panic: mtx_lock() of spin mutex (null) @ /syzkaller/managers/main/kernel/sys/netinet/sctputil.c:LINE

4 views
Skip to first unread message

syzbot

unread,
Mar 22, 2019, 1:33:05 AM3/22/19
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 434f0087 Catch up with Clang 8.0.
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=14a65bcf200000
dashboard link: https://syzkaller.appspot.com/bug?extid=a35c7ed9057deac6a5a2

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+a35c7e...@syzkaller.appspotmail.com

panic: mtx_lock() of spin mutex (null) @
/syzkaller/managers/main/kernel/sys/netinet/sctputil.c:4531
cpuid = 0
time = 466
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe00212ea570
vpanic() at vpanic+0x1e0/frame 0xfffffe00212ea5d0
panic() at panic+0x43/frame 0xfffffe00212ea630
__mtx_lock_flags() at __mtx_lock_flags+0x1fd/frame 0xfffffe00212ea690
sctp_add_to_readq() at sctp_add_to_readq+0x620/frame 0xfffffe00212ea710
sctp_ulp_notify() at sctp_ulp_notify+0xe75/frame 0xfffffe00212ea780
sctp_setopt() at sctp_setopt+0x99d0/frame 0xfffffe00212ea810
sctp_ctloutput() at sctp_ctloutput+0x214/frame 0xfffffe00212ea850
sosetopt() at sosetopt+0x101/frame 0xfffffe00212ea8d0
kern_setsockopt() at kern_setsockopt+0x158/frame 0xfffffe00212ea950
sys_setsockopt() at sys_setsockopt+0x33/frame 0xfffffe00212ea980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe00212eaab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe00212eaab0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x412e7a, rsp =
0x7fffdffbbf38, rbp = 0x5 ---
KDB: enter: panic
[ thread pid 5030 tid 100925 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Mar 22, 2019, 1:53:05 AM3/22/19
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 434f0087 Catch up with Clang 8.0.
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=10da9adf200000
dashboard link: https://syzkaller.appspot.com/bug?extid=a35c7ed9057deac6a5a2
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=14a08a3b200000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+a35c7e...@syzkaller.appspotmail.com

panic: mtx_lock() of spin mutex (null) @
/syzkaller/managers/main/kernel/sys/netinet/sctputil.c:4531
cpuid = 0
time = 1553233440
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe00212c2570
vpanic() at vpanic+0x1e0/frame 0xfffffe00212c25d0
panic() at panic+0x43/frame 0xfffffe00212c2630
__mtx_lock_flags() at __mtx_lock_flags+0x1fd/frame 0xfffffe00212c2690
sctp_add_to_readq() at sctp_add_to_readq+0x620/frame 0xfffffe00212c2710
sctp_ulp_notify() at sctp_ulp_notify+0xe75/frame 0xfffffe00212c2780
sctp_setopt() at sctp_setopt+0x99d0/frame 0xfffffe00212c2810
sctp_ctloutput() at sctp_ctloutput+0x214/frame 0xfffffe00212c2850
sosetopt() at sosetopt+0x101/frame 0xfffffe00212c28d0
kern_setsockopt() at kern_setsockopt+0x158/frame 0xfffffe00212c2950
sys_setsockopt() at sys_setsockopt+0x33/frame 0xfffffe00212c2980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe00212c2ab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe00212c2ab0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x412e7a, rsp =
0x7fffdffbbf38, rbp = 0x5 ---
KDB: enter: panic
[ thread pid 873 tid 100240 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why
db>

syzbot

unread,
May 5, 2019, 9:33:06 AM5/5/19
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 0d62ce24 Colemak Mod DH keyboard layout
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=15fad658a00000
dashboard link: https://syzkaller.appspot.com/bug?extid=a35c7ed9057deac6a5a2
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=17dfc3e0a00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=14d36b84a00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+a35c7e...@syzkaller.appspotmail.com

login: panic: mtx_lock() of spin mutex (null) @
/syzkaller/managers/main/kernel/sys/netinet/sctputil.c:4531
cpuid = 1
time = 1557062921
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe0021263570
vpanic() at vpanic+0x1e0/frame 0xfffffe00212635d0
panic() at panic+0x43/frame 0xfffffe0021263630
__mtx_lock_flags() at __mtx_lock_flags+0x1fd/frame 0xfffffe0021263690
sctp_add_to_readq() at sctp_add_to_readq+0x620/frame 0xfffffe0021263710
sctp_ulp_notify() at sctp_ulp_notify+0xe75/frame 0xfffffe0021263780
sctp_setopt() at sctp_setopt+0x99d0/frame 0xfffffe0021263810
sctp_ctloutput() at sctp_ctloutput+0x214/frame 0xfffffe0021263850
sosetopt() at sosetopt+0x101/frame 0xfffffe00212638d0
kern_setsockopt() at kern_setsockopt+0x158/frame 0xfffffe0021263950
sys_setsockopt() at sys_setsockopt+0x33/frame 0xfffffe0021263980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe0021263ab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe0021263ab0
--- syscall (0, FreeBSD ELF64, nosys), rip = 0x457c0a, rsp =
0x7fffdfffdf78, rbp = 0x6b6308 ---
KDB: enter: panic
[ thread pid 965 tid 100352 ]

Mark Johnston

unread,
Sep 7, 2021, 5:29:15 PM9/7/21
to syzbot, syzkaller-f...@googlegroups.com
#syz dup: panic: mtx_lock() of spin mutex (null) @ /syzkaller/managers/main/kernel/sys/netinet/tcp_output.c:LINE
Reply all
Reply to author
Forward
0 new messages