assert failed: lwpcnt >= 0

0 views
Skip to first unread message

syzbot

unread,
Feb 26, 2019, 8:17:05 AM2/26/19
to syzkaller-...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: ed61d1fdd6fd Add MI MII clause 45 MMD MDIO access macros v..
git tree: netbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=13507e5cc00000
dashboard link: https://syzkaller.appspot.com/bug?extid=6a430fda7379e7a59805

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+6a430f...@syzkaller.appspotmail.com

login: [ 89.4351715] panic: kernel diagnostic assertion "lwpcnt >= 0"
failed: file "/syzkaller/managers/netbsd/kernel/sys/kern/kern_uidinfo.c",
line 218
[ 89.4392118] cpu1: Begin traceback...
[ 89.4412360] vpanic() at netbsd:vpanic+0x214
[ 89.4493212] _GLOBAL__sub_D_65535_0_cpu_configure() at
netbsd:_GLOBAL__sub_D_65535_0_cpu_configure
[ 89.4574078] chglwpcnt() at netbsd:chglwpcnt+0x56
[ 89.4675147] lwp_free() at netbsd:lwp_free+0xf8
[ 89.4776223] lwp_wait() at netbsd:lwp_wait+0x11a
[ 89.4877298] exit_lwps() at netbsd:exit_lwps+0x1bd
[ 89.4978361] exit1() at netbsd:exit1+0xaa5
[ 89.5059222] sys_exit() at netbsd:sys_exit+0x6c
[ 89.5180507] syscall() at netbsd:syscall+0x30e
[ 89.5241158] --- syscall (number 1) ---
[ 89.5301798] 726ea1efe47a:
[ 89.5322002] cpu1: End traceback...

[ 89.5362437] dumping to dev 4,1 (offset=0, size=0): not possible
[ 89.5402864] rebooting...
SeaBIOS (version 1.8.2-20190204_181744-google)
Total RAM Size = 0x00000001e0000000 = 7680 MiB
CPUs found: 2 Max CPUs supported: 2
found virtio-scsi at 0:3
virtio-scsi vendor='Google' product='PersistentDisk' rev='1' type=0
removable=0
virtio-scsi blksize=512 sectors=4194304 = 2048 MiB
drive 0x000f2a00: PCHS=0/0/0 translation=lba LCHS=520/128/63 s=4194304
Booting from Hard Disk 0...

>> NetBSD/x86 BIOS Boot, Revision 5.10 (Tue Jul 17 14:59:51 UTC 2018) (from
>> NetBSD 8.0)
>> Memory: 639/3144640 k

1. Boot normally
2. Boot single user
3. Disable ACPI
4. Disable ACPI and SMP
5. Drop to boot prompt
| / - \ | / - 39065424\ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - +2877616\ | / - [1062168\ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / +1363032- \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / +1044595- \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ |
/ - \ | / - ]=0x2b4fbd8
\ | / - \ | / - \ | / - \ | / - \ | / - \ | / - \ | / - WARNING: couldn't
open /var/db/entropy-file
WARNING: 1 module failed to load


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#bug-status-tracking for how to communicate with
syzbot.

syzbot

unread,
Feb 26, 2019, 8:39:05 AM2/26/19
to syzkaller-...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: ed61d1fdd6fd Add MI MII clause 45 MMD MDIO access macros v..
git tree: netbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=10b0ee92c00000
dashboard link: https://syzkaller.appspot.com/bug?extid=6a430fda7379e7a59805
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=110e9b14c00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+6a430f...@syzkaller.appspotmail.com

[ 49.8769877] panic: kernel diagnostic assertion "lwpcnt >= 0" failed:
file "/syzkaller/managers/netbsd/kernel/sys/kern/kern_uidinfo.c", line 218
[ 49.8769877] cpu1: Begin traceback...
[ 49.8769877] vpanic() at netbsd:vpanic+0x214
[ 49.8870058] _GLOBAL__sub_D_65535_0_cpu_configure() at
netbsd:_GLOBAL__sub_D_65535_0_cpu_configure
[ 49.8970246] chglwpcnt() at netbsd:chglwpcnt+0x56
[ 49.9070448] lwp_free() at netbsd:lwp_free+0xf8
[ 49.9170637] lwp_wait() at netbsd:lwp_wait+0x11a
[ 49.9270830] exit_lwps() at netbsd:exit_lwps+0x1bd
[ 49.9371024] exit1() at netbsd:exit1+0xaa5
[ 49.9471202] sys_exit() at netbsd:sys_exit+0x6c
[ 49.9571402] syscall() at netbsd:syscall+0x30e
[ 49.9571402] --- syscall (number 1) ---
[ 49.9671583] 79886cefe47a:
[ 49.9671583] cpu1: End traceback...

[ 49.9771772] dumping to dev 4,1 (offset=0, size=0): not possible
[ 49.9771772] rebooting...

syzbot

unread,
Mar 10, 2019, 8:50:05 PM3/10/19
to syzkaller-...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 5e72195e Rename je_mallctltomib to je_mallctlnametomib
git tree: netbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=10d3516f200000
dashboard link: https://syzkaller.appspot.com/bug?extid=6a430fda7379e7a59805
userspace arch: amd64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=140c9f8d200000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=14e6e15f200000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+6a430f...@syzkaller.appspotmail.com

[ 1663.0220492] panic: kernel diagnostic assertion "lwpcnt >= 0" failed:
file "/syzkaller/managers/netbsd/kernel/sys/kern/kern_uidinfo.c", line 225
[ 1663.0220492] cpu1: Begin traceback...
[ 1663.0220492] vpanic() at netbsd:vpanic+0x214
[ 1663.0345939] _GLOBAL__sub_D_65535_0_cpu_configure() at
netbsd:_GLOBAL__sub_D_65535_0_cpu_configure
[ 1663.0345939] chglwpcnt() at netbsd:chglwpcnt+0x56
[ 1663.0471033] lwp_free() at netbsd:lwp_free+0xf8
[ 1663.0596302] lwp_wait() at netbsd:lwp_wait+0x11a
[ 1663.0721571] exit_lwps() at netbsd:exit_lwps+0x1c6
[ 1663.0846834] exit1() at netbsd:exit1+0xac6
[ 1663.0972096] sys_exit() at netbsd:sys_exit+0x6c
[ 1663.1097390] syscall() at netbsd:syscall+0x32e
[ 1663.1222633] --- syscall (number 1) ---
[ 1663.1347938] 7caa80afe47a:
[ 1663.1347938] cpu1: End traceback...

[ 1663.1347938] dumping to dev 4,1 (offset=0, size=0): not possible
[ 1663.1473166] rebooting...
SeaBIOS (version 1.8.2-20190122_225043-google)
Total RAM Size = 0x00000001e0000000 = 7680 MiB
CPUs found: 2 Max CPUs supported: 2
found virtio-scsi at 0:3
virtio-scsi vendor='Google' product='PersistentDisk' rev='1' type=0
removable=0
virtio-scsi blksize=512 sectors=4194304 = 2048 MiB
drive 0x000f29c0: PCHS=0/0/0 translation=lba LCHS=520/128/63 s=4194304
Reply all
Reply to author
Forward
0 new messages