panic: AEAD without a separate IV

1 view
Skip to first unread message

syzbot

unread,
May 6, 2021, 8:37:19 AM5/6/21
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 49c894dd powerpc64: Split out DMAP and non-DMAP implementa..
git tree: https://github.com/freebsd/freebsd-src.git main
console output: https://syzkaller.appspot.com/x/log.txt?x=10d3b145d00000
dashboard link: https://syzkaller.appspot.com/bug?extid=007341439ae295cee74f

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+007341...@syzkaller.appspotmail.com

panic: AEAD without a separate IV
cpuid = 0
time = 1620304582
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame 0xfffffe00949fb510
vpanic() at vpanic+0x1c7/frame 0xfffffe00949fb570
panic() at panic+0x43/frame 0xfffffe00949fb5d0
crp_sanity() at crp_sanity+0x94a/frame 0xfffffe00949fb630
crypto_dispatch() at crypto_dispatch+0x1a/frame 0xfffffe00949fb660
crypto_ioctl() at crypto_ioctl+0x2b05/frame 0xfffffe00949fb780
devfs_ioctl() at devfs_ioctl+0x14e/frame 0xfffffe00949fb7e0
VOP_IOCTL_APV() at VOP_IOCTL_APV+0x78/frame 0xfffffe00949fb810
vn_ioctl() at vn_ioctl+0x278/frame 0xfffffe00949fb930
devfs_ioctl_f() at devfs_ioctl_f+0x47/frame 0xfffffe00949fb970
kern_ioctl() at kern_ioctl+0x3cd/frame 0xfffffe00949fb9e0
sys_ioctl() at sys_ioctl+0x265/frame 0xfffffe00949fbab0
amd64_syscall() at amd64_syscall+0x247/frame 0xfffffe00949fbbf0
fast_syscall_common() at fast_syscall_common+0xf8/frame 0xfffffe00949fbbf0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x285e1a, rsp = 0x7fffdfffdf08, rbp = 0x7fffdfffdf70 ---
KDB: enter: panic
[ thread pid 1364 tid 100815 ]
Stopped at kdb_enter+0x67: movq $0,0x163a5ae(%rip)
db>
db> set $lines = 0
db> set $maxwidth = 0
db> show registers
cs 0x20
ds 0x3b
es 0x3b
fs 0x13
gs 0x1b
ss 0x28
rax 0x12
rcx 0xfffffe0095200000
rdx 0x3ffff
rbx 0
rsp 0xfffffe00949fb4f0
rbp 0xfffffe00949fb510
rsi 0x40001
rdi 0xffffffff81137be6 vprintf+0x176
r8 0
r9 0x8080808080808080
r10 0xfffffe00949fb3e0
r11 0x1ff6bfff59c
r12 0xffffffff82267ac0 ddb_dbbe
r13 0
r14 0xffffffff81a72b70
r15 0xffffffff81a72b70
rip 0xffffffff8112ebd7 kdb_enter+0x67
rflags 0x86
kdb_enter+0x67: movq $0,0x163a5ae(%rip)
db> show proc
Process 1364 (syz-executor.0) at 0xfffff80029554a70:
state: NORMAL
uid: 0 gids: 0, 0, 5
parent: pid 785 at 0xfffff80004fb0538
ABI: FreeBSD ELF64
flag: 0x10000080 flag2: 0
arguments: /root/syz-executor.0
reaper: 0xfffff8000452a538 reapsubtree: 1
sigparent: 20
vmspace: 0xfffffe0094bb0000
(map 0xfffffe0094bb0000)
(map.pmap 0xfffffe0094bb00c0)
(pmap 0xfffffe0094bb0120)
threads: 2
100136 RunQ syz-executor.0
100815 Run CPU 0 syz-executor.0
db> ps
pid ppid pgrp uid state wmesg wchan cmd
1364 785 785 0 R (threaded) syz-executor.0
100136 RunQ syz-executor.0
100815 Run CPU 0 syz-executor.0
1363 823 823 0 RE CPU 1 syz-executor.3
1358 786 786 0 R (threaded) syz-executor.1
100185 RunQ syz-executor.1
100811 S uwait 0xfffff80004f8a980 syz-executor.1
823 780 823 0 Ss nanslp 0xffffffff8273c8e1 syz-executor.3
816 810 816 0 Ss select 0xfffff80004f8a940 dhclient
813 1 813 0 Ss select 0xfffff80004f8ad40 dhclient
810 801 436 65 S select 0xfffff80004f8a8c0 dhclient
805 780 805 0 Ss piperd 0xfffff80029b428b8 syz-executor.2
801 436 436 0 S wait 0xfffff80029462538 sh
786 780 786 0 Ss nanslp 0xffffffff8273c8e0 syz-executor.1
785 780 785 0 Ss nanslp 0xffffffff8273c8e0 syz-executor.0
780 778 778 0 S (threaded) syz-fuzzer
100094 S uwait 0xfffff800049dd500 syz-fuzzer
100117 S uwait 0xfffff80004d04980 syz-fuzzer
100118 S uwait 0xfffff80004d04a80 syz-fuzzer
100119 S uwait 0xfffff80004f8af00 syz-fuzzer
100120 S kqread 0xfffff8002935c100 syz-fuzzer
100121 S uwait 0xfffff80004f89080 syz-fuzzer
100122 S uwait 0xfffff80004f89180 syz-fuzzer
100123 S uwait 0xfffff80004f8a180 syz-fuzzer
100124 S uwait 0xfffff80029b55d00 syz-fuzzer
778 776 778 0 Ss pause 0xfffff800240035e8 csh
776 694 776 0 Ss select 0xfffff80004f8a840 sshd
760 1 760 0 Ss+ ttyin 0xfffff800049d7cb0 getty
759 1 759 0 Ss+ ttyin 0xfffff80004cf58b0 getty
758 1 758 0 Ss+ ttyin 0xfffff80004cf5cb0 getty
757 1 757 0 Ss+ ttyin 0xfffff80004cfd0b0 getty
756 1 756 0 Ss+ ttyin 0xfffff80004cfd4b0 getty
755 1 755 0 Ss+ ttyin 0xfffff80004cfd8b0 getty
754 1 754 0 Ss+ ttyin 0xfffff80004cfdcb0 getty
753 1 753 0 Ss+ ttyin 0xfffff80004c6f0b0 getty
752 1 752 0 Ss+ ttyin 0xfffff80004c6f4b0 getty
698 1 698 0 Ss nanslp 0xffffffff8273c8e0 cron
694 1 694 0 Ss select 0xfffff80004f8aac0 sshd
507 1 507 0 Ss select 0xfffff80004f8ab40 syslogd
436 1 436 0 Ss wait 0xfffff80004f3c000 devd
435 1 435 65 Ss select 0xfffff80004f8ac40 dhclient
350 1 350 0 Ss select 0xfffff80004f8abc0 dhclient
347 1 347 0 Ss select 0xfffff80004f899c0 dhclient
23 0 0 0 DL syncer 0xffffffff8282bd50 [syncer]
22 0 0 0 DL vlruwt 0xfffff80004e94a70 [vnlru]
21 0 0 0 DL (threaded) [bufdaemon]
100080 D qsleep 0xffffffff8282ae00 [bufdaemon]
100087 D - 0xffffffff8220ae00 [bufspacedaemon-0]
100098 D sdflush 0xfffff80004f3ece8 [/ worker]
20 0 0 0 DL psleep 0xffffffff82852c08 [vmdaemon]
19 0 0 0 DL (threaded) [pagedaemon]
100078 D psleep 0xffffffff82847078 [dom0]
100085 D launds 0xffffffff82847084 [laundry: dom0]
100086 D umarcl 0xffffffff815c8de0 [uma]
18 0 0 0 DL - 0xffffffff82570c78 [rand_harvestq]
17 0 0 0 DL waiting 0xffffffff83088828 [sctp_iterator]
16 0 0 0 DL pftm 0xffffffff82d793c0 [pf purge]
15 0 0 0 DL - 0xffffffff8282845c [soaiod4]
9 0 0 0 DL - 0xffffffff8282845c [soaiod3]
8 0 0 0 DL - 0xffffffff8282845c [soaiod2]
7 0 0 0 DL - 0xffffffff8282845c [soaiod1]
6 0 0 0 DL (threaded) [cam]
100043 D - 0xffffffff82448140 [doneq0]
100044 D - 0xffffffff824480c0 [async]
100077 D - 0xffffffff82447f90 [scanner]
14 0 0 0 DL seqstat 0xfffff8000463a888 [sequencer 00]
5 0 0 0 DL crypto_ 0xfffff8000462ed80 [crypto returns 1]
4 0 0 0 DL crypto_ 0xfffff8000462ed30 [crypto returns 0]
3 0 0 0 DL crypto_ 0xffffffff828445a0 [crypto]
13 0 0 0 DL (threaded) [geom]
100034 D - 0xffffffff8271c120 [g_event]
100035 D - 0xffffffff8271c128 [g_up]
100036 D - 0xffffffff8271c130 [g_down]
2 0 0 0 DL (threaded) [KTLS]
100027 D - 0xfffff80004574700 [thr_0]
100028 D - 0xfffff80004574780 [thr_1]
12 0 0 0 WL (threaded) [intr]
100012 I [swi6: task queue]
100016 I [swi6: Giant taskq]
100018 I [swi5: fast taskq]
100029 I [swi1: netisr 0]
100030 I [swi3: vm]
100031 I [swi4: clock (0)]
100032 I [swi4: clock (1)]
100045 I [irq24: virtio_pci0]
100046 I [irq25: virtio_pci0]
100047 I [irq26: virtio_pci0]
100048 I [irq27: virtio_pci0]
100049 I [irq28: virtio_pci1]
100050 I [irq29: virtio_pci1]
100051 I [irq30: virtio_pci1]
100052 I [irq31: virtio_pci1]
100053 I [irq32: virtio_pci1]
100058 I [irq10: virtio_pci2]
100060 I [irq1: atkbd0]
100061 I [irq12: psm0]
100062 I [swi0: uart uart++]
100070 I [swi1: pf send]
100083 I [swi1: hpts]
100084 I [swi1: hpts]
11 0 0 0 RL (threaded) [idle]
100003 CanRun [idle: cpu0]
100004 CanRun [idle: cpu1]
1 0 1 0 SLs wait 0xfffff8000452a538 [init]
10 0 0 0 DL audit_w 0xffffffff82844ab0 [audit]
0 0 0 0 DLs (threaded) [kernel]
100000 D swapin 0xffffffff8271c6b0 [swapper]
100005 D - 0xfffff80004144800 [softirq_0]
100006 D - 0xfffff80004144700 [softirq_1]
100007 D - 0xfffff80004144600 [if_io_tqg_0]
100008 D - 0xfffff80004144500 [if_io_tqg_1]
100009 D - 0xfffff80004144400 [if_config_tqg_0]
100010 D - 0xfffff8000457a600 [kqueue_ctx taskq]
100011 D - 0xfffff8000457a500 [in6m_free taskq]
100013 D - 0xfffff8000457a200 [linuxkpi_irq_wq]
100014 D - 0xfffff8000457a100 [inm_free taskq]
100015 D - 0xfffff8000457a000 [aiod_kick taskq]
100017 D - 0xfffff80004574c00 [thread taskq]
100019 D - 0xfffff80004574900 [linuxkpi_short_wq_0]
100020 D - 0xfffff80004574900 [linuxkpi_short_wq_1]
100021 D - 0xfffff80004574900 [linuxkpi_short_wq_2]
100022 D - 0xfffff80004574900 [linuxkpi_short_wq_3]
100023 D - 0xfffff80004574800 [linuxkpi_long_wq_0]
100024 D - 0xfffff80004574800 [linuxkpi_long_wq_1]
100025 D - 0xfffff80004574800 [linuxkpi_long_wq_2]
100026 D - 0xfffff80004574800 [linuxkpi_long_wq_3]
100033 D - 0xfffff80004574100 [firmware taskq]
100037 D - 0xfffff8000462de00 [crypto_0]
100038 D - 0xfffff8000462de00 [crypto_1]
100054 D - 0xfffff8000462d800 [vtnet0 rxq 0]
100055 D - 0xfffff8000462d700 [vtnet0 txq 0]
100056 D - 0xfffff8000462d600 [vtnet0 rxq 1]
100057 D - 0xfffff8000462d500 [vtnet0 txq 1]
100059 D vtbslp 0xfffff80004973100 [virtio_balloon]
100063 D - 0xfffff80004972b00 [mca taskq]
100066 D - 0xffffffff81e1f4b0 [deadlkres]
100072 D - 0xfffff80004c3d700 [acpi_task_0]
100073 D - 0xfffff80004c3d700 [acpi_task_1]
100074 D - 0xfffff80004c3d700 [acpi_task_2]
100076 D - 0xfffff8000462dd00 [CAM taskq]
db> show all locks
db> show malloc
Type InUse MemUse Requests
pf_hash 5 11524K 5
devbuf 4216 4340K 4244
tcp_hpts 5 3201K 5
sysctloid 33530 1980K 33597
vtbuf 24 1968K 46
kobj 332 1328K 492
newblk 30 1032K 1160
vfscache 3 1025K 3
inodedep 552 719K 621
pcb 25 537K 133
ufs_quota 1 512K 1
vfs_hash 1 512K 1
callout 2 512K 2
intr 4 472K 4
subproc 118 240K 1429
acpica 1674 184K 55406
vnet_data 1 168K 1
tidhash 3 141K 3
dirrem 527 132K 555
pagedep 15 132K 559
tfo_ccache 1 128K 1
DEVFS1 107 107K 124
sem 4 106K 4
filedesc 14 105K 1121
linker 294 102K 330
bus 995 81K 3509
mtx_pool 2 72K 2
syncache 1 68K 1
freefile 527 66K 553
acpitask 1 64K 1
ddb_capture 1 64K 1
module 508 64K 508
umtx 330 42K 330
kdtrace 193 39K 2181
BPF 22 36K 22
temp 35 33K 1914
hostcache 1 32K 1
shm 1 32K 1
DEVFS3 126 32K 136
msg 4 30K 4
vmem 3 26K 5
gtaskqueue 18 26K 18
kbdmux 6 22K 6
DEVFS_RULE 56 20K 56
ifaddr 67 19K 69
ufs_mount 5 17K 6
proc 3 17K 3
routetbl 130 17K 418
tty 16 16K 16
ithread 99 16K 99
bus-sc 33 14K 1719
lltable 44 14K 50
KTRACE 100 13K 100
ifnet 7 13K 7
ether_multi 152 13K 162
kenv 93 12K 93
eventhandler 133 12K 133
rman 84 10K 425
GEOM 60 10K 489
in6_multi 65 9K 65
bmsafemap 3 9K 591
UART 12 9K 12
devstat 4 9K 4
ksem 1 8K 1
rpc 2 8K 2
shmfd 1 8K 1
pfs_vncache 1 8K 1
pfs_nodes 20 8K 20
audit_evclass 236 8K 294
sglist 5 7K 5
CAM DEV 3 6K 510
taskqueue 57 6K 57
cred 23 6K 211
kqueue 56 6K 1369
plimit 21 6K 364
CAM queue 5 6K 1528
DEVFSP 76 5K 357
ufs_dirhash 24 5K 24
xform 8 5K 602
UMA 265 5K 265
pf_ifnet 10 5K 19
vt 11 5K 11
memdesc 1 4K 1
MCA 32 4K 32
evdev 4 4K 4
kcovinfo 64 4K 68
acpisem 28 4K 28
diradd 27 4K 588
pwddesc 53 4K 1365
hhook 13 4K 13
session 25 4K 36
fpukern_ctx 3 3K 3
mkdir 24 3K 1094
terminal 11 3K 11
proc-args 44 3K 560
uidinfo 3 3K 8
lockf 20 3K 33
local_apic 1 2K 1
io_apic 1 2K 1
indirdep 8 2K 10
ipsec-saq 2 2K 2
selfd 31 2K 37596
ip6ndp 12 2K 13
sctp_ifa 13 2K 14
crypto 5 2K 104
Unitno 27 2K 47
CAM XPT 22 2K 543
newdirblk 12 2K 547
in_multi 6 2K 8
ipsecpolicy 2 2K 2
acpidev 20 2K 20
select 10 2K 32
msi 9 2K 9
clone 9 2K 9
tun 7 2K 7
sctp_timw 4 1K 4
softdep 1 1K 1
sahead 1 1K 1
secasvar 1 1K 1
nhops 6 1K 8
vnodemarker 2 1K 16
NFSD session 1 1K 1
CAM periph 4 1K 271
sctp_ifn 6 1K 14
ipsec 3 1K 3
mld 6 1K 6
igmp 6 1K 6
toponodes 6 1K 6
isadev 6 1K 6
mount 16 1K 89
pci_link 10 1K 10
encap_export_host 12 1K 12
pfil 4 1K 4
CAM SIM 2 1K 2
cdev 2 1K 2
inpcbpolicy 12 1K 348
chacha20random 1 1K 1
osd 3 1K 10
NFSD lckfile 1 1K 1
NFSD V4client 1 1K 1
DEVFS 9 1K 10
vnodes 1 1K 1
ktls 1 1K 1
procdesc 2 1K 8
feeder 7 1K 7
tcpfunc 3 1K 3
loginclass 3 1K 6
prison 6 1K 6
linux 5 1K 6
aesni_data 2 1K 2
apmdev 1 1K 1
atkbddev 2 1K 2
CAM dev queue 2 1K 2
CAM I/O Scheduler 1 1K 1
CAM path 4 1K 1034
pmchooks 1 1K 1
nexusdev 7 1K 7
soname 4 1K 3307
sctp_vrf 1 1K 1
vnet 1 1K 1
entropy 2 1K 38
acpiintr 1 1K 1
pmc 1 1K 1
cpus 2 1K 2
vnet_data_free 1 1K 1
Per-cpu 1 1K 1
filecaps 2 1K 72
freework 1 1K 553
p1003.1b 1 1K 1
sctp_mcore 0 0K 0
sctp_socko 0 0K 16
sctp_iter 0 0K 11
sctp_mvrf 0 0K 0
sctp_cpal 0 0K 0
sctp_cmsg 0 0K 0
sctp_stre 0 0K 0
sctp_athi 0 0K 0
sctp_athm 0 0K 20
sctp_atky 0 0K 24
sctp_atcl 0 0K 18
sctp_a_it 0 0K 11
sctp_aadr 0 0K 0
sctp_stro 0 0K 6
sctp_stri 0 0K 4
sctp_map 0 0K 8
mqdata 0 0K 0
pf_table 0 0K 0
pf_rule 0 0K 0
pf_altq 0 0K 0
pf_osfp 0 0K 0
pf_temp 0 0K 0
NFSD string 0 0K 0
NFSD V4lock 0 0K 0
madt_table 0 0K 2
smartpqi 0 0K 0
NFSD V4state 0 0K 0
NFSD srvcache 0 0K 0
msdosfs_fat 0 0K 0
msdosfs_mount 0 0K 0
msdosfs_node 0 0K 0
iavf 0 0K 0
ixl 0 0K 0
DEVFS4 0 0K 0
DEVFS2 0 0K 0
gntdev 0 0K 0
privcmd_dev 0 0K 0
ice-resmgr 0 0K 0
ice-osdep 0 0K 0
ice 0 0K 0
axgbe 0 0K 0
evtchn_dev 0 0K 0
xenstore 0 0K 0
ciss_data 0 0K 0
BACKLIGHT 0 0K 0
xnb 0 0K 0
xbbd 0 0K 0
xbd 0 0K 0
Balloon 0 0K 0
sysmouse 0 0K 0
vtfont 0 0K 0
xen_intr 0 0K 0
xen_hvm 0 0K 0
legacydrv 0 0K 0
qpidrv 0 0K 0
ath_hal 0 0K 0
athdev 0 0K 0
dmar_idpgtbl 0 0K 0
dmar_dom 0 0K 0
dmar_ctx 0 0K 0
ata_pci 0 0K 0
ata_dma 0 0K 0
ata_generic 0 0K 0
isci 0 0K 0
iommu_dmamap 0 0K 0
amr 0 0K 0
hyperv_socket 0 0K 0
bxe_ilt 0 0K 0
xenbus 0 0K 0
pvscsi 0 0K 0
scsi_da 0 0K 69
vm_fictitious 0 0K 0
ata_da 0 0K 0
scsi_ch 0 0K 0
scsi_cd 0 0K 0
AHCI driver 0 0K 0
USBdev 0 0K 0
USB 0 0K 0
agp 0 0K 0
nvme_da 0 0K 0
UMAHash 0 0K 0
acpipwr 0 0K 0
acpi_perf 0 0K 0
vm_pgdata 0 0K 0
jblocks 0 0K 0
savedino 0 0K 17
sentinel 0 0K 0
jfsync 0 0K 0
jtrunc 0 0K 0
sbdep 0 0K 5
jsegdep 0 0K 0
jseg 0 0K 0
jfreefrag 0 0K 0
jfreeblk 0 0K 0
jnewblk 0 0K 0
jmvref 0 0K 0
jremref 0 0K 0
jaddref 0 0K 0
freedep 0 0K 0
freeblks 0 0K 552
freefrag 0 0K 6
allocindir 0 0K 0
allocdirect 0 0K 0
ufs_trim 0 0K 0
mactemp 0 0K 0
audit_trigger 0 0K 0
audit_pipe_presel 0 0K 0
audit_pipeent 0 0K 0
audit_pipe 0 0K 0
audit_evname 0 0K 0
audit_bsm 0 0K 0
audit_gidset 0 0K 0
audit_text 0 0K 0
audit_path 0 0K 0
audit_data 0 0K 0
audit_cred 0 0K 0
twsbuf 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5E_TLS 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EN 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5DUMP 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
seq_file 0 0K 0
radix 0 0K 0
idr 0 0K 0
lkpifw 0 0K 0
NLM 0 0K 0
ipsec-spdcache 0 0K 0
ipsec-reg 0 0K 0
ipsec-misc 0 0K 0
ipsecrequest 0 0K 0
ip6opt 0 0K 3
ip6_msource 0 0K 0
ip6_moptions 0 0K 0
in6_mfilter 0 0K 0
frag6 0 0K 0
tcplog 0 0K 0
tcp_hwpace 0 0K 0
twe_commands 0 0K 0
LRO 0 0K 0
newreno data 0 0K 0
ip_msource 0 0K 0
ip_moptions 0 0K 0
in_mfilter 0 0K 0
ipid 0 0K 0
80211scan 0 0K 0
80211ratectl 0 0K 0
80211power 0 0K 0
80211nodeie 0 0K 0
80211node 0 0K 0
80211mesh_gt 0 0K 0
80211mesh_rt 0 0K 0
80211perr 0 0K 0
80211prep 0 0K 0
80211preq 0 0K 0
80211dfs 0 0K 0
80211crypto 0 0K 0
80211vap 0 0K 0
iflib 0 0K 0
vlan 0 0K 0
gif 0 0K 0
ifdescr 0 0K 0
zlib 0 0K 0
fadvise 0 0K 0
VN POLL 0 0K 0
twa_commands 0 0K 0
statfs 0 0K 719
namei_tracker 0 0K 0
export_host 0 0K 0
cl_savebuf 0 0K 4
tcp_log_dev 0 0K 0
midi buffers 0 0K 0
mixer 0 0K 0
ac97 0 0K 0
hdacc 0 0K 0
hdac 0 0K 0
hdaa 0 0K 0
acpicmbat 0 0K 0
SIIS driver 0 0K 0
CAM CCB 0 0K 1886
PUC 0 0K 0
ppbusdev 0 0K 0
agtiapi_MemAlloc malloc 0 0K 0
osti_cacheable 0 0K 0
tempbuff 0 0K 0
biobuf 0 0K 0
aios 0 0K 0
lio 0 0K 0
acl 0 0K 0
tempbuff 0 0K 0
mbuf_tag 0 0K 103
ag_tgt_map_t malloc 0 0K 0
ag_slr_map_t malloc 0 0K 0
lDevFlags * malloc 0 0K 0
tiDeviceHandle_t * malloc 0 0K 0
ag_portal_data_t malloc 0 0K 0
ag_device_t malloc 0 0K 0
STLock malloc 0 0K 0
CCB List 0 0K 0
sr_iov 0 0K 0
OCS 0 0K 0
OCS 0 0K 0
nvme 0 0K 0
nvd 0 0K 0
netmap 0 0K 0
mwldev 0 0K 0
MVS driver 0 0K 0
CAM ccb queue 0 0K 0
mrsasbuf 0 0K 0
mpt_user 0 0K 0
mps_user 0 0K 0
accf 0 0K 0
pts 0 0K 0
iov 0 0K 14200
ioctlops 0 0K 98
eventfd 0 0K 0
Witness 0 0K 0
stack 0 0K 0
MPSSAS 0 0K 0
mps 0 0K 0
mpr_user 0 0K 0
MPRSAS 0 0K 0
mpr 0 0K 0
mfibuf 0 0K 0
sbuf 0 0K 288
md_sectors 0 0K 0
firmware 0 0K 0
compressor 0 0K 0
md_disk 0 0K 0
SWAP 0 0K 0
malodev 0 0K 0
LED 0 0K 0
sysctltmp 0 0K 632
sysctl 0 0K 3
ekcd 0 0K 0
dumper 0 0K 0
sendfile 0 0K 0
rctl 0 0K 0
ix_sriov 0 0K 0
aacraidcam 0 0K 0
aacraid_buf 0 0K 0
ix 0 0K 0
ipsbuf 0 0K 0
cache 0 0K 0
iirbuf 0 0K 0
prison_racct 0 0K 0
Fail Points 0 0K 0
sigio 0 0K 1
filedesc_to_leader 0 0K 0
pwd 0 0K 0
tty console 0 0K 0
aaccam 0 0K 0
aacbuf 0 0K 0
zstd 0 0K 0
XZ_DEC 0 0K 0
nvlist 0 0K 0
SCSI ENC 0 0K 0
SCSI sa 0 0K 0
scsi_pass 0 0K 0
isofs_node 0 0K 0
isofs_mount 0 0K 0
tr_raid5_data 0 0K 0
tr_raid1e_data 0 0K 0
tr_raid1_data 0 0K 0
tr_raid0_data 0 0K 0
tr_concat_data 0 0K 0
md_sii_data 0 0K 0
md_promise_data 0 0K 0
md_nvidia_data 0 0K 0
md_jmicron_data 0 0K 0
md_intel_data 0 0K 0
md_ddf_data 0 0K 0
raid_data 0 0K 72
geom_flashmap 0 0K 0
tmpfs dir 0 0K 0
tmpfs name 0 0K 0
tmpfs mount 0 0K 0
NFS FHA 0 0K 0
newnfsmnt 0 0K 0
newnfsclient_req 0 0K 0
NFSCL layrecall 0 0K 0
NFSCL session 0 0K 0
NFSCL sockreq 0 0K 0
NFSCL devinfo 0 0K 0
NFSCL flayout 0 0K 0
NFSCL layout 0 0K 0
NFSD rollback 0 0K 0
NFSCL diroff 0 0K 0
NEWdirectio 0 0K 0
NEWNFSnode 0 0K 0
NFSCL lck 0 0K 0
NFSCL lckown 0 0K 0
NFSCL client 0 0K 0
NFSCL deleg 0 0K 0
NFSCL open 0 0K 0
NFSCL owner 0 0K 0
NFS fh 0 0K 0
NFS req 0 0K 0
NFSD usrgroup 0 0K 0
db> show uma
Zone Size Used Free Requests Sleeps Bucket Total Mem XFree
mbuf_jumbo_page 4096 8322 954 1435147 0 254 37994496 0
pbuf 2624 0 989 0 0 2 2595136 0
mbuf 256 8646 879 2159717 0 254 2438400 0
RADIX NODE 144 13680 205 83070 0 62 1999440 0
BUF TRIE 144 185 13283 537 0 62 1939392 0
malloc-384 384 4116 4 4116 0 30 1582080 0
malloc-128 128 10993 43 11008 0 126 1412608 0
malloc-4096 4096 332 1 492 0 2 1363968 0
UMA Slabs 0 112 10141 8 10141 0 126 1136688 0
FFS inode 1160 508 24 1063 0 8 617120 0
lkpimm 160 1 2324 1 0 62 372000 0
lkpicurr 160 2 2323 2 0 62 372000 0
VM OBJECT 264 1102 68 21114 0 30 308880 0
THREAD 1808 138 27 815 0 8 298320 0
malloc-4096 4096 64 5 1375 0 2 282624 0
VNODE 448 544 77 1101 0 30 278208 0
malloc-64 64 3995 163 5572 0 254 266112 0
malloc-65536 65536 4 0 4 0 1 262144 0
malloc-16384 16384 10 6 739 0 1 262144 0
256 Bucket 2048 122 2 16985 0 8 253952 0
malloc-128 128 1887 35 31323 0 126 246016 0
malloc-384 384 585 5 678 0 30 226560 0
malloc-16 16 13710 290 13821 0 254 224000 0
DEVCTL 1024 12 204 132 0 0 221184 0
malloc-65536 65536 1 2 199 0 1 196608 0
UMA Zones 768 237 2 237 0 16 183552 0
malloc-256 256 638 67 2627 0 62 180480 0
malloc-32 32 5172 246 5983 0 254 173376 0
mbuf_cluster 2048 75 1 75 0 254 155648 0
MAP ENTRY 96 1297 299 69958 0 126 153216 0
malloc-128 128 1024 30 2079 0 126 134912 0
FFS2 dinode 256 508 17 1061 0 62 134400 0
S VFS Cache 104 1011 276 1604 0 126 133848 0
malloc-65536 65536 2 0 2 0 1 131072 0
ksiginfo 112 47 997 1144 0 126 116928 0
vmem btag 56 2058 18 2058 0 254 116256 0
malloc-1024 1024 108 4 128 0 16 114688 0
malloc-8192 8192 9 4 138 0 1 106496 0
VMSPACE 2544 31 8 1343 0 4 99216 0
UMA Kegs 384 222 1 222 0 30 85632 0
PROC 1336 53 10 1364 0 8 84168 0
malloc-2048 2048 2 36 1894 0 8 77824 0
filedesc0 1072 53 17 1365 0 8 75040 0
malloc-4096 4096 15 3 114 0 2 73728 0
g_bio 408 0 170 4991 0 30 69360 0
malloc-256 256 220 50 1519 0 62 69120 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-65536 65536 0 1 8 0 1 65536 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-32768 32768 0 2 130 0 1 65536 0
malloc-32768 32768 2 0 2 0 1 65536 0
128 Bucket 1024 38 21 679 0 16 60416 0
64 Bucket 512 59 53 3372 0 30 57344 0
malloc-4096 4096 12 1 553 0 2 53248 0
socket 944 25 31 1506 0 254 52864 0
malloc-16384 16384 3 0 3 0 1 49152 0
malloc-2048 2048 4 20 511 0 8 49152 0
malloc-64 64 570 123 15480 0 254 44352 0
malloc-128 128 298 43 555 0 126 43648 0
malloc-256 256 153 12 178 0 62 42240 0
32 Bucket 256 50 115 3496 0 62 42240 0
clpbuf 2624 0 16 21 0 16 41984 0
malloc-8192 8192 5 0 5 0 1 40960 0
malloc-8192 8192 3 2 15 0 1 40960 0
pcpu-8 8 4577 543 4733 0 254 40960 0
malloc-384 384 80 20 98 0 30 38400 0
DIRHASH 1024 34 2 34 0 16 36864 0
NAMEI 1024 0 36 15570 0 16 36864 0
malloc-512 512 4 68 516 0 30 36864 0
malloc-64 64 209 358 38083 0 254 36288 0
malloc-64 64 488 79 1011 0 254 36288 0
malloc-256 256 108 27 741 0 62 34560 0
malloc-32768 32768 1 0 1 0 1 32768 0
pcpu-64 64 478 34 478 0 254 32768 0
malloc-4096 4096 4 3 726 0 2 28672 0
malloc-2048 2048 11 3 108 0 8 28672 0
malloc-2048 2048 3 11 15 0 8 28672 0
malloc-128 128 117 100 472 0 126 27776 0
malloc-384 384 52 18 52 0 30 26880 0
pipe 744 20 15 312 0 16 26040 0
TURNSTILE 136 166 23 166 0 62 25704 0
malloc-1024 1024 10 14 1240 0 16 24576 0
malloc-1024 1024 12 12 111 0 16 24576 0
KNOTE 160 28 122 369826 0 62 24000 0
ttyinq 160 135 15 300 0 62 24000 0
Files 80 190 110 8169 0 126 24000 0
8 Bucket 80 45 255 1316 0 126 24000 0
tcpcb 1048 4 18 46 0 254 23056 0
ttyoutq 256 72 18 160 0 62 23040 0
malloc-1024 1024 18 2 22 0 16 20480 0
PWD 32 17 613 637 0 254 20160 0
SLEEPQUEUE 88 166 58 166 0 126 19712 0
Mountpoints 2752 2 5 2 0 4 19264 0
mbuf_packet 256 2 73 499 0 254 19200 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-8192 8192 2 0 2 0 1 16384 0
malloc-2048 2048 2 6 282 0 8 16384 0
malloc-2048 2048 6 2 6 0 8 16384 0
malloc-1024 1024 12 4 12 0 16 16384 0
malloc-64 64 132 120 2785 0 254 16128 0
malloc-64 64 136 116 194 0 254 16128 0
malloc-32 32 413 91 595 0 254 16128 0
vtnet_tx_hdr 24 0 668 715861 0 254 16032 0
sctp_ep 1280 0 12 12 0 254 15360 0
malloc-256 256 33 27 398 0 62 15360 0
malloc-2048 2048 5 1 196 0 8 12288 0
malloc-1024 1024 5 7 25 0 16 12288 0
malloc-1024 1024 8 4 9 0 16 12288 0
malloc-512 512 3 21 193 0 30 12288 0
udplite_inpcb 488 0 24 144 0 254 11712 0
tcp_inpcb 488 4 20 46 0 254 11712 0
udp_inpcb 488 6 18 153 0 254 11712 0
kenv 258 15 30 1052 0 30 11610 0
routing nhops 256 27 18 34 0 62 11520 0
unpcb 256 11 34 1120 0 254 11520 0
malloc-384 384 22 8 375 0 30 11520 0
malloc-256 256 14 31 633 0 62 11520 0
malloc-256 256 24 21 642 0 62 11520 0
malloc-256 256 26 19 856 0 62 11520 0
sctp_asoc 2288 0 5 4 0 254 11440 0
malloc-8192 8192 1 0 1 0 1 8192 0
malloc-8192 8192 1 0 1 0 1 8192 0
malloc-8192 8192 1 0 1 0 1 8192 0
malloc-4096 4096 0 2 3 0 2 8192 0
malloc-1024 1024 0 8 5 0 16 8192 0
malloc-512 512 8 8 22 0 30 8192 0
malloc-512 512 8 8 8 0 30 8192 0
sctp_raddr 736 0 11 9 0 254 8096 0
rtentry 176 30 16 34 0 62 8096 0
PGRP 88 25 67 36 0 126 8096 0
rl_entry 40 34 168 34 0 254 8080 0
sctp_laddr 48 0 168 12 0 254 8064 0
udpcb 32 6 246 297 0 254 8064 0
malloc-64 64 8 118 9 0 254 8064 0
malloc-64 64 29 97 351 0 254 8064 0
malloc-32 32 6 246 11 0 254 8064 0
malloc-32 32 109 143 786 0 254 8064 0
malloc-32 32 37 215 775 0 254 8064 0
malloc-32 32 109 143 4262 0 254 8064 0
malloc-32 32 30 222 204 0 254 8064 0
16 Bucket 144 37 19 215 0 62 8064 0
4 Bucket 48 6 162 62 0 254 8064 0
2 Bucket 32 47 205 586 0 254 8064 0
malloc-16 16 1 499 4 0 254 8000 0
malloc-16 16 20 480 59 0 254 8000 0
malloc-16 16 314 186 532 0 254 8000 0
malloc-16 16 27 473 28 0 254 8000 0
malloc-16 16 189 311 1558 0 254 8000 0
malloc-16 16 31 469 25445 0 254 8000 0
malloc-16 16 14 486 32 0 254 8000 0
malloc-128 128 9 53 15 0 126 7936 0
malloc-128 128 52 10 599 0 126 7936 0
malloc-128 128 8 54 105 0 126 7936 0
sctp_readq 152 0 52 4 0 254 7904 0
sctp_chunk 152 0 52 7 0 254 7904 0
cryptop 280 1 27 35 0 30 7840 0
ripcb 488 2 14 5 0 254 7808 0
malloc-384 384 0 20 26 0 30 7680 0
malloc-384 384 20 0 20 0 30 7680 0
FPU_save_area 832 1 8 1 0 16 7488 0
cpuset 104 7 55 7 0 126 6448 0
epoch_record pcpu 256 4 12 4 0 62 4096 0
malloc-2048 2048 1 1 1 0 8 4096 0
malloc-512 512 0 8 2 0 30 4096 0
pcpu-16 16 7 249 7 0 254 4096 0
sctp_stream_msg_out 112 0 36 5 0 254 4032 0
hostcache 64 1 62 1 0 254 4032 0
syncache 168 0 24 4 0 254 4032 0
malloc-32 32 0 126 2 0 254 4032 0
UMA Slabs 1 176 9 13 9 0 62 3872 0
malloc-384 384 1 9 2 0 30 3840 0
mqnode 416 3 6 3 0 30 3744 0
KMAP ENTRY 96 12 27 12 0 0 3744 0
vmem 1856 1 1 1 0 8 3712 0
SMR CPU 32 3 60 3 0 254 2016 0
SMR SHARED 24 3 60 3 0 254 1512 0
FFS1 dinode 128 0 0 0 0 126 0 0
swblk 136 0 0 0 0 62 0 0
swpctrie 144 0 0 0 0 62 0 0
sctp_asconf_ack 48 0 0 0 0 254 0 0
sctp_asconf 40 0 0 0 0 254 0 0
pf state scrubs 40 0 0 0 0 254 0 0
pf frag entries 40 0 0 0 0 254 0 0
pf frags 248 0 0 0 0 62 0 0
pf table entries 160 0 0 0 0 62 0 0
pf table entry counters 64 0 0 0 0 254 0 0
pf source nodes 136 0 0 0 0 254 0 0
pf state keys 88 0 0 0 0 126 0 0
pf states 296 0 0 0 0 254 0 0
pf tags 104 0 0 0 0 126 0 0
pf mtags 48 0 0 0 0 254 0 0
tcp_bbr_pcb 832 0 0 0 0 16 0 0
tcp_bbr_map 128 0 0 0 0 126 0 0
tcp_rack_pcb 704 0 0 0 0 16 0 0
tcp_rack_map 120 0 0 0 0 126 0 0
IPsec SA lft_c 16 0 0 0 0 254 0 0
tcp_log_node 120 0 0 0 0 126 0 0
tcp_log_bucket 176 0 0 0 0 62 0 0
tcp_log 416 0 0 0 0 254 0 0
tcpreass 48 0 0 0 0 254 0 0
tfo_ccache_entries 80 0 0 0 0 126 0 0
tfo 4 0 0 0 0 254 0 0
sackhole 32 0 0 0 0 254 0 0
tcptw 88 0 0 0 0 254 0 0
ipq 56 0 0 0 0 254 0 0
itimer 352 0 0 0 0 30 0 0
AIOLIO 272 0 0 0 0 30 0 0
AIOCB 552 0 0 0 0 16 0 0
AIOP 32 0 0 0 0 254 0 0
AIO 208 0 0 0 0 62 0 0
NCLNODE 584 0 0 0 0 16 0 0
mqnotifier 216 0 0 0 0 62 0 0
mvdata 64 0 0 0 0 254 0 0
mqueue 248 0 0 0 0 62 0 0
TMPFS node 224 0 0 0 0 62 0 0
LTS VFS Cache 360 0 0 0 0 30 0 0
L VFS Cache 320 0 0 0 0 30 0 0
STS VFS Cache 144 0 0 0 0 62 0 0
linux_dma_object 24 0 0 0 0 254 0 0
linux_dma_pctrie 144 0 0 0 0 62 0 0
IOMMU_MAP_ENTRY 120 0 0 0 0 126 0 0
ktls_session 192 0 0 0 0 62 0 0
mbuf_jumbo_16k 16384 0 0 0 0 254 0 0
mbuf_jumbo_9k 9216 0 0 0 0 254 0 0
audit_record 1280 0 0 0 0 8 0 0
domainset 40 0 0 0 0 254 0 0
MAC labels 40 0 0 0 0 254 0 0
vnpbuf 2624 0 0 0 0 64 0 0
mdpbuf 2624 0 0 0 0 3 0 0
nfspbuf 2624 0 0 0 0 16 0 0
swwbuf 2624 0 0 0 0 8 0 0
swrbuf 2624 0 0 0 0 16 0 0
umtx_shm 88 0 0 0 0 126 0 0
umtx pi 96 0 0 0 0 126 0 0
rangeset pctrie nodes 144 0 0 0 0 62 0 0
malloc-65536 65536 0 0 0 0 1 0 0
malloc-65536 65536 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-16384 16384 0 0 0 0 1 0 0
malloc-16384 16384 0 0 0 0 1 0 0
malloc-16384 16384 0 0 0 0 1 0 0
malloc-16384 16384 0 0 0 0 1 0 0
malloc-16384 16384 0 0 0 0 1 0 0
malloc-8192 8192 0 0 0 0 1 0 0
malloc-4096 4096 0 0 0 0 2 0 0
malloc-4096 4096 0 0 0 0 2 0 0
malloc-512 512 0 0 0 0 30 0 0
malloc-512 512 0 0 0 0 30 0 0
malloc-512 512 0 0 0 0 30 0 0
pcpu-32 32 0 0 0 0 254 0 0
pcpu-4 4 0 0 0 0 254 0 0
fakepg 104 0 0 0 0 126 0 0
UMA Hash 256 0 0 0 0 62 0 0


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
May 6, 2021, 8:51:22 AM5/6/21
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 49c894dd powerpc64: Split out DMAP and non-DMAP implementa..
git tree: https://github.com/freebsd/freebsd-src.git main
console output: https://syzkaller.appspot.com/x/log.txt?x=11ab97c3d00000
dashboard link: https://syzkaller.appspot.com/bug?extid=007341439ae295cee74f
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=12f5af0bd00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=155a8d2dd00000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+007341...@syzkaller.appspotmail.com

panic: AEAD without a separate IV
cpuid = 1
time = 1620305314
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame 0xfffffe008854c510
vpanic() at vpanic+0x1c7/frame 0xfffffe008854c570
panic() at panic+0x43/frame 0xfffffe008854c5d0
crp_sanity() at crp_sanity+0x94a/frame 0xfffffe008854c630
crypto_dispatch() at crypto_dispatch+0x1a/frame 0xfffffe008854c660
crypto_ioctl() at crypto_ioctl+0x2b05/frame 0xfffffe008854c780
devfs_ioctl() at devfs_ioctl+0x14e/frame 0xfffffe008854c7e0
VOP_IOCTL_APV() at VOP_IOCTL_APV+0x78/frame 0xfffffe008854c810
vn_ioctl() at vn_ioctl+0x278/frame 0xfffffe008854c930
devfs_ioctl_f() at devfs_ioctl_f+0x47/frame 0xfffffe008854c970
kern_ioctl() at kern_ioctl+0x3cd/frame 0xfffffe008854c9e0
sys_ioctl() at sys_ioctl+0x265/frame 0xfffffe008854cab0
amd64_syscall() at amd64_syscall+0x247/frame 0xfffffe008854cbf0
fast_syscall_common() at fast_syscall_common+0xf8/frame 0xfffffe008854cbf0
--- syscall (0, FreeBSD ELF64, nosys), rip = 0x2b3d1a, rsp = 0x7fffffffea68, rbp = 0x7fffffffea80 ---
KDB: enter: panic
[ thread pid 785 tid 100112 ]
Stopped at kdb_enter+0x67: movq $0,0x163a5ae(%rip)
db>
db> set $lines = 0
db> set $maxwidth = 0
db> show registers
cs 0x20
ds 0x3b
es 0x3b
fs 0x13
gs 0x1b
ss 0x28
rax 0x12
rcx 0x80
rdx 0xffffffff819c182a
rbx 0
rsp 0xfffffe008854c4f0
rbp 0xfffffe008854c510
rsi 0x1
rdi 0
r8 0
r9 0x8080808080808080
r10 0xfffffe008854c3e0
r11 0x1ff77fff59c
r12 0xffffffff82267ac0 ddb_dbbe
r13 0
r14 0xffffffff81a72b70
r15 0xffffffff81a72b70
rip 0xffffffff8112ebd7 kdb_enter+0x67
rflags 0x86
kdb_enter+0x67: movq $0,0x163a5ae(%rip)
db> show proc
Process 785 (syz-executor6902623) at 0xfffff8003160d000:
state: NORMAL
uid: 0 gids: 0, 0, 5
parent: pid 783 at 0xfffff800316d3538
ABI: FreeBSD ELF64
flag: 0x10004000 flag2: 0
arguments: ./syz-executor690262386
reaper: 0xfffff8000452a538 reapsubtree: 1
sigparent: 20
vmspace: 0xfffffe00557c03e0
(map 0xfffffe00557c03e0)
(map.pmap 0xfffffe00557c04a0)
(pmap 0xfffffe00557c0500)
threads: 1
100112 Run CPU 1 syz-executor6902623
db> ps
pid ppid pgrp uid state wmesg wchan cmd
785 783 783 0 R CPU 1 syz-executor6902623
783 781 783 0 Ss pause 0xfffff800316d35e8 csh
781 694 781 0 Rs CPU 0 sshd
760 1 760 0 Ss+ ttyin 0xfffff800049d8cb0 getty
759 1 759 0 Ss+ ttyin 0xfffff80004cf58b0 getty
758 1 758 0 Ss+ ttyin 0xfffff80004cf5cb0 getty
757 1 757 0 Ss+ ttyin 0xfffff80004cfd0b0 getty
756 1 756 0 Ss+ ttyin 0xfffff80004cfd4b0 getty
755 1 755 0 Ss+ ttyin 0xfffff80004cfd8b0 getty
754 1 754 0 Ss+ ttyin 0xfffff80004cfdcb0 getty
753 1 753 0 Ss+ ttyin 0xfffff80004c700b0 getty
752 1 752 0 Ss+ ttyin 0xfffff80004c704b0 getty
750 1 24 0 S+ piperd 0xfffff800314b2000 logger
749 748 24 0 S+ nanslp 0xffffffff8273c8e1 sleep
748 1 24 0 S+ wait 0xfffff8003151d000 sh
698 1 698 0 Ss nanslp 0xffffffff8273c8e0 cron
694 1 694 0 Ss select 0xfffff80004fe0b40 sshd
507 1 507 0 Ss select 0xfffff80004fe09c0 syslogd
436 1 436 0 Ss select 0xfffff80004fe0940 devd
435 1 435 65 Ss select 0xfffff80004fe08c0 dhclient
350 1 350 0 Ss select 0xfffff80004fe07c0 dhclient
347 1 347 0 Ss select 0xfffff80004fe0ac0 dhclient
23 0 0 0 DL syncer 0xffffffff8282bd50 [syncer]
22 0 0 0 DL vlruwt 0xfffff80004cd7538 [vnlru]
21 0 0 0 DL (threaded) [bufdaemon]
100080 D qsleep 0xffffffff8282ae00 [bufdaemon]
100085 D - 0xffffffff8220ae00 [bufspacedaemon-0]
100095 D sdflush 0xfffff80004fa0ce8 [/ worker]
20 0 0 0 DL psleep 0xffffffff82852c08 [vmdaemon]
19 0 0 0 DL (threaded) [pagedaemon]
100078 D psleep 0xffffffff82847078 [dom0]
100086 D launds 0xffffffff82847084 [laundry: dom0]
100087 D umarcl 0xffffffff815c8de0 [uma]
18 0 0 0 DL - 0xffffffff82570c78 [rand_harvestq]
17 0 0 0 DL waiting 0xffffffff82e34828 [sctp_iterator]
16 0 0 0 DL pftm 0xffffffff8305a3c0 [pf purge]
15 0 0 0 DL - 0xffffffff8282845c [soaiod4]
9 0 0 0 DL - 0xffffffff8282845c [soaiod3]
8 0 0 0 DL - 0xffffffff8282845c [soaiod2]
7 0 0 0 DL - 0xffffffff8282845c [soaiod1]
6 0 0 0 DL (threaded) [cam]
100043 D - 0xffffffff82448140 [doneq0]
100044 D - 0xffffffff824480c0 [async]
100077 D - 0xffffffff82447f90 [scanner]
14 0 0 0 DL seqstat 0xfffff8000463b888 [sequencer 00]
5 0 0 0 DL crypto_ 0xfffff8000462fd80 [crypto returns 1]
4 0 0 0 DL crypto_ 0xfffff8000462fd30 [crypto returns 0]
100037 D - 0xfffff8000462ee00 [crypto_0]
100038 D - 0xfffff8000462ee00 [crypto_1]
100054 D - 0xfffff8000462e800 [vtnet0 rxq 0]
100055 D - 0xfffff8000462e700 [vtnet0 txq 0]
100056 D - 0xfffff8000462e600 [vtnet0 rxq 1]
100057 D - 0xfffff8000462e500 [vtnet0 txq 1]
100059 D vtbslp 0xfffff80004974100 [virtio_balloon]
100063 D - 0xfffff80004973b00 [mca taskq]
100065 D - 0xffffffff81e1f4b1 [deadlkres]
100072 D - 0xfffff80004c3c700 [acpi_task_0]
100073 D - 0xfffff80004c3c700 [acpi_task_1]
100074 D - 0xfffff80004c3c700 [acpi_task_2]
100076 D - 0xfffff8000462ed00 [CAM taskq]
db> show all locks
Process 781 (sshd) thread 0xfffffe00557f4900 (100106)
exclusive sx so_snd_sx (so_snd_sx) r = 0 (0xfffff80004fa8d90) locked @ /syzkaller/managers/main/kernel/sys/kern/uipc_sockbuf.c:467
db> show malloc
Type InUse MemUse Requests
pf_hash 5 11524K 5
devbuf 4216 4340K 4241
tcp_hpts 5 3201K 5
sysctloid 33530 1980K 33597
vtbuf 24 1968K 46
kobj 332 1328K 492
newblk 583 1170K 601
vfscache 3 1025K 3
pcb 23 537K 77
inodedep 49 530K 71
ufs_quota 1 512K 1
vfs_hash 1 512K 1
callout 2 512K 2
intr 4 472K 4
subproc 98 204K 838
acpica 1674 184K 55406
vnet_data 1 168K 1
tidhash 3 141K 3
pagedep 14 132K 18
tfo_ccache 1 128K 1
sem 4 106K 4
DEVFS1 103 103K 112
linker 294 102K 318
bus 995 81K 3509
mtx_pool 2 72K 2
syncache 1 68K 1
acpitask 1 64K 1
ddb_capture 1 64K 1
module 508 64K 508
temp 18 33K 1605
hostcache 1 32K 1
shm 1 32K 1
kdtrace 161 32K 901
DEVFS3 122 31K 132
umtx 242 31K 242
msg 4 30K 4
vmem 3 26K 5
gtaskqueue 18 26K 18
kbdmux 6 22K 6
DEVFS_RULE 56 20K 56
BPF 10 18K 10
ufs_mount 5 17K 6
proc 3 17K 3
tty 16 16K 16
ithread 99 16K 99
bus-sc 33 14K 1719
KTRACE 100 13K 100
kenv 93 12K 93
eventhandler 133 12K 133
ifaddr 30 12K 32
routetbl 50 11K 176
rman 84 10K 425
GEOM 60 10K 489
bmsafemap 2 9K 39
UART 12 9K 12
devstat 4 9K 4
ksem 1 8K 1
rpc 2 8K 2
shmfd 1 8K 1
pfs_vncache 1 8K 1
pfs_nodes 20 8K 20
audit_evclass 236 8K 294
sglist 5 7K 5
CAM DEV 3 6K 510
taskqueue 57 6K 57
cred 23 6K 234
CAM queue 5 6K 1528
ufs_dirhash 24 5K 24
xform 7 5K 54
UMA 265 5K 265
dirrem 17 5K 28
plimit 17 5K 322
vt 11 5K 11
ifnet 3 5K 3
memdesc 1 4K 1
MCA 32 4K 32
evdev 4 4K 4
filedesc 1 4K 1
acpisem 28 4K 28
hhook 13 4K 13
ether_multi 40 4K 50
diradd 25 4K 36
lltable 11 4K 11
pf_ifnet 5 3K 6
fpukern_ctx 3 3K 3
in6_multi 25 3K 25
kqueue 46 3K 788
pwddesc 46 3K 786
terminal 11 3K 11
session 20 3K 31
uidinfo 3 3K 8
local_apic 1 2K 1
io_apic 1 2K 1
ipsec-saq 2 2K 2
proc-args 39 2K 488
crypto 5 2K 5
Unitno 27 2K 39
CAM XPT 22 2K 543
lockf 15 2K 22
ipsecpolicy 2 2K 2
acpidev 20 2K 20
selfd 20 2K 9635
msi 9 2K 9
clone 9 2K 9
softdep 1 1K 1
sahead 1 1K 1
secasvar 1 1K 1
vnodemarker 2 1K 8
NFSD session 1 1K 1
CAM periph 4 1K 271
select 7 1K 29
ipsec 3 1K 3
indirdep 3 1K 3
nhops 6 1K 6
toponodes 6 1K 6
isadev 6 1K 6
mount 16 1K 89
pci_link 10 1K 10
sctp_ifa 5 1K 6
ip6ndp 4 1K 5
encap_export_host 12 1K 12
newdirblk 4 1K 8
mkdir 4 1K 16
in_multi 2 1K 4
pfil 4 1K 4
CAM SIM 2 1K 2
cdev 2 1K 2
chacha20random 1 1K 1
DEVFSP 5 1K 10
inpcbpolicy 10 1K 137
osd 3 1K 10
sctp_ifn 2 1K 6
NFSD lckfile 1 1K 1
NFSD V4client 1 1K 1
DEVFS 9 1K 10
mld 2 1K 2
igmp 2 1K 2
vnodes 1 1K 1
ktls 1 1K 1
feeder 7 1K 7
tcpfunc 3 1K 3
loginclass 3 1K 7
prison 6 1K 6
linux 5 1K 6
aesni_data 2 1K 2
apmdev 1 1K 1
atkbddev 2 1K 2
CAM dev queue 2 1K 2
CAM I/O Scheduler 1 1K 1
CAM path 4 1K 1034
procdesc 1 1K 6
pmchooks 1 1K 1
nexusdev 7 1K 7
soname 4 1K 3231
filecaps 4 1K 66
tun 3 1K 3
sctp_vrf 1 1K 1
vnet 1 1K 1
entropy 2 1K 35
acpiintr 1 1K 1
pmc 1 1K 1
cpus 2 1K 2
vnet_data_free 1 1K 1
Per-cpu 1 1K 1
freework 1 1K 26
p1003.1b 1 1K 1
pf_table 0 0K 0
pf_rule 0 0K 0
pf_altq 0 0K 0
pf_osfp 0 0K 0
pf_temp 0 0K 0
mqdata 0 0K 0
sctp_mcore 0 0K 0
sctp_socko 0 0K 0
sctp_iter 0 0K 3
sctp_mvrf 0 0K 0
sctp_timw 0 0K 0
sctp_cpal 0 0K 0
sctp_cmsg 0 0K 0
sctp_stre 0 0K 0
sctp_athi 0 0K 0
sctp_athm 0 0K 0
sctp_atky 0 0K 0
sctp_atcl 0 0K 0
sctp_a_it 0 0K 3
sctp_aadr 0 0K 0
sctp_stro 0 0K 0
sctp_stri 0 0K 0
sctp_map 0 0K 0
savedino 0 0K 19
sentinel 0 0K 0
jfsync 0 0K 0
jtrunc 0 0K 0
sbdep 0 0K 2
jsegdep 0 0K 0
jseg 0 0K 0
jfreefrag 0 0K 0
jfreeblk 0 0K 0
jnewblk 0 0K 0
jmvref 0 0K 0
jremref 0 0K 0
jaddref 0 0K 0
freedep 0 0K 0
freefile 0 0K 9
freeblks 0 0K 25
freefrag 0 0K 7
statfs 0 0K 195
namei_tracker 0 0K 0
export_host 0 0K 0
cl_savebuf 0 0K 6
tcp_log_dev 0 0K 0
midi buffers 0 0K 0
mixer 0 0K 0
ac97 0 0K 0
hdacc 0 0K 0
hdac 0 0K 0
hdaa 0 0K 0
acpicmbat 0 0K 0
SIIS driver 0 0K 0
CAM CCB 0 0K 1743
PUC 0 0K 0
ppbusdev 0 0K 0
agtiapi_MemAlloc malloc 0 0K 0
osti_cacheable 0 0K 0
tempbuff 0 0K 0
biobuf 0 0K 0
aios 0 0K 0
lio 0 0K 0
acl 0 0K 0
tempbuff 0 0K 0
mbuf_tag 0 0K 27
ag_tgt_map_t malloc 0 0K 0
ag_slr_map_t malloc 0 0K 0
lDevFlags * malloc 0 0K 0
tiDeviceHandle_t * malloc 0 0K 0
ag_portal_data_t malloc 0 0K 0
ag_device_t malloc 0 0K 0
STLock malloc 0 0K 0
CCB List 0 0K 0
sr_iov 0 0K 0
OCS 0 0K 0
OCS 0 0K 0
nvme 0 0K 0
nvd 0 0K 0
netmap 0 0K 0
mwldev 0 0K 0
MVS driver 0 0K 0
CAM ccb queue 0 0K 0
mrsasbuf 0 0K 0
mpt_user 0 0K 0
mps_user 0 0K 0
accf 0 0K 0
pts 0 0K 0
iov 0 0K 13511
ioctlops 0 0K 86
eventfd 0 0K 0
Witness 0 0K 0
stack 0 0K 0
MPSSAS 0 0K 0
mps 0 0K 0
mpr_user 0 0K 0
MPRSAS 0 0K 0
mpr 0 0K 0
mfibuf 0 0K 0
sbuf 0 0K 288
md_sectors 0 0K 0
firmware 0 0K 0
compressor 0 0K 0
md_disk 0 0K 0
SWAP 0 0K 0
malodev 0 0K 0
LED 0 0K 0
sysctltmp 0 0K 618
sysctl 0 0K 3
ekcd 0 0K 0
dumper 0 0K 0
sendfile 0 0K 0
rctl 0 0K 0
ix_sriov 0 0K 0
aacraidcam 0 0K 0
aacraid_buf 0 0K 0
ix 0 0K 0
ipsbuf 0 0K 0
cache 0 0K 0
iirbuf 0 0K 0
kcovinfo 0 0K 0
mbuf_jumbo_page 4096 8320 706 13298 0 254 36970496 0
pbuf 2624 0 989 0 0 2 2595136 0
mbuf 256 8577 813 15381 0 254 2403840 0
BUF TRIE 144 175 13293 424 0 62 1939392 0
malloc-384 384 4116 4 4116 0 30 1582080 0
malloc-128 128 10989 47 11000 0 126 1412608 0
malloc-4096 4096 332 2 492 0 2 1368064 0
UMA Slabs 0 112 9820 5 9820 0 126 1100400 0
FFS inode 1160 499 12 508 0 8 592760 0
lkpimm 160 1 2324 1 0 62 372000 0
lkpicurr 160 2 2323 2 0 62 372000 0
RADIX NODE 144 2060 149 20166 0 62 318096 0
malloc-65536 65536 4 0 4 0 1 262144 0
malloc-64 64 3987 108 4974 0 254 262080 0
VM OBJECT 264 892 53 12691 0 30 249480 0
VNODE 448 529 20 540 0 30 245952 0
malloc-4096 4096 56 3 796 0 2 241664 0
256 Bucket 2048 102 16 10052 0 8 241664 0
malloc-16 16 13710 290 13781 0 254 224000 0
DEVCTL 1024 0 216 116 0 0 221184 0
THREAD 1808 114 7 114 0 8 218768 0
malloc-65536 65536 1 2 183 0 1 196608 0
UMA Zones 768 237 2 237 0 16 183552 0
malloc-256 256 679 11 1011 0 62 176640 0
malloc-128 128 1282 51 29050 0 126 170624 0
malloc-32 32 5172 120 5976 0 254 169344 0
FFS2 dinode 256 499 26 508 0 62 134400 0
malloc-65536 65536 2 0 2 0 1 131072 0
malloc-65536 65536 0 2 8 0 1 131072 0
malloc-128 128 928 33 1905 0 126 123008 0
ksiginfo 112 34 1010 49 0 126 116928 0
MAP ENTRY 96 836 382 38043 0 126 116928 0
malloc-1024 1024 104 8 116 0 16 114688 0
S VFS Cache 104 966 87 1007 0 126 109512 0
vmem btag 56 1881 51 1881 0 254 108192 0
malloc-16384 16384 4 2 181 0 1 98304 0
malloc-8192 8192 9 3 138 0 1 98304 0
UMA Kegs 384 222 1 222 0 30 85632 0
malloc-2048 2048 2 38 1745 0 8 81920 0
VMSPACE 2544 23 4 764 0 4 68688 0
PROC 1336 45 6 785 0 8 68136 0
mbuf_cluster 2048 30 2 30 0 254 65536 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-32768 32768 0 2 130 0 1 65536 0
malloc-32768 32768 2 0 2 0 1 65536 0
malloc-4096 4096 14 2 110 0 2 65536 0
g_bio 408 0 150 4446 0 30 61200 0
filedesc0 1072 46 10 786 0 8 60032 0
malloc-256 256 175 50 752 0 62 57600 0
malloc-16384 16384 3 0 3 0 1 49152 0
malloc-2048 2048 4 20 511 0 8 49152 0
128 Bucket 1024 37 10 602 0 16 48128 0
malloc-64 64 526 167 14820 0 254 44352 0
malloc-128 128 293 48 452 0 126 43648 0
malloc-256 256 140 25 157 0 62 42240 0
32 Bucket 256 46 119 6759 0 62 42240 0
clpbuf 2624 0 16 18 0 16 41984 0
malloc-8192 8192 5 0 5 0 1 40960 0
malloc-8192 8192 3 2 5 0 1 40960 0
DIRHASH 1024 34 2 34 0 16 36864 0
NAMEI 1024 0 36 11992 0 16 36864 0
malloc-4096 4096 8 1 540 0 2 36864 0
malloc-512 512 4 68 512 0 30 36864 0
pcpu-8 8 4150 458 4178 0 254 36864 0
malloc-64 64 487 80 704 0 254 36288 0
malloc-384 384 68 22 102 0 30 34560 0
malloc-32768 32768 1 0 1 0 1 32768 0
pcpu-64 64 478 34 478 0 254 32768 0
64 Bucket 512 57 7 1287 0 30 32768 0
malloc-256 256 82 38 137 0 62 30720 0
malloc-128 128 118 99 419 0 126 27776 0
malloc-384 384 68 2 68 0 30 26880 0
socket 944 18 10 1253 0 254 26432 0
malloc-1024 1024 10 14 1078 0 16 24576 0
malloc-1024 1024 18 6 22 0 16 24576 0
ttyinq 160 135 15 300 0 62 24000 0
tcpcb 1048 3 19 7 0 254 23056 0
ttyoutq 256 72 18 160 0 62 23040 0
malloc-384 384 52 8 52 0 30 23040 0
pipe 744 7 23 284 0 16 22320 0
malloc-4096 4096 3 2 199 0 2 20480 0
malloc-2048 2048 6 4 83 0 8 20480 0
TURNSTILE 136 122 25 122 0 62 19992 0
Mountpoints 2752 2 5 2 0 4 19264 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-8192 8192 2 0 2 0 1 16384 0
malloc-2048 2048 6 2 6 0 8 16384 0
malloc-1024 1024 12 4 12 0 16 16384 0
malloc-1024 1024 12 4 12 0 16 16384 0
malloc-64 64 127 125 155 0 254 16128 0
malloc-32 32 335 169 433 0 254 16128 0
8 Bucket 80 38 162 406 0 126 16000 0
udp_inpcb 488 6 26 126 0 254 15616 0
SLEEPQUEUE 88 122 38 122 0 126 14080 0
malloc-2048 2048 3 3 268 0 8 12288 0
malloc-2048 2048 5 1 196 0 8 12288 0
malloc-1024 1024 5 7 21 0 16 12288 0
malloc-1024 1024 8 4 9 0 16 12288 0
malloc-512 512 3 21 189 0 30 12288 0
malloc-64 64 59 130 9703 0 254 12096 0
malloc-64 64 115 74 1622 0 254 12096 0
Files 80 72 78 6501 0 126 12000 0
kenv 258 15 30 1049 0 30 11610 0
malloc-256 256 14 31 102 0 62 11520 0
malloc-256 256 20 25 617 0 62 11520 0
malloc-256 256 13 32 354 0 62 11520 0
malloc-8192 8192 1 0 1 0 1 8192 0
malloc-8192 8192 1 0 1 0 1 8192 0
malloc-8192 8192 1 0 1 0 1 8192 0
malloc-4096 4096 0 2 3 0 2 8192 0
malloc-2048 2048 3 1 3 0 8 8192 0
malloc-1024 1024 0 8 4 0 16 8192 0
malloc-512 512 6 10 12 0 30 8192 0
malloc-512 512 8 8 8 0 30 8192 0
rtentry 176 13 33 17 0 62 8096 0
PGRP 88 20 72 31 0 126 8096 0
rl_entry 40 27 175 27 0 254 8080 0
sctp_laddr 48 0 168 4 0 254 8064 0
udpcb 32 6 246 126 0 254 8064 0
PWD 32 10 242 100 0 254 8064 0
malloc-64 64 8 118 9 0 254 8064 0
malloc-64 64 24 102 292 0 254 8064 0
malloc-32 32 6 246 11 0 254 8064 0
malloc-32 32 37 215 769 0 254 8064 0
malloc-32 32 70 182 3964 0 254 8064 0
malloc-32 32 30 222 189 0 254 8064 0
16 Bucket 144 34 22 198 0 62 8064 0
4 Bucket 48 6 162 53 0 254 8064 0
2 Bucket 32 44 208 501 0 254 8064 0
vtnet_tx_hdr 24 0 334 1243 0 254 8016 0
malloc-16 16 1 499 4 0 254 8000 0
malloc-16 16 20 480 59 0 254 8000 0
malloc-16 16 298 202 504 0 254 8000 0
malloc-16 16 23 477 24 0 254 8000 0
malloc-16 16 189 311 1444 0 254 8000 0
malloc-16 16 26 474 25396 0 254 8000 0
malloc-16 16 14 486 20 0 254 8000 0
malloc-128 128 5 57 11 0 126 7936 0
malloc-128 128 39 23 55 0 126 7936 0
malloc-128 128 10 52 79 0 126 7936 0
tcp_inpcb 488 3 13 7 0 254 7808 0
routing nhops 256 10 20 17 0 62 7680 0
unpcb 256 7 23 1099 0 254 7680 0
mbuf_packet 256 0 30 93 0 254 7680 0
malloc-384 384 0 20 19 0 30 7680 0
malloc-384 384 5 15 352 0 30 7680 0
malloc-384 384 20 0 20 0 30 7680 0
malloc-256 256 21 9 293 0 62 7680 0
FPU_save_area 832 1 8 1 0 16 7488 0
cpuset 104 7 55 7 0 126 6448 0
epoch_record pcpu 256 4 12 4 0 62 4096 0
malloc-2048 2048 1 1 1 0 8 4096 0
malloc-512 512 0 8 2 0 30 4096 0
pcpu-16 16 7 249 7 0 254 4096 0
hostcache 64 1 62 1 0 254 4032 0
syncache 168 0 24 5 0 254 4032 0
malloc-32 32 0 126 2 0 254 4032 0
malloc-32 32 103 23 227 0 254 4032 0
KNOTE 160 0 25 8 0 62 4000 0
cryptop 280 1 13 1 0 30 3920 0
ripcb 488 1 7 4 0 254 3904 0
UMA Slabs 1 176 8 14 8 0 62 3872 0
malloc-384 384 1 9 2 0 30 3840 0
mqnode 416 3 6 3 0 30 3744 0
KMAP ENTRY 96 12 27 12 0 0 3744 0
vmem 1856 1 1 1 0 8 3712 0
SMR CPU 32 3 60 3 0 254 2016 0
SMR SHARED 24 3 60 3 0 254 1512 0
FFS1 dinode 128 0 0 0 0 126 0 0
swblk 136 0 0 0 0 62 0 0
swpctrie 144 0 0 0 0 62 0 0
sctp_asconf_ack 48 0 0 0 0 254 0 0
sctp_asconf 40 0 0 0 0 254 0 0
sctp_stream_msg_out 112 0 0 0 0 254 0 0
sctp_readq 152 0 0 0 0 254 0 0
sctp_chunk 152 0 0 0 0 254 0 0
sctp_raddr 736 0 0 0 0 254 0 0
sctp_asoc 2288 0 0 0 0 254 0 0
sctp_ep 1280 0 0 0 0 254 0 0
pf state scrubs 40 0 0 0 0 254 0 0
pf frag entries 40 0 0 0 0 254 0 0
pf frags 248 0 0 0 0 62 0 0
pf table entries 160 0 0 0 0 62 0 0
pf table entry counters 64 0 0 0 0 254 0 0
pf source nodes 136 0 0 0 0 254 0 0
pf state keys 88 0 0 0 0 126 0 0
pf states 296 0 0 0 0 254 0 0
pf tags 104 0 0 0 0 126 0 0
pf mtags 48 0 0 0 0 254 0 0
tcp_bbr_pcb 832 0 0 0 0 16 0 0
tcp_bbr_map 128 0 0 0 0 126 0 0
tcp_rack_pcb 704 0 0 0 0 16 0 0
tcp_rack_map 120 0 0 0 0 126 0 0
IPsec SA lft_c 16 0 0 0 0 254 0 0
udplite_inpcb 488 0 0 0 0 254 0 0
tcp_log_node 120 0 0 0 0 126 0 0
tcp_log_bucket 176 0 0 0 0 62 0 0
tcp_log 416 0 0 0 0 254 0 0
tcpreass 48 0 0 0 0 254 0 0
tfo_ccache_entries 80 0 0 0 0 126 0 0
tfo 4 0 0 0 0 254 0 0
sackhole 32 0 0 0 0 254 0 0
tcptw 88 0 0 0 0 254 0 0
ipq 56 0 0 0 0 254 0 0
itimer 352 0 0 0 0 30 0 0
AIOLIO 272 0 0 0 0 30 0 0
AIOCB 552 0 0 0 0 16 0 0
AIOP 32 0 0 0 0 254 0 0
AIO 208 0 0 0 0 62 0 0
Reply all
Reply to author
Forward
0 new messages