Hello,
syzbot found the following crash on:
HEAD commit: f475d39e Bring back EVP_chacha20 list item that was accide..
git tree: openbsd
console output:
https://syzkaller.appspot.com/x/log.txt?x=1460e07d200000
kernel config:
https://syzkaller.appspot.com/x/.config?x=ffa1da4399f74b2b
dashboard link:
https://syzkaller.appspot.com/bug?extid=989f8e27257a60293bf6
Unfortunately, I don't have any reproducer for this crash yet.
IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by:
syzbot+989f8e...@syzkaller.appspotmail.com
panic() at panic+0x15c sys/kern/subr_prf.c:208
fifo_badop(ffff800014a4c0a0) at fifo_badop+0x14
sys/miscfs/fifofs/fifo_vnops.c:491
VOP_STRATEGY(fffffd802f4dad00) at VOP_STRATEGY+0xa5 sys/kern/vfs_vops.c:719
bwrite(fffffd802f4dad00) at bwrite+0x203 sys/kern/vfs_bio.c:742
VOP_BWRITE(fffffd802f4dad00) at VOP_BWRITE+0x56 sys/kern/vfs_vops.c:731
ufs_mkdir(ffff800014a4c340) at ufs_mkdir+0x741 sys/ufs/ufs/ufs_vnops.c:1250
VOP_MKDIR(fffffd8039fc3200,ffff800014a4c3f8,ffff800014a4c448,ffff800014a4c488)
at
VOP_MKDIR+0x76 sys/kern/vfs_vops.c:449
domkdirat(ffff8000ffff8e18,ffffff9c,7f7fffff1920,1ff) at domkdirat+0x12d
sys/kern/vfs_syscalls.c:2881
syscall(ffff800014a4c680) at syscall+0x541
Xsyscall(6,88,7f7fffff1920,88,0,7f7fffff1944) at Xsyscall+0x128
end of kernel
end trace frame: 0x7f7fffff1990, count: 4
https://www.openbsd.org/ddb.html describes the minimum info required in bug
reports. Insufficient info makes it difficult to find and fix bugs.
ddb>
ddb> set $lines = 0
ddb> set $maxwidth = 0
ddb> show panic
fifo_badop called
ddb> trace
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:399
panic() at panic+0x15c sys/kern/subr_prf.c:208
fifo_badop(ffff800014a4c0a0) at fifo_badop+0x14
sys/miscfs/fifofs/fifo_vnops.c:491
VOP_STRATEGY(fffffd802f4dad00) at VOP_STRATEGY+0xa5 sys/kern/vfs_vops.c:719
bwrite(fffffd802f4dad00) at bwrite+0x203 sys/kern/vfs_bio.c:742
VOP_BWRITE(fffffd802f4dad00) at VOP_BWRITE+0x56 sys/kern/vfs_vops.c:731
ufs_mkdir(ffff800014a4c340) at ufs_mkdir+0x741 sys/ufs/ufs/ufs_vnops.c:1250
VOP_MKDIR(fffffd8039fc3200,ffff800014a4c3f8,ffff800014a4c448,ffff800014a4c488)
at
VOP_MKDIR+0x76 sys/kern/vfs_vops.c:449
domkdirat(ffff8000ffff8e18,ffffff9c,7f7fffff1920,1ff) at domkdirat+0x12d
sys/kern/vfs_syscalls.c:2881
syscall(ffff800014a4c680) at syscall+0x541
Xsyscall(6,88,7f7fffff1920,88,0,7f7fffff1944) at Xsyscall+0x128
end of kernel
end trace frame: 0x7f7fffff1990, count: -11
ddb> show registers
rdi 0
rsi 0x1
rbp 0xffff800014a4bfd0
rbx 0xffff800014a4c080
rdx 0x2
rcx 0
rax 0
r8 0xffff800014a4bf90
r9 0x1
r10 0
r11 0xebf3fe13395d9d16
r12 0x3000000008
r13 0xffff800014a4bfe0
r14 0x100
r15 0x1
rip 0xffffffff81679bb8 db_enter+0x18
cs 0x8
rflags 0x246
rsp 0xffff800014a4bfc0
ss 0x10
db_enter+0x18: addq $0x8,%rsp
ddb> show proc
PROC (syz-executor.1) pid=335837 stat=onproc
flags process=2<EXEC> proc=0
pri=17, usrpri=86, nice=20
forw=0xffffffffffffffff, list=0xffff8000149eebd0,0xffffffff822df660
process=0xffff8000ffff7a50 user=0xffff800014a47000,
vmspace=0xfffffd803f014420
estcpu=36, cpticks=5, pctcpu=0.0
user=0, sys=4, intr=0
ddb> ps
PID TID PPID UID S FLAGS WAIT COMMAND
*36262 335837 32027 0 7 0x2 syz-executor.1
33501 238988 1 0 3 0x100083 ttyin getty
16373 218416 32027 0 2 0x2 syz-executor.0
58463 154698 0 0 3 0x14200 bored sosplice
32027 67392 53612 0 3 0x82 thrsleep syz-fuzzer
32027 241652 53612 0 3 0x4000082 thrsleep syz-fuzzer
32027 279020 53612 0 3 0x4000082 thrsleep syz-fuzzer
32027 351304 53612 0 3 0x4000082 thrsleep syz-fuzzer
32027 197283 53612 0 3 0x4000082 thrsleep syz-fuzzer
32027 42607 53612 0 3 0x4000082 kqread syz-fuzzer
32027 189019 53612 0 3 0x4000082 thrsleep syz-fuzzer
32027 325271 53612 0 3 0x4000082 thrsleep syz-fuzzer
32027 119231 53612 0 3 0x4000082 thrsleep syz-fuzzer
53612 219832 63662 0 3 0x10008a pause ksh
63662 311132 42411 0 3 0x92 select sshd
42411 53685 1 0 3 0x80 select sshd
18529 188670 24918 73 3 0x100090 kqread syslogd
24918 430186 1 0 3 0x100082 netio syslogd
54199 321788 1 77 3 0x100090 poll dhclient
21032 336329 1 0 3 0x80 poll dhclient
19807 365687 0 0 3 0x14200 pgzero zerothread
19947 362134 0 0 3 0x14200 aiodoned aiodoned
61564 434071 0 0 3 0x14200 syncer update
22815 78815 0 0 3 0x14200 cleaner cleaner
78853 167417 0 0 3 0x14200 reaper reaper
77184 106695 0 0 3 0x14200 pgdaemon pagedaemon
26378 73595 0 0 3 0x14200 bored crynlk
86355 503576 0 0 3 0x14200 bored crypto
10471 512194 0 0 3 0x40014200 acpi0 acpi0
32526 327232 0 0 3 0x14200 bored softnet
2950 382305 0 0 3 0x14200 bored systqmp
39804 294227 0 0 3 0x14200 bored systq
10095 286749 0 0 3 0x40014200 bored softclock
33906 104420 0 0 3 0x40014200 idle0
53323 509842 0 0 3 0x14200 bored smr
1 517205 0 0 3 0x82 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb> show all locks
No such command
ddb> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim Kern Lim
devbuf 9524 6354K 6370K 78643K 11609 0 0
pcb 23 9K 11K 78643K 1457 0 0
rtable 100 3K 4K 78643K 1620 0 0
ifaddr 62 17K 18K 78643K 567 0 0
counters 19 16K 16K 78643K 19 0 0
ioctlops 0 0K 2K 78643K 75 0 0
iov 0 0K 24K 78643K 411 0 0
mount 1 1K 1K 78643K 1 0 0
vnodes 1208 76K 76K 78643K 3097 0 0
UFS quota 1 32K 32K 78643K 1 0 0
UFS mount 5 36K 36K 78643K 5 0 0
shm 2 1K 5K 78643K 26 0 0
VM map 2 0K 0K 78643K 2 0 0
sem 12 0K 1K 78643K 332 0 0
dirhash 12 2K 2K 78643K 12 0 0
ACPI 1793 195K 288K 78643K 12537 0 0
file desc 4 9K 25K 78643K 2541 0 0
sigio 0 0K 0K 78643K 45 0 0
proc 42 30K 54K 78643K 1088 0 0
subproc 64 65538K 69634K 78643K 973 0 0
NFS srvsock 1 0K 0K 78643K 1 0 0
NFS daemon 1 16K 16K 78643K 1 0 0
ip_moptions 0 0K 0K 78643K 336 0 0
in_multi 33 2K 2K 78643K 443 0 0
ether_multi 1 0K 0K 78643K 28 0 0
mrt 0 0K 0K 78643K 5 0 0
ISOFS mount 1 32K 32K 78643K 1 0 0
MSDOSFS mount 1 16K 16K 78643K 1 0 0
ttys 102 450K 450K 78643K 102 0 0
exec 0 0K 1K 78643K 752 0 0
pfkey data 0 0K 1K 78643K 3 0 0
pagedep 1 8K 8K 78643K 1 0 0
inodedep 1 32K 32K 78643K 1 0 0
newblk 1 0K 0K 78643K 1 0 0
VM swap 7 26K 26K 78643K 7 0 0
UVM amap 95 21K 24K 78643K 7730 0 0
UVM aobj 107 3K 3K 78643K 122 0 0
memdesc 1 4K 4K 78643K 1 0 0
crypto data 1 1K 1K 78643K 1 0 0
ip6_options 0 0K 1K 78643K 107 0 0
NDP 13 0K 0K 78643K 187 0 0
temp 177 2359K 2427K 78643K 11349 0 0
kqueue 0 0K 0K 78643K 11 0 0
SYN cache 2 16K 16K 78643K 2 0 0
ddb> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg
Idle
arp 64 30 0 26 1 0 1 1 0
8 0
inpcbpl 280 1183 0 1176 1 0 1 1 0
8 0
plimitpl 152 109 0 102 1 0 1 1 0
8 0
rtentry 112 277 0 237 2 0 2 2 0
8 0
syncache 264 4 0 4 1 1 0 1 0
8 0
tcpqe 32 4 0 4 1 1 0 1 0
8 0
tcpcb 544 444 0 440 1 0 1 1 0
8 0
nd6 48 56 0 52 1 0 1 1 0
8 0
ppxss 1128 77 0 77 25 25 0 1 0
8 0
art_heap8 4096 1 0 0 1 0 1 1 0
8 0
art_heap4 256 1283 0 1091 14 2 12 13 0
8 0
art_table 32 1284 0 1091 2 0 2 2 0
8 0
art_node 16 274 0 240 1 0 1 1 0
8 0
sysvmsgpl 40 11 0 8 2 1 1 1 0
8 0
semupl 112 1 0 1 1 1 0 1 0
8 0
semapl 112 330 0 320 1 0 1 1 0
8 0
shmpl 112 120 0 15 4 0 4 4 0
8 1
dirhash 1024 17 0 0 3 0 3 3 0
8 0
dino1pl 128 6224 0 4688 50 0 50 50 0
8 0
ffsino 240 6224 0 4688 92 1 91 91 0
8 0
nchpl 144 9912 0 8214 64 0 64 64 0
8 0
uvmvnodes 72 5926 0 0 108 0 108 108 0
8 0
vnodes 200 5926 0 0 312 0 312 312 0
8 0
namei 1024 32543 0 32542 4 3 1 1 0
8 0
scsiplug 64 8 0 8 6 6 0 1 0
8 0
scxspl 192 133608 0 133608 23 22 1 6 0
8 1
sigapl 432 2633 0 2621 2 0 2 2 0
8 0
futexpl 56 40483 0 40483 3 2 1 1 0
8 1
knotepl 112 1008 0 981 6 5 1 2 0
8 0
kqueuepl 104 614 0 612 1 0 1 1 0
8 0
pipepl 112 1754 0 1735 7 6 1 2 0
8 0
fdescpl 424 2634 0 2621 2 0 2 2 0
8 0
filepl 120 17389 0 17294 8 4 4 5 0
8 0
lockfpl 104 766 0 766 43 42 1 1 0
8 1
lockfspl 32 1063 0 1063 43 42 1 1 0
8 1
sessionpl 112 45 0 35 1 0 1 1 0
8 0
pgrppl 48 76 0 66 1 0 1 1 0
8 0
ucredpl 96 4888 0 4881 1 0 1 1 0
8 0
zombiepl 144 2621 0 2621 2 1 1 1 0
8 1
processpl 840 2649 0 2621 4 0 4 4 0
8 0
procpl 600 6358 0 6322 4 0 4 4 0
8 0
sosppl 128 33 0 33 10 10 0 1 0
8 0
sockpl 384 2458 0 2441 46 43 3 4 0
8 1
mcl64k 65536 455 0 455 76 75 1 29 0
8 1
mcl16k 16384 8 0 8 8 8 0 1 0
8 0
mcl12k 12288 62 0 62 28 27 1 1 0
8 1
mcl9k 9216 37 0 37 22 21 1 1 0
8 1
mcl8k 8192 41 0 41 24 24 0 1 0
8 0
mcl4k 4096 156 0 156 39 39 0 1 0
8 0
mcl2k2 2112 19 0 19 12 11 1 1 0
8 1
mcl2k 2048 50448 0 50405 21 15 6 13 0
8 0
mtagpl 80 4 0 4 2 2 0 1 0
8 0
mbufpl 256 98365 0 98287 45 37 8 21 0
8 0
bufpl 256 13830 0 8168 355 0 355 355 0
8 0
anonpl 16 1221816 0 1213496 126 77 49 67 0
62 0
amapchunkpl 152 17425 0 17349 81 77 4 14 0
158 0
amappl16 192 68353 0 67875 182 152 30 48 0
8 3
amappl15 184 408 0 406 1 0 1 1 0
8 0
amappl14 176 739 0 734 1 0 1 1 0
8 0
amappl13 168 622 0 618 1 0 1 1 0
8 0
amappl12 160 487 0 487 4 4 0 1 0
8 0
amappl11 152 681 0 671 1 0 1 1 0
8 0
amappl10 144 435 0 432 2 1 1 1 0
8 0
amappl9 136 887 0 884 1 0 1 1 0
8 0
amappl8 128 933 0 901 2 0 2 2 0
8 0
amappl7 120 470 0 463 1 0 1 1 0
8 0
amappl6 112 313 0 306 1 0 1 1 0
8 0
amappl5 104 260 0 248 1 0 1 1 0
8 0
amappl4 96 661 0 636 1 0 1 1 0
8 0
amappl3 88 379 0 373 1 0 1 1 0
8 0
amappl2 80 24100 0 24057 2 0 2 2 0
8 0
amappl1 72 58816 0 58420 23 13 10 19 0
8 0
amappl 72 6955 0 6926 1 0 1 1 0
75 0
dma4096 4096 1 0 1 1 1 0 1 0
8 0
dma256 256 6 0 6 1 1 0 1 0
8 0
dma64 64 259 0 259 1 1 0 1 0
8 0
dma32 32 7 0 7 1 1 0 1 0
8 0
dma16 16 17 0 17 1 1 0 1 0
8 0
aobjpl 64 121 0 15 2 0 2 2 0
8 0
uaddrrnd 24 2634 0 2621 1 0 1 1 0
8 0
uaddrbest 32 2 0 0 1 0 1 1 0
8 0
uaddr 24 2634 0 2621 1 0 1 1 0
8 0
vmmpekpl 168 22151 0 22129 2 0 2 2 0
8 0
vmmpepl 168 535491 0 534156 283 211 72 88 0
357 0
vmsppl 264 2633 0 2621 11 10 1 2 0
8 0
pdppl 4096 5274 0 5242 6 1 5 6 0
8 0
pvpl 32 3642693 0 3631367 687 522 165 235 0 265
56
pmappl 192 2633 0 2621 1 0 1 1 0
8 0
extentpl 40 39 0 25 1 0 1 1 0
8 0
phpool 112 691 0 207 15 0 15 15 0
8 0
---
This bug is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#bug-status-tracking for how to communicate with
syzbot.