BUG: unable to handle kernel paging request in batadv_iv_ogm_schedule_buff

10 views
Skip to first unread message

syzbot

unread,
Aug 25, 2020, 3:02:16 AM8/25/20
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: d18b78ab Linux 4.19.141
git tree: linux-4.19.y
console output: https://syzkaller.appspot.com/x/log.txt?x=13bc3261900000
kernel config: https://syzkaller.appspot.com/x/.config?x=434d9db52d13a8e1
dashboard link: https://syzkaller.appspot.com/bug?extid=09bb4021bcb36b482312
compiler: gcc (GCC) 10.1.0-syz 20200507

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+09bb40...@syzkaller.appspotmail.com

FAT-fs (loop0): Filesystem has been set read-only
BUG: unable to handle kernel paging request at ffff8800551f2df8
PGD 0 P4D 0
Oops: 0000 [#1] PREEMPT SMP KASAN
CPU: 1 PID: 3421 Comm: kworker/u4:0 Not tainted 4.19.141-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Workqueue: bat_events batadv_iv_send_outstanding_bat_ogm_packet
RIP: 0010:batadv_iv_ogm_schedule_buff+0xc8d/0x1340 net/batman-adv/bat_iv_ogm.c:1024
Code: fb e0 65 50 8c 0f 84 78 02 00 00 e8 dd 04 4c fa 48 8d 7b 78 48 89 f8 48 c1 e8 03 42 80 3c 38 00 0f 85 ee 05 00 00 48 8b 04 24 <48> 8b 6b 78 80 38 00 0f 85 73 06 00 00 49 3b 6d 78 75 a7 e8 ab 04
RSP: 0018:ffff88802f0c7bc0 EFLAGS: 00010246
RAX: ffffed1011164d2f RBX: ffff8800551f2d80 RCX: ffffffff871dae7a
RDX: 0000000000000000 RSI: ffffffff871dac23 RDI: ffff8800551f2df8
RBP: 0000000000000000 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000000001 R11: 0000000000000000 R12: ffff88809a62bb70
R13: ffff888088b26900 R14: ffff888056795640 R15: dffffc0000000000
FS: 0000000000000000(0000) GS:ffff8880ae700000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: ffff8800551f2df8 CR3: 00000000a7a6b000 CR4: 00000000001406e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
batadv_iv_ogm_schedule net/batman-adv/bat_iv_ogm.c:1050 [inline]
batadv_iv_ogm_schedule net/batman-adv/bat_iv_ogm.c:1043 [inline]
batadv_iv_send_outstanding_bat_ogm_packet+0x5e0/0x7a0 net/batman-adv/bat_iv_ogm.c:1869
process_one_work+0x864/0x1570 kernel/workqueue.c:2155
worker_thread+0x64c/0x1130 kernel/workqueue.c:2298
kthread+0x30b/0x410 kernel/kthread.c:246
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:415
Modules linked in:
CR2: ffff8800551f2df8
---[ end trace 5db26b9b70ccad95 ]---
RIP: 0010:batadv_iv_ogm_schedule_buff+0xc8d/0x1340 net/batman-adv/bat_iv_ogm.c:1024
Code: fb e0 65 50 8c 0f 84 78 02 00 00 e8 dd 04 4c fa 48 8d 7b 78 48 89 f8 48 c1 e8 03 42 80 3c 38 00 0f 85 ee 05 00 00 48 8b 04 24 <48> 8b 6b 78 80 38 00 0f 85 73 06 00 00 49 3b 6d 78 75 a7 e8 ab 04
RSP: 0018:ffff88802f0c7bc0 EFLAGS: 00010246
RAX: ffffed1011164d2f RBX: ffff8800551f2d80 RCX: ffffffff871dae7a
RDX: 0000000000000000 RSI: ffffffff871dac23 RDI: ffff8800551f2df8
RBP: 0000000000000000 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000000001 R11: 0000000000000000 R12: ffff88809a62bb70
R13: ffff888088b26900 R14: ffff888056795640 R15: dffffc0000000000
FS: 0000000000000000(0000) GS:ffff8880ae700000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: ffff8800551f2df8 CR3: 00000000a7a6b000 CR4: 00000000001406e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Dec 23, 2020, 2:02:10 AM12/23/20
to syzkaller...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages