panic: m_uiotombuf: progress != total

10 views
Skip to first unread message

syzbot

unread,
Mar 19, 2019, 9:22:06 AM3/19/19
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 5d2bb169 Remove extra spaces.
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=148ad46d200000
dashboard link: https://syzkaller.appspot.com/bug?extid=cd8a5421358bcee606a8

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+cd8a54...@syzkaller.appspotmail.com

panic: m_uiotombuf: progress != total
cpuid = 0
time = 1199
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe00212db370
vpanic() at vpanic+0x1e0/frame 0xfffffe00212db3d0
panic() at panic+0x43/frame 0xfffffe00212db430
m_uiotombuf() at m_uiotombuf+0x2b5/frame 0xfffffe00212db490
sctp_lower_sosend() at sctp_lower_sosend+0x5099/frame 0xfffffe00212db670
sctp_sosend() at sctp_sosend+0x510/frame 0xfffffe00212db7a0
sosend() at sosend+0xc6/frame 0xfffffe00212db810
kern_sendit() at kern_sendit+0x35e/frame 0xfffffe00212db8c0
sendit() at sendit+0x226/frame 0xfffffe00212db920
sys_sendto() at sys_sendto+0x5c/frame 0xfffffe00212db980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe00212dbab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe00212dbab0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x412e5a, rsp =
0x7fffdffdcf38, rbp = 0x6 ---
KDB: enter: panic
[ thread pid 6408 tid 100938 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#bug-status-tracking for how to communicate with
syzbot.

syzbot

unread,
Mar 19, 2019, 9:37:06 AM3/19/19
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 5d2bb169 Remove extra spaces.
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=10564ef7200000
dashboard link: https://syzkaller.appspot.com/bug?extid=cd8a5421358bcee606a8
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=15e8ac6d200000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+cd8a54...@syzkaller.appspotmail.com

login: panic: m_uiotombuf: progress != total
cpuid = 1
time = 1553001884
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe0021295370
vpanic() at vpanic+0x1e0/frame 0xfffffe00212953d0
panic() at panic+0x43/frame 0xfffffe0021295430
m_uiotombuf() at m_uiotombuf+0x2b5/frame 0xfffffe0021295490
sctp_lower_sosend() at sctp_lower_sosend+0x5099/frame 0xfffffe0021295670
sctp_sosend() at sctp_sosend+0x510/frame 0xfffffe00212957a0
sosend() at sosend+0xc6/frame 0xfffffe0021295810
kern_sendit() at kern_sendit+0x35e/frame 0xfffffe00212958c0
sendit() at sendit+0x226/frame 0xfffffe0021295920
sys_sendto() at sys_sendto+0x5c/frame 0xfffffe0021295980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe0021295ab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe0021295ab0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x412e5a, rsp =
0x7fffdffdcf38, rbp = 0x6 ---
KDB: enter: panic
[ thread pid 784 tid 100123 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why
db>

Michael Tuexen

unread,
Jan 1, 2021, 3:34:16 PM1/1/21
to syzkaller-freebsd-bugs
#syz invalid

The last crash occurred 654 days ago, the reproducer does not trigger the bug anymore, so considering it invalid. If the problem still exists, hopefully a new reproducer will be found.

syzbot

unread,
Jan 1, 2021, 3:34:18 PM1/1/21
to 'Michael Tuexen' via syzkaller-freebsd-bugs, syzkaller-f...@googlegroups.com
> #syz invalid

I see the command but can't find the corresponding bug.
Please resend the email to syzbo...@syzkaller.appspotmail.com address
that is the sender of the bug report (also present in the Reported-by tag).
> --
> You received this message because you are subscribed to the Google Groups "syzkaller-freebsd-bugs" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to syzkaller-freebsd...@googlegroups.com.
> To view this discussion on the web visit https://groups.google.com/d/msgid/syzkaller-freebsd-bugs/1a68151e-47d4-4a62-9c33-373fa0c2f3b2n%40googlegroups.com.
Reply all
Reply to author
Forward
0 new messages