From: syzbot <syzbot+adb0bf16414b8bb2d799@syzkaller.appspotmail.com>
To: alex.aring@gmail.com, andrew@lunn.ch, davem@davemloft.net,
edumazet@google.com, kuba@kernel.org,
linux-kernel@vger.kernel.org, linux-wpan@vger.kernel.org,
miquel.raynal@bootlin.com, netdev@vger.kernel.org,
pabeni@redhat.com, stefan@datenfreihafen.org,
syzkaller-bugs@googlegroups.com
Subject: Re: [syzbot] [wpan?] WARNING in hwsim_hw_xmit
Date: Thu, 17 Sep 2026 12:05:29 -0700 [thread overview]
Message-ID: <6aac39f9.71f81b7d.278072.0020.GAE@google.com> (raw)
In-Reply-To: <6aa7c510.4c28b7d0.c1bba.0017.GAE@google.com>
syzbot has found a reproducer for the following issue on:
HEAD commit: 4982d3552a3b Merge tag 'sound-7.3-rc4' of git://git.kernel..
git tree: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
console output: https://syzkaller.appspot.com/x/log.txt?x=158afbf9580000
kernel config: https://syzkaller.appspot.com/x/.config?x=84649d3ff8d550cb
dashboard link: https://syzkaller.appspot.com/bug?extid=adb0bf16414b8bb2d799
compiler: gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=13fa7bf9580000
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+adb0bf16414b8bb2d799@syzkaller.appspotmail.com
------------[ cut here ]------------
current_phy->suspended
WARNING: drivers/net/ieee802154/mac802154_hwsim.c:266 at hwsim_hw_xmit+0xcbf/0x1540 drivers/net/ieee802154/mac802154_hwsim.c:266, CPU#0: syz-executor682/6038
Modules linked in:
CPU: 0 UID: 0 PID: 6038 Comm: syz-executor682 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:hwsim_hw_xmit+0xcbf/0x1540 drivers/net/ieee802154/mac802154_hwsim.c:266
Code: 48 c7 c2 40 3f c0 8c be 52 03 00 00 48 c7 c7 a0 3f c0 8c c6 05 8f 23 c6 09 01 e8 7c 1b 80 fa e9 c6 f8 ff ff e8 52 5a a5 fa 90 <0f> 0b 90 e9 11 f4 ff ff e8 44 5a a5 fa e8 1f 0a 89 fa 31 ff 89 c5
RSP: 0018:ffffc90003a0f650 EFLAGS: 00010293
RAX: 0000000000000000 RBX: ffff88802a808d20 RCX: 0000000000000202
RDX: ffff8880295e8000 RSI: ffffffff8766c55e RDI: ffff8880295e8000
RBP: 0000000000000001 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000000001 R11: 0000000000000001 R12: ffffffff8766b8a0
R13: 1ffff92000741ed4 R14: ffff88802a808720 R15: 0000000000000053
FS: 00007f554300f6c0(0000) GS:ffff8880d5b59000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f554300eff8 CR3: 0000000022b9e000 CR4: 0000000000352ef0
Call Trace:
<TASK>
drv_xmit_async net/mac802154/driver-ops.h:16 [inline]
ieee802154_tx.isra.0+0x29f/0x570 net/mac802154/tx.c:89
ieee802154_subif_start_xmit+0xc8/0xf0 net/mac802154/tx.c:239
__netdev_start_xmit include/linux/netdevice.h:5429 [inline]
netdev_start_xmit include/linux/netdevice.h:5438 [inline]
xmit_one net/core/dev.c:3937 [inline]
dev_hard_start_xmit+0x121/0x760 net/core/dev.c:3953
sch_direct_xmit+0x1b2/0xc70 net/sched/sch_generic.c:372
qdisc_restart net/sched/sch_generic.c:437 [inline]
__qdisc_run+0x52d/0x1b20 net/sched/sch_generic.c:445
qdisc_run include/net/pkt_sched.h:121 [inline]
qdisc_run include/net/pkt_sched.h:118 [inline]
__dev_xmit_skb net/core/dev.c:4272 [inline]
__dev_queue_xmit+0x18b9/0x4970 net/core/dev.c:4884
dev_queue_xmit include/linux/netdevice.h:3461 [inline]
dgram_sendmsg+0xa0d/0xf50 net/ieee802154/socket.c:689
sock_sendmsg_nosec net/socket.c:800 [inline]
__sock_sendmsg net/socket.c:815 [inline]
__sys_sendto+0x48b/0x4e0 net/socket.c:2281
__do_sys_sendto net/socket.c:2288 [inline]
__se_sys_sendto net/socket.c:2284 [inline]
__x64_sys_sendto+0xe0/0x1c0 net/socket.c:2284
do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline]
do_syscall_64+0x123/0x790 arch/x86/entry/syscall_64.c:84
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f554306749e
Code: 08 0f 85 f5 e2 ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 <c3> 90 41 57 41 56 4d 89 c6 41 55 4d 89 cd 41 54 55 53 48 83 ec 08
RSP: 002b:00007f554300f168 EFLAGS: 00000246 ORIG_RAX: 000000000000002c
RAX: ffffffffffffffda RBX: 00007f554300f6c0 RCX: 00007f554306749e
RDX: 0000000000000040 RSI: 00007f554300f1d0 RDI: 0000000000000004
RBP: 0000000000000021 R08: 00007f55430e5b10 R09: 0000000000000014
R10: 0000000000000000 R11: 0000000000000246 R12: ffffffffffffffd0
R13: 000000000000000b R14: 00007ffdf0e50d30 R15: 00007ffdf0e50e18
</TASK>
---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
prev parent reply other threads:[~2026-09-17 19:05 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-14 9:57 syzbot
2026-09-17 19:05 ` syzbot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=6aac39f9.71f81b7d.278072.0020.GAE@google.com \
--to=syzbot+adb0bf16414b8bb2d799@syzkaller.appspotmail.com \
--cc=alex.aring@gmail.com \
--cc=andrew@lunn.ch \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-wpan@vger.kernel.org \
--cc=miquel.raynal@bootlin.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=stefan@datenfreihafen.org \
--cc=syzkaller-bugs@googlegroups.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®