mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* Re: [syzbot] WARNING in wiphy_delayed_work_cancel
       [not found] <20261003101247.876-1-rajojha047@gmail.com>
@ 2026-10-03 10:29 ` syzbot
  0 siblings, 0 replies; 4+ messages in thread
From: syzbot @ 2026-10-03 10:29 UTC (permalink / raw)
  To: linux-kernel, rajojha047, syzkaller-bugs

Hello,

syzbot tried to test the proposed patch but the build/boot failed:

an_adv: batadv0: The MTU of interface batadv_slave_1 is too small (1500) to handle the transport of batman-adv packets. Packets going over this interface will be fragmented on layer2 which could impact the performance. Setting the MTU to 1532 would solve the problem.
[   62.793102][ T5864] batman_adv: batadv0: Not using interface batadv_slave_1 (retrying later): interface not active
[   62.814915][ T5864] hsr_slave_0: entered promiscuous mode
[   62.815489][ T5864] hsr_slave_1: entered promiscuous mode
[   62.815842][ T5864] debugfs: 'hsr0' already exists in 'hsr'
[   62.815935][ T5864] Cannot create hsr debugfs directory
[   64.359905][   T67] Bluetooth: hci0: command tx timeout
[   65.513797][ T5837] bridge_slave_1: left allmulticast mode
[   65.513852][ T5837] bridge_slave_1: left promiscuous mode
[   65.515345][ T5837] bridge0: port 2(bridge_slave_1) entered disabled state
[   65.527936][ T5837] bridge_slave_0: left allmulticast mode
[   65.527953][ T5837] bridge_slave_0: left promiscuous mode
[   65.528170][ T5837] bridge0: port 1(bridge_slave_0) entered disabled state
[   65.590137][   T43] kauditd_printk_skb: 20 callbacks suppressed
[   65.590156][   T43] audit: type=1400 audit(1791023292.018:189): avc:  denied  { write } for  pid=5883 comm="dhcpcd-run-hook" name="hook-state" dev="tmpfs" ino=1839 scontext=system_u:system_r:dhcpc_t tcontext=system_u:object_r:tmpfs_t tclass=dir permissive=1
[   65.590377][   T43] audit: type=1400 audit(1791023292.018:190): avc:  denied  { create } for  pid=5883 comm="dhcpcd-run-hook" name="resolv.conf.eth2.link" scontext=system_u:system_r:dhcpc_t tcontext=system_u:object_r:tmpfs_t tclass=file permissive=1
[   65.590877][   T43] audit: type=1400 audit(1791023292.018:191): avc:  denied  { write } for  pid=5883 comm="dhcpcd-run-hook" path="/run/dhcpcd/hook-state/resolv.conf.eth2.link" dev="tmpfs" ino=2013 scontext=system_u:system_r:dhcpc_t tcontext=system_u:object_r:tmpfs_t tclass=file permissive=1
[   65.591303][   T43] audit: type=1400 audit(1791023292.018:192): avc:  denied  { append } for  pid=5883 comm="dhcpcd-run-hook" name="resolv.conf.eth2.link" dev="tmpfs" ino=2013 scontext=system_u:system_r:dhcpc_t tcontext=system_u:object_r:tmpfs_t tclass=file permissive=1
[   65.649792][   T43] audit: type=1400 audit(1791023292.078:193): avc:  denied  { write } for  pid=5886 comm="rm" name="hook-state" dev="tmpfs" ino=1839 scontext=system_u:system_r:dhcpc_t tcontext=system_u:object_r:tmpfs_t tclass=dir permissive=1
[   65.649931][   T43] audit: type=1400 audit(1791023292.078:194): avc:  denied  { unlink } for  pid=5886 comm="rm" name="resolv.conf.eth2.link" dev="tmpfs" ino=2013 scontext=system_u:system_r:dhcpc_t tcontext=system_u:object_r:tmpfs_t tclass=file permissive=1
[   65.662713][ T5837] bond0 (unregistering): (slave bond_slave_0): Releasing backup interface
[   65.685485][ T5837] bond0 (unregistering): (slave bond_slave_1): Releasing backup interface
[   65.686538][ T5837] bond0 (unregistering): Released all slaves
[   65.733369][ T5441] 8021q: adding VLAN 0 to HW filter on device eth2
[   65.763611][ T5837] hsr_slave_0: left promiscuous mode
[   65.764176][ T5837] hsr_slave_1: left promiscuous mode
[   65.764872][ T5837] batman_adv: batadv0: Interface deactivated: batadv_slave_0
[   65.764895][ T5837] batman_adv: batadv0: Removing interface: batadv_slave_0
[   65.765793][ T5837] batman_adv: batadv0: Interface deactivated: batadv_slave_1
[   65.765807][ T5837] batman_adv: batadv0: Removing interface: batadv_slave_1
[   65.776211][ T5837] veth1_macvtap: left promiscuous mode
[   65.776258][ T5837] veth0_macvtap: left promiscuous mode
[   65.776383][ T5837] veth1_vlan: left promiscuous mode
[   65.776449][ T5837] veth0_vlan: left promiscuous mode
[   65.995161][ T5837] team0 (unregistering): Port device team_slave_1 removed
[   66.010657][ T5837] team0 (unregistering): Port device team_slave_0 removed
[   66.242707][   T43] audit: type=1400 audit(1791023292.668:195): avc:  denied  { write } for  pid=5889 comm="dhcpcd-run-hook" name="hook-state" dev="tmpfs" ino=1839 scontext=system_u:system_r:dhcpc_t tcontext=system_u:object_r:tmpfs_t tclass=dir permissive=1
[   66.318339][   T43] audit: type=1400 audit(1791023292.738:196): avc:  denied  { write } for  pid=5892 comm="rm" name="hook-state" dev="tmpfs" ino=1839 scontext=system_u:system_r:dhcpc_t tcontext=system_u:object_r:tmpfs_t tclass=dir permissive=1
[   66.439075][   T67] Bluetooth: hci0: command tx timeout
[   66.439466][ T5864] netdevsim netdevsim0 netdevsim0: renamed from eth0
[   66.442488][ T5864] 8021q: adding VLAN 0 to HW filter on device netdevsim0
[   66.443164][ T5864] netdevsim netdevsim0 netdevsim1: renamed from eth1
[   66.444629][ T5864] 8021q: adding VLAN 0 to HW filter on device netdevsim1
[   66.445152][ T5864] netdevsim netdevsim0 netdevsim2: renamed from eth2
[   66.447862][ T5864] 8021q: adding VLAN 0 to HW filter on device netdevsim2
[   66.448537][ T5864] netdevsim netdevsim0 netdevsim3: renamed from eth3
[   66.455828][ T5864] 8021q: adding VLAN 0 to HW filter on device netdevsim3
[   66.458030][   T43] audit: type=1400 audit(1791023292.878:197): avc:  denied  { write } for  pid=5895 comm="dhcpcd-run-hook" name="hook-state" dev="tmpfs" ino=1839 scontext=system_u:system_r:dhcpc_t tcontext=system_u:object_r:tmpfs_t tclass=dir permissive=1
[   66.525202][   T43] audit: type=1400 audit(1791023292.948:198): avc:  denied  { write } for  pid=5905 comm="rm" name="hook-state" dev="tmpfs" ino=1839 scontext=system_u:system_r:dhcpc_t tcontext=system_u:object_r:tmpfs_t tclass=dir permissive=1
[   66.543482][ T5864] 8021q: adding VLAN 0 to HW filter on device bond0
[   66.563932][ T5864] 8021q: adding VLAN 0 to HW filter on device team0
[   66.570011][  T209] bridge0: port 1(bridge_slave_0) entered blocking state
[   66.570091][  T209] bridge0: port 1(bridge_slave_0) entered forwarding state
[   66.579873][  T209] bridge0: port 2(bridge_slave_1) entered blocking state
[   66.579960][  T209] bridge0: port 2(bridge_slave_1) entered forwarding state
[   66.879344][ T5864] 8021q: adding VLAN 0 to HW filter on device batadv0
[   66.922063][ T5864] veth0_vlan: entered promiscuous mode
[   66.928641][ T5864] veth1_vlan: entered promiscuous mode
[   66.962353][ T5864] veth0_macvtap: entered promiscuous mode
[   66.964951][ T5864] veth1_macvtap: entered promiscuous mode
[   66.973999][ T5864] batman_adv: batadv0: Interface activated: batadv_slave_0
[   66.978182][ T5864] batman_adv: batadv0: Interface activated: batadv_slave_1
[   67.009928][ T5754] netdevsim netdevsim0 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0
[   67.043791][   T62] wlan0: Created IBSS using preconfigured BSSID 50:50:50:50:50:50
[   67.043805][   T62] wlan0: Creating new IBSS network, BSSID 50:50:50:50:50:50
[   67.049131][ T5837] netdevsim netdevsim0 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0
[   67.072199][   T62] wlan1: Created IBSS using preconfigured BSSID 50:50:50:50:50:50
[   67.072217][   T62] wlan1: Creating new IBSS network, BSSID 50:50:50:50:50:50
[   67.079714][ T5837] netdevsim netdevsim0 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0
[   67.090038][ T5754] netdevsim netdevsim0 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0
[   67.666773][ T5754] 
[   67.667906][ T5754] ============================================
[   67.670864][ T5754] WARNING: possible recursive locking detected
[   67.673721][ T5754] syzkaller #0 Not tainted
[   67.675241][ T5754] --------------------------------------------
[   67.677627][ T5754] kworker/u32:2/5754 is trying to acquire lock:
[   67.680230][ T5754] ffff8880539b0800 (&rdev->wiphy.mtx){+.+.}-{4:4}, at: ieee80211_uninit+0x104/0x2e0
[   67.684005][ T5754] 
[   67.684005][ T5754] but task is already holding lock:
[   67.687170][ T5754] ffff8880539b0800 (&rdev->wiphy.mtx){+.+.}-{4:4}, at: ieee80211_remove_interfaces+0xf0/0x6e0
[   67.691869][ T5754] 
[   67.691869][ T5754] other info that might help us debug this:
[   67.695164][ T5754]  Possible unsafe locking scenario:
[   67.695164][ T5754] 
[   67.698279][ T5754]        CPU0
[   67.699702][ T5754]        ----
[   67.701072][ T5754]   lock(&rdev->wiphy.mtx);
[   67.702958][ T5754]   lock(&rdev->wiphy.mtx);
[   67.704806][ T5754] 
[   67.704806][ T5754]  *** DEADLOCK ***
[   67.704806][ T5754] 
[   67.708010][ T5754]  May be due to missing lock nesting notation
[   67.708010][ T5754] 
[   67.710898][ T5754] locks held by kworker/u32:2/5754: 5, last CPU#3:
[   67.713491][ T5754]  #0: ffff88801d6a7140 ((wq_completion)netns){+.+.}-{0:0}, at: process_one_work+0x1466/0x1b10
[   67.717245][ T5754]  #1: ffffc90003e3fd08 (net_cleanup_work){+.+.}-{0:0}, at: process_one_work+0xa2c/0x1b10
[   67.721603][ T5754]  #2: ffffffff90cbbfa8 (pernet_ops_rwsem){++++}-{4:4}, at: cleanup_net+0xb8/0x920
[   67.727220][ T5754]  #3: ffffffff90cd4b00 (rtnl_mutex){+.+.}-{4:4}, at: ieee80211_unregister_hw+0x4d/0x360
[   67.731071][ T5754]  #4: ffff8880539b0800 (&rdev->wiphy.mtx){+.+.}-{4:4}, at: ieee80211_remove_interfaces+0xf0/0x6e0
[   67.734602][ T5754] 
[   67.734602][ T5754] stack backtrace:
[   67.736954][ T5754] CPU: 3 UID: 0 PID: 5754 Comm: kworker/u32:2 Not tainted syzkaller #0 PREEMPT(full) 
[   67.740313][ T5754] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[   67.744149][ T5754] Workqueue: netns cleanup_net
[   67.745929][ T5754] Call Trace:
[   67.747399][ T5754]  <TASK>
[   67.748493][ T5754]  dump_stack_lvl+0x100/0x190
[   67.750079][ T5754]  print_deadlock_bug.cold+0xbd/0xca
[   67.751840][ T5754]  __lock_acquire+0x13f4/0x1f40
[   67.753682][ T5754]  lock_acquire+0x1d1/0x380
[   67.755394][ T5754]  ? ieee80211_uninit+0x104/0x2e0
[   67.757427][ T5754]  ? __pfx___might_resched+0x10/0x10
[   67.759654][ T5754]  __mutex_lock+0x1a4/0x1bd0
[   67.761548][ T5754]  ? ieee80211_uninit+0x104/0x2e0
[   67.763313][ T5754]  ? ieee80211_uninit+0x104/0x2e0
[   67.765265][ T5754]  ? ib_device_get_by_netdev+0x1a8/0x530
[   67.767507][ T5754]  ? __pfx___mutex_lock+0x10/0x10
[   67.769502][ T5754]  ? vxlan_netdevice_event+0x11f/0x370
[   67.771717][ T5754]  ? __pfx_ib_device_get_by_netdev+0x10/0x10
[   67.774156][ T5754]  ? __sanitizer_cov_trace_switch+0x54/0x90
[   67.776825][ T5754]  ? __pfx_vxlan_netdevice_event+0x10/0x10
[   67.779316][ T5754]  ? ip6_route_dev_notify+0xe4/0x750
[   67.782010][ T5754]  ? ndisc_netdev_event+0xa1/0x560
[   67.784532][ T5754]  ? ieee80211_uninit+0x104/0x2e0
[   67.787098][ T5754]  ? rtnl_is_locked+0x15/0x20
[   67.789325][ T5754]  ieee80211_uninit+0x104/0x2e0
[   67.791104][ T5754]  ? __pfx_ieee80211_uninit+0x10/0x10
[   67.792953][ T5754]  unregister_netdevice_many_notify+0x1407/0x2150
[   67.794957][ T5754]  ? __pfx_unregister_netdevice_many_notify+0x10/0x10
[   67.797525][ T5754]  ? rcu_is_watching+0x13/0xc0
[   67.799462][ T5754]  unregister_netdevice_queue+0x30b/0x3c0
[   67.801666][ T5754]  ? kernfs_remove_by_name_ns+0x103/0x120
[   67.803902][ T5754]  ? __pfx_unregister_netdevice_queue+0x10/0x10
[   67.806383][ T5754]  _cfg80211_unregister_wdev+0x66e/0x830
[   67.808647][ T5754]  ieee80211_remove_interfaces+0x34e/0x6e0
[   67.811148][ T5754]  ? __pfx_ieee80211_remove_interfaces+0x10/0x10
[   67.813691][ T5754]  ieee80211_unregister_hw+0x55/0x360
[   67.815846][ T5754]  hwsim_exit_net+0x891/0x1500
[   67.818006][ T5754]  ? __pfx_hwsim_exit_net+0x10/0x10
[   67.821567][ T5754]  ? __pfx___might_resched+0x10/0x10
[   67.823580][ T5754]  ? ip_vs_sync_net_cleanup+0x84/0x90
[   67.825315][ T5754]  ? __ip_vs_dev_cleanup_batch+0x21e/0x2a0
[   67.827144][ T5754]  ? __pfx_hwsim_exit_net+0x10/0x10
[   67.828885][ T5754]  ops_undo_list+0x2ee/0xab0
[   67.830799][ T5754]  ? __pfx_ops_undo_list+0x10/0x10
[   67.832972][ T5754]  ? cleanup_net+0x332/0x920
[   67.834812][ T5754]  ? idr_destroy+0x62/0x2e0
[   67.836747][ T5754]  cleanup_net+0x499/0x920
[   67.838833][ T5754]  ? __pfx_cleanup_net+0x10/0x10
[   67.840948][ T5754]  ? process_one_work+0xa2c/0x1b10
[   67.843529][ T5754]  ? process_one_work+0x906/0x1b10
[   67.846421][ T5754]  process_one_work+0xac7/0x1b10
[   67.849247][ T5754]  ? __pfx_process_one_work+0x10/0x10
[   67.851637][ T5754]  ? lock_acquire+0x1d1/0x380
[   67.853690][ T5754]  ? __pfx_cleanup_net+0x10/0x10
[   67.856016][ T5754]  worker_thread+0x5ef/0xe50
[   67.858043][ T5754]  ? kthread+0x13a/0x450
[   67.859721][ T5754]  ? __pfx_worker_thread+0x10/0x10
[   67.861571][ T5754]  kthread+0x373/0x450
[   67.862940][ T5754]  ? __pfx_kthread+0x10/0x10
[   67.864501][ T5754]  ret_from_fork+0x730/0xd60
[   67.866036][ T5754]  ? __pfx_ret_from_fork+0x10/0x10
[   67.867762][ T5754]  ? __switch_to+0x800/0x10f0
[   67.869425][ T5754]  ? __pfx_kthread+0x10/0x10
[   67.871349][ T5754]  ret_from_fork_asm+0x1a/0x30
[   67.873464][ T5754]  </TASK>
[   71.389794][ T1440] ieee802154 phy0 wpan0: encryption failed: -22
[   71.389822][ T1440] ieee802154 phy1 wpan1: encryption failed: -22
[   76.509494][   T10] cfg80211: failed to load regulatory.db


syzkaller build log:
go env (err=<nil>)
AR='ar'
CC='gcc'
CGO_CFLAGS='-O2 -g'
CGO_CPPFLAGS=''
CGO_CXXFLAGS='-O2 -g'
CGO_ENABLED='1'
CGO_FFLAGS='-O2 -g'
CGO_LDFLAGS='-O2 -g'
CXX='g++'
GCCGO='gccgo'
GO111MODULE='auto'
GOAMD64='v1'
GOARCH='amd64'
GOAUTH='netrc'
GOBIN=''
GOCACHE='/syzkaller/.cache/go-build'
GOCACHEPROG=''
GODEBUG=''
GOENV='/syzkaller/.config/go/env'
GOEXE=''
GOEXPERIMENT=''
GOFIPS140='off'
GOFLAGS=''
GOGCCFLAGS='-fPIC -m64 -pthread -Wl,--no-gc-sections -fmessage-length=0 -ffile-prefix-map=/tmp/go-build1444367985=/tmp/go-build -gno-record-gcc-switches'
GOHOSTARCH='amd64'
GOHOSTOS='linux'
GOINSECURE=''
GOMOD='/syzkaller/jobs/linux/gopath/src/github.com/google/syzkaller/go.mod'
GOMODCACHE='/syzkaller/jobs/linux/gopath/pkg/mod'
GONOPROXY=''
GONOSUMDB=''
GOOS='linux'
GOPATH='/syzkaller/jobs/linux/gopath'
GOPRIVATE=''
GOPROXY='https://proxy.golang.org,direct'
GOROOT='/usr/local/go'
GOSUMDB='sum.golang.org'
GOTELEMETRY='local'
GOTELEMETRYDIR='/syzkaller/.config/go/telemetry'
GOTMPDIR=''
GOTOOLCHAIN='auto'
GOTOOLDIR='/usr/local/go/pkg/tool/linux_amd64'
GOVCS=''
GOVERSION='go1.26.0'
GOWORK=''
PKG_CONFIG='pkg-config'

git status (err=<nil>)
HEAD detached at 1e72964b011
nothing to commit, working tree clean


tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
go list -f '{{.Stale}}' -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=1e72964b0111319984575e60f266d1fa0a98abb5 -X github.com/google/syzkaller/prog.gitRevisionDate=20260817-123423"  ./sys/syz-sysgen | grep -q false || go install -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=1e72964b0111319984575e60f266d1fa0a98abb5 -X github.com/google/syzkaller/prog.gitRevisionDate=20260817-123423"  ./sys/syz-sysgen
make .descriptions
tput: No value for $TERM and no -T specified
tput: No value for $TERM and no -T specified
Makefile:31: run command via tools/syz-env for best compatibility, see:
Makefile:32: https://github.com/google/syzkaller/blob/master/docs/contributing.md#using-syz-env
bin/syz-sysgen
touch .descriptions
GOOS=linux GOARCH=amd64 go build -ldflags="-s -w -X github.com/google/syzkaller/prog.GitRevision=1e72964b0111319984575e60f266d1fa0a98abb5 -X github.com/google/syzkaller/prog.gitRevisionDate=20260817-123423"  -o ./bin/linux_amd64/syz-execprog github.com/google/syzkaller/tools/syz-execprog
mkdir -p ./bin/linux_amd64
g++ -o ./bin/linux_amd64/syz-executor executor/executor.cc \
	-m64 -O2 -pthread -Wall -Werror -Wparentheses -Wunused-const-variable -Wframe-larger-than=16384 -Wno-stringop-overflow -Wno-array-bounds -Wno-format-overflow -Wno-unused-but-set-variable -Wno-unused-command-line-argument -static-pie -std=c++17 -I. -Iexecutor/_include   -DGOOS_linux=1 -DGOARCH_amd64=1 \
	-DHOSTGOOS_linux=1 -DGIT_REVISION=\"1e72964b0111319984575e60f266d1fa0a98abb5\"
/usr/bin/ld: /tmp/ccQDOckT.o: in function `Connection::Connect(char const*, char const*)':
executor.cc:(.text._ZN10Connection7ConnectEPKcS1_[_ZN10Connection7ConnectEPKcS1_]+0x386): warning: Using 'gethostbyname' in statically linked applications requires at runtime the shared libraries from the glibc version used for linking
./tools/check-syzos.sh 2>/dev/null


Error text is too large and was truncated, full error text is at:
https://syzkaller.appspot.com/x/error.txt?x=12265725580000


Tested on:

commit:         e767a4ea Merge tag 'probes-fixes-v7.3-rc5' of git://gi..
git tree:       upstream
kernel config:  https://syzkaller.appspot.com/x/.config?x=929e4854a828f434
dashboard link: https://syzkaller.appspot.com/bug?extid=e9cbd080a7801f06cf08
compiler:       gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
patch:          https://syzkaller.appspot.com/x/patch.diff?x=16f92ec9580000


^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [syzbot] WARNING in wiphy_delayed_work_cancel
       [not found] <20261003103642.910-1-rajojha047@gmail.com>
@ 2026-10-03 10:53 ` syzbot
  0 siblings, 0 replies; 4+ messages in thread
From: syzbot @ 2026-10-03 10:53 UTC (permalink / raw)
  To: linux-kernel, rajojha047, syzkaller-bugs

Hello,

syzbot has tested the proposed patch and the reproducer did not trigger any issue:

Reported-by: syzbot+e9cbd080a7801f06cf08@syzkaller.appspotmail.com
Tested-by: syzbot+e9cbd080a7801f06cf08@syzkaller.appspotmail.com

Tested on:

commit:         e767a4ea Merge tag 'probes-fixes-v7.3-rc5' of git://gi..
git tree:       upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=15e29bf5580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=929e4854a828f434
dashboard link: https://syzkaller.appspot.com/bug?extid=e9cbd080a7801f06cf08
compiler:       gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
patch:          https://syzkaller.appspot.com/x/patch.diff?x=10013bf5580000

Note: testing is done by a robot and is best-effort only.

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [syzbot] WARNING in wiphy_delayed_work_cancel
       [not found] <20261003100515.1554-1-rajojha047@gmail.com>
@ 2026-10-03 10:07 ` syzbot
  0 siblings, 0 replies; 4+ messages in thread
From: syzbot @ 2026-10-03 10:07 UTC (permalink / raw)
  To: linux-kernel, rajojha047, syzkaller-bugs

Hello,

syzbot tried to test the proposed patch but the build/boot failed:

failed to apply patch:
error: corrupt patch at line 19



Tested on:

commit:         e767a4ea Merge tag 'probes-fixes-v7.3-rc5' of git://gi..
git tree:       upstream
kernel config:  https://syzkaller.appspot.com/x/.config?x=ccca94d2c01b9e78
dashboard link: https://syzkaller.appspot.com/bug?extid=e9cbd080a7801f06cf08
compiler:       
patch:          https://syzkaller.appspot.com/x/patch.diff?x=143b07f5580000


^ permalink raw reply	[flat|nested] 4+ messages in thread

* [syzbot] WARNING in wiphy_delayed_work_cancel
@ 2026-08-30 10:04 syzbot
  0 siblings, 0 replies; 4+ messages in thread
From: syzbot @ 2026-08-30 10:04 UTC (permalink / raw)
  To: linux-kernel, syzkaller-bugs

Hello,

syzbot found the following issue on:

HEAD commit:    818bebeb63dd drm/xe: Don't hand out the flat CCS storage a..
git tree:       git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
console output: https://syzkaller.appspot.com/x/log.txt?x=11cff979580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=ccca94d2c01b9e78
dashboard link: https://syzkaller.appspot.com/bug?extid=e9cbd080a7801f06cf08
compiler:       gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
C reproducer:   https://syzkaller.appspot.com/x/repro.c?x=1284d979580000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+e9cbd080a7801f06cf08@syzkaller.appspotmail.com

------------[ cut here ]------------
debug_locks && !(lock_is_held(&(&wiphy->mtx)->dep_map) != 0)
WARNING: net/wireless/core.c:1957 at wiphy_delayed_work_cancel+0x9a/0xb0 net/wireless/core.c:1957, CPU#3: kworker/u32:0/12
Modules linked in:
CPU: 3 UID: 0 PID: 12 Comm: kworker/u32:0 Not tainted syzkaller #0 PREEMPT(full) 
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Workqueue: netns cleanup_net
RIP: 0010:wiphy_delayed_work_cancel+0x9a/0xb0 net/wireless/core.c:1957
Code: e8 bb a8 fa f6 48 8d 7d 60 be ff ff ff ff e8 ed 85 b6 00 31 ff 41 89 c4 89 c6 e8 11 a3 fa f6 45 85 e4 75 bf e8 97 a8 fa f6 90 <0f> 0b 90 eb b4 48 c7 c7 84 8a 43 91 e8 45 7c 6d f7 eb 90 0f 1f 00
RSP: 0018:ffffc900000f7740 EFLAGS: 00010293
RAX: 0000000000000000 RBX: ffff88802b5e18a8 RCX: 0000000000000000
RDX: ffff88801ee9cb00 RSI: ffffffff8b105939 RDI: ffff88801ee9cb00
RBP: ffff888103680740 R08: 0000000000000005 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000001 R12: 0000000000000000
R13: 0000000000000000 R14: ffff888103680f40 R15: ffff888103680f90
FS:  0000000000000000(0000) GS:ffff8880d5ea2000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000055979cdf8da8 CR3: 000000003e9c7000 CR4: 0000000000352ef0
Call Trace:
 <TASK>
 ieee80211_free_keys+0xcd/0x640 net/mac80211/key.c:1148
 ieee80211_teardown_sdata+0x54/0x250 net/mac80211/iface.c:906
 unregister_netdevice_many_notify+0x1407/0x2150 net/core/dev.c:12537
 unregister_netdevice_many net/core/dev.c:12589 [inline]
 default_device_exit_batch+0x907/0xbd0 net/core/dev.c:13288
 ops_exit_list net/core/net_namespace.c:206 [inline]
 ops_undo_list+0x363/0xab0 net/core/net_namespace.c:253
 cleanup_net+0x499/0x920 net/core/net_namespace.c:706
 process_one_work+0xac7/0x1b10 kernel/workqueue.c:3387
 process_scheduled_works kernel/workqueue.c:3470 [inline]
 worker_thread+0x5ef/0xe50 kernel/workqueue.c:3551
 kthread+0x373/0x450 kernel/kthread.c:436
 ret_from_fork+0x730/0xd60 arch/x86/kernel/process.c:158
 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
 </TASK>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-10-03 10:53 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
     [not found] <20261003101247.876-1-rajojha047@gmail.com>
2026-10-03 10:29 ` [syzbot] WARNING in wiphy_delayed_work_cancel syzbot
     [not found] <20261003103642.910-1-rajojha047@gmail.com>
2026-10-03 10:53 ` syzbot
     [not found] <20261003100515.1554-1-rajojha047@gmail.com>
2026-10-03 10:07 ` syzbot
2026-08-30 10:04 syzbot

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®