panic: amap_lookup: offset out of range

0 views
Skip to first unread message

syzbot

unread,
May 3, 2020, 7:41:12 AM5/3/20
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 6fb15185 Add ping(1)-like summary statistics. ok djm@ dera..
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=177fb5f8100000
kernel config: https://syzkaller.appspot.com/x/.config?x=fe55924c11e64b0a
dashboard link: https://syzkaller.appspot.com/bug?extid=5ca1836760b4d8c55c78

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+5ca183...@syzkaller.appspotmail.com

login: panic: amap_lookup: offset out of range
Stopped at db_enter+0x18: addq $0x8,%rsp
TID PID UID PRFLAGS PFLAGS CPU COMMAND
* 98379 97766 0 0x2 0x4000000 0 syz-fuzzer
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:398
panic(ffffffff82233e7e) at panic+0x15c sys/kern/subr_prf.c:207
amap_lookup(fffffd80579acef0,0) at amap_lookup+0x19b sys/uvm/uvm_amap.c:1027
uvm_map_clean(fffffd806bc09660,c003136000,c003484000,8) at uvm_map_clean+0x43a sys/uvm/uvm_map.c:4670
syscall(ffff80001d7f4bc0) at syscall+0x507 sys/arch/amd64/amd64/trap.c:570
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0xc00015feb8, count: 9
https://www.openbsd.org/ddb.html describes the minimum info required in bug
reports. Insufficient info makes it difficult to find and fix bugs.
ddb>
ddb> set $lines = 0
ddb> set $maxwidth = 0
ddb> show panic
amap_lookup: offset out of range
ddb> trace
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:398
panic(ffffffff82233e7e) at panic+0x15c sys/kern/subr_prf.c:207
amap_lookup(fffffd80579acef0,0) at amap_lookup+0x19b sys/uvm/uvm_amap.c:1027
uvm_map_clean(fffffd806bc09660,c003136000,c003484000,8) at uvm_map_clean+0x43a sys/uvm/uvm_map.c:4670
syscall(ffff80001d7f4bc0) at syscall+0x507 sys/arch/amd64/amd64/trap.c:570
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0xc00015feb8, count: -6
ddb> show registers
rdi 0
rsi 0x1
rbp 0xffff80001d7f4910
rbx 0xffff80001d7f49c0
rdx 0x2
rcx 0
rax 0
r8 0xffff80001d7f48d0
r9 0x1
r10 0
r11 0x36fe151a5899e1e2
r12 0x3000000008
r13 0xffff80001d7f4920
r14 0x100
r15 0x1
rip 0xffffffff817fd778 db_enter+0x18
cs 0x8
rflags 0x246
rsp 0xffff80001d7f4900
ss 0x10
db_enter+0x18: addq $0x8,%rsp
ddb> show proc
PROC (syz-fuzzer) pid=98379 stat=onproc
flags process=2<EXEC,8ORPHAN> proc=4000000<THREAD>
pri=32, usrpri=50, nice=20
forw=0xffffffffffffffff, list=0xffff80001d7a8600,0xffff80001d73a128
process=0xffff8000ffff9210 user=0xffff80001d7ef000, vmspace=0xfffffd806bc09660
estcpu=0, cpticks=0, pctcpu=0.41
user=0, sys=0, intr=0
ddb> ps
PID TID PPID UID S FLAGS WAIT COMMAND
83077 348371 59591 0 2 0 syz-executor.0
83077 47774 59591 0 3 0x4000080 semwait syz-executor.0
83077 255212 59591 0 3 0x4000080 fsleep syz-executor.0
16704 114854 0 0 3 0x14200 bored sosplice
59591 479942 97766 0 3 0x82 nanosleep syz-executor.0
97766 340855 70502 0 3 0x82 thrsleep syz-fuzzer
97766 396325 70502 0 3 0x4000082 nanosleep syz-fuzzer
97766 42869 70502 0 2 0x4000002 syz-fuzzer
97766 19327 70502 0 3 0x4000082 thrsleep syz-fuzzer
97766 332508 70502 0 3 0x4000082 thrsleep syz-fuzzer
*97766 98379 70502 0 7 0x4000002 syz-fuzzer
97766 18943 70502 0 3 0x4000082 thrsleep syz-fuzzer
70502 106692 27111 0 3 0x10008a pause ksh
27111 139040 84641 0 3 0x92 select sshd
6139 25487 1 0 3 0x100083 ttyin getty
84641 411298 1 0 3 0x80 select sshd
36541 409859 23668 73 3 0x100090 kqread syslogd
23668 384644 1 0 3 0x100082 netio syslogd
27251 395974 1 77 3 0x100090 poll dhclient
1740 384513 1 0 3 0x80 poll dhclient
65040 312903 0 0 3 0x14200 bored smr
77845 288384 0 0 2 0x14200 zerothread
87824 263768 0 0 3 0x14200 aiodoned aiodoned
25247 432939 0 0 3 0x14200 syncer update
26036 192879 0 0 3 0x14200 cleaner cleaner
70800 49160 0 0 3 0x14200 reaper reaper
85726 55832 0 0 3 0x14200 pgdaemon pagedaemon
5290 106398 0 0 3 0x14200 bored crynlk
84066 46181 0 0 3 0x14200 bored crypto
30 505517 0 0 3 0x40014200 acpi0 acpi0
72628 470158 0 0 3 0x14200 bored softnet
64481 82302 0 0 3 0x14200 bored systqmp
1727 349067 0 0 3 0x14200 bored systq
8994 407254 0 0 3 0x40014200 bored softclock
67609 245879 0 0 3 0x40014200 idle0
1 436103 0 0 3 0x82 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb> show all locks
No such command
ddb> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 9462 6391K 6715K 78643K 10699 0
pcb 13 8K 8K 78643K 93 0
rtable 86 2K 3K 78643K 227 0
ifaddr 41 9K 11K 78643K 51 0
counters 20 16K 16K 78643K 21 0
ioctlops 0 0K 2K 78643K 15 0
iov 0 0K 12K 78643K 8 0
mount 1 1K 1K 78643K 1 0
vnodes 1219 77K 77K 78643K 1254 0
UFS quota 1 32K 32K 78643K 1 0
UFS mount 5 36K 36K 78643K 5 0
shm 2 1K 5K 78643K 4 0
VM map 2 0K 0K 78643K 2 0
sem 12 0K 0K 78643K 12 0
dirhash 12 2K 2K 78643K 12 0
ACPI 1794 195K 288K 78643K 12646 0
file desc 4 9K 25K 78643K 95 0
proc 49 38K 63K 78643K 360 0
subproc 16 1K 2K 78643K 34 0
NFS srvsock 1 0K 0K 78643K 1 0
NFS daemon 1 16K 16K 78643K 1 0
ip_moptions 0 0K 0K 78643K 6 0
in_multi 22 1K 2K 78643K 43 0
ether_multi 1 0K 0K 78643K 4 0
ISOFS mount 1 32K 32K 78643K 1 0
MSDOSFS mount 1 16K 16K 78643K 1 0
ttys 31 148K 148K 78643K 31 0
exec 0 0K 1K 78643K 189 0
pagedep 1 8K 8K 78643K 1 0
inodedep 1 32K 32K 78643K 1 0
newblk 1 0K 0K 78643K 1 0
VM swap 7 26K 26K 78643K 7 0
UVM amap 111 14K 22K 78643K 1086 0
UVM aobj 13 2K 2K 78643K 15 0
memdesc 1 4K 4K 78643K 1 0
crypto data 1 1K 1K 78643K 1 0
ip6_options 0 0K 0K 78643K 12 0
NDP 6 0K 0K 78643K 11 0
temp 54 3031K 3097K 78643K 8232 0
kqueue 3 4K 8K 78643K 5 0
SYN cache 2 16K 16K 78643K 2 0
ddb> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg Idle
arp 64 7 0 3 1 0 1 1 0 8 0
rtpcb 80 25 0 23 1 0 1 1 0 8 0
rtentry 112 50 0 17 2 0 2 2 0 8 0
unpcb 120 71 0 63 1 0 1 1 0 8 0
syncache 264 4 0 4 1 1 0 1 0 8 0
tcpqe 32 18 0 18 1 0 1 1 0 8 1
tcpcb 544 30 0 26 1 0 1 1 0 8 0
inpcb 280 158 0 151 1 0 1 1 0 8 0
nd6 48 6 0 3 1 0 1 1 0 8 0
art_heap8 4096 1 0 0 1 0 1 1 0 8 0
art_heap4 256 204 0 60 13 0 13 13 0 8 2
art_table 32 205 0 60 2 0 2 2 0 8 0
art_node 16 49 0 19 1 0 1 1 0 8 0
sysvmsgpl 40 3 0 3 1 0 1 1 0 8 1
semupl 112 1 0 0 1 0 1 1 0 8 0
semapl 112 10 0 0 1 0 1 1 0 8 0
shmpl 112 13 0 2 1 0 1 1 0 8 0
dirhash 1024 17 0 0 3 0 3 3 0 8 0
dino2pl 256 1504 0 110 88 0 88 88 0 8 0
ffsino 240 1504 0 110 83 0 83 83 0 8 0
nchpl 144 1842 0 262 60 0 60 60 0 8 0
uvmvnodes 72 1576 0 0 29 0 29 29 0 8 0
vnodes 208 1576 0 0 83 0 83 83 0 8 0
namei 1024 4573 0 4573 1 0 1 1 0 8 1
scxspl 192 4946 0 4946 1 0 1 1 0 8 1
plimitpl 152 24 0 18 1 0 1 1 0 8 0
sigapl 424 282 0 254 4 0 4 4 0 8 0
futexpl 56 1620 0 1619 1 0 1 1 0 8 0
knotepl 112 63 0 50 1 0 1 1 0 8 0
kqueuepl 144 8 0 6 1 0 1 1 0 8 0
pipelkpl 16 80 0 73 1 0 1 1 0 8 0
pipepl 120 160 0 147 1 0 1 1 0 8 0
fdescpl 432 267 0 254 2 0 2 2 0 8 0
filepl 120 1444 0 1371 4 0 4 4 0 8 1
lockfpl 104 38 0 37 1 0 1 1 0 8 0
lockfspl 48 14 0 13 1 0 1 1 0 8 0
sessionpl 112 17 0 8 1 0 1 1 0 8 0
pgrppl 48 50 0 41 1 0 1 1 0 8 0
ucredpl 96 95 0 88 1 0 1 1 0 8 0
zombiepl 144 254 0 254 1 0 1 1 0 8 1
processpl 920 282 0 254 4 0 4 4 0 8 0
procpl 624 377 0 341 4 0 4 4 0 8 1
sosppl 128 2 0 2 1 0 1 1 0 8 1
sockpl 400 254 0 237 4 0 4 4 0 8 2
mcl64k 65536 4 0 4 1 0 1 1 0 8 1
mcl12k 12288 3 0 3 1 0 1 1 0 8 1
mcl4k 4096 13 0 13 2 1 1 1 0 8 1
mcl2k 2048 60081 0 60038 13 1 12 12 0 8 5
mtagpl 80 8 0 8 2 1 1 1 0 8 1
mbufpl 256 95988 0 95930 10 1 9 9 0 8 1
bufpl 280 3521 0 127 243 0 243 243 0 8 0
anonpl 16 43999 0 28708 75 1 74 74 0 107 10
amapchunkpl 152 1390 0 1260 8 0 8 8 0 158 2
amappl16 192 1412 0 569 51 0 51 51 0 8 8
amappl15 184 4 0 1 1 0 1 1 0 8 0
amappl14 176 25 0 20 1 0 1 1 0 8 0
amappl13 168 24 0 23 1 0 1 1 0 8 0
amappl12 160 11 0 8 1 0 1 1 0 8 0
amappl11 152 75 0 66 1 0 1 1 0 8 0
amappl10 144 42 0 37 1 0 1 1 0 8 0
amappl9 136 365 0 364 1 0 1 1 0 8 0
amappl8 128 309 0 278 2 0 2 2 0 8 0
amappl7 120 138 0 123 1 0 1 1 0 8 0
amappl6 112 29 0 24 1 0 1 1 0 8 0
amappl5 104 212 0 201 1 0 1 1 0 8 0
amappl4 96 422 0 391 1 0 1 1 0 8 0
amappl3 88 106 0 99 1 0 1 1 0 8 0
amappl2 80 1312 0 1249 2 0 2 2 0 8 0
amappl1 72 14450 0 14050 21 6 15 17 0 8 6
amappl 80 617 0 578 1 0 1 1 0 84 0
dma4096 4096 1 0 1 1 1 0 1 0 8 0
dma256 256 6 0 6 1 1 0 1 0 8 0
dma128 128 253 0 253 1 1 0 1 0 8 0
dma64 64 6 0 6 1 1 0 1 0 8 0
dma32 32 7 0 7 1 1 0 1 0 8 0
dma16 16 18 0 17 1 0 1 1 0 8 0
aobjpl 64 14 0 2 1 0 1 1 0 8 0
uaddrrnd 24 267 0 254 1 0 1 1 0 8 0
uaddrbest 32 2 0 0 1 0 1 1 0 8 0
uaddr 24 267 0 254 1 0 1 1 0 8 0
vmmpekpl 168 6024 0 5999 2 0 2 2 0 8 0
vmmpepl 168 39347 0 37500 113 3 110 110 0 357 26
vmsppl 272 266 0 254 2 0 2 2 0 8 1
pdppl 4096 540 0 508 6 0 6 6 0 8 1
pvpl 32 143828 0 125629 173 0 173 173 0 265 24
pmappl 200 266 0 254 1 0 1 1 0 8 0
extentpl 40 46 0 29 1 0 1 1 0 8 0
phpool 112 234 0 5 7 0 7 7 0 8 0
ddb> machine ddbcpu 0
No such command
ddb> trace
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:398
panic(ffffffff82233e7e) at panic+0x15c sys/kern/subr_prf.c:207
amap_lookup(fffffd80579acef0,0) at amap_lookup+0x19b sys/uvm/uvm_amap.c:1027
uvm_map_clean(fffffd806bc09660,c003136000,c003484000,8) at uvm_map_clean+0x43a sys/uvm/uvm_map.c:4670
syscall(ffff80001d7f4bc0) at syscall+0x507 sys/arch/amd64/amd64/trap.c:570
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0xc00015feb8, count: -6
ddb> machine ddbcpu 1
No such command
ddb> trace
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:398
panic(ffffffff82233e7e) at panic+0x15c sys/kern/subr_prf.c:207
amap_lookup(fffffd80579acef0,0) at amap_lookup+0x19b sys/uvm/uvm_amap.c:1027
uvm_map_clean(fffffd806bc09660,c003136000,c003484000,8) at uvm_map_clean+0x43a sys/uvm/uvm_map.c:4670
syscall(ffff80001d7f4bc0) at syscall+0x507 sys/arch/amd64/amd64/trap.c:570
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0xc00015feb8, count: -6


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Sep 17, 2020, 1:48:16 AM9/17/20
to syzkaller-o...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages