已关闭
【26.09-DevStation】【kernel-6.6】【x86_64】syzkaller运行出现crash:WARNING in hci_conn_timeout #9810
ding-jiao创建于  8月25日关闭于  8月27日
ding-jiao成员
8月25日 创建

软件信息:
1.OS版本及分支: openEuler-26.09-DevStation-rc1
2.内核信息: kernel-6.6.0-163.0.0.1.oe2609.src.rpm

【问题复现步骤】

x86机器上部署syzkaller服务并运行
【预期结果】
服务正常,没有报错日志
【实际结果】
出现crash:WARNING in hci_conn_timeout
【其他信息】
image.png

------------[ cut here ]------------
WARNING: CPU: 0 PID: 1234 at net/bluetooth/hci_conn.c:569 hci_conn_timeout+0x1d5/0x210 net/bluetooth/hci_conn.c:569 [bluetooth]
Modules linked in: ip_set_hash_netiface ip_vs_sh ip_set_hash_ipport ip_set_bitmap_port ip_set_hash_ipportip ntfs msdos fat udf crc_itu_t pps_ldisc ip_set_hash_ipmac cramfs ib_uverbs ceph libceph tcp_lp ip_set_hash_ip erofs ntfs3 ip_vs_lc nls_utf8 cifs cifs_arc4 nls_ucs2_utils cifs_md4 dns_resolver exfat scmtcp virtiofs atm isofs tcp_diag sm4_generic sm4_aesni_avx2_x86_64 sm4_aesni_avx_x86_64 sm4 twofish_generic twofish_avx_x86_64 twofish_x86_64_3way twofish_x86_64 twofish_common camellia_generic camellia_aesni_avx2 camellia_aesni_avx_x86_64 camellia_x86_64 serpent_avx2 serpent_avx_x86_64 serpent_sse2_x86_64 serpent_generic blowfish_generic blowfish_x86_64 blowfish_common cast5_avx_x86_64 cast5_generic cast_common des_generic libdes cmac xcbc rmd160 vfio_iommu_type1 vfio iommufd xfs nft_compat nfs fscache netfs ip_vs_wlc overlay ansi_cprng snd_seq_dummy hidp nfnetlink_log nfsd auth_rpcgss nfs_acl lockd grace sunrpc cuse tcp_dctcp inet_diag vhost_net snd_hrtimer ip_vs nbd nfnetlink_cthelper gfs2 dlm rfcomm
 snd_seq snd_seq_device can_bcm cmtp kernelcapi nfnetlink_queue ieee802154_socket ieee802154 crypto_user nfnetlink_osf l2tp_ppp loop btrfs xor raid6_pq snd_timer snd soundcore pppoe vhost_vsock af_key vmw_vsock_virtio_transport_common vhost vhost_iotlb vsock uinput uhid pptp can_raw pppox ppp_generic can slhc bnep cfg80211 smc l2tp_ip6 nf_conntrack_netlink l2tp_netlink ib_core squashfs sctp l2tp_ip l2tp_core nfnetlink_cttimeout ip6_vti ip_vti ip_gre ipip sit ip_tunnel geneve ip6_udp_tunnel udp_tunnel macsec macvtap tap ipvlan macvlan 8021q garp mrp xfrm_interface xfrm6_tunnel tunnel4 veth nlmon dummy team bonding tls vcan can_dev bridge stp llc ip6_gre gre ip6_tunnel tunnel6 tun hci_vhci bluetooth ecdh_generic ecc binfmt_misc nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 rfkill ip_set intel_rapl_msr intel_rapl_common kvm_intel nf_tables sr_mod libcrc32c cdrom sg kvm ppdev
 irqbypass crct10dif_pclmul crc32_pclmul crc32c_intel ghash_clmulni_intel sha512_ssse3 ata_generic rapl joydev parport_pc bochs drm_vram_helper drm_ttm_helper ttm ata_piix parport drm_kms_helper libata pcspkr i2c_piix4 serio_raw drm fuse nfnetlink
CPU: 0 PID: 1234 Comm: kworker/u9:1 Not tainted 6.6.0 #1
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014
Workqueue: hci3 hci_conn_timeout [bluetooth]
RIP: 0010:hci_conn_timeout+0x1d5/0x210 net/bluetooth/hci_conn.c:569 [bluetooth]
Code: 40 e4 10 c1 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 80 3c 02 00 75 37 4e 8b 34 ed 40 e4 10 c1 eb af e8 4b 6c ca ef <0f> 0b e9 b5 fe ff ff 48 89 ef e8 5c f4 2c f0 e9 71 fe ff ff e8 12
RSP: 0018:ffffc90000f5fda0 EFLAGS: 00010293
RAX: 0000000000000000 RBX: ffff888158354310 RCX: ffffffffc0f625e5
RDX: ffff88811f461bc0 RSI: 0000000000000000 RDI: 0000000000000005
RBP: 00000000ffffffff R08: 0000000000000000 R09: ffffed102b06a802
R10: 00000000ffffffff R11: 0000000000000341 R12: ffff888158354000
R13: ffff888195e52400 R14: ffff888180d01b78 R15: 0000000000000000
FS:  0000000000000000(0000) GS:ffff8887df000000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000000000068d8f0 CR3: 000000024f652002 CR4: 0000000000170ef0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0001000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
Call Trace:
 <TASK>
 process_one_work+0x623/0xec0 kernel/workqueue.c:2753
 process_scheduled_works kernel/workqueue.c:2830 [inline]
 worker_thread+0x6bd/0xb80 kernel/workqueue.c:2911
 kthread+0x2c8/0x3b0 kernel/kthread.c:388
 ret_from_fork+0x49/0x80 arch/x86/kernel/process.c:152
 ret_from_fork_asm+0x1b/0x30 arch/x86/entry/entry_64.S:293
 </TASK>

<<<<<<<<<<<<<<< tail report >>>>>>>>>>>>>>>

SYZFAIL: failed to recv rpc
fd=3 want=4 recv=0 n=0 (errno 9: Bad file descriptor)

<<<<<<<<<<<<<<< tail report >>>>>>>>>>>>>>>

Modules linked in: ip_set_hash_netiface ip_vs_sh ip_set_hash_ipport ip_set_bitmap_port ip_set_hash_ipportip ntfs msdos fat udf crc_itu_t pps_ldisc ip_set_hash_ipmac cramfs ib_uverbs ceph libceph tcp_lp ip_set_hash_ip erofs ntfs3 ip_vs_lc nls_utf8 cifs cifs_arc4 nls_ucs2_utils cifs_md4 dns_resolver exfat scmtcp virtiofs atm isofs tcp_diag sm4_generic sm4_aesni_avx2_x86_64 sm4_aesni_avx_x86_64 sm4 twofish_generic twofish_avx_x86_64 twofish_x86_64_3way twofish_x86_64 twofish_common camellia_generic camellia_aesni_avx2 camellia_aesni_avx_x86_64 camellia_x86_64 serpent_avx2 serpent_avx_x86_64 serpent_sse2_x86_64 serpent_generic blowfish_generic blowfish_x86_64 blowfish_common cast5_avx_x86_64 cast5_generic cast_common des_generic libdes cmac xcbc rmd160 vfio_iommu_type1 vfio iommufd xfs nft_compat nfs fscache netfs ip_vs_wlc overlay ansi_cprng snd_seq_dummy hidp nfnetlink_log nfsd auth_rpcgss nfs_acl lockd grace sunrpc cuse tcp_dctcp inet_diag vhost_net snd_hrtimer ip_vs nbd nfnetlink_cthelper gfs2 dlm rfcomm
 snd_seq snd_seq_device can_bcm cmtp kernelcapi nfnetlink_queue ieee802154_socket ieee802154 crypto_user nfnetlink_osf l2tp_ppp loop btrfs xor raid6_pq snd_timer snd soundcore pppoe vhost_vsock af_key vmw_vsock_virtio_transport_common vhost vhost_iotlb vsock uinput uhid pptp can_raw pppox ppp_generic can slhc bnep cfg80211 smc l2tp_ip6 nf_conntrack_netlink l2tp_netlink ib_core squashfs sctp l2tp_ip l2tp_core nfnetlink_cttimeout ip6_vti ip_vti ip_gre ipip sit ip_tunnel geneve ip6_udp_tunnel udp_tunnel macsec macvtap tap ipvlan macvlan 8021q garp mrp xfrm_interface xfrm6_tunnel tunnel4 veth nlmon dummy team bonding tls vcan can_dev bridge stp llc ip6_gre gre ip6_tunnel tunnel6 tun hci_vhci bluetooth ecdh_generic ecc binfmt_misc nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 rfkill ip_set intel_rapl_msr intel_rapl_common kvm_intel nf_tables sr_mod libcrc32c cdrom sg kvm ppdev
 irqbypass crct10dif_pclmul crc32_pclmul crc32c_intel ghash_clmulni_intel sha512_ssse3 ata_generic rapl joydev parport_pc bochs drm_vram_helper drm_ttm_helper ttm ata_piix parport drm_kms_helper libata pcspkr i2c_piix4 serio_raw drm fuse nfnetlink
CPU: 0 PID: 1234 Comm: kworker/u9:1 Not tainted 6.6.0 #1
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014
Workqueue: hci3 hci_conn_timeout [bluetooth]
RIP: 0010:hci_conn_timeout+0x1d5/0x210 [bluetooth]
Code: 40 e4 10 c1 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 80 3c 02 00 75 37 4e 8b 34 ed 40 e4 10 c1 eb af e8 4b 6c ca ef <0f> 0b e9 b5 fe ff ff 48 89 ef e8 5c f4 2c f0 e9 71 fe ff ff e8 12
RSP: 0018:ffffc90000f5fda0 EFLAGS: 00010293
RAX: 0000000000000000 RBX: ffff888158354310 RCX: ffffffffc0f625e5
RDX: ffff88811f461bc0 RSI: 0000000000000000 RDI: 0000000000000005
RBP: 00000000ffffffff R08: 0000000000000000 R09: ffffed102b06a802
R10: 00000000ffffffff R11: 0000000000000341 R12: ffff888158354000
R13: ffff888195e52400 R14: ffff888180d01b78 R15: 0000000000000000
FS:  0000000000000000(0000) GS:ffff8887df000000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000000000068d8f0 CR3: 000000024f652002 CR4: 0000000000170ef0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0001000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
Call Trace:
 <TASK>
 process_one_work+0x623/0xec0
 worker_thread+0x6bd/0xb80
 kthread+0x2c8/0x3b0
 ret_from_fork+0x49/0x80
 ret_from_fork_asm+0x1b/0x30
 </TASK>
Kernel panic - not syncing: kernel: panic_on_warn set ...
CPU: 0 PID: 1234 Comm: kworker/u9:1 Not tainted 6.6.0 #1
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014
Workqueue: hci3 hci_conn_timeout [bluetooth]
Call Trace:
 <TASK>
 dump_stack_lvl+0x6e/0xa0
 panic+0x655/0x6f0
 check_panic_on_warn+0xac/0xb0
 __warn+0xf3/0x290
 report_bug+0x31a/0x440
 handle_bug+0x91/0xc0
 exc_invalid_op+0x13/0x60
 asm_exc_invalid_op+0x16/0x20
RIP: 0010:hci_conn_timeout+0x1d5/0x210 [bluetooth]
Code: 40 e4 10 c1 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 80 3c 02 00 75 37 4e 8b 34 ed 40 e4 10 c1 eb af e8 4b 6c ca ef <0f> 0b e9 b5 fe ff ff 48 89 ef e8 5c f4 2c f0 e9 71 fe ff ff e8 12
RSP: 0018:ffffc90000f5fda0 EFLAGS: 00010293
RAX: 0000000000000000 RBX: ffff888158354310 RCX: ffffffffc0f625e5
RDX: ffff88811f461bc0 RSI: 0000000000000000 RDI: 0000000000000005
RBP: 00000000ffffffff R08: 0000000000000000 R09: ffffed102b06a802
R10: 00000000ffffffff R11: 0000000000000341 R12: ffff888158354000
R13: ffff888195e52400 R14: ffff888180d01b78 R15: 0000000000000000
 process_one_work+0x623/0xec0
 worker_thread+0x6bd/0xb80
 kthread+0x2c8/0x3b0
 ret_from_fork+0x49/0x80
 ret_from_fork_asm+0x1b/0x30
 </TASK>
Dumping ftrace buffer:
   (ftrace buffer empty)
Kernel Offset: 0x2f600000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff)
Rebooting in 86400 seconds..

<<<<<<<<<<<<<<< tail report >>>>>>>>>>>>>>>

二、缺陷分析结构反馈
影响性分析说明:

缺陷严重等级:(Critical/High/Moderate/Low)

缺陷根因说明:

受影响版本排查(受影响/不受影响):
openEuler-20.03-LTS-SP4
openEuler-22.03-LTS-SP3
openEuler-22.03-LTS-SP4
openEuler-24.03-LTS
openEuler-24.03-LTS-SP1
openEuler-24.03-LTS-SP2

修复是否涉及abi变化(是/否):
openEuler-20.03-LTS-SP4
openEuler-22.03-LTS-SP3
openEuler-22.03-LTS-SP4
openEuler-24.03-LTS
openEuler-24.03-LTS-SP1
openEuler-24.03-LTS-SP2

likedislike
openeuler-ci-botopeneuler-ci-bot成员
8月25日 将 allen-shi 设为负责人
openeuler-ci-botopeneuler-ci-bot成员
8月25日 添加了label:sig/Kernel
openeuler-ci-botopeneuler-ci-bot成员
8月25日 修改了issue 的描述
openeuler-ci-bot
openeuler-ci-bot成员
8月25日 评论:

Welcome To openEuler Community

Hey @ding-jiao , thanks for your contribution to the community.

Bot Usage Manual

I'm the Bot here serving you. You can find the instructions on how to interact with me at Here . That means you can comment below every pull request or issue to trigger Bot Commands. You can self-configure the PR merge rules for this repository. For more details, please refer to Here.

Contact Guide

If you have any questions, please contact the SIG: Kernel ,
and any of the maintainers: @hanjunguo, @oekernel, @sanglipeng, @wkfxxx, @zeng_zhaorong ,
and any of the committers: @CTC-XiboWang, @Frank_Sae, @GoGo_phytium, @GongLei-, @LiuYongQiang0816, @SuperSix173, @Tankll2021, @TrueAI, @YiweiZ, @allen-shi, @baratta, @bibo_mao, @caixu-blue, @chen-jun-hw, @chenjiesong, @chenjunxin1992, @chenke2026, @chiqijun, @chriszjh, @duanqiangwen, @eingesch, @fangfeng123, @fanghaiqinghw, @gang_he, @gaojuxin09, @gouhao2022, @guohaocs2c, @guzitao, @hanjunguo, @hanliyang, @hellotcc, @henryze, @hewanhan, @hjx_gitff, @hongwu-wang, @htforge, @hu-chunzhi, @hunan4222, @jackknight, @jerry_lilijun, @jiayi0118, @junlong-zheng, @juntianlinux, @kailiu42, @kaitiandu, @kazero00, @kevinzhu1, @kile2009, @klmengkd, @koishimind, @kongzizaixian, @kylin-mayukun, @leoliu-oc, @li-huisong, @linan888, @linyunsheng, @liulongfang, @liyihang0226, @lostway1, @lujialin2, @mao-hongbo, @markyuan4ta21, @mawupeng, @mingqian218472, @mingrui-liu, @mufengyan, @pigalsofine, @robinorg, @rock_hw, @sanglipeng, @shu-shengming, @shuaijiakun, @sming56_admin, @stavewu, @stkid, @sun_nanyong, @wangboe2022, @wanghang73, @wenzhiwei11, @whoisxxx, @wkfxxx, @woqidaideshi, @wsoydl, @xingmz1, @xukuohai, @yeweihua999, @ygn-ndwd-official, @yonghu_4dc5, @young-sun, @yubo-liu1, @yuehaibing_planb, @yuzenghui1, @zhang-changzhong, @zhangyi089, @zhujianwei001, @zichengqu, @zouyipeng, @zqiao216 .

likedislike
openeuler-ci-bot
openeuler-ci-bot成员
8月25日 评论:

以下的要求不是强制性的, 未按模板评论时对issue无任何影响
issue处理注意事项:
1. 当前issue受影响的分支提交pr时, 须在pr描述中填写当前issue编号进行关联, 否则无法关闭当前issue;
2. 模板内容需要填写完整, 无论是受影响或者不受影响都需要填写完整内容,未引入的分支不需要填写, 否则无法关闭当前issue;
3. 以下为模板中需要填写完整的内容, 请复制到评论区回复, 注: 内容的标题名称(影响性分析说明, 缺陷严重等级, 受影响版本排查(受影响/不受影响), 修复是否涉及abi变化(是/否))不能省略,省略后defect-manager将无法正常解析填写内容.
评论区可能使用到的指令说明:

指令 指令说明 使用权限
/check-issue 触发defect-manager校验 不限
/reason xxx /reason +挂起或取消条件 不限

影响性分析说明:

缺陷严重等级:(Critical/High/Moderate/Low)

缺陷根因说明:

受影响版本排查(受影响/不受影响):

  1. openEuler-20.03-LTS-SP4:
  2. openEuler-22.03-LTS-SP3:
  3. openEuler-22.03-LTS-SP4:
  4. openEuler-24.03-LTS:
  5. openEuler-24.03-LTS-SP1:
  6. openEuler-24.03-LTS-SP2:

abi变化(是/否):

  1. openEuler-20.03-LTS-SP4:
  2. openEuler-22.03-LTS-SP3:
  3. openEuler-22.03-LTS-SP4:
  4. openEuler-24.03-LTS:
  5. openEuler-24.03-LTS-SP1:
  6. openEuler-24.03-LTS-SP2:

缺陷issue处理具体操作请参考:
https://atomgit.com/openeuler/cve-manager/blob/master/cve-vulner-manager/doc/md/defect-manager-manual.md
pr关联issue具体操作请参考:
https://docs.atomgit.com/docs/help/home/org_project/pullrequests/pr-related-issue

likedislike
openeuler-ci-botopeneuler-ci-bot成员
8月25日 添加了label:DEFECT/UNFIXED
Dding-jiao成员
8月25日 将 stavewu 设为负责人,移除负责人 allen-shi
Dding-jiao成员
8月25日 issue优先级由 无优先级 改变为 主要
Dding-jiao成员
8月25日 关联了里程碑:openEuler-26.09-DevStation-round1
Tengda Wu
Tengda Wu成员
8月27日 评论:

非核心模块,社区共性问题,2609作为创新分支,不处理。

likedislike
Dding-jiao成员
8月27日 issue状态由 待办的 改变为 已取消
Dding-jiao成员
8月27日 关闭了 issue
openeuler-ci-botopeneuler-ci-bot成员
8月27日 issue状态由 已取消 改变为 待办的
openeuler-ci-botopeneuler-ci-bot成员
8月27日 重新打开了 issue
openeuler-ci-bot
openeuler-ci-bot成员
8月27日 评论:

@stavewu
issue变更为 [已取消/已挂起] 状态前,请操作者填写相关原因
请按如下格式评论原因后,重新进行操作


/reason xxxxxx

likedislike
ding-jiao成员
8月27日 评论:

/reason 经开发确认,非核心模块,社区共性问题,2609作为创新分支,不处理。

likedislike
Dding-jiao成员
8月27日 issue状态由 待办的 改变为 已取消
Dding-jiao成员
8月27日 关闭了 issue