pool: free list modified: sockpl (3)

0 views
Skip to first unread message

syzbot

unread,
Sep 18, 2022, 10:44:35 PM9/18/22
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 076ab34a56d3 Allow TLSv1.3 clients to send CCS without mid..
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=11c242f8880000
kernel config: https://syzkaller.appspot.com/x/.config?x=7058272de1526588
dashboard link: https://syzkaller.appspot.com/bug?extid=2a9771c648cecb40bd67

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/213141cd2d41/disk-076ab34a.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/d4d57a6d9595/bsd-076ab34a.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/f7442080b61f/kernel-076ab34a.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+2a9771...@syzkaller.appspotmail.com

panic: pool_do_get: sockpl free list modified: page 0xfffffd806e45a000; item addr 0xfffffd806e45a203; offset 0x0=0xffbfc00859bf0455 != 0x859bf045577d0ab
Stopped at db_enter+0x18: addq $0x8,%rsp
TID PID UID PRFLAGS PFLAGS CPU COMMAND
48815 48681 0 0 0x4000000 0 syz-executor.4
*257335 21142 0 0 0x4000000 1 syz-executor.1
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:437
panic(ffffffff82640c0f) at panic+0x177 sys/kern/subr_prf.c:198
pool_do_get(ffffffff82b0b8b0,9,ffff80002981a9a8) at pool_do_get+0x436 sys/kern/subr_pool.c:738
pool_get(ffffffff82b0b8b0,9) at pool_get+0xe9 sys/kern/subr_pool.c:582
socreate(2,ffff80002981aa78,1,0) at socreate+0xb1 soalloc sys/kern/uipc_socket.c:146 [inline]
socreate(2,ffff80002981aa78,1,0) at socreate+0xb1 sys/kern/uipc_socket.c:177
sys_socket(ffff800028073268,ffff80002981ab08,ffff80002981ab50) at sys_socket+0xd8 sys/kern/uipc_syscalls.c:98
syscall(ffff80002981abd0) at syscall+0x4c3 mi_syscall sys/sys/syscall_mi.h:101 [inline]
syscall(ffff80002981abd0) at syscall+0x4c3 sys/arch/amd64/amd64/trap.c:585
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x556beae4b80, count: 7
https://www.openbsd.org/ddb.html describes the minimum info required in bug
reports. Insufficient info makes it difficult to find and fix bugs.
ddb{1}>
ddb{1}> set $lines = 0
ddb{1}> set $maxwidth = 0
ddb{1}> show panic
*cpu1: pool_do_get: sockpl free list modified: page 0xfffffd806e45a000; item addr 0xfffffd806e45a203; offset 0x0=0xffbfc00859bf0455 != 0x859bf045577d0ab
ddb{1}> trace
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:437
panic(ffffffff82640c0f) at panic+0x177 sys/kern/subr_prf.c:198
pool_do_get(ffffffff82b0b8b0,9,ffff80002981a9a8) at pool_do_get+0x436 sys/kern/subr_pool.c:738
pool_get(ffffffff82b0b8b0,9) at pool_get+0xe9 sys/kern/subr_pool.c:582
socreate(2,ffff80002981aa78,1,0) at socreate+0xb1 soalloc sys/kern/uipc_socket.c:146 [inline]
socreate(2,ffff80002981aa78,1,0) at socreate+0xb1 sys/kern/uipc_socket.c:177
sys_socket(ffff800028073268,ffff80002981ab08,ffff80002981ab50) at sys_socket+0xd8 sys/kern/uipc_syscalls.c:98
syscall(ffff80002981abd0) at syscall+0x4c3 mi_syscall sys/sys/syscall_mi.h:101 [inline]
syscall(ffff80002981abd0) at syscall+0x4c3 sys/arch/amd64/amd64/trap.c:585
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x556beae4b80, count: -8
ddb{1}> show registers
rdi 0
rsi 0x1
rbp 0xffff80002981a7f0
rbx 0xffff800020dd9b8f
rdx 0
rcx 0
rax 0xffff800028073268
r8 0x101010101010101
r9 0x8080808080808080
r10 0x9e6d1832600b8792
r11 0x9f587de0e7b4b9f
r12 0xffff800020dd9990
r13 0
r14 0
r15 0x1
rip 0xffffffff821849f8 db_enter+0x18
cs 0x8
rflags 0x246
rsp 0xffff80002981a7e0
ss 0x10
db_enter+0x18: addq $0x8,%rsp
ddb{1}> show proc
PROC (syz-executor.1) pid=257335 stat=onproc
flags process=0 proc=4000000<THREAD>
pri=32, usrpri=86, nice=20
forw=0xffffffffffffffff, list=0xffff800028072a88,0xffff8000280737b8
process=0xffff8000fffee588 user=0xffff800029815000, vmspace=0xfffffd806ae065d0
estcpu=36, cpticks=2, pctcpu=0.0
user=0, sys=1, intr=0
ddb{1}> ps
PID TID PPID UID S FLAGS WAIT COMMAND
48681 392656 87102 0 2 0 syz-executor.4
48681 48815 87102 0 7 0x4000000 syz-executor.4
35511 405967 42318 0 3 0x80 nanoslp syz-executor.3
35511 196419 42318 0 3 0x4000080 fsleep syz-executor.3
35511 413709 42318 0 3 0x4000080 fsleep syz-executor.3
21142 246553 96654 0 2 0 syz-executor.1
*21142 257335 96654 0 7 0x4000000 syz-executor.1
58992 42886 16913 0 3 0x1 kernel: protection fault trap, code=0
Faulted in DDB; continuing...
ddb{1}> show all locks
CPU 1:
exclusive mutex sockpl r = 0 (0xffffffff82b0b8c0)
#0 witness_lock+0x44d
#1 mtx_enter_try+0x100
#2 mtx_enter+0x4b sys/kern/kern_lock.c:266
#3 pool_get+0xbd sys/kern/subr_pool.c:579
#4 socreate+0xb1 soalloc sys/kern/uipc_socket.c:146 [inline]
#4 socreate+0xb1 sys/kern/uipc_socket.c:177
#5 sys_socket+0xd8 sys/kern/uipc_syscalls.c:98
#6 syscall+0x4c3 mi_syscall sys/sys/syscall_mi.h:101 [inline]
#6 syscall+0x4c3 sys/arch/amd64/amd64/trap.c:585
#7 Xsyscall+0x128
Process 48681 (syz-executor.4) thread 0xffff8000280737a8 (48815)
ddb{1}> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 10226 6554K 8925K 78643K 17624 0
pcb 13 14K 16K 78643K 694 0
rtable 181 20K 22K 78643K 1530 0
ifaddr 119 26K 29K 78643K 642 0
sysctl 2 0K 2K 78643K 38 0
counters 50 34K 36K 78643K 220 0
ioctlops 0 0K 4K 78643K 2524 0
iov 0 0K 24K 78643K 542 0
mount 1 1K 1K 78643K 1 0
log 0 0K 0K 78643K 4 0
vnodes 1555 97K 97K 78643K 4005 0
UFS quota 1 32K 32K 78643K 1 0
UFS mount 5 36K 36K 78643K 5 0
shm 2 1K 5K 78643K 38 0
VM map 2 1K 1K 78643K 2 0
sem 12 0K 1K 78643K 456 0
dirhash 12 2K 2K 78643K 12 0
ACPI 1697 195K 286K 78643K 12548 0
file desc 13 45K 89K 78643K 4797 0
sigio 0 0K 0K 78643K 411 0
proc 71 91K 128K 78643K 1453 0
subproc 91 5K 6K 78643K 442 0
NFS srvsock 1 0K 0K 78643K 1 0
NFS daemon 1 16K 16K 78643K 1 0
ip_moptions 0 0K 0K 78643K 306 0
in_multi 56 3K 6K 78643K 529 0
ether_multi 1 0K 0K 78643K 41 0
mrt 1 0K 0K 78643K 7 0
ISOFS mount 1 32K 32K 78643K 1 0
MSDOSFS mount 1 16K 16K 78643K 1 0
ttys 169 758K 758K 78643K 169 0
exec 0 0K 2K 78643K 2088 0
tdb 3 0K 0K 78643K 3 0
pagedep 1 8K 8K 78643K 1 0
inodedep 1 32K 32K 78643K 1 0
newblk 1 0K 0K 78643K 1 0
VM swap 8 62K 64K 78643K 10 0
UVM amap 350 426K 439K 78643K 30446 0
UVM aobj 131 4K 4K 78643K 131 0
memdesc 1 4K 4K 78643K 1 0
crypto data 1 1K 1K 78643K 1 0
ip6_options 0 0K 0K 78643K 123 0
NDP 13 0K 1K 78643K 163 0
temp 129 4734K 5374K 78643K 55952 0
kqueue 12 18K 28K 78643K 360 0
SYN cache 2 16K 16K 78643K 2 0
ddb{1}> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg Idle
plcache 128 22 0 0 1 0 1 1 0 8 0
rtpcb 120 346 0 343 4 3 1 3 0 8 0
rtentry 112 455 0 395 4 0 4 4 0 8 1
unpcb 144 3802 0 3787 37 31 6 6 0 8 5
syncache 296 31 0 31 9 9 0 1 0 8 0
tcpqe 32 125 0 125 3 3 0 1 0 8 0
tcpcb 768 6396 0 6362 145 136 9 23 0 8 5
arp 120 72 0 61 1 0 1 1 0 8 0
inpcb 368 8453 0 8444 76 68 8 13 0 8 7
nd6 48 111 0 95 1 0 1 1 0 8 0
pkpcb 40 71 0 71 2 2 0 1 0 8 0
kcovpl 48 34 0 27 1 0 1 1 0 8 0
ppxss 1256 49 0 49 6 6 0 1 0 8 0
pfstscr 40 7 0 7 3 3 0 1 0 8 0
pffrag 232 22 0 19 3 2 1 1 0 482 0
pffrnode 88 22 0 19 3 2 1 1 0 8 0
pffrent 40 46 0 43 3 2 1 1 0 8 0
pfosfp 40 1428 0 1005 5 0 5 5 0 8 0
pfosfpen 112 1428 0 714 21 0 21 21 0 8 0
pfrktable 1344 28 0 18 1 0 1 1 0 8 0
pfanchor 1280 218 0 32 16 0 16 16 0 8 0
pfpktdelay 88 1 0 1 1 1 0 1 0 8 0
pftag 88 75 0 68 2 1 1 1 0 8 0
pfstitem 24 31 0 29 1 0 1 1 0 8 0
pfstkey 120 41 0 39 1 0 1 1 0 8 0
pfstate 336 34 0 32 2 1 1 2 0 8 0
pfrule 1360 204 0 160 7 3 4 4 0 8 0
rttmr 136 3 0 3 1 1 0 1 0 8 0
art_heap8 4096 3 0 2 3 2 1 2 0 8 0
art_heap4 256 2043 0 1783 35 14 21 29 0 8 0
art_table 32 2046 0 1785 4 0 4 4 0 8 0
art_node 16 449 0 398 1 0 1 1 0 8 0
sysvmsgpl 40 93 0 70 1 0 1 1 0 8 0
semupl 112 3 0 3 1 1 0 1 0 8 0
semapl 112 449 0 439 1 0 1 1 0 8 0
shmpl 112 128 0 0 4 0 4 4 0 8 0
dirhash 1024 17 0 0 3 0 3 3 0 8 0
dino2pl 256 7476 0 6010 93 0 93 93 0 8 0
ffsino 272 7476 0 6010 99 0 99 99 0 8 0
nchpl 144 13939 0 12302 63 0 63 63 0 8 0
rtmask 32 8 0 8 3 3 0 1 0 8 0
uvmvnodes 80 5926 0 0 121 0 121 121 0 8 0
vnodes 216 5926 0 0 330 0 330 330 0 8 0
namei 1024 51294 0 51293 3 2 1 2 0 8 0
percpumem 16 122 0 85 1 0 1 1 0 8 0
vcpupl 2048 26 0 0 4 0 4 4 0 8 0
vmpool 568 97 0 71 2 0 2 2 0 8 0
pfiaddrpl 120 15 0 3 1 0 1 1 0 8 0
kstatmem 264 176 0 150 4 1 3 3 0 8 0
scxspl 216 39244 0 39244 20 18 2 8 0 8 2
plimitpl 152 1065 0 1050 1 0 1 1 0 8 0
sigapl 424 5081 0 5015 9 1 8 8 0 8 0
futexpl 64 40304 0 40302 1 0 1 1 0 8 0
knotepl 120 762 0 0 18 0 18 18 0 8 0
kqueuepl 216 950 0 942 15 14 1 5 0 8 0
pipepl 320 1151 0 1126 30 24 6 8 0 8 3
fdescpl 496 5042 0 5016 5 0 5 5 0 8 1
filepl 152 36851 0 36629 75 60 15 23 0 8 4
lockfpl 104 1293 0 1291 4 3 1 2 0 8 0
lockfspl 48 464 0 462 1 0 1 1 0 8 0
sessionpl 144 50 0 34 1 0 1 1 0 8 0
pgrppl 48 59 0 43 1 0 1 1 0 8 0
ucredpl 104 3669 0 3655 1 0 1 1 0 8 0
zombiepl 144 5016 0 5015 1 0 1 1 0 8 0
processpl 1064 5081 0 5015 5 0 5 5 0 8 0
procpl 672 14044 0 13959 17 8 9 10 0 8 0
srpgc 96 64 0 64 8 7 1 1 0 8 1
sosppl 168 16 0 16 4 4 0 1 0 8 0
sockpl 488 12678 0 12651 195 182 13 29 0 8 9
sockpl: pool(0xffffffff82b0b8b0:sockpl): free list modified: page 0xfffffd806e45a000; item ordinal 0; addr 0xfffffd806e45a203 (p 0xfffffd806e45a000); offset 0x0=0xffbfc00859bf0455
pool(sockpl): free list modified: page 0xfffffd806e45a000; item ordinal 0; addr 0xfffffd806e45a203 (p 0xfffffd806e45a000); offset 0x0=0xad4110de
sockpl: pool(0xffffffff82b0b8b0:sockpl): page inconsistency: page 0xfffffd806e45a000; item ordinal 1; addr 0xb9bbc979a59e0ab6
mcl64k 65536 18 0 0 3 0 3 3 0 8 0
mcl16k 16384 10 0 0 2 0 2 2 0 8 0
mcl12k 12288 17 0 0 2 0 2 2 0 8 0
mcl9k 9216 13 0 0 1 0 1 1 0 8 0
mcl8k 8192 17 0 0 3 0 3 3 0 8 0
mcl4k 4096 25 0 0 4 1 3 3 0 8 0
mcl2k2 2112 8 0 0 1 0 1 1 0 8 0
mcl2k 2048 302 0 0 33 1 32 33 0 8 0
mtagpl 96 384 0 0 7 0 7 7 0 8 0
mbufpl 256 1300 0 0 73 0 73 73 0 8 0
bufpl 288 10966 0 4627 454 0 454 454 0 8 0
anonpl 24 1003817 0 989656 193 62 131 137 0 186 12
amapchunkpl 152 98448 0 97796 66 35 31 41 0 158 0
amappl16 200 14775 0 14184 93 49 44 47 0 8 10
amappl15 192 520 0 517 3 2 1 1 0 8 0
amappl14 184 907 0 901 1 0 1 1 0 8 0
amappl13 176 621 0 616 1 0 1 1 0 8 0
amappl12 168 872 0 870 2 1 1 1 0 8 0
amappl11 160 420 0 400 3 1 2 2 0 8 0
amappl10 152 1133 0 1128 1 0 1 1 0 8 0
amappl9 144 932 0 925 1 0 1 1 0 8 0
amappl8 136 1406 0 1315 4 0 4 4 0 8 0
amappl7 128 491 0 469 1 0 1 1 0 8 0
amappl6 120 784 0 762 2 1 1 2 0 8 0
amappl5 112 4763 0 4747 1 0 1 1 0 8 0
amappl4 104 2189 0 2154 2 0 2 2 0 8 0
amappl3 96 15449 0 15394 2 0 2 2 0 8 0
amappl2 88 1500 0 1440 3 1 2 3 0 8 0
amappl1 80 127238 0 126497 23 5 18 23 0 8 0
amappl 88 29388 0 29201 6 1 5 5 0 92 0
dma4096 4096 1 0 1 1 1 0 1 0 8 0
dma1024 1024 1 0 0 1 0 1 1 0 8 0
dma256 256 6 0 6 1 1 0 1 0 8 0
dma128 128 253 0 253 1 1 0 1 0 8 0
dma64 64 6 0 6 1 1 0 1 0 8 0
dma32 32 7 0 7 1 1 0 1 0 8 0
dma16 16 18 0 17 1 0 1 1 0 8 0
aobjpl 72 130 0 0 3 0 3 3 0 8 0
uaddrrnd 24 5139 0 5087 1 0 1 1 0 8 0
uaddrbest 32 2 0 0 1 0 1 1 0 8 0
uaddr 24 5139 0 5087 1 0 1 1 0 8 0
vmmpekpl 168 45118 0 45047 4 0 4 4 0 8 0
vmmpepl 168 506966 0 504254 218 75 143 154 0 357 2
vmsppl 368 5138 0 5087 6 0 6 6 0 8 0
rwobjpl 56 130917 0 123087 122 6 116 116 0 8 3
pdppl 4096 10285 0 10200 403 310 93 95 0 8 8
pvpl 32 2019375 0 2000288 342 124 218 265 0 265 19
pmappl 248 5138 0 5087 4 0 4 4 0 8 0
extentpl 40 56 0 38 1 0 1 1 0 8 0
phpool 112 1315 0 410 27 0 27 27 0 8 0
ddb{1}> machine ddbcpu 0
Stopped at x86_ipi_db+0x1a: addq $0x8,%rsp
x86_ipi_db(ffffffff82939ff0) at x86_ipi_db+0x1a sys/arch/amd64/amd64/db_interface.c:393
x86_ipi_handler() at x86_ipi_handler+0xb7 sys/arch/amd64/amd64/ipi.c:106
Xresume_lapic_ipi() at Xresume_lapic_ipi+0x23
__mp_lock(ffffffff82a452c8) at __mp_lock+0x122 __mp_lock_spin sys/kern/kern_lock.c:116 [inline]
__mp_lock(ffffffff82a452c8) at __mp_lock+0x122 sys/kern/kern_lock.c:147
__mp_acquire_count(ffffffff82a452c8,1) at __mp_acquire_count+0x48 sys/kern/kern_lock.c:227
mi_switch() at mi_switch+0x3bb sys/kern/sched_bsd.c:415
sleep_finish(ffff800029844620,1) at sleep_finish+0x180 sys/kern/kern_synch.c:417
tsleep(fffffd8073a69280,11,ffffffff8262181c,0) at tsleep+0x12c sys/kern/kern_synch.c:155
biowait(fffffd8073a69280) at biowait+0x91 sys/kern/vfs_bio.c:1268
bwrite(fffffd8073a69280) at bwrite+0x21b sys/kern/vfs_bio.c:769
ffs_update(fffffd806ee4f780,1) at ffs_update+0x27d sys/ufs/ffs/ffs_inode.c:113
ufs_makeinode(1fe9,fffffd8064850440,ffff800029844af0,ffff800029844b20) at ufs_makeinode+0x489 sys/ufs/ufs/ufs_vnops.c:1852
ufs_mknod(ffff800029844990) at ufs_mknod+0x4e sys/ufs/ufs/ufs_vnops.c:171
VOP_MKNOD(fffffd8064850440,ffff800029844af0,ffff800029844b20,ffff800029844a20) at VOP_MKNOD+0xbf sys/kern/vfs_vops.c:121
end trace frame: 0xffff800029844be0, count: 0
ddb{0}> trace
x86_ipi_db(ffffffff82939ff0) at x86_ipi_db+0x1a sys/arch/amd64/amd64/db_interface.c:393
x86_ipi_handler() at x86_ipi_handler+0xb7 sys/arch/amd64/amd64/ipi.c:106
Xresume_lapic_ipi() at Xresume_lapic_ipi+0x23
__mp_lock(ffffffff82a452c8) at __mp_lock+0x122 __mp_lock_spin sys/kern/kern_lock.c:116 [inline]
__mp_lock(ffffffff82a452c8) at __mp_lock+0x122 sys/kern/kern_lock.c:147
__mp_acquire_count(ffffffff82a452c8,1) at __mp_acquire_count+0x48 sys/kern/kern_lock.c:227
mi_switch() at mi_switch+0x3bb sys/kern/sched_bsd.c:415
sleep_finish(ffff800029844620,1) at sleep_finish+0x180 sys/kern/kern_synch.c:417
tsleep(fffffd8073a69280,11,ffffffff8262181c,0) at tsleep+0x12c sys/kern/kern_synch.c:155
biowait(fffffd8073a69280) at biowait+0x91 sys/kern/vfs_bio.c:1268
bwrite(fffffd8073a69280) at bwrite+0x21b sys/kern/vfs_bio.c:769
ffs_update(fffffd806ee4f780,1) at ffs_update+0x27d sys/ufs/ffs/ffs_inode.c:113
ufs_makeinode(1fe9,fffffd8064850440,ffff800029844af0,ffff800029844b20) at ufs_makeinode+0x489 sys/ufs/ufs/ufs_vnops.c:1852
ufs_mknod(ffff800029844990) at ufs_mknod+0x4e sys/ufs/ufs/ufs_vnops.c:171
VOP_MKNOD(fffffd8064850440,ffff800029844af0,ffff800029844b20,ffff800029844a20) at VOP_MKNOD+0xbf sys/kern/vfs_vops.c:121
domknodat(ffff8000280737a8,ffffff9c,20000100,1ffb,0) at domknodat+0x326 sys/kern/vfs_syscalls.c:1628
syscall(ffff800029844cc0) at syscall+0x435 mi_syscall sys/sys/syscall_mi.h:101 [inline]
syscall(ffff800029844cc0) at syscall+0x435 sys/arch/amd64/amd64/trap.c:585
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x37245104270, count: -17
ddb{0}> machine ddbcpu 1
Stopped at db_enter+0x18: addq $0x8,%rsp
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:437
panic(ffffffff82640c0f) at panic+0x177 sys/kern/subr_prf.c:198
pool_do_get(ffffffff82b0b8b0,9,ffff80002981a9a8) at pool_do_get+0x436 sys/kern/subr_pool.c:738
pool_get(ffffffff82b0b8b0,9) at pool_get+0xe9 sys/kern/subr_pool.c:582
socreate(2,ffff80002981aa78,1,0) at socreate+0xb1 soalloc sys/kern/uipc_socket.c:146 [inline]
socreate(2,ffff80002981aa78,1,0) at socreate+0xb1 sys/kern/uipc_socket.c:177
sys_socket(ffff800028073268,ffff80002981ab08,ffff80002981ab50) at sys_socket+0xd8 sys/kern/uipc_syscalls.c:98
syscall(ffff80002981abd0) at syscall+0x4c3 mi_syscall sys/sys/syscall_mi.h:101 [inline]
syscall(ffff80002981abd0) at syscall+0x4c3 sys/arch/amd64/amd64/trap.c:585
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x556beae4b80, count: 7
ddb{1}> trace
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:437
panic(ffffffff82640c0f) at panic+0x177 sys/kern/subr_prf.c:198
pool_do_get(ffffffff82b0b8b0,9,ffff80002981a9a8) at pool_do_get+0x436 sys/kern/subr_pool.c:738
pool_get(ffffffff82b0b8b0,9) at pool_get+0xe9 sys/kern/subr_pool.c:582
socreate(2,ffff80002981aa78,1,0) at socreate+0xb1 soalloc sys/kern/uipc_socket.c:146 [inline]
socreate(2,ffff80002981aa78,1,0) at socreate+0xb1 sys/kern/uipc_socket.c:177
sys_socket(ffff800028073268,ffff80002981ab08,ffff80002981ab50) at sys_socket+0xd8 sys/kern/uipc_syscalls.c:98
syscall(ffff80002981abd0) at syscall+0x4c3 mi_syscall sys/sys/syscall_mi.h:101 [inline]
syscall(ffff80002981abd0) at syscall+0x4c3 sys/arch/amd64/amd64/trap.c:585
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x556beae4b80, count: -8


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
Reply all
Reply to author
Forward
0 new messages