panic: mtx_lock() of spin mutex (null) @ /syzkaller/managers/main/kernel/sys/netinet/tcp_output.c:LINE

14 views
Skip to first unread message

syzbot

unread,
Mar 15, 2019, 12:21:06 PM3/15/19
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 84b9791b bridge: Fix panic if the STP root is removed
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=15e4a227200000
dashboard link: https://syzkaller.appspot.com/bug?extid=9fece8a63c0e27273821
userspace arch: amd64

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+9fece8...@syzkaller.appspotmail.com

panic: mtx_lock() of spin mutex (null) @
/syzkaller/managers/main/kernel/sys/netinet/tcp_output.c:337
cpuid = 1
time = 10
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe0021272550
vpanic() at vpanic+0x1e0/frame 0xfffffe00212725b0
panic() at panic+0x43/frame 0xfffffe0021272610
__mtx_lock_flags() at __mtx_lock_flags+0x1fd/frame 0xfffffe0021272670
tcp_output() at tcp_output+0x62a/frame 0xfffffe0021272830
tcp_usr_connect() at tcp_usr_connect+0x25c/frame 0xfffffe0021272880
soconnectat() at soconnectat+0x183/frame 0xfffffe00212728e0
kern_connectat() at kern_connectat+0x1ff/frame 0xfffffe0021272940
sys_connect() at sys_connect+0xd9/frame 0xfffffe0021272980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe0021272ab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe0021272ab0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x412e5a, rsp =
0x7fffdfffdf38, rbp = 0x3 ---
KDB: enter: panic
[ thread pid 7692 tid 100139 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#bug-status-tracking for how to communicate with
syzbot.

syzbot

unread,
Mar 15, 2019, 12:38:05 PM3/15/19
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 84b9791b bridge: Fix panic if the STP root is removed
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=16916acf200000
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1738706d200000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+9fece8...@syzkaller.appspotmail.com

panic: mtx_lock() of spin mutex (null) @
/syzkaller/managers/main/kernel/sys/netinet/tcp_output.c:337
cpuid = 0
time = 1552667603
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe002125e550
vpanic() at vpanic+0x1e0/frame 0xfffffe002125e5b0
panic() at panic+0x43/frame 0xfffffe002125e610
__mtx_lock_flags() at __mtx_lock_flags+0x1fd/frame 0xfffffe002125e670
tcp_output() at tcp_output+0x62a/frame 0xfffffe002125e830
tcp_usr_connect() at tcp_usr_connect+0x25c/frame 0xfffffe002125e880
soconnectat() at soconnectat+0x183/frame 0xfffffe002125e8e0
kern_connectat() at kern_connectat+0x1ff/frame 0xfffffe002125e940
sys_connect() at sys_connect+0xd9/frame 0xfffffe002125e980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe002125eab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe002125eab0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x412e5a, rsp =
0x7fffdfffdf38, rbp = 0x3 ---
KDB: enter: panic
[ thread pid 791 tid 100121 ]
Reply all
Reply to author
Forward
0 new messages