Fatal trap 9: general protection fault in unp_dispose

16 views
Skip to first unread message

syzbot

unread,
Mar 20, 2019, 9:58:06 AM3/20/19
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 3d80c629 netmap: update unit tests
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=11ad862b200000
dashboard link: https://syzkaller.appspot.com/bug?extid=e8b214b2dc91425827eb
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=10ff7e2b200000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+e8b214...@syzkaller.appspotmail.com

Fatal trap 9: general protection fault while in kernel mode
cpuid = 1; apic id = 01
instruction pointer = 0x20:0xffffffff81163ee5
stack pointer = 0x28:0xfffffe002127a610
frame pointer = 0x28:0xfffffe002127a650
code segment = base 0x0, limit 0xfffff, type 0x1b
= DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags = interrupt enabled, resume, IOPL = 0
current process = 874 (syz-executor.2)
trap number = 9
panic: general protection fault
cpuid = 1
time = 1553089913
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe002127a2e0
vpanic() at vpanic+0x1e0/frame 0xfffffe002127a340
panic() at panic+0x43/frame 0xfffffe002127a3a0
trap_fatal() at trap_fatal+0x4c6/frame 0xfffffe002127a420
trap() at trap+0xba/frame 0xfffffe002127a540
calltrap() at calltrap+0x8/frame 0xfffffe002127a540
--- trap 0x9, rip = 0xffffffff81163ee5, rsp = 0xfffffe002127a610, rbp =
0xfffffe002127a650 ---
unp_dispose() at unp_dispose+0xa5/frame 0xfffffe002127a650
sofree() at sofree+0x42c/frame 0xfffffe002127a6b0
soclose() at soclose+0x5b3/frame 0xfffffe002127a730
_fdrop() at _fdrop+0x3a/frame 0xfffffe002127a760
closef() at closef+0x27d/frame 0xfffffe002127a7f0
fdescfree_fds() at fdescfree_fds+0xbd/frame 0xfffffe002127a840
fdescfree() at fdescfree+0x58a/frame 0xfffffe002127a900
exit1() at exit1+0x780/frame 0xfffffe002127a970
sys_sys_exit() at sys_sys_exit+0xd/frame 0xfffffe002127a980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe002127aab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe002127aab0
--- syscall (1, FreeBSD ELF64, sys_sys_exit), rip = 0x44f30a, rsp =
0x7fffffffec58, rbp = 0x1 ---
KDB: enter: panic
[ thread pid 874 tid 100116 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#bug-status-tracking for how to communicate with
syzbot.
syzbot can test patches for this bug, for details see:
https://goo.gl/tpsmEJ#testing-patches

syzbot

unread,
Mar 20, 2019, 1:33:05 PM3/20/19
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 3d80c629 netmap: update unit tests
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=11bad217200000
dashboard link: https://syzkaller.appspot.com/bug?extid=e8b214b2dc91425827eb
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=12f6bc3b200000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=159d862b200000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+e8b214...@syzkaller.appspotmail.com

Fatal trap 9: general protection fault while in kernel mode
cpuid = 1; apic id = 01
instruction pointer = 0x20:0xffffffff81163ee5
stack pointer = 0x28:0xfffffe00212a9610
frame pointer = 0x28:0xfffffe00212a9650
code segment = base 0x0, limit 0xfffff, type 0x1b
= DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags = interrupt enabled, resume, IOPL = 0
current process = 824 (syz-executor5687458)
trap number = 9
panic: general protection fault
cpuid = 1
time = 1553102872
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe00212a92e0
vpanic() at vpanic+0x1e0/frame 0xfffffe00212a9340
panic() at panic+0x43/frame 0xfffffe00212a93a0
trap_fatal() at trap_fatal+0x4c6/frame 0xfffffe00212a9420
trap() at trap+0xba/frame 0xfffffe00212a9540
calltrap() at calltrap+0x8/frame 0xfffffe00212a9540
--- trap 0x9, rip = 0xffffffff81163ee5, rsp = 0xfffffe00212a9610, rbp =
0xfffffe00212a9650 ---
unp_dispose() at unp_dispose+0xa5/frame 0xfffffe00212a9650
sofree() at sofree+0x42c/frame 0xfffffe00212a96b0
soclose() at soclose+0x5b3/frame 0xfffffe00212a9730
_fdrop() at _fdrop+0x3a/frame 0xfffffe00212a9760
closef() at closef+0x27d/frame 0xfffffe00212a97f0
fdescfree_fds() at fdescfree_fds+0xbd/frame 0xfffffe00212a9840
fdescfree() at fdescfree+0x58a/frame 0xfffffe00212a9900
exit1() at exit1+0x780/frame 0xfffffe00212a9970
sys_sys_exit() at sys_sys_exit+0xd/frame 0xfffffe00212a9980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe00212a9ab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe00212a9ab0
--- syscall (1, FreeBSD ELF64, sys_sys_exit), rip = 0x447a7a, rsp =
0x7fffdfffd508, rbp = 0x7fffdfffd520 ---
KDB: enter: panic
[ thread pid 824 tid 100222 ]

Mark Johnston

unread,
Mar 19, 2020, 4:43:43 PM3/19/20
to syzbot, syzkaller-f...@googlegroups.com
#syz dup: panic: sbfree: m ADDR !M_NOTREADY

> ---
> This bug is generated by a bot. It may contain errors.
> See https://goo.gl/tpsmEJ for more information about syzbot.
> syzbot engineers can be reached at syzk...@googlegroups.com.
>
> syzbot will keep track of this bug report. See:
> https://goo.gl/tpsmEJ#bug-status-tracking for how to communicate with
> syzbot.
> syzbot can test patches for this bug, for details see:
> https://goo.gl/tpsmEJ#testing-patches
>
> --
> You received this message because you are subscribed to the Google Groups "syzkaller-freebsd-bugs" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to syzkaller-freebsd...@googlegroups.com.
> To view this discussion on the web visit https://groups.google.com/d/msgid/syzkaller-freebsd-bugs/000000000000cd2a08058487022f%40google.com.
> For more options, visit https://groups.google.com/d/optout.
Reply all
Reply to author
Forward
0 new messages