uvm_fault: hardclock (5)

0 views
Skip to first unread message

syzbot

unread,
Mar 3, 2023, 9:04:40 AM3/3/23
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 1e5b016c5082 sync for __syscall removal
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=104481f2c80000
kernel config: https://syzkaller.appspot.com/x/.config?x=1bc15e68cd2a49e5
dashboard link: https://syzkaller.appspot.com/bug?extid=21738f9ef88044fa22da

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/452af0b271ef/disk-1e5b016c.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/5145fa4f4c7c/bsd-1e5b016c.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/992507fc6105/kernel-1e5b016c.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+21738f...@syzkaller.appspotmail.com

kernel: page fault trap, code=0
Stopped at hardclock+0x106: movq 0x260(%r14),%r15
ddb>
ddb> set $lines = 0
ddb> set $maxwidth = 0
ddb> show panic
the kernel did not panic
ddb> trace
hardclock(ffff80002e8d9450) at hardclock+0x106 sys/kern/kern_clock.c:149
clockintr_dispatch(ffff80002e8d9450) at clockintr_dispatch+0x1a8 sys/kern/kern_clockintr.c:196
lapic_clockintr(0,0) at lapic_clockintr+0x36 sys/arch/amd64/amd64/lapic.c:483
Xresume_lapic_ltimer() at Xresume_lapic_ltimer+0x26
pmap_kenter_pa(ffff800026c60000,5004c000,3) at pmap_kenter_pa+0x187 pmap_tlb_shootpage sys/arch/amd64/amd64/pmap.c:3377 [inline]
pmap_kenter_pa(ffff800026c60000,5004c000,3) at pmap_kenter_pa+0x187 sys/arch/amd64/amd64/pmap.c:519
buf_map(fffffd80683b5900) at buf_map+0x21d sys/kern/vfs_biomem.c:120
buf_get(0,0,1000ecf0) at buf_get+0x739 sys/kern/vfs_bio.c:1179
geteblk(1000ecf0) at geteblk+0x2c sys/kern/vfs_bio.c:1061
readdisklabel(2902,ffffffff81a39c40,ffff800000c9de00,0) at readdisklabel+0x145 sys/arch/amd64/amd64/disksubr.c:96
vndopen(2902,1,2000,ffff8000265b0b20) at vndopen+0x17a sys/dev/vnd.c:203
spec_open(ffff80002e8d9928) at spec_open+0x3df sys/kern/spec_vnops.c:150
VOP_OPEN(fffffd806edfed00,1,fffffd807f7d7958,ffff8000265b0b20) at VOP_OPEN+0x6c sys/kern/vfs_vops.c:138
vn_open(ffff80002e8d9b78,1,0) at vn_open+0x467 sys/kern/vfs_vnops.c:177
doopenat(ffff8000265b0b20,ffffff9c,200022c0,0,0,ffff80002e8d9d50) at doopenat+0x26a sys/kern/vfs_syscalls.c:1127
syscall(ffff80002e8d9dd0) at syscall+0x4a4 sys/arch/amd64/amd64/trap.c:625
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x86f2a513030, count: -16
ddb> show registers
rdi 0x3
rsi 0
rbp 0xffff80002e8d9380
rbx 0x1
rdx 0
rcx 0x679c112200
rax 0xffff8000265b0b20
r8 0
r9 0
r10 0
r11 0xa2757594453096ab
r12 0xffff8000265b0b20
r13 0
r14 0
r15 0
rip 0xffffffff81db7a16 hardclock+0x106
cs 0x8
rflags 0x10246 __ALIGN_SIZE+0xf246
rsp 0xffff80002e8d9350
ss 0x10
hardclock+0x106: movq 0x260(%r14),%r15
ddb> show proc
PROC (kernel: page fault trap, code=0
Faulted in DDB; continuing...
ddb> ps
PID TID PPID UID S FLAGS WAIT COMMAND
ddb> show all locks
No such command
ddb> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 10197 6414K 6833K 78643K 12403 0
pcb 13 16K 18K 78643K 1290 0
rtable 146 14K 16K 78643K 1739 0
ifaddr 67 20K 24K 78643K 467 0
sysctl 2 0K 0K 78643K 2 0
counters 25 17K 17K 78643K 131 0
ioctlops 0 0K 4K 78643K 327 0
iov 0 0K 24K 78643K 713 0
mount 1 1K 1K 78643K 1 0
log 0 0K 0K 78643K 4 0
vnodes 1405 88K 88K 78643K 3488 0
UFS quota 1 32K 32K 78643K 1 0
UFS mount 5 36K 36K 78643K 5 0
shm 2 1K 5K 78643K 29 0
VM map 2 1K 1K 78643K 2 0
sem 12 0K 0K 78643K 797 0
dirhash 12 2K 2K 78643K 12 0
ACPI 1697 195K 286K 78643K 12548 0
file desc 17 61K 77K 78643K 4644 0
sigio 0 0K 0K 78643K 35 0
proc 53 42K 83K 78643K 1499 0
subproc 117 7K 7K 78643K 520 0
NFS srvsock 1 0K 0K 78643K 1 0
NFS daemon 1 16K 16K 78643K 1 0
ip_moptions 0 0K 0K 78643K 315 0
in_multi 53 3K 6K 78643K 542 0
ether_multi 1 0K 0K 78643K 31 0
mrt 1 0K 0K 78643K 30 0
ISOFS mount 1 32K 32K 78643K 1 0
MSDOSFS mount 1 16K 16K 78643K 1 0
ttys 169 758K 758K 78643K 169 0
exec 0 0K 1K 78643K 1197 0
pfkey data 0 0K 0K 78643K 3 0
tdb 3 0K 0K 78643K 3 0
pagedep 1 8K 8K 78643K 1 0
inodedep 1 32K 32K 78643K 1 0
newblk 1 0K 0K 78643K 1 0
VM swap 8 62K 64K 78643K 10 0
UVM amap 283 94K 108K 78643K 31754 0
UVM aobj 47 6K 6K 78643K 57 0
memdesc 1 4K 4K 78643K 1 0
crypto data 1 1K 1K 78643K 1 0
ip6_options 0 0K 0K 78643K 117 0
NDP 10 0K 1K 78643K 178 0
temp 124 5770K 5898K 78643K 62951 0
kqueue 8 14K 24K 78643K 391 0
SYN cache 2 16K 16K 78643K 2 0
ddb> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg Idle
rtpcb 120 733 0 732 11 9 2 4 0 8 1
rtentry 112 516 0 457 4 0 4 4 0 8 0
unpcb 144 11656 0 11640 71 67 4 10 0 8 2
syncache 296 52 0 52 15 15 0 1 0 8 0
tcpqe 32 183 0 183 4 4 0 1 0 8 0
tcpcb 776 1376 0 1371 65 61 4 11 0 8 3
arp 88 84 0 74 1 0 1 1 0 8 0
ipq 40 1 0 1 1 1 0 1 0 8 0
ipqe 40 1 0 1 1 1 0 1 0 8 0
inpcb 336 4682 0 4677 82 75 7 12 0 8 6
nd6 48 125 0 113 1 0 1 1 0 8 0
pkpcb 40 5 0 5 2 2 0 1 0 8 0
kcovpl 48 40 0 31 1 0 1 1 0 8 0
mppekey 1024 6 0 6 2 2 0 1 0 8 0
ppxss 1160 61 0 61 11 11 0 1 0 8 0
pppxif 1360 5 0 5 1 1 0 1 0 8 0
pfstscr 40 56 0 45 1 0 1 1 0 8 0
pfosfp 40 2 0 1 1 0 1 1 0 8 0
pfosfpen 112 2 0 1 1 0 1 1 0 8 0
pfanchor 1280 504 0 62 42 5 37 37 0 8 0
pfstitem 24 24 0 6 1 0 1 1 0 8 0
pfstkey 128 108 0 98 1 0 1 1 0 8 0
pfstate 352 54 0 45 1 0 1 1 0 8 0
rttmr 136 6 0 6 2 2 0 1 0 8 0
art_heap8 4096 10 0 8 7 5 2 3 0 8 0
art_heap4 256 2156 0 1902 43 19 24 29 0 8 0
art_table 32 2166 0 1910 4 0 4 4 0 8 0
art_node 16 507 0 457 1 0 1 1 0 8 0
sysvmsgpl 40 10 0 2 1 0 1 1 0 8 0
semapl 112 795 0 785 1 0 1 1 0 8 0
shmpl 112 54 0 10 2 0 2 2 0 8 0
dirhash 1024 17 0 0 3 0 3 3 0 8 0
dirhash: pool(0xffffffff82bd74a8:dirhash): free list modified: page 0xffff8000216b1000; item ordinal 0; addr 0xffff8000216b2000 (p 0xfffffd806e762000); offset 0x0=0x0
pool(dirhash): free list modified: page 0xffff8000216b1000; item ordinal 0; addr 0xffff8000216b2000 (p 0xfffffd806e762000); offset 0x0=0x0
dirhash: pool(0xffffffff82bd74a8:dirhash): page inconsistency: page 0xffff8000216b1000; item ordinal 1; addr 0x352c87e45e3cc9aa
dino2pl 256 7208 0 5776 91 0 91 91 0 8 0
ffsino 240 7208 0 5776 85 0 85 85 0 8 0
nchpl 144 13360 0 11719 63 1 62 63 0 8 0
rtmask 32 2 0 2 1 1 0 1 0 8 0
uvmvnodes 80 5926 0 0 121 0 121 121 0 8 0
vnodes 216 5926 0 0 330 0 330 330 0 8 0
namei 1024 50484 0 50484 4 3 1 3 0 8 1
namei: pool(0xffffffff82c74a18:namei): free list modified: page 0xffff80002169d000; item ordinal 0; addr 0xffff80002169e000 (p 0xfffffd80672be000); offset 0x0=0x0
pool(namei): free list modified: page 0xffff80002169d000; item ordinal 0; addr 0xffff80002169e000 (p 0xfffffd80672be000); offset 0x0=0x0
namei: pool(0xffffffff82c74a18:namei): page inconsistency: page 0xffff80002169d000; item ordinal 1; addr 0x63c4eefddcd21fad
vmpool 664 4 0 4 1 1 0 1 0 8 0
kstatmem 264 194 0 174 2 0 2 2 0 8 0
scxspl 216 36676 0 36673 13 11 2 8 0 8 1
plimitpl 152 836 0 821 1 0 1 1 0 8 0
sigapl 424 5034 0 4971 8 0 8 8 0 8 0
futexpl 64 47425 0 47418 1 0 1 1 0 8 0
knotepl 120 86657 0 86591 38 31 7 12 0 8 3
kqueuepl 184 986 0 977 18 17 1 7 0 8 0
pipepl 288 1306 0 1277 34 27 7 10 0 8 4
fdescpl 432 4857 0 4832 4 0 4 4 0 8 0
filepl 120 42050 0 41806 88 76 12 19 0 8 2
lockfpl 104 1065 0 1063 5 4 1 2 0 8 0
lockfspl 48 328 0 326 1 0 1 1 0 8 0
sessionpl 144 55 0 39 1 0 1 1 0 8 0
pgrppl 48 196 0 180 1 0 1 1 0 8 0
ucredpl 104 4427 0 4415 1 0 1 1 0 8 0
zombiepl 144 4972 0 4971 2 1 1 1 0 8 0
processpl 1008 5034 0 4971 13 4 9 9 0 8 0
processpl: pool(0xffffffff82cf3698:processpl): page inconsistency: page 0x0; at page head addr 0xffff8000265cbf90 (p 0xffff8000265ca000)
procpl 696 12611 0 12525 19 10 9 10 0 8 0
procpl: pool(0xffffffff82cf34f0:procpl): page inconsistency: page 0x0; at page head addr 0xffff8000265b1f90 (p 0xffff8000265b0000)
procpl: pool(0xffffffff82cf34f0:procpl): page inconsistency: page 0x0; at page head addr 0xffff8000216e5f90 (p 0xffff8000216e4000)
sosppl 168 42 0 42 7 7 0 1 0 8 0
sockpl 456 17083 0 17061 391 379 12 34 0 8 8
mcl64k 65536 167 0 167 17 16 1 1 0 8 1
mcl16k 16384 94 0 94 17 16 1 1 0 8 1
mcl12k 12288 132 0 132 17 16 1 1 0 8 1
mcl9k 9216 70 0 70 17 17 0 1 0 8 0
mcl8k 8192 294 0 294 12 11 1 1 0 8 1
mcl4k 4096 559 0 559 5 4 1 1 0 8 1
mcl2k2 2112 31 0 31 18 17 1 1 0 8 1
mcl2k 2048 86395 0 86353 43 36 7 32 0 8 1
mtagpl 96 13 0 13 5 5 0 1 0 8 0
mbufpl 256 196573 0 196510 684 665 19 207 0 8 8
bufpl 288 9885 0 3491 457 0 457 457 0 8 0
anonpl 24 1008441 0 990485 204 84 120 132 0 188 6
amapchunkpl 152 87826 0 87105 48 16 32 42 0 158 0
amappl16 200 11653 0 11066 107 71 36 44 0 8 4
amappl15 192 11 0 10 1 0 1 1 0 8 0
amappl14 184 269 0 261 2 1 1 2 0 8 0
amappl13 176 8 0 8 2 2 0 1 0 8 0
amappl12 168 777 0 775 1 0 1 1 0 8 0
amappl11 160 47 0 43 1 0 1 1 0 8 0
amappl10 152 65 0 56 1 0 1 1 0 8 0
amappl9 144 993 0 992 1 0 1 1 0 8 0
amappl8 136 291 0 231 3 0 3 3 0 8 0
amappl7 128 213 0 191 2 0 2 2 0 8 0
amappl6 120 304 0 297 2 1 1 2 0 8 0
amappl5 112 300 0 296 1 0 1 1 0 8 0
amappl4 104 859 0 834 2 1 1 2 0 8 0
amappl3 96 13464 0 13415 2 0 2 2 0 8 0
amappl2 88 5467 0 5411 3 0 3 3 0 8 0
amappl1 80 111545 0 110912 29 14 15 26 0 8 0
amappl 88 30901 0 30724 5 0 5 5 0 92 0
dma4096 4096 1 0 1 1 1 0 1 0 8 0
dma1024 1024 1 0 0 1 0 1 1 0 8 0
dma256 256 6 0 6 1 1 0 1 0 8 0
dma128 128 253 0 253 1 1 0 1 0 8 0
dma64 64 6 0 6 1 1 0 1 0 8 0
dma32 32 7 0 7 1 1 0 1 0 8 0
dma16 16 18 0 17 1 0 1 1 0 8 0
aobjpl 72 56 0 10 1 0 1 1 0 8 0
uaddrrnd 24 4861 0 4836 1 0 1 1 0 8 0
uaddrbest 32 2 0 0 1 0 1 1 0 8 0
uaddr 24 4861 0 4836 1 0 1 1 0 8 0
vmmpekpl 168 42395 0 42327 4 0 4 4 0 8 0
vmmpepl 168 465081 0 462548 338 215 123 162 0 357 4
vmsppl 344 4860 0 4836 3 0 3 3 0 8 0
rwobjpl 24 126506 0 118972 49 2 47 48 0 8 0
pdppl 4096 9728 0 9672 520 460 60 70 0 8 4
pvpl 32 2003986 0 1981074 506 301 205 336 0 265 12
pmappl 216 4860 0 4836 2 0 2 2 0 8 0
extentpl 40 56 0 38 1 0 1 1 0 8 0
phpool 112 2110 0 1342 28 1 27 28 0 8 0
ddb> machine ddbcpu 0
No such command
ddb> trace
hardclock(ffff80002e8d9450) at hardclock+0x106 sys/kern/kern_clock.c:149
clockintr_dispatch(ffff80002e8d9450) at clockintr_dispatch+0x1a8 sys/kern/kern_clockintr.c:196
lapic_clockintr(0,0) at lapic_clockintr+0x36 sys/arch/amd64/amd64/lapic.c:483
Xresume_lapic_ltimer() at Xresume_lapic_ltimer+0x26
pmap_kenter_pa(ffff800026c60000,5004c000,3) at pmap_kenter_pa+0x187 pmap_tlb_shootpage sys/arch/amd64/amd64/pmap.c:3377 [inline]
pmap_kenter_pa(ffff800026c60000,5004c000,3) at pmap_kenter_pa+0x187 sys/arch/amd64/amd64/pmap.c:519
buf_map(fffffd80683b5900) at buf_map+0x21d sys/kern/vfs_biomem.c:120
buf_get(0,0,1000ecf0) at buf_get+0x739 sys/kern/vfs_bio.c:1179
geteblk(1000ecf0) at geteblk+0x2c sys/kern/vfs_bio.c:1061
readdisklabel(2902,ffffffff81a39c40,ffff800000c9de00,0) at readdisklabel+0x145 sys/arch/amd64/amd64/disksubr.c:96
vndopen(2902,1,2000,ffff8000265b0b20) at vndopen+0x17a sys/dev/vnd.c:203
spec_open(ffff80002e8d9928) at spec_open+0x3df sys/kern/spec_vnops.c:150
VOP_OPEN(fffffd806edfed00,1,fffffd807f7d7958,ffff8000265b0b20) at VOP_OPEN+0x6c sys/kern/vfs_vops.c:138
vn_open(ffff80002e8d9b78,1,0) at vn_open+0x467 sys/kern/vfs_vnops.c:177
doopenat(ffff8000265b0b20,ffffff9c,200022c0,0,0,ffff80002e8d9d50) at doopenat+0x26a sys/kern/vfs_syscalls.c:1127
syscall(ffff80002e8d9dd0) at syscall+0x4a4 sys/arch/amd64/amd64/trap.c:625
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x86f2a513030, count: -16
ddb> machine ddbcpu 1
No such command
ddb> trace
hardclock(ffff80002e8d9450) at hardclock+0x106 sys/kern/kern_clock.c:149
clockintr_dispatch(ffff80002e8d9450) at clockintr_dispatch+0x1a8 sys/kern/kern_clockintr.c:196
lapic_clockintr(0,0) at lapic_clockintr+0x36 sys/arch/amd64/amd64/lapic.c:483
Xresume_lapic_ltimer() at Xresume_lapic_ltimer+0x26
pmap_kenter_pa(ffff800026c60000,5004c000,3) at pmap_kenter_pa+0x187 pmap_tlb_shootpage sys/arch/amd64/amd64/pmap.c:3377 [inline]
pmap_kenter_pa(ffff800026c60000,5004c000,3) at pmap_kenter_pa+0x187 sys/arch/amd64/amd64/pmap.c:519
buf_map(fffffd80683b5900) at buf_map+0x21d sys/kern/vfs_biomem.c:120
buf_get(0,0,1000ecf0) at buf_get+0x739 sys/kern/vfs_bio.c:1179
geteblk(1000ecf0) at geteblk+0x2c sys/kern/vfs_bio.c:1061
readdisklabel(2902,ffffffff81a39c40,ffff800000c9de00,0) at readdisklabel+0x145 sys/arch/amd64/amd64/disksubr.c:96
vndopen(2902,1,2000,ffff8000265b0b20) at vndopen+0x17a sys/dev/vnd.c:203
spec_open(ffff80002e8d9928) at spec_open+0x3df sys/kern/spec_vnops.c:150
VOP_OPEN(fffffd806edfed00,1,fffffd807f7d7958,ffff8000265b0b20) at VOP_OPEN+0x6c sys/kern/vfs_vops.c:138
vn_open(ffff80002e8d9b78,1,0) at vn_open+0x467 sys/kern/vfs_vnops.c:177
doopenat(ffff8000265b0b20,ffffff9c,200022c0,0,0,ffff80002e8d9d50) at doopenat+0x26a sys/kern/vfs_syscalls.c:1127
syscall(ffff80002e8d9dd0) at syscall+0x4a4 sys/arch/amd64/amd64/trap.c:625
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0x86f2a513030, count: -16


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Mar 3, 2023, 10:32:49 AM3/3/23
to syzkaller-o...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 1e5b016c5082 sync for __syscall removal
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=1214f904c80000
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=149061f2c80000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/452af0b271ef/disk-1e5b016c.raw.xz
bsd.gdb: https://storage.googleapis.com/syzbot-assets/5145fa4f4c7c/bsd-1e5b016c.gdb.xz
kernel image: https://storage.googleapis.com/syzbot-assets/992507fc6105/kernel-1e5b016c.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+21738f...@syzkaller.appspotmail.com

kernel: page fault trap, code=0
Stopped at hardclock+0x106: movq 0x260(%r14),%r15
ddb>
ddb> set $lines = 0
ddb> set $maxwidth = 0
ddb> show panic
the kernel did not panic
ddb> trace
hardclock(ffff800021841ef0) at hardclock+0x106 sys/kern/kern_clock.c:149
clockintr_dispatch(ffff800021841ef0) at clockintr_dispatch+0x1a8 sys/kern/kern_clockintr.c:196
lapic_clockintr(0,0) at lapic_clockintr+0x36 sys/arch/amd64/amd64/lapic.c:483
Xresume_lapic_ltimer() at Xresume_lapic_ltimer+0x26
uvm_objtree_RBT_COMPARE(ffff800021842048,fffffd8005c90480) at uvm_objtree_RBT_COMPARE+0x2b uvm_pagecmp sys/uvm/uvm_page.c:87 [inline]
uvm_objtree_RBT_COMPARE(ffff800021842048,fffffd8005c90480) at uvm_objtree_RBT_COMPARE+0x2b sys/uvm/uvm_page.c:82
_rb_find(ffffffff829e9ed0,fffffd8077d2c0f0,ffff800021842048) at _rb_find+0x58 sys/kern/subr_tree.c:450
uvm_pagelookup(fffffd8077d2c0e0,a5eb000) at uvm_pagelookup+0x44 sys/uvm/uvm_page.c:1239
buf_map(fffffd8077d2c020) at buf_map+0x206 sys/kern/vfs_biomem.c:124
buf_get(0,0,1000ecf0) at buf_get+0x739 sys/kern/vfs_bio.c:1179
geteblk(1000ecf0) at geteblk+0x2c sys/kern/vfs_bio.c:1061
readdisklabel(2902,ffffffff81a39c40,ffff800000cb1000,0) at readdisklabel+0x145 sys/arch/amd64/amd64/disksubr.c:96
vndopen(2902,1,2000,ffff8000217198a8) at vndopen+0x17a sys/dev/vnd.c:203
spec_open(ffff8000218424a8) at spec_open+0x3df sys/kern/spec_vnops.c:150
VOP_OPEN(fffffd807e8e4c28,1,fffffd807f7d7a90,ffff8000217198a8) at VOP_OPEN+0x6c sys/kern/vfs_vops.c:138
vn_open(ffff8000218426f8,1,0) at vn_open+0x467 sys/kern/vfs_vnops.c:177
doopenat(ffff8000217198a8,ffffff9c,200022c0,0,0,ffff8000218428d0) at doopenat+0x26a sys/kern/vfs_syscalls.c:1127
syscall(ffff800021842950) at syscall+0x4a4 sys/arch/amd64/amd64/trap.c:625
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0xd1b3df64c30, count: -18
ddb> show registers
rdi 0x3
rsi 0
rbp 0xffff800021841e20
rbx 0x1
rdx 0xd8
rcx 0x6028b7e200
rax 0x22a6 __ALIGN_SIZE+0x12a6
r8 0
r9 0
r10 0
r11 0xcbd891701a4b1c5e
r12 0xffff8000217198a8
r13 0
r14 0
r15 0
rip 0xffffffff81db7a16 hardclock+0x106
cs 0x8
rflags 0x10246 __ALIGN_SIZE+0xf246
rsp 0xffff800021841df0
ss 0x10
hardclock+0x106: movq 0x260(%r14),%r15
ddb> show proc
PROC (kernel: page fault trap, code=0
Faulted in DDB; continuing...
ddb> ps
PID TID PPID UID S FLAGS WAIT COMMAND
ddb> show all locks
No such command
ddb> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 10180 6402K 6414K 78643K 11270 0
pcb 13 8K 8K 78643K 13 0
rtable 158 4K 4K 78643K 241 0
ifaddr 64 18K 18K 78643K 64 0
counters 28 17K 17K 78643K 28 0
ioctlops 0 0K 2K 78643K 23 0
mount 1 1K 1K 78643K 1 0
log 0 0K 0K 78643K 4 0
vnodes 1168 73K 73K 78643K 1182 0
UFS quota 1 32K 32K 78643K 1 0
UFS mount 5 36K 36K 78643K 5 0
shm 2 1K 1K 78643K 2 0
VM map 2 1K 1K 78643K 2 0
sem 2 0K 0K 78643K 2 0
dirhash 12 2K 2K 78643K 12 0
ACPI 1697 195K 286K 78643K 12548 0
file desc 20 73K 77K 78643K 109 0
proc 55 58K 75K 78643K 421 0
NFS srvsock 1 0K 0K 78643K 1 0
NFS daemon 1 16K 16K 78643K 1 0
in_multi 57 3K 3K 78643K 57 0
ether_multi 1 0K 0K 78643K 1 0
ISOFS mount 1 32K 32K 78643K 1 0
MSDOSFS mount 1 16K 16K 78643K 1 0
ttys 25 122K 122K 78643K 25 0
exec 0 0K 1K 78643K 338 0
tdb 3 0K 0K 78643K 3 0
pagedep 1 8K 8K 78643K 1 0
inodedep 1 32K 32K 78643K 1 0
newblk 1 0K 0K 78643K 1 0
VM swap 8 62K 64K 78643K 10 0
UVM amap 196 72K 72K 78643K 2126 0
UVM aobj 3 2K 2K 78643K 3 0
memdesc 1 4K 4K 78643K 1 0
crypto data 1 1K 1K 78643K 1 0
NDP 19 1K 1K 78643K 19 0
temp 51 5754K 5817K 78643K 3584 0
kqueue 12 18K 18K 78643K 25 0
SYN cache 2 16K 16K 78643K 2 0
ddb> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg Idle
rtpcb 120 28 0 25 1 0 1 1 0 8 0
rtentry 112 73 0 1 3 0 3 3 0 8 0
unpcb 144 33 0 20 1 0 1 1 0 8 0
syncache 296 5 0 5 2 1 1 1 0 8 1
tcpqe 32 27 0 27 1 1 0 1 0 8 0
tcpcb 776 8 0 5 1 0 1 1 0 8 0
arp 88 12 0 0 1 0 1 1 0 8 0
inpcb 336 51 0 45 1 0 1 1 0 8 0
nd6 48 12 0 0 1 0 1 1 0 8 0
art_heap8 4096 1 0 0 1 0 1 1 0 8 0
art_heap4 256 283 0 0 18 0 18 18 0 8 0
art_table 32 284 0 0 3 0 3 3 0 8 0
art_node 16 72 0 6 1 0 1 1 0 8 0
dirhash 1024 17 0 0 3 0 3 3 0 8 0
dirhash: pool(0xffffffff82bd74a8:dirhash): free list modified: page 0xffff8000216b1000; item ordinal 0; addr 0xffff8000216b1400 (p 0xfffffd806eddc000); offset 0x0=0x0
pool(dirhash): free list modified: page 0xffff8000216b1000; item ordinal 0; addr 0xffff8000216b1400 (p 0xfffffd806eddc000); offset 0x0=0x0
dirhash: pool(0xffffffff82bd74a8:dirhash): page inconsistency: page 0xffff8000216b1000; item ordinal 1; addr 0x141c1b00baba3640
dino2pl 256 1480 0 53 90 0 90 90 0 8 0
ffsino 240 1480 0 53 84 0 84 84 0 8 0
nchpl 144 1736 0 61 63 0 63 63 0 8 0
uvmvnodes 80 1490 0 0 31 0 31 31 0 8 0
vnodes 216 1490 0 0 83 0 83 83 0 8 0
namei 1024 5788 0 5788 4 1 3 3 0 8 3
namei: pool(0xffffffff82c74a18:namei): free list modified: page 0xffff800021683000; item ordinal 0; addr 0xffff800021684400 (p 0xfffffd806a746000); offset 0x0=0x0
pool(namei): free list modified: page 0xffff800021683000; item ordinal 0; addr 0xffff800021684400 (p 0xfffffd806a746000); offset 0x0=0x0
namei: pool(0xffffffff82c74a18:namei): page inconsistency: page 0xffff800021683000; item ordinal 1; addr 0x9769284ce4d23983
namei: pool(0xffffffff82c74a18:namei): free list modified: page 0xffff80002165f000; item ordinal 0; addr 0xffff800021660400 (p 0xfffffd80782b4000); offset 0x0=0x0
pool(namei): free list modified: page 0xffff80002165f000; item ordinal 0; addr 0xffff800021660400 (p 0xfffffd80782b4000); offset 0x0=0x0
namei: pool(0xffffffff82c74a18:namei): page inconsistency: page 0xffff80002165f000; item ordinal 1; addr 0x405eef52b8f397d7
namei: pool(0xffffffff82c74a18:namei): free list modified: page 0xffff80002168b000; item ordinal 0; addr 0xffff80002168c800 (p 0xfffffd806a746000); offset 0x0=0x0
pool(namei): free list modified: page 0xffff80002168b000; item ordinal 0; addr 0xffff80002168c800 (p 0xfffffd806a746000); offset 0x0=0x0
namei: pool(0xffffffff82c74a18:namei): page inconsistency: page 0xffff80002168b000; item ordinal 1; addr 0x5b1f8ec5d663c37
kstatmem 264 22 0 0 2 0 2 2 0 8 0
scxspl 216 6240 0 6240 22 21 1 8 0 8 1
plimitpl 152 25 0 10 1 0 1 1 0 8 0
sigapl 424 408 0 361 6 0 6 6 0 8 0
futexpl 64 8 0 7 1 0 1 1 0 8 0
knotepl 120 4236 0 4150 5 1 4 4 0 8 0
kqueuepl 184 21 0 13 1 0 1 1 0 8 0
pipepl 288 135 0 107 4 1 3 3 0 8 1
fdescpl 432 392 0 361 4 0 4 4 0 8 0
filepl 120 1518 0 1389 4 0 4 4 0 8 0
lockfpl 104 6 0 4 1 0 1 1 0 8 0
lockfspl 48 4 0 2 1 0 1 1 0 8 0
sessionpl 144 25 0 9 1 0 1 1 0 8 0
pgrppl 48 25 0 9 1 0 1 1 0 8 0
ucredpl 104 67 0 56 1 0 1 1 0 8 0
zombiepl 144 361 0 361 2 1 1 1 0 8 1
processpl 1008 408 0 361 8 1 7 7 0 8 0
processpl: pool(0xffffffff82cf3698:processpl): page inconsistency: page 0x0; at page head addr 0xffff800021713f90 (p 0xffff800021712000)
procpl 696 419 0 361 7 1 6 6 0 8 0
procpl: pool(0xffffffff82cf34f0:procpl): page inconsistency: page 0x0; at page head addr 0xffff800021719f90 (p 0xffff800021718000)
sockpl 456 112 0 90 5 1 4 4 0 8 1
mcl8k 8192 9 0 9 2 1 1 1 0 8 1
mcl4k 4096 5 0 5 2 1 1 1 0 8 1
mcl2k 2048 10824 0 10750 35 25 10 34 0 8 0
mtagpl 96 4 0 4 1 1 0 1 0 8 0
mbufpl 256 18158 0 17964 27 14 13 21 0 8 0
bufpl 288 3986 0 145 275 0 275 275 0 8 0
anonpl 24 111820 0 106748 68 13 55 55 0 188 23
amapchunkpl 152 6006 0 5636 21 1 20 20 0 158 5
amappl16 200 2077 0 2016 10 5 5 5 0 8 0
amappl15 192 10 0 10 1 1 0 1 0 8 0
amappl14 184 152 0 139 2 0 2 2 0 8 0
amappl13 176 13 0 12 2 1 1 1 0 8 0
amappl12 168 371 0 367 2 1 1 1 0 8 0
amappl11 160 45 0 35 1 0 1 1 0 8 0
amappl10 152 49 0 40 2 1 1 1 0 8 0
amappl9 144 945 0 945 2 1 1 1 0 8 1
amappl8 136 110 0 86 3 1 2 2 0 8 1
amappl7 128 125 0 110 2 0 2 2 0 8 0
amappl6 120 153 0 144 2 0 2 2 0 8 1
amappl5 112 108 0 102 1 0 1 1 0 8 0
amappl4 104 459 0 432 2 0 2 2 0 8 1
amappl3 96 516 0 474 2 0 2 2 0 8 0
amappl2 88 728 0 660 3 0 3 3 0 8 1
amappl1 80 11529 0 10855 29 3 26 26 0 8 11
amappl 88 1687 0 1568 3 0 3 3 0 92 0
dma4096 4096 1 0 1 1 1 0 1 0 8 0
dma1024 1024 1 0 0 1 0 1 1 0 8 0
dma256 256 6 0 6 1 1 0 1 0 8 0
dma128 128 253 0 253 1 1 0 1 0 8 0
dma64 64 6 0 6 1 1 0 1 0 8 0
dma32 32 7 0 7 1 1 0 1 0 8 0
dma16 16 18 0 17 1 0 1 1 0 8 0
aobjpl 72 2 0 0 1 0 1 1 0 8 0
uaddrrnd 24 392 0 361 1 0 1 1 0 8 0
uaddrbest 32 2 0 0 1 0 1 1 0 8 0
uaddr 24 392 0 361 1 0 1 1 0 8 0
vmmpekpl 168 9593 0 9565 2 0 2 2 0 8 0
vmmpepl 168 42800 0 40897 135 9 126 126 0 357 43
vmsppl 344 391 0 361 3 0 3 3 0 8 0
rwobjpl 24 15319 0 12804 21 1 20 20 0 8 3
pdppl 4096 790 0 722 92 22 70 70 0 8 2
pvpl 32 305788 0 296044 366 21 345 345 0 265 265
pmappl 216 391 0 361 2 0 2 2 0 8 0
extentpl 40 56 0 38 1 0 1 1 0 8 0
phpool 112 641 0 67 17 0 17 17 0 8 0
ddb> machine ddbcpu 0
No such command
ddb> trace
hardclock(ffff800021841ef0) at hardclock+0x106 sys/kern/kern_clock.c:149
clockintr_dispatch(ffff800021841ef0) at clockintr_dispatch+0x1a8 sys/kern/kern_clockintr.c:196
lapic_clockintr(0,0) at lapic_clockintr+0x36 sys/arch/amd64/amd64/lapic.c:483
Xresume_lapic_ltimer() at Xresume_lapic_ltimer+0x26
uvm_objtree_RBT_COMPARE(ffff800021842048,fffffd8005c90480) at uvm_objtree_RBT_COMPARE+0x2b uvm_pagecmp sys/uvm/uvm_page.c:87 [inline]
uvm_objtree_RBT_COMPARE(ffff800021842048,fffffd8005c90480) at uvm_objtree_RBT_COMPARE+0x2b sys/uvm/uvm_page.c:82
_rb_find(ffffffff829e9ed0,fffffd8077d2c0f0,ffff800021842048) at _rb_find+0x58 sys/kern/subr_tree.c:450
uvm_pagelookup(fffffd8077d2c0e0,a5eb000) at uvm_pagelookup+0x44 sys/uvm/uvm_page.c:1239
buf_map(fffffd8077d2c020) at buf_map+0x206 sys/kern/vfs_biomem.c:124
buf_get(0,0,1000ecf0) at buf_get+0x739 sys/kern/vfs_bio.c:1179
geteblk(1000ecf0) at geteblk+0x2c sys/kern/vfs_bio.c:1061
readdisklabel(2902,ffffffff81a39c40,ffff800000cb1000,0) at readdisklabel+0x145 sys/arch/amd64/amd64/disksubr.c:96
vndopen(2902,1,2000,ffff8000217198a8) at vndopen+0x17a sys/dev/vnd.c:203
spec_open(ffff8000218424a8) at spec_open+0x3df sys/kern/spec_vnops.c:150
VOP_OPEN(fffffd807e8e4c28,1,fffffd807f7d7a90,ffff8000217198a8) at VOP_OPEN+0x6c sys/kern/vfs_vops.c:138
vn_open(ffff8000218426f8,1,0) at vn_open+0x467 sys/kern/vfs_vnops.c:177
doopenat(ffff8000217198a8,ffffff9c,200022c0,0,0,ffff8000218428d0) at doopenat+0x26a sys/kern/vfs_syscalls.c:1127
syscall(ffff800021842950) at syscall+0x4a4 sys/arch/amd64/amd64/trap.c:625
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0xd1b3df64c30, count: -18
ddb> machine ddbcpu 1
No such command
ddb> trace
hardclock(ffff800021841ef0) at hardclock+0x106 sys/kern/kern_clock.c:149
clockintr_dispatch(ffff800021841ef0) at clockintr_dispatch+0x1a8 sys/kern/kern_clockintr.c:196
lapic_clockintr(0,0) at lapic_clockintr+0x36 sys/arch/amd64/amd64/lapic.c:483
Xresume_lapic_ltimer() at Xresume_lapic_ltimer+0x26
uvm_objtree_RBT_COMPARE(ffff800021842048,fffffd8005c90480) at uvm_objtree_RBT_COMPARE+0x2b uvm_pagecmp sys/uvm/uvm_page.c:87 [inline]
uvm_objtree_RBT_COMPARE(ffff800021842048,fffffd8005c90480) at uvm_objtree_RBT_COMPARE+0x2b sys/uvm/uvm_page.c:82
_rb_find(ffffffff829e9ed0,fffffd8077d2c0f0,ffff800021842048) at _rb_find+0x58 sys/kern/subr_tree.c:450
uvm_pagelookup(fffffd8077d2c0e0,a5eb000) at uvm_pagelookup+0x44 sys/uvm/uvm_page.c:1239
buf_map(fffffd8077d2c020) at buf_map+0x206 sys/kern/vfs_biomem.c:124
buf_get(0,0,1000ecf0) at buf_get+0x739 sys/kern/vfs_bio.c:1179
geteblk(1000ecf0) at geteblk+0x2c sys/kern/vfs_bio.c:1061
readdisklabel(2902,ffffffff81a39c40,ffff800000cb1000,0) at readdisklabel+0x145 sys/arch/amd64/amd64/disksubr.c:96
vndopen(2902,1,2000,ffff8000217198a8) at vndopen+0x17a sys/dev/vnd.c:203
spec_open(ffff8000218424a8) at spec_open+0x3df sys/kern/spec_vnops.c:150
VOP_OPEN(fffffd807e8e4c28,1,fffffd807f7d7a90,ffff8000217198a8) at VOP_OPEN+0x6c sys/kern/vfs_vops.c:138
vn_open(ffff8000218426f8,1,0) at vn_open+0x467 sys/kern/vfs_vnops.c:177
doopenat(ffff8000217198a8,ffffff9c,200022c0,0,0,ffff8000218428d0) at doopenat+0x26a sys/kern/vfs_syscalls.c:1127
syscall(ffff800021842950) at syscall+0x4a4 sys/arch/amd64/amd64/trap.c:625
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0xd1b3df64c30, count: -18

Reply all
Reply to author
Forward
0 new messages