Hello,
syzbot found the following issue on:
HEAD commit: 0477e928 Linux 5.10-rc7
git tree: upstream
console output:
https://syzkaller.appspot.com/x/log.txt?x=139fccdf500000
kernel config:
https://syzkaller.appspot.com/x/.config?x=329e76890d0bf5c3
dashboard link:
https://syzkaller.appspot.com/bug?extid=58d8e5eb0f93534fd5f6
compiler: clang version 12.0.0 (
https://github.com/llvm/llvm-project.git 913f6005669cfb590c99865a90bc51ed0983d09d)
CC: [
da...@davemloft.net ku...@kernel.org kuz...@ms2.inr.ac.ru linux-...@vger.kernel.org net...@vger.kernel.org yosh...@linux-ipv6.org]
Unfortunately, I don't have any reproducer for this issue yet.
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+58d8e5...@syzkaller.appspotmail.com
==================================================================
BUG: KCSAN: data-race in iptunnel_xmit / iptunnel_xmit
read-write to 0xffff888035f6d140 of 8 bytes by task 15297 on cpu 0:
iptunnel_xmit_stats include/net/ip_tunnels.h:461 [inline]
iptunnel_xmit+0x3f7/0x460 net/ipv4/ip_tunnel_core.c:87
ip_tunnel_xmit+0x1084/0x11b0 net/ipv4/ip_tunnel.c:807
__gre_xmit net/ipv4/ip_gre.c:466 [inline]
ipgre_xmit+0x4d9/0x530 net/ipv4/ip_gre.c:648
__netdev_start_xmit include/linux/netdevice.h:4735 [inline]
netdev_start_xmit include/linux/netdevice.h:4749 [inline]
xmit_one+0xf9/0x2e0 net/core/dev.c:3564
dev_hard_start_xmit net/core/dev.c:3580 [inline]
__dev_queue_xmit+0xeef/0x1510 net/core/dev.c:4140
dev_queue_xmit+0x13/0x20 net/core/dev.c:4173
__bpf_tx_skb net/core/filter.c:2116 [inline]
__bpf_redirect_no_mac net/core/filter.c:2141 [inline]
__bpf_redirect+0x544/0x750 net/core/filter.c:2164
____bpf_clone_redirect net/core/filter.c:2448 [inline]
bpf_clone_redirect+0x168/0x1c0 net/core/filter.c:2420
bpf_prog_d7d583f53caddbf0+0x56/0x808
bpf_dispatcher_nop_func include/linux/bpf.h:644 [inline]
bpf_test_run+0x266/0x450 net/bpf/test_run.c:50
bpf_prog_test_run_skb+0x6f0/0xe70 net/bpf/test_run.c:581
bpf_prog_test_run kernel/bpf/syscall.c:3125 [inline]
__do_sys_bpf+0x39d6/0x9aa0 kernel/bpf/syscall.c:4417
__se_sys_bpf kernel/bpf/syscall.c:4357 [inline]
__x64_sys_bpf+0x3d/0x50 kernel/bpf/syscall.c:4357
do_syscall_64+0x39/0x80 arch/x86/entry/common.c:46
entry_SYSCALL_64_after_hwframe+0x44/0xa9
read-write to 0xffff888035f6d140 of 8 bytes by task 15309 on cpu 1:
iptunnel_xmit_stats include/net/ip_tunnels.h:461 [inline]
iptunnel_xmit+0x3f7/0x460 net/ipv4/ip_tunnel_core.c:87
ip_tunnel_xmit+0x1084/0x11b0 net/ipv4/ip_tunnel.c:807
__gre_xmit net/ipv4/ip_gre.c:466 [inline]
ipgre_xmit+0x4d9/0x530 net/ipv4/ip_gre.c:648
__netdev_start_xmit include/linux/netdevice.h:4735 [inline]
netdev_start_xmit include/linux/netdevice.h:4749 [inline]
xmit_one+0xf9/0x2e0 net/core/dev.c:3564
dev_hard_start_xmit net/core/dev.c:3580 [inline]
__dev_queue_xmit+0xeef/0x1510 net/core/dev.c:4140
dev_queue_xmit+0x13/0x20 net/core/dev.c:4173
__bpf_tx_skb net/core/filter.c:2116 [inline]
__bpf_redirect_no_mac net/core/filter.c:2141 [inline]
__bpf_redirect+0x544/0x750 net/core/filter.c:2164
____bpf_clone_redirect net/core/filter.c:2448 [inline]
bpf_clone_redirect+0x168/0x1c0 net/core/filter.c:2420
bpf_prog_bebbfe2050753572+0x56/0x308
bpf_dispatcher_nop_func include/linux/bpf.h:644 [inline]
bpf_test_run+0x266/0x450 net/bpf/test_run.c:50
bpf_prog_test_run_skb+0x6f0/0xe70 net/bpf/test_run.c:581
bpf_prog_test_run kernel/bpf/syscall.c:3125 [inline]
__do_sys_bpf+0x39d6/0x9aa0 kernel/bpf/syscall.c:4417
__se_sys_bpf kernel/bpf/syscall.c:4357 [inline]
__x64_sys_bpf+0x3d/0x50 kernel/bpf/syscall.c:4357
do_syscall_64+0x39/0x80 arch/x86/entry/common.c:46
entry_SYSCALL_64_after_hwframe+0x44/0xa9
Reported by Kernel Concurrency Sanitizer on:
CPU: 1 PID: 15309 Comm: syz-executor.1 Not tainted 5.10.0-rc7-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
==================================================================
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.