kernel panic: [German Accent]: OOM for a small slab growth!!! (2)

10 views
Skip to first unread message

syzbot

unread,
Jul 18, 2018, 2:35:02 PM7/18/18
to aka...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: bf9a9ba0d6af Add panic_hwtf() for kernel faults
git tree: https://github.com/akaros/akaros.git/master
console output: https://syzkaller.appspot.com/x/log.txt?x=16b9a978400000
kernel config: https://syzkaller.appspot.com/x/.config?x=efef8cf2939304d3
dashboard link: https://syzkaller.appspot.com/bug?extid=b2f2e3eb4ea5b282c918
compiler:

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+b2f2e3...@syzkaller.appspotmail.com

ROS(Core 2)> kernel panic at kern/src/slab.c:518, from core 0: [German
Accent]: OOM for a small slab growth!!!
Stack Backtrace on Core 0:
#01 [<0xffffffffc200a3e7>] in backtrace at src/kdebug.c:219
#02 [<0xffffffffc2009bb2>] in _panic at src/init.c:273
#03 [<0xffffffffc2053541>] in __kmem_alloc_from_slab at src/slab.c:518
#04 [<0xffffffffc2053b6a>] in kmem_cache_alloc at src/slab.c:592
#05 [<0xffffffffc2002267>] in arena_alloc at src/arena.c:714
#06 [< [inline] >] in kpages_alloc at src/page_alloc.c:80
#06 [<0xffffffffc2045faf>] in get_a_free_page at src/page_alloc.c:18
#07 [<0xffffffffc2046081>] in upage_alloc at src/page_alloc.c:37
#08 [<0xffffffffc200dde4>] in copy_page.9776 at src/mm.c:506
#09 [<0xffffffffc20a6980>] in trampoline_cb.9421 at arch/x86/pmap64.c:522
#10 [<0xffffffffc20a63e8>] in __pml_for_each at arch/x86/pmap64.c:338
#11 [<0xffffffffc20a63c3>] in __pml_for_each at arch/x86/pmap64.c:329
#12 [<0xffffffffc20a63c3>] in __pml_for_each at arch/x86/pmap64.c:329
#13 [<0xffffffffc20a63c3>] in __pml_for_each at arch/x86/pmap64.c:329
#14 [< [inline] >] in pml_for_each at arch/x86/pmap64.c:347
#14 [<0xffffffffc20a6ff1>] in env_user_mem_walk at arch/x86/pmap64.c:529
#15 [< [inline] >] in copy_pages at src/mm.c:524
#15 [< [inline] >] in fill_vmr at src/mm.c:537
#15 [<0xffffffffc200ebbd>] in duplicate_vmrs at src/mm.c:587
#16 [<0xffffffffc20574ab>] in sys_fork at src/syscall.c:964
#17 [<0xffffffffc20593c9>] in syscall at src/syscall.c:2528
#18 [<0xffffffffc2059584>] in run_local_syscall at src/syscall.c:2563
#19 [<0xffffffffc2059ab9>] in prep_syscalls at src/syscall.c:2583
#20 [<0xffffffffc20ab29a>] in sysenter_callwrapper at arch/x86/trap.c:851


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#bug-status-tracking for how to communicate with
syzbot.

syzbot

unread,
Jul 20, 2018, 5:47:02 PM7/20/18
to aka...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 9196d29ad275 qio: Fix Qmsg panic in read_all_blocks()
git tree: https://github.com/akaros/akaros.git/master
console output: https://syzkaller.appspot.com/x/log.txt?x=10c90c44400000
syzkaller repro:https://syzkaller.appspot.com/x/repro.syz?x=1017cf94400000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1361c658400000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+b2f2e3...@syzkaller.appspotmail.com

kernel panic at kern/src/slab.c:518, from core 0: [German Accent]: OOM for
a small slab growth!!!
Stack Backtrace on Core 0:
#01 [<0xffffffffc200a2bc>] in backtrace at src/kdebug.c:220
#02 [<0xffffffffc2009afd>] in _panic at src/init.c:268
#03 [<0xffffffffc2053591>] in __kmem_alloc_from_slab at src/slab.c:518
#04 [<0xffffffffc2053bba>] in kmem_cache_alloc at src/slab.c:592
#05 [<0xffffffffc2002267>] in arena_alloc at src/arena.c:714
#06 [< [inline] >] in kmem_cache_grow at src/slab.c:706
#06 [<0xffffffffc2053394>] in __kmem_alloc_from_slab at src/slab.c:513
#07 [<0xffffffffc2053bba>] in kmem_cache_alloc at src/slab.c:592
#08 [<0xffffffffc200a742>] in kmalloc at src/kmalloc.c:74
#09 [<0xffffffffc205b65e>] in user_memdup.part.3 at src/umem.c:144
#10 [< [inline] >] in user_memdup at src/umem.c:144
#10 [<0xffffffffc205b8fd>] in user_strdup at src/umem.c:175
#11 [<0xffffffffc205b929>] in user_strdup_errno at src/umem.c:184
#12 [<0xffffffffc205bbda>] in copy_in_path at src/umem.c:252
#13 [<0xffffffffc205887a>] in sys_openat at src/syscall.c:1801
#14 [<0xffffffffc2059439>] in syscall at src/syscall.c:2528
#15 [<0xffffffffc2059604>] in run_local_syscall at src/syscall.c:2563
#16 [<0xffffffffc2059b39>] in prep_syscalls at src/syscall.c:2583
#17 [<0xffffffffc20ab38a>] in sysenter_callwrapper at arch/x86/trap.c:854

Reply all
Reply to author
Forward
0 new messages