uvm_fault: vio_start

0 views
Skip to first unread message

syzbot

unread,
Feb 15, 2020, 12:29:15 PM2/15/20
to syzkaller-o...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 2298c3ea get rid of an awkward ellipsis noticed by Jan Sta..
git tree: openbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=1655ef01e00000
kernel config: https://syzkaller.appspot.com/x/.config?x=bf87b6915a88cd0d
dashboard link: https://syzkaller.appspot.com/bug?extid=e33ebcc458383adf065a

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+e33ebc...@syzkaller.appspotmail.com

uvm_fault(0xffffffff82633f78, 0xc, 0, 1) -> e
kernel: page fault trap, code=0
Stopped at vio_start+0x192: movzwl 0xc(%rax),%esi
ddb{0}>
ddb{0}> set $lines = 0
ddb{0}> set $maxwidth = 0
ddb{0}> show panic
kernel page fault
uvm_fault(0xffffffff82633f78, 0xc, 0, 1) -> e
vio_start(ffff80000017b2a8) at vio_start+0x192 sys/dev/pv/if_vio.c:758
end trace frame: 0xffff800020a4fbf0, count: 0
ddb{0}> trace
vio_start(ffff80000017b2a8) at vio_start+0x192 sys/dev/pv/if_vio.c:758
if_qstart_compat(ffff80000017b520) at if_qstart_compat+0x36 sys/net/if.c:684
ifq_serialize(ffff80000017b520,ffff80000017b630) at ifq_serialize+0x173 sys/net/ifq.c:108
taskq_thread(ffff80000002b080) at taskq_thread+0x9c sys/kern/kern_task.c:369
end trace frame: 0x0, count: -4
ddb{0}> show registers
rdi 0
rsi 0x2
rbp 0xffff800020a4fbc0
rbx 0x2
rdx 0xc
rcx 0
rax 0
r8 0xffffffff813f30da vio_start+0x13a
r9 0x5
r10 0xe79ee0ab465cc64b
r11 0x11ce0cab27b95358
r12 0x2
r13 0x2a
r14 0xffff80000017b000
r15 0xfffffd806348a100
rip 0xffffffff813f3132 vio_start+0x192
cs 0x8
rflags 0x10202 __ALIGN_SIZE+0xf202
rsp 0xffff800020a4fb20
ss 0x10
vio_start+0x192: movzwl 0xc(%rax),%esi
ddb{0}> show proc
PROC (softnet) pid=97494 stat=onproc
flags process=14000<NOZOMBIE,SYSTEM> proc=200<SYSTEM>
pri=50, usrpri=50, nice=20
forw=0xffffffffffffffff, list=0xffff800020a28000,0xffff800020a284f0
process=0xffff800020a2a000 user=0xffff800020a4a000, vmspace=0xffffffff82633f78
estcpu=0, cpticks=1, pctcpu=0.49
user=0, sys=1, intr=0
ddb{0}> ps
PID TID PPID UID S FLAGS WAIT COMMAND
26994 269462 88722 0 7 0 syz-executor.1
26994 267218 88722 0 2 0x4000080 syz-executor.1
26994 402938 88722 0 3 0x4000080 fsleep syz-executor.1
44133 55382 35767 0 2 0 syz-executor.0
44133 57736 35767 0 3 0x4000080 fsleep syz-executor.0
44133 81301 35767 0 3 0x4000080 fsleep syz-executor.0
72267 27890 0 0 3 0x14200 bored sosplice
88722 162106 75569 0 3 0x82 nanosleep syz-executor.1
35767 259566 75569 0 3 0x82 nanosleep syz-executor.0
75569 365851 17970 0 3 0x82 thrsleep syz-fuzzer
75569 319931 17970 0 3 0x4000082 nanosleep syz-fuzzer
75569 10167 17970 0 3 0x4000082 thrsleep syz-fuzzer
75569 41977 17970 0 3 0x4000082 kqread syz-fuzzer
75569 231176 17970 0 3 0x4000082 thrsleep syz-fuzzer
75569 506390 17970 0 3 0x4000082 thrsleep syz-fuzzer
75569 221889 17970 0 3 0x4000082 thrsleep syz-fuzzer
75569 493406 17970 0 3 0x4000082 thrsleep syz-fuzzer
75569 208768 17970 0 3 0x4000082 thrsleep syz-fuzzer
75569 118831 17970 0 3 0x4000082 thrsleep syz-fuzzer
17970 392282 67214 0 3 0x10008a pause ksh
67214 87781 85603 0 3 0x92 select sshd
63232 36763 1 0 3 0x100083 ttyin getty
85603 485895 1 0 3 0x80 select sshd
43525 280023 54885 74 3 0x100092 bpf pflogd
54885 133356 1 0 3 0x80 netio pflogd
72551 140503 67763 73 3 0x100090 kqread syslogd
67763 338445 1 0 3 0x100082 netio syslogd
20719 378056 1 77 3 0x100090 poll dhclient
67936 103179 1 0 3 0x80 poll dhclient
15969 363265 0 0 2 0x14200 zerothread
93053 489193 0 0 3 0x14200 aiodoned aiodoned
92484 235607 0 0 3 0x14200 syncer update
11853 186674 0 0 3 0x14200 cleaner cleaner
28992 66120 0 0 3 0x14200 reaper reaper
42670 205432 0 0 3 0x14200 pgdaemon pagedaemon
53135 10297 0 0 3 0x14200 bored crynlk
56667 242609 0 0 3 0x14200 bored crypto
89126 200356 0 0 3 0x40014200 acpi0 acpi0
84749 423764 0 0 3 0x40014200 idle1
*10569 97494 0 0 7 0x14200 softnet
94028 382306 0 0 3 0x14200 bored systqmp
93798 139154 0 0 3 0x14200 bored systq
50397 280557 0 0 3 0x40014200 bored softclock
61388 98431 0 0 3 0x40014200 idle0
7764 321485 0 0 3 0x14200 bored smr
1 214328 0 0 3 0x82 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb{0}> show all locks
CPU 0:
exclusive mutex &ifq->ifq_mtx r = 0 (0xffff80000017b548)
#0 witness_lock+0x52e sys/kern/subr_witness.c:1164
#1 mtx_enter_try+0x102
#2 mtx_enter+0x4b sys/kern/kern_lock.c:266
#3 ifq_deq_begin+0x31 sys/net/ifq.c:345
#4 vio_start+0xf6 sys/dev/pv/if_vio.c:735
#5 if_qstart_compat+0x36 sys/net/if.c:684
#6 ifq_serialize+0x173 sys/net/ifq.c:108
#7 taskq_thread+0x9c sys/kern/kern_task.c:369
#8 proc_trampoline+0x1c
Process 10569 (softnet) thread 0xffff800020a28270 (97494)
exclusive kernel_lock &kernel_lock r = 1 (0xffffffff826518c0)
#0 witness_lock+0x52e sys/kern/subr_witness.c:1164
#1 if_qstart_compat+0x1a sys/net/if.c:682
#2 ifq_serialize+0x173 sys/net/ifq.c:108
#3 taskq_thread+0x9c sys/kern/kern_task.c:369
#4 proc_trampoline+0x1c
shared rwlock softnet r = 0 (0xffff80000002b0e0)
#0 witness_lock+0x52e sys/kern/subr_witness.c:1164
#1 taskq_thread+0x8f sys/kern/kern_task.c:368
#2 proc_trampoline+0x1c
exclusive mutex &ifq->ifq_mtx r = 0 (0xffff80000017b548)
#0 witness_lock+0x52e sys/kern/subr_witness.c:1164
#1 mtx_enter_try+0x102
#2 mtx_enter+0x4b sys/kern/kern_lock.c:266
#3 ifq_deq_begin+0x31 sys/net/ifq.c:345
#4 vio_start+0xf6 sys/dev/pv/if_vio.c:735
#5 if_qstart_compat+0x36 sys/net/if.c:684
#6 ifq_serialize+0x173 sys/net/ifq.c:108
#7 taskq_thread+0x9c sys/kern/kern_task.c:369
#8 proc_trampoline+0x1c
ddb{0}> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 9510 6414K 7456K 78643K 11208 0
pcb 13 8K 8K 78643K 80 0
rtable 104 3K 4K 78643K 280 0
ifaddr 68 13K 14K 78643K 102 0
counters 43 33K 34K 78643K 53 0
ioctlops 0 0K 4K 78643K 1477 0
iov 0 0K 16K 78643K 52 0
mount 1 1K 1K 78643K 1 0
vnodes 1227 77K 77K 78643K 1395 0
UFS quota 1 32K 32K 78643K 1 0
UFS mount 5 36K 36K 78643K 5 0
shm 2 1K 5K 78643K 4 0
VM map 2 1K 1K 78643K 2 0
sem 12 0K 0K 78643K 96 0
dirhash 12 2K 2K 78643K 12 0
ACPI 1809 196K 290K 78643K 12766 0
file desc 6 17K 25K 78643K 242 0
sigio 0 0K 0K 78643K 17 0
proc 61 63K 95K 78643K 455 0
subproc 32 2K 2K 78643K 34 0
NFS srvsock 1 0K 0K 78643K 1 0
NFS daemon 1 16K 16K 78643K 1 0
ip_moptions 0 0K 0K 78643K 22 0
in_multi 43 2K 3K 78643K 85 0
ether_multi 1 0K 0K 78643K 16 0
mrt 0 0K 0K 78643K 4 0
ISOFS mount 1 32K 32K 78643K 1 0
MSDOSFS mount 1 16K 16K 78643K 1 0
ttys 49 228K 228K 78643K 49 0
exec 0 0K 1K 78643K 237 0
pagedep 1 8K 8K 78643K 1 0
inodedep 1 32K 32K 78643K 1 0
newblk 1 0K 0K 78643K 1 0
VM swap 7 26K 26K 78643K 7 0
UVM amap 127 24K 24K 78643K 1770 0
UVM aobj 16 2K 2K 78643K 16 0
memdesc 1 4K 4K 78643K 1 0
crypto data 1 1K 1K 78643K 1 0
ip6_options 0 0K 0K 78643K 67 0
NDP 11 0K 0K 78643K 21 0
temp 103 3012K 3080K 78643K 11847 0
kqueue 3 4K 8K 78643K 18 0
SYN cache 2 16K 16K 78643K 2 0
ddb{0}> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg Idle
arp 64 7 0 1 1 0 1 1 0 8 0
plcache 128 20 0 0 1 0 1 1 0 8 0
rtpcb 80 37 0 35 1 0 1 1 0 8 0
rtentry 112 58 0 16 2 0 2 2 0 8 0
unpcb 120 207 0 197 1 0 1 1 0 8 0
syncache 264 4 0 4 1 1 0 1 0 8 0
tcpcb 544 122 0 118 1 0 1 1 0 8 0
inpcb 280 404 0 396 3 1 2 2 0 8 1
rttmr 72 1 0 1 1 1 0 1 0 8 0
nd6 48 10 0 5 1 0 1 1 0 8 0
pkpcb 40 2 0 2 1 0 1 1 0 8 1
ppxss 1128 1 0 1 1 0 1 1 0 8 1
pffrag 232 6 0 6 1 0 1 1 0 482 1
pffrnode 88 6 0 6 1 0 1 1 0 8 1
pffrent 40 270 0 270 1 0 1 1 0 8 1
pfosfp 40 846 0 423 5 0 5 5 0 8 0
pfosfpen 112 1428 0 714 21 0 21 21 0 8 0
pfstitem 24 47 0 5 1 0 1 1 0 8 0
pfstkey 112 47 0 5 2 0 2 2 0 8 0
pfstate 328 47 0 5 4 0 4 4 0 8 0
pfrule 1360 21 0 16 2 1 1 2 0 8 0
art_heap8 4096 1 0 0 1 0 1 1 0 8 0
art_heap4 256 238 0 46 14 0 14 14 0 8 0
art_table 32 239 0 46 2 0 2 2 0 8 0
art_node 16 57 0 18 1 0 1 1 0 8 0
sysvmsgpl 40 10 0 2 1 0 1 1 0 8 0
semupl 112 8 0 8 1 1 0 1 0 8 0
semapl 112 94 0 84 1 0 1 1 0 8 0
shmpl 112 14 0 0 1 0 1 1 0 8 0
dirhash 1024 17 0 0 3 0 3 3 0 8 0
dino1pl 128 1743 0 335 46 0 46 46 0 8 0
ffsino 272 1743 0 335 95 0 95 95 0 8 0
nchpl 144 2413 0 797 61 0 61 61 0 8 0
uvmvnodes 72 1921 0 0 35 0 35 35 0 8 0
vnodes 208 1921 0 0 102 0 102 102 0 8 0
namei 1024 6680 0 6680 1 0 1 1 0 8 1
percpumem 16 37 0 5 1 0 1 1 0 8 0
vcpupl 1984 2 0 0 1 0 1 1 0 8 0
vmpool 560 2 0 0 1 0 1 1 0 8 0
scxspl 192 6980 0 6980 8 5 3 7 0 8 3
plimitpl 152 37 0 29 1 0 1 1 0 8 0
sigapl 432 441 0 425 3 1 2 3 0 8 0
futexpl 56 4830 0 4827 1 0 1 1 0 8 0
knotepl 112 75 0 56 1 0 1 1 0 8 0
kqueuepl 144 35 0 30 1 0 1 1 0 8 0
pipelkpl 48 153 0 142 1 0 1 1 0 8 0
pipepl 120 306 0 285 3 1 2 2 0 8 1
fdescpl 496 442 0 425 3 0 3 3 0 8 0
filepl 152 3234 0 3128 7 2 5 6 0 8 0
lockfpl 104 65 0 64 1 0 1 1 0 8 0
lockfspl 48 26 0 25 1 0 1 1 0 8 0
sessionpl 112 18 0 7 1 0 1 1 0 8 0
pgrppl 48 20 0 9 1 0 1 1 0 8 0
ucredpl 96 253 0 244 1 0 1 1 0 8 0
zombiepl 144 425 0 425 1 0 1 1 0 8 1
processpl 960 458 0 425 5 0 5 5 0 8 0
procpl 624 995 0 949 4 0 4 4 0 8 0
sosppl 128 6 0 6 1 0 1 1 0 8 1
sockpl 400 656 0 636 5 1 4 5 0 8 2
mcl64k 65536 11 0 0 2 0 2 2 0 8 0
mcl16k 16384 1 0 0 1 0 1 1 0 8 0
mcl12k 12288 2 0 0 1 0 1 1 0 8 0
mcl9k 9216 3 0 0 1 0 1 1 0 8 0
mcl8k 8192 4 0 0 1 0 1 1 0 8 0
mcl4k 4096 10 0 0 2 0 2 2 0 8 0
mcl2k2 2112 2 0 0 1 0 1 1 0 8 0
mcl2k 2048 187 0 0 23 0 23 23 0 8 0
mtagpl 80 39 0 0 1 0 1 1 0 8 0
mbufpl 256 310 0 0 19 0 19 19 0 8 0
bufpl 280 4692 0 174 323 0 323 323 0 8 0
anonpl 16 58395 0 37257 87 1 86 86 0 125 0
amapchunkpl 152 2369 0 2208 8 1 7 8 0 158 0
amappl16 192 2364 0 1189 60 0 60 60 0 8 0
amappl15 184 1 0 0 1 0 1 1 0 8 0
amappl14 176 6 0 3 2 1 1 1 0 8 0
amappl13 168 128 0 125 1 0 1 1 0 8 0
amappl12 160 3 0 2 2 1 1 1 0 8 0
amappl11 152 74 0 56 1 0 1 1 0 8 0
amappl10 144 19 0 15 1 0 1 1 0 8 0
amappl9 136 396 0 392 1 0 1 1 0 8 0
amappl8 128 329 0 297 3 1 2 2 0 8 0
amappl7 120 120 0 109 1 0 1 1 0 8 0
amappl6 112 37 0 28 1 0 1 1 0 8 0
amappl5 104 137 0 122 1 0 1 1 0 8 0
amappl4 96 810 0 775 2 1 1 2 0 8 0
amappl3 88 110 0 103 1 0 1 1 0 8 0
amappl2 80 2583 0 2507 3 1 2 3 0 8 0
amappl1 72 19948 0 19482 25 15 10 20 0 8 0
amappl 80 1246 0 1197 2 0 2 2 0 84 0
dma4096 4096 1 0 1 1 1 0 1 0 8 0
dma256 256 6 0 6 1 1 0 1 0 8 0
dma128 128 253 0 253 1 1 0 1 0 8 0
dma64 64 6 0 6 1 1 0 1 0 8 0
dma32 32 7 0 7 1 1 0 1 0 8 0
dma16 16 18 0 17 1 0 1 1 0 8 0
aobjpl 64 15 0 0 1 0 1 1 0 8 0
uaddrrnd 24 444 0 425 1 0 1 1 0 8 0
uaddrbest 32 2 0 0 1 0 1 1 0 8 0
uaddr 24 444 0 425 1 0 1 1 0 8 0
vmmpekpl 168 7583 0 7545 2 0 2 2 0 8 0
vmmpepl 168 61211 0 58760 122 15 107 119 0 357 0
vmsppl 368 443 0 425 2 0 2 2 0 8 0
pdppl 4096 895 0 852 6 0 6 6 0 8 0
pvpl 32 185566 0 160694 201 0 201 201 0 265 0
pmappl 232 443 0 425 3 1 2 2 0 8 0
extentpl 40 46 0 29 1 0 1 1 0 8 0
phpool 112 184 0 4 6 0 6 6 0 8 0


---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
May 15, 2020, 1:29:11 PM5/15/20
to syzkaller-o...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages