[syzbot] [fs?] memory leak in adfs_init_fs_context

9 views
Skip to first unread message

syzbot

unread,
Dec 13, 2025, 2:01:40 PM (3 days ago) Dec 13
to linux-...@vger.kernel.org, linux-...@vger.kernel.org, syzkall...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: cb015814f8b6 Merge tag 'f2fs-for-6.19-rc1' of git://git.ke..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=14d85a1a580000
kernel config: https://syzkaller.appspot.com/x/.config?x=69400c231dedfdcf
dashboard link: https://syzkaller.appspot.com/bug?extid=1c70732df5fd4f0e4fbb
compiler: gcc (Debian 12.2.0-14+deb12u1) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=17de9eb4580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=15b6d992580000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/59ea583a27f0/disk-cb015814.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/5251b8b465ee/vmlinux-cb015814.xz
kernel image: https://storage.googleapis.com/syzbot-assets/061ac7ae9ddf/bzImage-cb015814.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+1c7073...@syzkaller.appspotmail.com

BUG: memory leak
unreferenced object 0xffff888126345900 (size 64):
comm "syz.0.18", pid 6076, jiffies 4294944529
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 c0 01 3f 00 00 00 00 00 ..........?.....
backtrace (crc 45941a6b):
kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline]
slab_post_alloc_hook mm/slub.c:4953 [inline]
slab_alloc_node mm/slub.c:5258 [inline]
__kmalloc_cache_noprof+0x3b2/0x570 mm/slub.c:5766
kmalloc_noprof include/linux/slab.h:957 [inline]
kzalloc_noprof include/linux/slab.h:1094 [inline]
adfs_init_fs_context+0x26/0xe0 fs/adfs/super.c:440
alloc_fs_context+0x2a0/0x6e0 fs/fs_context.c:315
do_new_mount fs/namespace.c:3692 [inline]
path_mount+0x93f/0x1320 fs/namespace.c:4022
do_mount fs/namespace.c:4035 [inline]
__do_sys_mount fs/namespace.c:4224 [inline]
__se_sys_mount fs/namespace.c:4201 [inline]
__x64_sys_mount+0x1a2/0x1e0 fs/namespace.c:4201
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xa4/0xf80 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f

BUG: memory leak
unreferenced object 0xffff888126345f40 (size 64):
comm "syz.0.19", pid 6079, jiffies 4294944531
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 c0 01 3f 00 00 00 00 00 ..........?.....
backtrace (crc 45941a6b):
kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline]
slab_post_alloc_hook mm/slub.c:4953 [inline]
slab_alloc_node mm/slub.c:5258 [inline]
__kmalloc_cache_noprof+0x3b2/0x570 mm/slub.c:5766
kmalloc_noprof include/linux/slab.h:957 [inline]
kzalloc_noprof include/linux/slab.h:1094 [inline]
adfs_init_fs_context+0x26/0xe0 fs/adfs/super.c:440
alloc_fs_context+0x2a0/0x6e0 fs/fs_context.c:315
do_new_mount fs/namespace.c:3692 [inline]
path_mount+0x93f/0x1320 fs/namespace.c:4022
do_mount fs/namespace.c:4035 [inline]
__do_sys_mount fs/namespace.c:4224 [inline]
__se_sys_mount fs/namespace.c:4201 [inline]
__x64_sys_mount+0x1a2/0x1e0 fs/namespace.c:4201
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xa4/0xf80 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f

BUG: memory leak
unreferenced object 0xffff88812636ad40 (size 64):
comm "syz.0.20", pid 6128, jiffies 4294945167
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 c0 01 3f 00 00 00 00 00 ..........?.....
backtrace (crc 45941a6b):
kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline]
slab_post_alloc_hook mm/slub.c:4953 [inline]
slab_alloc_node mm/slub.c:5258 [inline]
__kmalloc_cache_noprof+0x3b2/0x570 mm/slub.c:5766
kmalloc_noprof include/linux/slab.h:957 [inline]
kzalloc_noprof include/linux/slab.h:1094 [inline]
adfs_init_fs_context+0x26/0xe0 fs/adfs/super.c:440
alloc_fs_context+0x2a0/0x6e0 fs/fs_context.c:315
do_new_mount fs/namespace.c:3692 [inline]
path_mount+0x93f/0x1320 fs/namespace.c:4022
do_mount fs/namespace.c:4035 [inline]
__do_sys_mount fs/namespace.c:4224 [inline]
__se_sys_mount fs/namespace.c:4201 [inline]
__x64_sys_mount+0x1a2/0x1e0 fs/namespace.c:4201
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xa4/0xf80 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f

BUG: memory leak
unreferenced object 0xffff888126345b40 (size 64):
comm "syz.0.21", pid 6129, jiffies 4294945168
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 c0 01 3f 00 00 00 00 00 ..........?.....
backtrace (crc 45941a6b):
kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline]
slab_post_alloc_hook mm/slub.c:4953 [inline]
slab_alloc_node mm/slub.c:5258 [inline]
__kmalloc_cache_noprof+0x3b2/0x570 mm/slub.c:5766
kmalloc_noprof include/linux/slab.h:957 [inline]
kzalloc_noprof include/linux/slab.h:1094 [inline]
adfs_init_fs_context+0x26/0xe0 fs/adfs/super.c:440
alloc_fs_context+0x2a0/0x6e0 fs/fs_context.c:315
do_new_mount fs/namespace.c:3692 [inline]
path_mount+0x93f/0x1320 fs/namespace.c:4022
do_mount fs/namespace.c:4035 [inline]
__do_sys_mount fs/namespace.c:4224 [inline]
__se_sys_mount fs/namespace.c:4201 [inline]
__x64_sys_mount+0x1a2/0x1e0 fs/namespace.c:4201
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xa4/0xf80 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f

connection error: failed to recv *flatrpc.ExecutorMessageRawT: EOF


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Dec 13, 2025, 5:36:25 PM (3 days ago) Dec 13
to linux-...@vger.kernel.org, syzkall...@googlegroups.com
For archival purposes, forwarding an incoming command email to
linux-...@vger.kernel.org, syzkall...@googlegroups.com.

***

Subject: memory leak in adfs_init_fs_context
Author: eray...@gmail.com

#syz test

syzbot

unread,
Dec 13, 2025, 6:12:04 PM (3 days ago) Dec 13
to eray...@gmail.com, linux-...@vger.kernel.org, syzkall...@googlegroups.com
Hello,

syzbot has tested the proposed patch and the reproducer did not trigger any issue:

Reported-by: syzbot+1c7073...@syzkaller.appspotmail.com
Tested-by: syzbot+1c7073...@syzkaller.appspotmail.com

Tested on:

commit: 4a298a43 Merge tag 'smp-urgent-2025-12-12' of git://gi..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=103d71b4580000
kernel config: https://syzkaller.appspot.com/x/.config?x=d60836e327fd6756
dashboard link: https://syzkaller.appspot.com/bug?extid=1c70732df5fd4f0e4fbb
compiler: gcc (Debian 12.2.0-14+deb12u1) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40
patch: https://syzkaller.appspot.com/x/patch.diff?x=104109c2580000

Note: testing is done by a robot and is best-effort only.

syzbot

unread,
Dec 14, 2025, 3:59:27 PM (2 days ago) Dec 14
to linux-...@vger.kernel.org, syzkall...@googlegroups.com

syzbot

unread,
Dec 14, 2025, 4:15:04 PM (2 days ago) Dec 14
to eray...@gmail.com, linux-...@vger.kernel.org, syzkall...@googlegroups.com
Hello,

syzbot has tested the proposed patch but the reproducer is still triggering an issue:
memory leak in adfs_init_fs_context

BUG: memory leak
unreferenced object 0xffff888128792680 (size 64):
comm "syz.0.17", pid 6733, jiffies 4294947442
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 c0 01 3f 00 00 00 00 00 ..........?.....
backtrace (crc 45941a6b):
kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline]
slab_post_alloc_hook mm/slub.c:4958 [inline]
slab_alloc_node mm/slub.c:5263 [inline]
__kmalloc_cache_noprof+0x3b2/0x570 mm/slub.c:5771
kmalloc_noprof include/linux/slab.h:957 [inline]
kzalloc_noprof include/linux/slab.h:1094 [inline]
adfs_init_fs_context+0x26/0xe0 fs/adfs/super.c:440
alloc_fs_context+0x2a0/0x6e0 fs/fs_context.c:315
do_new_mount fs/namespace.c:3692 [inline]
path_mount+0x93f/0x1320 fs/namespace.c:4022
do_mount fs/namespace.c:4035 [inline]
__do_sys_mount fs/namespace.c:4224 [inline]
__se_sys_mount fs/namespace.c:4201 [inline]
__x64_sys_mount+0x1a2/0x1e0 fs/namespace.c:4201
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xa4/0xf80 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f

BUG: memory leak
unreferenced object 0xffff888128792280 (size 64):
comm "syz.0.18", pid 6736, jiffies 4294947443
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 c0 01 3f 00 00 00 00 00 ..........?.....
backtrace (crc 45941a6b):
kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline]
slab_post_alloc_hook mm/slub.c:4958 [inline]
slab_alloc_node mm/slub.c:5263 [inline]
__kmalloc_cache_noprof+0x3b2/0x570 mm/slub.c:5771
kmalloc_noprof include/linux/slab.h:957 [inline]
kzalloc_noprof include/linux/slab.h:1094 [inline]
adfs_init_fs_context+0x26/0xe0 fs/adfs/super.c:440
alloc_fs_context+0x2a0/0x6e0 fs/fs_context.c:315
do_new_mount fs/namespace.c:3692 [inline]
path_mount+0x93f/0x1320 fs/namespace.c:4022
do_mount fs/namespace.c:4035 [inline]
__do_sys_mount fs/namespace.c:4224 [inline]
__se_sys_mount fs/namespace.c:4201 [inline]
__x64_sys_mount+0x1a2/0x1e0 fs/namespace.c:4201
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xa4/0xf80 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f

BUG: memory leak
unreferenced object 0xffff88811cb63040 (size 64):
comm "syz.0.19", pid 6739, jiffies 4294947445
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 c0 01 3f 00 00 00 00 00 ..........?.....
backtrace (crc 45941a6b):
kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline]
slab_post_alloc_hook mm/slub.c:4958 [inline]
slab_alloc_node mm/slub.c:5263 [inline]
__kmalloc_cache_noprof+0x3b2/0x570 mm/slub.c:5771
kmalloc_noprof include/linux/slab.h:957 [inline]
kzalloc_noprof include/linux/slab.h:1094 [inline]
adfs_init_fs_context+0x26/0xe0 fs/adfs/super.c:440
alloc_fs_context+0x2a0/0x6e0 fs/fs_context.c:315
do_new_mount fs/namespace.c:3692 [inline]
path_mount+0x93f/0x1320 fs/namespace.c:4022
do_mount fs/namespace.c:4035 [inline]
__do_sys_mount fs/namespace.c:4224 [inline]
__se_sys_mount fs/namespace.c:4201 [inline]
__x64_sys_mount+0x1a2/0x1e0 fs/namespace.c:4201
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xa4/0xf80 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f

BUG: memory leak
unreferenced object 0xffff888128792f80 (size 64):
comm "syz.0.20", pid 6770, jiffies 4294948013
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 c0 01 3f 00 00 00 00 00 ..........?.....
backtrace (crc 45941a6b):
kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline]
slab_post_alloc_hook mm/slub.c:4958 [inline]
slab_alloc_node mm/slub.c:5263 [inline]
__kmalloc_cache_noprof+0x3b2/0x570 mm/slub.c:5771
kmalloc_noprof include/linux/slab.h:957 [inline]
kzalloc_noprof include/linux/slab.h:1094 [inline]
adfs_init_fs_context+0x26/0xe0 fs/adfs/super.c:440
alloc_fs_context+0x2a0/0x6e0 fs/fs_context.c:315
do_new_mount fs/namespace.c:3692 [inline]
path_mount+0x93f/0x1320 fs/namespace.c:4022
do_mount fs/namespace.c:4035 [inline]
__do_sys_mount fs/namespace.c:4224 [inline]
__se_sys_mount fs/namespace.c:4201 [inline]
__x64_sys_mount+0x1a2/0x1e0 fs/namespace.c:4201
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xa4/0xf80 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f

BUG: memory leak
unreferenced object 0xffff88811cb63f80 (size 64):
comm "syz.0.21", pid 6772, jiffies 4294948014
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 c0 01 3f 00 00 00 00 00 ..........?.....
backtrace (crc 45941a6b):
kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline]
slab_post_alloc_hook mm/slub.c:4958 [inline]
slab_alloc_node mm/slub.c:5263 [inline]
__kmalloc_cache_noprof+0x3b2/0x570 mm/slub.c:5771
kmalloc_noprof include/linux/slab.h:957 [inline]
kzalloc_noprof include/linux/slab.h:1094 [inline]
adfs_init_fs_context+0x26/0xe0 fs/adfs/super.c:440
alloc_fs_context+0x2a0/0x6e0 fs/fs_context.c:315
do_new_mount fs/namespace.c:3692 [inline]
path_mount+0x93f/0x1320 fs/namespace.c:4022
do_mount fs/namespace.c:4035 [inline]
__do_sys_mount fs/namespace.c:4224 [inline]
__se_sys_mount fs/namespace.c:4201 [inline]
__x64_sys_mount+0x1a2/0x1e0 fs/namespace.c:4201
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xa4/0xf80 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f

connection error: failed to recv *flatrpc.ExecutorMessageRawT: EOF


Tested on:

commit: 8f0b4cce Linux 6.19-rc1
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=1275511a580000
kernel config: https://syzkaller.appspot.com/x/.config?x=d60836e327fd6756
dashboard link: https://syzkaller.appspot.com/bug?extid=1c70732df5fd4f0e4fbb
compiler: gcc (Debian 12.2.0-14+deb12u1) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40

Note: no patches were applied.

syzbot

unread,
Dec 14, 2025, 4:59:02 PM (2 days ago) Dec 14
to linux-...@vger.kernel.org, syzkall...@googlegroups.com

syzbot

unread,
Dec 14, 2025, 5:19:07 PM (2 days ago) Dec 14
to eray...@gmail.com, linux-...@vger.kernel.org, syzkall...@googlegroups.com
Hello,

syzbot tried to test the proposed patch but the build/boot failed:

SYZFAIL: failed to recv rpc

SYZFAIL: failed to recv rpc


Warning: Permanently added '10.128.1.225' (ED25519) to the list of known hosts.
2025/12/14 22:17:44 parsed 1 programs
[ 40.760074][ T5814] cgroup: Unknown subsys name 'net'
[ 40.846544][ T5814] cgroup: Unknown subsys name 'cpuset'
[ 40.853552][ T5814] cgroup: Unknown subsys name 'rlimit'
Setting up swapspace version 1, size = 127995904 bytes
[ 48.749814][ T5814] Adding 124996k swap on ./swap-file. Priority:0 extents:1 across:124996k
[ 49.998856][ T5827] soft_limit_in_bytes is deprecated and will be removed. Please report your usecase to linu...@kvack.org if you depend on this functionality.
[ 50.288759][ T5847] chnl_net:caif_netlink_parms(): no params data found
[ 50.313070][ T5847] bridge0: port 1(bridge_slave_0) entered blocking state
[ 50.320409][ T5847] bridge0: port 1(bridge_slave_0) entered disabled state
[ 50.327549][ T5847] bridge_slave_0: entered allmulticast mode
[ 50.333830][ T5847] bridge_slave_0: entered promiscuous mode
[ 50.341481][ T5847] bridge0: port 2(bridge_slave_1) entered blocking state
[ 50.349768][ T5847] bridge0: port 2(bridge_slave_1) entered disabled state
[ 50.357266][ T5847] bridge_slave_1: entered allmulticast mode
[ 50.363438][ T5847] bridge_slave_1: entered promiscuous mode
[ 50.374980][ T5847] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link
[ 50.384999][ T5847] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link
[ 50.398552][ T5847] team0: Port device team_slave_0 added
[ 50.404698][ T5847] team0: Port device team_slave_1 added
[ 50.415314][ T5847] batman_adv: batadv0: Adding interface: batadv_slave_0
[ 50.422257][ T5847] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1532 would solve the problem.
[ 50.448268][ T5847] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active
[ 50.459550][ T5847] batman_adv: batadv0: Adding interface: batadv_slave_1
[ 50.466792][ T5847] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1532 would solve the problem.
[ 50.492780][ T5847] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active
[ 50.511794][ T5847] hsr_slave_0: entered promiscuous mode
[ 50.517681][ T5847] hsr_slave_1: entered promiscuous mode
[ 50.546550][ T5847] netdevsim netdevsim0 netdevsim0: renamed from eth0
[ 50.554507][ T5847] netdevsim netdevsim0 netdevsim1: renamed from eth1
[ 50.562970][ T5847] netdevsim netdevsim0 netdevsim2: renamed from eth2
[ 50.570577][ T5847] netdevsim netdevsim0 netdevsim3: renamed from eth3
[ 50.582378][ T5847] bridge0: port 2(bridge_slave_1) entered blocking state
[ 50.589968][ T5847] bridge0: port 2(bridge_slave_1) entered forwarding state
[ 50.597254][ T5847] bridge0: port 1(bridge_slave_0) entered blocking state
[ 50.604285][ T5847] bridge0: port 1(bridge_slave_0) entered forwarding state
[ 50.620737][ T5847] 8021q: adding VLAN 0 to HW filter on device bond0
[ 50.629704][ T2110] bridge0: port 1(bridge_slave_0) entered disabled state
[ 50.637191][ T2110] bridge0: port 2(bridge_slave_1) entered disabled state
[ 50.646684][ T5847] 8021q: adding VLAN 0 to HW filter on device team0
[ 50.654959][ T182] bridge0: port 1(bridge_slave_0) entered blocking state
[ 50.662020][ T182] bridge0: port 1(bridge_slave_0) entered forwarding state
[ 50.671112][ T2110] bridge0: port 2(bridge_slave_1) entered blocking state
[ 50.678182][ T2110] bridge0: port 2(bridge_slave_1) entered forwarding state
[ 50.718813][ T5847] 8021q: adding VLAN 0 to HW filter on device batadv0
[ 50.733071][ T5847] veth0_vlan: entered promiscuous mode
[ 50.740227][ T5847] veth1_vlan: entered promiscuous mode
[ 50.750549][ T5847] veth0_macvtap: entered promiscuous mode
[ 50.757401][ T5847] veth1_macvtap: entered promiscuous mode
[ 50.767087][ T5847] batman_adv: batadv0: Interface activated: batadv_slave_0
[ 50.776195][ T5847] batman_adv: batadv0: Interface activated: batadv_slave_1
[ 50.784802][ T336] netdevsim netdevsim0 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0
[ 50.793680][ T336] netdevsim netdevsim0 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0
[ 50.802584][ T336] netdevsim netdevsim0 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0
[ 50.811945][ T336] netdevsim netdevsim0 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0
[ 50.857670][ T182] netdevsim netdevsim0 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0
[ 50.883843][ T5135] Bluetooth: hci0: unexpected cc 0x0c03 length: 249 > 1
[ 50.891691][ T5135] Bluetooth: hci0: unexpected cc 0x1003 length: 249 > 9
[ 50.899005][ T5135] Bluetooth: hci0: unexpected cc 0x1001 length: 249 > 9
[ 50.907282][ T5135] Bluetooth: hci0: unexpected cc 0x0c23 length: 249 > 4
[ 50.914721][ T182] netdevsim netdevsim0 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0
[ 50.915268][ T5135] Bluetooth: hci0: unexpected cc 0x0c38 length: 249 > 2
[ 50.976589][ T182] netdevsim netdevsim0 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0
[ 51.006628][ T182] netdevsim netdevsim0 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0
[ 51.264854][ T336] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50
[ 51.274453][ T336] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50
[ 51.284604][ T336] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50
[ 51.292718][ T336] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50
2025/12/14 22:17:56 executed programs: 0
[ 53.667289][ T182] bridge_slave_1: left allmulticast mode
[ 53.672948][ T182] bridge_slave_1: left promiscuous mode
[ 53.679429][ T182] bridge0: port 2(bridge_slave_1) entered disabled state
[ 53.686953][ T182] bridge_slave_0: left allmulticast mode
[ 53.692571][ T182] bridge_slave_0: left promiscuous mode
[ 53.698282][ T182] bridge0: port 1(bridge_slave_0) entered disabled state
[ 53.717145][ T182] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface
[ 53.726561][ T182] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface
[ 53.736266][ T182] bond0 (unregistering): Released all slaves
[ 53.806502][ T182] hsr_slave_0: left promiscuous mode
[ 53.811955][ T182] hsr_slave_1: left promiscuous mode
[ 53.817467][ T182] batman_adv: batadv0: Interface deactivated: batadv_slave_0
[ 53.824830][ T182] batman_adv: batadv0: Removing interface: batadv_slave_0
[ 53.832282][ T182] batman_adv: batadv0: Interface deactivated: batadv_slave_1
[ 53.839713][ T182] batman_adv: batadv0: Removing interface: batadv_slave_1
[ 53.848340][ T182] veth1_macvtap: left promiscuous mode
[ 53.853883][ T182] veth0_macvtap: left promiscuous mode
[ 53.859443][ T182] veth1_vlan: left promiscuous mode
[ 53.864652][ T182] veth0_vlan: left promiscuous mode
[ 53.887392][ T182] team0 (unregistering): Port device team_slave_1 removed
[ 53.897695][ T182] team0 (unregistering): Port device team_slave_0 removed
[ 57.036318][ T50] Bluetooth: hci0: unexpected cc 0x0c03 length: 249 > 1
[ 57.043825][ T50] Bluetooth: hci0: unexpected cc 0x1003 length: 249 > 9
[ 57.051141][ T50] Bluetooth: hci0: unexpected cc 0x1001 length: 249 > 9
[ 57.058534][ T50] Bluetooth: hci0: unexpected cc 0x0c23 length: 249 > 4
[ 57.065979][ T50] Bluetooth: hci0: unexpected cc 0x0c38 length: 249 > 2
[ 57.100904][ T5987] chnl_net:caif_netlink_parms(): no params data found
[ 57.119366][ T5987] bridge0: port 1(bridge_slave_0) entered blocking state
[ 57.127002][ T5987] bridge0: port 1(bridge_slave_0) entered disabled state
[ 57.134166][ T5987] bridge_slave_0: entered allmulticast mode
[ 57.140647][ T5987] bridge_slave_0: entered promiscuous mode
[ 57.147369][ T5987] bridge0: port 2(bridge_slave_1) entered blocking state
[ 57.154562][ T5987] bridge0: port 2(bridge_slave_1) entered disabled state
[ 57.161755][ T5987] bridge_slave_1: entered allmulticast mode
[ 57.167935][ T5987] bridge_slave_1: entered promiscuous mode
[ 57.178268][ T5987] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link
[ 57.188122][ T5987] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link
[ 57.201767][ T5987] team0: Port device team_slave_0 added
[ 57.208482][ T5987] team0: Port device team_slave_1 added
[ 57.219095][ T5987] batman_adv: batadv0: Adding interface: batadv_slave_0
[ 57.226090][ T5987] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1532 would solve the problem.
[ 57.252518][ T5987] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active
[ 57.263509][ T5987] batman_adv: batadv0: Adding interface: batadv_slave_1
[ 57.270689][ T5987] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1532 would solve the problem.
[ 57.296997][ T5987] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active
[ 57.313719][ T5987] hsr_slave_0: entered promiscuous mode
[ 57.319704][ T5987] hsr_slave_1: entered promiscuous mode
[ 57.491380][ T5987] netdevsim netdevsim0 netdevsim0: renamed from eth0
[ 57.500328][ T5987] netdevsim netdevsim0 netdevsim1: renamed from eth1
[ 57.508909][ T5987] netdevsim netdevsim0 netdevsim2: renamed from eth2
[ 57.517055][ T5987] netdevsim netdevsim0 netdevsim3: renamed from eth3
[ 57.546048][ T5987] bridge0: port 2(bridge_slave_1) entered blocking state
[ 57.553236][ T5987] bridge0: port 2(bridge_slave_1) entered forwarding state
[ 57.560592][ T5987] bridge0: port 1(bridge_slave_0) entered blocking state
[ 57.567746][ T5987] bridge0: port 1(bridge_slave_0) entered forwarding state
[ 57.588988][ T5987] 8021q: adding VLAN 0 to HW filter on device bond0
[ 57.602398][ T1914] bridge0: port 1(bridge_slave_0) entered disabled state
[ 57.615522][ T1914] bridge0: port 2(bridge_slave_1) entered disabled state
[ 57.631386][ T5987] 8021q: adding VLAN 0 to HW filter on device team0
[ 57.641134][ T182] bridge0: port 1(bridge_slave_0) entered blocking state
[ 57.648228][ T182] bridge0: port 1(bridge_slave_0) entered forwarding state
[ 57.657921][ T1914] bridge0: port 2(bridge_slave_1) entered blocking state
[ 57.665277][ T1914] bridge0: port 2(bridge_slave_1) entered forwarding state
[ 57.728484][ T5987] 8021q: adding VLAN 0 to HW filter on device batadv0
[ 57.753422][ T5987] veth0_vlan: entered promiscuous mode
[ 57.761873][ T5987] veth1_vlan: entered promiscuous mode
[ 57.776420][ T5987] veth0_macvtap: entered promiscuous mode
[ 57.783392][ T5987] veth1_macvtap: entered promiscuous mode
[ 57.793989][ T5987] batman_adv: batadv0: Interface activated: batadv_slave_0
[ 57.804351][ T5987] batman_adv: batadv0: Interface activated: batadv_slave_1
[ 57.814363][ T182] netdevsim netdevsim0 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0
[ 57.835300][ T182] netdevsim netdevsim0 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0
[ 57.844102][ T182] netdevsim netdevsim0 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0
[ 57.855680][ T182] netdevsim netdevsim0 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0
[ 57.872009][ T35] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50
SYZFAIL: failed to recv rpc
[ 57.879896][ T1914] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50
[ 57.888257][ T1914] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50
[ 57.895768][ T35] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50


syzkaller build log:
go env (err=<nil>)
AR='ar'
CC='gcc'
CGO_CFLAGS='-O2 -g'
CGO_CPPFLAGS=''
CGO_CXXFLAGS='-O2 -g'
CGO_ENABLED='1'
CGO_FFLAGS='-O2 -g'
CGO_LDFLAGS='-O2 -g'
CXX='g++'
GCCGO='gccgo'
GO111MODULE='auto'
GOAMD64='v1'
GOARCH='amd64'
GOAUTH='netrc'
GOBIN=''
GOCACHE='/syzkaller/.cache/go-build'
GOCACHEPROG=''
GODEBUG=''
GOENV='/syzkaller/.config/go/env'
GOEXE=''
GOEXPERIMENT=''
GOFIPS140='off'
GOFLAGS=''
GOGCCFLAGS='-fPIC -m64 -pthread -Wl,--no-gc-sections -fmessage-length=0 -ffile-prefix-map=/tmp/go-build3133765014=/tmp/go-build -gno-record-gcc-switches'
GOHOSTARCH='amd64'
GOHOSTOS='linux'
GOINSECURE=''
GOMOD='/syzkaller/jobs-2/linux/gopath/src/github.com/google/syzkaller/go.mod'
GOMODCACHE='/syzkaller/jobs-2/linux/gopath/pkg/mod'
GONOPROXY=''
GONOSUMDB=''
GOOS='linux'
GOPATH='/syzkaller/jobs-2/linux/gopath'
GOPRIVATE=''
GOPROXY='https://proxy.golang.org,direct'
GOROOT='/usr/local/go'
GOSUMDB='sum.golang.org'
GOTELEMETRY='local'
GOTELEMETRYDIR='/syzkaller/.config/go/telemetry'
GOTMPDIR=''
GOTOOLCHAIN='auto'
GOTOOLDIR='/usr/local/go/pkg/tool/linux_amd64'
GOVCS=''
GOVERSION='go1.24.4'
GOWORK=''
PKG_CONFIG='pkg-config'

git status (err=<nil>)
HEAD detached at d6526ea3e
nothing to commit, working tree clean


tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
go list -f '{{.Stale}}' -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=d6526ea3e6ad9081c902859bbb80f9f840377cb4 -X github.com/google/syzkaller/prog.gitRevisionDate=20251126-113115" ./sys/syz-sysgen | grep -q false || go install -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=d6526ea3e6ad9081c902859bbb80f9f840377cb4 -X github.com/google/syzkaller/prog.gitRevisionDate=20251126-113115" ./sys/syz-sysgen
make .descriptions
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
bin/syz-sysgen
touch .descriptions
GOOS=linux GOARCH=amd64 go build -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=d6526ea3e6ad9081c902859bbb80f9f840377cb4 -X github.com/google/syzkaller/prog.gitRevisionDate=20251126-113115" -o ./bin/linux_amd64/syz-execprog github.com/google/syzkaller/tools/syz-execprog
mkdir -p ./bin/linux_amd64
g++ -o ./bin/linux_amd64/syz-executor executor/executor.cc \
-m64 -O2 -pthread -Wall -Werror -Wparentheses -Wunused-const-variable -Wframe-larger-than=16384 -Wno-stringop-overflow -Wno-array-bounds -Wno-format-overflow -Wno-unused-but-set-variable -Wno-unused-command-line-argument -static-pie -std=c++17 -I. -Iexecutor/_include -DGOOS_linux=1 -DGOARCH_amd64=1 \
-DHOSTGOOS_linux=1 -DGIT_REVISION=\"d6526ea3e6ad9081c902859bbb80f9f840377cb4\"
/usr/bin/ld: /tmp/ccLbkRWx.o: in function `Connection::Connect(char const*, char const*)':
executor.cc:(.text._ZN10Connection7ConnectEPKcS1_[_ZN10Connection7ConnectEPKcS1_]+0x104): warning: Using 'gethostbyname' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking
./tools/check-syzos.sh 2>/dev/null



Tested on:

commit: 8f0b4cce Linux 6.19-rc1
git tree: upstream
kernel config: https://syzkaller.appspot.com/x/.config?x=d60836e327fd6756
dashboard link: https://syzkaller.appspot.com/bug?extid=1c70732df5fd4f0e4fbb
compiler: gcc (Debian 12.2.0-14+deb12u1) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40
patch: https://syzkaller.appspot.com/x/patch.diff?x=166d99c2580000

syzbot

unread,
Dec 14, 2025, 5:27:40 PM (2 days ago) Dec 14
to linux-...@vger.kernel.org, syzkall...@googlegroups.com

syzbot

unread,
Dec 14, 2025, 5:44:03 PM (2 days ago) Dec 14
to eray...@gmail.com, linux-...@vger.kernel.org, syzkall...@googlegroups.com
Hello,

syzbot tried to test the proposed patch but the build/boot failed:

SYZFAIL: failed to recv rpc

SYZFAIL: failed to recv rpc
fd=3 want=4 recv=0 n=0 (errno 9: Bad file descriptor)


Warning: Permanently added '10.128.1.213' (ED25519) to the list of known hosts.
2025/12/14 22:43:18 parsed 1 programs
[ 37.712373][ T5814] cgroup: Unknown subsys name 'net'
[ 37.852708][ T5814] cgroup: Unknown subsys name 'cpuset'
[ 37.858990][ T5814] cgroup: Unknown subsys name 'rlimit'
Setting up swapspace version 1, size = 127995904 bytes
[ 45.793734][ T5814] Adding 124996k swap on ./swap-file. Priority:0 extents:1 across:124996k
[ 47.027391][ T5825] soft_limit_in_bytes is deprecated and will be removed. Please report your usecase to linu...@kvack.org if you depend on this functionality.
[ 47.298490][ T5848] chnl_net:caif_netlink_parms(): no params data found
[ 47.317351][ T5848] bridge0: port 1(bridge_slave_0) entered blocking state
[ 47.324739][ T5848] bridge0: port 1(bridge_slave_0) entered disabled state
[ 47.331833][ T5848] bridge_slave_0: entered allmulticast mode
[ 47.338011][ T5848] bridge_slave_0: entered promiscuous mode
[ 47.344534][ T5848] bridge0: port 2(bridge_slave_1) entered blocking state
[ 47.351584][ T5848] bridge0: port 2(bridge_slave_1) entered disabled state
[ 47.358656][ T5848] bridge_slave_1: entered allmulticast mode
[ 47.364787][ T5848] bridge_slave_1: entered promiscuous mode
[ 47.376139][ T5848] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link
[ 47.385864][ T5848] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link
[ 47.398694][ T5848] team0: Port device team_slave_0 added
[ 47.404689][ T5848] team0: Port device team_slave_1 added
[ 47.418227][ T5848] batman_adv: batadv0: Adding interface: batadv_slave_0
[ 47.425170][ T5848] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1532 would solve the problem.
[ 47.451033][ T5848] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active
[ 47.461955][ T5848] batman_adv: batadv0: Adding interface: batadv_slave_1
[ 47.468871][ T5848] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1532 would solve the problem.
[ 47.494836][ T5848] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active
[ 47.511287][ T5848] hsr_slave_0: entered promiscuous mode
[ 47.517050][ T5848] hsr_slave_1: entered promiscuous mode
[ 47.544260][ T5848] netdevsim netdevsim0 netdevsim0: renamed from eth0
[ 47.551678][ T5848] netdevsim netdevsim0 netdevsim1: renamed from eth1
[ 47.559215][ T5848] netdevsim netdevsim0 netdevsim2: renamed from eth2
[ 47.567128][ T5848] netdevsim netdevsim0 netdevsim3: renamed from eth3
[ 47.579629][ T5848] bridge0: port 2(bridge_slave_1) entered blocking state
[ 47.586718][ T5848] bridge0: port 2(bridge_slave_1) entered forwarding state
[ 47.593955][ T5848] bridge0: port 1(bridge_slave_0) entered blocking state
[ 47.600960][ T5848] bridge0: port 1(bridge_slave_0) entered forwarding state
[ 47.617557][ T5848] 8021q: adding VLAN 0 to HW filter on device bond0
[ 47.626433][ T2113] bridge0: port 1(bridge_slave_0) entered disabled state
[ 47.634115][ T2113] bridge0: port 2(bridge_slave_1) entered disabled state
[ 47.643636][ T5848] 8021q: adding VLAN 0 to HW filter on device team0
[ 47.651827][ T58] bridge0: port 1(bridge_slave_0) entered blocking state
[ 47.658866][ T58] bridge0: port 1(bridge_slave_0) entered forwarding state
[ 47.667451][ T2113] bridge0: port 2(bridge_slave_1) entered blocking state
[ 47.674493][ T2113] bridge0: port 2(bridge_slave_1) entered forwarding state
[ 47.712493][ T5848] 8021q: adding VLAN 0 to HW filter on device batadv0
[ 47.726799][ T5848] veth0_vlan: entered promiscuous mode
[ 47.733467][ T5848] veth1_vlan: entered promiscuous mode
[ 47.743510][ T5848] veth0_macvtap: entered promiscuous mode
[ 47.749952][ T5848] veth1_macvtap: entered promiscuous mode
[ 47.758532][ T5848] batman_adv: batadv0: Interface activated: batadv_slave_0
[ 47.767484][ T5848] batman_adv: batadv0: Interface activated: batadv_slave_1
[ 47.776289][ T2113] netdevsim netdevsim0 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0
[ 47.785155][ T2113] netdevsim netdevsim0 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0
[ 47.793957][ T2113] netdevsim netdevsim0 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0
[ 47.803186][ T2113] netdevsim netdevsim0 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0
[ 47.857905][ T35] netdevsim netdevsim0 netdevsim3 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0
[ 47.893462][ T35] netdevsim netdevsim0 netdevsim2 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0
[ 47.943714][ T35] netdevsim netdevsim0 netdevsim1 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0
[ 48.003482][ T35] netdevsim netdevsim0 netdevsim0 (unregistering): unset [1, 0] type 2 family 0 port 6081 - 0
[ 48.014825][ T58] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50
[ 48.024771][ T58] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50
[ 48.034932][ T1938] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50
[ 48.042907][ T1938] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50
[ 48.069136][ T5135] Bluetooth: hci0: unexpected cc 0x0c03 length: 249 > 1
[ 48.082403][ T5135] Bluetooth: hci0: unexpected cc 0x1003 length: 249 > 9
[ 48.089470][ T5135] Bluetooth: hci0: unexpected cc 0x1001 length: 249 > 9
[ 48.097107][ T5135] Bluetooth: hci0: unexpected cc 0x0c23 length: 249 > 4
[ 48.104358][ T5135] Bluetooth: hci0: unexpected cc 0x0c38 length: 249 > 2
2025/12/14 22:43:30 executed programs: 0
[ 50.851981][ T35] bridge_slave_1: left allmulticast mode
[ 50.857735][ T35] bridge_slave_1: left promiscuous mode
[ 50.863350][ T35] bridge0: port 2(bridge_slave_1) entered disabled state
[ 50.870740][ T35] bridge_slave_0: left allmulticast mode
[ 50.876445][ T35] bridge_slave_0: left promiscuous mode
[ 50.882278][ T35] bridge0: port 1(bridge_slave_0) entered disabled state
[ 50.943824][ T35] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface
[ 50.952823][ T35] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface
[ 50.961629][ T35] bond0 (unregistering): Released all slaves
[ 51.016728][ T35] hsr_slave_0: left promiscuous mode
[ 51.022435][ T35] hsr_slave_1: left promiscuous mode
[ 51.027855][ T35] batman_adv: batadv0: Interface deactivated: batadv_slave_0
[ 51.035519][ T35] batman_adv: batadv0: Removing interface: batadv_slave_0
[ 51.042948][ T35] batman_adv: batadv0: Interface deactivated: batadv_slave_1
[ 51.050311][ T35] batman_adv: batadv0: Removing interface: batadv_slave_1
[ 51.058439][ T35] veth1_macvtap: left promiscuous mode
[ 51.063920][ T35] veth0_macvtap: left promiscuous mode
[ 51.069372][ T35] veth1_vlan: left promiscuous mode
[ 51.074576][ T35] veth0_vlan: left promiscuous mode
[ 51.096386][ T35] team0 (unregistering): Port device team_slave_1 removed
[ 51.104418][ T35] team0 (unregistering): Port device team_slave_0 removed
[ 53.746742][ T50] Bluetooth: hci0: unexpected cc 0x0c03 length: 249 > 1
[ 53.753850][ T50] Bluetooth: hci0: unexpected cc 0x1003 length: 249 > 9
[ 53.760895][ T50] Bluetooth: hci0: unexpected cc 0x1001 length: 249 > 9
[ 53.768537][ T50] Bluetooth: hci0: unexpected cc 0x0c23 length: 249 > 4
[ 53.775682][ T50] Bluetooth: hci0: unexpected cc 0x0c38 length: 249 > 2
[ 53.808761][ T5985] chnl_net:caif_netlink_parms(): no params data found
[ 53.826975][ T5985] bridge0: port 1(bridge_slave_0) entered blocking state
[ 53.834029][ T5985] bridge0: port 1(bridge_slave_0) entered disabled state
[ 53.841055][ T5985] bridge_slave_0: entered allmulticast mode
[ 53.847228][ T5985] bridge_slave_0: entered promiscuous mode
[ 53.853510][ T5985] bridge0: port 2(bridge_slave_1) entered blocking state
[ 53.861516][ T5985] bridge0: port 2(bridge_slave_1) entered disabled state
[ 53.868608][ T5985] bridge_slave_1: entered allmulticast mode
[ 53.874881][ T5985] bridge_slave_1: entered promiscuous mode
[ 53.885891][ T5985] bond0: (slave bond_slave_0): Enslaving as an active interface with an up link
[ 53.895676][ T5985] bond0: (slave bond_slave_1): Enslaving as an active interface with an up link
[ 53.908861][ T5985] team0: Port device team_slave_0 added
[ 53.914938][ T5985] team0: Port device team_slave_1 added
[ 53.924223][ T5985] batman_adv: batadv0: Adding interface: batadv_slave_0
[ 53.931143][ T5985] batman_adv: batadv0: The MTU of interface batadv_slave_0 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1532 would solve the problem.
[ 53.957319][ T5985] batman_adv: batadv0: Not using interface batadv_slave_0 (retrying later): interface not active
[ 53.968209][ T5985] batman_adv: batadv0: Adding interface: batadv_slave_1
[ 53.975179][ T5985] batman_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1532 would solve the problem.
[ 54.001082][ T5985] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active
[ 54.017628][ T5985] hsr_slave_0: entered promiscuous mode
[ 54.023372][ T5985] hsr_slave_1: entered promiscuous mode
[ 54.191291][ T5985] netdevsim netdevsim0 netdevsim0: renamed from eth0
[ 54.199056][ T5985] netdevsim netdevsim0 netdevsim1: renamed from eth1
[ 54.207354][ T5985] netdevsim netdevsim0 netdevsim2: renamed from eth2
[ 54.215704][ T5985] netdevsim netdevsim0 netdevsim3: renamed from eth3
[ 54.230450][ T5985] bridge0: port 2(bridge_slave_1) entered blocking state
[ 54.237523][ T5985] bridge0: port 2(bridge_slave_1) entered forwarding state
[ 54.244770][ T5985] bridge0: port 1(bridge_slave_0) entered blocking state
[ 54.251818][ T5985] bridge0: port 1(bridge_slave_0) entered forwarding state
[ 54.272254][ T5985] 8021q: adding VLAN 0 to HW filter on device bond0
[ 54.282436][ T35] bridge0: port 1(bridge_slave_0) entered disabled state
[ 54.289785][ T35] bridge0: port 2(bridge_slave_1) entered disabled state
[ 54.300458][ T5985] 8021q: adding VLAN 0 to HW filter on device team0
[ 54.309349][ T989] bridge0: port 1(bridge_slave_0) entered blocking state
[ 54.316418][ T989] bridge0: port 1(bridge_slave_0) entered forwarding state
[ 54.330130][ T35] bridge0: port 2(bridge_slave_1) entered blocking state
[ 54.337171][ T35] bridge0: port 2(bridge_slave_1) entered forwarding state
[ 54.399081][ T5985] 8021q: adding VLAN 0 to HW filter on device batadv0
[ 54.416251][ T5985] veth0_vlan: entered promiscuous mode
[ 54.423550][ T5985] veth1_vlan: entered promiscuous mode
[ 54.436241][ T5985] veth0_macvtap: entered promiscuous mode
[ 54.443995][ T5985] veth1_macvtap: entered promiscuous mode
[ 54.453630][ T5985] batman_adv: batadv0: Interface activated: batadv_slave_0
[ 54.463191][ T5985] batman_adv: batadv0: Interface activated: batadv_slave_1
[ 54.473958][ T35] netdevsim netdevsim0 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0
[ 54.485525][ T35] netdevsim netdevsim0 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0
[ 54.495458][ T35] netdevsim netdevsim0 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0
[ 54.504485][ T35] netdevsim netdevsim0 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0
[ 54.524250][ T989] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50
[ 54.536235][ T989] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50
SYZFAIL: failed to recv rpc
fd=3 want=4 recv=0 n=0 (errno 9: Bad file descriptor)
[ 54.547638][ T989] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50
[ 54.555615][ T989] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50
GOGCCFLAGS='-fPIC -m64 -pthread -Wl,--no-gc-sections -fmessage-length=0 -ffile-prefix-map=/tmp/go-build3573500242=/tmp/go-build -gno-record-gcc-switches'
/usr/bin/ld: /tmp/cc0hxglS.o: in function `Connection::Connect(char const*, char const*)':
executor.cc:(.text._ZN10Connection7ConnectEPKcS1_[_ZN10Connection7ConnectEPKcS1_]+0x104): warning: Using 'gethostbyname' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking
./tools/check-syzos.sh 2>/dev/null



Tested on:

commit: 8f0b4cce Linux 6.19-rc1
git tree: upstream
kernel config: https://syzkaller.appspot.com/x/.config?x=d60836e327fd6756
dashboard link: https://syzkaller.appspot.com/bug?extid=1c70732df5fd4f0e4fbb
compiler: gcc (Debian 12.2.0-14+deb12u1) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40
patch: https://syzkaller.appspot.com/x/patch.diff?x=14e1811a580000

syzbot

unread,
Dec 14, 2025, 6:39:41 PM (2 days ago) Dec 14
to linux-...@vger.kernel.org, syzkall...@googlegroups.com

syzbot

unread,
Dec 14, 2025, 7:11:06 PM (2 days ago) Dec 14
to eray...@gmail.com, linux-...@vger.kernel.org, syzkall...@googlegroups.com
Hello,

syzbot has tested the proposed patch and the reproducer did not trigger any issue:

Reported-by: syzbot+1c7073...@syzkaller.appspotmail.com
Tested-by: syzbot+1c7073...@syzkaller.appspotmail.com

Tested on:

commit: 8f0b4cce Linux 6.19-rc1
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=1203811a580000
kernel config: https://syzkaller.appspot.com/x/.config?x=d60836e327fd6756
dashboard link: https://syzkaller.appspot.com/bug?extid=1c70732df5fd4f0e4fbb
compiler: gcc (Debian 12.2.0-14+deb12u1) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40
patch: https://syzkaller.appspot.com/x/patch.diff?x=16b799c2580000
Reply all
Reply to author
Forward
0 new messages