mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: syzbot <syzbot+adb0bf16414b8bb2d799@syzkaller.appspotmail.com>
To: alex.aring@gmail.com, andrew@lunn.ch, davem@davemloft.net,
	 edumazet@google.com, kuba@kernel.org,
	linux-kernel@vger.kernel.org,  linux-wpan@vger.kernel.org,
	miquel.raynal@bootlin.com, netdev@vger.kernel.org,
	 pabeni@redhat.com, stefan@datenfreihafen.org,
	syzkaller-bugs@googlegroups.com
Subject: Re: [syzbot] [wpan?] WARNING in hwsim_hw_xmit
Date: Thu, 17 Sep 2026 12:05:29 -0700	[thread overview]
Message-ID: <6aac39f9.71f81b7d.278072.0020.GAE@google.com> (raw)
In-Reply-To: <6aa7c510.4c28b7d0.c1bba.0017.GAE@google.com>

syzbot has found a reproducer for the following issue on:

HEAD commit:    4982d3552a3b Merge tag 'sound-7.3-rc4' of git://git.kernel..
git tree:       git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
console output: https://syzkaller.appspot.com/x/log.txt?x=158afbf9580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=84649d3ff8d550cb
dashboard link: https://syzkaller.appspot.com/bug?extid=adb0bf16414b8bb2d799
compiler:       gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
C reproducer:   https://syzkaller.appspot.com/x/repro.c?x=13fa7bf9580000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+adb0bf16414b8bb2d799@syzkaller.appspotmail.com

------------[ cut here ]------------
current_phy->suspended
WARNING: drivers/net/ieee802154/mac802154_hwsim.c:266 at hwsim_hw_xmit+0xcbf/0x1540 drivers/net/ieee802154/mac802154_hwsim.c:266, CPU#0: syz-executor682/6038
Modules linked in:
CPU: 0 UID: 0 PID: 6038 Comm: syz-executor682 Not tainted syzkaller #0 PREEMPT(full) 
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:hwsim_hw_xmit+0xcbf/0x1540 drivers/net/ieee802154/mac802154_hwsim.c:266
Code: 48 c7 c2 40 3f c0 8c be 52 03 00 00 48 c7 c7 a0 3f c0 8c c6 05 8f 23 c6 09 01 e8 7c 1b 80 fa e9 c6 f8 ff ff e8 52 5a a5 fa 90 <0f> 0b 90 e9 11 f4 ff ff e8 44 5a a5 fa e8 1f 0a 89 fa 31 ff 89 c5
RSP: 0018:ffffc90003a0f650 EFLAGS: 00010293
RAX: 0000000000000000 RBX: ffff88802a808d20 RCX: 0000000000000202
RDX: ffff8880295e8000 RSI: ffffffff8766c55e RDI: ffff8880295e8000
RBP: 0000000000000001 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000000001 R11: 0000000000000001 R12: ffffffff8766b8a0
R13: 1ffff92000741ed4 R14: ffff88802a808720 R15: 0000000000000053
FS:  00007f554300f6c0(0000) GS:ffff8880d5b59000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f554300eff8 CR3: 0000000022b9e000 CR4: 0000000000352ef0
Call Trace:
 <TASK>
 drv_xmit_async net/mac802154/driver-ops.h:16 [inline]
 ieee802154_tx.isra.0+0x29f/0x570 net/mac802154/tx.c:89
 ieee802154_subif_start_xmit+0xc8/0xf0 net/mac802154/tx.c:239
 __netdev_start_xmit include/linux/netdevice.h:5429 [inline]
 netdev_start_xmit include/linux/netdevice.h:5438 [inline]
 xmit_one net/core/dev.c:3937 [inline]
 dev_hard_start_xmit+0x121/0x760 net/core/dev.c:3953
 sch_direct_xmit+0x1b2/0xc70 net/sched/sch_generic.c:372
 qdisc_restart net/sched/sch_generic.c:437 [inline]
 __qdisc_run+0x52d/0x1b20 net/sched/sch_generic.c:445
 qdisc_run include/net/pkt_sched.h:121 [inline]
 qdisc_run include/net/pkt_sched.h:118 [inline]
 __dev_xmit_skb net/core/dev.c:4272 [inline]
 __dev_queue_xmit+0x18b9/0x4970 net/core/dev.c:4884
 dev_queue_xmit include/linux/netdevice.h:3461 [inline]
 dgram_sendmsg+0xa0d/0xf50 net/ieee802154/socket.c:689
 sock_sendmsg_nosec net/socket.c:800 [inline]
 __sock_sendmsg net/socket.c:815 [inline]
 __sys_sendto+0x48b/0x4e0 net/socket.c:2281
 __do_sys_sendto net/socket.c:2288 [inline]
 __se_sys_sendto net/socket.c:2284 [inline]
 __x64_sys_sendto+0xe0/0x1c0 net/socket.c:2284
 do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline]
 do_syscall_64+0x123/0x790 arch/x86/entry/syscall_64.c:84
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f554306749e
Code: 08 0f 85 f5 e2 ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 <c3> 90 41 57 41 56 4d 89 c6 41 55 4d 89 cd 41 54 55 53 48 83 ec 08
RSP: 002b:00007f554300f168 EFLAGS: 00000246 ORIG_RAX: 000000000000002c
RAX: ffffffffffffffda RBX: 00007f554300f6c0 RCX: 00007f554306749e
RDX: 0000000000000040 RSI: 00007f554300f1d0 RDI: 0000000000000004
RBP: 0000000000000021 R08: 00007f55430e5b10 R09: 0000000000000014
R10: 0000000000000000 R11: 0000000000000246 R12: ffffffffffffffd0
R13: 000000000000000b R14: 00007ffdf0e50d30 R15: 00007ffdf0e50e18
 </TASK>


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

      reply	other threads:[~2026-09-17 19:05 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-14  9:57 syzbot
2026-09-17 19:05 ` syzbot [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=6aac39f9.71f81b7d.278072.0020.GAE@google.com \
    --to=syzbot+adb0bf16414b8bb2d799@syzkaller.appspotmail.com \
    --cc=alex.aring@gmail.com \
    --cc=andrew@lunn.ch \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-wpan@vger.kernel.org \
    --cc=miquel.raynal@bootlin.com \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=stefan@datenfreihafen.org \
    --cc=syzkaller-bugs@googlegroups.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®