Hello,
syzbot found the following issue on:
HEAD commit: 2f693b607545 Linux 5.15.187
git tree: linux-5.15.y
console output:
https://syzkaller.appspot.com/x/log.txt?x=116a5d82580000
kernel config:
https://syzkaller.appspot.com/x/.config?x=ffb429fe3ba39a3c
dashboard link:
https://syzkaller.appspot.com/bug?extid=17595e1be20d57931171
compiler: Debian clang version 20.1.7 (++20250616065708+6146a88f6049-1~exp1~20250616065826.132), Debian LLD 20.1.7
userspace arch: arm64
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/129cdeb1c037/disk-2f693b60.raw.xz
vmlinux:
https://storage.googleapis.com/syzbot-assets/f163e8700a20/vmlinux-2f693b60.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/22c8c0cbe264/Image-2f693b60.gz.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+17595e...@syzkaller.appspotmail.com
------------[ cut here ]------------
WARNING: CPU: 1 PID: 136 at net/mac80211/rx.c:4911 ieee80211_rx_list+0x14f8/0x1e2c net/mac80211/rx.c:4911
Modules linked in:
CPU: 1 PID: 136 Comm: kworker/u4:1 Not tainted 5.15.187-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025
Workqueue: events_power_efficient check_lifetime
pstate: 40400005 (nZcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : ieee80211_rx_list+0x14f8/0x1e2c net/mac80211/rx.c:4911
lr : ieee80211_rx_list+0x14f8/0x1e2c net/mac80211/rx.c:4911
sp : ffff800008017a40
x29: ffff800008017c00 x28: ffff0000d1c510d0 x27: ffff700001002f60
x26: ffff0000d6af0dc0 x25: 1fffe0001a38a21a x24: dfff800000000000
x23: ffff0000d6af3368 x22: ffff0000d6af0e00 x21: ffff0000d6af15fc
x20: ffff800008017c80 x19: ffff0000d1c51000 x18: 0000000000000100
x17: 0000000000000000 x16: ffff8000111d162c x15: 0000000000000002
x14: 0000000000ff0100 x13: 1ffff0000283006b x12: 0000000000ff0100
x11: 0000000000000100 x10: 0000000000000000 x9 : ffff800010b6726c
x8 : ffff0000c0b89b40 x7 : ffff800010b7355c x6 : 0000000000000000
x5 : 0000000000000000 x4 : 0000000000000000 x3 : ffff800008017c80
x2 : ffff0000d1c51000 x1 : 0000000000000000 x0 : 0000000000000004
Call trace:
ieee80211_rx_list+0x14f8/0x1e2c net/mac80211/rx.c:4911
ieee80211_rx_napi+0x164/0x338 net/mac80211/rx.c:5009
ieee80211_rx include/net/mac80211.h:4571 [inline]
ieee80211_handle_queued_frames+0xe8/0x188 net/mac80211/main.c:237
ieee80211_tasklet_handler+0x20/0x30 net/mac80211/main.c:256
tasklet_action_common+0x340/0x3f4 kernel/softirq.c:-1
tasklet_action+0x60/0x84 kernel/softirq.c:827
handle_softirqs+0x344/0xbf0 kernel/softirq.c:576
__do_softirq kernel/softirq.c:610 [inline]
do_softirq_own_stack include/asm-generic/softirq_stack.h:10 [inline]
invoke_softirq kernel/softirq.c:457 [inline]
__irq_exit_rcu+0x240/0x440 kernel/softirq.c:659
irq_exit+0x14/0x88 kernel/softirq.c:683
handle_domain_irq+0x14c/0x1fc kernel/irq/irqdesc.c:711
gic_handle_irq+0x78/0x1c8 drivers/irqchip/irq-gic-v3.c:765
call_on_irq_stack+0x24/0x30 arch/arm64/kernel/entry.S:855
do_interrupt_handler+0x6c/0x88 arch/arm64/kernel/entry-common.c:267
el1_interrupt+0x30/0x58 arch/arm64/kernel/entry-common.c:454
el1h_64_irq_handler+0x18/0x24 arch/arm64/kernel/entry-common.c:470
el1h_64_irq+0x78/0x7c arch/arm64/kernel/entry.S:522
arch_local_irq_restore arch/arm64/include/asm/irqflags.h:122 [inline]
rcu_preempt_deferred_qs_irqrestore+0x280/0xd60 kernel/rcu/tree_plugin.h:568
rcu_read_unlock_special+0xac/0x428 kernel/rcu/tree_plugin.h:670
__rcu_read_unlock+0xa4/0x108 kernel/rcu/tree_plugin.h:422
rcu_read_unlock include/linux/rcupdate.h:771 [inline]
check_lifetime+0x3bc/0x878 net/ipv4/devinet.c:752
process_one_work+0x79c/0x1140 kernel/workqueue.c:2310
worker_thread+0x8f4/0x101c kernel/workqueue.c:2457
kthread+0x374/0x454 kernel/kthread.c:334
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:855
irq event stamp: 2274059
hardirqs last enabled at (2274058): [<ffff8000112ab724>] __raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:160 [inline]
hardirqs last enabled at (2274058): [<ffff8000112ab724>] _raw_spin_unlock_irqrestore+0xa8/0x14c kernel/locking/spinlock.c:194
hardirqs last disabled at (2274059): [<ffff8000111cce8c>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:396
softirqs last enabled at (2273876): [<ffff800010f516fc>] spin_unlock_bh include/linux/spinlock.h:408 [inline]
softirqs last enabled at (2273876): [<ffff800010f516fc>] batadv_nc_purge_paths+0x308/0x390 net/batman-adv/network-coding.c:475
softirqs last disabled at (2273933): [<ffff80000819efec>] __do_softirq kernel/softirq.c:610 [inline]
softirqs last disabled at (2273933): [<ffff80000819efec>] do_softirq_own_stack include/asm-generic/softirq_stack.h:10 [inline]
softirqs last disabled at (2273933): [<ffff80000819efec>] invoke_softirq kernel/softirq.c:457 [inline]
softirqs last disabled at (2273933): [<ffff80000819efec>] __irq_exit_rcu+0x240/0x440 kernel/softirq.c:659
---[ end trace 04add40d11cb875c ]---
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup