Hello,
syzkaller hit the following crash on
744c56def80933f393da5790862f21acdcfc816d
git://
git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git/master
compiler: gcc (GCC) 7.1.1 20170620
.config is attached
Raw console output is attached.
C reproducer is attached
syzkaller reproducer is attached. See
https://goo.gl/kgGztJ
for information about syzkaller reproducers
CC: [
a...@kernel.org dan...@iogearbox.net linux-...@vger.kernel.org
net...@vger.kernel.org]
kasan: GPF could be caused by NULL-ptr deref or user memory access
general protection fault: 0000 [#1] SMP KASAN
Dumping ftrace buffer:
(ftrace buffer empty)
Modules linked in:
CPU: 3 PID: 5265 Comm: syzkaller452061 Not tainted 4.13.0-next-20170905+ #15
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Bochs 01/01/2011
task: ffff88003d384100 task.stack: ffff880039a60000
RIP: 0010:__list_add_valid+0x46/0xd0 lib/list_debug.c:26
RSP: 0018:ffff880039a673d0 EFLAGS: 00010246
RAX: dffffc0000000000 RBX: ffff88006aa6dce8 RCX: 0000000000000000
RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff88006aa6dcf0
RBP: ffff880039a673e8 R08: 0000000000000000 R09: 1ffff1000734cddc
R10: 0000000011024d81 R11: 00000000a5f4a619 R12: ffff88006d83ca00
R13: ffff88003ca0c800 R14: ffff88006aa6dce8 R15: 0000000000000000
FS: 00007fcde7c66700(0000) GS:ffff88006df00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000020eb1000 CR3: 0000000039ae3000 CR4: 00000000000006e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
__list_add include/linux/list.h:59 [inline]
list_add_tail include/linux/list.h:92 [inline]
sock_map_ctx_update_elem.isra.11+0x9e9/0x1a00 kernel/bpf/sockmap.c:768
sock_map_update_elem+0x145/0x2d0 kernel/bpf/sockmap.c:843
map_update_elem kernel/bpf/syscall.c:587 [inline]
SYSC_bpf kernel/bpf/syscall.c:1468 [inline]
SyS_bpf+0x20cb/0x4c50 kernel/bpf/syscall.c:1443
entry_SYSCALL_64_fastpath+0x1f/0xbe
RIP: 0033:0x440389
RSP: 002b:00007fcde7c65db8 EFLAGS: 00000206 ORIG_RAX: 0000000000000141
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 0000000000440389
RDX: 0000000000000020 RSI: 00000000204eefe0 RDI: 0000000000000002
RBP: 0000000000000082 R08: 00007fcde7c66700 R09: 0000000000000000
R10: 00007fcde7c66700 R11: 0000000000000206 R12: 0000000000000000
R13: 0000000000000000 R14: 00007fcde7c669c0 R15: 00007fcde7c66700
Code: 48 89 fa 48 83 ec 08 48 c1 ea 03 80 3c 02 00 75 7c 48 8b 53 08 48 39
f2 75 37 48 89 f2 48 b8 00 00 00 00 00 fc ff df 48 c1 ea 03 <80> 3c 02 00
75 6e 48 8b 16 48 39 da 75 29 49 39 f4 74 38 49 39
RIP: __list_add_valid+0x46/0xd0 lib/list_debug.c:26 RSP: ffff880039a673d0
---[ end trace 90291bcf1b4371c8 ]---
Kernel panic - not syncing: Fatal exception in interrupt
Dumping ftrace buffer:
(ftrace buffer empty)
Kernel Offset: disabled
Rebooting in 86400 seconds..
---
This bug is generated by a dumb bot. It may contain errors.
See
https://goo.gl/tpsmEJ for details.
Direct all questions to
syzk...@googlegroups.com.
syzbot will keep track of this bug report.
Once a fix for this bug is committed, please reply to this email with:
#syz fix: exact-commit-title
To mark this as a duplicate of another syzbot report, please reply with:
#syz dup: exact-subject-of-another-report
If it's a one-off invalid bug report, please reply with:
#syz invalid
Note: if the crash happens again, it will cause creation of a new bug
report.
To upstream this report, please reply with:
#syz upstream