Hello,
syzbot found the following crash on:
HEAD commit: 54f904eb drm/amdkfd: fix a potential NULL pointer derefere..
git tree: openbsd
console output:
https://syzkaller.appspot.com/x/log.txt?x=15c97615e00000
kernel config:
https://syzkaller.appspot.com/x/.config?x=fe55924c11e64b0a
dashboard link:
https://syzkaller.appspot.com/bug?extid=ea8b62f6f611111600ce
Unfortunately, I don't have any reproducer for this crash yet.
IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by:
syzbot+ea8b62...@syzkaller.appspotmail.com
panic: unhandled af 0
Stopped at db_enter+0x18: addq $0x8,%rsp
TID PID UID PRFLAGS PFLAGS CPU COMMAND
*213491 58520 0 0 0x4000000 0 syz-executor.0
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:398
panic(ffffffff821b8806) at panic+0x15c sys/kern/subr_prf.c:207
unhandled_af(0) at unhandled_af+0x16
pf_addrcpy(ffff80001e455a48,ffff80001e455d40,0) at pf_addrcpy+0x99
sys/net/pf.c:409
pfioctl(4900,c0504417,ffff80001e455d40,1,ffff80001e43e018) at
pfioctl+0x43c0 sys/net/pf_ioctl.c:1827
VOP_IOCTL(fffffd805d5c8410,c0504417,ffff80001e455d40,1,fffffd806c3be900,ffff80001e43e018)
at
VOP_IOCTL+0x88 sys/kern/vfs_vops.c:291
vn_ioctl(fffffd8057e033d0,c0504417,ffff80001e455d40,ffff80001e43e018) at
vn_ioctl+0xb7 sys/kern/vfs_vnops.c:533
sys_ioctl(ffff80001e43e018,ffff80001e455e58,ffff80001e455ea0) at
sys_ioctl+0x5b9
syscall(ffff80001e455f20) at syscall+0x507 sys/arch/amd64/amd64/trap.c:555
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0xee0b7eb550, count: 5
https://www.openbsd.org/ddb.html describes the minimum info required in bug
reports. Insufficient info makes it difficult to find and fix bugs.
ddb>
ddb> set $lines = 0
ddb> set $maxwidth = 0
ddb> show panic
unhandled af 0
ddb> trace
db_enter() at db_enter+0x18 sys/arch/amd64/amd64/db_interface.c:398
panic(ffffffff821b8806) at panic+0x15c sys/kern/subr_prf.c:207
unhandled_af(0) at unhandled_af+0x16
pf_addrcpy(ffff80001e455a48,ffff80001e455d40,0) at pf_addrcpy+0x99
sys/net/pf.c:409
pfioctl(4900,c0504417,ffff80001e455d40,1,ffff80001e43e018) at
pfioctl+0x43c0 sys/net/pf_ioctl.c:1827
VOP_IOCTL(fffffd805d5c8410,c0504417,ffff80001e455d40,1,fffffd806c3be900,ffff80001e43e018)
at
VOP_IOCTL+0x88 sys/kern/vfs_vops.c:291
vn_ioctl(fffffd8057e033d0,c0504417,ffff80001e455d40,ffff80001e43e018) at
vn_ioctl+0xb7 sys/kern/vfs_vnops.c:533
sys_ioctl(ffff80001e43e018,ffff80001e455e58,ffff80001e455ea0) at
sys_ioctl+0x5b9
syscall(ffff80001e455f20) at syscall+0x507 sys/arch/amd64/amd64/trap.c:555
Xsyscall() at Xsyscall+0x128
end of kernel
end trace frame: 0xee0b7eb550, count: -10
ddb> show registers
rdi 0xffffffff8147cb17 db_enter+0x17
rsi 0xb44
rbp 0xffff80001e455900
rbx 0xffff80001e4559b0
rdx 0xb45
rcx 0xffff80001d43d000
rax 0xffff80001d43d000
r8 0xffff80001e4558c0
r9 0x1
r10 0xffff8000009f29c0
r11 0xd90a8ccfa14ceab5
r12 0x3000000008
r13 0xffff80001e455910
r14 0x100
r15 0x1
rip 0xffffffff8147cb18 db_enter+0x18
cs 0x8
rflags 0x246
rsp 0xffff80001e4558f0
ss 0x10
db_enter+0x18: addq $0x8,%rsp
ddb> show proc
PROC (syz-executor.0) pid=213491 stat=onproc
flags process=0 proc=4000000<THREAD>
pri=79, usrpri=79, nice=20
forw=0xffffffffffffffff, list=0xffff80001e43f3d8,0xffffffff8254aeb8
process=0xffff8000ffff77e8 user=0xffff80001e450000,
vmspace=0xfffffd806bc09660
estcpu=36, cpticks=0, pctcpu=0.0
user=0, sys=0, intr=0
ddb> ps
PID TID PPID UID S FLAGS WAIT COMMAND
58520 449827 2649 0 2 0 syz-executor.0
*58520 213491 2649 0 7 0x4000000 syz-executor.0
92597 350689 8684 0 2 0x2 syz-executor.1
2649 103958 8684 0 3 0x82 nanosleep syz-executor.0
8684 451886 18071 0 3 0x82 thrsleep syz-fuzzer
8684 371920 18071 0 3 0x4000082 nanosleep syz-fuzzer
8684 257372 18071 0 3 0x4000082 thrsleep syz-fuzzer
8684 70403 18071 0 3 0x4000082 thrsleep syz-fuzzer
8684 383980 18071 0 3 0x4000082 kqread syz-fuzzer
8684 298956 18071 0 3 0x4000082 thrsleep syz-fuzzer
8684 87175 18071 0 3 0x4000082 thrsleep syz-fuzzer
8684 462097 18071 0 3 0x4000082 thrsleep syz-fuzzer
18071 319199 6506 0 3 0x10008a pause ksh
6506 443763 20379 0 3 0x92 select sshd
69675 414626 1 0 3 0x100083 ttyin getty
20379 285303 1 0 3 0x80 select sshd
78827 92890 16912 73 3 0x100090 kqread syslogd
16912 235401 1 0 3 0x100082 netio syslogd
87568 7568 1 77 3 0x100090 poll dhclient
51367 90191 1 0 3 0x80 poll dhclient
21416 414501 0 0 2 0x14200 zerothread
7168 106554 0 0 3 0x14200 aiodoned aiodoned
63148 514674 0 0 3 0x14200 syncer update
61742 1361 0 0 3 0x14200 cleaner cleaner
92167 158910 0 0 3 0x14200 reaper reaper
43020 63299 0 0 3 0x14200 pgdaemon pagedaemon
80618 84007 0 0 3 0x14200 bored crynlk
42326 385229 0 0 3 0x14200 bored crypto
47098 63595 0 0 3 0x40014200 acpi0 acpi0
30007 337985 0 0 3 0x14200 bored softnet
35388 5252 0 0 3 0x14200 bored systqmp
41683 421611 0 0 3 0x14200 bored systq
85220 170698 0 0 3 0x40014200 bored softclock
26768 428777 0 0 3 0x40014200 idle0
60108 467258 0 0 3 0x14200 bored smr
1 497067 0 0 3 0x82 wait init
0 0 -1 0 3 0x10200 scheduler swapper
ddb> show all locks
No such command
ddb> show malloc
Type InUse MemUse HighUse Limit Requests Type Lim
devbuf 9448 6323K 6518K 78643K 11654 0
pcb 13 8K 9K 78643K 3453 0
rtable 105 3K 3K 78643K 193 0
ifaddr 39 10K 10K 78643K 39 0
counters 19 16K 16K 78643K 19 0
ioctlops 0 0K 2K 78643K 44 0
iov 0 0K 0K 78643K 12 0
mount 1 1K 1K 78643K 1 0
vnodes 1217 76K 76K 78643K 1932 0
UFS quota 1 32K 32K 78643K 1 0
UFS mount 5 36K 36K 78643K 5 0
shm 2 1K 5K 78643K 30 0
VM map 2 0K 0K 78643K 2 0
sem 3 0K 0K 78643K 4 0
dirhash 12 2K 2K 78643K 12 0
ACPI 1794 195K 288K 78643K 12646 0
file desc 5 13K 25K 78643K 4799 0
sigio 0 0K 0K 78643K 8 0
proc 65 39K 54K 78643K 376 0
subproc 32 2K 2K 78643K 34 0
NFS srvsock 1 0K 0K 78643K 1 0
NFS daemon 1 16K 16K 78643K 1 0
ip_moptions 0 0K 0K 78643K 2 0
in_multi 33 2K 2K 78643K 33 0
ether_multi 1 0K 0K 78643K 1 0
ISOFS mount 1 32K 32K 78643K 1 0
MSDOSFS mount 1 16K 16K 78643K 1 0
ttys 31 148K 148K 78643K 31 0
exec 0 0K 1K 78643K 181 0
pagedep 1 8K 8K 78643K 1 0
inodedep 1 32K 32K 78643K 1 0
newblk 1 0K 0K 78643K 1 0
VM swap 7 26K 26K 78643K 7 0
UVM amap 95 20K 21K 78643K 10493 0
UVM aobj 130 4K 4K 78643K 130 0
memdesc 1 4K 4K 78643K 1 0
crypto data 1 1K 1K 78643K 1 0
NDP 5 0K 0K 78643K 9 0
temp 103 3017K 3081K 78643K 13499 0
SYN cache 2 16K 16K 78643K 2 0
ddb> show all pools
Name Size Requests Fail Releases Pgreq Pgrel Npage Hiwat Minpg Maxpg
Idle
arp 64 6 0 0 1 0 1 1 0
8 0
rtpcb 80 19 0 17 1 0 1 1 0
8 0
rtentry 112 45 0 1 2 0 2 2 0
8 0
unpcb 120 6198 0 6190 4 2 2 2 0
8 1
syncache 264 4 0 4 1 1 0 1 0
8 0
sackhl 24 1 0 1 1 1 0 1 0
8 0
tcpqe 32 18 0 18 2 2 0 1 0
8 0
tcpcb 544 3285 0 3281 3 1 2 2 0
8 1
inpcb 280 6749 0 6742 5 3 2 3 0
8 1
nd6 48 4 0 0 1 0 1 1 0
8 0
art_heap8 4096 1 0 0 1 0 1 1 0
8 0
art_heap4 256 212 0 0 14 0 14 14 0
8 0
art_table 32 213 0 0 2 0 2 2 0
8 0
art_node 16 44 0 4 1 0 1 1 0
8 0
semapl 112 2 0 1 1 0 1 1 0
8 0
shmpl 112 128 0 0 4 0 4 4 0
8 0
dirhash 1024 17 0 0 3 0 3 3 0
8 0
dino1pl 128 6189 0 4789 46 0 46 46 0
8 0
ffsino 240 6189 0 4789 83 0 83 83 0
8 0
nchpl 144 13846 0 12235 60 0 60 60 0
8 0
uvmvnodes 72 5926 0 0 108 0 108 108 0
8 0
vnodes 208 5926 0 0 312 0 312 312 0
8 0
namei 1024 29265 0 29265 1 0 1 1 0
8 1
scxspl 192 33112 0 33112 1 0 1 1 0
8 1
plimitpl 152 14 0 7 1 0 1 1 0
8 0
sigapl 432 4970 0 4957 2 0 2 2 0
8 0
futexpl 56 57202 0 57202 1 0 1 1 0
8 1
knotepl 112 58 0 39 1 0 1 1 0
8 0
kqueuepl 104 45 0 43 1 0 1 1 0
8 0
pipepl 112 2342 0 2323 1 0 1 1 0
8 0
fdescpl 424 4971 0 4957 2 0 2 2 0
8 0
filepl 120 25588 0 25487 7 2 5 5 0
8 1
lockfpl 104 666 0 665 1 0 1 1 0
8 0
lockfspl 48 331 0 330 1 0 1 1 0
8 0
sessionpl 112 17 0 7 1 0 1 1 0
8 0
pgrppl 48 17 0 7 1 0 1 1 0
8 0
ucredpl 96 688 0 681 1 0 1 1 0
8 0
zombiepl 144 4957 0 4957 1 0 1 1 0
8 1
processpl 872 4985 0 4957 4 0 4 4 0
8 0
procpl 632 9810 0 9774 4 0 4 4 0
8 0
sockpl 384 12977 0 12960 15 9 6 7 0
8 4
mcl64k 65536 30 0 30 3 2 1 1 0
8 1
mcl16k 16384 108 0 108 1 1 0 1 0
8 0
mcl12k 12288 61 0 61 4 3 1 1 0
8 1
mcl9k 9216 38 0 38 3 3 0 1 0
8 0
mcl8k 8192 74 0 74 3 2 1 1 0
8 1
mcl4k 4096 335 0 335 4 3 1 1 0
8 1
mcl2k2 2112 36 0 36 4 4 0 1 0
8 0
mcl2k 2048 25538 0 25497 15 9 6 11 0
8 0
mtagpl 80 2 0 2 1 1 0 1 0
8 0
mbufpl 256 67037 0 66942 13 3 10 10 0
8 2
bufpl 280 10933 0 4749 442 0 442 442 0
8 0
anonpl 16 285935 0 281467 21 1 20 20 0
107 0
amapchunkpl 152 15281 0 15188 7 2 5 5 0
158 0
amappl16 192 16775 0 16567 11 0 11 11 0
8 0
amappl15 184 4788 0 4782 1 0 1 1 0
8 0
amappl14 176 25 0 23 1 0 1 1 0
8 0
amappl12 160 2402 0 2399 1 0 1 1 0
8 0
amappl11 152 47 0 36 1 0 1 1 0
8 0
amappl10 144 21 0 17 1 0 1 1 0
8 0
amappl9 136 557 0 554 1 0 1 1 0
8 0
amappl8 128 111 0 91 1 0 1 1 0
8 0
amappl7 120 92 0 81 1 0 1 1 0
8 0
amappl6 112 50 0 47 1 0 1 1 0
8 0
amappl5 104 2566 0 2554 1 0 1 1 0
8 0
amappl4 96 5293 0 5263 1 0 1 1 0
8 0
amappl3 88 218 0 211 1 0 1 1 0
8 0
amappl2 80 41413 0 41343 3 1 2 3 0
8 0
amappl1 72 92191 0 91769 26 16 10 20 0
8 0
amappl 80 10031 0 9996 1 0 1 1 0
84 0
dma4096 4096 1 0 1 1 1 0 1 0
8 0
dma256 256 6 0 6 1 1 0 1 0
8 0
dma128 128 253 0 253 1 1 0 1 0
8 0
dma64 64 6 0 6 1 1 0 1 0
8 0
dma32 32 7 0 7 1 1 0 1 0
8 0
dma16 16 18 0 17 1 0 1 1 0
8 0
aobjpl 64 129 0 0 3 0 3 3 0
8 0
uaddrrnd 24 4971 0 4957 1 0 1 1 0
8 0
uaddrbest 32 2 0 0 1 0 1 1 0
8 0
uaddr 24 4971 0 4957 1 0 1 1 0
8 0
vmmpekpl 168 28278 0 28258 2 0 2 2 0
8 0
vmmpepl 168 555164 0 553870 85 23 62 78 0
357 5
vmsppl 272 4970 0 4957 2 1 1 2 0
8 0
pdppl 4096 9948 0 9914 6 1 5 6 0
8 0
pvpl 32 829844 0 822375 119 54 65 115 0
265 1
pmappl 200 4970 0 4957 1 0 1 1 0
8 0
extentpl 40 46 0 29 1 0 1 1 0
8 0
phpool 112 154 0 25 4 0 4 4 0
8 0
---
This bug is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.