Hello,
syzbot found the following crash on:
HEAD commit: 8864b422 Switch bpf to use pgsigio(9) and sigio_init(9) in..
git tree: openbsd
console output:
https://syzkaller.appspot.com/x/log.txt?x=153b1fb6e00000
kernel config:
https://syzkaller.appspot.com/x/.config?x=fe55924c11e64b0a
dashboard link:
https://syzkaller.appspot.com/bug?extid=b288cd58e9dc8c092753
Unfortunately, I don't have any reproducer for this crash yet.
IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by:
syzbot+b288cd...@syzkaller.appspotmail.com
panic: unhandled af 115
Stopped at db_enter+0x18: addq $0x8,%rsp
TID PID UID PRFLAGS PFLAGS CPU COMMAND
*401700 39439 0 0 0x4000000 0 syz-executor.0
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:398
panic(ffffffff821b8616) at panic+0x15c sys/kern/subr_prf.c:207
unhandled_af(73) at unhandled_af+0x16
pf_addrcpy(ffff80001d42e4c8,ffff80001d42e7c0,73) at pf_addrcpy+0x99
sys/net/pf.c:409
pfioctl(4900,c0504417,ffff80001d42e7c0,1,ffff8000ffff2290) at
pfioctl+0x43c0 sys/net/pf_ioctl.c:1827
VOP_IOCTL(fffffd805d62a820,c0504417,ffff80001d42e7c0,1,fffffd806c3be5a0,ffff8000ffff2290)
at
VOP_IOCTL+0x88 sys/kern/vfs_vops.c:291
vn_ioctl(fffffd805fae4448,c0504417,ffff80001d42e7c0,ffff8000ffff2290) at
vn_ioctl+0xb7 sys/kern/vfs_vnops.c:533
sys_ioctl(ffff8000ffff2290,ffff80001d42e8d8,ffff80001d42e920) at
sys_ioctl+0x5b9
syscall(ffff80001d42e9a0) at syscall+0x507 sys/arch/amd64/amd64/trap.c:555
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0xf7441b0ab70, count: 5
https://www.openbsd.org/ddb.html describes the minimum info required in bug
reports. Insufficient info makes it difficult to find and fix bugs.
ddb>
ddb> set $lines = 0
ddb> set $maxwidth = 0
ddb> show panic
unhandled af 115
ddb> trace
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:398
panic(ffffffff821b8616) at panic+0x15c sys/kern/subr_prf.c:207
unhandled_af(73) at unhandled_af+0x16
pf_addrcpy(ffff80001d42e4c8,ffff80001d42e7c0,73) at pf_addrcpy+0x99
sys/net/pf.c:409
pfioctl(4900,c0504417,ffff80001d42e7c0,1,ffff8000ffff2290) at
pfioctl+0x43c0 sys/net/pf_ioctl.c:1827
VOP_IOCTL(fffffd805d62a820,c0504417,ffff80001d42e7c0,1,fffffd806c3be5a0,ffff8000ffff2290)
at
VOP_IOCTL+0x88 sys/kern/vfs_vops.c:291
vn_ioctl(fffffd805fae4448,c0504417,ffff80001d42e7c0,ffff8000ffff2290) at
vn_ioctl+0xb7 sys/kern/vfs_vnops.c:533
sys_ioctl(ffff8000ffff2290,ffff80001d42e8d8,ffff80001d42e920) at
sys_ioctl+0x5b9
syscall(ffff80001d42e9a0) at syscall+0x507 sys/arch/amd64/amd64/trap.c:555
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0xf7441b0ab70, count: -10
ddb> show registers
rdi 0xffffffff81f91017 db_enter+0x17
rsi 0xbf6
rbp 0xffff80001d42e380
rbx 0xffff80001d42e430
rdx 0xbf7
rcx 0xffff80001e455000
rax 0xffff80001e455000
r8 0xffff80001d42e340
r9 0x1
r10 0xffff8000009f1400
r11 0xcf1f3cdf68dc5ba3
r12 0x3000000008
r13 0xffff80001d42e390
r14 0x100
r15 0x1
rip 0xffffffff81f91018 db_enter+0x18
cs 0x8
rflags 0x246
rsp 0xffff80001d42e370
ss 0x10
db_enter+0x18: addq $0x8,%rsp
ddb> show proc
PROC (syz-executor.0) pid=401700 stat=onproc
flags process=0 proc=4000000<THREAD>
pri=82, usrpri=82, nice=20
forw=0xffffffffffffffff, list=0xffff8000ffff33d8,0xffffffff8256b098
process=0xffff8000ffff7b50 user=0xffff80001d429000,
vmspace=0xfffffd806bc0a550
estcpu=36, cpticks=0, pctcpu=0.0
user=0, sys=0, intr=0
ddb> ps
PID TID PPID UID S FLAGS WAIT COMMAND
39439 168657 57423 0 2 0 syz-executor.0
*39439 401700 57423 0 7 0x4000000 syz-executor.0
44581 223202 24048 0 2 0x2 syz-executor.1
57423 130739 24048 0 3 0x82 nanosleep syz-executor.0
59101 343719 0 0 3 0x14200 bored sosplice
24048 234317 63717 0 3 0x82 thrsleep syz-fuzzer
24048 266953 63717 0 3 0x4000082 nanosleep syz-fuzzer
24048 255985 63717 0 3 0x4000082 thrsleep syz-fuzzer
24048 316973 63717 0 3 0x4000082 thrsleep syz-fuzzer
24048 122668 63717 0 3 0x4000082 kqread syz-fuzzer
24048 63160 63717 0 3 0x4000082 thrsleep syz-fuzzer
24048 108200 63717 0 3 0x4000082 thrsleep syz-fuzzer
24048 522005 63717 0 3 0x4000082 thrsleep syz-fuzzer
63717 81902 15225 0 3 0x10008a pause ksh
15225 348858 95675 0 3 0x92 select sshd
3120 316471 1 0 3 0x100083 ttyin getty
95675 71751 1 0 3 0x80 select sshd
38557 265719 61903 73 3 0x100090 kqread syslogd
61903 191417 1 0 3 0x100082 netio syslogd
99341 472762 1 77 3 0x100090 poll dhclient
47606 116500 1 0 3 0x80 poll dhclient
47559 426285 0 0 2 0x14200 zerothread
3914 510463 0 0 3 0x14200 aiodoned aiodoned
66551 27204 0 0 3 0x14200 syncer update
75916 198305 0 0 3 0x14200 cleaner cleaner
40177 348545 0 0 3 0x14200 reaper reaper
53570 63419 0 0 3 0x14200 pgdaemon pagedaemon
84112 92753 0 0 3 0x14200 bored crynlk
18152 474238 0 0 3 0x14200 bored crypto
43364 491068 0 0 3 0x40014200 acpi0 acpi0
24689 361428 0 0 3 0x14200 bored softnet
37637 354789 0 0 3 0x14200 bored systqmp
37758 147777 0 0 3 0x14200 bored systq
95408 288675 0 0 3 0x40014200 bored softclock
13963 442023 0 0 3 0x40014200 idle0
85744 81832 0 0 3 0x14200 bored smr
1 383658 0 0 3 0x82 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb> show all locks
No such command
ddb> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 9455 6340K 6905K 78643K 25429 0
pcb 13 8K 8K 78643K 5286 0
rtable 108 3K 4K 78643K 589 0
ifaddr 39 10K 10K 78643K 124 0
counters 19 16K 16K 78643K 19 0
ioctlops 0 0K 4K 78643K 4088 0
iov 0 0K 16K 78643K 1834 0
mount 1 1K 1K 78643K 1 0
vnodes 1232 77K 77K 78643K 11945 0
UFS quota 1 32K 32K 78643K 1 0
UFS mount 5 36K 36K 78643K 5 0
shm 2 1K 9K 78643K 277 0
VM map 2 0K 0K 78643K 2 0
sem 12 0K 0K 78643K 408 0
dirhash 12 2K 2K 78643K 12 0
ACPI 1794 195K 288K 78643K 12646 0
file desc 5 13K 25K 78643K 45354 0
sigio 0 0K 2K 78643K 3418 0
proc 395 60K 75K 78643K 1354 0
subproc 32 2K 2K 78643K 187 0
NFS srvsock 1 0K 0K 78643K 1 0
NFS daemon 1 16K 16K 78643K 1 0
ip_moptions 0 0K 0K 78643K 280 0
in_multi 33 2K 2K 78643K 139 0
ether_multi 1 0K 0K 78643K 1 0
ISOFS mount 1 32K 32K 78643K 1 0
MSDOSFS mount 1 16K 16K 78643K 1 0
ttys 55 254K 254K 78643K 55 0
exec 0 0K 1K 78643K 328 0
pagedep 1 8K 8K 78643K 1 0
inodedep 1 32K 32K 78643K 1 0
newblk 1 0K 0K 78643K 1 0
VM swap 7 26K 26K 78643K 7 0
UVM amap 156 23K 32K 78643K 94070 0
UVM aobj 130 6K 6K 78643K 140 0
memdesc 1 4K 4K 78643K 1 0
crypto data 1 1K 1K 78643K 1 0
ip6_options 0 0K 0K 78643K 3855 0
NDP 5 0K 0K 78643K 40 0
temp 103 3021K 3094K 78643K 159466 0
kqueue 0 0K 0K 78643K 197 0
SYN cache 2 16K 16K 78643K 2 0
ddb> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg
Idle
arp 64 26 0 20 1 0 1 1 0
8 0
rtpcb 80 631 0 629 1 0 1 1 0
8 0
rtentry 112 137 0 93 2 0 2 2 0
8 0
unpcb 120 109147 0 109139 77 75 2 4 0
8 1
syncache 264 4 0 4 1 1 0 1 0
8 0
sackhl 24 24 0 24 13 13 0 1 0
8 0
tcpcb 544 3475 0 3471 1 0 1 1 0
8 0
inpcb 280 16296 0 16289 3 2 1 2 0
8 0
nd6 48 22 0 18 1 0 1 1 0
8 0
pkpcb 40 14 0 14 3 3 0 1 0
8 0
ppxss 1128 4 0 4 1 1 0 1 0
8 0
art_heap8 4096 1 0 0 1 0 1 1 0
8 0
art_heap4 256 602 0 387 14 0 14 14 0
8 0
art_table 32 603 0 387 2 0 2 2 0
8 0
art_node 16 136 0 96 1 0 1 1 0
8 0
sysvmsgpl 40 17 0 15 2 1 1 1 0
8 0
semapl 112 406 0 396 1 0 1 1 0
8 0
shmpl 112 138 0 10 4 0 4 4 0
8 0
dirhash 1024 17 0 0 3 0 3 3 0
8 0
dino1pl 128 50643 0 49023 53 0 53 53 0
8 0
ffsino 240 50643 0 49023 97 1 96 96 0
8 0
nchpl 144 103649 0 101966 63 0 63 63 0
8 0
uvmvnodes 72 7845 0 0 143 0 143 143 0
8 0
vnodes 208 7845 0 0 413 0 413 413 0
8 0
namei 1024 254490 0 254490 1 0 1 1 0
8 1
vmpool 528 5 0 5 1 1 0 1 0
8 0
scxspl 192 302890 0 302890 1 0 1 1 0
8 1
plimitpl 152 790 0 783 1 0 1 1 0
8 0
sigapl 432 45498 0 45485 2 0 2 2 0
8 0
futexpl 56 373880 0 373880 1 0 1 1 0
8 1
knotepl 112 5748 0 5729 1 0 1 1 0
8 0
kqueuepl 104 12238 0 12236 1 0 1 1 0
8 0
pipepl 112 24784 0 24765 31 30 1 2 0
8 0
fdescpl 424 45499 0 45485 2 0 2 2 0
8 0
filepl 120 259328 0 259228 86 81 5 7 0
8 1
lockfpl 104 3316 0 3315 1 0 1 1 0
8 0
lockfspl 48 1431 0 1430 1 0 1 1 0
8 0
sessionpl 112 26 0 16 1 0 1 1 0
8 0
pgrppl 48 503 0 493 1 0 1 1 0
8 0
ucredpl 96 17624 0 17595 1 0 1 1 0
8 0
zombiepl 144 45485 0 45485 1 0 1 1 0
8 1
processpl 872 45514 0 45485 4 0 4 4 0
8 0
procpl 632 92575 0 92538 4 0 4 4 0
8 0
sockpl 384 126123 0 126106 258 252 6 14 0
8 4
mcl64k 65536 433 0 433 32 32 0 1 0
8 0
mcl16k 16384 117 0 117 31 31 0 1 0
8 0
mcl12k 12288 1109 0 1109 47 47 0 1 0
8 0
mcl9k 9216 630 0 630 36 36 0 1 0
8 0
mcl8k 8192 1453 0 1453 53 53 0 1 0
8 0
mcl4k 4096 2479 0 2479 39 38 1 1 0
8 1
mcl2k2 2112 174 0 174 51 51 0 1 0
8 0
mcl2k 2048 79538 0 79510 68 64 4 7 0
8 0
mtagpl 80 2 0 2 1 1 0 1 0
8 0
mbufpl 256 377754 0 377673 30 22 8 12 0
8 0
bufpl 280 67430 0 59583 561 0 561 561 0
8 0
anonpl 16 2611828 0 2607574 52 32 20 34 0
107 0
amapchunkpl 152 145938 0 145848 33 28 5 18 0
158 0
amappl16 192 183971 0 183787 34 24 10 22 0
8 0
amappl15 184 520 0 516 1 0 1 1 0
8 0
amappl14 176 10646 0 10644 1 0 1 1 0
8 0
amappl13 168 23347 0 23344 1 0 1 1 0
8 0
amappl12 160 330 0 329 1 0 1 1 0
8 0
amappl11 152 10833 0 10822 1 0 1 1 0
8 0
amappl10 144 17 0 14 1 0 1 1 0
8 0
amappl9 136 695 0 691 1 0 1 1 0
8 0
amappl8 128 651 0 564 5 2 3 3 0
8 0
amappl7 120 147 0 134 1 0 1 1 0
8 0
amappl6 112 10791 0 10779 1 0 1 1 0
8 0
amappl5 104 938 0 928 1 0 1 1 0
8 0
amappl4 96 46601 0 46569 1 0 1 1 0
8 0
amappl3 88 23020 0 23012 1 0 1 1 0
8 0
amappl2 80 373496 0 373422 3 1 2 3 0
8 0
amappl1 72 740589 0 740160 25 15 10 20 0
8 0
amappl 80 92950 0 92916 1 0 1 1 0
84 0
dma4096 4096 1 0 1 1 1 0 1 0
8 0
dma256 256 6 0 6 1 1 0 1 0
8 0
dma128 128 253 0 253 1 1 0 1 0
8 0
dma64 64 6 0 6 1 1 0 1 0
8 0
dma32 32 7 0 7 1 1 0 1 0
8 0
dma16 16 18 0 17 1 0 1 1 0
8 0
aobjpl 64 139 0 10 3 0 3 3 0
8 0
uaddrrnd 24 45504 0 45490 1 0 1 1 0
8 0
uaddrbest 32 2 0 0 1 0 1 1 0
8 0
uaddr 24 45504 0 45490 1 0 1 1 0
8 0
vmmpekpl 168 217926 0 217905 2 0 2 2 0
8 0
vmmpepl 168 5045886 0 5044528 133 68 65 79 0
357 4
vmsppl 272 45503 0 45490 3 2 1 2 0
8 0
pdppl 4096 91014 0 90980 6 1 5 6 0
8 0
pvpl 32 7654092 0 7646784 339 276 63 116 0
265 1
pmappl 200 45503 0 45490 1 0 1 1 0
8 0
extentpl 40 46 0 29 1 0 1 1 0
8 0
phpool 112 381 0 246 4 0 4 4 0
8 0
---
This bug is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.