All of lore.kernel.org
 help / color / mirror / Atom feed
From: syzbot <syzbot+3e07a461b836821ff70e@syzkaller.appspotmail.com>
To: hdanton@sina.com, johan.hedberg@gmail.com,
	linux-bluetooth@vger.kernel.org,  linux-kernel@vger.kernel.org,
	luiz.dentz@gmail.com, marcel@holtmann.org,
	 netdev@vger.kernel.org, syzkaller-bugs@googlegroups.com
Subject: Re: [syzbot] [bluetooth?] WARNING in hci_recv_frame
Date: Mon, 19 May 2025 10:27:29 -0700	[thread overview]
Message-ID: <682b6a01.a00a0220.7a43a.0078.GAE@google.com> (raw)
In-Reply-To: <00000000000052c1d00616feca15@google.com>

syzbot has found a reproducer for the following issue on:

HEAD commit:    a5806cd506af Linux 6.15-rc7
git tree:       upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=14bd52d4580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=6c2cd7998c108ba7
dashboard link: https://syzkaller.appspot.com/bug?extid=3e07a461b836821ff70e
compiler:       Debian clang version 20.1.2 (++20250402124445+58df0ef89dd6-1~exp1~20250402004600.97), Debian LLD 20.1.2
syz repro:      https://syzkaller.appspot.com/x/repro.syz?x=12bd52d4580000
C reproducer:   https://syzkaller.appspot.com/x/repro.c?x=170ab1f4580000

Downloadable assets:
disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/d900f083ada3/non_bootable_disk-a5806cd5.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/114e439a107e/vmlinux-a5806cd5.xz
kernel image: https://storage.googleapis.com/syzbot-assets/28859a387c14/bzImage-a5806cd5.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+3e07a461b836821ff70e@syzkaller.appspotmail.com

------------[ cut here ]------------
workqueue: cannot queue hci_rx_work on wq hci0
WARNING: CPU: 0 PID: 7345 at kernel/workqueue.c:2258 __queue_work+0xd62/0xfe0 kernel/workqueue.c:2256
Modules linked in:
CPU: 0 UID: 0 PID: 7345 Comm: syz-executor130 Not tainted 6.15.0-rc7-syzkaller #0 PREEMPT(full) 
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014
RIP: 0010:__queue_work+0xd62/0xfe0 kernel/workqueue.c:2256
Code: 42 80 3c 20 00 74 08 4c 89 ef e8 89 de 96 00 49 8b 75 00 49 81 c7 78 01 00 00 48 c7 c7 40 cc 69 8b 4c 89 fa e8 9f 40 f9 ff 90 <0f> 0b 90 90 e9 f1 f4 ff ff e8 00 e4 34 00 90 0f 0b 90 e9 dd fc ff
RSP: 0018:ffffc9000f4d7a88 EFLAGS: 00010046
RAX: 701780e79c022b00 RBX: 0000000000000000 RCX: ffff88803d9a0000
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000002
RBP: 1ffff110022be938 R08: ffff88801fe23e93 R09: 1ffff11003fc47d2
R10: dffffc0000000000 R11: ffffed1003fc47d3 R12: dffffc0000000000
R13: ffff8880437f0a98 R14: ffff88803d9a0000 R15: ffff8880115f4978
FS:  00007f9904bca6c0(0000) GS:ffff88808d6c2000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000200000000040 CR3: 000000004012c000 CR4: 0000000000352ef0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
 <TASK>
 queue_work_on+0x181/0x270 kernel/workqueue.c:2392
 queue_work include/linux/workqueue.h:662 [inline]
 hci_recv_frame+0x5ad/0x700 net/bluetooth/hci_core.c:2926
 vhci_get_user drivers/bluetooth/hci_vhci.c:512 [inline]
 vhci_write+0x358/0x4a0 drivers/bluetooth/hci_vhci.c:608
 new_sync_write fs/read_write.c:591 [inline]
 vfs_write+0x548/0xa90 fs/read_write.c:684
 ksys_write+0x145/0x250 fs/read_write.c:736
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0xf6/0x210 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f9905433a6f
Code: 89 54 24 18 48 89 74 24 10 89 7c 24 08 e8 d9 6b 02 00 48 8b 54 24 18 48 8b 74 24 10 41 89 c0 8b 7c 24 08 b8 01 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 31 44 89 c7 48 89 44 24 08 e8 2c 6c 02 00 48
RSP: 002b:00007f9904bca1e0 EFLAGS: 00000293 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 00007f99054bf3f8 RCX: 00007f9905433a6f
RDX: 0000000000000007 RSI: 0000200000000040 RDI: 00000000000000ca
RBP: 0000200000000040 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000293 R12: 00007f99054bf3f0
R13: 00007f99054bf3fc R14: 0000000000000040 R15: 00007ffdd9006d98
 </TASK>


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

  parent reply	other threads:[~2025-05-19 17:27 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-04-26 12:10 [syzbot] [bluetooth?] WARNING in hci_recv_frame syzbot
2024-11-20  9:18 ` syzbot
2024-11-20 11:47   ` Hillf Danton
2024-11-20 12:22     ` syzbot
2025-05-19 17:27 ` syzbot [this message]
     [not found] <20250520105016.2205-1-hdanton@sina.com>
2025-05-20 11:13 ` syzbot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=682b6a01.a00a0220.7a43a.0078.GAE@google.com \
    --to=syzbot+3e07a461b836821ff70e@syzkaller.appspotmail.com \
    --cc=hdanton@sina.com \
    --cc=johan.hedberg@gmail.com \
    --cc=linux-bluetooth@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=luiz.dentz@gmail.com \
    --cc=marcel@holtmann.org \
    --cc=netdev@vger.kernel.org \
    --cc=syzkaller-bugs@googlegroups.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.