Re: [syzbot] [net?] [usb?] BUG: using smp_processor_id() in preemptible code in tx_complete
syzbot <[email protected]>
| Newsgroups | org.kernel.vger.linux-usb,org.kernel.vger.linux-kernel,org.kernel.vger.netdev |
|---|---|
| Message-ID | <[email protected]> |
syzbot has found a reproducer for the following issue on: HEAD commit: a59f57e2aa12 Merge tag 'watchdog-for-v7.2-rc7' of git://gi.. git tree: upstream console output: https://syzkaller.appspot.com/x/log.txt?x=127defb9580000 kernel config: https://syzkaller.appspot.com/x/.config?x=d07fbc6821d72a61 dashboard link: https://syzkaller.appspot.com/bug?extid=04cd90bb99c6ef81a65d compiler: gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44 C reproducer: https://syzkaller.appspot.com/x/repro.c?x=17106fb9580000 IMPORTANT: if you fix the issue, please add the following tag to the commit: Reported-by: [email protected] BUG: using smp_processor_id() in preemptible [00000000] code: vhci_rx/6048 caller is tx_complete+0x237/0x770 drivers/net/usb/usbnet.c:1301 CPU: 2 UID: 0 PID: 6048 Comm: vhci_rx Not tainted syzkaller #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 Call Trace: <TASK> __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x100/0x190 lib/dump_stack.c:120 check_preemption_disabled+0xd8/0xe0 lib/smp_processor_id.c:47 tx_complete+0x237/0x770 drivers/net/usb/usbnet.c:1301 __usb_hcd_giveback_urb+0x38d/0x610 drivers/usb/core/hcd.c:1657 usb_hcd_giveback_urb+0x3ca/0x4a0 drivers/usb/core/hcd.c:1741 vhci_recv_ret_submit drivers/usb/usbip/vhci_rx.c:107 [inline] vhci_rx_pdu drivers/usb/usbip/vhci_rx.c:242 [inline] vhci_rx_loop+0x60e/0xa60 drivers/usb/usbip/vhci_rx.c:265 kthread+0x370/0x450 kernel/kthread.c:436 ret_from_fork+0x72b/0xd50 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 </TASK> BUG: using smp_processor_id() in preemptible [00000000] code: vhci_rx/6048 caller is tx_complete+0x237/0x770 drivers/net/usb/usbnet.c:1301 CPU: 1 UID: 0 PID: 6048 Comm: vhci_rx Not tainted syzkaller #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 Call Trace: <TASK> __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x100/0x190 lib/dump_stack.c:120 check_preemption_disabled+0xd8/0xe0 lib/smp_processor_id.c:47 tx_complete+0x237/0x770 drivers/net/usb/usbnet.c:1301 __usb_hcd_giveback_urb+0x38d/0x610 drivers/usb/core/hcd.c:1657 usb_hcd_giveback_urb+0x3ca/0x4a0 drivers/usb/core/hcd.c:1741 vhci_recv_ret_submit drivers/usb/usbip/vhci_rx.c:107 [inline] vhci_rx_pdu drivers/usb/usbip/vhci_rx.c:242 [inline] vhci_rx_loop+0x60e/0xa60 drivers/usb/usbip/vhci_rx.c:265 kthread+0x370/0x450 kernel/kthread.c:436 ret_from_fork+0x72b/0xd50 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 </TASK> BUG: using smp_processor_id() in preemptible [00000000] code: vhci_rx/6048 caller is tx_complete+0x237/0x770 drivers/net/usb/usbnet.c:1301 CPU: 3 UID: 0 PID: 6048 Comm: vhci_rx Not tainted syzkaller #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 Call Trace: <TASK> __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x100/0x190 lib/dump_stack.c:120 check_preemption_disabled+0xd8/0xe0 lib/smp_processor_id.c:47 tx_complete+0x237/0x770 drivers/net/usb/usbnet.c:1301 __usb_hcd_giveback_urb+0x38d/0x610 drivers/usb/core/hcd.c:1657 usb_hcd_giveback_urb+0x3ca/0x4a0 drivers/usb/core/hcd.c:1741 vhci_recv_ret_submit drivers/usb/usbip/vhci_rx.c:107 [inline] vhci_rx_pdu drivers/usb/usbip/vhci_rx.c:242 [inline] vhci_rx_loop+0x60e/0xa60 drivers/usb/usbip/vhci_rx.c:265 kthread+0x370/0x450 kernel/kthread.c:436 ret_from_fork+0x72b/0xd50 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 </TASK> BUG: using smp_processor_id() in preemptible [00000000] code: vhci_rx/6048 caller is tx_complete+0x237/0x770 drivers/net/usb/usbnet.c:1301 CPU: 0 UID: 0 PID: 6048 Comm: vhci_rx Not tainted syzkaller #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 Call Trace: <TASK> __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x100/0x190 lib/dump_stack.c:120 check_preemption_disabled+0xd8/0xe0 lib/smp_processor_id.c:47 tx_complete+0x237/0x770 drivers/net/usb/usbnet.c:1301 __usb_hcd_giveback_urb+0x38d/0x610 drivers/usb/core/hcd.c:1657 usb_hcd_giveback_urb+0x3ca/0x4a0 drivers/usb/core/hcd.c:1741 vhci_recv_ret_submit drivers/usb/usbip/vhci_rx.c:107 [inline] vhci_rx_pdu drivers/usb/usbip/vhci_rx.c:242 [inline] vhci_rx_loop+0x60e/0xa60 drivers/usb/usbip/vhci_rx.c:265 kthread+0x370/0x450 kernel/kthread.c:436 ret_from_fork+0x72b/0xd50 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 </TASK> BUG: using smp_processor_id() in preemptible [00000000] code: vhci_rx/6048 caller is tx_complete+0x237/0x770 drivers/net/usb/usbnet.c:1301 CPU: 0 UID: 0 PID: 6048 Comm: vhci_rx Not tainted syzkaller #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 Call Trace: <TASK> __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x100/0x190 lib/dump_stack.c:120 check_preemption_disabled+0xd8/0xe0 lib/smp_processor_id.c:47 tx_complete+0x237/0x770 drivers/net/usb/usbnet.c:1301 __usb_hcd_giveback_urb+0x38d/0x610 drivers/usb/core/hcd.c:1657 usb_hcd_giveback_urb+0x3ca/0x4a0 drivers/usb/core/hcd.c:1741 vhci_recv_ret_submit drivers/usb/usbip/vhci_rx.c:107 [inline] vhci_rx_pdu drivers/usb/usbip/vhci_rx.c:242 [inline] vhci_rx_loop+0x60e/0xa60 drivers/usb/usbip/vhci_rx.c:265 kthread+0x370/0x450 kernel/kthread.c:436 ret_from_fork+0x72b/0xd50 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 </TASK> BUG: using smp_processor_id() in preemptible [00000000] code: vhci_rx/6048 caller is tx_complete+0x237/0x770 drivers/net/usb/usbnet.c:1301 CPU: 0 UID: 0 PID: 6048 Comm: vhci_rx Not tainted syzkaller #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 Call Trace: <TASK> __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x100/0x190 lib/dump_stack.c:120 check_preemption_disabled+0xd8/0xe0 lib/smp_processor_id.c:47 tx_complete+0x237/0x770 drivers/net/usb/usbnet.c:1301 __usb_hcd_giveback_urb+0x38d/0x610 drivers/usb/core/hcd.c:1657 usb_hcd_giveback_urb+0x3ca/0x4a0 drivers/usb/core/hcd.c:1741 vhci_recv_ret_submit drivers/usb/usbip/vhci_rx.c:107 [inline] vhci_rx_pdu drivers/usb/usbip/vhci_rx.c:242 [inline] vhci_rx_loop+0x60e/0xa60 drivers/usb/usbip/vhci_rx.c:265 kthread+0x370/0x450 kernel/kthread.c:436 ret_from_fork+0x72b/0xd50 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 </TASK> BUG: using smp_processor_id() in preemptible [00000000] code: vhci_rx/6048 caller is tx_complete+0x237/0x770 drivers/net/usb/usbnet.c:1301 CPU: 2 UID: 0 PID: 6048 Comm: vhci_rx Not tainted syzkaller #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 Call Trace: <TASK> __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x100/0x190 lib/dump_stack.c:120 check_preemption_disabled+0xd8/0xe0 lib/smp_processor_id.c:47 tx_complete+0x237/0x770 drivers/net/usb/usbnet.c:1301 __usb_hcd_giveback_urb+0x38d/0x610 drivers/usb/core/hcd.c:1657 usb_hcd_giveback_urb+0x3ca/0x4a0 drivers/usb/core/hcd.c:1741 vhci_recv_ret_submit drivers/usb/usbip/vhci_rx.c:107 [inline] vhci_rx_pdu drivers/usb/usbip/vhci_rx.c:242 [inline] vhci_rx_loop+0x60e/0xa60 drivers/usb/usbip/vhci_rx.c:265 kthread+0x370/0x450 kernel/kthread.c:436 ret_from_fork+0x72b/0xd50 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 </TASK> BUG: using smp_processor_id() in preemptible [00000000] code: vhci_rx/6048 caller is tx_complete+0x237/0x770 drivers/net/usb/usbnet.c:1301 CPU: 3 UID: 0 PID: 6048 Comm: vhci_rx Not tainted syzkaller #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 Call Trace: <TASK> __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x100/0x190 lib/dump_stack.c:120 check_preemption_disabled+0xd8/0xe0 lib/smp_processor_id.c:47 tx_complete+0x237/0x770 drivers/net/usb/usbnet.c:1301 __usb_hcd_giveback_urb+0x38d/0x610 drivers/usb/core/hcd.c:1657 usb_hcd_giveback_urb+0x3ca/0x4a0 drivers/usb/core/hcd.c:1741 vhci_recv_ret_submit drivers/usb/usbip/vhci_rx.c:107 [inline] vhci_rx_pdu drivers/usb/usbip/vhci_rx.c:242 [inline] vhci_rx_loop+0x60e/0xa60 drivers/usb/usbip/vhci_rx.c:265 kthread+0x370/0x450 kernel/kthread.c:436 ret_from_fork+0x72b/0xd50 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 </TASK> vhci_hcd: connection reset by peer --- If you want syzbot to run the reproducer, reply with: #syz test: git://repo/address.git branch-or-commit-hash If you attach or paste a git patch, syzbot will apply it before testing.