Fatal trap NUM: page fault in rtsock_msg_buffer

3 views
Skip to first unread message

syzbot

unread,
Nov 14, 2024, 10:40:23 PM (9 days ago) Nov 14
to syzkaller-f...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 13e82893d858 ena.4: optimize apropos and hardware
git tree: freebsd-src
console output: https://syzkaller.appspot.com/x/log.txt?x=12b51130580000
dashboard link: https://syzkaller.appspot.com/bug?extid=d4a2682059e23179e76e

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+d4a268...@syzkaller.appspotmail.com

Fatal trap 12: page fault while in kernel mode
cpuid = 1; apic id = 01
fault virtual address = 0x59
fault code = supervisor read data, page not present
instruction pointer = 0x20:0xffffffff8184a287
stack pointer = 0x28:0xfffffe0057057160
frame pointer = 0x28:0xfffffe00570572d0
code segment = base 0x0, limit 0xfffff, type 0x1b
= DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags = interrupt enabled, resume, IOPL = 0
current process = 1079 (syz-executor)
rdi: 0000000000000059 rsi: 0000000000000000 rdx: 000000000ae0ae67
rcx: fffffe00033eee30 r8: 0000000000000000 r9: 0000000000000001


FreeBSD/amd64 (ci-freebsd-main-5.us-central1-b.c.syzkaller.inrax: fffffe00033eee30 rbx: fffffe0057057320 rbp: fffffe00570572d0
r10: 0000000000000000 r11: 00000000000000ff r12: fffffe00570571e0
r13: fffffe0057057480 r14: 0000000000000001 r15: dffff7c000000000
trap number = 12
panic: page fault
cpuid = 1
time = 1731641994
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0xc6/frame 0xfffffe0057056870
kdb_backtrace() at kdb_backtrace+0xd0/frame 0xfffffe00570569d0
vpanic() at vpanic+0x257/frame 0xfffffe0057056b90
panic() at panic+0xb5/frame 0xfffffe0057056c50
trap_fatal() at trap_fatal+0x7ef/frame 0xfffffe0057056d70
trap_pfault() at trap_pfault+0x17b/frame 0xfffffe0057056eb0
trap() at trap+0x64a/frame 0xfffffe0057057090
calltrap() at calltrap+0x8/frame 0xfffffe0057057090
--- trap 0xc, rip = 0xffffffff8184a287, rsp = 0xfffffe0057057160, rbp = 0xfffffe00570572d0 ---
rtsock_msg_buffer() at rtsock_msg_buffer+0x167/frame 0xfffffe00570572d0
update_rtm_from_info() at update_rtm_from_info+0x18b/frame 0xfffffe00570573d0
rts_send() at rts_send+0x60f/frame 0xfffffe0057057770
sosend_generic_locked() at sosend_generic_locked+0xce6/frame 0xfffffe0057057960
sosend_generic() at sosend_generic+0x87/frame 0xfffffe00570579c0
sousrsend() at sousrsend+0x112/frame 0xfffffe0057057a50
kern_sendit() at kern_sendit+0x4fe/frame 0xfffffe0057057bb0
sendit() at sendit+0x15f/frame 0xfffffe0057057c10
sys_sendto() at sys_sendto+0x181/frame 0xfffffe0057057d30
amd64_syscall() at amd64_syscall+0x49b/frame 0xfffffe0057057f30
fast_syscall_common() at fast_syscall_common+0xf8/frame 0xfffffe0057057f30
--- syscall (198, FreeBSD ELF64, __syscall), rip = 0x39d58a, rsp = 0x8270fbf08, rbp = 0x8270fbf80 ---
KDB: enter: panic
[ thread pid 1079 tid 100399 ]
Stopped at kdb_enter+0x6e: movq $0,0x23eb927(%rip)
db> set $lines = 0
db> set $maxwidth = 0
db> show registers
cs 0x20
ds 0x3b
es 0x3b
fs 0x13
gs 0x1b
ss 0x28
rax 0x12
rcx 0xfffffe0070200000
rdx 0x3ffff
rbx 0xffffffff827286e0 .str.27
rsp 0xfffffe00570569b0
rbp 0xfffffe00570569d0
rsi 0x40001
rdi 0xffffffff815d0e09 printf+0x149
r8 0
r9 0xffffffff
r10 0
r11 0x17
r12 0xfffffe005b501740
r13 0xfffffffffffffffd
r14 0xffffffff827286e0 .str.27
r15 0
rip 0xffffffff815ba6ee kdb_enter+0x6e
rflags 0x46
kdb_enter+0x6e: movq $0,0x23eb927(%rip)
db> show proc
Process 1079 (syz-executor) at 0xfffffe005b4eab00:
state: NORMAL
uid: 0 gids: 0, 0, 5
parent: pid 766 at 0xfffffe005b4ca560
ABI: FreeBSD ELF64
flag: 0x10000080 flag2: 0
arguments: ./syz-executor exec
reaper: 0xfffffe0007a07040 reapsubtree: 1
sigparent: 20
vmspace: 0xfffffe005b48d268
(map 0xfffffe005b48d268)
(map.pmap 0xfffffe005b48d328)
(pmap 0xfffffe005b48d398)
threads: 2
100120 RunQ syz-executor
100399 Run CPU 1 syz-executor
db> ps
pid ppid pgrp uid state wmesg wchan cmd
1083 765 765 0 R (threaded) syz-executor
100341 RunQ syz-executor
100402 RunQ syz-executor
1081 767 767 0 R (threaded) syz-executor
100334 RunQ syz-executor
100403 RunQ syz-executor
1079 766 766 0 R (threaded) syz-executor
100120 RunQ syz-executor
100399 Run CPU 1 syz-executor
1025 1 766 0 S uwait 0xfffffe0059843280 syz-executor
1020 1 764 0 T uwait 0xfffffe005847e700 syz-executor
945 1 764 0 S uwait 0xfffffe0058701c00 syz-executor
943 1 764 0 S uwait 0xfffffe0059842980 syz-executor
890 1 890 0 Ss select 0xfffffe0059605d40 rtsol
889 1 889 0 Ss select 0xfffffe0059605dc0 rtsol
888 1 888 0 Ss select 0xfffffe00596060c0 rtsol
882 780 424 0 S kqread 0xfffffe0057fca100 rtsol
824 0 0 0 DL aiordy 0xfffffe005b4cc040 [aiod4]
823 0 0 0 DL aiordy 0xfffffe005b4cc5a0 [aiod3]
822 0 0 0 DL aiordy 0xfffffe005b4ccb00 [aiod2]
821 0 0 0 DL aiordy 0xfffffe0007a25ae0 [aiod1]
780 772 424 0 S wait 0xfffffe005b4cd5c0 sh
772 424 424 0 S wait 0xfffffe005b4a5060 sh
767 763 767 0 R CPU 0 syz-executor
766 763 766 0 R syz-executor
765 763 765 0 R syz-executor
764 763 764 0 S piperd 0xfffffe00599ba8a0 syz-executor
763 761 761 0 R syz-executor
761 759 761 0 Ss pause 0xfffffe0007a260f0 csh
759 682 759 0 Ss select 0xfffffe000797f3c0 sshd
748 1 748 0 Ss+ ttyin 0xfffffe00543ea4b0 getty
747 1 747 0 Ss+ ttyin 0xfffffe00588518b0 getty
746 1 746 0 Ss+ ttyin 0xfffffe0058851cb0 getty
745 1 745 0 Ss+ ttyin 0xfffffe00588520b0 getty
744 1 744 0 Ss+ ttyin 0xfffffe00588524b0 getty
743 1 743 0 Ss+ ttyin 0xfffffe00588528b0 getty
742 1 742 0 Ss+ ttyin 0xfffffe0058852cb0 getty
741 1 741 0 Ss+ ttyin 0xfffffe00588530b0 getty
740 1 740 0 Ss+ ttyin 0xfffffe00588534b0 getty
738 1 18 0 S+ piperd 0xfffffe00599c9420 logger
737 736 18 0 S+ nanslp 0xffffffff839873c0 sleep
736 1 18 0 S+ wait 0xfffffe005b4a2000 sh
686 1 686 0 Ss nanslp 0xffffffff839873c0 cron
682 1 682 0 Ss select 0xfffffe000797ecc0 sshd
495 1 495 0 Ss select 0xfffffe000797eb40 syslogd
424 1 424 0 Ss wait 0xfffffe0007be4040 devd
423 1 423 65 Ss select 0xfffffe000797e9c0 dhclient
338 1 338 0 Ss select 0xfffffe000797f2c0 dhclient
335 1 335 0 Ss select 0xfffffe000797e940 dhclient
17 0 0 0 DL syncer 0xffffffff83aa4be0 [syncer]
16 0 0 0 DL vlruwt 0xfffffe0007a27060 [vnlru]
15 0 0 0 DL (threaded) [bufdaemon]
100079 D psleep 0xffffffff83aa31c0 [bufdaemon]
100082 D - 0xffffffff82e02140 [bufspacedaemon-0]
100093 D sdflush 0xfffffe0059ad78e8 [/ worker]
9 0 0 0 DL psleep 0xffffffff83aee8e0 [vmdaemon]
8 0 0 0 DL (threaded) [pagedaemon]
100077 D psleep 0xffffffff83ad4878 [dom0]
100080 D launds 0xffffffff83ad4884 [laundry: dom0]
100081 D umarcl 0xffffffff81d6bbe0 [uma]
7 0 0 0 RL [rand_harvestq]
6 0 0 0 DL pftm 0xffffffff841d7d50 [pf purge]
5 0 0 0 DL waiting 0xffffffff846ba580 [sctp_iterator]
4 0 0 0 DL (threaded) [cam]
100045 D - 0xffffffff836cf340 [doneq0]
100046 D - 0xffffffff836cf2c0 [async]
100075 D - 0xffffffff836cf140 [scanner]
3 0 0 0 DL (threaded) [crypto]
100042 D crypto_ 0xffffffff83ad0060 [crypto]
100043 D crypto_ 0xfffffe0057f2ae30 [crypto returns 0]
100044 D crypto_ 0xfffffe0057f2ae80 [crypto returns 1]
14 0 0 0 DL seqstat 0xfffffe00085fd488 [sequencer 00]
13 0 0 0 DL (threaded) [geom]
100036 D - 0xffffffff8392fd80 [g_event]
100037 D - 0xffffffff8392fda0 [g_up]
100038 D - 0xffffffff8392fdc0 [g_down]
2 0 0 0 WL (threaded) [clock]
100030 I [clock (0)]
100031 I [clock (1)]
12 0 0 0 WL (threaded) [intr]
100012 I [swi6: task queue]
100013 I [swi6: Giant taskq]
100015 I [swi5: fast taskq]
100032 I [swi1: netisr 0]
100033 I [swi1: hpts]
100034 I [swi1: hpts]
100047 I [irq24: virtio_pci0]
100048 I [irq25: virtio_pci0]
100049 I [irq26: virtio_pci0]
100050 I [irq27: virtio_pci0]
100051 I [irq28: virtio_pci1]
100052 I [irq29: virtio_pci1]
100053 I [irq30: virtio_pci1]
100054 I [irq31: virtio_pci1]
100055 I [irq32: virtio_pci1]
100060 I [irq10: virtio_pci2]
100062 I [irq1: atkbd0]
100063 I [irq12: psm0]
100064 I [swi0: uart uart++]
100068 I [swi1: pf send]
11 0 0 0 RL (threaded) [idle]
100003 CanRun [idle: cpu0]
100004 CanRun [idle: cpu1]
1 0 1 0 SLs wait 0xfffffe0007a07040 [init]
10 0 0 0 DL audit_w 0xffffffff83ad0ac0 [audit]
0 0 0 0 DLs (threaded) [kernel]
100000 D parked 0xffffffff849f6ff0 [swapper]
100005 D - 0xfffffe00079d2700 [softirq_0]
100006 D - 0xfffffe00079d2600 [softirq_1]
100007 D - 0xfffffe00079d2500 [if_io_tqg_0]
100008 D - 0xfffffe00079d2400 [if_io_tqg_1]
100009 D - 0xfffffe00079d2300 [if_config_tqg_0]
100010 D - 0xfffffe00079d2200 [pci_hp taskq]
100011 D - 0xfffffe00079d2100 [kqueue_ctx taskq]
100014 D - 0xfffffe00079d1b00 [thread taskq]
100016 D - 0xfffffe00079d1800 [aiod_kick taskq]
100017 D - 0xfffffe00079d1700 [deferred_unmount ta]
100018 D - 0xfffffe00079d1600 [inm_free taskq]
100019 D - 0xfffffe00079d1500 [in6m_free taskq]
100020 D - 0xfffffe00079d1400 [linuxkpi_irq_wq]
100021 D - 0xfffffe00079d1300 [linuxkpi_short_wq_0]
100022 D - 0xfffffe00079d1300 [linuxkpi_short_wq_1]
100023 D - 0xfffffe00079d1300 [linuxkpi_short_wq_2]
100024 D - 0xfffffe00079d1300 [linuxkpi_short_wq_3]
100025 D - 0xfffffe00079d1200 [linuxkpi_long_wq_0]
100026 D - 0xfffffe00079d1200 [linuxkpi_long_wq_1]
100027 D - 0xfffffe00079d1200 [linuxkpi_long_wq_2]
100028 D - 0xfffffe00079d1200 [linuxkpi_long_wq_3]
100035 D - 0xfffffe00079d0c00 [firmware taskq]
100040 D - 0xfffffe00079d0200 [crypto_0]
100041 D - 0xfffffe00079d0200 [crypto_1]
100056 D - 0xfffffe0057fcc400 [vtnet0 rxq 0]
100057 D - 0xfffffe0057fcc300 [vtnet0 txq 0]
100058 D - 0xfffffe0057fcc200 [vtnet0 rxq 1]
100059 D - 0xfffffe0057fcc100 [vtnet0 txq 1]
100061 D vtbslp 0xfffffe000797ff00 [virtio_balloon]
100065 D - 0xffffffff8272d920 [deadlkres]
100069 D - 0xfffffe0057fcd200 [acpi_task_0]
100070 D - 0xfffffe0057fcd200 [acpi_task_1]
100071 D - 0xfffffe0057fcd200 [acpi_task_2]
100073 D - 0xfffffe00079d4100 [mca taskq]
100074 D - 0xfffffe0057fcd000 [CAM taskq]
100076 D - 0xfffffe0057fcb600 [ipsec_offload]
db> show all locks
Process 1079 (syz-executor) thread 0xfffffe005b501740 (100399)
exclusive sx so_snd_sx (so_snd_sx) r = 0 (0xfffffe0059d01580) locked @ /syzkaller/managers/main/kernel/sys/kern/uipc_socket.c:4815
Process 767 (syz-executor) thread 0xfffffe005b4d0000 (100109)
exclusive lockmgr bufwait (bufwait) r = 0 (0xfffffe0007ef7c70) locked @ /syzkaller/managers/main/kernel/sys/kern/vfs_bio.c:4013
exclusive lockmgr ufs (ufs) r = 0 (0xfffffe006e50f070) locked @ /syzkaller/managers/main/kernel/sys/kern/kern_ktrace.c:1375
exclusive sx ktrace_sx (ktrace_sx) r = 0 (0xffffffff83933d60) locked @ /syzkaller/managers/main/kernel/sys/kern/kern_ktrace.c:423
db> show malloc
Type InUse MemUse Requests
pf_hash 6 12804K 6
linker 375 5011K 501
tcp_hpts 7 4801K 7
devbuf 4188 4324K 4213
sysctloid 35218 2075K 35293
vtbuf 24 1968K 46
kobj 330 1320K 494
newblk 413 1127K 1489
vfscache 3 1025K 3
pcb 36 678K 126
inodedep 46 529K 423
ufs_quota 1 512K 1
vfs_hash 1 512K 1
callout 2 512K 2
intr 4 472K 4
subproc 150 278K 1174
vnet_data 2 224K 2
acpitask 1 224K 1
KTRACE 101 201K 1341
filedesc 24 185K 507
acpica 1674 184K 57800
vmem 5 144K 7
tidhash 3 141K 3
pagedep 19 133K 261
tfo_ccache 1 128K 1
IP reass 1 128K 1
DEVFS1 109 109K 126
sem 4 106K 4
gtaskqueue 18 98K 18
bus 994 81K 5040
mtx_pool 3 74K 3
syncache 1 68K 1
NFSD srvcache 3 68K 3
module 519 65K 519
ddb_capture 1 64K 1
umtx 320 40K 320
temp 36 39K 1846
kdtrace 200 39K 1488
hostcache 1 32K 1
shm 1 32K 2
DEVFS3 128 32K 138
msg 4 30K 4
kbdmux 6 28K 6
DEVFS_RULE 56 20K 56
ifaddr 66 19K 68
BPF 14 19K 27
ufs_mount 4 17K 5
proc 3 17K 3
LRO 16 17K 16
tty 16 16K 16
routetbl 124 16K 395
ithread 90 15K 90
bus-sc 34 15K 1637
eventhandler 163 14K 163
lltable 43 14K 43
ifnet 7 13K 7
ether_multi 152 13K 167
kenv 95 12K 95
GEOM 61 11K 477
CAM queue 5 11K 1528
rman 82 10K 437
shmfd 4 10K 5
in6_multi 65 9K 65
bmsafemap 2 9K 366
plimit 22 9K 318
rpc 4 9K 4
devstat 4 9K 4
UART 12 9K 12
ksem 1 8K 2
pfs_vncache 1 8K 1
dirrem 30 8K 363
audit_evclass 238 8K 300
taskqueue 66 7K 75
sglist 6 7K 6
kqueue 63 7K 1121
cred 24 6K 190
CAM DEV 3 6K 510
pfs_nodes 22 6K 22
ufs_dirhash 24 5K 24
UMA 269 5K 269
freework 18 5K 475
pf_ifnet 10 5K 19
tcp_fsb_rack 2 5K 6
freefile 33 5K 311
vt 11 5K 11
memdesc 1 4K 1
MCA 32 4K 32
evdev 4 4K 4
DEVFSP 62 4K 80
pwddesc 61 4K 1090
acpisem 28 4K 28
kcovinfo 52 4K 52
session 23 3K 34
proc-args 89 3K 2119
terminal 11 3K 11
freefrag 20 3K 55
hhook 8 3K 10
sctp_atcl 6 3K 42
clone 9 3K 9
uidinfo 3 3K 9
sctp_stro 2 2K 9
local_apic 1 2K 1
io_apic 1 2K 1
mkdir 16 2K 482
ipsec-saq 2 2K 2
selfd 32 2K 16034
newdirblk 15 2K 241
ip6ndp 12 2K 13
lockf 17 2K 30
sctp_timw 7 2K 7
Unitno 30 2K 54
sctp_ifa 13 2K 14
diradd 13 2K 377
CAM XPT 22 2K 543
CC Mem 6 2K 48
in_multi 6 2K 9
tun 4 2K 4
select 12 2K 40
toponodes 6 2K 6
netlink 3 2K 31
ipsecpolicy 2 2K 2
freeblks 5 2K 277
acpidev 20 2K 20
msi 9 2K 9
softdep 1 1K 1
sahead 1 1K 1
secasvar 1 1K 1
nhops 6 1K 8
vnodemarker 2 1K 10
NFSD session 1 1K 1
CAM periph 4 1K 271
sctp_ifn 6 1K 14
ipsec 3 1K 3
mld 6 1K 6
igmp 6 1K 6
pfil 6 1K 6
isadev 6 1K 6
mount 16 1K 139
pci_link 10 1K 10
crypto 4 1K 10
encap_export_host 12 1K 12
indirdep 2 1K 225
inpcbpolicy 16 1K 248
procdesc 4 1K 10
cdev 2 1K 2
osd 11 1K 61
lkpikmalloc 8 1K 9
chacha20random 1 1K 1
biobuf 1 1K 1
sctp_atky 8 1K 52
cryptodev 4 1K 52
tcp_pcm_rack 1 1K 3
vnodes 1 1K 1
NFSD lckfile 1 1K 1
NFSD V4client 1 1K 1
DEVFS 9 1K 10
CAM SIM 2 1K 2
feeder 7 1K 7
frag6 2 1K 2
tcpfunc 3 1K 3
loginclass 3 1K 5
prison 6 1K 6
nexusdev 8 1K 8
apmdev 1 1K 1
atkbddev 2 1K 2
aio 4 1K 4
iov 2 1K 14717
pmchooks 1 1K 1
CAM path 4 1K 1034
CAM dev queue 2 1K 2
CAM I/O Scheduler 1 1K 1
soname 4 1K 3393
filecaps 4 1K 78
sctp_athm 6 1K 43
sctp_vrf 1 1K 1
sctp_map 4 1K 18
vnet 1 1K 1
pmc 1 1K 1
entropy 2 1K 33
acpiintr 1 1K 1
cpus 2 1K 2
vnet_data_free 1 1K 1
Per-cpu 1 1K 1
p1003.1b 1 1K 1
sctp_mcore 0 0K 0
sctp_socko 0 0K 10
sctp_iter 0 0K 11
sctp_mvrf 0 0K 0
sctp_cpal 0 0K 0
sctp_cmsg 0 0K 0
sctp_stre 0 0K 0
sctp_athi 0 0K 0
sctp_a_it 0 0K 11
sctp_aadr 0 0K 0
sctp_stri 0 0K 2
ipcomp 0 0K 0
esp 0 0K 0
ah 0 0K 0
mqdata 0 0K 0
filemon 0 0K 1
tcp_do_rack 0 0K 0
pf_table 0 0K 0
pf_rule 0 0K 0
pf_altq 0 0K 0
pf_osfp 0 0K 0
pf_krule_item 0 0K 0
pf_temp 0 0K 0
madt_table 0 0K 2
smartpqi 0 0K 0
ixl 0 0K 0
ice-resmgr 0 0K 0
ice-osdep 0 0K 0
ice 0 0K 0
iavf 0 0K 0
axgbe 0 0K 0
fpukern_ctx 0 0K 0
xen_intr 0 0K 0
xen_hvm 0 0K 0
legacydrv 0 0K 0
bounce 0 0K 0
busdma 0 0K 0
qpidrv 0 0K 0
dmar_idpgtbl 0 0K 0
dmar_dom 0 0K 0
dmar_ctx 0 0K 0
amdiommu_dom 0 0K 0
amdiommu_ctx 0 0K 0
isci 0 0K 0
iommu_dmamap 0 0K 0
hyperv_socket 0 0K 0
bxe_ilt 0 0K 0
aesni_data 0 0K 0
xenbus 0 0K 0
vm_fictitious 0 0K 0
UMAHash 0 0K 0
vm_pgdata 0 0K 0
jblocks 0 0K 0
savedino 0 0K 319
sentinel 0 0K 0
jfsync 0 0K 0
jtrunc 0 0K 0
sbdep 0 0K 3
jsegdep 0 0K 0
jseg 0 0K 0
jfreefrag 0 0K 0
jfreeblk 0 0K 0
jnewblk 0 0K 0
jmvref 0 0K 0
jremref 0 0K 0
jaddref 0 0K 0
freedep 0 0K 0
allocindir 0 0K 0
allocdirect 0 0K 0
ufs_trim 0 0K 0
mactemp 0 0K 0
audit_trigger 0 0K 0
audit_pipe_presel 0 0K 0
audit_pipeent 0 0K 0
audit_pipe 0 0K 0
audit_evname 0 0K 0
audit_bsm 0 0K 0
audit_gidset 0 0K 0
audit_text 0 0K 0
audit_path 0 0K 0
audit_data 0 0K 0
audit_cred 0 0K 0
ktls_ocf 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5E_TLS_RX 0 0K 0
MLX5EEPROM 0 0K 0
MLX5E_TLS 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EN 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5DUMP 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
MLX5EEPROM 0 0K 0
simple_attr 0 0K 0
seq_file 0 0K 0
lkpiskb 0 0K 0
radix 0 0K 0
idr 0 0K 0
lkpindev 0 0K 0
lkpimhi 0 0K 0
lkpifw 0 0K 0
lkpi80211 0 0K 0
NLM 0 0K 0
ipsec-spdcache 0 0K 0
ipsec-reg 0 0K 0
ipsec-misc 0 0K 0
ipsecrequest 0 0K 0
ip6opt 0 0K 18
ip6_msource 0 0K 0
ip6_moptions 0 0K 0
in6_mfilter 0 0K 0
tcplog 0 0K 0
tcp_hwpace 0 0K 0
ip_msource 0 0K 1
ip_moptions 0 0K 3
in_mfilter 0 0K 2
ipid 0 0K 0
80211scan 0 0K 0
80211ratectl 0 0K 0
80211power 0 0K 0
80211nodeie 0 0K 0
80211node 0 0K 0
80211mesh_gt 0 0K 0
80211mesh_rt 0 0K 0
80211perr 0 0K 0
80211prep 0 0K 0
80211preq 0 0K 0
80211dfs 0 0K 0
80211crypto 0 0K 0
80211vap 0 0K 0
iflib 0 0K 0
vlan 0 0K 0
gif 0 0K 0
ifdescr 0 0K 0
zlib 0 0K 19
fadvise 0 0K 0
VN POLL 0 0K 2
statfs 0 0K 188
namei_tracker 0 0K 0
export_host 0 0K 0
cl_savebuf 0 0K 20
lio 0 0K 2
acl 0 0K 0
mbuf_tag 0 0K 0
ktls 0 0K 0
accf 0 0K 0
pts 0 0K 0
timerfd 0 0K 0
ioctlops 0 0K 108
eventfd 0 0K 0
Witness 0 0K 0
stack 0 0K 0
sbuf 0 0K 288
firmware 0 0K 0
compressor 0 0K 0
SWAP 0 0K 0
sysctltmp 0 0K 635
sysctl 0 0K 3
ekcd 0 0K 0
dumper 0 0K 0
sendfile 0 0K 0
rctl 0 0K 0
cache 0 0K 0
prison_racct 0 0K 0
Fail Points 0 0K 0
sigio 0 0K 2
filedesc_to_leader 0 0K 0
pwd 0 0K 0
tty console 0 0K 0
boottrace 0 0K 0
isofs_node 0 0K 0
isofs_mount 0 0K 0
tr_raid5_data 0 0K 0
tr_raid1e_data 0 0K 0
tr_raid1_data 0 0K 0
tr_raid0_data 0 0K 0
tr_concat_data 0 0K 0
md_sii_data 0 0K 0
md_promise_data 0 0K 0
md_nvidia_data 0 0K 0
md_jmicron_data 0 0K 0
md_intel_data 0 0K 0
md_ddf_data 0 0K 0
raid_data 0 0K 72
geom_flashmap 0 0K 0
tmpfs dir 0 0K 0
tmpfs name 0 0K 0
tmpfs mount 0 0K 0
tmpfs extattr 0 0K 0
NFS FHA 0 0K 0
newnfsmnt 0 0K 0
newnfsclient_req 0 0K 0
NFSCL layrecall 0 0K 0
NFSCL session 0 0K 0
NFSCL sockreq 0 0K 0
NFSCL devinfo 0 0K 0
NFSCL flayout 0 0K 0
NFSCL layout 0 0K 0
NFSD rollback 0 0K 0
NFSCL diroff 0 0K 0
NEWNFSnode 0 0K 0
NFSCL lck 0 0K 0
NFSCL lckown 0 0K 0
NFSCL client 0 0K 0
NFSCL deleg 0 0K 0
NFSCL open 0 0K 0
NFSCL owner 0 0K 0
NFS fh 0 0K 0
NFS req 0 0K 0
NFSD usrgroup 0 0K 0
NFSD string 0 0K 0
NFSD V4lock 0 0K 0
NFSD V4state 0 0K 0
msdosfs_fat 0 0K 0
msdosfs_mount 0 0K 0
msdosfs_node 0 0K 0
DEVFS4 0 0K 0
DEVFS2 0 0K 0
gntdev 0 0K 0
privcmd_dev 0 0K 0
evtchn_dev 0 0K 0
xenstore 0 0K 0
xnb 0 0K 0
xen_acpi 0 0K 0
xbbd 0 0K 0
xbd 0 0K 0
Balloon 0 0K 0
sysmouse 0 0K 0
vtfont 0 0K 0
pvscsi 0 0K 0
USBdev 0 0K 0
USB 0 0K 0
twsbuf 0 0K 0
tcp_log_dev 0 0K 3
midi buffers 0 0K 0
mixer 0 0K 0
ac97 0 0K 0
hdacc 0 0K 0
hdac 0 0K 0
hdaa 0 0K 0
SIIS driver 0 0K 0
PUC 0 0K 0
ppbusdev 0 0K 0
sr_iov 0 0K 0
OCS 0 0K 0
OCS 0 0K 0
nvme 0 0K 0
nvd 0 0K 0
netmap 0 0K 0
mwldev 0 0K 0
MVS driver 0 0K 0
mrsasbuf 0 0K 0
mpt_user 0 0K 0
mps_user 0 0K 0
MPSSAS 0 0K 0
mps 0 0K 0
mpr_user 0 0K 0
MPRSAS 0 0K 0
mpr 0 0K 0
mfibuf 0 0K 0
md_sectors 0 0K 0
md_disk 0 0K 1
malodev 0 0K 0
LED 0 0K 0
ix_sriov 0 0K 0
ix 0 0K 0
ipsbuf 0 0K 0
ciss_data 0 0K 0
BACKLIGHT 0 0K 0
ath_hal 0 0K 0
athdev 0 0K 0
ata_pci 0 0K 0
ata_dma 0 0K 0
ata_generic 0 0K 0
AHCI driver 0 0K 0
agp 0 0K 0
acpipwr 0 0K 0
acpi_perf 0 0K 0
acpicmbat 0 0K 0
aacraidcam 0 0K 0
aacraid_buf 0 0K 0
aaccam 0 0K 0
aacbuf 0 0K 0
zstd 0 0K 0
XZ_DEC 0 0K 0
nvlist 0 0K 0
SCSI ENC 0 0K 0
SCSI sa 0 0K 0
scsi_pass 0 0K 0
scsi_da 0 0K 69
ata_da 0 0K 0
scsi_ch 0 0K 0
scsi_cd 0 0K 0
nvme_da 0 0K 0
CAM CCB 0 0K 523
CAM ccb queue 0 0K 0
db> show uma
Zone Size Used Free Requests Sleeps Bucket Total Mem XFree
mbuf_jumbo_page 4096 8321 1077 12950 0 254 38494208 0
mbuf 256 8624 1038 21074 0 254 2473472 0
malloc-4096 4096 410 6 2091 0 2 1703936 0
BUF TRIE 144 212 11604 1302 0 62 1701504 0
malloc-384 384 4226 34 4226 0 30 1635840 0
mbuf_cluster 2048 508 254 509 0 254 1560576 0
malloc-128 128 11531 187 11545 0 126 1499904 0
UMA Slabs 0 112 11043 3 11043 0 126 1237152 0
sctp_asoc 2256 2 508 9 0 254 1150560 0
vmem btag 56 16337 46 16337 0 254 917448 0
RADIX NODE 144 5517 274 32224 0 62 833904 0
malloc-65536 65536 9 1 12 0 1 655360 0
FFS inode 1168 526 34 837 0 8 654080 0
sctp_ep 1152 4 507 32 0 254 588672 0
pbuf 2624 0 202 0 0 2 530048 0
socket 1024 35 473 1501 0 254 520192 0
lkpicurr 168 2 3094 2 0 62 520128 0
malloc-65536 65536 6 0 6 0 1 393216 0
sctp_raddr 736 3 514 10 0 254 380512 0
VM OBJECT 264 1191 69 16234 0 30 332640 0
256 Bucket 2048 141 11 1019 0 8 311296 0
malloc-16384 16384 13 5 433 0 1 294912 0
VNODE 440 564 102 877 0 30 293040 0
THREAD 1824 138 22 403 0 8 291840 0
malloc-32768 32768 2 6 192 0 1 262144 0
malloc-64 64 3862 233 3889 0 254 262080 0
malloc-2048 2048 107 13 318 0 8 245760 0
malloc-16 16 14520 230 14635 0 254 236000 0
DEVCTL 1024 22 198 147 0 0 225280 0
tcp_log 416 0 513 22 0 254 213408 0
UMA Zones 768 241 3 241 0 16 187392 0
malloc-32 32 5337 333 5401 0 254 181440 0
malloc-128 128 1163 232 30615 0 126 178560 0
malloc-256 256 522 168 1961 0 62 176640 0
lkpimm 56 1 3095 1 0 254 173376 0
MAP ENTRY 96 1418 346 50724 0 126 169344 0
unpcb 320 14 502 1191 0 254 165120 0
malloc-32768 32768 3 2 123 0 1 163840 0
FFS2 dinode 256 526 104 837 0 62 161280 0
FPU_save_area 832 140 40 625 0 16 149760 0
S VFS Cache 104 997 407 1315 0 126 146016 0
malloc-65536 65536 0 2 110 0 1 131072 0
malloc-65536 65536 0 2 70 0 1 131072 0
malloc-2048 2048 13 51 548 0 8 131072 0
malloc-1024 1024 109 19 126 0 16 131072 0
mbuf_packet 256 39 469 1848 0 254 130048 0
PROC 1376 60 28 1083 0 8 121088 0
ksiginfo 112 59 985 85 0 126 116928 0
malloc-128 128 683 216 1148 0 126 115072 0
malloc-32768 32768 2 1 13 0 1 98304 0
malloc-8192 8192 10 2 118 0 1 98304 0
UMA Kegs 384 227 6 227 0 30 89472 0
g_bio 408 0 210 8424 0 30 85680 0
malloc-64 64 159 1164 16249 0 254 84672 0
malloc-128 128 353 298 1179 0 126 83328 0
filedesc0 1072 61 16 1090 0 8 82544 0
malloc-256 256 149 166 1851 0 62 80640 0
sctp_chunk 152 2 518 3 0 254 79040 0
malloc-384 384 87 93 528 0 30 69120 0
128 Bucket 1024 58 9 261 0 16 68608 0
malloc-64 64 580 491 17343 0 254 68544 0
tcp_bbr_map 128 0 527 291 0 126 67456 0
malloc-128 128 316 211 631 0 126 67456 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-256 256 136 119 149 0 62 65280 0
32 Bucket 256 77 178 1888 0 62 65280 0
malloc-8192 8192 7 0 8 0 1 57344 0
malloc-4096 4096 10 4 15 0 2 57344 0
64 Bucket 512 84 20 1733 0 30 53248 0
ertt_txseginfo 40 0 1313 3065 0 254 52520 0
malloc-64 64 143 676 2847 0 254 52416 0
malloc-64 64 479 340 950 0 254 52416 0
malloc-256 256 118 77 1263 0 62 49920 0
malloc-256 256 163 32 1284 0 62 49920 0
DIRHASH 1024 35 13 35 0 16 49152 0
NAMEI 1024 0 48 14003 0 16 49152 0
malloc-16384 16384 3 0 3 0 1 49152 0
malloc-2048 2048 5 19 545 0 8 49152 0
malloc-2048 2048 9 15 88 0 8 49152 0
malloc-1024 1024 9 39 720 0 16 49152 0
malloc-1024 1024 34 14 65 0 16 49152 0
syncache 168 0 264 3 0 254 44352 0
tcp_inpcb 1320 6 27 48 0 8 43560 0
pcpu-8 8 4705 415 4896 0 254 40960 0
VMSPACE 616 40 26 1062 0 16 40656 0
pipe 736 19 36 325 0 16 40480 0
sctp_readq 152 0 260 1 0 254 39520 0
da_ccb 544 0 70 2222 0 16 38080 0
udp_inpcb 416 6 84 175 0 30 37440 0
hostcache 64 3 564 3 0 254 36288 0
malloc-64 64 241 326 276 0 254 36288 0
malloc-64 64 230 337 261 0 254 36288 0
malloc-64 64 7 560 28 0 254 36288 0
tcp_rack_map 128 2 277 519 0 126 35712 0
malloc-128 128 136 143 636 0 126 35712 0
malloc-128 128 114 165 705 0 126 35712 0
malloc-128 128 63 216 79 0 126 35712 0
routing nhops 256 26 109 33 0 62 34560 0
ttyoutq 256 72 63 160 0 62 34560 0
malloc-384 384 75 15 714 0 30 34560 0
malloc-256 256 15 120 58 0 62 34560 0
malloc-256 256 23 112 28 0 62 34560 0
malloc-256 256 9 126 342 0 62 34560 0
malloc-32768 32768 0 1 1 0 1 32768 0
malloc-8192 8192 4 0 4 0 1 32768 0
malloc-4096 4096 5 3 90 0 2 32768 0
malloc-4096 4096 4 4 195 0 2 32768 0
malloc-2048 2048 7 9 7 0 8 32768 0
malloc-2048 2048 5 11 73 0 8 32768 0
malloc-1024 1024 5 27 9 0 16 32768 0
malloc-1024 1024 9 23 10 0 16 32768 0
malloc-1024 1024 3 29 23 0 16 32768 0
malloc-1024 1024 9 23 991 0 16 32768 0
malloc-512 512 10 54 18 0 30 32768 0
malloc-512 512 3 61 166 0 30 32768 0
malloc-512 512 2 62 31 0 30 32768 0
malloc-512 512 3 61 8 0 30 32768 0
malloc-512 512 0 64 16 0 30 32768 0
pcpu-64 64 494 18 494 0 254 32768 0
tcp_bbr_pcb 896 0 36 3 0 16 32256 0
ttyinq 160 135 65 300 0 62 32000 0
PGRP 120 27 237 38 0 126 31680 0
sctp_laddr 48 4 584 29 0 254 28224 0
rl_entry 48 10 578 10 0 254 28224 0
malloc-32 32 420 462 569 0 254 28224 0
16 Bucket 144 64 132 324 0 62 28224 0
4 Bucket 48 6 582 7 0 254 28224 0
AIO 208 0 133 9 0 62 27664 0
udplite_inpcb 416 0 63 3 0 30 26208 0
TURNSTILE 136 161 28 161 0 62 25704 0
cpuset 200 7 121 7 0 62 25600 0
malloc-8192 8192 2 1 4 0 1 24576 0
PWD 40 20 586 312 0 254 24240 0
rtentry 168 29 115 33 0 62 24192 0
Files 80 193 107 7531 0 126 24000 0
8 Bucket 80 57 243 366 0 126 24000 0
itimer 352 0 66 23 0 30 23232 0
ripcb 384 4 56 22 0 30 23040 0
malloc-384 384 25 35 37 0 30 23040 0
malloc-384 384 1 59 4 0 30 23040 0
Mountpoints 2816 2 6 3 0 4 22528 0
SLEEPQUEUE 88 161 95 161 0 126 22528 0
clpbuf 2624 0 8 36 0 4 20992 0
udp_inpcb ports 32 3 627 31 0 254 20160 0
tcp_inpcb ports 32 3 627 24 0 254 20160 0
ertt 72 6 274 48 0 126 20160 0
malloc-32 32 101 529 346 0 254 20160 0
malloc-32 32 90 540 903 0 254 20160 0
malloc-32 32 46 584 72 0 254 20160 0
malloc-32 32 68 562 859 0 254 20160 0
malloc-32 32 32 598 2738 0 254 20160 0
malloc-32 32 25 605 1100 0 254 20160 0
2 Bucket 32 61 569 399 0 254 20160 0
KNOTE 160 3 122 28 0 62 20000 0
AIOCB 552 0 35 9 0 16 19320 0
L VFS Cache 320 0 60 15 0 30 19200 0
vmem 1856 2 7 2 0 8 16704 0
epoch_record pcpu 256 4 60 4 0 62 16384 0
malloc-16384 16384 1 0 2 0 1 16384 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-8192 8192 0 2 19 0 1 16384 0
malloc-4096 4096 1 3 41 0 2 16384 0
malloc-4096 4096 1 3 2 0 2 16384 0
malloc-2048 2048 1 7 1 0 8 16384 0
malloc-2048 2048 2 6 2 0 8 16384 0
malloc-512 512 4 28 8 0 30 16384 0
malloc-512 512 0 32 15 0 30 16384 0
SMR CPU 32 8 503 8 0 254 16352 0
tcp_rack_pcb 1152 1 13 3 0 8 16128 0
malloc-16 16 319 681 527 0 254 16000 0
mqueue 248 1 63 1 0 62 15872 0
tcp_log_id_node 120 0 132 2 0 126 15840 0
kenv 258 17 43 1065 0 30 15480 0
mqnode 416 4 32 4 0 30 14976 0
SMR SHARED 24 8 503 8 0 254 12264 0
tcp_log_id_bucket 176 0 69 1 0 62 12144 0
malloc-16 16 25 725 139 0 254 12000 0
malloc-16 16 29 721 84 0 254 12000 0
malloc-16 16 33 717 59 0 254 12000 0
malloc-16 16 223 527 4491 0 254 12000 0
malloc-16 16 14 736 27162 0 254 12000 0
malloc-16 16 35 715 109 0 254 12000 0
malloc-384 384 6 24 6 0 30 11520 0
malloc-384 384 1 29 69 0 30 11520 0
AIOLIO 272 0 42 2 0 30 11424 0
malloc-8192 8192 1 0 1 0 1 8192 0
malloc-8192 8192 1 0 1 0 1 8192 0
malloc-4096 4096 1 1 6 0 2 8192 0
malloc-4096 4096 0 2 2 0 2 8192 0
pcpu-16 16 8 504 8 0 254 8192 0
vtnet_tx_hdr 24 0 334 2805 0 254 8016 0
UMA Slabs 1 176 9 13 9 0 62 3872 0
KMAP ENTRY 96 12 27 14 0 0 3744 0
FFS1 dinode 128 0 0 0 0 126 0 0
ada_ccb 272 0 0 0 0 30 0 0
swblk 136 0 0 0 0 62 0 0
swpctrie 144 0 0 0 0 62 0 0
cdg_qdiffsample 16 0 0 0 0 254 0 0
pf state scrubs 40 0 0 0 0 254 0 0
pf frag entries 40 0 0 0 0 254 0 0
pf frags 248 0 0 0 0 62 0 0
pf table entries 160 0 0 0 0 254 0 0
pf table entry counters 64 0 0 0 0 254 0 0
pf UDP mappings 104 0 0 0 0 126 0 0
pf source nodes 152 0 0 0 0 254 0 0
pf state keys 88 0 0 0 0 126 0 0
pf states 368 0 0 0 0 254 0 0
pf tags 104 0 0 0 0 126 0 0
pf mtags 184 0 0 0 0 62 0 0
tfo_ccache_entries 80 0 0 0 0 126 0 0
tfo 4 0 0 0 0 254 0 0
sackhole 32 0 0 0 0 254 0 0
ipq 56 0 0 0 0 254 0 0
sctp_asconf_ack 48 0 0 0 0 254 0 0
sctp_asconf 40 0 0 0 0 254 0 0
sctp_stream_msg_out 112 0 0 0 0 254 0 0
tcpreass 48 0 0 0 0 254 0 0
udplite_inpcb ports 32 0 0 0 0 254 0 0
ripcb ports 32 0 0 0 0 254 0 0
IPsec SA lft_c 16 0 0 0 0 254 0 0
mqnotifier 216 0 0 0 0 62 0 0
mvdata 64 0 0 0 0 254 0 0
TMPFS node 240 0 0 0 0 62 0 0
NCLNODE 608 0 0 0 0 16 0 0
LTS VFS Cache 360 0 0 0 0 30 0 0
STS VFS Cache 144 0 0 0 0 62 0 0
cryptop 280 0 0 0 0 30 0 0
linux_dma_object 32 0 0 0 0 254 0 0
linux_dma_pctrie 144 0 0 0 0 62 0 0
IOMMU_MAP_ENTRY 112 0 0 0 0 126 0 0
mbuf_jumbo_16k 16384 0 0 0 0 254 0 0
mbuf_jumbo_9k 9216 0 0 0 0 254 0 0

---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Nov 18, 2024, 12:22:34 PM (5 days ago) Nov 18
to syzkaller-f...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: f4f46a2eef3b hidraw(4): update hgd_actlen in HIDRAW_GET_RE..
git tree: freebsd-src
console output: https://syzkaller.appspot.com/x/log.txt?x=12a14930580000
dashboard link: https://syzkaller.appspot.com/bug?extid=d4a2682059e23179e76e
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=10436ac0580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=169fbb5f980000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+d4a268...@syzkaller.appspotmail.com

Fatal trap 12: page fault while in kernel mode
cpuid = 0; apic id = 00
fault virtual address = 0x58
fault code = supervisor read data, page not present
instruction pointer = 0x20:0xffffffff8184a1f7
stack pointer = 0x28:0xfffffe0056fc4160
frame pointer = 0x28:0xfffffe0056fc42d0
code segment = base 0x0, limit 0xfffff, type 0x1b
= DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags = interrupt enabled, resume, IOPL = 0
current process = 3824 (syz-executor3868138)
rdi: 0000000000000058 rsi: 0000000000000000 rdx: 000000000adf8867
rcx: fffffe00033eee30 r8: 0000000000000000 r9: 0000000000000001
rax: fffffe00033eee30 rbx: fffffe0056fc4320 rbp: fffffe0056fc42d0

r10: 0000000000000000 r11: 00000000000000ff r12: fffffe0056fc41e0
r13: fffffe0056fc4480 r14: 0000000000000000
FreeBSD/amd64 r15: dffff7c000000000
(ci-freebsd-maitrap number = 12
panic: page fault
cpuid = 0
time = 1731950424
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0xc6/frame 0xfffffe0056fc3870
kdb_backtrace() at kdb_backtrace+0xd0/frame 0xfffffe0056fc39d0
vpanic() at vpanic+0x257/frame 0xfffffe0056fc3b90
panic() at panic+0xb5/frame 0xfffffe0056fc3c50
trap_fatal() at trap_fatal+0x7ef/frame 0xfffffe0056fc3d70
trap_pfault() at trap_pfault+0x17b/frame 0xfffffe0056fc3eb0
trap() at trap+0x64a/frame 0xfffffe0056fc4090
calltrap() at calltrap+0x8/frame 0xfffffe0056fc4090
--- trap 0xc, rip = 0xffffffff8184a1f7, rsp = 0xfffffe0056fc4160, rbp = 0xfffffe0056fc42d0 ---
rtsock_msg_buffer() at rtsock_msg_buffer+0x167/frame 0xfffffe0056fc42d0
update_rtm_from_info() at update_rtm_from_info+0x18b/frame 0xfffffe0056fc43d0
rts_send() at rts_send+0x60f/frame 0xfffffe0056fc4770
sosend_generic_locked() at sosend_generic_locked+0xce6/frame 0xfffffe0056fc4960
sosend_generic() at sosend_generic+0x87/frame 0xfffffe0056fc49c0
sousrsend() at sousrsend+0x112/frame 0xfffffe0056fc4a50
kern_sendit() at kern_sendit+0x4fe/frame 0xfffffe0056fc4bb0
sendit() at sendit+0x15f/frame 0xfffffe0056fc4c10
sys_sendto() at sys_sendto+0x181/frame 0xfffffe0056fc4d30
amd64_syscall() at amd64_syscall+0x49b/frame 0xfffffe0056fc4f30
fast_syscall_common() at fast_syscall_common+0xf8/frame 0xfffffe0056fc4f30
--- syscall (0, FreeBSD ELF64, syscall), rip = 0x23479a, rsp = 0x820d8ff68, rbp = 0x820d8ff80 ---
KDB: enter: panic
[ thread pid 3824 tid 103123 ]
Stopped at kdb_enter+0x6e: movq $0,0x23eb8d7(%rip)
db> set $lines = 0
db> set $maxwidth = 0
db> show registers
cs 0x20
ds 0x3b
es 0x3b
fs 0x13
gs 0x1b
ss 0x28
rax 0x12
rcx 0xfffffe00033eee30
rdx 0xdffff7c000000000
rbx 0xffffffff82728720 .str.27
rsp 0xfffffe0056fc39b0
rbp 0xfffffe0056fc39d0
rsi 0
rdi 0xffffffff82e004c0 panicstr
r8 0
r9 0xffffffff
r10 0
r11 0x17
r12 0xfffffe005bafc740
r13 0xfffffffffffffffe
r14 0xffffffff82728720 .str.27
r15 0
rip 0xffffffff815ba73e kdb_enter+0x6e
rflags 0x46
kdb_enter+0x6e: movq $0,0x23eb8d7(%rip)
db> show proc
Process 3824 (syz-executor3868138) at 0xfffffe005bac7ac0:
state: NORMAL
uid: 0 gids: 0, 0, 5
parent: pid 773 at 0xfffffe0007a085c0
ABI: FreeBSD ELF64
flag: 0x10000080 flag2: 0
arguments: ./syz-executor3868138776
reaper: 0xfffffe0007a07040 reapsubtree: 1
sigparent: 20
vmspace: 0xfffffe0007a0e738
(map 0xfffffe0007a0e738)
(map.pmap 0xfffffe0007a0e7f8)
(pmap 0xfffffe0007a0e868)
threads: 2
100111 S nanslp 0xffffffff839873c1 syz-executor3868138
103123 Run CPU 0 syz-executor3868138
db> ps
pid ppid pgrp uid state wmesg wchan cmd
3824 773 771 0 R (threaded) syz-executor3868138
100111 S nanslp 0xffffffff839873c1 syz-executor3868138
103123 Run CPU 0 syz-executor3868138
773 771 771 0 S nanslp 0xffffffff839873c1 syz-executor3868138
771 769 771 0 Ss pause 0xfffffe005bab9b70 csh
769 682 769 0 Ss select 0xfffffe000797e5c0 sshd
750 1 750 0 Ss+ ttyin 0xfffffe00543ea4b0 getty
749 1 749 0 Ss+ ttyin 0xfffffe00588520b0 getty
748 1 748 0 Ss+ ttyin 0xfffffe00588524b0 getty
747 1 747 0 Ss+ ttyin 0xfffffe00596938b0 getty
746 1 746 0 Ss+ ttyin 0xfffffe00588528b0 getty
745 1 745 0 Ss+ ttyin 0xfffffe0059693cb0 getty
744 1 744 0 Ss+ ttyin 0xfffffe0058852cb0 getty
743 1 743 0 Ss+ ttyin 0xfffffe00588530b0 getty
742 1 742 0 Ss+ ttyin 0xfffffe00588534b0 getty
686 1 686 0 Ss nanslp 0xffffffff839873c0 cron
682 1 682 0 Ss select 0xfffffe000797e540 sshd
495 1 495 0 Ds bo_wwai 0xfffffe006dfffd70 syslogd
424 1 424 0 Ss select 0xfffffe000797e8c0 devd
17 0 0 0 DL syncer 0xffffffff83aa4be0 [syncer]
16 0 0 0 DL vlruwt 0xfffffe0007a26040 [vnlru]
15 0 0 0 DL (threaded) [bufdaemon]
100079 D psleep 0xffffffff83aa31a0 [bufdaemon]
100082 D - 0xffffffff82e02140 [bufspacedaemon-0]
100094 D sdflush 0xfffffe00596934e8 [/ worker]
9 0 0 0 DL psleep 0xffffffff83aee8e0 [vmdaemon]
8 0 0 0 DL (threaded) [pagedaemon]
100077 D psleep 0xffffffff83ad4878 [dom0]
100080 D launds 0xffffffff83ad4884 [laundry: dom0]
100081 D umarcl 0xffffffff81d6bb50 [uma]
7 0 0 0 DL - 0xffffffff83704bb0 [rand_harvestq]
6 0 0 0 DL pftm 0xffffffff841a9d50 [pf purge]
5 0 0 0 DL waiting 0xffffffff84456580 [sctp_iterator]
4 0 0 0 DL (threaded) [cam]
100045 D - 0xffffffff836cf340 [doneq0]
100046 D - 0xffffffff836cf2c0 [async]
100075 D - 0xffffffff836cf140 [scanner]
3 0 0 0 DL (threaded) [crypto]
100042 D crypto_ 0xffffffff83ad0060 [crypto]
100043 D crypto_ 0xfffffe0057f2ae30 [crypto returns 0]
100044 D crypto_ 0xfffffe0057f2ae80 [crypto returns 1]
14 0 0 0 DL seqstat 0xfffffe00085fd488 [sequencer 00]
13 0 0 0 DL (threaded) [geom]
100036 D - 0xffffffff8392fd80 [g_event]
100037 D - 0xffffffff8392fda0 [g_up]
100038 D - 0xffffffff8392fdc0 [g_down]
2 0 0 0 WL (threaded) [clock]
100030 I [clock (0)]
100031 I [clock (1)]
12 0 0 0 RL (threaded) [intr]
100012 I [swi6: task queue]
100013 I [swi6: Giant taskq]
100015 I [swi5: fast taskq]
100032 I [swi1: netisr 0]
100033 I [swi1: hpts]
100034 I [swi1: hpts]
100047 I [irq24: virtio_pci0]
100048 I [irq25: virtio_pci0]
100049 I [irq26: virtio_pci0]
100050 RunQ [irq27: virtio_pci0]
100051 I [irq28: virtio_pci1]
100052 I [irq29: virtio_pci1]
100053 I [irq30: virtio_pci1]
100054 I [irq31: virtio_pci1]
100055 I [irq32: virtio_pci1]
100060 I [irq10: virtio_pci2]
100062 I [irq1: atkbd0]
100063 I [irq12: psm0]
100064 I [swi0: uart uart++]
100068 I [swi1: pf send]
11 0 0 0 RL (threaded) [idle]
100003 CanRun [idle: cpu0]
100004 Run CPU 1 [idle: cpu1]
100065 D - 0xffffffff8272d960 [deadlkres]
100069 D - 0xfffffe0057fcd200 [acpi_task_0]
100070 D - 0xfffffe0057fcd200 [acpi_task_1]
100071 D - 0xfffffe0057fcd200 [acpi_task_2]
100073 D - 0xfffffe00079d4100 [mca taskq]
100074 D - 0xfffffe0057fcd000 [CAM taskq]
100076 D - 0xfffffe00079d0900 [ipsec_offload]
db> show all locks
Process 3824 (syz-executor3868138) thread 0xfffffe005bafc740 (103123)
exclusive sx so_snd_sx (so_snd_sx) r = 0 (0xfffffe006e656580) locked @ /syzkaller/managers/main/kernel/sys/kern/uipc_socket.c:4815
Process 495 (syslogd) thread 0xfffffe005baa1740 (100097)
exclusive lockmgr ufs (ufs) r = 0 (0xfffffe006dfffc78) locked @ /syzkaller/managers/main/kernel/sys/kern/vfs_syscalls.c:3582
db> show malloc
Type InUse MemUse Requests
pf_hash 6 12804K 6
linker 375 5011K 485
tcp_hpts 7 4801K 7
devbuf 4188 4324K 4216
sysctloid 35218 2075K 35293
vtbuf 24 1968K 46
newblk 1594 1423K 1671
kobj 330 1320K 494
vfscache 3 1025K 3
pcb 23 669K 3045
inodedep 16 518K 82
ufs_quota 1 512K 1
vfs_hash 1 512K 1
callout 2 512K 2
intr 4 472K 4
vnet_data 2 224K 2
acpitask 1 224K 1
KTRACE 100 200K 100
acpica 1674 184K 57800
subproc 102 166K 3892
vmem 5 144K 6
tidhash 3 141K 3
pagedep 3 129K 21
tfo_ccache 1 128K 1
IP reass 1 128K 1
sem 4 106K 4
DEVFS1 105 105K 114
gtaskqueue 18 98K 18
bus 994 81K 5040
mtx_pool 3 74K 3
syncache 1 68K 1
NFSD srvcache 3 68K 3
module 519 65K 519
ddb_capture 1 64K 1
temp 19 39K 4638
umtx 288 36K 288
kdtrace 158 33K 6949
hostcache 1 32K 1
shm 1 32K 1
DEVFS3 124 31K 134
msg 4 30K 4
kbdmux 6 28K 6
DEVFS_RULE 56 20K 56
ufs_mount 4 17K 5
proc 3 17K 3
tty 16 16K 16
ithread 90 15K 90
bus-sc 34 15K 1637
eventhandler 163 14K 163
kenv 95 12K 95
ifaddr 30 12K 32
GEOM 61 11K 477
routetbl 50 11K 176
CAM queue 5 11K 1528
rman 82 10K 437
bmsafemap 3 9K 47
rpc 4 9K 4
devstat 4 9K 4
UART 12 9K 12
ksem 1 8K 1
shmfd 1 8K 1
pfs_vncache 1 8K 1
audit_evclass 238 8K 300
taskqueue 66 7K 66
sglist 6 7K 6
CAM DEV 3 6K 510
plimit 15 6K 338
pfs_nodes 22 6K 22
cred 21 6K 284
ufs_dirhash 24 5K 24
UMA 269 5K 269
ifnet 3 5K 3
vt 11 5K 11
memdesc 1 4K 1
MCA 32 4K 32
filedesc 1 4K 1
evdev 4 4K 4
acpisem 28 4K 28
ether_multi 40 4K 50
lltable 11 4K 12
pf_ifnet 5 3K 6
in6_multi 25 3K 25
terminal 11 3K 11
hhook 8 3K 10
clone 9 3K 9
kqueue 35 3K 3827
pwddesc 35 3K 3825
uidinfo 2 3K 9
local_apic 1 2K 1
io_apic 1 2K 1
ipsec-saq 2 2K 2
session 16 2K 32
proc-args 51 2K 4790
Unitno 28 2K 42
CAM XPT 22 2K 543
toponodes 6 2K 6
ipsecpolicy 2 2K 2
lockf 13 2K 27
acpidev 20 2K 20
msi 9 2K 9
netlink 2 2K 28
softdep 1 1K 1
dirrem 4 1K 32
sahead 1 1K 1
secasvar 1 1K 1
vnodemarker 2 1K 14
NFSD session 1 1K 1
selfd 15 1K 63717
CAM periph 4 1K 271
ipsec 3 1K 3
freefile 6 1K 30
indirdep 3 1K 3
CC Mem 3 1K 7
nhops 6 1K 6
pfil 6 1K 6
isadev 6 1K 6
mount 16 1K 89
pci_link 10 1K 10
sctp_ifa 5 1K 6
diradd 5 1K 38
crypto 4 1K 4
ip6ndp 4 1K 5
encap_export_host 12 1K 12
in_multi 2 1K 4
select 4 1K 29
cdev 2 1K 2
lkpikmalloc 8 1K 9
osd 8 1K 20
chacha20random 1 1K 1
biobuf 1 1K 1
inpcbpolicy 9 1K 140
sctp_ifn 2 1K 6
mld 2 1K 2
igmp 2 1K 2
BPF 2 1K 10
vnodes 1 1K 1
NFSD lckfile 1 1K 1
NFSD V4client 1 1K 1
DEVFS 9 1K 10
CAM SIM 2 1K 2
feeder 7 1K 7
tcpfunc 3 1K 3
loginclass 3 1K 7
prison 6 1K 6
cryptodev 2 1K 49
nexusdev 8 1K 8
apmdev 1 1K 1
atkbddev 2 1K 2
pmchooks 1 1K 1
DEVFSP 2 1K 9
CAM path 4 1K 1034
CAM dev queue 2 1K 2
CAM I/O Scheduler 1 1K 1
soname 4 1K 3334
sctp_vrf 1 1K 1
vnet 1 1K 1
pmc 1 1K 1
entropy 2 1K 35
acpiintr 1 1K 1
cpus 2 1K 2
freework 1 1K 31
vnet_data_free 1 1K 1
Per-cpu 1 1K 1
p1003.1b 1 1K 1
ipcomp 0 0K 0
esp 0 0K 0
ah 0 0K 0
tcp_pcm_rack 0 0K 0
tcp_do_rack 0 0K 0
tcp_fsb_rack 0 0K 0
filemon 0 0K 0
mqdata 0 0K 0
sctp_mcore 0 0K 0
sctp_socko 0 0K 0
sctp_iter 0 0K 4
sctp_mvrf 0 0K 0
sctp_timw 0 0K 0
sctp_cpal 0 0K 0
sctp_cmsg 0 0K 0
sctp_stre 0 0K 0
sctp_athi 0 0K 0
sctp_athm 0 0K 0
sctp_atky 0 0K 0
sctp_atcl 0 0K 0
sctp_a_it 0 0K 4
sctp_aadr 0 0K 0
sctp_stro 0 0K 0
sctp_stri 0 0K 0
sctp_map 0 0K 0
savedino 0 0K 19
sentinel 0 0K 0
jfsync 0 0K 0
jtrunc 0 0K 0
sbdep 0 0K 5
jsegdep 0 0K 0
jseg 0 0K 0
jfreefrag 0 0K 0
jfreeblk 0 0K 0
jnewblk 0 0K 0
jmvref 0 0K 0
jremref 0 0K 0
jaddref 0 0K 0
freedep 0 0K 0
newdirblk 0 0K 9
mkdir 0 0K 18
freeblks 0 0K 30
freefrag 0 0K 20
ip6opt 0 0K 3
ip6_msource 0 0K 0
ip6_moptions 0 0K 0
in6_mfilter 0 0K 0
frag6 0 0K 0
tcplog 0 0K 0
tcp_hwpace 0 0K 0
LRO 0 0K 0
ip_msource 0 0K 0
ip_moptions 0 0K 0
in_mfilter 0 0K 0
ipid 0 0K 0
80211scan 0 0K 0
80211ratectl 0 0K 0
80211power 0 0K 0
80211nodeie 0 0K 0
80211node 0 0K 0
80211mesh_gt 0 0K 0
80211mesh_rt 0 0K 0
80211perr 0 0K 0
80211prep 0 0K 0
80211preq 0 0K 0
80211dfs 0 0K 0
80211crypto 0 0K 0
80211vap 0 0K 0
iflib 0 0K 0
vlan 0 0K 0
tun 0 0K 0
gif 0 0K 0
ifdescr 0 0K 0
zlib 0 0K 19
fadvise 0 0K 0
VN POLL 0 0K 0
statfs 0 0K 300
namei_tracker 0 0K 0
export_host 0 0K 0
cl_savebuf 0 0K 28
aio 0 0K 0
lio 0 0K 0
acl 0 0K 0
mbuf_tag 0 0K 0
ktls 0 0K 0
accf 0 0K 0
pts 0 0K 0
timerfd 0 0K 0
procdesc 0 0K 6
iov 0 0K 14800
ioctlops 0 0K 86
eventfd 0 0K 0
Witness 0 0K 0
stack 0 0K 0
sbuf 0 0K 288
firmware 0 0K 0
compressor 0 0K 0
SWAP 0 0K 0
sysctltmp 0 0K 655
sysctl 0 0K 3
ekcd 0 0K 0
dumper 0 0K 0
sendfile 0 0K 0
rctl 0 0K 0
cache 0 0K 0
kcovinfo 0 0K 0
prison_racct 0 0K 0
Fail Points 0 0K 0
filecaps 0 0K 66
sigio 0 0K 1
tcp_log_dev 0 0K 0
md_disk 0 0K 0
mbuf_jumbo_page 4096 8320 1078 23747 0 254 38494208 0
mbuf 256 8577 1086 36435 0 254 2473728 0
BUF TRIE 144 272 11544 951 0 62 1701504 0
malloc-4096 4096 380 20 4827 0 2 1638400 0
malloc-384 384 4188 12 4189 0 30 1612800 0
mbuf_cluster 2048 762 0 762 0 254 1560576 0
malloc-128 128 11532 62 11540 0 126 1484032 0
UMA Slabs 0 112 11059 23 11059 0 126 1241184 0
vmem btag 56 15834 45 15834 0 254 889224 0
socket 1024 15 749 4320 0 254 782336 0
malloc-65536 65536 9 1 12 0 1 655360 0
FFS inode 1168 500 39 530 0 8 629552 0
RADIX NODE 144 3668 443 84066 0 62 591984 0
lkpicurr 168 2 3094 2 0 62 520128 0
pbuf 2624 0 198 0 0 2 519552 0
malloc-256 256 1660 140 1797 0 62 460800 0
malloc-65536 65536 6 0 6 0 1 393216 0
256 Bucket 2048 124 20 1046 0 8 294912 0
VM OBJECT 264 819 231 43339 0 30 277200 0
THREAD 1824 122 22 3123 0 8 262656 0
malloc-64 64 3862 233 3886 0 254 262080 0
VNODE 440 531 45 563 0 30 253440 0
malloc-16 16 14517 233 14587 0 254 236000 0
malloc-2048 2048 107 5 298 0 8 229376 0
DEVCTL 1024 0 220 123 0 0 225280 0
malloc-2048 2048 6 90 522 0 8 196608 0
mbuf_packet 256 1 761 3125 0 254 195072 0
UMA Zones 768 241 3 241 0 16 187392 0
malloc-32 32 5337 333 5398 0 254 181440 0
malloc-128 128 1147 248 30264 0 126 178560 0
lkpimm 56 1 3095 1 0 254 173376 0
unpcb 320 5 511 1160 0 254 165120 0
malloc-32768 32768 3 2 123 0 1 163840 0
FFS2 dinode 256 500 70 530 0 62 145920 0
FPU_save_area 832 124 38 3140 0 16 134784 0
S VFS Cache 104 989 298 1030 0 126 133848 0
MAP ENTRY 96 687 699 86426 0 126 133056 0
malloc-65536 65536 0 2 110 0 1 131072 0
malloc-65536 65536 0 2 60 0 1 131072 0
malloc-1024 1024 105 23 114 0 16 131072 0
ksiginfo 112 45 999 62 0 126 116928 0
128 Bucket 1024 50 49 378 0 16 101376 0
malloc-128 128 624 151 808 0 126 99200 0
malloc-32768 32768 2 1 13 0 1 98304 0
PROC 1376 34 32 3824 0 8 90816 0
malloc-8192 8192 10 1 117 0 1 90112 0
UMA Kegs 384 227 6 227 0 30 89472 0
g_bio 408 4 206 5427 0 30 85680 0
malloc-256 256 135 180 3809 0 62 80640 0
malloc-64 64 471 600 924 0 254 68544 0
malloc-64 64 551 520 19792 0 254 68544 0
malloc-128 128 296 231 377 0 126 67456 0
malloc-128 128 305 222 1085 0 126 67456 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-65536 65536 1 0 1 0 1 65536 0
malloc-32768 32768 2 0 2 0 1 65536 0
malloc-16384 16384 2 2 182 0 1 65536 0
malloc-256 256 119 136 468 0 62 65280 0
filedesc0 1072 35 21 3825 0 8 60032 0
malloc-8192 8192 7 0 8 0 1 57344 0
64 Bucket 512 66 46 3024 0 30 57344 0
malloc-64 64 90 729 8250 0 254 52416 0
malloc-128 128 135 268 636 0 126 51584 0
malloc-256 256 128 67 141 0 62 49920 0
malloc-256 256 70 125 1073 0 62 49920 0
32 Bucket 256 63 132 24982 0 62 49920 0
DIRHASH 1024 35 13 35 0 16 49152 0
NAMEI 1024 0 48 12689 0 16 49152 0
malloc-16384 16384 3 0 3 0 1 49152 0
malloc-4096 4096 10 2 15 0 2 49152 0
malloc-2048 2048 5 19 544 0 8 49152 0
malloc-1024 1024 8 40 717 0 16 49152 0
malloc-1024 1024 32 16 56 0 16 49152 0
malloc-384 384 68 52 734 0 30 46080 0
syncache 168 0 264 5 0 254 44352 0
VMSPACE 616 18 48 3809 0 16 40656 0
pipe 736 5 50 312 0 16 40480 0
da_ccb 544 1 69 1565 0 16 38080 0
udp_inpcb 416 6 84 129 0 30 37440 0
pcpu-8 8 4295 313 4337 0 254 36864 0
malloc-64 64 125 442 149 0 254 36288 0
malloc-64 64 85 482 63829 0 254 36288 0
malloc-64 64 229 338 260 0 254 36288 0
malloc-64 64 6 561 20 0 254 36288 0
malloc-128 128 52 227 126 0 126 35712 0
malloc-128 128 56 223 73 0 126 35712 0
routing nhops 256 10 125 17 0 62 34560 0
ttyoutq 256 72 63 160 0 62 34560 0
malloc-384 384 35 55 123 0 30 34560 0
malloc-256 256 12 123 45 0 62 34560 0
malloc-256 256 23 112 24 0 62 34560 0
malloc-256 256 5 130 304 0 62 34560 0
malloc-8192 8192 2 2 4 0 1 32768 0
malloc-8192 8192 4 0 4 0 1 32768 0
malloc-2048 2048 3 13 3 0 8 32768 0
malloc-2048 2048 4 12 67 0 8 32768 0
malloc-2048 2048 5 11 3034 0 8 32768 0
malloc-1024 1024 5 27 9 0 16 32768 0
malloc-1024 1024 9 23 10 0 16 32768 0
malloc-1024 1024 3 29 3 0 16 32768 0
malloc-1024 1024 9 23 899 0 16 32768 0
malloc-512 512 10 54 22 0 30 32768 0
malloc-512 512 3 61 160 0 30 32768 0
malloc-512 512 1 63 11 0 30 32768 0
malloc-512 512 1 63 3 0 30 32768 0
pcpu-64 64 494 18 494 0 254 32768 0
ertt_txseginfo 40 0 808 3483 0 254 32320 0
ttyinq 160 135 65 300 0 62 32000 0
Files 80 54 346 9824 0 126 32000 0
PGRP 120 16 248 32 0 126 31680 0
clpbuf 2624 0 12 68 0 4 31488 0
sctp_laddr 48 0 588 4 0 254 28224 0
malloc-32 32 299 583 407 0 254 28224 0
malloc-32 32 62 820 3875 0 254 28224 0
malloc-32 32 20 862 4086 0 254 28224 0
16 Bucket 144 54 142 547 0 62 28224 0
4 Bucket 48 7 581 12 0 254 28224 0
TURNSTILE 136 145 44 145 0 62 25704 0
cpuset 200 7 121 7 0 62 25600 0
malloc-4096 4096 3 3 303 0 2 24576 0
PWD 40 9 597 116 0 254 24240 0
rtentry 168 13 131 17 0 62 24192 0
8 Bucket 80 56 244 636 0 126 24000 0
tcp_inpcb 1320 3 15 7 0 8 23760 0
ripcb 384 0 60 4 0 30 23040 0
malloc-384 384 1 59 2 0 30 23040 0
Mountpoints 2816 2 6 2 0 4 22528 0
SLEEPQUEUE 88 145 111 145 0 126 22528 0
hostcache 64 1 314 1 0 254 20160 0
udp_inpcb ports 32 3 627 40 0 254 20160 0
ertt 72 3 277 7 0 126 20160 0
malloc-32 32 94 536 238 0 254 20160 0
malloc-32 32 46 584 57 0 254 20160 0
malloc-32 32 27 603 2679 0 254 20160 0
2 Bucket 32 53 577 317 0 254 20160 0
vmem 1856 2 7 2 0 8 16704 0
epoch_record pcpu 256 4 60 4 0 62 16384 0
malloc-16384 16384 1 0 2 0 1 16384 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-16384 16384 1 0 1 0 1 16384 0
malloc-4096 4096 4 0 86 0 2 16384 0
malloc-2048 2048 1 7 1 0 8 16384 0
malloc-2048 2048 2 6 2 0 8 16384 0
malloc-512 512 4 28 8 0 30 16384 0
malloc-512 512 0 32 10 0 30 16384 0
SMR CPU 32 8 503 8 0 254 16352 0
vtnet_tx_hdr 24 0 668 5510 0 254 16032 0
malloc-16 16 318 682 502 0 254 16000 0
kenv 258 17 43 1065 0 30 15480 0
mqnode 416 3 33 3 0 30 14976 0
SMR SHARED 24 8 503 8 0 254 12264 0
tcp_inpcb ports 32 1 377 1 0 254 12096 0
malloc-32 32 76 302 689 0 254 12096 0
KNOTE 160 0 75 8 0 62 12000 0
malloc-16 16 25 725 139 0 254 12000 0
malloc-16 16 7 743 25 0 254 12000 0
malloc-16 16 33 717 49 0 254 12000 0
malloc-16 16 199 551 4195 0 254 12000 0
malloc-16 16 14 736 26604 0 254 12000 0
malloc-16 16 15 735 62 0 254 12000 0
malloc-384 384 6 24 6 0 30 11520 0
malloc-384 384 25 5 37 0 30 11520 0
malloc-384 384 1 29 2 0 30 11520 0
malloc-8192 8192 1 0 1 0 1 8192 0
malloc-8192 8192 0 1 19 0 1 8192 0
malloc-8192 8192 1 0 1 0 1 8192 0
malloc-4096 4096 0 2 3 0 2 8192 0
malloc-4096 4096 0 2 2 0 2 8192 0
malloc-4096 4096 1 1 1 0 2 8192 0
malloc-4096 4096 1 1 1 0 2 8192 0
pcpu-16 16 8 504 8 0 254 8192 0
UMA Slabs 1 176 8 14 8 0 62 3872 0
KMAP ENTRY 96 12 27 14 0 0 3744 0
FFS1 dinode 128 0 0 0 0 126 0 0
ada_ccb 272 0 0 0 0 30 0 0
swblk 136 0 0 0 0 62 0 0
swpctrie 144 0 0 0 0 62 0 0
cdg_qdiffsample 16 0 0 0 0 254 0 0
pf state scrubs 40 0 0 0 0 254 0 0
pf frag entries 40 0 0 0 0 254 0 0
pf frags 248 0 0 0 0 62 0 0
pf table entries 160 0 0 0 0 254 0 0
pf table entry counters 64 0 0 0 0 254 0 0
pf UDP mappings 104 0 0 0 0 126 0 0
pf source nodes 152 0 0 0 0 254 0 0
pf state keys 88 0 0 0 0 126 0 0
pf states 368 0 0 0 0 254 0 0
pf tags 104 0 0 0 0 126 0 0
pf mtags 184 0 0 0 0 62 0 0
tcp_rack_pcb 1152 0 0 0 0 8 0 0
tcp_rack_map 128 0 0 0 0 126 0 0
tcp_bbr_pcb 896 0 0 0 0 16 0 0
tcp_bbr_map 128 0 0 0 0 126 0 0
tfo_ccache_entries 80 0 0 0 0 126 0 0
tfo 4 0 0 0 0 254 0 0
sackhole 32 0 0 0 0 254 0 0
ipq 56 0 0 0 0 254 0 0
sctp_asconf_ack 48 0 0 0 0 254 0 0
sctp_asconf 40 0 0 0 0 254 0 0
sctp_stream_msg_out 112 0 0 0 0 254 0 0
sctp_readq 152 0 0 0 0 254 0 0
sctp_chunk 152 0 0 0 0 254 0 0
sctp_raddr 736 0 0 0 0 254 0 0
sctp_asoc 2256 0 0 0 0 254 0 0
sctp_ep 1152 0 0 0 0 254 0 0
tcp_log_id_node 120 0 0 0 0 126 0 0
tcp_log_id_bucket 176 0 0 0 0 62 0 0
tcp_log 416 0 0 0 0 254 0 0
tcpreass 48 0 0 0 0 254 0 0
udplite_inpcb ports 32 0 0 0 0 254 0 0
udplite_inpcb 416 0 0 0 0 30 0 0
ripcb ports 32 0 0 0 0 254 0 0
IPsec SA lft_c 16 0 0 0 0 254 0 0
itimer 352 0 0 0 0 30 0 0
AIOLIO 272 0 0 0 0 30 0 0
AIOCB 552 0 0 0 0 16 0 0
AIO 208 0 0 0 0 62 0 0
mqnotifier 216 0 0 0 0 62 0 0
mvdata 64 0 0 0 0 254 0 0
mqueue 248 0 0 0 0 62 0 0
TMPFS node 240 0 0 0 0 62 0 0
NCLNODE 608 0 0 0 0 16 0 0
LTS VFS Cache 360 0 0 0 0 30 0 0
L VFS Cache 320 0 0 0 0 30 0 0
STS VFS Cache 144 0 0 0 0 62 0 0
cryptop 280 0 0 0 0 30 0 0
linux_dma_object 32 0 0 0 0 254 0 0
linux_dma_pctrie 144 0 0 0 0 62 0 0
IOMMU_MAP_ENTRY 112 0 0 0 0 126 0 0
mbuf_jumbo_16k 16384 0 0 0 0 254 0 0
mbuf_jumbo_9k 9216 0 0 0 0 254 0 0
audit_record 1280 0 0 0 0 8 0 0
domainset 40 0 0 0 0 254 0 0
MAC labels 40 0 0 0 0 254 0 0
vnpbuf 2624 0 0 0 0 16 0 0
nfspbuf 2624 0 0 0 0 4 0 0
swwbuf 2624 0 0 0 0 2 0 0
swrbuf 2624 0 0 0 0 4 0 0
umtx_shm 88 0 0 0 0 126 0 0
umtx pi 96 0 0 0 0 126 0 0
rangeset pctrie nodes 144 0 0 0 0 62 0 0
rl_entry 48 0 0 0 0 254 0 0
malloc-65536 65536 0 0 0 0 1 0 0
malloc-65536 65536 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-32768 32768 0 0 0 0 1 0 0
malloc-16384 16384 0 0 0 0 1 0 0
malloc-16384 16384 0 0 0 0 1 0 0
malloc-16384 16384 0 0 0 0 1 0 0
malloc-8192 8192 0 0 0 0 1 0 0
malloc-1024 1024 0 0 0 0 16 0 0
malloc-512 512 0 0 0 0 30 0 0
malloc-512 512 0 0 0 0 30 0 0
malloc-384 384 0 0 0 0 30 0 0
pcpu-32 32 0 0 0 0 254 0 0
pcpu-4 4 0 0 0 0 254 0 0
fakepg 104 0 0 0 0 126 0 0


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
Reply all
Reply to author
Forward
0 new messages