panic: sx_xlock() of destroyed sx at sys/kern/uipc_sockbuf.c:LINE

12 views
Skip to first unread message

syzbot

unread,
Mar 15, 2019, 5:00:06 PM3/15/19
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 84b9791b bridge: Fix panic if the STP root is removed
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=1714639d200000
dashboard link: https://syzkaller.appspot.com/bug?extid=b32b4833408b77f3798c
userspace arch: amd64

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+b32b48...@syzkaller.appspotmail.com

panic: sx_xlock() of destroyed sx @
/syzkaller/managers/main/kernel/sys/kern/uipc_sockbuf.c:285
cpuid = 0
time = 2
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe00212d65c0
vpanic() at vpanic+0x1e0/frame 0xfffffe00212d6620
panic() at panic+0x43/frame 0xfffffe00212d6680
_sx_xlock() at _sx_xlock+0x1c9/frame 0xfffffe00212d66d0
sosend_generic() at sosend_generic+0x1a0/frame 0xfffffe00212d67a0
sosend() at sosend+0xc6/frame 0xfffffe00212d6810
kern_sendit() at kern_sendit+0x35e/frame 0xfffffe00212d68c0
sendit() at sendit+0x226/frame 0xfffffe00212d6920
sys_sendto() at sys_sendto+0x5c/frame 0xfffffe00212d6980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe00212d6ab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe00212d6ab0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x412e5a, rsp =
0x7fffdffbbf38, rbp = 0x6 ---
KDB: enter: panic
[ thread pid 49547 tid 100116 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#bug-status-tracking for how to communicate with
syzbot.

syzbot

unread,
Mar 16, 2019, 10:19:05 PM3/16/19
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 4ccae816 Add openmp __kmp_gettid() wrapper, using pthread_..
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=15aa35fb200000
dashboard link: https://syzkaller.appspot.com/bug?extid=b32b4833408b77f3798c
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1497aed7200000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+b32b48...@syzkaller.appspotmail.com

panic: sx_xlock() of destroyed sx @
/syzkaller/managers/main/kernel/sys/kern/uipc_sockbuf.c:282
cpuid = 0
time = 1552788887
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe001fa5e4f0
vpanic() at vpanic+0x1e0/frame 0xfffffe001fa5e550
panic() at panic+0x43/frame 0xfffffe001fa5e5b0
_sx_xlock() at _sx_xlock+0x1c9/frame 0xfffffe001fa5e600
sblock() at sblock+0xeb/frame 0xfffffe001fa5e630
vn_sendfile() at vn_sendfile+0x650/frame 0xfffffe001fa5e8e0
sendfile() at sendfile+0x155/frame 0xfffffe001fa5e980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe001fa5eab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe001fa5eab0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x412e5a, rsp =
0x7fffdffdcf38, rbp = 0x4 ---
KDB: enter: panic
[ thread pid 796 tid 100122 ]

Mark Johnston

unread,
Sep 7, 2021, 5:27:32 PM9/7/21
to syzbot, syzkaller-f...@googlegroups.com
#syz dup: panic: mtx_lock() of spin mutex (null) @ /syzkaller/managers/main/kernel/sys/netinet/tcp_output.c:LINE
Reply all
Reply to author
Forward
0 new messages