[syzbot] [rdma?] kernel BUG in ib_device_get_by_netdev

0 views
Skip to first unread message

syzbot

unread,
2:34 AM (2 hours ago) 2:34 AM
to j...@ziepe.ca, le...@kernel.org, linux-...@vger.kernel.org, linux...@vger.kernel.org, syzkall...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 779cae956c83 Add linux-next specific files for 20260223
git tree: linux-next
console output: https://syzkaller.appspot.com/x/log.txt?x=13be455a580000
kernel config: https://syzkaller.appspot.com/x/.config?x=a3fcc8cba4273681
dashboard link: https://syzkaller.appspot.com/bug?extid=d4b5f56fae098a9ff611
compiler: Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/8e60025d7912/disk-779cae95.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/a9dd1cf82d19/vmlinux-779cae95.xz
kernel image: https://storage.googleapis.com/syzbot-assets/3c0e344b536d/bzImage-779cae95.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+d4b5f5...@syzkaller.appspotmail.com

------------[ cut here ]------------
kernel BUG at ./include/rdma/ib_verbs.h:4611!
Oops: invalid opcode: 0000 [#1] SMP KASAN PTI
CPU: 1 UID: 0 PID: 7532 Comm: syz.1.433 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2026
RIP: 0010:ib_device_try_get include/rdma/ib_verbs.h:4611 [inline]
RIP: 0010:ib_device_get_by_netdev+0x529/0x530 drivers/infiniband/core/device.c:2356
Code: 28 f9 48 8b 44 24 38 42 80 3c 30 00 74 08 4c 89 e7 e8 1b ad 92 f9 4d 8b 3c 24 e9 fd fe ff ff e8 2d e4 10 03 e8 28 85 28 f9 90 <0f> 0b 0f 1f 44 00 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90
RSP: 0018:ffffc9000493e640 EFLAGS: 00010283
RAX: ffffffff889d0d38 RBX: ffff88806d3e5104 RCX: 0000000000080000
RDX: ffffc9000d311000 RSI: 0000000000031136 RDI: 0000000000031137
RBP: ffffc9000493e720 R08: ffffffff889d0891 R09: ffffffff8e7602e0
R10: dffffc0000000000 R11: ffffffff88c6ab20 R12: ffff88807d7251b8
R13: ffff88806d3e4000 R14: dffffc0000000000 R15: 1ffff92000927cd0
FS: 00007fdd927f66c0(0000) GS:ffff88812555e000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000055558fbca4e8 CR3: 00000000796b6000 CR4: 00000000003526f0
Call Trace:
<TASK>
siw_netdev_event+0x4c/0x170 drivers/infiniband/sw/siw/siw_main.c:374
notifier_call_chain+0x1be/0x400 kernel/notifier.c:85
call_netdevice_notifiers_extack net/core/dev.c:2288 [inline]
call_netdevice_notifiers net/core/dev.c:2302 [inline]
netdev_features_change net/core/dev.c:1590 [inline]
netdev_change_features net/core/dev.c:11097 [inline]
netdev_compute_master_upper_features+0x91e/0xac0 net/core/dev.c:12869
bond_enslave+0x21cc/0x3c40 drivers/net/bonding/bond_main.c:2226
do_set_master+0x533/0x6d0 net/core/rtnetlink.c:2963
do_setlink+0x1018/0x4590 net/core/rtnetlink.c:3165
rtnl_changelink net/core/rtnetlink.c:3776 [inline]
__rtnl_newlink net/core/rtnetlink.c:3935 [inline]
rtnl_newlink+0x15a9/0x1be0 net/core/rtnetlink.c:4072
rtnetlink_rcv_msg+0x7d5/0xbe0 net/core/rtnetlink.c:6958
netlink_rcv_skb+0x232/0x4b0 net/netlink/af_netlink.c:2550
netlink_unicast_kernel net/netlink/af_netlink.c:1318 [inline]
netlink_unicast+0x80f/0x9b0 net/netlink/af_netlink.c:1344
netlink_sendmsg+0x813/0xb40 net/netlink/af_netlink.c:1894
sock_sendmsg_nosec+0x18f/0x1d0 net/socket.c:737
__sock_sendmsg net/socket.c:752 [inline]
____sys_sendmsg+0x589/0x8c0 net/socket.c:2610
___sys_sendmsg+0x2a5/0x360 net/socket.c:2664
__sys_sendmsg net/socket.c:2696 [inline]
__do_sys_sendmsg net/socket.c:2701 [inline]
__se_sys_sendmsg net/socket.c:2699 [inline]
__x64_sys_sendmsg+0x1bd/0x2a0 net/socket.c:2699
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x14d/0xf80 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fdd9459c629
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fdd927f6028 EFLAGS: 00000246 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007fdd94815fa0 RCX: 00007fdd9459c629
RDX: 0000000000000010 RSI: 0000200000000600 RDI: 0000000000000004
RBP: 00007fdd94632b39 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007fdd94816038 R14: 00007fdd94815fa0 R15: 00007ffc8f7a8198
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:ib_device_try_get include/rdma/ib_verbs.h:4611 [inline]
RIP: 0010:ib_device_get_by_netdev+0x529/0x530 drivers/infiniband/core/device.c:2356
Code: 28 f9 48 8b 44 24 38 42 80 3c 30 00 74 08 4c 89 e7 e8 1b ad 92 f9 4d 8b 3c 24 e9 fd fe ff ff e8 2d e4 10 03 e8 28 85 28 f9 90 <0f> 0b 0f 1f 44 00 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90
RSP: 0018:ffffc9000493e640 EFLAGS: 00010283
RAX: ffffffff889d0d38 RBX: ffff88806d3e5104 RCX: 0000000000080000
RDX: ffffc9000d311000 RSI: 0000000000031136 RDI: 0000000000031137
RBP: ffffc9000493e720 R08: ffffffff889d0891 R09: ffffffff8e7602e0
R10: dffffc0000000000 R11: ffffffff88c6ab20 R12: ffff88807d7251b8
R13: ffff88806d3e4000 R14: dffffc0000000000 R15: 1ffff92000927cd0
FS: 00007fdd927f66c0(0000) GS:ffff88812545e000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f8d20bc3484 CR3: 00000000796b6000 CR4: 00000000003526f0


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages