page fault in solocked2

0 views
Skip to first unread message

syzbot

unread,
May 16, 2019, 3:00:07 AM5/16/19
to syzkaller-...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: edebeed8 Add md_clear.
git tree: netbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=15db3164a00000
dashboard link: https://syzkaller.appspot.com/bug?extid=6e49265469a527c78432

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+6e4926...@syzkaller.appspotmail.com

[ 583.9022469] fatal page fault in supervisor mode
[ 583.9146341] trap type 6 code 0 rip 0xffffffff80fd4b6c cs 0x8 rflags
0x10287 cr2 0xffff900000000000 ilevel 0 rsp 0xffffdb016efc1ab8
[ 583.9282589] curlwp 0xffffdb0012f94140 pid 2648.3 lowest kstack
0xffffdb016efba2c0
[ 583.9357204] panic: trap
[ 583.9357204] cpu0: Begin traceback...
[ 583.9423105] vpanic() at netbsd:vpanic+0x214
[ 583.9523099] snprintf() at netbsd:snprintf
[ 583.9623234] startlwp() at netbsd:startlwp
[ 583.9623234] alltraps() at netbsd:alltraps+0xb2
[ 583.9733582] solocked2() at netbsd:solocked2+0x1e
[ 583.9826089] unp_accept() at netbsd:unp_accept+0xfe
[ 583.9931420] do_sys_accept() at netbsd:do_sys_accept+0x2f4
[ 584.0031850] sys_accept() at netbsd:sys_accept+0xac
[ 584.0126429] sys___syscall() at netbsd:sys___syscall+0xe2
[ 584.0230856] syscall() at netbsd:syscall+0x348
[ 584.0335794] --- syscall (number 198) ---
[ 584.0424270] 7cfbb3c3f4aa:
[ 584.0424270] cpu0: End traceback...

[ 584.0424270] dumping to dev 4,1 (offset=0, size=0): not possible
[ 584.0424270] rebooting...
SeaBIOS (version 1.8.2-20190308_060531-google)
Total RAM Size = 0x00000001e0000000 = 7680 MiB
CPUs found: 2 Max CPUs supported: 2
found virtio-scsi at 0:3
virtio-scsi vendor='Google' product='PersistentDisk' rev='1' type=0
removable=0
virtio-scsi blksize=512 sectors=4194304 = 2048 MiB
drive 0x000f29d0: PCHS=0/0/0 translation=lba LCHS=520/128/63 s=4194304
Booting from Hard Disk 0...

>> NetBSD/x86 BIOS Boot, Revision 5.10 (Tue Jul 17 14:59:51 UTC 2018) (from
>> NetBSD 8.0)
>> Memory: 639/3144640 k

1. Boot normally
2. Boot single user
3. Disable ACPI
4. Disable ACPI and SMP
5. Drop to boot prompt


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
May 16, 2019, 3:19:05 AM5/16/19
to syzkaller-...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: edebeed8 Add md_clear.
git tree: netbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=15a0c608a00000
dashboard link: https://syzkaller.appspot.com/bug?extid=6e49265469a527c78432
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=11c60db2a00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=12f965b2a00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+6e4926...@syzkaller.appspotmail.com

[ 28.0409520] fatal page fault in supervisor mode
[ 28.0509673] trap type 6 code 0 rip 0xffffffff80fd4b6c cs 0x8 rflags
0x10287 cr2 0xffff900000000000 ilevel 0 rsp 0xffffae816eb0fab8
[ 28.0609838] curlwp 0xffffae8011f42ac0 pid 830.3 lowest kstack
0xffffae816eb082c0
[ 28.0710005] panic: trap
[ 28.0710005] cpu1: Begin traceback...
[ 28.0710005] vpanic() at netbsd:vpanic+0x214
[ 28.0810200] snprintf() at netbsd:snprintf
[ 28.0910331] startlwp() at netbsd:startlwp
[ 28.1010488] alltraps() at netbsd:alltraps+0xb2
[ 28.1110638] solocked2() at netbsd:solocked2+0x1e
[ 28.1210798] unp_accept() at netbsd:unp_accept+0xfe
[ 28.1310973] do_sys_accept() at netbsd:do_sys_accept+0x2f4
[ 28.1411132] sys_accept() at netbsd:sys_accept+0xac
[ 28.1511277] sys_syscall() at netbsd:sys_syscall+0xe2
[ 28.1611448] syscall() at netbsd:syscall+0x348
[ 28.1711597] --- syscall (number 0) ---
[ 28.1811789] 77ff26e3f4ca:
[ 28.1811789] cpu1: End traceback...

[ 28.1811789] dumping to dev 4,1 (offset=0, size=0): not possible
[ 28.1911919] rebooting...
Reply all
Reply to author
Forward
0 new messages