kernel panic: kroc-ful Page Fault in thPe Kernel at ADDR!buf 4096r,S STAT_FIX_LENT_AT_FIX_LEN_9P 49 n the Kernel at ADDR

0 views
Skip to first unread message

syzbot

unread,
Jul 18, 2018, 8:00:06 PM7/18/18
to aka...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: bf9a9ba0d6af Add panic_hwtf() for kernel faults
git tree: https://github.com/akaros/akaros.git/master
console output: https://syzkaller.appspot.com/x/log.txt?x=159814b4400000
kernel config: https://syzkaller.appspot.com/x/.config?x=efef8cf2939304d3
dashboard link: https://syzkaller.appspot.com/bug?extid=b6dc1dbc7daf58c54794
compiler:

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+b6dc1d...@syzkaller.appspotmail.com

kernel panic at kern/arch/x86/trap.c:309, from core 1: kroc-ful Page Fault
in thPe Kernel at 0x000000000000001b!buf 4096r,S
STAT_FIX_LENT_AT_FIX_LEN_9P 49 n the Kernel at 0x000000000000001b!9
PH0xffWT16SZ 2, GBIT16(buf) 0 f0000cad30 on core BIT16SZ 1
2 rax 0x0000000000000000
0 rbfffx 0xffff8000063ebba0
8 rcx 0xfffffff0000caea0
f rdx 0xfffffff0000cad6c
f 0000cae38rThis is bad!
s is bad!
nAbuT_FIf 40X9_6, LSEN_9PT rsi 0x0000000000000000
0ff0000caea0
49 IT16SZ 2, GBIT16(buf) 0
B r8 0x0000000000000001
r9 0xffffffff r9 0c87xffffffffc8790880
9 00 r10 0x0000000000000030
3 r11 0xffff800003a9e6a0
0 his is bad!
80000217aac0
T r13 0x00000000200006c0
r14 0x0000000000000073
r r15 0x0000000000000021
1 trap 0x0000000e Page Fault
a gsbs 0xffffffffc8667c40
s fsbs 0x0000000000000000
err 00x------x------00000000
rip 0xffffffffc20583b4
cs 0x------------0008
flag 0x0000000000010246
rsp 0xfffffff0000cadf8
ss 0x------------0010
Backtrace of kernel context on Core 1:
#01 [<0xffffffffc20583b4>] in sys_readlink at src/syscall.c:2037
#02 [<0xffffffffc20593c9>] in syscall at src/syscall.c:2528
#03 [<0xffffffffc2059584>] in run_local_syscall at src/syscall.c:2563
#04 [<0xffffffffc2059ab9>] in prep_syscalls at src/syscall.c:2583
#05 [<0xffffffffc20ab29a>] in sysenter_callwrapper at arch/x86/trap.c:851
23:35:54 executing program 4:
r0 = openat$proc_self_fpregs(0xffffffffffffff9c,
&(0x7f0000000000)='/proc/self/fpregs\x00', 0x12, 0x1, 0x0)
tcgetattr(r0, &(0x7f0000000040))
23:35:54 executing program 5:
openat$dev_kmesg(0xffffffffffffff9c, &(0x7f0000000000)='/dev/kmesg\x00',
0xb, 0x1, 0x0)
mmap(&(0x7f0000ffe000/0x2000)=nil, 0x2000, 0x1000000, 0x4011,
0xffffffffffffff9c, 0x0)


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#bug-status-tracking for how to communicate with
syzbot.

Barret Rhoden

unread,
Jul 19, 2018, 4:24:14 PM7/19/18
to syzbot, aka...@googlegroups.com
On 2018-07-18 at 17:00 syzbot
#syz invalid
Reply all
Reply to author
Forward
0 new messages