panic: inp_join_group: imf_sources not empty

17 views
Skip to first unread message

syzbot

unread,
Mar 15, 2019, 10:32:05 AM3/15/19
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 84b9791b bridge: Fix panic if the STP root is removed
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=13a4a227200000
dashboard link: https://syzkaller.appspot.com/bug?extid=f8c3c564ee21d650475e
userspace arch: amd64

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+f8c3c5...@syzkaller.appspotmail.com

panic: inp_join_group: imf_sources not empty
cpuid = 1
time = 2403
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe001fae5520
vpanic() at vpanic+0x1e0/frame 0xfffffe001fae5580
panic() at panic+0x43/frame 0xfffffe001fae55e0
inp_setmoptions() at inp_setmoptions+0x4023/frame 0xfffffe001fae57c0
ip_ctloutput() at ip_ctloutput+0x80f/frame 0xfffffe001fae5810
rip_ctloutput() at rip_ctloutput+0x2c9/frame 0xfffffe001fae5850
sosetopt() at sosetopt+0x101/frame 0xfffffe001fae58d0
kern_setsockopt() at kern_setsockopt+0x158/frame 0xfffffe001fae5950
sys_setsockopt() at sys_setsockopt+0x33/frame 0xfffffe001fae5980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe001fae5ab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe001fae5ab0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x412e5a, rsp =
0x7fffdff9af38, rbp = 0x5 ---
KDB: enter: panic
[ thread pid 31550 tid 100522 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#bug-status-tracking for how to communicate with
syzbot.

syzbot

unread,
Mar 15, 2019, 11:34:06 AM3/15/19
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 84b9791b bridge: Fix panic if the STP root is removed
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=1503a8a3200000
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=142874f7200000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=17c5e76f200000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+f8c3c5...@syzkaller.appspotmail.com

login: panic: inp_join_group: imf_sources not empty
cpuid = 0
time = 1552663815
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe0021231520
vpanic() at vpanic+0x1e0/frame 0xfffffe0021231580
panic() at panic+0x43/frame 0xfffffe00212315e0
inp_setmoptions() at inp_setmoptions+0x4023/frame 0xfffffe00212317c0
ip_ctloutput() at ip_ctloutput+0x80f/frame 0xfffffe0021231810
rip_ctloutput() at rip_ctloutput+0x2c9/frame 0xfffffe0021231850
sosetopt() at sosetopt+0x101/frame 0xfffffe00212318d0
kern_setsockopt() at kern_setsockopt+0x158/frame 0xfffffe0021231950
sys_setsockopt() at sys_setsockopt+0x33/frame 0xfffffe0021231980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe0021231ab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe0021231ab0
--- syscall (0, FreeBSD ELF64, nosys), rip = 0x457ada, rsp =
0x7fffdffdcf78, rbp = 0x6b6100 ---
KDB: enter: panic
[ thread pid 759 tid 100103 ]
Reply all
Reply to author
Forward
0 new messages