Home | History | Annotate | Download | only in guilty
      1 FILE: net/ipv6/route.c
      2 
      3 ==================================================================
      4 BUG: KMSAN: use of uninitialized memory in rt6_mtu_change_route+0x4d8/0xa70 net/ipv6/route.c:3822
      5 CPU: 0 PID: 8319 Comm: syz-executor7 Not tainted 4.16.0-rc4+ #63
      6 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
      7 Call Trace:
      8  __dump_stack lib/dump_stack.c:17 [inline]
      9  dump_stack+0x185/0x1d0 lib/dump_stack.c:53
     10  kmsan_report+0x142/0x1f0 mm/kmsan/kmsan.c:1093
     11  __msan_warning_32+0x6c/0xb0 mm/kmsan/kmsan_instr.c:676
     12  rt6_mtu_change_route+0x4d8/0xa70 net/ipv6/route.c:3822
     13  fib6_clean_node+0x319/0x6b0 net/ipv6/ip6_fib.c:1918
     14  fib6_walk_continue+0x9a1/0xbb0 net/ipv6/ip6_fib.c:1844
     15  fib6_walk net/ipv6/ip6_fib.c:1892 [inline]
     16  fib6_clean_tree net/ipv6/ip6_fib.c:1969 [inline]
     17  __fib6_clean_all+0x501/0x810 net/ipv6/ip6_fib.c:1985
     18  fib6_clean_all+0x90/0xa0 net/ipv6/ip6_fib.c:1996
     19  rt6_mtu_change+0xd2/0x120 net/ipv6/route.c:3843
     20  addrconf_notify+0xb59/0x5020 net/ipv6/addrconf.c:3395
     21  notifier_call_chain kernel/notifier.c:93 [inline]
     22  __raw_notifier_call_chain kernel/notifier.c:394 [inline]
     23  raw_notifier_call_chain+0x13b/0x250 kernel/notifier.c:401
     24  call_netdevice_notifiers_info net/core/dev.c:1707 [inline]
     25  call_netdevice_notifiers net/core/dev.c:1725 [inline]
     26  dev_set_mtu+0xa0e/0xea0 net/core/dev.c:7043
     27  dev_ifsioc+0x3a9/0x10d0 net/core/dev_ioctl.c:244
     28  dev_ioctl+0x876/0x1490 net/core/dev_ioctl.c:498
     29  sock_do_ioctl+0x43a/0x6b0 net/socket.c:981
     30  sock_ioctl+0x4e0/0xbf0 net/socket.c:1081
     31  vfs_ioctl fs/ioctl.c:46 [inline]
     32  do_vfs_ioctl+0xc6d/0x2440 fs/ioctl.c:686
     33  SYSC_ioctl+0x1d9/0x260 fs/ioctl.c:701
     34  SyS_ioctl+0x54/0x80 fs/ioctl.c:692
     35  do_syscall_64+0x2f1/0x450 arch/x86/entry/common.c:287
     36  entry_SYSCALL_64_after_hwframe+0x3d/0xa2
     37 RIP: 0033:0x454239
     38 RSP: 002b:00007fac6f2d2c68 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
     39 RAX: ffffffffffffffda RBX: 00007fac6f2d36d4 RCX: 0000000000454239
     40 RDX: 0000000020000100 RSI: 0000000000008922 RDI: 0000000000000013
     41 RBP: 000000000072bea0 R08: 0000000000000000 R09: 0000000000000000
     42 R10: 0000000000000000 R11: 0000000000000246 R12: 00000000ffffffff
     43 R13: 0000000000000379 R14: 00000000006f63f8 R15: 0000000000000000
     44 chained origin:
     45  kmsan_save_stack_with_flags mm/kmsan/kmsan.c:303 [inline]
     46  kmsan_save_stack mm/kmsan/kmsan.c:318 [inline]
     47  kmsan_internal_chain_origin+0x12d/0x210 mm/kmsan/kmsan.c:709
     48  __msan_chain_origin+0x69/0xc0 mm/kmsan/kmsan_instr.c:521
     49  ip6_convert_metrics+0x715/0xa00 net/ipv6/route.c:2429
     50  ip6_route_add+0x13c/0x300 net/ipv6/route.c:2861
     51  inet6_rtm_newroute+0x1481/0x2520 net/ipv6/route.c:4255
     52  rtnetlink_rcv_msg+0xa4b/0x15d0 net/core/rtnetlink.c:4635
     53  netlink_rcv_skb+0x355/0x5f0 net/netlink/af_netlink.c:2444
     54  rtnetlink_rcv+0x50/0x60 net/core/rtnetlink.c:4653
     55  netlink_unicast_kernel net/netlink/af_netlink.c:1308 [inline]
     56  netlink_unicast+0x1656/0x1730 net/netlink/af_netlink.c:1334
     57  netlink_sendmsg+0x1048/0x1310 net/netlink/af_netlink.c:1897
     58  sock_sendmsg_nosec net/socket.c:630 [inline]
     59  sock_sendmsg net/socket.c:640 [inline]
     60  ___sys_sendmsg+0xed5/0x1330 net/socket.c:2046
     61  __sys_sendmsg net/socket.c:2080 [inline]
     62  SYSC_sendmsg+0x2a6/0x3d0 net/socket.c:2091
     63  SyS_sendmsg+0x54/0x80 net/socket.c:2087
     64  do_syscall_64+0x2f1/0x450 arch/x86/entry/common.c:287
     65  entry_SYSCALL_64_after_hwframe+0x3d/0xa2
     66 origin:
     67  kmsan_save_stack_with_flags mm/kmsan/kmsan.c:303 [inline]
     68  kmsan_internal_poison_shadow+0xb8/0x1b0 mm/kmsan/kmsan.c:213
     69  kmsan_kmalloc+0x94/0x100 mm/kmsan/kmsan.c:339
     70  kmsan_slab_alloc+0x11/0x20 mm/kmsan/kmsan.c:346
     71  slab_post_alloc_hook mm/slab.h:445 [inline]
     72  slab_alloc_node mm/slub.c:2737 [inline]
     73  __kmalloc_node_track_caller+0xa7a/0x1290 mm/slub.c:4369
     74  __kmalloc_reserve net/core/skbuff.c:138 [inline]
     75  __alloc_skb+0x2e3/0xa20 net/core/skbuff.c:206
     76  alloc_skb include/linux/skbuff.h:984 [inline]
     77  netlink_alloc_large_skb net/netlink/af_netlink.c:1180 [inline]
     78  netlink_sendmsg+0x9a6/0x1310 net/netlink/af_netlink.c:1872
     79  sock_sendmsg_nosec net/socket.c:630 [inline]
     80  sock_sendmsg net/socket.c:640 [inline]
     81  ___sys_sendmsg+0xed5/0x1330 net/socket.c:2046
     82  __sys_sendmsg net/socket.c:2080 [inline]
     83  SYSC_sendmsg+0x2a6/0x3d0 net/socket.c:2091
     84  SyS_sendmsg+0x54/0x80 net/socket.c:2087
     85  do_syscall_64+0x2f1/0x450 arch/x86/entry/common.c:287
     86  entry_SYSCALL_64_after_hwframe+0x3d/0xa2
     87 ==================================================================
     88