panic: Counter goes negative

5 views
Skip to first unread message

syzbot

unread,
Mar 18, 2019, 6:55:06 PM3/18/19
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: b24a98cb Revert r345244 for now.
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=119a683b200000
dashboard link: https://syzkaller.appspot.com/bug?extid=6b8a4bc8cc828e9d9790

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+6b8a4b...@syzkaller.appspotmail.com

panic: Counter goes negative
cpuid = 0
time = 1552949666
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe001f5fc430
vpanic() at vpanic+0x1e0/frame 0xfffffe001f5fc490
panic() at panic+0x43/frame 0xfffffe001f5fc4f0
sctp_sorecvmsg() at sctp_sorecvmsg+0x30cf/frame 0xfffffe001f5fc640
sctp_soreceive() at sctp_soreceive+0x243/frame 0xfffffe001f5fc850
soreceive() at soreceive+0xb9/frame 0xfffffe001f5fc8b0
dofileread() at dofileread+0xd3/frame 0xfffffe001f5fc910
kern_readv() at kern_readv+0x66/frame 0xfffffe001f5fc950
sys_readv() at sys_readv+0x50/frame 0xfffffe001f5fc980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe001f5fcab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe001f5fcab0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x412e5a, rsp =
0x7fffdffdcf38, rbp = 0x3 ---
KDB: enter: panic
[ thread pid 2183 tid 100523 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#bug-status-tracking for how to communicate with
syzbot.

syzbot

unread,
Mar 18, 2019, 7:17:06 PM3/18/19
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: b24a98cb Revert r345244 for now.
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=1683acb3200000
dashboard link: https://syzkaller.appspot.com/bug?extid=6b8a4bc8cc828e9d9790
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=13d728df200000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1531846d200000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+6b8a4b...@syzkaller.appspotmail.com

login: panic: Counter goes negative
cpuid = 1
time = 1552950821
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe001fa36430
vpanic() at vpanic+0x1e0/frame 0xfffffe001fa36490
panic() at panic+0x43/frame 0xfffffe001fa364f0
sctp_sorecvmsg() at sctp_sorecvmsg+0x30cf/frame 0xfffffe001fa36640
sctp_soreceive() at sctp_soreceive+0x243/frame 0xfffffe001fa36850
soreceive() at soreceive+0xb9/frame 0xfffffe001fa368b0
dofileread() at dofileread+0xd3/frame 0xfffffe001fa36910
kern_readv() at kern_readv+0x66/frame 0xfffffe001fa36950
sys_readv() at sys_readv+0x50/frame 0xfffffe001fa36980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe001fa36ab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe001fa36ab0
--- syscall (0, FreeBSD ELF64, nosys), rip = 0x4575ba, rsp =
0x7fffdffdcf88, rbp = 0x6b5b00 ---
KDB: enter: panic
[ thread pid 759 tid 100104 ]
Reply all
Reply to author
Forward
0 new messages