* Re: [syzbot] [wireless?] WARNING in cfg80211_scan_done
2024-08-13 14:03 [syzbot] [wireless?] WARNING in cfg80211_scan_done syzbot
@ 2025-06-13 3:55 ` syzbot
2025-06-19 8:05 ` [PATCH] wifi: cfg80211: Prevent comparison with invalid registered dev scan req Lizhi Xu
2025-06-19 2:52 ` [syzbot] Re: [syzbot] [wireless?] WARNING in cfg80211_scan_done syzbot
` (2 subsequent siblings)
3 siblings, 1 reply; 8+ messages in thread
From: syzbot @ 2025-06-13 3:55 UTC (permalink / raw)
To: davem, edumazet, johannes, kuba, linux-kernel, linux-wireless,
netdev, pabeni, syzkaller-bugs
syzbot has found a reproducer for the following issue on:
HEAD commit: 19272b37aa4f Linux 6.16-rc1
git tree: git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git for-kernelci
console output: https://syzkaller.appspot.com/x/log.txt?x=10e239d4580000
kernel config: https://syzkaller.appspot.com/x/.config?x=8409c4d4e51ac27
dashboard link: https://syzkaller.appspot.com/bug?extid=189dcafc06865d38178d
compiler: Debian clang version 20.1.6 (++20250514063057+1e4d39e07757-1~exp1~20250514183223.118), Debian LLD 20.1.6
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=14e239d4580000
Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/92d22b0c6493/disk-19272b37.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/3fb0142bb63a/vmlinux-19272b37.xz
kernel image: https://storage.googleapis.com/syzbot-assets/3d5f3836ae42/Image-19272b37.gz.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+189dcafc06865d38178d@syzkaller.appspotmail.com
------------[ cut here ]------------
WARNING: CPU: 1 PID: 2225 at net/wireless/scan.c:1182 cfg80211_scan_done+0x2c8/0x4b0 net/wireless/scan.c:1181
Modules linked in:
CPU: 1 UID: 0 PID: 2225 Comm: kworker/u8:12 Not tainted 6.16.0-rc1-syzkaller-g19272b37aa4f #0 PREEMPT
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025
Workqueue: events_unbound cfg80211_wiphy_work
pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : cfg80211_scan_done+0x2c8/0x4b0 net/wireless/scan.c:1181
lr : cfg80211_scan_done+0x2c8/0x4b0 net/wireless/scan.c:1181
sp : ffff8000a14d77c0
x29: ffff8000a14d7820 x28: ffff0000c7570700 x27: 1fffe00019a1e20c
x26: 1ffff0001429aef8 x25: dfff800000000000 x24: ffff0000c75701b8
x23: ffff0000cd0f1060 x22: ffff0000c75729f0 x21: ffff0000cd0f1070
x20: ffff8000a14d77e0 x19: ffff0000cd0f1000 x18: 1fffe00033807876
x17: ffff80008f55e000 x16: ffff80008ae5617c x15: 0000000000000002
x14: 1ffff0001429aefc x13: 0000000000000000 x12: 0000000000000000
x11: ffff70001429aefe x10: 0000000000ff0100 x9 : 0000000000000000
x8 : ffff0000cc293d00 x7 : 0000000000000000 x6 : 0000000000000000
x5 : ffff8000a14d77f0 x4 : ffff0000cd0f1080 x3 : ffff80008a530eec
x2 : 0000000000000010 x1 : ffff80008b492da0 x0 : 0000000000000001
Call trace:
cfg80211_scan_done+0x2c8/0x4b0 net/wireless/scan.c:1181 (P)
__ieee80211_scan_completed+0x4ec/0xae0 net/mac80211/scan.c:501
ieee80211_scan_work+0x140/0x18c4 net/mac80211/scan.c:1177
cfg80211_wiphy_work+0x2a8/0x48c net/wireless/core.c:435
process_one_work+0x7e8/0x155c kernel/workqueue.c:3238
process_scheduled_works kernel/workqueue.c:3321 [inline]
worker_thread+0x958/0xed8 kernel/workqueue.c:3402
kthread+0x5fc/0x75c kernel/kthread.c:464
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:847
irq event stamp: 1301622
hardirqs last enabled at (1301621): [<ffff8000830764a8>] class_irqsave_destructor include/linux/irqflags.h:266 [inline]
hardirqs last enabled at (1301621): [<ffff8000830764a8>] __free_object+0x528/0x71c lib/debugobjects.c:524
hardirqs last disabled at (1301622): [<ffff80008ae5160c>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:511
softirqs last enabled at (1301568): [<ffff80008644576c>] spin_unlock_bh include/linux/spinlock.h:396 [inline]
softirqs last enabled at (1301568): [<ffff80008644576c>] nsim_dev_trap_report drivers/net/netdevsim/dev.c:820 [inline]
softirqs last enabled at (1301568): [<ffff80008644576c>] nsim_dev_trap_report_work+0x67c/0x9fc drivers/net/netdevsim/dev.c:851
softirqs last disabled at (1301566): [<ffff8000864456e4>] spin_lock_bh include/linux/spinlock.h:356 [inline]
softirqs last disabled at (1301566): [<ffff8000864456e4>] nsim_dev_trap_report drivers/net/netdevsim/dev.c:816 [inline]
softirqs last disabled at (1301566): [<ffff8000864456e4>] nsim_dev_trap_report_work+0x5f4/0x9fc drivers/net/netdevsim/dev.c:851
---[ end trace 0000000000000000 ]---
---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
^ permalink raw reply [flat|nested] 8+ messages in thread* Re: [syzbot] Re: [syzbot] [wireless?] WARNING in cfg80211_scan_done
2024-08-13 14:03 [syzbot] [wireless?] WARNING in cfg80211_scan_done syzbot
2025-06-13 3:55 ` syzbot
@ 2025-06-19 2:52 ` syzbot
2025-06-19 7:37 ` syzbot
2026-01-05 17:04 ` syzbot
3 siblings, 0 replies; 8+ messages in thread
From: syzbot @ 2025-06-19 2:52 UTC (permalink / raw)
To: linux-kernel
For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org.
***
Subject: Re: [syzbot] [wireless?] WARNING in cfg80211_scan_done
Author: lizhi.xu@windriver.com
#syz test
diff --git a/net/mac80211/scan.c b/net/mac80211/scan.c
index cd8385ecafd9..7fc1e98abb2c 100644
--- a/net/mac80211/scan.c
+++ b/net/mac80211/scan.c
@@ -498,6 +498,8 @@ static void __ieee80211_scan_completed(struct ieee80211_hw *hw, bool aborted)
if (scan_req != local->int_scan_req) {
local->scan_info.aborted = aborted;
+ printk("local: %p, sr: %p, wip: %p, %s\n",
+ local, scan_req, scan_req->wiphy, __func__);
cfg80211_scan_done(scan_req, &local->scan_info);
}
@@ -1123,6 +1125,8 @@ void ieee80211_scan_work(struct wiphy *wiphy, struct wiphy_work *work)
/* need to complete scan in cfg80211 */
rcu_assign_pointer(local->scan_req, scan_req);
aborted = true;
+ printk("local: %p, sr: %p, wip: %p, %s\n",
+ local, scan_req, scan_req->wiphy, __func__);
goto out_complete;
}
@@ -1135,6 +1139,8 @@ void ieee80211_scan_work(struct wiphy *wiphy, struct wiphy_work *work)
do {
if (!ieee80211_sdata_running(sdata)) {
aborted = true;
+ printk("2local: %p, sr: %p, wip: %p, %s\n",
+ local, scan_req, scan_req->wiphy, __func__);
goto out_complete;
}
@@ -1147,6 +1153,8 @@ void ieee80211_scan_work(struct wiphy *wiphy, struct wiphy_work *work)
/* if no more bands/channels left, complete scan */
if (local->scan_channel_idx >= scan_req->n_channels) {
aborted = false;
+ printk("3local: %p, sr: %p, wip: %p, %s\n",
+ local, scan_req, scan_req->wiphy, __func__);
goto out_complete;
}
ieee80211_scan_state_decision(local, &next_delay);
@@ -1165,6 +1173,8 @@ void ieee80211_scan_work(struct wiphy *wiphy, struct wiphy_work *work)
break;
case SCAN_ABORT:
aborted = true;
+ printk("4local: %p, sr: %p, wip: %p, %s\n",
+ local, scan_req, scan_req->wiphy, __func__);
goto out_complete;
}
} while (next_delay == 0);
diff --git a/net/wireless/scan.c b/net/wireless/scan.c
index e8a4fe44ec2d..7c1f80be24bb 100644
--- a/net/wireless/scan.c
+++ b/net/wireless/scan.c
@@ -1178,6 +1178,11 @@ void cfg80211_scan_done(struct cfg80211_scan_request *request,
struct cfg80211_scan_info old_info = request->info;
trace_cfg80211_scan_done(request, info);
+ printk("r: %p, wiphy: %p, scan_req: %p, int_scan_req: %p, %s\n",
+ request, request->wiphy,
+ wiphy_to_rdev(request->wiphy)->scan_req,
+ wiphy_to_rdev(request->wiphy)->int_scan_req,
+ __func__);
WARN_ON(request != wiphy_to_rdev(request->wiphy)->scan_req &&
request != wiphy_to_rdev(request->wiphy)->int_scan_req);
^ permalink raw reply [flat|nested] 8+ messages in thread* Re: [syzbot] [wireless?] WARNING in cfg80211_scan_done
2024-08-13 14:03 [syzbot] [wireless?] WARNING in cfg80211_scan_done syzbot
` (2 preceding siblings ...)
2025-06-19 7:37 ` syzbot
@ 2026-01-05 17:04 ` syzbot
3 siblings, 0 replies; 8+ messages in thread
From: syzbot @ 2026-01-05 17:04 UTC (permalink / raw)
To: davem, edumazet, johannes, kuba, linux-kernel, linux-wireless,
lizhi.xu, netdev, pabeni, syzkaller-bugs
syzbot has found a reproducer for the following issue on:
HEAD commit: 3609fa95fb0f Merge tag 'devicetree-fixes-for-6.19-2' of gi..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=17dac074580000
kernel config: https://syzkaller.appspot.com/x/.config?x=1f2b6fe1fdf1a00b
dashboard link: https://syzkaller.appspot.com/bug?extid=189dcafc06865d38178d
compiler: Debian clang version 20.1.8 (++20250708063551+0c9f909b7976-1~exp1~20250708183702.136), Debian LLD 20.1.8
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=135c2f92580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=175c2f92580000
Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/e4b2b971f67c/disk-3609fa95.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/9b03d2a13efd/vmlinux-3609fa95.xz
kernel image: https://storage.googleapis.com/syzbot-assets/2727d816c6d5/bzImage-3609fa95.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+189dcafc06865d38178d@syzkaller.appspotmail.com
------------[ cut here ]------------
WARNING: net/wireless/scan.c:1194 at cfg80211_scan_done+0x2d5/0x460 net/wireless/scan.c:1193, CPU#0: kworker/u8:15/3576
Modules linked in:
CPU: 0 UID: 0 PID: 3576 Comm: kworker/u8:15 Not tainted syzkaller #0 PREEMPT_{RT,(full)}
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/25/2025
Workqueue: events_unbound cfg80211_wiphy_work
RIP: 0010:cfg80211_scan_done+0x2d5/0x460 net/wireless/scan.c:1193
Code: 75 7b 48 8d 65 d8 5b 41 5c 41 5d 41 5e 41 5f 5d c3 cc cc cc cc cc e8 7a 8a 9c f7 90 0f 0b 90 e9 25 fe ff ff e8 6c 8a 9c f7 90 <0f> 0b 90 e9 db fe ff ff e8 5e 8a 9c f7 48 8d 3d f7 43 c7 04 67 48
RSP: 0018:ffffc9000d2e78e0 EFLAGS: 00010293
RAX: ffffffff8a2321c4 RBX: ffff88802e603618 RCX: ffff88803083dac0
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: ffffc9000d2e79a8 R08: 0000000000000000 R09: 0000000000000000
R10: dffffc0000000000 R11: fffffbfff1db66ef R12: ffff88802e603600
R13: ffff88802e603678 R14: dffffc0000000000 R15: ffff888031c10860
FS: 0000000000000000(0000) GS:ffff888126cef000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fff386e7408 CR3: 000000000d3a8000 CR4: 00000000003526f0
Call Trace:
<TASK>
__ieee80211_scan_completed+0x550/0xb20 net/mac80211/scan.c:505
cfg80211_wiphy_work+0x2ab/0x450 net/wireless/core.c:438
process_one_work kernel/workqueue.c:3257 [inline]
process_scheduled_works+0xad1/0x1770 kernel/workqueue.c:3340
worker_thread+0x8a0/0xda0 kernel/workqueue.c:3421
kthread+0x711/0x8a0 kernel/kthread.c:463
ret_from_fork+0x510/0xa50 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:246
</TASK>
---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
^ permalink raw reply [flat|nested] 8+ messages in thread