com/bug?extid=5f2ad02c28da41099f8a
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/f83b390cfc1f/disk-aa0e4987.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/1d4bdb338edd/vmlinux-aa0e4987.xz
kernel image: https://storage.googleapis.com/syzbot-assets/3f57c1d51ee3/bzImage-aa0e4987.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+5f2ad0...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 0 PID: 5785 at net/ceph/messenger_v1.c:906 process_connect net/ceph/messenger_v1.c:905 [inline]
WARNING: CPU: 0 PID: 5785 at net/ceph/messenger_v1.c:906 ceph_con_v1_try_read+0x3136/0x6400 net/ceph/messenger_v1.c:1370
Modules linked in:
CPU: 0 PID: 5785 Comm: kworker/0:3 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
Workqueue: ceph-msgr ceph_con_workfn
RIP: 0010:process_connect net/ceph/messenger_v1.c:905 [inline]
RIP: 0010:ceph_con_v1_try_read+0x3136/0x6400 net/ceph/messenger_v1.c:1370
Code: e8 bf 22 3b f7 45 31 ff e9 19 d3 ff ff e8 b2 22 3b f7 0f 0b e9 dd d5 ff ff e8 a6 22 3b f7 0f 0b e9 0f e8 ff ff e8 9a 22 3b f7 <0f> 0b e9 2e e9 ff ff 89 d9 80 e1 07 80 c1 03 38 c1 0f 8c 10 d3 ff
RSP: 0018:ffffc9000472f1c0 EFLAGS: 00010293
RAX: ffffffff8a4c4ee6 RBX: 0000000000000001 RCX: ffff888030a91e00
RDX: 0000000000000000 RSI: 00000000ffffffff RDI: 0000000000000001
RBP: ffffc9000472fb38 R08: ffff888030a91e00 R09: 0000000000000009
R10: 000000000000000d R11: 0000000000000000 R12: ffff88802dfbc8c0
R13: dffffc0000000000 R14: fffff520008e5e74 R15: 00000000ffffffff
FS: 0000000000000000(0000) GS:ffff8880b8e00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f060615cff8 CR3: 00000000596fe000 CR4: 00000000003506f0
Call Trace:
<TASK>
ceph_con_workfn+0x205/0x1250 net/ceph/messenger.c:1576
process_one_work kernel/workqueue.c:2657 [inline]
process_scheduled_works+0xa60/0x1600 kernel/workqueue.c:2734
worker_thread+0xa5e/0xfe0 kernel/workqueue.c:2815
kthread+0x2fa/0x390 kernel/kthread.c:388
ret_from_fork+0x48/0x80 arch/x86/kernel/process.c:152
ret_from_fork_asm+0x11/0x20 arch/x86/entry/entry_64.S:293

syzbot

unread,
Aug 4, 2026, 8:22:23 AM (4 days ago) Aug 4
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 6e2fd6534337 Linux 5.15.213
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1597e3b9580000
kernel config: https://syzkaller.appspot.com/x/.config?x=f161cbc9aef65db0
dashboard link: https://syzkaller.appspot.com/bug?extid=7e30a4b55dcfeab9b21d
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=13898bb9580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=15a32cc6580000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/d7b46606b13d/disk-6e2fd653.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/da120fdeb081/vmlinux-6e2fd653.xz
kernel image: https://storage.googleapis.com/syzbot-assets/3c2643457e3f/bzImage-6e2fd653.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+7e30a4...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 1 PID: 1324 at net/ceph/messenger_v1.c:912 process_connect net/ceph/messenger_v1.c:911 [inline]
WARNING: CPU: 1 PID: 1324 at net/ceph/messenger_v1.c:912 ceph_con_v1_try_read+0x3166/0x6440 net/ceph/messenger_v1.c:1252
Modules linked in:
CPU: 1 PID: 1324 Comm: kworker/1:2 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
Workqueue: ceph-msgr ceph_con_workfn
RIP: 0010:process_connect net/ceph/messenger_v1.c:911 [inline]
RIP: 0010:ceph_con_v1_try_read+0x3166/0x6440 net/ceph/messenger_v1.c:1252
Code: e8 af f9 eb f7 45 31 ff e9 d9 d2 ff ff e8 a2 f9 eb f7 0f 0b e9 6a d5 ff ff e8 96 f9 eb f7 0f 0b e9 7e e7 ff ff e8 8a f9 eb f7 <0f> 0b e9 82 e8 ff ff 89 d9 80 e1 07 80 c1 03 38 c1 0f 8c d0 d2 ff
RSP: 0018:ffffc900052b7240 EFLAGS: 00010293
RAX: ffffffff898d0326 RBX: 0000000000000001 RCX: ffff8880239a9dc0
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000001
RBP: ffffc900052b7bb8 R08: ffff8880239a9dc0 R09: 0000000000000009
R10: 000000000000000d R11: 0000000000000000 R12: ffff88807b0a88b8
R13: fffff52000a56e84 R14: dffffc0000000000 R15: 0000000000000000
FS: 0000000000000000(0000) GS:ffff8880b9100000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007ff57daf5700 CR3: 000000007ea71000 CR4: 00000000003506e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
ceph_con_workfn+0x201/0x1110 net/ceph/messenger.c:1530
process_one_work+0x867/0xff0 kernel/workqueue.c:2310
worker_thread+0xad7/0x12a0 kernel/workqueue.c:2457
kthread+0x42e/0x520 kernel/kthread.c:334
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:287
</TASK>


---
Reply all
Reply to author
Forward
0 new messages