Fatal trap 12: page fault in inp_freemoptions

7 views
Skip to first unread message

syzbot

unread,
Mar 20, 2019, 6:32:05 AM3/20/19
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 90d8cba8 Fix two typos: an -> and; the the -> the
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=13a02327200000
dashboard link: https://syzkaller.appspot.com/bug?extid=1b803796ab94d11a46f9

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+1b8037...@syzkaller.appspotmail.com

Fatal trap 12: page fault while in kernel mode
cpuid = 1; apic id = 01
fault virtual address = 0x18
fault code = supervisor read data , page not present
instruction pointer = 0x20:0xffffffff812bee77
stack pointer = 0x28:0xfffffe0016ac08c0
frame pointer = 0x28:0xfffffe0016ac0900
code segment = base 0x0, limit 0xfffff, type 0x1b
= DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags = interrupt enabled, resume, IOPL = 0
current process = 0 (softirq_1)
trap number = 12
panic: page fault
cpuid = 1
time = 17363
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe0016ac0520
vpanic() at vpanic+0x1e0/frame 0xfffffe0016ac0580
panic() at panic+0x43/frame 0xfffffe0016ac05e0
trap_fatal() at trap_fatal+0x4c6/frame 0xfffffe0016ac0660
trap_pfault() at trap_pfault+0x9f/frame 0xfffffe0016ac06d0
trap() at trap+0x44d/frame 0xfffffe0016ac07f0
calltrap() at calltrap+0x8/frame 0xfffffe0016ac07f0
--- trap 0xc, rip = 0xffffffff812bee77, rsp = 0xfffffe0016ac08c0, rbp =
0xfffffe0016ac0900 ---
inp_freemoptions() at inp_freemoptions+0x177/frame 0xfffffe0016ac0900
in_pcbfree_deferred() at in_pcbfree_deferred+0x224/frame 0xfffffe0016ac0960
epoch_call_task() at epoch_call_task+0x262/frame 0xfffffe0016ac09c0
gtaskqueue_run_locked() at gtaskqueue_run_locked+0x13e/frame
0xfffffe0016ac0a20
gtaskqueue_thread_loop() at gtaskqueue_thread_loop+0xdd/frame
0xfffffe0016ac0a60
fork_exit() at fork_exit+0xb0/frame 0xfffffe0016ac0ab0
fork_trampoline() at fork_trampoline+0xe/frame 0xfffffe0016ac0ab0
--- trap 0, rip = 0, rsp = 0, rbp = 0 ---
KDB: enter: panic
[ thread pid 0 tid 100013 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#bug-status-tracking for how to communicate with
syzbot.

syzbot

unread,
Mar 20, 2019, 6:53:05 AM3/20/19
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 90d8cba8 Fix two typos: an -> and; the the -> the
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=1361505d200000
dashboard link: https://syzkaller.appspot.com/bug?extid=1b803796ab94d11a46f9
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=17c98217200000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+1b8037...@syzkaller.appspotmail.com

Fatal trap 12: page fault while in kernel mode
cpuid = 1; apic id = 01
fault virtual address = 0x18
fault code = supervisor read data , page not present
instruction pointer = 0x20:0xffffffff812bee77
stack pointer = 0x28:0xfffffe0016ac08c0
frame pointer = 0x28:0xfffffe0016ac0900
code segment = base 0x0, limit 0xfffff, type 0x1b
= DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags = interrupt enabled, resume, IOPL = 0
current process = 0 (softirq_1)
trap number = 12
panic: page fault
cpuid = 1
time = 1553078936

syzbot

unread,
May 8, 2019, 12:21:09 AM5/8/19
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 206ba424 make sysent after r347228
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=1395008ca00000
dashboard link: https://syzkaller.appspot.com/bug?extid=1b803796ab94d11a46f9
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=10b84422a00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1362ee20a00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+1b8037...@syzkaller.appspotmail.com

Fatal trap 12: page fault while in kernel mode
cpuid = 0; apic id = 00
fault virtual address = 0x18
fault code = supervisor read data , page not present
instruction pointer = 0x20:0xffffffff812c3df7
stack pointer = 0x28:0xfffffe0016ac58c0
frame pointer = 0x28:0xfffffe0016ac5900
code segment = base 0x0, limit 0xfffff, type 0x1b
= DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags = interrupt enabled, resume, IOPL = 0
current process = 0 (softirq_0)
trap number = 12
panic: page fault
cpuid = 0
time = 1557289015
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe0016ac5520
vpanic() at vpanic+0x1e0/frame 0xfffffe0016ac5580
panic() at panic+0x43/frame 0xfffffe0016ac55e0
trap_fatal() at trap_fatal+0x4c6/frame 0xfffffe0016ac5660
trap_pfault() at trap_pfault+0x9f/frame 0xfffffe0016ac56d0
trap() at trap+0x44d/frame 0xfffffe0016ac57f0
calltrap() at calltrap+0x8/frame 0xfffffe0016ac57f0
--- trap 0xc, rip = 0xffffffff812c3df7, rsp = 0xfffffe0016ac58c0, rbp =
0xfffffe0016ac5900 ---
inp_freemoptions() at inp_freemoptions+0x177/frame 0xfffffe0016ac5900
in_pcbfree_deferred() at in_pcbfree_deferred+0x224/frame 0xfffffe0016ac5960
epoch_call_task() at epoch_call_task+0x262/frame 0xfffffe0016ac59c0
gtaskqueue_run_locked() at gtaskqueue_run_locked+0x13e/frame
0xfffffe0016ac5a20
gtaskqueue_thread_loop() at gtaskqueue_thread_loop+0xdd/frame
0xfffffe0016ac5a60
fork_exit() at fork_exit+0xb0/frame 0xfffffe0016ac5ab0
fork_trampoline() at fork_trampoline+0xe/frame 0xfffffe0016ac5ab0
--- trap 0, rip = 0, rsp = 0, rbp = 0 ---
KDB: enter: panic
[ thread pid 0 tid 100014 ]
Reply all
Reply to author
Forward
0 new messages