Hello,
syzbot found the following crash on:
HEAD commit: 47350a9f ANDROID: x86_64_cuttlefish_defconfig: Enable lz4 ..
git tree: android-4.14
console output:
https://syzkaller.appspot.com/x/log.txt?x=109a0151400000
kernel config:
https://syzkaller.appspot.com/x/.config?x=10d236078f3378a3
dashboard link:
https://syzkaller.appspot.com/bug?extid=57ddc5cc4954be1e328e
compiler: gcc (GCC) 8.0.1 20180413 (experimental)
syz repro:
https://syzkaller.appspot.com/x/repro.syz?x=13319d1e400000
C reproducer:
https://syzkaller.appspot.com/x/repro.c?x=105713a6400000
IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by:
syzbot+57ddc5...@syzkaller.appspotmail.com
------------[ cut here ]------------
WARNING: CPU: 1 PID: 2920 at net/xfrm/xfrm_state.c:2337
xfrm_state_fini+0x1e4/0x250 net/xfrm/xfrm_state.c:2337
Kernel panic - not syncing: panic_on_warn set ...
CPU: 1 PID: 2920 Comm: kworker/u4:7 Not tainted 4.14.67+ #1
Workqueue: netns cleanup_net
Call Trace:
__dump_stack lib/dump_stack.c:17 [inline]
dump_stack+0xb9/0x11b lib/dump_stack.c:53
panic+0x1bf/0x3a4 kernel/panic.c:181
__warn.cold.7+0x148/0x185 kernel/panic.c:542
report_bug+0x1f7/0x26c lib/bug.c:186
fixup_bug arch/x86/kernel/traps.c:177 [inline]
do_error_trap+0x1ba/0x2c0 arch/x86/kernel/traps.c:295
invalid_op+0x18/0x40 arch/x86/entry/entry_64.S:944
RIP: 0010:xfrm_state_fini+0x1e4/0x250 net/xfrm/xfrm_state.c:2337
RSP: 0018:ffff8801d338fbc0 EFLAGS: 00010297
RAX: ffff8801b6d21780 RBX: ffff8801d00d8000 RCX: 0000000000000000
RDX: 0000000000000000 RSI: ffff8801b6d22000 RDI: ffff8801b6d21fac
RBP: ffff8801d00d9200 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: ffff8801d338fce8
R13: ffffffff9adf6118 R14: dffffc0000000000 R15: fffffbfff35bec23
ops_exit_list.isra.3+0xa8/0x150 net/core/net_namespace.c:142
cleanup_net+0x3e9/0x880 net/core/net_namespace.c:483
process_one_work+0x86e/0x15c0 kernel/workqueue.c:2114
worker_thread+0xdc/0x1000 kernel/workqueue.c:2248
kthread+0x348/0x420 kernel/kthread.c:232
ret_from_fork+0x3a/0x50 arch/x86/entry/entry_64.S:402
Dumping ftrace buffer:
(ftrace buffer empty)
Kernel Offset: 0x17600000 from 0xffffffff81000000 (relocation range:
0xffffffff80000000-0xffffffffbfffffff)
Rebooting in 86400 seconds..
---
This bug is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this bug, for details see:
https://goo.gl/tpsmEJ#testing-patches