WARNING: ODEBUG bug in slave_kobj_release

13 views
Skip to first unread message

syzbot

unread,
Dec 13, 2020, 7:48:10 PM12/13/20
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 13d2ce42 Linux 4.19.163
git tree: linux-4.19.y
console output: https://syzkaller.appspot.com/x/log.txt?x=11dbcc13500000
kernel config: https://syzkaller.appspot.com/x/.config?x=fac7c3360835a4e0
dashboard link: https://syzkaller.appspot.com/bug?extid=1511a8ea3aaf5750f2ab
compiler: gcc (GCC) 10.1.0-syz 20200507

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+1511a8...@syzkaller.appspotmail.com

R13: 00007ffe9945d74f R14: 00007f88f682f9c0 R15: 000000000119bf8c
kobject_add_internal failed for bonding_slave (error: -12 parent: ipvlan1)
------------[ cut here ]------------
ODEBUG: assert_init not available (active state 0) object type: timer_list hint: (null)
WARNING: CPU: 0 PID: 11782 at lib/debugobjects.c:325 debug_print_object+0x160/0x250 lib/debugobjects.c:325
Kernel panic - not syncing: panic_on_warn set ...

CPU: 0 PID: 11782 Comm: syz-executor.4 Not tainted 4.19.163-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x1fc/0x2fe lib/dump_stack.c:118
panic+0x26a/0x50e kernel/panic.c:186
__warn.cold+0x20/0x61 kernel/panic.c:541
report_bug+0x262/0x2b0 lib/bug.c:186
fixup_bug arch/x86/kernel/traps.c:178 [inline]
fixup_bug arch/x86/kernel/traps.c:173 [inline]
do_error_trap+0x1d7/0x310 arch/x86/kernel/traps.c:296
invalid_op+0x14/0x20 arch/x86/entry/entry_64.S:1038
RIP: 0010:debug_print_object+0x160/0x250 lib/debugobjects.c:325
Code: dd e0 ca b3 88 48 89 fa 48 c1 ea 03 80 3c 02 00 0f 85 bf 00 00 00 48 8b 14 dd e0 ca b3 88 48 c7 c7 00 bf b3 88 e8 fb 80 b8 fd <0f> 0b 83 05 23 b6 a6 07 01 48 83 c4 20 5b 5d 41 5c 41 5d c3 48 89
RSP: 0018:ffff8880494a6d28 EFLAGS: 00010082
RAX: 0000000000000000 RBX: 0000000000000005 RCX: 0000000000000000
RDX: 0000000000040000 RSI: ffffffff814fdbb1 RDI: ffffed1009294d97
RBP: 0000000000000001 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000000005 R11: ffffffff8c65b01b R12: ffffffff89f90700
R13: ffffffff81554330 R14: ffff888093954178 R15: 1ffff11009294db0
debug_object_assert_init lib/debugobjects.c:694 [inline]
debug_object_assert_init+0x1f0/0x2e0 lib/debugobjects.c:665
debug_timer_assert_init kernel/time/timer.c:733 [inline]
debug_assert_init kernel/time/timer.c:785 [inline]
del_timer+0x6d/0x100 kernel/time/timer.c:1210
try_to_grab_pending+0x2b6/0x6f0 kernel/workqueue.c:1223
__cancel_work_timer+0xa6/0x590 kernel/workqueue.c:2974
slave_kobj_release+0x48/0xe0 drivers/net/bonding/bond_main.c:1276
kobject_cleanup lib/kobject.c:662 [inline]
kobject_release lib/kobject.c:691 [inline]
kref_put include/linux/kref.h:70 [inline]
kobject_put+0x28b/0x5d0 lib/kobject.c:708
bond_alloc_slave drivers/net/bonding/bond_main.c:1321 [inline]
bond_enslave+0xe53/0x5230 drivers/net/bonding/bond_main.c:1517
do_set_master+0x1c8/0x220 net/core/rtnetlink.c:2321
do_setlink+0x7ec/0x3540 net/core/rtnetlink.c:2455
rtnl_setlink+0x243/0x350 net/core/rtnetlink.c:2709
rtnetlink_rcv_msg+0x453/0xb80 net/core/rtnetlink.c:4778
netlink_rcv_skb+0x160/0x440 net/netlink/af_netlink.c:2455
netlink_unicast_kernel net/netlink/af_netlink.c:1318 [inline]
netlink_unicast+0x4d5/0x690 net/netlink/af_netlink.c:1344
netlink_sendmsg+0x6bb/0xc40 net/netlink/af_netlink.c:1909
sock_sendmsg_nosec net/socket.c:622 [inline]
sock_sendmsg+0xc3/0x120 net/socket.c:632
___sys_sendmsg+0x7bb/0x8e0 net/socket.c:2115
__sys_sendmsg net/socket.c:2153 [inline]
__do_sys_sendmsg net/socket.c:2162 [inline]
__se_sys_sendmsg net/socket.c:2160 [inline]
__x64_sys_sendmsg+0x132/0x220 net/socket.c:2160
do_syscall_64+0xf9/0x620 arch/x86/entry/common.c:293
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x45e159
Code: 0d b4 fb ff c3 66 2e 0f 1f 84 00 00 00 00 00 66 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 0f 83 db b3 fb ff c3 66 2e 0f 1f 84 00 00 00 00
RSP: 002b:00007f88f682ec68 EFLAGS: 00000246 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 0000000000000004 RCX: 000000000045e159
RDX: 0000000000000000 RSI: 00000000200002c0 RDI: 0000000000000003
RBP: 00007f88f682eca0 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000004
R13: 00007ffe9945d74f R14: 00007f88f682f9c0 R15: 000000000119bf8c
Kernel Offset: disabled
Rebooting in 86400 seconds..


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Dec 13, 2020, 8:04:11 PM12/13/20
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 13d2ce42 Linux 4.19.163
git tree: linux-4.19.y
console output: https://syzkaller.appspot.com/x/log.txt?x=12fdad37500000
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1629d487500000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=15db5f07500000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+1511a8...@syzkaller.appspotmail.com

R10: 0000000000000000 R11: 0000000000000246 R12: 00007ffea2daca00
R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000
kobject_add_internal failed for bonding_slave (error: -12 parent: ipvlan1)
------------[ cut here ]------------
ODEBUG: assert_init not available (active state 0) object type: timer_list hint: (null)
WARNING: CPU: 0 PID: 8330 at lib/debugobjects.c:325 debug_print_object+0x160/0x250 lib/debugobjects.c:325
Kernel panic - not syncing: panic_on_warn set ...

CPU: 0 PID: 8330 Comm: syz-executor359 Not tainted 4.19.163-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x1fc/0x2fe lib/dump_stack.c:118
panic+0x26a/0x50e kernel/panic.c:186
__warn.cold+0x20/0x61 kernel/panic.c:541
report_bug+0x262/0x2b0 lib/bug.c:186
fixup_bug arch/x86/kernel/traps.c:178 [inline]
fixup_bug arch/x86/kernel/traps.c:173 [inline]
do_error_trap+0x1d7/0x310 arch/x86/kernel/traps.c:296
invalid_op+0x14/0x20 arch/x86/entry/entry_64.S:1038
RIP: 0010:debug_print_object+0x160/0x250 lib/debugobjects.c:325
Code: dd e0 ca b3 88 48 89 fa 48 c1 ea 03 80 3c 02 00 0f 85 bf 00 00 00 48 8b 14 dd e0 ca b3 88 48 c7 c7 00 bf b3 88 e8 fb 80 b8 fd <0f> 0b 83 05 23 b6 a6 07 01 48 83 c4 20 5b 5d 41 5c 41 5d c3 48 89
RSP: 0018:ffff888094466d28 EFLAGS: 00010082
RAX: 0000000000000000 RBX: 0000000000000005 RCX: 0000000000000000
RDX: 0000000000000000 RSI: ffffffff814fdbb1 RDI: ffffed101288cd97
RBP: 0000000000000001 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000000005 R11: ffffffff8c65b01b R12: ffffffff89f90700
R13: ffffffff81554330 R14: ffff8880adf3f338 R15: 1ffff1101288cdb0
RIP: 0033:0x444679
Code: e8 6c 05 03 00 48 83 c4 18 c3 0f 1f 80 00 00 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 0f 83 eb 05 fc ff c3 66 2e 0f 1f 84 00 00 00 00
RSP: 002b:00007ffea2dac9b8 EFLAGS: 00000246 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 0000000000000003 RCX: 0000000000444679
RDX: 0000000000000000 RSI: 00000000200002c0 RDI: 0000000000000004
RBP: 00007ffea2dac9d0 R08: 0000000000000001 R09: 00000000bb1414ac
R10: 0000000000000000 R11: 0000000000000246 R12: 00007ffea2daca00
R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000

syzbot

unread,
Dec 19, 2020, 6:35:10 PM12/19/20
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 3f2ecb86 Linux 4.14.212
git tree: linux-4.14.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1169eadf500000
kernel config: https://syzkaller.appspot.com/x/.config?x=80549830ca6ffbb2
dashboard link: https://syzkaller.appspot.com/bug?extid=faa9b3afe454a5f907b2
compiler: gcc (GCC) 10.1.0-syz 20200507

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+faa9b3...@syzkaller.appspotmail.com

R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000005
R13: 00007ffeecfd949f R14: 00007fc52ebfd9c0 R15: 000000000119c034
kobject_add_internal failed for bonding_slave (error: -12 parent: bond77)
ODEBUG: assert_init not available (active state 0) object type: timer_list hint: (null)
------------[ cut here ]------------
WARNING: CPU: 0 PID: 29758 at lib/debugobjects.c:287 debug_print_object.cold+0xa7/0xdb lib/debugobjects.c:287
Kernel panic - not syncing: panic_on_warn set ...

CPU: 0 PID: 29758 Comm: syz-executor.0 Not tainted 4.14.212-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:17 [inline]
dump_stack+0x1b2/0x283 lib/dump_stack.c:58
panic+0x1f9/0x42d kernel/panic.c:183
__warn.cold+0x20/0x4b kernel/panic.c:547
report_bug+0x208/0x249 lib/bug.c:186
fixup_bug arch/x86/kernel/traps.c:177 [inline]
fixup_bug arch/x86/kernel/traps.c:172 [inline]
do_error_trap+0x195/0x2d0 arch/x86/kernel/traps.c:295
invalid_op+0x1b/0x40 arch/x86/entry/entry_64.S:964
RIP: 0010:debug_print_object.cold+0xa7/0xdb lib/debugobjects.c:287
RSP: 0018:ffff888059efed48 EFLAGS: 00010086
RAX: 0000000000000061 RBX: 0000000000000005 RCX: 0000000000000000
RDX: 0000000000040000 RSI: ffffffff8145db00 RDI: ffffed100b3dfd9f
RBP: ffffffff878b6d80 R08: 0000000000000061 R09: 0000000000000001
R10: 0000000000000000 R11: ffff888047572400 R12: 0000000000000000
R13: 0000000000000000 R14: ffff888090ff2178 R15: 1ffff1100b3dfdb2
debug_object_assert_init lib/debugobjects.c:656 [inline]
debug_object_assert_init+0x1d3/0x2d0 lib/debugobjects.c:627
debug_timer_assert_init kernel/time/timer.c:708 [inline]
debug_assert_init kernel/time/timer.c:756 [inline]
del_timer+0x5d/0xe0 kernel/time/timer.c:1151
try_to_grab_pending+0x243/0x610 kernel/workqueue.c:1225
__cancel_work_timer+0x90/0x460 kernel/workqueue.c:2923
slave_kobj_release+0x48/0xd0 drivers/net/bonding/bond_main.c:1261
kobject_cleanup lib/kobject.c:646 [inline]
kobject_release lib/kobject.c:675 [inline]
kref_put include/linux/kref.h:70 [inline]
kobject_put+0x251/0x550 lib/kobject.c:692
bond_alloc_slave drivers/net/bonding/bond_main.c:1306 [inline]
bond_enslave+0xd2b/0x4cc0 drivers/net/bonding/bond_main.c:1494
do_set_master+0x19e/0x200 net/core/rtnetlink.c:1961
do_setlink+0x8b8/0x2bf0 net/core/rtnetlink.c:2098
rtnl_newlink+0x1267/0x1830 net/core/rtnetlink.c:2660
rtnetlink_rcv_msg+0x3be/0xb10 net/core/rtnetlink.c:4316
netlink_rcv_skb+0x125/0x390 net/netlink/af_netlink.c:2433
netlink_unicast_kernel net/netlink/af_netlink.c:1287 [inline]
netlink_unicast+0x437/0x610 net/netlink/af_netlink.c:1313
netlink_sendmsg+0x62e/0xb80 net/netlink/af_netlink.c:1878
sock_sendmsg_nosec net/socket.c:646 [inline]
sock_sendmsg+0xb5/0x100 net/socket.c:656
___sys_sendmsg+0x6c8/0x800 net/socket.c:2062
__sys_sendmsg+0xa3/0x120 net/socket.c:2096
SYSC_sendmsg net/socket.c:2107 [inline]
SyS_sendmsg+0x27/0x40 net/socket.c:2103
do_syscall_64+0x1d5/0x640 arch/x86/entry/common.c:292
entry_SYSCALL_64_after_hwframe+0x46/0xbb
RIP: 0033:0x45e149
RSP: 002b:00007fc52ebfcc68 EFLAGS: 00000246 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 0000000000000007 RCX: 000000000045e149
RDX: 0000000000000000 RSI: 0000000020000080 RDI: 0000000000000005
RBP: 00007fc52ebfcca0 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000005
R13: 00007ffeecfd949f R14: 00007fc52ebfd9c0 R15: 000000000119c034
Kernel Offset: disabled
Rebooting in 86400 seconds..


syzbot

unread,
Dec 19, 2020, 7:45:11 PM12/19/20
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 3f2ecb86 Linux 4.14.212
git tree: linux-4.14.y
console output: https://syzkaller.appspot.com/x/log.txt?x=14fa0ca3500000
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=12780923500000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=14423487500000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+faa9b3...@syzkaller.appspotmail.com

R10: 0000000000000000 R11: 0000000000000246 R12: ffffffffffffffff
R13: 0000000000000007 R14: 0000000000000000 R15: 0000000000000000
kobject_add_internal failed for bonding_slave (error: -12 parent: ipvlan0)
ODEBUG: assert_init not available (active state 0) object type: timer_list hint: (null)
------------[ cut here ]------------
WARNING: CPU: 1 PID: 8300 at lib/debugobjects.c:287 debug_print_object.cold+0xa7/0xdb lib/debugobjects.c:287
Kernel panic - not syncing: panic_on_warn set ...

CPU: 1 PID: 8300 Comm: syz-executor809 Not tainted 4.14.212-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:17 [inline]
dump_stack+0x1b2/0x283 lib/dump_stack.c:58
panic+0x1f9/0x42d kernel/panic.c:183
__warn.cold+0x20/0x4b kernel/panic.c:547
report_bug+0x208/0x249 lib/bug.c:186
fixup_bug arch/x86/kernel/traps.c:177 [inline]
fixup_bug arch/x86/kernel/traps.c:172 [inline]
do_error_trap+0x195/0x2d0 arch/x86/kernel/traps.c:295
invalid_op+0x1b/0x40 arch/x86/entry/entry_64.S:964
RIP: 0010:debug_print_object.cold+0xa7/0xdb lib/debugobjects.c:287
RSP: 0018:ffff8880a2486d48 EFLAGS: 00010086
RAX: 0000000000000061 RBX: 0000000000000005 RCX: 0000000000000000
RDX: 0000000000000000 RSI: ffffffff87ccd060 RDI: ffffed1014490d9f
RBP: ffffffff878b6d80 R08: 0000000000000061 R09: 0000000000000001
R10: 0000000000000000 R11: ffff8880a2fae380 R12: 0000000000000000
R13: 0000000000000000 R14: ffff8880aa8a5c78 R15: 1ffff11014490db2
RIP: 0033:0x444769
RSP: 002b:00007ffc16d072a8 EFLAGS: 00000246 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 0000000000000003 RCX: 0000000000444769
RDX: 0000000000000000 RSI: 0000000020000080 RDI: 0000000000000005
RBP: 0000000000000000 R08: 0000000000000001 R09: 00000000bb1414ac
R10: 0000000000000000 R11: 0000000000000246 R12: ffffffffffffffff
R13: 0000000000000007 R14: 0000000000000000 R15: 0000000000000000

syzbot

unread,
Jul 8, 2021, 6:36:11 AM7/8/21
to syzkaller...@googlegroups.com
syzbot suspects this issue was fixed by commit:

commit f583748c2a4a1dc731812ae2c12cadca5c1a88b5
Author: Johannes Berg <johann...@intel.com>
Date: Mon May 17 14:13:35 2021 +0000

bonding: init notify_work earlier to avoid uninitialized use

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=123445d8300000
start commit: 13d2ce42 Linux 4.19.163
git tree: linux-4.19.y
If the result looks correct, please mark the issue as fixed by replying with:

#syz fix: bonding: init notify_work earlier to avoid uninitialized use

For information about bisection process see: https://goo.gl/tpsmEJ#bisection
Reply all
Reply to author
Forward
0 new messages