panic: ASan: Invalid access, NUM-byte read at ADDR, UMAUseAfterFree(fd) (4)

瀏覽次數:4 次
跳到第一則未讀訊息

syzbot

未讀,
2022年6月18日 下午6:38:212022/6/18
收件者:syzkaller-f...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 6d25ea6d9641 nfscl: Clean up the code by removing #if(n)de..
git tree: freebsd-src
console output: https://syzkaller.appspot.com/x/log.txt?x=115b3ba7f00000
dashboard link: https://syzkaller.appspot.com/bug?extid=8a3ead6aa115945e43fc

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+8a3ead...@syzkaller.appspotmail.com

panic: ASan: Invalid access, 4-byte read at 0xfffffe009f1b1968, UMAUseAfterFree(fd)
cpuid = 0
time = 461
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0xc7/frame 0xfffffe0053ab74f0
kdb_backtrace() at kdb_backtrace+0xd3/frame 0xfffffe0053ab7650
vpanic() at vpanic+0x254/frame 0xfffffe0053ab7730
panic() at panic+0xb5/frame 0xfffffe0053ab77f0
kasan_report() at kasan_report+0xdc/frame 0xfffffe0053ab78c0
sctp_timer_stop() at sctp_timer_stop+0x444/frame 0xfffffe0053ab7920
sctp_stop_association_timers() at sctp_stop_association_timers+0x1af/frame 0xfffffe0053ab7950
sctp_free_assoc() at sctp_free_assoc+0x45a/frame 0xfffffe0053ab7ac0
sctp_threshold_management() at sctp_threshold_management+0x440/frame 0xfffffe0053ab7b10
sctp_asconf_timer() at sctp_asconf_timer+0x7c/frame 0xfffffe0053ab7b90
sctp_timeout_handler() at sctp_timeout_handler+0xcdb/frame 0xfffffe0053ab7cd0
softclock_call_cc() at softclock_call_cc+0x3c9/frame 0xfffffe0053ab7e80
softclock_thread() at softclock_thread+0x1ff/frame 0xfffffe0053ab7ef0
fork_exit() at fork_exit+0xd0/frame 0xfffffe0053ab7f30
fork_trampoline() at fork_trampoline+0xe/frame 0xfffffe0053ab7f30
--- trap 0, rip = 0, rsp = 0, rbp = 0 ---
KDB: enter: panic
[ thread pid 2 tid 100029 ]
Stopped at kdb_enter+0x6b: movq $0,0x275c2ea(%rip)
db>
db> set $lines = 0
db> set $maxwidth = 0
db> show registers
cs 0x20
ds 0x3b
es 0x3b
fs 0x13
gs 0x1b
ss 0x28
rax 0x12
rcx 0xffffffff8172b8a6 printf+0xf6
rdx 0x1
rbx 0
rsp 0xfffffe0053ab7630
rbp 0xfffffe0053ab7650
rsi 0
rdi 0xffffffff8172b908 printf+0x158
r8 0
r9 0xffffffff
r10 0
r11 0xfffffe0057441c30
r12 0
r13 0xfffffe0053e883a0
r14 0xffffffff82b5ae60 .str.26
r15 0xffffffff82b5ae60 .str.26
rip 0xffffffff8171b42b kdb_enter+0x6b
rflags 0x46
kdb_enter+0x6b: movq $0,0x275c2ea(%rip)
db> show proc
Process 2 (clock) at 0xfffffe0053dcb000:
state: NORMAL
uid: 0 gids: 0
parent: pid 0 at 0xffffffff83e1adc0
ABI: null
flag: 0x10000284 flag2: 0
reaper: 0xffffffff83e1adc0 reapsubtree: 2
sigparent: 20
vmspace: 0xffffffff83e1bd60
(map 0xffffffff83e1bd60)
(map.pmap 0xffffffff83e1be20)
(pmap 0xffffffff83e1be88)
threads: 2
100029 Run CPU 0 [clock (0)]
100030 I [clock (1)]
db> ps
pid ppid pgrp uid state wmesg wchan cmd
14727 779 779 0 R (threaded) syz-executor.1
117932 RunQ syz-executor.1
118501 S uwait 0xfffffe00a8882680 syz-executor.1
14726 778 778 0 R (threaded) syz-executor.0
118486 RunQ syz-executor.0
118502 S uwait 0xfffffe00a6a82e00 syz-executor.0
14725 780 780 0 R (threaded) syz-executor.2
118483 RunQ syz-executor.2
118499 S connec 0xfffffe0058c6d49a syz-executor.2
14499 1 782 0 S uwait 0xfffffe00a6ab3800 syz-executor.3
14494 1 782 0 S uwait 0xfffffe00a850ab00 syz-executor.3
14492 1 782 0 S uwait 0xfffffe0058b0da00 syz-executor.3
14488 1 782 0 S uwait 0xfffffe00a6a80100 syz-executor.3
14379 1 780 0 S uwait 0xfffffe00a6ab6500 syz-executor.2
14376 1 780 0 S uwait 0xfffffe00a8508e00 syz-executor.2
14369 1 782 0 S uwait 0xfffffe00a6ab6580 syz-executor.3
14368 1 782 0 S uwait 0xfffffe00a6a78d80 syz-executor.3
14367 1 780 0 S uwait 0xfffffe00a6a7f600 syz-executor.2
14365 1 780 0 S uwait 0xfffffe00a6a81880 syz-executor.2
14361 1 779 0 S uwait 0xfffffe00a6ab5c00 syz-executor.1
14359 1 779 0 S uwait 0xfffffe00a6a77280 syz-executor.1
14355 1 782 0 S uwait 0xfffffe00a850b980 syz-executor.3
14354 1 780 0 S uwait 0xfffffe00a8508e80 syz-executor.2
14353 1 782 0 S uwait 0xfffffe00a6a79e80 syz-executor.3
14351 1 780 0 S uwait 0xfffffe0058b64e00 syz-executor.2
14350 1 779 0 S uwait 0xfffffe00a8509300 syz-executor.1
14346 1 779 0 S uwait 0xfffffe009f1e2f00 syz-executor.1
14342 1 782 0 S uwait 0xfffffe00a8509500 syz-executor.3
14341 1 782 0 S uwait 0xfffffe00a6a79980 syz-executor.3
14337 1 779 0 S uwait 0xfffffe00a6a81c00 syz-executor.1
14335 1 779 0 S uwait 0xfffffe00a6a3e380 syz-executor.1
14324 1 779 0 S uwait 0xfffffe00a6a77a00 syz-executor.1
14322 1 779 0 S uwait 0xfffffe00a5eb0200 syz-executor.1
14101 1 780 0 S uwait 0xfffffe00a5dd1500 syz-executor.2
14096 1 779 60928 S uwait 0xfffffe00a6a77d00 syz-executor.1
14075 1 779 0 S uwait 0xfffffe00a850b700 syz-executor.1
13972 1 779 0 S uwait 0xfffffe00a5da9580 syz-executor.1
13968 1 782 0 S uwait 0xfffffe009ea0e080 syz-executor.3
13966 1 780 0 S uwait 0xfffffe00a6a80b00 syz-executor.2
13965 1 779 0 S uwait 0xfffffe00a79cd900 syz-executor.1
13963 1 782 0 S uwait 0xfffffe00a6a37900 syz-executor.3
13960 1 780 0 S uwait 0xfffffe00a6ab4b80 syz-executor.2
13959 1 779 0 S uwait 0xfffffe00a8509100 syz-executor.1
13956 1 782 0 S uwait 0xfffffe00a79cde80 syz-executor.3
13953 1 780 0 S uwait 0xfffffe00a6a7f480 syz-executor.2
13952 1 778 0 S uwait 0xfffffe00a8509280 syz-executor.0
13949 1 778 0 S uwait 0xfffffe00a6a77080 syz-executor.0
13947 1 778 0 S uwait 0xfffffe009ea0e100 syz-executor.0
13945 1 778 0 S uwait 0xfffffe00a5dd1200 syz-executor.0
13604 1 782 0 S uwait 0xfffffe00a6a3e300 syz-executor.3
13598 1 779 0 S uwait 0xfffffe00a6a7a280 syz-executor.1
13591 1 779 0 S uwait 0xfffffe00a8509e00 syz-executor.1
13590 1 782 0 S uwait 0xfffffe00a79cd880 syz-executor.3
13585 1 782 0 S uwait 0xfffffe00a6ab4500 syz-executor.3
13581 1 779 0 S uwait 0xfffffe00a8508f00 syz-executor.1
13568 1 779 0 S uwait 0xfffffe00a6ab6780 syz-executor.1
12641 1 779 0 S uwait 0xfffffe00a6a3ec80 syz-executor.1
12635 1 778 0 S uwait 0xfffffe00a6a77e80 syz-executor.0
12629 1 779 0 S uwait 0xfffffe00a850b000 syz-executor.1
12625 1 778 0 S uwait 0xfffffe00a6a3db00 syz-executor.0
12624 1 780 0 S uwait 0xfffffe009ea0ed80 syz-executor.2
12618 1 779 0 S uwait 0xfffffe00a6a79000 syz-executor.1
12616 1 778 0 S uwait 0xfffffe00a6a7fa80 syz-executor.0
12614 1 780 0 S uwait 0xfffffe00a850b100 syz-executor.2
12607 1 780 0 S uwait 0xfffffe00a6a77c00 syz-executor.2
12593 1 780 0 S uwait 0xfffffe00a6a3ee80 syz-executor.2
12244 1 782 0 S uwait 0xfffffe009ea0d680 syz-executor.3
12238 1 779 0 S uwait 0xfffffe00a6ab4c80 syz-executor.1
12232 1 782 0 S uwait 0xfffffe00a6ab5600 syz-executor.3
12228 1 779 0 S uwait 0xfffffe00a6a37600 syz-executor.1
12221 1 782 0 S uwait 0xfffffe00a6a79080 syz-executor.3
12218 1 779 0 S uwait 0xfffffe0058b62300 syz-executor.1
12208 1 779 0 S uwait 0xfffffe00a79d8000 syz-executor.1
11075 1 778 0 S uwait 0xfffffe00a6a3d180 syz-executor.0
11069 1 778 0 S uwait 0xfffffe00a6a3dc80 syz-executor.0
11060 1 778 0 S uwait 0xfffffe00a850bb80 syz-executor.0
11048 1 778 0 S uwait 0xfffffe00a6a3eb80 syz-executor.0
10981 0 0 0 DL aiordy 0xfffffe00a8563a90 [aiod5]
10872 0 0 0 DL (threaded) [KTLS]
113217 D - 0xfffffe009eb43e00 [thr_0]
113229 D - 0xfffffe009eb43e80 [thr_1]
113230 D - 0xffffffff83f65828 [alloc_0]
10469 1 779 0 S uwait 0xfffffe00a6ab6700 syz-executor.1
10461 1 779 0 S uwait 0xfffffe00a6a81200 syz-executor.1
10448 1 779 0 S uwait 0xfffffe00a6ab6b00 syz-executor.1
10441 1 778 0 S uwait 0xfffffe00a6a3e480 syz-executor.0
10437 1 780 0 S uwait 0xfffffe00a6ab5900 syz-executor.2
10435 1 778 0 S uwait 0xfffffe00a6a77900 syz-executor.0
10431 1 780 0 S uwait 0xfffffe0058b0d800 syz-executor.2
10429 1 778 0 S uwait 0xfffffe00a6ab6a00 syz-executor.0
10423 1 780 0 S uwait 0xfffffe009f1e4180 syz-executor.2
10414 1 780 0 S uwait 0xfffffe00a6a82700 syz-executor.2
9566 1 778 0 S uwait 0xfffffe00a6ab5480 syz-executor.0
8974 1 778 0 S uwait 0xfffffe00a6a81a00 syz-executor.0
8964 1 778 0 S uwait 0xfffffe00a6ab6880 syz-executor.0
8960 1 782 0 S uwait 0xfffffe00a6a3f080 syz-executor.3
8958 1 778 0 S uwait 0xfffffe00a6ab5b00 syz-executor.0
8953 1 779 0 S uwait 0xfffffe00a6a37400 syz-executor.1
8952 1 778 0 S uwait 0xfffffe00a6a79300 syz-executor.0
8951 1 782 0 S uwait 0xfffffe00a6a79400 syz-executor.3
8950 1 780 0 S uwait 0xfffffe00a6a81100 syz-executor.2
8946 1 779 0 S uwait 0xfffffe00a6a80800 syz-executor.1
8944 1 778 0 S uwait 0xfffffe00a6ab5400 syz-executor.0
8943 1 782 0 S uwait 0xfffffe00a6a78b80 syz-executor.3
8942 1 780 0 S uwait 0xfffffe00a6a79a00 syz-executor.2
8937 1 779 0 S uwait 0xfffffe00a6a80580 syz-executor.1
8936 1 780 0 S uwait 0xfffffe00a6ab4c00 syz-executor.2
8934 1 778 0 S uwait 0xfffffe00a6a7ac00 syz-executor.0
8927 1 779 0 S uwait 0xfffffe00a79cda00 syz-executor.1
6807 1 6806 0 S uwait 0xfffffe009ea0ee80 syz-executor.3
6804 1 6799 0 S uwait 0xfffffe00a6a77700 syz-executor.3
6802 1 6801 0 S uwait 0xfffffe00a5da8900 syz-executor.0
6800 1 6796 0 S uwait 0xfffffe0058b61800 syz-executor.0
6797 1 6794 0 S uwait 0xfffffe00a6a7ac80 syz-executor.3
6793 1 6792 0 S uwait 0xfffffe0058b64780 syz-executor.0
6790 1 6788 0 S uwait 0xfffffe00a6a78e80 syz-executor.0
6719 0 0 0 DL - 0xffffffff83f64ac0 [soaiod4]
6718 0 0 0 DL - 0xffffffff83f64ac0 [soaiod3]
6717 0 0 0 DL - 0xffffffff83f64ac0 [soaiod2]
6716 0 0 0 DL - 0xffffffff83f64ac0 [soaiod1]
5175 1 782 0 S uwait 0xfffffe00a6a3ed80 syz-executor.3
5174 1 779 0 S uwait 0xfffffe009ea10980 syz-executor.1
5163 1 782 0 S uwait 0xfffffe00a5f27900 syz-executor.3
5161 1 779 0 S uwait 0xfffffe00a6a37100 syz-executor.1
5160 1 778 0 S uwait 0xfffffe00a6a3ea80 syz-executor.0
5157 1 782 0 S uwait 0xfffffe00a6a3f100 syz-executor.3
5155 1 779 0 S uwait 0xfffffe009ea0f000 syz-executor.1
5153 1 778 0 S uwait 0xfffffe00a5ee4400 syz-executor.0
5152 1 780 0 S uwait 0xfffffe0058b0cc80 syz-executor.2
5149 1 782 0 S umtxn 0xfffffe0058b64b80 syz-executor.3
5147 1 779 0 S uwait 0xfffffe00a5ee4800 syz-executor.1
5145 1 778 0 S uwait 0xfffffe00a5f28600 syz-executor.0
5144 1 780 0 S uwait 0xfffffe009f1e2000 syz-executor.2
5141 1 782 0 S uwait 0xfffffe00a6a37800 syz-executor.3
5139 1 779 0 S uwait 0xfffffe009ea0e980 syz-executor.1
5137 1 780 0 S uwait 0xfffffe0058b0cb80 syz-executor.2
5136 1 778 0 S uwait 0xfffffe0058b61100 syz-executor.0
5133 1 782 0 S uwait 0xfffffe00a6a37200 syz-executor.3
5132 1 779 0 S uwait 0xfffffe00a5da9780 syz-executor.1
5129 1 778 0 S uwait 0xfffffe00a5ee4300 syz-executor.0
5122 1 778 0 S uwait 0xfffffe0058b62900 syz-executor.0
5113 1 778 0 S uwait 0xfffffe009f1e4900 syz-executor.0
4646 0 0 0 DL mdwait 0xfffffe00a6a96000 [md10]
4644 0 0 0 DL mdwait 0xfffffe009f03e000 [md9]
4635 0 0 0 DL mdwait 0xfffffe00a5ede000 [md8]
4631 0 0 0 DL mdwait 0xfffffe00a6f92000 [md7]
4453 1 4453 65 Ss select 0xfffffe0056fbc240 dhclient
4278 0 0 0 DL (threaded) [zfskern]
102437 D t->zthr 0xfffffe00a6fcb848 [arc_evict]
104512 D t->zthr 0xfffffe00a6fcba48 [arc_reap]
104513 D - 0xfffffe009ea1f200 [dbu_evict]
104514 D dbuf_ev 0xffffffff85a37c60 [dbuf_evict_thread]
104515 D - 0xfffffe000817b000 [z_vdev_file_0]
104516 D - 0xfffffe000817b000 [z_vdev_file_1]
104517 D - 0xfffffe000817b000 [z_vdev_file_2]
104518 D - 0xfffffe000817b000 [z_vdev_file_3]
104519 D - 0xfffffe000817b000 [z_vdev_file_4]
104520 D - 0xfffffe000817b000 [z_vdev_file_5]
104521 D - 0xfffffe000817b000 [z_vdev_file_6]
104522 D - 0xfffffe000817b000 [z_vdev_file_7]
104523 D - 0xfffffe000817b000 [z_vdev_file_8]
104524 D - 0xfffffe000817b000 [z_vdev_file_9]
104525 D - 0xfffffe000817b000 [z_vdev_file_10]
104526 D - 0xfffffe000817b000 [z_vdev_file_11]
104527 D - 0xfffffe000817b000 [z_vdev_file_12]
104528 D - 0xfffffe000817b000 [z_vdev_file_13]
104529 D - 0xfffffe000817b000 [z_vdev_file_14]
104530 D - 0xfffffe000817b000 [z_vdev_file_15]
104531 D l2arc_f 0xffffffff859f6d80 [l2arc_feed_thread]
104532 D - 0xfffffe000817b100 [zfsvfs]
104533 S zevent_ 0xffffffff85a38800 [sysevent]
3781 1 3781 0 Ss select 0xfffffe00578711c0 dhclient
3778 1 3778 0 Ss select 0xfffffe0056fbc5c0 dhclient
3756 1 3756 65 Ss select 0xfffffe0056fbc6c0 dhclient
3003 1 3003 0 Ss select 0xfffffe00578713c0 dhclient
3000 1 3000 0 Ss select 0xfffffe00578712c0 dhclient
2973 1 2973 65 Ss select 0xfffffe00578715c0 dhclient
2365 0 0 0 DL aiordy 0xfffffe00a5d77548 [aiod4]
2364 0 0 0 DL aiordy 0xfffffe00a5f15548 [aiod3]
2363 0 0 0 DL aiordy 0xfffffe00a5f15000 [aiod2]
2343 1 780 0 SV uwait 0xfffffe0058b61700 syz-executor.2
2332 1 780 0 SV uwait 0xfffffe0058b64680 syz-executor.2
2328 1 779 0 SV uwait 0xfffffe0058b0bc00 syz-executor.1
2322 1 779 0 SV uwait 0xfffffe0058b0de80 syz-executor.1
2321 1 780 0 SV uwait 0xfffffe00a5ee4a00 syz-executor.2
2314 1 779 0 SV uwait 0xfffffe0058b62800 syz-executor.1
2301 1 779 0 SV uwait 0xfffffe0058b0b900 syz-executor.1
2249 1 2249 0 Ss select 0xfffffe00578717c0 dhclient
2246 1 2246 0 Ss select 0xfffffe0056fbc840 dhclient
2219 1 2219 65 Ss select 0xfffffe0057871940 dhclient
1293 1 1293 0 Ss select 0xfffffe0056f9c940 dhclient
1290 1 1290 0 Ss select 0xfffffe0057871ac0 dhclient
1220 0 0 0 DL mdwait 0xfffffe00a5ed4000 [md6]
1219 0 0 0 DL mdwait 0xfffffe009f051000 [md5]
1215 0 0 0 DL mdwait 0xfffffe00a5ecd000 [md4]
1214 0 0 0 DL mdwait 0xfffffe009f08c000 [md3]
1209 0 0 0 DL mdwait 0xfffffe00a5eae000 [md2]
1208 0 0 0 DL mdwait 0xfffffe009f1d2000 [md1]
1203 0 0 0 DL mdwait 0xfffffe009f1d1000 [md0]
782 776 782 0 Rs syz-executor.3
780 776 780 0 Ss nanslp 0xffffffff83e44dc1 syz-executor.2
779 776 779 0 Ss nanslp 0xffffffff83e44dc1 syz-executor.1
778 776 778 0 Ss nanslp 0xffffffff83e44dc1 syz-executor.0
776 774 774 0 S (threaded) syz-fuzzer
100086 S uwait 0xfffffe005743a080 syz-fuzzer
100112 S uwait 0xfffffe0058afa380 syz-fuzzer
100113 S uwait 0xfffffe0058b0c980 syz-fuzzer
100114 S uwait 0xfffffe005783b100 syz-fuzzer
100115 S uwait 0xfffffe0058af0980 syz-fuzzer
100116 S uwait 0xfffffe0058b0c880 syz-fuzzer
100117 S uwait 0xfffffe0058b0c780 syz-fuzzer
100118 S kqread 0xfffffe005785b200 syz-fuzzer
100120 S uwait 0xfffffe0058b62b00 syz-fuzzer
774 772 774 0 Ss pause 0xfffffe009ec9c0b0 csh
772 688 772 0 Ss select 0xfffffe0056fbc9c0 sshd
754 1 754 0 Ss+ ttyin 0xfffffe0056f2acb0 getty
753 1 753 0 Ss+ ttyin 0xfffffe0056f298b0 getty
752 1 752 0 Ss+ ttyin 0xfffffe00585d78b0 getty
751 1 751 0 Ss+ ttyin 0xfffffe00585d7cb0 getty
750 1 750 0 Ss+ ttyin 0xfffffe00585d80b0 getty
749 1 749 0 Ss+ ttyin 0xfffffe0056f29cb0 getty
748 1 748 0 Ss+ ttyin 0xfffffe00585d84b0 getty
747 1 747 0 Ss+ ttyin 0xfffffe00585d88b0 getty
746 1 746 0 Ss+ ttyin 0xfffffe00585d8cb0 getty
692 1 692 0 Ss nanslp 0xffffffff83e44dc0 cron
688 1 688 0 Ss select 0xfffffe0056f9cb40 sshd
501 1 501 0 Ss select 0xfffffe0056f9cbc0 syslogd
430 1 430 0 Ss select 0xfffffe0056f9d1c0 devd
429 1 429 65 Ss select 0xfffffe0056f9cdc0 dhclient
344 1 344 0 Ss select 0xfffffe0056f9ce40 dhclient
341 1 341 0 Ss select 0xfffffe00578719c0 dhclient
17 0 0 0 DL vlruwt 0xfffffe0056f67548 [vnlru]
16 0 0 0 DL syncer 0xffffffff83f6a5e0 [syncer]
15 0 0 0 RL (threaded) [bufdaemon]
100079 D psleep 0xffffffff83f68c00 [bufdaemon]
100082 RunQ [bufspacedaemon-0]
100094 D sdflush 0xfffffe0053c6e8e8 [/ worker]
9 0 0 0 DL psleep 0xffffffff83f9c6c0 [vmdaemon]
8 0 0 0 DL (threaded) [pagedaemon]
100077 D psleep 0xffffffff83f90578 [dom0]
100083 D launds 0xffffffff83f90584 [laundry: dom0]
100084 D umarcl 0xffffffff81e4d0f0 [uma]
7 0 0 0 DL - 0xffffffff83c013a8 [rand_harvestq]
6 0 0 0 DL pftm 0xffffffff846e5550 [pf purge]
5 0 0 0 DL waiting 0xffffffff84a44420 [sctp_iterator]
4 0 0 0 DL (threaded) [cam]
100044 D - 0xffffffff83aa4340 [doneq0]
100045 D - 0xffffffff83aa42c0 [async]
100076 D - 0xffffffff83aa4140 [scanner]
14 0 0 0 DL seqstat 0xfffffe0007962888 [sequencer 00]
3 0 0 0 DL (threaded) [crypto]
100040 D crypto_ 0xffffffff83f8bda0 [crypto]
100041 D crypto_ 0xfffffe0053e71d30 [crypto returns 0]
100042 D crypto_ 0xfffffe0053e71d80 [crypto returns 1]
13 0 0 0 DL (threaded) [geom]
100035 D - 0xffffffff83e1a3c0 [g_event]
100036 D - 0xffffffff83e1a3e0 [g_up]
100037 D - 0xffffffff83e1a400 [g_down]
2 0 0 0 RL (threaded) [clock]
100029 Run CPU 0 [clock (0)]
100030 I [clock (1)]
12 0 0 0 RL (threaded) [intr]
100015 I [swi5: fast taskq]
100018 I [swi6: task queue]
100019 I [swi6: Giant taskq]
100031 Run CPU 1 [swi1: netisr 0]
100032 I [swi1: hpts]
100033 I [swi1: hpts]
100046 I [irq24: virtio_pci0]
100047 I [irq25: virtio_pci0]
100048 I [irq26: virtio_pci0]
100049 I [irq27: virtio_pci0]
100050 I [irq28: virtio_pci1]
100051 I [irq29: virtio_pci1]
100052 I [irq30: virtio_pci1]
100053 I [irq31: virtio_pci1]
100054 I [irq32: virtio_pci1]
100059 I [irq33: virtio_pci2]
100060 I [irq34: virtio_pci2]
100061 I [irq35: virtio_pci2]
100063 I [irq1: atkbd0]
100064 I [irq12: psm0]
100065 I [swi0: uart uart++]
100069 I [swi1: pf send]
11 0 0 0 RL (threaded) [idle]
100003 CanRun [idle: cpu0]
100004 CanRun [idle: cpu1]
1 0 1 0 SLs wait 0xfffffe0053dcc000 [init]
10 0 0 0 DL audit_w 0xffffffff83f8c880 [audit]
0 0 0 0 DLs (threaded) [kernel]
100000 D swapin 0xffffffff83e1adc0 [swapper]
100005 D - 0xfffffe000817de00 [if_config_tqg_0]
100006 D - 0xfffffe000817dd00 [softirq_0]
100007 D - 0xfffffe000817dc00 [softirq_1]
100008 D - 0xfffffe000817db00 [if_io_tqg_0]
100009 D - 0xfffffe000817da00 [if_io_tqg_1]
100010 D - 0xfffffe000817d900 [inm_free taskq]
100011 D - 0xfffffe000817d800 [linuxkpi_irq_wq]
100012 D - 0xfffffe000817d700 [in6m_free taskq]
100013 D - 0xfffffe000817d600 [deferred_unmount ta]
100014 D - 0xfffffe000817d500 [thread taskq]
100016 D - 0xfffffe000817d300 [kqueue_ctx taskq]
100017 D - 0xfffffe000817d200 [pci_hp taskq]
100020 D - 0xfffffe000817ce00 [aiod_kick taskq]
100021 D - 0xfffffe000817cd00 [linuxkpi_short_wq_0]
100022 D - 0xfffffe000817cd00 [linuxkpi_short_wq_1]
100023 D - 0xfffffe000817cd00 [linuxkpi_short_wq_2]
100024 D - 0xfffffe000817cd00 [linuxkpi_short_wq_3]
100025 D - 0xfffffe000817cc00 [linuxkpi_long_wq_0]
100026 D - 0xfffffe000817cc00 [linuxkpi_long_wq_1]
100027 D - 0xfffffe000817cc00 [linuxkpi_long_wq_2]
100028 D - 0xfffffe000817cc00 [linuxkpi_long_wq_3]
100034 D - 0xfffffe000817cb00 [firmware taskq]
100038 D - 0xfffffe000817ca00 [crypto_0]
100039 D - 0xfffffe000817ca00 [crypto_1]
100055 D - 0xfffffe000817c800 [vtnet0 rxq 0]
100056 D - 0xfffffe000817c700 [vtnet0 txq 0]
100057 D - 0xfffffe000817c600 [vtnet0 rxq 1]
100058 D - 0xfffffe000817c500 [vtnet0 txq 1]
100062 D vtbslp 0xfffffe0056f9d380 [virtio_balloon]
100066 D - 0xffffffff82b60ce0 [deadlkres]
100070 D - 0xfffffe000817e100 [mca taskq]
100071 D - 0xfffffe00585d3300 [acpi_task_0]
100072 D - 0xfffffe00585d3300 [acpi_task_1]
100073 D - 0xfffffe00585d3300 [acpi_task_2]
100075 D - 0xfffffe000817c900 [CAM taskq]
104507 D - 0xfffffe000817ad00 [system_taskq_0]
104508 D - 0xfffffe000817ad00 [system_taskq_1]
104509 D - 0xfffffe000817ae00 [system_delay_taskq_]
104510 D - 0xfffffe000817ae00 [system_delay_taskq_]
104511 D - 0xfffffe009ea1f300 [arc_prune]
db> show all locks
Process 782 (syz-executor.3) thread 0xfffffe0057441720 (100087)
exclusive rw pmap pv list (pmap pv list) r = 0 (0xfffffe0007767e80) locked @ /syzkaller/managers/main/kernel/sys/amd64/amd64/pmap.c:5799
exclusive sleep mutex pmap (pmap) r = 0 (0xfffffe00a9575128) locked @ /syzkaller/managers/main/kernel/sys/amd64/amd64/pmap.c:7851
exclusive sleep mutex pmap (pmap) r = 0 (0xfffffe009eb0d128) locked @ /syzkaller/managers/main/kernel/sys/amd64/amd64/pmap.c:7850
exclusive sx vm map (user) (vm map (user)) r = 0 (0xfffffe00a9575060) locked @ /syzkaller/managers/main/kernel/sys/vm/vm_map.c:4271
exclusive sx vm map (user) (vm map (user)) r = 0 (0xfffffe009eb0d060) locked @ /syzkaller/managers/main/kernel/sys/vm/vm_map.c:4267
Process 2 (clock) thread 0xfffffe0053e883a0 (100029)
exclusive sleep mutex sctp-tcb (tcb) r = 0 (0xfffffe00a5c47320) locked @ /syzkaller/managers/main/kernel/sys/netinet/sctputil.c:1777
db> show malloc
Type InUse MemUse Requests
sctp_stro 180 32429K 6240
pf_hash 5 11524K 5
linker 380 9604K 416
tcp_hpts 7 4801K 7
devbuf 4217 4323K 4257
sysctloid 48651 2862K 48755
solaris 130 2804K 200
filedesc 278 2221K 27387
vtbuf 24 1968K 46
pcb 768 1367K 28394
kobj 328 1312K 589
newblk 215 1078K 61984
vfscache 3 1025K 3
subproc 425 914K 14963
inodedep 91 546K 16717
ufs_quota 1 512K 1
vfs_hash 1 512K 1
callout 2 512K 2
intr 4 472K 4
vmem 3 276K 6
sctp_atcl 575 216K 21024
acpica 1674 184K 57552
vnet_data 1 168K 1
tidhash 3 141K 3
pagedep 39 138K 13940
tfo_ccache 1 128K 1
DEVFS1 121 121K 138
sem 4 106K 4
kdtrace 531 94K 33232
umtx 704 88K 704
BPF 46 88K 128
bus 995 81K 5208
mtx_pool 2 72K 2
syncache 1 68K 1
module 518 65K 518
acpitask 1 64K 1
ddb_capture 1 64K 1
filemon 7 56K 273
freework 204 51K 31983
md_disk 18 45K 35
DEVFS3 140 35K 150
temp 36 35K 19490
hostcache 1 32K 1
shm 1 32K 190
sctp_atky 764 31K 28440
msg 4 30K 4
md_sectors 7 28K 7
gtaskqueue 18 26K 18
GEOM 138 22K 979
kbdmux 6 22K 6
ifaddr 70 20K 72
DEVFS_RULE 56 20K 56
routetbl 138 19K 1118
kstat_data 17 17K 17
ufs_mount 4 17K 5
proc 3 17K 3
tty 16 16K 16
sctp_timw 63 16K 63
ithread 97 16K 97
lltable 49 16K 527
kqueue 210 16K 14846
bus-sc 34 15K 1681
ksem 35 14K 335
pwddesc 208 13K 14848
KTRACE 101 13K 45819
cred 49 13K 492
ifnet 7 13K 7
ether_multi 152 13K 213
devstat 6 13K 6
eventhandler 139 12K 139
kenv 95 12K 95
rman 88 11K 431
CAM queue 5 11K 1528
sctp_stri 18 9K 1696
sctp_athm 575 9K 21853
dirrem 35 9K 15834
in6_multi 65 9K 65
taskqueue 81 9K 81
bmsafemap 2 9K 16810
UART 12 9K 12
rpc 2 8K 2
shmfd 1 8K 27
pfs_vncache 1 8K 1
plimit 31 8K 493
pfs_nodes 20 8K 20
audit_evclass 237 8K 296
UMA 376 8K 376
sglist 5 7K 5
CAM DEV 3 6K 510
freefile 47 6K 15576
freeblks 23 6K 16034
sctp_map 360 6K 12290
pf_osfp 49 6K 49
proc-args 222 6K 16050
session 42 6K 123
pf_ifnet 13 5K 222
DEVFSP 75 5K 1306
ufs_dirhash 24 5K 24
tcp_fsb 49 5K 1991
newdirblk 34 5K 13670
vt 11 5K 11
pf_table 2 4K 177
memdesc 1 4K 1
MCA 32 4K 32
indirdep 16 4K 22608
evdev 4 4K 4
lockf 34 4K 315
acpisem 28 4K 28
CC Mem 55 4K 5287
selfd 55 4K 184764
hhook 15 4K 17
kcovinfo 52 4K 52
inpcbpolicy 88 3K 6324
terminal 11 3K 11
ip6opt 18 3K 274
select 19 3K 172
uidinfo 4 3K 81
sctp_aadr 37 3K 66
mount 40 3K 1056
local_apic 1 2K 1
io_apic 1 2K 1
fpukern_ctx 2 2K 2
ipsec-saq 2 2K 2
ip6ndp 12 2K 14
Unitno 30 2K 987
osd 83 2K 5184
sctp_ifa 13 2K 14
CAM XPT 22 2K 543
msi 12 2K 12
in_multi 6 2K 21
vnodemarker 3 2K 1019
ipsecpolicy 2 2K 2
acpidev 20 2K 20
ip_msource 18 2K 192
clone 9 2K 9
tun 7 2K 7
softdep 1 1K 1
mkdir 8 1K 27340
sahead 1 1K 1
secasvar 1 1K 1
nhops 6 1K 8
filedesc_to_leader 16 1K 32
NFSD session 1 1K 1
CAM periph 4 1K 271
sctp_ifn 6 1K 14
ipsec 3 1K 3
mld 6 1K 6
igmp 6 1K 6
toponodes 6 1K 6
isadev 6 1K 6
pci_link 10 1K 10
crypto 4 1K 435
encap_export_host 12 1K 12
procdesc 5 1K 18
diradd 4 1K 15874
pfil 4 1K 4
cdev 2 1K 2
chacha20random 1 1K 1
NFSD lckfile 1 1K 1
NFSD V4client 1 1K 1
DEVFS 9 1K 10
vnodes 1 1K 39
ktls 1 1K 14
CAM SIM 2 1K 2
prison 8 1K 8
feeder 7 1K 7
taskq 2 1K 2
tcpfunc 3 1K 3
loginclass 3 1K 6
lkpikmalloc 5 1K 6
aesni_data 2 1K 2
soname 5 1K 21645
pf_rule 1 1K 208
cryptodev 2 1K 1699
nexusdev 8 1K 8
apmdev 1 1K 1
atkbddev 2 1K 2
CAM dev queue 2 1K 2
CAM I/O Scheduler 1 1K 1
CAM path 4 1K 1034
pmchooks 1 1K 1
filecaps 5 1K 122
sctp_vrf 1 1K 1
vnet 1 1K 1
entropy 2 1K 46
pmc 1 1K 1
acpiintr 1 1K 1
cpus 2 1K 2
vnet_data_free 1 1K 1
Per-cpu 1 1K 1
p1003.1b 1 1K 1
sfs_nodes 0 0K 0
zones_data 0 0K 0
sctp_mcore 0 0K 0
sctp_socko 0 0K 9828
sctp_iter 0 0K 59
sctp_mvrf 0 0K 0
sctp_cpal 0 0K 56
sctp_cmsg 0 0K 0
sctp_stre 0 0K 0
sctp_athi 0 0K 0
sctp_a_it 0 0K 14
mqdata 0 0K 0
pf_altq 0 0K 0
pf_temp 0 0K 0
ipcomp 0 0K 0
esp 0 0K 0
ah 0 0K 0
NFSCL layrecall 0 0K 0
NFSCL session 0 0K 0
madt_table 0 0K 2
smartpqi 0 0K 0
NFSCL sockreq 0 0K 0
NFSCL devinfo 0 0K 0
NFSCL flayout 0 0K 0
ixl 0 0K 0
NFSCL layout 0 0K 0
NFSD rollback 0 0K 0
NFSCL diroff 0 0K 0
NEWdirectio 0 0K 0
NEWNFSnode 0 0K 0
NFSCL lck 0 0K 0
NFSCL lckown 0 0K 0
ice-resmgr 0 0K 0
ice-osdep 0 0K 0
ice 0 0K 0
iavf 0 0K 0
axgbe 0 0K 0
NFSCL client 0 0K 0
NFSCL deleg 0 0K 0
NFSCL open 0 0K 0
NFSCL owner 0 0K 0
NFS fh 0 0K 0
NFS req 0 0K 0
NFSD usrgroup 0 0K 0
NFSD string 0 0K 0
NFSD V4lock 0 0K 0
xen_intr 0 0K 0
NFSD V4state 0 0K 0
xen_hvm 0 0K 0
legacydrv 0 0K 0
bounce 0 0K 0
busdma 0 0K 0
qpidrv 0 0K 0
NFSD srvcache 0 0K 0
msdosfs_fat 0 0K 0
dmar_idpgtbl 0 0K 0
dmar_dom 0 0K 0
dmar_ctx 0 0K 0
msdosfs_mount 0 0K 0
msdosfs_node 0 0K 0
isci 0 0K 0
iommu_dmamap 0 0K 0
hyperv_socket 0 0K 0
bxe_ilt 0 0K 0
xenbus 0 0K 0
DEVFS4 0 0K 0
vm_fictitious 0 0K 0
DEVFS2 0 0K 0
gntdev 0 0K 0
privcmd_dev 0 0K 0
evtchn_dev 0 0K 0
xenstore 0 0K 0
scsi_pass 0 0K 0
ciss_data 0 0K 0
xnb 0 0K 0
xen_acpi 0 0K 0
xbbd 0 0K 0
xbd 0 0K 0
UMAHash 0 0K 0
Balloon 0 0K 0
sysmouse 0 0K 0
vm_pgdata 0 0K 0
jblocks 0 0K 0
savedino 0 0K 16480
sentinel 0 0K 0
jfsync 0 0K 0
jtrunc 0 0K 0
sbdep 0 0K 497
jsegdep 0 0K 0
jseg 0 0K 0
jfreefrag 0 0K 0
jfreeblk 0 0K 0
jnewblk 0 0K 0
jmvref 0 0K 0
jremref 0 0K 0
jaddref 0 0K 0
freedep 0 0K 0
freefrag 0 0K 799
allocindir 0 0K 0
allocdirect 0 0K 0
ufs_trim 0 0K 0
mactemp 0 0K 0
audit_trigger 0 0K 0
audit_pipe_presel 0 0K 0
audit_pipeent 0 0K 0
audit_pipe 0 0K 0
audit_evname 0 0K 0
audit_bsm 0 0K 0
audit_gidset 0 0K 0
audit_text 0 0K 0
audit_path 0 0K 0
audit_data 0 0K 0
audit_cred 0 0K 0
vtfont 0 0K 0
BACKLIGHT 0 0K 0
ath_hal 0 0K 0
athdev 0 0K 0
ata_pci 0 0K 0
ata_dma 0 0K 0
ata_generic 0 0K 0
pvscsi 0 0K 0
scsi_da 0 0K 69
ata_da 0 0K 0
scsi_ch 0 0K 0
scsi_cd 0 0K 0
ktls_ocf 0 0K 0
AHCI driver 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5E_TLS_RX 0 0K 0
MLX5EEPROM 0 0K 0
MLX5E_TLS 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EN 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5DUMP 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
seq_file 0 0K 0
lkpiskb 0 0K 0
radix 0 0K 0
idr 0 0K 0
lkpindev 0 0K 0
lkpifw 0 0K 0
lkpi80211 0 0K 0
NLM 0 0K 0
ipsec-spdcache 0 0K 0
ipsec-reg 0 0K 0
ipsec-misc 0 0K 0
ipsecrequest 0 0K 0
ip6_msource 0 0K 0
ip6_moptions 0 0K 1
in6_mfilter 0 0K 1
frag6 0 0K 0
tcplog 0 0K 0
tcp_hwpace 0 0K 0
USBdev 0 0K 0
USB 0 0K 0
LRO 0 0K 0
ip_moptions 0 0K 117
in_mfilter 0 0K 342
ipid 0 0K 0
80211scan 0 0K 0
80211ratectl 0 0K 0
80211power 0 0K 0
80211nodeie 0 0K 0
80211node 0 0K 0
80211mesh_gt 0 0K 0
80211mesh_rt 0 0K 0
80211perr 0 0K 0
80211prep 0 0K 0
80211preq 0 0K 0
80211dfs 0 0K 0
80211crypto 0 0K 0
80211vap 0 0K 0
iflib 0 0K 0
vlan 0 0K 0
gif 0 0K 0
ifdescr 0 0K 0
zlib 0 0K 0
fadvise 0 0K 0
VN POLL 0 0K 0
agp 0 0K 0
statfs 0 0K 13902
namei_tracker 0 0K 28
export_host 0 0K 0
cl_savebuf 0 0K 168
nvme_da 0 0K 0
acpipwr 0 0K 0
acpi_perf 0 0K 0
twsbuf 0 0K 0
twe_commands 0 0K 0
tcp_log_dev 0 0K 679
midi buffers 0 0K 0
mixer 0 0K 0
ac97 0 0K 0
hdacc 0 0K 0
hdac 0 0K 0
hdaa 0 0K 0
acpicmbat 0 0K 0
SIIS driver 0 0K 0
CAM CCB 0 0K 523
biobuf 0 0K 0
aios 0 0K 58
lio 0 0K 64
acl 0 0K 0
mbuf_tag 0 0K 269
PUC 0 0K 0
ppbusdev 0 0K 0
agtiapi_MemAlloc malloc 0 0K 0
osti_cacheable 0 0K 0
tempbuff 0 0K 0
tempbuff 0 0K 0
ag_tgt_map_t malloc 0 0K 0
ag_slr_map_t malloc 0 0K 0
lDevFlags * malloc 0 0K 0
tiDeviceHandle_t * malloc 0 0K 0
ag_portal_data_t malloc 0 0K 0
ag_device_t malloc 0 0K 0
STLock malloc 0 0K 0
CCB List 0 0K 0
sr_iov 0 0K 0
OCS 0 0K 0
OCS 0 0K 0
nvme 0 0K 0
nvd 0 0K 0
netmap 0 0K 0
mwldev 0 0K 0
MVS driver 0 0K 0
CAM ccb queue 0 0K 0
accf 0 0K 0
pts 0 0K 0
iov 0 0K 26204
ioctlops 0 0K 1583
eventfd 0 0K 67
Witness 0 0K 0
stack 0 0K 0
mrsasbuf 0 0K 0
mpt_user 0 0K 0
mps_user 0 0K 0
MPSSAS 0 0K 0
mps 0 0K 0
sbuf 0 0K 522
mpr_user 0 0K 0
firmware 0 0K 0
compressor 0 0K 0
MPRSAS 0 0K 0
SWAP 0 0K 0
mpr 0 0K 0
mfibuf 0 0K 0
sysctltmp 0 0K 960
sysctl 0 0K 3
ekcd 0 0K 0
dumper 0 0K 0
sendfile 0 0K 4
rctl 0 0K 0
malodev 0 0K 0
LED 0 0K 0
ix_sriov 0 0K 0
cache 0 0K 0
aacraidcam 0 0K 0
prison_racct 0 0K 0
Fail Points 0 0K 0
sigio 0 0K 12
pwd 0 0K 0
tty console 0 0K 0
ix 0 0K 0
ipsbuf 0 0K 0
aacraid_buf 0 0K 0
aaccam 0 0K 0
boottrace 0 0K 0
aacbuf 0 0K 0
zstd 0 0K 0
XZ_DEC 0 0K 0
nvlist 0 0K 0
SCSI ENC 0 0K 0
SCSI sa 0 0K 0
isofs_node 0 0K 0
isofs_mount 0 0K 0
tr_raid5_data 0 0K 0
tr_raid1e_data 0 0K 0
tr_raid1_data 0 0K 0
tr_raid0_data 0 0K 0
tr_concat_data 0 0K 0
md_sii_data 0 0K 0
md_promise_data 0 0K 0
md_nvidia_data 0 0K 0
md_jmicron_data 0 0K 0
md_intel_data 0 0K 0
md_ddf_data 0 0K 0
raid_data 0 0K 138
geom_flashmap 0 0K 0
tmpfs dir 0 0K 0
tmpfs name 0 0K 0
tmpfs mount 0 0K 0
NFS FHA 0 0K 0
newnfsmnt 0 0K 0
newnfsclient_req 0 0K 0
db> show uma
Zone Size Used Free Requests Sleeps Bucket Total Mem XFree
mbuf_jumbo_page 4096 8393 1513 128878 0 254 40574976 0
tcp_log 416 4999 15323 1104534 0 254 8453952 0
mbuf 256 9185 8608 3862851 0 254 4555008 0
pbuf 2624 0 957 0 0 2 2511168 0
malloc-16384 16384 139 5 13852 0 1 2359296 0
malloc-128 128 17244 426 77188 0 126 2261760 0
ertt_txseginfo 40 45640 10011 2096669 0 254 2226040 0
malloc-384 384 4264 446 21394 0 30 1808640 0
RADIX NODE 144 11977 450 304248 0 62 1789488 0
BUF TRIE 144 401 11359 41345 0 62 1693440 0
mbuf_cluster 2048 762 0 762 0 254 1560576 0
malloc-4096 4096 341 5 615 0 2 1417216 0
VM OBJECT 264 5111 109 327411 0 30 1378080 0
UMA Slabs 0 112 12137 25 12137 0 126 1362144 0
vmem btag 56 24229 74 24229 0 254 1360968 0
sctp_asoc 2256 180 330 6056 0 254 1150560 0
malloc-4096 4096 223 5 14864 0 2 933888 0
malloc-2048 2048 376 80 14314 0 8 933888 0
sctp_ep 1208 377 393 14057 0 254 930160 0
256 Bucket 2048 350 98 15959 0 8 917504 0
MAP ENTRY 96 9035 415 862558 0 126 907200 0
FFS inode 1160 689 32 16311 0 8 836360 0
tcp_bbr_map 128 2313 3887 493856 0 127 793600 0
socket 960 321 443 22087 0 254 733440 0
THREAD 1808 321 31 18502 0 8 636416 0
tcpcb 1104 55 456 5144 0 254 564144 0
VMSPACE 2552 171 9 14667 0 4 459360 0
malloc-65536 65536 4 2 362 0 1 393216 0
lkpimm 168 1 2327 1 0 62 391104 0
lkpicurr 168 2 2326 2 0 62 391104 0
sctp_raddr 736 186 331 6926 0 254 380512 0
VNODE 448 730 116 16354 0 30 379008 0
malloc-64 64 5289 570 191143 0 254 374976 0
sctp_chunk 152 140 2148 67250 0 254 347776 0
malloc-16 16 20028 472 27701 0 254 328000 0
malloc-65536 65536 2 3 195 0 1 327680 0
FPU_save_area 832 323 46 21790 0 16 307008 0
malloc-384 384 575 205 21070 0 30 299520 0
PROC 1352 208 8 14728 0 8 292032 0
malloc-1024 1024 176 96 6070 0 16 278528 0
malloc-256 256 579 486 37164 0 62 272640 0
UMA Zones 768 348 1 348 0 16 268032 0
malloc-65536 65536 3 1 139 0 1 262144 0
malloc-32768 32768 1 7 21028 0 1 262144 0
malloc-32 32 7591 347 9203 0 254 254016 0
filedesc0 1072 208 16 14848 0 8 240128 0
DEVCTL 1024 0 220 177 0 0 225280 0
mbuf_packet 256 124 638 69106 0 254 195072 0
malloc-128 128 1332 187 27692 0 126 194432 0
FFS2 dinode 256 689 61 16310 0 62 192000 0
malloc-256 256 569 181 31127 0 62 192000 0
malloc-256 256 290 400 65817 0 62 176640 0
malloc-32768 32768 0 5 10 0 1 163840 0
malloc-1024 1024 132 28 449 0 16 163840 0
128 Bucket 1024 66 81 3456 0 16 150528 0
S VFS Cache 104 1027 377 17265 0 126 146016 0
malloc-256 256 2 568 33290 0 62 145920 0
zio_buf_comb_131072 131072 0 1 1 0 1 131072 0
malloc-8192 8192 10 6 276 0 1 131072 0
malloc-2048 2048 9 55 516 0 8 131072 0
unpcb 256 20 490 1647 0 254 130560 0
UMA Kegs 384 333 0 333 0 30 127872 0
clpbuf 2624 0 48 1139 0 16 125952 0
ksiginfo 112 204 840 3850 0 126 116928 0
malloc-16384 16384 0 7 71 0 1 114688 0
malloc-16384 16384 7 0 22 0 1 114688 0
malloc-4096 4096 22 6 136 0 2 114688 0
64 Bucket 512 114 86 23659 0 30 102400 0
malloc-64 64 1302 273 52518 0 254 100800 0
malloc-32768 32768 1 2 121 0 1 98304 0
malloc-8192 8192 12 0 14 0 1 98304 0
g_bio 408 0 240 330780 0 30 97920 0
malloc-384 384 218 22 613 0 30 92160 0
syncache 168 0 528 18 0 254 88704 0
malloc-128 128 438 213 5380 0 126 83328 0
sctp_readq 152 0 520 923 0 254 79040 0
Files 80 623 277 51374 0 126 72000 0
malloc-64 64 906 165 30100 0 254 68544 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-32768 32768 0 2 20 0 1 65536 0
malloc-2048 2048 14 18 489 0 8 65536 0
malloc-256 256 133 122 1125 0 62 65280 0
malloc-256 256 211 44 32395 0 62 65280 0
32 Bucket 256 118 137 10608 0 62 65280 0
tcp_inpcb

---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

未讀,
2022年8月4日 上午9:37:332022/8/4
收件者:syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: dc6f578a8f53 virtio_mmio: correct offset of VIRTIO_MMIO_CO..
git tree: freebsd-src
console output: https://syzkaller.appspot.com/x/log.txt?x=109c813e080000
dashboard link: https://syzkaller.appspot.com/bug?extid=8a3ead6aa115945e43fc
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=12edd146080000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+8a3ead...@syzkaller.appspotmail.com

panic: ASan: Invalid access, 8-byte read at 0xfffffe0092c3beb0, UMAUseAfterFree(fd)
cpuid = 0
time = 1659614624
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0xc7/frame 0xfffffe00540d8890
kdb_backtrace() at kdb_backtrace+0xd3/frame 0xfffffe00540d89f0
vpanic() at vpanic+0x254/frame 0xfffffe00540d8ad0
panic() at panic+0xb5/frame 0xfffffe00540d8ba0
kasan_report() at kasan_report+0xdc/frame 0xfffffe00540d8c70
__mtx_lock_flags() at __mtx_lock_flags+0x125/frame 0xfffffe00540d8d50
sctp_sendall_completes() at sctp_sendall_completes+0x41/frame 0xfffffe00540d8d70
sctp_iterator_worker() at sctp_iterator_worker+0xff4/frame 0xfffffe00540d8ed0
sctp_iterator_thread() at sctp_iterator_thread+0x5e/frame 0xfffffe00540d8ef0
fork_exit() at fork_exit+0xd0/frame 0xfffffe00540d8f30
fork_trampoline() at fork_trampoline+0xe/frame 0xfffffe00540d8f30
--- trap 0, rip = 0, rsp = 0, rbp = 0 ---
KDB: enter: panic
[ thread pid 5 tid 100067 ]
Stopped at kdb_enter+0x6b: movq $0,0x2760b8a(%rip)
db>
db> set $lines = 0
db> set $maxwidth = 0
db> show registers
cs 0x20
ds 0x3b
es 0x3b
fs 0x13
gs 0x1b
ss 0x28
rax 0x12
rcx 0x1fffffc00a81b0c8
rdx 0xdffff7c000000000
rbx 0
rsp 0xfffffe00540d89d0
rbp 0xfffffe00540d89f0
rsi 0x1
rdi 0
r8 0x3
r9 0xffffffff
r10 0
r11 0
r12 0
r13 0xfffffe0057875720
r14 0xffffffff82b66260 .str.26
r15 0xffffffff82b66260 .str.26
rip 0xffffffff8171c60b kdb_enter+0x6b
rflags 0x46
kdb_enter+0x6b: movq $0,0x2760b8a(%rip)
db> show proc
Process 5 (sctp_iterator) at 0xfffffe005798fa90:
state: NORMAL
uid: 0 gids: 0
parent: pid 0 at 0xffffffff83e207e0
ABI: null
flag: 0x10000204 flag2: 0
reaper: 0xffffffff83e207e0 reapsubtree: 5
sigparent: 20
vmspace: 0xffffffff83e21780
(map 0xffffffff83e21780)
(map.pmap 0xffffffff83e21840)
(pmap 0xffffffff83e218b0)
threads: 1
100067 Run CPU 0 [sctp_iterator]
db> ps
pid ppid pgrp uid state wmesg wchan cmd
18786 800 800 0 RE CPU 1 syz-executor.3
18785 798 798 0 R (threaded) syz-executor.2
100899 RunQ syz-executor.2
117982 S uwait 0xfffffe0092be1d80 syz-executor.2
18784 797 797 0 RE syz-executor.0
14290 14276 14290 0 Ss select 0xfffffe0056fd0f40 dhclient
14283 1 14283 0 Ss select 0xfffffe0057a62d40 dhclient
14276 14252 430 65 S select 0xfffffe0057a62f40 dhclient
14252 430 430 0 S wait 0xfffffe00925c2000 sh
14225 1 14225 65 Ss select 0xfffffe0056fd1840 dhclient
3275 1 3275 0 Ss select 0xfffffe0056fd18c0 dhclient
3265 1 3265 0 Ss select 0xfffffe0056fd12c0 dhclient
808 795 808 0 Rs syz-executor.1
800 795 800 0 Ss nanslp 0xffffffff83e4a841 syz-executor.3
798 795 798 0 Rs syz-executor.2
797 795 797 0 Rs syz-executor.0
795 793 793 0 S (threaded) syz-execprog
100113 S uwait 0xfffffe0058b94900 syz-execprog
100115 S uwait 0xfffffe0058b94b00 syz-execprog
100116 S wait 0xfffffe00925c1000 syz-execprog
100117 S wait 0xfffffe00925c1000 syz-execprog
100119 S uwait 0xfffffe0057881b80 syz-execprog
100120 S uwait 0xfffffe0057881c80 syz-execprog
100121 S kqread 0xfffffe0092775800 syz-execprog
100122 S wait 0xfffffe00925c1000 syz-execprog
100123 S uwait 0xfffffe0057882400 syz-execprog
100124 S wait 0xfffffe00925c1000 syz-execprog
100125 S uwait 0xfffffe0057881180 syz-execprog
100383 S uwait 0xfffffe0057882a00 syz-execprog
793 791 793 0 Ss pause 0xfffffe00925b2b40 csh
791 688 791 0 Ss select 0xfffffe0056fd1540 sshd
754 1 754 0 Ss+ ttyin 0xfffffe0056fcbcb0 getty
753 1 753 0 Ss+ ttyin 0xfffffe00586b08b0 getty
752 1 752 0 Ss+ ttyin 0xfffffe00586b20b0 getty
751 1 751 0 Ss+ ttyin 0xfffffe00586b28b0 getty
750 1 750 0 Ss+ ttyin 0xfffffe0053f410b0 getty
749 1 749 0 Ss+ ttyin 0xfffffe0053f418b0 getty
748 1 748 0 Ss+ ttyin 0xfffffe0053f420b0 getty
747 1 747 0 Ss+ ttyin 0xfffffe0053f428b0 getty
746 1 746 0 Ss+ ttyin 0xfffffe0053f430b0 getty
692 1 692 0 Ss nanslp 0xffffffff83e4a841 cron
688 1 688 0 Ss select 0xfffffe0056fd1a40 sshd
501 1 501 0 Ss select 0xfffffe0057a62dc0 syslogd
430 1 430 0 Ss wait 0xfffffe0058ba2000 devd
429 1 429 65 Ss select 0xfffffe0056fd1ac0 dhclient
344 1 344 0 Ss select 0xfffffe0056fd19c0 dhclient
341 1 341 0 Ss select 0xfffffe0057a62e40 dhclient
17 0 0 0 DL syncer 0xffffffff83f70020 [syncer]
16 0 0 0 DL vlruwt 0xfffffe0056f88a90 [vnlru]
15 0 0 0 DL (threaded) [bufdaemon]
100079 D psleep 0xffffffff83f6e620 [bufdaemon]
100082 D - 0xffffffff83212100 [bufspacedaemon-0]
100094 D sdflush 0xfffffe0058a1f4e8 [/ worker]
9 0 0 0 DL psleep 0xffffffff83fa2180 [vmdaemon]
8 0 0 0 DL (threaded) [pagedaemon]
100077 D psleep 0xffffffff83f96038 [dom0]
100080 D launds 0xffffffff83f96044 [laundry: dom0]
100081 D umarcl 0xffffffff81e57fd0 [uma]
7 0 0 0 DL - 0xffffffff83c06da8 [rand_harvestq]
6 0 0 0 DL pftm 0xffffffff84595550 [pf purge]
5 0 0 0 RL CPU 0 [sctp_iterator]
4 0 0 0 DL (threaded) [cam]
100044 D - 0xffffffff83aa9340 [doneq0]
100045 D - 0xffffffff83aa92c0 [async]
100076 D - 0xffffffff83aa9140 [scanner]
14 0 0 0 DL seqstat 0xfffffe0053fa5088 [sequencer 00]
3 0 0 0 DL (threaded) [crypto]
100040 D crypto_ 0xffffffff83f91820 [crypto]
100041 D crypto_ 0xfffffe0053c8a830 [crypto returns 0]
100042 D crypto_ 0xfffffe0053c8a880 [crypto returns 1]
13 0 0 0 DL (threaded) [geom]
100035 D - 0xffffffff83e1fdc0 [g_event]
100036 D - 0xffffffff83e1fde0 [g_up]
100037 D - 0xffffffff83e1fe00 [g_down]
2 0 0 0 WL (threaded) [clock]
100030 I [clock (0)]
100031 I [clock (1)]
12 0 0 0 WL (threaded) [intr]
100015 I [swi5: fast taskq]
100018 I [swi6: task queue]
100019 I [swi6: Giant taskq]
100029 I [swi1: netisr 0]
100032 I [swi1: hpts]
100033 I [swi1: hpts]
100046 I [irq24: virtio_pci0]
100047 I [irq25: virtio_pci0]
100048 I [irq26: virtio_pci0]
100049 I [irq27: virtio_pci0]
100050 I [irq28: virtio_pci1]
100051 I [irq29: virtio_pci1]
100052 I [irq30: virtio_pci1]
100053 I [irq31: virtio_pci1]
100054 I [irq32: virtio_pci1]
100059 I [irq33: virtio_pci2]
100060 I [irq34: virtio_pci2]
100061 I [irq35: virtio_pci2]
100063 I [irq1: atkbd0]
100064 I [irq12: psm0]
100065 I [swi0: uart uart++]
100069 I [swi1: pf send]
11 0 0 0 RL (threaded) [idle]
100003 CanRun [idle: cpu0]
100004 CanRun [idle: cpu1]
1 0 1 0 SLs wait 0xfffffe0053ddf000 [init]
10 0 0 0 DL audit_w 0xffffffff83f92300 [audit]
0 0 0 0 DLs (threaded) [kernel]
100000 D swapin 0xffffffff83e207e0 [swapper]
100005 D - 0xfffffe0053c8ae00 [if_config_tqg_0]
100006 D - 0xfffffe0053c8ad00 [softirq_0]
100007 D - 0xfffffe0053c8ac00 [softirq_1]
100008 D - 0xfffffe0053c8ab00 [if_io_tqg_0]
100009 D - 0xfffffe0053c8aa00 [if_io_tqg_1]
100010 D - 0xfffffe0008187000 [inm_free taskq]
100011 D - 0xfffffe0008186e00 [linuxkpi_irq_wq]
100012 D - 0xfffffe0008186d00 [in6m_free taskq]
100013 D - 0xfffffe0008186c00 [deferred_unmount ta]
100014 D - 0xfffffe0008186b00 [thread taskq]
100016 D - 0xfffffe0008186900 [pci_hp taskq]
100017 D - 0xfffffe0008186800 [kqueue_ctx taskq]
100020 D - 0xfffffe0008186500 [aiod_kick taskq]
100021 D - 0xfffffe0008186400 [linuxkpi_short_wq_0]
100022 D - 0xfffffe0008186400 [linuxkpi_short_wq_1]
100023 D - 0xfffffe0008186400 [linuxkpi_short_wq_2]
100024 D - 0xfffffe0008186400 [linuxkpi_short_wq_3]
100025 D - 0xfffffe0008186300 [linuxkpi_long_wq_0]
100026 D - 0xfffffe0008186300 [linuxkpi_long_wq_1]
100027 D - 0xfffffe0008186300 [linuxkpi_long_wq_2]
100028 D - 0xfffffe0008186300 [linuxkpi_long_wq_3]
100034 D - 0xfffffe0008186200 [firmware taskq]
100038 D - 0xfffffe0008186100 [crypto_0]
100039 D - 0xfffffe0008186100 [crypto_1]
100055 D - 0xfffffe0008185e00 [vtnet0 rxq 0]
100056 D - 0xfffffe0008185d00 [vtnet0 txq 0]
100057 D - 0xfffffe0008185c00 [vtnet0 rxq 1]
100058 D - 0xfffffe0008185b00 [vtnet0 txq 1]
100062 D vtbslp 0xfffffe0056f5b380 [virtio_balloon]
100066 D - 0xffffffff82b6c260 [deadlkres]
100070 D - 0xfffffe0008187100 [mca taskq]
100071 D - 0xfffffe0058600300 [acpi_task_0]
100072 D - 0xfffffe0058600300 [acpi_task_1]
100073 D - 0xfffffe0058600300 [acpi_task_2]
100075 D - 0xfffffe0008186000 [CAM taskq]
db> show all locks
Process 18784 (syz-executor.0) thread 0xfffffe0092bde1e0 (100422)
exclusive sleep mutex sctp-create (inp_create) r = 0 (0xfffffe0092c38548) locked @ /syzkaller/managers/main/kernel/sys/netinet/sctp_pcb.c:3338
db> show malloc
Type InUse MemUse Requests
pf_hash 5 11524K 5
tcp_hpts 7 4801K 7
devbuf 4217 4323K 4245
sysctloid 35205 2074K 35276
vtbuf 24 1968K 46
inodedep 3663 1886K 17934
kobj 328 1312K 490
newblk 11 1027K 18333
vfscache 3 1025K 3
dirrem 3648 912K 17859
pcb 25 541K 35716
ufs_quota 1 512K 1
vfs_hash 1 512K 1
callout 2 512K 2
intr 4 472K 4
freefile 3648 456K 17854
vmem 3 274K 6
subproc 124 232K 18860
acpica 1674 184K 57585
vnet_data 1 168K 1
tidhash 3 141K 3
linker 358 134K 386
pagedep 15 132K 17866
tfo_ccache 1 128K 1
filedesc 16 121K 35724
DEVFS1 109 109K 126
sem 4 106K 4
bus 995 81K 5210
mtx_pool 2 72K 2
syncache 1 68K 1
module 514 65K 514
acpitask 1 64K 1
ddb_capture 1 64K 1
BPF 30 53K 30
umtx 352 44K 352
kdtrace 206 42K 36772
temp 34 33K 2136
DEVFS3 128 32K 138
hostcache 1 32K 1
shm 1 32K 1
msg 4 30K 4
gtaskqueue 18 26K 18
kbdmux 6 22K 6
DEVFS_RULE 56 20K 56
ifaddr 68 20K 70
ufs_mount 4 17K 5
proc 3 17K 3
tty 16 16K 16
routetbl 130 16K 410
ithread 97 16K 97
bus-sc 34 15K 1682
lltable 42 13K 43
KTRACE 100 13K 100
ifnet 7 13K 7
ether_multi 152 13K 162
eventhandler 136 12K 136
kenv 95 12K 95
rman 88 11K 431
GEOM 61 11K 481
CAM queue 5 11K 1528
in6_multi 65 9K 65
bmsafemap 3 9K 17898
UART 12 9K 12
devstat 4 9K 4
ksem 1 8K 1
rpc 2 8K 2
shmfd 1 8K 1
pfs_vncache 1 8K 1
pfs_nodes 20 8K 20
audit_evclass 237 8K 296
taskqueue 63 7K 63
cred 26 7K 295
sglist 5 7K 5
CAM DEV 3 6K 510
plimit 22 6K 456
kqueue 53 6K 18793
ufs_dirhash 24 5K 24
UMA 271 5K 271
pf_ifnet 10 5K 19
vt 11 5K 11
memdesc 1 4K 1
MCA 32 4K 32
evdev 4 4K 4
acpisem 28 4K 28
session 28 4K 48
hhook 15 4K 17
proc-args 81 4K 20039
pwddesc 49 4K 18787
terminal 11 3K 11
lockf 24 3K 43
selfd 38 3K 8255
uidinfo 3 3K 12
local_apic 1 2K 1
io_apic 1 2K 1
fpukern_ctx 2 2K 2
ipsec-saq 2 2K 2
ip6ndp 12 2K 14
Unitno 30 2K 47
sctp_ifa 13 2K 14
diradd 13 2K 17898
select 13 2K 46
CAM XPT 22 2K 543
msi 12 2K 12
in_multi 6 2K 8
ipsecpolicy 2 2K 2
acpidev 20 2K 20
clone 9 2K 9
tun 7 2K 7
freework 5 2K 17855
softdep 1 1K 1
mkdir 8 1K 35696
freeblks 4 1K 17854
sahead 1 1K 1
secasvar 1 1K 1
nhops 6 1K 8
vnodemarker 2 1K 46
NFSD session 1 1K 1
CAM periph 4 1K 271
sctp_ifn 6 1K 14
sctp_atcl 2 1K 17831
ipsec 3 1K 3
DEVFSP 12 1K 17
mld 6 1K 6
igmp 6 1K 6
toponodes 6 1K 6
isadev 6 1K 6
mount 16 1K 89
pci_link 10 1K 10
crypto 4 1K 4
encap_export_host 12 1K 12
newdirblk 4 1K 17848
pfil 4 1K 4
cdev 2 1K 2
inpcbpolicy 12 1K 206
chacha20random 1 1K 1
procdesc 3 1K 14
osd 7 1K 18
sctp_iter 1 1K 17841
NFSD lckfile 1 1K 1
NFSD V4client 1 1K 1
DEVFS 9 1K 10
vnodes 1 1K 1
CAM SIM 2 1K 2
feeder 7 1K 7
tcpfunc 3 1K 3
CC Mem 3 1K 7
loginclass 3 1K 7
prison 6 1K 6
lkpikmalloc 5 1K 6
aesni_data 2 1K 2
cryptodev 2 1K 49
sctp_cpal 1 1K 17829
nexusdev 8 1K 8
apmdev 1 1K 1
atkbddev 2 1K 2
CAM dev queue 2 1K 2
CAM I/O Scheduler 1 1K 1
CAM path 4 1K 1034
pmchooks 1 1K 1
soname 4 1K 21320
sctp_vrf 1 1K 1
sctp_atky 2 1K 17831
vnet 1 1K 1
entropy 2 1K 47
pmc 1 1K 1
acpiintr 1 1K 1
filecaps 3 1K 105
sctp_athm 2 1K 17831
cpus 2 1K 2
vnet_data_free 1 1K 1
Per-cpu 1 1K 1
p1003.1b 1 1K 1
tcp_do 0 0K 0
tcp_fsb 0 0K 0
sctp_mcore 0 0K 0
sctp_socko 0 0K 17830
sctp_mvrf 0 0K 0
sctp_timw 0 0K 0
sctp_cmsg 0 0K 0
sctp_stre 0 0K 0
sctp_athi 0 0K 0
sctp_a_it 0 0K 12
sctp_aadr 0 0K 0
sctp_stro 0 0K 0
sctp_stri 0 0K 0
sctp_map 0 0K 0
filemon 0 0K 0
ipcomp 0 0K 0
esp 0 0K 0
ah 0 0K 0
pf_table 0 0K 0
pf_rule 0 0K 0
pf_altq 0 0K 0
pf_osfp 0 0K 0
pf_temp 0 0K 0
mqdata 0 0K 0
savedino 0 0K 4457
sentinel 0 0K 0
jfsync 0 0K 0
jtrunc 0 0K 0
sbdep 0 0K 9
jsegdep 0 0K 0
jseg 0 0K 0
jfreefrag 0 0K 0
jfreeblk 0 0K 0
jnewblk 0 0K 0
jmvref 0 0K 0
jremref 0 0K 0
jaddref 0 0K 0
freedep 0 0K 0
freefrag 0 0K 1
allocindir 0 0K 0
indirdep 0 0K 10
ip6opt 0 0K 6
ip6_msource 0 0K 0
ip6_moptions 0 0K 0
in6_mfilter 0 0K 0
frag6 0 0K 0
tcplog 0 0K 0
tcp_hwpace 0 0K 0
USBdev 0 0K 0
USB 0 0K 0
LRO 0 0K 0
ip_msource 0 0K 0
ip_moptions 0 0K 0
in_mfilter 0 0K 0
ipid 0 0K 0
80211scan 0 0K 0
80211ratectl 0 0K 0
80211power 0 0K 0
80211nodeie 0 0K 0
80211node 0 0K 0
80211mesh_gt 0 0K 0
80211mesh_rt 0 0K 0
80211perr 0 0K 0
80211prep 0 0K 0
80211preq 0 0K 0
80211dfs 0 0K 0
80211crypto 0 0K 0
80211vap 0 0K 0
iflib 0 0K 0
vlan 0 0K 0
gif 0 0K 0
ifdescr 0 0K 0
zlib 0 0K 0
fadvise 0 0K 0
VN POLL 0 0K 0
agp 0 0K 0
statfs 0 0K 18044
namei_tracker 0 0K 0
export_host 0 0K 0
cl_savebuf 0 0K 2
nvme_da 0 0K 0
acpipwr 0 0K 0
acpi_perf 0 0K 0
twsbuf 0 0K 0
twe_commands 0 0K 0
tcp_log_dev 0 0K 0
midi buffers 0 0K 0
mixer 0 0K 0
ac97 0 0K 0
hdacc 0 0K 0
hdac 0 0K 0
hdaa 0 0K 0
acpicmbat 0 0K 0
SIIS driver 0 0K 0
CAM CCB 0 0K 523
biobuf 0 0K 0
aio 0 0K 0
lio 0 0K 0
acl 0 0K 0
mbuf_tag 0 0K 101
ktls 0 0K 0
iov 0 0K 33177
ioctlops 0 0K 105
eventfd 0 0K 0
Witness 0 0K 0
stack 0 0K 0
mrsasbuf 0 0K 0
mpt_user 0 0K 0
mps_user 0 0K 0
MPSSAS 0 0K 0
mps 0 0K 0
sbuf 0 0K 288
mpr_user 0 0K 0
firmware 0 0K 0
compressor 0 0K 0
MPRSAS 0 0K 0
SWAP 0 0K 0
mpr 0 0K 0
mfibuf 0 0K 0
sysctltmp 0 0K 710
sysctl 0 0K 3
md_sectors 0 0K 0
ekcd 0 0K 0
dumper 0 0K 0
sendfile 0 0K 0
rctl 0 0K 0
md_disk 0 0K 0
malodev 0 0K 0
LED 0 0K 0
ix_sriov 0 0K 0
cache 0 0K 0
aacraidcam 0 0K 0
kcovinfo 0 0K 0
prison_racct 0 0K 0
Fail Points 0 0K 0
sigio 0 0K 1
filedesc_to_leader 0 0K 0
raid_data 0 0K 72
geom_flashmap 0 0K 0
tmpfs dir 0 0K 0
tmpfs name 0 0K 0
tmpfs mount 0 0K 0
NFS FHA 0 0K 0
newnfsmnt 0 0K 0
newnfsclient_req 0 0K 0
db> show uma
Zone Size Used Free Requests Sleeps Bucket Total Mem XFree
mbuf_jumbo_page 4096 8320 1078 12317 0 254 38494208 0
mbuf 256 8636 1026 32866 0 254 2473472 0
malloc-384 384 3684 1956 17989 0 30 2165760 0
pbuf 2624 0 794 0 0 2 2083456 0
BUF TRIE 144 186 11574 652 0 62 1693440 0
malloc-384 384 4184 76 22015 0 30 1635840 0
malloc-256 256 4072 2018 54704 0 62 1559040 0
malloc-128 128 11552 166 11608 0 126 1499904 0
malloc-4096 4096 330 4 18538 0 2 1368064 0
UMA Slabs 0 112 10658 28 10658 0 126 1196832 0
mbuf_cluster 2048 508 0 508 0 254 1040384 0
vmem btag 56 18035 76 18035 0 254 1014216 0
malloc-256 256 54 3606 4817 0 62 936960 0
malloc-128 128 3665 2132 17886 0 126 742016 0
FFS inode 1160 516 30 18371 0 8 633360 0
RADIX NODE 144 3858 449 367880 0 64 620208 0
sctp_ep 1208 2 508 17831 0 254 616080 0
tcpcb 1104 3 508 7 0 254 564144 0
VM OBJECT 264 1797 93 404401 0 30 498960 0
socket 960 32 476 19290 0 254 487680 0
malloc-65536 65536 4 2 102 0 1 393216 0
lkpimm 168 1 2327 1 0 62 391104 0
lkpicurr 168 2 2326 2 0 62 391104 0
malloc-65536 65536 3 2 11 0 1 327680 0
THREAD 1824 154 22 17984 0 8 321024 0
VNODE 448 551 115 18408 0 30 298368 0
256 Bucket 2048 139 5 1171 0 8 294912 0
malloc-64 64 3890 457 22641 0 254 278208 0
MAP ENTRY 96 2316 330 819274 0 126 254016 0
malloc-4096 4096 55 5 18792 0 2 245760 0
malloc-16 16 14573 177 32507 0 254 236000 0
DEVCTL 1024 18 202 150 0 0 225280 0
malloc-16384 16384 8 5 17860 0 1 212992 0
malloc-2048 2048 6 90 1229 0 8 196608 0
UMA Zones 768 243 1 243 0 16 187392 0
malloc-32 32 5306 364 5530 0 254 181440 0
malloc-128 128 1156 239 27114 0 126 178560 0
FPU_save_area 832 156 42 18048 0 16 164736 0
malloc-1024 1024 135 25 1315 0 16 163840 0
S VFS Cache 104 1061 460 18937 0 126 158184 0
malloc-128 128 1060 87 1084 0 126 146816 0
FFS2 dinode 256 516 54 18370 0 62 145920 0
128 Bucket 1024 75 56 3387 0 16 134144 0
malloc-65536 65536 0 2 136 0 1 131072 0
64 Bucket 512 165 91 8074 0 30 131072 0
unpcb 256 14 496 1223 0 254 130560 0
malloc-256 256 21 489 54043 0 62 130560 0
mbuf_packet 256 8 500 17967 0 254 130048 0
ksiginfo 112 63 981 132 0 126 116928 0
VMSPACE 2560 34 11 18771 0 4 115200 0
g_bio 408 0 270 6045 0 30 110160 0
malloc-128 128 407 368 54556 0 126 99200 0
PROC 1352 50 22 18786 0 8 97344 0
32 Bucket 256 131 244 22273 0 62 96000 0
UMA Kegs 384 229 4 229 0 30 89472 0
filedesc0 1072 51 26 18787 0 8 82544 0
malloc-4096 4096 14 4 34 0 2 73728 0
malloc-64 64 535 536 16563 0 254 68544 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-32768 32768 2 0 2 0 1 65536 0
malloc-32768 32768 0 2 120 0 1 65536 0
malloc-16384 16384 4 0 19 0 1 65536 0
malloc-4096 4096 15 1 640 0 2 65536 0
malloc-8192 8192 7 0 7 0 1 57344 0
malloc-8192 8192 6 1 8 0 1 57344 0
da_ccb 544 0 98 1614 0 16 53312 0
malloc-64 64 356 463 27376 0 254 52416 0
malloc-64 64 484 335 1051 0 254 52416 0
malloc-128 128 76 327 18608 0 126 51584 0
malloc-128 128 169 234 3614 0 126 51584 0
malloc-128 128 16 387 17869 0 126 51584 0
malloc-256 256 72 123 259 0 62 49920 0
malloc-256 256 41 154 18605 0 62 49920 0
malloc-256 256 36 159 18563 0 62 49920 0
DIRHASH 1024 35 13 35 0 16 49152 0
NAMEI 1024 0 48 85987 0 16 49152 0
malloc-8192 8192 6 0 6 0 1 49152 0
malloc-2048 2048 14 10 62 0 8 49152 0
malloc-2048 2048 4 20 17833 0 8 49152 0
malloc-384 384 73 47 73 0 30 46080 0
syncache 168 0 264 5 0 254 44352 0
clpbuf 2624 0 16 16 0 16 41984 0
pcpu-8 8 4665 455 4821 0 254 40960 0
Mountpoints 2752 2 12 2 0 4 38528 0
udp_inpcb 424 6 84 190 0 30 38160 0
pipe 744 21 29 381 0 16 37200 0
malloc-64 64 11 556 83 0 254 36288 0
malloc-64 64 170 397 677 0 254 36288 0
malloc-64 64 91 476 18853 0 254 36288 0
routing nhops 256 27 108 34 0 62 34560 0
ttyoutq 256 72 63 160 0 62 34560 0
malloc-256 256 24 111 141 0 62 34560 0
malloc-256 256 24 111 17919 0 62 34560 0
TURNSTILE 136 177 75 177 0 62 34272 0
malloc-32768 32768 1 0 1 0 1 32768 0
malloc-16384 16384 0 2 160 0 1 32768 0
malloc-8192 8192 4 0 4 0 1 32768 0
malloc-4096 4096 7 1 7 0 2 32768 0
malloc-2048 2048 3 13 3 0 8 32768 0
malloc-2048 2048 7 9 9 0 8 32768 0
malloc-2048 2048 1 15 75 0 8 32768 0
malloc-1024 1024 4 28 44 0 16 32768 0
malloc-1024 1024 5 27 5 0 16 32768 0
malloc-1024 1024 4 28 166 0 16 32768 0
malloc-1024 1024 1 31 8 0 16 32768 0
malloc-512 512 0 64 118 0 30 32768 0
malloc-512 512 1 63 15 0 30 32768 0
malloc-512 512 16 48 66 0 30 32768 0
pcpu-64 64 493 19 493 0 254 32768 0
KNOTE 160 26 174 98604 0 62 32000 0
ttyinq 160 135 65 300 0 62 32000 0
Files 80 141 259 43751 0 126 32000 0
cpuset 104 7 272 7 0 126 29016 0
sctp_laddr 48 0 588 12 0 254 28224 0
PWD 32 17 865 17950 0 254 28224 0
malloc-32 32 280 602 3107 0 254 28224 0
16 Bucket 144 52 144 319 0 62 28224 0
4 Bucket 48 6 582 431 0 254 28224 0
ripcb 424 3 60 9 0 30 26712 0
tcp_inpcb 424 3 60 7 0 30 26712 0
PGRP 88 28 248 48 0 126 24288 0
rl_entry 40 41 565 41 0 254 24240 0
rtentry 168 30 114 34 0 62 24192 0
8 Bucket 80 55 245 2797 0 126 24000 0
malloc-384 384 53 7 53 0 30 23040 0
malloc-384 384 4 56 365 0 30 23040 0
SLEEPQUEUE 88 177 79 177 0 126 22528 0
hostcache 64 1 314 1 0 254 20160 0
udpcb 32 6 624 190 0 254 20160 0
udp_inpcb ports 32 3 627 40 0 254 20160 0
ertt 72 3 277 7 0 126 20160 0
malloc-64 64 3 312 7 0 254 20160 0
malloc-32 32 16 614 17936 0 254 20160 0
malloc-32 32 77 553 704 0 254 20160 0
malloc-32 32 112 518 18014 0 254 20160 0
malloc-32 32 89 541 1176 0 254 20160 0
malloc-32 32 165 465 1071 0 254 20160 0
malloc-32 32 9 621 44 0 254 20160 0
2 Bucket 32 54 576 2015 0 254 20160 0
epoch_record pcpu 256 4 60 4 0 62 16384 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-8192 8192 1 1 102 0 1 16384 0
malloc-2048 2048 1 7 13 0 8 16384 0
malloc-2048 2048 1 7 1 0 8 16384 0
malloc-1024 1024 7 9 8 0 16 16384 0
malloc-1024 1024 10 6 518 0 16 16384 0
malloc-1024 1024 6 10 6 0 16 16384 0
malloc-512 512 1 31 1 0 30 16384 0
malloc-512 512 1 31 1 0 30 16384 0
malloc-512 512 2 30 47 0 30 16384 0
malloc-512 512 1 31 1 0 30 16384 0
SMR CPU 32 7 504 7 0 254 16352 0
kenv 258 15 45 1048 0 30 15480 0
mqnode 416 3 33 3 0 30 14976 0
vmem 1856 1 7 1 0 8 14848 0
SMR SHARED 24 7 504 7 0 254 12264 0
ertt_txseginfo 40 0 303 195 0 254 12120 0
tcp_inpcb ports 32 1 377 1 0 254 12096 0
malloc-16 16 12 738 23 0 254 12000 0
malloc-16 16 286 464 291 0 254 12000 0
malloc-16 16 75 675 18029 0 254 12000 0
malloc-16 16 27 723 18187 0 254 12000 0
malloc-16 16 228 522 22516 0 254 12000 0
malloc-16 16 23 727 44133 0 254 12000 0
malloc-16 16 10 740 11 0 254 12000 0
malloc-384 384 11 19 11 0 30 11520 0
malloc-8192 8192 0 1 26 0 1 8192 0
malloc-8192 8192 0 1 1 0 1 8192 0
malloc-8192 8192 1 0 1 0 1 8192 0
malloc-4096 4096 0 2 1 0 2 8192 0
malloc-4096 4096 1 1 1 0 2 8192 0
pcpu-16 16 14 498 14 0 254 8192 0
vtnet_tx_hdr 24 0 334 1335 0 254 8016 0
UMA Slabs 1 176 10 12 10 0 62 3872 0
KMAP ENTRY 96 12 27 14 0 0 3744 0
pcpu-4 4 1 511 1 0 254 2048 0
FFS1 dinode 128 0 0 0 0 126 0 0
ada_ccb 272 0 0 0 0 30 0 0
swblk 136 0 0 0 0 62 0 0
swpctrie 144 0 0 0 0 62 0 0
cdg_qdiffsample 16 0 0 0 0 254 0 0
pf state scrubs 40 0 0 0 0 254 0 0
pf frag entries 40 0 0 0 0 254 0 0
pf frags 248 0 0 0 0 62 0 0
pf table entries 160 0 0 0 0 254 0 0
pf table entry counters 64 0 0 0 0 254 0 0
pf source nodes 136 0 0 0 0 254 0 0
pf state keys 88 0 0 0 0 126 0 0
pf states 312 0 0 0 0 254 0 0
pf tags 104 0 0 0 0 126 0 0
pf mtags 184 0 0 0 0 62 0 0
tcp_rack_pcb 896 0 0 0 0 16 0 0
tcp_rack_map 120 0 0 0 0 126 0 0
tcp_bbr_pcb 832 0 0 0 0 16 0 0
tcp_bbr_map 128 0 0 0 0 126 0 0
ipq 56 0 0 0 0 254 0 0
tfo_ccache_entries 80 0 0 0 0 126 0 0
tfo 4 0 0 0 0 254 0 0
sackhole 32 0 0 0 0 254 0 0
tcptw 72 0 0 0 0 254 0 0
sctp_asconf_ack 48 0 0 0 0 254 0 0
sctp_asconf 40 0 0 0 0 254 0 0
sctp_stream_msg_out 112 0 0 0 0 254 0 0
sctp_readq 152 0 0 0 0 254 0 0
sctp_chunk 152 0 0 0 0 254 0 0
sctp_raddr 736 0 0 0 0 254 0 0
sctp_asoc 2256 0 0 0 0 254 0 0
tcp_log_id_node 120 0 0 0 0 126 0 0
tcp_log_id_bucket 176 0 0 0 0 62 0 0
tcp_log 416 0 0 0 0 254 0 0
tcpreass 48 0 0 0 0 254 0 0
ripcb ports 32 0 0 0 0 254 0 0
udplite_inpcb ports 32 0 0 0 0 254 0 0
udplite_inpcb 424 0 0 0 0 30 0 0
IPsec SA lft_c 16 0 0 0 0 254 0 0
itimer 352 0 0 0 0 30 0 0
AIOLIO 272 0 0 0 0 30 0 0
AIOCB 552 0 0 0 0 16 0 0
AIO 208 0 0 0 0 62 0 0
NCLNODE 608 0 0 0 0 16 0 0
TMPFS node 224 0 0 0 0 62 0 0
mqnotifier 216 0 0 0 0 62 0 0
mvdata 64 0 0 0 0 254 0 0
mqueue 248 0 0 0 0 62 0 0
LTS VFS Cache 360 0 0 0 0 30 0 0
L VFS Cache 320 0 0 0 0 30 0 0
STS VFS Cache 144 0 0 0 0 62 0 0
cryptop 280 0 0 0 0 30 0 0
linux_dma_object 32 0 0 0 0 254 0 0
linux_dma_pctrie 144 0 0 0 0 62 0 0
IOMMU_MAP_ENTRY 104 0 0 0 0 126 0 0
mbuf_jumbo_16k 16384 0 0 0 0 254 0 0
mbuf_jumbo_9k 9216 0 0 0 0 254 0 0
audit_record 1280 0 0 0 0 8 0 0
domainset 40 0 0 0 0 254 0 0
MAC labels 40 0 0 0 0 254 0 0
vnpbuf 2624 0 0 0 0 64 0 0
mdpbuf 2624 0 0 0 0 3 0 0
nfspbuf 2624 0 0 0 0 16 0 0
swwbuf 2624 0 0 0 0 8 0 0
swrbuf 2624 0 0 0 0 16 0 0
umtx_shm 88 0 0 0 0 126 0 0
umtx pi 96 0 0 0 0 126 0 0
rangeset pctrie nodes 144 0 0 0 0 62 0 0
malloc-65536 65536 0 0 0 0 1 0 0
malloc-65536 65536 0 0 0 0 1 0 0
malloc-65536 65536 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-16384 16384 0 0 0 0 1 0 0
malloc-16384 16384

syzbot

未讀,
2022年10月22日 下午4:08:462022/10/22
收件者:syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: f585d13dd60b rtld: remove unused macro FPTR_TARGET
git tree: freebsd-src
console output: https://syzkaller.appspot.com/x/log.txt?x=176b0a36880000
dashboard link: https://syzkaller.appspot.com/bug?extid=8a3ead6aa115945e43fc
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1619b8d6880000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=175f4686880000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+8a3ead...@syzkaller.appspotmail.com

panic: ASan: Invalid access, 8-byte read at 0xfffffe0092c10260, UMAUseAfterFree(fd)
cpuid = 0
time = 1666469153
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0xc7/frame 0xfffffe0007cca890
kdb_backtrace() at kdb_backtrace+0xd3/frame 0xfffffe0007cca9f0
vpanic() at vpanic+0x254/frame 0xfffffe0007ccaad0
panic() at panic+0xb5/frame 0xfffffe0007ccaba0
kasan_report() at kasan_report+0xdc/frame 0xfffffe0007ccac70
__mtx_lock_flags() at __mtx_lock_flags+0x125/frame 0xfffffe0007ccad50
sctp_sendall_completes() at sctp_sendall_completes+0x41/frame 0xfffffe0007ccad70
sctp_iterator_worker() at sctp_iterator_worker+0xff4/frame 0xfffffe0007ccaed0
sctp_iterator_thread() at sctp_iterator_thread+0x5e/frame 0xfffffe0007ccaef0
fork_exit() at fork_exit+0xd0/frame 0xfffffe0007ccaf30
fork_trampoline() at fork_trampoline+0xe/frame 0xfffffe0007ccaf30
--- trap 0, rip = 0, rsp = 0, rbp = 0 ---
KDB: enter: panic
[ thread pid 5 tid 100067 ]
Stopped at kdb_enter+0x6b: movq $0,0x2765faa(%rip)
db>
db> set $lines = 0
db> set $maxwidth = 0
db> show registers
cs 0x20
ds 0x3b
es 0x3b
fs 0x13
gs 0x1b
ss 0x28
rax 0x12
rcx 0x1fffffc000f994c8
rdx 0xdffff7c000000000
rbx 0
rsp 0xfffffe0007cca9d0
rbp 0xfffffe0007cca9f0
rsi 0x1
rdi 0
r8 0x3
r9 0xffffffff
r10 0
r11 0xfffffe0058bfcfe0
r12 0
r13 0xfffffe0057850720
r14 0xffffffff82b79d80 .str.26
r15 0xffffffff82b79d80 .str.26
rip 0xffffffff817221eb kdb_enter+0x6b
rflags 0x46
kdb_enter+0x6b: movq $0,0x2765faa(%rip)
db> show proc
Process 5 (sctp_iterator) at 0xfffffe005796d558:
state: NORMAL
uid: 0 gids: 0
parent: pid 0 at 0xffffffff83e2b820
ABI: null
flag: 0x10000204 flag2: 0
reaper: 0xffffffff83e2b820 reapsubtree: 5
sigparent: 20
vmspace: 0xffffffff83e2c7c0
(map 0xffffffff83e2c7c0)
(map.pmap 0xffffffff83e2c880)
(pmap 0xffffffff83e2c8f0)
threads: 1
100067 Run CPU 0 [sctp_iterator]
db> ps
pid ppid pgrp uid state wmesg wchan cmd
1083 779 777 0 RE CPU 1 syz-executor1678739
779 777 777 0 S nanslp 0xffffffff83e55941 syz-executor1678739
777 775 777 0 Ss pause 0xfffffe009261a0c0 csh
775 688 775 0 Ss select 0xfffffe0092669cc0 sshd
754 1 754 0 Ss+ ttyin 0xfffffe005744ecb0 getty
753 1 753 0 Ss+ ttyin 0xfffffe00586010b0 getty
752 1 752 0 Ss+ ttyin 0xfffffe00586014b0 getty
751 1 751 0 Ss+ ttyin 0xfffffe00586018b0 getty
750 1 750 0 Ss+ ttyin 0xfffffe0058601cb0 getty
749 1 749 0 Ss+ ttyin 0xfffffe00586020b0 getty
748 1 748 0 Ss+ ttyin 0xfffffe00586024b0 getty
747 1 747 0 Ss+ ttyin 0xfffffe00586028b0 getty
746 1 746 0 Ss+ ttyin 0xfffffe0058602cb0 getty
744 1 18 0 S+ piperd 0xfffffe0058b2d3e8 logger
743 742 18 0 S+ nanslp 0xffffffff83e55940 sleep
742 1 18 0 S+ wait 0xfffffe0092618558 sh
692 1 692 0 Ss nanslp 0xffffffff83e55941 cron
688 1 688 0 Ss select 0xfffffe005785eb40 sshd
501 1 501 0 Ss select 0xfffffe0007ac2b40 syslogd
430 1 430 0 Ss select 0xfffffe0007ac2bc0 devd
429 1 429 65 Ss select 0xfffffe0007ac29c0 dhclient
344 1 344 0 Ss select 0xfffffe0007ac2a40 dhclient
341 1 341 0 Ss select 0xfffffe00574393c0 dhclient
17 0 0 0 DL syncer 0xffffffff83f7ade0 [syncer]
16 0 0 0 DL vlruwt 0xfffffe0056f87010 [vnlru]
15 0 0 0 DL (threaded) [bufdaemon]
100079 D psleep 0xffffffff83f79400 [bufdaemon]
100082 D - 0xffffffff83212100 [bufspacedaemon-0]
100094 D sdflush 0xfffffe005744d4e8 [/ worker]
9 0 0 0 DL psleep 0xffffffff83face00 [vmdaemon]
8 0 0 0 DL (threaded) [pagedaemon]
100077 D psleep 0xffffffff83fa0cb8 [dom0]
100080 D launds 0xffffffff83fa0cc4 [laundry: dom0]
100081 D umarcl 0xffffffff81e68d70 [uma]
7 0 0 0 DL - 0xffffffff83c11e28 [rand_harvestq]
6 0 0 0 DL pftm 0xffffffff848c52e0 [pf purge]
5 0 0 0 RL CPU 0 [sctp_iterator]
4 0 0 0 DL (threaded) [cam]
100044 D - 0xffffffff83ab4340 [doneq0]
100045 D - 0xffffffff83ab42c0 [async]
100076 D - 0xffffffff83ab4140 [scanner]
14 0 0 0 DL seqstat 0xfffffe0056ed8c88 [sequencer 00]
3 0 0 0 DL (threaded) [crypto]
100040 D crypto_ 0xffffffff83f9c420 [crypto]
100041 D crypto_ 0xfffffe0007b50030 [crypto returns 0]
100042 D crypto_ 0xfffffe0007b50080 [crypto returns 1]
13 0 0 0 DL (threaded) [geom]
100035 D - 0xffffffff83e2ae00 [g_event]
100036 D - 0xffffffff83e2ae20 [g_up]
100037 D - 0xffffffff83e2ae40 [g_down]
2 0 0 0 WL (threaded) [clock]
100029 I [clock (0)]
100030 I [clock (1)]
12 0 0 0 WL (threaded) [intr]
100012 I [swi6: Giant taskq]
100014 I [swi5: fast taskq]
100017 I [swi6: task queue]
100031 I [swi1: netisr 0]
100032 I [swi1: hpts]
100033 I [swi1: hpts]
100046 I [irq24: virtio_pci0]
100047 I [irq25: virtio_pci0]
100048 I [irq26: virtio_pci0]
100049 I [irq27: virtio_pci0]
100050 I [irq28: virtio_pci1]
100051 I [irq29: virtio_pci1]
100052 I [irq30: virtio_pci1]
100053 I [irq31: virtio_pci1]
100054 I [irq32: virtio_pci1]
100059 I [irq33: virtio_pci2]
100060 I [irq34: virtio_pci2]
100061 I [irq35: virtio_pci2]
100063 I [irq1: atkbd0]
100064 I [irq12: psm0]
100065 I [swi0: uart uart++]
100069 I [swi1: pf send]
11 0 0 0 RL (threaded) [idle]
100003 CanRun [idle: cpu0]
100004 CanRun [idle: cpu1]
1 0 1 0 SLs wait 0xfffffe00541d0010 [init]
10 0 0 0 DL audit_w 0xffffffff83f9cfa0 [audit]
0 0 0 0 DLs (threaded) [kernel]
100000 D swapin 0xffffffff83e2b820 [swapper]
100005 D - 0xfffffe0007968700 [if_io_tqg_0]
100006 D - 0xfffffe0007968200 [if_io_tqg_1]
100007 D - 0xfffffe0007968100 [if_config_tqg_0]
100008 D - 0xfffffe0007968000 [softirq_0]
100009 D - 0xfffffe0007967e00 [softirq_1]
100010 D - 0xfffffe00085f4e00 [linuxkpi_irq_wq]
100011 D - 0xfffffe00085f4d00 [deferred_unmount ta]
100013 D - 0xfffffe00085f4b00 [thread taskq]
100015 D - 0xfffffe00085f4900 [kqueue_ctx taskq]
100016 D - 0xfffffe00085f4800 [pci_hp taskq]
100018 D - 0xfffffe00085f4600 [inm_free taskq]
100019 D - 0xfffffe00085f4500 [aiod_kick taskq]
100020 D - 0xfffffe00085f4400 [in6m_free taskq]
100021 D - 0xfffffe00085f4300 [linuxkpi_short_wq_0]
100022 D - 0xfffffe00085f4300 [linuxkpi_short_wq_1]
100023 D - 0xfffffe00085f4300 [linuxkpi_short_wq_2]
100024 D - 0xfffffe00085f4300 [linuxkpi_short_wq_3]
100025 D - 0xfffffe00085f4200 [linuxkpi_long_wq_0]
100026 D - 0xfffffe00085f4200 [linuxkpi_long_wq_1]
100027 D - 0xfffffe00085f4200 [linuxkpi_long_wq_2]
100028 D - 0xfffffe00085f4200 [linuxkpi_long_wq_3]
100034 D - 0xfffffe00085f4100 [firmware taskq]
100038 D - 0xfffffe00085f3600 [crypto_0]
100039 D - 0xfffffe00085f3600 [crypto_1]
100055 D - 0xfffffe00085f2700 [vtnet0 rxq 0]
100056 D - 0xfffffe00085f2600 [vtnet0 txq 0]
100057 D - 0xfffffe00085f2500 [vtnet0 rxq 1]
100058 D - 0xfffffe00085f2400 [vtnet0 txq 1]
100062 D vtbslp 0xfffffe0007981580 [virtio_balloon]
100066 D - 0xffffffff82b7fe21 [deadlkres]
100071 D - 0xfffffe00085f3300 [acpi_task_0]
100072 D - 0xfffffe00085f3300 [acpi_task_1]
100073 D - 0xfffffe00085f3300 [acpi_task_2]
100074 D - 0xfffffe00085f5100 [mca taskq]
100075 D - 0xfffffe00085f2e00 [CAM taskq]
db> show all locks
Process 1083 (syz-executor1678739) thread 0xfffffe0058bfcac0 (100090)
shared rm osd_object (osd_object) r = 0 (0xffffffff836d7060) locked @ /syzkaller/managers/main/kernel/sys/kern/kern_osd.c:306
shared rw helper list lock (helper list lock) r = 0 (0xffffffff83e2f300) locked @ /syzkaller/managers/main/kernel/sys/kern/kern_khelp.c:197
db> show malloc
Type InUse MemUse Requests
pf_hash 5 11524K 5
tcp_hpts 7 4801K 7
devbuf 4216 4323K 4241
sysctloid 35104 2068K 35175
vtbuf 24 1968K 46
kobj 329 1316K 493
newblk 789 1221K 819
vfscache 3 1025K 3
pcb 19 537K 646
inodedep 44 529K 72
ufs_quota 1 512K 1
vfs_hash 1 512K 1
callout 2 512K 2
intr 4 472K 4
subproc 97 185K 1140
acpica 1674 184K 58126
tidhash 3 141K 3
vmem 3 138K 4
linker 351 133K 384
pagedep 14 132K 18
tfo_ccache 1 128K 1
IP reass 1 128K 1
vnet_data 1 112K 1
sem 4 106K 4
DEVFS1 105 105K 114
bus 998 82K 5213
mtx_pool 2 72K 2
syncache 1 68K 1
module 515 65K 515
acpitask 1 64K 1
ddb_capture 1 64K 1
temp 17 33K 1605
hostcache 1 32K 1
shm 1 32K 1
kdtrace 157 32K 1200
DEVFS3 124 31K 134
umtx 242 31K 242
msg 4 30K 4
gtaskqueue 18 26K 18
kbdmux 6 22K 6
DEVFS_RULE 56 20K 56
BPF 10 18K 10
ufs_mount 4 17K 5
proc 3 17K 3
tty 16 16K 16
ithread 97 16K 97
bus-sc 34 15K 1682
KTRACE 100 13K 100
eventhandler 151 13K 151
kenv 95 12K 95
ifaddr 30 12K 32
rman 88 11K 431
GEOM 61 11K 483
routetbl 50 11K 176
CAM queue 5 11K 1528
cred 33 9K 234
UART 12 9K 12
devstat 4 9K 4
ksem 1 8K 1
rpc 2 8K 2
bmsafemap 1 8K 40
shmfd 1 8K 1
pfs_vncache 1 8K 1
pfs_nodes 20 8K 20
audit_evclass 237 8K 296
taskqueue 63 7K 63
sglist 5 7K 5
CAM DEV 3 6K 510
ufs_dirhash 24 5K 24
UMA 270 5K 270
dirrem 17 5K 28
plimit 17 5K 322
vt 11 5K 11
ifnet 3 5K 3
memdesc 1 4K 1
MCA 32 4K 32
filedesc 1 4K 1
evdev 4 4K 4
acpisem 28 4K 28
hhook 15 4K 17
ether_multi 40 4K 50
diradd 25 4K 36
lltable 11 4K 11
pf_ifnet 5 3K 6
in6_multi 25 3K 25
terminal 11 3K 11
kqueue 41 3K 1086
session 20 3K 31
pwddesc 40 3K 1084
clone 9 3K 9
uidinfo 3 3K 8
proc-args 63 3K 2024
local_apic 1 2K 1
io_apic 1 2K 1
fpukern_ctx 2 2K 2
ipsec-saq 2 2K 2
selfd 27 2K 16640
Unitno 27 2K 41
CAM XPT 22 2K 543
lockf 15 2K 22
msi 12 2K 12
ipsecpolicy 2 2K 2
acpidev 20 2K 20
softdep 1 1K 1
sahead 1 1K 1
secasvar 1 1K 1
vnodemarker 2 1K 10
NFSD session 1 1K 1
CAM periph 4 1K 271
select 7 1K 29
ipsec 3 1K 3
indirdep 3 1K 3
nhops 6 1K 6
toponodes 6 1K 6
isadev 6 1K 6
mount 16 1K 89
pci_link 10 1K 10
sctp_ifa 5 1K 6
crypto 4 1K 4
ip6ndp 4 1K 5
encap_export_host 12 1K 12
newdirblk 4 1K 8
mkdir 4 1K 16
in_multi 2 1K 4
pfil 4 1K 4
cdev 2 1K 2
CC Mem 3 1K 7
chacha20random 1 1K 1
osd 7 1K 18
inpcbpolicy 10 1K 139
sctp_iter 1 1K 308
sctp_ifn 2 1K 6
NFSD lckfile 1 1K 1
NFSD V4client 1 1K 1
DEVFSP 4 1K 9
DEVFS 9 1K 10
mld 2 1K 2
igmp 2 1K 2
vnodes 1 1K 1
CAM SIM 2 1K 2
feeder 7 1K 7
tcpfunc 3 1K 3
loginclass 3 1K 7
prison 6 1K 6
lkpikmalloc 5 1K 6
aesni_data 2 1K 2
cryptodev 2 1K 49
sctp_cpal 1 1K 304
nexusdev 8 1K 8
apmdev 1 1K 1
atkbddev 2 1K 2
CAM dev queue 2 1K 2
CAM I/O Scheduler 1 1K 1
CAM path 4 1K 1034
procdesc 1 1K 6
pmchooks 1 1K 1
soname 4 1K 3423
filecaps 4 1K 66
tun 3 1K 3
sctp_vrf 1 1K 1
vnet 1 1K 1
entropy 2 1K 35
pmc 1 1K 1
acpiintr 1 1K 1
cpus 2 1K 2
vnet_data_free 1 1K 1
Per-cpu 1 1K 1
freework 1 1K 26
p1003.1b 1 1K 1
tcp_do 0 0K 0
tcp_fsb 0 0K 0
ipcomp 0 0K 0
esp 0 0K 0
ah 0 0K 0
pf_table 0 0K 0
pf_rule 0 0K 0
pf_altq 0 0K 0
pf_osfp 0 0K 0
pf_temp 0 0K 0
mqdata 0 0K 0
filemon 0 0K 0
sctp_mcore 0 0K 0
sctp_socko 0 0K 304
sctp_mvrf 0 0K 0
sctp_timw 0 0K 0
sctp_cmsg 0 0K 0
sctp_stre 0 0K 0
sctp_athi 0 0K 0
sctp_athm 0 0K 304
sctp_atky 0 0K 304
sctp_atcl 0 0K 304
sctp_a_it 0 0K 4
sctp_aadr 0 0K 0
sctp_stro 0 0K 0
sctp_stri 0 0K 0
sctp_map 0 0K 0
savedino 0 0K 13
sentinel 0 0K 0
jfsync 0 0K 0
jtrunc 0 0K 0
sbdep 0 0K 3
jsegdep 0 0K 0
jseg 0 0K 0
jfreefrag 0 0K 0
jfreeblk 0 0K 0
jnewblk 0 0K 0
jmvref 0 0K 0
jremref 0 0K 0
jaddref 0 0K 0
freedep 0 0K 0
freefile 0 0K 9
freeblks 0 0K 25
freefrag 0 0K 4
simple_attr 0 0K 0
seq_file 0 0K 0
lkpiskb 0 0K 0
radix 0 0K 0
idr 0 0K 0
lkpindev 0 0K 0
lkpifw 0 0K 0
lkpi80211 0 0K 0
NLM 0 0K 0
ipsec-spdcache 0 0K 0
ipsec-reg 0 0K 0
ipsec-misc 0 0K 0
ipsecrequest 0 0K 0
ip6opt 0 0K 3
ip6_msource 0 0K 0
ip6_moptions 0 0K 0
in6_mfilter 0 0K 0
frag6 0 0K 0
tcplog 0 0K 0
tcp_hwpace 0 0K 0
USBdev 0 0K 0
USB 0 0K 0
LRO 0 0K 0
ip_msource 0 0K 0
ip_moptions 0 0K 0
in_mfilter 0 0K 0
ipid 0 0K 0
80211scan 0 0K 0
80211ratectl 0 0K 0
80211power 0 0K 0
80211nodeie 0 0K 0
80211node 0 0K 0
80211mesh_gt 0 0K 0
80211mesh_rt 0 0K 0
80211perr 0 0K 0
80211prep 0 0K 0
80211preq 0 0K 0
80211dfs 0 0K 0
80211crypto 0 0K 0
80211vap 0 0K 0
iflib 0 0K 0
vlan 0 0K 0
gif 0 0K 0
ifdescr 0 0K 0
zlib 0 0K 0
fadvise 0 0K 0
VN POLL 0 0K 0
agp 0 0K 0
statfs 0 0K 195
namei_tracker 0 0K 0
export_host 0 0K 0
cl_savebuf 0 0K 4
nvme_da 0 0K 0
acpipwr 0 0K 0
acpi_perf 0 0K 0
twsbuf 0 0K 0
twe_commands 0 0K 0
tcp_log_dev 0 0K 0
midi buffers 0 0K 0
mixer 0 0K 0
ac97 0 0K 0
hdacc 0 0K 0
hdac 0 0K 0
hdaa 0 0K 0
acpicmbat 0 0K 0
SIIS driver 0 0K 0
CAM CCB 0 0K 523
biobuf 0 0K 0
aio 0 0K 0
lio 0 0K 0
acl 0 0K 0
mbuf_tag 0 0K 0
ktls 0 0K 0
iov 0 0K 14051
ioctlops 0 0K 86
eventfd 0 0K 0
Witness 0 0K 0
stack 0 0K 0
mrsasbuf 0 0K 0
mpt_user 0 0K 0
mps_user 0 0K 0
MPSSAS 0 0K 0
mps 0 0K 0
sbuf 0 0K 288
mpr_user 0 0K 0
firmware 0 0K 0
compressor 0 0K 0
MPRSAS 0 0K 0
SWAP 0 0K 0
mpr 0 0K 0
mfibuf 0 0K 0
sysctltmp 0 0K 650
sysctl 0 0K 3
md_sectors 0 0K 0
ekcd 0 0K 0
dumper 0 0K 0
sendfile 0 0K 0
rctl 0 0K 0
md_disk 0 0K 0
malodev 0 0K 0
LED 0 0K 0
ix_sriov 0 0K 0
cache 0 0K 0
aacraidcam 0 0K 0
kcovinfo 0 0K 0
prison_racct 0 0K 0
Fail Points 0 0K 0
sigio 0 0K 1
filedesc_to_leader 0 0K 0
raid_data 0 0K 72
geom_flashmap 0 0K 0
tmpfs dir 0 0K 0
tmpfs name 0 0K 0
tmpfs mount 0 0K 0
NFS FHA 0 0K 0
newnfsmnt 0 0K 0
newnfsclient_req 0 0K 0
db> show uma
Zone Size Used Free Requests Sleeps Bucket Total Mem XFree
mbuf_jumbo_page 4096 8320 1078 15920 0 254 38494208 0
mbuf 256 8577 1085 19690 0 254 2473472 0
pbuf 2624 0 778 0 0 2 2041472 0
BUF TRIE 144 193 11567 555 0 62 1693440 0
malloc-384 384 4117 23 4117 0 30 1589760 0
malloc-128 128 11515 79 11569 0 126 1484032 0
malloc-4096 4096 329 3 493 0 2 1359872 0
UMA Slabs 0 112 10544 34 10544 0 126 1184736 0
mbuf_cluster 2048 508 0 508 0 254 1040384 0
vmem btag 56 16289 94 16289 0 254 917448 0
sctp_ep 1208 0 510 304 0 254 616080 0
FFS inode 1160 499 19 510 0 8 600880 0
tcpcb 1104 3 508 7 0 254 564144 0
RADIX NODE 144 3368 239 23111 0 62 519408 0
socket 960 19 489 1623 0 254 487680 0
VM OBJECT 264 1418 112 26872 0 30 403920 0
lkpimm 168 1 2327 1 0 62 391104 0
lkpicurr 168 2 2326 2 0 62 391104 0
256 Bucket 2048 131 13 995 0 8 294912 0
malloc-256 256 1056 69 1368 0 62 288000 0
malloc-65536 65536 4 0 4 0 1 262144 0
malloc-64 64 3823 272 3853 0 254 262080 0
VNODE 448 529 47 542 0 30 258048 0
malloc-16 16 14513 237 14581 0 254 236000 0
DEVCTL 1024 0 220 124 0 0 225280 0
THREAD 1824 115 6 115 0 8 220704 0
malloc-128 128 1284 235 30501 0 126 194432 0
MAP ENTRY 96 1604 412 91705 0 126 193536 0
UMA Zones 768 242 2 242 0 16 187392 0
malloc-32 32 5304 366 5318 0 254 181440 0
malloc-4096 4096 41 3 1084 0 2 180224 0
malloc-128 128 923 224 1915 0 126 146816 0
FFS2 dinode 256 499 71 508 0 62 145920 0
malloc-65536 65536 2 0 2 0 1 131072 0
malloc-65536 65536 0 2 182 0 1 131072 0
malloc-65536 65536 2 0 2 0 1 131072 0
malloc-2048 2048 6 58 1342 0 8 131072 0
malloc-1024 1024 105 23 117 0 16 131072 0
unpcb 256 7 503 1163 0 254 130560 0
mbuf_packet 256 1 507 401 0 254 130048 0
S VFS Cache 104 966 204 1008 0 126 121680 0
FPU_save_area 832 117 27 130 0 16 119808 0
ksiginfo 112 38 1006 54 0 126 116928 0
malloc-32768 32768 3 0 3 0 1 98304 0
malloc-8192 8192 10 1 137 0 1 90112 0
UMA Kegs 384 228 5 228 0 30 89472 0
128 Bucket 1024 43 40 514 0 16 84992 0
VMSPACE 2560 24 9 1068 0 4 84480 0
clpbuf 2624 0 32 25 0 16 83968 0
malloc-16384 16384 3 2 177 0 1 81920 0
PROC 1368 40 15 1083 0 8 75240 0
filedesc0 1072 41 29 1084 0 8 75040 0
64 Bucket 512 66 70 1691 0 30 69632 0
malloc-64 64 555 516 2071 0 254 68544 0
malloc-64 64 535 536 15058 0 254 68544 0
malloc-128 128 345 182 575 0 126 67456 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-65536 65536 0 1 8 0 1 65536 0
malloc-32768 32768 0 2 120 0 1 65536 0
malloc-8192 8192 8 0 8 0 1 65536 0
malloc-4096 4096 13 3 108 0 2 65536 0
g_bio 408 0 150 4664 0 30 61200 0
malloc-64 64 178 641 1232 0 254 52416 0
malloc-256 256 146 49 165 0 62 49920 0
malloc-256 256 98 97 713 0 62 49920 0
32 Bucket 256 62 133 3536 0 62 49920 0
DIRHASH 1024 35 13 35 0 16 49152 0
NAMEI 1024 0 48 12179 0 16 49152 0
malloc-16384 16384 3 0 3 0 1 49152 0
malloc-4096 4096 10 2 10 0 2 49152 0
malloc-1024 1024 15 33 1591 0 16 49152 0
malloc-384 384 95 25 123 0 30 46080 0
syncache 168 0 264 5 0 254 44352 0
pipe 728 7 48 284 0 16 40040 0
Mountpoints 2752 2 12 2 0 4 38528 0
udp_inpcb 424 6 84 128 0 30 38160 0
pcpu-8 8 4221 387 4249 0 254 36864 0
malloc-64 64 46 521 16688 0 254 36288 0
malloc-64 64 58 509 1628 0 254 36288 0
malloc-64 64 219 348 230 0 254 36288 0
malloc-64 64 11 556 15 0 254 36288 0
malloc-128 128 6 273 7 0 126 35712 0
malloc-128 128 72 207 72 0 126 35712 0
malloc-128 128 59 220 81 0 126 35712 0
malloc-128 128 16 263 578 0 126 35712 0
routing nhops 256 10 125 17 0 62 34560 0
ttyoutq 256 72 63 160 0 62 34560 0
malloc-384 384 38 52 344 0 30 34560 0
malloc-384 384 56 34 56 0 30 34560 0
malloc-256 256 17 118 107 0 62 34560 0
malloc-256 256 19 116 949 0 62 34560 0
malloc-256 256 26 109 30 0 62 34560 0
malloc-256 256 10 125 413 0 62 34560 0
malloc-256 256 7 128 821 0 62 34560 0
malloc-4096 4096 7 1 552 0 2 32768 0
malloc-2048 2048 2 14 11 0 8 32768 0
malloc-2048 2048 6 10 93 0 8 32768 0
malloc-2048 2048 7 9 7 0 8 32768 0
malloc-1024 1024 2 30 10 0 16 32768 0
malloc-1024 1024 17 15 33 0 16 32768 0
malloc-1024 1024 5 27 5 0 16 32768 0
malloc-1024 1024 7 25 7 0 16 32768 0
malloc-512 512 5 59 190 0 30 32768 0
malloc-512 512 8 56 8 0 30 32768 0
malloc-512 512 4 60 4 0 30 32768 0
pcpu-64 64 495 17 495 0 254 32768 0
ttyinq 160 135 65 300 0 62 32000 0
cpuset 104 7 272 7 0 126 29016 0
sctp_laddr 48 0 588 4 0 254 28224 0
malloc-32 32 284 598 354 0 254 28224 0
malloc-32 32 110 772 1388 0 254 28224 0
16 Bucket 144 45 151 237 0 62 28224 0
4 Bucket 48 6 582 115 0 254 28224 0
ripcb 424 1 62 4 0 30 26712 0
tcp_inpcb 424 3 60 7 0 30 26712 0
da_ccb 544 0 49 1296 0 16 26656 0
TURNSTILE 136 122 67 122 0 62 25704 0
malloc-8192 8192 2 1 4 0 1 24576 0
PGRP 88 20 256 31 0 126 24288 0
ertt_txseginfo 40 0 606 580 0 254 24240 0
rl_entry 40 30 576 30 0 254 24240 0
rtentry 168 13 131 17 0 62 24192 0
Files 80 72 228 6868 0 126 24000 0
8 Bucket 80 38 262 325 0 126 24000 0
malloc-384 384 2 58 31 0 30 23040 0
malloc-384 384 1 59 347 0 30 23040 0
malloc-384 384 27 33 28 0 30 23040 0
malloc-384 384 4 56 5 0 30 23040 0
SLEEPQUEUE 88 122 134 122 0 126 22528 0
udpcb 32 6 624 128 0 254 20160 0
hostcache 64 1 314 1 0 254 20160 0
udp_inpcb ports 32 3 627 40 0 254 20160 0
ertt 72 3 277 7 0 126 20160 0
PWD 32 10 620 100 0 254 20160 0
malloc-32 32 36 594 386 0 254 20160 0
malloc-32 32 19 611 41 0 254 20160 0
2 Bucket 32 41 589 281 0 254 20160 0
epoch_record pcpu 256 4 60 4 0 62 16384 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-8192 8192 2 0 2 0 1 16384 0
malloc-8192 8192 2 0 2 0 1 16384 0
malloc-4096 4096 2 2 198 0 2 16384 0
malloc-2048 2048 1 7 1 0 8 16384 0
malloc-2048 2048 1 7 1 0 8 16384 0
malloc-2048 2048 1 7 1 0 8 16384 0
malloc-2048 2048 7 1 198 0 8 16384 0
malloc-1024 1024 8 8 9 0 16 16384 0
malloc-1024 1024 9 7 9 0 16 16384 0
malloc-512 512 0 32 1 0 30 16384 0
malloc-512 512 1 31 1 0 30 16384 0
malloc-512 512 0 32 1 0 30 16384 0
SMR CPU 32 7 504 7 0 254 16352 0
malloc-16 16 322 678 522 0 254 16000 0
kenv 258 15 45 1038 0 30 15480 0
mqnode 416 3 33 3 0 30 14976 0
vmem 1856 1 7 1 0 8 14848 0
SMR SHARED 24 7 504 7 0 254 12264 0
tcp_inpcb ports 32 1 377 1 0 254 12096 0
malloc-32 32 0 378 2 0 254 12096 0
malloc-32 32 131 247 738 0 254 12096 0
malloc-32 32 33 345 3939 0 254 12096 0
KNOTE 160 0 75 8 0 62 12000 0
malloc-16 16 19 731 58 0 254 12000 0
malloc-16 16 8 742 329 0 254 12000 0
malloc-16 16 43 707 58 0 254 12000 0
malloc-16 16 210 540 4344 0 254 12000 0
malloc-16 16 20 730 26980 0 254 12000 0
malloc-16 16 7 743 312 0 254 12000 0
malloc-8192 8192 1 0 1 0 1 8192 0
malloc-8192 8192 1 0 1 0 1 8192 0
malloc-4096 4096 1 1 1 0 2 8192 0
pcpu-16 16 14 498 14 0 254 8192 0
vtnet_tx_hdr 24 0 334 2267 0 254 8016 0
UMA Slabs 1 176 8 14 8 0 62 3872 0
KMAP ENTRY 96 12 27 14 0 0 3744 0
FFS1 dinode 128 0 0 0 0 126 0 0
ada_ccb 272 0 0 0 0 30 0 0
swblk 136 0 0 0 0 62 0 0
swpctrie 144 0 0 0 0 62 0 0
cdg_qdiffsample 16 0 0 0 0 254 0 0
pf state scrubs 40 0 0 0 0 254 0 0
pf frag entries 40 0 0 0 0 254 0 0
pf frags 248 0 0 0 0 62 0 0
pf table entries 160 0 0 0 0 254 0 0
pf table entry counters 64 0 0 0 0 254 0 0
pf source nodes 136 0 0 0 0 254 0 0
pf state keys 88 0 0 0 0 126 0 0
pf states 312 0 0 0 0 254 0 0
pf tags 104 0 0 0 0 126 0 0
pf mtags 184 0 0 0 0 62 0 0
tcp_rack_pcb 896 0 0 0 0 16 0 0
tcp_rack_map 120 0 0 0 0 126 0 0
tcp_bbr_pcb 832 0 0 0 0 16 0 0
tcp_bbr_map 128 0 0 0 0 126 0 0
ipq 56 0 0 0 0 254 0 0
tfo_ccache_entries 80 0 0 0 0 126 0 0
tfo 4 0 0 0 0 254 0 0
sackhole 32 0 0 0 0 254 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-16384 16384 0 0 0 0 1 0 0
malloc-16384 16384 0 0 0 0 1 0 0
malloc-16384 16384 0 0 0 0 1 0 0
malloc-16384 16384 0 0 0 0 1 0 0
malloc-16384 16384 0 0 0 0 1 0 0
malloc-8192 8192 0 0 0 0 1 0 0
malloc-4096 4096 0 0 0 0 2 0 0
malloc-512 512 0 0 0 0 30 0 0
malloc-512 512 0 0 0 0 30 0 0
pcpu-32 32 0 0 0 0 254 0 0
pcpu-4 4 0 0 0 0 254 0 0
fakepg 104 0 0 0 0 126 0 0
UMA Hash 256 0 0 0 0 62 0 0

回覆所有人
回覆作者
轉寄
0 則新訊息