panic: Assertion (t->parent->p_treeflag & P_TREE_REAPER) != NUM failed at /syzkaller/managers/main/kernel/sys/kern/kern_

0 views
Skip to first unread message

syzbot

unread,
Apr 29, 2022, 1:45:21 AM4/29/22
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 9fb40baf6043 cam_periph: Return ENXIO when peripheral is i..
git tree: freebsd-src
console output: https://syzkaller.appspot.com/x/log.txt?x=1283b05af00000
dashboard link: https://syzkaller.appspot.com/bug?extid=5ac6a8777481bbe86395

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+5ac6a8...@syzkaller.appspotmail.com

panic: Assertion (t->parent->p_treeflag & P_TREE_REAPER) != 0 failed at /syzkaller/managers/main/kernel/sys/kern/kern_procctl.c:383
cpuid = 1
time = 325
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0xc7/frame 0xfffffe009f1c6690
kdb_backtrace() at kdb_backtrace+0xd3/frame 0xfffffe009f1c67f0
vpanic() at vpanic+0x2b8/frame 0xfffffe009f1c68d0
panic() at panic+0xb5/frame 0xfffffe009f1c6990
reap_kill() at reap_kill+0x9fe/frame 0xfffffe009f1c6ba0
kern_procctl() at kern_procctl+0x535/frame 0xfffffe009f1c6c10
sys_procctl() at sys_procctl+0x247/frame 0xfffffe009f1c6d30
amd64_syscall() at amd64_syscall+0x40c/frame 0xfffffe009f1c6f30
fast_syscall_common() at fast_syscall_common+0xf8/frame 0xfffffe009f1c6f30
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x28a42a, rsp = 0x83123bf08, rbp = 0x83123bf70 ---
KDB: enter: panic
[ thread pid 38845 tid 143428 ]
Stopped at kdb_enter+0x6b: movq $0,0x27048aa(%rip)
db>
db> set $lines = 0
db> set $maxwidth = 0
db> show registers
cs 0x20
ds 0x3b
es 0x3b
fs 0x13
gs 0x1b
ss 0x28
rax 0x12
rcx 0x28abe563d0c752cf
rdx 0x3ffff
rbx 0
rsp 0xfffffe009f1c67d0
rbp 0xfffffe009f1c67f0
rsi 0x40001
rdi 0xffffffff817825fa vprintf+0x35a
r8 0
r9 0xffffffff
r10 0
r11 0xfffffe0058dc6190
r12 0xfffffe00a7e9ae40
r13 0xfffffe009f1c6801
r14 0xffffffff82bc9b00 .str.26
r15 0xffffffff82bc9b00 .str.26
rip 0xffffffff81775b6b kdb_enter+0x6b
rflags 0x46
kdb_enter+0x6b: movq $0,0x27048aa(%rip)
db> show proc
Process 38845 (syz-executor.0) at 0xfffffe009f240000:
state: NORMAL
uid: 0 gids: 0, 0, 5
parent: pid 779 at 0xfffffe009ea31000
ABI: FreeBSD ELF64
flag: 0x10080480 flag2: 0
arguments: /root/syz-executor.0 exec
reaper: 0xfffffe0053df0000 reapsubtree: 1
sigparent: 20
vmspace: 0xfffffe00a7f0b000
(map 0xfffffe00a7f0b000)
(map.pmap 0xfffffe00a7f0b0c0)
(pmap 0xfffffe00a7f0b128)
threads: 2
143360 s syz-executor.0
143428 Run CPU 1 syz-executor.0
db> ps
pid ppid pgrp uid state wmesg wchan cmd
38848 780 780 0 R (threaded) syz-executor.1
143230 RunQ syz-executor.1
143431 S connec 0xfffffe009c30e0da syz-executor.1
143434 S uwait 0xfffffe00a66f4b00 syz-executor.1
38846 857 857 0 R (threaded) syz-executor.3
138972 RunQ syz-executor.3
143430 S connec 0xfffffe0058c9a85a syz-executor.3
143433 S uwait 0xfffffe00a66f5d80 syz-executor.3
38845 779 38845 0 Ts (threaded) syz-executor.0
143360 s syz-executor.0
143428 Run CPU 1 syz-executor.0
34038 0 0 0 DL (threaded) [zfskern]
135660 D t->zthr 0xfffffe00a6a68348 [arc_evict]
137212 D t->zthr 0xfffffe00a6a68948 [arc_reap]
137213 D - 0xfffffe00a5d65500 [dbu_evict]
137214 D dbuf_ev 0xffffffff85840120 [dbuf_evict_thread]
137215 D - 0xfffffe00a5f7a700 [z_vdev_file_0]
137216 D - 0xfffffe00a5f7a700 [z_vdev_file_1]
137217 D - 0xfffffe00a5f7a700 [z_vdev_file_2]
137218 D - 0xfffffe00a5f7a700 [z_vdev_file_3]
137219 D - 0xfffffe00a5f7a700 [z_vdev_file_4]
137220 D - 0xfffffe00a5f7a700 [z_vdev_file_5]
137221 D - 0xfffffe00a5f7a700 [z_vdev_file_6]
137222 D - 0xfffffe00a5f7a700 [z_vdev_file_7]
137223 D - 0xfffffe00a5f7a700 [z_vdev_file_8]
137224 D - 0xfffffe00a5f7a700 [z_vdev_file_9]
137225 D - 0xfffffe00a5f7a700 [z_vdev_file_10]
137226 D - 0xfffffe00a5f7a700 [z_vdev_file_11]
137227 D - 0xfffffe00a5f7a700 [z_vdev_file_12]
137228 D - 0xfffffe00a5f7a700 [z_vdev_file_13]
137229 D - 0xfffffe00a5f7a700 [z_vdev_file_14]
137230 D - 0xfffffe00a5f7a700 [z_vdev_file_15]
137231 D l2arc_f 0xffffffff8582f240 [l2arc_feed_thread]
137232 D - 0xfffffe009e92b500 [zfsvfs]
137233 S zevent_ 0xffffffff85840cc0 [sysevent]
17576 1 779 0 RE syz-executor.0
17544 1 814 0 RE syz-executor.2
17526 1 814 0 RE syz-executor.2
17514 1 814 0 RE syz-executor.2
17074 0 0 0 DL - 0xffffffff83f677c0 [soaiod4]
17073 0 0 0 DL - 0xffffffff83f677c0 [soaiod3]
17072 0 0 0 DL - 0xffffffff83f677c0 [soaiod2]
17071 0 0 0 DL - 0xffffffff83f677c0 [soaiod1]
857 774 857 0 Rs syz-executor.3
824 0 0 0 DL aiordy 0xfffffe0056f9d000 [aiod4]
823 0 0 0 DL aiordy 0xfffffe009ea31a90 [aiod3]
821 0 0 0 DL aiordy 0xfffffe0058cc6000 [aiod2]
820 0 0 0 DL aiordy 0xfffffe009f240548 [aiod1]
814 774 814 0 Rs syz-executor.2
780 774 780 0 Rs syz-executor.1
779 774 779 0 Rs syz-executor.0
774 772 772 0 R (threaded) syz-fuzzer
100093 RunQ syz-fuzzer
100117 S uwait 0xfffffe0057894600 syz-fuzzer
100118 S uwait 0xfffffe0057894700 syz-fuzzer
100119 S uwait 0xfffffe0057894800 syz-fuzzer
100120 S uwait 0xfffffe0057894900 syz-fuzzer
100121 S uwait 0xfffffe0057894a00 syz-fuzzer
100122 S uwait 0xfffffe0057894b00 syz-fuzzer
100123 S uwait 0xfffffe0058cbde80 syz-fuzzer
100124 S kqread 0xfffffe0058b5f400 syz-fuzzer
772 770 772 0 REs CPU 0 csh
770 688 770 0 Rs sshd
754 1 754 0 Rs+ getty
753 1 753 0 Rs+ getty
752 1 752 0 Rs+ getty
751 1 751 0 Rs+ getty
750 1 750 0 Rs+ getty
749 1 749 0 Rs+ getty
748 1 748 0 Rs+ getty
747 1 747 0 Rs+ getty
746 1 746 0 Rs+ getty
692 1 692 0 Rs cron
688 1 688 0 Rs sshd
501 1 501 0 Rs syslogd
430 1 430 0 Rs devd
429 1 429 65 Rs dhclient
344 1 344 0 Rs dhclient
341 1 341 0 Rs dhclient
17 0 0 0 DL vlruwt 0xfffffe0056f9e548 [vnlru]
16 0 0 0 DL syncer 0xffffffff83f6d2e0 [syncer]
15 0 0 0 DL (threaded) [bufdaemon]
100079 D psleep 0xffffffff83f6b8e0 [bufdaemon]
100082 D - 0xffffffff83211f80 [bufspacedaemon-0]
100095 D sdflush 0xfffffe0058ce3ce8 [/ worker]
9 0 0 0 DL psleep 0xffffffff83f9f400 [vmdaemon]
8 0 0 0 DL (threaded) [pagedaemon]
100077 D psleep 0xffffffff83f932b8 [dom0]
100083 D launds 0xffffffff83f932c4 [laundry: dom0]
100084 D umarcl 0xffffffff81eb1ca0 [uma]
7 0 0 0 DL - 0xffffffff83c03788 [rand_harvestq]
6 0 0 0 DL pftm 0xffffffff84993530 [pf purge]
5 0 0 0 DL waiting 0xffffffff847c54a0 [sctp_iterator]
4 0 0 0 DL (threaded) [cam]
100044 D - 0xffffffff83aa56c0 [doneq0]
100045 D - 0xffffffff83aa5640 [async]
100076 D - 0xffffffff83aa54c0 [scanner]
14 0 0 0 DL seqstat 0xfffffe0056f01c88 [sequencer 00]
3 0 0 0 DL (threaded) [crypto]
100040 D crypto_ 0xffffffff83f8eac0 [crypto]
100041 D crypto_ 0xfffffe0053f73030 [crypto returns 0]
100042 D crypto_ 0xfffffe0053f73080 [crypto returns 1]
13 0 0 0 DL (threaded) [geom]
100035 D - 0xffffffff83e1d000 [g_event]
100036 D - 0xffffffff83e1d020 [g_up]
100037 D - 0xffffffff83e1d040 [g_down]
2 0 0 0 WL (threaded) [clock]
100029 I [clock (0)]
100030 I [clock (1)]
12 0 0 0 WL (threaded) [intr]
100015 I [swi5: fast taskq]
100018 I [swi6: task queue]
100019 I [swi6: Giant taskq]
100031 I [swi1: netisr 0]
100032 I [swi1: hpts]
100033 I [swi1: hpts]
100046 I [irq24: virtio_pci0]
100047 I [irq25: virtio_pci0]
100048 I [irq26: virtio_pci0]
100049 I [irq27: virtio_pci0]
100050 I [irq28: virtio_pci1]
100051 I [irq29: virtio_pci1]
100052 I [irq30: virtio_pci1]
100053 I [irq31: virtio_pci1]
100054 I [irq32: virtio_pci1]
100059 I [irq33: virtio_pci2]
100060 I [irq34: virtio_pci2]
100061 I [irq35: virtio_pci2]
100063 I [irq1: atkbd0]
100064 I [irq12: psm0]
100065 I [swi0: uart uart++]
100069 I [swi1: pf send]
11 0 0 0 RL (threaded) [idle]
100003 CanRun [idle: cpu0]
100004 CanRun [idle: cpu1]
1 0 1 0 RLs [init]
10 0 0 0 DL audit_w 0xffffffff83f8f5c0 [audit]
0 0 0 0 DLs (threaded) [kernel]
100000 D swapin 0xffffffff83e1da40 [swapper]
100005 D - 0xfffffe0008191000 [if_config_tqg_0]
100006 D - 0xfffffe0008190e00 [softirq_0]
100007 D - 0xfffffe0008190d00 [softirq_1]
100008 D - 0xfffffe0008190c00 [if_io_tqg_0]
100009 D - 0xfffffe0008190b00 [if_io_tqg_1]
100010 D - 0xfffffe0008190a00 [inm_free taskq]
100011 D - 0xfffffe0008190900 [linuxkpi_irq_wq]
100012 D - 0xfffffe0008190800 [in6m_free taskq]
100013 D - 0xfffffe0008190700 [deferred_unmount ta]
100014 D - 0xfffffe0008190600 [thread taskq]
100016 D - 0xfffffe0008190400 [kqueue_ctx taskq]
100017 D - 0xfffffe0008190300 [pci_hp taskq]
100020 D - 0xfffffe0008190000 [aiod_kick taskq]
100021 D - 0xfffffe000818fe00 [linuxkpi_short_wq_0]
100022 D - 0xfffffe000818fe00 [linuxkpi_short_wq_1]
100023 D - 0xfffffe000818fe00 [linuxkpi_short_wq_2]
100024 D - 0xfffffe000818fe00 [linuxkpi_short_wq_3]
100025 D - 0xfffffe000818fd00 [linuxkpi_long_wq_0]
100026 D - 0xfffffe000818fd00 [linuxkpi_long_wq_1]
100027 D - 0xfffffe000818fd00 [linuxkpi_long_wq_2]
100028 D - 0xfffffe000818fd00 [linuxkpi_long_wq_3]
100034 D - 0xfffffe000818fc00 [firmware taskq]
100038 D - 0xfffffe000818f200 [crypto_0]
100039 D - 0xfffffe000818f200 [crypto_1]
100055 D - 0xfffffe000818e900 [vtnet0 rxq 0]
100056 D - 0xfffffe000818e800 [vtnet0 txq 0]
100057 D - 0xfffffe000818e700 [vtnet0 rxq 1]
100058 D - 0xfffffe000818e600 [vtnet0 txq 1]
100062 D vtbslp 0xfffffe0056f4be00 [virtio_balloon]
100066 D - 0xffffffff82bcf981 [deadlkres]
100070 D - 0xfffffe0008191100 [mca taskq]
100072 D - 0xfffffe000818eb00 [acpi_task_0]
100073 D - 0xfffffe000818eb00 [acpi_task_1]
100074 D - 0xfffffe000818eb00 [acpi_task_2]
100075 D - 0xfffffe000818ea00 [CAM taskq]
137207 D - 0xfffffe00a6ae5200 [system_taskq_0]
137208 D - 0xfffffe00a6ae5200 [system_taskq_1]
137209 D - 0xfffffe00a5fd4900 [system_delay_taskq_]
137210 D - 0xfffffe00a5fd4900 [system_delay_taskq_]
137211 D - 0xfffffe00a5e75000 [arc_prune]
17519 1 814 0 Z syz-executor.2
17532 1 814 0 Z syz-executor.2
17538 1 814 0 Z syz-executor.2
17547 1 779 0 Z syz-executor.0
17552 1 814 0 Z syz-executor.2
17554 1 779 0 Z syz-executor.0
17557 1 814 0 Z syz-executor.2
17562 1 779 0 Z syz-executor.0
17564 1 814 0 Z syz-executor.2
17567 1 779 0 Z syz-executor.0
17573 1 779 0 Z syz-executor.0
17582 1 779 0 Z syz-executor.0
17586 1 779 0 Z syz-executor.0
4371 1 4371 65 Z dhclient
4398 1 4398 0 Z dhclient
4401 1 4401 0 Z dhclient
6611 1 6611 65 Z dhclient
6630 1 6630 0 Z dhclient
6634 1 6634 0 Z dhclient
38710 1 814 0 Z syz-executor.2
17209 1 857 0 Z syz-executor.3
17216 1 857 0 Z syz-executor.3
17217 1 857 0 Z syz-executor.3
17222 1 857 0 Z syz-executor.3
1932 1 1932 0 Z dhclient
1940 1 1940 0 Z dhclient
33692 1 33692 0 Z syz-executor.1
7068 1 7068 65 Z dhclient
33693 1 33693 0 Z syz-executor.1
5046 1 5046 65 Z dhclient
5075 1 5075 0 Z dhclient
5078 1 5078 0 Z dhclient
db> show all locks
Process 38845 (syz-executor.0) thread 0xfffffe00a7e9ae40 (143428)
shared sx proctree (proctree) r = 0 (0xffffffff83209a40) locked @ /syzkaller/managers/main/kernel/sys/kern/kern_procctl.c:253
exclusive sx sapblk (sapblk) r = 0 (0xffffffff83e35e00) locked @ /syzkaller/managers/main/kernel/sys/kern/kern_proc.c:3405
Process 17544 (syz-executor.2) thread 0xfffffe009f3b4c80 (118880)
exclusive sleep mutex pmap (pmap) r = 0 (0xfffffe00a66e4128) locked @ /syzkaller/managers/main/kernel/sys/amd64/amd64/pmap.c:8305
Process 17526 (syz-executor.2) thread 0xfffffe00a66ef560 (118871)
exclusive sleep mutex pmap (pmap) r = 0 (0xfffffe00a66e4b20) locked @ /syzkaller/managers/main/kernel/sys/amd64/amd64/pmap.c:8305
Process 17514 (syz-executor.2) thread 0xfffffe009f3b5ac0 (118610)
exclusive sleep mutex pmap (pmap) r = 0 (0xfffffe00a66c4128) locked @ /syzkaller/managers/main/kernel/sys/amd64/amd64/pmap.c:8305
Process 772 (csh) thread 0xfffffe0058cbb020 (100101)
exclusive sleep mutex pmap (pmap) r = 0 (0xfffffe009ec42128) locked @ /syzkaller/managers/main/kernel/sys/amd64/amd64/pmap.c:8305
db> show malloc
Type InUse MemUse Requests
pf_hash 5 11524K 5
linker 380 9856K 1032
tcp_hpts 7 4801K 7
devbuf 4217 4323K 4246
solaris 130 2804K 200
sysctloid 47595 2800K 47699
vtbuf 24 1968K 46
kobj 328 1312K 489
newblk 14 1028K 38513
vfscache 3 1025K 3
pcb 255 802K 121727
inodedep 151 569K 38026
ufs_quota 1 512K 1
vfs_hash 1 512K 1
callout 2 512K 2
intr 4 472K 4
subproc 204 400K 38968
vmem 3 274K 5
acpica 1674 184K 57552
sctp_stro 175 175K 19011
vnet_data 1 168K 1
tidhash 3 141K 3
filedesc 18 137K 75709
pagedep 12 131K 37873
tfo_ccache 1 128K 1
DEVFS1 110 110K 127
sctp_atcl 293 110K 79772
sem 4 106K 4
bus 994 81K 5207
mtx_pool 2 72K 2
syncache 1 68K 1
module 517 65K 517
acpitask 1 64K 1
ddb_capture 1 64K 1
kdtrace 310 61K 82297
umtx 484 61K 484
sctp_timw 240 60K 240
temp 37 36K 3576
DEVFS3 129 33K 139
hostcache 1 32K 1
shm 1 32K 21
msg 4 30K 4
dirrem 117 30K 37873
gtaskqueue 18 26K 18
kbdmux 6 22K 6
ifaddr 71 21K 73
sctp_atky 468 21K 100102
DEVFS_RULE 56 20K 56
routetbl 143 19K 2875
BPF 14 19K 53
freefile 142 18K 37867
kstat_data 17 17K 17
ufs_mount 4 17K 5
proc 3 17K 3
tty 16 16K 16
ithread 97 16K 97
bus-sc 34 15K 1681
KTRACE 101 13K 104
ether_multi 157 13K 172
ifnet 7 13K 7
lltable 40 12K 107
eventhandler 137 12K 137
kenv 95 12K 95
rman 88 11K 431
GEOM 61 11K 494
CAM queue 5 11K 1528
in6_multi 71 9K 71
taskqueue 81 9K 81
bmsafemap 2 9K 37948
UART 12 9K 12
devstat 4 9K 4
filemon 1 8K 399
ksem 1 8K 1
rpc 2 8K 2
freework 32 8K 37864
shmfd 1 8K 28
pfs_vncache 1 8K 1
kqueue 91 8K 38874
freeblks 31 8K 37851
pfs_nodes 20 8K 20
audit_evclass 237 8K 296
UMA 367 7K 367
cred 26 7K 335
sglist 5 7K 5
CAM DEV 3 6K 510
plimit 24 6K 506
Unitno 155 6K 193
sctp_map 350 6K 38022
session 38 5K 407
ufs_dirhash 24 5K 24
pf_ifnet 12 5K 547
sctp_athm 293 5K 79823
vt 11 5K 11
pf_table 2 4K 612
memdesc 1 4K 1
MCA 32 4K 32
evdev 4 4K 4
DEVFSP 61 4K 942
acpisem 28 4K 28
hhook 15 4K 17
pwddesc 53 4K 38853
proc-args 83 4K 40229
kcovinfo 52 4K 52
lockf 25 3K 90
terminal 11 3K 11
uidinfo 3 3K 13
local_apic 1 2K 1
io_apic 1 2K 1
fpukern_ctx 2 2K 2
ipsec-saq 2 2K 2
ip6ndp 12 2K 15
sctp_ifa 14 2K 15
selfd 27 2K 517962
CAM XPT 22 2K 543
msi 12 2K 12
in_multi 6 2K 9
vnodemarker 3 2K 237
ipsecpolicy 2 2K 2
acpidev 20 2K 20
clone 9 2K 9
tun 7 2K 7
softdep 1 1K 1
mkdir 8 1K 75682
sahead 1 1K 1
secasvar 1 1K 1
nhops 6 1K 8
NFSD session 1 1K 1
newdirblk 7 1K 37841
CAM periph 4 1K 271
select 7 1K 151
osd 32 1K 7477
ipsec 3 1K 3
sctp_ifn 6 1K 15
mld 6 1K 6
igmp 6 1K 6
toponodes 6 1K 6
isadev 6 1K 6
mount 16 1K 89
pci_link 10 1K 10
crypto 4 1K 791
encap_export_host 12 1K 12
diradd 4 1K 37914
pfil 4 1K 4
cdev 2 1K 2
chacha20random 1 1K 1
inpcbpolicy 11 1K 9211
NFSD lckfile 1 1K 1
NFSD V4client 1 1K 1
DEVFS 9 1K 10
CC Mem 4 1K 7437
vnodes 1 1K 1
CAM SIM 2 1K 2
sigio 4 1K 11
prison 8 1K 8
feeder 7 1K 7
taskq 2 1K 2
tcpfunc 3 1K 3
loginclass 3 1K 6
lkpikmalloc 5 1K 6
soname 6 1K 58744
aesni_data 2 1K 2
pf_rule 1 1K 646
cryptodev 2 1K 1011
nexusdev 8 1K 8
apmdev 1 1K 1
atkbddev 2 1K 2
CAM dev queue 2 1K 2
CAM I/O Scheduler 1 1K 1
CAM path 4 1K 1034
procdesc 1 1K 18
pmchooks 1 1K 1
sctp_vrf 1 1K 1
vnet 1 1K 1
entropy 2 1K 47
pmc 1 1K 1
acpiintr 1 1K 1
cpus 2 1K 2
vnet_data_free 1 1K 1
Per-cpu 1 1K 1
p1003.1b 1 1K 1
filecaps 1 1K 126
sfs_nodes 0 0K 0
zones_data 0 0K 0
tcp_do 0 0K 0
tcp_fsb 0 0K 1425
ipcomp 0 0K 0
esp 0 0K 0
ah 0 0K 0
mqdata 0 0K 0
pf_altq 0 0K 0
pf_osfp 0 0K 0
pf_temp 0 0K 0
sctp_mcore 0 0K 0
sctp_socko 0 0K 54531
sctp_iter 0 0K 11
sctp_mvrf 0 0K 0
sctp_cpal 0 0K 0
sctp_cmsg 0 0K 0
sctp_stre 0 0K 0
sctp_athi 0 0K 0
sctp_a_it 0 0K 11
sctp_aadr 0 0K 0
sctp_stri 0 0K 117
NFSCL layrecall 0 0K 0
NFSCL session 0 0K 0
madt_table 0 0K 2
smartpqi 0 0K 0
NFSCL sockreq 0 0K 0
NFSCL devinfo 0 0K 0
NFSCL flayout 0 0K 0
ixl 0 0K 0
NFSCL layout 0 0K 0
NFSD rollback 0 0K 0
NFSCL diroff 0 0K 0
NEWdirectio 0 0K 0
NEWNFSnode 0 0K 0
NFSCL lck 0 0K 0
NFSCL lckown 0 0K 0
ice-resmgr 0 0K 0
ice-osdep 0 0K 0
ice 0 0K 0
iavf 0 0K 0
axgbe 0 0K 0
NFSCL client 0 0K 0
NFSCL deleg 0 0K 0
NFSCL open 0 0K 0
NFSCL owner 0 0K 0
NFS fh 0 0K 0
NFS req 0 0K 0
NFSD usrgroup 0 0K 0
NFSD string 0 0K 0
NFSD V4lock 0 0K 0
xen_intr 0 0K 0
NFSD V4state 0 0K 0
xen_hvm 0 0K 0
legacydrv 0 0K 0
bounce 0 0K 0
busdma 0 0K 0
qpidrv 0 0K 0
NFSD srvcache 0 0K 0
msdosfs_fat 0 0K 0
dmar_idpgtbl 0 0K 0
dmar_dom 0 0K 0
dmar_ctx 0 0K 0
msdosfs_mount 0 0K 0
msdosfs_node 0 0K 0
isci 0 0K 0
iommu_dmamap 0 0K 0
hyperv_socket 0 0K 0
bxe_ilt 0 0K 0
xenbus 0 0K 0
DEVFS4 0 0K 0
vm_fictitious 0 0K 0
DEVFS2 0 0K 0
gntdev 0 0K 0
privcmd_dev 0 0K 0
evtchn_dev 0 0K 0
xenstore 0 0K 0
scsi_pass 0 0K 0
ciss_data 0 0K 0
xnb 0 0K 0
xen_acpi 0 0K 0
xbbd 0 0K 0
xbd 0 0K 0
UMAHash 0 0K 0
Balloon 0 0K 0
sysmouse 0 0K 0
vm_pgdata 0 0K 0
jblocks 0 0K 0
savedino 0 0K 35329
sentinel 0 0K 0
jfsync 0 0K 0
jtrunc 0 0K 0
sbdep 0 0K 93
jsegdep 0 0K 0
jseg 0 0K 0
jfreefrag 0 0K 0
jfreeblk 0 0K 0
jnewblk 0 0K 0
jmvref 0 0K 0
jremref 0 0K 0
jaddref 0 0K 0
freedep 0 0K 0
freefrag 0 0K 2
allocindir 0 0K 0
indirdep 0 0K 30
allocdirect 0 0K 0
ufs_trim 0 0K 0
mactemp 0 0K 0
audit_trigger 0 0K 0
audit_pipe_presel 0 0K 0
audit_pipeent 0 0K 0
audit_pipe 0 0K 0
audit_evname 0 0K 0
audit_bsm 0 0K 0
audit_gidset 0 0K 0
audit_text 0 0K 0
audit_path 0 0K 0
audit_data 0 0K 0
audit_cred 0 0K 0
vtfont 0 0K 0
BACKLIGHT 0 0K 0
ath_hal 0 0K 0
athdev 0 0K 0
ata_pci 0 0K 0
ata_dma 0 0K 0
ata_generic 0 0K 0
pvscsi 0 0K 0
scsi_da 0 0K 69
ata_da 0 0K 0
scsi_ch 0 0K 0
scsi_cd 0 0K 0
ktls_ocf 0 0K 0
AHCI driver 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5E_TLS_RX 0 0K 0
MLX5EEPROM 0 0K 0
MLX5E_TLS 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EN 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5DUMP 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
seq_file 0 0K 0
lkpiskb 0 0K 0
radix 0 0K 0
idr 0 0K 0
lkpindev 0 0K 0
lkpifw 0 0K 0
lkpi80211 0 0K 0
NLM 0 0K 0
ipsec-spdcache 0 0K 0
ipsec-reg 0 0K 0
ipsec-misc 0 0K 0
ipsecrequest 0 0K 0
ip6opt 0 0K 88
ip6_msource 0 0K 0
ip6_moptions 0 0K 0
in6_mfilter 0 0K 0
frag6 0 0K 9
tcplog 0 0K 0
tcp_hwpace 0 0K 0
USBdev 0 0K 0
USB 0 0K 0
LRO 0 0K 0
ip_msource 0 0K 0
ip_moptions 0 0K 1
in_mfilter 0 0K 1
ipid 0 0K 0
80211scan 0 0K 0
80211ratectl 0 0K 0
80211power 0 0K 0
80211nodeie 0 0K 0
80211node 0 0K 0
80211mesh_gt 0 0K 0
80211mesh_rt 0 0K 0
80211perr 0 0K 0
80211prep 0 0K 0
80211preq 0 0K 0
80211dfs 0 0K 0
80211crypto 0 0K 0
80211vap 0 0K 0
iflib 0 0K 0
vlan 0 0K 0
gif 0 0K 0
ifdescr 0 0K 0
zlib 0 0K 0
fadvise 0 0K 4
VN POLL 0 0K 0
agp 0 0K 0
statfs 0 0K 38203
namei_tracker 0 0K 0
export_host 0 0K 0
cl_savebuf 0 0K 3
nvme_da 0 0K 0
acpipwr 0 0K 0
acpi_perf 0 0K 0
twsbuf 0 0K 0
twe_commands 0 0K 0
tcp_log_dev 0 0K 2814
midi buffers 0 0K 0
mixer 0 0K 0
ac97 0 0K 0
hdacc 0 0K 0
hdac 0 0K 0
hdaa 0 0K 0
acpicmbat 0 0K 0
SIIS driver 0 0K 0
CAM CCB 0 0K 523
biobuf 0 0K 0
aios 0 0K 36
lio 0 0K 20
acl 0 0K 0
mbuf_tag 0 0K 127
ktls 0 0K 0
PUC 0 0K 0
ppbusdev 0 0K 0
agtiapi_MemAlloc malloc 0 0K 0
osti_cacheable 0 0K 0
tempbuff 0 0K 0
tempbuff 0 0K 0
ag_tgt_map_t malloc 0 0K 0
ag_slr_map_t malloc 0 0K 0
lDevFlags * malloc 0 0K 0
tiDeviceHandle_t * malloc 0 0K 0
ag_portal_data_t malloc 0 0K 0
ag_device_t malloc 0 0K 0
STLock malloc 0 0K 0
CCB List 0 0K 0
sr_iov 0 0K 0
OCS 0 0K 0
OCS 0 0K 0
nvme 0 0K 0
nvd 0 0K 0
netmap 0 0K 0
mwldev 0 0K 0
MVS driver 0 0K 0
CAM ccb queue 0 0K 0
accf 0 0K 0
pts 0 0K 0
iov 0 0K 28735
ioctlops 0 0K 2814
eventfd 0 0K 9
Witness 0 0K 0
stack 0 0K 0
mrsasbuf 0 0K 0
mpt_user 0 0K 0
mps_user 0 0K 0
MPSSAS 0 0K 0
mps 0 0K 0
sbuf 0 0K 288
mpr_user 0 0K 0
firmware 0 0K 0
compressor 0 0K 0
MPRSAS 0 0K 0
SWAP 0 0K 0
mpr 0 0K 0
mfibuf 0 0K 0
sysctltmp 0 0K 888
sysctl 0 0K 3
md_sectors 0 0K 0
ekcd 0 0K 0
dumper 0 0K 0
sendfile 0 0K 0
rctl 0 0K 0
md_disk 0 0K 0
malodev 0 0K 0
LED 0 0K 0
ix_sriov 0 0K 0
cache 0 0K 0
aacraidcam 0 0K 0
prison_racct 0 0K 0
Fail Points 0 0K 0
filedesc_to_leader 0 0K 0
pwd 0 0K 0
tty console 0 0K 0
ix 0 0K 0
ipsbuf 0 0K 0
aacraid_buf 0 0K 0
aaccam 0 0K 0
boottrace 0 0K 0
aacbuf 0 0K 0
zstd 0 0K 0
XZ_DEC 0 0K 0
nvlist 0 0K 0
SCSI ENC 0 0K 0
SCSI sa 0 0K 0
isofs_node 0 0K 0
isofs_mount 0 0K 0
tr_raid5_data 0 0K 0
tr_raid1e_data 0 0K 0
tr_raid1_data 0 0K 0
tr_raid0_data 0 0K 0
tr_concat_data 0 0K 0
md_sii_data 0 0K 0
md_promise_data 0 0K 0
md_nvidia_data 0 0K 0
md_jmicron_data 0 0K 0
md_intel_data 0 0K 0
md_ddf_data 0 0K 0
raid_data 0 0K 72
geom_flashmap 0 0K 0
tmpfs dir 0 0K 0
tmpfs name 0 0K 0
tmpfs mount 0 0K 0
NFS FHA 0 0K 0
newnfsmnt 0 0K 0
newnfsclient_req 0 0K 0
db> show uma
Zone Size Used Free Requests Sleeps Bucket Total Mem XFree
mbuf_jumbo_page 4096 8338 1060 1473240 0 254 38494208 0
tcp_log 416 0 10161 248600 0 254 4226976 0
malloc-384 384 4267 3263 42143 0 30 2891520 0
mbuf 256 9002 1921 2640967 0 254 2796288 0
pbuf 2624 0 973 0 0 2 2553152 0
RADIX NODE 144 16529 910 740825 0 62 2511216 0
sctp_asoc 2256 175 845 19011 0 254 2301120 0
malloc-128 128 15616 163 129448 0 126 2019712 0
BUF TRIE 144 232 11556 1514 0 62 1697472 0
mbuf_cluster 2048 762 0 762 0 254 1560576 0
malloc-2048 2048 127 593 60648 0 8 1474560 0
malloc-4096 4096 330 4 505 0 2 1368064 0
UMA Slabs 0 112 11530 20 11530 0 126 1293600 0
sctp_ep 1208 118 902 60639 0 254 1232160 0
vmem btag 56 21548 91 21548 0 254 1211784 0
malloc-256 256 186 3294 38152 0 62 890880 0
malloc-256 256 50 3310 74086 0 62 860160 0
malloc-16384 16384 9 38 37853 0 1 770048 0
VM OBJECT 264 1740 1140 831149 0 30 760320 0
sctp_raddr 736 175 848 19011 0 254 752928 0
socket 960 22 742 71985 0 254 733440 0
FFS inode 1160 521 60 38388 0 8 673960 0
malloc-1024 1024 178 414 19026 0 16 606208 0
256 Bucket 2048 267 13 7606 0 8 573440 0
tcpcb 1104 4 507 7437 0 254 564144 0
malloc-384 384 320 880 79866 0 30 460800 0
malloc-128 128 172 3362 38057 0 126 452352 0
malloc-4096 4096 94 14 38860 0 2 442368 0
THREAD 1808 220 22 43443 0 8 437536 0
MAP ENTRY 96 2043 2493 1973688 0 126 435456 0
malloc-65536 65536 6 0 6 0 1 393216 0
lkpimm 168 1 2327 1 0 62 391104 0
lkpicurr 168 2 2326 2 0 62 391104 0
malloc-64 64 5198 409 561903 0 254 358848 0
malloc-8192 8192 2 39 400 0 1 335872 0
malloc-16 16 19593 407 27130 0 254 320000 0
VNODE 448 562 131 38431 0 30 310464 0
tcp_bbr_map 128 0 2294 51997 0 126 293632 0
UMA Zones 768 339 0 339 0 16 260352 0
ertt_txseginfo 40 0 6363 290958 0 254 254520 0
malloc-32 32 7655 283 7764 0 254 254016 0
FPU_save_area 832 222 57 48760 0 16 232128 0
DEVCTL 1024 0 220 156 0 0 225280 0
malloc-256 256 213 657 54734 0 62 222720 0
malloc-256 256 239 571 136735 0 62 207360 0
VMSPACE 2552 31 50 38818 0 4 206712 0
malloc-65536 65536 1 2 275 0 1 196608 0
malloc-65536 65536 1 2 137 0 1 196608 0
mbuf_packet 256 175 587 68295 0 254 195072 0
malloc-128 128 1242 277 27293 0 126 194432 0
malloc-1024 1024 155 21 172 0 16 180224 0
malloc-128 128 1245 150 6049 0 126 178560 0
128 Bucket 1024 123 40 3583 0 16 166912 0
malloc-32768 32768 0 5 19 0 1 163840 0
FFS2 dinode 256 521 109 38388 0 62 161280 0
S VFS Cache 104 1044 477 39440 0 126 158184 0
sctp_chunk 152 191 849 1336 0 254 158080 0
PROC 1352 88 26 38852 0 8 154128 0
64 Bucket 512 221 43 30132 0 30 135168 0
zio_buf_comb_131072 131072 0 1 1 0 1 131072 0
unpcb 256 8 502 2092 0 254 130560 0
malloc-256 256 317 193 44070 0 62 130560 0
UMA Kegs 384 325 8 325 0 30 127872 0
filedesc0 1072 53 59 38853 0 8 120064 0
ksiginfo 112 103 941 5673 0 126 116928 0
malloc-64 64 747 1080 20882 0 254 116928 0
malloc-4096 4096 5 21 31 0 2 106496 0
g_bio 408 0 240 11054 0 30 97920 0
malloc-256 256 279 96 2324 0 62 96000 0
32 Bucket 256 269 106 19795 0 62 96000 0
malloc-8192 8192 9 2 37 0 1 90112 0
malloc-8192 8192 10 1 12 0 1 90112 0
malloc-4096 4096 21 1 35 0 2 90112 0
pipe 744 19 96 2136 0 16 85560 0
clpbuf 2624 0 32 44 0 16 83968 0
malloc-2048 2048 5 35 1238 0 8 81920 0
malloc-384 384 167 43 168 0 30 80640 0
sctp_readq 152 0 520 29 0 254 79040 0
malloc-64 64 563 508 1344 0 254 68544 0
malloc-128 128 374 153 40170 0 126 67456 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-65536 65536 0 1 8 0 1 65536 0
malloc-32768 32768 2 0 2 0 1 65536 0
malloc-32768 32768 0 2 120 0 1 65536 0
malloc-16384 16384 3 1 4 0 1 65536 0
malloc-2048 2048 12 20 622 0 8 65536 0
pcpu-8 8 5202 2990 18197 0 254 65536 0
malloc-256 256 25 230 3734 0 62 65280 0
udp_inpcb 424 6 147 616 0 30 64872 0
Files 80 163 637 133227 0 126 64000 0
sctp_stream_msg_out 112 69 471 1583 0 254 60480 0
malloc-32 32 496 1394 131535 0 254 60480 0
tcp_inpcb 424 4 122 7437 0 30 53424 0
ripcb 424 1 125 958 0 30 53424 0
udplite_inpcb 424 0 126 200 0 30 53424 0
malloc-64 64 119 700 47072 0 254 52416 0
zio_data_buf_16384 16384 0 3 9 0 1 49152 0
DIRHASH 1024 35 13 35 0 16 49152 0
NAMEI 1024 0 48 178326 0 16 49152 0
malloc-16384 16384 1 2 7 0 1 49152 0
malloc-2048 2048 4 20 775 0 8 49152 0
malloc-1024 1024 5 43 2051 0 16 49152 0
pcpu-64 64 498 270 498 0 254 49152 0
da_ccb 544 0 84 2929 0 16 45696 0
tcp_bbr_pcb 832 0 54 4501 0 16 44928 0
syncache 168 0 264 4 0 254 44352 0
TURNSTILE 136 243 72 243 0 62 42840 0
Mountpoints 2752 2 12 2 0 4 38528 0
malloc-64 64 192 375 39076 0 254 36288 0
malloc-64 64 37 530 19935 0 254 36288 0
malloc-64 64 224 343 249 0 254 36288 0
malloc-64 64 161 406 1047 0 254 36288 0
malloc-128 128 43 236 281 0 126 35712 0
malloc-128 128 27 252 3150 0 126 35712 0
malloc-128 128 47 232 47 0 126 35712 0
routing nhops 256 27 108 35 0 62 34560 0
ttyoutq 256 72 63 160 0 62 34560 0
malloc-384 384 7 83 1380 0 30 34560 0
malloc-384 384 55 35 57 0 30 34560 0
malloc-256 256 7 128 38816 0 62 34560 0
SLEEPQUEUE 88 243 141 243 0 126 33792 0
zio_buf_16384 16384 0 2 10 0 1 32768 0
malloc-32768 32768 1 0 1 0 1 32768 0
malloc-16384 16384 2 0 17 0 1 32768 0
malloc-16384 16384 0 2 160 0 1 32768 0
malloc-8192 8192 2 2 224 0 1 32768 0
malloc-4096 4096 2 6 38828 0 2 32768 0
malloc-2048 2048 3 13 2443 0 8 32768 0
malloc-2048 2048 0 16 50 0 8 32768 0
malloc-1024 1024 8 24 9 0 16 32768 0
malloc-1024 1024 5 27 5 0 16 32768 0
malloc-1024 1024 3 29 436 0 16 32768 0
malloc-1024 1024 9 23 9 0 16 32768 0
malloc-1024 1024 3 29 20 0 16 32768 0
malloc-512 512 2 62 52 0 30 32768 0
malloc-512 512 4 60 17 0 30 32768 0
malloc-512 512 0 64 132 0 30 32768 0
malloc-512 512 2 62 51 0 30 32768 0
malloc-512 512 5 59 239 0 30 32768 0
malloc-512 512 0 64 118 0 30 32768 0
malloc-512 512 8 56 8 0 30 32768 0
tcp_rack_pcb 896 0 36 1425 0 16 32256 0
KNOTE 160 28 172 377298 0 62 32000 0
ttyinq 160 135 65 300 0 62 32000 0
malloc-16 16 579 1421 115577 0 254 32000 0
tcp_rack_map 120 0 264 2484 0 126 31680 0
cpuset 104 7 272 7 0 126 29016 0
sctp_laddr 48 0 588 2129 0 254 28224 0
tcp_inpcb ports 32 2 880 5531 0 254 28224 0
PWD 32 18 864 37910 0 254 28224 0
16 Bucket 144 99 97 746 0 62 28224 0
4 Bucket 48 15 573 858 0 254 28224 0
malloc-16 16 385 1365 99508 0 254 28000 0
AIO 208 0 133 99 0 62 27664 0
malloc-8192 8192 3 0 3 0 1 24576 0
malloc-4096 4096 2 4 5 0 2 24576 0
rtentry 176 31 107 35 0 62 24288 0
PGRP 88 38 238 407 0 126 24288 0
rl_entry 40 69 537 69 0 254 24240 0
8 Bucket 80 126 174 7976 0 126 24000 0
malloc-384 384 20 40 360 0 30 23040 0
hostcache 64 1 314 1 0 254 20160 0
udpcb 32 6 624 816 0 254 20160 0
udp_inpcb ports 32 3 627 65 0 254 20160 0
udplite_inpcb ports 32 0 630 14 0 254 20160 0
AIOP 32 4 626 4 0 254 20160 0
ertt 72 4 276 7437 0 126 20160 0
malloc-32 32 240 390 301 0 254 20160 0
malloc-32 32 27 603 2188 0 254 20160 0
malloc-32 32 132 498 36509 0 254 20160 0
malloc-32 32 59 571 3863 0 254 20160 0
malloc-32 32 51 579 1251 0 254 20160 0
malloc-32 32 5 625 9 0 254 20160 0
2 Bucket 32 111 519 3944 0 254 20160 0
cryptop 280 0 70 36 0 30 19600 0
AIOCB 552 0 35 157 0 16 19320 0
AIOLIO 272 0 70 20 0 30 19040 0
epoch_record pcpu 256 4 60 4 0 62 16384 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-8192 8192 2 0 2 0 1 16384 0
malloc-2048 2048 3 5 3 0 8 16384 0
malloc-2048 2048 3 5 3 0 8 16384 0
malloc-512 512 1 31 1 0 30 16384

---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

Mark Johnston

unread,
Jun 13, 2022, 5:10:42 PM6/13/22
to syzbot, syzkaller-f...@googlegroups.com
On Thu, Apr 28, 2022 at 10:45:20PM -0700, syzbot wrote:
> Hello,
>
> syzbot found the following issue on:
>
> HEAD commit: 9fb40baf6043 cam_periph: Return ENXIO when peripheral is i..
> git tree: freebsd-src
> console output: https://syzkaller.appspot.com/x/log.txt?x=1283b05af00000
> dashboard link: https://syzkaller.appspot.com/bug?extid=5ac6a8777481bbe86395
>
> Unfortunately, I don't have any reproducer for this issue yet.
>
> IMPORTANT: if you fix the issue, please add the following tag to the commit:
> Reported-by: syzbot+5ac6a8...@syzkaller.appspotmail.com
>
> panic: Assertion (t->parent->p_treeflag & P_TREE_REAPER) != 0 failed at /syzkaller/managers/main/kernel/sys/kern/kern_procctl.c:383
> cpuid = 1
> time = 325
> KDB: stack backtrace:
> db_trace_self_wrapper() at db_trace_self_wrapper+0xc7/frame 0xfffffe009f1c6690
> kdb_backtrace() at kdb_backtrace+0xd3/frame 0xfffffe009f1c67f0
> vpanic() at vpanic+0x2b8/frame 0xfffffe009f1c68d0
> panic() at panic+0xb5/frame 0xfffffe009f1c6990
> reap_kill() at reap_kill+0x9fe/frame 0xfffffe009f1c6ba0
> kern_procctl() at kern_procctl+0x535/frame 0xfffffe009f1c6c10
> sys_procctl() at sys_procctl+0x247/frame 0xfffffe009f1c6d30
> amd64_syscall() at amd64_syscall+0x40c/frame 0xfffffe009f1c6f30
> fast_syscall_common() at fast_syscall_common+0xf8/frame 0xfffffe009f1c6f30
> --- syscall (198, FreeBSD ELF64, nosys), rip = 0x28a42a, rsp = 0x83123bf08, rbp = 0x83123bf70 ---

#syz fix: reap_kill_proc(): avoid singlethreading any other process if we are exiting
Reply all
Reply to author
Forward
0 new messages