panic: tcp_output: mbuf chain shorter than expected: 0 + 60 + 24 - 0 != 60

6 views
Skip to first unread message

syzbot

unread,
Mar 17, 2019, 4:22:05 AM3/17/19
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 310a121b `make buildkernel' should display the build time ..
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=125ffbe7200000
dashboard link: https://syzkaller.appspot.com/bug?extid=adb5836b8a9ff621b2aa

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+adb583...@syzkaller.appspotmail.com

panic: tcp_output: mbuf chain shorter than expected: 0 + 60 + 24 - 0 != 60
cpuid = 0
time = 32794
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe0016ad95c0
vpanic() at vpanic+0x1e0/frame 0xfffffe0016ad9620
panic() at panic+0x43/frame 0xfffffe0016ad9680
tcp_output() at tcp_output+0x3fe2/frame 0xfffffe0016ad9850
tcp_timer_rexmt() at tcp_timer_rexmt+0x87d/frame 0xfffffe0016ad98e0
softclock_call_cc() at softclock_call_cc+0x1dd/frame 0xfffffe0016ad99b0
softclock() at softclock+0xa3/frame 0xfffffe0016ad99f0
ithread_loop() at ithread_loop+0x2f2/frame 0xfffffe0016ad9a60
fork_exit() at fork_exit+0xb0/frame 0xfffffe0016ad9ab0
fork_trampoline() at fork_trampoline+0xe/frame 0xfffffe0016ad9ab0
--- trap 0, rip = 0, rsp = 0, rbp = 0 ---
KDB: enter: panic
[ thread pid 12 tid 100018 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#bug-status-tracking for how to communicate with
syzbot.

syzbot

unread,
Mar 17, 2019, 5:04:05 AM3/17/19
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 310a121b `make buildkernel' should display the build time ..
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=13cc36d7200000
dashboard link: https://syzkaller.appspot.com/bug?extid=adb5836b8a9ff621b2aa
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1038d39d200000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=136b3293200000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+adb583...@syzkaller.appspotmail.com

panic: tcp_output: mbuf chain shorter than expected: 0 + 60 + 24 - 0 != 60
cpuid = 0
time = 1552813207
Reply all
Reply to author
Forward
0 new messages