uvm_fault: ml_enlist

1 view
Skip to first unread message

syzbot

unread,
Jan 16, 2020, 5:28:12 PM1/16/20
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 70e79057 Link iked live test to build. To operate it need..
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=179ec001e00000
kernel config: https://syzkaller.appspot.com/x/.config?x=fe55924c11e64b0a
dashboard link: https://syzkaller.appspot.com/bug?extid=271b2b25d53d960c271e

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+271b2b...@syzkaller.appspotmail.com

uvm_fault(0xfffffd806bc09110, 0x8, 0, 2) -> e
kernel: page fault trap, code=0
Stopped at ml_enlist+0x5c: movq %rbx,0x8(%rax)
ddb>
ddb> set $lines = 0
ddb> set $maxwidth = 0
ddb> show panic
kernel page fault
uvm_fault(0xfffffd806bc09110, 0x8, 0, 2) -> e
ml_enlist(ffff800020495628,ffff800000a1c700) at ml_enlist+0x5c
sys/kern/uipc_mbuf.c:1582
end trace frame: 0xffff800020495670, count: 0
ddb> trace
ml_enlist(ffff800020495628,ffff800000a1c700) at ml_enlist+0x5c
sys/kern/uipc_mbuf.c:1582
ifq_purge(ffff800000a2aa78) at ifq_purge+0x5d sys/net/ifq.c:414
if_down(ffff800000a2a800) at if_down+0x9c if_linkstate sys/net/if.c:1677
[inline]
if_down(ffff800000a2a800) at if_down+0x9c sys/net/if.c:1628
ifioctl(fffffd805d8ede18,80206910,ffff800020495780,ffff8000ffff8770) at
ifioctl+0x176d sys/net/if.c:2015
sys_ioctl(ffff8000ffff8770,ffff800020495898,ffff8000204958e0) at
sys_ioctl+0x498
syscall(ffff800020495960) at syscall+0x507 sys/arch/amd64/amd64/trap.c:570
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0xc1ffbb4f900, count: -7
ddb> show registers
rdi 0xffffffff81da3e18 ml_enlist+0x58
rsi 0x4a
rbp 0xffff800020495610
rbx 0xfffffd8059e76700
rdx 0x4b
rcx 0xffff800020637000
rax 0
r8 0x101010101010101
r9 0x7
r10 0x134c98a0a3ee61ad
r11 0x58f41cd072edeefc
r12 0x6
r13 0
r14 0xffff800000a1c700
r15 0xffff800020495628
rip 0xffffffff81da3e1c ml_enlist+0x5c
cs 0x8
rflags 0x10246 __ALIGN_SIZE+0xf246
rsp 0xffff8000204955d0
ss 0x10
ml_enlist+0x5c: movq %rbx,0x8(%rax)
ddb> show proc
PROC (syz-executor.0) pid=174291 stat=onproc
flags process=0 proc=4000000<THREAD>
pri=77, usrpri=77, nice=20
forw=0xffffffffffffffff, list=0xffff8000ffff89e8,0xffffffff825900a0
process=0xffff80001d39b0f8 user=0xffff800020490000,
vmspace=0xfffffd806bc09110
estcpu=36, cpticks=0, pctcpu=0.0
user=0, sys=0, intr=0
ddb> ps
PID TID PPID UID S FLAGS WAIT COMMAND
39729 153019 84446 0 2 0 syz-executor.0
*39729 174291 84446 0 7 0x4000000 syz-executor.0
2555 482807 65987 0 2 0 syz-executor.1
2555 256944 65987 0 3 0x4000080 fsleep syz-executor.1
21675 471344 1 0 3 0x100083 ttyin getty
65987 16208 19678 0 3 0x82 nanosleep syz-executor.1
84446 192859 19678 0 3 0x82 nanosleep syz-executor.0
74650 117615 0 0 3 0x14200 acct acct
8381 389836 0 0 3 0x14200 bored sosplice
19678 387109 12160 0 3 0x82 thrsleep syz-fuzzer
19678 162171 12160 0 3 0x4000082 nanosleep syz-fuzzer
19678 3696 12160 0 3 0x4000082 thrsleep syz-fuzzer
19678 34051 12160 0 3 0x4000082 thrsleep syz-fuzzer
19678 716 12160 0 3 0x4000082 kqread syz-fuzzer
19678 248022 12160 0 3 0x4000082 thrsleep syz-fuzzer
19678 168397 12160 0 3 0x4000082 thrsleep syz-fuzzer
19678 76807 12160 0 3 0x4000082 thrsleep syz-fuzzer
12160 244640 10761 0 3 0x10008a pause ksh
10761 141328 31315 0 3 0x92 select sshd
31315 151778 1 0 3 0x80 select sshd
50281 168825 8757 73 3 0x100090 kqread syslogd
8757 6065 1 0 3 0x100082 netio syslogd
32644 105523 1 77 3 0x100090 poll dhclient
83194 145340 1 0 3 0x80 poll dhclient
89664 247472 0 0 2 0x14200 zerothread
57299 80455 0 0 3 0x14200 aiodoned aiodoned
34386 162461 0 0 3 0x14200 syncer update
25644 294449 0 0 3 0x14200 cleaner cleaner
19010 354024 0 0 3 0x14200 reaper reaper
73622 290360 0 0 3 0x14200 pgdaemon pagedaemon
41462 439936 0 0 3 0x14200 bored crynlk
48309 36057 0 0 3 0x14200 bored crypto
86503 248066 0 0 3 0x40014200 acpi0 acpi0
21035 146061 0 0 3 0x14200 bored softnet
67942 381287 0 0 3 0x14200 bored systqmp
48544 333543 0 0 3 0x14200 bored systq
51369 358643 0 0 3 0x40014200 bored softclock
35934 62923 0 0 3 0x40014200 idle0
62721 514962 0 0 3 0x14200 bored smr
1 186719 0 0 3 0x82 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb> show all locks
No such command
ddb> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 9544 6383K 7031K 78643K 12629 0
pcb 13 10K 12K 78643K 208 0
rtable 129 4K 5K 78643K 798 0
ifaddr 101 18K 19K 78643K 763 0
counters 19 16K 16K 78643K 19 0
ioctlops 0 0K 2K 78643K 138 0
iov 0 0K 16K 78643K 332 0
mount 1 1K 1K 78643K 1 0
vnodes 1221 77K 77K 78643K 3463 0
UFS quota 1 32K 32K 78643K 1 0
UFS mount 5 36K 36K 78643K 5 0
shm 2 1K 5K 78643K 25 0
VM map 2 0K 0K 78643K 2 0
sem 12 0K 1K 78643K 249 0
dirhash 12 2K 2K 78643K 12 0
ACPI 1794 195K 288K 78643K 12646 0
file desc 6 17K 25K 78643K 2865 0
sigio 0 0K 0K 78643K 42 0
proc 51 46K 55K 78643K 730 0
subproc 32 2K 2K 78643K 136 0
NFS srvsock 1 0K 0K 78643K 1 0
NFS daemon 1 16K 16K 78643K 1 0
ip_moptions 0 0K 0K 78643K 80 0
in_multi 80 4K 4K 78643K 229 0
ether_multi 1 0K 0K 78643K 32 0
mrt 0 0K 0K 78643K 18 0
ISOFS mount 1 32K 32K 78643K 1 0
MSDOSFS mount 1 16K 16K 78643K 1 0
ttys 85 387K 387K 78643K 85 0
exec 0 0K 1K 78643K 419 0
pagedep 1 8K 8K 78643K 1 0
inodedep 1 32K 32K 78643K 1 0
newblk 1 0K 0K 78643K 1 0
VM swap 7 26K 26K 78643K 7 0
UVM amap 146 136K 142K 78643K 7610 0
UVM aobj 87 3K 3K 78643K 92 0
memdesc 1 4K 4K 78643K 1 0
crypto data 1 1K 1K 78643K 1 0
ip6_options 0 0K 0K 78643K 199 0
NDP 17 0K 0K 78643K 67 0
temp 150 3015K 3082K 78643K 44366 0
kqueue 3 4K 18K 78643K 106 0
SYN cache 2 16K 16K 78643K 2 0
ddb> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg
Idle
arp 64 27 0 17 1 0 1 1 0
8 0
rtpcb 80 135 0 133 1 0 1 1 0
8 0
rtentry 112 135 0 85 2 0 2 2 0
8 0
unpcb 120 621 0 613 1 0 1 1 0
8 0
syncache 264 10 0 10 3 3 0 1 0
8 0
sackhl 24 1 0 1 1 1 0 1 0
8 0
tcpqe 32 222 0 222 1 1 0 1 0
8 0
tcpcb 544 945 0 941 12 11 1 11 0
8 0
ipq 40 7 0 7 6 5 1 1 0
8 1
ipqe 40 191 0 191 6 5 1 1 0
8 1
inpcb 280 2955 0 2945 16 14 2 9 0
8 1
rttmr 72 7 0 7 3 3 0 1 0
8 0
ip6q 72 2 0 2 1 1 0 1 0
8 0
ip6af 40 6 0 6 1 1 0 1 0
8 0
nd6 48 17 0 13 1 0 1 1 0
8 0
pkpcb 40 8 0 8 3 2 1 1 0
8 1
ppxss 1128 24 0 24 5 4 1 1 0
8 1
art_heap8 4096 2 0 0 2 0 2 2 0
8 0
art_heap4 256 581 0 333 21 5 16 16 0
8 0
art_table 32 583 0 333 3 0 3 3 0
8 0
art_node 16 134 0 89 1 0 1 1 0
8 0
sysvmsgpl 40 2 0 2 1 1 0 1 0
8 0
semupl 112 1 0 1 1 1 0 1 0
8 0
semapl 112 245 0 235 1 0 1 1 0
8 0
shmpl 112 90 0 5 3 0 3 3 0
8 0
dirhash 1024 17 0 0 3 0 3 3 0
8 0
dino1pl 128 6729 0 5333 46 0 46 46 0
8 0
ffsino 240 6729 0 5333 83 0 83 83 0
8 0
nchpl 144 11211 0 9610 60 0 60 60 0
8 0
uvmvnodes 72 5926 0 0 108 0 108 108 0
8 0
vnodes 208 5926 0 0 312 0 312 312 0
8 0
namei 1024 32394 0 32394 1 0 1 1 0
8 1
vcpupl 1984 12 0 0 2 0 2 2 0
8 0
vmpool 528 18 0 6 1 0 1 1 0
8 0
scsiplug 64 2 0 2 1 1 0 1 0
8 0
scxspl 192 28663 0 28663 1 0 1 1 0
8 1
plimitpl 152 108 0 101 1 0 1 1 0
8 0
sigapl 432 3020 0 3006 2 0 2 2 0
8 0
futexpl 56 52146 0 52145 1 0 1 1 0
8 0
knotepl 112 280 0 261 1 0 1 1 0
8 0
kqueuepl 104 476 0 474 4 3 1 4 0
8 0
pipelkpl 16 394 0 384 1 0 1 1 0
8 0
pipepl 120 788 0 769 2 1 1 2 0
8 0
fdescpl 432 3021 0 3006 2 0 2 2 0
8 0
filepl 120 18611 0 18514 12 8 4 11 0
8 1
lockfpl 104 1092 0 1091 1 0 1 1 0
8 0
lockfspl 48 346 0 345 1 0 1 1 0
8 0
sessionpl 112 25 0 15 1 0 1 1 0
8 0
pgrppl 48 45 0 35 1 0 1 1 0
8 0
ucredpl 96 2331 0 2324 1 0 1 1 0
8 0
zombiepl 144 3006 0 3006 1 0 1 1 0
8 1
processpl 864 3037 0 3006 4 0 4 4 0
8 0
procpl 632 6579 0 6539 8 4 4 5 0
8 0
sosppl 128 18 0 18 4 3 1 1 0
8 1
sockpl 400 3758 0 3740 23 20 3 14 0
8 1
mcl64k 65536 618 0 618 72 39 33 33 0 8
33
mcl16k 16384 43 0 43 8 8 0 1 0
8 0
mcl12k 12288 125 0 125 5 4 1 1 0
8 1
mcl9k 9216 27 0 27 9 8 1 1 0
8 1
mcl8k 8192 445 0 445 2 1 1 1 0
8 1
mcl4k 4096 107 0 107 9 8 1 1 0
8 1
mcl2k2 2112 13 0 13 6 5 1 1 0
8 1
mcl2k 2048 65258 0 65197 22 13 9 17 0
8 0
mtagpl 80 52 0 32 3 2 1 1 0
8 0
mbufpl 256 122563 0 122407 87 68 19 35 0
8 8
bufpl 280 11192 0 5008 442 0 442 442 0
8 0
anonpl 16 254549 0 239271 108 30 78 79 0 107
10
amapchunkpl 152 12951 0 12807 33 25 8 20 0
158 1
amappl16 192 13970 0 13074 88 35 53 57 0
8 8
amappl15 184 655 0 651 1 0 1 1 0
8 0
amappl14 176 1140 0 1137 1 0 1 1 0
8 0
amappl13 168 114 0 114 1 1 0 1 0
8 0
amappl12 160 17 0 16 1 0 1 1 0
8 0
amappl11 152 972 0 959 1 0 1 1 0
8 0
amappl10 144 189 0 186 1 0 1 1 0
8 0
amappl9 136 823 0 820 1 0 1 1 0
8 0
amappl8 128 380 0 348 2 0 2 2 0
8 0
amappl7 120 301 0 288 1 0 1 1 0
8 0
amappl6 112 964 0 953 1 0 1 1 0
8 0
amappl5 104 235 0 225 1 0 1 1 0
8 0
amappl4 96 2220 0 2188 1 0 1 1 0
8 0
amappl3 88 2389 0 2377 1 0 1 1 0
8 0
amappl2 80 23445 0 23368 3 1 2 3 0
8 0
amappl1 72 57351 0 56918 25 16 9 20 0
8 0
amappl 80 6900 0 6847 3 1 2 2 0
84 0
dma4096 4096 1 0 1 1 1 0 1 0
8 0
dma256 256 6 0 6 1 1 0 1 0
8 0
dma128 128 253 0 253 1 1 0 1 0
8 0
dma64 64 6 0 6 1 1 0 1 0
8 0
dma32 32 7 0 7 1 1 0 1 0
8 0
dma16 16 18 0 17 1 0 1 1 0
8 0
aobjpl 64 91 0 5 2 0 2 2 0
8 0
uaddrrnd 24 3039 0 3012 1 0 1 1 0
8 0
uaddrbest 32 2 0 0 1 0 1 1 0
8 0
uaddr 24 3039 0 3012 1 0 1 1 0
8 0
vmmpekpl 168 18352 0 18322 2 0 2 2 0
8 0
vmmpepl 168 350468 0 348351 161 62 99 117 0
357 6
vmsppl 272 3038 0 3012 3 1 2 2 0
8 0
pdppl 4096 6084 0 6036 9 2 7 7 0
8 0
pvpl 32 702929 0 684504 262 78 184 187 0 265
25
pmappl 200 3038 0 3012 2 0 2 2 0
8 0
extentpl 40 46 0 29 1 0 1 1 0
8 0
phpool 112 359 0 178 6 0 6 6 0
8 0


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Apr 15, 2020, 6:28:10 PM4/15/20
to syzkaller-o...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages