panic: ASan: Invalid access, NUM-byte write at ADDR, MallocRedZone(fb)

3 views
Skip to first unread message

syzbot

unread,
Jun 22, 2022, 3:17:26 AM6/22/22
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: b256d2dc0c2f Temporarily skip flaky test case: sys.netpfil..
git tree: freebsd-src
console output: https://syzkaller.appspot.com/x/log.txt?x=15f6c63ff00000
dashboard link: https://syzkaller.appspot.com/bug?extid=c94f6c97744bd9f9d14d
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1776c174080000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1250d674080000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+c94f6c...@syzkaller.appspotmail.com

login: panic: ASan: Invalid access, 4-byte write at 0xfffffe00579977f8, MallocRedZone(fb)
cpuid = 1
time = 1655882111
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0xc7/frame 0xfffffe005402fcb0
kdb_backtrace() at kdb_backtrace+0xd3/frame 0xfffffe005402fe10
vpanic() at vpanic+0x254/frame 0xfffffe005402fef0
panic() at panic+0xb5/frame 0xfffffe005402ffb0
kasan_report() at kasan_report+0xdc/frame 0xfffffe0054030080
cb_put_phdr() at cb_put_phdr+0x4b/frame 0xfffffe00540300c0
each_dumpable_segment() at each_dumpable_segment+0x231/frame 0xfffffe0054030110
elf64_puthdr() at elf64_puthdr+0x497/frame 0xfffffe00540301f0
elf64_coredump() at elf64_coredump+0x53d/frame 0xfffffe00540303d0
sigexit() at sigexit+0x1e3c/frame 0xfffffe0054030d30
postsig() at postsig+0x2c4/frame 0xfffffe0054030eb0
ast() at ast+0xc5b/frame 0xfffffe0054030f30
doreti_ast() at doreti_ast+0x1f/frame 0x821126e80
KDB: enter: panic
[ thread pid 783 tid 100093 ]
Stopped at kdb_enter+0x6b: movq $0,0x275b2ea(%rip)
db>
db> set $lines = 0
db> set $maxwidth = 0
db> show registers
cs 0x20
ds 0x3b
es 0x3b
fs 0x13
gs 0x1b
ss 0
rax 0x12
rcx 0x1fffffc00a805f4c
rdx 0xdffff7c000000000
rbx 0
rsp 0xfffffe005402fdf0
rbp 0xfffffe005402fe10
rsi 0x1
rdi 0
r8 0x3
r9 0xffffffff
r10 0
r11 0x246
r12 0
r13 0xfffffe0058c29560
r14 0xffffffff82b5ae60 .str.26
r15 0xffffffff82b5ae60 .str.26
rip 0xffffffff8171b42b kdb_enter+0x6b
rflags 0x46
kdb_enter+0x6b: movq $0,0x275b2ea(%rip)
db> show proc
Process 783 (syz-executor1927027) at 0xfffffe0058c27000:
state: NORMAL
uid: 0 gids: 0, 0, 5
parent: pid 782 at 0xfffffe0058c25000
ABI: FreeBSD ELF64
flag: 0x10000000 flag2: 0x40000
arguments: ./syz-executor1927027967
reaper: 0xfffffe0053dcc000 reapsubtree: 1
sigparent: 0
vmspace: 0xfffffe0058b4f3f0
(map 0xfffffe0058b4f3f0)
(map.pmap 0xfffffe0058b4f4b0)
(pmap 0xfffffe0058b4f518)
threads: 1
100093 Run CPU 1 syz-executor1927027
db> ps
pid ppid pgrp uid state wmesg wchan cmd
784 783 779 0 R syz-executor1927027
783 782 779 0 R CPU 1 syz-executor1927027
782 781 779 0 R CPU 0 syz-executor1927027
781 779 779 0 R syz-executor1927027
779 777 779 0 Ss pause 0xfffffe0058c25b40 csh
777 688 777 0 Ss select 0xfffffe0056fbc940 sshd
754 1 754 0 Ss+ ttyin 0xfffffe0056f2acb0 getty
753 1 753 0 Ss+ ttyin 0xfffffe0056f294b0 getty
752 1 752 0 Ss+ ttyin 0xfffffe0056f298b0 getty
751 1 751 0 Ss+ ttyin 0xfffffe00585d7cb0 getty
750 1 750 0 Ss+ ttyin 0xfffffe00585d80b0 getty
749 1 749 0 Ss+ ttyin 0xfffffe0056f29cb0 getty
748 1 748 0 Ss+ ttyin 0xfffffe00585d84b0 getty
747 1 747 0 Ss+ ttyin 0xfffffe00585d88b0 getty
746 1 746 0 Ss+ ttyin 0xfffffe00585d8cb0 getty
744 1 18 0 S+ piperd 0xfffffe0058b4dba0 logger
743 742 18 0 S+ nanslp 0xffffffff83e43dc0 sleep
742 1 18 0 S+ wait 0xfffffe00926cea90 sh
692 1 692 0 Ss nanslp 0xffffffff83e43dc0 cron
688 1 688 0 Ss select 0xfffffe0057871a40 sshd
501 1 501 0 Ss select 0xfffffe0056f9cc40 syslogd
430 1 430 0 Ss select 0xfffffe0056f9d0c0 devd
429 1 429 65 Ss select 0xfffffe0056f9cf40 dhclient
344 1 344 0 Ss select 0xfffffe0056f9cdc0 dhclient
341 1 341 0 Ss select 0xfffffe00578719c0 dhclient
17 0 0 0 DL vlruwt 0xfffffe0056f67548 [vnlru]
16 0 0 0 DL syncer 0xffffffff83f695e0 [syncer]
15 0 0 0 DL (threaded) [bufdaemon]
100079 D psleep 0xffffffff83f67be0 [bufdaemon]
100082 D - 0xffffffff83211f80 [bufspacedaemon-0]
100094 D sdflush 0xfffffe0053c6e8e8 [/ worker]
9 0 0 0 DL psleep 0xffffffff83f9b700 [vmdaemon]
8 0 0 0 DL (threaded) [pagedaemon]
100077 D psleep 0xffffffff83f8f5b8 [dom0]
100080 D launds 0xffffffff83f8f5c4 [laundry: dom0]
100081 D umarcl 0xffffffff81e4d160 [uma]
7 0 0 0 DL - 0xffffffff83c003a8 [rand_harvestq]
6 0 0 0 DL pftm 0xffffffff8465f550 [pf purge]
5 0 0 0 DL waiting 0xffffffff84a77420 [sctp_iterator]
4 0 0 0 DL (threaded) [cam]
100044 D - 0xffffffff83aa3340 [doneq0]
100045 D - 0xffffffff83aa32c0 [async]
100076 D - 0xffffffff83aa3140 [scanner]
14 0 0 0 DL seqstat 0xfffffe0007962888 [sequencer 00]
3 0 0 0 DL (threaded) [crypto]
100040 D crypto_ 0xffffffff83f8ade0 [crypto]
100041 D crypto_ 0xfffffe0053e71d30 [crypto returns 0]
100042 D crypto_ 0xfffffe0053e71d80 [crypto returns 1]
13 0 0 0 DL (threaded) [geom]
100035 D - 0xffffffff83e193c0 [g_event]
100036 D - 0xffffffff83e193e0 [g_up]
100037 D - 0xffffffff83e19400 [g_down]
2 0 0 0 WL (threaded) [clock]
100029 I [clock (0)]
100030 I [clock (1)]
12 0 0 0 WL (threaded) [intr]
100015 I [swi5: fast taskq]
100018 I [swi6: task queue]
100019 I [swi6: Giant taskq]
100031 I [swi1: netisr 0]
100032 I [swi1: hpts]
100033 I [swi1: hpts]
100046 I [irq24: virtio_pci0]
100047 I [irq25: virtio_pci0]
100048 I [irq26: virtio_pci0]
100049 I [irq27: virtio_pci0]
100050 I [irq28: virtio_pci1]
100051 I [irq29: virtio_pci1]
100052 I [irq30: virtio_pci1]
100053 I [irq31: virtio_pci1]
100054 I [irq32: virtio_pci1]
100059 I [irq33: virtio_pci2]
100060 I [irq34: virtio_pci2]
100061 I [irq35: virtio_pci2]
100063 I [irq1: atkbd0]
100064 I [irq12: psm0]
100065 I [swi0: uart uart++]
100069 I [swi1: pf send]
11 0 0 0 RL (threaded) [idle]
100003 CanRun [idle: cpu0]
100004 CanRun [idle: cpu1]
1 0 1 0 SLs wait 0xfffffe0053dcc000 [init]
10 0 0 0 DL audit_w 0xffffffff83f8b8c0 [audit]
0 0 0 0 DLs (threaded) [kernel]
100000 D swapin 0xffffffff83e19dc0 [swapper]
100005 D - 0xfffffe000817de00 [if_config_tqg_0]
100006 D - 0xfffffe000817dd00 [softirq_0]
100007 D - 0xfffffe000817dc00 [softirq_1]
100008 D - 0xfffffe000817db00 [if_io_tqg_0]
100009 D - 0xfffffe000817da00 [if_io_tqg_1]
100010 D - 0xfffffe000817d900 [inm_free taskq]
100011 D - 0xfffffe000817d800 [linuxkpi_irq_wq]
100012 D - 0xfffffe000817d700 [in6m_free taskq]
100013 D - 0xfffffe000817d600 [deferred_unmount ta]
100014 D - 0xfffffe000817d500 [thread taskq]
100016 D - 0xfffffe000817d300 [kqueue_ctx taskq]
100017 D - 0xfffffe000817d200 [pci_hp taskq]
100020 D - 0xfffffe000817ce00 [aiod_kick taskq]
100021 D - 0xfffffe000817cd00 [linuxkpi_short_wq_0]
100022 D - 0xfffffe000817cd00 [linuxkpi_short_wq_1]
100023 D - 0xfffffe000817cd00 [linuxkpi_short_wq_2]
100024 D - 0xfffffe000817cd00 [linuxkpi_short_wq_3]
100025 D - 0xfffffe000817cc00 [linuxkpi_long_wq_0]
100026 D - 0xfffffe000817cc00 [linuxkpi_long_wq_1]
100027 D - 0xfffffe000817cc00 [linuxkpi_long_wq_2]
100028 D - 0xfffffe000817cc00 [linuxkpi_long_wq_3]
100034 D - 0xfffffe000817cb00 [firmware taskq]
100038 D - 0xfffffe000817ca00 [crypto_0]
100039 D - 0xfffffe000817ca00 [crypto_1]
100055 D - 0xfffffe000817c800 [vtnet0 rxq 0]
100056 D - 0xfffffe000817c700 [vtnet0 txq 0]
100057 D - 0xfffffe000817c600 [vtnet0 rxq 1]
100058 D - 0xfffffe000817c500 [vtnet0 txq 1]
100062 D vtbslp 0xfffffe0056f9d380 [virtio_balloon]
100066 D - 0xffffffff82b60ce0 [deadlkres]
100070 D - 0xfffffe000817e100 [mca taskq]
100071 D - 0xfffffe00585d3300 [acpi_task_0]
100072 D - 0xfffffe00585d3300 [acpi_task_1]
100073 D - 0xfffffe00585d3300 [acpi_task_2]
100075 D - 0xfffffe000817c900 [CAM taskq]
db> show all locks
Process 783 (syz-executor1927027) thread 0xfffffe0058c29560 (100093)
shared sx vm map (user) (vm map (user)) r = 0 (0xfffffe0058b4f450) locked @ /syzkaller/managers/main/kernel/sys/kern/imgact_elf.c:1743
db> show malloc
Type InUse MemUse Requests
pf_hash 5 11524K 5
tcp_hpts 7 4801K 7
devbuf 4217 4323K 4242
sysctloid 35205 2074K 35276
vtbuf 24 1968K 46
kobj 328 1312K 490
newblk 540 1159K 591
vfscache 3 1025K 3
pcb 19 537K 38
inodedep 27 522K 72
ufs_quota 1 512K 1
vfs_hash 1 512K 1
callout 2 512K 2
intr 4 472K 4
subproc 101 194K 843
acpica 1674 184K 57552
vnet_data 1 168K 1
tidhash 3 141K 3
vmem 3 138K 4
linker 358 134K 386
pagedep 8 130K 18
tfo_ccache 1 128K 1
sem 4 106K 4
DEVFS1 105 105K 114
bus 995 81K 5208
mtx_pool 2 72K 2
syncache 1 68K 1
module 514 65K 514
acpitask 1 64K 1
ddb_capture 1 64K 1
temp 35 36K 1639
hostcache 1 32K 1
shm 1 32K 1
kdtrace 159 32K 901
DEVFS3 124 31K 134
umtx 242 31K 242
msg 4 30K 4
gtaskqueue 18 26K 18
kbdmux 6 22K 6
DEVFS_RULE 56 20K 56
BPF 10 18K 10
ufs_mount 4 17K 5
proc 3 17K 3
tty 16 16K 16
ithread 97 16K 97
bus-sc 34 15K 1681
KTRACE 100 13K 100
eventhandler 136 12K 136
kenv 95 12K 95
ifaddr 30 12K 32
rman 88 11K 431
GEOM 61 11K 490
routetbl 50 11K 176
CAM queue 5 11K 1528
bmsafemap 3 9K 42
UART 12 9K 12
devstat 4 9K 4
ksem 1 8K 1
rpc 2 8K 2
shmfd 1 8K 1
pfs_vncache 1 8K 1
cred 31 8K 244
pfs_nodes 20 8K 20
audit_evclass 237 8K 296
taskqueue 63 7K 63
sglist 5 7K 5
CAM DEV 3 6K 510
ufs_dirhash 24 5K 24
UMA 271 5K 271
plimit 17 5K 337
kqueue 47 5K 791
vt 11 5K 11
ifnet 3 5K 3
memdesc 1 4K 1
MCA 32 4K 32
filedesc 1 4K 1
evdev 4 4K 4
acpisem 28 4K 28
hhook 15 4K 17
ether_multi 40 4K 50
lltable 11 4K 11
pf_ifnet 5 3K 6
in6_multi 25 3K 25
terminal 11 3K 11
pwddesc 41 3K 783
session 20 3K 32
uidinfo 3 3K 9
proc-args 65 3K 1730
local_apic 1 2K 1
io_apic 1 2K 1
fpukern_ctx 2 2K 2
ipsec-saq 2 2K 2
lockf 19 2K 29
selfd 27 2K 9090
freefile 13 2K 22
Unitno 27 2K 39
CAM XPT 22 2K 543
msi 12 2K 12
ipsecpolicy 2 2K 2
acpidev 20 2K 20
clone 9 2K 9
softdep 1 1K 1
dirrem 4 1K 28
diradd 8 1K 37
sahead 1 1K 1
secasvar 1 1K 1
vnodemarker 2 1K 10
NFSD session 1 1K 1
CAM periph 4 1K 271
select 7 1K 29
ipsec 3 1K 3
indirdep 3 1K 3
nhops 6 1K 6
toponodes 6 1K 6
isadev 6 1K 6
mount 16 1K 89
pci_link 10 1K 10
sctp_ifa 5 1K 6
crypto 4 1K 4
ip6ndp 4 1K 5
encap_export_host 12 1K 12
newdirblk 4 1K 8
mkdir 4 1K 16
in_multi 2 1K 4
pfil 4 1K 4
cdev 2 1K 2
chacha20random 1 1K 1
osd 7 1K 18
inpcbpolicy 10 1K 139
sctp_ifn 2 1K 6
NFSD lckfile 1 1K 1
NFSD V4client 1 1K 1
DEVFSP 4 1K 9
DEVFS 9 1K 10
mld 2 1K 2
igmp 2 1K 2
vnodes 1 1K 1
CAM SIM 2 1K 2
feeder 7 1K 7
tcpfunc 3 1K 3
CC Mem 3 1K 7
loginclass 3 1K 7
prison 6 1K 6
filedesc_to_leader 3 1K 3
lkpikmalloc 5 1K 6
aesni_data 2 1K 2
cryptodev 2 1K 49
nexusdev 8 1K 8
apmdev 1 1K 1
atkbddev 2 1K 2
CAM dev queue 2 1K 2
CAM I/O Scheduler 1 1K 1
CAM path 4 1K 1034
procdesc 1 1K 6
pmchooks 1 1K 1
soname 4 1K 3473
filecaps 4 1K 66
tun 3 1K 3
sctp_vrf 1 1K 1
vnet 1 1K 1
entropy 2 1K 35
pmc 1 1K 1
acpiintr 1 1K 1
cpus 2 1K 2
vnet_data_free 1 1K 1
Per-cpu 1 1K 1
freework 1 1K 26
p1003.1b 1 1K 1
tcp_do 0 0K 0
tcp_fsb 0 0K 0
sctp_mcore 0 0K 0
sctp_socko 0 0K 0
sctp_iter 0 0K 4
sctp_mvrf 0 0K 0
sctp_timw 0 0K 0
sctp_cpal 0 0K 0
sctp_cmsg 0 0K 0
sctp_stre 0 0K 0
sctp_athi 0 0K 0
sctp_athm 0 0K 0
sctp_atky 0 0K 0
sctp_atcl 0 0K 0
sctp_a_it 0 0K 4
sctp_aadr 0 0K 0
sctp_stro 0 0K 0
sctp_stri 0 0K 0
sctp_map 0 0K 0
mqdata 0 0K 0
filemon 0 0K 0
ipcomp 0 0K 0
esp 0 0K 0
ah 0 0K 0
pf_table 0 0K 0
pf_rule 0 0K 0
pf_altq 0 0K 0
pf_osfp 0 0K 0
pf_temp 0 0K 0
NFSCL layrecall 0 0K 0
NFSCL session 0 0K 0
madt_table 0 0K 2
smartpqi 0 0K 0
NFSCL sockreq 0 0K 0
NFSCL devinfo 0 0K 0
NFSCL flayout 0 0K 0
ixl 0 0K 0
NFSCL layout 0 0K 0
NFSD rollback 0 0K 0
NFSCL diroff 0 0K 0
NEWdirectio 0 0K 0
NEWNFSnode 0 0K 0
NFSCL lck 0 0K 0
NFSCL lckown 0 0K 0
ice-resmgr 0 0K 0
ice-osdep 0 0K 0
ice 0 0K 0
iavf 0 0K 0
axgbe 0 0K 0
NFSCL client 0 0K 0
NFSCL deleg 0 0K 0
NFSCL open 0 0K 0
NFSCL owner 0 0K 0
NFS fh 0 0K 0
NFS req 0 0K 0
NFSD usrgroup 0 0K 0
NFSD string 0 0K 0
NFSD V4lock 0 0K 0
xen_intr 0 0K 0
NFSD V4state 0 0K 0
xen_hvm 0 0K 0
legacydrv 0 0K 0
bounce 0 0K 0
busdma 0 0K 0
qpidrv 0 0K 0
NFSD srvcache 0 0K 0
msdosfs_fat 0 0K 0
dmar_idpgtbl 0 0K 0
dmar_dom 0 0K 0
dmar_ctx 0 0K 0
msdosfs_mount 0 0K 0
msdosfs_node 0 0K 0
isci 0 0K 0
iommu_dmamap 0 0K 0
hyperv_socket 0 0K 0
bxe_ilt 0 0K 0
xenbus 0 0K 0
DEVFS4 0 0K 0
vm_fictitious 0 0K 0
DEVFS2 0 0K 0
gntdev 0 0K 0
privcmd_dev 0 0K 0
evtchn_dev 0 0K 0
xenstore 0 0K 0
scsi_pass 0 0K 0
ciss_data 0 0K 0
xnb 0 0K 0
xen_acpi 0 0K 0
xbbd 0 0K 0
xbd 0 0K 0
UMAHash 0 0K 0
Balloon 0 0K 0
sysmouse 0 0K 0
vm_pgdata 0 0K 0
jblocks 0 0K 0
savedino 0 0K 17
sentinel 0 0K 0
jfsync 0 0K 0
jtrunc 0 0K 0
sbdep 0 0K 3
jsegdep 0 0K 0
jseg 0 0K 0
jfreefrag 0 0K 0
jfreeblk 0 0K 0
jnewblk 0 0K 0
jmvref 0 0K 0
jremref 0 0K 0
jaddref 0 0K 0
freedep 0 0K 0
freeblks 0 0K 25
freefrag 0 0K 1
allocindir 0 0K 0
allocdirect 0 0K 0
ufs_trim 0 0K 0
mactemp 0 0K 0
audit_trigger 0 0K 0
audit_pipe_presel 0 0K 0
audit_pipeent 0 0K 0
audit_pipe 0 0K 0
audit_evname 0 0K 0
audit_bsm 0 0K 0
audit_gidset 0 0K 0
audit_text 0 0K 0
audit_path 0 0K 0
audit_data 0 0K 0
audit_cred 0 0K 0
vtfont 0 0K 0
BACKLIGHT 0 0K 0
ath_hal 0 0K 0
athdev 0 0K 0
ata_pci 0 0K 0
ata_dma 0 0K 0
ata_generic 0 0K 0
pvscsi 0 0K 0
scsi_da 0 0K 69
ata_da 0 0K 0
scsi_ch 0 0K 0
scsi_cd 0 0K 0
ktls_ocf 0 0K 0
AHCI driver 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5E_TLS_RX 0 0K 0
MLX5EEPROM 0 0K 0
MLX5E_TLS 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EN 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5DUMP 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
seq_file 0 0K 0
lkpiskb 0 0K 0
radix 0 0K 0
idr 0 0K 0
lkpindev 0 0K 0
lkpifw 0 0K 0
lkpi80211 0 0K 0
NLM 0 0K 0
ipsec-spdcache 0 0K 0
ipsec-reg 0 0K 0
ipsec-misc 0 0K 0
ipsecrequest 0 0K 0
ip6opt 0 0K 3
ip6_msource 0 0K 0
ip6_moptions 0 0K 0
in6_mfilter 0 0K 0
frag6 0 0K 0
tcplog 0 0K 0
tcp_hwpace 0 0K 0
USBdev 0 0K 0
USB 0 0K 0
LRO 0 0K 0
ip_msource 0 0K 0
ip_moptions 0 0K 0
in_mfilter 0 0K 0
ipid 0 0K 0
80211scan 0 0K 0
80211ratectl 0 0K 0
80211power 0 0K 0
80211nodeie 0 0K 0
80211node 0 0K 0
80211mesh_gt 0 0K 0
80211mesh_rt 0 0K 0
80211perr 0 0K 0
80211prep 0 0K 0
80211preq 0 0K 0
80211dfs 0 0K 0
80211crypto 0 0K 0
80211vap 0 0K 0
iflib 0 0K 0
vlan 0 0K 0
gif 0 0K 0
ifdescr 0 0K 0
zlib 0 0K 0
fadvise 0 0K 0
VN POLL 0 0K 0
agp 0 0K 0
statfs 0 0K 197
namei_tracker 0 0K 0
export_host 0 0K 0
cl_savebuf 0 0K 3
nvme_da 0 0K 0
acpipwr 0 0K 0
acpi_perf 0 0K 0
twsbuf 0 0K 0
twe_commands 0 0K 0
tcp_log_dev 0 0K 0
midi buffers 0 0K 0
mixer 0 0K 0
ac97 0 0K 0
hdacc 0 0K 0
hdac 0 0K 0
hdaa 0 0K 0
acpicmbat 0 0K 0
SIIS driver 0 0K 0
CAM CCB 0 0K 523
biobuf 0 0K 0
aio 0 0K 0
lio 0 0K 0
acl 0 0K 0
mbuf_tag 0 0K 27
ktls 0 0K 0
PUC 0 0K 0
ppbusdev 0 0K 0
agtiapi_MemAlloc malloc 0 0K 0
osti_cacheable 0 0K 0
tempbuff 0 0K 0
tempbuff 0 0K 0
ag_tgt_map_t malloc 0 0K 0
ag_slr_map_t malloc 0 0K 0
lDevFlags * malloc 0 0K 0
tiDeviceHandle_t * malloc 0 0K 0
ag_portal_data_t malloc 0 0K 0
ag_device_t malloc 0 0K 0
STLock malloc 0 0K 0
CCB List 0 0K 0
sr_iov 0 0K 0
OCS 0 0K 0
OCS 0 0K 0
nvme 0 0K 0
nvd 0 0K 0
netmap 0 0K 0
mwldev 0 0K 0
MVS driver 0 0K 0
CAM ccb queue 0 0K 0
accf 0 0K 0
pts 0 0K 0
iov 0 0K 13515
ioctlops 0 0K 86
eventfd 0 0K 0
Witness 0 0K 0
stack 0 0K 0
mrsasbuf 0 0K 0
mpt_user 0 0K 0
mps_user 0 0K 0
MPSSAS 0 0K 0
mps 0 0K 0
sbuf 0 0K 294
mpr_user 0 0K 0
firmware 0 0K 0
compressor 0 0K 0
MPRSAS 0 0K 0
SWAP 0 0K 0
mpr 0 0K 0
mfibuf 0 0K 0
sysctltmp 0 0K 659
sysctl 0 0K 3
md_sectors 0 0K 0
ekcd 0 0K 0
dumper 0 0K 0
sendfile 0 0K 0
rctl 0 0K 0
md_disk 0 0K 0
malodev 0 0K 0
LED 0 0K 0
ix_sriov 0 0K 0
cache 0 0K 0
aacraidcam 0 0K 0
kcovinfo 0 0K 0
prison_racct 0 0K 0
Fail Points 0 0K 0
sigio 0 0K 1
pwd 0 0K 0
tty console 0 0K 0
ix 0 0K 0
ipsbuf 0 0K 0
aacraid_buf 0 0K 0
aaccam 0 0K 0
boottrace 0 0K 0
aacbuf 0 0K 0
zstd 0 0K 0
XZ_DEC 0 0K 0
nvlist 0 0K 0
SCSI ENC 0 0K 0
SCSI sa 0 0K 0
isofs_node 0 0K 0
isofs_mount 0 0K 0
tr_raid5_data 0 0K 0
tr_raid1e_data 0 0K 0
tr_raid1_data 0 0K 0
tr_raid0_data 0 0K 0
tr_concat_data 0 0K 0
md_sii_data 0 0K 0
md_promise_data 0 0K 0
md_nvidia_data 0 0K 0
md_jmicron_data 0 0K 0
md_intel_data 0 0K 0
md_ddf_data 0 0K 0
raid_data 0 0K 72
geom_flashmap 0 0K 0
tmpfs dir 0 0K 0
tmpfs name 0 0K 0
tmpfs mount 0 0K 0
NFS FHA 0 0K 0
newnfsmnt 0 0K 0
newnfsclient_req 0 0K 0
db> show uma
Zone Size Used Free Requests Sleeps Bucket Total Mem XFree
mbuf_jumbo_page 4096 8320 1078 13424 0 254 38494208 0
mbuf 256 8577 1084 15927 0 254 2473216 0
pbuf 2624 0 794 0 0 2 2083456 0
BUF TRIE 144 170 11590 452 0 62 1693440 0
malloc-384 384 4174 56 4220 0 30 1624320 0
malloc-128 128 12364 253 12677 0 126 1614976 0
malloc-4096 4096 340 2 513 0 2 1400832 0
UMA Slabs 0 112 10430 4 10430 0 126 1168608 0
vmem btag 56 16095 72 16095 0 254 905352 0
FFS inode 1160 490 35 513 0 8 609000 0
tcpcb 1104 3 508 7 0 254 564144 0
mbuf_cluster 2048 254 0 254 0 254 520192 0
RADIX NODE 144 3243 196 19941 0 62 495216 0
socket 960 18 490 1336 0 254 487680 0
malloc-65536 65536 2 5 138 0 1 458752 0
VM OBJECT 264 1427 73 24524 0 30 396000 0
malloc-65536 65536 4 2 50 0 1 393216 0
lkpimm 168 1 2327 1 0 62 391104 0
lkpicurr 168 2 2326 2 0 62 391104 0
256 Bucket 2048 119 19 984 0 8 282624 0
malloc-64 64 3871 224 12948 0 254 262080 0
VNODE 448 520 56 545 0 30 258048 0
malloc-16 16 14570 180 14642 0 254 236000 0
DEVCTL 1024 0 220 126 0 0 225280 0
THREAD 1808 115 6 115 0 8 218768 0
malloc-65536 65536 2 1 10 0 1 196608 0
malloc-4096 4096 46 2 871 0 2 196608 0
malloc-128 128 1296 223 27046 0 126 194432 0
MAP ENTRY 96 1583 433 84526 0 126 193536 0
UMA Zones 768 243 1 243 0 16 187392 0
malloc-32 32 5335 335 6407 0 254 181440 0
malloc-256 256 598 92 1539 0 62 176640 0
FFS2 dinode 256 490 80 512 0 62 145920 0
S VFS Cache 104 970 317 1012 0 126 133848 0
malloc-1024 1024 116 12 282 0 16 131072 0
unpcb 256 7 503 1180 0 254 130560 0
FPU_save_area 832 117 27 131 0 16 119808 0
ksiginfo 112 38 1006 55 0 126 116928 0
malloc-32768 32768 1 2 121 0 1 98304 0
malloc-8192 8192 11 1 13 0 1 98304 0
UMA Kegs 384 229 4 229 0 30 89472 0
128 Bucket 1024 43 40 474 0 16 84992 0
malloc-64 64 919 404 2906 0 254 84672 0
VMSPACE 2552 24 9 767 0 4 84216 0
malloc-128 128 393 258 4419 0 126 83328 0
malloc-16384 16384 5 0 20 0 1 81920 0
malloc-2048 2048 5 35 512 0 8 81920 0
malloc-256 256 262 53 825 0 62 80640 0
PROC 1352 42 15 784 0 8 77064 0
g_bio 408 0 180 4645 0 30 73440 0
malloc-64 64 569 502 2405 0 254 68544 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-16384 16384 1 3 161 0 1 65536 0
malloc-8192 8192 5 3 106 0 1 65536 0
mbuf_packet 256 0 254 81 0 254 65024 0
filedesc0 1072 41 15 783 0 8 60032 0
64 Bucket 512 62 42 1619 0 30 53248 0
malloc-256 256 139 56 286 0 62 49920 0
malloc-256 256 55 140 408 0 62 49920 0
32 Bucket 256 61 134 1414 0 62 49920 0
DIRHASH 1024 35 13 35 0 16 49152 0
NAMEI 1024 0 48 12271 0 16 49152 0
malloc-8192 8192 3 3 31 0 1 49152 0
malloc-4096 4096 9 3 552 0 2 49152 0
malloc-2048 2048 12 12 39 0 8 49152 0
malloc-2048 2048 2 22 534 0 8 49152 0
malloc-1024 1024 4 44 512 0 16 49152 0
malloc-384 384 83 37 83 0 30 46080 0
syncache 168 0 264 5 0 254 44352 0
clpbuf 2624 0 16 20 0 16 41984 0
Mountpoints 2752 2 12 2 0 4 38528 0
udp_inpcb 424 6 84 128 0 30 38160 0
pcpu-8 8 4220 388 4248 0 254 36864 0
malloc-64 64 8 559 13215 0 254 36288 0
malloc-64 64 56 511 56 0 254 36288 0
malloc-64 64 26 541 58 0 254 36288 0
malloc-64 64 2 565 525 0 254 36288 0
malloc-64 64 0 567 16 0 254 36288 0
malloc-128 128 35 244 112 0 126 35712 0
malloc-128 128 44 235 61 0 126 35712 0
malloc-128 128 30 249 81 0 126 35712 0
malloc-128 128 89 190 436 0 126 35712 0
malloc-128 128 4 275 4 0 126 35712 0
routing nhops 256 10 125 17 0 62 34560 0
ttyoutq 256 72 63 160 0 62 34560 0
malloc-384 384 59 31 399 0 30 34560 0
malloc-256 256 35 100 494 0 62 34560 0
malloc-256 256 3 132 59 0 62 34560 0
malloc-256 256 3 132 55 0 62 34560 0
malloc-256 256 9 126 82 0 62 34560 0
malloc-32768 32768 1 0 1 0 1 32768 0
malloc-32768 32768 1 0 1 0 1 32768 0
malloc-8192 8192 4 0 4 0 1 32768 0
malloc-2048 2048 1 15 13 0 8 32768 0
malloc-2048 2048 1 15 3 0 8 32768 0
malloc-2048 2048 8 8 249 0 8 32768 0
malloc-1024 1024 3 29 43 0 16 32768 0
malloc-1024 1024 15 17 899 0 16 32768 0
malloc-1024 1024 20 12 36 0 16 32768 0
malloc-1024 1024 10 22 14 0 16 32768 0
malloc-1024 1024 2 30 6 0 16 32768 0
malloc-512 512 6 58 24 0 30 32768 0
malloc-512 512 8 56 9 0 30 32768 0
malloc-512 512 2 62 51 0 30 32768 0
malloc-512 512 3 61 3 0 30 32768 0
pcpu-64 64 493 19 493 0 254 32768 0
ttyinq 160 135 65 300 0 62 32000 0
cpuset 104 7 272 7 0 126 29016 0
sctp_laddr 48 0 588 4 0 254 28224 0
malloc-32 32 383 499 1313 0 254 28224 0
16 Bucket 144 41 155 223 0 62 28224 0
4 Bucket 48 6 582 47 0 254 28224 0
tcp_inpcb 424 3 60 7 0 30 26712 0
da_ccb 544 0 49 1275 0 16 26656 0
pipe 744 7 28 286 0 16 26040 0
TURNSTILE 136 122 67 122 0 62 25704 0
malloc-8192 8192 3 0 3 0 1 24576 0
malloc-4096 4096 6 0 6 0 2 24576 0
rtentry 176 13 125 17 0 62 24288 0
PGRP 88 20 256 32 0 126 24288 0
rl_entry 40 30 576 30 0 254 24240 0
Files 80 74 226 6610 0 126 24000 0
8 Bucket 80 38 262 225 0 126 24000 0
malloc-384 384 7 53 9 0 30 23040 0
malloc-384 384 3 57 13 0 30 23040 0
malloc-384 384 0 60 19 0 30 23040 0
SLEEPQUEUE 88 122 134 122 0 126 22528 0
hostcache 64 1 314 1 0 254 20160 0
udpcb 32 6 624 128 0 254 20160 0
udp_inpcb ports 32 3 627 40 0 254 20160 0
ertt 72 3 277 7 0 126 20160 0
PWD 32 10 620 102 0 254 20160 0
malloc-32 32 75 555 87 0 254 20160 0
malloc-32 32 33 597 2867 0 254 20160 0
malloc-32 32 46 584 175 0 254 20160 0
malloc-32 32 41 589 622 0 254 20160 0
malloc-32 32 3 627 47 0 254 20160 0
2 Bucket 32 45 585 304 0 254 20160 0
epoch_record pcpu 256 4 60 4 0 62 16384 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-4096 4096 0 4 197 0 2 16384 0
malloc-4096 4096 3 1 4 0 2 16384 0
malloc-2048 2048 2 6 2 0 8 16384 0
malloc-512 512 1 31 119 0 30 16384 0
malloc-512 512 0 32 1 0 30 16384 0
SMR CPU 32 7 504 7 0 254 16352 0
malloc-16 16 526 474 4918 0 254 16000 0
kenv 258 15 45 1037 0 30 15480 0
ripcb 424 1 35 4 0 30 15264 0
mqnode 416 3 33 3 0 30 14976 0
vmem 1856 1 7 1 0 8 14848 0
SMR SHARED 24 7 504 7 0 254 12264 0
ertt_txseginfo 40 0 303 212 0 254 12120 0
tcp_inpcb ports 32 1 377 1 0 254 12096 0
malloc-32 32 11 367 44 0 254 12096 0
KNOTE 160 2 73 10 0 62 12000 0
malloc-16 16 11 739 74 0 254 12000 0
malloc-16 16 33 717 26364 0 254 12000 0
malloc-16 16 7 743 9 0 254 12000 0
malloc-16 16 23 727 28 0 254 12000 0
malloc-16 16 1 749 6 0 254 12000 0
malloc-384 384 0 30 1 0 30 11520 0
malloc-4096 4096 0 2 2 0 2 8192 0
malloc-4096 4096 0 2 3 0 2 8192 0
pcpu-16 16 14 498 14 0 254 8192 0
vtnet_tx_hdr 24 0 334 1630 0 254 8016 0
malloc-16 16 23 477 24 0 254 8000 0
UMA Slabs 1 176 9 13 9 0 62 3872 0
KMAP ENTRY 96 12 27 14 0 0 3744 0
pcpu-4 4 1 511 1 0 254 2048 0
FFS1 dinode 128 0 0 0 0 126 0 0
ada_ccb 272 0 0 0 0 30 0 0
swblk 136 0 0 0 0 62 0 0
swpctrie 144 0 0 0 0 62 0 0
cdg_qdiffsample 16 0 0 0 0 254 0 0
pf state scrubs 40 0 0 0 0 254 0 0
pf frag entries 40 0 0 0 0 254 0 0
pf frags 248 0 0 0 0 62 0 0
pf table entries 160 0 0 0 0 254 0 0
pf table entry counters 64 0 0 0 0 254 0 0
pf source nodes 136 0 0 0 0 254 0 0
pf state keys 88 0 0 0 0 126 0 0
pf states 312 0 0 0 0 254 0 0
pf tags 104 0 0 0 0 126 0 0
pf mtags 184 0 0 0 0 62 0 0
tcp_rack_pcb 896 0 0 0 0 16 0 0
tcp_rack_map 120 0 0 0 0 126 0 0
tcp_bbr_pcb 832 0 0 0 0 16 0 0
tcp_bbr_map 128 0 0 0 0 126 0 0
ipq 56 0 0 0 0 254 0 0
tfo_ccache_entries 80 0 0 0 0 126 0 0
tfo 4 0 0 0 0 254 0 0
sackhole 32 0 0 0 0 254 0 0
tcptw 72 0 0 0 0 254 0 0
sctp_asconf_ack 48 0 0 0 0 254 0 0
sctp_asconf 40 0 0 0 0 254 0 0
sctp_stream_msg_out 112 0 0 0 0 254 0 0
sctp_readq 152 0 0 0 0 254 0 0
sctp_chunk 152 0 0 0 0 254 0 0
sctp_raddr 736 0 0 0 0 254 0 0
sctp_asoc 2256 0 0 0 0 254 0 0
sctp_ep 1208 0 0 0 0 254 0 0
tcp_log_id_node 120 0 0 0 0 126 0 0
tcp_log_id_bucket 176 0 0 0 0 62 0 0
tcp_log 416 0 0 0 0 254 0 0
tcpreass 48 0 0 0 0 254 0 0
udplite_inpcb ports 32 0 0 0 0 254 0 0
udplite_inpcb 424 0 0 0 0 30 0 0
ripcb ports 32 0 0 0 0 254 0 0
IPsec SA lft_c 16 0 0 0 0 254 0 0
itimer 352 0 0 0 0 30 0 0
AIOLIO 272 0 0 0 0 30 0 0
AIOCB 552 0 0 0 0 16 0 0
AIO 208 0 0 0 0 62 0 0
NCLNODE 608 0 0 0 0 16 0 0
mqnotifier 216 0 0 0 0 62 0 0
mvdata 64 0 0 0 0 254 0 0
mqueue 248 0 0 0 0 62 0 0
TMPFS node 224 0 0 0 0 62 0 0
LTS VFS Cache 360 0 0 0 0 30 0 0
L VFS Cache 320 0 0 0 0 30 0 0
STS VFS Cache 144 0 0 0 0 62 0 0
cryptop 280 0 0 0 0 30 0 0
linux_dma_object 32 0 0 0 0 254 0 0
linux_dma_pctrie 144 0 0 0 0 62 0 0
IOMMU_MAP_ENTRY 120 0 0 0 0 126 0 0
mbuf_jumbo_16k 16384 0 0 0 0 254 0 0
mbuf_jumbo_9k 9216 0 0 0 0 254 0 0
audit_record 1280 0 0 0 0 8 0 0
domainset 40 0 0 0 0 254 0 0
MAC labels 40 0 0 0 0 254 0 0
vnpbuf 2624 0 0 0 0 64 0 0
mdpbuf 2624 0 0 0 0 3 0 0
nfspbuf 2624 0 0 0 0 16 0 0
swwbuf 2624 0 0 0 0 8 0 0
swrbuf 2624 0 0 0 0 16 0 0
umtx_shm 88 0 0 0 0 126 0 0
umtx pi 96 0 0 0 0 126 0 0
rangeset pctrie nodes 144 0 0 0 0 62 0 0
malloc-65536 65536 0 0 0 0 1 0 0
malloc-65536 65536 0 0 0 0 1 0 0
malloc-65536 65536 0 0 0 0 1 0 0
malloc-65536 65536 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-16384 16384 0 0 0 0 1 0 0
malloc-16384 16384 0 0 0 0 1 0 0
malloc-16384 16384 0 0 0 0 1 0 0
malloc-16384 16384 0 0 0 0 1 0 0
malloc-16384 16384 0 0 0 0 1 0 0
malloc-8192 8192 0 0 0 0 1 0 0
malloc-8192 8192 0 0 0 0 1 0 0
malloc-8192 8192 0 0 0 0 1 0 0
malloc-2048 2048 0 0 0 0 8 0 0
malloc-1024 1024 0 0 0 0 16 0 0
malloc-512 512 0 0 0 0 30 0 0
malloc-512 512 0 0 0 0 30 0 0
malloc-384 384 0 0 0 0 30 0 0
pcpu-32 32 0 0 0 0 254 0 0
fakepg 104 0 0 0 0 126 0 0
UMA Hash 256 0 0 0 0 62 0 0


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this issue, for details see:
https://goo.gl/tpsmEJ#testing-patches
Reply all
Reply to author
Forward
0 new messages