[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <67a3515a.050a0220.50516.0041.GAE@google.com>
Date: Wed, 05 Feb 2025 03:54:02 -0800
From: syzbot <syzbot+3201be560ebfa39bc6bd@...kaller.appspotmail.com>
To: hdanton@...a.com, linux-kernel@...r.kernel.org,
syzkaller-bugs@...glegroups.com
Subject: Re: [syzbot] [net?] general protection fault in ip6_pol_route (3)
Hello,
syzbot tried to test the proposed patch but the build/boot failed:
79.765602][ T5343]
[ 79.766558][ T5343] The buggy address belongs to the physical page:
[ 79.769019][ T5343] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x4f464
[ 79.772366][ T5343] head: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
[ 79.775598][ T5343] anon flags: 0x4fff00000000040(head|node=1|zone=1|lastcpupid=0x7ff)
[ 79.778676][ T5343] page_type: f5(slab)
[ 79.780232][ T5343] raw: 04fff00000000040 ffff88801ac41c80 0000000000000000 dead000000000001
[ 79.783372][ T5343] raw: 0000000000000000 0000000000080008 00000000f5000000 0000000000000000
[ 79.786627][ T5343] head: 04fff00000000040 ffff88801ac41c80 0000000000000000 dead000000000001
[ 79.789858][ T5343] head: 0000000000000000 0000000000080008 00000000f5000000 0000000000000000
[ 79.793129][ T5343] head: 04fff00000000001 ffffea00013d1901 ffffffffffffffff 0000000000000000
[ 79.796507][ T5343] head: 0000000000000002 0000000000000000 00000000ffffffff 0000000000000000
[ 79.799785][ T5343] page dumped because: kasan: bad access detected
[ 79.802261][ T5343] page_owner tracks the page as allocated
[ 79.804507][ T5343] page last allocated via order 1, migratetype Unmovable, gfp_mask 0xd20c0(__GFP_IO|__GFP_FS|__GFP_NOWARN|__GFP_NORETRY|__GFP_COMP|__GFP_NOMEMALLOC), pid 5329, tgid 5329 (syz-executor), ts 78415084094, free_ts 78169759446
[ 79.812368][ T5343] post_alloc_hook+0x1f4/0x240
[ 79.814298][ T5343] get_page_from_freelist+0x365c/0x37a0
[ 79.816463][ T5343] __alloc_frozen_pages_noprof+0x292/0x710
[ 79.818703][ T5343] alloc_pages_mpol+0x311/0x660
[ 79.820563][ T5343] allocate_slab+0x8f/0x3a0
[ 79.822338][ T5343] ___slab_alloc+0xc27/0x14a0
[ 79.824253][ T5343] __slab_alloc+0x58/0xa0
[ 79.825926][ T5343] __kmalloc_cache_noprof+0x27b/0x390
[ 79.827981][ T5343] binderfs_fill_super+0x58e/0xd90
[ 79.829916][ T5343] get_tree_nodev+0xb7/0x140
[ 79.831720][ T5343] vfs_get_tree+0x90/0x2b0
[ 79.833832][ T5343] do_new_mount+0x2be/0xb40
[ 79.835650][ T5343] __se_sys_mount+0x2d6/0x3c0
[ 79.837488][ T5343] do_syscall_64+0xf3/0x230
[ 79.839249][ T5343] entry_SYSCALL_64_after_hwframe+0x77/0x7f
[ 79.841466][ T5343] page last free pid 80 tgid 80 stack trace:
[ 79.843812][ T5343] free_unref_folios+0xe40/0x18b0
[ 79.845786][ T5343] shrink_folio_list+0x41a7/0x5ac0
[ 79.847791][ T5343] evict_folios+0x45fd/0x56a0
[ 79.849591][ T5343] try_to_shrink_lruvec+0x713/0x9b0
[ 79.851656][ T5343] shrink_one+0x3b9/0x850
[ 79.853309][ T5343] shrink_node+0x37c5/0x3e50
[ 79.855093][ T5343] kswapd+0x20f3/0x3b10
[ 79.856715][ T5343] kthread+0x7a9/0x920
[ 79.858297][ T5343] ret_from_fork+0x4b/0x80
[ 79.859943][ T5343] ret_from_fork_asm+0x1a/0x30
[ 79.861728][ T5343]
[ 79.862691][ T5343] Memory state around the buggy address:
[ 79.864899][ T5343] ffff88804f464700: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 79.868793][ T5343] ffff88804f464780: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 79.871847][ T5343] >ffff88804f464800: fa fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[ 79.875096][ T5343] ^
[ 79.876814][ T5343] ffff88804f464880: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[ 79.879777][ T5343] ffff88804f464900: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[ 79.882810][ T5343] ==================================================================
[ 80.174438][ T1033] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50
[ 80.177606][ T1033] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50
[ 80.241533][ T1068] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50
[ 80.255404][ T1068] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50
[ 80.841220][ T5343] Kernel panic - not syncing: KASAN: panic_on_warn set ...
[ 80.844058][ T5343] CPU: 0 UID: 0 PID: 5343 Comm: syz-executor Not tainted 6.14.0-rc1-syzkaller-g5c8c229261f1-dirty #0
[ 80.848035][ T5343] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014
[ 80.852045][ T5343] Call Trace:
[ 80.853331][ T5343] <TASK>
[ 80.854460][ T5343] dump_stack_lvl+0x241/0x360
[ 80.856209][ T5343] ? __pfx_dump_stack_lvl+0x10/0x10
[ 80.858174][ T5343] ? __pfx__printk+0x10/0x10
[ 80.859914][ T5343] ? preempt_schedule+0xe1/0xf0
[ 80.861752][ T5343] ? vscnprintf+0x5d/0x90
[ 80.863363][ T5343] panic+0x349/0x880
[ 80.864858][ T5343] ? check_panic_on_warn+0x21/0xb0
[ 80.866780][ T5343] ? __pfx_panic+0x10/0x10
[ 80.868454][ T5343] ? _raw_spin_unlock_irqrestore+0x130/0x140
[ 80.870716][ T5343] ? __pfx__raw_spin_unlock_irqrestore+0x10/0x10
[ 80.873049][ T5343] ? print_report+0x502/0x550
[ 80.874886][ T5343] check_panic_on_warn+0x86/0xb0
[ 80.876762][ T5343] ? binder_add_device+0x5f/0xa0
[ 80.878699][ T5343] end_report+0x77/0x160
[ 80.880307][ T5343] kasan_report+0x154/0x180
[ 80.882054][ T5343] ? binder_add_device+0x5f/0xa0
[ 80.883951][ T5343] binder_add_device+0x5f/0xa0
[ 80.885778][ T5343] binderfs_binder_device_create+0x7bf/0x9c0
[ 80.888011][ T5343] binderfs_fill_super+0x944/0xd90
[ 80.889968][ T5343] ? __pfx_binderfs_fill_super+0x10/0x10
[ 80.892086][ T5343] ? shrinker_register+0x160/0x230
[ 80.893912][ T5343] ? sget_fc+0x909/0x9c0
[ 80.895358][ T5343] ? __pfx_set_anon_super_fc+0x10/0x10
[ 80.897187][ T5343] ? __pfx_binderfs_fill_super+0x10/0x10
[ 80.899300][ T5343] get_tree_nodev+0xb7/0x140
[ 80.901061][ T5343] vfs_get_tree+0x90/0x2b0
[ 80.902772][ T5343] do_new_mount+0x2be/0xb40
[ 80.904510][ T5343] ? __pfx_do_new_mount+0x10/0x10
[ 80.906387][ T5343] __se_sys_mount+0x2d6/0x3c0
[ 80.908141][ T5343] ? lockdep_hardirqs_on_prepare+0x43d/0x780
[ 80.910345][ T5343] ? __pfx___se_sys_mount+0x10/0x10
[ 80.912308][ T5343] ? do_syscall_64+0x100/0x230
[ 80.914126][ T5343] ? __x64_sys_mount+0x20/0xc0
[ 80.915911][ T5343] do_syscall_64+0xf3/0x230
[ 80.917629][ T5343] ? clear_bhb_loop+0x35/0x90
[ 80.919384][ T5343] entry_SYSCALL_64_after_hwframe+0x77/0x7f
[ 80.921583][ T5343] RIP: 0033:0x7fc18af7feba
[ 80.923238][ T5343] Code: d8 64 89 02 48 c7 c0 ff ff ff ff eb a6 e8 de 1a 00 00 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 49 89 ca b8 a5 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48
[ 80.930263][ T5343] RSP: 002b:00007fffe7bd7398 EFLAGS: 00000246 ORIG_RAX: 00000000000000a5
[ 80.933382][ T5343] RAX: ffffffffffffffda RBX: 00007fc18aff1b21 RCX: 00007fc18af7feba
[ 80.936291][ T5343] RDX: 00007fc18affcfa8 RSI: 00007fc18aff1b21 RDI: 00007fc18affcfa8
[ 80.939200][ T5343] RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000
[ 80.942081][ T5343] R10: 0000000000000000 R11: 0000000000000246 R12: 00007fc18b005050
[ 80.944983][ T5343] R13: 00007fffe7bd7418 R14: 0000000000000009 R15: 0000000000000000
[ 80.947863][ T5343] </TASK>
[ 80.949295][ T5343] Kernel Offset: disabled
[ 80.950938][ T5343] Rebooting in 86400 seconds..
VM DIAGNOSIS:
11:53:19 Registers:
info registers vcpu 0
CPU#0
RAX=000000000000007a RBX=ffffffff9a718760 RCX=0000000000000000 RDX=00000000000003f8
RSI=0000000000000000 RDI=0000000000000020 RBP=0000000000000000 RSP=ffffc9000d3171d0
R8 =ffffffff856cbbeb R9 =1ffff110067ff046 R10=dffffc0000000000 R11=ffffffff856cbba0
R12=dffffc0000000000 R13=000000000000007a R14=000000000000007a R15=00000000000003f8
RIP=ffffffff856cbc1e RFL=00000002 [-------] CPL=0 II=0 A20=1 SMM=0 HLT=0
ES =0000 0000000000000000 ffffffff 00c00000
CS =0010 0000000000000000 ffffffff 00a09b00 DPL=0 CS64 [-RA]
SS =0018 0000000000000000 ffffffff 00c09300 DPL=0 DS [-WA]
DS =0000 0000000000000000 ffffffff 00c00000
FS =0000 000055558166b500 ffffffff 00c00000
GS =0000 ffff88801fc00000 ffffffff 00c00000
LDT=0000 0000000000000000 ffffffff 00c00000
TR =0040 fffffe0000003000 00004087 00008b00 DPL=0 TSS64-busy
GDT= fffffe0000001000 0000007f
IDT= fffffe0000000000 00000fff
CR0=80050033 CR2=00007fc18ae4af90 CR3=000000004f316000 CR4=00352ef0
DR0=0000000000000000 DR1=0000000000000000 DR2=0000000000000000 DR3=0000000000000000
DR6=00000000fffe0ff0 DR7=0000000000000400
EFER=0000000000000d01
FCW=037f FSW=0000 [ST=0] FTW=00 MXCSR=00001f80
FPR0=0000000000000000 0000 FPR1=0000000000000000 0000
FPR2=0000000000000000 0000 FPR3=0000000000000000 0000
FPR4=0000000000000000 0000 FPR5=0000000000000000 0000
FPR6=0000000000000000 0000 FPR7=0000000000000000 0000
Opmask00=00000000ffffff80 Opmask01=000000000000000f Opmask02=00000000ffffffef Opmask03=0000000000000000
Opmask04=0000000000000000 Opmask05=0000000000000000 Opmask06=0000000000000000 Opmask07=0000000000000000
ZMM00=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM01=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 00007fffe7bd73b0 0000003000000010
ZMM02=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM03=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM04=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM05=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM06=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM07=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM08=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM09=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM10=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM11=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM12=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM13=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM14=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM15=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM16=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM17=0000000000000000 0000000000000000 0000000000000000 0000000000000000 2525252525252525 2525252525252525 2525252525252525 2525252525252525
ZMM18=0000000000000000 0000000000000000 0000000000000000 0000000000000000 6573726170206f74 2064656c69616600 277325273d727473 0035333535362030
ZMM19=0000000000000000 0000000000000000 0000000000000000 0000000000000000 4056574455054a51 054140494c444300 0256000218575156 0010161010130515
ZMM20=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM21=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM22=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM23=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM24=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM25=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM26=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM27=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM28=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM29=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM30=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
ZMM31=0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000
syzkaller build log:
go env (err=<nil>)
GO111MODULE='auto'
GOARCH='amd64'
GOBIN=''
GOCACHE='/syzkaller/.cache/go-build'
GOENV='/syzkaller/.config/go/env'
GOEXE=''
GOEXPERIMENT=''
GOFLAGS=''
GOHOSTARCH='amd64'
GOHOSTOS='linux'
GOINSECURE=''
GOMODCACHE='/syzkaller/jobs/linux/gopath/pkg/mod'
GONOPROXY=''
GONOSUMDB=''
GOOS='linux'
GOPATH='/syzkaller/jobs/linux/gopath'
GOPRIVATE=''
GOPROXY='https://proxy.golang.org,direct'
GOROOT='/usr/local/go'
GOSUMDB='sum.golang.org'
GOTMPDIR=''
GOTOOLCHAIN='auto'
GOTOOLDIR='/usr/local/go/pkg/tool/linux_amd64'
GOVCS=''
GOVERSION='go1.22.7'
GCCGO='gccgo'
GOAMD64='v1'
AR='ar'
CC='gcc'
CXX='g++'
CGO_ENABLED='1'
GOMOD='/syzkaller/jobs/linux/gopath/src/github.com/google/syzkaller/go.mod'
GOWORK=''
CGO_CFLAGS='-O2 -g'
CGO_CPPFLAGS=''
CGO_CXXFLAGS='-O2 -g'
CGO_FFLAGS='-O2 -g'
CGO_LDFLAGS='-O2 -g'
PKG_CONFIG='pkg-config'
GOGCCFLAGS='-fPIC -m64 -pthread -Wl,--no-gc-sections -fmessage-length=0 -ffile-prefix-map=/tmp/go-build102701335=/tmp/go-build -gno-record-gcc-switches'
git status (err=<nil>)
HEAD detached at 4dfba277487
nothing to commit, working tree clean
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
go list -f '{{.Stale}}' ./sys/syz-sysgen | grep -q false || go install ./sys/syz-sysgen
make .descriptions
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
bin/syz-sysgen
go fmt ./sys/... >/dev/null
touch .descriptions
GOOS=linux GOARCH=amd64 go build "-ldflags=-s -w -X github.com/google/syzkaller/prog.GitRevision=4dfba277487a7023ab9f5783302da4a9b5e9bef8 -X 'github.com/google/syzkaller/prog.gitRevisionDate=20241113-111659'" "-tags=syz_target syz_os_linux syz_arch_amd64 " -o ./bin/linux_amd64/syz-execprog github.com/google/syzkaller/tools/syz-execprog
mkdir -p ./bin/linux_amd64
g++ -o ./bin/linux_amd64/syz-executor executor/executor.cc \
-m64 -O2 -pthread -Wall -Werror -Wparentheses -Wunused-const-variable -Wframe-larger-than=16384 -Wno-stringop-overflow -Wno-array-bounds -Wno-format-overflow -Wno-unused-but-set-variable -Wno-unused-command-line-argument -static-pie -std=c++17 -I. -Iexecutor/_include -fpermissive -w -DGOOS_linux=1 -DGOARCH_amd64=1 \
-DHOSTGOOS_linux=1 -DGIT_REVISION=\"4dfba277487a7023ab9f5783302da4a9b5e9bef8\"
/usr/bin/ld: /tmp/ccOQNa87.o: in function `test_cover_filter()':
executor.cc:(.text+0x1426b): warning: the use of `tempnam' is dangerous, better use `mkstemp'
/usr/bin/ld: /tmp/ccOQNa87.o: in function `Connection::Connect(char const*, char const*)':
executor.cc:(.text._ZN10Connection7ConnectEPKcS1_[_ZN10Connection7ConnectEPKcS1_]+0x104): warning: Using 'gethostbyname' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking
Error text is too large and was truncated, full error text is at:
https://syzkaller.appspot.com/x/error.txt?x=131f44a4580000
Tested on:
commit: 5c8c2292 Merge tag 'kthreads-fixes-2025-02-04' of git:..
git tree: upstream
kernel config: https://syzkaller.appspot.com/x/.config?x=d256a021904f1cd7
dashboard link: https://syzkaller.appspot.com/bug?extid=3201be560ebfa39bc6bd
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
patch: https://syzkaller.appspot.com/x/patch.diff?x=109493df980000
Powered by blists - more mailing lists