panic: ASan: Invalid access, NUM-byte write at ADDR, UMAUseAfterFree(fd) (2)

2 views
Skip to first unread message

syzbot

unread,
May 30, 2022, 1:43:19 AM5/30/22
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: a6a596e102be sctp: improve handling of listen() call
git tree: freebsd-src
console output: https://syzkaller.appspot.com/x/log.txt?x=12aa123df00000
dashboard link: https://syzkaller.appspot.com/bug?extid=583ce35a13ec4552b187
userspace arch: i386

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+583ce3...@syzkaller.appspotmail.com

panic: ASan: Invalid access, 4-byte write at 0xfffffe009f36a538, UMAUseAfterFree(fd)
cpuid = 0
time = 1653889338
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0xc7/frame 0xfffffe0053b32790
kdb_backtrace() at kdb_backtrace+0xd3/frame 0xfffffe0053b328f0
vpanic() at vpanic+0x2b8/frame 0xfffffe0053b329d0
panic() at panic+0xb5/frame 0xfffffe0053b32aa0
kasan_report() at kasan_report+0xdc/frame 0xfffffe0053b32b70
kasan_atomic_fetchadd_int() at kasan_atomic_fetchadd_int+0x19a/frame 0xfffffe0053b32b90
sctp_timeout_handler() at sctp_timeout_handler+0x1255/frame 0xfffffe0053b32cd0
softclock_call_cc() at softclock_call_cc+0x3c9/frame 0xfffffe0053b32e80
softclock_thread() at softclock_thread+0x1ff/frame 0xfffffe0053b32ef0
fork_exit() at fork_exit+0xd0/frame 0xfffffe0053b32f30
fork_trampoline() at fork_trampoline+0xe/frame 0xfffffe0053b32f30
--- trap 0, rip = 0, rsp = 0, rbp = 0 ---
KDB: enter: panic
[ thread pid 2 tid 100029 ]
Stopped at kdb_enter+0x6b: movq $0,0x275b69a(%rip)
db>
db> set $lines = 0
db> set $maxwidth = 0
db> show registers
cs 0x20
ds 0x3b
es 0x3b
fs 0x13
gs 0x1b
ss 0
rax 0x12
rcx 0xffffffff8172b3f6 printf+0xf6
rdx 0x1
rbx 0
rsp 0xfffffe0053b328d0
rbp 0xfffffe0053b328f0
rsi 0
rdi 0xffffffff8172b458 printf+0x158
r8 0
r9 0xffffffff
r10 0
r11 0
r12 0xfffffe0053e9b3a0
r13 0xfffffe0053b32901
r14 0xffffffff82b58800 .str.26
r15 0xffffffff82b58800 .str.26
rip 0xffffffff8171af7b kdb_enter+0x6b
rflags 0x46
kdb_enter+0x6b: movq $0,0x275b69a(%rip)
db> show proc
Process 2 (clock) at 0xfffffe0053de0000:
state: NORMAL
uid: 0 gids: 0
parent: pid 0 at 0xffffffff83e19c80
ABI: null
flag: 0x10000284 flag2: 0
reaper: 0xffffffff83e19c80 reapsubtree: 2
sigparent: 20
vmspace: 0xffffffff83e1ac20
(map 0xffffffff83e1ac20)
(map.pmap 0xffffffff83e1ace0)
(pmap 0xffffffff83e1ad48)
threads: 2
100029 Run CPU 0 [clock (0)]
100030 I [clock (1)]
db> ps
pid ppid pgrp uid state wmesg wchan cmd
9314 779 779 0 S (threaded) syz-executor.0
105336 S nanslp 0xffffffff83e43c81 syz-executor.0
111616 S connec 0xfffffe0058c610da syz-executor.0
111621 S uwait 0xfffffe0057327580 syz-executor.0
9312 780 780 0 S (threaded) syz-executor.1
111530 S nanslp 0xffffffff83e43c81 syz-executor.1
111613 S connec 0xfffffe0058c6385a syz-executor.1
111618 S uwait 0xfffffe005788b000 syz-executor.1
9260 1 781 0 S uwait 0xfffffe0057328a00 syz-executor.3
9259 1 781 0 S uwait 0xfffffe005788b200 syz-executor.3
9257 1 781 0 S uwait 0xfffffe00a69bb500 syz-executor.3
9255 1 781 0 S uwait 0xfffffe00a69bd280 syz-executor.3
9248 1 780 0 S uwait 0xfffffe00a69bcd80 syz-executor.1
9244 1 781 0 S uwait 0xfffffe0058b20a00 syz-executor.3
9243 1 780 0 S uwait 0xfffffe005788ae80 syz-executor.1
9242 1 781 0 S uwait 0xfffffe005788ab80 syz-executor.3
9239 1 780 0 S uwait 0xfffffe0058b23680 syz-executor.1
9238 1 781 0 S uwait 0xfffffe005788aa80 syz-executor.3
9237 1 780 0 S uwait 0xfffffe0058b23500 syz-executor.1
9235 1 781 0 S uwait 0xfffffe00a69bb100 syz-executor.3
9232 1 781 0 S uwait 0xfffffe0057328b00 syz-executor.3
9231 1 781 0 S umtxn 0xfffffe005788b400 syz-executor.3
9228 1 781 0 S uwait 0xfffffe0057328c00 syz-executor.3
9227 1 781 0 S uwait 0xfffffe00a69bb000 syz-executor.3
9226 1 780 0 S uwait 0xfffffe0058b23e80 syz-executor.1
9223 1 780 0 S umtxn 0xfffffe00a69bc780 syz-executor.1
9220 1 780 0 S uwait 0xfffffe00a69bbe00 syz-executor.1
9218 1 780 0 S uwait 0xfffffe0058b23d80 syz-executor.1
8791 0 0 0 DL mdwait 0xfffffe00a77c0000 [md4]
8216 1 782 0 S uwait 0xfffffe0058b23980 syz-executor.2
8215 1 780 0 S uwait 0xfffffe005788a880 syz-executor.1
8206 1 782 0 S uwait 0xfffffe005788b500 syz-executor.2
8205 1 780 0 S uwait 0xfffffe005732af00 syz-executor.1
8196 1 780 0 S uwait 0xfffffe0058b23b80 syz-executor.1
8195 1 782 0 S uwait 0xfffffe0057889580 syz-executor.2
8186 1 782 0 S uwait 0xfffffe005788ac80 syz-executor.2
7609 1 779 0 S uwait 0xfffffe00a69bc580 syz-executor.0
7053 1 780 0 S uwait 0xfffffe0057328800 syz-executor.1
6188 1 782 0 S umtxn 0xfffffe00a69bc180 syz-executor.2
6148 1 782 0 S uwait 0xfffffe005788a780 syz-executor.2
6142 1 780 0 S uwait 0xfffffe00a69bcb80 syz-executor.1
6138 1 782 0 S uwait 0xfffffe005788a980 syz-executor.2
6133 1 780 0 S uwait 0xfffffe0058b23c80 syz-executor.1
6131 1 780 0 S uwait 0xfffffe00a69bd000 syz-executor.1
6130 1 782 0 S umtxn 0xfffffe00a69bc080 syz-executor.2
6121 1 780 0 S umtxn 0xfffffe0057328180 syz-executor.1
5601 0 0 0 DL - 0xffffffff83f639c0 [soaiod4]
5600 0 0 0 DL - 0xffffffff83f639c0 [soaiod3]
5599 0 0 0 DL - 0xffffffff83f639c0 [soaiod2]
5598 0 0 0 DL - 0xffffffff83f639c0 [soaiod1]
5029 1 781 0 SV uwait 0xfffffe00a69bba00 syz-executor.3
5021 1 781 0 SV uwait 0xfffffe00a69bb400 syz-executor.3
5009 1 781 0 SV uwait 0xfffffe005788cc00 syz-executor.3
4996 1 781 0 SV uwait 0xfffffe00a69bb600 syz-executor.3
4729 1 782 0 S umtxn 0xfffffe00a69bc980 syz-executor.2
4246 1 779 0 S uwait 0xfffffe00a69bcc80 syz-executor.0
4245 1 780 0 S uwait 0xfffffe00a69be180 syz-executor.1
4242 1 779 0 S uwait 0xfffffe005788a580 syz-executor.0
4241 1 780 0 S uwait 0xfffffe00a69bda80 syz-executor.1
4238 1 780 0 S uwait 0xfffffe00a69bc880 syz-executor.1
4237 1 779 0 S uwait 0xfffffe00a69bb800 syz-executor.0
4231 1 780 0 S umtxn 0xfffffe00a69bb200 syz-executor.1
3837 1 3837 65 Ss select 0xfffffe00578fadc0 dhclient
3542 1 780 0 S uwait 0xfffffe00a69bd580 syz-executor.1
3072 1 3072 0 Ss select 0xfffffe00a6526240 dhclient
3069 1 3069 0 Ss select 0xfffffe00a63058c0 dhclient
3042 1 3042 65 Ss select 0xfffffe00a6305bc0 dhclient
2880 1 781 0 S uwait 0xfffffe00a69bca80 syz-executor.3
2570 1 781 0 S uwait 0xfffffe0058b20800 syz-executor.3
2569 1 781 0 S uwait 0xfffffe00a69bd480 syz-executor.3
2564 0 0 0 DL mdwait 0xfffffe0058d56000 [md3]
2559 1 781 0 S uwait 0xfffffe00a69bd100 syz-executor.3
2557 1 781 0 S uwait 0xfffffe0057889380 syz-executor.3
2556 0 0 0 DL mdwait 0xfffffe0058d57000 [md2]
2552 0 0 0 DL mdwait 0xfffffe0008173000 [md1]
2545 0 0 0 DL mdwait 0xfffffe00a5ca0000 [md0]
2541 1 781 0 S uwait 0xfffffe00a69bd380 syz-executor.3
2540 1 781 0 S uwait 0xfffffe005788c380 syz-executor.3
2536 1 779 0 S umtxn 0xfffffe0057889700 syz-executor.0
2535 1 779 0 S uwait 0xfffffe00a69be080 syz-executor.0
2533 1 782 0 S uwait 0xfffffe00a69bdb80 syz-executor.2
2532 1 782 0 S umtxn 0xfffffe005788a400 syz-executor.2
2531 1 780 0 S umtxn 0xfffffe005732a280 syz-executor.1
2530 1 780 0 S uwait 0xfffffe00a69bde00 syz-executor.1
2528 1 781 0 S uwait 0xfffffe005788cf00 syz-executor.3
2527 1 781 0 S uwait 0xfffffe00a69bdf00 syz-executor.3
2524 1 779 0 S uwait 0xfffffe00a69bd980 syz-executor.0
2523 1 779 0 S uwait 0xfffffe0057889d00 syz-executor.0
2521 1 782 0 S uwait 0xfffffe005788a200 syz-executor.2
2520 1 782 0 S uwait 0xfffffe00a69bd880 syz-executor.2
2519 1 781 0 S uwait 0xfffffe005732ac00 syz-executor.3
2518 1 781 0 S uwait 0xfffffe005788a280 syz-executor.3
2517 1 780 0 S uwait 0xfffffe00a69be480 syz-executor.1
2516 1 780 0 S uwait 0xfffffe005788c500 syz-executor.1
2512 1 779 0 S uwait 0xfffffe005732ae00 syz-executor.0
2511 1 779 0 S uwait 0xfffffe00a69be280 syz-executor.0
2509 1 780 0 S uwait 0xfffffe005788ce00 syz-executor.1
2508 1 782 0 S uwait 0xfffffe0058b20600 syz-executor.2
2507 1 780 0 S umtxn 0xfffffe0057889280 syz-executor.1
2506 1 781 0 S uwait 0xfffffe00a69be380 syz-executor.3
2505 1 782 0 S uwait 0xfffffe0057889900 syz-executor.2
2504 1 781 0 S uwait 0xfffffe005788a080 syz-executor.3
2497 1 781 0 S uwait 0xfffffe0058b20900 syz-executor.3
2496 1 781 0 S umtxn 0xfffffe005788c900 syz-executor.3
2246 1 2246 0 Ss select 0xfffffe00578fa940 dhclient
2243 1 2243 0 Ss select 0xfffffe0053ff6440 dhclient
2224 1 2224 65 Ss select 0xfffffe00a63061c0 dhclient
1936 1 782 0 S uwait 0xfffffe005788c700 syz-executor.2
1931 1 782 0 S uwait 0xfffffe0057327b00 syz-executor.2
1926 1 782 0 S uwait 0xfffffe0058b23280 syz-executor.2
1920 1 782 0 S uwait 0xfffffe0057889800 syz-executor.2
1655 1 1655 0 Ss select 0xfffffe00a63051c0 dhclient
1649 1 1649 0 Ss select 0xfffffe00578fabc0 dhclient
1628 1 1628 65 Ss select 0xfffffe00578fb440 dhclient
1604 0 0 0 DL aiordy 0xfffffe00a5ca5000 [aiod4]
1603 0 0 0 DL aiordy 0xfffffe0058ca2a90 [aiod3]
1602 0 0 0 DL aiordy 0xfffffe00a64df000 [aiod2]
1601 0 0 0 DL aiordy 0xfffffe00a64de548 [aiod1]
1538 1 779 0 S umtxn 0xfffffe0058b22a00 syz-executor.0
1531 1 779 0 S uwait 0xfffffe0058b21580 syz-executor.0
1524 1 782 0 S uwait 0xfffffe0058b22c00 syz-executor.2
1520 1 780 0 S uwait 0xfffffe0058b23080 syz-executor.1
1518 1 781 0 S uwait 0xfffffe0057889b00 syz-executor.3
1516 1 779 0 S umtxn 0xfffffe0058b21480 syz-executor.0
1514 1 782 0 S umtxn 0xfffffe0058b20500 syz-executor.2
1512 1 780 0 S uwait 0xfffffe0058b22f00 syz-executor.1
1510 1 781 0 S umtxn 0xfffffe0057327f00 syz-executor.3
1508 1 779 0 S uwait 0xfffffe0058b22b00 syz-executor.0
1506 1 782 0 S uwait 0xfffffe0057329880 syz-executor.2
1504 1 780 0 S uwait 0xfffffe0058b23380 syz-executor.1
1502 1 781 0 S uwait 0xfffffe0058b22d00 syz-executor.3
1500 1 779 0 S uwait 0xfffffe005732a980 syz-executor.0
1495 1 779 0 S uwait 0xfffffe0058b21c80 syz-executor.0
1490 1 779 0 S uwait 0xfffffe005732a380 syz-executor.0
988 1 988 0 Ss select 0xfffffe00578fbd40 dhclient
985 1 985 0 Ss select 0xfffffe00578fbc40 dhclient
782 774 782 0 Ss piperd 0xfffffe0058bde000 syz-executor.2
781 774 781 0 Ss piperd 0xfffffe0058bc4000 syz-executor.3
780 774 780 0 Ss nanslp 0xffffffff83e43c81 syz-executor.1
779 774 779 0 Ss nanslp 0xffffffff83e43c81 syz-executor.0
774 772 772 0 S (threaded) syz-fuzzer
100103 S uwait 0xfffffe0057327c00 syz-fuzzer
100118 S uwait 0xfffffe0058b22400 syz-fuzzer
100119 S uwait 0xfffffe0058b22300 syz-fuzzer
100120 S uwait 0xfffffe0058b22200 syz-fuzzer
100121 S kqread 0xfffffe0007957200 syz-fuzzer
100122 S uwait 0xfffffe0058b20c00 syz-fuzzer
100123 S uwait 0xfffffe0058b20d00 syz-fuzzer
100124 S uwait 0xfffffe0058b20e00 syz-fuzzer
100125 S uwait 0xfffffe0058b21000 syz-fuzzer
772 770 772 0 Ss pause 0xfffffe009e8ce5f8 csh
770 688 770 0 Ss select 0xfffffe0056f6aac0 sshd
754 1 754 0 Ss+ ttyin 0xfffffe00574764b0 getty
753 1 753 0 Ss+ ttyin 0xfffffe00574728b0 getty
752 1 752 0 Ss+ ttyin 0xfffffe0057472cb0 getty
751 1 751 0 Ss+ ttyin 0xfffffe00579c30b0 getty
750 1 750 0 Ss+ ttyin 0xfffffe00579c34b0 getty
749 1 749 0 Ss+ ttyin 0xfffffe00579c38b0 getty
748 1 748 0 Ss+ ttyin 0xfffffe00579c3cb0 getty
747 1 747 0 Ss+ ttyin 0xfffffe00579c40b0 getty
746 1 746 0 Ss+ ttyin 0xfffffe00579c44b0 getty
692 1 692 0 Ss nanslp 0xffffffff83e43c80 cron
688 1 688 0 Ss select 0xfffffe0056f6acc0 sshd
501 1 501 0 Ss select 0xfffffe0056f6b140 syslogd
430 1 430 0 Ss select 0xfffffe0056f6b1c0 devd
429 1 429 65 Ss select 0xfffffe0056f6b040 dhclient
344 1 344 0 Ss select 0xfffffe0056f6b0c0 dhclient
341 1 341 0 Ss select 0xfffffe0056f6b3c0 dhclient
17 0 0 0 DL vlruwt 0xfffffe0056fa0548 [vnlru]
16 0 0 0 DL syncer 0xffffffff83f694e0 [syncer]
15 0 0 0 DL (threaded) [bufdaemon]
100079 D psleep 0xffffffff83f67ae0 [bufdaemon]
100082 D - 0xffffffff83211f80 [bufspacedaemon-0]
100093 D sdflush 0xfffffe00574720e8 [/ worker]
9 0 0 0 DL psleep 0xffffffff83f9b5c0 [vmdaemon]
8 0 0 0 DL (threaded) [pagedaemon]
100077 D psleep 0xffffffff83f8f478 [dom0]
100083 D launds 0xffffffff83f8f484 [laundry: dom0]
100084 D umarcl 0xffffffff81e4ae30 [uma]
7 0 0 0 DL - 0xffffffff83c002a8 [rand_harvestq]
6 0 0 0 DL pftm 0xffffffff84581550 [pf purge]
5 0 0 0 DL waiting 0xffffffff84b63460 [sctp_iterator]
4 0 0 0 DL (threaded) [cam]
100044 D - 0xffffffff83aa3240 [doneq0]
100045 D - 0xffffffff83aa31c0 [async]
100076 D - 0xffffffff83aa3040 [scanner]
14 0 0 0 DL seqstat 0xfffffe0053fd7488 [sequencer 00]
3 0 0 0 DL (threaded) [crypto]
100040 D crypto_ 0xffffffff83f8aca0 [crypto]
100041 D crypto_ 0xfffffe0053ecd830 [crypto returns 0]
100042 D crypto_ 0xfffffe0053ecd880 [crypto returns 1]
13 0 0 0 DL (threaded) [geom]
100035 D - 0xffffffff83e19280 [g_event]
100036 D - 0xffffffff83e192a0 [g_up]
100037 D - 0xffffffff83e192c0 [g_down]
2 0 0 0 RL (threaded) [clock]
100029 Run CPU 0 [clock (0)]
100030 I [clock (1)]
12 0 0 0 RL (threaded) [intr]
100015 I [swi5: fast taskq]
100018 I [swi6: task queue]
100019 I [swi6: Giant taskq]
100031 Run CPU 1 [swi1: netisr 0]
100032 I [swi1: hpts]
100033 I [swi1: hpts]
100046 I [irq24: virtio_pci0]
100047 I [irq25: virtio_pci0]
100048 I [irq26: virtio_pci0]
100049 I [irq27: virtio_pci0]
100050 I [irq28: virtio_pci1]
100051 I [irq29: virtio_pci1]
100052 I [irq30: virtio_pci1]
100053 I [irq31: virtio_pci1]
100054 I [irq32: virtio_pci1]
100059 I [irq33: virtio_pci2]
100060 I [irq34: virtio_pci2]
100061 I [irq35: virtio_pci2]
100063 I [irq1: atkbd0]
100064 I [irq12: psm0]
100065 I [swi0: uart uart++]
100069 I [swi1: pf send]
11 0 0 0 RL (threaded) [idle]
100003 CanRun [idle: cpu0]
100004 CanRun [idle: cpu1]
1 0 1 0 SLs wait 0xfffffe0053de1000 [init]
10 0 0 0 DL audit_w 0xffffffff83f8b780 [audit]
0 0 0 0 DLs (threaded) [kernel]
100000 D swapin 0xffffffff83e19c80 [swapper]
100005 D - 0xfffffe0053e84100 [if_config_tqg_0]
100006 D - 0xfffffe0053e84000 [softirq_0]
100007 D - 0xfffffe0053e83e00 [softirq_1]
100008 D - 0xfffffe0053e83d00 [if_io_tqg_0]
100009 D - 0xfffffe0053e83c00 [if_io_tqg_1]
100010 D - 0xfffffe000795a100 [inm_free taskq]
100011 D - 0xfffffe000795a000 [linuxkpi_irq_wq]
100012 D - 0xfffffe0007959e00 [in6m_free taskq]
100013 D - 0xfffffe0007959d00 [deferred_unmount ta]
100014 D - 0xfffffe0007959c00 [thread taskq]
100016 D - 0xfffffe0007959a00 [kqueue_ctx taskq]
100017 D - 0xfffffe0007959900 [pci_hp taskq]
100020 D - 0xfffffe0007959600 [aiod_kick taskq]
100021 D - 0xfffffe0007959500 [linuxkpi_short_wq_0]
100022 D - 0xfffffe0007959500 [linuxkpi_short_wq_1]
100023 D - 0xfffffe0007959500 [linuxkpi_short_wq_2]
100024 D - 0xfffffe0007959500 [linuxkpi_short_wq_3]
100025 D - 0xfffffe0007959400 [linuxkpi_long_wq_0]
100026 D - 0xfffffe0007959400 [linuxkpi_long_wq_1]
100027 D - 0xfffffe0007959400 [linuxkpi_long_wq_2]
100028 D - 0xfffffe0007959400 [linuxkpi_long_wq_3]
100034 D - 0xfffffe0007959300 [firmware taskq]
100038 D - 0xfffffe0007959200 [crypto_0]
100039 D - 0xfffffe0007959200 [crypto_1]
100055 D - 0xfffffe0007959000 [vtnet0 rxq 0]
100056 D - 0xfffffe0007958e00 [vtnet0 txq 0]
100057 D - 0xfffffe0007958d00 [vtnet0 rxq 1]
100058 D - 0xfffffe0007958c00 [vtnet0 txq 1]
100062 D vtbslp 0xfffffe0056f6c000 [virtio_balloon]
100066 D - 0xffffffff82b5e681 [deadlkres]
100070 D - 0xfffffe000795a200 [mca taskq]
100071 D - 0xfffffe00585ef600 [acpi_task_0]
100072 D - 0xfffffe00585ef600 [acpi_task_1]
100073 D - 0xfffffe00585ef600 [acpi_task_2]
100075 D - 0xfffffe0007959100 [CAM taskq]
db> show all locks
db> show malloc
Type InUse MemUse Requests
pf_hash 5 11524K 5
tcp_hpts 7 4801K 7
devbuf 4217 4323K 4250
sysctloid 35790 2109K 35861
vtbuf 24 1968K 46
filedesc 220 1756K 16629
kobj 328 1312K 535
pcb 622 1205K 17415
newblk 217 1078K 30466
vfscache 3 1025K 3
subproc 358 755K 9509
inodedep 82 543K 9514
ufs_quota 1 512K 1
vfs_hash 1 512K 1
callout 2 512K 2
intr 4 472K 4
vmem 3 276K 6
sctp_stro 241 241K 4121
sctp_atcl 557 209K 13429
acpica 1674 184K 57552
vnet_data 1 168K 1
tidhash 3 141K 3
linker 358 134K 386
pagedep 19 133K 8330
tfo_ccache 1 128K 1
DEVFS1 114 114K 131
sem 4 106K 4
BPF 46 88K 92
bus 995 81K 5208
kdtrace 428 75K 20946
mtx_pool 2 72K 2
umtx 550 69K 550
syncache 1 68K 1
module 514 65K 514
acpitask 1 64K 1
ddb_capture 1 64K 1
sctp_atky 804 34K 18476
DEVFS3 133 34K 143
temp 34 33K 4153
filemon 4 32K 112
hostcache 1 32K 1
shm 1 32K 1
msg 4 30K 4
gtaskqueue 18 26K 18
kbdmux 6 22K 6
md_disk 9 21K 9
ifaddr 70 20K 73
DEVFS_RULE 56 20K 56
lltable 55 18K 386
ufs_mount 4 17K 5
proc 3 17K 3
sctp_timw 64 16K 64
tty 16 16K 16
md_sectors 4 16K 4
routetbl 130 16K 1898
ithread 97 16K 97
dirrem 62 16K 9081
GEOM 96 16K 656
bus-sc 34 15K 1681
ksem 35 14K 232
kqueue 173 13K 9417
KTRACE 100 13K 128
ifnet 7 13K 7
ether_multi 152 13K 179
devstat 6 13K 6
eventhandler 136 12K 136
kenv 95 12K 95
pwddesc 171 11K 9374
rman 88 11K 431
CAM queue 5 11K 1528
sctp_athm 557 9K 13991
in6_multi 65 9K 65
bmsafemap 2 9K 9685
UART 12 9K 12
rpc 2 8K 2
shmfd 1 8K 1
pfs_vncache 1 8K 1
crypto 11 8K 258
sctp_map 482 8K 8308
pfs_nodes 20 8K 20
audit_evclass 237 8K 296
freefile 59 8K 8934
lockf 65 7K 185
taskqueue 63 7K 63
sctp_stri 13 7K 1230
cred 26 7K 297
sglist 5 7K 5
CAM DEV 3 6K 510
plimit 24 6K 480
pf_ifnet 16 6K 483
proc-args 193 6K 10693
freework 20 5K 17011
DEVFSP 79 5K 756
ufs_dirhash 24 5K 24
UMA 276 5K 276
session 35 5K 81
vt 11 5K 11
memdesc 1 4K 1
MCA 32 4K 32
evdev 4 4K 4
ip6opt 28 4K 191
acpisem 28 4K 28
selfd 55 4K 126463
hhook 15 4K 17
kcovinfo 52 4K 52
indirdep 11 3K 12561
terminal 11 3K 11
CC Mem 39 3K 3880
select 19 3K 165
uidinfo 3 3K 20
local_apic 1 2K 1
io_apic 1 2K 1
fpukern_ctx 2 2K 2
ipsec-saq 2 2K 2
sctp_aadr 30 2K 57
ip6ndp 12 2K 13
newdirblk 14 2K 8223
freeblks 7 2K 9355
Unitno 29 2K 387
cryptodev 23 2K 1082
sctp_ifa 13 2K 14
inpcbpolicy 51 2K 5342
CAM XPT 22 2K 543
msi 12 2K 12
in_multi 6 2K 12
ipsecpolicy 2 2K 2
acpidev 20 2K 20
clone 9 2K 9
tun 7 2K 7
softdep 1 1K 1
mkdir 8 1K 16446
sahead 1 1K 1
secasvar 1 1K 1
nhops 6 1K 8
vnodemarker 2 1K 358
NFSD session 1 1K 1
osd 43 1K 3804
pf_osfp 8 1K 8
CAM periph 4 1K 271
sctp_ifn 6 1K 14
tcp_fsb 21 1K 1031
ipsec 3 1K 3
mld 6 1K 6
igmp 6 1K 6
toponodes 6 1K 6
isadev 6 1K 6
mount 16 1K 89
pci_link 10 1K 10
encap_export_host 12 1K 12
procdesc 5 1K 18
filedesc_to_leader 9 1K 18
diradd 4 1K 9121
pfil 4 1K 4
cdev 2 1K 2
chacha20random 1 1K 1
NFSD lckfile 1 1K 1
NFSD V4client 1 1K 1
DEVFS 9 1K 10
vnodes 1 1K 8
CAM SIM 2 1K 2
feeder 7 1K 7
tcpfunc 3 1K 3
loginclass 3 1K 6
prison 6 1K 6
lkpikmalloc 5 1K 6
aesni_data 2 1K 2
soname 6 1K 15506
nexusdev 8 1K 8
apmdev 1 1K 1
atkbddev 2 1K 2
CAM dev queue 2 1K 2
CAM I/O Scheduler 1 1K 1
CAM path 4 1K 1034
pmchooks 1 1K 1
filecaps 5 1K 118
sctp_vrf 1 1K 1
ip_msource 1 1K 1
vnet 1 1K 1
entropy 2 1K 47
pmc 1 1K 1
acpiintr 1 1K 1
sigio 1 1K 6
cpus 2 1K 2
vnet_data_free 1 1K 1
Per-cpu 1 1K 1
p1003.1b 1 1K 1
mqdata 0 0K 0
sctp_mcore 0 0K 0
sctp_socko 0 0K 6495
sctp_iter 0 0K 43
sctp_mvrf 0 0K 0
sctp_cpal 0 0K 43
sctp_cmsg 0 0K 0
sctp_stre 0 0K 0
sctp_athi 0 0K 0
sctp_a_it 0 0K 14
ipcomp 0 0K 0
esp 0 0K 0
ah 0 0K 0
pf_table 0 0K 372
pf_rule 0 0K 199
pf_altq 0 0K 0
pf_temp 0 0K 0
NFSCL layrecall 0 0K 0
NFSCL session 0 0K 0
madt_table 0 0K 2
smartpqi 0 0K 0
NFSCL sockreq 0 0K 0
NFSCL devinfo 0 0K 0
NFSCL flayout 0 0K 0
ixl 0 0K 0
NFSCL layout 0 0K 0
NFSD rollback 0 0K 0
NFSCL diroff 0 0K 0
NEWdirectio 0 0K 0
NEWNFSnode 0 0K 0
NFSCL lck 0 0K 0
NFSCL lckown 0 0K 0
ice-resmgr 0 0K 0
ice-osdep 0 0K 0
ice 0 0K 0
iavf 0 0K 0
axgbe 0 0K 0
NFSCL client 0 0K 0
NFSCL deleg 0 0K 0
NFSCL open 0 0K 0
NFSCL owner 0 0K 0
NFS fh 0 0K 0
NFS req 0 0K 0
NFSD usrgroup 0 0K 0
NFSD string 0 0K 0
NFSD V4lock 0 0K 0
xen_intr 0 0K 0
NFSD V4state 0 0K 0
xen_hvm 0 0K 0
legacydrv 0 0K 0
bounce 0 0K 0
busdma 0 0K 0
qpidrv 0 0K 0
NFSD srvcache 0 0K 0
msdosfs_fat 0 0K 0
dmar_idpgtbl 0 0K 0
dmar_dom 0 0K 0
dmar_ctx 0 0K 0
msdosfs_mount 0 0K 0
msdosfs_node 0 0K 0
isci 0 0K 0
iommu_dmamap 0 0K 0
hyperv_socket 0 0K 0
bxe_ilt 0 0K 0
xenbus 0 0K 0
DEVFS4 0 0K 0
vm_fictitious 0 0K 0
DEVFS2 0 0K 0
gntdev 0 0K 0
privcmd_dev 0 0K 0
evtchn_dev 0 0K 0
xenstore 0 0K 0
scsi_pass 0 0K 0
ciss_data 0 0K 0
xnb 0 0K 0
xen_acpi 0 0K 0
xbbd 0 0K 0
xbd 0 0K 0
UMAHash 0 0K 0
Balloon 0 0K 0
sysmouse 0 0K 0
vm_pgdata 0 0K 0
jblocks 0 0K 0
savedino 0 0K 8421
sentinel 0 0K 0
jfsync 0 0K 0
jtrunc 0 0K 0
sbdep 0 0K 177
jsegdep 0 0K 0
jseg 0 0K 0
jfreefrag 0 0K 0
jfreeblk 0 0K 0
jnewblk 0 0K 0
jmvref 0 0K 0
jremref 0 0K 0
jaddref 0 0K 0
freedep 0 0K 0
freefrag 0 0K 94
allocindir 0 0K 0
allocdirect 0 0K 0
ufs_trim 0 0K 0
mactemp 0 0K 0
audit_trigger 0 0K 0
audit_pipe_presel 0 0K 0
audit_pipeent 0 0K 0
audit_pipe 0 0K 0
audit_evname 0 0K 0
audit_bsm 0 0K 0
audit_gidset 0 0K 0
audit_text 0 0K 0
audit_path 0 0K 0
audit_data 0 0K 0
audit_cred 0 0K 0
vtfont 0 0K 0
BACKLIGHT 0 0K 0
ath_hal 0 0K 0
athdev 0 0K 0
ata_pci 0 0K 0
ata_dma 0 0K 0
ata_generic 0 0K 0
pvscsi 0 0K 0
scsi_da 0 0K 69
ata_da 0 0K 0
scsi_ch 0 0K 0
scsi_cd 0 0K 0
ktls_ocf 0 0K 0
AHCI driver 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5E_TLS_RX 0 0K 0
MLX5EEPROM 0 0K 0
MLX5E_TLS 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EN 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5DUMP 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
seq_file 0 0K 0
lkpiskb 0 0K 0
radix 0 0K 0
idr 0 0K 0
lkpindev 0 0K 0
lkpifw 0 0K 0
lkpi80211 0 0K 0
NLM 0 0K 0
ipsec-spdcache 0 0K 0
ipsec-reg 0 0K 0
ipsec-misc 0 0K 0
ipsecrequest 0 0K 0
ip6_msource 0 0K 0
ip6_moptions 0 0K 1
in6_mfilter 0 0K 0
frag6 0 0K 0
tcplog 0 0K 0
tcp_hwpace 0 0K 0
USBdev 0 0K 0
USB 0 0K 0
LRO 0 0K 0
ip_moptions 0 0K 8
in_mfilter 0 0K 7
ipid 0 0K 0
80211scan 0 0K 0
80211ratectl 0 0K 0
80211power 0 0K 0
80211nodeie 0 0K 0
80211node 0 0K 0
80211mesh_gt 0 0K 0
80211mesh_rt 0 0K 0
80211perr 0 0K 0
80211prep 0 0K 0
80211preq 0 0K 0
80211dfs 0 0K 0
80211crypto 0 0K 0
80211vap 0 0K 0
iflib 0 0K 0
vlan 0 0K 0
gif 0 0K 0
ifdescr 0 0K 0
zlib 0 0K 0
fadvise 0 0K 0
VN POLL 0 0K 4
agp 0 0K 0
statfs 0 0K 8429
namei_tracker 0 0K 0
export_host 0 0K 0
cl_savebuf 0 0K 31
nvme_da 0 0K 0
acpipwr 0 0K 0
acpi_perf 0 0K 0
twsbuf 0 0K 0
twe_commands 0 0K 0
tcp_log_dev 0 0K 438
midi buffers 0 0K 0
mixer 0 0K 0
ac97 0 0K 0
hdacc 0 0K 0
hdac 0 0K 0
hdaa 0 0K 0
acpicmbat 0 0K 0
SIIS driver 0 0K 0
CAM CCB 0 0K 523
biobuf 0 0K 0
aios 0 0K 0
lio 0 0K 82
acl 0 0K 0
mbuf_tag 0 0K 232
ktls 0 0K 0
PUC 0 0K 0
ppbusdev 0 0K 0
agtiapi_MemAlloc malloc 0 0K 0
osti_cacheable 0 0K 0
tempbuff 0 0K 0
tempbuff 0 0K 0
ag_tgt_map_t malloc 0 0K 0
ag_slr_map_t malloc 0 0K 0
lDevFlags * malloc 0 0K 0
tiDeviceHandle_t * malloc 0 0K 0
ag_portal_data_t malloc 0 0K 0
ag_device_t malloc 0 0K 0
STLock malloc 0 0K 0
CCB List 0 0K 0
sr_iov 0 0K 0
OCS 0 0K 0
OCS 0 0K 0
nvme 0 0K 0
nvd 0 0K 0
netmap 0 0K 0
mwldev 0 0K 0
MVS driver 0 0K 0
CAM ccb queue 0 0K 0
accf 0 0K 0
pts 0 0K 0
iov 0 0K 20854
ioctlops 0 0K 874
eventfd 0 0K 4
Witness 0 0K 0
stack 0 0K 0
mrsasbuf 0 0K 0
mpt_user 0 0K 0
mps_user 0 0K 0
MPSSAS 0 0K 0
mps 0 0K 0
sbuf 0 0K 348
mpr_user 0 0K 0
firmware 0 0K 0
compressor 0 0K 0
MPRSAS 0 0K 0
SWAP 0 0K 0
mpr 0 0K 0
mfibuf 0 0K 0
sysctltmp 0 0K 925
sysctl 0 0K 3
ekcd 0 0K 0
dumper 0 0K 0
sendfile 0 0K 5
rctl 0 0K 0
malodev 0 0K 0
LED 0 0K 0
ix_sriov 0 0K 0
cache 0 0K 0
aacraidcam 0 0K 0
prison_racct 0 0K 0
Fail Points 0 0K 0
pwd 0 0K 0
tty console 0 0K 0
ix 0 0K 0
ipsbuf 0 0K 0
aacraid_buf 0 0K 0
aaccam 0 0K 0
boottrace 0 0K 0
aacbuf 0 0K 0
zstd 0 0K 0
XZ_DEC 0 0K 0
nvlist 0 0K 0
SCSI ENC 0 0K 0
SCSI sa 0 0K 0
isofs_node 0 0K 0
isofs_mount 0 0K 0
tr_raid5_data 0 0K 0
tr_raid1e_data 0 0K 0
tr_raid1_data 0 0K 0
tr_raid0_data 0 0K 0
tr_concat_data 0 0K 0
md_sii_data 0 0K 0
md_promise_data 0 0K 0
md_nvidia_data 0 0K 0
md_jmicron_data 0 0K 0
md_intel_data 0 0K 0
md_ddf_data 0 0K 0
raid_data 0 0K 102
geom_flashmap 0 0K 0
tmpfs dir 0 0K 0
tmpfs name 0 0K 0
tmpfs mount 0 0K 0
NFS FHA 0 0K 0
newnfsmnt 0 0K 0
newnfsclient_req 0 0K 0
db> show uma
Zone Size Used Free Requests Sleeps Bucket Total Mem XFree
mbuf_jumbo_page 4096 8323 3869 1118465 0 254 49938432 0
tcp_log 416 18271 10943 1017238 0 254 12153024 0
mbuf 256 9272 9016 4492873 0 254 4681728 0
pbuf 2624 0 957 0 0 2 2511168 0
RADIX NODE 144 16413 354 258562 0 63 2414448 0
malloc-16384 16384 113 6 8476 0 1 1949696 0
sctp_asoc 2256 241 524 4048 0 254 1725840 0
BUF TRIE 144 314 11474 20375 0 62 1697472 0
malloc-384 384 4169 31 4510 0 30 1612800 0
UMA Slabs 0 112 14211 3 14211 0 126 1591968 0
mbuf_cluster 2048 762 0 762 0 254 1560576 0
malloc-128 128 11782 215 21085 0 126 1535616 0
vmem btag 56 26364 99 26364 0 254 1481928 0
ertt_txseginfo 40 1309 34849 1527175 0 254 1446320 0
malloc-4096 4096 328 2 539 0 2 1351680 0
256 Bucket 2048 422 60 16746 0 8 987136 0
VM OBJECT 264 3573 87 152037 0 30 966240 0
sctp_ep 1208 303 467 8642 0 254 930160 0
malloc-4096 4096 193 5 9353 0 2 811008 0
FFS inode 1160 635 30 9585 0 8 771400 0
malloc-2048 2048 300 20 8837 0 8 655360 0
MAP ENTRY 96 5698 350 399390 0 126 580608 0
sctp_raddr 736 245 525 4729 0 254 566720 0
tcpcb 1104 39 472 3793 0 254 564144 0
tcp_bbr_map 128 400 3661 357734 0 126 519808 0
THREAD 1808 256 19 11624 0 8 497200 0
socket 960 137 371 15418 0 254 487680 0
malloc-65536 65536 4 2 140 0 1 393216 0
lkpimm 168 1 2327 1 0 62 391104 0
lkpicurr 168 2 2326 2 0 62 391104 0
VMSPACE 2552 141 12 9293 0 4 390456 0
VNODE 448 675 108 9627 0 30 350784 0
sctp_chunk 152 239 2049 77276 0 254 347776 0
malloc-64 64 4305 546 14152 0 254 310464 0
malloc-1024 1024 248 40 4029 0 16 294912 0
malloc-65536 65536 2 2 29 0 1 262144 0
malloc-32768 32768 1 7 11906 0 1 262144 0
PROC 1352 170 16 9320 0 8 251472 0
malloc-16 16 14855 395 15008 0 254 244000 0
malloc-384 384 559 71 13431 0 30 241920 0
FPU_save_area 832 258 30 17843 0 16 239616 0
DEVCTL 1024 0 220 164 0 0 225280 0
malloc-256 256 524 346 83798 0 62 222720 0
filedesc0 1072 171 25 9374 0 8 210112 0
malloc-65536 65536 1 2 182 0 1 196608 0
mbuf_packet 256 162 600 214179 0 254 195072 0
UMA Zones 768 248 1 248 0 16 191232 0
malloc-32 32 5421 501 5837 0 254 189504 0
malloc-128 128 1226 169 27096 0 126 178560 0
FFS2 dinode 256 635 55 9583 0 62 176640 0
malloc-384 384 95 325 10329 0 30 161280 0
S VFS Cache 104 1022 499 10313 0 126 158184 0
128 Bucket 1024 99 48 5164 0 16 150528 0
malloc-1024 1024 128 16 492 0 16 147456 0
malloc-65536 65536 0 2 432 0 1 131072 0
malloc-8192 8192 10 6 287 0 1 131072 0
unpcb 256 20 490 1372 0 254 130560 0
malloc-256 256 389 121 9258 0 62 130560 0
malloc-256 256 154 356 11201 0 62 130560 0
clpbuf 2624 0 48 201 0 16 125952 0
ksiginfo 112 167 877 6582 0 126 116928 0
malloc-128 128 451 448 17978 0 126 115072 0
malloc-256 256 305 130 11815 0 62 111360 0
malloc-128 128 532 243 5216 0 126 99200 0
malloc-128 128 598 177 1820 0 126 99200 0
UMA Kegs 384 234 9 234 0 30 93312 0
syncache 168 0 528 26 0 254 88704 0
64 Bucket 512 84 84 8826 0 30 86016 0
malloc-64 64 840 483 10745 0 254 84672 0
malloc-2048 2048 5 35 1521 0 8 81920 0
malloc-384 384 187 23 359 0 30 80640 0
g_bio 408 0 180 182879 0 30 73440 0
malloc-64 64 582 489 1518 0 254 68544 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-32768 32768 0 2 120 0 1 65536 0
malloc-32768 32768 0 2 7 0 1 65536 0
malloc-4096 4096 13 3 27 0 2 65536 0
malloc-2048 2048 7 25 996 0 8 65536 0
32 Bucket 256 99 156 6442 0 62 65280 0
Files 80 447 353 35148 0 126 64000 0
sctp_stream_msg_out 112 91 449 1344 0 254 60480 0
udp_inpcb 424 6 120 1299 0 30 53424 0
tcp_inpcb 424 39 87 3793 0 30 53424 0
malloc-128 128 182 221 780 0 126 51584 0
malloc-128 128 188 215 317 0 126 51584 0
malloc-128 128 46 357 16906 0 126 51584 0
TURNSTILE 136 276 102 276 0 62 51408 0
malloc-256 256 55 140 1726 0 62 49920 0
DIRHASH 1024 35 13 35 0 16 49152 0
NAMEI 1024 0 48 53145 0 16 49152 0
malloc-16384 16384 2 1 18 0 1 49152 0
malloc-8192 8192 6 0 6 0 1 49152 0
malloc-4096 4096 7 5 8506 0 2 49152 0
malloc-2048 2048 10 14 28 0 8 49152 0
malloc-1024 1024 27 21 43 0 16 49152 0
malloc-1024 1024 6 42 531 0 16 49152 0
pcpu-8 8 4816 1328 15753 0 254 49152 0
tcp_rack_pcb 896 1 53 1011 0 16 48384 0
pipe 744 33 32 747 0 16 48360 0
malloc-384 384 58 62 389 0 30 46080 0
tcp_bbr_pcb 832 1 53 1331 0 16 44928 0
malloc-32 32 814 572 16177 0 254 44352 0
malloc-8192 8192 4 1 6 0 1 40960 0
malloc-8192 8192 5 0 5 0 1 40960 0
malloc-4096 4096 8 2 8 0 2 40960 0
sctp_readq 152 0 260 642 0 254 39520 0
Mountpoints 2752 2 12 2 0 4 38528 0
udplite_inpcb 424 0 90 120 0 30 38160 0
ripcb 424 6 84 130 0 30 38160 0
hostcache 64 5 562 5 0 254 36288 0
PWD 32 97 1037 8295 0 254 36288 0
malloc-64 64 3 564 17472 0 254 36288 0
malloc-64 64 216 351 301 0 254 36288 0
malloc-64 64 294 273 136000 0 254 36288 0
malloc-64 64 208 359 10372 0 254 36288 0
malloc-64 64 18 549 389 0 254 36288 0
16 Bucket 144 73 179 2095 0 62 36288 0
routing nhops 256 27 108 34 0 62 34560 0
ttyoutq 256 72 63 160 0 62 34560 0
malloc-384 384 43 47 45 0 30 34560 0
malloc-256 256 2 133 1518 0 62 34560 0
malloc-256 256 46 89 50 0 62 34560 0
malloc-256 256 32 103 868 0 62 34560 0
SLEEPQUEUE 88 276 108 276 0 126 33792 0
malloc-32768 32768 1 0 1 0 1 32768 0
malloc-32768 32768 1 0 1 0 1 32768 0
malloc-16384 16384 0 2 2 0 1 32768 0
malloc-4096 4096 6 2 635 0 2 32768 0
malloc-2048 2048 2 14 66 0 8 32768 0
malloc-2048 2048 2 14 43 0 8 32768 0
malloc-1024 1024 0 32 67 0 16 32768 0
malloc-1024 1024 8 24 41 0 16 32768 0
malloc-1024 1024 6 26 1415 0 16 32768 0
malloc-512 512 11 53 367 0 30 32768 0
malloc-512 512 3 61 185 0 30 32768 0
malloc-512 512 0 64 28 0 30 32768 0
malloc-512 512 15 49 1232 0 30 32768 0
malloc-512 512 0 64 12 0 30 32768 0
malloc-512 512 10 54 114 0 30 32768 0
pcpu-64 64 493 19 493 0 254 32768 0
KNOTE 160 28 172 100076 0 62 32000 0
ttyinq 160 135 65 300 0 62 32000 0
tcp_rack_map 120 2 262 3097 0 126 31680 0
cpuset 104 7 272 649 0 126 29016 0
sctp_asconf_ack 48 0 588 11 0 254 28224 0
sctp_laddr 48 136 452 3235 0 254 28224 0
tcp_inpcb ports 32 14 868 2787 0 254 28224 0
4 Bucket 48 7 581 250 0 254 28224 0
2 Bucket 32 63 819 3197 0 254 28224 0
AIO 208 0 133 87 0 62 27664 0
da_ccb 544 0 49 45802 0 16 26656 0
malloc-8192 8192 2 1 4 0 1 24576 0
malloc-4096 4096 6 0 6 0 2 24576 0
rtentry 176 30 108 34 0 62 24288 0
PGRP 88 35 241 81 0 126 24288 0
rl_entry 40 158 448 158 0 254 24240 0
8 Bucket 80 54 246 2967

---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Dec 18, 2023, 9:48:25 PM12/18/23
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 92f58c69a14c Implement "strict key exchange" in ssh and ss..
git tree: freebsd-src
console output: https://syzkaller.appspot.com/x/log.txt?x=10e52276e80000
dashboard link: https://syzkaller.appspot.com/bug?extid=583ce35a13ec4552b187
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=14a14c9ee80000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=11be5569e80000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+583ce3...@syzkaller.appspotmail.com

panic: ASan: Invalid access, 8-byte write at 0xfffffe006d2978d8, UMAUseAfterFree(fd)
cpuid = 0
time = 1702953929
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0xc6/frame 0xfffffe0007bdc7b0
kdb_backtrace() at kdb_backtrace+0xd0/frame 0xfffffe0007bdc910
vpanic() at vpanic+0x271/frame 0xfffffe0007bdcab0
panic() at panic+0xb5/frame 0xfffffe0007bdcb70
kasan_code_name() at kasan_code_name/frame 0xfffffe0007bdcc40
kasan_atomic_fcmpset_acq_ptr() at kasan_atomic_fcmpset_acq_ptr+0x2fc/frame 0xfffffe0007bdcc70
__mtx_lock_flags() at __mtx_lock_flags+0x1d0/frame 0xfffffe0007bdcd50
sctp_sendall_completes() at sctp_sendall_completes+0x41/frame 0xfffffe0007bdcd70
sctp_iterator_worker() at sctp_iterator_worker+0x1022/frame 0xfffffe0007bdced0
sctp_iterator_thread() at sctp_iterator_thread+0x5e/frame 0xfffffe0007bdcef0
fork_exit() at fork_exit+0xcc/frame 0xfffffe0007bdcf30
fork_trampoline() at fork_trampoline+0xe/frame 0xfffffe0007bdcf30
--- trap 0, rip = 0, rsp = 0, rbp = 0 ---
KDB: enter: panic
[ thread pid 5 tid 100067 ]
Stopped at kdb_enter+0x6e: movq $0,0x2196097(%rip)
db>
db> set $lines = 0
db> set $maxwidth = 0
db> show registers
cs 0x20
ds 0x3b
es 0x3b
fs 0x13
gs 0x1b
ss 0x28
rax 0x12
rcx 0x1fffffc000f7b8ac
rdx 0xdffff7c000000000
rbx 0xffffffff826f2d60 .str.28
rsp 0xfffffe0007bdc8f0
rbp 0xfffffe0007bdc910
rsi 0x1
rdi 0
r8 0
r9 0xffffffff
r10 0x7
r11 0x6
r12 0
r13 0xfffffe00578fd000
r14 0xffffffff826f2d60 .str.28
r15 0
rip 0xffffffff815c5f7e kdb_enter+0x6e
rflags 0x46
kdb_enter+0x6e: movq $0,0x2196097(%rip)
db> show proc
Process 5 (sctp_iterator) at 0xfffffe0057a2b560:
state: NORMAL
uid: 0 gids: 0
parent: pid 0 at 0xffffffff836e6700
ABI: null
flag: 0x10000204 flag2: 0
reaper: 0xffffffff836e6700 reapsubtree: 5
sigparent: 20
vmspace: 0xffffffff836e76a0
(map 0xffffffff836e76a0)
(map.pmap 0xffffffff836e7760)
(pmap 0xffffffff836e77d0)
threads: 1
100067 Run CPU 0 [sctp_iterator]
db> ps
pid ppid pgrp uid state wmesg wchan cmd
61971 775 771 0 R syz-executor5881231
61970 778 61970 0 REs CPU 1 syz-executor5881231
61969 774 771 0 R syz-executor5881231
61968 777 771 0 R syz-executor5881231
778 773 771 0 R syz-executor5881231
777 773 771 0 S nanslp 0xffffffff8373d3c0 syz-executor5881231
775 773 771 0 S nanslp 0xffffffff8373d3c0 syz-executor5881231
774 773 771 0 R syz-executor5881231
773 771 771 0 S nanslp 0xffffffff8373d3c1 syz-executor5881231
771 769 771 0 Ss pause 0xfffffe0057a2cb90 csh
769 682 769 0 Ss select 0xfffffe00570f1ac0 sshd
748 1 748 0 Ss+ ttyin 0xfffffe00570c94b0 getty
747 1 747 0 Ss+ ttyin 0xfffffe0057a438b0 getty
746 1 746 0 Ss+ ttyin 0xfffffe0057a43cb0 getty
745 1 745 0 Ss+ ttyin 0xfffffe0057a440b0 getty
744 1 744 0 Ss+ ttyin 0xfffffe0057a444b0 getty
743 1 743 0 Ss+ ttyin 0xfffffe0057a448b0 getty
742 1 742 0 Ss+ ttyin 0xfffffe0057a44cb0 getty
741 1 741 0 Ss+ ttyin 0xfffffe0057a450b0 getty
740 1 740 0 Ss+ ttyin 0xfffffe0057a454b0 getty
686 1 686 0 Ss nanslp 0xffffffff8373d3c1 cron
682 1 682 0 Ss select 0xfffffe00570f1740 sshd
495 1 495 0 Ss select 0xfffffe00570f1ec0 syslogd
424 1 424 0 Ss select 0xfffffe00571c1040 devd
423 1 423 65 Ss select 0xfffffe00570f1b40 dhclient
338 1 338 0 Ss select 0xfffffe00570f1cc0 dhclient
335 1 335 0 Ss select 0xfffffe00570f1d40 dhclient
17 0 0 0 DL syncer 0xffffffff8385ab20 [syncer]
16 0 0 0 DL vlruwt 0xfffffe00571fe060 [vnlru]
15 0 0 0 DL (threaded) [bufdaemon]
100079 D psleep 0xffffffff83859100 [bufdaemon]
100082 D - 0xffffffff82c0a140 [bufspacedaemon-0]
100093 D sdflush 0xfffffe00589958e8 [/ worker]
9 0 0 0 DL psleep 0xffffffff838cbd80 [vmdaemon]
8 0 0 0 DL (threaded) [pagedaemon]
100077 D psleep 0xffffffff838b3bf8 [dom0]
100080 D launds 0xffffffff838b3c04 [laundry: dom0]
100081 D umarcl 0xffffffff81d5e250 [uma]
7 0 0 0 DL - 0xffffffff834bac10 [rand_harvestq]
6 0 0 0 DL pftm 0xffffffff83f9cd10 [pf purge]
5 0 0 0 RL CPU 0 [sctp_iterator]
4 0 0 0 DL (threaded) [cam]
100044 D - 0xffffffff83485340 [doneq0]
100045 D - 0xffffffff834852c0 [async]
100076 D - 0xffffffff83485140 [scanner]
3 0 0 0 DL (threaded) [crypto]
100041 D crypto_ 0xffffffff838af420 [crypto]
100042 D crypto_ 0xfffffe005719e030 [crypto returns 0]
100043 D crypto_ 0xfffffe005719e080 [crypto returns 1]
14 0 0 0 DL seqstat 0xfffffe0057105488 [sequencer 00]
13 0 0 0 DL (threaded) [geom]
100035 D - 0xffffffff836e5d20 [g_event]
100036 D - 0xffffffff836e5d40 [g_up]
100037 D - 0xffffffff836e5d60 [g_down]
2 0 0 0 WL (threaded) [clock]
100029 I [clock (0)]
100030 I [clock (1)]
12 0 0 0 WL (threaded) [intr]
100012 I [swi6: task queue]
100013 I [swi6: Giant taskq]
100015 I [swi5: fast taskq]
100031 I [swi1: netisr 0]
100032 I [swi1: hpts]
100033 I [swi1: hpts]
100046 I [irq24: virtio_pci0]
100047 I [irq25: virtio_pci0]
100048 I [irq26: virtio_pci0]
100049 I [irq27: virtio_pci0]
100050 I [irq28: virtio_pci1]
100051 I [irq29: virtio_pci1]
100052 I [irq30: virtio_pci1]
100053 I [irq31: virtio_pci1]
100054 I [irq32: virtio_pci1]
100059 I [irq33: virtio_pci2]
100060 I [irq34: virtio_pci2]
100061 I [irq35: virtio_pci2]
100063 I [irq1: atkbd0]
100064 I [irq12: psm0]
100065 I [swi0: uart uart++]
100069 I [swi1: pf send]
11 0 0 0 RL (threaded) [idle]
100003 CanRun [idle: cpu0]
100004 CanRun [idle: cpu1]
1 0 1 0 SLs wait 0xfffffe0054232040 [init]
10 0 0 0 DL audit_w 0xffffffff838afe80 [audit]
0 0 0 0 DLs (threaded) [kernel]
100000 D swapin 0xffffffff836e6700 [swapper]
100005 D - 0xfffffe00542e3100 [softirq_0]
100006 D - 0xfffffe00542e3000 [softirq_1]
100007 D - 0xfffffe00542e2e00 [if_io_tqg_0]
100008 D - 0xfffffe00542e2d00 [if_io_tqg_1]
100009 D - 0xfffffe00542e2c00 [if_config_tqg_0]
100010 D - 0xfffffe00079bc900 [pci_hp taskq]
100011 D - 0xfffffe00079bc800 [kqueue_ctx taskq]
100014 D - 0xfffffe00079bc300 [thread taskq]
100016 D - 0xfffffe00079bc000 [aiod_kick taskq]
100017 D - 0xfffffe00079bbe00 [deferred_unmount ta]
100018 D - 0xfffffe00079bbd00 [inm_free taskq]
100019 D - 0xfffffe00079bbc00 [in6m_free taskq]
100020 D - 0xfffffe00079bbb00 [linuxkpi_irq_wq]
100021 D - 0xfffffe00079bba00 [linuxkpi_short_wq_0]
100022 D - 0xfffffe00079bba00 [linuxkpi_short_wq_1]
100023 D - 0xfffffe00079bba00 [linuxkpi_short_wq_2]
100024 D - 0xfffffe00079bba00 [linuxkpi_short_wq_3]
100025 D - 0xfffffe00079bb900 [linuxkpi_long_wq_0]
100026 D - 0xfffffe00079bb900 [linuxkpi_long_wq_1]
100027 D - 0xfffffe00079bb900 [linuxkpi_long_wq_2]
100028 D - 0xfffffe00079bb900 [linuxkpi_long_wq_3]
100034 D - 0xfffffe00079bb400 [firmware taskq]
100039 D - 0xfffffe00079bb300 [crypto_0]
100040 D - 0xfffffe00079bb300 [crypto_1]
100055 D - 0xfffffe0007d8a000 [vtnet0 rxq 0]
100056 D - 0xfffffe0007d89e00 [vtnet0 txq 0]
100057 D - 0xfffffe0007d89d00 [vtnet0 rxq 1]
100058 D - 0xfffffe0007d89c00 [vtnet0 txq 1]
100062 D vtbslp 0xfffffe00571c2280 [virtio_balloon]
100066 D - 0xffffffff826f7fc0 [deadlkres]
100070 D - 0xfffffe00586bd400 [acpi_task_0]
100071 D - 0xfffffe00586bd400 [acpi_task_1]
100072 D - 0xfffffe00586bd400 [acpi_task_2]
100074 D - 0xfffffe00079be700 [mca taskq]
100075 D - 0xfffffe00079bb200 [CAM taskq]
db> show all locks
Process 61970 (syz-executor5881231) thread 0xfffffe006d398000 (100129)
shared rw helper list lock (helper list lock) r = 0 (0xffffffff836e9c80) locked @ /syzkaller/managers/main/kernel/sys/kern/kern_khelp.c:194
Process 61968 (syz-executor5881231) thread 0xfffffe006d396740 (100132)
shared lockmgr ufs (ufs) r = 0 (0xfffffe0057844230) locked @ /syzkaller/managers/main/kernel/sys/kern/vfs_lookup.c:1083
db> show malloc
Type InUse MemUse Requests
pf_hash 5 11524K 5
tcp_hpts 7 4801K 7
devbuf 4192 4324K 4220
sysctloid 34934 2059K 35005
vtbuf 24 1968K 46
kobj 326 1304K 488
vfscache 3 1025K 3
newblk 1 1024K 842
pcb 23 669K 244778
ufs_quota 1 512K 1
inodedep 1 512K 72
vfs_hash 1 512K 1
callout 2 512K 2
intr 4 472K 4
vnet_data 2 224K 2
acpitask 1 224K 1
subproc 112 206K 62039
acpica 1674 184K 60830
tidhash 3 141K 3
vmem 3 134K 4
linker 352 130K 386
pagedep 1 128K 19
tfo_ccache 1 128K 1
IP reass 1 128K 1
sem 4 106K 4
DEVFS1 105 105K 114
gtaskqueue 18 98K 18
bus 985 81K 5155
mtx_pool 2 72K 2
syncache 1 68K 1
NFSD srvcache 3 68K 3
module 512 64K 512
ddb_capture 1 64K 1
temp 18 37K 1593
kdtrace 178 37K 62105
umtx 272 34K 272
hostcache 1 32K 1
shm 1 32K 1
DEVFS3 124 31K 134
msg 4 30K 4
kbdmux 6 28K 6
DEVFS_RULE 56 20K 56
BPF 10 18K 10
ufs_mount 4 17K 5
proc 3 17K 3
tty 16 16K 16
ithread 97 16K 97
bus-sc 34 15K 1687
eventhandler 161 14K 161
KTRACE 100 13K 100
kenv 95 12K 95
ifaddr 30 12K 32
GEOM 61 11K 481
routetbl 50 11K 176
rman 86 11K 429
CAM queue 5 11K 1528
rpc 4 9K 4
devstat 4 9K 4
UART 12 9K 12
ksem 1 8K 1
filemon 1 8K 183552
bmsafemap 1 8K 41
shmfd 1 8K 1
pfs_vncache 1 8K 1
audit_evclass 238 8K 300
taskqueue 63 7K 63
sglist 6 7K 6
CAM DEV 3 6K 510
cred 22 6K 293
pfs_nodes 20 5K 20
hhook 15 5K 17
ufs_dirhash 24 5K 24
UMA 268 5K 268
ifnet 3 5K 3
vt 11 5K 11
memdesc 1 4K 1
MCA 32 4K 32
plimit 16 4K 353
filedesc 1 4K 1
evdev 4 4K 4
acpisem 28 4K 28
ether_multi 40 4K 50
lltable 11 4K 11
pf_ifnet 5 3K 6
in6_multi 25 3K 25
kqueue 45 3K 61974
terminal 11 3K 11
pwddesc 44 3K 61972
session 20 3K 122401
clone 9 3K 9
uidinfo 3 3K 10
proc-args 64 3K 62915
local_apic 1 2K 1
io_apic 1 2K 1
ipsec-saq 2 2K 2
selfd 27 2K 753497
lockf 16 2K 26
Unitno 27 2K 41
CAM XPT 22 2K 543
msi 12 2K 12
toponodes 6 2K 6
ipsecpolicy 2 2K 2
acpidev 20 2K 20
softdep 1 1K 1
sahead 1 1K 1
secasvar 1 1K 1
vnodemarker 2 1K 20
NFSD session 1 1K 1
select 7 1K 29
CAM periph 4 1K 271
ipsec 3 1K 3
CC Mem 3 1K 7
nhops 6 1K 6
pfil 6 1K 6
isadev 6 1K 6
mount 16 1K 89
pci_link 10 1K 10
sctp_ifa 5 1K 6
crypto 4 1K 4
ip6ndp 4 1K 5
encap_export_host 12 1K 12
in_multi 2 1K 4
cdev 2 1K 2
osd 8 1K 20
netlink 2 1K 2
chacha20random 1 1K 1
biobuf 1 1K 1
inpcbpolicy 10 1K 139
DEVFSP 5 1K 183561
sctp_iter 1 1K 116925
sctp_ifn 2 1K 6
mld 2 1K 2
igmp 2 1K 2
vnodes 1 1K 1
NFSD lckfile 1 1K 1
NFSD V4client 1 1K 1
DEVFS 9 1K 10
CAM SIM 2 1K 2
feeder 7 1K 7
tcpfunc 3 1K 3
loginclass 3 1K 7
prison 6 1K 6
lkpikmalloc 5 1K 6
sctp_cpal 1 1K 122368
cryptodev 2 1K 49
nexusdev 8 1K 8
apmdev 1 1K 1
atkbddev 2 1K 2
procdesc 1 1K 6
pmchooks 1 1K 1
CAM path 4 1K 1034
CAM dev queue 2 1K 2
CAM I/O Scheduler 1 1K 1
soname 4 1K 3332
tun 3 1K 3
sctp_vrf 1 1K 1
freework 1 1K 26
vnet 1 1K 1
pmc 1 1K 1
entropy 2 1K 36
acpiintr 1 1K 1
cpus 2 1K 2
vnet_data_free 1 1K 1
Per-cpu 1 1K 1
p1003.1b 1 1K 1
filecaps 1 1K 70
tcp_do 0 0K 0
tcp_fsb 0 0K 0
mqdata 0 0K 0
ipcomp 0 0K 0
esp 0 0K 0
ah 0 0K 0
sctp_mcore 0 0K 0
sctp_socko 0 0K 61184
sctp_mvrf 0 0K 0
sctp_timw 0 0K 0
sctp_cmsg 0 0K 0
sctp_stre 0 0K 0
sctp_athi 0 0K 0
sctp_athm 0 0K 122368
sctp_atky 0 0K 122368
sctp_atcl 0 0K 122368
sctp_a_it 0 0K 4
sctp_aadr 0 0K 0
sctp_stro 0 0K 0
sctp_stri 0 0K 0
sctp_map 0 0K 0
pf_table 0 0K 0
pf_rule 0 0K 0
pf_altq 0 0K 0
pf_osfp 0 0K 0
pf_krule_item 0 0K 0
pf_temp 0 0K 0
madt_table 0 0K 2
smartpqi 0 0K 0
ixl 0 0K 0
ice-resmgr 0 0K 0
ice-osdep 0 0K 0
ice 0 0K 0
iavf 0 0K 0
axgbe 0 0K 0
fpukern_ctx 0 0K 0
xen_intr 0 0K 0
xen_hvm 0 0K 0
legacydrv 0 0K 0
bounce 0 0K 0
busdma 0 0K 0
qpidrv 0 0K 0
dmar_idpgtbl 0 0K 0
dmar_dom 0 0K 0
dmar_ctx 0 0K 0
isci 0 0K 0
iommu_dmamap 0 0K 0
hyperv_socket 0 0K 0
bxe_ilt 0 0K 0
aesni_data 0 0K 0
xenbus 0 0K 0
vm_fictitious 0 0K 0
UMAHash 0 0K 0
vm_pgdata 0 0K 0
jblocks 0 0K 0
savedino 0 0K 19
sentinel 0 0K 0
jfsync 0 0K 0
jtrunc 0 0K 0
sbdep 0 0K 6
jsegdep 0 0K 0
jseg 0 0K 0
jfreefrag 0 0K 0
jfreeblk 0 0K 0
jnewblk 0 0K 0
jmvref 0 0K 0
jremref 0 0K 0
jaddref 0 0K 0
freedep 0 0K 0
newdirblk 0 0K 8
dirrem 0 0K 28
mkdir 0 0K 16
diradd 0 0K 37
freefile 0 0K 26
freeblks 0 0K 25
freefrag 0 0K 1
allocindir 0 0K 0
indirdep 0 0K 3
allocdirect 0 0K 0
ufs_trim 0 0K 0
mactemp 0 0K 0
audit_trigger 0 0K 0
audit_pipe_presel 0 0K 0
audit_pipeent 0 0K 0
audit_pipe 0 0K 0
audit_evname 0 0K 0
audit_bsm 0 0K 0
audit_gidset 0 0K 0
audit_text 0 0K 0
audit_path 0 0K 0
audit_data 0 0K 0
audit_cred 0 0K 0
ktls_ocf 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5E_TLS_RX 0 0K 0
MLX5EEPROM 0 0K 0
MLX5E_TLS 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EN 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5DUMP 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
simple_attr 0 0K 0
seq_file 0 0K 0
lkpiskb 0 0K 0
radix 0 0K 0
idr 0 0K 0
lkpindev 0 0K 0
lkpimhi 0 0K 0
lkpifw 0 0K 0
lkpi80211 0 0K 0
NLM 0 0K 0
ipsec-spdcache 0 0K 0
ipsec-reg 0 0K 0
ipsec-misc 0 0K 0
ipsecrequest 0 0K 0
ip6opt 0 0K 3
ip6_msource 0 0K 0
ip6_moptions 0 0K 0
in6_mfilter 0 0K 0
frag6 0 0K 0
tcplog 0 0K 0
tcp_hwpace 0 0K 0
LRO 0 0K 0
ip_msource 0 0K 0
ip_moptions 0 0K 0
in_mfilter 0 0K 0
ipid 0 0K 0
80211scan 0 0K 0
80211ratectl 0 0K 0
80211power 0 0K 0
80211nodeie 0 0K 0
80211node 0 0K 0
80211mesh_gt 0 0K 0
80211mesh_rt 0 0K 0
80211perr 0 0K 0
80211prep 0 0K 0
80211preq 0 0K 0
80211dfs 0 0K 0
80211crypto 0 0K 0
80211vap 0 0K 0
iflib 0 0K 0
vlan 0 0K 0
gif 0 0K 0
ifdescr 0 0K 0
zlib 0 0K 0
fadvise 0 0K 0
VN POLL 0 0K 0
statfs 0 0K 201
namei_tracker 0 0K 0
export_host 0 0K 0
cl_savebuf 0 0K 3
aio 0 0K 0
lio 0 0K 0
acl 0 0K 0
mbuf_tag 0 0K 0
ktls 0 0K 0
accf 0 0K 0
pts 0 0K 0
timerfd 0 0K 0
iov 0 0K 13653
ioctlops 0 0K 86
eventfd 0 0K 0
Witness 0 0K 0
stack 0 0K 0
sbuf 0 0K 288
firmware 0 0K 0
compressor 0 0K 0
SWAP 0 0K 0
sysctltmp 0 0K 651
sysctl 0 0K 3
ekcd 0 0K 0
dumper 0 0K 0
sendfile 0 0K 0
rctl 0 0K 0
cache 0 0K 0
kcovinfo 0 0K 0
prison_racct 0 0K 0
Fail Points 0 0K 0
sigio 0 0K 1
filedesc_to_leader 0 0K 0
pwd 0 0K 0
tty console 0 0K 0
boottrace 0 0K 0
isofs_node 0 0K 0
isofs_mount 0 0K 0
tr_raid5_data 0 0K 0
tr_raid1e_data 0 0K 0
tr_raid1_data 0 0K 0
tr_raid0_data 0 0K 0
tr_concat_data 0 0K 0
md_sii_data 0 0K 0
md_promise_data 0 0K 0
md_nvidia_data 0 0K 0
md_jmicron_data 0 0K 0
md_intel_data 0 0K 0
md_ddf_data 0 0K 0
raid_data 0 0K 72
geom_flashmap 0 0K 0
tmpfs dir 0 0K 0
tmpfs name 0 0K 0
tmpfs mount 0 0K 0
tmpfs extattr 0 0K 0
NFS FHA 0 0K 0
newnfsmnt 0 0K 0
newnfsclient_req 0 0K 0
NFSCL layrecall 0 0K 0
NFSCL session 0 0K 0
NFSCL sockreq 0 0K 0
NFSCL devinfo 0 0K 0
NFSCL flayout 0 0K 0
NFSCL layout 0 0K 0
NFSD rollback 0 0K 0
NFSCL diroff 0 0K 0
NEWdirectio 0 0K 0
NEWNFSnode 0 0K 0
NFSCL lck 0 0K 0
NFSCL lckown 0 0K 0
NFSCL client 0 0K 0
NFSCL deleg 0 0K 0
NFSCL open 0 0K 0
NFSCL owner 0 0K 0
NFS fh 0 0K 0
NFS req 0 0K 0
NFSD usrgroup 0 0K 0
NFSD string 0 0K 0
NFSD V4lock 0 0K 0
NFSD V4state 0 0K 0
msdosfs_fat 0 0K 0
msdosfs_mount 0 0K 0
msdosfs_node 0 0K 0
DEVFS4 0 0K 0
DEVFS2 0 0K 0
gntdev 0 0K 0
privcmd_dev 0 0K 0
evtchn_dev 0 0K 0
xenstore 0 0K 0
xnb 0 0K 0
xen_acpi 0 0K 0
xbbd 0 0K 0
xbd 0 0K 0
Balloon 0 0K 0
sysmouse 0 0K 0
vtfont 0 0K 0
pvscsi 0 0K 0
USBdev 0 0K 0
USB 0 0K 0
twsbuf 0 0K 0
tcp_log_dev 0 0K 0
midi buffers 0 0K 0
mixer 0 0K 0
ac97 0 0K 0
hdacc 0 0K 0
hdac 0 0K 0
hdaa 0 0K 0
SIIS driver 0 0K 0
PUC 0 0K 0
ppbusdev 0 0K 0
sr_iov 0 0K 0
OCS 0 0K 0
OCS 0 0K 0
nvme 0 0K 0
nvd 0 0K 0
netmap 0 0K 0
mwldev 0 0K 0
MVS driver 0 0K 0
mrsasbuf 0 0K 0
mpt_user 0 0K 0
mps_user 0 0K 0
MPSSAS 0 0K 0
mps 0 0K 0
mpr_user 0 0K 0
MPRSAS 0 0K 0
mpr 0 0K 0
mfibuf 0 0K 0
md_sectors 0 0K 0
md_disk 0 0K 0
malodev 0 0K 0
LED 0 0K 0
ix_sriov 0 0K 0
ix 0 0K 0
ipsbuf 0 0K 0
ciss_data 0 0K 0
BACKLIGHT 0 0K 0
ath_hal 0 0K 0
athdev 0 0K 0
ata_pci 0 0K 0
ata_dma 0 0K 0
ata_generic 0 0K 0
AHCI driver 0 0K 0
agp 0 0K 0
acpipwr 0 0K 0
acpi_perf 0 0K 0
acpicmbat 0 0K 0
aacraidcam 0 0K 0
aacraid_buf 0 0K 0
aaccam 0 0K 0
aacbuf 0 0K 0
zstd 0 0K 0
XZ_DEC 0 0K 0
nvlist 0 0K 0
SCSI ENC 0 0K 0
SCSI sa 0 0K 0
scsi_pass 0 0K 0
scsi_da 0 0K 69
ata_da 0 0K 0
scsi_ch 0 0K 0
scsi_cd 0 0K 0
nvme_da 0 0K 0
CAM CCB 0 0K 523
CAM ccb queue 0 0K 0
db> show uma
Zone Size Used Free Requests Sleeps Bucket Total Mem XFree
mbuf_jumbo_page 4096 8320 1078 44425 0 254 38494208 0
mbuf 256 8579 1084 163323 0 254 2473728 0
BUF TRIE 144 185 11631 614 0 62 1701504 0
malloc-384 384 4169 31 4514 0 30 1612800 0
mbuf_cluster 2048 762 0 762 0 254 1560576 0
malloc-128 128 11565 153 11640 0 126 1499904 0
malloc-4096 4096 338 2 512 0 2 1392640 0
UMA Slabs 0 112 10798 32 10798 0 126 1212960 0
vmem btag 56 15734 73 15734 0 254 885192 0
FFS inode 1168 488 37 514 0 8 613200 0
sctp_ep 1176 0 510 122368 0 254 599760 0
lkpimm 168 1 3095 1 0 62 520128 0
lkpicurr 168 2 3094 2 0 62 520128 0
pbuf 2624 0 198 0 0 2 519552 0
RADIX NODE 144 3237 258 146148 0 62 503280 0
socket 960 19 489 123684 0 254 487680 0
malloc-65536 65536 4 2 114 0 1 393216 0
256 Bucket 2048 136 24 1293 0 8 327680 0
malloc-256 256 228 897 1342 0 62 288000 0
malloc-64 64 3839 508 757350 0 254 278208 0
VM OBJECT 264 923 127 503441 0 30 277200 0
VNODE 448 519 57 547 0 30 258048 0
THREAD 1824 132 4 132 0 8 248064 0
malloc-16 16 14422 328 14494 0 254 236000 0
DEVCTL 1024 0 220 123 0 0 225280 0
malloc-4096 4096 45 7 61972 0 2 212992 0
mbuf_packet 256 1 761 117040 0 254 195072 0
malloc-32 32 5531 391 5667 0 254 189504 0
UMA Zones 768 240 4 240 0 16 187392 0
malloc-128 128 1193 202 28392 0 126 178560 0
malloc-32768 32768 3 2 123 0 1 163840 0
malloc-8192 8192 2 18 183553 0 3 163840 0
malloc-1024 1024 120 24 329 0 16 147456 0
FFS2 dinode 256 488 82 514 0 62 145920 0
malloc-65536 65536 2 0 2 0 1 131072 0
malloc-65536 65536 0 2 54 0 1 131072 0
unpcb 256 7 503 1160 0 254 130560 0
S VFS Cache 104 982 188 1024 0 126 121680 0
MAP ENTRY 96 905 355 775028 0 126 120960 0
FPU_save_area 832 134 10 153 0 16 119808 0
ksiginfo 112 55 989 75 0 126 116928 0
malloc-128 128 541 358 248542 0 126 115072 0
malloc-32768 32768 3 0 3 0 1 98304 0
malloc-2048 2048 7 41 576 0 8 98304 0
PROC 1376 44 22 61971 0 8 90816 0
UMA Kegs 384 227 6 227 0 30 89472 0
64 Bucket 512 90 78 5750 0 30 86016 0
128 Bucket 1024 50 33 494 0 16 84992 0
malloc-64 64 608 715 125605 0 254 84672 0
malloc-256 256 145 170 122632 0 62 80640 0
filedesc0 1072 45 25 61972 0 8 75040 0
g_bio 408 0 180 5016 0 30 73440 0
malloc-64 64 525 546 184558 0 254 68544 0
malloc-128 128 361 166 597 0 126 67456 0
malloc-128 128 285 242 1047 0 126 67456 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-16384 16384 3 1 163 0 1 65536 0
malloc-2048 2048 6 26 123088 0 8 65536 0
32 Bucket 256 64 191 13482 0 62 65280 0
malloc-384 384 80 70 122449 0 30 57600 0
malloc-128 128 150 253 643 0 126 51584 0
malloc-256 256 10 185 117292 0 62 49920 0
malloc-256 256 64 131 1358 0 62 49920 0
malloc-256 256 89 106 376 0 62 49920 0
DIRHASH 1024 35 13 35 0 16 49152 0
NAMEI 1024 1 47 195807 0 16 49152 0
malloc-8192 8192 5 1 132 0 1 49152 0
malloc-8192 8192 6 0 6 0 1 49152 0
malloc-1024 1024 30 18 49 0 16 49152 0
malloc-1024 1024 5 43 513 0 16 49152 0
PGRP 120 20 376 122401 0 126 47520 0
syncache 168 0 264 5 0 254 44352 0
malloc-8192 8192 5 0 5 0 1 40960 0
malloc-4096 4096 8 2 8 0 2 40960 0
VMSPACE 616 28 38 61956 0 16 40656 0
pipe 728 6 49 287 0 16 40040 0
udp_inpcb 424 6 84 128 0 30 38160 0
da_ccb 544 0 70 1392 0 16 38080 0
pcpu-8 8 4287 321 4315 0 254 36864 0
malloc-64 64 10 557 13335 0 254 36288 0
malloc-64 64 152 415 169 0 254 36288 0
malloc-64 64 261 306 62778 0 254 36288 0
malloc-64 64 4 563 36 0 254 36288 0
malloc-128 128 56 223 108 0 126 35712 0
routing nhops 256 10 125 17 0 62 34560 0
ttyoutq 256 72 63 160 0 62 34560 0
malloc-384 384 0 90 72 0 30 34560 0
malloc-256 256 34 101 76 0 62 34560 0
malloc-256 256 6 129 307 0 62 34560 0
malloc-32768 32768 1 0 1 0 1 32768 0
malloc-32768 32768 1 0 1 0 1 32768 0
malloc-16384 16384 2 0 2 0 1 32768 0
malloc-4096 4096 7 1 11 0 2 32768 0
malloc-2048 2048 4 12 4 0 8 32768 0
malloc-2048 2048 3 13 12 0 8 32768 0
malloc-2048 2048 1 15 27 0 8 32768 0
malloc-1024 1024 12 20 16 0 16 32768 0
malloc-1024 1024 2 30 2 0 16 32768 0
malloc-1024 1024 0 32 870 0 16 32768 0
malloc-512 512 8 56 8 0 30 32768 0
malloc-512 512 5 59 172 0 30 32768 0
malloc-512 512 3 61 31 0 30 32768 0
malloc-512 512 2 62 12 0 30 32768 0
pcpu-64 64 487 25 487 0 254 32768 0
ertt_txseginfo 40 1 807 58162 0 254 32320 0
ttyinq 160 135 65 300 0 62 32000 0
Files 80 70 330 312519 0 126 32000 0
8 Bucket 80 49 351 775 0 126 32000 0
clpbuf 2624 0 12 29 0 4 31488 0
sctp_laddr 48 0 588 4 0 254 28224 0
malloc-32 32 134 748 62252 0 254 28224 0
malloc-32 32 85 797 536 0 254 28224 0
16 Bucket 144 49 147 388 0 62 28224 0
4 Bucket 48 11 577 742 0 254 28224 0
TURNSTILE 136 137 52 137 0 62 25704 0
cpuset 200 7 121 7 0 62 25600 0
ripcb 392 1 62 4 0 30 24696 0
malloc-8192 8192 2 1 4 0 1 24576 0
malloc-4096 4096 4 2 559 0 2 24576 0
rl_entry 40 33 573 33 0 254 24240 0
PWD 40 10 596 103 0 254 24240 0
rtentry 168 13 131 17 0 62 24192 0
tcp_inpcb 1312 3 15 7 0 8 23616 0
malloc-384 384 7 53 9 0 30 23040 0
malloc-384 384 15 45 16 0 30 23040 0
malloc-384 384 1 59 20 0 30 23040 0
SLEEPQUEUE 88 137 119 137 0 126 22528 0
hostcache 64 1 314 1 0 254 20160 0
udp_inpcb ports 32 3 627 40 0 254 20160 0
ertt 72 3 277 7 0 126 20160 0
malloc-64 64 3 312 3 0 254 20160 0
malloc-32 32 17 613 122405 0 254 20160 0
malloc-32 32 85 545 112 0 254 20160 0
malloc-32 32 33 597 3165 0 254 20160 0
malloc-32 32 22 608 1081 0 254 20160 0
2 Bucket 32 49 581 3802 0 254 20160 0
malloc-256 256 2 73 5 0 62 19200 0
epoch_record pcpu 256 4 60 4 0 62 16384 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-8192 8192 2 0 2 0 1 16384 0
malloc-4096 4096 1 3 3 0 2 16384 0
malloc-4096 4096 0 4 201 0 2 16384 0
malloc-4096 4096 4 0 4 0 2 16384 0
malloc-2048 2048 3 5 3 0 8 16384 0
malloc-2048 2048 1 7 1 0 8 16384 0
malloc-2048 2048 5 3 6 0 8 16384 0
malloc-512 512 1 31 1 0 30 16384 0
malloc-512 512 1 31 1 0 30 16384 0
SMR CPU 32 7 504 7 0 254 16352 0
vtnet_tx_hdr 24 1 667 60063 0 254 16032 0
malloc-16 16 492 508 4719 0 254 16000 0
kenv 258 17 43 1069 0 30 15480 0
mqnode 416 3 33 3 0 30 14976 0
vmem 1856 1 7 1 0 8 14848 0
SMR SHARED 24 7 504 7 0 254 12264 0
tcp_inpcb ports 32 1 377 1 0 254 12096 0
malloc-32 32 6 372 6 0 254 12096 0
KNOTE 160 0 75 8 0 62 12000 0
malloc-16 16 8 742 122499 0 254 12000 0
malloc-16 16 27 723 141 0 254 12000 0
malloc-16 16 33 717 88951 0 254 12000 0
malloc-16 16 2 748 3 0 254 12000 0
malloc-16 16 46 704 66 0 254 12000 0
malloc-16 16 11 739 58 0 254 12000 0
malloc-384 384 1 29 1 0 30 11520 0
malloc-384 384 29 1 30 0 30 11520 0
Mountpoints 2816 2 2 2 0 4 11264 0
malloc-8192 8192 1 0 1 0 1 8192 0
malloc-8192 8192 1 0 1 0 1 8192 0
pcpu-16 16 4 252 4 0 254 4096 0
UMA Slabs 1 176 8 14 8 0 62 3872 0
KMAP ENTRY 96 12 27 14 0 0 3744 0
FFS1 dinode 128 0 0 0 0 126 0 0
ada_ccb 272 0 0 0 0 30 0 0
swblk 136 0 0 0 0 62 0 0
swpctrie 144 0 0 0 0 62 0 0
cdg_qdiffsample 16 0 0 0 0 254 0 0
pf state scrubs 40 0 0 0 0 254 0 0
pf frag entries 40 0 0 0 0 254 0 0
pf frags 248 0 0 0 0 62 0 0
pf table entries 160 0 0 0 0 254 0 0
pf table entry counters 64 0 0 0 0 254 0 0
pf source nodes 152 0 0 0 0 254 0 0
pf state keys 88 0 0 0 0 126 0 0
pf states 352 0 0 0 0 254 0 0
pf tags 104 0 0 0 0 126 0 0
pf mtags 184 0 0 0 0 62 0 0
tcp_rack_pcb 1024 0 0 0 0 16 0 0
tcp_rack_map 128 0 0 0 0 126 0 0
tcp_bbr_pcb 832 0 0 0 0 16 0 0
tcp_bbr_map 128 0 0 0 0 126 0 0
tfo_ccache_entries 80 0 0 0 0 126 0 0
tfo 4 0 0 0 0 254 0 0
sackhole 32 0 0 0 0 254 0 0
ipq 56 0 0 0 0 254 0 0
sctp_asconf_ack 48 0 0 0 0 254 0 0
sctp_asconf 40 0 0 0 0 254 0 0
sctp_stream_msg_out 112 0 0 0 0 254 0 0
sctp_readq 152 0 0 0 0 254 0 0
sctp_chunk 152 0 0 0 0 254 0 0
sctp_raddr 736 0 0 0 0 254 0 0
sctp_asoc 2256 0 0 0 0 254 0 0
tcp_log_id_node 120 0 0 0 0 126 0 0
tcp_log_id_bucket 176 0 0 0 0 62 0 0
tcp_log 416 0 0 0 0 254 0 0
tcpreass 48 0 0 0 0 254 0 0
udplite_inpcb ports 32 0 0 0 0 254 0 0
udplite_inpcb 424 0 0 0 0 30 0 0
ripcb ports 32 0 0 0 0 254 0 0
IPsec SA lft_c 16 0 0 0 0 254 0 0
netlink 2048 0 0 0 0 8 0 0
itimer 352 0 0 0 0 30 0 0
AIOLIO 272 0 0 0 0 30 0 0
AIOCB 552 0 0 0 0 16 0 0
AIO 208 0 0 0 0 62 0 0
mqnotifier 216 0 0 0 0 62 0 0
mvdata 64 0 0 0 0 254 0 0
mqueue 248 0 0 0 0 62 0 0
TMPFS node 232 0 0 0 0 62 0 0
NCLNODE 608 0 0 0 0 16 0 0
LTS VFS Cache 360 0 0 0 0 30 0 0
L VFS Cache 320 0 0 0 0 30 0 0
STS VFS Cache 144 0 0 0 0 62 0 0
cryptop 280 0 0 0 0 30 0 0
linux_dma_object 32 0 0 0 0 254 0 0
linux_dma_pctrie 144 0 0 0 0 62 0 0
IOMMU_MAP_ENTRY 104 0 0 0 0 126 0 0
mbuf_jumbo_16k 16384 0 0 0 0 254 0 0
mbuf_jumbo_9k 9216 0 0 0 0 254 0 0
audit_record 1280 0 0 0 0 8 0 0
domainset 40 0 0 0 0 254 0 0
MAC labels 40 0 0 0 0 254 0 0
vnpbuf 2624 0 0 0 0 16 0 0
nfspbuf 2624 0 0 0 0 4 0 0
swwbuf 2624 0 0 0 0 2 0 0
swrbuf 2624 0 0 0 0 4 0 0
umtx_shm 88 0 0 0 0 126 0 0
umtx pi 96 0 0 0 0 126 0 0
rangeset pctrie nodes 144 0 0 0 0 62 0 0
malloc-65536 65536 0 0 0 0 1 0 0
malloc-65536 65536 0 0 0 0 1 0 0
malloc-65536 65536 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-16384 16384 0 0 0 0 1 0 0
malloc-16384 16384 0 0 0 0 1 0 0
malloc-16384 16384 0 0 0 0 1 0 0
malloc-16384 16384 0 0 0 0 1 0 0
malloc-1024 1024 0 0 0 0 16 0 0
malloc-1024 1024 0 0 0 0 16 0 0
malloc-512 512 0 0 0 0 30 0 0
malloc-512 512 0 0 0 0 30 0 0
malloc-128 128 0 0 0 0 126 0 0
pcpu-32 32 0 0 0 0 254 0 0
pcpu-4 4 0 0 0 0 254 0 0
fakepg 104 0 0 0 0 126 0 0
UMA Hash 256 0 0 0 0 62 0 0


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
Reply all
Reply to author
Forward
0 new messages