MSan: Uninitialized Memory in fixjobc

0 views
Skip to first unread message

syzbot

unread,
Mar 22, 2020, 4:25:16 AM3/22/20
to syzkaller-...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 550a7869 Add more casts.
git tree: netbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=12daffe3e00000
kernel config: https://syzkaller.appspot.com/x/.config?x=9544af77043190a5
dashboard link: https://syzkaller.appspot.com/bug?extid=5da27ca388df30ce0f0d
compiler: clang version 3.8.0-2ubuntu4 (tags/RELEASE_380/final)
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1248b9b1e00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+5da27c...@syzkaller.appspotmail.com

[ 102.3419266] panic: MSan: Uninitialized Kmem Memory From amap_alloc1()

[ 102.3530455] cpu1: Begin traceback...
[ 102.3752784] vpanic() at netbsd:vpanic+0x7c1 sys/kern/subr_prf.c:334
[ 102.4308978] panic() at netbsd:panic+0x1ad sys/kern/subr_prf.c:255
[ 102.4865221] __msan_warning() at netbsd:__msan_warning+0xe7 kmsan_report_inline sys/kern/subr_msan.c:236 [inline]
[ 102.4865221] __msan_warning() at netbsd:__msan_warning+0xe7 sys/kern/subr_msan.c:612
[ 102.5310197] fixjobc() at netbsd:fixjobc+0x9a9 sys/kern/kern_proc.c:1197
[ 102.5866489] proc_enterpgrp() at netbsd:proc_enterpgrp+0x1b7c sys/kern/kern_proc.c:947
[ 102.6422652] sys_setpgid() at netbsd:sys_setpgid+0x1c8 sys/kern/kern_prot.c:289
[ 102.6978873] sys___syscall() at netbsd:sys___syscall+0x27e sys/kern/sys_syscall.c:77
[ 102.7646354] syscall() at netbsd:syscall+0x35d sy_call sys/sys/syscallvar.h:65 [inline]
[ 102.7646354] syscall() at netbsd:syscall+0x35d sy_invoke sys/sys/syscallvar.h:94 [inline]
[ 102.7646354] syscall() at netbsd:syscall+0x35d sys/arch/x86/x86/syscall.c:138
[ 102.7757586] --- syscall (number 198) ---
[ 102.7980077] 7443cbe43b9a:
[ 102.7980077] cpu1: End traceback...
[ 102.8091257] fatal breakpoint trap in supervisor mode
[ 102.8091257] trap type 1 code 0 rip 0xffffffff8022025d cs 0x8 rflags 0x246 cr2 0x75d389443b9a ilevel 0 rsp 0xffffda807af678f0
[ 102.8313764] curlwp 0xffffda8014ac4200 pid 1259.2 lowest kstack 0xffffda807af602c0
Stopped in pid 1259.2 (syz-executor.2) at netbsd:breakpoint+0x5: leave
?
breakpoint() at netbsd:breakpoint+0x5
vpanic() at netbsd:vpanic+0x7c1 sys/kern/subr_prf.c:334
panic() at netbsd:panic+0x1ad sys/kern/subr_prf.c:255
__msan_warning() at netbsd:__msan_warning+0xe7 kmsan_report_inline sys/kern/subr_msan.c:236 [inline]
__msan_warning() at netbsd:__msan_warning+0xe7 sys/kern/subr_msan.c:612
fixjobc() at netbsd:fixjobc+0x9a9 sys/kern/kern_proc.c:1197
proc_enterpgrp() at netbsd:proc_enterpgrp+0x1b7c sys/kern/kern_proc.c:947
sys_setpgid() at netbsd:sys_setpgid+0x1c8 sys/kern/kern_prot.c:289
sys___syscall() at netbsd:sys___syscall+0x27e sys/kern/sys_syscall.c:77
syscall() at netbsd:syscall+0x35d sy_call sys/sys/syscallvar.h:65 [inline]
syscall() at netbsd:syscall+0x35d sy_invoke sys/sys/syscallvar.h:94 [inline]
syscall() at netbsd:syscall+0x35d sys/arch/x86/x86/syscall.c:138
--- syscall (number 198) ---
7443cbe43b9a:
ds 78e0
es 0
fs 1f7c
gs 104
rdi 8000000000
rsi ffffc88000000000
rbp ffffda807af678f0
rbx 0
rdx ffff810014ac44b8
rcx 0
rax 0
r8 1
r9 0
r10 ffffda807af677a0
r11 0
r12 0
r13 104
r14 1f7c
r15 0
rip ffffffff8022025d breakpoint+0x5
cs 8
rflags 246
rsp ffffda807af678f0
ss 0
netbsd:breakpoint+0x5: leave
PID LID S CPU FLAGS STRUCT LWP * NAME WAIT
887 2 2 1 0 ffffda8013e34bc0 syz-executor.5
629 2 3 0 80 ffffda8011fe9300 syz-executor.2 parked
886 2 2 1 0 ffffda8012a12780 syz-executor.3
884 1 2 0 0 ffffda8013d106c0 syz-executor.0
1267 3 3 0 80 ffffda8012065ac0 syz-executor.3 parked
1267 2 3 1 80 ffffda80110f4b40 syz-executor.3 parked
1267 1 2 0 10040000 ffffda8013e518c0 syz-executor.3
882 3 3 1 80 ffffda801206e6c0 syz-executor.5 parked
882 2 3 1 80 ffffda8013e51480 syz-executor.5 parked
882 1 2 0 10040000 ffffda8013e51040 syz-executor.5
1007 2 3 0 40080 ffffda8014ab7a40 syz-executor.1 parked
752 3 3 0 40080 ffffda8014ac4640 syz-executor.5 parked
1262 3 3 0 40080 ffffda8014ab7600 syz-executor.4 parked
365 3 3 0 40080 ffffda8014aa5a00 syz-executor.5 parked
876 2 3 0 40080 ffffda8014aa5180 syz-executor.4 parked
362 3 3 0 40080 ffffda8013d22b40 syz-executor.3 parked
1259 3 3 1 80 ffffda8014025900 syz-executor.2 parked
1259 > 2 7 1 0 ffffda8014ac4200 syz-executor.2
1259 1 2 0 10040000 ffffda8013d2db80 syz-executor.2
360 2 3 0 40080 ffffda80114749c0 syz-executor.3 parked
1254 3 3 0 40080 ffffda8014963980 syz-executor.2 parked
997 2 3 0 40080 ffffda8011ffc780 syz-executor.1 parked
868 2 3 0 40080 ffffda8013d22700 syz-executor.2 parked
739 4 3 0 80 ffffda80115f8200 syz-executor.0 parked
481 3 3 0 80 ffffda8014963540 syz-executor.1 parked
480 3 3 1 80 ffffda8014963100 syz-executor.0 parked
990 2 3 0 80 ffffda8014835940 syz-executor.4 parked
988 2 3 1 80 ffffda80147fd900 syz-executor.1 parked
985 2 3 1 80 ffffda80120f0100 syz-executor.3 parked
856 2 3 1 80 ffffda80117b7100 syz-executor.3 parked
981 3 3 0 80 ffffda8011ffc340 syz-executor.4 parked
980 2 3 1 80 ffffda80120d9900 syz-executor.4 parked
978 3 3 0 80 ffffda8014578480 syz-executor.3 parked
851 4 3 0 80 ffffda80145788c0 syz-executor.5 parked
336 2 3 1 80 ffffda8011939a00 syz-executor.5 parked
974 2 3 0 80 ffffda8013a909c0 syz-executor.3 parked
461 2 3 0 80 ffffda8013abd200 syz-executor.0 parked
971 2 3 0 80 ffffda8013abd640 syz-executor.1 parked
586 2 3 0 80 ffffda8013a93180 syz-executor.1 parked
457 2 3 0 80 ffffda80116f50c0 syz-executor.0 parked
837 3 3 0 80 ffffda8011939180 syz-executor.4 parked
580 2 3 1 80 ffffda8011f64280 syz-executor.2 parked
705 3 3 1 80 ffffda8014578040 syz-executor.1 parked
704 3 3 0 80 ffffda8014569780 syz-executor.5 parked
830 2 3 0 80 ffffda80143b9b40 syz-executor.5 parked
954 3 3 0 80 ffffda8013a02100 syz-executor.1 parked
950 2 3 1 80 ffffda80117b7980 syz-executor.3 parked
949 3 3 0 80 ffffda80138204c0 syz-executor.3 parked
948 3 3 0 80 ffffda80143b92c0 syz-executor.4 parked
815 2 3 1 80 ffffda80143ab280 syz-executor.4 parked
946 3 3 0 80 ffffda80118a9b40 syz-executor.0 parked
561 3 3 0 80 ffffda801351b2c0 syz-executor.0 parked
940 2 3 1 80 ffffda8014269600 syz-executor.3 parked
297 2 3 0 80 ffffda8011898280 syz-executor.1 parked
1191 2 3 0 80 ffffda801188b240 syz-executor.5 parked
805 3 3 1 80 ffffda8013837940 syz-executor.4 parked
932 2 3 1 80 ffffda801188bac0 syz-executor.5 parked
674 2 3 1 80 ffffda8013820900 syz-executor.4 parked
925 3 3 1 80 ffffda80117b7540 syz-executor.0 parked
794 2 3 0 80 ffffda80142691c0 syz-executor.4 parked
920 2 3 1 80 ffffda80140039c0 syz-executor.1 parked
1175 2 3 1 80 ffffda8011772340 syz-executor.3 parked
790 2 3 1 80 ffffda8014003580 syz-executor.1 parked
788 3 3 1 80 ffffda8013ff4980 syz-executor.2 parked
913 2 3 1 80 ffffda8013172980 syz-executor.3 parked
656 2 3 1 80 ffffda80134fd240 syz-executor.3 parked
269 2 3 0 80 ffffda801207a700 syz-executor.2 parked
650 3 3 0 80 ffffda8013411a80 syz-executor.5 parked
771 3 3 0 80 ffffda80115f8a80 syz-executor.3 parked
901 2 3 1 80 ffffda80115f8640 syz-executor.4 parked
900 2 3 1 80 ffffda80115de600 syz-executor.0 parked
258 2 3 0 80 ffffda801402f500 syz-executor.1 parked
384 3 3 1 80 ffffda801402f0c0 syz-executor.5 parked
775 4 3 1 80 ffffda8014025080 syz-executor.4 parked
321 2 3 0 80 ffffda80110f6300 syz-executor.5 parked
819 2 3 0 80 ffffda80120379c0 syz-executor.1 parked
825 3 3 0 80 ffffda801207a2c0 syz-executor.4 parked
541 2 3 0 80 ffffda8011f47ac0 syz-executor.3 parked
767 2 3 1 80 ffffda8013e34340 syz-executor.4 parked
894 2 3 1 80 ffffda80115dea40 syz-executor.3 parked
889 4 3 1 80 ffffda8011755b80 syz-executor.2 parked
892 2 3 0 80 ffffda8013d2d740 syz-executor.1 parked
759 2 3 1 80 ffffda80120405c0 syz-executor.5 parked
758 2 3 0 80 ffffda8013d10b00 syz-executor.3 parked
565 2 3 0 80 ffffda8013d10280 syz-executor.4 parked
756 2 3 1 80 ffffda8011efe200 syz-executor.2 parked
625 2 3 1 80 ffffda8012037580 syz-executor.0 parked
687 2 3 1 80 ffffda80118e99c0 syz-executor.4 parked
237 2 3 1 80 ffffda80120e7940 syz-executor.3 parked
748 3 3 1 80 ffffda8013c54680 syz-executor.2 parked
875 2 3 1 80 ffffda801200e040 syz-executor.5 parked
232 2 3 0 80 ffffda80118b2740 syz-executor.0 parked
677 2 3 1 80 ffffda8011fdb2c0 syz-executor.2 parked
740 2 3 0 80 ffffda80120d9080 syz-executor.4 parked
419 2 3 1 80 ffffda8013abda80 syz-executor.5 parked
671 2 3 0 80 ffffda801200e480 syz-executor.2 parked
670 3 3 0 80 ffffda801298e740 syz-executor.3 parked
605 3 3 0 80 ffffda8013a9a1c0 syz-executor.4 parked
668 3 3 1 80 ffffda8013a93a00 syz-executor.3 parked
666 2 3 0 80 ffffda80117898c0 syz-executor.5 parked
662 3 3 0 80 ffffda8013a02980 syz-executor.0 parked
660 3 3 1 80 ffffda8011702100 syz-executor.0 parked
658 2 3 1 80 ffffda8011702980 syz-executor.1 parked
272 3 3 0 80 ffffda80116ea4c0 syz-executor.2 parked
654 2 3 1 80 ffffda80118585c0 syz-executor.2 parked
137 2 3 1 80 ffffda801164e6c0 syz-executor.3 parked
458 2 3 1 80 ffffda80118b2300 syz-executor.0 parked
709 2 3 0 80 ffffda80118a92c0 syz-executor.1 parked
516 3 3 0 80 ffffda8011898b00 syz-executor.2 parked
678 2 3 1 80 ffffda801187fa80 syz-executor.0 parked
451 3 3 0 80 ffffda801187f200 syz-executor.5 parked
700 2 3 1 80 ffffda8011858a00 syz-executor.5 parked
623 2 3 1 80 ffffda80136d3b80 syz-executor.4 parked
598 3 3 0 80 ffffda8013701480 syz-executor.1 parked
602 3 3 0 80 ffffda8013820080 syz-executor.2 parked
599 2 3 1 80 ffffda80117a90c0 syz-executor.3 parked
501 4 3 1 80 ffffda8011755300 syz-executor.5 parked
465 2 3 0 80 ffffda80136e7bc0 syz-executor.1 parked
208 2 3 0 80 ffffda80136e7340 syz-executor.0 parked
686 2 3 1 80 ffffda80136d3740 syz-executor.0 parked
556 3 3 0 80 ffffda801164eb00 syz-executor.2 parked
266 3 3 1 80 ffffda8011772780 syz-executor.5 parked
169 2 3 1 80 ffffda801351b700 syz-executor.1 parked
646 2 3 1 80 ffffda8011637240 syz-executor.0 parked
613 2 3 0 80 ffffda80135086c0 syz-executor.4 parked
548 2 3 1 80 ffffda80134fdac0 syz-executor.4 parked
601 3 3 0 80 ffffda80132f3600 syz-executor.1 parked
590 2 3 1 80 ffffda80115de1c0 syz-executor.4 parked
570 3 3 0 80 ffffda80132f31c0 syz-executor.0 parked
517 2 3 1 80 ffffda80132ea180 syz-executor.0 parked
527 1 2 0 0 ffffda8013172100 syz-executor.1
564 1 2 0 0 ffffda8013166940 syz-executor.5
45 > 1 7 0 40000 ffffda8013166500 syz-executor.0
452 1 2 0 0 ffffda80131660c0 syz-executor.3
531 1 3 1 0 ffffda8011565a00 syz-executor.2 tstile
40 1 3 1 4 ffffda8013156900 syz-executor.4 biowait
606 12 3 1 80 ffffda80131564c0 syz-execprog parked
606 11 3 0 80 ffffda8013156080 syz-execprog parked
606 10 3 1 80 ffffda801314f8c0 syz-execprog parked
606 9 3 0 80 ffffda801314f480 syz-execprog parked
606 8 3 0 80 ffffda801314f040 syz-execprog parked
606 7 3 1 80 ffffda8012a12bc0 syz-execprog parked
606 6 3 1 80 ffffda8012065240 syz-execprog kqueue
606 5 3 1 80 ffffda8012040a00 syz-execprog parked
606 4 3 1 80 ffffda801200e8c0 syz-execprog parked
606 3 3 1 80 ffffda8012037140 syz-execprog parked
606 2 3 1 80 ffffda8010c23b00 syz-execprog parked
606 1 3 0 80 ffffda8011565180 syz-execprog parked
562 1 3 1 80 ffffda8011472100 sshd select
583 1 3 1 80 ffffda8012055a80 getty nanoslp
536 1 3 1 80 ffffda8012055200 getty nanoslp
587 1 3 1 80 ffffda8012065680 getty nanoslp
381 1 3 1 80 ffffda801206e280 getty ttyraw
567 1 3 1 80 ffffda8011efea80 cron nanoslp
433 1 3 1 80 ffffda8011efe640 inetd kqueue
460 1 3 0 80 ffffda80119c1a40 sshd select
405 1 3 1 80 ffffda8011858180 powerd kqueue
176 1 3 0 80 ffffda8011f64b00 syslogd kqueue
234 1 3 0 80 ffffda80116cc340 dhcpcd kqueue
219 1 3 1 80 ffffda8011795080 dhcpcd kqueue
1 1 3 0 80 ffffda80112c2940 init wait
0 44 3 0 204 ffffda8011472540 physiod physiod
0 48 3 1 200 ffffda8011474140 ioflush syncer
0 47 3 0 204 ffffda8011474580 pooldrain pooldrain
0 46 3 1 200 ffffda8011472980 pgdaemon pgdaemon
0 29 3 1 200 ffffda8010c23280 npfgc-0 npfgccv
0 43 3 1 204 ffffda80112c2500 rt_free rt_free
0 42 3 1 204 ffffda80112c20c0 unpgc unpgc
0 41 3 1 204 ffffda80112be900 key_timehandler key_timehandler
0 40 3 1 204 ffffda80112be4c0 icmp6_wqinput/1 icmp6_wqinput
0 39 3 0 204 ffffda80112be080 icmp6_wqinput/0 icmp6_wqinput
0 38 3 1 204 ffffda80112b58c0 nd6_timer nd6_timer
0 37 3 1 204 ffffda80112b5480 carp6_wqinput/1 carp6_wqinput
0 36 3 0 204 ffffda80112b5040 carp6_wqinput/0 carp6_wqinput
0 35 3 1 204 ffffda801110abc0 carp_wqinput/1 carp_wqinput
0 34 3 0 204 ffffda801110a780 carp_wqinput/0 carp_wqinput
0 33 3 1 204 ffffda801110a340 icmp_wqinput/1 icmp_wqinput
0 32 3 0 204 ffffda80110f6b80 icmp_wqinput/0 icmp_wqinput
0 31 3 1 204 ffffda80110f6740 rt_timer rt_timer
0 30 3 0 204 ffffda80110f4700 vmem_rehash vmem_rehash
0 28 3 0 204 ffffda800f895ac0 scsibus0 sccomp
0 27 3 0 200 ffffda800f895680 pms0 pmsreset
0 26 3 1 204 ffffda800f895240 xcall/1 xcall
0 25 1 1 200 ffffda800f892a80 softser/1
0 24 1 1 200 ffffda800f892640 softclk/1
0 23 1 1 200 ffffda800f892200 softbio/1
0 22 1 1 200 ffffda800e20fa40 softnet/1
0 21 1 1 201 ffffda800e20f600 idle/1
0 20 3 0 204 ffffda800e20f1c0 lnxpwrwq lnxpwrwq
0 19 3 0 204 ffffda800e20da00 lnxlngwq lnxlngwq
0 18 3 0 204 ffffda800e20d5c0 lnxsyswq lnxsyswq
0 17 3 0 204 ffffda800e20d180 lnxrcugc lnxrcugc
0 16 3 0 204 ffffda800e2079c0 sysmon smtaskq
0 15 3 0 204 ffffda800e207580 pmfsuspend pmfsuspend
0 14 3 0 204 ffffda800e207140 pmfevent pmfevent
0 13 3 0 204 ffffda800e202980 sopendfree sopendfr
0 12 3 1 204 ffffda800e202540 iflnkst iflnkst
0 11 3 0 204 ffffda800e202100 nfssilly nfssilly
0 10 3 0 200 ffffda800e1f9940 cachegc cachegc
0 9 3 0 204 ffffda800e1f9500 vdrain vdrain
0 8 3 0 200 ffffda800e1f90c0 modunload mod_unld
0 7 3 0 204 ffffda800e1f0900 xcall/0 xcall
0 6 1 0 200 ffffda800e1f04c0 softser/0
0 5 1 0 200 ffffda800e1f0080 softclk/0
0 4 1 0 200 ffffda800e1eb8c0 softbio/0
0 3 1 0 200 ffffda800e1eb480 softnet/0
0 2 1 0 201 ffffda800e1eb040 idle/0
0 1 3 0 200 ffffffff859a44c0 swapper uvm
[Locks tracked through LWPs]

****** LWP 887.2 (syz-executor.5) @ 0xffffda8013e34bc0, l_stat=2

*** Locks held:

* Lock 0 (initialized at uvm_obj_init)
lock address : 0xffffda8012dc7a80 type : sleep/adaptive
initialized : 0xffffffff83317808
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffda8013e34bc0 last held: 0xffffda8013e34bc0
last locked* : 0xffffffff832ae22c unlocked : 0xffffffff832bb1d5
owner/count : 0xffffda8013e34bc0 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

* Lock 1 (initialized at pmap_ctor)
lock address : 0xffffda8014ad1380 type : sleep/adaptive
initialized : 0xffffffff8031c6c7
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffda8013e34bc0 last held: 0xffffda8013e34bc0
last locked* : 0xffffffff80333174 unlocked : 0xffffffff803385dd
owner field : 0xffffda8013e34bc0 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 629.2 (syz-executor.2) @ 0xffffda8011fe9300, l_stat=3

*** Locks held:

* Lock 0 (initialized at amap_ctor)
lock address : 0xffffda80131757c0 type : sleep/adaptive
initialized : 0xffffffff8327d213
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffda8011fe9300 last held: 0xffffda8011fe9300
last locked* : 0xffffffff832abb3b unlocked : 0xffffffff832b9c8b
owner/count : 000000000000000000 flags : 000000000000000000
Turnstile: no active turnstile for this lock.

* Lock 1 (initialized at pmap_ctor)
lock address : 0xffffda801203a8c0 type : sleep/adaptive
initialized : 0xffffffff8031c6c7
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffda8011fe9300 last held: 0xffffda8011fe9300
last locked* : 0xffffffff80333174 unlocked : 0xffffffff8032613f
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 886.2 (syz-executor.3) @ 0xffffda8012a12780, l_stat=2

*** Locks held:

* Lock 0 (initialized at amap_ctor)
lock address : 0xffffda8013175a40 type : sleep/adaptive
initialized : 0xffffffff8327d213
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffda8012a12780 last held: 0xffffda8012a12780
last locked* : 0xffffffff832abb3b unlocked : 0xffffffff832b9c8b
owner/count : 0xffffda8012a12780 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

* Lock 1 (initialized at pmap_ctor)
lock address : 0xffffda8011f4ea80 type : sleep/adaptive
initialized : 0xffffffff8031c6c7
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffda8012a12780 last held: 0xffffda8012a12780
last locked* : 0xffffffff80333174 unlocked : 0xffffffff8032613f
owner field : 0xffffda8012a12780 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 884.1 (syz-executor.0) @ 0xffffda8013d106c0, l_stat=2

*** Locks held:

* Lock 0 (initialized at amap_ctor)
lock address : 0xffffda8013049f80 type : sleep/adaptive
initialized : 0xffffffff8327d213
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffda8013d106c0 last held: 0xffffda8013d106c0
last locked* : 0xffffffff832abb3b unlocked : 0xffffffff832b9c8b
owner/count : 0xffffda8013d106c0 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 882.1 (syz-executor.5) @ 0xffffda8013e51040, l_stat=2

*** Locks held:

* Lock 0 (initialized at uvmspace_fork)
lock address : 0xffffda80112cc1a0 type : sleep/adaptive
initialized : 0xffffffff832fedd3
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffda8013e51040 last held: 0xffffda8013e51040
last locked* : 0xffffffff832ce8cf unlocked : 0xffffffff832aff03
owner/count : 0xffffda8013e51040 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

*** Locks wanted:

* Lock 0 (initialized at pool_init)
lock address : 0xffffda800dccd230 type : sleep/adaptive
initialized : 0xffffffff83639018
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 1
relevant cpu : 0 last held: 0
relevant lwp : 0xffffda8013e51040 last held: 000000000000000000
last locked : 0xffffffff8363e191 unlocked*: 0xffffffff83640c04
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 1259.2 (syz-executor.2) @ 0xffffda8014ac4200, l_stat=7

*** Locks held:

* Lock 0 (initialized at procinit)
lock address : 0xffffda800dcb30c0 type : sleep/adaptive
initialized : 0xffffffff834a31b0
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 1
relevant cpu : 1 last held: 1
relevant lwp : 0xffffda8014ac4200 last held: 0xffffda8014ac4200
last locked* : 0xffffffff834b1473 unlocked : 0xffffffff834b1407
owner field : 0xffffda8014ac4200 wait/spin: 1/0
Turnstile:
=> 0 waiting readers:
=> 1 waiting writers: 0xffffda8011565a00

*** Locks wanted: none

****** LWP 527.1 (syz-executor.1) @ 0xffffda8013172100, l_stat=2

*** Locks held:

* Lock 0 (initialized at vcache_new)
lock address : 0xffffda80131617c0 type : sleep/adaptive
initialized : 0xffffffff838b7347
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffda8013172100 last held: 0xffffda8013172100
last locked* : 0xffffffff8392f093 unlocked : 0xffffffff8392f3f5
owner/count : 0xffffda8013172100 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

* Lock 1 (initialized at vcache_new)
lock address : 0xffffda8014add1c0 type : sleep/adaptive
initialized : 0xffffffff838b7347
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffda8013172100 last held: 0xffffda8013172100
last locked* : 0xffffffff8392f093 unlocked : 000000000000000000
owner/count : 0xffffda8013172100 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 531.1 (syz-executor.2) @ 0xffffda8011565a00, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at procinit)
lock address : 0xffffda800dcb30c0 type : sleep/adaptive
initialized : 0xffffffff834a31b0
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 1
relevant cpu : 1 last held: 1
relevant lwp : 0xffffda8011565a00 last held: 0xffffda8014ac4200
last locked* : 0xffffffff834b1473 unlocked : 0xffffffff834b1407
owner field : 0xffffda8014ac4200 wait/spin: 1/0
Turnstile:
=> 0 waiting readers:
=> 1 waiting writers: 0xffffda8011565a00

****** LWP 40.1 (syz-executor.4) @ 0xffffda8013156900, l_stat=3

*** Locks held:

* Lock 0 (initialized at vcache_new)
lock address : 0xffffda8013157bc0 type : sleep/adaptive
initialized : 0xffffffff838b7347
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffda8013156900 last held: 0xffffda8013156900
last locked* : 0xffffffff8392f093 unlocked : 0xffffffff8392f3f5
owner/count : 0xffffda8013156900 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

* Lock 1 (initialized at vcache_new)
lock address : 0xffffda801481d3c0 type : sleep/adaptive
initialized : 0xffffffff838b7347
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffda8013156900 last held: 0xffffda8013156900
last locked* : 0xffffffff8392f093 unlocked : 0xffffffff8392f3f5
owner/count : 0xffffda8013156900 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 0.24 (softclk/1) @ 0xffffda800f892640, l_stat=1

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff85a5d600 type : sleep/adaptive
initialized : 0xffffffff8347d683
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffffda800f892640 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.12 (iflnkst) @ 0xffffda800e202540, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff85a5d600 type : sleep/adaptive
initialized : 0xffffffff8347d683
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffffda800e202540 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.5 (softclk/0) @ 0xffffda800e1f0080, l_stat=1

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff85a5d600 type : sleep/adaptive
initialized : 0xffffffff8347d683
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffda800e1f0080 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

[Locks tracked through CPUs]

PAGE FLAG PQ UOBJECT UANON
0xffffda8000014180 0041 00000000 0x0 0x0
0xffffda8000014200 0041 00000000 0x0 0x0
0xffffda8000014280 0041 00000000 0x0 0x0
0xffffda8000014300 0041 00000000 0x0 0x0
0xffffda8000014380 0041 00000000 0x0 0x0
0xffffda8000014400 0041 00000000 0x0 0x0
0xffffda8000014480 0041 00000000 0x0 0x0
0xffffda8000014500 0041 00000000 0x0 0x0
0xffffda8000014580 0041 00000000 0x0 0x0
0xffffda8000014600 0041 00000000 0x0 0x0
0xffffda8000014680 0041 00000000 0x0 0x0
0xffffda8000014700 0041 00000000 0x0 0x0
0xffffda8000014780 0041 00000000 0x0 0x0
0xffffda8000014800 0041 00000000 0x0 0x0
0xffffda8000014880 0041 00000000 0x0 0x0
0xffffda8000014900 0041 00000000 0x0 0x0
0xffffda8000014980 0041 00000000 0x0 0x0
0xffffda8000014a00 0041 00000000 0x0 0x0
0xffffda8000014a80 0041 00000000 0x0 0x0
0xffffda8000014b00 0041 00000000 0x0 0x0
0xffffda8000014b80 0041 00000000 0x0 0x0
0xffffda8000014c00 0041 00000000 0x0 0x0
0xffffda8000014c80 0041 00000000 0x0 0x0
0xffffda8000014d00 0041 00000000 0x0 0x0
0xffffda8000014d80 0041 00000000 0x0 0x0
0xffffda8000014e00 0041 00000000 0x0 0x0
0xffffda8000014e80 0041 00000000 0x0 0x0
0xffffda8000014f00 0041 00000000 0x0 0x0
0xffffda8000014f80 0041 00000000 0x0 0x0
0xffffda8000015000 0041 00000000 0x0 0x0
0xffffda8000015080 0041 00000000 0x0 0x0
0xffffda8000015100 0041 00000000 0x0 0x0
0xffffda8000015180 0041 00000000 0x0 0x0
0xffffda8000015200 0041 00000000 0x0 0x0
0xffffda8000015280 0041 00000000 0x0 0x0
0xffffda8000015300 0041 00000000 0x0 0x0
0xffffda8000015380 0041 00000000 0x0 0x0
0xffffda8000015400 0041 00000000 0x0 0x0
0xffffda8000015480 0041 00000000 0x0 0x0
0xffffda8000015500 0041 00000000 0x0 0x0
0xffffda8000015580 0041 00000000 0x0 0x0
0xffffda8000015600 0041 00000000 0x0 0x0
0xffffda8000015680 0041 00000000 0x0 0x0
0xffffda8000015700 0041 00000000 0x0 0x0
0xffffda8000015780 0041 00000000 0x0 0x0
0xffffda8000015800 0041 00000000 0x0 0x0
0xffffda8000015880 0041 00000000 0x0 0x0
0xffffda8000015900 0041 00000000 0x0 0x0
0xffffda8000015980 0041 00000000 0x0 0x0
0xffffda8000015a00 0041 00000000 0x0 0x0
0xffffda8000015a80 0041 00000000 0x0 0x0
0xffffda8000015b00 0041 00000000 0x0 0x0
0xffffda8000015b80 0041 00000000 0x0 0x0
0xffffda8000015c00 0041 00000000 0x0 0x0
0xffffda8000015c80 0041 00000000 0x0 0x0
0xffffda8000015d00 0041 00000000 0x0 0x0
0xffffda8000015d80 0041 00000000 0x0 0x0
0xffffda8000015e00 0041 00000000 0x0 0x0
0xffffda8000015e80 0041 00000000 0x0 0x0
0xffffda8000015f00 0041 00000000 0x0 0x0
0xffffda8000015f80 0041 00000000 0x0 0x0
0xffffda8000016000 0041 00000000 0x0 0x0
0xffffda8000016080 0041 00000000 0x0 0x0
0xffffda8000016100 0041 00000000 0x0 0x0
0xffffda8000016180 0041 00000000 0x0 0x0
0xffffda8000016200 0041 00000000 0x0 0x0
0xffffda8000016280 0041 00000000 0x0 0x0
0xffffda8000016300 0041 00000000 0x0 0x0
0xffffda8000016380 0041 00000000 0x0 0x0
0xffffda8000016400 0041 00000000 0x0 0x0
0xffffda8000016480 0041 00000000 0x0 0x0
0xffffda8000016500 0041 00000000 0x0 0x0
0xffffda8000016580 0041 00000000 0x0 0x0
0xffffda8000016600 0041 00000000 0x0 0x0
0xffffda8000016680 0041 00000000 0x0 0x0
0xffffda8000016700 0041 00000000 0x0 0x0
0xffffda8000016780 0041 00000000 0x0 0x0
0xffffda8000016800 0041 00000000 0x0 0x0
0xffffda8000016880 0041 00000000 0x0 0x0
0xffffda8000016900 0041 00000000 0x0 0x0
0xffffda8000016980 0041 00000000 0x0 0x0
0xffffda8000016a00 0041 00000000 0x0 0x0
0xffffda8000016a80 0041 00000000 0x0 0x0
0xffffda8000016b00 0041 00000000 0x0 0x0
0xffffda8000016b80 0041 00000000 0x0 0x0
0xffffda8000016c00 0041 00000000 0x0 0x0
0xffffda8000016c80 0041 00000000 0x0 0x0
0xffffda8000016d00 0041 00000000 0x0 0x0
0xffffda8000016d80 0041 00000000 0x0 0x0
0xffffda8000016e00 0041 00000000 0x0 0x0
0xffffda8000016e80 0041 00000000 0x0 0x0
0xffffda8000016f00 0041 00000000 0x0 0x0
0xffffda8000016f80 0041 00000000 0x0 0x0
0xffffda8000017000 0041 00000000 0x0 0x0
0xffffda8000017080 0041 00000000 0x0 0x0
0xffffda8000017100 0041 00000000 0x0 0x0
0xffffda8000017180 0041 00000000 0x0 0x0
0xffffda8000017200 0041 00000000 0x0 0x0
0xffffda8000017280 0041 00000000 0x0 0x0
0xffffda8000017300 0041 00000000 0x0 0x0
0xffffda8000017380 0041 00000000 0x0 0x0
0xffffda8000017400 0041 00000000 0x0 0x0
0xffffda8000017480 0041 00000000 0x0 0x0
0xffffda8000017500 0041 00000000 0x0 0x0
0xffffda8000017580 0041 00000000 0x0 0x0
0xffffda8000017600 0041 00000000 0x0 0x0
0xffffda8000017680 0041 00000000 0x0 0x0
0xffffda8000017700 0041 00000000 0x0 0x0
0xffffda8000017780 0041 00000000 0x0 0x0
0xffffda8000017800 0041 00000000 0x0 0x0
0xffffda8000017880 0041 00000000 0x0 0x0
0xffffda8000017900 0041 00000000 0x0 0x0
0xffffda8000017980 0041 00000000 0x0 0x0
0xffffda8000017a00 0041 00000000 0x0 0x0
0xffffda8000017a80 0041 00000000 0x0 0x0
0xffffda8000017b00 0041 00000000 0x0 0x0
0xffffda8000017b80 0041 00000000 0x0 0x0
0xffffda8000017c00 0041 00000000 0x0 0x0
0xffffda8000017c80 0041 00000000 0x0 0x0
0xffffda8000017d00 0041 00000000 0x0 0x0
0xffffda8000017d80 0041 00000000 0x0 0x0
0xffffda8000017e00 0041 00000000 0x0 0x0
0xffffda8000017e80 0041 00000000 0x0 0x0
0xffffda8000017f00 0041 00000000 0x0 0x0
0xffffda8000017f80 0041 00000000 0x0 0x0
0xffffda8000018000 0041 00000000 0x0 0x0
0xffffda8000018080 0041 00000000 0x0 0x0
0xffffda8000018100 0041 00000000 0x0 0x0
0xffffda8000018180 0041 00000000 0x0 0x0
0xffffda8000018200 0041 00000000 0x0 0x0
0xffffda8000018280 0041 00000000 0x0 0x0
0xffffda8000018300 0041 00000000 0x0 0x0
0xffffda8000018380 0041 00000000 0x0 0x0
0xffffda8000018400 0041 00000000 0x0 0x0
0xffffda8000018480 0041 00000000 0x0 0x0
0xffffda8000018500 0041 00000000 0x0 0x0
0xffffda8000018580 0041 00000000 0x0 0x0
0xffffda8000018600 0041 00000000 0x0 0x0
0xffffda8000018680 0041 00000000 0x0 0x0
0xffffda8000018700 0041 00000000 0x0 0x0
0xffffda8000018780 0041 00000000 0x0 0x0
0xffffda8000018800 0041 00000000 0x0 0x0
0xffffda8000018880 0041 00000000 0x0 0x0
0xffffda8000018900 0041 00000000 0x0 0x0
0xffffda8000018980 0041 00000000 0x0 0x0
0xffffda8000018a00 0041 00000000 0x0 0x0
0xffffda8000018a80 0041 00000000 0x0 0x0
0xffffda8000018b00 0041 00000000 0x0 0x0
0xffffda8000018b80 0041 00000000 0x0 0x0
0xffffda8000018c00 0041 00000000 0x0 0x0
0xffffda8000018c80 0041 00000000 0x0 0x0
0xffffda8000018d00 0041 00000000 0x0 0x0
0xffffda8000018d80 0041 00000000 0x0 0x0
0xffffda8000018e00 0041 00000000 0x0 0x0
0xffffda8000018e80 0041 00000000 0x0 0x0
0xffffda8000018f00 0041 00000000 0x0 0x0
0xffffda8000018f80 0041 00000000 0x0 0x0
0xffffda8000019000 0041 00000000 0x0 0x0
0xffffda8000019080 0041 00000000 0x0 0x0
0xffffda8000019100 0041 00000000 0x0 0x0
0xffffda8000019180 0041 00000000 0x0 0x0
0xffffda8000019200 0041 00000000 0x0 0x0
0xffffda8000019280 0041 00000000 0x0 0x0
0xffffda8000019300 0041 00000000 0x0 0x0
0xffffda8000019380 0041 00000000 0x0 0x0
0xffffda8000019400 0041 00000000 0x0 0x0
0xffffda8000019480 0041 00000000 0x0 0x0
0xffffda8000019500 0041 00000000 0x0 0x0
0xffffda8000019580 0041 00000000 0x0 0x0
0xffffda8000019600 0041 00000000 0x0 0x0
0xffffda8000019680 0041 00000000 0x0 0x0
0xffffda8000019700 0041 00000000 0x0 0x0
0xffffda8000019780 0041 00000000 0x0 0x0
0xffffda8000019800 0041 00000000 0x0 0x0
0xffffda8000019880 0041 00000000 0x0 0x0
0xffffda8000019900 0041 00000000 0x0 0x0
0xffffda8000019980 0041 00000000 0x0 0x0
0xffffda8000019a00 0041 00000000 0x0 0x0
0xffffda8000019a80 0041 00000000 0x0 0x0
0xffffda8000019b00 0041 00000000 0x0 0x0
0xffffda8000019b80 0041 00000000 0x0 0x0
0xffffda8000019c00 0041 00000000 0x0 0x0
0xffffda8000019c80 0041 00000000 0x0 0x0
0xffffda8000019d00 0041 00000000 0x0 0x0
0xffffda8000019d80 0041 00000000 0x0 0x0
0xffffda8000019e00 0041 00000000 0x0 0x0
0xffffda8000019e80 0041 00000000 0x0 0x0
0xffffda8000019f00 0041 00000000 0x0 0x0
0xffffda8000019f80 0041 00000000 0x0 0x0
0xffffda800001a000 0041 00000000 0x0 0x0
0xffffda800001a080 0041 00000000 0x0 0x0
0xffffda800001a100 0041 00000000 0x0 0x0
0xffffda800001a180 0041 00000000 0x0 0x0
0xffffda800001a200 0041 00000000 0x0 0x0
0xffffda800001a280 0041 00000000 0x0 0x0
0xffffda800001a300 0041 00000000 0x0 0x0
0xffffda800001a380 0041 00000000 0x0 0x0
0xffffda800001a400 0041 00000000 0x0 0x0
0xffffda800001a480 0041 00000000 0x0 0x0
0


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this bug, for details see:
https://goo.gl/tpsmEJ#testing-patches
Reply all
Reply to author
Forward
0 new messages