kernel panic: Proc-ful Page Fault in the Kernel at ADDR! (2)

1 view
Skip to first unread message

syzbot

unread,
Apr 30, 2019, 3:02:06 PM4/30/19
to aka...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 95e5d955 Remove extraneous sysfd2path()
git tree: akaros
console output: https://syzkaller.appspot.com/x/log.txt?x=11d0d7a8a00000
kernel config: https://syzkaller.appspot.com/x/.config?x=bc709c3b83482973
dashboard link: https://syzkaller.appspot.com/bug?extid=790face429c757264a6f

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+790fac...@syzkaller.appspotmail.com

kernel panic at kern/arch/x86/trap.c:318, from core 3: Proc-ful Page Fault
in the Kernel at 0x0000000020000104!
HW TRAP frame at 0xfffffff0000c7d40 on core 3
rax 0x00007f7fdfbfff00
rbx 0x0000000000000000
rcx 0x0000000000000020
rdx 0x000000001ffff100
rbp 0xfffffff0000c7e38
rsi 0x0000000020000100
rdi 0xffff80001576ad00
r8 0x0000000000000000
r9 0x0000000000000000
r10 0x000010000000a4c0
r11 0x0000000000000202
r12 0x0000000020000100
r13 0x0000000020000100
r14 0x0000000000000001
r15 0xffff80001576ad00
trap 0x0000000e Page Fault
gsbs 0xffffffffc8e38340
fsbs 0x0000000000000000
err 0x--------00000000
rip 0xffffffffc2058b44
cs 0x------------0008
flag 0x0000000000010246
rsp 0xfffffff0000c7e08
ss 0x------------0010
Backtrace of kernel context on Core 3:
#01 [<0xffffffffc2058b44>] in sys_tap_fds at src/syscall.c:2457
#02 [<0xffffffffc2059d79>] in syscall at src/syscall.c:2577
#03 [<0xffffffffc205a928>] in run_local_syscall at src/syscall.c:2614
#04 [<0xffffffffc205ae69>] in prep_syscalls at src/syscall.c:2634
#05 [<0xffffffffc20ac752>] in sysenter_callwrapper at arch/x86/trap.c:877


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Apr 30, 2019, 3:08:08 PM4/30/19
to aka...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 95e5d955 Remove extraneous sysfd2path()
git tree: akaros
console output: https://syzkaller.appspot.com/x/log.txt?x=10c86b42a00000
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=102f5b42a00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=10549cb8a00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+790fac...@syzkaller.appspotmail.com

kernel panic at kern/arch/x86/trap.c:318, from core 1: Proc-ful Page Fault
in the Kernel at 0x0000000020000104!
HW TRAP frame at 0xfffffff000014d40 on core 1
rax 0x00007f7fdfbfff00
rbx 0x0000000000000000
rcx 0x0000000000000020
rdx 0x000000001ffff100
rbp 0xfffffff000014e38
rsi 0x0000000020000100
rdi 0xffff80000218d000
r8 0x000030000003cfb0
r9 0x00000000006b0508
r10 0x000010000000a4c0
r11 0x0000000000000206
r12 0x0000000020000100
r13 0x0000000020000100
r14 0x0000000000000001
r15 0xffff80000218d000
trap 0x0000000e Page Fault
gsbs 0xffffffffc8e37dc0
fsbs 0x0000000000000000
err 0x--------00000000
rip 0xffffffffc2058b44
cs 0x------------0008
flag 0x0000000000010246
rsp 0xfffffff000014e08
ss 0x------------0010
Backtrace of kernel context on Core 1:
Reply all
Reply to author
Forward
0 new messages