kernel panic: Damn Damn! Unhandled trap in the kernel! (4)

3 views
Skip to first unread message

syzbot

unread,
May 4, 2019, 1:41:07 AM5/4/19
to aka...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: d8ea787e 9ns: don't pass user pointers for 'spec'
git tree: akaros
console output: https://syzkaller.appspot.com/x/log.txt?x=1386ad70a00000
kernel config: https://syzkaller.appspot.com/x/.config?x=bc709c3b83482973
dashboard link: https://syzkaller.appspot.com/bug?extid=a20f4107d5ec7009c1c4

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+a20f41...@syzkaller.appspotmail.com

kernel panic at kern/arch/x86/trap.c:628, from core 0: Damn Damn!
Unhandled trap in the kernel!
HW TRAP frame at 0xfffffff0000527b0 on core 0
rax 0x0000000000000006
rbx 0xffff8000155c4900
rcx 0x00000000000000c5
rdx 0x0000000000000000
rbp 0xfffffff0000528c8
rsi 0xffff800014ee0000
rdi 0xffff8000155c4900
r8 0x0000000000000000
r9 0x0000000000000002
r10 0x00000000000005b8
r11 0xffff80001538a6dc
r12 0x0000000020001700
r13 0x0000000000000005
r14 0xfffffff000052910
r15 0xffff80000218fd01
trap 0x00000000 Divide error
gsbs 0xffffffffc8e37b00
fsbs 0x0000000000000000
err 0x--------00000000
rip 0xffffffffc200758d
cs 0x------------0008
flag 0x0000000000010206
rsp 0xfffffff000052878
ss 0x------------0000
Backtrace of kernel context on Core 0:
#01 [<0xffffffffc200758d>] in send_event at src/event.c:393
#02 [<0xffffffffc2008074>] in fire_tap at src/fdtap.c:182
#03 [<0xffffffffc20161bb>] in fire_data_taps at src/net/devip.c:1560
#04 [<0xffffffffc201620a>] in ip_wake_cb at src/net/devip.c:1577
#05 [< [inline] >] in qwake_cb at src/ns/qio.c:113
#05 [<0xffffffffc203b5c7>] in __qbwrite at src/ns/qio.c:1566
#06 [<0xffffffffc203c4bb>] in qpassnolim at src/ns/qio.c:930
#07 [<0xffffffffc202ef41>] in tcpiput at src/net/tcp.c:2595
#08 [<0xffffffffc201e232>] in ipiput4 at src/net/ip.c:543
#09 [<0xffffffffc201a601>] in etherread4 at src/net/ethermedium.c:457
#10 [<0xffffffffc200b354>] in __ktask_wrapper at src/kthread.c:292
#11 [<0xffffffffc205bd0d>] in process_routine_kmsg at src/trap.c:241
#12 [<0xffffffffc20556ee>] in __smp_idle at src/smp.c:78


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
May 4, 2019, 2:01:06 AM5/4/19
to aka...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: d8ea787e 9ns: don't pass user pointers for 'spec'
git tree: akaros
console output: https://syzkaller.appspot.com/x/log.txt?x=126351c2a00000
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=103b76e2a00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+a20f41...@syzkaller.appspotmail.com

kernel panic at kern/arch/x86/trap.c:628, from core 0: Damn Damn!
Unhandled trap in the kernel!
HW TRAP frame at 0xfffffff0000527b0 on core 0
rax 0x0000000000000006
rbx 0xffff80000218b900
rcx 0x00000000000000c5
rdx 0x0000000000000000
rbp 0xfffffff0000528c8
rsi 0xffff800003b39000
rdi 0xffff80000218b900
r8 0x0000000000000000
r9 0x0000000000000000
r10 0x0000000000000054
r11 0xffff800004da117c
r12 0x0000000020001700
r13 0x0000000000000005
r14 0xfffffff000052910
r15 0xffff80000218d001
Reply all
Reply to author
Forward
0 new messages