Fatal trap 12: page fault in pmap_remove_pte

8 views
Skip to first unread message

syzbot

unread,
May 22, 2019, 9:42:05 AM5/22/19
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: e2abb7b2 Protect commands that are considered dangerous wi..
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=171f2c18a00000
dashboard link: https://syzkaller.appspot.com/bug?extid=d0ed948e4ec6c701bcd3

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+d0ed94...@syzkaller.appspotmail.com

Fatal trap 12: page fault while in kernel mode
cpuid = 1; apic id = 01
fault virtual address = 0x0
fault code = supervisor read data, page not present
instruction pointer = 0x20:0xffffffff816be59b
stack pointer = 0x0:0xfffffe0016bfc810
frame pointer = 0x0:0xfffffe0016bfc870
code segment = base 0x0, limit 0xfffff, type 0x1b
= DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags = interrupt enabled, resume, IOPL = 0
current process = 18 (vmdaemon)
trap number = 12
panic: page fault
cpuid = 1
time = 126
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe0016bfc470
vpanic() at vpanic+0x1e0/frame 0xfffffe0016bfc4d0
panic() at panic+0x43/frame 0xfffffe0016bfc530
trap_fatal() at trap_fatal+0x4c6/frame 0xfffffe0016bfc5b0
trap_pfault() at trap_pfault+0x9f/frame 0xfffffe0016bfc620
trap() at trap+0x44d/frame 0xfffffe0016bfc740
calltrap() at calltrap+0x8/frame 0xfffffe0016bfc740
--- trap 0xc, rip = 0xffffffff816be59b, rsp = 0xfffffe0016bfc810, rbp =
0xfffffe0016bfc870 ---
pmap_remove_pte() at pmap_remove_pte+0x32b/frame 0xfffffe0016bfc870
pmap_remove_ptes() at pmap_remove_ptes+0x1b5/frame 0xfffffe0016bfc8f0
pmap_remove() at pmap_remove+0x4a5/frame 0xfffffe0016bfc980
vm_swapout_map_deactivate_pages() at
vm_swapout_map_deactivate_pages+0x310/frame 0xfffffe0016bfc9e0
vm_daemon() at vm_daemon+0xbe0/frame 0xfffffe0016bfca60
fork_exit() at fork_exit+0xb0/frame 0xfffffe0016bfcab0
fork_trampoline() at fork_trampoline+0xe/frame 0xfffffe0016bfcab0
--- trap 0, rip = 0, rsp = 0, rbp = 0 ---
KDB: enter: panic
[ thread pid 18 tid 100062 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Oct 25, 2019, 4:36:07 AM10/25/19
to syzkaller-f...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages