panic: Most recently used by in6_mfilter

5 views
Skip to first unread message

syzbot

unread,
May 7, 2021, 3:28:18 AM5/7/21
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: fb53b42e virtio-modern: fix PCI common read/write function..
git tree: https://github.com/freebsd/freebsd-src.git main
console output: https://syzkaller.appspot.com/x/log.txt?x=1045ad69d00000
dashboard link: https://syzkaller.appspot.com/bug?extid=1840bd9f7f1cd756ac6a

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+1840bd...@syzkaller.appspotmail.com

panic: Most recently used by in6_mfilter

cpuid = 1
time = 1620372449
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame 0xfffffe005175d490
vpanic() at vpanic+0x1c7/frame 0xfffffe005175d4f0
panic() at panic+0x43/frame 0xfffffe005175d550
mtrash_ctor() at mtrash_ctor+0xe5/frame 0xfffffe005175d590
item_ctor() at item_ctor+0x46f/frame 0xfffffe005175d5f0
malloc() at malloc+0xe3/frame 0xfffffe005175d650
crypto_open() at crypto_open+0x22/frame 0xfffffe005175d670
devfs_open() at devfs_open+0x1b1/frame 0xfffffe005175d6e0
VOP_OPEN_APV() at VOP_OPEN_APV+0x75/frame 0xfffffe005175d710
vn_open_vnode() at vn_open_vnode+0x379/frame 0xfffffe005175d7c0
vn_open_cred() at vn_open_cred+0x7d9/frame 0xfffffe005175d940
kern_openat() at kern_openat+0x3bd/frame 0xfffffe005175dab0
amd64_syscall() at amd64_syscall+0x247/frame 0xfffffe005175dbf0
fast_syscall_common() at fast_syscall_common+0xf8/frame 0xfffffe005175dbf0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x285e1a, rsp = 0x7fffdfffdf08, rbp = 0x7fffdfffdf70 ---
KDB: enter: panic
[ thread pid 7479 tid 114452 ]
Stopped at kdb_enter+0x67: movq $0,0x163a54e(%rip)
db>
db> set $lines = 0
db> set $maxwidth = 0
db> show registers
cs 0x20
ds 0x3b
es 0x3b
fs 0x13
gs 0x1b
ss 0x28
rax 0x12
rcx 0xfffffe0095a00000
rdx 0x3ffff
rbx 0
rsp 0xfffffe005175d470
rbp 0xfffffe005175d490
rsi 0x40001
rdi 0xffffffff81137c46 vprintf+0x176
r8 0
r9 0x8080808080808080
r10 0xfffffe005175d360
r11 0x1ffaefff59c
r12 0xffffffff82267ac0 ddb_dbbe
r13 0
r14 0xffffffff81a73d13
r15 0xffffffff81a73d13
rip 0xffffffff8112ec37 kdb_enter+0x67
rflags 0x82
kdb_enter+0x67: movq $0,0x163a54e(%rip)
db> show proc
Process 7479 (syz-executor.1) at 0xfffff8002f839538:
state: NORMAL
uid: 0 gids: 0, 0, 5
parent: pid 784 at 0xfffff800240e0a70
ABI: FreeBSD ELF64
flag: 0x10000080 flag2: 0
arguments: /root/syz-executor.1
reaper: 0xfffff8000452a538 reapsubtree: 1
sigparent: 20
vmspace: 0xfffffe009512c000
(map 0xfffffe009512c000)
(map.pmap 0xfffffe009512c0c0)
(pmap 0xfffffe009512c120)
threads: 2
113193 Run CPU 0 syz-executor.1
114452 Run CPU 1 syz-executor.1
db> ps
pid ppid pgrp uid state wmesg wchan cmd
7479 784 784 0 R (threaded) syz-executor.1
113193 Run CPU 0 syz-executor.1
114452 Run CPU 1 syz-executor.1
7477 783 783 0 S (threaded) syz-executor.0
114189 S nanslp 0xffffffff8273c8e0 syz-executor.0
114443 S connec 0xfffff80042e22bf0 syz-executor.0
114445 S uwait 0xfffff80027fd2180 syz-executor.0
7475 821 821 0 S (threaded) syz-executor.3
114166 S nanslp 0xffffffff8273c8e0 syz-executor.3
114441 S select 0xfffff80042da1bc0 syz-executor.3
114444 S sbwait 0xfffff80042ea3574 syz-executor.3
114446 S uwait 0xfffff8003d04f200 syz-executor.3
114448 S uwait 0xfffff80042d42600 syz-executor.3
114450 S uwait 0xfffff80027fd2980 syz-executor.3
114451 S uwait 0xfffff80042530d00 syz-executor.3
7474 786 786 0 S (threaded) syz-executor.2
114322 S nanslp 0xffffffff8273c8e0 syz-executor.2
114439 S connec 0xfffff80027cd4490 syz-executor.2
114440 S uwait 0xfffff8003d04f380 syz-executor.2
7234 1 783 0 S uwait 0xfffff80027f72480 syz-executor.0
7233 1 783 0 S uwait 0xfffff80027fd2580 syz-executor.0
7099 1 783 0 S uwait 0xfffff8003d04fa00 syz-executor.0
7098 1 7098 0 S uwait 0xfffff8003d04fd00 syz-executor.0
6842 1 786 0 S uwait 0xfffff80042d42500 syz-executor.2
6841 1 786 0 S uwait 0xfffff80004cfc680 syz-executor.2
6840 1 786 0 S uwait 0xfffff8002759b580 syz-executor.2
6839 1 786 0 S uwait 0xfffff80042d42a00 syz-executor.2
6772 1 783 0 S uwait 0xfffff80027f72000 syz-executor.0
6770 1 783 0 S uwait 0xfffff80027fd2780 syz-executor.0
6768 1 783 0 S uwait 0xfffff8002759b780 syz-executor.0
6766 1 783 0 S uwait 0xfffff8003d04f300 syz-executor.0
6764 1 783 0 S uwait 0xfffff80042d42b00 syz-executor.0
6511 1 821 0 S uwait 0xfffff80027f72a80 syz-executor.3
6510 1 821 0 S uwait 0xfffff80027fd2380 syz-executor.3
6490 1 784 0 S uwait 0xfffff80027f2ce00 syz-executor.1
6484 1 784 0 S uwait 0xfffff80004f5e180 syz-executor.1
6482 1 786 0 S uwait 0xfffff8002759b080 syz-executor.2
6479 1 786 0 S uwait 0xfffff8002759b480 syz-executor.2
6474 1 784 0 S umtxn 0xfffff80027f2c800 syz-executor.1
6472 1 786 0 S uwait 0xfffff80027f72880 syz-executor.2
6469 1 786 0 S uwait 0xfffff80004cfc580 syz-executor.2
6463 1 786 0 S uwait 0xfffff8002759b980 syz-executor.2
6460 1 786 0 S uwait 0xfffff8003d04f900 syz-executor.2
6456 1 786 0 S uwait 0xfffff8002759bb80 syz-executor.2
6454 1 786 0 S uwait 0xfffff80027fd2680 syz-executor.2
5295 1 821 0 S uwait 0xfffff80004cfc480 syz-executor.3
5285 1 821 0 S uwait 0xfffff80004fc0080 syz-executor.3
5282 1 786 0 S umtxn 0xfffff80027f72780 syz-executor.2
5281 1 821 0 S uwait 0xfffff8003d04fe00 syz-executor.3
5276 1 786 0 S uwait 0xfffff80027f2cc00 syz-executor.2
5274 1 786 0 S uwait 0xfffff8003d04f600 syz-executor.2
5266 1 5264 0 S uwait 0xfffff80027f2c500 syz-executor.2
5265 1 786 0 S uwait 0xfffff80027f2c600 syz-executor.2
4545 4544 821 0 SV uwait 0xfffff80027f72580 syz-executor.3
4544 1 821 0 DV ppwait 0xfffff80027fd34e8 syz-executor.3
3982 1 821 0 S uwait 0xfffff80027f72e80 syz-executor.3
3977 1 821 0 S uwait 0xfffff80027f2c900 syz-executor.3
3973 1 821 0 S uwait 0xfffff8002759b380 syz-executor.3
3968 1 821 0 S uwait 0xfffff800240bf080 syz-executor.3
3964 1 821 0 S uwait 0xfffff80027f72d80 syz-executor.3
3415 1 3415 65 Ss select 0xfffff8003d04f440 dhclient
2878 1 786 0 S uwait 0xfffff800240bf180 syz-executor.2
2869 1 786 0 S uwait 0xfffff800240bff00 syz-executor.2
2860 1 786 0 S uwait 0xfffff80004f5e380 syz-executor.2
2855 1 2855 0 Ss select 0xfffff8003d04f4c0 dhclient
2852 1 2852 0 Ss select 0xfffff80027fd2ac0 dhclient
2833 1 2833 65 Ss select 0xfffff8003d04f040 dhclient
2828 1 786 0 S uwait 0xfffff80004cfc780 syz-executor.2
2820 1 786 0 S uwait 0xfffff8003d04ff00 syz-executor.2
2208 1 2208 0 Ss select 0xfffff8003d04f1c0 dhclient
2205 1 2205 0 Ss select 0xfffff80027fd2f40 dhclient
2191 1 2191 65 Ss select 0xfffff8003d04f140 dhclient
1512 1 1512 0 Ss select 0xfffff80027f721c0 dhclient
1509 1 1509 0 Ss select 0xfffff80027f720c0 dhclient
1485 1 1485 65 Ss select 0xfffff80027f72240 dhclient
835 1 835 0 Ss select 0xfffff80004f5e540 dhclient
829 1 829 0 Ss select 0xfffff8002759bc40 dhclient
821 780 821 0 Ss nanslp 0xffffffff8273c8e0 syz-executor.3
786 780 786 0 Ss nanslp 0xffffffff8273c8e1 syz-executor.2
784 780 784 0 Rs syz-executor.1
783 780 783 0 Ss nanslp 0xffffffff8273c8e0 syz-executor.0
780 778 778 0 S (threaded) syz-fuzzer
100097 S uwait 0xfffff800049dd080 syz-fuzzer
100118 S uwait 0xfffff800240bf580 syz-fuzzer
100119 S uwait 0xfffff800240bf680 syz-fuzzer
100120 S uwait 0xfffff800240bf780 syz-fuzzer
100121 S uwait 0xfffff800240bf880 syz-fuzzer
100122 S uwait 0xfffff80004cfc180 syz-fuzzer
100123 S uwait 0xfffff800049dd300 syz-fuzzer
100124 S kqread 0xfffff80027597500 syz-fuzzer
100578 S uwait 0xfffff8002759b280 syz-fuzzer
778 776 778 0 Ss pause 0xfffff80004e8d0b0 csh
776 694 776 0 Ss select 0xfffff8002759bdc0 sshd
760 1 760 0 Ss+ ttyin 0xfffff800049d7cb0 getty
759 1 759 0 Ss+ ttyin 0xfffff80004ced8b0 getty
758 1 758 0 Ss+ ttyin 0xfffff80004cedcb0 getty
757 1 757 0 Ss+ ttyin 0xfffff80004cf40b0 getty
756 1 756 0 Ss+ ttyin 0xfffff80004cf44b0 getty
755 1 755 0 Ss+ ttyin 0xfffff80004cf48b0 getty
754 1 754 0 Ss+ ttyin 0xfffff80004cf4cb0 getty
753 1 753 0 Ss+ ttyin 0xfffff80004c6e0b0 getty
752 1 752 0 Ss+ ttyin 0xfffff80004c6e4b0 getty
698 1 698 0 Ss nanslp 0xffffffff8273c8e1 cron
694 1 694 0 Ss select 0xfffff80004f5e8c0 sshd
507 1 507 0 Ss select 0xfffff800240bfc40 syslogd
436 1 436 0 Ss select 0xfffff800240bfac0 devd
435 1 435 65 Ss select 0xfffff80004f5eac0 dhclient
350 1 350 0 Ss select 0xfffff800240bf9c0 dhclient
347 1 347 0 Ss select 0xfffff800240bfcc0 dhclient
23 0 0 0 DL syncer 0xffffffff8282bd50 [syncer]
22 0 0 0 DL vlruwt 0xfffff80004e8da70 [vnlru]
21 0 0 0 DL (threaded) [bufdaemon]
100081 D qsleep 0xffffffff8282ae00 [bufdaemon]
100088 D - 0xffffffff8220ae00 [bufspacedaemon-0]
100099 D sdflush 0xfffff80004fcece8 [/ worker]
20 0 0 0 DL psleep 0xffffffff82852c08 [vmdaemon]
19 0 0 0 DL (threaded) [pagedaemon]
100079 D psleep 0xffffffff82847078 [dom0]
100086 D launds 0xffffffff82847084 [laundry: dom0]
100087 D umarcl 0xffffffff815c9360 [uma]
18 0 0 0 DL - 0xffffffff82570c78 [rand_harvestq]
17 0 0 0 DL waiting 0xffffffff82fe6828 [sctp_iterator]
16 0 0 0 DL pftm 0xffffffff82dab3c0 [pf purge]
15 0 0 0 DL - 0xffffffff8282845c [soaiod4]
9 0 0 0 DL - 0xffffffff8282845c [soaiod3]
8 0 0 0 DL - 0xffffffff8282845c [soaiod2]
7 0 0 0 DL - 0xffffffff8282845c [soaiod1]
6 0 0 0 DL (threaded) [cam]
100044 D - 0xffffffff82448140 [doneq0]
100045 D - 0xffffffff824480c0 [async]
100078 D - 0xffffffff82447f90 [scanner]
14 0 0 0 DL seqstat 0xfffff8000463c888 [sequencer 00]
5 0 0 0 DL crypto_ 0xfffff8000462ed80 [crypto returns 1]
4 0 0 0 DL crypto_ 0xfffff8000462ed30 [crypto returns 0]
3 0 0 0 DL crypto_ 0xffffffff828445a0 [crypto]
13 0 0 0 DL (threaded) [geom]
100035 D - 0xffffffff8271c120 [g_event]
100036 D - 0xffffffff8271c128 [g_up]
100037 D - 0xffffffff8271c130 [g_down]
2 0 0 0 DL (threaded) [KTLS]
100028 D - 0xfffff80004574600 [thr_0]
100029 D - 0xfffff80004574680 [thr_1]
12 0 0 0 WL (threaded) [intr]
100011 I [swi6: task queue]
100013 I [swi6: Giant taskq]
100018 I [swi5: fast taskq]
100030 I [swi4: clock (0)]
100031 I [swi4: clock (1)]
100032 I [swi1: netisr 0]
100033 I [swi3: vm]
100046 I [irq24: virtio_pci0]
100047 I [irq25: virtio_pci0]
100048 I [irq26: virtio_pci0]
100049 I [irq27: virtio_pci0]
100050 I [irq28: virtio_pci1]
100051 I [irq29: virtio_pci1]
100052 I [irq30: virtio_pci1]
100053 I [irq31: virtio_pci1]
100054 I [irq32: virtio_pci1]
100059 I [irq10: virtio_pci2]
100061 I [irq1: atkbd0]
100062 I [irq12: psm0]
100063 I [swi0: uart uart++]
100071 I [swi1: pf send]
100084 I [swi1: hpts]
100085 I [swi1: hpts]
11 0 0 0 RL (threaded) [idle]
100003 CanRun [idle: cpu0]
100004 CanRun [idle: cpu1]
1 0 1 0 SLs wait 0xfffff8000452a538 [init]
10 0 0 0 DL audit_w 0xffffffff82844ab0 [audit]
0 0 0 0 DLs (threaded) [kernel]
100000 D swapin 0xffffffff8271c6b0 [swapper]
100005 D - 0xfffff80004144800 [if_config_tqg_0]
100006 D - 0xfffff80004144700 [softirq_0]
100007 D - 0xfffff80004144600 [softirq_1]
100008 D - 0xfffff80004144500 [if_io_tqg_0]
100009 D - 0xfffff80004144400 [if_io_tqg_1]
100010 D - 0xfffff8000457a600 [pci_hp taskq]
100012 D - 0xfffff8000457a300 [inm_free taskq]
100014 D - 0xfffff8000457a000 [linuxkpi_irq_wq]
100015 D - 0xfffff80004574e00 [thread taskq]
100016 D - 0xfffff80004574d00 [in6m_free taskq]
100017 D - 0xfffff80004574c00 [aiod_kick taskq]
100019 D - 0xfffff80004574900 [kqueue_ctx taskq]
100020 D - 0xfffff80004574800 [linuxkpi_short_wq_0]
100021 D - 0xfffff80004574800 [linuxkpi_short_wq_1]
100022 D - 0xfffff80004574800 [linuxkpi_short_wq_2]
100023 D - 0xfffff80004574800 [linuxkpi_short_wq_3]
100024 D - 0xfffff80004574700 [linuxkpi_long_wq_0]
100025 D - 0xfffff80004574700 [linuxkpi_long_wq_1]
100026 D - 0xfffff80004574700 [linuxkpi_long_wq_2]
100027 D - 0xfffff80004574700 [linuxkpi_long_wq_3]
100034 D - 0xfffff80004574000 [firmware taskq]
100038 D - 0xfffff800045c1d00 [crypto_0]
100039 D - 0xfffff800045c1d00 [crypto_1]
100055 D - 0xfffff800045c1700 [vtnet0 rxq 0]
100056 D - 0xfffff800045c1600 [vtnet0 txq 0]
100057 D - 0xfffff800045c1500 [vtnet0 rxq 1]
100058 D - 0xfffff800045c1400 [vtnet0 txq 1]
100060 D vtbslp 0xfffff80004972100 [virtio_balloon]
100064 D - 0xfffff80004973a00 [mca taskq]
100066 D - 0xffffffff81e206a0 [deadlkres]
100073 D - 0xfffff80004c3b700 [acpi_task_0]
100074 D - 0xfffff80004c3b700 [acpi_task_1]
100075 D - 0xfffff80004c3b700 [acpi_task_2]
100077 D - 0xfffff800045c1c00 [CAM taskq]
db> show all locks
Process 7479 (syz-executor.1) thread 0xfffffe0094e16000 (113193)
exclusive sleep mutex umtxql (umtxql) r = 0 (0xffffffff8275f500) locked @ /syzkaller/managers/main/kernel/sys/kern/kern_umtx.c:511
db> show malloc
Type InUse MemUse Requests
sctp_stro 202 90294K 3739
pf_hash 5 11524K 5
devbuf 4216 4340K 4244
tcp_hpts 5 3201K 5
sysctloid 33718 1992K 33785
vtbuf 24 1968K 46
kobj 332 1328K 492
newblk 40 1034K 15259
vfscache 3 1025K 3
pcb 471 1025K 16450
filedesc 108 858K 13109
inodedep 98 549K 7317
ufs_quota 1 512K 1
vfs_hash 1 512K 1
callout 2 512K 2
subproc 233 483K 7609
intr 4 472K 4
acpica 1674 184K 55406
vnet_data 1 168K 1
sctp_atcl 441 166K 12058
tidhash 3 141K 3
pagedep 11 131K 6725
tfo_ccache 1 128K 1
DEVFS1 107 107K 124
sem 4 106K 4
linker 294 102K 330
BPF 46 88K 46
bus 995 81K 3509
mtx_pool 2 72K 2
syncache 1 68K 1
acpitask 1 64K 1
ddb_capture 1 64K 1
module 508 64K 508
kdtrace 316 59K 21933
umtx 462 58K 462
temp 35 33K 2747
hostcache 1 32K 1
shm 1 32K 18
DEVFS3 126 32K 136
sctp_atky 671 31K 16451
msg 4 30K 4
vmem 3 26K 4
gtaskqueue 18 26K 18
dirrem 88 22K 6882
kbdmux 6 22K 6
ifaddr 70 20K 72
DEVFS_RULE 56 20K 56
ufs_mount 5 17K 6
proc 3 17K 3
routetbl 131 17K 689
tty 16 16K 16
ithread 99 16K 99
lltable 49 16K 221
sctp_timw 60 15K 60
bus-sc 33 14K 1719
KTRACE 100 13K 100
ifnet 7 13K 7
ether_multi 152 13K 162
kenv 93 12K 93
eventhandler 133 12K 133
freefile 87 11K 6844
rman 84 10K 425
GEOM 60 10K 489
ksem 12 10K 122
kqueue 111 10K 7589
in6_multi 65 9K 65
bmsafemap 2 9K 7243
UART 12 9K 12
devstat 4 9K 4
sctp_stri 16 8K 867
rpc 2 8K 2
shmfd 1 8K 23
pfs_vncache 1 8K 1
pfs_nodes 20 8K 20
audit_evclass 236 8K 294
sctp_athm 441 7K 12393
pwddesc 108 7K 7466
cred 26 7K 296
sctp_map 404 7K 7380
taskqueue 60 7K 60
sglist 5 7K 5
CAM DEV 3 6K 510
plimit 24 6K 563
DEVFSP 81 6K 311
CAM queue 5 6K 1528
freework 20 5K 9150
ufs_dirhash 24 5K 24
pf_ifnet 11 5K 214
session 35 5K 48
UMA 265 5K 265
vt 11 5K 11
memdesc 1 4K 1
MCA 32 4K 32
evdev 4 4K 4
kcovinfo 64 4K 68
lockf 33 4K 725
acpisem 28 4K 28
selfd 55 4K 108423
hhook 13 4K 13
fpukern_ctx 3 3K 3
proc-args 52 3K 662
terminal 11 3K 11
select 20 3K 474
uidinfo 3 3K 23
pf_osfp 18 3K 18
local_apic 1 2K 1
io_apic 1 2K 1
ipsec-saq 2 2K 2
ip6ndp 12 2K 13
freeblks 7 2K 6916
sctp_ifa 13 2K 14
Unitno 27 2K 63
CAM XPT 22 2K 543
in_multi 6 2K 8
ipsecpolicy 2 2K 2
acpidev 20 2K 20
msi 9 2K 9
clone 9 2K 9
tun 7 2K 7
softdep 1 1K 1
mkdir 8 1K 13140
sahead 1 1K 1
secasvar 1 1K 1
nhops 6 1K 8
vnodemarker 2 1K 606
NFSD session 1 1K 1
inpcbpolicy 31 1K 8415
CAM periph 4 1K 271
ipsec 3 1K 3
sctp_ifn 6 1K 14
newdirblk 6 1K 6570
mld 6 1K 6
igmp 6 1K 6
toponodes 6 1K 6
isadev 6 1K 6
mount 16 1K 535
pci_link 10 1K 10
crypto 4 1K 94
encap_export_host 12 1K 12
procdesc 5 1K 14
diradd 4 1K 6922
pfil 4 1K 4
CAM SIM 2 1K 2
cdev 2 1K 2
ip6_msource 7 1K 16
chacha20random 1 1K 1
osd 3 1K 10
filedesc_to_leader 5 1K 19
NFSD lckfile 1 1K 1
NFSD V4client 1 1K 1
DEVFS 9 1K 10
indirdep 1 1K 3636
vnodes 1 1K 30
ktls 1 1K 1
feeder 7 1K 7
xform 3 1K 359
tcpfunc 3 1K 3
loginclass 3 1K 6
prison 6 1K 6
linux 5 1K 6
aesni_data 2 1K 2
soname 6 1K 10462
apmdev 1 1K 1
atkbddev 2 1K 2
CAM dev queue 2 1K 2
CAM I/O Scheduler 1 1K 1
ip_msource 2 1K 2
CAM path 4 1K 1034
pmchooks 1 1K 1
nexusdev 7 1K 7
filecaps 5 1K 98
sctp_vrf 1 1K 1
vnet 1 1K 1
entropy 2 1K 46
acpiintr 1 1K 1
pmc 1 1K 1
cpus 2 1K 2
vnet_data_free 1 1K 1
Per-cpu 1 1K 1
p1003.1b 1 1K 1
sctp_mcore 0 0K 0
sctp_socko 0 0K 5793
sctp_iter 0 0K 31
sctp_mvrf 0 0K 0
sctp_cpal 0 0K 22
sctp_cmsg 0 0K 0
sctp_stre 0 0K 0
sctp_athi 0 0K 0
sctp_a_it 0 0K 9
sctp_aadr 0 0K 88
tcp_do 0 0K 0
tcp_fsb 0 0K 271
pf_table 0 0K 68
pf_rule 0 0K 234
pf_altq 0 0K 0
pf_temp 0 0K 0
mqdata 0 0K 0
NFSD string 0 0K 0
NFSD V4lock 0 0K 0
madt_table 0 0K 2
smartpqi 0 0K 0
NFSD V4state 0 0K 0
NFSD srvcache 0 0K 0
msdosfs_fat 0 0K 0
msdosfs_mount 0 0K 0
msdosfs_node 0 0K 0
iavf 0 0K 0
ixl 0 0K 0
DEVFS4 0 0K 0
DEVFS2 0 0K 0
gntdev 0 0K 0
privcmd_dev 0 0K 0
ice-resmgr 0 0K 0
ice-osdep 0 0K 0
ice 0 0K 0
axgbe 0 0K 0
evtchn_dev 0 0K 0
xenstore 0 0K 0
ciss_data 0 0K 0
BACKLIGHT 0 0K 0
xnb 0 0K 0
xbbd 0 0K 0
xbd 0 0K 0
Balloon 0 0K 0
sysmouse 0 0K 0
vtfont 0 0K 0
xen_intr 0 0K 0
xen_hvm 0 0K 0
legacydrv 0 0K 0
qpidrv 0 0K 0
ath_hal 0 0K 0
athdev 0 0K 0
dmar_idpgtbl 0 0K 0
dmar_dom 0 0K 0
dmar_ctx 0 0K 0
ata_pci 0 0K 0
ata_dma 0 0K 0
ata_generic 0 0K 0
isci 0 0K 0
iommu_dmamap 0 0K 0
amr 0 0K 0
hyperv_socket 0 0K 0
bxe_ilt 0 0K 0
xenbus 0 0K 0
pvscsi 0 0K 0
scsi_da 0 0K 69
vm_fictitious 0 0K 0
ata_da 0 0K 0
scsi_ch 0 0K 0
scsi_cd 0 0K 0
AHCI driver 0 0K 0
USBdev 0 0K 0
USB 0 0K 0
agp 0 0K 0
nvme_da 0 0K 0
UMAHash 0 0K 0
acpipwr 0 0K 0
acpi_perf 0 0K 0
vm_pgdata 0 0K 0
jblocks 0 0K 0
savedino 0 0K 3627
sentinel 0 0K 0
jfsync 0 0K 0
jtrunc 0 0K 0
sbdep 0 0K 293
jsegdep 0 0K 0
jseg 0 0K 0
jfreefrag 0 0K 0
jfreeblk 0 0K 0
jnewblk 0 0K 0
jmvref 0 0K 0
jremref 0 0K 0
jaddref 0 0K 0
freedep 0 0K 0
freefrag 0 0K 11
allocindir 0 0K 0
allocdirect 0 0K 0
ufs_trim 0 0K 0
mactemp 0 0K 0
audit_trigger 0 0K 0
audit_pipe_presel 0 0K 0
audit_pipeent 0 0K 0
audit_pipe 0 0K 0
audit_evname 0 0K 0
audit_bsm 0 0K 0
audit_gidset 0 0K 0
audit_text 0 0K 0
audit_path 0 0K 0
audit_data 0 0K 0
audit_cred 0 0K 0
twsbuf 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5E_TLS 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EN 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5DUMP 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
seq_file 0 0K 0
radix 0 0K 0
idr 0 0K 0
lkpifw 0 0K 0
NLM 0 0K 0
ipsec-spdcache 0 0K 0
ipsec-reg 0 0K 0
ipsec-misc 0 0K 0
ipsecrequest 0 0K 0
ip6opt 0 0K 90
ip6_moptions 0 0K 19
in6_mfilter 0 0K 59
frag6 0 0K 0
tcplog 0 0K 0
tcp_hwpace 0 0K 0
twe_commands 0 0K 0
LRO 0 0K 0
newreno data 0 0K 0
ip_moptions 0 0K 11
in_mfilter 0 0K 20
ipid 0 0K 0
80211scan 0 0K 0
80211ratectl 0 0K 0
80211power 0 0K 0
80211nodeie 0 0K 0
80211node 0 0K 0
80211mesh_gt 0 0K 0
80211mesh_rt 0 0K 0
80211perr 0 0K 0
80211prep 0 0K 0
80211preq 0 0K 0
80211dfs 0 0K 0
80211crypto 0 0K 0
80211vap 0 0K 0
iflib 0 0K 0
vlan 0 0K 0
gif 0 0K 0
ifdescr 0 0K 0
zlib 0 0K 0
fadvise 0 0K 0
VN POLL 0 0K 1
twa_commands 0 0K 0
statfs 0 0K 6758
namei_tracker 0 0K 6
export_host 0 0K 0
cl_savebuf 0 0K 106
tcp_log_dev 0 0K 105
midi buffers 0 0K 0
mixer 0 0K 0
ac97 0 0K 0
hdacc 0 0K 0
hdac 0 0K 0
hdaa 0 0K 0
acpicmbat 0 0K 0
SIIS driver 0 0K 0
CAM CCB 0 0K 29203
PUC 0 0K 0
ppbusdev 0 0K 0
agtiapi_MemAlloc malloc 0 0K 0
osti_cacheable 0 0K 0
tempbuff 0 0K 0
biobuf 0 0K 0
aios 0 0K 0
lio 0 0K 0
acl 0 0K 0
tempbuff 0 0K 0
mbuf_tag 0 0K 169
ag_tgt_map_t malloc 0 0K 0
ag_slr_map_t malloc 0 0K 0
lDevFlags * malloc 0 0K 0
tiDeviceHandle_t * malloc 0 0K 0
ag_portal_data_t malloc 0 0K 0
ag_device_t malloc 0 0K 0
STLock malloc 0 0K 0
CCB List 0 0K 0
sr_iov 0 0K 0
OCS 0 0K 0
OCS 0 0K 0
nvme 0 0K 0
nvd 0 0K 0
netmap 0 0K 0
mwldev 0 0K 0
MVS driver 0 0K 0
CAM ccb queue 0 0K 0
mrsasbuf 0 0K 0
mpt_user 0 0K 0
mps_user 0 0K 0
accf 0 0K 0
pts 0 0K 0
iov 0 0K 22825
ioctlops 0 0K 980
eventfd 0 0K 0
Witness 0 0K 0
stack 0 0K 0
MPSSAS 0 0K 0
mps 0 0K 0
mpr_user 0 0K 0
MPRSAS 0 0K 0
mpr 0 0K 0
mfibuf 0 0K 0
sbuf 0 0K 338
md_sectors 0 0K 0
firmware 0 0K 0
compressor 0 0K 0
md_disk 0 0K 0
SWAP 0 0K 0
malodev 0 0K 0
LED 0 0K 0
sysctltmp 0 0K 798
sysctl 0 0K 3
ekcd 0 0K 0
dumper 0 0K 0
sendfile 0 0K 0
rctl 0 0K 0
ix_sriov 0 0K 0
aacraidcam 0 0K 0
aacraid_buf 0 0K 0
ix 0 0K 0
ipsbuf 0 0K 0
cache 0 0K 0
iirbuf 0 0K 0
prison_racct 0 0K 0
Fail Points 0 0K 0
sigio 0 0K 3
pwd 0 0K 0
tty console 0 0K 0
aaccam 0 0K 0
aacbuf 0 0K 0
zstd 0 0K 0
XZ_DEC 0 0K 0
nvlist 0 0K 0
SCSI ENC 0 0K 0
SCSI sa 0 0K 0
scsi_pass 0 0K 0
isofs_node 0 0K 0
isofs_mount 0 0K 0
tr_raid5_data 0 0K 0
tr_raid1e_data 0 0K 0
tr_raid1_data 0 0K 0
tr_raid0_data 0 0K 0
tr_concat_data 0 0K 0
md_sii_data 0 0K 0
md_promise_data 0 0K 0
md_nvidia_data 0 0K 0
md_jmicron_data 0 0K 0
md_intel_data 0 0K 0
md_ddf_data 0 0K 0
raid_data 0 0K 72
geom_flashmap 0 0K 0
tmpfs dir 0 0K 0
tmpfs name 0 0K 0
tmpfs mount 0 0K 0
NFS FHA 0 0K 0
newnfsmnt 0 0K 0
newnfsclient_req 0 0K 0
NFSCL layrecall 0 0K 0
NFSCL session 0 0K 0
NFSCL sockreq 0 0K 0
NFSCL devinfo 0 0K 0
NFSCL flayout 0 0K 0
NFSCL layout 0 0K 0
NFSD rollback 0 0K 0
NFSCL diroff 0 0K 0
NEWdirectio 0 0K 0
NEWNFSnode 0 0K 0
NFSCL lck 0 0K 0
NFSCL lckown 0 0K 0
NFSCL client 0 0K 0
NFSCL deleg 0 0K 0
NFSCL open 0 0K 0
NFSCL owner 0 0K 0
NFS fh 0 0K 0
NFS req 0 0K 0
NFSD usrgroup 0 0K 0
db> show uma
Zone Size Used Free Requests Sleeps Bucket Total Mem XFree
mbuf_jumbo_page 4096 10598 7455 998381 0 254 73945088 0
tcp_log 416 0 30069 381855 0 254 12508704 0
mbuf 256 12068 7102 2470674 0 254 4907520 0
RADIX NODE 144 16242 1199 280010 0 63 2511504 0
pbuf 2624 0 957 0 0 2 2511168 0
UMA Slabs 0 112 19849 20 19849 0 126 2225328 0
BUF TRIE 144 353 13115 18617 0 62 1939392 0
mbuf_cluster 2048 780 2 780 0 254 1601536 0
malloc-384 384 4116 4 4116 0 30 1582080 0
malloc-128 128 11104 56 11570 0 126 1428480 0
malloc-4096 4096 332 4 837 0 2 1376256 0
malloc-16384 16384 57 4 6733 0 1 999424 0
sctp_asoc 2288 202 153 3690 0 254 812240 0
tcp_bbr_map 128 1078 4440 205649 0 126 706304 0
FFS inode 1160 552 29 7426 0 8 673960 0
256 Bucket 2048 315 3 30089 0 8 651264 0
malloc-2048 2048 219 91 7753 0 8 634880 0
VM OBJECT 264 1927 83 115443 0 30 530640 0
malloc-4096 4096 121 4 7494 0 2 512000 0
sctp_ep 1280 223 146 7750 0 254 472320 0
MAP ENTRY 96 4129 281 446644 0 126 423360 0
THREAD 1808 206 25 14452 0 8 417648 0
malloc-65536 65536 4 2 14 0 1 393216 0
lkpimm 160 1 2324 1 0 62 372000 0
lkpicurr 160 2 2323 2 0 62 372000 0
malloc-1024 1024 179 125 3714 0 16 311296 0
VNODE 448 590 76 7466 0 30 298368 0
malloc-64 64 4304 232 16719 0 254 290304 0
malloc-384 384 581 139 12279 0 30 276480 0
sctp_raddr 736 212 162 4658 0 254 275264 0
malloc-2048 2048 2 130 29273 0 8 270336 0
socket 944 82 186 18052 0 254 252992 0
VMSPACE 2544 85 8 7456 0 4 236592 0
malloc-16 16 14197 553 26329 0 254 236000 0
malloc-256 256 214 701 29793 0 62 234240 0
malloc-32768 32768 0 7 204 0 1 229376 0
DEVCTL 1024 0 216 132 0 0 221184 0
malloc-128 128 1408 297 56788 0 126 218240 0
mbuf_packet 256 211 569 31766 0 254 199680 0
malloc-65536 65536 1 2 425 0 1 196608 0
malloc-32768 32768 0 6 3314 0 1 196608 0
g_bio 408 0 480 94921 0 30 195840 0
malloc-32 32 5644 404 17726 0 254 193536 0
UMA Zones 768 237 2 237 0 16 183552 0
PROC 1336 108 15 7479 0 8 164328 0
malloc-128 128 1169 102 3094 0 126 162688 0
malloc-384 384 134 276 7513 0 30 157440 0
sctp_chunk 152 518 470 4842 0 254 150176 0
FFS2 dinode 256 552 33 7425 0 62 149760 0
S VFS Cache 104 1027 338 8014 0 126 141960 0
vmem btag 56 2430 78 2430 0 254 140448 0
filedesc0 1072 108 18 7466 0 8 135072 0
128 Bucket 1024 95 36 4293 0 16 134144 0
malloc-65536 65536 2 0 2 0 1 131072 0
malloc-65536 65536 0 2 96 0 1 131072 0
clpbuf 2624 0 48 1689 0 16 125952 0
ksiginfo 112 106 938 1187 0 126 116928 0
malloc-256 256 33 417 4853 0 62 115200 0
malloc-8192 8192 9 5 138 0 1 114688 0
malloc-1024 1024 108 4 150 0 16 114688 0
udplite_inpcb 488 5 219 6646 0 254 109312 0
malloc-256 256 291 99 15423 0 62 99840 0
malloc-4096 4096 23 0 555 0 2 94208 0
UMA Kegs 384 222 1 222 0 30 85632 0
malloc-256 256 245 85 15878 0 62 84480 0
malloc-4096 4096 15 3 113 0 2 73728 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-65536 65536 0 1 8 0 1 65536 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-32768 32768 2 0 2 0 1 65536 0
64 Bucket 512 88 40 8521 0 30 65536 0
malloc-256 256 109 131 7554 0 62 61440 0
32 Bucket 256 92 133 18386 0 62 57600 0
malloc-256 256 154 41 479 0 62 49920 0
malloc-16384 16384 3 0 3 0 1 49152 0
malloc-16384 16384 0 3 8 0 1 49152 0
malloc-2048 2048 4 20 517 0 8 49152 0
malloc-64 64 570 186 19145 0 254 48384 0
malloc-256 256 33 147 9337 0 62 46080 0
malloc-2048 2048 11 11 461 0 8 45056 0
pcpu-8 8 4687 945 10035 0 254 45056 0
tcpcb 1064 8 34 1282 0 254 44688 0
Files 80 289 261 33859 0 126 44000 0
malloc-128 128 300 41 539 0 126 43648 0
DIRHASH 1024 34 6 34 0 16 40960 0
malloc-8192 8192 5 0 5 0 1 40960 0
malloc-8192 8192 3 2 5 0 1 40960 0
malloc-512 512 20 60 1379 0 30 40960 0
malloc-64 64 487 143 1265 0 254 40320 0
NAMEI 1024 0 36 43362 0 16 36864 0
malloc-4096 4096 4 5 6765 0 2 36864 0
malloc-64 64 238 329 109005 0 254 36288 0
malloc-128 128 117 162 471 0 126 35712 0
TURNSTILE 136 232 20 232 0 62 34272 0
pipe 744 24 21 777 0 16 33480 0
malloc-32768 32768 1 0 1 0 1 32768 0
malloc-8192 8192 1 3 8 0 1 32768 0
malloc-8192 8192 2 2 7 0 1 32768 0
pcpu-64 64 480 32 480 0 254 32768 0
tcp_bbr_pcb 832 3 33 457 0 16 29952 0
tcp_rack_pcb 832 0 36 271 0 16 29952 0
KNOTE 160 28 147 320353 0 62 28000 0
8 Bucket 80 71 279 4193 0 126 28000 0
malloc-384 384 52 18 62 0 30 26880 0
malloc-256 256 80 25 946 0 62 26880 0
malloc-2048 2048 5 7 225 0 8 24576 0
malloc-1024 1024 10 14 1463 0 16 24576 0
malloc-1024 1024 18 6 22 0 16 24576 0
malloc-64 64 251 127 15055 0 254 24192 0
ttyinq 160 135 15 300 0 62 24000 0
tcp_inpcb 488 9 39 1282 0 254 23424 0
ttyoutq 256 72 18 160 0 62 23040 0
malloc-384 384 27 33 546 0 30 23040 0
SLEEPQUEUE 88 232 24 232 0 126 22528 0
malloc-2048 2048 6 4 23 0 8 20480 0
malloc-1024 1024 12 8 27 0 16 20480 0
malloc-1024 1024 11 9 80 0 16 20480 0
malloc-512 512 14 26 618 0 30 20480 0
sctp_stream_msg_out 112 92 88 1024 0 254 20160 0
PWD 32 56 574 6612 0 254 20160 0
malloc-32 32 415 215 708 0 254 20160 0
16 Bucket 144 69 71 884 0 62 20160 0
2 Bucket 32 65 565 2043 0 254 20160 0
malloc-16 16 718 532 7942 0 254 20000 0
malloc-128 128 56 99 6664 0 126 19840 0
Mountpoints 2752 2 5 7 0 4 19264 0
unpcb 256 24 51 1839 0 254 19200 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-2048 2048 2 6 282 0 8 16384 0
sctp_laddr 48 198 138 2523 0 254 16128 0
malloc-64 64 141 111 213 0 254 16128 0
malloc-32 32 128 376 16374 0 254 16128 0
cpuset 104 38 117 243 0 126 16120 0
vtnet_tx_hdr 24 0 668 799548 0 254 16032 0
ripcb 488 7 25 182 0 254 15616 0
udp_inpcb 488 11 21 305 0 254 15616 0
malloc-384 384 20 20 36 0 30 15360 0
malloc-4096 4096 0 3 27 0 2 12288 0
malloc-1024 1024 8 4 9 0 16 12288 0
malloc-512 512 3 21 209 0 30 12288 0
udpcb 32 16 362 6951 0 254 12096 0
malloc-32 32 156 222 6795 0 254 12096 0
itimer 352 0 33 52 0 30 11616 0
kenv 258 15 30 1061 0 30 11610 0
routing nhops 256 27 18 34 0 62 11520 0
malloc-8192 8192 1 0 1 0 1 8192 0
malloc-8192 8192 1 0 1 0 1 8192 0
malloc-2048 2048 1 3 433 0 8 8192 0
malloc-1024 1024 0 8 8 0 16 8192 0
malloc-512 512 0 16 24 0 30 8192 0
malloc-512 512 0 16 10 0 30 8192 0
malloc-512 512 0 16 20 0 30 8192 0
malloc-512 512 8 8 15 0 30 8192 0
pf tags 104 0 78 11 0 126 8112 0
rtentry 176 30 16 34 0 62 8096 0
tcptw 88 0 92 7 0 254 8096 0
PGRP 88 37 55 68 0 126 8096 0
rl_entry 40 113 89 118 0 254 8080 0
sctp_asconf_ack 48 7 161 32 0 254 8064 0
tcp_rack_map 112 0 72 480 0 126 8064 0
ipq 56 0 144 10 0 254 8064 0
malloc-64 64 8 118 18 0 254 8064 0
malloc-64 64 39 87 1221 0 254 8064 0
malloc-32 32 6 246 41 0 254 8064 0
malloc-32 32 0 252 35 0 254 8064 0
malloc-32 32 37 215 766 0 254 8064 0
malloc-32 32 38 214 522 0 254 8064 0
4 Bucket 48 7 161 196 0 254 8064 0
malloc-16 16 1 499 27 0 254 8000 0
malloc-16 16 20 480 274 0 254 8000 0
malloc-16 16 28 472 29 0 254 8000 0
malloc-16 16 188 312 1491 0 254 8000 0
malloc-16 16 36 464 31742 0 254 8000 0
malloc-16 16 14 486 4248 0 254 8000 0
malloc-128 128 9 53 30 0 126 7936 0
malloc-128 128 23 39 218 0 126 7936 0
sctp_readq 152 0 52 388 0 254 7904 0
cryptop 280 0 28 10 0 30 7840 0
L VFS Cache 320 0 24 8 0 30 7680 0
malloc-384 384 0 20 41 0 30 7680 0
malloc-384 384 1 19 75 0 30 7680 0
FPU_save_area 832 1 8 1 0 16 7488 0
domainset 40 0 126 228 0 254 5040 0
epoch_record pcpu 256 4 12 4 0 62 4096 0
malloc-512 512 0 8 2 0 30 4096 0
pcpu-16 16 7 249 7 0 254 4096 0
hostcache 64 2 61 2 0 254 4032 0
syncache 168 0 24 14 0 254 4032 0
UMA Slabs 1 176 10 12 10 0 62 3872 0
mqnode 416 3 6 3 0 30 3744 0
KMAP ENTRY 96 12 27 12 0 0 3744 0
vmem 1856 1 1 1 0 8 3712 0
SMR CPU 32 3 60 3 0 254 2016 0
SMR SHARED 24 3 60 3 0 254 1512 0
FFS1 dinode 128 0 0 0 0 126 0 0
swblk 136 0 0 0 0 62 0 0
swpctrie 144 0 0 0 0 62 0 0
sctp_asconf 40 0 0 0 0 254 0 0
pf state scrubs 40 0 0 0 0 254 0 0
pf frag entries 40 0 0 0 0 254 0 0
pf frags 248 0 0 0 0 62 0 0
pf table entries 160 0 0 0 0 62 0 0
pf table entry counters 64 0 0 0 0 254 0 0
pf source nodes 136 0 0 0 0 254 0 0
pf state keys 88 0 0 0 0 126 0 0
pf states 296 0 0 0 0 254 0 0
pf mtags 48 0 0 0 0 254 0 0
IPsec SA lft_c 16 0 0 0 0 254 0

---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Aug 6, 2021, 1:17:20 PM8/6/21
to syzkaller-f...@googlegroups.com, tue...@freebsd.org
This bug is marked as fixed by commit:
#syz fix: Fix a UDP tunneling issue with rack. Basically there are two
But I can't find it in any tested tree for more than 90 days.
Is it a correct commit? Please update it by replying:
#syz fix: exact-commit-title
Until then the bug is still considered open and
new crashes with the same signature are ignored.

syzbot

unread,
Aug 20, 2021, 1:18:14 PM8/20/21
to syzkaller-f...@googlegroups.com, tue...@freebsd.org

syzbot

unread,
Sep 3, 2021, 1:18:19 PM9/3/21
to syzkaller-f...@googlegroups.com, tue...@freebsd.org

syzbot

unread,
Sep 17, 2021, 1:19:13 PM9/17/21
to syzkaller-f...@googlegroups.com, tue...@freebsd.org

Mark Johnston

unread,
Sep 17, 2021, 5:42:56 PM9/17/21
to syzbot, syzkaller-f...@googlegroups.com
Reply all
Reply to author
Forward
0 new messages