panic: Assertion mtx_unowned(m) failed at /syzkaller/managers/i386/kernel/sys/kern/kern_mutex.c:LINE

3 views
Skip to first unread message

syzbot

unread,
Nov 13, 2019, 8:35:09 PM11/13/19
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: a30fad3f ssp: further refine the conditional used for cons..
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=165ce28ce00000
dashboard link: https://syzkaller.appspot.com/bug?extid=f8ce38d2cd2f184d7f46
userspace arch: i386

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+f8ce38...@syzkaller.appspotmail.com

panic: Assertion mtx_unowned(m) failed at
/syzkaller/managers/i386/kernel/sys/kern/kern_mutex.c:1170
cpuid = 0
time = 1573695265
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe00242d8850
vpanic() at vpanic+0x1c7/frame 0xfffffe00242d88c0
panic() at panic+0x43/frame 0xfffffe00242d8920
_mtx_destroy() at _mtx_destroy+0x132/frame 0xfffffe00242d8960
solisten_proto() at solisten_proto+0xf6/frame 0xfffffe00242d89c0
tcp6_usr_listen() at tcp6_usr_listen+0x1dc/frame 0xfffffe00242d8a30
solisten() at solisten+0x7a/frame 0xfffffe00242d8a70
kern_listen() at kern_listen+0x125/frame 0xfffffe00242d8ab0
ia32_syscall() at ia32_syscall+0x466/frame 0xfffffe00242d8bf0
int0x80_syscall_common() at int0x80_syscall_common+0x9c/frame 0x8142e6d
KDB: enter: panic
[ thread pid 11065 tid 100659 ]
Stopped at kdb_enter+0x67: movq $0,0x1469726(%rip)
db>
db> set $lines = 0
db> set $maxwidth = 0
db> show registers
cs 0x20
ds 0x3b ll+0x1a
es 0x3b ll+0x1a
fs 0x13
gs 0x1b
ss 0
rax 0x12
rcx 0xfffffe0027400000
rdx 0x3ffff
rbx 0
rsp 0xfffffe00242d8830
rbp 0xfffffe00242d8850
rsi 0x40001
rdi 0xffffffff810b4d41 vprintf+0xe1
r8 0
r9 0xffffffff
r10 0x38a7c265
r11 0xf3f47ecd
r12 0xffffffff82068cf0 ddb_dbbe
r13 0
r14 0xffffffff819141f0
r15 0xffffffff819141f0
rip 0xffffffff810a9fc7 kdb_enter+0x67
rflags 0x200086 kernphys+0x86
kdb_enter+0x67: movq $0,0x1469726(%rip)
db> show proc
Process 11065 (syz-executor.1) at 0xfffff80003c52000:
state: NORMAL
uid: 0 gids: 0, 0, 5
parent: pid 760 at 0xfffff800363d4a60
ABI: FreeBSD ELF32
arguments: /root/syz-executor.1
reaper: 0xfffff800031f9530 reapsubtree: 1
sigparent: 20
vmspace: 0xfffff800390f7000
(map 0xfffff800390f7000)
(map.pmap 0xfffff800390f70d0)
(pmap 0xfffff800390f7130)
threads: 7
100081 RunQ syz-executor.1
100626 D biowr 0xfffffe0004019ac0 syz-executor.1
100641 S accept 0xfffff80003d7d168 syz-executor.1
100650 D ufs 0xfffff800394b7d88 syz-executor.1
101170 S accept 0xfffff80003d7d168 syz-executor.1
100659 Run CPU 0 syz-executor.1
100662 Run CPU 1 syz-executor.1
db> ps
pid ppid pgrp uid state wmesg wchan cmd
11072 780 780 0 S (threaded) syz-executor.2
100117 S nanslp 0xffffffff824fc2e1 syz-executor.2
100657 S select 0xfffff800390348c0 syz-executor.2
100635 S uwait 0xfffff800030d0700 syz-executor.2
11071 761 761 0 D (threaded) syz-executor.3
100634 S nanslp 0xffffffff824fc2e0 syz-executor.3
100646 D biowr 0xfffffe0003e42d40 syz-executor.3
100647 S uwait 0xfffff800392df700 syz-executor.3
11065 760 760 0 R (threaded) syz-executor.1
100081 RunQ syz-executor.1
100626 D biowr 0xfffffe0004019ac0 syz-executor.1
100641 S accept 0xfffff80003d7d168 syz-executor.1
100650 D ufs 0xfffff800394b7d88 syz-executor.1
101170 S accept 0xfffff80003d7d168 syz-executor.1
100659 Run CPU 0 syz-executor.1
100662 Run CPU 1 syz-executor.1
3299 1 3299 65 Ss select 0xfffff800363a2940 dhclient
2689 1 2689 0 Ss select 0xfffff800363a14c0 dhclient
2685 1 2685 0 Ss select 0xfffff80036d0a140 dhclient
2665 1 2665 65 Ss select 0xfffff800363a2440 dhclient
2076 1 2076 0 Ss select 0xfffff800363a2040 dhclient
2072 1 2072 0 Ss select 0xfffff800030745c0 dhclient
2051 1 2051 65 Ss select 0xfffff800363a2340 dhclient
1426 1 1426 0 Ss select 0xfffff800039fdc40 dhclient
1423 1 1423 0 Ss select 0xfffff800363a0140 dhclient
1402 1 1402 65 Ss select 0xfffff800363a1cc0 dhclient
802 1 802 0 Ss select 0xfffff800363a25c0 dhclient
794 1 794 0 Ss select 0xfffff800363a2d40 dhclient
780 754 780 0 Ss nanslp 0xffffffff824fc2e1 syz-executor.2
761 754 761 0 Ss nanslp 0xffffffff824fc2e0 syz-executor.3
760 754 760 0 Ss nanslp 0xffffffff824fc2e1 syz-executor.1
759 754 759 0 Ss piperd 0xfffff80003bffbe0 syz-executor.0
754 752 752 0 S (threaded) syz-fuzzer
100097 S uwait 0xfffff800032a7580 syz-fuzzer
100101 S uwait 0xfffff800032aad00 syz-fuzzer
100102 S uwait 0xfffff800032aae00 syz-fuzzer
100103 S uwait 0xfffff800032aaf00 syz-fuzzer
100104 S kqread 0xfffff800031d8b00 syz-fuzzer
100105 S uwait 0xfffff80003430180 syz-fuzzer
100106 S uwait 0xfffff800032a6e00 syz-fuzzer
100107 S uwait 0xfffff800032a6f00 syz-fuzzer
100109 S uwait 0xfffff800032a7180 syz-fuzzer
100111 S uwait 0xfffff800032a6900 syz-fuzzer
752 750 752 0 Ss pause 0xfffff800039a75d8 csh
750 668 750 0 Ss select 0xfffff800363a2dc0 sshd
734 1 734 0 Ss+ ttyin 0xfffff800036e40b0 getty
733 1 733 0 Ss+ ttyin 0xfffff80003a040b0 getty
732 1 732 0 Ss+ ttyin 0xfffff80003a048b0 getty
731 1 731 0 Ss+ ttyin 0xfffff80003a050b0 getty
730 1 730 0 Ss+ ttyin 0xfffff80003a058b0 getty
729 1 729 0 Ss+ ttyin 0xfffff80003a060b0 getty
728 1 728 0 Ss+ ttyin 0xfffff80003a068b0 getty
727 1 727 0 Ss+ ttyin 0xfffff80003a070b0 getty
726 1 726 0 Ss+ ttyin 0xfffff800036fb0b0 getty
672 1 672 0 Ss nanslp 0xffffffff824fc2e1 cron
668 1 668 0 Ss select 0xfffff800363a30c0 sshd
481 1 481 0 Ss select 0xfffff800030743c0 syslogd
410 1 410 0 Ss select 0xfffff800039fee40 devd
409 1 409 65 Ss select 0xfffff800039fec40 dhclient
324 1 324 0 Ss select 0xfffff800039fedc0 dhclient
321 1 321 0 Ss select 0xfffff800039fef40 dhclient
21 0 0 0 DL syncer 0xffffffff825d27b0 [syncer]
20 0 0 0 DL vlruwt 0xfffff80003429000 [vnlru]
19 0 0 0 DL (threaded) [bufdaemon]
100063 D qsleep 0xffffffff825d1c58 [bufdaemon]
100065 D - 0xffffffff8200a900
[bufspacedaemon-0]
100079 D sdflush 0xfffff800039024e8 [/ worker]
18 0 0 0 DL psleep 0xffffffff825ed108 [vmdaemon]
17 0 0 0 DL (threaded) [pagedaemon]
100061 D psleep 0xffffffff82618e98 [dom0]
100067 D launds 0xffffffff82618ea4 [laundry: dom0]
100068 D umarcl 0xffffffff81529f70 [uma]
16 0 0 0 DL - 0xffffffff82357f20 [rand_harvestq]
15 0 0 0 DL waiting 0xffffffff8265e470 [sctp_iterator]
9 0 0 0 DL - 0xffffffff825d165c [soaiod4]
8 0 0 0 DL - 0xffffffff825d165c [soaiod3]
7 0 0 0 DL - 0xffffffff825d165c [soaiod2]
6 0 0 0 DL - 0xffffffff825d165c [soaiod1]
5 0 0 0 DL (threaded) [cam]
100031 D - 0xffffffff822332c0 [doneq0]
100060 D - 0xffffffff82233188 [scanner]
4 0 0 0 DL crypto_ 0xfffff800031dbc90 [crypto
returns 1]
3 0 0 0 DL crypto_ 0xfffff800031dbc30 [crypto
returns 0]
2 0 0 0 DL crypto_ 0xffffffff825e7748 [crypto]
14 0 0 0 DL seqstat 0xfffff80003254888 [sequencer 00]
13 0 0 0 DL (threaded) [geom]
100022 D - 0xffffffff82617490 [g_event]
100023 D - 0xffffffff826174a0 [g_up]
100024 D - 0xffffffff82617498 [g_down]
12 0 0 0 WL (threaded) [intr]
100005 I [swi6: Giant
taskq]
100007 I [swi5: fast
taskq]
100011 I [swi6: task
queue]
100017 I [swi4: clock
(0)]
100018 I [swi4: clock
(1)]
100019 I [swi3: vm]
100020 I [swi1: netisr
0]
100032 I [irq24:
virtio_pci0]
100033 I [irq25:
virtio_pci0]
100034 I [irq26:
virtio_pci0]
100035 I [irq27:
virtio_pci0]
100036 I [irq28:
virtio_pci1]
100037 I [irq29:
virtio_pci1]
100038 I [irq30:
virtio_pci1]
100039 I [irq31:
virtio_pci1]
100040 I [irq32:
virtio_pci1]
100045 I [irq1: atkbd0]
100046 I [irq12: psm0]
100047 I [swi0: uart
uart++]
11 0 0 0 RL (threaded) [idle]
100003 CanRun [idle: cpu0]
100004 CanRun [idle: cpu1]
1 0 1 0 SLs wait 0xfffff800031f9530 [init]
10 0 0 0 DL audit_w 0xffffffff8265f100 [audit]
0 0 0 0 DLs (threaded) [kernel]
100000 D swapin 0xffffffff82606c68 [swapper]
100006 D - 0xfffff8000322ce00 [thread taskq]
100008 D - 0xfffff8000322cc00 [config_0]
100009 D - 0xfffff8000322cb00 [kqueue_ctx
taskq]
100010 D - 0xfffff8000322ca00 [aiod_kick
taskq]
100012 D - 0xfffff8000322c800 [softirq_0]
100013 D - 0xfffff8000322c700 [softirq_1]
100014 D - 0xfffff8000322c600 [if_io_tqg_0]
100015 D - 0xfffff8000322c500 [if_io_tqg_1]
100016 D - 0xfffff8000322c400
[if_config_tqg_0]
100021 D - 0xfffff8000322c300 [firmware
taskq]
100026 D - 0xfffff8000322c200 [crypto_0]
100027 D - 0xfffff8000322c200 [crypto_1]
100041 D - 0xfffff8000322bd00 [vtnet0 rxq 0]
100042 D - 0xfffff8000322bc00 [vtnet0 txq 0]
100043 D - 0xfffff8000322bb00 [vtnet0 rxq 1]
100044 D - 0xfffff8000322ba00 [vtnet0 txq 1]
100048 D - 0xfffff8000322b900 [mca taskq]
100052 D - 0xffffffff824fb061 [deadlkres]
100055 D - 0xfffff800039d9100 [acpi_task_0]
100056 D - 0xfffff800039d9100 [acpi_task_1]
100057 D - 0xfffff800039d9100 [acpi_task_2]
100059 D - 0xfffff8000322c100 [CAM taskq]
db> show all locks
Process 11071 (syz-executor.3) thread 0xfffff8003933e6e0 (100646)
exclusive lockmgr bufwait (bufwait) r = 0 (0xfffffe0003e42dc0) locked @
/syzkaller/managers/i386/kernel/sys/kern/vfs_bio.c:3873
exclusive lockmgr ufs (ufs) r = 0 (0xfffff800366c2d88) locked @
/syzkaller/managers/i386/kernel/sys/kern/vfs_vnops.c:874
Process 11065 (syz-executor.1) thread 0xfffff800391966e0 (100626)
exclusive lockmgr bufwait (bufwait) r = 0 (0xfffffe0004019b40) locked @
/syzkaller/managers/i386/kernel/sys/kern/vfs_bio.c:3873
exclusive lockmgr ufs (ufs) r = 0 (0xfffff800394b7d88) locked @
/syzkaller/managers/i386/kernel/sys/kern/vfs_vnops.c:874
Process 11065 (syz-executor.1) thread 0xfffff8003917b000 (100650)
exclusive lockmgr ufs (ufs) r = 0 (0xfffff80039374d88) locked @
/syzkaller/managers/i386/kernel/sys/kern/vfs_lookup.c:713
Process 11065 (syz-executor.1) thread 0xfffff800394ec000 (100659)
exclusive sleep mutex socket (socket) r = 0 (0xfffff80003d6ba98) locked @
/syzkaller/managers/i386/kernel/sys/netinet/tcp_usrreq.c:479
exclusive rw tcpinp (tcpinp) r = 0 (0xfffff80036326020) locked @
/syzkaller/managers/i386/kernel/sys/netinet/tcp_usrreq.c:471
db> show malloc
Type InUse MemUse Requests
devbuf 4200 4764K 4227
vtbuf 24 1968K 46
callout 3 1672K 3
kobj 332 1328K 488
newblk 34 1033K 74713
vfscache 4 1025K 4
pcb 29 537K 3595
inodedep 7 515K 16694
ufs_quota 1 512K 1
vfs_hash 1 512K 1
intr 4 388K 4
subproc 142 281K 11155
acpica 1674 185K 47809
vnet_data 1 168K 1
filedesc 19 133K 20343
pagedep 9 130K 10189
tfo_ccache 1 128K 1
sysctloid 2038 107K 2098
sem 4 106K 4
DEVFS1 105 105K 122
BPF 46 88K 46
bus 948 77K 2929
linker 205 76K 231
mtx_pool 2 72K 2
UMAHash 3 69K 5
syncache 1 68K 1
acpitask 1 64K 1
ddb_capture 1 64K 1
module 494 62K 494
umtx 320 40K 320
kdtrace 187 36K 44426
gtaskqueue 22 34K 22
hostcache 1 32K 1
shm 1 32K 16
DEVFS3 124 31K 134
msg 4 30K 4
DEVFS_RULE 56 27K 56
ifaddr 76 26K 76
kbdmux 6 22K 6
vmem 3 20K 5
temp 34 17K 2735
ufs_mount 3 17K 4
proc 3 17K 3
lltable 44 16K 118
tty 16 16K 16
tidhash 1 16K 1
ithread 87 15K 87
ether_multi 172 14K 177
bus-sc 26 13K 1128
KTRACE 100 13K 100
ifnet 7 13K 7
kenv 95 12K 99
in6_multi 89 11K 89
eventhandler 122 11K 122
pfs_nodes 20 10K 20
GEOM 60 10K 487
rman 77 9K 418
cred 34 9K 351
bmsafemap 2 9K 14417
devstat 4 9K 4
UART 12 9K 12
rpc 2 8K 2
sctp_timw 32 8K 32
shmfd 1 8K 1
pfs_vncache 1 8K 1
select 63 8K 63
audit_evclass 230 8K 288
routetbl 58 7K 62
plimit 24 6K 509
kqueue 62 6K 11077
CAM DEV 3 6K 508
vt 11 6K 11
sglist 5 6K 5
CAM queue 5 6K 1522
DEVFSP 78 5K 82
ufs_dirhash 24 5K 24
taskqueue 42 5K 42
session 35 5K 52
pgrp 35 5K 52
memdesc 1 4K 1
MCA 32 4K 32
evdev 4 4K 4
kcovinfo 64 4K 68
CAM CCB 2 4K 147424
lockf 35 4K 416
hhook 13 4K 13
proc-args 52 3K 660
terminal 11 3K 11
acpisem 20 3K 20
uidinfo 5 3K 18
sctp_ifa 17 3K 17
local_apic 1 2K 1
io_apic 1 2K 1
ipsec-saq 2 2K 2
ip6ndp 12 2K 21
Unitno 32 2K 42425
CAM XPT 22 2K 542
in_multi 6 2K 7
acpidev 20 2K 20
crypto 2 2K 2
msi 9 2K 9
tun 7 2K 7
ipsecpolicy 1 1K 1
sahead 1 1K 1
secasvar 1 1K 1
clone 8 1K 8
cdev 4 1K 4
NFSD session 1 1K 1
CAM periph 4 1K 270
diradd 6 1K 12643
mld 6 1K 6
sctp_ifn 6 1K 6
igmp 6 1K 6
toponodes 6 1K 6
isadev 6 1K 6
mount 16 1K 86
pci_link 10 1K 10
iov 4 1K 21855
CAM SIM 2 1K 2
softdep 1 1K 1
savedino 2 1K 12814
mkdir 4 1K 20336
indirdep 2 1K 38733
chacha20random 1 1K 1
epoch 4 1K 4
inpcbpolicy 15 1K 2423
encap_export_host 8 1K 8
pfil 3 1K 3
osd 3 1K 9
newdirblk 4 1K 10168
vnodes 1 1K 162
NFSD lckfile 1 1K 1
NFSD V4client 1 1K 1
DEVFS 9 1K 10
feeder 7 1K 7
loginclass 3 1K 3
apmdev 1 1K 1
atkbddev 2 1K 2
pmchooks 1 1K 1
prison 4 1K 4
CAM dev queue 2 1K 2
CAM I/O Scheduler 1 1K 1
CAM path 4 1K 1030
soname 4 1K 6547
nexusdev 5 1K 5
filecaps 5 1K 99
ip6_msource 1 1K 1
tcpfunc 1 1K 1
sctp_vrf 1 1K 1
ip_msource 1 1K 1
vnet 1 1K 1
acpiintr 1 1K 1
pmc 1 1K 1
cpus 2 1K 2
freework 1 1K 36110
vnet_data_free 1 1K 1
Per-cpu 1 1K 1
entropy 1 1K 45
p1003.1b 1 1K 1
ppbusdev 0 0K 0
agtiapi_MemAlloc malloc 0 0K 0
osti_cacheable 0 0K 0
madt_table 0 0K 2
tempbuff 0 0K 0
tempbuff 0 0K 0
smartpqi 0 0K 0
ag_tgt_map_t malloc 0 0K 0
ag_slr_map_t malloc 0 0K 0
lDevFlags * malloc 0 0K 0
tiDeviceHandle_t * malloc 0 0K 0
ag_portal_data_t malloc 0 0K 0
ag_device_t malloc 0 0K 0
STLock malloc 0 0K 0
CCB List 0 0K 0
iavf 0 0K 0
ixl 0 0K 0
sr_iov 0 0K 0
OCS 0 0K 0
OCS 0 0K 0
nvme 0 0K 0
nvd 0 0K 0
netmap 0 0K 0
mwldev 0 0K 0
MVS driver 0 0K 0
fpukern_ctx 0 0K 0
xen_intr 0 0K 0
CAM ccb queue 0 0K 0
xen_hvm 0 0K 0
legacydrv 0 0K 0
qpidrv 0 0K 0
mrsasbuf 0 0K 0
mpt_user 0 0K 0
dmar_idpgtbl 0 0K 0
dmar_dom 0 0K 0
dmar_ctx 0 0K 0
dmar_dmamap 0 0K 0
mps_user 0 0K 0
MPSSAS 0 0K 0
isci 0 0K 0
bxe_ilt 0 0K 0
xenbus 0 0K 0
vm_fictitious 0 0K 0
mps 0 0K 0
mpr_user 0 0K 0
MPRSAS 0 0K 0
vm_pgdata 0 0K 0
jblocks 0 0K 0
sentinel 0 0K 0
jfsync 0 0K 0
jtrunc 0 0K 0
sbdep 0 0K 43
jsegdep 0 0K 0
jseg 0 0K 0
jfreefrag 0 0K 0
jfreeblk 0 0K 0
jnewblk 0 0K 0
jmvref 0 0K 0
jremref 0 0K 0
jaddref 0 0K 0
freedep 0 0K 0
dirrem 0 0K 12599
freefile 0 0K 12594
freeblks 0 0K 13884
freefrag 0 0K 22
allocindir 0 0K 0
allocdirect 0 0K 0
ufs_trim 0 0K 0
mactemp 0 0K 0
audit_trigger 0 0K 0
audit_pipe_presel 0 0K 0
audit_pipeent 0 0K 0
audit_pipe 0 0K 0
audit_evname 0 0K 0
audit_bsm 0 0K 0
audit_gidset 0 0K 0
audit_text 0 0K 0
audit_path 0 0K 0
audit_data 0 0K 0
audit_cred 0 0K 0
xform 0 0K 0
NLM 0 0K 0
nfsclient_nlminfo 0 0K 0
nfsclient_lock 0 0K 0
NFS FHA 0 0K 0
ipsec-spdcache 0 0K 0
ipsec-reg 0 0K 0
ipsec-misc 0 0K 0
ipsecrequest 0 0K 0
ip6opt 0 0K 15
ip6_moptions 0 0K 5
in6_mfilter 0 0K 10
frag6 0 0K 3
tcplog 0 0K 0
LRO 0 0K 0
sctp_mcore 0 0K 0
sctp_socko 0 0K 116
sctp_iter 0 0K 10
sctp_mvrf 0 0K 0
sctp_cpal 0 0K 0
sctp_cmsg 0 0K 0
sctp_stre 0 0K 0
sctp_athi 0 0K 0
sctp_athm 0 0K 1820
sctp_atky 0 0K 2213
sctp_atcl 0 0K 1819
sctp_a_it 0 0K 10
sctp_aadr 0 0K 0
sctp_stro 0 0K 394
sctp_stri 0 0K 0
sctp_map 0 0K 788
newreno data 0 0K 1
ip_moptions 0 0K 2
in_mfilter 0 0K 4
ipid 0 0K 0
80211scan 0 0K 0
80211ratectl 0 0K 0
80211power 0 0K 0
80211nodeie 0 0K 0
80211node 0 0K 0
80211mesh_gt 0 0K 0
80211mesh_rt 0 0K 0
80211perr 0 0K 0
80211prep 0 0K 0
80211preq 0 0K 0
80211dfs 0 0K 0
80211crypto 0 0K 0
80211vap 0 0K 0
iflib 0 0K 0
vlan 0 0K 0
gif 0 0K 0
ifdescr 0 0K 0
zlib 0 0K 0
fadvise 0 0K 0
vnodemarker 0 0K 92
mpr 0 0K 0
statfs 0 0K 10362
export_host 0 0K 0
cl_savebuf 0 0K 9
biobuf 0 0K 0
aios 0 0K 0
lio 0 0K 0
acl 0 0K 0
mfibuf 0 0K 0
mbuf_tag 0 0K 189
accf 0 0K 0
pts 0 0K 0
ioctlops 0 0K 116
Witness 0 0K 0
stack 0 0K 0
md_sectors 0 0K 0
sbuf 0 0K 364
md_disk 0 0K 0
compressor 0 0K 0
malodev 0 0K 0
SWAP 0 0K 0
LED 0 0K 0
sysctltmp 0 0K 757
sysctl 0 0K 1
ekcd 0 0K 0
dumper 0 0K 0
rctl 0 0K 0
ix_sriov 0 0K 0
aacraidcam 0 0K 0
ix 0 0K 0
ipsbuf 0 0K 0
iirbuf 0 0K 0
cache 0 0K 0
aacraid_buf 0 0K 0
prison_racct 0 0K 0
Fail Points 0 0K 0
sigio 0 0K 1
filedesc_to_leader 0 0K 0
tty console 0 0K 0
aaccam 0 0K 0
aacbuf 0 0K 0
zstd 0 0K 0
nvlist 0 0K 0
SCSI ENC 0 0K 0
SCSI sa 0 0K 0
isofs_node 0 0K 0
isofs_mount 0 0K 0
tr_raid5_data 0 0K 0
tr_raid1e_data 0 0K 0
tr_raid1_data 0 0K 0
tr_raid0_data 0 0K 0
tr_concat_data 0 0K 0
md_sii_data 0 0K 0
md_promise_data 0 0K 0
md_nvidia_data 0 0K 0
md_jmicron_data 0 0K 0
md_intel_data 0 0K 0
md_ddf_data 0 0K 0
raid_data 0 0K 72
geom_flashmap 0 0K 0
newnfsmnt 0 0K 0
newnfsclient_req 0 0K 0
NFSCL layrecall 0 0K 0
NFSCL session 0 0K 0
NFSCL sockreq 0 0K 0
NFSCL devinfo 0 0K 0
NFSCL flayout 0 0K 0
NFSCL layout 0 0K 0
NFSD rollback 0 0K 0
NFSCL diroffdiroff 0 0K 0
NEWdirectio 0 0K 0
NEWNFSnode 0 0K 0
NFSCL lck 0 0K 0
NFSCL lckown 0 0K 0
NFSCL client 0 0K 0
NFSCL deleg 0 0K 0
NFSCL open 0 0K 0
NFSCL owner 0 0K 0
NFS fh 0 0K 0
NFS req 0 0K 0
NFSD usrgroup 0 0K 0
NFSD string 0 0K 0
NFSD V4lock 0 0K 0
NFSD V4state 0 0K 0
NFSD srvcache 0 0K 0
msdosfs_fat 0 0K 0
msdosfs_mount 0 0K 0
msdosfs_node 0 0K 0
DEVFS4 0 0K 0
DEVFS2 0 0K 0
gntdev 0 0K 0
privcmd_dev 0 0K 0
evtchn_dev 0 0K 0
xenstore 0 0K 0
scsi_pass 0 0K 0
ciss_data 0 0K 0
xnb 0 0K 0
xbbd 0 0K 0
xbd 0 0K 0
Balloon 0 0K 0
sysmouse 0 0K 0
vtfont 0 0K 0
ath_hal 0 0K 0
athdev 0 0K 0
ata_pci 0 0K 0
ata_dma 0 0K 0
ata_generic 0 0K 0
amr 0 0K 0
scsi_da 0 0K 69
ata_da 0 0K 0
scsi_ch 0 0K 0
scsi_cd 0 0K 0
USBdev 0 0K 0
USB 0 0K 0
AHCI driver 0 0K 0
agp 0 0K 0
nvme_da 0 0K 0
acpipwr 0 0K 0
twsbuf 0 0K 0
twe_commands 0 0K 0
twa_commands 0 0K 0
tcp_log_dev 0 0K 0
midi buffers 0 0K 0
mixer 0 0K 0
ac97 0 0K 0
hdacc 0 0K 0
hdac 0 0K 0
hdaa 0 0K 0
acpi_perf 0 0K 0
acpicmbat 0 0K 0
SIIS driver 0 0K 0
PUC 0 0K 0
db> show ktr
No such command; use "help" to list available commands


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Feb 8, 2020, 9:42:11 AM2/8/20
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: f0a4f1b9 vfs: use newly added zpcpu routines instead of di..
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=1380a431e00000
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=138c6ba5e00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+f8ce38...@syzkaller.appspotmail.com

login: panic: Assertion mtx_unowned(m) failed at /syzkaller/managers/i386/kernel/sys/kern/kern_mutex.c:1179
cpuid = 0
time = 1581172570
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame 0xfffffe0024b0f850
vpanic() at vpanic+0x1ce/frame 0xfffffe0024b0f8c0
panic() at panic+0x43/frame 0xfffffe0024b0f920
_mtx_destroy() at _mtx_destroy+0x132/frame 0xfffffe0024b0f960
solisten_proto() at solisten_proto+0xf6/frame 0xfffffe0024b0f9c0
tcp6_usr_listen() at tcp6_usr_listen+0x1dc/frame 0xfffffe0024b0fa30
solisten() at solisten+0x7a/frame 0xfffffe0024b0fa70
kern_listen() at kern_listen+0x125/frame 0xfffffe0024b0fab0
ia32_syscall() at ia32_syscall+0x48c/frame 0xfffffe0024b0fbf0
int0x80_syscall_common() at int0x80_syscall_common+0x9c/frame 0x8142e7d
KDB: enter: panic
[ thread pid 892 tid 100295 ]
Stopped at kdb_enter+0x67: movq $0,0x1465d66(%rip)
db>
db> set $lines = 0
db> set $maxwidth = 0
db> show registers
cs 0x20
ds 0x3b ll+0x1a
es 0x3b ll+0x1a
fs 0x13
gs 0x1b
ss 0
rax 0x12
rcx 0x80 ll+0x5f
rdx 0xffffffff818f2c52
rbx 0
rsp 0xfffffe0024b0f830
rbp 0xfffffe0024b0f850
rsi 0x1
rdi 0
r8 0
r9 0xffffffff
r10 0
r11 0xfffffe00249a02b0
r12 0xffffffff82068d90 ddb_dbbe
r13 0
r14 0xffffffff8193ad7f
r15 0xffffffff8193ad7f
rip 0xffffffff810b0357 kdb_enter+0x67
rflags 0x200086 kernphys+0x86
kdb_enter+0x67: movq $0,0x1465d66(%rip)
db> show proc
Process 892 (syz-executor.2) at 0xfffff800032d4a60:
state: NORMAL
uid: 0 gids: 0, 0, 5
parent: pid 784 at 0xfffff8003a2bb530
ABI: FreeBSD ELF32
arguments: /root/syz-executor.2
reaper: 0xfffff800032d4000 reapsubtree: 1
sigparent: 20
vmspace: 0xfffffe0004990000
(map 0xfffffe0004990000)
(map.pmap 0xfffffe00049900c0)
(pmap 0xfffffe0004990120)
threads: 6
100072 RunQ syz-executor.2
100277 S connec 0xfffffe0004dd7f10 syz-executor.2
100278 S connec 0xfffffe0024909d30 syz-executor.2
100279 S connec 0xfffffe0004dd29a8 syz-executor.2
100295 Run CPU 0 syz-executor.2
100296 Run CPU 1 syz-executor.2
db> ps
pid ppid pgrp uid state wmesg wchan cmd
895 773 773 0 S (threaded) syz-executor.1
100115 S nanslp 0xffffffff824fecc1 syz-executor.1
100292 S connec 0xfffffe002490a800 syz-executor.1
100293 S connec 0xfffffe002490cf10 syz-executor.1
100294 S uwait 0xfffff800039b1200 syz-executor.1
894 776 776 0 S (threaded) syz-executor.0
100118 S nanslp 0xffffffff824fecc0 syz-executor.0
100285 S connec 0xfffffe00249120f0 syz-executor.0
100287 S connec 0xfffffe002490c800 syz-executor.0
100289 S uwait 0xfffff80003b3be00 syz-executor.0
893 774 774 0 S (threaded) syz-executor.3
100170 S nanslp 0xffffffff824fecc0 syz-executor.3
100282 S connec 0xfffffe0004dd69a8 syz-executor.3
100286 S connec 0xfffffe002490a478 syz-executor.3
100288 S uwait 0xfffff800039b1a00 syz-executor.3
892 784 784 0 R (threaded) syz-executor.2
100072 RunQ syz-executor.2
100277 S connec 0xfffffe0004dd7f10 syz-executor.2
100278 S connec 0xfffffe0024909d30 syz-executor.2
100279 S connec 0xfffffe0004dd29a8 syz-executor.2
100295 Run CPU 0 syz-executor.2
100296 Run CPU 1 syz-executor.2
868 1 868 0 Ss select 0xfffff80003b3b440 rtsol
867 1 867 0 Ss select 0xfffff800039b1040 rtsol
866 1 866 0 Ss select 0xfffff800039b10c0 rtsol
863 794 422 0 S kqread 0xfffff80003b57500 rtsol
794 783 422 0 S wait 0xfffff8003a843530 sh
784 771 784 0 Ss nanslp 0xffffffff824fecc0 syz-executor.2
783 422 422 0 S wait 0xfffff8003a433a60 sh
776 771 776 0 Ss nanslp 0xffffffff824fecc1 syz-executor.0
774 771 774 0 Ss nanslp 0xffffffff824fecc0 syz-executor.3
773 771 773 0 Ss nanslp 0xffffffff824fecc1 syz-executor.1
771 769 769 0 S (threaded) syz-execprog
100079 S uwait 0xfffff80003b3dd80 syz-execprog
100104 S uwait 0xfffff80003b3c800 syz-execprog
100105 S kqread 0xfffff80003b5ad00 syz-execprog
100106 S uwait 0xfffff80003b3ca00 syz-execprog
100107 S uwait 0xfffff800039b0580 syz-execprog
100108 S uwait 0xfffff80003b3d200 syz-execprog
100109 S uwait 0xfffff800039b0680 syz-execprog
100110 S uwait 0xfffff800039b0780 syz-execprog
100111 S uwait 0xfffff80003b3d300 syz-execprog
769 767 769 0 Ss pause 0xfffff80003bfa5d8 csh
767 680 767 0 Ss select 0xfffff80003b3c140 sshd
746 1 746 0 Ss+ ttyin 0xfffff800033f5cb0 getty
745 1 745 0 Ss+ ttyin 0xfffff80003a928b0 getty
744 1 744 0 Ss+ ttyin 0xfffff80003a92cb0 getty
743 1 743 0 Ss+ ttyin 0xfffff80003a950b0 getty
742 1 742 0 Ss+ ttyin 0xfffff80003a954b0 getty
741 1 741 0 Ss+ ttyin 0xfffff80003a958b0 getty
740 1 740 0 Ss+ ttyin 0xfffff80003a95cb0 getty
739 1 739 0 Ss+ ttyin 0xfffff80003a940b0 getty
738 1 738 0 Ss+ ttyin 0xfffff80003a944b0 getty
736 734 22 0 S+ nanslp 0xffffffff824fecc1 sleep
735 1 22 0 S+ piperd 0xfffff80003bd6be0 logger
734 1 22 0 S+ wait 0xfffff80003bfaa60 sh
684 1 684 0 Ss nanslp 0xffffffff824fecc1 cron
680 1 680 0 Ss select 0xfffff80003b3d040 sshd
493 1 493 0 Ss select 0xfffff80003b3cbc0 syslogd
422 1 422 0 Ss wait 0xfffff80003bd7a60 devd
421 1 421 65 Ss select 0xfffff80003b3e440 dhclient
336 1 336 0 Ss select 0xfffff80003b3cdc0 dhclient
333 1 333 0 Ss select 0xfffff80003b3d940 dhclient
21 0 0 0 DL syncer 0xffffffff825d5158 [syncer]
20 0 0 0 DL vlruwt 0xfffff80003a70000 [vnlru]
19 0 0 0 DL (threaded) [bufdaemon]
100065 D qsleep 0xffffffff825d4658 [bufdaemon]
100066 D - 0xffffffff8200a980 [bufspacedaemon-0]
100082 D sdflush 0xfffff80003b638e8 [/ worker]
18 0 0 0 DL psleep 0xffffffff825f00c8 [vmdaemon]
17 0 0 0 DL (threaded) [pagedaemon]
100063 D psleep 0xffffffff8261cfd8 [dom0]
100069 D launds 0xffffffff8261cfe4 [laundry: dom0]
100070 D umarcl 0xffffffff81540fb0 [uma]
16 0 0 0 DL - 0xffffffff82359530 [rand_harvestq]
15 0 0 0 DL waiting 0xffffffff826625a0 [sctp_iterator]
9 0 0 0 DL - 0xffffffff825d405c [soaiod4]
8 0 0 0 DL - 0xffffffff825d405c [soaiod3]
7 0 0 0 DL - 0xffffffff825d405c [soaiod2]
6 0 0 0 DL - 0xffffffff825d405c [soaiod1]
5 0 0 0 DL (threaded) [cam]
100031 D - 0xffffffff82234940 [doneq0]
100062 D - 0xffffffff82234808 [scanner]
4 0 0 0 DL crypto_ 0xfffff80003303190 [crypto returns 1]
3 0 0 0 DL crypto_ 0xfffff80003303130 [crypto returns 0]
2 0 0 0 DL crypto_ 0xffffffff825ea138 [crypto]
14 0 0 0 DL seqstat 0xfffff8000333a888 [sequencer 00]
13 0 0 0 DL (threaded) [geom]
100022 D - 0xffffffff8261b608 [g_event]
100023 D - 0xffffffff8261b618 [g_up]
100024 D - 0xffffffff8261b610 [g_down]
12 0 0 0 WL (threaded) [intr]
100005 I [swi5: fast taskq]
100009 I [swi6: task queue]
100010 I [swi6: Giant taskq]
100017 I [swi3: vm]
100018 I [swi1: netisr 0]
100019 I [swi4: clock (0)]
100020 I [swi4: clock (1)]
100032 I [irq24: virtio_pci0]
100033 I [irq25: virtio_pci0]
100034 I [irq26: virtio_pci0]
100035 I [irq27: virtio_pci0]
100036 I [irq28: virtio_pci1]
100037 I [irq29: virtio_pci1]
100038 I [irq30: virtio_pci1]
100039 I [irq31: virtio_pci1]
100040 I [irq32: virtio_pci1]
100045 I [irq10: virtio_pci2]
100047 I [irq1: atkbd0]
100048 I [irq12: psm0]
100049 I [swi0: uart uart++]
11 0 0 0 RL (threaded) [idle]
100003 CanRun [idle: cpu0]
100004 CanRun [idle: cpu1]
1 0 1 0 SLs wait 0xfffff800032d4000 [init]
10 0 0 0 DL audit_w 0xffffffff82663230 [audit]
0 0 0 0 DLs (threaded) [kernel]
100000 D swapin 0xffffffff82609c48 [swapper]
100006 D - 0xfffff800031d4000 [config_0]
100007 D - 0xfffff800031d8800 [kqueue_ctx taskq]
100008 D - 0xfffff800031d8600 [aiod_kick taskq]
100011 D - 0xfffff800031d8000 [thread taskq]
100012 D - 0xfffff800031d3e00 [softirq_0]
100013 D - 0xfffff800031d3d00 [softirq_1]
100014 D - 0xfffff800031d3c00 [if_io_tqg_0]
100015 D - 0xfffff800031d3b00 [if_io_tqg_1]
100016 D - 0xfffff800031d3a00 [if_config_tqg_0]
100021 D - 0xfffff800031d7400 [firmware taskq]
100026 D - 0xfffff800031d6d00 [crypto_0]
100027 D - 0xfffff800031d6d00 [crypto_1]
100041 D - 0xfffff800031d6000 [vtnet0 rxq 0]
100042 D - 0xfffff800031d5e00 [vtnet0 txq 0]
100043 D - 0xfffff800031d5d00 [vtnet0 rxq 1]
100044 D - 0xfffff800031d5c00 [vtnet0 txq 1]
100046 D vtbslp 0xfffff8000352f880 [virtio_balloon]
100050 D - 0xfffff80003774e00 [mca taskq]
100055 D - 0xffffffff81cdef30 [deadlkres]
100057 D - 0xfffff800039b4700 [acpi_task_0]
100058 D - 0xfffff800039b4700 [acpi_task_1]
100059 D - 0xfffff800039b4700 [acpi_task_2]
100061 D - 0xfffff800031d6600 [CAM taskq]
db> show all locks
Process 892 (syz-executor.2) thread 0xfffffe002499fdc0 (100295)
exclusive sleep mutex socket (socket) r = 0 (0xfffffe0004dd9e20) locked @ /syzkaller/managers/i386/kernel/sys/netinet/tcp_usrreq.c:483
exclusive rw tcpinp (tcpinp) r = 0 (0xfffff8003a3b0d78) locked @ /syzkaller/managers/i386/kernel/sys/netinet/tcp_usrreq.c:475
db> show malloc
Type InUse MemUse Requests
devbuf 4213 4851K 4238
vtbuf 24 1968K 46
sysctloid 26632 1559K 26696
kobj 332 1328K 488
newblk 389 1121K 458
vfscache 4 1025K 4
inodedep 96 560K 119
pcb 49 549K 354
ufs_quota 1 512K 1
vfs_hash 1 512K 1
callout 2 512K 2
intr 4 388K 4
subproc 131 269K 969
acpica 1674 185K 50140
vnet_data 1 168K 1
filedesc 21 149K 123
pagedep 26 135K 57
tfo_ccache 1 128K 1
sem 4 106K 4
DEVFS1 105 105K 122
linker 222 89K 253
bus 992 79K 3335
mtx_pool 2 72K 2
syncache 1 68K 1
acpitask 1 64K 1
ddb_capture 1 64K 1
module 494 62K 494
shm 5 40K 32
umtx 306 39K 306
kdtrace 188 37K 2022
gtaskqueue 22 34K 22
hostcache 1 32K 1
DEVFS3 124 31K 134
msg 4 30K 4
DEVFS_RULE 56 27K 56
ifaddr 70 23K 72
vmem 3 22K 4
kbdmux 6 22K 6
BPF 14 19K 14
lltable 47 18K 47
temp 34 17K 1831
ufs_mount 3 17K 4
proc 3 17K 3
tty 16 16K 16
tidhash 1 16K 1
ithread 89 15K 89
ether_multi 172 14K 177
bus-sc 30 14K 1397
KTRACE 100 13K 100
ifnet 7 13K 7
kenv 95 12K 99
dirrem 44 11K 55
in6_multi 89 11K 89
eventhandler 122 11K 122
pfs_nodes 20 10K 20
GEOM 60 10K 487
rman 82 10K 423
bmsafemap 3 9K 89
kqueue 62 9K 902
devstat 4 9K 4
UART 12 9K 12
rpc 2 8K 2
shmfd 1 8K 1
pfs_vncache 1 8K 1
routetbl 57 8K 61
audit_evclass 231 8K 289
cred 28 7K 235
diradd 49 7K 87
CAM DEV 3 6K 510
vt 11 6K 11
plimit 21 6K 350
sglist 5 6K 5
CAM queue 5 6K 1528
sctp_timw 19 5K 19
ufs_dirhash 24 5K 24
sctp_atcl 9 5K 90
taskqueue 42 5K 42
memdesc 1 4K 1
MCA 32 4K 32
sctp_stro 4 4K 31
evdev 4 4K 4
UMA 235 4K 235
mkdir 27 4K 94
freefile 27 4K 36
session 27 4K 38
pgrp 27 4K 38
hhook 13 4K 13
acpisem 22 3K 22
terminal 11 3K 11
proc-args 49 3K 546
indirdep 10 3K 10
select 20 3K 20
uidinfo 4 3K 4
sctp_ifa 17 3K 17
local_apic 1 2K 1
io_apic 1 2K 1
newdirblk 16 2K 47
ipsec-saq 2 2K 2
ip6ndp 12 2K 21
Unitno 29 2K 45
CAM XPT 22 2K 543
lockf 15 2K 22
in_multi 6 2K 7
acpidev 20 2K 20
crypto 2 2K 2
msi 9 2K 9
tun 7 2K 7
softdep 1 1K 1
ipsecpolicy 1 1K 1
sahead 1 1K 1
secasvar 1 1K 1
clone 8 1K 8
vnodemarker 2 1K 6
NFSD session 1 1K 1
CAM periph 4 1K 271
inpcbpolicy 28 1K 417
mld 6 1K 6
sctp_ifn 6 1K 6
igmp 6 1K 6
toponodes 6 1K 6
isadev 6 1K 6
mount 16 1K 86
pci_link 10 1K 10
sctp_atky 13 1K 121
CAM SIM 2 1K 2
pfil 4 1K 4
chacha20random 1 1K 1
epoch 4 1K 4
cdev 2 1K 2
encap_export_host 8 1K 8
DEVFSP 6 1K 6
soname 13 1K 5869
osd 3 1K 9
vnodes 1 1K 1
NFSD lckfile 1 1K 1
NFSD V4client 1 1K 1
DEVFS 9 1K 10
feeder 7 1K 7
loginclass 3 1K 3
sctp_athm 9 1K 90
CAM path 4 1K 1034
apmdev 1 1K 1
atkbddev 2 1K 2
sctp_map 8 1K 62
pmchooks 1 1K 1
prison 4 1K 4
CAM dev queue 2 1K 2
CAM I/O Scheduler 1 1K 1
filecaps 4 1K 78
nexusdev 5 1K 5
entropy 2 1K 41
tcpfunc 1 1K 1
sctp_vrf 1 1K 1
vnet 1 1K 1
acpiintr 1 1K 1
pmc 1 1K 1
cpus 2 1K 2
freework 1 1K 53
vnet_data_free 1 1K 1
Per-cpu 1 1K 1
p1003.1b 1 1K 1
CAM CCB 0 0K 1787
madt_table 0 0K 2
PUC 0 0K 0
ppbusdev 0 0K 0
agtiapi_MemAlloc malloc 0 0K 0
osti_cacheable 0 0K 0
tempbuff 0 0K 0
pvscsi 0 0K 0
smartpqi 0 0K 0
tempbuff 0 0K 0
ag_tgt_map_t malloc 0 0K 0
ag_slr_map_t malloc 0 0K 0
lDevFlags * malloc 0 0K 0
tiDeviceHandle_t * malloc 0 0K 0
ag_portal_data_t malloc 0 0K 0
ag_device_t malloc 0 0K 0
STLock malloc 0 0K 0
iavf 0 0K 0
ixl 0 0K 0
CCB List 0 0K 0
sr_iov 0 0K 0
OCS 0 0K 0
OCS 0 0K 0
nvme 0 0K 0
nvd 0 0K 0
netmap 0 0K 0
mwldev 0 0K 0
fpukern_ctx 0 0K 0
MVS driver 0 0K 0
xen_intr 0 0K 0
xen_hvm 0 0K 0
legacydrv 0 0K 0
qpidrv 0 0K 0
CAM ccb queue 0 0K 0
mrsasbuf 0 0K 0
dmar_idpgtbl 0 0K 0
dmar_dom 0 0K 0
dmar_ctx 0 0K 0
dmar_dmamap 0 0K 0
mpt_user 0 0K 0
mps_user 0 0K 0
isci 0 0K 0
bxe_ilt 0 0K 0
xenbus 0 0K 0
vm_fictitious 0 0K 0
MPSSAS 0 0K 0
mps 0 0K 0
mpr_user 0 0K 0
MPRSAS 0 0K 0
UMAHash 0 0K 0
vm_pgdata 0 0K 0
jblocks 0 0K 0
savedino 0 0K 13
sentinel 0 0K 0
jfsync 0 0K 0
jtrunc 0 0K 0
sbdep 0 0K 2
jsegdep 0 0K 0
jseg 0 0K 0
jfreefrag 0 0K 0
jfreeblk 0 0K 0
jnewblk 0 0K 0
jmvref 0 0K 0
jremref 0 0K 0
jaddref 0 0K 0
freedep 0 0K 0
freeblks 0 0K 52
freefrag 0 0K 5
allocindir 0 0K 0
allocdirect 0 0K 0
ufs_trim 0 0K 0
mactemp 0 0K 0
audit_trigger 0 0K 0
audit_pipe_presel 0 0K 0
audit_pipeent 0 0K 0
audit_pipe 0 0K 0
audit_evname 0 0K 0
audit_bsm 0 0K 0
audit_gidset 0 0K 0
audit_text 0 0K 0
audit_path 0 0K 0
audit_data 0 0K 0
audit_cred 0 0K 0
xform 0 0K 0
NLM 0 0K 0
nfsclient_nlminfo 0 0K 0
nfsclient_lock 0 0K 0
NFS FHA 0 0K 0
ipsec-spdcache 0 0K 0
ipsec-reg 0 0K 0
ipsec-misc 0 0K 0
ipsecrequest 0 0K 0
ip6opt 0 0K 4
ip6_msource 0 0K 0
ip6_moptions 0 0K 0
in6_mfilter 0 0K 0
frag6 0 0K 0
tcplog 0 0K 0
LRO 0 0K 0
sctp_mcore 0 0K 0
sctp_socko 0 0K 0
sctp_iter 0 0K 8
sctp_mvrf 0 0K 0
sctp_cpal 0 0K 0
sctp_cmsg 0 0K 0
sctp_stre 0 0K 0
sctp_athi 0 0K 0
sctp_a_it 0 0K 8
sctp_aadr 0 0K 0
sctp_stri 0 0K 0
newreno data 0 0K 0
ip_msource 0 0K 0
ip_moptions 0 0K 0
in_mfilter 0 0K 0
ipid 0 0K 0
80211scan 0 0K 0
80211ratectl 0 0K 0
80211power 0 0K 0
80211nodeie 0 0K 0
80211node 0 0K 0
80211mesh_gt 0 0K 0
80211mesh_rt 0 0K 0
80211perr 0 0K 0
80211prep 0 0K 0
80211preq 0 0K 0
80211dfs 0 0K 0
80211crypto 0 0K 0
80211vap 0 0K 0
iflib 0 0K 0
vlan 0 0K 0
gif 0 0K 0
ifdescr 0 0K 0
zlib 0 0K 0
fadvise 0 0K 0
mpr 0 0K 0
statfs 0 0K 228
export_host 0 0K 0
cl_savebuf 0 0K 2
biobuf 0 0K 0
aios 0 0K 0
lio 0 0K 0
acl 0 0K 0
mfibuf 0 0K 0
mbuf_tag 0 0K 109
accf 0 0K 0
pts 0 0K 0
iov 0 0K 13371
ioctlops 0 0K 99
Witness 0 0K 0
stack 0 0K 0
md_sectors 0 0K 0
sbuf 0 0K 288
md_disk 0 0K 0
compressor 0 0K 0
malodev 0 0K 0
SWAP 0 0K 0
LED 0 0K 0
sysctltmp 0 0K 578
sysctl 0 0K 1
ekcd 0 0K 0
dumper 0 0K 0
rctl 0 0K 0
ix_sriov 0 0K 0
aacraidcam 0 0K 0
ix 0 0K 0
ipsbuf 0 0K 0
iirbuf 0 0K 0
cache 0 0K 0
aacraid_buf 0 0K 0
kcovinfo 0 0K 0
db> show ktr
No such command; use "help" to list available commands
db>

Mark Johnston

unread,
Sep 7, 2021, 5:35:02 PM9/7/21
to syzbot, syzkaller-f...@googlegroups.com
#syz dup: panic: mtx_lock() of spin mutex (null) @ /syzkaller/managers/main/kernel/sys/netinet/tcp_output.c:LINE
Reply all
Reply to author
Forward
0 new messages