WARNING in xfrm_state_fini (2)

From: syzbot <hidden>
Date: 2018-02-04 11:30:04

Hello,

syzbot hit the following crash on upstream commit
4bf772b14675411a69b3c807f73006de0fe4b649 (Fri Feb 2 01:48:47 2018 +0000)
Merge tag 'drm-for-v4.16' of git://people.freedesktop.org/~airlied/linux

Unfortunately, I don't have any reproducer for this crash yet.
Raw console output is attached.
compiler: gcc (GCC) 7.1.1 20170620
.config is attached.
user-space arch: i386

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+0bf0519d6e0de15914fe@syzkaller.appspotmail.com
It will help syzbot understand when the bug is fixed. See footer for  
details.
If you forward the report, please keep this part and the footer.

netlink: 3 bytes leftover after parsing attributes in process  
`syz-executor2'.
WARNING: CPU: 0 PID: 28 at net/xfrm/xfrm_state.c:2341  
xfrm_state_fini+0x46a/0x620 net/xfrm/xfrm_state.c:2341
Kernel panic - not syncing: panic_on_warn set ...

CPU: 0 PID: 28 Comm: kworker/u4:2 Not tainted 4.15.0+ #202
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS  
Google 01/01/2011
Workqueue: netns cleanup_net
Call Trace:
  __dump_stack lib/dump_stack.c:17 [inline]
  dump_stack+0x194/0x257 lib/dump_stack.c:53
  panic+0x1e4/0x41c kernel/panic.c:183
  __warn+0x1dc/0x200 kernel/panic.c:547
  report_bug+0x211/0x2d0 lib/bug.c:184
  fixup_bug.part.11+0x37/0x80 arch/x86/kernel/traps.c:178
  fixup_bug arch/x86/kernel/traps.c:247 [inline]
  do_error_trap+0x2d7/0x3e0 arch/x86/kernel/traps.c:296
  do_invalid_op+0x1b/0x20 arch/x86/kernel/traps.c:315
  invalid_op+0x22/0x40 arch/x86/entry/entry_64.S:1097
RIP: 0010:xfrm_state_fini+0x46a/0x620 net/xfrm/xfrm_state.c:2341
RSP: 0000:ffff8801d993f148 EFLAGS: 00010293
RAX: ffff8801d9926000 RBX: ffff8801b899a100 RCX: ffffffff84be327a
RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffff86ac93f8
RBP: ffff8801d993f2a0 R08: 1ffff1003b327dbc R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: 1ffff1003b327e2b
R13: ffff8801d993f278 R14: 1ffff1003b327e2f R15: ffff8801b899b500
  xfrm_net_exit+0x25/0x70 net/xfrm/xfrm_policy.c:2978
  ops_exit_list.isra.6+0xae/0x150 net/core/net_namespace.c:142
  cleanup_net+0x6a3/0xcc0 net/core/net_namespace.c:517
  process_one_work+0xbbf/0x1af0 kernel/workqueue.c:2113
  worker_thread+0x223/0x1990 kernel/workqueue.c:2247
  kthread+0x33c/0x400 kernel/kthread.c:238
  ret_from_fork+0x3a/0x50 arch/x86/entry/entry_64.S:542
Dumping ftrace buffer:
    (ftrace buffer empty)
Kernel Offset: disabled
Rebooting in 86400 seconds..


---
This bug is generated by a dumb bot. It may contain errors.
See https://goo.gl/tpsmEJ for details.
Direct all questions to syzkaller@googlegroups.com.

syzbot will keep track of this bug report.
If you forgot to add the Reported-by tag, once the fix for this bug is  
merged
into any tree, please reply to this email with:
#syz fix: exact-commit-title
To mark this as a duplicate of another syzbot report, please reply with:
#syz dup: exact-subject-of-another-report
If it's a one-off invalid bug report, please reply with:
#syz invalid
Note: if the crash happens again, it will cause creation of a new bug  
report.
Note: all commands must start from beginning of the line in the email body.

Attachments

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help