[syzbot] [net?] WARNING in tcf_skbmod_act

syzbot <[email protected]>
Newsgroups org.kernel.vger.netdev,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
Hello,

syzbot found the following issue on:

HEAD commit:    66fb95a52111 Merge tag 'caps-pr-20260820' of git://git.ker..
git tree:       upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=135f6179580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=a70bec3546180b6
dashboard link: https://syzkaller.appspot.com/bug?extid=1d56f14f95c0480cfdc9
compiler:       Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/6da0d1c4d90d/disk-66fb95a5.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/34b5360f76fd/vmlinux-66fb95a5.xz
kernel image: https://storage.googleapis.com/syzbot-assets/bea190471e9f/bzImage-66fb95a5.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: [email protected]

------------[ cut here ]------------
!skb_transport_header_was_set(skb)
WARNING: ./include/linux/skbuff.h:3243 at skb_network_header_len include/linux/skbuff.h:3243 [inline], CPU#0: syz.0.2516/14949
WARNING: ./include/linux/skbuff.h:3243 at tcf_skbmod_act+0xfe8/0x1810 net/sched/act_skbmod.c:55, CPU#0: syz.0.2516/14949
Modules linked in:
CPU: 0 UID: 0 PID: 14949 Comm: syz.0.2516 Tainted: G             L      syzkaller #0 PREEMPT(full) 
Tainted: [L]=SOFTLOCKUP
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
RIP: 0010:skb_network_header_len include/linux/skbuff.h:3243 [inline]
RIP: 0010:tcf_skbmod_act+0xfe8/0x1810 net/sched/act_skbmod.c:55
Code: 48 c1 e8 03 42 80 3c 20 00 74 08 48 89 df e8 6f 05 60 f8 48 8b 03 65 ff 40 10 b8 02 00 00 00 e9 66 ff ff ff e8 99 5b f0 f7 90 <0f> 0b 90 e9 a0 f5 ff ff e8 8b 5b f0 f7 90 0f 0b 90 e9 49 f6 ff ff
RSP: 0018:ffffc90006c571c8 EFLAGS: 00010293
RAX: ffffffff89d6cdf7 RBX: 1ffff1100fa67d56 RCX: ffff888029678000
RDX: 0000000000000000 RSI: 000000000000ffff RDI: 000000000000ffff
RBP: 0000000000000010 R08: ffff888029678000 R09: 0000000000000002
R10: 000000000000dd86 R11: 0000000000000000 R12: 000000000000ffff
R13: ffff88807d33eab6 R14: 000000000000000e R15: ffff88807d33eaba
FS:  00007fecc9f156c0(0000) GS:ffff888124cfd000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fecc9f14ff8 CR3: 00000000265a6000 CR4: 00000000003526f0
Call Trace:
 <TASK>
 tc_act include/net/tc_wrapper.h:131 [inline]
 tcf_action_exec+0x185/0x8d0 net/sched/act_api.c:1150
 tcf_exts_exec include/net/pkt_cls.h:361 [inline]
 basic_classify+0x1b2/0x2d0 net/sched/cls_basic.c:54
 tc_classify include/net/tc_wrapper.h:198 [inline]
 __tcf_classify net/sched/cls_api.c:1779 [inline]
 tcf_classify+0x43d/0x1160 net/sched/cls_api.c:1875
 tc_run+0x42d/0x750 net/core/dev.c:4463
 sch_handle_ingress net/core/dev.c:4538 [inline]
 __netif_receive_skb_core+0x1443/0x30c0 net/core/dev.c:6115
 __netif_receive_skb_one_core net/core/dev.c:6262 [inline]
 __netif_receive_skb net/core/dev.c:6377 [inline]
 netif_receive_skb_internal net/core/dev.c:6463 [inline]
 netif_receive_skb+0x1fe/0xbf0 net/core/dev.c:6522
 tun_rx_batched+0x1de/0x790 drivers/net/tun.c:1571
 tun_get_user+0x2be0/0x44d0 drivers/net/tun.c:2045
 tun_chr_write_iter+0x113/0x200 drivers/net/tun.c:2091
 new_sync_write fs/read_write.c:595 [inline]
 vfs_write+0x612/0xba0 fs/read_write.c:687
 ksys_write+0x150/0x270 fs/read_write.c:739
 do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline]
 do_syscall_64+0x166/0x520 arch/x86/entry/syscall_64.c:84
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fecc8f5e90e
Code: 08 0f 85 a5 a8 ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 <c3> 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 80 00 00 00 00 48 83 ec 08
RSP: 002b:00007fecc9f14fb8 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 00007fecc9f156c0 RCX: 00007fecc8f5e90e
RDX: 0000000000000097 RSI: 0000200000000080 RDI: 00000000000000c8
RBP: 00007fecc9035024 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007fecc9226038 R14: 00007fecc9225fa0 R15: 00007fecc934fa48
 </TASK>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at [email protected].

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.