Fatal trap NUM: page fault in pf_krule_global_RB_INSERT (2)

0 views
Skip to first unread message

syzbot

unread,
May 12, 2022, 9:52:27 PM5/12/22
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: f9e90c24737f LinuxKPI: Implement linux/hashtable.h for Fre..
git tree: freebsd-src
console output: https://syzkaller.appspot.com/x/log.txt?x=12260bfaf00000
dashboard link: https://syzkaller.appspot.com/bug?extid=0627bad101efe63cb5a3
userspace arch: i386

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+0627ba...@syzkaller.appspotmail.com

Fatal trap 12: page fault while in kernel mode
cpuid = 1; apic id = 01
fault virtual address = 0x0
fault code = supervi
sor read data, page not present
instruction pointer = 0x20:0xffffffff845ba4c4
stack pointer = 0x0:0xfffffe0097b15df0
frame pointer = 0x0:0xfffffe0097b15e30
code segment = base 0x0, limit 0xfffff, type 0x1b
= DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags = interrupt enabled,
FreeBSD/amd64resume, IOPL = 0
current process = 2109 (syz-executor.3)
trap number = 12
panic: page fault
cpuid = 0
time = 1652406699
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0xc7/frame 0xfffffe0097b155f0
kdb_backtrace() at kdb_backtrace+0xd3/frame 0xfffffe0097b15750
vpanic() at vpanic+0x2b8/frame 0xfffffe0097b15830
panic() at panic+0xb5/frame 0xfffffe0097b158f0
trap_fatal() at trap_fatal+0x6a4/frame 0xfffffe0097b159f0
trap_pfault() at trap_pfault+0x186/frame 0xfffffe0097b15b30
trap() at trap+0x5ad/frame 0xfffffe0097b15d20
calltrap() at calltrap+0x8/frame 0xfffffe0097b15d20
--- trap 0xc, rip = 0xffffffff845ba4c4, rsp = 0xfffffe0097b15df0, rbp = 0xfffffe0097b15e30 ---
pf_krule_global_RB_INSERT() at pf_krule_global_RB_INSERT+0x24/frame 0xfffffe0097b15e30
pfioctl() at pfioctl+0xc2e8/frame 0xfffffe0097b171d0
devfs_ioctl() at devfs_ioctl+0x22a/frame 0xfffffe0097b172b0
VOP_IOCTL_APV() at VOP_IOCTL_APV+0xb0/frame 0xfffffe0097b172f0
vn_ioctl() at vn_ioctl+0x215/frame 0xfffffe0097b17640
devfs_ioctl_f() at devfs_ioctl_f+0x71/frame 0xfffffe0097b17690
kern_ioctl() at kern_ioctl+0x631/frame 0xfffffe0097b17790
sys_ioctl() at sys_ioctl+0x31f/frame 0xfffffe0097b178f0
freebsd32_ioctl() at freebsd32_ioctl+0x629/frame 0xfffffe0097b17d30
ia32_syscall() at ia32_syscall+0x419/frame 0xfffffe0097b17f30
int0x80_syscall_common() at int0x80_syscall_common+0x9c/frame 0xfbffcf78
KDB: enter: panic
[ thread pid 2109 tid 101422 ]
Stopped at kdb_enter+0x6b: movq $0,0x26fef9a(%rip)
db> set $lines = 0
db> set $maxwidth = 0
db> show registers
cs 0x20
ds 0x3b
es 0x3b
fs 0x13
gs 0x1b
ss 0
rax 0x12
rcx 0x5d67283c5a0725b5
rdx 0x3ffff
rbx 0
rsp 0xfffffe0097b15730
rbp 0xfffffe0097b15750
rsi 0x40001
rdi 0xffffffff817821ba vprintf+0x35a
r8 0
r9 0xffffffff
r10 0
r11 0
r12 0xfffffe0097c371e0
r13 0xfffffe0097b15701
r14 0xffffffff82bc7e60 .str.26
r15 0xffffffff82bc7e60 .str.26
rip 0xffffffff817756fb kdb_enter+0x6b
rflags 0x200046 kernload+0x46
kdb_enter+0x6b: movq $0,0x26fef9a(%rip)
db> show proc
Process 2109 (syz-executor.3) at 0xfffffe0097c43000:
state: NORMAL
uid: 0 gids: 0, 0, 5
parent: pid 790 at 0xfffffe00579ada90
ABI: FreeBSD ELF32
flag: 0x10000080 flag2: 0
arguments: /root/syz-executor.3 exec
reaper: 0xfffffe0053dd8000 reapsubtree: 1
sigparent: 20
vmspace: 0xfffffe00998ba9f8
(map 0xfffffe00998ba9f8)
(map.pmap 0xfffffe00998baab8)
(pmap 0xfffffe00998bab20)
threads: 2
100133 S nanslp 0xffffffff83e41d01 syz-executor.3
101422 Run CPU 0 syz-executor.3
db> ps
pid ppid pgrp uid state wmesg wchan cmd
2109 790 790 0 R (threaded) syz-executor.3
100133 S nanslp 0xffffffff83e41d01 syz-executor.3
101422 Run CPU 0 syz-executor.3
1104 1098 1104 0 Ss select 0xfffffe009252a540 dhclient
1101 1 1101 0 Ss select 0xfffffe0092375a40 dhclient
1098 1091 430 65 S select 0xfffffe00923759c0 dhclient
1091 430 430 0 S wait 0xfffffe0058d61a90 sh
790 774 790 0 Ss nanslp 0xffffffff83e41d01 syz-executor.3
782 774 782 0 Ss piperd 0xfffffe0058b9b000 syz-executor.2
780 774 780 0 Ss piperd 0xfffffe0058b9eba0 syz-executor.1
779 774 779 0 Ss piperd 0xfffffe0058b9bba0 syz-executor.0
774 772 772 0 S (threaded) syz-fuzzer
100097 S uwait 0xfffffe0053f72800 syz-fuzzer
100111 S uwait 0xfffffe0007979100 syz-fuzzer
100112 S uwait 0xfffffe0007979200 syz-fuzzer
100113 S uwait 0xfffffe0007979300 syz-fuzzer
100114 S uwait 0xfffffe0007979400 syz-fuzzer
100115 S uwait 0xfffffe0053f72400 syz-fuzzer
100116 S uwait 0xfffffe0053f72500 syz-fuzzer
100117 S uwait 0xfffffe0007979500 syz-fuzzer
100119 S kqread 0xfffffe0053f6a000 syz-fuzzer
772 770 772 0 Ss pause 0xfffffe00927bf5f8 csh
770 688 770 0 Ss select 0xfffffe009252a840 sshd
754 1 754 0 Ss+ ttyin 0xfffffe0056fde8b0 getty
753 1 753 0 Ss+ ttyin 0xfffffe005747f4b0 getty
752 1 752 0 Ss+ ttyin 0xfffffe00586c30b0 getty
751 1 751 0 Ss+ ttyin 0xfffffe00586c38b0 getty
750 1 750 0 Ss+ ttyin 0xfffffe0053f330b0 getty
749 1 749 0 Ss+ ttyin 0xfffffe0053f338b0 getty
748 1 748 0 Ss+ ttyin 0xfffffe0053f340b0 getty
747 1 747 0 Ss+ ttyin 0xfffffe0053f348b0 getty
746 1 746 0 Ss+ ttyin 0xfffffe0053f350b0 getty
692 1 692 0 Ss nanslp 0xffffffff83e41d00 cron
688 1 688 0 Ss select 0xfffffe009252acc0 sshd
501 1 501 0 Ss select 0xfffffe009252ad40 syslogd
430 1 430 0 Ss wait 0xfffffe0058d63000 devd
429 1 429 65 Ss select 0xfffffe0092376240 dhclient
344 1 344 0 Ss select 0xfffffe009252ae40 dhclient
341 1 341 0 Ss select 0xfffffe00923762c0 dhclient
17 0 0 0 DL vlruwt 0xfffffe0056fa4548 [vnlru]
16 0 0 0 DL syncer 0xffffffff83f67560 [syncer]
15 0 0 0 DL (threaded) [bufdaemon]
100079 D psleep 0xffffffff83f65b60 [bufdaemon]
100080 D - 0xffffffff83211f80 [bufspacedaemon-0]
100093 D sdflush 0xfffffe0056fad4e8 [/ worker]
9 0 0 0 DL psleep 0xffffffff83f99600 [vmdaemon]
8 0 0 0 DL (threaded) [pagedaemon]
100077 D psleep 0xffffffff83f8d4b8 [dom0]
100081 D launds 0xffffffff83f8d4c4 [laundry: dom0]
100082 D umarcl 0xffffffff81eb1da0 [uma]
7 0 0 0 DL - 0xffffffff83bfe328 [rand_harvestq]
6 0 0 0 DL pftm 0xffffffff84579530 [pf purge]
5 0 0 0 DL waiting 0xffffffff848c94a0 [sctp_iterator]
4 0 0 0 DL (threaded) [cam]
100044 D - 0xffffffff83aa12c0 [doneq0]
100045 D - 0xffffffff83aa1240 [async]
100076 D - 0xffffffff83aa10c0 [scanner]
14 0 0 0 DL seqstat 0xfffffe0053fafc88 [sequencer 00]
3 0 0 0 DL (threaded) [crypto]
100040 D crypto_ 0xffffffff83f88ce0 [crypto]
100041 D crypto_ 0xfffffe0053f6c030 [crypto returns 0]
100042 D crypto_ 0xfffffe0053f6c080 [crypto returns 1]
13 0 0 0 DL (threaded) [geom]
100035 D - 0xffffffff83e17300 [g_event]
100036 D - 0xffffffff83e17320 [g_up]
100037 D - 0xffffffff83e17340 [g_down]
2 0 0 0 WL (threaded) [clock]
100029 I [clock (0)]
100030 I [clock (1)]
12 0 0 0 WL (threaded) [intr]
100015 I [swi5: fast taskq]
100018 I [swi6: task queue]
100019 I [swi6: Giant taskq]
100031 I [swi1: netisr 0]
100032 I [swi1: hpts]
100033 I [swi1: hpts]
100046 I [irq24: virtio_pci0]
100047 I [irq25: virtio_pci0]
100048 I [irq26: virtio_pci0]
100049 I [irq27: virtio_pci0]
100050 I [irq28: virtio_pci1]
100051 I [irq29: virtio_pci1]
100052 I [irq30: virtio_pci1]
100053 I [irq31: virtio_pci1]
100054 I [irq32: virtio_pci1]
100059 I [irq33: virtio_pci2]
100060 I [irq34: virtio_pci2]
100061 I [irq35: virtio_pci2]
100063 I [irq1: atkbd0]
100064 I [irq12: psm0]
100065 I [swi0: uart uart++]
100069 I [swi1: pf send]
11 0 0 0 RL (threaded) [idle]
100003 CanRun [idle: cpu0]
100004 Run CPU 1 [idle: cpu1]
1 0 1 0 SLs wait 0xfffffe0053dd8000 [init]
10 0 0 0 DL audit_w 0xffffffff83f897c0 [audit]
0 0 0 0 DLs (threaded) [kernel]
100000 D swapin 0xffffffff83e17d00 [swapper]
100005 D - 0xfffffe00081f8e00 [if_config_tqg_0]
100006 D - 0xfffffe00081f8d00 [softirq_0]
100007 D - 0xfffffe00081f8c00 [softirq_1]
100008 D - 0xfffffe00081f8b00 [if_io_tqg_0]
100009 D - 0xfffffe00081f8a00 [if_io_tqg_1]
100010 D - 0xfffffe0007972600 [inm_free taskq]
100011 D - 0xfffffe0007972400 [linuxkpi_irq_wq]
100012 D - 0xfffffe0007972200 [in6m_free taskq]
100013 D - 0xfffffe0007972000 [deferred_unmount ta]
100014 D - 0xfffffe0007971d00 [thread taskq]
100016 D - 0xfffffe0007971900 [kqueue_ctx taskq]
100017 D - 0xfffffe0007971700 [pci_hp taskq]
100020 D - 0xfffffe0007971100 [aiod_kick taskq]
100021 D - 0xfffffe0007970e00 [linuxkpi_short_wq_0]
100022 D - 0xfffffe0007970e00 [linuxkpi_short_wq_1]
100023 D - 0xfffffe0007970e00 [linuxkpi_short_wq_2]
100024 D - 0xfffffe0007970e00 [linuxkpi_short_wq_3]
100025 D - 0xfffffe0007970900 [linuxkpi_long_wq_0]
100026 D - 0xfffffe0007970900 [linuxkpi_long_wq_1]
100027 D - 0xfffffe0007970900 [linuxkpi_long_wq_2]
100028 D - 0xfffffe0007970900 [linuxkpi_long_wq_3]
100034 D - 0xfffffe0053ee7300 [firmware taskq]
100038 D - 0xfffffe0053ee6d00 [crypto_0]
100039 D - 0xfffffe0053ee6d00 [crypto_1]
100055 D - 0xfffffe0053ee5b00 [vtnet0 rxq 0]
100056 D - 0xfffffe0053ee5a00 [vtnet0 txq 0]
100057 D - 0xfffffe0053ee5900 [vtnet0 rxq 1]
100058 D - 0xfffffe0053ee5800 [vtnet0 txq 1]
100062 D vtbslp 0xfffffe0056f7c280 [virtio_balloon]
100066 D - 0xffffffff82bcdce0 [deadlkres]
100070 D - 0xfffffe0007973200 [mca taskq]
100072 D - 0xfffffe005789a600 [acpi_task_0]
100073 D - 0xfffffe005789a600 [acpi_task_1]
100074 D - 0xfffffe005789a600 [acpi_task_2]
100075 D - 0xfffffe0053ee6600 [CAM taskq]
db> show all locks
Process 2109 (syz-executor.3) thread 0xfffffe0097c371e0 (101422)
exclusive rm pf rulesets (pf rulesets) r = 0 (0xffffffff846356a0) locked @ /syzkaller/managers/i386/kernel/sys/netpfil/pf/pf_ioctl.c:3436
exclusive sx pf config (pf config) r = 0 (0xffffffff846354c0) locked @ /syzkaller/managers/i386/kernel/sys/netpfil/pf/pf_ioctl.c:3435
db> show malloc
Type InUse MemUse Requests
pf_hash 5 11524K 5
tcp_hpts 7 4801K 7
devbuf 4217 4323K 4245
sysctloid 35322 2081K 35393
vtbuf 24 1968K 46
kobj 328 1312K 489
newblk 17 1028K 1673
vfscache 3 1025K 3
inodedep 773 802K 1297
pcb 20 537K 1025
ufs_quota 1 512K 1
vfs_hash 1 512K 1
callout 2 512K 2
intr 4 472K 4
subproc 113 210K 2183
dirrem 750 188K 1231
acpica 1674 184K 57552
vnet_data 1 168K 1
vmem 3 146K 5
tidhash 3 141K 3
linker 358 134K 386
pagedep 15 132K 1236
tfo_ccache 1 128K 1
DEVFS1 109 109K 126
sem 4 106K 4
freefile 750 94K 1229
filedesc 12 89K 2469
bus 994 81K 5207
mtx_pool 2 72K 2
syncache 1 68K 1
module 513 65K 513
acpitask 1 64K 1
ddb_capture 1 64K 1
umtx 330 42K 330
kdtrace 184 38K 3545
BPF 22 36K 22
temp 34 33K 2044
DEVFS3 128 32K 138
hostcache 1 32K 1
shm 1 32K 1
msg 4 30K 4
gtaskqueue 18 26K 18
kbdmux 6 22K 6
DEVFS_RULE 56 20K 56
ifaddr 68 20K 70
ufs_mount 4 17K 5
proc 3 17K 3
tty 16 16K 16
routetbl 138 16K 430
ithread 97 16K 97
lltable 46 15K 46
bus-sc 34 15K 1681
ether_multi 157 13K 167
KTRACE 100 13K 100
ifnet 7 13K 7
kenv 95 12K 95
eventhandler 134 12K 134
rman 88 11K 431
GEOM 61 11K 487
CAM queue 5 11K 1528
ksem 4 10K 5
in6_multi 71 9K 71
bmsafemap 2 9K 1266
UART 12 9K 12
devstat 4 9K 4
sctp_timw 32 8K 32
rpc 2 8K 2
shmfd 1 8K 1
pfs_vncache 1 8K 1
pfs_nodes 20 8K 20
audit_evclass 237 8K 296
taskqueue 63 7K 63
sglist 5 7K 5
CAM DEV 3 6K 510
cred 24 6K 214
plimit 21 6K 364
kqueue 48 6K 2123
ufs_dirhash 24 5K 24
UMA 272 5K 272
pf_ifnet 10 5K 19
vt 11 5K 11
memdesc 1 4K 1
MCA 32 4K 32
ioctlops 1 4K 174
evdev 4 4K 4
DEVFSP 62 4K 66
acpisem 28 4K 28
hhook 15 4K 17
kcovinfo 52 4K 52
diradd 25 4K 1264
session 25 4K 39
pwddesc 46 3K 2116
proc-args 73 3K 3269
terminal 11 3K 11
pf_rule 5 3K 5
uidinfo 3 3K 8
lockf 20 3K 33
local_apic 1 2K 1
io_apic 1 2K 1
fpukern_ctx 2 2K 2
mkdir 16 2K 2446
ipsec-saq 2 2K 2
selfd 31 2K 40117
ip6ndp 12 2K 15
sctp_ifa 14 2K 15
Unitno 29 2K 47
CAM XPT 22 2K 543
msi 12 2K 12
newdirblk 12 2K 1223
in_multi 6 2K 8
freework 5 2K 1229
ipsecpolicy 2 2K 2
acpidev 20 2K 20
select 10 2K 38
clone 9 2K 9
tun 7 2K 7
softdep 1 1K 1
freeblks 4 1K 1228
sahead 1 1K 1
secasvar 1 1K 1
nhops 6 1K 8
vnodemarker 2 1K 18
NFSD session 1 1K 1
CAM periph 4 1K 271
ipsec 3 1K 3
sctp_ifn 6 1K 15
mld 6 1K 6
igmp 6 1K 6
toponodes 6 1K 6
isadev 6 1K 6
mount 16 1K 89
pci_link 10 1K 10
crypto 4 1K 4
encap_export_host 12 1K 12
pfil 4 1K 4
cdev 2 1K 2
osd 8 1K 288
inpcbpolicy 12 1K 460
chacha20random 1 1K 1
NFSD lckfile 1 1K 1
NFSD V4client 1 1K 1
DEVFS 9 1K 10
CC Mem 4 1K 277
vnodes 1 1K 1
CAM SIM 2 1K 2
procdesc 2 1K 12
feeder 7 1K 7
tcpfunc 3 1K 3
loginclass 3 1K 6
prison 6 1K 6
lkpikmalloc 5 1K 6
aesni_data 2 1K 2
cryptodev 2 1K 42
nexusdev 8 1K 8
apmdev 1 1K 1
atkbddev 2 1K 2
CAM dev queue 2 1K 2
CAM I/O Scheduler 1 1K 1
CAM path 4 1K 1034
pmchooks 1 1K 1
soname 4 1K 4350
sctp_vrf 1 1K 1
vnet 1 1K 1
entropy 2 1K 39
pmc 1 1K 1
acpiintr 1 1K 1
cpus 2 1K 2
vnet_data_free 1 1K 1
Per-cpu 1 1K 1
filecaps 2 1K 90
p1003.1b 1 1K 1
ipcomp 0 0K 0
esp 0 0K 0
ah 0 0K 0
tcp_do 0 0K 0
tcp_fsb 0 0K 202
sctp_mcore 0 0K 0
sctp_socko 0 0K 201
sctp_iter 0 0K 11
sctp_mvrf 0 0K 0
sctp_cpal 0 0K 0
sctp_cmsg 0 0K 0
sctp_stre 0 0K 0
sctp_athi 0 0K 0
sctp_athm 0 0K 668
sctp_atky 0 0K 849
sctp_atcl 0 0K 668
sctp_a_it 0 0K 11
sctp_aadr 0 0K 0
sctp_stro 0 0K 181
sctp_stri 0 0K 0
sctp_map 0 0K 362
mqdata 0 0K 0
pf_table 0 0K 0
pf_altq 0 0K 0
pf_osfp 0 0K 0
pf_temp 0 0K 0
filemon 0 0K 0
NFSCL layrecall 0 0K 0
NFSCL session 0 0K 0
madt_table 0 0K 2
smartpqi 0 0K 0
NFSCL sockreq 0 0K 0
NFSCL devinfo 0 0K 0
NFSCL flayout 0 0K 0
ixl 0 0K 0
NFSCL layout 0 0K 0
NFSD rollback 0 0K 0
NFSCL diroff 0 0K 0
NEWdirectio 0 0K 0
NEWNFSnode 0 0K 0
NFSCL lck 0 0K 0
NFSCL lckown 0 0K 0
ice-resmgr 0 0K 0
ice-osdep 0 0K 0
ice 0 0K 0
iavf 0 0K 0
axgbe 0 0K 0
NFSCL client 0 0K 0
NFSCL deleg 0 0K 0
NFSCL open 0 0K 0
NFSCL owner 0 0K 0
NFS fh 0 0K 0
NFS req 0 0K 0
NFSD usrgroup 0 0K 0
NFSD string 0 0K 0
NFSD V4lock 0 0K 0
xen_intr 0 0K 0
NFSD V4state 0 0K 0
xen_hvm 0 0K 0
legacydrv 0 0K 0
bounce 0 0K 0
busdma 0 0K 0
qpidrv 0 0K 0
NFSD srvcache 0 0K 0
msdosfs_fat 0 0K 0
dmar_idpgtbl 0 0K 0
dmar_dom 0 0K 0
dmar_ctx 0 0K 0
msdosfs_mount 0 0K 0
msdosfs_node 0 0K 0
isci 0 0K 0
iommu_dmamap 0 0K 0
hyperv_socket 0 0K 0
bxe_ilt 0 0K 0
xenbus 0 0K 0
DEVFS4 0 0K 0
vm_fictitious 0 0K 0
DEVFS2 0 0K 0
gntdev 0 0K 0
privcmd_dev 0 0K 0
evtchn_dev 0 0K 0
xenstore 0 0K 0
scsi_pass 0 0K 0
ciss_data 0 0K 0
xnb 0 0K 0
xen_acpi 0 0K 0
xbbd 0 0K 0
xbd 0 0K 0
UMAHash 0 0K 0
Balloon 0 0K 0
sysmouse 0 0K 0
vm_pgdata 0 0K 0
jblocks 0 0K 0
savedino 0 0K 474
sentinel 0 0K 0
jfsync 0 0K 0
jtrunc 0 0K 0
sbdep 0 0K 6
jsegdep 0 0K 0
jseg 0 0K 0
jfreefrag 0 0K 0
jfreeblk 0 0K 0
jnewblk 0 0K 0
jmvref 0 0K 0
jremref 0 0K 0
jaddref 0 0K 0
freedep 0 0K 0
freefrag 0 0K 2
allocindir 0 0K 0
indirdep 0 0K 10
allocdirect 0 0K 0
ufs_trim 0 0K 0
mactemp 0 0K 0
audit_trigger 0 0K 0
audit_pipe_presel 0 0K 0
audit_pipeent 0 0K 0
audit_pipe 0 0K 0
audit_evname 0 0K 0
audit_bsm 0 0K 0
audit_gidset 0 0K 0
audit_text 0 0K 0
audit_path 0 0K 0
audit_data 0 0K 0
audit_cred 0 0K 0
vtfont 0 0K 0
BACKLIGHT 0 0K 0
ath_hal 0 0K 0
athdev 0 0K 0
ata_pci 0 0K 0
ata_dma 0 0K 0
ata_generic 0 0K 0
pvscsi 0 0K 0
scsi_da 0 0K 69
ata_da 0 0K 0
scsi_ch 0 0K 0
scsi_cd 0 0K 0
ktls_ocf 0 0K 0
AHCI driver 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5E_TLS_RX 0 0K 0
MLX5EEPROM 0 0K 0
MLX5E_TLS 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EN 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5DUMP 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
seq_file 0 0K 0
lkpiskb 0 0K 0
radix 0 0K 0
idr 0 0K 0
lkpindev 0 0K 0
lkpifw 0 0K 0
lkpi80211 0 0K 0
NLM 0 0K 0
ipsec-spdcache 0 0K 0
ipsec-reg 0 0K 0
ipsec-misc 0 0K 0
ipsecrequest 0 0K 0
ip6opt 0 0K 6
ip6_msource 0 0K 0
ip6_moptions 0 0K 0
in6_mfilter 0 0K 0
frag6 0 0K 0
tcplog 0 0K 0
tcp_hwpace 0 0K 0
USBdev 0 0K 0
USB 0 0K 0
LRO 0 0K 0
ip_msource 0 0K 0
ip_moptions 0 0K 0
in_mfilter 0 0K 0
ipid 0 0K 0
80211scan 0 0K 0
80211ratectl 0 0K 0
80211power 0 0K 0
80211nodeie 0 0K 0
80211node 0 0K 0
80211mesh_gt 0 0K 0
80211mesh_rt 0 0K 0
80211perr 0 0K 0
80211prep 0 0K 0
80211preq 0 0K 0
80211dfs 0 0K 0
80211crypto 0 0K 0
80211vap 0 0K 0
iflib 0 0K 0
vlan 0 0K 0
gif 0 0K 0
ifdescr 0 0K 0
zlib 0 0K 0
fadvise 0 0K 0
VN POLL 0 0K 0
agp 0 0K 0
statfs 0 0K 1401
namei_tracker 0 0K 0
export_host 0 0K 0
cl_savebuf 0 0K 2
nvme_da 0 0K 0
acpipwr 0 0K 0
acpi_perf 0 0K 0
twsbuf 0 0K 0
twe_commands 0 0K 0
tcp_log_dev 0 0K 85
midi buffers 0 0K 0
mixer 0 0K 0
ac97 0 0K 0
hdacc 0 0K 0
hdac 0 0K 0
hdaa 0 0K 0
acpicmbat 0 0K 0
SIIS driver 0 0K 0
CAM CCB 0 0K 523
biobuf 0 0K 0
aios 0 0K 0
lio 0 0K 0
acl 0 0K 0
mbuf_tag 0 0K 101
ktls 0 0K 0
PUC 0 0K 0
ppbusdev 0 0K 0
agtiapi_MemAlloc malloc 0 0K 0
osti_cacheable 0 0K 0
tempbuff 0 0K 0
tempbuff 0 0K 0
ag_tgt_map_t malloc 0 0K 0
ag_slr_map_t malloc 0 0K 0
lDevFlags * malloc 0 0K 0
tiDeviceHandle_t * malloc 0 0K 0
ag_portal_data_t malloc 0 0K 0
ag_device_t malloc 0 0K 0
STLock malloc 0 0K 0
CCB List 0 0K 0
sr_iov 0 0K 0
OCS 0 0K 0
OCS 0 0K 0
nvme 0 0K 0
nvd 0 0K 0
netmap 0 0K 0
mwldev 0 0K 0
MVS driver 0 0K 0
CAM ccb queue 0 0K 0
accf 0 0K 0
pts 0 0K 0
iov 0 0K 14600
eventfd 0 0K 0
Witness 0 0K 0
stack 0 0K 0
mrsasbuf 0 0K 0
mpt_user 0 0K 0
mps_user 0 0K 0
MPSSAS 0 0K 0
mps 0 0K 0
sbuf 0 0K 288
mpr_user 0 0K 0
firmware 0 0K 0
compressor 0 0K 0
MPRSAS 0 0K 0
SWAP 0 0K 0
mpr 0 0K 0
mfibuf 0 0K 0
sysctltmp 0 0K 676
sysctl 0 0K 3
md_sectors 0 0K 0
ekcd 0 0K 0
dumper 0 0K 0
sendfile 0 0K 0
rctl 0 0K 0
md_disk 0 0K 0
malodev 0 0K 0
LED 0 0K 0
ix_sriov 0 0K 0
cache 0 0K 0
aacraidcam 0 0K 0
prison_racct 0 0K 0
Fail Points 0 0K 0
sigio 0 0K 1
filedesc_to_leader 0 0K 0
pwd 0 0K 0
tty console 0 0K 0
ix 0 0K 0
ipsbuf 0 0K 0
aacraid_buf 0 0K 0
aaccam 0 0K 0
boottrace 0 0K 0
aacbuf 0 0K 0
zstd 0 0K 0
XZ_DEC 0 0K 0
nvlist 0 0K 0
SCSI ENC 0 0K 0
SCSI sa 0 0K 0
isofs_node 0 0K 0
isofs_mount 0 0K 0
tr_raid5_data 0 0K 0
tr_raid1e_data 0 0K 0
tr_raid1_data 0 0K 0
tr_raid0_data 0 0K 0
tr_concat_data 0 0K 0
md_sii_data 0 0K 0
md_promise_data 0 0K 0
md_nvidia_data 0 0K 0
md_jmicron_data 0 0K 0
md_intel_data 0 0K 0
md_ddf_data 0 0K 0
raid_data 0 0K 72
geom_flashmap 0 0K 0
tmpfs dir 0 0K 0
tmpfs name 0 0K 0
tmpfs mount 0 0K 0
NFS FHA 0 0K 0
newnfsmnt 0 0K 0
newnfsclient_req 0 0K 0
db> show uma
Zone Size Used Free Requests Sleeps Bucket Total Mem XFree
mbuf_jumbo_page 4096 8321 1077 1308018 0 254 38494208 0
mbuf 256 8698 965 1970793 0 254 2473728 0
pbuf 2624 0 778 0 0 2 2041472 0
RADIX NODE 144 12047 240 79447 0 62 1769328 0
BUF TRIE 144 164 11624 493 0 62 1697472 0
malloc-384 384 4218 12 4218 0 30 1624320 0
malloc-4096 4096 384 8 3238 0 2 1605632 0
mbuf_cluster 2048 762 0 762 0 254 1560576 0
malloc-128 128 11723 150 15083 0 126 1519744 0
UMA Slabs 0 112 10762 32 10762 0 126 1208928 0
sctp_asoc 2256 0 510 181 0 254 1150560 0
vmem btag 56 17191 56 17191 0 254 965832 0
FFS inode 1160 508 31 1737 0 8 625240 0
sctp_ep 1208 0 510 487 0 254 616080 0
tcpcb 1104 4 507 277 0 254 564144 0
VM OBJECT 264 1717 203 45225 0 30 506880 0
socket 960 25 483 2202 0 254 487680 0
malloc-65536 65536 7 0 7 0 1 458752 0
lkpimm 168 1 2327 1 0 62 391104 0
lkpicurr 168 2 2326 2 0 62 391104 0
sctp_raddr 736 0 517 181 0 254 380512 0
256 Bucket 2048 156 14 4217 0 8 348160 0
tcp_log 416 0 765 1174 0 254 318240 0
malloc-384 384 772 38 1296 0 30 311040 0
malloc-256 256 1088 97 2965 0 62 303360 0
THREAD 1808 137 28 1428 0 8 298320 0
VNODE 448 545 85 1776 0 30 282240 0
malloc-64 64 3906 441 6955 0 254 278208 0
malloc-65536 65536 0 4 136 0 1 262144 0
malloc-16384 16384 9 7 1236 0 1 262144 0
MAP ENTRY 96 1997 649 133754 0 126 254016 0
malloc-16 16 14611 389 16207 0 254 240000 0
DEVCTL 1024 22 198 152 0 0 225280 0
malloc-2048 2048 12 84 1113 0 8 196608 0
mbuf_packet 256 6 756 1650 0 254 195072 0
malloc-128 128 1410 109 3023 0 126 194432 0
malloc-128 128 1291 228 29729 0 126 194432 0
UMA Zones 768 244 0 244 0 16 187392 0
malloc-32 32 5306 364 6915 0 254 181440 0
malloc-1024 1024 136 24 154 0 16 163840 0
FPU_save_area 832 139 41 11404 0 16 149760 0
S VFS Cache 104 1006 398 2248 0 126 146016 0
FFS2 dinode 256 508 62 1737 0 62 145920 0
malloc-65536 65536 0 2 80 0 1 131072 0
malloc-65536 65536 2 0 2 0 1 131072 0
unpcb 256 11 499 1228 0 254 130560 0
malloc-256 256 18 492 2153 0 62 130560 0
ksiginfo 112 51 993 10035 0 126 116928 0
VMSPACE 2552 29 16 2105 0 4 114840 0
malloc-8192 8192 9 2 12 0 1 90112 0
UMA Kegs 384 230 3 230 0 30 89472 0
PROC 1352 45 21 2115 0 8 89232 0
128 Bucket 1024 56 27 583 0 16 84992 0
clpbuf 2624 0 32 16 0 16 83968 0
malloc-4096 4096 15 5 36 0 2 81920 0
filedesc0 1072 46 24 2116 0 8 75040 0
g_bio 408 0 180 5155 0 30 73440 0
malloc-64 64 619 452 15840 0 254 68544 0
malloc-128 128 407 120 1662 0 126 67456 0
malloc-128 128 295 232 372 0 126 67456 0
malloc-32768 32768 0 2 120 0 1 65536 0
malloc-16384 16384 3 1 18 0 1 65536 0
malloc-16384 16384 0 4 160 0 1 65536 0
sctp_stream_msg_out 112 0 540 13 0 254 60480 0
64 Bucket 512 76 28 3522 0 30 53248 0
malloc-64 64 43 776 40153 0 254 52416 0
malloc-64 64 406 413 4614 0 254 52416 0
malloc-64 64 453 366 653 0 254 52416 0
malloc-256 256 51 144 3056 0 62 49920 0
malloc-256 256 77 118 1504 0 62 49920 0
malloc-256 256 74 121 1176 0 62 49920 0
32 Bucket 256 71 124 8624 0 62 49920 0
DIRHASH 1024 35 13 35 0 16 49152 0
NAMEI 1024 0 48 18674 0 16 49152 0
malloc-4096 4096 9 3 16 0 2 49152 0
malloc-2048 2048 1 23 488 0 8 49152 0
malloc-1024 1024 5 43 717 0 16 49152 0
syncache 168 0 264 4 0 254 44352 0
malloc-8192 8192 2 3 30 0 1 40960 0
pcpu-8 8 4662 458 4818 0 254 40960 0
udp_inpcb 424 6 84 175 0 30 38160 0
tcp_inpcb 424 4 86 277 0 30 38160 0
pipe 744 20 30 355 0 16 37200 0
malloc-64 64 57 510 68 0 254 36288 0
malloc-64 64 106 461 230 0 254 36288 0
malloc-64 64 44 523 331 0 254 36288 0
malloc-128 128 25 254 85 0 126 35712 0
malloc-128 128 26 253 1238 0 126 35712 0
malloc-128 128 65 214 364 0 126 35712 0
routing nhops 256 27 108 35 0 62 34560 0
ttyoutq 256 72 63 160 0 62 34560 0
malloc-384 384 67 23 407 0 30 34560 0
malloc-256 256 65 70 1414 0 62 34560 0
malloc-256 256 37 98 851 0 62 34560 0
malloc-256 256 51 84 363 0 62 34560 0
TURNSTILE 136 166 86 166 0 62 34272 0
SLEEPQUEUE 88 166 218 166 0 126 33792 0
malloc-32768 32768 1 0 1 0 1 32768 0
malloc-32768 32768 1 0 1 0 1 32768 0
malloc-32768 32768 1 0 1 0 1 32768 0
malloc-8192 8192 4 0 4 0 1 32768 0
malloc-8192 8192 2 2 103 0 1 32768 0
malloc-8192 8192 4 0 4 0 1 32768 0
malloc-2048 2048 5 11 17 0 8 32768 0
malloc-2048 2048 7 9 57 0 8 32768 0
malloc-2048 2048 3 13 194 0 8 32768 0
malloc-1024 1024 2 30 42 0 16 32768 0
malloc-1024 1024 3 29 6 0 16 32768 0
malloc-1024 1024 8 24 1074 0 16 32768 0
malloc-1024 1024 10 22 167 0 16 32768 0
malloc-512 512 1 63 119 0 30 32768 0
malloc-512 512 2 62 18 0 30 32768 0
malloc-512 512 9 55 25 0 30 32768 0
malloc-512 512 1 63 8 0 30 32768 0
malloc-512 512 6 58 55 0 30 32768 0
pcpu-64 64 493 19 493 0 254 32768 0
ertt_txseginfo 40 0 808 6195 0 254 32320 0
tcp_rack_pcb 896 0 36 202 0 16 32256 0
KNOTE 160 28 172 40856 0 62 32000 0
ttyinq 160 135 65 300 0 62 32000 0
tcp_rack_map 120 0 264 249 0 126 31680 0
cpuset 104 7 272 7 0 126 29016 0
PWD 32 16 866 1311 0 254 28224 0
malloc-32 32 324 558 3586 0 254 28224 0
16 Bucket 144 55 141 244 0 62 28224 0
4 Bucket 48 6 582 85 0 254 28224 0
ripcb 424 2 61 8 0 30 26712 0
da_ccb 544 0 49 1389 0 16 26656 0
malloc-4096 4096 3 3 1404 0 2 24576 0
rtentry 176 31 107 35 0 62 24288 0
PGRP 88 25 251 39 0 126 24288 0
rl_entry 40 36 570 36 0 254 24240 0
Files 80 177 123 9869 0 126 24000 0
8 Bucket 80 49 251 792 0 126 24000 0
malloc-384 384 11 49 11 0 30 23040 0
malloc-384 384 3 57 32 0 30 23040 0
malloc-384 384 1 59 700 0 30 23040 0
malloc-384 384 23 37 26 0 30 23040 0
hostcache 64 1 314 1 0 254 20160 0
udpcb 32 6 624 175 0 254 20160 0
udp_inpcb ports 32 3 627 33 0 254 20160 0
tcp_inpcb ports 32 2 628 131 0 254 20160 0
ertt 72 4 276 277 0 126 20160 0
malloc-32 32 82 548 84 0 254 20160 0
malloc-32 32 186 444 1388 0 254 20160 0
malloc-32 32 84 546 1396 0 254 20160 0
malloc-32 32 34 596 781 0 254 20160 0
malloc-32 32 53 577 238 0 254 20160 0
2 Bucket 32 56 574 446 0 254 20160 0
Mountpoints 2752 2 5 2 0 4 19264 0
epoch_record pcpu 256 4 60 4 0 62 16384 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-16384 16384 0 1 1 0 1 16384 0
malloc-8192 8192 2 0 2 0 1 16384 0
malloc-4096 4096 2 2 2 0 2 16384 0
malloc-2048 2048 8 0 8 0 8 16384 0
malloc-2048 2048 0 8 50 0 8 16384 0
malloc-1024 1024 3 13 3 0 16 16384 0
malloc-1024 1024 6 10 6 0 16 16384 0
malloc-512 512 1 31 1 0 30 16384 0
SMR CPU 32 7 504 7 0 254 16352 0
sctp_laddr 48 0 336 13 0 254 16128 0
vtnet_tx_hdr 24 0 668 653293 0 254 16032 0
kenv 258 15 45 1044 0 30 15480 0
mqnode 416 3 33 3 0 30 14976 0
vmem 1856 1 7 1 0 8 14848 0
SMR SHARED 24 7 504 7 0 254 12264 0
malloc-32 32 7 371 30 0 254 12096 0
malloc-16 16 16 734 323 0 254 12000 0
malloc-16 16 28 722 67 0 254 12000 0
malloc-16 16 306 444 472 0 254 12000 0
malloc-16 16 57 693 448 0 254 12000 0
malloc-16 16 191 559 3110 0 254 12000 0
malloc-16 16 23 727 26365 0 254 12000 0
malloc-16 16 45 705 2700 0 254 12000 0
malloc-384 384 20 10 20 0 30 11520 0
malloc-8192 8192 1 0 1 0 1 8192 0
malloc-8192 8192 1 0 1 0 1 8192 0
malloc-4096 4096 0 2 2 0 2 8192 0
malloc-4096 4096 1 1 1 0 2 8192 0
pcpu-16 16 7 249 7 0 254 4096 0
UMA Slabs 1 176 10 12 10 0 62 3872 0
KMAP ENTRY 96 12 27 14 0 0 3744 0
pcpu-4 4 1 511 1 0 254 2048 0
FFS1 dinode 128 0 0 0 0 126 0 0
ada_ccb 272 0 0 0 0 30 0 0
swblk 136 0 0 0 0 62 0 0
swpctrie 144 0 0 0 0 62 0 0
cdg_qdiffsample 16 0 0 0 0 254 0 0
pf state scrubs 40 0 0 0 0 254 0 0
pf frag entries 40 0 0 0 0 254 0 0
pf frags 248 0 0 0 0 62 0 0
pf table entries 160 0 0 0 0 254 0 0
pf table entry counters 64 0 0 0 0 254 0 0
pf source nodes 136 0 0 0 0 254 0 0
pf state keys 88 0 0 0 0 126 0 0
pf states 312 0 0 0 0 254 0 0
pf tags 104 0 0 0 0 126 0 0
pf mtags 56 0 0 0 0 254 0 0
tcp_bbr_pcb 832 0 0 0 0 16 0 0
tcp_bbr_map 128 0 0 0 0 126 0 0
tfo_ccache_entries 80 0 0 0 0 126 0 0
tfo 4 0 0 0 0 254 0 0
sackhole 32 0 0 0 0 254 0 0
tcptw 72 0 0 0 0 254 0 0
ipq 56 0 0 0 0 254 0 0
sctp_asconf_ack 48 0 0 0 0 254 0 0
sctp_asconf 40 0 0 0 0 254 0 0
sctp_readq 152 0 0 0 0 254 0 0
sctp_chunk 152 0 0 0 0 254 0 0
tcp_log_id_node 120 0 0 0 0 126 0 0
tcp_log_id_bucket 176 0 0 0 0 62 0 0
tcpreass 48 0 0 0 0 254 0 0
ripcb ports 32 0 0 0 0 254 0 0
udplite_inpcb ports 32 0 0 0 0 254 0 0
udplite_inpcb 424 0 0 0 0 30 0 0
IPsec SA lft_c 16 0 0 0 0 254 0 0
itimer 352 0 0 0 0 30 0 0
AIOLIO 272 0 0 0 0 30 0 0
AIOCB 552 0 0 0 0 16 0 0
AIOP 32 0 0 0 0 254 0 0
AIO 208 0 0 0 0 62 0 0
TMPFS node 224 0 0 0 0 62 0 0
NCLNODE 608 0 0 0 0 16 0 0
mqnotifier 216 0 0 0 0 62 0 0
mvdata 64 0 0 0 0 254 0 0
mqueue 248 0 0 0 0 62 0 0
LTS VFS Cache 360 0 0 0 0 30 0 0
L VFS Cache 320 0 0 0 0 30 0 0
STS VFS Cache 144 0 0 0 0 62 0 0
cryptop 280 0 0 0 0 30 0 0
linux_dma_object 32 0 0 0 0 254 0 0
linux_dma_pctrie 144 0 0 0 0 62 0 0
IOMMU_MAP_ENTRY 120 0 0 0 0 126 0 0
mbuf_jumbo_16k 16384 0 0 0 0 254 0 0
mbuf_jumbo_9k 9216 0 0 0 0 254 0 0
audit_record 1280 0 0 0 0 8 0 0
domainset 40 0 0 0 0 254 0 0
MAC labels 40 0 0 0 0 254 0 0
vnpbuf 2624 0 0 0 0 64 0 0
mdpbuf 2624 0 0 0 0 3 0 0
nfspbuf 2624 0 0 0 0 16 0 0
swwbuf 2624 0 0 0 0 8 0 0
swrbuf 2624 0 0 0 0 16 0 0
umtx_shm 88 0 0 0 0 126 0 0
umtx pi 96 0 0 0 0 126 0 0
rangeset pctrie nodes 144 0 0 0 0 62 0 0
malloc-65536 65536 0 0 0 0 1 0 0
malloc-65536 65536 0 0 0 0 1 0 0
malloc-65536 65536 0 0

---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
May 15, 2022, 2:53:31 PM5/15/22
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: f210e4fbc54a sctp: cleanup, no functional change intended
git tree: freebsd-src
console output: https://syzkaller.appspot.com/x/log.txt?x=1055b766f00000
dashboard link: https://syzkaller.appspot.com/bug?extid=0627bad101efe63cb5a3
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=170e8656f00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=15416335f00000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+0627ba...@syzkaller.appspotmail.com

Fatal trap 12: page fault while in kernel mode
cpuid = 1; apic id = 01
fault virtual address = 0x0
fault code = supervisor read data, page not present
instruction pointer = 0x20:0xffffffff84b118d4
stack pointer = 0x28:0xfffffe0054099230
frame pointer = 0x28:0xfffffe0054099270
code segment = base 0x0, limit 0xfffff, type 0x1b
= DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags = interrupt enabled, resume, IOPL = 0
current process = 779 (syz-executor4017504)
trap number = 12
panic: page fault
cpuid = 1
time = 1652640644
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0xc7/frame 0xfffffe0054098a10
kdb_backtrace() at kdb_backtrace+0xd3/frame 0xfffffe0054098b70
vpanic() at vpanic+0x2b8/frame 0xfffffe0054098c50
panic() at panic+0xb5/frame 0xfffffe0054098d10
trap_fatal() at trap_fatal+0x6bd/frame 0xfffffe0054098e30
trap_pfault() at trap_pfault+0x182/frame 0xfffffe0054098f70
trap() at trap+0x5b0/frame 0xfffffe0054099160
calltrap() at calltrap+0x8/frame 0xfffffe0054099160
--- trap 0xc, rip = 0xffffffff84b118d4, rsp = 0xfffffe0054099230, rbp = 0xfffffe0054099270 ---
pf_krule_global_RB_INSERT() at pf_krule_global_RB_INSERT+0x24/frame 0xfffffe0054099270
pfioctl() at pfioctl+0xc30a/frame 0xfffffe005409a610
devfs_ioctl() at devfs_ioctl+0x22a/frame 0xfffffe005409a6f0
VOP_IOCTL_APV() at VOP_IOCTL_APV+0xb0/frame 0xfffffe005409a730
vn_ioctl() at vn_ioctl+0x215/frame 0xfffffe005409aa80
devfs_ioctl_f() at devfs_ioctl_f+0x71/frame 0xfffffe005409aad0
kern_ioctl() at kern_ioctl+0x631/frame 0xfffffe005409abd0
sys_ioctl() at sys_ioctl+0x31c/frame 0xfffffe005409ad30
amd64_syscall() at amd64_syscall+0x410/frame 0xfffffe005409af30
fast_syscall_common() at fast_syscall_common+0xf8/frame 0xfffffe005409af30
--- syscall (0, FreeBSD ELF64, nosys), rip = 0x2b3d4a, rsp = 0x8205572c8, rbp = 0x8205572e0 ---
KDB: enter: panic
[ thread pid 779 tid 100092 ]
Stopped at kdb_enter+0x6b: movq $0,0x275a85a(%rip)
db>
db> set $lines = 0
db> set $maxwidth = 0
db> show registers
cs 0x20
ds 0x3b
es 0x3b
fs 0x13
gs 0x1b
ss 0x28
rax 0x12
rcx 0xfffffe00033eee30
rdx 0xdffff7c000000000
rbx 0
rsp 0xfffffe0054098b50
rbp 0xfffffe0054098b70
rsi 0x1
rdi 0
r8 0x3
r9 0xffffffff
r10 0
r11 0
r12 0xfffffe0058bb2c80
r13 0xfffffe0054098b01
r14 0xffffffff82b4fd00 .str.26
r15 0xffffffff82b4fd00 .str.26
rip 0xffffffff8171983b kdb_enter+0x6b
rflags 0x46
kdb_enter+0x6b: movq $0,0x275a85a(%rip)
db> show proc
Process 779 (syz-executor4017504) at 0xfffffe0058c0e548:
state: NORMAL
uid: 0 gids: 0, 0, 5
parent: pid 777 at 0xfffffe0058c0c548
ABI: FreeBSD ELF64
flag: 0x10004000 flag2: 0
arguments: ./syz-executor4017504747
reaper: 0xfffffe0053de1000 reapsubtree: 1
sigparent: 20
vmspace: 0xfffffe00927b83f0
(map 0xfffffe00927b83f0)
(map.pmap 0xfffffe00927b84b0)
(pmap 0xfffffe00927b8518)
threads: 1
100092 Run CPU 1 syz-executor4017504
db> ps
pid ppid pgrp uid state wmesg wchan cmd
779 777 777 0 R CPU 1 syz-executor4017504
777 775 777 0 Ss pause 0xfffffe0058c0c5f8 csh
775 688 775 0 Ss select 0xfffffe0056f6ae40 sshd
754 1 754 0 Ss+ ttyin 0xfffffe00574764b0 getty
753 1 753 0 Ss+ ttyin 0xfffffe0057a788b0 getty
752 1 752 0 Ss+ ttyin 0xfffffe0057a78cb0 getty
751 1 751 0 Ss+ ttyin 0xfffffe0057a790b0 getty
750 1 750 0 Ss+ ttyin 0xfffffe0057a794b0 getty
749 1 749 0 Ss+ ttyin 0xfffffe0057a798b0 getty
748 1 748 0 Ss+ ttyin 0xfffffe0057a79cb0 getty
747 1 747 0 Ss+ ttyin 0xfffffe0057a7a0b0 getty
746 1 746 0 Ss+ ttyin 0xfffffe0057a7a4b0 getty
744 1 18 0 S+ piperd 0xfffffe0058b508b8 logger
743 742 18 0 S+ nanslp 0xffffffff83e41700 sleep
742 1 18 0 S+ wait 0xfffffe00926fda90 sh
692 1 692 0 Ss nanslp 0xffffffff83e41701 cron
688 1 688 0 Ss select 0xfffffe0056f6aec0 sshd
501 1 501 0 Ss select 0xfffffe0056f6b440 syslogd
430 1 430 0 Ss select 0xfffffe0056f6b140 devd
429 1 429 65 Ss select 0xfffffe0056f6b0c0 dhclient
344 1 344 0 Ss select 0xfffffe0056f6adc0 dhclient
341 1 341 0 Ss select 0xfffffe00578fcf40 dhclient
17 0 0 0 DL vlruwt 0xfffffe0056fa0548 [vnlru]
16 0 0 0 DL syncer 0xffffffff83f66f60 [syncer]
15 0 0 0 DL (threaded) [bufdaemon]
100079 D psleep 0xffffffff83f65560 [bufdaemon]
100082 D - 0xffffffff83211f80 [bufspacedaemon-0]
100095 D sdflush 0xfffffe00574724e8 [/ worker]
9 0 0 0 DL psleep 0xffffffff83f99000 [vmdaemon]
8 0 0 0 DL (threaded) [pagedaemon]
100077 D psleep 0xffffffff83f8ceb8 [dom0]
100080 D launds 0xffffffff83f8cec4 [laundry: dom0]
100081 D umarcl 0xffffffff81e46dc0 [uma]
7 0 0 0 DL - 0xffffffff83bfdd28 [rand_harvestq]
6 0 0 0 DL pftm 0xffffffff84ad0550 [pf purge]
5 0 0 0 DL waiting 0xffffffff846a34a0 [sctp_iterator]
4 0 0 0 DL (threaded) [cam]
100044 D - 0xffffffff83aa0cc0 [doneq0]
100045 D - 0xffffffff83aa0c40 [async]
100076 D - 0xffffffff83aa0ac0 [scanner]
14 0 0 0 DL seqstat 0xfffffe0053fd7488 [sequencer 00]
3 0 0 0 DL (threaded) [crypto]
100040 D crypto_ 0xffffffff83f886e0 [crypto]
100041 D crypto_ 0xfffffe0053ecd830 [crypto returns 0]
100042 D crypto_ 0xfffffe0053ecd880 [crypto returns 1]
13 0 0 0 DL (threaded) [geom]
100035 D - 0xffffffff83e16d00 [g_event]
100036 D - 0xffffffff83e16d20 [g_up]
100037 D - 0xffffffff83e16d40 [g_down]
100003 Run CPU 0 [idle: cpu0]
100004 CanRun [idle: cpu1]
1 0 1 0 SLs wait 0xfffffe0053de1000 [init]
10 0 0 0 DL audit_w 0xffffffff83f891c0 [audit]
0 0 0 0 DLs (threaded) [kernel]
100000 D swapin 0xffffffff83e17700 [swapper]
100005 D - 0xfffffe0053e84100 [if_config_tqg_0]
100006 D - 0xfffffe0053e84000 [softirq_0]
100007 D - 0xfffffe0053e83e00 [softirq_1]
100008 D - 0xfffffe0053e83d00 [if_io_tqg_0]
100009 D - 0xfffffe0053e83c00 [if_io_tqg_1]
100010 D - 0xfffffe000795a100 [inm_free taskq]
100011 D - 0xfffffe000795a000 [linuxkpi_irq_wq]
100012 D - 0xfffffe0007959e00 [in6m_free taskq]
100013 D - 0xfffffe0007959d00 [deferred_unmount ta]
100014 D - 0xfffffe0007959c00 [thread taskq]
100016 D - 0xfffffe0007959a00 [kqueue_ctx taskq]
100017 D - 0xfffffe0007959900 [pci_hp taskq]
100020 D - 0xfffffe0007959600 [aiod_kick taskq]
100021 D - 0xfffffe0007959500 [linuxkpi_short_wq_0]
100022 D - 0xfffffe0007959500 [linuxkpi_short_wq_1]
100023 D - 0xfffffe0007959500 [linuxkpi_short_wq_2]
100024 D - 0xfffffe0007959500 [linuxkpi_short_wq_3]
100025 D - 0xfffffe0007959400 [linuxkpi_long_wq_0]
100026 D - 0xfffffe0007959400 [linuxkpi_long_wq_1]
100027 D - 0xfffffe0007959400 [linuxkpi_long_wq_2]
100028 D - 0xfffffe0007959400 [linuxkpi_long_wq_3]
100034 D - 0xfffffe0007959300 [firmware taskq]
100038 D - 0xfffffe0007959200 [crypto_0]
100039 D - 0xfffffe0007959200 [crypto_1]
100055 D - 0xfffffe0007959000 [vtnet0 rxq 0]
100056 D - 0xfffffe0007958e00 [vtnet0 txq 0]
100057 D - 0xfffffe0007958d00 [vtnet0 rxq 1]
100058 D - 0xfffffe0007958c00 [vtnet0 txq 1]
100062 D vtbslp 0xfffffe0056f6c000 [virtio_balloon]
100066 D - 0xffffffff82b55b80 [deadlkres]
100070 D - 0xfffffe000795a200 [mca taskq]
100072 D - 0xfffffe00585ef600 [acpi_task_0]
100073 D - 0xfffffe00585ef600 [acpi_task_1]
100074 D - 0xfffffe00585ef600 [acpi_task_2]
100075 D - 0xfffffe0007959100 [CAM taskq]
db> show all locks
Process 779 (syz-executor4017504) thread 0xfffffe0058bb2c80 (100092)
exclusive rm pf rulesets (pf rulesets) r = 0 (0xffffffff84b8a6a0) locked @ /syzkaller/managers/main/kernel/sys/netpfil/pf/pf_ioctl.c:3436
exclusive sx pf config (pf config) r = 0 (0xffffffff84b8a4c0) locked @ /syzkaller/managers/main/kernel/sys/netpfil/pf/pf_ioctl.c:3435
db> show malloc
Type InUse MemUse Requests
pf_hash 5 11524K 5
tcp_hpts 7 4801K 7
devbuf 4217 4323K 4242
sysctloid 35322 2081K 35393
vtbuf 24 1968K 46
kobj 328 1312K 489
newblk 578 1169K 591
vfscache 3 1025K 3
pcb 21 539K 40
inodedep 49 530K 72
ufs_quota 1 512K 1
vfs_hash 1 512K 1
callout 2 512K 2
intr 4 472K 4
acpica 1674 184K 57552
subproc 89 179K 829
vnet_data 1 168K 1
tidhash 3 141K 3
vmem 3 137K 3
linker 358 134K 386
pagedep 14 132K 18
tfo_ccache 1 128K 1
sem 4 106K 4
DEVFS1 105 105K 114
bus 994 81K 5207
mtx_pool 2 72K 2
syncache 1 68K 1
module 513 65K 513
acpitask 1 64K 1
ddb_capture 1 64K 1
temp 17 33K 1606
hostcache 1 32K 1
shm 1 32K 1
kdtrace 156 32K 896
DEVFS3 124 31K 134
umtx 242 31K 242
msg 4 30K 4
gtaskqueue 18 26K 18
kbdmux 6 22K 6
DEVFS_RULE 56 20K 56
BPF 10 18K 10
ufs_mount 4 17K 5
proc 3 17K 3
tty 16 16K 16
ithread 97 16K 97
bus-sc 34 15K 1681
KTRACE 100 13K 100
kenv 95 12K 95
eventhandler 134 12K 134
ifaddr 30 12K 32
rman 88 11K 431
GEOM 61 11K 490
routetbl 50 11K 176
CAM queue 5 11K 1528
bmsafemap 3 9K 40
UART 12 9K 12
devstat 4 9K 4
ksem 1 8K 1
rpc 2 8K 2
shmfd 1 8K 1
pfs_vncache 1 8K 1
pfs_nodes 20 8K 20
audit_evclass 237 8K 296
cred 29 8K 234
taskqueue 63 7K 63
sglist 5 7K 5
CAM DEV 3 6K 510
ufs_dirhash 24 5K 24
UMA 272 5K 272
dirrem 17 5K 28
plimit 17 5K 322
vt 11 5K 11
ifnet 3 5K 3
memdesc 1 4K 1
MCA 32 4K 32
ioctlops 1 4K 87
filedesc 1 4K 1
evdev 4 4K 4
acpisem 28 4K 28
hhook 15 4K 17
ether_multi 40 4K 50
diradd 25 4K 36
lltable 11 4K 11
pf_ifnet 5 3K 6
in6_multi 25 3K 25
terminal 11 3K 11
session 20 3K 31
kqueue 40 3K 782
pwddesc 40 3K 780
uidinfo 3 3K 8
proc-args 62 3K 1720
pf_rule 1 2K 1
local_apic 1 2K 1
io_apic 1 2K 1
fpukern_ctx 2 2K 2
ipsec-saq 2 2K 2
selfd 27 2K 9077
Unitno 27 2K 39
CAM XPT 22 2K 543
lockf 15 2K 22
msi 12 2K 12
ipsecpolicy 2 2K 2
acpidev 20 2K 20
clone 9 2K 9
sctp_stro 1 1K 1
softdep 1 1K 1
sahead 1 1K 1
secasvar 1 1K 1
vnodemarker 2 1K 8
NFSD session 1 1K 1
CAM periph 4 1K 271
select 7 1K 29
ipsec 3 1K 3
sctp_atcl 2 1K 2
indirdep 3 1K 3
nhops 6 1K 6
toponodes 6 1K 6
isadev 6 1K 6
mount 16 1K 89
pci_link 10 1K 10
sctp_ifa 5 1K 6
crypto 4 1K 4
ip6ndp 4 1K 5
encap_export_host 12 1K 12
newdirblk 4 1K 8
mkdir 4 1K 16
in_multi 2 1K 4
pfil 4 1K 4
cdev 2 1K 2
chacha20random 1 1K 1
osd 7 1K 18
inpcbpolicy 10 1K 139
sctp_ifn 2 1K 6
NFSD lckfile 1 1K 1
NFSD V4client 1 1K 1
DEVFSP 4 1K 9
DEVFS 9 1K 10
freework 1 1K 26
mld 2 1K 2
igmp 2 1K 2
vnodes 1 1K 1
CAM SIM 2 1K 2
feeder 7 1K 7
tcpfunc 3 1K 3
CC Mem 3 1K 7
loginclass 3 1K 7
prison 6 1K 6
lkpikmalloc 5 1K 6
aesni_data 2 1K 2
cryptodev 2 1K 49
sctp_atky 3 1K 3
nexusdev 8 1K 8
apmdev 1 1K 1
atkbddev 2 1K 2
freefrag 1 1K 2
CAM dev queue 2 1K 2
CAM I/O Scheduler 1 1K 1
CAM path 4 1K 1034
procdesc 1 1K 6
pmchooks 1 1K 1
soname 4 1K 3472
filecaps 4 1K 66
tun 3 1K 3
sctp_vrf 1 1K 1
vnet 1 1K 1
entropy 2 1K 35
pmc 1 1K 1
acpiintr 1 1K 1
sctp_athm 2 1K 2
sctp_map 2 1K 2
cpus 2 1K 2
vnet_data_free 1 1K 1
Per-cpu 1 1K 1
p1003.1b 1 1K 1
ipcomp 0 0K 0
esp 0 0K 0
ah 0 0K 0
pf_table 0 0K 0
pf_altq 0 0K 0
pf_osfp 0 0K 0
pf_temp 0 0K 0
mqdata 0 0K 0
tcp_do 0 0K 0
tcp_fsb 0 0K 0
filemon 0 0K 0
sctp_mcore 0 0K 0
sctp_socko 0 0K 1
sctp_iter 0 0K 4
sctp_mvrf 0 0K 0
sctp_timw 0 0K 0
sctp_cpal 0 0K 0
sctp_cmsg 0 0K 0
sctp_stre 0 0K 0
sctp_athi 0 0K 0
sctp_a_it 0 0K 4
sctp_aadr 0 0K 0
sctp_stri 0 0K 0
savedino 0 0K 17
sentinel 0 0K 0
jfsync 0 0K 0
jtrunc 0 0K 0
sbdep 0 0K 2
jsegdep 0 0K 0
jseg 0 0K 0
jfreefrag 0 0K 0
jfreeblk 0 0K 0
jnewblk 0 0K 0
jmvref 0 0K 0
jremref 0 0K 0
jaddref 0 0K 0
freedep 0 0K 0
freefile 0 0K 9
freeblks 0 0K 25
allocindir 0 0K 0
ip6opt 0 0K 3
statfs 0 0K 195
namei_tracker 0 0K 0
export_host 0 0K 0
cl_savebuf 0 0K 3
nvme_da 0 0K 0
acpipwr 0 0K 0
acpi_perf 0 0K 0
twsbuf 0 0K 0
twe_commands 0 0K 0
tcp_log_dev 0 0K 0
midi buffers 0 0K 0
mixer 0 0K 0
ac97 0 0K 0
hdacc 0 0K 0
hdac 0 0K 0
hdaa 0 0K 0
acpicmbat 0 0K 0
SIIS driver 0 0K 0
CAM CCB 0 0K 523
biobuf 0 0K 0
aios 0 0K 0
lio 0 0K 0
acl 0 0K 0
mbuf_tag 0 0K 27
iov 0 0K 13531
eventfd 0 0K 0
Witness 0 0K 0
stack 0 0K 0
mrsasbuf 0 0K 0
mpt_user 0 0K 0
mps_user 0 0K 0
MPSSAS 0 0K 0
mps 0 0K 0
sbuf 0 0K 288
mpr_user 0 0K 0
firmware 0 0K 0
compressor 0 0K 0
MPRSAS 0 0K 0
SWAP 0 0K 0
mpr 0 0K 0
mfibuf 0 0K 0
sysctltmp 0 0K 658
sysctl 0 0K 3
md_sectors 0 0K 0
ekcd 0 0K 0
dumper 0 0K 0
sendfile 0 0K 0
rctl 0 0K 0
md_disk 0 0K 0
malodev 0 0K 0
LED 0 0K 0
ix_sriov 0 0K 0
cache 0 0K 0
aacraidcam 0 0K 0
kcovinfo 0 0K 0
mbuf_jumbo_page 4096 8320 1078 13252 0 254 38494208 0
mbuf 256 8577 1085 15497 0 254 2473472 0
pbuf 2624 0 778 0 0 2 2041472 0
BUF TRIE 144 173 11615 425 0 62 1697472 0
malloc-384 384 4169 31 4509 0 30 1612800 0
malloc-128 128 11647 71 11681 0 126 1499904 0
malloc-4096 4096 328 2 492 0 2 1351680 0
UMA Slabs 0 112 10543 35 10543 0 126 1184736 0
mbuf_cluster 2048 508 0 508 0 254 1040384 0
vmem btag 56 16332 51 16332 0 254 917448 0
FFS inode 1160 499 19 508 0 8 600880 0
sctp_asoc 2256 1 254 1 0 254 575280 0
tcpcb 1104 3 508 7 0 254 564144 0
socket 960 19 489 1336 0 254 487680 0
RADIX NODE 144 3245 110 19809 0 62 483120 0
VM OBJECT 264 1409 91 24435 0 30 396000 0
lkpicurr 168 2 2350 2 0 62 395136 0
lkpimm 168 1 2327 1 0 62 391104 0
malloc-65536 65536 4 1 140 0 1 327680 0
sctp_ep 1208 1 259 1 0 254 314080 0
256 Bucket 2048 130 22 999 0 8 311296 0
malloc-64 64 4113 234 5372 0 254 278208 0
VNODE 448 530 46 541 0 30 258048 0
malloc-16 16 14655 345 14729 0 254 240000 0
DEVCTL 1024 0 220 126 0 0 225280 0
malloc-256 256 823 47 1190 0 62 222720 0
THREAD 1808 115 6 115 0 8 218768 0
malloc-4096 4096 46 4 786 0 2 204800 0
sctp_raddr 736 1 263 1 0 254 194304 0
MAP ENTRY 96 1559 457 84314 0 126 193536 0
UMA Zones 768 244 0 244 0 16 187392 0
malloc-32 32 5361 309 5938 0 254 181440 0
malloc-128 128 1203 192 26870 0 126 178560 0
malloc-1024 1024 118 26 325 0 16 147456 0
FFS2 dinode 256 499 71 508 0 62 145920 0
malloc-65536 65536 2 0 2 0 1 131072 0
malloc-65536 65536 0 2 54 0 1 131072 0
unpcb 256 7 503 1179 0 254 130560 0
mbuf_packet 256 0 508 78 0 254 130048 0
S VFS Cache 104 966 204 1005 0 126 121680 0
FPU_save_area 832 117 27 129 0 16 119808 0
ksiginfo 112 38 1006 53 0 126 116928 0
malloc-128 128 524 251 3835 0 126 99200 0
UMA Kegs 384 230 3 230 0 30 89472 0
128 Bucket 1024 45 38 478 0 16 84992 0
clpbuf 2624 0 32 18 0 16 83968 0
malloc-16384 16384 3 2 163 0 1 81920 0
malloc-8192 8192 7 3 136 0 1 81920 0
malloc-2048 2048 5 35 1061 0 8 81920 0
VMSPACE 2552 23 7 764 0 4 76560 0
g_bio 408 0 180 4475 0 30 73440 0
64 Bucket 512 64 72 1616 0 30 69632 0
malloc-64 64 503 568 739 0 254 68544 0
malloc-64 64 521 550 1615 0 254 68544 0
malloc-128 128 331 196 481 0 126 67456 0
malloc-128 128 266 261 1039 0 126 67456 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-32768 32768 0 2 120 0 1 65536 0
malloc-4096 4096 13 3 27 0 2 65536 0
malloc-256 256 162 93 175 0 62 65280 0
PROC 1352 39 9 779 0 8 64896 0
filedesc0 1072 40 9 780 0 8 52528 0
malloc-128 128 151 252 638 0 126 51584 0
malloc-256 256 73 122 798 0 62 49920 0
32 Bucket 256 60 135 1252 0 62 49920 0
DIRHASH 1024 35 13 35 0 16 49152 0
NAMEI 1024 0 48 12228 0 16 49152 0
malloc-8192 8192 6 0 6 0 1 49152 0
malloc-2048 2048 9 15 10 0 8 49152 0
malloc-1024 1024 27 21 38 0 16 49152 0
malloc-1024 1024 6 42 530 0 16 49152 0
syncache 168 0 264 5 0 254 44352 0
malloc-8192 8192 4 1 6 0 1 40960 0
malloc-8192 8192 5 0 5 0 1 40960 0
Mountpoints 2752 2 12 2 0 4 38528 0
udp_inpcb 424 6 84 128 0 30 38160 0
da_ccb 544 0 70 1228 0 16 38080 0
pcpu-8 8 4231 377 4259 0 254 36864 0
malloc-64 64 0 567 13177 0 254 36288 0
malloc-64 64 135 432 154 0 254 36288 0
malloc-64 64 90 477 9936 0 254 36288 0
malloc-64 64 61 506 1053 0 254 36288 0
malloc-64 64 13 554 31 0 254 36288 0
malloc-128 128 137 142 189 0 126 35712 0
malloc-128 128 35 244 111 0 126 35712 0
routing nhops 256 10 125 17 0 62 34560 0
ttyoutq 256 72 63 160 0 62 34560 0
malloc-384 384 61 29 113 0 30 34560 0
malloc-384 384 49 41 50 0 30 34560 0
malloc-256 256 2 133 319 0 62 34560 0
malloc-256 256 18 117 23 0 62 34560 0
malloc-256 256 50 85 655 0 62 34560 0
malloc-256 256 21 114 27 0 62 34560 0
malloc-256 256 10 125 565 0 62 34560 0
malloc-32768 32768 1 0 1 0 1 32768 0
malloc-32768 32768 1 0 1 0 1 32768 0
malloc-32768 32768 1 0 1 0 1 32768 0
malloc-16384 16384 2 0 17 0 1 32768 0
malloc-2048 2048 2 14 64 0 8 32768 0
malloc-2048 2048 4 12 13 0 8 32768 0
malloc-2048 2048 5 11 196 0 8 32768 0
malloc-2048 2048 3 13 3 0 8 32768 0
malloc-1024 1024 8 24 8 0 16 32768 0
malloc-1024 1024 6 26 874 0 16 32768 0
malloc-512 512 11 53 17 0 30 32768 0
malloc-512 512 2 62 12 0 30 32768 0
pcpu-64 64 493 19 493 0 254 32768 0
ttyinq 160 135 65 300 0 62 32000 0
cpuset 104 7 272 7 0 126 29016 0
sctp_laddr 48 0 588 4 0 254 28224 0
malloc-32 32 267 615 3094 0 254 28224 0
16 Bucket 144 47 149 228 0 62 28224 0
4 Bucket 48 6 582 46 0 254 28224 0
tcp_inpcb 424 3 60 7 0 30 26712 0
ripcb 424 1 62 4 0 30 26712 0
pipe 744 7 28 284 0 16 26040 0
TURNSTILE 136 122 67 122 0 62 25704 0
malloc-4096 4096 4 2 630 0 2 24576 0
malloc-4096 4096 6 0 6 0 2 24576 0
rtentry 176 13 125 17 0 62 24288 0
PGRP 88 20 256 31 0 126 24288 0
ertt_txseginfo 40 0 606 209 0 254 24240 0
rl_entry 40 31 575 31 0 254 24240 0
Files 80 73 227 6582 0 126 24000 0
8 Bucket 80 36 264 221 0 126 24000 0
malloc-384 384 27 33 29 0 30 23040 0
malloc-384 384 4 56 4 0 30 23040 0
malloc-384 384 30 30 30 0 30 23040 0
SLEEPQUEUE 88 122 134 122 0 126 22528 0
hostcache 64 1 314 1 0 254 20160 0
udpcb 32 6 624 128 0 254 20160 0
udp_inpcb ports 32 3 627 40 0 254 20160 0
ertt 72 3 277 7 0 126 20160 0
PWD 32 10 620 100 0 254 20160 0
malloc-32 32 5 625 14 0 254 20160 0
malloc-32 32 116 514 297 0 254 20160 0
malloc-32 32 33 597 35 0 254 20160 0
malloc-32 32 55 575 233 0 254 20160 0
malloc-32 32 23 607 1072 0 254 20160 0
2 Bucket 32 47 583 290 0 254 20160 0
epoch_record pcpu 256 4 60 4 0 62 16384 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-8192 8192 2 0 2 0 1 16384 0
malloc-4096 4096 2 2 197 0 2 16384 0
malloc-4096 4096 3 1 3 0 2 16384 0
malloc-2048 2048 3 5 3 0 8 16384 0
malloc-2048 2048 1 7 1 0 8 16384 0
malloc-1024 1024 4 12 4 0 16 16384 0
malloc-1024 1024 1 15 1 0 16 16384 0
malloc-512 512 3 29 170 0 30 16384 0
malloc-512 512 0 32 1 0 30 16384 0
malloc-512 512 2 30 2 0 30 16384 0
SMR CPU 32 7 504 7 0 254 16352 0
malloc-16 16 478 522 3438 0 254 16000 0
kenv 258 15 45 1037 0 30 15480 0
mqnode 416 3 33 3 0 30 14976 0
vmem 1856 1 7 1 0 8 14848 0
SMR SHARED 24 7 504 7 0 254 12264 0
tcp_inpcb ports 32 1 377 1 0 254 12096 0
malloc-32 32 81 297 892 0 254 12096 0
KNOTE 160 0 75 8 0 62 12000 0
malloc-16 16 9 741 195 0 254 12000 0
malloc-16 16 18 732 131 0 254 12000 0
malloc-16 16 16 734 56 0 254 12000 0
malloc-16 16 36 714 26254 0 254 12000 0
malloc-16 16 23 727 1251 0 254 12000 0
malloc-16 16 13 737 61 0 254 12000 0
malloc-384 384 0 30 1 0 30 11520 0
malloc-384 384 1 29 1 0 30 11520 0
malloc-8192 8192 1 0 1 0 1 8192 0
malloc-8192 8192 1 0 1 0 1 8192 0
pcpu-16 16 14 498 14 0 254 8192 0
vtnet_tx_hdr 24 0 334 1370 0 254 8016 0
UMA Slabs 1 176 9 13 9 0 62 3872 0
KMAP ENTRY 96 12 27 14 0 0 3744 0
pcpu-4 4 1 511 1 0 254 2048 0
FFS1 dinode 128 0 0 0 0 126 0 0
ada_ccb 272 0 0 0 0 30 0 0
swblk 136 0 0 0 0 62 0 0
swpctrie 144 0 0 0 0 62 0 0
cdg_qdiffsample 16 0 0 0 0 254 0 0
pf state scrubs 40 0 0 0 0 254 0 0
pf frag entries 40 0 0 0 0 254 0 0
pf frags 248 0 0 0 0 62 0 0
pf table entries 160 0 0 0 0 254 0 0
pf table entry counters 64 0 0 0 0 254 0 0
pf source nodes 136 0 0 0 0 254 0 0
pf state keys 88 0 0 0 0 126 0 0
pf states 312 0 0 0 0 254 0 0
pf tags 104 0 0 0 0 126 0 0
pf mtags 184 0 0 0 0 62 0 0
tcp_bbr_pcb 832 0 0 0 0 16 0 0
tcp_bbr_map 128 0 0 0 0 126 0 0
tcp_rack_pcb 896 0 0 0 0 16 0 0
tcp_rack_map 120 0 0 0 0 126 0 0
ipq 56 0 0 0 0 254 0 0
tfo_ccache_entries 80 0 0 0 0 126 0 0
tfo 4 0 0 0 0 254 0 0
sackhole 32 0 0 0 0 254 0 0
tcptw 72 0 0 0 0 254 0 0
sctp_asconf_ack 48 0 0 0 0 254 0 0
sctp_asconf 40 0 0 0 0 254 0 0
sctp_stream_msg_out 112 0 0 0 0 254 0 0
sctp_readq 152 0 0 0 0 254 0 0
sctp_chunk 152 0 0 0 0 254 0 0
tcp_log_id_node 120 0 0 0 0 126 0 0
tcp_log_id_bucket 176 0 0 0 0 62 0 0
tcp_log 416 0 0 0 0 254 0 0
tcpreass 48 0 0 0 0 254 0 0
ripcb ports 32 0 0 0 0 254 0 0
udplite_inpcb ports 32 0 0 0 0 254 0 0
udplite_inpcb 424 0 0 0 0 30 0 0
IPsec SA lft_c 16 0 0 0 0 254 0 0
itimer 352 0 0 0 0 30 0 0
AIOLIO 272 0 0 0 0 30 0 0
AIOCB 552 0 0 0 0 16 0 0
AIOP 32 0 0 0 0 254 0 0
AIO 208 0 0 0 0 62 0 0
TMPFS node 224 0 0 0 0 62 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-16384 16384 0 0 0 0 1 0 0
malloc-16384 16384 0 0 0 0 1 0 0
malloc-16384 16384 0 0 0 0 1 0 0
malloc-16384 16384 0 0 0 0 1 0 0
malloc-8192 8192 0 0 0 0 1 0 0
malloc-4096 4096 0 0 0 0 2 0 0
malloc-1024 1024 0 0 0 0 16 0 0
malloc-512 512 0 0 0 0 30 0 0
malloc-512 512 0 0 0 0 30 0 0
malloc-512 512 0 0 0 0 30 0 0
pcpu-32 32 0 0 0 0 254 0 0
fakepg 104 0 0 0 0 126 0 0

Mark Johnston

unread,
May 31, 2022, 10:56:58 AM5/31/22
to syzbot, syzkaller-f...@googlegroups.com
#syz fix: pf: make sure the rule tree is allocated in DIOCCHANGERULE
Reply all
Reply to author
Forward
0 new messages