* [PATCH] ipv6: addrconf: drop "BUG: " prefix from pr_warn()
@ 2026-08-07 13:13 Pimyn Girgis
2026-08-10 9:51 ` Ido Schimmel
0 siblings, 1 reply; 4+ messages in thread
From: Pimyn Girgis @ 2026-08-07 13:13 UTC (permalink / raw)
To: dsahern, idosch, davem, edumazet, kuba, pabeni
Cc: horms, netdev, linux-kernel, syzbot+ded267b328e950a7c0c4,
Pimyn Girgis
Kernel warning messages emitted via pr_warn() already have the
appropriate log level (KERN_WARNING) and should not include manual
prefixes such as "BUG: " or "WARNING: ".
Explicit "BUG: " prefixes in log strings can mislead testing tools
like syzkaller, which scan kernel console output for "BUG: " to
identify kernel oopses, panics, and fatal conditions.
Remove the manual "BUG: " prefix from the pr_warn() call in
__ipv6_ifa_notify().
Fixes: 2d819d250a1393 ("ipv6: Handle missing host route in __ipv6_ifa_notify")
Reported-by: syzbot+ded267b328e950a7c0c4@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=ded267b328e950a7c0c4
Signed-off-by: Pimyn Girgis <pimyn@google.com>
---
net/ipv6/addrconf.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/ipv6/addrconf.c b/net/ipv6/addrconf.c
index f6fa2715b450b..8c714b4c0a9ba 100644
--- a/net/ipv6/addrconf.c
+++ b/net/ipv6/addrconf.c
@@ -6318,7 +6318,7 @@ static void __ipv6_ifa_notify(int event, struct inet6_ifaddr *ifp)
if (ifp->rt && !rcu_access_pointer(ifp->rt->fib6_node)) {
ip6_ins_rt(net, ifp->rt);
} else if (!ifp->rt && (ifp->idev->dev->flags & IFF_UP)) {
- pr_warn("BUG: Address %pI6c on device %s is missing its host route.\n",
+ pr_warn("Address %pI6c on device %s is missing its host route.\n",
&ifp->addr, ifp->idev->dev->name);
}
--
2.55.0.654.g21b8a5bc05-goog
^ permalink raw reply related [flat|nested] 4+ messages in thread
* Re: [PATCH] ipv6: addrconf: drop "BUG: " prefix from pr_warn()
2026-08-10 9:51 ` Ido Schimmel
@ 2026-08-10 8:54 ` Pimyn Girgis
2026-08-10 10:40 ` Ido Schimmel
0 siblings, 1 reply; 4+ messages in thread
From: Pimyn Girgis @ 2026-08-10 8:54 UTC (permalink / raw)
To: Ido Schimmel
Cc: dsahern, davem, edumazet, kuba, pabeni, horms, netdev,
linux-kernel, syzbot+ded267b328e950a7c0c4
On Mon, Aug 10, 2026 at 8:54 AM Ido Schimmel <idosch@nvidia.com> wrote:
>
> On Fri, Aug 07, 2026 at 03:13:00PM +0200, Pimyn Girgis wrote:
> > Kernel warning messages emitted via pr_warn() already have the
> > appropriate log level (KERN_WARNING) and should not include manual
> > prefixes such as "BUG: " or "WARNING: ".
> >
> > Explicit "BUG: " prefixes in log strings can mislead testing tools
> > like syzkaller, which scan kernel console output for "BUG: " to
> > identify kernel oopses, panics, and fatal conditions.
> >
> > Remove the manual "BUG: " prefix from the pr_warn() call in
> > __ipv6_ifa_notify().
> >
> > Fixes: 2d819d250a1393 ("ipv6: Handle missing host route in __ipv6_ifa_notify")
> > Reported-by: syzbot+ded267b328e950a7c0c4@syzkaller.appspotmail.com
> > Closes: https://syzkaller.appspot.com/bug?extid=ded267b328e950a7c0c4
> > Signed-off-by: Pimyn Girgis <pimyn@google.com>
>
> I am able to reproduce this (there is no reproducer from syzbot, so I'm
> not sure if it's the same one) and will investigate if we can avoid
> getting into this state. If so, there wouldn't be any need to touch this
> message.
Hi Ido,
Thanks for looking into this!
Correct me if I'm misunderstanding the code comment above that check:
/*
* If the address was optimistic we inserted the route at the
* start of our DAD process, so we don't need to do it again.
* If the device was taken down in the middle of the DAD
* cycle there is a race where we could get here without a
* host route, so nothing to insert. That will be fixed when
* the device is brought up.
*/
It seems this state is somewhat expected/handled and otherwise
harmless. The main issue here is simply that pr_warn() includes the
literal string "BUG: ", which leads syzkaller to treat a non-fatal
warning as a critical kernel panic/crash.
>
>
> Currently busy with more pressing issues, so this will take a while.
Thanks again, and no rush. Whenever you have time to look into it!
--
Ⲡⲟⲓⲙⲏⲛ Ⲅⲉⲱⲣⲅⲓⲟⲥ - Pimyn Girgis
Software Engineer
Kernel Dynamic Analysis
pimyn@google.com
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH] ipv6: addrconf: drop "BUG: " prefix from pr_warn()
2026-08-07 13:13 [PATCH] ipv6: addrconf: drop "BUG: " prefix from pr_warn() Pimyn Girgis
@ 2026-08-10 9:51 ` Ido Schimmel
2026-08-10 8:54 ` Pimyn Girgis
0 siblings, 1 reply; 4+ messages in thread
From: Ido Schimmel @ 2026-08-10 9:51 UTC (permalink / raw)
To: Pimyn Girgis
Cc: dsahern, davem, edumazet, kuba, pabeni, horms, netdev,
linux-kernel, syzbot+ded267b328e950a7c0c4
On Fri, Aug 07, 2026 at 03:13:00PM +0200, Pimyn Girgis wrote:
> Kernel warning messages emitted via pr_warn() already have the
> appropriate log level (KERN_WARNING) and should not include manual
> prefixes such as "BUG: " or "WARNING: ".
>
> Explicit "BUG: " prefixes in log strings can mislead testing tools
> like syzkaller, which scan kernel console output for "BUG: " to
> identify kernel oopses, panics, and fatal conditions.
>
> Remove the manual "BUG: " prefix from the pr_warn() call in
> __ipv6_ifa_notify().
>
> Fixes: 2d819d250a1393 ("ipv6: Handle missing host route in __ipv6_ifa_notify")
> Reported-by: syzbot+ded267b328e950a7c0c4@syzkaller.appspotmail.com
> Closes: https://syzkaller.appspot.com/bug?extid=ded267b328e950a7c0c4
> Signed-off-by: Pimyn Girgis <pimyn@google.com>
I am able to reproduce this (there is no reproducer from syzbot, so I'm
not sure if it's the same one) and will investigate if we can avoid
getting into this state. If so, there wouldn't be any need to touch this
message.
Currently busy with more pressing issues, so this will take a while.
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH] ipv6: addrconf: drop "BUG: " prefix from pr_warn()
2026-08-10 8:54 ` Pimyn Girgis
@ 2026-08-10 10:40 ` Ido Schimmel
0 siblings, 0 replies; 4+ messages in thread
From: Ido Schimmel @ 2026-08-10 10:40 UTC (permalink / raw)
To: Pimyn Girgis
Cc: dsahern, davem, edumazet, kuba, pabeni, horms, netdev,
linux-kernel, syzbot+ded267b328e950a7c0c4
On Mon, Aug 10, 2026 at 10:54:58AM +0200, Pimyn Girgis wrote:
> On Mon, Aug 10, 2026 at 8:54 AM Ido Schimmel <idosch@nvidia.com> wrote:
> >
> > On Fri, Aug 07, 2026 at 03:13:00PM +0200, Pimyn Girgis wrote:
> > > Kernel warning messages emitted via pr_warn() already have the
> > > appropriate log level (KERN_WARNING) and should not include manual
> > > prefixes such as "BUG: " or "WARNING: ".
> > >
> > > Explicit "BUG: " prefixes in log strings can mislead testing tools
> > > like syzkaller, which scan kernel console output for "BUG: " to
> > > identify kernel oopses, panics, and fatal conditions.
> > >
> > > Remove the manual "BUG: " prefix from the pr_warn() call in
> > > __ipv6_ifa_notify().
> > >
> > > Fixes: 2d819d250a1393 ("ipv6: Handle missing host route in __ipv6_ifa_notify")
> > > Reported-by: syzbot+ded267b328e950a7c0c4@syzkaller.appspotmail.com
> > > Closes: https://syzkaller.appspot.com/bug?extid=ded267b328e950a7c0c4
> > > Signed-off-by: Pimyn Girgis <pimyn@google.com>
> >
> > I am able to reproduce this (there is no reproducer from syzbot, so I'm
> > not sure if it's the same one) and will investigate if we can avoid
> > getting into this state. If so, there wouldn't be any need to touch this
> > message.
>
> Hi Ido,
>
> Thanks for looking into this!
>
> Correct me if I'm misunderstanding the code comment above that check:
>
> /*
> * If the address was optimistic we inserted the route at the
> * start of our DAD process, so we don't need to do it again.
> * If the device was taken down in the middle of the DAD
> * cycle there is a race where we could get here without a
> * host route, so nothing to insert. That will be fixed when
> * the device is brought up.
> */
>
> It seems this state is somewhat expected/handled and otherwise
> harmless. The main issue here is simply that pr_warn() includes the
> literal string "BUG: ", which leads syzkaller to treat a non-fatal
> warning as a critical kernel panic/crash.
The comment refers to the case where the device is down, but the warning
fires when the device is up. According to the blamed commit, the state
where the warning fires should be impossible to reach: "Add a warning if
the host route is missing AND the device is up; this is a situation that
should never happen". I guess that is why "BUG: " was used.
I have a reproducer that always ends up in this state, so it's not
impossible to reach. I need to see if we can avoid ending up in this
state, and then it should be fine to keep the message since it should
never fire unless there's an actual bug.
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-08-10 10:41 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-07 13:13 [PATCH] ipv6: addrconf: drop "BUG: " prefix from pr_warn() Pimyn Girgis
2026-08-10 9:51 ` Ido Schimmel
2026-08-10 8:54 ` Pimyn Girgis
2026-08-10 10:40 ` Ido Schimmel
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).