panic: inp_leave_group: imf_sources not empty (2)

4 views
Skip to first unread message

syzbot

unread,
May 17, 2019, 5:13:05 AM5/17/19
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 85eaade9 Fix integer overflow in r346386.
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=10951e9ca00000
dashboard link: https://syzkaller.appspot.com/bug?extid=fd317bf832b72a6e43cf

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+fd317b...@syzkaller.appspotmail.com

panic: inp_leave_group: imf_sources not empty
cpuid = 1
time = 1558084352
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe001fb82520
vpanic() at vpanic+0x1e0/frame 0xfffffe001fb82580
panic() at panic+0x43/frame 0xfffffe001fb825e0
inp_setmoptions() at inp_setmoptions+0x40bd/frame 0xfffffe001fb827c0
ip_ctloutput() at ip_ctloutput+0x80f/frame 0xfffffe001fb82810
rip_ctloutput() at rip_ctloutput+0x2c9/frame 0xfffffe001fb82850
sosetopt() at sosetopt+0x101/frame 0xfffffe001fb828d0
kern_setsockopt() at kern_setsockopt+0x158/frame 0xfffffe001fb82950
sys_setsockopt() at sys_setsockopt+0x33/frame 0xfffffe001fb82980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe001fb82ab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe001fb82ab0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x41309a, rsp =
0x7fffdff9af38, rbp = 0x5 ---
KDB: enter: panic
[ thread pid 1871 tid 100525 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
May 17, 2019, 5:44:05 AM5/17/19
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 85eaade9 Fix integer overflow in r346386.
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=120d6964a00000
dashboard link: https://syzkaller.appspot.com/bug?extid=fd317bf832b72a6e43cf
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1123e454a00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+fd317b...@syzkaller.appspotmail.com

panic: inp_leave_group: imf_sources not empty
cpuid = 0
time = 1558086004
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe0021268520
vpanic() at vpanic+0x1e0/frame 0xfffffe0021268580
panic() at panic+0x43/frame 0xfffffe00212685e0
inp_setmoptions() at inp_setmoptions+0x40bd/frame 0xfffffe00212687c0
ip_ctloutput() at ip_ctloutput+0x80f/frame 0xfffffe0021268810
rip_ctloutput() at rip_ctloutput+0x2c9/frame 0xfffffe0021268850
sosetopt() at sosetopt+0x101/frame 0xfffffe00212688d0
kern_setsockopt() at kern_setsockopt+0x158/frame 0xfffffe0021268950
sys_setsockopt() at sys_setsockopt+0x33/frame 0xfffffe0021268980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe0021268ab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe0021268ab0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x41309a, rsp =
0x7fffdff9af38, rbp = 0x5 ---
KDB: enter: panic
[ thread pid 836 tid 100130 ]

syzbot

unread,
May 19, 2019, 4:58:05 PM5/19/19
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: e2abb7b2 Protect commands that are considered dangerous wi..
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=16df1710a00000
dashboard link: https://syzkaller.appspot.com/bug?extid=fd317bf832b72a6e43cf
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1056fcbca00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=10ad56f8a00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+fd317b...@syzkaller.appspotmail.com

panic: inp_leave_group: imf_sources not empty
cpuid = 0
time = 1558299277
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe001f845520
vpanic() at vpanic+0x1e0/frame 0xfffffe001f845580
panic() at panic+0x43/frame 0xfffffe001f8455e0
inp_setmoptions() at inp_setmoptions+0x40bd/frame 0xfffffe001f8457c0
ip_ctloutput() at ip_ctloutput+0x80f/frame 0xfffffe001f845810
rip_ctloutput() at rip_ctloutput+0x2c9/frame 0xfffffe001f845850
sosetopt() at sosetopt+0x101/frame 0xfffffe001f8458d0
kern_setsockopt() at kern_setsockopt+0x158/frame 0xfffffe001f845950
sys_setsockopt() at sys_setsockopt+0x33/frame 0xfffffe001f845980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe001f845ab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe001f845ab0
--- syscall (0, FreeBSD ELF64, nosys), rip = 0x45762a, rsp =
0x7fffdffdcf88, rbp = 0x6b5bc0 ---
KDB: enter: panic
[ thread pid 864 tid 100305 ]
Reply all
Reply to author
Forward
0 new messages