panic: sbflush_internal: residual data

6 views
Skip to first unread message

syzbot

unread,
Feb 13, 2020, 3:29:14 AM2/13/20
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 70af7c90 Use INT instead of string for the ints. Because t..
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=12afe07ee00000
dashboard link: https://syzkaller.appspot.com/bug?extid=bca42a93f1254ca91e94
userspace arch: i386

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+bca42a...@syzkaller.appspotmail.com

panic: sbflush_internal: ccc 0 mb 0 mbcnt 256
cpuid = 0
time = 1581582527
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame 0xfffffe0024cb5850
vpanic() at vpanic+0x1ce/frame 0xfffffe0024cb58c0
panic() at panic+0x43/frame 0xfffffe0024cb5920
sbrelease_internal() at sbrelease_internal+0x168/frame 0xfffffe0024cb5960
solisten_proto() at solisten_proto+0xc6/frame 0xfffffe0024cb59c0
sctp_listen() at sctp_listen+0x4e6/frame 0xfffffe0024cb5a30
solisten() at solisten+0x7a/frame 0xfffffe0024cb5a70
kern_listen() at kern_listen+0x125/frame 0xfffffe0024cb5ab0
ia32_syscall() at ia32_syscall+0x487/frame 0xfffffe0024cb5bf0
int0x80_syscall_common() at int0x80_syscall_common+0x9c/frame 0x8142e7d
KDB: enter: panic
[ thread pid 2212 tid 100644 ]
Stopped at kdb_enter+0x67: movq $0,0x1465766(%rip)
db>
db> set $lines = 0
db> set $maxwidth = 0
db> show registers
cs 0x20
ds 0x3b ll+0x1a
es 0x3b ll+0x1a
fs 0x13
gs 0x1b
ss 0
rax 0x12
rcx 0xfffffe0025200000
rdx 0x3ffff
rbx 0
rsp 0xfffffe0024cb5830
rbp 0xfffffe0024cb5850
rsi 0x40001
rdi 0xffffffff810bc8c6 vprintf+0x176
r8 0
r9 0xffffffff
r10 0
r11 0xfffffe00249afc00
r12 0xffffffff82068dc0 ddb_dbbe
r13 0
r14 0xffffffff81939d65
r15 0xffffffff81939d65
rip 0xffffffff810b1957 kdb_enter+0x67
rflags 0x200086 kernphys+0x86
kdb_enter+0x67: movq $0,0x1465766(%rip)
db> show proc
Process 2212 (syz-executor.0) at 0xfffff800032d4a60:
state: NORMAL
uid: 0 gids: 0, 0, 5
parent: pid 768 at 0xfffff8003a32f530
ABI: FreeBSD ELF32
arguments: /root/syz-executor.0
reaper: 0xfffff800032d4000 reapsubtree: 1
sigparent: 20
vmspace: 0xfffffe00249a83d0
(map 0xfffffe00249a83d0)
(map.pmap 0xfffffe00249a8490)
(pmap 0xfffffe00249a84f0)
threads: 2
100072 RunQ syz-executor.0
100644 Run CPU 0 syz-executor.0
db> ps
pid ppid pgrp uid state wmesg wchan cmd
2212 768 768 0 R (threaded) syz-executor.0
100072 RunQ syz-executor.0
100644 Run CPU 0 syz-executor.0
2206 771 771 0 D (threaded) syz-executor.2
100155 S nanslp 0xffffffff824ffcc0 syz-executor.2
100632 D biowr 0xfffffe0003e030c0 syz-executor.2
100635 S uwait 0xfffff800039ac880 syz-executor.2
100637 S uwait 0xfffff800039acc80 syz-executor.2
2024 2017 2024 0 Ss select 0xfffff8003af6e9c0 dhclient
2020 1 2020 0 Ss select 0xfffff8003af6e940 dhclient
2017 2008 422 65 S select 0xfffff80003b2de40 dhclient
2008 422 422 0 S wait 0xfffff8003aa84a60 sh
1999 1 1999 65 Ss select 0xfffff8003af6ea40 dhclient
821 1 821 0 Ss select 0xfffff800039afac0 dhclient
816 1 816 0 Ss select 0xfffff80003b2dd40 dhclient
771 766 771 0 Ss nanslp 0xffffffff824ffcc0 syz-executor.2
770 766 770 0 Ds getblk 0xfffffe0003e03140 syz-executor.3
769 766 769 0 Rs CPU 1 syz-executor.1
768 766 768 0 Ss nanslp 0xffffffff824ffcc1 syz-executor.0
766 764 764 0 S (threaded) syz-fuzzer
100083 S uwait 0xfffff80003b2e180 syz-fuzzer
100096 S uwait 0xfffff800039aed00 syz-fuzzer
100097 S uwait 0xfffff80003b2e300 syz-fuzzer
100098 S uwait 0xfffff80003b2ce80 syz-fuzzer
100099 S uwait 0xfffff80003b2f000 syz-fuzzer
100100 S kqread 0xfffff80003b57d00 syz-fuzzer
100101 S uwait 0xfffff800039ae200 syz-fuzzer
100102 S uwait 0xfffff80003b2f600 syz-fuzzer
100103 S uwait 0xfffff80003b2f700 syz-fuzzer
100104 S uwait 0xfffff800039ae300 syz-fuzzer
764 762 764 0 Ss pause 0xfffff8003a34bb08 csh
762 680 762 0 Ss select 0xfffff80003b2c9c0 sshd
746 1 746 0 Ss+ ttyin 0xfffff800033f5cb0 getty
745 1 745 0 Ss+ ttyin 0xfffff80003a928b0 getty
744 1 744 0 Ss+ ttyin 0xfffff80003a92cb0 getty
743 1 743 0 Ss+ ttyin 0xfffff80003a950b0 getty
742 1 742 0 Ss+ ttyin 0xfffff80003a954b0 getty
741 1 741 0 Ss+ ttyin 0xfffff80003a958b0 getty
740 1 740 0 Ss+ ttyin 0xfffff80003a95cb0 getty
739 1 739 0 Ss+ ttyin 0xfffff80003a940b0 getty
738 1 738 0 Ss+ ttyin 0xfffff80003a944b0 getty
684 1 684 0 Ss nanslp 0xffffffff824ffcc1 cron
680 1 680 0 Ss select 0xfffff80003b2f940 sshd
493 1 493 0 Ss select 0xfffff80003b2cac0 syslogd
422 1 422 0 Ss wait 0xfffff80003bcba60 devd
421 1 421 65 Ss select 0xfffff80003b2cb40 dhclient
336 1 336 0 Ss select 0xfffff80003b2f840 dhclient
333 1 333 0 Ss select 0xfffff80003b2f8c0 dhclient
21 0 0 0 DL syncer 0xffffffff825d6158 [syncer]
20 0 0 0 DL vlruwt 0xfffff80003a70000 [vnlru]
19 0 0 0 DL (threaded) [bufdaemon]
100065 D qsleep 0xffffffff825d5658 [bufdaemon]
100070 D - 0xffffffff8200a980 [bufspacedaemon-0]
100080 D sdflush 0xfffff80003b628e8 [/ worker]
18 0 0 0 DL psleep 0xffffffff825f10c8 [vmdaemon]
17 0 0 0 DL (threaded) [pagedaemon]
100063 D psleep 0xffffffff8261cfd8 [dom0]
100068 D launds 0xffffffff8261cfe4 [laundry: dom0]
100069 D umarcl 0xffffffff81540270 [uma]
16 0 0 0 DL - 0xffffffff8235a530 [rand_harvestq]
15 0 0 0 DL waiting 0xffffffff826625a0 [sctp_iterator]
9 0 0 0 DL - 0xffffffff825d505c [soaiod4]
8 0 0 0 DL - 0xffffffff825d505c [soaiod3]
7 0 0 0 DL - 0xffffffff825d505c [soaiod2]
6 0 0 0 DL - 0xffffffff825d505c [soaiod1]
5 0 0 0 DL (threaded) [cam]
100031 D - 0xffffffff82235940 [doneq0]
100062 D - 0xffffffff82235808 [scanner]
4 0 0 0 DL crypto_ 0xfffff80003303190 [crypto returns 1]
3 0 0 0 DL crypto_ 0xfffff80003303130 [crypto returns 0]
2 0 0 0 DL crypto_ 0xffffffff825eb138 [crypto]
14 0 0 0 DL seqstat 0xfffff8000333a888 [sequencer 00]
13 0 0 0 DL (threaded) [geom]
100022 D - 0xffffffff8261b608 [g_event]
100023 D - 0xffffffff8261b618 [g_up]
100024 D - 0xffffffff8261b610 [g_down]
12 0 0 0 WL (threaded) [intr]
100005 I [swi5: fast taskq]
100009 I [swi6: task queue]
100010 I [swi6: Giant taskq]
100017 I [swi3: vm]
100018 I [swi1: netisr 0]
100019 I [swi4: clock (0)]
100020 I [swi4: clock (1)]
100032 I [irq24: virtio_pci0]
100033 I [irq25: virtio_pci0]
100034 I [irq26: virtio_pci0]
100035 I [irq27: virtio_pci0]
100036 I [irq28: virtio_pci1]
100037 I [irq29: virtio_pci1]
100038 I [irq30: virtio_pci1]
100039 I [irq31: virtio_pci1]
100040 I [irq32: virtio_pci1]
100045 I [irq10: virtio_pci2]
100047 I [irq1: atkbd0]
100048 I [irq12: psm0]
100049 I [swi0: uart uart++]
11 0 0 0 RL (threaded) [idle]
100003 CanRun [idle: cpu0]
100004 CanRun [idle: cpu1]
1 0 1 0 SLs wait 0xfffff800032d4000 [init]
10 0 0 0 DL audit_w 0xffffffff82663230 [audit]
0 0 0 0 DLs (threaded) [kernel]
100000 D swapin 0xffffffff8260ac48 [swapper]
100006 D - 0xfffff800031d4000 [config_0]
100007 D - 0xfffff800031d8800 [kqueue_ctx taskq]
100008 D - 0xfffff800031d8600 [aiod_kick taskq]
100011 D - 0xfffff800031d8000 [thread taskq]
100012 D - 0xfffff800031d3e00 [softirq_0]
100013 D - 0xfffff800031d3d00 [softirq_1]
100014 D - 0xfffff800031d3c00 [if_io_tqg_0]
100015 D - 0xfffff800031d3b00 [if_io_tqg_1]
100016 D - 0xfffff800031d3a00 [if_config_tqg_0]
100021 D - 0xfffff800031d7400 [firmware taskq]
100026 D - 0xfffff800031d6d00 [crypto_0]
100027 D - 0xfffff800031d6d00 [crypto_1]
100041 D - 0xfffff800031d6000 [vtnet0 rxq 0]
100042 D - 0xfffff800031d5e00 [vtnet0 txq 0]
100043 D - 0xfffff800031d5d00 [vtnet0 rxq 1]
100044 D - 0xfffff800031d5c00 [vtnet0 txq 1]
100046 D vtbslp 0xfffff8000352f880 [virtio_balloon]
100050 D - 0xfffff80003774e00 [mca taskq]
100054 D - 0xffffffff81cde0d1 [deadlkres]
100057 D - 0xfffff800039b2700 [acpi_task_0]
100058 D - 0xfffff800039b2700 [acpi_task_1]
100059 D - 0xfffff800039b2700 [acpi_task_2]
100061 D - 0xfffff800031d6600 [CAM taskq]
db> show all locks
Process 2212 (syz-executor.0) thread 0xfffffe00249af700 (100644)
exclusive sleep mutex socket (socket) r = 0 (0xfffffe0024913530) locked @ /syzkaller/managers/i386/kernel/sys/netinet/sctp_usrreq.c:7285
exclusive sleep mutex sctp-inp (inp) r = 0 (0xfffff8003acb5968) locked @ /syzkaller/managers/i386/kernel/sys/netinet/sctp_usrreq.c:7283
Process 2206 (syz-executor.2) thread 0xfffffe00249ac500 (100632)
exclusive lockmgr bufwait (bufwait) r = 0 (0xfffffe0003e03140) locked @ /syzkaller/managers/i386/kernel/sys/kern/vfs_bio.c:3885
exclusive lockmgr ufs (ufs) r = 0 (0xfffff8003a5aa250) locked @ /syzkaller/managers/i386/kernel/sys/kern/vfs_vnops.c:877
Process 770 (syz-executor.3) thread 0xfffffe0004cfe800 (100105)
exclusive lockmgr bufwait (bufwait) r = 0 (0xfffffe0003f2d100) locked @ /syzkaller/managers/i386/kernel/sys/kern/vfs_bio.c:3885
exclusive lockmgr ufs (ufs) r = 1 (0xfffff8003a8bfbd8) locked @ /syzkaller/managers/i386/kernel/sys/kern/vfs_subr.c:2922
exclusive lockmgr ufs (ufs) r = 0 (0xfffff8003a261250) locked @ /syzkaller/managers/i386/kernel/sys/kern/vfs_subr.c:2922
Process 769 (syz-executor.1) thread 0xfffffe002492e300 (100086)
exclusive sleep mutex pmap (pmap) r = 0 (0xfffffe0024969b08) locked @ /syzkaller/managers/i386/kernel/sys/amd64/amd64/pmap.c:6816
exclusive sx vm map (user) (vm map (user)) r = 0 (0xfffffe0024969a48) locked @ /syzkaller/managers/i386/kernel/sys/vm/vm_map.c:4104
exclusive sx vm map (user) (vm map (user)) r = 0 (0xfffffe002496a430) locked @ /syzkaller/managers/i386/kernel/sys/vm/vm_map.c:4100
db> show malloc
Type InUse MemUse Requests
devbuf 4213 4851K 4241
vtbuf 24 1968K 46
sysctloid 26636 1559K 26700
kobj 332 1328K 488
newblk 112 1052K 22827
vfscache 4 1025K 4
pcb 270 814K 560
inodedep 34 529K 2731
ufs_quota 1 512K 1
vfs_hash 1 512K 1
callout 2 512K 2
intr 4 388K 4
subproc 127 253K 2286
acpica 1674 185K 50140
vnet_data 1 168K 1
pagedep 15 132K 1399
tfo_ccache 1 128K 1
sctp_atcl 244 122K 404
sctp_stro 121 121K 183
filedesc 17 117K 2797
sem 4 106K 4
DEVFS1 105 105K 122
linker 222 89K 253
bus 980 79K 3335
mtx_pool 2 72K 2
syncache 1 68K 1
acpitask 1 64K 1
ddb_capture 1 64K 1
module 494 62K 494
BPF 30 53K 30
umtx 324 41K 324
gtaskqueue 22 34K 22
kdtrace 173 33K 7067
hostcache 1 32K 1
shm 1 32K 3
DEVFS3 124 31K 134
msg 4 30K 4
DEVFS_RULE 56 27K 56
vmem 3 26K 5
ifaddr 72 24K 74
kbdmux 6 22K 6
lltable 46 17K 48
temp 34 17K 1985
ufs_mount 3 17K 4
proc 3 17K 3
tty 16 16K 16
tidhash 1 16K 1
sctp_atky 365 16K 587
ithread 89 15K 89
ether_multi 172 14K 177
bus-sc 30 14K 1397
KTRACE 100 13K 100
ifnet 7 13K 7
kenv 95 12K 99
freework 46 12K 10006
in6_multi 89 11K 89
eventhandler 122 11K 122
pfs_nodes 20 10K 20
GEOM 60 10K 487
rman 82 10K 423
bmsafemap 3 9K 2953
devstat 4 9K 4
UART 12 9K 12
rpc 2 8K 2
shmfd 1 8K 1
pfs_vncache 1 8K 1
routetbl 58 8K 62
audit_evclass 231 8K 289
cred 28 7K 209
sctp_timw 26 7K 26
CAM DEV 3 6K 510
kqueue 56 6K 2217
plimit 22 6K 366
vt 11 6K 11
sglist 5 6K 5
CAM queue 5 6K 1528
select 40 5K 40
ufs_dirhash 24 5K 24
DEVFSP 74 5K 78
taskqueue 42 5K 42
memdesc 1 4K 1
MCA 32 4K 32
evdev 4 4K 4
kcovinfo 64 4K 68
sctp_athm 244 4K 404
sctp_map 242 4K 366
UMA 235 4K 235
session 28 4K 38
pgrp 28 4K 38
hhook 13 4K 13
dirrem 12 3K 2462
acpisem 22 3K 22
terminal 11 3K 11
lockf 24 3K 2522
proc-args 47 3K 567
uidinfo 4 3K 4
freeblks 9 3K 2624
sctp_ifa 17 3K 17
local_apic 1 2K 1
io_apic 1 2K 1
CAM CCB 1 2K 45785
freefile 16 2K 2459
ipsec-saq 2 2K 2
ip6ndp 12 2K 21
Unitno 34 2K 3151
diradd 14 2K 2498
CAM XPT 22 2K 543
in_multi 6 2K 7
acpidev 20 2K 20
savedino 5 2K 7504
crypto 2 2K 2
msi 9 2K 9
tun 7 2K 7
softdep 1 1K 1
mkdir 8 1K 2770
indirdep 4 1K 12837
ipsecpolicy 1 1K 1
sahead 1 1K 1
secasvar 1 1K 1
clone 8 1K 8
vnodemarker 2 1K 16
NFSD session 1 1K 1
CAM periph 4 1K 271
mld 6 1K 6
sctp_ifn 6 1K 6
igmp 6 1K 6
toponodes 6 1K 6
isadev 6 1K 6
mount 16 1K 86
pci_link 10 1K 10
CAM SIM 2 1K 2
newdirblk 4 1K 1385
pfil 4 1K 4
chacha20random 1 1K 1
epoch 4 1K 4
cdev 2 1K 2
encap_export_host 8 1K 8
inpcbpolicy 10 1K 219
osd 3 1K 9
vnodes 1 1K 1
NFSD lckfile 1 1K 1
NFSD V4client 1 1K 1
DEVFS 9 1K 10
feeder 7 1K 7
loginclass 3 1K 3
CAM path 4 1K 1034
apmdev 1 1K 1
atkbddev 2 1K 2
iov 2 1K 16706
pmchooks 1 1K 1
prison 4 1K 4
CAM dev queue 2 1K 2
CAM I/O Scheduler 1 1K 1
soname 4 1K 5980
nexusdev 5 1K 5
entropy 2 1K 38
tcpfunc 1 1K 1
sctp_vrf 1 1K 1
vnet 1 1K 1
acpiintr 1 1K 1
pmc 1 1K 1
filecaps 3 1K 79
cpus 2 1K 2
vnet_data_free 1 1K 1
Per-cpu 1 1K 1
p1003.1b 1 1K 1
madt_table 0 0K 2
PUC 0 0K 0
ppbusdev 0 0K 0
agtiapi_MemAlloc malloc 0 0K 0
osti_cacheable 0 0K 0
tempbuff 0 0K 0
pvscsi 0 0K 0
smartpqi 0 0K 0
tempbuff 0 0K 0
ag_tgt_map_t malloc 0 0K 0
ag_slr_map_t malloc 0 0K 0
lDevFlags * malloc 0 0K 0
tiDeviceHandle_t * malloc 0 0K 0
ag_portal_data_t malloc 0 0K 0
ag_device_t malloc 0 0K 0
STLock malloc 0 0K 0
iavf 0 0K 0
ixl 0 0K 0
CCB List 0 0K 0
sr_iov 0 0K 0
OCS 0 0K 0
OCS 0 0K 0
nvme 0 0K 0
nvd 0 0K 0
netmap 0 0K 0
mwldev 0 0K 0
fpukern_ctx 0 0K 0
MVS driver 0 0K 0
xen_intr 0 0K 0
xen_hvm 0 0K 0
legacydrv 0 0K 0
qpidrv 0 0K 0
CAM ccb queue 0 0K 0
mrsasbuf 0 0K 0
dmar_idpgtbl 0 0K 0
dmar_dom 0 0K 0
dmar_ctx 0 0K 0
dmar_dmamap 0 0K 0
mpt_user 0 0K 0
mps_user 0 0K 0
isci 0 0K 0
bxe_ilt 0 0K 0
xenbus 0 0K 0
vm_fictitious 0 0K 0
MPSSAS 0 0K 0
mps 0 0K 0
mpr_user 0 0K 0
MPRSAS 0 0K 0
UMAHash 0 0K 0
vm_pgdata 0 0K 0
jblocks 0 0K 0
sentinel 0 0K 0
jfsync 0 0K 0
jtrunc 0 0K 0
sbdep 0 0K 7
jsegdep 0 0K 0
jseg 0 0K 0
jfreefrag 0 0K 0
jfreeblk 0 0K 0
jnewblk 0 0K 0
jmvref 0 0K 0
jremref 0 0K 0
jaddref 0 0K 0
freedep 0 0K 0
freefrag 0 0K 5
allocindir 0 0K 0
allocdirect 0 0K 0
ufs_trim 0 0K 0
mactemp 0 0K 0
audit_trigger 0 0K 0
audit_pipe_presel 0 0K 0
audit_pipeent 0 0K 0
audit_pipe 0 0K 0
audit_evname 0 0K 0
audit_bsm 0 0K 0
audit_gidset 0 0K 0
audit_text 0 0K 0
audit_path 0 0K 0
audit_data 0 0K 0
audit_cred 0 0K 0
xform 0 0K 0
NLM 0 0K 0
nfsclient_nlminfo 0 0K 0
nfsclient_lock 0 0K 0
NFS FHA 0 0K 0
ipsec-spdcache 0 0K 0
ipsec-reg 0 0K 0
ipsec-misc 0 0K 0
ipsecrequest 0 0K 0
ip6opt 0 0K 3
ip6_msource 0 0K 0
ip6_moptions 0 0K 0
in6_mfilter 0 0K 0
frag6 0 0K 0
tcplog 0 0K 0
LRO 0 0K 0
sctp_mcore 0 0K 0
sctp_socko 0 0K 238
sctp_iter 0 0K 10
sctp_mvrf 0 0K 0
sctp_cpal 0 0K 0
sctp_cmsg 0 0K 0
sctp_stre 0 0K 0
sctp_athi 0 0K 0
sctp_a_it 0 0K 10
sctp_aadr 0 0K 0
sctp_stri 0 0K 0
newreno data 0 0K 0
ip_msource 0 0K 0
ip_moptions 0 0K 0
in_mfilter 0 0K 0
ipid 0 0K 0
80211scan 0 0K 0
80211ratectl 0 0K 0
80211power 0 0K 0
80211nodeie 0 0K 0
80211node 0 0K 0
80211mesh_gt 0 0K 0
80211mesh_rt 0 0K 0
80211perr 0 0K 0
80211prep 0 0K 0
80211preq 0 0K 0
80211dfs 0 0K 0
80211crypto 0 0K 0
80211vap 0 0K 0
iflib 0 0K 0
vlan 0 0K 0
gif 0 0K 0
ifdescr 0 0K 0
zlib 0 0K 0
fadvise 0 0K 0
mpr 0 0K 0
statfs 0 0K 1557
export_host 0 0K 0
cl_savebuf 0 0K 2
biobuf 0 0K 0
aios 0 0K 0
lio 0 0K 0
acl 0 0K 0
mfibuf 0 0K 0
mbuf_tag 0 0K 116
accf 0 0K 0
pts 0 0K 0
ioctlops 0 0K 121
Witness 0 0K 0
stack 0 0K 0
md_sectors 0 0K 0
sbuf 0 0K 288
md_disk 0 0K 0
compressor 0 0K 0
malodev 0 0K 0
SWAP 0 0K 0
LED 0 0K 0
sysctltmp 0 0K 613
sysctl 0 0K 1
ekcd 0 0K 0
dumper 0 0K 0
rctl 0 0K 0
ix_sriov 0 0K 0
aacraidcam 0 0K 0
ix 0 0K 0
ipsbuf 0 0K 0
iirbuf 0 0K 0
cache 0 0K 0
aacraid_buf 0 0K 0
prison_racct 0 0K 0
Fail Points 0 0K 0
sigio 0 0K 1
filedesc_to_leader 0 0K 0
tty console 0 0K 0
aaccam 0 0K 0
aacbuf 0 0K 0
zstd 0 0K 0
nvlist 0 0K 0
SCSI ENC 0 0K 0
SCSI sa 0 0K 0
isofs_node 0 0K 0
isofs_mount 0 0K 0
tr_raid5_data 0 0K 0
tr_raid1e_data 0 0K 0
tr_raid1_data 0 0K 0
tr_raid0_data 0 0K 0
tr_concat_data 0 0K 0
md_sii_data 0 0K 0
md_promise_data 0 0K 0
md_nvidia_data 0 0K 0
md_jmicron_data 0 0K 0
md_intel_data 0 0K 0
md_ddf_data 0 0K 0
raid_data 0 0K 72
geom_flashmap 0 0K 0
newnfsmnt 0 0K 0
newnfsclient_req 0 0K 0
NFSCL layrecall 0 0K 0
NFSCL session 0 0K 0
NFSCL sockreq 0 0K 0
NFSCL devinfo 0 0K 0
NFSCL flayout 0 0K 0
NFSCL layout 0 0K 0
NFSD rollback 0 0K 0
NFSCL diroffdiroff 0 0K 0
NEWdirectio 0 0K 0
NEWNFSnode 0 0K 0
NFSCL lck 0 0K 0
NFSCL lckown 0 0K 0
NFSCL client 0 0K 0
NFSCL deleg 0 0K 0
NFSCL open 0 0K 0
NFSCL owner 0 0K 0
NFS fh 0 0K 0
NFS req 0 0K 0
NFSD usrgroup 0 0K 0
NFSD string 0 0K 0
NFSD V4lock 0 0K 0
NFSD V4state 0 0K 0
NFSD srvcache 0 0K 0
msdosfs_fat 0 0K 0
msdosfs_mount 0 0K 0
msdosfs_node 0 0K 0
DEVFS4 0 0K 0
DEVFS2 0 0K 0
gntdev 0 0K 0
privcmd_dev 0 0K 0
evtchn_dev 0 0K 0
xenstore 0 0K 0
scsi_pass 0 0K 0
ciss_data 0 0K 0
xnb 0 0K 0
xbbd 0 0K 0
xbd 0 0K 0
Balloon 0 0K 0
sysmouse 0 0K 0
vtfont 0 0K 0
ath_hal 0 0K 0
athdev 0 0K 0
ata_pci 0 0K 0
ata_dma 0 0K 0
ata_generic 0 0K 0
amr 0 0K 0
scsi_da 0 0K 69
ata_da 0 0K 0
scsi_ch 0 0K 0
scsi_cd 0 0K 0
USBdev 0 0K 0
USB 0 0K 0
AHCI driver 0 0K 0
agp 0 0K 0
nvme_da 0 0K 0
acpipwr 0 0K 0
twsbuf 0 0K 0
twe_commands 0 0K 0
twa_commands 0 0K 0
tcp_log_dev 0 0K 0
midi buffers 0 0K 0
mixer 0 0K 0
ac97 0 0K 0
hdacc 0 0K 0
hdac 0 0K 0
hdaa 0 0K 0
acpi_perf 0 0K 0
acpicmbat 0 0K 0
SIIS driver 0 0K 0
db> show ktr
No such command; use "help" to list available commands


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Feb 13, 2020, 4:14:14 AM2/13/20
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 70af7c90 Use INT instead of string for the ints. Because t..
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=17510ae6e00000
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=116232a1e00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+bca42a...@syzkaller.appspotmail.com

login: panic: sbflush_internal: ccc 0 mb 0 mbcnt 256
cpuid = 0
time = 1581585066
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame 0xfffffe0024c13850
vpanic() at vpanic+0x1ce/frame 0xfffffe0024c138c0
panic() at panic+0x43/frame 0xfffffe0024c13920
sbrelease_internal() at sbrelease_internal+0x168/frame 0xfffffe0024c13960
solisten_proto() at solisten_proto+0xc6/frame 0xfffffe0024c139c0
sctp_listen() at sctp_listen+0x4e6/frame 0xfffffe0024c13a30
solisten() at solisten+0x7a/frame 0xfffffe0024c13a70
kern_listen() at kern_listen+0x125/frame 0xfffffe0024c13ab0
ia32_syscall() at ia32_syscall+0x487/frame 0xfffffe0024c13bf0
int0x80_syscall_common() at int0x80_syscall_common+0x9c/frame 0x8142e7d
KDB: enter: panic
[ thread pid 794 tid 100091 ]
Stopped at kdb_enter+0x67: movq $0,0x1465766(%rip)
db>
db> set $lines = 0
db> set $maxwidth = 0
db> show registers
cs 0x20
ds 0x3b ll+0x1a
es 0x3b ll+0x1a
fs 0x13
gs 0x1b
ss 0
rax 0x12
rcx 0x80 ll+0x5f
rdx 0xffffffff818f1c39
rbx 0
rsp 0xfffffe0024c13830
rbp 0xfffffe0024c13850
rsi 0x1
rdi 0
r8 0
r9 0xffffffff
r10 0
r11 0xfffffe0024954a00
r12 0xffffffff82068dc0 ddb_dbbe
r13 0
r14 0xffffffff81939d65
r15 0xffffffff81939d65
rip 0xffffffff810b1957 kdb_enter+0x67
rflags 0x200086 kernphys+0x86
kdb_enter+0x67: movq $0,0x1465766(%rip)
db> show proc
Process 794 (syz-executor.0) at 0xfffff8003a28c530:
state: NORMAL
uid: 0 gids: 0, 0, 5
parent: pid 777 at 0xfffff80003c86a60
ABI: FreeBSD ELF32
arguments: /root/syz-executor.0
reaper: 0xfffff800032d4000 reapsubtree: 1
sigparent: 20
vmspace: 0xfffffe00049909e8
(map 0xfffffe00049909e8)
(map.pmap 0xfffffe0004990aa8)
(pmap 0xfffffe0004990b08)
threads: 1
100091 Run CPU 0 syz-executor.0
db> ps
pid ppid pgrp uid state wmesg wchan cmd
795 792 422 0 R CPU 1 kenv
794 777 777 0 R CPU 0 syz-executor.0
792 422 422 0 R sh
777 775 777 0 Rs syz-executor.0
775 773 773 0 S (threaded) syz-execprog
100106 S uwait 0xfffff800039aea80 syz-execprog
100107 S uwait 0xfffff80003bd3f00 syz-execprog
100108 S uwait 0xfffff80003bd9080 syz-execprog
100109 S uwait 0xfffff80003bd9180 syz-execprog
100110 S uwait 0xfffff80003bd9380 syz-execprog
100111 S kqread 0xfffff80003b58000 syz-execprog
100112 S uwait 0xfffff80003bd9580 syz-execprog
100113 S uwait 0xfffff80003bd9680 syz-execprog
100114 S uwait 0xfffff80003bd3600 syz-execprog
773 771 773 0 Ss pause 0xfffff8003a2885d8 csh
771 680 771 0 Ss select 0xfffff80003bd37c0 sshd
746 1 746 0 Ss+ ttyin 0xfffff800033f5cb0 getty
745 1 745 0 Ss+ ttyin 0xfffff80003a928b0 getty
744 1 744 0 Ss+ ttyin 0xfffff80003a92cb0 getty
743 1 743 0 Ss+ ttyin 0xfffff80003a950b0 getty
742 1 742 0 Ss+ ttyin 0xfffff80003a954b0 getty
741 1 741 0 Ss+ ttyin 0xfffff80003a958b0 getty
740 1 740 0 Ss+ ttyin 0xfffff80003a95cb0 getty
739 1 739 0 Ss+ ttyin 0xfffff80003a940b0 getty
738 1 738 0 Ss+ ttyin 0xfffff80003a944b0 getty
736 1 22 0 S+ piperd 0xfffff80003bf2000 logger
735 734 22 0 S+ nanslp 0xffffffff824ffcc1 sleep
734 1 22 0 S+ wait 0xfffff800032d4a60 sh
684 1 684 0 Ss nanslp 0xffffffff824ffcc0 cron
680 1 680 0 Ss select 0xfffff800039aedc0 sshd
493 1 493 0 Ss select 0xfffff80003be9240 syslogd
422 1 422 0 Ss wait 0xfffff80003bd1000 devd
421 1 421 65 Ss select 0xfffff80003195640 dhclient
336 1 336 0 Ss select 0xfffff80003be92c0 dhclient
333 1 333 0 Ss select 0xfffff800031956c0 dhclient
21 0 0 0 DL syncer 0xffffffff825d6158 [syncer]
20 0 0 0 DL vlruwt 0xfffff80003a70000 [vnlru]
19 0 0 0 DL (threaded) [bufdaemon]
100065 D qsleep 0xffffffff825d5658 [bufdaemon]
100070 D - 0xffffffff8200a980 [bufspacedaemon-0]
100080 D sdflush 0xfffff80003b5e0e8 [/ worker]
Process 795 (kenv) thread 0xfffffe0004d9e300 (100082)
shared lockmgr ufs (ufs) r = 0 (0xfffff80003988068) locked @ /syzkaller/managers/i386/kernel/sys/kern/vfs_subr.c:2922
shared lockmgr ufs (ufs) r = 0 (0xfffff8000398a438) locked @ /syzkaller/managers/i386/kernel/sys/kern/vfs_lookup.c:751
Process 794 (syz-executor.0) thread 0xfffffe0024954500 (100091)
exclusive sleep mutex socket (socket) r = 0 (0xfffffe00249111a8) locked @ /syzkaller/managers/i386/kernel/sys/netinet/sctp_usrreq.c:7285
exclusive sleep mutex sctp-inp (inp) r = 0 (0xfffff8003a89a968) locked @ /syzkaller/managers/i386/kernel/sys/netinet/sctp_usrreq.c:7283
db> show malloc
Type InUse MemUse Requests
devbuf 4213 4851K 4238
vtbuf 24 1968K 46
sysctloid 26636 1559K 26700
kobj 332 1328K 488
newblk 369 1116K 411
vfscache 4 1025K 4
inodedep 55 539K 78
pcb 23 539K 79
ufs_quota 1 512K 1
vfs_hash 1 512K 1
callout 2 512K 2
intr 4 388K 4
subproc 106 221K 854
acpica 1674 185K 50140
vnet_data 1 168K 1
pagedep 18 133K 22
tfo_ccache 1 128K 1
sem 4 106K 4
DEVFS1 102 102K 113
linker 222 89K 244
bus 964 78K 3311
mtx_pool 2 72K 2
syncache 1 68K 1
acpitask 1 64K 1
ddb_capture 1 64K 1
module 494 62K 494
filedesc 5 37K 17
gtaskqueue 22 34K 22
umtx 270 34K 270
hostcache 1 32K 1
shm 1 32K 1
DEVFS3 121 31K 131
msg 4 30K 4
kdtrace 154 30K 1650
DEVFS_RULE 56 27K 56
vmem 3 22K 4
kbdmux 6 22K 6
BPF 11 18K 11
temp 22 17K 1662
ufs_mount 3 17K 4
proc 3 17K 3
tty 16 16K 16
tidhash 1 16K 1
ifaddr 40 15K 42
ithread 89 15K 89
bus-sc 30 14K 1397
KTRACE 100 13K 100
kenv 95 12K 99
eventhandler 122 11K 122
pfs_nodes 20 10K 20
GEOM 60 10K 487
rman 82 10K 423
bmsafemap 4 9K 47
devstat 4 9K 4
UART 12 9K 12
rpc 2 8K 2
shmfd 1 8K 1
pfs_vncache 1 8K 1
audit_evclass 231 8K 289
lltable 20 7K 20
cred 28 7K 243
ifnet 4 7K 4
CAM DEV 3 6K 510
ether_multi 73 6K 78
routetbl 36 6K 40
vt 11 6K 11
kqueue 50 6K 800
sglist 5 6K 5
CAM queue 5 6K 1528
in6_multi 41 5K 41
ufs_dirhash 24 5K 24
plimit 18 5K 344
taskqueue 42 5K 42
dirrem 17 5K 28
memdesc 1 4K 1
MCA 32 4K 32
diradd 32 4K 43
evdev 4 4K 4
UMA 235 4K 235
hhook 13 4K 13
acpisem 22 3K 22
terminal 11 3K 11
session 21 3K 33
pgrp 21 3K 33
uidinfo 5 3K 5
proc-args 42 3K 507
local_apic 1 2K 1
io_apic 1 2K 1
ipsec-saq 2 2K 2
select 14 2K 14
CAM XPT 22 2K 543
lockf 15 2K 22
Unitno 25 2K 39
ip6ndp 8 2K 9
acpidev 20 2K 20
mkdir 10 2K 22
crypto 2 2K 2
msi 9 2K 9
softdep 1 1K 1
indirdep 4 1K 4
ipsecpolicy 1 1K 1
sahead 1 1K 1
secasvar 1 1K 1
sctp_ifa 8 1K 8
clone 8 1K 8
vnodemarker 2 1K 6
NFSD session 1 1K 1
CAM periph 4 1K 271
newdirblk 7 1K 11
in_multi 3 1K 4
toponodes 6 1K 6
isadev 6 1K 6
mount 16 1K 86
pci_link 10 1K 10
CAM SIM 2 1K 2
sctp_atcl 1 1K 2
pfil 4 1K 4
chacha20random 1 1K 1
epoch 4 1K 4
cdev 2 1K 2
encap_export_host 8 1K 8
mld 3 1K 3
sctp_ifn 3 1K 3
igmp 3 1K 3
tun 4 1K 4
osd 3 1K 9
sctp_timw 1 1K 1
vnodes 1 1K 1
NFSD lckfile 1 1K 1
NFSD V4client 1 1K 1
DEVFS 9 1K 10
inpcbpolicy 7 1K 143
feeder 7 1K 7
loginclass 3 1K 3
DEVFSP 3 1K 3
CAM path 4 1K 1034
apmdev 1 1K 1
atkbddev 2 1K 2
pmchooks 1 1K 1
prison 4 1K 4
CAM dev queue 2 1K 2
CAM I/O Scheduler 1 1K 1
soname 4 1K 5766
filecaps 4 1K 70
nexusdev 5 1K 5
entropy 2 1K 38
tcpfunc 1 1K 1
sctp_vrf 1 1K 1
vnet 1 1K 1
acpiintr 1 1K 1
pmc 1 1K 1
cpus 2 1K 2
freework 1 1K 26
sctp_atky 1 1K 3
vnet_data_free 1 1K 1
Per-cpu 1 1K 1
sctp_athm 1 1K 2
p1003.1b 1 1K 1
CAM CCB 0 0K 1769
savedino 0 0K 11
sentinel 0 0K 0
jfsync 0 0K 0
jtrunc 0 0K 0
sbdep 0 0K 2
jsegdep 0 0K 0
jseg 0 0K 0
jfreefrag 0 0K 0
jfreeblk 0 0K 0
jnewblk 0 0K 0
jmvref 0 0K 0
jremref 0 0K 0
jaddref 0 0K 0
freedep 0 0K 0
freefile 0 0K 9
freeblks 0 0K 25
sctp_socko 0 0K 1
sctp_iter 0 0K 5
sctp_mvrf 0 0K 0
sctp_cpal 0 0K 0
sctp_cmsg 0 0K 0
sctp_stre 0 0K 0
sctp_athi 0 0K 0
sctp_a_it 0 0K 5
sctp_aadr 0 0K 0
sctp_stro 0 0K 1
sctp_stri 0 0K 0
sctp_map 0 0K 2
statfs 0 0K 197
export_host 0 0K 0
cl_savebuf 0 0K 2
biobuf 0 0K 0
aios 0 0K 0
lio 0 0K 0
acl 0 0K 0
mfibuf 0 0K 0
mbuf_tag 0 0K 46
accf 0 0K 0
pts 0 0K 0
iov 0 0K 13302
ioctlops 0 0K 92
Witness 0 0K 0
stack 0 0K 0
md_sectors 0 0K 0
sbuf 0 0K 288
md_disk 0 0K 0
compressor 0 0K 0
malodev 0 0K 0
SWAP 0 0K 0
LED 0 0K 0
sysctltmp 0 0K 591
sysctl 0 0K 1
ekcd 0 0K 0
dumper 0 0K 0
rctl 0 0K 0
ix_sriov 0 0K 0
aacraidcam 0 0K 0
ix 0 0K 0
ipsbuf 0 0K 0
iirbuf 0 0K 0
cache 0 0K 0
aacraid_buf 0 0K 0
kcovinfo 0 0K 0

syzbot

unread,
Jun 14, 2020, 4:40:14 AM6/14/20
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 0d32fd8e Oops, r362158 committed a duplicate definition of..
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=12530571100000
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=13efc7c1100000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1013d401100000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+bca42a...@syzkaller.appspotmail.com

login: panic: sbflush_internal: ccc 0 mb 0 mbcnt 256
cpuid = 0
time = 1592123871
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame 0xfffffe002554e830
vpanic() at vpanic+0x1c7/frame 0xfffffe002554e890
panic() at panic+0x43/frame 0xfffffe002554e8f0
sbrelease_internal() at sbrelease_internal+0x168/frame 0xfffffe002554e930
sbdestroy() at sbdestroy+0x20/frame 0xfffffe002554e960
solisten_proto() at solisten_proto+0xc6/frame 0xfffffe002554e9c0
sctp_listen() at sctp_listen+0x4e6/frame 0xfffffe002554ea30
solisten() at solisten+0x7a/frame 0xfffffe002554ea70
kern_listen() at kern_listen+0x13c/frame 0xfffffe002554eab0
ia32_syscall() at ia32_syscall+0x24e/frame 0xfffffe002554ebf0
int0x80_syscall_common() at int0x80_syscall_common+0x9c/frame 0xffffdb88
KDB: enter: panic
[ thread pid 776 tid 100081 ]
Stopped at kdb_enter+0x67: movq $0,0x14a5046(%rip)
db>
db> set $lines = 0
db> set $maxwidth = 0
db> show registers
cs 0x20
ds 0x3b ll+0x1a
es 0x3b ll+0x1a
fs 0x13
gs 0x1b
ss 0
rax 0x12
rcx 0x80 ll+0x5f
rdx 0xffffffff8195e8a8
rbx 0
rsp 0xfffffe002554e810
rbp 0xfffffe002554e830
rsi 0x1
rdi 0
r8 0
r9 0xffffffff
r10 0
r11 0xfffffe0023bb8310
r12 0xffffffff82068f70 ddb_dbbe
r13 0
r14 0xffffffff819a9130
r15 0xffffffff819a9130
rip 0xffffffff810b4ba7 kdb_enter+0x67
rflags 0x200082 kernphys+0x82
kdb_enter+0x67: movq $0,0x14a5046(%rip)
db> show proc
Process 776 (syz-executor1776447) at 0xfffff80003c5e520:
state: NORMAL
uid: 0 gids: 0, 0, 5
parent: pid 774 at 0xfffff80016909000
ABI: FreeBSD ELF32
arguments: ./syz-executor177644779
reaper: 0xfffff80003318000 reapsubtree: 1
sigparent: 20
vmspace: 0xfffffe00257ae3d0
(map 0xfffffe00257ae3d0)
(map.pmap 0xfffffe00257ae490)
(pmap 0xfffffe00257ae4f0)
threads: 1
100081 Run CPU 0 syz-executor1776447
db> ps
pid ppid pgrp uid state wmesg wchan cmd
780 778 771 0 R CPU 1 syz-executor1776447
779 775 771 0 R syz-executor1776447
778 773 771 0 S nanslp 0xffffffff8252f1f1 syz-executor1776447
777 773 771 0 R syz-executor1776447
776 774 771 0 R CPU 0 syz-executor1776447
775 773 771 0 S nanslp 0xffffffff8252f1f1 syz-executor1776447
774 773 771 0 R syz-executor1776447
773 771 771 0 S nanslp 0xffffffff8252f1f1 syz-executor1776447
771 769 771 0 Ss pause 0xfffff80003c615c8 csh
769 682 769 0 Ss select 0xfffff80003db78c0 sshd
748 1 748 0 Ss+ ttyin 0xfffff800037b98b0 getty
747 1 747 0 Ss+ ttyin 0xfffff80003b35cb0 getty
746 1 746 0 Ss+ ttyin 0xfffff80003b384b0 getty
745 1 745 0 Ss+ ttyin 0xfffff80003b38cb0 getty
744 1 744 0 Ss+ ttyin 0xfffff800033c44b0 getty
743 1 743 0 Ss+ ttyin 0xfffff800033c4cb0 getty
742 1 742 0 Ss+ ttyin 0xfffff800033c34b0 getty
741 1 741 0 Ss+ ttyin 0xfffff800033c3cb0 getty
740 1 740 0 Ss+ ttyin 0xfffff800033c84b0 getty
738 1 24 0 S+ piperd 0xfffff80003c6c8e8 logger
737 736 24 0 S+ nanslp 0xffffffff8252f1f1 sleep
736 1 24 0 S+ wait 0xfffff80003cec000 sh
686 1 686 0 Ss nanslp 0xffffffff8252f1f0 cron
682 1 682 0 Ss select 0xfffff800039e16c0 sshd
495 1 495 0 Ss select 0xfffff80003da9440 syslogd
424 1 424 0 Ss select 0xfffff80003da9540 devd
423 1 423 65 Ss select 0xfffff80003da96c0 dhclient
338 1 338 0 Ss select 0xfffff800039e1640 dhclient
335 1 335 0 Ss select 0xfffff80003da9ec0 dhclient
23 0 0 0 DL vlruwt 0xfffff800033ef520 [vnlru]
22 0 0 0 DL syncer 0xffffffff8261a458 [syncer]
21 0 0 0 DL (threaded) [bufdaemon]
100069 D qsleep 0xffffffff826197a0 [bufdaemon]
100076 D - 0xffffffff8200aa00 [bufspacedaemon-0]
100086 D sdflush 0xfffff80003cf1ce8 [/ worker]
20 0 0 0 DL psleep 0xffffffff82640788 [vmdaemon]
19 0 0 0 DL (threaded) [pagedaemon]
100067 D psleep 0xffffffff82634c18 [dom0]
100074 D launds 0xffffffff82634c24 [laundry: dom0]
100075 D umarcl 0xffffffff8154f5a0 [uma]
18 0 0 0 DL - 0xffffffff82362e58 [rand_harvestq]
17 0 0 0 DL pftm 0xffffffff82c5a3a0 [pf purge]
16 0 0 0 DL waiting 0xffffffff8261cbd0 [sctp_iterator]
15 0 0 0 DL - 0xffffffff82618dac [soaiod4]
9 0 0 0 DL - 0xffffffff82618dac [soaiod3]
8 0 0 0 DL - 0xffffffff82618dac [soaiod2]
7 0 0 0 DL - 0xffffffff82618dac [soaiod1]
6 0 0 0 DL (threaded) [cam]
100033 D - 0xffffffff8223abc0 [doneq0]
100066 D - 0xffffffff8223aa90 [scanner]
5 0 0 0 DL crypto_ 0xfffff80003347690 [crypto returns 1]
4 0 0 0 DL crypto_ 0xfffff80003347630 [crypto returns 0]
3 0 0 0 DL crypto_ 0xffffffff82632400 [crypto]
14 0 0 0 DL seqstat 0xfffff800030e0488 [sequencer 00]
13 0 0 0 DL (threaded) [geom]
100024 D - 0xffffffff8250e180 [g_event]
100025 D - 0xffffffff8250e188 [g_up]
100026 D - 0xffffffff8250e190 [g_down]
2 0 0 0 DL (threaded) [KTLS]
100017 D - 0xfffff800030f7c00 [thr_0]
100018 D - 0xfffff800030f7c40 [thr_1]
12 0 0 0 WL (threaded) [intr]
100010 I [swi5: fast taskq]
100013 I [swi6: task queue]
100014 I [swi6: Giant taskq]
100019 I [swi4: clock (0)]
100020 I [swi4: clock (1)]
100021 I [swi3: vm]
100022 I [swi1: netisr 0]
100034 I [irq24: virtio_pci0]
100035 I [irq25: virtio_pci0]
100036 I [irq26: virtio_pci0]
100037 I [irq27: virtio_pci0]
100038 I [irq28: virtio_pci1]
100039 I [irq29: virtio_pci1]
100040 I [irq30: virtio_pci1]
100041 I [irq31: virtio_pci1]
100042 I [irq32: virtio_pci1]
100047 I [irq10: virtio_pci2]
100049 I [irq1: atkbd0]
100050 I [irq12: psm0]
100051 I [swi0: uart uart++]
100060 I [swi1: pf send]
100072 I [swi1: hpts]
100073 I [swi1: hpts]
11 0 0 0 RL (threaded) [idle]
100003 CanRun [idle: cpu0]
100004 CanRun [idle: cpu1]
1 0 1 0 SLs wait 0xfffff80003318000 [init]
10 0 0 0 DL audit_w 0xffffffff826328d8 [audit]
0 0 0 0 DLs (threaded) [kernel]
100000 D swapin 0xffffffff8250e710 [swapper]
100005 D - 0xfffff80003215e00 [if_config_tqg_0]
100006 D - 0xfffff80003215d00 [softirq_0]
100007 D - 0xfffff80003215c00 [softirq_1]
100008 D - 0xfffff80003215b00 [if_io_tqg_0]
100009 D - 0xfffff80003215a00 [if_io_tqg_1]
100011 D - 0xfffff8000334a000 [kqueue_ctx taskq]
100012 D - 0xfffff80003347e00 [aiod_kick taskq]
100015 D - 0xfffff80003347b00 [in6m_free taskq]
100016 D - 0xfffff80003347a00 [thread taskq]
100023 D - 0xfffff80003347900 [firmware taskq]
100028 D - 0xfffff80003347700 [crypto_0]
100029 D - 0xfffff80003347700 [crypto_1]
100043 D - 0xfffff80003347400 [vtnet0 rxq 0]
100044 D - 0xfffff80003347300 [vtnet0 txq 0]
100045 D - 0xfffff80003347200 [vtnet0 rxq 1]
100046 D - 0xfffff80003347100 [vtnet0 txq 1]
100048 D vtbslp 0xfffff8000351a580 [virtio_balloon]
100052 D - 0xfffff80003347000 [mca taskq]
100056 D - 0xffffffff81d4e801 [deadlkres]
100061 D - 0xfffff80003b26300 [acpi_task_0]
100062 D - 0xfffff80003b26300 [acpi_task_1]
100063 D - 0xfffff80003b26300 [acpi_task_2]
100065 D - 0xfffff80003347500 [CAM taskq]
db> show all locks
Process 780 (syz-executor1776447) thread 0xfffffe0025850700 (100112)
exclusive rw sctp-info (sctp-info) r = 0 (0xfffffe0004956b60) locked @ /syzkaller/managers/i386/kernel/sys/netinet/sctp_pcb.c:2520
Process 776 (syz-executor1776447) thread 0xfffffe0023bb7e00 (100081)
exclusive sleep mutex socket (socket) r = 0 (0xfffffe00239aee20) locked @ /syzkaller/managers/i386/kernel/sys/netinet/sctp_usrreq.c:7286
exclusive sleep mutex sctp-inp (inp) r = 0 (0xfffff8001699f968) locked @ /syzkaller/managers/i386/kernel/sys/netinet/sctp_usrreq.c:7284
db> show malloc
Type InUse MemUse Requests
pf_hash 5 11524K 5
devbuf 4212 4850K 4237
tcp_hpts 5 3201K 5
vtbuf 24 1968K 46
sysctloid 27849 1625K 27913
kobj 334 1336K 493
newblk 465 1140K 483
vfscache 4 1025K 4
pcb 27 544K 81
inodedep 48 536K 71
ufs_quota 1 512K 1
vfs_hash 1 512K 1
callout 2 512K 2
intr 4 472K 4
subproc 120 246K 848
acpica 1674 185K 55859
vnet_data 1 168K 1
pagedep 14 132K 18
tfo_ccache 1 128K 1
sem 4 106K 4
DEVFS1 101 101K 110
linker 239 96K 268
bus 972 79K 3360
mtx_pool 2 72K 2
syncache 1 68K 1
acpitask 1 64K 1
ddb_capture 1 64K 1
module 501 63K 501
temp 18 33K 1534
hostcache 1 32K 1
shm 1 32K 1
umtx 252 32K 252
kdtrace 160 31K 1616
msg 4 30K 4
DEVFS3 120 30K 130
DEVFS_RULE 56 27K 56
gtaskqueue 18 26K 18
vmem 3 22K 4
kbdmux 6 22K 6
BPF 10 18K 10
ufs_mount 4 17K 5
proc 3 17K 3
tty 16 16K 16
tidhash 1 16K 1
ithread 98 16K 98
bus-sc 30 14K 1439
ifaddr 32 13K 32
KTRACE 100 13K 100
kenv 95 12K 99
eventhandler 132 12K 132
pfs_nodes 20 10K 20
GEOM 60 10K 487
rman 82 10K 423
bmsafemap 3 9K 39
UART 12 9K 12
devstat 4 9K 4
rpc 2 8K 2
shmfd 1 8K 1
pfs_vncache 1 8K 1
audit_evclass 233 8K 291
CAM DEV 3 6K 510
vt 11 6K 11
cred 21 6K 234
sglist 5 6K 5
CAM queue 5 6K 1528
taskqueue 45 5K 45
ufs_dirhash 24 5K 24
dirrem 17 5K 28
plimit 17 5K 322
ifnet 3 5K 3
memdesc 1 4K 1
MCA 32 4K 32
UMA 248 4K 248
evdev 4 4K 4
filedesc 1 4K 1
lltable 11 4K 11
routetbl 14 4K 14
kqueue 53 4K 783
hhook 13 4K 13
ether_multi 40 4K 45
diradd 25 4K 36
pf_ifnet 5 3K 6
in6_multi 25 3K 25
acpisem 22 3K 22
terminal 11 3K 11
session 20 3K 31
pgrp 20 3K 31
uidinfo 3 3K 8
select 17 3K 17
local_apic 1 2K 1
io_apic 1 2K 1
ipsec-saq 2 2K 2
proc-args 39 2K 472
CAM XPT 22 2K 543
lockf 15 2K 22
Unitno 25 2K 37
acpidev 20 2K 20
msi 9 2K 9
softdep 1 1K 1
ipsecpolicy 1 1K 1
sahead 1 1K 1
secasvar 1 1K 1
sctp_atcl 2 1K 4
clone 8 1K 8
vnodemarker 2 1K 8
NFSD session 1 1K 1
CAM periph 4 1K 271
indirdep 3 1K 3
nhops 6 1K 6
toponodes 6 1K 6
isadev 6 1K 6
mount 16 1K 86
pci_link 10 1K 10
ip6ndp 4 1K 5
sctp_ifa 5 1K 5
crypto 3 1K 3
newdirblk 4 1K 8
mkdir 4 1K 16
sctp_timw 2 1K 2
in_multi 2 1K 3
pfil 4 1K 4
chacha20random 1 1K 1
CAM SIM 2 1K 2
epoch 4 1K 4
cdev 2 1K 2
encap_export_host 8 1K 8
osd 3 1K 9
mld 2 1K 2
sctp_ifn 2 1K 2
igmp 2 1K 2
vnodes 1 1K 1
NFSD lckfile 1 1K 1
NFSD V4client 1 1K 1
DEVFS 9 1K 10
feeder 7 1K 7
inpcbpolicy 6 1K 129
loginclass 3 1K 7
soname 5 1K 5790
CAM dev queue 2 1K 2
CAM I/O Scheduler 1 1K 1
apmdev 1 1K 1
atkbddev 2 1K 2
CAM path 4 1K 1034
tcpfunc 2 1K 2
ktls 1 1K 1
pmchooks 1 1K 1
prison 4 1K 4
DEVFSP 2 1K 2
filecaps 4 1K 66
tun 3 1K 3
nexusdev 5 1K 5
entropy 2 1K 35
freework 1 1K 26
sctp_vrf 1 1K 1
sctp_atky 2 1K 6
vnet 1 1K 1
acpiintr 1 1K 1
pmc 1 1K 1
cpus 2 1K 2
sctp_athm 2 1K 4
vnet_data_free 1 1K 1
Per-cpu 1 1K 1
p1003.1b 1 1K 1
pf_table 0 0K 0
pf_rule 0 0K 0
pf_altq 0 0K 0
pf_osfp 0 0K 0
pf_temp 0 0K 0
ath_hal 0 0K 0
madt_table 0 0K 2
athdev 0 0K 0
ata_pci 0 0K 0
ata_dma 0 0K 0
ata_generic 0 0K 0
amr 0 0K 0
scsi_da 0 0K 69
ata_da 0 0K 0
pvscsi 0 0K 0
smartpqi 0 0K 0
scsi_ch 0 0K 0
scsi_cd 0 0K 0
USBdev 0 0K 0
USB 0 0K 0
AHCI driver 0 0K 0
agp 0 0K 0
iavf 0 0K 0
ixl 0 0K 0
nvme_da 0 0K 0
acpipwr 0 0K 0
twsbuf 0 0K 0
twe_commands 0 0K 0
twa_commands 0 0K 0
tcp_log_dev 0 0K 0
ice-resmgr 0 0K 0
ice-osdep 0 0K 0
ice 0 0K 0
fpukern_ctx 0 0K 0
midi buffers 0 0K 0
xen_intr 0 0K 0
mixer 0 0K 0
xen_hvm 0 0K 0
legacydrv 0 0K 0
qpidrv 0 0K 0
ac97 0 0K 0
hdacc 0 0K 0
dmar_idpgtbl 0 0K 0
dmar_dom 0 0K 0
dmar_ctx 0 0K 0
dmar_dmamap 0 0K 0
hdac 0 0K 0
hdaa 0 0K 0
acpi_perf 0 0K 0
isci 0 0K 0
hyperv_socket 0 0K 0
bxe_ilt 0 0K 0
xenbus 0 0K 0
acpicmbat 0 0K 0
SIIS driver 0 0K 0
vm_fictitious 0 0K 0
CAM CCB 0 0K 1790
PUC 0 0K 0
ppbusdev 0 0K 0
agtiapi_MemAlloc malloc 0 0K 0
osti_cacheable 0 0K 0
tempbuff 0 0K 0
tempbuff 0 0K 0
UMAHash 0 0K 0
ag_tgt_map_t malloc 0 0K 0
ag_slr_map_t malloc 0 0K 0
vm_pgdata 0 0K 0
jblocks 0 0K 0
savedino 0 0K 12
sentinel 0 0K 0
jfsync 0 0K 0
jtrunc 0 0K 0
sbdep 0 0K 3
jsegdep 0 0K 0
jseg 0 0K 0
jfreefrag 0 0K 0
jfreeblk 0 0K 0
jnewblk 0 0K 0
jmvref 0 0K 0
jremref 0 0K 0
jaddref 0 0K 0
freedep 0 0K 0
freefile 0 0K 9
freeblks 0 0K 25
freefrag 0 0K 7
allocindir 0 0K 0
allocdirect 0 0K 0
ufs_trim 0 0K 0
mactemp 0 0K 0
audit_trigger 0 0K 0
audit_pipe_presel 0 0K 0
audit_pipeent 0 0K 0
audit_pipe 0 0K 0
audit_evname 0 0K 0
audit_bsm 0 0K 0
audit_gidset 0 0K 0
audit_text 0 0K 0
audit_path 0 0K 0
audit_data 0 0K 0
audit_cred 0 0K 0
xform 0 0K 0
NLM 0 0K 0
ipsec-spdcache 0 0K 0
ipsec-reg 0 0K 0
ipsec-misc 0 0K 0
ipsecrequest 0 0K 0
ip6opt 0 0K 3
ip6_msource 0 0K 0
ip6_moptions 0 0K 0
in6_mfilter 0 0K 0
frag6 0 0K 0
tcplog 0 0K 0
lDevFlags * malloc 0 0K 0
LRO 0 0K 0
sctp_mcore 0 0K 0
sctp_socko 0 0K 2
sctp_iter 0 0K 3
sctp_mvrf 0 0K 0
sctp_cpal 0 0K 0
sctp_cmsg 0 0K 0
sctp_stre 0 0K 0
sctp_athi 0 0K 0
sctp_a_it 0 0K 3
sctp_aadr 0 0K 0
sctp_stro 0 0K 2
sctp_stri 0 0K 0
sctp_map 0 0K 4
newreno data 0 0K 0
ip_msource 0 0K 0
ip_moptions 0 0K 0
in_mfilter 0 0K 0
ipid 0 0K 0
80211scan 0 0K 0
80211ratectl 0 0K 0
80211power 0 0K 0
80211nodeie 0 0K 0
80211node 0 0K 0
80211mesh_gt 0 0K 0
80211mesh_rt 0 0K 0
80211perr 0 0K 0
80211prep 0 0K 0
80211preq 0 0K 0
80211dfs 0 0K 0
80211crypto 0 0K 0
80211vap 0 0K 0
iflib 0 0K 0
vlan 0 0K 0
gif 0 0K 0
ifdescr 0 0K 0
zlib 0 0K 0
fadvise 0 0K 0
tiDeviceHandle_t * malloc 0 0K 0
statfs 0 0K 195
export_host 0 0K 0
cl_savebuf 0 0K 3
ag_portal_data_t malloc 0 0K 0
ag_device_t malloc 0 0K 0
STLock malloc 0 0K 0
CCB List 0 0K 0
sr_iov 0 0K 0
OCS 0 0K 0
OCS 0 0K 0
nvme 0 0K 0
nvd 0 0K 0
netmap 0 0K 0
mwldev 0 0K 0
MVS driver 0 0K 0
CAM ccb queue 0 0K 0
mrsasbuf 0 0K 0
mpt_user 0 0K 0
mps_user 0 0K 0
biobuf 0 0K 0
aios 0 0K 0
lio 0 0K 0
acl 0 0K 0
MPSSAS 0 0K 0
mbuf_tag 0 0K 25
accf 0 0K 0
pts 0 0K 0
iov 0 0K 12941
ioctlops 0 0K 85
Witness 0 0K 0
stack 0 0K 0
mps 0 0K 0
mpr_user 0 0K 0
MPRSAS 0 0K 0
mpr 0 0K 0
mfibuf 0 0K 0
md_sectors 0 0K 0
sbuf 0 0K 288
md_disk 0 0K 0
firmware 0 0K 0
compressor 0 0K 0
malodev 0 0K 0
SWAP 0 0K 0
LED 0 0K 0
sysctltmp 0 0K 574
sysctl 0 0K 1
ekcd 0 0K 0
dumper 0 0K 0
sendfile 0 0K 0
rctl 0 0K 0
ix_sriov 0 0K 0
aacraidcam 0 0K 0
ix 0 0K 0
ipsbuf 0 0K 0
iirbuf 0 0K 0
cache 0 0K 0
aacraid_buf 0 0K 0
kcovinfo 0 0K 0
prison_racct 0 0K 0
Fail Points 0 0K 0
sigio 0 0K 1
filedesc_to_leader 0 0K 0
pwd 0 0K 0
tty console 0 0K 0
aaccam 0 0K 0
aacbuf 0 0K 0
zstd 0 0K 0
nvlist 0 0K 0
SCSI ENC 0 0K 0
SCSI sa 0 0K 0
isofs_node 0 0K 0
isofs_mount 0 0K 0
tr_raid5_data 0 0K 0
tr_raid1e_data 0 0K 0
tr_raid1_data 0 0K 0
tr_raid0_data 0 0K 0
tr_concat_data 0 0K 0
md_sii_data 0 0K 0
md_promise_data 0 0K 0
md_nvidia_data 0 0K 0
md_jmicron_data 0 0K 0
md_intel_data 0 0K 0
md_ddf_data 0 0K 0
raid_data 0 0K 72
geom_flashmap 0 0K 0
NFS FHA 0 0K 0
db> show uma
Zone Size Used Free Requests Sleeps Bucket Total Mem XFree
mbuf_cluster 2048 9526 126 9526 0 254 19767296 0
mbuf_packet 256 8192 1206 24022 0 254 2405888 0
512 512 4180 20 4181 0 30 2150400 0
mbuf_jumbo_page 4096 0 508 10 0 254 2080768 0
BUF TRIE 144 165 13331 473 0 62 1943424 0
4096 4096 393 3 1729 0 2 1622016 0
128 128 9251 80 14947 0 126 1194368 0
sctp_asoc 2288 0 510 2 0 254 1166880 0
pbuf 832 0 969 0 0 2 806208 0
UMA Slabs 0 112 6729 33 6729 0 126 757344 0
sctp_ep 1280 3 507 3 0 254 652800 0
tcpcb 1040 3 514 7 0 254 537680 0
socket 904 17 496 1164 0 254 463752 0
65536 65536 6 0 6 0 1 393216 0
sctp_raddr 736 2 515 2 0 254 380512 0
RADIX NODE 144 2053 184 19393 0 62 322128 0
256 Bucket 2048 131 13 361 0 8 294912 0
VNODE 488 528 48 539 0 30 281088 0
VM OBJECT 264 934 26 12461 0 30 253440 0
tcp_inpcb 488 3 509 7 0 254 249856 0
udp_inpcb 488 2 510 118 0 254 249856 0
THREAD 1792 112 14 112 0 8 225792 0
mbuf 256 388 384 2007 0 254 197632 0
64 64 2752 335 3722 0 254 197568 0
65536 65536 1 2 52 0 1 196608 0
128 128 1275 244 25581 0 126 194432 0
16 16 11706 294 11922 0 254 192000 0
UMA Zones 768 222 4 222 0 16 173568 0
32 32 4432 482 4619 0 254 157248 0
1024 1024 129 15 139 0 16 147456 0
FFS2 dinode 256 499 71 508 0 62 145920 0
256 256 466 104 501 0 62 145920 0
65536 65536 2 0 2 0 1 131072 0
2048 2048 7 57 2561 0 8 131072 0
unpcb 256 7 503 1015 0 254 130560 0
ripcb 488 1 255 4 0 254 124928 0
MAP ENTRY 96 913 347 37271 0 126 120960 0
ksiginfo 112 43 1001 59 0 126 116928 0
vmem btag 56 1921 154 1921 0 254 116200 0
128 128 559 216 1459 0 126 99200 0
FFS inode 160 499 76 508 0 62 92000 0
PROC 1312 52 14 780 0 8 86592 0
g_bio 408 0 210 4811 0 30 85680 0
128 Bucket 1024 38 45 204 0 16 84992 0
VMSPACE 2536 30 3 760 0 4 83688 0
UMA Kegs 384 208 7 208 0 30 82560 0
S VFS Cache 108 583 173 1107 0 126 81648 0
256 256 266 49 1064 0 62 80640 0
filedesc0 1088 53 17 781 0 8 76160 0
1024 1024 10 58 281 0 16 69632 0
64 64 607 464 14301 0 254 68544 0
128 128 309 218 392 0 126 67456 0
65536 65536 0 1 112 0 1 65536 0
32768 32768 2 0 2 0 1 65536 0
16384 16384 3 1 4 0 1 65536 0
16384 16384 4 0 4 0 1 65536 0
4096 4096 15 1 28 0 2 65536 0
8192 8192 6 1 8 0 1 57344 0
64 64 286 533 1061 0 254 52416 0
64 64 445 374 679 0 254 52416 0
128 128 317 86 352 0 126 51584 0
256 256 64 131 189 0 62 49920 0
32 Bucket 256 31 164 375 0 62 49920 0
DIRHASH 1024 34 14 34 0 16 49152 0
NAMEI 1024 0 48 11460 0 16 49152 0
512 512 69 27 210 0 30 49152 0
512 512 71 25 392 0 30 49152 0
syncache 168 0 264 5 0 254 44352 0
8192 8192 4 1 32 0 1 40960 0
clpbuf 832 0 48 110 0 16 39936 0
sctp_readq 152 2 258 2 0 254 39520 0
64 Bucket 512 57 15 402 0 30 36864 0
selfd 64 38 529 3998 0 254 36288 0
64 64 12 555 26 0 254 36288 0
64 64 12 555 36 0 254 36288 0
64 64 33 534 65 0 254 36288 0
64 64 28 539 69 0 254 36288 0
128 128 19 260 77 0 126 35712 0
128 128 13 266 14 0 126 35712 0
128 128 62 217 67 0 126 35712 0
routing nhops 256 8 127 18 0 62 34560 0
ttyoutq 256 72 63 160 0 62 34560 0
256 256 33 102 356 0 62 34560 0
256 256 22 113 681 0 62 34560 0
256 256 64 71 156 0 62 34560 0
256 256 9 126 1225 0 62 34560 0
256 256 70 65 633 0 62 34560 0
32768 32768 1 0 1 0 1 32768 0
32768 32768 0 1 112 0 1 32768 0
4096 4096 8 0 12 0 2 32768 0
2048 2048 4 12 16 0 8 32768 0
2048 2048 5 11 6 0 8 32768 0
2048 2048 3 13 194 0 8 32768 0
2048 2048 4 12 4 0 8 32768 0
1024 1024 2 30 31 0 16 32768 0
1024 1024 9 23 865 0 16 32768 0
1024 1024 4 28 22 0 16 32768 0
1024 1024 6 26 8 0 16 32768 0
512 512 1 63 4 0 30 32768 0
512 512 4 60 28 0 30 32768 0
512 512 19 45 20 0 30 32768 0
512 512 4 60 514 0 30 32768 0
mt_stats_zone 64 443 69 443 0 254 32768 0
64 pcpu 8 3393 703 3395 0 254 32768 0
ttyinq 160 135 65 300 0 62 32000 0
cpuset 104 7 272 7 0 126 29016 0
sctp_laddr 48 0 588 4 0 254 28224 0
hostcache 96 1 293 1 0 254 28224 0
32 32 313 569 375 0 254 28224 0
4 Bucket 48 6 582 4463 0 254 28224 0
KMAP ENTRY 96 12 279 12 0 126 27936 0
rtentry 208 14 119 18 0 62 27664 0
pipe 760 7 28 280 0 16 26600 0
TURNSTILE 136 127 62 127 0 62 25704 0
8192 8192 3 0 3 0 1 24576 0
4096 4096 2 4 197 0 2 24576 0
rl_entry 40 30 576 30 0 254 24240 0
8 Bucket 80 40 260 6548 0 126 24000 0
Mountpoints 2816 2 6 2 0 4 22528 0
SLEEPQUEUE 88 127 129 127 0 126 22528 0
udpcb 32 2 628 118 0 254 20160 0
PWD 32 10 620 98 0 254 20160 0
Files 72 72 208 6305 0 126 20160 0
32 32 42 588 1135 0 254 20160 0
32 32 39 591 130 0 254 20160 0
32 32 34 596 793 0 254 20160 0
32 32 42 588 2881 0 254 20160 0
32 32 30 600 810 0 254 20160 0
16 Bucket 144 40 100 142 0 62 20160 0
2 Bucket 32 38 592 7775 0 254 20160 0
KNOTE 160 0 125 7 0 62 20000 0
procdesc 136 1 144 6 0 62 19720 0
epoch_record pcpu 256 4 60 4 0 62 16384 0
16384 16384 1 0 1 0 1 16384 0
16384 16384 0 1 136 0 1 16384 0
8192 8192 2 0 2 0 1 16384 0
8192 8192 1 1 82 0 1 16384 0
8192 8192 2 0 2 0 1 16384 0
4096 4096 0 4 3 0 2 16384 0
4096 4096 2 2 2 0 2 16384 0
2048 2048 7 1 7 0 8 16384 0
1024 1024 1 15 1 0 16 16384 0
1024 1024 1 15 1 0 16 16384 0
512 512 11 21 11 0 30 16384 0
vtnet_tx_hdr 24 0 668 1063 0 254 16032 0
mt_zone 24 443 225 443 0 254 16032 0
MAP 216 2 69 2 0 62 15336 0
FPU_save_area 832 1 17 1 0 16 14976 0
vmem 1856 1 7 1 0 8 14848 0
32 32 20 358 39 0 254 12096 0
16 16 11 739 45 0 254 12000 0
16 16 30 720 71 0 254 12000 0
16 16 258 492 415 0 254 12000 0
16 16 16 734 40 0 254 12000 0
16 16 26 724 25422 0 254 12000 0
16 16 15 735 279 0 254 12000 0
8192 8192 1 0 1 0 1 8192 0
8192 8192 1 0 1 0 1 8192 0
4096 4096 1 1 1 0 2 8192 0
4096 4096 1 1 1 0 2 8192 0
SMR CPU 32 1 254 1 0 254 8160 0
16 16 185 315 1239 0 254 8000 0
SMR SHARED 24 1 254 1 0 254 6120 0
2048 2048 0 2 32 0 8 4096 0
UMA Slabs 1 176 8 14 8 0 62 3872 0
int pcpu 4 34 478 34 0 254 2048 0
FFS1 dinode 128 0 0 0 0 126 0 0
swblk 136 0 0 0 0 62 0 0
swpctrie 144 0 0 0 0 62 0 0
pf state scrubs 40 0 0 0 0 254 0 0
pf frag entries 40 0 0 0 0 254 0 0
pf frags 256 0 0 0 0 62 0 0
pf table entries 160 0 0 0 0 62 0 0
pf table entry counters 64 0 0 0 0 254 0 0
pf source nodes 136 0 0 0 0 254 0 0
pf state keys 88 0 0 0 0 126 0 0
pf states 296 0 0 0 0 254 0 0
pf tags 104 0 0 0 0 126 0 0
pf mtags 48 0 0 0 0 254 0 0
tcp_bbr_pcb 832 0 0 0 0 16 0 0
tcp_bbr_map 128 0 0 0 0 126 0 0
IPsec SA lft_c 16 0 0 0 0 254 0 0
udplite_inpcb 488 0 0 0 0 254 0 0
sctp_asconf_ack 48 0 0 0 0 254 0 0
sctp_asconf 40 0 0 0 0 254 0 0
sctp_stream_msg_out 112 0 0 0 0 254 0 0
sctp_chunk 152 0 0 0 0 254 0 0
tcp_log_node 120 0 0 0 0 126 0 0
tcp_log_bucket 184 0 0 0 0 62 0 0
tcp_log 416 0 0 0 0 254 0 0
tcpreass 48 0 0 0 0 254 0 0
tfo_ccache_entries 80 0 0 0 0 126 0 0
tfo 4 0 0 0 0 254 0 0
sackhole 32 0 0 0 0 254 0 0
tcptw 88 0 0 0 0 254 0 0
ipq 56 0 0 0 0 254 0 0
itimer 352 0 0 0 0 30 0 0
AIOLIO 280 0 0 0 0 30 0 0
AIOCB 752 0 0 0 0 16 0 0
AIOP 32 0 0 0 0 254 0 0
AIO 208 0 0 0 0 62 0 0
NCLNODE 592 0 0 0 0 16 0 0
rentr 24 0 0 0 0 254 0 0
LTS VFS Cache 368 0 0 0 0 30 0 0
L VFS Cache 328 0 0 0 0 30 0 0
STS VFS Cache 148 0 0 0 0 62 0 0
VNODEPOLL 120 0 0 0 0 126 0 0
crypto_session 72 0 0 0 0 126 0 0
cryptop 272 0 0 0 0 30 0 0
nvme_request 128 0 0 0 0 126 0 0
DMAR_MAP_ENTRY 128 0 0 0 0 126 0 0
ktls_session 192 0 0 0 0 62 0 0
mbuf_jumbo_16k 16384 0 0 0 0 254 0 0
mbuf_jumbo_9k 9216 0 0 0 0 254 0 0
audit_record 1280 0 0 0 0 8 0 0
domainset 40 0 0 0 0 254 0 0
MAC labels 40 0 0 0 0 254 0 0
vnpbuf 832 0 0 0 0 62 0 0
mdpbuf 832 0 0 0 0 4 0 0
nfspbuf 832 0 0 0 0 16 0 0
swwbuf 832 0 0 0 0 8 0 0
swrbuf 832 0 0 0 0 16 0 0
umtx_shm 88 0 0 0 0 126 0 0
umtx pi 96 0 0 0 0 126 0 0
rangeset pctrie nodes 144 0 0 0 0 62 0 0
65536 65536 0 0 0 0 1 0 0
65536 65536 0 0 0 0 1 0 0
65536 65536 0 0 0 0 1 0 0
65536 65536 0 0 0 0 1 0 0
32768 32768 0 0 0 0 1 0 0
32768 32768 0 0 0 0 1 0 0
32768 32768 0 0 0 0 1 0 0
32768 32768 0 0 0 0 1 0 0
32768 32768 0 0 0 0 1 0 0
16384 16384 0 0 0 0 1 0 0
16384 16384 0 0 0 0 1 0 0
16384 16384 0 0 0 0 1 0 0
16384 16384 0 0 0 0 1 0 0
2048 2048 0 0 0 0 8 0 0
fakepg 104 0 0 0 0 126 0 0
UMA Hash 256 0 0 0 0 62 0 0

Mark Johnston

unread,
Sep 7, 2021, 5:31:52 PM9/7/21
to syzbot, syzkaller-f...@googlegroups.com
#syz dup: panic: mtx_lock() of spin mutex (null) @ /syzkaller/managers/main/kernel/sys/netinet/tcp_output.c:LINE
Reply all
Reply to author
Forward
0 new messages