Hello,
syzbot found the following issue on:
HEAD commit: de927f6c0b07 Merge tag 's390-6.8-1' of git://git.kernel.or..
git tree: upstream
console output:
https://syzkaller.appspot.com/x/log.txt?x=16e63e83e80000
kernel config:
https://syzkaller.appspot.com/x/.config?x=2e7bd9c668099438
dashboard link:
https://syzkaller.appspot.com/bug?extid=51ba45f5a4d22d00d406
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
CC: [
da...@davemloft.net edum...@google.com ha...@kernel.org ilias.ap...@linaro.org ku...@kernel.org linux-...@vger.kernel.org net...@vger.kernel.org pab...@redhat.com]
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/1e10cc79afc4/disk-de927f6c.raw.xz
vmlinux:
https://storage.googleapis.com/syzbot-assets/f54d75ec6dce/vmlinux-de927f6c.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/9f634194daa9/bzImage-de927f6c.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+51ba45...@syzkaller.appspotmail.com
==================================================================
BUG: KCSAN: data-race in page_pool_put_defragged_page / page_pool_refill_alloc_cache
write to 0xffff88815538d800 of 8 bytes by task 26690 on cpu 1:
__ptr_ring_discard_one include/linux/ptr_ring.h:280 [inline]
__ptr_ring_consume include/linux/ptr_ring.h:301 [inline]
page_pool_refill_alloc_cache+0x271/0x380 net/core/page_pool.c:289
__page_pool_get_cached net/core/page_pool.c:328 [inline]
page_pool_alloc_pages+0x7a/0xa0 net/core/page_pool.c:492
page_pool_dev_alloc_pages include/net/page_pool/helpers.h:96 [inline]
xdp_test_run_batch net/bpf/test_run.c:299 [inline]
bpf_test_run_xdp_live+0x399/0xe40 net/bpf/test_run.c:382
bpf_prog_test_run_xdp+0x51e/0x8a0 net/bpf/test_run.c:1254
bpf_prog_test_run+0x265/0x3d0 kernel/bpf/syscall.c:4040
__sys_bpf+0x3af/0x780 kernel/bpf/syscall.c:5401
__do_sys_bpf kernel/bpf/syscall.c:5487 [inline]
__se_sys_bpf kernel/bpf/syscall.c:5485 [inline]
__x64_sys_bpf+0x43/0x50 kernel/bpf/syscall.c:5485
do_syscall_x64 arch/x86/entry/common.c:52 [inline]
do_syscall_64+0x59/0x120 arch/x86/entry/common.c:83
entry_SYSCALL_64_after_hwframe+0x63/0x6b
read to 0xffff88815538d800 of 8 bytes by task 26685 on cpu 0:
__ptr_ring_produce include/linux/ptr_ring.h:106 [inline]
ptr_ring_produce_bh include/linux/ptr_ring.h:163 [inline]
page_pool_recycle_in_ring net/core/page_pool.c:567 [inline]
page_pool_put_defragged_page+0x2aa/0x450 net/core/page_pool.c:654
page_pool_put_page include/net/page_pool/helpers.h:307 [inline]
page_pool_put_full_page include/net/page_pool/helpers.h:323 [inline]
napi_pp_put_page+0x146/0x260 net/core/skbuff.c:931
skb_pp_recycle net/core/skbuff.c:942 [inline]
skb_free_head net/core/skbuff.c:958 [inline]
skb_release_data+0x511/0x550 net/core/skbuff.c:992
skb_release_all net/core/skbuff.c:1058 [inline]
__kfree_skb+0x44/0x140 net/core/skbuff.c:1072
kfree_skb_reason+0xae/0x2b0 net/core/skbuff.c:1108
__skb_queue_purge_reason include/linux/skbuff.h:3166 [inline]
skb_queue_purge_reason+0x1ea/0x240 net/core/skbuff.c:3740
skb_queue_purge include/linux/skbuff.h:3179 [inline]
packet_release+0x6e3/0x7e0 net/packet/af_packet.c:3188
__sock_release net/socket.c:659 [inline]
sock_close+0x64/0x140 net/socket.c:1421
__fput+0x299/0x630 fs/file_table.c:381
__fput_sync+0x44/0x50 fs/file_table.c:466
__do_sys_close fs/open.c:1554 [inline]
__se_sys_close+0xfa/0x1a0 fs/open.c:1539
__x64_sys_close+0x1f/0x30 fs/open.c:1539
do_syscall_x64 arch/x86/entry/common.c:52 [inline]
do_syscall_64+0x59/0x120 arch/x86/entry/common.c:83
entry_SYSCALL_64_after_hwframe+0x63/0x6b
value changed: 0xffffea0005b9bbc0 -> 0x0000000000000000
Reported by Kernel Concurrency Sanitizer on:
CPU: 0 PID: 26685 Comm: syz-executor.3 Not tainted 6.7.0-syzkaller-02723-gde927f6c0b07 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 11/17/2023
==================================================================
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup