panic: sbfree: m ADDR !M_NOTREADY

9 views
Skip to first unread message

syzbot

unread,
Mar 16, 2019, 2:58:05 AM3/16/19
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 4d504c57 stack(9): Drop unused API mode and comment that r..
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=1469ab0b200000
dashboard link: https://syzkaller.appspot.com/bug?extid=bf0ad5e1143a68572a42
userspace arch: amd64

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+bf0ad5...@syzkaller.appspotmail.com

panic: sbfree: m 0xfffff8001498ac00 !M_NOTREADY
cpuid = 0
time = 23
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe00212ae4c0
vpanic() at vpanic+0x1e0/frame 0xfffffe00212ae520
panic() at panic+0x43/frame 0xfffffe00212ae580
sbfree() at sbfree+0x1f4/frame 0xfffffe00212ae5c0
sbcut_internal() at sbcut_internal+0xf0/frame 0xfffffe00212ae610
sbrelease_internal() at sbrelease_internal+0x9c/frame 0xfffffe00212ae650
sofree() at sofree+0x492/frame 0xfffffe00212ae6b0
soclose() at soclose+0x5b3/frame 0xfffffe00212ae730
_fdrop() at _fdrop+0x3a/frame 0xfffffe00212ae760
closef() at closef+0x27d/frame 0xfffffe00212ae7f0
fdescfree_fds() at fdescfree_fds+0xbd/frame 0xfffffe00212ae840
fdescfree() at fdescfree+0x58a/frame 0xfffffe00212ae900
exit1() at exit1+0x780/frame 0xfffffe00212ae970
sys_sys_exit() at sys_sys_exit+0xd/frame 0xfffffe00212ae980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe00212aeab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe00212aeab0
--- syscall (1, FreeBSD ELF64, sys_sys_exit), rip = 0x44f30a, rsp =
0x7fffffffec58, rbp = 0 ---
KDB: enter: panic
[ thread pid 30650 tid 100120 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#bug-status-tracking for how to communicate with
syzbot.

syzbot

unread,
Mar 20, 2019, 11:40:06 PM3/20/19
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: f61d2405 googletest: backport GTEST_SKIP to googletest 1.8.1
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=15b9505d200000
dashboard link: https://syzkaller.appspot.com/bug?extid=bf0ad5e1143a68572a42
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=13d46d1b200000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=11aba2df200000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+bf0ad5...@syzkaller.appspotmail.com

login: panic: sbfree: m 0xfffff80012817b00 !M_NOTREADY
cpuid = 1
time = 1553138944
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe0020ded4c0
vpanic() at vpanic+0x1e0/frame 0xfffffe0020ded520
panic() at panic+0x43/frame 0xfffffe0020ded580
sbfree() at sbfree+0x1f4/frame 0xfffffe0020ded5c0
sbcut_internal() at sbcut_internal+0xf0/frame 0xfffffe0020ded610
sbrelease_internal() at sbrelease_internal+0x9c/frame 0xfffffe0020ded650
sofree() at sofree+0x492/frame 0xfffffe0020ded6b0
soclose() at soclose+0x5b3/frame 0xfffffe0020ded730
_fdrop() at _fdrop+0x3a/frame 0xfffffe0020ded760
closef() at closef+0x27d/frame 0xfffffe0020ded7f0
fdescfree_fds() at fdescfree_fds+0xbd/frame 0xfffffe0020ded840
fdescfree() at fdescfree+0x58a/frame 0xfffffe0020ded900
exit1() at exit1+0x780/frame 0xfffffe0020ded970
sys_sys_exit() at sys_sys_exit+0xd/frame 0xfffffe0020ded980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe0020dedab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe0020dedab0
--- syscall (1, FreeBSD ELF64, sys_sys_exit), rip = 0x40cb7a, rsp =
0x7fffffffea98, rbp = 0x7fffffffeab0 ---
KDB: enter: panic
[ thread pid 14241 tid 100090 ]

Mark Johnston

unread,
Apr 11, 2020, 3:50:18 PM4/11/20
to syzbot, syzkaller-f...@googlegroups.com
#syz fix: Properly handle disconnected sockets in uipc_ready().
Reply all
Reply to author
Forward
0 new messages