Fatal trap 9: general protection fault while in kernel mode

32 views
Skip to first unread message

syzbot

unread,
Mar 15, 2019, 12:56:05 PM3/15/19
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 84b9791b bridge: Fix panic if the STP root is removed
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=160202d7200000
dashboard link: https://syzkaller.appspot.com/bug?extid=04703fa0ea5d303be039
userspace arch: amd64

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+04703f...@syzkaller.appspotmail.com

Fatal trap 9: general protection fault while in kernel mode
cpuid = 0; apic id = 00
instruction pointer = 0x20:0xffffffff813441d5
stack pointer = 0x28:0xfffffe0020df27e0
frame pointer = 0x28:0xfffffe0020df2890
code segment = base 0x0, limit 0xfffff, type 0x1b
= DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags = interrupt enabled, resume, IOPL = 0
current process = 10429 (syz-executor.3)
trap number = 9
panic: general protection fault
cpuid = 0
time = 80
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe0020df24b0
vpanic() at vpanic+0x1e0/frame 0xfffffe0020df2510
panic() at panic+0x43/frame 0xfffffe0020df2570
trap_fatal() at trap_fatal+0x4c6/frame 0xfffffe0020df25f0
trap() at trap+0xba/frame 0xfffffe0020df2710
calltrap() at calltrap+0x8/frame 0xfffffe0020df2710
--- trap 0x9, rip = 0xffffffff813441d5, rsp = 0xfffffe0020df27e0, rbp =
0xfffffe0020df2890 ---
sctp_inpcb_bind() at sctp_inpcb_bind+0x3f5/frame 0xfffffe0020df2890
sctp_listen() at sctp_listen+0x475/frame 0xfffffe0020df2900
solisten() at solisten+0x7a/frame 0xfffffe0020df2940
kern_listen() at kern_listen+0x132/frame 0xfffffe0020df2980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe0020df2ab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe0020df2ab0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x412e5a, rsp =
0x7fffdfffdf38, rbp = 0x2 ---
KDB: enter: panic
[ thread pid 10429 tid 100875 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#bug-status-tracking for how to communicate with
syzbot.

syzbot

unread,
Mar 17, 2019, 2:29:05 PM3/17/19
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 8f6fafa8 Fix legacy IP autoconfiguration.
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=169d4b83200000
dashboard link: https://syzkaller.appspot.com/bug?extid=04703fa0ea5d303be039
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=12bb27e7200000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+04703f...@syzkaller.appspotmail.com

Fatal trap 9: general protection fault while in kernel mode
cpuid = 0; apic id = 00
instruction pointer = 0x20:0xffffffff81163cf5
stack pointer = 0x28:0xfffffe0021268610
frame pointer = 0x28:0xfffffe0021268650
code segment = base 0x0, limit 0xfffff, type 0x1b
= DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags = interrupt enabled, resume, IOPL = 0
current process = 1021 (syz-executor.2)
trap number = 9
panic: general protection fault
cpuid = 0
time = 1552846104
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe00212682e0
vpanic() at vpanic+0x1e0/frame 0xfffffe0021268340
panic() at panic+0x43/frame 0xfffffe00212683a0
trap_fatal() at trap_fatal+0x4c6/frame 0xfffffe0021268420
trap() at trap+0xba/frame 0xfffffe0021268540
calltrap() at calltrap+0x8/frame 0xfffffe0021268540
--- trap 0x9, rip = 0xffffffff81163cf5, rsp = 0xfffffe0021268610, rbp =
0xfffffe0021268650 ---
unp_dispose() at unp_dispose+0xa5/frame 0xfffffe0021268650
sofree() at sofree+0x42c/frame 0xfffffe00212686b0
soclose() at soclose+0x5b3/frame 0xfffffe0021268730
_fdrop() at _fdrop+0x3a/frame 0xfffffe0021268760
closef() at closef+0x27d/frame 0xfffffe00212687f0
fdescfree_fds() at fdescfree_fds+0xbd/frame 0xfffffe0021268840
fdescfree() at fdescfree+0x58a/frame 0xfffffe0021268900
exit1() at exit1+0x780/frame 0xfffffe0021268970
sys_sys_exit() at sys_sys_exit+0xd/frame 0xfffffe0021268980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe0021268ab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe0021268ab0
--- syscall (1, FreeBSD ELF64, sys_sys_exit), rip = 0x44f30a, rsp =
0x7fffffffec58, rbp = 0x1 ---
KDB: enter: panic
[ thread pid 1021 tid 100114 ]

syzbot

unread,
Mar 18, 2019, 12:05:05 AM3/18/19
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 8b17fbc2 Change date of Canberra Day, now on second Monday..
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=15846dfb200000
dashboard link: https://syzkaller.appspot.com/bug?extid=04703fa0ea5d303be039
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=139a71d7200000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=15fe91d7200000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+04703f...@syzkaller.appspotmail.com

Fatal trap 9: general protection fault while in kernel mode
cpuid = 0; apic id = 00
instruction pointer = 0x20:0xffffffff81163cf5
stack pointer = 0x28:0xfffffe001fa0e610
frame pointer = 0x28:0xfffffe001fa0e650
code segment = base 0x0, limit 0xfffff, type 0x1b
= DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags = interrupt enabled, resume, IOPL = 0
current process = 907 (syz-executor9083768)
trap number = 9
panic: general protection fault
cpuid = 0
time = 1552881695
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe001fa0e2e0
vpanic() at vpanic+0x1e0/frame 0xfffffe001fa0e340
panic() at panic+0x43/frame 0xfffffe001fa0e3a0
trap_fatal() at trap_fatal+0x4c6/frame 0xfffffe001fa0e420
trap() at trap+0xba/frame 0xfffffe001fa0e540
calltrap() at calltrap+0x8/frame 0xfffffe001fa0e540
--- trap 0x9, rip = 0xffffffff81163cf5, rsp = 0xfffffe001fa0e610, rbp =
0xfffffe001fa0e650 ---
unp_dispose() at unp_dispose+0xa5/frame 0xfffffe001fa0e650
sofree() at sofree+0x42c/frame 0xfffffe001fa0e6b0
soclose() at soclose+0x5b3/frame 0xfffffe001fa0e730
_fdrop() at _fdrop+0x3a/frame 0xfffffe001fa0e760
closef() at closef+0x27d/frame 0xfffffe001fa0e7f0
fdescfree_fds() at fdescfree_fds+0xbd/frame 0xfffffe001fa0e840
fdescfree() at fdescfree+0x58a/frame 0xfffffe001fa0e900
exit1() at exit1+0x780/frame 0xfffffe001fa0e970
sys_sys_exit() at sys_sys_exit+0xd/frame 0xfffffe001fa0e980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe001fa0eab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe001fa0eab0
--- syscall (1, FreeBSD ELF64, sys_sys_exit), rip = 0x447a0a, rsp =
0x7fffffffea68, rbp = 0x7fffffffea80 ---
KDB: enter: panic
[ thread pid 907 tid 100096 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why
db>

Mark Johnston

unread,
Mar 22, 2019, 11:31:37 AM3/22/19
to syzbot, syzkaller-f...@googlegroups.com
#syz dup: Fatal trap 9: general protection fault in unp_dispose
Reply all
Reply to author
Forward
0 new messages