BUG: unable to handle kernel paging request in wait_consider_task

16 views
Skip to first unread message

syzbot

unread,
Sep 3, 2019, 5:28:08 PM9/3/19
to syzkaller-upst...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: d00ee466 nfp: add AMDA0058 boards to firmware list
git tree: net-next
console output: https://syzkaller.appspot.com/x/log.txt?x=175df85c600000
kernel config: https://syzkaller.appspot.com/x/.config?x=e34a4fe936eac597
dashboard link: https://syzkaller.appspot.com/bug?extid=a248bc935509efad4dac
compiler: gcc (GCC) 9.0.0 20181231 (experimental)
CC: [aarc...@redhat.com ak...@linux-foundation.org
andrea...@amarulasolutions.com ap42...@gmail.com ava...@gmail.com
chri...@brauner.io linux-...@vger.kernel.org ol...@redhat.com
prs...@codeaurora.org tg...@linutronix.de t...@kernel.org
net...@vger.kernel.org]

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+a248bc...@syzkaller.appspotmail.com

BUG: unable to handle page fault for address: ffffffffffffff6c
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 8e70067 P4D 8e70067 PUD 8e72067 PMD 0
Oops: 0000 [#1] PREEMPT SMP KASAN
CPU: 1 PID: 8889 Comm: syz-executor.0 Not tainted 5.3.0-rc5+ #151
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS
Google 01/01/2011
RIP: 0010:__read_once_size include/linux/compiler.h:199 [inline]
RIP: 0010:wait_consider_task+0xb3/0x38a0 kernel/exit.c:1349
Code: 00 00 48 89 c8 48 89 8d 48 ff ff ff 48 c1 e8 03 42 0f b6 14 20 48 89
c8 83 e0 07 83 c0 03 38 d0 7c 08 84 d2 0f 85 47 1a 00 00 <45> 8b a6 74 04
00 00 bf 10 00 00 00 44 89 e6 e8 19 94 2d 00 41 83
RSP: 0018:ffff88809f58faa0 EFLAGS: 00010246
RAX: 0000000000000007 RBX: 0000000000000000 RCX: ffffffffffffff6c
RDX: 0000000000000000 RSI: ffffffff8144de54 RDI: ffff88809f58fcb8
RBP: ffff88809f58fbc8 R08: ffff8880a916e640 R09: fffffbfff11c1219
R10: fffffbfff11c1218 R11: ffffffff88e090c3 R12: dffffc0000000000
R13: dffffc0000000000 R14: fffffffffffffaf8 R15: ffff88809f58fcb8
FS: 0000555555b93940(0000) GS:ffff8880ae900000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: ffffffffffffff6c CR3: 00000000a5c7c000 CR4: 00000000001406e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
do_wait_thread kernel/exit.c:1458 [inline]
do_wait+0x452/0xa10 kernel/exit.c:1529
kernel_wait4+0x171/0x290 kernel/exit.c:1671
__do_sys_wait4+0x147/0x160 kernel/exit.c:1683
__se_sys_wait4 kernel/exit.c:1679 [inline]
__x64_sys_wait4+0x97/0xf0 kernel/exit.c:1679
do_syscall_64+0xfd/0x6a0 arch/x86/entry/common.c:296
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x41380a
Code: 0f 83 6a 18 00 00 c3 66 0f 1f 84 00 00 00 00 00 8b 05 8e 2a 66 00 85
c0 75 36 45 31 d2 48 63 d2 48 63 ff b8 3d 00 00 00 0f 05 <48> 3d 00 f0 ff
ff 77 06 c3 0f 1f 44 00 00 48 c7 c2 d4 ff ff ff f7
RSP: 002b:00007fffd24f2578 EFLAGS: 00000246 ORIG_RAX: 000000000000003d
RAX: ffffffffffffffda RBX: 000000000002b136 RCX: 000000000041380a
RDX: 0000000040000001 RSI: 00007fffd24f25b0 RDI: ffffffffffffffff
RBP: 0000000000000020 R08: 0000000000000001 R09: 0000555555b93940
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000011
R13: 00007fffd24f25b0 R14: 000000000002b0cb R15: 00007fffd24f25c0
Modules linked in:
CR2: ffffffffffffff6c
---[ end trace 9160f93910f7ba1d ]---
RIP: 0010:__read_once_size include/linux/compiler.h:199 [inline]
RIP: 0010:wait_consider_task+0xb3/0x38a0 kernel/exit.c:1349
Code: 00 00 48 89 c8 48 89 8d 48 ff ff ff 48 c1 e8 03 42 0f b6 14 20 48 89
c8 83 e0 07 83 c0 03 38 d0 7c 08 84 d2 0f 85 47 1a 00 00 <45> 8b a6 74 04
00 00 bf 10 00 00 00 44 89 e6 e8 19 94 2d 00 41 83
RSP: 0018:ffff88809f58faa0 EFLAGS: 00010246
RAX: 0000000000000007 RBX: 0000000000000000 RCX: ffffffffffffff6c
RDX: 0000000000000000 RSI: ffffffff8144de54 RDI: ffff88809f58fcb8
RBP: ffff88809f58fbc8 R08: ffff8880a916e640 R09: fffffbfff11c1219
R10: fffffbfff11c1218 R11: ffffffff88e090c3 R12: dffffc0000000000
R13: dffffc0000000000 R14: fffffffffffffaf8 R15: ffff88809f58fcb8
FS: 0000555555b93940(0000) GS:ffff8880ae900000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: ffffffffffffff6c CR3: 00000000a5c7c000 CR4: 00000000001406e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Nov 28, 2019, 3:23:05 PM11/28/19
to syzkaller-upst...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages