panic: cap_rights_is_vset:LINE

9 views
Skip to first unread message

syzbot

unread,
Jun 10, 2019, 1:16:06 PM6/10/19
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 50200ba5 Enhance the comment ieee80211_add_channel() to av..
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=12cde28ea00000
dashboard link: https://syzkaller.appspot.com/bug?extid=ae359438769fda1840f8

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+ae3594...@syzkaller.appspotmail.com

panic: cap_rights_is_vset:243
cpuid = 1
time = 50
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe0020f126c0
vpanic() at vpanic+0x1e0/frame 0xfffffe0020f12720
panic() at panic+0x43/frame 0xfffffe0020f12780
__cap_rights_is_set() at __cap_rights_is_set+0x22d/frame 0xfffffe0020f12810
cap_rights_to_vmprot() at cap_rights_to_vmprot+0x59/frame 0xfffffe0020f12840
fget_mmap() at fget_mmap+0xf3/frame 0xfffffe0020f128b0
kern_mmap() at kern_mmap+0x86c/frame 0xfffffe0020f12950
sys_mmap() at sys_mmap+0x38/frame 0xfffffe0020f12980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe0020f12ab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe0020f12ab0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x4131ba, rsp =
0x7fffdfffdf38, rbp = 0x6 ---
KDB: enter: panic
[ thread pid 57002 tid 100299 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Jun 10, 2019, 1:57:03 PM6/10/19
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 50200ba5 Enhance the comment ieee80211_add_channel() to av..
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=121f2ab6a00000
dashboard link: https://syzkaller.appspot.com/bug?extid=ae359438769fda1840f8
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=16ca372ea00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+ae3594...@syzkaller.appspotmail.com

panic: cap_rights_is_vset:243
cpuid = 0
time = 1560188884
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe001f6db6c0
vpanic() at vpanic+0x1e0/frame 0xfffffe001f6db720
panic() at panic+0x43/frame 0xfffffe001f6db780
__cap_rights_is_set() at __cap_rights_is_set+0x22d/frame 0xfffffe001f6db810
cap_rights_to_vmprot() at cap_rights_to_vmprot+0x2b/frame 0xfffffe001f6db840
fget_mmap() at fget_mmap+0xf3/frame 0xfffffe001f6db8b0
kern_mmap() at kern_mmap+0x86c/frame 0xfffffe001f6db950
sys_mmap() at sys_mmap+0x38/frame 0xfffffe001f6db980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe001f6dbab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe001f6dbab0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x4131ba, rsp =
0x7fffdfffdf38, rbp = 0x6 ---
KDB: enter: panic
[ thread pid 958 tid 100350 ]
Reply all
Reply to author
Forward
0 new messages