panic: invalid dst page ADDR

7 views
Skip to first unread message

syzbot

unread,
Mar 15, 2019, 6:20:06 PM3/15/19
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 84b9791b bridge: Fix panic if the STP root is removed
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=163eba27200000
dashboard link: https://syzkaller.appspot.com/bug?extid=514d40ce757a3f8b15bc
userspace arch: amd64

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+514d40...@syzkaller.appspotmail.com

panic: invalid dst page 0xfffff8007fb17f98
cpuid = 0
time = 14
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe001fb08750
vpanic() at vpanic+0x1e0/frame 0xfffffe001fb087b0
panic() at panic+0x43/frame 0xfffffe001fb08810
vm_fault_copy_entry() at vm_fault_copy_entry+0x808/frame 0xfffffe001fb088d0
vm_map_protect() at vm_map_protect+0x5f9/frame 0xfffffe001fb08940
sys_mprotect() at sys_mprotect+0xcc/frame 0xfffffe001fb08980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe001fb08ab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe001fb08ab0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x412e5a, rsp =
0x7fffdff79f38, rbp = 0x3 ---
KDB: enter: panic
[ thread pid 18020 tid 101148 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#bug-status-tracking for how to communicate with
syzbot.

syzbot

unread,
Mar 15, 2019, 6:43:05 PM3/15/19
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 84b9791b bridge: Fix panic if the STP root is removed
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=1173ecf7200000
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=16ba5b0b200000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+514d40...@syzkaller.appspotmail.com

panic: invalid dst page 0xfffff8007e638f98
cpuid = 0
time = 1552689540
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe0021277750
vpanic() at vpanic+0x1e0/frame 0xfffffe00212777b0
panic() at panic+0x43/frame 0xfffffe0021277810
vm_fault_copy_entry() at vm_fault_copy_entry+0x808/frame 0xfffffe00212778d0
vm_map_protect() at vm_map_protect+0x5f9/frame 0xfffffe0021277940
sys_mprotect() at sys_mprotect+0xcc/frame 0xfffffe0021277980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe0021277ab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe0021277ab0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x412e5a, rsp =
0x7fffdffdcf38, rbp = 0x3 ---
KDB: enter: panic
[ thread pid 796 tid 100137 ]

syzbot

unread,
Mar 16, 2019, 12:54:05 PM3/16/19
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 4ccae816 Add openmp __kmp_gettid() wrapper, using pthread_..
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=1532fb5f200000
dashboard link: https://syzkaller.appspot.com/bug?extid=514d40ce757a3f8b15bc
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1000c86d200000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=12ae5b0b200000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+514d40...@syzkaller.appspotmail.com

login: panic: invalid dst page 0xfffff8007f14af98
cpuid = 0
time = 1552754985
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe002126d750
vpanic() at vpanic+0x1e0/frame 0xfffffe002126d7b0
panic() at panic+0x43/frame 0xfffffe002126d810
vm_fault_copy_entry() at vm_fault_copy_entry+0x808/frame 0xfffffe002126d8d0
vm_map_protect() at vm_map_protect+0x5f9/frame 0xfffffe002126d940
sys_mprotect() at sys_mprotect+0xcc/frame 0xfffffe002126d980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe002126dab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe002126dab0
--- syscall (0, FreeBSD ELF64, nosys), rip = 0x45781a, rsp =
0x7fffdfffdf88, rbp = 0x6b60c8 ---
KDB: enter: panic
[ thread pid 777 tid 100134 ]
Reply all
Reply to author
Forward
0 new messages