KCSAN: data-race in fib6_clean_node / ip6_dst_check (3)

12 views
Skip to first unread message

syzbot

unread,
Dec 11, 2020, 6:43:14 AM12/11/20
to syzkaller-upst...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 32f741b0 Merge tag 'powerpc-5.10-5' of git://git.kernel.or..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=107230f3500000
kernel config: https://syzkaller.appspot.com/x/.config?x=c949fed53798f819
dashboard link: https://syzkaller.appspot.com/bug?extid=ce12ee04ef8be54aa5ed
compiler: clang version 12.0.0 (https://github.com/llvm/llvm-project.git 913f6005669cfb590c99865a90bc51ed0983d09d)
CC: [and...@kernel.org a...@kernel.org b...@vger.kernel.org dan...@iogearbox.net da...@davemloft.net john.fa...@gmail.com ka...@fb.com kps...@chromium.org ku...@kernel.org kuz...@ms2.inr.ac.ru linux-...@vger.kernel.org net...@vger.kernel.org songliu...@fb.com y...@fb.com yosh...@linux-ipv6.org]

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+ce12ee...@syzkaller.appspotmail.com

==================================================================
BUG: KCSAN: data-race in fib6_clean_node / ip6_dst_check

write to 0xffff8880268d852c of 4 bytes by task 9231 on cpu 1:
fib6_clean_node+0xc0/0x260 net/ipv6/ip6_fib.c:2177
fib6_walk_continue+0x38e/0x430 net/ipv6/ip6_fib.c:2111
fib6_walk net/ipv6/ip6_fib.c:2159 [inline]
fib6_clean_tree net/ipv6/ip6_fib.c:2239 [inline]
__fib6_clean_all+0x188/0x2b0 net/ipv6/ip6_fib.c:2255
fib6_flush_trees+0x6c/0x80 net/ipv6/ip6_fib.c:2280
rt_genid_bump_ipv6 include/net/net_namespace.h:458 [inline]
addrconf_dad_completed+0x57f/0x860 net/ipv6/addrconf.c:4205
addrconf_dad_work+0x8dd/0x1150 net/ipv6/addrconf.c:3958
process_one_work+0x3e1/0x950 kernel/workqueue.c:2272
worker_thread+0x635/0xb90 kernel/workqueue.c:2418
kthread+0x1fd/0x220 kernel/kthread.c:292
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:296

read to 0xffff8880268d852c of 4 bytes by task 5 on cpu 0:
fib6_get_cookie_safe include/net/ip6_fib.h:283 [inline]
fib6_check net/ipv6/route.c:2577 [inline]
rt6_dst_from_check net/ipv6/route.c:2608 [inline]
ip6_dst_check+0x270/0x400 net/ipv6/route.c:2636
dst_cache_per_cpu_get+0x103/0x1b0 net/core/dst_cache.c:50
dst_cache_get_ip6+0x33/0x70 net/core/dst_cache.c:130
send6+0x168/0x3a0 drivers/net/wireguard/socket.c:129
wg_socket_send_skb_to_peer+0xbb/0x120 drivers/net/wireguard/socket.c:177
wg_packet_create_data_done drivers/net/wireguard/send.c:252 [inline]
wg_packet_tx_worker+0x1e3/0x4c0 drivers/net/wireguard/send.c:280
process_one_work+0x3e1/0x950 kernel/workqueue.c:2272
worker_thread+0x635/0xb90 kernel/workqueue.c:2418
kthread+0x1fd/0x220 kernel/kthread.c:292
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:296

Reported by Kernel Concurrency Sanitizer on:
CPU: 0 PID: 5 Comm: kworker/0:0 Not tainted 5.10.0-rc6-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Workqueue: wg-crypt-wg0 wg_packet_tx_worker
==================================================================


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Jan 9, 2021, 8:07:19 PM1/9/21
to syzkaller-upst...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages