From: Zhu Yanjun <yanjun.zhu@linux.dev>
To: syzbot <syzbot+8425ccfb599521edb153@syzkaller.appspotmail.com>,
jgg@ziepe.ca, leon@kernel.org, linux-kernel@vger.kernel.org,
linux-rdma@vger.kernel.org, syzkaller-bugs@googlegroups.com,
zyjzyj2000@gmail.com
Subject: Re: [syzbot] [rdma?] WARNING in rxe_skb_tx_dtor
Date: Thu, 26 Jun 2025 21:53:47 -0700 [thread overview]
Message-ID: <dbcc14cc-abfa-4486-a642-2fe97b4a0ef3@linux.dev> (raw)
In-Reply-To: <685e168e.a00a0220.2e5631.03f4.GAE@google.com>
#syz test: https://github.com/zhuyj/linux.git v6.16_fix_rxe_skb_tx_dtor
在 2025/6/26 20:57, syzbot 写道:
> Hello,
>
> syzbot has tested the proposed patch but the reproducer is still triggering an issue:
> WARNING in rxe_skb_tx_dtor
>
> ------------[ cut here ]------------
> WARNING: CPU: 0 PID: 3034 at drivers/infiniband/sw/rxe/rxe_net.c:357 rxe_skb_tx_dtor+0x8b/0x2a0 drivers/infiniband/sw/rxe/rxe_net.c:357
> Modules linked in:
> CPU: 0 UID: 0 PID: 3034 Comm: kworker/u4:10 Not tainted 6.16.0-rc3-syzkaller-ge9ef70b277ad #0 PREEMPT(full)
> Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014
> Workqueue: rxe_wq do_work
> RIP: 0010:rxe_skb_tx_dtor+0x8b/0x2a0 drivers/infiniband/sw/rxe/rxe_net.c:357
> Code: 80 3c 20 00 74 08 4c 89 ff e8 c1 64 81 f9 4d 8b 37 44 89 f6 83 e6 01 31 ff e8 d1 e5 1d f9 41 f6 c6 01 75 0e e8 e6 e0 1d f9 90 <0f> 0b 90 e9 b4 01 00 00 4c 89 ff e8 45 97 fd 01 48 89 c7 be 0e 00
> RSP: 0018:ffffc900000079e8 EFLAGS: 00010246
> RAX: ffffffff88a26d8a RBX: ffff8880560d4500 RCX: ffff88801f722440
> RDX: 0000000000000100 RSI: 0000000000000000 RDI: 0000000000000000
> RBP: 0000000000000000 R08: 0000000000000000 R09: ffffffff887bc1c4
> R10: dffffc0000000000 R11: ffffffff88a26d00 R12: dffffc0000000000
> R13: 1ffff1100ac1a8ab R14: 0000000000025820 R15: ffff888033440000
> FS: 0000000000000000(0000) GS:ffff88808d250000(0000) knlGS:0000000000000000
> CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
> CR2: 00007f5e595acfc8 CR3: 0000000056029000 CR4: 0000000000352ef0
> DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
> DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
> Call Trace:
> <IRQ>
> skb_release_head_state+0x101/0x250 net/core/skbuff.c:1139
> napi_consume_skb+0xd2/0x1e0 net/core/skbuff.c:-1
> e1000_unmap_and_free_tx_resource drivers/net/ethernet/intel/e1000/e1000_main.c:1972 [inline]
> e1000_clean_tx_irq drivers/net/ethernet/intel/e1000/e1000_main.c:3864 [inline]
> e1000_clean+0x49d/0x2b00 drivers/net/ethernet/intel/e1000/e1000_main.c:3805
> __napi_poll+0xc7/0x480 net/core/dev.c:7414
> napi_poll net/core/dev.c:7478 [inline]
> net_rx_action+0x707/0xe30 net/core/dev.c:7605
> handle_softirqs+0x286/0x870 kernel/softirq.c:579
> do_softirq+0xec/0x180 kernel/softirq.c:480
> </IRQ>
> <TASK>
> __local_bh_enable_ip+0x17d/0x1c0 kernel/softirq.c:407
> local_bh_enable include/linux/bottom_half.h:33 [inline]
> __neigh_event_send+0x9b/0x1560 net/core/neighbour.c:1194
> neigh_event_send_probe include/net/neighbour.h:463 [inline]
> neigh_event_send include/net/neighbour.h:469 [inline]
> neigh_resolve_output+0x198/0x750 net/core/neighbour.c:1496
> neigh_output include/net/neighbour.h:539 [inline]
> ip6_finish_output2+0x11fb/0x16a0 net/ipv6/ip6_output.c:141
> __ip6_finish_output net/ipv6/ip6_output.c:-1 [inline]
> ip6_finish_output+0x234/0x7d0 net/ipv6/ip6_output.c:226
> rxe_send drivers/infiniband/sw/rxe/rxe_net.c:391 [inline]
> rxe_xmit_packet+0x79e/0xa30 drivers/infiniband/sw/rxe/rxe_net.c:450
> rxe_requester+0x1fea/0x3d20 drivers/infiniband/sw/rxe/rxe_req.c:805
> rxe_sender+0x16/0x50 drivers/infiniband/sw/rxe/rxe_req.c:839
> do_task drivers/infiniband/sw/rxe/rxe_task.c:127 [inline]
> do_work+0x1b4/0x6c0 drivers/infiniband/sw/rxe/rxe_task.c:187
> process_one_work kernel/workqueue.c:3238 [inline]
> process_scheduled_works+0xae1/0x17b0 kernel/workqueue.c:3321
> worker_thread+0x8a0/0xda0 kernel/workqueue.c:3402
> kthread+0x70e/0x8a0 kernel/kthread.c:464
> ret_from_fork+0x3fc/0x770 arch/x86/kernel/process.c:148
> ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
> </TASK>
>
>
> Tested on:
>
> commit: e9ef70b2 RDNA/rxe: Fix rxe_skb_tx_dtor problem
> git tree: https://github.com/zhuyj/linux.git v6.16_fix_rxe_skb_tx_dtor
> console output: https://syzkaller.appspot.com/x/log.txt?x=122183d4580000
> kernel config: https://syzkaller.appspot.com/x/.config?x=79da270cec5ffd65
> dashboard link: https://syzkaller.appspot.com/bug?extid=8425ccfb599521edb153
> compiler: Debian clang version 20.1.6 (++20250514063057+1e4d39e07757-1~exp1~20250514183223.118), Debian LLD 20.1.6
>
> Note: no patches were applied.
--
Best Regards,
Yanjun.Zhu
next prev parent reply other threads:[~2025-06-27 4:54 UTC|newest]
Thread overview: 28+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-05-01 16:45 [syzbot] [rdma?] WARNING in rxe_skb_tx_dtor syzbot
2025-05-02 9:54 ` Zhu Yanjun
2025-05-13 14:57 ` Zhu Yanjun
2025-06-26 20:55 ` syzbot
2025-06-26 22:22 ` Yanjun.Zhu
2025-06-26 22:25 ` syzbot
2025-06-26 22:38 ` Yanjun.Zhu
2025-06-26 22:54 ` syzbot
2025-06-27 2:49 ` Zhu Yanjun
2025-06-27 3:11 ` syzbot
2025-06-27 3:41 ` Zhu Yanjun
2025-06-27 3:57 ` syzbot
2025-06-27 4:53 ` Zhu Yanjun [this message]
2025-06-27 5:09 ` syzbot
2025-06-26 22:52 ` Hillf Danton
2025-06-26 23:09 ` syzbot
2025-06-27 18:27 ` [syzbot] " syzbot
[not found] <f63acb1b-083f-4a48-8352-d07d48827330@linux.dev>
2025-06-27 18:43 ` syzbot
2025-06-27 19:35 ` Yanjun.Zhu
2025-06-27 19:50 ` syzbot
2025-06-27 20:26 ` Yanjun.Zhu
2025-06-27 20:46 ` syzbot
2025-06-27 23:10 ` Yanjun.Zhu
2025-06-27 23:32 ` syzbot
2025-06-27 23:42 ` Yanjun.Zhu
2025-07-03 0:36 ` Yanjun.Zhu
2025-07-03 0:58 ` syzbot
2025-07-06 21:04 ` Zhu Yanjun
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=dbcc14cc-abfa-4486-a642-2fe97b4a0ef3@linux.dev \
--to=yanjun.zhu@linux.dev \
--cc=jgg@ziepe.ca \
--cc=leon@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-rdma@vger.kernel.org \
--cc=syzbot+8425ccfb599521edb153@syzkaller.appspotmail.com \
--cc=syzkaller-bugs@googlegroups.com \
--cc=zyjzyj2000@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.