panic: mtx_lock_spin: recursed on non-recursive mutex msgbuf @ /syzkaller/managers/i386/kernel/sys/kern/subr_msgbuf.c:LI

0 views
Skip to first unread message

syzbot

unread,
Dec 29, 2023, 7:17:22 AM12/29/23
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 9035bfffede5 indent: make the URL of the manpage two chara..
git tree: freebsd-src
console output: https://syzkaller.appspot.com/x/log.txt?x=111b7e81e80000
dashboard link: https://syzkaller.appspot.com/bug?extid=a0a42945ec9d69f1d108
userspace arch: i386

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+a0a429...@syzkaller.appspotmail.com

panic: mtx_lock_spin: recursed on non-recursive mutex msgbuf @ /syzkaller/managers/i386/kernel/sys/kern/subr_msgbuf.c:198

cpuid = 0
time = 865
KDB: stack backtrace:
SeaBIOS (version 1.8.2-google)
Total RAM Size = 0x0000000080000000 = 2048 MiB
CPUs found: 2 Max CPUs supported: 2
SeaBIOS (version 1.8.2-google)
Machine UUID 289f06aa-698b-3fcd-555f-6939f7158709
found virtio-scsi at 0:3
virtio-scsi vendor='Google' product='PersistentDisk' rev='1' type=0 removable=0
virtio-scsi blksize=512 sectors=6291456 = 3072 MiB
drive 0x000f28a0: PCHS=0/0/0 translation=lba LCHS=780/128/63 s=6291456
Sending Seabios boot VM event.
Booting from Hard Disk 0...
Loading /boot/loader.conf.local
- \ | / - \ | / - \ | / - \ | / - \ | / - [0;37;40m\ | / - \ | / - \ | / - \ | / - \ | / - \ | / Loading kernel...
- \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / /boot/kernel/kernel text=0x179758 - \ | / - \ | / - \ | / - text=0x1eef887 \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / text=0x8fea94 - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / data=0x71a0 data=0x878a70+0x57f590 - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - syms=[0x8+0x39bd48\ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ +0x8+0x1cee0a| / - \ | / - \ | / - \ | / ]
Loading configured modules...
- \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / /boot/kernel/cc_htcp.ko - size 0x7960 at 0x3f6b000
\ | / - \ | / - \ | / - \ | / - \ | / - \ /boot/kernel/pf.ko | / - \ | / - \ | / - \ | / - \ | / size 0x218350 at 0x3f73000
- \ | / - \ | / - \ | / - \ | /boot/kernel/sem.ko / size 0x10bc0 at 0x418c000
- \ | / - \ | / - \ | / - \ | /boot/kernel/ipsec.ko / - \ | / size 0x7eac0 at 0x419d000
- \ | / - \ | / - \ | / - \ | / - \ | / - /boot/kernel/filemon.ko \ size 0xd920 at 0x421c000
| / - \ | / - \ | / - \ | / - \ | / - \ | /boot/kernel/cc_dctcp.ko / size 0x87a8 at 0x422a000
- \ | / - \ | / - \ | / - \ | /boot/kernel/cc_hd.ko size 0x60b0 at 0x4233000
/ - \ | / - \ | / - \ | / - \ | / - \ /boot/kernel/cc_vegas.ko size 0x62d8 at 0x423a000
| / - \ | / - \ | / - \ | / - /boot/kernel/cryptodev.ko \ size 0x15910 at 0x4241000
| / - \ | / - \ | / - \ | / - \ | / - /boot/kernel/cc_cubic.ko size 0x9788 at 0x4257000
\ | / - \ | / - \ | / - \ | / - \ | / /boot/kernel/cc_chd.ko size 0x8f30 at 0x4261000
- \ | / - \ | / - \ | / - \ | / - \ | /boot/kernel/tcp_bbr.ko / - \ | / - \ | size 0xd5638 at 0x426a000
/ - \ | / - \ | / - \ | / - \ /boot/kernel/cc_cdg.ko | size 0xdb98 at 0x4340000
/ - \ | / - \ | / - \ | / - \ /boot/kernel/mqueuefs.ko | size 0x268c8 at 0x434e000
/ - \ | / - \ | / - \ | / - \ | / - \ /boot/kernel/tcp_rack.ko | / - \ | / - \ | / size 0x12e190 at 0x4375000
- \ | / - \ | / - \ | / - \ | / - \ | /boot/kernel/sctp.ko / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | size 0x2e2038 at 0x44a4000
/ - \ | / - \ | / - /boot/entropy size=0x1000
\ | / - GDB: no debug ports present
KDB: debugger backends: ddb
KDB: current backend: ddb
---<<BOOT>>---
Copyright (c) 1992-2023 The FreeBSD Project.
Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
The Regents of the University of California. All rights reserved.
FreeBSD is a registered trademark of The FreeBSD Foundation.
FreeBSD 15.0-CURRENT #0 n267308-9035bfffede5: Fri Dec 29 11:43:27 UTC 2023
root@freebsd:/syzkaller/managers/i386/kernel/obj/syzkaller/managers/i386/kernel/amd64.amd64/sys/SYZKALLER amd64
FreeBSD clang version 17.0.6 (https://github.com/llvm/llvm-project.git llvmorg-17.0.6-0-g6009708b4367)
WARNING: WITNESS option enabled, expect reduced performance.
WARNING: DIAGNOSTIC option enabled, expect reduced performance.
VT(vga): text 80x25
module cubic already present!
CPU: Intel(R) Xeon(R) CPU @ 2.20GHz (2199.88-MHz K8-class CPU)
Origin="GenuineIntel" Id=0x406f0 Family=0x6 Model=0x4f Stepping=0
Features=0x1f83fbff<FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,MMX,FXSR,SSE,SSE2,SS,HTT>
Features2=0xfefa3223<SSE3,PCLMULQDQ,VMX,SSSE3,FMA,CX16,PCID,SSE4.1,SSE4.2,x2APIC,MOVBE,POPCNT,AESNI,XSAVE,OSXSAVE,AVX,F16C,RDRAND,HV>
AMD Features=0x2c100800<SYSCALL,NX,Page1GB,RDTSCP,LM>
AMD Features2=0x121<LAHF,ABM,Prefetch>
Structured Extended Features=0x1c2ffb<FSGSBASE,TSCADJ,BMI1,HLE,AVX2,FDPEXC,SMEP,BMI2,ERMS,INVPCID,RTM,NFPUSG,RDSEED,ADX,SMAP>
Structured Extended Features3=0xac000400<MD_CLEAR,IBPB,STIBP,ARCH_CAP,SSBD>
XSAVE Features=0x1<XSAVEOPT>
IA32_ARCH_CAPS=0x400004c<RSBA,SKIP_L1DFL_VME>
VT-x: PAT,HLT,MTF,PAUSE,EPT,UG,VPID,VID
TSC: P-state invariant
Hypervisor: Origin = "KVMKVMKVM"
real memory = 2147483648 (2048 MB)
avail memory = 1799442432 (1716 MB)
Event timer "LAPIC" quality 600
ACPI APIC Table: <Google GOOGAPIC>
FreeBSD/SMP: Multiprocessor System Detected: 2 CPUs
FreeBSD/SMP: 1 package(s) x 1 core(s) x 2 hardware threads
random: registering fast source Intel Secure Key RNG
random: fast provider: "Intel Secure Key RNG"
random: unblocking device.
ioapic0 <Version 1.1> irqs 0-23
Launching APs: 1
TCP_ratelimit: Is now initialized
TCP Hpts created 2 swi interrupt threads and bound 0 to cpus
random: entropy device external interface
kbd1 at kbdmux0
vtvga0: <VT VGA driver>
kvmclock0: <KVM paravirtual clock>
Timecounter "kvmclock" frequency 1000000000 Hz quality 975
kvmclock0: registered as a time-of-day clock, resolution 0.000001s
smbios0: <System Management BIOS> at iomem 0xf2910-0xf292e
smbios0: Version: 2.4, BCD Revision: 2.4
aesni0: <AES-CBC,AES-CCM,AES-GCM,AES-ICM,AES-XTS>
acpi0: <Google GOOGRSDT>
acpi0: Power Button (fixed)
acpi0: Sleep Button (fixed)
cpu0: <ACPI CPU> on acpi0
atrtc0: <AT realtime clock> port 0x70-0x71,0x72-0x77 irq 8 on acpi0
atrtc0: registered as a time-of-day clock, resolution 1.000000s
Event timer "RTC" frequency 32768 Hz quality 0
Timecounter "ACPI-fast" frequency 3579545 Hz quality 900
acpi_timer0: <24-bit timer at 3.579545MHz> port 0xb008-0xb00b on acpi0
pcib0: <ACPI Host-PCI bridge> port 0xcf8-0xcff on acpi0
pci0: <ACPI PCI bus> on pcib0
isab0: <PCI-ISA bridge> at device 1.0 on pci0
isa0: <ISA bus> on isab0
pci0: <bridge> at device 1.3 (no driver attached)
virtio_pci0: <VirtIO PCI (legacy) SCSI adapter> port 0xc000-0xc03f mem 0xfe800000-0xfe80007f irq 11 at device 3.0 on pci0
vtscsi0: <VirtIO SCSI Adapter> on virtio_pci0
virtio_pci1: <VirtIO PCI (legacy) Network adapter> port 0xc040-0xc07f mem 0xfe801000-0xfe80107f irq 11 at device 4.0 on pci0
vtnet0: <VirtIO Networking Adapter> on virtio_pci1
vtnet0: Ethernet address: 42:01:0a:80:0a:19
vtnet0: netmap queues/slots: TX 2/2048, RX 2/2048
000.000127 [ 452] vtnet_netmap_attach vtnet attached txq=2, txd=2048 rxq=2, rxd=2048
vgapci0: <VGA-compatible display> mem 0xfe000000-0xfe7fffff irq 10 at device 5.0 on pci0
vgapci0: Boot video device
virtio_pci2: <VirtIO PCI (legacy) Balloon adapter> port 0xc080-0xc09f mem 0xfe802000-0xfe80207f irq 10 at device 6.0 on pci0
vtballoon0: <VirtIO Balloon Adapter> on virtio_pci2
virtio_pci3: <VirtIO PCI (legacy) Entropy adapter> port 0xc0a0-0xc0bf mem 0xfe803000-0xfe80303f irq 11 at device 7.0 on pci0
atkbdc0: <Keyboard controller (i8042)> port 0x60,0x64 irq 1 on acpi0
atkbd0: <AT Keyboard> irq 1 on atkbdc0
kbd0 at atkbd0
atkbd0: [GIANT-LOCKED]
psm0: <PS/2 Mouse> irq 12 on atkbdc0
psm0: [GIANT-LOCKED]
WARNING: Device "psm" is Giant locked and may be deleted before FreeBSD 15.0.
psm0: model IntelliMouse Explorer, device ID 4
uart0: <16550 or compatible> port 0x3f8-0x3ff irq 4 flags 0x10 on acpi0
uart0: console (9600,n,8,1)
uart1: <16550 or compatible> port 0x2f8-0x2ff irq 3 on acpi0
uart2: <16550 or compatible> port 0x3e8-0x3ef irq 6 on acpi0
uart3: <16550 or compatible> port 0x2e8-0x2ef irq 7 on acpi0
orm0: <ISA Option ROM> at iomem 0xeb800-0xeffff pnpid ORM0000 on isa0
vga0: <Generic ISA VGA> at port 0x3c0-0x3df iomem 0xa0000-0xbffff pnpid PNP0900 on isa0
attimer0: <AT timer> at port 0x40 on isa0
Timecounter "i8254" frequency 1193182 Hz quality 0
attimer0: Can't map interrupt.
NULL mp in getnewvnode(9), tag crossmp
Timecounter "TSC-low" frequency 1099994334 Hz quality 1000
Timecounters tick every 10.000 msec
Attempting to load tcp_bbr
tcp_bbr is now available
usb_needs_explore_all: no devclass
Trying to mount root from ufs:/dev/gpt/rootfs [rw]...
WARNING: WITNESS option enabled, expect reduced performance.
WARNING: DIAGNOSTIC option enabled, expect reduced performance.
da0 at vtscsi0 bus 0 scbus0 target 1 lun 0
da0: <Google PersistentDisk 1> Fixed Direct Access SPC-4 SCSI device
da0: 300.000MB/s transfers
da0: Command Queueing enabled
da0: 3072MB (6291456 512 byte sectors)
GEOM: da0: the secondary GPT header is not in the last LBA.
WARNING: / was not properly dismounted
WARNING: /: mount pending error: blocks 10624 files 130
Setting hostuuid: c5737494-45a4-11e9-9216-00a0980e0293.
Setting hostid: 0xdcc40b08.
No suitable dump device was found.
Starting file system checks:
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=500 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=504 (2112 should be 1216) (CORRECTED)
/dev/gpt/rootfs: INODE 504: FILE SIZE 1048576 BEYOND END OF ALLOCATED FILE, SIZE SHOULD BE 589824 (ADJUSTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=509 (2112 should be 960) (CORRECTED)
/dev/gpt/rootfs: INODE 509: FILE SIZE 1048576 BEYOND END OF ALLOCATED FILE, SIZE SHOULD BE 458752 (ADJUSTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=510 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=629 (2112 should be 1856) (CORRECTED)
/dev/gpt/rootfs: INODE 629: FILE SIZE 1048576 BEYOND END OF ALLOCATED FILE, SIZE SHOULD BE 917504 (ADJUSTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=634 (2112 should be 1536) (CORRECTED)
/dev/gpt/rootfs: INODE 634: FILE SIZE 1048576 BEYOND END OF ALLOCATED FILE, SIZE SHOULD BE 753664 (ADJUSTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=636 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=637 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=647 (2112 should be 128) (CORRECTED)
/dev/gpt/rootfs: INODE 647: FILE SIZE 1048576 BEYOND END OF ALLOCATED FILE, SIZE SHOULD BE 65536 (ADJUSTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=652 (2112 should be 1152) (CORRECTED)
/dev/gpt/rootfs: INODE 652: FILE SIZE 1048576 BEYOND END OF ALLOCATED FILE, SIZE SHOULD BE 557056 (ADJUSTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=654 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=655 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=656 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=676 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=687 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=703 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=708 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=711 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=719 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=725 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=755 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=799 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=864 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=879 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=884 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=887 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=889 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=890 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=892 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=895 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=896 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=897 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=898 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=899 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=901 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=902 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=903 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=904 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=905 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=907 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=908 (2112 should be 1472) (CORRECTED)
/dev/gpt/rootfs: INODE 908: FILE SIZE 1048576 BEYOND END OF ALLOCATED FILE, SIZE SHOULD BE 720896 (ADJUSTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=911 (2112 should be 1280) (CORRECTED)
/dev/gpt/rootfs: INODE 911: FILE SIZE 1048576 BEYOND END OF ALLOCATED FILE, SIZE SHOULD BE 622592 (ADJUSTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=912 (2112 should be 1344) (CORRECTED)
/dev/gpt/rootfs: INODE 912: FILE SIZE 1048576 BEYOND END OF ALLOCATED FILE, SIZE SHOULD BE 655360 (ADJUSTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=913 (8 should be 0) (CORRECTED)
/dev/gpt/rootfs: INCORRECT BLOCK COUNT I=915 (8 should be 0) (CORRECTED)


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Apr 23, 2024, 3:59:14 PM (9 days ago) Apr 23
to syzkaller-f...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages