kernel panic: rpc tags (2)

22 views
Skip to first unread message

syzbot

unread,
Jul 24, 2018, 2:32:05 AM7/24/18
to aka...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: c5f7000db927 Print backtraces when we do a warn()
git tree: https://github.com/akaros/akaros.git/master
console output: https://syzkaller.appspot.com/x/log.txt?x=15417b70400000
kernel config: https://syzkaller.appspot.com/x/.config?x=efef8cf2939304d3
dashboard link: https://syzkaller.appspot.com/bug?extid=07c27d1bdc8f9cd038d3
compiler:

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+07c27d...@syzkaller.appspotmail.com

kernel panic at kern/drivers/dev/mnt.c:1106, from core 3: rpc tags
Stack Backtrace on Core 3:
#01 [<0xffffffffc200a2dc>] in backtrace at src/kdebug.c:220
#02 [<0xffffffffc2009afd>] in _panic at src/init.c:268
#03 [<0xffffffffc207df5a>] in mntralloc at drivers/dev/mnt.c:1106
#04 [<0xffffffffc207e003>] in mntflushalloc at drivers/dev/mnt.c:1033
#05 [<0xffffffffc207e45a>] in mountio at drivers/dev/mnt.c:831
#06 [<0xffffffffc207e585>] in mountrpc at drivers/dev/mnt.c:770
#07 [<0xffffffffc207f539>] in mntrdwr at drivers/dev/mnt.c:740
#08 [<0xffffffffc207f64d>] in mntread at drivers/dev/mnt.c:687
#09 [<0xffffffffc203f6c3>] in rread at src/ns/sysfile.c:763
#10 [<0xffffffffc203f86b>] in sysread at src/ns/sysfile.c:821
#11 [<0xffffffffc2055fa1>] in sys_read at src/syscall.c:1779
#12 [<0xffffffffc2059459>] in syscall at src/syscall.c:2528
#13 [<0xffffffffc2059624>] in run_local_syscall at src/syscall.c:2563
#14 [<0xffffffffc2059b59>] in prep_syscalls at src/syscall.c:2583
#15 [<0xffffffffc20ab41a>] in sysenter_callwrapper at arch/x86/trap.c:854
ROS(Core 3)>
kernel panic at kern/drivers/dev/mnt.c:1106, from core 0: rpc tags
Stack Backtrace on Core 0:
#01 [<0xffffffffc200a2dc>] in backtrace at src/kdebug.c:220
#02 [<0xffffffffc2009afd>] in _panic at src/init.c:268
#03 [<0xffffffffc207df5a>] in mntralloc at drivers/dev/mnt.c:1106
#04 [<0xffffffffc207ed96>] in mntclunk at drivers/dev/mnt.c:591
#05 [<0xffffffffc207ee5e>] in mntclose at drivers/dev/mnt.c:642
#06 [<0xffffffffc2031a40>] in chan_release at src/ns/chan.c:174
#07 [<0xffffffffc203117b>] in kref_put at include/kref.h:70
#08 [<0xffffffffc2031868>] in cclose at src/ns/chan.c:333
#09 [<0xffffffffc2041898>] in close_fdt at src/ns/sysfile.c:1843
#10 [<0xffffffffc204ceff>] in proc_destroy at src/process.c:918
#11 [<0xffffffffc2056d56>] in sys_proc_destroy at src/syscall.c:909
#12 [<0xffffffffc2059459>] in syscall at src/syscall.c:2528
#13 [<0xffffffffc2059624>] in run_local_syscall at src/syscall.c:2563
#14 [<0xffffffffc2059b59>] in prep_syscalls at src/syscall.c:2583
#15 [<0xffffffffc20ab41a>] in sysenter_callwrapper at arch/x86/trap.c:854


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#bug-status-tracking for how to communicate with
syzbot.

syzbot

unread,
Jul 25, 2018, 9:33:02 PM7/25/18
to aka...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 8dc899e19d0f vmm: x86: Set the reserved bits in rflags
git tree: https://github.com/akaros/akaros.git/master
console output: https://syzkaller.appspot.com/x/log.txt?x=1169932c400000
syzkaller repro:https://syzkaller.appspot.com/x/repro.syz?x=159a1770400000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=177fa9a4400000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+07c27d...@syzkaller.appspotmail.com

kernel panic at kern/drivers/dev/mnt.c:1106, from core 3: rpc tags
Stack Backtrace on Core 3:
#01 [<0xffffffffc200a2dc>] in backtrace at src/kdebug.c:220
#02 [<0xffffffffc2009afd>] in _panic at src/init.c:268
#03 [<0xffffffffc207deaa>] in mntralloc at drivers/dev/mnt.c:1106
#04 [<0xffffffffc207df53>] in mntflushalloc at drivers/dev/mnt.c:1033
#05 [<0xffffffffc207e3aa>] in mountio at drivers/dev/mnt.c:831
#06 [<0xffffffffc207e4d5>] in mountrpc at drivers/dev/mnt.c:770
#07 [<0xffffffffc207f489>] in mntrdwr at drivers/dev/mnt.c:740
#08 [<0xffffffffc207f59d>] in mntread at drivers/dev/mnt.c:687
#09 [<0xffffffffc203f673>] in rread at src/ns/sysfile.c:763
#10 [<0xffffffffc203f81b>] in sysread at src/ns/sysfile.c:821
#11 [<0xffffffffc2055f51>] in sys_read at src/syscall.c:1779
#12 [<0xffffffffc2059409>] in syscall at src/syscall.c:2528
#13 [<0xffffffffc20595d4>] in run_local_syscall at src/syscall.c:2563
#14 [<0xffffffffc2059b09>] in prep_syscalls at src/syscall.c:2583
#15 [<0xffffffffc20ab36a>] in sysenter_callwrapper at arch/x86/trap.c:854
ROS(Core 3)>
kernel panic at kern/src/slab.c:518, from core 0: [German Accent]: OOM for
a small slab growth!!!
Stack Backtrace on Core 0:
#01 [<0xffffffffc200a2dc>] in backtrace at src/kdebug.c:220
#02 [<0xffffffffc2009afd>] in _panic at src/init.c:268
#03 [<0xffffffffc2053561>] in __kmem_alloc_from_slab at src/slab.c:518
#04 [<0xffffffffc2053b8a>] in kmem_cache_alloc at src/slab.c:592
#05 [<0xffffffffc2002267>] in arena_alloc at src/arena.c:714
#06 [< [inline] >] in kpages_alloc at src/page_alloc.c:80
#06 [<0xffffffffc2045d8f>] in get_a_free_page at src/page_alloc.c:18
#07 [<0xffffffffc2045e61>] in upage_alloc at src/page_alloc.c:37
#08 [<0xffffffffc200e62e>] in __hpf at src/mm.c:1226
#09 [<0xffffffffc200f8be>] in handle_page_fault at src/mm.c:1302
#10 [< [inline] >] in __handler_user_page_fault at
arch/x86/trap.c:253
#10 [< [inline] >] in __handle_page_fault at arch/x86/trap.c:330
#10 [< [inline] >] in trap_dispatch at arch/x86/trap.c:588
#10 [<0xffffffffc20aa863>] in trap at arch/x86/trap.c:669

Reply all
Reply to author
Forward
0 new messages