WARNING in strp_done

From: syzbot <hidden>
Date: 2018-02-14 14:59:47
Also in: lkml

Hello,

syzbot hit the following crash on upstream commit
5b7d27967dabfb17c21b0d98b29153b9e3ee71e5 (Thu Jan 25 01:24:30 2018 +0000)
Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/net

So far this crash happened 1937 times on net-next, upstream.
C reproducer is attached.
syzkaller reproducer is attached.
Raw console output is attached.
compiler: gcc (GCC) 7.1.1 20170620
.config is attached.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+88dfb55e4c8b770d86e3@syzkaller.appspotmail.com
It will help syzbot understand when the bug is fixed. See footer for  
details.
If you forward the report, please keep this part and the footer.

WARNING: CPU: 1 PID: 3786 at net/strparser/strparser.c:532  
strp_done+0xb7/0xe0 net/strparser/strparser.c:532
Kernel panic - not syncing: panic_on_warn set ...

CPU: 1 PID: 3786 Comm: syzkaller868787 Not tainted 4.15.0-rc9+ #279
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS  
Google 01/01/2011
Call Trace:
  __dump_stack lib/dump_stack.c:17 [inline]
  dump_stack+0x194/0x257 lib/dump_stack.c:53
  panic+0x1e4/0x41c kernel/panic.c:183
  __warn+0x1dc/0x200 kernel/panic.c:547
  report_bug+0x211/0x2d0 lib/bug.c:184
  fixup_bug.part.11+0x37/0x80 arch/x86/kernel/traps.c:178
  fixup_bug arch/x86/kernel/traps.c:247 [inline]
  do_error_trap+0x2d7/0x3e0 arch/x86/kernel/traps.c:296
  do_invalid_op+0x1b/0x20 arch/x86/kernel/traps.c:315
  invalid_op+0x22/0x40 arch/x86/entry/entry_64.S:1096
RIP: 0010:strp_done+0xb7/0xe0 net/strparser/strparser.c:532
RSP: 0018:ffff8801d875fac0 EFLAGS: 00010293
RAX: ffff8801d0850680 RBX: ffff8801bbd89908 RCX: ffffffff84fdc797
RDX: 0000000000000000 RSI: 0000000000000001 RDI: ffff8801bbd89910
RBP: ffff8801d875fad8 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: ffff8801bac92a00
R13: ffffc90000002000 R14: ffff8801bec88040 R15: ffff8801d875fcd8
  kcm_attach net/kcm/kcmsock.c:1420 [inline]
  kcm_attach_ioctl net/kcm/kcmsock.c:1477 [inline]
  kcm_ioctl+0x139a/0x17f0 net/kcm/kcmsock.c:1682
  sock_do_ioctl+0x65/0xb0 net/socket.c:966
  sock_ioctl+0x2c2/0x440 net/socket.c:1063
  vfs_ioctl fs/ioctl.c:46 [inline]
  do_vfs_ioctl+0x1b1/0x1520 fs/ioctl.c:686
  SYSC_ioctl fs/ioctl.c:701 [inline]
  SyS_ioctl+0x8f/0xc0 fs/ioctl.c:692
  entry_SYSCALL_64_fastpath+0x29/0xa0
RIP: 0033:0x44aba9
RSP: 002b:00007fa1da5c0d48 EFLAGS: 00000297 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 00000000006dcc3c RCX: 000000000044aba9
RDX: 0000000020ed6ff8 RSI: 00000000000089e0 RDI: 0000000000000006
RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000297 R12: 00000000006dcc38
R13: 656c6c616b7a7973 R14: 00007fa1da5c19c0 R15: 0000000000002710
Dumping ftrace buffer:
    (ftrace buffer empty)
Kernel Offset: disabled
Rebooting in 86400 seconds..


---
This bug is generated by a dumb bot. It may contain errors.
See https://goo.gl/tpsmEJ for details.
Direct all questions to syzkaller@googlegroups.com.

syzbot will keep track of this bug report.
If you forgot to add the Reported-by tag, once the fix for this bug is  
merged
into any tree, please reply to this email with:
#syz fix: exact-commit-title
If you want to test a patch for this bug, please reply with:
#syz test: git://repo/address.git branch
and provide the patch inline or as an attachment.
To mark this as a duplicate of another syzbot report, please reply with:
#syz dup: exact-subject-of-another-report
If it's a one-off invalid bug report, please reply with:
#syz invalid
Note: if the crash happens again, it will cause creation of a new bug  
report.
Note: all commands must start from beginning of the line in the email body.

Attachments

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help