panic: size_on_reasm_queue is NUM (2)

0 views
Skip to first unread message

syzbot

unread,
Jun 22, 2023, 11:00:52 PM6/22/23
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 781624ca2d05 getfacl: free `acl` in print_acl error path
git tree: freebsd-src
console output: https://syzkaller.appspot.com/x/log.txt?x=15fd9160a80000
dashboard link: https://syzkaller.appspot.com/bug?extid=ea6ebcc99f80ec656579

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+ea6ebc...@syzkaller.appspotmail.com

panic: size_on_reasm_queue is 3
cpuid = 1
time = 1687489116
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0xc7/frame 0xfffffe006a5c6fd0
kdb_backtrace() at kdb_backtrace+0xd1/frame 0xfffffe006a5c7130
vpanic() at vpanic+0x252/frame 0xfffffe006a5c7210
panic() at panic+0xb5/frame 0xfffffe006a5c72e0
sctp_calc_rwnd() at sctp_calc_rwnd+0x279/frame 0xfffffe006a5c7330
sctp_user_rcvd() at sctp_user_rcvd+0x258/frame 0xfffffe006a5c7430
sctp_sorecvmsg() at sctp_sorecvmsg+0x28a7/frame 0xfffffe006a5c76c0
sctp_soreceive() at sctp_soreceive+0x242/frame 0xfffffe006a5c79c0
soreceive() at soreceive+0xe2/frame 0xfffffe006a5c7a30
kern_recvit() at kern_recvit+0x4ef/frame 0xfffffe006a5c7bf0
sys_recvmsg() at sys_recvmsg+0x1bd/frame 0xfffffe006a5c7d30
amd64_syscall() at amd64_syscall+0x40a/frame 0xfffffe006a5c7f30
fast_syscall_common() at fast_syscall_common+0xf8/frame 0xfffffe006a5c7f30
--- syscall (198, FreeBSD ELF64, __syscall), rip = 0x28e66a, rsp = 0x832336f08, rbp = 0x832336f70 ---
KDB: enter: panic
[ thread pid 47599 tid 153218 ]
Stopped at kdb_enter+0x6b: movq $0,0x2145b3a(%rip)
db>
db> set $lines = 0
db> set $maxwidth = 0
db> show registers
cs 0x20
ds 0x3b
es 0x3b
fs 0x13
gs 0x1b
ss 0x28
rax 0x12
rcx 0xfffffe00033eee30
rdx 0xdffff7c000000000
rbx 0
rsp 0xfffffe006a5c7110
rbp 0xfffffe006a5c7130
rsi 0x1
rdi 0
r8 0x3
r9 0xffffffff
r10 0
r11 0xfffffe006d0aae20
r12 0
r13 0xfffffe006d0aa900
r14 0xffffffff8269e000 .str.26
r15 0xffffffff8269e000 .str.26
rip 0xffffffff815ab55b kdb_enter+0x6b
rflags 0x46
kdb_enter+0x6b: movq $0,0x2145b3a(%rip)
db> show proc
Process 47599 (syz-executor.1) at 0xfffffe006d0bab00:
state: NORMAL
uid: 0 gids: 0, 0, 5
parent: pid 780 at 0xfffffe0057bae040
ABI: FreeBSD ELF64
flag: 0x10000080 flag2: 0
arguments: /root/syz-executor.1 exec
reaper: 0xfffffe00541da040 reapsubtree: 1
sigparent: 20
vmspace: 0xfffffe0058faee38
(map 0xfffffe0058faee38)
(map.pmap 0xfffffe0058faeef8)
(pmap 0xfffffe0058faef68)
threads: 4
153192 RunQ syz-executor.1
153216 S connec 0xfffffe0058cc9c1a syz-executor.1
153217 RunQ syz-executor.1
153218 Run CPU 1 syz-executor.1
db> ps
pid ppid pgrp uid state wmesg wchan cmd
47599 780 780 0 R (threaded) syz-executor.1
153192 RunQ syz-executor.1
153216 S connec 0xfffffe0058cc9c1a syz-executor.1
153217 RunQ syz-executor.1
153218 Run CPU 1 syz-executor.1
47597 779 779 0 R (threaded) syz-executor.0
119270 RunQ syz-executor.0
153219 S connec 0xfffffe0058ce20da syz-executor.0
153225 S uwait 0xfffffe006ca0e880 syz-executor.0
153226 S uwait 0xfffffe0058aca080 syz-executor.0
47526 1 779 0 SV uwait 0xfffffe005894ee80 syz-executor.0
47515 1 779 0 SV uwait 0xfffffe0058bd6e00 syz-executor.0
47503 1 779 0 SV uwait 0xfffffe0058ac9f00 syz-executor.0
22637 1 781 0 S uwait 0xfffffe006ca0fc00 syz-executor.2
22631 1 781 0 S uwait 0xfffffe006ca0ea80 syz-executor.2
19801 0 0 0 DL - 0xffffffff836aa460 [accounting]
16135 1 779 0 S uwait 0xfffffe006ca0f300 syz-executor.0
16131 1 779 0 S uwait 0xfffffe006ca0db00 syz-executor.0
16127 1 779 0 S uwait 0xfffffe0058b71d00 syz-executor.0
6081 1 6081 65 Ss select 0xfffffe006ca0d440 dhclient
5122 1 5122 0 Ss select 0xfffffe006ca0d4c0 dhclient
5119 1 5119 0 Ss select 0xfffffe006ca0d540 dhclient
5100 1 5100 65 Ss select 0xfffffe0058acab40 dhclient
4640 1 4640 0 Ss select 0xfffffe0058acaac0 dhclient
4636 1 4636 0 Ss select 0xfffffe0058acaa40 dhclient
4617 1 4617 65 Ss select 0xfffffe0058aca940 dhclient
4012 1 4012 0 Ss select 0xfffffe0058aca6c0 dhclient
4009 1 4009 0 Ss select 0xfffffe006ca0d740 dhclient
3990 1 3990 65 Ss select 0xfffffe006ca0e3c0 dhclient
2543 0 0 0 DL aiordy 0xfffffe006cdb8020 [aiod4]
2542 0 0 0 DL aiordy 0xfffffe0057184040 [aiod3]
2541 0 0 0 DL aiordy 0xfffffe0057183ae0 [aiod2]
2539 0 0 0 DL aiordy 0xfffffe00571845a0 [aiod1]
1553 1 1553 0 Ss select 0xfffffe0058aca4c0 dhclient
1550 1 1550 0 Ss select 0xfffffe0058ac9840 dhclient
790 776 790 0 Ss piperd 0xfffffe006d08b888 syz-executor.3
781 776 781 0 Ss piperd 0xfffffe006d08cc70 syz-executor.2
780 776 780 0 Rs syz-executor.1
779 776 779 0 Rs syz-executor.0
776 774 774 0 S (threaded) syz-fuzzer
100110 S wait 0xfffffe006cdb7000 syz-fuzzer
100112 S uwait 0xfffffe0058b74480 syz-fuzzer
100113 S wait 0xfffffe006cdb7000 syz-fuzzer
100114 S wait 0xfffffe006cdb7000 syz-fuzzer
100115 S uwait 0xfffffe0058b73a80 syz-fuzzer
100116 S uwait 0xfffffe0058b73980 syz-fuzzer
100117 S uwait 0xfffffe0058b74180 syz-fuzzer
100119 S uwait 0xfffffe0058b73880 syz-fuzzer
100122 S wait 0xfffffe006cdb7000 syz-fuzzer
100128 S uwait 0xfffffe006ca0f000 syz-fuzzer
100130 S uwait 0xfffffe0058b73780 syz-fuzzer
100140 S kqread 0xfffffe000798f800 syz-fuzzer
101845 S uwait 0xfffffe0058ac9400 syz-fuzzer
774 772 774 0 Ss pause 0xfffffe0058ee6670 csh
772 688 772 0 Ss select 0xfffffe005894e6c0 sshd
754 1 754 0 Ss+ ttyin 0xfffffe0057665cb0 getty
753 1 753 0 Ss+ ttyin 0xfffffe0057b5f4b0 getty
752 1 752 0 Ss+ ttyin 0xfffffe0057b5f8b0 getty
751 1 751 0 Ss+ ttyin 0xfffffe0057b5fcb0 getty
750 1 750 0 Ss+ ttyin 0xfffffe00576648b0 getty
749 1 749 0 Ss+ ttyin 0xfffffe0057664cb0 getty
748 1 748 0 Ss+ ttyin 0xfffffe0057b600b0 getty
747 1 747 0 Ss+ ttyin 0xfffffe0057b604b0 getty
746 1 746 0 Ss+ ttyin 0xfffffe0057b608b0 getty
692 1 692 0 Ss nanslp 0xffffffff836d2841 cron
688 1 688 0 Ss select 0xfffffe006ca0fd40 sshd
501 1 501 0 Ss select 0xfffffe0058b74c40 syslogd
430 1 430 0 Ss select 0xfffffe0058b752c0 devd
429 1 429 65 Ss select 0xfffffe0058b74bc0 dhclient
344 1 344 0 Ss select 0xfffffe005894e140 dhclient
341 1 341 0 Ss select 0xfffffe0058b74ac0 dhclient
17 0 0 0 DL vlruwt 0xfffffe00541db5c0 [vnlru]
16 0 0 0 DL syncer 0xffffffff837d4d20 [syncer]
15 0 0 0 DL (threaded) [bufdaemon]
100079 D psleep 0xffffffff837d3340 [bufdaemon]
100082 D - 0xffffffff82c0a140 [bufspacedaemon-0]
100093 D sdflush 0xfffffe005407b0e8 [/ worker]
9 0 0 0 DL psleep 0xffffffff8380ac00 [vmdaemon]
8 0 0 0 DL (threaded) [pagedaemon]
100077 D psleep 0xffffffff837feab8 [dom0]
100080 D launds 0xffffffff837feac4 [laundry: dom0]
100081 D umarcl 0xffffffff81d24960 [uma]
7 0 0 0 RL [rand_harvestq]
6 0 0 0 RL [pf purge]
5 0 0 0 DL waiting 0xffffffff841821c0 [sctp_iterator]
4 0 0 0 DL (threaded) [cam]
100044 D - 0xffffffff83479340 [doneq0]
100045 D - 0xffffffff834792c0 [async]
100076 D - 0xffffffff83479140 [scanner]
14 0 0 0 DL seqstat 0xfffffe0054383c88 [sequencer 00]
3 0 0 0 DL (threaded) [crypto]
100040 D crypto_ 0xffffffff837fa360 [crypto]
100041 D crypto_ 0xfffffe005408ce30 [crypto returns 0]
100042 D crypto_ 0xfffffe005408ce80 [crypto returns 1]
13 0 0 0 DL (threaded) [geom]
100035 D - 0xffffffff836a8640 [g_event]
100036 D - 0xffffffff836a8660 [g_up]
100037 D - 0xffffffff836a8680 [g_down]
2 0 0 0 WL (threaded) [clock]
100029 I [clock (0)]
100030 I [clock (1)]
12 0 0 0 RL (threaded) [intr]
100016 I [swi5: fast taskq]
100019 I [swi6: task queue]
100020 I [swi6: Giant taskq]
100031 Run CPU 0 [swi1: netisr 0]
100032 I [swi1: hpts]
100033 I [swi1: hpts]
100046 I [irq24: virtio_pci0]
100047 I [irq25: virtio_pci0]
100048 I [irq26: virtio_pci0]
100049 I [irq27: virtio_pci0]
100050 I [irq28: virtio_pci1]
100051 I [irq29: virtio_pci1]
100052 I [irq30: virtio_pci1]
100053 I [irq31: virtio_pci1]
100054 I [irq32: virtio_pci1]
100059 I [irq33: virtio_pci2]
100060 I [irq34: virtio_pci2]
100061 I [irq35: virtio_pci2]
100063 I [irq1: atkbd0]
100064 I [irq12: psm0]
100065 I [swi0: uart uart++]
100069 I [swi1: pf send]
11 0 0 0 RL (threaded) [idle]
100003 CanRun [idle: cpu0]
100004 CanRun [idle: cpu1]
1 0 1 0 SLs wait 0xfffffe00541da040 [init]
10 0 0 0 DL audit_w 0xffffffff837fada0 [audit]
0 0 0 0 DLs (threaded) [kernel]
100000 D swapin 0xffffffff836a9060 [swapper]
100005 D - 0xfffffe0054297100 [if_io_tqg_0]
100006 D - 0xfffffe0054297000 [if_io_tqg_1]
100007 D - 0xfffffe0054296e00 [if_config_tqg_0]
100008 D - 0xfffffe0054296d00 [softirq_0]
100009 D - 0xfffffe0054296c00 [softirq_1]
100010 D - 0xfffffe00085ff300 [linuxkpi_irq_wq]
100011 D - 0xfffffe00085ff100 [thread taskq]
100012 D - 0xfffffe00085fee00 [inm_free taskq]
100013 D - 0xfffffe00085fec00 [aiod_kick taskq]
100014 D - 0xfffffe00085fea00 [deferred_unmount ta]
100015 D - 0xfffffe00085fe800 [in6m_free taskq]
100017 D - 0xfffffe00085fe400 [kqueue_ctx taskq]
100018 D - 0xfffffe00085fe200 [pci_hp taskq]
100021 D - 0xfffffe00085fdb00 [linuxkpi_short_wq_0]
100022 D - 0xfffffe00085fdb00 [linuxkpi_short_wq_1]
100023 D - 0xfffffe00085fdb00 [linuxkpi_short_wq_2]
100024 D - 0xfffffe00085fdb00 [linuxkpi_short_wq_3]
100025 D - 0xfffffe00085fd600 [linuxkpi_long_wq_0]
100026 D - 0xfffffe00085fd600 [linuxkpi_long_wq_1]
100027 D - 0xfffffe00085fd600 [linuxkpi_long_wq_2]
100028 D - 0xfffffe00085fd600 [linuxkpi_long_wq_3]
100034 D - 0xfffffe00085fcb00 [firmware taskq]
100038 D - 0xfffffe00085fc600 [crypto_0]
100039 D - 0xfffffe00085fc600 [crypto_1]
100055 D - 0xfffffe00570bd900 [vtnet0 rxq 0]
100056 D - 0xfffffe00570bd800 [vtnet0 txq 0]
100057 D - 0xfffffe00570bd700 [vtnet0 rxq 1]
100058 D - 0xfffffe00570bd600 [vtnet0 txq 1]
100062 D vtbslp 0xfffffe005715f300 [virtio_balloon]
100066 D - 0xffffffff826a2f40 [deadlkres]
100070 D - 0xfffffe0057a87500 [acpi_task_0]
100071 D - 0xfffffe0057a87500 [acpi_task_1]
100072 D - 0xfffffe0057a87500 [acpi_task_2]
100073 D - 0xfffffe000798f100 [mca taskq]
100075 D - 0xfffffe00570be100 [CAM taskq]
db> show all locks
Process 47599 (syz-executor.1) thread 0xfffffe0074d37ac0 (153192)
exclusive rw vmobject (vmobject) r = 0 (0xfffffe0074c1b318) locked @ /syzkaller/managers/main/kernel/sys/vm/vm_fault.c:361
shared sx vm map (user) (vm map (user)) r = 0 (0xfffffe0058faee98) locked @ /syzkaller/managers/main/kernel/sys/vm/vm_map.c:4930
Process 47599 (syz-executor.1) thread 0xfffffe006d0aa900 (153218)
exclusive sleep mutex sctp-read (inpr) r = 0 (0xfffffe006d1aed98) locked @ /syzkaller/managers/main/kernel/sys/netinet/sctputil.c:6052
exclusive sx so_rcv_sx (so_rcv_sx) r = 0 (0xfffffe0058cc9900) locked @ /syzkaller/managers/main/kernel/sys/kern/uipc_socket.c:4026
Process 6 (pf purge) thread 0xfffffe0057a75000 (100068)
shared sx vnet_sxlock (vnet_sxlock) r = 0 (0xffffffff837d82e0) locked @ /syzkaller/managers/main/kernel/sys/netpfil/pf/pf.c:1856
exclusive sx pf end thread (pf end thread) r = 0 (0xffffffff8440c840) locked @ /syzkaller/managers/main/kernel/sys/netpfil/pf/pf.c:1852
Process 12 (intr) thread 0xfffffe00542ac560 (100031)
exclusive sleep mutex sctp-tcb (tcb) r = 0 (0xfffffe0073ebe8b8) locked @ /syzkaller/managers/main/kernel/sys/netinet/sctp_pcb.c:2138
db> show malloc
Type InUse MemUse Requests
pf_hash 5 11524K 5
tcp_hpts 7 4801K 7
devbuf 4218 4324K 4246
sysctloid 34805 2051K 34876
vtbuf 24 1968K 46
kobj 326 1304K 488
newblk 47 1036K 48074
vfscache 3 1025K 3
pcb 161 820K 164427
inodedep 106 552K 46843
ufs_quota 1 512K 1
vfs_hash 1 512K 1
callout 2 512K 2
intr 4 472K 4
subproc 157 306K 47693
vmem 3 266K 6
filedesc 30 233K 93143
acpica 1674 184K 57877
tidhash 3 141K 3
pagedep 12 131K 46573
tfo_ccache 1 128K 1
IP reass 1 128K 1
linker 324 127K 361
vnet_data 1 112K 1
DEVFS1 109 109K 126
sem 4 106K 4
BPF 47 89K 152
bus 988 81K 5135
mtx_pool 2 72K 2
NFSD srvcache 3 68K 3
syncache 1 68K 1
acpitask 1 64K 1
ddb_capture 1 64K 1
module 508 64K 508
sctp_timw 222 56K 222
sctp_stro 55 55K 17170
temp 36 53K 2886
umtx 418 53K 418
kdtrace 243 48K 100831
sctp_atcl 123 47K 102771
filemon 5 40K 316
DEVFS3 128 32K 138
hostcache 1 32K 1
shm 1 32K 7
msg 4 30K 4
kbdmux 6 28K 6
gtaskqueue 18 26K 18
dirrem 95 24K 46736
ifaddr 71 21K 73
DEVFS_RULE 56 20K 56
CC Mem 71 18K 26385
ufs_mount 4 17K 5
proc 3 17K 3
tty 16 16K 16
routetbl 138 16K 430
ithread 97 16K 97
lltable 46 15K 135
bus-sc 34 15K 1648
eventhandler 157 13K 157
KTRACE 101 13K 10873
ether_multi 157 13K 167
ifnet 7 13K 7
freefile 93 12K 46721
kenv 95 12K 95
rman 88 11K 431
GEOM 61 11K 481
CAM queue 5 11K 1528
in6_multi 71 9K 71
bmsafemap 2 9K 46825
rpc 4 9K 4
UART 12 9K 12
devstat 4 9K 4
ksem 1 8K 1
pfs_vncache 1 8K 1
shmfd 1 8K 24
audit_evclass 237 8K 297
sctp_atky 178 8K 123810
taskqueue 63 7K 63
cred 26 7K 321
kqueue 70 7K 47695
sglist 5 7K 5
CAM DEV 3 6K 510
plimit 24 6K 530
freework 21 6K 46753
pfs_nodes 20 5K 20
ufs_dirhash 24 5K 24
DEVFSP 74 5K 8212
session 35 5K 57
UMA 267 5K 267
pf_ifnet 10 5K 19
pwddesc 68 5K 47604
vt 11 5K 11
memdesc 1 4K 1
MCA 32 4K 32
evdev 4 4K 4
lockf 33 4K 86
proc-args 98 4K 49073
acpisem 28 4K 28
selfd 55 4K 789972
hhook 15 4K 17
kcovinfo 52 4K 52
terminal 11 3K 11
inpcbpolicy 82 3K 27465
select 19 3K 72
clone 9 3K 9
uidinfo 3 3K 16
local_apic 1 2K 1
io_apic 1 2K 1
fpukern_ctx 2 2K 2
freeblks 8 2K 46584
ipsec-saq 2 2K 2
sctp_athm 123 2K 106510
ip6ndp 12 2K 15
sctp_map 110 2K 37166
sctp_ifa 14 2K 15
Unitno 27 2K 49
CAM XPT 22 2K 543
msi 12 2K 12
in_multi 6 2K 8
osd 76 2K 26398
ipsecpolicy 2 2K 2
acpidev 20 2K 20
tun 7 2K 7
NFSD session 1 1K 1
softdep 1 1K 1
mkdir 8 1K 93104
sahead 1 1K 1
secasvar 1 1K 1
nhops 6 1K 8
vnodemarker 2 1K 116
newdirblk 7 1K 46552
CAM periph 4 1K 271
ipsec 3 1K 3
sctp_ifn 6 1K 15
mld 6 1K 6
igmp 6 1K 6
pfil 6 1K 6
toponodes 6 1K 6
isadev 6 1K 6
mount 16 1K 89
pci_link 10 1K 10
crypto 4 1K 4
encap_export_host 12 1K 12
procdesc 5 1K 18
sctp_stri 1 1K 7413
diradd 4 1K 46778
indirdep 2 1K 315
cdev 2 1K 2
chacha20random 1 1K 1
biobuf 1 1K 1
NFSD lckfile 1 1K 1
NFSD V4client 1 1K 1
DEVFS 9 1K 10
vnodes 1 1K 1
CAM SIM 2 1K 2
feeder 7 1K 7
tcpfunc 3 1K 3
loginclass 3 1K 6
prison 6 1K 6
lkpikmalloc 5 1K 6
soname 6 1K 117285
aesni_data 2 1K 2
cryptodev 2 1K 7765
nexusdev 8 1K 8
apmdev 1 1K 1
atkbddev 2 1K 2
netlink 1 1K 1
CAM dev queue 2 1K 2
CAM I/O Scheduler 1 1K 1
aio 4 1K 4
CAM path 4 1K 1034
pmchooks 1 1K 1
filecaps 5 1K 124
sctp_vrf 1 1K 1
vnet 1 1K 1
entropy 2 1K 49
pmc 1 1K 1
acpiintr 1 1K 1
cpus 2 1K 2
vnet_data_free 1 1K 1
Per-cpu 1 1K 1
iov 1 1K 72947
p1003.1b 1 1K 1
tcp_do 0 0K 0
tcp_fsb 0 0K 45010
ipcomp 0 0K 0
esp 0 0K 0
ah 0 0K 0
mqdata 0 0K 0
pf_table 0 0K 0
pf_rule 0 0K 0
pf_altq 0 0K 0
pf_osfp 0 0K 0
pf_krule_item 0 0K 0
pf_temp 0 0K 0
sctp_mcore 0 0K 0
sctp_socko 0 0K 25993
sctp_iter 0 0K 12
sctp_mvrf 0 0K 0
sctp_cpal 0 0K 0
sctp_cmsg 0 0K 0
sctp_stre 0 0K 0
sctp_athi 0 0K 0
sctp_a_it 0 0K 12
sctp_aadr 0 0K 0
md_intel_data 0 0K 0
md_ddf_data 0 0K 0
madt_table 0 0K 2
smartpqi 0 0K 0
raid_data 0 0K 72
geom_flashmap 0 0K 0
ixl 0 0K 0
tmpfs dir 0 0K 0
tmpfs name 0 0K 0
tmpfs mount 0 0K 0
tmpfs extattr 0 0K 0
NFS FHA 0 0K 0
ice-resmgr 0 0K 0
ice-osdep 0 0K 0
ice 0 0K 0
iavf 0 0K 0
axgbe 0 0K 0
newnfsmnt 0 0K 0
newnfsclient_req 0 0K 0
NFSCL layrecall 0 0K 0
NFSCL session 0 0K 0
NFSCL sockreq 0 0K 0
NFSCL devinfo 0 0K 0
NFSCL flayout 0 0K 0
NFSCL layout 0 0K 0
NFSD rollback 0 0K 0
xen_intr 0 0K 0
NFSCL diroff 0 0K 0
NEWdirectio 0 0K 0
xen_hvm 0 0K 0
legacydrv 0 0K 0
bounce 0 0K 0
busdma 0 0K 0
qpidrv 0 0K 0
NEWNFSnode 0 0K 0
NFSCL lck 0 0K 0
dmar_idpgtbl 0 0K 0
dmar_dom 0 0K 0
dmar_ctx 0 0K 0
NFSCL lckown 0 0K 0
NFSCL client 0 0K 0
NFSCL deleg 0 0K 0
isci 0 0K 0
iommu_dmamap 0 0K 0
NFSCL open 0 0K 0
hyperv_socket 0 0K 0
bxe_ilt 0 0K 0
NFSCL owner 0 0K 0
xenbus 0 0K 0
NFS fh 0 0K 0
NFS req 0 0K 0
NFSD usrgroup 0 0K 0
vm_fictitious 0 0K 0
NFSD string 0 0K 0
NFSD V4lock 0 0K 0
NFSD V4state 0 0K 0
msdosfs_fat 0 0K 0
msdosfs_mount 0 0K 0
msdosfs_node 0 0K 0
UMAHash 0 0K 0
DEVFS4 0 0K 0
vm_pgdata 0 0K 0
jblocks 0 0K 0
savedino 0 0K 40419
sentinel 0 0K 0
jfsync 0 0K 0
jtrunc 0 0K 0
sbdep 0 0K 54
jsegdep 0 0K 0
jseg 0 0K 0
jfreefrag 0 0K 0
jfreeblk 0 0K 0
jnewblk 0 0K 0
jmvref 0 0K 0
jremref 0 0K 0
jaddref 0 0K 0
freedep 0 0K 0
freefrag 0 0K 78
allocindir 0 0K 0
allocdirect 0 0K 0
ufs_trim 0 0K 0
mactemp 0 0K 0
audit_trigger 0 0K 0
audit_pipe_presel 0 0K 0
audit_pipeent 0 0K 0
audit_pipe 0 0K 0
audit_evname 0 0K 0
audit_bsm 0 0K 0
audit_gidset 0 0K 0
audit_text 0 0K 0
audit_path 0 0K 0
audit_data 0 0K 0
audit_cred 0 0K 0
DEVFS2 0 0K 0
gntdev 0 0K 0
privcmd_dev 0 0K 0
evtchn_dev 0 0K 0
xenstore 0 0K 0
scsi_pass 0 0K 0
ciss_data 0 0K 0
xnb 0 0K 0
xen_acpi 0 0K 0
xbbd 0 0K 0
xbd 0 0K 0
Balloon 0 0K 0
sysmouse 0 0K 0
vtfont 0 0K 0
ktls_ocf 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5E_TLS_RX 0 0K 0
MLX5EEPROM 0 0K 0
MLX5E_TLS 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EN 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5DUMP 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
simple_attr 0 0K 0
seq_file 0 0K 0
lkpiskb 0 0K 0
radix 0 0K 0
idr 0 0K 0
lkpindev 0 0K 0
lkpimhi 0 0K 0
lkpifw 0 0K 0
lkpi80211 0 0K 0
NLM 0 0K 0
ipsec-spdcache 0 0K 0
ipsec-reg 0 0K 0
ipsec-misc 0 0K 0
ipsecrequest 0 0K 0
ip6opt 0 0K 100
ip6_msource 0 0K 0
ip6_moptions 0 0K 0
in6_mfilter 0 0K 0
frag6 0 0K 0
tcplog 0 0K 0
tcp_hwpace 0 0K 0
BACKLIGHT 0 0K 0
LRO 0 0K 0
ip_msource 0 0K 0
ip_moptions 0 0K 0
in_mfilter 0 0K 0
ipid 0 0K 0
80211scan 0 0K 0
80211ratectl 0 0K 0
80211power 0 0K 0
80211nodeie 0 0K 0
80211node 0 0K 0
80211mesh_gt 0 0K 0
80211mesh_rt 0 0K 0
80211perr 0 0K 0
80211prep 0 0K 0
80211preq 0 0K 0
80211dfs 0 0K 0
80211crypto 0 0K 0
80211vap 0 0K 0
iflib 0 0K 0
vlan 0 0K 0
gif 0 0K 0
ifdescr 0 0K 0
zlib 0 0K 0
fadvise 0 0K 0
VN POLL 0 0K 0
ath_hal 0 0K 0
statfs 0 0K 46919
namei_tracker 0 0K 100
export_host 0 0K 0
cl_savebuf 0 0K 17
athdev 0 0K 0
ata_pci 0 0K 0
ata_dma 0 0K 0
ata_generic 0 0K 0
pvscsi 0 0K 0
scsi_da 0 0K 69
ata_da 0 0K 0
scsi_ch 0 0K 0
scsi_cd 0 0K 0
AHCI driver 0 0K 0
USBdev 0 0K 0
USB 0 0K 0
agp 0 0K 0
nvme_da 0 0K 0
acpipwr 0 0K 0
acpi_perf 0 0K 0
twsbuf 0 0K 0
tcp_log_dev 0 0K 78
lio 0 0K 21560
acl 0 0K 0
midi buffers 0 0K 0
mbuf_tag 0 0K 0
ktls 0 0K 0
mixer 0 0K 0
ac97 0 0K 0
hdacc 0 0K 0
hdac 0 0K 0
hdaa 0 0K 0
acpicmbat 0 0K 0
SIIS driver 0 0K 0
CAM CCB 0 0K 523
PUC 0 0K 0
ppbusdev 0 0K 0
sr_iov 0 0K 0
OCS 0 0K 0
OCS 0 0K 0
nvme 0 0K 0
nvd 0 0K 0
netmap 0 0K 0
mwldev 0 0K 0
MVS driver 0 0K 0
CAM ccb queue 0 0K 0
accf 0 0K 0
pts 0 0K 0
ioctlops 0 0K 354
eventfd 0 0K 150
Witness 0 0K 0
stack 0 0K 0
mrsasbuf 0 0K 0
mpt_user 0 0K 0
mps_user 0 0K 0
MPSSAS 0 0K 0
mps 0 0K 0
sbuf 0 0K 288
mpr_user 0 0K 0
firmware 0 0K 0
compressor 0 0K 0
MPRSAS 0 0K 0
SWAP 0 0K 0
mpr 0 0K 0
mfibuf 0 0K 0
sysctltmp 0 0K 1039
sysctl 0 0K 3
md_sectors 0 0K 0
ekcd 0 0K 0
dumper 0 0K 0
sendfile 0 0K 0
rctl 0 0K 0
md_disk 0 0K 0
malodev 0 0K 0
LED 0 0K 0
ix_sriov 0 0K 0
cache 0 0K 0
aacraidcam 0 0K 0
prison_racct 0 0K 0
Fail Points 0 0K 0
sigio 0 0K 38
filedesc_to_leader 0 0K 0
pwd 0 0K 0
tty console 0 0K 0
ix 0 0K 0
ipsbuf 0 0K 0
aacraid_buf 0 0K 0
aaccam 0 0K 0
boottrace 0 0K 0
aacbuf 0 0K 0
zstd 0 0K 0
XZ_DEC 0 0K 0
nvlist 0 0K 0
SCSI ENC 0 0K 0
SCSI sa 0 0K 0
isofs_node 0 0K 0
isofs_mount 0 0K 0
tr_raid5_data 0 0K 0
tr_raid1e_data 0 0K 0
tr_raid1_data 0 0K 0
tr_raid0_data 0 0K 0
tr_concat_data 0 0K 0
md_sii_data 0 0K 0
md_promise_data 0 0K 0
md_nvidia_data 0 0K 0
md_jmicron_data 0 0K 0
db> show uma
Zone Size Used Free Requests Sleeps Bucket Total Mem XFree
mbuf_jumbo_page 4096 8332 812 1947961 0 254 37453824 0
mbuf 256 23801 25733 19550011 0 254 12680704 0
RADIX NODE 144 19635 380 940624 0 63 2882160 0
tcp_log 416 0 5589 5855633 0 254 2325024 0
mbuf_cluster 2048 1016 0 1016 0 254 2080768 0
BUF TRIE 144 213 11603 2338 0 62 1701504 0
malloc-384 384 4150 20 4152 0 30 1601280 0
malloc-128 128 12433 60 12956 0 126 1599104 0
malloc-4096 4096 326 12 22993 0 2 1384448 0
sctp_chunk 152 3350 5048 1979326 0 254 1276496 0
UMA Slabs 0 112 11204 22 11204 0 126 1257312 0
vmem btag 56 21376 47 21376 0 254 1199688 0
sctp_asoc 2264 55 455 17103 0 254 1154640 0
sctp_ep 1176 67 703 81961 0 254 905520 0
256 Bucket 2048 335 105 82668 0 8 901120 0
malloc-384 384 106 1994 46843 0 30 806400 0
malloc-2048 2048 69 291 82486 0 8 737280 0
socket 960 123 641 110914 0 254 733440 0
VM OBJECT 264 2466 84 923941 0 30 673200 0
FFS inode 1160 529 24 47251 0 8 641480 0
malloc-8192 8192 10 67 321 0 1 630784 0
malloc-256 256 163 2207 41762 0 62 606720 0
malloc-256 256 173 2122 128708 0 62 587520 0
sctp_raddr 736 55 715 17103 0 254 566720 0
pbuf 2624 0 198 0 0 2 519552 0
malloc-65536 65536 0 6 273 0 1 393216 0
lkpimm 168 1 2327 1 0 62 391104 0
lkpicurr 168 2 2326 2 0 62 391104 0
THREAD 1824 174 35 53226 0 8 381216 0
malloc-1024 1024 59 309 17286 0 16 376832 0
malloc-16384 16384 15 6 46570 0 1 344064 0
MAP ENTRY 96 3210 318 2450638 0 126 338688 0
ertt_txseginfo 40 301 8082 1657536 0 254 335320 0
malloc-4096 4096 71 7 48224 0 2 319488 0
VNODE 448 570 96 47294 0 30 298368 0
malloc-128 128 204 2090 141059 0 126 293632 0
malloc-64 64 3808 539 6836 0 254 278208 0
malloc-384 384 147 573 102797 0 30 276480 0
malloc-65536 65536 4 0 4 0 1 262144 0
mbuf_packet 256 220 796 83495 0 254 260096 0
malloc-16 16 14562 688 75051 0 254 244000 0
malloc-32768 32768 2 5 291 0 1 229376 0
DEVCTL 1024 0 220 153 0 0 225280 0
malloc-65536 65536 1 2 457 0 1 196608 0
malloc-65536 65536 2 1 10 0 1 196608 0
malloc-256 256 109 641 48264 0 62 192000 0
malloc-32 32 5305 617 51948 0 254 189504 0
UMA Zones 768 239 0 239 0 16 183552 0
FPU_save_area 832 176 40 59996 0 16 179712 0
malloc-128 128 1126 269 26919 0 126 178560 0
malloc-4096 4096 39 3 57 0 2 172032 0
S VFS Cache 104 1027 494 67780 0 126 158184 0
malloc-2048 2048 8 64 516 0 8 147456 0
malloc-1024 1024 120 24 138 0 16 147456 0
FFS2 dinode 256 529 41 47250 0 62 145920 0
128 Bucket 1024 86 45 8359 0 16 134144 0
malloc-65536 65536 2 0 2 0 1 131072 0
unpcb 256 20 490 1429 0 254 130560 0
malloc-256 256 316 194 194005 0 62 130560 0
PROC 1376 67 21 47603 0 8 121088 0
tcp_inpcb 1304 71 19 26385 0 8 117360 0
ksiginfo 112 79 965 6943 0 126 116928 0
64 Bucket 512 149 51 17097 0 30 102400 0
filedesc0 1072 68 23 47604 0 8 97552 0
UMA Kegs 384 226 7 226 0 30 89472 0
sctp_stream_msg_out 112 62 730 7742 0 254 88704 0
pipe 728 23 98 741 0 16 88088 0
malloc-64 64 583 740 840719 0 254 84672 0
malloc-256 256 272 43 1610 0 62 80640 0
32 Bucket 256 167 148 21822 0 62 80640 0
sctp_readq 152 2 518 3145 0 254 79040 0
malloc-8192 8192 8 1 34 0 1 73728 0
malloc-64 64 260 811 96017 0 254 68544 0
malloc-64 64 525 546 1622 0 254 68544 0
malloc-128 128 289 238 439 0 126 67456 0
malloc-32768 32768 0 2 120 0 1 65536 0
malloc-256 256 98 157 72975 0 62 65280 0
malloc-512 512 14 106 114 0 30 61440 0
g_bio 408 0 150 14641 0 30 61200 0
malloc-8192 8192 7 0 9 0 1 57344 0
udplite_inpcb 424 0 126 168 0 30 53424 0
udp_inpcb 424 6 120 381 0 30 53424 0
malloc-64 64 347 472 27564 0 254 52416 0
malloc-64 64 176 643 25062 0 254 52416 0
Files 80 309 341 216523 0 126 52000 0
tcp_bbr_map 128 5 398 25771 0 126 51584 0
tcp_rack_map 128 0 403 410903 0 126 51584 0
malloc-128 128 112 291 115936 0 126 51584 0
malloc-128 128 217 186 693 0 126 51584 0
malloc-256 256 77 118 7960 0 62 49920 0
ripcb 392 5 121 531 0 30 49392 0
tcp_rack_pcb 1024 0 48 22505 0 16 49152 0
DIRHASH 1024 35 13 35 0 16 49152 0
NAMEI 1024 0 48 270555 0 16 49152 0
malloc-16384 16384 3 0 3 0 1 49152 0
malloc-1024 1024 10 38 1863 0 16 49152 0
malloc-512 512 4 92 7468 0 30 49152 0
VMSPACE 520 46 44 47580 0 16 46800 0
malloc-384 384 89 31 472 0 30 46080 0
pcpu-8 8 4795 837 5651 0 254 45056 0
tcp_bbr_pcb 832 2 52 2172 0 16 44928 0
syncache 168 0 264 4 0 254 44352 0
malloc-32 32 535 851 127335 0 254 44352 0
sctp_laddr 48 150 690 4312 0 254 40320 0
AIO 208 0 190 21572 0 62 39520 0
da_ccb 544 0 70 3787 0 16 38080 0
hostcache 64 2 565 2 0 254 36288 0
malloc-64 64 59 508 15232 0 254 36288 0
malloc-64 64 0 567 1242 0 254 36288 0
16 Bucket 144 93 159 770 0 62 36288 0
malloc-128 128 31 248 14162 0 126 35712 0
malloc-128 128 72 207 26464 0 126 35712 0
routing nhops 256 27 108 35 0 62 34560 0
ttyoutq 256 72 63 160 0 62 34560 0
malloc-384 384 53 37 53 0 30 34560 0
malloc-256 256 44 91 616 0 62 34560 0
TURNSTILE 136 210 42 210 0 62 34272 0
SLEEPQUEUE 88 210 174 210 0 126 33792 0
malloc-32768 32768 1 0 1 0 1 32768 0
malloc-32768 32768 1 0 1 0 1 32768 0
malloc-32768 32768 1 0 1 0 1 32768 0
malloc-16384 16384 2 0 12 0 1 32768 0
malloc-16384 16384 0 2 160 0 1 32768 0
malloc-8192 8192 2 2 110 0 1 32768 0
malloc-4096 4096 4 4 11 0 2 32768 0
malloc-4096 4096 5 3 8 0 2 32768 0
malloc-2048 2048 3 13 15 0 8 32768 0
malloc-2048 2048 4 12 132 0 8 32768 0
malloc-2048 2048 1 15 279 0 8 32768 0
malloc-2048 2048 7 9 7 0 8 32768 0
malloc-2048 2048 3 13 194 0 8 32768 0
malloc-1024 1024 2 30 42 0 16 32768 0
malloc-1024 1024 1 31 18 0 16 32768 0
malloc-1024 1024 16 16 16 0 16 32768 0
malloc-1024 1024 17 15 17 0 16 32768 0
malloc-1024 1024 5 27 5 0 16 32768 0
malloc-512 512 0 64 15 0 30 32768 0
malloc-512 512 2 62 116 0 30 32768 0
malloc-512 512 8 56 8 0 30 32768 0
pcpu-64 64 486 26 486 0 254 32768 0
PWD 40 28 780 46658 0 254 32320 0
KNOTE 160 28 172 385530 0 62 32000 0
ttyinq 160 135 65 300 0 62 32000 0
clpbuf 2624 0 12 128 0 4 31488 0
cpuset 104 7 272 7 0 126 29016 0
tcp_inpcb ports 32 3 879 23893 0 254 28224 0
ertt 72 71 321 26385 0 126 28224 0
4 Bucket 48 6 582 15 0 254 28224 0
8 Bucket 80 101 249 16635 0 126 28000 0
malloc-4096 4096 1 5 46926 0 2 24576 0
PGRP 88 35 241 59 0 126 24288 0
rl_entry 40 95 511 95 0 254 24240 0
rtentry 168 31 113 35 0 62 24192 0
malloc-16 16 441 1059 155159 0 254 24000 0
malloc-384 384 25 35 137 0 30 23040 0
udplite_inpcb ports 32 0 630 6 0 254 20160 0
udp_inpcb ports 32 3 627 39 0 254 20160 0
malloc-32 32 121 509 35083 0 254 20160 0
malloc-32 32 184 446 1788 0 254 20160 0
malloc-32 32 33 597 1863 0 254 20160 0
malloc-32 32 6 624 5194 0 254 20160 0
malloc-32 32 32 598 2807 0 254 20160 0
2 Bucket 32 102 528 5837 0 254 20160 0
AIOCB 552 0 35 75273 0 16 19320 0
AIOLIO 272 0 70 21560 0 30 19040 0
epoch_record pcpu 256 4 60 4 0 62 16384 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-8192 8192 2 0 2 0 1 16384 0
malloc-8192 8192 2 0 2 0 1 16384 0
malloc-4096 4096 1 3 2 0 2 16384 0
malloc-2048 2048 5 3 7 0 8 16384 0
malloc-512 512 2 30 120 0 30 16384 0
malloc-512 512 0 32 1 0 30 16384 0
SMR CPU 32 7 504 7 0 254 16352 0
vtnet_tx_hdr 24 0 668 927515 0 254 16032 0
kenv 258 15 45 1050 0 30 15480 0
mqnode 416 3 33 3 0 30 14976 0
vmem 1856 1 7 1 0 8 14848 0
SMR SHARED 24 7 504 7 0 254 12264 0
malloc-32 32 13 365 56 0 254 12096 0
malloc-16 16 16 734 125 0 254 12000 0
malloc-16 16 41 709 108927 0 254 12000 0
malloc-16 16 54 696 260 0 254 12000 0
malloc-16 16 188 562 17960 0 254 12000 0
malloc-16 16 8 742 4828 0 254 12000 0
malloc-16 16 32 718 26379 0 254 12000 0
malloc-384 384 1 29 1 0 30 11520 0
malloc-384 384 1 29 1 0 30 11520 0
Mountpoints 2816 2 2 2 0 4 11264 0
malloc-8192 8192 1 0 1 0 1 8192 0
pcpu-16 16 4 252 4 0 254 4096 0
UMA Slabs 1 176 10 12 10 0 62 3872 0
KMAP ENTRY 96 12 27 14 0 0 3744 0
FFS1 dinode 128 0 0 0 0 126 0 0
ada_ccb 272 0 0 0 0 30 0 0
swblk 136 0 0 0 0 62 0 0
swpctrie 144 0 0 0 0 62 0 0
pf state scrubs 40 0 0 0 0 254 0 0
pf frag entries 40 0 0 0 0 254 0 0
pf frags 248 0 0 0 0 62 0 0
pf table entries 160 0 0 0 0 254 0 0
pf table entry counters 64 0 0 0 0 254 0 0
pf source nodes 152 0 0 0 0 254 0 0
pf state keys 88 0 0 0 0 126 0 0
pf states 344 0 0 0 0 254 0 0
pf tags 104 0 0 0 0 126 0 0
pf mtags 184 0 0 0 0 62 0 0
tfo_ccache_entries 80 0 0 0 0 126 0 0
tfo 4 0 0 0 0 254 0 0
sackhole 32 0 0 0 0 254 0 0
ipq 56 0 0 0 0 254 0 0
tcp_log_id_node 120 0 0 0 0 126 0 0
tcp_log_id_bucket 176 0 0 0 0 62 0 0
tcpreass 48 0 0 0 0 254 0 0
sctp_asconf_ack 48 0 0 0 0 254 0 0
sctp_asconf 40 0 0 0 0 254 0 0
ripcb ports 32 0 0 0 0 254 0 0
IPsec SA lft_c 16 0 0 0 0 254 0 0
netlink 2048 0 0 0 0 8 0 0
itimer 352 0 0 0 0 30 0 0
NCLNODE 608 0 0 0 0 16 0 0
mqnotifier 216 0 0 0 0 62 0 0
mvdata 64 0 0 0 0 254 0 0
mqueue 248 0 0 0 0 62 0 0
TMPFS node 232 0 0 0 0 62 0 0
LTS VFS Cache 360 0 0 0 0 30 0

---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the bug is already fixed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to change bug's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the bug is a duplicate of another bug, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Sep 20, 2023, 10:59:27 PM9/20/23
to syzkaller-f...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages