protection_fault: lf_advlock (4)

1 view
Skip to first unread message

syzbot

unread,
Mar 19, 2024, 3:17:26 AMMar 19
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: a69db6767cfd Pass PHY OF node to the MII layer for use by ..
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=148b8711180000
kernel config: https://syzkaller.appspot.com/x/.config?x=7058272de1526588
dashboard link: https://syzkaller.appspot.com/bug?extid=7ce68750203264d6bfbf
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=157d1d66180000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=100c01f1180000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/fc3da15842e7/disk-a69db676.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/d07e2ef08d0f/bsd-a69db676.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/ae2603a92e10/kernel-a69db676.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+7ce687...@syzkaller.appspotmail.com

kernel: protection fault trap, code=0
Stopped at lf_advlock+0x225: incl 0x28(%r12)
ddb{1}>
ddb{1}> set $lines = 0
ddb{1}> set $maxwidth = 0
ddb{1}> show panic
the kernel did not panic
ddb{1}> trace
lf_advlock(ffff800000dd18e0,0,fffffd806d5c6ba8,2,ffff80002a222b00,40) at lf_advlock+0x225 ls_ref sys/kern/vfs_lockf.c:138 [inline]
lf_advlock(ffff800000dd18e0,0,fffffd806d5c6ba8,2,ffff80002a222b00,40) at lf_advlock+0x225 sys/kern/vfs_lockf.c:278
VOP_ADVLOCK(fffffd806c6150f0,fffffd806d5c6ba8,2,ffff80002a222b00,40) at VOP_ADVLOCK+0x75 sys/kern/vfs_vops.c:612
closef(fffffd806e545b58,ffff80002a187d60) at closef+0xe9
fdfree(ffff80002a187d60) at fdfree+0xe4 sys/kern/kern_descrip.c:1190
exit1(ffff80002a187d60,0,0,1) at exit1+0x3a0 sys/kern/kern_exit.c:199
sys_exit(ffff80002a187d60,ffff80002a222d50,ffff80002a222cb0) at sys_exit+0x1a sys/kern/kern_exit.c:89
syscall(ffff80002a222d50) at syscall+0x53b mi_syscall sys/sys/syscall_mi.h:183 [inline]
syscall(ffff80002a222d50) at syscall+0x53b sys/arch/amd64/amd64/trap.c:577
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x7c949edf1660, count: -8
ddb{1}> show registers
rdi 0
rsi 0
rbp 0xffff80002a222a50
rbx 0
rdx 0xa
rcx 0x9
rax 0
r8 0x30
r9 0x1
r10 0x80932b5a4f1b51fc
r11 0xa55bfdc2f55aa6de
r12 0xdeafbeaddeafbead
r13 0x2
r14 0xffff800000dd18e0
r15 0xffffffffffffffff
rip 0xffffffff813008d5 lf_advlock+0x225
cs 0x8
rflags 0x10246 __ALIGN_SIZE+0xf246
rsp 0xffff80002a2229c0
ss 0x10
lf_advlock+0x225: incl 0x28(%r12)
ddb{1}> show proc
PROC (syz-executor126314685) tid=373523 pid=52072 tcnt=1 stat=onproc
flags process=8000008<EXITING> proc=2000<WEXIT>
runpri=32, usrpri=50, slppri=32, nice=20
wchan=0x0, wmesg=, ps_single=0x0
forw=0xffffffffffffffff, list=0xffff80002a1882b0,0xffff80002a187820
process=0xffff8000ffff0d68 user=0xffff80002a21d000, vmspace=0xfffffd807ab2f010
estcpu=36, cpticks=0, pctcpu=0.0, user=0, sys=0, intr=0
ddb{1}> ps
PID TID PPID UID S FLAGS WAIT COMMAND
31792 385046 82052 0 3 0x8000000 lockflk syz-executor126314685
97857 116886 64941 0 3 0x8000000 lockflk syz-executor126314685
82052 88224 896 0 3 0x8000080 nanoslp syz-executor126314685
64941 374291 896 0 3 0x8000080 nanoslp syz-executor126314685
73631 214431 896 0 3 0x8000080 nanoslp syz-executor126314685
72219 183891 896 0 3 0x8000080 nanoslp syz-executor126314685
37545 466633 896 0 3 0x8000080 nanoslp syz-executor126314685
72749 58424 896 0 3 0x8000080 nanoslp syz-executor126314685
30764 21294 896 0 3 0x8000080 nanoslp syz-executor126314685
53784 307874 896 0 3 0x8000080 nanoslp syz-executor126314685
896 199422 64019 0 3 0x8000082 nanoslp syz-executor126314685
64019 104575 89224 0 3 0x810008a sigsusp ksh
89224 83564 79960 0 3 0x1800009a kqread sshd
41914 147726 1 0 3 0x18100083 ttyin getty
79960 146431 1 0 3 0x18000088 kqread sshd
72707 46929 87453 73 3 0x19100090 kqread syslogd
87453 182163 1 0 3 0x18100082 netio syslogd
86409 204017 1 0 3 0x18100080 kqread resolvd
40093 488990 13943 77 3 0x18100092 kqread dhcpleased
51793 131945 13943 77 3 0x18100092 kqread dhcpleased
13943 384003 1 0 3 0x18000080 kqread dhcpleased
47818 165877 0 0 3 0x14200 bored smr
96377 466269 0 0 3 0x14200 pgzero zerothread
68963 242179 0 0 3 0x14200 aiodoned aiodoned
74118 520660 0 0 3 0x14200 syncer update
30836 130211 0 0 3 0x14200 cleaner cleaner
84479 57517 0 0 3 0x14200 reaper reaper
6433 206270 0 0 3 0x14200 pgdaemon pagedaemon
16762 506985 0 0 3 0x14200 bored viomb
11212 16708 0 0 3 0x40014200 acpi0 acpi0
51907 244303 0 0 3 0x40014200 idle1
11981 496207 0 0 3 0x14200 bored softnet3
94379 241037 0 0 3 0x14200 bored softnet2
32446 209658 0 0 3 0x14200 bored softnet1
83410 387093 0 0 3 0x14200 bored softnet0
27381 427184 0 0 3 0x14200 bored systqmp
28262 223740 0 0 3 0x14200 bored systq
47499 42076 0 0 3 0x14200 tmoslp softclockmp
11281 232076 0 0 3 0x40014200 tmoslp softclock
93839 187848 0 0 7 0x40014200 idle0
1 446785 0 0 3 0x8000082 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb{1}> show all locks
ddb{1}> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 10165 6390K 6419K 166960K 11243 0
pcb 15 10K 10K 166960K 15 0
rtable 58 1K 2K 166960K 112 0
pf 12 6K 6K 166960K 12 0
ifaddr 12 9K 9K 166960K 12 0
ifgroup 17 1K 1K 166960K 17 0
counters 48 34K 34K 166960K 48 0
ioctlops 0 0K 2K 166960K 21 0
mount 1 1K 1K 166960K 1 0
log 0 0K 0K 166960K 4 0
vnodes 1259 79K 79K 166960K 88250 0
UFS quota 1 32K 32K 166960K 1 0
UFS mount 5 36K 36K 166960K 5 0
shm 2 1K 1K 166960K 2 0
VM map 2 1K 1K 166960K 2 0
sem 2 0K 0K 166960K 2 0
dirhash 12 2K 2K 166960K 12 0
ACPI 1697 195K 286K 166960K 12548 0
file desc 4 6K 17K 166960K 222460 0
proc 55 78K 79K 166960K 246 0
NFS srvsock 1 0K 0K 166960K 1 0
NFS daemon 1 16K 16K 166960K 1 0
in_multi 11 0K 0K 166960K 11 0
ether_multi 1 0K 0K 166960K 1 0
ISOFS mount 1 32K 32K 166960K 1 0
MSDOSFS mount 1 16K 16K 166960K 1 0
ttys 121 546K 546K 166960K 121 0
exec 0 0K 1K 166960K 246 0
tdb 3 0K 0K 166960K 3 0
VM swap 8 62K 64K 166960K 10 0
UVM amap 105 5K 6K 166960K 76580 0
UVM aobj 3 2K 2K 166960K 3 0
pinsyscall 32 64K 74K 166960K 75010 0
memdesc 1 4K 4K 166960K 1 0
crypto data 1 1K 1K 166960K 1 0
NDP 3 0K 0K 166960K 3 0
temp 1 6796K 6860K 166960K 2858 0
kqueue 11 16K 18K 166960K 24 0
SYN cache 2 16K 16K 166960K 2 0
ddb{1}> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg Idle
plcache 128 24 0 0 1 0 1 1 0 8 0
rtpcb 120 21 0 18 1 0 1 1 0 8 0
rtentry 112 23 0 1 1 0 1 1 0 8 0
unpcb 144 33 0 20 1 0 1 1 0 8 0
syncache 336 5 0 5 2 2 0 1 0 8 0
tcpqe 32 92 0 92 1 1 0 1 0 8 0
tcpcb 808 8 0 5 1 0 1 1 0 8 0
arp 120 2 0 0 1 0 1 1 0 8 0
inpcb 392 26 0 20 1 0 1 1 0 8 0
art_heap8 4096 1 0 0 1 0 1 1 0 8 0
art_heap4 256 97 0 0 7 0 7 7 0 8 0
art_table 32 98 0 0 1 0 1 1 0 8 0
art_node 16 22 0 2 1 0 1 1 0 8 0
dirhash 1024 17 0 0 3 0 3 3 0 8 0
dino2pl 256 88477 0 87015 92 0 92 92 0 8 0
ffsino 272 88477 0 87015 98 0 98 98 0 8 0
nchpl 144 88661 0 87022 61 0 61 61 0 8 0
uvmvnodes 80 5926 0 0 121 0 121 121 0 8 0
vnodes 216 5926 0 0 330 0 330 330 0 8 0
namei 1024 1190792 0 1190792 2 1 1 1 0 8 1
percpumem 16 38 0 0 1 0 1 1 0 8 0
kstatmem 264 6 0 0 1 0 1 1 0 8 0
scxspl 216 5544 0 5544 9 8 1 8 1 8 1
plimitpl 152 16 0 10 1 0 1 1 0 8 0
sigapl 424 74474 0 74427 6 0 6 6 0 8 0
knotepl 120 47 0 0 2 0 2 2 0 8 0
kqueuepl 216 20 0 13 1 0 1 1 0 8 0
pipepl 320 88 0 85 2 1 1 1 0 8 0
fdescpl 496 74456 0 74432 5 1 4 4 0 8 0
filepl 152 890963 0 890899 8 4 4 4 0 8 1
lockfpl 104 296615 0 296612 1 0 1 1 0 8 0
lockfspl 48 74157 0 74154 1 0 1 1 0 8 0
sessionpl 144 17 0 9 1 0 1 1 0 8 0
pgrppl 48 17 0 9 1 0 1 1 0 8 0
ucredpl 104 889893 0 889883 1 0 1 1 0 8 0
zombiepl 144 74433 0 74427 2 1 1 1 0 8 0
processpl 1136 74474 0 74427 4 0 4 4 0 8 0
procpl 680 74474 0 74427 4 0 4 4 0 8 0
sockpl 584 80 0 58 2 0 2 2 0 8 0
mcl8k 8192 2 0 0 1 0 1 1 0 8 0
mcl4k 4096 6 0 0 1 0 1 1 0 8 0
mcl2k 2048 299 0 0 33 9 24 33 0 8 0
mtagpl 96 3 0 0 1 0 1 1 0 8 0
mbufpl 256 324 0 0 18 1 17 18 0 8 0
bufpl 280 2481 0 84 172 0 172 172 0 8 0
anonpl 24 631968 0 630129 26 14 12 23 0 186 0
amapchunkpl 152 82641 0 82499 7 1 6 7 0 158 0
amappl16 200 79662 0 79659 6 5 1 5 0 8 0
amappl15 192 11 0 11 1 1 0 1 0 8 0
amappl14 184 162 0 153 1 0 1 1 0 8 0
amappl13 176 13 0 13 1 1 0 1 0 8 0
amappl12 168 826 0 814 1 0 1 1 0 8 0
amappl11 160 58 0 48 1 0 1 1 0 8 0
amappl10 152 17 0 17 2 2 0 1 0 8 0
amappl9 144 208 0 208 1 1 0 1 0 8 0
amappl8 136 33 0 32 2 1 1 1 0 8 0
amappl7 128 45 0 44 1 0 1 1 0 8 0
amappl6 120 174 0 163 1 0 1 1 0 8 0
amappl5 112 125 0 113 1 0 1 1 0 8 0
amappl4 104 74560 0 74524 2 0 2 2 0 8 1
amappl3 96 2166 0 2140 1 0 1 1 0 8 0
amappl2 88 74751 0 74697 2 0 2 2 0 8 0
amappl1 80 231350 0 230922 15 4 11 11 0 8 0
amappl 88 76274 0 76215 2 0 2 2 0 92 0
dma4096 4096 1 0 1 1 1 0 1 0 8 0
dma1024 1024 1 0 0 1 0 1 1 0 8 0
dma256 256 6 0 6 1 1 0 1 0 8 0
dma128 128 253 0 253 1 1 0 1 0 8 0
dma64 64 6 0 6 1 1 0 1 0 8 0
dma32 32 7 0 7 1 1 0 1 0 8 0
dma16 16 18 0 17 1 0 1 1 0 8 0
aobjpl 72 2 0 0 1 0 1 1 0 8 0
uaddrrnd 24 74457 0 74433 1 0 1 1 0 8 0
uaddrbest 32 2 0 0 1 0 1 1 0 8 0
uaddr 24 74457 0 74433 1 0 1 1 0 8 0
vmmpekpl 168 208064 0 208047 1 0 1 1 0 8 0
vmmpepl 168 1221380 0 1220314 66 16 50 50 0 357 2
vmsppl 448 74456 0 74433 9 5 4 4 0 8 1
rwobjpl 56 97719 0 91187 94 1 93 93 0 8 0
pdppl 4096 148921 0 148866 121 62 59 65 0 8 4
pvpl 32 6275 0 0 51 0 51 51 0 265 0
pmappl 248 74456 0 74433 3 1 2 2 0 8 0
extentpl 40 56 0 38 1 0 1 1 0 8 0
phpool 112 398 0 82 10 0 10 10 0 8 0
ddb{1}> machine ddbcpu 0
Stopped at x86_ipi_db+0x1e: addq $0x8,%rsp
ddb{0}> trace
x86_ipi_db(ffffffff82d54ff0) at x86_ipi_db+0x1e sys/arch/amd64/amd64/db_interface.c:393
x86_ipi_handler() at x86_ipi_handler+0xb7 sys/arch/amd64/amd64/ipi.c:106
Xresume_lapic_ipi() at Xresume_lapic_ipi+0x27
acpicpu_idle() at acpicpu_idle+0x2f1 sys/dev/acpi/acpicpu.c:1206
sched_idle(ffffffff82d54ff0) at sched_idle+0x41d sys/kern/kern_sched.c:183
end trace frame: 0x0, count: -5
ddb{0}> machine ddbcpu 1
Stopped at lf_advlock+0x225: incl 0x28(%r12)
ddb{1}> trace
lf_advlock(ffff800000dd18e0,0,fffffd806d5c6ba8,2,ffff80002a222b00,40) at lf_advlock+0x225 ls_ref sys/kern/vfs_lockf.c:138 [inline]
lf_advlock(ffff800000dd18e0,0,fffffd806d5c6ba8,2,ffff80002a222b00,40) at lf_advlock+0x225 sys/kern/vfs_lockf.c:278
VOP_ADVLOCK(fffffd806c6150f0,fffffd806d5c6ba8,2,ffff80002a222b00,40) at VOP_ADVLOCK+0x75 sys/kern/vfs_vops.c:612
closef(fffffd806e545b58,ffff80002a187d60) at closef+0xe9
fdfree(ffff80002a187d60) at fdfree+0xe4 sys/kern/kern_descrip.c:1190
exit1(ffff80002a187d60,0,0,1) at exit1+0x3a0 sys/kern/kern_exit.c:199
sys_exit(ffff80002a187d60,ffff80002a222d50,ffff80002a222cb0) at sys_exit+0x1a sys/kern/kern_exit.c:89
syscall(ffff80002a222d50) at syscall+0x53b mi_syscall sys/sys/syscall_mi.h:183 [inline]
syscall(ffff80002a222d50) at syscall+0x53b sys/arch/amd64/amd64/trap.c:577
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x7c949edf1660, count: -8


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages