Fatal trap NUM: page fault in tcp_input_with_port

0 views
Skip to first unread message

syzbot

unread,
Jun 1, 2023, 12:10:18 AM6/1/23
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 4f2cc73f34eb tcp: Refactor tcp_get_srtt()
git tree: freebsd-src
console output: https://syzkaller.appspot.com/x/log.txt?x=1269f599280000
dashboard link: https://syzkaller.appspot.com/bug?extid=e7d2e451f89fb444319b

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+e7d2e4...@syzkaller.appspotmail.com

Fatal trap 12: page fault while in kernel mode
cpuid = 0; apic id = 00
fault virtual address = 0xb8
fault code = supervisor read data, page not present
instruction pointer = 0x20:0xffffffff8194b409
stack pointer = 0x28:0xfffffe0053fbf740
frame pointer = 0x28:0xfffffe0053fbfa00
code segment = base 0x0, limit 0xfffff, type 0x1b
= DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags = interrupt enabled, resume, IOPL = 0
current process = 12 (swi1: netisr 0)
rdi: 00000000000000b8 rsi: 0000000000000000 rdx: 0000000000000000
rcx: fffffe00033eee30 r8: 0000000000000000 r9: ffffffff827479e0
rax: fffffe00033eee30 rbx: 0000000000000000 rbp: fffffe0053fbfa00
r10: 00000000000005c0 r11: 00000000652fe220 r12: fffffe0073d67578
r13: fffffe006c0e1700 r14: fffffe0073d675c8 r15: fffffe0073d67540
trap number = 12
panic: page fault
cpuid = 0
time = 1685592532
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0xc7/frame 0xfffffe0053fbef30
kdb_backtrace() at kdb_backtrace+0xd1/frame 0xfffffe0053fbf090
vpanic() at vpanic+0x252/frame 0xfffffe0053fbf170
panic() at panic+0xb5/frame 0xfffffe0053fbf230
trap_fatal() at trap_fatal+0x7ed/frame 0xfffffe0053fbf350
trap_pfault() at trap_pfault+0x182/frame 0xfffffe0053fbf490
trap() at trap+0x5e1/frame 0xfffffe0053fbf670
calltrap() at calltrap+0x8/frame 0xfffffe0053fbf670
--- trap 0xc, rip = 0xffffffff8194b409, rsp = 0xfffffe0053fbf740, rbp = 0xfffffe0053fbfa00 ---
tcp_input_with_port() at tcp_input_with_port+0x1269/frame 0xfffffe0053fbfa00
tcp6_input_with_port() at tcp6_input_with_port+0xe5/frame 0xfffffe0053fbfa40
tcp6_input() at tcp6_input+0x28/frame 0xfffffe0053fbfa70
ip6_input() at ip6_input+0x22da/frame 0xfffffe0053fbfcd0
swi_net() at swi_net+0x2ed/frame 0xfffffe0053fbfd70
ithread_loop() at ithread_loop+0x4ee/frame 0xfffffe0053fbfef0
fork_exit() at fork_exit+0xd0/frame 0xfffffe0053fbff30
fork_trampoline() at fork_trampoline+0xe/frame 0xfffffe0053fbff30
--- trap 0, rip = 0, rsp = 0, rbp = 0 ---
KDB: enter: panic
[ thread pid 12 tid 100031 ]
Stopped at kdb_enter+0x6b: movq $0,0x2144c7a(%rip)
db> set $lines = 0
db> set $maxwidth = 0
db> show registers
cs 0x20
ds 0x3b
es 0x3b
fs 0x13
gs 0x1b
ss 0x28
rax 0x12
rcx 0xffffffff815bb636 printf+0xf6
rdx 0x1
rbx 0
rsp 0xfffffe0053fbf070
rbp 0xfffffe0053fbf090
rsi 0
rdi 0xffffffff815bb698 printf+0x158
r8 0
r9 0xffffffff
r10 0
r11 0x652fe220
r12 0
r13 0xfffffe005428c560
r14 0xffffffff8269b9a0 .str.26
r15 0xffffffff8269b9a0 .str.26
rip 0xffffffff815ab41b kdb_enter+0x6b
rflags 0x46
kdb_enter+0x6b: movq $0,0x2144c7a(%rip)
db> show proc
Process 12 (intr) at 0xfffffe00541db580:
state: NORMAL
uid: 0 gids: 0
parent: pid 0 at 0xffffffff836a8040
ABI: null
flag: 0x10000284 flag2: 0
reaper: 0xffffffff836a8040 reapsubtree: 12
sigparent: 20
vmspace: 0xffffffff836a8fe0
(map 0xffffffff836a8fe0)
(map.pmap 0xffffffff836a90a0)
(pmap 0xffffffff836a9110)
threads: 22
100016 I [swi5: fast taskq]
100019 I [swi6: task queue]
100020 I [swi6: Giant taskq]
100031 Run CPU 0 [swi1: netisr 0]
100032 I [swi1: hpts]
100033 I [swi1: hpts]
100046 I [irq24: virtio_pci0]
100047 I [irq25: virtio_pci0]
100048 I [irq26: virtio_pci0]
100049 I [irq27: virtio_pci0]
100050 I [irq28: virtio_pci1]
100051 I [irq29: virtio_pci1]
100052 I [irq30: virtio_pci1]
100053 I [irq31: virtio_pci1]
100054 I [irq32: virtio_pci1]
100059 I [irq33: virtio_pci2]
100060 I [irq34: virtio_pci2]
100061 I [irq35: virtio_pci2]
100063 I [irq1: atkbd0]
100064 I [irq12: psm0]
100065 I [swi0: uart uart++]
100069 I [swi1: pf send]
db> ps
pid ppid pgrp uid state wmesg wchan cmd
44949 793 793 0 R (threaded) syz-executor.3
154591 RunQ syz-executor.3
154608 RunQ syz-executor.3
154609 L *tcpinp 0xfffffe0075574780 syz-executor.3
154610 S uwait 0xfffffe0057a5ed00 syz-executor.3
44944 777 777 0 R (threaded) syz-executor.0
149590 RunQ syz-executor.0
154598 D biowr 0xfffffe0007f2c408 syz-executor.0
154604 S uwait 0xfffffe0058f59180 syz-executor.0
44942 778 778 0 R (threaded) syz-executor.1
154552 RunQ syz-executor.1
154596 S connec 0xfffffe00749800da syz-executor.1
154603 S uwait 0xfffffe0057a5b200 syz-executor.1
41381 1 41378 0 SV uwait 0xfffffe0058f5a900 syz-executor.0
41374 41373 41368 0 SV uwait 0xfffffe0057a5d300 syz-executor.0
41373 1 41368 0 DV ppwait 0xfffffe0073f9bfc0 syz-executor.0
41365 41364 41357 0 SV uwait 0xfffffe0058f59a00 syz-executor.0
41364 1 41357 0 DV ppwait 0xfffffe00748f0500 syz-executor.0
41356 41355 41350 0 SV uwait 0xfffffe0057a5c900 syz-executor.0
41355 1 41350 0 DV ppwait 0xfffffe00753bffc0 syz-executor.0
41344 41343 41338 0 SV uwait 0xfffffe0058f59b00 syz-executor.0
41343 1 41338 0 DV ppwait 0xfffffe006cc49a80 syz-executor.0
41332 41331 41330 0 SV uwait 0xfffffe0057a5bb80 syz-executor.0
41331 1 41330 0 DV ppwait 0xfffffe0073f9ca80 syz-executor.0
41323 41322 41317 0 SV uwait 0xfffffe0057612c80 syz-executor.0
41322 1 41317 0 DV ppwait 0xfffffe00748f3ac0 syz-executor.0
41309 41308 41306 0 SV uwait 0xfffffe0057a5d500 syz-executor.0
41308 1 41306 0 DV ppwait 0xfffffe006d1d8540 syz-executor.0
41299 41298 41295 0 SV uwait 0xfffffe0057a5d200 syz-executor.0
41298 1 41295 0 DV ppwait 0xfffffe0073f9e560 syz-executor.0
41154 1 41150 0 SV uwait 0xfffffe0058f59d00 syz-executor.2
41153 1 41150 0 SV uwait 0xfffffe0057a5c100 syz-executor.2
41141 41140 41139 0 SV uwait 0xfffffe0057a5b880 syz-executor.2
41140 1 41139 0 DV ppwait 0xfffffe00748f2540 syz-executor.2
31285 1 777 0 SV uwait 0xfffffe0058f5bb80 syz-executor.0
31284 1 777 0 SV uwait 0xfffffe0057a5cb00 syz-executor.0
31275 1 777 0 SV uwait 0xfffffe0058f59e00 syz-executor.0
31263 1 777 0 SV uwait 0xfffffe0057a5bd80 syz-executor.0
27622 1 793 0 S uwait 0xfffffe0058f5a280 syz-executor.3
27620 1 793 0 S uwait 0xfffffe0057a5d800 syz-executor.3
27615 1 793 0 S uwait 0xfffffe0057a5ce80 syz-executor.3
27510 1 793 0 S uwait 0xfffffe0058f59900 syz-executor.3
27505 1 793 0 S uwait 0xfffffe0058f5b300 syz-executor.3
27498 1 793 0 S uwait 0xfffffe0057a5c000 syz-executor.3
27443 1 777 0 S uwait 0xfffffe0058f5a180 syz-executor.0
23796 1 778 0 SV uwait 0xfffffe0057a5d600 syz-executor.1
12911 0 0 0 DL aiordy 0xfffffe0073f9b560 [aiod4]
12910 0 0 0 DL aiordy 0xfffffe0073f9c020 [aiod3]
12909 0 0 0 DL aiordy 0xfffffe0058e85060 [aiod2]
12908 0 0 0 DL aiordy 0xfffffe006d1d7580 [aiod1]
5038 1 5038 65 Ss select 0xfffffe0058f5a3c0 dhclient
4265 1 4265 0 Ss select 0xfffffe0058f5a440 dhclient
4262 1 4262 0 Ss select 0xfffffe0057a5b3c0 dhclient
4243 1 4243 65 Ss select 0xfffffe0058f5a6c0 dhclient
3692 1 3692 0 Ss select 0xfffffe0057a5b4c0 dhclient
3689 1 3689 0 Ss select 0xfffffe0058f5a740 dhclient
3670 1 3670 65 Ss select 0xfffffe0057a5b6c0 dhclient
3200 1 3200 0 Ss select 0xfffffe0057a5b5c0 dhclient
3195 1 3195 0 Ss select 0xfffffe0058f5a5c0 dhclient
3174 1 3174 65 Ss select 0xfffffe0057a5b640 dhclient
811 1 811 0 Ss select 0xfffffe0058f5a640 dhclient
808 1 808 0 Ss select 0xfffffe0058f5a540 dhclient
793 774 793 0 Rs syz-executor.3
783 774 783 0 Ss piperd 0xfffffe0058be6998 syz-executor.2
778 774 778 0 Rs syz-executor.1
777 774 777 0 Rs syz-executor.0
774 772 772 0 S (threaded) syz-fuzzer
100091 S uwait 0xfffffe0057612980 syz-fuzzer
100111 S uwait 0xfffffe0058f5be00 syz-fuzzer
100112 S wait 0xfffffe0057b6dae0 syz-fuzzer
100113 S wait 0xfffffe0057b6dae0 syz-fuzzer
100114 S wait 0xfffffe0057b6dae0 syz-fuzzer
100115 S uwait 0xfffffe0058f5c180 syz-fuzzer
100116 S uwait 0xfffffe0058f5c280 syz-fuzzer
100118 S uwait 0xfffffe005712ec00 syz-fuzzer
100119 S wait 0xfffffe0057b6dae0 syz-fuzzer
100123 S uwait 0xfffffe0058f5ad00 syz-fuzzer
100126 S kqread 0xfffffe00574fe600 syz-fuzzer
100144 S uwait 0xfffffe0058f5a800 syz-fuzzer
132559 S uwait 0xfffffe0058f5c480 syz-fuzzer
772 770 772 0 Ss pause 0xfffffe0058e840f0 csh
770 688 770 0 Ss select 0xfffffe0058f5b3c0 sshd
754 1 754 0 Rs+ CPU 1 getty
753 1 753 0 Ss+ ttyin 0xfffffe005881e0b0 getty
752 1 752 0 Ss+ ttyin 0xfffffe005881e4b0 getty
751 1 751 0 Ss+ ttyin 0xfffffe005881e8b0 getty
750 1 750 0 Ss+ ttyin 0xfffffe005881ecb0 getty
749 1 749 0 Ss+ ttyin 0xfffffe005881f0b0 getty
748 1 748 0 Ss+ ttyin 0xfffffe005881f4b0 getty
747 1 747 0 Ss+ ttyin 0xfffffe005881f8b0 getty
746 1 746 0 Ss+ ttyin 0xfffffe005881fcb0 getty
692 1 692 0 Ss nanslp 0xffffffff836d1800 cron
688 1 688 0 Ss select 0xfffffe0058f5b640 sshd
501 1 501 0 Ss select 0xfffffe0058f5bb40 syslogd
430 1 430 0 Ss select 0xfffffe0058f5ba40 devd
429 1 429 65 Ss select 0xfffffe0058f5b8c0 dhclient
344 1 344 0 Ss select 0xfffffe0058f5b9c0 dhclient
341 1 341 0 Ss select 0xfffffe0058f5bac0 dhclient
17 0 0 0 DL syncer 0xffffffff837d3d20 [syncer]
16 0 0 0 DL vlruwt 0xfffffe0057161000 [vnlru]
15 0 0 0 DL (threaded) [bufdaemon]
100079 D psleep 0xffffffff837d2340 [bufdaemon]
100082 D - 0xffffffff82c0a140 [bufspacedaemon-0]
100094 D sdflush 0xfffffe0058b884e8 [/ worker]
9 0 0 0 DL psleep 0xffffffff83809bc0 [vmdaemon]
8 0 0 0 RL (threaded) [pagedaemon]
100077 RunQ [dom0]
100080 D launds 0xffffffff837fda84 [laundry: dom0]
100081 D umarcl 0xffffffff81d22880 [uma]
7 0 0 0 DL - 0xffffffff83495e28 [rand_harvestq]
6 0 0 0 DL pftm 0xffffffff8452f310 [pf purge]
5 0 0 0 DL waiting 0xffffffff843611c0 [sctp_iterator]
4 0 0 0 RL (threaded) [cam]
100044 RunQ [doneq0]
100045 D - 0xffffffff834782c0 [async]
100076 D - 0xffffffff83478140 [scanner]
14 0 0 0 DL seqstat 0xfffffe0054366088 [sequencer 00]
3 0 0 0 DL (threaded) [crypto]
100040 D crypto_ 0xffffffff837f9320 [crypto]
100041 D crypto_ 0xfffffe0054078d30 [crypto returns 0]
100042 D crypto_ 0xfffffe0054078d80 [crypto returns 1]
13 0 0 0 DL (threaded) [geom]
100035 D - 0xffffffff836a7620 [g_event]
100036 D - 0xffffffff836a7640 [g_up]
100037 D - 0xffffffff836a7660 [g_down]
2 0 0 0 WL (threaded) [clock]
100029 I [clock (0)]
100030 I [clock (1)]
12 0 0 0 RL (threaded) [intr]
100016 I [swi5: fast taskq]
100019 I [swi6: task queue]
100020 I [swi6: Giant taskq]
100031 Run CPU 0 [swi1: netisr 0]
100032 I [swi1: hpts]
100033 I [swi1: hpts]
100046 I [irq24: virtio_pci0]
100047 I [irq25: virtio_pci0]
100048 I [irq26: virtio_pci0]
100049 I [irq27: virtio_pci0]
100050 I [irq28: virtio_pci1]
100051 I [irq29: virtio_pci1]
100052 I [irq30: virtio_pci1]
100053 I [irq31: virtio_pci1]
100054 I [irq32: virtio_pci1]
100059 I [irq33: virtio_pci2]
100060 I [irq34: virtio_pci2]
100061 I [irq35: virtio_pci2]
100063 I [irq1: atkbd0]
100064 I [irq12: psm0]
100065 I [swi0: uart uart++]
100069 I [swi1: pf send]
11 0 0 0 RL (threaded) [idle]
100003 CanRun [idle: cpu0]
100004 CanRun [idle: cpu1]
1 0 1 0 SLs wait 0xfffffe00541dc040 [init]
10 0 0 0 DL audit_w 0xffffffff837f9d60 [audit]
0 0 0 0 DLs (threaded) [kernel]
100000 D swapin 0xffffffff836a8040 [swapper]
100005 D - 0xfffffe005427b100 [if_io_tqg_0]
100006 D - 0xfffffe005427b000 [if_io_tqg_1]
100007 D - 0xfffffe005427ae00 [if_config_tqg_0]
100008 D - 0xfffffe005427ad00 [softirq_0]
100009 D - 0xfffffe005427ac00 [softirq_1]
100010 D - 0xfffffe000795fc00 [linuxkpi_irq_wq]
100011 D - 0xfffffe000795fb00 [thread taskq]
100012 D - 0xfffffe000795fa00 [inm_free taskq]
100013 D - 0xfffffe000795f900 [aiod_kick taskq]
100014 D - 0xfffffe000795f800 [deferred_unmount ta]
100015 D - 0xfffffe000795f700 [in6m_free taskq]
100017 D - 0xfffffe000795f400 [kqueue_ctx taskq]
100018 D - 0xfffffe000795f300 [pci_hp taskq]
100021 D - 0xfffffe000795ed00 [linuxkpi_short_wq_0]
100022 D - 0xfffffe000795ed00 [linuxkpi_short_wq_1]
100023 D - 0xfffffe000795ed00 [linuxkpi_short_wq_2]
100024 D - 0xfffffe000795ed00 [linuxkpi_short_wq_3]
100025 D - 0xfffffe000795ec00 [linuxkpi_long_wq_0]
100026 D - 0xfffffe000795ec00 [linuxkpi_long_wq_1]
100027 D - 0xfffffe000795ec00 [linuxkpi_long_wq_2]
100028 D - 0xfffffe000795ec00 [linuxkpi_long_wq_3]
100034 D - 0xfffffe000795e700 [firmware taskq]
100038 D - 0xfffffe000795e600 [crypto_0]
100039 D - 0xfffffe000795e600 [crypto_1]
100055 D - 0xfffffe000795e000 [vtnet0 rxq 0]
100056 D - 0xfffffe00574ff300 [vtnet0 txq 0]
100057 D - 0xfffffe00574ff200 [vtnet0 rxq 1]
100058 D - 0xfffffe00574ff100 [vtnet0 txq 1]
100062 D vtbslp 0xfffffe0057615100 [virtio_balloon]
100066 D - 0xffffffff826a08e0 [deadlkres]
100071 D - 0xfffffe0007961900 [mca taskq]
100072 D - 0xfffffe0058806400 [acpi_task_0]
100073 D - 0xfffffe0058806400 [acpi_task_1]
100074 D - 0xfffffe0058806400 [acpi_task_2]
100075 D - 0xfffffe000795e500 [CAM taskq]
db> show all locks
Process 44949 (syz-executor.3) thread 0xfffffe007567dc80 (154608)
exclusive rw tcpinp (tcpinp) r = 0 (0xfffffe0073e75020) locked @ /syzkaller/managers/main/kernel/sys/netinet/tcp_usrreq.c:560
Process 44944 (syz-executor.0) thread 0xfffffe0073e81000 (154598)
exclusive lockmgr bufwait (bufwait) r = 0 (0xfffffe0007f2c488) locked @ /syzkaller/managers/main/kernel/sys/kern/vfs_bio.c:1733
exclusive lockmgr ufs (ufs) r = 0 (0xfffffe0075399070) locked @ /syzkaller/managers/main/kernel/sys/kern/vfs_vnops.c:1164
Process 754 (getty) thread 0xfffffe0058e75900 (100109)
exclusive sleep mutex ttymtx (ttymtx) r = 0 (0xfffffe0057171408) locked @ /syzkaller/managers/main/kernel/sys/kern/tty_ttydisc.c:489
Process 12 (intr) thread 0xfffffe005428c560 (100031)
shared rw tcpinp (tcpinp) r = 0 (0xfffffe0073d67560) locked @ /syzkaller/managers/main/kernel/sys/netinet/in_pcb.c:1472
db> show malloc
Type InUse MemUse Requests
pf_hash 5 11524K 5
tcp_hpts 7 4801K 7
devbuf 4218 4324K 4246
sysctloid 34684 2044K 34755
vtbuf 24 1968K 46
pcb 676 1398K 201988
kobj 326 1304K 488
newblk 33 1032K 150490
vfscache 3 1025K 3
filedesc 82 650K 87999
inodedep 9 515K 50750
ufs_quota 1 512K 1
vfs_hash 1 512K 1
callout 2 512K 2
intr 4 472K 4
subproc 215 418K 45072
sctp_stro 314 314K 20247
vmem 3 266K 6
sctp_atcl 638 240K 122080
acpica 1674 184K 57877
tidhash 3 141K 3
pagedep 9 130K 44000
tfo_ccache 1 128K 1
IP reass 1 128K 1
linker 324 127K 353
vnet_data 1 112K 1
DEVFS1 109 109K 126
sem 4 106K 4
BPF 46 88K 84
bus 988 81K 5135
mtx_pool 2 72K 2
NFSD srvcache 3 68K 3
syncache 1 68K 1
acpitask 1 64K 1
ddb_capture 1 64K 1
module 508 64K 508
umtx 462 58K 462
kdtrace 293 56K 99561
temp 36 53K 2920
sctp_timw 209 53K 209
sctp_atky 952 40K 145873
DEVFS3 128 32K 138
hostcache 1 32K 1
shm 1 32K 10
msg 4 30K 4
kbdmux 6 28K 6
gtaskqueue 18 26K 18
ifaddr 70 20K 72
DEVFS_RULE 56 20K 56
ufs_mount 4 17K 5
proc 3 17K 3
tty 16 16K 16
ithread 97 16K 97
routetbl 128 16K 411
bus-sc 34 15K 1648
lltable 43 14K 141
eventhandler 156 13K 156
KTRACE 101 13K 509
ifnet 7 13K 7
ether_multi 152 13K 162
kenv 95 12K 95
rman 88 11K 431
GEOM 61 11K 481
CAM queue 5 11K 1528
sctp_athm 638 10K 123616
sctp_map 628 10K 40494
in6_multi 65 9K 65
bmsafemap 2 9K 49922
rpc 4 9K 4
UART 12 9K 12
devstat 4 9K 4
kqueue 95 9K 44959
ksem 1 8K 105
pfs_vncache 1 8K 1
shmfd 1 8K 104
audit_evclass 237 8K 297
taskqueue 63 7K 63
cred 26 7K 507
sglist 5 7K 5
CAM DEV 3 6K 510
plimit 24 6K 546
pwddesc 93 6K 44950
session 46 6K 85
pfs_nodes 20 5K 20
ufs_dirhash 24 5K 24
UMA 266 5K 266
pf_ifnet 10 5K 19
DEVFSP 68 5K 1584
vt 11 5K 11
memdesc 1 4K 1
MCA 32 4K 32
evdev 4 4K 4
proc-args 124 4K 46364
acpisem 28 4K 28
selfd 55 4K 603550
lockf 32 4K 70
hhook 15 4K 17
kcovinfo 52 4K 52
terminal 11 3K 11
select 19 3K 102
clone 9 3K 9
uidinfo 3 3K 133
local_apic 1 2K 1
io_apic 1 2K 1
fpukern_ctx 2 2K 2
ipsec-saq 2 2K 2
pf_rule 15 2K 132
ip6ndp 12 2K 13
sctp_ifa 13 2K 14
CC Mem 13 2K 20914
Unitno 27 2K 143
CAM XPT 22 2K 543
msi 12 2K 12
in_multi 6 2K 8
ipsecpolicy 2 2K 2
acpidev 20 2K 20
tun 7 2K 7
NFSD session 1 1K 1
softdep 1 1K 1
sahead 1 1K 1
secasvar 1 1K 1
nhops 6 1K 8
vnodemarker 2 1K 126
CAM periph 4 1K 271
sctp_ifn 6 1K 14
ipsec 3 1K 3
diradd 6 1K 47867
inpcbpolicy 24 1K 23107
mld 6 1K 6
igmp 6 1K 6
pfil 6 1K 6
toponodes 6 1K 6
isadev 6 1K 6
mount 16 1K 89
pci_link 10 1K 10
crypto 4 1K 362
encap_export_host 12 1K 12
procdesc 5 1K 14
osd 18 1K 20927
newdirblk 4 1K 43978
dirrem 2 1K 47822
mkdir 4 1K 87956
cdev 2 1K 2
chacha20random 1 1K 1
biobuf 1 1K 1
NFSD lckfile 1 1K 1
NFSD V4client 1 1K 1
DEVFS 9 1K 10
freefile 2 1K 47788
indirdep 1 1K 63232
vnodes 1 1K 1
CAM SIM 2 1K 2
feeder 7 1K 7
tcpfunc 3 1K 3
loginclass 3 1K 6
prison 6 1K 6
lkpikmalloc 5 1K 6
soname 6 1K 67381
aesni_data 2 1K 2
cryptodev 2 1K 2372
nexusdev 8 1K 8
apmdev 1 1K 1
atkbddev 2 1K 2
netlink 1 1K 1
CAM dev queue 2 1K 2
CAM I/O Scheduler 1 1K 1
aio 4 1K 7
CAM path 4 1K 1034
iov 2 1K 43909
pmchooks 1 1K 1
filecaps 5 1K 109
sctp_vrf 1 1K 1
vnet 1 1K 1
entropy 2 1K 49
pmc 1 1K 1
acpiintr 1 1K 1
cpus 2 1K 2
freework 1 1K 89467
vnet_data_free 1 1K 1
Per-cpu 1 1K 1
p1003.1b 1 1K 1
pf_table 0 0K 0
pf_altq 0 0K 0
pf_osfp 0 0K 0
pf_krule_item 0 0K 0
pf_temp 0 0K 0
sctp_mcore 0 0K 0
sctp_socko 0 0K 54200
sctp_iter 0 0K 12
sctp_mvrf 0 0K 0
sctp_cpal 0 0K 0
sctp_cmsg 0 0K 0
sctp_stre 0 0K 0
sctp_athi 0 0K 0
sctp_a_it 0 0K 12
sctp_aadr 0 0K 21
sctp_stri 0 0K 2718
ipcomp 0 0K 0
esp 0 0K 0
ah 0 0K 0
filemon 0 0K 58
mqdata 0 0K 0
tcp_do 0 0K 0
tcp_fsb 0 0K 2312
md_intel_data 0 0K 0
md_ddf_data 0 0K 0
madt_table 0 0K 2
smartpqi 0 0K 0
raid_data 0 0K 72
geom_flashmap 0 0K 0
ixl 0 0K 0
tmpfs dir 0 0K 0
tmpfs name 0 0K 0
tmpfs mount 0 0K 0
tmpfs extattr 0 0K 0
NFS FHA 0 0K 0
ice-resmgr 0 0K 0
ice-osdep 0 0K 0
ice 0 0K 0
iavf 0 0K 0
axgbe 0 0K 0
newnfsmnt 0 0K 0
newnfsclient_req 0 0K 0
NFSCL layrecall 0 0K 0
NFSCL session 0 0K 0
NFSCL sockreq 0 0K 0
NFSCL devinfo 0 0K 0
NFSCL flayout 0 0K 0
NFSCL layout 0 0K 0
NFSD rollback 0 0K 0
xen_intr 0 0K 0
NFSCL diroff 0 0K 0
NEWdirectio 0 0K 0
xen_hvm 0 0K 0
legacydrv 0 0K 0
bounce 0 0K 0
busdma 0 0K 0
qpidrv 0 0K 0
NEWNFSnode 0 0K 0
NFSCL lck 0 0K 0
dmar_idpgtbl 0 0K 0
dmar_dom 0 0K 0
dmar_ctx 0 0K 0
NFSCL lckown 0 0K 0
NFSCL client 0 0K 0
NFSCL deleg 0 0K 0
isci 0 0K 0
iommu_dmamap 0 0K 0
NFSCL open 0 0K 0
hyperv_socket 0 0K 0
bxe_ilt 0 0K 0
NFSCL owner 0 0K 0
xenbus 0 0K 0
NFS fh 0 0K 0
NFS req 0 0K 0
NFSD usrgroup 0 0K 0
vm_fictitious 0 0K 0
NFSD string 0 0K 0
NFSD V4lock 0 0K 0
NFSD V4state 0 0K 0
msdosfs_fat 0 0K 0
msdosfs_mount 0 0K 0
msdosfs_node 0 0K 0
UMAHash 0 0K 0
DEVFS4 0 0K 0
vm_pgdata 0 0K 0
jblocks 0 0K 0
savedino 0 0K 48845
sentinel 0 0K 0
jfsync 0 0K 0
jtrunc 0 0K 0
sbdep 0 0K 59
jsegdep 0 0K 0
jseg 0 0K 0
jfreefrag 0 0K 0
jfreeblk 0 0K 0
jnewblk 0 0K 0
jmvref 0 0K 0
jremref 0 0K 0
jaddref 0 0K 0
freedep 0 0K 0
freeblks 0 0K 49520
freefrag 0 0K 43
allocindir 0 0K 0
allocdirect 0 0K 0
ufs_trim 0 0K 0
mactemp 0 0K 0
audit_trigger 0 0K 0
audit_pipe_presel 0 0K 0
audit_pipeent 0 0K 0
audit_pipe 0 0K 0
audit_evname 0 0K 0
audit_bsm 0 0K 0
audit_gidset 0 0K 0
audit_text 0 0K 0
audit_path 0 0K 0
audit_data 0 0K 0
audit_cred 0 0K 0
DEVFS2 0 0K 0
gntdev 0 0K 0
privcmd_dev 0 0K 0
evtchn_dev 0 0K 0
xenstore 0 0K 0
scsi_pass 0 0K 0
ciss_data 0 0K 0
xnb 0 0K 0
xen_acpi 0 0K 0
xbbd 0 0K 0
xbd 0 0K 0
Balloon 0 0K 0
sysmouse 0 0K 0
vtfont 0 0K 0
ktls_ocf 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5E_TLS_RX 0 0K 0
MLX5EEPROM 0 0K 0
MLX5E_TLS 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EN 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5DUMP 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
simple_attr 0 0K 0
seq_file 0 0K 0
lkpiskb 0 0K 0
radix 0 0K 0
idr 0 0K 0
lkpindev 0 0K 0
lkpimhi 0 0K 0
lkpifw 0 0K 0
lkpi80211 0 0K 0
NLM 0 0K 0
ipsec-spdcache 0 0K 0
ipsec-reg 0 0K 0
ipsec-misc 0 0K 0
ipsecrequest 0 0K 0
ip6opt 0 0K 44
ip6_msource 0 0K 0
ip6_moptions 0 0K 0
in6_mfilter 0 0K 0
frag6 0 0K 0
tcplog 0 0K 0
tcp_hwpace 0 0K 0
BACKLIGHT 0 0K 0
LRO 0 0K 0
ip_msource 0 0K 0
ip_moptions 0 0K 26
in_mfilter 0 0K 0
ipid 0 0K 0
80211scan 0 0K 0
80211ratectl 0 0K 0
80211power 0 0K 0
80211nodeie 0 0K 0
80211node 0 0K 0
80211mesh_gt 0 0K 0
80211mesh_rt 0 0K 0
80211perr 0 0K 0
80211prep 0 0K 0
80211preq 0 0K 0
80211dfs 0 0K 0
80211crypto 0 0K 0
80211vap 0 0K 0
iflib 0 0K 0
vlan 0 0K 0
gif 0 0K 0
ifdescr 0 0K 0
zlib 0 0K 0
fadvise 0 0K 3
VN POLL 0 0K 0
ath_hal 0 0K 0
statfs 0 0K 44376
namei_tracker 0 0K 0
export_host 0 0K 0
cl_savebuf 0 0K 2
athdev 0 0K 0
ata_pci 0 0K 0
ata_dma 0 0K 0
ata_generic 0 0K 0
pvscsi 0 0K 0
scsi_da 0 0K 69
ata_da 0 0K 0
scsi_ch 0 0K 0
scsi_cd 0 0K 0
AHCI driver 0 0K 0
USBdev 0 0K 0
USB 0 0K 0
agp 0 0K 0
nvme_da 0 0K 0
acpipwr 0 0K 0
acpi_perf 0 0K 0
twsbuf 0 0K 0
tcp_log_dev 0 0K 2128
lio 0 0K 3
acl 0 0K 0
midi buffers 0 0K 0
mbuf_tag 0 0K 0
ktls 0 0K 0
mixer 0 0K 0
ac97 0 0K 0
hdacc 0 0K 0
hdac 0 0K 0
hdaa 0 0K 0
acpicmbat 0 0K 0
SIIS driver 0 0K 0
CAM CCB 0 0K 523
PUC 0 0K 0
ppbusdev 0 0K 0
sr_iov 0 0K 0
OCS 0 0K 0
OCS 0 0K 0
nvme 0 0K 0
nvd 0 0K 0
netmap 0 0K 0
mwldev 0 0K 0
MVS driver 0 0K 0
CAM ccb queue 0 0K 0
accf 0 0K 0
pts 0 0K 0
ioctlops 0 0K 3248
eventfd 0 0K 106
Witness 0 0K 0
stack 0 0K 0
mrsasbuf 0 0K 0
mpt_user 0 0K 0
mps_user 0 0K 0
MPSSAS 0 0K 0
mps 0 0K 0
sbuf 0 0K 288
mpr_user 0 0K 0
firmware 0 0K 0
compressor 0 0K 0
MPRSAS 0 0K 0
SWAP 0 0K 0
mpr 0 0K 0
mfibuf 0 0K 0
sysctltmp 0 0K 1032
sysctl 0 0K 3
md_sectors 0 0K 0
ekcd 0 0K 0
dumper 0 0K 0
sendfile 0 0K 0
rctl 0 0K 0
md_disk 0 0K 0
malodev 0 0K 0
LED 0 0K 0
ix_sriov 0 0K 0
cache 0 0K 0
aacraidcam 0 0K 0
prison_racct 0 0K 0
Fail Points 0 0K 0
sigio 0 0K 1
filedesc_to_leader 0 0K 0
pwd 0 0K 0
tty console 0 0K 0
ix 0 0K 0
ipsbuf 0 0K 0
aacraid_buf 0 0K 0
aaccam 0 0K 0
boottrace 0 0K 0
aacbuf 0 0K 0
zstd 0 0K 0
XZ_DEC 0 0K 0
nvlist 0 0K 0
SCSI ENC 0 0K 0
SCSI sa 0 0K 0
isofs_node 0 0K 0
isofs_mount 0 0K 0
tr_raid5_data 0 0K 0
tr_raid1e_data 0 0K 0
tr_raid1_data 0 0K 0
tr_raid0_data 0 0K 0
tr_concat_data 0 0K 0
md_sii_data 0 0K 0
md_promise_data 0 0K 0
md_nvidia_data 0 0K 0
md_jmicron_data 0 0K 0
db> show uma
Zone Size Used Free Requests Sleeps Bucket Total Mem XFree
mbuf_jumbo_page 4096 8324 1074 1543558 0 254 38494208 0
tcp_log 416 132 10290 212101 0 254 4335552 0
sctp_asoc 2264 314 1211 20247 0 254 3452600 0
mbuf 256 9004 1411 2909152 0 254 2666240 0
RADIX NODE 144 17635 504 956091 0 63 2612016 0
mbuf_cluster 2048 1270 0 1270 0 254 2600960 0
malloc-2048 2048 331 909 101195 0 8 2539520 0
sctp_ep 1176 324 1456 100474 0 254 2093280 0
malloc-4096 4096 420 6 45640 0 2 1744896 0
BUF TRIE 144 223 11593 107309 0 62 1701504 0
malloc-384 384 4169 31 4512 0 30 1612800 0
malloc-256 256 84 6186 96756 0 62 1605120 0
malloc-128 128 11544 174 11894 0 126 1499904 0
UMA Slabs 0 112 12131 31 12131 0 126 1362144 0
malloc-1024 1024 316 868 20298 0 16 1212416 0
malloc-384 384 31 3089 50774 0 30 1198080 0
vmem btag 56 21153 126 21153 0 254 1191624 0
malloc-384 384 763 1757 122267 0 30 967680 0
sctp_raddr 736 314 962 22797 0 254 939136 0
malloc-16384 16384 40 5 43997 0 1 737280 0
VM OBJECT 264 2684 106 882637 0 30 736560 0
socket 960 72 692 125404 0 254 733440 0
FFS inode 1160 549 32 48341 0 8 673960 0
256 Bucket 2048 291 23 8510 0 8 643072 0
ertt_txseginfo 40 0 13029 373491 0 254 521160 0
pbuf 2624 0 198 0 0 2 519552 0
THREAD 1824 199 32 54610 0 8 421344 0
malloc-128 128 11 3275 135941 0 126 420608 0
MAP ENTRY 96 3896 388 2282366 0 126 411264 0
malloc-256 256 549 1011 155468 0 62 399360 0
malloc-65536 65536 4 2 614 0 1 393216 0
lkpimm 168 1 2327 1 0 62 391104 0
lkpicurr 168 2 2326 2 0 62 391104 0
mbuf_packet 256 290 980 79993 0 254 325120 0
VNODE 448 590 103 48384 0 30 310464 0
tcp_inpcb 1304 13 212 20914 0 8 293400 0
malloc-64 64 3893 454 609065 0 254 278208 0
malloc-32768 32768 0 8 60020 0 1 262144 0
malloc-256 256 318 687 197210 0 62 257280 0
malloc-16 16 14331 169 14965 0 254 232000 0
DEVCTL 1024 0 220 152 0 0 225280 0
FPU_save_area 832 201 42 63147 0 16 202176 0
malloc-128 128 1219 300 49185 0 126 194432 0
sctp_chunk 152 20 1254 13195 0 254 193648 0
malloc-32 32 5503 419 5990 0 254 189504 0
UMA Zones 768 238 1 238 0 16 183552 0
FFS2 dinode 256 549 141 48340 0 62 176640 0
PROC 1376 92 29 44949 0 8 166496 0
S VFS Cache 104 1066 455 52284 0 126 158184 0
128 Bucket 1024 107 40 6178 0 16 150528 0
malloc-1024 1024 124 20 1617 0 16 147456 0
malloc-128 128 904 243 2309 0 126 146816 0
64 Bucket 512 200 64 47867 0 30 135168 0
malloc-65536 65536 2 0 2 0 1 131072 0
malloc-2048 2048 6 58 708 0 8 131072 0
tcp_bbr_map 128 8 1015 43508 0 126 130944 0
unpcb 256 20 490 1757 0 254 130560 0
filedesc0 1072 93 19 44950 0 8 120064 0
ksiginfo 112 103 941 8712 0 126 116928 0
malloc-4096 4096 22 4 38 0 2 106496 0
malloc-64 64 325 1250 47237 0 254 100800 0
malloc-128 128 576 199 7819 0 126 99200 0
malloc-32768 32768 3 0 3 0 1 98304 0
malloc-16384 16384 5 1 175 0 1 98304 0
32 Bucket 256 237 138 29501 0 62 96000 0
malloc-32 32 738 2160 147631 0 254 92736 0
malloc-8192 8192 10 1 137 0 1 90112 0
UMA Kegs 384 225 8 225 0 30 89472 0
sctp_stream_msg_out 112 296 496 2353 0 254 88704 0
pipe 728 23 98 1497 0 16 88088 0
malloc-64 64 758 565 91573 0 254 84672 0
malloc-256 256 28 287 139633 0 62 80640 0
sctp_readq 152 0 520 586 0 254 79040 0
g_bio 408 4 176 831038 0 30 73440 0
malloc-64 64 619 452 2735 0 254 68544 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-65536 65536 0 1 8 0 1 65536 0
malloc-32768 32768 0 2 120 0 1 65536 0
malloc-256 256 213 42 13953 0 62 65280 0
udp_inpcb 424 6 147 669 0 30 64872 0
Files 80 258 542 202129 0 126 64000 0
ripcb 392 5 148 1336 0 30 59976 0
malloc-4096 4096 13 1 24 0 2 57344 0
malloc-4096 4096 10 4 13 0 2 57344 0
VMSPACE 520 61 44 44904 0 16 54600 0
malloc-64 64 308 511 45778 0 254 52416 0
malloc-128 128 57 346 91893 0 126 51584 0
malloc-128 128 20 383 339 0 126 51584 0
malloc-256 256 52 143 53196 0 62 49920 0
tcp_rack_pcb 1024 0 48 1156 0 16 49152 0
DIRHASH 1024 35 13 35 0 16 49152 0
NAMEI 1024 0 48 220313 0 16 49152 0
malloc-1024 1024 13 35 521 0 16 49152 0
malloc-512 512 0 96 2761 0 30 49152 0
16 Bucket 144 140 196 9721 0 62 48384 0
malloc-16 16 643 2357 220714 0 254 48000 0
malloc-16 16 683 2317 87801 0 254 48000 0
AIOCB 552 0 84 248 0 16 46368 0
tcp_bbr_pcb 832 8 46 11507 0 16 44928 0
PWD 40 43 1068 44062 0 254 44440 0
syncache 168 0 264 4 0 254 44352 0
TURNSTILE 136 232 83 232 0 62 42840 0
malloc-8192 8192 0 5 97 0 1 40960 0
malloc-8192 8192 5 0 5 0 1 40960 0
malloc-8192 8192 5 0 5 0 1 40960 0
malloc-4096 4096 3 7 1159 0 2 40960 0
pcpu-8 8 4796 324 5148 0 254 40960 0
udplite_inpcb 424 0 90 188 0 30 38160 0
da_ccb 544 1 69 207884 0 16 38080 0
malloc-64 64 157 410 195 0 254 36288 0
malloc-64 64 2 565 19 0 254 36288 0
malloc-64 64 6 561 39 0 254 36288 0
8 Bucket 80 192 258 13832 0 126 36000 0
tcp_rack_map 128 0 279 1524 0 126 35712 0
malloc-128 128 96 183 358 0 126 35712 0
routing nhops 256 27 108 34 0 62 34560 0
ttyoutq 256 72 63 160 0 62 34560 0
malloc-256 256 51 84 1616 0 62 34560 0
malloc-256 256 16 119 556 0 62 34560 0
SLEEPQUEUE 88 232 152 232 0 126 33792 0
malloc-32768 32768 1 0 1 0 1 32768 0
malloc-32768 32768 1 0 1 0 1 32768 0
malloc-16384 16384 2 0 2 0 1 32768 0
malloc-8192 8192 3 1 5 0 1 32768 0
malloc-4096 4096 4 4 620 0 2 32768 0
malloc-4096 4096 0 8 44376 0 2 32768 0
malloc-2048 2048 4 12 1821 0 8 32768 0
malloc-2048 2048 3 13 3 0 8 32768 0
malloc-2048 2048 6 10 6 0 8 32768 0
malloc-2048 2048 1 15 137 0 8 32768 0
malloc-2048 2048 6 10 10 0 8 32768 0
malloc-1024 1024 18 14 140 0 16 32768 0
malloc-1024 1024 12 20 12 0 16 32768 0
malloc-1024 1024 1 31 87 0 16 32768 0
malloc-512 512 7 57 317 0 30 32768 0
malloc-512 512 8 56 8 0 30 32768 0
malloc-512 512 10 54 39 0 30 32768 0
pcpu-64 64 486 26 486 0 254 32768 0
KNOTE 160 28 172 341628 0 62 32000 0
ttyinq 160 135 65 300 0 62 32000 0
clpbuf 2624 0 12 83 0 4 31488 0
cpuset 104 7 272 204 0 126 29016 0
sctp_laddr 48 0 588 14679 0 254 28224 0
tcp_inpcb ports 32 5 877 5542 0 254 28224 0
ertt 72 13 379 20914 0 126 28224 0
malloc-32 32 58 824 26578 0 254 28224 0
malloc-32 32 128 754 45621 0 254 28224 0
4 Bucket 48 6 582 10 0 254 28224 0
2 Bucket 32 67 815 16312 0 254 28224 0
AIO 208 0 133 138 0 62 27664 0
PGRP 88 46 230 85 0 126 24288 0
rl_entry 40 131 475 131 0 254 24240 0
rtentry 168 30 114 34 0 62 24192 0
malloc-384 384 30 30 128 0 30 23040 0
domainset 40 0 567 150 0 254 22680 0
hostcache 64 1 314 1 0 254 20160 0
udplite_inpcb ports 32 0 630 6 0 254 20160 0
udp_inpcb ports 32 3 627 48 0 254 20160 0
malloc-32 32 9 621 125 0 254 20160 0
malloc-32 32 220 410 1173 0 254 20160 0
malloc-32 32 7 623 20 0 254 20160 0
malloc-32 32 17 613 45 0 254 20160 0
malloc-16 16 575 675 49141 0 254 20000 0
cryptop 280 0 70 119 0 30 19600 0
L VFS Cache 320 0 60 25 0 30 19200 0
epoch_record pcpu 256 4 60 4 0 62 16384 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-8192 8192 2 0 2 0 1 16384 0
malloc-2048 2048 0 8 11 0 8 16384 0
malloc-1024 1024 5 11 5 0 16 16384 0
malloc-512 512 1 31 1 0 30 16384 0
malloc-512 512 1 31 1 0 30 16384 0
malloc-512 512 1 31 1 0 30 16384 0
SMR CPU 32 7 504 7 0 254 16352 0
vtnet_tx_hdr 24 0 668 802658 0 254 16032 0
kenv 258 15 45 1046 0 30 15480 0
mqnode 416 3 33 3 0 30 14976 0
vmem 1856 1 7 1 0 8 14848 0
SMR SHARED 24 7 504 7 0

---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the bug is already fixed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to change bug's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the bug is a duplicate of another bug, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Jul 1, 2023, 5:20:01 AM7/1/23
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 0631830a7a3c siftr: document siftr probe to man page of th..
git tree: freebsd-src
console output: https://syzkaller.appspot.com/x/log.txt?x=16178a4f280000
dashboard link: https://syzkaller.appspot.com/bug?extid=e7d2e451f89fb444319b
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=12696830a80000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+e7d2e4...@syzkaller.appspotmail.com

Fatal trap 12: page fault while in kernel mode
cpuid = 1; apic id = 01
fault virtual address = 0xb8
fault code = supervisor read data, page not present
instruction pointer = 0x20:0xffffffff81961339
stack pointer = 0x28:0xfffffe0053fbb760
frame pointer = 0x28:0xfffffe0053fbba20
code segment = base 0x0, limit 0xfffff, type 0x1b
= DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags = interrupt enabled, resume, IOPL = 0
current process = 12 (swi1: netisr 0)
rdi: 00000000000000b8 rsi: 0000000000000000 rdx: ffffffff82770980

rcx: fffffe00033eee30 r8: 0000000000000000 r9: ffffffff82766720
rax: fffffe00033eee30 rbx: fffffe006d17bb08 rbp: fffffe0053fbba20
r10: 00000000000005c0 r11: 0000000000000002 r12: fffffe006d0fbc00
r13: fffffe006d0fbc47 r14: 0000000000000000 r15: fffffe006d17ba80
trap number = 12
panic: page fault
cpuid = 1
time = 1688202980
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0xc6/frame 0xfffffe0053fbaf50
kdb_backtrace() at kdb_backtrace+0xd0/frame 0xfffffe0053fbb0b0
vpanic() at vpanic+0x252/frame 0xfffffe0053fbb190
panic() at panic+0xb5/frame 0xfffffe0053fbb250
trap_fatal() at trap_fatal+0x7ee/frame 0xfffffe0053fbb370
trap_pfault() at trap_pfault+0x183/frame 0xfffffe0053fbb4b0
trap() at trap+0x5f3/frame 0xfffffe0053fbb690
calltrap() at calltrap+0x8/frame 0xfffffe0053fbb690
--- trap 0xc, rip = 0xffffffff81961339, rsp = 0xfffffe0053fbb760, rbp = 0xfffffe0053fbba20 ---
tcp_input_with_port() at tcp_input_with_port+0x1109/frame 0xfffffe0053fbba20
tcp6_input_with_port() at tcp6_input_with_port+0xeb/frame 0xfffffe0053fbba60
tcp6_input() at tcp6_input+0x26/frame 0xfffffe0053fbba90
ip6_input() at ip6_input+0x22a8/frame 0xfffffe0053fbbcf0
swi_net() at swi_net+0x2f3/frame 0xfffffe0053fbbd90
ithread_loop() at ithread_loop+0x4eb/frame 0xfffffe0053fbbef0
fork_exit() at fork_exit+0xd1/frame 0xfffffe0053fbbf30
fork_trampoline() at fork_trampoline+0xe/frame 0xfffffe0053fbbf30
--- trap 0, rip = 0, rsp = 0, rbp = 0 ---
KDB: enter: panic
[ thread pid 12 tid 100031 ]
Stopped at kdb_enter+0x6e: movq $0,0x2133c87(%rip)
db> set $lines = 0
db> set $maxwidth = 0
db> show registers
cs 0x20
ds 0x3b
es 0x3b
fs 0x13
gs 0x1b
ss 0x28
rax 0x12
rcx 0xfffffe00033eee30
rdx 0xdffff7c000000000
rbx 0xffffffff826ba6e0 .str.26
rsp 0xfffffe0053fbb090
rbp 0xfffffe0053fbb0b0
rsi 0x1
rdi 0
r8 0
r9 0xffffffff
r10 0
r11 0x1
r12 0xfffffe005428a560
r13 0xfffffffffffffffd
r14 0xffffffff826ba6e0 .str.26
r15 0
rip 0xffffffff815bd40e kdb_enter+0x6e
rflags 0x46
kdb_enter+0x6e: movq $0,0x2133c87(%rip)
db> show proc
Process 12 (intr) at 0xfffffe00541de580:
state: NORMAL
uid: 0 gids: 0
parent: pid 0 at 0xffffffff836a9060
ABI: null
flag: 0x10000284 flag2: 0
reaper: 0xffffffff836a9060 reapsubtree: 12
sigparent: 20
vmspace: 0xffffffff836aa000
(map 0xffffffff836aa000)
(map.pmap 0xffffffff836aa0c0)
(pmap 0xffffffff836aa130)
threads: 22
100016 I [swi5: fast taskq]
100019 I [swi6: task queue]
100020 I [swi6: Giant taskq]
100031 Run CPU 1 [swi1: netisr 0]
100032 I [swi1: hpts]
100033 I [swi1: hpts]
100046 I [irq24: virtio_pci0]
100047 I [irq25: virtio_pci0]
100048 I [irq26: virtio_pci0]
100049 I [irq27: virtio_pci0]
100050 I [irq28: virtio_pci1]
100051 I [irq29: virtio_pci1]
100052 I [irq30: virtio_pci1]
100053 I [irq31: virtio_pci1]
100054 I [irq32: virtio_pci1]
100059 I [irq33: virtio_pci2]
100060 I [irq34: virtio_pci2]
100061 I [irq35: virtio_pci2]
100063 I [irq1: atkbd0]
100064 I [irq12: psm0]
100065 I [swi0: uart uart++]
100069 I [swi1: pf send]
db> ps
pid ppid pgrp uid state wmesg wchan cmd
881 781 781 0 R (threaded) syz-executor.0
100099 RunQ syz-executor.0
100160 RunQ syz-executor.0
100161 S uwait 0xfffffe0057a54480 syz-executor.0
876 1 876 0 Ss select 0xfffffe00571c5b40 rtsol
874 1 874 0 Ss select 0xfffffe005719bb40 rtsol
872 1 872 0 Ss select 0xfffffe00571c5ac0 rtsol
867 790 430 0 S kqread 0xfffffe006c99bc00 rtsol
790 784 430 0 S wait 0xfffffe0058e7f5a0 sh
784 430 430 0 S wait 0xfffffe006cd96000 sh
781 779 781 0 Rs syz-executor.0
779 777 777 0 S (threaded) syz-execprog
100112 S uwait 0xfffffe0058f37f00 syz-execprog
100114 S uwait 0xfffffe0058f38180 syz-execprog
100115 S kqread 0xfffffe006c99d600 syz-execprog
100116 S uwait 0xfffffe0057a55300 syz-execprog
100117 S uwait 0xfffffe0057a54b00 syz-execprog
100119 S uwait 0xfffffe0057a54d00 syz-execprog
100120 S uwait 0xfffffe0057a54e00 syz-execprog
100121 S uwait 0xfffffe0057a54f00 syz-execprog
100122 S wait 0xfffffe0058e805c0 syz-execprog
777 775 777 0 Ss pause 0xfffffe0058e80110 csh
775 688 775 0 Ss select 0xfffffe00571c5a40 sshd
754 1 754 0 Rs+ CPU 0 getty
753 1 753 0 Ss+ ttyin 0xfffffe0057ba58b0 getty
752 1 752 0 Ss+ ttyin 0xfffffe00571058b0 getty
751 1 751 0 Ss+ ttyin 0xfffffe0057105cb0 getty
750 1 750 0 Ss+ ttyin 0xfffffe0057ba5cb0 getty
749 1 749 0 Ss+ ttyin 0xfffffe0057ba60b0 getty
748 1 748 0 Ss+ ttyin 0xfffffe0057ba64b0 getty
747 1 747 0 Ss+ ttyin 0xfffffe0057ba68b0 getty
746 1 746 0 Ss+ ttyin 0xfffffe0057ba6cb0 getty
744 1 18 0 S+ piperd 0xfffffe0058bd83e8 logger
743 742 18 0 S+ nanslp 0xffffffff836d2841 sleep
742 1 18 0 S+ wait 0xfffffe0057b70ae0 sh
692 1 692 0 Ss nanslp 0xffffffff836d2840 cron
688 1 688 0 Ss select 0xfffffe0057a6dac0 sshd
501 1 501 0 Ss select 0xfffffe005719bcc0 syslogd
430 1 430 0 Ss wait 0xfffffe0057b725c0 devd
429 1 429 65 Ss select 0xfffffe005719bdc0 dhclient
344 1 344 0 Ss select 0xfffffe0057a6db40 dhclient
341 1 341 0 Ss select 0xfffffe00571a01c0 dhclient
17 0 0 0 DL vlruwt 0xfffffe00541e05c0 [vnlru]
16 0 0 0 DL syncer 0xffffffff837d4d20 [syncer]
15 0 0 0 DL (threaded) [bufdaemon]
100079 D psleep 0xffffffff837d3340 [bufdaemon]
100082 D - 0xffffffff82c0a140 [bufspacedaemon-0]
100095 D sdflush 0xfffffe0058b5f8e8 [/ worker]
9 0 0 0 DL psleep 0xffffffff8380ac00 [vmdaemon]
8 0 0 0 DL (threaded) [pagedaemon]
100077 D psleep 0xffffffff837feab8 [dom0]
100080 D launds 0xffffffff837feac4 [laundry: dom0]
100081 D umarcl 0xffffffff81d3da40 [uma]
7 0 0 0 DL - 0xffffffff83496e48 [rand_harvestq]
6 0 0 0 DL pftm 0xffffffff844683d0 [pf purge]
5 0 0 0 DL waiting 0xffffffff842ad1c0 [sctp_iterator]
4 0 0 0 DL (threaded) [cam]
100044 D - 0xffffffff83479340 [doneq0]
100045 D - 0xffffffff834792c0 [async]
100076 D - 0xffffffff83479140 [scanner]
14 0 0 0 DL seqstat 0xfffffe000795d488 [sequencer 00]
3 0 0 0 DL (threaded) [crypto]
100040 D crypto_ 0xffffffff837fa360 [crypto]
100041 D crypto_ 0xfffffe00542c4830 [crypto returns 0]
100042 D crypto_ 0xfffffe00542c4880 [crypto returns 1]
13 0 0 0 DL (threaded) [geom]
100035 D - 0xffffffff836a8640 [g_event]
100036 D - 0xffffffff836a8660 [g_up]
100037 D - 0xffffffff836a8680 [g_down]
2 0 0 0 WL (threaded) [clock]
100029 I [clock (0)]
100030 I [clock (1)]
12 0 0 0 RL (threaded) [intr]
100016 I [swi5: fast taskq]
100019 I [swi6: task queue]
100020 I [swi6: Giant taskq]
100031 Run CPU 1 [swi1: netisr 0]
100032 I [swi1: hpts]
100033 I [swi1: hpts]
100046 I [irq24: virtio_pci0]
100047 I [irq25: virtio_pci0]
100048 I [irq26: virtio_pci0]
100049 I [irq27: virtio_pci0]
100050 I [irq28: virtio_pci1]
100051 I [irq29: virtio_pci1]
100052 I [irq30: virtio_pci1]
100053 I [irq31: virtio_pci1]
100054 I [irq32: virtio_pci1]
100059 I [irq33: virtio_pci2]
100060 I [irq34: virtio_pci2]
100061 I [irq35: virtio_pci2]
100063 I [irq1: atkbd0]
100064 I [irq12: psm0]
100065 I [swi0: uart uart++]
100069 I [swi1: pf send]
11 0 0 0 RL (threaded) [idle]
100003 CanRun [idle: cpu0]
100004 CanRun [idle: cpu1]
1 0 1 0 SLs wait 0xfffffe00541df040 [init]
10 0 0 0 DL audit_w 0xffffffff837fada0 [audit]
0 0 0 0 DLs (threaded) [kernel]
100000 D swapin 0xffffffff836a9060 [swapper]
100005 D - 0xfffffe005408c000 [if_io_tqg_0]
100006 D - 0xfffffe005408be00 [if_io_tqg_1]
100007 D - 0xfffffe005408bd00 [if_config_tqg_0]
100008 D - 0xfffffe005408bc00 [softirq_0]
100009 D - 0xfffffe005408bb00 [softirq_1]
100010 D - 0xfffffe0007966500 [linuxkpi_irq_wq]
100011 D - 0xfffffe0007966400 [thread taskq]
100012 D - 0xfffffe0007966300 [inm_free taskq]
100013 D - 0xfffffe0007966200 [aiod_kick taskq]
100014 D - 0xfffffe0007966100 [deferred_unmount ta]
100015 D - 0xfffffe0007966000 [in6m_free taskq]
100017 D - 0xfffffe0007965d00 [kqueue_ctx taskq]
100018 D - 0xfffffe0007965c00 [pci_hp taskq]
100021 D - 0xfffffe0007965900 [linuxkpi_short_wq_0]
100022 D - 0xfffffe0007965900 [linuxkpi_short_wq_1]
100023 D - 0xfffffe0007965900 [linuxkpi_short_wq_2]
100024 D - 0xfffffe0007965900 [linuxkpi_short_wq_3]
100025 D - 0xfffffe0007965800 [linuxkpi_long_wq_0]
100026 D - 0xfffffe0007965800 [linuxkpi_long_wq_1]
100027 D - 0xfffffe0007965800 [linuxkpi_long_wq_2]
100028 D - 0xfffffe0007965800 [linuxkpi_long_wq_3]
100034 D - 0xfffffe0007965700 [firmware taskq]
100038 D - 0xfffffe0007965500 [crypto_0]
100039 D - 0xfffffe0007965500 [crypto_1]
100055 D - 0xfffffe00571cc700 [vtnet0 rxq 0]
100056 D - 0xfffffe00571cc600 [vtnet0 txq 0]
100057 D - 0xfffffe00571cc500 [vtnet0 rxq 1]
100058 D - 0xfffffe00571cc400 [vtnet0 txq 1]
100062 D vtbslp 0xfffffe00571a0380 [virtio_balloon]
100066 D - 0xffffffff826bf621 [deadlkres]
100070 D - 0xfffffe0057ba1200 [acpi_task_0]
100071 D - 0xfffffe0057ba1200 [acpi_task_1]
100072 D - 0xfffffe0057ba1200 [acpi_task_2]
100073 D - 0xfffffe0007966d00 [mca taskq]
100075 D - 0xfffffe0007965300 [CAM taskq]
db> show all locks
Process 881 (syz-executor.0) thread 0xfffffe006d166000 (100160)
exclusive rw tcpinp (tcpinp) r = 0 (0xfffffe006cd54020) locked @ /syzkaller/managers/main/kernel/sys/netinet/tcp_usrreq.c:560
Process 754 (getty) thread 0xfffffe0058e5c740 (100106)
exclusive sleep mutex ttymtx (ttymtx) r = 0 (0xfffffe0057106c08) locked @ /syzkaller/managers/main/kernel/sys/kern/tty.c:218
Process 12 (intr) thread 0xfffffe005428a560 (100031)
shared rw tcpinp (tcpinp) r = 0 (0xfffffe006d17baa0) locked @ /syzkaller/managers/main/kernel/sys/netinet/in_pcb.c:1472
db> show malloc
Type InUse MemUse Requests
pf_hash 5 11524K 5
tcp_hpts 7 4801K 7
devbuf 4218 4324K 4243
sysctloid 34805 2051K 34876
vtbuf 24 1968K 46
kobj 326 1304K 488
newblk 658 1189K 726
vfscache 3 1025K 3
pcb 27 669K 73
inodedep 84 544K 107
ufs_quota 1 512K 1
vfs_hash 1 512K 1
callout 2 512K 2
intr 4 472K 4
subproc 115 218K 949
acpica 1674 184K 57877
tidhash 3 141K 3
vmem 3 134K 4
pagedep 17 132K 50
tfo_ccache 1 128K 1
IP reass 1 128K 1
linker 324 127K 353
vnet_data 1 112K 1
DEVFS1 106 106K 117
sem 4 106K 4
bus 988 81K 5135
mtx_pool 2 72K 2
NFSD srvcache 3 68K 3
syncache 1 68K 1
acpitask 1 64K 1
ddb_capture 1 64K 1
module 508 64K 508
temp 24 53K 1727
filedesc 5 37K 75
umtx 286 36K 286
kdtrace 177 36K 1044
hostcache 1 32K 1
shm 1 32K 1
DEVFS3 125 32K 135
msg 4 30K 4
kbdmux 6 28K 6
gtaskqueue 18 26K 18
DEVFS_RULE 56 20K 56
BPF 11 18K 11
ufs_mount 4 17K 5
proc 3 17K 3
tty 16 16K 16
ithread 97 16K 97
bus-sc 34 15K 1648
ifaddr 39 13K 41
eventhandler 157 13K 157
KTRACE 100 13K 100
dirrem 46 12K 57
kenv 95 12K 95
routetbl 62 11K 222
rman 88 11K 431
GEOM 61 11K 481
CAM queue 5 11K 1528
rpc 4 9K 4
UART 12 9K 12
devstat 4 9K 4
ksem 1 8K 1
pfs_vncache 1 8K 1
bmsafemap 1 8K 73
shmfd 1 8K 1
kqueue 52 8K 888
audit_evclass 237 8K 297
taskqueue 63 7K 63
ifnet 4 7K 4
sglist 5 7K 5
CAM DEV 3 6K 510
cred 24 6K 235
lltable 19 6K 19
ether_multi 68 6K 78
pfs_nodes 20 5K 20
ufs_dirhash 24 5K 24
plimit 18 5K 329
in6_multi 35 5K 35
UMA 267 5K 267
vt 11 5K 11
memdesc 1 4K 1
MCA 32 4K 32
evdev 4 4K 4
diradd 31 4K 71
freefile 29 4K 38
pf_ifnet 7 4K 10
acpisem 28 4K 28
hhook 15 4K 17
session 24 3K 35
pwddesc 48 3K 882
proc-args 77 3K 1890
terminal 11 3K 11
clone 9 3K 9
uidinfo 3 3K 8
local_apic 1 2K 1
io_apic 1 2K 1
fpukern_ctx 2 2K 2
ipsec-saq 2 2K 2
selfd 32 2K 10826
Unitno 27 2K 43
CAM XPT 22 2K 543
lockf 15 2K 22
msi 12 2K 12
select 11 2K 35
mkdir 10 2K 80
ipsecpolicy 2 2K 2
CC Mem 5 2K 67
acpidev 20 2K 20
NFSD session 1 1K 1
softdep 1 1K 1
indirdep 4 1K 4
sahead 1 1K 1
secasvar 1 1K 1
vnodemarker 2 1K 8
ip6ndp 6 1K 7
sctp_ifa 7 1K 8
newdirblk 7 1K 40
CAM periph 4 1K 271
ipsec 3 1K 3
in_multi 3 1K 5
nhops 6 1K 6
pfil 6 1K 6
toponodes 6 1K 6
isadev 6 1K 6
mount 16 1K 89
pci_link 10 1K 10
crypto 4 1K 4
encap_export_host 12 1K 12
procdesc 4 1K 10
cdev 2 1K 2
osd 10 1K 80
inpcbpolicy 14 1K 225
sctp_ifn 3 1K 8
mld 3 1K 3
igmp 3 1K 3
chacha20random 1 1K 1
biobuf 1 1K 1
tun 4 1K 4
DEVFSP 5 1K 10
NFSD lckfile 1 1K 1
NFSD V4client 1 1K 1
DEVFS 9 1K 10
vnodes 1 1K 1
CAM SIM 2 1K 2
feeder 7 1K 7
tcpfunc 3 1K 3
loginclass 3 1K 7
prison 6 1K 6
lkpikmalloc 5 1K 6
aesni_data 2 1K 2
soname 5 1K 3492
cryptodev 2 1K 49
nexusdev 8 1K 8
apmdev 1 1K 1
atkbddev 2 1K 2
freefrag 1 1K 2
netlink 1 1K 1
CAM dev queue 2 1K 2
CAM I/O Scheduler 1 1K 1
CAM path 4 1K 1034
pmchooks 1 1K 1
filecaps 4 1K 78
sctp_vrf 1 1K 1
vnet 1 1K 1
entropy 2 1K 39
pmc 1 1K 1
acpiintr 1 1K 1
cpus 2 1K 2
freework 1 1K 55
vnet_data_free 1 1K 1
Per-cpu 1 1K 1
p1003.1b 1 1K 1
mqdata 0 0K 0
ipcomp 0 0K 0
esp 0 0K 0
ah 0 0K 0
pf_table 0 0K 0
pf_rule 0 0K 0
pf_altq 0 0K 0
pf_osfp 0 0K 0
pf_krule_item 0 0K 0
pf_temp 0 0K 0
sctp_mcore 0 0K 0
sctp_socko 0 0K 0
sctp_iter 0 0K 6
sctp_mvrf 0 0K 0
sctp_timw 0 0K 0
sctp_cpal 0 0K 0
sctp_cmsg 0 0K 0
sctp_stre 0 0K 0
sctp_athi 0 0K 0
sctp_athm 0 0K 0
sctp_atky 0 0K 0
sctp_atcl 0 0K 0
sctp_a_it 0 0K 6
sctp_aadr 0 0K 0
sctp_stro 0 0K 0
sctp_stri 0 0K 0
sctp_map 0 0K 0
filemon 0 0K 0
tcp_do 0 0K 0
tcp_fsb 0 0K 0
savedino 0 0K 17
sentinel 0 0K 0
jfsync 0 0K 0
jtrunc 0 0K 0
sbdep 0 0K 2
jsegdep 0 0K 0
jseg 0 0K 0
jfreefrag 0 0K 0
jfreeblk 0 0K 0
jnewblk 0 0K 0
jmvref 0 0K 0
jremref 0 0K 0
jaddref 0 0K 0
freedep 0 0K 0
freeblks 0 0K 54
ip6opt 0 0K 3
ip6_msource 0 0K 0
ip6_moptions 0 0K 0
in6_mfilter 0 0K 0
frag6 0 0K 0
tcplog 0 0K 0
tcp_hwpace 0 0K 0
BACKLIGHT 0 0K 0
LRO 0 0K 0
ip_msource 0 0K 0
ip_moptions 0 0K 0
in_mfilter 0 0K 0
ipid 0 0K 0
80211scan 0 0K 0
80211ratectl 0 0K 0
80211power 0 0K 0
80211nodeie 0 0K 0
80211node 0 0K 0
80211mesh_gt 0 0K 0
80211mesh_rt 0 0K 0
80211perr 0 0K 0
80211prep 0 0K 0
80211preq 0 0K 0
80211dfs 0 0K 0
80211crypto 0 0K 0
80211vap 0 0K 0
iflib 0 0K 0
vlan 0 0K 0
gif 0 0K 0
ifdescr 0 0K 0
zlib 0 0K 0
fadvise 0 0K 0
VN POLL 0 0K 0
ath_hal 0 0K 0
statfs 0 0K 229
namei_tracker 0 0K 0
export_host 0 0K 0
cl_savebuf 0 0K 2
athdev 0 0K 0
ata_pci 0 0K 0
ata_dma 0 0K 0
ata_generic 0 0K 0
pvscsi 0 0K 0
scsi_da 0 0K 69
ata_da 0 0K 0
scsi_ch 0 0K 0
scsi_cd 0 0K 0
AHCI driver 0 0K 0
USBdev 0 0K 0
USB 0 0K 0
agp 0 0K 0
nvme_da 0 0K 0
acpipwr 0 0K 0
acpi_perf 0 0K 0
twsbuf 0 0K 0
tcp_log_dev 0 0K 0
aio 0 0K 0
lio 0 0K 0
iov 0 0K 14036
ioctlops 0 0K 91
eventfd 0 0K 0
Witness 0 0K 0
stack 0 0K 0
mrsasbuf 0 0K 0
mpt_user 0 0K 0
mps_user 0 0K 0
MPSSAS 0 0K 0
mps 0 0K 0
sbuf 0 0K 288
mpr_user 0 0K 0
firmware 0 0K 0
compressor 0 0K 0
MPRSAS 0 0K 0
SWAP 0 0K 0
mpr 0 0K 0
mfibuf 0 0K 0
sysctltmp 0 0K 658
sysctl 0 0K 3
md_sectors 0 0K 0
ekcd 0 0K 0
dumper 0 0K 0
sendfile 0 0K 0
rctl 0 0K 0
md_disk 0 0K 0
malodev 0 0K 0
LED 0 0K 0
ix_sriov 0 0K 0
cache 0 0K 0
aacraidcam 0 0K 0
kcovinfo 0 0K 0
mbuf_jumbo_page 4096 8320 1078 14317 0 254 38494208 0
mbuf 256 8588 1074 17462 0 254 2473472 0
BUF TRIE 144 180 11636 471 0 62 1701504 0
malloc-384 384 4293 27 4329 0 30 1658880 0
malloc-128 128 11413 181 11678 0 126 1484032 0
malloc-4096 4096 328 2 565 0 2 1351680 0
UMA Slabs 0 112 10558 20 10558 0 126 1184736 0
mbuf_cluster 2048 508 0 508 0 254 1040384 0
vmem btag 56 15316 59 15316 0 254 861000 0
FFS inode 1160 505 27 543 0 8 617120 0
RADIX NODE 144 3540 207 27231 0 62 539568 0
pbuf 2624 0 202 0 0 2 530048 0
socket 960 30 478 1431 0 254 487680 0
lkpimm 168 1 2327 1 0 62 391104 0
lkpicurr 168 2 2326 2 0 62 391104 0
VM OBJECT 264 1083 57 15859 0 30 300960 0
VNODE 448 537 66 577 0 30 270144 0
256 Bucket 2048 115 15 955 0 8 266240 0
malloc-65536 65536 4 0 4 0 1 262144 0
malloc-65536 65536 2 2 58 0 1 262144 0
malloc-65536 65536 2 2 10 0 1 262144 0
malloc-4096 4096 60 4 1434 0 2 262144 0
malloc-64 64 3789 306 3790 0 254 262080 0
THREAD 1824 128 15 161 0 8 260832 0
malloc-256 256 869 61 1146 0 62 238080 0
malloc-16 16 14372 378 14433 0 254 236000 0
DEVCTL 1024 4 216 130 0 0 225280 0
malloc-128 128 1327 192 27355 0 126 194432 0
UMA Zones 768 239 0 239 0 16 183552 0
malloc-32 32 5270 400 5280 0 254 181440 0
FFS2 dinode 256 505 65 543 0 62 145920 0
S VFS Cache 104 982 305 1050 0 126 133848 0
MAP ENTRY 96 1176 210 44959 0 126 133056 0
malloc-65536 65536 0 2 126 0 1 131072 0
malloc-32768 32768 2 2 122 0 1 131072 0
malloc-1024 1024 117 11 275 0 16 131072 0
unpcb 256 14 496 1186 0 254 130560 0
mbuf_packet 256 0 508 112 0 254 130048 0
FPU_save_area 832 130 14 180 0 16 119808 0
ksiginfo 112 41 1003 64 0 126 116928 0
malloc-128 128 686 213 1391 0 126 115072 0
malloc-128 128 638 137 3973 0 126 99200 0
malloc-16384 16384 4 2 49 0 1 98304 0
malloc-2048 2048 4 44 1036 0 8 98304 0
PROC 1376 47 19 881 0 8 90816 0
UMA Kegs 384 226 7 226 0 30 89472 0
128 Bucket 1024 43 40 247 0 16 84992 0
malloc-64 64 763 560 2395 0 254 84672 0
filedesc0 1072 48 22 882 0 8 75040 0
malloc-8192 8192 7 2 110 0 1 73728 0
g_bio 408 0 180 4512 0 30 73440 0
64 Bucket 512 60 76 1099 0 30 69632 0
malloc-64 64 556 515 1708 0 254 68544 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-32768 32768 2 0 2 0 1 65536 0
malloc-16384 16384 4 0 4 0 1 65536 0
malloc-1024 1024 24 40 556 0 16 65536 0
malloc-256 256 179 76 1191 0 62 65280 0
malloc-256 256 166 89 554 0 62 65280 0
malloc-8192 8192 7 0 7 0 1 57344 0
malloc-4096 4096 12 2 23 0 2 57344 0
32 Bucket 256 57 138 429 0 62 49920 0
DIRHASH 1024 35 13 35 0 16 49152 0
NAMEI 1024 0 48 12857 0 16 49152 0
malloc-16384 16384 1 2 161 0 1 49152 0
malloc-2048 2048 11 13 25 0 8 49152 0
syncache 168 0 264 5 0 254 44352 0
tcp_inpcb 1304 5 28 67 0 8 43032 0
VMSPACE 520 31 44 866 0 16 39000 0
udp_inpcb 424 6 84 152 0 30 38160 0
pcpu-8 8 4390 218 4450 0 254 36864 0
malloc-64 64 76 491 14818 0 254 36288 0
malloc-64 64 32 535 52 0 254 36288 0
malloc-64 64 226 341 11876 0 254 36288 0
malloc-128 128 36 243 171 0 126 35712 0
malloc-128 128 34 245 45 0 126 35712 0
malloc-128 128 11 268 11 0 126 35712 0
routing nhops 256 14 121 21 0 62 34560 0
ttyoutq 256 72 63 160 0 62 34560 0
malloc-384 384 63 27 63 0 30 34560 0
malloc-256 256 46 89 566 0 62 34560 0
malloc-256 256 7 128 10 0 62 34560 0
malloc-256 256 4 131 58 0 62 34560 0
malloc-256 256 53 82 724 0 62 34560 0
malloc-256 256 5 130 5 0 62 34560 0
malloc-32768 32768 1 0 1 0 1 32768 0
malloc-8192 8192 4 0 4 0 1 32768 0
malloc-2048 2048 7 9 7 0 8 32768 0
malloc-2048 2048 1 15 31 0 8 32768 0
malloc-2048 2048 8 8 249 0 8 32768 0
malloc-1024 1024 3 29 43 0 16 32768 0
malloc-1024 1024 20 12 958 0 16 32768 0
malloc-1024 1024 4 28 4 0 16 32768 0
malloc-1024 1024 4 28 4 0 16 32768 0
malloc-512 512 0 64 118 0 30 32768 0
malloc-512 512 11 53 17 0 30 32768 0
malloc-512 512 3 61 4 0 30 32768 0
malloc-512 512 0 64 11 0 30 32768 0
malloc-512 512 2 62 51 0 30 32768 0
pcpu-64 64 486 26 486 0 254 32768 0
ttyinq 160 135 65 300 0 62 32000 0
cpuset 104 7 272 7 0 126 29016 0
sctp_laddr 48 0 588 6 0 254 28224 0
malloc-32 32 274 608 495 0 254 28224 0
malloc-32 32 158 724 1438 0 254 28224 0
4 Bucket 48 4 584 5 0 254 28224 0
da_ccb 544 0 49 1248 0 16 26656 0
TURNSTILE 136 144 45 144 0 62 25704 0
ripcb 392 3 60 6 0 30 24696 0
malloc-8192 8192 3 0 3 0 1 24576 0
malloc-8192 8192 3 0 3 0 1 24576 0
malloc-4096 4096 6 0 6 0 2 24576 0
PGRP 88 24 252 35 0 126 24288 0
ertt_txseginfo 40 0 606 247 0 254 24240 0
rl_entry 40 35 571 35 0 254 24240 0
PWD 40 12 594 132 0 254 24240 0
rtentry 168 17 127 21 0 62 24192 0
pipe 728 11 22 330 0 16 24024 0
Files 80 104 196 7152 0 126 24000 0
8 Bucket 80 44 256 305 0 126 24000 0
malloc-384 384 17 43 42 0 30 23040 0
malloc-384 384 1 59 343 0 30 23040 0
SLEEPQUEUE 88 144 112 144 0 126 22528 0
clpbuf 2624 0 8 21 0 4 20992 0
hostcache 64 1 314 1 0 254 20160 0
tcp_inpcb ports 32 3 627 61 0 254 20160 0
udp_inpcb ports 32 3 627 40 0 254 20160 0
ertt 72 5 275 67 0 126 20160 0
malloc-32 32 24 606 263 0 254 20160 0
malloc-32 32 64 566 125 0 254 20160 0
malloc-32 32 111 519 3063 0 254 20160 0
malloc-32 32 4 626 1037 0 254 20160 0
16 Bucket 144 45 95 258 0 62 20160 0
2 Bucket 32 45 585 294 0 254 20160 0
KNOTE 160 11 114 211 0 62 20000 0
malloc-128 128 81 74 423 0 126 19840 0
epoch_record pcpu 256 4 60 4 0 62 16384 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-8192 8192 2 0 2 0 1 16384 0
malloc-4096 4096 1 3 234 0 2 16384 0
malloc-4096 4096 3 1 4 0 2 16384 0
malloc-2048 2048 1 7 13 0 8 16384 0
malloc-1024 1024 0 16 1 0 16 16384 0
malloc-512 512 1 31 2 0 30 16384 0
malloc-512 512 3 29 3 0 30 16384 0
SMR CPU 32 7 504 7 0 254 16352 0
malloc-16 16 493 507 3478 0 254 16000 0
kenv 258 16 44 1037 0 30 15480 0
mqnode 416 3 33 3 0 30 14976 0
vmem 1856 1 7 1 0 8 14848 0
SMR SHARED 24 7 504 7 0 254 12264 0
malloc-32 32 7 371 7 0 254 12096 0
malloc-16 16 42 708 1459 0 254 12000 0
malloc-16 16 15 735 17 0 254 12000 0
malloc-16 16 23 727 74 0 254 12000 0
malloc-16 16 58 692 26707 0 254 12000 0
malloc-384 384 0 30 1 0 30 11520 0
malloc-384 384 1 29 1 0 30 11520 0
Mountpoints 2816 2 2 2 0 4 11264 0
malloc-8192 8192 0 1 26 0 1 8192 0
malloc-16 16 0 500 1 0 254 8000 0
malloc-16 16 4 496 4 0 254 8000 0
pcpu-16 16 4 252 4 0 254 4096 0
vtnet_tx_hdr 24 0 167 2107 0 254 4008 0
UMA Slabs 1 176 8 14 8 0 62 3872 0
KMAP ENTRY 96 12 27 14 0 0 3744 0
FFS1 dinode 128 0 0 0 0 126 0 0
ada_ccb 272 0 0 0 0 30 0 0
swblk 136 0 0 0 0 62 0 0
swpctrie 144 0 0 0 0 62 0 0
pf state scrubs 40 0 0 0 0 254 0 0
pf frag entries 40 0 0 0 0 254 0 0
pf frags 248 0 0 0 0 62 0 0
pf table entries 160 0 0 0 0 254 0 0
pf table entry counters 64 0 0 0 0 254 0 0
pf source nodes 152 0 0 0 0 254 0 0
pf state keys 88 0 0 0 0 126 0 0
pf states 344 0 0 0 0 254 0 0
pf tags 104 0 0 0 0 126 0 0
pf mtags 184 0 0 0 0 62 0 0
tcp_rack_pcb 1024 0 0 0 0 16 0 0
tcp_rack_map 128 0 0 0 0 126 0 0
tcp_bbr_pcb 832 0 0 0 0 16 0 0
tcp_bbr_map 128 0 0 0 0 126 0 0
tfo_ccache_entries 80 0 0 0 0 126 0 0
tfo 4 0 0 0 0 254 0 0
sackhole 32 0 0 0 0 254 0 0
ipq 56 0 0 0 0 254 0 0
tcp_log_id_node 120 0 0 0 0 126 0 0
tcp_log_id_bucket 176 0 0 0 0 62 0 0
tcp_log 416 0 0 0 0 254 0 0
tcpreass 48 0 0 0 0 254 0 0
sctp_asconf_ack 48 0 0 0 0 254 0 0
sctp_asconf 40 0 0 0 0 254 0 0
sctp_stream_msg_out 112 0 0 0 0 254 0 0
sctp_readq 152 0 0 0 0 254 0 0
sctp_chunk 152 0 0 0 0 254 0 0
sctp_raddr 736 0 0 0 0 254 0 0
sctp_asoc 2264 0 0 0 0 254 0 0
sctp_ep 1176 0 0 0 0 254 0 0
ripcb ports 32 0 0 0 0 254 0 0
udplite_inpcb ports 32 0 0 0 0 254 0 0
udplite_inpcb 424 0 0 0 0 30 0 0
IPsec SA lft_c 16 0 0 0 0 254 0 0
netlink 2048 0 0 0 0 8 0 0
itimer 352 0 0 0 0 30 0 0
AIOLIO 272 0 0 0 0 30 0 0
AIOCB 552 0 0 0 0 16 0 0
AIO 208 0 0 0 0 62 0 0
mqnotifier 216 0 0 0 0 62 0 0
mvdata 64 0 0 0 0 254 0 0
mqueue 248 0 0 0 0 62 0 0
NCLNODE 608 0 0 0 0 16 0 0
TMPFS node 232 0 0 0 0 62 0 0
LTS VFS Cache 360 0 0 0 0 30 0 0
L VFS Cache 320 0 0 0 0 30 0 0
STS VFS Cache 144 0 0 0 0 62 0 0
cryptop 280 0 0 0 0 30 0 0
linux_dma_object 32 0 0 0 0 254 0 0
linux_dma_pctrie 144 0 0 0 0 62 0 0
IOMMU_MAP_ENTRY 104 0 0 0 0 126 0 0
mbuf_jumbo_16k 16384 0 0 0 0 254 0 0
mbuf_jumbo_9k 9216 0 0 0 0 254 0 0
audit_record 1280 0 0 0 0 8 0 0
domainset 40 0 0 0 0 254 0 0
MAC labels 40 0 0 0 0 254 0 0
vnpbuf 2624 0 0 0 0 16 0 0
nfspbuf 2624 0 0 0 0 4 0 0
swwbuf 2624 0 0 0 0 2 0 0
swrbuf 2624 0 0 0 0 4 0 0
umtx_shm 88 0 0 0 0 126 0 0
umtx pi 96

---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

syzbot

unread,
Jul 10, 2023, 6:51:47 PM7/10/23
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 8ab2da68283b Remove GCC 4.2 include dirs
git tree: freebsd-src
console output: https://syzkaller.appspot.com/x/log.txt?x=17667ad4a80000
dashboard link: https://syzkaller.appspot.com/bug?extid=e7d2e451f89fb444319b
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1240fc5ca80000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=13d6f364a80000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+e7d2e4...@syzkaller.appspotmail.com

Fatal trap 12: page fault while in kernel mode
cpuid = 0; apic id = 00
fault virtual address = 0xb8
fault code = supervisor read data, page not present
instruction pointer = 0x20:0xffffffff81961d39
stack pointer = 0x28:0xfffffe0053fbb760
executing program
frame pointer = 0x28:0xfffffe0053fbba20
code segment = base 0x0, limit 0xfffff, type 0x1b
= DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags = interrupt enabled, resume, IOPL = 0
current process = 12 (swi1: netisr 0)
rdi: 00000000000000b8 rsi: 0000000000000000 rdx: ffffffff82771e80
rcx: fffffe00033eee30 r8: 0000000000000000 r9: ffffffff82767c20
rax: fffffe00033eee30 rbx: fffffe006cd8a088 rbp: fffffe0053fbba20
r10: 00000000000005c0 r11: 0000000000000002 r12: fffffe006d128300
r13: fffffe006d128347 r14: 0000000000000000 r15: fffffe006cd8a000
trap number = 12
panic: page fault
cpuid = 0
time = 1689028549
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0xc6/frame 0xfffffe0053fbaf50
kdb_backtrace() at kdb_backtrace+0xd0/frame 0xfffffe0053fbb0b0
vpanic() at vpanic+0x24b/frame 0xfffffe0053fbb190
panic() at panic+0xb5/frame 0xfffffe0053fbb250
trap_fatal() at trap_fatal+0x7ee/frame 0xfffffe0053fbb370
trap_pfault() at trap_pfault+0x17b/frame 0xfffffe0053fbb4b0
trap() at trap+0x5f3/frame 0xfffffe0053fbb690
calltrap() at calltrap+0x8/frame 0xfffffe0053fbb690
--- trap 0xc, rip = 0xffffffff81961d39, rsp = 0xfffffe0053fbb760, rbp = 0xfffffe0053fbba20 ---
tcp_input_with_port() at tcp_input_with_port+0x1109/frame 0xfffffe0053fbba20
tcp6_input_with_port() at tcp6_input_with_port+0xeb/frame 0xfffffe0053fbba60
tcp6_input() at tcp6_input+0x26/frame 0xfffffe0053fbba90
ip6_input() at ip6_input+0x2297/frame 0xfffffe0053fbbcf0
swi_net() at swi_net+0x2f3/frame 0xfffffe0053fbbd90
ithread_loop() at ithread_loop+0x4eb/frame 0xfffffe0053fbbef0
fork_exit() at fork_exit+0xc9/frame 0xfffffe0053fbbf30
fork_trampoline() at fork_trampoline+0xe/frame 0xfffffe0053fbbf30
--- trap 0, rip = 0, rsp = 0, rbp = 0 ---
KDB: enter: panic
[ thread pid 12 tid 100031 ]
Stopped at kdb_enter+0x6e: movq $0,0x2133517(%rip)
db>
db> set $lines = 0
db> set $maxwidth = 0
db> show registers
cs 0x20
ds 0x3b
es 0x3b
fs 0x13
gs 0x1b
ss 0x28
rax 0x12
rcx 0xfffffe00033eee30
rdx 0xdffff7c000000000
rbx 0xffffffff826bbb80 .str.28
rsp 0xfffffe0053fbb090
rbp 0xfffffe0053fbb0b0
rsi 0x1
rdi 0
r8 0
r9 0xffffffff
r10 0
r11 0x1
r12 0
r13 0xfffffe00542c2560
r14 0xffffffff826bbb80 .str.28
r15 0
rip 0xffffffff815beb7e kdb_enter+0x6e
rflags 0x46
kdb_enter+0x6e: movq $0,0x2133517(%rip)
db> show proc
Process 12 (intr) at 0xfffffe00541fa580:
state: NORMAL
uid: 0 gids: 0
parent: pid 0 at 0xffffffff836aa060
ABI: null
flag: 0x10000284 flag2: 0
reaper: 0xffffffff836aa060 reapsubtree: 12
sigparent: 20
vmspace: 0xffffffff836ab000
(map 0xffffffff836ab000)
(map.pmap 0xffffffff836ab0c0)
(pmap 0xffffffff836ab130)
4939 780 774 0 R (threaded) syz-executor4164038
100426 RunQ syz-executor4164038
105096 S connec 0xfffffe0058cde85a syz-executor4164038
4938 777 774 0 R (threaded) syz-executor4164038
100763 RunQ syz-executor4164038
105094 S connec 0xfffffe0058cd685a syz-executor4164038
4937 778 774 0 R (threaded) syz-executor4164038
101338 RunQ syz-executor4164038
105095 S connec 0xfffffe0058cd5c1a syz-executor4164038
4935 781 774 0 R (threaded) syz-executor4164038
100103 RunQ syz-executor4164038
105092 RunQ syz-executor4164038
781 776 774 0 R syz-executor4164038
780 776 774 0 R syz-executor4164038
778 776 774 0 R syz-executor4164038
777 776 774 0 R syz-executor4164038
776 774 774 0 S nanslp 0xffffffff836d3841 syz-executor4164038
774 772 774 0 Ss pause 0xfffffe0058ecdbb0 csh
772 682 772 0 Ss select 0xfffffe006c9ca5c0 sshd
748 1 748 0 Ss+ ttyin 0xfffffe00576728b0 getty
747 1 747 0 Ss+ ttyin 0xfffffe0057687cb0 getty
746 1 746 0 Ss+ ttyin 0xfffffe00589e08b0 getty
745 1 745 0 Ss+ ttyin 0xfffffe00589e10b0 getty
744 1 744 0 Ss+ ttyin 0xfffffe00589e18b0 getty
743 1 743 0 Ss+ ttyin 0xfffffe005433e0b0 getty
742 1 742 0 Ss+ ttyin 0xfffffe005433e8b0 getty
741 1 741 0 Ss+ ttyin 0xfffffe005433f0b0 getty
740 1 740 0 Ss+ ttyin 0xfffffe005433f8b0 getty
686 1 686 0 Ss nanslp 0xffffffff836d3840 cron
682 1 682 0 Ss select 0xfffffe006c9cb040 sshd
495 1 495 0 Ds getbuf 0xfffffe0007e36ea4 syslogd
424 1 424 0 Ss select 0xfffffe006c9cb2c0 devd
423 1 423 65 Ss select 0xfffffe006cc25dc0 dhclient
338 1 338 0 Ss select 0xfffffe006c9cb1c0 dhclient
335 1 335 0 Ss select 0xfffffe006c9cb840 dhclient
17 0 0 0 DL vlruwt 0xfffffe00541fc5c0 [vnlru]
16 0 0 0 DL syncer 0xffffffff837d5d20 [syncer]
15 0 0 0 DL (threaded) [bufdaemon]
100079 D psleep 0xffffffff837d4340 [bufdaemon]
100082 D - 0xffffffff82c0a140 [bufspacedaemon-0]
100094 D sdflush 0xfffffe00085f98e8 [/ worker]
9 0 0 0 DL psleep 0xffffffff8380bc00 [vmdaemon]
8 0 0 0 DL (threaded) [pagedaemon]
100077 D psleep 0xffffffff837ffab8 [dom0]
100080 D launds 0xffffffff837ffac4 [laundry: dom0]
100081 D umarcl 0xffffffff81d3e340 [uma]
7 0 0 0 DL - 0xffffffff83497e48 [rand_harvestq]
6 0 0 0 DL pftm 0xffffffff844713d0 [pf purge]
5 0 0 0 DL waiting 0xffffffff8425c1c0 [sctp_iterator]
4 0 0 0 RL (threaded) [cam]
100044 Run CPU 1 [doneq0]
100045 D - 0xffffffff8347a2c0 [async]
100076 D - 0xffffffff8347a140 [scanner]
14 0 0 0 DL seqstat 0xfffffe00085fb888 [sequencer 00]
3 0 0 0 DL (threaded) [crypto]
100040 D crypto_ 0xffffffff837fb360 [crypto]
100041 D crypto_ 0xfffffe005436f030 [crypto returns 0]
100042 D crypto_ 0xfffffe005436f080 [crypto returns 1]
13 0 0 0 DL (threaded) [geom]
100035 D - 0xffffffff836a9640 [g_event]
100036 D - 0xffffffff836a9660 [g_up]
100037 D - 0xffffffff836a9680 [g_down]
1 0 1 0 SLs wait 0xfffffe00541fb040 [init]
10 0 0 0 DL audit_w 0xffffffff837fbda0 [audit]
0 0 0 0 DLs (threaded) [kernel]
100000 D swapin 0xffffffff836aa060 [swapper]
100005 D - 0xfffffe00542a8100 [if_io_tqg_0]
100006 D - 0xfffffe00542a8000 [if_io_tqg_1]
100007 D - 0xfffffe00542a7e00 [if_config_tqg_0]
100008 D - 0xfffffe00542a7d00 [softirq_0]
100009 D - 0xfffffe00542a7c00 [softirq_1]
100010 D - 0xfffffe000799f000 [linuxkpi_irq_wq]
100011 D - 0xfffffe00085ffe00 [thread taskq]
100012 D - 0xfffffe00085ffd00 [inm_free taskq]
100013 D - 0xfffffe00085ffc00 [aiod_kick taskq]
100014 D - 0xfffffe00085ffb00 [deferred_unmount ta]
100015 D - 0xfffffe00085ffa00 [in6m_free taskq]
100017 D - 0xfffffe00085ff800 [kqueue_ctx taskq]
100018 D - 0xfffffe00085ff700 [pci_hp taskq]
100021 D - 0xfffffe00085ff400 [linuxkpi_short_wq_0]
100022 D - 0xfffffe00085ff400 [linuxkpi_short_wq_1]
100023 D - 0xfffffe00085ff400 [linuxkpi_short_wq_2]
100024 D - 0xfffffe00085ff400 [linuxkpi_short_wq_3]
100025 D - 0xfffffe00085ff300 [linuxkpi_long_wq_0]
100026 D - 0xfffffe00085ff300 [linuxkpi_long_wq_1]
100027 D - 0xfffffe00085ff300 [linuxkpi_long_wq_2]
100028 D - 0xfffffe00085ff300 [linuxkpi_long_wq_3]
100034 D - 0xfffffe00085ff200 [firmware taskq]
100038 D - 0xfffffe00085fe700 [crypto_0]
100039 D - 0xfffffe00085fe700 [crypto_1]
100055 D - 0xfffffe00085fde00 [vtnet0 rxq 0]
100056 D - 0xfffffe00085fdd00 [vtnet0 txq 0]
100057 D - 0xfffffe00085fdc00 [vtnet0 rxq 1]
100058 D - 0xfffffe00085fdb00 [vtnet0 txq 1]
100062 D vtbslp 0xfffffe0057176080 [virtio_balloon]
100066 D - 0xffffffff826c0b20 [deadlkres]
100070 D - 0xfffffe00085fe400 [acpi_task_0]
100071 D - 0xfffffe00085fe400 [acpi_task_1]
100072 D - 0xfffffe00085fe400 [acpi_task_2]
100073 D - 0xfffffe000799f100 [mca taskq]
100075 D - 0xfffffe00085fe000 [CAM taskq]
db> show all locks
Process 4935 (syz-executor4164038) thread 0xfffffe006d185560 (105092)
exclusive rw tcpinp (tcpinp) r = 0 (0xfffffe006d17e020) locked @ /syzkaller/managers/main/kernel/sys/netinet/tcp_usrreq.c:560
Process 495 (syslogd) thread 0xfffffe0058ead720 (100098)
exclusive lockmgr ufs (ufs) r = 0 (0xfffffe006cd0c070) locked @ /syzkaller/managers/main/kernel/sys/kern/vfs_syscalls.c:3551
Process 12 (intr) thread 0xfffffe00542c2560 (100031)
shared rw tcpinp (tcpinp) r = 0 (0xfffffe006cd8a020) locked @ /syzkaller/managers/main/kernel/sys/netinet/in_pcb.c:1472
db> show malloc
Type InUse MemUse Requests
pf_hash 5 11524K 5
tcp_hpts 7 4801K 7
devbuf 4218 4324K 4246
sysctloid 34809 2051K 34880
vtbuf 24 1968K 46
inodedep 3718 1906K 4236
kobj 326 1304K 488
newblk 145 1060K 4983
vfscache 3 1025K 3
dirrem 3707 927K 4183
pcb 29 670K 4199
ufs_quota 1 512K 1
vfs_hash 1 512K 1
callout 2 512K 2
intr 4 472K 4
freefile 3707 464K 4181
subproc 112 206K 5007
acpica 1674 184K 57212
tidhash 3 141K 3
vmem 3 134K 4
pagedep 10 131K 4182
tfo_ccache 1 128K 1
IP reass 1 128K 1
linker 324 127K 353
vnet_data 1 112K 1
sem 4 106K 4
DEVFS1 105 105K 114
bus 985 81K 5069
mtx_pool 2 72K 2
NFSD srvcache 3 68K 3
syncache 1 68K 1
acpitask 1 64K 1
ddb_capture 1 64K 1
module 508 64K 508
temp 19 53K 1592
umtx 308 39K 308
kdtrace 182 38K 10037
hostcache 1 32K 1
shm 1 32K 1
DEVFS3 124 31K 134
msg 4 30K 4
kbdmux 6 28K 6
gtaskqueue 18 26K 18
DEVFS_RULE 56 20K 56
BPF 10 18K 10
ufs_mount 4 17K 5
proc 3 17K 3
tty 16 16K 16
ithread 97 16K 97
bus-sc 34 15K 1648
eventhandler 157 13K 157
KTRACE 100 13K 100
kenv 95 12K 95
ifaddr 30 12K 32
rman 88 11K 431
GEOM 61 11K 481
routetbl 50 11K 176
CAM queue 5 11K 1528
bmsafemap 2 9K 4204
rpc 4 9K 4
UART 12 9K 12
devstat 4 9K 4
ksem 1 8K 1
pfs_vncache 1 8K 1
shmfd 1 8K 1
audit_evclass 237 8K 297
taskqueue 63 7K 63
sglist 5 7K 5
CAM DEV 3 6K 510
cred 22 6K 244
pfs_nodes 20 5K 20
plimit 20 5K 362
ufs_dirhash 24 5K 24
UMA 267 5K 267
vt 11 5K 11
ifnet 3 5K 3
memdesc 1 4K 1
MCA 32 4K 32
filedesc 1 4K 1
evdev 4 4K 4
acpisem 28 4K 28
hhook 15 4K 17
ether_multi 40 4K 50
lltable 11 4K 11
pf_ifnet 5 3K 6
in6_multi 25 3K 25
kqueue 45 3K 4942
pwddesc 45 3K 4940
CC Mem 11 3K 8325
terminal 11 3K 11
session 19 3K 32
clone 9 3K 9
uidinfo 3 3K 9
proc-args 64 3K 5873
local_apic 1 2K 1
io_apic 1 2K 1
fpukern_ctx 2 2K 2
ipsec-saq 2 2K 2
lockf 16 2K 26
Unitno 27 2K 41
CAM XPT 22 2K 543
msi 12 2K 12
mkdir 12 2K 8342
selfd 22 2K 64925
ipsecpolicy 2 2K 2
acpidev 20 2K 20
diradd 9 2K 4199
freework 5 2K 4181
NFSD session 1 1K 1
softdep 1 1K 1
newdirblk 8 1K 4171
freeblks 4 1K 4180
sahead 1 1K 1
secasvar 1 1K 1
vnodemarker 2 1K 20
CAM periph 4 1K 271
select 7 1K 29
ipsec 3 1K 3
nhops 6 1K 6
pfil 6 1K 6
toponodes 6 1K 6
isadev 6 1K 6
mount 16 1K 89
pci_link 10 1K 10
sctp_ifa 5 1K 6
crypto 4 1K 4
ip6ndp 4 1K 5
encap_export_host 12 1K 12
inpcbpolicy 18 1K 8457
osd 16 1K 8338
in_multi 2 1K 4
cdev 2 1K 2
chacha20random 1 1K 1
biobuf 1 1K 1
sctp_ifn 2 1K 6
NFSD lckfile 1 1K 1
NFSD V4client 1 1K 1
DEVFSP 4 1K 9
DEVFS 9 1K 10
indirdep 1 1K 3
mld 2 1K 2
igmp 2 1K 2
vnodes 1 1K 1
CAM SIM 2 1K 2
soname 8 1K 11713
feeder 7 1K 7
tcpfunc 3 1K 3
loginclass 3 1K 7
prison 6 1K 6
lkpikmalloc 5 1K 6
aesni_data 2 1K 2
cryptodev 2 1K 49
nexusdev 8 1K 8
apmdev 1 1K 1
atkbddev 2 1K 2
freefrag 1 1K 2
netlink 1 1K 1
CAM dev queue 2 1K 2
CAM I/O Scheduler 1 1K 1
CAM path 4 1K 1034
procdesc 1 1K 6
pmchooks 1 1K 1
tun 3 1K 3
sctp_vrf 1 1K 1
vnet 1 1K 1
entropy 2 1K 39
pmc 1 1K 1
acpiintr 1 1K 1
cpus 2 1K 2
vnet_data_free 1 1K 1
Per-cpu 1 1K 1
p1003.1b 1 1K 1
filecaps 1 1K 66
pf_table 0 0K 0
pf_rule 0 0K 0
pf_altq 0 0K 0
pf_osfp 0 0K 0
pf_krule_item 0 0K 0
pf_temp 0 0K 0
mqdata 0 0K 0
filemon 0 0K 0
sctp_mcore 0 0K 0
sctp_socko 0 0K 0
sctp_iter 0 0K 4
sctp_mvrf 0 0K 0
sctp_timw 0 0K 0
sctp_cpal 0 0K 0
sctp_cmsg 0 0K 0
sctp_stre 0 0K 0
sctp_athi 0 0K 0
sctp_athm 0 0K 0
sctp_atky 0 0K 0
sctp_atcl 0 0K 0
sctp_a_it 0 0K 4
sctp_aadr 0 0K 0
sctp_stro 0 0K 0
sctp_stri 0 0K 0
sctp_map 0 0K 0
tcp_do 0 0K 0
tcp_fsb 0 0K 0
ipcomp 0 0K 0
esp 0 0K 0
ah 0 0K 0
savedino 0 0K 474
sentinel 0 0K 0
jfsync 0 0K 0
jtrunc 0 0K 0
sbdep 0 0K 6
jsegdep 0 0K 0
jseg 0 0K 0
jfreefrag 0 0K 0
jfreeblk 0 0K 0
jnewblk 0 0K 0
jmvref 0 0K 0
jremref 0 0K 0
jaddref 0 0K 0
freedep 0 0K 0
ip6opt 0 0K 3
ip6_msource 0 0K 0
ip6_moptions 0 0K 0
in6_mfilter 0 0K 0
frag6 0 0K 0
tcplog 0 0K 0
tcp_hwpace 0 0K 0
BACKLIGHT 0 0K 0
LRO 0 0K 0
ip_msource 0 0K 0
ip_moptions 0 0K 0
in_mfilter 0 0K 0
ipid 0 0K 0
80211scan 0 0K 0
80211ratectl 0 0K 0
80211power 0 0K 0
80211nodeie 0 0K 0
80211node 0 0K 0
80211mesh_gt 0 0K 0
80211mesh_rt 0 0K 0
80211perr 0 0K 0
80211prep 0 0K 0
80211preq 0 0K 0
80211dfs 0 0K 0
80211crypto 0 0K 0
80211vap 0 0K 0
iflib 0 0K 0
vlan 0 0K 0
gif 0 0K 0
ifdescr 0 0K 0
zlib 0 0K 0
fadvise 0 0K 0
VN POLL 0 0K 0
ath_hal 0 0K 0
statfs 0 0K 4354
namei_tracker 0 0K 0
export_host 0 0K 0
cl_savebuf 0 0K 3
athdev 0 0K 0
ata_pci 0 0K 0
ata_dma 0 0K 0
ata_generic 0 0K 0
pvscsi 0 0K 0
scsi_da 0 0K 69
ata_da 0 0K 0
scsi_ch 0 0K 0
scsi_cd 0 0K 0
AHCI driver 0 0K 0
USBdev 0 0K 0
USB 0 0K 0
agp 0 0K 0
nvme_da 0 0K 0
acpipwr 0 0K 0
acpi_perf 0 0K 0
twsbuf 0 0K 0
tcp_log_dev 0 0K 0
aio 0 0K 0
lio 0 0K 0
iov 0 0K 13586
ioctlops 0 0K 86
eventfd 0 0K 0
Witness 0 0K 0
stack 0 0K 0
mrsasbuf 0 0K 0
mpt_user 0 0K 0
mps_user 0 0K 0
MPSSAS 0 0K 0
mps 0 0K 0
sbuf 0 0K 288
mpr_user 0 0K 0
firmware 0 0K 0
compressor 0 0K 0
MPRSAS 0 0K 0
SWAP 0 0K 0
mpr 0 0K 0
mfibuf 0 0K 0
sysctltmp 0 0K 645
sysctl 0 0K 3
md_sectors 0 0K 0
ekcd 0 0K 0
dumper 0 0K 0
sendfile 0 0K 0
rctl 0 0K 0
md_disk 0 0K 0
malodev 0 0K 0
LED 0 0K 0
ix_sriov 0 0K 0
cache 0 0K 0
aacraidcam 0 0K 0
kcovinfo 0 0K 0
mbuf_jumbo_page 4096 8320 1078 17484 0 254 38494208 0
mbuf 256 8583 1079 32933 0 254 2473472 0
BUF TRIE 144 196 11620 642 0 62 1701504 0
malloc-384 384 4170 30 4171 0 30 1612800 0
malloc-128 128 11436 158 15708 0 126 1484032 0
malloc-384 384 3733 47 4261 0 30 1451520 0
malloc-4096 4096 327 1 489 0 2 1343488 0
UMA Slabs 0 112 10638 12 10638 0 126 1192800 0
mbuf_cluster 2048 508 0 508 0 254 1040384 0
malloc-256 256 3768 27 12973 0 62 971520 0
vmem btag 56 16254 57 16254 0 254 913416 0
malloc-128 128 4899 30 39202 0 126 630912 0
FFS inode 1160 494 31 4676 0 8 609000 0
pbuf 2624 0 198 0 0 2 519552 0
RADIX NODE 144 3380 227 119731 0 62 519408 0
socket 960 26 482 9628 0 254 487680 0
malloc-2048 2048 7 193 1076 0 8 409600 0
lkpicurr 168 2 2350 2 0 62 395136 0
malloc-65536 65536 6 0 6 0 1 393216 0
lkpimm 168 1 2327 1 0 62 391104 0
256 Bucket 2048 125 19 1052 0 8 294912 0
THREAD 1824 136 18 5096 0 8 280896 0
malloc-64 64 3888 459 13733 0 254 278208 0
VNODE 448 524 79 4708 0 30 270144 0
VM OBJECT 264 956 64 64927 0 30 269280 0
malloc-256 256 358 572 5365 0 62 238080 0
malloc-4096 4096 53 5 4950 0 2 237568 0
malloc-16 16 14387 113 22764 0 254 232000 0
DEVCTL 1024 0 220 123 0 0 225280 0
UMA Zones 768 239 0 239 0 16 183552 0
malloc-32 32 5280 390 5307 0 254 181440 0
malloc-1024 1024 131 29 140 0 16 163840 0
FPU_save_area 832 138 42 5116 0 16 149760 0
malloc-128 128 1029 118 5413 0 126 146816 0
S VFS Cache 104 981 423 5177 0 126 146016 0
FFS2 dinode 256 494 76 4675 0 62 145920 0
malloc-256 256 11 559 535 0 62 145920 0
malloc-65536 65536 0 2 54 0 1 131072 0
unpcb 256 7 503 1154 0 254 130560 0
mbuf_packet 256 0 508 98 0 254 130048 0
MAP ENTRY 96 933 327 112857 0 126 120960 0
ksiginfo 112 55 989 75 0 126 116928 0
malloc-32768 32768 3 0 3 0 1 98304 0
PROC 1376 44 22 4939 0 8 90816 0
UMA Kegs 384 226 7 226 0 30 89472 0
128 Bucket 1024 47 36 336 0 16 84992 0
malloc-256 256 180 135 9689 0 62 80640 0
filedesc0 1072 45 25 4940 0 8 75040 0
malloc-8192 8192 8 1 10 0 1 73728 0
malloc-4096 4096 18 0 29 0 2 73728 0
g_bio 408 1 179 5094 0 30 73440 0
malloc-64 64 515 556 1623 0 254 68544 0
malloc-128 128 332 195 4640 0 126 67456 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-65536 65536 0 1 126 0 1 65536 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-32768 32768 2 0 2 0 1 65536 0
malloc-8192 8192 6 1 107 0 1 57344 0
64 Bucket 512 86 18 2840 0 30 53248 0
malloc-64 64 474 345 910 0 254 52416 0
malloc-256 256 47 148 4427 0 62 49920 0
32 Bucket 256 55 140 3885 0 62 49920 0
DIRHASH 1024 35 13 35 0 16 49152 0
NAMEI 1024 0 48 28748 0 16 49152 0
malloc-16384 16384 3 0 3 0 1 49152 0
malloc-1024 1024 10 38 1421 0 16 49152 0
malloc-384 384 96 24 99 0 30 46080 0
PWD 40 18 1093 4264 0 254 44440 0
syncache 168 0 264 5 0 254 44352 0
tcp_inpcb 1304 11 22 8325 0 8 43032 0
malloc-8192 8192 4 1 30 0 1 40960 0
VMSPACE 520 28 47 4924 0 16 39000 0
udp_inpcb 424 6 84 128 0 30 38160 0
da_ccb 544 0 70 1407 0 16 38080 0
pcpu-8 8 4287 321 4315 0 254 36864 0
malloc-64 64 27 540 27 0 254 36288 0
malloc-64 64 71 496 78221 0 254 36288 0
malloc-64 64 59 508 5501 0 254 36288 0
malloc-64 64 211 356 233 0 254 36288 0
malloc-64 64 158 409 176 0 254 36288 0
malloc-128 128 3 276 3 0 126 35712 0
malloc-128 128 23 256 34 0 126 35712 0
malloc-128 128 24 255 166 0 126 35712 0
malloc-128 128 133 146 142 0 126 35712 0
routing nhops 256 10 125 17 0 62 34560 0
ttyoutq 256 72 63 160 0 62 34560 0
malloc-256 256 28 107 8439 0 62 34560 0
malloc-256 256 29 106 370 0 62 34560 0
malloc-256 256 52 83 5129 0 62 34560 0
malloc-32768 32768 0 1 120 0 1 32768 0
malloc-16384 16384 2 0 12 0 1 32768 0
malloc-4096 4096 7 1 7 0 2 32768 0
malloc-2048 2048 4 12 4 0 8 32768 0
malloc-2048 2048 2 14 2 0 8 32768 0
malloc-2048 2048 6 10 15 0 8 32768 0
malloc-2048 2048 7 9 7 0 8 32768 0
malloc-1024 1024 0 32 4 0 16 32768 0
malloc-1024 1024 11 21 15 0 16 32768 0
malloc-1024 1024 4 28 8 0 16 32768 0
malloc-1024 1024 4 28 151 0 16 32768 0
malloc-1024 1024 10 22 10 0 16 32768 0
malloc-1024 1024 1 31 16 0 16 32768 0
malloc-512 512 2 62 20 0 30 32768 0
malloc-512 512 4 60 4 0 30 32768 0
malloc-512 512 0 64 128 0 30 32768 0
malloc-512 512 11 53 60 0 30 32768 0
pcpu-64 64 486 26 486 0 254 32768 0
ertt_txseginfo 40 1 807 4328 0 254 32320 0
ttyinq 160 135 65 300 0 62 32000 0
PGRP 120 19 245 32 0 126 31680 0
clpbuf 2624 0 12 27 0 4 31488 0
cpuset 104 7 272 7 0 126 29016 0
sctp_laddr 48 0 588 4 0 254 28224 0
tcp_inpcb ports 32 9 873 8319 0 254 28224 0
16 Bucket 144 56 140 302 0 62 28224 0
4 Bucket 48 6 582 8 0 254 28224 0
TURNSTILE 136 155 34 155 0 62 25704 0
malloc-4096 4096 2 4 4906 0 2 24576 0
rl_entry 40 30 576 30 0 254 24240 0
rtentry 168 13 131 17 0 62 24192 0
pipe 728 6 27 284 0 16 24024 0
Files 80 75 225 19013 0 126 24000 0
8 Bucket 80 65 235 1944 0 126 24000 0
malloc-384 384 0 60 19 0 30 23040 0
SLEEPQUEUE 88 155 101 155 0 126 22528 0
hostcache 64 1 314 1 0 254 20160 0
udp_inpcb ports 32 3 627 40 0 254 20160 0
ertt 72 11 269 8325 0 126 20160 0
malloc-32 32 6 624 20 0 254 20160 0
malloc-32 32 25 605 70 0 254 20160 0
malloc-32 32 368 262 9272 0 254 20160 0
malloc-32 32 74 556 5125 0 254 20160 0
malloc-32 32 38 592 81 0 254 20160 0
malloc-32 32 52 578 3879 0 254 20160 0
malloc-32 32 54 576 8499 0 254 20160 0
2 Bucket 32 42 588 326 0 254 20160 0
epoch_record pcpu 256 4 60 4 0 62 16384 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-16384 16384 0 1 160 0 1 16384 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-8192 8192 2 0 2 0 1 16384 0
malloc-8192 8192 2 0 2 0 1 16384 0
malloc-8192 8192 2 0 2 0 1 16384 0
malloc-2048 2048 0 8 50 0 8 16384 0
malloc-2048 2048 2 6 193 0 8 16384 0
malloc-2048 2048 1 7 1 0 8 16384 0
malloc-512 512 1 31 2 0 30 16384 0
malloc-512 512 2 30 2 0 30 16384 0
SMR CPU 32 7 504 7 0 254 16352 0
vtnet_tx_hdr 24 0 668 6332 0 254 16032 0
kenv 258 16 44 1033 0 30 15480 0
mqnode 416 3 33 3 0 30 14976 0
vmem 1856 1 7 1 0 8 14848 0
ripcb 392 1 35 4 0 30 14112 0
SMR SHARED 24 7 504 7 0 254 12264 0
KNOTE 160 0 75 8 0 62 12000 0
malloc-16 16 26 724 113 0 254 12000 0
malloc-16 16 49 701 288 0 254 12000 0
malloc-16 16 214 536 4290 0 254 12000 0
malloc-16 16 28 722 150 0 254 12000 0
malloc-16 16 278 472 26318 0 254 12000 0
malloc-16 16 11 739 17 0 254 12000 0
malloc-384 384 0 30 1 0 30 11520 0
malloc-384 384 0 30 342 0 30 11520 0
malloc-384 384 2 28 2 0 30 11520 0
malloc-384 384 1 29 1 0 30 11520 0
Mountpoints 2816 2 2 2 0 4 11264 0
malloc-8192 8192 1 0 1 0 1 8192 0
malloc-8192 8192 1 0 1 0 1 8192 0
malloc-4096 4096 0 2 5 0 2 8192 0
malloc-16 16 0 500 2 0 254 8000 0
pcpu-16 16 4 252 4 0 254 4096 0
UMA Slabs 1 176 8 14 8 0 62 3872 0
KMAP ENTRY 96 12 27 14 0 0 3744 0
FFS1 dinode 128 0 0 0 0 126 0 0
ada_ccb 272 0 0 0 0 30 0 0
swblk 136 0 0 0 0 62 0 0
swpctrie 144 0 0 0 0 62 0 0
pf state scrubs 40 0 0 0 0 254 0 0
pf frag entries 40 0 0 0 0 254 0 0
pf frags 248 0 0 0 0 62 0 0
pf table entries 160 0 0 0 0 254 0 0
pf table entry counters 64 0 0 0 0 254 0 0
pf source nodes 152 0 0 0 0 254 0 0
pf state keys 88 0 0 0 0 126 0 0
pf states 344 0 0 0 0 254 0 0
pf tags 104 0 0 0 0 126 0 0
pf mtags 184 0 0 0 0 62 0 0
NCLNODE 608 0 0 0 0 16 0 0
TMPFS node 232 0 0 0 0 62 0 0
mqnotifier 216 0 0 0 0 62 0 0
mvdata 64 0 0 0 0 254 0 0
mqueue 248 0 0 0 0 62 0 0
LTS VFS Cache 360 0 0 0 0 30 0 0
L VFS Cache 320 0 0 0 0 30 0 0
STS VFS Cache 144 0 0 0 0 62 0 0
cryptop 280 0 0 0 0 30 0 0
linux_dma_object 32 0 0 0 0 254 0 0
linux_dma_pctrie 144 0 0 0 0 62 0 0
IOMMU_MAP_ENTRY 104 0 0 0 0 126 0 0
mbuf_jumbo_16k 16384 0 0 0 0 254 0 0
mbuf_jumbo_9k 9216 0 0 0 0 254 0 0
audit_record 1280 0 0 0 0 8 0 0
domainset 40 0 0 0 0 2

Reply all
Reply to author
Forward
0 new messages