panic: timeout_add: to_ticks (-ADDR) < 0

2 views
Skip to first unread message

syzbot

unread,
Feb 15, 2019, 5:32:03 AM2/15/19
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 91a1919492c9 allow configuration of the rdomain that mpls ..
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=17db464cc00000
kernel config: https://syzkaller.appspot.com/x/.config?x=ffa1da4399f74b2b
dashboard link: https://syzkaller.appspot.com/bug?extid=d77cc86bec0ee187125a
compiler:

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+d77cc8...@syzkaller.appspotmail.com

panic: timeout_add: to_ticks (-973078528) < 0
Stopped at db_enter+0x18: addq $0x8,%rsp
TID PID UID PRFLAGS PFLAGS CPU COMMAND
*111431 60519 0 0 0x4000000 0 syz-executor.1
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:399
panic() at panic+0x15c sys/kern/subr_prf.c:208
timeout_add(ffff800000669260,c6000000) at timeout_add+0x179
sys/kern/kern_timeout.c:190
pcppi_bell(ffff800000669200,9,c6000000,1) at pcppi_bell+0x2a0
sys/dev/isa/pcppi.c:234
spkrioctl(1b00,80085301,ffff8000149f4a60,2,ffff80001495c010) at
spkrioctl+0x123 tone sys/dev/isa/spkr.c:89 [inline]
spkrioctl(1b00,80085301,ffff8000149f4a60,2,ffff80001495c010) at
spkrioctl+0x123 sys/dev/isa/spkr.c:489
VOP_IOCTL(fffffd803e76a070,80085301,ffff8000149f4a60,2,fffffd803f7c7c00,ffff80001495c010)
at
VOP_IOCTL+0x9a sys/kern/vfs_vops.c:290
vn_ioctl(fffffd8030060bc8,80085301,ffff8000149f4a60,ffff80001495c010) at
vn_ioctl+0xc9 sys/kern/vfs_vnops.c:512
sys_ioctl(ffff80001495c010,ffff8000149f4ba8,ffff8000149f4b90) at
sys_ioctl+0x62d
syscall(ffff8000149f4c40) at syscall+0x535
Xsyscall(6,0,ffffffffffffff88,0,3,628c465c010) at Xsyscall+0x128
end of kernel
end trace frame: 0x62ae85582f0, count: 5
https://www.openbsd.org/ddb.html describes the minimum info required in bug
reports. Insufficient info makes it difficult to find and fix bugs.


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#bug-status-tracking for how to communicate with
syzbot.

syzbot

unread,
Feb 15, 2019, 5:46:03 AM2/15/19
to syzkaller-o...@googlegroups.com
syzbot has found a reproducer for the following crash on:

HEAD commit: 91a1919492c9 allow configuration of the rdomain that mpls ..
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=12f8686cc00000
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1600d86cc00000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=131dbfe4c00000

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+d77cc8...@syzkaller.appspotmail.com

login: panic: timeout_add: to_ticks (-973078528) < 0
Stopped at db_enter+0x18: addq $0x8,%rsp
TID PID UID PRFLAGS PFLAGS CPU COMMAND
*225150 58898 0 0x2 0 0 syz-executor2130
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:399
panic() at panic+0x15c sys/kern/subr_prf.c:208
timeout_add(ffff800000669260,c6000000) at timeout_add+0x179
sys/kern/kern_timeout.c:190
pcppi_bell(ffff800000669200,9,c6000000,1) at pcppi_bell+0x2a0
sys/dev/isa/pcppi.c:234
spkrioctl(1b00,80085301,ffff8000149944c0,2,ffff80001495d078) at
spkrioctl+0x123 tone sys/dev/isa/spkr.c:89 [inline]
spkrioctl(1b00,80085301,ffff8000149944c0,2,ffff80001495d078) at
spkrioctl+0x123 sys/dev/isa/spkr.c:489
VOP_IOCTL(fffffd80355d5710,80085301,ffff8000149944c0,2,fffffd803f7c7ba0,ffff80001495d078)
at
VOP_IOCTL+0x9a sys/kern/vfs_vops.c:290
vn_ioctl(fffffd80361d90f8,80085301,ffff8000149944c0,ffff80001495d078) at
vn_ioctl+0xc9 sys/kern/vfs_vnops.c:512
sys_ioctl(ffff80001495d078,ffff800014994608,ffff8000149945f0) at
sys_ioctl+0x62d
syscall(ffff8000149946a0) at syscall+0x535
Xsyscall(6,0,7f7ffffcda88,0,1,7f7ffffcda98) at Xsyscall+0x128
end of kernel
end trace frame: 0x7f7ffffcda20, count: 5
https://www.openbsd.org/ddb.html describes the minimum info required in bug
reports. Insufficient info makes it difficult to find and fix bugs.
ddb>
ddb> set $lines = 0
ddb> set $maxwidth = 0
ddb> show panic
timeout_add: to_ticks (-973078528) < 0
ddb> trace
db_enter() at db_enter+24
panic() at panic+348
timeout_add(ffff800000669260,c6000000) at timeout_add+377
pcppi_bell(ffff800000669200,9,c6000000,1) at pcppi_bell+672
spkrioctl(1b00,80085301,ffff8000149944c0,2,ffff80001495d078) at
spkrioctl+291
VOP_IOCTL(fffffd80355d5710,80085301,ffff8000149944c0,2,fffffd803f7c7ba0,ffff80001495d078)
at
VOP_IOCTL+154
vn_ioctl(fffffd80361d90f8,80085301,ffff8000149944c0,ffff80001495d078) at
vn_ioctl+201
sys_ioctl(ffff80001495d078,ffff800014994608,ffff8000149945f0) at
sys_ioctl+1581
syscall(ffff8000149946a0) at syscall+1333
Xsyscall(6,0,7f7ffffcda88,0,1,7f7ffffcda98) at Xsyscall+296
end of kernel
end trace frame: 0x7f7ffffcda20, count: -10
ddb> show registers
rdi 0
rsi 1
rbp 18446603336566784224
rbx 18446603336566784400
rdx 2
rcx 1
rax 1
r8 18446603336566784160
r9 1
r10 279886934289127801
r11 2502221657416412312
r12 206158430216
r13 18446603336566784240
r14 256
r15 1
rip 18446744071581504680 db_enter+24
cs 8
rflags 582
rsp 18446603336566784208
ss 16
db_enter+24: addq $8,%rsp
ddb> show proc
PROC (syz-executor2130) pid=225150 stat=onproc
flags process=2<EXEC> proc=0
pri=50, usrpri=50, nice=20
forw=0xffffffffffffffff, list=0xffff80001495d2d0,0xffffffff8225bc68
process=0xffff8000ffff6358 user=0xffff80001498f000,
vmspace=0xfffffd803f015108
estcpu=0, cpticks=0, pctcpu=0.0
user=0, sys=0, intr=0
ddb> ps
PID TID PPID UID S FLAGS WAIT COMMAND
*58898 225150 34911 0 7 0x2 syz-executor2130
34911 456630 89072 0 3 0x10008a pause ksh
89072 354430 23284 0 3 0x92 select sshd
79593 267214 1 0 3 0x100083 ttyin getty
23284 444955 1 0 3 0x80 select sshd
15247 436527 17402 73 3 0x100090 kqread syslogd
17402 142758 1 0 3 0x100082 netio syslogd
47565 507769 1 77 3 0x100090 poll dhclient
13477 17358 1 0 3 0x80 poll dhclient
47007 498988 0 0 3 0x14200 pgzero zerothread
72504 182861 0 0 3 0x14200 aiodoned aiodoned
40145 441429 0 0 3 0x14200 syncer update
91685 203554 0 0 3 0x14200 cleaner cleaner
32314 311262 0 0 3 0x14200 reaper reaper
98168 433293 0 0 3 0x14200 pgdaemon pagedaemon
30014 2684 0 0 3 0x14200 bored crynlk
77429 429331 0 0 3 0x14200 bored crypto
25772 236285 0 0 3 0x40014200 acpi0 acpi0
18785 65609 0 0 3 0x14200 bored softnet
31357 84818 0 0 3 0x14200 bored systqmp
57765 453358 0 0 3 0x14200 bored systq
74963 173525 0 0 3 0x40014200 bored softclock
37948 152056 0 0 3 0x40014200 idle0
1 165260 0 0 3 0x82 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb> show all locks
No such command
ddb> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim Kern Lim
devbuf 9427 6306K 6307K 78643K 10520 0 0
pcb 23 9K 9K 78643K 55 0 0
rtable 61 1K 2K 78643K 115 0 0
ifaddr 21 7K 7K 78643K 21 0 0
counters 19 16K 16K 78643K 19 0 0
ioctlops 0 0K 2K 78643K 13 0 0
mount 1 1K 1K 78643K 1 0 0
vnodes 1166 73K 73K 78643K 1172 0 0
UFS quota 1 32K 32K 78643K 1 0 0
UFS mount 5 36K 36K 78643K 5 0 0
shm 2 1K 1K 78643K 2 0 0
VM map 2 0K 0K 78643K 2 0 0
sem 2 0K 0K 78643K 2 0 0
dirhash 12 2K 2K 78643K 12 0 0
ACPI 1777 193K 286K 78643K 12501 0 0
file desc 1 0K 0K 78643K 1 0 0
proc 40 30K 38K 78643K 207 0 0
NFS srvsock 1 0K 0K 78643K 1 0 0
NFS daemon 1 16K 16K 78643K 1 0 0
in_multi 11 0K 0K 78643K 11 0 0
ether_multi 1 0K 0K 78643K 1 0 0
ISOFS mount 1 32K 32K 78643K 1 0 0
MSDOSFS mount 1 16K 16K 78643K 1 0 0
ttys 18 79K 79K 78643K 18 0 0
exec 0 0K 1K 78643K 150 0 0
pagedep 1 8K 8K 78643K 1 0 0
inodedep 1 32K 32K 78643K 1 0 0
newblk 1 0K 0K 78643K 1 0 0
VM swap 7 26K 26K 78643K 7 0 0
UVM amap 47 2K 3K 78643K 653 0 0
UVM aobj 2 2K 2K 78643K 2 0 0
memdesc 1 4K 4K 78643K 1 0 0
crypto data 1 1K 1K 78643K 1 0 0
NDP 3 0K 0K 78643K 3 0 0
temp 30 2327K 2391K 78643K 1695 0 0
SYN cache 2 16K 16K 78643K 2 0 0
ddb> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg
Idle
arp 64 2 0 0 1 0 1 1 0
8 0
inpcbpl 280 22 0 16 1 0 1 1 0
8 0
plimitpl 152 13 0 8 1 0 1 1 0
8 0
rtentry 112 23 0 1 1 0 1 1 0
8 0
syncache 264 5 0 5 1 0 1 1 0
8 1
tcpcb 544 8 0 5 1 0 1 1 0
8 0
art_heap8 4096 1 0 0 1 0 1 1 0
8 0
art_heap4 256 96 0 0 6 0 6 6 0
8 0
art_table 32 97 0 0 1 0 1 1 0
8 0
art_node 16 22 0 2 1 0 1 1 0
8 0
dirhash 1024 17 0 0 3 0 3 3 0
8 0
dino1pl 128 1383 0 18 45 0 45 45 0
8 0
ffsino 240 1383 0 18 81 0 81 81 0
8 0
nchpl 144 1555 0 30 57 0 57 57 0
8 0
uvmvnodes 72 1392 0 0 26 0 26 26 0
8 0
vnodes 200 1392 0 0 74 0 74 74 0
8 0
namei 1024 3262 0 3262 2 1 1 1 0
8 1
scxspl 192 2343 0 2343 8 2 6 6 0
8 6
sigapl 432 174 0 164 2 0 2 2 0
8 0
knotepl 112 5 0 0 1 0 1 1 0
8 0
kqueuepl 104 1 0 0 1 0 1 1 0
8 0
pipepl 112 114 0 107 2 1 1 1 0
8 0
fdescpl 424 175 0 164 2 0 2 2 0
8 0
filepl 120 808 0 765 2 0 2 2 0
8 0
lockfpl 104 7 0 6 2 1 1 1 0
8 0
lockfspl 32 4 0 3 2 1 1 1 0
8 0
sessionpl 112 17 0 9 1 0 1 1 0
8 0
pgrppl 48 17 0 9 1 0 1 1 0
8 0
ucredpl 96 47 0 40 1 0 1 1 0
8 0
zombiepl 144 164 0 164 2 1 1 1 0
8 1
processpl 840 188 0 164 4 1 3 4 0
8 0
procpl 600 188 0 164 3 0 3 3 0
8 0
sockpl 384 64 0 48 2 0 2 2 0
8 0
mcl4k 4096 10 0 10 1 0 1 1 0
8 1
mcl2k 2048 5630 0 5602 6 0 6 6 0
8 2
mtagpl 80 2 0 2 1 1 0 1 0
8 0
mbufpl 256 9753 0 9716 6 2 4 4 0
8 0
bufpl 256 1997 0 254 109 0 109 109 0
8 0
anonpl 16 16903 0 15823 7 2 5 7 0
62 0
amapchunkpl 152 491 0 456 2 0 2 2 0
158 0
amappl16 192 73 0 68 1 0 1 1 0
8 0
amappl15 184 1 0 0 1 0 1 1 0
8 0
amappl14 176 1 0 1 1 1 0 1 0
8 0
amappl13 168 15 0 12 1 0 1 1 0
8 0
amappl12 160 6 0 6 1 0 1 1 0
8 1
amappl11 152 174 0 165 1 0 1 1 0
8 0
amappl10 144 43 0 43 2 1 1 1 0
8 1
amappl9 136 97 0 95 1 0 1 1 0
8 0
amappl8 128 108 0 102 1 0 1 1 0
8 0
amappl7 120 30 0 26 1 0 1 1 0
8 0
amappl6 112 38 0 34 1 0 1 1 0
8 0
amappl5 104 362 0 351 1 0 1 1 0
8 0
amappl4 96 254 0 234 1 0 1 1 0
8 0
amappl3 88 112 0 107 1 0 1 1 0
8 0
amappl2 80 559 0 523 1 0 1 1 0
8 0
amappl1 72 11596 0 11210 16 6 10 16 0
8 0
amappl 72 367 0 348 1 0 1 1 0
75 0
dma4096 4096 1 0 1 1 1 0 1 0
8 0
dma256 256 6 0 6 1 1 0 1 0
8 0
dma64 64 259 0 259 1 1 0 1 0
8 0
dma32 32 7 0 7 1 1 0 1 0
8 0
dma16 16 17 0 17 1 1 0 1 0
8 0
aobjpl 64 1 0 0 1 0 1 1 0
8 0
uaddrrnd 24 175 0 164 1 0 1 1 0
8 0
uaddrbest 32 2 0 0 1 0 1 1 0
8 0
uaddr 24 175 0 164 1 0 1 1 0
8 0
vmmpekpl 168 5195 0 5181 1 0 1 1 0
8 0
vmmpepl 168 23631 0 22941 49 15 34 47 0
357 3
vmsppl 264 174 0 164 1 0 1 1 0
8 0
pdppl 4096 356 0 328 5 0 5 5 0
8 0
pvpl 32 69400 0 66705 31 5 26 26 0
265 3
pmappl 192 174 0 164 1 0 1 1 0
8 0
extentpl 40 39 0 25 1 0 1 1 0
8 0
phpool 112 223 0 5 7 0 7 7 0
8 0
ddb>

Anton Lindqvist

unread,
Feb 15, 2019, 1:50:15 PM2/15/19
to syzbot, syzkaller-o...@googlegroups.com
Adding `set $maxwidth = 0' to the ddb commands caused the output radix
to change from hex to decimal. The fix[1] should be picked up soon by
syzkaller.

[1] https://marc.info/?l=openbsd-cvs&m=155025563711840&w=2

Dmitry Vyukov

unread,
Feb 16, 2019, 12:10:25 AM2/16/19
to syzbot, syzkaller-o...@googlegroups.com
That's when you ask yourself: how did it ever work before?

Greg Steuck

unread,
Feb 16, 2019, 1:26:32 AM2/16/19
to Dmitry Vyukov, syzkaller-o...@googlegroups.com
On Fri, Feb 15, 2019 at 9:10 PM 'Dmitry Vyukov' via syzkaller-openbsd-bugs <syzkaller-o...@googlegroups.com> wrote:
That's when you ask yourself: how did it ever work before?

Poorly :) Interactive kernel debugger modes are not the most tested features.

--
nest.cx is Gmail hosted, use PGP for anything private. Key: http://goo.gl/6dMsr
Fingerprint: 5E2B 2D0E 1E03 2046 BEC3  4D50 0B15 42BD 8DF5 A1B0

Anton Lindqvist

unread,
Feb 16, 2019, 3:24:03 AM2/16/19
to syzbot, syzkaller-o...@googlegroups.com
#syz dup: panic: timeout_add: to_ticks < 0
Reply all
Reply to author
Forward
0 new messages