BUG: unable to handle kernel paging request in fib6_purge_rt

4 views
Skip to the first unread message

syzbot

unread,
5 Mar 2019, 14:12:0505/03/2019
to syzkaller-upst...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 1435d9970378 cxgb4: TLS record offload enable
git tree: net-next
console output: https://syzkaller.appspot.com/x/log.txt?x=113b3518c00000
kernel config: https://syzkaller.appspot.com/x/.config?x=505743eba4e4f68
dashboard link: https://syzkaller.appspot.com/bug?extid=aba17079f5b75f674d50
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
CC: [da...@davemloft.net kuz...@ms2.inr.ac.ru
linux-...@vger.kernel.org net...@vger.kernel.org yosh...@linux-ipv6.org
net...@vger.kernel.org]

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+aba170...@syzkaller.appspotmail.com

BUG: unable to handle kernel paging request at ffffff86ca02612b
#PF error: [WRITE]
PGD 9874067 P4D 9874067 PUD 0
Oops: 0002 [#1] PREEMPT SMP KASAN
CPU: 0 PID: 17611 Comm: syz-executor3 Not tainted 5.0.0-rc3+ #16
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
RIP: 0010:arch_atomic_dec_and_test arch/x86/include/asm/atomic.h:125
[inline]
RIP: 0010:atomic_dec_and_test include/asm-generic/atomic-instrumented.h:260
[inline]
RIP: 0010:fib6_info_release include/net/ip6_fib.h:294 [inline]
RIP: 0010:fib6_info_release include/net/ip6_fib.h:292 [inline]
RIP: 0010:fib6_drop_pcpu_from net/ipv6/ip6_fib.c:927 [inline]
RIP: 0010:fib6_purge_rt+0x62b/0x7f0 net/ipv6/ip6_fib.c:960
Code: e8 03 4d 85 ff 49 c7 46 70 00 00 00 00 c6 04 18 f8 0f 84 bc fe ff ff
e8 03 16 b0 fa 49 8d 7f 2c be 04 00 00 00 e8 65 e1 f3 fa <f0> 41 ff 4f 2c
41 0f 94 c6 31 ff 44 89 f6 e8 22 17 b0 fa 45 84 f6
RSP: 0018:ffff888067d16468 EFLAGS: 00010246
RAX: fffffbf0d9404c26 RBX: dffffc0000000000 RCX: ffffffff86d1e8fb
RDX: 0000000000000001 RSI: 0000000000000004 RDI: ffffff86ca02612b
RBP: ffff888067d16568 R08: 1ffffff0d9404c25 R09: fffffbf0d9404c26
R10: fffffbf0d9404c25 R11: ffffff86ca02612e R12: 0000000000000000
R13: ffff888096bd8780 R14: ffff88809f13c6bf R15: ffffff86ca0260ff
FS: 0000000000c6a940(0000) GS:ffff8880ae600000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: ffffff86ca02612b CR3: 0000000086d9a000 CR4: 00000000001406f0
Call Trace:
fib6_del_route net/ipv6/ip6_fib.c:1813 [inline]
fib6_del+0xbdb/0x12e0 net/ipv6/ip6_fib.c:1844
fib6_clean_node+0x453/0x660 net/ipv6/ip6_fib.c:2006
kobject: 'loop0' (00000000026f8682): kobject_uevent_env
kobject: 'loop0' (00000000026f8682): fill_kobj_path: path
= '/devices/virtual/block/loop0'
fib6_walk_continue+0x4b3/0x8e0 net/ipv6/ip6_fib.c:1928
fib6_walk+0x9d/0x100 net/ipv6/ip6_fib.c:1976
fib6_clean_tree+0x22a/0x340 net/ipv6/ip6_fib.c:2055
__fib6_clean_all+0x216/0x430 net/ipv6/ip6_fib.c:2071
fib6_clean_all+0x2b/0x40 net/ipv6/ip6_fib.c:2082
rt6_sync_down_dev+0x17e/0x1b0 net/ipv6/route.c:4041
rt6_disable_ip+0x80/0x730 net/ipv6/route.c:4046
kernel msg: ebtables bug: please report to author: Wrong len argument
addrconf_ifdown+0x13e/0x15e0 net/ipv6/addrconf.c:3704
addrconf_notify+0x629/0x25f0 net/ipv6/addrconf.c:3629
notifier_call_chain+0x179/0x380 kernel/notifier.c:93
__raw_notifier_call_chain kernel/notifier.c:394 [inline]
raw_notifier_call_chain+0x2e/0x40 kernel/notifier.c:401
call_netdevice_notifiers_info+0x3f/0x90 net/core/dev.c:1739
call_netdevice_notifiers_extack net/core/dev.c:1751 [inline]
call_netdevice_notifiers net/core/dev.c:1765 [inline]
dev_close_many+0x42e/0x890 net/core/dev.c:1508
rollback_registered_many+0x544/0x1370 net/core/dev.c:8079
rollback_registered+0x1c9/0x410 net/core/dev.c:8144
unregister_netdevice_queue net/core/dev.c:9188 [inline]
unregister_netdevice_queue+0x30e/0x660 net/core/dev.c:9181
unregister_netdevice include/linux/netdevice.h:2642 [inline]
__tun_detach+0x11ae/0x1600 drivers/net/tun.c:727
tun_detach drivers/net/tun.c:744 [inline]
tun_chr_close+0xe0/0x180 drivers/net/tun.c:3436
__fput+0x3c5/0xb10 fs/file_table.c:278
____fput+0x16/0x20 fs/file_table.c:309
task_work_run+0x1f4/0x2b0 kernel/task_work.c:113
exit_task_work include/linux/task_work.h:22 [inline]
do_exit+0xad7/0x26e0 kernel/exit.c:867
do_group_exit+0x177/0x430 kernel/exit.c:971
__do_sys_exit_group kernel/exit.c:982 [inline]
__se_sys_exit_group kernel/exit.c:980 [inline]
__x64_sys_exit_group+0x44/0x50 kernel/exit.c:980
do_syscall_64+0x1a3/0x800 arch/x86/entry/common.c:290
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x458099
Code: 6d b7 fb ff c3 66 2e 0f 1f 84 00 00 00 00 00 66 90 48 89 f8 48 89 f7
48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff
ff 0f 83 3b b7 fb ff c3 66 2e 0f 1f 84 00 00 00 00
RSP: 002b:00007ffff7ed5f58 EFLAGS: 00000246 ORIG_RAX: 00000000000000e7
RAX: ffffffffffffffda RBX: 0000000000000011 RCX: 0000000000458099
RDX: 0000000000411d80 RSI: 0000000000a54ef0 RDI: 0000000000000043
RBP: 00000000004bd81d R08: 000000000000000c R09: 00000000002d720f
R10: 0000000000c6a940 R11: 0000000000000246 R12: 0000000000000002
R13: 00000000002d718f R14: 00000000000015d3 R15: 0000000000000003
Modules linked in:
CR2: ffffff86ca02612b
---[ end trace 2074127e8067021d ]---
RIP: 0010:arch_atomic_dec_and_test arch/x86/include/asm/atomic.h:125
[inline]
RIP: 0010:atomic_dec_and_test include/asm-generic/atomic-instrumented.h:260
[inline]
RIP: 0010:fib6_info_release include/net/ip6_fib.h:294 [inline]
RIP: 0010:fib6_info_release include/net/ip6_fib.h:292 [inline]
RIP: 0010:fib6_drop_pcpu_from net/ipv6/ip6_fib.c:927 [inline]
RIP: 0010:fib6_purge_rt+0x62b/0x7f0 net/ipv6/ip6_fib.c:960
Code: e8 03 4d 85 ff 49 c7 46 70 00 00 00 00 c6 04 18 f8 0f 84 bc fe ff ff
e8 03 16 b0 fa 49 8d 7f 2c be 04 00 00 00 e8 65 e1 f3 fa <f0> 41 ff 4f 2c
41 0f 94 c6 31 ff 44 89 f6 e8 22 17 b0 fa 45 84 f6
RSP: 0018:ffff888067d16468 EFLAGS: 00010246
RAX: fffffbf0d9404c26 RBX: dffffc0000000000 RCX: ffffffff86d1e8fb
RDX: 0000000000000001 RSI: 0000000000000004 RDI: ffffff86ca02612b
RBP: ffff888067d16568 R08: 1ffffff0d9404c25 R09: fffffbf0d9404c26
R10: fffffbf0d9404c25 R11: ffffff86ca02612e R12: 0000000000000000
R13: ffff888096bd8780 R14: ffff88809f13c6bf R15: ffffff86ca0260ff
FS: 0000000000c6a940(0000) GS:ffff8880ae600000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: ffffff86ca02612b CR3: 0000000086d9a000 CR4: 00000000001406f0


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#bug-status-tracking for how to communicate with
syzbot.

syzbot

unread,
21 Jul 2019, 22:00:0421/07/2019
to syzkaller-upst...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages