Fatal trap 12: page fault in vm_page_unhold_pages

9 views
Skip to first unread message

syzbot

unread,
Mar 19, 2019, 9:08:05 PM3/19/19
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 90d8cba8 Fix two typos: an -> and; the the -> the
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=15c0866d200000
dashboard link: https://syzkaller.appspot.com/bug?extid=21811cc0a89b2a87a9e7

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+21811c...@syzkaller.appspotmail.com

Fatal trap 12: page fault while in kernel mode
cpuid = 1; apic id = 01
fault virtual address = 0x30
fault code = supervisor read data , page not present
instruction pointer = 0x20:0xffffffff8156d5fa
stack pointer = 0x28:0xfffffe00213337a0
frame pointer = 0x28:0xfffffe00213337e0
code segment = base 0x0, limit 0xfffff, type 0x1b
= DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags = interrupt enabled, resume, IOPL = 0
current process = 3193 (syz-executor.3)
trap number = 12
panic: page fault
cpuid = 1
time = 256
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe0021333400
vpanic() at vpanic+0x1e0/frame 0xfffffe0021333460
panic() at panic+0x43/frame 0xfffffe00213334c0
trap_fatal() at trap_fatal+0x4c6/frame 0xfffffe0021333540
trap_pfault() at trap_pfault+0x9f/frame 0xfffffe00213335b0
trap() at trap+0x44d/frame 0xfffffe00213336d0
calltrap() at calltrap+0x8/frame 0xfffffe00213336d0
--- trap 0xc, rip = 0xffffffff8156d5fa, rsp = 0xfffffe00213337a0, rbp =
0xfffffe00213337e0 ---
vm_page_unhold_pages() at vm_page_unhold_pages+0x5a/frame 0xfffffe00213337e0
pipe_write() at pipe_write+0x16d8/frame 0xfffffe00213338b0
dofilewrite() at dofilewrite+0xfd/frame 0xfffffe0021333910
kern_writev() at kern_writev+0x66/frame 0xfffffe0021333950
sys_writev() at sys_writev+0x50/frame 0xfffffe0021333980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe0021333ab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe0021333ab0
--- syscall (198, FreeBSD ELF64, nosys), rip = 0x412e5a, rsp =
0x7fffdfffdf38, rbp = 0x3 ---
KDB: enter: panic
[ thread pid 3193 tid 100527 ]
Stopped at kdb_enter+0x6a: movq $0,kdb_why


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#bug-status-tracking for how to communicate with
syzbot.

syzbot

unread,
Mar 20, 2019, 12:37:05 AM3/20/19
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 90d8cba8 Fix two typos: an -> and; the the -> the
git tree: freebsd
console output: https://syzkaller.appspot.com/x/log.txt?x=1423005d200000
dashboard link: https://syzkaller.appspot.com/bug?extid=21811cc0a89b2a87a9e7
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1090866d200000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1290e017200000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+21811c...@syzkaller.appspotmail.com

Fatal trap 12: page fault while in kernel mode
cpuid = 1; apic id = 01
fault virtual address = 0x30
fault code = supervisor read data , page not present
instruction pointer = 0x20:0xffffffff8156d5fa
stack pointer = 0x28:0xfffffe00212317a0
frame pointer = 0x28:0xfffffe00212317e0
code segment = base 0x0, limit 0xfffff, type 0x1b
= DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags = interrupt enabled, resume, IOPL = 0
current process = 759 (syz-executor7892514)
trap number = 12
panic: page fault
cpuid = 1
time = 1553056409
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x47/frame
0xfffffe0021231400
vpanic() at vpanic+0x1e0/frame 0xfffffe0021231460
panic() at panic+0x43/frame 0xfffffe00212314c0
trap_fatal() at trap_fatal+0x4c6/frame 0xfffffe0021231540
trap_pfault() at trap_pfault+0x9f/frame 0xfffffe00212315b0
trap() at trap+0x44d/frame 0xfffffe00212316d0
calltrap() at calltrap+0x8/frame 0xfffffe00212316d0
--- trap 0xc, rip = 0xffffffff8156d5fa, rsp = 0xfffffe00212317a0, rbp =
0xfffffe00212317e0 ---
vm_page_unhold_pages() at vm_page_unhold_pages+0x5a/frame 0xfffffe00212317e0
pipe_write() at pipe_write+0x16d8/frame 0xfffffe00212318b0
dofilewrite() at dofilewrite+0xfd/frame 0xfffffe0021231910
kern_writev() at kern_writev+0x66/frame 0xfffffe0021231950
sys_writev() at sys_writev+0x50/frame 0xfffffe0021231980
amd64_syscall() at amd64_syscall+0x436/frame 0xfffffe0021231ab0
fast_syscall_common() at fast_syscall_common+0x101/frame 0xfffffe0021231ab0
--- syscall (0, FreeBSD ELF64, nosys), rip = 0x4576ca, rsp =
0x7fffdfffdf88, rbp = 0x6b5c08 ---
KDB: enter: panic
[ thread pid 759 tid 100103 ]
Reply all
Reply to author
Forward
0 new messages