BUG: stack guard page was hit in __orc_find

4 views
Skip to first unread message

syzbot

unread,
Jul 1, 2021, 4:50:21 PM7/1/21
to syzkaller-upst...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: ff8744b5 Merge branch '100GbE' of git://git.kernel.org/pub..
git tree: net-next
console output: https://syzkaller.appspot.com/x/log.txt?x=13f1372c300000
kernel config: https://syzkaller.appspot.com/x/.config?x=7cf9abab1592f017
dashboard link: https://syzkaller.appspot.com/bug?extid=4e1ccdc40f48e600d960
CC: [b...@alien8.de h...@zytor.com jiri...@kernel.org jpoi...@redhat.com jthi...@redhat.com linux-...@vger.kernel.org mbe...@suse.cz mi...@redhat.com pet...@infradead.org tg...@linutronix.de x...@kernel.org net...@vger.kernel.org]

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+4e1ccd...@syzkaller.appspotmail.com

BUG: stack guard page was hit at ffffc9001232fff8 (stack is ffffc90012330000..ffffc90012337fff)
kernel stack overflow (double-fault): 0000 [#1] PREEMPT SMP KASAN
CPU: 0 PID: 21966 Comm: syz-executor.2 Not tainted 5.13.0-rc6-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
RIP: 0010:__orc_find+0xf/0xf0 arch/x86/kernel/unwind_orc.c:35
Code: cc cc cc cc cc cc cc cc cc cc cc 48 8b 07 c3 66 66 2e 0f 1f 84 00 00 00 00 00 90 41 57 89 d0 41 56 41 55 41 54 4c 8d 64 87 fc <55> 53 48 83 ec 10 85 d2 0f 84 95 00 00 00 4c 39 e7 49 89 fd 0f 87
RSP: 0018:ffffc90012330000 EFLAGS: 00010202
RAX: 0000000000000001 RBX: 1ffff9200246600d RCX: ffffffff81333bd5
RDX: 0000000000000001 RSI: ffffffff8e42e8ca RDI: ffffffff8dd67aec
RBP: 0000000000000001 R08: 0000000000000000 R09: ffffffff8e42e8ca
R10: fffff52002466035 R11: 0000000000084088 R12: ffffffff8dd67aec
R13: ffffc90012330185 R14: ffffc90012330150 R15: ffffffff81333bd5
FS: 00007f7859d5e700(0000) GS:ffff8880b9c00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: ffffc9001232fff8 CR3: 0000000082541000 CR4: 00000000001506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
orc_find arch/x86/kernel/unwind_orc.c:173 [inline]
unwind_next_frame+0x32a/0x1ce0 arch/x86/kernel/unwind_orc.c:443
__unwind_start+0x51b/0x800 arch/x86/kernel/unwind_orc.c:699
unwind_start arch/x86/include/asm/unwind.h:60 [inline]
arch_stack_walk+0x5c/0xe0 arch/x86/kernel/stacktrace.c:24
stack_trace_save+0x8c/0xc0 kernel/stacktrace.c:121
kasan_save_stack+0x1b/0x40 mm/kasan/common.c:38
kasan_set_track mm/kasan/common.c:46 [inline]
set_alloc_info mm/kasan/common.c:428 [inline]
__kasan_slab_alloc+0x84/0xa0 mm/kasan/common.c:461
kasan_slab_alloc include/linux/kasan.h:236 [inline]
slab_post_alloc_hook mm/slab.h:524 [inline]
slab_alloc_node mm/slub.c:2914 [inline]
kmem_cache_alloc_node+0x269/0x3e0 mm/slub.c:2950
__alloc_skb+0x20b/0x340 net/core/skbuff.c:414
alloc_skb include/linux/skbuff.h:1112 [inline]
nlmsg_new include/net/netlink.h:953 [inline]
rtmsg_ifinfo_build_skb+0x72/0x1a0 net/core/rtnetlink.c:3811
rtmsg_ifinfo_event net/core/rtnetlink.c:3847 [inline]
rtmsg_ifinfo_event net/core/rtnetlink.c:3838 [inline]
rtnetlink_event+0x123/0x1d0 net/core/rtnetlink.c:5625
notifier_call_chain+0xb5/0x200 kernel/notifier.c:83
call_netdevice_notifiers_info+0xb5/0x130 net/core/dev.c:2121
call_netdevice_notifiers_extack net/core/dev.c:2133 [inline]
call_netdevice_notifiers net/core/dev.c:2147 [inline]
netdev_features_change net/core/dev.c:1493 [inline]
netdev_sync_lower_features net/core/dev.c:9837 [inline]
__netdev_update_features+0x95d/0x17d0 net/core/dev.c:9984
netdev_change_features+0x61/0xb0 net/core/dev.c:10056
bond_compute_features+0x56c/0xaa0 drivers/net/bonding/bond_main.c:1329
bond_slave_netdev_event drivers/net/bonding/bond_main.c:3431 [inline]
bond_netdev_event+0x5d6/0xa80 drivers/net/bonding/bond_main.c:3471
notifier_call_chain+0xb5/0x200 kernel/notifier.c:83
call_netdevice_notifiers_info+0xb5/0x130 net/core/dev.c:2121
call_netdevice_notifiers_extack net/core/dev.c:2133 [inline]
call_netdevice_notifiers net/core/dev.c:2147 [inline]
netdev_features_change net/core/dev.c:1493 [inline]
netdev_sync_lower_features net/core/dev.c:9837 [inline]
__netdev_update_features+0x95d/0x17d0 net/core/dev.c:9984
netdev_change_features+0x61/0xb0 net/core/dev.c:10056
bond_compute_features+0x56c/0xaa0 drivers/net/bonding/bond_main.c:1329
bond_slave_netdev_event drivers/net/bonding/bond_main.c:3431 [inline]
bond_netdev_event+0x5d6/0xa80 drivers/net/bonding/bond_main.c:3471
notifier_call_chain+0xb5/0x200 kernel/notifier.c:83
call_netdevice_notifiers_info+0xb5/0x130 net/core/dev.c:2121
call_netdevice_notifiers_extack net/core/dev.c:2133 [inline]
call_netdevice_notifiers net/core/dev.c:2147 [inline]
netdev_features_change net/core/dev.c:1493 [inline]
netdev_sync_lower_features net/core/dev.c:9837 [inline]
__netdev_update_features+0x95d/0x17d0 net/core/dev.c:9984
netdev_change_features+0x61/0xb0 net/core/dev.c:10056
bond_compute_features+0x56c/0xaa0 drivers/net/bonding/bond_main.c:1329
bond_slave_netdev_event drivers/net/bonding/bond_main.c:3431 [inline]
bond_netdev_event+0x5d6/0xa80 drivers/net/bonding/bond_main.c:3471
notifier_call_chain+0xb5/0x200 kernel/notifier.c:83
call_netdevice_notifiers_info+0xb5/0x130 net/core/dev.c:2121
call_netdevice_notifiers_extack net/core/dev.c:2133 [inline]
call_netdevice_notifiers net/core/dev.c:2147 [inline]
netdev_features_change net/core/dev.c:1493 [inline]
netdev_sync_lower_features net/core/dev.c:9837 [inline]
__netdev_update_features+0x95d/0x17d0 net/core/dev.c:9984
netdev_change_features+0x61/0xb0 net/core/dev.c:10056
bond_compute_features+0x56c/0xaa0 drivers/net/bonding/bond_main.c:1329
bond_slave_netdev_event drivers/net/bonding/bond_main.c:3431 [inline]
bond_netdev_event+0x5d6/0xa80 drivers/net/bonding/bond_main.c:3471
notifier_call_chain+0xb5/0x200 kernel/notifier.c:83
call_netdevice_notifiers_info+0xb5/0x130 net/core/dev.c:2121
call_netdevice_notifiers_extack net/core/dev.c:2133 [inline]
call_netdevice_notifiers net/core/dev.c:2147 [inline]
netdev_features_change net/core/dev.c:1493 [inline]
netdev_sync_lower_features net/core/dev.c:9837 [inline]
__netdev_update_features+0x95d/0x17d0 net/core/dev.c:9984
netdev_change_features+0x61/0xb0 net/core/dev.c:10056
bond_compute_features+0x56c/0xaa0 drivers/net/bonding/bond_main.c:1329
bond_slave_netdev_event drivers/net/bonding/bond_main.c:3431 [inline]
bond_netdev_event+0x5d6/0xa80 drivers/net/bonding/bond_main.c:3471
notifier_call_chain+0xb5/0x200 kernel/notifier.c:83
call_netdevice_notifiers_info+0xb5/0x130 net/core/dev.c:2121
call_netdevice_notifiers_extack net/core/dev.c:2133 [inline]
call_netdevice_notifiers net/core/dev.c:2147 [inline]
netdev_features_change net/core/dev.c:1493 [inline]
netdev_sync_lower_features net/core/dev.c:9837 [inline]
__netdev_update_features+0x95d/0x17d0 net/core/dev.c:9984
netdev_change_features+0x61/0xb0 net/core/dev.c:10056
bond_compute_features+0x56c/0xaa0 drivers/net/bonding/bond_main.c:1329
bond_slave_netdev_event drivers/net/bonding/bond_main.c:3431 [inline]
bond_netdev_event+0x5d6/0xa80 drivers/net/bonding/bond_main.c:3471
notifier_call_chain+0xb5/0x200 kernel/notifier.c:83
call_netdevice_notifiers_info+0xb5/0x130 net/core/dev.c:2121
call_netdevice_notifiers_extack net/core/dev.c:2133 [inline]
call_netdevice_notifiers net/core/dev.c:2147 [inline]
netdev_features_change net/core/dev.c:1493 [inline]
netdev_sync_lower_features net/core/dev.c:9837 [inline]
__netdev_update_features+0x95d/0x17d0 net/core/dev.c:9984
netdev_change_features+0x61/0xb0 net/core/dev.c:10056
bond_compute_features+0x56c/0xaa0 drivers/net/bonding/bond_main.c:1329
bond_slave_netdev_event drivers/net/bonding/bond_main.c:3431 [inline]
bond_netdev_event+0x5d6/0xa80 drivers/net/bonding/bond_main.c:3471
notifier_call_chain+0xb5/0x200 kernel/notifier.c:83
call_netdevice_notifiers_info+0xb5/0x130 net/core/dev.c:2121
call_netdevice_notifiers_extack net/core/dev.c:2133 [inline]
call_netdevice_notifiers net/core/dev.c:2147 [inline]
netdev_features_change net/core/dev.c:1493 [inline]
netdev_sync_lower_features net/core/dev.c:9837 [inline]
__netdev_update_features+0x95d/0x17d0 net/core/dev.c:9984
netdev_change_features+0x61/0xb0 net/core/dev.c:10056
bond_compute_features+0x56c/0xaa0 drivers/net/bonding/bond_main.c:1329
bond_slave_netdev_event drivers/net/bonding/bond_main.c:3431 [inline]
bond_netdev_event+0x5d6/0xa80 drivers/net/bonding/bond_main.c:3471
notifier_call_chain+0xb5/0x200 kernel/notifier.c:83
call_netdevice_notifiers_info+0xb5/0x130 net/core/dev.c:2121
call_netdevice_notifiers_extack net/core/dev.c:2133 [inline]
call_netdevice_notifiers net/core/dev.c:2147 [inline]
netdev_features_change net/core/dev.c:1493 [inline]
netdev_sync_lower_features net/core/dev.c:9837 [inline]
__netdev_update_features+0x95d/0x17d0 net/core/dev.c:9984
netdev_change_features+0x61/0xb0 net/core/dev.c:10056
bond_compute_features+0x56c/0xaa0 drivers/net/bonding/bond_main.c:1329
bond_slave_netdev_event drivers/net/bonding/bond_main.c:3431 [inline]
bond_netdev_event+0x5d6/0xa80 drivers/net/bonding/bond_main.c:3471
notifier_call_chain+0xb5/0x200 kernel/notifier.c:83
call_netdevice_notifiers_info+0xb5/0x130 net/core/dev.c:2121
call_netdevice_notifiers_extack net/core/dev.c:2133 [inline]
call_netdevice_notifiers net/core/dev.c:2147 [inline]
netdev_features_change net/core/dev.c:1493 [inline]
netdev_sync_lower_features net/core/dev.c:9837 [inline]
__netdev_update_features+0x95d/0x17d0 net/core/dev.c:9984
netdev_change_features+0x61/0xb0 net/core/dev.c:10056
bond_compute_features+0x56c/0xaa0 drivers/net/bonding/bond_main.c:1329
bond_slave_netdev_event drivers/net/bonding/bond_main.c:3431 [inline]
bond_netdev_event+0x5d6/0xa80 drivers/net/bonding/bond_main.c:3471
notifier_call_chain+0xb5/0x200 kernel/notifier.c:83
call_netdevice_noti
Lost 408 message(s)!
---[ end trace 0d1e853915ded6cd ]---
RIP: 0010:__orc_find+0xf/0xf0 arch/x86/kernel/unwind_orc.c:35
Code: cc cc cc cc cc cc cc cc cc cc cc 48 8b 07 c3 66 66 2e 0f 1f 84 00 00 00 00 00 90 41 57 89 d0 41 56 41 55 41 54 4c 8d 64 87 fc <55> 53 48 83 ec 10 85 d2 0f 84 95 00 00 00 4c 39 e7 49 89 fd 0f 87
RSP: 0018:ffffc90012330000 EFLAGS: 00010202
RAX: 0000000000000001 RBX: 1ffff9200246600d RCX: ffffffff81333bd5
RDX: 0000000000000001 RSI: ffffffff8e42e8ca RDI: ffffffff8dd67aec
RBP: 0000000000000001 R08: 0000000000000000 R09: ffffffff8e42e8ca
R10: fffff52002466035 R11: 0000000000084088 R12: ffffffff8dd67aec
R13: ffffc90012330185 R14: ffffc90012330150 R15: ffffffff81333bd5
FS: 00007f7859d5e700(0000) GS:ffff8880b9c00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: ffffc9001232fff8 CR3: 0000000082541000 CR4: 00000000001506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

Dmitry Vyukov

unread,
Jul 13, 2021, 10:04:44 AM7/13/21
to syzbot, syzkaller-upst...@googlegroups.com
After https://github.com/google/syzkaller/commit/f415556d566aa67761414184f49b919c0869ed52
we should get a new, better report

#syz invalid
> --
> You received this message because you are subscribed to the Google Groups "syzkaller-upstream-moderation" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to syzkaller-upstream-m...@googlegroups.com.
> To view this discussion on the web visit https://groups.google.com/d/msgid/syzkaller-upstream-moderation/000000000000c89f4105c615fc4f%40google.com.
Reply all
Reply to author
Forward
0 new messages